Aias00 opened a new issue, #6723:
URL: https://github.com/apache/shenyu/issues/6723

   - Severity: Medium
   - Location:
   
`shenyu-plugin/shenyu-plugin-base/src/main/java/org/apache/shenyu/plugin/base/cache/MetaDataCache.java:122-138`
 (scan `:125-129`, cache `:133-134`)
   - 
   Description:
   On a `CACHE` miss, `obtain` scans 
`META_DATA_MAP.values().stream().filter(data -> data.getEnabled() && 
PathMatchUtils.match(data.getPath(), path)).findFirst()`. `META_DATA_MAP` is a 
`ConcurrentHashMap`; `values()` iteration order is hash-bucket order, not 
pattern specificity. When two registered metadata paths both match (e.g. 
`/api/**` and `/api/users/**` both matching `/api/users/42`), the one returned 
is whichever the CHM yields first — not the more specific one — and that 
arbitrary choice is pinned into `CACHE.put`. The choice can flip after an 
unrelated metadata insert/delete triggers a CHM resize (changing bucket 
layout). Exact (non-wildcard) metadata is pre-cached directly in `cache()` at 
line 85, so only overlapping-wildcard configs are exposed.
   - 
   Impact:
   Non-deterministic / wrong-backend routing when overlapping wildcard metadata 
exists; cached once chosen.
   - 
   Suggested fix:
   Sort matching candidates by specificity (longest non-wildcard prefix / 
`PathPattern` comparator) before `findFirst`.
   - 
   Confidence: Medium
   - Related existing: #6548/#6549/#6550/PERF-04/05 cover unbounded cache and 
O(n) miss cost; this is the separate selection-arity correctness issue.
   
   ---
   _Identified during the 2026-08-02 deep re-scan; full list in 
[`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to