Aias00 opened a new issue, #6611:
URL: https://github.com/apache/shenyu/issues/6611

   - Severity: Critical
   - Location:
   
`shenyu-sync-data-center/shenyu-sync-data-zookeeper/src/main/java/org/apache/shenyu/sync/data/zookeeper/ZookeeperSyncDataService.java:86`
 (guard), `:102-112` (dead `NODE_DELETED` switch branch)
   - 
   Description:
   The `CuratorCacheListener` lambda (`(type, oldData, data)`) has an early 
guard `if (Objects.isNull(data) || Objects.isNull(data.getData())) { return; 
}`. Per the Curator 5.7.0 `CuratorCacheListener` contract (verified: the lambda 
maps to `event(Type, ChildData oldData, ChildData data)` where `data` is "the 
new data or null"), for `NODE_DELETED` the `data` parameter is `null` because 
the node no longer exists. Every delete event hits the early return and never 
reaches the `switch(type)` block. The `case NODE_DELETED: eventType = 
EventType.DELETE;` branch is dead code. No 
plugin/selector/rule/auth/metadata/proxy-selector deletion is ever processed on 
the ZK sync path.
   - 
   Impact:
   When any config item is deleted in admin (ZK sync backend), the gateway 
never removes it from its local cache. Deleted plugins, selectors, rules, 
app-auths, metadata, proxy-selectors remain active indefinitely — stale 
routing, phantom rules, security exposure (deleted auth keys still honored).
   - 
   Suggested fix:
   Before the null-data guard, check `type == NODE_DELETED` and use `oldData` 
(carries the path and last-known data) to dispatch `event(configNamespace, 
oldData.getPath(), null, registerPath, EventType.DELETE)`. Only guard on `data` 
for PUT events.
   - 
   Confidence: High
   - Related existing: none — #6526/#6525 are in `shenyu-registry` (discovery 
registry), not `shenyu-sync-data-zookeeper` (config sync). Different component.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to