allthingssecurity opened a new pull request, #27125:
URL: https://github.com/apache/camel/pull/27125

   # Description
   
   [CAMEL-25179](https://issues.apache.org/jira/browse/CAMEL-25179)
   
   `CryptoDataFormat` appends an HMAC by default (`shouldAppendHMAC=true`). On 
unmarshal, `HMACAccumulator.decryptUpdate` holds back the last `maclength` 
bytes in a `CircularBuffer` of `bufferSize + maclength` bytes. Both `write` and 
`read` of that buffer get the wrap-around at the end of the array wrong:
   
   - `write`: `int overlap = write + len % buffer.length;` makes the first 
`arraycopy` length `-write`, so every write that has to wrap throws (it also 
copies from offset 0 instead of `pos`).
   - `read`: with the read position behind the write position it copies 
`buffer.length - read` bytes instead of `len`, and it never wraps when `read <= 
write`.
   
   `CipherInputStream` hands the decrypted data out in chunks, so the buffer 
wraps as soon as a message is larger than `bufferSize`. With the default 
options every unmarshal of 4096 bytes or more fails:
   
   ```
   java.lang.ArrayIndexOutOfBoundsException: arraycopy: length -4088 is negative
       at 
org.apache.camel.converter.crypto.HMACAccumulator$CircularBuffer.write(HMACAccumulator.java:138)
       at 
org.apache.camel.converter.crypto.HMACAccumulator.decryptUpdate(HMACAccumulator.java:71)
       at 
org.apache.camel.converter.crypto.CryptoDataFormat.unmarshal(CryptoDataFormat.java:197)
   ```
   
   The code is from the original contribution (CAMEL-2482); the existing tests 
use a 49 byte payload, and `HMACAccumulatorTest` never wraps the buffer.
   
   This change: both methods copy `min(len, buffer.length - position)` bytes up 
to the end of the array and the rest from/to its start. The message format is 
unchanged (marshal is not touched), so messages written by earlier versions 
still unmarshal, and the MAC is computed and compared over the same bytes as 
before. No upgrade guide entry, as nothing changes for messages that worked 
before.
   
   Tests:
   - `CryptoDataFormatLargePayloadTest` (new): marshal and unmarshal round 
trips of 100, 4096, 5000 and 100000 bytes with `new CryptoDataFormat("DES", 
key)` and the default options.
   - `HMACAccumulatorTest`: `testBufferWriteWrapsAround` and 
`testBufferReadBehindWritePosition` for the two `CircularBuffer` cases, and 
`testDecryptionWhereDataWrapsAroundBuffer` (1000 bytes plus the MAC fed to the 
accumulator in 24 byte chunks with a 64 byte buffer).
   - Without the fix, 6 of the new tests fail with 
`ArrayIndexOutOfBoundsException` (the 4096, 5000 and 100000 byte round trips 
and the three `HMACAccumulatorTest` tests); the 100 byte round trip passes.
   - With the fix, all camel-crypto tests pass: 84 tests, 0 failures.
   
   # Target
   
   - [x] I checked that the commit is targeting the correct branch (Camel 4 
uses the `main` branch)
   
   # Tracking
   - [x] If this is a large change, bug fix, or code improvement, I checked 
there is a [JIRA issue](https://issues.apache.org/jira/browse/CAMEL) filed for 
the change (usually before you start working on it).
   
   # Apache Camel coding standards and style
   
   - [x] I checked that each commit in the pull request has a meaningful 
subject line and body.
   - [ ] I have run `mvn clean install -DskipTests` locally from root folder 
and I have committed all auto-generated changes.
     (I built and tested the affected module, including the formatter and 
import-sort plugins. I did not run the full root build.)
   
   # AI-assisted contributions
   
   - [x] If this PR includes AI-generated code, commits have proper 
co-authorship attribution (e.g., `Co-authored-by` trailers) and the PR 
description identifies the AI tool used.
     This PR was prepared with Claude Code (Claude Opus 5.5). The commit 
carries a `Co-Authored-By` trailer.
   
   _Claude Code on behalf of allthingssecurity_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to