fix(grok): apply the type converter declared in %{SYNTAX:semantic:type} - #116
Merged
Conversation
…pe}` (#108) `GrokMatcher` indexed the compiled patterns by their *syntax*, but looked them up by the name of the regex capture group, which is the *semantic* whenever one is defined. The lookup therefore always missed for named captures and the type silently fell back to `STRING`, so `%{NUMBER:n:int}` returned `"7"` instead of `7`. Index the patterns by the capture-group name they actually produce. Also: - leave empty captures (unmatched optional groups) unconverted, so they keep behaving as before with `keepEmptyCaptures`; - report a conversion failure as a `GrokException` naming the field and the target type instead of a bare Jackson error. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Contributor
📦 Artifacts
🛡 TrivyVulnerability in:
|
| Vulnerability | Severity | Package | Installed Version | Fixed Version |
|---|---|---|---|---|
| GHSA-r7wm-3cxj-wff9 | HIGH | com.fasterxml.jackson.core:jackson-core | 2.21.1 | 2.18.8, 2.21.4 |
| GHSA-r7wm-3cxj-wff9 | HIGH | com.fasterxml.jackson.core:jackson-core | 2.21.1 | 2.18.8, 2.21.4 |
| GHSA-r7wm-3cxj-wff9 | HIGH | com.fasterxml.jackson.core:jackson-core | 2.21.1 | 2.18.8, 2.21.4 |
| CVE-2026-54512 | HIGH | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.8, 3.1.4, 2.21.4 |
| CVE-2026-54512 | HIGH | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.8, 3.1.4, 2.21.4 |
| CVE-2026-54512 | HIGH | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.8, 3.1.4, 2.21.4 |
| CVE-2026-54513 | HIGH | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.8, 2.21.4, 3.1.4 |
| CVE-2026-54513 | HIGH | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.8, 2.21.4, 3.1.4 |
| CVE-2026-54513 | HIGH | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.8, 2.21.4, 3.1.4 |
| CVE-2026-54514 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.8, 2.21.4, 3.1.4 |
| CVE-2026-54514 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.8, 2.21.4, 3.1.4 |
| CVE-2026-54514 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.8, 2.21.4, 3.1.4 |
| CVE-2026-54515 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 3.1.4, 2.18.9, 2.21.5, 2.22.1 |
| CVE-2026-54515 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 3.1.4, 2.18.9, 2.21.5, 2.22.1 |
| CVE-2026-54515 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 3.1.4, 2.18.9, 2.21.5, 2.22.1 |
| CVE-2026-54516 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.21.4, 3.1.4 |
| CVE-2026-54516 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.21.4, 3.1.4 |
| CVE-2026-54516 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.21.4, 3.1.4 |
| CVE-2026-54517 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.21.4, 3.1.4 |
| CVE-2026-54517 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.21.4, 3.1.4 |
| CVE-2026-54517 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.21.4, 3.1.4 |
| CVE-2026-54518 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.21.4 |
| CVE-2026-54518 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.21.4 |
| CVE-2026-54518 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.21.4 |
| CVE-2026-59888 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.8, 2.21.4 |
| CVE-2026-59888 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.8, 2.21.4 |
| CVE-2026-59888 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.8, 2.21.4 |
| CVE-2026-59889 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.21.5, 2.18.9, 2.22.1 |
| CVE-2026-59889 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.21.5, 2.18.9, 2.22.1 |
| CVE-2026-59889 | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.21.5, 2.18.9, 2.22.1 |
| GHSA-mhm7-754m-9p8w | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.9, 2.21.5 |
| GHSA-mhm7-754m-9p8w | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.9, 2.21.5 |
| GHSA-mhm7-754m-9p8w | MEDIUM | com.fasterxml.jackson.core:jackson-databind | 2.21.1 | 2.18.9, 2.21.5 |
🧪 Java Unit Tests
| Tests | Passed ✅ | Skipped | Failed | Time ⏱ | |
|---|---|---|---|---|---|
| Java Tests Report | 164 ran | 163 ✅ | 1 | 0 ❌ | 54s 74ms |
🔁 Unreleased Commits
✅ No unreleased commits found.
Contributor
Tests report quick summary:success ✅ > tests: 164, success: 163, skipped: 1, failed: 0 unfold for details
|
fdelbrayelle
approved these changes
Sep 1, 2026
1 task
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #108
Problem
%{NUMBER:n:int}returned the string"7"instead of the number7, and the same applied to:float,:booleanand every other converter.%{NUMBER:n}gave an identical result, so the suffix had no effect at all.Root cause
GrokMatcherindexed the compiled patterns by their syntax (NUMBER), but looked them up by the name of the regex capture group — whichGrokPatternCompiler#compileRegexsets to the semantic (n) whenever one is defined. The lookup therefore missed for every named capture,patternwasnull, and the type silently fell back toSTRING.Fix
Index the patterns by the capture-group name they actually produce (
semanticwhen present, otherwisesyntax).Two follow-ons the fix exposed:
""; running it through the converter turned it into a Jackson-coercednull, changing whatkeepEmptyCaptures: truereturns. It now stays"", exactly as for untyped groups.%{WORD:w:int}onkestra) now throws aGrokExceptionnaming the field and the target type, instead of surfacing a bare Jackson error.Tests
5 new tests in
GrokMatcherTestand 2 inTransformValueTest— all fail before the fix, except the untyped control:%{NUMBER:n:int}on"7"→7short/int/long/float/double/boolean, plus an untyped field)%{NUMBER:n}still returns"7"GrokException""Full build green: 164 tests, 0 failures (1 pre-existing skip).
🤖 Generated with Claude Code