[pfx] Re: cleanup(8): recipient_canonical can emit an over-long socketmap query with no operator guard; PERM then retried as 451

Wietse Venema via Postfix-users <[email protected]> Thu, 16 Jul 2026 07:49:39 -0400 (EDT)
Newsgroups gmane.mail.postfix.user
Message-ID <[email protected]>
Dmytro Alieksieiev:
> The negative pattern
> if !/(.{300})/
> /(.+)/ $1
> ENDIF
> 
> never rewrites the key. It returns the whole, unmodified string when it 
> is under the limit, and no result for anything at or above 300 bytes, at 
> which point pipemap short-circuits and the socketmap is never queried. 
> Because the key is never truncated, there is no encoding hazard 
> regardless of where a multibyte character sits. Side note: I changed 
> (.*) to (.+) as empty string result is not allowed in maps.

Good. It would make sense to implement a socketmap_max_query_size
feature that forces a "not found" result for long queries. This can
be a Postfix 3.12 feature.

An over-long envelope address can already be blocked with a
check_sender_access or check_recipient_access PCRE pattern:

    /.{300}/	REJECT address too long

Adding support for signaling a new type of database lookup error
remains future work.

	Wietse
_______________________________________________
Postfix-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]