undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,261 @@
/*
* Copyright (c) 2014, 2015, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
import java.awt.Image;
import java.beans.BeanDescriptor;
import java.beans.BeanInfo;
import java.beans.EventSetDescriptor;
import java.beans.FeatureDescriptor;
import java.beans.IndexedPropertyDescriptor;
import java.beans.Introspector;
import java.beans.MethodDescriptor;
import java.beans.ParameterDescriptor;
import java.beans.PropertyDescriptor;
import java.lang.reflect.Array;
import java.lang.reflect.Method;
import java.net.URI;
import java.nio.file.FileSystem;
import java.nio.file.FileSystems;
import java.nio.file.FileVisitResult;
import java.nio.file.Files;
import java.nio.file.Path;
import java.nio.file.SimpleFileVisitor;
import java.nio.file.attribute.BasicFileAttributes;
import java.util.Arrays;
import java.util.Comparator;
import java.util.Enumeration;
import java.util.Map.Entry;
import java.util.Objects;
import java.util.TreeMap;
import java.util.TreeSet;
/*
* @test
* @bug 4058433
* @summary Generates BeanInfo for public classes in AWT, Accessibility, and Swing
* @author Sergey Malenkov
*/
public class Test4058433 implements Comparator<Object> {
@Override
public int compare(Object one, Object two) {
if (one instanceof Method && two instanceof Method) {
Method oneMethod = (Method) one;
Method twoMethod = (Method) two;
int result = oneMethod.getName().compareTo(twoMethod.getName());
if (result != 0) {
return result;
}
}
if (one instanceof FeatureDescriptor && two instanceof FeatureDescriptor) {
FeatureDescriptor oneFD = (FeatureDescriptor) one;
FeatureDescriptor twoFD = (FeatureDescriptor) two;
int result = oneFD.getName().compareTo(twoFD.getName());
if (result != 0) {
return result;
}
}
return one.toString().compareTo(two.toString());
}
public static void main(String[] args) throws Exception {
FileSystem fs = FileSystems.getFileSystem(URI.create("jrt:/"));
fs.getFileStores();
TreeSet<Class<?>> types = new TreeSet<>(new Test4058433());
Files.walkFileTree(fs.getPath("/modules/java.desktop"), new SimpleFileVisitor<Path>() {
@Override
public FileVisitResult visitFile(Path file,
BasicFileAttributes attrs) {
file = file.subpath(2, file.getNameCount());
if (file.startsWith("java/awt/")
|| file.startsWith("javax/accessibility/")
|| file.startsWith("javax/swing/")) {
String name =file.toString();
if (name.endsWith(".class")) {
name = name.substring(0, name.indexOf(".")).replace('/', '.');
final Class<?> type;
try {
type = Class.forName(name);
} catch (ClassNotFoundException e) {
throw new RuntimeException(e);
}
if (!BeanInfo.class.isAssignableFrom(type) && !type.isInterface()
&& !type.isEnum() && !type.isAnnotation()
&& !type.isAnonymousClass()) {
if (null == type.getDeclaringClass()) {
types.add(type);
}
}
}
}
return FileVisitResult.CONTINUE;
}
});
System.out.println("found " + types.size() + " classes");
long time = -System.currentTimeMillis();
for (Class<?> type : types) {
System.out.println("========================================");
BeanInfo info = Introspector.getBeanInfo(type);
BeanDescriptor bd = info.getBeanDescriptor();
System.out.println(bd.getBeanClass());
print("customizer", bd.getCustomizerClass());
print(bd);
print("mono 16x16", info.getIcon(BeanInfo.ICON_MONO_16x16));
print("mono 32x32", info.getIcon(BeanInfo.ICON_MONO_32x32));
print("color 16x16", info.getIcon(BeanInfo.ICON_COLOR_16x16));
print("color 32x32", info.getIcon(BeanInfo.ICON_COLOR_32x32));
PropertyDescriptor[] pds = info.getPropertyDescriptors();
PropertyDescriptor dpd = getDefault(pds, info.getDefaultPropertyIndex());
System.out.println(pds.length + " property descriptors");
Arrays.sort(pds, new Test4058433());
for (PropertyDescriptor pd : pds) {
print(pd);
if (dpd == pd) {
System.out.println("default property");
}
print("bound", pd.isBound());
print("constrained", pd.isConstrained());
print("property editor", pd.getPropertyEditorClass());
print("property type", pd.getPropertyType());
print("read method", pd.getReadMethod());
print("write method", pd.getWriteMethod());
if (pd instanceof IndexedPropertyDescriptor) {
IndexedPropertyDescriptor ipd = (IndexedPropertyDescriptor) pd;
print("indexed property type", ipd.getIndexedPropertyType());
print("indexed read method", ipd.getIndexedReadMethod());
print("indexed write method", ipd.getIndexedWriteMethod());
}
}
EventSetDescriptor[] esds = info.getEventSetDescriptors();
EventSetDescriptor desd = getDefault(esds, info.getDefaultEventIndex());
System.out.println(esds.length + " event set descriptors");
Arrays.sort(esds, new Test4058433());
for (EventSetDescriptor esd : esds) {
print(esd);
if (desd == esd) {
System.out.println("default event set");
}
print("in default", esd.isInDefaultEventSet());
print("unicast", esd.isUnicast());
print("listener type", esd.getListenerType());
print("get listener method", esd.getGetListenerMethod());
print("add listener method", esd.getAddListenerMethod());
print("remove listener method", esd.getRemoveListenerMethod());
Method[] methods = esd.getListenerMethods();
Arrays.sort(methods, new Test4058433());
for (Method method : methods) {
print("listener method", method);
}
print(esd.getListenerMethodDescriptors());
}
print(info.getMethodDescriptors());
}
time += System.currentTimeMillis();
System.out.println("DONE IN " + time + " MS");
}
private static <T> T getDefault(T[] array, int index) {
return (index == -1) ? null : array[index];
}
private static void print(MethodDescriptor[] mds) {
System.out.println(mds.length + " method descriptors");
Arrays.sort(mds, new Test4058433());
for (MethodDescriptor md : mds) {
print(md);
print("method", md.getMethod());
ParameterDescriptor[] pds = md.getParameterDescriptors();
if (pds != null) {
System.out.println(pds.length + " parameter descriptors");
for (ParameterDescriptor pd : pds) {
print(pd);
}
}
}
}
private static void print(FeatureDescriptor descriptor) {
String name = descriptor.getName();
String display = descriptor.getDisplayName();
String description = descriptor.getShortDescription();
System.out.println("name: " + name);
if (!Objects.equals(name, display)) {
System.out.println("display name: " + display);
}
if (!Objects.equals(display, description)) {
System.out.println("description: " + description.trim());
}
print("expert", descriptor.isExpert());
print("hidden", descriptor.isHidden());
print("preferred", descriptor.isPreferred());
TreeMap<String,Object> map = new TreeMap<>();
Enumeration<String> enumeration = descriptor.attributeNames();
while (enumeration.hasMoreElements()) {
String id = enumeration.nextElement();
Object value = descriptor.getValue(id);
if (value.getClass().isArray()) {
TreeSet<String> set = new TreeSet<>();
int index = 0;
int length = Array.getLength(value);
while (index < length) {
set.add(Array.get(value, index++) + ", " +
Array.get(value, index++) + ", " +
Array.get(value, index++));
}
value = set.toString();
}
map.put(id, value);
}
for (Entry<String,Object> entry : map.entrySet()) {
System.out.println(entry.getKey() + ": " + entry.getValue());
}
}
private static void print(String id, boolean flag) {
if (flag) {
System.out.println(id + " is set");
}
}
private static void print(String id, Class<?> type) {
if (type != null) {
System.out.println(id + ": " + type.getName());
}
}
private static void print(String id, Method method) {
if (method != null) {
System.out.println(id + ": " + method);
}
}
private static void print(String name, Image image) {
if (image != null) {
System.out.println(name + " icon is exist");
}
}
}

View file

@ -0,0 +1,57 @@
/*
* Copyright (c) 2012, 2013, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 7187618 7122740
* @summary Tests just a benchmark of PropertyDescriptor(String, Class) performance
* @author Sergey Malenkov
* @run main/manual Test7122740
*/
import java.beans.PropertyDescriptor;
public class Test7122740 {
public static void main(String[] args) throws Exception {
long time = System.nanoTime();
for (int i = 0; i < 1000; i++) {
new PropertyDescriptor("name", PropertyDescriptor.class);
new PropertyDescriptor("value", Concrete.class);
}
time -= System.nanoTime();
System.out.println("Time (ms): " + (-time / 1000000));
}
public static class Abstract<T> {
private T value;
public T getValue() {
return this.value;
}
public void setValue(T value) {
this.value = value;
}
}
private static class Concrete extends Abstract<String> {
}
}

View file

@ -0,0 +1,71 @@
/*
* Copyright (c) 2012, 2013, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 7187618 7184799
* @summary Tests just a benchmark of Introspector.getBeanInfo(Class) performance
* @author Sergey Malenkov
* @run main/manual Test7184799
*/
import java.beans.Introspector;
import java.util.*;
import java.util.concurrent.ConcurrentHashMap;
public class Test7184799 {
private static final Class[] TYPES = {
Class.class,
String.class,
Character.class,
Boolean.class,
Byte.class,
Short.class,
Integer.class,
Long.class,
Float.class,
Double.class,
Collection.class,
Set.class,
HashSet.class,
TreeSet.class,
LinkedHashSet.class,
Map.class,
HashMap.class,
TreeMap.class,
LinkedHashMap.class,
WeakHashMap.class,
ConcurrentHashMap.class,
Dictionary.class,
Exception.class,
};
public static void main(String[] args) throws Exception {
long time = System.nanoTime();
for (Class type : TYPES) {
Introspector.getBeanInfo(type);
}
time -= System.nanoTime();
System.out.println("Time (ms): " + (-time / 1000000));
}
}

View file

@ -0,0 +1,156 @@
/*
* Copyright (c) 2003, 2025, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @summary Tests just a benchmark of introspector performance
* @author Mark Davidson
* @run main TestIntrospector
*/
import java.beans.BeanInfo;
import java.beans.IntrospectionException;
import java.beans.Introspector;
/**
* This test is just a benchmark of introspector performance.
*/
public class TestIntrospector {
private static final Class[] TYPES = {
javax.swing.Box.class,
javax.swing.DefaultComboBoxModel.class,
javax.swing.DefaultCellEditor.class,
javax.swing.DefaultComboBoxModel.class,
javax.swing.DefaultListModel.class,
javax.swing.ImageIcon.class,
javax.swing.JButton.class,
javax.swing.JCheckBox.class,
javax.swing.JColorChooser.class,
javax.swing.JComboBox.class,
javax.swing.JDesktopPane.class,
javax.swing.JDialog.class,
javax.swing.JEditorPane.class,
javax.swing.JFileChooser.class,
javax.swing.JFrame.class,
javax.swing.JInternalFrame.class,
javax.swing.JLabel.class,
javax.swing.JList.class,
javax.swing.JMenu.class,
javax.swing.JMenuBar.class,
javax.swing.JMenuItem.class,
javax.swing.JOptionPane.class,
javax.swing.JPanel.class,
javax.swing.JPasswordField.class,
javax.swing.JPopupMenu.class,
javax.swing.JProgressBar.class,
javax.swing.JRadioButton.class,
javax.swing.JRadioButtonMenuItem.class,
javax.swing.JRootPane.class,
javax.swing.JScrollPane.class,
javax.swing.JSeparator.class,
javax.swing.JSlider.class,
javax.swing.JSplitPane.class,
javax.swing.JTabbedPane.class,
javax.swing.JTable.class,
javax.swing.JTextField.class,
javax.swing.JTextArea.class,
javax.swing.JTextPane.class,
javax.swing.JToggleButton.class,
javax.swing.JToolBar.class,
javax.swing.JToolTip.class,
javax.swing.JTree.class,
javax.swing.JWindow.class,
java.awt.Button.class,
java.awt.Canvas.class,
java.awt.Checkbox.class,
java.awt.Choice.class,
java.awt.Dialog.class,
java.awt.FileDialog.class,
java.awt.Frame.class,
java.awt.Image.class,
java.awt.List.class,
java.awt.Menu.class,
java.awt.MenuBar.class,
java.awt.MenuItem.class,
java.awt.Panel.class,
java.awt.Point.class,
java.awt.Rectangle.class,
java.awt.Scrollbar.class,
java.awt.TextArea.class,
java.awt.TextField.class,
java.awt.Window.class,
};
public static void main(String[] args) throws IntrospectionException {
StringBuilder sb = null;
if (args.length > 0) {
if (args[0].equals("show")) {
sb = new StringBuilder(65536);
}
}
Introspector.flushCaches();
int count = (sb != null) ? 10 : 100;
long time = -System.currentTimeMillis();
for (int i = 0; i < count; i++) {
test(sb);
test(sb);
Introspector.flushCaches();
}
time += System.currentTimeMillis();
System.out.println("Time (average): " + time / count);
}
private static void test(StringBuilder sb) throws IntrospectionException {
long time = 0L;
if (sb != null) {
sb.append("Time\t#Props\t#Events\t#Methods\tClass\n");
sb.append("----------------------------------------");
time = -System.currentTimeMillis();
}
for (Class type : TYPES) {
test(sb, type);
}
if (sb != null) {
time += System.currentTimeMillis();
sb.append("\nTime: ").append(time).append(" ms\n");
System.out.println(sb);
sb.setLength(0);
}
}
private static void test(StringBuilder sb, Class type) throws IntrospectionException {
long time = 0L;
if (sb != null) {
time = -System.currentTimeMillis();
}
BeanInfo info = Introspector.getBeanInfo(type);
if (sb != null) {
time += System.currentTimeMillis();
sb.append('\n').append(time);
sb.append('\t').append(info.getPropertyDescriptors().length);
sb.append('\t').append(info.getEventSetDescriptors().length);
sb.append('\t').append(info.getMethodDescriptors().length);
sb.append('\t').append(type.getName());
}
}
}

View file

@ -0,0 +1,75 @@
/*
* Copyright (c) 2007, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @run main/manual TestPropertyChangeSupport
* @summary Tests just a benchmark of PropertyChangeSupport performance
* @author Sergey Malenkov
*/
import java.beans.PropertyChangeEvent;
import java.beans.PropertyChangeListener;
import java.beans.PropertyChangeSupport;
public class TestPropertyChangeSupport implements PropertyChangeListener {
private static final String NAME = "property";
public static void main(String[] args) {
for (int i = 1; i <= 3; i++) {
test(i, 1, 10000000);
test(i, 10, 1000000);
test(i, 100, 100000);
test(i, 1000, 10000);
test(i, 10000, 1000);
test(i, 20000, 1000);
}
}
private static void test(int step, int listeners, int attempts) {
TestPropertyChangeSupport test = new TestPropertyChangeSupport();
PropertyChangeSupport pcs = new PropertyChangeSupport(test);
PropertyChangeEvent eventNull = new PropertyChangeEvent(test, null, null, null);
PropertyChangeEvent eventName = new PropertyChangeEvent(test, NAME, null, null);
long time1 = System.currentTimeMillis();
for (int i = 0; i < listeners; i++) {
pcs.addPropertyChangeListener(test);
pcs.addPropertyChangeListener(NAME, test);
}
long time2 = System.currentTimeMillis();
for (int i = 0; i < attempts; i++) {
pcs.firePropertyChange(eventNull);
pcs.firePropertyChange(eventName);
}
long time3 = System.currentTimeMillis();
time1 = time2 - time1; // time of adding the listeners
time2 = time3 - time2; // time of firing the events
System.out.println("Step: " + step
+ "; Listeners: " + listeners
+ "; Attempts: " + attempts
+ "; Time (ms): " + time1 + "/" + time2);
}
public void propertyChange(PropertyChangeEvent event) {
}
}

View file

@ -0,0 +1,76 @@
/*
* Copyright (c) 2007, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @run main/manual TestVetoableChangeSupport
* @summary Tests just a benchmark of VetoableChangeSupport performance
* @author Sergey Malenkov
*/
import java.beans.PropertyChangeEvent;
import java.beans.PropertyVetoException;
import java.beans.VetoableChangeListener;
import java.beans.VetoableChangeSupport;
public class TestVetoableChangeSupport implements VetoableChangeListener {
private static final String NAME = "property";
public static void main(String[] args) throws PropertyVetoException {
for (int i = 1; i <= 3; i++) {
test(i, 1, 10000000);
test(i, 10, 1000000);
test(i, 100, 100000);
test(i, 1000, 10000);
test(i, 10000, 1000);
test(i, 20000, 1000);
}
}
private static void test(int step, int listeners, int attempts) throws PropertyVetoException {
TestVetoableChangeSupport test = new TestVetoableChangeSupport();
VetoableChangeSupport vcs = new VetoableChangeSupport(test);
PropertyChangeEvent eventNull = new PropertyChangeEvent(test, null, null, null);
PropertyChangeEvent eventName = new PropertyChangeEvent(test, NAME, null, null);
long time1 = System.currentTimeMillis();
for (int i = 0; i < listeners; i++) {
vcs.addVetoableChangeListener(test);
vcs.addVetoableChangeListener(NAME, test);
}
long time2 = System.currentTimeMillis();
for (int i = 0; i < attempts; i++) {
vcs.fireVetoableChange(eventNull);
vcs.fireVetoableChange(eventName);
}
long time3 = System.currentTimeMillis();
time1 = time2 - time1; // time of adding the listeners
time2 = time3 - time2; // time of firing the events
System.out.println("Step: " + step
+ "; Listeners: " + listeners
+ "; Attempts: " + attempts
+ "; Time (ms): " + time1 + "/" + time2);
}
public void vetoableChange(PropertyChangeEvent event) {
}
}