Aias00 opened a new issue, #6831:
URL: https://github.com/apache/shenyu/issues/6831

   ## Description
   `AbstractNodeDataChangedListener.onCommonMultiChanged`'s switch merges 
`REFRESH`, `MYSELF` and `default` into one branch that only publishes each 
changed entry and calls `putChangedMapToList`, which reads the old per-plugin 
id list and `addAll`s new ids not already present — it **never removes** ids no 
longer in the changed set and **never `delConfig`s** stale per-entry nodes. So 
a `REFRESH` that is supposed to *replace* a plugin's full selector/rule set 
instead *unions* it: stale selector/rule ids (and their config nodes) deleted 
elsewhere accumulate forever in the per-plugin LIST node and in the config 
center.
   
   `syncAllByNamespaceId(REFRESH)` (NamespacePluginController:210, 
ConfigsExportImportController:141) groups selectors/rules across ALL plugins of 
a namespace into one REFRESH event, so every namespace resync after a deletion 
leaves the deleted selectors/rules live in nacos/apollo/polaris.
   
   ## Location
   - 
`shenyu-admin-listener/shenyu-admin-listener-api/src/main/java/org/apache/shenyu/admin/listener/AbstractNodeDataChangedListener.java:228-234`
 (switch), `242-255` (`putChangedMapToList`); entry points 
`onSelectorChanged:172-180`, `onRuleChanged:183-194`, 
`onProxySelectorChanged:272-280`, `onDiscoveryUpstreamChanged:283-291`
   
   ## Impact
   On nacos/apollo/polaris backends, after any namespace resync or config 
import that follows selector/rule deletions, stale selector and rule entries 
persist in the config center and in the per-plugin id list. Gateways re-reading 
the list fetch stale configs and may route to deleted selectors or apply 
deleted rules — silent routing drift.
   
   ## Suggested fix
   Add a distinct `REFRESH` branch in `onCommonMultiChanged` that, before 
publishing, computes the old per-plugin id list, `removeAll`s the new ids, and 
`delConfig`s the remainder (mirroring `delChangedMapToList`), then publishes 
the new list — replace-then-add rather than add-only.
   
   ## Related existing
   Distinct from SYNC-5/SYNC-6/SYNC-7 (#6780/#6781/#6782, gateway-side 
`shenyu-sync-data-center` discovery/proxySelector refresh no-clear). Those are 
gateway-side consumers; this is the admin-side publisher (nacos/apollo/polaris) 
— different base class and root cause (REFRESH merged into additive default vs 
missing refresh()-on-empty).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to