[
https://issues.apache.org/jira/browse/CAMEL-24262?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Andrea Cosentino reassigned CAMEL-24262:
----------------------------------------
Fix Version/s: 4.22.0
Assignee: Andrea Cosentino
> camel-aws2: producer catch blocks eagerly dereference nullable
> awsErrorDetails() when logging the error code
> ------------------------------------------------------------------------------------------------------------
>
> Key: CAMEL-24262
> URL: https://issues.apache.org/jira/browse/CAMEL-24262
> Project: Camel
> Issue Type: Bug
> Components: camel-aws
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.22.0
>
>
> h3. Summary
> Related to CAMEL-24251 (same root cause, different location). Across 28 AWS
> v2 producers, the {{catch (AwsServiceException ase)}} blocks log the error
> code with:
> {code:java}
> } catch (AwsServiceException ase) {
> LOG.trace("List Brokers command returned the error code {}",
> ase.awsErrorDetails().errorCode());
> throw ase;
> }
> {code}
> {{AwsServiceException.awsErrorDetails()}} is nullable (see CAMEL-24251, where
> the same dereference is reproduced throwing NPE in the producer health
> checks). Here the dereference sits on the *main error-handling path*: if
> {{awsErrorDetails()}} is null, {{ase.awsErrorDetails().errorCode()}} throws
> {{NullPointerException}} and the original {{AwsServiceException}} is *masked*
> by that NPE at the {{throw}} site.
> Because the expression is a method argument, Java evaluates it *eagerly* — so
> this happens even when TRACE logging is disabled. It is not gated by the log
> level.
> h3. Scope
> 358 such log sites across 28 producer files (every operation's catch block).
> For a genuine AWS service error the SDK populates {{awsErrorDetails}}, so the
> practical trigger is narrow (synthetic / edge-case exceptions, as in
> CAMEL-24251) — this is *lower severity* than CAMEL-24251, filed for
> consistency and defense-in-depth rather than a frequently-hit crash.
> h3. Proposed fix (low-churn)
> Add a null-safe helper in {{camel-aws-common}}, e.g.:
> {code:java}
> public static String errorCode(AwsServiceException e) {
> return e.awsErrorDetails() != null ? e.awsErrorDetails().errorCode() :
> null;
> }
> {code}
> and migrate the log sites to {{AwsExceptionHelper.errorCode(ase)}}
> opportunistically (e.g. per component, alongside other work), rather than one
> 358-site sweep. This also removes the eager-deref foot-gun for future
> producers.
> Raised from an automated audit of the camel-aws components.
> ----
> _Reported by Claude Code on behalf of acosentino._
--
This message was sent by Atlassian Jira
(v8.20.10#820010)