8023672: Enhance jar file validation
Summary: Also reviewed by Chris Ries and Alexander Fomin
Reviewed-by: mullan, sherman
--- a/jdk/src/share/classes/java/util/jar/JarVerifier.java Fri Sep 13 15:37:39 2013 +0800
+++ b/jdk/src/share/classes/java/util/jar/JarVerifier.java Fri Sep 13 15:37:43 2013 +0800
@@ -179,7 +179,9 @@
name = name.substring(1);
// only set the jev object for entries that have a signature
- if (sigFileSigners.get(name) != null) {
+ // (either verified or not)
+ if (sigFileSigners.get(name) != null ||
+ verifiedSigners.get(name) != null) {
mev.setEntry(name, je);
return;
}