Skip to content

2.0.63.android8: port security fixes from main - #7711

Merged
wenshao merged 7 commits into
android8from
release/2.0.63.android8
Jul 30, 2026
Merged

2.0.63.android8: port security fixes from main#7711
wenshao merged 7 commits into
android8from
release/2.0.63.android8

Conversation

@wenshao

@wenshao wenshao commented Jul 29, 2026

Copy link
Copy Markdown
Member

Port 2.0.63 安全修复到 android8 分支(手工适配 cherry-pick):

未 port:bdfe92f76 readString AIOOBE —— 本分支无 strBuf 缓存机制,bug 不存在。

验证:core 全量测试 5149 个全绿(含新增 AutoTypeValidationTest 27 个、Issue7668/7669/7678/1591)。

wenshao and others added 7 commits July 29, 2026 13:43
…StringValueAsString enabled, for issue #1591

(cherry picked from commit f15dc36, manually applied)

Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
(cherry picked from commit d7ad403, manually applied)

Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
(cherry picked from commit 1357fdc, manually applied)

Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
…ion (#7703)

- Reject type names containing URL-special characters (: and !)
- Text verification after whitelist hash match (acceptNameSet)
- ClassLoader/DataSource/RowSet deny check on accept prefix match

isAutoTypeDenyClass lives in TypeUtils (not JDKUtils) since this branch
has no reflective SQL handles and already links javax.sql directly.

(cherry picked from commit ec47e24, manually applied)

Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
Add bounds checks at 3 BC_BINARY allocation sites; extract checkBigintLen
helper for the BC_BIGINT checks (mirrors main refactor).

(cherry picked from commit 373cbe7, manually applied)

Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
(cherry picked from commit 01eab36, manually applied)

Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
@wenshao
wenshao merged commit 186e6e2 into android8 Jul 30, 2026
1 of 10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant