findAndVerifyWindowGrace() recurses over parent GraphNodes without a visited accumulator. Kafka Streams GraphNode is a genuine DAG (addChild wires parent→child with multiple parents allowed), so a diamond topology causes 2^D recursive calls. Fix: thread an IdentityHashMap<GraphNode,Long> memo through recursion; memoize on first visit, return cached result on revisit. 8/8 unit tests PASS; D=10 defect count=3071 vs patched O(N). Diamond-recursion CLEAN markers added for: flink, neo4j, janusgraph, tinkerpop, dgraph, zookeeper, storm, ant, gradle, graal, eclipse-jdt, exposed, intellij, kotlin, scala3, hibernate-0007 (prior session work now committed).
19 lines
645 B
Markdown
19 lines
645 B
Markdown
# janusgraph — diamond recursion CWE-407 scan: CLEAN
|
|
|
|
## Scan date: 2026-03-29
|
|
|
|
## Method scanned
|
|
|
|
`TypeUtil`, `JanusGraphSchemaVertex`, `RelationTypeVertex`, `VertexLabelVertex`,
|
|
`EdgeLabelVertex` — schema type dependency traversal.
|
|
|
|
## Finding
|
|
|
|
Schema-type methods (`getRelated`, `getTypeModifier`, `getBaseType`) return flat
|
|
lists from the backing graph store; they do not recurse over a DAG without a
|
|
visited set. `getBaseType` terminates at a fixed-depth one-hop (returns
|
|
`type.getBaseType()` which is a single pointer, not iterated).
|
|
|
|
No recursive multi-hop schema traversal without a visited accumulator was found.
|
|
|
|
## Verdict: CLEAN
|