allthingssecurity opened a new pull request, #27036:
URL: https://github.com/apache/camel/pull/27036

   # Description
   
   [CAMEL-25127](https://issues.apache.org/jira/browse/CAMEL-25127)
   
   `SyslogConverter.parseMessage` fails on, or misreads, three kinds of valid 
RFC 5424 messages:
   
   1. **No MSG.** `SYSLOG-MSG = HEADER SP STRUCTURED-DATA [SP MSG]`, so MSG is 
optional, but every field loop is `while ((c = get()) != ' ')` and reads past 
the end of the buffer when the field is the last one. RFC 5424 example 4 
("STRUCTURED-DATA Only ... This is a valid message") and `... su - ID47 -` 
throw `BufferUnderflowException`, and in a syslog route the message is dropped 
after the error handler logs it. An RFC 3164 message that ends after the host 
name fails the same way.
   2. **Escaped `]` in a PARAM-VALUE.** RFC 5424 6.3.3 requires `"`, `\` and 
`]` to be escaped inside a value. The structured data loop only tracks `[` and 
`]` (CAMEL-8687), so `note="a\] b"` closes the element at `\]`, the next space 
ends the structured data, and the log message becomes `b"] hello`, with no 
error.
   3. **NILVALUE timestamp.** A sender that cannot obtain the time MUST send 
`-` (6.2.3). It goes to `DatatypeConverter.parseDateTime("-")`, which throws 
`IllegalArgumentException`.
   
   This change:
   - The header field loops also stop at the end of the input, so MSG is empty 
when it is absent. A field followed by a space is read exactly as before.
   - The structured data loop follows the RFC grammar: a `"` right after `=` 
inside an element starts a PARAM-VALUE, in which a backslash escapes the next 
character, and only a `]` outside a PARAM-VALUE closes the element. The only 
input that is read differently is an unescaped `]` followed by a space inside a 
quoted value, which the RFC does not allow; it now stays in the value.
   - The timestamp is left null for the NILVALUE. `unmarshal` already skips the 
`CamelSyslogTimestamp` header when the timestamp is null.
   
   The character decoding of the same method (UTF-8, companion issue) is fixed 
in a separate PR. That PR only changes the lines that set the fields, and this 
one only the loop conditions, the structured data loop and the timestamp, so 
the two merge without conflict in either order.
   
   Tests:
   - New `SyslogRfc5424ParseTest`: RFC 5424 example 4, the NILVALUE structured 
data without MSG, an escaped `]`, escaped `"` and `\` together with `\]` in 
several elements, the NILVALUE timestamp, an RFC 3164 message without MSG, and 
through a route with `unmarshal().syslog()` example 4 and the NILVALUE 
timestamp. Controls: RFC 5424 examples 1 to 3, and a stray quote that does not 
start a value, which is parsed as before.
   - Without the change, 8 of the 9 new tests fail: 6 with 
`BufferUnderflowException` or `IllegalArgumentException: -` (in the two route 
tests wrapped in a `CamelExecutionException`), and the two escape tests with 
the structured data cut at `\]` (`[exampleSDID@32473 note="a\]`). The control 
test (RFC 5424 examples 1 to 3 and the stray quote) passes.
   - With the change, the whole camel-syslog module: 22 tests (13 existing, 9 
new), 0 failures, 0 errors, 0 skipped.
   
   Found with a Lean 4 model of the field and structured data loops (any last 
field fails; for any element text before `\]` and a space the structured data 
ends at `\]`; the fixed loops give the Java result whenever a space follows the 
field), then reproduced with the real classes.
   
   # Target
   
   - [x] I checked that the commit is targeting the correct branch (Camel 4 
uses the `main` branch)
   
   # Tracking
   - [x] If this is a large change, bug fix, or code improvement, I checked 
there is a [JIRA issue](https://issues.apache.org/jira/browse/CAMEL) filed for 
the change (usually before you start working on it).
   
   # Apache Camel coding standards and style
   
   - [x] I checked that each commit in the pull request has a meaningful 
subject line and body.
   - [ ] I have run `mvn clean install -DskipTests` locally from root folder 
and I have committed all auto-generated changes.
     (I built and tested the affected module, including the formatter and 
import-sort plugins. I did not run the full root build.)
   
   # AI-assisted contributions
   
   - [x] If this PR includes AI-generated code, commits have proper 
co-authorship attribution (e.g., `Co-authored-by` trailers) and the PR 
description identifies the AI tool used.
     This PR was prepared with Claude Code (Claude Opus 5.5). The commit 
carries a `Co-Authored-By` trailer.
   
   _Claude Code on behalf of allthingssecurity_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to