Sean-Walker0 opened a new pull request, #7364: URL: https://github.com/apache/shenyu/pull/7364
<!-- Describe your PR here; e.g. Fixes #issueNo --> Found by code audit (no existing issue — happy to file one if maintainers prefer). `SelectorEventPublisher#onDeleted(Collection, List)` resolves each selector's plugin name via `pluginMap.get(selectorDO.getPluginId())` and immediately calls `pluginName.equals(PluginEnum.DIVIDE.getName())`. Callers do not guarantee the map covers every selector: `SelectorServiceImpl#deleteByNamespaceId` builds it from `pluginMapper.selectByIds(...)`, which silently drops ids whose plugin row no longer exists — so deleting a **dangling selector** (one whose plugin was already removed, reachable because `selectByIdSet` does not join plugins) throws `NullPointerException` inside the event publisher and fails the whole deletion request. The sibling `RuleEventPublisher#onDeleted` performs the same plugin lookup null-safely via `Optional`, confirming the anticipated state. <!-- Thank you for proposing a pull request. This template will guide you through the essential steps necessary for a pull request. --> Make sure that: - [x] You have read the [contribution guidelines](https://shenyu.apache.org/community/contributor-guide). - [x] You submit test cases (unit or integration tests) that back your changes. - [x] Your local test passed `./mvnw test -pl shenyu-admin -am and ./mvnw checkstyle:check -pl shenyu-admin` (module-scoped; full build left to CI). ### Modifications - Flip the comparison to constant-first: `PluginEnum.DIVIDE.getName().equals(pluginName)` — null-safe, identical semantics for present plugin names, and the deletion events now publish with a null plugin name instead of crashing. ### Verifying this change - New `testOnDeletedSelectorReferencingMissingPlugin` deletes a selector whose pluginId is absent from the plugins list and asserts both deletion events still publish. It fails on current master with `NullPointerException: Cannot invoke "String.equals(Object)" because "pluginName" is null` and passes with this change. - Full `shenyu-admin` module suite green (502 test classes); checkstyle green. ### Notes - Behavior change: deleting selectors that reference an already-deleted plugin now succeeds and publishes its events instead of returning 500. - Orthogonal to open PRs: no open PR touches `SelectorEventPublisher` (checked against the file lists of all 198 open PRs). -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
