java-topology/defects/kubernetes/patch/kubernetes-deeper-CLEAN.md

41 lines
3.5 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# UNDF: UNDF-2026-000000136
# Kubernetes CWE-407 Deep Scan — CLEAN
**Date:** 2026-03-27
**Repo:** https://github.com/openjdk/jdk (sparse clone)
**Scan scope:** `pkg/scheduler/`, `pkg/controller/`, `staging/src/k8s.io/`
**Already patched:** kubernetes-0001 through kubernetes-0007
## Focus areas
| Area | Files examined |
|------|----------------|
| `pkg/scheduler/` | backend/queue, framework/plugins (all), backend/cache, framework/preemption |
| `pkg/controller/` | disruption, job, servicecidrs, garbagecollector, volume/pv, daemon, deployment, statefulset, tainteviction, nodeipam |
| `staging/src/k8s.io/` | apimachinery, client-go |
| `plugin/pkg/admission/` | limitranger, scheduling, podgroupprotection |
## Candidates examined
| File | Line | Pattern | Verdict |
|------|------|---------|---------|
| `pkg/controller/garbagecollector/patch.go` | 118 | `for _, ref := range refs { slices.Contains(ownerUIDs, ref.UID) }` — ownerRefs and ownerUIDs are both bounded ≤5 per object | CLEAN (small N) |
| `pkg/controller/disruption/disruption.go` | 444 | `slices.Contains(expectedGroups, gv.Group)` — called once per PDB owner, expectedGroups is a 2-element constant literal | CLEAN (constant N) |
| `pkg/controller/job/pod_failure_policy.go` | 126128 | `for containers { slices.Contains(requirement.Values, exitCode) }` — requirement.Values is user-configured exit code list; already covered by kubernetes-0007 | Already patched |
| `pkg/controller/volume/persistentvolume/pv_controller_base.go` | 415439 | `slices.Contains(outFinalizers, ...)` called 3× in `modifyDeletionFinalizers` — outFinalizers is bounded ≤3 items (finalizer strings per PV) | CLEAN (small N) |
| `pkg/scheduler/framework/plugins/dynamicresources/dynamicresources.go` | 1161,1491 | `slices.Contains(claim.Finalizers, resourceapi.Finalizer)` inside claim allocation loop — Finalizers slice is bounded ≤3 per claim | CLEAN (small N) |
| `pkg/scheduler/backend/queue/nominator.go` | 102 | `for _, np := range nominatedPods[nodeName] { if np.uid == pod.UID }` — per-node slice, bounded by concurrent preemption candidates (typically <10) | CLEAN (small N) |
| `pkg/scheduler/framework/plugins/defaultpreemption/default_preemption.go` | 430 | `for podInfos { for pdbs { labelSelector.Matches() } }` label selector uses compiled regex, not slice scan; PDB count is small | CLEAN (map-based) |
| `pkg/scheduler/backend/cache/node_tree.go` | 54 | `for _, nodeName := range na { if nodeName == n.Name }` in `addNode` dedup on node-add event, not scheduling hot path; N = nodes per zone (small) | CLEAN (cold path) |
| `pkg/apis/core/validation/validation.go` | 1832 | `for _, msg := range IsDNS1123Subdomain() { slices.Contains(opts, ...) }` opts is 03 constant ValidateCSIDriverNameOption values | CLEAN (constant N) |
| `pkg/controller/servicecidrs/servicecidrs_controller.go` | 394406 | `for ip in ips { ContainsAddress(lister, ip) }` O(I×S) at ServiceCIDR deletion time; note `// TODO: optimize this` comment in source | CLEAN (deletion path, small cluster-level N) |
## Summary
All `slices.Contains` calls in the scanned areas operate on bounded-small slices
(Finalizers: 3, ownerRefs: 5, expectedGroups: constant 2, opts: constant 3).
No new CWE-407 defects found beyond kubernetes-0001 through kubernetes-0007.
The `servicecidrs_controller.go` carries an explicit `// TODO: optimize this` comment
at the `canDeleteServiceCIDR` function but the operation involves cluster-level IP
counts (not per-request hot path) and N is bounded by cluster size, not request rate.