2018-11-12 16:33:59 +00:00
|
|
|
/*
|
8338411: Implement JEP 486: Permanently Disable the Security Manager
Co-authored-by: Sean Mullan <mullan@openjdk.org>
Co-authored-by: Alan Bateman <alanb@openjdk.org>
Co-authored-by: Weijun Wang <weijun@openjdk.org>
Co-authored-by: Aleksei Efimov <aefimov@openjdk.org>
Co-authored-by: Brian Burkhalter <bpb@openjdk.org>
Co-authored-by: Daniel Fuchs <dfuchs@openjdk.org>
Co-authored-by: Harshitha Onkar <honkar@openjdk.org>
Co-authored-by: Joe Wang <joehw@openjdk.org>
Co-authored-by: Jorn Vernee <jvernee@openjdk.org>
Co-authored-by: Justin Lu <jlu@openjdk.org>
Co-authored-by: Kevin Walls <kevinw@openjdk.org>
Co-authored-by: Lance Andersen <lancea@openjdk.org>
Co-authored-by: Naoto Sato <naoto@openjdk.org>
Co-authored-by: Roger Riggs <rriggs@openjdk.org>
Co-authored-by: Brent Christian <bchristi@openjdk.org>
Co-authored-by: Stuart Marks <smarks@openjdk.org>
Co-authored-by: Ian Graves <igraves@openjdk.org>
Co-authored-by: Phil Race <prr@openjdk.org>
Co-authored-by: Erik Gahlin <egahlin@openjdk.org>
Co-authored-by: Jaikiran Pai <jpai@openjdk.org>
Reviewed-by: kevinw, aivanov, rriggs, lancea, coffeys, dfuchs, ihse, erikj, cjplummer, coleenp, naoto, mchung, prr, weijun, joehw, azvegint, psadhukhan, bchristi, sundar, attila
2024-11-12 17:16:15 +00:00
|
|
|
* Copyright (c) 2018, 2024, Oracle and/or its affiliates. All rights reserved.
|
2018-11-12 16:33:59 +00:00
|
|
|
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
|
|
|
|
*
|
|
|
|
* This code is free software; you can redistribute it and/or modify it
|
|
|
|
* under the terms of the GNU General Public License version 2 only, as
|
2023-09-12 20:16:05 +00:00
|
|
|
* published by the Free Software Foundation.
|
2018-11-12 16:33:59 +00:00
|
|
|
*
|
|
|
|
* This code is distributed in the hope that it will be useful, but WITHOUT
|
|
|
|
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
|
|
|
|
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
|
|
|
* version 2 for more details (a copy is included in the LICENSE file that
|
|
|
|
* accompanied this code).
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License version
|
|
|
|
* 2 along with this work; if not, write to the Free Software Foundation,
|
|
|
|
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
|
|
|
|
*
|
|
|
|
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
|
|
|
|
* or visit www.oracle.com if you need additional information or have any
|
|
|
|
* questions.
|
|
|
|
*/
|
|
|
|
|
|
|
|
import java.io.File;
|
|
|
|
import java.io.FileOutputStream;
|
|
|
|
import java.io.IOException;
|
|
|
|
import java.security.Permission;
|
2020-05-08 10:23:37 +00:00
|
|
|
import java.util.HashSet;
|
2018-11-12 16:33:59 +00:00
|
|
|
import java.util.Hashtable;
|
2020-05-08 10:23:37 +00:00
|
|
|
import java.util.Random;
|
|
|
|
import java.util.Set;
|
2018-11-12 16:33:59 +00:00
|
|
|
import java.util.concurrent.Callable;
|
2020-05-08 10:23:37 +00:00
|
|
|
import java.util.concurrent.ExecutionException;
|
2018-11-12 16:33:59 +00:00
|
|
|
import java.util.concurrent.FutureTask;
|
|
|
|
|
|
|
|
import javax.naming.Context;
|
|
|
|
import javax.naming.InitialContext;
|
|
|
|
import javax.naming.NamingException;
|
|
|
|
import javax.naming.directory.InitialDirContext;
|
|
|
|
import javax.naming.directory.SearchControls;
|
|
|
|
|
2020-05-08 10:23:37 +00:00
|
|
|
import sun.net.PortConfig;
|
|
|
|
|
|
|
|
import jdk.test.lib.RandomFactory;
|
|
|
|
|
2018-11-12 16:33:59 +00:00
|
|
|
/**
|
|
|
|
* @test
|
|
|
|
* @bug 8160768
|
2020-05-08 10:23:37 +00:00
|
|
|
* @key randomness intermittent
|
|
|
|
* @summary ctx provider tests for ldap.
|
|
|
|
* Two test cases need to establish connection to the
|
|
|
|
* unreachable port on localhost. Each tries 5 connection
|
|
|
|
* attempts with a random port expecting for connection to fail.
|
|
|
|
* In rare cases it could establish connections due to services
|
|
|
|
* running on these ports, therefore it can fail intermittently.
|
|
|
|
* @modules java.naming/com.sun.jndi.ldap java.base/sun.net
|
|
|
|
* @library /test/lib
|
|
|
|
* @build jdk.test.lib.RandomFactory
|
2018-11-12 16:33:59 +00:00
|
|
|
* @compile dnsprovider/TestDnsProvider.java
|
|
|
|
* @run main/othervm LdapDnsProviderTest
|
8338411: Implement JEP 486: Permanently Disable the Security Manager
Co-authored-by: Sean Mullan <mullan@openjdk.org>
Co-authored-by: Alan Bateman <alanb@openjdk.org>
Co-authored-by: Weijun Wang <weijun@openjdk.org>
Co-authored-by: Aleksei Efimov <aefimov@openjdk.org>
Co-authored-by: Brian Burkhalter <bpb@openjdk.org>
Co-authored-by: Daniel Fuchs <dfuchs@openjdk.org>
Co-authored-by: Harshitha Onkar <honkar@openjdk.org>
Co-authored-by: Joe Wang <joehw@openjdk.org>
Co-authored-by: Jorn Vernee <jvernee@openjdk.org>
Co-authored-by: Justin Lu <jlu@openjdk.org>
Co-authored-by: Kevin Walls <kevinw@openjdk.org>
Co-authored-by: Lance Andersen <lancea@openjdk.org>
Co-authored-by: Naoto Sato <naoto@openjdk.org>
Co-authored-by: Roger Riggs <rriggs@openjdk.org>
Co-authored-by: Brent Christian <bchristi@openjdk.org>
Co-authored-by: Stuart Marks <smarks@openjdk.org>
Co-authored-by: Ian Graves <igraves@openjdk.org>
Co-authored-by: Phil Race <prr@openjdk.org>
Co-authored-by: Erik Gahlin <egahlin@openjdk.org>
Co-authored-by: Jaikiran Pai <jpai@openjdk.org>
Reviewed-by: kevinw, aivanov, rriggs, lancea, coffeys, dfuchs, ihse, erikj, cjplummer, coleenp, naoto, mchung, prr, weijun, joehw, azvegint, psadhukhan, bchristi, sundar, attila
2024-11-12 17:16:15 +00:00
|
|
|
* @run main/othervm LdapDnsProviderTest serviceloader
|
|
|
|
* @run main/othervm LdapDnsProviderTest missingprovider
|
2018-11-12 16:33:59 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
|
|
|
|
class ProviderTest implements Callable<Boolean> {
|
|
|
|
|
|
|
|
private final String url;
|
|
|
|
private final String expected;
|
|
|
|
private final Hashtable<String, String> env = new Hashtable<>(11);
|
|
|
|
|
|
|
|
public ProviderTest(String url, String expected) {
|
|
|
|
this.url = url;
|
|
|
|
this.expected = expected;
|
|
|
|
env.put(Context.INITIAL_CONTEXT_FACTORY, "com.sun.jndi.ldap.LdapCtxFactory");
|
|
|
|
}
|
|
|
|
|
|
|
|
boolean shutItDown(InitialContext ctx) {
|
|
|
|
try {
|
|
|
|
if (ctx != null) ctx.close();
|
|
|
|
return true;
|
|
|
|
} catch (NamingException ex) {
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
public Boolean call() {
|
|
|
|
boolean passed;
|
|
|
|
InitialContext ctx = null;
|
|
|
|
|
|
|
|
if (url != null) {
|
|
|
|
env.put(Context.PROVIDER_URL, url);
|
|
|
|
}
|
|
|
|
|
2020-08-12 11:01:52 +00:00
|
|
|
// Set JNDI LDAP connect timeout property. It helps to prevent
|
|
|
|
// initial bind operation from blocking in case of a local process
|
|
|
|
// listening on the port specified in the URL. With the property set,
|
|
|
|
// the bind operation will fail with timeout exception, and then it
|
|
|
|
// could be retried with another port number.
|
|
|
|
env.put("com.sun.jndi.ldap.connect.timeout", "1000");
|
|
|
|
|
2018-11-12 16:33:59 +00:00
|
|
|
try {
|
|
|
|
ctx = new InitialDirContext(env);
|
|
|
|
SearchControls scl = new SearchControls();
|
|
|
|
scl.setSearchScope(SearchControls.SUBTREE_SCOPE);
|
|
|
|
((InitialDirContext)ctx).search(
|
|
|
|
"ou=People,o=Test", "(objectClass=*)", scl);
|
|
|
|
throw new RuntimeException("Search should not complete");
|
|
|
|
} catch (NamingException e) {
|
|
|
|
passed = e.toString().contains(expected);
|
2020-08-12 11:01:52 +00:00
|
|
|
System.err.println((passed ? "Expected" : "Unexpected") +
|
|
|
|
" NamingException observed: " + e.toString());
|
|
|
|
// Print stack trace only for unexpected exceptions
|
|
|
|
if (!passed) {
|
|
|
|
e.printStackTrace();
|
|
|
|
}
|
2018-11-12 16:33:59 +00:00
|
|
|
} finally {
|
|
|
|
shutItDown(ctx);
|
|
|
|
}
|
|
|
|
return passed;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
public class LdapDnsProviderTest {
|
|
|
|
|
|
|
|
private static final String TEST_CLASSES =
|
|
|
|
System.getProperty("test.classes", ".");
|
|
|
|
|
|
|
|
public static void writeFile(String content, File dstFile)
|
|
|
|
throws IOException
|
|
|
|
{
|
|
|
|
try (FileOutputStream dst = new FileOutputStream(dstFile)) {
|
|
|
|
byte[] buf = content.getBytes();
|
|
|
|
dst.write(buf, 0, buf.length);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
public static void installServiceConfigurationFile(String content) {
|
|
|
|
String filename = "javax.naming.ldap.spi.LdapDnsProvider";
|
|
|
|
|
|
|
|
File dstDir = new File(TEST_CLASSES, "META-INF/services");
|
|
|
|
if (!dstDir.exists()) {
|
|
|
|
if (!dstDir.mkdirs()) {
|
|
|
|
throw new RuntimeException(
|
|
|
|
"could not create META-INF/services directory " + dstDir);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
File dstFile = new File(dstDir, filename);
|
|
|
|
|
|
|
|
try {
|
|
|
|
writeFile(content, dstFile);
|
|
|
|
} catch (IOException e) {
|
|
|
|
throw new RuntimeException("could not install " + dstFile, e);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
public static void main(String[] args) throws Exception {
|
8338411: Implement JEP 486: Permanently Disable the Security Manager
Co-authored-by: Sean Mullan <mullan@openjdk.org>
Co-authored-by: Alan Bateman <alanb@openjdk.org>
Co-authored-by: Weijun Wang <weijun@openjdk.org>
Co-authored-by: Aleksei Efimov <aefimov@openjdk.org>
Co-authored-by: Brian Burkhalter <bpb@openjdk.org>
Co-authored-by: Daniel Fuchs <dfuchs@openjdk.org>
Co-authored-by: Harshitha Onkar <honkar@openjdk.org>
Co-authored-by: Joe Wang <joehw@openjdk.org>
Co-authored-by: Jorn Vernee <jvernee@openjdk.org>
Co-authored-by: Justin Lu <jlu@openjdk.org>
Co-authored-by: Kevin Walls <kevinw@openjdk.org>
Co-authored-by: Lance Andersen <lancea@openjdk.org>
Co-authored-by: Naoto Sato <naoto@openjdk.org>
Co-authored-by: Roger Riggs <rriggs@openjdk.org>
Co-authored-by: Brent Christian <bchristi@openjdk.org>
Co-authored-by: Stuart Marks <smarks@openjdk.org>
Co-authored-by: Ian Graves <igraves@openjdk.org>
Co-authored-by: Phil Race <prr@openjdk.org>
Co-authored-by: Erik Gahlin <egahlin@openjdk.org>
Co-authored-by: Jaikiran Pai <jpai@openjdk.org>
Reviewed-by: kevinw, aivanov, rriggs, lancea, coffeys, dfuchs, ihse, erikj, cjplummer, coleenp, naoto, mchung, prr, weijun, joehw, azvegint, psadhukhan, bchristi, sundar, attila
2024-11-12 17:16:15 +00:00
|
|
|
if (args.length > 0 && args[0].equals("serviceloader")) {
|
|
|
|
// service loader
|
|
|
|
// TestDnsProvider
|
2018-11-12 16:33:59 +00:00
|
|
|
installServiceConfigurationFile("dnsprovider.TestDnsProvider");
|
|
|
|
runTest("ldap:///dc=example,dc=com", "yupyupyup:389");
|
8338411: Implement JEP 486: Permanently Disable the Security Manager
Co-authored-by: Sean Mullan <mullan@openjdk.org>
Co-authored-by: Alan Bateman <alanb@openjdk.org>
Co-authored-by: Weijun Wang <weijun@openjdk.org>
Co-authored-by: Aleksei Efimov <aefimov@openjdk.org>
Co-authored-by: Brian Burkhalter <bpb@openjdk.org>
Co-authored-by: Daniel Fuchs <dfuchs@openjdk.org>
Co-authored-by: Harshitha Onkar <honkar@openjdk.org>
Co-authored-by: Joe Wang <joehw@openjdk.org>
Co-authored-by: Jorn Vernee <jvernee@openjdk.org>
Co-authored-by: Justin Lu <jlu@openjdk.org>
Co-authored-by: Kevin Walls <kevinw@openjdk.org>
Co-authored-by: Lance Andersen <lancea@openjdk.org>
Co-authored-by: Naoto Sato <naoto@openjdk.org>
Co-authored-by: Roger Riggs <rriggs@openjdk.org>
Co-authored-by: Brent Christian <bchristi@openjdk.org>
Co-authored-by: Stuart Marks <smarks@openjdk.org>
Co-authored-by: Ian Graves <igraves@openjdk.org>
Co-authored-by: Phil Race <prr@openjdk.org>
Co-authored-by: Erik Gahlin <egahlin@openjdk.org>
Co-authored-by: Jaikiran Pai <jpai@openjdk.org>
Reviewed-by: kevinw, aivanov, rriggs, lancea, coffeys, dfuchs, ihse, erikj, cjplummer, coleenp, naoto, mchung, prr, weijun, joehw, azvegint, psadhukhan, bchristi, sundar, attila
2024-11-12 17:16:15 +00:00
|
|
|
} else if (args.length > 0 && args[0].equals("missingprovider")) {
|
|
|
|
// no service loader
|
|
|
|
// MissingDnsProvider
|
2018-11-12 16:33:59 +00:00
|
|
|
installServiceConfigurationFile("dnsprovider.MissingDnsProvider");
|
|
|
|
runTest("ldap:///dc=example,dc=com", "not found");
|
|
|
|
} else {
|
8338411: Implement JEP 486: Permanently Disable the Security Manager
Co-authored-by: Sean Mullan <mullan@openjdk.org>
Co-authored-by: Alan Bateman <alanb@openjdk.org>
Co-authored-by: Weijun Wang <weijun@openjdk.org>
Co-authored-by: Aleksei Efimov <aefimov@openjdk.org>
Co-authored-by: Brian Burkhalter <bpb@openjdk.org>
Co-authored-by: Daniel Fuchs <dfuchs@openjdk.org>
Co-authored-by: Harshitha Onkar <honkar@openjdk.org>
Co-authored-by: Joe Wang <joehw@openjdk.org>
Co-authored-by: Jorn Vernee <jvernee@openjdk.org>
Co-authored-by: Justin Lu <jlu@openjdk.org>
Co-authored-by: Kevin Walls <kevinw@openjdk.org>
Co-authored-by: Lance Andersen <lancea@openjdk.org>
Co-authored-by: Naoto Sato <naoto@openjdk.org>
Co-authored-by: Roger Riggs <rriggs@openjdk.org>
Co-authored-by: Brent Christian <bchristi@openjdk.org>
Co-authored-by: Stuart Marks <smarks@openjdk.org>
Co-authored-by: Ian Graves <igraves@openjdk.org>
Co-authored-by: Phil Race <prr@openjdk.org>
Co-authored-by: Erik Gahlin <egahlin@openjdk.org>
Co-authored-by: Jaikiran Pai <jpai@openjdk.org>
Reviewed-by: kevinw, aivanov, rriggs, lancea, coffeys, dfuchs, ihse, erikj, cjplummer, coleenp, naoto, mchung, prr, weijun, joehw, azvegint, psadhukhan, bchristi, sundar, attila
2024-11-12 17:16:15 +00:00
|
|
|
// no service loader
|
2018-11-12 16:33:59 +00:00
|
|
|
// DefaultLdapDnsProvider
|
|
|
|
System.err.println("TEST_CLASSES:");
|
|
|
|
System.err.println(TEST_CLASSES);
|
|
|
|
File f = new File(
|
|
|
|
TEST_CLASSES, "META-INF/services/javax.naming.ldap.spi.LdapDnsProvider");
|
|
|
|
if (f.exists()) {
|
|
|
|
f.delete();
|
|
|
|
}
|
|
|
|
|
|
|
|
runTest("ldap:///dc=example,dc=com", "localhost:389");
|
|
|
|
runTest("ldap://localhost/dc=example,dc=com", "localhost:389");
|
2020-05-08 10:23:37 +00:00
|
|
|
runLocalHostTestWithRandomPort("ldap", "/dc=example,dc=com", 5);
|
|
|
|
runLocalHostTestWithRandomPort("ldaps", "/dc=example,dc=com", 5);
|
2018-11-12 16:33:59 +00:00
|
|
|
runTest("ldaps://localhost/dc=example,dc=com", "localhost:636");
|
|
|
|
runTest(null, "localhost:389");
|
|
|
|
runTest("", "ConfigurationException");
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-05-08 10:23:37 +00:00
|
|
|
// Pseudorandom number generator
|
|
|
|
private static final Random RND = RandomFactory.getRandom();
|
|
|
|
// Port numbers already seen to be generated by pseudorandom generator
|
|
|
|
private static final Set<Integer> SEEN_PORTS = new HashSet<>();
|
|
|
|
|
|
|
|
// Get random, previously unseen port number from [1111, PortConfig.getUpper()) range
|
|
|
|
private static int generateUnseenPort() {
|
|
|
|
int port;
|
|
|
|
do {
|
|
|
|
port = 1111 + RND.nextInt(PortConfig.getUpper() - 1111);
|
|
|
|
// Seen ports will never contain more than maxAttempts*2 ports
|
|
|
|
} while (SEEN_PORTS.contains(port));
|
|
|
|
SEEN_PORTS.add(port);
|
|
|
|
return port;
|
|
|
|
}
|
|
|
|
|
|
|
|
// Run test with ldap connection to localhost and random port. The test is expected to fail
|
|
|
|
// with CommunicationException that is caused by connection refuse exception.
|
|
|
|
// But in case if there is a service running on the same port the connection
|
|
|
|
// will be established and then closed or timed-out. Both cases will generate exception
|
|
|
|
// messages which differ from the expected one.
|
|
|
|
// For such cases the test will be repeated with another random port. That will be done
|
|
|
|
// maxAttempts times. If the expected exception won't be observed - test will be treated
|
|
|
|
// as failed.
|
|
|
|
private static void runLocalHostTestWithRandomPort(String scheme, String path, int maxAttempts) {
|
|
|
|
for (int attempt = 0; attempt <= maxAttempts; attempt++) {
|
|
|
|
boolean attemptSuccessful = true;
|
|
|
|
int port = generateUnseenPort();
|
|
|
|
|
|
|
|
// Construct URL for the current attempt
|
|
|
|
String url = scheme + "://localhost" + ":" + port + path;
|
|
|
|
|
|
|
|
// Construct text expected to be present in Exception message
|
|
|
|
String expected = "localhost:" + port;
|
|
|
|
|
2020-08-12 11:01:52 +00:00
|
|
|
System.err.printf("Iteration %d: Testing: url='%s', expected content='%s'%n",
|
|
|
|
attempt, url, expected);
|
2020-05-08 10:23:37 +00:00
|
|
|
|
|
|
|
FutureTask<Boolean> future = new FutureTask<>(
|
|
|
|
new ProviderTest(url, expected));
|
|
|
|
new Thread(future).start();
|
|
|
|
while (!future.isDone()) {
|
|
|
|
try {
|
|
|
|
if (!future.get()) {
|
|
|
|
if (attempt == maxAttempts) {
|
|
|
|
throw new RuntimeException("Test failed, ProviderTest" +
|
|
|
|
" returned false " + maxAttempts + " times");
|
|
|
|
} else {
|
|
|
|
System.err.printf("Iteration %d failed:" +
|
|
|
|
" ProviderTest returned false%n", attempt);
|
|
|
|
attemptSuccessful = false;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
} catch (InterruptedException | ExecutionException e) {
|
|
|
|
System.err.println("Iteration %d failed to execute provider test: " + e.getMessage());
|
|
|
|
attemptSuccessful = false;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if (attemptSuccessful) {
|
|
|
|
System.err.println("Test passed. It took " + (attempt + 1) + " iterations to complete");
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-11-12 16:33:59 +00:00
|
|
|
private static void runTest(String url, String expected) {
|
|
|
|
FutureTask<Boolean> future =
|
|
|
|
new FutureTask<>(
|
|
|
|
new ProviderTest(url, expected));
|
|
|
|
new Thread(future).start();
|
|
|
|
|
2020-08-12 11:01:52 +00:00
|
|
|
System.err.printf("Testing: url='%s', expected content='%s'%n", url, expected);
|
2018-11-12 16:33:59 +00:00
|
|
|
while (!future.isDone()) {
|
|
|
|
try {
|
|
|
|
if (!future.get()) {
|
|
|
|
System.err.println("Test failed");
|
|
|
|
throw new RuntimeException(
|
|
|
|
"Test failed, ProviderTest returned false");
|
|
|
|
}
|
|
|
|
} catch (Exception e) {
|
|
|
|
if (!e.toString().contains(expected)) {
|
|
|
|
System.err.println("Test failed");
|
|
|
|
throw new RuntimeException(
|
|
|
|
"Test failed, unexpected result");
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
System.err.println("Test passed");
|
|
|
|
}
|
|
|
|
|
|
|
|
}
|
|
|
|
|