This is an automated email from the ASF dual-hosted git repository. asf-gitbox-commits pushed a commit to branch misc-hardening__MATH-1691 in repository https://gitbox.apache.org/repos/asf/commons-math.git
commit 77e7044ba4a98ca3ca4e05d3bc8923e2b9acbdce Author: Gilles Sadowski <[email protected]> AuthorDate: Sun Sep 27 18:40:46 2026 +0200 MATH-1691: Abort early on non finite input. Found by a security scan. --- .../math4/transform/TransformException.java | 2 ++ .../commons/math4/transform/TransformUtils.java | 8 ++++++++ .../math4/transform/TransformUtilsTest.java | 24 ++++++++++++++++++++++ 3 files changed, 34 insertions(+) diff --git a/commons-math-transform/src/main/java/org/apache/commons/math4/transform/TransformException.java b/commons-math-transform/src/main/java/org/apache/commons/math4/transform/TransformException.java index 0591b330d..04e585743 100644 --- a/commons-math-transform/src/main/java/org/apache/commons/math4/transform/TransformException.java +++ b/commons-math-transform/src/main/java/org/apache/commons/math4/transform/TransformException.java @@ -23,6 +23,8 @@ import java.text.MessageFormat; * Class is package-private (for internal use only). */ class TransformException extends IllegalArgumentException { + /** Error message for non finite argument. */ + public static final String NOT_FINITE = "Argument '{0}' is not finite: {1}"; /** Error message for "out of range" condition. */ public static final String FIRST_ELEMENT_NOT_ZERO = "First element ({0}) must be 0"; /** Error message for "not strictly positive" condition. */ diff --git a/commons-math-transform/src/main/java/org/apache/commons/math4/transform/TransformUtils.java b/commons-math-transform/src/main/java/org/apache/commons/math4/transform/TransformUtils.java index 9a54af968..f2910ee2f 100644 --- a/commons-math-transform/src/main/java/org/apache/commons/math4/transform/TransformUtils.java +++ b/commons-math-transform/src/main/java/org/apache/commons/math4/transform/TransformUtils.java @@ -145,6 +145,14 @@ final class TransformUtils { throw new TransformException(TransformException.NOT_STRICTLY_POSITIVE, Integer.valueOf(n)); } + if (!Double.isFinite(min)) { + throw new TransformException(TransformException.NOT_FINITE, "min", + Double.valueOf(min)); + } + if (!Double.isFinite(max)) { + throw new TransformException(TransformException.NOT_FINITE, "max", + Double.valueOf(max)); + } if (min >= max) { throw new TransformException(TransformException.TOO_LARGE, min, max); } diff --git a/commons-math-transform/src/test/java/org/apache/commons/math4/transform/TransformUtilsTest.java b/commons-math-transform/src/test/java/org/apache/commons/math4/transform/TransformUtilsTest.java index c1b3599ab..3f1a7f307 100644 --- a/commons-math-transform/src/test/java/org/apache/commons/math4/transform/TransformUtilsTest.java +++ b/commons-math-transform/src/test/java/org/apache/commons/math4/transform/TransformUtilsTest.java @@ -39,6 +39,30 @@ public class TransformUtilsTest { TransformUtils.sample(SIN, Math.PI, 0.0, 10)); } + @Test + public void testSampleInfiniteMinBound() { + assertThrows(TransformException.class, () -> + TransformUtils.sample(SIN, Double.NEGATIVE_INFINITY, 1, 10)); + } + + @Test + public void testSampleMinBoundNaN() { + assertThrows(TransformException.class, () -> + TransformUtils.sample(SIN, Double.NaN, 1, 10)); + } + + @Test + public void testSampleInfiniteMaxBound() { + assertThrows(TransformException.class, () -> + TransformUtils.sample(SIN, 0, Double.POSITIVE_INFINITY, 10)); + } + + @Test + public void testSampleMaxBoundNaN() { + assertThrows(TransformException.class, () -> + TransformUtils.sample(SIN, 0, Double.NaN, 10)); + } + @Test public void testSampleNegativeNumberOfPoints() { assertThrows(TransformException.class, () ->
