undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,60 @@
/*
* Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/* @test
@bug 4428861
@summary Method.invoke() should wrap all Throwables in InvocationTargetException
@author Kenneth Russell
*/
import java.lang.reflect.Method;
import java.lang.reflect.InvocationTargetException;
public class ErrorInInvoke {
public static void run() {
throw new AbstractMethodError("Not really, just testing");
}
public static void main(String[] args) {
Method m = null;
try {
m = ErrorInInvoke.class.getMethod("run", new Class[] {});
} catch (Throwable t) {
throw new RuntimeException("Test failed (getMethod() failed");
}
try {
m.invoke(null, null);
} catch (AbstractMethodError e) {
throw new RuntimeException("Test failed (AbstractMethodError passed through)");
} catch (InvocationTargetException e) {
Throwable t = e.getTargetException();
if (!(t instanceof AbstractMethodError)) {
throw new RuntimeException("Test failed (InvocationTargetException didn't wrap AbstractMethodError)");
}
} catch (Throwable t) {
throw new RuntimeException("Test failed (Unexpected exception)");
}
}
}

View file

@ -0,0 +1,69 @@
/*
* Copyright (c) 1998, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/* @test
@bug 4109289
@summary Turning off access checks now enables illegal reflection.
@author Anand Palaniswamy
*/
import java.lang.reflect.Method;
/**
* Try to call a private method with Method.invoke(). If that doesn't
* throw a IllegalAccessException, then access checks are disabled,
* which is a bad idea.
*/
public class IllegalAccessInInvoke {
public static void main(String[] argv) {
Class[] argTypes = new Class[0];
Object[] args = new Object[0];
Method pm = null;
try {
pm = Foo.class.getDeclaredMethod("privateMethod", argTypes);
} catch (NoSuchMethodException nsme) {
throw new
RuntimeException("Bizzare: privateMethod *must* be there");
}
boolean ethrown = false;
try {
pm.invoke(new Foo(), args);
} catch (IllegalAccessException iae) {
ethrown = true;
} catch (Exception e) {
throw new RuntimeException("Unexpected " + e.toString());
}
if (!ethrown) {
throw new
RuntimeException("Reflection access checks are disabled");
}
}
}
class Foo {
private void privateMethod() {
}
}

View file

@ -0,0 +1,130 @@
/*
* Copyright (c) 2014, 2023, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 5043030
* @summary Verify that the method java.lang.reflect.Method.invoke(Object, Object...)
* makes use of the same caching mechanism as used for autoboxing
* when wrapping returned values of the primitive types.
* @author Andrej Golovnin
* @run main/othervm TestMethodReflectValueOf
*/
import java.lang.reflect.InvocationTargetException;
import java.lang.reflect.Method;
public class TestMethodReflectValueOf {
public static void main(String[] args) {
// When the inflation is disabled we compare values using "=="
// as the returned values of the primitive types should be cached
// by the same mechanism as used for autoboxing. When the inflation
// is enabled we use "equals()"-method to compare values as the native
// code still creates new instances to wrap values of the primitive
// types.
boolean checkIdentity = Boolean.getBoolean("sun.reflect.noInflation");
// Boolean#valueOf test
testMethod(Boolean.TYPE, Boolean.FALSE, checkIdentity);
testMethod(Boolean.TYPE, Boolean.TRUE, checkIdentity);
// Byte#valueOf test
for (int b = Byte.MIN_VALUE; b < (Byte.MAX_VALUE + 1); b++) {
testMethod(Byte.TYPE, Byte.valueOf((byte) b), checkIdentity);
}
// Character#valueOf test
for (char c = '\u0000'; c <= '\u007F'; c++) {
testMethod(Character.TYPE, Character.valueOf(c), checkIdentity);
}
// Integer#valueOf test
for (int i = -128; i <= 127; i++) {
testMethod(Integer.TYPE, Integer.valueOf(i), checkIdentity);
}
// Long#valueOf test
for (long l = -128L; l <= 127L; l++) {
testMethod(Long.TYPE, Long.valueOf(l), checkIdentity);
}
// Short#valueOf test
for (short s = -128; s <= 127; s++) {
testMethod(Short.TYPE, Short.valueOf(s), checkIdentity);
}
}
public static void testMethod(Class<?> primType, Object wrappedValue,
boolean checkIdentity)
{
String methodName = primType.getName() + "Method";
try {
Method method = TestMethodReflectValueOf.class.getMethod(methodName, primType);
Object result = method.invoke(new TestMethodReflectValueOf(), wrappedValue);
if (checkIdentity) {
if (result != wrappedValue) {
throw new RuntimeException("The value " + wrappedValue
+ " is not cached for the type " + primType);
}
} else {
if (!result.equals(wrappedValue)) {
throw new RuntimeException("The result value " + result
+ " is not equal to the expected value "
+ wrappedValue + " for the type " + primType);
}
}
} catch ( NoSuchMethodException | SecurityException
| IllegalAccessException | IllegalArgumentException
| InvocationTargetException e)
{
throw new RuntimeException(e);
}
}
public int intMethod(int value) {
return value;
}
public long longMethod(long value) {
return value;
}
public short shortMethod(short value) {
return value;
}
public byte byteMethod(byte value) {
return value;
}
public char charMethod(char value) {
return value;
}
public boolean booleanMethod(boolean value) {
return value;
}
}

View file

@ -0,0 +1,117 @@
/*
* Copyright (c) 2013, 2024, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 8026213
* @summary Reflection support for private methods in interfaces
* @author Robert Field
* @run main TestPrivateInterfaceMethodReflect
*/
import java.lang.classfile.ClassFile;
import java.lang.constant.ClassDesc;
import java.lang.constant.MethodTypeDesc;
import java.lang.reflect.*;
import static java.lang.classfile.ClassFile.ACC_PRIVATE;
import static java.lang.classfile.ClassFile.ACC_PUBLIC;
import static java.lang.constant.ConstantDescs.CD_Object;
import static java.lang.constant.ConstantDescs.CD_int;
import static java.lang.constant.ConstantDescs.INIT_NAME;
import static java.lang.constant.ConstantDescs.MTD_void;
public class TestPrivateInterfaceMethodReflect {
static final String INTERFACE_NAME = "PrivateInterfaceMethodReflectTest_Interface";
static final String CLASS_NAME = "PrivateInterfaceMethodReflectTest_Class";
static final int EXPECTED = 1234;
static class TestClassLoader extends ClassLoader {
@Override
public Class<?> findClass(String name) throws ClassNotFoundException {
byte[] b;
try {
b = loadClassData(name);
} catch (Throwable th) {
// th.printStackTrace();
throw new ClassNotFoundException("Loading error", th);
}
return defineClass(name, b, 0, b.length);
}
private byte[] loadClassData(String name) {
return switch (name) {
case INTERFACE_NAME -> ClassFile.of().build(ClassDesc.ofInternalName(INTERFACE_NAME), clb -> {
clb.withFlags(AccessFlag.ABSTRACT, AccessFlag.INTERFACE, AccessFlag.PUBLIC);
clb.withSuperclass(CD_Object);
clb.withMethodBody("privInstance", MethodTypeDesc.of(CD_int), ACC_PRIVATE, cob -> {
cob.loadConstant(EXPECTED);
cob.ireturn();
});
});
case CLASS_NAME -> ClassFile.of().build(ClassDesc.of(CLASS_NAME), clb -> {
clb.withFlags(AccessFlag.PUBLIC);
clb.withSuperclass(CD_Object);
clb.withInterfaceSymbols(ClassDesc.ofInternalName(INTERFACE_NAME));
clb.withMethodBody(INIT_NAME, MTD_void, ACC_PUBLIC, cob -> {
cob.aload(0);
cob.invokespecial(CD_Object, INIT_NAME, MTD_void);
cob.return_();
});
});
default -> throw new IllegalArgumentException();
};
}
}
public static void main(String[] args) throws Exception {
TestClassLoader tcl = new TestClassLoader();
Class<?> itf = tcl.loadClass(INTERFACE_NAME);
Class<?> k = tcl.loadClass(CLASS_NAME);
Object inst = k.getDeclaredConstructor().newInstance();
Method[] meths = itf.getDeclaredMethods();
if (meths.length != 1) {
throw new Exception("Expected one method in " + INTERFACE_NAME + " instead " + meths.length);
}
Method m = meths[0];
int mod = m.getModifiers();
if ((mod & Modifier.PRIVATE) == 0) {
throw new Exception("Expected " + m + " to be private");
}
if ((mod & Modifier.STATIC) != 0) {
throw new Exception("Expected " + m + " to be instance method");
}
m.setAccessible(true);
for (int i = 1; i < 200; i++) {
if (!m.invoke(inst).equals(EXPECTED)) {
throw new Exception("Expected " + EXPECTED + " from " + m);
}
}
System.out.println("Passed.");
}
}