|
|
719156 |
commit 09bcd3ebb639af6cfd83ff2203ffeb80a59cc0eb
|
|
|
719156 |
Author: Jiri Vanek <jvanek@redhat.com>
|
|
|
719156 |
Date: Fri Jun 28 16:05:35 2019 +0200
|
|
|
719156 |
|
|
|
719156 |
All files, except signaturre files, are now checked for signatures
|
|
|
719156 |
|
|
|
719156 |
diff --git a/netx/net/sourceforge/jnlp/tools/JarCertVerifier.java b/netx/net/sourceforge/jnlp/tools/JarCertVerifier.java
|
|
|
719156 |
index 759bedfb..cabfb3c5 100644
|
|
|
719156 |
--- a/netx/net/sourceforge/jnlp/tools/JarCertVerifier.java
|
|
|
719156 |
+++ b/netx/net/sourceforge/jnlp/tools/JarCertVerifier.java
|
|
|
719156 |
@@ -41,6 +41,7 @@
|
|
|
719156 |
import java.util.Map;
|
|
|
719156 |
import java.util.Vector;
|
|
|
719156 |
import java.util.jar.JarEntry;
|
|
|
719156 |
+import java.util.regex.Pattern;
|
|
|
719156 |
|
|
|
719156 |
import net.sourceforge.jnlp.JARDesc;
|
|
|
719156 |
import net.sourceforge.jnlp.JNLPFile;
|
|
|
719156 |
@@ -67,6 +68,7 @@
|
|
|
719156 |
public class JarCertVerifier implements CertVerifier {
|
|
|
719156 |
|
|
|
719156 |
private static final String META_INF = "META-INF/";
|
|
|
719156 |
+ private static final Pattern SIG = Pattern.compile(".*" + META_INF + "SIG-.*");
|
|
|
719156 |
|
|
|
719156 |
// prefix for new signature-related files in META-INF directory
|
|
|
719156 |
private static final String SIG_PREFIX = META_INF + "SIG-";
|
|
|
719156 |
@@ -500,12 +502,20 @@
|
|
|
719156 |
|
|
|
719156 |
/**
|
|
|
719156 |
* Returns whether a file is in META-INF, and thus does not require signing.
|
|
|
719156 |
- *
|
|
|
719156 |
+ *
|
|
|
719156 |
* Signature-related files under META-INF include: . META-INF/MANIFEST.MF . META-INF/SIG-* . META-INF/*.SF . META-INF/*.DSA . META-INF/*.RSA
|
|
|
719156 |
*/
|
|
|
719156 |
static boolean isMetaInfFile(String name) {
|
|
|
719156 |
- String ucName = name.toUpperCase();
|
|
|
719156 |
- return ucName.startsWith(META_INF);
|
|
|
719156 |
+ if (name.endsWith("class")) {
|
|
|
719156 |
+ return false;
|
|
|
719156 |
+ }
|
|
|
719156 |
+ return name.startsWith(META_INF) && (
|
|
|
719156 |
+ name.endsWith(".MF") ||
|
|
|
719156 |
+ name.endsWith(".SF") ||
|
|
|
719156 |
+ name.endsWith(".DSA") ||
|
|
|
719156 |
+ name.endsWith(".RSA") ||
|
|
|
719156 |
+ SIG.matcher(name).matches()
|
|
|
719156 |
+ );
|
|
|
719156 |
}
|
|
|
719156 |
|
|
|
719156 |
/**
|
|
|
719156 |
diff --git a/tests/netx/unit/net/sourceforge/jnlp/tools/JarCertVerifierTest.java b/tests/netx/unit/net/sourceforge/jnlp/tools/JarCertVerifierTest.java
|
|
|
719156 |
index 4661fb87..44253e08 100644
|
|
|
719156 |
--- a/tests/netx/unit/net/sourceforge/jnlp/tools/JarCertVerifierTest.java
|
|
|
719156 |
+++ b/tests/netx/unit/net/sourceforge/jnlp/tools/JarCertVerifierTest.java
|
|
|
719156 |
@@ -58,9 +58,22 @@ public class JarCertVerifierTest {
|
|
|
719156 |
@Test
|
|
|
719156 |
public void testIsMetaInfFile() {
|
|
|
719156 |
final String METAINF = "META-INF";
|
|
|
719156 |
+ assertTrue(JarCertVerifier.isMetaInfFile(METAINF + "/file.MF"));
|
|
|
719156 |
+ assertTrue(JarCertVerifier.isMetaInfFile(METAINF + "/file.SF"));
|
|
|
719156 |
+ assertTrue(JarCertVerifier.isMetaInfFile(METAINF + "/file.DSA"));
|
|
|
719156 |
+ assertTrue(JarCertVerifier.isMetaInfFile(METAINF + "/file.RSA"));
|
|
|
719156 |
+ assertTrue(JarCertVerifier.isMetaInfFile(METAINF + "/SIG-blah.blah"));
|
|
|
719156 |
+
|
|
|
719156 |
+ assertFalse(JarCertVerifier.isMetaInfFile(METAINF + "/file.MF.class"));
|
|
|
719156 |
+ assertFalse(JarCertVerifier.isMetaInfFile(METAINF + "/file.SF.class"));
|
|
|
719156 |
+ assertFalse(JarCertVerifier.isMetaInfFile(METAINF + "/file.DSA.class"));
|
|
|
719156 |
+ assertFalse(JarCertVerifier.isMetaInfFile(METAINF + "/file.RSA.class"));
|
|
|
719156 |
+ assertFalse(JarCertVerifier.isMetaInfFile(METAINF + "/SIG-blah.blah.class"));
|
|
|
719156 |
+
|
|
|
719156 |
assertFalse(JarCertVerifier.isMetaInfFile("some_dir/" + METAINF + "/filename"));
|
|
|
719156 |
assertFalse(JarCertVerifier.isMetaInfFile(METAINF + "filename"));
|
|
|
719156 |
- assertTrue(JarCertVerifier.isMetaInfFile(METAINF + "/filename"));
|
|
|
719156 |
+ assertFalse(JarCertVerifier.isMetaInfFile(METAINF + "/filename"));
|
|
|
719156 |
+ assertFalse(JarCertVerifier.isMetaInfFile(METAINF + "/filename"));
|
|
|
719156 |
}
|
|
|
719156 |
|
|
|
719156 |
class JarCertVerifierEntry extends JarEntry {
|