Aias00 opened a new issue, #6625:
URL: https://github.com/apache/shenyu/issues/6625

   - severity: High
   - files: 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/ScalePolicyServiceImpl.java:80-88`
   - description: `update(...)` performs 
`scalePolicyMapper.updateByPrimaryKeySelective`, then 
`scalePolicyCache.updatePolicy(...)`, then `scaleService.executeScaling()` with 
no `@Transactional`. Each mapper call auto-commits immediately. If 
`executeScaling()` throws after the DB write and cache update have already 
taken effect, the policy is persisted and cached as the new value but the 
scaling action was not applied → persistent state drift.
   - impact: DB/cache and actual scaling actions can diverge on failure with no 
rollback; a failed scaling leaves the system in a state where the stored policy 
says "scaled" but the runtime did not scale (or vice versa).
   - suggested_fix: Annotate `update` with `@Transactional(rollbackFor = 
Exception.class)`; move `scaleService.executeScaling()` to an after-commit 
phase or call it after the transactional method returns so the side effect only 
fires on committed state.
   - confidence: High
   - related_existing: none. N12 is about cache payload shape; this is a 
transaction-boundary/side-effect-ordering defect in the same method but a 
distinct concern.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to