Aias00 opened a new issue, #7313:
URL: https://github.com/apache/shenyu/issues/7313

   ## Current Behavior
   
   Admin serializes WebSocket writes through one `SessionSendQueue` per 
session. The queue advances only when the callback passed to 
`AsyncRemote.sendText` executes.
   
   If the async send never invokes its callback—for example on a half-open 
connection, stalled ingress/LB path, or a non-reading client—`sending` remains 
`true` forever. Later configuration messages are appended to an unbounded 
`ArrayDeque`, but no call restarts `sendNext()`.
   
   There is no configured async-send timeout, queue limit, oldest-message 
deadline, or watchdog.
   
   When a callback reports failure, or `sendText` throws, the current message 
is logged and discarded. The session is not closed and no gateway full 
resynchronization is requested. Because WebSocket events have no ACK/replay 
cursor, the gateway can remain stale until restart.
   
   ## Reproduction
   
   - Mock `RemoteEndpoint.Async#sendText` so the first send never invokes its 
`SendHandler`.
   - Send two or more updates to the same session.
   - Verify only the first call reaches `sendText`; subsequent messages remain 
queued indefinitely.
   - In a second case, return a failed `SendResult` and verify the failed 
update is discarded without closing the session or triggering `MYSELF`.
   
   ## Expected Behavior
   
   A blocked or failed WebSocket send must be detected within a bounded time 
and force a recoverable connection state. Configuration updates must not remain 
silently queued or be dropped without reconciliation.
   
   ## Scope
   
   - Configure or implement a bounded per-message send timeout.
   - Bound the per-session queue by count and/or bytes.
   - On timeout or send failure, stop the queue, remove the session from all 
indexes, close it, and allow the gateway to reconnect and perform `MYSELF` full 
synchronization.
   - Preserve message ordering for healthy sessions.
   - Define behavior for queue overflow; silent drop is not acceptable.
   - Add metrics for queue length/bytes, oldest message age, in-flight 
duration, timeout, failure, overflow, and forced reconnect.
   - Cover races among callback completion, timeout, `onClose`, and new 
messages.
   
   ## Acceptance Criteria
   
   - [ ] A missing send callback cannot stall a session queue indefinitely.
   - [ ] Failed sends cannot leave the gateway silently stale.
   - [ ] Queue memory use is bounded.
   - [ ] Failure/timeout removes the session and its queue from all maps.
   - [ ] Reconnect triggers a full synchronization before normal incremental 
delivery resumes.
   - [ ] Ordering is preserved on healthy connections.
   - [ ] Unit tests cover no-callback, failed callback, synchronous exception, 
overflow, close race, and recovery.
   - [ ] An integration test reproduces a stalled/broken WebSocket connection 
and verifies final cache convergence.
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to