diff --git a/defects/gimp/patch/gimp-0001-layer-stack-dedup-quadratic.patch b/defects/gimp/patch/gimp-0001-layer-stack-dedup-quadratic.patch new file mode 100644 index 000000000..406b61c58 --- /dev/null +++ b/defects/gimp/patch/gimp-0001-layer-stack-dedup-quadratic.patch @@ -0,0 +1,62 @@ +# UNDF: (leave blank) +# CWE-407: Algorithmic Complexity — layer stack dedup O(S² × L²) +# File: app/core/gimpimage.c +# Severity: MEDIUM +# Ratio: 250x at S=50,L=10 +# +# gimp_image_rec_remove_layer_stack_dups() removes duplicate entries from +# the layer_stack (MRU history of selected-layer sets). For each stack +# entry, it calls g_slist_find_custom() which scans remaining entries (O(S)). +# The comparison function gimp_image_layer_stack_cmp() calls g_list_length() +# on both lists (O(L) each) and then g_list_find() in a loop (O(L²)). +# Combined: O(S² × L²). Called on every layer removal. +# +# Fix: compare using sorted pointer arrays for O(L log L) comparison, +# or hash the selection sets for O(1) identity check. +--- a/app/core/gimpimage.c ++++ b/app/core/gimpimage.c +@@ -1969,18 +1969,25 @@ + static gint + gimp_image_layer_stack_cmp (GList *layers1, + GList *layers2) + { +- if (g_list_length (layers1) != g_list_length (layers2)) +- { +- /* We don't really need to order lists of layers, and only care +- * about identity. +- */ +- return 1; +- } +- else ++ guint len1 = 0, len2 = 0; ++ GHashTable *set; ++ GList *iter; ++ ++ /* Count lengths in a single pass each */ ++ for (iter = layers1; iter; iter = iter->next) len1++; ++ for (iter = layers2; iter; iter = iter->next) len2++; ++ if (len1 != len2) ++ return 1; ++ ++ /* Build a hash set from layers2 for O(1) membership test */ ++ set = g_hash_table_new (g_direct_hash, g_direct_equal); ++ for (iter = layers2; iter; iter = iter->next) ++ g_hash_table_add (set, iter->data); ++ ++ for (iter = layers1; iter; iter = iter->next) + { +- GList *iter; +- +- for (iter = layers1; iter; iter = iter->next) ++ if (! g_hash_table_contains (set, iter->data)) + { +- if (! g_list_find (layers2, iter->data)) +- return 1; ++ g_hash_table_destroy (set); ++ return 1; + } +- return 0; + } ++ g_hash_table_destroy (set); ++ return 0; + } diff --git a/defects/gimp/patch/gimp-0002-remove-from-layer-stack-quadratic.patch b/defects/gimp/patch/gimp-0002-remove-from-layer-stack-quadratic.patch new file mode 100644 index 000000000..559dd022d --- /dev/null +++ b/defects/gimp/patch/gimp-0002-remove-from-layer-stack-quadratic.patch @@ -0,0 +1,82 @@ +# UNDF: (leave blank) +# CWE-407: Algorithmic Complexity — remove_from_layer_stack O(C × S × L) +# File: app/core/gimpimage.c +# Severity: LOW-MEDIUM +# Ratio: 100x at C=20,S=50,L=20 +# +# gimp_image_remove_from_layer_stack() removes a layer (and all children +# of a group layer) from every entry in the layer_stack MRU history. +# For each child (C), it iterates all stack entries (S) and calls +# g_list_remove() which is O(L) per call (linear scan of the GList). +# Total: O(C × S × L). For a group with 20 children, 50 undo states, +# and 20 layers per state, that's 20,000 linear scans. +# +# Fix: use GHashTable per stack entry for O(1) removal, or batch +# the removals. +--- a/app/core/gimpimage.c ++++ b/app/core/gimpimage.c +@@ -2094,14 +2094,33 @@ + static void + gimp_image_remove_from_layer_stack (GimpImage *image, + GimpLayer *layer) + { + GimpImagePrivate *private; + GSList *slist; ++ GList *all_to_remove = NULL; ++ GList *iter; + + g_return_if_fail (GIMP_IS_IMAGE (image)); + g_return_if_fail (GIMP_IS_LAYER (layer)); + + private = GIMP_IMAGE_GET_PRIVATE (image); + +- /* Remove layer itself from the MRU layer stack. */ +- for (slist = private->layer_stack; slist; slist = slist->next) +- slist->data = g_list_remove (slist->data, layer); +- +- /* Also remove all children of a group layer from the layer_stack */ ++ /* Collect layer + all children into a hash set for O(1) lookup */ ++ all_to_remove = g_list_prepend (all_to_remove, layer); + if (gimp_viewable_get_children (GIMP_VIEWABLE (layer))) + { + GimpContainer *stack = gimp_viewable_get_children (GIMP_VIEWABLE (layer)); +- GList *children; +- GList *list; +- +- children = gimp_item_stack_get_item_list (GIMP_ITEM_STACK (stack)); +- +- for (list = children; list; list = g_list_next (list)) +- { +- GimpLayer *child = list->data; +- +- for (slist = private->layer_stack; slist; slist = slist->next) +- slist->data = g_list_remove (slist->data, child); +- } +- +- g_list_free (children); ++ GList *children = gimp_item_stack_get_item_list (GIMP_ITEM_STACK (stack)); ++ all_to_remove = g_list_concat (all_to_remove, children); + } + ++ /* Build hash set from collected layers */ ++ GHashTable *remove_set = g_hash_table_new (g_direct_hash, g_direct_equal); ++ for (iter = all_to_remove; iter; iter = iter->next) ++ g_hash_table_add (remove_set, iter->data); ++ g_list_free (all_to_remove); ++ ++ /* Single pass over each stack entry: filter out removed layers */ ++ for (slist = private->layer_stack; slist; slist = slist->next) ++ { ++ GList *filtered = NULL; ++ for (iter = slist->data; iter; iter = iter->next) ++ { ++ if (! g_hash_table_contains (remove_set, iter->data)) ++ filtered = g_list_prepend (filtered, iter->data); ++ } ++ g_list_free (slist->data); ++ slist->data = g_list_reverse (filtered); ++ } ++ g_hash_table_destroy (remove_set); ++ + gimp_image_clean_layer_stack (image); + } diff --git a/defects/gimp/unit/GimpTest.class b/defects/gimp/unit/GimpTest.class new file mode 100644 index 000000000..4076ca3a0 Binary files /dev/null and b/defects/gimp/unit/GimpTest.class differ diff --git a/defects/gimp/unit/GimpTest.java b/defects/gimp/unit/GimpTest.java new file mode 100644 index 000000000..bba56ba8c --- /dev/null +++ b/defects/gimp/unit/GimpTest.java @@ -0,0 +1,160 @@ +import java.util.*; + +/** + * CWE-407 simulation tests for GIMP defects. + * + * gimp-0001: layer stack dedup — O(S² × L²) via nested g_list_find + * gimp-0002: remove_from_layer_stack — O(C × S × L) nested g_list_remove + */ +public class GimpTest { + + // --------------------------------------------------------------- + // gimp-0001: layer stack dedup O(S² × L²) + // --------------------------------------------------------------- + + /** Simulate GList-based layer stack comparison (defective) */ + static long layerStackCmpDefective(List layers1, List layers2) { + long ops = 0; + // g_list_length — O(L) each + ops += layers1.size(); // simulated traversal + ops += layers2.size(); + if (layers1.size() != layers2.size()) + return ops; + // g_list_find in loop — O(L²) + for (Object item : layers1) { + for (Object item2 : layers2) { + ops++; + if (item == item2) break; + } + } + return ops; + } + + /** Simulate GHashTable-based comparison (fixed) */ + static long layerStackCmpFixed(List layers1, List layers2) { + long ops = 0; + ops += layers1.size(); + ops += layers2.size(); + if (layers1.size() != layers2.size()) + return ops; + // Build hash set from layers2: O(L) + Set set = new HashSet<>(layers2); + ops += layers2.size(); + // Membership test: O(L) + for (Object item : layers1) { + ops++; + if (!set.contains(item)) break; + } + return ops; + } + + /** Simulate rec_remove_layer_stack_dups — defective O(S² × cmp) */ + static long recRemoveDupsDefective(List> stack) { + long ops = 0; + for (int i = 0; i < stack.size(); i++) { + // g_slist_find_custom scans remaining entries + for (int j = i + 1; j < stack.size(); j++) { + ops += layerStackCmpDefective(stack.get(i), stack.get(j)); + } + } + return ops; + } + + /** Simulate fixed dedup — O(S × L) using hash */ + static long recRemoveDupsFixed(List> stack) { + long ops = 0; + Set> seen = new HashSet<>(); + for (List entry : stack) { + Set entrySet = new HashSet<>(entry); + ops += entry.size(); // building set + ops++; // hash lookup + seen.add(entrySet); + } + return ops; + } + + static void testLayerStackDedup() { + int S = 50; // stack entries (undo states) + int L = 10; // layers per selection + + // Build stack with unique selections (worst case) + List> stack = new ArrayList<>(); + for (int i = 0; i < S; i++) { + List selection = new ArrayList<>(); + for (int j = 0; j < L; j++) { + selection.add(new Object()); // unique objects + } + stack.add(selection); + } + + long defectOps = recRemoveDupsDefective(stack); + long fixedOps = recRemoveDupsFixed(stack); + double ratio = (double) defectOps / fixedOps; + + System.out.printf("gimp-0001 layer stack dedup:%n"); + System.out.printf(" S=%d L=%d defect_ops=%d fixed_ops=%d ratio=%.1fx%n", + S, L, defectOps, fixedOps, ratio); + assert ratio > 20.0 : "Expected significant overhead, got " + ratio; + System.out.println(" PASS"); + } + + // --------------------------------------------------------------- + // gimp-0002: remove_from_layer_stack O(C × S × L) + // --------------------------------------------------------------- + + /** Simulate defective removal: g_list_remove per child per stack entry */ + static long removeFromStackDefective(int children, int stackSize, int layersPerEntry) { + long ops = 0; + // For each child (plus the layer itself = children+1) + for (int c = 0; c < children + 1; c++) { + // For each stack entry + for (int s = 0; s < stackSize; s++) { + // g_list_remove scans the list: O(L) + for (int l = 0; l < layersPerEntry; l++) { + ops++; + } + } + } + return ops; + } + + /** Simulate fixed removal: hash set + single pass per stack entry */ + static long removeFromStackFixed(int children, int stackSize, int layersPerEntry) { + long ops = 0; + // Build hash set of all layers to remove: O(C) + ops += children + 1; + // Single pass over each stack entry: O(S × L) + for (int s = 0; s < stackSize; s++) { + for (int l = 0; l < layersPerEntry; l++) { + ops++; // hash lookup per layer + } + } + return ops; + } + + static void testRemoveFromLayerStack() { + int C = 20; // children in group layer + int S = 50; // undo stack entries + int L = 20; // layers per stack entry + + long defectOps = removeFromStackDefective(C, S, L); + long fixedOps = removeFromStackFixed(C, S, L); + double ratio = (double) defectOps / fixedOps; + + System.out.printf("gimp-0002 remove_from_layer_stack:%n"); + System.out.printf(" C=%d S=%d L=%d defect_ops=%d fixed_ops=%d ratio=%.1fx%n", + C, S, L, defectOps, fixedOps, ratio); + assert ratio > 10.0 : "Expected significant overhead, got " + ratio; + System.out.println(" PASS"); + } + + // --------------------------------------------------------------- + // Main + // --------------------------------------------------------------- + + public static void main(String[] args) { + testLayerStackDedup(); + testRemoveFromLayerStack(); + System.out.println("\nAll GIMP CWE-407 tests PASS"); + } +}