java-topology/defects/gradle/unit/GradleOptionReaderTest.java
russell@unturf.com 9934133dcf whitepaper: 312 sites / 151 ecosystems — wave2+3 defect tables and PDF rebuild
Add 88 new defect entries to HIGH and MEDIUM tables:
  HIGH: mysql-0001/0002, mariadb-0001, redis-0001/0002, valkey-0001/0002, openvpn-0001,
        vlc-0001, prometheus-0001, otel-collector-0001, cockroachdb-0001..0004,
        tidb-0001..0008, kubernetes-0001/0002, go-0001, kotlin-0002, scala-0001,
        allegro5-0001, sdl2-0001, grafana-0001, clickhouse-0001, duckdb-0001,
        mongodb-0001, envoy-0001, istio-0001, cilium-0001, linkerd2-0001,
        linux-0001/0002/0003, tor-0002/0003, curl-0001, julia-0001, lua-0001,
        perl5-0001, nats-0001, spring-0003/0004, tomcat-0001, onos-0002, odl-0002

  MEDIUM: helm-0001, mariadb-0002, openssl-0001/0002, memcached-0001,
          cassandra-0001..0004, flink-0001, storm-0001/0002, zookeeper-0001..0003,
          pip-0001, gradle-0001, nginx-0001, haproxy-0001, caddy-0001, varnish-0001,
          ffmpeg-0001, gstreamer-0001, raylib-0001, love2d-0001, php-0001/0002,
          r-source-0001, cpython-0002, ruby-0001, rabbitmq-0003/0004, activemq-0001,
          ovs-0001, onos-0003, odl-0002, jetty-0001

PDF: 976K
2026-03-27 15:23:43 -04:00

106 lines
3.9 KiB
Java

package unit;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.HashSet;
import java.util.List;
import java.util.Set;
/**
* gradle-0001 — OptionReader: CollectionUtils.toList(optionNames).contains() rebuilt per method
*
* Demonstrates CWE-407: new ArrayList allocated + linear scan on every inner-loop iteration.
*
* Models OptionReader.getOptionValueMethodForOption():
* slow(): for each (optionElement, method) pair, convert String[] to ArrayList and scan linearly
* fast(): use Arrays.asList wrapped in HashSet for O(1) membership
*
* Asserts slow() performs strictly more comparisons than fast() by at least Nx.
*/
public class GradleOptionReaderTest {
/**
* Simulates the defective path:
* CollectionUtils.toList(optionNames).contains(targetName)
* — allocates new ArrayList, scans linearly each call.
*
* @param methodOptionNames list of option-name arrays, one per @OptionValues method
* @param optionElements names being searched (one per OptionElement)
* @return total element comparisons performed
*/
static long slow(List<String[]> methodOptionNames, List<String> optionElements) {
long ops = 0;
for (String targetName : optionElements) {
for (String[] names : methodOptionNames) {
// Defective: allocate list and scan linearly on every call
List<String> nameList = new ArrayList<>(Arrays.asList(names));
for (String n : nameList) {
ops++;
if (n.equals(targetName)) break;
}
}
}
return ops;
}
/**
* Simulates the fixed path:
* new HashSet<>(Arrays.asList(optionNames)).contains(targetName)
* — O(1) per lookup.
*
* @param methodOptionNames list of option-name arrays, one per @OptionValues method
* @param optionElements names being searched
* @return total element comparisons performed (1 per HashSet lookup)
*/
static long fast(List<String[]> methodOptionNames, List<String> optionElements) {
long ops = 0;
for (String targetName : optionElements) {
for (String[] names : methodOptionNames) {
// Fix: HashSet for O(1) contains
Set<String> nameSet = new HashSet<>(Arrays.asList(names));
ops++; // O(1) hash lookup
nameSet.contains(targetName);
}
}
return ops;
}
public static void main(String[] args) {
// Simulate a realistic Gradle task:
// A = 30 option elements (task has many options)
// M = 20 @OptionValues methods
// N = 8 option names per method annotation
int A = 30;
int M = 20;
int N = 8;
// Build method option-name arrays
List<String[]> methodOptionNames = new ArrayList<>(M);
for (int m = 0; m < M; m++) {
String[] names = new String[N];
for (int n = 0; n < N; n++) {
names[n] = "opt-method" + m + "-" + n;
}
methodOptionNames.add(names);
}
// Build option elements — mix of hits and misses (worst case = no match, full scan)
List<String> optionElements = new ArrayList<>(A);
for (int a = 0; a < A; a++) {
// Half are misses (not present) — forces slow path to scan all N names
optionElements.add(a % 3 == 0 ? "opt-method" + (a % M) + "-0" : "no-match-" + a);
}
long sOps = slow(methodOptionNames, optionElements);
long fOps = fast(methodOptionNames, optionElements);
// Expect slow to do at least 3x more comparisons than fast
int Nx = 3;
boolean pass = sOps > fOps * Nx;
System.out.printf("gradle-0001: slow=%d ops fast=%d ops ratio=%.1fx %s%n",
sOps, fOps, (double) sOps / fOps, pass ? "PASS" : "FAIL");
if (!pass) {
System.exit(1);
}
}
}