Sean-Walker0 opened a new pull request, #7364:
URL: https://github.com/apache/shenyu/pull/7364

   <!-- Describe your PR here; e.g. Fixes #issueNo -->
   Found by code audit (no existing issue — happy to file one if maintainers 
prefer).
   
   `SelectorEventPublisher#onDeleted(Collection, List)` resolves each 
selector's plugin name via `pluginMap.get(selectorDO.getPluginId())` and 
immediately calls `pluginName.equals(PluginEnum.DIVIDE.getName())`. Callers do 
not guarantee the map covers every selector: 
`SelectorServiceImpl#deleteByNamespaceId` builds it from 
`pluginMapper.selectByIds(...)`, which silently drops ids whose plugin row no 
longer exists — so deleting a **dangling selector** (one whose plugin was 
already removed, reachable because `selectByIdSet` does not join plugins) 
throws `NullPointerException` inside the event publisher and fails the whole 
deletion request. The sibling `RuleEventPublisher#onDeleted` performs the same 
plugin lookup null-safely via `Optional`, confirming the anticipated state.
   
   <!--
   Thank you for proposing a pull request. This template will guide you through 
the essential steps necessary for a pull request.
   -->
   Make sure that:
   
   - [x] You have read the [contribution 
guidelines](https://shenyu.apache.org/community/contributor-guide).
   - [x] You submit test cases (unit or integration tests) that back your 
changes.
   - [x] Your local test passed `./mvnw test -pl shenyu-admin -am and ./mvnw 
checkstyle:check -pl shenyu-admin` (module-scoped; full build left to CI).
   
   ### Modifications
   
   - Flip the comparison to constant-first: 
`PluginEnum.DIVIDE.getName().equals(pluginName)` — null-safe, identical 
semantics for present plugin names, and the deletion events now publish with a 
null plugin name instead of crashing.
   
   ### Verifying this change
   
   - New `testOnDeletedSelectorReferencingMissingPlugin` deletes a selector 
whose pluginId is absent from the plugins list and asserts both deletion events 
still publish. It fails on current master with `NullPointerException: Cannot 
invoke "String.equals(Object)" because "pluginName" is null` and passes with 
this change.
   - Full `shenyu-admin` module suite green (502 test classes); checkstyle 
green.
   
   ### Notes
   
   - Behavior change: deleting selectors that reference an already-deleted 
plugin now succeeds and publishes its events instead of returning 500.
   - Orthogonal to open PRs: no open PR touches `SelectorEventPublisher` 
(checked against the file lists of all 198 open PRs).


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to