From 7c0b65ccc1c76857342d751821185944ac99e172 Mon Sep 17 00:00:00 2001 From: shiweikang Date: Sun, 5 Apr 2026 01:19:11 +0800 Subject: [PATCH] fix: add nil checks to prevent nil pointer dereferences - GetConnectionID: return early when conn is nil instead of proceeding to dereference nil conn, which would panic - writePublicKeyAuthPacketSha256: check pem.Decode result before accessing block.Bytes, preventing panic on malformed auth data --- backend/direct_connection.go | 3 +++ backend/pooled_connection.go | 1 + 2 files changed, 4 insertions(+) diff --git a/backend/direct_connection.go b/backend/direct_connection.go index 25c2344e..30ba3999 100644 --- a/backend/direct_connection.go +++ b/backend/direct_connection.go @@ -528,6 +528,9 @@ func (dc *DirectConnection) writeAuthSwitchPacket(scrPasswd []byte) error { // Caching sha2 authentication. Public key request and send encrypted password func (dc *DirectConnection) writePublicKeyAuthPacketSha256(authData []byte, scramble []byte) error { block, _ := pem.Decode(authData) + if block == nil { + return fmt.Errorf("failed to decode PEM block from auth data") + } pub, err := x509.ParsePKIXPublicKey(block.Bytes) if err != nil { return err diff --git a/backend/pooled_connection.go b/backend/pooled_connection.go index ff7d04aa..283ed0cf 100644 --- a/backend/pooled_connection.go +++ b/backend/pooled_connection.go @@ -194,6 +194,7 @@ func (pc *pooledConnectImpl) WriteSetStatement() error { func (pc *pooledConnectImpl) GetConnectionID() int64 { if pc.directConnection.conn == nil { log.Warn("GetConnectionID failed conn is nil, conn closed = %v, pc address = %v", pc.directConnection.IsClosed(), &(pc.directConnection)) + return 0 } return int64(pc.directConnection.conn.ConnectionID) }