apache / apache/rocketmq

Avoid logging raw heartbeat sync message body

Open Beginner friendly
#10,726 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
22.6k
Forks
12k
Avg merge
3d 1h
Merged PRs (30d)
27

Description

## Problem

`HeartbeatSyncer.consumeMessage` logs the full `MessageExt` and raw message body when heartbeat sync message parsing or processing fails:

```java
log.error("heartbeat consume message failed. msg:{}, data:{}", msg, new String(msg.getBody(), StandardCharsets.UTF_8), t);
```

The body contains serialized heartbeat synchronization data, including client identity and subscription metadata. Logging the raw body is unnecessary for diagnostics and can expose operational metadata in proxy logs.

## Scope

Track 2 / Proxy runtime diagnostics hardening. This is a logging-safety change only; heartbeat sync behavior should remain unchanged.

## Expected behavior

- Do not log raw heartbeat sync message body on failure.
- Keep useful diagnostics such as topic, messageId, body size, and parsed heartbeat summary when available.
- Add targeted coverage for the summary helper so raw payload fields are not emitted.

## Evidence

- `proxy/src/main/java/org/apache/rocketmq/proxy/service/sysmessage/HeartbeatSyncer.java` logs `new String(msg.getBody(), StandardCharsets.UTF_8)` in the catch block.

Contributor guide

Open the contributing guide

Research direction

Start in proxy/src/main/java/org/apache/rocketmq/proxy/service/sysmessage/HeartbeatSyncer.java at HeartbeatSyncer.consumeMessage and inspect the failure logging path. Add targeted coverage for the summary helper, ensuring failures retain useful diagnostics without emitting raw heartbeat payload fields; heartbeat sync behavior should remain unchanged.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
backend, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
78/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.