Each MOAD now has a synthetic defective specimen and fixed specimen proven from first principles across three test tiers: Unit (tests/unit/Moad000X*.java): - Correctness: defective and fixed produce identical functional output - Defect behavior: defective specimen exhibits the defect (measurable) - Fix behavior: fixed specimen eliminates the defect Integration (tests/integration/AllMoadsIntegrationTest.java): - All 9 MOADs proven at medium scale (N=500-2000) - MOAD-0001: O(N^2) vs O(N) list scan at N=1000 - MOAD-0002: 500 sessions trample each other (defective) vs coexist (fixed) - MOAD-0003: 250 anonymous requests leak auth identity (defective) vs zero (fixed) - MOAD-0004: 3000 credential exposures across 1000 requests (defective) vs zero (fixed) - MOAD-0005: 500 computes for 500 concurrent misses vs exactly 1 - MOAD-0006: all 500 passwords extractable from DB (defective) vs unextractable (fixed) - MOAD-0007: N=2000 spatial objects, defective visits all 2000 vs O(log N + k) - MOAD-0009: 990 wasted firings for 1000 ticks / 10 events vs zero waste - MOAD-0011: 10240 NFA steps vs 13 steps on N=12 adversarial input (788x) Functional (tests/functional/AllMoadsFunctionalTest.java): - MOAD-0005: real-thread contention proves herd (defective >1 compute, fixed exactly 1) - MOAD-0007: N=50000 spatial objects, 50M defective probes vs 516K fixed (97x speedup) - MOAD-0009: 10000 ticks / 10 events, 9990 wasted firings vs zero (1000x ratio) - MOAD-0011: N=16 adversarial, 163840 defective steps vs 17 fixed (9638x ratio) Support algorithms (tests/support/Moad000X*.java): - Moad0002Algorithm: shared mutable global state (DefectiveAudioSystem / FixedAudioSystem + Context) - Moad0003Algorithm: ThreadLocal not cleared (handleDefective / handleFixed with finally) - Moad0004Algorithm: HTTP headers logged verbatim (logDefective / logFixed with CREDENTIAL_HEADERS denylist) - Moad0005Algorithm: get+null+compute+put (DefectiveCache HashMap / FixedCache ConcurrentHashMap.computeIfAbsent) - Moad0006Algorithm: Base64 password storage (DefectiveCredentialStore / FixedCredentialStore SHA-256+salt) - Moad0007Algorithm: linear spatial scan (queryDefective list / queryFixed sorted array + binary search) - Moad0009Algorithm: timer-driven polling (runDefectiveScheduler / runFixedEventDriven) - Moad0011Algorithm: PCRE nested quantifiers (matchDefective backtracking NFA / matchFixed linear NFA) Makefile: added unit-moad-0002 through unit-moad-0011 targets, integration-all-moads, functional-all-moads. integration and functional targets now depend on all-MOADs variants.
84 lines
3.3 KiB
Java
84 lines
3.3 KiB
Java
package support;
|
|
|
|
/**
|
|
* MOAD-0002: An Intertangled Defect.
|
|
*
|
|
* Defect: independent subsystems (Audio, Display) share a single mutable static
|
|
* state object. Any write by one subsystem is immediately visible to all others.
|
|
* Two independent execution contexts cannot coexist — they trample each other's
|
|
* configuration silently, with no exception thrown.
|
|
*
|
|
* Fix: each subsystem receives an immutable Context snapshot at construction.
|
|
* No shared state. N contexts exist independently, and subsystem writes
|
|
* affect only the context they own.
|
|
*
|
|
* Scanner detects: static mutable fields accessed from multiple subsystem classes
|
|
* without synchronization or phase isolation.
|
|
*/
|
|
public class Moad0002Algorithm {
|
|
|
|
// ── Defective: shared mutable global state ────────────────────────────────
|
|
|
|
/**
|
|
* God object holding all subsystem configuration.
|
|
* The intertangle point: audio, display, and locale all live here.
|
|
*/
|
|
public static final class SharedState {
|
|
public int volume = 50;
|
|
public int brightness = 100;
|
|
public String locale = "en";
|
|
}
|
|
|
|
/** Singleton — all defective subsystems reference this one object. */
|
|
public static final SharedState GLOBAL = new SharedState();
|
|
|
|
public static final class DefectiveAudioSystem {
|
|
public void setVolume(int v) { GLOBAL.volume = v; }
|
|
public int getVolume() { return GLOBAL.volume; }
|
|
public void setLocale(String l) { GLOBAL.locale = l; }
|
|
public String getLocale() { return GLOBAL.locale; }
|
|
}
|
|
|
|
public static final class DefectiveDisplaySystem {
|
|
public void setBrightness(int b) { GLOBAL.brightness = b; }
|
|
public int getBrightness() { return GLOBAL.brightness; }
|
|
public void setLocale(String l) { GLOBAL.locale = l; }
|
|
public String getLocale() { return GLOBAL.locale; }
|
|
}
|
|
|
|
// ── Fixed: each subsystem owns an isolated immutable context ──────────────
|
|
|
|
/** Immutable per-context snapshot. Passed to subsystems at construction. */
|
|
public static final class Context {
|
|
public final int volume;
|
|
public final int brightness;
|
|
public final String locale;
|
|
|
|
public Context(int volume, int brightness, String locale) {
|
|
this.volume = volume;
|
|
this.brightness = brightness;
|
|
this.locale = locale;
|
|
}
|
|
}
|
|
|
|
public static final class FixedAudioSystem {
|
|
private final Context ctx;
|
|
public FixedAudioSystem(Context ctx) { this.ctx = ctx; }
|
|
public int getVolume() { return ctx.volume; }
|
|
public String getLocale() { return ctx.locale; }
|
|
}
|
|
|
|
public static final class FixedDisplaySystem {
|
|
private final Context ctx;
|
|
public FixedDisplaySystem(Context ctx) { this.ctx = ctx; }
|
|
public int getBrightness() { return ctx.brightness; }
|
|
public String getLocale() { return ctx.locale; }
|
|
}
|
|
|
|
/** Reset GLOBAL between test cases so tests do not bleed into each other. */
|
|
public static void resetGlobal() {
|
|
GLOBAL.volume = 50;
|
|
GLOBAL.brightness = 100;
|
|
GLOBAL.locale = "en";
|
|
}
|
|
}
|