undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,112 @@
/*
* Copyright (c) 2017, 2023, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 4087295 4785472
* @library /test/lib
* @build jdk.test.lib.compiler.CompilerUtils
* jdk.test.lib.Utils
* jdk.test.lib.Asserts
* jdk.test.lib.JDKToolFinder
* jdk.test.lib.JDKToolLauncher
* jdk.test.lib.Platform
* jdk.test.lib.process.*
* @build RenamePackageTest
* @run main RenamePackageTest
* @summary Enable resolveClass() to accommodate package renaming.
* This fix enables one to implement a resolveClass method that maps a
* Serialiazable class within a serialization stream to the same class
* in a different package within the JVM runtime. See run shell script
* for instructions on how to run this test.
*/
import java.io.File;
import java.nio.file.Path;
import java.nio.file.Paths;
import jdk.test.lib.compiler.CompilerUtils;
import jdk.test.lib.process.ProcessTools;
public class RenamePackageTest {
public static void main(String args[]) throws Exception {
setup();
runTestSerialDriver();
runInstallSerialDriver();
runInstallSerialDriver();
runTestSerialDriver();
}
private static final Path SHARE = Paths.get(System.getProperty("test.classes"), "share");
private static final Path OCLASSES = Paths.get(System.getProperty("test.classes"), "oclasses");
private static final Path NCLASSES = Paths.get(System.getProperty("test.classes"), "nclasses");
private static void setup() throws Exception {
boolean b = CompilerUtils.compile(Paths.get(System.getProperty("test.src"), "extension"),
SHARE);
assertTrue(b);
b = CompilerUtils.compile(Paths.get(System.getProperty("test.src"), "test"),
OCLASSES,
"-classpath",
SHARE.toString());
assertTrue(b);
b = CompilerUtils.compile(Paths.get(System.getProperty("test.src"), "install"),
NCLASSES,
"-classpath",
SHARE.toString());
assertTrue(b);
}
private static void runTestSerialDriver() throws Exception {
ProcessBuilder pb = ProcessTools.createTestJavaProcessBuilder(
"-classpath",
SHARE.toString()
+ File.pathSeparator
+ OCLASSES.toString(),
"test.SerialDriver", "-s");
Process p = ProcessTools.startProcess("test SerialDriver", pb);
p.waitFor();
assertTrue(p.exitValue() == 0);
}
private static void runInstallSerialDriver() throws Exception {
ProcessBuilder pb = ProcessTools.createTestJavaProcessBuilder(
"-classpath",
SHARE.toString()
+ File.pathSeparator
+ NCLASSES.toString(),
"install.SerialDriver", "-d");
Process p = ProcessTools.startProcess("install SerialDriver", pb);
p.waitFor();
assertTrue(p.exitValue() == 0);
}
private static void assertTrue(boolean b) {
if (!b) {
throw new RuntimeException("expected true, get false");
}
}
}

View file

@ -0,0 +1,77 @@
/*
* Copyright (c) 1998, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
package extension;
import java.util.Hashtable;
import java.io.*;
public class ExtendedObjectInputStream extends ObjectInputStream {
private static Hashtable renamedClassMap;
public ExtendedObjectInputStream(InputStream si)
throws IOException, StreamCorruptedException
{
super(si);
}
protected Class resolveClass(ObjectStreamClass v)
throws IOException, ClassNotFoundException
{
if (renamedClassMap != null) {
// System.out.println("resolveClass(" + v.getName() + ")");
Class newClass = (Class)renamedClassMap.get(v.getName());
if (newClass != null) {
v = ObjectStreamClass.lookup(newClass);
}
}
return super.resolveClass(v);
}
public static void addRenamedClassName(String oldName, String newName)
throws ClassNotFoundException
{
Class cl = null;
if (renamedClassMap == null)
renamedClassMap = new Hashtable(10);
if (newName.startsWith("[L")) {
// System.out.println("Array processing");
Class componentType =
Class.forName(newName.substring(2));
//System.out.println("ComponentType=" + componentType.getName());
Object dummy =
java.lang.reflect.Array.newInstance(componentType, 3);
cl = dummy.getClass();
// System.out.println("Class=" + cl.getName());
}
else
cl = Class.forName(newName);
//System.out.println("oldName=" + oldName +
// " newName=" + cl.getName());
renamedClassMap.put(oldName, cl);
}
}

View file

@ -0,0 +1,139 @@
/*
* Copyright (c) 1998, 2011, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
*
* @bug 4087295
* @build install/SerialDriver.java test/SerialDriver.java extension/ExtendedObjectInputStream.java
* @summary Enable resolveClass() to accommodate package renaming.
* This fix enables one to implement a resolveClass method that maps a
* Serializable class within a serialization stream to the same class
* in a different package within the JVM runtime. See run shell script
* for instructions on how to run this test.
*/
package install;
import java.io.*;
import extension.ExtendedObjectInputStream;
public class SerialDriver implements Serializable {
private static final long serialVersionUID = 1L;
String name;
SerialDriver next;
transient Object objarray[];
public SerialDriver() {
name = "<terminator>";
next = null;
}
public SerialDriver(String name, SerialDriver next) {
this.name = name;
this.next = next;
}
static boolean serialize;
static boolean deserialize;
public static void main(String args[]) throws Exception {
SerialDriver obj = new SerialDriver("SerialDriver_2",
new SerialDriver());
SerialDriver[] array = new SerialDriver[5];
for (int i = 0; i < array.length; i++)
array[i] = new SerialDriver("SerialDriver_1_" + i, new SerialDriver());
/*
* see if we are serializing or deserializing.
* The ability to deserialize or serialize allows
* us to see the bidirectional readability and writeability
*/
if (args.length == 1) {
if (args[0].equals("-d")) {
deserialize = true;
} else if (args[0].equals("-s")) {
serialize = true;
} else {
usage();
throw new Exception("incorrect command line arguments");
}
} else {
usage();
throw new Exception("incorrect command line arguments");
}
File f = new File("stream.ser");
if (serialize) {
// Serialize the subclass
try (FileOutputStream fo = new FileOutputStream(f);
ObjectOutputStream so = new ObjectOutputStream(fo))
{
so.writeObject(obj);
/* Skip arrays since they do not work with rename yet.
The serialVersionUID changes due to the name change
and there is no way to set the serialVersionUID for an
array. */
so.writeObject(array);
} catch (Exception e) {
System.out.println(e);
throw e;
}
}
if (deserialize) {
// Deserialize the subclass
try (FileInputStream fi = new FileInputStream(f);
ExtendedObjectInputStream si = new ExtendedObjectInputStream(fi))
{
si.addRenamedClassName("test.SerialDriver", "install.SerialDriver");
si.addRenamedClassName("[Ltest.SerialDriver;",
"[Linstall.SerialDriver");
obj = (SerialDriver) si.readObject();
array = (SerialDriver[]) si.readObject();
} catch (Exception e) {
System.out.println(e);
throw e;
}
System.out.println();
System.out.println("Printing deserialized class: ");
System.out.println();
System.out.println(obj.toString());
System.out.println();
}
}
public String toString() {
String nextString = next != null ? next.toString() : "<null>";
return "name =" + name + " next = <" + nextString + ">";
}
/**
* Prints out the usage
*/
static void usage() {
System.out.println("Usage:");
System.out.println(" -s (in order to serialize)");
System.out.println(" -d (in order to deserialize)");
}
}

View file

@ -0,0 +1,135 @@
/*
* Copyright (c) 1998, 2011, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
*
* @bug 4087295
* @build install/SerialDriver.java test/SerialDriver.java extension/ExtendedObjectInputStream.java
* @summary Enable resolveClass() to accommodate package renaming.
* This fix enables one to implement a resolveClass method that maps a
* Serializable class within a serialization stream to the same class
* in a different package within the JVM runtime. See run shell script
* for instructions on how to run this test.
*/
package test;
import java.io.*;
import extension.ExtendedObjectInputStream;
public class SerialDriver implements Serializable {
private static final long serialVersionUID = 1L;
String name;
SerialDriver next;
public SerialDriver() {
name = "<terminator>";
next = null;
}
public SerialDriver(String name, SerialDriver next) {
this.name = name;
this.next = next;
}
static boolean serialize = false;
static boolean deserialize = false;
public static void main(String args[]) throws Exception {
SerialDriver obj = new SerialDriver("SerialDriver_1", new SerialDriver());
SerialDriver[] array = new SerialDriver[5];
for (int i = 0; i < array.length; i++)
array[i] = new SerialDriver("SerialDriver_1_" + i, new SerialDriver());
/*
* see if we are serializing or deserializing.
* The ability to deserialize or serialize allows
* us to see the bidirectional readability and writeability
*/
if (args.length == 1) {
if (args[0].equals("-d")) {
deserialize = true;
} else if (args[0].equals("-s")) {
serialize = true;
} else {
usage();
throw new Exception("incorrect command line arguments");
}
} else {
usage();
throw new Exception("incorrect command line arguments");
}
File f = new File("stream.ser");
if (serialize) {
// Serialize the subclass
try (FileOutputStream fo = new FileOutputStream(f);
ObjectOutputStream so = new ObjectOutputStream(fo))
{
so.writeObject(obj);
/* Comment out since renaming arrays does not work
since it changes the serialVersionUID. */
so.writeObject(array);
} catch (Exception e) {
System.out.println(e);
throw e;
}
}
if (deserialize) {
// Deserialize the subclass
try (FileInputStream fi = new FileInputStream(f);
ExtendedObjectInputStream si = new ExtendedObjectInputStream(fi))
{
si.addRenamedClassName("install.SerialDriver",
"test.SerialDriver");
si.addRenamedClassName("[Linstall.SerialDriver;",
"[Ltest.SerialDriver");
obj = (SerialDriver) si.readObject();
array = (SerialDriver[]) si.readObject();
} catch (Exception e) {
System.out.println(e);
throw e;
}
System.out.println();
System.out.println("Printing deserialized class: ");
System.out.println();
System.out.println(obj.toString());
System.out.println();
}
}
public String toString() {
String nextString = next != null ? next.toString() : "<null>";
return "name =" + name + " next = <" + nextString + ">";
}
/**
* Prints out the usage
*/
static void usage() {
System.out.println("Usage:");
System.out.println(" -s (in order to serialize)");
System.out.println(" -d (in order to deserialize)");
}
}