shashank created CAMEL-25127:
--------------------------------

             Summary: camel-syslog - valid RFC 5424 messages fail or are 
misparsed: no MSG (RFC 5424 example 4) throws BufferUnderflowException, an 
escaped ']' ends the structured data, a NILVALUE timestamp throws
                 Key: CAMEL-25127
                 URL: https://issues.apache.org/jira/browse/CAMEL-25127
             Project: Camel
          Issue Type: Bug
          Components: camel-syslog
            Reporter: shashank


{{SyslogConverter.parseMessage}} reads each RFC 5424 header field with a loop 
of the form {{while ((c = (char) (byteBuffer.get() & 0xff)) != ' ')}}. Three 
kinds of valid RFC 5424 messages are not handled.

*1. A message without MSG throws BufferUnderflowException.* The grammar is 
{{SYSLOG-MSG = HEADER SP STRUCTURED-DATA \[SP MSG\]}}: MSG is optional. When 
the structured data is the last field there is no space after it, and the loop 
reads past the end of the buffer. RFC 5424 section 6.5 example 4 
("STRUCTURED-DATA Only ... This is a valid message") fails:

{noformat}
<165>1 2003-10-11T22:14:15.003Z mymachine.example.com evntslog - ID47 
[exampleSDID@32473 iut="3" eventSource="Application" 
eventID="1011"][examplePriority@32473 class="high"]
  -> java.nio.BufferUnderflowException

<34>1 2003-10-11T22:14:15.003Z mymachine.example.com su - ID47 -
  -> java.nio.BufferUnderflowException
{noformat}

In a syslog route ({{netty:udp}} or {{netty:tcp}} with 
{{unmarshal().syslog()}}) the exchange fails, and the message is dropped after 
the error handler logs it. An RFC 3164 message that ends after the host name 
fails the same way.

*2. An escaped ']' in a structured data value ends the structured data.* RFC 
5424 section 6.3.3: inside a PARAM-VALUE the characters '"', '\' and ']' MUST 
be escaped with a backslash. The structured data loop only tracks '\[' and '\]' 
(CAMEL-8687) and does not know about quotes and escapes, so the escaped bracket 
closes the element and the next space ends the structured data:

{noformat}
<165>1 2003-10-11T22:14:15.003Z mymachine.example.com evntslog - ID47 
[exampleSDID@32473 note="a\] b"] hello
  structured data: [exampleSDID@32473 note="a\]            expected 
[exampleSDID@32473 note="a\] b"]
  log message:     b"] hello                               expected hello
{noformat}

The structured data is cut and the log message gets its tail, with no error.

*3. A NILVALUE timestamp throws IllegalArgumentException.* {{TIMESTAMP = 
NILVALUE / FULL-DATE "T" FULL-TIME}}, and section 6.2.3 says that a sender that 
cannot obtain the system time MUST send "-". The parser passes "-" to 
{{DatatypeConverter.parseDateTime}}, which throws. The timestamp should be null 
(the data format already skips a null timestamp when it sets the headers).

RFC 5424 examples 1 to 3 and the messages of the existing tests are parsed 
correctly today.

h3. Reproduction

{{SyslogConverter.toSyslogMessage(...)}} of the messages above on main, and the 
same messages through a route with {{unmarshal().syslog()}}. A small formal 
model (Lean 4) of the loops shows that any field that is the last one of the 
message fails, and that for every element text before an escaped ']' followed 
by a space, the structured data ends right after the escaped bracket. The model 
of the fix below is checked on these messages and on RFC 5424 examples 1 to 4.

h3. Affected versions

The field loops are the same since RFC 5424 support was added in 2.14.0 
(CAMEL-7788). The '\[' / '\]' tracking came with CAMEL-8687 (2.14.3, 2.15.2, 
2.16.0). Checked in 2.16.0, 3.0.0, 4.0.0, 4.14.0, 4.18.0, 4.22.0 and main.

h3. Proposed fix

* The end of the input also ends a field, and MSG is empty when it is absent.
* Read STRUCTURED-DATA with the RFC grammar: a '"' right after '=' inside an 
element starts a PARAM-VALUE, in which a backslash escapes the next character; 
a ']' outside a PARAM-VALUE closes the element; a space outside an element ends 
the structured data.
* Leave the timestamp null for the NILVALUE "-".

A field that is followed by a space is read exactly as before. The only input 
that is read differently is a structured data value with an unescaped ']' 
followed by a space inside the quotes, which RFC 5424 does not allow; it is now 
kept in the value instead of ending the structured data. The companion issue 
about the character decoding of the same method (UTF-8) is independent; the two 
changes touch different lines.

Duplicate check (2026-09-29): JIRA "SyslogConverter", "syslog" with "5424", 
"NILVALUE" or "structured data", and "BufferUnderflowException": CAMEL-8687 
(spaces inside structured data, fixed) and CAMEL-14369 (message without PRI, 
not a bug); nothing about a missing MSG, escaped values or the NILVALUE 
timestamp. No open pull request touches camel-syslog.

_Filed with Claude Code on behalf of allthingssecurity._




--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to