Skip to content

[fix][broker] Read the producer name of GetOrCreateSchema before authorization completes - #26770

Merged
merlimat merged 1 commit into
apache:masterfrom
lhotari:lh-fix-schema-producer-name
Sep 30, 2026
Merged

merlimat merged 1 commit into
apache:masterfrom
lhotari:lh-fix-schema-producer-name

Conversation

@lhotari

@lhotari lhotari commented Sep 30, 2026

Copy link
Copy Markdown
Member

Motivation

ServerCnx#handleGetOrCreateSchema reads the producer name from the command inside the callback that runs after the asynchronous topic authorization check. The Pulsar decoder reuses the command object once the handler returns, so when authorization completes asynchronously, the fields read in the callback can belong to a later command decoded on the same connection. The replicator producer flag passed to Topic#addSchema can then be wrong.

Modifications

  • Compute the replicator producer flag from the producer name before the asynchronous authorization step, while the command fields are still valid, and use it in the callback.

Verifying this change

  • Make sure that the change passes the CI checks.

This change added tests and can be verified as follows:

  • Added ServerCnxTest#testGetOrCreateSchemaKeepsProducerNameWhileAuthorizing: a replicator producer sends GetOrCreateSchema while its authorization is pending, a second GetOrCreateSchema with an ordinary producer name is decoded before authorization completes, and the first request must add the schema with the replicator flag set. The test fails without the fix.

Does this pull request potentially affect one of the following parts:

If the box was checked, please highlight the changes

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

…orization completes

handleGetOrCreateSchema read the producer name from the command inside the
callback that runs after the asynchronous topic authorization check. The
Pulsar decoder reuses the command object once the handler returns, so by
then the fields could belong to a later command on the same connection, and
the replicator producer flag passed to addSchema could be wrong.

Compute the replicator producer flag before the asynchronous step, and add a
test that decodes a second command while the first request is being
authorized.

Assisted-by: Claude Code
@merlimat
merlimat merged commit 2648735 into apache:master Sep 30, 2026
44 checks passed
@lhotari lhotari added this to the 5.0.0 milestone Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants