Repository navigation
fix: report IMPORT_TRANSFORM of a non-existent domain instead of crashing - #4969
Merged
TomOnTime merged 1 commit intoOct 3, 2026
Conversation
…hing ValidateAndNormalizeConfig records an error when the domain named by an IMPORT_TRANSFORM does not exist, but then calls importTransform with the nil domain anyway, which dereferences it and panics. Skip the transform after recording the error, as is done when the transform table cannot be decoded.
TomOnTime
approved these changes
Oct 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ValidateAndNormalizeConfigrecords the errorIMPORT_TRANSFORM mentions non-existent domain "..."when the domain named by anIMPORT_TRANSFORMis not in the config, but it then callsimportTransformwith the nil domain anyway. That dereferences it, sodnscontrol check(and preview/push, which run the same validation) dies with a nil-pointer panic and a stack trace instead of printing the validation error.The fix is the missing
continueafter the error is recorded, the same as the branch just above it that handles a transform table that cannot be decoded.Example
dnsconfig.js(the second domain namesbaz.com, which is not defined):dnscontrol checkon the base commit (built on my fork's CI):With this change:
Test:
TestImportTransformMissingDomaininpkg/normalize/importTransform_test.go. It callsValidateAndNormalizeConfigwith anIMPORT_TRANSFORMthat names a missing domain and expects the error (and no panic). On the base commit it fails withValidateAndNormalizeConfig panicked: runtime error: invalid memory address or nil pointer dereference; with the change it passes.Fork CI on the same tree as this PR (Go stable, linux):
go test ./pkg/normalize/..., the fullgo test ./...,go build,go vet ./pkg/normalize/...,gofmtonpkg/normalize,go fix ./...(no diff) and golangci-lint all succeed. This change does not touch generated files.Other places I checked:
DNSConfig.FindDomainis only called here, andimportTransform's other argument (domain) comes from the loop and is never nil.