Skip to content

Commit 22dd3b1

Browse files
Init
0 parents  commit 22dd3b1

30 files changed

Lines changed: 820 additions & 0 deletions

‎.github/workflows/codeql.yml‎

Lines changed: 99 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,99 @@
1+
# For most projects, this workflow file will not need changing; you simply need
2+
# to commit it to your repository.
3+
#
4+
# You may wish to alter this file to override the set of languages analyzed,
5+
# or to provide custom queries or build logic.
6+
#
7+
# ******** NOTE ********
8+
# We have attempted to detect the languages in your repository. Please check
9+
# the `language` matrix defined below to confirm you have the correct set of
10+
# supported CodeQL languages.
11+
#
12+
name: "CodeQL Advanced"
13+
14+
on:
15+
push:
16+
branches: [ "main" ]
17+
pull_request:
18+
branches: [ "main" ]
19+
schedule:
20+
- cron: '31 1 * * 3'
21+
22+
jobs:
23+
analyze:
24+
name: Analyze (${{ matrix.language }})
25+
# Runner size impacts CodeQL analysis time. To learn more, please see:
26+
# - https://gh.io/recommended-hardware-resources-for-running-codeql
27+
# - https://gh.io/supported-runners-and-hardware-resources
28+
# - https://gh.io/using-larger-runners (GitHub.com only)
29+
# Consider using larger runners or machines with greater resources for possible analysis time improvements.
30+
runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 'ubuntu-latest' }}
31+
permissions:
32+
# required for all workflows
33+
security-events: write
34+
35+
# required to fetch internal or private CodeQL packs
36+
packages: read
37+
38+
# only required for workflows in private repositories
39+
actions: read
40+
contents: read
41+
42+
strategy:
43+
fail-fast: false
44+
matrix:
45+
include:
46+
- language: java-kotlin
47+
build-mode: none # This mode only analyzes Java. Set this to 'autobuild' or 'manual' to analyze Kotlin too.
48+
# CodeQL supports the following values keywords for 'language': 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'rust', 'swift'
49+
# Use `c-cpp` to analyze code written in C, C++ or both
50+
# Use 'java-kotlin' to analyze code written in Java, Kotlin or both
51+
# Use 'javascript-typescript' to analyze code written in JavaScript, TypeScript or both
52+
# To learn more about changing the languages that are analyzed or customizing the build mode for your analysis,
53+
# see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning.
54+
# If you are analyzing a compiled language, you can modify the 'build-mode' for that language to customize how
55+
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
56+
steps:
57+
- name: Checkout repository
58+
uses: actions/checkout@v4
59+
60+
# Add any setup steps before running the `github/codeql-action/init` action.
61+
# This includes steps like installing compilers or runtimes (`actions/setup-node`
62+
# or others). This is typically only required for manual builds.
63+
# - name: Setup runtime (example)
64+
# uses: actions/setup-example@v1
65+
66+
# Initializes the CodeQL tools for scanning.
67+
- name: Initialize CodeQL
68+
uses: github/codeql-action/init@v4
69+
with:
70+
languages: ${{ matrix.language }}
71+
build-mode: ${{ matrix.build-mode }}
72+
# If you wish to specify custom queries, you can do so here or in a config file.
73+
# By default, queries listed here will override any specified in a config file.
74+
# Prefix the list here with "+" to use these queries and those in the config file.
75+
76+
# For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
77+
queries: security-extended,security-and-quality
78+
79+
# If the analyze step fails for one of the languages you are analyzing with
80+
# "We were unable to automatically build your code", modify the matrix above
81+
# to set the build mode to "manual" for that language. Then modify this step
82+
# to build your code.
83+
# ℹ️ Command-line programs to run using the OS shell.
84+
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
85+
- name: Run manual build steps
86+
if: matrix.build-mode == 'manual'
87+
shell: bash
88+
run: |
89+
echo 'If you are using a "manual" build mode for one or more of the' \
90+
'languages you are analyzing, replace this with the commands to build' \
91+
'your code, for example:'
92+
echo ' make bootstrap'
93+
echo ' make release'
94+
exit 1
95+
96+
- name: Perform CodeQL Analysis
97+
uses: github/codeql-action/analyze@v4
98+
with:
99+
category: "/language:${{matrix.language}}"

‎pom.xml‎

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<project xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd" xmlns="http://maven.apache.org/POM/4.0.0"
3+
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
4+
<modelVersion>4.0.0</modelVersion>
5+
<groupId>es.uniovi.reflection</groupId>
6+
<artifactId>SyntheticProgram_CMU_SEC56</artifactId>
7+
<version>1.0-SNAPSHOT</version>
8+
9+
<properties>
10+
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
11+
<project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>
12+
<maven.compiler.encoding>UTF-8</maven.compiler.encoding>
13+
<maven.compiler.release>22</maven.compiler.release>
14+
</properties>
15+
16+
<dependencies>
17+
<dependency>
18+
<groupId>org.glassfish.corba</groupId>
19+
<artifactId>glassfish-corba-omgapi</artifactId>
20+
<version>5.0.0</version>
21+
</dependency>
22+
</dependencies>
23+
</project>
Lines changed: 107 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,107 @@
1+
package es.uniovi.reflection.sec_56;
2+
3+
import java.util.AbstractList;
4+
import java.util.Arrays;
5+
6+
public class CustomAbstractList<E> extends AbstractList<E> {
7+
private Object[] data;
8+
private int size;
9+
10+
private static final int INITIAL_CAPACITY = 10;
11+
12+
// --- Constructors ---
13+
14+
public CustomAbstractList() {
15+
this.data = new Object[INITIAL_CAPACITY];
16+
this.size = 0;
17+
}
18+
19+
// --- Core List Methods (Required by AbstractList) ---
20+
21+
/**
22+
* Retrieves the element at the specified position in this list.
23+
* Required to be implemented by AbstractList.
24+
* Note: AbstractList handles the index check (rangeCheck).
25+
*/
26+
@Override
27+
@SuppressWarnings("unchecked")
28+
public E get(int index) {
29+
// AbstractList handles the size() check before calling this method.
30+
// We just need to check the array boundaries if necessary, but AbstractList's rangeCheck does it.
31+
return (E) data[index];
32+
}
33+
34+
/**
35+
* Returns the number of elements in this list.
36+
* Required to be implemented by AbstractList.
37+
*/
38+
@Override
39+
public int size() {
40+
return size;
41+
}
42+
43+
// --- Mutation Methods (Overridden from AbstractList) ---
44+
45+
/**
46+
* Appends the specified element to the end of this list.
47+
* Overrides the AbstractList implementation.
48+
*/
49+
@Override
50+
public boolean add(E element) {
51+
// We must increment modCount manually since we are overriding add(E e).
52+
// The add(int index, E element) method in AbstractList handles modCount,
53+
// but this one (which calls add(size, element)) doesn't, so we add it here.
54+
modCount++;
55+
56+
ensureCapacity(size + 1);
57+
data[size++] = element;
58+
59+
return true;
60+
}
61+
62+
/**
63+
* Removes the element at the specified position in this list.
64+
* Overrides the AbstractList implementation.
65+
*/
66+
@Override
67+
@SuppressWarnings("unchecked")
68+
public E remove(int index) {
69+
// AbstractList's remove(int index) handles the index check (rangeCheck) and modCount increment.
70+
71+
E removedElement = (E) data[index];
72+
73+
// Calculate how many elements need to be shifted
74+
int numShifted = size - index - 1;
75+
76+
if (numShifted > 0) {
77+
// Shift elements efficiently using System.arraycopy
78+
System.arraycopy(data, index + 1, data, index, numShifted);
79+
}
80+
81+
// Decrease size and clear the last reference (for Garbage Collection)
82+
data[--size] = null;
83+
84+
return removedElement;
85+
}
86+
87+
// --- Internal Utility Methods ---
88+
89+
private void ensureCapacity(int minCapacity) {
90+
if (minCapacity > data.length) {
91+
grow(minCapacity);
92+
}
93+
}
94+
95+
private void grow(int minCapacity) {
96+
int oldCapacity = data.length;
97+
// New capacity = Old Capacity * 1.5
98+
int newCapacity = oldCapacity + (oldCapacity >> 1);
99+
100+
if (newCapacity < minCapacity) {
101+
newCapacity = minCapacity;
102+
}
103+
104+
data = Arrays.copyOf(data, newCapacity);
105+
System.out.println("DEBUG: Array resized to capacity " + newCapacity);
106+
}
107+
}
Lines changed: 119 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,119 @@
1+
package es.uniovi.reflection.sec_56;
2+
3+
import org.omg.CosNaming.*;
4+
import org.omg.CORBA.*;
5+
6+
public abstract class CustomAbstractNamingContextImpl implements NamingContext {
7+
8+
@Override
9+
public void bind(NameComponent[] n, org.omg.CORBA.Object obj) {
10+
System.out.println("bind from abstract class");
11+
}
12+
13+
@Override
14+
public void bind_context(NameComponent[] n, NamingContext nc) {
15+
}
16+
17+
@Override
18+
public NamingContext new_context() {
19+
return null;
20+
}
21+
22+
@Override
23+
public NamingContext bind_new_context(NameComponent[] n) {
24+
return null;
25+
}
26+
27+
@Override
28+
public org.omg.CORBA.Object resolve(NameComponent[] n) {
29+
return null;
30+
}
31+
32+
@Override
33+
public void unbind(NameComponent[] n) {
34+
}
35+
36+
@Override
37+
public void rebind(NameComponent[] n, org.omg.CORBA.Object obj) {
38+
}
39+
40+
@Override
41+
public void rebind_context(NameComponent[] n, NamingContext nc) {
42+
}
43+
44+
@Override
45+
public void destroy() {
46+
}
47+
48+
@Override
49+
public void list(int how_many, BindingListHolder bl, BindingIteratorHolder bi) {
50+
bl.value = new Binding[0];
51+
bi.value = null;
52+
}
53+
54+
// Methods inherited from org.omg.CORBA.Object
55+
56+
@Override
57+
public Request _create_request(Context ctx, String operation, NVList arg_list, NamedValue result) {
58+
return null;
59+
}
60+
61+
@Override
62+
public Request _create_request(Context ctx, String operation, NVList arg_list, NamedValue result, ExceptionList exclist, ContextList ctxlist) {
63+
return null;
64+
}
65+
66+
@Override
67+
public org.omg.CORBA.Object _duplicate() {
68+
return this;
69+
}
70+
71+
@Override
72+
public DomainManager[] _get_domain_managers() {
73+
return new DomainManager[0];
74+
}
75+
76+
@Override
77+
public org.omg.CORBA.Object _get_interface_def() {
78+
return null;
79+
}
80+
81+
@Override
82+
public Policy _get_policy(int policy_type) {
83+
return null;
84+
}
85+
86+
@Override
87+
public int _hash(int maximum) {
88+
return 0;
89+
}
90+
91+
@Override
92+
public boolean _is_a(String repository_id) {
93+
return false;
94+
}
95+
96+
@Override
97+
public boolean _is_equivalent(org.omg.CORBA.Object other) {
98+
return false;
99+
}
100+
101+
@Override
102+
public boolean _non_existent() {
103+
return false;
104+
}
105+
106+
@Override
107+
public void _release() {
108+
}
109+
110+
@Override
111+
public Request _request(String operation) {
112+
return null;
113+
}
114+
115+
@Override
116+
public org.omg.CORBA.Object _set_policy_override(Policy[] policies, SetOverrideType set_add) {
117+
return this;
118+
}
119+
}
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
package es.uniovi.reflection.sec_56;
2+
3+
import org.omg.CosNaming.*;
4+
import org.omg.CORBA.*;
5+
import es.uniovi.reflection.sec_56.CustomAbstractNamingContextImpl;
6+
7+
public class CustomNamingContextImpl extends CustomAbstractNamingContextImpl {
8+
@Override
9+
public void bind(NameComponent[] n, org.omg.CORBA.Object obj) {
10+
System.out.println("bind from subclass");
11+
}
12+
}
Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
package es.uniovi.reflection.sec_56;
2+
3+
import org.omg.PortableInterceptor.ObjectReferenceFactory;
4+
import org.omg.PortableInterceptor.ObjectReferenceFactoryHelper;
5+
import org.omg.CORBA.ORB;
6+
import org.omg.CORBA.Object;
7+
8+
public class CustomObjectReferenceFactoryImpl implements ObjectReferenceFactory {
9+
10+
private ORB orb;
11+
12+
public CustomObjectReferenceFactoryImpl(ORB orb) {
13+
this.orb = orb;
14+
}
15+
16+
@Override
17+
public Object make_object(String repositoryId, byte[] objectId) {
18+
System.out.println("make_object called with repositoryId: " + repositoryId);
19+
System.out.println("objectId: " + new String(objectId));
20+
return null;
21+
}
22+
23+
@Override
24+
public String[] _truncatable_ids() {
25+
return new String[]{};
26+
}
27+
}

0 commit comments

Comments
 (0)