Aias00 opened a new issue, #6684:
URL: https://github.com/apache/shenyu/issues/6684

   - severity: Medium-High
   - files: 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/DiscoveryServiceImpl.java:121-125,185-188`;
 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/discovery/DefaultDiscoveryProcessor.java:82-84`;
 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/listener/DataChangedEventDispatcher.java`
   - description: `registerDiscoveryConfig` is 
`@Transactional(rollbackFor=Exception.class)`. Inside it `bindingDiscovery` 
inserts `discovery`/`discoveryHandler`/`discoveryRel` rows and then calls 
`discoveryProcessor.createProxySelector(...)`, which publishes 
`DataChangedEvent(PROXY_SELECTOR, CREATE)`. `DataChangedEventDispatcher` 
implements `ApplicationListener<DataChangedEvent>` (a synchronous Spring 
listener, NOT `@TransactionalEventListener(AFTER_COMMIT)`), so the gateway-sync 
listeners push the new proxySelector to the gateway BEFORE the transaction 
commits. The same method also calls `createDiscovery` (network registry init + 
watch registration) as an un-rollbackable side effect inside the tx. If the tx 
rolls back, the gateway has received a CREATE for a proxySelector whose DB rows 
were rolled back, and the registry connection/watch is leaked.
   - impact: Ghost proxySelector in gateway / divergent admin-vs-gateway state 
on rollback of discovery binding; leaked registry watch resources.
   - suggested_fix: Move the `createDiscovery`/`createProxySelector` (and the 
event publish) to an after-commit phase 
(`@TransactionalEventListener(phase=AFTER_COMMIT)`).
   - confidence: Medium-High
   - related_existing: none. #6479 is about delete stale cache; this is a 
CREATE publish-before-commit (transaction visibility) defect.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to