From 50e64f7e7810be6cb204fafa97c2fc67cc832084 Mon Sep 17 00:00:00 2001 From: Sebastien Tardif Date: Mon, 8 Jun 2026 18:45:53 -0700 Subject: [PATCH] fix: prevent nil pointer panic in webhook sendLog Add missing return statements after error checks in sendLog. When json.Marshal or http.NewRequest fails, the error is logged but execution continues. If http.NewRequest returns a nil *Request, the subsequent req.Header.Set call panics with a nil pointer dereference. This bug was introduced in PR #129 (2023-07-14) and has been present for nearly 3 years. Signed-off-by: Sebastien Tardif --- s3log/webhook.go | 2 ++ s3log/webhook_test.go | 24 ++++++++++++++++++++++++ 2 files changed, 26 insertions(+) create mode 100644 s3log/webhook_test.go diff --git a/s3log/webhook.go b/s3log/webhook.go index c5f6d45a..3a1c16c0 100644 --- a/s3log/webhook.go +++ b/s3log/webhook.go @@ -131,11 +131,13 @@ func (wl *WebhookLogger) sendLog(lf LogFields) { jsonLog, err := json.Marshal(lf) if err != nil { fmt.Fprintf(os.Stderr, "failed to parse the log data: %v\n", err.Error()) + return } req, err := http.NewRequest(http.MethodPost, wl.url, bytes.NewReader(jsonLog)) if err != nil { fmt.Fprintln(os.Stderr, err) + return } req.Header.Set("Content-Type", "application/json; charset=utf-8") diff --git a/s3log/webhook_test.go b/s3log/webhook_test.go new file mode 100644 index 00000000..599b17c7 --- /dev/null +++ b/s3log/webhook_test.go @@ -0,0 +1,24 @@ +// Copyright 2023 Versity Software +// This file is licensed under the Apache License, Version 2.0 +// (the "License"); you may not use this file except in compliance +// with the License. You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, +// software distributed under the License is distributed on an +// "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +// KIND, either express or implied. See the License for the +// specific language governing permissions and limitations +// under the License. + +package s3log + +import "testing" + +func TestSendLog_InvalidURL_NoPanic(t *testing.T) { + wl := &WebhookLogger{url: "://invalid"} + // sendLog must not panic when http.NewRequest fails due to + // an invalid URL. Before the fix, the nil req was dereferenced. + wl.sendLog(LogFields{}) +}