Rename the identifiers that carried the upstream name
ci / fork-checks (pull_request) Successful in 16s
ci / build (pull_request) Successful in 7m53s

Everything clients, users and operators meet now carries the fork's name,
with no aliases (SPEC.md §2.4, changed here from "protocol identifiers
stay"):

- JMAP: upstream's registry capability is urn:inbuxa:jmap:registry, beside
  the fork's own urn:inbuxa:jmap.
- WebDAV lock and sync tokens are urn:inbuxa:dav*; clients resync once.
- Sieve: vnd.inbuxa.while and vnd.inbuxa.expressions. sieve-rs spells these
  into its compiler, so it's vendored (vendor/sieve-rs, 0.7.3) and patched in;
  a unit test fails if Cargo.lock ever moves past the vendored copy. The
  trusted runtime now names itself too, rather than answering sieve-rs's
  default.
- The web interface's OAuth client is inbuxa-webui. On every start the old
  stalwart-webui client is removed and any application naming it is moved
  over.
- The spam filter's blobs are INBUXA_SPAM_*; every start moves any left
  under the old keys, so a trained model survives.
- SQL stores and log files default to inbuxa, in the code and in the
  schema served to the admin (checksum regenerated).
- Settings are INBUXA_* only. A STALWART_* variable that's set where its
  INBUXA_* one isn't stops the server at startup, naming it.
- The version-upgrade messages link docs.inbuxa.org's migration page, and
  the OpenAPI description, smtp crate metadata and web-push test fixtures
  lose the name.

Kept on purpose, allowlisted with reasons: the OAuth key-derivation
contexts (renaming them would end every session and invalidate every
sealed client id) and the hashed application prefix.

Also fixes a latent start-up failure: ensure_client updated an existing
first-party client with a revision of 0, which the registry's assertion
never matches, so adding a redirect URI or changing the webmail secret
failed start-up. And the principal session test now expects
legacyProtocols (C-1, added 2026-09-21), which it had missed.

Tested: the server builds without warnings; common's 106 unit tests,
including the vendoring check; a new integration test for the two
start-up migrations; and the webdav, jmap, imap and SMTP Sieve suites.
This commit is contained in:
2026-09-22 19:33:02 -07:00
parent 4799d191a0
commit cc6f1eb298
129 changed files with 20504 additions and 168 deletions
+36 -13
View File
@@ -47,22 +47,32 @@ macro_rules! brand_url {
}
/// Reads one of the server's environment variables by its unprefixed name,
/// such as `RECOVERY_ADMIN`.
/// such as `RECOVERY_ADMIN`, from `INBUXA_<name>`.
///
/// `INBUXA_<name>` wins. `STALWART_<name>` is still read when the new name
/// isn't set, so an existing Stalwart install moves over without editing its
/// environment, and a warning says which variable to rename.
/// The upstream prefix isn't read (SPEC §2.4). An install moved over from
/// upstream that still sets it stops here with the variable to rename, rather
/// than starting on defaults the operator didn't choose.
pub fn env_var(name: &str) -> Result<String, std::env::VarError> {
match std::env::var(format!("INBUXA_{name}")) {
Err(std::env::VarError::NotPresent) => {
let legacy = std::env::var(format!("STALWART_{name}"));
if legacy.is_ok() {
eprintln!("Warning: STALWART_{name} is deprecated; set INBUXA_{name} instead.");
}
legacy
}
found => found,
let found = std::env::var(format!("INBUXA_{name}"));
if matches!(found, Err(std::env::VarError::NotPresent))
&& let Some(legacy) = legacy_setting(name, |var| std::env::var_os(var).is_some())
{
eprintln!(
"Error: {legacy} is set, but inbuxa reads INBUXA_{name}. Rename it and start again \
(https://docs.inbuxa.org/install/migrating/)."
);
std::process::exit(1);
}
found
}
/// The environment prefix upstream reads. Only ever used to refuse it.
const LEGACY_ENV_PREFIX: &str = "STALWART";
/// The upstream-prefixed variable for `name`, if it's set.
fn legacy_setting(name: &str, is_set: impl Fn(&str) -> bool) -> Option<String> {
let legacy = format!("{LEGACY_ENV_PREFIX}_{name}");
is_set(&legacy).then_some(legacy)
}
/// INBUXA's own version, dated like the rest of its family: `YYYY.M.D`, with
@@ -90,3 +100,16 @@ macro_rules! brand_version_full {
concat!($crate::brand_version!(), " (upstream ", env!("CARGO_PKG_VERSION"), ")")
};
}
#[cfg(test)]
mod tests {
use super::{LEGACY_ENV_PREFIX, legacy_setting};
#[test]
fn an_upstream_setting_is_named_for_renaming() {
let old = format!("{LEGACY_ENV_PREFIX}_RECOVERY_ADMIN");
let set = |var: &str| var == old;
assert_eq!(legacy_setting("RECOVERY_ADMIN", set), Some(old.clone()));
assert_eq!(legacy_setting("HOSTNAME", set), None);
}
}