undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,125 @@
/*
* Copyright (c) 2001, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 4431020
* @summary On Windows 2000 we observed behaviour that reflects the underlying
* implementation :-
* 1. PortUnreachableException throw per underlying reset
* 2. No PUE throw for DatagramSocket.send
*/
import java.net.*;
public class Concurrent implements Runnable {
DatagramSocket s;
public void run() {
try {
byte b[] = new byte[512];
DatagramPacket p = new DatagramPacket(b, b.length);
int pue_count = 0;
while (true) {
try {
System.out.println("receive...");
s.receive(p);
} catch (PortUnreachableException pue) {
System.out.println("receive threw PortUnreachableException");
pue_count++;
}
System.out.println("receiver sleeping");
Thread.currentThread().sleep(100*pue_count);
}
} catch (Exception e) { }
}
Concurrent(InetAddress ia, int port) throws Exception {
System.out.println("");
System.out.println("***");
System.out.println("Test Description:");
System.out.println(" - Block reader thread on receive");
System.out.println(" - Send datagrams to bad destination with wee pauses");
System.out.println(" - Observe which thread gets the PUE");
System.out.println("");
/*
* Create the datagram and connect it to destination
*/
s = new DatagramSocket();
s.connect(ia, port);
s.setSoTimeout(60000);
/*
* Start the reader thread
*/
Thread thr = new Thread(this);
thr.start();
Thread.currentThread().sleep(2000);
byte b[] = new byte[512];
DatagramPacket p = new DatagramPacket(b, b.length);
/*
* Send a bunch of packets to the destination
*/
for (int i=0; i<10; i++) {
try {
System.out.println("Sending...");
s.send(p);
} catch (PortUnreachableException e) {
System.out.println("send threw PortUnreachableException");
}
Thread.currentThread().sleep(100);
}
/*
* Give time for ICMP port unreachables to return
*/
Thread.currentThread().sleep(5000);
s.close();
}
public static void main(String args[]) throws Exception {
InetAddress ia;
int port;
if (args.length >= 2) {
ia = InetAddress.getByName(args[0]);
port = Integer.parseInt(args[1]);
} else {
ia = InetAddress.getLocalHost();
DatagramSocket s1 = new DatagramSocket();
port = s1.getLocalPort();
s1.close();
}
new Concurrent(ia, port);
}
}

View file

@ -0,0 +1,144 @@
/*
* Copyright (c) 2001, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 4431020
* @summary On Windows 2000 we observed behaviour that reflects the underlying
* implementation :-
* 1. PortUnreachableException throw per underlying reset
* 2. No PUE throw for DatagramSocket.send
*/
import java.net.*;
public class OneExceptionOnly {
static void doTest(InetAddress ia, int port, boolean testSend) throws Exception {
System.out.println("");
System.out.println("***");
System.out.println("Test Description:");
System.out.println(" - Send 10 datagrams to bad destination");
System.out.println(" - <wait a wee while>");
if (testSend) {
System.out.println(" - Send another datagram - should throw PUE or timeout");
} else {
System.out.println(" - Receive another datagram - should throw PUE or timeout");
}
System.out.println(" - Receive another receive - a SocketTimeoutException expected");
System.out.println("");
/*
* Create the datagram and connect it to destination
*/
DatagramSocket s1 = new DatagramSocket();
s1.connect(ia, port);
byte b[] = new byte[512];
DatagramPacket p = new DatagramPacket(b, b.length);
/*
* Send a bunch of packets to the destination
*/
int outstanding = 0;
for (int i=0; i<20; i++) {
try {
s1.send(p);
outstanding++;
} catch (PortUnreachableException e) {
/* PUE throw => assume none outstanding now */
outstanding = 0;
}
if (outstanding > 1) {
break;
}
}
if (outstanding < 1) {
System.out.println("Insufficient exceptions outstanding - Test Skipped (Passed).");
s1.close();
return;
}
/*
* Give time for ICMP port unreachables to return
*/
Thread.currentThread().sleep(5000);
/*
* The next send or receive should cause a PUE to be thrown
*/
boolean gotPUE = false;
boolean gotTimeout = false;
s1.setSoTimeout(2000);
try {
if (testSend) {
s1.send(p);
} else {
s1.receive(p);
}
} catch (PortUnreachableException pue) {
gotPUE = true;
System.out.println("Expected PortUnreachableException thrown - good!");
} catch (SocketTimeoutException exc) {
}
/*
* The next receive should timeout
*/
if (gotPUE) {
try {
s1.receive(p);
} catch (PortUnreachableException pue) {
throw new Exception("Unexpected PUE received - assumed that PUs would be consumed");
} catch (SocketTimeoutException exc) {
System.out.println("Expected SocketTimeoutException thrown - excellent! - Test Passed.");
}
} else {
System.out.println("Expected PUE not thrown - packets probably discarded (Passed).");
}
s1.close();
}
public static void main(String args[]) throws Exception {
InetAddress ia;
int port;
if (args.length >= 2) {
ia = InetAddress.getByName(args[0]);
port = Integer.parseInt(args[1]);
} else {
ia = InetAddress.getLocalHost();
DatagramSocket s1 = new DatagramSocket();
port = s1.getLocalPort();
s1.close();
}
doTest(ia, port, true);
doTest(ia, port, false);
}
}

View file

@ -0,0 +1,135 @@
/*
* Copyright (c) 2001, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/**
* @test
* @bug 4413768
* @summary Checking that PortUnreachableException is thrown when
* ICMP Port Unreachable is received.
*/
import java.net.*;
import java.util.Properties;
public class Test {
/*
* Return an available port
*/
int getPort() throws Exception {
DatagramSocket s = new DatagramSocket(0);
int port = s.getLocalPort();
s.close();
return port;
}
/*
* Perform test by sending to remote_host:port
* sendOnly => send datagram to host and expect PUE on subsequent
* send
* !sendOnly => send datagram to host and expect PUE on subsequent
* send or receive.
*/
void doTest(String remote_host, int port, boolean sendOnly) throws Exception {
System.out.println("***");
System.out.println("Test Description:");
System.out.println(" DatagramSocket.connect");
System.out.println(" Loop: DatagramSocket.send");
if (!sendOnly) {
System.out.println(" DatagramSocket.receive");
}
System.out.println("");
System.out.println("Test Run:");
InetAddress ia = InetAddress.getByName(remote_host);
DatagramSocket s = new DatagramSocket(0);
s.setSoTimeout(1000);
s.connect(ia, port);
byte[] b = "Hello".getBytes();
DatagramPacket p1 = new DatagramPacket(b, b.length, ia, port);
DatagramPacket p2 = new DatagramPacket(b, b.length);
int i = 0;
boolean gotPUE = false;
do {
System.out.println("Sending datagram to unreachable port...");
try {
s.send(p1);
} catch (PortUnreachableException e) {
System.out.println("DatagramSocket.send threw PUE");
gotPUE = true;
}
if (!gotPUE) {
Thread.currentThread().sleep(1000);
}
if (!sendOnly && !gotPUE) {
System.out.println("DatagramSocket.receive...");
try {
s.receive(p2);
} catch (PortUnreachableException e) {
System.out.println("DatagramSocket.receive threw PUE");
gotPUE = true;
} catch (SocketTimeoutException e) {
System.out.println("DatagramSocket.receive timed out - no PUE");
}
}
i++;
} while (i < 10 && !gotPUE);
if (!gotPUE) {
System.out.println("DatagramSocket.{send,receive} didn't throw " +
"PortUnreachableException - passing anyway!");
} else {
System.out.println(" Test passed.");
}
System.out.println("");
}
/*
* Perform tests via remote_host.
*/
Test(String remote_host) throws Exception {
int port = getPort();
doTest(remote_host, port, true);
doTest(remote_host, port, false);
}
public static void main(String args[]) throws Exception {
String remote_host = "localhost";
if (args.length > 0) {
remote_host = args[0];
}
new Test(remote_host);
}
}