ffang opened a new pull request, #3553:
URL: https://github.com/apache/cxf/pull/3553

   …osed
   
   Since #3541, LoggingOutputStream closes itself (and logs) when a write 
fails, and any later close() is a no-op. If something writes to the stream 
after that, and the underlying stream silently accepts writes after close (as 
Tomcat 10.1 does), CacheAndWriteOutputStream caches those bytes again. Because 
totalLength is never reset, they spill into a new temp file and the stream is 
registered with the DelayedCachedOutputStreamCleaner again. When the cleaner 
fires, its close() is a no-op, so the temp file is never deleted, not even by 
the cleanup thread.
   
   This happens on a client connection reset during a large response: the write 
fails, the stream closes itself, and the fault chain (SoapOutEndingInterceptor) 
then writes the closing tags to the same stream.
   
   Once closed, the write methods now only pass the bytes through to the 
flow-through stream and no longer cache them, so nothing is spilled to disk 
after the payload has been logged.
   
   Add 2 tests to LoggingOutInterceptorTest (write after close, write after a 
failed write) that check the temp file is deleted after forceClean(); both fail 
without this change.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to