In the current master branch, BlobMailRepository.removeAll() invokes mailMetaDataBlobStore.listBlobs() globally on the default bucket without scoping it to the repository's path prefix. Because of this, invoking removeAll() on repositoryA fetches metadata blobs for all other repositories sharing the same bucket (e.g., repositoryB). The subsequent internal calls to remove() decode these foreign metadata entries and physically delete their corresponding MIME blobs from mimeMessageStore, leading to cross-repository data loss. The regression test removeAllShouldBeIsolatedAcrossRepositories() included in this PR explicitly reproduces this scenario. It creates two repositories (var/mail/error and var/mail/spam) in the same bucket. When testeeA.removeAll() is executed, the assertions checking testeeB.size() and testeeB.retrieve(keyB) fail on the master implementation (returning 0 instead of 1) and successfully pass with the fix introduced in this PR."
пн, 28 сент. 2026 г. в 15:11, Benoit TELLIER via server-dev < [email protected]>: > If we have a test showing that clearing mailRepositoryA also clear > mailRepositoryB then this is a very valid finding. > > I personally do not use this component in prod. I rely on > CassandraMailRepository. > -- > > > Best regards, > > Benoit TELLIER > > General manager of Linagora VIETNAM. > Product owner for Twake-Mail product. > Chairman of the Apache James project. > > Mail: [email protected] > Tel: (0033) 6 77 26 04 58 (WhatsApp, Signal) > > > > Le sept. 28, 2026 9:45 AM, de Ilya Terskov <[email protected]>looking > for ur advice, its really that dangerous bug or false positive? > github.com/apache/james-project/pull/3213 >
