Skip to content

admission: add missing return after http.Error on marshal failure#8582

Merged
simonpasquier merged 1 commit into
prometheus-operator:mainfrom
SebTardif:fix-admission-missing-return
May 21, 2026
Merged

admission: add missing return after http.Error on marshal failure#8582
simonpasquier merged 1 commit into
prometheus-operator:mainfrom
SebTardif:fix-admission-missing-return

Conversation

@SebTardif

Copy link
Copy Markdown
Contributor

What this PR does

In pkg/admission/admission.go, function serveAdmission: when json.Marshal(responseAdmissionReview) fails, http.Error is called but execution falls through to w.Write(respBytes) with nil bytes on an already-committed response. This triggers Go's "http: superfluous response.WriteHeader call" warning and writes corrupted output.

The two earlier error handlers (empty body, wrong content-type) both correctly return. This was the only path missing it.

Fix:

  • Added return after the http.Error call on the marshal error path
  • Moved the debug log after the error check so it only runs when respBytes is valid

AI Disclosure

Developed with AI assistance (Grok by xAI) in a human-in-the-loop workflow. All code reviewed and verified by the human author.

Signed-off-by: Sebastien Tardif [email protected]

When json.Marshal fails in serveAdmission, the handler calls http.Error
but does not return, causing execution to fall through to w.Write with
nil bytes on an already-committed response.

Add return after the http.Error call and move the debug log after the
error check so it doesn't log nil response bytes on failure.

Signed-off-by: Sebastien Tardif <[email protected]>
@SebTardif
SebTardif requested a review from a team as a code owner May 21, 2026 14:43

@simonpasquier simonpasquier left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks!

@simonpasquier
simonpasquier enabled auto-merge May 21, 2026 14:56
@simonpasquier
simonpasquier merged commit 75553fe into prometheus-operator:main May 21, 2026
21 of 22 checks passed
sdwilsh pushed a commit to sdwilsh/ansible-playbooks that referenced this pull request Jul 22, 2026
…r to v0.92.1 (#1765)

##### [\`v0.92.1\`](https://github.com/prometheus-operator/prometheus-operator/releases/tag/v0.92.1)

- \[BUGFIX] Fix "namespace not found" errors when the operator watches monitoring and workload resources in different resources. [#8658](prometheus-operator/prometheus-operator#8658)

---
##### [\`v0.92.0\`](https://github.com/prometheus-operator/prometheus-operator/releases/tag/v0.92.0)

> \[!NOTE]
> The `PrometheusTopologySharding` and `PrometheusShardRetentionPolicy` feature gates have been promoted to **Beta** in this release and are now enabled by default. See the [sharding documentation](https://prometheus-operator.dev/docs/platform/sharding/) for details.

- \[CHANGE] Add URL validation for the `tokenUrl` field in OAuth2 configuration across all CRDs. [#8579](prometheus-operator/prometheus-operator#8579)
- \[CHANGE] Add URL validation for the `url` field in `RemoteReadSpec` in `Prometheus` CRD. [#8596](prometheus-operator/prometheus-operator#8596)
- \[FEATURE] Migrate retention options from CLI flags to the config file for `Prometheus` CRD (Prometheus >= v3 uses the config file; older versions continue to use CLI flags). [#8547](prometheus-operator/prometheus-operator#8547)
- \[FEATURE] Add `staleSeriesCompactionThreshold` field to `TSDBSpec` in `Prometheus` and `PrometheusAgent` CRDs. [#8563](prometheus-operator/prometheus-operator#8563)
- \[FEATURE] Add `labelNameUnderscoreSanitization` and `labelNamePreserveMultipleUnderscores` fields to `OTLPConfig` in `Prometheus` and `PrometheusAgent` CRDs. [#8562](prometheus-operator/prometheus-operator#8562)
- \[FEATURE] Add `payload` field to Webhook receiver in `AlertmanagerConfig` CRD. [#8507](prometheus-operator/prometheus-operator#8507)
- \[ENHANCEMENT] Use pod topology labels for zone sharding on Kubernetes >= 1.35 when the `PrometheusTopologySharding` feature gate is enabled (removes the need for `attachMetadata.node=true`). [#8564](prometheus-operator/prometheus-operator#8564)
- \[ENHANCEMENT] Add validation for the Slack `update_message` field in Alertmanager configuration Secret. [#8556](prometheus-operator/prometheus-operator#8556)
- \[BUGFIX] Validate target labels in `Probe` static configuration to prevent invalid Prometheus scrape configs. [#7901](prometheus-operator/prometheus-operator#7901)
- \[BUGFIX] Fix goroutine leak and data race in `pollBasedListerWatcher`. [#8593](prometheus-operator/prometheus-operator#8593)
- \[BUGFIX] Validate `ProxyConfig` in OAuth2 configuration. [#8610](prometheus-operator/prometheus-operator#8610)
- \[BUGFIX] Fix SMTP smarthost format error handling in Alertmanager configuration. [#8586](prometheus-operator/prometheus-operator#8586)
- \[BUGFIX] Fix missing `return` in admission webhook after marshal failure. [#8582](prometheus-operator/prometheus-operator#8582)
- \[BUGFIX] Fix `FindOwner` to return `nil` on `meta.Accessor` error. [#8585](prometheus-operator/prometheus-operator#8585)
- \[BUGFIX] Fix dropped gzip `Close` errors in `GzipConfig` and `GunzipConfig`. [#8573](prometheus-operator/prometheus-operator#8573)
- \[BUGFIX] Fix panic on malformed key=value flag input (e.g. `--labels "key"`). [#8560](prometheus-operator/prometheus-operator#8560)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants