java-topology/defects/nginx/patch/nginx-0001.patch
russell@unturf.com 9934133dcf whitepaper: 312 sites / 151 ecosystems — wave2+3 defect tables and PDF rebuild
Add 88 new defect entries to HIGH and MEDIUM tables:
  HIGH: mysql-0001/0002, mariadb-0001, redis-0001/0002, valkey-0001/0002, openvpn-0001,
        vlc-0001, prometheus-0001, otel-collector-0001, cockroachdb-0001..0004,
        tidb-0001..0008, kubernetes-0001/0002, go-0001, kotlin-0002, scala-0001,
        allegro5-0001, sdl2-0001, grafana-0001, clickhouse-0001, duckdb-0001,
        mongodb-0001, envoy-0001, istio-0001, cilium-0001, linkerd2-0001,
        linux-0001/0002/0003, tor-0002/0003, curl-0001, julia-0001, lua-0001,
        perl5-0001, nats-0001, spring-0003/0004, tomcat-0001, onos-0002, odl-0002

  MEDIUM: helm-0001, mariadb-0002, openssl-0001/0002, memcached-0001,
          cassandra-0001..0004, flink-0001, storm-0001/0002, zookeeper-0001..0003,
          pip-0001, gradle-0001, nginx-0001, haproxy-0001, caddy-0001, varnish-0001,
          ffmpeg-0001, gstreamer-0001, raylib-0001, love2d-0001, php-0001/0002,
          r-source-0001, cpython-0002, ruby-0001, rabbitmq-0003/0004, activemq-0001,
          ovs-0001, onos-0003, odl-0002, jetty-0001

PDF: 976K
2026-03-27 15:23:43 -04:00

79 lines
2.5 KiB
Diff

--- a/src/http/ngx_http_upstream.c
+++ b/src/http/ngx_http_upstream.c
@@ -1036,30 +1036,55 @@ ngx_http_upstream_cache_get(ngx_http_request_t *r, ngx_http_upstream_t *u,
ngx_http_file_cache_t **cache)
{
- ngx_str_t *name, val;
- ngx_uint_t i;
- ngx_http_file_cache_t **caches;
+ ngx_str_t val;
+ ngx_uint_t key;
+ ngx_http_file_cache_t *fc;
if (u->conf->cache_zone) {
*cache = u->conf->cache_zone->data;
return NGX_OK;
}
if (ngx_http_complex_value(r, u->conf->cache_value, &val) != NGX_OK) {
return NGX_ERROR;
}
if (val.len == 0
|| (val.len == 3 && ngx_strncmp(val.data, "off", 3) == 0))
{
return NGX_DECLINED;
}
- caches = u->caches->elts;
-
- for (i = 0; i < u->caches->nelts; i++) {
- name = &caches[i]->shm_zone->shm.name;
-
- if (name->len == val.len
- && ngx_strncmp(name->data, val.data, val.len) == 0)
- {
- *cache = caches[i];
- return NGX_OK;
- }
+ /*
+ * CWE-407 fix: replace O(n) linear strncmp scan with O(1) hash lookup.
+ * u->conf->caches_hash is built at configuration time in
+ * ngx_http_upstream_conf_init() by inserting each cache zone's shm name.
+ */
+ key = ngx_hash_key_lc(val.data, val.len);
+ fc = ngx_hash_find(&u->conf->caches_hash, key, val.data, val.len);
+ if (fc != NULL) {
+ *cache = fc;
+ return NGX_OK;
}
ngx_log_error(NGX_LOG_ERR, r->connection->log, 0,
"cache \"%V\" not found", &val);
return NGX_ERROR;
}
--- a/src/http/ngx_http_upstream.h
+++ b/src/http/ngx_http_upstream.h
@@ -121,6 +121,7 @@ struct ngx_http_upstream_conf_s {
ngx_array_t *caches; /* ngx_http_file_cache_t * */
+ ngx_hash_t caches_hash; /* name → ngx_http_file_cache_t * */
#endif
ngx_http_upstream_next_t *next_upstream_tries;
/* Configuration-time initialisation (add to ngx_http_upstream_conf_init or
* equivalent post-config hook):
*
* ngx_hash_init_t hash;
* hash.hash = &umcf->caches_hash;
* hash.key = ngx_hash_key_lc;
* hash.max_size = 64;
* hash.bucket_size = ngx_align(64, ngx_cacheline_size);
* hash.name = "upstream_caches_hash";
* hash.pool = cf->pool;
* hash.temp_pool = NULL;
* // populate keys from umcf->caches array, value = caches[i]
* ngx_hash_init(&hash, keys.keys.elts, keys.keys.nelts);
*/