added proper unit tests. Files: myflock.[hc], myflock_test.c,
wrap_fcntl.[hc], mock_fcntl.[hc].
+20260716
+
+ Feature: support for the "tls_sni" attribute in the SMTP
+ server policy delegation protocol, and for the "{tls_sni}"
+ macro in the Milter protocol. This also corrects a MILTER_README
+ table with macro availability (TLS-related macros are not
+ available in the EOH and EOM Milter protocol stages).
+ Contributed by Steve Short (fortra.com). Files:
+ MILTER_README.html, SMTPD_POLICY_README.html, mail_proto.h,
+ milter.h, test-milter.c, smtpd_check.c, smtpd_milter.c.
+
+ Cleanup: removed unused variables. Viktor Dukhovni. Files:
+ posttls-finger.c, tls_server.c.
+
+ Typofixes. Files: proto/stop, nbbio.c, dict_nisplus.c.
+
+ Feature: socketmap_max_query_size (default: 10000) limits
+ the length in bytes for a socketmap search key. A request
+ that exceeds the limit produces a warning and a 'not found'
+ result. Files: postlink, socketmap_table, dict_sockmap.[hc],
+ global/mail_params.[hc].
+
TODO
Reorganize PTEST_LIB, PMOCK_LIB, TESTLIB, TESTLIBS, etc.
| | |When address -> name |
| | |lookup fails: "unknown" |
|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b |
- |{cert_issuer} |HELO, MAIL, DATA, EOH, |TLS client certificate |
- | |EOM |issuer |
+ |{cert_issuer} |HELO, MAIL, DATA |TLS client certificate |
+ | | |issuer |
|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b |
- |{cert_subject} |HELO, MAIL, DATA, EOH, |TLS client certificate |
- | |EOM |subject |
+ |{cert_subject} |HELO, MAIL, DATA |TLS client certificate |
+ | | |subject |
|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b |
- |{cipher_bits} |HELO, MAIL, DATA, EOH, |TLS session key size |
- | |EOM | |
+ |{cipher_bits} |HELO, MAIL, DATA |TLS session key size |
|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b |
- |{cipher} |HELO, MAIL, DATA, EOH, |TLS cipher |
- | |EOM | |
+ |{cipher} |HELO, MAIL, DATA |TLS cipher |
|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b |
|{daemon_addr} |Always (Postfix >=3.2) |Local server IP address |
|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b |
| |only with smtpd_milters) |With rejected recipient: |
| | |"error" |
|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b |
- |{tls_version} |HELO, MAIL, DATA, EOH, |TLS protocol version |
- | |EOM | |
+ |{tls_sni} |HELO, MAIL, DATA (Postfix|TLS server name indication|
+ | |>=3.12) | |
+ |_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b |
+ |{tls_version} |HELO, MAIL, DATA |TLS protocol version |
|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b |
|v |Always |value of milter_macro_v |
|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b|_\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b _\b |
P\bPo\bos\bst\btf\bfi\bix\bx v\bve\ber\brs\bsi\bio\bon\bn 3\b3.\b.8\b8 a\ban\bnd\bd l\bla\bat\bte\ber\br:\b:
compatibility_level=major.minor.patch
mail_version=3.8.0
+ P\bPo\bos\bst\btf\bfi\bix\bx v\bve\ber\brs\bsi\bio\bon\bn 3\b3.\b.1\b12\b2 a\ban\bnd\bd l\bla\bat\bte\ber\br:\b:
+ tls_sni=mail.example.com
[empty line]
Notes:
about how the connection is encrypted. With plaintext connections the
protocol and cipher attributes are empty and the keysize is zero.
+ * The "tls_sni" attribute (Postfix 3.12 and later) specifies the server name
+ indication that the remote SMTP client sent in the TLS handshake. This
+ attribute is empty for plaintext connections and when the remote SMTP
+ client sends no SNI.
+
* The "etrn_domain" attribute is defined only in the context of the ETRN
command, and specifies the ETRN command parameter.
<td> Client name from address → name lookup <br> When address
→ name lookup fails: "unknown" </td> </tr>
-<tr> <td> {cert_issuer} </td> <td> HELO, MAIL, DATA, EOH, EOM </td> <td>
+<tr> <td> {cert_issuer} </td> <td> HELO, MAIL, DATA </td> <td>
TLS client certificate issuer </td> </tr>
-<tr> <td> {cert_subject} </td> <td> HELO, MAIL, DATA, EOH, EOM </td>
+<tr> <td> {cert_subject} </td> <td> HELO, MAIL, DATA </td>
<td> TLS client certificate subject </td> </tr>
-<tr> <td> {cipher_bits} </td> <td> HELO, MAIL, DATA, EOH, EOM </td> <td>
+<tr> <td> {cipher_bits} </td> <td> HELO, MAIL, DATA </td> <td>
TLS session key size </td> </tr>
-<tr> <td> {cipher} </td> <td> HELO, MAIL, DATA, EOH, EOM </td> <td> TLS
+<tr> <td> {cipher} </td> <td> HELO, MAIL, DATA </td> <td> TLS
cipher </td> </tr>
<tr> <td> {daemon_addr} </td> <td> Always (Postfix ≥3.2) </td>
<a href="postconf.5.html#smtpd_milters">smtpd_milters</a>) </td> <td> Recipient mail delivery transport <br>
With rejected recipient: "error" </td> </tr>
-<tr> <td> {tls_version} </td> <td> HELO, MAIL, DATA, EOH, EOM </td>
+<tr> <td> {tls_sni} </td> <td> HELO, MAIL, DATA (Postfix ≥3.12)
+</td> <td> TLS server name indication </td> </tr>
+
+<tr> <td> {tls_version} </td> <td> HELO, MAIL, DATA </td>
<td> TLS protocol version </td> </tr>
<tr> <td> v </td> <td> Always </td> <td> value of <a href="postconf.5.html#milter_macro_v">milter_macro_v</a>
<b>Postfix version 3.8 and later:</b>
<a href="postconf.5.html#compatibility_level">compatibility_level</a>=<i>major</i>.<i>minor</i>.<i>patch</i>
<a href="postconf.5.html#mail_version">mail_version</a>=3.8.0
+<b>Postfix version 3.12 and later:</b>
+tls_sni=mail.example.com
[empty line]
</pre>
</blockquote>
plaintext connections the protocol and cipher attributes are
empty and the keysize is zero. </p>
+ <li> <p> The "tls_sni" attribute (Postfix 3.12 and later)
+ specifies the server name indication that the remote SMTP client
+ sent in the TLS handshake. This attribute is empty for plaintext
+ connections and when the remote SMTP client sends no SNI. </p>
+
<li> <p> The "etrn_domain" attribute is defined only in the
context of the ETRN command, and specifies the ETRN command
parameter. </p>
<p> This feature is available in Postfix 3.0 and later. </p>
+</DD>
+
+<DT><b><a name="socketmap_max_query_size">socketmap_max_query_size</a>
+(default: 10000)</b></DT><DD>
+
+<p> The maximum allowed query size for a socketmap client, not
+including the socketmap and netstring encapsulation. A request that
+exceeds the limit generates a warning and a 'not found' result.
+</p>
+
+<p> This feature is available in Postfix ≥ 3.12. </p>
+
+
</DD>
<DT><b><a name="socketmap_max_reply_size">socketmap_max_reply_size</a>
can be changed with the <a href="postconf.5.html#socketmap_max_reply_size">socketmap_max_reply_size</a> configuration parame-
ter (Postfix 3.10 and later).
+ The Postfix socketmap client requires that queries are no longer than
+ 10000 bytes (not including the netstring encapsulation). This limit can
+ be changed with the <a href="postconf.5.html#socketmap_max_query_size">socketmap_max_query_size</a> configuration parameter
+ (Postfix 3.12 and later).
+
The Postfix socketmap client enforces a 100s time limit to connect to a
- socketmap server, to send a request, and to receive a reply. It closes
- an idle connection after 10s, and closes an active connection after
+ socketmap server, to send a request, and to receive a reply. It closes
+ an idle connection after 10s, and closes an active connection after
100s. These limits are not (yet) configurable.
<b><a name="security">SECURITY</a></b>
- This map cannot be used for security-sensitive information, because
+ This map cannot be used for security-sensitive information, because
neither the connection nor the server are authenticated.
<b><a name="configuration_parameters">CONFIGURATION PARAMETERS</a></b>
<b><a href="postconf.5.html#socketmap_max_reply_size">socketmap_max_reply_size</a> (100000)</b>
- The maximum allowed reply size from a socketmap server, not
+ The maximum allowed reply size from a socketmap server, not
including the netstring encapsulation.
<b><a name="see_also">SEE ALSO</a></b>
built to support these protocols.
.PP
This feature is available in Postfix 3.0 and later.
+.SH socketmap_max_query_size (default: 10000)
+The maximum allowed query size for a socketmap client, not
+including the socketmap and netstring encapsulation. A request that
+exceeds the limit generates a warning and a 'not found' result.
+.PP
+This feature is available in Postfix >= 3.12.
.SH socketmap_max_reply_size (default: 100000)
The maximum allowed reply size from a socketmap server, not
including the netstring encapsulation.
socketmap_max_reply_size configuration parameter (Postfix 3.10
and later).
+The Postfix socketmap client requires that queries are no longer
+than 10000 bytes (not including the netstring encapsulation). This
+limit can be changed with the socketmap_max_query_size
+configuration parameter (Postfix 3.12 and later).
+
The Postfix socketmap client enforces a 100s time limit to
connect to a socketmap server, to send a request, and to receive
a reply. It closes an idle connection after 10s, and closes
s;\bservice_name\b;<a href="postconf.5.html#service_name">$&</a>;g;
s;\bsocket[-</Bb>]*\n* *[<Bb>]*map_max_reply_size\b;<a href="postconf.5.html#socketmap_max_reply_size">$&</a>;g;
+ s;\bsocket[-</Bb>]*\n* *[<Bb>]*map_max_query_size\b;<a href="postconf.5.html#socketmap_max_query_size">$&</a>;g;
s;\bdefault_desti[-</Bb>]*\n* *[<Bb>]*na[-</Bb>]*\n* *[<Bb>]*tion_con[-</Bb>]*\n* *[<Bb>]*cur[-</Bb>]*\n* *[<Bb>]*rency_negative_feedback\b;<a href="postconf.5.html#default_destination_concurrency_negative_feedback">$&</a>;g;
s;\bdefault_desti[-</Bb>]*\n* *[<Bb>]*na[-</Bb>]*\n* *[<Bb>]*tion_con[-</Bb>]*\n* *[<Bb>]*cur[-</Bb>]*\n* *[<Bb>]*rency_positive_feedback\b;<a href="postconf.5.html#default_destination_concurrency_positive_feedback">$&</a>;g;
s;\bdefault_desti[-</Bb>]*\n* *[<Bb>]*na[-</Bb>]*\n* *[<Bb>]*tion_con[-</Bb>]*\n* *[<Bb>]*cur[-</Bb>]*\n* *[<Bb>]*rency_failed_cohort_limit\b;<a href="postconf.5.html#default_destination_concurrency_failed_cohort_limit">$&</a>;g;
<td> Client name from address → name lookup <br> When address
→ name lookup fails: "unknown" </td> </tr>
-<tr> <td> {cert_issuer} </td> <td> HELO, MAIL, DATA, EOH, EOM </td> <td>
+<tr> <td> {cert_issuer} </td> <td> HELO, MAIL, DATA </td> <td>
TLS client certificate issuer </td> </tr>
-<tr> <td> {cert_subject} </td> <td> HELO, MAIL, DATA, EOH, EOM </td>
+<tr> <td> {cert_subject} </td> <td> HELO, MAIL, DATA </td>
<td> TLS client certificate subject </td> </tr>
-<tr> <td> {cipher_bits} </td> <td> HELO, MAIL, DATA, EOH, EOM </td> <td>
+<tr> <td> {cipher_bits} </td> <td> HELO, MAIL, DATA </td> <td>
TLS session key size </td> </tr>
-<tr> <td> {cipher} </td> <td> HELO, MAIL, DATA, EOH, EOM </td> <td> TLS
+<tr> <td> {cipher} </td> <td> HELO, MAIL, DATA </td> <td> TLS
cipher </td> </tr>
<tr> <td> {daemon_addr} </td> <td> Always (Postfix ≥3.2) </td>
smtpd_milters) </td> <td> Recipient mail delivery transport <br>
With rejected recipient: "error" </td> </tr>
-<tr> <td> {tls_version} </td> <td> HELO, MAIL, DATA, EOH, EOM </td>
+<tr> <td> {tls_sni} </td> <td> HELO, MAIL, DATA (Postfix ≥3.12)
+</td> <td> TLS server name indication </td> </tr>
+
+<tr> <td> {tls_version} </td> <td> HELO, MAIL, DATA </td>
<td> TLS protocol version </td> </tr>
<tr> <td> v </td> <td> Always </td> <td> value of milter_macro_v
<b>Postfix version 3.8 and later:</b>
compatibility_level=<i>major</i>.<i>minor</i>.<i>patch</i>
mail_version=3.8.0
+<b>Postfix version 3.12 and later:</b>
+tls_sni=mail.example.com
[empty line]
</pre>
</blockquote>
plaintext connections the protocol and cipher attributes are
empty and the keysize is zero. </p>
+ <li> <p> The "tls_sni" attribute (Postfix 3.12 and later)
+ specifies the server name indication that the remote SMTP client
+ sent in the TLS handshake. This attribute is empty for plaintext
+ connections and when the remote SMTP client sends no SNI. </p>
+
<li> <p> The "etrn_domain" attribute is defined only in the
context of the ETRN command, and specifies the ETRN command
parameter. </p>
<p> This feature is available in Postfix ≥ 3.10. </p>
+%PARAM socketmap_max_query_size 10000
+
+<p> The maximum allowed query size for a socketmap client, not
+including the socketmap and netstring encapsulation. A request that
+exceeds the limit generates a warning and a 'not found' result.
+</p>
+
+<p> This feature is available in Postfix ≥ 3.12. </p>
+
%PARAM tls_required_enable yes
<p> Enable support for the "TLS-Required: no" message header, defined
# socketmap_max_reply_size configuration parameter (Postfix 3.10
# and later).
#
+# The Postfix socketmap client requires that queries are no longer
+# than 10000 bytes (not including the netstring encapsulation). This
+# limit can be changed with the socketmap_max_query_size
+# configuration parameter (Postfix 3.12 and later).
+#
# The Postfix socketmap client enforces a 100s time limit to
# connect to a socketmap server, to send a request, and to receive
# a reply. It closes an idle connection after 10s, and closes
yyyymmddhhmmss
ASAN
TristanInSec
+Mythos
+Qualys
+linkers
+strncmp
+DEV
+jitter
+msgfree
+optimizers
+resloop
+tokenized
bool var_oldlog_compat;
int var_delay_max_res;
int var_sockmap_max_reply;
+int var_sockmap_max_query;
char *var_int_filt_classes;
bool var_cyrus_sasl_authzid;
VAR_DELAY_MAX_RES, DEF_DELAY_MAX_RES, &var_delay_max_res, MIN_DELAY_MAX_RES, MAX_DELAY_MAX_RES,
VAR_INET_WINDOW, DEF_INET_WINDOW, &var_inet_windowsize, 0, 0,
VAR_SOCKMAP_MAX_REPLY, DEF_SOCKMAP_MAX_REPLY, &var_sockmap_max_reply, 1, 0,
+ VAR_SOCKMAP_MAX_QUERY, DEF_SOCKMAP_MAX_QUERY, &var_sockmap_max_query, 1, 0,
0,
};
static const CONFIG_LONG_TABLE long_defaults[] = {
dict_db_cache_size = var_db_read_buf;
dict_lmdb_map_size = var_lmdb_map_size;
dict_sockmap_max_reply = var_sockmap_max_reply;
+ dict_sockmap_max_query = var_sockmap_max_query;
inet_windowsize = var_inet_windowsize;
if (set_logwriter_create_perms(var_maillog_file_perms) < 0)
msg_warn("ignoring bad permissions: %s = %s",
#define DEF_SOCKMAP_MAX_REPLY 100000 /* reply size limit */
extern int var_sockmap_max_reply;
+#define VAR_SOCKMAP_MAX_QUERY "socketmap_max_query_size"
+#define DEF_SOCKMAP_MAX_QUERY 10000 /* query size limit */
+extern int var_sockmap_max_query;
+
/*
* Client privacy.
*/
#define MAIL_ATTR_CRYPTO_PROTOCOL "encryption_protocol"
#define MAIL_ATTR_CRYPTO_CIPHER "encryption_cipher"
#define MAIL_ATTR_CRYPTO_KEYSIZE "encryption_keysize"
+#define MAIL_ATTR_TLS_SNI "tls_sni"
#define MAIL_ATTR_COMPAT_LEVEL "compatibility_level"
#define MAIL_ATTR_MAIL_VERSION "mail_version"
* Patches change both the patchlevel and the release date. Snapshots have no
* patchlevel; they change the release date only.
*/
-#define MAIL_RELEASE_DATE "20260715"
+#define MAIL_RELEASE_DATE "20260716"
#define MAIL_VERSION_NUMBER "3.12"
#ifdef SNAPSHOT
#define S8_MAC_TLS_VERSION "{tls_version}"
#define S8_MAC_CIPHER "{cipher}"
#define S8_MAC_CIPHER_BITS "{cipher_bits}"
+#define S8_MAC_TLS_SNI "{tls_sni}"
#define S8_MAC_CERT_SUBJECT "{cert_subject}"
#define S8_MAC_CERT_ISSUER "{cert_issuer}"
"{rcpt_host}",
"{rcpt_mailer}",
"{tls_version}",
+ "{tls_sni}",
0,
};
static BIO *posttls_trace_open(void *arg, const char *trace_peer)
{
STATE *state = (STATE *) arg;
- struct timeval tv;
FILE *fp;
BIO *bio;
IF_ENCRYPTED(state->tls_context->cipher_name, "")),
SEND_ATTR_INT(MAIL_ATTR_CRYPTO_KEYSIZE,
IF_ENCRYPTED(state->tls_context->cipher_usebits, 0)),
+ SEND_ATTR_STR(MAIL_ATTR_TLS_SNI,
+ IF_ENCRYPTED(state->tls_context->peer_sni, "")),
#endif
SEND_ATTR_STR(MAIL_ATTR_POL_CONTEXT,
policy_clnt->policy_context),
IF_ENCRYPTED(state->tls_context->cipher_usebits));
return (STR(state->expand_buf));
}
+ if (strcmp(name, S8_MAC_TLS_SNI) == 0)
+ return (IF_ENCRYPTED(state->tls_context->peer_sni));
if (strcmp(name, S8_MAC_CERT_SUBJECT) == 0)
return (IF_TRUSTED(state->tls_context->peer_CN));
if (strcmp(name, S8_MAC_CERT_ISSUER) == 0)
TLS_APPL_STATE *tls_server_init(const TLS_SERVER_INIT_PROPS *props)
{
SSL_CTX *server_ctx;
- X509_STORE *cert_store;
long off = 0;
int verify_flags = SSL_VERIFY_NONE;
int cachable;
* is that the comma character is special in main.cf. When no column
* number is given at the end of the map name, we use a default column.
*
- * 2026506 Qualys+Mythos: enforce template substution syntax.
+ * 2026506 Qualys+Mythos: enforce template substitution syntax.
*/
if ((cp = strchr(map, '%')) == 0 || strncmp(cp, "%s", 2) != 0
|| strchr(cp + 2, '%') != 0)
*/
#define DICT_SOCKMAP_DEF_TIMEOUT 100 /* connect/read/write timeout */
#define DICT_SOCKMAP_DEF_MAX_REPLY 100000 /* reply size limit */
+#define DICT_SOCKMAP_DEF_MAX_QUERY 10000 /* query size limit */
#define DICT_SOCKMAP_DEF_MAX_IDLE 10 /* close idle socket */
#define DICT_SOCKMAP_DEF_MAX_TTL 100 /* close old socket */
*/
static int dict_sockmap_timeout = DICT_SOCKMAP_DEF_TIMEOUT;
int dict_sockmap_max_reply = DICT_SOCKMAP_DEF_MAX_REPLY;
+int dict_sockmap_max_query = DICT_SOCKMAP_DEF_MAX_QUERY;
static int dict_sockmap_max_idle = DICT_SOCKMAP_DEF_MAX_IDLE;
static int dict_sockmap_max_ttl = DICT_SOCKMAP_DEF_MAX_TTL;
if (msg_verbose)
msg_info("%s: key %s", myname, key);
+ /*
+ * Enforce the query size limit. As with UTF-8, an invalid key "does not
+ * exist".
+ */
+ if (dict_sockmap_max_query > 0 && strlen(key) > dict_sockmap_max_query) {
+ msg_warn("table %s:%s query too large: '%.100s', returning 'not found'",
+ dict->type, dict->name, key);
+ dict->error = 0;
+ return (0);
+ }
+
/*
* Optionally fold the key.
*/
extern DICT *dict_sockmap_open(const char *, int, int);
extern int dict_sockmap_max_reply;
+extern int dict_sockmap_max_query;
/* LICENSE
/* .ad
void nbbio_free(NBBIO *np)
{
nbbio_disable_readwrite(np);
- /* 202606 Qualys+Mythos: close decriptor only if owner. */
+ /* 202606 Qualys+Mythos: close descriptor only if owner. */
if (np->flags & NBBIO_FLAG_OWN_FD)
(void) close(np->fd);
myfree(np->label);