]> dgit.raspbian.org Git - dovecot.git/commit
[PATCH 10/14] lib-mail: Clamp hdr->value cumulatively against header_block_max_size
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Sun, 19 Apr 2026 21:16:14 +0000 (00:16 +0300)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
commitce70f4539a3a044d4a985ccbb53d117159e5384e
tree586e1d6afdf039d7eaa0d7442cb2e2482649bdc0
parent9b1e29260ec699bcd408bc49ae79c126f9f994d3
[PATCH 10/14] lib-mail: Clamp hdr->value cumulatively against header_block_max_size

Until now header_block_max_size only bounded hdr->full_value via
value_buf.  Continued chunks returned to the caller via hdr->value were
left at the raw chunk size, so a caller that consumed hdr->value per
chunk without ever requesting use_full_value (e.g. the header-cache
path in index_mail_parse_header()) could accumulate the full raw header
size.  A pathological To: with millions of addresses could grow
mail->header_data and the cache write buffer to tens of megabytes each,
driving the imap process over vsz_limit on FETCH ENVELOPE.

Reinterpret header_block_total_size as the running sum of line_value_size
across all chunks of all headers, and clamp each new chunk against the
remaining header_block_max_size budget. Propagate the clamped size to
line->value_len in the two continued-line branches that previously left
it untouched. value_buf is bounded implicitly since every append uses
line_value_size. The up-front per-chunk clamp
(line->value_len = MIN(value_len, max_size)) is now subsumed by the
cumulative clamp and has been removed.

Update the truncation tests that were documenting the old
"value_len stays at raw chunk size" behavior.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Gbp-Pq: Name 0010-lib-mail-Clamp-hdr-value-cumulatively-against-header.patch
src/lib-mail/message-header-parser.c
src/lib-mail/test-message-header-parser.c