From: Timo Sirainen Date: Sun, 19 Apr 2026 15:28:16 +0000 (+0300) Subject: [PATCH 09/14] lib-storage: Cap per-header size in index_mail_get_header_stream() X-Git-Tag: archive/raspbian/1%2.4.1+dfsg1-6+rpi1+deb13u7^2~55 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=9b1e29260ec699bcd408bc49ae79c126f9f994d3;p=dovecot.git [PATCH 09/14] lib-storage: Cap per-header size in index_mail_get_header_stream() Apply MESSAGE_HEADER_BLOCK_DEFAULT_MAX_SIZE (10 MB) to the header-filter istream used for populating the header cache. A pathological single header (for example a To: with millions of addresses) otherwise grows mail->header_data and the cache write buffer in lockstep with the raw header size, which can push the imap process over vsz_limit on FETCH ENVELOPE / BODYSTRUCTURE. On its own this change does not yet bound hdr->value delivery; that requires the upcoming change to message_parse_header_next() to clamp per-chunk value_len cumulatively. Setting the limit here now lets that follow-up take effect without further touching this file. Co-Authored-By: Claude Opus 4.7 (1M context) Gbp-Pq: Name 0009-lib-storage-Cap-per-header-size-in-index_mail_get_he.patch --- diff --git a/src/lib-storage/index/index-mail-headers.c b/src/lib-storage/index/index-mail-headers.c index 18c9222..a9f4d55 100644 --- a/src/lib-storage/index/index-mail-headers.c +++ b/src/lib-storage/index/index-mail-headers.c @@ -992,6 +992,11 @@ int index_mail_get_header_stream(struct mail *_mail, HEADER_FILTER_HIDE_BODY, headers->name, headers->count, header_cache_callback, mail); + /* Cap per-header data so a single pathological header cannot exhaust + memory in mail->header_data / the filter's buffer. */ + i_stream_header_filter_set_max_header_block_size( + mail->data.filter_stream, + MESSAGE_HEADER_BLOCK_DEFAULT_MAX_SIZE); *stream_r = mail->data.filter_stream; return 0; }