undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,119 @@
/*
* Copyright (c) 2003, 2024, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/* @test
* @bug 4507539
* @summary support using dynamic proxies as RMI stubs
* @author Ann Wollrath
*
* @build UseDynamicProxies UseDynamicProxies_Stub
* @run main/othervm/timeout=240 UseDynamicProxies true
* @run main/othervm/timeout=240 UseDynamicProxies
* false
*/
import java.io.IOException;
import java.lang.reflect.Proxy;
import java.rmi.Remote;
import java.rmi.server.RemoteObjectInvocationHandler;
import java.rmi.server.RemoteStub;
import java.rmi.server.UnicastRemoteObject;
public class UseDynamicProxies implements RemoteInterface {
public Object passObject(Object obj) {
return obj;
}
public int passInt(int x) {
return x;
}
public String passString(String string) {
return string;
}
public static void main(String[] args) throws Exception {
RemoteInterface server = null;
RemoteInterface proxy = null;
try {
System.setProperty("java.rmi.server.ignoreStubClasses", args[0]);
boolean ignoreStubClasses = Boolean.parseBoolean(args[0]);
System.err.println("export object");
server = new UseDynamicProxies();
proxy =
(RemoteInterface) UnicastRemoteObject.exportObject(server, 0);
System.err.println("proxy = " + proxy);
if (ignoreStubClasses) {
if (!Proxy.isProxyClass(proxy.getClass())) {
throw new RuntimeException(
"server proxy is not a dynamic proxy");
}
if (!(Proxy.getInvocationHandler(proxy) instanceof
RemoteObjectInvocationHandler))
{
throw new RuntimeException("invalid invocation handler");
}
} else if (!(proxy instanceof RemoteStub)) {
throw new RuntimeException(
"server proxy is not a RemoteStub");
}
System.err.println("invoke methods");
Object obj = proxy.passObject(proxy);
if (!proxy.equals(obj)) {
throw new RuntimeException("returned proxy not equal");
}
int x = proxy.passInt(53);
if (x != 53) {
throw new RuntimeException("returned int not equal");
}
String string = proxy.passString("test");
if (!string.equals("test")) {
throw new RuntimeException("returned string not equal");
}
System.err.println("TEST PASSED");
} finally {
if (proxy != null) {
UnicastRemoteObject.unexportObject(server, true);
}
}
}
}
interface RemoteInterface extends Remote {
Object passObject(Object obj) throws IOException;
int passInt(int x) throws IOException;
String passString(String string) throws IOException;
}

View file

@ -0,0 +1,102 @@
/*
* Copyright (c) 2003, 2008, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
// Stub class generated by rmic, do not edit.
// Contents subject to change without notice.
public final class UseDynamicProxies_Stub
extends java.rmi.server.RemoteStub
implements RemoteInterface
{
private static final long serialVersionUID = 2;
private static java.lang.reflect.Method $method_passInt_0;
private static java.lang.reflect.Method $method_passObject_1;
private static java.lang.reflect.Method $method_passString_2;
static {
try {
$method_passInt_0 = RemoteInterface.class.getMethod("passInt", new java.lang.Class[] {int.class});
$method_passObject_1 = RemoteInterface.class.getMethod("passObject", new java.lang.Class[] {java.lang.Object.class});
$method_passString_2 = RemoteInterface.class.getMethod("passString", new java.lang.Class[] {java.lang.String.class});
} catch (java.lang.NoSuchMethodException e) {
throw new java.lang.NoSuchMethodError(
"stub class initialization failed");
}
}
// constructors
public UseDynamicProxies_Stub(java.rmi.server.RemoteRef ref) {
super(ref);
}
// methods from remote interfaces
// implementation of passInt(int)
public int passInt(int $param_int_1)
throws java.io.IOException
{
try {
Object $result = ref.invoke(this, $method_passInt_0, new java.lang.Object[] {new java.lang.Integer($param_int_1)}, 8655249712495061761L);
return ((java.lang.Integer) $result).intValue();
} catch (java.lang.RuntimeException e) {
throw e;
} catch (java.io.IOException e) {
throw e;
} catch (java.lang.Exception e) {
throw new java.rmi.UnexpectedException("undeclared checked exception", e);
}
}
// implementation of passObject(Object)
public java.lang.Object passObject(java.lang.Object $param_Object_1)
throws java.io.IOException
{
try {
Object $result = ref.invoke(this, $method_passObject_1, new java.lang.Object[] {$param_Object_1}, 3074202549763602823L);
return ((java.lang.Object) $result);
} catch (java.lang.RuntimeException e) {
throw e;
} catch (java.io.IOException e) {
throw e;
} catch (java.lang.Exception e) {
throw new java.rmi.UnexpectedException("undeclared checked exception", e);
}
}
// implementation of passString(String)
public java.lang.String passString(java.lang.String $param_String_1)
throws java.io.IOException
{
try {
Object $result = ref.invoke(this, $method_passString_2, new java.lang.Object[] {$param_String_1}, 6627880292288702000L);
return ((java.lang.String) $result);
} catch (java.lang.RuntimeException e) {
throw e;
} catch (java.io.IOException e) {
throw e;
} catch (java.lang.Exception e) {
throw new java.rmi.UnexpectedException("undeclared checked exception", e);
}
}
}