ppkarwasz opened a new issue, #4333:
URL: https://github.com/apache/logging-log4j2/issues/4333

   `DatagramOutputStream#copy` allocates a new array of exactly the accumulated 
length and copies the previous contents on every `write()` call. The encoder 
writes a formatted event in chunks of `Constants.ENCODER_BYTE_BUFFER_SIZE` (8 
KiB), so accumulating an event of n bytes before `flush()` sends the datagram 
costs O(n²): a benchmark writing a single value in 8 KiB chunks takes 0.15 s 
for 8 MB, 6 s for 64 MB and 99 s for 256 MB, quadrupling each time the payload 
doubles.
   
   In practice the effect is bounded: `protocol="UDP"` forces `immediateFlush`, 
so the accumulator is reset after every event, and `DatagramSocket#send` 
rejects payloads above 65,507 bytes, so a deliverable event needs at most eight 
copies. Events larger than that already fail at send time. This is therefore a 
performance and code-quality bug, not a security issue; it originates from a 
private security report classified as a bug.
   
   Proposal: back the accumulator with a growable buffer 
(`ByteArrayOutputStream` or a manually doubled array), and reject an 
accumulated payload above the maximum datagram size in `flush()` with a 
`StatusLogger` warning instead of letting `send()` fail.
   
   Reported by @August829
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to