oscerd commented on code in PR #27073:
URL: https://github.com/apache/camel/pull/27073#discussion_r4132885309


##########
components/camel-opa/src/main/java/org/apache/camel/component/opa/OpaPolicyEvaluator.java:
##########
@@ -88,15 +88,18 @@ public boolean evaluate(Exchange exchange) throws 
OpaPolicyEvaluationException {
             decision = evaluateDecision(buildInput(exchange));
         } catch (InterruptedException e) {
             // not a policy failure but a shutdown, so failOpen must not turn 
it into an allow: nothing decided
-            // that this exchange was permitted. Restore the flag the 
interruptible wait cleared, then fail closed
+            // that this exchange was permitted. Restore the flag the 
interruptible wait cleared, then fail closed.
+            // This catches the wasm pool's wait; the REST SDK wraps an 
interrupted call in its OPAException, which
+            // reaches the catch below and fails closed there, as 
isDecisionPointUnavailable does not count it
             Thread.currentThread().interrupt();
             throw new OpaPolicyEvaluationException(
                     "Interrupted while evaluating policy " + policyPath, 
exchange, e);
         } catch (Exception e) {

Review Comment:
   Right, thanks. The SDK clears the flag when it wraps the interrupt, and the 
exchange failed closed without handing it back. Done in 3d012fb78:
   
   - `restoreInterruptIfWrapped` walks the cause chain and calls 
`Thread.currentThread().interrupt()` when it finds an `InterruptedException`. 
It runs in the single-evaluation catch and the whole-batch catch, and also for 
a per-element batch failure, because the SDK's one-call-per-element fallback 
can carry an interrupt on a single element.
   - `failsClosedOnAnInterruptedCallEvenUnderFailOpen` now asserts 
`Thread.interrupted()`, which also clears the flag again so it doesn't leak 
into the next test. A batch twin, 
`failsTheWholeBatchClosedAndKeepsTheInterruptWhenTheCallWasInterrupted`, does 
the same.
   - Both tests fail with the restore removed.
   
   The PR description now notes the deliberate difference from camel-openfga on 
5xx: OPA uses 500 for an error evaluating the policy against the input, so it 
fails closed here.
   
   _Claude Code on behalf of @oscerd_
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to