Harden required WASM parser boundaries for receive-only SMTP #17
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/wasm-parser-boundaries"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Required-WASM admission now rejects every DATA block above 64 KiB. Configuration, advertised SIZE, and network admission share that ceiling, so the network path cannot select host parsing or plaintext temporary-file spill. Larger mail requires a future bounded streaming WASM parser.
Command, DATA, and DNS wrappers serialize initialization, invocation, output copy, and shutdown with per-parser lifecycle mutexes. Guest output lengths are bounded before host reads, and all three decoders require exact packet consumption. Regression tests exercise malformed output, oversized valid DATA, and distinctive concurrent requests racing shutdown.
A target-discovered privilege-drop ABI bug is also fixed: setgroups receives numeric NULL instead of Scheme (void), with a non-mutating libc regression. The soak DATA fixture now includes its required From header. Docs mark root-launch chroot/path handling unsupported for this production profile; use a directly unprivileged service in an independently confined jail, omit run_uid/run_gid, and configure an absolute store_root.
Local macOS validation on
c58f1f573cpassed: native build/smoke; full verification including all tests, RustSec audit, SBOM, and clean-build reproducibility; explicit all-required-WASM encrypted delivery with 250 acceptance, store decryption using the local test key, no plaintext on disk, and 550 relay denial. Live oversized DATA received 552 without new spool files or a plaintext marker.The sanitized candidate packet records 1,000 envelope sessions, DATA queueing, slow-DATA rejection, and 2,048 cargo-fuzz runs per SMTP command/DATA target. It was assembled from the immediately preceding successful verification. These are bounded local checks, not target confinement proof or sustained adversarial load evidence.
Public deployment still requires exact-artifact FreeBSD delivery/confinement/load evidence and human review. Stdio-only Capsicum is not process-wide confinement. Outbound TLS policy is unchanged; the receive-only profile disables outbound delivery. Version advances to 0.8.2.