-
Notifications
You must be signed in to change notification settings - Fork 41.1k
Fix null pointer dereference in CSI volume handling #133403
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
Add defensive nil checks for spec.PersistentVolume before accessing its fields in CSI attacher, mounter, and block volume handlers. The issue occurs when volume specs are created from Volume sources (spec.Volume.CSI) rather than PersistentVolume sources, which can result in spec.PersistentVolume being nil while still having valid CSI volume configuration. This change makes the code consistent with existing defensive patterns already present in the codebase, such as the MountOptions handling in csi_attacher.go:320. Fixes kubernetes#133177
Please note that we're already in Test Freeze for the Fast forwards are scheduled to happen every 6 hours, whereas the most recent run was: Wed Aug 6 15:00:21 UTC 2025. |
Keywords which can automatically close issues and at(@) or hashtag(#) mentions are not allowed in commit messages. The list of commits with invalid commit messages:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
The committers listed above are authorized under a signed CLA. |
Welcome @amyanger! |
This issue is currently awaiting triage. If a SIG or subproject determines this is a relevant issue, they will accept it by applying the The Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Hi @amyanger. Thanks for your PR. I'm waiting for a kubernetes member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: amyanger The full list of commands accepted by this bot can be found here.
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
What type of PR is this?
/kind bug
What this PR does / why we need it:
This PR fixes a potential null pointer dereference in CSI (Container Storage Interface) volume handling code identified by static analysis.
The issue occurs when volume specs are created from Volume sources (
spec.Volume.CSI
) rather than PersistentVolume sources (spec.PersistentVolume.Spec.CSI
), which can result inspec.PersistentVolume
being nil while still having valid CSI volume configuration.Which issue(s) this PR fixes:
Fixes #133177
Special notes for your reviewer:
The fix adds defensive nil checks for
spec.PersistentVolume
before accessing its fields, making the code consistent with existing defensive patterns already present in the codebase (such as the MountOptions handling incsi_attacher.go:320
).Changes made:
pkg/volume/csi/csi_attacher.go
: Added nil check before accessing AccessModespkg/volume/csi/csi_mounter.go
: Added nil checks for both AccessModes and MountOptionspkg/volume/csi/csi_block.go
: Added nil checks for AccessModes in both SetUpDevice and MapPodDevice methodsDoes this PR introduce a user-facing change?
Additional documentation e.g., KEPs (Kubernetes Enhancement Proposals), usage docs, etc.:
N/A