I read the PR.

Indeed big bug.
The fix is indeed welcomed.
I made tiny comments to enhance it - mostly generalise fixes.-- 


Best regards,

Benoit TELLIER

General manager of Linagora VIETNAM.
Product owner for Twake-Mail product.
Chairman of the Apache James project.

Mail: [email protected]
Tel: (0033) 6 77 26 04 58 (WhatsApp, Signal)



Le sept. 28, 2026 10:20 AM, de Ilya Terskov <[email protected]>In the 
current master branch, BlobMailRepository.removeAll() invokes
mailMetaDataBlobStore.listBlobs() globally on the default bucket without
scoping it to the repository's path prefix.
Because of this, invoking removeAll() on repositoryA fetches metadata blobs
for all other repositories sharing the same bucket (e.g., repositoryB). The
subsequent internal calls to remove() decode these foreign metadata entries
and physically delete their corresponding MIME blobs from mimeMessageStore,
leading to cross-repository data loss.
The regression test removeAllShouldBeIsolatedAcrossRepositories() included
in this PR explicitly reproduces this scenario. It creates two repositories
(var/mail/error and var/mail/spam) in the same bucket. When
testeeA.removeAll() is executed, the assertions checking testeeB.size() and
testeeB.retrieve(keyB) fail on the master implementation (returning 0
instead of 1) and successfully pass with the fix introduced in this PR."

пн, 28 сент. 2026 г. в 15:11, Benoit TELLIER via server-dev <
[email protected]>:

> If we have a test showing that clearing mailRepositoryA also clear
> mailRepositoryB then this is a very valid finding.
>
> I personally do not use this component in prod. I rely on
> CassandraMailRepository.
> --
>
>
> Best regards,
>
> Benoit TELLIER
>
> General manager of Linagora VIETNAM.
> Product owner for Twake-Mail product.
> Chairman of the Apache James project.
>
> Mail: [email protected]
> Tel: (0033) 6 77 26 04 58 (WhatsApp, Signal)
>
>
>
> Le sept. 28, 2026 9:45 AM, de Ilya Terskov <[email protected]>looking
> for ur advice, its really that dangerous bug or false positive?
> github.com/apache/james-project/pull/3213
>

Reply via email to