Add Redos static analysis utility to labs.regex and RedosVulnerability Error Prone checker Implements static AST analysis on RegexPattern to detect Regular Expression Denial of Service (ReDoS) / catastrophic backtracking vulnerabilities. Features: - Functional Stream-based and IntStream-based AST traversal returning ImmutableList<Finding> with flatMap(). - Synthesizes the culprit attack witness input string and formula using StringFormat template and Substring.all().replaceAllFrom(). - Detects nested unbounded quantifiers, overlapping alternations, adjacent overlapping quantifiers, and optional element overlaps. - Guards against false positives on possessive quantifiers, bounded limits, and disjoint delimiters. - Adds Error Prone BugChecker RedosVulnerability extending AbstractPatternSyntaxChecker, generating RedosVulnerability_refactoring for flumejavac / JavacFlume. - Comprehensive test coverage including unit tests, mutation testing (100% kill score), property-based AST and regex grammar fuzzer tests in RedosFuzzTest, and RedosVulnerabilityTest. - Tests written with TestParameterInjector, Truth assertThat(), and JUnit4. PiperOrigin-RevId: 964990494
Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.
public class ShortSet { public static void main (String[] args) { Set<Short> s = new HashSet<>(); for (short i = 0; i < 100; i++) { s.add(i); s.remove(i - 1); } System.out.println(s.size()); } }
error: [CollectionIncompatibleType] Argument 'i - 1' should not be passed to this method;
its type int is not compatible with its collection's type argument Short
s.remove(i - 1);
^
(see https://errorprone.info/bugpattern/CollectionIncompatibleType)
1 error
Our documentation is at errorprone.info.
Error Prone works with Bazel, Maven, Ant, and Gradle. See our installation instructions for details.
Developing and building Error Prone is documented on the wiki.