Notes on the POP3 implementation
================================

- LIST and UIDL are issued only once to get information about all mails

  Therefore, mpop has to keep information about every mail in memory. Currently,
  roughly 10 bytes plus the average length of an UID are required per mail on a 
  32 bit system. In most cases, less than 30 bytes are needed, so you can handle
  1000 mails in less than 30 KB, or 100000 mails in less than 3 MB.

  A malicious server can send a very big total number of mails in response to 
  the STAT command, which causes mpop to try to allocate very large amounts of 
  memory.

  This can cause the following:
  1) xmalloc() fails, mpop aborts.
  2) xmalloc() succeeds (for example on overcommitting OSes like Linux). The 
     next thing mpop does is issuing the LIST command to request the size of 
     each mail. Then two things can happen:
     a) The server is not able to deliver them all, mpop terminates.
     b) mpop tries to access much of the allocated memory and gets killed by the
        OOM killer.

  It would be possible to avoid this by limiting the total number of mails to 
  100000 and abort when STAT returns more, but since nothing dangerous can 
  happen, this is currently not done. 


- Pipelining can be used for TOP, RETR, and DELE.

  Pipelining works by sending up to pipeline_max commands to the server, then 
  begin to read its answers, and refill the command pipeline when the number of
  unanswered commands drops to pipeline_min.
  The default values can be found in the documentation. If you have problems
  with these defaults or find better values, please send a mail.
