Fri, 24 Sep 2010 22:42:14 -0700
6891766: Vulnerabilities in use of reflection in CORBA
Reviewed-by: hawtin
duke@1 | 1 | /* |
ohair@158 | 2 | * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved. |
duke@1 | 3 | * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER. |
duke@1 | 4 | * |
duke@1 | 5 | * This code is free software; you can redistribute it and/or modify it |
duke@1 | 6 | * under the terms of the GNU General Public License version 2 only, as |
ohair@158 | 7 | * published by the Free Software Foundation. Oracle designates this |
duke@1 | 8 | * particular file as subject to the "Classpath" exception as provided |
ohair@158 | 9 | * by Oracle in the LICENSE file that accompanied this code. |
duke@1 | 10 | * |
duke@1 | 11 | * This code is distributed in the hope that it will be useful, but WITHOUT |
duke@1 | 12 | * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or |
duke@1 | 13 | * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License |
duke@1 | 14 | * version 2 for more details (a copy is included in the LICENSE file that |
duke@1 | 15 | * accompanied this code). |
duke@1 | 16 | * |
duke@1 | 17 | * You should have received a copy of the GNU General Public License version |
duke@1 | 18 | * 2 along with this work; if not, write to the Free Software Foundation, |
duke@1 | 19 | * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA. |
duke@1 | 20 | * |
ohair@158 | 21 | * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA |
ohair@158 | 22 | * or visit www.oracle.com if you need additional information or have any |
ohair@158 | 23 | * questions. |
duke@1 | 24 | */ |
duke@1 | 25 | |
duke@1 | 26 | package com.sun.corba.se.impl.orbutil ; |
duke@1 | 27 | |
duke@1 | 28 | import java.util.Arrays ; |
duke@1 | 29 | |
duke@1 | 30 | public abstract class ObjectWriter { |
duke@1 | 31 | public static ObjectWriter make( boolean isIndenting, |
duke@1 | 32 | int initialLevel, int increment ) |
duke@1 | 33 | { |
duke@1 | 34 | if (isIndenting) |
duke@1 | 35 | return new IndentingObjectWriter( initialLevel, increment ) ; |
duke@1 | 36 | else |
duke@1 | 37 | return new SimpleObjectWriter() ; |
duke@1 | 38 | } |
duke@1 | 39 | |
duke@1 | 40 | public abstract void startObject( Object obj ) ; |
duke@1 | 41 | |
duke@1 | 42 | public abstract void startElement() ; |
duke@1 | 43 | |
duke@1 | 44 | public abstract void endElement() ; |
duke@1 | 45 | |
duke@1 | 46 | public abstract void endObject( String str ) ; |
duke@1 | 47 | |
duke@1 | 48 | public abstract void endObject() ; |
duke@1 | 49 | |
duke@1 | 50 | public String toString() { return result.toString() ; } |
duke@1 | 51 | |
duke@1 | 52 | public void append( boolean arg ) { result.append( arg ) ; } |
duke@1 | 53 | |
duke@1 | 54 | public void append( char arg ) { result.append( arg ) ; } |
duke@1 | 55 | |
duke@1 | 56 | public void append( short arg ) { result.append( arg ) ; } |
duke@1 | 57 | |
duke@1 | 58 | public void append( int arg ) { result.append( arg ) ; } |
duke@1 | 59 | |
duke@1 | 60 | public void append( long arg ) { result.append( arg ) ; } |
duke@1 | 61 | |
duke@1 | 62 | public void append( float arg ) { result.append( arg ) ; } |
duke@1 | 63 | |
duke@1 | 64 | public void append( double arg ) { result.append( arg ) ; } |
duke@1 | 65 | |
duke@1 | 66 | public void append( String arg ) { result.append( arg ) ; } |
duke@1 | 67 | |
duke@1 | 68 | //================================================================================================= |
duke@1 | 69 | // Implementation |
duke@1 | 70 | //================================================================================================= |
duke@1 | 71 | |
duke@1 | 72 | protected StringBuffer result ; |
duke@1 | 73 | |
duke@1 | 74 | protected ObjectWriter() |
duke@1 | 75 | { |
duke@1 | 76 | result = new StringBuffer() ; |
duke@1 | 77 | } |
duke@1 | 78 | |
duke@1 | 79 | protected void appendObjectHeader( Object obj ) |
duke@1 | 80 | { |
duke@1 | 81 | result.append( obj.getClass().getName() ) ; |
duke@1 | 82 | result.append( "<" ) ; |
duke@1 | 83 | result.append( System.identityHashCode( obj ) ) ; |
duke@1 | 84 | result.append( ">" ) ; |
duke@1 | 85 | Class compClass = obj.getClass().getComponentType() ; |
duke@1 | 86 | |
duke@1 | 87 | if (compClass != null) { |
duke@1 | 88 | result.append( "[" ) ; |
duke@1 | 89 | if (compClass == boolean.class) { |
duke@1 | 90 | boolean[] arr = (boolean[])obj ; |
duke@1 | 91 | result.append( arr.length ) ; |
duke@1 | 92 | result.append( "]" ) ; |
duke@1 | 93 | } else if (compClass == byte.class) { |
duke@1 | 94 | byte[] arr = (byte[])obj ; |
duke@1 | 95 | result.append( arr.length ) ; |
duke@1 | 96 | result.append( "]" ) ; |
duke@1 | 97 | } else if (compClass == short.class) { |
duke@1 | 98 | short[] arr = (short[])obj ; |
duke@1 | 99 | result.append( arr.length ) ; |
duke@1 | 100 | result.append( "]" ) ; |
duke@1 | 101 | } else if (compClass == int.class) { |
duke@1 | 102 | int[] arr = (int[])obj ; |
duke@1 | 103 | result.append( arr.length ) ; |
duke@1 | 104 | result.append( "]" ) ; |
duke@1 | 105 | } else if (compClass == long.class) { |
duke@1 | 106 | long[] arr = (long[])obj ; |
duke@1 | 107 | result.append( arr.length ) ; |
duke@1 | 108 | result.append( "]" ) ; |
duke@1 | 109 | } else if (compClass == char.class) { |
duke@1 | 110 | char[] arr = (char[])obj ; |
duke@1 | 111 | result.append( arr.length ) ; |
duke@1 | 112 | result.append( "]" ) ; |
duke@1 | 113 | } else if (compClass == float.class) { |
duke@1 | 114 | float[] arr = (float[])obj ; |
duke@1 | 115 | result.append( arr.length ) ; |
duke@1 | 116 | result.append( "]" ) ; |
duke@1 | 117 | } else if (compClass == double.class) { |
duke@1 | 118 | double[] arr = (double[])obj ; |
duke@1 | 119 | result.append( arr.length ) ; |
duke@1 | 120 | result.append( "]" ) ; |
duke@1 | 121 | } else { // array of object |
duke@1 | 122 | java.lang.Object[] arr = (java.lang.Object[])obj ; |
duke@1 | 123 | result.append( arr.length ) ; |
duke@1 | 124 | result.append( "]" ) ; |
duke@1 | 125 | } |
duke@1 | 126 | } |
duke@1 | 127 | |
duke@1 | 128 | result.append( "(" ) ; |
duke@1 | 129 | } |
duke@1 | 130 | |
duke@1 | 131 | /** Expected patterns: |
duke@1 | 132 | * startObject endObject( str ) |
duke@1 | 133 | * header( elem )\n |
duke@1 | 134 | * startObject ( startElement append* endElement ) * endObject |
duke@1 | 135 | * header(\n |
duke@1 | 136 | * append*\n * |
duke@1 | 137 | * )\n |
duke@1 | 138 | */ |
duke@1 | 139 | private static class IndentingObjectWriter extends ObjectWriter { |
duke@1 | 140 | private int level ; |
duke@1 | 141 | private int increment ; |
duke@1 | 142 | |
duke@1 | 143 | public IndentingObjectWriter( int initialLevel, int increment ) |
duke@1 | 144 | { |
duke@1 | 145 | this.level = initialLevel ; |
duke@1 | 146 | this.increment = increment ; |
duke@1 | 147 | startLine() ; |
duke@1 | 148 | } |
duke@1 | 149 | |
duke@1 | 150 | private void startLine() |
duke@1 | 151 | { |
duke@1 | 152 | char[] fill = new char[ level * increment ] ; |
duke@1 | 153 | Arrays.fill( fill, ' ' ) ; |
duke@1 | 154 | result.append( fill ) ; |
duke@1 | 155 | } |
duke@1 | 156 | |
duke@1 | 157 | public void startObject( java.lang.Object obj ) |
duke@1 | 158 | { |
duke@1 | 159 | appendObjectHeader( obj ) ; |
duke@1 | 160 | level++ ; |
duke@1 | 161 | } |
duke@1 | 162 | |
duke@1 | 163 | public void startElement() |
duke@1 | 164 | { |
duke@1 | 165 | result.append( "\n" ) ; |
duke@1 | 166 | startLine() ; |
duke@1 | 167 | } |
duke@1 | 168 | |
duke@1 | 169 | public void endElement() |
duke@1 | 170 | { |
duke@1 | 171 | } |
duke@1 | 172 | |
duke@1 | 173 | public void endObject( String str ) |
duke@1 | 174 | { |
duke@1 | 175 | level-- ; |
duke@1 | 176 | result.append( str ) ; |
duke@1 | 177 | result.append( ")" ) ; |
duke@1 | 178 | } |
duke@1 | 179 | |
duke@1 | 180 | public void endObject( ) |
duke@1 | 181 | { |
duke@1 | 182 | level-- ; |
duke@1 | 183 | result.append( "\n" ) ; |
duke@1 | 184 | startLine() ; |
duke@1 | 185 | result.append( ")" ) ; |
duke@1 | 186 | } |
duke@1 | 187 | } |
duke@1 | 188 | |
duke@1 | 189 | private static class SimpleObjectWriter extends ObjectWriter { |
duke@1 | 190 | public void startObject( java.lang.Object obj ) |
duke@1 | 191 | { |
duke@1 | 192 | appendObjectHeader( obj ) ; |
duke@1 | 193 | result.append( " " ) ; |
duke@1 | 194 | } |
duke@1 | 195 | |
duke@1 | 196 | public void startElement() |
duke@1 | 197 | { |
duke@1 | 198 | result.append( " " ) ; |
duke@1 | 199 | } |
duke@1 | 200 | |
duke@1 | 201 | public void endObject( String str ) |
duke@1 | 202 | { |
duke@1 | 203 | result.append( str ) ; |
duke@1 | 204 | result.append( ")" ) ; |
duke@1 | 205 | } |
duke@1 | 206 | |
duke@1 | 207 | public void endElement() |
duke@1 | 208 | { |
duke@1 | 209 | } |
duke@1 | 210 | |
duke@1 | 211 | public void endObject() |
duke@1 | 212 | { |
duke@1 | 213 | result.append( ")" ) ; |
duke@1 | 214 | } |
duke@1 | 215 | } |
duke@1 | 216 | } |