undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,106 @@
/*
* Copyright (c) 2004, 2018, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 5089985
* @summary Test checks that drawing AA lines don't crash the VM
*/
import java.awt.Graphics2D;
import java.awt.RenderingHints;
import java.awt.geom.GeneralPath;
import java.awt.image.BufferedImage;
public class AALineTest {
/* Pairs of endpoints which cause VM crash */
public static int xBound [][] = {
{634,25,640,33},
{634,57,640,65},
{634,89,640,97},
{634,121,640,129},
{634,153,640,161},
{634,185,640,193},
{634,217,640,225},
{634,249,640,257},
{634,281,640,289},
{634,313,640,321},
{634,345,640,353},
{634,377,640,385},
{634,409,640,417},
{634,441,640,449}
};
public static int yBound [][] = {
{25, 634,33, 640},
{57, 634,65, 640},
{89, 634,97, 640},
{121,634,129,640},
{153,634,161,640},
{185,634,193,640},
{217,634,225,640},
{249,634,257,640},
{281,634,289,640},
{313,634,321,640},
{345,634,353,640},
{377,634,385,640},
{409,634,417,640},
{441,634,449,640}
};
public static void main(String[] args) {
BufferedImage image =
new BufferedImage(640, 480, BufferedImage.TYPE_INT_ARGB);
Graphics2D graphics = image.createGraphics();
graphics.setRenderingHint(RenderingHints.KEY_ANTIALIASING,
RenderingHints.VALUE_ANTIALIAS_ON);
GeneralPath path = new GeneralPath();
for(int i=0; i < xBound.length; i++) {
path.reset();
path.moveTo(0, 0);
path.lineTo(xBound[i][0],xBound[i][1]);
path.lineTo(xBound[i][2],xBound[i][3]);
path.closePath();
graphics.draw(path);
}
image = new BufferedImage(480, 640, BufferedImage.TYPE_INT_ARGB);
graphics = image.createGraphics();
graphics.setRenderingHint(RenderingHints.KEY_ANTIALIASING,
RenderingHints.VALUE_ANTIALIAS_ON);
for(int i=0; i < yBound.length; i++) {
path.reset();
path.moveTo(0, 0);
path.lineTo(yBound[i][0],yBound[i][1]);
path.lineTo(yBound[i][2],yBound[i][3]);
path.closePath();
graphics.draw(path);
}
}
}

View file

@ -0,0 +1,77 @@
/*
* Copyright (c) 2002, 2018, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 4335024
* @summary Verifies that the ptXXXDistSq methods return non-negative numbers
*/
import java.awt.geom.Line2D;
public class NegLineDistSqBug {
static int errored;
public static void main (String[] args) {
// First a sanity check
test(1, 2, 3, 4, 15, 19, 21, 32);
// Next, the test numbers from bug report 4335024
test(-313.0, 241.0, -97.0, 75.0,
126.15362619253153, -96.49769420351959, -97.0, 75.0);
// Next test 100 points along the line from bug report 4335024
for (double fract = 0.0; fract <= 0.5; fract += 0.01) {
test(-313.0, 241.0, -97.0, 75.0,
interp(-313.0, -97.0, fract), interp(241.0, 75.0, fract),
interp(-313.0, -97.0, 1-fract), interp(241.0, 75.0, 1-fract));
}
if (errored > 0) {
throw new RuntimeException(errored+" negative distances!");
}
}
public static double interp(double v1, double v2, double t) {
return (v1 * (1-t) + v2 * t);
}
public static void test(double l1x1, double l1y1,
double l1x2, double l1y2,
double l2x1, double l2y1,
double l2x2, double l2y2)
{
Line2D l1 = new Line2D.Double(l1x1, l1y1, l1x2, l1y2);
Line2D l2 = new Line2D.Double(l2x1, l2y1, l2x2, l2y2);
System.out.println("Line distances:");
verify(l1.ptLineDistSq(l2.getP1()));
verify(l1.ptLineDistSq(l2.getP2()));
System.out.println("Segment distances:");
verify(l1.ptSegDistSq(l2.getP1()));
verify(l1.ptSegDistSq(l2.getP2()));
}
public static void verify(double distSq) {
System.out.println(distSq);
if (distSq < 0) {
errored++;
}
}
}