Compare commits
26
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
999ae12cc7 | ||
|
|
5853831bad | ||
|
|
639a415a4f | ||
|
|
9311c1a38b | ||
|
|
24be4a1b85 | ||
|
|
95f0445d83 | ||
|
|
c974a0918e | ||
|
|
7c80a12d75 | ||
|
|
22d8ad8572 | ||
|
|
7109e67f07 | ||
|
|
52b5a5f909 | ||
|
|
9232662913 | ||
|
|
57d1c5b074 | ||
|
|
ca3abf40f0 | ||
|
|
499e4d7810 | ||
|
|
212cd77cd3 | ||
|
|
7735780807 | ||
|
|
e223f7d327 | ||
|
|
30df055e39 | ||
|
|
5393c4405a | ||
|
|
cc532b914c | ||
|
|
c09eff2214 | ||
|
|
eba4c7a32e | ||
|
|
17426f6d60 | ||
|
|
d7c9416713 | ||
|
|
238079da66 |
+8
-2
@@ -1,10 +1,16 @@
|
|||||||
// Ignore everything
|
# Ignore everything
|
||||||
*
|
*
|
||||||
|
|
||||||
// Allow what is needed
|
# Allow what is needed
|
||||||
!crates
|
!crates
|
||||||
!tests
|
!tests
|
||||||
!resources
|
!resources
|
||||||
|
|
||||||
|
# The patched dependency Cargo.toml's [patch.crates-io] points at. Without
|
||||||
|
# it the build context has no vendor/, and `cargo chef cook` fails on
|
||||||
|
# "failed to load source for dependency sieve-rs" -- which CI cannot see,
|
||||||
|
# because CI builds from a checkout and only the image build has a context.
|
||||||
|
!vendor
|
||||||
|
|
||||||
!Cargo.lock
|
!Cargo.lock
|
||||||
!Cargo.toml
|
!Cargo.toml
|
||||||
|
|||||||
@@ -35,6 +35,11 @@ jobs:
|
|||||||
- run: python3 tools/fork/name-check.py
|
- run: python3 tools/fork/name-check.py
|
||||||
- if: always()
|
- if: always()
|
||||||
run: python3 tools/fork/notice-check.py
|
run: python3 tools/fork/notice-check.py
|
||||||
|
# Cargo can patch a dependency to a directory in this repository, and
|
||||||
|
# the image builds from a context .dockerignore prunes to almost
|
||||||
|
# nothing. CI never sees the difference; a release does.
|
||||||
|
- if: always()
|
||||||
|
run: python3 tools/fork/context-check.py
|
||||||
|
|
||||||
build:
|
build:
|
||||||
# Either runner (host1 or host2): the build needs no docker socket.
|
# Either runner (host1 or host2): the build needs no docker socket.
|
||||||
|
|||||||
@@ -3,11 +3,28 @@
|
|||||||
# whether a person pushed it or weekly-release.yml created it through the
|
# whether a person pushed it or weekly-release.yml created it through the
|
||||||
# releases API.
|
# releases API.
|
||||||
#
|
#
|
||||||
# The image is multi-arch (linux/amd64, linux/arm64) as before, but built in
|
# The image is multi-arch (linux/amd64, linux/arm64), built by two jobs on
|
||||||
# one buildx run on host1 instead of one native runner per architecture: the
|
# the image-build runner rather than one buildx run for both. The Dockerfile's
|
||||||
# Dockerfile's builder stage runs on the build platform and cross-compiles
|
# builder stage runs on the build platform and cross-compiles with an aarch64
|
||||||
# with an aarch64 linker, so only the small final stage (apt, setcap) goes
|
# linker, so only the small final stage (apt, setcap) goes through QEMU for
|
||||||
# through QEMU for arm64. No digest-joining job is needed.
|
# arm64 -- but two release builds (LTO, one codegen unit) side by side on one
|
||||||
|
# machine each take twice as long. Production runs amd64, so amd64 goes first
|
||||||
|
# and on its own:
|
||||||
|
# * publish-amd64 pushes :<version>-amd64 and :<version>, a plain amd64
|
||||||
|
# image, as soon as its build is done. A deploy can start from it.
|
||||||
|
# * publish-arm64 then builds arm64, pushes :<version>-arm64, and replaces
|
||||||
|
# :<version> with the two-platform index. :latest moves only here, so it
|
||||||
|
# never names an image without arm64.
|
||||||
|
#
|
||||||
|
# Both jobs use one BuildKit builder, `gitea-builder`, whose container
|
||||||
|
# (buildx_buildkit_gitea-builder0) and state volume stay on the runner's host
|
||||||
|
# between jobs: a job container's `buildx create` finds the existing container
|
||||||
|
# and reuses it and its cache. The dependency build (`cargo chef cook`) is
|
||||||
|
# keyed on the recipe, which only a dependency change alters, so a release
|
||||||
|
# normally compiles just the workspace. Removing that container or its volume
|
||||||
|
# costs the next release a cold build, nothing more. The planner and dependency
|
||||||
|
# layers for the build platform are shared, so arm64 also reuses what amd64
|
||||||
|
# just did where it can.
|
||||||
#
|
#
|
||||||
# Two guards before anything is pushed:
|
# Two guards before anything is pushed:
|
||||||
# * the tag must be v<brand_version!>. The version is a string in
|
# * the tag must be v<brand_version!>. The version is a string in
|
||||||
@@ -62,7 +79,7 @@ jobs:
|
|||||||
echo "version=$V" >> "$GITHUB_OUTPUT"
|
echo "version=$V" >> "$GITHUB_OUTPUT"
|
||||||
echo "version $V"
|
echo "version $V"
|
||||||
|
|
||||||
publish:
|
publish-amd64:
|
||||||
needs: [version]
|
needs: [version]
|
||||||
runs-on: docker
|
runs-on: docker
|
||||||
container:
|
container:
|
||||||
@@ -81,16 +98,15 @@ jobs:
|
|||||||
test -n "$REGISTRY" && test -n "$VERSION"
|
test -n "$REGISTRY" && test -n "$VERSION"
|
||||||
test -n "$PACKAGE_TOKEN" || { echo "PACKAGE_TOKEN secret is not set on this repository" >&2; exit 1; }
|
test -n "$PACKAGE_TOKEN" || { echo "PACKAGE_TOKEN secret is not set on this repository" >&2; exit 1; }
|
||||||
echo "$PACKAGE_TOKEN" | docker login -u jcoffey-dev --password-stdin "$REGISTRY"
|
echo "$PACKAGE_TOKEN" | docker login -u jcoffey-dev --password-stdin "$REGISTRY"
|
||||||
docker run --privileged --rm tonistiigi/binfmt --install arm64
|
|
||||||
docker buildx create --use --name gitea-builder --driver docker-container || docker buildx use gitea-builder
|
docker buildx create --use --name gitea-builder --driver docker-container || docker buildx use gitea-builder
|
||||||
# Attestations off, as before: they add manifests of their own to the
|
# Attestations off, as before: they add manifests of their own, and the
|
||||||
# index, and the index should hold the two images and nothing else.
|
# index should hold the two images and nothing else.
|
||||||
- run: |
|
- run: |
|
||||||
docker buildx build \
|
docker buildx build \
|
||||||
--platform linux/amd64,linux/arm64 \
|
--platform linux/amd64 \
|
||||||
--provenance=false --sbom=false \
|
--provenance=false --sbom=false \
|
||||||
|
--tag "$IMAGE:$VERSION-amd64" \
|
||||||
--tag "$IMAGE:$VERSION" \
|
--tag "$IMAGE:$VERSION" \
|
||||||
--tag "$IMAGE:latest" \
|
|
||||||
--push .
|
--push .
|
||||||
docker buildx imagetools inspect "$IMAGE:$VERSION"
|
docker buildx imagetools inspect "$IMAGE:$VERSION"
|
||||||
# Gitea keeps a container package on its owner; linking it shows it on
|
# Gitea keeps a container package on its owner; linking it shows it on
|
||||||
@@ -103,11 +119,47 @@ jobs:
|
|||||||
- if: always()
|
- if: always()
|
||||||
run: docker logout "$REGISTRY" || true
|
run: docker logout "$REGISTRY" || true
|
||||||
|
|
||||||
|
publish-arm64:
|
||||||
|
needs: [version, publish-amd64]
|
||||||
|
runs-on: docker
|
||||||
|
container:
|
||||||
|
image: docker:28-cli@sha256:625d9431a9f54c5a2bc90f24f0e1c3d55b1349fd857dd85035f98c2c9acbdd4d # 28-cli
|
||||||
|
volumes:
|
||||||
|
- /var/run/docker.sock:/var/run/docker.sock
|
||||||
|
env:
|
||||||
|
DOCKER_BUILDKIT: "1"
|
||||||
|
REGISTRY: ${{ vars.REGISTRY }}
|
||||||
|
IMAGE: ${{ vars.REGISTRY }}/${{ github.repository }}
|
||||||
|
VERSION: ${{ needs.version.outputs.version }}
|
||||||
|
PACKAGE_TOKEN: ${{ secrets.PACKAGE_TOKEN }}
|
||||||
|
steps:
|
||||||
|
- uses: coffey-labs/actions/checkout@fab0c4d45e0162963965f1555df27b7bed5e20ec
|
||||||
|
- run: |
|
||||||
|
echo "$PACKAGE_TOKEN" | docker login -u jcoffey-dev --password-stdin "$REGISTRY"
|
||||||
|
docker run --privileged --rm tonistiigi/binfmt --install arm64
|
||||||
|
docker buildx create --use --name gitea-builder --driver docker-container || docker buildx use gitea-builder
|
||||||
|
# The index is built from the two per-architecture tags rather than from
|
||||||
|
# :<version>, which by now is the amd64 image and would be read as such.
|
||||||
|
- run: |
|
||||||
|
docker buildx build \
|
||||||
|
--platform linux/arm64 \
|
||||||
|
--provenance=false --sbom=false \
|
||||||
|
--tag "$IMAGE:$VERSION-arm64" \
|
||||||
|
--push .
|
||||||
|
docker buildx imagetools create \
|
||||||
|
--tag "$IMAGE:$VERSION" \
|
||||||
|
--tag "$IMAGE:latest" \
|
||||||
|
"$IMAGE:$VERSION-amd64" "$IMAGE:$VERSION-arm64"
|
||||||
|
docker buildx imagetools inspect "$IMAGE:$VERSION"
|
||||||
|
- if: always()
|
||||||
|
run: docker logout "$REGISTRY" || true
|
||||||
|
|
||||||
# The weekly release creates its Release (and so the tag) first; a tag
|
# The weekly release creates its Release (and so the tag) first; a tag
|
||||||
# pushed by hand has none. Either way the tag ends up with exactly one
|
# pushed by hand has none. Either way the tag ends up with exactly one
|
||||||
# Release, created after the image exists so its pull instructions work.
|
# Release, created once the amd64 image exists so its pull instructions
|
||||||
|
# work; arm64 and the binaries follow.
|
||||||
release:
|
release:
|
||||||
needs: [version, publish]
|
needs: [version, publish-amd64]
|
||||||
runs-on: light
|
runs-on: light
|
||||||
container:
|
container:
|
||||||
image: python:3.13-slim@sha256:8d9d0b8bcf6506481eae4907c18f5e3e7902e629f5f6d684f9e7c32e85e3ddf0 # 3.13-slim
|
image: python:3.13-slim@sha256:8d9d0b8bcf6506481eae4907c18f5e3e7902e629f5f6d684f9e7c32e85e3ddf0 # 3.13-slim
|
||||||
@@ -131,7 +183,9 @@ jobs:
|
|||||||
except urllib.error.HTTPError as e:
|
except urllib.error.HTTPError as e:
|
||||||
if e.code != 404: raise
|
if e.code != 404: raise
|
||||||
image = f"{os.environ['REGISTRY']}/{os.environ['REPO']}:{version}"
|
image = f"{os.environ['REGISTRY']}/{os.environ['REPO']}:{version}"
|
||||||
body = (f"Container image: `{image}` (linux/amd64, linux/arm64); also `:latest`.\n\n"
|
body = (f"Container image: `{image}` (linux/amd64, linux/arm64); also `:latest`. "
|
||||||
|
"amd64 is published first; arm64 is added to the same tag when its build "
|
||||||
|
"finishes, and `:latest` moves then.\n\n"
|
||||||
"Binaries for a host install are attached: `inbuxa-linux-amd64.tar.gz` and "
|
"Binaries for a host install are attached: `inbuxa-linux-amd64.tar.gz` and "
|
||||||
"`inbuxa-linux-arm64.tar.gz`, with `SHA256SUMS`. Each is the binary out of this "
|
"`inbuxa-linux-arm64.tar.gz`, with `SHA256SUMS`. Each is the binary out of this "
|
||||||
"release's image for that architecture, so it is the same build. The image "
|
"release's image for that architecture, so it is the same build. The image "
|
||||||
@@ -154,7 +208,7 @@ jobs:
|
|||||||
# `docker create` does not start anything, so pulling an arm64 image on an
|
# `docker create` does not start anything, so pulling an arm64 image on an
|
||||||
# amd64 runner and copying a file out of it needs no emulation.
|
# amd64 runner and copying a file out of it needs no emulation.
|
||||||
binaries:
|
binaries:
|
||||||
needs: [version, publish, release]
|
needs: [version, publish-arm64, release]
|
||||||
runs-on: docker
|
runs-on: docker
|
||||||
container:
|
container:
|
||||||
image: docker:28-cli@sha256:625d9431a9f54c5a2bc90f24f0e1c3d55b1349fd857dd85035f98c2c9acbdd4d # 28-cli
|
image: docker:28-cli@sha256:625d9431a9f54c5a2bc90f24f0e1c3d55b1349fd857dd85035f98c2c9acbdd4d # 28-cli
|
||||||
|
|||||||
@@ -12,6 +12,9 @@
|
|||||||
# An issue is opened once per release: an existing one with the same title,
|
# An issue is opened once per release: an existing one with the same title,
|
||||||
# open or closed, stops a second.
|
# open or closed, stops a second.
|
||||||
#
|
#
|
||||||
|
# It also watches spam-filter, whose rules the server bundles
|
||||||
|
# (resources/spam-filter/), and opens an issue for a newer release.
|
||||||
|
#
|
||||||
# Daily 06:17 UTC; run it by hand with workflow_dispatch.
|
# Daily 06:17 UTC; run it by hand with workflow_dispatch.
|
||||||
name: upstream-watch
|
name: upstream-watch
|
||||||
|
|
||||||
@@ -64,7 +67,7 @@ jobs:
|
|||||||
and key(r["tag_name"]) > key(base)),
|
and key(r["tag_name"]) > key(base)),
|
||||||
key=lambda r: key(r["tag_name"]))
|
key=lambda r: key(r["tag_name"]))
|
||||||
if not newer:
|
if not newer:
|
||||||
print(f"Up to date: {base} is the newest upstream release."); sys.exit(0)
|
print(f"Up to date: {base} is the newest upstream release.")
|
||||||
|
|
||||||
# Titles and bodies stay free of the upstream project's name, as the
|
# Titles and bodies stay free of the upstream project's name, as the
|
||||||
# rest of the fork's user-visible text does.
|
# rest of the fork's user-visible text does.
|
||||||
@@ -85,4 +88,35 @@ jobs:
|
|||||||
"add any new third-party notices to `THIRD-PARTY.md`, then merge `upstream` into `main`.")
|
"add any new third-party notices to `THIRD-PARTY.md`, then merge `upstream` into `main`.")
|
||||||
issue = call("POST", f"{api}/issues", {"title": title, "body": body})
|
issue = call("POST", f"{api}/issues", {"title": title, "body": body})
|
||||||
print(f"{tag}: opened #{issue['number']}.")
|
print(f"{tag}: opened #{issue['number']}.")
|
||||||
|
|
||||||
|
# The spam filter rules bundled with the server (resources/spam-filter/):
|
||||||
|
# an issue when spam-filter publishes a newer release than the one
|
||||||
|
# BUNDLED_SPAM_RULES_VERSION names on main.
|
||||||
|
src = call("GET", f"{api}/contents/crates/common/src/manager/spam_rules.rs?ref=main")
|
||||||
|
import base64
|
||||||
|
text = base64.b64decode(src["content"]).decode()
|
||||||
|
m = re.search(r'BUNDLED_SPAM_RULES_VERSION: &str = "(\d+\.\d+\.\d+)"', text)
|
||||||
|
if not m:
|
||||||
|
print("Can't read BUNDLED_SPAM_RULES_VERSION from spam_rules.rs", file=sys.stderr); sys.exit(1)
|
||||||
|
bundled = "v" + m.group(1)
|
||||||
|
rels = call("GET", "https://api.github.com/repos/stalwartlabs/spam-filter/releases?per_page=30", token=None)
|
||||||
|
newer = sorted((r for r in rels
|
||||||
|
if not r["draft"] and not r["prerelease"] and SEMVER.match(r["tag_name"])
|
||||||
|
and key(r["tag_name"]) > key(bundled)),
|
||||||
|
key=lambda r: key(r["tag_name"]))
|
||||||
|
if not newer:
|
||||||
|
print(f"Up to date: the bundled spam rules are {bundled}, the newest release."); sys.exit(0)
|
||||||
|
latest = newer[-1]
|
||||||
|
tag = latest["tag_name"]
|
||||||
|
title = f"Update the bundled spam rules to {tag}"
|
||||||
|
existing = {i["title"] for i in call("GET", f"{api}/issues?state=all&type=issues&q=bundled+spam+rules&limit=50")}
|
||||||
|
if title in existing:
|
||||||
|
print(f"spam rules {tag}: issue already exists."); sys.exit(0)
|
||||||
|
body = (f"spam-filter published {tag} on {latest['published_at'][:10]}. "
|
||||||
|
f"The server bundles {bundled}.\n\n"
|
||||||
|
"Update it as resources/spam-filter/README.md describes: take the rules file "
|
||||||
|
f"from the {tag} release (by tag, not `latest`), set BUNDLED_SPAM_RULES_VERSION, "
|
||||||
|
"and run the antispam test.")
|
||||||
|
issue = call("POST", f"{api}/issues", {"title": title, "body": body})
|
||||||
|
print(f"spam rules {tag}: opened #{issue['number']}.")
|
||||||
PY
|
PY
|
||||||
|
|||||||
@@ -19,6 +19,10 @@ RUN export DEBIAN_FRONTEND=noninteractive && \
|
|||||||
g++-x86-64-linux-gnu binutils-x86-64-linux-gnu
|
g++-x86-64-linux-gnu binutils-x86-64-linux-gnu
|
||||||
RUN rustup target add "$(cat /target.txt)"
|
RUN rustup target add "$(cat /target.txt)"
|
||||||
COPY --from=planner /recipe.json /recipe.json
|
COPY --from=planner /recipe.json /recipe.json
|
||||||
|
# inbuxa: [patch.crates-io] points sieve-rs at vendor/, and the recipe only
|
||||||
|
# carries the workspace's own manifests, so cooking the dependencies needs the
|
||||||
|
# vendored crate itself (the context allows it since #27; this puts it here).
|
||||||
|
COPY vendor/ vendor/
|
||||||
RUN RUSTFLAGS="$(cat /flags.txt)" cargo chef cook --target "$(cat /target.txt)" --release --no-default-features --features "sqlite postgres mysql rocks s3 redis azure nats" --recipe-path /recipe.json
|
RUN RUSTFLAGS="$(cat /flags.txt)" cargo chef cook --target "$(cat /target.txt)" --release --no-default-features --features "sqlite postgres mysql rocks s3 redis azure nats" --recipe-path /recipe.json
|
||||||
COPY . .
|
COPY . .
|
||||||
RUN RUSTFLAGS="$(cat /flags.txt)" cargo build --target "$(cat /target.txt)" --release -p inbuxa --no-default-features --features "sqlite postgres mysql rocks s3 redis azure nats"
|
RUN RUSTFLAGS="$(cat /flags.txt)" cargo build --target "$(cat /target.txt)" --release -p inbuxa --no-default-features --features "sqlite postgres mysql rocks s3 redis azure nats"
|
||||||
|
|||||||
+1
-1
@@ -24,7 +24,7 @@ carry their own license files.
|
|||||||
| `crates/common/src/network/acme/directory.rs`, `crates/common/src/network/acme/jose.rs`, `crates/common/src/network/acme/order.rs` | [rustls-acme](https://github.com/FlorianUekermann/rustls-acme) (MIT or Apache-2.0) | Copyright (c) Florian Uekermann |
|
| `crates/common/src/network/acme/directory.rs`, `crates/common/src/network/acme/jose.rs`, `crates/common/src/network/acme/order.rs` | [rustls-acme](https://github.com/FlorianUekermann/rustls-acme) (MIT or Apache-2.0) | Copyright (c) Florian Uekermann |
|
||||||
| `crates/types/src/id.rs` | [crockford](https://github.com/archer884/crockford) (MIT or Apache-2.0) | Copyright (c) 2017 J/A <archer884@gmail.com> |
|
| `crates/types/src/id.rs` | [crockford](https://github.com/archer884/crockford) (MIT or Apache-2.0) | Copyright (c) 2017 J/A <archer884@gmail.com> |
|
||||||
| `crates/nlp/src/tokenizers/types.rs` | test cases from [linkify](https://github.com/robinst/linkify) (MIT or Apache-2.0) | Copyright (c) 2017 Robin Stocker |
|
| `crates/nlp/src/tokenizers/types.rs` | test cases from [linkify](https://github.com/robinst/linkify) (MIT or Apache-2.0) | Copyright (c) 2017 Robin Stocker |
|
||||||
| `tests/resources/smtp/antispam/spam-filter-rules.json.gz` | the published rules of [spam-filter](https://github.com/stalwartlabs/spam-filter) v3.0.2, unmodified, for the spam filter's tests (MIT or Apache-2.0) | Copyright (C) 2024, Stalwart Labs LLC |
|
| `resources/spam-filter/spam-filter-rules.json.gz` | the published rules of [spam-filter](https://github.com/stalwartlabs/spam-filter) v3.0.2, unmodified, built into the server as its default spam rules (MIT or Apache-2.0) | Copyright (C) 2024, Stalwart Labs LLC |
|
||||||
|
|
||||||
Each notice above applies with this permission notice:
|
Each notice above applies with this permission notice:
|
||||||
|
|
||||||
|
|||||||
Vendored
+80
-29
@@ -20,13 +20,20 @@ use ahash::AHashMap;
|
|||||||
use directory::Directories;
|
use directory::Directories;
|
||||||
use registry::{
|
use registry::{
|
||||||
schema::{prelude::ObjectType, structs::BlockedIp},
|
schema::{prelude::ObjectType, structs::BlockedIp},
|
||||||
types::error::{Error, Warning},
|
types::{
|
||||||
|
error::{Error, Warning},
|
||||||
|
id::ObjectId,
|
||||||
|
},
|
||||||
};
|
};
|
||||||
use std::sync::Arc;
|
use std::sync::Arc;
|
||||||
use store::{LookupStores, registry::bootstrap::Bootstrap, write::now};
|
use store::{LookupStores, registry::bootstrap::Bootstrap, write::now};
|
||||||
|
|
||||||
pub struct ReloadResult {
|
pub struct ReloadResult {
|
||||||
|
/// Errors that kept the reload from being applied.
|
||||||
pub errors: Vec<Error>,
|
pub errors: Vec<Error>,
|
||||||
|
/// inbuxa: errors in objects that already failed when the running
|
||||||
|
/// settings were built; logged, but they don't refuse a reload.
|
||||||
|
pub known_errors: Vec<Error>,
|
||||||
pub warnings: Vec<Warning>,
|
pub warnings: Vec<Warning>,
|
||||||
pub replaced_core: bool,
|
pub replaced_core: bool,
|
||||||
}
|
}
|
||||||
@@ -114,42 +121,60 @@ impl Server {
|
|||||||
directories: directory.directories,
|
directories: directory.directories,
|
||||||
};
|
};
|
||||||
|
|
||||||
// Parse tracers
|
// inbuxa: upstream swapped the core only when the whole build
|
||||||
|
// was free of errors, while boot runs with whatever built. So one
|
||||||
|
// object that failed (a DNS lookup that timed out, say) refused
|
||||||
|
// every later reload, cluster-wide when the reload came from
|
||||||
|
// ReloadSettings, and the running settings went stale. Now a
|
||||||
|
// reload is refused only for errors in objects that built when
|
||||||
|
// the running settings were built: those would be lost by
|
||||||
|
// applying it. Objects that already failed then are missing
|
||||||
|
// from the running settings anyway, as at boot, so their
|
||||||
|
// errors are reported but don't hold the reload back.
|
||||||
let tracers = Telemetry::parse(&mut bootstrap, &storage).await;
|
let tracers = Telemetry::parse(&mut bootstrap, &storage).await;
|
||||||
|
let core = Box::pin(Core::parse(&mut bootstrap, storage)).await;
|
||||||
|
let mut servers = Listeners::parse(&mut bootstrap).await;
|
||||||
|
|
||||||
if bootstrap.errors.is_empty() {
|
if !self.has_new_build_errors(&bootstrap.errors) {
|
||||||
let core = Box::pin(Core::parse(&mut bootstrap, storage)).await;
|
servers
|
||||||
|
.parse_tcp_acceptors(&mut bootstrap, self.inner.clone())
|
||||||
|
.await;
|
||||||
|
|
||||||
if bootstrap.errors.is_empty() {
|
if !self.has_new_build_errors(&bootstrap.errors) {
|
||||||
let mut servers = Listeners::parse(&mut bootstrap).await;
|
// Update core
|
||||||
servers
|
self.inner.shared_core.store(core.into());
|
||||||
.parse_tcp_acceptors(&mut bootstrap, self.inner.clone())
|
|
||||||
.await;
|
|
||||||
|
|
||||||
if bootstrap.errors.is_empty() {
|
// Update tracers
|
||||||
// Update core
|
tracers.update();
|
||||||
self.inner.shared_core.store(core.into());
|
|
||||||
|
|
||||||
// Update tracers
|
// Reload queue settings
|
||||||
|
self.inner
|
||||||
|
.ipc
|
||||||
|
.queue_tx
|
||||||
|
.send(QueueEvent::ReloadSettings)
|
||||||
|
.await
|
||||||
|
.ok();
|
||||||
|
|
||||||
tracers.update();
|
self.record_build_errors(&bootstrap.errors);
|
||||||
|
|
||||||
// Reload queue settings
|
return Ok(ReloadResult {
|
||||||
self.inner
|
errors: Vec::new(),
|
||||||
.ipc
|
known_errors: bootstrap.errors,
|
||||||
.queue_tx
|
warnings: bootstrap.warnings,
|
||||||
.send(QueueEvent::ReloadSettings)
|
replaced_core: true,
|
||||||
.await
|
});
|
||||||
.ok();
|
|
||||||
|
|
||||||
return Ok(ReloadResult {
|
|
||||||
errors: bootstrap.errors,
|
|
||||||
warnings: bootstrap.warnings,
|
|
||||||
replaced_core: true,
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
let (known_errors, errors) = std::mem::take(&mut bootstrap.errors)
|
||||||
|
.into_iter()
|
||||||
|
.partition(|error| self.is_known_build_error(error));
|
||||||
|
return Ok(ReloadResult {
|
||||||
|
errors,
|
||||||
|
known_errors,
|
||||||
|
warnings: bootstrap.warnings,
|
||||||
|
replaced_core: false,
|
||||||
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -163,7 +188,7 @@ impl ReloadResult {
|
|||||||
}
|
}
|
||||||
|
|
||||||
pub fn log(&self) {
|
pub fn log(&self) {
|
||||||
for error in &self.errors {
|
for error in self.errors.iter().chain(&self.known_errors) {
|
||||||
error.log();
|
error.log();
|
||||||
}
|
}
|
||||||
for warning in &self.warnings {
|
for warning in &self.warnings {
|
||||||
@@ -176,8 +201,34 @@ impl From<Bootstrap> for ReloadResult {
|
|||||||
fn from(bootstrap: Bootstrap) -> Self {
|
fn from(bootstrap: Bootstrap) -> Self {
|
||||||
Self {
|
Self {
|
||||||
errors: bootstrap.errors,
|
errors: bootstrap.errors,
|
||||||
|
known_errors: Vec::new(),
|
||||||
warnings: bootstrap.warnings,
|
warnings: bootstrap.warnings,
|
||||||
replaced_core: false,
|
replaced_core: false,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// inbuxa: which objects failed to build for the running settings
|
||||||
|
impl Server {
|
||||||
|
/// Records the objects that failed to build for the settings now running.
|
||||||
|
pub fn record_build_errors(&self, errors: &[Error]) {
|
||||||
|
*self.inner.data.build_errors.lock() = errors.iter().filter_map(error_object).collect();
|
||||||
|
}
|
||||||
|
|
||||||
|
fn is_known_build_error(&self, error: &Error) -> bool {
|
||||||
|
error_object(error).is_some_and(|id| self.inner.data.build_errors.lock().contains(&id))
|
||||||
|
}
|
||||||
|
|
||||||
|
fn has_new_build_errors(&self, errors: &[Error]) -> bool {
|
||||||
|
errors.iter().any(|error| !self.is_known_build_error(error))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn error_object(error: &Error) -> Option<ObjectId> {
|
||||||
|
match error {
|
||||||
|
Error::Validation { object_id, .. }
|
||||||
|
| Error::Build { object_id, .. }
|
||||||
|
| Error::NotFound { object_id } => Some(*object_id),
|
||||||
|
Error::Internal { object_id, .. } => *object_id,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -96,6 +96,7 @@ impl Data {
|
|||||||
applications,
|
applications,
|
||||||
logos: Default::default(),
|
logos: Default::default(),
|
||||||
smtp_connectors: TlsConnectors::try_new().failed("Failed to build TLS connectors"),
|
smtp_connectors: TlsConnectors::try_new().failed("Failed to build TLS connectors"),
|
||||||
|
build_errors: Default::default(),
|
||||||
asn_geo_data: Default::default(),
|
asn_geo_data: Default::default(),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -237,6 +238,7 @@ impl Default for Data {
|
|||||||
applications: WebApplications::new(),
|
applications: WebApplications::new(),
|
||||||
logos: Default::default(),
|
logos: Default::default(),
|
||||||
smtp_connectors: TlsConnectors::try_new().unwrap(),
|
smtp_connectors: TlsConnectors::try_new().unwrap(),
|
||||||
|
build_errors: Default::default(),
|
||||||
asn_geo_data: Default::default(),
|
asn_geo_data: Default::default(),
|
||||||
lookup_stores: Default::default(),
|
lookup_stores: Default::default(),
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -16,7 +16,6 @@ use mail_auth::common::resolver::ToReverseName;
|
|||||||
use nlp::classifier::model::{CcfhClassifier, FhClassifier};
|
use nlp::classifier::model::{CcfhClassifier, FhClassifier};
|
||||||
use registry::schema::{
|
use registry::schema::{
|
||||||
enums::{ExpressionVariable, ModelSize},
|
enums::{ExpressionVariable, ModelSize},
|
||||||
prelude::ObjectType,
|
|
||||||
structs::{
|
structs::{
|
||||||
self, SpamDnsblServer, SpamDnsblSettings, SpamFileExtension, SpamPyzor, SpamRule,
|
self, SpamDnsblServer, SpamDnsblSettings, SpamFileExtension, SpamPyzor, SpamRule,
|
||||||
SpamSettings, SpamTag,
|
SpamSettings, SpamTag,
|
||||||
@@ -25,10 +24,10 @@ use registry::schema::{
|
|||||||
use sieve::SpamStatus;
|
use sieve::SpamStatus;
|
||||||
use std::{
|
use std::{
|
||||||
net::{IpAddr, SocketAddr},
|
net::{IpAddr, SocketAddr},
|
||||||
time::Duration,
|
sync::Arc,
|
||||||
|
time::{Duration, Instant},
|
||||||
};
|
};
|
||||||
use store::registry::{RegistryObject, bootstrap::Bootstrap};
|
use store::registry::{RegistryObject, bootstrap::Bootstrap};
|
||||||
use tokio::net::lookup_host;
|
|
||||||
use utils::{cache::CacheItemWeight, glob::GlobMap};
|
use utils::{cache::CacheItemWeight, glob::GlobMap};
|
||||||
|
|
||||||
#[derive(rkyv::Archive, rkyv::Deserialize, rkyv::Serialize, Debug, Default)]
|
#[derive(rkyv::Archive, rkyv::Deserialize, rkyv::Serialize, Debug, Default)]
|
||||||
@@ -157,7 +156,11 @@ pub struct FtrlParameters {
|
|||||||
|
|
||||||
#[derive(Debug, Clone)]
|
#[derive(Debug, Clone)]
|
||||||
pub struct PyzorConfig {
|
pub struct PyzorConfig {
|
||||||
pub address: SocketAddr,
|
// inbuxa: the server is resolved when a message is checked, not while the
|
||||||
|
// settings are built (see PyzorConfig::address)
|
||||||
|
pub host: String,
|
||||||
|
pub port: u16,
|
||||||
|
pub resolved: Arc<parking_lot::Mutex<Option<(SocketAddr, Instant)>>>,
|
||||||
pub timeout: Duration,
|
pub timeout: Duration,
|
||||||
pub min_count: u64,
|
pub min_count: u64,
|
||||||
pub min_wl_count: u64,
|
pub min_wl_count: u64,
|
||||||
@@ -243,7 +246,8 @@ impl SpamFilterConfig {
|
|||||||
spam_threshold: spam.score_spam.into_inner() as f32,
|
spam_threshold: spam.score_spam.into_inner() as f32,
|
||||||
},
|
},
|
||||||
grey_list_expiry: spam.greylist_for.map(|d| d.into_inner().as_secs()),
|
grey_list_expiry: spam.greylist_for.map(|d| d.into_inner().as_secs()),
|
||||||
spam_rules_url: spam.spam_filter_rules_url,
|
// inbuxa: unset, empty or upstream's old default means the bundled rules
|
||||||
|
spam_rules_url: crate::manager::spam_rules::rules_url(spam.spam_filter_rules_url),
|
||||||
url_client: utils::http::http_client_builder(true)
|
url_client: utils::http::http_client_builder(true)
|
||||||
.pool_max_idle_per_host(0)
|
.pool_max_idle_per_host(0)
|
||||||
.redirect(reqwest::redirect::Policy::none())
|
.redirect(reqwest::redirect::Policy::none())
|
||||||
@@ -473,31 +477,15 @@ impl PyzorConfig {
|
|||||||
return None;
|
return None;
|
||||||
}
|
}
|
||||||
|
|
||||||
let port = pyzor.port;
|
// inbuxa: upstream resolved the host here and reported a failed lookup
|
||||||
let host = pyzor.host;
|
// as a build error, so a DNS hiccup on one node refused every settings
|
||||||
let address = match lookup_host(format!("{host}:{port}"))
|
// reload on it (and, from the node that ran ReloadSettings, across the
|
||||||
.await
|
// cluster). The lookup now happens when a message is checked; a
|
||||||
.map(|mut a| a.next())
|
// failure there is logged as a Pyzor error for that message.
|
||||||
{
|
|
||||||
Ok(Some(address)) => address,
|
|
||||||
Ok(None) => {
|
|
||||||
bp.build_error(
|
|
||||||
ObjectType::SpamPyzor.singleton(),
|
|
||||||
"Invalid address: No addresses found.",
|
|
||||||
);
|
|
||||||
return None;
|
|
||||||
}
|
|
||||||
Err(err) => {
|
|
||||||
bp.build_error(
|
|
||||||
ObjectType::SpamPyzor.singleton(),
|
|
||||||
format!("Invalid address: {}", err),
|
|
||||||
);
|
|
||||||
return None;
|
|
||||||
}
|
|
||||||
};
|
|
||||||
|
|
||||||
PyzorConfig {
|
PyzorConfig {
|
||||||
address,
|
host: pyzor.host,
|
||||||
|
port: pyzor.port as u16,
|
||||||
|
resolved: Default::default(),
|
||||||
timeout: pyzor.timeout.into_inner(),
|
timeout: pyzor.timeout.into_inner(),
|
||||||
min_count: pyzor.block_count,
|
min_count: pyzor.block_count,
|
||||||
min_wl_count: pyzor.allow_count,
|
min_wl_count: pyzor.allow_count,
|
||||||
@@ -507,6 +495,35 @@ impl PyzorConfig {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// inbuxa: how long a resolved Pyzor address is reused
|
||||||
|
const PYZOR_RESOLVE_TTL: Duration = Duration::from_secs(300);
|
||||||
|
|
||||||
|
impl PyzorConfig {
|
||||||
|
/// The server's address: the host itself when it is an IP address,
|
||||||
|
/// otherwise the first address it resolves to, reused for five minutes.
|
||||||
|
pub async fn address(&self) -> std::io::Result<SocketAddr> {
|
||||||
|
if let Ok(ip) = self.host.parse::<IpAddr>() {
|
||||||
|
return Ok(SocketAddr::new(ip, self.port));
|
||||||
|
}
|
||||||
|
if let Some((address, resolved_at)) = *self.resolved.lock()
|
||||||
|
&& resolved_at.elapsed() < PYZOR_RESOLVE_TTL
|
||||||
|
{
|
||||||
|
return Ok(address);
|
||||||
|
}
|
||||||
|
let address = tokio::net::lookup_host((self.host.as_str(), self.port))
|
||||||
|
.await?
|
||||||
|
.next()
|
||||||
|
.ok_or_else(|| {
|
||||||
|
std::io::Error::new(
|
||||||
|
std::io::ErrorKind::NotFound,
|
||||||
|
format!("{} has no addresses", self.host),
|
||||||
|
)
|
||||||
|
})?;
|
||||||
|
*self.resolved.lock() = Some((address, Instant::now()));
|
||||||
|
Ok(address)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
impl ClassifierConfig {
|
impl ClassifierConfig {
|
||||||
pub async fn parse(bp: &mut Bootstrap) -> Option<Self> {
|
pub async fn parse(bp: &mut Bootstrap) -> Option<Self> {
|
||||||
let classifier = bp.setting_infallible::<structs::SpamClassifier>().await;
|
let classifier = bp.setting_infallible::<structs::SpamClassifier>().await;
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use self::resolver::Policy;
|
use self::resolver::Policy;
|
||||||
@@ -22,7 +24,7 @@ use registry::schema::{
|
|||||||
};
|
};
|
||||||
use smtp_proto::*;
|
use smtp_proto::*;
|
||||||
use std::{
|
use std::{
|
||||||
net::{SocketAddr, ToSocketAddrs},
|
net::{IpAddr, SocketAddr},
|
||||||
str::FromStr,
|
str::FromStr,
|
||||||
time::Duration,
|
time::Duration,
|
||||||
};
|
};
|
||||||
@@ -384,19 +386,16 @@ impl SessionConfig {
|
|||||||
Some(Milter {
|
Some(Milter {
|
||||||
enable: bp.compile_expr(id, &milter.ctx_enable()),
|
enable: bp.compile_expr(id, &milter.ctx_enable()),
|
||||||
id,
|
id,
|
||||||
addrs: format!("{}:{}", milter.hostname, milter.port)
|
// inbuxa: upstream resolved the hostname here (a
|
||||||
.to_socket_addrs()
|
// blocking lookup) and made a failure a build error,
|
||||||
.map_err(|err| {
|
// which refused the whole settings reload. An IP
|
||||||
bp.build_error(
|
// address is kept as is; a name is resolved on each
|
||||||
id,
|
// connection (MilterClient::connect).
|
||||||
format!(
|
addrs: milter
|
||||||
"Unable to resolve milter hostname {}: {}",
|
.hostname
|
||||||
milter.hostname, err
|
.parse::<IpAddr>()
|
||||||
),
|
.map(|ip| vec![SocketAddr::new(ip, milter.port as u16)])
|
||||||
)
|
.unwrap_or_default(),
|
||||||
})
|
|
||||||
.ok()?
|
|
||||||
.collect(),
|
|
||||||
hostname: milter.hostname,
|
hostname: milter.hostname,
|
||||||
port: milter.port as u16,
|
port: milter.port as u16,
|
||||||
timeout_connect: milter.timeout_connect.into_inner(),
|
timeout_connect: milter.timeout_connect.into_inner(),
|
||||||
|
|||||||
@@ -335,3 +335,57 @@ impl EmailPush {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// inbuxa: the task locks this node holds, so a graceful stop can hand them
|
||||||
|
/// back instead of leaving the tasks blocked until the locks expire.
|
||||||
|
pub struct TaskLocks {
|
||||||
|
held: parking_lot::Mutex<ahash::AHashSet<u64>>,
|
||||||
|
stopping: AtomicBool,
|
||||||
|
expiry: std::sync::atomic::AtomicU64,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl TaskLocks {
|
||||||
|
/// How long a task lock lasts, in seconds, unless it is released first.
|
||||||
|
pub const DEFAULT_EXPIRY: u64 = 60 * 60;
|
||||||
|
|
||||||
|
pub fn is_stopping(&self) -> bool {
|
||||||
|
self.stopping.load(Ordering::Acquire)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Stops new claims and returns the ids of every lock still held.
|
||||||
|
pub fn stop(&self) -> Vec<u64> {
|
||||||
|
self.stopping.store(true, Ordering::Release);
|
||||||
|
self.held.lock().drain().collect()
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn insert(&self, id: u64) {
|
||||||
|
self.held.lock().insert(id);
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn remove(&self, id: u64) {
|
||||||
|
self.held.lock().remove(&id);
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn held(&self) -> usize {
|
||||||
|
self.held.lock().len()
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn expiry(&self) -> u64 {
|
||||||
|
self.expiry.load(Ordering::Relaxed)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Changes the lock lifetime; the tests shorten it.
|
||||||
|
pub fn set_expiry(&self, seconds: u64) {
|
||||||
|
self.expiry.store(seconds.max(1), Ordering::Relaxed);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Default for TaskLocks {
|
||||||
|
fn default() -> Self {
|
||||||
|
Self {
|
||||||
|
held: Default::default(),
|
||||||
|
stopping: AtomicBool::new(false),
|
||||||
|
expiry: std::sync::atomic::AtomicU64::new(Self::DEFAULT_EXPIRY),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -166,6 +166,10 @@ pub struct Data {
|
|||||||
pub logos: Mutex<AHashMap<Box<str>, LogoCache>>,
|
pub logos: Mutex<AHashMap<Box<str>, LogoCache>>,
|
||||||
|
|
||||||
pub smtp_connectors: TlsConnectors,
|
pub smtp_connectors: TlsConnectors,
|
||||||
|
|
||||||
|
// inbuxa: the objects that failed to build when the running settings
|
||||||
|
// were built, at boot or by the last applied reload (see reload_registry)
|
||||||
|
pub build_errors: Mutex<AHashSet<registry::types::id::ObjectId>>,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Clone)]
|
#[derive(Clone)]
|
||||||
@@ -279,6 +283,8 @@ pub struct HttpAuthCache {
|
|||||||
pub struct Ipc {
|
pub struct Ipc {
|
||||||
pub push_tx: mpsc::Sender<PushEvent>,
|
pub push_tx: mpsc::Sender<PushEvent>,
|
||||||
pub task_tx: Arc<Notify>,
|
pub task_tx: Arc<Notify>,
|
||||||
|
// inbuxa: task locks held by this node, released on a graceful stop
|
||||||
|
pub task_locks: Arc<crate::ipc::TaskLocks>,
|
||||||
pub queue_tx: mpsc::Sender<QueueEvent>,
|
pub queue_tx: mpsc::Sender<QueueEvent>,
|
||||||
pub report_tx: mpsc::Sender<ReportingEvent>,
|
pub report_tx: mpsc::Sender<ReportingEvent>,
|
||||||
pub broadcast_tx: Option<mpsc::Sender<BroadcastEvent>>,
|
pub broadcast_tx: Option<mpsc::Sender<BroadcastEvent>>,
|
||||||
|
|||||||
@@ -23,6 +23,13 @@ use utils::{UnwrapFailure, codec::leb128::Leb128_};
|
|||||||
|
|
||||||
pub(super) const MAGIC_MARKER: u8 = 123;
|
pub(super) const MAGIC_MARKER: u8 = 123;
|
||||||
|
|
||||||
|
// inbuxa: blobs kept under a fixed name instead of a content hash. Nothing
|
||||||
|
// links to them, so the export names them outright.
|
||||||
|
const NAMED_BLOBS: &[&[u8]] = &[
|
||||||
|
crate::manager::SPAM_CLASSIFIER_KEY,
|
||||||
|
crate::manager::SPAM_TRAINER_KEY,
|
||||||
|
];
|
||||||
|
|
||||||
#[derive(Debug, Clone, Copy, Hash, PartialEq, Eq)]
|
#[derive(Debug, Clone, Copy, Hash, PartialEq, Eq)]
|
||||||
pub(super) enum Family {
|
pub(super) enum Family {
|
||||||
Data = 0,
|
Data = 0,
|
||||||
@@ -143,15 +150,21 @@ impl Core {
|
|||||||
.await
|
.await
|
||||||
.failed("Failed to iterate over data store");
|
.failed("Failed to iterate over data store");
|
||||||
|
|
||||||
for hash in blobs {
|
// inbuxa: the trained spam classifier and its trainer state are
|
||||||
|
// blobs stored under fixed names with no blob link, so the walk
|
||||||
|
// over links above never reaches them.
|
||||||
|
let named = NAMED_BLOBS.iter().map(|key| key.to_vec());
|
||||||
|
for key in blobs
|
||||||
|
.into_iter()
|
||||||
|
.map(|hash| hash.as_slice().to_vec())
|
||||||
|
.chain(named)
|
||||||
|
{
|
||||||
if let Some(blob) = blob_store
|
if let Some(blob) = blob_store
|
||||||
.get_blob(hash.as_slice(), 0..usize::MAX)
|
.get_blob(&key, 0..usize::MAX)
|
||||||
.await
|
.await
|
||||||
.failed("Failed to get blob")
|
.failed("Failed to get blob")
|
||||||
{
|
{
|
||||||
writer
|
writer.send((key, blob)).failed("Failed to send key");
|
||||||
.send((hash.as_slice().to_vec(), blob))
|
|
||||||
.failed("Failed to send key");
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}),
|
}),
|
||||||
@@ -323,7 +336,13 @@ impl Family {
|
|||||||
SUBSPACE_REGISTRY_IDX,
|
SUBSPACE_REGISTRY_IDX,
|
||||||
SUBSPACE_REGISTRY_PK,
|
SUBSPACE_REGISTRY_PK,
|
||||||
SUBSPACE_DIRECTORY,
|
SUBSPACE_DIRECTORY,
|
||||||
store::SUBSPACE_INBUXA, // inbuxa: masked email
|
// inbuxa: registry objects the upstream list left out, so an
|
||||||
|
// export dropped them: archived items (undelete) and spam
|
||||||
|
// training samples. Their indexes and id counters already
|
||||||
|
// travel in this family and in `data`, so they ride along.
|
||||||
|
SUBSPACE_DELETED_ITEMS,
|
||||||
|
SUBSPACE_SPAM_SAMPLES,
|
||||||
|
store::SUBSPACE_INBUXA, // inbuxa: the fork's own data (masked email, undelete, policies)
|
||||||
],
|
],
|
||||||
Family::Changelog => &[SUBSPACE_LOGS],
|
Family::Changelog => &[SUBSPACE_LOGS],
|
||||||
Family::Queue => &[SUBSPACE_QUEUE_MESSAGE, SUBSPACE_QUEUE_EVENT],
|
Family::Queue => &[SUBSPACE_QUEUE_MESSAGE, SUBSPACE_QUEUE_EVENT],
|
||||||
|
|||||||
@@ -54,6 +54,13 @@ Options:
|
|||||||
-o, --console Open the store console
|
-o, --console Open the store console
|
||||||
-h, --help Print help
|
-h, --help Print help
|
||||||
-V, --version Print version
|
-V, --version Print version
|
||||||
|
|
||||||
|
An export holds everything in the data and blob stores except short-lived
|
||||||
|
in-memory state (rate limits, locks, greylisting) and the full-text search
|
||||||
|
index, which belongs to one search backend. An import into an empty store
|
||||||
|
queues the index to be rebuilt when the server next starts. EXPORT_TYPES
|
||||||
|
limits an export to some of: data, registry, blob, changelog, queue, report,
|
||||||
|
telemetry, tasks.
|
||||||
"#
|
"#
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -233,6 +240,9 @@ impl BootManager {
|
|||||||
.parse_tcp_acceptors(&mut bootstrap, inner.clone())
|
.parse_tcp_acceptors(&mut bootstrap, inner.clone())
|
||||||
.await;
|
.await;
|
||||||
|
|
||||||
|
// inbuxa: a reload isn't refused over objects that failed here
|
||||||
|
inner.build_server().record_build_errors(&bootstrap.errors);
|
||||||
|
|
||||||
BootManager {
|
BootManager {
|
||||||
inner,
|
inner,
|
||||||
bootstrap,
|
bootstrap,
|
||||||
@@ -256,10 +266,10 @@ impl BootManager {
|
|||||||
telemetry.enable();
|
telemetry.enable();
|
||||||
|
|
||||||
// Parse settings and restore
|
// Parse settings and restore
|
||||||
Box::pin(Core::parse(&mut bootstrap, storage))
|
let core = Box::pin(Core::parse(&mut bootstrap, storage)).await;
|
||||||
.await
|
let imported = core.restore(path).await;
|
||||||
.restore(path)
|
// inbuxa: the search index isn't exported; rebuild it
|
||||||
.await;
|
core.queue_reindex(&imported).await;
|
||||||
std::process::exit(0);
|
std::process::exit(0);
|
||||||
}
|
}
|
||||||
StoreOp::Console => {
|
StoreOp::Console => {
|
||||||
@@ -290,6 +300,7 @@ pub fn build_ipc(has_pubsub: bool) -> (Ipc, IpcReceivers) {
|
|||||||
report_tx,
|
report_tx,
|
||||||
broadcast_tx: has_pubsub.then_some(broadcast_tx),
|
broadcast_tx: has_pubsub.then_some(broadcast_tx),
|
||||||
task_tx: Arc::new(Notify::new()),
|
task_tx: Arc::new(Notify::new()),
|
||||||
|
task_locks: Arc::new(crate::ipc::TaskLocks::default()),
|
||||||
train_task_controller: Arc::new(TrainTaskController::default()),
|
train_task_controller: Arc::new(TrainTaskController::default()),
|
||||||
},
|
},
|
||||||
IpcReceivers {
|
IpcReceivers {
|
||||||
|
|||||||
@@ -530,13 +530,22 @@ async fn insert_safe_defaults(bp: &mut Bootstrap) -> trc::Result<()> {
|
|||||||
use store::write::BatchBuilder;
|
use store::write::BatchBuilder;
|
||||||
use types::id::Id;
|
use types::id::Id;
|
||||||
|
|
||||||
if bp.registry.count_object(ObjectType::SpamRule).await? == 0
|
// inbuxa: rules are always to hand, since a copy ships with the server
|
||||||
&& bp
|
// (spam_rules). They load on first boot, and again when the bundled
|
||||||
.registry
|
// version differs from the one last loaded, which only adds what's
|
||||||
|
// missing: new tags and rules, never a changed score.
|
||||||
|
let rules_url = super::spam_rules::rules_url(
|
||||||
|
bp.registry
|
||||||
.object::<SpamSettings>(Id::singleton())
|
.object::<SpamSettings>(Id::singleton())
|
||||||
.await?
|
.await?
|
||||||
.is_none_or(|spam| spam.spam_filter_rules_url.is_some())
|
.and_then(|spam| spam.spam_filter_rules_url),
|
||||||
{
|
);
|
||||||
|
let bundled_is_new = rules_url.is_none()
|
||||||
|
&& super::spam_rules::applied_version(&bp.data_store)
|
||||||
|
.await?
|
||||||
|
.as_deref()
|
||||||
|
!= Some(super::spam_rules::BUNDLED_SPAM_RULES_VERSION);
|
||||||
|
if bp.registry.count_object(ObjectType::SpamRule).await? == 0 || bundled_is_new {
|
||||||
let mut batch = BatchBuilder::new();
|
let mut batch = BatchBuilder::new();
|
||||||
batch.schedule_task(Task::SpamFilterMaintenance(TaskSpamFilterMaintenance {
|
batch.schedule_task(Task::SpamFilterMaintenance(TaskSpamFilterMaintenance {
|
||||||
maintenance_type: TaskSpamFilterMaintenanceType::UpdateRules,
|
maintenance_type: TaskSpamFilterMaintenanceType::UpdateRules,
|
||||||
|
|||||||
@@ -22,6 +22,7 @@ pub mod console;
|
|||||||
pub mod defaults;
|
pub mod defaults;
|
||||||
pub mod first_party;
|
pub mod first_party;
|
||||||
pub mod restore;
|
pub mod restore;
|
||||||
|
pub mod spam_rules; // inbuxa: rules bundled with the server
|
||||||
|
|
||||||
pub const SPAM_TRAINER_KEY: &[u8] = "INBUXA_SPAM_TRAIN_DATA.lz4".as_bytes();
|
pub const SPAM_TRAINER_KEY: &[u8] = "INBUXA_SPAM_TRAIN_DATA.lz4".as_bytes();
|
||||||
pub const SPAM_CLASSIFIER_KEY: &[u8] = "INBUXA_SPAM_CLASSIFIER_MODEL.lz4".as_bytes();
|
pub const SPAM_CLASSIFIER_KEY: &[u8] = "INBUXA_SPAM_CLASSIFIER_MODEL.lz4".as_bytes();
|
||||||
|
|||||||
@@ -9,15 +9,22 @@
|
|||||||
use super::backup::MAGIC_MARKER;
|
use super::backup::MAGIC_MARKER;
|
||||||
use crate::{Core, DATABASE_SCHEMA_VERSION};
|
use crate::{Core, DATABASE_SCHEMA_VERSION};
|
||||||
use lz4_flex::frame::FrameDecoder;
|
use lz4_flex::frame::FrameDecoder;
|
||||||
use registry::schema::enums::CompressionAlgo;
|
use registry::{
|
||||||
|
schema::{
|
||||||
|
enums::{CompressionAlgo, TaskStoreMaintenanceType},
|
||||||
|
structs::{Task, TaskStatus, TaskStoreMaintenance},
|
||||||
|
},
|
||||||
|
types::EnumImpl,
|
||||||
|
};
|
||||||
use std::{
|
use std::{
|
||||||
fs::File,
|
fs::File,
|
||||||
io::{BufReader, ErrorKind, Read},
|
io::{BufReader, ErrorKind, Read},
|
||||||
path::{Path, PathBuf},
|
path::{Path, PathBuf},
|
||||||
};
|
};
|
||||||
use store::{
|
use store::{
|
||||||
BlobStore, IterateParams, SUBSPACE_BLOBS, SUBSPACE_COUNTER, SUBSPACE_INDEXES, SUBSPACE_QUOTA,
|
BlobStore, IterateParams, SUBSPACE_BLOBS, SUBSPACE_COUNTER, SUBSPACE_INDEXES,
|
||||||
SUBSPACE_REGISTRY_PK, Store, U32_LEN,
|
SUBSPACE_PROPERTY, SUBSPACE_QUOTA, SUBSPACE_REGISTRY_PK, SUBSPACE_TELEMETRY_SPAN, Store,
|
||||||
|
U32_LEN,
|
||||||
write::{
|
write::{
|
||||||
AnyClass, AnyKey, BatchBuilder, ValueClass,
|
AnyClass, AnyKey, BatchBuilder, ValueClass,
|
||||||
key::{DeserializeBigEndian, is_node_id_key},
|
key::{DeserializeBigEndian, is_node_id_key},
|
||||||
@@ -27,7 +34,9 @@ use types::{collection::Collection, field::Field};
|
|||||||
use utils::{UnwrapFailure, failed};
|
use utils::{UnwrapFailure, failed};
|
||||||
|
|
||||||
impl Core {
|
impl Core {
|
||||||
pub async fn restore(&self, src: PathBuf) {
|
/// Imports an export into an empty store and returns the subspaces it
|
||||||
|
/// wrote. inbuxa: the caller hands them to [`Core::queue_reindex`].
|
||||||
|
pub async fn restore(&self, src: PathBuf) -> Vec<u8> {
|
||||||
// Backup the core
|
// Backup the core
|
||||||
let paths = if src.is_dir() {
|
let paths = if src.is_dir() {
|
||||||
let mut paths = Vec::new();
|
let mut paths = Vec::new();
|
||||||
@@ -64,6 +73,13 @@ impl Core {
|
|||||||
std::process::exit(1);
|
std::process::exit(1);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
let mut imported = paths
|
||||||
|
.iter()
|
||||||
|
.map(|path| KeyValueReader::new(path).subspace)
|
||||||
|
.collect::<Vec<_>>();
|
||||||
|
imported.sort_unstable();
|
||||||
|
imported.dedup();
|
||||||
|
|
||||||
let mut tasks = Vec::new();
|
let mut tasks = Vec::new();
|
||||||
for path in paths {
|
for path in paths {
|
||||||
let storage = self.storage.clone();
|
let storage = self.storage.clone();
|
||||||
@@ -76,6 +92,54 @@ impl Core {
|
|||||||
for task in tasks {
|
for task in tasks {
|
||||||
task.await.failed("Failed to wait for task");
|
task.await.failed("Failed to wait for task");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
imported
|
||||||
|
}
|
||||||
|
|
||||||
|
/// inbuxa: an export never carries the full-text index. It is built by
|
||||||
|
/// and for one search backend (the SQL stores index into their own
|
||||||
|
/// tables, the key-value stores into a subspace, external engines keep it
|
||||||
|
/// themselves), so it would be wrong or unreadable after a move to
|
||||||
|
/// another one. Instead, an import queues the same reindex tasks an
|
||||||
|
/// administrator can queue by hand (`reindexAccounts` and
|
||||||
|
/// `reindexTelemetry` store maintenance), and the server rebuilds the
|
||||||
|
/// index for whatever search store it is configured with once it starts.
|
||||||
|
pub async fn queue_reindex(&self, imported: &[u8]) -> Vec<TaskStoreMaintenanceType> {
|
||||||
|
let mut queued = Vec::new();
|
||||||
|
if imported.contains(&SUBSPACE_PROPERTY) {
|
||||||
|
queued.push(TaskStoreMaintenanceType::ReindexAccounts);
|
||||||
|
}
|
||||||
|
if imported.contains(&SUBSPACE_TELEMETRY_SPAN) {
|
||||||
|
queued.push(TaskStoreMaintenanceType::ReindexTelemetry);
|
||||||
|
}
|
||||||
|
if queued.is_empty() {
|
||||||
|
return queued;
|
||||||
|
}
|
||||||
|
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
for maintenance_type in &queued {
|
||||||
|
batch.schedule_task(Task::StoreMaintenance(TaskStoreMaintenance {
|
||||||
|
maintenance_type: *maintenance_type,
|
||||||
|
status: TaskStatus::now(),
|
||||||
|
shard_index: None,
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
self.storage
|
||||||
|
.data
|
||||||
|
.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.failed("Failed to queue the reindex tasks");
|
||||||
|
|
||||||
|
println!(
|
||||||
|
"Queued {} to rebuild the search index; it runs when the server starts.",
|
||||||
|
queued
|
||||||
|
.iter()
|
||||||
|
.map(|t| t.as_str())
|
||||||
|
.collect::<Vec<_>>()
|
||||||
|
.join(" and ")
|
||||||
|
);
|
||||||
|
|
||||||
|
queued
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -125,17 +189,22 @@ async fn restore_file(store: Store, blob_store: BlobStore, path: &Path) {
|
|||||||
}
|
}
|
||||||
SUBSPACE_COUNTER | SUBSPACE_QUOTA => {
|
SUBSPACE_COUNTER | SUBSPACE_QUOTA => {
|
||||||
while let Some((key, value)) = reader.next() {
|
while let Some((key, value)) = reader.next() {
|
||||||
batch.add(
|
let class = ValueClass::Any(AnyClass {
|
||||||
ValueClass::Any(AnyClass {
|
subspace: reader.subspace,
|
||||||
subspace: reader.subspace,
|
key,
|
||||||
key,
|
});
|
||||||
}),
|
let value = u64::from_le_bytes(
|
||||||
u64::from_le_bytes(
|
value
|
||||||
value
|
.try_into()
|
||||||
.try_into()
|
.expect("Failed to deserialize counter/quota"),
|
||||||
.expect("Failed to deserialize counter/quota"),
|
) as i64;
|
||||||
) as i64,
|
// inbuxa: the SQL stores add a negative amount with an UPDATE,
|
||||||
);
|
// which does nothing to a row that isn't there yet, so a
|
||||||
|
// negative counter vanished on import. Create the row first.
|
||||||
|
if value < 0 {
|
||||||
|
batch.add(class.clone(), 0);
|
||||||
|
}
|
||||||
|
batch.add(class, value);
|
||||||
if batch.is_large_batch() {
|
if batch.is_large_batch() {
|
||||||
store
|
store
|
||||||
.write(batch.build_all())
|
.write(batch.build_all())
|
||||||
|
|||||||
@@ -0,0 +1,103 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! inbuxa: the spam filter rules that ship with the server.
|
||||||
|
//!
|
||||||
|
//! Upstream fetches its latest published rules from GitHub at run time, so
|
||||||
|
//! scoring changes with a release nobody here tested and depends on reaching
|
||||||
|
//! it. The fork embeds a pinned copy (resources/spam-filter/, with its version
|
||||||
|
//! and license) and uses it whenever no other source is configured. The rules
|
||||||
|
//! URL remains an operator override (`https://` or `file://`).
|
||||||
|
//!
|
||||||
|
//! Loading rules only ever adds what's missing, never changes an existing rule
|
||||||
|
//! or score. They load on first boot, and again whenever the bundled version
|
||||||
|
//! differs from the one last applied, so an upgrade brings new tags (the AI
|
||||||
|
//! classifier's `LLM_*` scores, say) to an install that already had rules.
|
||||||
|
|
||||||
|
use std::io::Read;
|
||||||
|
use store::{
|
||||||
|
SUBSPACE_INBUXA, Store, ValueKey,
|
||||||
|
write::{AnyClass, BatchBuilder, ValueClass},
|
||||||
|
};
|
||||||
|
use trc::AddContext;
|
||||||
|
|
||||||
|
/// The version of spam-filter the embedded rules come from.
|
||||||
|
pub const BUNDLED_SPAM_RULES_VERSION: &str = "3.0.2";
|
||||||
|
|
||||||
|
static BUNDLED_SPAM_RULES: &[u8] =
|
||||||
|
include_bytes!("../../../../resources/spam-filter/spam-filter-rules.json.gz");
|
||||||
|
|
||||||
|
/// Upstream's default rules source, the value every install created before
|
||||||
|
/// the rules were bundled has saved. Read only to treat it as unset.
|
||||||
|
const LEGACY_DEFAULT_URL: &str =
|
||||||
|
"https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz";
|
||||||
|
|
||||||
|
/// The URL to fetch rules from, or `None` for the bundled rules. An empty
|
||||||
|
/// setting and upstream's old default both mean the bundled rules.
|
||||||
|
pub fn rules_url(configured: Option<String>) -> Option<String> {
|
||||||
|
configured.filter(|url| !url.trim().is_empty() && url != LEGACY_DEFAULT_URL)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The bundled rules, uncompressed: the same JSON the rules URL serves.
|
||||||
|
pub fn bundled_rules() -> Result<Vec<u8>, String> {
|
||||||
|
let mut json = Vec::new();
|
||||||
|
mail_auth::flate2::read::GzDecoder::new(BUNDLED_SPAM_RULES)
|
||||||
|
.read_to_end(&mut json)
|
||||||
|
.map_err(|err| format!("Failed to decompress the bundled spam rules: {err}"))?;
|
||||||
|
Ok(json)
|
||||||
|
}
|
||||||
|
|
||||||
|
fn applied_key() -> ValueClass {
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace: SUBSPACE_INBUXA,
|
||||||
|
key: b"Sr".to_vec(),
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The bundled version last loaded into the registry, if any.
|
||||||
|
pub async fn applied_version(data: &Store) -> trc::Result<Option<String>> {
|
||||||
|
data.get_value::<String>(ValueKey::from(applied_key()))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Records that the bundled rules of this version have been loaded.
|
||||||
|
pub async fn set_applied_version(data: &Store, version: &str) -> trc::Result<()> {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.set(applied_key(), version.as_bytes().to_vec());
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())
|
||||||
|
.map(|_| ())
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn upstream_default_and_empty_mean_bundled() {
|
||||||
|
assert_eq!(rules_url(None), None);
|
||||||
|
assert_eq!(rules_url(Some(String::new())), None);
|
||||||
|
assert_eq!(rules_url(Some(" ".into())), None);
|
||||||
|
assert_eq!(rules_url(Some(LEGACY_DEFAULT_URL.into())), None);
|
||||||
|
assert_eq!(
|
||||||
|
rules_url(Some("file:///srv/rules.json.gz".into())).as_deref(),
|
||||||
|
Some("file:///srv/rules.json.gz")
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn bundled_rules_parse_and_score_the_ai_tags() {
|
||||||
|
let rules: serde_json::Value = serde_json::from_slice(&bundled_rules().unwrap()).unwrap();
|
||||||
|
let tags = rules["SpamTag"].as_array().unwrap();
|
||||||
|
for (tag, score) in [("LLM_UNSOLICITED_HIGH", 3.0), ("LLM_LEGITIMATE_HIGH", -3.0)] {
|
||||||
|
let found = tags.iter().find(|t| t["tag"] == tag).unwrap();
|
||||||
|
assert_eq!(found["score"].as_f64(), Some(score), "{tag}");
|
||||||
|
}
|
||||||
|
assert!(!rules["SpamRule"].as_array().unwrap().is_empty());
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -8,7 +8,7 @@ store = { path = "../store" }
|
|||||||
registry = { path = "../registry" }
|
registry = { path = "../registry" }
|
||||||
trc = { path = "../trc" }
|
trc = { path = "../trc" }
|
||||||
futures = { version = "0.3", optional = true }
|
futures = { version = "0.3", optional = true }
|
||||||
tokio = { version = "1.53", features = ["sync", "fs", "io-util"] }
|
tokio = { version = "1.53", features = ["sync", "fs", "io-util", "rt", "time"] }
|
||||||
async-nats = { version = "0.50", default-features = false, features = ["server_2_10", "server_2_11", "aws-lc-rs"], optional = true }
|
async-nats = { version = "0.50", default-features = false, features = ["server_2_10", "server_2_11", "aws-lc-rs"], optional = true }
|
||||||
zenoh = { version = "1.10.0", default-features = false, features = ["auth_pubkey", "transport_multilink", "transport_compression", "transport_quic", "transport_tcp", "transport_tls", "transport_udp"], optional = true }
|
zenoh = { version = "1.10.0", default-features = false, features = ["auth_pubkey", "transport_multilink", "transport_compression", "transport_quic", "transport_tcp", "transport_tls", "transport_udp"], optional = true }
|
||||||
rdkafka = { version = "0.39", features = ["cmake-build"], optional = true }
|
rdkafka = { version = "0.39", features = ["cmake-build"], optional = true }
|
||||||
|
|||||||
@@ -2,13 +2,22 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use std::sync::Arc;
|
use std::{
|
||||||
|
sync::{
|
||||||
|
Arc,
|
||||||
|
atomic::{AtomicBool, Ordering},
|
||||||
|
},
|
||||||
|
time::Duration,
|
||||||
|
};
|
||||||
|
|
||||||
use crate::Coordinator;
|
use crate::Coordinator;
|
||||||
use async_nats::Client;
|
use async_nats::Client;
|
||||||
use registry::schema::structs::NatsCoordinator;
|
use registry::schema::structs::NatsCoordinator;
|
||||||
|
use trc::ClusterEvent;
|
||||||
|
|
||||||
pub mod pubsub;
|
pub mod pubsub;
|
||||||
|
|
||||||
@@ -47,9 +56,116 @@ impl NatsPubSub {
|
|||||||
opts = opts.token(credentials);
|
opts = opts.token(credentials);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// inbuxa: connect in the background and keep trying, so a node that
|
||||||
|
// starts while NATS is down still joins the cluster once NATS is
|
||||||
|
// back, instead of running without a coordinator until restarted;
|
||||||
|
// and report the connection going and coming back
|
||||||
|
let reporter = Arc::new(Reporter::default());
|
||||||
|
opts = opts.retry_on_initial_connect().event_callback({
|
||||||
|
let reporter = reporter.clone();
|
||||||
|
move |event| {
|
||||||
|
let reporter = reporter.clone();
|
||||||
|
async move { reporter.report(event) }
|
||||||
|
}
|
||||||
|
});
|
||||||
|
let connection_timeout = config.timeout_connection.into_inner();
|
||||||
|
|
||||||
async_nats::connect_with_options(config.addresses.into_inner(), opts)
|
async_nats::connect_with_options(config.addresses.into_inner(), opts)
|
||||||
.await
|
.await
|
||||||
.map(|client| Coordinator::Nats(Arc::new(NatsPubSub { client })))
|
.map(|client| {
|
||||||
|
reporter.watch_first_connection(client.clone(), connection_timeout);
|
||||||
|
Coordinator::Nats(Arc::new(NatsPubSub { client }))
|
||||||
|
})
|
||||||
.map_err(|err| format!("Failed to connect to Nats: {}", err))
|
.map_err(|err| format!("Failed to connect to Nats: {}", err))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// inbuxa: whether the client is connected to a NATS server right now.
|
||||||
|
pub fn is_connected(&self) -> bool {
|
||||||
|
matches!(
|
||||||
|
self.client.connection_state(),
|
||||||
|
async_nats::connection::State::Connected
|
||||||
|
)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// inbuxa: reports the client's connection events as the server's own.
|
||||||
|
#[derive(Default)]
|
||||||
|
struct Reporter {
|
||||||
|
connected_once: AtomicBool,
|
||||||
|
// A failed attempt raises an error each time the client retries, every
|
||||||
|
// few seconds while NATS is down: report the first after each change
|
||||||
|
error_reported: AtomicBool,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Reporter {
|
||||||
|
fn report(&self, event: async_nats::Event) {
|
||||||
|
match event {
|
||||||
|
async_nats::Event::Connected => {
|
||||||
|
self.connected_once.store(true, Ordering::Relaxed);
|
||||||
|
self.error_reported.store(false, Ordering::Relaxed);
|
||||||
|
trc::event!(Cluster(ClusterEvent::CoordinatorConnected), Type = "nats");
|
||||||
|
}
|
||||||
|
async_nats::Event::Disconnected => {
|
||||||
|
self.error_reported.store(false, Ordering::Relaxed);
|
||||||
|
trc::event!(
|
||||||
|
Cluster(ClusterEvent::CoordinatorDisconnected),
|
||||||
|
Type = "nats",
|
||||||
|
Details = "Connection lost; reconnecting in the background",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
async_nats::Event::Closed => {
|
||||||
|
trc::event!(
|
||||||
|
Cluster(ClusterEvent::CoordinatorDisconnected),
|
||||||
|
Type = "nats",
|
||||||
|
Details = "Connection closed; no further attempts will be made",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
async_nats::Event::ClientError(async_nats::ClientError::MaxReconnects) => {
|
||||||
|
trc::event!(
|
||||||
|
Cluster(ClusterEvent::CoordinatorDisconnected),
|
||||||
|
Type = "nats",
|
||||||
|
Details = "Gave up reconnecting (maxReconnects reached)",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
async_nats::Event::ClientError(err) => {
|
||||||
|
if !self.error_reported.swap(true, Ordering::Relaxed) {
|
||||||
|
trc::event!(
|
||||||
|
Cluster(ClusterEvent::CoordinatorError),
|
||||||
|
Type = "nats",
|
||||||
|
Details = "Connection attempt failed; retrying",
|
||||||
|
Reason = err.to_string(),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
event => {
|
||||||
|
trc::event!(
|
||||||
|
Cluster(ClusterEvent::CoordinatorError),
|
||||||
|
Type = "nats",
|
||||||
|
Details = event.to_string(),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The first connection is made in the background, so say so when it
|
||||||
|
/// hasn't been made within the connection timeout. The client keeps
|
||||||
|
/// trying, and reports the connection when it comes.
|
||||||
|
fn watch_first_connection(self: &Arc<Self>, client: Client, timeout: Duration) {
|
||||||
|
let reporter = self.clone();
|
||||||
|
tokio::spawn(async move {
|
||||||
|
tokio::time::sleep(timeout).await;
|
||||||
|
if !reporter.connected_once.load(Ordering::Relaxed)
|
||||||
|
&& !matches!(
|
||||||
|
client.connection_state(),
|
||||||
|
async_nats::connection::State::Connected
|
||||||
|
)
|
||||||
|
{
|
||||||
|
trc::event!(
|
||||||
|
Cluster(ClusterEvent::CoordinatorDisconnected),
|
||||||
|
Type = "nats",
|
||||||
|
Details = "Not connected at startup; retrying in the background",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::{Coordinator, Msg, PubSubStream};
|
use crate::{Coordinator, Msg, PubSubStream};
|
||||||
@@ -43,6 +45,17 @@ impl Coordinator {
|
|||||||
pub fn is_none(&self) -> bool {
|
pub fn is_none(&self) -> bool {
|
||||||
matches!(self, Coordinator::None)
|
matches!(self, Coordinator::None)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// inbuxa: whether the coordinator is connected right now, for the
|
||||||
|
/// backends that track it (NATS); `None` for the others and when no
|
||||||
|
/// coordinator is configured.
|
||||||
|
pub fn is_connected(&self) -> Option<bool> {
|
||||||
|
match self {
|
||||||
|
#[cfg(feature = "nats")]
|
||||||
|
Coordinator::Nats(store) => Some(store.is_connected()),
|
||||||
|
_ => None,
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
impl PubSubStream {
|
impl PubSubStream {
|
||||||
|
|||||||
@@ -562,6 +562,27 @@ impl ParseHttp for Server {
|
|||||||
})
|
})
|
||||||
.into_http_response());
|
.into_http_response());
|
||||||
}
|
}
|
||||||
|
// inbuxa: the cluster coordinator's connection, for
|
||||||
|
// monitoring. It stays out of live and ready on purpose:
|
||||||
|
// a node without its coordinator still serves mail, and
|
||||||
|
// failing those would have an orchestrator restart, or
|
||||||
|
// take out of service, every node at once when the
|
||||||
|
// coordinator goes down
|
||||||
|
"cluster" => {
|
||||||
|
let coordinator = &self.core.storage.coordinator;
|
||||||
|
let (status, state) = match coordinator.is_connected() {
|
||||||
|
Some(true) => (StatusCode::OK, "connected"),
|
||||||
|
Some(false) => (StatusCode::SERVICE_UNAVAILABLE, "disconnected"),
|
||||||
|
None if coordinator.is_none() => (StatusCode::OK, "none"),
|
||||||
|
None => (StatusCode::OK, "unknown"),
|
||||||
|
};
|
||||||
|
return Ok(http_proto::JsonResponse::with_status(
|
||||||
|
status,
|
||||||
|
serde_json::json!({ "coordinator": state }),
|
||||||
|
)
|
||||||
|
.no_cache()
|
||||||
|
.into_http_response());
|
||||||
|
}
|
||||||
_ => (),
|
_ => (),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -427,9 +427,24 @@ pub(crate) async fn trace_query(
|
|||||||
}
|
}
|
||||||
None => false,
|
None => false,
|
||||||
},
|
},
|
||||||
Property::QueueId => match value.as_str() {
|
// The queue id column is an integer on every search backend, and
|
||||||
|
// holds a trace's first queue id; the keywords carry all of them
|
||||||
|
Property::QueueId => match value
|
||||||
|
.as_str()
|
||||||
|
.and_then(|v| v.trim().parse::<u64>().ok())
|
||||||
|
.or_else(|| value.as_u64())
|
||||||
|
{
|
||||||
Some(queue_id) => {
|
Some(queue_id) => {
|
||||||
search.push(SearchFilter::eq(TracingSearchField::QueueId, queue_id.to_string()));
|
search.extend([
|
||||||
|
SearchFilter::Or,
|
||||||
|
SearchFilter::eq(TracingSearchField::QueueId, queue_id),
|
||||||
|
SearchFilter::has_text(
|
||||||
|
TracingSearchField::Keywords,
|
||||||
|
queue_id.to_string(),
|
||||||
|
nlp::language::Language::None,
|
||||||
|
),
|
||||||
|
SearchFilter::End,
|
||||||
|
]);
|
||||||
true
|
true
|
||||||
}
|
}
|
||||||
None => false,
|
None => false,
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::registry::mapping::{RegistrySetResponse, map_bootstrap_error};
|
use crate::registry::mapping::{RegistrySetResponse, map_bootstrap_error};
|
||||||
@@ -99,7 +101,7 @@ pub(crate) async fn action_set(
|
|||||||
} else {
|
} else {
|
||||||
set.response
|
set.response
|
||||||
.not_created
|
.not_created
|
||||||
.append(id, map_bootstrap_error(result.errors));
|
.append(id, reload_refused(result.errors));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Action::InvalidateCaches => {
|
Action::InvalidateCaches => {
|
||||||
@@ -573,3 +575,34 @@ async fn dmarc_troubleshoot(
|
|||||||
|
|
||||||
Some(request)
|
Some(request)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// inbuxa: a refused reload names the object that stopped it and says the
|
||||||
|
/// settings weren't applied; upstream passed on the first error's bare message
|
||||||
|
/// ("Invalid address: ..."), which read like a problem with the request.
|
||||||
|
fn reload_refused(errors: Vec<registry::types::error::Error>) -> SetError<Property> {
|
||||||
|
use registry::types::error::Error;
|
||||||
|
let more = errors.len().saturating_sub(1);
|
||||||
|
let mut description = match errors.first() {
|
||||||
|
Some(Error::Build { object_id, message }) => format!("{object_id}: {message}"),
|
||||||
|
Some(Error::Validation { object_id, errors }) => format!(
|
||||||
|
"{object_id}: {}",
|
||||||
|
errors
|
||||||
|
.iter()
|
||||||
|
.map(|err| err.to_string())
|
||||||
|
.collect::<Vec<_>>()
|
||||||
|
.join("; ")
|
||||||
|
),
|
||||||
|
Some(Error::Internal {
|
||||||
|
object_id: Some(object_id),
|
||||||
|
error,
|
||||||
|
}) => format!("{object_id}: {error}"),
|
||||||
|
Some(Error::Internal { error, .. }) => error.to_string(),
|
||||||
|
Some(Error::NotFound { object_id }) => format!("{object_id} was not found"),
|
||||||
|
None => String::new(),
|
||||||
|
};
|
||||||
|
description.insert_str(0, "Settings were not reloaded. ");
|
||||||
|
if more > 0 {
|
||||||
|
description.push_str(&format!(" ({more} more in the server log.)"));
|
||||||
|
}
|
||||||
|
map_bootstrap_error(errors).with_description(description)
|
||||||
|
}
|
||||||
|
|||||||
@@ -947,10 +947,14 @@ impl RegistrySet for Server {
|
|||||||
self.cluster_broadcast(common::ipc::BroadcastEvent::RegistryChange(change))
|
self.cluster_broadcast(common::ipc::BroadcastEvent::RegistryChange(change))
|
||||||
.await;
|
.await;
|
||||||
}
|
}
|
||||||
Ok(_) => trc::event!(
|
Ok(reload) => {
|
||||||
Registry(trc::RegistryEvent::BuildWarning),
|
// inbuxa: name what stopped it
|
||||||
Details = "Settings didn't reload after a directory change",
|
reload.log();
|
||||||
),
|
trc::event!(
|
||||||
|
Registry(trc::RegistryEvent::BuildWarning),
|
||||||
|
Details = "Settings didn't reload after a directory change",
|
||||||
|
)
|
||||||
|
}
|
||||||
Err(err) => {
|
Err(err) => {
|
||||||
trc::error!(err.details("Failed to reload directories"));
|
trc::error!(err.details("Failed to reload directories"));
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -109,6 +109,10 @@ async fn main() -> std::io::Result<()> {
|
|||||||
// Wait for shutdown signal
|
// Wait for shutdown signal
|
||||||
wait_for_shutdown().await;
|
wait_for_shutdown().await;
|
||||||
|
|
||||||
|
// inbuxa: hand back the task locks this node holds, so other nodes can
|
||||||
|
// run those tasks now rather than when the locks expire
|
||||||
|
services::task_manager::lock::release_task_locks(&inner.build_server()).await;
|
||||||
|
|
||||||
// Shutdown collector
|
// Shutdown collector
|
||||||
Collector::shutdown();
|
Collector::shutdown();
|
||||||
|
|
||||||
|
|||||||
@@ -40215,7 +40215,7 @@ impl Default for SpamSettings {
|
|||||||
score_reject: Float::new(0.0f64),
|
score_reject: Float::new(0.0f64),
|
||||||
score_spam: Float::new(5.0f64),
|
score_spam: Float::new(5.0f64),
|
||||||
trust_replies: true,
|
trust_replies: true,
|
||||||
spam_filter_rules_url: Some("https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz".to_string()),
|
spam_filter_rules_url: None,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -26,7 +26,7 @@ pub fn spawn_broadcast_subscriber(inner: Arc<Inner>, mut shutdown_rx: watch::Rec
|
|||||||
};
|
};
|
||||||
|
|
||||||
tokio::spawn(async move {
|
tokio::spawn(async move {
|
||||||
let mut retry_count = 0;
|
let mut retry_count: u32 = 0;
|
||||||
|
|
||||||
trc::event!(Cluster(ClusterEvent::SubscriberStart));
|
trc::event!(Cluster(ClusterEvent::SubscriberStart));
|
||||||
|
|
||||||
@@ -53,7 +53,7 @@ pub fn spawn_broadcast_subscriber(inner: Arc<Inner>, mut shutdown_rx: watch::Rec
|
|||||||
);
|
);
|
||||||
|
|
||||||
match tokio::time::timeout(
|
match tokio::time::timeout(
|
||||||
Duration::from_secs(1 << retry_count.max(6)),
|
subscribe_retry_delay(retry_count),
|
||||||
shutdown_rx.changed(),
|
shutdown_rx.changed(),
|
||||||
)
|
)
|
||||||
.await
|
.await
|
||||||
@@ -62,7 +62,7 @@ pub fn spawn_broadcast_subscriber(inner: Arc<Inner>, mut shutdown_rx: watch::Rec
|
|||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
Err(_) => {
|
Err(_) => {
|
||||||
retry_count += 1;
|
retry_count = retry_count.saturating_add(1);
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -234,6 +234,11 @@ pub fn spawn_broadcast_subscriber(inner: Arc<Inner>, mut shutdown_rx: watch::Rec
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Delay before the next subscribe attempt: 1 s, 2 s, 4 s ... capped at 64 s.
|
||||||
|
fn subscribe_retry_delay(retry_count: u32) -> Duration {
|
||||||
|
Duration::from_secs(1u64 << retry_count.min(6))
|
||||||
|
}
|
||||||
|
|
||||||
fn log_event(event: &BroadcastEvent) -> trc::Value {
|
fn log_event(event: &BroadcastEvent) -> trc::Value {
|
||||||
match event {
|
match event {
|
||||||
BroadcastEvent::PushNotification(notification) => match notification {
|
BroadcastEvent::PushNotification(notification) => match notification {
|
||||||
@@ -296,3 +301,19 @@ fn log_event(event: &BroadcastEvent) -> trc::Value {
|
|||||||
BroadcastEvent::QueueRefresh => "QueueRefresh".into(),
|
BroadcastEvent::QueueRefresh => "QueueRefresh".into(),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::subscribe_retry_delay;
|
||||||
|
use std::time::Duration;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn subscribe_retry_backoff_grows_then_caps() {
|
||||||
|
let schedule: Vec<u64> = (0..10)
|
||||||
|
.map(|n| subscribe_retry_delay(n).as_secs())
|
||||||
|
.collect();
|
||||||
|
assert_eq!(schedule, vec![1, 2, 4, 8, 16, 32, 64, 64, 64, 64]);
|
||||||
|
// No shift overflow at the top of the range.
|
||||||
|
assert_eq!(subscribe_retry_delay(u32::MAX), Duration::from_secs(64));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -91,7 +91,15 @@ impl SearchIndexTask for Server {
|
|||||||
build_contact_document(self, account_id, document_id).await
|
build_contact_document(self, account_id, document_id).await
|
||||||
}
|
}
|
||||||
IndexDocumentType::File => {
|
IndexDocumentType::File => {
|
||||||
// File indexing not implemented yet
|
// File indexing not implemented yet. inbuxa: still
|
||||||
|
// one result per task: update_tasks pairs them by
|
||||||
|
// position, and a missing one shifts every result
|
||||||
|
// after it onto the wrong task
|
||||||
|
results.push(IndexTaskResult {
|
||||||
|
task_type: TaskType::Insert,
|
||||||
|
index: task.document_type,
|
||||||
|
result: TaskResult::Ignored,
|
||||||
|
});
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
@@ -567,20 +575,14 @@ async fn build_contact_document(
|
|||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
// inbuxa: MON-16: a trace's search document, when trace search is on:
|
// inbuxa: MON-16: a trace's search document, when trace search is on
|
||||||
// its event types, queue ids, and addresses, their domains, hosts, IPs,
|
|
||||||
// message ids and account names as keywords
|
|
||||||
async fn build_tracing_span_document(
|
async fn build_tracing_span_document(
|
||||||
server: &Server,
|
server: &Server,
|
||||||
span_id: u64,
|
span_id: u64,
|
||||||
) -> trc::Result<Option<IndexDocument>> {
|
) -> trc::Result<Option<IndexDocument>> {
|
||||||
use common::telemetry::tracers::store::MaybeTrace;
|
use common::telemetry::tracers::store::MaybeTrace;
|
||||||
use registry::schema::{enums::SearchTracingField, structs::Search};
|
use registry::schema::structs::Search;
|
||||||
use store::{
|
use store::write::{TelemetryClass, ValueClass};
|
||||||
search::TracingSearchField,
|
|
||||||
write::{TelemetryClass, ValueClass},
|
|
||||||
};
|
|
||||||
use trc::Key;
|
|
||||||
|
|
||||||
let settings = server
|
let settings = server
|
||||||
.registry()
|
.registry()
|
||||||
@@ -590,7 +592,6 @@ async fn build_tracing_span_document(
|
|||||||
if !settings.index_telemetry {
|
if !settings.index_telemetry {
|
||||||
return Ok(None);
|
return Ok(None);
|
||||||
}
|
}
|
||||||
let wants = |field: SearchTracingField| settings.index_tracing_fields.iter().any(|f| *f == field);
|
|
||||||
let Some(MaybeTrace(Some(trace))) = server
|
let Some(MaybeTrace(Some(trace))) = server
|
||||||
.tracing_store()
|
.tracing_store()
|
||||||
.get_value::<MaybeTrace>(ValueKey::from(ValueClass::Telemetry(TelemetryClass::Span(
|
.get_value::<MaybeTrace>(ValueKey::from(ValueClass::Telemetry(TelemetryClass::Span(
|
||||||
@@ -601,23 +602,67 @@ async fn build_tracing_span_document(
|
|||||||
return Ok(None);
|
return Ok(None);
|
||||||
};
|
};
|
||||||
|
|
||||||
|
Ok(Some(trace_search_document(
|
||||||
|
span_id,
|
||||||
|
&trace,
|
||||||
|
&settings
|
||||||
|
.index_tracing_fields
|
||||||
|
.iter()
|
||||||
|
.copied()
|
||||||
|
.collect::<Vec<_>>(),
|
||||||
|
)))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// inbuxa: MON-16: the search document for a stored trace.
|
||||||
|
///
|
||||||
|
/// The event type and queue id columns are integers on every search backend
|
||||||
|
/// (BIGINT on PostgreSQL and MySQL, long on Elasticsearch), and each holds a
|
||||||
|
/// single value per trace: the event type is the trace's opening event, the
|
||||||
|
/// one `x:Trace/query` filters on, and the queue id is the first queue id the
|
||||||
|
/// trace mentions. Every queue id also goes into the keywords, so a session
|
||||||
|
/// that queued several messages is found by any of them.
|
||||||
|
pub fn trace_search_document(
|
||||||
|
span_id: u64,
|
||||||
|
trace: ®istry::schema::structs::Trace,
|
||||||
|
fields: &[registry::schema::enums::SearchTracingField],
|
||||||
|
) -> IndexDocument {
|
||||||
|
use registry::schema::{enums::SearchTracingField, structs::TraceValue};
|
||||||
|
use store::search::TracingSearchField;
|
||||||
|
use trc::Key;
|
||||||
|
|
||||||
|
let wants = |field: SearchTracingField| fields.contains(&field);
|
||||||
let mut document = IndexDocument::new(SearchIndex::Tracing).with_id(span_id);
|
let mut document = IndexDocument::new(SearchIndex::Tracing).with_id(span_id);
|
||||||
|
if wants(SearchTracingField::EventType)
|
||||||
|
&& let Some(first) = trace.events.iter().next()
|
||||||
|
{
|
||||||
|
document.index_unsigned(TracingSearchField::EventType, first.event.to_id() as u64);
|
||||||
|
}
|
||||||
|
|
||||||
let mut seen = store::ahash::AHashSet::new();
|
let mut seen = store::ahash::AHashSet::new();
|
||||||
|
let mut queue_id_indexed = false;
|
||||||
for event in trace.events.iter() {
|
for event in trace.events.iter() {
|
||||||
if wants(SearchTracingField::EventType) && seen.insert(event.event.as_str().to_string()) {
|
|
||||||
document.index_keyword(TracingSearchField::EventType, event.event.as_str());
|
|
||||||
}
|
|
||||||
for kv in event.key_values.iter() {
|
for kv in event.key_values.iter() {
|
||||||
let text = match &kv.value {
|
let text = match &kv.value {
|
||||||
registry::schema::structs::TraceValue::String(v) => v.value.clone(),
|
TraceValue::String(v) => v.value.clone(),
|
||||||
registry::schema::structs::TraceValue::UnsignedInt(v) => v.value.to_string(),
|
TraceValue::UnsignedInt(v) => v.value.to_string(),
|
||||||
registry::schema::structs::TraceValue::IpAddr(v) => v.value.to_string(),
|
TraceValue::IpAddr(v) => v.value.to_string(),
|
||||||
_ => continue,
|
_ => continue,
|
||||||
};
|
};
|
||||||
match kv.key {
|
match kv.key {
|
||||||
Key::QueueId if wants(SearchTracingField::QueueId) => {
|
Key::QueueId => {
|
||||||
if seen.insert(format!("q:{text}")) {
|
let Ok(queue_id) = text.parse::<u64>() else {
|
||||||
document.index_keyword(TracingSearchField::QueueId, &text);
|
continue;
|
||||||
|
};
|
||||||
|
if wants(SearchTracingField::QueueId) && !queue_id_indexed {
|
||||||
|
document.index_unsigned(TracingSearchField::QueueId, queue_id);
|
||||||
|
queue_id_indexed = true;
|
||||||
|
}
|
||||||
|
if wants(SearchTracingField::Keywords) && seen.insert(format!("k:{text}")) {
|
||||||
|
document.index_text(
|
||||||
|
TracingSearchField::Keywords,
|
||||||
|
&text,
|
||||||
|
nlp::language::Language::None,
|
||||||
|
);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Key::From
|
Key::From
|
||||||
@@ -648,7 +693,7 @@ async fn build_tracing_span_document(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Ok(Some(document))
|
document
|
||||||
}
|
}
|
||||||
|
|
||||||
// inbuxa: UD-1, UD-4: archives a deleted file, event or contact noted at
|
// inbuxa: UD-1, UD-4: archives a deleted file, event or contact noted at
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::task_manager::*;
|
use crate::task_manager::*;
|
||||||
@@ -13,13 +15,21 @@ pub trait TaskLockManager: Sync + Send {
|
|||||||
|
|
||||||
impl TaskLockManager for Server {
|
impl TaskLockManager for Server {
|
||||||
async fn try_lock_task(&self, id: u64) -> bool {
|
async fn try_lock_task(&self, id: u64) -> bool {
|
||||||
|
// inbuxa: a node that is stopping claims nothing new
|
||||||
|
let locks = &self.inner.ipc.task_locks;
|
||||||
|
if locks.is_stopping() {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
match self
|
match self
|
||||||
.in_memory_store()
|
.in_memory_store()
|
||||||
.try_lock(KV_LOCK_TASK, &id.to_be_bytes(), DEFAULT_LOCK_EXPIRY)
|
.try_lock(KV_LOCK_TASK, &id.to_be_bytes(), locks.expiry())
|
||||||
.await
|
.await
|
||||||
{
|
{
|
||||||
Ok(result) => {
|
Ok(result) => {
|
||||||
if !result {
|
if result {
|
||||||
|
locks.insert(id);
|
||||||
|
} else {
|
||||||
trc::event!(
|
trc::event!(
|
||||||
TaskManager(TaskManagerEvent::TaskLocked),
|
TaskManager(TaskManagerEvent::TaskLocked),
|
||||||
Id = id,
|
Id = id,
|
||||||
@@ -48,5 +58,27 @@ impl TaskLockManager for Server {
|
|||||||
.caused_by(trc::location!())
|
.caused_by(trc::location!())
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
self.inner.ipc.task_locks.remove(id);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// inbuxa: on a graceful stop, stops claiming tasks and releases every task
|
||||||
|
/// lock this node holds, so the rest of the cluster can pick the tasks up at
|
||||||
|
/// once instead of after the lock expires. Returns how many were released.
|
||||||
|
pub async fn release_task_locks(server: &Server) -> usize {
|
||||||
|
let ids = server.inner.ipc.task_locks.stop();
|
||||||
|
for id in &ids {
|
||||||
|
if let Err(err) = server
|
||||||
|
.in_memory_store()
|
||||||
|
.remove_lock(KV_LOCK_TASK, &id.to_be_bytes())
|
||||||
|
.await
|
||||||
|
{
|
||||||
|
trc::error!(
|
||||||
|
err.details("Failed to release task lock on shutdown")
|
||||||
|
.ctx(trc::Key::Id, *id)
|
||||||
|
.caused_by(trc::location!())
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
ids.len()
|
||||||
|
}
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::task_manager::acme::AcmeTask;
|
use crate::task_manager::acme::AcmeTask;
|
||||||
@@ -18,7 +20,7 @@ use crate::task_manager::report::{self, SubmitReportTask};
|
|||||||
use crate::task_manager::restore_item::RestoreItemTask;
|
use crate::task_manager::restore_item::RestoreItemTask;
|
||||||
use crate::task_manager::spam_classifier::SpamFilterMaintenanceTask;
|
use crate::task_manager::spam_classifier::SpamFilterMaintenanceTask;
|
||||||
use crate::task_manager::{
|
use crate::task_manager::{
|
||||||
DEFAULT_LOCK_EXPIRY, Locked, QUEUE_REFRESH_INTERVAL, TaskDetails, TaskFailureType, TaskInfo,
|
CLAIM_RECHECK_INTERVAL, Locked, QUEUE_REFRESH_INTERVAL, TaskDetails, TaskFailureType, TaskInfo,
|
||||||
TaskJob, TaskManagerIpc, TaskResult,
|
TaskJob, TaskManagerIpc, TaskResult,
|
||||||
};
|
};
|
||||||
use common::BuildServer;
|
use common::BuildServer;
|
||||||
@@ -124,72 +126,47 @@ pub fn spawn_task_manager(inner: Arc<Inner>) {
|
|||||||
let server = inner.build_server();
|
let server = inner.build_server();
|
||||||
let batch_size = server.core.email.index_batch_size;
|
let batch_size = server.core.email.index_batch_size;
|
||||||
let mut batch = Vec::with_capacity(batch_size);
|
let mut batch = Vec::with_capacity(batch_size);
|
||||||
match server
|
if let Some(task) = fetch_task(&server, job).await {
|
||||||
.store()
|
batch.push(task);
|
||||||
.get_value::<Task>(ValueKey::from(ValueClass::TaskQueue(
|
|
||||||
TaskQueueClass::Task { id: job.id },
|
|
||||||
)))
|
|
||||||
.await
|
|
||||||
{
|
|
||||||
Ok(Some(task)) => {
|
|
||||||
batch.push(TaskDetails { task, info: job });
|
|
||||||
}
|
|
||||||
Ok(None) => {
|
|
||||||
trc::event!(
|
|
||||||
TaskManager(TaskManagerEvent::TaskIgnored),
|
|
||||||
Id = job.id,
|
|
||||||
Reason = "Task not found in store, likely already processed.",
|
|
||||||
);
|
|
||||||
}
|
|
||||||
Err(err) => {
|
|
||||||
trc::error!(
|
|
||||||
err.id(job.id)
|
|
||||||
.details("Failed to retrieve task details.")
|
|
||||||
.caused_by(trc::location!())
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
while batch.len() < batch_size {
|
while batch.len() < batch_size {
|
||||||
match rx.try_recv() {
|
match rx.try_recv() {
|
||||||
Ok(job) => {
|
Ok(job) => {
|
||||||
match server
|
if let Some(task) = fetch_task(&server, job).await {
|
||||||
.store()
|
batch.push(task);
|
||||||
.get_value::<Task>(ValueKey::from(ValueClass::TaskQueue(
|
|
||||||
TaskQueueClass::Task { id: job.id },
|
|
||||||
)))
|
|
||||||
.await
|
|
||||||
{
|
|
||||||
Ok(Some(task)) => {
|
|
||||||
batch.push(TaskDetails { task, info: job });
|
|
||||||
}
|
|
||||||
Ok(None) => {
|
|
||||||
trc::event!(
|
|
||||||
TaskManager(TaskManagerEvent::TaskIgnored),
|
|
||||||
Id = job.id,
|
|
||||||
Reason = "Task not found in store, likely already processed.",
|
|
||||||
);
|
|
||||||
}
|
|
||||||
Err(err) => {
|
|
||||||
trc::error!(
|
|
||||||
err.id(job.id)
|
|
||||||
.details("Failed to retrieve task details.")
|
|
||||||
.caused_by(trc::location!())
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Err(_) => break,
|
Err(_) => break,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Dispatch
|
// Dispatch. inbuxa: on a task of its own, so a panic
|
||||||
|
// releases the batch's locks and leaves this worker
|
||||||
|
// running; a dead worker would keep claiming tasks it
|
||||||
|
// can never run
|
||||||
let mut refresh_queue = false;
|
let mut refresh_queue = false;
|
||||||
let results = server.index(&batch).await.into_iter().map(|r| {
|
let ids = batch.iter().map(|task| task.info.id).collect::<Vec<_>>();
|
||||||
refresh_queue |= r.result.is_retry();
|
let run = {
|
||||||
r.result
|
let server = server.clone();
|
||||||
});
|
tokio::spawn(async move {
|
||||||
update_tasks(&server, &mut batch, results).await;
|
let results = server.index(&batch).await;
|
||||||
|
(batch, results)
|
||||||
|
})
|
||||||
|
};
|
||||||
|
match run.await {
|
||||||
|
Ok((mut batch, results)) => {
|
||||||
|
let results = results.into_iter().map(|r| {
|
||||||
|
refresh_queue |= r.result.is_retry();
|
||||||
|
r.result
|
||||||
|
});
|
||||||
|
update_tasks(&server, &mut batch, results).await;
|
||||||
|
}
|
||||||
|
Err(err) => {
|
||||||
|
worker_failed(&server, &ids, err).await;
|
||||||
|
refresh_queue = true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if refresh_queue || rx.is_empty() {
|
if refresh_queue || rx.is_empty() {
|
||||||
server.notify_task_queue();
|
server.notify_task_queue();
|
||||||
@@ -203,83 +180,31 @@ pub fn spawn_task_manager(inner: Arc<Inner>) {
|
|||||||
let server = inner.build_server();
|
let server = inner.build_server();
|
||||||
let mut refresh_queue = false;
|
let mut refresh_queue = false;
|
||||||
|
|
||||||
match server
|
if let Some(TaskDetails { task, info }) = fetch_task(&server, job).await {
|
||||||
.store()
|
// inbuxa: on a task of its own, as above
|
||||||
.get_value::<Task>(ValueKey::from(ValueClass::TaskQueue(
|
let run = {
|
||||||
TaskQueueClass::Task { id: job.id },
|
let server = server.clone();
|
||||||
)))
|
let server_instance = server_instance.clone();
|
||||||
.await
|
tokio::spawn(async move {
|
||||||
{
|
let result = run_task(&server, &task, server_instance).await;
|
||||||
Ok(Some(task)) => {
|
(task, result)
|
||||||
let result = match &task {
|
})
|
||||||
Task::CalendarAlarmEmail(task) => {
|
};
|
||||||
server.send_email_alarm(task, server_instance.clone()).await
|
match run.await {
|
||||||
}
|
Ok((task, result)) => {
|
||||||
Task::CalendarAlarmNotification(task) => {
|
refresh_queue = result.is_retry();
|
||||||
server.send_display_alarm(task).await
|
|
||||||
}
|
|
||||||
Task::CalendarItipMessage(task) => {
|
|
||||||
server.send_imip(task, server_instance.clone()).await
|
|
||||||
}
|
|
||||||
Task::MergeThreads(task) => server.merge_threads(task).await,
|
|
||||||
Task::DmarcReport(task) => {
|
|
||||||
server
|
|
||||||
.submit_report(report::ReportId::Dmarc(task.report_id.id()))
|
|
||||||
.await
|
|
||||||
}
|
|
||||||
Task::TlsReport(task) => {
|
|
||||||
server
|
|
||||||
.submit_report(report::ReportId::Tls(task.report_id.id()))
|
|
||||||
.await
|
|
||||||
}
|
|
||||||
Task::RestoreArchivedItem(task) => server.restore_item(task).await,
|
|
||||||
Task::DestroyAccount(task) => server.destroy_account(task).await,
|
|
||||||
Task::AccountMaintenance(task) => {
|
|
||||||
server.account_maintenance(task).await
|
|
||||||
}
|
|
||||||
Task::TenantMaintenance(task) => {
|
|
||||||
server.tenant_maintenance(task).await
|
|
||||||
}
|
|
||||||
Task::StoreMaintenance(task) => {
|
|
||||||
server.store_maintenance(task).await
|
|
||||||
}
|
|
||||||
Task::SpamFilterMaintenance(task) => {
|
|
||||||
Box::pin(server.spam_filter_maintenance(task)).await
|
|
||||||
}
|
|
||||||
Task::AcmeRenewal(task) => server.acme_management(task).await,
|
|
||||||
Task::DkimManagement(task_dkim_rotation) => {
|
|
||||||
server.dkim_management(task_dkim_rotation).await
|
|
||||||
}
|
|
||||||
Task::DnsManagement(task_dns_management) => {
|
|
||||||
server.dns_management(task_dns_management).await
|
|
||||||
}
|
|
||||||
Task::IndexDocument(_)
|
|
||||||
| Task::UnindexDocument(_)
|
|
||||||
| Task::IndexTrace(_) => unreachable!(),
|
|
||||||
};
|
|
||||||
|
|
||||||
refresh_queue = result.is_retry();
|
update_tasks(
|
||||||
|
&server,
|
||||||
update_tasks(
|
&mut [TaskDetails { task, info }],
|
||||||
&server,
|
vec![result],
|
||||||
&mut [TaskDetails { task, info: job }],
|
)
|
||||||
vec![result],
|
.await;
|
||||||
)
|
}
|
||||||
.await;
|
Err(err) => {
|
||||||
}
|
worker_failed(&server, &[info.id], err).await;
|
||||||
Ok(None) => {
|
refresh_queue = true;
|
||||||
trc::event!(
|
}
|
||||||
TaskManager(TaskManagerEvent::TaskIgnored),
|
|
||||||
Id = job.id,
|
|
||||||
Reason = "Task not found in store, likely already processed.",
|
|
||||||
);
|
|
||||||
}
|
|
||||||
Err(err) => {
|
|
||||||
trc::error!(
|
|
||||||
err.id(job.id)
|
|
||||||
.details("Failed to retrieve task details.")
|
|
||||||
.caused_by(trc::location!())
|
|
||||||
);
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -318,6 +243,13 @@ pub(crate) trait TaskQueueManager: Sync + Send {
|
|||||||
|
|
||||||
impl TaskQueueManager for Server {
|
impl TaskQueueManager for Server {
|
||||||
async fn process_tasks(&self, ipc: &mut TaskManagerIpc) -> Duration {
|
async fn process_tasks(&self, ipc: &mut TaskManagerIpc) -> Duration {
|
||||||
|
// inbuxa: a node that is stopping has released its locks and claims
|
||||||
|
// nothing new
|
||||||
|
let task_locks = &self.inner.ipc.task_locks;
|
||||||
|
if task_locks.is_stopping() {
|
||||||
|
return Duration::from_secs(QUEUE_REFRESH_INTERVAL);
|
||||||
|
}
|
||||||
|
let lock_expiry = task_locks.expiry();
|
||||||
let now_timestamp = now();
|
let now_timestamp = now();
|
||||||
let from_key = ValueKey::<ValueClass> {
|
let from_key = ValueKey::<ValueClass> {
|
||||||
account_id: 0,
|
account_id: 0,
|
||||||
@@ -393,9 +325,7 @@ impl TaskQueueManager for Server {
|
|||||||
let locked = entry.get_mut();
|
let locked = entry.get_mut();
|
||||||
if locked.expires <= now || locked.due < task_due {
|
if locked.expires <= now || locked.due < task_due {
|
||||||
locked.expires = Instant::now()
|
locked.expires = Instant::now()
|
||||||
+ std::time::Duration::from_secs(
|
+ std::time::Duration::from_secs(lock_expiry + 1);
|
||||||
DEFAULT_LOCK_EXPIRY + 1,
|
|
||||||
);
|
|
||||||
locked.due = task_due;
|
locked.due = task_due;
|
||||||
tasks.push((
|
tasks.push((
|
||||||
TaskJob {
|
TaskJob {
|
||||||
@@ -411,9 +341,7 @@ impl TaskQueueManager for Server {
|
|||||||
Entry::Vacant(entry) => {
|
Entry::Vacant(entry) => {
|
||||||
entry.insert(Locked {
|
entry.insert(Locked {
|
||||||
expires: Instant::now()
|
expires: Instant::now()
|
||||||
+ std::time::Duration::from_secs(
|
+ std::time::Duration::from_secs(lock_expiry + 1),
|
||||||
DEFAULT_LOCK_EXPIRY + 1,
|
|
||||||
),
|
|
||||||
due: task_due,
|
due: task_due,
|
||||||
revision: ipc.revision,
|
revision: ipc.revision,
|
||||||
});
|
});
|
||||||
@@ -464,12 +392,26 @@ impl TaskQueueManager for Server {
|
|||||||
let tx = &ipc.txs[task_type_idx as usize];
|
let tx = &ipc.txs[task_type_idx as usize];
|
||||||
|
|
||||||
if tx.capacity() > 0 {
|
if tx.capacity() > 0 {
|
||||||
if self.try_lock_task(task_job.id).await && tx.send(task_job).await.is_err() {
|
let id = task_job.id;
|
||||||
|
if !self.try_lock_task(id).await {
|
||||||
|
// inbuxa: another node holds the task. Look again after a
|
||||||
|
// short while rather than a full lock lifetime from now:
|
||||||
|
// the holder may have claimed it after this scan began,
|
||||||
|
// or run on a clock ahead of this one, and waiting the
|
||||||
|
// whole lifetime again would leave the task stuck for
|
||||||
|
// another hour past its lock if that holder died
|
||||||
|
if let Some(locked) = ipc.locked.get_mut(&id) {
|
||||||
|
locked.expires =
|
||||||
|
Instant::now() + Duration::from_secs(claim_recheck_interval(lock_expiry));
|
||||||
|
}
|
||||||
|
} else if tx.send(task_job).await.is_err() {
|
||||||
trc::event!(
|
trc::event!(
|
||||||
Server(trc::ServerEvent::ThreadError),
|
Server(trc::ServerEvent::ThreadError),
|
||||||
Details = "Error sending task.",
|
Details = "Error sending task.",
|
||||||
CausedBy = trc::location!()
|
CausedBy = trc::location!()
|
||||||
);
|
);
|
||||||
|
// inbuxa: nothing will run it here, so don't hold it
|
||||||
|
self.remove_index_lock(id).await;
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
// If the channel is full, release the lock so it can be picked up in the next iteration
|
// If the channel is full, release the lock so it can be picked up in the next iteration
|
||||||
@@ -481,9 +423,117 @@ impl TaskQueueManager for Server {
|
|||||||
let now = Instant::now();
|
let now = Instant::now();
|
||||||
ipc.locked
|
ipc.locked
|
||||||
.retain(|_, locked| locked.expires > now && locked.revision == ipc.revision);
|
.retain(|_, locked| locked.expires > now && locked.revision == ipc.revision);
|
||||||
Duration::from_secs(next_event.map_or(QUEUE_REFRESH_INTERVAL, |timestamp| {
|
let sleep_for = Duration::from_secs(next_event.map_or(QUEUE_REFRESH_INTERVAL, |timestamp| {
|
||||||
timestamp.saturating_sub(store::write::now())
|
timestamp.saturating_sub(store::write::now())
|
||||||
}))
|
}));
|
||||||
|
|
||||||
|
// inbuxa: wake up when a claim held elsewhere is due to be tried
|
||||||
|
// again, rather than only on the next task or refresh
|
||||||
|
ipc.locked
|
||||||
|
.values()
|
||||||
|
.map(|locked| locked.expires.saturating_duration_since(now))
|
||||||
|
.min()
|
||||||
|
.map_or(sleep_for, |recheck| sleep_for.min(recheck.max(Duration::from_secs(1))))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn run_task(
|
||||||
|
server: &Server,
|
||||||
|
task: &Task,
|
||||||
|
server_instance: Arc<ServerInstance>,
|
||||||
|
) -> TaskResult {
|
||||||
|
match task {
|
||||||
|
Task::CalendarAlarmEmail(task) => {
|
||||||
|
server.send_email_alarm(task, server_instance.clone()).await
|
||||||
|
}
|
||||||
|
Task::CalendarAlarmNotification(task) => {
|
||||||
|
server.send_display_alarm(task).await
|
||||||
|
}
|
||||||
|
Task::CalendarItipMessage(task) => {
|
||||||
|
server.send_imip(task, server_instance.clone()).await
|
||||||
|
}
|
||||||
|
Task::MergeThreads(task) => server.merge_threads(task).await,
|
||||||
|
Task::DmarcReport(task) => {
|
||||||
|
server
|
||||||
|
.submit_report(report::ReportId::Dmarc(task.report_id.id()))
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
Task::TlsReport(task) => {
|
||||||
|
server
|
||||||
|
.submit_report(report::ReportId::Tls(task.report_id.id()))
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
Task::RestoreArchivedItem(task) => server.restore_item(task).await,
|
||||||
|
Task::DestroyAccount(task) => server.destroy_account(task).await,
|
||||||
|
Task::AccountMaintenance(task) => {
|
||||||
|
server.account_maintenance(task).await
|
||||||
|
}
|
||||||
|
Task::TenantMaintenance(task) => {
|
||||||
|
server.tenant_maintenance(task).await
|
||||||
|
}
|
||||||
|
Task::StoreMaintenance(task) => {
|
||||||
|
server.store_maintenance(task).await
|
||||||
|
}
|
||||||
|
Task::SpamFilterMaintenance(task) => {
|
||||||
|
Box::pin(server.spam_filter_maintenance(task)).await
|
||||||
|
}
|
||||||
|
Task::AcmeRenewal(task) => server.acme_management(task).await,
|
||||||
|
Task::DkimManagement(task_dkim_rotation) => {
|
||||||
|
server.dkim_management(task_dkim_rotation).await
|
||||||
|
}
|
||||||
|
Task::DnsManagement(task_dns_management) => {
|
||||||
|
server.dns_management(task_dns_management).await
|
||||||
|
}
|
||||||
|
Task::IndexDocument(_)
|
||||||
|
| Task::UnindexDocument(_)
|
||||||
|
| Task::IndexTrace(_) => unreachable!(),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Reads a claimed task. When it is gone or can't be read, the claim is
|
||||||
|
/// released: inbuxa: holding it would block the task, everywhere, until
|
||||||
|
/// the lock expired.
|
||||||
|
async fn fetch_task(server: &Server, job: TaskJob) -> Option<TaskDetails> {
|
||||||
|
match server
|
||||||
|
.store()
|
||||||
|
.get_value::<Task>(ValueKey::from(ValueClass::TaskQueue(TaskQueueClass::Task {
|
||||||
|
id: job.id,
|
||||||
|
})))
|
||||||
|
.await
|
||||||
|
{
|
||||||
|
Ok(Some(task)) => Some(TaskDetails { task, info: job }),
|
||||||
|
Ok(None) => {
|
||||||
|
trc::event!(
|
||||||
|
TaskManager(TaskManagerEvent::TaskIgnored),
|
||||||
|
Id = job.id,
|
||||||
|
Reason = "Task not found in store, likely already processed.",
|
||||||
|
);
|
||||||
|
server.remove_index_lock(job.id).await;
|
||||||
|
None
|
||||||
|
}
|
||||||
|
Err(err) => {
|
||||||
|
trc::error!(
|
||||||
|
err.id(job.id)
|
||||||
|
.details("Failed to retrieve task details.")
|
||||||
|
.caused_by(trc::location!())
|
||||||
|
);
|
||||||
|
server.remove_index_lock(job.id).await;
|
||||||
|
None
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// inbuxa: a task panicked: its locks are released so it runs again, here or
|
||||||
|
/// on another node, and the worker carries on.
|
||||||
|
async fn worker_failed(server: &Server, ids: &[u64], err: tokio::task::JoinError) {
|
||||||
|
trc::event!(
|
||||||
|
Server(trc::ServerEvent::ThreadError),
|
||||||
|
Details = "Task worker failed",
|
||||||
|
Reason = err.to_string(),
|
||||||
|
CausedBy = trc::location!()
|
||||||
|
);
|
||||||
|
for id in ids {
|
||||||
|
server.remove_index_lock(*id).await;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -614,6 +664,13 @@ async fn update_tasks(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// inbuxa: how long to wait before trying again to claim a task another node
|
||||||
|
/// holds: a twelfth of the lock lifetime, so five minutes for the one-hour
|
||||||
|
/// lock, never more than that and never under a second.
|
||||||
|
pub(crate) fn claim_recheck_interval(lock_expiry: u64) -> u64 {
|
||||||
|
(lock_expiry / 12).clamp(1, CLAIM_RECHECK_INTERVAL)
|
||||||
|
}
|
||||||
|
|
||||||
pub fn perpetual_retry_time(typ: TaskType, attempt: u64) -> Option<u64> {
|
pub fn perpetual_retry_time(typ: TaskType, attempt: u64) -> Option<u64> {
|
||||||
matches!(
|
matches!(
|
||||||
typ,
|
typ,
|
||||||
|
|||||||
@@ -35,7 +35,9 @@ pub mod scheduler;
|
|||||||
pub mod spam_classifier;
|
pub mod spam_classifier;
|
||||||
|
|
||||||
const QUEUE_REFRESH_INTERVAL: u64 = 60 * 5; // 5 minutes
|
const QUEUE_REFRESH_INTERVAL: u64 = 60 * 5; // 5 minutes
|
||||||
const DEFAULT_LOCK_EXPIRY: u64 = 60 * 60; // 1 hour
|
// inbuxa: the lock lifetime (one hour) lives in common::ipc::TaskLocks, per
|
||||||
|
// server, so a graceful stop can release the locks and the tests can shorten it
|
||||||
|
const CLAIM_RECHECK_INTERVAL: u64 = 60 * 5; // 5 minutes
|
||||||
|
|
||||||
pub(crate) struct TaskManagerIpc {
|
pub(crate) struct TaskManagerIpc {
|
||||||
txs: [mpsc::Sender<TaskJob>; TaskType::COUNT],
|
txs: [mpsc::Sender<TaskJob>; TaskType::COUNT],
|
||||||
|
|||||||
@@ -2,13 +2,15 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::task_manager::{TaskFailureType, TaskResult};
|
use crate::task_manager::{TaskFailureType, TaskResult};
|
||||||
use common::{
|
use common::{
|
||||||
Server,
|
Server,
|
||||||
ipc::{BroadcastEvent, RegistryChange},
|
ipc::{BroadcastEvent, RegistryChange},
|
||||||
manager::{SPAM_CLASSIFIER_KEY, SPAM_TRAINER_KEY, fetch_resource},
|
manager::{SPAM_CLASSIFIER_KEY, SPAM_TRAINER_KEY, fetch_resource, spam_rules},
|
||||||
};
|
};
|
||||||
use registry::{
|
use registry::{
|
||||||
schema::{
|
schema::{
|
||||||
@@ -106,6 +108,7 @@ struct RuleUpdateResult {
|
|||||||
|
|
||||||
async fn update_spam_rules(server: &Server) -> trc::Result<TaskResult> {
|
async fn update_spam_rules(server: &Server) -> trc::Result<TaskResult> {
|
||||||
let started = Instant::now();
|
let started = Instant::now();
|
||||||
|
let bundled = server.core.spam.spam_rules_url.is_none();
|
||||||
let rules = match fetch_spam_rules(server).await {
|
let rules = match fetch_spam_rules(server).await {
|
||||||
Ok(rules) => rules,
|
Ok(rules) => rules,
|
||||||
Err(err) => {
|
Err(err) => {
|
||||||
@@ -289,29 +292,36 @@ async fn update_spam_rules(server: &Server) -> trc::Result<TaskResult> {
|
|||||||
Elapsed = started.elapsed(),
|
Elapsed = started.elapsed(),
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// inbuxa: so the next start knows these bundled rules are in
|
||||||
|
if bundled {
|
||||||
|
spam_rules::set_applied_version(server.store(), spam_rules::BUNDLED_SPAM_RULES_VERSION)
|
||||||
|
.await?;
|
||||||
|
}
|
||||||
|
|
||||||
Ok(TaskResult::Success(vec![]))
|
Ok(TaskResult::Success(vec![]))
|
||||||
}
|
}
|
||||||
|
|
||||||
async fn fetch_spam_rules(server: &Server) -> Result<Rules, RuleUpdateError> {
|
async fn fetch_spam_rules(server: &Server) -> Result<Rules, RuleUpdateError> {
|
||||||
let Some(rules_url) = server.core.spam.spam_rules_url.as_ref() else {
|
// inbuxa: no URL means the rules bundled with the server
|
||||||
return Err(RuleUpdateError {
|
let bytes = match server.core.spam.spam_rules_url.as_ref() {
|
||||||
typ: TaskFailureType::Permanent,
|
Some(rules_url) => fetch_resource(rules_url, None, Duration::from_secs(60), 1024 * 500)
|
||||||
reason: "Spam rules resource URL not configured".to_string(),
|
|
||||||
});
|
|
||||||
};
|
|
||||||
let rules_json: AHashMap<String, Vec<serde_json::Value>> =
|
|
||||||
fetch_resource(rules_url, None, Duration::from_secs(60), 1024 * 500)
|
|
||||||
.await
|
.await
|
||||||
.map_err(|reason| RuleUpdateError {
|
.map_err(|reason| RuleUpdateError {
|
||||||
typ: TaskFailureType::Temporary,
|
typ: TaskFailureType::Temporary,
|
||||||
reason,
|
reason,
|
||||||
|
}),
|
||||||
|
None => spam_rules::bundled_rules().map_err(|reason| RuleUpdateError {
|
||||||
|
typ: TaskFailureType::Permanent,
|
||||||
|
reason,
|
||||||
|
}),
|
||||||
|
};
|
||||||
|
let rules_json: AHashMap<String, Vec<serde_json::Value>> =
|
||||||
|
bytes.and_then(|bytes| {
|
||||||
|
serde_json::from_slice(&bytes).map_err(|err| RuleUpdateError {
|
||||||
|
typ: TaskFailureType::Permanent,
|
||||||
|
reason: format!("Failed to parse spam rules JSON: {err}"),
|
||||||
})
|
})
|
||||||
.and_then(|bytes| {
|
})?;
|
||||||
serde_json::from_slice(&bytes).map_err(|err| RuleUpdateError {
|
|
||||||
typ: TaskFailureType::Permanent,
|
|
||||||
reason: format!("Failed to parse spam rules JSON: {err}"),
|
|
||||||
})
|
|
||||||
})?;
|
|
||||||
|
|
||||||
let mut rules = Rules::default();
|
let mut rules = Rules::default();
|
||||||
for (object_type, values) in rules_json {
|
for (object_type, values) in rules_json {
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use common::config::smtp::session::Milter;
|
use common::config::smtp::session::Milter;
|
||||||
@@ -25,7 +27,19 @@ impl MilterClient<TcpStream> {
|
|||||||
pub async fn connect(config: &Milter, session_id: u64) -> Result<Self> {
|
pub async fn connect(config: &Milter, session_id: u64) -> Result<Self> {
|
||||||
tokio::time::timeout(config.timeout_command, async {
|
tokio::time::timeout(config.timeout_command, async {
|
||||||
let mut last_err = Error::Disconnected;
|
let mut last_err = Error::Disconnected;
|
||||||
for addr in &config.addrs {
|
// inbuxa: a hostname is resolved here, per connection, rather
|
||||||
|
// than while the settings are built
|
||||||
|
let resolved;
|
||||||
|
let addrs = if config.addrs.is_empty() {
|
||||||
|
resolved = tokio::net::lookup_host((config.hostname.as_str(), config.port))
|
||||||
|
.await
|
||||||
|
.map_err(Error::Io)?
|
||||||
|
.collect::<Vec<_>>();
|
||||||
|
&resolved
|
||||||
|
} else {
|
||||||
|
&config.addrs
|
||||||
|
};
|
||||||
|
for addr in addrs {
|
||||||
match TcpStream::connect(addr).await {
|
match TcpStream::connect(addr).await {
|
||||||
Ok(stream) => {
|
Ok(stream) => {
|
||||||
return Ok(MilterClient {
|
return Ok(MilterClient {
|
||||||
|
|||||||
@@ -48,19 +48,24 @@ pub(crate) async fn pyzor_check(
|
|||||||
// Send message to address. inbuxa: in tests, a fixed table answers
|
// Send message to address. inbuxa: in tests, a fixed table answers
|
||||||
// instead of a public server (test_response).
|
// instead of a public server (test_response).
|
||||||
#[cfg(not(feature = "test_mode"))]
|
#[cfg(not(feature = "test_mode"))]
|
||||||
let response = pyzor_send_message(config.address, config.timeout, &request).await;
|
let response = match tokio::time::timeout(config.timeout, config.address()).await {
|
||||||
|
Ok(Ok(address)) => pyzor_send_message(address, config.timeout, &request).await,
|
||||||
|
Ok(Err(err)) => Err(err),
|
||||||
|
Err(_) => Err(std::io::Error::new(
|
||||||
|
std::io::ErrorKind::TimedOut,
|
||||||
|
"Timed out resolving the Pyzor server",
|
||||||
|
)),
|
||||||
|
};
|
||||||
#[cfg(feature = "test_mode")]
|
#[cfg(feature = "test_mode")]
|
||||||
let response = std::io::Result::Ok(test_response(&request));
|
let response = std::io::Result::Ok(test_response(&request));
|
||||||
|
|
||||||
response
|
response.map(Into::into).map_err(|err| {
|
||||||
.map(Into::into)
|
trc::SpamEvent::PyzorError
|
||||||
.map_err(|err| {
|
.into_err()
|
||||||
trc::SpamEvent::PyzorError
|
.ctx(trc::Key::Url, format!("{}:{}", config.host, config.port))
|
||||||
.into_err()
|
.reason(err)
|
||||||
.ctx(trc::Key::Url, config.address.to_string())
|
.details("Pyzor failed")
|
||||||
.reason(err)
|
})
|
||||||
.details("Pyzor failed")
|
|
||||||
})
|
|
||||||
}
|
}
|
||||||
|
|
||||||
/// inbuxa: the answers tests get, by digest, instead of a public server's,
|
/// inbuxa: the answers tests get, by digest, instead of a public server's,
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::{
|
use crate::{
|
||||||
@@ -19,7 +21,7 @@ use crate::{
|
|||||||
write::SearchIndex,
|
write::SearchIndex,
|
||||||
};
|
};
|
||||||
use mysql_async::{IsolationLevel, TxOpts, Value, prelude::Queryable};
|
use mysql_async::{IsolationLevel, TxOpts, Value, prelude::Queryable};
|
||||||
use nlp::tokenizers::word::WordTokenizer;
|
use nlp::{language::Language, tokenizers::word::WordTokenizer};
|
||||||
use std::fmt::Write;
|
use std::fmt::Write;
|
||||||
|
|
||||||
impl MysqlStore {
|
impl MysqlStore {
|
||||||
@@ -146,6 +148,20 @@ impl MysqlStore {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// inbuxa: InnoDB's default full-text stopword list
|
||||||
|
// (INFORMATION_SCHEMA.INNODB_FT_DEFAULT_STOPWORD) and innodb_ft_min_token_size
|
||||||
|
// default; words outside these are not in a FULLTEXT index.
|
||||||
|
const FT_STOPWORDS: &[&str] = &[
|
||||||
|
"a", "about", "an", "are", "as", "at", "be", "by", "com", "de", "en", "for", "from", "how",
|
||||||
|
"i", "in", "is", "it", "la", "of", "on", "or", "that", "the", "this", "to", "was", "what",
|
||||||
|
"when", "where", "who", "will", "with", "und", "www",
|
||||||
|
];
|
||||||
|
const FT_MIN_TOKEN_SIZE: usize = 3;
|
||||||
|
|
||||||
|
fn is_ft_indexed(word: &str) -> bool {
|
||||||
|
word.chars().count() >= FT_MIN_TOKEN_SIZE && !FT_STOPWORDS.contains(&word)
|
||||||
|
}
|
||||||
|
|
||||||
fn build_filter(query: &mut String, filters: &[SearchFilter]) -> Vec<Value> {
|
fn build_filter(query: &mut String, filters: &[SearchFilter]) -> Vec<Value> {
|
||||||
if filters.is_empty() {
|
if filters.is_empty() {
|
||||||
return Vec::new();
|
return Vec::new();
|
||||||
@@ -171,30 +187,77 @@ fn build_filter(query: &mut String, filters: &[SearchFilter]) -> Vec<Value> {
|
|||||||
|
|
||||||
if field.is_text() && matches!(op, SearchOperator::Equal | SearchOperator::Contains)
|
if field.is_text() && matches!(op, SearchOperator::Equal | SearchOperator::Contains)
|
||||||
{
|
{
|
||||||
let (value, mode) = match (value, op) {
|
let (value, mode, unindexed) = match (value, op) {
|
||||||
(SearchValue::Text { value, .. }, SearchOperator::Equal) => {
|
(SearchValue::Text { value, .. }, SearchOperator::Equal) => (
|
||||||
(Value::Bytes(format!("{value:?}").into_bytes()), "BOOLEAN")
|
Value::Bytes(format!("{value:?}").into_bytes()),
|
||||||
}
|
"BOOLEAN",
|
||||||
(SearchValue::Text { value, .. }, ..) => {
|
Vec::new(),
|
||||||
|
),
|
||||||
|
(SearchValue::Text { value, language }, ..) => {
|
||||||
let mut text_query = String::with_capacity(value.len() + 1);
|
let mut text_query = String::with_capacity(value.len() + 1);
|
||||||
|
let mut unindexed = Vec::new();
|
||||||
|
|
||||||
for item in WordTokenizer::new(value, MAX_TOKEN_LENGTH) {
|
for item in WordTokenizer::new(value, MAX_TOKEN_LENGTH) {
|
||||||
if !text_query.is_empty() {
|
// inbuxa: InnoDB never indexes stopwords ("com",
|
||||||
text_query.push(' ');
|
// "de", "www", ...) or words under
|
||||||
|
// innodb_ft_min_token_size, and a required
|
||||||
|
// (+word) term it has not indexed matches no row,
|
||||||
|
// so "example.com" or "[email protected]" found
|
||||||
|
// nothing. Such words are matched with a
|
||||||
|
// word-boundary REGEXP instead.
|
||||||
|
if is_ft_indexed(&item.word) {
|
||||||
|
if !text_query.is_empty() {
|
||||||
|
text_query.push(' ');
|
||||||
|
}
|
||||||
|
text_query.push('+');
|
||||||
|
text_query.push_str(&item.word);
|
||||||
|
} else {
|
||||||
|
unindexed.push(item.word);
|
||||||
}
|
}
|
||||||
text_query.push('+');
|
|
||||||
text_query.push_str(&item.word);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
(Value::Bytes(text_query.into_bytes()), "BOOLEAN")
|
// For language text (bodies, subjects) the unindexed
|
||||||
|
// words are noise words and only checked when nothing
|
||||||
|
// else is left to match; keyword text (addresses,
|
||||||
|
// contact fields) checks every word, as the other
|
||||||
|
// backends do.
|
||||||
|
if !text_query.is_empty() && !matches!(language, Language::None) {
|
||||||
|
unindexed.clear();
|
||||||
|
}
|
||||||
|
|
||||||
|
(Value::Bytes(text_query.into_bytes()), "BOOLEAN", unindexed)
|
||||||
}
|
}
|
||||||
_ => {
|
_ => {
|
||||||
debug_assert!(false, "Invalid search value for text field");
|
debug_assert!(false, "Invalid search value for text field");
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
let _ = write!(query, "MATCH({}) AGAINST(? IN {mode} MODE)", field.column());
|
if unindexed.is_empty() {
|
||||||
values.push(value);
|
let _ =
|
||||||
|
write!(query, "MATCH({}) AGAINST(? IN {mode} MODE)", field.column());
|
||||||
|
values.push(value);
|
||||||
|
} else {
|
||||||
|
query.push('(');
|
||||||
|
let is_empty = matches!(&value, Value::Bytes(v) if v.is_empty());
|
||||||
|
if !is_empty {
|
||||||
|
let _ = write!(
|
||||||
|
query,
|
||||||
|
"MATCH({}) AGAINST(? IN {mode} MODE) AND ",
|
||||||
|
field.column()
|
||||||
|
);
|
||||||
|
values.push(value);
|
||||||
|
}
|
||||||
|
for (i, word) in unindexed.iter().enumerate() {
|
||||||
|
if i > 0 {
|
||||||
|
query.push_str(" AND ");
|
||||||
|
}
|
||||||
|
let _ = write!(query, "{} REGEXP ?", field.column());
|
||||||
|
values.push(Value::Bytes(
|
||||||
|
format!("(^|[^[:alnum:]]){word}([^[:alnum:]]|$)").into_bytes(),
|
||||||
|
));
|
||||||
|
}
|
||||||
|
query.push(')');
|
||||||
|
}
|
||||||
} else if let SearchValue::KeyValues(kv) = value {
|
} else if let SearchValue::KeyValues(kv) = value {
|
||||||
let (key, value) = kv.iter().next().unwrap();
|
let (key, value) = kv.iter().next().unwrap();
|
||||||
|
|
||||||
|
|||||||
@@ -2,12 +2,17 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::{
|
use crate::{
|
||||||
backend::postgres::{
|
backend::{
|
||||||
DELETE_CHUNK_SIZE, MIN_DELETE_CHUNK_SIZE, PostgresStore, PsqlSearchField, into_error,
|
MAX_TOKEN_LENGTH,
|
||||||
into_pool_error, is_timeout_error,
|
postgres::{
|
||||||
|
DELETE_CHUNK_SIZE, MIN_DELETE_CHUNK_SIZE, PostgresStore, PsqlSearchField, into_error,
|
||||||
|
into_pool_error, is_timeout_error,
|
||||||
|
},
|
||||||
},
|
},
|
||||||
search::{
|
search::{
|
||||||
IndexDocument, SearchComparator, SearchDocumentId, SearchFilter, SearchOperator,
|
IndexDocument, SearchComparator, SearchDocumentId, SearchFilter, SearchOperator,
|
||||||
@@ -15,7 +20,7 @@ use crate::{
|
|||||||
},
|
},
|
||||||
write::SearchIndex,
|
write::SearchIndex,
|
||||||
};
|
};
|
||||||
use nlp::language::Language;
|
use nlp::{language::Language, tokenizers::space::SpaceTokenizer};
|
||||||
use std::fmt::Write;
|
use std::fmt::Write;
|
||||||
use tokio_postgres::{
|
use tokio_postgres::{
|
||||||
IsolationLevel,
|
IsolationLevel,
|
||||||
@@ -43,6 +48,19 @@ impl PostgresStore {
|
|||||||
let primary_keys = index.primary_keys();
|
let primary_keys = index.primary_keys();
|
||||||
let all_fields = index.all_fields();
|
let all_fields = index.all_fields();
|
||||||
let fields = document.fields;
|
let fields = document.fields;
|
||||||
|
// inbuxa: keyword text (addresses, contact fields, ...) is split into
|
||||||
|
// words before it reaches the text parser, see keyword_terms().
|
||||||
|
let keywords = primary_keys
|
||||||
|
.iter()
|
||||||
|
.chain(all_fields)
|
||||||
|
.map(|field| match fields.get(field) {
|
||||||
|
Some(SearchValue::Text {
|
||||||
|
value,
|
||||||
|
language: Language::None,
|
||||||
|
}) if field.is_text() => Some(keyword_terms(value)),
|
||||||
|
_ => None,
|
||||||
|
})
|
||||||
|
.collect::<Vec<_>>();
|
||||||
let mut values = Vec::with_capacity(fields.len() + 2);
|
let mut values = Vec::with_capacity(fields.len() + 2);
|
||||||
let mut query = format!("INSERT INTO {} (", index.psql_table());
|
let mut query = format!("INSERT INTO {} (", index.psql_table());
|
||||||
|
|
||||||
@@ -74,7 +92,20 @@ impl PostgresStore {
|
|||||||
(0, PG_UNSTEMMED_LANG)
|
(0, PG_UNSTEMMED_LANG)
|
||||||
};
|
};
|
||||||
|
|
||||||
if field.is_text() {
|
if let Some(keywords) = &keywords[i] {
|
||||||
|
let _ = write!(&mut query, "to_tsvector('{language}',{value_ref})");
|
||||||
|
values.push(keywords as &(dyn ToSql + Sync));
|
||||||
|
if field.sort_column().is_some() {
|
||||||
|
let value_ref = format!("${}", values.len() + 1);
|
||||||
|
if text_len > 255 {
|
||||||
|
let _ = write!(&mut query, ",left({value_ref},255)");
|
||||||
|
} else {
|
||||||
|
let _ = write!(&mut query, ",{value_ref}");
|
||||||
|
}
|
||||||
|
values.push(value as &(dyn ToSql + Sync));
|
||||||
|
}
|
||||||
|
continue;
|
||||||
|
} else if field.is_text() {
|
||||||
let _ = write!(&mut query, "to_tsvector('{language}',{value_ref})");
|
let _ = write!(&mut query, "to_tsvector('{language}',{value_ref})");
|
||||||
} else if text_len > 512 {
|
} else if text_len > 512 {
|
||||||
query.push_str("left(");
|
query.push_str("left(");
|
||||||
@@ -134,6 +165,7 @@ impl PostgresStore {
|
|||||||
) -> trc::Result<Vec<R>> {
|
) -> trc::Result<Vec<R>> {
|
||||||
let mut query = format!("SELECT {} FROM {}", R::field().column(), index.psql_table());
|
let mut query = format!("SELECT {} FROM {}", R::field().column(), index.psql_table());
|
||||||
let params = self.build_filter(&mut query, filters);
|
let params = self.build_filter(&mut query, filters);
|
||||||
|
let params = params.iter().map(SqlParam::as_sql).collect::<Vec<_>>();
|
||||||
if !sort.is_empty() {
|
if !sort.is_empty() {
|
||||||
build_sort(&mut query, sort);
|
build_sort(&mut query, sort);
|
||||||
}
|
}
|
||||||
@@ -155,6 +187,7 @@ impl PostgresStore {
|
|||||||
let table = filter.index.psql_table();
|
let table = filter.index.psql_table();
|
||||||
let mut where_clause = String::new();
|
let mut where_clause = String::new();
|
||||||
let params = self.build_filter(&mut where_clause, &filter.filters);
|
let params = self.build_filter(&mut where_clause, &filter.filters);
|
||||||
|
let params = params.iter().map(SqlParam::as_sql).collect::<Vec<_>>();
|
||||||
let conn = self.conn_pool.get().await.map_err(into_pool_error)?;
|
let conn = self.conn_pool.get().await.map_err(into_pool_error)?;
|
||||||
let s = conn
|
let s = conn
|
||||||
.prepare_cached(&format!("DELETE FROM {table}{where_clause}"))
|
.prepare_cached(&format!("DELETE FROM {table}{where_clause}"))
|
||||||
@@ -196,7 +229,7 @@ impl PostgresStore {
|
|||||||
&self,
|
&self,
|
||||||
query: &mut String,
|
query: &mut String,
|
||||||
filters: &'x [SearchFilter],
|
filters: &'x [SearchFilter],
|
||||||
) -> Vec<&'x (dyn ToSql + Sync)> {
|
) -> Vec<SqlParam<'x>> {
|
||||||
if filters.is_empty() {
|
if filters.is_empty() {
|
||||||
return Vec::new();
|
return Vec::new();
|
||||||
}
|
}
|
||||||
@@ -237,6 +270,10 @@ impl PostgresStore {
|
|||||||
|
|
||||||
if matches!(language, Language::None) {
|
if matches!(language, Language::None) {
|
||||||
let _ = write!(query, "@@ {method}('{config}', ${value_pos})");
|
let _ = write!(query, "@@ {method}('{config}', ${value_pos})");
|
||||||
|
if let SearchValue::Text { value, .. } = value {
|
||||||
|
values.push(SqlParam::Owned(keyword_terms(value)));
|
||||||
|
continue;
|
||||||
|
}
|
||||||
} else {
|
} else {
|
||||||
let _ = write!(query, "@@ ({method}('{config}', ${value_pos})");
|
let _ = write!(query, "@@ ({method}('{config}', ${value_pos})");
|
||||||
for fallback in [PG_FALLBACK_LANG, PG_UNSTEMMED_LANG] {
|
for fallback in [PG_FALLBACK_LANG, PG_UNSTEMMED_LANG] {
|
||||||
@@ -247,18 +284,18 @@ impl PostgresStore {
|
|||||||
}
|
}
|
||||||
query.push(')');
|
query.push(')');
|
||||||
}
|
}
|
||||||
values.push(value as &(dyn ToSql + Sync));
|
values.push(SqlParam::Ref(value));
|
||||||
} else if let SearchValue::KeyValues(kv) = value {
|
} else if let SearchValue::KeyValues(kv) = value {
|
||||||
query.push_str(field.column());
|
query.push_str(field.column());
|
||||||
query.push(' ');
|
query.push(' ');
|
||||||
|
|
||||||
let (key, value) = kv.iter().next().unwrap();
|
let (key, value) = kv.iter().next().unwrap();
|
||||||
values.push(key as &(dyn ToSql + Sync));
|
values.push(SqlParam::Ref(key));
|
||||||
|
|
||||||
if !value.is_empty() {
|
if !value.is_empty() {
|
||||||
let _ = write!(query, "->> ${value_pos} ");
|
let _ = write!(query, "->> ${value_pos} ");
|
||||||
op.write_pqsql(query, values.len() + 1);
|
op.write_pqsql(query, values.len() + 1);
|
||||||
values.push(value as &(dyn ToSql + Sync));
|
values.push(SqlParam::Ref(value));
|
||||||
} else {
|
} else {
|
||||||
let _ = write!(query, " ? ${value_pos}");
|
let _ = write!(query, " ? ${value_pos}");
|
||||||
}
|
}
|
||||||
@@ -267,7 +304,7 @@ impl PostgresStore {
|
|||||||
query.push(' ');
|
query.push(' ');
|
||||||
|
|
||||||
op.write_pqsql(query, value_pos);
|
op.write_pqsql(query, value_pos);
|
||||||
values.push(value as &(dyn ToSql + Sync));
|
values.push(SqlParam::Ref(value));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
SearchFilter::And | SearchFilter::Or => {
|
SearchFilter::And | SearchFilter::Or => {
|
||||||
@@ -321,6 +358,38 @@ impl PostgresStore {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// inbuxa: PostgreSQL's text parser keeps "[email protected]" (and host names,
|
||||||
|
// URLs, file paths, ...) as a single token, so a search for "user" or
|
||||||
|
// "example.com" never matched an address. Keyword text is split into words the
|
||||||
|
// same way the built-in index splits it (SpaceTokenizer: lowercase runs of
|
||||||
|
// alphanumerics) on both the indexing and the query side, so a full address,
|
||||||
|
// its local part, its domain and the display-name words all match, as they do
|
||||||
|
// on the other backends.
|
||||||
|
pub(crate) fn keyword_terms(value: &str) -> String {
|
||||||
|
let mut terms = String::with_capacity(value.len());
|
||||||
|
for token in SpaceTokenizer::new(value, MAX_TOKEN_LENGTH) {
|
||||||
|
if !terms.is_empty() {
|
||||||
|
terms.push(' ');
|
||||||
|
}
|
||||||
|
terms.push_str(&token);
|
||||||
|
}
|
||||||
|
terms
|
||||||
|
}
|
||||||
|
|
||||||
|
pub(super) enum SqlParam<'x> {
|
||||||
|
Ref(&'x (dyn ToSql + Sync)),
|
||||||
|
Owned(String),
|
||||||
|
}
|
||||||
|
|
||||||
|
impl SqlParam<'_> {
|
||||||
|
fn as_sql(&self) -> &(dyn ToSql + Sync) {
|
||||||
|
match self {
|
||||||
|
SqlParam::Ref(value) => *value,
|
||||||
|
SqlParam::Owned(value) => value,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
fn build_sort(query: &mut String, sort: &[SearchComparator]) {
|
fn build_sort(query: &mut String, sort: &[SearchComparator]) {
|
||||||
query.push_str(" ORDER BY ");
|
query.push_str(" ORDER BY ");
|
||||||
for (i, comparator) in sort.iter().enumerate() {
|
for (i, comparator) in sort.iter().enumerate() {
|
||||||
|
|||||||
@@ -10,8 +10,9 @@
|
|||||||
|
|
||||||
// inbuxa: 637 to 641 are the fork's SCIM events (SCIM-54); 642 is
|
// inbuxa: 637 to 641 are the fork's SCIM events (SCIM-54); 642 is
|
||||||
// auth.legacy-protocol-refused (legacy-protocols LP-6); 643 is
|
// auth.legacy-protocol-refused (legacy-protocols LP-6); 643 is
|
||||||
// security.legacy-protocols-changed (LP-8)
|
// security.legacy-protocols-changed (LP-8); 644 to 646 are the cluster
|
||||||
pub const TOTAL_EVENT_COUNT: usize = 644;
|
// coordinator's connection events
|
||||||
|
pub const TOTAL_EVENT_COUNT: usize = 647;
|
||||||
pub const TOTAL_METRIC_COUNT: usize = 369;
|
pub const TOTAL_METRIC_COUNT: usize = 369;
|
||||||
|
|
||||||
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)]
|
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)]
|
||||||
@@ -150,6 +151,10 @@ pub enum ClusterEvent {
|
|||||||
MessageSkipped = 47,
|
MessageSkipped = 47,
|
||||||
MessageInvalid = 49,
|
MessageInvalid = 49,
|
||||||
NodeIdRenewed = 275,
|
NodeIdRenewed = 275,
|
||||||
|
// inbuxa: the coordinator's connection
|
||||||
|
CoordinatorConnected = 644,
|
||||||
|
CoordinatorDisconnected = 645,
|
||||||
|
CoordinatorError = 646,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)]
|
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash)]
|
||||||
|
|||||||
@@ -81,6 +81,10 @@ impl EventType {
|
|||||||
b"cluster.message-skipped" => EventType::Cluster(ClusterEvent::MessageSkipped),
|
b"cluster.message-skipped" => EventType::Cluster(ClusterEvent::MessageSkipped),
|
||||||
b"cluster.message-invalid" => EventType::Cluster(ClusterEvent::MessageInvalid),
|
b"cluster.message-invalid" => EventType::Cluster(ClusterEvent::MessageInvalid),
|
||||||
b"cluster.node-id-renewed" => EventType::Cluster(ClusterEvent::NodeIdRenewed),
|
b"cluster.node-id-renewed" => EventType::Cluster(ClusterEvent::NodeIdRenewed),
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
b"cluster.coordinator-connected" => EventType::Cluster(ClusterEvent::CoordinatorConnected),
|
||||||
|
b"cluster.coordinator-disconnected" => EventType::Cluster(ClusterEvent::CoordinatorDisconnected),
|
||||||
|
b"cluster.coordinator-error" => EventType::Cluster(ClusterEvent::CoordinatorError),
|
||||||
b"dane.authentication-success" => EventType::Dane(DaneEvent::AuthenticationSuccess),
|
b"dane.authentication-success" => EventType::Dane(DaneEvent::AuthenticationSuccess),
|
||||||
b"dane.authentication-failure" => EventType::Dane(DaneEvent::AuthenticationFailure),
|
b"dane.authentication-failure" => EventType::Dane(DaneEvent::AuthenticationFailure),
|
||||||
b"dane.no-certificates-found" => EventType::Dane(DaneEvent::NoCertificatesFound),
|
b"dane.no-certificates-found" => EventType::Dane(DaneEvent::NoCertificatesFound),
|
||||||
@@ -742,6 +746,14 @@ impl EventType {
|
|||||||
EventType::Cluster(ClusterEvent::MessageSkipped) => "cluster.message-skipped",
|
EventType::Cluster(ClusterEvent::MessageSkipped) => "cluster.message-skipped",
|
||||||
EventType::Cluster(ClusterEvent::MessageInvalid) => "cluster.message-invalid",
|
EventType::Cluster(ClusterEvent::MessageInvalid) => "cluster.message-invalid",
|
||||||
EventType::Cluster(ClusterEvent::NodeIdRenewed) => "cluster.node-id-renewed",
|
EventType::Cluster(ClusterEvent::NodeIdRenewed) => "cluster.node-id-renewed",
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorConnected) => {
|
||||||
|
"cluster.coordinator-connected"
|
||||||
|
}
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorDisconnected) => {
|
||||||
|
"cluster.coordinator-disconnected"
|
||||||
|
}
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorError) => "cluster.coordinator-error",
|
||||||
EventType::Dane(DaneEvent::AuthenticationSuccess) => "dane.authentication-success",
|
EventType::Dane(DaneEvent::AuthenticationSuccess) => "dane.authentication-success",
|
||||||
EventType::Dane(DaneEvent::AuthenticationFailure) => "dane.authentication-failure",
|
EventType::Dane(DaneEvent::AuthenticationFailure) => "dane.authentication-failure",
|
||||||
EventType::Dane(DaneEvent::NoCertificatesFound) => "dane.no-certificates-found",
|
EventType::Dane(DaneEvent::NoCertificatesFound) => "dane.no-certificates-found",
|
||||||
@@ -1524,6 +1536,10 @@ impl EventType {
|
|||||||
EventType::Cluster(ClusterEvent::MessageSkipped) => 47,
|
EventType::Cluster(ClusterEvent::MessageSkipped) => 47,
|
||||||
EventType::Cluster(ClusterEvent::MessageInvalid) => 49,
|
EventType::Cluster(ClusterEvent::MessageInvalid) => 49,
|
||||||
EventType::Cluster(ClusterEvent::NodeIdRenewed) => 275,
|
EventType::Cluster(ClusterEvent::NodeIdRenewed) => 275,
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorConnected) => 644,
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorDisconnected) => 645,
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorError) => 646,
|
||||||
EventType::Dane(DaneEvent::AuthenticationSuccess) => 67,
|
EventType::Dane(DaneEvent::AuthenticationSuccess) => 67,
|
||||||
EventType::Dane(DaneEvent::AuthenticationFailure) => 66,
|
EventType::Dane(DaneEvent::AuthenticationFailure) => 66,
|
||||||
EventType::Dane(DaneEvent::NoCertificatesFound) => 69,
|
EventType::Dane(DaneEvent::NoCertificatesFound) => 69,
|
||||||
@@ -2176,6 +2192,10 @@ impl EventType {
|
|||||||
47 => Some(EventType::Cluster(ClusterEvent::MessageSkipped)),
|
47 => Some(EventType::Cluster(ClusterEvent::MessageSkipped)),
|
||||||
49 => Some(EventType::Cluster(ClusterEvent::MessageInvalid)),
|
49 => Some(EventType::Cluster(ClusterEvent::MessageInvalid)),
|
||||||
275 => Some(EventType::Cluster(ClusterEvent::NodeIdRenewed)),
|
275 => Some(EventType::Cluster(ClusterEvent::NodeIdRenewed)),
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
644 => Some(EventType::Cluster(ClusterEvent::CoordinatorConnected)),
|
||||||
|
645 => Some(EventType::Cluster(ClusterEvent::CoordinatorDisconnected)),
|
||||||
|
646 => Some(EventType::Cluster(ClusterEvent::CoordinatorError)),
|
||||||
67 => Some(EventType::Dane(DaneEvent::AuthenticationSuccess)),
|
67 => Some(EventType::Dane(DaneEvent::AuthenticationSuccess)),
|
||||||
66 => Some(EventType::Dane(DaneEvent::AuthenticationFailure)),
|
66 => Some(EventType::Dane(DaneEvent::AuthenticationFailure)),
|
||||||
69 => Some(EventType::Dane(DaneEvent::NoCertificatesFound)),
|
69 => Some(EventType::Dane(DaneEvent::NoCertificatesFound)),
|
||||||
@@ -3114,6 +3134,10 @@ impl EventType {
|
|||||||
EventType::Auth(AuthEvent::TooManyAttempts) => Level::Warn,
|
EventType::Auth(AuthEvent::TooManyAttempts) => Level::Warn,
|
||||||
EventType::Calendar(CalendarEvent::AlarmFailed) => Level::Warn,
|
EventType::Calendar(CalendarEvent::AlarmFailed) => Level::Warn,
|
||||||
EventType::Cluster(ClusterEvent::SubscriberDisconnected) => Level::Warn,
|
EventType::Cluster(ClusterEvent::SubscriberDisconnected) => Level::Warn,
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorConnected) => Level::Info,
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorDisconnected) => Level::Warn,
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorError) => Level::Warn,
|
||||||
EventType::Delivery(DeliveryEvent::MissingOutboundHostname) => Level::Warn,
|
EventType::Delivery(DeliveryEvent::MissingOutboundHostname) => Level::Warn,
|
||||||
EventType::Delivery(DeliveryEvent::ConcurrencyLimitExceeded) => Level::Warn,
|
EventType::Delivery(DeliveryEvent::ConcurrencyLimitExceeded) => Level::Warn,
|
||||||
EventType::Delivery(DeliveryEvent::RateLimitExceeded) => Level::Warn,
|
EventType::Delivery(DeliveryEvent::RateLimitExceeded) => Level::Warn,
|
||||||
@@ -3244,6 +3268,10 @@ impl EventType {
|
|||||||
EventType::Cluster(ClusterEvent::MessageSkipped) => "PubSub message skipped",
|
EventType::Cluster(ClusterEvent::MessageSkipped) => "PubSub message skipped",
|
||||||
EventType::Cluster(ClusterEvent::MessageInvalid) => "Invalid PubSub message",
|
EventType::Cluster(ClusterEvent::MessageInvalid) => "Invalid PubSub message",
|
||||||
EventType::Cluster(ClusterEvent::NodeIdRenewed) => "Node ID renewed",
|
EventType::Cluster(ClusterEvent::NodeIdRenewed) => "Node ID renewed",
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorConnected) => "Coordinator connected",
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorDisconnected) => "Coordinator unavailable",
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorError) => "Coordinator error",
|
||||||
EventType::Dane(DaneEvent::AuthenticationSuccess) => "DANE authentication successful",
|
EventType::Dane(DaneEvent::AuthenticationSuccess) => "DANE authentication successful",
|
||||||
EventType::Dane(DaneEvent::AuthenticationFailure) => "DANE authentication failed",
|
EventType::Dane(DaneEvent::AuthenticationFailure) => "DANE authentication failed",
|
||||||
EventType::Dane(DaneEvent::NoCertificatesFound) => "No certificates found for DANE",
|
EventType::Dane(DaneEvent::NoCertificatesFound) => "No certificates found for DANE",
|
||||||
@@ -4322,6 +4350,10 @@ impl EventType {
|
|||||||
EventType::Cluster(ClusterEvent::MessageSkipped),
|
EventType::Cluster(ClusterEvent::MessageSkipped),
|
||||||
EventType::Cluster(ClusterEvent::MessageInvalid),
|
EventType::Cluster(ClusterEvent::MessageInvalid),
|
||||||
EventType::Cluster(ClusterEvent::NodeIdRenewed),
|
EventType::Cluster(ClusterEvent::NodeIdRenewed),
|
||||||
|
// inbuxa: coordinator connection
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorConnected),
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorDisconnected),
|
||||||
|
EventType::Cluster(ClusterEvent::CoordinatorError),
|
||||||
EventType::Dane(DaneEvent::AuthenticationSuccess),
|
EventType::Dane(DaneEvent::AuthenticationSuccess),
|
||||||
EventType::Dane(DaneEvent::AuthenticationFailure),
|
EventType::Dane(DaneEvent::AuthenticationFailure),
|
||||||
EventType::Dane(DaneEvent::NoCertificatesFound),
|
EventType::Dane(DaneEvent::NoCertificatesFound),
|
||||||
|
|||||||
@@ -81,7 +81,7 @@ fn legacy_setting(name: &str, is_set: impl Fn(&str) -> bool) -> Option<String> {
|
|||||||
#[macro_export]
|
#[macro_export]
|
||||||
macro_rules! brand_version {
|
macro_rules! brand_version {
|
||||||
() => {
|
() => {
|
||||||
"2026.9.24"
|
"2026.9.24.3"
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -102,7 +102,10 @@ Permissions: `sysSpamLlmGet`, `sysSpamLlmUpdate`.
|
|||||||
- **Tags and scores.** The classifier's tags are ordinary spam tags, scored
|
- **Tags and scores.** The classifier's tags are ordinary spam tags, scored
|
||||||
by `x:SpamTag` entries like every other tag: `Score` (a number), `Discard`
|
by `x:SpamTag` entries like every other tag: `Score` (a number), `Discard`
|
||||||
or `Reject`. The documented defaults are `LLM_UNSOLICITED_HIGH` 3.0 and
|
or `Reject`. The documented defaults are `LLM_UNSOLICITED_HIGH` 3.0 and
|
||||||
`LLM_LEGITIMATE_HIGH` −3.0. A tag with no entry scores 0.
|
`LLM_LEGITIMATE_HIGH` −3.0. A tag with no entry scores 0. The server ships
|
||||||
|
those entries in its bundled spam rules (`resources/spam-filter/`), loaded
|
||||||
|
on first boot and again when the bundled version changes, so an install
|
||||||
|
that predates them gains them on upgrade (added 2026-09-23).
|
||||||
- **`interactAi`** permission ("Interact with AI models"): lets an account's
|
- **`interactAi`** permission ("Interact with AI models"): lets an account's
|
||||||
own Sieve scripts call `llm_prompt`. This repository's default roles give it
|
own Sieve scripts call `llm_prompt`. This repository's default roles give it
|
||||||
to users, tenant administrators and superusers
|
to users, tenant administrators and superusers
|
||||||
|
|||||||
@@ -212,10 +212,15 @@ unchanged.
|
|||||||
- **MON-16.** With `indexTelemetry` on, storing a trace schedules an
|
- **MON-16.** With `indexTelemetry` on, storing a trace schedules an
|
||||||
`IndexTrace` task. The task builds one document for `SearchIndex::Tracing`
|
`IndexTrace` task. The task builds one document for `SearchIndex::Tracing`
|
||||||
with the fields named in `indexTracingFields`:
|
with the fields named in `indexTracingFields`:
|
||||||
- `eventType`: every event type in the trace;
|
- `eventType`: the trace's opening event, as its numeric id;
|
||||||
- `queueId`: every `queueId` value;
|
- `queueId`: the first `queueId` value, as an integer;
|
||||||
- `keywords`: every address in `from` and `to`, each address's domain, every
|
- `keywords`: every address in `from` and `to`, each address's domain, every
|
||||||
`domain`, `hostname`, `remoteIp`, `messageId` and `accountName` value.
|
`domain`, `hostname`, `remoteIp`, `messageId` and `accountName` value,
|
||||||
|
and every `queueId` value.
|
||||||
|
The event type and queue id are single integer columns on every search
|
||||||
|
backend (BIGINT on PostgreSQL and MySQL), so the `queueId` filter matches
|
||||||
|
the column or any queue id in the keywords, and a session that queued
|
||||||
|
several messages is found by each of them.
|
||||||
So searching `example.org` finds every trace to or from that domain, as the
|
So searching `example.org` finds every trace to or from that domain, as the
|
||||||
upstream suite expects. With `indexTelemetry` off nothing is indexed, and
|
upstream suite expects. With `indexTelemetry` off nothing is indexed, and
|
||||||
the `text` and `queueId` filters are refused (see "Interfaces").
|
the `text` and `queueId` filters are refused (see "Interfaces").
|
||||||
|
|||||||
Binary file not shown.
@@ -1 +1 @@
|
|||||||
rWqJwNJkqgKsbC1eqcEmmIAMtJPmnlDlThR2ZtW_N1c
|
XFI3xuKC_rH1KZyaVBF0uTIiRDXRqyYboijquiGz2eg
|
||||||
@@ -0,0 +1,32 @@
|
|||||||
|
# Bundled spam filter rules
|
||||||
|
|
||||||
|
`spam-filter-rules.json.gz` is the published rules file of
|
||||||
|
[spam-filter](https://github.com/stalwartlabs/spam-filter) **v3.0.2**,
|
||||||
|
unmodified. The server embeds it (`crates/common/src/manager/spam_rules.rs`)
|
||||||
|
and loads it whenever no other rules source is configured, so a release
|
||||||
|
scores mail with the rules it was tested with, offline and with nothing to
|
||||||
|
fetch. The rules URL setting stays an operator override.
|
||||||
|
|
||||||
|
The rules are dual-licensed MIT or Apache-2.0, Copyright (C) 2024, Stalwart
|
||||||
|
Labs LLC; the fork takes them under MIT, with the notice in `THIRD-PARTY.md`.
|
||||||
|
|
||||||
|
They include the scores for the AI classifier's tags (`LLM_*`, 3.0 for the
|
||||||
|
high-confidence spam categories, −3.0 for legitimate), which match
|
||||||
|
`docs/spec/features/ai-spam-classification.md`.
|
||||||
|
|
||||||
|
## Updating
|
||||||
|
|
||||||
|
The `upstream-watch` workflow opens an issue when spam-filter publishes a
|
||||||
|
newer release. To take it:
|
||||||
|
|
||||||
|
1. Download `spam-filter-rules.json.gz` from that release, pinned by tag
|
||||||
|
(`releases/download/vX.Y.Z/…`, not `latest`), over this file.
|
||||||
|
2. Set `BUNDLED_SPAM_RULES_VERSION` in `spam_rules.rs` and the version in
|
||||||
|
this README and in `THIRD-PARTY.md`.
|
||||||
|
3. Run the antispam test (`STORE=RocksDb RUST_MIN_STACK=16777216 cargo test
|
||||||
|
-p tests --lib -- smtp::inbound::antispam::antispam --exact`) and fix
|
||||||
|
expectations the new rules change, knowingly.
|
||||||
|
|
||||||
|
On the next start each server loads the new version once. Loading only adds
|
||||||
|
rules and tags that are missing; it never changes an existing one, so an
|
||||||
|
operator's own adjustments survive.
|
||||||
@@ -0,0 +1,145 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! A node that starts while its NATS coordinator is down joins the cluster
|
||||||
|
//! once NATS comes up, without a restart, and reports the coordinator's
|
||||||
|
//! connection on `/healthz/cluster` as it goes and comes back.
|
||||||
|
|
||||||
|
use crate::utils::server::TestServerBuilder;
|
||||||
|
use coordinator::Coordinator;
|
||||||
|
use registry::{
|
||||||
|
schema::{
|
||||||
|
enums::NetworkListenerProtocol,
|
||||||
|
structs::{Coordinator as CoordinatorSetting, NatsCoordinator},
|
||||||
|
},
|
||||||
|
types::map::Map,
|
||||||
|
};
|
||||||
|
use serde_json::{Value, json};
|
||||||
|
use std::time::{Duration, Instant};
|
||||||
|
use testcontainers::{
|
||||||
|
GenericImage, ImageExt, core::IntoContainerPort, core::WaitFor, runners::AsyncRunner,
|
||||||
|
};
|
||||||
|
|
||||||
|
const HTTP_PORT: u16 = 11_310;
|
||||||
|
const TOPIC: &str = "inbuxa-coordinator-test";
|
||||||
|
|
||||||
|
#[tokio::test(flavor = "multi_thread")]
|
||||||
|
pub async fn coordinator_reconnect_tests() {
|
||||||
|
println!("Running coordinator reconnect tests...");
|
||||||
|
|
||||||
|
// A port with no NATS server behind it, yet
|
||||||
|
let nats_port = std::net::TcpListener::bind("127.0.0.1:0")
|
||||||
|
.unwrap()
|
||||||
|
.local_addr()
|
||||||
|
.unwrap()
|
||||||
|
.port();
|
||||||
|
let config = NatsCoordinator {
|
||||||
|
addresses: Map::new(vec![format!("127.0.0.1:{nats_port}")]),
|
||||||
|
use_tls: false,
|
||||||
|
timeout_connection: 1_000u64.into(),
|
||||||
|
..Default::default()
|
||||||
|
};
|
||||||
|
|
||||||
|
// 1. The node starts, without a build error, while NATS is down, and
|
||||||
|
// says so
|
||||||
|
let test = TestServerBuilder::new("coordinator_reconnect_tests")
|
||||||
|
.await
|
||||||
|
.with_object(CoordinatorSetting::Nats(config.clone()))
|
||||||
|
.await
|
||||||
|
.with_listener(NetworkListenerProtocol::Http, "http", HTTP_PORT, true)
|
||||||
|
.await
|
||||||
|
.build()
|
||||||
|
.await;
|
||||||
|
let coordinator = test.server.core.storage.coordinator.clone();
|
||||||
|
assert!(
|
||||||
|
coordinator.is_enabled(),
|
||||||
|
"a coordinator, though not connected"
|
||||||
|
);
|
||||||
|
assert_eq!(coordinator.is_connected(), Some(false));
|
||||||
|
assert_eq!(
|
||||||
|
cluster_health().await,
|
||||||
|
(503, json!({"coordinator": "disconnected"}))
|
||||||
|
);
|
||||||
|
|
||||||
|
// A subscription made now, as the broadcast subscriber makes it at
|
||||||
|
// startup, has to work once NATS is up
|
||||||
|
let mut stream = coordinator.subscribe(TOPIC).await.unwrap();
|
||||||
|
|
||||||
|
// 2. NATS comes up: the node connects on its own
|
||||||
|
let nats = GenericImage::new("nats", "latest")
|
||||||
|
.with_wait_for(WaitFor::message_on_stderr("Server is ready"))
|
||||||
|
.with_mapped_port(nats_port, 4222.tcp())
|
||||||
|
.start()
|
||||||
|
.await
|
||||||
|
.expect("Failed to start NATS container");
|
||||||
|
wait_for_health(200, "connected").await;
|
||||||
|
let other_node = coordinator::backend::nats::NatsPubSub::open(config.clone())
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
wait_until_connected(&other_node).await;
|
||||||
|
round_trip(&other_node, &mut stream, b"after startup").await;
|
||||||
|
|
||||||
|
// 3. NATS goes away: the node reports it; and it comes back: the node
|
||||||
|
// reconnects and the same subscription carries on
|
||||||
|
nats.stop().await.unwrap();
|
||||||
|
wait_for_health(503, "disconnected").await;
|
||||||
|
nats.start().await.unwrap();
|
||||||
|
wait_for_health(200, "connected").await;
|
||||||
|
wait_until_connected(&other_node).await;
|
||||||
|
round_trip(&other_node, &mut stream, b"after reconnect").await;
|
||||||
|
|
||||||
|
drop(nats);
|
||||||
|
if test.is_reset() {
|
||||||
|
test.temp_dir.delete();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn cluster_health() -> (u16, Value) {
|
||||||
|
let response = reqwest::Client::builder()
|
||||||
|
.danger_accept_invalid_certs(true)
|
||||||
|
.timeout(Duration::from_secs(5))
|
||||||
|
.build()
|
||||||
|
.unwrap()
|
||||||
|
.get(format!("https://127.0.0.1:{HTTP_PORT}/healthz/cluster"))
|
||||||
|
.send()
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
let status = response.status().as_u16();
|
||||||
|
(status, response.json().await.unwrap())
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn wait_for_health(status: u16, state: &str) {
|
||||||
|
let started = Instant::now();
|
||||||
|
loop {
|
||||||
|
let health = cluster_health().await;
|
||||||
|
if health == (status, json!({"coordinator": state})) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
assert!(
|
||||||
|
started.elapsed() < Duration::from_secs(30),
|
||||||
|
"expected {status} {state}, still {health:?}"
|
||||||
|
);
|
||||||
|
tokio::time::sleep(Duration::from_millis(250)).await;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn wait_until_connected(coordinator: &Coordinator) {
|
||||||
|
let started = Instant::now();
|
||||||
|
while coordinator.is_connected() != Some(true) {
|
||||||
|
assert!(started.elapsed() < Duration::from_secs(30), "not connected");
|
||||||
|
tokio::time::sleep(Duration::from_millis(100)).await;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Another node publishes; this one's subscription receives it.
|
||||||
|
async fn round_trip(from: &Coordinator, stream: &mut coordinator::PubSubStream, payload: &[u8]) {
|
||||||
|
from.publish(TOPIC, payload.to_vec()).await.unwrap();
|
||||||
|
let message = tokio::time::timeout(Duration::from_secs(10), stream.next())
|
||||||
|
.await
|
||||||
|
.expect("no message within 10 seconds")
|
||||||
|
.expect("subscription ended");
|
||||||
|
assert_eq!(message.payload(), payload);
|
||||||
|
}
|
||||||
@@ -2,7 +2,11 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
pub mod broadcast;
|
pub mod broadcast;
|
||||||
|
#[cfg(feature = "nats")]
|
||||||
|
pub mod coordinator; // inbuxa: coordinator reconnects
|
||||||
pub mod stress;
|
pub mod stress;
|
||||||
|
|||||||
@@ -86,19 +86,10 @@ async fn antispam() {
|
|||||||
.registry_create_object(SpamSettings {
|
.registry_create_object(SpamSettings {
|
||||||
score_spam: Float::new(5.0),
|
score_spam: Float::new(5.0),
|
||||||
// inbuxa: the rules carry the scores the expectations are written
|
// inbuxa: the rules carry the scores the expectations are written
|
||||||
// against, so they're pinned (spam-filter v3.0.2, beside the test
|
// against. Unset, the server uses the rules bundled with it
|
||||||
// cases) rather than read from a developer's own checkout, which
|
// (resources/spam-filter/), the path production takes;
|
||||||
// left every score at zero. SPAM_RULES_URL still overrides.
|
// SPAM_RULES_URL tests another set.
|
||||||
spam_filter_rules_url: std::env::var("SPAM_RULES_URL")
|
spam_filter_rules_url: std::env::var("SPAM_RULES_URL").ok(),
|
||||||
.unwrap_or_else(|_| {
|
|
||||||
concat!(
|
|
||||||
"file://",
|
|
||||||
env!("CARGO_MANIFEST_DIR"),
|
|
||||||
"/resources/smtp/antispam/spam-filter-rules.json.gz"
|
|
||||||
)
|
|
||||||
.to_string()
|
|
||||||
})
|
|
||||||
.into(),
|
|
||||||
..Default::default()
|
..Default::default()
|
||||||
})
|
})
|
||||||
.await;
|
.await;
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::{
|
use crate::{
|
||||||
@@ -75,7 +77,7 @@ async fn milter_session() {
|
|||||||
else_: "true".into(),
|
else_: "true".into(),
|
||||||
..Default::default()
|
..Default::default()
|
||||||
},
|
},
|
||||||
hostname: "127.0.0.1".into(),
|
hostname: "localhost".into(), // inbuxa: resolved when the session connects
|
||||||
port: 9332,
|
port: 9332,
|
||||||
use_tls: false,
|
use_tls: false,
|
||||||
stages: Map::new(vec![MtaStage::Data]),
|
stages: Map::new(vec![MtaStage::Data]),
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::utils::{
|
use crate::utils::{
|
||||||
@@ -9,14 +11,22 @@ use crate::utils::{
|
|||||||
server::TestServer,
|
server::TestServer,
|
||||||
temp_dir::TempDir,
|
temp_dir::TempDir,
|
||||||
};
|
};
|
||||||
use ::registry::schema::enums::CompressionAlgo;
|
use ::registry::schema::{
|
||||||
|
enums::{CompressionAlgo, TaskStoreMaintenanceType},
|
||||||
|
prelude::ObjectType,
|
||||||
|
structs::Task,
|
||||||
|
};
|
||||||
use ahash::AHashSet;
|
use ahash::AHashSet;
|
||||||
use common::{DATABASE_SCHEMA_VERSION, manager::backup::BackupParams};
|
use common::{
|
||||||
|
DATABASE_SCHEMA_VERSION,
|
||||||
|
manager::{SPAM_CLASSIFIER_KEY, SPAM_TRAINER_KEY, backup::BackupParams},
|
||||||
|
};
|
||||||
use store::{
|
use store::{
|
||||||
rand,
|
rand,
|
||||||
write::{
|
write::{
|
||||||
AnyClass, AnyKey, BatchBuilder, BlobLink, BlobOp, Operation, QueueClass, QueueEvent,
|
AnyClass, AnyKey, BatchBuilder, BlobLink, BlobOp, Operation, QueueClass, QueueEvent,
|
||||||
RegistryClass, ValueClass, key::KeySerializer,
|
RegistryClass, TaskQueueClass, ValueClass,
|
||||||
|
key::{DeserializeBigEndian, KeySerializer},
|
||||||
},
|
},
|
||||||
*,
|
*,
|
||||||
};
|
};
|
||||||
@@ -167,6 +177,50 @@ pub async fn test(test: &TestServer) {
|
|||||||
}
|
}
|
||||||
db.write(batch.build_all()).await.unwrap();
|
db.write(batch.build_all()).await.unwrap();
|
||||||
|
|
||||||
|
// inbuxa: registry objects kept outside the registry subspace (archived
|
||||||
|
// items for undelete, spam training samples, directory entries) and the
|
||||||
|
// fork's own subspace. Exports used to leave the first two behind.
|
||||||
|
println!("Creating archived items, spam samples and fork data...");
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
for item_id in [1u64, 2, 3] {
|
||||||
|
for object in [
|
||||||
|
ObjectType::ArchivedItem,
|
||||||
|
ObjectType::SpamTrainingSample,
|
||||||
|
ObjectType::Account,
|
||||||
|
] {
|
||||||
|
batch.set(
|
||||||
|
ValueClass::Registry(RegistryClass::Item {
|
||||||
|
object_id: object as u16,
|
||||||
|
item_id,
|
||||||
|
}),
|
||||||
|
random_bytes(item_id as usize * 64),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
batch.set(
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace: SUBSPACE_INBUXA,
|
||||||
|
key: [b'U', b'x']
|
||||||
|
.into_iter()
|
||||||
|
.chain(item_id.to_be_bytes())
|
||||||
|
.collect(),
|
||||||
|
}),
|
||||||
|
random_bytes(32),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
db.write(batch.build_all()).await.unwrap();
|
||||||
|
|
||||||
|
// inbuxa: the trained spam classifier lives in blobs with fixed names
|
||||||
|
let mut named_blobs = Vec::new();
|
||||||
|
for key in [SPAM_CLASSIFIER_KEY, SPAM_TRAINER_KEY] {
|
||||||
|
let data = random_bytes(4096);
|
||||||
|
test.server
|
||||||
|
.blob_store()
|
||||||
|
.put_blob(key, &data, CompressionAlgo::Lz4)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
named_blobs.push((key, data));
|
||||||
|
}
|
||||||
|
|
||||||
// Create directory data
|
// Create directory data
|
||||||
println!("Creating directory data...");
|
println!("Creating directory data...");
|
||||||
let mut batch = BatchBuilder::new();
|
let mut batch = BatchBuilder::new();
|
||||||
@@ -185,6 +239,17 @@ pub async fn test(test: &TestServer) {
|
|||||||
println!("Calculating store hash...");
|
println!("Calculating store hash...");
|
||||||
let snapshot = Snapshot::new(&db).await;
|
let snapshot = Snapshot::new(&db).await;
|
||||||
assert!(!snapshot.keys.is_empty(), "Store hash counts are empty",);
|
assert!(!snapshot.keys.is_empty(), "Store hash counts are empty",);
|
||||||
|
for subspace in [
|
||||||
|
SUBSPACE_DELETED_ITEMS,
|
||||||
|
SUBSPACE_SPAM_SAMPLES,
|
||||||
|
SUBSPACE_INBUXA,
|
||||||
|
] {
|
||||||
|
assert!(
|
||||||
|
snapshot.keys.iter().any(|k| k.subspace == subspace),
|
||||||
|
"No test data in subspace {}",
|
||||||
|
char::from(subspace)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
// Export store
|
// Export store
|
||||||
println!("Exporting store...");
|
println!("Exporting store...");
|
||||||
@@ -210,22 +275,188 @@ pub async fn test(test: &TestServer) {
|
|||||||
.finalize(),
|
.finalize(),
|
||||||
);
|
);
|
||||||
db.write(batch.build_all()).await.unwrap();
|
db.write(batch.build_all()).await.unwrap();
|
||||||
test.server.core.restore(temp_dir.path.clone()).await;
|
for (key, _) in &named_blobs {
|
||||||
|
test.server.blob_store().delete_blob(key).await.unwrap();
|
||||||
|
}
|
||||||
|
let imported = test.server.core.restore(temp_dir.path.clone()).await;
|
||||||
let mut batch = BatchBuilder::new();
|
let mut batch = BatchBuilder::new();
|
||||||
batch.clear(ValueClass::NodeId(0));
|
batch.clear(ValueClass::NodeId(0));
|
||||||
db.write(batch.build_all()).await.unwrap();
|
db.write(batch.build_all()).await.unwrap();
|
||||||
|
for subspace in [
|
||||||
|
SUBSPACE_DELETED_ITEMS,
|
||||||
|
SUBSPACE_SPAM_SAMPLES,
|
||||||
|
SUBSPACE_INBUXA,
|
||||||
|
] {
|
||||||
|
assert!(
|
||||||
|
imported.contains(&subspace),
|
||||||
|
"Subspace {} was not exported",
|
||||||
|
char::from(subspace)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
// Verify hash
|
// Verify hash
|
||||||
print!("Verifying store hash...");
|
print!("Verifying store hash...");
|
||||||
snapshot.assert_is_eq(&Snapshot::new(&db).await);
|
snapshot.assert_is_eq(&Snapshot::new(&db).await);
|
||||||
|
assert_named_blobs(test.server.blob_store(), &named_blobs).await;
|
||||||
println!(" GREAT SUCCESS!");
|
println!(" GREAT SUCCESS!");
|
||||||
|
|
||||||
|
// inbuxa: import the same export into a fresh store of another backend,
|
||||||
|
// the way a move from one database to another does it
|
||||||
|
#[cfg(all(feature = "rocks", feature = "sqlite"))]
|
||||||
|
cross_backend(test, &db, &temp_dir, &named_blobs).await;
|
||||||
|
|
||||||
// Destroy store
|
// Destroy store
|
||||||
|
for (key, _) in &named_blobs {
|
||||||
|
test.server.blob_store().delete_blob(key).await.unwrap();
|
||||||
|
}
|
||||||
store_destroy(&db).await;
|
store_destroy(&db).await;
|
||||||
store_assert_is_empty(&db, db.clone().into(), true).await;
|
store_assert_is_empty(&db, db.clone().into(), true).await;
|
||||||
temp_dir.delete();
|
temp_dir.delete();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(all(feature = "rocks", feature = "sqlite"))]
|
||||||
|
async fn cross_backend(
|
||||||
|
test: &TestServer,
|
||||||
|
source: &Store,
|
||||||
|
export: &TempDir,
|
||||||
|
named_blobs: &[(&[u8], Vec<u8>)],
|
||||||
|
) {
|
||||||
|
let source_type = std::env::var("STORE").unwrap();
|
||||||
|
let target_type = if source_type.eq_ignore_ascii_case("sqlite") {
|
||||||
|
"RocksDb"
|
||||||
|
} else {
|
||||||
|
"Sqlite"
|
||||||
|
};
|
||||||
|
println!("Importing the export into a fresh {target_type} store...");
|
||||||
|
|
||||||
|
let target_dir = TempDir::new("art_vandelay_cross_backend", true);
|
||||||
|
let target = Store::build(
|
||||||
|
crate::utils::storage::build_data_store(target_type, &target_dir.path.to_string_lossy())
|
||||||
|
.await,
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
target.create_tables().await.unwrap();
|
||||||
|
store_destroy(&target).await;
|
||||||
|
|
||||||
|
let mut core = test.server.core.as_ref().clone();
|
||||||
|
core.storage.data = target.clone();
|
||||||
|
core.storage.blob = target.clone().into();
|
||||||
|
let imported = core.restore(export.path.clone()).await;
|
||||||
|
|
||||||
|
// Counters are stored differently by the SQL and key-value backends, so
|
||||||
|
// compare their keys here and their values through the counter API.
|
||||||
|
print!("Verifying {target_type} store hash...");
|
||||||
|
Snapshot::new_portable(source)
|
||||||
|
.await
|
||||||
|
.assert_is_eq(&Snapshot::new_portable(&target).await);
|
||||||
|
for subspace in [SUBSPACE_COUNTER, SUBSPACE_QUOTA] {
|
||||||
|
let mut keys = Vec::new();
|
||||||
|
source
|
||||||
|
.iterate(
|
||||||
|
IterateParams::new(
|
||||||
|
AnyKey {
|
||||||
|
subspace,
|
||||||
|
key: vec![0u8],
|
||||||
|
},
|
||||||
|
AnyKey {
|
||||||
|
subspace,
|
||||||
|
key: vec![u8::MAX; 10],
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.no_values(),
|
||||||
|
|key, _| {
|
||||||
|
keys.push(key.to_vec());
|
||||||
|
Ok(true)
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
for key in keys {
|
||||||
|
let class = || {
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace,
|
||||||
|
key: key.clone(),
|
||||||
|
})
|
||||||
|
};
|
||||||
|
assert_eq!(
|
||||||
|
source.get_counter(class()).await.unwrap(),
|
||||||
|
target.get_counter(class()).await.unwrap(),
|
||||||
|
"Counter mismatch in {} for {key:?}",
|
||||||
|
char::from(subspace)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
assert_named_blobs(&core.storage.blob, named_blobs).await;
|
||||||
|
println!(" GREAT SUCCESS!");
|
||||||
|
|
||||||
|
// The search index isn't exported; the import queues its rebuild
|
||||||
|
let queued = core.queue_reindex(&imported).await;
|
||||||
|
let expected = [
|
||||||
|
TaskStoreMaintenanceType::ReindexAccounts,
|
||||||
|
TaskStoreMaintenanceType::ReindexTelemetry,
|
||||||
|
];
|
||||||
|
assert_eq!(queued, expected);
|
||||||
|
let mut task_ids = Vec::new();
|
||||||
|
target
|
||||||
|
.iterate(
|
||||||
|
IterateParams::new(
|
||||||
|
AnyKey {
|
||||||
|
subspace: SUBSPACE_TASK_QUEUE,
|
||||||
|
key: vec![0u8],
|
||||||
|
},
|
||||||
|
AnyKey {
|
||||||
|
subspace: SUBSPACE_TASK_QUEUE,
|
||||||
|
key: vec![u8::MAX; 20],
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.no_values(),
|
||||||
|
|key, _| {
|
||||||
|
if key.deserialize_be_u64(0)? == 0 {
|
||||||
|
task_ids.push(key.deserialize_be_u64(U64_LEN)?);
|
||||||
|
}
|
||||||
|
Ok(true)
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
let mut found = Vec::new();
|
||||||
|
for id in task_ids {
|
||||||
|
match target
|
||||||
|
.get_value::<Task>(ValueKey::from(ValueClass::TaskQueue(
|
||||||
|
TaskQueueClass::Task { id },
|
||||||
|
)))
|
||||||
|
.await
|
||||||
|
.unwrap()
|
||||||
|
{
|
||||||
|
Some(Task::StoreMaintenance(task)) => found.push(task.maintenance_type),
|
||||||
|
other => panic!("Unexpected task {other:?}"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
found.sort_by_key(|t| *t as u16);
|
||||||
|
assert_eq!(found, expected, "Queued tasks don't match");
|
||||||
|
|
||||||
|
store_destroy(&target).await;
|
||||||
|
drop(core);
|
||||||
|
drop(target);
|
||||||
|
target_dir.delete();
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn assert_named_blobs(blob_store: &BlobStore, named_blobs: &[(&[u8], Vec<u8>)]) {
|
||||||
|
for (key, data) in named_blobs {
|
||||||
|
assert_eq!(
|
||||||
|
blob_store
|
||||||
|
.get_blob(key, 0..usize::MAX)
|
||||||
|
.await
|
||||||
|
.unwrap()
|
||||||
|
.as_ref(),
|
||||||
|
Some(data),
|
||||||
|
"Blob {} was not restored",
|
||||||
|
String::from_utf8_lossy(key)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
#[derive(Debug, PartialEq, Eq)]
|
#[derive(Debug, PartialEq, Eq)]
|
||||||
struct Snapshot {
|
struct Snapshot {
|
||||||
keys: AHashSet<KeyValue>,
|
keys: AHashSet<KeyValue>,
|
||||||
@@ -240,7 +471,19 @@ struct KeyValue {
|
|||||||
|
|
||||||
impl Snapshot {
|
impl Snapshot {
|
||||||
async fn new(db: &Store) -> Self {
|
async fn new(db: &Store) -> Self {
|
||||||
let is_sql = db.is_sql();
|
Self::build(db, !db.is_sql(), true).await
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Comparable across backends: no counter values, which the SQL and
|
||||||
|
/// key-value stores encode differently, and no blobs, which only live in
|
||||||
|
/// the data store when it doubles as the blob store.
|
||||||
|
#[cfg(all(feature = "rocks", feature = "sqlite"))]
|
||||||
|
async fn new_portable(db: &Store) -> Self {
|
||||||
|
Self::build(db, false, false).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn build(db: &Store, counter_values: bool, with_blobs: bool) -> Self {
|
||||||
|
let is_sql = !counter_values;
|
||||||
|
|
||||||
let mut keys = AHashSet::new();
|
let mut keys = AHashSet::new();
|
||||||
|
|
||||||
@@ -265,7 +508,12 @@ impl Snapshot {
|
|||||||
(SUBSPACE_QUOTA, !is_sql),
|
(SUBSPACE_QUOTA, !is_sql),
|
||||||
(SUBSPACE_REPORT_OUT, true),
|
(SUBSPACE_REPORT_OUT, true),
|
||||||
(SUBSPACE_REPORT_IN, true),
|
(SUBSPACE_REPORT_IN, true),
|
||||||
|
(SUBSPACE_DIRECTORY, true),
|
||||||
|
(SUBSPACE_INBUXA, true),
|
||||||
] {
|
] {
|
||||||
|
if subspace == SUBSPACE_BLOBS && !with_blobs {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
let from_key = AnyKey {
|
let from_key = AnyKey {
|
||||||
subspace,
|
subspace,
|
||||||
key: vec![0u8],
|
key: vec![0u8],
|
||||||
|
|||||||
@@ -21,6 +21,7 @@ pub mod replica_cluster; // inbuxa: read replicas across nodes
|
|||||||
pub mod scaleout; // inbuxa: scale-out storage
|
pub mod scaleout; // inbuxa: scale-out storage
|
||||||
#[cfg(any(feature = "postgres", feature = "mysql"))]
|
#[cfg(any(feature = "postgres", feature = "mysql"))]
|
||||||
pub mod sql_timeout;
|
pub mod sql_timeout;
|
||||||
|
pub mod task_locks; // inbuxa: task locks across nodes
|
||||||
|
|
||||||
use crate::utils::server::TestServerBuilder;
|
use crate::utils::server::TestServerBuilder;
|
||||||
use std::io::Read;
|
use std::io::Read;
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::{store::deflate_test_resource, utils::server::TestServer};
|
use crate::{store::deflate_test_resource, utils::server::TestServer};
|
||||||
@@ -122,6 +124,15 @@ pub async fn test(test: &TestServer) {
|
|||||||
println!("Running global id filtering tests...");
|
println!("Running global id filtering tests...");
|
||||||
test_global(store.clone()).await;
|
test_global(store.clone()).await;
|
||||||
|
|
||||||
|
// inbuxa: trace documents as the index task builds them
|
||||||
|
println!("Running trace document tests...");
|
||||||
|
test_trace_documents(store.clone()).await;
|
||||||
|
|
||||||
|
// inbuxa: address fields match by full address, local part, domain and
|
||||||
|
// display name on every backend
|
||||||
|
println!("Running address search tests...");
|
||||||
|
test_address_search(store.clone()).await;
|
||||||
|
|
||||||
// Large document insert test
|
// Large document insert test
|
||||||
println!("Running large document insert tests...");
|
println!("Running large document insert tests...");
|
||||||
let mut large_text = String::with_capacity(20 * 1024 * 1024);
|
let mut large_text = String::with_capacity(20 * 1024 * 1024);
|
||||||
@@ -809,3 +820,312 @@ async fn test_global(store: SearchStore) {
|
|||||||
AHashSet::from_iter([3, 4, 5])
|
AHashSet::from_iter([3, 4, 5])
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// inbuxa: MON-16: documents built by the index task from stored traces go
|
||||||
|
// into every search backend (the SQL backends type etyp and qid as BIGINT)
|
||||||
|
// and are found again by queue id and keyword.
|
||||||
|
async fn test_trace_documents(store: SearchStore) {
|
||||||
|
use registry::schema::{
|
||||||
|
enums::SearchTracingField,
|
||||||
|
structs::{
|
||||||
|
Trace, TraceEvent, TraceKeyValue, TraceValue, TraceValueString,
|
||||||
|
TraceValueUnsignedInt,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
use services::task_manager::index::trace_search_document;
|
||||||
|
use trc::{DeliveryEvent, EventType, Key, SmtpEvent};
|
||||||
|
|
||||||
|
let kv_u = |key: Key, value: u64| TraceKeyValue {
|
||||||
|
key,
|
||||||
|
value: TraceValue::UnsignedInt(TraceValueUnsignedInt { value }),
|
||||||
|
};
|
||||||
|
let kv_s = |key: Key, value: &str| TraceKeyValue {
|
||||||
|
key,
|
||||||
|
value: TraceValue::String(TraceValueString {
|
||||||
|
value: value.to_string(),
|
||||||
|
}),
|
||||||
|
};
|
||||||
|
let event = |event: EventType, key_values: Vec<TraceKeyValue>| TraceEvent {
|
||||||
|
event,
|
||||||
|
key_values: key_values.into(),
|
||||||
|
..Default::default()
|
||||||
|
};
|
||||||
|
let fields = [
|
||||||
|
SearchTracingField::EventType,
|
||||||
|
SearchTracingField::QueueId,
|
||||||
|
SearchTracingField::Keywords,
|
||||||
|
];
|
||||||
|
|
||||||
|
// An SMTP session that queued two messages, and a delivery attempt
|
||||||
|
let session = Trace {
|
||||||
|
events: vec![
|
||||||
|
event(
|
||||||
|
EventType::Smtp(SmtpEvent::ConnectionStart),
|
||||||
|
vec![kv_s(Key::RemoteIp, "192.0.2.7")],
|
||||||
|
),
|
||||||
|
event(
|
||||||
|
EventType::Smtp(SmtpEvent::MailFrom),
|
||||||
|
vec![kv_s(Key::From, "[email protected]")],
|
||||||
|
),
|
||||||
|
event(
|
||||||
|
EventType::Smtp(SmtpEvent::RcptTo),
|
||||||
|
vec![kv_u(Key::QueueId, 9_000_000_001), kv_s(Key::To, "[email protected]")],
|
||||||
|
),
|
||||||
|
event(
|
||||||
|
EventType::Smtp(SmtpEvent::RcptTo),
|
||||||
|
vec![kv_u(Key::QueueId, 9_000_000_002)],
|
||||||
|
),
|
||||||
|
]
|
||||||
|
.into(),
|
||||||
|
};
|
||||||
|
let delivery = Trace {
|
||||||
|
events: vec![event(
|
||||||
|
EventType::Delivery(DeliveryEvent::AttemptStart),
|
||||||
|
vec![kv_u(Key::QueueId, 9_000_000_003), kv_s(Key::Hostname, "relay.example.net")],
|
||||||
|
)]
|
||||||
|
.into(),
|
||||||
|
};
|
||||||
|
let documents = vec![
|
||||||
|
trace_search_document(100, &session, &fields),
|
||||||
|
trace_search_document(101, &delivery, &fields),
|
||||||
|
];
|
||||||
|
assert!(
|
||||||
|
documents
|
||||||
|
.iter()
|
||||||
|
.all(|d| d.has_field(&SearchField::Tracing(TracingSearchField::QueueId))
|
||||||
|
&& d.has_field(&SearchField::Tracing(TracingSearchField::EventType))),
|
||||||
|
"trace documents carry a queue id and an event type"
|
||||||
|
);
|
||||||
|
store.index(documents).await.unwrap();
|
||||||
|
if let SearchStore::ElasticSearch(store) = &store {
|
||||||
|
store.refresh_index(SearchIndex::Tracing).await.unwrap();
|
||||||
|
}
|
||||||
|
|
||||||
|
let query = |filters: Vec<SearchFilter>| {
|
||||||
|
let store = store.clone();
|
||||||
|
async move {
|
||||||
|
store
|
||||||
|
.query_global(
|
||||||
|
SearchQuery::new(SearchIndex::Tracing)
|
||||||
|
.with_filter(SearchFilter::ge(SearchField::Id, 100u64))
|
||||||
|
.with_filters(filters),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap()
|
||||||
|
.into_iter()
|
||||||
|
.collect::<AHashSet<_>>()
|
||||||
|
}
|
||||||
|
};
|
||||||
|
// By queue id, the way x:Trace/query asks: the queue id column, or any
|
||||||
|
// queue id in the keywords
|
||||||
|
let by_queue_id = |queue_id: u64| {
|
||||||
|
vec![
|
||||||
|
SearchFilter::Or,
|
||||||
|
SearchFilter::eq(TracingSearchField::QueueId, queue_id),
|
||||||
|
SearchFilter::has_text(
|
||||||
|
TracingSearchField::Keywords,
|
||||||
|
queue_id.to_string(),
|
||||||
|
Language::None,
|
||||||
|
),
|
||||||
|
SearchFilter::End,
|
||||||
|
]
|
||||||
|
};
|
||||||
|
assert_eq!(query(by_queue_id(9_000_000_001)).await, AHashSet::from_iter([100]));
|
||||||
|
assert_eq!(query(by_queue_id(9_000_000_002)).await, AHashSet::from_iter([100]));
|
||||||
|
assert_eq!(query(by_queue_id(9_000_000_003)).await, AHashSet::from_iter([101]));
|
||||||
|
assert_eq!(query(by_queue_id(9_000_000_004)).await, AHashSet::new());
|
||||||
|
assert_eq!(
|
||||||
|
query(vec![SearchFilter::eq(TracingSearchField::QueueId, 9_000_000_003u64)]).await,
|
||||||
|
AHashSet::from_iter([101])
|
||||||
|
);
|
||||||
|
// By opening event type
|
||||||
|
assert_eq!(
|
||||||
|
query(vec![SearchFilter::eq(
|
||||||
|
TracingSearchField::EventType,
|
||||||
|
EventType::Delivery(DeliveryEvent::AttemptStart).to_id() as u64,
|
||||||
|
)])
|
||||||
|
.await,
|
||||||
|
AHashSet::from_iter([101])
|
||||||
|
);
|
||||||
|
// By keyword: an address, lowercased, and its domain
|
||||||
|
assert_eq!(
|
||||||
|
query(vec![SearchFilter::has_text(
|
||||||
|
TracingSearchField::Keywords,
|
||||||
|
"example.org",
|
||||||
|
Language::None,
|
||||||
|
)])
|
||||||
|
.await,
|
||||||
|
AHashSet::from_iter([100])
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
query(vec![SearchFilter::has_text(
|
||||||
|
TracingSearchField::Keywords,
|
||||||
|
"relay.example.net",
|
||||||
|
Language::None,
|
||||||
|
)])
|
||||||
|
.await,
|
||||||
|
AHashSet::from_iter([101])
|
||||||
|
);
|
||||||
|
|
||||||
|
for id in [100u64, 101] {
|
||||||
|
store
|
||||||
|
.unindex(
|
||||||
|
SearchQuery::new(SearchIndex::Tracing)
|
||||||
|
.with_filter(SearchFilter::eq(SearchField::Id, id)),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// inbuxa: the message indexer passes each display name and each address of
|
||||||
|
// From/To/Cc/Bcc as keyword text (Language::None). The built-in index splits
|
||||||
|
// that text into words, so an address is found by its full form, its local
|
||||||
|
// part, its domain or a display-name word; PostgreSQL kept the whole address
|
||||||
|
// as one token and MySQL dropped stopwords such as "com" and words under three
|
||||||
|
// characters. The expected results below are the built-in (RocksDB/SQLite)
|
||||||
|
// results and must be the same on every backend.
|
||||||
|
async fn test_address_search(store: SearchStore) {
|
||||||
|
const ACCOUNT_ID: u32 = 7;
|
||||||
|
let messages: [[&[(&str, &str)]; 4]; 5] = [
|
||||||
|
// From, To, Cc, Bcc
|
||||||
|
[
|
||||||
|
&[("Amazon.com", "[email protected]")],
|
||||||
|
&[("Jane Doe", "[email protected]")],
|
||||||
|
&[],
|
||||||
|
&[],
|
||||||
|
],
|
||||||
|
[
|
||||||
|
&[("", "[email protected]")],
|
||||||
|
&[("", "[email protected]")],
|
||||||
|
&[("Jane Doe", "[email protected]")],
|
||||||
|
&[],
|
||||||
|
],
|
||||||
|
[
|
||||||
|
&[("GitHub", "[email protected]")],
|
||||||
|
&[("Jo Li", "[email protected]")],
|
||||||
|
&[],
|
||||||
|
&[("Audit", "[email protected]")],
|
||||||
|
],
|
||||||
|
[
|
||||||
|
&[("Jane Doe", "[email protected]")],
|
||||||
|
&[("Amazon Web Services", "[email protected]")],
|
||||||
|
&[("Bob", "[email protected]")],
|
||||||
|
&[("", "[email protected]")],
|
||||||
|
],
|
||||||
|
[
|
||||||
|
&[("Newsletter", "[email protected]")],
|
||||||
|
&[("", "[email protected]")],
|
||||||
|
&[],
|
||||||
|
&[],
|
||||||
|
],
|
||||||
|
];
|
||||||
|
let fields = [
|
||||||
|
EmailSearchField::From,
|
||||||
|
EmailSearchField::To,
|
||||||
|
EmailSearchField::Cc,
|
||||||
|
EmailSearchField::Bcc,
|
||||||
|
];
|
||||||
|
|
||||||
|
let mut documents = Vec::new();
|
||||||
|
let mut mask = RoaringBitmap::new();
|
||||||
|
for (document_id, message) in messages.iter().enumerate() {
|
||||||
|
let mut document = IndexDocument::new(SearchIndex::Email)
|
||||||
|
.with_account_id(ACCOUNT_ID)
|
||||||
|
.with_document_id(document_id as u32);
|
||||||
|
for (field, addresses) in fields.iter().zip(message.iter()) {
|
||||||
|
for (name, address) in addresses.iter() {
|
||||||
|
if !name.is_empty() {
|
||||||
|
document.index_text(field.clone(), name, Language::None);
|
||||||
|
}
|
||||||
|
document.index_text(field.clone(), address, Language::None);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
document.index_unsigned(EmailSearchField::ReceivedAt, document_id as u64);
|
||||||
|
documents.push(document);
|
||||||
|
mask.insert(document_id as u32);
|
||||||
|
}
|
||||||
|
store.index(documents).await.unwrap();
|
||||||
|
if let SearchStore::ElasticSearch(store) = &store {
|
||||||
|
store.refresh_index(SearchIndex::Email).await.unwrap();
|
||||||
|
}
|
||||||
|
|
||||||
|
for (field, text, expected) in [
|
||||||
|
// full address
|
||||||
|
(EmailSearchField::From, "[email protected]", vec![0u32]),
|
||||||
|
(EmailSearchField::To, "[email protected]", vec![0]),
|
||||||
|
(EmailSearchField::Cc, "[email protected]", vec![1]),
|
||||||
|
(EmailSearchField::Bcc, "[email protected]", vec![3]),
|
||||||
|
(EmailSearchField::To, "[email protected]", vec![1, 2]),
|
||||||
|
// local part
|
||||||
|
(EmailSearchField::From, "noreply", vec![0, 2]),
|
||||||
|
(EmailSearchField::To, "jo", vec![1, 2]),
|
||||||
|
(EmailSearchField::Cc, "bob", vec![3]),
|
||||||
|
(EmailSearchField::Bcc, "audit", vec![2]),
|
||||||
|
// domain
|
||||||
|
(EmailSearchField::From, "amazon.com", vec![0, 1]),
|
||||||
|
(EmailSearchField::From, "amazon", vec![0, 1]),
|
||||||
|
(EmailSearchField::To, "example.org", vec![0, 4]),
|
||||||
|
(EmailSearchField::To, "io.de", vec![1, 2]),
|
||||||
|
(EmailSearchField::Cc, "example.net", vec![3]),
|
||||||
|
(EmailSearchField::Bcc, "example.org", vec![2]),
|
||||||
|
(EmailSearchField::From, "www.example.com", vec![4]),
|
||||||
|
(EmailSearchField::From, "com", vec![0, 1, 2, 4]),
|
||||||
|
// display name
|
||||||
|
(EmailSearchField::From, "Jane", vec![3]),
|
||||||
|
(EmailSearchField::From, "jane doe", vec![3]),
|
||||||
|
(EmailSearchField::To, "Web Services", vec![3]),
|
||||||
|
(EmailSearchField::To, "Li", vec![2]),
|
||||||
|
(EmailSearchField::Cc, "Doe", vec![1]),
|
||||||
|
(EmailSearchField::Bcc, "Audit", vec![2]),
|
||||||
|
// hyphenated local part
|
||||||
|
(EmailSearchField::From, "shipment-tracking", vec![1]),
|
||||||
|
(EmailSearchField::From, "tracking", vec![1]),
|
||||||
|
// no match
|
||||||
|
(EmailSearchField::From, "amazon.org", vec![]),
|
||||||
|
(EmailSearchField::To, "noreply", vec![]),
|
||||||
|
(EmailSearchField::Bcc, "jane", vec![]),
|
||||||
|
] {
|
||||||
|
let ids = store
|
||||||
|
.query_account(
|
||||||
|
SearchQuery::new(SearchIndex::Email)
|
||||||
|
.with_filters(vec![
|
||||||
|
SearchFilter::eq(SearchField::AccountId, ACCOUNT_ID),
|
||||||
|
SearchFilter::has_keyword(field.clone(), text),
|
||||||
|
])
|
||||||
|
.with_comparator(SearchComparator::ascending(EmailSearchField::ReceivedAt))
|
||||||
|
.with_mask(mask.clone()),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(ids, expected, "{field:?} {text:?}");
|
||||||
|
}
|
||||||
|
|
||||||
|
// TEXT-style search across all address fields
|
||||||
|
let ids = store
|
||||||
|
.query_account(
|
||||||
|
SearchQuery::new(SearchIndex::Email)
|
||||||
|
.with_filters(vec![
|
||||||
|
SearchFilter::eq(SearchField::AccountId, ACCOUNT_ID),
|
||||||
|
SearchFilter::Or,
|
||||||
|
SearchFilter::has_keyword(EmailSearchField::From, "example.org"),
|
||||||
|
SearchFilter::has_keyword(EmailSearchField::To, "example.org"),
|
||||||
|
SearchFilter::has_keyword(EmailSearchField::Cc, "example.org"),
|
||||||
|
SearchFilter::has_keyword(EmailSearchField::Bcc, "example.org"),
|
||||||
|
SearchFilter::End,
|
||||||
|
])
|
||||||
|
.with_comparator(SearchComparator::ascending(EmailSearchField::ReceivedAt))
|
||||||
|
.with_mask(mask.clone()),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(ids, vec![0, 1, 2, 3, 4]);
|
||||||
|
|
||||||
|
store
|
||||||
|
.unindex(
|
||||||
|
SearchQuery::new(SearchIndex::Email)
|
||||||
|
.with_filter(SearchFilter::eq(SearchField::AccountId, ACCOUNT_ID)),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
}
|
||||||
|
|||||||
@@ -0,0 +1,184 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! Task locks across nodes: tasks claimed by a node that then disappears
|
||||||
|
//! run elsewhere once its locks expire, and a node that stops gracefully
|
||||||
|
//! hands its locks back at once. The other node is played by writing its
|
||||||
|
//! locks straight into the shared in-memory store, as a node that claimed
|
||||||
|
//! the tasks and died leaves them.
|
||||||
|
|
||||||
|
use crate::utils::server::TestServerBuilder;
|
||||||
|
use common::{KV_LOCK_TASK, Server};
|
||||||
|
use registry::schema::{
|
||||||
|
enums::IndexDocumentType,
|
||||||
|
structs::{Task, TaskIndexDocument, TaskStatus},
|
||||||
|
};
|
||||||
|
use services::task_manager::lock::{TaskLockManager, release_task_locks};
|
||||||
|
use std::time::{Duration, Instant};
|
||||||
|
use store::{
|
||||||
|
ValueKey,
|
||||||
|
write::{BatchBuilder, TaskQueueClass, ValueClass},
|
||||||
|
};
|
||||||
|
use utils::snowflake::SnowflakeIdGenerator;
|
||||||
|
|
||||||
|
// Short enough for a test, long enough that the recheck interval (a twelfth
|
||||||
|
// of it) is well below it
|
||||||
|
const LOCK_EXPIRY: u64 = 12;
|
||||||
|
|
||||||
|
#[tokio::test(flavor = "multi_thread")]
|
||||||
|
pub async fn task_lock_tests() {
|
||||||
|
let test = TestServerBuilder::new("task_lock_tests")
|
||||||
|
.await
|
||||||
|
.build()
|
||||||
|
.await;
|
||||||
|
let server = test.server.clone();
|
||||||
|
println!(
|
||||||
|
"Running task lock tests on {}...",
|
||||||
|
std::env::var("STORE").unwrap_or_default()
|
||||||
|
);
|
||||||
|
server.inner.ipc.task_locks.set_expiry(LOCK_EXPIRY);
|
||||||
|
|
||||||
|
// 1. Another node claimed the tasks and died. Its locks block them until
|
||||||
|
// they expire; then this node runs them, without waiting for anything
|
||||||
|
// else to wake it
|
||||||
|
let ids = new_task_ids(4);
|
||||||
|
for id in &ids {
|
||||||
|
assert!(foreign_lock(&server, *id, LOCK_EXPIRY).await);
|
||||||
|
}
|
||||||
|
schedule(&server, &ids).await;
|
||||||
|
let started = Instant::now();
|
||||||
|
server.notify_task_queue();
|
||||||
|
tokio::time::sleep(Duration::from_secs(3)).await;
|
||||||
|
assert_eq!(pending(&server, &ids).await, ids.len(), "held by the other node");
|
||||||
|
wait_until_done(&server, &ids, Duration::from_secs(LOCK_EXPIRY + 10)).await;
|
||||||
|
let elapsed = started.elapsed();
|
||||||
|
assert!(
|
||||||
|
elapsed >= Duration::from_secs(LOCK_EXPIRY - 2),
|
||||||
|
"ran before the other node's locks expired: {elapsed:?}"
|
||||||
|
);
|
||||||
|
|
||||||
|
// 2. The other node's locks outlive what this node expects: claimed just
|
||||||
|
// after this node looked, or by a node whose clock runs ahead. This node
|
||||||
|
// keeps checking at the recheck interval, so the tasks run soon after
|
||||||
|
// those locks expire, not a whole lock lifetime later
|
||||||
|
let held_for = LOCK_EXPIRY + LOCK_EXPIRY / 2;
|
||||||
|
let ids = new_task_ids(4);
|
||||||
|
for id in &ids {
|
||||||
|
assert!(foreign_lock(&server, *id, held_for).await);
|
||||||
|
}
|
||||||
|
schedule(&server, &ids).await;
|
||||||
|
let started = Instant::now();
|
||||||
|
server.notify_task_queue();
|
||||||
|
wait_until_done(&server, &ids, Duration::from_secs(held_for + 8)).await;
|
||||||
|
let elapsed = started.elapsed();
|
||||||
|
assert!(
|
||||||
|
elapsed >= Duration::from_secs(held_for - 2),
|
||||||
|
"ran before the other node's locks expired: {elapsed:?}"
|
||||||
|
);
|
||||||
|
|
||||||
|
// 3. A graceful stop releases the locks this node holds: another node
|
||||||
|
// can claim those tasks at once, and this one claims nothing more
|
||||||
|
let ids = new_task_ids(3);
|
||||||
|
for id in &ids {
|
||||||
|
assert!(server.try_lock_task(*id).await, "claim {id}");
|
||||||
|
}
|
||||||
|
assert_eq!(server.inner.ipc.task_locks.held(), ids.len());
|
||||||
|
for id in &ids {
|
||||||
|
assert!(
|
||||||
|
!foreign_lock(&server, *id, LOCK_EXPIRY).await,
|
||||||
|
"held while this node runs"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
assert_eq!(release_task_locks(&server).await, ids.len());
|
||||||
|
assert_eq!(server.inner.ipc.task_locks.held(), 0);
|
||||||
|
for id in &ids {
|
||||||
|
assert!(
|
||||||
|
foreign_lock(&server, *id, LOCK_EXPIRY).await,
|
||||||
|
"released on stop: {id}"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
let [id] = new_task_ids(1)[..] else {
|
||||||
|
unreachable!()
|
||||||
|
};
|
||||||
|
assert!(!server.try_lock_task(id).await, "a stopping node claims nothing");
|
||||||
|
|
||||||
|
for id in ids {
|
||||||
|
let _ = server
|
||||||
|
.in_memory_store()
|
||||||
|
.remove_lock(KV_LOCK_TASK, &id.to_be_bytes())
|
||||||
|
.await;
|
||||||
|
}
|
||||||
|
if test.is_reset() {
|
||||||
|
test.temp_dir.delete();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn new_task_ids(count: usize) -> Vec<u64> {
|
||||||
|
(0..count)
|
||||||
|
.map(|_| SnowflakeIdGenerator::global_id().unwrap())
|
||||||
|
.collect()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The other node's claim on a task, as its task manager takes it.
|
||||||
|
async fn foreign_lock(server: &Server, id: u64, seconds: u64) -> bool {
|
||||||
|
server
|
||||||
|
.in_memory_store()
|
||||||
|
.try_lock(KV_LOCK_TASK, &id.to_be_bytes(), seconds)
|
||||||
|
.await
|
||||||
|
.unwrap()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Unindex tasks for files that don't exist: files aren't search-indexed and
|
||||||
|
/// there is no undelete note, so running one only drops it from the queue.
|
||||||
|
async fn schedule(server: &Server, ids: &[u64]) {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
for (n, id) in ids.iter().enumerate() {
|
||||||
|
batch.schedule_task_with_id(
|
||||||
|
*id,
|
||||||
|
Task::UnindexDocument(TaskIndexDocument {
|
||||||
|
account_id: 0u32.into(),
|
||||||
|
document_id: (u32::MAX - n as u32).into(),
|
||||||
|
document_type: IndexDocumentType::File,
|
||||||
|
status: TaskStatus::now(),
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
server.store().write(batch.build_all()).await.unwrap();
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn pending(server: &Server, ids: &[u64]) -> usize {
|
||||||
|
let mut count = 0;
|
||||||
|
for id in ids {
|
||||||
|
if server
|
||||||
|
.store()
|
||||||
|
.get_value::<Task>(ValueKey::from(ValueClass::TaskQueue(
|
||||||
|
TaskQueueClass::Task { id: *id },
|
||||||
|
)))
|
||||||
|
.await
|
||||||
|
.unwrap()
|
||||||
|
.is_some()
|
||||||
|
{
|
||||||
|
count += 1;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
count
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn wait_until_done(server: &Server, ids: &[u64], within: Duration) {
|
||||||
|
let started = Instant::now();
|
||||||
|
loop {
|
||||||
|
let left = pending(server, ids).await;
|
||||||
|
if left == 0 {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
assert!(
|
||||||
|
started.elapsed() < within,
|
||||||
|
"{left} task(s) still pending after {:?}",
|
||||||
|
started.elapsed()
|
||||||
|
);
|
||||||
|
tokio::time::sleep(Duration::from_millis(250)).await;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -20,6 +20,7 @@ pub mod monitoring;
|
|||||||
pub mod oidc;
|
pub mod oidc;
|
||||||
pub mod purge;
|
pub mod purge;
|
||||||
pub mod quota;
|
pub mod quota;
|
||||||
|
pub mod reload; // inbuxa: reloads and build errors
|
||||||
pub mod security;
|
pub mod security;
|
||||||
pub mod task;
|
pub mod task;
|
||||||
pub mod tenant;
|
pub mod tenant;
|
||||||
|
|||||||
@@ -148,6 +148,73 @@ pub async fn test(test: &mut TestServer) {
|
|||||||
"test 9: to"
|
"test 9: to"
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// MON-16: the queueId filter finds the traces that name a queue id (the
|
||||||
|
// session that queued the message and its delivery attempt) through the
|
||||||
|
// search index, given as a string or a number (the index column is an
|
||||||
|
// integer)
|
||||||
|
fn queue_ids(value: &Value, out: &mut Vec<u64>) {
|
||||||
|
match value {
|
||||||
|
Value::Object(map) => {
|
||||||
|
if map.get("key").and_then(|k| k.as_str()) == Some("queueId")
|
||||||
|
&& let Some(id) = map
|
||||||
|
.get("value")
|
||||||
|
.and_then(|v| v.get("value").unwrap_or(v).as_u64())
|
||||||
|
{
|
||||||
|
out.push(id);
|
||||||
|
}
|
||||||
|
map.values().for_each(|v| queue_ids(v, out));
|
||||||
|
}
|
||||||
|
Value::Array(list) => list.iter().for_each(|v| queue_ids(v, out)),
|
||||||
|
_ => {}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
let with_ids = traces
|
||||||
|
.iter()
|
||||||
|
.map(|t| {
|
||||||
|
let mut ids = Vec::new();
|
||||||
|
queue_ids(t, &mut ids);
|
||||||
|
(t["id"].as_str().unwrap().to_string(), ids)
|
||||||
|
})
|
||||||
|
.collect::<Vec<_>>();
|
||||||
|
let queue_id = with_ids
|
||||||
|
.iter()
|
||||||
|
.find_map(|(_, ids)| ids.first().copied())
|
||||||
|
.expect("MON-16: a trace with a queue id");
|
||||||
|
let mut expected = with_ids
|
||||||
|
.iter()
|
||||||
|
.filter(|(_, ids)| ids.contains(&queue_id))
|
||||||
|
.map(|(id, _)| id.clone())
|
||||||
|
.collect::<Vec<_>>();
|
||||||
|
expected.sort();
|
||||||
|
for filter in [json!(queue_id.to_string()), json!(queue_id)] {
|
||||||
|
let response = admin
|
||||||
|
.jmap_method_call("x:Trace/query", json!({"filter": {"queueId": filter}}))
|
||||||
|
.await;
|
||||||
|
let mut found = response
|
||||||
|
.0
|
||||||
|
.pointer("/methodResponses/0/1/ids")
|
||||||
|
.and_then(|ids| ids.as_array())
|
||||||
|
.map(|ids| {
|
||||||
|
ids.iter()
|
||||||
|
.filter_map(|id| id.as_str().map(str::to_string))
|
||||||
|
.collect::<Vec<_>>()
|
||||||
|
})
|
||||||
|
.unwrap_or_default();
|
||||||
|
found.sort();
|
||||||
|
assert_eq!(found, expected, "MON-16: queueId {filter}: {response:?}");
|
||||||
|
}
|
||||||
|
let response = admin
|
||||||
|
.jmap_method_call(
|
||||||
|
"x:Trace/query",
|
||||||
|
json!({"filter": {"queueId": (queue_id ^ 0x5a5a_5a5a).to_string()}}),
|
||||||
|
)
|
||||||
|
.await;
|
||||||
|
assert_eq!(
|
||||||
|
response.0.pointer("/methodResponses/0/1/ids"),
|
||||||
|
Some(&json!([])),
|
||||||
|
"MON-16: an unknown queue id"
|
||||||
|
);
|
||||||
|
|
||||||
// Acceptance test 24: destroy removes a trace; create is refused
|
// Acceptance test 24: destroy removes a trace; create is refused
|
||||||
let trace_id = traces[0]["id"].as_str().unwrap().to_string();
|
let trace_id = traces[0]["id"].as_str().unwrap().to_string();
|
||||||
let response = admin
|
let response = admin
|
||||||
|
|||||||
@@ -0,0 +1,213 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
// inbuxa: a settings reload isn't held back by a DNS lookup, or by objects
|
||||||
|
// that already failed when the running settings were built; an error in an
|
||||||
|
// object that built then still refuses it, and says which object.
|
||||||
|
|
||||||
|
use crate::utils::server::{TestServer, TestServerBuilder};
|
||||||
|
use common::{BuildServer, config::mailstore::spamfilter::PyzorConfig, ipc::RegistryChange};
|
||||||
|
use registry::schema::{
|
||||||
|
enums::TracingLevel,
|
||||||
|
prelude::{ObjectType, Property},
|
||||||
|
structs::{Action, Expression, MtaStageAuth, SpamPyzor, Tracer, TracerStdout},
|
||||||
|
};
|
||||||
|
|
||||||
|
#[tokio::test(flavor = "multi_thread")]
|
||||||
|
pub async fn reload_tests() {
|
||||||
|
let mut test = TestServerBuilder::new("reload_tests")
|
||||||
|
.await
|
||||||
|
.with_default_listeners()
|
||||||
|
.await
|
||||||
|
.with_object(MtaStageAuth {
|
||||||
|
require: Expression {
|
||||||
|
else_: "false".to_string(),
|
||||||
|
..Default::default()
|
||||||
|
},
|
||||||
|
..Default::default()
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.build()
|
||||||
|
.await;
|
||||||
|
|
||||||
|
let admin = test
|
||||||
|
.create_user_account(
|
||||||
|
"admin",
|
||||||
|
"[email protected]",
|
||||||
|
"these_pretzels_are_making_me_thirsty",
|
||||||
|
&[],
|
||||||
|
"Admin",
|
||||||
|
)
|
||||||
|
.await;
|
||||||
|
test.account("admin")
|
||||||
|
.assign_roles_to_account(admin.id(), &["user", "system"])
|
||||||
|
.await;
|
||||||
|
test.insert_account(admin);
|
||||||
|
|
||||||
|
test_unresolvable_pyzor(&test).await;
|
||||||
|
test_build_errors(&test).await;
|
||||||
|
|
||||||
|
if test.is_reset() {
|
||||||
|
test.temp_dir.delete();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn test_unresolvable_pyzor(test: &TestServer) {
|
||||||
|
println!("Running reload with an unresolvable Pyzor host...");
|
||||||
|
let admin = test.account("[email protected]");
|
||||||
|
|
||||||
|
// Upstream resolved the host while building the settings and refused the
|
||||||
|
// reload when that failed.
|
||||||
|
admin
|
||||||
|
.registry_update_setting(
|
||||||
|
SpamPyzor {
|
||||||
|
enable: true,
|
||||||
|
host: "pyzor.invalid".into(),
|
||||||
|
port: 24441,
|
||||||
|
..Default::default()
|
||||||
|
},
|
||||||
|
&[Property::Enable, Property::Host, Property::Port],
|
||||||
|
)
|
||||||
|
.await;
|
||||||
|
admin.reload_settings().await;
|
||||||
|
|
||||||
|
let pyzor = running_pyzor(test);
|
||||||
|
assert_eq!(pyzor.host, "pyzor.invalid");
|
||||||
|
assert_eq!(pyzor.port, 24441);
|
||||||
|
assert!(pyzor.address().await.is_err());
|
||||||
|
|
||||||
|
// An IP address needs no lookup
|
||||||
|
admin
|
||||||
|
.registry_update_setting(
|
||||||
|
SpamPyzor {
|
||||||
|
host: "192.0.2.1".into(),
|
||||||
|
..Default::default()
|
||||||
|
},
|
||||||
|
&[Property::Host],
|
||||||
|
)
|
||||||
|
.await;
|
||||||
|
admin.reload_settings().await;
|
||||||
|
assert_eq!(
|
||||||
|
running_pyzor(test).address().await.unwrap().to_string(),
|
||||||
|
"192.0.2.1:24441"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn test_build_errors(test: &TestServer) {
|
||||||
|
println!("Running reload with build errors...");
|
||||||
|
let admin = test.account("[email protected]");
|
||||||
|
let pyzor_ratio = running_pyzor(test).ratio;
|
||||||
|
assert_ne!(pyzor_ratio, 0.25);
|
||||||
|
|
||||||
|
// Two console tracers: only one is allowed, so the build of one of them
|
||||||
|
// fails. Neither existed when the running settings were built.
|
||||||
|
let mut tracer_ids = Vec::new();
|
||||||
|
for _ in 0..2 {
|
||||||
|
tracer_ids.push(
|
||||||
|
admin
|
||||||
|
.registry_create_object(Tracer::Stdout(TracerStdout {
|
||||||
|
enable: true,
|
||||||
|
level: TracingLevel::Error,
|
||||||
|
..Default::default()
|
||||||
|
}))
|
||||||
|
.await,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
admin
|
||||||
|
.registry_update_setting(
|
||||||
|
SpamPyzor {
|
||||||
|
ratio: 0.25.into(),
|
||||||
|
..Default::default()
|
||||||
|
},
|
||||||
|
&[Property::Ratio],
|
||||||
|
)
|
||||||
|
.await;
|
||||||
|
|
||||||
|
// A new error refuses the reload and names the object
|
||||||
|
let err = admin
|
||||||
|
.registry_create_object_expect_err(Action::ReloadSettings)
|
||||||
|
.await;
|
||||||
|
let description = err.description.clone().unwrap_or_default();
|
||||||
|
assert!(
|
||||||
|
description.starts_with("Settings were not reloaded. ")
|
||||||
|
&& description.contains("Tracer")
|
||||||
|
&& description.contains("Only one console tracer is allowed"),
|
||||||
|
"{err:?}"
|
||||||
|
);
|
||||||
|
assert_eq!(running_pyzor(test).ratio, pyzor_ratio);
|
||||||
|
|
||||||
|
// Had the running settings been built with that tracer failing, as a
|
||||||
|
// restart now would, the same error doesn't hold the reload back.
|
||||||
|
let result = Box::pin(
|
||||||
|
test.server
|
||||||
|
.reload_registry(RegistryChange::Reload(ObjectType::DataStore)),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert!(!result.replaced_core);
|
||||||
|
assert_eq!(result.errors.len(), 1, "{:?}", result.errors);
|
||||||
|
test.server.record_build_errors(&result.errors);
|
||||||
|
|
||||||
|
admin.reload_settings().await;
|
||||||
|
assert_eq!(running_pyzor(test).ratio, 0.25);
|
||||||
|
let result = Box::pin(
|
||||||
|
test.server
|
||||||
|
.reload_registry(RegistryChange::Reload(ObjectType::DataStore)),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert!(result.replaced_core);
|
||||||
|
assert!(result.errors.is_empty());
|
||||||
|
assert_eq!(result.known_errors.len(), 1);
|
||||||
|
|
||||||
|
// Once fixed, the object is no longer known to fail, so a new error
|
||||||
|
// there refuses the reload again.
|
||||||
|
admin
|
||||||
|
.registry_destroy(ObjectType::Tracer, tracer_ids.iter())
|
||||||
|
.await
|
||||||
|
.assert_destroyed(&tracer_ids);
|
||||||
|
admin.reload_settings().await;
|
||||||
|
let result = Box::pin(
|
||||||
|
test.server
|
||||||
|
.reload_registry(RegistryChange::Reload(ObjectType::DataStore)),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert!(result.replaced_core);
|
||||||
|
assert!(result.errors.is_empty() && result.known_errors.is_empty());
|
||||||
|
|
||||||
|
for _ in 0..2 {
|
||||||
|
tracer_ids.push(
|
||||||
|
admin
|
||||||
|
.registry_create_object(Tracer::Stdout(TracerStdout {
|
||||||
|
enable: true,
|
||||||
|
level: TracingLevel::Error,
|
||||||
|
..Default::default()
|
||||||
|
}))
|
||||||
|
.await,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
admin
|
||||||
|
.registry_create_object_expect_err(Action::ReloadSettings)
|
||||||
|
.await;
|
||||||
|
let tracer_ids = tracer_ids.split_off(2);
|
||||||
|
admin
|
||||||
|
.registry_destroy(ObjectType::Tracer, tracer_ids.iter())
|
||||||
|
.await
|
||||||
|
.assert_destroyed(&tracer_ids);
|
||||||
|
admin.reload_settings().await;
|
||||||
|
}
|
||||||
|
|
||||||
|
fn running_pyzor(test: &TestServer) -> PyzorConfig {
|
||||||
|
test.server
|
||||||
|
.inner
|
||||||
|
.build_server()
|
||||||
|
.core
|
||||||
|
.spam
|
||||||
|
.pyzor
|
||||||
|
.clone()
|
||||||
|
.expect("Pyzor enabled")
|
||||||
|
}
|
||||||
Executable
+120
@@ -0,0 +1,120 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
# SPDX-FileCopyrightText: 2026 Coffey Labs
|
||||||
|
# SPDX-License-Identifier: AGPL-3.0-or-later
|
||||||
|
"""Every path Cargo patches has to be in the image's build context.
|
||||||
|
|
||||||
|
Cargo.toml's [patch.crates-io] can point at a directory in this repository,
|
||||||
|
and the Dockerfile builds from a context that .dockerignore prunes to almost
|
||||||
|
nothing. Those two facts met on 2026-09-23: a vendored, patched sieve-rs
|
||||||
|
landed, CI stayed green -- it builds from a checkout, where the directory is
|
||||||
|
simply there -- and the release build failed on
|
||||||
|
|
||||||
|
failed to load source for dependency `sieve-rs`
|
||||||
|
failed to read /build/vendor/sieve-rs/Cargo.toml
|
||||||
|
|
||||||
|
after a tag had already been pushed. This is seconds, and it runs beside the
|
||||||
|
other fork checks rather than waiting for a release to find out.
|
||||||
|
|
||||||
|
Being in the context isn't enough on its own: the Dockerfile cooks the
|
||||||
|
dependencies (`cargo chef cook`) before it copies the tree in, from a recipe
|
||||||
|
that carries only the workspace's manifests. So each patched path must also be
|
||||||
|
copied into that stage before the cook step, or the same error comes back
|
||||||
|
there -- as it did for 2026.9.24.2, the first tag after the context fix.
|
||||||
|
"""
|
||||||
|
|
||||||
|
import re
|
||||||
|
import sys
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
root = Path(__file__).resolve().parents[2]
|
||||||
|
|
||||||
|
|
||||||
|
def patched_paths(manifest: Path) -> list[str]:
|
||||||
|
"""Directories named by a [patch...] section's `path = "..."` entries."""
|
||||||
|
out, in_patch = [], False
|
||||||
|
for line in manifest.read_text().splitlines():
|
||||||
|
stripped = line.strip()
|
||||||
|
if stripped.startswith("["):
|
||||||
|
in_patch = stripped.startswith("[patch")
|
||||||
|
continue
|
||||||
|
if not in_patch:
|
||||||
|
continue
|
||||||
|
m = re.search(r'path\s*=\s*"([^"]+)"', stripped)
|
||||||
|
if m:
|
||||||
|
out.append(m.group(1))
|
||||||
|
return out
|
||||||
|
|
||||||
|
|
||||||
|
def allowed(dockerignore: Path) -> set[str]:
|
||||||
|
"""The first path segment of every re-inclusion rule."""
|
||||||
|
keep = set()
|
||||||
|
for line in dockerignore.read_text().splitlines():
|
||||||
|
stripped = line.strip()
|
||||||
|
if stripped.startswith("!"):
|
||||||
|
keep.add(stripped[1:].strip("/").split("/")[0])
|
||||||
|
return keep
|
||||||
|
|
||||||
|
|
||||||
|
def copied_before_cook(dockerfile: Path) -> list[str] | None:
|
||||||
|
"""Sources COPY'd into the stage that runs `cargo chef cook`, before it.
|
||||||
|
|
||||||
|
None when no stage cooks. A `COPY . .` covers everything.
|
||||||
|
"""
|
||||||
|
stage: list[str] = []
|
||||||
|
for line in dockerfile.read_text().splitlines():
|
||||||
|
stripped = line.strip()
|
||||||
|
if re.match(r"(?i)^FROM\s", stripped):
|
||||||
|
stage = []
|
||||||
|
continue
|
||||||
|
if "cargo chef cook" in stripped:
|
||||||
|
return stage
|
||||||
|
m = re.match(r"(?i)^COPY\s+(?!--from)(.+)$", stripped)
|
||||||
|
if m:
|
||||||
|
parts = m.group(1).split()
|
||||||
|
stage.extend(p.strip("./").split("/")[0] or "." for p in parts[:-1])
|
||||||
|
return None
|
||||||
|
|
||||||
|
|
||||||
|
def main() -> int:
|
||||||
|
paths = patched_paths(root / "Cargo.toml")
|
||||||
|
if not paths:
|
||||||
|
print("no patched paths to check")
|
||||||
|
return 0
|
||||||
|
keep = allowed(root / ".dockerignore")
|
||||||
|
bad = []
|
||||||
|
for p in paths:
|
||||||
|
top = p.strip("/").split("/")[0]
|
||||||
|
if top not in keep:
|
||||||
|
bad.append((p, top))
|
||||||
|
elif not (root / p).is_dir():
|
||||||
|
bad.append((p, None))
|
||||||
|
for path, top in bad:
|
||||||
|
if top is None:
|
||||||
|
print(f"Cargo.toml patches {path}, which does not exist", file=sys.stderr)
|
||||||
|
else:
|
||||||
|
print(
|
||||||
|
f"Cargo.toml patches {path}, but .dockerignore does not re-include {top!r}:\n"
|
||||||
|
f" the image build would not see it, and cargo would fail on it.\n"
|
||||||
|
f" Add `!{top}` to .dockerignore.",
|
||||||
|
file=sys.stderr,
|
||||||
|
)
|
||||||
|
copied = copied_before_cook(root / "Dockerfile")
|
||||||
|
if copied is not None and "." not in copied:
|
||||||
|
for p in paths:
|
||||||
|
top = p.strip("/").split("/")[0]
|
||||||
|
if top not in copied:
|
||||||
|
print(
|
||||||
|
f"Cargo.toml patches {p}, but the Dockerfile doesn't copy {top!r} into the\n"
|
||||||
|
f" stage that runs `cargo chef cook` before that step, so cooking the\n"
|
||||||
|
f" dependencies fails on it. Add `COPY {top}/ {top}/` before the cook.",
|
||||||
|
file=sys.stderr,
|
||||||
|
)
|
||||||
|
bad.append((p, top))
|
||||||
|
if bad:
|
||||||
|
return 1
|
||||||
|
print(f"build context and cook stage include every patched path: {', '.join(paths)}")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
raise SystemExit(main())
|
||||||
@@ -23,6 +23,6 @@ crates/migration/src/lib.rs "STALWART_SPAM_CLASSIFIER_MODEL.lz4"
|
|||||||
crates/migration/src/lib.rs "STALWART_SPAM_TRAIN_DATA.lz4"
|
crates/migration/src/lib.rs "STALWART_SPAM_TRAIN_DATA.lz4"
|
||||||
crates/types/src/branding.rs "STALWART"
|
crates/types/src/branding.rs "STALWART"
|
||||||
|
|
||||||
# OPEN, not yet decided (2026-09-22): upstream's published spam-filter rules,
|
# Upstream's old default rules source, read only to treat it as unset: the
|
||||||
# which the server downloads at runtime from this address.
|
# server uses the rules bundled with it (resources/spam-filter/).
|
||||||
crates/registry/src/schema/structs_impl.rs "https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz"
|
crates/common/src/manager/spam_rules.rs "https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz"
|
||||||
|
|||||||
@@ -46,6 +46,10 @@ TEXT_RENAMES = [
|
|||||||
# that must match their containers and identity provider (database users,
|
# that must match their containers and identity provider (database users,
|
||||||
# passwords, an OIDC audience), and name their databases explicitly.
|
# passwords, an OIDC audience), and name their databases explicitly.
|
||||||
('"stalwart".to_string()', '"inbuxa".to_string()', ('crates',)),
|
('"stalwart".to_string()', '"inbuxa".to_string()', ('crates',)),
|
||||||
|
# The spam filter rules ship with the server (common::manager::spam_rules);
|
||||||
|
# upstream's default of fetching its latest from GitHub becomes unset.
|
||||||
|
('spam_filter_rules_url: Some("https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz".to_string()),',
|
||||||
|
'spam_filter_rules_url: None,', ('crates',)),
|
||||||
]
|
]
|
||||||
ROOTS = ('crates', 'tests', 'resources')
|
ROOTS = ('crates', 'tests', 'resources')
|
||||||
SKIP_SUFFIXES = {'.md', '.txt'}
|
SKIP_SUFFIXES = {'.md', '.txt'}
|
||||||
@@ -58,6 +62,10 @@ SCHEMA_HASH = Path('resources/schema/schema.json.sha256')
|
|||||||
SCHEMA_RENAMES = [
|
SCHEMA_RENAMES = [
|
||||||
('"stalwart"', '"inbuxa"'),
|
('"stalwart"', '"inbuxa"'),
|
||||||
('vnd.stalwart', 'vnd.inbuxa'),
|
('vnd.stalwart', 'vnd.inbuxa'),
|
||||||
|
# The bundled spam rules: no default URL, and say what empty means.
|
||||||
|
('"spamFilterRulesUrl":"https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz",', ''),
|
||||||
|
('"URL to download spam filter rules from"',
|
||||||
|
'"URL to download spam filter rules from. Empty uses the rules bundled with the server."'),
|
||||||
]
|
]
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user