Skip to content

fix: Fix nil pointer dereference in getDockerToken on request creation failure - #23276

Open
SAY-5 wants to merge 4 commits into
cloudquery:mainfrom
SAY-5:fix-getdockertoken-nil-deref
Open

SAY-5 wants to merge 4 commits into
cloudquery:mainfrom
SAY-5:fix-getdockertoken-nil-deref

Conversation

@SAY-5

@SAY-5 SAY-5 commented Aug 25, 2026

Copy link
Copy Markdown

Summary

⚠️ If you're contributing to a plugin please read this section of the contribution guidelines 🧑‍🎓 before submitting this PR ⚠️

getDockerToken called req.Header.Add on the request returned by http.NewRequestWithContext before checking its error, so a failed URL parse (e.g. via a malformed realm in the auth challenge) panicked with a nil pointer dereference instead of returning an error. Moved the error check above the header calls. Also dropped a second os.ReadFile in GetSpecJsonScheme that could never hit its IsNotExist branch since the same read already succeeded above it.

Fixes #23164.

…ilure

Signed-off-by: Sai Asish Y <say.apm35@gmail.com>
@SAY-5
SAY-5 requested a review from a team as a code owner August 25, 2026 01:02
@SAY-5
SAY-5 requested a review from murarustefaan August 25, 2026 01:02
@greptile-apps

greptile-apps Bot commented Aug 25, 2026

Copy link
Copy Markdown

Greptile Summary

The PR prevents getDockerToken from dereferencing a nil request when a malformed authentication realm causes request creation to fail. It also removes a redundant schema-file read and adds focused regression coverage for both changes.

Confidence Score: 5/5

The PR appears safe to merge, with no actionable correctness or security issues identified.

The request error is now returned before the request is dereferenced, and the schema helper retains its established absent-file and successful-read behavior.

Important Files Changed

Filename Overview
cli/internal/publish/plugins.go Correctly checks request-construction errors before accessing headers and simplifies schema loading without changing normal missing-file semantics.
cli/internal/publish/plugins_test.go Adds focused coverage for malformed token-request URLs and both absent and present schema files.

Reviews (1): Last reviewed commit: "fix: nil pointer dereference in getDocke..." | Re-trigger Greptile

@murarustefaan

Copy link
Copy Markdown
Member

Hey @SAY-5!

First of all, thanks for the contribution, the change looks good.

Might I ask what prompted it?

@SAY-5

SAY-5 commented Aug 25, 2026

Copy link
Copy Markdown
Author

It's from #23164. A malformed realm in the registry auth challenge makes the request URL parse fail, and getDockerToken was calling req.Header.Add before checking that error, so it panicked on the nil request instead of returning it. Noticed it reading through the publish path.

@murarustefaan murarustefaan added automerge Automatically merge once required checks pass and removed automerge Automatically merge once required checks pass labels Sep 25, 2026
@murarustefaan murarustefaan changed the title fix: nil pointer dereference in getDockerToken on request creation failure fix: Fix nil pointer dereference in getDockerToken on request creation failure Sep 25, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

cli/internal/publish/plugins.go: nil pointer dereference in getDockerToken + dead code in GetSpecJsonScheme

2 participants