undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,57 @@
/*
* Copyright (c) 2018, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 8208080
* @summary Tests DateFormatSymbols provider implementations
* @library provider
* @build provider/module-info provider/foo.DateFormatSymbolsProviderImpl
* @run main/othervm -Djava.locale.providers=SPI,CLDR DateFormatSymbolsProviderTests
*/
import java.text.DateFormatSymbols;
import java.util.Locale;
import java.util.Map;
/**
* Test DateFormatSymbolsProvider SPI with BCP47 U extensions
*/
public class DateFormatSymbolsProviderTests {
private static final Map<Locale, String> data = Map.of(
Locale.forLanguageTag("en-AA"), "foo",
Locale.forLanguageTag("en-US-u-rg-aazzzz"), "foo",
Locale.forLanguageTag("en-US-u-ca-japanese"), "bar"
);
public static void main(String... args) {
data.forEach((l, e) -> {
DateFormatSymbols dfs = DateFormatSymbols.getInstance(l);
String[] months = dfs.getMonths();
System.out.printf("January string for locale %s is %s.%n", l.toString(), months[0]);
if (!months[0].equals(e)) {
throw new RuntimeException("DateFormatSymbols provider is not called for" + l);
}
});
}
}

View file

@ -0,0 +1,52 @@
/*
* Copyright (c) 2017, 2025, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
*
* @test
* @bug 8176841 8354548
* @summary Tests LocaleNameProvider SPIs
* @library provider
* @build provider/module-info provider/foo.LocaleNameProviderImpl
* @run main/othervm -Djava.locale.providers=SPI LocaleNameProviderTests
*/
import java.util.Locale;
/**
* Test LocaleNameProvider SPI with BCP47 U extensions
*
* Verifies getUnicodeExtensionKey() and getUnicodeExtensionType() methods in
* LocaleNameProvider works.
*/
public class LocaleNameProviderTests {
private static final String expected = "foo (foo_ca=foo_japanese)";
public static void main(String... args) {
String name = Locale.forLanguageTag("foo-u-ca-japanese").getDisplayName(Locale.of("foo"));
if (!name.equals(expected)) {
throw new RuntimeException("Unicode extension key and/or type name(s) is incorrect. " +
"Expected: \"" + expected + "\", got: \"" + name + "\"");
}
}
}

View file

@ -0,0 +1,83 @@
/*
* Copyright (c) 2018, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
package foo;
import java.text.DateFormatSymbols;
import java.text.spi.DateFormatSymbolsProvider;
import java.util.Locale;
/*
* Implements DateFormatSymbolsProvider SPI, in order to check if the
* extensions work correctly.
*/
public class DateFormatSymbolsProviderImpl extends DateFormatSymbolsProvider {
private static final Locale AA = Locale.forLanguageTag("en-AA");
private static final Locale USJCAL = Locale.forLanguageTag("en-US-u-ca-japanese");
private static final Locale[] avail = {AA, Locale.US};
@Override
public Locale[] getAvailableLocales() {
return avail;
}
@Override
public boolean isSupportedLocale(Locale l) {
// Overriding to check the relation between
// isSupportedLocale/getAvailableLocales works correctly
if (l.equals(AA)) {
// delegates to super, as if isSupportedLocale didn't exist.
return super.isSupportedLocale(l);
} else {
return (l.equals(USJCAL));
}
}
@Override
public DateFormatSymbols getInstance(Locale l) {
return new MyDateFormatSymbols(l);
}
class MyDateFormatSymbols extends DateFormatSymbols {
Locale locale;
public MyDateFormatSymbols(Locale l) {
super(l);
locale = l;
}
@Override
public String[] getMonths() {
String[] ret = super.getMonths();
// replace the first item with some unique value
if (locale.stripExtensions().equals(AA)) {
ret[0] = "foo";
} else if (locale.equals(USJCAL)) {
ret[0] = "bar";
} else {
throw new RuntimeException("Unsupported locale: " + locale);
}
return ret;
}
}
}

View file

@ -0,0 +1,65 @@
/*
* Copyright (c) 2017, 2025, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
package foo;
import java.util.Locale;
import java.util.spi.LocaleNameProvider;
/*
* Implements LocaleNameProvider SPI, augmenting the default
* values for Unicode Locale Extension key/type names.
*/
public class LocaleNameProviderImpl extends LocaleNameProvider {
private static final Locale[] avail = {Locale.of("foo")};
@Override
public Locale[] getAvailableLocales() {
return avail;
}
@Override
public String getDisplayLanguage(String lang, Locale target) {
return null;
}
@Override
public String getDisplayCountry(String ctry, Locale target) {
return null;
}
@Override
public String getDisplayVariant(String vrnt, Locale target) {
return null;
}
@Override
public String getDisplayUnicodeExtensionKey(String key, Locale target) {
return "foo_" + key;
}
@Override
public String getDisplayUnicodeExtensionType(String extType, String key, Locale target) {
return "foo_" + key + "=foo_" + extType;
}
}

View file

@ -0,0 +1,28 @@
/*
* Copyright (c) 2017, 2018, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
module provider {
exports foo;
provides java.text.spi.DateFormatSymbolsProvider with foo.DateFormatSymbolsProviderImpl;
provides java.util.spi.LocaleNameProvider with foo.LocaleNameProviderImpl;
}