Sending "XCLIENT FORWARD=AA==" (base64 for a single NUL byte) followed
by a regular login crashed pop3-login (and other login services) with:
Panic: file ../../src/lib/array.h: line 275 (array_idx_i):
assertion failed: (idx < array->buffer->used / array->element_size)
p_strsplit_tabescaped() truncates at the first NUL, so an all-NUL
payload produced an empty fields list. forward_fields was still
created (but empty), and the later array_front() call in
sasl_server_auth_begin() then panicked on the empty array.
Reject empty payloads and payloads containing NUL bytes during base64
decode, so the array is never created in this case.
Gbp-Pq: Name 0001-login-common-Fix-crash-when-XCLIENT-FORWARD-base64-c.patch
string_t *str = t_str_new(MAX_BASE64_DECODED_SIZE(value_len));
if (base64_decode(value, value_len, str) < 0)
return FALSE;
+ /* Embedded NUL would yield a created-but-empty array, panicking later
+ in array_front() during sasl_server_auth_begin(). */
+ if (str_len(str) == 0 ||
+ memchr(str_data(str), '\0', str_len(str)) != NULL)
+ return FALSE;
char **_fields = p_strsplit_tabescaped(client->preproxy_pool,
str_c(str));