Tue, 08 Oct 2013 16:46:03 +0200
8026048: Function constructor should convert arguments to String before performing any syntax checks
Reviewed-by: jlaskey, hannesw
src/jdk/nashorn/internal/objects/NativeFunction.java | file | annotate | diff | comparison | revisions | |
test/script/basic/JDK-8026048.js | file | annotate | diff | comparison | revisions |
1.1 --- a/src/jdk/nashorn/internal/objects/NativeFunction.java Tue Oct 08 15:53:22 2013 +0200 1.2 +++ b/src/jdk/nashorn/internal/objects/NativeFunction.java Tue Oct 08 16:46:03 2013 +0200 1.3 @@ -221,6 +221,7 @@ 1.4 final StringBuilder sb = new StringBuilder(); 1.5 1.6 sb.append("(function ("); 1.7 + final String funcBody; 1.8 if (args.length > 0) { 1.9 final StringBuilder paramListBuf = new StringBuilder(); 1.10 for (int i = 0; i < args.length - 1; i++) { 1.11 @@ -230,15 +231,20 @@ 1.12 } 1.13 } 1.14 1.15 + // now convert function body to a string 1.16 + funcBody = JSType.toString(args[args.length - 1]); 1.17 + 1.18 final String paramList = paramListBuf.toString(); 1.19 if (! paramList.isEmpty()) { 1.20 checkFunctionParameters(paramList); 1.21 sb.append(paramList); 1.22 } 1.23 + } else { 1.24 + funcBody = null; 1.25 } 1.26 + 1.27 sb.append(") {\n"); 1.28 if (args.length > 0) { 1.29 - final String funcBody = JSType.toString(args[args.length - 1]); 1.30 checkFunctionBody(funcBody); 1.31 sb.append(funcBody); 1.32 sb.append('\n');
2.1 --- /dev/null Thu Jan 01 00:00:00 1970 +0000 2.2 +++ b/test/script/basic/JDK-8026048.js Tue Oct 08 16:46:03 2013 +0200 2.3 @@ -0,0 +1,37 @@ 2.4 +/* 2.5 + * Copyright (c) 2010, 2013, Oracle and/or its affiliates. All rights reserved. 2.6 + * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER. 2.7 + * 2.8 + * This code is free software; you can redistribute it and/or modify it 2.9 + * under the terms of the GNU General Public License version 2 only, as 2.10 + * published by the Free Software Foundation. 2.11 + * 2.12 + * This code is distributed in the hope that it will be useful, but WITHOUT 2.13 + * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or 2.14 + * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License 2.15 + * version 2 for more details (a copy is included in the LICENSE file that 2.16 + * accompanied this code). 2.17 + * 2.18 + * You should have received a copy of the GNU General Public License version 2.19 + * 2 along with this work; if not, write to the Free Software Foundation, 2.20 + * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA. 2.21 + * 2.22 + * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA 2.23 + * or visit www.oracle.com if you need additional information or have any 2.24 + * questions. 2.25 + */ 2.26 + 2.27 +/** 2.28 + * JDK-8026048: Function constructor should convert arguments to String before performing any syntax checks 2.29 + * 2.30 + * @test 2.31 + * @run 2.32 + */ 2.33 + 2.34 +try { 2.35 + Function("-", {toString:function(){throw "err"}}) 2.36 +} catch (e) { 2.37 + if (e !== "err") { 2.38 + fail("err xpected, got " + e); 2.39 + } 2.40 +}