Apply MESSAGE_HEADER_BLOCK_DEFAULT_MAX_SIZE (10 MB) to the header-filter
istream used for populating the header cache. A pathological single
header (for example a To: with millions of addresses) otherwise grows
mail->header_data and the cache write buffer in lockstep with the raw
header size, which can push the imap process over vsz_limit on FETCH
ENVELOPE / BODYSTRUCTURE.
On its own this change does not yet bound hdr->value delivery; that
requires the upcoming change to message_parse_header_next() to clamp
per-chunk value_len cumulatively. Setting the limit here now lets that
follow-up take effect without further touching this file.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Gbp-Pq: Name 0009-lib-storage-Cap-per-header-size-in-index_mail_get_he.patch
HEADER_FILTER_HIDE_BODY,
headers->name, headers->count,
header_cache_callback, mail);
+ /* Cap per-header data so a single pathological header cannot exhaust
+ memory in mail->header_data / the filter's buffer. */
+ i_stream_header_filter_set_max_header_block_size(
+ mail->data.filter_stream,
+ MESSAGE_HEADER_BLOCK_DEFAULT_MAX_SIZE);
*stream_r = mail->data.filter_stream;
return 0;
}