Skip to content

8387124: Incomplete algorithm decomposition for TLS 1.3 cipher suites in SSLAlgorithmDecomposer - #679

Open
chmielewskiandreas wants to merge 1 commit into
openjdk:masterfrom
chmielewskiandreas:backport-8387124
Open

8387124: Incomplete algorithm decomposition for TLS 1.3 cipher suites in SSLAlgorithmDecomposer#679
chmielewskiandreas wants to merge 1 commit into
openjdk:masterfrom
chmielewskiandreas:backport-8387124

Conversation

@chmielewskiandreas

@chmielewskiandreas chmielewskiandreas commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Hi, this is a clean backport of 3f52251c9d82991b14f0bbf34c81627911b0fdbf

Testing:

make run-test TEST="jdk_security"
make run-test TEST="test/jdk/javax/net/ssl/ciphersuites/BulkCipherDisabledAlgorithms.java
test/jdk/sun/security/ssl/CipherSuite/TLS13BulkCipherDisabledCipherSuite.java"



Progress

  • Change must not contain extraneous whitespace
  • Commit message must refer to an issue
  • JDK-8387124 needs maintainer approval

Issue

  • JDK-8387124: Incomplete algorithm decomposition for TLS 1.3 cipher suites in SSLAlgorithmDecomposer (Bug - P4 - Requested)

Reviewing

Using git

Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk25u-dev.git pull/679/head:pull/679
$ git checkout pull/679

Update a local copy of the PR:
$ git checkout pull/679
$ git pull https://git.openjdk.org/jdk25u-dev.git pull/679/head

Using Skara CLI tools

Checkout this PR locally:
$ git pr checkout 679

View PR using the GUI difftool:
$ git pr show -t 679

Using diff file

Download this PR as a diff file:
https://git.openjdk.org/jdk25u-dev/pull/679.diff

Using Webrev

Link to Webrev Comment

@bridgekeeper

bridgekeeper Bot commented Jul 24, 2026

Copy link
Copy Markdown

👋 Welcome back achmielewski! A progress list of the required criteria for merging this PR into master will be added to the body of your pull request. There are additional pull request commands available for use with this pull request.

@openjdk

openjdk Bot commented Jul 24, 2026

Copy link
Copy Markdown

❗ This change is not yet ready to be integrated.
See the Progress checklist in the description for automated requirements.

@openjdk openjdk Bot changed the title Backport 3f52251c9d82991b14f0bbf34c81627911b0fdbf 8387124: Incomplete algorithm decomposition for TLS 1.3 cipher suites in SSLAlgorithmDecomposer Jul 24, 2026
@openjdk

openjdk Bot commented Jul 24, 2026

Copy link
Copy Markdown

This backport pull request has now been updated with issue from the original commit.

@openjdk openjdk Bot added backport Port of a pull request already in a different code base clean Identical backport; no merge resolution required labels Jul 24, 2026
@chmielewskiandreas
chmielewskiandreas marked this pull request as ready for review July 27, 2026 05:41
@chmielewskiandreas

chmielewskiandreas commented Jul 27, 2026

Copy link
Copy Markdown
Contributor Author

/approval request

The change applies cleanly,

I would classify the backport risk as low, with the main risk being behavioral compatibility. The issue addresses incomplete decomposition of TLS 1.3 cipher suites, which caused jdk.tls.disabledAlgorithms constraints such as AES_128_GCM, AES_256_GCM, and CHACHA20_POLY1305 to not consistently match the corresponding TLS cipher suites.

As a result, disabling these algorithms may not disable the corresponding TLS 1.3 cipher suites as expected. This change makes the behavior consistent with other cipher suites and ensures that the configured algorithm constraints are applied correctly.

Please note that this change will be followed by JDK-8387874, which improves the timeout handling in this test.

@openjdk

openjdk Bot commented Jul 27, 2026

Copy link
Copy Markdown

⚠️ @chmielewskiandreas This change is now ready for you to apply for maintainer approval. This can be done directly in each associated issue or by using the /approval command.

@openjdk openjdk Bot added the rfr Pull request is ready for review label Jul 27, 2026
@openjdk

openjdk Bot commented Jul 27, 2026

Copy link
Copy Markdown

@chmielewskiandreas
8387124: The approval request has been created successfully.

@openjdk openjdk Bot added the approval Requires approval; will be removed when approval is received label Jul 27, 2026
@mlbridge

mlbridge Bot commented Jul 27, 2026

Copy link
Copy Markdown

Webrevs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approval Requires approval; will be removed when approval is received backport Port of a pull request already in a different code base clean Identical backport; no merge resolution required rfr Pull request is ready for review

Development

Successfully merging this pull request may close these issues.

1 participant