Compare commits
5
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f398d95062 | ||
|
|
81ec917d74 | ||
|
|
e2ab26ad19 | ||
|
|
0b4aa9c084 | ||
|
|
4e6c8b916e |
@@ -3,36 +3,22 @@
|
||||
# whether a person pushed it or weekly-release.yml created it through the
|
||||
# releases API.
|
||||
#
|
||||
# The image is multi-arch (linux/amd64, linux/arm64), built by two jobs on
|
||||
# the image-build runner rather than one buildx run for both. The Dockerfile's
|
||||
# builder stage runs on the build platform and cross-compiles with an aarch64
|
||||
# linker, so only the small final stage (apt, setcap) goes through QEMU for
|
||||
# arm64 -- but two release builds (LTO, one codegen unit) side by side on one
|
||||
# machine each take twice as long. Production runs amd64, so amd64 goes first
|
||||
# and on its own:
|
||||
# * publish-amd64 pushes :<version>-amd64 and :<version>, a plain amd64
|
||||
# image, as soon as its build is done. A deploy can start from it.
|
||||
# * publish-arm64 then builds arm64, pushes :<version>-arm64, and replaces
|
||||
# :<version> with the two-platform index. :latest moves only here, so it
|
||||
# never names an image without arm64.
|
||||
#
|
||||
# Both jobs use one BuildKit builder, `gitea-builder`, whose container
|
||||
# (buildx_buildkit_gitea-builder0) and state volume stay on the runner's host
|
||||
# between jobs: a job container's `buildx create` finds the existing container
|
||||
# and reuses it and its cache. The dependency build (`cargo chef cook`) is
|
||||
# keyed on the recipe, which only a dependency change alters, so a release
|
||||
# normally compiles just the workspace. Removing that container or its volume
|
||||
# costs the next release a cold build, nothing more. The planner and dependency
|
||||
# layers for the build platform are shared, so arm64 also reuses what amd64
|
||||
# just did where it can.
|
||||
# The image is multi-arch (linux/amd64, linux/arm64) as before, but built in
|
||||
# one buildx run on host1 instead of one native runner per architecture: the
|
||||
# Dockerfile's builder stage runs on the build platform and cross-compiles
|
||||
# with an aarch64 linker, so only the small final stage (apt, setcap) goes
|
||||
# through QEMU for arm64. No digest-joining job is needed.
|
||||
#
|
||||
# Two guards before anything is pushed:
|
||||
# * the tag must be v<brand_version!>. The version is a string in
|
||||
# crates/types/src/branding.rs, not Cargo.toml, and the image is tagged
|
||||
# with it, so a tag beside an unbumped macro would publish an image that
|
||||
# reports a different version from its tag.
|
||||
# * the tag must be on main, so an image never describes code that was never
|
||||
# reviewed onto the default branch.
|
||||
# * the tag must be on main or on a release/* branch, so an image never
|
||||
# describes code that was never reviewed onto one of them. A release/*
|
||||
# branch carries a hotfix: it starts at an earlier release tag, takes
|
||||
# fixes through pull requests into it, and is tagged there, so production
|
||||
# can get a fix without everything that has landed on main since.
|
||||
#
|
||||
# :latest moves with every published tag: tags are cut by the weekly release
|
||||
# (or by hand for a real release); there are no prerelease tags here.
|
||||
@@ -74,12 +60,17 @@ jobs:
|
||||
echo "Refusing to publish an image that would report the wrong version." >&2
|
||||
exit 1
|
||||
fi
|
||||
git merge-base --is-ancestor "$(git rev-parse "${TAG}^{commit}")" origin/main \
|
||||
|| { echo "$TAG is not on main" >&2; exit 1; }
|
||||
commit="$(git rev-parse "${TAG}^{commit}")"
|
||||
on=""
|
||||
for ref in origin/main $(git for-each-ref --format='%(refname:short)' 'refs/remotes/origin/release/*'); do
|
||||
if git merge-base --is-ancestor "$commit" "$ref"; then on="$ref"; break; fi
|
||||
done
|
||||
[ -n "$on" ] || { echo "$TAG is not on main or a release/* branch" >&2; exit 1; }
|
||||
echo "$TAG is on $on"
|
||||
echo "version=$V" >> "$GITHUB_OUTPUT"
|
||||
echo "version $V"
|
||||
|
||||
publish-amd64:
|
||||
publish:
|
||||
needs: [version]
|
||||
runs-on: docker
|
||||
container:
|
||||
@@ -98,15 +89,16 @@ jobs:
|
||||
test -n "$REGISTRY" && test -n "$VERSION"
|
||||
test -n "$PACKAGE_TOKEN" || { echo "PACKAGE_TOKEN secret is not set on this repository" >&2; exit 1; }
|
||||
echo "$PACKAGE_TOKEN" | docker login -u jcoffey-dev --password-stdin "$REGISTRY"
|
||||
docker run --privileged --rm tonistiigi/binfmt --install arm64
|
||||
docker buildx create --use --name gitea-builder --driver docker-container || docker buildx use gitea-builder
|
||||
# Attestations off, as before: they add manifests of their own, and the
|
||||
# index should hold the two images and nothing else.
|
||||
# Attestations off, as before: they add manifests of their own to the
|
||||
# index, and the index should hold the two images and nothing else.
|
||||
- run: |
|
||||
docker buildx build \
|
||||
--platform linux/amd64 \
|
||||
--platform linux/amd64,linux/arm64 \
|
||||
--provenance=false --sbom=false \
|
||||
--tag "$IMAGE:$VERSION-amd64" \
|
||||
--tag "$IMAGE:$VERSION" \
|
||||
--tag "$IMAGE:latest" \
|
||||
--push .
|
||||
docker buildx imagetools inspect "$IMAGE:$VERSION"
|
||||
# Gitea keeps a container package on its owner; linking it shows it on
|
||||
@@ -119,47 +111,11 @@ jobs:
|
||||
- if: always()
|
||||
run: docker logout "$REGISTRY" || true
|
||||
|
||||
publish-arm64:
|
||||
needs: [version, publish-amd64]
|
||||
runs-on: docker
|
||||
container:
|
||||
image: docker:28-cli@sha256:625d9431a9f54c5a2bc90f24f0e1c3d55b1349fd857dd85035f98c2c9acbdd4d # 28-cli
|
||||
volumes:
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
env:
|
||||
DOCKER_BUILDKIT: "1"
|
||||
REGISTRY: ${{ vars.REGISTRY }}
|
||||
IMAGE: ${{ vars.REGISTRY }}/${{ github.repository }}
|
||||
VERSION: ${{ needs.version.outputs.version }}
|
||||
PACKAGE_TOKEN: ${{ secrets.PACKAGE_TOKEN }}
|
||||
steps:
|
||||
- uses: coffey-labs/actions/checkout@fab0c4d45e0162963965f1555df27b7bed5e20ec
|
||||
- run: |
|
||||
echo "$PACKAGE_TOKEN" | docker login -u jcoffey-dev --password-stdin "$REGISTRY"
|
||||
docker run --privileged --rm tonistiigi/binfmt --install arm64
|
||||
docker buildx create --use --name gitea-builder --driver docker-container || docker buildx use gitea-builder
|
||||
# The index is built from the two per-architecture tags rather than from
|
||||
# :<version>, which by now is the amd64 image and would be read as such.
|
||||
- run: |
|
||||
docker buildx build \
|
||||
--platform linux/arm64 \
|
||||
--provenance=false --sbom=false \
|
||||
--tag "$IMAGE:$VERSION-arm64" \
|
||||
--push .
|
||||
docker buildx imagetools create \
|
||||
--tag "$IMAGE:$VERSION" \
|
||||
--tag "$IMAGE:latest" \
|
||||
"$IMAGE:$VERSION-amd64" "$IMAGE:$VERSION-arm64"
|
||||
docker buildx imagetools inspect "$IMAGE:$VERSION"
|
||||
- if: always()
|
||||
run: docker logout "$REGISTRY" || true
|
||||
|
||||
# The weekly release creates its Release (and so the tag) first; a tag
|
||||
# pushed by hand has none. Either way the tag ends up with exactly one
|
||||
# Release, created once the amd64 image exists so its pull instructions
|
||||
# work; arm64 and the binaries follow.
|
||||
# Release, created after the image exists so its pull instructions work.
|
||||
release:
|
||||
needs: [version, publish-amd64]
|
||||
needs: [version, publish]
|
||||
runs-on: light
|
||||
container:
|
||||
image: python:3.13-slim@sha256:8d9d0b8bcf6506481eae4907c18f5e3e7902e629f5f6d684f9e7c32e85e3ddf0 # 3.13-slim
|
||||
@@ -183,9 +139,7 @@ jobs:
|
||||
except urllib.error.HTTPError as e:
|
||||
if e.code != 404: raise
|
||||
image = f"{os.environ['REGISTRY']}/{os.environ['REPO']}:{version}"
|
||||
body = (f"Container image: `{image}` (linux/amd64, linux/arm64); also `:latest`. "
|
||||
"amd64 is published first; arm64 is added to the same tag when its build "
|
||||
"finishes, and `:latest` moves then.\n\n"
|
||||
body = (f"Container image: `{image}` (linux/amd64, linux/arm64); also `:latest`.\n\n"
|
||||
"Binaries for a host install are attached: `inbuxa-linux-amd64.tar.gz` and "
|
||||
"`inbuxa-linux-arm64.tar.gz`, with `SHA256SUMS`. Each is the binary out of this "
|
||||
"release's image for that architecture, so it is the same build. The image "
|
||||
@@ -208,7 +162,7 @@ jobs:
|
||||
# `docker create` does not start anything, so pulling an arm64 image on an
|
||||
# amd64 runner and copying a file out of it needs no emulation.
|
||||
binaries:
|
||||
needs: [version, publish-arm64, release]
|
||||
needs: [version, publish, release]
|
||||
runs-on: docker
|
||||
container:
|
||||
image: docker:28-cli@sha256:625d9431a9f54c5a2bc90f24f0e1c3d55b1349fd857dd85035f98c2c9acbdd4d # 28-cli
|
||||
|
||||
@@ -23,13 +23,6 @@ use utils::{UnwrapFailure, codec::leb128::Leb128_};
|
||||
|
||||
pub(super) const MAGIC_MARKER: u8 = 123;
|
||||
|
||||
// inbuxa: blobs kept under a fixed name instead of a content hash. Nothing
|
||||
// links to them, so the export names them outright.
|
||||
const NAMED_BLOBS: &[&[u8]] = &[
|
||||
crate::manager::SPAM_CLASSIFIER_KEY,
|
||||
crate::manager::SPAM_TRAINER_KEY,
|
||||
];
|
||||
|
||||
#[derive(Debug, Clone, Copy, Hash, PartialEq, Eq)]
|
||||
pub(super) enum Family {
|
||||
Data = 0,
|
||||
@@ -150,21 +143,15 @@ impl Core {
|
||||
.await
|
||||
.failed("Failed to iterate over data store");
|
||||
|
||||
// inbuxa: the trained spam classifier and its trainer state are
|
||||
// blobs stored under fixed names with no blob link, so the walk
|
||||
// over links above never reaches them.
|
||||
let named = NAMED_BLOBS.iter().map(|key| key.to_vec());
|
||||
for key in blobs
|
||||
.into_iter()
|
||||
.map(|hash| hash.as_slice().to_vec())
|
||||
.chain(named)
|
||||
{
|
||||
for hash in blobs {
|
||||
if let Some(blob) = blob_store
|
||||
.get_blob(&key, 0..usize::MAX)
|
||||
.get_blob(hash.as_slice(), 0..usize::MAX)
|
||||
.await
|
||||
.failed("Failed to get blob")
|
||||
{
|
||||
writer.send((key, blob)).failed("Failed to send key");
|
||||
writer
|
||||
.send((hash.as_slice().to_vec(), blob))
|
||||
.failed("Failed to send key");
|
||||
}
|
||||
}
|
||||
}),
|
||||
@@ -336,13 +323,7 @@ impl Family {
|
||||
SUBSPACE_REGISTRY_IDX,
|
||||
SUBSPACE_REGISTRY_PK,
|
||||
SUBSPACE_DIRECTORY,
|
||||
// inbuxa: registry objects the upstream list left out, so an
|
||||
// export dropped them: archived items (undelete) and spam
|
||||
// training samples. Their indexes and id counters already
|
||||
// travel in this family and in `data`, so they ride along.
|
||||
SUBSPACE_DELETED_ITEMS,
|
||||
SUBSPACE_SPAM_SAMPLES,
|
||||
store::SUBSPACE_INBUXA, // inbuxa: the fork's own data (masked email, undelete, policies)
|
||||
store::SUBSPACE_INBUXA, // inbuxa: masked email
|
||||
],
|
||||
Family::Changelog => &[SUBSPACE_LOGS],
|
||||
Family::Queue => &[SUBSPACE_QUEUE_MESSAGE, SUBSPACE_QUEUE_EVENT],
|
||||
|
||||
@@ -54,13 +54,6 @@ Options:
|
||||
-o, --console Open the store console
|
||||
-h, --help Print help
|
||||
-V, --version Print version
|
||||
|
||||
An export holds everything in the data and blob stores except short-lived
|
||||
in-memory state (rate limits, locks, greylisting) and the full-text search
|
||||
index, which belongs to one search backend. An import into an empty store
|
||||
queues the index to be rebuilt when the server next starts. EXPORT_TYPES
|
||||
limits an export to some of: data, registry, blob, changelog, queue, report,
|
||||
telemetry, tasks.
|
||||
"#
|
||||
);
|
||||
|
||||
@@ -263,10 +256,10 @@ impl BootManager {
|
||||
telemetry.enable();
|
||||
|
||||
// Parse settings and restore
|
||||
let core = Box::pin(Core::parse(&mut bootstrap, storage)).await;
|
||||
let imported = core.restore(path).await;
|
||||
// inbuxa: the search index isn't exported; rebuild it
|
||||
core.queue_reindex(&imported).await;
|
||||
Box::pin(Core::parse(&mut bootstrap, storage))
|
||||
.await
|
||||
.restore(path)
|
||||
.await;
|
||||
std::process::exit(0);
|
||||
}
|
||||
StoreOp::Console => {
|
||||
|
||||
@@ -9,22 +9,15 @@
|
||||
use super::backup::MAGIC_MARKER;
|
||||
use crate::{Core, DATABASE_SCHEMA_VERSION};
|
||||
use lz4_flex::frame::FrameDecoder;
|
||||
use registry::{
|
||||
schema::{
|
||||
enums::{CompressionAlgo, TaskStoreMaintenanceType},
|
||||
structs::{Task, TaskStatus, TaskStoreMaintenance},
|
||||
},
|
||||
types::EnumImpl,
|
||||
};
|
||||
use registry::schema::enums::CompressionAlgo;
|
||||
use std::{
|
||||
fs::File,
|
||||
io::{BufReader, ErrorKind, Read},
|
||||
path::{Path, PathBuf},
|
||||
};
|
||||
use store::{
|
||||
BlobStore, IterateParams, SUBSPACE_BLOBS, SUBSPACE_COUNTER, SUBSPACE_INDEXES,
|
||||
SUBSPACE_PROPERTY, SUBSPACE_QUOTA, SUBSPACE_REGISTRY_PK, SUBSPACE_TELEMETRY_SPAN, Store,
|
||||
U32_LEN,
|
||||
BlobStore, IterateParams, SUBSPACE_BLOBS, SUBSPACE_COUNTER, SUBSPACE_INDEXES, SUBSPACE_QUOTA,
|
||||
SUBSPACE_REGISTRY_PK, Store, U32_LEN,
|
||||
write::{
|
||||
AnyClass, AnyKey, BatchBuilder, ValueClass,
|
||||
key::{DeserializeBigEndian, is_node_id_key},
|
||||
@@ -34,9 +27,7 @@ use types::{collection::Collection, field::Field};
|
||||
use utils::{UnwrapFailure, failed};
|
||||
|
||||
impl Core {
|
||||
/// Imports an export into an empty store and returns the subspaces it
|
||||
/// wrote. inbuxa: the caller hands them to [`Core::queue_reindex`].
|
||||
pub async fn restore(&self, src: PathBuf) -> Vec<u8> {
|
||||
pub async fn restore(&self, src: PathBuf) {
|
||||
// Backup the core
|
||||
let paths = if src.is_dir() {
|
||||
let mut paths = Vec::new();
|
||||
@@ -73,13 +64,6 @@ impl Core {
|
||||
std::process::exit(1);
|
||||
}
|
||||
|
||||
let mut imported = paths
|
||||
.iter()
|
||||
.map(|path| KeyValueReader::new(path).subspace)
|
||||
.collect::<Vec<_>>();
|
||||
imported.sort_unstable();
|
||||
imported.dedup();
|
||||
|
||||
let mut tasks = Vec::new();
|
||||
for path in paths {
|
||||
let storage = self.storage.clone();
|
||||
@@ -92,54 +76,6 @@ impl Core {
|
||||
for task in tasks {
|
||||
task.await.failed("Failed to wait for task");
|
||||
}
|
||||
|
||||
imported
|
||||
}
|
||||
|
||||
/// inbuxa: an export never carries the full-text index. It is built by
|
||||
/// and for one search backend (the SQL stores index into their own
|
||||
/// tables, the key-value stores into a subspace, external engines keep it
|
||||
/// themselves), so it would be wrong or unreadable after a move to
|
||||
/// another one. Instead, an import queues the same reindex tasks an
|
||||
/// administrator can queue by hand (`reindexAccounts` and
|
||||
/// `reindexTelemetry` store maintenance), and the server rebuilds the
|
||||
/// index for whatever search store it is configured with once it starts.
|
||||
pub async fn queue_reindex(&self, imported: &[u8]) -> Vec<TaskStoreMaintenanceType> {
|
||||
let mut queued = Vec::new();
|
||||
if imported.contains(&SUBSPACE_PROPERTY) {
|
||||
queued.push(TaskStoreMaintenanceType::ReindexAccounts);
|
||||
}
|
||||
if imported.contains(&SUBSPACE_TELEMETRY_SPAN) {
|
||||
queued.push(TaskStoreMaintenanceType::ReindexTelemetry);
|
||||
}
|
||||
if queued.is_empty() {
|
||||
return queued;
|
||||
}
|
||||
|
||||
let mut batch = BatchBuilder::new();
|
||||
for maintenance_type in &queued {
|
||||
batch.schedule_task(Task::StoreMaintenance(TaskStoreMaintenance {
|
||||
maintenance_type: *maintenance_type,
|
||||
status: TaskStatus::now(),
|
||||
shard_index: None,
|
||||
}));
|
||||
}
|
||||
self.storage
|
||||
.data
|
||||
.write(batch.build_all())
|
||||
.await
|
||||
.failed("Failed to queue the reindex tasks");
|
||||
|
||||
println!(
|
||||
"Queued {} to rebuild the search index; it runs when the server starts.",
|
||||
queued
|
||||
.iter()
|
||||
.map(|t| t.as_str())
|
||||
.collect::<Vec<_>>()
|
||||
.join(" and ")
|
||||
);
|
||||
|
||||
queued
|
||||
}
|
||||
}
|
||||
|
||||
@@ -189,22 +125,17 @@ async fn restore_file(store: Store, blob_store: BlobStore, path: &Path) {
|
||||
}
|
||||
SUBSPACE_COUNTER | SUBSPACE_QUOTA => {
|
||||
while let Some((key, value)) = reader.next() {
|
||||
let class = ValueClass::Any(AnyClass {
|
||||
batch.add(
|
||||
ValueClass::Any(AnyClass {
|
||||
subspace: reader.subspace,
|
||||
key,
|
||||
});
|
||||
let value = u64::from_le_bytes(
|
||||
}),
|
||||
u64::from_le_bytes(
|
||||
value
|
||||
.try_into()
|
||||
.expect("Failed to deserialize counter/quota"),
|
||||
) as i64;
|
||||
// inbuxa: the SQL stores add a negative amount with an UPDATE,
|
||||
// which does nothing to a row that isn't there yet, so a
|
||||
// negative counter vanished on import. Create the row first.
|
||||
if value < 0 {
|
||||
batch.add(class.clone(), 0);
|
||||
}
|
||||
batch.add(class, value);
|
||||
) as i64,
|
||||
);
|
||||
if batch.is_large_batch() {
|
||||
store
|
||||
.write(batch.build_all())
|
||||
|
||||
@@ -427,24 +427,9 @@ pub(crate) async fn trace_query(
|
||||
}
|
||||
None => false,
|
||||
},
|
||||
// The queue id column is an integer on every search backend, and
|
||||
// holds a trace's first queue id; the keywords carry all of them
|
||||
Property::QueueId => match value
|
||||
.as_str()
|
||||
.and_then(|v| v.trim().parse::<u64>().ok())
|
||||
.or_else(|| value.as_u64())
|
||||
{
|
||||
Property::QueueId => match value.as_str() {
|
||||
Some(queue_id) => {
|
||||
search.extend([
|
||||
SearchFilter::Or,
|
||||
SearchFilter::eq(TracingSearchField::QueueId, queue_id),
|
||||
SearchFilter::has_text(
|
||||
TracingSearchField::Keywords,
|
||||
queue_id.to_string(),
|
||||
nlp::language::Language::None,
|
||||
),
|
||||
SearchFilter::End,
|
||||
]);
|
||||
search.push(SearchFilter::eq(TracingSearchField::QueueId, queue_id.to_string()));
|
||||
true
|
||||
}
|
||||
None => false,
|
||||
|
||||
@@ -2,6 +2,8 @@
|
||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||
*
|
||||
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||
*/
|
||||
|
||||
use crate::{
|
||||
@@ -15,22 +17,42 @@ use jmap_proto::{error::set::SetError, types::state::State};
|
||||
use jmap_tools::{Key, Value};
|
||||
use registry::{
|
||||
jmap::IntoValue,
|
||||
schema::prelude::{Object, ObjectInner, ObjectType, Property},
|
||||
schema::{
|
||||
prelude::{Object, ObjectInner, ObjectType, Property},
|
||||
structs::Task,
|
||||
},
|
||||
types::{EnumImpl, datetime::UTCDateTime},
|
||||
};
|
||||
use services::task_manager::lock::TaskLockManager;
|
||||
use smtp::reporting::index::{ExternalReportIndex, InternalReportIndex};
|
||||
use std::str::FromStr;
|
||||
use store::{
|
||||
U64_LEN, ValueKey,
|
||||
registry::{RegistryFilter, RegistryFilterValue, RegistryQuery},
|
||||
write::{BatchBuilder, RegistryClass, ValueClass, key::KeySerializer},
|
||||
write::{BatchBuilder, RegistryClass, TaskQueueClass, ValueClass, key::KeySerializer},
|
||||
};
|
||||
use trc::AddContext;
|
||||
use types::id::Id;
|
||||
|
||||
pub(crate) async fn report_set(
|
||||
mut set: RegistrySetResponse<'_>,
|
||||
set: RegistrySetResponse<'_>,
|
||||
) -> trc::Result<RegistrySetResponse<'_>> {
|
||||
// inbuxa: task locks taken to reschedule reports are released however
|
||||
// the request ends; a held lock is renewed, so a leaked one would keep
|
||||
// the report's task from ever running
|
||||
let server = set.server;
|
||||
let mut locked_tasks = Vec::new();
|
||||
let result = report_set_locked(set, &mut locked_tasks).await;
|
||||
for task_id in locked_tasks {
|
||||
server.remove_index_lock(task_id).await;
|
||||
}
|
||||
result
|
||||
}
|
||||
|
||||
async fn report_set_locked<'x>(
|
||||
mut set: RegistrySetResponse<'x>,
|
||||
locked_tasks: &mut Vec<u64>,
|
||||
) -> trc::Result<RegistrySetResponse<'x>> {
|
||||
let object_id = set.object_type.to_id();
|
||||
|
||||
// Reports cannot be created
|
||||
@@ -89,12 +111,45 @@ pub(crate) async fn report_set(
|
||||
.get_value::<Object>(ValueKey::from(key.clone()))
|
||||
.await?
|
||||
{
|
||||
// inbuxa: the report's task shares its id. Hold the task
|
||||
// while its queue rows move, as x:Task/set does, and move the
|
||||
// row the task is actually queued under
|
||||
if !set.server.try_lock_task(item_id).await {
|
||||
set.response.not_updated.append(
|
||||
id,
|
||||
SetError::forbidden().with_description(
|
||||
"The report is being sent and cannot be rescheduled".to_string(),
|
||||
),
|
||||
);
|
||||
continue;
|
||||
}
|
||||
locked_tasks.push(item_id);
|
||||
let queued = set
|
||||
.server
|
||||
.store()
|
||||
.get_value::<Task>(ValueKey::from(ValueClass::TaskQueue(
|
||||
TaskQueueClass::Task { id: item_id },
|
||||
)))
|
||||
.await?;
|
||||
|
||||
match &mut report_obj.inner {
|
||||
ObjectInner::DmarcInternalReport(report) => {
|
||||
report.reschedule_ops(&mut batch, item_id, report_obj.revision, deliver_at);
|
||||
report.reschedule_ops(
|
||||
&mut batch,
|
||||
item_id,
|
||||
report_obj.revision,
|
||||
deliver_at,
|
||||
queued.as_ref(),
|
||||
);
|
||||
}
|
||||
ObjectInner::TlsInternalReport(report) => {
|
||||
report.reschedule_ops(&mut batch, item_id, report_obj.revision, deliver_at);
|
||||
report.reschedule_ops(
|
||||
&mut batch,
|
||||
item_id,
|
||||
report_obj.revision,
|
||||
deliver_at,
|
||||
queued.as_ref(),
|
||||
);
|
||||
}
|
||||
_ => {}
|
||||
}
|
||||
@@ -156,6 +211,9 @@ pub(crate) async fn report_set(
|
||||
.write(batch.build_all())
|
||||
.await
|
||||
.caused_by(trc::location!())?;
|
||||
// inbuxa: a rescheduled report may now be due sooner than the task
|
||||
// manager's next scan
|
||||
set.server.notify_task_queue();
|
||||
}
|
||||
|
||||
Ok(set)
|
||||
|
||||
@@ -463,15 +463,10 @@ pub(crate) async fn task_query(
|
||||
.set_values(typ.is_some()),
|
||||
|key, value| {
|
||||
if let Some(typ) = typ {
|
||||
let task_type =
|
||||
TaskType::from_id(value.deserialize_be_u16(0)?).ok_or_else(|| {
|
||||
trc::StoreEvent::DataCorruption
|
||||
.into_err()
|
||||
.ctx(trc::Key::Key, key.to_vec())
|
||||
.ctx(trc::Key::Value, value.to_vec())
|
||||
.caused_by(trc::location!())
|
||||
})?;
|
||||
if task_type != typ {
|
||||
// inbuxa: a row whose type can't be read matches no type
|
||||
// filter; the task manager logs and repairs it
|
||||
let task_type = value.deserialize_be_u16(0).ok().and_then(TaskType::from_id);
|
||||
if task_type != Some(typ) {
|
||||
return Ok(true);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -26,7 +26,7 @@ pub fn spawn_broadcast_subscriber(inner: Arc<Inner>, mut shutdown_rx: watch::Rec
|
||||
};
|
||||
|
||||
tokio::spawn(async move {
|
||||
let mut retry_count: u32 = 0;
|
||||
let mut retry_count = 0;
|
||||
|
||||
trc::event!(Cluster(ClusterEvent::SubscriberStart));
|
||||
|
||||
@@ -53,7 +53,7 @@ pub fn spawn_broadcast_subscriber(inner: Arc<Inner>, mut shutdown_rx: watch::Rec
|
||||
);
|
||||
|
||||
match tokio::time::timeout(
|
||||
subscribe_retry_delay(retry_count),
|
||||
Duration::from_secs(1 << retry_count.max(6)),
|
||||
shutdown_rx.changed(),
|
||||
)
|
||||
.await
|
||||
@@ -62,7 +62,7 @@ pub fn spawn_broadcast_subscriber(inner: Arc<Inner>, mut shutdown_rx: watch::Rec
|
||||
break;
|
||||
}
|
||||
Err(_) => {
|
||||
retry_count = retry_count.saturating_add(1);
|
||||
retry_count += 1;
|
||||
continue;
|
||||
}
|
||||
}
|
||||
@@ -234,11 +234,6 @@ pub fn spawn_broadcast_subscriber(inner: Arc<Inner>, mut shutdown_rx: watch::Rec
|
||||
});
|
||||
}
|
||||
|
||||
/// Delay before the next subscribe attempt: 1 s, 2 s, 4 s ... capped at 64 s.
|
||||
fn subscribe_retry_delay(retry_count: u32) -> Duration {
|
||||
Duration::from_secs(1u64 << retry_count.min(6))
|
||||
}
|
||||
|
||||
fn log_event(event: &BroadcastEvent) -> trc::Value {
|
||||
match event {
|
||||
BroadcastEvent::PushNotification(notification) => match notification {
|
||||
@@ -301,19 +296,3 @@ fn log_event(event: &BroadcastEvent) -> trc::Value {
|
||||
BroadcastEvent::QueueRefresh => "QueueRefresh".into(),
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::subscribe_retry_delay;
|
||||
use std::time::Duration;
|
||||
|
||||
#[test]
|
||||
fn subscribe_retry_backoff_grows_then_caps() {
|
||||
let schedule: Vec<u64> = (0..10)
|
||||
.map(|n| subscribe_retry_delay(n).as_secs())
|
||||
.collect();
|
||||
assert_eq!(schedule, vec![1, 2, 4, 8, 16, 32, 64, 64, 64, 64]);
|
||||
// No shift overflow at the top of the range.
|
||||
assert_eq!(subscribe_retry_delay(u32::MAX), Duration::from_secs(64));
|
||||
}
|
||||
}
|
||||
|
||||
@@ -567,14 +567,20 @@ async fn build_contact_document(
|
||||
}
|
||||
|
||||
|
||||
// inbuxa: MON-16: a trace's search document, when trace search is on
|
||||
// inbuxa: MON-16: a trace's search document, when trace search is on:
|
||||
// its event types, queue ids, and addresses, their domains, hosts, IPs,
|
||||
// message ids and account names as keywords
|
||||
async fn build_tracing_span_document(
|
||||
server: &Server,
|
||||
span_id: u64,
|
||||
) -> trc::Result<Option<IndexDocument>> {
|
||||
use common::telemetry::tracers::store::MaybeTrace;
|
||||
use registry::schema::structs::Search;
|
||||
use store::write::{TelemetryClass, ValueClass};
|
||||
use registry::schema::{enums::SearchTracingField, structs::Search};
|
||||
use store::{
|
||||
search::TracingSearchField,
|
||||
write::{TelemetryClass, ValueClass},
|
||||
};
|
||||
use trc::Key;
|
||||
|
||||
let settings = server
|
||||
.registry()
|
||||
@@ -584,6 +590,7 @@ async fn build_tracing_span_document(
|
||||
if !settings.index_telemetry {
|
||||
return Ok(None);
|
||||
}
|
||||
let wants = |field: SearchTracingField| settings.index_tracing_fields.iter().any(|f| *f == field);
|
||||
let Some(MaybeTrace(Some(trace))) = server
|
||||
.tracing_store()
|
||||
.get_value::<MaybeTrace>(ValueKey::from(ValueClass::Telemetry(TelemetryClass::Span(
|
||||
@@ -594,67 +601,23 @@ async fn build_tracing_span_document(
|
||||
return Ok(None);
|
||||
};
|
||||
|
||||
Ok(Some(trace_search_document(
|
||||
span_id,
|
||||
&trace,
|
||||
&settings
|
||||
.index_tracing_fields
|
||||
.iter()
|
||||
.copied()
|
||||
.collect::<Vec<_>>(),
|
||||
)))
|
||||
}
|
||||
|
||||
/// inbuxa: MON-16: the search document for a stored trace.
|
||||
///
|
||||
/// The event type and queue id columns are integers on every search backend
|
||||
/// (BIGINT on PostgreSQL and MySQL, long on Elasticsearch), and each holds a
|
||||
/// single value per trace: the event type is the trace's opening event, the
|
||||
/// one `x:Trace/query` filters on, and the queue id is the first queue id the
|
||||
/// trace mentions. Every queue id also goes into the keywords, so a session
|
||||
/// that queued several messages is found by any of them.
|
||||
pub fn trace_search_document(
|
||||
span_id: u64,
|
||||
trace: ®istry::schema::structs::Trace,
|
||||
fields: &[registry::schema::enums::SearchTracingField],
|
||||
) -> IndexDocument {
|
||||
use registry::schema::{enums::SearchTracingField, structs::TraceValue};
|
||||
use store::search::TracingSearchField;
|
||||
use trc::Key;
|
||||
|
||||
let wants = |field: SearchTracingField| fields.contains(&field);
|
||||
let mut document = IndexDocument::new(SearchIndex::Tracing).with_id(span_id);
|
||||
if wants(SearchTracingField::EventType)
|
||||
&& let Some(first) = trace.events.iter().next()
|
||||
{
|
||||
document.index_unsigned(TracingSearchField::EventType, first.event.to_id() as u64);
|
||||
}
|
||||
|
||||
let mut seen = store::ahash::AHashSet::new();
|
||||
let mut queue_id_indexed = false;
|
||||
for event in trace.events.iter() {
|
||||
if wants(SearchTracingField::EventType) && seen.insert(event.event.as_str().to_string()) {
|
||||
document.index_keyword(TracingSearchField::EventType, event.event.as_str());
|
||||
}
|
||||
for kv in event.key_values.iter() {
|
||||
let text = match &kv.value {
|
||||
TraceValue::String(v) => v.value.clone(),
|
||||
TraceValue::UnsignedInt(v) => v.value.to_string(),
|
||||
TraceValue::IpAddr(v) => v.value.to_string(),
|
||||
registry::schema::structs::TraceValue::String(v) => v.value.clone(),
|
||||
registry::schema::structs::TraceValue::UnsignedInt(v) => v.value.to_string(),
|
||||
registry::schema::structs::TraceValue::IpAddr(v) => v.value.to_string(),
|
||||
_ => continue,
|
||||
};
|
||||
match kv.key {
|
||||
Key::QueueId => {
|
||||
let Ok(queue_id) = text.parse::<u64>() else {
|
||||
continue;
|
||||
};
|
||||
if wants(SearchTracingField::QueueId) && !queue_id_indexed {
|
||||
document.index_unsigned(TracingSearchField::QueueId, queue_id);
|
||||
queue_id_indexed = true;
|
||||
}
|
||||
if wants(SearchTracingField::Keywords) && seen.insert(format!("k:{text}")) {
|
||||
document.index_text(
|
||||
TracingSearchField::Keywords,
|
||||
&text,
|
||||
nlp::language::Language::None,
|
||||
);
|
||||
Key::QueueId if wants(SearchTracingField::QueueId) => {
|
||||
if seen.insert(format!("q:{text}")) {
|
||||
document.index_keyword(TracingSearchField::QueueId, &text);
|
||||
}
|
||||
}
|
||||
Key::From
|
||||
@@ -685,7 +648,7 @@ pub fn trace_search_document(
|
||||
}
|
||||
}
|
||||
}
|
||||
document
|
||||
Ok(Some(document))
|
||||
}
|
||||
|
||||
// inbuxa: UD-1, UD-4: archives a deleted file, event or contact noted at
|
||||
|
||||
@@ -2,6 +2,8 @@
|
||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||
*
|
||||
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||
*/
|
||||
|
||||
use crate::task_manager::acme::AcmeTask;
|
||||
@@ -27,6 +29,7 @@ use common::network::limiter::ConcurrencyLimiter;
|
||||
use common::network::{ServerInstance, TcpAcceptor};
|
||||
use common::{Inner, Server};
|
||||
use registry::schema::enums::TaskType;
|
||||
use registry::schema::prelude::ObjectType;
|
||||
use registry::schema::structs::{
|
||||
Task, TaskManager, TaskRetryStrategy, TaskStatus, TaskStatusFailed, TaskStatusRetry,
|
||||
};
|
||||
@@ -337,6 +340,7 @@ impl TaskQueueManager for Server {
|
||||
|
||||
// Retrieve tasks pending to be processed
|
||||
let mut tasks = Vec::new();
|
||||
let mut unreadable = Vec::new();
|
||||
let now = Instant::now();
|
||||
let mut next_event = None;
|
||||
let roles = &self.core.network.roles;
|
||||
@@ -351,12 +355,21 @@ impl TaskQueueManager for Server {
|
||||
let task_id = key.deserialize_be_u64(U64_LEN)?;
|
||||
|
||||
if task_due <= now_timestamp {
|
||||
let task_type_idx = value.deserialize_be_u16(0)?;
|
||||
let task_type = TaskType::from_id(task_type_idx).ok_or_else(|| {
|
||||
trc::StoreEvent::DataCorruption
|
||||
.caused_by(trc::location!())
|
||||
.ctx(trc::Key::Value, value)
|
||||
})?;
|
||||
// inbuxa: a row whose task type can't be read is
|
||||
// set aside, not allowed to end the scan: every
|
||||
// task due after it would wait behind it
|
||||
let Some((task_type_idx, task_type)) = value
|
||||
.deserialize_be_u16(0)
|
||||
.ok()
|
||||
.and_then(|idx| TaskType::from_id(idx).map(|typ| (idx, typ)))
|
||||
else {
|
||||
unreadable.push(UnreadableDueRow {
|
||||
due: task_due,
|
||||
id: task_id,
|
||||
value: value.to_vec(),
|
||||
});
|
||||
return Ok(true);
|
||||
};
|
||||
let enabled = match task_type {
|
||||
TaskType::IndexDocument
|
||||
| TaskType::UnindexDocument
|
||||
@@ -446,6 +459,11 @@ impl TaskQueueManager for Server {
|
||||
);
|
||||
});
|
||||
|
||||
if !unreadable.is_empty() && repair_due_rows(self, unreadable).await {
|
||||
// Look again at once for the rows that were rewritten
|
||||
self.notify_task_queue();
|
||||
}
|
||||
|
||||
if !tasks.is_empty() {
|
||||
trc::event!(
|
||||
TaskManager(TaskManagerEvent::TaskAcquired),
|
||||
@@ -686,3 +704,114 @@ impl TaskResult {
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
/// inbuxa: a task queue row whose task type could not be read.
|
||||
struct UnreadableDueRow {
|
||||
due: u64,
|
||||
id: u64,
|
||||
value: Vec<u8>,
|
||||
}
|
||||
|
||||
/// inbuxa: logs each unreadable queue row and repairs it from the task it
|
||||
/// schedules. The task row says what the task is, so the queue row is
|
||||
/// rewritten with that task's type; a row with no task behind it is removed.
|
||||
///
|
||||
/// Rescheduling an internal DMARC or TLS report wrote the report's object
|
||||
/// type into the queue row instead of the task type. Such a row is the time
|
||||
/// an administrator chose, so the task is moved to it as the reschedule
|
||||
/// meant to do: the task row takes that due, and a queue row left at the
|
||||
/// task's previous due is removed. Returns whether any row was repaired.
|
||||
async fn repair_due_rows(server: &Server, rows: Vec<UnreadableDueRow>) -> bool {
|
||||
let mut repaired = false;
|
||||
for row in rows {
|
||||
let UnreadableDueRow { due, id, value } = row;
|
||||
trc::error!(
|
||||
trc::StoreEvent::DataCorruption
|
||||
.into_err()
|
||||
.id(id)
|
||||
.ctx(trc::Key::Due, trc::Value::Timestamp(due))
|
||||
.ctx(
|
||||
trc::Key::Key,
|
||||
[due.to_be_bytes(), id.to_be_bytes()].concat()
|
||||
)
|
||||
.ctx(trc::Key::Value, value.clone())
|
||||
.details("Unreadable task queue row skipped")
|
||||
.caused_by(trc::location!())
|
||||
);
|
||||
|
||||
let task_key = ValueClass::TaskQueue(TaskQueueClass::Task { id });
|
||||
let due_key = ValueClass::TaskQueue(TaskQueueClass::Due { id, due });
|
||||
let task = match server
|
||||
.store()
|
||||
.get_value::<Task>(ValueKey::from(task_key.clone()))
|
||||
.await
|
||||
{
|
||||
Ok(task) => task,
|
||||
Err(err) => {
|
||||
trc::error!(
|
||||
err.id(id)
|
||||
.details("Failed to read the task of an unreadable queue row.")
|
||||
.caused_by(trc::location!())
|
||||
);
|
||||
continue;
|
||||
}
|
||||
};
|
||||
|
||||
let mut batch = BatchBuilder::new();
|
||||
let action = if let Some(mut task) = task {
|
||||
let task_type = task.object_type();
|
||||
batch.assert_value(task_key.clone(), AssertValue::Some);
|
||||
if rescheduled_report_type(&value) == Some(task_type) {
|
||||
let old_due = task.due_timestamp();
|
||||
if old_due != due {
|
||||
batch.clear(ValueClass::TaskQueue(TaskQueueClass::Due {
|
||||
id,
|
||||
due: old_due,
|
||||
}));
|
||||
}
|
||||
task.set_status(TaskStatus::at(due as i64));
|
||||
}
|
||||
batch
|
||||
.set(due_key, task_type.to_id().serialize())
|
||||
.set(task_key, task.to_pickled_vec());
|
||||
"Rewrote the queue row from its task."
|
||||
} else {
|
||||
batch.clear(due_key);
|
||||
"Removed a queue row with no task."
|
||||
};
|
||||
|
||||
match server.store().write(batch.build_all()).await {
|
||||
Ok(_) => {
|
||||
repaired = true;
|
||||
trc::event!(
|
||||
TaskManager(TaskManagerEvent::TaskIgnored),
|
||||
Id = id,
|
||||
Due = trc::Value::Timestamp(due),
|
||||
Reason = action,
|
||||
);
|
||||
}
|
||||
Err(err) if err.matches(trc::EventType::Store(trc::StoreEvent::AssertValueFailed)) => {
|
||||
// The task went away meanwhile; the next scan looks again
|
||||
}
|
||||
Err(err) => {
|
||||
trc::error!(
|
||||
err.id(id)
|
||||
.details("Failed to repair an unreadable queue row.")
|
||||
.caused_by(trc::location!())
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
repaired
|
||||
}
|
||||
|
||||
/// inbuxa: the task type a report reschedule meant, when a queue row holds
|
||||
/// an internal report's object type (the value that reschedule wrote).
|
||||
fn rescheduled_report_type(value: &[u8]) -> Option<TaskType> {
|
||||
let id = u16::from_be_bytes(value.get(..2)?.try_into().ok()?);
|
||||
match ObjectType::from_id(id)? {
|
||||
ObjectType::DmarcInternalReport => Some(TaskType::DmarcReport),
|
||||
ObjectType::TlsInternalReport => Some(TaskType::TlsReport),
|
||||
_ => None,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -2,6 +2,8 @@
|
||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||
*
|
||||
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||
*/
|
||||
|
||||
use registry::{
|
||||
@@ -40,35 +42,49 @@ pub trait InternalReportIndex: ObjectImpl {
|
||||
|
||||
fn primary_key(&self) -> ValueClass;
|
||||
|
||||
/// Moves the report's delivery, and its queued task, to `at`.
|
||||
///
|
||||
/// inbuxa: the new queue row carries the task's type, as
|
||||
/// `schedule_task_with_id` writes it, and the task row gets the new due
|
||||
/// too. `queued` is the task as stored: its due, not the report's
|
||||
/// `deliverAt`, is the queue row that exists (they differ once the task
|
||||
/// has been retried).
|
||||
fn reschedule_ops(
|
||||
&mut self,
|
||||
batch: &mut BatchBuilder,
|
||||
item_id: u64,
|
||||
revision: u64,
|
||||
at: UTCDateTime,
|
||||
queued: Option<&Task>,
|
||||
) {
|
||||
let current_deliver_at = self.deliver_at();
|
||||
let current_due = current_deliver_at.timestamp() as u64;
|
||||
let queued_due = queued.map_or(current_due, |task| task.due_timestamp());
|
||||
let new_due = at.timestamp() as u64;
|
||||
|
||||
if current_deliver_at != at {
|
||||
if current_deliver_at != at || queued_due != new_due {
|
||||
let object = Self::OBJECT;
|
||||
let object_id = object.to_id();
|
||||
let key = ValueClass::Registry(RegistryClass::Item { object_id, item_id });
|
||||
|
||||
self.set_deliver_at(at);
|
||||
|
||||
batch.assert_value(key.clone(), AssertValue::Hash(revision));
|
||||
if queued_due != new_due {
|
||||
batch.clear(ValueClass::TaskQueue(TaskQueueClass::Due {
|
||||
id: item_id,
|
||||
due: queued_due,
|
||||
}));
|
||||
}
|
||||
// A row an earlier reschedule left at the report's deliverAt
|
||||
if current_due != new_due && current_due != queued_due {
|
||||
batch.clear(ValueClass::TaskQueue(TaskQueueClass::Due {
|
||||
id: item_id,
|
||||
due: current_due,
|
||||
}));
|
||||
}
|
||||
batch
|
||||
.assert_value(key.clone(), AssertValue::Hash(revision))
|
||||
.clear(ValueClass::TaskQueue(TaskQueueClass::Due {
|
||||
id: item_id,
|
||||
due: current_deliver_at.timestamp() as u64,
|
||||
}))
|
||||
.set(
|
||||
ValueClass::TaskQueue(TaskQueueClass::Due {
|
||||
id: item_id,
|
||||
due: at.timestamp() as u64,
|
||||
}),
|
||||
object_id.serialize(),
|
||||
)
|
||||
.schedule_task_with_id(item_id, self.task(item_id))
|
||||
.set(key, self.to_pickled_vec());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -81,7 +81,7 @@ fn legacy_setting(name: &str, is_set: impl Fn(&str) -> bool) -> Option<String> {
|
||||
#[macro_export]
|
||||
macro_rules! brand_version {
|
||||
() => {
|
||||
"2026.9.24.3"
|
||||
"2026.9.24.4"
|
||||
};
|
||||
}
|
||||
|
||||
|
||||
@@ -212,15 +212,10 @@ unchanged.
|
||||
- **MON-16.** With `indexTelemetry` on, storing a trace schedules an
|
||||
`IndexTrace` task. The task builds one document for `SearchIndex::Tracing`
|
||||
with the fields named in `indexTracingFields`:
|
||||
- `eventType`: the trace's opening event, as its numeric id;
|
||||
- `queueId`: the first `queueId` value, as an integer;
|
||||
- `eventType`: every event type in the trace;
|
||||
- `queueId`: every `queueId` value;
|
||||
- `keywords`: every address in `from` and `to`, each address's domain, every
|
||||
`domain`, `hostname`, `remoteIp`, `messageId` and `accountName` value,
|
||||
and every `queueId` value.
|
||||
The event type and queue id are single integer columns on every search
|
||||
backend (BIGINT on PostgreSQL and MySQL), so the `queueId` filter matches
|
||||
the column or any queue id in the keywords, and a session that queued
|
||||
several messages is found by each of them.
|
||||
`domain`, `hostname`, `remoteIp`, `messageId` and `accountName` value.
|
||||
So searching `example.org` finds every trace to or from that domain, as the
|
||||
upstream suite expects. With `indexTelemetry` off nothing is indexed, and
|
||||
the `text` and `queueId` filters are refused (see "Interfaces").
|
||||
|
||||
@@ -2,9 +2,12 @@
|
||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||
*
|
||||
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||
*/
|
||||
|
||||
pub mod analyze;
|
||||
pub mod dmarc;
|
||||
pub mod reschedule; // inbuxa: report reschedules and unreadable queue rows
|
||||
pub mod scheduler;
|
||||
pub mod tls;
|
||||
|
||||
@@ -0,0 +1,370 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only
|
||||
*/
|
||||
|
||||
//! Rescheduling an internal DMARC or TLS report over JMAP moves its task: the
|
||||
//! task runs at the new time, x:Task/get shows the new due, and tasks due
|
||||
//! after it still run. A task queue row whose type can't be read is logged
|
||||
//! and repaired rather than stopping every task due after it, including the
|
||||
//! rows an earlier reschedule wrote with the report's object type.
|
||||
|
||||
use crate::utils::server::{TestServer, TestServerBuilder};
|
||||
use common::{
|
||||
Server,
|
||||
config::smtp::report::AggregateFrequency,
|
||||
ipc::{DmarcEvent, PolicyType, TlsEvent},
|
||||
};
|
||||
use mail_auth::{
|
||||
common::parse::TxtRecordParser,
|
||||
dmarc::Dmarc,
|
||||
mta_sts::TlsRpt,
|
||||
report::{ActionDisposition, DmarcResult, Record},
|
||||
};
|
||||
use registry::{
|
||||
schema::{
|
||||
enums::{TaskStoreMaintenanceType, TaskType},
|
||||
prelude::{ObjectType, Property},
|
||||
structs::{
|
||||
DmarcInternalReport, DmarcReportSettings, Expression, Task, TaskStatus,
|
||||
TaskStoreMaintenance, TlsInternalReport, TlsReportSettings,
|
||||
},
|
||||
},
|
||||
types::{EnumImpl, ObjectImpl, datetime::UTCDateTime},
|
||||
};
|
||||
use serde_json::json;
|
||||
use smtp::reporting::{index::InternalReportIndex, send::MtaReportSend};
|
||||
use std::{
|
||||
sync::Arc,
|
||||
time::{Duration, Instant},
|
||||
};
|
||||
use store::{
|
||||
SerializeInfallible, ValueKey,
|
||||
write::{BatchBuilder, RegistryClass, TaskQueueClass, ValueClass, now},
|
||||
};
|
||||
use types::id::Id;
|
||||
use utils::snowflake::SnowflakeIdGenerator;
|
||||
|
||||
#[tokio::test(flavor = "multi_thread")]
|
||||
#[serial_test::serial]
|
||||
async fn report_reschedule() {
|
||||
let mut test = TestServerBuilder::new("smtp_report_reschedule")
|
||||
.await
|
||||
.with_http_listener(19057)
|
||||
.await
|
||||
.capture_queue()
|
||||
.build()
|
||||
.await;
|
||||
|
||||
let admin = test.account("admin");
|
||||
admin
|
||||
.registry_create_object(TlsReportSettings {
|
||||
max_report_size: Expression {
|
||||
else_: "1024".into(),
|
||||
..Default::default()
|
||||
},
|
||||
..Default::default()
|
||||
})
|
||||
.await;
|
||||
admin
|
||||
.registry_create_object(DmarcReportSettings {
|
||||
aggregate_max_report_size: Expression {
|
||||
else_: "1024".into(),
|
||||
..Default::default()
|
||||
},
|
||||
..Default::default()
|
||||
})
|
||||
.await;
|
||||
admin.reload_settings().await;
|
||||
test.reload_core();
|
||||
test.expect_reload_settings().await;
|
||||
let admin = test.account("admin");
|
||||
|
||||
// A daily DMARC and TLS report, due a day from now
|
||||
schedule_dmarc(&test, "foobar.org").await;
|
||||
schedule_tls(&test, "foobar.org").await;
|
||||
let dmarc_id = wait_for_report::<DmarcInternalReport>(&test, "foobar.org").await;
|
||||
let tls_id = wait_for_report::<TlsInternalReport>(&test, "foobar.org").await;
|
||||
|
||||
// Reschedule both to a few seconds from now, with a task due after them
|
||||
let at = now() + 3;
|
||||
let later = marker_task(&test.server, at + 3).await;
|
||||
for (object, id, task_type) in [
|
||||
(
|
||||
ObjectType::DmarcInternalReport,
|
||||
dmarc_id,
|
||||
TaskType::DmarcReport,
|
||||
),
|
||||
(ObjectType::TlsInternalReport, tls_id, TaskType::TlsReport),
|
||||
] {
|
||||
admin
|
||||
.registry_update_object(
|
||||
object,
|
||||
id,
|
||||
json!({
|
||||
Property::DeliverAt: UTCDateTime::from_timestamp(at as i64),
|
||||
}),
|
||||
)
|
||||
.await;
|
||||
|
||||
// x:Task/get shows the new due, and the queue row carries the task's
|
||||
// type. Upstream wrote the report's object type there and left the
|
||||
// task at its old due
|
||||
let task = admin.registry_get::<Task>(id).await;
|
||||
assert_eq!(task.object_type(), task_type);
|
||||
assert_eq!(
|
||||
task.due_timestamp(),
|
||||
at,
|
||||
"{object:?} task due not moved: {task:?}"
|
||||
);
|
||||
assert_eq!(
|
||||
queue_row(&test.server, id.id(), at).await,
|
||||
Some(task_type.to_id().serialize()),
|
||||
"{object:?} queue row"
|
||||
);
|
||||
}
|
||||
|
||||
// Both reports go out at the new time, and the later task still runs
|
||||
wait_until_run(&test.server, &[dmarc_id.id(), tls_id.id(), later]).await;
|
||||
assert!(now() >= at, "the reports went out before their new time");
|
||||
assert!(
|
||||
admin
|
||||
.registry_get_all::<DmarcInternalReport>()
|
||||
.await
|
||||
.is_empty()
|
||||
);
|
||||
assert!(
|
||||
admin
|
||||
.registry_get_all::<TlsInternalReport>()
|
||||
.await
|
||||
.is_empty()
|
||||
);
|
||||
|
||||
// Rows an earlier reschedule may have left in a store: one with the
|
||||
// report's object type and the task left at its old due, and one that
|
||||
// is unreadable and has no task behind it. Neither may hold back a task
|
||||
// due after them.
|
||||
schedule_dmarc(&test, "foobar.net").await;
|
||||
let dmarc_id = wait_for_report::<DmarcInternalReport>(&test, "foobar.net").await;
|
||||
let at = now() + 2;
|
||||
let old_due = old_style_reschedule(&test.server, dmarc_id.id(), at).await;
|
||||
let orphan = SnowflakeIdGenerator::global_id().unwrap();
|
||||
let mut batch = BatchBuilder::new();
|
||||
batch.set(
|
||||
ValueClass::TaskQueue(TaskQueueClass::Due {
|
||||
id: orphan,
|
||||
due: at,
|
||||
}),
|
||||
vec![0xff, 0xff],
|
||||
);
|
||||
test.server.store().write(batch.build_all()).await.unwrap();
|
||||
let later = marker_task(&test.server, at + 2).await;
|
||||
|
||||
wait_until_run(&test.server, &[dmarc_id.id(), later]).await;
|
||||
assert!(
|
||||
admin
|
||||
.registry_get_all::<DmarcInternalReport>()
|
||||
.await
|
||||
.is_empty()
|
||||
);
|
||||
assert_eq!(queue_row(&test.server, orphan, at).await, None);
|
||||
assert_eq!(queue_row(&test.server, dmarc_id.id(), at).await, None);
|
||||
assert_eq!(queue_row(&test.server, dmarc_id.id(), old_due).await, None);
|
||||
|
||||
// x:Task/query by type skips an unreadable row rather than failing
|
||||
let mut batch = BatchBuilder::new();
|
||||
let due = now() + 3600;
|
||||
batch.set(
|
||||
ValueClass::TaskQueue(TaskQueueClass::Due { id: orphan, due }),
|
||||
vec![0xff, 0xff],
|
||||
);
|
||||
test.server.store().write(batch.build_all()).await.unwrap();
|
||||
admin
|
||||
.registry_query_ids(
|
||||
ObjectType::Task,
|
||||
vec![(Property::Type, TaskType::DmarcReport.as_str())],
|
||||
Vec::<&str>::new(),
|
||||
)
|
||||
.await;
|
||||
let mut batch = BatchBuilder::new();
|
||||
batch.clear(ValueClass::TaskQueue(TaskQueueClass::Due {
|
||||
id: orphan,
|
||||
due,
|
||||
}));
|
||||
test.server.store().write(batch.build_all()).await.unwrap();
|
||||
|
||||
if test.is_reset() {
|
||||
test.temp_dir.delete();
|
||||
}
|
||||
}
|
||||
|
||||
async fn schedule_dmarc(test: &TestServer, domain: &str) {
|
||||
test.server
|
||||
.schedule_report(DmarcEvent {
|
||||
domain: domain.to_string(),
|
||||
report_record: Record::new()
|
||||
.with_source_ip("192.168.1.2".parse().unwrap())
|
||||
.with_action_disposition(ActionDisposition::Pass)
|
||||
.with_dmarc_dkim_result(DmarcResult::Pass)
|
||||
.with_dmarc_spf_result(DmarcResult::Fail)
|
||||
.with_envelope_from("[email protected]")
|
||||
.with_envelope_to("[email protected]")
|
||||
.with_header_from("[email protected]"),
|
||||
dmarc_record: Arc::new(
|
||||
Dmarc::parse(format!("v=DMARC1; p=reject; rua=mailto:reports@{domain}").as_bytes())
|
||||
.unwrap(),
|
||||
),
|
||||
interval: AggregateFrequency::Daily,
|
||||
span_id: 0,
|
||||
})
|
||||
.await;
|
||||
}
|
||||
|
||||
async fn schedule_tls(test: &TestServer, domain: &str) {
|
||||
test.server
|
||||
.schedule_report(TlsEvent {
|
||||
domain: domain.to_string(),
|
||||
policy: PolicyType::None,
|
||||
failure: None,
|
||||
tls_record: Arc::new(
|
||||
TlsRpt::parse(format!("v=TLSRPTv1;rua=mailto:reports@{domain}").as_bytes())
|
||||
.unwrap(),
|
||||
),
|
||||
interval: AggregateFrequency::Daily,
|
||||
span_id: 0,
|
||||
})
|
||||
.await;
|
||||
}
|
||||
|
||||
trait ReportDomain: ObjectImpl {
|
||||
fn report_domain(&self) -> &str;
|
||||
}
|
||||
|
||||
impl ReportDomain for DmarcInternalReport {
|
||||
fn report_domain(&self) -> &str {
|
||||
&self.domain
|
||||
}
|
||||
}
|
||||
|
||||
impl ReportDomain for TlsInternalReport {
|
||||
fn report_domain(&self) -> &str {
|
||||
&self.domain
|
||||
}
|
||||
}
|
||||
|
||||
async fn wait_for_report<T: ReportDomain>(test: &TestServer, domain: &str) -> Id {
|
||||
let admin = test.account("admin");
|
||||
for _ in 0..100 {
|
||||
if let Some((id, _)) = admin
|
||||
.registry_get_all::<T>()
|
||||
.await
|
||||
.into_iter()
|
||||
.find(|(_, report)| report.report_domain() == domain)
|
||||
{
|
||||
return id;
|
||||
}
|
||||
tokio::time::sleep(Duration::from_millis(100)).await;
|
||||
}
|
||||
panic!("No {} for {domain}", T::OBJECT.as_str());
|
||||
}
|
||||
|
||||
/// A task that succeeds when it runs, due at `due`.
|
||||
async fn marker_task(server: &Server, due: u64) -> u64 {
|
||||
let id = SnowflakeIdGenerator::global_id().unwrap();
|
||||
let mut batch = BatchBuilder::new();
|
||||
batch.schedule_task_with_id(
|
||||
id,
|
||||
Task::StoreMaintenance(TaskStoreMaintenance {
|
||||
maintenance_type: TaskStoreMaintenanceType::RemoveLockDav,
|
||||
shard_index: Some(0),
|
||||
status: TaskStatus::at(due as i64),
|
||||
}),
|
||||
);
|
||||
server.store().write(batch.build_all()).await.unwrap();
|
||||
server.notify_task_queue();
|
||||
id
|
||||
}
|
||||
|
||||
/// What the reschedule before this fix wrote: the report's object type in
|
||||
/// the new queue row, and the task row left at its old due. Returns that
|
||||
/// old due.
|
||||
async fn old_style_reschedule(server: &Server, item_id: u64, at: u64) -> u64 {
|
||||
let object_id = ObjectType::DmarcInternalReport.to_id();
|
||||
let key = ValueClass::Registry(RegistryClass::Item { object_id, item_id });
|
||||
let mut report = server
|
||||
.store()
|
||||
.get_value::<DmarcInternalReport>(ValueKey::from(key.clone()))
|
||||
.await
|
||||
.unwrap()
|
||||
.unwrap();
|
||||
let old_due = report.deliver_at().timestamp() as u64;
|
||||
report.set_deliver_at(UTCDateTime::from_timestamp(at as i64));
|
||||
let mut batch = BatchBuilder::new();
|
||||
batch
|
||||
.clear(ValueClass::TaskQueue(TaskQueueClass::Due {
|
||||
id: item_id,
|
||||
due: old_due,
|
||||
}))
|
||||
.set(
|
||||
ValueClass::TaskQueue(TaskQueueClass::Due {
|
||||
id: item_id,
|
||||
due: at,
|
||||
}),
|
||||
object_id.serialize(),
|
||||
)
|
||||
.set(key, report.to_pickled_vec());
|
||||
server.store().write(batch.build_all()).await.unwrap();
|
||||
server.notify_task_queue();
|
||||
old_due
|
||||
}
|
||||
|
||||
struct RawValue(Vec<u8>);
|
||||
|
||||
impl store::Deserialize for RawValue {
|
||||
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
|
||||
Ok(RawValue(bytes.to_vec()))
|
||||
}
|
||||
}
|
||||
|
||||
async fn queue_row(server: &Server, id: u64, due: u64) -> Option<Vec<u8>> {
|
||||
server
|
||||
.store()
|
||||
.get_value::<RawValue>(ValueKey::from(ValueClass::TaskQueue(TaskQueueClass::Due {
|
||||
id,
|
||||
due,
|
||||
})))
|
||||
.await
|
||||
.unwrap()
|
||||
.map(|raw| raw.0)
|
||||
}
|
||||
|
||||
async fn task_exists(server: &Server, id: u64) -> bool {
|
||||
server
|
||||
.store()
|
||||
.get_value::<Task>(ValueKey::from(ValueClass::TaskQueue(
|
||||
TaskQueueClass::Task { id },
|
||||
)))
|
||||
.await
|
||||
.unwrap()
|
||||
.is_some()
|
||||
}
|
||||
|
||||
async fn wait_until_run(server: &Server, ids: &[u64]) {
|
||||
let started = Instant::now();
|
||||
loop {
|
||||
let mut pending = Vec::new();
|
||||
for id in ids {
|
||||
if task_exists(server, *id).await {
|
||||
pending.push(*id);
|
||||
}
|
||||
}
|
||||
if pending.is_empty() {
|
||||
return;
|
||||
}
|
||||
if started.elapsed() > Duration::from_secs(30) {
|
||||
panic!("tasks {pending:?} never ran");
|
||||
}
|
||||
tokio::time::sleep(Duration::from_millis(200)).await;
|
||||
}
|
||||
}
|
||||
@@ -2,8 +2,6 @@
|
||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||
*
|
||||
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||
*/
|
||||
|
||||
use crate::utils::{
|
||||
@@ -11,22 +9,14 @@ use crate::utils::{
|
||||
server::TestServer,
|
||||
temp_dir::TempDir,
|
||||
};
|
||||
use ::registry::schema::{
|
||||
enums::{CompressionAlgo, TaskStoreMaintenanceType},
|
||||
prelude::ObjectType,
|
||||
structs::Task,
|
||||
};
|
||||
use ::registry::schema::enums::CompressionAlgo;
|
||||
use ahash::AHashSet;
|
||||
use common::{
|
||||
DATABASE_SCHEMA_VERSION,
|
||||
manager::{SPAM_CLASSIFIER_KEY, SPAM_TRAINER_KEY, backup::BackupParams},
|
||||
};
|
||||
use common::{DATABASE_SCHEMA_VERSION, manager::backup::BackupParams};
|
||||
use store::{
|
||||
rand,
|
||||
write::{
|
||||
AnyClass, AnyKey, BatchBuilder, BlobLink, BlobOp, Operation, QueueClass, QueueEvent,
|
||||
RegistryClass, TaskQueueClass, ValueClass,
|
||||
key::{DeserializeBigEndian, KeySerializer},
|
||||
RegistryClass, ValueClass, key::KeySerializer,
|
||||
},
|
||||
*,
|
||||
};
|
||||
@@ -177,50 +167,6 @@ pub async fn test(test: &TestServer) {
|
||||
}
|
||||
db.write(batch.build_all()).await.unwrap();
|
||||
|
||||
// inbuxa: registry objects kept outside the registry subspace (archived
|
||||
// items for undelete, spam training samples, directory entries) and the
|
||||
// fork's own subspace. Exports used to leave the first two behind.
|
||||
println!("Creating archived items, spam samples and fork data...");
|
||||
let mut batch = BatchBuilder::new();
|
||||
for item_id in [1u64, 2, 3] {
|
||||
for object in [
|
||||
ObjectType::ArchivedItem,
|
||||
ObjectType::SpamTrainingSample,
|
||||
ObjectType::Account,
|
||||
] {
|
||||
batch.set(
|
||||
ValueClass::Registry(RegistryClass::Item {
|
||||
object_id: object as u16,
|
||||
item_id,
|
||||
}),
|
||||
random_bytes(item_id as usize * 64),
|
||||
);
|
||||
}
|
||||
batch.set(
|
||||
ValueClass::Any(AnyClass {
|
||||
subspace: SUBSPACE_INBUXA,
|
||||
key: [b'U', b'x']
|
||||
.into_iter()
|
||||
.chain(item_id.to_be_bytes())
|
||||
.collect(),
|
||||
}),
|
||||
random_bytes(32),
|
||||
);
|
||||
}
|
||||
db.write(batch.build_all()).await.unwrap();
|
||||
|
||||
// inbuxa: the trained spam classifier lives in blobs with fixed names
|
||||
let mut named_blobs = Vec::new();
|
||||
for key in [SPAM_CLASSIFIER_KEY, SPAM_TRAINER_KEY] {
|
||||
let data = random_bytes(4096);
|
||||
test.server
|
||||
.blob_store()
|
||||
.put_blob(key, &data, CompressionAlgo::Lz4)
|
||||
.await
|
||||
.unwrap();
|
||||
named_blobs.push((key, data));
|
||||
}
|
||||
|
||||
// Create directory data
|
||||
println!("Creating directory data...");
|
||||
let mut batch = BatchBuilder::new();
|
||||
@@ -239,17 +185,6 @@ pub async fn test(test: &TestServer) {
|
||||
println!("Calculating store hash...");
|
||||
let snapshot = Snapshot::new(&db).await;
|
||||
assert!(!snapshot.keys.is_empty(), "Store hash counts are empty",);
|
||||
for subspace in [
|
||||
SUBSPACE_DELETED_ITEMS,
|
||||
SUBSPACE_SPAM_SAMPLES,
|
||||
SUBSPACE_INBUXA,
|
||||
] {
|
||||
assert!(
|
||||
snapshot.keys.iter().any(|k| k.subspace == subspace),
|
||||
"No test data in subspace {}",
|
||||
char::from(subspace)
|
||||
);
|
||||
}
|
||||
|
||||
// Export store
|
||||
println!("Exporting store...");
|
||||
@@ -275,188 +210,22 @@ pub async fn test(test: &TestServer) {
|
||||
.finalize(),
|
||||
);
|
||||
db.write(batch.build_all()).await.unwrap();
|
||||
for (key, _) in &named_blobs {
|
||||
test.server.blob_store().delete_blob(key).await.unwrap();
|
||||
}
|
||||
let imported = test.server.core.restore(temp_dir.path.clone()).await;
|
||||
test.server.core.restore(temp_dir.path.clone()).await;
|
||||
let mut batch = BatchBuilder::new();
|
||||
batch.clear(ValueClass::NodeId(0));
|
||||
db.write(batch.build_all()).await.unwrap();
|
||||
for subspace in [
|
||||
SUBSPACE_DELETED_ITEMS,
|
||||
SUBSPACE_SPAM_SAMPLES,
|
||||
SUBSPACE_INBUXA,
|
||||
] {
|
||||
assert!(
|
||||
imported.contains(&subspace),
|
||||
"Subspace {} was not exported",
|
||||
char::from(subspace)
|
||||
);
|
||||
}
|
||||
|
||||
// Verify hash
|
||||
print!("Verifying store hash...");
|
||||
snapshot.assert_is_eq(&Snapshot::new(&db).await);
|
||||
assert_named_blobs(test.server.blob_store(), &named_blobs).await;
|
||||
println!(" GREAT SUCCESS!");
|
||||
|
||||
// inbuxa: import the same export into a fresh store of another backend,
|
||||
// the way a move from one database to another does it
|
||||
#[cfg(all(feature = "rocks", feature = "sqlite"))]
|
||||
cross_backend(test, &db, &temp_dir, &named_blobs).await;
|
||||
|
||||
// Destroy store
|
||||
for (key, _) in &named_blobs {
|
||||
test.server.blob_store().delete_blob(key).await.unwrap();
|
||||
}
|
||||
store_destroy(&db).await;
|
||||
store_assert_is_empty(&db, db.clone().into(), true).await;
|
||||
temp_dir.delete();
|
||||
}
|
||||
|
||||
#[cfg(all(feature = "rocks", feature = "sqlite"))]
|
||||
async fn cross_backend(
|
||||
test: &TestServer,
|
||||
source: &Store,
|
||||
export: &TempDir,
|
||||
named_blobs: &[(&[u8], Vec<u8>)],
|
||||
) {
|
||||
let source_type = std::env::var("STORE").unwrap();
|
||||
let target_type = if source_type.eq_ignore_ascii_case("sqlite") {
|
||||
"RocksDb"
|
||||
} else {
|
||||
"Sqlite"
|
||||
};
|
||||
println!("Importing the export into a fresh {target_type} store...");
|
||||
|
||||
let target_dir = TempDir::new("art_vandelay_cross_backend", true);
|
||||
let target = Store::build(
|
||||
crate::utils::storage::build_data_store(target_type, &target_dir.path.to_string_lossy())
|
||||
.await,
|
||||
)
|
||||
.await
|
||||
.unwrap();
|
||||
target.create_tables().await.unwrap();
|
||||
store_destroy(&target).await;
|
||||
|
||||
let mut core = test.server.core.as_ref().clone();
|
||||
core.storage.data = target.clone();
|
||||
core.storage.blob = target.clone().into();
|
||||
let imported = core.restore(export.path.clone()).await;
|
||||
|
||||
// Counters are stored differently by the SQL and key-value backends, so
|
||||
// compare their keys here and their values through the counter API.
|
||||
print!("Verifying {target_type} store hash...");
|
||||
Snapshot::new_portable(source)
|
||||
.await
|
||||
.assert_is_eq(&Snapshot::new_portable(&target).await);
|
||||
for subspace in [SUBSPACE_COUNTER, SUBSPACE_QUOTA] {
|
||||
let mut keys = Vec::new();
|
||||
source
|
||||
.iterate(
|
||||
IterateParams::new(
|
||||
AnyKey {
|
||||
subspace,
|
||||
key: vec![0u8],
|
||||
},
|
||||
AnyKey {
|
||||
subspace,
|
||||
key: vec![u8::MAX; 10],
|
||||
},
|
||||
)
|
||||
.no_values(),
|
||||
|key, _| {
|
||||
keys.push(key.to_vec());
|
||||
Ok(true)
|
||||
},
|
||||
)
|
||||
.await
|
||||
.unwrap();
|
||||
for key in keys {
|
||||
let class = || {
|
||||
ValueClass::Any(AnyClass {
|
||||
subspace,
|
||||
key: key.clone(),
|
||||
})
|
||||
};
|
||||
assert_eq!(
|
||||
source.get_counter(class()).await.unwrap(),
|
||||
target.get_counter(class()).await.unwrap(),
|
||||
"Counter mismatch in {} for {key:?}",
|
||||
char::from(subspace)
|
||||
);
|
||||
}
|
||||
}
|
||||
assert_named_blobs(&core.storage.blob, named_blobs).await;
|
||||
println!(" GREAT SUCCESS!");
|
||||
|
||||
// The search index isn't exported; the import queues its rebuild
|
||||
let queued = core.queue_reindex(&imported).await;
|
||||
let expected = [
|
||||
TaskStoreMaintenanceType::ReindexAccounts,
|
||||
TaskStoreMaintenanceType::ReindexTelemetry,
|
||||
];
|
||||
assert_eq!(queued, expected);
|
||||
let mut task_ids = Vec::new();
|
||||
target
|
||||
.iterate(
|
||||
IterateParams::new(
|
||||
AnyKey {
|
||||
subspace: SUBSPACE_TASK_QUEUE,
|
||||
key: vec![0u8],
|
||||
},
|
||||
AnyKey {
|
||||
subspace: SUBSPACE_TASK_QUEUE,
|
||||
key: vec![u8::MAX; 20],
|
||||
},
|
||||
)
|
||||
.no_values(),
|
||||
|key, _| {
|
||||
if key.deserialize_be_u64(0)? == 0 {
|
||||
task_ids.push(key.deserialize_be_u64(U64_LEN)?);
|
||||
}
|
||||
Ok(true)
|
||||
},
|
||||
)
|
||||
.await
|
||||
.unwrap();
|
||||
let mut found = Vec::new();
|
||||
for id in task_ids {
|
||||
match target
|
||||
.get_value::<Task>(ValueKey::from(ValueClass::TaskQueue(
|
||||
TaskQueueClass::Task { id },
|
||||
)))
|
||||
.await
|
||||
.unwrap()
|
||||
{
|
||||
Some(Task::StoreMaintenance(task)) => found.push(task.maintenance_type),
|
||||
other => panic!("Unexpected task {other:?}"),
|
||||
}
|
||||
}
|
||||
found.sort_by_key(|t| *t as u16);
|
||||
assert_eq!(found, expected, "Queued tasks don't match");
|
||||
|
||||
store_destroy(&target).await;
|
||||
drop(core);
|
||||
drop(target);
|
||||
target_dir.delete();
|
||||
}
|
||||
|
||||
async fn assert_named_blobs(blob_store: &BlobStore, named_blobs: &[(&[u8], Vec<u8>)]) {
|
||||
for (key, data) in named_blobs {
|
||||
assert_eq!(
|
||||
blob_store
|
||||
.get_blob(key, 0..usize::MAX)
|
||||
.await
|
||||
.unwrap()
|
||||
.as_ref(),
|
||||
Some(data),
|
||||
"Blob {} was not restored",
|
||||
String::from_utf8_lossy(key)
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Debug, PartialEq, Eq)]
|
||||
struct Snapshot {
|
||||
keys: AHashSet<KeyValue>,
|
||||
@@ -471,19 +240,7 @@ struct KeyValue {
|
||||
|
||||
impl Snapshot {
|
||||
async fn new(db: &Store) -> Self {
|
||||
Self::build(db, !db.is_sql(), true).await
|
||||
}
|
||||
|
||||
/// Comparable across backends: no counter values, which the SQL and
|
||||
/// key-value stores encode differently, and no blobs, which only live in
|
||||
/// the data store when it doubles as the blob store.
|
||||
#[cfg(all(feature = "rocks", feature = "sqlite"))]
|
||||
async fn new_portable(db: &Store) -> Self {
|
||||
Self::build(db, false, false).await
|
||||
}
|
||||
|
||||
async fn build(db: &Store, counter_values: bool, with_blobs: bool) -> Self {
|
||||
let is_sql = !counter_values;
|
||||
let is_sql = db.is_sql();
|
||||
|
||||
let mut keys = AHashSet::new();
|
||||
|
||||
@@ -508,12 +265,7 @@ impl Snapshot {
|
||||
(SUBSPACE_QUOTA, !is_sql),
|
||||
(SUBSPACE_REPORT_OUT, true),
|
||||
(SUBSPACE_REPORT_IN, true),
|
||||
(SUBSPACE_DIRECTORY, true),
|
||||
(SUBSPACE_INBUXA, true),
|
||||
] {
|
||||
if subspace == SUBSPACE_BLOBS && !with_blobs {
|
||||
continue;
|
||||
}
|
||||
let from_key = AnyKey {
|
||||
subspace,
|
||||
key: vec![0u8],
|
||||
|
||||
@@ -2,8 +2,6 @@
|
||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||
*
|
||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||
*
|
||||
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||
*/
|
||||
|
||||
use crate::{store::deflate_test_resource, utils::server::TestServer};
|
||||
@@ -124,10 +122,6 @@ pub async fn test(test: &TestServer) {
|
||||
println!("Running global id filtering tests...");
|
||||
test_global(store.clone()).await;
|
||||
|
||||
// inbuxa: trace documents as the index task builds them
|
||||
println!("Running trace document tests...");
|
||||
test_trace_documents(store.clone()).await;
|
||||
|
||||
// Large document insert test
|
||||
println!("Running large document insert tests...");
|
||||
let mut large_text = String::with_capacity(20 * 1024 * 1024);
|
||||
@@ -815,160 +809,3 @@ async fn test_global(store: SearchStore) {
|
||||
AHashSet::from_iter([3, 4, 5])
|
||||
);
|
||||
}
|
||||
|
||||
// inbuxa: MON-16: documents built by the index task from stored traces go
|
||||
// into every search backend (the SQL backends type etyp and qid as BIGINT)
|
||||
// and are found again by queue id and keyword.
|
||||
async fn test_trace_documents(store: SearchStore) {
|
||||
use registry::schema::{
|
||||
enums::SearchTracingField,
|
||||
structs::{
|
||||
Trace, TraceEvent, TraceKeyValue, TraceValue, TraceValueString,
|
||||
TraceValueUnsignedInt,
|
||||
},
|
||||
};
|
||||
use services::task_manager::index::trace_search_document;
|
||||
use trc::{DeliveryEvent, EventType, Key, SmtpEvent};
|
||||
|
||||
let kv_u = |key: Key, value: u64| TraceKeyValue {
|
||||
key,
|
||||
value: TraceValue::UnsignedInt(TraceValueUnsignedInt { value }),
|
||||
};
|
||||
let kv_s = |key: Key, value: &str| TraceKeyValue {
|
||||
key,
|
||||
value: TraceValue::String(TraceValueString {
|
||||
value: value.to_string(),
|
||||
}),
|
||||
};
|
||||
let event = |event: EventType, key_values: Vec<TraceKeyValue>| TraceEvent {
|
||||
event,
|
||||
key_values: key_values.into(),
|
||||
..Default::default()
|
||||
};
|
||||
let fields = [
|
||||
SearchTracingField::EventType,
|
||||
SearchTracingField::QueueId,
|
||||
SearchTracingField::Keywords,
|
||||
];
|
||||
|
||||
// An SMTP session that queued two messages, and a delivery attempt
|
||||
let session = Trace {
|
||||
events: vec![
|
||||
event(
|
||||
EventType::Smtp(SmtpEvent::ConnectionStart),
|
||||
vec![kv_s(Key::RemoteIp, "192.0.2.7")],
|
||||
),
|
||||
event(
|
||||
EventType::Smtp(SmtpEvent::MailFrom),
|
||||
vec![kv_s(Key::From, "[email protected]")],
|
||||
),
|
||||
event(
|
||||
EventType::Smtp(SmtpEvent::RcptTo),
|
||||
vec![kv_u(Key::QueueId, 9_000_000_001), kv_s(Key::To, "[email protected]")],
|
||||
),
|
||||
event(
|
||||
EventType::Smtp(SmtpEvent::RcptTo),
|
||||
vec![kv_u(Key::QueueId, 9_000_000_002)],
|
||||
),
|
||||
]
|
||||
.into(),
|
||||
};
|
||||
let delivery = Trace {
|
||||
events: vec![event(
|
||||
EventType::Delivery(DeliveryEvent::AttemptStart),
|
||||
vec![kv_u(Key::QueueId, 9_000_000_003), kv_s(Key::Hostname, "relay.example.net")],
|
||||
)]
|
||||
.into(),
|
||||
};
|
||||
let documents = vec![
|
||||
trace_search_document(100, &session, &fields),
|
||||
trace_search_document(101, &delivery, &fields),
|
||||
];
|
||||
assert!(
|
||||
documents
|
||||
.iter()
|
||||
.all(|d| d.has_field(&SearchField::Tracing(TracingSearchField::QueueId))
|
||||
&& d.has_field(&SearchField::Tracing(TracingSearchField::EventType))),
|
||||
"trace documents carry a queue id and an event type"
|
||||
);
|
||||
store.index(documents).await.unwrap();
|
||||
if let SearchStore::ElasticSearch(store) = &store {
|
||||
store.refresh_index(SearchIndex::Tracing).await.unwrap();
|
||||
}
|
||||
|
||||
let query = |filters: Vec<SearchFilter>| {
|
||||
let store = store.clone();
|
||||
async move {
|
||||
store
|
||||
.query_global(
|
||||
SearchQuery::new(SearchIndex::Tracing)
|
||||
.with_filter(SearchFilter::ge(SearchField::Id, 100u64))
|
||||
.with_filters(filters),
|
||||
)
|
||||
.await
|
||||
.unwrap()
|
||||
.into_iter()
|
||||
.collect::<AHashSet<_>>()
|
||||
}
|
||||
};
|
||||
// By queue id, the way x:Trace/query asks: the queue id column, or any
|
||||
// queue id in the keywords
|
||||
let by_queue_id = |queue_id: u64| {
|
||||
vec![
|
||||
SearchFilter::Or,
|
||||
SearchFilter::eq(TracingSearchField::QueueId, queue_id),
|
||||
SearchFilter::has_text(
|
||||
TracingSearchField::Keywords,
|
||||
queue_id.to_string(),
|
||||
Language::None,
|
||||
),
|
||||
SearchFilter::End,
|
||||
]
|
||||
};
|
||||
assert_eq!(query(by_queue_id(9_000_000_001)).await, AHashSet::from_iter([100]));
|
||||
assert_eq!(query(by_queue_id(9_000_000_002)).await, AHashSet::from_iter([100]));
|
||||
assert_eq!(query(by_queue_id(9_000_000_003)).await, AHashSet::from_iter([101]));
|
||||
assert_eq!(query(by_queue_id(9_000_000_004)).await, AHashSet::new());
|
||||
assert_eq!(
|
||||
query(vec![SearchFilter::eq(TracingSearchField::QueueId, 9_000_000_003u64)]).await,
|
||||
AHashSet::from_iter([101])
|
||||
);
|
||||
// By opening event type
|
||||
assert_eq!(
|
||||
query(vec![SearchFilter::eq(
|
||||
TracingSearchField::EventType,
|
||||
EventType::Delivery(DeliveryEvent::AttemptStart).to_id() as u64,
|
||||
)])
|
||||
.await,
|
||||
AHashSet::from_iter([101])
|
||||
);
|
||||
// By keyword: an address, lowercased, and its domain
|
||||
assert_eq!(
|
||||
query(vec![SearchFilter::has_text(
|
||||
TracingSearchField::Keywords,
|
||||
"example.org",
|
||||
Language::None,
|
||||
)])
|
||||
.await,
|
||||
AHashSet::from_iter([100])
|
||||
);
|
||||
assert_eq!(
|
||||
query(vec![SearchFilter::has_text(
|
||||
TracingSearchField::Keywords,
|
||||
"relay.example.net",
|
||||
Language::None,
|
||||
)])
|
||||
.await,
|
||||
AHashSet::from_iter([101])
|
||||
);
|
||||
|
||||
for id in [100u64, 101] {
|
||||
store
|
||||
.unindex(
|
||||
SearchQuery::new(SearchIndex::Tracing)
|
||||
.with_filter(SearchFilter::eq(SearchField::Id, id)),
|
||||
)
|
||||
.await
|
||||
.unwrap();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -148,73 +148,6 @@ pub async fn test(test: &mut TestServer) {
|
||||
"test 9: to"
|
||||
);
|
||||
|
||||
// MON-16: the queueId filter finds the traces that name a queue id (the
|
||||
// session that queued the message and its delivery attempt) through the
|
||||
// search index, given as a string or a number (the index column is an
|
||||
// integer)
|
||||
fn queue_ids(value: &Value, out: &mut Vec<u64>) {
|
||||
match value {
|
||||
Value::Object(map) => {
|
||||
if map.get("key").and_then(|k| k.as_str()) == Some("queueId")
|
||||
&& let Some(id) = map
|
||||
.get("value")
|
||||
.and_then(|v| v.get("value").unwrap_or(v).as_u64())
|
||||
{
|
||||
out.push(id);
|
||||
}
|
||||
map.values().for_each(|v| queue_ids(v, out));
|
||||
}
|
||||
Value::Array(list) => list.iter().for_each(|v| queue_ids(v, out)),
|
||||
_ => {}
|
||||
}
|
||||
}
|
||||
let with_ids = traces
|
||||
.iter()
|
||||
.map(|t| {
|
||||
let mut ids = Vec::new();
|
||||
queue_ids(t, &mut ids);
|
||||
(t["id"].as_str().unwrap().to_string(), ids)
|
||||
})
|
||||
.collect::<Vec<_>>();
|
||||
let queue_id = with_ids
|
||||
.iter()
|
||||
.find_map(|(_, ids)| ids.first().copied())
|
||||
.expect("MON-16: a trace with a queue id");
|
||||
let mut expected = with_ids
|
||||
.iter()
|
||||
.filter(|(_, ids)| ids.contains(&queue_id))
|
||||
.map(|(id, _)| id.clone())
|
||||
.collect::<Vec<_>>();
|
||||
expected.sort();
|
||||
for filter in [json!(queue_id.to_string()), json!(queue_id)] {
|
||||
let response = admin
|
||||
.jmap_method_call("x:Trace/query", json!({"filter": {"queueId": filter}}))
|
||||
.await;
|
||||
let mut found = response
|
||||
.0
|
||||
.pointer("/methodResponses/0/1/ids")
|
||||
.and_then(|ids| ids.as_array())
|
||||
.map(|ids| {
|
||||
ids.iter()
|
||||
.filter_map(|id| id.as_str().map(str::to_string))
|
||||
.collect::<Vec<_>>()
|
||||
})
|
||||
.unwrap_or_default();
|
||||
found.sort();
|
||||
assert_eq!(found, expected, "MON-16: queueId {filter}: {response:?}");
|
||||
}
|
||||
let response = admin
|
||||
.jmap_method_call(
|
||||
"x:Trace/query",
|
||||
json!({"filter": {"queueId": (queue_id ^ 0x5a5a_5a5a).to_string()}}),
|
||||
)
|
||||
.await;
|
||||
assert_eq!(
|
||||
response.0.pointer("/methodResponses/0/1/ids"),
|
||||
Some(&json!([])),
|
||||
"MON-16: an unknown queue id"
|
||||
);
|
||||
|
||||
// Acceptance test 24: destroy removes a trace; create is refused
|
||||
let trace_id = traces[0]["id"].as_str().unwrap().to_string();
|
||||
let response = admin
|
||||
|
||||
Reference in New Issue
Block a user