undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,110 @@
/*
* Copyright (c) 2007, 2016, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/**
* @test
* @key headful
* @bug 6603887
* @summary Verifies that drawImage with bg color works correctly for ICM image
* @run main/othervm DrawImageBgTest
* @run main/othervm -Dsun.java2d.pmoffscreen=true DrawImageBgTest
*/
import java.awt.Color;
import java.awt.Graphics;
import java.awt.GraphicsConfiguration;
import java.awt.GraphicsEnvironment;
import java.awt.image.BufferedImage;
import java.awt.image.IndexColorModel;
import java.awt.image.VolatileImage;
import java.awt.image.WritableRaster;
import java.io.File;
import java.io.IOException;
import javax.imageio.ImageIO;
public class DrawImageBgTest {
public static void main(String[] args) {
GraphicsConfiguration gc =
GraphicsEnvironment.getLocalGraphicsEnvironment().
getDefaultScreenDevice().getDefaultConfiguration();
if (gc.getColorModel().getPixelSize() <= 8) {
System.out.println("8-bit color model, test considered passed");
return;
}
/*
* Set up images:
* 1.) VolatileImge for rendering to,
* 2.) BufferedImage for reading back the contents of the VI
* 3.) The image triggering the problem
*/
VolatileImage vImg = null;
BufferedImage readBackBImg;
// create a BITMASK ICM such that the transparent color is
// tr. black (and it's the first in the color map so a buffered image
// created with this ICM is transparent
byte r[] = { 0x00, (byte)0xff};
byte g[] = { 0x00, (byte)0xff};
byte b[] = { 0x00, (byte)0xff};
IndexColorModel icm = new IndexColorModel(8, 2, r, g, b, 0);
WritableRaster wr = icm.createCompatibleWritableRaster(25, 25);
BufferedImage tImg = new BufferedImage(icm, wr, false, null);
do {
if (vImg == null ||
vImg.validate(gc) == VolatileImage.IMAGE_INCOMPATIBLE)
{
vImg = gc.createCompatibleVolatileImage(tImg.getWidth(),
tImg.getHeight());
}
Graphics viG = vImg.getGraphics();
viG.setColor(Color.red);
viG.fillRect(0, 0, vImg.getWidth(), vImg.getHeight());
viG.drawImage(tImg, 0, 0, Color.green, null);
viG.fillRect(0, 0, vImg.getWidth(), vImg.getHeight());
viG.drawImage(tImg, 0, 0, Color.white, null);
readBackBImg = vImg.getSnapshot();
} while (vImg.contentsLost());
for (int x = 0; x < readBackBImg.getWidth(); x++) {
for (int y = 0; y < readBackBImg.getHeight(); y++) {
int currPixel = readBackBImg.getRGB(x, y);
if (currPixel != Color.white.getRGB()) {
String fileName = "DrawImageBgTest.png";
try {
ImageIO.write(readBackBImg, "png", new File(fileName));
System.err.println("Dumped image to " + fileName);
} catch (IOException ex) {}
throw new
RuntimeException("Test Failed: found wrong color: 0x"+
Integer.toHexString(currPixel));
}
}
}
System.out.println("Test Passed.");
}
}

View file

@ -0,0 +1,149 @@
/*
* Copyright (c) 2005, 2025, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
import java.awt.Color;
import java.awt.Component;
import java.awt.Dimension;
import java.awt.EventQueue;
import java.awt.Frame;
import java.awt.Graphics;
import java.awt.Point;
import java.awt.Rectangle;
import java.awt.Robot;
import java.awt.Toolkit;
import java.awt.image.BufferedImage;
import java.awt.image.VolatileImage;
/*
*
*
* Tests that the use of shared memory pixmaps isn't broken:
* create a VolatileImage, fill it with red color, copy it to the screen
* make sure the pixels on the screen are red.
*
* Note that we force the use of shared memory pixmaps in the shell script.
*/
public class SharedMemoryPixmapsTest {
static final int IMAGE_SIZE = 200;
static volatile boolean show = false;
static volatile Frame testFrame;
static volatile TestComponent testComponent;
static void createUI() {
testFrame = new Frame("SharedMemoryPixmapsTest");
testComponent = new TestComponent();
testFrame.add(testComponent);
testFrame.setUndecorated(true);
testFrame.setResizable(false);
testFrame.pack();
testFrame.setLocationRelativeTo(null);
testFrame.setVisible(true);
testFrame.toFront();
}
public static void main(String[] args) throws Exception {
for (String s : args) {
if ("-show".equals(s)) {
show = true;
} else {
System.err.println("Usage: SharedMemoryPixmapsTest [-show]");
}
}
EventQueue.invokeAndWait(SharedMemoryPixmapsTest::createUI);
if (testRendering()) {
System.err.println("Test Passed");
} else {
System.err.println("Test Failed");
}
if (!show && testFrame != null) {
EventQueue.invokeAndWait(testFrame::dispose);
}
}
static boolean testRendering() throws Exception {
Robot r = new Robot();
r.waitForIdle();
r.delay(2000);
Point p = testComponent.getLocationOnScreen();
BufferedImage b =
r.createScreenCapture(new Rectangle(p, testComponent.getPreferredSize()));
for (int y = 20; y < b.getHeight() - 40; y++) {
for (int x = 20; x < b.getWidth() - 40; x++) {
if (b.getRGB(x, y) != Color.red.getRGB()) {
System.err.println("Incorrect pixel at "
+ x + "x" + y + " : " +
Integer.toHexString(b.getRGB(x, y)));
if (show) {
return false;
}
System.err.println("Test Failed");
System.exit(1);
}
}
}
return true;
}
static class TestComponent extends Component {
VolatileImage vi = null;
void initVI() {
int res;
if (vi == null) {
res = VolatileImage.IMAGE_INCOMPATIBLE;
} else {
res = vi.validate(getGraphicsConfiguration());
}
if (res == VolatileImage.IMAGE_INCOMPATIBLE) {
if (vi != null) vi.flush();
vi = createVolatileImage(IMAGE_SIZE, IMAGE_SIZE);
vi.validate(getGraphicsConfiguration());
res = VolatileImage.IMAGE_RESTORED;
}
if (res == VolatileImage.IMAGE_RESTORED) {
Graphics vig = vi.getGraphics();
vig.setColor(Color.red);
vig.fillRect(0, 0, vi.getWidth(), vi.getHeight());
vig.dispose();
}
}
@Override
public synchronized void paint(Graphics g) {
do {
g.setColor(Color.green);
g.fillRect(0, 0, getWidth(), getHeight());
vi = null;
initVI();
g.drawImage(vi, 0, 0, null);
} while (vi.contentsLost());
}
@Override
public Dimension getPreferredSize() {
return new Dimension(IMAGE_SIZE, IMAGE_SIZE);
}
}
}

View file

@ -0,0 +1,50 @@
#!/bin/sh
#
# Copyright (c) 2005, 2025, Oracle and/or its affiliates. All rights reserved.
# DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
#
# This code is free software; you can redistribute it and/or modify it
# under the terms of the GNU General Public License version 2 only, as
# published by the Free Software Foundation.
#
# This code is distributed in the hope that it will be useful, but WITHOUT
# ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
# FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
# version 2 for more details (a copy is included in the LICENSE file that
# accompanied this code).
#
# You should have received a copy of the GNU General Public License version
# 2 along with this work; if not, write to the Free Software Foundation,
# Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
#
# Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
# or visit www.oracle.com if you need additional information or have any
# questions.
#
# @test
# @key headful
# @bug 6363434 6588884
# @summary Verify that shared memory pixmaps are not broken
# by filling a VolatileImage with red color and copying it
# to the screen.
# Note that we force the use of shared memory pixmaps.
echo "TESTJAVA=${TESTJAVA}"
echo "TESTSRC=${TESTSRC}"
echo "TESTCLASSES=${TESTCLASSES}"
cd ${TESTSRC}
${TESTJAVA}/bin/javac -d ${TESTCLASSES} SharedMemoryPixmapsTest.java
cd ${TESTCLASSES}
J2D_PIXMAPS=shared
export J2D_PIXMAPS
${TESTJAVA}/bin/java ${TESTVMOPTS} SharedMemoryPixmapsTest
if [ $? -ne 0 ]; then
echo "Test failed!"
exit 1
fi
exit 0