Skip to content

RuleSet's hash map hashes by identity of TrustedOrigin and not by value. RulesSet attempts to add to an immutable list if trustedorigins are equal - #143

Open
saoirse-a wants to merge 4 commits into
eclipse-biscuit:mainfrom
saoirse-a:AK/ruleSet-issue
Open

saoirse-a wants to merge 4 commits into
eclipse-biscuit:mainfrom
saoirse-a:AK/ruleSet-issue

Conversation

@saoirse-a

Copy link
Copy Markdown
Contributor

The ruleset object that world has a reference of is an object that stores a hash map. This hash map is keyed by trustedOrigin and has a value of List(Pair<long, Rule>). Two bugs that mask each other:

  1. List.of(...) creates an immutable list, as a result adding to this list at runtime will cause a runtime crash. RuleSet checks if the key exists and if it doesn't exist it creates a new immutable list, otherwise it attempts to append to the immutable list, which crashes. However the else never gets hit because of point 2.
  2. TrustedOrigin has no override for equals and hashCode, so it defaults to Java default equals and hash, which essentially compares by reference and not by value. Whenever we add a new entry into the List we clone TrustedOrigin TrustedOrigin.fromScopes. since this new trustedOrigin is a different object it is added as a new entry in RuleSet.

saoirse-a and others added 4 commits September 30, 2026 11:49
Signed-off-by: Saoirse Aronson <saoirse@apple.com>
Co-authored-by: Sasha Kobrusev <skobrusev@apple.com>
Signed-off-by: Saoirse Aronson <saoirse@apple.com>
Co-authored-by: Sasha Kobrusev <skobrusev@apple.com>
…correctly used as key in ruleset

Signed-off-by: Saoirse Aronson <saoirse@apple.com>
Co-authored-by: Sasha Kobrusev <skobrusev@apple.com>
restored not modified authorizerTest.java file

remove unneeded authorizertest dependencies

Signed-off-by: Saoirse Aronson <saoirse@apple.com>
Co-authored-by: Sasha Kobrusev <skobrusev@apple.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant