davsclaus commented on code in PR #27036:
URL: https://github.com/apache/camel/pull/27036#discussion_r4130731538
##########
components/camel-syslog/src/main/java/org/apache/camel/component/syslog/SyslogConverter.java:
##########
@@ -224,32 +227,47 @@ public static SyslogMessage parseMessage(byte[] bytes) {
if (isRfc5424) {
Rfc5424SyslogMessage rfc5424SyslogMessage = (Rfc5424SyslogMessage)
syslogMessage;
StringBuilder appName = new StringBuilder();
- while ((charFound = (char) (byteBuffer.get() & 0xff)) != ' ') {
+ while (byteBuffer.hasRemaining() && (charFound = (char)
(byteBuffer.get() & 0xff)) != ' ') {
appName.append(charFound);
}
rfc5424SyslogMessage.setAppName(appName.toString());
StringBuilder procId = new StringBuilder();
- while ((charFound = (char) (byteBuffer.get() & 0xff)) != ' ') {
+ while (byteBuffer.hasRemaining() && (charFound = (char)
(byteBuffer.get() & 0xff)) != ' ') {
procId.append(charFound);
}
rfc5424SyslogMessage.setProcId(procId.toString());
StringBuilder msgId = new StringBuilder();
- while ((charFound = (char) (byteBuffer.get() & 0xff)) != ' ') {
+ while (byteBuffer.hasRemaining() && (charFound = (char)
(byteBuffer.get() & 0xff)) != ' ') {
msgId.append(charFound);
}
rfc5424SyslogMessage.setMsgId(msgId.toString());
+ // STRUCTURED-DATA is the NILVALUE or SD-ELEMENTs (RFC 5424 6.3).
A PARAM-VALUE is quoted, and escapes
+ // '"', '\' and ']' with a backslash, so a ']' only closes the
element outside a PARAM-VALUE
StringBuilder structuredData = new StringBuilder();
boolean inblock = false;
- while ((charFound = (char) (byteBuffer.get() & 0xff)) != ' ' ||
inblock) {
- if (charFound == '[') {
+ boolean inValue = false;
+ boolean escaped = false;
+ char previous = 0;
+ while (byteBuffer.hasRemaining() && ((charFound = (char)
(byteBuffer.get() & 0xff)) != ' ' || inblock)) {
+ if (inValue) {
+ if (escaped) {
+ escaped = false;
+ } else if (charFound == '\\') {
+ escaped = true;
+ } else if (charFound == '"') {
+ inValue = false;
+ }
+ } else if (charFound == '[') {
inblock = true;
- }
- if (charFound == ']') {
+ } else if (charFound == ']') {
inblock = false;
+ } else if (charFound == '"' && inblock && previous == '=') {
+ inValue = true;
Review Comment:
Non-blocking: for malformed input with an unterminated quoted value, e.g.
`[id a="x] hello`, `inValue` never resets, so the rest of the message goes into
the structured data and MSG comes out empty. Before, the element closed at `]`.
This is invalid input so I'm fine with the new behaviour, but could you add a
test that pins it down, so it is a documented choice rather than an accident?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]