Aias00 opened a new issue, #6724:
URL: https://github.com/apache/shenyu/issues/6724

   - Severity: Medium
   - Location:
   
`shenyu-plugin/shenyu-plugin-response/src/main/java/org/apache/shenyu/plugin/response/strategy/WebClientMessageWriter.java:84`
 + `:124-126`; 
`shenyu-plugin/shenyu-plugin-response/src/main/java/org/apache/shenyu/plugin/response/strategy/NettyClientMessageWriter.java:81`
 + `:97-99`
   - 
   Description:
   Both writers, on `response.writeWith(body)` error, call 
`releaseIfNotConsumed(body, error)` whose body is 
`dataBufferDody.map(DataBufferUtils::release).then(Mono.error(ex))`. That 
operator **re-subscribes** to the same `body` `Flux<DataBuffer>` to 
drain/release remaining buffers. But both body sources are single-subscription: 
WebClient's `fluxResponseEntity.getBody()` and Netty's 
`connection.inbound().receive().retain()`. A second subscription errors or 
emits nothing, so the buffers already emitted-but-not-yet-released when the 
write failed are never reached by `DataBufferUtils::release`. They leak. On the 
Netty path the second-subscription `IllegalStateException` can replace the 
original error signal.
   - 
   Impact:
   Pooled direct-memory ByteBuf leak on the response error/cancel path (client 
abort during streamed response). Compounds PERF-27/28.
   - 
   Suggested fix:
   Track emitted buffers via `DataBufferUtils.track(...)` or 
release-on-complete/cancel inside the same single subscription 
(`body.doOnDiscard(DataBuffer.class, DataBufferUtils::release)` + `doFinally`), 
instead of re-subscribing to the single-use source.
   - 
   Confidence: Medium
   - Related existing: #6413 is the *request*-body single-use retry bug 
(different stream and trigger); this is the *response*-body release-on-error 
re-subscription.
   
   ---
   
   ## D. Plugin lifecycle / SPI (8 findings)
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to