Skip to content

REF-32: Replace the JAXB runtime and reject document type declarations in OIOBPP - #99

Merged
thomasnymand merged 1 commit into
masterfrom
feature/REF-32-oiobpp-parsing
Aug 26, 2026
Merged

thomasnymand merged 1 commit into
masterfrom
feature/REF-32-oiobpp-parsing

Conversation

@thomasnymand

Copy link
Copy Markdown
Collaborator

Fixes OIO Basic Privilege Profile parsing, which has been returning nothing on recent JDKs, and hardens the parser.

Problem

OIOBPPUtil.parse returned null for every privilege list on JDK 16 and later. com.sun.xml.bind 2.3.0 generates accessors by reflecting into ClassLoader.defineClass, which those JDKs refuse:

NullPointerException: Cannot invoke "java.lang.reflect.Method.invoke(Object, Object[])"
because "com.sun.xml.bind.v2.runtime.reflect.opt.Injector.defineClass" is null

parse catches the exception and logs a warning, so privileges carried in an assertion were silently dropped and callers simply saw none. OIOBPPUtilTest failing on master was the visible symptom of that, not a test problem.

Separately, the parser accepted a document type declaration. External entities were already turned off, which does not cover entities declared inside the document, so a short privilege list could expand into a very large document while being parsed.

Changes

  • Replace com.sun.xml.bind:jaxb-core and jaxb-impl 2.3.0 with the reference implementation under its current coordinates, org.glassfish.jaxb:jaxb-runtime 2.3.9, and move javax.xml.bind:jaxb-api to 2.3.1. This stays on the javax.xml.bind API, no jakarta migration, and the new artifact is still Java 8 bytecode (major version 52).
  • Set disallow-doctype-decl and FEATURE_SECURE_PROCESSING on the SAX parser factory, alongside the external entity features already there.

The privilege list comes from an assertion whose signature has already been validated, so both of these sit behind an authenticated boundary.

Verification

mvn -pl oiosaml test → 113 tests, 0 failures. This is the first fully green run; OIOBPPUtilTest had been failing on master on this JDK.

The new test parses a privilege list carrying a document type declaration with nested entities and expects it to be refused. With OIOBPPUtil reverted it fails.

Note for release

Consumers running the current release on JDK 16 or later get no privileges out of OIOBPPUtil, without an error at the call site. Worth calling out in RELEASE_NOTES.md.

…s in OIOBPP

OIOBPPUtil.parse returned null for every privilege list, and had done so on any
JDK 16 or later: com.sun.xml.bind 2.3.0 generates accessors by reflecting into
ClassLoader.defineClass, which those JDKs refuse, and the resulting exception is
swallowed by the catch in parse. Privileges from the assertion were silently
dropped, and OIOBPPUtilTest was the visible symptom.

Replace com.sun.xml.bind jaxb-core and jaxb-impl 2.3.0 with the reference
implementation under its current coordinates, org.glassfish.jaxb:jaxb-runtime
2.3.9, and move jaxb-api to 2.3.1. This stays on the javax.xml.bind API and the
artifact is still Java 8 bytecode.

The parser also accepted a document type declaration, so a short privilege list
could expand into a very large document while being parsed. External entities
were already turned off, which does not cover entities declared inside the
document. disallow-doctype-decl and FEATURE_SECURE_PROCESSING are now set.

The privilege list is taken from an assertion whose signature has already been
validated, so both of these are behind an authenticated boundary.

Tested with a privilege list carrying a document type declaration, which is now
refused. The whole suite passes for the first time, 113 tests without failures.
@thomasnymand
thomasnymand merged commit afff4d3 into master Aug 26, 2026
2 checks passed
@thomasnymand
thomasnymand deleted the feature/REF-32-oiobpp-parsing branch August 26, 2026 18:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants