whitepaper: re-add 10 missing entries + 11 new defects this session, count 578→590; rebuild PDF

This commit is contained in:
russell@unturf.com 2026-03-27 22:18:31 -04:00
parent e4ee168b1e
commit 2e4f7807d5
401 changed files with 3914 additions and 114 deletions

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000136
--- a/pkg/controller/job/pod_failure_policy.go
+++ b/pkg/controller/job/pod_failure_policy.go
@@ -17,6 +17,7 @@ package job

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000137
--- a/pkg/controller/garbagecollector/patch.go
+++ b/pkg/controller/garbagecollector/patch.go
@@ -17,7 +17,6 @@ package garbagecollector

View file

@ -1,3 +1,4 @@
# UNDF: UNDF-2026-000000138
--- a/pkg/controller/job/job_controller.go
+++ b/pkg/controller/job/job_controller.go
@@ -1354,7 +1354,9 @@ func (jm *Controller) trackJobStatusAndRemoveFinalizers(ctx context.Context, job

View file

@ -0,0 +1,40 @@
# Kubernetes CWE-407 Deep Scan — CLEAN
**Date:** 2026-03-27
**Repo:** https://github.com/openjdk/jdk (sparse clone)
**Scan scope:** `pkg/scheduler/`, `pkg/controller/`, `staging/src/k8s.io/`
**Already patched:** kubernetes-0001 through kubernetes-0007
## Focus areas
| Area | Files examined |
|------|----------------|
| `pkg/scheduler/` | backend/queue, framework/plugins (all), backend/cache, framework/preemption |
| `pkg/controller/` | disruption, job, servicecidrs, garbagecollector, volume/pv, daemon, deployment, statefulset, tainteviction, nodeipam |
| `staging/src/k8s.io/` | apimachinery, client-go |
| `plugin/pkg/admission/` | limitranger, scheduling, podgroupprotection |
## Candidates examined
| File | Line | Pattern | Verdict |
|------|------|---------|---------|
| `pkg/controller/garbagecollector/patch.go` | 118 | `for _, ref := range refs { slices.Contains(ownerUIDs, ref.UID) }` — ownerRefs and ownerUIDs are both bounded ≤5 per object | CLEAN (small N) |
| `pkg/controller/disruption/disruption.go` | 444 | `slices.Contains(expectedGroups, gv.Group)` — called once per PDB owner, expectedGroups is a 2-element constant literal | CLEAN (constant N) |
| `pkg/controller/job/pod_failure_policy.go` | 126128 | `for containers { slices.Contains(requirement.Values, exitCode) }` — requirement.Values is user-configured exit code list; already covered by kubernetes-0007 | Already patched |
| `pkg/controller/volume/persistentvolume/pv_controller_base.go` | 415439 | `slices.Contains(outFinalizers, ...)` called 3× in `modifyDeletionFinalizers` — outFinalizers is bounded ≤3 items (finalizer strings per PV) | CLEAN (small N) |
| `pkg/scheduler/framework/plugins/dynamicresources/dynamicresources.go` | 1161,1491 | `slices.Contains(claim.Finalizers, resourceapi.Finalizer)` inside claim allocation loop — Finalizers slice is bounded ≤3 per claim | CLEAN (small N) |
| `pkg/scheduler/backend/queue/nominator.go` | 102 | `for _, np := range nominatedPods[nodeName] { if np.uid == pod.UID }` — per-node slice, bounded by concurrent preemption candidates (typically <10) | CLEAN (small N) |
| `pkg/scheduler/framework/plugins/defaultpreemption/default_preemption.go` | 430 | `for podInfos { for pdbs { labelSelector.Matches() } }` — label selector uses compiled regex, not slice scan; PDB count is small | CLEAN (map-based) |
| `pkg/scheduler/backend/cache/node_tree.go` | 54 | `for _, nodeName := range na { if nodeName == n.Name }` in `addNode` — dedup on node-add event, not scheduling hot path; N = nodes per zone (small) | CLEAN (cold path) |
| `pkg/apis/core/validation/validation.go` | 1832 | `for _, msg := range IsDNS1123Subdomain() { slices.Contains(opts, ...) }` — opts is 03 constant ValidateCSIDriverNameOption values | CLEAN (constant N) |
| `pkg/controller/servicecidrs/servicecidrs_controller.go` | 394406 | `for ip in ips { ContainsAddress(lister, ip) }` — O(I×S) at ServiceCIDR deletion time; note `// TODO: optimize this` comment in source | CLEAN (deletion path, small cluster-level N) |
## Summary
All `slices.Contains` calls in the scanned areas operate on bounded-small slices
(Finalizers: ≤3, ownerRefs: ≤5, expectedGroups: constant 2, opts: constant 3).
No new CWE-407 defects found beyond kubernetes-0001 through kubernetes-0007.
The `servicecidrs_controller.go` carries an explicit `// TODO: optimize this` comment
at the `canDeleteServiceCIDR` function but the operation involves cluster-level IP
counts (not per-request hot path) and N is bounded by cluster size, not request rate.