Add 88 new defect entries to HIGH and MEDIUM tables:
HIGH: mysql-0001/0002, mariadb-0001, redis-0001/0002, valkey-0001/0002, openvpn-0001,
vlc-0001, prometheus-0001, otel-collector-0001, cockroachdb-0001..0004,
tidb-0001..0008, kubernetes-0001/0002, go-0001, kotlin-0002, scala-0001,
allegro5-0001, sdl2-0001, grafana-0001, clickhouse-0001, duckdb-0001,
mongodb-0001, envoy-0001, istio-0001, cilium-0001, linkerd2-0001,
linux-0001/0002/0003, tor-0002/0003, curl-0001, julia-0001, lua-0001,
perl5-0001, nats-0001, spring-0003/0004, tomcat-0001, onos-0002, odl-0002
MEDIUM: helm-0001, mariadb-0002, openssl-0001/0002, memcached-0001,
cassandra-0001..0004, flink-0001, storm-0001/0002, zookeeper-0001..0003,
pip-0001, gradle-0001, nginx-0001, haproxy-0001, caddy-0001, varnish-0001,
ffmpeg-0001, gstreamer-0001, raylib-0001, love2d-0001, php-0001/0002,
r-source-0001, cpython-0002, ruby-0001, rabbitmq-0003/0004, activemq-0001,
ovs-0001, onos-0003, odl-0002, jetty-0001
PDF: 976K
79 lines
2.8 KiB
Java
79 lines
2.8 KiB
Java
package unit;
|
|
|
|
/**
|
|
* GoInferTest — CWE-407 unit test for go-0001
|
|
*
|
|
* Models the O(n) slices.Index membership check in tpWalker.isParameterized
|
|
* (src/cmd/compile/internal/types2/infer.go:630) that fires for every TypeParam
|
|
* node during type inference.
|
|
*
|
|
* slow(): simulates tpWalker with slice-based tparams — O(n) scan per lookup.
|
|
* fast(): simulates tpWalker with map-based tparams — O(1) lookup.
|
|
*
|
|
* Both perform QUERIES * TPARAMS membership checks (same logical work).
|
|
* We assert slow() requires >= 5x more comparisons than fast().
|
|
*/
|
|
public class GoInferTest {
|
|
|
|
static final int TPARAMS = 200; // type parameters in a large generic function
|
|
static final int QUERIES = 500; // TypeParam nodes visited during walk
|
|
static final int N = 5; // minimum speedup factor required
|
|
|
|
/**
|
|
* Slow path: slice-based tparams lookup (mirrors slices.Index).
|
|
* For each query, scans from index 0 until the target is found.
|
|
* Returns total number of element comparisons performed.
|
|
*/
|
|
static long slow() {
|
|
// Build tparams slice (indices 0..TPARAMS-1)
|
|
int[] tparams = new int[TPARAMS];
|
|
for (int i = 0; i < TPARAMS; i++) tparams[i] = i;
|
|
|
|
long ops = 0;
|
|
// Simulate QUERIES lookups — target is the last element (worst case)
|
|
for (int q = 0; q < QUERIES; q++) {
|
|
int target = TPARAMS - 1; // worst case: found at end
|
|
for (int i = 0; i < tparams.length; i++) {
|
|
ops++;
|
|
if (tparams[i] == target) break;
|
|
}
|
|
}
|
|
return ops;
|
|
}
|
|
|
|
/**
|
|
* Fast path: map-based tparams lookup (mirrors map[*TypeParam]bool).
|
|
* Each query is O(1) hash lookup. We simulate this by tracking
|
|
* exactly 1 "probe" per lookup (hash table amortized cost).
|
|
*/
|
|
static long fast() {
|
|
// Build tparams set
|
|
java.util.HashSet<Integer> tparams = new java.util.HashSet<>();
|
|
for (int i = 0; i < TPARAMS; i++) tparams.add(i);
|
|
|
|
long ops = 0;
|
|
for (int q = 0; q < QUERIES; q++) {
|
|
int target = TPARAMS - 1;
|
|
// Simulate O(1) hash lookup: count 1 operation per query
|
|
ops++;
|
|
tparams.contains(target);
|
|
}
|
|
return ops;
|
|
}
|
|
|
|
public static void main(String[] args) {
|
|
long sOps = slow();
|
|
long fOps = fast();
|
|
|
|
System.out.println("slow ops: " + sOps);
|
|
System.out.println("fast ops: " + fOps);
|
|
System.out.println("ratio: " + sOps + "/" + fOps + " = " + (sOps / fOps) + "x");
|
|
|
|
// slow must be >= N times more expensive than fast
|
|
if (sOps < fOps * N) {
|
|
System.out.println("1/1 FAIL — expected slowOps >= " + N + "x fastOps, got ratio=" + (sOps / fOps));
|
|
System.exit(1);
|
|
}
|
|
System.out.println("1/1 PASS");
|
|
}
|
|
}
|