java-topology/defects/go/unit/GoInferTest.java
russell@unturf.com 9934133dcf whitepaper: 312 sites / 151 ecosystems — wave2+3 defect tables and PDF rebuild
Add 88 new defect entries to HIGH and MEDIUM tables:
  HIGH: mysql-0001/0002, mariadb-0001, redis-0001/0002, valkey-0001/0002, openvpn-0001,
        vlc-0001, prometheus-0001, otel-collector-0001, cockroachdb-0001..0004,
        tidb-0001..0008, kubernetes-0001/0002, go-0001, kotlin-0002, scala-0001,
        allegro5-0001, sdl2-0001, grafana-0001, clickhouse-0001, duckdb-0001,
        mongodb-0001, envoy-0001, istio-0001, cilium-0001, linkerd2-0001,
        linux-0001/0002/0003, tor-0002/0003, curl-0001, julia-0001, lua-0001,
        perl5-0001, nats-0001, spring-0003/0004, tomcat-0001, onos-0002, odl-0002

  MEDIUM: helm-0001, mariadb-0002, openssl-0001/0002, memcached-0001,
          cassandra-0001..0004, flink-0001, storm-0001/0002, zookeeper-0001..0003,
          pip-0001, gradle-0001, nginx-0001, haproxy-0001, caddy-0001, varnish-0001,
          ffmpeg-0001, gstreamer-0001, raylib-0001, love2d-0001, php-0001/0002,
          r-source-0001, cpython-0002, ruby-0001, rabbitmq-0003/0004, activemq-0001,
          ovs-0001, onos-0003, odl-0002, jetty-0001

PDF: 976K
2026-03-27 15:23:43 -04:00

79 lines
2.8 KiB
Java

package unit;
/**
* GoInferTest — CWE-407 unit test for go-0001
*
* Models the O(n) slices.Index membership check in tpWalker.isParameterized
* (src/cmd/compile/internal/types2/infer.go:630) that fires for every TypeParam
* node during type inference.
*
* slow(): simulates tpWalker with slice-based tparams — O(n) scan per lookup.
* fast(): simulates tpWalker with map-based tparams — O(1) lookup.
*
* Both perform QUERIES * TPARAMS membership checks (same logical work).
* We assert slow() requires >= 5x more comparisons than fast().
*/
public class GoInferTest {
static final int TPARAMS = 200; // type parameters in a large generic function
static final int QUERIES = 500; // TypeParam nodes visited during walk
static final int N = 5; // minimum speedup factor required
/**
* Slow path: slice-based tparams lookup (mirrors slices.Index).
* For each query, scans from index 0 until the target is found.
* Returns total number of element comparisons performed.
*/
static long slow() {
// Build tparams slice (indices 0..TPARAMS-1)
int[] tparams = new int[TPARAMS];
for (int i = 0; i < TPARAMS; i++) tparams[i] = i;
long ops = 0;
// Simulate QUERIES lookups — target is the last element (worst case)
for (int q = 0; q < QUERIES; q++) {
int target = TPARAMS - 1; // worst case: found at end
for (int i = 0; i < tparams.length; i++) {
ops++;
if (tparams[i] == target) break;
}
}
return ops;
}
/**
* Fast path: map-based tparams lookup (mirrors map[*TypeParam]bool).
* Each query is O(1) hash lookup. We simulate this by tracking
* exactly 1 "probe" per lookup (hash table amortized cost).
*/
static long fast() {
// Build tparams set
java.util.HashSet<Integer> tparams = new java.util.HashSet<>();
for (int i = 0; i < TPARAMS; i++) tparams.add(i);
long ops = 0;
for (int q = 0; q < QUERIES; q++) {
int target = TPARAMS - 1;
// Simulate O(1) hash lookup: count 1 operation per query
ops++;
tparams.contains(target);
}
return ops;
}
public static void main(String[] args) {
long sOps = slow();
long fOps = fast();
System.out.println("slow ops: " + sOps);
System.out.println("fast ops: " + fOps);
System.out.println("ratio: " + sOps + "/" + fOps + " = " + (sOps / fOps) + "x");
// slow must be >= N times more expensive than fast
if (sOps < fOps * N) {
System.out.println("1/1 FAIL — expected slowOps >= " + N + "x fastOps, got ratio=" + (sOps / fOps));
System.exit(1);
}
System.out.println("1/1 PASS");
}
}