Fri, 24 Sep 2010 22:42:14 -0700
6891766: Vulnerabilities in use of reflection in CORBA
Reviewed-by: hawtin
duke@1 | 1 | /* |
skoppar@205 | 2 | * Copyright (c) 2002, 2010, Oracle and/or its affiliates. All rights reserved. |
duke@1 | 3 | * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER. |
duke@1 | 4 | * |
duke@1 | 5 | * This code is free software; you can redistribute it and/or modify it |
duke@1 | 6 | * under the terms of the GNU General Public License version 2 only, as |
ohair@158 | 7 | * published by the Free Software Foundation. Oracle designates this |
duke@1 | 8 | * particular file as subject to the "Classpath" exception as provided |
ohair@158 | 9 | * by Oracle in the LICENSE file that accompanied this code. |
duke@1 | 10 | * |
duke@1 | 11 | * This code is distributed in the hope that it will be useful, but WITHOUT |
duke@1 | 12 | * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or |
duke@1 | 13 | * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License |
duke@1 | 14 | * version 2 for more details (a copy is included in the LICENSE file that |
duke@1 | 15 | * accompanied this code). |
duke@1 | 16 | * |
duke@1 | 17 | * You should have received a copy of the GNU General Public License version |
duke@1 | 18 | * 2 along with this work; if not, write to the Free Software Foundation, |
duke@1 | 19 | * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA. |
duke@1 | 20 | * |
ohair@158 | 21 | * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA |
ohair@158 | 22 | * or visit www.oracle.com if you need additional information or have any |
ohair@158 | 23 | * questions. |
duke@1 | 24 | */ |
duke@1 | 25 | |
duke@1 | 26 | package com.sun.corba.se.impl.orb ; |
duke@1 | 27 | |
duke@1 | 28 | import org.omg.CORBA.INITIALIZE ; |
duke@1 | 29 | |
duke@1 | 30 | import java.util.Properties ; |
duke@1 | 31 | import java.util.List ; |
duke@1 | 32 | import java.util.LinkedList ; |
duke@1 | 33 | import java.util.Iterator ; |
duke@1 | 34 | |
duke@1 | 35 | import java.lang.reflect.Array ; |
duke@1 | 36 | |
duke@1 | 37 | import com.sun.corba.se.spi.orb.Operation ; |
duke@1 | 38 | import com.sun.corba.se.spi.orb.StringPair ; |
duke@1 | 39 | import com.sun.corba.se.spi.logging.CORBALogDomains ; |
duke@1 | 40 | |
duke@1 | 41 | import com.sun.corba.se.impl.orbutil.ObjectUtility ; |
duke@1 | 42 | import com.sun.corba.se.impl.logging.ORBUtilSystemException ; |
duke@1 | 43 | |
duke@1 | 44 | public class PrefixParserAction extends ParserActionBase { |
duke@1 | 45 | private Class componentType ; |
duke@1 | 46 | private ORBUtilSystemException wrapper ; |
duke@1 | 47 | |
duke@1 | 48 | public PrefixParserAction( String propertyName, |
duke@1 | 49 | Operation operation, String fieldName, Class componentType ) |
duke@1 | 50 | { |
duke@1 | 51 | super( propertyName, true, operation, fieldName ) ; |
duke@1 | 52 | this.componentType = componentType ; |
duke@1 | 53 | this.wrapper = ORBUtilSystemException.get( |
duke@1 | 54 | CORBALogDomains.ORB_LIFECYCLE ) ; |
duke@1 | 55 | } |
duke@1 | 56 | |
duke@1 | 57 | /** For each String s that matches the prefix given by getPropertyName(), |
duke@1 | 58 | * apply getOperation() to { suffix( s ), value } |
duke@1 | 59 | * and add the result to an Object[] |
duke@1 | 60 | * which forms the result of apply. Returns null if there are no |
duke@1 | 61 | * matches. |
duke@1 | 62 | */ |
duke@1 | 63 | public Object apply( Properties props ) |
duke@1 | 64 | { |
duke@1 | 65 | String prefix = getPropertyName() ; |
duke@1 | 66 | int prefixLength = prefix.length() ; |
duke@1 | 67 | if (prefix.charAt( prefixLength - 1 ) != '.') { |
duke@1 | 68 | prefix += '.' ; |
duke@1 | 69 | prefixLength++ ; |
duke@1 | 70 | } |
duke@1 | 71 | |
duke@1 | 72 | List matches = new LinkedList() ; |
duke@1 | 73 | |
duke@1 | 74 | // Find all keys in props that start with propertyName |
duke@1 | 75 | Iterator iter = props.keySet().iterator() ; |
duke@1 | 76 | while (iter.hasNext()) { |
duke@1 | 77 | String key = (String)(iter.next()) ; |
duke@1 | 78 | if (key.startsWith( prefix )) { |
duke@1 | 79 | String suffix = key.substring( prefixLength ) ; |
duke@1 | 80 | String value = props.getProperty( key ) ; |
duke@1 | 81 | StringPair data = new StringPair( suffix, value ) ; |
duke@1 | 82 | Object result = getOperation().operate( data ) ; |
duke@1 | 83 | matches.add( result ) ; |
duke@1 | 84 | } |
duke@1 | 85 | } |
duke@1 | 86 | |
duke@1 | 87 | int size = matches.size() ; |
duke@1 | 88 | if (size > 0) { |
duke@1 | 89 | // Convert the list into an array of the proper type. |
duke@1 | 90 | // An Object[] as a result does NOT work. Also report |
duke@1 | 91 | // any errors carefully, as errors here or in parsers that |
duke@1 | 92 | // use this Operation often show up at ORB.init(). |
duke@1 | 93 | Object result = null ; |
duke@1 | 94 | try { |
duke@1 | 95 | result = Array.newInstance( componentType, size ) ; |
duke@1 | 96 | } catch (Throwable thr) { |
duke@1 | 97 | throw wrapper.couldNotCreateArray( thr, |
duke@1 | 98 | getPropertyName(), componentType, |
duke@1 | 99 | new Integer( size ) ) ; |
duke@1 | 100 | } |
duke@1 | 101 | |
duke@1 | 102 | Iterator iter2 = matches.iterator() ; |
duke@1 | 103 | int ctr = 0 ; |
duke@1 | 104 | while (iter2.hasNext()) { |
duke@1 | 105 | Object obj = iter2.next() ; |
duke@1 | 106 | |
duke@1 | 107 | try { |
duke@1 | 108 | Array.set( result, ctr, obj ) ; |
duke@1 | 109 | } catch (Throwable thr) { |
duke@1 | 110 | throw wrapper.couldNotSetArray( thr, |
duke@1 | 111 | getPropertyName(), new Integer(ctr), |
duke@1 | 112 | componentType, new Integer(size), |
skoppar@205 | 113 | obj.toString() ) ; |
duke@1 | 114 | } |
duke@1 | 115 | ctr++ ; |
duke@1 | 116 | } |
duke@1 | 117 | |
duke@1 | 118 | return result ; |
duke@1 | 119 | } else |
duke@1 | 120 | return null ; |
duke@1 | 121 | } |
duke@1 | 122 | } |