git: openjdk/jdk: 8300140: ZipFile.isSignatureRelated returns true for files in META-INF subdirectories

Weijun Wang weijun at openjdk.org
Fri Jan 27 22:49:45 UTC 2023


Changeset: 5dfc4ec7
Author:    Eirik Bjorsnos <eirbjo at gmail.com>
Committer: Weijun Wang <weijun at openjdk.org>
Date:      2023-01-27 22:47:51 +0000
URL:       https://git.openjdk.org/jdk/commit/5dfc4ec7d94af9fe39fdee9d83b06101b827a3c6

8300140: ZipFile.isSignatureRelated returns true for files in META-INF subdirectories

Reviewed-by: weijun

! src/java.base/share/classes/java/util/jar/JarVerifier.java
! src/java.base/share/classes/java/util/zip/ZipFile.java
! src/java.base/share/classes/sun/security/util/SignatureFileVerifier.java
! src/jdk.jartool/share/classes/jdk/security/jarsigner/JarSigner.java
! src/jdk.jartool/share/classes/sun/security/tools/jarsigner/Main.java
+ test/jdk/java/util/jar/JarFile/IgnoreUnrelatedSignatureFiles.java



More information about the jdk-changes mailing list