Aias00 opened a new issue, #6624: URL: https://github.com/apache/shenyu/issues/6624
- severity: High - files: `shenyu-admin/src/main/java/org/apache/shenyu/admin/service/impl/ScalePolicyServiceImpl.java:80-88`; `shenyu-admin/src/main/java/org/apache/shenyu/admin/model/entity/ScalePolicyDO.java:230-252`; `shenyu-admin/src/main/java/org/apache/shenyu/admin/scale/scaler/cache/ScalePolicyCache.java`; `shenyu-admin/src/main/java/org/apache/shenyu/admin/scale/scaler/ScaleService.java` - description: `ScalePolicyServiceImpl.update` builds `scalePolicy = ScalePolicyDO.buildScalePolicyDO(scalePolicyDTO)` from the (partial) web DTO. `ScalePolicyDTO.num`/`beginTime`/`endTime` are nullable (no `@NotNull`). `buildScalePolicyDO` sets `.num(item.getNum())` etc., so null DTO fields → null DO fields. `updateByPrimaryKeySelective` correctly writes only non-null columns (DB retains old values) BUT `scalePolicyCache.updatePolicy(scalePolicy)` puts the *partial* DO (with null `num`/`beginTime`/`endTime`) into the cache. `executeScaling()` then reads from the cache (not DB). For policy `"1"` it calls `kubernetesScaler.scaleByNum(activePolicy.getNum())` — `getNum()` returns boxed `Integer` auto-unboxed to primitive `int`, NPE if null. For policy `"2"` it calls `now.after(policy.getBeginTime())` where `getBeginTime()` is null → NPE. - impact: Enabling/updating a scale policy with a partial DTO corrupts the in-memory cache (cache/DB divergence) and throws NPE inside `executeScaling`; the corrupted cache entry persists and breaks all subsequent scaling cycles. - suggested_fix: After `updateByPrimaryKeySelective`, re-read the full row (`scalePolicyMapper.selectByPrimaryKey(id)`) and cache that merged DO; or have `buildScalePolicyDO` merge against the existing cached/DB row. Gate `executeScaling` on null fields. - confidence: High - related_existing: none. Not a dup of PERF-11 (unbounded caches); this is selective-update/DB-vs-cache divergence specific to ScalePolicy. --- _Identified during the 2026-08-02 deep re-scan; full list in [`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
