The seven OpenPGP signature subpackets whose body RFC 9580 defines as a fixed length now all enforce that length where the subpacket is parsed rather than deferring it to an accessor, only Signature Expiration Time having done so, since SignatureSubpacketInputStream.readPacket validated a declared body length for range and for the case where it overran the subpacket area but handed a body whose declared length matched the octets it carried to the constructor whatever that length was, so Signature Creation Time and Key Expiration Time reported a body that was not the four octets of a time field, Exportable Certification, Revocable and Primary User ID a body that was not the single zero or one octet of a flag, and Issuer Key ID one shorter than a key ID, as an unchecked IllegalStateException out of org.bouncycastle.bcpg.sig.Utils or an IllegalArgumentException out of FingerprintUtil.readKeyID when the value was read, which matters because such a body inside a self-signature is content the signer signed over, so a certificate carrying one verified as valid and failed only later in ordinary reader code - PGPPublicKey.getValidSeconds(), PGPSignatureSubpacketVector.getKeyExpirationTime() and isExportable(), OpenPGPCertificate.getExpirationTime(), and the keyserver re-export path PGPPublicKeyRing.encode(out, true), which declares IOException - and the length and flag-value checks now sit as shared statics beside the accessors they protect, with Signature Expiration Time's own check folded into them, a malformed subpacket refused at parse time as a MalformedPacketException the way Features, Trust Signature and Notation Data already were, and the parser's tolerance of a fixed-length field whose declared length overruns the subpacket area preserved, BytesBooleansTest being wired into the openpgp suite it had never been registered in, relates to github #2426.
D
David Hook committed
9eadfc935bf757f3a04050839ca9e4d841a9acf7
Parent: a5e172b