Aias00 opened a new issue, #6864:
URL: https://github.com/apache/shenyu/issues/6864
## Description
In `parseUpstream`, the `protocol` array is populated from
`annotations.get(UPSTREAMS_PROTOCOL_ANNOTATION_KEY).split(",")` (line 307).
Then for each endpoint address, line 325 does `protocol[i++]` where `i`
increments per address. If the user provides fewer comma-separated protocol
values than there are endpoint addresses (e.g. 2 protocols for 3 endpoints),
`i` exceeds the array bounds and throws `ArrayIndexOutOfBoundsException`. The
sibling `DubboIngressParser` (line 348-349) has the same `protocol[i++]`
pattern.
## Location
-
`shenyu-kubernetes-controller/src/main/java/org/apache/shenyu/k8s/parser/DivideIngressParser.java:325`
(same at `DubboIngressParser.java:348-349`)
## Impact
An ingress with a mismatched `upstreams-protocol` annotation (fewer
protocols than endpoints) crashes the reconcile, blocking route configuration.
## Suggested fix
Guard with `protocol.length > i ? protocol[i++] : "http://"` (or cycle:
`protocol[i % protocol.length]`), and add a bounds check.
## Related existing
None — #6598 covers http:// hardcode in `EndpointsReconciler`; this is an
AIOOBE in the parser.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]