Merge upstream v0.16.24

Eight conflicted files resolved, plus the lock file and the schema:

- crates/services/src/task_manager/spam_classifier.rs: upstream's rules
  update now replaces existing rules, DNSBL servers, lookups and file
  extensions, keeping only whether each is on. Taken, with one difference:
  an object an admin edited is kept as it is. Every object an update writes
  is fingerprinted (content without `enable`, SHA-256, stored under
  SUBSPACE_INBUXA "Sf"), and only one that still matches is replaced.
  Scores are never replaced, as upstream has it. The AU-1.10 summary record
  now names what was added, replaced and kept, and the bundled rules are
  marked applied only when the update fully succeeded, so a failure runs
  again on the next start. The marker becomes "3.0.2+2", which runs the
  update once on upgrade to fingerprint every rule still as bundled.
- crates/common/src/network/autoconfig/autodiscover.rs: upstream's rewrite
  (implicit TLS first, labeled SSL), with the per-protocol switches (LP-7,
  LP-14a) passed in as a filter.
- crates/store/src/backend/mysql/{search,write}.rs: upstream's chunked
  deletes (no unbounded first DELETE, stop on a short chunk, halve the
  chunk on the new chunk-too-large errors) inside the fork's query timeout.
- crates/smtp/src/lib.rs: the fork's queue spawn kept. It already fixed the
  stall upstream fixes here (a node without outboundMta stops accepting
  mail at about 1024 queued messages), and follows role changes live.
- crates/jmap/src/registry/mapping/bootstrap.rs: the log path stays
  /var/log/inbuxa/; upstream's PowerDNS mapping taken.
- crates/main/Cargo.toml: the AGPL-only license kept, version 0.16.24.
- tests/src/jmap/principal/get.rs: the fork's capabilities kept.
- resources/schema/schema.json.gz: merged as JSON; upstream relabeled the
  vendor Sieve extensions "(Stalwart)", kept as "(vnd.inbuxa)".
- Cargo.lock: upstream's, with the fork's crates added by Cargo.

Also:

- tests/src/smtp/inbound/spam_rules_kept.rs: an edited rule survives an
  update, an unedited one is updated, rules from before fingerprints are
  handled, and the audit summary says so. Upstream's own spam_rules test
  passes unchanged.
- tests/src/smtp/reporting/reschedule.rs moves to port 19058; upstream's
  new spam_rules test took 19057.
- tools/fork/renames.py renames the "(Stalwart)" labels and the default
  log path, so neither conflicts again.
- tools/fork/notice-check.py compares against the newest snapshot in the
  checked-out history instead of the upstream branch head, so moving the
  branch no longer fails other open pull requests.
- tests/src/directory/issuer.rs (since v0.16.23) stays out, and is on the
  build check's known list: it tests issuer-based directory routing, which
  the fork doesn't have (DIR-2).
- Strip report: docs/fork/strip-reports/v0.16.24.{md,json}.
This commit is contained in:
2026-09-28 06:30:20 -07:00
94 changed files with 4206 additions and 1065 deletions
+6 -1
View File
@@ -696,7 +696,12 @@ impl<T: SessionStream> Session<T> {
.map(|a| a.as_str())
.unwrap_or_default(),
)
.with_message(parsed_message);
.with_message(
edited_message
.as_deref()
.and_then(|message| MessageParser::new().parse(message))
.unwrap_or(parsed_message),
);
let modifications = match self.run_script(script_id, script.clone(), params).await {
ScriptResult::Accept { modifications } => modifications,
+1 -1
View File
@@ -132,7 +132,7 @@ impl<T: SessionStream> Session<T> {
name: "X-Quarantine".into(),
value: "true".into(),
});
FilterResponse::accept()
continue;
}
};
+42 -10
View File
@@ -531,11 +531,23 @@ impl QueuedMessage {
};
// Obtain remote hosts list
let mx_unvalidated = mx_config.is_some() && !tls_strategy.try_dane();
let mx_list;
if let Some(mx_config) = mx_config {
// Lookup MX
let time = Instant::now();
mx_list = match server.mx_lookup(domain).await {
let mx_lookup = if mx_unvalidated {
server
.core
.smtp
.resolvers
.dns
.mx_lookup(domain, Some(&server.inner.cache.dns_mx))
.await
} else {
server.mx_lookup(domain).await
};
mx_list = match mx_lookup {
Ok(mx) => mx,
Err(mail_auth::Error::Dns(mail_auth::DnsError::RecordNotFound(_))) => {
trc::event!(
@@ -674,6 +686,33 @@ impl QueuedMessage {
message.span_id,
);
let validated_host;
let remote_host = if mx_unvalidated && tls_strategy.try_dane() {
let time = Instant::now();
let dnssec_status = match server.mx_lookup(domain).await {
Ok(mx) => mx.dnssec_status,
Err(mail_auth::Error::Dns(mail_auth::DnsError::RecordNotFound(_))) => {
DnssecStatus::Indeterminate
}
Err(err) => {
trc::event!(
Delivery(DeliveryEvent::MxLookupFailed),
SpanId = message.span_id,
Domain = domain.to_string(),
CausedBy = trc::Error::from(err.clone()),
Elapsed = time.elapsed(),
);
last_status = Status::from_mail_auth_error(domain, err);
continue 'next_host;
}
};
validated_host = remote_host.with_dnssec_status(dnssec_status);
&validated_host
} else {
remote_host
};
// Obtain source and remote IPs
let time = Instant::now();
let validate_addresses = server.core.smtp.resolvers.dnssec_available
@@ -722,15 +761,8 @@ impl QueuedMessage {
let time = Instant::now();
let strict = tls_strategy.is_dane_required();
let (dnssec_status, dnssec_entity) = match remote_host.dnssec_status() {
DnssecStatus::Secure => match addresses_dnssec_status {
status @ (DnssecStatus::Insecure | DnssecStatus::Bogus) => {
(status, "A/AAAA")
}
_ => (DnssecStatus::Secure, "MX"),
},
status => (status, "MX"),
};
let (dnssec_status, dnssec_entity) =
remote_host.dane_status(addresses_dnssec_status);
match dnssec_status {
DnssecStatus::Secure => {
+28 -1
View File
@@ -350,12 +350,39 @@ impl NextHop<'_> {
}
}
fn dnssec_status(&self) -> DnssecStatus {
pub fn dnssec_status(&self) -> DnssecStatus {
match self {
NextHop::MX { dnssec_status, .. } => *dnssec_status,
NextHop::Relay(_) => DnssecStatus::Indeterminate,
}
}
fn with_dnssec_status(&self, dnssec_status: DnssecStatus) -> Self {
match self {
NextHop::MX {
is_implicit,
host,
config,
..
} => NextHop::MX {
is_implicit: *is_implicit,
host,
config,
dnssec_status,
},
NextHop::Relay(relay) => NextHop::Relay(relay),
}
}
pub fn dane_status(&self, addresses: DnssecStatus) -> (DnssecStatus, &'static str) {
match self.dnssec_status() {
DnssecStatus::Secure => match addresses {
status @ (DnssecStatus::Insecure | DnssecStatus::Bogus) => (status, "A/AAAA"),
_ => (DnssecStatus::Secure, "MX"),
},
status => (status, "MX"),
}
}
}
impl DeliveryResult {
+5
View File
@@ -67,6 +67,10 @@ impl SpawnQueue for mpsc::Receiver<QueueEvent> {
Queue::new(core, self).start().await;
});
}
fn discard(mut self) {
tokio::spawn(async move { while self.recv().await.is_some() {} });
}
}
const BACK_PRESSURE_WARN_INTERVAL: Duration = Duration::from_secs(60);
@@ -510,6 +514,7 @@ impl Recipient {
pub trait SpawnQueue {
fn spawn(self, core: Arc<Inner>);
fn discard(self);
}
impl QueueStats {