Aias00 opened a new issue, #6686:
URL: https://github.com/apache/shenyu/issues/6686

   - severity: Medium
   - files: 
`shenyu-admin/src/main/java/org/apache/shenyu/admin/discovery/DiscoveryDataChangedEventSyncListener.java:71,86,166-173`
   - description: `discoverySyncDataList` is a plain `new ArrayList<>()` (line 
71). It is mutated by `addListener` (lines 167-173, using `stream().noneMatch` 
+ `add`) from the request/startup thread, and iterated by `onChange` 
(`discoverySyncDataList.forEach`, line 86) on the registry watch-callback 
thread. These are different threads operating on an unsynchronized `ArrayList`.
   - impact: Intermittent `ConcurrentModificationException` in the watch thread 
(kills that watch notification), or a selector's upstream changes silently 
dropped because its context wasn't yet visible to the iterating `onChange`.
   - suggested_fix: Use `CopyOnWriteArrayList` for `discoverySyncDataList`, or 
synchronize `addListener`/`onChange` on a shared lock.
   - confidence: Medium-High
   - related_existing: none. PERF-11 flags the second HashMap in 
`AbstractDiscoveryProcessor`; this is a different field in a different class.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to