]
Ilia Vassilev updated ELY-946:
------------------------------
Fix Version/s: 1.1.0.Beta25
Coverity static analysis, suspicious bitwise logical expression,
DigestUtil (Elytron)
-------------------------------------------------------------------------------------
Key: ELY-946
URL:
https://issues.jboss.org/browse/ELY-946
Project: WildFly Elytron
Issue Type: Bug
Components: SASL
Reporter: Martin Choma
Assignee: Ilia Vassilev
Priority: Critical
Fix For: 1.1.0.Beta25
Coverity found suspicious logical operation
https://scan7.coverity.com/reports.htm#v23632/p11778/fileInstanceId=95638...
See detailed description of possible problem in [1]
If I extend DigestUtilTest#testDecodeByteOrderedInteger with case from [1], test fails
{code}
byte[] inputFF =
CodePointIterator.ofString("000000FF").hexDecode().drain();
assertEquals(0xFF, decodeByteOrderedInteger(inputFF, 0, 4));
{code}
If I change decodeByteOrderedInteger implementation according to [1], all tests passes.
{code}
result |= (buf[offset + i] & 0xff);
{code}
[1]
http://findbugs.sourceforge.net/bugDescriptions.html#BIT_IOR_OF_SIGNED_BYTE
Setting to high priority, because correct behavior of SASL Digest mechanism could be
impacted.