This is an automated email from the ASF dual-hosted git repository.

davsclaus pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git


The following commit(s) were added to refs/heads/main by this push:
     new 626f134fae6a CAMEL-24440: docs - add the camel-crypto note to the 4.22 
upgrade guide (#27491)
626f134fae6a is described below

commit 626f134fae6aa272eab7b828c8532152994a179a
Author: Claus Ibsen <[email protected]>
AuthorDate: Wed Oct 7 14:59:40 2026 +0200

    CAMEL-24440: docs - add the camel-crypto note to the 4.22 upgrade guide 
(#27491)
    
    The fix is backported to camel-4.22.x (#27490), so the 4.22.2 section of 
the 4.22 upgrade guide on main gets the same note as the 4.23 guide.
    
    Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
    Signed-off-by: Claus Ibsen <[email protected]>
---
 .../ROOT/pages/camel-4x-upgrade-guide-4_22.adoc    | 26 ++++++++++++++++++++++
 1 file changed, 26 insertions(+)

diff --git 
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc 
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
index be580bbe1ac5..59d9bcc08758 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_22.adoc
@@ -246,6 +246,32 @@ applied does not receive the messages of the producers, 
and it is closed when it
 A WebSocket client that connected without satisfying the configured security 
provider or allowed roles is now
 rejected: it must authenticate, or the option must be removed from the 
WebSocket endpoint.
 
+=== camel-crypto
+
+Three changes to `CryptoDataFormat`, none of which affects the format of data 
already written.
+
+*A per-message initialization vector when inlining.* `marshal` used to throw
+`Inlining cannot be performed, as no initialization vector was specified` when
+`shouldInlineInitializationVector` was set without a statically configured 
vector — which pushed routes
+into reusing one vector for every message, the thing inlining exists to avoid. 
A fresh vector is now
+generated per message when none is supplied. Because the vector is written 
into the message, readers pick
+it up from the stream and need no change. A vector supplied explicitly, by 
configuration or by the
+`CamelCryptoInitVector` header, is still used as given.
+
+*Authentication failures report uniformly.* A tampered message previously 
surfaced two distinguishable
+outcomes: `Given final block not properly padded` from the cipher, or 
`Expected mac did not match actual
+mac` from the MAC check. A caller able to submit ciphertext and observe which 
one came back can use that
+distinction to recover plaintext. Both now report `Message authentication 
failed`, and the message no
+longer includes the expected and computed MAC values — the computed one is 
`HMAC_k` over the plaintext
+just produced. Code matching on the old text must be updated.
+
+*The inlined vector length is bounded.* The length prefix is read from the 
message and used to size an
+allocation; a declared length outside 0–1024 is now rejected instead of 
attempted.
+
+Not changed: the HMAC key is still derived from the same key material as the 
cipher. Separating them
+would change the MAC written into the message and so could not be read by 
earlier versions; that is
+tracked separately.
+
 == Upgrading from 4.22.0 to 4.22.1
 
 === camel-docling

Reply via email to