This is an automated email from the ASF dual-hosted git repository.

oscerd pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel-kamelets.git


The following commit(s) were added to refs/heads/main by this push:
     new 925b53fb2 Fix #2980: drop exec-sink's non-functional args / ce-args 
interface (#3066)
925b53fb2 is described below

commit 925b53fb22d6bbfcf5d8be72420200930e2a6c1e
Author: Andrea Cosentino <[email protected]>
AuthorDate: Mon Sep 28 10:19:58 2026 +0200

    Fix #2980: drop exec-sink's non-functional args / ce-args interface (#3066)
    
    exec-sink mapped an inbound `args` / `ce-args` header onto
    `CamelExecCommandArgs`, and the doc partial advertised it:
    
        === Optional Headers
        - `args` / `ce-args`: Command line arguments to pass to the executable
    
    camel-exec never reads that header. `DefaultExecBinding.readInput` gates
    it behind an endpoint option:
    
        Object args = endpoint.isAllowControlHeaders()
                ? exchange.getIn().removeHeader(EXEC_COMMAND_ARGS) : null;
    
    `allowControlHeaders` defaults to false -- deliberately, because dynamic
    arguments from a message header are a command-injection surface -- and
    exec-sink never set it. The advertised interface has therefore never
    done anything.
    
    Remove the mapping and the doc claim rather than relax the component
    default. Option (b) from the issue -- setting allowControlHeaders=true
    and stripping the rest of the CamelExec* family -- stays available if
    the feature is ever wanted, but it relaxes a security-relevant default
    in a shared catalog and needs an upgrade-guide entry and PMC sign-off.
    
    Verified with `camel run` on Camel 4.22.0, calling the Kamelet with
    executable=echo and an `args` header:
    
        old:  stdout=[\n]  CamelExecCommandArgs after the call = HEADER-ARGS
        new:  stdout=[\n]  CamelExecCommandArgs after the call = (unset)
    
    Identical output, so the removal is a behavioural no-op. Its one
    observable effect was leaving a Camel-internal dispatch header set on
    the outgoing message, which now stops too.
    
    Control, same runtime, confirming the harness rather than a silent exec
    failure:
    
        CamelExecCommandArgs header -> stdout=[]
        exec:echo?args=URI-ARGS     -> stdout=[URI-ARGS]
    
    security-model.adoc cited this mapping as its example of "a Kamelet
    doing, by design, the dangerous thing it is named for", so that passage
    is corrected too. exec-sink still belongs in that list -- it runs
    `exec:{{executable}}` with an operator-bound executable -- it just no
    longer reads anything from the message.
    
    Signed-off-by: Andrea Cosentino <[email protected]>
    Co-authored-by: Claude Opus 5 <[email protected]>
---
 docs/modules/ROOT/pages/security-model.adoc                  | 12 ++++++------
 docs/modules/ROOT/partials/exec-sink-description.adoc        |  5 -----
 kamelets/exec-sink.kamelet.yaml                              | 12 ------------
 .../src/main/resources/kamelets/exec-sink.kamelet.yaml       | 12 ------------
 4 files changed, 6 insertions(+), 35 deletions(-)

diff --git a/docs/modules/ROOT/pages/security-model.adoc 
b/docs/modules/ROOT/pages/security-model.adoc
index 17e5e9ddb..f9ab5b195 100644
--- a/docs/modules/ROOT/pages/security-model.adoc
+++ b/docs/modules/ROOT/pages/security-model.adoc
@@ -301,12 +301,12 @@ such, with a reference to this page.
   operator-bound property. Wiring an untrusted source into that property is
   route-author error, exactly as in the Camel model.
 * *A Kamelet doing, by design, the dangerous thing it is named for.*
-  `exec-sink` ("Execute system commands") deliberately maps an inbound `args` /
-  `ce-args` header into `CamelExecCommandArgs` and runs `exec:{\{executable}}`;
-  `ssh-sink`, `scp-sink`, `ssh-source` run remote commands/transfers. Placing
-  such a Kamelet downstream of untrusted input is operator responsibility - the
-  behaviour is the Kamelet's documented contract, analogous to Camel's
-  "bean-based dispatch via internal headers is intentional" limitation.
+  `exec-sink` ("Execute system commands") runs `exec:{\{executable}}` with the
+  executable bound by the operator; `ssh-sink`, `scp-sink`, `ssh-source` run
+  remote commands/transfers. Placing such a Kamelet downstream of untrusted
+  input is operator responsibility - the behaviour is the Kamelet's documented
+  contract, analogous to Camel's "bean-based dispatch via internal headers is
+  intentional" limitation.
 * *Network exposure of a source Kamelet.* `webhook-source`, `http-source`,
   `http-secured-source` and similar open a `platform-http` listener. The 
catalog
   does not add authentication except where a Kamelet's name and properties say
diff --git a/docs/modules/ROOT/partials/exec-sink-description.adoc 
b/docs/modules/ROOT/partials/exec-sink-description.adoc
index fec2feb94..b581ce1fe 100644
--- a/docs/modules/ROOT/partials/exec-sink-description.adoc
+++ b/docs/modules/ROOT/partials/exec-sink-description.adoc
@@ -4,11 +4,6 @@
 
 This Kamelet executes system commands on the local machine. It requires an 
executable command to be specified.
 
-=== Optional Headers
-
-The Kamelet supports the following optional headers:
-- `args` / `ce-args`: Command line arguments to pass to the executable
-
 === Output
 
 The Kamelet returns the standard output (stdout) of the executed command as 
the response body.
diff --git a/kamelets/exec-sink.kamelet.yaml b/kamelets/exec-sink.kamelet.yaml
index bdcec5646..2c05c10dd 100644
--- a/kamelets/exec-sink.kamelet.yaml
+++ b/kamelets/exec-sink.kamelet.yaml
@@ -47,18 +47,6 @@ spec:
     from:
       uri: kamelet:source
       steps:
-      - choice:
-          when:
-          - simple: "${header[args]}"
-            steps:
-            - setHeader:
-                name: CamelExecCommandArgs
-                simple: "${header[args]}"
-          - simple: "${header[ce-args]}"
-            steps:
-            - setHeader:
-                name: CamelExecCommandArgs
-                simple: "${header[ce-args]}"
       - to:
           uri: "exec:{{executable}}"
       - setBody:
diff --git 
a/library/camel-kamelets/src/main/resources/kamelets/exec-sink.kamelet.yaml 
b/library/camel-kamelets/src/main/resources/kamelets/exec-sink.kamelet.yaml
index bdcec5646..2c05c10dd 100644
--- a/library/camel-kamelets/src/main/resources/kamelets/exec-sink.kamelet.yaml
+++ b/library/camel-kamelets/src/main/resources/kamelets/exec-sink.kamelet.yaml
@@ -47,18 +47,6 @@ spec:
     from:
       uri: kamelet:source
       steps:
-      - choice:
-          when:
-          - simple: "${header[args]}"
-            steps:
-            - setHeader:
-                name: CamelExecCommandArgs
-                simple: "${header[args]}"
-          - simple: "${header[ce-args]}"
-            steps:
-            - setHeader:
-                name: CamelExecCommandArgs
-                simple: "${header[ce-args]}"
       - to:
           uri: "exec:{{executable}}"
       - setBody:

Reply via email to