email: bound the MIME walk and drop two copies of every body (V-581)
The MIME tree walk had no depth limit, and the nesting comes off the wire. A boundary line is a few bytes, so one message inside MaxMessageBytes can declare tens of thousands of multipart levels and pick the recursion depth of a daemon reading his mail. MaxMIMEDepth stops the walk at 12, well past the three levels real mail uses, and the headers still come through. ParseMessage converted the raw message to a string to read it, which copied up to 2 MiB per mail on a box already holding the resident model. It reads the bytes directly now. decodeCP1251 collected runes and then copied them into a string, four bytes a character for the whole body, and writes into a Builder instead. No behaviour change to what is read: EXAMINE and BODY.PEEK are still the only mailbox commands, and no credential reaches a log line. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,6 +1,7 @@
|
||||
package email
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
@@ -143,6 +144,24 @@ func TestParseTruncatesLongBody(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// Nesting depth comes off the wire, so a hostile message must not get to pick
|
||||
// the recursion depth. The walk stops and the headers still come through.
|
||||
func TestParseMessageBoundsMIMEDepth(t *testing.T) {
|
||||
var b strings.Builder
|
||||
b.WriteString("Subject: deep\r\nMIME-Version: 1.0\r\n")
|
||||
for i := 0; i < MaxMIMEDepth+20; i++ {
|
||||
fmt.Fprintf(&b, "Content-Type: multipart/mixed; boundary=\"b%d\"\r\n\r\n--b%d\r\n", i, i)
|
||||
}
|
||||
b.WriteString("Content-Type: text/plain\r\n\r\nглубоко\r\n")
|
||||
msg, err := ParseMessage(7, []byte(b.String()))
|
||||
if err != nil {
|
||||
t.Fatalf("ParseMessage: %v", err)
|
||||
}
|
||||
if msg.Subject != "deep" {
|
||||
t.Errorf("Subject = %q, want the headers to survive", msg.Subject)
|
||||
}
|
||||
}
|
||||
|
||||
func TestCollapseSqueezesBlankLines(t *testing.T) {
|
||||
got := collapse(" a b \r\n\r\n\r\n\r\n c \r\n")
|
||||
if got != "a b\n\nc" {
|
||||
|
||||
Reference in New Issue
Block a user