Aias00 opened a new issue, #6722:
URL: https://github.com/apache/shenyu/issues/6722

   - Severity: Medium
   - Location:
   
`shenyu-plugin/shenyu-plugin-base/src/main/java/org/apache/shenyu/plugin/base/support/ResponseDecorator.java:55`
 (first release) and `:58` (second release in `doFinally`)
   - 
   Description:
   `writeWith` does `DataBufferUtils.join(body)` into a single buffer, copies 
bytes via `dataBuffer.read(bytes)`, then calls 
`DataBufferUtils.release(dataBuffer)` at line 55 (refcount → 0, buffer returned 
to pool). The returned Mono then attaches `.doFinally(signalType -> 
DataBufferUtils.release(dataBuffer))` at line 58, which fires on every terminal 
signal and calls `release` again on the same buffer. On the default Netty 
pooled-direct-buffer runtime, the second release either throws 
`IllegalReferenceCountException` or releases a buffer the pool has already 
handed to another writer (refcount bumped back to 1 on reuse → release drops to 
0 while in use), corrupting an unrelated response. Triggered on every response 
through `ResponseDecorator` (wired in `ServerWebExchangeUtils.java:76`).
   - 
   Impact:
   Post-write errors / connection resets / pooled-buffer corruption under load. 
On heap buffer factories the second release is a harmless no-op (why it 
survived).
   - 
   Suggested fix:
   Drop the eager `release` at line 55 and keep only the `doFinally` release; 
or vice-versa.
   - 
   Confidence: High
   - Related existing: none — #6444 is a different class.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to