]> dgit.raspbian.org Git - dovecot.git/commitdiff
[PATCH 09/14] lib-storage: Cap per-header size in index_mail_get_header_stream()
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Sun, 19 Apr 2026 15:28:16 +0000 (18:28 +0300)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
Apply MESSAGE_HEADER_BLOCK_DEFAULT_MAX_SIZE (10 MB) to the header-filter
istream used for populating the header cache. A pathological single
header (for example a To: with millions of addresses) otherwise grows
mail->header_data and the cache write buffer in lockstep with the raw
header size, which can push the imap process over vsz_limit on FETCH
ENVELOPE / BODYSTRUCTURE.

On its own this change does not yet bound hdr->value delivery; that
requires the upcoming change to message_parse_header_next() to clamp
per-chunk value_len cumulatively. Setting the limit here now lets that
follow-up take effect without further touching this file.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Gbp-Pq: Name 0009-lib-storage-Cap-per-header-size-in-index_mail_get_he.patch

src/lib-storage/index/index-mail-headers.c

index 18c922239daa154cf682b035926334f1362e300c..a9f4d55c0d36cd3f5fefce0f51fd584cdf847c30 100644 (file)
@@ -992,6 +992,11 @@ int index_mail_get_header_stream(struct mail *_mail,
                                              HEADER_FILTER_HIDE_BODY,
                                              headers->name, headers->count,
                                              header_cache_callback, mail);
+       /* Cap per-header data so a single pathological header cannot exhaust
+          memory in mail->header_data / the filter's buffer. */
+       i_stream_header_filter_set_max_header_block_size(
+               mail->data.filter_stream,
+               MESSAGE_HEADER_BLOCK_DEFAULT_MAX_SIZE);
        *stream_r = mail->data.filter_stream;
        return 0;
 }