java-topology/docs/tickets/prosody-0001-clean.md

1 KiB

prosody-0001 — CLEAN

Target: prosody/prosody (Lua) Verdict: No CWE-407 defect found in hot paths

Analysis

Prosody uses hash tables (Lua tables as dicts) throughout its hot paths:

  • Roster: self._affiliations is a hash keyed by bare JID — O(1) lookup
  • Session management: host.sessions[username].sessions[resource] — nested hash, O(1) per lookup
  • MUC affiliations: room._affiliations[bare] — O(1) hash lookup (muc/muc.lib.lua:1386)
  • MUC occupants: stored as room._occupants[nick] — O(1)
  • util/set.lua: set:contains(item) uses items[item] — O(1) hash

The one linear-scan helper found:

-- util/prosodyctl/check.lua:327 (admin CLI path only)
local function contains_match(hayset, needle)
    for member in hayset do
        if member:find(needle) then return true end
    end
end

This is executed only during prosodyctl check, an administrator diagnostic command run infrequently from the command line. Not a hot path. Not a CWE-407 defect.

Result: CLEAN