java-topology/defects/exposed/patch/exposed-0003-Table-clone-consParamNames.patch
russell@unturf.com 547a9f5738 ORM wave 2: 10 new defects — Active Record +3, Exposed +3, SeaORM +4 (167 sites, 64 ecosystems)
rails-0009: FilterAttributeHandler filter_parameters Array O(A×F) → Set (450×)
rails-0010: Encryption::AutoFilteredParameters two Array scans → Set (250×)
rails-0011: TimeZoneConversion skip_list Array O(M×C×S) → Set (20×)

exposed-0001: SchemaUtilityApi mapMissingColumnStatements O(N×M) → map (118×)
exposed-0002: IdentifierManagerApi isAKeyword O(K) linear → HashSet (144×)
exposed-0003: Table.clone consParams.map fresh List → hoisted HashSet (6×)

seaorm-0001: active_model establish_links leftover.any O(N²) → HashSet (501×)
seaorm-0002: rbac engine group_permissions .values().find() → HashMap by ID (502×)
seaorm-0003: schema builder sorted_tables Vec::contains → HashSet (500×)
seaorm-0004: TopologicalSort from_iter seen Vec O(N²) → BTreeSet (28×)

Unit tests: RailsTest 11/11, ExposedTest 3/3, SeaORMTest 4/4 PASS
Whitepaper: 157→167 sites, 62→64 ecosystems; §13.12 ORM Wave 2 added
2026-03-27 13:49:46 -04:00

14 lines
1.1 KiB
Diff
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

--- a/exposed-core/src/main/kotlin/org/jetbrains/exposed/v1/core/Table.kt
+++ b/exposed-core/src/main/kotlin/org/jetbrains/exposed/v1/core/Table.kt
@@ -1682,8 +1682,10 @@ open class Table(
private fun <T : Any> T.clone(replaceArgs: Map<KProperty1<T, *>, Any> = emptyMap()): T = javaClass.kotlin.run {
val consParams = primaryConstructor!!.parameters
val mutableProperties = memberProperties.filterIsInstance<KMutableProperty1<T, Any?>>()
+ // CWE-407 fix: pre-compute constructor parameter names as HashSet to avoid O(P×C) repeated List allocations
+ val consParamNames = consParams.mapTo(HashSet()) { it.name }
val allValues = memberProperties
- .filter { it in mutableProperties || it.name in consParams.map(KParameter::name) }
+ .filter { it in mutableProperties || it.name in consParamNames }
.associate { it.name to (replaceArgs[it] ?: it.get(this@clone)) }
primaryConstructor!!.callBy(consParams.associateWith { allValues[it.name] }).also { newInstance ->
for (prop in mutableProperties) {