Compare commits
16
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8a8f48c944 | ||
|
|
7109e67f07 | ||
|
|
52b5a5f909 | ||
|
|
9232662913 | ||
|
|
57d1c5b074 | ||
|
|
ca3abf40f0 | ||
|
|
499e4d7810 | ||
|
|
212cd77cd3 | ||
|
|
7735780807 | ||
|
|
e223f7d327 | ||
|
|
30df055e39 | ||
|
|
5393c4405a | ||
|
|
cc532b914c | ||
|
|
c09eff2214 | ||
|
|
d7c9416713 | ||
|
|
238079da66 |
+8
-2
@@ -1,10 +1,16 @@
|
|||||||
// Ignore everything
|
# Ignore everything
|
||||||
*
|
*
|
||||||
|
|
||||||
// Allow what is needed
|
# Allow what is needed
|
||||||
!crates
|
!crates
|
||||||
!tests
|
!tests
|
||||||
!resources
|
!resources
|
||||||
|
|
||||||
|
# The patched dependency Cargo.toml's [patch.crates-io] points at. Without
|
||||||
|
# it the build context has no vendor/, and `cargo chef cook` fails on
|
||||||
|
# "failed to load source for dependency sieve-rs" -- which CI cannot see,
|
||||||
|
# because CI builds from a checkout and only the image build has a context.
|
||||||
|
!vendor
|
||||||
|
|
||||||
!Cargo.lock
|
!Cargo.lock
|
||||||
!Cargo.toml
|
!Cargo.toml
|
||||||
|
|||||||
@@ -35,6 +35,11 @@ jobs:
|
|||||||
- run: python3 tools/fork/name-check.py
|
- run: python3 tools/fork/name-check.py
|
||||||
- if: always()
|
- if: always()
|
||||||
run: python3 tools/fork/notice-check.py
|
run: python3 tools/fork/notice-check.py
|
||||||
|
# Cargo can patch a dependency to a directory in this repository, and
|
||||||
|
# the image builds from a context .dockerignore prunes to almost
|
||||||
|
# nothing. CI never sees the difference; a release does.
|
||||||
|
- if: always()
|
||||||
|
run: python3 tools/fork/context-check.py
|
||||||
|
|
||||||
build:
|
build:
|
||||||
# Either runner (host1 or host2): the build needs no docker socket.
|
# Either runner (host1 or host2): the build needs no docker socket.
|
||||||
|
|||||||
@@ -19,6 +19,10 @@ RUN export DEBIAN_FRONTEND=noninteractive && \
|
|||||||
g++-x86-64-linux-gnu binutils-x86-64-linux-gnu
|
g++-x86-64-linux-gnu binutils-x86-64-linux-gnu
|
||||||
RUN rustup target add "$(cat /target.txt)"
|
RUN rustup target add "$(cat /target.txt)"
|
||||||
COPY --from=planner /recipe.json /recipe.json
|
COPY --from=planner /recipe.json /recipe.json
|
||||||
|
# inbuxa: [patch.crates-io] points sieve-rs at vendor/, and the recipe only
|
||||||
|
# carries the workspace's own manifests, so cooking the dependencies needs the
|
||||||
|
# vendored crate itself (the context allows it since #27; this puts it here).
|
||||||
|
COPY vendor/ vendor/
|
||||||
RUN RUSTFLAGS="$(cat /flags.txt)" cargo chef cook --target "$(cat /target.txt)" --release --no-default-features --features "sqlite postgres mysql rocks s3 redis azure nats" --recipe-path /recipe.json
|
RUN RUSTFLAGS="$(cat /flags.txt)" cargo chef cook --target "$(cat /target.txt)" --release --no-default-features --features "sqlite postgres mysql rocks s3 redis azure nats" --recipe-path /recipe.json
|
||||||
COPY . .
|
COPY . .
|
||||||
RUN RUSTFLAGS="$(cat /flags.txt)" cargo build --target "$(cat /target.txt)" --release -p inbuxa --no-default-features --features "sqlite postgres mysql rocks s3 redis azure nats"
|
RUN RUSTFLAGS="$(cat /flags.txt)" cargo build --target "$(cat /target.txt)" --release -p inbuxa --no-default-features --features "sqlite postgres mysql rocks s3 redis azure nats"
|
||||||
|
|||||||
@@ -23,6 +23,13 @@ use utils::{UnwrapFailure, codec::leb128::Leb128_};
|
|||||||
|
|
||||||
pub(super) const MAGIC_MARKER: u8 = 123;
|
pub(super) const MAGIC_MARKER: u8 = 123;
|
||||||
|
|
||||||
|
// inbuxa: blobs kept under a fixed name instead of a content hash. Nothing
|
||||||
|
// links to them, so the export names them outright.
|
||||||
|
const NAMED_BLOBS: &[&[u8]] = &[
|
||||||
|
crate::manager::SPAM_CLASSIFIER_KEY,
|
||||||
|
crate::manager::SPAM_TRAINER_KEY,
|
||||||
|
];
|
||||||
|
|
||||||
#[derive(Debug, Clone, Copy, Hash, PartialEq, Eq)]
|
#[derive(Debug, Clone, Copy, Hash, PartialEq, Eq)]
|
||||||
pub(super) enum Family {
|
pub(super) enum Family {
|
||||||
Data = 0,
|
Data = 0,
|
||||||
@@ -143,15 +150,21 @@ impl Core {
|
|||||||
.await
|
.await
|
||||||
.failed("Failed to iterate over data store");
|
.failed("Failed to iterate over data store");
|
||||||
|
|
||||||
for hash in blobs {
|
// inbuxa: the trained spam classifier and its trainer state are
|
||||||
|
// blobs stored under fixed names with no blob link, so the walk
|
||||||
|
// over links above never reaches them.
|
||||||
|
let named = NAMED_BLOBS.iter().map(|key| key.to_vec());
|
||||||
|
for key in blobs
|
||||||
|
.into_iter()
|
||||||
|
.map(|hash| hash.as_slice().to_vec())
|
||||||
|
.chain(named)
|
||||||
|
{
|
||||||
if let Some(blob) = blob_store
|
if let Some(blob) = blob_store
|
||||||
.get_blob(hash.as_slice(), 0..usize::MAX)
|
.get_blob(&key, 0..usize::MAX)
|
||||||
.await
|
.await
|
||||||
.failed("Failed to get blob")
|
.failed("Failed to get blob")
|
||||||
{
|
{
|
||||||
writer
|
writer.send((key, blob)).failed("Failed to send key");
|
||||||
.send((hash.as_slice().to_vec(), blob))
|
|
||||||
.failed("Failed to send key");
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}),
|
}),
|
||||||
@@ -323,7 +336,13 @@ impl Family {
|
|||||||
SUBSPACE_REGISTRY_IDX,
|
SUBSPACE_REGISTRY_IDX,
|
||||||
SUBSPACE_REGISTRY_PK,
|
SUBSPACE_REGISTRY_PK,
|
||||||
SUBSPACE_DIRECTORY,
|
SUBSPACE_DIRECTORY,
|
||||||
store::SUBSPACE_INBUXA, // inbuxa: masked email
|
// inbuxa: registry objects the upstream list left out, so an
|
||||||
|
// export dropped them: archived items (undelete) and spam
|
||||||
|
// training samples. Their indexes and id counters already
|
||||||
|
// travel in this family and in `data`, so they ride along.
|
||||||
|
SUBSPACE_DELETED_ITEMS,
|
||||||
|
SUBSPACE_SPAM_SAMPLES,
|
||||||
|
store::SUBSPACE_INBUXA, // inbuxa: the fork's own data (masked email, undelete, policies)
|
||||||
],
|
],
|
||||||
Family::Changelog => &[SUBSPACE_LOGS],
|
Family::Changelog => &[SUBSPACE_LOGS],
|
||||||
Family::Queue => &[SUBSPACE_QUEUE_MESSAGE, SUBSPACE_QUEUE_EVENT],
|
Family::Queue => &[SUBSPACE_QUEUE_MESSAGE, SUBSPACE_QUEUE_EVENT],
|
||||||
|
|||||||
@@ -54,6 +54,13 @@ Options:
|
|||||||
-o, --console Open the store console
|
-o, --console Open the store console
|
||||||
-h, --help Print help
|
-h, --help Print help
|
||||||
-V, --version Print version
|
-V, --version Print version
|
||||||
|
|
||||||
|
An export holds everything in the data and blob stores except short-lived
|
||||||
|
in-memory state (rate limits, locks, greylisting) and the full-text search
|
||||||
|
index, which belongs to one search backend. An import into an empty store
|
||||||
|
queues the index to be rebuilt when the server next starts. EXPORT_TYPES
|
||||||
|
limits an export to some of: data, registry, blob, changelog, queue, report,
|
||||||
|
telemetry, tasks.
|
||||||
"#
|
"#
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -256,10 +263,10 @@ impl BootManager {
|
|||||||
telemetry.enable();
|
telemetry.enable();
|
||||||
|
|
||||||
// Parse settings and restore
|
// Parse settings and restore
|
||||||
Box::pin(Core::parse(&mut bootstrap, storage))
|
let core = Box::pin(Core::parse(&mut bootstrap, storage)).await;
|
||||||
.await
|
let imported = core.restore(path).await;
|
||||||
.restore(path)
|
// inbuxa: the search index isn't exported; rebuild it
|
||||||
.await;
|
core.queue_reindex(&imported).await;
|
||||||
std::process::exit(0);
|
std::process::exit(0);
|
||||||
}
|
}
|
||||||
StoreOp::Console => {
|
StoreOp::Console => {
|
||||||
|
|||||||
@@ -9,15 +9,22 @@
|
|||||||
use super::backup::MAGIC_MARKER;
|
use super::backup::MAGIC_MARKER;
|
||||||
use crate::{Core, DATABASE_SCHEMA_VERSION};
|
use crate::{Core, DATABASE_SCHEMA_VERSION};
|
||||||
use lz4_flex::frame::FrameDecoder;
|
use lz4_flex::frame::FrameDecoder;
|
||||||
use registry::schema::enums::CompressionAlgo;
|
use registry::{
|
||||||
|
schema::{
|
||||||
|
enums::{CompressionAlgo, TaskStoreMaintenanceType},
|
||||||
|
structs::{Task, TaskStatus, TaskStoreMaintenance},
|
||||||
|
},
|
||||||
|
types::EnumImpl,
|
||||||
|
};
|
||||||
use std::{
|
use std::{
|
||||||
fs::File,
|
fs::File,
|
||||||
io::{BufReader, ErrorKind, Read},
|
io::{BufReader, ErrorKind, Read},
|
||||||
path::{Path, PathBuf},
|
path::{Path, PathBuf},
|
||||||
};
|
};
|
||||||
use store::{
|
use store::{
|
||||||
BlobStore, IterateParams, SUBSPACE_BLOBS, SUBSPACE_COUNTER, SUBSPACE_INDEXES, SUBSPACE_QUOTA,
|
BlobStore, IterateParams, SUBSPACE_BLOBS, SUBSPACE_COUNTER, SUBSPACE_INDEXES,
|
||||||
SUBSPACE_REGISTRY_PK, Store, U32_LEN,
|
SUBSPACE_PROPERTY, SUBSPACE_QUOTA, SUBSPACE_REGISTRY_PK, SUBSPACE_TELEMETRY_SPAN, Store,
|
||||||
|
U32_LEN,
|
||||||
write::{
|
write::{
|
||||||
AnyClass, AnyKey, BatchBuilder, ValueClass,
|
AnyClass, AnyKey, BatchBuilder, ValueClass,
|
||||||
key::{DeserializeBigEndian, is_node_id_key},
|
key::{DeserializeBigEndian, is_node_id_key},
|
||||||
@@ -27,7 +34,9 @@ use types::{collection::Collection, field::Field};
|
|||||||
use utils::{UnwrapFailure, failed};
|
use utils::{UnwrapFailure, failed};
|
||||||
|
|
||||||
impl Core {
|
impl Core {
|
||||||
pub async fn restore(&self, src: PathBuf) {
|
/// Imports an export into an empty store and returns the subspaces it
|
||||||
|
/// wrote. inbuxa: the caller hands them to [`Core::queue_reindex`].
|
||||||
|
pub async fn restore(&self, src: PathBuf) -> Vec<u8> {
|
||||||
// Backup the core
|
// Backup the core
|
||||||
let paths = if src.is_dir() {
|
let paths = if src.is_dir() {
|
||||||
let mut paths = Vec::new();
|
let mut paths = Vec::new();
|
||||||
@@ -64,6 +73,13 @@ impl Core {
|
|||||||
std::process::exit(1);
|
std::process::exit(1);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
let mut imported = paths
|
||||||
|
.iter()
|
||||||
|
.map(|path| KeyValueReader::new(path).subspace)
|
||||||
|
.collect::<Vec<_>>();
|
||||||
|
imported.sort_unstable();
|
||||||
|
imported.dedup();
|
||||||
|
|
||||||
let mut tasks = Vec::new();
|
let mut tasks = Vec::new();
|
||||||
for path in paths {
|
for path in paths {
|
||||||
let storage = self.storage.clone();
|
let storage = self.storage.clone();
|
||||||
@@ -76,6 +92,54 @@ impl Core {
|
|||||||
for task in tasks {
|
for task in tasks {
|
||||||
task.await.failed("Failed to wait for task");
|
task.await.failed("Failed to wait for task");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
imported
|
||||||
|
}
|
||||||
|
|
||||||
|
/// inbuxa: an export never carries the full-text index. It is built by
|
||||||
|
/// and for one search backend (the SQL stores index into their own
|
||||||
|
/// tables, the key-value stores into a subspace, external engines keep it
|
||||||
|
/// themselves), so it would be wrong or unreadable after a move to
|
||||||
|
/// another one. Instead, an import queues the same reindex tasks an
|
||||||
|
/// administrator can queue by hand (`reindexAccounts` and
|
||||||
|
/// `reindexTelemetry` store maintenance), and the server rebuilds the
|
||||||
|
/// index for whatever search store it is configured with once it starts.
|
||||||
|
pub async fn queue_reindex(&self, imported: &[u8]) -> Vec<TaskStoreMaintenanceType> {
|
||||||
|
let mut queued = Vec::new();
|
||||||
|
if imported.contains(&SUBSPACE_PROPERTY) {
|
||||||
|
queued.push(TaskStoreMaintenanceType::ReindexAccounts);
|
||||||
|
}
|
||||||
|
if imported.contains(&SUBSPACE_TELEMETRY_SPAN) {
|
||||||
|
queued.push(TaskStoreMaintenanceType::ReindexTelemetry);
|
||||||
|
}
|
||||||
|
if queued.is_empty() {
|
||||||
|
return queued;
|
||||||
|
}
|
||||||
|
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
for maintenance_type in &queued {
|
||||||
|
batch.schedule_task(Task::StoreMaintenance(TaskStoreMaintenance {
|
||||||
|
maintenance_type: *maintenance_type,
|
||||||
|
status: TaskStatus::now(),
|
||||||
|
shard_index: None,
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
self.storage
|
||||||
|
.data
|
||||||
|
.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.failed("Failed to queue the reindex tasks");
|
||||||
|
|
||||||
|
println!(
|
||||||
|
"Queued {} to rebuild the search index; it runs when the server starts.",
|
||||||
|
queued
|
||||||
|
.iter()
|
||||||
|
.map(|t| t.as_str())
|
||||||
|
.collect::<Vec<_>>()
|
||||||
|
.join(" and ")
|
||||||
|
);
|
||||||
|
|
||||||
|
queued
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -125,17 +189,22 @@ async fn restore_file(store: Store, blob_store: BlobStore, path: &Path) {
|
|||||||
}
|
}
|
||||||
SUBSPACE_COUNTER | SUBSPACE_QUOTA => {
|
SUBSPACE_COUNTER | SUBSPACE_QUOTA => {
|
||||||
while let Some((key, value)) = reader.next() {
|
while let Some((key, value)) = reader.next() {
|
||||||
batch.add(
|
let class = ValueClass::Any(AnyClass {
|
||||||
ValueClass::Any(AnyClass {
|
|
||||||
subspace: reader.subspace,
|
subspace: reader.subspace,
|
||||||
key,
|
key,
|
||||||
}),
|
});
|
||||||
u64::from_le_bytes(
|
let value = u64::from_le_bytes(
|
||||||
value
|
value
|
||||||
.try_into()
|
.try_into()
|
||||||
.expect("Failed to deserialize counter/quota"),
|
.expect("Failed to deserialize counter/quota"),
|
||||||
) as i64,
|
) as i64;
|
||||||
);
|
// inbuxa: the SQL stores add a negative amount with an UPDATE,
|
||||||
|
// which does nothing to a row that isn't there yet, so a
|
||||||
|
// negative counter vanished on import. Create the row first.
|
||||||
|
if value < 0 {
|
||||||
|
batch.add(class.clone(), 0);
|
||||||
|
}
|
||||||
|
batch.add(class, value);
|
||||||
if batch.is_large_batch() {
|
if batch.is_large_batch() {
|
||||||
store
|
store
|
||||||
.write(batch.build_all())
|
.write(batch.build_all())
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ store = { path = "../store" }
|
|||||||
registry = { path = "../registry" }
|
registry = { path = "../registry" }
|
||||||
trc = { path = "../trc" }
|
trc = { path = "../trc" }
|
||||||
futures = { version = "0.3", optional = true }
|
futures = { version = "0.3", optional = true }
|
||||||
tokio = { version = "1.53", features = ["sync", "fs", "io-util"] }
|
tokio = { version = "1.53", features = ["sync", "fs", "io-util", "rt", "time"] }
|
||||||
async-nats = { version = "0.50", default-features = false, features = ["server_2_10", "server_2_11", "aws-lc-rs"], optional = true }
|
async-nats = { version = "0.50", default-features = false, features = ["server_2_10", "server_2_11", "aws-lc-rs"], optional = true }
|
||||||
zenoh = { version = "1.10.0", default-features = false, features = ["auth_pubkey", "transport_multilink", "transport_compression", "transport_quic", "transport_tcp", "transport_tls", "transport_udp"], optional = true }
|
zenoh = { version = "1.10.0", default-features = false, features = ["auth_pubkey", "transport_multilink", "transport_compression", "transport_quic", "transport_tcp", "transport_tls", "transport_udp"], optional = true }
|
||||||
rdkafka = { version = "0.39", features = ["cmake-build"], optional = true }
|
rdkafka = { version = "0.39", features = ["cmake-build"], optional = true }
|
||||||
|
|||||||
@@ -2,13 +2,22 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use std::sync::Arc;
|
use std::{
|
||||||
|
sync::{
|
||||||
|
Arc,
|
||||||
|
atomic::{AtomicBool, Ordering},
|
||||||
|
},
|
||||||
|
time::Duration,
|
||||||
|
};
|
||||||
|
|
||||||
use crate::Coordinator;
|
use crate::Coordinator;
|
||||||
use async_nats::Client;
|
use async_nats::Client;
|
||||||
use registry::schema::structs::NatsCoordinator;
|
use registry::schema::structs::NatsCoordinator;
|
||||||
|
use trc::ClusterEvent;
|
||||||
|
|
||||||
pub mod pubsub;
|
pub mod pubsub;
|
||||||
|
|
||||||
@@ -47,9 +56,116 @@ impl NatsPubSub {
|
|||||||
opts = opts.token(credentials);
|
opts = opts.token(credentials);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// inbuxa: connect in the background and keep trying, so a node that
|
||||||
|
// starts while NATS is down still joins the cluster once NATS is
|
||||||
|
// back, instead of running without a coordinator until restarted;
|
||||||
|
// and report the connection going and coming back
|
||||||
|
let reporter = Arc::new(Reporter::default());
|
||||||
|
opts = opts.retry_on_initial_connect().event_callback({
|
||||||
|
let reporter = reporter.clone();
|
||||||
|
move |event| {
|
||||||
|
let reporter = reporter.clone();
|
||||||
|
async move { reporter.report(event) }
|
||||||
|
}
|
||||||
|
});
|
||||||
|
let connection_timeout = config.timeout_connection.into_inner();
|
||||||
|
|
||||||
async_nats::connect_with_options(config.addresses.into_inner(), opts)
|
async_nats::connect_with_options(config.addresses.into_inner(), opts)
|
||||||
.await
|
.await
|
||||||
.map(|client| Coordinator::Nats(Arc::new(NatsPubSub { client })))
|
.map(|client| {
|
||||||
|
reporter.watch_first_connection(client.clone(), connection_timeout);
|
||||||
|
Coordinator::Nats(Arc::new(NatsPubSub { client }))
|
||||||
|
})
|
||||||
.map_err(|err| format!("Failed to connect to Nats: {}", err))
|
.map_err(|err| format!("Failed to connect to Nats: {}", err))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// inbuxa: whether the client is connected to a NATS server right now.
|
||||||
|
pub fn is_connected(&self) -> bool {
|
||||||
|
matches!(
|
||||||
|
self.client.connection_state(),
|
||||||
|
async_nats::connection::State::Connected
|
||||||
|
)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// inbuxa: reports the client's connection events as the server's own.
|
||||||
|
#[derive(Default)]
|
||||||
|
struct Reporter {
|
||||||
|
connected_once: AtomicBool,
|
||||||
|
// A failed attempt raises an error each time the client retries, every
|
||||||
|
// few seconds while NATS is down: report the first after each change
|
||||||
|
error_reported: AtomicBool,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Reporter {
|
||||||
|
fn report(&self, event: async_nats::Event) {
|
||||||
|
match event {
|
||||||
|
async_nats::Event::Connected => {
|
||||||
|
self.connected_once.store(true, Ordering::Relaxed);
|
||||||
|
self.error_reported.store(false, Ordering::Relaxed);
|
||||||
|
trc::event!(Cluster(ClusterEvent::CoordinatorConnected), Type = "nats");
|
||||||
|
}
|
||||||
|
async_nats::Event::Disconnected => {
|
||||||
|
self.error_reported.store(false, Ordering::Relaxed);
|
||||||
|
trc::event!(
|
||||||
|
Cluster(ClusterEvent::CoordinatorDisconnected),
|
||||||
|
Type = "nats",
|
||||||
|
Details = "Connection lost; reconnecting in the background",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
async_nats::Event::Closed => {
|
||||||
|
trc::event!(
|
||||||
|
Cluster(ClusterEvent::CoordinatorDisconnected),
|
||||||
|
Type = "nats",
|
||||||
|
Details = "Connection closed; no further attempts will be made",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
async_nats::Event::ClientError(async_nats::ClientError::MaxReconnects) => {
|
||||||
|
trc::event!(
|
||||||
|
Cluster(ClusterEvent::CoordinatorDisconnected),
|
||||||
|
Type = "nats",
|
||||||
|
Details = "Gave up reconnecting (maxReconnects reached)",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
async_nats::Event::ClientError(err) => {
|
||||||
|
if !self.error_reported.swap(true, Ordering::Relaxed) {
|
||||||
|
trc::event!(
|
||||||
|
Cluster(ClusterEvent::CoordinatorError),
|
||||||
|
Type = "nats",
|
||||||
|
Details = "Connection attempt failed; retrying",
|
||||||
|
Reason = err.to_string(),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
event => {
|
||||||
|
trc::event!(
|
||||||
|
Cluster(ClusterEvent::CoordinatorError),
|
||||||
|
Type = "nats",
|
||||||
|
Details = event.to_string(),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The first connection is made in the background, so say so when it
|
||||||
|
/// hasn't been made within the connection timeout. The client keeps
|
||||||
|
/// trying, and reports the connection when it comes.
|
||||||
|
fn watch_first_connection(self: &Arc<Self>, client: Client, timeout: Duration) {
|
||||||
|
let reporter = self.clone();
|
||||||
|
tokio::spawn(async move {
|
||||||
|
tokio::time::sleep(timeout).await;
|
||||||
|
if !reporter.connected_once.load(Ordering::Relaxed)
|
||||||
|
&& !matches!(
|
||||||
|
client.connection_state(),
|
||||||
|
async_nats::connection::State::Connected
|
||||||
|
)
|
||||||
|
{
|
||||||
|
trc::event!(
|
||||||
|
Cluster(ClusterEvent::CoordinatorDisconnected),
|
||||||
|
Type = "nats",
|
||||||
|
Details = "Not connected at startup; retrying in the background",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::{Coordinator, Msg, PubSubStream};
|
use crate::{Coordinator, Msg, PubSubStream};
|
||||||
@@ -43,6 +45,17 @@ impl Coordinator {
|
|||||||
pub fn is_none(&self) -> bool {
|
pub fn is_none(&self) -> bool {
|
||||||
matches!(self, Coordinator::None)
|
matches!(self, Coordinator::None)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// inbuxa: whether the coordinator is connected right now, for the
|
||||||
|
/// backends that track it (NATS); `None` for the others and when no
|
||||||
|
/// coordinator is configured.
|
||||||
|
pub fn is_connected(&self) -> Option<bool> {
|
||||||
|
match self {
|
||||||
|
#[cfg(feature = "nats")]
|
||||||
|
Coordinator::Nats(store) => Some(store.is_connected()),
|
||||||
|
_ => None,
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl PubSubStream {
|
impl PubSubStream {
|
||||||
|
|||||||
@@ -562,6 +562,27 @@ impl ParseHttp for Server {
|
|||||||
})
|
})
|
||||||
.into_http_response());
|
.into_http_response());
|
||||||
}
|
}
|
||||||
|
// inbuxa: the cluster coordinator's connection, for
|
||||||
|
// monitoring. It stays out of live and ready on purpose:
|
||||||
|
// a node without its coordinator still serves mail, and
|
||||||
|
// failing those would have an orchestrator restart, or
|
||||||
|
// take out of service, every node at once when the
|
||||||
|
// coordinator goes down
|
||||||
|
"cluster" => {
|
||||||
|
let coordinator = &self.core.storage.coordinator;
|
||||||
|
let (status, state) = match coordinator.is_connected() {
|
||||||
|
Some(true) => (StatusCode::OK, "connected"),
|
||||||
|
Some(false) => (StatusCode::SERVICE_UNAVAILABLE, "disconnected"),
|
||||||
|
None if coordinator.is_none() => (StatusCode::OK, "none"),
|
||||||
|
None => (StatusCode::OK, "unknown"),
|
||||||
|
};
|
||||||
|
return Ok(http_proto::JsonResponse::with_status(
|
||||||
|
status,
|
||||||
|
serde_json::json!({ "coordinator": state }),
|
||||||
|
)
|
||||||
|
.no_cache()
|
||||||
|
.into_http_response());
|
||||||
|
}
|
||||||
_ => (),
|
_ => (),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -427,9 +427,24 @@ pub(crate) async fn trace_query(
|
|||||||
}
|
}
|
||||||
None => false,
|
None => false,
|
||||||
},
|
},
|
||||||
Property::QueueId => match value.as_str() {
|
// The queue id column is an integer on every search backend, and
|
||||||
|
// holds a trace's first queue id; the keywords carry all of them
|
||||||
|
Property::QueueId => match value
|
||||||
|
.as_str()
|
||||||
|
.and_then(|v| v.trim().parse::<u64>().ok())
|
||||||
|
.or_else(|| value.as_u64())
|
||||||
|
{
|
||||||
Some(queue_id) => {
|
Some(queue_id) => {
|
||||||
search.push(SearchFilter::eq(TracingSearchField::QueueId, queue_id.to_string()));
|
search.extend([
|
||||||
|
SearchFilter::Or,
|
||||||
|
SearchFilter::eq(TracingSearchField::QueueId, queue_id),
|
||||||
|
SearchFilter::has_text(
|
||||||
|
TracingSearchField::Keywords,
|
||||||
|
queue_id.to_string(),
|
||||||
|
nlp::language::Language::None,
|
||||||
|
),
|
||||||
|
SearchFilter::End,
|
||||||
|
]);
|
||||||
true
|
true
|
||||||
}
|
}
|
||||||
None => false,
|
None => false,
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ pub fn spawn_broadcast_subscriber(inner: Arc<Inner>, mut shutdown_rx: watch::Rec
|
|||||||
};
|
};
|
||||||
|
|
||||||
tokio::spawn(async move {
|
tokio::spawn(async move {
|
||||||
let mut retry_count = 0;
|
let mut retry_count: u32 = 0;
|
||||||
|
|
||||||
trc::event!(Cluster(ClusterEvent::SubscriberStart));
|
trc::event!(Cluster(ClusterEvent::SubscriberStart));
|
||||||
|
|
||||||
@@ -53,7 +53,7 @@ pub fn spawn_broadcast_subscriber(inner: Arc<Inner>, mut shutdown_rx: watch::Rec
|
|||||||
);
|
);
|
||||||
|
|
||||||
match tokio::time::timeout(
|
match tokio::time::timeout(
|
||||||
Duration::from_secs(1 << retry_count.max(6)),
|
subscribe_retry_delay(retry_count),
|
||||||
shutdown_rx.changed(),
|
shutdown_rx.changed(),
|
||||||
)
|
)
|
||||||
.await
|
.await
|
||||||
@@ -62,7 +62,7 @@ pub fn spawn_broadcast_subscriber(inner: Arc<Inner>, mut shutdown_rx: watch::Rec
|
|||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
Err(_) => {
|
Err(_) => {
|
||||||
retry_count += 1;
|
retry_count = retry_count.saturating_add(1);
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -234,6 +234,11 @@ pub fn spawn_broadcast_subscriber(inner: Arc<Inner>, mut shutdown_rx: watch::Rec
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Delay before the next subscribe attempt: 1 s, 2 s, 4 s ... capped at 64 s.
|
||||||
|
fn subscribe_retry_delay(retry_count: u32) -> Duration {
|
||||||
|
Duration::from_secs(1u64 << retry_count.min(6))
|
||||||
|
}
|
||||||
|
|
||||||
fn log_event(event: &BroadcastEvent) -> trc::Value {
|
fn log_event(event: &BroadcastEvent) -> trc::Value {
|
||||||
match event {
|
match event {
|
||||||
BroadcastEvent::PushNotification(notification) => match notification {
|
BroadcastEvent::PushNotification(notification) => match notification {
|
||||||
@@ -296,3 +301,19 @@ fn log_event(event: &BroadcastEvent) -> trc::Value {
|
|||||||
BroadcastEvent::QueueRefresh => "QueueRefresh".into(),
|
BroadcastEvent::QueueRefresh => "QueueRefresh".into(),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::subscribe_retry_delay;
|
||||||
|
use std::time::Duration;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn subscribe_retry_backoff_grows_then_caps() {
|
||||||
|
let schedule: Vec<u64> = (0..10)
|
||||||
|
.map(|n| subscribe_retry_delay(n).as_secs())
|
||||||
|
.collect();
|
||||||
|
assert_eq!(schedule, vec![1, 2, 4, 8, 16, 32, 64, 64, 64, 64]);
|
||||||
|
// No shift overflow at the top of the range.
|
||||||
|
assert_eq!(subscribe_retry_delay(u32::MAX), Duration::from_secs(64));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -567,20 +567,14 @@ async fn build_contact_document(
|
|||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
// inbuxa: MON-16: a trace's search document, when trace search is on:
|
// inbuxa: MON-16: a trace's search document, when trace search is on
|
||||||
// its event types, queue ids, and addresses, their domains, hosts, IPs,
|
|
||||||
// message ids and account names as keywords
|
|
||||||
async fn build_tracing_span_document(
|
async fn build_tracing_span_document(
|
||||||
server: &Server,
|
server: &Server,
|
||||||
span_id: u64,
|
span_id: u64,
|
||||||
) -> trc::Result<Option<IndexDocument>> {
|
) -> trc::Result<Option<IndexDocument>> {
|
||||||
use common::telemetry::tracers::store::MaybeTrace;
|
use common::telemetry::tracers::store::MaybeTrace;
|
||||||
use registry::schema::{enums::SearchTracingField, structs::Search};
|
use registry::schema::structs::Search;
|
||||||
use store::{
|
use store::write::{TelemetryClass, ValueClass};
|
||||||
search::TracingSearchField,
|
|
||||||
write::{TelemetryClass, ValueClass},
|
|
||||||
};
|
|
||||||
use trc::Key;
|
|
||||||
|
|
||||||
let settings = server
|
let settings = server
|
||||||
.registry()
|
.registry()
|
||||||
@@ -590,7 +584,6 @@ async fn build_tracing_span_document(
|
|||||||
if !settings.index_telemetry {
|
if !settings.index_telemetry {
|
||||||
return Ok(None);
|
return Ok(None);
|
||||||
}
|
}
|
||||||
let wants = |field: SearchTracingField| settings.index_tracing_fields.iter().any(|f| *f == field);
|
|
||||||
let Some(MaybeTrace(Some(trace))) = server
|
let Some(MaybeTrace(Some(trace))) = server
|
||||||
.tracing_store()
|
.tracing_store()
|
||||||
.get_value::<MaybeTrace>(ValueKey::from(ValueClass::Telemetry(TelemetryClass::Span(
|
.get_value::<MaybeTrace>(ValueKey::from(ValueClass::Telemetry(TelemetryClass::Span(
|
||||||
@@ -601,23 +594,67 @@ async fn build_tracing_span_document(
|
|||||||
return Ok(None);
|
return Ok(None);
|
||||||
};
|
};
|
||||||
|
|
||||||
let mut document = IndexDocument::new(SearchIndex::Tracing).with_id(span_id);
|
Ok(Some(trace_search_document(
|
||||||
let mut seen = store::ahash::AHashSet::new();
|
span_id,
|
||||||
for event in trace.events.iter() {
|
&trace,
|
||||||
if wants(SearchTracingField::EventType) && seen.insert(event.event.as_str().to_string()) {
|
&settings
|
||||||
document.index_keyword(TracingSearchField::EventType, event.event.as_str());
|
.index_tracing_fields
|
||||||
|
.iter()
|
||||||
|
.copied()
|
||||||
|
.collect::<Vec<_>>(),
|
||||||
|
)))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// inbuxa: MON-16: the search document for a stored trace.
|
||||||
|
///
|
||||||
|
/// The event type and queue id columns are integers on every search backend
|
||||||
|
/// (BIGINT on PostgreSQL and MySQL, long on Elasticsearch), and each holds a
|
||||||
|
/// single value per trace: the event type is the trace's opening event, the
|
||||||
|
/// one `x:Trace/query` filters on, and the queue id is the first queue id the
|
||||||
|
/// trace mentions. Every queue id also goes into the keywords, so a session
|
||||||
|
/// that queued several messages is found by any of them.
|
||||||
|
pub fn trace_search_document(
|
||||||
|
span_id: u64,
|
||||||
|
trace: ®istry::schema::structs::Trace,
|
||||||
|
fields: &[registry::schema::enums::SearchTracingField],
|
||||||
|
) -> IndexDocument {
|
||||||
|
use registry::schema::{enums::SearchTracingField, structs::TraceValue};
|
||||||
|
use store::search::TracingSearchField;
|
||||||
|
use trc::Key;
|
||||||
|
|
||||||
|
let wants = |field: SearchTracingField| fields.contains(&field);
|
||||||
|
let mut document = IndexDocument::new(SearchIndex::Tracing).with_id(span_id);
|
||||||
|
if wants(SearchTracingField::EventType)
|
||||||
|
&& let Some(first) = trace.events.iter().next()
|
||||||
|
{
|
||||||
|
document.index_unsigned(TracingSearchField::EventType, first.event.to_id() as u64);
|
||||||
|
}
|
||||||
|
|
||||||
|
let mut seen = store::ahash::AHashSet::new();
|
||||||
|
let mut queue_id_indexed = false;
|
||||||
|
for event in trace.events.iter() {
|
||||||
for kv in event.key_values.iter() {
|
for kv in event.key_values.iter() {
|
||||||
let text = match &kv.value {
|
let text = match &kv.value {
|
||||||
registry::schema::structs::TraceValue::String(v) => v.value.clone(),
|
TraceValue::String(v) => v.value.clone(),
|
||||||
registry::schema::structs::TraceValue::UnsignedInt(v) => v.value.to_string(),
|
TraceValue::UnsignedInt(v) => v.value.to_string(),
|
||||||
registry::schema::structs::TraceValue::IpAddr(v) => v.value.to_string(),
|
TraceValue::IpAddr(v) => v.value.to_string(),
|
||||||
_ => continue,
|
_ => continue,
|
||||||
};
|
};
|
||||||
match kv.key {
|
match kv.key {
|
||||||
Key::QueueId if wants(SearchTracingField::QueueId) => {
|
Key::QueueId => {
|
||||||
if seen.insert(format!("q:{text}")) {
|
let Ok(queue_id) = text.parse::<u64>() else {
|
||||||
document.index_keyword(TracingSearchField::QueueId, &text);
|
continue;
|
||||||
|
};
|
||||||
|
if wants(SearchTracingField::QueueId) && !queue_id_indexed {
|
||||||
|
document.index_unsigned(TracingSearchField::QueueId, queue_id);
|
||||||
|
queue_id_indexed = true;
|
||||||
|
}
|
||||||
|
if wants(SearchTracingField::Keywords) && seen.insert(format!("k:{text}")) {
|
||||||
|
document.index_text(
|
||||||
|
TracingSearchField::Keywords,
|
||||||
|
&text,
|
||||||
|
nlp::language::Language::None,
|
||||||
|
);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Key::From
|
Key::From
|
||||||
@@ -648,7 +685,7 @@ async fn build_tracing_span_document(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Ok(Some(document))
|
document
|
||||||
}
|
}
|
||||||
|
|
||||||
// inbuxa: UD-1, UD-4: archives a deleted file, event or contact noted at
|
// inbuxa: UD-1, UD-4: archives a deleted file, event or contact noted at
|
||||||
|
|||||||
@@ -10,8 +10,9 @@
|
|||||||
|
|
||||||
// inbuxa: 637 to 641 are the fork's SCIM events (SCIM-54); 642 is
|
// inbuxa: 637 to 641 are the fork's SCIM events (SCIM-54); 642 is
|
||||||
// auth.legacy-protocol-refused (legacy-protocols LP-6); 643 is
|
// auth.legacy-protocol-refused (legacy-protocols LP-6); 643 is
|
||||||
// security.legacy-protocols-changed (LP-8)
|
// security.legacy-protocols-changed (LP-8); 644 to 646 are the cluster
|
||||||
pub const TOTAL_EVENT_COUNT: usize = 644;
|
// coordinator's connection events
|
||||||
|
pub const TOTAL_EVENT_COUNT: usize = 647;
|
||||||
pub const TOTAL_METRIC_COUNT: usize = 369;
|
pub const TOTAL_METRIC_COUNT: usize = 369;
|
||||||
|
|
||||||
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)]
|
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)]
|
||||||
@@ -150,6 +151,10 @@ pub enum ClusterEvent {
|
|||||||
MessageSkipped = 47,
|
MessageSkipped = 47,
|
||||||
MessageInvalid = 49,
|
MessageInvalid = 49,
|
||||||
NodeIdRenewed = 275,
|
NodeIdRenewed = 275,
|
||||||
|
// inbuxa: the coordinator's connection
|
||||||
|
CoordinatorConnected = 644,
|
||||||
|
CoordinatorDisconnected = 645,
|
||||||
|
CoordinatorError = 646,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)]
|
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)]
|
||||||
|
|||||||
@@ -81,6 +81,10 @@ impl EventType {
|
|||||||
b"cluster.message-skipped" => EventType::Cluster(ClusterEvent::MessageSkipped),
|
b"cluster.message-skipped" => EventType::Cluster(ClusterEvent::MessageSkipped),
|
||||||
b"cluster.message-invalid" => EventType::Cluster(ClusterEvent::MessageInvalid),
|
b"cluster.message-invalid" => EventType::Cluster(ClusterEvent::MessageInvalid),
|
||||||
b"cluster.node-id-renewed" => EventType::Cluster(ClusterEvent::NodeIdRenewed),
|
b"cluster.node-id-renewed" => EventType::Cluster(ClusterEvent::NodeIdRenewed),
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
b"cluster.coordinator-connected" => EventType::Cluster(ClusterEvent::CoordinatorConnected),
|
||||||
|
b"cluster.coordinator-disconnected" => EventType::Cluster(ClusterEvent::CoordinatorDisconnected),
|
||||||
|
b"cluster.coordinator-error" => EventType::Cluster(ClusterEvent::CoordinatorError),
|
||||||
b"dane.authentication-success" => EventType::Dane(DaneEvent::AuthenticationSuccess),
|
b"dane.authentication-success" => EventType::Dane(DaneEvent::AuthenticationSuccess),
|
||||||
b"dane.authentication-failure" => EventType::Dane(DaneEvent::AuthenticationFailure),
|
b"dane.authentication-failure" => EventType::Dane(DaneEvent::AuthenticationFailure),
|
||||||
b"dane.no-certificates-found" => EventType::Dane(DaneEvent::NoCertificatesFound),
|
b"dane.no-certificates-found" => EventType::Dane(DaneEvent::NoCertificatesFound),
|
||||||
@@ -742,6 +746,14 @@ impl EventType {
|
|||||||
EventType::Cluster(ClusterEvent::MessageSkipped) => "cluster.message-skipped",
|
EventType::Cluster(ClusterEvent::MessageSkipped) => "cluster.message-skipped",
|
||||||
EventType::Cluster(ClusterEvent::MessageInvalid) => "cluster.message-invalid",
|
EventType::Cluster(ClusterEvent::MessageInvalid) => "cluster.message-invalid",
|
||||||
EventType::Cluster(ClusterEvent::NodeIdRenewed) => "cluster.node-id-renewed",
|
EventType::Cluster(ClusterEvent::NodeIdRenewed) => "cluster.node-id-renewed",
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorConnected) => {
|
||||||
|
"cluster.coordinator-connected"
|
||||||
|
}
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorDisconnected) => {
|
||||||
|
"cluster.coordinator-disconnected"
|
||||||
|
}
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorError) => "cluster.coordinator-error",
|
||||||
EventType::Dane(DaneEvent::AuthenticationSuccess) => "dane.authentication-success",
|
EventType::Dane(DaneEvent::AuthenticationSuccess) => "dane.authentication-success",
|
||||||
EventType::Dane(DaneEvent::AuthenticationFailure) => "dane.authentication-failure",
|
EventType::Dane(DaneEvent::AuthenticationFailure) => "dane.authentication-failure",
|
||||||
EventType::Dane(DaneEvent::NoCertificatesFound) => "dane.no-certificates-found",
|
EventType::Dane(DaneEvent::NoCertificatesFound) => "dane.no-certificates-found",
|
||||||
@@ -1524,6 +1536,10 @@ impl EventType {
|
|||||||
EventType::Cluster(ClusterEvent::MessageSkipped) => 47,
|
EventType::Cluster(ClusterEvent::MessageSkipped) => 47,
|
||||||
EventType::Cluster(ClusterEvent::MessageInvalid) => 49,
|
EventType::Cluster(ClusterEvent::MessageInvalid) => 49,
|
||||||
EventType::Cluster(ClusterEvent::NodeIdRenewed) => 275,
|
EventType::Cluster(ClusterEvent::NodeIdRenewed) => 275,
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorConnected) => 644,
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorDisconnected) => 645,
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorError) => 646,
|
||||||
EventType::Dane(DaneEvent::AuthenticationSuccess) => 67,
|
EventType::Dane(DaneEvent::AuthenticationSuccess) => 67,
|
||||||
EventType::Dane(DaneEvent::AuthenticationFailure) => 66,
|
EventType::Dane(DaneEvent::AuthenticationFailure) => 66,
|
||||||
EventType::Dane(DaneEvent::NoCertificatesFound) => 69,
|
EventType::Dane(DaneEvent::NoCertificatesFound) => 69,
|
||||||
@@ -2176,6 +2192,10 @@ impl EventType {
|
|||||||
47 => Some(EventType::Cluster(ClusterEvent::MessageSkipped)),
|
47 => Some(EventType::Cluster(ClusterEvent::MessageSkipped)),
|
||||||
49 => Some(EventType::Cluster(ClusterEvent::MessageInvalid)),
|
49 => Some(EventType::Cluster(ClusterEvent::MessageInvalid)),
|
||||||
275 => Some(EventType::Cluster(ClusterEvent::NodeIdRenewed)),
|
275 => Some(EventType::Cluster(ClusterEvent::NodeIdRenewed)),
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
644 => Some(EventType::Cluster(ClusterEvent::CoordinatorConnected)),
|
||||||
|
645 => Some(EventType::Cluster(ClusterEvent::CoordinatorDisconnected)),
|
||||||
|
646 => Some(EventType::Cluster(ClusterEvent::CoordinatorError)),
|
||||||
67 => Some(EventType::Dane(DaneEvent::AuthenticationSuccess)),
|
67 => Some(EventType::Dane(DaneEvent::AuthenticationSuccess)),
|
||||||
66 => Some(EventType::Dane(DaneEvent::AuthenticationFailure)),
|
66 => Some(EventType::Dane(DaneEvent::AuthenticationFailure)),
|
||||||
69 => Some(EventType::Dane(DaneEvent::NoCertificatesFound)),
|
69 => Some(EventType::Dane(DaneEvent::NoCertificatesFound)),
|
||||||
@@ -3114,6 +3134,10 @@ impl EventType {
|
|||||||
EventType::Auth(AuthEvent::TooManyAttempts) => Level::Warn,
|
EventType::Auth(AuthEvent::TooManyAttempts) => Level::Warn,
|
||||||
EventType::Calendar(CalendarEvent::AlarmFailed) => Level::Warn,
|
EventType::Calendar(CalendarEvent::AlarmFailed) => Level::Warn,
|
||||||
EventType::Cluster(ClusterEvent::SubscriberDisconnected) => Level::Warn,
|
EventType::Cluster(ClusterEvent::SubscriberDisconnected) => Level::Warn,
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorConnected) => Level::Info,
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorDisconnected) => Level::Warn,
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorError) => Level::Warn,
|
||||||
EventType::Delivery(DeliveryEvent::MissingOutboundHostname) => Level::Warn,
|
EventType::Delivery(DeliveryEvent::MissingOutboundHostname) => Level::Warn,
|
||||||
EventType::Delivery(DeliveryEvent::ConcurrencyLimitExceeded) => Level::Warn,
|
EventType::Delivery(DeliveryEvent::ConcurrencyLimitExceeded) => Level::Warn,
|
||||||
EventType::Delivery(DeliveryEvent::RateLimitExceeded) => Level::Warn,
|
EventType::Delivery(DeliveryEvent::RateLimitExceeded) => Level::Warn,
|
||||||
@@ -3244,6 +3268,10 @@ impl EventType {
|
|||||||
EventType::Cluster(ClusterEvent::MessageSkipped) => "PubSub message skipped",
|
EventType::Cluster(ClusterEvent::MessageSkipped) => "PubSub message skipped",
|
||||||
EventType::Cluster(ClusterEvent::MessageInvalid) => "Invalid PubSub message",
|
EventType::Cluster(ClusterEvent::MessageInvalid) => "Invalid PubSub message",
|
||||||
EventType::Cluster(ClusterEvent::NodeIdRenewed) => "Node ID renewed",
|
EventType::Cluster(ClusterEvent::NodeIdRenewed) => "Node ID renewed",
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorConnected) => "Coordinator connected",
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorDisconnected) => "Coordinator unavailable",
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorError) => "Coordinator error",
|
||||||
EventType::Dane(DaneEvent::AuthenticationSuccess) => "DANE authentication successful",
|
EventType::Dane(DaneEvent::AuthenticationSuccess) => "DANE authentication successful",
|
||||||
EventType::Dane(DaneEvent::AuthenticationFailure) => "DANE authentication failed",
|
EventType::Dane(DaneEvent::AuthenticationFailure) => "DANE authentication failed",
|
||||||
EventType::Dane(DaneEvent::NoCertificatesFound) => "No certificates found for DANE",
|
EventType::Dane(DaneEvent::NoCertificatesFound) => "No certificates found for DANE",
|
||||||
@@ -4322,6 +4350,10 @@ impl EventType {
|
|||||||
EventType::Cluster(ClusterEvent::MessageSkipped),
|
EventType::Cluster(ClusterEvent::MessageSkipped),
|
||||||
EventType::Cluster(ClusterEvent::MessageInvalid),
|
EventType::Cluster(ClusterEvent::MessageInvalid),
|
||||||
EventType::Cluster(ClusterEvent::NodeIdRenewed),
|
EventType::Cluster(ClusterEvent::NodeIdRenewed),
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorConnected),
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorDisconnected),
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorError),
|
||||||
EventType::Dane(DaneEvent::AuthenticationSuccess),
|
EventType::Dane(DaneEvent::AuthenticationSuccess),
|
||||||
EventType::Dane(DaneEvent::AuthenticationFailure),
|
EventType::Dane(DaneEvent::AuthenticationFailure),
|
||||||
EventType::Dane(DaneEvent::NoCertificatesFound),
|
EventType::Dane(DaneEvent::NoCertificatesFound),
|
||||||
|
|||||||
@@ -81,7 +81,7 @@ fn legacy_setting(name: &str, is_set: impl Fn(&str) -> bool) -> Option<String> {
|
|||||||
#[macro_export]
|
#[macro_export]
|
||||||
macro_rules! brand_version {
|
macro_rules! brand_version {
|
||||||
() => {
|
() => {
|
||||||
"2026.9.24"
|
"2026.9.24.3"
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -212,10 +212,15 @@ unchanged.
|
|||||||
- **MON-16.** With `indexTelemetry` on, storing a trace schedules an
|
- **MON-16.** With `indexTelemetry` on, storing a trace schedules an
|
||||||
`IndexTrace` task. The task builds one document for `SearchIndex::Tracing`
|
`IndexTrace` task. The task builds one document for `SearchIndex::Tracing`
|
||||||
with the fields named in `indexTracingFields`:
|
with the fields named in `indexTracingFields`:
|
||||||
- `eventType`: every event type in the trace;
|
- `eventType`: the trace's opening event, as its numeric id;
|
||||||
- `queueId`: every `queueId` value;
|
- `queueId`: the first `queueId` value, as an integer;
|
||||||
- `keywords`: every address in `from` and `to`, each address's domain, every
|
- `keywords`: every address in `from` and `to`, each address's domain, every
|
||||||
`domain`, `hostname`, `remoteIp`, `messageId` and `accountName` value.
|
`domain`, `hostname`, `remoteIp`, `messageId` and `accountName` value,
|
||||||
|
and every `queueId` value.
|
||||||
|
The event type and queue id are single integer columns on every search
|
||||||
|
backend (BIGINT on PostgreSQL and MySQL), so the `queueId` filter matches
|
||||||
|
the column or any queue id in the keywords, and a session that queued
|
||||||
|
several messages is found by each of them.
|
||||||
So searching `example.org` finds every trace to or from that domain, as the
|
So searching `example.org` finds every trace to or from that domain, as the
|
||||||
upstream suite expects. With `indexTelemetry` off nothing is indexed, and
|
upstream suite expects. With `indexTelemetry` off nothing is indexed, and
|
||||||
the `text` and `queueId` filters are refused (see "Interfaces").
|
the `text` and `queueId` filters are refused (see "Interfaces").
|
||||||
|
|||||||
Binary file not shown.
@@ -1 +1 @@
|
|||||||
VbnFuwCOTBh0s2T-NuRhb2JaJr8Jl5s3LgXv4Pv2sTg
|
XFI3xuKC_rH1KZyaVBF0uTIiRDXRqyYboijquiGz2eg
|
||||||
@@ -0,0 +1,145 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! A node that starts while its NATS coordinator is down joins the cluster
|
||||||
|
//! once NATS comes up, without a restart, and reports the coordinator's
|
||||||
|
//! connection on `/healthz/cluster` as it goes and comes back.
|
||||||
|
|
||||||
|
use crate::utils::server::TestServerBuilder;
|
||||||
|
use coordinator::Coordinator;
|
||||||
|
use registry::{
|
||||||
|
schema::{
|
||||||
|
enums::NetworkListenerProtocol,
|
||||||
|
structs::{Coordinator as CoordinatorSetting, NatsCoordinator},
|
||||||
|
},
|
||||||
|
types::map::Map,
|
||||||
|
};
|
||||||
|
use serde_json::{Value, json};
|
||||||
|
use std::time::{Duration, Instant};
|
||||||
|
use testcontainers::{
|
||||||
|
GenericImage, ImageExt, core::IntoContainerPort, core::WaitFor, runners::AsyncRunner,
|
||||||
|
};
|
||||||
|
|
||||||
|
const HTTP_PORT: u16 = 11_310;
|
||||||
|
const TOPIC: &str = "inbuxa-coordinator-test";
|
||||||
|
|
||||||
|
#[tokio::test(flavor = "multi_thread")]
|
||||||
|
pub async fn coordinator_reconnect_tests() {
|
||||||
|
println!("Running coordinator reconnect tests...");
|
||||||
|
|
||||||
|
// A port with no NATS server behind it, yet
|
||||||
|
let nats_port = std::net::TcpListener::bind("127.0.0.1:0")
|
||||||
|
.unwrap()
|
||||||
|
.local_addr()
|
||||||
|
.unwrap()
|
||||||
|
.port();
|
||||||
|
let config = NatsCoordinator {
|
||||||
|
addresses: Map::new(vec![format!("127.0.0.1:{nats_port}")]),
|
||||||
|
use_tls: false,
|
||||||
|
timeout_connection: 1_000u64.into(),
|
||||||
|
..Default::default()
|
||||||
|
};
|
||||||
|
|
||||||
|
// 1. The node starts, without a build error, while NATS is down, and
|
||||||
|
// says so
|
||||||
|
let test = TestServerBuilder::new("coordinator_reconnect_tests")
|
||||||
|
.await
|
||||||
|
.with_object(CoordinatorSetting::Nats(config.clone()))
|
||||||
|
.await
|
||||||
|
.with_listener(NetworkListenerProtocol::Http, "http", HTTP_PORT, true)
|
||||||
|
.await
|
||||||
|
.build()
|
||||||
|
.await;
|
||||||
|
let coordinator = test.server.core.storage.coordinator.clone();
|
||||||
|
assert!(
|
||||||
|
coordinator.is_enabled(),
|
||||||
|
"a coordinator, though not connected"
|
||||||
|
);
|
||||||
|
assert_eq!(coordinator.is_connected(), Some(false));
|
||||||
|
assert_eq!(
|
||||||
|
cluster_health().await,
|
||||||
|
(503, json!({"coordinator": "disconnected"}))
|
||||||
|
);
|
||||||
|
|
||||||
|
// A subscription made now, as the broadcast subscriber makes it at
|
||||||
|
// startup, has to work once NATS is up
|
||||||
|
let mut stream = coordinator.subscribe(TOPIC).await.unwrap();
|
||||||
|
|
||||||
|
// 2. NATS comes up: the node connects on its own
|
||||||
|
let nats = GenericImage::new("nats", "latest")
|
||||||
|
.with_wait_for(WaitFor::message_on_stderr("Server is ready"))
|
||||||
|
.with_mapped_port(nats_port, 4222.tcp())
|
||||||
|
.start()
|
||||||
|
.await
|
||||||
|
.expect("Failed to start NATS container");
|
||||||
|
wait_for_health(200, "connected").await;
|
||||||
|
let other_node = coordinator::backend::nats::NatsPubSub::open(config.clone())
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
wait_until_connected(&other_node).await;
|
||||||
|
round_trip(&other_node, &mut stream, b"after startup").await;
|
||||||
|
|
||||||
|
// 3. NATS goes away: the node reports it; and it comes back: the node
|
||||||
|
// reconnects and the same subscription carries on
|
||||||
|
nats.stop().await.unwrap();
|
||||||
|
wait_for_health(503, "disconnected").await;
|
||||||
|
nats.start().await.unwrap();
|
||||||
|
wait_for_health(200, "connected").await;
|
||||||
|
wait_until_connected(&other_node).await;
|
||||||
|
round_trip(&other_node, &mut stream, b"after reconnect").await;
|
||||||
|
|
||||||
|
drop(nats);
|
||||||
|
if test.is_reset() {
|
||||||
|
test.temp_dir.delete();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn cluster_health() -> (u16, Value) {
|
||||||
|
let response = reqwest::Client::builder()
|
||||||
|
.danger_accept_invalid_certs(true)
|
||||||
|
.timeout(Duration::from_secs(5))
|
||||||
|
.build()
|
||||||
|
.unwrap()
|
||||||
|
.get(format!("https://127.0.0.1:{HTTP_PORT}/healthz/cluster"))
|
||||||
|
.send()
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
let status = response.status().as_u16();
|
||||||
|
(status, response.json().await.unwrap())
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn wait_for_health(status: u16, state: &str) {
|
||||||
|
let started = Instant::now();
|
||||||
|
loop {
|
||||||
|
let health = cluster_health().await;
|
||||||
|
if health == (status, json!({"coordinator": state})) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
assert!(
|
||||||
|
started.elapsed() < Duration::from_secs(30),
|
||||||
|
"expected {status} {state}, still {health:?}"
|
||||||
|
);
|
||||||
|
tokio::time::sleep(Duration::from_millis(250)).await;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn wait_until_connected(coordinator: &Coordinator) {
|
||||||
|
let started = Instant::now();
|
||||||
|
while coordinator.is_connected() != Some(true) {
|
||||||
|
assert!(started.elapsed() < Duration::from_secs(30), "not connected");
|
||||||
|
tokio::time::sleep(Duration::from_millis(100)).await;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Another node publishes; this one's subscription receives it.
|
||||||
|
async fn round_trip(from: &Coordinator, stream: &mut coordinator::PubSubStream, payload: &[u8]) {
|
||||||
|
from.publish(TOPIC, payload.to_vec()).await.unwrap();
|
||||||
|
let message = tokio::time::timeout(Duration::from_secs(10), stream.next())
|
||||||
|
.await
|
||||||
|
.expect("no message within 10 seconds")
|
||||||
|
.expect("subscription ended");
|
||||||
|
assert_eq!(message.payload(), payload);
|
||||||
|
}
|
||||||
@@ -2,7 +2,11 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
pub mod broadcast;
|
pub mod broadcast;
|
||||||
|
#[cfg(feature = "nats")]
|
||||||
|
pub mod coordinator; // inbuxa: coordinator reconnects
|
||||||
pub mod stress;
|
pub mod stress;
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::utils::{
|
use crate::utils::{
|
||||||
@@ -9,14 +11,22 @@ use crate::utils::{
|
|||||||
server::TestServer,
|
server::TestServer,
|
||||||
temp_dir::TempDir,
|
temp_dir::TempDir,
|
||||||
};
|
};
|
||||||
use ::registry::schema::enums::CompressionAlgo;
|
use ::registry::schema::{
|
||||||
|
enums::{CompressionAlgo, TaskStoreMaintenanceType},
|
||||||
|
prelude::ObjectType,
|
||||||
|
structs::Task,
|
||||||
|
};
|
||||||
use ahash::AHashSet;
|
use ahash::AHashSet;
|
||||||
use common::{DATABASE_SCHEMA_VERSION, manager::backup::BackupParams};
|
use common::{
|
||||||
|
DATABASE_SCHEMA_VERSION,
|
||||||
|
manager::{SPAM_CLASSIFIER_KEY, SPAM_TRAINER_KEY, backup::BackupParams},
|
||||||
|
};
|
||||||
use store::{
|
use store::{
|
||||||
rand,
|
rand,
|
||||||
write::{
|
write::{
|
||||||
AnyClass, AnyKey, BatchBuilder, BlobLink, BlobOp, Operation, QueueClass, QueueEvent,
|
AnyClass, AnyKey, BatchBuilder, BlobLink, BlobOp, Operation, QueueClass, QueueEvent,
|
||||||
RegistryClass, ValueClass, key::KeySerializer,
|
RegistryClass, TaskQueueClass, ValueClass,
|
||||||
|
key::{DeserializeBigEndian, KeySerializer},
|
||||||
},
|
},
|
||||||
*,
|
*,
|
||||||
};
|
};
|
||||||
@@ -167,6 +177,50 @@ pub async fn test(test: &TestServer) {
|
|||||||
}
|
}
|
||||||
db.write(batch.build_all()).await.unwrap();
|
db.write(batch.build_all()).await.unwrap();
|
||||||
|
|
||||||
|
// inbuxa: registry objects kept outside the registry subspace (archived
|
||||||
|
// items for undelete, spam training samples, directory entries) and the
|
||||||
|
// fork's own subspace. Exports used to leave the first two behind.
|
||||||
|
println!("Creating archived items, spam samples and fork data...");
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
for item_id in [1u64, 2, 3] {
|
||||||
|
for object in [
|
||||||
|
ObjectType::ArchivedItem,
|
||||||
|
ObjectType::SpamTrainingSample,
|
||||||
|
ObjectType::Account,
|
||||||
|
] {
|
||||||
|
batch.set(
|
||||||
|
ValueClass::Registry(RegistryClass::Item {
|
||||||
|
object_id: object as u16,
|
||||||
|
item_id,
|
||||||
|
}),
|
||||||
|
random_bytes(item_id as usize * 64),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
batch.set(
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace: SUBSPACE_INBUXA,
|
||||||
|
key: [b'U', b'x']
|
||||||
|
.into_iter()
|
||||||
|
.chain(item_id.to_be_bytes())
|
||||||
|
.collect(),
|
||||||
|
}),
|
||||||
|
random_bytes(32),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
db.write(batch.build_all()).await.unwrap();
|
||||||
|
|
||||||
|
// inbuxa: the trained spam classifier lives in blobs with fixed names
|
||||||
|
let mut named_blobs = Vec::new();
|
||||||
|
for key in [SPAM_CLASSIFIER_KEY, SPAM_TRAINER_KEY] {
|
||||||
|
let data = random_bytes(4096);
|
||||||
|
test.server
|
||||||
|
.blob_store()
|
||||||
|
.put_blob(key, &data, CompressionAlgo::Lz4)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
named_blobs.push((key, data));
|
||||||
|
}
|
||||||
|
|
||||||
// Create directory data
|
// Create directory data
|
||||||
println!("Creating directory data...");
|
println!("Creating directory data...");
|
||||||
let mut batch = BatchBuilder::new();
|
let mut batch = BatchBuilder::new();
|
||||||
@@ -185,6 +239,17 @@ pub async fn test(test: &TestServer) {
|
|||||||
println!("Calculating store hash...");
|
println!("Calculating store hash...");
|
||||||
let snapshot = Snapshot::new(&db).await;
|
let snapshot = Snapshot::new(&db).await;
|
||||||
assert!(!snapshot.keys.is_empty(), "Store hash counts are empty",);
|
assert!(!snapshot.keys.is_empty(), "Store hash counts are empty",);
|
||||||
|
for subspace in [
|
||||||
|
SUBSPACE_DELETED_ITEMS,
|
||||||
|
SUBSPACE_SPAM_SAMPLES,
|
||||||
|
SUBSPACE_INBUXA,
|
||||||
|
] {
|
||||||
|
assert!(
|
||||||
|
snapshot.keys.iter().any(|k| k.subspace == subspace),
|
||||||
|
"No test data in subspace {}",
|
||||||
|
char::from(subspace)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
// Export store
|
// Export store
|
||||||
println!("Exporting store...");
|
println!("Exporting store...");
|
||||||
@@ -210,22 +275,188 @@ pub async fn test(test: &TestServer) {
|
|||||||
.finalize(),
|
.finalize(),
|
||||||
);
|
);
|
||||||
db.write(batch.build_all()).await.unwrap();
|
db.write(batch.build_all()).await.unwrap();
|
||||||
test.server.core.restore(temp_dir.path.clone()).await;
|
for (key, _) in &named_blobs {
|
||||||
|
test.server.blob_store().delete_blob(key).await.unwrap();
|
||||||
|
}
|
||||||
|
let imported = test.server.core.restore(temp_dir.path.clone()).await;
|
||||||
let mut batch = BatchBuilder::new();
|
let mut batch = BatchBuilder::new();
|
||||||
batch.clear(ValueClass::NodeId(0));
|
batch.clear(ValueClass::NodeId(0));
|
||||||
db.write(batch.build_all()).await.unwrap();
|
db.write(batch.build_all()).await.unwrap();
|
||||||
|
for subspace in [
|
||||||
|
SUBSPACE_DELETED_ITEMS,
|
||||||
|
SUBSPACE_SPAM_SAMPLES,
|
||||||
|
SUBSPACE_INBUXA,
|
||||||
|
] {
|
||||||
|
assert!(
|
||||||
|
imported.contains(&subspace),
|
||||||
|
"Subspace {} was not exported",
|
||||||
|
char::from(subspace)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
// Verify hash
|
// Verify hash
|
||||||
print!("Verifying store hash...");
|
print!("Verifying store hash...");
|
||||||
snapshot.assert_is_eq(&Snapshot::new(&db).await);
|
snapshot.assert_is_eq(&Snapshot::new(&db).await);
|
||||||
|
assert_named_blobs(test.server.blob_store(), &named_blobs).await;
|
||||||
println!(" GREAT SUCCESS!");
|
println!(" GREAT SUCCESS!");
|
||||||
|
|
||||||
|
// inbuxa: import the same export into a fresh store of another backend,
|
||||||
|
// the way a move from one database to another does it
|
||||||
|
#[cfg(all(feature = "rocks", feature = "sqlite"))]
|
||||||
|
cross_backend(test, &db, &temp_dir, &named_blobs).await;
|
||||||
|
|
||||||
// Destroy store
|
// Destroy store
|
||||||
|
for (key, _) in &named_blobs {
|
||||||
|
test.server.blob_store().delete_blob(key).await.unwrap();
|
||||||
|
}
|
||||||
store_destroy(&db).await;
|
store_destroy(&db).await;
|
||||||
store_assert_is_empty(&db, db.clone().into(), true).await;
|
store_assert_is_empty(&db, db.clone().into(), true).await;
|
||||||
temp_dir.delete();
|
temp_dir.delete();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(all(feature = "rocks", feature = "sqlite"))]
|
||||||
|
async fn cross_backend(
|
||||||
|
test: &TestServer,
|
||||||
|
source: &Store,
|
||||||
|
export: &TempDir,
|
||||||
|
named_blobs: &[(&[u8], Vec<u8>)],
|
||||||
|
) {
|
||||||
|
let source_type = std::env::var("STORE").unwrap();
|
||||||
|
let target_type = if source_type.eq_ignore_ascii_case("sqlite") {
|
||||||
|
"RocksDb"
|
||||||
|
} else {
|
||||||
|
"Sqlite"
|
||||||
|
};
|
||||||
|
println!("Importing the export into a fresh {target_type} store...");
|
||||||
|
|
||||||
|
let target_dir = TempDir::new("art_vandelay_cross_backend", true);
|
||||||
|
let target = Store::build(
|
||||||
|
crate::utils::storage::build_data_store(target_type, &target_dir.path.to_string_lossy())
|
||||||
|
.await,
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
target.create_tables().await.unwrap();
|
||||||
|
store_destroy(&target).await;
|
||||||
|
|
||||||
|
let mut core = test.server.core.as_ref().clone();
|
||||||
|
core.storage.data = target.clone();
|
||||||
|
core.storage.blob = target.clone().into();
|
||||||
|
let imported = core.restore(export.path.clone()).await;
|
||||||
|
|
||||||
|
// Counters are stored differently by the SQL and key-value backends, so
|
||||||
|
// compare their keys here and their values through the counter API.
|
||||||
|
print!("Verifying {target_type} store hash...");
|
||||||
|
Snapshot::new_portable(source)
|
||||||
|
.await
|
||||||
|
.assert_is_eq(&Snapshot::new_portable(&target).await);
|
||||||
|
for subspace in [SUBSPACE_COUNTER, SUBSPACE_QUOTA] {
|
||||||
|
let mut keys = Vec::new();
|
||||||
|
source
|
||||||
|
.iterate(
|
||||||
|
IterateParams::new(
|
||||||
|
AnyKey {
|
||||||
|
subspace,
|
||||||
|
key: vec![0u8],
|
||||||
|
},
|
||||||
|
AnyKey {
|
||||||
|
subspace,
|
||||||
|
key: vec![u8::MAX; 10],
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.no_values(),
|
||||||
|
|key, _| {
|
||||||
|
keys.push(key.to_vec());
|
||||||
|
Ok(true)
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
for key in keys {
|
||||||
|
let class = || {
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace,
|
||||||
|
key: key.clone(),
|
||||||
|
})
|
||||||
|
};
|
||||||
|
assert_eq!(
|
||||||
|
source.get_counter(class()).await.unwrap(),
|
||||||
|
target.get_counter(class()).await.unwrap(),
|
||||||
|
"Counter mismatch in {} for {key:?}",
|
||||||
|
char::from(subspace)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
assert_named_blobs(&core.storage.blob, named_blobs).await;
|
||||||
|
println!(" GREAT SUCCESS!");
|
||||||
|
|
||||||
|
// The search index isn't exported; the import queues its rebuild
|
||||||
|
let queued = core.queue_reindex(&imported).await;
|
||||||
|
let expected = [
|
||||||
|
TaskStoreMaintenanceType::ReindexAccounts,
|
||||||
|
TaskStoreMaintenanceType::ReindexTelemetry,
|
||||||
|
];
|
||||||
|
assert_eq!(queued, expected);
|
||||||
|
let mut task_ids = Vec::new();
|
||||||
|
target
|
||||||
|
.iterate(
|
||||||
|
IterateParams::new(
|
||||||
|
AnyKey {
|
||||||
|
subspace: SUBSPACE_TASK_QUEUE,
|
||||||
|
key: vec![0u8],
|
||||||
|
},
|
||||||
|
AnyKey {
|
||||||
|
subspace: SUBSPACE_TASK_QUEUE,
|
||||||
|
key: vec![u8::MAX; 20],
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.no_values(),
|
||||||
|
|key, _| {
|
||||||
|
if key.deserialize_be_u64(0)? == 0 {
|
||||||
|
task_ids.push(key.deserialize_be_u64(U64_LEN)?);
|
||||||
|
}
|
||||||
|
Ok(true)
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
let mut found = Vec::new();
|
||||||
|
for id in task_ids {
|
||||||
|
match target
|
||||||
|
.get_value::<Task>(ValueKey::from(ValueClass::TaskQueue(
|
||||||
|
TaskQueueClass::Task { id },
|
||||||
|
)))
|
||||||
|
.await
|
||||||
|
.unwrap()
|
||||||
|
{
|
||||||
|
Some(Task::StoreMaintenance(task)) => found.push(task.maintenance_type),
|
||||||
|
other => panic!("Unexpected task {other:?}"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
found.sort_by_key(|t| *t as u16);
|
||||||
|
assert_eq!(found, expected, "Queued tasks don't match");
|
||||||
|
|
||||||
|
store_destroy(&target).await;
|
||||||
|
drop(core);
|
||||||
|
drop(target);
|
||||||
|
target_dir.delete();
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn assert_named_blobs(blob_store: &BlobStore, named_blobs: &[(&[u8], Vec<u8>)]) {
|
||||||
|
for (key, data) in named_blobs {
|
||||||
|
assert_eq!(
|
||||||
|
blob_store
|
||||||
|
.get_blob(key, 0..usize::MAX)
|
||||||
|
.await
|
||||||
|
.unwrap()
|
||||||
|
.as_ref(),
|
||||||
|
Some(data),
|
||||||
|
"Blob {} was not restored",
|
||||||
|
String::from_utf8_lossy(key)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
#[derive(Debug, PartialEq, Eq)]
|
#[derive(Debug, PartialEq, Eq)]
|
||||||
struct Snapshot {
|
struct Snapshot {
|
||||||
keys: AHashSet<KeyValue>,
|
keys: AHashSet<KeyValue>,
|
||||||
@@ -240,7 +471,19 @@ struct KeyValue {
|
|||||||
|
|
||||||
impl Snapshot {
|
impl Snapshot {
|
||||||
async fn new(db: &Store) -> Self {
|
async fn new(db: &Store) -> Self {
|
||||||
let is_sql = db.is_sql();
|
Self::build(db, !db.is_sql(), true).await
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Comparable across backends: no counter values, which the SQL and
|
||||||
|
/// key-value stores encode differently, and no blobs, which only live in
|
||||||
|
/// the data store when it doubles as the blob store.
|
||||||
|
#[cfg(all(feature = "rocks", feature = "sqlite"))]
|
||||||
|
async fn new_portable(db: &Store) -> Self {
|
||||||
|
Self::build(db, false, false).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn build(db: &Store, counter_values: bool, with_blobs: bool) -> Self {
|
||||||
|
let is_sql = !counter_values;
|
||||||
|
|
||||||
let mut keys = AHashSet::new();
|
let mut keys = AHashSet::new();
|
||||||
|
|
||||||
@@ -265,7 +508,12 @@ impl Snapshot {
|
|||||||
(SUBSPACE_QUOTA, !is_sql),
|
(SUBSPACE_QUOTA, !is_sql),
|
||||||
(SUBSPACE_REPORT_OUT, true),
|
(SUBSPACE_REPORT_OUT, true),
|
||||||
(SUBSPACE_REPORT_IN, true),
|
(SUBSPACE_REPORT_IN, true),
|
||||||
|
(SUBSPACE_DIRECTORY, true),
|
||||||
|
(SUBSPACE_INBUXA, true),
|
||||||
] {
|
] {
|
||||||
|
if subspace == SUBSPACE_BLOBS && !with_blobs {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
let from_key = AnyKey {
|
let from_key = AnyKey {
|
||||||
subspace,
|
subspace,
|
||||||
key: vec![0u8],
|
key: vec![0u8],
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::{store::deflate_test_resource, utils::server::TestServer};
|
use crate::{store::deflate_test_resource, utils::server::TestServer};
|
||||||
@@ -122,6 +124,10 @@ pub async fn test(test: &TestServer) {
|
|||||||
println!("Running global id filtering tests...");
|
println!("Running global id filtering tests...");
|
||||||
test_global(store.clone()).await;
|
test_global(store.clone()).await;
|
||||||
|
|
||||||
|
// inbuxa: trace documents as the index task builds them
|
||||||
|
println!("Running trace document tests...");
|
||||||
|
test_trace_documents(store.clone()).await;
|
||||||
|
|
||||||
// Large document insert test
|
// Large document insert test
|
||||||
println!("Running large document insert tests...");
|
println!("Running large document insert tests...");
|
||||||
let mut large_text = String::with_capacity(20 * 1024 * 1024);
|
let mut large_text = String::with_capacity(20 * 1024 * 1024);
|
||||||
@@ -809,3 +815,160 @@ async fn test_global(store: SearchStore) {
|
|||||||
AHashSet::from_iter([3, 4, 5])
|
AHashSet::from_iter([3, 4, 5])
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// inbuxa: MON-16: documents built by the index task from stored traces go
|
||||||
|
// into every search backend (the SQL backends type etyp and qid as BIGINT)
|
||||||
|
// and are found again by queue id and keyword.
|
||||||
|
async fn test_trace_documents(store: SearchStore) {
|
||||||
|
use registry::schema::{
|
||||||
|
enums::SearchTracingField,
|
||||||
|
structs::{
|
||||||
|
Trace, TraceEvent, TraceKeyValue, TraceValue, TraceValueString,
|
||||||
|
TraceValueUnsignedInt,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
use services::task_manager::index::trace_search_document;
|
||||||
|
use trc::{DeliveryEvent, EventType, Key, SmtpEvent};
|
||||||
|
|
||||||
|
let kv_u = |key: Key, value: u64| TraceKeyValue {
|
||||||
|
key,
|
||||||
|
value: TraceValue::UnsignedInt(TraceValueUnsignedInt { value }),
|
||||||
|
};
|
||||||
|
let kv_s = |key: Key, value: &str| TraceKeyValue {
|
||||||
|
key,
|
||||||
|
value: TraceValue::String(TraceValueString {
|
||||||
|
value: value.to_string(),
|
||||||
|
}),
|
||||||
|
};
|
||||||
|
let event = |event: EventType, key_values: Vec<TraceKeyValue>| TraceEvent {
|
||||||
|
event,
|
||||||
|
key_values: key_values.into(),
|
||||||
|
..Default::default()
|
||||||
|
};
|
||||||
|
let fields = [
|
||||||
|
SearchTracingField::EventType,
|
||||||
|
SearchTracingField::QueueId,
|
||||||
|
SearchTracingField::Keywords,
|
||||||
|
];
|
||||||
|
|
||||||
|
// An SMTP session that queued two messages, and a delivery attempt
|
||||||
|
let session = Trace {
|
||||||
|
events: vec![
|
||||||
|
event(
|
||||||
|
EventType::Smtp(SmtpEvent::ConnectionStart),
|
||||||
|
vec![kv_s(Key::RemoteIp, "192.0.2.7")],
|
||||||
|
),
|
||||||
|
event(
|
||||||
|
EventType::Smtp(SmtpEvent::MailFrom),
|
||||||
|
vec![kv_s(Key::From, "[email protected]")],
|
||||||
|
),
|
||||||
|
event(
|
||||||
|
EventType::Smtp(SmtpEvent::RcptTo),
|
||||||
|
vec![kv_u(Key::QueueId, 9_000_000_001), kv_s(Key::To, "[email protected]")],
|
||||||
|
),
|
||||||
|
event(
|
||||||
|
EventType::Smtp(SmtpEvent::RcptTo),
|
||||||
|
vec![kv_u(Key::QueueId, 9_000_000_002)],
|
||||||
|
),
|
||||||
|
]
|
||||||
|
.into(),
|
||||||
|
};
|
||||||
|
let delivery = Trace {
|
||||||
|
events: vec![event(
|
||||||
|
EventType::Delivery(DeliveryEvent::AttemptStart),
|
||||||
|
vec![kv_u(Key::QueueId, 9_000_000_003), kv_s(Key::Hostname, "relay.example.net")],
|
||||||
|
)]
|
||||||
|
.into(),
|
||||||
|
};
|
||||||
|
let documents = vec![
|
||||||
|
trace_search_document(100, &session, &fields),
|
||||||
|
trace_search_document(101, &delivery, &fields),
|
||||||
|
];
|
||||||
|
assert!(
|
||||||
|
documents
|
||||||
|
.iter()
|
||||||
|
.all(|d| d.has_field(&SearchField::Tracing(TracingSearchField::QueueId))
|
||||||
|
&& d.has_field(&SearchField::Tracing(TracingSearchField::EventType))),
|
||||||
|
"trace documents carry a queue id and an event type"
|
||||||
|
);
|
||||||
|
store.index(documents).await.unwrap();
|
||||||
|
if let SearchStore::ElasticSearch(store) = &store {
|
||||||
|
store.refresh_index(SearchIndex::Tracing).await.unwrap();
|
||||||
|
}
|
||||||
|
|
||||||
|
let query = |filters: Vec<SearchFilter>| {
|
||||||
|
let store = store.clone();
|
||||||
|
async move {
|
||||||
|
store
|
||||||
|
.query_global(
|
||||||
|
SearchQuery::new(SearchIndex::Tracing)
|
||||||
|
.with_filter(SearchFilter::ge(SearchField::Id, 100u64))
|
||||||
|
.with_filters(filters),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap()
|
||||||
|
.into_iter()
|
||||||
|
.collect::<AHashSet<_>>()
|
||||||
|
}
|
||||||
|
};
|
||||||
|
// By queue id, the way x:Trace/query asks: the queue id column, or any
|
||||||
|
// queue id in the keywords
|
||||||
|
let by_queue_id = |queue_id: u64| {
|
||||||
|
vec![
|
||||||
|
SearchFilter::Or,
|
||||||
|
SearchFilter::eq(TracingSearchField::QueueId, queue_id),
|
||||||
|
SearchFilter::has_text(
|
||||||
|
TracingSearchField::Keywords,
|
||||||
|
queue_id.to_string(),
|
||||||
|
Language::None,
|
||||||
|
),
|
||||||
|
SearchFilter::End,
|
||||||
|
]
|
||||||
|
};
|
||||||
|
assert_eq!(query(by_queue_id(9_000_000_001)).await, AHashSet::from_iter([100]));
|
||||||
|
assert_eq!(query(by_queue_id(9_000_000_002)).await, AHashSet::from_iter([100]));
|
||||||
|
assert_eq!(query(by_queue_id(9_000_000_003)).await, AHashSet::from_iter([101]));
|
||||||
|
assert_eq!(query(by_queue_id(9_000_000_004)).await, AHashSet::new());
|
||||||
|
assert_eq!(
|
||||||
|
query(vec![SearchFilter::eq(TracingSearchField::QueueId, 9_000_000_003u64)]).await,
|
||||||
|
AHashSet::from_iter([101])
|
||||||
|
);
|
||||||
|
// By opening event type
|
||||||
|
assert_eq!(
|
||||||
|
query(vec![SearchFilter::eq(
|
||||||
|
TracingSearchField::EventType,
|
||||||
|
EventType::Delivery(DeliveryEvent::AttemptStart).to_id() as u64,
|
||||||
|
)])
|
||||||
|
.await,
|
||||||
|
AHashSet::from_iter([101])
|
||||||
|
);
|
||||||
|
// By keyword: an address, lowercased, and its domain
|
||||||
|
assert_eq!(
|
||||||
|
query(vec![SearchFilter::has_text(
|
||||||
|
TracingSearchField::Keywords,
|
||||||
|
"example.org",
|
||||||
|
Language::None,
|
||||||
|
)])
|
||||||
|
.await,
|
||||||
|
AHashSet::from_iter([100])
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
query(vec![SearchFilter::has_text(
|
||||||
|
TracingSearchField::Keywords,
|
||||||
|
"relay.example.net",
|
||||||
|
Language::None,
|
||||||
|
)])
|
||||||
|
.await,
|
||||||
|
AHashSet::from_iter([101])
|
||||||
|
);
|
||||||
|
|
||||||
|
for id in [100u64, 101] {
|
||||||
|
store
|
||||||
|
.unindex(
|
||||||
|
SearchQuery::new(SearchIndex::Tracing)
|
||||||
|
.with_filter(SearchFilter::eq(SearchField::Id, id)),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -148,6 +148,73 @@ pub async fn test(test: &mut TestServer) {
|
|||||||
"test 9: to"
|
"test 9: to"
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// MON-16: the queueId filter finds the traces that name a queue id (the
|
||||||
|
// session that queued the message and its delivery attempt) through the
|
||||||
|
// search index, given as a string or a number (the index column is an
|
||||||
|
// integer)
|
||||||
|
fn queue_ids(value: &Value, out: &mut Vec<u64>) {
|
||||||
|
match value {
|
||||||
|
Value::Object(map) => {
|
||||||
|
if map.get("key").and_then(|k| k.as_str()) == Some("queueId")
|
||||||
|
&& let Some(id) = map
|
||||||
|
.get("value")
|
||||||
|
.and_then(|v| v.get("value").unwrap_or(v).as_u64())
|
||||||
|
{
|
||||||
|
out.push(id);
|
||||||
|
}
|
||||||
|
map.values().for_each(|v| queue_ids(v, out));
|
||||||
|
}
|
||||||
|
Value::Array(list) => list.iter().for_each(|v| queue_ids(v, out)),
|
||||||
|
_ => {}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
let with_ids = traces
|
||||||
|
.iter()
|
||||||
|
.map(|t| {
|
||||||
|
let mut ids = Vec::new();
|
||||||
|
queue_ids(t, &mut ids);
|
||||||
|
(t["id"].as_str().unwrap().to_string(), ids)
|
||||||
|
})
|
||||||
|
.collect::<Vec<_>>();
|
||||||
|
let queue_id = with_ids
|
||||||
|
.iter()
|
||||||
|
.find_map(|(_, ids)| ids.first().copied())
|
||||||
|
.expect("MON-16: a trace with a queue id");
|
||||||
|
let mut expected = with_ids
|
||||||
|
.iter()
|
||||||
|
.filter(|(_, ids)| ids.contains(&queue_id))
|
||||||
|
.map(|(id, _)| id.clone())
|
||||||
|
.collect::<Vec<_>>();
|
||||||
|
expected.sort();
|
||||||
|
for filter in [json!(queue_id.to_string()), json!(queue_id)] {
|
||||||
|
let response = admin
|
||||||
|
.jmap_method_call("x:Trace/query", json!({"filter": {"queueId": filter}}))
|
||||||
|
.await;
|
||||||
|
let mut found = response
|
||||||
|
.0
|
||||||
|
.pointer("/methodResponses/0/1/ids")
|
||||||
|
.and_then(|ids| ids.as_array())
|
||||||
|
.map(|ids| {
|
||||||
|
ids.iter()
|
||||||
|
.filter_map(|id| id.as_str().map(str::to_string))
|
||||||
|
.collect::<Vec<_>>()
|
||||||
|
})
|
||||||
|
.unwrap_or_default();
|
||||||
|
found.sort();
|
||||||
|
assert_eq!(found, expected, "MON-16: queueId {filter}: {response:?}");
|
||||||
|
}
|
||||||
|
let response = admin
|
||||||
|
.jmap_method_call(
|
||||||
|
"x:Trace/query",
|
||||||
|
json!({"filter": {"queueId": (queue_id ^ 0x5a5a_5a5a).to_string()}}),
|
||||||
|
)
|
||||||
|
.await;
|
||||||
|
assert_eq!(
|
||||||
|
response.0.pointer("/methodResponses/0/1/ids"),
|
||||||
|
Some(&json!([])),
|
||||||
|
"MON-16: an unknown queue id"
|
||||||
|
);
|
||||||
|
|
||||||
// Acceptance test 24: destroy removes a trace; create is refused
|
// Acceptance test 24: destroy removes a trace; create is refused
|
||||||
let trace_id = traces[0]["id"].as_str().unwrap().to_string();
|
let trace_id = traces[0]["id"].as_str().unwrap().to_string();
|
||||||
let response = admin
|
let response = admin
|
||||||
|
|||||||
Executable
+120
@@ -0,0 +1,120 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
# SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||||
|
# SPDX-License-Identifier: AGPL-3.0-or-later
|
||||||
|
"""Every path Cargo patches has to be in the image's build context.
|
||||||
|
|
||||||
|
Cargo.toml's [patch.crates-io] can point at a directory in this repository,
|
||||||
|
and the Dockerfile builds from a context that .dockerignore prunes to almost
|
||||||
|
nothing. Those two facts met on 2026-09-23: a vendored, patched sieve-rs
|
||||||
|
landed, CI stayed green -- it builds from a checkout, where the directory is
|
||||||
|
simply there -- and the release build failed on
|
||||||
|
|
||||||
|
failed to load source for dependency `sieve-rs`
|
||||||
|
failed to read /build/vendor/sieve-rs/Cargo.toml
|
||||||
|
|
||||||
|
after a tag had already been pushed. This is seconds, and it runs beside the
|
||||||
|
other fork checks rather than waiting for a release to find out.
|
||||||
|
|
||||||
|
Being in the context isn't enough on its own: the Dockerfile cooks the
|
||||||
|
dependencies (`cargo chef cook`) before it copies the tree in, from a recipe
|
||||||
|
that carries only the workspace's manifests. So each patched path must also be
|
||||||
|
copied into that stage before the cook step, or the same error comes back
|
||||||
|
there -- as it did for 2026.9.24.2, the first tag after the context fix.
|
||||||
|
"""
|
||||||
|
|
||||||
|
import re
|
||||||
|
import sys
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
root = Path(__file__).resolve().parents[2]
|
||||||
|
|
||||||
|
|
||||||
|
def patched_paths(manifest: Path) -> list[str]:
|
||||||
|
"""Directories named by a [patch...] section's `path = "..."` entries."""
|
||||||
|
out, in_patch = [], False
|
||||||
|
for line in manifest.read_text().splitlines():
|
||||||
|
stripped = line.strip()
|
||||||
|
if stripped.startswith("["):
|
||||||
|
in_patch = stripped.startswith("[patch")
|
||||||
|
continue
|
||||||
|
if not in_patch:
|
||||||
|
continue
|
||||||
|
m = re.search(r'path\s*=\s*"([^"]+)"', stripped)
|
||||||
|
if m:
|
||||||
|
out.append(m.group(1))
|
||||||
|
return out
|
||||||
|
|
||||||
|
|
||||||
|
def allowed(dockerignore: Path) -> set[str]:
|
||||||
|
"""The first path segment of every re-inclusion rule."""
|
||||||
|
keep = set()
|
||||||
|
for line in dockerignore.read_text().splitlines():
|
||||||
|
stripped = line.strip()
|
||||||
|
if stripped.startswith("!"):
|
||||||
|
keep.add(stripped[1:].strip("/").split("/")[0])
|
||||||
|
return keep
|
||||||
|
|
||||||
|
|
||||||
|
def copied_before_cook(dockerfile: Path) -> list[str] | None:
|
||||||
|
"""Sources COPY'd into the stage that runs `cargo chef cook`, before it.
|
||||||
|
|
||||||
|
None when no stage cooks. A `COPY . .` covers everything.
|
||||||
|
"""
|
||||||
|
stage: list[str] = []
|
||||||
|
for line in dockerfile.read_text().splitlines():
|
||||||
|
stripped = line.strip()
|
||||||
|
if re.match(r"(?i)^FROM\s", stripped):
|
||||||
|
stage = []
|
||||||
|
continue
|
||||||
|
if "cargo chef cook" in stripped:
|
||||||
|
return stage
|
||||||
|
m = re.match(r"(?i)^COPY\s+(?!--from)(.+)$", stripped)
|
||||||
|
if m:
|
||||||
|
parts = m.group(1).split()
|
||||||
|
stage.extend(p.strip("./").split("/")[0] or "." for p in parts[:-1])
|
||||||
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
def main() -> int:
|
||||||
|
paths = patched_paths(root / "Cargo.toml")
|
||||||
|
if not paths:
|
||||||
|
print("no patched paths to check")
|
||||||
|
return 0
|
||||||
|
keep = allowed(root / ".dockerignore")
|
||||||
|
bad = []
|
||||||
|
for p in paths:
|
||||||
|
top = p.strip("/").split("/")[0]
|
||||||
|
if top not in keep:
|
||||||
|
bad.append((p, top))
|
||||||
|
elif not (root / p).is_dir():
|
||||||
|
bad.append((p, None))
|
||||||
|
for path, top in bad:
|
||||||
|
if top is None:
|
||||||
|
print(f"Cargo.toml patches {path}, which does not exist", file=sys.stderr)
|
||||||
|
else:
|
||||||
|
print(
|
||||||
|
f"Cargo.toml patches {path}, but .dockerignore does not re-include {top!r}:\n"
|
||||||
|
f" the image build would not see it, and cargo would fail on it.\n"
|
||||||
|
f" Add `!{top}` to .dockerignore.",
|
||||||
|
file=sys.stderr,
|
||||||
|
)
|
||||||
|
copied = copied_before_cook(root / "Dockerfile")
|
||||||
|
if copied is not None and "." not in copied:
|
||||||
|
for p in paths:
|
||||||
|
top = p.strip("/").split("/")[0]
|
||||||
|
if top not in copied:
|
||||||
|
print(
|
||||||
|
f"Cargo.toml patches {p}, but the Dockerfile doesn't copy {top!r} into the\n"
|
||||||
|
f" stage that runs `cargo chef cook` before that step, so cooking the\n"
|
||||||
|
f" dependencies fails on it. Add `COPY {top}/ {top}/` before the cook.",
|
||||||
|
file=sys.stderr,
|
||||||
|
)
|
||||||
|
bad.append((p, top))
|
||||||
|
if bad:
|
||||||
|
return 1
|
||||||
|
print(f"build context and cook stage include every patched path: {', '.join(paths)}")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
raise SystemExit(main())
|
||||||
Reference in New Issue
Block a user