Aias00 opened a new issue, #6874:
URL: https://github.com/apache/shenyu/issues/6874

   ## Description
   In the REFRESH/MYSELF case, stale-entry removal is guarded by 
`configDataNames.size() > changedList.size()` (old count must strictly exceed 
new count). The actual cleanup (`configDataNames.removeAll(changeNames); 
configDataNames.forEach(this::delConfig)`) is only reached when old size > new 
size. When a REFRESH replaces the set with equal or larger cardinality but 
different members (e.g. old=[A,B,C,D], new=[C,D,E,F], 4 vs 4), the guard is 
false, so stale entries A and B are never deleted from nacos/apollo/polaris — 
only C,D,E,F are published and the new list overwrites the LIST node. The 
per-entry config nodes for A and B persist orphaned. This path is reached by 
`syncAllByNamespaceId(REFRESH, ns)` from `NamespacePluginController:210` and 
`ConfigsExportImportController:141`, which publish PLUGIN/AUTH/META REFRESH 
events spanning a whole namespace.
   
   ## Location
   - 
`shenyu-admin-listener/shenyu-admin-listener-api/src/main/java/org/apache/shenyu/admin/listener/AbstractNodeDataChangedListener.java:129-140`
 (guard at :134)
   
   ## Impact
   After a namespace resync or config import on nacos/apollo/polaris backends, 
deleted plugin / app-auth / metadata config entries whose count doesn't 
net-decrease remain in the config center. For app-auth this is 
security-adjacent: a deleted app key's config node can linger and be served to 
gateways that read it before the list update propagates.
   
   ## Suggested fix
   Remove the size guard and always diff: `if (configDataNames != null) { 
configDataNames.removeAll(changeNames); 
configDataNames.forEach(this::delConfig); }` (the `removeAll` already yields 
the correct stale set regardless of sizes).
   
   ## Related existing
   None — distinct from SYNC-3/SYNC-4 (gateway-side `shenyu-sync-data-http` 
refresh NPE on null/empty) and SYNC-5/SYNC-6 (gateway-side 
`DiscoveryUpstream`/`ProxySelectorRefresh` no-clear-on-empty). Those are 
gateway-side `shenyu-sync-data-center` refresh handlers; this is admin-side 
`AbstractNodeDataChangedListener` (nacos/apollo/polaris publish path) with a 
different root cause (faulty size guard vs NPE/no-clear-on-empty).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to