fix(tlsutil): avoid nil pointer dereference in ClientConfig

When opts.CertFile and opts.KeyFile are empty, cert remains nil.
Previously, ClientConfig unconditionally dereferenced cert when
constructing tls.Config, causing a runtime panic when only CaCertFile
or InsecureSkipVerify was configured.

This conditions the assignment of cfg.Certificates on cert != nil and
adds a unit test covering the scenario.

Fixes #32674

Signed-off-by: Cosmin Neculcea <cosminneculcea60@gmail.com>
pull/32679/head
Cosmin Neculcea 2 weeks ago
parent cddb9c4138
commit 64ce98d1c6

@ -53,6 +53,12 @@ func ClientConfig(opts Options) (cfg *tls.Config, err error) {
}
}
cfg = &tls.Config{InsecureSkipVerify: opts.InsecureSkipVerify, Certificates: []tls.Certificate{*cert}, RootCAs: pool}
cfg = &tls.Config{
InsecureSkipVerify: opts.InsecureSkipVerify,
RootCAs: pool,
}
if cert != nil {
cfg.Certificates = []tls.Certificate{*cert}
}
return cfg, nil
}

@ -112,3 +112,22 @@ func TestNewClientTLS(t *testing.T) {
t.Fatalf("mismatch tls RootCAs, expecting nil")
}
}
func TestClientConfigWithoutClientCert(t *testing.T) {
opts := Options{
InsecureSkipVerify: true,
}
cfg, err := ClientConfig(opts)
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
if cfg == nil {
t.Fatal("expected non-nil tls.Config")
}
if len(cfg.Certificates) != 0 {
t.Fatalf("expected empty Certificates slice, got %d", len(cfg.Certificates))
}
}

Loading…
Cancel
Save