Add 88 new defect entries to HIGH and MEDIUM tables:
HIGH: mysql-0001/0002, mariadb-0001, redis-0001/0002, valkey-0001/0002, openvpn-0001,
vlc-0001, prometheus-0001, otel-collector-0001, cockroachdb-0001..0004,
tidb-0001..0008, kubernetes-0001/0002, go-0001, kotlin-0002, scala-0001,
allegro5-0001, sdl2-0001, grafana-0001, clickhouse-0001, duckdb-0001,
mongodb-0001, envoy-0001, istio-0001, cilium-0001, linkerd2-0001,
linux-0001/0002/0003, tor-0002/0003, curl-0001, julia-0001, lua-0001,
perl5-0001, nats-0001, spring-0003/0004, tomcat-0001, onos-0002, odl-0002
MEDIUM: helm-0001, mariadb-0002, openssl-0001/0002, memcached-0001,
cassandra-0001..0004, flink-0001, storm-0001/0002, zookeeper-0001..0003,
pip-0001, gradle-0001, nginx-0001, haproxy-0001, caddy-0001, varnish-0001,
ffmpeg-0001, gstreamer-0001, raylib-0001, love2d-0001, php-0001/0002,
r-source-0001, cpython-0002, ruby-0001, rabbitmq-0003/0004, activemq-0001,
ovs-0001, onos-0003, odl-0002, jetty-0001
PDF: 976K
60 lines
2.8 KiB
Diff
60 lines
2.8 KiB
Diff
diff --git a/pilot/pkg/networking/core/envoyfilter/rc_patch.go b/pilot/pkg/networking/core/envoyfilter/rc_patch.go
|
||
index 1234567..abcdef0 100644
|
||
--- a/pilot/pkg/networking/core/envoyfilter/rc_patch.go
|
||
+++ b/pilot/pkg/networking/core/envoyfilter/rc_patch.go
|
||
@@ -73,12 +73,22 @@ func patchRouteConfig(
|
||
patchContext networking.EnvoyFilter_PatchContext,
|
||
efw *model.EnvoyFilterWrapper,
|
||
patches map[networking.EnvoyFilter_ApplyTo][]*model.EnvoyFilterConfigPatchWrapper,
|
||
routeConfiguration *route.RouteConfiguration, portMap model.GatewayPortMap,
|
||
) {
|
||
removedVirtualHosts := sets.New[string]()
|
||
+ // Build domain→VirtualHost index once so virtualHostMatch is O(1) per domain lookup
|
||
+ // rather than O(D) slices.Contains on every VH×patch combination.
|
||
+ domainIndex := make(map[string]*route.VirtualHost, len(routeConfiguration.VirtualHosts))
|
||
+ for _, vh := range routeConfiguration.VirtualHosts {
|
||
+ for _, d := range vh.Domains {
|
||
+ domainIndex[d] = vh
|
||
+ }
|
||
+ }
|
||
// first do removes/merges/replaces
|
||
for i := range routeConfiguration.VirtualHosts {
|
||
- if patchVirtualHost(patchContext, patches, routeConfiguration, routeConfiguration.VirtualHosts, i, portMap) {
|
||
+ if patchVirtualHost(patchContext, patches, routeConfiguration, routeConfiguration.VirtualHosts, i, portMap, domainIndex) {
|
||
removedVirtualHosts.Insert(routeConfiguration.VirtualHosts[i].Name)
|
||
}
|
||
}
|
||
@@ -106,7 +116,7 @@ func patchVirtualHost(
|
||
patches map[networking.EnvoyFilter_ApplyTo][]*model.EnvoyFilterConfigPatchWrapper,
|
||
routeConfiguration *route.RouteConfiguration, virtualHosts []*route.VirtualHost,
|
||
- idx int, portMap model.GatewayPortMap,
|
||
+ idx int, portMap model.GatewayPortMap, domainIndex map[string]*route.VirtualHost,
|
||
) bool {
|
||
for _, rp := range patches[networking.EnvoyFilter_VIRTUAL_HOST] {
|
||
applied := false
|
||
if commonConditionMatch(patchContext, rp) &&
|
||
routeConfigurationMatch(patchContext, routeConfiguration, rp, portMap) &&
|
||
- virtualHostMatch(virtualHosts[idx], rp) {
|
||
+ virtualHostMatch(virtualHosts[idx], rp, domainIndex) {
|
||
@@ -327,10 +337,12 @@ func virtualHostMatch(vh *route.VirtualHost, rp *model.EnvoyFilterConfigPatchWra
|
||
-func virtualHostMatch(vh *route.VirtualHost, rp *model.EnvoyFilterConfigPatchWrapper) bool {
|
||
+func virtualHostMatch(vh *route.VirtualHost, rp *model.EnvoyFilterConfigPatchWrapper, domainIndex map[string]*route.VirtualHost) bool {
|
||
rMatch := rp.Match.GetRouteConfiguration()
|
||
if rMatch == nil {
|
||
return true
|
||
}
|
||
|
||
match := rMatch.Vhost
|
||
if match == nil {
|
||
return true
|
||
}
|
||
if vh == nil {
|
||
return false
|
||
}
|
||
|
||
// check if virtual host name and a domain name matches
|
||
+ // O(1) map lookup instead of O(D) slices.Contains(vh.Domains, match.DomainName)
|
||
return (match.Name == "" || match.Name == vh.Name) &&
|
||
- (match.DomainName == "" || slices.Contains(vh.Domains, match.DomainName))
|
||
+ (match.DomainName == "" || domainIndex[match.DomainName] == vh)
|
||
}
|