Write signature files to uber jars to for Oracle Java 17 verification
Update Gradle and Maven plugins to write an empty `META-INF/BOOT.SF`
file whenever there is a nested signed jar.
This update allows Oracle Java 17 to correctly verify the nested JARs.
The file is required because `JarVerifier` has code roughly equivalent
to:
if (!jarManifestNameChecked && SharedSecrets
.getJavaUtilZipFileAccess().getManifestName(jf, true) == null) {
throw new JarException("The JCE Provider " + jarURL.toString() +
" is not signed.");
}
The `SharedSecrets.getJavaUtilZipFileAccess().getManifestName(jf, true)`
call ends up in `ZipFile.getManifestName(onlyIfSignatureRelatedFiles)`
which is a private method that we cannot override in our `NestedJarFile`
subclass. By writing an empty `.SF` file we ensure that the `Manifest`
is always returned because there are always "signature related files".
Fixes gh-28837
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2012-2022 the original author or authors.
|
||||
* Copyright 2012-2023 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -18,6 +18,9 @@ package org.springframework.boot.loader.tools;
|
||||
|
||||
import java.io.File;
|
||||
import java.io.IOException;
|
||||
import java.util.jar.Attributes;
|
||||
import java.util.jar.JarFile;
|
||||
import java.util.jar.Manifest;
|
||||
|
||||
/**
|
||||
* Utilities for manipulating files and directories in Spring Boot tooling.
|
||||
@@ -61,4 +64,31 @@ public abstract class FileUtils {
|
||||
return Digest.sha1(InputStreamSupplier.forFile(file));
|
||||
}
|
||||
|
||||
/**
|
||||
* Returns {@code true} if the given jar file has been signed.
|
||||
* @param file the file to check
|
||||
* @return if the file has been signed
|
||||
* @throws IOException on IO error
|
||||
*/
|
||||
public static boolean isSignedJarFile(File file) throws IOException {
|
||||
try (JarFile jarFile = new JarFile(file)) {
|
||||
if (hasDigestEntry(jarFile.getManifest())) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
private static boolean hasDigestEntry(Manifest manifest) {
|
||||
return (manifest != null) && manifest.getEntries().values().stream().anyMatch(FileUtils::hasDigestName);
|
||||
}
|
||||
|
||||
private static boolean hasDigestName(Attributes attributes) {
|
||||
return attributes.keySet().stream().anyMatch(FileUtils::isDigestName);
|
||||
}
|
||||
|
||||
private static boolean isDigestName(Object name) {
|
||||
return String.valueOf(name).toUpperCase().endsWith("-DIGEST");
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -217,6 +217,7 @@ public abstract class Packager {
|
||||
if (isLayered()) {
|
||||
writeLayerIndex(writer);
|
||||
}
|
||||
writeSignatureFileIfNecessary(writtenLibraries, writer);
|
||||
}
|
||||
|
||||
private void writeLoaderClasses(AbstractJarWriter writer) throws IOException {
|
||||
@@ -263,6 +264,10 @@ public abstract class Packager {
|
||||
}
|
||||
}
|
||||
|
||||
protected void writeSignatureFileIfNecessary(Map<String, Library> writtenLibraries, AbstractJarWriter writer)
|
||||
throws IOException {
|
||||
}
|
||||
|
||||
private EntryTransformer getEntityTransformer() {
|
||||
if (getLayout() instanceof RepackagingLayout repackagingLayout) {
|
||||
return new RepackagingEntryTransformer(repackagingLayout);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 2012-2022 the original author or authors.
|
||||
* Copyright 2012-2023 the original author or authors.
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
@@ -19,6 +19,7 @@ package org.springframework.boot.loader.tools;
|
||||
import java.io.File;
|
||||
import java.io.IOException;
|
||||
import java.nio.file.attribute.FileTime;
|
||||
import java.util.Map;
|
||||
import java.util.jar.JarFile;
|
||||
|
||||
import org.springframework.util.Assert;
|
||||
@@ -46,6 +47,24 @@ public class Repackager extends Packager {
|
||||
super(source);
|
||||
}
|
||||
|
||||
@Override
|
||||
protected void writeSignatureFileIfNecessary(Map<String, Library> writtenLibraries, AbstractJarWriter writer)
|
||||
throws IOException {
|
||||
if (getSource().getName().toLowerCase().endsWith(".jar") && hasSignedLibrary(writtenLibraries)) {
|
||||
writer.writeEntry("META-INF/BOOT.SF", (entryWriter) -> {
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
private boolean hasSignedLibrary(Map<String, Library> writtenLibraries) throws IOException {
|
||||
for (Library library : writtenLibraries.values()) {
|
||||
if (!(library instanceof JarModeLibrary) && FileUtils.isSignedJarFile(library.getFile())) {
|
||||
return true;
|
||||
}
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
/**
|
||||
* Sets if source files should be backed up when they would be overwritten.
|
||||
* @param backupSource if source files should be backed up
|
||||
|
||||
@@ -660,7 +660,7 @@ abstract class AbstractPackagerTests<P extends Packager> {
|
||||
return library.getFile();
|
||||
}
|
||||
|
||||
private Library newLibrary(File file, LibraryScope scope, boolean unpackRequired) {
|
||||
protected Library newLibrary(File file, LibraryScope scope, boolean unpackRequired) {
|
||||
return new Library(null, file, scope, null, unpackRequired, false, true);
|
||||
}
|
||||
|
||||
@@ -687,7 +687,7 @@ abstract class AbstractPackagerTests<P extends Packager> {
|
||||
&& hasPackagedEntry("org/springframework/boot/loader/launch/JarLauncher.class");
|
||||
}
|
||||
|
||||
private boolean hasPackagedEntry(String name) throws IOException {
|
||||
protected boolean hasPackagedEntry(String name) throws IOException {
|
||||
return getPackagedEntry(name) != null;
|
||||
}
|
||||
|
||||
|
||||
@@ -17,9 +17,13 @@
|
||||
package org.springframework.boot.loader.tools;
|
||||
|
||||
import java.io.File;
|
||||
import java.io.FileNotFoundException;
|
||||
import java.io.FileOutputStream;
|
||||
import java.io.IOException;
|
||||
import java.io.OutputStream;
|
||||
import java.util.jar.JarOutputStream;
|
||||
import java.util.jar.Manifest;
|
||||
import java.util.zip.ZipEntry;
|
||||
|
||||
import org.junit.jupiter.api.BeforeEach;
|
||||
import org.junit.jupiter.api.Test;
|
||||
@@ -99,4 +103,28 @@ class FileUtilsTests {
|
||||
assertThat(FileUtils.sha1Hash(file)).isEqualTo("7037807198c22a7d2b0807371d763779a84fdfcf");
|
||||
}
|
||||
|
||||
@Test
|
||||
void isSignedJarFileWhenSignedReturnsTrue() throws IOException {
|
||||
Manifest manifest = new Manifest(getClass().getResourceAsStream("signed-manifest.mf"));
|
||||
File jarFile = new File(this.tempDir, "test.jar");
|
||||
writeTestJar(manifest, jarFile);
|
||||
assertThat(FileUtils.isSignedJarFile(jarFile)).isTrue();
|
||||
}
|
||||
|
||||
@Test
|
||||
void isSignedJarFileWhenNotSignedReturnsFalse() throws IOException {
|
||||
Manifest manifest = new Manifest();
|
||||
File jarFile = new File(this.tempDir, "test.jar");
|
||||
writeTestJar(manifest, jarFile);
|
||||
assertThat(FileUtils.isSignedJarFile(jarFile)).isFalse();
|
||||
}
|
||||
|
||||
private void writeTestJar(Manifest manifest, File jarFile) throws IOException, FileNotFoundException {
|
||||
try (JarOutputStream out = new JarOutputStream(new FileOutputStream(jarFile))) {
|
||||
out.putNextEntry(new ZipEntry("META-INF/MANIFEST.MF"));
|
||||
manifest.write(out);
|
||||
out.closeEntry();
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -28,6 +28,7 @@ import java.util.ArrayList;
|
||||
import java.util.Collection;
|
||||
import java.util.Enumeration;
|
||||
import java.util.List;
|
||||
import java.util.jar.Attributes;
|
||||
import java.util.jar.JarEntry;
|
||||
import java.util.jar.JarFile;
|
||||
import java.util.jar.Manifest;
|
||||
@@ -218,6 +219,20 @@ class RepackagerTests extends AbstractPackagerTests<Repackager> {
|
||||
assertThat(stopWatch.getTotalTimeMillis()).isLessThan(5000);
|
||||
}
|
||||
|
||||
@Test
|
||||
void signedJar() throws Exception {
|
||||
Repackager packager = createPackager();
|
||||
packager.setMainClass("a.b.C");
|
||||
Manifest manifest = new Manifest();
|
||||
Attributes attributes = new Attributes();
|
||||
attributes.putValue("SHA1-Digest", "0000");
|
||||
manifest.getEntries().put("a/b/C.class", attributes);
|
||||
TestJarFile libJar = new TestJarFile(this.tempDir);
|
||||
libJar.addManifest(manifest);
|
||||
execute(packager, (callback) -> callback.library(newLibrary(libJar.getFile(), LibraryScope.COMPILE, false)));
|
||||
assertThat(hasPackagedEntry("META-INF/BOOT.SF")).isTrue();
|
||||
}
|
||||
|
||||
private boolean hasLauncherClasses(File file) throws IOException {
|
||||
return hasEntry(file, "org/springframework/boot/")
|
||||
&& hasEntry(file, "org/springframework/boot/loader/launch/JarLauncher.class");
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
Manifest-Version: 1.0
|
||||
Created-By: 1.5.0_08 (Sun Microsystems Inc.)
|
||||
Specification-Version: 1.1
|
||||
|
||||
Name: org/bouncycastle/pqc/legacy/math/linearalgebra/GoppaCode.class
|
||||
SHA-256-Digest: wNhEfeTvNG9ggqKfLjQDDoFoDqeWwGUc47JiL7VqxqU=
|
||||
|
||||
Name: org/bouncycastle/crypto/modes/gcm/Tables8kGCMMultiplier.class
|
||||
SHA-256-Digest: nqljr9DNx4nNie4sbkZajVenvd3LdMF3X5s5dmSMToM=
|
||||
Reference in New Issue
Block a user