BLOCKER: Notes IMAP does not apply its IP or User connection caps #786

Open
opened 2026-10-02 13:10:43 +00:00 by kayg · 1 comment
Owner

Protocol audit assigned under #663; source base c4a61e8cf0. Source review only; no hostile payload, live exploit or crash-threshold measurement. The owner rule blocks authorization holes and crash/DoS risks. No product code is changed by this audit.

Evidence: crates/calternal-server/src/notes_imap.rs:45–46 declares both
caps, with defaults of eight (:64–65). start reserves only the shared
global semaphore (:150, :179) before spawning a connection. connection
does not reserve a User permit after authentication. The SMTP implementation
does have IP and User permits in notes_submission.rs:26–42, :74, :128.

Impact: one source can consume the 64-slot global pool shared by IMAP and SMTP
without the advertised eight-connection IP bound. One authenticated User can
also consume it without the advertised User bound. Frame and handshake
deadlines reduce the duration, but do not enforce fairness or the configured
caps. Round-7a and committed mailproxy-486 retain this gap.

Repair: move the existing cap implementation to a shared listener boundary.
Share its registry across implicit IMAP, STARTTLS and SMTP. Hold the IP permit
through the handshake and socket lifetime, and hold a User permit from login
until disconnect. Reject saturation without queueing a task.

Regression coverage: small server-owned limits, each listener independently,
combined listeners, two synthetic IPs and Users, handshake failure, login
failure, IDLE, disconnect and permit release. Do not load-test the shared host.

Duplicate check: searched all issue states for XML depth, connection cap, SSE revocation and MCP session. Read related #457, #328, #329 and #668. No matching repair issue identified. Track the repair with source-level tests and a safe local validation of the repaired boundary. Do not close this issue from the audit job.

Protocol audit assigned under #663; source base c4a61e8cf090170f35b1bed3350d9de20c83ecd5. Source review only; no hostile payload, live exploit or crash-threshold measurement. The owner rule blocks authorization holes and crash/DoS risks. No product code is changed by this audit. Evidence: `crates/calternal-server/src/notes_imap.rs:45–46` declares both caps, with defaults of eight (`:64–65`). `start` reserves only the shared global semaphore (`:150`, `:179`) before spawning a connection. `connection` does not reserve a User permit after authentication. The SMTP implementation does have IP and User permits in `notes_submission.rs:26–42`, `:74`, `:128`. Impact: one source can consume the 64-slot global pool shared by IMAP and SMTP without the advertised eight-connection IP bound. One authenticated User can also consume it without the advertised User bound. Frame and handshake deadlines reduce the duration, but do not enforce fairness or the configured caps. Round-7a and committed mailproxy-486 retain this gap. Repair: move the existing cap implementation to a shared listener boundary. Share its registry across implicit IMAP, STARTTLS and SMTP. Hold the IP permit through the handshake and socket lifetime, and hold a User permit from login until disconnect. Reject saturation without queueing a task. Regression coverage: small server-owned limits, each listener independently, combined listeners, two synthetic IPs and Users, handshake failure, login failure, IDLE, disconnect and permit release. Do not load-test the shared host. Duplicate check: searched all issue states for XML depth, connection cap, SSE revocation and MCP session. Read related #457, #328, #329 and #668. No matching repair issue identified. Track the repair with source-level tests and a safe local validation of the repaired boundary. Do not close this issue from the audit job.
Author
Owner

SMTP had the only IP/User cap registry. It now shares one registry with implicit IMAP and STARTTLS. IP permits are reserved before spawn/handshake; User permits are reserved before the authenticated reply and retained for the session lifetime. Admission is non-waiting. Existing release/identity-retention test moved with the shared implementation.
Validation is in progress. No completion or live exploit claim.

SMTP had the only IP/User cap registry. It now shares one registry with implicit IMAP and STARTTLS. IP permits are reserved before spawn/handshake; User permits are reserved before the authenticated reply and retained for the session lifetime. Admission is non-waiting. Existing release/identity-retention test moved with the shared implementation. Validation is in progress. No completion or live exploit claim.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#786
No description provided.