fix: bound JMAP pre-auth connections #27

Merged
ober merged 1 commit from fix/astra-jmap-resource-limits into main 2026-09-23 18:04:09 -04:00
Owner

Problem

JMAP accepted allowlisted status only after TLS setup and request parsing. The configured max_connections value was used as the listen backlog while pre-auth workers had no per-peer cap or bounded TLS/socket I/O. Native TLS close could also contend with a blocked read and race descriptor reuse.

Changes

  • Reject disallowed peers immediately after accept, before TLS state or worker creation.
  • Enforce global and per-IP active worker caps with exact release accounting.
  • Apply bounded native socket read/write timeouts to handshake, request, and response I/O.
  • Add mutex-independent TLS abort using an independently owned duplicated socket descriptor.
  • Shut down the transport before removing the native connection entry.
  • Add allowlist regression coverage.
  • Stop cached DB actors before init-db! opens raw connections, fixing test and maintenance reset races.
  • Bump VERSION and jpkg.sexp to 0.2.32.

Verification

  • make test — all Scheme tests pass.
  • make verify — security gates, Scheme tests, native Rust tests, Android native tests, build, and e2e pass.
  • make binary passes.
  • ./jjmapd --help passes.
  • ./support/e2e-local.sh passes.
  • Native Rust tests: 9 passed; Android native tests: 6 passed.

The generated jjmapd and FFI symbol list are included because this repository tracks the executable release artifact.

## Problem JMAP accepted allowlisted status only after TLS setup and request parsing. The configured `max_connections` value was used as the listen backlog while pre-auth workers had no per-peer cap or bounded TLS/socket I/O. Native TLS close could also contend with a blocked read and race descriptor reuse. ## Changes - Reject disallowed peers immediately after accept, before TLS state or worker creation. - Enforce global and per-IP active worker caps with exact release accounting. - Apply bounded native socket read/write timeouts to handshake, request, and response I/O. - Add mutex-independent TLS abort using an independently owned duplicated socket descriptor. - Shut down the transport before removing the native connection entry. - Add allowlist regression coverage. - Stop cached DB actors before `init-db!` opens raw connections, fixing test and maintenance reset races. - Bump `VERSION` and `jpkg.sexp` to `0.2.32`. ## Verification - `make test` — all Scheme tests pass. - `make verify` — security gates, Scheme tests, native Rust tests, Android native tests, build, and e2e pass. - `make binary` passes. - `./jjmapd --help` passes. - `./support/e2e-local.sh` passes. - Native Rust tests: 9 passed; Android native tests: 6 passed. The generated `jjmapd` and FFI symbol list are included because this repository tracks the executable release artifact.
fix: bound JMAP pre-auth connections
All checks were successful
version-policy / required (pull_request) Successful in 4m53s
required-ci / required (pull_request) Successful in 12m40s
715fd85f01
ober scheduled this pull request to auto merge when all checks succeed 2026-09-23 18:03:37 -04:00
ober merged commit 2c7c4e556d into main 2026-09-23 18:04:09 -04:00
ober referenced this pull request from a commit 2026-09-23 18:04:10 -04:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa-jmap!27
No description provided.