undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,71 @@
/*
* Copyright (c) 2003, 2007, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
import java.awt.event.ActionListener;
public class Bean {
private String name;
private int number;
private ActionListener listener;
public Bean() {
this("Bean", 1);
}
public Bean(String name, int number) {
this.name = name;
this.number = number;
}
public String getName() {
return this.name;
}
public void setName(String name) {
this.name = name;
}
public int getNumber() {
return this.number;
}
public void setNumber(int i) {
this.number = i;
}
// Introduce at least one Eventset
public void addActionListener(ActionListener listener) {
this.listener = listener;
}
public void removeActionListener(ActionListener listener) {
this.listener = null;
}
public ActionListener[] getActionListeners() {
return (this.listener != null)
? new ActionListener[] {this.listener}
: new ActionListener[] {};
}
}

View file

@ -0,0 +1,52 @@
/*
* Copyright (c) 2003, 2007, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
public class Bean2 {
private String name;
private int number;
public Bean2() {
this("Bean2", 1);
}
public Bean2(String name, int number) {
this.name = name;
this.number = number;
}
public String getName() {
return this.name;
}
public void setName(String name) {
this.name = name;
}
public int getNumber() {
return this.number;
}
public void setNumber(int i) {
this.number = i;
}
}

View file

@ -0,0 +1,52 @@
/*
* Copyright (c) 2003, 2007, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
public class Bean3 {
private String name;
private int number;
public Bean3() {
this("Bean3", 1);
}
public Bean3(String name, int number) {
this.name = name;
this.number = number;
}
public String getName() {
return this.name;
}
public void setName(String name) {
this.name = name;
}
public int getNumber() {
return this.number;
}
public void setNumber(int i) {
this.number = i;
}
}

View file

@ -0,0 +1,52 @@
/*
* Copyright (c) 2003, 2007, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
public class Bean4 {
private String name;
private int number;
public Bean4() {
this("Bean4", 1);
}
public Bean4(String name, int number) {
this.name = name;
this.number = number;
}
public String getName() {
return this.name;
}
public void setName(String name) {
this.name = name;
}
public int getNumber() {
return this.number;
}
public void setNumber(int i) {
this.number = i;
}
}

View file

@ -0,0 +1,64 @@
/*
* Copyright (c) 2007, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
import java.io.FileInputStream;
import java.io.InputStream;
import java.io.IOException;
import java.io.File;
class SimpleClassLoader extends ClassLoader {
public static int numFinalizers;
SimpleClassLoader() {
super(null);
}
protected Class findClass(String name) throws ClassNotFoundException {
File f = new File(System.getProperty("test.classes"), name + ".class");
InputStream fi = null;
try {
fi = new FileInputStream(f);
int length = fi.available();
byte[] bytes = new byte[length];
fi.read(bytes, 0, length);
return defineClass(name, bytes, 0, length);
}
catch (IOException exception) {
// we could not find the class, so indicate the problem
throw new ClassNotFoundException(name, exception);
}
finally {
if (null != fi) {
try {
fi.close();
} catch (IOException exception) {
}
}
}
}
protected void finalize() throws Throwable {
super.finalize();
numFinalizers++;
}
}

View file

@ -0,0 +1,132 @@
/*
* Copyright (c) 2003, 2007, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 4508780
* @summary Tests shared access to the Introspector cache
* @author Mark Davidson
*/
import java.beans.IntrospectionException;
import java.beans.Introspector;
import java.beans.PropertyDescriptor;
import java.lang.reflect.Method;
/**
* Multiple classloader test to ensure that methods
* returned by the BeanInfo classes are unique to the classloader.
*/
public class Test4508780 implements Runnable {
/**
* This is here to force the bean classes to be compiled
*/
private static final Class[] COMPILE = {
Bean.class,
Bean2.class,
Bean3.class,
Bean4.class,
};
public static void main(String[] args) {
for (int i = 0; i < 10; i++) test();
}
private static void test() {
test("Bean", "Bean2", "Bean3", "Bean4");
test("Bean4", "Bean", "Bean2", "Bean3");
test("Bean3", "Bean4", "Bean", "Bean2");
test("Bean2", "Bean3", "Bean4", "Bean");
Introspector.flushCaches();
}
private static void test(String... names) {
new Thread(new Test4508780(names)).start();
}
private final ClassLoader loader = new SimpleClassLoader();
private final String[] names;
private Test4508780(String... names) {
this.names = names;
}
public void run() {
for (String name : this.names) {
Object bean;
try {
bean = this.loader.loadClass(name).newInstance();
} catch (Exception exception) {
throw new Error("could not instantiate bean: " + name, exception);
}
if (this.loader != bean.getClass().getClassLoader()) {
throw new Error("bean class loader is not equal to default one");
}
PropertyDescriptor[] pds = getPropertyDescriptors(bean);
for (PropertyDescriptor pd : pds) {
Class type = pd.getPropertyType();
Method setter = pd.getWriteMethod();
Method getter = pd.getReadMethod();
if (type.equals(String.class)) {
executeMethod(setter, bean, "Foo");
} else if (type.equals(int.class)) {
executeMethod(setter, bean, Integer.valueOf(1));
}
executeMethod(getter, bean);
}
}
}
private static void executeMethod(Method method, Object bean, Object... args) {
if (method == null) {
throw new Error("method is null");
}
if (bean == null) {
throw new Error("target bean is null");
}
try {
method.invoke(bean, args);
} catch (Exception exception) {
throw new Error("could not execute method: " + method, exception);
}
}
private static PropertyDescriptor[] getPropertyDescriptors(Object object) {
Class type = object.getClass();
synchronized (System.out) {
System.out.println(type);
ClassLoader loader = type.getClassLoader();
while (loader != null) {
System.out.println(" - loader: " + loader);
loader = loader.getParent();
}
}
try {
return Introspector.getBeanInfo(type).getPropertyDescriptors();
} catch (IntrospectionException exception) {
throw new Error("unexpected exception", exception);
}
}
}

View file

@ -0,0 +1,85 @@
/*
* Copyright (c) 2003, 2007, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 4809008
* @build Bean
* @run main/othervm -server -XX:SoftRefLRUPolicyMSPerMB=0 Test4809008
* @summary Tests memory leak with multiple class loader access
* @author Mark Davidson
*/
import java.beans.BeanInfo;
import java.beans.Introspector;
/**
* This tests to see if the classes will be garbage collected when multiple
* short lived classloaders populate the BeanInfo cache with classes.
* <p/>
* We are also trying to verify if the ClassLoader finalize method is called.
* <p/>
* Use:
* java -verbose:class to print out class loading.
* java -verbose:gc to print out gc events.
*/
public class Test4809008 {
public static void main(String[] args) throws Exception {
printMemory("Start Memory");
int introspected = 200;
for (int i = 0; i < introspected; i++) {
ClassLoader cl = new SimpleClassLoader();
Class type = cl.loadClass("Bean");
type.newInstance();
// The methods and the bean info should be cached
BeanInfo info = Introspector.getBeanInfo(type);
cl = null;
type = null;
info = null;
System.gc();
}
System.runFinalization();
printMemory("End Memory");
int finalized = SimpleClassLoader.numFinalizers;
System.out.println(introspected + " classes introspected");
System.out.println(finalized + " classes finalized");
// good if at least half of the finalizers are run
if (finalized < (introspected >> 1)) {
throw new Error("ClassLoaders not finalized: " + finalized);
}
}
private static void printMemory(String message) {
Runtime runtime = Runtime.getRuntime();
runtime.gc();
long free = runtime.freeMemory();
long total = runtime.totalMemory();
System.out.println(message);
System.out.println("\tfree: " + free);
System.out.println("\ttotal: " + total);
}
}