Skip to content

ScriptedConfiguration.getGroovyScriptEngine() can return null while release() runs #149

Description

@vharseko

Found in the review of #132; the race predates that PR.

What happens

ScriptedConfiguration.getGroovyScriptEngine() reads the groovyScriptEngine field twice outside the lock: once for the null check on the fast path (ScriptedConfiguration.java:786) and once for the return (:804). release() sets the field to null (:668) inside synchronized (this), a lock the fast path does not take.

If release() runs between the two reads, getGroovyScriptEngine() returns null, and evaluate throws an NPE at getGroovyScriptEngine().createScript(...) (:744). loadScript (:760) has the same exposure. release() is called from OperationalContext.dispose() when the connector's pooled configuration is disposed, for example on connector-server shutdown. ConnectionListener.shutdown does not wait for in-flight requests, so a script evaluation that is still running can hit the race. The window is small.

Expected

getGroovyScriptEngine() never returns null. The usual way to write double-checked locking with a volatile field is to read the field once into a local variable.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingconcurrencyRaces, locking and thread-safety fixesconnector:groovyGroovy connector

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions