Aias00 opened a new issue, #6609:
URL: https://github.com/apache/shenyu/issues/6609

   ## Background
   
   A 2026-08-02 source audit confirmed that 7 open issues share the **same root 
cause**: k8s ingress parsers and reconcilers in `shenyu-kubernetes-controller` 
dereference informer lookups, annotations, labels, and per-address arrays 
**without null/length guards**, producing NPEs / 
`ArrayIndexOutOfBoundsException`s during transient cache misses or 
partial/missing annotations.
   
   ## Affected issues (all verified VALID)
   - #6484 Dubbo ingress parsing throws NPE when endpoints are missing 
(`DubboIngressParser.java:337-338, 161-162` — `v1Endpoints.getSubsets()` with 
no null check on `v1Endpoints`; contrast `DivideIngressParser` which guards)
   - #6490 gRPC ingress parsing throws NPE when endpoints are missing 
(`GrpcParser.java:156, 187` — same gap)
   - #6486 Kubernetes RPC ingress parsers can throw NPE when labels or services 
are missing (`DubboIngressParser.java:241-242`, `GrpcParser.java:255-256`, 
`SofaParser.java:172-173` — `labels.keySet()` and 
`serviceLister...get(...).getMetadata()` unguarded)
   - #6491 Ingress reconciler dereferences missing ingress or annotations 
before validation (`IngressReconciler.java:134-138` — annotation access before 
the `isNull(v1Ingress)` check; `enablePluginsBasedOnAnnotations` NPEs on null 
annotations)
   - #6485 Kubernetes upstream protocol annotation can break Divide and Dubbo 
ingress parsing (`DivideIngressParser.java:325` array index OOB; 
`DubboIngressParser.java:339` NPE on absent annotation; `:356` double-increment 
of `i`)
   - #6492 Kubernetes gRPC/Sofa context-path parsing reads annotations from the 
wrong resource (`IngressParser.java:109` -> `ContextPathParser.java:87` reads 
ingress annotations while the examples place the annotation on the Service; 
injected `serviceLister` is dead)
   - #6493 Endpoint updates can rewrite multi-port service routes to the wrong 
port (`EndpointsReconciler.java:192-195` picks first TCP port; 
`ServiceIngressCache` never records the selected backend port)
   
   ## Suggested fix pattern
   1. **Standardize the lister-lookup guard**: every 
`endpointsLister.namespace(ns).get(name)` / `serviceLister...get(...)` must 
null-check before `.getSubsets()`/`.getMetadata()` — mirror the existing guard 
in `IngressReconciler.java:578-582` and `DivideIngressParser`.
   2. **Validate annotations/labels before use**: null-check 
`getAnnotations()`/`getLabels()`; skip-and-defer (let a later reconcile retry) 
when the referenced Service is not yet in cache.
   3. **Bounds-check per-address arrays** (the `protocol[i++]` pattern) and fix 
the double-increment in `DubboIngressParser.java:356`.
   4. **Persist the selected backend port** through `ServiceIngressCache` so 
`EndpointsReconciler` rewrites preserve the ingress-selected port.
   5. Add unit tests with missing endpoints/annotations/labels as fixtures (the 
current controller tests cover only the happy path — see the governance audit).
   
   ## Goal
   Track the shared hardening pass so the 7 issues close under one focused PR 
rather than seven scattered patches.
   
   _Audit ref: docs/issue-candidates-2026-08-02.md_
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to