Sitelet https://github.com/dnsjava/dnsjava/pull/415
Skip to content

Validate SSHFP fingerprint lengths - #415

Merged
ibauersachs merged 3 commits into
dnsjava:masterfrom
Mahmoodifar:fix/sshfp-fingerprint-length
Sep 26, 2026
Merged

ibauersachs merged 3 commits into
dnsjava:masterfrom
Mahmoodifar:fix/sshfp-fingerprint-length

Conversation

@Mahmoodifar

Copy link
Copy Markdown
Contributor

SSHFP records such as 1 1 AABBCCDD currently accept a four-byte SHA-1 fingerprint. Validate the expected 20-byte SHA-1 and 32-byte SHA-256 lengths in the constructor and text parser, following the existing DSRecord behavior. Unknown digest types remain unrestricted.

Fixes #414.

Added regression coverage for valid fingerprints, incorrect lengths, and unknown digest types. All 24 SSHFP tests pass; 18 cases fail without the fix.

Validation on Java 17:

  • mvn -Dtest=SSHFPRecordTest test passed.
  • mvn verify -Dgpg.skip -DexcludedGroups=concurrency ran 1,770 tests with one ResolverTest.resolverListenerExceptionUnwrap timeout failure, also reproduced on clean upstream.
  • mvn verify -DskipTests -Dgpg.skip passed packaging, API compatibility, formatting, and Checkstyle checks.

@codecov

codecov Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 96.15385% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 66.96%. Comparing base (8bed725) to head (e8bbaca).

Files with missing lines Patch % Lines
src/main/java/org/xbill/DNS/SSHFPRecord.java 91.66% 1 Missing ⚠️
Additional details and impacted files
@@             Coverage Diff              @@
##             master     #415      +/-   ##
============================================
- Coverage     66.97%   66.96%   -0.02%     
- Complexity     3085     3096      +11     
============================================
  Files           198      198              
  Lines         13691    13702      +11     
  Branches       2140     2141       +1     
============================================
+ Hits           9170     9175       +5     
- Misses         3941     3948       +7     
+ Partials        580      579       -1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@ibauersachs ibauersachs added this to the v3.6.6 milestone Sep 26, 2026
@ibauersachs
ibauersachs merged commit bb59924 into dnsjava:master Sep 26, 2026
18 checks passed
@ibauersachs

Copy link
Copy Markdown
Member

Thanks!

I added some more tests and shared the digest lengths, as these are used in quite a few places.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Validate SSHFP fingerprint lengths

2 participants