findAndVerifyWindowGrace() recurses over parent GraphNodes without a visited accumulator. Kafka Streams GraphNode is a genuine DAG (addChild wires parent→child with multiple parents allowed), so a diamond topology causes 2^D recursive calls. Fix: thread an IdentityHashMap<GraphNode,Long> memo through recursion; memoize on first visit, return cached result on revisit. 8/8 unit tests PASS; D=10 defect count=3071 vs patched O(N). Diamond-recursion CLEAN markers added for: flink, neo4j, janusgraph, tinkerpop, dgraph, zookeeper, storm, ant, gradle, graal, eclipse-jdt, exposed, intellij, kotlin, scala3, hibernate-0007 (prior session work now committed).
688 B
688 B
tinkerpop — diamond recursion CWE-407 scan: CLEAN
Scan date: 2026-03-29
Method scanned
TraversalHelper.getStepsOfAssignableClassRecursively — recursive step collection
across parent/child traversals.
Finding
Each Traversal.Admin has exactly one parent (getParent() returns a single
TraversalParent). The traversal structure is a tree (parent-step owns its child
traversals; each child has exactly one parent). Diamond sharing of sub-traversals
does not occur in the Gremlin traversal compilation model.
The existing tinkerpop-0001 (path isSimple linear scan) was already filed and
patched. No new diamond recursion patterns were found.