mirror of
https://github.com/coredns/coredns.git
synced 2026-08-20 23:08:28 -04:00
plugin/kubernetes: copy Labels in Pod.DeepCopyObject (#8415)
* plugin/kubernetes: copy Labels in Pod.DeepCopyObject Pod.DeepCopyObject built the copy field by field and left Labels out, so every copy came back unlabelled. Every other object in this package copies all of its fields; Pod was the only one missing any. Labels feeds the kubernetes/client-label/<key> metadata, so anything that reached a pod through a deep copy would see no labels at all rather than an error. Nothing does today - DefaultProcessor stores the converted object straight into the indexer without copying it, which is why this has not surfaced - so this is a latent bug rather than a live one. Clone the map instead of assigning it, so the copy does not alias the original. maps.Clone returns nil for a nil map, so an unlabelled pod stays unlabelled and a round trip does not turn a nil map into an empty one. The test covers every runtime.Object in the package rather than just Pod, and refuses to pass if a fixture leaves a field at its zero value. Adding a field to any of these types therefore fails the test until the fixture sets it, which is what makes the round-trip assertion cover the new field too. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Manuel Rüger <manuel@rueg.eu> * plugin/kubernetes/object: deep copy the Service and ServiceImport ports The deepcopy tests claimed a package-wide guarantee that a copy shares nothing with its original, but only checked it for Pod and a hand-written Endpoints value. Both api.ServicePort and mcs.ServicePort hold an AppProtocol *string, so the elementwise copy(s1.Ports, s.Ports) in Service.DeepCopyObject and ServiceImport.DeepCopyObject left the copy pointing at the original's string. Mutating it through either side was visible from the other, and the tests still passed. Copy the ports with the generated DeepCopyInto so the copy owns everything it can reach, and make the guarantee real: TestDeepCopyObjectIsDeep now runs over every case in deepCopyCases, mutates every value reachable through a pointer, slice, or map, and requires the copy to still equal a pristine fixture. A type that gains a reference-bearing field is covered as soon as assertAllFieldsSet forces the fixture to populate it, rather than needing a new hand-written case. Failure messages render as JSON, because %+v prints an aliased pointer field as an address and hides the value that actually differs. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Manuel Rüger <manuel@rueg.eu> --------- Signed-off-by: Manuel Rüger <manuel@rueg.eu> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -3,6 +3,7 @@ package object
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"maps"
|
||||
|
||||
api "k8s.io/api/core/v1"
|
||||
meta "k8s.io/apimachinery/pkg/apis/meta/v1"
|
||||
@@ -57,6 +58,8 @@ func (p *Pod) DeepCopyObject() runtime.Object {
|
||||
PodIP: p.PodIP,
|
||||
Namespace: p.Namespace,
|
||||
Name: p.Name,
|
||||
// maps.Clone returns nil for a nil map, so an unlabelled pod stays unlabelled.
|
||||
Labels: maps.Clone(p.Labels),
|
||||
}
|
||||
return p1
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user