[
https://issues.apache.org/jira/browse/CAMEL-25127?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Claus Ibsen resolved CAMEL-25127.
---------------------------------
Resolution: Fixed
Fixed by https://github.com/apache/camel/pull/27036 (merged to main, 4.23.0).
_Claude Code on behalf of davsclaus_
> camel-syslog - valid RFC 5424 messages fail or are misparsed: no MSG (RFC
> 5424 example 4) throws BufferUnderflowException, an escaped ']' ends the
> structured data, a NILVALUE timestamp throws
> -----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
>
> Key: CAMEL-25127
> URL: https://issues.apache.org/jira/browse/CAMEL-25127
> Project: Camel
> Issue Type: Bug
> Components: camel-syslog
> Reporter: shashank
> Priority: Minor
> Fix For: 4.23.0
>
>
> {{SyslogConverter.parseMessage}} reads each RFC 5424 header field with a loop
> of the form {{while ((c = (char) (byteBuffer.get() & 0xff)) != ' ')}}. Three
> kinds of valid RFC 5424 messages are not handled.
> *1. A message without MSG throws BufferUnderflowException.* The grammar is
> {{SYSLOG-MSG = HEADER SP STRUCTURED-DATA \[SP MSG\]}}: MSG is optional. When
> the structured data is the last field there is no space after it, and the
> loop reads past the end of the buffer. RFC 5424 section 6.5 example 4
> ("STRUCTURED-DATA Only ... This is a valid message") fails:
> {noformat}
> <165>1 2003-10-11T22:14:15.003Z mymachine.example.com evntslog - ID47
> [exampleSDID@32473 iut="3" eventSource="Application"
> eventID="1011"][examplePriority@32473 class="high"]
> -> java.nio.BufferUnderflowException
> <34>1 2003-10-11T22:14:15.003Z mymachine.example.com su - ID47 -
> -> java.nio.BufferUnderflowException
> {noformat}
> In a syslog route ({{netty:udp}} or {{netty:tcp}} with
> {{unmarshal().syslog()}}) the exchange fails, and the message is dropped
> after the error handler logs it. An RFC 3164 message that ends after the host
> name fails the same way.
> *2. An escaped ']' in a structured data value ends the structured data.* RFC
> 5424 section 6.3.3: inside a PARAM-VALUE the characters '"', '\' and ']' MUST
> be escaped with a backslash. The structured data loop only tracks '\[' and
> '\]' (CAMEL-8687) and does not know about quotes and escapes, so the escaped
> bracket closes the element and the next space ends the structured data:
> {noformat}
> <165>1 2003-10-11T22:14:15.003Z mymachine.example.com evntslog - ID47
> [exampleSDID@32473 note="a\] b"] hello
> structured data: [exampleSDID@32473 note="a\] expected
> [exampleSDID@32473 note="a\] b"]
> log message: b"] hello expected hello
> {noformat}
> The structured data is cut and the log message gets its tail, with no error.
> *3. A NILVALUE timestamp throws IllegalArgumentException.* {{TIMESTAMP =
> NILVALUE / FULL-DATE "T" FULL-TIME}}, and section 6.2.3 says that a sender
> that cannot obtain the system time MUST send "-". The parser passes "-" to
> {{DatatypeConverter.parseDateTime}}, which throws. The timestamp should be
> null (the data format already skips a null timestamp when it sets the
> headers).
> RFC 5424 examples 1 to 3 and the messages of the existing tests are parsed
> correctly today.
> h3. Reproduction
> {{SyslogConverter.toSyslogMessage(...)}} of the messages above on main, and
> the same messages through a route with {{unmarshal().syslog()}}. A small
> formal model (Lean 4) of the loops shows that any field that is the last one
> of the message fails, and that for every element text before an escaped ']'
> followed by a space, the structured data ends right after the escaped
> bracket. The model of the fix below is checked on these messages and on RFC
> 5424 examples 1 to 4.
> h3. Affected versions
> The field loops are the same since RFC 5424 support was added in 2.14.0
> (CAMEL-7788). The '\[' / '\]' tracking came with CAMEL-8687 (2.14.3, 2.15.2,
> 2.16.0). Checked in 2.16.0, 3.0.0, 4.0.0, 4.14.0, 4.18.0, 4.22.0 and main.
> h3. Proposed fix
> * The end of the input also ends a field, and MSG is empty when it is absent.
> * Read STRUCTURED-DATA with the RFC grammar: a '"' right after '=' inside an
> element starts a PARAM-VALUE, in which a backslash escapes the next
> character; a ']' outside a PARAM-VALUE closes the element; a space outside an
> element ends the structured data.
> * Leave the timestamp null for the NILVALUE "-".
> A field that is followed by a space is read exactly as before. The only input
> that is read differently is a structured data value with an unescaped ']'
> followed by a space inside the quotes, which RFC 5424 does not allow; it is
> now kept in the value instead of ending the structured data. The companion
> issue about the character decoding of the same method (UTF-8) is independent;
> the two changes touch different lines.
> Duplicate check (2026-09-29): JIRA "SyslogConverter", "syslog" with "5424",
> "NILVALUE" or "structured data", and "BufferUnderflowException": CAMEL-8687
> (spaces inside structured data, fixed) and CAMEL-14369 (message without PRI,
> not a bug); nothing about a missing MSG, escaped values or the NILVALUE
> timestamp. No open pull request touches camel-syslog.
> _Filed with Claude Code on behalf of allthingssecurity._
--
This message was sent by Atlassian Jira
(v8.20.10#820010)