undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,82 @@
/*
* Copyright (c) 2011, 2024, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
import java.awt.BorderLayout;
import java.awt.Color;
import java.awt.Component;
import java.awt.Frame;
import java.awt.Panel;
/*
* @test
* @bug 6392086
* @summary Tests dnd to another screen
* @library /java/awt/regtesthelpers
* @build PassFailJFrame
* @run main/manual DnDHTMLToOutlookTest
*/
public class DnDHTMLToOutlookTest {
private static final String INSTRUCTIONS = """
The window contains a yellow button. Click on the button
to copy HTML from DnDSource.html file into the clipboard or drag
HTML context. Paste into or drop over the HTML capable editor in
external application such as Outlook, Word.
When the mouse enters the editor, cursor should change to indicate
that copy operation is about to happen and then release the mouse
button. HTML text without tags should appear inside the document.
You should be able to repeat this operation multiple times.
If the above is true Press PASS else FAIL.
""";
public static void main(String[] args) throws Exception {
PassFailJFrame.builder()
.title("Test Instructions")
.instructions(INSTRUCTIONS)
.columns(40)
.testUI(DnDHTMLToOutlookTest::createAndShowUI)
.build()
.awaitAndCheck();
}
private static Frame createAndShowUI() {
Frame frame = new Frame("DnDHTMLToOutlookTest");
Panel mainPanel;
Component dragSource;
mainPanel = new Panel();
mainPanel.setLayout(new BorderLayout());
mainPanel.setBackground(Color.YELLOW);
dragSource = new DnDSource("Drag ME (HTML)!");
mainPanel.add(dragSource, BorderLayout.CENTER);
frame.add(mainPanel);
frame.setSize(200, 200);
return frame;
}
}

View file

@ -0,0 +1,25 @@
<!--
Copyright (c) 2011, 2024, Oracle and/or its affiliates. All rights reserved.
DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
This code is free software; you can redistribute it and/or modify it
under the terms of the GNU General Public License version 2 only, as
published by the Free Software Foundation.
This code is distributed in the hope that it will be useful, but WITHOUT
ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
version 2 for more details (a copy is included in the LICENSE file that
accompanied this code).
You should have received a copy of the GNU General Public License version
2 along with this work; if not, write to the Free Software Foundation,
Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
or visit www.oracle.com if you need additional information or have any
questions.
-->
<h1>DnDHTMLToOutlookTest<br>HTML Drag & Paste problem</h1>
<p>if you see the bold header above without HTML tags and without StartHTML as the first word, press PASS</p>

View file

@ -0,0 +1,142 @@
/*
* Copyright (c) 2011, 2024, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
import java.awt.Button;
import java.awt.Color;
import java.awt.Toolkit;
import java.awt.datatransfer.DataFlavor;
import java.awt.datatransfer.Transferable;
import java.awt.datatransfer.UnsupportedFlavorException;
import java.awt.dnd.DnDConstants;
import java.awt.dnd.DragGestureEvent;
import java.awt.dnd.DragGestureListener;
import java.awt.dnd.DragSource;
import java.awt.dnd.DragSourceDragEvent;
import java.awt.dnd.DragSourceDropEvent;
import java.awt.dnd.DragSourceEvent;
import java.awt.dnd.DragSourceListener;
import java.awt.dnd.InvalidDnDOperationException;
import java.awt.event.ActionEvent;
import java.awt.event.ActionListener;
import java.io.ByteArrayInputStream;
import java.io.InputStream;
import java.nio.file.Files;
import java.nio.file.Paths;
class DnDSource extends Button implements Transferable,
DragGestureListener,
DragSourceListener {
private DataFlavor m_df;
private transient int m_dropAction;
private ByteArrayInputStream m_data = null;
DnDSource(String label) {
super(label);
setBackground(Color.yellow);
setForeground(Color.blue);
setSize(200, 120);
try {
m_df = new DataFlavor("text/html; Class=" + InputStream.class.getName() + "; charset=UTF-8");
} catch (Exception e) {
e.printStackTrace();
}
DragSource dragSource = new DragSource();
dragSource.createDefaultDragGestureRecognizer(
this,
DnDConstants.ACTION_COPY_OR_MOVE,
this
);
dragSource.addDragSourceListener(this);
String dir = System.getProperty("test.src", ".");
try {
m_data = new ByteArrayInputStream(Files.readAllBytes(
Paths.get(dir, "DnDSource.html")));
m_data.mark(m_data.available());
addActionListener(
new ActionListener(){
public void actionPerformed(ActionEvent ae){
Toolkit.getDefaultToolkit().getSystemClipboard()
.setContents( DnDSource.this, null);
}
}
);
} catch (Exception e) {
e.printStackTrace();
}
}
public void dragGestureRecognized(DragGestureEvent dge) {
System.err.println("starting Drag");
try {
dge.startDrag(null, this, this);
} catch (InvalidDnDOperationException e) {
e.printStackTrace();
}
}
public void dragEnter(DragSourceDragEvent dsde) {
System.err.println("[Source] dragEnter");
}
public void dragOver(DragSourceDragEvent dsde) {
System.err.println("[Source] dragOver");
m_dropAction = dsde.getDropAction();
System.out.println("m_dropAction = " + m_dropAction);
}
public void dragExit(DragSourceEvent dsde) {
System.err.println("[Source] dragExit");
}
public void dragDropEnd(DragSourceDropEvent dsde) {
System.err.println("[Source] dragDropEnd");
}
public void dropActionChanged(DragSourceDragEvent dsde) {
System.err.println("[Source] dropActionChanged");
m_dropAction = dsde.getDropAction();
System.out.println("m_dropAction = " + m_dropAction);
}
public DataFlavor[] getTransferDataFlavors() {
return new DataFlavor[] {m_df};
}
public boolean isDataFlavorSupported(DataFlavor sdf) {
System.err.println("[Source] isDataFlavorSupported" + m_df.equals(sdf));
return m_df.equals(sdf);
}
public Object getTransferData(DataFlavor tdf) throws UnsupportedFlavorException {
if (!m_df.equals(tdf)) {
throw new UnsupportedFlavorException(tdf);
}
System.err.println("[Source] Ok");
m_data.reset();
return m_data;
}
}