Aias00 opened a new issue, #6779:
URL: https://github.com/apache/shenyu/issues/6779

   - Severity: Medium
   - Location:
   `HttpClientRegisterRepository.java:232-246` (`doUnregister`), called from 
`offline()` (`:131-133`) and the per-URI shutdown hook 
`ShenyuClientURIExecutorSubscriber:109`
   - 
   Description:
   `doUnregister` catches `Exception` per server, logs, and never throws — it 
lacks the `if (i == serverList.size()) throw new RuntimeException(e)` that 
`doRegister` (`:205-207`) and `doHeartbeat` (`:225-227`) have. `offline()` is 
not wrapped by `FailbackRegistryRepository.persist*`, so no failback retry is 
enqueued. This is the *only* offline mechanism (the per-URI shutdown hook also 
routes through `offline()`). If all admin servers are unreachable at shutdown, 
the offline is silently lost.
   - 
   Impact:
   Stale upstream entries after client shutdown when admin is temporarily 
unavailable; gateway may route traffic to dead instances during the 
health-check grace window.
   - 
   Suggested fix:
   Throw on last-server failure (mirroring `doRegister`) and/or route offline 
through a failback retry; alternatively document as best-effort.
   - 
   Confidence: Medium
   - Related existing: none — #6559/FUNC-E4 concerns `doRegister` 
partial-failure; #6487 concerns the heartbeat scheduler. `doUnregister` is a 
distinct method with no retry.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to