Skip to content

on forName validate packages of classes to load#8277

Closed
DaanHoogland wants to merge 2 commits intoapache:4.20from
shapeblue:secondRingSecDefenceForName
Closed

on forName validate packages of classes to load#8277
DaanHoogland wants to merge 2 commits intoapache:4.20from
shapeblue:secondRingSecDefenceForName

Conversation

@DaanHoogland
Copy link
Contributor

Description

This PR...

Types of changes

  • Breaking change (fix or feature that would cause existing functionality to change)
  • New feature (non-breaking change which adds functionality)
  • Bug fix (non-breaking change which fixes an issue)
  • Enhancement (improves an existing feature and functionality)
  • Cleanup (Code refactoring and cleanup, that may add test cases)
  • build/CI

Feature/Enhancement Scale or Bug Severity

Feature/Enhancement Scale

  • Major
  • Minor

Bug Severity

  • BLOCKER
  • Critical
  • Major
  • Minor
  • Trivial

Screenshots (if appropriate):

How Has This Been Tested?

How did you try to break this feature and the system with this change?

@codecov
Copy link

codecov bot commented Nov 28, 2023

Codecov Report

Attention: 11 lines in your changes are missing coverage. Please review.

Comparison is base (3bb318b) 13.13% compared to head (b3965d3) 13.11%.

❗ Current head b3965d3 differs from pull request most recent head e5e91a2. Consider uploading reports for the commit e5e91a2 to get more accurate results

Files Patch % Lines
...c/main/java/com/cloud/api/ApiSerializerHelper.java 45.00% 6 Missing and 5 partials ⚠️
Additional details and impacted files
@@             Coverage Diff              @@
##               4.18    #8277      +/-   ##
============================================
- Coverage     13.13%   13.11%   -0.02%     
+ Complexity     9143     9135       -8     
============================================
  Files          2720     2720              
  Lines        257717   257658      -59     
  Branches      40176    40173       -3     
============================================
- Hits          33843    33804      -39     
+ Misses       219583   219561      -22     
- Partials       4291     4293       +2     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

public class ApiSerializerHelper {
public static final Logger s_logger = Logger.getLogger(ApiSerializerHelper.class.getName());
private static String token = "/";
private static String[] apiPackages = {"com.cloud.agent.api", "org.apache.cloudstack.api"};
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I am not sure if this will improve security (is it the goal of this PR ?).
anyone can create java classes in the packages

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes, it is just an extra layer. They will also have to get those classes on the classpath of the remote machine though. I was think of extending the method to also be able to add a required base class or interface.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I am not sure if this will improve security (is it the goal of this PR ?). anyone can create java classes in the packages

any sugestions for improvement @weizhouapache ?

@apache apache deleted a comment from blueorangutan Nov 29, 2023
@DaanHoogland DaanHoogland force-pushed the secondRingSecDefenceForName branch from b3965d3 to e5e91a2 Compare December 18, 2023 09:21
@apache apache deleted a comment from blueorangutan Jan 19, 2024
@apache apache deleted a comment from blueorangutan Jan 19, 2024
@apache apache deleted a comment from blueorangutan Jan 19, 2024
@apache apache deleted a comment from blueorangutan Jan 19, 2024
@DaanHoogland DaanHoogland force-pushed the secondRingSecDefenceForName branch from e5e91a2 to 4805e80 Compare April 19, 2024 09:34
@codecov-commenter
Copy link

codecov-commenter commented Apr 19, 2024

Codecov Report

❌ Patch coverage is 52.00000% with 12 lines in your changes missing coverage. Please review.
✅ Project coverage is 16.18%. Comparing base (e4414d1) to head (3199374).
⚠️ Report is 9 commits behind head on 4.20.

Files with missing lines Patch % Lines
...c/main/java/com/cloud/api/ApiSerializerHelper.java 52.00% 7 Missing and 5 partials ⚠️
Additional details and impacted files
@@             Coverage Diff              @@
##               4.20    #8277      +/-   ##
============================================
- Coverage     16.18%   16.18%   -0.01%     
- Complexity    13300    13302       +2     
============================================
  Files          5657     5657              
  Lines        498478   498488      +10     
  Branches      60501    60503       +2     
============================================
- Hits          80668    80661       -7     
- Misses       408827   408840      +13     
- Partials       8983     8987       +4     
Flag Coverage Δ
uitests 4.00% <ø> (ø)
unittests 17.03% <52.00%> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@DaanHoogland DaanHoogland force-pushed the secondRingSecDefenceForName branch from 4805e80 to 099404b Compare April 19, 2024 10:49
@apache apache deleted a comment from blueorangutan Apr 19, 2024
@apache apache deleted a comment from blueorangutan Apr 19, 2024
@apache apache deleted a comment from blueorangutan Apr 19, 2024
@apache apache deleted a comment from blueorangutan Apr 19, 2024
@apache apache deleted a comment from blueorangutan Apr 19, 2024
@apache apache deleted a comment from blueorangutan Apr 19, 2024
@DaanHoogland DaanHoogland force-pushed the secondRingSecDefenceForName branch from 099404b to 4baf61f Compare April 22, 2024 09:37
@apache apache deleted a comment from blueorangutan Apr 22, 2024
@apache apache deleted a comment from blueorangutan Apr 22, 2024
@DaanHoogland DaanHoogland force-pushed the secondRingSecDefenceForName branch from 4baf61f to eaeb853 Compare December 8, 2025 15:07
@DaanHoogland DaanHoogland changed the base branch from 4.18 to 4.20 December 8, 2025 15:07
@apache apache deleted a comment from blueorangutan Dec 8, 2025
@apache apache deleted a comment from blueorangutan Dec 8, 2025
@apache apache deleted a comment from blueorangutan Dec 8, 2025
@apache apache deleted a comment from blueorangutan Dec 8, 2025
@DaanHoogland
Copy link
Contributor Author

@blueorangutan package

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants