Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-70982

Creating certificate credentials without uploading a certificate file causes unwanted behavior

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Minor Minor
    • credentials-plugin
    • None
    • 2.396

      When creating a folder-level certificate credential, if you do not upload a certificate and try to create the credential anyway, a NullPointerException is thrown:

      Apr  3 17:00:05 sv1702055 java: 2023-04-03 15:00:05.370+0000 [id=3631477]#011WARNING#011o.e.j.s.h.ContextHandler$Context#log: Error while serving https://jenkins.example.com/job/example-job/credentials/store/folder/domain/_/createCredentials
      Apr  3 17:00:05 sv1702055 java: java.lang.NullPointerException
      Apr  3 17:00:05 sv1702055 java: at java.base/java.util.Objects.requireNonNull(Objects.java:221)
      Apr  3 17:00:05 sv1702055 java: at com.cloudbees.plugins.credentials.impl.CertificateCredentialsImpl.<init>(CertificateCredentialsImpl.java:124)
      Apr  3 17:00:05 sv1702055 java: at java.base/jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)
      Apr  3 17:00:05 sv1702055 java: at java.base/jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62)
      Apr  3 17:00:05 sv1702055 java: at java.base/jdk.internal.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45)
      Apr  3 17:00:05 sv1702055 java: at java.base/java.lang.reflect.Constructor.newInstance(Constructor.java:490)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.RequestImpl.invokeConstructor(RequestImpl.java:602)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.RequestImpl.instantiate(RequestImpl.java:881)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.RequestImpl$TypePair.convertJSON(RequestImpl.java:766)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.RequestImpl.bindJSON(RequestImpl.java:549)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.RequestImpl.bindJSON(RequestImpl.java:544)
      Apr  3 17:00:05 sv1702055 java: at com.cloudbees.plugins.credentials.CredentialsStoreAction$DomainWrapper.doCreateCredentials(CredentialsStoreAction.java:815)
      Apr  3 17:00:05 sv1702055 java: at java.base/java.lang.invoke.MethodHandle.invokeWithArguments(MethodHandle.java:710)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Function$MethodFunction.invoke(Function.java:397)
      Apr  3 17:00:05 sv1702055 java: Caused: java.lang.reflect.InvocationTargetException
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Function$MethodFunction.invoke(Function.java:401)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Function$InstanceFunction.invoke(Function.java:409)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.interceptor.RequirePOST$Processor.invoke(RequirePOST.java:78)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.PreInvokeInterceptedFunction.invoke(PreInvokeInterceptedFunction.java:26)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Function.bindAndInvoke(Function.java:207)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Function.bindAndInvokeAndServeResponse(Function.java:140)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.MetaClass$11.doDispatch(MetaClass.java:558)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.NameBasedDispatcher.dispatch(NameBasedDispatcher.java:59)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.tryInvoke(Stapler.java:770)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.invoke(Stapler.java:900)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.MetaClass$4.doDispatch(MetaClass.java:289)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.NameBasedDispatcher.dispatch(NameBasedDispatcher.java:59)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.tryInvoke(Stapler.java:770)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.invoke(Stapler.java:900)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.MetaClass$4.doDispatch(MetaClass.java:289)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.NameBasedDispatcher.dispatch(NameBasedDispatcher.java:59)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.tryInvoke(Stapler.java:770)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.invoke(Stapler.java:900)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.MetaClass$9.dispatch(MetaClass.java:475)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.tryInvoke(Stapler.java:770)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.invoke(Stapler.java:900)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.MetaClass$4.doDispatch(MetaClass.java:289)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.NameBasedDispatcher.dispatch(NameBasedDispatcher.java:59)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.tryInvoke(Stapler.java:770)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.invoke(Stapler.java:900)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.MetaClass$4.doDispatch(MetaClass.java:289)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.NameBasedDispatcher.dispatch(NameBasedDispatcher.java:59)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.tryInvoke(Stapler.java:770)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.invoke(Stapler.java:900)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.MetaClass$4.doDispatch(MetaClass.java:289)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.NameBasedDispatcher.dispatch(NameBasedDispatcher.java:59)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.tryInvoke(Stapler.java:770)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.invoke(Stapler.java:900)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.invoke(Stapler.java:698)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.Stapler.service(Stapler.java:248)
      Apr  3 17:00:05 sv1702055 java: at javax.servlet.http.HttpServlet.service(HttpServlet.java:590)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.ServletHolder.handle(ServletHolder.java:764)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.ServletHandler$ChainEnd.doFilter(ServletHandler.java:1665)
      Apr  3 17:00:05 sv1702055 java: at hudson.util.PluginServletFilter$1.doFilter(PluginServletFilter.java:157)
      Apr  3 17:00:05 sv1702055 java: at org.jenkinsci.plugins.ssegateway.Endpoint$SSEListenChannelFilter.doFilter(Endpoint.java:248)
      Apr  3 17:00:05 sv1702055 java: at hudson.util.PluginServletFilter$1.doFilter(PluginServletFilter.java:154)
      Apr  3 17:00:05 sv1702055 java: at jenkins.security.ResourceDomainFilter.doFilter(ResourceDomainFilter.java:81)
      Apr  3 17:00:05 sv1702055 java: at hudson.util.PluginServletFilter$1.doFilter(PluginServletFilter.java:154)
      Apr  3 17:00:05 sv1702055 java: at jenkins.telemetry.impl.UserLanguages$AcceptLanguageFilter.doFilter(UserLanguages.java:129)
      Apr  3 17:00:05 sv1702055 java: at hudson.util.PluginServletFilter$1.doFilter(PluginServletFilter.java:154)
      Apr  3 17:00:05 sv1702055 java: at hudson.plugins.audit_trail.AuditTrailFilter.doFilter(AuditTrailFilter.java:112)
      Apr  3 17:00:05 sv1702055 java: at hudson.util.PluginServletFilter$1.doFilter(PluginServletFilter.java:154)
      Apr  3 17:00:05 sv1702055 java: at hudson.plugins.locale.LocaleFilter.doFilter(LocaleFilter.java:42)
      Apr  3 17:00:05 sv1702055 java: at hudson.util.PluginServletFilter$1.doFilter(PluginServletFilter.java:154)
      Apr  3 17:00:05 sv1702055 java: at com.atlassian.bitbucket.jenkins.internal.applink.oauth.serviceprovider.auth.OAuth1aRequestFilter.doFilter(OAuth1aRequestFilter.java:91)
      Apr  3 17:00:05 sv1702055 java: at hudson.util.PluginServletFilter$1.doFilter(PluginServletFilter.java:154)
      Apr  3 17:00:05 sv1702055 java: at io.jenkins.blueocean.ResourceCacheControl.doFilter(ResourceCacheControl.java:134)
      Apr  3 17:00:05 sv1702055 java: at hudson.util.PluginServletFilter$1.doFilter(PluginServletFilter.java:154)
      Apr  3 17:00:05 sv1702055 java: at io.jenkins.blueocean.auth.jwt.impl.JwtAuthenticationFilter.doFilter(JwtAuthenticationFilter.java:60)
      Apr  3 17:00:05 sv1702055 java: at hudson.util.PluginServletFilter$1.doFilter(PluginServletFilter.java:154)
      Apr  3 17:00:05 sv1702055 java: at hudson.plugins.greenballs.GreenBallFilter.doFilter(GreenBallFilter.java:64)
      Apr  3 17:00:05 sv1702055 java: at hudson.util.PluginServletFilter$1.doFilter(PluginServletFilter.java:154)
      Apr  3 17:00:05 sv1702055 java: at jenkins.metrics.impl.MetricsFilter.doFilter(MetricsFilter.java:125)
      Apr  3 17:00:05 sv1702055 java: at hudson.util.PluginServletFilter$1.doFilter(PluginServletFilter.java:154)
      Apr  3 17:00:05 sv1702055 java: at hudson.util.PluginServletFilter.doFilter(PluginServletFilter.java:160)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.FilterHolder.doFilter(FilterHolder.java:202)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.ServletHandler$Chain.doFilter(ServletHandler.java:1635)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.csrf.CrumbFilter.doFilter(CrumbFilter.java:154)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.FilterHolder.doFilter(FilterHolder.java:202)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.ServletHandler$Chain.doFilter(ServletHandler.java:1635)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.ChainedServletFilter$1.doFilter(ChainedServletFilter.java:94)
      Apr  3 17:00:05 sv1702055 java: at jenkins.security.AcegiSecurityExceptionFilter.doFilter(AcegiSecurityExceptionFilter.java:52)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.ChainedServletFilter$1.doFilter(ChainedServletFilter.java:99)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.UnwrapSecurityExceptionFilter.doFilter(UnwrapSecurityExceptionFilter.java:54)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.ChainedServletFilter$1.doFilter(ChainedServletFilter.java:99)
      Apr  3 17:00:05 sv1702055 java: at org.springframework.security.web.access.ExceptionTranslationFilter.doFilter(ExceptionTranslationFilter.java:126)
      Apr  3 17:00:05 sv1702055 java: at org.springframework.security.web.access.ExceptionTranslationFilter.doFilter(ExceptionTranslationFilter.java:120)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.ChainedServletFilter$1.doFilter(ChainedServletFilter.java:99)
      Apr  3 17:00:05 sv1702055 java: at org.springframework.security.web.authentication.AnonymousAuthenticationFilter.doFilter(AnonymousAuthenticationFilter.java:100)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.ChainedServletFilter$1.doFilter(ChainedServletFilter.java:99)
      Apr  3 17:00:05 sv1702055 java: at org.springframework.security.web.authentication.rememberme.RememberMeAuthenticationFilter.doFilter(RememberMeAuthenticationFilter.java:110)
      Apr  3 17:00:05 sv1702055 java: at org.springframework.security.web.authentication.rememberme.RememberMeAuthenticationFilter.doFilter(RememberMeAuthenticationFilter.java:101)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.ChainedServletFilter$1.doFilter(ChainedServletFilter.java:99)
      Apr  3 17:00:05 sv1702055 java: at org.springframework.security.web.authentication.AbstractAuthenticationProcessingFilter.doFilter(AbstractAuthenticationProcessingFilter.java:227)
      Apr  3 17:00:05 sv1702055 java: at org.springframework.security.web.authentication.AbstractAuthenticationProcessingFilter.doFilter(AbstractAuthenticationProcessingFilter.java:221)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.ChainedServletFilter$1.doFilter(ChainedServletFilter.java:99)
      Apr  3 17:00:05 sv1702055 java: at jenkins.security.BasicHeaderProcessor.doFilter(BasicHeaderProcessor.java:97)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.ChainedServletFilter$1.doFilter(ChainedServletFilter.java:99)
      Apr  3 17:00:05 sv1702055 java: at org.springframework.security.web.context.SecurityContextPersistenceFilter.doFilter(SecurityContextPersistenceFilter.java:117)
      Apr  3 17:00:05 sv1702055 java: at org.springframework.security.web.context.SecurityContextPersistenceFilter.doFilter(SecurityContextPersistenceFilter.java:87)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.HttpSessionContextIntegrationFilter2.doFilter(HttpSessionContextIntegrationFilter2.java:63)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.ChainedServletFilter$1.doFilter(ChainedServletFilter.java:99)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.ChainedServletFilter.doFilter(ChainedServletFilter.java:111)
      Apr  3 17:00:05 sv1702055 java: at hudson.security.HudsonFilter.doFilter(HudsonFilter.java:172)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.FilterHolder.doFilter(FilterHolder.java:202)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.ServletHandler$Chain.doFilter(ServletHandler.java:1635)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.compression.CompressionFilter.doFilter(CompressionFilter.java:53)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.FilterHolder.doFilter(FilterHolder.java:202)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.ServletHandler$Chain.doFilter(ServletHandler.java:1635)
      Apr  3 17:00:05 sv1702055 java: at hudson.util.CharacterEncodingFilter.doFilter(CharacterEncodingFilter.java:86)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.FilterHolder.doFilter(FilterHolder.java:202)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.ServletHandler$Chain.doFilter(ServletHandler.java:1635)
      Apr  3 17:00:05 sv1702055 java: at org.kohsuke.stapler.DiagnosticThreadNameFilter.doFilter(DiagnosticThreadNameFilter.java:30)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.FilterHolder.doFilter(FilterHolder.java:202)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.ServletHandler$Chain.doFilter(ServletHandler.java:1635)
      Apr  3 17:00:05 sv1702055 java: at jenkins.security.SuspiciousRequestFilter.doFilter(SuspiciousRequestFilter.java:38)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.FilterHolder.doFilter(FilterHolder.java:202)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.ServletHandler$Chain.doFilter(ServletHandler.java:1635)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.ServletHandler.doHandle(ServletHandler.java:527)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:131)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.security.SecurityHandler.handle(SecurityHandler.java:549)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.handler.HandlerWrapper.handle(HandlerWrapper.java:122)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.handler.ScopedHandler.nextHandle(ScopedHandler.java:223)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.session.SessionHandler.doHandle(SessionHandler.java:1570)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.handler.ScopedHandler.nextHandle(ScopedHandler.java:221)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.handler.ContextHandler.doHandle(ContextHandler.java:1383)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.handler.ScopedHandler.nextScope(ScopedHandler.java:176)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.servlet.ServletHandler.doScope(ServletHandler.java:484)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.session.SessionHandler.doScope(SessionHandler.java:1543)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.handler.ScopedHandler.nextScope(ScopedHandler.java:174)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.handler.ContextHandler.doScope(ContextHandler.java:1305)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:129)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.handler.HandlerWrapper.handle(HandlerWrapper.java:122)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.Server.handle(Server.java:563)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.HttpChannel.lambda$handle$0(HttpChannel.java:505)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.HttpChannel.dispatch(HttpChannel.java:762)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.HttpChannel.handle(HttpChannel.java:497)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.server.HttpConnection.onFillable(HttpConnection.java:282)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.io.AbstractConnection$ReadCallback.succeeded(AbstractConnection.java:314)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.io.FillInterest.fillable(FillInterest.java:100)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.io.SelectableChannelEndPoint$1.run(SelectableChannelEndPoint.java:53)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.util.thread.strategy.AdaptiveExecutionStrategy.runTask(AdaptiveExecutionStrategy.java:416)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.util.thread.strategy.AdaptiveExecutionStrategy.consumeTask(AdaptiveExecutionStrategy.java:385)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.util.thread.strategy.AdaptiveExecutionStrategy.tryProduce(AdaptiveExecutionStrategy.java:272)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.util.thread.strategy.AdaptiveExecutionStrategy.lambda$new$0(AdaptiveExecutionStrategy.java:140)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.util.thread.ReservedThreadExecutor$ReservedThread.run(ReservedThreadExecutor.java:411)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.util.thread.QueuedThreadPool.runJob(QueuedThreadPool.java:934)
      Apr  3 17:00:05 sv1702055 java: at org.eclipse.jetty.util.thread.QueuedThreadPool$Runner.run(QueuedThreadPool.java:1078)
      Apr  3 17:00:05 sv1702055 java: at java.base/java.lang.Thread.run(Thread.java:829)
      

      Consquently, the user can experience

      • being forced to log in again;
      • an empty list of folder credentials after clicking the folder in which Jenkins failed to create the certificate credential, and then clicking "Credentials" in the menu on the left;
      • a ghost credential entry called "index-0", which is visible only after clicking the store that Jenkins failed to create the certificate credential in (under "Stores scoped to <FOLDER_NAME>") and then clicking "Global credentials (unrestricted)" on the next page

      Deleting the ghost credential solves these symptoms.

            Unassigned Unassigned
            cdekkers Cas Dekkers
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: