[ 
https://issues.apache.org/jira/browse/CAMEL-24578?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Claus Ibsen updated CAMEL-24578:
--------------------------------
    Fix Version/s: 4.23.0

> camel-avro-rpc fails with Avro 1.12.2 due to new ClassSecurityValidator 
> rejecting HandshakeRequest
> --------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-24578
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24578
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-avro
>            Reporter: Claus Ibsen
>            Assignee: Omar Atie
>            Priority: Major
>             Fix For: 4.23.0
>
>
> Bumping Avro from 1.12.1 to 1.12.2 (see PR #25971, a Dependabot dependency 
> bump) breaks camel-avro-rpc's test suite on the Java 25 build. Avro 1.12.2 
> introduced a new schema-class security check 
> (org.apache.avro.util.ClassSecurityValidator) that rejects any class 
> referenced in an Avro schema unless it is explicitly trusted via the 
> org.apache.avro.SERIALIZABLE_CLASSES / org.apache.avro.SERIALIZABLE_PACKAGES 
> system properties, or the ClassSecurityValidator API.
> camel-avro-rpc's Netty/Jetty RPC producer and consumer tests build handshake 
> protocols that reference org.apache.avro.ipc.HandshakeRequest, which is not 
> on Avro's default trust list. This fails 61 of 64 tests in 
> camel-avro-rpc-component with:
> {noformat}
> Security Forbidden org.apache.avro.ipc.HandshakeRequest! This class is not 
> trusted to be
> included in Avro schemas. You may either use the system properties
> org.apache.avro.SERIALIZABLE_CLASSES and 
> org.apache.avro.SERIALIZABLE_PACKAGES to set the
> comma separated list of the classes or packages you trust, or you can set 
> them via the API
> (see org.apache.avro.util.ClassSecurityValidator).
> {noformat}
> Affected tests include AvroNettyProducerTest, AvroNettySpringProducerTest, 
> AvroNettySpringConsumerTest, and others, all failing at initializeServer() 
> during handshake setup.
> The camel-avro module's own surefire run also failed in the same CI build 
> (components/camel-avro/target/surefire-reports), likely for the same 
> underlying reason, though the detailed per-test output wasn't captured in the 
> console log for that module.
> Proposal: camel-avro-rpc (and camel-avro, if affected) should configure a 
> trusted class/package allowlist for the Avro classes/packages it legitimately 
> needs at runtime (e.g., org.apache.avro.ipc.*) rather than leaving this 
> unconfigured and broken. This likely means setting 
> org.apache.avro.SERIALIZABLE_PACKAGES (or using ClassSecurityValidator 
> programmatically) somewhere in the component's initialization, and 
> documenting/exposing it as a URI option if users need to trust their own 
> custom classes for RPC payloads.
> Reference: PR #25971 (Dependabot bump 1.12.1 -> 1.12.2) CI run: 
> https://github.com/apache/camel/actions/runs/33479975446/job/99767198741



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to