]> dgit.raspbian.org Git - dovecot.git/commitdiff
[PATCH 06/14] lib-storage/mbox: Explicitly disable the header block size limit
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Sun, 19 Apr 2026 12:57:08 +0000 (15:57 +0300)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
mbox_sync_parse_next_mail() appends each header's raw bytes into
ctx->header and writes them back when rewriting the mbox file. The
default MESSAGE_HEADER_BLOCK_DEFAULT_MAX_SIZE limit (10 MB) must not
apply here: any truncation would corrupt the mbox on rewrite.
Similarly, mbox_sync_parse_match_mail() feeds full raw header bytes
into the MD5 verifier.

Today the per-chunk hdr->value delivered by message_parse_header_next()
is not clamped cumulatively, so the limit only bites on full_value and
unknown headers pass through intact. That is about to change - a
subsequent commit will clamp hdr->value cumulatively. Explicitly
setting SIZE_MAX here locks in the intent and prevents a regression.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Gbp-Pq: Name 0006-lib-storage-mbox-Explicitly-disable-the-header-block.patch

src/lib-storage/index/mbox/mbox-sync-parse.c

index 90f032a017f7d64e0e5d1e38d3f956d8774f9f2f..660e9b63d0ce2613d0f6df0c9d75b69711a08dbb 100644 (file)
@@ -479,6 +479,9 @@ int mbox_sync_parse_next_mail(struct istream *input,
 
         line_start_pos = 0;
        hdr_ctx = message_parse_header_init(input, NULL, 0);
+       /* Rewriting the mbox requires the full raw header bytes, so disable
+          the default per-header block size limit. */
+       message_parse_header_set_limit(hdr_ctx, SIZE_MAX);
        while ((ret = message_parse_header_next(hdr_ctx, &hdr)) > 0) {
                if (hdr->eoh) {
                        ctx->have_eoh = TRUE;
@@ -576,6 +579,8 @@ bool mbox_sync_parse_match_mail(struct mbox_mailbox *mbox,
         mbox_md5_ctx = mbox->md5_v.init();
 
        hdr_ctx = message_parse_header_init(mbox->mbox_stream, NULL, 0);
+       /* MD5 matching must see the full raw header bytes. */
+       message_parse_header_set_limit(hdr_ctx, SIZE_MAX);
        while ((ret = message_parse_header_next(hdr_ctx, &hdr)) > 0) {
                if (hdr->eoh)
                        break;