davsclaus commented on code in PR #27073:
URL: https://github.com/apache/camel/pull/27073#discussion_r4132780517


##########
components/camel-opa/src/main/java/org/apache/camel/component/opa/OpaPolicyEvaluator.java:
##########
@@ -88,15 +88,18 @@ public boolean evaluate(Exchange exchange) throws 
OpaPolicyEvaluationException {
             decision = evaluateDecision(buildInput(exchange));
         } catch (InterruptedException e) {
             // not a policy failure but a shutdown, so failOpen must not turn 
it into an allow: nothing decided
-            // that this exchange was permitted. Restore the flag the 
interruptible wait cleared, then fail closed
+            // that this exchange was permitted. Restore the flag the 
interruptible wait cleared, then fail closed.
+            // This catches the wasm pool's wait; the REST SDK wraps an 
interrupted call in its OPAException, which
+            // reaches the catch below and fails closed there, as 
isDecisionPointUnavailable does not count it
             Thread.currentThread().interrupt();
             throw new OpaPolicyEvaluationException(
                     "Interrupted while evaluating policy " + policyPath, 
exchange, e);
         } catch (Exception e) {

Review Comment:
   The OPA SDK catches `InterruptedException` and wraps it in `OPAException` 
without re-setting the interrupt flag, so it lands in this `catch (Exception 
e)` (and the batch one at line 197). It fails closed, but the thread's 
interrupt status stays cleared. Suggest walking the cause chain in both catches 
and calling `Thread.currentThread().interrupt()` when it contains an 
`InterruptedException`, and asserting `Thread.interrupted()` in 
`failsClosedOnAnInterruptedCallEvenUnderFailOpen` (camel-openfga does this).



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to