fix(logstash source): close the connection on a malformed frame#25664
Merged
Conversation
A failed JSON decode or decompression was marked continuable (`can_continue() == true`), but the Lumberjack stream is length-prefixed binary with no resync marker. Continuing left the decoder desynchronized yet running: the uncompressed-JSON path never consumes the bad bytes (a CPU busy-loop) and the compressed path advances but keeps stale state, misframing subsequent bytes and emitting ACKs for bogus sequence numbers — surfacing as `invalid sequence number received` on the client. Treat every decode error as fatal (`can_continue() == false`) so the connection closes and the client reconnects (fresh decoder) and retransmits the unacknowledged window. This matches the upstream `logstash-input-beats` server, which closes the channel on any decode exception, and is at-least-once and safe. Adds decoder-level tests that malformed JSON and bad compression are fatal, and a socket-level test that a malformed frame closes the connection without sending an ACK. Also adds the missing authors line to the prior changelog fragment.
graphcareful
approved these changes
Jun 22, 2026
pront
approved these changes
Jun 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A failed JSON decode or decompression was marked continuable (
can_continue() == true), but the Lumberjack stream is length-prefixed binary with no resync marker. Continuing left the decoder desynchronized yet running: the uncompressed-JSON path never consumes the bad bytes (a CPU busy-loop) and the compressed path advances but keeps stale state, misframing subsequent bytes and emitting ACKs for bogus sequence numbers — surfacing asinvalid sequence number receivedon the client.Treat every decode error as fatal (
can_continue() == false) so the connection closes and the client reconnects (fresh decoder) and retransmits the unacknowledged window. This matches the upstreamlogstash-input-beatsserver, which closes the channel on any decode exception, and is at-least-once and safe.Adds decoder-level tests that malformed JSON and bad compression are fatal, and a socket-level test that a malformed frame closes the connection without sending an ACK. Also adds the missing authors line to the prior changelog fragment.
This was originally part of #25655 but I've broken it out here to simplify reviewing.
Vector configuration
How did you test this PR?
Unit tests are included
Change Type
Is this a breaking change?
Does this PR include user facing changes?
no-changeloglabel to this PR.References
Related: #25655
Notes
@vectordotdev/vectorto reach out to us regarding this PR.pre-pushhook, please see this template.make fmtmake check-clippy(if there are failures it's possible some of them can be fixed withmake clippy-fix)make testgit merge origin masterandgit push.Cargo.lock), pleaserun
make build-licensesto regenerate the license inventory and commit the changes (if any). More details on the dd-rust-license-tool.