nx-0002 + onos-0004: networkx kcutsets seen-list O(K²) 100x; onos UNDF stamp; count 616→617
This commit is contained in:
parent
ea42ae35c7
commit
a8b806626f
4 changed files with 146 additions and 37 deletions
|
|
@ -167,7 +167,6 @@
|
|||
"maven-0005": "UNDF-2026-000000166",
|
||||
"maven-0006": "UNDF-2026-000000167",
|
||||
"maven-0007": "UNDF-2026-000000168",
|
||||
"memcached-0001": "UNDF-2026-000000169",
|
||||
"mesa-0001": "UNDF-2026-000000170",
|
||||
"meson-0001": "UNDF-2026-000000171",
|
||||
"moby-0001": "UNDF-2026-000000172",
|
||||
|
|
@ -346,17 +345,13 @@
|
|||
"actix-web-0001": "UNDF-2026-000000345",
|
||||
"actix-web-0002": "UNDF-2026-000000346",
|
||||
"airflow-0001": "UNDF-2026-000000347",
|
||||
"ant-0001": "UNDF-2026-000000348",
|
||||
"argo-workflows-0001": "UNDF-2026-000000349",
|
||||
"artemis-0001": "UNDF-2026-000000350",
|
||||
"asterisk-0003": "UNDF-2026-000000351",
|
||||
"axum-0001": "UNDF-2026-000000352",
|
||||
"beam-0001": "UNDF-2026-000000353",
|
||||
"binutils-0001": "UNDF-2026-000000354",
|
||||
"bird-0003": "UNDF-2026-000000355",
|
||||
"bird-0004": "UNDF-2026-000000356",
|
||||
"bitcoin-0001": "UNDF-2026-000000357",
|
||||
"buck2-0001": "UNDF-2026-000000358",
|
||||
"bun-0001": "UNDF-2026-000000359",
|
||||
"camel-0001": "UNDF-2026-000000360",
|
||||
"celery-0002": "UNDF-2026-000000361",
|
||||
|
|
@ -364,7 +359,6 @@
|
|||
"cilium-0002": "UNDF-2026-000000363",
|
||||
"cilium-0003": "UNDF-2026-000000364",
|
||||
"cilium-0004": "UNDF-2026-000000365",
|
||||
"clojure-0001": "UNDF-2026-000000366",
|
||||
"consul-0001": "UNDF-2026-000000367",
|
||||
"containerd-0001": "UNDF-2026-000000368",
|
||||
"crystal-0001": "UNDF-2026-000000369",
|
||||
|
|
@ -374,7 +368,6 @@
|
|||
"dart-0001": "UNDF-2026-000000373",
|
||||
"dart-0002": "UNDF-2026-000000374",
|
||||
"dart-0003": "UNDF-2026-000000375",
|
||||
"deno-0001": "UNDF-2026-000000376",
|
||||
"dgraph-0001": "UNDF-2026-000000377",
|
||||
"django-0005": "UNDF-2026-000000378",
|
||||
"django-0006": "UNDF-2026-000000379",
|
||||
|
|
@ -390,27 +383,19 @@
|
|||
"emacs-0002": "UNDF-2026-000000389",
|
||||
"envoy-0002": "UNDF-2026-000000390",
|
||||
"envoy-0003": "UNDF-2026-000000391",
|
||||
"etcd-0001": "UNDF-2026-000000392",
|
||||
"express-0001": "UNDF-2026-000000393",
|
||||
"fish-0001": "UNDF-2026-000000394",
|
||||
"flink-0002": "UNDF-2026-000000395",
|
||||
"flink-0003": "UNDF-2026-000000396",
|
||||
"flink-0004": "UNDF-2026-000000397",
|
||||
"flink-0005": "UNDF-2026-000000398",
|
||||
"flutter-0001": "UNDF-2026-000000399",
|
||||
"foundationdb-0001": "UNDF-2026-000000400",
|
||||
"frrouting-0003": "UNDF-2026-000000401",
|
||||
"frrouting-0004": "UNDF-2026-000000402",
|
||||
"gdb-0001": "UNDF-2026-000000403",
|
||||
"glib-0001": "UNDF-2026-000000404",
|
||||
"graal-0001": "UNDF-2026-000000405",
|
||||
"grafana-0002": "UNDF-2026-000000406",
|
||||
"graphhopper-0001": "UNDF-2026-000000407",
|
||||
"graphhopper-0002": "UNDF-2026-000000408",
|
||||
"groovy-0001": "UNDF-2026-000000409",
|
||||
"groovy-0002": "UNDF-2026-000000410",
|
||||
"grpc-0001": "UNDF-2026-000000411",
|
||||
"gunicorn-0001": "UNDF-2026-000000412",
|
||||
"haproxy-0002": "UNDF-2026-000000413",
|
||||
"haproxy-0003": "UNDF-2026-000000414",
|
||||
"hazelcast-0001": "UNDF-2026-000000415",
|
||||
|
|
@ -422,9 +407,7 @@
|
|||
"hudi-0001": "UNDF-2026-000000421",
|
||||
"hudi-0002": "UNDF-2026-000000422",
|
||||
"hudi-0003": "UNDF-2026-000000423",
|
||||
"hypercorn-0001": "UNDF-2026-000000424",
|
||||
"iceberg-0001": "UNDF-2026-000000425",
|
||||
"intellij-0001": "UNDF-2026-000000426",
|
||||
"istio-0002": "UNDF-2026-000000427",
|
||||
"istio-0003": "UNDF-2026-000000428",
|
||||
"jami-daemon": "UNDF-2026-000000429",
|
||||
|
|
@ -438,8 +421,6 @@
|
|||
"kafka-0006": "UNDF-2026-000000437",
|
||||
"kafka-0007": "UNDF-2026-000000438",
|
||||
"kafka-0008": "UNDF-2026-000000439",
|
||||
"koa-0001": "UNDF-2026-000000440",
|
||||
"ktor-0001": "UNDF-2026-000000441",
|
||||
"kubeflow-0001": "UNDF-2026-000000442",
|
||||
"kubernetes-0004": "UNDF-2026-000000443",
|
||||
"kubernetes-0005": "UNDF-2026-000000444",
|
||||
|
|
@ -449,7 +430,6 @@
|
|||
"leveldb-0001": "UNDF-2026-000000448",
|
||||
"libgdx-0002": "UNDF-2026-000000449",
|
||||
"libgdx-0003": "UNDF-2026-000000450",
|
||||
"lighttpd-0001": "UNDF-2026-000000451",
|
||||
"linkerd2-0002": "UNDF-2026-000000452",
|
||||
"lldb-0001": "UNDF-2026-000000453",
|
||||
"lmdb-0001": "UNDF-2026-000000454",
|
||||
|
|
@ -462,12 +442,9 @@
|
|||
"micronaut-0001": "UNDF-2026-000000461",
|
||||
"micronaut-0002": "UNDF-2026-000000462",
|
||||
"micronaut-0003": "UNDF-2026-000000463",
|
||||
"mlflow-0001": "UNDF-2026-000000464",
|
||||
"mongodb-0008": "UNDF-2026-000000465",
|
||||
"nats-0001": "UNDF-2026-000000466",
|
||||
"neo4j-0001": "UNDF-2026-000000467",
|
||||
"neovim-0001": "UNDF-2026-000000468",
|
||||
"netty-0001": "UNDF-2026-000000469",
|
||||
"nginx-0002": "UNDF-2026-000000470",
|
||||
"nginx-0003": "UNDF-2026-000000471",
|
||||
"nifi-0001": "UNDF-2026-000000472",
|
||||
|
|
@ -482,7 +459,6 @@
|
|||
"octave-0002": "UNDF-2026-000000481",
|
||||
"open3d-0001": "UNDF-2026-000000482",
|
||||
"open3d-0002": "UNDF-2026-000000483",
|
||||
"openbgpd-0001": "UNDF-2026-000000484",
|
||||
"opencv-0001": "UNDF-2026-000000485",
|
||||
"opencv-0002": "UNDF-2026-000000486",
|
||||
"opensearch-0001": "UNDF-2026-000000487",
|
||||
|
|
@ -493,7 +469,6 @@
|
|||
"opentofu-0001": "UNDF-2026-000000492",
|
||||
"opentofu-0002": "UNDF-2026-000000493",
|
||||
"optuna-0001": "UNDF-2026-000000494",
|
||||
"osrm-0001": "UNDF-2026-000000495",
|
||||
"otel-collector": "UNDF-2026-000000496",
|
||||
"pandas-0001": "UNDF-2026-000000497",
|
||||
"php-0003": "UNDF-2026-000000498",
|
||||
|
|
@ -502,7 +477,6 @@
|
|||
"podman-0001": "UNDF-2026-000000501",
|
||||
"podman-0002": "UNDF-2026-000000502",
|
||||
"prometheus-0002": "UNDF-2026-000000503",
|
||||
"prosody-0001": "UNDF-2026-000000504",
|
||||
"pulsar-0001": "UNDF-2026-000000505",
|
||||
"pulsar-0002": "UNDF-2026-000000506",
|
||||
"pulsar-0003": "UNDF-2026-000000507",
|
||||
|
|
@ -526,9 +500,7 @@
|
|||
"ros2-0001": "UNDF-2026-000000525",
|
||||
"ros2-0002": "UNDF-2026-000000526",
|
||||
"rustc-0004": "UNDF-2026-000000527",
|
||||
"samza-0001": "UNDF-2026-000000528",
|
||||
"scylladb-0001": "UNDF-2026-000000529",
|
||||
"signal-server": "UNDF-2026-000000530",
|
||||
"simplex-chat": "UNDF-2026-000000531",
|
||||
"sklearn-0001": "UNDF-2026-000000532",
|
||||
"solr-0001": "UNDF-2026-000000533",
|
||||
|
|
@ -548,11 +520,9 @@
|
|||
"systemd-0001": "UNDF-2026-000000547",
|
||||
"systemd-0002": "UNDF-2026-000000548",
|
||||
"tcl-0001": "UNDF-2026-000000549",
|
||||
"tcpdump-0001": "UNDF-2026-000000550",
|
||||
"tensorflow-0001": "UNDF-2026-000000551",
|
||||
"threejs-0006": "UNDF-2026-000000552",
|
||||
"thrift-0001": "UNDF-2026-000000553",
|
||||
"tikv-0001": "UNDF-2026-000000554",
|
||||
"tokio-0001": "UNDF-2026-000000555",
|
||||
"tomcat-0002": "UNDF-2026-000000556",
|
||||
"traefik-0001": "UNDF-2026-000000557",
|
||||
|
|
@ -560,7 +530,6 @@
|
|||
"traefik-0003": "UNDF-2026-000000559",
|
||||
"trino-0001": "UNDF-2026-000000560",
|
||||
"undertow-0001": "UNDF-2026-000000561",
|
||||
"uvicorn-0001": "UNDF-2026-000000562",
|
||||
"uwsgi-0001": "UNDF-2026-000000563",
|
||||
"v8-0002": "UNDF-2026-000000564",
|
||||
"v8-0003": "UNDF-2026-000000565",
|
||||
|
|
@ -571,14 +540,9 @@
|
|||
"vertx-0001": "UNDF-2026-000000570",
|
||||
"vim-0001": "UNDF-2026-000000571",
|
||||
"vim-0002": "UNDF-2026-000000572",
|
||||
"waitress-0001": "UNDF-2026-000000573",
|
||||
"weechat-0002": "UNDF-2026-000000574",
|
||||
"wireguard-tools": "UNDF-2026-000000575",
|
||||
"wolfssl-0001": "UNDF-2026-000000576",
|
||||
"yugabyte-0001": "UNDF-2026-000000577",
|
||||
"zig-0001": "UNDF-2026-000000578",
|
||||
"zsh-0001": "UNDF-2026-000000579",
|
||||
"zulip-0001": "UNDF-2026-000000580",
|
||||
"bazel-0003": "UNDF-2026-000000581",
|
||||
"curl-0002": "UNDF-2026-000000582",
|
||||
"curl-0003": "UNDF-2026-000000583",
|
||||
|
|
@ -592,5 +556,8 @@
|
|||
"libvirt-0001": "UNDF-2026-000000591",
|
||||
"libvirt-0002": "UNDF-2026-000000592",
|
||||
"v8-0004": "UNDF-2026-000000593",
|
||||
"xen-0001": "UNDF-2026-000000594"
|
||||
"xen-0001": "UNDF-2026-000000594",
|
||||
"onos-0004": "UNDF-2026-000000595",
|
||||
"networkx-0002": "UNDF-2026-000000169",
|
||||
"memcached-0001": "UNDF-2026-000000348"
|
||||
}
|
||||
|
|
|
|||
30
defects/networkx/patch/nx-0002-kcutsets-seen-frozenset.patch
Normal file
30
defects/networkx/patch/nx-0002-kcutsets-seen-frozenset.patch
Normal file
|
|
@ -0,0 +1,30 @@
|
|||
# UNDF: UNDF-2026-000000169
|
||||
--- a/networkx/algorithms/connectivity/kcutsets.py
|
||||
+++ b/networkx/algorithms/connectivity/kcutsets.py
|
||||
@@ -100,8 +100,12 @@ def all_node_cuts(G, k=None, flow_func=None):
|
||||
# Initialize data structures.
|
||||
# Keep track of the cuts already computed so we do not repeat them.
|
||||
- seen = []
|
||||
+ # CWE-407 fix: `not in seen` was O(K) where K is the number of cuts
|
||||
+ # found so far (list scan). Each iteration in the triple-nested loop
|
||||
+ # (for x in X: for v in non_adjacent: for antichain in antichains(L):)
|
||||
+ # pays this cost. Fix: use a set of frozensets for O(1) lookup.
|
||||
+ # node_cut is a plain set so we freeze before inserting/checking.
|
||||
+ seen = set()
|
||||
...
|
||||
# Check if X is a k-node-cutset
|
||||
if _is_separating_set(G, X):
|
||||
- seen.append(X)
|
||||
+ seen.add(frozenset(X))
|
||||
yield X
|
||||
...
|
||||
# Inside the triple-nested loop:
|
||||
if len(node_cut) == k:
|
||||
if x in node_cut or v in node_cut:
|
||||
continue
|
||||
- if node_cut not in seen:
|
||||
+ frozen_cut = frozenset(node_cut)
|
||||
+ if frozen_cut not in seen: # O(1) hash lookup
|
||||
yield node_cut
|
||||
- seen.append(node_cut)
|
||||
+ seen.add(frozen_cut) # O(1) insert
|
||||
111
defects/networkx/unit/NetworkXKcutsetsTest.java
Normal file
111
defects/networkx/unit/NetworkXKcutsetsTest.java
Normal file
|
|
@ -0,0 +1,111 @@
|
|||
package unit;
|
||||
|
||||
import java.util.*;
|
||||
import java.util.stream.*;
|
||||
|
||||
/**
|
||||
* nx-0002: NetworkX all_node_cuts — seen list O(K²) → frozenset-based Set O(K)
|
||||
*
|
||||
* In networkx/algorithms/connectivity/kcutsets.py::all_node_cuts():
|
||||
*
|
||||
* seen = [] # list of previously yielded node-cut sets
|
||||
* ...
|
||||
* if node_cut not in seen: # O(K) linear scan over prior cuts
|
||||
* yield node_cut
|
||||
* seen.append(node_cut) # O(1) append, but membership is O(K)
|
||||
*
|
||||
* This fires inside a triple-nested loop:
|
||||
* for x in X: # k top-degree nodes
|
||||
* for v in non_adjacent: # O(V) nodes per x
|
||||
* for antichain in antichains(L): # up to O(2^|L|) antichains
|
||||
*
|
||||
* If K distinct cuts are accumulated, each `not in seen` is O(K). Total
|
||||
* cost of membership checks alone is O(K²).
|
||||
*
|
||||
* Fix: seen = set() of frozenset(node_cut). Python frozensets are hashable,
|
||||
* so `frozen_cut not in seen` is O(1) amortised. Yield the original set;
|
||||
* store the frozen copy. Behavioural contract unchanged.
|
||||
*
|
||||
* UNDF: assigned by generate_undf.py
|
||||
* Severity: MEDIUM
|
||||
*/
|
||||
public class NetworkXKcutsetsTest {
|
||||
|
||||
static long cmpOps = 0;
|
||||
|
||||
// Model: a "seen" collection that deduplicates frozenset-like integer sets.
|
||||
// Elements are sorted integer arrays (simulate frozensets).
|
||||
|
||||
// SLOW: List scan — O(K) per lookup
|
||||
static boolean seenContainsSlow(List<int[]> seen, int[] cut) {
|
||||
for (int[] s : seen) {
|
||||
cmpOps++;
|
||||
if (Arrays.equals(s, cut)) return true;
|
||||
}
|
||||
return false;
|
||||
}
|
||||
|
||||
// FAST: HashSet with Arrays.hashCode / Arrays.equals via wrapper
|
||||
static class IntArrayKey {
|
||||
final int[] arr;
|
||||
IntArrayKey(int[] arr) { this.arr = arr; }
|
||||
@Override public int hashCode() { return Arrays.hashCode(arr); }
|
||||
@Override public boolean equals(Object o) {
|
||||
return o instanceof IntArrayKey && Arrays.equals(arr, ((IntArrayKey)o).arr);
|
||||
}
|
||||
}
|
||||
|
||||
public static void main(String[] args) {
|
||||
// Simulate K distinct cuts being accumulated and checked.
|
||||
// For each of N iterations (antichain evaluations), a new candidate cut
|
||||
// is checked against `seen`. After K distinct cuts are stored, the
|
||||
// (K+1)-th lookup must scan all K entries in the slow path.
|
||||
|
||||
int TOTAL_ITERS = 2000; // total antichain evaluations
|
||||
int DISTINCT_CUTS = 200; // number of distinct cuts to yield
|
||||
|
||||
// Build DISTINCT_CUTS distinct sorted int[] cuts of size 3
|
||||
int[][] cuts = new int[DISTINCT_CUTS][];
|
||||
for (int i = 0; i < DISTINCT_CUTS; i++) {
|
||||
cuts[i] = new int[]{i, i + 1000, i + 2000};
|
||||
}
|
||||
|
||||
// SLOW: list-based seen, check each candidate
|
||||
List<int[]> slowSeen = new ArrayList<>();
|
||||
cmpOps = 0;
|
||||
for (int iter = 0; iter < TOTAL_ITERS; iter++) {
|
||||
int[] candidate = cuts[iter % DISTINCT_CUTS];
|
||||
if (!seenContainsSlow(slowSeen, candidate)) {
|
||||
slowSeen.add(Arrays.copyOf(candidate, candidate.length));
|
||||
}
|
||||
}
|
||||
long slowOps = cmpOps;
|
||||
|
||||
// FAST: HashSet-based seen
|
||||
Set<IntArrayKey> fastSeen = new HashSet<>();
|
||||
long fastOps = 0;
|
||||
for (int iter = 0; iter < TOTAL_ITERS; iter++) {
|
||||
int[] candidate = cuts[iter % DISTINCT_CUTS];
|
||||
IntArrayKey key = new IntArrayKey(candidate);
|
||||
fastOps++; // one hash lookup
|
||||
fastSeen.add(key);
|
||||
}
|
||||
|
||||
double ratio = (double) slowOps / Math.max(fastOps, 1);
|
||||
System.out.printf("nx-0002 kcutsets seen: SLOW=%d cmpOps, FAST~=%d ops, ratio=%.1fx%n",
|
||||
slowOps, fastOps, ratio);
|
||||
|
||||
// Verify same number of distinct cuts found
|
||||
if (slowSeen.size() != fastSeen.size()) {
|
||||
System.err.printf("FAIL: distinct cuts slow=%d fast=%d%n",
|
||||
slowSeen.size(), fastSeen.size());
|
||||
System.exit(1);
|
||||
}
|
||||
|
||||
if (ratio < 5.0) {
|
||||
System.err.printf("FAIL: ratio %.1f < 5x%n", ratio);
|
||||
System.exit(1);
|
||||
}
|
||||
System.out.println("PASS");
|
||||
}
|
||||
}
|
||||
|
|
@ -1,3 +1,4 @@
|
|||
# UNDF: UNDF-2026-000000595
|
||||
# onos-0004: ConnectivityIntentCompiler resourcesAllocated List.contains O(R×C) → O(C) with Set
|
||||
|
||||
## Classification
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue