changeset 47310:eca11f20586e

8186654: Poor quality of sun.security.util.Cache.EqualByteArray.hashCode() Reviewed-by: coffeys
author igerasim
date Wed, 04 Oct 2017 01:08:36 -0700
parents 66774e1fc3a7
children ff631a3cadbc
files src/java.base/share/classes/sun/security/util/Cache.java test/jdk/sun/security/util/Cache/EbaHash.java
diffstat 2 files changed, 47 insertions(+), 7 deletions(-) [+]
line wrap: on
line diff
--- a/src/java.base/share/classes/sun/security/util/Cache.java	Tue Oct 03 23:42:08 2017 -0700
+++ b/src/java.base/share/classes/sun/security/util/Cache.java	Wed Oct 04 01:08:36 2017 -0700
@@ -164,7 +164,7 @@
     public static class EqualByteArray {
 
         private final byte[] b;
-        private volatile int hash;
+        private int hash;
 
         public EqualByteArray(byte[] b) {
             this.b = b;
@@ -172,12 +172,8 @@
 
         public int hashCode() {
             int h = hash;
-            if (h == 0) {
-                h = b.length + 1;
-                for (int i = 0; i < b.length; i++) {
-                    h += (b[i] & 0xff) * 37;
-                }
-                hash = h;
+            if (h == 0 && b.length > 0) {
+                hash = h = Arrays.hashCode(b);
             }
             return h;
         }
--- /dev/null	Thu Jan 01 00:00:00 1970 +0000
+++ b/test/jdk/sun/security/util/Cache/EbaHash.java	Wed Oct 04 01:08:36 2017 -0700
@@ -0,0 +1,44 @@
+/*
+ * Copyright (c) 2017, Oracle and/or its affiliates. All rights reserved.
+ * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
+ *
+ * This code is free software; you can redistribute it and/or modify it
+ * under the terms of the GNU General Public License version 2 only, as
+ * published by the Free Software Foundation.
+ *
+ * This code is distributed in the hope that it will be useful, but WITHOUT
+ * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
+ * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
+ * version 2 for more details (a copy is included in the LICENSE file that
+ * accompanied this code).
+ *
+ * You should have received a copy of the GNU General Public License version
+ * 2 along with this work; if not, write to the Free Software Foundation,
+ * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+ *
+ * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
+ * or visit www.oracle.com if you need additional information or have any
+ * questions.
+ */
+
+/*
+ * @test
+ * @bug 8186654
+ * @summary Transpositions of an array result in the same
+ *          EqualByteArray.hashCode()
+ * @modules java.base/sun.security.util
+ */
+
+import sun.security.util.Cache;
+
+public class EbaHash {
+    public static void main(String[] args) throws Throwable {
+        int h1 = new Cache.EqualByteArray(new byte[] {1,2,3}).hashCode();
+        int h2 = new Cache.EqualByteArray(new byte[] {2,3,1}).hashCode();
+        int h3 = new Cache.EqualByteArray(new byte[] {3,1,2}).hashCode();
+        if (h1 == h2 && h2 == h3) {
+            throw new RuntimeException("Transpositions of an array" +
+                " resulted in the same hashCode()");
+        }
+    }
+}