Add 88 new defect entries to HIGH and MEDIUM tables:
HIGH: mysql-0001/0002, mariadb-0001, redis-0001/0002, valkey-0001/0002, openvpn-0001,
vlc-0001, prometheus-0001, otel-collector-0001, cockroachdb-0001..0004,
tidb-0001..0008, kubernetes-0001/0002, go-0001, kotlin-0002, scala-0001,
allegro5-0001, sdl2-0001, grafana-0001, clickhouse-0001, duckdb-0001,
mongodb-0001, envoy-0001, istio-0001, cilium-0001, linkerd2-0001,
linux-0001/0002/0003, tor-0002/0003, curl-0001, julia-0001, lua-0001,
perl5-0001, nats-0001, spring-0003/0004, tomcat-0001, onos-0002, odl-0002
MEDIUM: helm-0001, mariadb-0002, openssl-0001/0002, memcached-0001,
cassandra-0001..0004, flink-0001, storm-0001/0002, zookeeper-0001..0003,
pip-0001, gradle-0001, nginx-0001, haproxy-0001, caddy-0001, varnish-0001,
ffmpeg-0001, gstreamer-0001, raylib-0001, love2d-0001, php-0001/0002,
r-source-0001, cpython-0002, ruby-0001, rabbitmq-0003/0004, activemq-0001,
ovs-0001, onos-0003, odl-0002, jetty-0001
PDF: 976K
90 lines
3.2 KiB
Java
90 lines
3.2 KiB
Java
package unit;
|
|
|
|
import java.util.*;
|
|
|
|
/**
|
|
* Standalone unit test for grafana-0001: CWE-407.
|
|
*
|
|
* grafana-0001: dfs() visited-array Array.includes — O(n²) on time-range refresh
|
|
* slow() uses a List<String> for visited; contains() is O(V) per node visit.
|
|
* DFS over N nodes with average degree d: O(N * V_avg) ≈ O(N²).
|
|
* fast() uses a HashSet<String>; contains() is O(1) per visit.
|
|
* DFS over N nodes: O(N + E) where E = total edges.
|
|
* Assert: slowOps > fastOps * 10x for N=200 variables in a chain graph.
|
|
*/
|
|
public class GrafanaTest {
|
|
|
|
/** Simulate the DFS with List<String> visited — O(V) membership test per node. */
|
|
static long slowDfs(List<List<Integer>> adj, int start, int N) {
|
|
long ops = 0;
|
|
List<Integer> visited = new ArrayList<>();
|
|
Deque<Integer> stack = new ArrayDeque<>();
|
|
stack.push(start);
|
|
while (!stack.isEmpty()) {
|
|
int node = stack.pop();
|
|
// visited.includes(node) — O(V) scan
|
|
boolean seen = false;
|
|
for (int v : visited) {
|
|
ops++;
|
|
if (v == node) { seen = true; break; }
|
|
}
|
|
if (seen) continue;
|
|
visited.add(node); // push(node.name)
|
|
for (int child : adj.get(node)) {
|
|
// !visited.includes(child) — another O(V) per edge
|
|
boolean childSeen = false;
|
|
for (int v : visited) {
|
|
ops++;
|
|
if (v == child) { childSeen = true; break; }
|
|
}
|
|
if (!childSeen) {
|
|
stack.push(child);
|
|
}
|
|
}
|
|
}
|
|
return ops;
|
|
}
|
|
|
|
/** Simulate the DFS with Set<String> visited — O(1) membership test per node. */
|
|
static long fastDfs(List<List<Integer>> adj, int start, int N) {
|
|
long ops = 0;
|
|
Set<Integer> visited = new HashSet<>();
|
|
Deque<Integer> stack = new ArrayDeque<>();
|
|
stack.push(start);
|
|
while (!stack.isEmpty()) {
|
|
int node = stack.pop();
|
|
ops++; // O(1) hash lookup
|
|
if (visited.contains(node)) continue;
|
|
visited.add(node);
|
|
for (int child : adj.get(node)) {
|
|
ops++; // O(1) hash lookup
|
|
if (!visited.contains(child)) {
|
|
stack.push(child);
|
|
}
|
|
}
|
|
}
|
|
return ops;
|
|
}
|
|
|
|
static void testDfsVisited() {
|
|
int N = 200; // variable count
|
|
// Build a chain graph: 0→1→2→…→N-1 (worst-case for visited growth)
|
|
List<List<Integer>> adj = new ArrayList<>(N);
|
|
for (int i = 0; i < N; i++) adj.add(new ArrayList<>());
|
|
for (int i = 0; i < N - 1; i++) adj.get(i).add(i + 1);
|
|
|
|
long sOps = slowDfs(adj, 0, N);
|
|
long fOps = fastDfs(adj, 0, N);
|
|
|
|
int Nx = 10;
|
|
boolean pass = sOps > fOps * Nx;
|
|
System.out.printf("grafana-0001 [N=%d chain]: slow=%d fast=%d ratio=%.1fx — %s%n",
|
|
N, sOps, fOps, (double) sOps / fOps, pass ? "PASS" : "FAIL");
|
|
if (!pass) throw new AssertionError("grafana-0001 FAIL: slow=" + sOps + " fast=" + fOps);
|
|
}
|
|
|
|
public static void main(String[] args) {
|
|
testDfsVisited();
|
|
System.out.println("1/1 PASS");
|
|
}
|
|
}
|