[ 
https://issues.apache.org/jira/browse/KAFKA-20894?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18102217#comment-18102217
 ] 

Matthias J. Sax commented on KAFKA-20894:
-----------------------------------------

Thanks for the ticket – I am just wondering how we could hit this, ie, when is 
`toString()` actually used?

> StreamsGroupDescription.toString throws NullPointerException when authorized 
> operations are omitted
> ---------------------------------------------------------------------------------------------------
>
>                 Key: KAFKA-20894
>                 URL: https://issues.apache.org/jira/browse/KAFKA-20894
>             Project: Kafka
>          Issue Type: Bug
>          Components: clients
>            Reporter: GiminKim
>            Assignee: GiminKim
>            Priority: Minor
>
> h2. Problem
> `DescribeStreamsGroupsOptions.includeAuthorizedOperations()` defaults to 
> `false`. In this normal request path, the broker omits authorized operations 
> and `AdminUtils.validAclOperations()` converts the omitted value to `null`. 
> `StreamsGroupDescription` and its Javadoc explicitly allow that nullable 
> state.
> However, `StreamsGroupDescription.toString()` unconditionally calls 
> `authorizedOperations.stream()`. As a result, merely logging or rendering a 
> successfully returned description can throw `NullPointerException`.
> h2. Reproduction
> {code:java}
> StreamsGroupDescription description = result.get();
> log.info("group={}", description);
> {code}
> The failure occurs when authorized operations were not requested:
> {code}
> includeAuthorizedOperations=false
>   -> server omits authorized operations
>   -> validAclOperations() returns null
>   -> StreamsGroupDescription stores null
>   -> toString() calls authorizedOperations.stream()
>   -> NullPointerException
> {code}
> h2. Expected behavior
> `toString()` should handle the documented omitted state and render 
> `authorizedOperations=null`. Formatting for populated authorized-operation 
> sets should remain unchanged.
> h2. Root cause
> The constructor and accessor accept and document `null`, but `toString()` 
> assumes the set is always non-null.
> h2. Proposed fix
> Add a null check in `StreamsGroupDescription.toString()` and extend the 
> existing AdminClient test for an omitted authorized-operations response to 
> assert that `toString()` does not throw and includes 
> `authorizedOperations=null`.
> h2. Testing
> * Targeted `KafkaAdminClientTest` and `DescribeStreamsGroupsHandlerTest`
> * Full `clients:test` suite
> * Checkstyle and SpotBugs main analysis
> * `spotlessCheck`
> All applicable local tests and quality checks pass.
> h2. Pull request
> [apache/kafka#23083|https://github.com/apache/kafka/pull/23083]



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to