SECURITY: Mail failure logs must exclude provider response text and bytes #733

Open
opened 2026-10-02 13:06:52 +00:00 by kayg · 2 comments
Owner

Defensive sec-admin-deploy audit, assigned through #663.

Source: origin/dev c4a61e8cf0.
Also present in origin/job/merge-round-7a. Source review only; no production access or exploit execution.

  1. Mail command failures write provider text to logs.
    crates/plugins/mail/src/sync.rs:214 and :1222 log the first 300
    characters of a dependency error. A length limit does not remove private
    values. The resolved async-imap 0.11.3 error types include provider text
    in No(String) and Bad(String), and raw response bytes in
    ParseError::DataNotUtf8. The claim in the comment that these strings
    contain no private data is not an invariant of those types. Log a static
    error class and the static step instead. Test log capture with synthetic
    provider errors; verify no response text or bytes reach the log.

Fix acceptance: add the tests described above, run touched-crate gates, and verify no secrets appear in reports.

Defensive sec-admin-deploy audit, assigned through #663. Source: origin/dev c4a61e8cf090170f35b1bed3350d9de20c83ecd5. Also present in origin/job/merge-round-7a. Source review only; no production access or exploit execution. 2. **Mail command failures write provider text to logs.** `crates/plugins/mail/src/sync.rs:214` and `:1222` log the first 300 characters of a dependency error. A length limit does not remove private values. The resolved async-imap 0.11.3 error types include provider text in `No(String)` and `Bad(String)`, and raw response bytes in `ParseError::DataNotUtf8`. The claim in the comment that these strings contain no private data is not an invariant of those types. Log a static error class and the static step instead. Test log capture with synthetic provider errors; verify no response text or bytes reach the log. Fix acceptance: add the tests described above, run touched-crate gates, and verify no secrets appear in reports.
Author
Owner

Additional source evidence: Mail resolves async-imap from crates/plugins/mail/vendor/async-imap (not the registry copy). The vendored client.rs:1513-1514 still formats provider code and information into Error::Bad/No; parse.rs:141-144 does the same. command() in sync.rs:1220-1223 logs that Display text. The patch removes wire traces and fixes tagged FETCH errors, but does not cover these command-result paths. These constructors also remain in merge-round-7a and job/imaptest-625. No provider traffic was sent.

Additional source evidence: Mail resolves async-imap from crates/plugins/mail/vendor/async-imap (not the registry copy). The vendored client.rs:1513-1514 still formats provider code and information into Error::Bad/No; parse.rs:141-144 does the same. command() in sync.rs:1220-1223 logs that Display text. The patch removes wire traces and fixes tagged FETCH errors, but does not cover these command-result paths. These constructors also remain in merge-round-7a and job/imaptest-625. No provider traffic was sent.
Author
Owner

#733 finding and fix in progress: sync.rs formatted async-imap errors, whose No/Bad variants carry provider text and whose UTF-8 parse variant carries raw bytes. Mail command logs now use fixed error classes plus only the NO/BAD status word, and cache-step logs retain only a static step and storage class. The Mail capture regression includes synthetic provider text, malformed bytes and a synthetic cache error. The broader Mail/Calendar/DAV audit also removed raw SQL error formatting and raw Calendar feed User-Agent text from logs. Crate gates are pending.

#733 finding and fix in progress: `sync.rs` formatted `async-imap` errors, whose `No`/`Bad` variants carry provider text and whose UTF-8 parse variant carries raw bytes. Mail command logs now use fixed error classes plus only the `NO`/`BAD` status word, and cache-step logs retain only a static step and `storage` class. The Mail capture regression includes synthetic provider text, malformed bytes and a synthetic cache error. The broader Mail/Calendar/DAV audit also removed raw SQL error formatting and raw Calendar feed User-Agent text from logs. Crate gates are pending.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#733
No description provided.