Repository navigation
Conversation
Customer (~180K/day) hits repeated IllegalArgumentException from Functions.BASE64_DECODE when a Kafka producer sends non-Base64 header values, paying full stack-trace fill-in on every throw. Adds a guarded decode path (GuardedBase64Decode) that fast-fails with a stack-trace-free exception once a real failure is seen, with hysteresis to re-check after a run of valid input, wired behind a new kafka.client.base64.decoding.guard.enabled config flag (default true). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This comment has been minimized.
This comment has been minimized.
🟢 Java Benchmark SLOs — All performance SLOs passed
PR vs. master results
Commit: Load and DaCapo benchmarks can be triggered manually in the GitLab pipeline. Results will appear in the Benchmarking Platform UI after completion. |
Kafka / producer-benchmarkParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 3 metrics, 0 unstable metrics. See unchanged results
|
Kafka / consumer-benchmarkParameters
See matching parameters
SummaryFound 0 performance improvements and 0 performance regressions! Performance is the same for 3 metrics, 0 unstable metrics. See unchanged results
|
|
Closing in favor of #12672, which now carries this fix built on a shared It also fixes a bug in this version's pre-check: it treated any input whose length is not a multiple of 4 (and empty input) as invalid, but |
Summary
Functions.BASE64_DECODEthrows and catches anIllegalArgumentExceptionfor every malformed (non-Base64) Kafka header value from a mixed/misbehaving producer, paying full stack-trace fill-in on every throw.Functions.GuardedBase64Decode: after a real decode failure, a cheap alphabet-scan precheck opens a hysteresis window (CLOSE_THRESHOLD = 20successful decodes to close) during which further malformed input fast-fails via a stack-trace-freeDefinitelyNotBase64Exceptioninstead of hitting the JDK decoder's exception path.TextMapExtractAdapterimplementations (kafka-clients-0.11, kafka-clients-3.8) behind a new config flagkafka.client.base64.decoding.guard.enabled(defaulttrue), so it can be disabled if needed.Test plan
GuardedBase64DecodeTest(JUnit 5) covers: valid decode, real exception when unguarded, fast-fail stand-in while guarded, valid decode still works while guarded, guard closes after enough successful decodes,decodeOrNullvariants.TextMapExtractAdapterTest.groovy/ Kafka forked tests pass unchanged./techdebtreview: no findings./perf-review: no findings — confirmed bounded added work (precheck only runs while guard is open) and no new per-call allocation beyond the existing decode path.🤖 Generated with Claude Code