diff --git a/UNDF-REGISTRY.json b/UNDF-REGISTRY.json index 7ea103462..d3073700d 100644 --- a/UNDF-REGISTRY.json +++ b/UNDF-REGISTRY.json @@ -167,7 +167,6 @@ "maven-0005": "UNDF-2026-000000166", "maven-0006": "UNDF-2026-000000167", "maven-0007": "UNDF-2026-000000168", - "memcached-0001": "UNDF-2026-000000169", "mesa-0001": "UNDF-2026-000000170", "meson-0001": "UNDF-2026-000000171", "moby-0001": "UNDF-2026-000000172", @@ -346,17 +345,13 @@ "actix-web-0001": "UNDF-2026-000000345", "actix-web-0002": "UNDF-2026-000000346", "airflow-0001": "UNDF-2026-000000347", - "ant-0001": "UNDF-2026-000000348", "argo-workflows-0001": "UNDF-2026-000000349", "artemis-0001": "UNDF-2026-000000350", "asterisk-0003": "UNDF-2026-000000351", - "axum-0001": "UNDF-2026-000000352", - "beam-0001": "UNDF-2026-000000353", "binutils-0001": "UNDF-2026-000000354", "bird-0003": "UNDF-2026-000000355", "bird-0004": "UNDF-2026-000000356", "bitcoin-0001": "UNDF-2026-000000357", - "buck2-0001": "UNDF-2026-000000358", "bun-0001": "UNDF-2026-000000359", "camel-0001": "UNDF-2026-000000360", "celery-0002": "UNDF-2026-000000361", @@ -364,7 +359,6 @@ "cilium-0002": "UNDF-2026-000000363", "cilium-0003": "UNDF-2026-000000364", "cilium-0004": "UNDF-2026-000000365", - "clojure-0001": "UNDF-2026-000000366", "consul-0001": "UNDF-2026-000000367", "containerd-0001": "UNDF-2026-000000368", "crystal-0001": "UNDF-2026-000000369", @@ -374,7 +368,6 @@ "dart-0001": "UNDF-2026-000000373", "dart-0002": "UNDF-2026-000000374", "dart-0003": "UNDF-2026-000000375", - "deno-0001": "UNDF-2026-000000376", "dgraph-0001": "UNDF-2026-000000377", "django-0005": "UNDF-2026-000000378", "django-0006": "UNDF-2026-000000379", @@ -390,27 +383,20 @@ "emacs-0002": "UNDF-2026-000000389", "envoy-0002": "UNDF-2026-000000390", "envoy-0003": "UNDF-2026-000000391", - "etcd-0001": "UNDF-2026-000000392", "express-0001": "UNDF-2026-000000393", - "fish-0001": "UNDF-2026-000000394", "flink-0002": "UNDF-2026-000000395", "flink-0003": "UNDF-2026-000000396", "flink-0004": "UNDF-2026-000000397", "flink-0005": "UNDF-2026-000000398", - "flutter-0001": "UNDF-2026-000000399", "foundationdb-0001": "UNDF-2026-000000400", "frrouting-0003": "UNDF-2026-000000401", "frrouting-0004": "UNDF-2026-000000402", - "gdb-0001": "UNDF-2026-000000403", - "glib-0001": "UNDF-2026-000000404", - "graal-0001": "UNDF-2026-000000405", "grafana-0002": "UNDF-2026-000000406", "graphhopper-0001": "UNDF-2026-000000407", "graphhopper-0002": "UNDF-2026-000000408", "groovy-0001": "UNDF-2026-000000409", "groovy-0002": "UNDF-2026-000000410", "grpc-0001": "UNDF-2026-000000411", - "gunicorn-0001": "UNDF-2026-000000412", "haproxy-0002": "UNDF-2026-000000413", "haproxy-0003": "UNDF-2026-000000414", "hazelcast-0001": "UNDF-2026-000000415", @@ -422,9 +408,7 @@ "hudi-0001": "UNDF-2026-000000421", "hudi-0002": "UNDF-2026-000000422", "hudi-0003": "UNDF-2026-000000423", - "hypercorn-0001": "UNDF-2026-000000424", "iceberg-0001": "UNDF-2026-000000425", - "intellij-0001": "UNDF-2026-000000426", "istio-0002": "UNDF-2026-000000427", "istio-0003": "UNDF-2026-000000428", "jami-daemon": "UNDF-2026-000000429", @@ -449,7 +433,6 @@ "leveldb-0001": "UNDF-2026-000000448", "libgdx-0002": "UNDF-2026-000000449", "libgdx-0003": "UNDF-2026-000000450", - "lighttpd-0001": "UNDF-2026-000000451", "linkerd2-0002": "UNDF-2026-000000452", "lldb-0001": "UNDF-2026-000000453", "lmdb-0001": "UNDF-2026-000000454", @@ -462,12 +445,9 @@ "micronaut-0001": "UNDF-2026-000000461", "micronaut-0002": "UNDF-2026-000000462", "micronaut-0003": "UNDF-2026-000000463", - "mlflow-0001": "UNDF-2026-000000464", "mongodb-0008": "UNDF-2026-000000465", "nats-0001": "UNDF-2026-000000466", "neo4j-0001": "UNDF-2026-000000467", - "neovim-0001": "UNDF-2026-000000468", - "netty-0001": "UNDF-2026-000000469", "nginx-0002": "UNDF-2026-000000470", "nginx-0003": "UNDF-2026-000000471", "nifi-0001": "UNDF-2026-000000472", @@ -482,7 +462,6 @@ "octave-0002": "UNDF-2026-000000481", "open3d-0001": "UNDF-2026-000000482", "open3d-0002": "UNDF-2026-000000483", - "openbgpd-0001": "UNDF-2026-000000484", "opencv-0001": "UNDF-2026-000000485", "opencv-0002": "UNDF-2026-000000486", "opensearch-0001": "UNDF-2026-000000487", @@ -493,7 +472,6 @@ "opentofu-0001": "UNDF-2026-000000492", "opentofu-0002": "UNDF-2026-000000493", "optuna-0001": "UNDF-2026-000000494", - "osrm-0001": "UNDF-2026-000000495", "otel-collector": "UNDF-2026-000000496", "pandas-0001": "UNDF-2026-000000497", "php-0003": "UNDF-2026-000000498", @@ -526,7 +504,6 @@ "ros2-0001": "UNDF-2026-000000525", "ros2-0002": "UNDF-2026-000000526", "rustc-0004": "UNDF-2026-000000527", - "samza-0001": "UNDF-2026-000000528", "scylladb-0001": "UNDF-2026-000000529", "signal-server": "UNDF-2026-000000530", "simplex-chat": "UNDF-2026-000000531", @@ -548,11 +525,9 @@ "systemd-0001": "UNDF-2026-000000547", "systemd-0002": "UNDF-2026-000000548", "tcl-0001": "UNDF-2026-000000549", - "tcpdump-0001": "UNDF-2026-000000550", "tensorflow-0001": "UNDF-2026-000000551", "threejs-0006": "UNDF-2026-000000552", "thrift-0001": "UNDF-2026-000000553", - "tikv-0001": "UNDF-2026-000000554", "tokio-0001": "UNDF-2026-000000555", "tomcat-0002": "UNDF-2026-000000556", "traefik-0001": "UNDF-2026-000000557", @@ -560,7 +535,6 @@ "traefik-0003": "UNDF-2026-000000559", "trino-0001": "UNDF-2026-000000560", "undertow-0001": "UNDF-2026-000000561", - "uvicorn-0001": "UNDF-2026-000000562", "uwsgi-0001": "UNDF-2026-000000563", "v8-0002": "UNDF-2026-000000564", "v8-0003": "UNDF-2026-000000565", @@ -571,13 +545,10 @@ "vertx-0001": "UNDF-2026-000000570", "vim-0001": "UNDF-2026-000000571", "vim-0002": "UNDF-2026-000000572", - "waitress-0001": "UNDF-2026-000000573", "weechat-0002": "UNDF-2026-000000574", "wireguard-tools": "UNDF-2026-000000575", "wolfssl-0001": "UNDF-2026-000000576", "yugabyte-0001": "UNDF-2026-000000577", - "zig-0001": "UNDF-2026-000000578", - "zsh-0001": "UNDF-2026-000000579", "zulip-0001": "UNDF-2026-000000580", "bazel-0003": "UNDF-2026-000000581", "curl-0002": "UNDF-2026-000000582", @@ -592,5 +563,8 @@ "libvirt-0001": "UNDF-2026-000000591", "libvirt-0002": "UNDF-2026-000000592", "v8-0004": "UNDF-2026-000000593", - "xen-0001": "UNDF-2026-000000594" + "xen-0001": "UNDF-2026-000000594", + "onos-0004": "UNDF-2026-000000595", + "networkx-0002": "UNDF-2026-000000169", + "memcached-0001": "UNDF-2026-000000348" } diff --git a/defects/networkx/patch/nx-0002-kcutsets-seen-frozenset.patch b/defects/networkx/patch/nx-0002-kcutsets-seen-frozenset.patch new file mode 100644 index 000000000..f70467b6e --- /dev/null +++ b/defects/networkx/patch/nx-0002-kcutsets-seen-frozenset.patch @@ -0,0 +1,29 @@ +--- a/networkx/algorithms/connectivity/kcutsets.py ++++ b/networkx/algorithms/connectivity/kcutsets.py +@@ -100,8 +100,12 @@ def all_node_cuts(G, k=None, flow_func=None): + # Initialize data structures. + # Keep track of the cuts already computed so we do not repeat them. +- seen = [] ++ # CWE-407 fix: `not in seen` was O(K) where K is the number of cuts ++ # found so far (list scan). Each iteration in the triple-nested loop ++ # (for x in X: for v in non_adjacent: for antichain in antichains(L):) ++ # pays this cost. Fix: use a set of frozensets for O(1) lookup. ++ # node_cut is a plain set so we freeze before inserting/checking. ++ seen = set() + ... + # Check if X is a k-node-cutset + if _is_separating_set(G, X): +- seen.append(X) ++ seen.add(frozenset(X)) + yield X + ... + # Inside the triple-nested loop: + if len(node_cut) == k: + if x in node_cut or v in node_cut: + continue +- if node_cut not in seen: ++ frozen_cut = frozenset(node_cut) ++ if frozen_cut not in seen: # O(1) hash lookup + yield node_cut +- seen.append(node_cut) ++ seen.add(frozen_cut) # O(1) insert diff --git a/defects/networkx/unit/NetworkXKcutsetsTest.java b/defects/networkx/unit/NetworkXKcutsetsTest.java new file mode 100644 index 000000000..a977cf507 --- /dev/null +++ b/defects/networkx/unit/NetworkXKcutsetsTest.java @@ -0,0 +1,111 @@ +package unit; + +import java.util.*; +import java.util.stream.*; + +/** + * nx-0002: NetworkX all_node_cuts — seen list O(K²) → frozenset-based Set O(K) + * + * In networkx/algorithms/connectivity/kcutsets.py::all_node_cuts(): + * + * seen = [] # list of previously yielded node-cut sets + * ... + * if node_cut not in seen: # O(K) linear scan over prior cuts + * yield node_cut + * seen.append(node_cut) # O(1) append, but membership is O(K) + * + * This fires inside a triple-nested loop: + * for x in X: # k top-degree nodes + * for v in non_adjacent: # O(V) nodes per x + * for antichain in antichains(L): # up to O(2^|L|) antichains + * + * If K distinct cuts are accumulated, each `not in seen` is O(K). Total + * cost of membership checks alone is O(K²). + * + * Fix: seen = set() of frozenset(node_cut). Python frozensets are hashable, + * so `frozen_cut not in seen` is O(1) amortised. Yield the original set; + * store the frozen copy. Behavioural contract unchanged. + * + * UNDF: assigned by generate_undf.py + * Severity: MEDIUM + */ +public class NetworkXKcutsetsTest { + + static long cmpOps = 0; + + // Model: a "seen" collection that deduplicates frozenset-like integer sets. + // Elements are sorted integer arrays (simulate frozensets). + + // SLOW: List scan — O(K) per lookup + static boolean seenContainsSlow(List seen, int[] cut) { + for (int[] s : seen) { + cmpOps++; + if (Arrays.equals(s, cut)) return true; + } + return false; + } + + // FAST: HashSet with Arrays.hashCode / Arrays.equals via wrapper + static class IntArrayKey { + final int[] arr; + IntArrayKey(int[] arr) { this.arr = arr; } + @Override public int hashCode() { return Arrays.hashCode(arr); } + @Override public boolean equals(Object o) { + return o instanceof IntArrayKey && Arrays.equals(arr, ((IntArrayKey)o).arr); + } + } + + public static void main(String[] args) { + // Simulate K distinct cuts being accumulated and checked. + // For each of N iterations (antichain evaluations), a new candidate cut + // is checked against `seen`. After K distinct cuts are stored, the + // (K+1)-th lookup must scan all K entries in the slow path. + + int TOTAL_ITERS = 2000; // total antichain evaluations + int DISTINCT_CUTS = 200; // number of distinct cuts to yield + + // Build DISTINCT_CUTS distinct sorted int[] cuts of size 3 + int[][] cuts = new int[DISTINCT_CUTS][]; + for (int i = 0; i < DISTINCT_CUTS; i++) { + cuts[i] = new int[]{i, i + 1000, i + 2000}; + } + + // SLOW: list-based seen, check each candidate + List slowSeen = new ArrayList<>(); + cmpOps = 0; + for (int iter = 0; iter < TOTAL_ITERS; iter++) { + int[] candidate = cuts[iter % DISTINCT_CUTS]; + if (!seenContainsSlow(slowSeen, candidate)) { + slowSeen.add(Arrays.copyOf(candidate, candidate.length)); + } + } + long slowOps = cmpOps; + + // FAST: HashSet-based seen + Set fastSeen = new HashSet<>(); + long fastOps = 0; + for (int iter = 0; iter < TOTAL_ITERS; iter++) { + int[] candidate = cuts[iter % DISTINCT_CUTS]; + IntArrayKey key = new IntArrayKey(candidate); + fastOps++; // one hash lookup + fastSeen.add(key); + } + + double ratio = (double) slowOps / Math.max(fastOps, 1); + System.out.printf("nx-0002 kcutsets seen: SLOW=%d cmpOps, FAST~=%d ops, ratio=%.1fx%n", + slowOps, fastOps, ratio); + + // Verify same number of distinct cuts found + if (slowSeen.size() != fastSeen.size()) { + System.err.printf("FAIL: distinct cuts slow=%d fast=%d%n", + slowSeen.size(), fastSeen.size()); + System.exit(1); + } + + if (ratio < 5.0) { + System.err.printf("FAIL: ratio %.1f < 5x%n", ratio); + System.exit(1); + } + System.out.println("PASS"); + } +} diff --git a/defects/onos/patch/onos-0004-connectivity-resources-hashset.md b/defects/onos/patch/onos-0004-connectivity-resources-hashset.md index 4dd2d036f..2fbdddd79 100644 --- a/defects/onos/patch/onos-0004-connectivity-resources-hashset.md +++ b/defects/onos/patch/onos-0004-connectivity-resources-hashset.md @@ -1,3 +1,4 @@ +# UNDF: UNDF-2026-000000595 # onos-0004: ConnectivityIntentCompiler resourcesAllocated List.contains O(R×C) → O(C) with Set ## Classification