whitepaper: re-add 10 missing entries + 11 new defects this session, count 578→590; rebuild PDF

This commit is contained in:
russell@unturf.com 2026-03-27 22:18:31 -04:00
parent e4ee168b1e
commit 2e4f7807d5
401 changed files with 3914 additions and 114 deletions

345
UNDF-REGISTRY.json Normal file
View file

@ -0,0 +1,345 @@
{
"activemq-0001": "UNDF-2026-000000001",
"allegro5-0001": "UNDF-2026-000000002",
"angelscript-0001": "UNDF-2026-000000003",
"angelscript-0003": "UNDF-2026-000000004",
"ansible-0001": "UNDF-2026-000000005",
"ansible-0002": "UNDF-2026-000000006",
"asterisk-0001": "UNDF-2026-000000007",
"asterisk-0002": "UNDF-2026-000000008",
"bazel-0001": "UNDF-2026-000000009",
"bazel-0002": "UNDF-2026-000000010",
"bevy-0001": "UNDF-2026-000000011",
"bird-0001": "UNDF-2026-000000012",
"bird-0002": "UNDF-2026-000000013",
"bottle-0001": "UNDF-2026-000000014",
"box2d-0001": "UNDF-2026-000000015",
"buildkit-0001": "UNDF-2026-000000016",
"bullet-0001": "UNDF-2026-000000017",
"bullet-0002": "UNDF-2026-000000018",
"bullet-0003": "UNDF-2026-000000019",
"caddy-0001": "UNDF-2026-000000020",
"cargo-0001": "UNDF-2026-000000021",
"cargo-0002": "UNDF-2026-000000022",
"cassandra-0001": "UNDF-2026-000000023",
"cassandra-0005": "UNDF-2026-000000024",
"celery-0001": "UNDF-2026-000000025",
"ceph-0001": "UNDF-2026-000000026",
"cfengine-0001": "UNDF-2026-000000027",
"cfengine-0002": "UNDF-2026-000000028",
"cfengine-0003": "UNDF-2026-000000029",
"cilium-0001": "UNDF-2026-000000030",
"clickhouse-0001": "UNDF-2026-000000031",
"cmake-0001": "UNDF-2026-000000032",
"cmake-0002": "UNDF-2026-000000033",
"cmake-0003": "UNDF-2026-000000034",
"cmake-0004": "UNDF-2026-000000035",
"cockroachdb-0001": "UNDF-2026-000000036",
"composer-0001": "UNDF-2026-000000037",
"composer-0002": "UNDF-2026-000000038",
"cpython-0001": "UNDF-2026-000000039",
"curl-0001": "UNDF-2026-000000040",
"dendrite-0001": "UNDF-2026-000000041",
"dendrite-0002": "UNDF-2026-000000042",
"diesel-0001": "UNDF-2026-000000043",
"diesel-0002": "UNDF-2026-000000044",
"diesel-0003": "UNDF-2026-000000045",
"distlib-0001": "UNDF-2026-000000046",
"django-0001": "UNDF-2026-000000047",
"django-0002": "UNDF-2026-000000048",
"django-0003": "UNDF-2026-000000049",
"doctrine-0001": "UNDF-2026-000000050",
"doctrine-0002": "UNDF-2026-000000051",
"doctrine-0003": "UNDF-2026-000000052",
"dovecot-0001": "UNDF-2026-000000053",
"dry-0001": "UNDF-2026-000000054",
"dry-0002": "UNDF-2026-000000055",
"duckdb-0001": "UNDF-2026-000000056",
"efcore-0001": "UNDF-2026-000000057",
"efcore-0002": "UNDF-2026-000000058",
"efcore-0003": "UNDF-2026-000000059",
"ejabberd-0001": "UNDF-2026-000000060",
"ejabberd-0002": "UNDF-2026-000000061",
"element-web-0001": "UNDF-2026-000000062",
"envoy-0001": "UNDF-2026-000000063",
"erlang-0001": "UNDF-2026-000000064",
"erlang-0003": "UNDF-2026-000000065",
"exposed-0001": "UNDF-2026-000000066",
"exposed-0002": "UNDF-2026-000000067",
"exposed-0003": "UNDF-2026-000000068",
"fastapi-0001": "UNDF-2026-000000069",
"ffmpeg-0001": "UNDF-2026-000000070",
"fiber-0001": "UNDF-2026-000000071",
"flink-0001": "UNDF-2026-000000072",
"freeswitch-0001": "UNDF-2026-000000073",
"frrouting-0001": "UNDF-2026-000000074",
"frrouting-0002": "UNDF-2026-000000075",
"gcc-0001": "UNDF-2026-000000076",
"gcc-0002": "UNDF-2026-000000077",
"ghc-0001": "UNDF-2026-000000078",
"ghc-0003": "UNDF-2026-000000079",
"gin-0001": "UNDF-2026-000000080",
"go-0001": "UNDF-2026-000000081",
"go-ethereum-0001": "UNDF-2026-000000082",
"godot-0001": "UNDF-2026-000000083",
"godot-0002": "UNDF-2026-000000084",
"godot-0003": "UNDF-2026-000000085",
"godot-0004": "UNDF-2026-000000086",
"gorm-0001": "UNDF-2026-000000087",
"gradle-0001": "UNDF-2026-000000088",
"gradle-0002": "UNDF-2026-000000089",
"grafana-0001": "UNDF-2026-000000090",
"grape-0001": "UNDF-2026-000000091",
"grape-0002": "UNDF-2026-000000092",
"grape-0003": "UNDF-2026-000000093",
"gstreamer-0001": "UNDF-2026-000000094",
"gyp-0001": "UNDF-2026-000000095",
"hadoop-0001": "UNDF-2026-000000096",
"hadoop-0002": "UNDF-2026-000000097",
"hadoop-0003": "UNDF-2026-000000098",
"hadoop-0004": "UNDF-2026-000000099",
"hanami-0001": "UNDF-2026-000000100",
"haproxy-0001": "UNDF-2026-000000101",
"hbase-0001": "UNDF-2026-000000102",
"hbase-0002": "UNDF-2026-000000103",
"helm-0001": "UNDF-2026-000000104",
"helm-0002": "UNDF-2026-000000105",
"helm-0003": "UNDF-2026-000000106",
"hibernate-0001": "UNDF-2026-000000107",
"hibernate-0002": "UNDF-2026-000000108",
"hibernate-0003": "UNDF-2026-000000109",
"hibernate-0004": "UNDF-2026-000000110",
"hibernate-0005": "UNDF-2026-000000111",
"hive-0001": "UNDF-2026-000000112",
"httpd-0001": "UNDF-2026-000000113",
"istio-0001": "UNDF-2026-000000114",
"jami-daemon-0001": "UNDF-2026-000000115",
"jami-daemon-0002": "UNDF-2026-000000116",
"javac-0001": "UNDF-2026-000000117",
"javac-0002": "UNDF-2026-000000118",
"javac-0003": "UNDF-2026-000000119",
"javac-0004": "UNDF-2026-000000120",
"javac-0005": "UNDF-2026-000000121",
"javac-0006": "UNDF-2026-000000122",
"javac-0007": "UNDF-2026-000000123",
"jenkins-0001": "UNDF-2026-000000124",
"jenkins-0002": "UNDF-2026-000000125",
"jetty-0001": "UNDF-2026-000000126",
"jitsi-videobridge-0001": "UNDF-2026-000000127",
"jitsi-videobridge-0002": "UNDF-2026-000000128",
"jitsi-videobridge-0003": "UNDF-2026-000000129",
"julia-0001": "UNDF-2026-000000130",
"kafka-0001": "UNDF-2026-000000131",
"keystone-0001": "UNDF-2026-000000132",
"kicad-0001": "UNDF-2026-000000133",
"kotlin-0001": "UNDF-2026-000000134",
"kotlin-0002": "UNDF-2026-000000135",
"kubernetes-0001": "UNDF-2026-000000136",
"kubernetes-0002": "UNDF-2026-000000137",
"kubernetes-0003": "UNDF-2026-000000138",
"libgdx-0001": "UNDF-2026-000000139",
"libgdx-0004": "UNDF-2026-000000140",
"libgit2-0001": "UNDF-2026-000000141",
"linkerd2-0001": "UNDF-2026-000000142",
"linphone-0001": "UNDF-2026-000000143",
"linux-0001": "UNDF-2026-000000144",
"linux-0002": "UNDF-2026-000000145",
"linux-0003": "UNDF-2026-000000146",
"linux-0004": "UNDF-2026-000000147",
"linux-0005": "UNDF-2026-000000148",
"linux-0006": "UNDF-2026-000000149",
"linux-0007": "UNDF-2026-000000150",
"linux-0008": "UNDF-2026-000000151",
"llvm-0001": "UNDF-2026-000000152",
"llvm-0002": "UNDF-2026-000000153",
"llvm-0003": "UNDF-2026-000000154",
"llvm-0004": "UNDF-2026-000000155",
"llvm-0005": "UNDF-2026-000000156",
"love2d-0001": "UNDF-2026-000000157",
"lua-0001": "UNDF-2026-000000158",
"luigi-0001": "UNDF-2026-000000159",
"mariadb-0001": "UNDF-2026-000000160",
"mariadb-0002": "UNDF-2026-000000161",
"mattermost-0001": "UNDF-2026-000000162",
"maven-0001": "UNDF-2026-000000163",
"maven-0003": "UNDF-2026-000000164",
"maven-0004": "UNDF-2026-000000165",
"maven-0005": "UNDF-2026-000000166",
"maven-0006": "UNDF-2026-000000167",
"maven-0007": "UNDF-2026-000000168",
"memcached-0001": "UNDF-2026-000000169",
"mesa-0001": "UNDF-2026-000000170",
"meson-0001": "UNDF-2026-000000171",
"moby-0001": "UNDF-2026-000000172",
"mongodb-0001": "UNDF-2026-000000173",
"mybatis-0001": "UNDF-2026-000000174",
"mysql-0001": "UNDF-2026-000000175",
"mysql-0002": "UNDF-2026-000000176",
"mysql-0003": "UNDF-2026-000000177",
"mysql-0004": "UNDF-2026-000000178",
"nats-server-0001": "UNDF-2026-000000179",
"nestjs-0001": "UNDF-2026-000000180",
"nestjs-0002": "UNDF-2026-000000181",
"networkx-0001": "UNDF-2026-000000182",
"neutron-0001": "UNDF-2026-000000183",
"neutron-0002": "UNDF-2026-000000184",
"nginx-0001": "UNDF-2026-000000185",
"ninja-0001": "UNDF-2026-000000186",
"nmap-0001": "UNDF-2026-000000187",
"nova-0001": "UNDF-2026-000000188",
"npm-0002": "UNDF-2026-000000189",
"octave-0001": "UNDF-2026-000000190",
"odl-0001": "UNDF-2026-000000191",
"odl-0002": "UNDF-2026-000000192",
"ogre-0001": "UNDF-2026-000000193",
"ogre-0002": "UNDF-2026-000000194",
"ogre-0003": "UNDF-2026-000000195",
"onos-0001": "UNDF-2026-000000196",
"onos-0002": "UNDF-2026-000000197",
"onos-0003": "UNDF-2026-000000198",
"openbsd-0001": "UNDF-2026-000000199",
"openbsd-0002": "UNDF-2026-000000200",
"opensmtpd-0001": "UNDF-2026-000000201",
"openssl-0001": "UNDF-2026-000000202",
"openssl-0002": "UNDF-2026-000000203",
"openvpn-0001": "UNDF-2026-000000204",
"otel-collector-0001": "UNDF-2026-000000205",
"ovs-0001": "UNDF-2026-000000206",
"panda3d-0001": "UNDF-2026-000000207",
"panda3d-0002": "UNDF-2026-000000208",
"peewee-0001": "UNDF-2026-000000209",
"perl5-0001": "UNDF-2026-000000210",
"phoenix-0001": "UNDF-2026-000000211",
"phoenix-0002": "UNDF-2026-000000212",
"php-0001": "UNDF-2026-000000213",
"php-0002": "UNDF-2026-000000214",
"pip-0001": "UNDF-2026-000000215",
"postfix-0001": "UNDF-2026-000000216",
"postfix-0002": "UNDF-2026-000000217",
"postgresql-0006": "UNDF-2026-000000218",
"postgresql-0007": "UNDF-2026-000000219",
"postgresql-0008": "UNDF-2026-000000220",
"postgresql-0009": "UNDF-2026-000000221",
"prefect-0001": "UNDF-2026-000000222",
"prefect-0002": "UNDF-2026-000000223",
"presto-0001": "UNDF-2026-000000224",
"prometheus-0001": "UNDF-2026-000000225",
"puppet-0001": "UNDF-2026-000000226",
"pygame-0001": "UNDF-2026-000000227",
"pylons-0001": "UNDF-2026-000000228",
"pylons-0002": "UNDF-2026-000000229",
"pylons-0003": "UNDF-2026-000000230",
"pyramid-0001": "UNDF-2026-000000231",
"pyramid-0002": "UNDF-2026-000000232",
"pyramid-0003": "UNDF-2026-000000233",
"pyramid-0004": "UNDF-2026-000000234",
"pyramid-0005": "UNDF-2026-000000235",
"r-source-0001": "UNDF-2026-000000236",
"rabbitmq-0001": "UNDF-2026-000000237",
"rabbitmq-0002": "UNDF-2026-000000238",
"rabbitmq-0003": "UNDF-2026-000000239",
"rabbitmq-0004": "UNDF-2026-000000240",
"rails-0001": "UNDF-2026-000000241",
"rails-0002": "UNDF-2026-000000242",
"rails-0003": "UNDF-2026-000000243",
"rails-0004": "UNDF-2026-000000244",
"rails-0005": "UNDF-2026-000000245",
"rails-0007": "UNDF-2026-000000246",
"rails-0008": "UNDF-2026-000000247",
"rails-0009": "UNDF-2026-000000248",
"rails-0010": "UNDF-2026-000000249",
"rails-0011": "UNDF-2026-000000250",
"rails-0012": "UNDF-2026-000000251",
"rails-0013": "UNDF-2026-000000252",
"rails-0014": "UNDF-2026-000000253",
"rails-0015": "UNDF-2026-000000254",
"rails-0016": "UNDF-2026-000000255",
"rails-0017": "UNDF-2026-000000256",
"rails-0018": "UNDF-2026-000000257",
"ray-0001": "UNDF-2026-000000258",
"raylib-0001": "UNDF-2026-000000259",
"redis-0001": "UNDF-2026-000000260",
"redis-0002": "UNDF-2026-000000261",
"redis-0003": "UNDF-2026-000000262",
"rocketchat-0001": "UNDF-2026-000000263",
"rocketchat-0002": "UNDF-2026-000000264",
"ruby-0001": "UNDF-2026-000000265",
"ruby-0002": "UNDF-2026-000000266",
"rustc-0001": "UNDF-2026-000000267",
"rustc-0003": "UNDF-2026-000000268",
"saltstack-0001": "UNDF-2026-000000269",
"scala-0001": "UNDF-2026-000000270",
"scala3-0001": "UNDF-2026-000000271",
"sdl2-0001": "UNDF-2026-000000272",
"sdl3-0001": "UNDF-2026-000000273",
"seaorm-0001": "UNDF-2026-000000274",
"seaorm-0002": "UNDF-2026-000000275",
"seaorm-0003": "UNDF-2026-000000276",
"seaorm-0004": "UNDF-2026-000000277",
"sequelize-0001": "UNDF-2026-000000278",
"sequelize-0002": "UNDF-2026-000000279",
"sfml-0001": "UNDF-2026-000000280",
"sfml-0004": "UNDF-2026-000000281",
"sfml-0005": "UNDF-2026-000000282",
"simplex-chat-0001": "UNDF-2026-000000283",
"simplex-chat-0002": "UNDF-2026-000000284",
"simplex-chat-0003": "UNDF-2026-000000285",
"sinatra-0001": "UNDF-2026-000000286",
"sinatra-0002": "UNDF-2026-000000287",
"solc-0001": "UNDF-2026-000000288",
"solc-0002": "UNDF-2026-000000289",
"spark-0001": "UNDF-2026-000000290",
"spark-0003": "UNDF-2026-000000291",
"spidermonkey-0001": "UNDF-2026-000000292",
"spirv-cross-0001": "UNDF-2026-000000293",
"spirv-cross-0002": "UNDF-2026-000000294",
"spring-0001": "UNDF-2026-000000295",
"spring-0003": "UNDF-2026-000000296",
"sqlalchemy-0001": "UNDF-2026-000000297",
"sqlalchemy-0002": "UNDF-2026-000000298",
"sqlite-0001": "UNDF-2026-000000299",
"sqlite-0003": "UNDF-2026-000000300",
"storm-0001": "UNDF-2026-000000301",
"storm-0002": "UNDF-2026-000000302",
"substrate-0001": "UNDF-2026-000000303",
"substrate-0002": "UNDF-2026-000000304",
"synapse-0001": "UNDF-2026-000000305",
"synapse-0002": "UNDF-2026-000000306",
"terraform-0001": "UNDF-2026-000000307",
"terraform-0002": "UNDF-2026-000000308",
"threejs-0001": "UNDF-2026-000000309",
"threejs-0002": "UNDF-2026-000000310",
"threejs-0003": "UNDF-2026-000000311",
"tidb-0001": "UNDF-2026-000000312",
"tidb-0002": "UNDF-2026-000000313",
"tinkerpop-0001": "UNDF-2026-000000314",
"tomcat-0001": "UNDF-2026-000000315",
"tor-0001": "UNDF-2026-000000316",
"tor-0002": "UNDF-2026-000000317",
"tor-0003": "UNDF-2026-000000318",
"typeorm-0001": "UNDF-2026-000000319",
"typeorm-0002": "UNDF-2026-000000320",
"typeorm-0003": "UNDF-2026-000000321",
"typescript-0001": "UNDF-2026-000000322",
"unrealircd-0001": "UNDF-2026-000000323",
"unrealircd-0002": "UNDF-2026-000000324",
"v8-0001": "UNDF-2026-000000325",
"valkey-0001": "UNDF-2026-000000326",
"valkey-0002": "UNDF-2026-000000327",
"valkey-0003": "UNDF-2026-000000328",
"varnish-0001": "UNDF-2026-000000329",
"victoria-metrics-0001": "UNDF-2026-000000330",
"vlc-0001": "UNDF-2026-000000331",
"vtk-0001": "UNDF-2026-000000332",
"vtk-0002": "UNDF-2026-000000333",
"wasmer-0001": "UNDF-2026-000000334",
"wasmer-0002": "UNDF-2026-000000335",
"wasmtime-0001": "UNDF-2026-000000336",
"wasmtime-0002": "UNDF-2026-000000337",
"webpack-0001": "UNDF-2026-000000338",
"webpack-0002": "UNDF-2026-000000339",
"weechat-0001": "UNDF-2026-000000340",
"wireshark-0001": "UNDF-2026-000000341",
"zeek-0001": "UNDF-2026-000000342",
"zookeeper-0001": "UNDF-2026-000000343"
}

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000001
--- a/activemq-broker/src/main/java/org/apache/activemq/broker/region/Topic.java
+++ b/activemq-broker/src/main/java/org/apache/activemq/broker/region/Topic.java
@@ -21,6 +21,8 @@ import java.util.ArrayList;

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000002
--- a/addons/audio/kcm_sample.c
+++ b/addons/audio/kcm_sample.c
@@ -38,6 +38,8 @@ typedef struct {

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000003
Fixes angelscript-0001/0002: FindNewOwnerForSharedType/Func — IndexOf on per-module
type arrays inside module loop. The engine itself has a TODO comment acknowledging this.

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000004
Fixes angelscript-0003: CompileSwitch — caseValues.IndexOf() O(n) inside while loop
over switch cases. Duplicate detection is O(n²) for switch statements.

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000005
From: agent-blackops <blackops@unturf.com>
Date: Thu, 26 Mar 2026 00:00:00 +0000
Subject: [PATCH] playbook/role: replace seen list with identity-keyed set in get_vars()

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000006
From: agent-blackops <blackops@unturf.com>
Date: Thu, 26 Mar 2026 00:00:00 +0000
Subject: [PATCH] playbook/role: maintain parallel _collections_set for O(1) membership in _load_role_data()

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000007
--- a/apps/app_meetme.c
+++ b/apps/app_meetme.c
@@ -944,7 +944,17 @@ static char *complete_meetmecmd_mute_kick(const char *line, const char *word, in

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000008
--- a/apps/confbridge/include/confbridge.h
+++ b/apps/confbridge/include/confbridge.h
@@ -258,6 +258,10 @@ struct confbridge_conference {

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000009
--- a/src/main/java/com/google/devtools/build/lib/analysis/AspectCollection.java
+++ b/src/main/java/com/google/devtools/build/lib/analysis/AspectCollection.java
@@ -27,7 +27,6 @@

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000010
--- a/src/main/java/com/google/devtools/build/lib/analysis/AspectCollection.java
+++ b/src/main/java/com/google/devtools/build/lib/analysis/AspectCollection.java
@@ -27,6 +27,7 @@

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000011
Fixes bevy-0001: slab_allocator — O(E×L×S) Vec::iter().position() in free_empty_slabs().
--- a/crates/bevy_render/src/slab_allocator.rs

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000012
From: CWE-407 patch <patch@undefect.com>
Date: 2026-03-26
Subject: [PATCH] ospf: replace SPF candidate sorted-list with binary min-heap

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000013
From: CWE-407 patch <patch@undefect.com>
Date: 2026-03-26
Subject: [PATCH] nest/a-set: replace linear scan in *_set_contains with bsearch

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000014
Fixes bottle-0001: Route.all_plugins() — skiplist is a list, scanned 4× per plugin iteration.
--- a/bottle.py

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000015
--- a/src/broad_phase.h
+++ b/src/broad_phase.h
@@ -30,8 +30,9 @@ typedef struct b2BroadPhase

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000016
diff --git a/cache/remotecache/v1/cachestorage.go b/cache/remotecache/v1/cachestorage.go
index 7ea9fa1..patched 100644
--- a/cache/remotecache/v1/cachestorage.go

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000017
--- a/src/BulletCollision/CollisionDispatch/btGhostObject.h
+++ b/src/BulletCollision/CollisionDispatch/btGhostObject.h
@@ -25,6 +25,7 @@ subject to the following restrictions:

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000018
--- a/src/BulletCollision/CollisionDispatch/btCollisionObject.h
+++ b/src/BulletCollision/CollisionDispatch/btCollisionObject.h
@@ -23,6 +23,7 @@ subject to the following restrictions:

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000019
--- a/src/BulletCollision/BroadphaseCollision/btOverlappingPairCache.cpp
+++ b/src/BulletCollision/BroadphaseCollision/btOverlappingPairCache.cpp
@@ -444,13 +444,11 @@ void* btSortedOverlappingPairCache::removeOverlappingPair(btBroadphaseProxy* pro

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000020
--- a/modules/caddyhttp/reverseproxy/selectionpolicies.go
+++ b/modules/caddyhttp/reverseproxy/selectionpolicies.go
@@ -1,6 +1,7 @@

View file

@ -0,0 +1,24 @@
# Caddy matchers.go + upstreams.go — CWE-407 scan result: CLEAN
## Scan date: 2026-03-27
## Files scanned
| File | Finding |
|------|---------|
| `modules/caddyhttp/matchers.go` | CLEAN — see notes |
| `modules/caddyhttp/reverseproxy/upstreams.go` | CLEAN |
## Notes
**matchers.go `matchHeaders`**: Contains a triple-nested loop O(H×A×V) where
H = header fields in matcher config, A = actual header values per field,
V = allowed values per field. All three dimensions are practically bounded
to small constants by HTTP header semantics (H ≤ 10, A ≤ 5, V ≤ 5).
This does not produce unbounded O(N²) growth and does not meet the CWE-407
threshold.
**upstreams.go**: SRV/A record loops use map-based O(1) lookups
(`srvs[suAddr]`, `aAaaa[auStr]`). No nested linear membership tests found.
**Verdict: CLEAN** (beyond caddy-0001 which is already patched)

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000021
diff --git a/src/cargo/ops/tree/mod.rs b/src/cargo/ops/tree/mod.rs
index 4344daa..4c60bc9 100644
--- a/src/cargo/ops/tree/mod.rs

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000022
diff --git a/src/cargo/ops/tree/graph.rs b/src/cargo/ops/tree/graph.rs
--- a/src/cargo/ops/tree/graph.rs
+++ b/src/cargo/ops/tree/graph.rs

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000023
--- a/src/java/org/apache/cassandra/gms/Gossiper.java
+++ b/src/java/org/apache/cassandra/gms/Gossiper.java
@@ -144,10 +144,14 @@ public class Gossiper implements IFailureDetectionEventListener, GossiperMBean,

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000024
--- a/src/java/org/apache/cassandra/cql3/terms/Lists.java
+++ b/src/java/org/apache/cassandra/cql3/terms/Lists.java
@@ -519,15 +519,15 @@ public abstract class Lists

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000025
From: agent-blackops <blackops@unturf.com>
Date: Fri, 27 Mar 2026 00:00:00 +0000
Subject: [PATCH] canvas: replace list membership test in append_to_list_option with set mirror

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000026
diff --git a/src/osd/OSDMap.cc b/src/osd/OSDMap.cc
--- a/src/osd/OSDMap.cc
+++ b/src/osd/OSDMap.cc

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000027
diff --git a/libpromises/evalfunction.c b/libpromises/evalfunction.c
index a1b2c3d..e4f5a6b 100644
--- a/libpromises/evalfunction.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000028
diff --git a/libpromises/evalfunction.c b/libpromises/evalfunction.c
index a1b2c3d..f7c8d9e 100644
--- a/libpromises/evalfunction.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000029
diff --git a/libpromises/evalfunction.c b/libpromises/evalfunction.c
index a1b2c3d..c2e1f7b 100644
--- a/libpromises/evalfunction.c

Binary file not shown.

Binary file not shown.

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000030
diff --git a/pkg/k8s/slim/k8s/apis/labels/selector.go b/pkg/k8s/slim/k8s/apis/labels/selector.go
index 1234567..abcdef0 100644
--- a/pkg/k8s/slim/k8s/apis/labels/selector.go

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000031
diff --git a/src/Analyzer/ColumnTransformers.cpp b/src/Analyzer/ColumnTransformers.cpp
index d5484e6c..5632ba67 100644
--- a/src/Analyzer/ColumnTransformers.cpp

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000032
diff --git a/Source/cmComputeLinkDepends.cxx b/Source/cmComputeLinkDepends.cxx
index d2da7ec..0d785a1 100644
--- a/Source/cmComputeLinkDepends.cxx

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000033
diff --git a/Source/cmComputeLinkInformation.cxx b/Source/cmComputeLinkInformation.cxx
index abc1234..def5678 100644
--- a/Source/cmComputeLinkInformation.cxx

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000034
diff --git a/Source/cmComputeLinkInformation.h b/Source/cmComputeLinkInformation.h
index abc1234..def5678 100644
--- a/Source/cmComputeLinkInformation.h

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000035
diff --git a/Source/cmTarget.cxx b/Source/cmTarget.cxx
index abc1234..def5678 100644
--- a/Source/cmTarget.cxx

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000036
--- a/pkg/sql/opt/exec/execbuilder/builder.go
+++ b/pkg/sql/opt/exec/execbuilder/builder.go
@@ -197,16 +197,28 @@ type IndexesUsed struct {

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000037
diff --git a/src/Composer/Repository/RepositoryUtils.php b/src/Composer/Repository/RepositoryUtils.php
index e6960c6..9538b7b 100644
--- a/src/Composer/Repository/RepositoryUtils.php

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000038
diff --git a/src/Composer/Repository/InstalledRepository.php b/src/Composer/Repository/InstalledRepository.php
index 3520fde..3cbe917 100644
--- a/src/Composer/Repository/InstalledRepository.php

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000039
diff --git a/Lib/pkgutil.py b/Lib/pkgutil.py
--- a/Lib/pkgutil.py
+++ b/Lib/pkgutil.py

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000040
diff --git a/lib/cookie.h b/lib/cookie.h
index abc1234..def5678 100644
--- a/lib/cookie.h

Binary file not shown.

Binary file not shown.

Binary file not shown.

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000041
--- a/syncapi/storage/shared/storage_consumer.go
+++ b/syncapi/storage/shared/storage_consumer.go
@@ -238,14 +238,15 @@ func (d *Database) updateRoomIDsWithEventTypes(ctx context.Context, txn *sql.Tx

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000042
--- a/roomserver/internal/perform/perform_backfill.go
+++ b/roomserver/internal/perform/perform_backfill.go
@@ -430,17 +430,20 @@ func (b *backfillRequester) ServersAtEvent(ctx context.Context, roomID, eventID string) []spec.ServerName {

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000043
diff --git a/diesel/src/sqlite/connection/row.rs b/diesel/src/sqlite/connection/row.rs
index xxxxxxx..xxxxxxx 100644
--- a/diesel/src/sqlite/connection/row.rs

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000044
diff --git a/diesel/src/sqlite/connection/owned_row.rs b/diesel/src/sqlite/connection/owned_row.rs
index xxxxxxx..xxxxxxx 100644
--- a/diesel/src/sqlite/connection/owned_row.rs

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000045
diff --git a/diesel/src/mysql/connection/stmt/iterator.rs b/diesel/src/mysql/connection/stmt/iterator.rs
index xxxxxxx..xxxxxxx 100644
--- a/diesel/src/mysql/connection/stmt/iterator.rs

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000046
diff --git a/distlib/util.py b/distlib/util.py
index 0d5bd7a..f5f3c83 100644
--- a/distlib/util.py

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000047
Fixes django-0001: Model.from_db() — field_names list membership test inside concrete_fields loop.
--- a/django/db/models/base.py

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000048
Fixes django-0002: Serializer.serialize() — selected_fields list membership tested 3× per field per object.
--- a/django/core/serializers/base.py

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000049
Fixes django-0003/0004: Model._check_column_name_clashes() list dedup + RawQuerySet.resolve_model_init_order() columns list scans.
--- a/django/db/models/base.py

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000050
Fixes doctrine-0001: AbstractHydrator `discriminatorValues` in_array per row.
--- a/src/Doctrine/ORM/Internal/Hydration/AbstractHydrator.php

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000051
Fixes doctrine-0002: ClassMetadata::addSubClass in_array dedup.
--- a/src/Doctrine/ORM/Mapping/ClassMetadata.php

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000052
Fixes doctrine-0003: SqlWalker::walkObjectExpression in_array per field.
--- a/src/Doctrine/ORM/Query/SqlWalker.php

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000053
--- a/src/doveadm/dsync/dsync-mailbox-import.c
+++ b/src/doveadm/dsync/dsync-mailbox-import.c
@@ -1334,21 +1334,38 @@ dsync_mail_change_have_keyword(const struct dsync_mail_change *change,

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000054
--- a/Source/Dry/UI/ListView.h
+++ b/Source/Dry/UI/ListView.h
@@ -... ListView class members

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000055
--- a/Source/Dry/Core/Object.cpp
+++ b/Source/Dry/Core/Object.cpp
@@ -269,12 +269,16 @@ void Object::UnsubscribeFromAllEventsExcept(const PODVector<StringHash>& exceptions, bool onlyUserData)

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000056
diff --git a/src/include/duckdb/planner/binder.hpp b/src/include/duckdb/planner/binder.hpp
index 31e7489..7b31df0 100644
--- a/src/include/duckdb/planner/binder.hpp

View file

@ -0,0 +1,99 @@
# eclipse-jdt-0001: minimalErasedCandidates BFS work-queue ArrayList.contains O(N²)
**CWE-407** — Inefficient Algorithmic Complexity
**Severity:** HIGH
**Status:** PATCHED (patch below)
## Location
`org.eclipse.jdt.core.compiler.batch/src/org/eclipse/jdt/internal/compiler/lookup/Scope.java`
Method: `minimalErasedCandidates(TypeBinding[], Map<TypeBinding,Object>)`
Lines: **4273, 42954383** (current HEAD)
## Root Cause
`typesToVisit` is declared as `new ArrayList<>()` (line 4273).
The BFS loop at line 4295 (`for (int i = 0; i < max; i++)`) expands the supertype
hierarchy by appending to `typesToVisit` while walking it. For every candidate
supertype it calls `typesToVisit.contains(superType)` to deduplicate — up to **5
times per iteration** (elementType, Serializable, Cloneable, Object, each
interface, superclass).
`ArrayList.contains` is O(N) linear scan. With N types in the common supertype
hierarchy the BFS performs O(N) contains checks per step × O(N) steps =
**O(N²) overall**.
This fires during every `lub()` / common-supertype computation, which is invoked:
- for every conditional/ternary expression (`? :`)
- for every multi-catch clause (`catch (A | B e)`)
- for every intersection cast
- for lambda return-type inference when multiple branches have different types
A class hierarchy with N=200 supertypes (achievable with deep interface diamond
graphs or generated code) produces 40 000 list scans where 200 HashMap lookups
would suffice.
## Defective Code
```java
// Scope.java line 4273
List<TypeBinding> typesToVisit = new ArrayList<>(); // <-- O(N) contains
// ... inside BFS at line 4295:
for (int i = 0; i < max; i++) {
...
if (!typesToVisit.contains(superType)) { // O(N) × O(N) = O(N²)
typesToVisit.add(superType);
max++;
}
}
```
## Fix
Replace the single `ArrayList` with a parallel `HashSet` used exclusively for
deduplication; the `ArrayList` is kept for ordered iteration (the method later
indexes into it).
```java
// PATCHED
List<TypeBinding> typesToVisit = new ArrayList<>();
Set<TypeBinding> visitedSet = new HashSet<>(); // O(1) contains
visitedSet.add(firstType);
// In the BFS loop, every !typesToVisit.contains(x) becomes:
if (visitedSet.add(x)) { // Set.add returns false if already present
typesToVisit.add(x);
max++;
}
```
`Set.add` returns `false` when the element is already present, giving O(1) dedup
while preserving the original ordered traversal semantics.
Note: `TypeBinding.equals` / `TypeBinding.hashCode` are already properly
implemented in the JDT codebase (identity-based via `IdentityHashMap` usage
elsewhere), so `HashSet<TypeBinding>` is safe here.
## Complexity Table
| Metric | Before (ArrayList) | After (HashSet dedup) |
|--------|-------------------|----------------------|
| Contains check | O(N) | O(1) |
| BFS total work | O(N²) | O(N) |
| Memory | O(N) | O(N) — one extra set |
## Speedup (measured in unit test, BRANCH=4)
| N (supertype count) | SLOW ops | FAST ops | Ratio |
|---------------------|----------|----------|-------|
| 50 | 4 870 | 184 | 26.5× |
| 100 | 19 770 | 384 | 51.5× |
| 200 | 79 570 | 784 | 101.5× |
| 500 | 498 970 | 1 984 | 251.5× |
## Affected Callers
- `Scope.lub(TypeBinding[])` — line 4176: every `? :` ternary in compiled code
- `Scope.lub(TypeBinding, TypeBinding)` — line 3749: pairwise common supertype
- Any flow-analysis pass that calls `lub` (exception merging, return type merging)

View file

@ -0,0 +1,129 @@
package unit;
import java.util.*;
/**
* eclipse-jdt-0001: minimalErasedCandidatesAlgorithm BFS work-queue dedup
*
* Demonstrates O(N²) ArrayList.contains vs O(N) HashSet.add dedup when
* building the supertype-hierarchy work-queue in Scope.minimalErasedCandidates.
*
* The real BFS (Scope.java ~4295-4383) walks a type's superinterfaces AND
* superclass, calling typesToVisit.contains() for each candidate. In a deep
* diamond interface graph each BFS step checks K candidates (K = branching
* factor), so total contains-calls = K * N steps * avg-list-size N/2 = O(K*N²).
*
* This test models K=4 candidates per step (one superclass + 3 interfaces),
* which matches the worst-case pattern in the Eclipse JDT source.
*
* SLOW: List<Integer> typesToVisit + typesToVisit.contains(x) O(N²) ops
* FAST: List + parallel HashSet visitedSet + visitedSet.add(x) O(N) ops
*/
public class MinimalErasedCandidatesAlgorithm {
// Branching factor: number of supertypes added per BFS node
// (mirrors: superclass + up to 3 interfaces in typical Java hierarchy)
private static final int BRANCH = 4;
// SLOW path (ArrayList dedup mirrors JDT defect)
// Each BFS step checks BRANCH candidate supertypes via typesToVisit.contains
static long slowBfs(int n) {
List<Integer> typesToVisit = new ArrayList<>();
typesToVisit.add(0);
int max = 1;
long ops = 0;
for (int i = 0; i < max && max < n; i++) {
int base = typesToVisit.get(i);
// Simulate checking BRANCH supertypes per BFS node
for (int k = 1; k <= BRANCH && max < n; k++) {
int candidate = base + k;
ops += typesToVisit.size(); // cost of ArrayList.contains
if (!typesToVisit.contains(candidate)) {
typesToVisit.add(candidate);
max++;
}
}
}
return ops;
}
// FAST path (HashSet dedup the fix)
static long fastBfs(int n) {
List<Integer> typesToVisit = new ArrayList<>();
Set<Integer> visitedSet = new HashSet<>();
typesToVisit.add(0);
visitedSet.add(0);
int max = 1;
long ops = 0;
for (int i = 0; i < max && max < n; i++) {
int base = typesToVisit.get(i);
for (int k = 1; k <= BRANCH && max < n; k++) {
int candidate = base + k;
ops++; // O(1) hash lookup cost
if (visitedSet.add(candidate)) {
typesToVisit.add(candidate);
max++;
}
}
}
return ops;
}
// Test harness
static class Result {
final String label;
final int n;
final long slowOps;
final long fastOps;
final boolean pass;
Result(String label, int n, long slowOps, long fastOps) {
this.label = label;
this.n = n;
this.slowOps = slowOps;
this.fastOps = fastOps;
double ratio = fastOps > 0 ? (double) slowOps / fastOps : slowOps;
this.pass = ratio >= 5.0;
}
}
public static void main(String[] args) {
int[] sizes = {50, 100, 200, 500};
List<Result> results = new ArrayList<>();
for (int n : sizes) {
long slow = slowBfs(n);
long fast = fastBfs(n);
results.add(new Result("N=" + n, n, slow, fast));
}
System.out.println("eclipse-jdt-0001 MinimalErasedCandidatesAlgorithm");
System.out.println("==================================================");
System.out.printf("%-8s %10s %10s %8s %s%n",
"N", "SLOW ops", "FAST ops", "Ratio", "PASS");
System.out.println("-".repeat(55));
int passed = 0;
int total = results.size();
for (Result r : results) {
double ratio = r.fastOps > 0 ? (double) r.slowOps / r.fastOps : r.slowOps;
String status = r.pass ? "PASS" : "FAIL";
System.out.printf("%-8s %10d %10d %8.1fx %s%n",
r.label, r.slowOps, r.fastOps, ratio, status);
if (r.pass) passed++;
}
System.out.println("-".repeat(55));
System.out.printf("%d/%d PASS%n", passed, total);
if (passed < total) {
System.exit(1);
}
}
}

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000057
diff --git a/src/EFCore/Metadata/Internal/PropertyExtensions.cs b/src/EFCore/Metadata/Internal/PropertyExtensions.cs
index xxxxxxx..xxxxxxx 100644
--- a/src/EFCore/Metadata/Internal/PropertyExtensions.cs

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000058
diff --git a/src/EFCore/Metadata/IReadOnlyProperty.cs b/src/EFCore/Metadata/IReadOnlyProperty.cs
index xxxxxxx..xxxxxxx 100644
--- a/src/EFCore/Metadata/IReadOnlyProperty.cs

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000059
diff --git a/src/EFCore/Metadata/Conventions/ForeignKeyPropertyDiscoveryConvention.cs b/src/EFCore/Metadata/Conventions/ForeignKeyPropertyDiscoveryConvention.cs
index xxxxxxx..xxxxxxx 100644
--- a/src/EFCore/Metadata/Conventions/ForeignKeyPropertyDiscoveryConvention.cs

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000060
--- a/src/mod_mam.erl
+++ b/src/mod_mam.erl
@@ -1021,14 +1021,14 @@ check_store_hint(Pkt) ->

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000061
--- a/src/mod_shared_roster.erl
+++ b/src/mod_shared_roster.erl
@@ -351,10 +351,10 @@ process_subscription(Direction, User, Server, JID, _Type, Acc) ->

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000062
--- a/apps/web/src/TextForEvent.tsx
+++ b/apps/web/src/TextForEvent.tsx
@@ -499,15 +499,12 @@ function textForPowerEvent(event: MatrixEvent, allowJSX: boolean, isHistoric: b

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000063
diff --git a/source/extensions/retry/host/previous_hosts/previous_hosts.h b/source/extensions/retry/host/previous_hosts/previous_hosts.h
index 1234567..abcdef0 100644
--- a/source/extensions/retry/host/previous_hosts/previous_hosts.h

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000064
diff --git a/lib/stdlib/src/digraph.erl b/lib/stdlib/src/digraph.erl
index a38d242..f6bce33 100644
--- a/lib/stdlib/src/digraph.erl

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000065
--- a/lib/kernel/src/code_server.erl
+++ b/lib/kernel/src/code_server.erl
@@ -598,14 +598,19 @@ merge_path(Path,IPath,Acc) ->

View file

@ -0,0 +1,38 @@
# etcd CWE-407 Deeper Scan — CLEAN
**Date:** 2026-03-27
**Repo:** https://github.com/etcd-io/etcd
**Scan scope:** `server/etcdserver/`, `server/storage/mvcc/`, `server/embed/`, `raft/`
**Prior status:** etcd-CLEAN.md confirmed no defects in initial scan
## Re-verification
Scanned for `slices.Contains`, `strings.Contains` (membership context), and any
`for ... range` loops with inner linear membership tests.
### Results
All `strings.Contains` calls in production code paths are substring checks on error
message strings or content-type headers — not slice membership tests. No method named
`slices.Contains` or `ContainsString` appears anywhere in `server/` or `raft/`
non-test source files.
The `strings.Contains` calls found:
| File | Usage |
|------|-------|
| `server/embed/config.go:1092` | Substring check on peer URL string for `"https://"` |
| `server/embed/serve.go:312` | Content-Type header substring match for gRPC detection |
| `server/etcdmain/etcd.go:144` | Error message substring check |
| `server/etcdserver/corrupt.go:606613` | Error message substring checks |
| `server/etcdserver/cluster_util.go:340343` | Error message substring checks |
| `server/etcdserver/api/v2store/watcher_hub.go:198` | Path prefix substring check |
| `server/storage/backend/verify.go:64` | Stack trace substring check |
None of these are slice membership tests inside scaling loops.
## Summary
etcd confirmed CLEAN. No new CWE-407 defects found in the deeper scan.
etcd's watcher machinery uses maps (`map[string]watcherSet`) and interval trees —
O(1) and O(log N) membership — throughout.

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000066
--- a/exposed-core/src/main/kotlin/org/jetbrains/exposed/v1/core/SchemaUtilityApi.kt
+++ b/exposed-core/src/main/kotlin/org/jetbrains/exposed/v1/core/SchemaUtilityApi.kt
@@ -77,14 +77,16 @@ abstract class SchemaUtilityApi {

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000067
--- a/exposed-core/src/main/kotlin/org/jetbrains/exposed/v1/core/statements/api/IdentifierManagerApi.kt
+++ b/exposed-core/src/main/kotlin/org/jetbrains/exposed/v1/core/statements/api/IdentifierManagerApi.kt
@@ -35,6 +35,10 @@ abstract class IdentifierManagerApi {

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000068
--- a/exposed-core/src/main/kotlin/org/jetbrains/exposed/v1/core/Table.kt
+++ b/exposed-core/src/main/kotlin/org/jetbrains/exposed/v1/core/Table.kt
@@ -1682,8 +1682,10 @@ open class Table(

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000069
--- a/fastapi/dependencies/utils.py
+++ b/fastapi/dependencies/utils.py
@@ -139,13 +139,13 @@ def _get_dependant_for_depends(

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000070
--- a/libavformat/utils.c
+++ b/libavformat/utils.c
@@ -131,22 +131,108 @@

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000071
--- a/app.go
+++ b/app.go
@@ -98,6 +98,8 @@ type App struct {

View file

@ -0,0 +1,33 @@
# fish — CLEAN
## Scan Date
2026-03-27
## Files Scanned
- `src/complete.rs` (completion dedup, wrap targets)
- `src/exec.rs` (process execution)
## Findings
No CWE-407 defects found. Fish shell has been rewritten in Rust and uses
appropriate data structures throughout.
### Completion dedup (`unique_completions_retaining_order`)
Uses `HashSet::insert()` for O(1) per-element dedup — correct.
### Completion tombstones (`COMPLETION_TOMBSTONES`)
`BTreeSet<WString>` — O(log N) lookup — not O(N). Correct.
### Wrap targets (`complete_add_wrapper`)
`Vec::contains()` on per-command wrapper list. The list is bounded by the
number of wraps registered for a single command (typically 1-5). Not a
cross-product loop. Correct.
### Verdict
CLEAN — no algorithmic complexity defects in scanned code paths.

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000072
--- a/flink-runtime/src/main/java/org/apache/flink/runtime/jobgraph/JobGraph.java
+++ b/flink-runtime/src/main/java/org/apache/flink/runtime/jobgraph/JobGraph.java
@@ -117,8 +117,8 @@

View file

@ -0,0 +1,99 @@
# flink-0005: DynamicPartitionPruningUtils — List.indexOf + List.contains O(A×F + K×A) → O(F + K)
## Metadata
- **Project**: Apache Flink
- **Component**: `flink-table/flink-table-planner/src/main/java/org/apache/flink/table/planner/utils/DynamicPartitionPruningUtils.java`
- **CWE**: CWE-407 (Inefficient Algorithmic Complexity)
- **Severity**: MEDIUM
- **Method**: `convertDppFactSide()` lines 325334
- **Hot path**: Query planning for every batch job using dynamic partition pruning (star-schema joins)
## Location
```
flink-table/flink-table-planner/src/main/java/org/apache/flink/table/planner/utils/DynamicPartitionPruningUtils.java
method: convertDppFactSide() lines 325334
```
## Defective code
```java
// O(A×F): indexOf on List<String> called A times — A = accepted filter fields, F = table columns
List<Integer> acceptedFieldIndices =
acceptedFilterFields.stream()
.map(f -> scan.getRowType().getFieldNames().indexOf(f)) // O(F) per field
.collect(Collectors.toList());
// O(K×A): List.contains() called K times — K = join keys, A = accepted field indices
List<Integer> dynamicFilteringFieldIndices = new ArrayList<>();
for (int i = 0; i < joinKeys.size(); ++i) {
if (acceptedFieldIndices.contains(joinKeys.get(i))) { // O(A) linear scan
dynamicFilteringFieldIndices.add(dimSideJoinKey.get(i));
}
}
```
### Why this is O(A×F + K×A)
**Part 1 — `indexOf` loop (line 327):**
`scan.getRowType().getFieldNames()` returns a `List<String>` of F field names. `.indexOf(f)` scans the list linearly → O(F) per call. Called once per accepted filter field (A calls) → total O(A×F).
**Part 2 — `contains` loop (line 331):**
`acceptedFieldIndices` is a `List<Integer>`. `.contains(joinKeys.get(i))` scans the list linearly → O(A) per call. Called once per join key (K calls) → total O(K×A).
For a wide partitioned table (F=200 columns, A=20 accepted fields, K=20 join keys):
- Part 1: 20 × 200 = 4,000 string comparisons
- Part 2: 20 × 20 = 400 integer comparisons
- **Total: 4,400 ops vs O(F + K) = 220 ops → ~20× overhead**
At F=500, A=50, K=50: **27,500 ops vs 550 ops → 50× overhead**.
## Fix
Build a `Map<String, Integer>` from field name → index once in O(F), then do O(1) lookups. Replace `acceptedFieldIndices` list with a `Set<Integer>` for O(1) membership tests.
```java
// O(F): build name→index map once
List<String> fieldNames = scan.getRowType().getFieldNames();
Map<String, Integer> fieldNameToIndex = new HashMap<>(fieldNames.size() * 2);
for (int i = 0; i < fieldNames.size(); i++) {
fieldNameToIndex.put(fieldNames.get(i), i);
}
// O(A): O(1) map lookup per field
Set<Integer> acceptedFieldIndexSet = new HashSet<>();
List<Integer> acceptedFieldIndices = new ArrayList<>();
for (String f : acceptedFilterFields) {
Integer idx = fieldNameToIndex.get(f); // O(1)
if (idx != null) {
acceptedFieldIndices.add(idx);
acceptedFieldIndexSet.add(idx);
}
}
// O(K): O(1) set lookup per join key
List<Integer> dynamicFilteringFieldIndices = new ArrayList<>();
for (int i = 0; i < joinKeys.size(); ++i) {
if (acceptedFieldIndexSet.contains(joinKeys.get(i))) { // O(1)
dynamicFilteringFieldIndices.add(dimSideJoinKey.get(i));
}
}
```
## Complexity analysis
| Scenario | Before (Part 1 + Part 2) | After |
|----------|--------------------------|-------|
| F=50, A=10, K=10 | 500 + 100 = 600 ops | 50 + 10 + 10 = 70 ops — 8.6× |
| F=100, A=20, K=20 | 2,000 + 400 = 2,400 ops | 100 + 20 + 20 = 140 ops — 17× |
| F=200, A=30, K=30 | 6,000 + 900 = 6,900 ops | 200 + 30 + 30 = 260 ops — 26.5× |
| F=500, A=50, K=50 | 25,000 + 2,500 = 27,500 ops | 500 + 50 + 50 = 600 ops — 45.8× |
## Notes
Dynamic partition pruning (DPP) is used in batch Flink jobs for star-schema queries
(e.g., TPC-DS queries). `convertDppFactSide` is called once per fact table scan during
query planning. Wide tables (typical in data warehouse workloads) with many partition
columns experience the most overhead.
This defect was present alongside a similar pattern: `acceptedFilterFields.stream().map(f -> getFieldNames().indexOf(f))` — both the building and querying phases are linear-scan based.

View file

@ -0,0 +1,326 @@
package unit;
import java.util.*;
/**
* CWE-407 unit test flink-0005
*
* DynamicPartitionPruningUtils.convertDppFactSide() uses:
* 1. List<String>.indexOf(f) inside a stream.map() O(A×F)
* 2. List<Integer>.contains() inside a for loop O(K×A)
*
* where A = accepted filter fields, F = total table columns, K = join keys.
*
* Fix: build a Map<String,Integer> once in O(F), use Set<Integer> for membership in O(1).
*
* No JUnit. Run:
* javac -d . FlinkDynamicPartitionPruningTest.java
* java -ea unit.FlinkDynamicPartitionPruningTest
*/
public class FlinkDynamicPartitionPruningTest {
// ---------------------------------------------------------------------------
// SLOW path: simulates defective DynamicPartitionPruningUtils.convertDppFactSide()
//
// acceptedFieldIndices = acceptedFilterFields.stream()
// .map(f -> fieldNames.indexOf(f)) // O(F) per field
// .collect(toList());
//
// for (int i = 0; i < joinKeys.size(); ++i) {
// if (acceptedFieldIndices.contains(joinKeys.get(i))) // O(A) per key
// result.add(dimSideJoinKey.get(i));
// }
//
// Returns: (result indices, op count)
// ---------------------------------------------------------------------------
static long[] slowConvertDpp(
List<String> fieldNames,
List<String> acceptedFilterFields,
List<Integer> joinKeys,
List<Integer> dimSideJoinKey) {
long ops = 0;
// Part 1: indexOf O(A × F)
List<Integer> acceptedFieldIndices = new ArrayList<>();
for (String f : acceptedFilterFields) {
for (int i = 0; i < fieldNames.size(); i++) {
ops++;
if (fieldNames.get(i).equals(f)) {
acceptedFieldIndices.add(i);
break;
}
}
}
// Part 2: List.contains O(K × A)
List<Integer> result = new ArrayList<>();
for (int i = 0; i < joinKeys.size(); ++i) {
int key = joinKeys.get(i);
for (int accepted : acceptedFieldIndices) {
ops++;
if (accepted == key) {
result.add(dimSideJoinKey.get(i));
break;
}
}
}
return new long[]{result.size(), ops};
}
// ---------------------------------------------------------------------------
// FAST path: Map<String,Integer> + Set<Integer>
//
// Map<String,Integer> nameToIdx = build once from fieldNames O(F)
// Set<Integer> acceptedSet = acceptedFilterFields.stream()
// .map(nameToIdx::get) O(A)
// .collect(toSet())
//
// for (int i = 0; i < joinKeys.size(); ++i) {
// if (acceptedSet.contains(joinKeys.get(i))) O(1)
// result.add(dimSideJoinKey.get(i));
// }
//
// Returns: (result indices, op count)
// ---------------------------------------------------------------------------
static long[] fastConvertDpp(
List<String> fieldNames,
List<String> acceptedFilterFields,
List<Integer> joinKeys,
List<Integer> dimSideJoinKey) {
long ops = 0;
// Build nameindex map: O(F)
Map<String, Integer> nameToIdx = new HashMap<>(fieldNames.size() * 2);
for (int i = 0; i < fieldNames.size(); i++) {
nameToIdx.put(fieldNames.get(i), i);
ops++; // one write per field
}
// Build accepted set: O(A)
Set<Integer> acceptedSet = new HashSet<>();
List<Integer> acceptedFieldIndices = new ArrayList<>();
for (String f : acceptedFilterFields) {
Integer idx = nameToIdx.get(f); // O(1)
ops++;
if (idx != null) {
acceptedSet.add(idx);
acceptedFieldIndices.add(idx);
}
}
// Membership test: O(K)
List<Integer> result = new ArrayList<>();
for (int i = 0; i < joinKeys.size(); ++i) {
ops++; // O(1) set lookup
if (acceptedSet.contains(joinKeys.get(i))) {
result.add(dimSideJoinKey.get(i));
}
}
return new long[]{result.size(), ops};
}
// ---------------------------------------------------------------------------
// Build test data
// ---------------------------------------------------------------------------
/** Generate fieldNames = ["col_0", "col_1", ..., "col_{F-1}"] */
static List<String> buildFieldNames(int F) {
List<String> names = new ArrayList<>(F);
for (int i = 0; i < F; i++) names.add("col_" + i);
return names;
}
/**
* Select A evenly-spaced field names from fieldNames as the accepted filter fields.
* Also build joinKeys as indices into fieldNames (same set), and dimSideJoinKey as identity.
*/
static Object[] buildScenario(int F, int A, int K) {
List<String> fieldNames = buildFieldNames(F);
// acceptedFilterFields: A evenly-spaced field names
List<String> accepted = new ArrayList<>(A);
for (int i = 0; i < A; i++) {
int idx = (int) ((long) i * F / A);
accepted.add(fieldNames.get(idx));
}
// joinKeys: K evenly-spaced indices into fieldNames (subset overlapping with accepted)
List<Integer> joinKeys = new ArrayList<>(K);
List<Integer> dimSideJoinKey = new ArrayList<>(K);
for (int i = 0; i < K; i++) {
int idx = (int) ((long) i * F / K);
joinKeys.add(idx);
dimSideJoinKey.add(i * 10); // arbitrary dim-side key
}
return new Object[]{fieldNames, accepted, joinKeys, dimSideJoinKey};
}
// ---------------------------------------------------------------------------
// Test helpers
// ---------------------------------------------------------------------------
static void test(String name, boolean cond) {
if (!cond) throw new AssertionError("FAIL: " + name);
System.out.println("PASS: " + name);
}
// ---------------------------------------------------------------------------
// Main
// ---------------------------------------------------------------------------
@SuppressWarnings("unchecked")
public static void main(String[] args) {
System.out.println("=== flink-0005: DynamicPartitionPruningUtils indexOf+contains O(A*F+K*A) ===");
System.out.println();
// T1: correctness small scenario F=20, A=5, K=5
{
Object[] s = buildScenario(20, 5, 5);
List<String> fn = (List<String>) s[0];
List<String> af = (List<String>) s[1];
List<Integer> jk = (List<Integer>) s[2];
List<Integer> dk = (List<Integer>) s[3];
long[] slow = slowConvertDpp(fn, af, jk, dk);
long[] fast = fastConvertDpp(fn, af, jk, dk);
test("T1: slow and fast return same result count (F=20,A=5,K=5)",
slow[0] == fast[0]);
System.out.printf("T1: result=%d slow-ops=%d fast-ops=%d%n",
slow[0], slow[1], fast[1]);
}
// T2: correctness larger scenario F=100, A=20, K=20
{
Object[] s = buildScenario(100, 20, 20);
List<String> fn = (List<String>) s[0];
List<String> af = (List<String>) s[1];
List<Integer> jk = (List<Integer>) s[2];
List<Integer> dk = (List<Integer>) s[3];
long[] slow = slowConvertDpp(fn, af, jk, dk);
long[] fast = fastConvertDpp(fn, af, jk, dk);
test("T2: slow and fast return same result count (F=100,A=20,K=20)",
slow[0] == fast[0]);
}
// T3: op count comparison F=100, A=30, K=30
// slow: O(A*F + K*A) = 30*100 + 30*30 = 3000 + 900 = 3900
// fast: O(F + A + K) = 100 + 30 + 30 = 160
{
int F = 100, A = 30, K = 30;
Object[] s = buildScenario(F, A, K);
List<String> fn = (List<String>) s[0];
List<String> af = (List<String>) s[1];
List<Integer> jk = (List<Integer>) s[2];
List<Integer> dk = (List<Integer>) s[3];
long[] slow = slowConvertDpp(fn, af, jk, dk);
long[] fast = fastConvertDpp(fn, af, jk, dk);
System.out.printf("T3: F=%d A=%d K=%d — slow-ops=%d fast-ops=%d ratio=%.1fx%n",
F, A, K, slow[1], fast[1], (double) slow[1] / fast[1]);
test("T3: slow ops > fast ops (F=100, A=30, K=30)", slow[1] > fast[1]);
test("T3: slow ops >= A*F/2 (lower bound for O(A*F))", slow[1] >= (long) A * F / 2);
test("T3: fast ops <= F + A + K + 10 (linear bound)", fast[1] <= F + A + K + 10);
double ratio = (double) slow[1] / fast[1];
test("T3: speedup >= 5x at F=100,A=30,K=30", ratio >= 5.0);
}
// T4: scaling doubling F should ~2x slow Part 1, ~1x fast
{
int A = 20, K = 20;
int F1 = 100, F2 = 200;
Object[] s1 = buildScenario(F1, A, K);
Object[] s2 = buildScenario(F2, A, K);
long[] slowF1 = slowConvertDpp(
(List<String>) s1[0], (List<String>) s1[1],
(List<Integer>) s1[2], (List<Integer>) s1[3]);
long[] slowF2 = slowConvertDpp(
(List<String>) s2[0], (List<String>) s2[1],
(List<Integer>) s2[2], (List<Integer>) s2[3]);
long[] fastF1 = fastConvertDpp(
(List<String>) s1[0], (List<String>) s1[1],
(List<Integer>) s1[2], (List<Integer>) s1[3]);
long[] fastF2 = fastConvertDpp(
(List<String>) s2[0], (List<String>) s2[1],
(List<Integer>) s2[2], (List<Integer>) s2[3]);
double slowRatio = (double) slowF2[1] / slowF1[1];
double fastRatio = (double) fastF2[1] / fastF1[1];
System.out.printf("T4: F=%d slow=%d fast=%d%n", F1, slowF1[1], fastF1[1]);
System.out.printf("T4: F=%d slow=%d fast=%d%n", F2, slowF2[1], fastF2[1]);
System.out.printf("T4: slow ratio=%.2f (expect ~2.0 for O(F)), fast ratio=%.2f%n",
slowRatio, fastRatio);
test("T4: slow ops grow with F (ratio >= 1.5)", slowRatio >= 1.5);
test("T4: fast ops grow with F but much slower (ratio <= slowRatio)",
fastRatio <= slowRatio);
}
// T5: large scenario measure speedup at F=500, A=50, K=50
{
int F = 500, A = 50, K = 50;
Object[] s = buildScenario(F, A, K);
List<String> fn = (List<String>) s[0];
List<String> af = (List<String>) s[1];
List<Integer> jk = (List<Integer>) s[2];
List<Integer> dk = (List<Integer>) s[3];
long[] slow = slowConvertDpp(fn, af, jk, dk);
long[] fast = fastConvertDpp(fn, af, jk, dk);
double ratio = (double) slow[1] / fast[1];
System.out.printf("T5: F=%d A=%d K=%d — slow-ops=%d fast-ops=%d speedup=%.1fx%n",
F, A, K, slow[1], fast[1], ratio);
test("T5: slow ops >= A*F/2 (O(A*F) lower bound)", slow[1] >= (long) A * F / 2);
test("T5: fast ops <= F + A*2 + K*2 (O(F+A+K) bound)",
fast[1] <= F + A * 2 + K * 2);
test("T5: speedup >= 10x at F=500,A=50,K=50", ratio >= 10.0);
test("T5: results match", slow[0] == fast[0]);
}
// T6: wall-clock at F=1000, A=100, K=100
{
int F = 1000, A = 100, K = 100;
Object[] s = buildScenario(F, A, K);
List<String> fn = (List<String>) s[0];
List<String> af = (List<String>) s[1];
List<Integer> jk = (List<Integer>) s[2];
List<Integer> dk = (List<Integer>) s[3];
long t0 = System.nanoTime();
long[] slow = slowConvertDpp(fn, af, jk, dk);
long slowNs = System.nanoTime() - t0;
t0 = System.nanoTime();
long[] fast = fastConvertDpp(fn, af, jk, dk);
long fastNs = System.nanoTime() - t0;
double speedup = (double) slowNs / Math.max(fastNs, 1);
System.out.printf("T6: F=%d A=%d K=%d — slow=%.3fms fast=%.3fms speedup=%.1fx%n",
F, A, K, slowNs / 1e6, fastNs / 1e6, speedup);
long[] slow2 = slowConvertDpp(fn, af, jk, dk);
long[] fast2 = fastConvertDpp(fn, af, jk, dk);
test("T6: results match (F=1000,A=100,K=100)", slow[0] == fast[0]);
test("T6: slow ops >= A*F/2", slow2[1] >= (long) A * F / 2);
}
System.out.println();
System.out.println("6/6 PASS — flink-0005: DynamicPartitionPruningUtils " +
"indexOf+contains O(A*F + K*A) → HashMap+HashSet O(F + A + K)");
}
}

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000073
diff --git a/src/mod/applications/mod_conference/mod_conference.c b/src/mod/applications/mod_conference/mod_conference.c
index 1234567..abcdef0 100644
--- a/src/mod/applications/mod_conference/mod_conference.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000074
diff --git a/ospfd/ospf_ti_lfa.c b/ospfd/ospf_ti_lfa.c
index 9b8b2fd..21fb960 100644
--- a/ospfd/ospf_ti_lfa.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000075
diff --git a/ospfd/ospf_spf.c b/ospfd/ospf_spf.c
index a1b2c43..7f3e2d1 100644
--- a/ospfd/ospf_spf.c

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000076
diff --git a/gcc/gcov.cc b/gcc/gcov.cc
index 6256caa..5965e16 100644
--- a/gcc/gcov.cc

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000077
diff --git a/gcc/gimple-range-path.cc b/gcc/gimple-range-path.cc
index d3e4f5a..c6b7d8e 100644
--- a/gcc/gimple-range-path.cc

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000079
diff --git a/compiler/GHC/Data/Graph/Ops.hs b/compiler/GHC/Data/Graph/Ops.hs
index dc90b9e..16e097a 100644
--- a/compiler/GHC/Data/Graph/Ops.hs

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000078
diff --git a/compiler/GHC/Data/Graph/Directed/Internal.hs b/compiler/GHC/Data/Graph/Directed/Internal.hs
index 159e1ff..c560954 100644
--- a/compiler/GHC/Data/Graph/Directed/Internal.hs

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000080
--- a/gin.go
+++ b/gin.go
@@ -181,6 +181,7 @@ type Engine struct {

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000082
--- a/eth/filters/filter.go
+++ b/eth/filters/filter.go
@@ -501,21 +501,32 @@ func bloomFilter(bloom types.Bloom, addresses []common.Address, topics [][]common.Hash) bool {

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000081
diff --git a/src/cmd/compile/internal/types2/infer.go b/src/cmd/compile/internal/types2/infer.go
index eeefb117..cwe407fix 100644
--- a/src/cmd/compile/internal/types2/infer.go

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000083
--- a/scene/main/scene_tree.h
+++ b/scene/main/scene_tree.h
@@ -117,6 +117,7 @@ class SceneTree : public MainLoop {

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000084
--- a/modules/godot_physics_2d/godot_body_2d.h
+++ b/modules/godot_physics_2d/godot_body_2d.h
@@ -118,6 +118,7 @@ class GodotBody2D : public GodotCollisionObject2D {

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000085
--- a/modules/godot_physics_3d/godot_body_3d.h
+++ b/modules/godot_physics_3d/godot_body_3d.h
@@ -114,6 +114,7 @@ class GodotBody3D : public GodotCollisionObject3D {

Some files were not shown because too many files have changed in this diff Show more