tmielke opened a new pull request, #27136:
URL: https://github.com/apache/camel/pull/27136

   
   # Description
   
   When `MllpTcpServerConsumer` receives an MLLP payload whose first byte is a 
segment delimiter (0x0D / \r), populateHl7DataHeaders crashes with 
`ArrayIndexOutOfBoundsException: Index -1` because the parsing loop accesses 
`hl7MessageBytes[i - 1]` at i == 0.
   
   This is a latent defect in the original 2018 implementation — the default 
configuration (hl7Headers=true, validatePayload=false) leaves this path 
unguarded.
   
   Changes
   
   - `MllpTcpServerConsumer.java` — two fixes:
     - Added `i > 0` guard before `hl7MessageBytes[i - 1]` to prevent the 
out-of-bounds access
     - Changed if (`-1 == endOfMSH`) to if (`endOfMSH <= 0`) so a zero-length 
MSH segment (delimiter at byte 0) is treated as invalid rather than falling 
through to the header parsing branch
   - `MllpTcpServerConsumerPopulateHl7DataHeadersTest.java` — new unit test 
with two test cases:
     - Message starting with segment delimiter (reproduces the reported crash)
     - Message where f`ieldSeparator == SEGMENT_DELIMITER` (edge case where 
byte[3] is also 0x0D)
   
   Test plan
   
   - [x] New unit tests pass (`mvn test 
-Dtest=MllpTcpServerConsumerPopulateHl7DataHeadersTest -pl 
components/camel-mllp`)
   - [x] Full MLLP test suite passes with no regressions (348 tests, 0 failures)
   
   
   # Target
   
   - [x] I checked that the commit is targeting the correct branch (Camel 4 
uses the `main` branch)
   
   # Tracking
   - [x] If this is a large change, bug fix, or code improvement, I checked 
there is a [JIRA issue](https://issues.apache.org/jira/browse/CAMEL) filed for 
the change (usually before you start working on it).
   
   # Apache Camel coding standards and style
   
   - [x] I checked that each commit in the pull request has a meaningful 
subject line and body.
   
   - [x] I have run `mvn clean install -DskipTests` locally from root folder 
and I have committed all auto-generated changes.
   
   # AI-assisted contributions
   
   - [x] If this PR includes AI-generated code, commits have proper 
co-authorship attribution (e.g., `Co-authored-by` trailers) and the PR 
description identifies the AI tool used.
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to