Aias00 opened a new issue, #6724: URL: https://github.com/apache/shenyu/issues/6724
- Severity: Medium - Location: `shenyu-plugin/shenyu-plugin-response/src/main/java/org/apache/shenyu/plugin/response/strategy/WebClientMessageWriter.java:84` + `:124-126`; `shenyu-plugin/shenyu-plugin-response/src/main/java/org/apache/shenyu/plugin/response/strategy/NettyClientMessageWriter.java:81` + `:97-99` - Description: Both writers, on `response.writeWith(body)` error, call `releaseIfNotConsumed(body, error)` whose body is `dataBufferDody.map(DataBufferUtils::release).then(Mono.error(ex))`. That operator **re-subscribes** to the same `body` `Flux<DataBuffer>` to drain/release remaining buffers. But both body sources are single-subscription: WebClient's `fluxResponseEntity.getBody()` and Netty's `connection.inbound().receive().retain()`. A second subscription errors or emits nothing, so the buffers already emitted-but-not-yet-released when the write failed are never reached by `DataBufferUtils::release`. They leak. On the Netty path the second-subscription `IllegalStateException` can replace the original error signal. - Impact: Pooled direct-memory ByteBuf leak on the response error/cancel path (client abort during streamed response). Compounds PERF-27/28. - Suggested fix: Track emitted buffers via `DataBufferUtils.track(...)` or release-on-complete/cancel inside the same single subscription (`body.doOnDiscard(DataBuffer.class, DataBufferUtils::release)` + `doFinally`), instead of re-subscribing to the single-use source. - Confidence: Medium - Related existing: #6413 is the *request*-body single-use retry bug (different stream and trigger); this is the *response*-body release-on-error re-subscription. --- ## D. Plugin lifecycle / SPI (8 findings) --- _Identified during the 2026-08-02 deep re-scan; full list in [`docs/scan2-2026-08-02/06-medium-tiers.md`](docs/scan2-2026-08-02/06-medium-tiers.md)._ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
