Aias00 opened a new issue, #6861:
URL: https://github.com/apache/shenyu/issues/6861

   ## Description
   Each parser iterates `for (String label : labels.keySet())` where `labels` 
comes from `ingress.getMetadata().getLabels()`, which returns null when no 
labels are set — `labels.keySet()` NPEs. Inside the loop, 
`serviceLister.namespace(namespace).get(labels.get(label)).getMetadata().getAnnotations()`
 is a 4-deep deref chain with no null check — if the referenced Service does 
not exist, `.getMetadata()` NPEs.
   
   ## Location
   - 
`shenyu-kubernetes-controller/src/main/java/org/apache/shenyu/k8s/parser/GrpcParser.java:255-256`
   - 
`shenyu-kubernetes-controller/src/main/java/org/apache/shenyu/k8s/parser/DubboIngressParser.java:241-242`
   - 
`shenyu-kubernetes-controller/src/main/java/org/apache/shenyu/k8s/parser/SofaParser.java:172-173`
   
   ## Impact
   A gRPC/Dubbo/Sofa ingress with no k8s labels (or referencing a non-existent 
Service) crashes the reconcile with NPE, blocking route configuration for that 
ingress.
   
   ## Suggested fix
   Null-check `labels` before the loop (`if (Objects.isNull(labels)) return 
res;`); inside the loop, fetch `V1Service svc = 
serviceLister.namespace(namespace).get(labels.get(label)); if 
(Objects.isNull(svc)) { continue; }` before dereferencing.
   
   ## Related existing
   None — the label-chain deref pattern is not covered by GOV-T6 (#6679) or any 
baseline item.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to