REF-32: Replace the JAXB runtime and reject document type declarations in OIOBPP - #99
Merged
Merged
Conversation
…s in OIOBPP OIOBPPUtil.parse returned null for every privilege list, and had done so on any JDK 16 or later: com.sun.xml.bind 2.3.0 generates accessors by reflecting into ClassLoader.defineClass, which those JDKs refuse, and the resulting exception is swallowed by the catch in parse. Privileges from the assertion were silently dropped, and OIOBPPUtilTest was the visible symptom. Replace com.sun.xml.bind jaxb-core and jaxb-impl 2.3.0 with the reference implementation under its current coordinates, org.glassfish.jaxb:jaxb-runtime 2.3.9, and move jaxb-api to 2.3.1. This stays on the javax.xml.bind API and the artifact is still Java 8 bytecode. The parser also accepted a document type declaration, so a short privilege list could expand into a very large document while being parsed. External entities were already turned off, which does not cover entities declared inside the document. disallow-doctype-decl and FEATURE_SECURE_PROCESSING are now set. The privilege list is taken from an assertion whose signature has already been validated, so both of these are behind an authenticated boundary. Tested with a privilege list carrying a document type declaration, which is now refused. The whole suite passes for the first time, 113 tests without failures.
mthiim
approved these changes
Aug 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes OIO Basic Privilege Profile parsing, which has been returning nothing on recent JDKs, and hardens the parser.
Problem
OIOBPPUtil.parsereturnednullfor every privilege list on JDK 16 and later.com.sun.xml.bind2.3.0 generates accessors by reflecting intoClassLoader.defineClass, which those JDKs refuse:parsecatches the exception and logs a warning, so privileges carried in an assertion were silently dropped and callers simply saw none.OIOBPPUtilTestfailing onmasterwas the visible symptom of that, not a test problem.Separately, the parser accepted a document type declaration. External entities were already turned off, which does not cover entities declared inside the document, so a short privilege list could expand into a very large document while being parsed.
Changes
com.sun.xml.bind:jaxb-coreandjaxb-impl2.3.0 with the reference implementation under its current coordinates,org.glassfish.jaxb:jaxb-runtime2.3.9, and movejavax.xml.bind:jaxb-apito 2.3.1. This stays on thejavax.xml.bindAPI, no jakarta migration, and the new artifact is still Java 8 bytecode (major version 52).disallow-doctype-declandFEATURE_SECURE_PROCESSINGon the SAX parser factory, alongside the external entity features already there.The privilege list comes from an assertion whose signature has already been validated, so both of these sit behind an authenticated boundary.
Verification
mvn -pl oiosaml test→ 113 tests, 0 failures. This is the first fully green run;OIOBPPUtilTesthad been failing onmasteron this JDK.The new test parses a privilege list carrying a document type declaration with nested entities and expects it to be refused. With
OIOBPPUtilreverted it fails.Note for release
Consumers running the current release on JDK 16 or later get no privileges out of
OIOBPPUtil, without an error at the call site. Worth calling out inRELEASE_NOTES.md.