[#726] Reject malformed bracketed IPv6 hosts in HostPort - #732
Merged
vharseko merged 1 commit intoJul 12, 2026
Merged
Conversation
…rm#726) An ACI such as (version 3.0; acl "f"; allow (search) userdn="q://[:1"; ) crashed Aci.decode with StringIndexOutOfBoundsException: removeExtraChars assumed any host containing '[' was a well-formed "[IPv6]" literal and blindly stripped the first and last characters. Validate the bracket syntax instead: throw IllegalArgumentException for hosts that start or end with a bracket without forming "[...]", detect "[host" without "]:" already in HostPort.valueOf, and guard valueOf against empty input. LDAPURL.decode already converts the IAE to a DirectoryException, so ACI decoding now fails with the expected AciException.
maximthomas
approved these changes
Jul 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #726.
Problem
Decoding an ACI with a malformed IPv6 host inside
userdncrashed with a rawStringIndexOutOfBoundsExceptioninstead of the expectedAciException:HostPort.removeExtraCharsassumed that any host containing[is a well-formed bracketed IPv6 literal and blindly stripped the first and last characters, so the host"["blew up onsubstring(1, 0). Other malformed inputs ("[x","ab[cd") were silently mangled instead of rejected.Fix
HostPort.removeExtraCharsnow validates the bracket syntax: hosts without brackets pass through unchanged,[...]with non-empty content gets the brackets stripped, and anything else that starts or ends with a bracket throwsIllegalArgumentException.HostPort.valueOfdetects a string starting with[that is not of the form[...]:port/[...]right away (previously this check only fired when the string contained more than one colon), and rejects empty input (which also used to throwStringIndexOutOfBoundsExceptiononcharAt(0)).LDAPURL.decodealready convertsIllegalArgumentExceptioninto aDirectoryException, whichUserDN.decodewraps intoAciException— so ACI decoding now fails cleanly, as expected in the issue, with no changes needed in the upper layers.Tests
HostPortTest: 10 new cases — both crashing inputs from the issue (valueOf("[:1"),new HostPort("[", 1)), missing opening/closing brackets, empty brackets, empty string, plus a positive control for a valid bracketed IPv6 host.UserDNTestCase: the ACI from the issue and anldap://[::1:389/...variant must fail withAciException; a well-formedldap://[::1]:389/...must still decode.Verified that the regression test reproduces the original failure: on the unfixed code it fails with
StringIndexOutOfBoundsException: Range [1, 0) out of bounds for length 1. With the fix,HostPortTest+UserDNTestCase(42/42) andLDAPURLTest+LDAPURLTestCase(37/37) are green.