java-topology/defects/ant/patch/ant-CLEAN.md

25 lines
1.2 KiB
Markdown

# UNDF: UNDF-2026-000000348
## Apache Ant — CWE-407 Scan Result: CLEAN
Scanned: `src/main/org/apache/tools/ant/` (depth=1 clone, 2026-03-27)
### Patterns checked
| Location | Type | Verdict |
|----------|------|---------|
| `DirectoryScanner.processIncluded()` L1348 | `inc/exc/des.contains()` | CLEAN — lists are `VectorSet<>` (O(1) HashSet-backed `contains()`) |
| `Project.executeTargets()` | `succeededTargets.contains()` | CLEAN — `HashSet<String>` |
| `ComponentHelper` | `checkedNamespaces.contains()` | CLEAN — `HashSet<String>` |
| `AntAnalyzer.determineDependencies()` | `dependencies.contains()` | CLEAN — `HashSet<String>` |
| `Javadoc` | `addedPackages.contains()` | CLEAN — `HashSet<String>` |
| `Main.handleArg()` | `LAUNCH_COMMANDS.contains()` | CLEAN — `unmodifiableSet(HashSet)` |
### Key finding
Ant already fixed the O(N) `DirectoryScanner` `contains()` issue in **Ant 1.8.0** by
introducing `VectorSet<E>` (`src/main/org/apache/tools/ant/util/VectorSet.java`).
`VectorSet.contains()` delegates to an internal `HashSet<E>` — O(1). The class comment
says it was created precisely because the `protected` field types in `DirectoryScanner`
prevented switching to a pure `HashSet`.
No CWE-407 defects found.