Skip to content

fix: report IMPORT_TRANSFORM of a non-existent domain instead of crashing - #4969

Merged
TomOnTime merged 1 commit into
DNSControl:mainfrom
SulimanAbdulrazzaq:fix/import-transform-missing-domain
Oct 3, 2026
Merged

TomOnTime merged 1 commit into
DNSControl:mainfrom
SulimanAbdulrazzaq:fix/import-transform-missing-domain

Conversation

@SulimanAbdulrazzaq

Copy link
Copy Markdown
Contributor

ValidateAndNormalizeConfig records the error IMPORT_TRANSFORM mentions non-existent domain "..." when the domain named by an IMPORT_TRANSFORM is not in the config, but it then calls importTransform with the nil domain anyway. That dereferences it, so dnscontrol check (and preview/push, which run the same validation) dies with a nil-pointer panic and a stack trace instead of printing the validation error.

The fix is the missing continue after the error is recorded, the same as the branch just above it that handles a transform table that cannot be decoded.

Example dnsconfig.js (the second domain names baz.com, which is not defined):

var REG_NONE = NewRegistrar("none");
var DNS_NONE = NewDnsProvider("none");
var TRANSFORM = [{ low: "1.2.3.10", high: "1.2.3.20", newBase: "123.123.123.100" }];
D("foo.com", REG_NONE, DnsProvider(DNS_NONE), A("one", "1.2.3.1"));
D("bar.com", REG_NONE, DnsProvider(DNS_NONE), A("www", "123.123.123.123"), IMPORT_TRANSFORM(TRANSFORM, "baz.com", 300));

dnscontrol check on the base commit (built on my fork's CI):

panic: runtime error: invalid memory address or nil pointer dereference
github.com/DNSControl/dnscontrol/v5/pkg/normalize.importTransform(0x0, ...)
	pkg/normalize/validate.go:286
github.com/DNSControl/dnscontrol/v5/pkg/normalize.ValidateAndNormalizeConfig(...)
	pkg/normalize/validate.go:534
exit status: 2

With this change:

1 Validation errors:
ERROR: IMPORT_TRANSFORM mentions non-existent domain "baz.com"
exiting due to validation errors
exit status: 1

Test: TestImportTransformMissingDomain in pkg/normalize/importTransform_test.go. It calls ValidateAndNormalizeConfig with an IMPORT_TRANSFORM that names a missing domain and expects the error (and no panic). On the base commit it fails with ValidateAndNormalizeConfig panicked: runtime error: invalid memory address or nil pointer dereference; with the change it passes.

Fork CI on the same tree as this PR (Go stable, linux): go test ./pkg/normalize/..., the full go test ./..., go build, go vet ./pkg/normalize/..., gofmt on pkg/normalize, go fix ./... (no diff) and golangci-lint all succeed. This change does not touch generated files.

Other places I checked: DNSConfig.FindDomain is only called here, and importTransform's other argument (domain) comes from the loop and is never nil.

…hing

ValidateAndNormalizeConfig records an error when the domain named by an
IMPORT_TRANSFORM does not exist, but then calls importTransform with the nil
domain anyway, which dereferences it and panics. Skip the transform after
recording the error, as is done when the transform table cannot be decoded.
@TomOnTime
TomOnTime merged commit 094cc35 into DNSControl:main Oct 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants