Import upstream v0.16.24, stripped
Upstream commit: af37a234981722493b74623a983581691d2b70b6 Enterprise-only files removed or emptied: 63 Enterprise-only snippets removed: 118 in 50 files Dangling module declarations removed: 5 Edits turning enterprise off: 25 Third-party code: 14 files, 0 not in THIRD-PARTY.md Renamed identifiers: 62 in 18 files Verification: clean The same Enterprise footprint as v0.16.23. The build check fails only on tests/src/directory/issuer.rs, unchanged since v0.16.23: it calls a helper from upstream's Enterprise-only OIDC test, and tests issuer-based directory routing, an Enterprise feature. main has never carried it.
This commit is contained in:
@@ -531,11 +531,23 @@ impl QueuedMessage {
|
||||
};
|
||||
|
||||
// Obtain remote hosts list
|
||||
let mx_unvalidated = mx_config.is_some() && !tls_strategy.try_dane();
|
||||
let mx_list;
|
||||
if let Some(mx_config) = mx_config {
|
||||
// Lookup MX
|
||||
let time = Instant::now();
|
||||
mx_list = match server.mx_lookup(domain).await {
|
||||
let mx_lookup = if mx_unvalidated {
|
||||
server
|
||||
.core
|
||||
.smtp
|
||||
.resolvers
|
||||
.dns
|
||||
.mx_lookup(domain, Some(&server.inner.cache.dns_mx))
|
||||
.await
|
||||
} else {
|
||||
server.mx_lookup(domain).await
|
||||
};
|
||||
mx_list = match mx_lookup {
|
||||
Ok(mx) => mx,
|
||||
Err(mail_auth::Error::Dns(mail_auth::DnsError::RecordNotFound(_))) => {
|
||||
trc::event!(
|
||||
@@ -674,6 +686,33 @@ impl QueuedMessage {
|
||||
message.span_id,
|
||||
);
|
||||
|
||||
let validated_host;
|
||||
let remote_host = if mx_unvalidated && tls_strategy.try_dane() {
|
||||
let time = Instant::now();
|
||||
let dnssec_status = match server.mx_lookup(domain).await {
|
||||
Ok(mx) => mx.dnssec_status,
|
||||
Err(mail_auth::Error::Dns(mail_auth::DnsError::RecordNotFound(_))) => {
|
||||
DnssecStatus::Indeterminate
|
||||
}
|
||||
Err(err) => {
|
||||
trc::event!(
|
||||
Delivery(DeliveryEvent::MxLookupFailed),
|
||||
SpanId = message.span_id,
|
||||
Domain = domain.to_string(),
|
||||
CausedBy = trc::Error::from(err.clone()),
|
||||
Elapsed = time.elapsed(),
|
||||
);
|
||||
|
||||
last_status = Status::from_mail_auth_error(domain, err);
|
||||
continue 'next_host;
|
||||
}
|
||||
};
|
||||
validated_host = remote_host.with_dnssec_status(dnssec_status);
|
||||
&validated_host
|
||||
} else {
|
||||
remote_host
|
||||
};
|
||||
|
||||
// Obtain source and remote IPs
|
||||
let time = Instant::now();
|
||||
let validate_addresses = server.core.smtp.resolvers.dnssec_available
|
||||
@@ -722,15 +761,8 @@ impl QueuedMessage {
|
||||
let time = Instant::now();
|
||||
let strict = tls_strategy.is_dane_required();
|
||||
|
||||
let (dnssec_status, dnssec_entity) = match remote_host.dnssec_status() {
|
||||
DnssecStatus::Secure => match addresses_dnssec_status {
|
||||
status @ (DnssecStatus::Insecure | DnssecStatus::Bogus) => {
|
||||
(status, "A/AAAA")
|
||||
}
|
||||
_ => (DnssecStatus::Secure, "MX"),
|
||||
},
|
||||
status => (status, "MX"),
|
||||
};
|
||||
let (dnssec_status, dnssec_entity) =
|
||||
remote_host.dane_status(addresses_dnssec_status);
|
||||
|
||||
match dnssec_status {
|
||||
DnssecStatus::Secure => {
|
||||
|
||||
@@ -350,12 +350,39 @@ impl NextHop<'_> {
|
||||
}
|
||||
}
|
||||
|
||||
fn dnssec_status(&self) -> DnssecStatus {
|
||||
pub fn dnssec_status(&self) -> DnssecStatus {
|
||||
match self {
|
||||
NextHop::MX { dnssec_status, .. } => *dnssec_status,
|
||||
NextHop::Relay(_) => DnssecStatus::Indeterminate,
|
||||
}
|
||||
}
|
||||
|
||||
fn with_dnssec_status(&self, dnssec_status: DnssecStatus) -> Self {
|
||||
match self {
|
||||
NextHop::MX {
|
||||
is_implicit,
|
||||
host,
|
||||
config,
|
||||
..
|
||||
} => NextHop::MX {
|
||||
is_implicit: *is_implicit,
|
||||
host,
|
||||
config,
|
||||
dnssec_status,
|
||||
},
|
||||
NextHop::Relay(relay) => NextHop::Relay(relay),
|
||||
}
|
||||
}
|
||||
|
||||
pub fn dane_status(&self, addresses: DnssecStatus) -> (DnssecStatus, &'static str) {
|
||||
match self.dnssec_status() {
|
||||
DnssecStatus::Secure => match addresses {
|
||||
status @ (DnssecStatus::Insecure | DnssecStatus::Bogus) => (status, "A/AAAA"),
|
||||
_ => (DnssecStatus::Secure, "MX"),
|
||||
},
|
||||
status => (status, "MX"),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl DeliveryResult {
|
||||
|
||||
Reference in New Issue
Block a user