Add 88 new defect entries to HIGH and MEDIUM tables:
HIGH: mysql-0001/0002, mariadb-0001, redis-0001/0002, valkey-0001/0002, openvpn-0001,
vlc-0001, prometheus-0001, otel-collector-0001, cockroachdb-0001..0004,
tidb-0001..0008, kubernetes-0001/0002, go-0001, kotlin-0002, scala-0001,
allegro5-0001, sdl2-0001, grafana-0001, clickhouse-0001, duckdb-0001,
mongodb-0001, envoy-0001, istio-0001, cilium-0001, linkerd2-0001,
linux-0001/0002/0003, tor-0002/0003, curl-0001, julia-0001, lua-0001,
perl5-0001, nats-0001, spring-0003/0004, tomcat-0001, onos-0002, odl-0002
MEDIUM: helm-0001, mariadb-0002, openssl-0001/0002, memcached-0001,
cassandra-0001..0004, flink-0001, storm-0001/0002, zookeeper-0001..0003,
pip-0001, gradle-0001, nginx-0001, haproxy-0001, caddy-0001, varnish-0001,
ffmpeg-0001, gstreamer-0001, raylib-0001, love2d-0001, php-0001/0002,
r-source-0001, cpython-0002, ruby-0001, rabbitmq-0003/0004, activemq-0001,
ovs-0001, onos-0003, odl-0002, jetty-0001
PDF: 976K
76 lines
2.6 KiB
Java
76 lines
2.6 KiB
Java
package unit;
|
|
|
|
import java.util.*;
|
|
|
|
/**
|
|
* Standalone unit test for otel-collector-0001: CWE-407.
|
|
*
|
|
* otel-collector-0001: pcommon.Map Put* methods — O(n) Get inside O(n) build loop
|
|
* slow() simulates Map construction via repeated PutStr, each doing a linear
|
|
* scan of all existing entries to check for duplicates: O(n²) total.
|
|
* fast() simulates Map construction via a native HashMap accumulator (O(1) put),
|
|
* then a single O(n) conversion to the slice representation: O(n) total.
|
|
* Assert: slowOps > fastOps * 10x for N=300 attributes.
|
|
*/
|
|
public class OtelCollectorTest {
|
|
|
|
/** Simulates pcommon.Map backed by []KeyValue — PutStr calls Get (O(n) linear scan). */
|
|
static long slowMapBuild(int N) {
|
|
long ops = 0;
|
|
// Underlying slice: list of (key, value) pairs
|
|
List<String[]> slice = new ArrayList<>(N);
|
|
for (int i = 0; i < N; i++) {
|
|
String key = "attr_" + i;
|
|
String val = "value_" + i;
|
|
// m.Get(key) — linear scan of all existing entries (PutStr pattern)
|
|
boolean found = false;
|
|
for (String[] kv : slice) {
|
|
ops++;
|
|
if (kv[0].equals(key)) { found = true; break; }
|
|
}
|
|
if (!found) {
|
|
slice.add(new String[]{key, val});
|
|
}
|
|
}
|
|
return ops;
|
|
}
|
|
|
|
/**
|
|
* Simulates bulk Map construction via a native map accumulator:
|
|
* O(1) per put, O(n) final copy — the FromMap approach.
|
|
*/
|
|
static long fastMapBuild(int N) {
|
|
long ops = 0;
|
|
Map<String, String> acc = new HashMap<>(N);
|
|
for (int i = 0; i < N; i++) {
|
|
ops++; // O(1) hash put
|
|
acc.put("attr_" + i, "value_" + i);
|
|
}
|
|
// O(n) conversion to sorted slice
|
|
List<String> keys = new ArrayList<>(acc.keySet());
|
|
Collections.sort(keys);
|
|
List<String[]> slice = new ArrayList<>(keys.size());
|
|
for (String k : keys) {
|
|
ops++;
|
|
slice.add(new String[]{k, acc.get(k)});
|
|
}
|
|
return ops;
|
|
}
|
|
|
|
static void testMapBuild() {
|
|
int N = 300; // attribute count
|
|
long sOps = slowMapBuild(N);
|
|
long fOps = fastMapBuild(N);
|
|
|
|
int Nx = 10;
|
|
boolean pass = sOps > fOps * Nx;
|
|
System.out.printf("otel-collector-0001 [N=%d]: slow=%d fast=%d ratio=%.1fx — %s%n",
|
|
N, sOps, fOps, (double) sOps / fOps, pass ? "PASS" : "FAIL");
|
|
if (!pass) throw new AssertionError("otel-collector-0001 FAIL: slow=" + sOps + " fast=" + fOps);
|
|
}
|
|
|
|
public static void main(String[] args) {
|
|
testMapBuild();
|
|
System.out.println("1/1 PASS");
|
|
}
|
|
}
|