Harden required WASM parser boundaries for receive-only SMTP #17

Merged
ober merged 3 commits from fix/wasm-parser-boundaries into main 2026-09-19 16:45:52 -04:00
Owner

Required-WASM admission now rejects every DATA block above 64 KiB. Configuration, advertised SIZE, and network admission share that ceiling, so the network path cannot select host parsing or plaintext temporary-file spill. Larger mail requires a future bounded streaming WASM parser.

Command, DATA, and DNS wrappers serialize initialization, invocation, output copy, and shutdown with per-parser lifecycle mutexes. Guest output lengths are bounded before host reads, and all three decoders require exact packet consumption. Regression tests exercise malformed output, oversized valid DATA, and distinctive concurrent requests racing shutdown.

A target-discovered privilege-drop ABI bug is also fixed: setgroups receives numeric NULL instead of Scheme (void), with a non-mutating libc regression. The soak DATA fixture now includes its required From header. Docs mark root-launch chroot/path handling unsupported for this production profile; use a directly unprivileged service in an independently confined jail, omit run_uid/run_gid, and configure an absolute store_root.

Local macOS validation on c58f1f573c passed: native build/smoke; full verification including all tests, RustSec audit, SBOM, and clean-build reproducibility; explicit all-required-WASM encrypted delivery with 250 acceptance, store decryption using the local test key, no plaintext on disk, and 550 relay denial. Live oversized DATA received 552 without new spool files or a plaintext marker.

The sanitized candidate packet records 1,000 envelope sessions, DATA queueing, slow-DATA rejection, and 2,048 cargo-fuzz runs per SMTP command/DATA target. It was assembled from the immediately preceding successful verification. These are bounded local checks, not target confinement proof or sustained adversarial load evidence.

Public deployment still requires exact-artifact FreeBSD delivery/confinement/load evidence and human review. Stdio-only Capsicum is not process-wide confinement. Outbound TLS policy is unchanged; the receive-only profile disables outbound delivery. Version advances to 0.8.2.

Required-WASM admission now rejects every DATA block above 64 KiB. Configuration, advertised SIZE, and network admission share that ceiling, so the network path cannot select host parsing or plaintext temporary-file spill. Larger mail requires a future bounded streaming WASM parser. Command, DATA, and DNS wrappers serialize initialization, invocation, output copy, and shutdown with per-parser lifecycle mutexes. Guest output lengths are bounded before host reads, and all three decoders require exact packet consumption. Regression tests exercise malformed output, oversized valid DATA, and distinctive concurrent requests racing shutdown. A target-discovered privilege-drop ABI bug is also fixed: setgroups receives numeric NULL instead of Scheme (void), with a non-mutating libc regression. The soak DATA fixture now includes its required From header. Docs mark root-launch chroot/path handling unsupported for this production profile; use a directly unprivileged service in an independently confined jail, omit run_uid/run_gid, and configure an absolute store_root. Local macOS validation on c58f1f573cfa60c79fa3f58ae8348f405af680d8 passed: native build/smoke; full verification including all tests, RustSec audit, SBOM, and clean-build reproducibility; explicit all-required-WASM encrypted delivery with 250 acceptance, store decryption using the local test key, no plaintext on disk, and 550 relay denial. Live oversized DATA received 552 without new spool files or a plaintext marker. The sanitized candidate packet records 1,000 envelope sessions, DATA queueing, slow-DATA rejection, and 2,048 cargo-fuzz runs per SMTP command/DATA target. It was assembled from the immediately preceding successful verification. These are bounded local checks, not target confinement proof or sustained adversarial load evidence. Public deployment still requires exact-artifact FreeBSD delivery/confinement/load evidence and human review. Stdio-only Capsicum is not process-wide confinement. Outbound TLS policy is unchanged; the receive-only profile disables outbound delivery. Version advances to 0.8.2.
Harden required WASM parser admission and lifecycle boundaries
Some checks failed
version-policy / required (pull_request) Successful in 3m52s
required-ci / required (pull_request) Has been cancelled
f3d840db5a
Repair release soak DATA fixture required sender header
Some checks failed
version-policy / required (pull_request) Successful in 3m48s
required-ci / required (pull_request) Has been cancelled
b67e63aeb1
Pass numeric NULL to privilege-drop setgroups FFI
All checks were successful
version-policy / required (pull_request) Successful in 3m49s
required-ci / required (pull_request) Successful in 13m55s
c58f1f573c
ober merged commit bc7610d7f0 into main 2026-09-19 16:45:52 -04:00
ober referenced this pull request from a commit 2026-09-19 16:45:54 -04:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
ober/jerboa-smtp!17
No description provided.