Commit Graph
70 Commits
Author SHA1 Message Date
jcoffey-dev 4ce772d6e5 http: a way to send a write that must not be applied twice
A POST that failed in transport -- including a timeout while waiting for the
answer -- is resent today, and so is one that got a 502 or 504. For a write
such as Email/import the server may already have applied the first copy,
so the resend can create a duplicate.

post_json_once and Request::send_once send it once: a transport failure or
a gateway error comes back to the caller, which can check the target before
trying again. 429 and 503, which mean the request was not processed, are
still retried.
2026-09-30 12:39:57 -07:00
jcoffey-dev 97d126fbfa Merge pull request 'export: bring matched items up to date on every run' (#7) from feat/export-updates into main
ci / test (push) Skipped
github/ci (branch) GitHub Actions
ci / github (push) Successful in 2m30s
ci / announce (push) Skipped
2026-09-30 18:40:48 +00:00
jcoffey-dev 687027c7cb export: bring matched items up to date on every run
ci / test (pull_request) Skipped
github/ci (branch) GitHub Actions
ci / github (pull_request) Successful in 2m50s
ci / announce (pull_request) Skipped
Export matched each item against the target and then skipped it, so a second
run -- the usual final pass of a cutover -- never carried anything that had
changed at the source since the first: read and flagged state, moves between
folders, edited contacts, events and Sieve scripts. It reported them as
skipped and exited 0, while the usage guide said matched items were updated.

Matched items are now updated, with one batched /set per type:

- Email: keywords are set to the archive's, added and removed, compared
  case-insensitively. Memberships of folders this run migrated are added and
  removed to match; folders that exist only on the target are left alone,
  and a message is never left in no folder. Properties the server did not
  report are not touched.
- Contacts and events: when both copies carry `updated`, the archive's is
  written only if it is newer, compared as instants so an offset or a
  fraction of a second is not taken for a change; otherwise each property the
  archive writes is compared, and those that differ are sent whole.
- Sieve scripts: the target's copy is downloaded and compared byte for byte
  with what export would write -- after renaming Stalwart's vendor names for
  an inbuxa target -- and replaced when it differs, so a renamed script is
  not re-uploaded on every run.

Updated items are counted as `updated`; unchanged ones stay `skipped`. The
usage guide now describes this.
2026-09-30 11:37:39 -07:00
jcoffey-dev 14a797cd65 Merge pull request 'Time out every connection, and scope --allow-invalid-certs' (#6) from fix/connection-safety into main
ci / test (push) Skipped
github/ci (branch) GitHub Actions
ci / github (push) Successful in 3m31s
ci / announce (push) Skipped
2026-09-30 18:34:50 +00:00
jcoffey-dev 01ac1a5b3e Merge pull request 'export: write a message once, in every folder it was in' (#4) from fix/one-message-many-folders into main
ci / test (push) Skipped
github/ci (branch) GitHub Actions
ci / github (push) Canceled after 1m36s
ci / announce (push) Canceled after 0s
2026-09-30 18:33:09 +00:00
jcoffey-dev 234b3203d7 Scope --allow-invalid-certs to the server the user named
ci / test (pull_request) Skipped
github/ci (branch) GitHub Actions
ci / github (pull_request) Successful in 2m33s
ci / announce (pull_request) Skipped
The flag switched certificate checks off for every connection in the run.
That included the Microsoft sign-in endpoints, so a user passing it for a
self-signed source also sent refresh tokens, device codes and EWS client
secrets over unverified TLS. It also covered the export target, and any host
a server redirected to or named for its API, uploads or downloads.

It now applies only where the user pointed it: the host of --url, for the
source of an import or the target of an export. For an Exchange import with
no --url, it covers the mailbox's own domain, where on-premises Autodiscover
looks, and then only the EWS endpoint Autodiscover finds. The Microsoft and
Google sign-in and cloud hosts are always verified, with or without the flag.

Each HTTP client keeps a verifying agent and, only when the flag applies, a
second one that accepts invalid certificates, and picks per request by host.
The sign-in modules no longer take the flag at all. Autodiscover v2, which is
Microsoft's own service, is always verified.
2026-09-30 11:31:44 -07:00
jcoffey-dev 15b1cbd637 Merge pull request 'Create the archive readable by its owner only' (#5) from fix/archive-permissions into main
ci / test (push) Skipped
github/ci (branch) GitHub Actions
ci / github (push) Successful in 3m51s
ci / announce (push) Skipped
2026-09-30 18:29:04 +00:00
jcoffey-dev 67891994e6 Merge pull request 'Rename Stalwart's Sieve names for inbuxa, and fail when activation does' (#3) from fix/sieve-stalwart-names into main
ci / test (push) Skipped
github/ci (branch) GitHub Actions
ci / github (push) Canceled after 1m34s
ci / announce (push) Canceled after 0s
2026-09-30 18:27:28 +00:00
jcoffey-dev 59a8edbc7e Merge pull request 'docs: export matches and skips, it does not update' (#2) from docs/export-matching into main
ci / test (push) Canceled after 0s
ci / github (push) Canceled after 0s
ci / announce (push) Canceled after 0s
2026-09-30 18:27:26 +00:00
jcoffey-dev 38d32811e4 Create the archive readable by its owner only
ci / test (pull_request) Skipped
github/ci (branch) GitHub Actions
ci / github (pull_request) Successful in 2m32s
ci / announce (pull_request) Skipped
An archive holds a whole mailbox, its contacts and calendars, and it was
created with SQLite's default mode, readable by every user on the machine.
On Unix a new archive is now created with mode 0600 before SQLite opens it;
SQLite gives the -wal and -shm files the database file's mode, so they
follow, which a test confirms. An existing archive that others can read is
left as it is, with a warning naming it and the chmod that fixes it.
Nothing changes on Windows.
2026-09-30 11:26:18 -07:00
jcoffey-dev eb38603dbc Time out every HTTP connection instead of waiting forever
No ureq agent set a timeout, and ureq sets none by default, so a connection
dropped silently mid-transfer (a NAT or load-balancer idle drop) hung a JMAP,
DAV, EWS or Graph run, or an export, with no error, and the retry logic never
got a chance to run. IMAP and ManageSieve already had read timeouts.

Every agent now takes its settings from a new net module: 30s to connect,
60s to send the request headers, 5 minutes for the server's first byte, and
30 minutes for a whole response body, which ureq counts as one budget for the
body rather than per read: enough for the 512 MiB limit at about 300 KB/s.
A JMAP upload's send budget grows with its size, from a 2 minute floor at an
assumed 64 KiB/s worst case.

A timeout is a transport error, and every client already retries those, so a
stalled transfer is now abandoned and retried. Tests pin that down for each
client. The TLS setup the seven agents repeated moves to one helper.
2026-09-30 11:25:34 -07:00
jcoffey-dev 5ae0625ee1 export: write a message once, in every folder it was in
ci / test (pull_request) Skipped
github/ci (branch) GitHub Actions
ci / github (pull_request) Successful in 2m11s
ci / announce (pull_request) Skipped
A source that files one message in several folders -- IMAP and Maildir
copies, Gmail labels -- leaves one archive row per folder, all pointing at the
same blob. Export imported each row on its own, so the message arrived on the
target once per folder. Worse, an interrupted export matched the rest by
Message-ID alone on the next run and skipped them, so their folders were never
added.

Export now folds rows with the same blob into one email, with the union of
their folders and keywords. On a match it adds, with one batched Email/set,
any migrated folder the target copy is missing; folders that exist only on the
target are left alone. Matching is still by Message-ID (or the fallback
digest), with size deciding between several messages that share one, so two
different messages are never folded onto one target email.

The archive is unchanged: the fold happens at export, so imports, resumes and
deletions work exactly as before.
2026-09-30 11:25:04 -07:00
jcoffey-dev 470fda6ac8 Rename Stalwart's Sieve names for inbuxa, and fail when activation does
ci / test (pull_request) Skipped
github/ci (branch) GitHub Actions
ci / github (pull_request) Successful in 2m11s
ci / announce (pull_request) Skipped
inbuxa accepts vnd.inbuxa.while and vnd.inbuxa.expressions, and names its
environment items vnd.inbuxa.*, with no alias for Stalwart's vnd.stalwart.*
names. A script carried over unchanged failed to compile on the target, and
the account was left with no filtering behind a single warning.

When the target lists vnd.inbuxa extensions in its sieveExtensions, export
now renames Stalwart's names in the three places they are names: the strings
of a require list, the item name of an environment test, and
${env.vnd.stalwart.*} references inside strings. A small tokenizer skips
comments and reads quoted strings and text: blocks whole, so other text that
happens to contain the name is copied unchanged. Each rename is printed.
Against a target without the inbuxa names nothing changes.

The activation call is now checked. A method error, or an active script
that could not be created, is logged as an error naming the script and
counted as a failure, so export exits non-zero instead of leaving
filtering off with one warning line.
2026-09-30 11:24:16 -07:00
jcoffey-dev 54fd18b410 docs: export matches and skips, it does not update
ci / test (pull_request) Skipped
github/ci (branch) GitHub Actions
ci / github (pull_request) Successful in 1m50s
ci / announce (pull_request) Skipped
usage.md said items that match are updated. Export skips a match: a
change made at the source after the first export -- read state, a folder
move, an edited event, contact or Sieve script -- does not reach the target
on a second one. Say so until updating on re-export is built.
2026-09-30 11:16:47 -07:00
jcoffey-dev 2d94915702 Merge pull request 'Make Vandelay into inbuxa-migrate' (#1) from rename/inbuxa-migrate into main
github/ci (branch) GitHub Actions
Reviewed-on: #1
2026-09-30 17:30:46 +00:00
jcoffey-dev 210c04997c Track the Gitea workflows and docs/usage.md
The .gitignore inherited from upstream ignores every dotfile except .github,
and every Markdown file except README and CHANGELOG. The Gitea workflows and
docs/usage.md, which the README links to, were therefore never committed.
Both are now excepted and added.
2026-09-30 10:23:30 -07:00
jcoffey-dev f03e197d0b docs: write dates the American way
"October 1, 2026" and "April 1, 2027", matching the rest of the suite.
2026-09-30 10:22:35 -07:00
jcoffey-dev bfea4a5467 Rewrite the README for inbuxa-migrate
The README now says what the tool is in the suite's plain voice: the
archive in the middle, convergent reruns, --dry-run, the archive as a
backup, the sources it reads (Stalwart among the JMAP ones), the
INBUXA_MIGRATE_* credential variables, installing from the Gitea release
with SHA256SUMS, building and testing, and the license with the lineage
line. Upstream's logo, badges and install channels are gone.

The full command and flag reference moves to docs/usage.md, with the
renamed binary and variables. The CHANGELOG gains a section for this first
release, above upstream's history.
2026-09-30 10:15:07 -07:00
jcoffey-dev 42413563ef Replace the release tooling with the suite's CI
Upstream's cargo-dist pipeline published to npm and Homebrew under its own
names, built an MSI, and ran on every pull request. It goes, with its
dist-workspace.toml, the wix/ installer files and the README image.

CI now follows the rest of the suite. .gitea/workflows runs `cargo test
--locked` on Gitea's runners, or, when the org variable BUILD_ON is
'github', waits for the result GitHub reports on the commit. On GitHub,
.github/workflows/ci.yml runs the same tests, and for a v* tag on main
whose version matches Cargo.toml builds scripts/build-release.sh on native
amd64 and arm64 runners (Ubuntu 22.04, for the widest glibc range),
attaches inbuxa-migrate-linux-{amd64,arm64}.tar.gz and SHA256SUMS to the
Gitea Release, copies the Release to GitHub, and reports back. Releases are
built only on GitHub; with BUILD_ON unset a tag is tested but not released.
Published releases are announced on the forum.
2026-09-30 10:12:48 -07:00
jcoffey-dev 7fbcf5031e Take the registry capability from the server's session
Registry calls (x:Account, x:Domain and the rest of the x: types) were
always sent under urn:stalwart:jmap. inbuxa advertises the same registry
as urn:inbuxa:jmap:registry, so the capability now comes from the connected
server: Session::registry_urn() picks urn:inbuxa:jmap:registry when the
session advertises it, else urn:stalwart:jmap, so Stalwart servers still
work as a source. A request carrying an x: call against a server that
advertises neither fails with a MissingCapability error naming both,
treated like any other connection-level failure, instead of sending a
capability the server never offered.
2026-09-30 10:09:10 -07:00
jcoffey-dev 5931b06392 Rename to inbuxa-migrate
The crate, binary, library path and every name the tool writes or reads
become inbuxa-migrate: the CLI name and about text, the HTTP user agent,
the credential variables (INBUXA_MIGRATE_PASSWORD, _TOKEN,
_EWS_CLIENT_SECRET and _GRAPH_TOKEN, with no fallback to the old names),
thread names, synthesized UIDs and calendar addresses
(urn:x-inbuxa-migrate:attendee:), and the Maildir file suffix used by the
export script. This is a new tool, so archives written by Vandelay are not
read back.

The version moves to the date scheme the release tags use (2026.9.30), and
the package metadata points at the inbuxa-migrate repository. The cargo-dist
and MSI metadata goes with the release tooling it served.

Modified files carry an added copyright line; the original notices stay.
2026-09-30 10:09:10 -07:00
Stalwart Official 486a384712 Merge branch 'main' of github.com:stalwartlabs/vandelay 2026-09-30 14:16:40 +02:00
Stalwart Official 3a04a6e1fd Added EWS details 2026-09-30 14:16:11 +02:00
Maurus Decimus 1596cabd51 v1.0.11 2026-09-28 11:38:50 +02:00
Maurus Decimus 70fa688d25 Fix IMAP: import failed after authenticating to Dovecot when a capability contained :, such as IMAPSIEVE=sieve://... (fixes #43) 2026-09-28 11:38:10 +02:00
Maurus Decimus 5dc92c7329 Migrate to encodify 2026-09-28 10:45:15 +02:00
Maurus Decimus 42f7c87911 v1.0.10 2026-08-27 19:53:06 +02:00
Maurus Decimus e00909640a MS Exchange Graph fixes 2026-08-27 19:51:18 +02:00
Maurus Decimus e8d98abccb MS Exchange Graph: Import the default Contacts folder, recover series exceptions (fixes #39) 2026-08-27 19:15:03 +02:00
Maurus Decimus 423b761617 v1.0.9 2026-08-22 18:46:54 +02:00
Maurus Decimus 1cc633f39c v1.0.8 (fixes #29 fixes #30 fixes #31) 2026-08-16 12:29:05 +02:00
Maurus Decimus c4e06bd87d Testcontainer fixes 2026-07-28 09:12:10 +02:00
Maurus Decimus fe16f2b2fe IMAP import failed with "LIST mailbox name missing" when a mailbox name is a purely numeric unquoted atom (closes #26) 2026-07-26 17:28:48 +02:00
Maurus Decimus 846fc88f7e Improve verbosity (closes #4 closes #19) 2026-07-18 11:41:08 +02:00
Maurus Decimus 9fc9178b67 Crypto provider test fixes 2026-07-17 18:53:09 +02:00
Maurus Decimus f35c6fd90a Report which email failed to import when the blob is too large (fixes #22) 2026-07-17 17:16:34 +02:00
Maurus Decimus c572cacb5c Fix: ureq default features pull in an unused crypto provider and CA bundle (closes #23) 2026-07-17 16:03:49 +02:00
Maurus Decimus c13435b8f7 Report user friendly error message when urn:ietf:params:jmap:principals is not supported and no accountId is provided (closes #21) 2026-07-17 15:51:05 +02:00
Maurus Decimus 0f28e9b17e WebDAV import materialised the account root collection as a directory named after the account displayname (fixes #18) 2026-07-12 18:54:43 +02:00
Maurus Decimus ec6b3f9d15 Update CI node version 2026-07-12 16:40:07 +02:00
Maurus Decimus 824166ce54 v1.0.6 2026-07-12 16:27:46 +02:00
Maurus Decimus 7f9e77ae58 Add vCard X-label tests 2026-07-08 11:34:59 +02:00
Maurus Decimus 24dadff463 Mapping existing special mailbox fails after alreadyExists response (fixes #17) 2026-07-07 11:36:47 +02:00
Maurus Decimus ceb8e1815c Self heal on blobNotFound errors when exporting data (closes #13) 2026-06-28 11:11:23 +02:00
Maurus Decimus 6ca561fff5 Fix: Strict RFC822.SIZE == BODY[] length check discards good mail 2026-06-27 12:00:12 +02:00
Maurus Decimus 3e9d4593f7 Use tgz instead of xz (closes #10) 2026-06-24 13:43:40 +02:00
Maurus Decimus 0aaad2fd57 v1.0.4 2026-06-21 19:02:19 +02:00
Maurus Decimus cbcf0a1a84 Fix: Failures are double-counted 2026-06-21 08:42:58 +02:00
Maurus Decimus 4102b5f4ae Include correct JMAP capabilities in using 2026-06-19 11:05:04 +02:00
Maurus Decimus 08c1c5ac84 v1.0.3 2026-06-15 21:32:49 +02:00