oscerd opened a new pull request, #27140: URL: https://github.com/apache/camel/pull/27140
Doc-sync for CAMEL-25023, per the backport upgrade-guide policy: the guides for **every** release line live on `main`, so a fix backported to a maintenance branch needs its entry added to the matching `camel-4x-upgrade-guide-4_XX.adoc` here. #26892 added the entry to the 4.23 guide. CAMEL-25023 is now being backported to **camel-4.22.x (#27137)** and **camel-4.18.x (#27138)**, so the same entry belongs under `== Upgrading from 4.22.1 to 4.22.2` and `== Upgrading from 4.18.4 to 4.18.5`. Without it, `main`'s version-specific guides drift out of sync with what actually ships on those branches. The behaviour recorded is identical on all three lines: a `maxDecompressedSize` of 2 GiB or more is now enforced, and `IOHelper.copy` returns `Integer.MAX_VALUE` instead of a wrapped negative. ### Why the backports were needed The Jira already listed 4.18.5 and 4.22.2 in its fixVersions, but the fix was on neither branch — both still counted in an `int` while carrying the `maxSize` guard, so the zip/tar-bomb limit was bypassable there. Reverting the fix on each branch fails the ported tests with `maxSize 2147483547 was not enforced` and a returned count of `-1073741824`. ### One unrelated line The 4.18 guide had `=== camel-dynamic-router` with **no blank line before it**, so AsciiDoc rendered that section title as body text of the preceding paragraph rather than as a heading. It is a pre-existing defect on `main`, one line, in a file this change already touches. Happy to split it out if you would rather keep the diff to the doc-sync alone. Merge order does not strictly matter, but this reads best alongside #27137 and #27138. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
