Skip to content

pkg/dns: GetDomainAddress panics with nil-pointer dereference on cache miss #1798

Description

@Priyanshubhartistm

What happened:

GetDomainAddress in pkg/dns/dns.go dereferences the map-lookup result before checking whether the domain was actually found, so a cache miss panics with a nil-pointer dereference.

func (r *DNSResolver) GetDomainAddress(domain string) ([]string, bool) {
  r.RLock()
  addresses, ok := r.cache[domain]   // dns.go:274 — addresses is nil when ok == false
  r.RUnlock()
  return addresses.Addresses, ok     // dns.go:276 — dereferences nil *DomainCacheEntry
}

r.cache is a map[string]*DomainCacheEntry. On a miss, addresses is a nil *DomainCacheEntry and ok is false, but the code still evaluates addresses.Addresses and panics. The ok value is computed but never used to guard the field access.

The two sibling accessors in the same package guard this correctly, which shows the intended pattern:

  • GetDNSAddresses (pkg/dns/utils.go:110): if entry, ok := r.cache[domain]; ok { return entry.Addresses }
  • getByNamespace (pkg/auth/policy_store.go:122): if s, ok := ps.byNamespace[namespace]; ok { ... }

GetDomainAddress is the only place in the tree that reads the value before the ok check.

What you expected to happen:

On a cache miss, return nil, false instead of panicking:

func (r *DNSResolver) GetDomainAddress(domain string) ([]string, bool) {
  r.RLock()
  defer r.RUnlock()
  if entry, ok := r.cache[domain]; ok {
    return entry.Addresses, true
  }
  return nil, false
}

How to reproduce it (as minimally and precisely as possible):

Unit test:

r, _ := NewDNSResolver()
r.GetDomainAddress("absent.example.com") // panics: runtime error: invalid memory address or nil pointer dereference

Anything else we need to know?:

GetDomainAddress currently has no non-test callers, so this is a latent landmine rather than an active crash today - but it is an unambiguous bug and will panic the first time it is called with an unknown domain. Trivial, obviously-correct fix.

Environment:

  • Kmesh version: main (current, a28a1a19)
  • Kmesh mode(kmesh has Kernel-Native Mode and Dual-Engine Mode): N/A (bug is in shared DNS resolver code)
  • Istio version: N/A
  • Kernel version: N/A
  • Others: N/A

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions