shashank created CAMEL-25127:
--------------------------------
Summary: camel-syslog - valid RFC 5424 messages fail or are
misparsed: no MSG (RFC 5424 example 4) throws BufferUnderflowException, an
escaped ']' ends the structured data, a NILVALUE timestamp throws
Key: CAMEL-25127
URL: https://issues.apache.org/jira/browse/CAMEL-25127
Project: Camel
Issue Type: Bug
Components: camel-syslog
Reporter: shashank
{{SyslogConverter.parseMessage}} reads each RFC 5424 header field with a loop
of the form {{while ((c = (char) (byteBuffer.get() & 0xff)) != ' ')}}. Three
kinds of valid RFC 5424 messages are not handled.
*1. A message without MSG throws BufferUnderflowException.* The grammar is
{{SYSLOG-MSG = HEADER SP STRUCTURED-DATA \[SP MSG\]}}: MSG is optional. When
the structured data is the last field there is no space after it, and the loop
reads past the end of the buffer. RFC 5424 section 6.5 example 4
("STRUCTURED-DATA Only ... This is a valid message") fails:
{noformat}
<165>1 2003-10-11T22:14:15.003Z mymachine.example.com evntslog - ID47
[exampleSDID@32473 iut="3" eventSource="Application"
eventID="1011"][examplePriority@32473 class="high"]
-> java.nio.BufferUnderflowException
<34>1 2003-10-11T22:14:15.003Z mymachine.example.com su - ID47 -
-> java.nio.BufferUnderflowException
{noformat}
In a syslog route ({{netty:udp}} or {{netty:tcp}} with
{{unmarshal().syslog()}}) the exchange fails, and the message is dropped after
the error handler logs it. An RFC 3164 message that ends after the host name
fails the same way.
*2. An escaped ']' in a structured data value ends the structured data.* RFC
5424 section 6.3.3: inside a PARAM-VALUE the characters '"', '\' and ']' MUST
be escaped with a backslash. The structured data loop only tracks '\[' and '\]'
(CAMEL-8687) and does not know about quotes and escapes, so the escaped bracket
closes the element and the next space ends the structured data:
{noformat}
<165>1 2003-10-11T22:14:15.003Z mymachine.example.com evntslog - ID47
[exampleSDID@32473 note="a\] b"] hello
structured data: [exampleSDID@32473 note="a\] expected
[exampleSDID@32473 note="a\] b"]
log message: b"] hello expected hello
{noformat}
The structured data is cut and the log message gets its tail, with no error.
*3. A NILVALUE timestamp throws IllegalArgumentException.* {{TIMESTAMP =
NILVALUE / FULL-DATE "T" FULL-TIME}}, and section 6.2.3 says that a sender that
cannot obtain the system time MUST send "-". The parser passes "-" to
{{DatatypeConverter.parseDateTime}}, which throws. The timestamp should be null
(the data format already skips a null timestamp when it sets the headers).
RFC 5424 examples 1 to 3 and the messages of the existing tests are parsed
correctly today.
h3. Reproduction
{{SyslogConverter.toSyslogMessage(...)}} of the messages above on main, and the
same messages through a route with {{unmarshal().syslog()}}. A small formal
model (Lean 4) of the loops shows that any field that is the last one of the
message fails, and that for every element text before an escaped ']' followed
by a space, the structured data ends right after the escaped bracket. The model
of the fix below is checked on these messages and on RFC 5424 examples 1 to 4.
h3. Affected versions
The field loops are the same since RFC 5424 support was added in 2.14.0
(CAMEL-7788). The '\[' / '\]' tracking came with CAMEL-8687 (2.14.3, 2.15.2,
2.16.0). Checked in 2.16.0, 3.0.0, 4.0.0, 4.14.0, 4.18.0, 4.22.0 and main.
h3. Proposed fix
* The end of the input also ends a field, and MSG is empty when it is absent.
* Read STRUCTURED-DATA with the RFC grammar: a '"' right after '=' inside an
element starts a PARAM-VALUE, in which a backslash escapes the next character;
a ']' outside a PARAM-VALUE closes the element; a space outside an element ends
the structured data.
* Leave the timestamp null for the NILVALUE "-".
A field that is followed by a space is read exactly as before. The only input
that is read differently is a structured data value with an unescaped ']'
followed by a space inside the quotes, which RFC 5424 does not allow; it is now
kept in the value instead of ending the structured data. The companion issue
about the character decoding of the same method (UTF-8) is independent; the two
changes touch different lines.
Duplicate check (2026-09-29): JIRA "SyslogConverter", "syslog" with "5424",
"NILVALUE" or "structured data", and "BufferUnderflowException": CAMEL-8687
(spaces inside structured data, fixed) and CAMEL-14369 (message without PRI,
not a bug); nothing about a missing MSG, escaped values or the NILVALUE
timestamp. No open pull request touches camel-syslog.
_Filed with Claude Code on behalf of allthingssecurity._
--
This message was sent by Atlassian Jira
(v8.20.10#820010)