diff --git a/pkg/common/common.go b/pkg/common/common.go index de37ad86..45de1f19 100644 --- a/pkg/common/common.go +++ b/pkg/common/common.go @@ -276,7 +276,11 @@ func ShouldReload(config Config, resourceType string, annotations Map, podAnnota values := strings.Split(annotationValue, ",") for _, value := range values { value = strings.TrimSpace(value) - re := regexp.MustCompile("^" + value + "$") + re, err := regexp.Compile("^" + value + "$") + if err != nil { + logrus.Errorf("Invalid regex %q in reload annotation %q on resource '%s' of type '%s'; skipping this pattern: %v", value, config.Annotation, config.ResourceName, config.Type, err) + continue + } if re.Match([]byte(config.ResourceName)) { return ReloadCheckResult{ ShouldReload: true, diff --git a/pkg/common/common_test.go b/pkg/common/common_test.go index 532d3adf..0bbdab54 100644 --- a/pkg/common/common_test.go +++ b/pkg/common/common_test.go @@ -222,3 +222,27 @@ func TestShouldReload_IssueRBACPermissionFixed(t *testing.T) { }) } } + +// A malformed regex in a named reload annotation must not panic the operator. +// Regression test: previously regexp.MustCompile("^"+value+"$") panicked on an +// invalid pattern, crashing Reloader cluster-wide (no recover on the worker). +func TestShouldReload_InvalidRegexAnnotation_DoesNotPanic(t *testing.T) { + config := Config{ + ResourceName: "app-config", + Annotation: "secret.reloader.stakater.com/reload", + } + annotations := Map{ + // unbalanced bracket => invalid regex + "secret.reloader.stakater.com/reload": "app-config[", + } + opts := &ReloaderOptions{ + ReloaderAutoAnnotation: "reloader.stakater.com/auto", + } + + // Before the fix this panicked inside ShouldReload. + result := ShouldReload(config, "Deployment", annotations, Map{}, opts) + + if result.ShouldReload { + t.Errorf("Expected ShouldReload=false for an invalid regex pattern, got=%v", result.ShouldReload) + } +}