Compare commits

..
103 Commits
Author SHA1 Message Date
jcoffey-dev e35fc3e6d6 Ports: each node checks the others' ports from outside
ci / fork-checks (pull_request) Successful in 16s
ci / build (pull_request) Successful in 7m26s
2026-09-28 18:07:49 -07:00
jcoffey-dev 5f52dad5f1 Merge pull request 'Explain: don't prepare answers for date fields' (#101) from fix/explain-skip-date-fields into main
ci / fork-checks (push) Successful in 37s
ci / build (push) Canceled after 8m58s
2026-09-29 01:06:46 +00:00
jcoffey-dev 15064d6fd5 Merge pull request 'Webhooks: send one sample event to a saved webhook' (#100) from feature/webhook-test into main
ci / fork-checks (push) Canceled after 34s
ci / build (push) Canceled after 33s
2026-09-29 01:06:13 +00:00
jcoffey-dev a3a36cd5d7 Merge pull request 'DLP and mail flow rules: rules, engine, and inbuxa:MailRule over JMAP' (#103) from feature/dlp-rules into main
ci / fork-checks (push) Successful in 2m10s
ci / build (push) Canceled after 29m46s
2026-09-29 00:36:26 +00:00
jcoffey-dev 8afaee7d21 DLP and mail flow rules: inbuxa:MailRule over JMAP, and its permissions
ci / fork-checks (pull_request) Successful in 15s
ci / build (pull_request) Successful in 4m41s
Phase 2e of the DLP and mail flow rules spec, the API half.

- inbuxa:MailRule/get and /set under urn:inbuxa:jmap. Rules convert
  through serde, so what a client sends is the stored format. A create
  or change is validated whole (Rule::validate) and refused with the
  property at fault; id, createdBy, createdAt and updatedAt are the
  server's. Every change goes through the request layer's audit record.
- Six permissions, ids 674-679 (enum and schema labels): mail flow rules
  (sysMailRuleGet/Update), DLP rules (sysDlpPolicyGet/Update) and held
  mail (sysDlpReviewGet/Update, for phase 3). Either kind's permission
  gets through the gate; the handler shows and changes each rule only
  with its own kind's. All server-level: a tenant is refused (settled
  answer 3).
- Administrators get all six; the server-level Compliance Officer gets
  DLP rules to see and held mail to review (settled answer 4), added
  once to an existing server's officer role by the grant mechanism,
  which gains an officer audience.
- Privacy catalog entry for inbuxa:MailRule.

tests/src/system/mail_rules.rs: create, list in order, validation,
server-set properties refused, update, kind-separated permissions for
an officer, destroy, audit records.
2026-09-28 17:29:35 -07:00
jcoffey-dev c8280de9c3 DLP and mail flow rules: the rule model, the engine and the node cache
Phase 2e of the DLP and mail flow rules spec, in the features crate.

- rules.rs: a rule (§2.2) with its conditions (§2.3) and actions (§2.4),
  as JSON under R/r in the fork's subspace. validate() enforces the
  spec's shape: DLP rules check outgoing mail and have exactly one of
  block, warn or hold; transport rules have neither those nor
  detectors; lists, header names, header values (one line), addresses,
  texts, word lists, patterns and detector ids are checked.
- engine.rs: rules compiled once (word lists to automata, patterns to
  size-limited regexes) and run in priority order with exceptions and
  stop processing. Each detector runs at most once per message and
  only when a rule asks for it. The outcome lists what matched with
  each detector's count, and decides DLP strictest first: block, hold,
  warn; an override answers warnings only (§2.5).
- cache.rs: each node's compiled copy, refreshed after 30 seconds or at
  once when this node changes a rule.

Nothing calls this yet: the JMAP object and the check at DATA follow.
55 unit tests in mailflow.
2026-09-28 17:29:35 -07:00
jcoffey-dev f8b9df6438 Merge pull request 'DLP: regional identifiers and templates' (#102) from feature/dlp-detectors-us-uk-ca-au into main
ci / fork-checks (push) Successful in 59s
ci / build (push) Canceled after 14m34s
2026-09-29 00:21:51 +00:00
jcoffey-dev 92d14fbd60 DLP: regional identifiers and templates
ci / fork-checks (pull_request) Successful in 1m47s
ci / build (pull_request) Successful in 7m42s
Phase 2b of the DLP and mail flow rules spec: every identifier in the
§2.3 catalog, each implemented from its issuer's published rules and
tested against published examples.

US (SSN, ITIN, EIN, ABA routing, driver's licenses, MBI, NPI, DEA), UK
(NI number, NHS number, UTR), Canada (SIN), Australia (TFN, Medicare),
the EU (Germany's tax ID and ID card, France's NIR, Spain's DNI/NIE,
Italy's codice fiscale, the Dutch BSN, Belgium's national number,
Poland's PESEL, Sweden's personnummer, Denmark's CPR, Finland's HETU,
Ireland's PPS, Portugal's NIF, Austria's SVNR), Norway, Switzerland,
India (Aadhaar, PAN), China, Japan, Singapore, South Korea, Brazil (CPF,
CNPJ), Mexico (CURP) and South Africa. 49 detectors in all, plus seven
templates named for what they find.

An identifier that is only digits and whose check about one random
number in ten passes counts alone only in its written form
(536-22-1234, 943 476 5919) and as bare digits only beside a word; ABA
routing numbers and NPIs always need one. Spec §2.3 records this.

A test runs every detector over an ordinary business email (order,
invoice and tracking numbers, dates, amounts, an address) and requires
nothing to fire but the contact detectors. 47 unit tests.
2026-09-28 17:13:42 -07:00
jcoffey-dev 01f6b99631 Merge pull request 'DLP: the detector framework, the region-free detectors, word lists and attachment text' (#99) from feature/dlp-detectors into main
ci / fork-checks (push) Successful in 2m37s
ci / build (push) Canceled after 8m29s
2026-09-29 00:13:20 +00:00
jcoffey-dev 8d5e4ee052 Explain: don't prepare answers for date fields
ci / fork-checks (pull_request) Successful in 16s
ci / build (pull_request) Successful in 3m54s
2026-09-28 17:11:32 -07:00
jcoffey-dev 213c7f0362 Merge pull request 'Release 2026.9.28.5' (#98) from release/2026.9.28.5-pr into main
ci / fork-checks (push) Successful in 15s
publish / version (push) Successful in 12s
ci / build (push) Canceled after 7m39s
publish / publish-amd64 (push) Successful in 30m34s
publish / release (push) Successful in 30s
publish / publish-arm64 (push) Successful in 57m44s
publish / binaries (push) Successful in 51s
publish / announce (push) Successful in 23s
2026-09-29 00:05:39 +00:00
jcoffey-dev 9e0aab6b6a Webhooks: send one sample event to a saved webhook
ci / fork-checks (pull_request) Successful in 52s
ci / build (pull_request) Successful in 18m39s
2026-09-28 17:02:47 -07:00
jcoffey-dev 3eb5a454fd Cargo.lock: the features crate's new dependencies
ci / fork-checks (pull_request) Successful in 2m23s
ci / build (pull_request) Successful in 11m50s
2026-09-28 17:01:00 -07:00
jcoffey-dev dc49bf4d14 DLP: the detector framework, the region-free detectors, word lists and attachment text
ci / fork-checks (pull_request) Canceled after 8s
ci / build (pull_request) Canceled after 8s
Phase 2a of the DLP and mail flow rules spec: pure functions in
crates/features/src/mailflow, nothing wired into the mail path yet.

- Detectors report distinct values found, each either checked by its
  published check digit or counted only beside a corroborating word
  within 50 characters. This PR adds the region-free ones: payment
  cards (issuer prefixes, Luhn), IBAN (registry lengths, mod 97),
  SWIFT/BIC, email addresses and phone numbers in bulk, dates of birth,
  passport numbers, private keys and published service-token formats.
  Regional identifiers follow, a region per PR.
- Word lists (Aho-Corasick, whole words, any case) and patterns (regex
  with a compiled-size limit) count occurrences.
- Attachment text: text files with or without a UTF-16 mark, HTML,
  DOCX/XLSX/PPTX, ODT/ODS/ODP and ZIP archives one level deep, read
  with the zip and quick-xml crates the workspace already has.
  Encrypted files, PDF, legacy binary Office files, nested archives
  and anything past the limits come back as not inspectable, with why.

21 unit tests, against the networks' test card numbers and the IBAN
registry's own examples among others.
2026-09-28 17:00:49 -07:00
jcoffey-dev f7fb115a0f Merge pull request 'Spec: data loss prevention and mail flow rules' (#97) from spec/dlp-mail-flow-rules into main
ci / fork-checks (push) Successful in 44s
ci / build (push) Canceled after 6m41s
2026-09-28 23:58:53 +00:00
jcoffey-dev 3199a6f1fb Release 2026.9.28.5
ci / fork-checks (pull_request) Successful in 47s
ci / build (pull_request) Successful in 7m37s
2026-09-28 16:57:47 -07:00
jcoffey-dev 2b45a2e412 Spec: approved
ci / fork-checks (pull_request) Successful in 46s
ci / build (pull_request) Successful in 16m58s
2026-09-28 16:41:38 -07:00
jcoffey-dev 3fadf82909 Spec: John's answers, and the detector catalog answer 6 asks for
ci / fork-checks (pull_request) Successful in 19s
ci / build (pull_request) Successful in 7m23s
All six settled as recommended. Answer 6 ("and any other recognized and protected PII") becomes a catalog of identifiers with published formats and checks, grouped by region, each either checked by its check digit or counted only beside a corroborating word, plus templates named for what they find. Data with no number to find is covered by word lists and not claimed as detection. Office documents are read; PDF counts as can't be inspected.
2026-09-28 16:04:31 -07:00
jcoffey-dev 2a851ea230 Spec: data loss prevention and mail flow rules
ci / fork-checks (pull_request) Successful in 46s
ci / build (pull_request) Successful in 4m52s
Phase 1: one native rule engine at DATA, after the system Sieve script,
for both DLP policies and transport rules. DLP checks outgoing mail
with counted detectors (payment cards, IBAN, US SSN, word lists,
patterns) and blocks, warns with an audited override, or holds for
review. Held mail stays in the queue unscheduled, with its own review
record, so the queue's stored format is unchanged. Matches go to the
audit log without the matched text. Six questions for John at the end.
2026-09-28 15:57:53 -07:00
jcoffey-dev 0502eb45ed Merge pull request 'DNS test: expect the account-configuration digest inbuxa publishes' (#96) from fix/dns-test-pacc-digest into main
ci / fork-checks (push) Successful in 34s
ci / build (push) Successful in 24m56s
2026-09-28 22:48:02 +00:00
jcoffey-dev 11ba361c8c DNS test: expect the account-configuration digest inbuxa publishes
ci / fork-checks (pull_request) Successful in 55s
ci / build (pull_request) Successful in 18m46s
The automation suite's DNS test compared the published zone with one
copied from upstream v0.16.22. Its _ua-auto-config record carries a
SHA-256 of the account-configuration (PACC) document, and that document
names the provider as the brand, which the rebrand changed. The digest
the server publishes is right; the expected zone still held upstream's.

With the new digest the whole automation suite passes: ACME (including
the not-due reschedule check), DKIM, DNS and RFC 2136. It had been
failing at this point on main since the rebrand.
2026-09-28 15:29:06 -07:00
jcoffey-dev ba75ab4ecc Merge pull request 'ACME: a renewal that isn't due yet is rescheduled, not failed for good' (#93) from fix/acme-not-due-reschedule into main
ci / fork-checks (push) Successful in 18s
ci / build (push) Successful in 42m1s
2026-09-28 21:52:17 +00:00
jcoffey-dev afffa0fc96 Merge pull request 'Try a directory before anything signs in through it' (#95) from feature/directory-test into main
ci / fork-checks (push) Canceled after 21s
ci / build (push) Canceled after 21s
2026-09-28 21:51:56 +00:00
jcoffey-dev 32b22d0828 Merge pull request 'Schema: each expression field says which values and variables it accepts' (#91) from feature/expression-schema into main
ci / fork-checks (push) Canceled after 20s
ci / build (push) Canceled after 20s
2026-09-28 21:51:34 +00:00
jcoffey-dev 558b776e9f Merge pull request 'Release 2026.9.28.4' (#94) from release/2026.9.28.4-pr into main
ci / fork-checks (push) Successful in 15s
publish / version (push) Successful in 2m18s
publish / publish-amd64 (push) Successful in 29m39s
publish / release (push) Successful in 1s
ci / build (push) Successful in 59m47s
publish / publish-arm64 (push) Successful in 44m48s
publish / binaries (push) Successful in 45s
publish / announce (push) Successful in 23s
2026-09-28 19:46:36 +00:00
jcoffey-dev ac3a63973d Try a directory before anything signs in through it
ci / fork-checks (pull_request) Successful in 59s
ci / build (pull_request) Successful in 4m5s
POST /api/directory/test takes a saved directory's id, an address and
optionally a password, and answers whether the directory opened, what a
recipient lookup of the address finds (account or group, with its
aliases, groups and name), and whether the password signs in. A wrong
password is told apart from a directory that can't be reached or is set
up wrong.

It calls the directory itself, below the sign-in path: a test never
creates or updates an account, never counts toward the sign-in ban and
doesn't depend on which domains use the directory. A password hash a
directory returns is never sent back. OIDC directories report their
discovered issuer; they take no passwords.

For server-level administrators with directory update permission. The
console's guided directory setup uses it to test a real person before
any domain is switched over.
2026-09-28 12:38:58 -07:00
jcoffey-dev e61a475859 Schema: each expression field says which values and variables it accepts
ci / fork-checks (pull_request) Successful in 52s
ci / build (pull_request) Successful in 5m24s
The registry knows, for every expression field, the constants it may
evaluate to and the variables its conditions may read, and enforces both.
The schema served to INBUXA Admin described every one as a bare
x:Expression, so the console could offer nothing better than free text.

tools/fork/expr-schema.py reads those contexts from the generated registry
code and writes them onto each field's type as
expression: {constants, variables}. All 124 expression fields are covered.
CI runs it with --check so the schema can't drift from the registry.
2026-09-28 12:32:28 -07:00
jcoffey-dev 6c862e4971 Release 2026.9.28.4
ci / fork-checks (pull_request) Successful in 15s
ci / build (pull_request) Successful in 23m29s
The personal-data catalog and what it feeds: the data inventory and its
snapshots (#83, #89), the Compliance Officer roles (#88), the Compliance
Overview and Data Inventory menu entries (#92). Log file retention
(#87), privacy defaults for new installs (#85, #90), webhooks that send
only the events they name (#82), and upstream v0.16.24 (#84), whose
spam rules updates keep what an admin edited.

Explain: 12 settings asked about (upstream's new createdAt fields, the
certificate dates and the webhook events policy), with the release's
recommended model built locally; 705 answers carry over.
2026-09-28 12:22:34 -07:00
jcoffey-dev beb6c33e63 ACME: a renewal that isn't due yet is rescheduled, not failed for good
ci / fork-checks (pull_request) Successful in 14s
ci / build (pull_request) Successful in 16m46s
When a valid certificate already covered a domain's names (one stored
by hand before the domain was switched to automatic, for instance), the
renewal task ended with NotDue, which the task manager treats as a
permanent failure. Nothing rescheduled it, so the certificate expired
unrenewed. The renewal now returns a new AcmeRenewal task due when the
certificate falls due, the same way a successful renewal does, and logs
it as a backoff.

The ACME integration suite checks that renewing again right after
issuance hands back one AcmeRenewal for that domain, due at the
certificate's renewal point.
2026-09-28 12:15:05 -07:00
jcoffey-dev 5a73a1183a Merge pull request 'Compliance menu: Overview and Data Inventory first' (#92) from feature/compliance-pages-nav into main
ci / fork-checks (push) Successful in 50s
ci / build (push) Successful in 33m2s
2026-09-28 18:48:52 +00:00
jcoffey-dev ac204078eb Merge pull request 'New installs start with the hashed-address blocklist off, and DNSBL zones read right' (#90) from feature/d5-msbl-off into main
ci / fork-checks (push) Successful in 15s
ci / build (push) Canceled after 16m10s
2026-09-28 18:32:41 +00:00
jcoffey-dev 728586998b Catalog: what the Overview showed wrong
ci / fork-checks (pull_request) Successful in 19s
ci / build (pull_request) Successful in 44m19s
Seen in the console's first Overview. x:DmarcTroubleshoot and
x:SpamClassify are one-off actions whose results come back in the
response, not kept: object-life, not unbounded. Tasks go when done
(only a failed one's status may stay, still unconfirmed): object-life.
x:Log reads the log files, so it follows inbuxa:LogSettings.keepForDays.
x:TracerLog, x:WebHook and the OpenTelemetry tracers are configuration:
their credential fields stay classified, but they are no longer listed
in the inventory, where they counted as always sent off the server
even with none configured; the log-file, webhooks and otel-tracer
sources carry what they send.
2026-09-28 11:03:55 -07:00
jcoffey-dev cca49de92c Compliance menu: Overview and Data Inventory first
ci / fork-checks (pull_request) Successful in 16s
ci / build (pull_request) Canceled after 9m28s
Personal-data catalog spec, §8: the Compliance section in the console
reads Overview, Data Inventory, Legal Holds, Audit Log, Locked
Accounts. The two new entries are hand-built console pages
(CustomComponent/ComplianceOverview, CustomComponent/DataInventory),
shown to people with sysComplianceGet.

A console from before these pages shows the links and answers
"Unknown component", so the console that has them should be deployed
with the server release that carries this. Schema edited as the fork's
earlier Compliance entries were, hash updated.
2026-09-28 10:54:32 -07:00
jcoffey-dev b20b09f81a New installs start with the hashed-address blocklist off, and DNSBL zones read right
ci / fork-checks (pull_request) Successful in 1m3s
ci / build (pull_request) Successful in 1h11m16s
Personal-data catalog spec, default D5 (settled 2026-09-28; built after
the v0.16.24 import's spam-rules loader landed). msbl.org's EBL is sent
a SHA-1 of every email address it's asked about. A new install's first
boot now leaves a note, and the rules update, once the bundled rules
are in, switches STWT_MSBL_EBL_EMAIL off and forgets the note, so it
happens once; the loader keeps that switch through later updates. An
existing server has no note and keeps every blocklist as it is.

Also fixes the data inventory's DNSBL endpoints: a zone is an
expression (`ip_reverse + '.zen.spamhaus.org'`, conditional branches,
`hash(email, 'sha1') + '.ebl.msbl.org'`), and the zone names are now
the quoted literals that start with a dot, from every branch, rather
than the expression's text.

Tested: unit test for the zone rule; the compliance system test (no
note, no change; the inventory lists ebl.msbl.org, not a hash; with the
note the blocklist goes off; the note works once); the system suite;
fork checks.
2026-09-28 10:21:15 -07:00
jcoffey-dev 7bbbff0648 Merge pull request 'Evaluate the personal-data catalog: the data inventory and its history' (#89) from feature/data-inventory into main
ci / fork-checks (push) Successful in 36s
ci / build (push) Successful in 43m2s
2026-09-28 17:15:10 +00:00
jcoffey-dev a8fb10458b Evaluate the personal-data catalog: the data inventory and its history
ci / fork-checks (pull_request) Successful in 57s
ci / build (pull_request) Successful in 15m6s
Personal-data catalog spec, §6 (Phase 3c).

inbuxa:DataInventory/get evaluates the catalog against the server's
live settings and says what this server holds: for each source and each
object that can hold personal data, its categories and whose data it
is, whether it is collected here at all, what bounds its retention (the
live value of the setting that does, or unbounded), whether it leaves
the host and to which endpoints, and a summary. Every host that
receives something is listed once as a candidate processor with what it
receives. Inside a tenant it answers with the tenant's slice and none
of the server's processors. Read-only, with sysComplianceGet.

inbuxa:InventorySnapshot/get is the history: a dated copy of the
evaluated inventory, recorded when it changes -- after a registry write
to an object the inventory reads, after inbuxa's log, audit or AI
settings change, and on the daily clean-up -- and kept as long as the
audit log's records. ids: null lists every snapshot, newest first; the
full inventory only when asked for.

The catalog is embedded and parsed at start (new dependency: toml,
MIT/Apache); the evaluation is a pure function of it and the live
facts, so each configuration is tested without a server. Loopback
endpoints stay on the host; any other configured endpoint leaves it.

Tested: unit tests for the evaluation (a new install's defaults, an
external blob store, a hosted AI endpoint, telemetry off, a tenant's
slice, hosts from URLs, loopback), snapshots, and the fact gathering's
store and duration rules; the compliance system test, extended (the
officer reads the inventory, a plain user is refused, a tenant's
officer sees its slice and no processors, a webhook to another host
becomes a processor and a snapshot names x:WebHook, a retention change
reads through); the system, audit, legal hold and account lock suites;
fork checks. The system suite failed once of three runs with an email
import's blob not found, in antispam.rs; the same happened once in
purge.rs on the previous branch. Nothing here touches uploads; noted
for a separate look.
2026-09-28 09:59:48 -07:00
jcoffey-dev c61497e2b2 Merge pull request 'Add the compliance permission and the Compliance Officer roles' (#88) from feature/compliance-roles into main
ci / fork-checks (push) Successful in 40s
ci / build (push) Canceled after 40m52s
2026-09-28 16:34:17 +00:00
jcoffey-dev 7285b3e38a Merge main (upstream v0.16.24) into feature/compliance-roles
ci / fork-checks (pull_request) Successful in 15s
ci / build (pull_request) Successful in 7m33s
The schema conflicted as a binary file: taken from main and the one
edit here re-applied (sysComplianceGet after sysLegalHoldExport). The
import kept the permission count at 673, so the new id stays 673.

Retested on the merged tree in its own target directory: the
compliance and system suites pass. One earlier system run failed in
purge.rs (an imported blob not found) and didn't recur.
2026-09-28 09:26:27 -07:00
jcoffey-dev 9893452ca2 Merge pull request 'Merge upstream v0.16.24' (#84) from merge/upstream-v0.16.24 into main
ci / fork-checks (push) Successful in 54s
ci / build (push) Canceled after 39m0s
2026-09-28 15:55:16 +00:00
jcoffey-dev 63adb4e2b8 Add the compliance permission and the Compliance Officer roles
ci / fork-checks (pull_request) Successful in 31s
ci / build (pull_request) Successful in 11m31s
Personal-data catalog spec, §7 (settled 2026-09-28).

sysComplianceGet (673) sees the data inventory and compliance
overview: superusers and, for their tenant's slice, tenant
administrators, by default and through the one-time grants on servers
that already have their roles stored.

A Compliance Officer role at server level holds it with reading and
exporting the audit log, placing, widening, releasing and exporting
legal holds, seeing account locks, and reading accounts, lists,
domains, tenants and roles. It changes no server setting, creates or
deletes no account, and can't shorten audit retention.

A tenant's accounts can hold only roles of their own tenant (MT-3), so
the tenant role is one "Compliance Officer" role per tenant, without
holds (LH-13): made once for every tenant a server has, and whenever a
tenant is created. While nobody holds it, it is removed with its tenant
so it doesn't block the delete, and put back if the delete is refused
for another reason. Both roles carry a user's own permissions too,
since roles given to a person replace the default user role, which a
tenant's accounts can't hold anyway.

Every server makes these once, new or existing -- the built-in roles
are only made on a server with none -- and records each under P c, so a
role an administrator deletes stays deleted.

Tested: unit tests (neither role changes a setting beyond a user's
own; holds for the server's officer only; per-place records); a new
compliance system test (one server-level role; an officer reads the
audit log, places and releases a hold, and is refused a setting, an
account and audit retention; a tenant gets its role, whose holder reads
the tenant's audit log and no holds; a tenant with an unused role is
deleted and the role goes with it); the system, audit, legal hold,
account lock and SCIM suites; fork checks. The directory suite needs
its LDAP container and wasn't run here.
2026-09-28 08:50:17 -07:00
jcoffey-dev d107c1b2bb Merge pull request 'Keep rotated log files for a set number of days' (#87) from feature/log-retention into main
ci / fork-checks (push) Successful in 14s
ci / build (push) Successful in 23m17s
2026-09-28 15:27:34 +00:00
jcoffey-dev 1d5a49409f Keep rotated log files for a set number of days
ci / fork-checks (pull_request) Successful in 2m28s
ci / build (pull_request) Successful in 3m47s
Personal-data catalog spec, default D1 (settled 2026-09-28): log files
were never deleted. inbuxa:LogSettings.keepForDays says how many days
rotated log files are kept; unset (null) keeps every file, as before,
and a new install sets 30 days.

It is a fork-owned setting, stored under T + l as audit retention is,
not a field on x:TracerLog: that object is also stored inside
x:Bootstrap with a field after it, so a new field would change
x:Bootstrap's stored format. Server-level, with the tracers'
permissions (sysTracerGet, sysTracerUpdate); changes are in the audit
log, before and after.

Log files are local, so every node deletes its own: hourly, and at once
when the setting changes on that node. Only regular files named
<prefix>.<something> in each enabled log tracer's directory, last
changed more than the limit ago, are removed; the file being written is
never that old, and nothing else in the directory is touched. Minimum
one day. The catalog classifies inbuxa:LogSettings and points the log
file's retention at it.

Tested: unit tests for the file rule (only this log's old files; the
current file, other files and directories stay) and a purge on disk;
the system suite, which reads, sets, refuses zero, restores null and
checks the audit records; fork checks.
2026-09-28 08:23:36 -07:00
jcoffey-dev 80d6c09c59 Merge main into merge/upstream-v0.16.24
ci / fork-checks (pull_request) Successful in 21s
ci / build (pull_request) Successful in 35m18s
The schema, which both sides changed, merged as JSON with no conflicts.
The personal-data catalog (#83) gains upstream's new x:DnsServerPowerDns:
nothing personal but its API key, like the other DNS providers.
2026-09-28 08:19:24 -07:00
jcoffey-dev 480d93f4d6 Merge pull request 'Spec: settle where log retention lives and when D5 is built' (#86) from spec/d1-d5-settled into main
ci / fork-checks (push) Successful in 15s
ci / build (push) Canceled after 12m46s
2026-09-28 15:14:47 +00:00
jcoffey-dev f47371b3a1 Spec: settle where log retention lives and when D5 is built
ci / fork-checks (pull_request) Successful in 15s
ci / build (pull_request) Successful in 4m50s
D1 becomes a fork-owned setting, as audit retention is, because a field
on x:TracerLog would change x:Bootstrap's stored format. D5 waits for
the v0.16.24 import's reworked spam-rules loader.
2026-09-28 08:09:32 -07:00
jcoffey-dev bdd97c5828 Merge pull request 'New-install privacy defaults, and expired bans purged daily' (#85) from feature/new-install-privacy-defaults into main
ci / fork-checks (push) Successful in 1m20s
ci / build (push) Canceled after 23m15s
2026-09-28 14:51:23 +00:00
jcoffey-dev a0ffdb8071 New-install privacy defaults, and expired bans purged daily
ci / fork-checks (pull_request) Successful in 48s
ci / build (pull_request) Successful in 6m52s
Personal-data catalog spec, defaults D2, D3, D4, D6 and D7 (settled
2026-09-28, new installs only):

- D2: automatic IP bans expire after 30 days instead of never; D3:
  spam training samples, whole messages, are kept 90 days instead of
  180; D4: Pyzor, which sends a digest of each message's text to a
  public server, is off; D6: delivery history is kept 14 days instead
  of 30. Written on the first boot of a new install only -- one with no
  roles yet, the same test the built-in roles use -- by reading each
  singleton, setting these fields and writing it back whole. A server
  with roles keeps its settings, saved or default.
- D7: a webhook created from now on starts with the include policy and
  no events, so it sends nothing until events are chosen (Rust default
  and schema default, marked). The registry stores every field, so
  existing webhooks keep their policy.
- Expired bans are also removed by the daily data clean-up. They
  already stopped blocking and were deleted when settings next loaded;
  a server that seldom reloads kept them.

D1 (log retention) and D5 (the hashed-address blocklist off) are held,
and the spec says why: x:TracerLog is stored inside x:Bootstrap with a
field after it, so adding one changes that object's stored format; and
the spam-rules loader D5 touches is being reworked by the v0.16.24
import. The spec also corrects finding 3: expired bans were deleted on
settings load; bans were permanent only because no period is set.

Tested: unit tests for the new-install values and that everything else
in each singleton stays; the system suite, whose security test now
purges an expired ban and checks its record is gone; the telemetry
test; common's unit tests; fork checks.
2026-09-28 07:43:59 -07:00
jcoffey-dev 18b28fad27 Merge pull request 'Add the personal-data catalog and the check that keeps it true' (#83) from feature/privacy-catalog into main
ci / fork-checks (push) Successful in 17s
ci / build (push) Canceled after 19m3s
2026-09-28 14:32:24 +00:00
jcoffey-dev a8dde68800 Add the personal-data catalog and the check that keeps it true
ci / fork-checks (pull_request) Successful in 52s
ci / build (pull_request) Successful in 37m38s
Phase 2 of the personal-data catalog spec.

resources/privacy/catalog.toml classifies every object in the schema
(316) and inbuxa's own JMAP objects (12): each property that can hold
personal data, with its categories, and for objects that hold any,
whose data it is, where it lives, its scope and what bounds its
retention (a named setting where there is one). Twenty sources that
are no object -- the log file, exporters, webhooks, spam lookups, the
Explain cache, relays and hooks, push, legacy-use records -- carry the
same facts plus the settings that turn them on, whether the data
leaves the host, and the code that writes it. Classifications of
objects that hold data about people are from the spec's source map;
the rest are typed from the schema alone (address, IP, secret).

tools/fork/privacy-check.py fails CI when an object or inbuxa object
has no entry, when a property the schema types as an address, IP or
secret is left to its object's default, when an entry names an
object, property, setting or code path that is gone, or when it uses
a word outside the catalog's vocabulary. --unlisted prints starting
entries. strip.py's report gains "Unclassified in the privacy
catalog": objects and fields new in an import and not classified,
informational like the Enterprise flags.

Tested: 13 unit tests (tools/fork/tests): the check passes on this
tree; fails on an unclassified object, an address hidden behind a
default, a secret in a set or object reference, stale properties,
objects, settings and code paths, an unlisted inbuxa object and a
word outside the vocabulary; --unlisted's entries; and the strip
report on a synthetic import. The check and the tests run in the
fork-checks job.
2026-09-28 06:54:34 -07:00
jcoffey-dev 09c55ba503 Merge pull request 'Stop webhooks sending every event, message content included' (#82) from fix/webhook-event-levels into main
ci / fork-checks (push) Successful in 13s
ci / build (push) Successful in 38m0s
2026-09-28 13:44:51 +00:00
jcoffey-dev eac3db34e9 Principal get test: expect legacyAllowed
ci / fork-checks (pull_request) Successful in 12s
ci / build (pull_request) Successful in 1h18m28s
The per-protocol switches (#79) added legacyAllowed to the account's
urn:inbuxa:jmap capability, but this expectation wasn't updated, so
jmap_tests stopped here and the suites after it never ran.
2026-09-28 06:42:08 -07:00
jcoffey-dev 6945714aa9 Stop webhooks sending every event, message content included
ci / fork-checks (pull_request) Successful in 45s
ci / build (pull_request) Successful in 5m42s
A webhook has a level (info by default) that nothing read: its events
were chosen by its list and policy alone. With the default policy,
exclude, and nothing listed, that meant every event type, including
smtp.raw-input (the raw SMTP bytes, DATA included) and the model's
reply to the spam classifier. The docs suggest a webhook to pass the
audit log to a SIEM; set up that way it would have received whole
messages. Found by the personal-data catalog investigation (finding 1).

Now an include list is sent as named, whatever each event's level:
naming an event is the choice. Otherwise a webhook gets only events at
or above its level, as a tracer does, and never a protocol's raw input
or output (IMAP, SMTP, POP3, ManageSieve, delivery, milter), which
carries whole messages and credentials; those go out only when named.

Tested: unit tests for the rule (level, raw I/O only when named, a
named event below the level, custom event levels, a webhook's own
errors); the telemetry system test, whose webhook names debug-level
connection events and still receives them.
2026-09-28 06:38:37 -07:00
jcoffey-dev b2453d066b Merge upstream v0.16.24
Eight conflicted files resolved, plus the lock file and the schema:

- crates/services/src/task_manager/spam_classifier.rs: upstream's rules
  update now replaces existing rules, DNSBL servers, lookups and file
  extensions, keeping only whether each is on. Taken, with one difference:
  an object an admin edited is kept as it is. Every object an update writes
  is fingerprinted (content without `enable`, SHA-256, stored under
  SUBSPACE_INBUXA "Sf"), and only one that still matches is replaced.
  Scores are never replaced, as upstream has it. The AU-1.10 summary record
  now names what was added, replaced and kept, and the bundled rules are
  marked applied only when the update fully succeeded, so a failure runs
  again on the next start. The marker becomes "3.0.2+2", which runs the
  update once on upgrade to fingerprint every rule still as bundled.
- crates/common/src/network/autoconfig/autodiscover.rs: upstream's rewrite
  (implicit TLS first, labeled SSL), with the per-protocol switches (LP-7,
  LP-14a) passed in as a filter.
- crates/store/src/backend/mysql/{search,write}.rs: upstream's chunked
  deletes (no unbounded first DELETE, stop on a short chunk, halve the
  chunk on the new chunk-too-large errors) inside the fork's query timeout.
- crates/smtp/src/lib.rs: the fork's queue spawn kept. It already fixed the
  stall upstream fixes here (a node without outboundMta stops accepting
  mail at about 1024 queued messages), and follows role changes live.
- crates/jmap/src/registry/mapping/bootstrap.rs: the log path stays
  /var/log/inbuxa/; upstream's PowerDNS mapping taken.
- crates/main/Cargo.toml: the AGPL-only license kept, version 0.16.24.
- tests/src/jmap/principal/get.rs: the fork's capabilities kept.
- resources/schema/schema.json.gz: merged as JSON; upstream relabeled the
  vendor Sieve extensions "(Stalwart)", kept as "(vnd.inbuxa)".
- Cargo.lock: upstream's, with the fork's crates added by Cargo.

Also:

- tests/src/smtp/inbound/spam_rules_kept.rs: an edited rule survives an
  update, an unedited one is updated, rules from before fingerprints are
  handled, and the audit summary says so. Upstream's own spam_rules test
  passes unchanged.
- tests/src/smtp/reporting/reschedule.rs moves to port 19058; upstream's
  new spam_rules test took 19057.
- tools/fork/renames.py renames the "(Stalwart)" labels and the default
  log path, so neither conflicts again.
- tools/fork/notice-check.py compares against the newest snapshot in the
  checked-out history instead of the upstream branch head, so moving the
  branch no longer fails other open pull requests.
- tests/src/directory/issuer.rs (since v0.16.23) stays out, and is on the
  build check's known list: it tests issuer-based directory routing, which
  the fork doesn't have (DIR-2).
- Strip report: docs/fork/strip-reports/v0.16.24.{md,json}.
2026-09-28 06:30:20 -07:00
jcoffey-dev f59b084ce5 Import upstream v0.16.24, stripped
Upstream commit: af37a234981722493b74623a983581691d2b70b6
Enterprise-only files removed or emptied: 63
Enterprise-only snippets removed: 118 in 50 files
Dangling module declarations removed: 5
Edits turning enterprise off: 25
Third-party code: 14 files, 0 not in THIRD-PARTY.md
Renamed identifiers: 62 in 18 files
Verification: clean

The same Enterprise footprint as v0.16.23. The build check fails only on
tests/src/directory/issuer.rs, unchanged since v0.16.23: it calls a helper
from upstream's Enterprise-only OIDC test, and tests issuer-based directory
routing, an Enterprise feature. main has never carried it.
2026-09-28 06:29:38 -07:00
jcoffey-dev 85ea0c80e9 Merge pull request 'Spec: personal-data catalog, compliance role, Overview and Data inventory' (#81) from spec/personal-data-catalog into main
ci / fork-checks (push) Successful in 47s
ci / build (push) Canceled after 39m47s
2026-09-28 13:05:02 +00:00
jcoffey-dev a588a8aa7d Spec: record John's answers to the personal-data catalog questions
ci / fork-checks (pull_request) Successful in 15s
ci / build (pull_request) Successful in 7m25s
The sidecar catalog; the Compliance Officer places and releases holds;
the Tenant Compliance Officer is built now; shortening audit retention
is recorded and surfaced, not gated on a second person; all seven
new-install defaults, in Phase 3; the webhook finding fixed now as a
bug; snapshots kept as long as the audit log.
2026-09-28 05:57:24 -07:00
jcoffey-dev 35cf3f405f Spec: personal-data catalog, compliance role, Overview and Data inventory
ci / fork-checks (pull_request) Successful in 50s
ci / build (pull_request) Successful in 11m33s
Phase 1 of the GDPR auditor foundation: the investigation and the
design, committed before anything is built (SPEC.md §3 rule 3).

It maps every place the server stores or sends personal data found
in the code at de275ba, each with its categories, whose data it is,
the settings that control it, what bounds its retention, where it
lives, whether it leaves the host, its scope and the code that writes
it, and the default in a new install. It proposes a sidecar catalog
(resources/privacy/catalog.toml), since the schema and registry code
are upstream's generated output with no generator here; a CI check
modeled on name-check.py; a strip-report section; a read-only
inventory method with dated snapshots; a Compliance Officer role; and
the Compliance navigation with Overview and Data inventory.

Findings worth reading on their own: webhooks ignore levels and, at
their defaults, receive every event including raw SMTP input; log
files are never deleted; automatic bans never expire; some of the
fork's records outlive the account; spam training keeps whole
messages for 180 days; traces are on in a new install; the spam
filter sends IPs, domains, hashed addresses and body digests to
third-party services by default.

Proposed default changes (new installs only) and seven open questions
are for John to decide. No default is changed.
2026-09-28 01:36:57 -07:00
jcoffey-dev de275bac60 Merge pull request 'Release 2026.9.28.3' (#80) from release-2026.9.28.3 into main
ci / fork-checks (push) Successful in 1m1s
publish / version (push) Successful in 56s
publish / publish-amd64 (push) Successful in 30m35s
publish / release (push) Successful in 6s
ci / build (push) Successful in 32m44s
publish / publish-arm64 (push) Successful in 36m4s
publish / binaries (push) Successful in 35s
publish / announce (push) Successful in 22s
2026-09-28 07:23:19 +00:00
jcoffey-dev 305406a331 Release 2026.9.28.3
ci / fork-checks (pull_request) Successful in 14s
ci / build (pull_request) Successful in 7m25s
Per-protocol legacy switches (#79) and the hold export's exceptions
list (#75). The prepared Explain answers are relabeled for this
release; 706 carry over unchanged.
2026-09-28 00:15:33 -07:00
jcoffey-dev f5888d79b0 Merge pull request 'Give IMAP, POP3 and ManageSieve a switch each' (#79) from feature/per-protocol-switches into main
ci / fork-checks (push) Successful in 38s
ci / build (push) Successful in 35m58s
2026-09-28 06:32:41 +00:00
jcoffey-dev 8e9cedbe97 Give IMAP, POP3 and ManageSieve a switch each
ci / fork-checks (pull_request) Successful in 43s
ci / build (pull_request) Successful in 7m40s
The legacy-protocols switch was all or nothing. An operator can now stop
POP3 and keep IMAP: each of IMAP, POP3 and ManageSieve has its own
switch, server-wide on inbuxa:ProtocolPolicy and per tenant on
inbuxa:TenantProtocolPolicy (properties imap, pop3, manageSieve).

legacyProtocols stays as the kill-all: setting it sets all three, and it
reads "disabled" exactly when all three are off. A policy stored before
this has only legacyProtocols and reads as all three at that value, so
existing servers and tenants carry over unchanged. In one /set, a
protocol named beside legacyProtocols overrides it.

SMTP submission keeps no switch of its own: sign-in over it is refused
only when all three are off, as the single switch did (LP-6), so
turning one protocol off never stops a mail app sending. For a tenant,
the server's switches and the tenant's count together.

Server-wide, a change closes the listeners of whatever is now off and
puts back the saved listeners of whatever is on again, both in one
change if asked; listeners of a protocol still off stay saved. Sign-in,
autoconfig, autodiscover, PACC (now prepared once per combination) and
the suggested DNS records all follow each protocol separately. A tenant
may turn a protocol on only while the server has it on (LP-9), and the
refusal names which. The JMAP session adds legacyAllowed, the protocols
still allowed for the account; legacyProtocols there keeps its meaning
for older webmail builds. Events name the switches ("pop3 disabled"),
and audit before/after reads every switch even from an older policy.

Tested: unit tests for the switches, the old-policy reading, the
server/tenant combination, the tenant refusal and listener refusal; and
tests/e2e/legacy_protocols.py against a running server, all 100 checks,
including new ones: POP3 alone off closes only its port and refuses
only its sign-in while IMAP and sending go on; only POP3 stops being
advertised; one change closes IMAP and reopens POP3; a tenant turns
POP3 off for itself, and can't turn IMAP on while the server has it off.
2026-09-27 23:12:32 -07:00
jcoffey-dev 5ba54e8fb7 Merge pull request 'List what a hold export can't read instead of skipping it (LH-12)' (#75) from fix/hold-export-exceptions into main
ci / fork-checks (push) Successful in 54s
ci / build (push) Canceled after 23m21s
Reviewed-on: #75
2026-09-28 06:09:20 +00:00
jcoffey-dev db817dd507 Merge pull request 'Release 2026.9.28.2' (#77) from release-2026.9.28.2 into main
publish / version (push) Successful in 31s
ci / fork-checks (push) Successful in 52s
ci / build (push) Canceled after 9m20s
publish / publish-amd64 (push) Successful in 34m25s
publish / release (push) Successful in 45s
publish / publish-arm64 (push) Successful in 36m5s
publish / binaries (push) Successful in 34s
publish / announce (push) Successful in 22s
2026-09-28 05:59:59 +00:00
jcoffey-dev b7e3a765ca Release 2026.9.28.2
ci / fork-checks (pull_request) Successful in 56s
ci / build (pull_request) Successful in 5m22s
2026-09-27 22:54:18 -07:00
jcoffey-dev 7ba9ec9fa0 Merge pull request 'Send "none" instead of "pass" as the DMARC report disposition' (#76) from fix/dmarc-disposition-compat into main
ci / build (push) Canceled after 11m35s
ci / fork-checks (push) Successful in 15s
2026-09-28 05:48:22 +00:00
jcoffey-dev 4c07779c16 Merge pull request 'Recheck DNSSEC lookups that hickory wrongly calls bogus' (#72) from fix/dnssec-insecure-fallback into main
ci / fork-checks (push) Successful in 2m2s
ci / build (push) Canceled after 14m59s
2026-09-28 05:33:21 +00:00
jcoffey-dev e1e8a9aeb0 Send "none" instead of "pass" as the DMARC report disposition
ci / build (pull_request) Successful in 16m34s
ci / fork-checks (pull_request) Successful in 52s
Cloudflare's DMARC report intake rejects every aggregate report we
send with "555 5.7.1 invalid_report_schema". Bisected against the live
endpoint: the only element it objects to is <disposition>pass</disposition>,
the value RFC 9990 added for mail that passed DMARC under an enforcing
policy. The RFC 9990 namespace, <np>, <discovery_method>, <testing> and
a missing <pct> are all accepted, and a report that differs only in
using "none" there goes through.

"none" (no action taken) is valid under both RFC 9990 and RFC 7489 and
says the same thing to the reader, so reports now go out with it. The
stored report keeps "pass"; only the serialized copy changes.
2026-09-27 22:31:13 -07:00
jcoffey-dev 5c506b9d2b List what a hold export can't read instead of skipping it (LH-12)
ci / fork-checks (pull_request) Successful in 49s
ci / build (pull_request) Successful in 11m32s
An item the hold covers whose stored record or content can't be read
goes in exceptions.csv with the path it would have had and the reason,
rather than being left out silently. The file is always in the ZIP, so a
header-only one shows nothing was missed, and manifest.sha256 carries
its hash beside the manifest's.
2026-09-27 22:15:05 -07:00
jcoffey-dev 3978cf5785 Merge pull request 'Release 2026.9.28.1' (#74) from release-2026.9.28.1 into main
ci / build (push) Canceled after 29m44s
ci / fork-checks (push) Successful in 14s
publish / version (push) Successful in 32s
publish / publish-amd64 (push) Successful in 28m55s
publish / release (push) Successful in 15s
publish / publish-arm64 (push) Successful in 1h2m48s
publish / binaries (push) Successful in 51s
publish / announce (push) Successful in 23s
2026-09-28 05:03:38 +00:00
jcoffey-dev 815a642cc4 Release 2026.9.28.1
ci / fork-checks (pull_request) Successful in 16s
ci / build (pull_request) Successful in 7m29s
Legal hold exports (LH-12, #73). The prepared Explain answers are
relabeled for this release; 706 carry over unchanged.
2026-09-27 21:55:55 -07:00
jcoffey-dev 1d5f4a2cd3 Merge pull request 'Export what a legal hold keeps as a ZIP (LH-12)' (#73) from feature/hold-export into main
ci / fork-checks (push) Successful in 50s
ci / build (push) Canceled after 12m21s
2026-09-28 04:51:16 +00:00
jcoffey-dev 68dd749291 Export what a legal hold keeps as a ZIP (LH-12)
ci / build (pull_request) Successful in 4m47s
ci / fork-checks (pull_request) Successful in 14s
inbuxa:HoldExport/set takes a hold, optionally some of the accounts it
covers, and a reason; the collection runs in the background and get
says when it's ready. The ZIP has, per account, mail as .eml under its
folders, calendars as .ics, contacts as .vcf, files as stored, and the
archived items the hold keeps under archived/; a manifest.csv gives each
entry's account, kind, folder, date, whether it was archived, size and
SHA-256, and manifest.sha256 hashes the manifest. Accounts the hold
doesn't cover are left out, and items outside its date range are too:
live mail by arrival, events by start, and archived items the same way,
so an export doesn't carry deleted items that only another hold keeps.

The finished file is a blob of whoever started the export, so only they
download it, and it lasts as long as any upload (uploadTtl). Exports
are records under the hold (SUBSPACE_INBUXA H/e): never changed or
destroyed, each with its status, counts, size and checksum. Starting
one needs sysLegalHoldExport, an active hold and a reason, and is
recorded in the audit log like the audit log's own export.

The build is in memory and capped at 2 GB; bigger holds fail with a
message saying so, and are split by picking accounts.

Tested: unit tests for safe ZIP names and the manifest and its hash;
the legal_hold system test, on RocksDB, PostgreSQL and MySQL, exports a
hold end to end (live and archived mail, the manifest's hash, an asked-
for account the hold doesn't cover left out) and checks the refusals
(no reason, a user without the permission, a released hold) and the
audit record; and by hand from the console on a local server. Not
covered by a test: the archived-item date range with two holds of
different ranges over one account.
2026-09-27 21:45:52 -07:00
jcoffey-dev b1bc5ed6e0 Recheck DNSSEC lookups that hickory wrongly calls bogus
ci / fork-checks (pull_request) Successful in 14s
ci / build (pull_request) Successful in 7m34s
hickory 0.26.3 rejects two kinds of valid answers, and outbound
delivery then retries those hosts until the message expires:

- A zone delegated beneath an unsigned zone (l.google.com under
  google.com). Proving the delegation insecure needs an SOA record in
  the DS reply, and public resolvers often leave it out. Every Google
  MX host behind a signed MX record was unreachable.
- A signed CNAME to a signed name that lacks the queried type. The
  NSEC denial is checked against the original name, not the target's.

On a bogus verdict, follow a signed CNAME and repeat the lookup at its
target; otherwise look up the name's zone and its parents, nearest
first. A zone that validates as unsigned means nothing below it can be
signed, so the plain resolver answers and the result is insecure. A
zone that validates as signed first leaves the verdict standing.
2026-09-27 21:45:13 -07:00
jcoffey-dev b074c73219 Merge pull request 'Release 2026.9.28' (#71) from release-2026.9.28 into main
publish / publish-amd64 (push) Successful in 25m6s
publish / release (push) Successful in 9s
publish / publish-arm64 (push) Successful in 36m18s
publish / binaries (push) Successful in 34s
publish / announce (push) Successful in 34s
ci / build (push) Canceled after 1h33m5s
publish / version (push) Successful in 10s
ci / fork-checks (push) Successful in 54s
2026-09-28 03:18:09 +00:00
jcoffey-dev 3046c418cd Release 2026.9.28
ci / fork-checks (pull_request) Successful in 50s
ci / build (pull_request) Successful in 13m2s
Legal holds (#70): a hold on people, groups, domains, tenants or the
whole server keeps everything it covers from being destroyed, by anyone,
until it's released; deleted accounts keep their data. Audit records
name accounts by their full address and holds by their case name. The
daily clean-up of expired archived items works again.

Prepared Explain answers relabeled for this release; no setting changed
since 2026.9.27.2, so all 706 carry over.
2026-09-27 20:04:44 -07:00
jcoffey-dev faeb1fed86 Merge pull request 'Legal holds (phase 3)' (#70) from feature/legal-hold into main
ci / fork-checks (push) Successful in 1m12s
ci / build (push) Canceled after 17m24s
2026-09-28 03:00:43 +00:00
jcoffey-dev c1b5bf956c Audit records name accounts in full, and holds by name
ci / build (pull_request) Successful in 6m24s
ci / fork-checks (pull_request) Successful in 1m17s
An account's or mailing list's name is only its local part, so the log
said "Account ken.gosling" where two domains could each have one; it
now says [email protected]. A change to a legal hold was
recorded under its id; the hold's current state is now read first, so
the record carries its case name and each change reads before/after.
2026-09-27 19:33:07 -07:00
jcoffey-dev 3217aae4e8 LegalHold/get takes coveringAccount
Only the active holds covering one account, live or deleted and kept,
through any route: for the console's Held badge (LH-14).
2026-09-27 19:33:07 -07:00
jcoffey-dev 538ae107d7 Legal holds, step 6: what each hold keeps
inbuxa:LegalHold/get answers accountsCovered, itemsHeld and sizeHeld
when asked: the accounts a hold reaches now (deleted ones it keeps
included) and the archived items it keeps, with their size. Worked out
in one pass over accounts and archive, only for requests that name them.
Held items stay out of the user's quota, as all archived copies do
(LH-9).
2026-09-27 19:33:07 -07:00
jcoffey-dev 39707cd2e8 Legal holds, step 5: held accounts can't be destroyed
Destroying a held account removes the login, as offboarding needs, but
keeps its data as a deleted account with no expiry, whether or not
undelete keeps accounts; its addresses stay reserved and its holds name
it from then on. Destroy-now refuses it, and its DestroyAccount task
defers itself while it's held or its time hasn't come. Holds placed or
released later freeze or free kept accounts in the same settle pass,
with 30 days' grace after the last release (LH-8, LH-10).
2026-09-27 19:33:07 -07:00
jcoffey-dev 8d3e99bc00 Legal holds, step 4: freezing, release, and the audit log
Placing or widening a hold freezes what's already archived in its scope
and range, its old deadline noted; releasing one gives each item no other
hold covers that deadline back, or release plus 30 days if later. One
pass over the archive does both and changes nothing twice (LH-6, LH-10,
LH-11). A held archived item can't be destroyed; restoring still can,
and the hold is named only to callers who may see holds (LH-7). Audit
records about a held account survive the purge (AU-7).

Fixes the daily clean-up of expired archived items (UD-13), which never
found any: the registry's unfiltered query reads an all-ids index that
archived items aren't in. Items are now walked account by account, kept
deleted accounts included. Expired items were still removed whenever
their account's archive was read.
2026-09-27 19:33:07 -07:00
jcoffey-dev 7b97efbb7f Legal holds, step 3: deleted items in a held account are kept
Every way of deleting mail (JMAP, IMAP EXPUNGE, POP3, mailbox removal,
Trash emptying) and Sieve scripts, events, contacts and files now asks
how the account's deletions are kept: a hold keeps them with no expiry
(archivedUntil 9999-12-31), even with undelete off; otherwise undelete's
period applies as before (LH-4).

A hold's date range decides by the item's own date (LH-3). Mail is noted
as held at deletion and settled when it's archived, once its received
date is known; outside the range it gets undelete's deadline or isn't
kept. Events go by their start, with a day's slack for time zones;
recurring events, contacts, files and scripts are held whole.

A groupware item's note now stays until its archive succeeds, and a
failure retries the task instead of being logged and lost (LH-5).
2026-09-27 19:33:07 -07:00
jcoffey-dev 318783f444 Legal holds, step 2: who a hold covers
A hold reaches an account by name, through any of its addresses'
domains, its groups or its tenant, as they are now, so an account added
to a held domain later is held too. An account that leaves a held
domain, group or tenant stays held: the registry write hook adds it to
the hold by name on every account change, whoever makes it (LH-2).
Server::holds_on answers for the deletion paths, from the store each
time so a hold binds every node at once.
2026-09-27 19:33:06 -07:00
jcoffey-dev 5d2e35b2dc Legal holds, step 1: the hold itself
inbuxa:LegalHold get/set places a hold on accounts, groups, domains,
tenants or the whole server, with an optional date range. A hold's range
and scope can only widen, a released hold is read-only, and none is ever
deleted. Placing, changing and releasing each need a reason and are
audited (LH-1, LH-3, LH-10, AU-12).

Permissions 669-672 (see, place, widen or release, export held data)
go to server administrators only; the tenant ceiling always strips them,
as it does Impersonate (LH-13). Schema: Compliance > Legal Holds.

What a hold keeps comes next, through the undelete hooks.

Also moves the lock expiry helpers below the lock module's imports.
2026-09-27 19:33:06 -07:00
jcoffey-dev 621ebdff74 Merge pull request 'Release 2026.9.27.2' (#69) from release-2026.9.27.2 into main
publish / publish-arm64 (push) Successful in 39m17s
publish / binaries (push) Successful in 33s
publish / announce (push) Successful in 23s
ci / fork-checks (push) Successful in 14s
publish / version (push) Successful in 32s
publish / publish-amd64 (push) Successful in 25m41s
publish / release (push) Successful in 1s
ci / build (push) Successful in 37m4s
2026-09-28 01:35:26 +00:00
jcoffey-dev 355bd3a40e Release 2026.9.27.2
ci / fork-checks (pull_request) Successful in 1m23s
ci / build (pull_request) Successful in 7m16s
Delegates reach the whole locked account (#68): its calendars, contacts
and files as well as its mail, even a kind it holds none of yet, and
writing delegates may add at the top of its Files.

Prepared Explain answers relabeled for this release; no setting changed
since 2026.9.27.1, so all 706 carry over.
2026-09-27 18:27:33 -07:00
jcoffey-dev f7a63b9ed0 Merge pull request 'Delegates reach the whole locked account' (#68) from fix/delegate-whole-account into main
ci / fork-checks (push) Successful in 48s
ci / build (push) Canceled after 12m39s
2026-09-28 01:22:48 +00:00
jcoffey-dev 9f6761c9dd Writing delegates may add at the top of a locked account's Files
ci / fork-checks (pull_request) Successful in 17s
ci / build (pull_request) Successful in 17m56s
A shared account refuses top-level folders, so an organize or full
delegate couldn't add anything to a locked account with no folders. A
delegate who may write now can, as the owner could; the reconcile after
the create grants it the new folder. Read delegates still can't (AL-6,
AL-7).
2026-09-27 18:04:24 -07:00
jcoffey-dev d4d127fa7d Delegates reach the whole locked account
ci / build (pull_request) Canceled after 5m27s
ci / fork-checks (pull_request) Successful in 14s
A delegate's token listed the locked account only for kinds of data it
held grants on, so one with no files (or no calendar) was refused to the
delegate outright: "You do not have access to account". The token now
lists the locked account for mail, calendars, contacts and files alike,
so an empty kind reads as empty. What the delegate may see or change is
still each container's grant (AL-7).
2026-09-27 17:58:50 -07:00
jcoffey-dev 7720a57ac9 Merge pull request 'Release 2026.9.27.1' (#67) from release-2026.9.27.1 into main
publish / publish-amd64 (push) Successful in 28m13s
ci / build (push) Successful in 34m51s
publish / release (push) Successful in 2s
publish / publish-arm64 (push) Successful in 42m7s
publish / binaries (push) Successful in 39s
publish / announce (push) Successful in 22s
publish / version (push) Successful in 28s
ci / fork-checks (push) Successful in 14s
2026-09-27 23:43:31 +00:00
jcoffey-dev 30ea43d019 Release 2026.9.27.1
ci / fork-checks (pull_request) Successful in 13s
ci / build (pull_request) Successful in 7m33s
The audit log (#64): every administrator change, admin sign-in and look
into someone else's data, recorded before it happens, chained per node
and checkable for tampering, exportable with a manifest, kept 2 years.

Locked accounts (#65, #66): an account that keeps receiving mail but
can't sign in and sends nothing on its own, handed to delegates at read,
organize or full, ending at a date when one is set.

Prepared Explain answers relabeled for this release; no setting changed
since 2026.9.27, so all 706 carry over.
2026-09-27 16:35:42 -07:00
jcoffey-dev dd3eec3936 Merge pull request 'End a locked account's delegation at its date' (#66) from fix/delegation-until into main
ci / fork-checks (push) Successful in 1m1s
ci / build (push) Canceled after 12m1s
2026-09-27 23:31:30 +00:00
jcoffey-dev a36236efff End a locked account's delegation at its date
ci / fork-checks (pull_request) Successful in 44s
ci / build (pull_request) Successful in 4m59s
A delegation with an end date dropped out of the delegate's token then,
but its folder grants stayed until the daily sweep, so the delegate kept
the account as an ordinary share for up to a day. Each node now sleeps
until the soonest end date, woken early by any lock write and at least
hourly, and re-applies that lock under a cluster-wide claim.

The sweep also had a second-run bug: a delegation past its date gave the
delegate back its earlier share, then dropped the note, so the next sweep
removed that share entirely. The note is now kept while the delegate is
still listed.
2026-09-27 16:26:04 -07:00
jcoffey-dev 224597cab2 Merge pull request 'Locked accounts: keep receiving mail, no sign-in, hand to delegates' (#65) from feature/account-lock into main
ci / fork-checks (push) Successful in 14s
ci / build (push) Canceled after 35m53s
2026-09-27 22:55:36 +00:00
jcoffey-dev 447229f871 Lock accounts: keep receiving mail, no sign-in, hand to delegates
ci / fork-checks (pull_request) Successful in 1m4s
ci / build (pull_request) Successful in 8m47s
A locked account can't sign in (it fails as a wrong password does), its
sessions end on every node, refresh tokens stop working, and its Sieve
scripts forward and reply to nothing. Mail keeps arriving.

Delegates get real ACL grants on the account's mailboxes, calendars,
address books and files at read, organize or full, with the rights they
replaced restored on unlock. Folders made later are granted after the
create and in a daily sweep. Organize delegates can't destroy; send-as
needs organize or full. The JMAP session marks delegated accounts in
urn:inbuxa:jmap.

New inbuxa:AccountLock object with get/set, permissions 665-668, and a
Compliance > Locked Accounts entry in the schema. Lock, unlock and
delegate changes need a reason and are audited; delegate access and
writes are audited too (audit-hold-lock spec AL-1 to AL-12).
2026-09-27 14:46:06 -07:00
jcoffey-dev ebf2fe11d9 Merge pull request 'Audit log: a permanent, tamper-evident record of admin actions' (#64) from feature/audit-log into main
ci / fork-checks (push) Successful in 1m22s
ci / build (push) Successful in 21m54s
2026-09-27 21:45:50 +00:00
jcoffey-dev 86d7ebd982 Audit log: a permanent, tamper-evident record of admin actions
ci / fork-checks (pull_request) Successful in 52s
ci / build (pull_request) Successful in 1h4m15s
What administrators and the server itself do to the control plane is now
recorded, from inbuxa-drafts/specs/audit-hold-lock.md (AU-1 to AU-12):
settings, accounts, domains, roles and every other registry change, with
each field's before and after (secrets only as "changed"); the fork's own
settings objects; administrator sign-ins (and failed ones to administrator
accounts), master-user and recovery-admin sign-ins, once an hour per
account, method and address; access to another account's data through
impersonation or FetchAnyBlob, once an hour; exports and tamper checks;
and registry writes the server makes on its own, named by subsystem
(system:AcmeRenewal, system:auto-ban, system:directory-sync, ...), with a
spam rules update as one summary record.

No change without its record (AU-3): before a set method changes anything,
a pending record per requested create, update and destroy is written; if
that fails, the method is refused with serverFail. Its outcome follows as
a later entry. A change interrupted by a crash stays "unfinished".

Records live in the fork's subspace under L, as one SHA-256 hash chain per
node. The chain's head is stored, never cached, and every append asserts
it, so two writers can't take the same place. Nothing can edit or delete
a record; the daily purge removes the oldest past the retention (default
730 days, minimum 90) and records where the chain now starts, so
verification still passes. security.audit-recorded (647) copies each
record to webhooks, OpenTelemetry and the log; security.audit-write-failed
(648) reports a failed write.

New JMAP objects under urn:inbuxa:jmap: inbuxa:AuditEvent/get and /query
(filters: time, actor, action, target, account, tenant, outcome, address,
text), inbuxa:AuditSettings, inbuxa:AuditExport (CSV or JSON Lines built
on the server, each line with its chain hash, ending in a manifest; the
created object names the blob and its SHA-256) and
inbuxa:AuditVerification. New permissions sysAuditGet, sysAuditExport and
sysAuditSettingsUpdate: the Administrator role gets all three, the Tenant
Administrator role gets read and export, once, on existing installs too.
A tenant administrator sees records whose actor or target is in its
tenant, including a server administrator's changes there.

Sign-in method on the session: access tokens now remember how they signed
in (password, app password, API key, OAuth client, directory, master user,
recovery admin), including across the HTTP credential cache. New OAuth
access tokens carry their client id in the sealed claims; older ones show
as client "unknown" until they expire.

The schema gains the permissions, the two events and a Management >
Compliance > Audit Log link.

Stack: the request layer boxes every inner future where it's made. Without
that, a debug build overflowed the default 2 MB worker stack on a registry
set; measured with the same request, the branch and main now overflow at
the same stack size (between 1856 and 1920 KiB, debug), so the layer adds
nothing measurable.

Tests: unit tests in inbuxa-features and jmap; system::audit::audit_log_tests
(run with --ignored) passes on RocksDB, SQLite, PostgreSQL, PostgreSQL with a
read replica, MySQL, MySQL with a replica and FoundationDB. The system, JMAP
and SCIM suites pass. authorization.rs skipped fork permissions that guard
no registry object; the audit suite checks a plain user is refused instead.
2026-09-27 13:40:12 -07:00
jcoffey-dev d3ebfb79f9 Merge pull request 'Release 2026.9.27' (#63) from release-2026.9.27 into main
ci / fork-checks (push) Successful in 28s
publish / version (push) Successful in 29s
publish / publish-amd64 (push) Successful in 24m11s
publish / release (push) Successful in 1s
ci / build (push) Successful in 35m44s
publish / publish-arm64 (push) Successful in 35m26s
publish / binaries (push) Successful in 33s
publish / announce (push) Successful in 22s
2026-09-27 05:18:54 +00:00
jcoffey-dev 833e6871f7 Release 2026.9.27
ci / fork-checks (pull_request) Successful in 45s
ci / build (pull_request) Successful in 4m51s
inbuxa's own mark (#62): the kitten over a server with a bay for each
piece of the suite, on the built-in sign-in and RSVP pages, the web
logo and the email logo.

Prepared Explain answers relabeled for this release; no setting changed
since 2026.9.26.1, so all 706 carry over.
2026-09-26 22:13:54 -07:00
jcoffey-dev 056bbb179d Merge pull request 'Brand: inbuxa own kitten replaces ihasmail cat' (#62) from brand/new-mark into main
ci / fork-checks (push) Successful in 53s
ci / build (push) Canceled after 6m7s
2026-09-27 05:12:44 +00:00
jcoffey-dev d7182f4511 Brand: inbuxa's own kitten replaces ihasmail's cat
ci / fork-checks (pull_request) Successful in 43s
ci / build (pull_request) Successful in 3m18s
inbuxa's mark was ihasmail's cat-and-envelope reused unchanged. The new
one keeps the family's face, paws and colors, over a server with a bay
for each piece of the suite: the letter (webmail), a prompt (console),
status lights (server).

- The built-in sign-in and calendar RSVP pages, and the web logo, drew
  the old cat as an embedded PNG. They now draw the mark as vector in
  the same slot, keeping class="symbol"; each page is about 31 KB
  lighter. The .min copies are updated the same way and the .min.gz
  regenerated with gzip -9 -n, as minify_html.sh does.
- resources/branding: email-logo.png (the compact lockup at 380x80 on
  white, as before) with its .b64 regenerated byte-for-byte in the old
  76-column form, and favicon-64.png.
- img/brand: the logo bundle, now pure vector, with its README.
2026-09-26 22:05:17 -07:00
jcoffey-dev 055752f3a3 Merge pull request 'Announce releases on the community forum' (#61) from announce-releases into main
ci / fork-checks (push) Successful in 1m19s
ci / build (push) Successful in 1h28m25s
2026-09-27 02:40:21 +00:00
jcoffey-dev 07557ba8e2 Announce releases on the community forum
ci / fork-checks (pull_request) Successful in 45s
ci / build (pull_request) Successful in 6m11s
announce.yml runs coffey-labs/actions discourse-release on every published
release, posting it to this project's Announcements category on
community.coffeylabs.org. The release workflow also announces
from its own job, since a release made with the job token fires no
'on: release' workflow in Gitea.
2026-09-26 19:28:04 -07:00
287 changed files with 32267 additions and 1697 deletions
+17
View File
@@ -0,0 +1,17 @@
# Announce each published release on the community forum, in this project's
# Announcements category (coffey-labs/actions discourse-release; the repo ->
# category map is its release-map.json). Safe to re-run: one topic per tag.
name: announce
on:
release:
types: [published]
jobs:
announce:
runs-on: light
steps:
- uses: coffey-labs/actions/discourse-release@e9293996e2efa770839121fa8f8da93083f216be
with:
api-key: ${{ secrets.DISCOURSE_RELEASE_KEY }}
discord-webhook: ${{ secrets.DISCORD_RELEASE_WEBHOOK }}
+10
View File
@@ -40,6 +40,16 @@ jobs:
# nothing. CI never sees the difference; a release does.
- if: always()
run: python3 tools/fork/context-check.py
# The personal-data catalog must classify every object and field the
# schema has, and name nothing that is gone.
- if: always()
run: python3 tools/fork/privacy-check.py
# The admin reads each expression field's allowed values and variables
# from the schema; they're generated from the registry and must match it.
- if: always()
run: python3 tools/fork/expr-schema.py --check
- if: always()
run: python3 -m unittest discover -s tools/fork/tests
build:
# Either runner (host1 or host2): the build needs no docker socket.
+13
View File
@@ -285,3 +285,16 @@ jobs:
PY
- if: always()
run: docker logout "$REGISTRY" || true
# The release above is made with the job's own token, and Gitea starts no
# workflow for events the Actions bot causes -- announce.yml's
# 'on: release' never fires for it -- so announce it from here.
announce:
needs: [release, binaries]
runs-on: light
steps:
- uses: coffey-labs/actions/discourse-release@e9293996e2efa770839121fa8f8da93083f216be
with:
api-key: ${{ secrets.DISCOURSE_RELEASE_KEY }}
discord-webhook: ${{ secrets.DISCORD_RELEASE_WEBHOOK }}
tag: ${{ github.ref_name }}
+33
View File
@@ -2,6 +2,39 @@
All notable changes to this project will be documented in this file. This project adheres to [Semantic Versioning](http://semver.org/).
## [0.16.24] - 2026-09-27
If you are upgrading from v0.16.x, replace the binary (or run `docker pull`). If you are upgrading from v0.15.x and below, please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md) for more information on how to upgrade from previous versions.
## Added
- DNS: PowerDNS Authoritative provider for automatic DNS record management.
## Changed
## Fixed
- Troubleshoot tool: `TLSA` records are looked up for every MX host, including hosts whose zone is not DNSSEC signed.
- Spam filter:
- OpenPhish and PhishTank entries containing uppercase characters never match, since message URLs are lowercased while HTTP lookup entries keep their original case. HTTP lookups now match keys case-insensitively.
- URL shortener links are followed using the lowercased URL, so case-sensitive short links resolve to the wrong destination or not at all.
- Incremental training never advances its position past the first run, so every retained sample added since then is trained again, and counted again in the reservoir, on each run until it expires.
- Updating the rules only adds new objects, so upstream changes to existing rules, DNSBL servers, HTTP lookups, lookup keys and file extensions never reach an existing installation.
- Updating the rules reports success when objects fail to import, or when a configuration error stops the updated settings from being activated.
- JMAP:
- A `PushSubscription` created within the verification rate limit window of another one on the same account never receives its `PushVerification`, since the blocked verification is dropped instead of being sent once the window expires.
- A push notification retried after a failed delivery can report an older state than a change queued during the failed attempt, since the older state changes are merged last and overwrite the newer ones.
- Changes made while a push request is in flight are not delivered until the next change reaches the same subscription, since a successful delivery cancels the pending retry.
- The VAPID `aud` claim is derived from a hand-written parse of the push URL, so a crafted push URL can make the server sign a token for a push service other than the one the request is sent to.
- `Email/import` rejects a `blobId` that refers to a `Blob/upload` creation id in the same request (`"#u0"`) with `Invalid blob id.`.
- `Email/set` with a full `mailboxIds` object identical to the current mailboxes, together with a keyword change, stores the message with IMAP UID 0, so IMAP clients stop seeing it.
- MTA:
- A node without the `outboundMta` role stops replying to `DATA` and to JMAP submissions once about 1024 messages have been queued on it.
- MX records are resolved through the DNSSEC-validating resolver even when DANE is disabled.
- A `DATA` stage Sieve script does not see headers added by milters or MTA hooks, and discards every milter and MTA hook change when it edits the message.
- MySQL: Range deletions and search index removals start with a single unbounded `DELETE` and switch to chunks only after a timeout.
- IMAP: `COPY` and `MOVE` fail with `NO [CONTACTADMIN]` when another session changes the same message at the same time.
- Autodiscover: Implicit TLS ports (993, 995, 465) are advertised with `<Encryption>TLS</Encryption>`, which Outlook reads as STARTTLS.
- HTTP: Idle keep-alive connections are never closed.
## [0.16.23] - 2026-09-21
If you are upgrading from v0.16.x, replace the binary (or run `docker pull`). If you are upgrading from v0.15.x and below, please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md) for more information on how to upgrade from previous versions.
Generated
+183 -177
View File
File diff suppressed because it is too large Load Diff
+1 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "common"
version = "0.16.23"
version = "0.16.24"
edition = "2024"
build = "build.rs"
+588
View File
@@ -0,0 +1,588 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! inbuxa: the audit log's server side (audit-hold-lock spec, AU-1 to
//! AU-11). The records, the chain and queries live in
//! `inbuxa_features::audit`; this is what needs the running server: the
//! node's id, account names, and the sign-in and access hooks.
use crate::{
Server,
auth::{AccessToken, AuthRequest, permissions::DefaultPermissions},
};
use directory::Credentials;
use inbuxa_features::hold::{self, Member};
use inbuxa_features::audit::{
Action, Actor, AuditLog, EntryId, Outcome, Record, Target, Via, diff, log, scope,
};
use registry::{
jmap::IntoValue,
schema::{enums::Permission, prelude::ObjectType},
types::EnumImpl,
};
use std::{future::Future, pin::Pin, sync::Arc, sync::OnceLock};
use store::{
Store,
registry::hook::{RegistryChange, RegistryWriteHook},
write::now,
};
use types::id::Id;
/// What kind of recorded access a dedupe key is for (AU-1.4, AU-1.6).
const KIND_ACCOUNT_ACCESS: u8 = 0;
const KIND_BLOB_ACCESS: u8 = 1;
const KIND_SIGN_IN: u8 = 2;
const KIND_SIGN_IN_FAILED: u8 = 3;
const KIND_DELEGATE_ACCESS: u8 = 4;
/// The permissions that make an account an administrator for AU-1.4: every
/// `sys*` permission a plain user doesn't get by default, and impersonation.
fn admin_permissions() -> &'static [Permission] {
static ADMIN: OnceLock<Vec<Permission>> = OnceLock::new();
ADMIN.get_or_init(|| {
let user = DefaultPermissions::default().user;
(0..Permission::COUNT)
.filter_map(|id| Permission::from_id(id as u16))
.filter(|permission| {
(permission.as_str().starts_with("sys") && !user.contains(permission))
|| matches!(
permission,
Permission::Impersonate | Permission::FetchAnyBlob
)
})
.collect()
})
}
/// Whether a session holds any administrator permission.
pub fn is_admin(token: &AccessToken) -> bool {
admin_permissions()
.iter()
.any(|permission| token.has_permission(*permission))
}
fn ms() -> u64 {
std::time::SystemTime::now()
.duration_since(std::time::UNIX_EPOCH)
.map_or(0, |d| d.as_millis() as u64)
}
/// A small, stable number for a sign-in's method and address, so repeated
/// sign-ins the same way are recorded once an hour (AU-1.4).
fn sign_in_key(via: Option<&Via>, ip: std::net::IpAddr) -> u32 {
use std::hash::{Hash, Hasher};
let mut hasher = ahash::AHasher::default();
via.hash(&mut hasher);
ip.hash(&mut hasher);
hasher.finish() as u32
}
impl Server {
fn audit(&self) -> &AuditLog {
&self.inner.data.audit
}
/// This node's chain.
pub fn audit_node(&self) -> u64 {
self.core.network.node_id
}
/// An account as an actor, named as it is now, which the record keeps
/// (AU-4).
pub async fn audit_actor(&self, token: &AccessToken) -> Actor {
let account_id = token.account_id();
Actor::account(
account_id,
self.audit_account_name(account_id).await,
token.tenant_id(),
)
}
pub async fn audit_account_name(&self, account_id: u32) -> String {
self.account(account_id)
.await
.map(|account| account.name.to_string())
.unwrap_or_else(|_| format!("account {}", Id::from(account_id)))
}
/// Writes a record to this node's chain. An error means nothing was
/// written: a change must then be refused (AU-3).
pub async fn audit_append(&self, record: &Record) -> trc::Result<EntryId> {
match self
.audit()
.append(self.store(), self.audit_node(), record)
.await
{
Ok(id) => {
trc::event!(
Security(trc::SecurityEvent::AuditRecorded),
Id = id.to_string(),
Type = record.action.as_str(),
AccountName = record.actor.name.clone(),
Details = describe_target(&record.target),
Result = record.outcome.as_str(),
);
Ok(id)
}
Err(err) => {
trc::event!(
Security(trc::SecurityEvent::AuditWriteFailed),
Type = record.action.as_str(),
AccountName = record.actor.name.clone(),
Details = describe_target(&record.target),
Reason = err.to_string(),
);
Err(err)
}
}
}
/// Writes the outcome of a record written as pending.
pub async fn audit_finish(&self, id: EntryId, outcome: Outcome) -> trc::Result<()> {
let result = outcome.as_str();
match self
.audit()
.finish(self.store(), self.audit_node(), id, ms(), outcome)
.await
{
Ok(_) => {
trc::event!(
Security(trc::SecurityEvent::AuditRecorded),
Id = id.to_string(),
Result = result,
);
Ok(())
}
Err(err) => {
trc::event!(
Security(trc::SecurityEvent::AuditWriteFailed),
Id = id.to_string(),
Reason = err.to_string(),
);
Err(err)
}
}
}
/// Records something that isn't a change (a sign-in, an access), where
/// a failed write is reported but stops nothing.
pub async fn audit_note(&self, record: Record) -> bool {
self.audit_append(&record).await.is_ok()
}
/// AU-1.4, AU-1.5: an administrator's sign-in, a master user's, or the
/// recovery administrator's, at most once an hour per account, method
/// and address. Using an OAuth or directory token isn't a sign-in: the
/// sign-in was on the server's own page, with a password.
pub async fn audit_sign_in(&self, req: &AuthRequest, token: &AccessToken) {
let via = token.origin();
let (actor, target) = match via {
None | Some(Via::OAuth { .. }) | Some(Via::Directory) => return,
Some(Via::Master { account_id, name }) => {
let target_id = token.account_id();
(
Actor {
account_id: *account_id,
name: name.clone(),
tenant_id: None,
},
Target {
kind: "account".into(),
id: Some(Id::from(target_id).to_string()),
name: Some(self.audit_account_name(target_id).await),
account_id: Some(target_id),
tenant_id: token.tenant_id(),
},
)
}
// The recovery admin is an account for the log's purposes, as
// its changes are: named, and signing in to itself
Some(Via::Recovery) => {
let actor = self.audit_actor(token).await;
let target = Target {
kind: "account".into(),
id: Some(Id::from(token.account_id()).to_string()),
name: Some(actor.name.clone()),
account_id: Some(token.account_id()),
tenant_id: None,
};
(actor, target)
}
Some(_) if is_admin(token) => {
let actor = self.audit_actor(token).await;
let target = Target {
kind: "account".into(),
id: Some(Id::from(token.account_id()).to_string()),
name: Some(actor.name.clone()),
account_id: Some(token.account_id()),
tenant_id: token.tenant_id(),
};
(actor, target)
}
Some(_) => return,
};
let actor_key = actor.account_id.unwrap_or(u32::MAX);
let key = sign_in_key(via, req.remote_ip);
if !self
.audit()
.first_access_this_hour(actor_key, key, KIND_SIGN_IN, now())
{
return;
}
let recorded = self
.audit_note(Record {
at: ms(),
actor,
via: via.cloned(),
remote_ip: Some(req.remote_ip),
action: Action::SignIn,
target,
changes: vec![],
details: None,
reason: None,
outcome: Outcome::success(),
})
.await;
if !recorded {
self.audit().forget_access(actor_key, key, KIND_SIGN_IN);
}
}
/// AU-1.4: a failed password sign-in to an administrator's account, at
/// most once an hour per account and address. Accounts that don't exist
/// or aren't administrators aren't recorded, so guessing doesn't fill
/// the log.
pub async fn audit_sign_in_failed(&self, req: &AuthRequest) {
let Credentials::Basic { username, .. } = &req.credentials else {
return;
};
// `target%master` fails as the master
let name = username.rsplit('%').next().unwrap_or(username);
let Ok(Some(account_id)) = self.account_id_from_email(name, false).await else {
return;
};
let Ok(token) = self.access_token(account_id).await else {
return;
};
let token = AccessToken::new_maybe_invalid(token);
if !is_admin(&token) {
return;
}
let key = sign_in_key(None, req.remote_ip);
if !self
.audit()
.first_access_this_hour(account_id, key, KIND_SIGN_IN_FAILED, now())
{
return;
}
let actor = self.audit_actor(&token).await;
let target = Target {
kind: "account".into(),
id: Some(Id::from(account_id).to_string()),
name: Some(actor.name.clone()),
account_id: Some(account_id),
tenant_id: token.tenant_id(),
};
if !self
.audit_note(Record {
at: ms(),
actor,
via: None,
remote_ip: Some(req.remote_ip),
action: Action::SignInFailed,
target,
changes: vec![],
details: None,
reason: None,
outcome: Outcome::refused("authenticationFailed", None),
})
.await
{
self.audit()
.forget_access(account_id, key, KIND_SIGN_IN_FAILED);
}
}
/// AU-1.6: access to another account's data through `Impersonate` (or a
/// blob through `FetchAnyBlob`), once an hour per session's account and
/// target. Access through a share or group membership isn't this: the
/// owner granted it.
pub async fn audit_foreign_access(&self, token: &AccessToken, target_id: u32, blob: bool) {
if target_id == token.account_id() || token.is_member_directly(target_id) {
return;
}
let kind = if blob {
KIND_BLOB_ACCESS
} else {
KIND_ACCOUNT_ACCESS
};
if !self
.audit()
.first_access_this_hour(token.account_id(), target_id, kind, now())
{
return;
}
let actor = self.audit_actor(token).await;
let target_tenant = self
.account(target_id)
.await
.ok()
.and_then(|account| account.id_tenant);
if !self
.audit_note(Record {
at: ms(),
actor,
via: token.origin().cloned(),
remote_ip: None,
action: if blob {
Action::BlobAccess
} else {
Action::AccountAccess
},
target: Target {
kind: "account".into(),
id: Some(Id::from(target_id).to_string()),
name: Some(self.audit_account_name(target_id).await),
account_id: Some(target_id),
tenant_id: target_tenant,
},
changes: vec![],
details: None,
reason: None,
outcome: Outcome::success(),
})
.await
{
self.audit()
.forget_access(token.account_id(), target_id, kind);
}
}
/// AU-1.10: from here on, registry writes the server makes on its own
/// are recorded. Installed once boot has written its defaults.
pub fn install_audit_hook(&self) {
self.registry().set_write_hook(Arc::new(SystemWrites {
data: self.store().clone(),
log: AuditLog::new(),
node: self.audit_node(),
}));
}
/// AL-9: a delegate reaching a locked account: its access once an hour,
/// and every change it makes there, one record per method call.
pub async fn audit_delegate(
&self,
token: &AccessToken,
locked_id: u32,
access: &str,
write: Option<&str>,
error: Option<&trc::Error>,
) {
let first = self.audit().first_access_this_hour(
token.account_id(),
locked_id,
KIND_DELEGATE_ACCESS,
now(),
);
if !first && write.is_none() {
return;
}
let actor = self.audit_actor(token).await;
let target = Target {
kind: "account".into(),
id: Some(Id::from(locked_id).to_string()),
name: Some(self.audit_account_name(locked_id).await),
account_id: Some(locked_id),
tenant_id: self
.account(locked_id)
.await
.ok()
.and_then(|account| account.id_tenant),
};
let mut records = Vec::new();
if first {
records.push(Record {
at: ms(),
actor: actor.clone(),
via: token.origin().cloned(),
remote_ip: None,
action: Action::AccountAccess,
target: target.clone(),
changes: vec![],
details: Some(format!("As a delegate ({access})")),
reason: None,
outcome: Outcome::success(),
});
}
if let Some(method) = write {
records.push(Record {
at: ms(),
actor,
via: token.origin().cloned(),
remote_ip: None,
action: Action::Update,
target,
changes: vec![],
details: Some(format!("{method} as a delegate ({access})")),
reason: None,
outcome: match error {
None => Outcome::success(),
Some(err) => Outcome::refused(
"error",
err.value_as_str(trc::Key::Details).map(str::to_string),
),
},
});
}
for record in records {
if !self.audit_note(record).await && first {
self.audit()
.forget_access(token.account_id(), locked_id, KIND_DELEGATE_ACCESS);
}
}
}
/// AU-7: removes entries past the retention period.
pub async fn audit_purge(&self) -> trc::Result<usize> {
let settings = log::settings(self.store()).await?;
let cutoff = ms().saturating_sub(settings.keep_for_secs.saturating_mul(1000));
// LH-6, AU-7: a record about a held account stays while it's held.
// Worked out before the purge, which can't wait on lookups.
let held = self.held_accounts().await?;
log::purge(self.store(), cutoff, |record| {
record
.target
.account_id
.is_some_and(|account_id| held.contains(&account_id))
})
.await
}
}
fn describe_target(target: &Target) -> String {
match (&target.name, &target.id) {
(Some(name), _) => format!("{} {name}", target.kind),
(None, Some(id)) => format!("{} {id}", target.kind),
(None, None) => target.kind.clone(),
}
}
/// AU-1.10: records a registry write made outside any request, as the
/// server's own, under the subsystem its task runs in.
struct SystemWrites {
data: Store,
log: AuditLog,
node: u64,
}
/// Objects whose writes aren't the control plane: telemetry and mail data
/// the registry also stores.
fn is_quiet_object(object_type: ObjectType) -> bool {
matches!(
object_type,
ObjectType::SpamTrainingSample
| ObjectType::ArchivedItem
| ObjectType::Trace
| ObjectType::Metric
| ObjectType::Log
| ObjectType::ClusterNode
| ObjectType::Task
| ObjectType::QueuedMessage
| ObjectType::ArfExternalReport
| ObjectType::DmarcExternalReport
| ObjectType::TlsExternalReport
| ObjectType::DmarcInternalReport
| ObjectType::TlsInternalReport
)
}
impl RegistryWriteHook for SystemWrites {
fn written<'a>(
&'a self,
change: RegistryChange<'a>,
) -> Pin<Box<dyn Future<Output = ()> + Send + 'a>> {
Box::pin(async move {
// LH-2: every change to an account, whoever makes it: one that
// leaves a held domain, group or tenant stays held by name
if change.object_type == ObjectType::Account
&& let (Some(before), Some(after)) = (change.before, change.after)
&& let (Some(before), Some(after)) = (
Member::of(change.id.document_id(), &before.inner),
Member::of(change.id.document_id(), &after.inner),
)
&& let Err(err) = hold::keep_moved(&self.data, &before, &after).await
{
trc::error!(err
.account_id(after.account)
.details("Failed to keep a moved account under its legal hold"));
}
let subsystem = match scope::current() {
Some(scope::Scope::Request | scope::Scope::Quiet) => return,
Some(scope::Scope::System(subsystem)) => subsystem,
None => "server",
};
if is_quiet_object(change.object_type) {
return;
}
let kind = format!("x:{}", change.object_type.as_str());
let json = |object: &registry::schema::prelude::Object| {
serde_json::to_value(object.clone().into_value()).unwrap_or_default()
};
let before = change.before.map(json);
let after = change.after.map(json);
let described = after
.as_ref()
.or(before.as_ref())
.map(diff::describe)
.unwrap_or_default();
let action = match (&before, &after) {
(None, _) => Action::Create,
(Some(_), Some(_)) => Action::Update,
(Some(_), None) => Action::Destroy,
};
let changes = match action {
Action::Destroy => vec![],
_ => diff::diff(&kind, before.as_ref(), after.as_ref()),
};
let record = Record {
at: std::time::SystemTime::now()
.duration_since(std::time::UNIX_EPOCH)
.map_or(0, |d| d.as_millis() as u64),
actor: Actor::system(subsystem),
via: None,
remote_ip: None,
action,
target: Target {
kind,
id: Some(change.id.to_string()),
name: described.name,
account_id: described.account_id,
tenant_id: described.tenant_id,
},
changes,
details: None,
reason: None,
outcome: Outcome::success(),
};
match self.log.append(&self.data, self.node, &record).await {
Ok(id) => trc::event!(
Security(trc::SecurityEvent::AuditRecorded),
Id = id.to_string(),
Type = record.action.as_str(),
AccountName = record.actor.name.clone(),
Details = describe_target(&record.target),
),
Err(err) => trc::event!(
Security(trc::SecurityEvent::AuditWriteFailed),
Type = record.action.as_str(),
AccountName = record.actor.name.clone(),
Details = describe_target(&record.target),
Reason = err.to_string(),
),
}
})
}
}
+140 -2
View File
@@ -43,6 +43,27 @@ impl Server {
revision: u64,
revision_account: u64,
) -> trc::Result<AccessTokenInner> {
// inbuxa: AL-2, AL-5: whether this account is locked, and which
// locked accounts are handed to it. The token is their cache: every
// change to a lock invalidates the tokens it touches.
let locked = inbuxa_features::lock::get(self.store(), account_id)
.await
.caused_by(trc::location!())?
.is_some();
let now_secs = now();
let delegations: Box<[super::Delegation]> =
inbuxa_features::lock::delegated_to(self.store(), account_id)
.await
.caused_by(trc::location!())?
.into_iter()
.filter(|(_, delegate)| delegate.is_current(now_secs))
.map(|(locked_id, delegate)| super::Delegation {
account_id: locked_id,
access: delegate.access,
send_as: delegate.send_as,
until: delegate.until,
})
.collect();
match account {
Account::User(account) => {
let tenant_id = account.member_tenant_id.map(|t| t.id() as u32);
@@ -122,6 +143,29 @@ impl Server {
}
}
}
// inbuxa: AL-7: a delegate reaches the whole locked account,
// mail, calendars, contacts and files, even a kind it holds
// none of yet, so an empty one reads as empty rather than
// refused. What it may see or change there is still each
// container's grant.
for delegation in delegations.iter() {
let whole: Bitmap<Collection> = Bitmap::from_iter([
Collection::Mailbox,
Collection::Email,
Collection::Calendar,
Collection::CalendarEvent,
Collection::AddressBook,
Collection::ContactCard,
Collection::FileNode,
]);
match access_to.iter_mut().find(|a| a.account_id == delegation.account_id) {
Some(entry) => entry.collections.union(&whole),
None => access_to.push(AccessTo {
account_id: delegation.account_id,
collections: whole,
}),
}
}
let now = now();
let mut credential_version = 0;
@@ -202,6 +246,8 @@ impl Server {
.upload_max_concurrent
.map(ConcurrencyLimiter::new),
obj_size: 0,
locked,
delegations: delegations.clone(),
revision,
revision_account,
credential_version,
@@ -211,7 +257,15 @@ impl Server {
access_to: access_to.into_boxed_slice(),
scopes: []
.into_iter()
.chain(credential_scopes)
.chain(credential_scopes.into_iter().map(|mut scope| {
// inbuxa: AL-2: no credential of a locked
// account authenticates; receiving mail isn't
// signing in, so EmailReceive stays
if locked {
scope.permissions.clear(Permission::Authenticate as usize);
}
scope
}))
.collect::<Box<[AccessScope]>>(),
}
.update_size())
@@ -245,6 +299,8 @@ impl Server {
.upload_max_concurrent
.map(ConcurrencyLimiter::new),
obj_size: 0,
locked,
delegations: delegations.clone(),
revision,
revision_account,
credential_version: 0,
@@ -376,6 +432,7 @@ impl AccessToken {
pub fn new(inner: Arc<AccessTokenInner>, remote_ip: IpAddr) -> trc::Result<Self> {
AccessToken {
scope_idx: 0,
origin: None,
inner,
}
.assert_is_valid(remote_ip)
@@ -384,6 +441,7 @@ impl AccessToken {
pub fn new_maybe_invalid(inner: Arc<AccessTokenInner>) -> Self {
AccessToken {
scope_idx: 0,
origin: None,
inner,
}
}
@@ -404,7 +462,11 @@ impl AccessToken {
.ctx(trc::Key::Id, credential_id)
.reason("Credential expired or removed.")
})
.map(|scope_idx| AccessToken { scope_idx, inner })
.map(|scope_idx| AccessToken {
scope_idx,
inner,
origin: None,
})
.and_then(|token| token.assert_is_valid(remote_ip))
}
@@ -418,6 +480,7 @@ impl AccessToken {
} else {
AccessToken {
scope_idx: 0,
origin: None,
inner,
}
.assert_is_valid(remote_ip)
@@ -481,6 +544,15 @@ impl AccessToken {
|| self.has_permission(Permission::Impersonate)
}
/// inbuxa: AU-1.6: whether the account is reachable without
/// impersonation: its own, a group's it belongs to, or one shared with
/// it.
pub fn is_member_directly(&self, account_id: u32) -> bool {
self.inner.account_id == account_id
|| self.inner.member_of.contains(&account_id)
|| self.inner.access_to.iter().any(|a| a.account_id == account_id)
}
pub fn is_account_id(&self, account_id: u32) -> bool {
self.inner.account_id == account_id
}
@@ -575,10 +647,13 @@ impl AccessToken {
revision: old_inner.revision,
credential_version: old_inner.credential_version,
obj_size: old_inner.obj_size,
locked: old_inner.locked,
delegations: old_inner.delegations.clone(),
};
access_token = AccessToken {
scope_idx: access_token.scope_idx,
origin: access_token.origin.clone(),
inner: Arc::new(inner),
};
}
@@ -758,9 +833,62 @@ impl AccessToken {
}
}
/// inbuxa: AL-2: the account is locked.
pub fn is_locked(&self) -> bool {
self.inner.locked
}
/// inbuxa: AL-5: this account's delegation into a locked account, if it
/// has one that hasn't ended.
/// inbuxa: AL-6, AL-7: a delegate at organize or full, who may add to
/// the locked account as its owner could, top-level folders included.
pub fn delegate_may_write(&self, account_id: u32) -> bool {
self.delegation(account_id)
.is_some_and(|d| d.access != inbuxa_features::lock::Access::Read)
}
pub fn delegation(&self, account_id: u32) -> Option<&super::Delegation> {
let now = now();
self.inner
.delegations
.iter()
.find(|d| d.account_id == account_id && d.until.is_none_or(|until| until > now))
}
/// inbuxa: AL-5: every current delegation this account holds.
pub fn delegations(&self) -> impl Iterator<Item = &super::Delegation> {
let now = now();
self.inner
.delegations
.iter()
.filter(move |d| d.until.is_none_or(|until| until > now))
}
/// inbuxa: how this session signed in (AU-5).
pub fn origin(&self) -> Option<&inbuxa_features::audit::Via> {
self.origin.as_deref()
}
/// inbuxa: records how this session signed in (AU-5).
pub fn with_origin(mut self, origin: inbuxa_features::audit::Via) -> Self {
self.origin = Some(Arc::new(origin));
self
}
pub fn origin_arc(&self) -> Option<Arc<inbuxa_features::audit::Via>> {
self.origin.clone()
}
/// inbuxa: restores how a cached session signed in (AU-5).
pub fn with_origin_arc(mut self, origin: Option<Arc<inbuxa_features::audit::Via>>) -> Self {
self.origin = origin;
self
}
pub fn new_admin() -> AccessToken {
AccessToken {
scope_idx: 0,
origin: None,
inner: Arc::new(AccessTokenInner::new_admin()),
}
}
@@ -775,6 +903,7 @@ impl AccessToken {
}
AccessToken {
scope_idx: 0,
origin: None,
inner: Arc::new(AccessTokenInner {
account_id,
tenant_id: Default::default(),
@@ -788,6 +917,8 @@ impl AccessToken {
revision_account: Default::default(),
credential_version: Default::default(),
obj_size: Default::default(),
locked: false,
delegations: Default::default(),
}),
}
}
@@ -798,6 +929,11 @@ impl AccessToken {
}
impl AccessTokenInner {
/// inbuxa: AL-2: the account is locked.
pub fn is_locked(&self) -> bool {
self.locked
}
/// inbuxa: SCIM-27: the account's own effective permission, from its
/// roles, its own settings and its tenant, before a credential narrows it
pub fn account_has_permission(&self, permission: Permission) -> bool {
@@ -841,6 +977,8 @@ impl AccessTokenInner {
revision_account: Default::default(),
credential_version: Default::default(),
obj_size: Default::default(),
locked: false,
delegations: Default::default(),
}
}
+72 -6
View File
@@ -26,6 +26,7 @@ use registry::schema::{
use serde::Deserialize;
use std::{borrow::Cow, net::IpAddr, sync::Arc};
use store::write::now;
use inbuxa_features::audit::Via;
use trc::AddContext;
pub struct UsernameParts {
@@ -43,10 +44,32 @@ impl Server {
pub async fn authenticate(&self, req: &AuthRequest) -> trc::Result<AccessToken> {
match Box::pin(self.route_auth_request(req))
.await
// inbuxa: AL-2: a locked account fails as a wrong password does,
// so the right password learns nothing; master and recovery
// sign-ins as it fail the same way
.and_then(|token| {
if token.is_locked() {
Err(trc::AuthEvent::Failed
.into_err()
.ctx(trc::Key::AccountId, token.account_id())
.reason("Account is locked"))
} else {
Ok(token)
}
})
.and_then(|token| token.assert_has_permission(Permission::Authenticate))
{
Ok(token) => Ok(token),
Ok(token) => {
// inbuxa: AU-1.4, AU-1.5
self.audit_sign_in(req, &token).await;
Ok(token)
}
Err(err) => {
// inbuxa: AU-1.4
if matches!(err.as_ref(), trc::EventType::Auth(trc::AuthEvent::Failed)) {
self.audit_sign_in_failed(req).await;
}
// Random delay to mitigate user enumeration attacks
#[cfg(not(feature = "test_mode"))]
{
@@ -106,6 +129,13 @@ impl Server {
self.access_token(account_id)
.await
.and_then(|token| AccessToken::new(token, req.remote_ip))
// inbuxa: AU-1.5, AU-5
.map(|token| {
token.with_origin(Via::Master {
account_id: None,
name: fallback_user.to_string(),
})
})
} else {
Err(trc::AuthEvent::Failed
.into_err()
@@ -119,7 +149,8 @@ impl Server {
SpanId = req.session_id,
);
Ok(AccessToken::new_admin())
// inbuxa: AU-1.5, AU-5
Ok(AccessToken::new_admin().with_origin(Via::Recovery))
}
} else {
Err(trc::AuthEvent::Failed
@@ -163,6 +194,12 @@ impl Server {
req.session_id,
)
.await
// inbuxa: AU-5
.map(|token| {
token.with_origin(Via::AppPassword {
id: app_pass.credential_id,
})
})
} else {
Err(trc::AuthEvent::Failed
.into_err()
@@ -262,6 +299,7 @@ impl Server {
// Validate master user access
if username.is_master() {
let master_id = token.account_id(); // inbuxa: AU-5
token.assert_has_permissions(&[
Permission::Impersonate,
Permission::Authenticate,
@@ -282,6 +320,13 @@ impl Server {
self.access_token(account_id)
.await
.map(AccessToken::new_maybe_invalid)
// inbuxa: AU-1.5, AU-5: the master stays known
.map(|impersonated| {
impersonated.with_origin(Via::Master {
account_id: Some(master_id),
name: master_address.to_string(),
})
})
} else {
Err(trc::AuthEvent::Failed
.into_err()
@@ -297,7 +342,12 @@ impl Server {
SpanId = req.session_id,
);
Ok(token)
// inbuxa: AU-5 (a directory's token already says so)
Ok(if token.origin().is_none() {
token.with_origin(Via::Password)
} else {
token
})
}
}
Credentials::Bearer { username, token } => {
@@ -311,7 +361,9 @@ impl Server {
req.remote_ip,
req.session_id,
)
.await;
.await
// inbuxa: AU-5
.map(|token| token.with_origin(Via::ApiKey { id: key.credential_id }));
}
#[cfg(feature = "dev_mode")]
@@ -368,7 +420,8 @@ impl Server {
.ctx(trc::Key::AccountId, token.account_id())
.reason("Authenticated using an email alias but account does not have AuthenticateAlias permission"));
}
return Ok(token);
// inbuxa: AU-5
return Ok(token.with_origin(Via::Directory));
}
Err(err) => {
external_error = Some(err);
@@ -384,7 +437,20 @@ impl Server {
Ok(token_info) => self
.access_token(token_info.account_id)
.await
.and_then(|token| AccessToken::new(token, req.remote_ip)),
.and_then(|token| AccessToken::new(token, req.remote_ip))
// inbuxa: AU-5
.map(|token| {
token.with_origin(Via::OAuth {
client: token_info
.claims
.as_deref()
.filter(|claims| !claims.is_empty())
.unwrap_or("unknown")
.chars()
.take(200)
.collect(),
})
}),
Err(err) => {
if let Some(external_error) = external_error {
Err(external_error)
+18
View File
@@ -132,6 +132,8 @@ pub struct PermissionsGroup {
pub struct AccessToken {
scope_idx: usize,
inner: Arc<AccessTokenInner>,
// inbuxa: how this session signed in, for the audit log (AU-5)
origin: Option<Arc<inbuxa_features::audit::Via>>,
}
#[derive(Debug, Default, Clone)]
@@ -148,6 +150,21 @@ pub struct AccessTokenInner {
pub(crate) revision: u64,
pub(crate) credential_version: u64,
pub(crate) obj_size: u64,
// inbuxa: AL-2: the account is locked; it may not authenticate
pub(crate) locked: bool,
// inbuxa: AL-5: locked accounts handed to this one
pub(crate) delegations: Box<[Delegation]>,
}
/// inbuxa: a locked account this one may open, and how (AL-5, AL-6).
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct Delegation {
/// The locked account.
pub account_id: u32,
pub access: inbuxa_features::lock::Access,
pub send_as: bool,
/// Seconds since the epoch.
pub until: Option<u64>,
}
#[derive(Debug, Default, Hash, Clone)]
@@ -298,6 +315,7 @@ impl BuildAccessToken for Arc<AccessTokenInner> {
fn build(self) -> AccessToken {
AccessToken {
scope_idx: 0,
origin: None,
inner: self,
}
}
+47
View File
@@ -104,6 +104,16 @@ impl Server {
ceiling(base, policy).apply(&mut permissions.enabled, &mut permissions.disabled);
// inbuxa: MT-1, MT-15: impersonation would reach beyond the tenant
permissions.disabled.set(Permission::Impersonate as usize);
// inbuxa: LH-13: only server-level administrators see or place
// holds, and a hold may concern the tenant's own administrator
for permission in [
Permission::SysLegalHoldGet,
Permission::SysLegalHoldCreate,
Permission::SysLegalHoldUpdate,
Permission::SysLegalHoldExport,
] {
permissions.disabled.set(permission as usize);
}
Ok(())
}
@@ -254,6 +264,11 @@ impl Default for DefaultPermissions {
default.tenant.push(permission);
}
Permission::Impersonate
// inbuxa: LH-13: holds are the server administrator's alone
| Permission::SysLegalHoldGet
| Permission::SysLegalHoldCreate
| Permission::SysLegalHoldUpdate
| Permission::SysLegalHoldExport
| Permission::UnlimitedRequests
| Permission::UnlimitedUploads
| Permission::LiveMetrics
@@ -269,6 +284,38 @@ impl Default for DefaultPermissions {
default.superuser.push(permission);
default.tenant.push(permission);
}
// inbuxa: AU-9: a tenant administrator reads and exports
// its tenant's audit log; retention stays the server's
Permission::SysAuditGet | Permission::SysAuditExport => {
default.superuser.push(permission);
default.tenant.push(permission);
}
// inbuxa: personal-data catalog: the data inventory, the
// server's or, inside a tenant, the tenant's slice
Permission::SysComplianceGet => {
default.superuser.push(permission);
default.tenant.push(permission);
}
// inbuxa: DLP and mail flow rules, and held mail, are the
// server's: never a tenant's (dlp-and-mail-flow-rules spec,
// settled answer 3)
Permission::SysMailRuleGet
| Permission::SysMailRuleUpdate
| Permission::SysDlpPolicyGet
| Permission::SysDlpPolicyUpdate
| Permission::SysDlpReviewGet
| Permission::SysDlpReviewUpdate => {
default.superuser.push(permission);
}
// inbuxa: AL-12: tenant administrators lock and delegate
// within their tenant
Permission::SysAccountLockGet
| Permission::SysAccountLockCreate
| Permission::SysAccountLockUpdate
| Permission::SysAccountLockDestroy => {
default.superuser.push(permission);
default.tenant.push(permission);
}
permission => {
let name = permission.as_str();
if name.starts_with("jmap")
+22
View File
@@ -31,6 +31,19 @@ impl Server {
pub async fn synchronize_account(
&self,
account: directory::Account,
) -> trc::Result<AccountWithId> {
// inbuxa: AU-1.10: what a directory (LDAP, AD, SQL, OIDC) changed
// is recorded as its sync, not as the server acting on its own
inbuxa_features::audit::scope::system(
"directory-sync",
self.synchronize_account_unscoped(account),
)
.await
}
async fn synchronize_account_unscoped(
&self,
account: directory::Account,
) -> trc::Result<AccountWithId> {
let (local, domain) = self.validate_address(&account.email).await?;
@@ -267,6 +280,15 @@ impl Server {
}
pub async fn synchronize_group(&self, group: directory::Group) -> trc::Result<u32> {
// inbuxa: AU-1.10, as for accounts
inbuxa_features::audit::scope::system(
"directory-sync",
self.synchronize_group_unscoped(group),
)
.await
}
async fn synchronize_group_unscoped(&self, group: directory::Group) -> trc::Result<u32> {
let (local, domain) = self.validate_address(&group.email).await?;
match self
+2
View File
@@ -99,6 +99,7 @@ impl Data {
logos: Default::default(),
smtp_connectors: TlsConnectors::try_new().failed("Failed to build TLS connectors"),
build_errors: Default::default(),
audit: Default::default(),
asn_geo_data: Default::default(),
}
}
@@ -243,6 +244,7 @@ impl Default for Data {
logos: Default::default(),
smtp_connectors: TlsConnectors::try_new().unwrap(),
build_errors: Default::default(),
audit: Default::default(),
asn_geo_data: Default::default(),
lookup_stores: Default::default(),
}
+25 -15
View File
@@ -46,10 +46,10 @@ pub struct Network {
#[derive(Clone)]
pub struct NetworkInfo {
pub pacc: Pacc,
/// inbuxa: the same document without IMAP, POP3, SMTP and ManageSieve,
/// served while legacy protocols are off (legacy-protocols LP-7).
pub pacc_jmap_only: Pacc,
/// inbuxa: the document once per combination of legacy protocols off,
/// indexed by `LegacyOff::index` (legacy-protocols LP-7, one switch per
/// protocol); index 0 is the full document.
pub pacc: Vec<Pacc>,
pub mxs: Vec<MailExchanger>,
pub services: VecMap<ServiceProtocol, Service>,
}
@@ -333,16 +333,27 @@ impl Network {
})
.unwrap()
};
// inbuxa: legacy-protocols LP-7
let pacc_jmap_only = {
let mut pacc = pacc.clone();
pacc.protocols.imap = None;
pacc.protocols.pop3 = None;
pacc.protocols.smtp = None;
pacc.protocols.managesieve = None;
split(&pacc)
};
let pacc = split(&pacc);
// inbuxa: legacy-protocols LP-7, one document per combination of
// protocols off, bits as `LegacyOff::index`: IMAP, POP3, ManageSieve,
// submission.
let pacc = (0..16usize)
.map(|off| {
let mut pacc = pacc.clone();
if off & 1 != 0 {
pacc.protocols.imap = None;
}
if off & 2 != 0 {
pacc.protocols.pop3 = None;
}
if off & 4 != 0 {
pacc.protocols.managesieve = None;
}
if off & 8 != 0 {
pacc.protocols.smtp = None;
}
split(&pacc)
})
.collect();
let mut network = Network {
node_id: bp.node_id() as u64,
server_name: default_hostname.to_string(),
@@ -358,7 +369,6 @@ impl Network {
mxs: system.mail_exchangers.into_iter().collect(),
services: system.services,
pacc,
pacc_jmap_only,
},
};
+92 -1
View File
@@ -483,8 +483,16 @@ impl Tracers {
};
// Parse webhook events
// inbuxa: personal-data catalog, finding 1: an include list is
// sent as named; otherwise a webhook honors its level as a
// tracer does, and never sends a protocol's raw input or
// output (whole messages)
let level = Level::from(hook.level);
let named = (hook.events_policy == EventPolicy::Include)
.then(|| hook.events.iter().copied().collect::<AHashSet<_>>())
.unwrap_or_default();
apply_events(hook.events, hook.events_policy, |event_type| {
if event_type != EventType::Telemetry(TelemetryEvent::WebhookError) {
if webhook_wants(event_type, level, &custom_levels, &named) {
tracer.interests.set(event_type);
global_interests.set(event_type);
}
@@ -743,6 +751,31 @@ fn tracer_settings(tracer: &Tracer) -> u64 {
settings_hash(&tracer)
}
/// inbuxa: whether a webhook at `level` receives this event type. Its own
/// error event never, or a failing webhook would report itself to itself.
/// An event `named` in an include list always: naming it is the choice.
/// Otherwise (the exclude policy, the default) only events at or above its
/// level, as for a tracer, and never a protocol's raw input or output, which
/// carries whole messages and credentials.
fn webhook_wants(
event_type: EventType,
level: Level,
custom_levels: &AHashMap<EventType, Level>,
named: &AHashSet<EventType>,
) -> bool {
if event_type == EventType::Telemetry(TelemetryEvent::WebhookError) {
return false;
}
if named.contains(&event_type) {
return true;
}
let event_level = custom_levels
.get(&event_type)
.copied()
.unwrap_or(event_type.level());
level.is_contained(event_level) && !event_type.is_raw_io()
}
fn webhook_settings(hook: &WebHook) -> u64 {
let mut hook = hook.clone();
in_place_reset!(hook);
@@ -804,3 +837,61 @@ impl std::fmt::Debug for OtelMetrics {
.finish()
}
}
#[cfg(test)]
mod tests {
use super::*;
use trc::{AuthEvent, SmtpEvent};
fn wants(event: EventType, level: Level, named: &[EventType]) -> bool {
webhook_wants(
event,
level,
&AHashMap::new(),
&named.iter().copied().collect(),
)
}
#[test]
fn a_webhook_honors_its_level() {
let success = EventType::Auth(AuthEvent::Success);
assert!(wants(success, Level::Info, &[]));
assert!(!wants(success, Level::Error, &[]), "info is below error");
}
#[test]
fn raw_io_goes_out_only_when_named() {
let raw = EventType::Smtp(SmtpEvent::RawInput);
assert!(raw.is_raw_io());
// Not with the exclude policy, even at trace
assert!(!wants(raw, Level::Info, &[]));
assert!(!wants(raw, Level::Trace, &[]));
// Named in an include list, whatever the level
assert!(wants(raw, Level::Info, &[raw]));
}
#[test]
fn a_named_event_is_sent_whatever_its_level() {
let start = EventType::Smtp(SmtpEvent::ConnectionStart);
assert!(!Level::Info.is_contained(start.level()), "below info");
assert!(!wants(start, Level::Info, &[]));
assert!(wants(start, Level::Info, &[start]));
}
#[test]
fn a_custom_level_counts() {
let start = EventType::Smtp(SmtpEvent::ConnectionStart);
let custom = [(start, Level::Info)].into_iter().collect::<AHashMap<_, _>>();
assert!(webhook_wants(start, Level::Info, &custom, &AHashSet::new()));
// Raw I/O raised to info still needs naming
let raw = EventType::Smtp(SmtpEvent::RawInput);
let custom = [(raw, Level::Info)].into_iter().collect::<AHashMap<_, _>>();
assert!(!webhook_wants(raw, Level::Info, &custom, &AHashSet::new()));
}
#[test]
fn a_webhook_never_hears_its_own_errors() {
let own = EventType::Telemetry(TelemetryEvent::WebhookError);
assert!(!wants(own, Level::Trace, &[own]));
}
}
+282
View File
@@ -0,0 +1,282 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! inbuxa: which legal holds cover an account (audit-hold-lock spec, LH-2,
//! LH-11), for the paths that destroy data. Read from the store every time,
//! not cached: a hold placed on one node must bind every node at once, and
//! there are few holds.
use crate::Server;
use ahash::AHashMap;
use inbuxa_features::{
hold::{self, HELD_UNTIL, Hold, Keeping, Member, is_held_until},
undelete::records,
};
use inbuxa_features::undelete::data::{self as undelete_data, KeptAccount};
use registry::{
pickle::PickledStream,
schema::{
prelude::{ObjectInner, ObjectType},
structs::ArchivedItem,
},
};
use store::{registry::RegistryQuery, write::now};
use trc::AddContext;
use types::id::Id;
/// The grace a released item gets at least (LH-10): a release made in error
/// can be undone by placing a new hold within it.
const RELEASE_GRACE: u64 = 30 * 86_400;
/// What a settle pass changed.
#[derive(Debug, Default, Clone, Copy, PartialEq, Eq)]
pub struct Settled {
pub frozen: usize,
pub released: usize,
/// Deleted accounts kept by a hold, or let go by a release (LH-8, LH-10).
pub accounts_frozen: usize,
pub accounts_released: usize,
}
/// What one hold keeps (LH-9).
#[derive(Debug, Default, Clone, Copy, PartialEq, Eq)]
pub struct HoldSummary {
pub accounts: u64,
pub items: u64,
pub size: u64,
}
/// A kept account as it was when deleted, for a hold's scope: its record
/// still names its domain, groups and tenant.
pub fn kept_member(account_id: u32, kept: &KeptAccount) -> Member {
PickledStream::new(&kept.record)
.and_then(|mut stream| ObjectInner::unpickle(ObjectType::Account, &mut stream))
.and_then(|inner| Member::of(account_id, &inner))
.unwrap_or(Member {
account: account_id,
..Default::default()
})
}
impl Server {
/// What decides whether a hold reaches a live account; None if it's gone.
pub async fn member_of(&self, account_id: u32) -> Option<Member> {
let account = self.account(account_id).await.ok()?;
let mut domains = account
.addresses
.iter()
.map(|address| address.domain_id)
.collect::<Vec<_>>();
domains.sort_unstable();
domains.dedup();
Some(Member {
account: account_id,
domains,
groups: account.id_member_of.iter().copied().collect(),
tenant: account.id_tenant,
})
}
/// LH-9, the console's "what's held": per active hold, the accounts it
/// covers now (deleted ones it keeps included), and the archived items
/// it keeps with their size. One pass over accounts and archive.
pub async fn hold_summaries(&self) -> trc::Result<AHashMap<u32, HoldSummary>> {
let data = self.store();
let registry = self.registry();
let holds = hold::active(data).await?;
let mut summaries: AHashMap<u32, HoldSummary> =
holds.iter().map(|h| (h.id, HoldSummary::default())).collect();
if holds.is_empty() {
return Ok(summaries);
}
let mut members: AHashMap<u32, Member> = AHashMap::new();
for id in registry
.query::<Vec<Id>>(RegistryQuery::new(ObjectType::Account))
.await
.caused_by(trc::location!())?
{
if let Some(member) = self.member_of(id.document_id()).await {
members.insert(id.document_id(), member);
}
}
for (account_id, kept) in undelete_data::kept_accounts(data).await? {
members.insert(account_id, kept_member(account_id, &kept));
}
for member in members.values() {
for hold in holds.iter().filter(|h| h.scope.covers(member)) {
summaries.entry(hold.id).or_default().accounts += 1;
}
}
for id in records::all(data, registry).await? {
let Some(item) = registry.object::<ArchivedItem>(id).await? else {
continue;
};
if !is_held_until(item.archived_until().timestamp().max(0) as u64) {
continue;
}
let Some(member) = members.get(&item.account_id().document_id()) else {
continue;
};
let size = match &item {
ArchivedItem::Email(email) => email.size,
ArchivedItem::FileNode(_) => match undelete_data::extra(data, id).await? {
Some(inbuxa_features::undelete::data::Extra::FileNode { size, .. }) => size as u64,
_ => 0,
},
_ => 0,
};
for hold in holds.iter().filter(|h| h.scope.covers(member)) {
let summary = summaries.entry(hold.id).or_default();
summary.items += 1;
summary.size += size;
}
}
Ok(summaries)
}
/// The active holds covering `account_id`, through its own name, its
/// addresses' domains, its groups or its tenant. Empty for an account
/// that no longer exists: a deleted one is kept by LH-8's own check.
pub async fn holds_on(&self, account_id: u32) -> trc::Result<Vec<Hold>> {
let Ok(account) = self.account(account_id).await else {
return Ok(Vec::new());
};
let mut domains = account
.addresses
.iter()
.map(|address| address.domain_id)
.collect::<Vec<_>>();
domains.sort_unstable();
domains.dedup();
let member = Member {
account: account_id,
domains,
groups: account.id_member_of.iter().copied().collect(),
tenant: account.id_tenant,
};
hold::covering(self.store(), &member).await
}
/// How `account_id`'s deleted items are kept: its holds' ranges and the
/// undelete period in force now (LH-4, UD-6a).
pub async fn keeping(&self, account_id: u32) -> trc::Result<Keeping> {
let retention = inbuxa_features::undelete::settings::retention(self.registry())
.await?
.items;
Ok(Keeping::new(retention, &self.holds_on(account_id).await?))
}
/// LH-6, LH-10, LH-11: brings the whole archive in line with the active
/// holds. An archived item a hold covers is frozen (no deadline), its
/// old deadline noted; a frozen one no hold covers any more gets that
/// deadline back, or release plus 30 days if later. Run after every
/// change to a hold; it changes nothing twice.
pub async fn settle_archive(&self) -> trc::Result<Settled> {
let data = self.store();
let registry = self.registry();
let any_active = !hold::active(data).await?.is_empty();
let now = now();
let mut keeping: AHashMap<u32, Option<Keeping>> = AHashMap::new();
let mut settled = Settled::default();
for id in records::all(data, registry).await? {
let Some(item) = registry.object::<ArchivedItem>(id).await? else {
continue;
};
let account_id = item.account_id().document_id();
if !keeping.contains_key(&account_id) {
// An account that's gone can't be placed in a domain or
// tenant any more: None, and its items are left as they are
let known = self.account(account_id).await.is_ok();
let value = if known { Some(self.keeping(account_id).await?) } else { None };
keeping.insert(account_id, value);
}
let until = item.archived_until().timestamp().max(0) as u64;
let held = is_held_until(until);
let covered = match keeping.get(&account_id).and_then(Option::as_ref) {
Some(keeping) => match &item {
ArchivedItem::Email(email) => {
keeping.covers(Some(email.received_at.timestamp().max(0) as u64))
}
ArchivedItem::CalendarEvent(event) => keeping
.covers_event(event.start_time.map(|t| t.timestamp().max(0) as u64)),
_ => keeping.covers(None),
},
// Gone: release only once no hold is active anywhere
None => held && any_active,
};
if covered && !held {
hold::set_original_deadline(data, id.id(), Some(until)).await?;
records::set_deadline(data, registry, id, &item, HELD_UNTIL).await?;
settled.frozen += 1;
} else if !covered && held {
let original = hold::original_deadline(data, id.id()).await?.unwrap_or(0);
records::set_deadline(data, registry, id, &item, original.max(now + RELEASE_GRACE))
.await?;
hold::set_original_deadline(data, id.id(), None).await?;
settled.released += 1;
}
}
// LH-8, LH-10: deleted accounts kept by undelete follow the holds
// too. Their DestroyAccount task defers itself while they're kept.
let retention = inbuxa_features::undelete::settings::retention(registry)
.await?
.accounts;
for (account_id, mut kept) in undelete_data::kept_accounts(data).await? {
let covered = !hold::covering(data, &kept_member(account_id, &kept)).await?.is_empty();
let held = is_held_until(kept.kept_until);
let until = if covered && !held {
settled.accounts_frozen += 1;
HELD_UNTIL
} else if !covered && held {
settled.accounts_released += 1;
(kept.deleted_at + retention.unwrap_or(0)).max(now + RELEASE_GRACE)
} else {
continue;
};
kept.kept_until = until;
let mut batch = store::write::BatchBuilder::new();
undelete_data::set_kept_account(&mut batch, account_id, &kept)?;
data.write(batch.build_all())
.await
.caused_by(trc::location!())?;
}
Ok(settled)
}
/// LH-8: whether a hold covers a deleted account undelete keeps.
pub async fn is_kept_held(&self, account_id: u32, kept: &KeptAccount) -> trc::Result<bool> {
Ok(!hold::covering(self.store(), &kept_member(account_id, kept))
.await?
.is_empty())
}
/// Every account an active hold covers now. Empty, without looking at
/// accounts, when nothing is held.
pub async fn held_accounts(&self) -> trc::Result<ahash::AHashSet<u32>> {
let mut held = ahash::AHashSet::new();
if hold::active(self.store()).await?.is_empty() {
return Ok(held);
}
for id in self
.registry()
.query::<Vec<Id>>(RegistryQuery::new(ObjectType::Account))
.await
.caused_by(trc::location!())?
{
let account_id = id.document_id();
if self.is_held(account_id).await? {
held.insert(account_id);
}
}
Ok(held)
}
/// Whether any active hold covers `account_id` at all.
pub async fn is_held(&self, account_id: u32) -> trc::Result<bool> {
Ok(!self.holds_on(account_id).await?.is_empty())
}
}
+2
View File
@@ -86,6 +86,8 @@ pub enum BroadcastEvent {
CacheInvalidateNegative,
MtaQueueStatus { is_running: bool },
QueueRefresh,
// inbuxa: AL-3: end an account's open sessions on every node
EndSessions(u32),
}
#[derive(Debug, Clone, Copy)]
+11
View File
@@ -67,6 +67,10 @@ use utils::{
pub mod auth;
pub mod cache;
pub mod audit; // inbuxa: the audit log (audit-hold-lock spec, AU)
pub mod hold; // inbuxa: legal holds (audit-hold-lock spec, LH)
pub mod privacy; // inbuxa: the personal-data catalog, evaluated
pub mod reachability; // inbuxa: whether the outside world reaches each node's ports
pub mod config;
pub mod expr;
pub mod i18n;
@@ -126,6 +130,8 @@ pub const KV_LOCK_QUEUE_MESSAGE: u8 = 21;
pub const KV_LOCK_TASK: u8 = 23;
pub const KV_LOCK_DAV: u8 = 25;
pub const KV_SIEVE_ID: u8 = 26;
// inbuxa: far above upstream's prefixes, so a new one of theirs never collides
pub const KV_PORT_REACHABILITY: u8 = 200;
#[derive(Clone)]
pub struct Server {
@@ -174,6 +180,9 @@ pub struct Data {
// inbuxa: the objects that failed to build when the running settings
// were built, at boot or by the last applied reload (see reload_registry)
pub build_errors: Mutex<AHashSet<registry::types::id::ObjectId>>,
// inbuxa: the audit log's chain heads and recent-access marks (AU)
pub audit: inbuxa_features::audit::AuditLog,
}
#[derive(Clone)]
@@ -282,6 +291,8 @@ pub struct HttpAuthCache {
pub revision: u64,
pub credential_id: Option<u32>,
pub expires: Instant,
// inbuxa: how the cached credentials signed in (AU-5)
pub origin: Option<Arc<inbuxa_features::audit::Via>>,
}
pub struct Ipc {
+4
View File
@@ -243,6 +243,10 @@ impl BootManager {
// inbuxa: a reload isn't refused over objects that failed here
inner.build_server().record_build_errors(&bootstrap.errors);
// inbuxa: AU-1.10: the server's own registry writes are
// recorded from here on, after boot's defaults
inner.build_server().install_audit_hook();
BootManager {
inner,
bootstrap,
@@ -0,0 +1,294 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! The compliance roles (personal-data catalog spec, §7; settled
//! 2026-09-28): a server-level Compliance Officer, and one Compliance
//! Officer role in each tenant. A tenant's accounts can hold only roles of
//! their own tenant (MT-3), so the tenant role is made per tenant: once for
//! each tenant a server already has, and whenever a tenant is created.
//!
//! Each creation is recorded under `P` `c` in the fork's subspace, so a
//! role an administrator deletes stays deleted. A tenant's role, while
//! nobody holds it, is removed with the tenant so it doesn't block the
//! delete.
//!
//! Both read what compliance work needs and change no server setting. The
//! server-level officer also places, widens, releases and exports legal
//! holds: that is the job, and each is audited with its reason. A tenant's
//! role has no holds, which are server-level only (LH-13), and the tenant
//! ceiling keeps it within the tenant. Each role carries a user's own
//! permissions too (signing in, mail), since roles given to a person replace
//! the default user role, and a tenant's accounts can't hold the
//! server-level User role.
use registry::schema::{
enums::Permission,
prelude::ObjectType,
structs::{Role, Tenant},
};
use registry::types::map::Map;
use store::{
RegistryStore, SUBSPACE_INBUXA, Store, ValueKey,
registry::write::{RegistryWrite, RegistryWriteResult},
write::{AnyClass, BatchBuilder, ValueClass},
};
use trc::AddContext;
use types::id::Id;
/// The role's name, in the server's roles and in each tenant's.
pub const NAME: &str = "Compliance Officer";
/// Reading who and what records refer to, for both roles.
const READS: &[Permission] = &[
Permission::SysAccountGet,
Permission::SysAccountQuery,
Permission::SysMailingListGet,
Permission::SysMailingListQuery,
Permission::SysDomainGet,
Permission::SysDomainQuery,
Permission::SysTenantGet,
Permission::SysTenantQuery,
Permission::SysRoleGet,
Permission::SysRoleQuery,
];
/// What the server-level officer holds besides [`READS`].
const OFFICER: &[Permission] = &[
Permission::SysComplianceGet,
Permission::SysAuditGet,
Permission::SysAuditExport,
Permission::SysLegalHoldGet,
Permission::SysLegalHoldCreate,
Permission::SysLegalHoldUpdate,
Permission::SysLegalHoldExport,
Permission::SysAccountLockGet,
// dlp-and-mail-flow-rules spec, §2.8: see DLP rules, review held mail
Permission::SysDlpPolicyGet,
Permission::SysDlpReviewGet,
Permission::SysDlpReviewUpdate,
];
/// What a tenant's officer holds besides [`READS`].
const TENANT_OFFICER: &[Permission] = &[
Permission::SysComplianceGet,
Permission::SysAuditGet,
Permission::SysAuditExport,
Permission::SysAccountLockGet,
];
fn role(own: &[Permission], tenant: Option<Id>) -> Role {
let mut permissions = crate::auth::permissions::DefaultPermissions::default().user;
for permission in own.iter().chain(READS) {
if !permissions.contains(permission) {
permissions.push(*permission);
}
}
Role {
description: NAME.into(),
enabled_permissions: Map::new(permissions),
member_tenant_id: tenant,
..Default::default()
}
}
/// The server-level Compliance Officer role.
pub fn officer_role() -> Role {
role(OFFICER, None)
}
/// A tenant's Compliance Officer role.
pub fn tenant_role(tenant: Id) -> Role {
role(TENANT_OFFICER, Some(tenant))
}
/// Where a creation is recorded: the server's role, or a tenant's. The value
/// is the role's id.
fn created_key(tenant: Option<Id>) -> ValueClass {
let mut key = b"Pc".to_vec();
if let Some(tenant) = tenant {
key.extend_from_slice(&tenant.id().to_be_bytes());
}
ValueClass::Any(AnyClass {
subspace: SUBSPACE_INBUXA,
key,
})
}
/// The server-level Compliance Officer role the server made, if it has.
pub async fn server_role(data: &Store) -> trc::Result<Option<Id>> {
recorded(data, None).await
}
async fn recorded(data: &Store, tenant: Option<Id>) -> trc::Result<Option<Id>> {
Ok(data
.get_value::<u64>(ValueKey::from(created_key(tenant)))
.await
.caused_by(trc::location!())?
.map(Id::from))
}
async fn record(data: &Store, tenant: Option<Id>, role: Option<Id>) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
match role {
Some(role) => batch.set(created_key(tenant), role.id().to_be_bytes().to_vec()),
None => batch.clear(created_key(tenant)),
};
data.write(batch.build_all())
.await
.caused_by(trc::location!())
.map(|_| ())
}
/// Creates a role, unless one was created for this place before, and records
/// it. Returns the new role's id.
async fn create_once(
registry: &RegistryStore,
data: &Store,
tenant: Option<Id>,
role: Role,
) -> trc::Result<Option<Id>> {
if recorded(data, tenant).await?.is_some() {
return Ok(None);
}
match registry.write(RegistryWrite::insert(&role.into())).await? {
RegistryWriteResult::Success(id) => {
record(data, tenant, Some(id)).await?;
Ok(Some(id))
}
err => {
trc::error!(
trc::EventType::Registry(trc::RegistryEvent::ValidationError)
.into_err()
.details(format!("Failed to create the {NAME} role: {err}"))
);
Ok(None)
}
}
}
/// Once per server: the officer role, and one in each tenant it already has.
pub async fn ensure_compliance_roles(registry: &RegistryStore, data: &Store) -> trc::Result<()> {
create_once(registry, data, None, officer_role()).await?;
for tenant in registry.list::<Tenant>().await? {
let tenant = Id::from(tenant.id.id());
create_once(registry, data, Some(tenant), tenant_role(tenant)).await?;
}
Ok(())
}
/// A new tenant gets its Compliance Officer role.
pub async fn tenant_created(registry: &RegistryStore, data: &Store, tenant: Id) -> trc::Result<()> {
create_once(registry, data, Some(tenant), tenant_role(tenant))
.await
.map(|_| ())
}
/// Before a tenant is deleted: removes its Compliance Officer role if nobody
/// holds it, so the role doesn't block the delete. Returns whether it did,
/// so a delete refused for another reason can put it back.
pub async fn tenant_deleting(
registry: &RegistryStore,
data: &Store,
tenant: Id,
) -> trc::Result<bool> {
let Some(role) = recorded(data, Some(tenant)).await? else {
return Ok(false);
};
match registry
.write(RegistryWrite::delete(ObjectType::Role.id(role)))
.await?
{
RegistryWriteResult::Success(_) | RegistryWriteResult::NotFound { .. } => {
record(data, Some(tenant), None).await?;
Ok(true)
}
// Held by someone: the tenant's delete is refused for that anyway
_ => Ok(false),
}
}
/// A tenant's delete was refused after its role went: the role comes back.
pub async fn tenant_kept(registry: &RegistryStore, data: &Store, tenant: Id) -> trc::Result<()> {
tenant_created(registry, data, tenant).await
}
#[cfg(test)]
mod tests {
use super::*;
use registry::types::EnumImpl;
fn permissions(role: &Role) -> Vec<Permission> {
role.enabled_permissions.iter().copied().collect()
}
#[test]
fn neither_role_changes_a_setting() {
let user = crate::auth::permissions::DefaultPermissions::default().user;
for role in [officer_role(), tenant_role(Id::from(7u64))] {
let all = permissions(&role);
for permission in user.iter() {
assert!(all.contains(permission), "a user's own {permission:?}");
}
// Beyond what any user holds for their own account
for permission in all.into_iter().filter(|p| !user.contains(p)) {
let name = permission.as_str();
// Placing holds and reviewing held mail are the officer's
// job, not settings (settled answers 2 and 4)
let holds = name.starts_with("sysLegalHold") || name.starts_with("sysDlpReview");
assert!(
!(name.ends_with("Update") && !holds)
&& !(name.ends_with("Create") && !holds)
&& !name.ends_with("Destroy")
&& permission != Permission::Impersonate
&& permission != Permission::FetchAnyBlob,
"{} holds {name}",
role.description
);
}
}
}
#[test]
fn the_officer_places_and_releases_holds_a_tenants_does_not() {
let officer = permissions(&officer_role());
let tenant = tenant_role(Id::from(7u64));
assert_eq!(tenant.member_tenant_id, Some(Id::from(7u64)));
let tenant = permissions(&tenant);
for hold in [
Permission::SysLegalHoldGet,
Permission::SysLegalHoldCreate,
Permission::SysLegalHoldUpdate,
Permission::SysLegalHoldExport,
] {
assert!(officer.contains(&hold));
assert!(!tenant.contains(&hold));
}
for both in [
Permission::SysComplianceGet,
Permission::SysAuditGet,
Permission::SysAccountGet,
] {
assert!(officer.contains(&both) && tenant.contains(&both));
}
assert!(!officer.contains(&Permission::SysAuditSettingsUpdate));
}
#[test]
fn records_are_per_place() {
let ValueClass::Any(server) = created_key(None) else {
panic!()
};
let ValueClass::Any(a) = created_key(Some(Id::from(1u64))) else {
panic!()
};
let ValueClass::Any(b) = created_key(Some(Id::from(2u64))) else {
panic!()
};
assert_eq!(server.key, b"Pc");
assert_ne!(a.key, b.key);
assert!(a.key.starts_with(b"Pc"));
}
}
+123 -4
View File
@@ -14,7 +14,7 @@ use aws_lc_rs::{
use registry::{
schema::{
enums::*,
prelude::{ObjectType, SocketAddr},
prelude::{Object, ObjectType, SocketAddr},
structs::*,
},
types::{duration::Duration, error::Error, list::List, map::Map},
@@ -388,6 +388,45 @@ async fn insert_safe_defaults(bp: &mut Bootstrap) -> trc::Result<()> {
}
}
// inbuxa: personal-data catalog, defaults D2, D3, D4 and D6 (settled
// 2026-09-28): privacy-leaning values, for new installs only. A server
// with roles is not new, and keeps its settings whether saved or left at
// the default. Each singleton is read, changed and written back whole, so
// anything already in it stays.
#[cfg(not(feature = "test_mode"))]
if bp.registry.count_object(ObjectType::Role).await? == 0 {
let mut security = bp.setting_infallible::<Security>().await;
let mut classifier = bp.setting_infallible::<SpamClassifier>().await;
let mut pyzor = bp.setting_infallible::<SpamPyzor>().await;
let mut retention = bp.setting_infallible::<DataRetention>().await;
new_install_privacy_defaults(&mut security, &mut classifier, &mut pyzor, &mut retention);
for object in [
Object::from(security),
classifier.into(),
pyzor.into(),
retention.into(),
] {
bp.registry.write(RegistryWrite::insert(&object)).await?;
}
// D5: the blocklist sent hashed email addresses starts off; the
// rules load later, from a task, which acts on this note
super::spam_rules::mark_new_install(&bp.data_store).await?;
// D1: rotated log files are kept 30 days (a fork-owned setting,
// since x:TracerLog is also stored inside x:Bootstrap)
use inbuxa_features::security::log_files;
if !log_files::is_set(&bp.data_store).await? {
log_files::set(
&bp.data_store,
&log_files::LogSettings {
keep_for_days: Some(log_files::NEW_INSTALL_KEEP_DAYS),
},
)
.await?;
}
}
if bp.registry.count_object(ObjectType::Role).await? == 0 {
let permissions = DefaultPermissions::default();
let mut role_ids = Vec::with_capacity(4);
@@ -447,6 +486,8 @@ async fn insert_safe_defaults(bp: &mut Bootstrap) -> trc::Result<()> {
// inbuxa: administrator roles stored before a permission existed get it once
super::granted_permissions::grant_new_admin_permissions(bp).await?;
// inbuxa: personal-data catalog: the compliance roles, once per server
super::compliance_roles::ensure_compliance_roles(&bp.registry, &bp.data_store).await?;
if bp
.registry
@@ -535,8 +576,8 @@ async fn insert_safe_defaults(bp: &mut Bootstrap) -> trc::Result<()> {
// inbuxa: rules are always to hand, since a copy ships with the server
// (spam_rules). They load on first boot, and again when the bundled
// version differs from the one last loaded, which only adds what's
// missing: new tags and rules, never a changed score.
// rules differ from the ones last loaded: new tags and rules, fixes to
// rules nobody edited, never a changed score or an admin's edit.
let rules_url = super::spam_rules::rules_url(
bp.registry
.object::<SpamSettings>(Id::singleton())
@@ -547,7 +588,7 @@ async fn insert_safe_defaults(bp: &mut Bootstrap) -> trc::Result<()> {
&& super::spam_rules::applied_version(&bp.data_store)
.await?
.as_deref()
!= Some(super::spam_rules::BUNDLED_SPAM_RULES_VERSION);
!= Some(super::spam_rules::BUNDLED_SPAM_RULES_APPLIED);
if bp.registry.count_object(ObjectType::SpamRule).await? == 0 || bundled_is_new {
let mut batch = BatchBuilder::new();
batch.schedule_task(Task::SpamFilterMaintenance(TaskSpamFilterMaintenance {
@@ -560,3 +601,81 @@ async fn insert_safe_defaults(bp: &mut Bootstrap) -> trc::Result<()> {
Ok(())
}
/// inbuxa: the new-install values of defaults D2, D3, D4 and D6 from the
/// personal-data catalog spec. Automatic IP bans expire after 30 days instead
/// of never; spam training samples are kept 90 days instead of 180; Pyzor,
/// which sends a digest of each message's text to a public server, is off;
/// delivery history is kept 14 days instead of 30.
fn new_install_privacy_defaults(
security: &mut Security,
classifier: &mut SpamClassifier,
pyzor: &mut SpamPyzor,
retention: &mut DataRetention,
) {
const DAY: u64 = 24 * 60 * 60 * 1000;
let ban_period = Some(Duration::from_millis(30 * DAY));
security.auth_ban_period = ban_period;
security.abuse_ban_period = ban_period;
security.loiter_ban_period = ban_period;
security.scan_ban_period = ban_period;
classifier.hold_samples_for = Duration::from_millis(90 * DAY);
pyzor.enable = false;
retention.hold_traces_for = Some(Duration::from_millis(14 * DAY));
}
#[cfg(test)]
mod tests {
use super::*;
const DAY: u64 = 24 * 60 * 60 * 1000;
#[test]
fn new_installs_get_the_privacy_defaults() {
let (mut security, mut classifier, mut pyzor, mut retention) = (
Security::default(),
SpamClassifier::default(),
SpamPyzor::default(),
DataRetention::default(),
);
// What an install gets without them: bans that never lift, 180-day
// samples, Pyzor on, 30-day traces.
assert_eq!(security.auth_ban_period, None);
assert!(pyzor.enable);
new_install_privacy_defaults(&mut security, &mut classifier, &mut pyzor, &mut retention);
for period in [
security.auth_ban_period,
security.abuse_ban_period,
security.loiter_ban_period,
security.scan_ban_period,
] {
assert_eq!(period.map(|p| p.into_inner().as_millis() as u64), Some(30 * DAY));
}
assert_eq!(classifier.hold_samples_for.into_inner().as_millis() as u64, 90 * DAY);
assert!(!pyzor.enable);
assert_eq!(
retention.hold_traces_for.map(|p| p.into_inner().as_millis() as u64),
Some(14 * DAY)
);
}
#[test]
fn everything_else_in_the_settings_stays() {
let mut retention = DataRetention {
archive_deleted_items_for: Some(Duration::from_millis(7 * DAY)),
..Default::default()
};
let before = retention.clone();
new_install_privacy_defaults(
&mut Security::default(),
&mut SpamClassifier::default(),
&mut SpamPyzor::default(),
&mut retention,
);
assert_eq!(retention.archive_deleted_items_for, before.archive_deleted_items_for);
assert_eq!(retention.hold_metrics_for, before.hold_metrics_for);
assert_eq!(retention.expunge_trash_after, before.expunge_trash_after);
}
}
+110 -27
View File
@@ -29,11 +29,68 @@ use trc::AddContext;
use types::id::Id;
/// Granted to the default administrator roles: "Explain this"
/// (ai-explain spec, EX-4: superuser by default).
const ADMIN_GRANTS: &[Permission] = &[Permission::SysAiExplain];
/// (ai-explain spec, EX-4: superuser by default), the audit log, account
/// locks and legal holds (audit-hold-lock spec, AU-9, AL-12, LH-13), and
/// the data inventory (personal-data catalog spec).
const ADMIN_GRANTS: &[Permission] = &[
Permission::SysAiExplain,
Permission::SysAuditGet,
Permission::SysAuditExport,
Permission::SysAuditSettingsUpdate,
Permission::SysAccountLockGet,
Permission::SysAccountLockCreate,
Permission::SysAccountLockUpdate,
Permission::SysAccountLockDestroy,
Permission::SysLegalHoldGet,
Permission::SysLegalHoldCreate,
Permission::SysLegalHoldUpdate,
Permission::SysLegalHoldExport,
Permission::SysComplianceGet,
Permission::SysMailRuleGet,
Permission::SysMailRuleUpdate,
Permission::SysDlpPolicyGet,
Permission::SysDlpPolicyUpdate,
Permission::SysDlpReviewGet,
Permission::SysDlpReviewUpdate,
];
fn granted_key(permission: Permission) -> ValueClass {
/// Granted to the server-level Compliance Officer role once it exists:
/// seeing DLP rules and reviewing held mail (dlp-and-mail-flow-rules spec,
/// §2.8, settled answer 4). A new install's role has them from the start.
const OFFICER_GRANTS: &[Permission] = &[
Permission::SysDlpPolicyGet,
Permission::SysDlpReviewGet,
Permission::SysDlpReviewUpdate,
];
/// Granted to the default tenant administrator roles: reading and exporting
/// the tenant's audit log (AU-9), locking and delegating its accounts
/// (AL-12), and the tenant's slice of the data inventory.
const TENANT_GRANTS: &[Permission] = &[
Permission::SysAuditGet,
Permission::SysAuditExport,
Permission::SysAccountLockGet,
Permission::SysAccountLockCreate,
Permission::SysAccountLockUpdate,
Permission::SysAccountLockDestroy,
Permission::SysComplianceGet,
];
#[derive(Clone, Copy, PartialEq, Eq)]
enum Audience {
Admin,
Tenant,
Officer,
}
fn granted_key(permission: Permission, audience: Audience) -> ValueClass {
let mut key = b"Pg".to_vec();
// Admin grants keep the key they were first recorded under
match audience {
Audience::Admin => {}
Audience::Tenant => key.extend_from_slice(b"tenant:"),
Audience::Officer => key.extend_from_slice(b"officer:"),
}
key.extend_from_slice(permission.as_str().as_bytes());
ValueClass::Any(AnyClass {
subspace: SUBSPACE_INBUXA,
@@ -42,11 +99,17 @@ fn granted_key(permission: Permission) -> ValueClass {
}
pub(crate) async fn grant_new_admin_permissions(bp: &mut Bootstrap) -> trc::Result<()> {
grant(bp, Audience::Admin, ADMIN_GRANTS).await?;
grant(bp, Audience::Tenant, TENANT_GRANTS).await?;
grant(bp, Audience::Officer, OFFICER_GRANTS).await
}
async fn grant(bp: &mut Bootstrap, audience: Audience, grants: &[Permission]) -> trc::Result<()> {
let mut pending = Vec::new();
for permission in ADMIN_GRANTS {
for permission in grants {
if bp
.data_store
.get_value::<String>(ValueKey::from(granted_key(*permission)))
.get_value::<String>(ValueKey::from(granted_key(*permission, audience)))
.await
.caused_by(trc::location!())?
.is_none()
@@ -57,27 +120,47 @@ pub(crate) async fn grant_new_admin_permissions(bp: &mut Bootstrap) -> trc::Resu
if pending.is_empty() {
return Ok(());
}
// An administrator's default roles include the plain User role, which
// every user also holds; only roles that are administrators' alone get it
let admin_roles: Vec<Id> = bp
.registry
.object::<Authentication>(Id::singleton())
.await?
.map(|auth| {
let shared = [
auth.default_user_role_ids.as_slice(),
auth.default_group_role_ids.as_slice(),
auth.default_tenant_role_ids.as_slice(),
]
.concat();
auth.default_admin_role_ids
.as_slice()
.iter()
.filter(|id| !shared.contains(id))
.copied()
.collect()
})
.unwrap_or_default();
// The officer role is the one the server made, if it has made it yet: a
// new install makes it after this, with the permissions already in it
let admin_roles: Vec<Id> = if audience == Audience::Officer {
super::compliance_roles::server_role(&bp.data_store)
.await?
.into_iter()
.collect()
} else {
// An administrator's default roles include the plain User role, which
// every user also holds; only roles that are the audience's alone get it
bp.registry
.object::<Authentication>(Id::singleton())
.await?
.map(|auth| {
let (own, shared) = match audience {
Audience::Admin => (
auth.default_admin_role_ids.as_slice(),
[
auth.default_user_role_ids.as_slice(),
auth.default_group_role_ids.as_slice(),
auth.default_tenant_role_ids.as_slice(),
]
.concat(),
),
Audience::Tenant | Audience::Officer => (
auth.default_tenant_role_ids.as_slice(),
[
auth.default_user_role_ids.as_slice(),
auth.default_group_role_ids.as_slice(),
auth.default_admin_role_ids.as_slice(),
]
.concat(),
),
};
own.iter()
.filter(|id| !shared.contains(id))
.copied()
.collect()
})
.unwrap_or_default()
};
// Fetched by id: the registry's listing doesn't reach stored roles
for role_id in admin_roles {
let Some(stored) = bp
@@ -114,7 +197,7 @@ pub(crate) async fn grant_new_admin_permissions(bp: &mut Bootstrap) -> trc::Resu
}
let mut batch = BatchBuilder::new();
for permission in pending {
batch.set(granted_key(permission), b"granted".to_vec());
batch.set(granted_key(permission, audience), b"granted".to_vec());
}
bp.data_store
.write(batch.build_all())
+1
View File
@@ -18,6 +18,7 @@ use utils::HttpLimitResponse;
pub mod application;
pub mod backup;
pub mod boot;
pub mod compliance_roles; // inbuxa: personal-data catalog, the compliance roles
pub mod console;
pub mod defaults;
pub mod first_party;
+133 -8
View File
@@ -12,11 +12,16 @@
//! and license) and uses it whenever no other source is configured. The rules
//! URL remains an operator override (`https://` or `file://`).
//!
//! Loading rules only ever adds what's missing, never changes an existing rule
//! or score. They load on first boot, and again whenever the bundled version
//! differs from the one last applied, so an upgrade brings new tags (the AI
//! classifier's `LLM_*` scores, say) to an install that already had rules.
//! Loading rules adds what's missing and brings an existing rule up to date,
//! but never touches one an admin edited: every object an update writes is
//! fingerprinted, and one that no longer matches its fingerprint is kept as
//! it is. Tags (scores) are never replaced. Switching a rule on or off isn't
//! an edit, and is kept either way. They load on first boot, and again
//! whenever the bundled rules differ from the ones last applied, so an
//! upgrade brings new tags (the AI classifier's `LLM_*` scores, say) and
//! fixed rules to an install that already had rules.
use registry::{schema::prelude::ObjectType, types::EnumImpl};
use std::io::Read;
use store::{
SUBSPACE_INBUXA, Store, ValueKey,
@@ -27,13 +32,17 @@ use trc::AddContext;
/// The version of spam-filter the embedded rules come from.
pub const BUNDLED_SPAM_RULES_VERSION: &str = "3.0.2";
/// What's recorded once the bundled rules are loaded: their version, then the
/// fork's own generation of the update, so a change to how an update applies
/// runs it once more. Generation 2 fingerprints (upstream v0.16.24).
pub const BUNDLED_SPAM_RULES_APPLIED: &str = "3.0.2+2";
static BUNDLED_SPAM_RULES: &[u8] =
include_bytes!("../../../../resources/spam-filter/spam-filter-rules.json.gz");
/// Upstream's default rules source, the value every install created before
/// the rules were bundled has saved. Read only to treat it as unset.
const LEGACY_DEFAULT_URL: &str =
"https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz";
const LEGACY_DEFAULT_URL: &str = "https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz";
/// The URL to fetch rules from, or `None` for the bundled rules. An empty
/// setting and upstream's old default both mean the bundled rules.
@@ -57,14 +66,49 @@ fn applied_key() -> ValueClass {
})
}
/// The bundled version last loaded into the registry, if any.
fn fingerprint_key(object: ObjectType, id: u64) -> ValueClass {
let mut key = b"Sf".to_vec();
key.extend_from_slice(object.as_str().as_bytes());
key.push(0);
key.extend_from_slice(&id.to_be_bytes());
ValueClass::Any(AnyClass {
subspace: SUBSPACE_INBUXA,
key,
})
}
/// The fingerprint of what a rules update last wrote to this object, if one
/// did.
pub async fn fingerprint(data: &Store, object: ObjectType, id: u64) -> trc::Result<Option<String>> {
data.get_value::<String>(ValueKey::from(fingerprint_key(object, id)))
.await
.caused_by(trc::location!())
}
/// Records the fingerprint of what a rules update wrote to this object.
pub async fn set_fingerprint(
data: &Store,
object: ObjectType,
id: u64,
fingerprint: &str,
) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
batch.set(fingerprint_key(object, id), fingerprint.as_bytes().to_vec());
data.write(batch.build_all())
.await
.caused_by(trc::location!())
.map(|_| ())
}
/// The bundled rules last loaded into the registry, if any
/// ([`BUNDLED_SPAM_RULES_APPLIED`]'s form).
pub async fn applied_version(data: &Store) -> trc::Result<Option<String>> {
data.get_value::<String>(ValueKey::from(applied_key()))
.await
.caused_by(trc::location!())
}
/// Records that the bundled rules of this version have been loaded.
/// Records that the bundled rules have been loaded.
pub async fn set_applied_version(data: &Store, version: &str) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
batch.set(applied_key(), version.as_bytes().to_vec());
@@ -74,6 +118,78 @@ pub async fn set_applied_version(data: &Store, version: &str) -> trc::Result<()>
.map(|_| ())
}
/// The blocklists a new install starts with switched off (personal-data
/// catalog spec, default D5, settled 2026-09-28): the one that is sent a
/// hash of every email address it's asked about.
pub const NEW_INSTALL_OFF: &[&str] = &["STWT_MSBL_EBL_EMAIL"];
fn new_install_key() -> ValueClass {
ValueClass::Any(AnyClass {
subspace: SUBSPACE_INBUXA,
key: b"Sn".to_vec(),
})
}
/// Notes, on a new install's first boot, that [`NEW_INSTALL_OFF`] is to be
/// switched off once the rules are in: they load later, from a task.
pub async fn mark_new_install(data: &Store) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
batch.set(new_install_key(), b"D5".to_vec());
data.write(batch.build_all())
.await
.caused_by(trc::location!())
.map(|_| ())
}
/// After rules load: on a new install, switches [`NEW_INSTALL_OFF`] off and
/// forgets the note, so it happens once. Returns whether anything changed.
/// An existing server has no note, and keeps every blocklist as it is.
pub async fn apply_new_install(
registry: &store::RegistryStore,
data: &Store,
) -> trc::Result<bool> {
use registry::schema::{prelude::Object, structs::SpamDnsblServer};
use store::registry::write::RegistryWrite;
if data
.get_value::<String>(ValueKey::from(new_install_key()))
.await
.caused_by(trc::location!())?
.is_none()
{
return Ok(false);
}
let mut changed = false;
for server in registry.list::<SpamDnsblServer>().await? {
let mut updated = server.object.clone();
let SpamDnsblServer::Email(email) = &mut updated else {
continue;
};
if !NEW_INSTALL_OFF.contains(&email.name.as_str()) || !email.enable {
continue;
}
email.enable = false;
let old = Object {
inner: server.object.into(),
revision: server.revision,
};
let new = Object {
inner: updated.into(),
revision: server.revision,
};
registry
.write(RegistryWrite::update(types::id::Id::from(server.id.id()), &new, &old))
.await?;
changed = true;
}
let mut batch = BatchBuilder::new();
batch.clear(new_install_key());
data.write(batch.build_all())
.await
.caused_by(trc::location!())?;
Ok(changed)
}
#[cfg(test)]
mod tests {
use super::*;
@@ -90,6 +206,15 @@ mod tests {
);
}
#[test]
fn applied_marker_names_the_bundled_version() {
assert!(
BUNDLED_SPAM_RULES_APPLIED
.strip_prefix(BUNDLED_SPAM_RULES_VERSION)
.is_some_and(|generation| generation.starts_with('+'))
);
}
#[test]
fn bundled_rules_parse_and_score_the_ai_tags() {
let rules: serde_json::Value = serde_json::from_slice(&bundled_rules().unwrap()).unwrap();
+19 -5
View File
@@ -1,7 +1,10 @@
/*
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <[email protected]>
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
*
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use crate::{
@@ -72,11 +75,22 @@ impl Server {
.acme_certificate_renewal_due(&domains, renew_before, now())
.await?
{
return Err(AcmeError::NotDue(format!(
"Certificate for domain {} is still valid; renewal is not due until {}",
domain.name,
UTCDateTime::from_timestamp(renew_at as i64)
)));
// INBUXA: a certificate already covering these names (one stored by
// hand before the domain was switched to automatic, say) isn't a
// failure: schedule the renewal for when it falls due. Returning
// NotDue here ended the task for good, and nothing renewed the
// certificate before it expired.
trc::event!(
Acme(trc::AcmeEvent::RenewBackoff),
Domain = domain.name.clone(),
Hostname = domains.as_slice(),
Details = "A valid certificate already covers these names",
NextRetry = trc::Value::Timestamp(renew_at),
);
return Ok(vec![Task::AcmeRenewal(TaskDomainManagement {
domain_id,
status: TaskStatus::at(renew_at as i64),
})]);
}
let dns_parameters = match &domain.dns_management {
@@ -6,12 +6,13 @@
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use crate::{Server, manager::application::Resource, network::legacy::is_legacy_service};
use crate::{Server, manager::application::Resource};
use quick_xml::Reader;
use quick_xml::XmlVersion;
use quick_xml::events::Event;
use registry::schema::enums::ServiceProtocol;
use registry::schema::{enums::ServiceProtocol, structs::Service};
use std::fmt::Write;
use utils::map::vec_map::VecMap;
impl Server {
pub async fn handle_autodiscover_request(
@@ -26,89 +27,103 @@ impl Server {
.details("Failed to parse autodiscover request")
.ctx(trc::Key::Reason, err)
})?;
let default_host = &self.core.network.server_name;
// Build XML response
let mut config = String::with_capacity(1024);
let _ = writeln!(&mut config, "<?xml version=\"1.0\" encoding=\"UTF-8\"?>");
let _ = writeln!(
&mut config,
"<Autodiscover xmlns=\"http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006\">"
);
let _ = writeln!(
&mut config,
"\t<Response xmlns=\"http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a\">"
);
let _ = writeln!(&mut config, "\t\t<User>");
let _ = writeln!(
&mut config,
"\t\t\t<DisplayName>{emailaddress}</DisplayName>"
);
let _ = writeln!(
&mut config,
"\t\t\t<AutoDiscoverSMTPAddress>{emailaddress}</AutoDiscoverSMTPAddress>"
);
// DeploymentId is a required field of User but we are not a MS Exchange server so use a random value
let _ = writeln!(
&mut config,
"\t\t\t<DeploymentId>644560b8-a1ce-429c-8ace-23395843f701</DeploymentId>"
);
let _ = writeln!(&mut config, "\t\t</User>");
let _ = writeln!(&mut config, "\t\t<Account>");
let _ = writeln!(&mut config, "\t\t\t<AccountType>email</AccountType>");
let _ = writeln!(&mut config, "\t\t\t<Action>settings</Action>");
// inbuxa: legacy-protocols LP-7, LP-14a
let legacy_off = match emailaddress.rsplit_once('@') {
Some((_, domain)) => self.legacy_protocols_off_for(domain).await?,
None => self.legacy_protocols_off_for("").await?,
Some((_, domain)) => self.legacy_off_for(domain).await?,
None => self.legacy_off_for("").await?,
};
for (protocol, service) in &self.core.network.info.services {
if legacy_off && is_legacy_service(protocol) {
continue;
}
let (protocol, ports) = match protocol {
ServiceProtocol::Imap => ("IMAP", [143, 993]),
ServiceProtocol::Pop3 => ("POP3", [110, 995]),
ServiceProtocol::Smtp => ("SMTP", [587, 465]),
_ => continue,
};
for (is_tls, port) in ports.into_iter().enumerate() {
if is_tls == 1 || service.cleartext {
let server_name = service.hostname.as_deref().unwrap_or(default_host);
let _ = writeln!(&mut config, "\t\t\t<Protocol>");
let _ = writeln!(&mut config, "\t\t\t\t<Type>{protocol}</Type>",);
let _ = writeln!(&mut config, "\t\t\t\t<Server>{server_name}</Server>");
let _ = writeln!(&mut config, "\t\t\t\t<Port>{port}</Port>");
let _ = writeln!(&mut config, "\t\t\t\t<LoginName>{emailaddress}</LoginName>");
let _ = writeln!(&mut config, "\t\t\t\t<AuthRequired>on</AuthRequired>");
let _ = writeln!(&mut config, "\t\t\t\t<DirectoryPort>0</DirectoryPort>");
let _ = writeln!(&mut config, "\t\t\t\t<ReferralPort>0</ReferralPort>");
let _ = writeln!(
&mut config,
"\t\t\t\t<SSL>{}</SSL>",
if is_tls == 1 { "on" } else { "off" }
);
if is_tls == 1 {
let _ = writeln!(&mut config, "\t\t\t\t<Encryption>TLS</Encryption>");
}
let _ = writeln!(&mut config, "\t\t\t\t<SPA>off</SPA>");
let _ = writeln!(&mut config, "\t\t\t</Protocol>");
}
}
}
let _ = writeln!(&mut config, "\t\t</Account>");
let _ = writeln!(&mut config, "\t</Response>");
let _ = writeln!(&mut config, "</Autodiscover>");
Ok(Resource::new(
"application/xml; charset=utf-8",
config.into_bytes(),
build_autodiscover_response(
&emailaddress,
&self.core.network.server_name,
&self.core.network.info.services,
|protocol| legacy_off.service(protocol),
)
.into_bytes(),
))
}
}
fn build_autodiscover_response(
emailaddress: &str,
default_host: &str,
services: &VecMap<ServiceProtocol, Service>,
switched_off: impl Fn(&ServiceProtocol) -> bool,
) -> String {
// Build XML response
let mut config = String::with_capacity(1024);
let _ = writeln!(&mut config, "<?xml version=\"1.0\" encoding=\"UTF-8\"?>");
let _ = writeln!(
&mut config,
"<Autodiscover xmlns=\"http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006\">"
);
let _ = writeln!(
&mut config,
"\t<Response xmlns=\"http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a\">"
);
let _ = writeln!(&mut config, "\t\t<User>");
let _ = writeln!(
&mut config,
"\t\t\t<DisplayName>{emailaddress}</DisplayName>"
);
let _ = writeln!(
&mut config,
"\t\t\t<AutoDiscoverSMTPAddress>{emailaddress}</AutoDiscoverSMTPAddress>"
);
// DeploymentId is a required field of User but we are not a MS Exchange server so use a random value
let _ = writeln!(
&mut config,
"\t\t\t<DeploymentId>644560b8-a1ce-429c-8ace-23395843f701</DeploymentId>"
);
let _ = writeln!(&mut config, "\t\t</User>");
let _ = writeln!(&mut config, "\t\t<Account>");
let _ = writeln!(&mut config, "\t\t\t<AccountType>email</AccountType>");
let _ = writeln!(&mut config, "\t\t\t<Action>settings</Action>");
for (protocol, service) in services {
if switched_off(protocol) {
continue;
}
let (protocol, ports) = match protocol {
ServiceProtocol::Imap => ("IMAP", [(993, true), (143, false)]),
ServiceProtocol::Pop3 => ("POP3", [(995, true), (110, false)]),
ServiceProtocol::Smtp => ("SMTP", [(465, true), (587, false)]),
_ => continue,
};
// Implicit TLS is listed first so that it is preferred (RFC 8314)
for (port, is_tls) in ports {
if is_tls || service.cleartext {
let server_name = service.hostname.as_deref().unwrap_or(default_host);
let _ = writeln!(&mut config, "\t\t\t<Protocol>");
let _ = writeln!(&mut config, "\t\t\t\t<Type>{protocol}</Type>",);
let _ = writeln!(&mut config, "\t\t\t\t<Server>{server_name}</Server>");
let _ = writeln!(&mut config, "\t\t\t\t<Port>{port}</Port>");
let _ = writeln!(&mut config, "\t\t\t\t<LoginName>{emailaddress}</LoginName>");
let _ = writeln!(&mut config, "\t\t\t\t<AuthRequired>on</AuthRequired>");
let _ = writeln!(&mut config, "\t\t\t\t<DirectoryPort>0</DirectoryPort>");
let _ = writeln!(&mut config, "\t\t\t\t<ReferralPort>0</ReferralPort>");
let (ssl, encryption) = if is_tls {
("on", "SSL")
} else {
("off", "TLS")
};
let _ = writeln!(&mut config, "\t\t\t\t<SSL>{ssl}</SSL>");
let _ = writeln!(&mut config, "\t\t\t\t<Encryption>{encryption}</Encryption>");
let _ = writeln!(&mut config, "\t\t\t\t<SPA>off</SPA>");
let _ = writeln!(&mut config, "\t\t\t</Protocol>");
}
}
}
let _ = writeln!(&mut config, "\t\t</Account>");
let _ = writeln!(&mut config, "\t</Response>");
let _ = writeln!(&mut config, "</Autodiscover>");
config
}
fn parse_autodiscover_request(bytes: &[u8]) -> Result<String, String> {
if bytes.is_empty() {
return Err("Empty request body".to_string());
@@ -211,4 +226,79 @@ mod tests {
"[email protected]"
);
}
#[test]
fn autodiscover_encryption() {
use registry::schema::{enums::ServiceProtocol, structs::Service};
use utils::map::vec_map::VecMap;
fn tag<'x>(block: &'x str, name: &str) -> &'x str {
block
.split_once(&format!("<{name}>"))
.and_then(|(_, rest)| rest.split_once(&format!("</{name}>")))
.map(|(value, _)| value)
.unwrap()
}
for (cleartext, expected) in [
(
false,
vec![
("IMAP", "993", "on", "SSL"),
("POP3", "995", "on", "SSL"),
("SMTP", "465", "on", "SSL"),
],
),
(
true,
vec![
("IMAP", "993", "on", "SSL"),
("IMAP", "143", "off", "TLS"),
("POP3", "995", "on", "SSL"),
("POP3", "110", "off", "TLS"),
("SMTP", "465", "on", "SSL"),
("SMTP", "587", "off", "TLS"),
],
),
] {
let services: VecMap<ServiceProtocol, Service> = [
ServiceProtocol::Imap,
ServiceProtocol::Pop3,
ServiceProtocol::Smtp,
ServiceProtocol::Jmap,
]
.into_iter()
.map(|protocol| {
(
protocol,
Service {
hostname: None,
cleartext,
},
)
})
.collect();
let response = super::build_autodiscover_response(
"[email protected]",
"mail.example.com",
&services,
|_| false,
);
assert_eq!(
response
.split("<Protocol>")
.skip(1)
.map(|block| (
tag(block, "Type"),
tag(block, "Port"),
tag(block, "SSL"),
tag(block, "Encryption"),
))
.collect::<Vec<_>>(),
expected,
"cleartext: {cleartext}"
);
}
}
}
@@ -6,7 +6,7 @@
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use crate::{Server, manager::application::Resource, network::legacy::is_legacy_service};
use crate::{Server, manager::application::Resource};
use registry::schema::enums::ServiceProtocol;
use std::fmt::Write;
use utils::url_params::UrlParams;
@@ -31,7 +31,7 @@ impl Server {
};
// inbuxa: legacy-protocols LP-7, LP-14a
let legacy_off = self.legacy_protocols_off_for(domain).await?;
let legacy_off = self.legacy_off_for(domain).await?;
// Build XML response
let mut config = String::with_capacity(1024);
@@ -45,7 +45,7 @@ impl Server {
"\t\t<displayShortName>{domain}</displayShortName>"
);
for (protocol, service) in &self.core.network.info.services {
if legacy_off && is_legacy_service(protocol) {
if legacy_off.service(protocol) {
continue;
}
let (protocol, tag, ports) = match protocol {
+7 -14
View File
@@ -6,11 +6,7 @@
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use crate::{
Server,
config::network::Pacc,
network::{dkim::generate_dkim_dns_record, legacy::is_legacy_service},
};
use crate::{Server, config::network::Pacc, network::dkim::generate_dkim_dns_record};
use ahash::{AHashMap, AHashSet};
use base64::{Engine, engine::general_purpose};
use dns_update::{
@@ -41,7 +37,7 @@ impl Server {
let default_host = network.server_name.as_str();
let domain_name = domain.name.as_str();
// inbuxa: legacy-protocols LP-7, LP-14a
let legacy_off = self.legacy_protocols_off_for(domain_name).await?;
let legacy_off = self.legacy_off_for(domain_name).await?;
let domain_name_suffix = format!(".{domain_name}");
for record_type in record_types {
@@ -205,7 +201,7 @@ impl Server {
// name says "not offered" -- target "." (RFC 6186 section
// 3.4) -- rather than vanishing, so a client that looks
// is told, and an old record left in the zone is replaced.
if legacy_off && is_legacy_service(protocol) {
if legacy_off.service(protocol) {
for (service_name, _) in services {
records.push(NamedDnsRecord {
name: format!("_{service_name}._tcp.{domain_name}."),
@@ -307,8 +303,8 @@ impl Server {
// inbuxa: legacy-protocols LP-7. No TLS pin for a port
// the switch has closed. Submission's port stays open
// (the SMTP lock), so its record stays.
if legacy_off
&& matches!(protocol, ServiceProtocol::Imap | ServiceProtocol::Pop3)
if matches!(protocol, ServiceProtocol::Imap | ServiceProtocol::Pop3)
&& legacy_off.service(protocol)
{
continue;
}
@@ -418,11 +414,8 @@ impl Server {
pub async fn get_pacc_for_domain(&self, domain_name: &str) -> trc::Result<String> {
// inbuxa: legacy-protocols LP-7, LP-14a
let pacc = if self.legacy_protocols_off_for(domain_name).await? {
&self.core.network.info.pacc_jmap_only
} else {
&self.core.network.info.pacc
};
let off = self.legacy_off_for(domain_name).await?;
let pacc = &self.core.network.info.pacc[off.index()];
self.get_directory_for_domain(domain_name)
.await
.caused_by(trc::location!())
+14
View File
@@ -961,6 +961,20 @@ impl DnsUpdater {
)
.map_err(|err| format!("Failed to build DNS updater: {}", err))?,
}),
DnsServer::PowerDns(server) => Ok(DnsUpdater {
polling_interval: server.polling_interval.into_inner(),
propagation_timeout: server.propagation_timeout.into_inner(),
propagation_delay: server.propagation_delay.map(|d| d.into_inner()),
ttl: server.ttl.into_inner(),
core,
updater: dns_update::DnsUpdater::new_pdns(
server.api_key.secret().await?,
server.endpoint,
server.server_id,
server.timeout.into_inner().into(),
)
.map_err(|err| format!("Failed to build DNS updater: {}", err))?,
}),
DnsServer::Safedns(server) => Ok(DnsUpdater {
polling_interval: server.polling_interval.into_inner(),
propagation_timeout: server.propagation_timeout.into_inner(),
+191 -63
View File
@@ -35,8 +35,8 @@ use directory::Credentials;
use inbuxa_features::security::{
legacy_use::{self, LegacyUse},
listeners,
protocol_policy::{self, ProtocolPolicy, SavedListener},
tenant_protocol_policy,
protocol_policy::{self, ProtocolPolicy, SUBMISSION, SWITCHED, SavedListener, Switches},
tenant_protocol_policy::{self, OffBy, TenantProtocolPolicy},
};
use registry::schema::enums::ServiceProtocol;
use registry::types::{error::Error, id::ObjectId};
@@ -97,40 +97,48 @@ impl Server {
// this, and a /set that omitted it must not lose the listeners still
// waiting to come back.
let previous = self.protocol_policy().await?;
policy.saved_listeners = previous.saved_listeners;
policy.saved_listeners = previous.saved_listeners.clone();
policy.changed_at = Some(store::write::now() * 1000);
policy.changed_by = changed_by;
policy.normalize();
if policy.legacy_protocols.is_disabled() {
self.close_legacy_listeners(&mut policy, &mut change).await?;
} else {
self.reopen_legacy_listeners(&mut policy, &mut change)
.await?;
}
// Each protocol on its own switch: close what is off now, and put
// back what was saved for a protocol that is on again. Either may
// happen in one change, when one protocol goes off as another comes
// back.
self.close_legacy_listeners(&mut policy, &mut change)
.await?;
self.reopen_legacy_listeners(&mut policy, &mut change)
.await?;
protocol_policy::set(&self.core.storage.data, &policy).await?;
// LP-8. Raised here rather than by the JMAP method, so whatever turns
// the switch is reported. A /set that changed nothing -- the switch
// a switch is reported. A /set that changed nothing -- every switch
// already where it was asked to be, nothing to close or reopen -- is
// not a change.
if previous.legacy_protocols != policy.legacy_protocols || !change.is_empty() {
let (moved, direction) = if policy.legacy_protocols.is_disabled() {
(&change.closed, "closed")
} else {
(&change.reopened, "reopened")
};
let mut before = previous;
before.normalize();
if before.off() != policy.off() || !change.is_empty() {
// The closed first, then the reopened; `Details` says which.
let moved = change
.closed
.iter()
.chain(change.reopened.iter())
.map(|l| l.id.clone());
trc::event!(
Security(trc::SecurityEvent::LegacyProtocolsChanged),
Policy = "server",
Value = if policy.legacy_protocols.is_disabled() {
"disabled"
} else {
"enabled"
},
Value = switches_value(&policy),
AccountId = policy.changed_by.clone(),
Details = direction,
ListenerId = listener_names(moved.iter().map(|l| l.id.clone())),
Details = if change.closed.is_empty() {
"reopened"
} else if change.reopened.is_empty() {
"closed"
} else {
"closed and reopened"
},
ListenerId = listener_names(moved),
// Only when a listener could not be put back (LP-5).
Reason = (!change.failed.is_empty()).then(|| listener_names(
change
@@ -165,21 +173,27 @@ impl Server {
Ok(())
}
/// Puts back every saved listener and starts it again (LP-5).
/// Puts back every saved listener whose protocol is on again, and starts
/// it (LP-5). The rest stay saved.
async fn reopen_legacy_listeners(
&self,
policy: &mut ProtocolPolicy,
change: &mut PolicyChange,
) -> trc::Result<()> {
if policy.saved_listeners.is_empty() {
let (wanted, still_closed): (Vec<_>, Vec<_>) = std::mem::take(&mut policy.saved_listeners)
.into_iter()
.partition(|saved| !policy.closes(&saved.protocol, &saved.ports));
policy.saved_listeners = still_closed;
if wanted.is_empty() {
return Ok(());
}
let saved = std::mem::take(&mut policy.saved_listeners);
let (restored, failed) = listeners::reopen(self.registry(), &saved).await?;
let (restored, failed) = listeners::reopen(self.registry(), &wanted).await?;
// A listener that could not be put back stays saved for another try.
policy.saved_listeners = failed.iter().map(|(listener, _)| listener.clone()).collect();
policy
.saved_listeners
.extend(failed.iter().map(|(listener, _)| listener.clone()));
change.failed = failed;
if !restored.is_empty() {
@@ -254,6 +268,17 @@ impl Server {
}
}
/// The switches as an event value: `disabled` or `enabled` when all three
/// agree, otherwise which are off, such as `pop3 disabled` (LP-8).
pub fn switches_value(policy: &impl Switches) -> String {
let off = policy.off();
match off.len() {
0 => "enabled".to_string(),
n if n == SWITCHED.len() => "disabled".to_string(),
_ => format!("{} disabled", off.join(", ")),
}
}
/// Names for an event field: the listeners a change closed, reopened or
/// failed to reopen (LP-8).
fn listener_names<T: Into<trc::Value>>(names: impl Iterator<Item = T>) -> trc::Value {
@@ -395,15 +420,18 @@ impl Server {
credentials: &Credentials,
) -> trc::Result<()> {
let domain = domain_of(credentials);
if self.protocol_policy().await?.legacy_protocols.is_disabled() {
let server = self.protocol_policy().await?;
if server.is_off(protocol.as_str()) {
return Err(protocol.refused(RefusalScope::Server, domain));
}
if let Some(name) = &domain
&& let Some(domain) = self.domain(name).await?
&& let Some(tenant_id) = domain.id_tenant
&& self.tenant_legacy_protocols_off(tenant_id).await?
{
return Err(protocol.refused(RefusalScope::Tenant(tenant_id), Some(name.clone())));
let tenant = self.tenant_protocol_policy(tenant_id).await?;
if tenant_protocol_policy::off_by(&server, Some(&tenant), protocol.as_str()).is_some() {
return Err(protocol.refused(RefusalScope::Tenant(tenant_id), Some(name.clone())));
}
}
Ok(())
}
@@ -422,10 +450,16 @@ impl Server {
protocol: LegacyProtocol,
access_token: &AccessToken,
) -> trc::Result<()> {
if let Some(tenant_id) = access_token.tenant_id()
&& self.tenant_legacy_protocols_off(tenant_id).await?
{
return Err(protocol.refused(RefusalScope::Tenant(tenant_id), None));
if let Some(tenant_id) = access_token.tenant_id() {
let server = self.protocol_policy().await?;
let tenant = self.tenant_protocol_policy(tenant_id).await?;
match tenant_protocol_policy::off_by(&server, Some(&tenant), protocol.as_str()) {
Some(OffBy::Server) => return Err(protocol.refused(RefusalScope::Server, None)),
Some(OffBy::Tenant) => {
return Err(protocol.refused(RefusalScope::Tenant(tenant_id), None));
}
None => {}
}
}
if let Err(err) = legacy_use::record(
&self.core.storage.data,
@@ -463,31 +497,96 @@ impl Server {
Ok(recent)
}
/// Whether legacy protocols are off for this account: the stricter of the
/// server's switch and its tenant's. What the JMAP session tells the
/// Which legacy protocols are off for this account: each the stricter of
/// the server's switch and its tenant's. What the JMAP session tells the
/// account's apps (legacy-protocols spec, Interfaces), so the webmail can
/// say why a mail app won't connect (LP-19).
pub async fn legacy_protocols_off_for_account(
pub async fn legacy_off_for_account(
&self,
access_token: &AccessToken,
) -> trc::Result<bool> {
if self.protocol_policy().await?.legacy_protocols.is_disabled() {
return Ok(true);
}
match access_token.tenant_id() {
Some(tenant_id) => self.tenant_legacy_protocols_off(tenant_id).await,
None => Ok(false),
) -> trc::Result<LegacyOff> {
let server = self.protocol_policy().await?;
let tenant = match access_token.tenant_id() {
Some(tenant_id) => Some(self.tenant_protocol_policy(tenant_id).await?),
None => None,
};
Ok(LegacyOff::of(&server, tenant.as_ref()))
}
/// A tenant's switches, or all on when it has never set them (LP-10).
pub async fn tenant_protocol_policy(
&self,
tenant_id: u32,
) -> trc::Result<TenantProtocolPolicy> {
tenant_protocol_policy::get(&self.core.storage.data, tenant_id).await
}
}
/// Which legacy protocols are off, for one account or one domain: the server's
/// switches and the tenant's together. Submission is off only when all three
/// are.
#[derive(Debug, Clone, Copy, Default, PartialEq, Eq)]
pub struct LegacyOff {
pub imap: bool,
pub pop3: bool,
pub manage_sieve: bool,
pub submission: bool,
}
impl LegacyOff {
pub fn of(server: &ProtocolPolicy, tenant: Option<&TenantProtocolPolicy>) -> Self {
let off = |protocol| tenant_protocol_policy::off_by(server, tenant, protocol).is_some();
LegacyOff {
imap: off("imap"),
pop3: off("pop3"),
manage_sieve: off("manageSieve"),
submission: off(SUBMISSION),
}
}
/// Whether a tenant has turned legacy protocols off for itself (LP-10).
pub async fn tenant_legacy_protocols_off(&self, tenant_id: u32) -> trc::Result<bool> {
Ok(
tenant_protocol_policy::get(&self.core.storage.data, tenant_id)
.await?
.legacy_protocols
.is_disabled(),
)
/// Whether this configured service must not be offered (LP-7). SMTP here
/// is submission; inbound mail is never a configured service.
pub fn service(&self, protocol: &ServiceProtocol) -> bool {
match protocol {
ServiceProtocol::Imap => self.imap,
ServiceProtocol::Pop3 => self.pop3,
ServiceProtocol::Managesieve => self.manage_sieve,
ServiceProtocol::Smtp => self.submission,
_ => false,
}
}
/// Whether anything is off.
pub fn any(&self) -> bool {
self.imap || self.pop3 || self.manage_sieve || self.submission
}
/// Whether everything is off: the kill-all's effect.
pub fn all(&self) -> bool {
self.imap && self.pop3 && self.manage_sieve && self.submission
}
/// An index for answers prepared once per combination (the PACC
/// document): one bit per protocol.
pub fn index(&self) -> usize {
(self.imap as usize)
| (self.pop3 as usize) << 1
| (self.manage_sieve as usize) << 2
| (self.submission as usize) << 3
}
/// The protocols that are still allowed, by JMAP name, for the session.
pub fn allowed(&self) -> Vec<&'static str> {
[
("imap", self.imap),
("pop3", self.pop3),
("manageSieve", self.manage_sieve),
(SUBMISSION, self.submission),
]
.into_iter()
.filter(|(_, off)| !off)
.map(|(name, _)| name)
.collect()
}
}
@@ -505,21 +604,20 @@ pub fn is_legacy_service(protocol: &ServiceProtocol) -> bool {
}
impl Server {
/// Whether legacy services are off for this domain, for the answers that
/// Which legacy services are off for this domain, for the answers that
/// must stop offering them: off for the whole server (LP-7), or for the
/// tenant the domain belongs to (LP-14a). Read per answer, as sign-in
/// reads it. A name that is no domain here answers for the server alone.
pub async fn legacy_protocols_off_for(&self, domain_name: &str) -> trc::Result<bool> {
if self.protocol_policy().await?.legacy_protocols.is_disabled() {
return Ok(true);
}
match self.domain(domain_name).await? {
pub async fn legacy_off_for(&self, domain_name: &str) -> trc::Result<LegacyOff> {
let server = self.protocol_policy().await?;
let tenant = match self.domain(domain_name).await? {
Some(domain) => match domain.id_tenant {
Some(tenant_id) => self.tenant_legacy_protocols_off(tenant_id).await,
None => Ok(false),
Some(tenant_id) => Some(self.tenant_protocol_policy(tenant_id).await?),
None => None,
},
None => Ok(false),
}
None => None,
};
Ok(LegacyOff::of(&server, tenant.as_ref()))
}
}
@@ -619,6 +717,36 @@ mod tests {
}
}
#[test]
fn what_is_off_for_one_account_or_domain() {
use inbuxa_features::security::protocol_policy::LegacyProtocols;
let mut server = ProtocolPolicy::default();
server.set("pop3", LegacyProtocols::Disabled);
let mut tenant = TenantProtocolPolicy::default();
tenant.set("manageSieve", LegacyProtocols::Disabled);
let off = LegacyOff::of(&server, Some(&tenant));
assert!(off.pop3 && off.manage_sieve && !off.imap && !off.submission);
assert!(off.service(&ServiceProtocol::Pop3));
assert!(!off.service(&ServiceProtocol::Imap));
assert!(
!off.service(&ServiceProtocol::Smtp),
"sending is still offered"
);
assert!(!off.service(&ServiceProtocol::Jmap));
assert_eq!(off.allowed(), vec!["imap", "submission"]);
assert!(off.any() && !off.all());
let off = LegacyOff::of(&server, None);
assert_eq!(off.index(), 0b0010);
server.set_all(LegacyProtocols::Disabled);
let off = LegacyOff::of(&server, None);
assert!(off.all());
assert_eq!(off.index(), 0b1111);
assert!(off.allowed().is_empty());
}
#[test]
fn the_domain_comes_from_the_name_given() {
assert_eq!(domain_of(&basic("[email protected]")), Some("b.test".to_string()));
+40 -5
View File
@@ -2,6 +2,8 @@
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
*
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
*
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use crate::{
@@ -335,9 +337,10 @@ impl Server {
.insert(IpWithTtl::new(ip, expires_at.unwrap_or(u64::MAX)));
// Write blocked IP to config
let RegistryWriteResult::Success(id) = self
.registry()
.write(RegistryWrite::insert(
// inbuxa: AU-1.10: recorded as the server's automatic ban
let RegistryWriteResult::Success(id) = inbuxa_features::audit::scope::system(
"auto-ban",
self.registry().write(RegistryWrite::insert(
&BlockedIp {
address: IpAddrOrMask::from_ip(ip),
created_at: UTCDateTime::from_timestamp(now as i64),
@@ -345,8 +348,9 @@ impl Server {
reason,
}
.into(),
))
.await
)),
)
.await
.caused_by(trc::location!())?
else {
return Ok(());
@@ -422,6 +426,37 @@ impl Server {
}
}
impl Server {
/// inbuxa: personal-data catalog, D2: removes bans whose period is over.
/// They already stop blocking when they expire, and go when settings are
/// next loaded; the daily clean-up makes sure a server that seldom
/// reloads doesn't keep them.
pub async fn purge_expired_blocked_ips(&self) -> trc::Result<()> {
let now = now() as i64;
let mut expired = Vec::new();
for ip in self.registry().list::<BlockedIp>().await? {
if ip.object.expires_at.as_ref().is_some_and(|at| at.timestamp() <= now) {
let address = ip.object.address.clone();
let object = Object {
inner: ip.object.into(),
revision: ip.revision,
};
self.registry()
.write(RegistryWrite::delete_object(ip.id, &object))
.await?;
expired.push(trc::Value::from(address.into_inner().0));
}
}
if !expired.is_empty() {
trc::event!(
Security(trc::SecurityEvent::IpBlockExpired),
Details = expired
);
}
Ok(())
}
}
impl BlockedIps {
pub async fn parse(bp: &mut Bootstrap) -> Self {
let mut ips = Self::default();
+102 -36
View File
@@ -6,33 +6,79 @@
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use ahash::AHashMap;
use base64::{Engine, engine::general_purpose::URL_SAFE_NO_PAD};
use p256::{
SecretKey,
ecdsa::{Signature, SigningKey, signature::Signer},
pkcs8::{DecodePrivateKey, PrivateKeyInfo, der::SecretDocument},
};
use parking_lot::Mutex;
use reqwest::{Url, header::HeaderValue};
use std::sync::Arc;
const VAPID_TOKEN_TTL: u64 = 12 * 60 * 60;
const VAPID_TOKEN_REFRESH: u64 = VAPID_TOKEN_TTL / 2;
#[derive(Clone)]
pub struct Vapid {
key: VapidKey,
contact: Option<String>,
tokens: Arc<Mutex<AHashMap<String, VapidToken>>>,
}
struct VapidToken {
authorization: HeaderValue,
issued_at: u64,
}
impl Vapid {
pub fn new(key: VapidKey, contact: Option<String>) -> Self {
Self { key, contact }
Self {
key,
contact,
tokens: Arc::default(),
}
}
pub fn public_key(&self) -> &str {
self.key.public_key()
}
pub fn authorization(&self, endpoint: &str, now: u64) -> Option<String> {
self.key
.authorization(endpoint, self.contact.as_deref(), now)
pub fn authorization(&self, endpoint: &str, now: u64) -> Option<HeaderValue> {
let prefix = endpoint_prefix(endpoint)?;
if let Some(token) = self
.tokens
.lock()
.get(prefix)
.filter(|token| token.is_fresh(now))
{
return Some(token.authorization.clone());
}
let authorization = HeaderValue::try_from(self.key.authorization(
endpoint,
self.contact.as_deref(),
now,
)?)
.ok()?;
let mut tokens = self.tokens.lock();
tokens.retain(|_, token| token.is_fresh(now));
tokens.insert(
prefix.to_string(),
VapidToken {
authorization: authorization.clone(),
issued_at: now,
},
);
Some(authorization)
}
}
impl VapidToken {
fn is_fresh(&self, now: u64) -> bool {
now.checked_sub(self.issued_at)
.is_some_and(|age| age < VAPID_TOKEN_REFRESH)
}
}
@@ -105,41 +151,15 @@ impl VapidKey {
}
}
fn endpoint_origin(url: &str) -> Option<String> {
fn endpoint_prefix(url: &str) -> Option<&str> {
let (scheme, rest) = url.split_once("://")?;
let scheme = scheme.to_ascii_lowercase();
let authority = rest.split(['/', '?', '#']).next()?;
let authority = authority
.rsplit_once('@')
.map(|(_, host)| host)
.unwrap_or(authority);
if authority.is_empty() {
return None;
}
url.get(..scheme.len() + "://".len() + authority.len())
}
let (host, port) = if let Some(rest) = authority.strip_prefix('[') {
let (addr, tail) = rest.split_once(']')?;
(
format!("[{}]", addr.to_ascii_lowercase()),
tail.strip_prefix(':').filter(|port| !port.is_empty()),
)
} else if let Some((host, port)) = authority.rsplit_once(':') {
(
host.to_ascii_lowercase(),
Some(port).filter(|p| !p.is_empty()),
)
} else {
(authority.to_ascii_lowercase(), None)
};
match port {
Some(port)
if !((scheme == "https" && port == "443") || (scheme == "http" && port == "80")) =>
{
Some(format!("{scheme}://{host}:{port}"))
}
_ => Some(format!("{scheme}://{host}")),
}
fn endpoint_origin(url: &str) -> Option<String> {
let origin = Url::parse(url).ok()?.origin();
origin.is_tuple().then(|| origin.ascii_serialization())
}
pub fn normalize_contact(contact: &str) -> Option<String> {
@@ -206,7 +226,12 @@ mod tests {
endpoint_origin("http://[2001:DB8::1]:80/p").unwrap(),
"http://[2001:db8::1]"
);
assert_eq!(
endpoint_origin("https://attacker.example\\@fcm.googleapis.com/fcm/send/x").unwrap(),
"https://attacker.example"
);
assert!(endpoint_origin("not-a-url").is_none());
assert!(endpoint_origin("mailto:[email protected]").is_none());
}
#[test]
@@ -336,6 +361,47 @@ B4yDfR2rGOd2H6Kv3fQNHPj9Nu5Tks8QYMLzrX8ONCNoFnNUQl9S0r0QS6phVqD0
}
}
#[test]
fn authorization_is_reused_per_endpoint_prefix() {
let vapid = Vapid::new(test_key(), None);
let now = 1_700_000_000;
let token = vapid
.authorization("https://push.example.com/push/a", now)
.unwrap();
assert_eq!(
vapid
.authorization("https://push.example.com/push/b?x=1", now + 60)
.unwrap(),
token
);
assert_ne!(
vapid
.authorization("https://other.example.com/push/a", now)
.unwrap(),
token
);
assert_ne!(
vapid
.authorization("https://push.example.com/push/a", now - 1)
.unwrap(),
token
);
let refreshed = vapid
.authorization("https://push.example.com/push/a", now + VAPID_TOKEN_REFRESH)
.unwrap();
assert_ne!(refreshed, token);
assert_eq!(
vapid
.authorization(
"https://push.example.com/push/c",
now + VAPID_TOKEN_REFRESH + 1
)
.unwrap(),
refreshed
);
}
#[test]
fn authorization_omits_subject_when_no_contact() {
let key = test_key();
+434
View File
@@ -0,0 +1,434 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! The live facts the personal-data catalog is evaluated against
//! (personal-data catalog spec, §6): which sources are switched on, what
//! bounds each one's retention, which stores and endpoints are elsewhere.
//! Read from the registry on each request, so every node answers alike.
use crate::Server;
use inbuxa_features::privacy::{
self, Days, Inventory, LiveFacts, is_loopback,
snapshot::{self, Snapshot, Trigger},
};
use registry::schema::{
prelude::Object,
structs::{
AiModel, BlobStore, DataRetention, DataStore, InMemoryStore, Jmap, MtaHook, MtaMilter,
MtaRoute, Search, SearchStore, SpamClassifier, SpamClassifierModel, SpamDnsblServer,
SpamLlm, SpamPyzor, Tracer, TracingStore, WebHook,
},
};
use registry::types::duration::Duration;
use serde_json::Value;
use types::id::Id;
/// The objects [`Server::privacy_facts`] reads: a write to one may change
/// the inventory.
pub const INVENTORY_OBJECTS: &[&str] = &[
"x:DataRetention",
"x:SpamClassifier",
"x:Jmap",
"x:TracingStore",
"x:Search",
"x:Tracer",
"x:WebHook",
"x:AiModel",
"x:SpamLlm",
"x:SpamDnsblServer",
"x:SpamPyzor",
"x:MtaMilter",
"x:MtaHook",
"x:MtaRoute",
"x:DataStore",
"x:BlobStore",
"x:SearchStore",
"x:InMemoryStore",
"inbuxa:AuditSettings",
"inbuxa:LogSettings",
"inbuxa:AiLimits",
];
/// A store or endpoint object's type and host, from its JSON: local types
/// stay on the host.
fn remote_host(value: &Value) -> Option<String> {
let kind = value.get("@type").and_then(Value::as_str).unwrap_or_default();
if matches!(kind, "" | "RocksDb" | "Sqlite" | "FileSystem" | "Default" | "Disabled") {
return None;
}
for key in ["host", "url", "endpoint", "address", "hostname"] {
if let Some(host) = value.get(key).and_then(Value::as_str).filter(|h| !h.is_empty()) {
return Some(host.to_string());
}
}
// A list of URLs, as an array or as a map keyed by URL
match value.get("urls") {
Some(Value::Array(urls)) => {
if let Some(url) = urls.first().and_then(Value::as_str) {
return Some(url.to_string());
}
}
Some(Value::Object(urls)) => {
if let Some(url) = urls.keys().next() {
return Some(url.clone());
}
}
_ => {}
}
Some(kind.to_string())
}
fn days(duration: Option<&Duration>) -> Days {
match duration {
Some(d) => Days::Days(d.into_inner().as_secs().div_ceil(86_400)),
None => Days::Unbounded,
}
}
/// The zones a DNSBL's zone expression can query: each quoted literal that
/// starts with a dot, in any branch (`ip_reverse + '.zen.spamhaus.org'`).
fn zone_hosts(value: &Value) -> Vec<String> {
let mut hosts = Vec::new();
let mut texts = Vec::new();
fn collect<'a>(value: &'a Value, texts: &mut Vec<&'a str>) {
match value {
Value::String(s) => texts.push(s),
Value::Array(items) => items.iter().for_each(|v| collect(v, texts)),
Value::Object(map) => map.values().for_each(|v| collect(v, texts)),
_ => {}
}
}
collect(value, &mut texts);
for text in texts {
for literal in text.split('\'').skip(1).step_by(2) {
if let Some(zone) = literal.strip_prefix('.')
&& zone.contains('.')
&& !hosts.iter().any(|h| h == zone)
{
hosts.push(zone.to_string());
}
}
}
hosts
}
impl Server {
async fn singleton<T: registry::types::ObjectImpl + From<Object> + Default>(&self) -> trc::Result<T> {
Ok(self.registry().object::<T>(Id::singleton()).await?.unwrap_or_default())
}
/// The facts the catalog is evaluated against, from the live settings.
pub async fn privacy_facts(&self) -> trc::Result<LiveFacts> {
let mut facts = LiveFacts::default();
let data = &self.core.storage.data;
let endpoint = |facts: &mut LiveFacts, id: &str, url: String| {
if !url.is_empty() && !is_loopback(&url) {
facts.endpoints.entry(id.to_string()).or_default().push(url);
}
};
// Retention
let retention = self.singleton::<DataRetention>().await?;
for (name, value) in [
("x:DataRetention.holdTracesFor", &retention.hold_traces_for),
("x:DataRetention.holdMetricsFor", &retention.hold_metrics_for),
("x:DataRetention.holdMtaReportsFor", &retention.hold_mta_reports_for),
("x:DataRetention.archiveDeletedItemsFor", &retention.archive_deleted_items_for),
("x:DataRetention.archiveDeletedAccountsFor", &retention.archive_deleted_accounts_for),
("x:DataRetention.expungeTrashAfter", &retention.expunge_trash_after),
("x:DataRetention.expungeSubmissionsAfter", &retention.expunge_submissions_after),
] {
facts.durations.insert(name.into(), days(value.as_ref()));
}
let classifier = self.singleton::<SpamClassifier>().await?;
facts.durations.insert(
"x:SpamClassifier.holdSamplesFor".into(),
days(Some(&classifier.hold_samples_for)),
);
let jmap = self.singleton::<Jmap>().await?;
facts
.durations
.insert("x:Jmap.uploadTtl".into(), days(Some(&jmap.upload_ttl)));
let audit = inbuxa_features::audit::log::settings(data).await?;
facts.durations.insert(
"inbuxa:AuditSettings.keepForDays".into(),
Days::Days(audit.keep_for_secs.div_ceil(86_400)),
);
let logs = inbuxa_features::security::log_files::get(data).await?;
facts.durations.insert(
"inbuxa:LogSettings.keepForDays".into(),
logs.keep_for_days.map_or(Days::Unbounded, Days::Days),
);
// What's switched on
let tracing = self.singleton::<TracingStore>().await?;
let tracing_on = !matches!(tracing, TracingStore::Disabled);
let search = self.singleton::<Search>().await?;
for id in ["x:Trace", "x:TraceEvent", "x:TraceKeyValue", "x:TraceValueIpAddr", "x:TraceValueString"] {
facts.collected.insert(id.into(), tracing_on);
}
facts
.collected
.insert("trace-index".into(), tracing_on && search.index_telemetry);
facts.collected.insert(
"full-text-index".into(),
search.index_email || search.index_calendar || search.index_contacts,
);
let archive_on = retention.archive_deleted_items_for.is_some();
for id in [
"x:ArchivedEmail",
"x:ArchivedFileNode",
"x:ArchivedCalendarEvent",
"x:ArchivedContactCard",
"x:ArchivedSieveScript",
] {
facts.collected.insert(id.into(), archive_on);
}
facts.collected.insert(
"inbuxa:DeletedAccount".into(),
retention.archive_deleted_accounts_for.is_some(),
);
let reports_on = retention.hold_mta_reports_for.is_some();
for id in [
"x:ArfExternalReport",
"x:ArfFeedbackReport",
"x:DmarcExternalReport",
"x:DmarcReport",
"x:DmarcReportRecord",
"x:TlsExternalReport",
"x:TlsReport",
"x:TlsFailureDetails",
] {
facts.collected.insert(id.into(), reports_on);
}
let classifier_on = !matches!(classifier.model, SpamClassifierModel::Disabled);
facts
.collected
.insert("x:SpamTrainingSample".into(), classifier_on);
facts
.collected
.insert("spam-trainer-state".into(), classifier_on);
// Tracers
let (mut log_on, mut console_on, mut otel_on) = (false, false, false);
for tracer in self.registry().list::<Tracer>().await? {
match tracer.object {
Tracer::Log(t) => log_on |= t.enable,
Tracer::Stdout(t) => console_on |= t.enable,
Tracer::Journal(t) => console_on |= t.enable,
Tracer::OtelHttp(t) if t.enable => {
otel_on = true;
endpoint(&mut facts, "otel-tracer", t.endpoint);
}
Tracer::OtelGrpc(t) if t.enable => {
otel_on = true;
endpoint(&mut facts, "otel-tracer", t.endpoint.unwrap_or_default());
}
_ => {}
}
}
facts.collected.insert("log-file".into(), log_on);
facts.collected.insert("x:Log".into(), log_on);
facts.collected.insert("console-and-journal".into(), console_on);
facts.collected.insert("otel-tracer".into(), otel_on);
// Webhooks
let mut hooks_on = false;
for hook in self.registry().list::<WebHook>().await? {
if hook.object.enable {
hooks_on = true;
endpoint(&mut facts, "webhooks", hook.object.url);
}
}
facts.collected.insert("webhooks".into(), hooks_on);
// AI: the classifier's model, and Explain's
let models = self.registry().list::<AiModel>().await?;
let model_url = |id: Id| {
models
.iter()
.find(|m| Id::from(m.id.id()) == id)
.map(|m| m.object.url.clone())
};
let llm_on = match self.singleton::<SpamLlm>().await? {
SpamLlm::Enable(props) => {
if let Some(url) = model_url(props.model_id) {
endpoint(&mut facts, "spam-llm", url);
}
true
}
SpamLlm::Disable => false,
};
facts.collected.insert("spam-llm".into(), llm_on);
let limits = self.ai_limits().await;
let explain = self.ai_explain_model(&limits).await;
if let Some((_, model)) = &explain {
endpoint(&mut facts, "inbuxa:Explanation", model.url.clone());
}
facts
.collected
.insert("explain-cache".into(), explain.is_some());
facts
.collected
.insert("inbuxa:Explanation".into(), explain.is_some());
// Spam lookups off the host
let mut dnsbl_on = false;
for server in self.registry().list::<SpamDnsblServer>().await? {
let value = serde_json::to_value(&server.object).unwrap_or_default();
if value.get("enable").and_then(Value::as_bool).unwrap_or(false) {
dnsbl_on = true;
for zone in value.get("zone").map(zone_hosts).unwrap_or_default() {
endpoint(&mut facts, "spam-dnsbl", zone);
}
}
}
facts.collected.insert("spam-dnsbl".into(), dnsbl_on);
let pyzor = self.singleton::<SpamPyzor>().await?;
if pyzor.enable {
endpoint(&mut facts, "spam-pyzor", format!("{}:{}", pyzor.host, pyzor.port));
}
facts.collected.insert("spam-pyzor".into(), pyzor.enable);
// Mail handed to others
let mut hooks = false;
for milter in self.registry().list::<MtaMilter>().await? {
hooks = true;
endpoint(
&mut facts,
"mta-milter-and-hooks",
format!("{}:{}", milter.object.hostname, milter.object.port),
);
}
for hook in self.registry().list::<MtaHook>().await? {
hooks = true;
endpoint(&mut facts, "mta-milter-and-hooks", hook.object.url);
}
facts.collected.insert("mta-milter-and-hooks".into(), hooks);
let mut relays = false;
for route in self.registry().list::<MtaRoute>().await? {
if let MtaRoute::Relay(relay) = route.object {
relays = true;
endpoint(&mut facts, "relay", format!("{}:{}", relay.address, relay.port));
}
}
facts.collected.insert("relay".into(), relays);
// Stores elsewhere
let stores = [
("data-store", serde_json::to_value(self.singleton::<DataStore>().await.ok()).unwrap_or_default()),
("blob-store", serde_json::to_value(self.singleton::<BlobStore>().await?).unwrap_or_default()),
("search-store", serde_json::to_value(self.singleton::<SearchStore>().await?).unwrap_or_default()),
("in-memory-store", serde_json::to_value(self.singleton::<InMemoryStore>().await?).unwrap_or_default()),
];
for (place, value) in stores {
if let Some(host) = remote_host(&value) {
facts.remote_stores.insert(place.into(), host);
}
}
if let Some(host) = remote_host(&serde_json::to_value(&tracing).unwrap_or_default()) {
for id in ["x:Trace", "x:TraceEvent", "x:TraceKeyValue", "x:TraceValueIpAddr", "x:TraceValueString"] {
endpoint(&mut facts, id, host.clone());
}
}
Ok(facts)
}
/// The server's inventory, or a tenant's slice of it.
pub async fn data_inventory(&self, tenant_only: bool) -> trc::Result<Inventory> {
let facts = self.privacy_facts().await?;
Ok(privacy::evaluate(privacy::catalog(), &facts, tenant_only))
}
/// Records a snapshot of the server's inventory if it differs from the
/// newest one, or if there is none: the history shows when what the
/// server holds changed, not a copy a day. Returns whether it recorded.
pub async fn inventory_snapshot(&self, trigger: Trigger) -> trc::Result<bool> {
let data = &self.core.storage.data;
let inventory = self.data_inventory(false).await?;
if let Some(latest) = snapshot::latest(data).await?
&& let Some(previous) = snapshot::get(data, latest).await?
&& previous.inventory == inventory
{
return Ok(false);
}
snapshot::record(
data,
&Snapshot {
taken_at: store::write::now(),
trigger,
summary: inventory.summary(),
inventory,
},
)
.await?;
Ok(true)
}
/// A snapshot after a registry write, when the object is one the
/// inventory reads. Failures are logged: a snapshot is history, not
/// worth failing the write over.
pub async fn inventory_snapshot_after(&self, object: &str) {
if !INVENTORY_OBJECTS.contains(&object) {
return;
}
if let Err(err) = self
.inventory_snapshot(Trigger::SettingChanged {
setting: object.to_string(),
})
.await
{
trc::error!(err.details("Failed to record an inventory snapshot"));
}
}
/// Removes snapshots past the audit log's retention (settled
/// 2026-09-28: snapshots are kept as long as audit records).
pub async fn purge_inventory_snapshots(&self) -> trc::Result<usize> {
let data = &self.core.storage.data;
let keep = inbuxa_features::audit::log::settings(data).await?.keep_for_secs;
snapshot::purge(data, store::write::now().saturating_sub(keep)).await
}
}
#[cfg(test)]
mod tests {
use super::*;
use serde_json::json;
#[test]
fn local_stores_stay_and_others_name_their_host() {
assert_eq!(remote_host(&json!({"@type": "RocksDb", "path": "/var/lib"})), None);
assert_eq!(remote_host(&json!({"@type": "Default"})), None);
assert_eq!(
remote_host(&json!({"@type": "PostgreSql", "host": "db.example.net"})),
Some("db.example.net".into())
);
assert_eq!(
remote_host(&json!({"@type": "ElasticSearch", "url": "https://es.example.net:9200"})),
Some("https://es.example.net:9200".into())
);
assert_eq!(remote_host(&json!({"@type": "S3", "bucket": "mail"})), Some("S3".into()));
}
#[test]
fn zones_come_from_every_branch() {
let zone = json!({"else": "false", "match": {"0": {"if": "location == 'tcp'",
"then": "ip_reverse + '.rep.mailspike.net'"}}});
assert_eq!(zone_hosts(&zone), vec!["rep.mailspike.net"]);
let zone = json!({"else": "hash(email, 'sha1') + '.ebl.msbl.org'", "match": {}});
assert_eq!(zone_hosts(&zone), vec!["ebl.msbl.org"], "not 'sha1'");
assert!(zone_hosts(&json!({"else": "false"})).is_empty());
}
#[test]
fn days_round_up() {
assert_eq!(days(Some(&Duration::from_millis(86_400_000))), Days::Days(1));
assert_eq!(days(Some(&Duration::from_millis(3_600_000))), Days::Days(1));
assert_eq!(days(None), Days::Unbounded);
}
}
+293
View File
@@ -0,0 +1,293 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Whether the outside world can reach each node's ports (settings-reorg,
//! Ports: the reachability check).
//!
//! A server can't answer this about itself: a connection to its own public
//! address never leaves the machine, so it passes whatever the firewall in
//! front says. In a cluster the other nodes are outside that machine. Every
//! ten minutes each node resolves every other active node's hostname, as a
//! sender would, and tries a TCP connection to each listener port on each
//! address. What it saw goes in the shared in-memory store for an hour, under
//! (target, prober), so whichever node the admin asks can report it all.
//!
//! A single server has no one outside to ask. It reports only whether each
//! port is listening, and says so.
//!
//! A connection is all that's tried: nothing is sent, so no protocol logs a
//! session and no rate limit counts it.
use crate::{KV_PORT_REACHABILITY, Server};
use registry::schema::{enums::ClusterNodeStatus, structs::NetworkListener};
use serde::{Deserialize, Serialize};
use serde_json::{Value, json};
use std::{
collections::BTreeSet,
net::{IpAddr, Ipv4Addr, Ipv6Addr, SocketAddr},
time::{Duration, Instant},
};
use store::{dispatch::lookup::KeyValue, write::now};
/// How often each node probes the others.
pub const PROBE_INTERVAL: Duration = Duration::from_secs(600);
/// How long one node's view of another is kept: long enough to span a missed round.
const KEEP_FOR: u64 = 3600;
const CONNECT_TIMEOUT: Duration = Duration::from_secs(5);
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct Probe {
pub port: u16,
pub address: String,
pub ok: bool,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub error: Option<String>,
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct Report {
/// Unix seconds.
pub checked_at: u64,
pub probes: Vec<Probe>,
/// The hostname didn't resolve, so nothing could be tried.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub error: Option<String>,
}
/// The ports a sender or client could reach: every listener's port, leaving
/// out listeners bound only to loopback, which are private by design.
pub fn public_ports<'x>(listeners: impl IntoIterator<Item = &'x NetworkListener>) -> Vec<u16> {
listeners
.into_iter()
.flat_map(|l| l.bind.iter())
.map(|addr| addr.0)
.filter(|addr| !addr.ip().is_loopback())
.map(|addr| addr.port())
.collect::<BTreeSet<_>>()
.into_iter()
.collect()
}
fn key(target: &str, prober: &str) -> Vec<u8> {
format!("{target}\n{prober}").into_bytes()
}
async fn connect(address: SocketAddr) -> Result<(), String> {
match tokio::time::timeout(CONNECT_TIMEOUT, tokio::net::TcpStream::connect(address)).await {
Ok(Ok(_)) => Ok(()),
Ok(Err(err)) => Err(err.to_string()),
Err(_) => Err("no answer within 5 seconds".into()),
}
}
/// Tries each port on each address `hostname` resolves to.
pub async fn probe_host(hostname: &str, ports: &[u16]) -> Report {
let checked_at = now();
let addresses = match tokio::net::lookup_host((hostname, 0)).await {
Ok(found) => found.map(|a| a.ip()).collect::<BTreeSet<_>>(),
Err(err) => {
return Report {
checked_at,
probes: vec![],
error: Some(format!("{hostname} doesn't resolve: {err}")),
};
}
};
let tries = addresses.iter().flat_map(|ip| {
ports.iter().map(move |port| {
let address = SocketAddr::new(*ip, *port);
async move {
let result = connect(address).await;
Probe {
port: *port,
address: ip.to_string(),
ok: result.is_ok(),
error: result.err(),
}
}
})
});
Report {
checked_at,
probes: futures::future::join_all(tries).await,
error: None,
}
}
async fn listeners(server: &Server) -> trc::Result<Vec<NetworkListener>> {
Ok(server
.registry()
.list::<NetworkListener>()
.await?
.into_iter()
.map(|l| l.object)
.collect())
}
/// Where to knock to see a port listening on this machine: the bound
/// address, or loopback of the same family for a wildcard bind.
pub fn local_targets<'x>(
listeners: impl IntoIterator<Item = &'x NetworkListener>,
) -> Vec<SocketAddr> {
listeners
.into_iter()
.flat_map(|l| l.bind.iter())
.map(|addr| addr.0)
.filter(|addr| !addr.ip().is_loopback())
.map(|addr| match addr.ip() {
IpAddr::V4(ip) if ip.is_unspecified() => {
SocketAddr::new(Ipv4Addr::LOCALHOST.into(), addr.port())
}
IpAddr::V6(ip) if ip.is_unspecified() => {
SocketAddr::new(Ipv6Addr::LOCALHOST.into(), addr.port())
}
_ => addr,
})
.collect::<BTreeSet<_>>()
.into_iter()
.collect()
}
/// One round: this node probes every other active node and records what it saw.
pub async fn probe_peers(server: &Server) -> trc::Result<()> {
let nodes = server.registry().cluster_node_list().await?;
let me = server.registry().node_id() as u64;
let Some(prober) = nodes
.iter()
.find(|n| n.node_id == me)
.map(|n| n.hostname.clone())
else {
return Ok(());
};
let ports = public_ports(&listeners(server).await?);
for target in nodes.iter().filter(|n| {
n.node_id != me && n.status == ClusterNodeStatus::Active && n.hostname != prober
}) {
let report = probe_host(&target.hostname, &ports).await;
server
.in_memory_store()
.key_set(
KeyValue::with_prefix(
KV_PORT_REACHABILITY,
key(&target.hostname, &prober),
serde_json::to_vec(&report).unwrap_or_default(),
)
.expires(KEEP_FOR),
)
.await?;
}
Ok(())
}
/// What `GET /api/ports/check` answers.
pub async fn report(server: &Server) -> trc::Result<Value> {
let listeners = listeners(server).await?;
let ports = public_ports(&listeners);
let nodes = if server.core.storage.coordinator.is_enabled() {
server.registry().cluster_node_list().await?
} else {
vec![]
};
let active = nodes
.iter()
.filter(|n| n.status == ClusterNodeStatus::Active)
.collect::<Vec<_>>();
if active.len() < 2 {
// No one outside to ask: only whether each port is listening here.
let started = Instant::now();
let listening = futures::future::join_all(local_targets(&listeners).into_iter().map(
|address| async move {
let result = connect(address).await;
json!({ "port": address.port(), "address": address.ip().to_string(), "listening": result.is_ok() })
},
))
.await;
return Ok(json!({
"mode": "local",
"ports": ports,
"listening": listening,
"ms": started.elapsed().as_millis() as u64,
}));
}
let mut out = Vec::new();
for target in &active {
let mut seen_by = Vec::new();
for prober in active.iter().filter(|p| p.node_id != target.node_id) {
let stored = server
.in_memory_store()
.key_get::<String>(KeyValue::<()>::build_key(
KV_PORT_REACHABILITY,
key(&target.hostname, &prober.hostname),
))
.await?;
let report = stored.and_then(|raw| serde_json::from_str::<Report>(&raw).ok());
seen_by.push(json!({ "prober": prober.hostname, "report": report }));
}
out.push(json!({ "hostname": target.hostname, "seenBy": seen_by }));
}
Ok(json!({
"mode": "cluster",
"ports": ports,
"intervalSeconds": PROBE_INTERVAL.as_secs(),
"nodes": out,
}))
}
#[cfg(test)]
mod tests {
use super::*;
fn listener(binds: &[&str]) -> NetworkListener {
NetworkListener {
bind: registry::schema::prelude::Map::new(
binds.iter().map(|b| b.parse().unwrap()).collect(),
),
..Default::default()
}
}
#[test]
fn public_ports_leave_out_loopback_only_listeners() {
let listeners = [
listener(&["[::]:25"]),
listener(&["0.0.0.0:993", "[::]:993"]),
listener(&["127.0.0.1:8080"]),
listener(&["203.0.113.5:465"]),
];
assert_eq!(public_ports(listeners.iter()), vec![25, 465, 993]);
assert_eq!(
local_targets(listeners.iter())
.iter()
.map(ToString::to_string)
.collect::<Vec<_>>(),
vec!["127.0.0.1:993", "203.0.113.5:465", "[::1]:25", "[::1]:993"]
);
}
#[tokio::test]
async fn probe_host_reports_open_and_closed_ports() {
let open = tokio::net::TcpListener::bind("127.0.0.1:0").await.unwrap();
let open_port = open.local_addr().unwrap().port();
let closed_port = {
let l = std::net::TcpListener::bind("127.0.0.1:0").unwrap();
l.local_addr().unwrap().port()
};
let report = probe_host("127.0.0.1", &[open_port, closed_port]).await;
assert_eq!(report.error, None);
let ok = |port| report.probes.iter().find(|p| p.port == port).unwrap().ok;
assert!(ok(open_port));
assert!(!ok(closed_port));
}
#[tokio::test]
async fn probe_host_says_when_a_name_does_not_resolve() {
let report = probe_host("does-not-exist.invalid", &[25]).await;
assert!(report.probes.is_empty());
assert!(report.error.unwrap().contains("doesn't resolve"));
}
}
+148 -9
View File
@@ -156,15 +156,7 @@ async fn post_webhook_events(
// Add HMAC-SHA256 signature
let mut headers = settings.headers.clone();
if !settings.key.is_empty() {
let key = hmac::Key::new(hmac::HMAC_SHA256, settings.key.as_bytes());
let tag = hmac::sign(&key, body.as_bytes());
headers.insert(
"X-Signature",
STANDARD.encode(tag.as_ref()).parse().unwrap(),
);
}
sign(&mut headers, &settings.key, &body);
// Send request
let response = settings
@@ -188,3 +180,150 @@ async fn post_webhook_events(
))
}
}
/// Adds the HMAC-SHA256 `X-Signature` a receiver checks, when the webhook has a key.
fn sign(headers: &mut hyper::HeaderMap, key: &str, body: &str) {
if !key.is_empty() {
let key = hmac::Key::new(hmac::HMAC_SHA256, key.as_bytes());
let tag = hmac::sign(&key, body.as_bytes());
headers.insert(
"X-Signature",
STANDARD.encode(tag.as_ref()).parse().unwrap(),
);
}
}
/// inbuxa: "Send test" for a saved webhook (settings-reorg, Webhooks). One
/// sample event, sent the way a real batch is: the same URL, headers, sign-in,
/// signature, timeout and certificate checks. The event's type,
/// `webhook.test`, is none the server raises, and an `X-Inbuxa-Test` header
/// marks it, so a receiver can tell it apart. Answers the HTTP status, or why
/// nothing came back.
pub async fn send_test(hook: &registry::schema::structs::WebHook) -> Result<u16, String> {
let mut headers = hook
.http_auth
.build_headers(hook.http_headers.clone(), "application/json".into())
.await
.map_err(|err| format!("Unable to build HTTP headers: {err}"))?;
let key = hook
.signature_key
.secret()
.await
.map_err(|err| format!("Unable to retrieve signature key: {err}"))?
.unwrap_or_default()
.into_owned();
let created = now();
let body = serde_json::json!({
"events": [{
"id": format!("test-{created}"),
"createdAt": mail_parser::DateTime::from_timestamp(created as i64).to_rfc3339(),
"type": "webhook.test",
"data": { "details": "A test from inbuxa Admin. Nothing happened on the server." },
}]
})
.to_string();
sign(&mut headers, &key, &body);
headers.insert("X-Inbuxa-Test", "true".parse().unwrap());
let response = utils::http::http_client_builder(hook.allow_invalid_certs)
.build()
.map_err(|err| format!("Unable to build an HTTP client: {err}"))?
.post(&hook.url)
.timeout(hook.timeout.into_inner())
.headers(headers)
.body(body)
.send()
.await
.map_err(|err| format!("Webhook request to {} failed: {err}", hook.url))?;
Ok(response.status().as_u16())
}
#[cfg(test)]
mod tests {
use super::*;
use registry::schema::structs::{SecretKeyOptional, SecretKeyValue, WebHook};
use tokio::io::{AsyncReadExt, AsyncWriteExt};
/// One request in, the given status out; hands back what was received.
async fn receiver(status: &'static str) -> (String, tokio::task::JoinHandle<String>) {
let listener = tokio::net::TcpListener::bind("127.0.0.1:0").await.unwrap();
let url = format!("http://{}/hook", listener.local_addr().unwrap());
let task = tokio::spawn(async move {
let (mut socket, _) = listener.accept().await.unwrap();
let mut buf = Vec::new();
let mut chunk = [0u8; 4096];
loop {
let n = socket.read(&mut chunk).await.unwrap();
buf.extend_from_slice(&chunk[..n]);
let text = String::from_utf8_lossy(&buf);
if let Some(end) = text.find("\r\n\r\n") {
let length = text[..end]
.lines()
.find_map(|l| {
l.to_ascii_lowercase()
.strip_prefix("content-length:")
.map(|v| v.trim().parse::<usize>().unwrap())
})
.unwrap_or(0);
if buf.len() >= end + 4 + length || n == 0 {
break;
}
}
}
socket
.write_all(
format!("HTTP/1.1 {status}\r\ncontent-length: 0\r\nconnection: close\r\n\r\n")
.as_bytes(),
)
.await
.unwrap();
String::from_utf8_lossy(&buf).into_owned()
});
(url, task)
}
#[tokio::test]
async fn send_test_signs_and_marks_the_sample() {
let (url, task) = receiver("204 No Content").await;
let hook = WebHook {
url,
enable: false,
signature_key: SecretKeyOptional::Value(SecretKeyValue { secret: "k".into() }),
..Default::default()
};
assert_eq!(send_test(&hook).await, Ok(204));
let request = task.await.unwrap();
let (head, body) = request.split_once("\r\n\r\n").unwrap();
let head = head.to_ascii_lowercase();
assert!(head.contains("x-inbuxa-test: true"), "{head}");
let parsed: serde_json::Value = serde_json::from_str(body).unwrap();
assert_eq!(parsed["events"][0]["type"], "webhook.test");
let tag = hmac::sign(&hmac::Key::new(hmac::HMAC_SHA256, b"k"), body.as_bytes());
assert!(
head.contains(&format!(
"x-signature: {}",
STANDARD.encode(tag.as_ref()).to_ascii_lowercase()
)),
"{head}"
);
}
#[tokio::test]
async fn send_test_reports_what_came_back() {
let (url, _task) = receiver("403 Forbidden").await;
let hook = WebHook {
url,
..Default::default()
};
assert_eq!(send_test(&hook).await, Ok(403));
let hook = WebHook {
url: "http://127.0.0.1:9/hook".into(),
..Default::default()
};
assert!(send_test(&hook).await.unwrap_err().contains("failed"));
}
}
+1 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "coordinator"
version = "0.16.23"
version = "0.16.24"
edition = "2024"
[dependencies]
+1 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "dav-proto"
version = "0.16.23"
version = "0.16.24"
edition = "2024"
[dependencies]
+1 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "dav"
version = "0.16.23"
version = "0.16.24"
edition = "2024"
[dependencies]
+10
View File
@@ -2,6 +2,8 @@
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
*
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
*
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use super::proppatch::FilePropPatchRequestHandler;
@@ -131,6 +133,14 @@ impl FileMkColRequestHandler for Server {
let etag = batch.etag();
self.commit_batch(batch).await.caused_by(trc::location!())?;
// inbuxa: AL-7: a folder a delegate makes in a locked account gets
// the lock's grants
if account_id != access_token.account_id()
&& let Err(err) = groupware::inbuxa_lock::reconcile_dav(self, account_id).await
{
trc::error!(err.details("Failed to grant a lock's delegates on a new folder"));
}
if let Some(prop_stat) = return_prop_stat {
Ok(HttpResponse::new(StatusCode::CREATED)
.with_xml_body(
+10
View File
@@ -2,6 +2,8 @@
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
*
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
*
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use crate::{
@@ -299,6 +301,14 @@ impl FileUpdateRequestHandler for Server {
let etag = batch.etag();
self.commit_batch(batch).await.caused_by(trc::location!())?;
// inbuxa: AL-7: a top-level file a delegate adds to a locked
// account gets the lock's grants
if account_id != access_token.account_id()
&& let Err(err) = groupware::inbuxa_lock::reconcile_dav(self, account_id).await
{
trc::error!(err.details("Failed to grant a lock's delegates on a new file"));
}
Ok(HttpResponse::new(StatusCode::CREATED).with_etag_opt(etag))
}
}
+1 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "directory"
version = "0.16.23"
version = "0.16.24"
edition = "2024"
[dependencies]
+1 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "email"
version = "0.16.23"
version = "0.16.24"
edition = "2024"
[dependencies]
+128
View File
@@ -0,0 +1,128 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! inbuxa: a locked account's grants, whole (audit-hold-lock spec, AL-7,
//! AL-10): its mailboxes here, and its calendars, address books and files
//! through `groupware::inbuxa_lock`.
//!
//! A delegate's access is real ACL grants on the locked account's
//! containers, the sharing IMAP, DAV and JMAP already honor, so a delegate
//! sees the account as a shared one everywhere. The lock notes what each
//! delegate had on a container before, so ending a delegation or the lock
//! puts it back. Idempotent: run again, it grants on containers made since
//! and changes nothing else.
use crate::{cache::MessageCacheFetch, mailbox::Mailbox};
use common::{Server, storage::index::ObjectIndexBuilder};
use groupware::inbuxa_lock::{apply_dav_grants, invalidate, same_replaced};
use inbuxa_features::lock::{self, Lock, Replaced};
use store::{
ValueKey,
write::{AlignedBytes, Archive, BatchBuilder, now},
};
use trc::AddContext;
use types::{collection::Collection, special_use::SpecialUse};
/// Grants a lock's delegates their rights on every container of the locked
/// account, and takes away those of delegations that ended. Returns what the
/// lock now has to remember.
pub async fn apply_grants(
server: &Server,
account_id: u32,
old: Option<&Lock>,
new: Option<&Lock>,
) -> trc::Result<Vec<Replaced>> {
let now = now();
let mut replaced = Vec::new();
let mut batch = BatchBuilder::new();
let cache = server
.get_cached_messages(account_id)
.await
.caused_by(trc::location!())?;
for mailbox in cache.mailboxes.items.iter() {
// Mail in Trash and Junk is destroyed in time: an organizing
// delegate may look, not move mail in
let is_trash = matches!(mailbox.role, SpecialUse::Trash | SpecialUse::Junk);
let current = mailbox.acls.to_vec();
let Some(acls) = lock::merge_grants(
&current,
Collection::Mailbox,
mailbox.document_id,
is_trash,
old,
new,
now,
&mut replaced,
) else {
continue;
};
let Some(archive) = server
.store()
.get_value::<Archive<AlignedBytes>>(ValueKey::archive(
account_id,
Collection::Mailbox,
mailbox.document_id,
))
.await
.caused_by(trc::location!())?
else {
continue;
};
let current = archive
.into_deserialized::<Mailbox>()
.caused_by(trc::location!())?;
let mut changed = current.inner.clone();
changed.acls = acls;
batch
.with_account_id(account_id)
.with_collection(Collection::Mailbox)
.with_document(mailbox.document_id)
.custom(
ObjectIndexBuilder::new()
.with_changes(changed)
.with_current(current),
)
.caused_by(trc::location!())?;
}
apply_dav_grants(server, account_id, old, new, now, &mut replaced, &mut batch).await?;
if !batch.is_empty() {
server
.commit_batch(batch)
.await
.caused_by(trc::location!())?;
}
Ok(replaced)
}
/// Re-applies the lock on `account_id`, if any, so containers made since get
/// its grants: after a delegate creates something there, and daily.
pub async fn reconcile(server: &Server, account_id: u32) -> trc::Result<()> {
let data = server.store();
let Some(current) = lock::get(data, account_id).await? else {
return Ok(());
};
let replaced = apply_grants(server, account_id, Some(&current), Some(&current)).await?;
if !same_replaced(&replaced, &current.replaced) {
let updated = Lock {
replaced,
..current.clone()
};
lock::set(data, &updated, Some(&current)).await?;
}
invalidate(server, account_id, Some(&current), Some(&current)).await
}
/// Re-applies every lock: the daily sweep, for containers made by the server
/// itself (a Sieve `fileinto :create`) rather than by a delegate.
pub async fn reconcile_all(server: &Server) -> trc::Result<()> {
for current in lock::all(server.store()).await? {
reconcile(server, current.account_id).await?;
}
Ok(())
}
+1
View File
@@ -14,6 +14,7 @@
pub mod cache;
pub mod identity;
pub mod inbuxa_lock; // inbuxa: account lock grants
pub mod mailbox;
pub mod message;
pub mod push;
+4 -6
View File
@@ -92,10 +92,8 @@ impl MailboxDestroy for Server {
let mut deleted_ids = RoaringBitmap::new();
let mut thread_ids = RoaringBitmap::new();
// inbuxa: UD-1, UD-6a: the retention in force now
let retention = inbuxa_features::undelete::settings::retention(self.registry())
.await?
.items;
// inbuxa: UD-1, UD-6a, LH-4: how this account's deletions are kept
let keeping = self.keeping(account_id).await?;
self.archives(
account_id,
Collection::Email,
@@ -125,10 +123,10 @@ impl MailboxDestroy for Server {
deleted_ids.insert(message_id);
thread_ids.insert(prev_message_data.inner.thread_id.to_native());
// inbuxa: UD-1, UD-4: a deleted message is noted for archiving
if let Some(retention) = retention {
if keeping.keeps_anything() {
inbuxa_features::undelete::email::note(
&mut batch,
retention,
&keeping,
account_id,
message_id,
prev_message_data.inner.size.to_native() as u64,
+4 -6
View File
@@ -69,10 +69,8 @@ impl EmailDeletion for Server {
batch
.with_account_id(account_id)
.with_collection(Collection::Email);
// inbuxa: UD-1, UD-6a: the retention in force now
let retention = inbuxa_features::undelete::settings::retention(self.registry())
.await?
.items;
// inbuxa: UD-1, UD-6a, LH-4: how this account's deletions are kept
let keeping = self.keeping(account_id).await?;
self.archives(
account_id,
Collection::Email,
@@ -90,10 +88,10 @@ impl EmailDeletion for Server {
}
thread_ids.insert(metadata.inner.thread_id.to_native());
// inbuxa: UD-1, UD-4: a deleted message is noted for archiving
if let Some(retention) = retention {
if keeping.keeps_anything() {
inbuxa_features::undelete::email::note(
batch,
retention,
&keeping,
account_id,
document_id,
metadata.inner.size.to_native() as u64,
+6 -6
View File
@@ -44,12 +44,12 @@ impl SieveScriptDelete for Server {
))
.await?
{
// inbuxa: UD-1: a deleted script is kept, when archiving is on
if let Some(retention) =
inbuxa_features::undelete::settings::retention(self.registry())
.await?
.items
{
// inbuxa: UD-1, LH-4: a deleted script is kept, when archiving
// is on or a hold covers the account (whole: scripts have no date)
let keeping = self.keeping(account_id).await?;
let now = store::write::now();
if let Some(until) = keeping.until(now, keeping.is_held()) {
let retention = until.saturating_sub(now);
let script = obj_
.deserialize::<SieveScript>()
.caused_by(trc::location!())?;
+23
View File
@@ -287,6 +287,18 @@ impl SieveScriptIngest for Server {
do_discard = true;
input = true.into();
}
// inbuxa: AL-4: a locked account answers no sender, so a
// rejection is kept instead; sieve has already cleared
// the implicit keep, so it is filed here
Event::Reject { .. } if access_token.is_locked() => {
if let Some(message) = messages.get_mut(0)
&& !message.file_into.contains(&INBOX_ID)
{
message.file_into.push(INBOX_ID);
}
do_deliver = true;
input = true.into();
}
Event::Reject { reason, .. } => {
reject_reason = reason.into();
do_discard = true;
@@ -388,6 +400,17 @@ impl SieveScriptIngest for Server {
}
input = true.into();
}
// inbuxa: AL-4: a locked account sends nothing on its
// own: no redirect, vacation reply or notification. An
// unsent redirect leaves the message to be kept.
Event::SendMessage { .. } if access_token.is_locked() => {
trc::event!(
Sieve(SieveEvent::ActionReject),
Details = "Account is locked: nothing is sent",
SpanId = session_id
);
input = true.into();
}
Event::SendMessage {
recipient,
message_id,
+9
View File
@@ -15,8 +15,17 @@ utils = { path = "../utils" }
ahash = { version = "0.8.12", features = ["serde"] }
serde = { version = "1.0", features = ["derive"] }
serde_json = "1.0"
toml = "1.1"
xxhash-rust = { version = "0.8.18", features = ["xxh3"] }
base64 = "0.23"
sha2 = "0.11"
flate2 = "1.1"
tokio = { version = "1.53", features = ["sync", "rt"] }
# inbuxa: DLP detectors and attachment text (dlp-and-mail-flow-rules spec)
regex = "1.13.1"
aho-corasick = "1.1"
zip = "8.6"
quick-xml = "0.41"
[dev-dependencies]
tokio = { version = "1.53", features = ["macros", "rt"] }
+17 -1
View File
@@ -9,11 +9,27 @@
//! it holds a secret anywhere inside it.
use serde_json::Value;
use std::collections::HashSet;
use std::{collections::HashSet, io::Read, sync::OnceLock};
/// The registry schema, as the console downloads it.
pub struct Schema(Value);
/// The schema built into the server, read once. Also used by the audit log,
/// to know which properties hold secrets (AU-4).
pub fn embedded() -> Option<&'static Schema> {
static SCHEMA: OnceLock<Option<Schema>> = OnceLock::new();
static SCHEMA_JSON: &[u8] = include_bytes!("../../../../../resources/schema/schema.json.gz");
SCHEMA
.get_or_init(|| {
let mut json = Vec::new();
flate2::read::GzDecoder::new(SCHEMA_JSON)
.read_to_end(&mut json)
.ok()?;
serde_json::from_slice(&json).ok().map(Schema::new)
})
.as_ref()
}
/// What the schema says about one property of one object.
#[derive(Debug, Clone, PartialEq)]
pub struct PropertyInfo {
+215
View File
@@ -0,0 +1,215 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! What changed in an object, as audit changes (AU-4). Objects are compared
//! as their JMAP JSON, one top-level property at a time. A property that is
//! a secret, or holds one anywhere inside it, is recorded as changed and
//! never with its value: the registry schema says which those are, and a few
//! names are treated as secret whatever it says.
use crate::{ai::explain::schema, audit::record::Change};
use serde_json::{Map, Value};
use std::str::FromStr;
use types::id::Id;
/// Properties never recorded with a value, even if the schema lacks them.
const ALWAYS_SECRET: &[&str] = &[
"secret",
"password",
"credentials",
"apiKey",
"token",
"privateKey",
"otpAuth",
];
/// Whether `property` of `object` (`x:AiModel`, `apiKey`) holds a secret.
pub fn is_secret(object: &str, property: &str) -> bool {
let lower = property.to_ascii_lowercase();
ALWAYS_SECRET
.iter()
.any(|name| lower == name.to_ascii_lowercase())
|| lower.ends_with("secret")
|| lower.ends_with("password")
|| schema::embedded()
.and_then(|schema| schema.property(object, property))
.is_some_and(|info| info.secret)
}
/// The changes between two versions of an object; `None` for a side that
/// doesn't exist (a create or a destroy).
pub fn diff(object: &str, before: Option<&Value>, after: Option<&Value>) -> Vec<Change> {
let empty = Map::new();
let before = before.and_then(Value::as_object).unwrap_or(&empty);
let after = after.and_then(Value::as_object).unwrap_or(&empty);
let mut fields = before.keys().chain(after.keys()).collect::<Vec<_>>();
fields.sort();
fields.dedup();
let mut changes = Vec::new();
for field in fields {
if field == "id" {
continue;
}
let old = before.get(field).filter(|v| !v.is_null());
let new = after.get(field).filter(|v| !v.is_null());
if old == new {
continue;
}
changes.push(if is_secret(object, field) {
Change::redacted(field.as_str())
} else {
Change::new(field.as_str(), old.cloned(), new.cloned())
});
}
changes
}
/// The changes a JMAP patch asks for, with what each place held before when
/// the old object is known. Patch keys are properties or JSON pointers
/// (`sections/0/enabled`); the property is the pointer's first part.
pub fn patch(object: &str, before: Option<&Value>, patch: &Map<String, Value>) -> Vec<Change> {
let mut changes = Vec::new();
for (pointer, value) in patch {
let property = pointer.split('/').next().unwrap_or(pointer);
if property == "id" {
continue;
}
if is_secret(object, property) {
changes.push(Change::redacted(pointer.as_str()));
continue;
}
let old = before
.and_then(|before| before.pointer(&format!("/{pointer}")))
.filter(|v| !v.is_null())
.cloned();
let new = Some(value.clone()).filter(|v| !v.is_null());
if old == new {
continue;
}
changes.push(Change::new(pointer.as_str(), old, new));
}
changes
}
/// What an object is called, and whose it is, for an audit target.
#[derive(Debug, Default, PartialEq, Eq)]
pub struct Described {
pub name: Option<String>,
pub account_id: Option<u32>,
pub tenant_id: Option<u32>,
}
/// Reads a target's name and owners from its JSON.
pub fn describe(value: &Value) -> Described {
let name = [
"name",
"email",
"address",
"hostname",
"domain",
"description",
]
.iter()
.find_map(|key| value.get(key)?.as_str())
.map(|name| name.chars().take(200).collect());
let id = |key: &str| {
value
.get(key)?
.as_str()
.and_then(|id| Id::from_str(id).ok())
.map(|id| id.document_id())
};
Described {
name,
account_id: id("accountId"),
tenant_id: id("memberTenantId"),
}
}
#[cfg(test)]
mod tests {
use super::*;
use serde_json::json;
#[test]
fn diffs_by_property() {
let before = json!({"id": "a", "name": "x", "enabled": true, "gone": 1});
let after = json!({"id": "b", "name": "y", "enabled": true, "added": [1]});
let changes = diff("x:Thing", Some(&before), Some(&after));
assert_eq!(
changes,
vec![
Change::new("added", None, Some(json!([1]))),
Change::new("gone", Some(json!(1)), None),
Change::new("name", Some(json!("x")), Some(json!("y"))),
]
);
// A create lists everything that is set
assert_eq!(diff("x:Thing", None, Some(&after)).len(), 3);
}
#[test]
fn secrets_are_never_kept() {
let before = json!({"apiKey": "old-key", "userPassword": "a", "name": "m"});
let after = json!({"apiKey": "new-key", "userPassword": "b", "name": "m"});
let changes = diff("x:AiModel", Some(&before), Some(&after));
assert_eq!(
changes,
vec![Change::redacted("apiKey"), Change::redacted("userPassword")]
);
let text = serde_json::to_string(&changes).unwrap();
assert!(!text.contains("new-key"));
assert!(!text.contains("old-key"));
// Unchanged secrets aren't mentioned at all
assert!(diff("x:AiModel", Some(&before), Some(&before)).is_empty());
}
#[test]
fn secrets_the_schema_knows() {
// x:AiModel's httpAuth holds a secret inside one of its variants
if schema::embedded().is_some() {
assert!(is_secret("x:AiModel", "httpAuth"));
assert!(!is_secret("x:AiModel", "name"));
}
}
#[test]
fn patches_with_their_old_values() {
let before = json!({"name": "a", "list": [{"on": false}], "secret": "s"});
let patch_value = json!({"name": "b", "list/0/on": true, "secret": "t", "new": 3});
let changes = patch("x:Thing", Some(&before), patch_value.as_object().unwrap());
assert!(changes.contains(&Change::new("name", Some(json!("a")), Some(json!("b")))));
assert!(changes.contains(&Change::new(
"list/0/on",
Some(json!(false)),
Some(json!(true))
)));
assert!(changes.contains(&Change::redacted("secret")));
assert!(changes.contains(&Change::new("new", None, Some(json!(3)))));
// Nothing to nothing isn't a change
let nulls = json!({"description": null});
assert!(patch("x:Thing", None, nulls.as_object().unwrap()).is_empty());
}
#[test]
fn describes_targets() {
let d = describe(&json!({
"name": "example.com",
"memberTenantId": Id::from(5u32).to_string(),
"accountId": Id::from(9u32).to_string(),
}));
assert_eq!(
d,
Described {
name: Some("example.com".into()),
account_id: Some(9),
tenant_id: Some(5)
}
);
assert_eq!(describe(&json!({"n": 1})), Described::default());
}
}
+984
View File
@@ -0,0 +1,984 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! The audit log's storage (AU-2, AU-3, AU-6, AU-7), in the fork's own
//! subspace (`store::SUBSPACE_INBUXA`). Every key starts with `L`, then one
//! byte for the kind:
//!
//! - `e` + node + seq: one entry of that node's chain, as JSON. An entry is
//! an event, or the outcome of an event written before its change was
//! tried. Each holds the SHA-256 of the entry before it on the same node.
//! - `t` + time + node + seq: the time index of events, for queries.
//! - `o` + node + seq: the seq of an event's outcome entry.
//! - `h` + node: the chain's head: that entry's hash, then its seq as the
//! last eight bytes, which each append asserts, so two writers can never
//! both add the same seq.
//! - `f` + node: where the chain starts after purging, and the hash the
//! first kept entry names.
//! - `s`: the settings (`keepFor`).
//!
//! Numbers are big-endian, so keys sort in time and chain order. Each node
//! writes only its own chain, so nodes never contend for a key; nothing about
//! a chain is kept in memory, so a node restarted or rebuilt carries on
//! from what is stored.
use crate::audit::record::{Action, Outcome, Record};
use ahash::AHashMap;
use serde::{Deserialize as SerdeDeserialize, Serialize as SerdeSerialize};
use sha2::{Digest, Sha256};
use std::{fmt, net::IpAddr, str::FromStr};
use store::{
Deserialize, IterateParams, SUBSPACE_INBUXA, Serialize, Store, ValueKey,
write::{AnyClass, BatchBuilder, ValueClass, assert::AssertValue},
};
use tokio::sync::Mutex;
use trc::AddContext;
const FEATURE: u8 = b'L';
const KIND_ENTRY: u8 = b'e';
const KIND_TIME: u8 = b't';
const KIND_OUTCOME: u8 = b'o';
const KIND_HEAD: u8 = b'h';
const KIND_FLOOR: u8 = b'f';
const KIND_SETTINGS: u8 = b's';
/// How long entries are kept unless set otherwise: two years (AU-7).
pub const DEFAULT_KEEP_FOR_SECS: u64 = 730 * 86_400;
/// The shortest period an administrator may set (AU-7).
pub const MIN_KEEP_FOR_SECS: u64 = 90 * 86_400;
/// Most results one query page returns.
pub const MAX_QUERY_LIMIT: usize = 500;
/// Keys cleared per purge batch.
const PURGE_BATCH: usize = 500;
/// Where one entry sits: its node's chain and its place in it.
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, PartialOrd, Ord)]
pub struct EntryId {
pub node: u64,
pub seq: u64,
}
impl EntryId {
/// As one number, for JMAP ids: the node in the top 16 bits, the seq in
/// the rest. Node ids are 16 bits; a chain reaches 2^48 entries never.
pub fn to_u64(&self) -> u64 {
(self.node << 48) | (self.seq & ((1 << 48) - 1))
}
pub fn from_u64(id: u64) -> Self {
EntryId {
node: id >> 48,
seq: id & ((1 << 48) - 1),
}
}
}
impl fmt::Display for EntryId {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
write!(f, "{}-{}", self.node, self.seq)
}
}
impl FromStr for EntryId {
type Err = ();
fn from_str(s: &str) -> Result<Self, Self::Err> {
let (node, seq) = s.split_once('-').ok_or(())?;
Ok(EntryId {
node: node.parse().map_err(|_| ())?,
seq: seq.parse().map_err(|_| ())?,
})
}
}
/// What is kept for one chain entry. The hash of these exact bytes is what
/// the next entry names as `prev`.
#[derive(Debug, Clone, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
struct Stored {
seq: u64,
prev: String,
#[serde(flatten)]
entry: Entry,
}
#[derive(Debug, Clone, SerdeSerialize, SerdeDeserialize)]
#[serde(tag = "entry", rename_all = "camelCase")]
enum Entry {
Event { record: Record },
Outcome { of: u64, at: u64, outcome: Outcome },
}
impl Entry {
fn at(&self) -> u64 {
match self {
Entry::Event { record } => record.at,
Entry::Outcome { at, .. } => *at,
}
}
}
#[derive(Debug, Clone, Default, PartialEq)]
struct Head {
seq: u64,
hash: String,
}
impl Head {
fn to_bytes(&self) -> Vec<u8> {
let mut bytes = self.hash.as_bytes().to_vec();
bytes.extend_from_slice(&self.seq.to_be_bytes());
bytes
}
}
impl Deserialize for Head {
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
let split = bytes.len().checked_sub(8).ok_or_else(|| {
trc::StoreEvent::DataCorruption
.into_err()
.details("Invalid audit chain head")
})?;
Ok(Head {
seq: u64::from_be_bytes(bytes[split..].try_into().unwrap()),
hash: String::from_utf8_lossy(&bytes[..split]).into_owned(),
})
}
}
async fn head(data: &Store, node: u64) -> trc::Result<Option<Head>> {
data.get_value::<Head>(key(KIND_HEAD, &[node]))
.await
.caused_by(trc::location!())
}
/// Attempts at an append that another writer beat to the same seq.
const APPEND_ATTEMPTS: usize = 5;
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
struct Floor {
seq: u64,
prev: String,
}
/// The audit log's settings (`inbuxa:AuditSettings`).
#[derive(Debug, Clone, PartialEq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub struct Settings {
pub keep_for_secs: u64,
}
impl Default for Settings {
fn default() -> Self {
Settings {
keep_for_secs: DEFAULT_KEEP_FOR_SECS,
}
}
}
/// A value stored as JSON.
struct Json<T>(T);
impl<T: SerdeSerialize> Serialize for Json<T> {
fn serialize(&self) -> trc::Result<Vec<u8>> {
serde_json::to_vec(&self.0).map_err(|err| {
trc::StoreEvent::UnexpectedError
.into_err()
.details("Failed to serialize audit entry")
.reason(err)
})
}
}
impl<T: serde::de::DeserializeOwned + Sync + Send> Deserialize for Json<T> {
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
serde_json::from_slice(bytes).map(Json).map_err(|err| {
trc::StoreEvent::DataCorruption
.into_err()
.details("Invalid audit entry")
.reason(err)
})
}
}
/// Raw bytes, for entries whose hash is checked.
struct Raw(Vec<u8>);
impl Deserialize for Raw {
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
Ok(Raw(bytes.to_vec()))
}
}
struct U64(u64);
impl Deserialize for U64 {
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
bytes
.try_into()
.map(|bytes| U64(u64::from_be_bytes(bytes)))
.map_err(|_| {
trc::StoreEvent::DataCorruption
.into_err()
.details("Invalid audit outcome pointer")
})
}
}
fn class(kind: u8, parts: &[u64]) -> ValueClass {
let mut key = Vec::with_capacity(2 + parts.len() * 8);
key.push(FEATURE);
key.push(kind);
for part in parts {
key.extend_from_slice(&part.to_be_bytes());
}
ValueClass::Any(AnyClass {
subspace: SUBSPACE_INBUXA,
key,
})
}
fn key(kind: u8, parts: &[u64]) -> ValueKey<ValueClass> {
ValueKey::from(class(kind, parts))
}
/// Where an entry is kept, for tests and tools that check tampering is
/// caught.
pub fn entry_key(id: EntryId) -> ValueKey<ValueClass> {
key(KIND_ENTRY, &[id.node, id.seq])
}
/// Where a node's chain head is kept, for the same.
pub fn head_key(node: u64) -> ValueKey<ValueClass> {
key(KIND_HEAD, &[node])
}
/// The numbers after the kind byte, read from the key's tail: the iterator
/// may or may not hand back the subspace byte.
fn parse_key(key: &[u8], kind: u8, parts: usize) -> Option<Vec<u64>> {
let len = 2 + parts * 8;
let tail = key.get(key.len().checked_sub(len)?..)?;
(tail[0] == FEATURE && tail[1] == kind).then_some(())?;
Some(
tail[2..]
.chunks_exact(8)
.map(|chunk| u64::from_be_bytes(chunk.try_into().unwrap()))
.collect(),
)
}
fn hash(bytes: &[u8]) -> String {
Sha256::digest(bytes)
.iter()
.map(|b| format!("{b:02x}"))
.collect()
}
/// Lines up this process's appends, so they rarely race for a head; the
/// store's assert settles any that still do.
static APPENDING: Mutex<()> = Mutex::const_new(());
/// What a node keeps in memory: which accesses it has recorded lately
/// (AU-1.6).
#[derive(Default)]
pub struct AuditLog {
recent_access: std::sync::Mutex<AHashMap<(u32, u32, u8), u64>>,
}
/// A query over events (AU-9), newest first.
#[derive(Debug, Clone, Default)]
pub struct Filter {
/// From this time on, in ms.
pub after: Option<u64>,
/// Before this time, in ms.
pub before: Option<u64>,
pub actor_id: Option<u32>,
pub action: Option<Action>,
pub target_kind: Option<String>,
pub target_id: Option<String>,
pub account_id: Option<u32>,
/// Records whose actor or target is in this tenant.
pub tenant_id: Option<u32>,
pub outcome: Option<String>,
pub remote_ip: Option<IpAddr>,
/// Words that must all appear in the actor's or target's name, the
/// target kind, or the details, ignoring case.
pub text: Option<String>,
}
impl Filter {
pub fn matches(&self, record: &Record) -> bool {
self.after.is_none_or(|after| record.at >= after)
&& self.before.is_none_or(|before| record.at < before)
&& self
.actor_id
.is_none_or(|actor| record.actor.account_id == Some(actor))
&& self.action.is_none_or(|action| record.action == action)
&& self
.target_kind
.as_ref()
.is_none_or(|kind| record.target.kind.eq_ignore_ascii_case(kind))
&& self
.target_id
.as_ref()
.is_none_or(|target| record.target.id.as_ref() == Some(target))
&& self.account_id.is_none_or(|account| {
record.target.account_id == Some(account)
|| record.actor.account_id == Some(account)
|| (record.target.kind == "x:Account"
&& record.target.id.as_deref()
== Some(types::id::Id::from(account).to_string().as_str()))
})
&& self
.tenant_id
.is_none_or(|tenant| in_tenant(record, tenant))
&& self
.outcome
.as_ref()
.is_none_or(|outcome| record.outcome.as_str() == outcome)
&& self.remote_ip.is_none_or(|ip| record.remote_ip == Some(ip))
&& self.text.as_ref().is_none_or(|text| {
let haystack = format!(
"{} {} {} {} {}",
record.actor.name,
record.target.kind,
record.target.name.as_deref().unwrap_or_default(),
record.details.as_deref().unwrap_or_default(),
record.reason.as_deref().unwrap_or_default()
)
.to_lowercase();
text.to_lowercase()
.split_whitespace()
.all(|word| haystack.contains(word))
})
}
}
/// Whether a tenant administrator may see a record: its actor or its
/// target is in the tenant (AU-9).
pub fn in_tenant(record: &Record, tenant_id: u32) -> bool {
record.actor.tenant_id == Some(tenant_id) || record.target.tenant_id == Some(tenant_id)
}
/// One node's chain, as `verify` found it.
#[derive(Debug, Clone, PartialEq, SerdeSerialize)]
#[serde(rename_all = "camelCase")]
pub struct ChainReport {
pub node: u64,
pub entries: u64,
pub first_seq: u64,
pub last_seq: u64,
/// The first entry that doesn't follow from the one before it, or the
/// head that doesn't match the last entry.
#[serde(skip_serializing_if = "Option::is_none")]
pub broken_at: Option<String>,
#[serde(skip_serializing_if = "Option::is_none")]
pub reason: Option<String>,
/// Events written before their change whose outcome never followed.
pub unfinished: u64,
}
impl AuditLog {
pub fn new() -> Self {
Self::default()
}
/// Appends an event to this node's chain. An error means nothing was
/// written, and the caller must not go ahead with the change (AU-3).
pub async fn append(&self, data: &Store, node: u64, record: &Record) -> trc::Result<EntryId> {
self.append_entry(
data,
node,
Entry::Event {
record: record.clone(),
},
)
.await
}
/// Appends the outcome of an event written as pending.
pub async fn finish(
&self,
data: &Store,
node: u64,
of: EntryId,
at: u64,
outcome: Outcome,
) -> trc::Result<EntryId> {
self.append_entry(
data,
node,
Entry::Outcome {
of: of.seq,
at,
outcome,
},
)
.await
}
async fn append_entry(&self, data: &Store, node: u64, entry: Entry) -> trc::Result<EntryId> {
let _appending = APPENDING.lock().await;
let at = entry.at();
let event_of = match &entry {
Entry::Outcome { of, .. } => Some(*of),
Entry::Event { .. } => None,
};
let mut stored = Stored {
seq: 0,
prev: String::new(),
entry,
};
let mut attempt = 0;
loop {
attempt += 1;
let current = head(data, node).await?;
let (seq, prev) = current
.as_ref()
.map_or((1, String::new()), |head| (head.seq + 1, head.hash.clone()));
stored.seq = seq;
stored.prev = prev;
let bytes = Json(&stored).serialize()?;
let new_head = Head {
seq,
hash: hash(&bytes),
};
let mut batch = BatchBuilder::new();
batch.assert_value(
class(KIND_HEAD, &[node]),
current.map_or(AssertValue::None, |head| AssertValue::U64(head.seq)),
);
batch.set(class(KIND_ENTRY, &[node, seq]), bytes);
match event_of {
None => {
batch.set(class(KIND_TIME, &[at, node, seq]), vec![]);
}
Some(of) => {
batch.set(class(KIND_OUTCOME, &[node, of]), seq.to_be_bytes().to_vec());
}
}
batch.set(class(KIND_HEAD, &[node]), new_head.to_bytes());
match data.write(batch.build_all()).await {
Ok(_) => return Ok(EntryId { node, seq }),
Err(err)
if attempt < APPEND_ATTEMPTS
&& matches!(
err.as_ref(),
trc::EventType::Store(trc::StoreEvent::AssertValueFailed)
) =>
{
continue;
}
Err(err) => return Err(err.caused_by(trc::location!())),
}
}
}
/// Whether an access of `target` by `actor` (kind 0: account, 1: blob)
/// is the first this hour on this node, and so should be recorded
/// (AU-1.6). Marks it recorded.
pub fn first_access_this_hour(&self, actor: u32, target: u32, kind: u8, now_secs: u64) -> bool {
let hour = now_secs / 3600;
let mut recent = self.recent_access.lock().unwrap_or_else(|e| e.into_inner());
if recent.len() > 10_000 {
recent.retain(|_, seen| *seen == hour);
}
recent.insert((actor, target, kind), hour) != Some(hour)
}
/// Forgets which accesses were recorded, so the next is recorded again
/// (after a write failed).
pub fn forget_access(&self, actor: u32, target: u32, kind: u8) {
self.recent_access
.lock()
.unwrap_or_else(|e| e.into_inner())
.remove(&(actor, target, kind));
}
}
/// One event with its outcome, when that was written separately.
pub async fn get(data: &Store, id: EntryId) -> trc::Result<Option<Record>> {
let Some(Json(stored)) = data
.get_value::<Json<Stored>>(key(KIND_ENTRY, &[id.node, id.seq]))
.await
.caused_by(trc::location!())?
else {
return Ok(None);
};
let Entry::Event { mut record } = stored.entry else {
return Ok(None);
};
if record.outcome == Outcome::Pending
&& let Some(U64(outcome_seq)) = data
.get_value::<U64>(key(KIND_OUTCOME, &[id.node, id.seq]))
.await
.caused_by(trc::location!())?
&& let Some(Json(Stored {
entry: Entry::Outcome { outcome, .. },
..
})) = data
.get_value::<Json<Stored>>(key(KIND_ENTRY, &[id.node, outcome_seq]))
.await
.caused_by(trc::location!())?
{
record.outcome = outcome;
}
Ok(Some(record))
}
/// One event with its outcome, and the hash of its entry and the hash that
/// entry follows: what an export carries so a recipient can match it
/// against a later verification (AU-11).
pub async fn get_with_hash(
data: &Store,
id: EntryId,
) -> trc::Result<Option<(Record, String, String)>> {
let Some(Raw(bytes)) = data
.get_value::<Raw>(key(KIND_ENTRY, &[id.node, id.seq]))
.await
.caused_by(trc::location!())?
else {
return Ok(None);
};
let Json(stored) = Json::<Stored>::deserialize(&bytes)?;
if !matches!(stored.entry, Entry::Event { .. }) {
return Ok(None);
}
let entry_hash = hash(&bytes);
Ok(get(data, id)
.await?
.map(|record| (record, entry_hash, stored.prev)))
}
/// Every event matching `filter`, newest first, up to `max`: for exports.
pub async fn query_all(data: &Store, filter: &Filter, max: usize) -> trc::Result<Vec<EntryId>> {
query_inner(data, filter, 0, max, false)
.await
.map(|(ids, _)| ids)
}
/// Events matching `filter`, newest first: the ids from `position`, at most
/// `limit` of them, and how many match in all when `count_all` is set.
pub async fn query(
data: &Store,
filter: &Filter,
position: usize,
limit: usize,
count_all: bool,
) -> trc::Result<(Vec<EntryId>, usize)> {
query_inner(
data,
filter,
position,
limit.min(MAX_QUERY_LIMIT),
count_all,
)
.await
}
async fn query_inner(
data: &Store,
filter: &Filter,
position: usize,
limit: usize,
count_all: bool,
) -> trc::Result<(Vec<EntryId>, usize)> {
let from = filter.after.unwrap_or(0);
let to = filter
.before
.map_or(u64::MAX, |before| before.saturating_sub(1));
if from > to {
return Ok((Vec::new(), 0));
}
// Walk the time index newest first, collecting candidates
let mut candidates = Vec::new();
data.iterate(
IterateParams::new(
key(KIND_TIME, &[from, 0, 0]),
key(KIND_TIME, &[to, u64::MAX, u64::MAX]),
)
.descending()
.no_values(),
|key, _| {
if let Some(parts) = parse_key(key, KIND_TIME, 3) {
candidates.push(EntryId {
node: parts[1],
seq: parts[2],
});
}
Ok(true)
},
)
.await
.caused_by(trc::location!())?;
let mut ids = Vec::with_capacity(limit);
let mut matched = 0;
for id in candidates {
if !count_all && ids.len() >= limit {
break;
}
let Some(record) = get(data, id).await? else {
continue;
};
if filter.matches(&record) {
if matched >= position && ids.len() < limit {
ids.push(id);
}
matched += 1;
}
}
Ok((ids, matched))
}
pub async fn settings(data: &Store) -> trc::Result<Settings> {
Ok(data
.get_value::<Json<Settings>>(key(KIND_SETTINGS, &[]))
.await
.caused_by(trc::location!())?
.map(|Json(settings)| settings)
.unwrap_or_default())
}
pub async fn set_settings(data: &Store, settings: &Settings) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
batch.set(class(KIND_SETTINGS, &[]), Json(settings).serialize()?);
data.write(batch.build_all())
.await
.caused_by(trc::location!())
.map(|_| ())
}
/// The nodes that have a chain.
async fn nodes(data: &Store) -> trc::Result<Vec<u64>> {
let mut nodes = Vec::new();
data.iterate(
IterateParams::new(key(KIND_HEAD, &[0]), key(KIND_HEAD, &[u64::MAX])).no_values(),
|key, _| {
if let Some(parts) = parse_key(key, KIND_HEAD, 1) {
nodes.push(parts[0]);
}
Ok(true)
},
)
.await
.caused_by(trc::location!())?;
Ok(nodes)
}
async fn floor(data: &Store, node: u64) -> trc::Result<Floor> {
Ok(data
.get_value::<Json<Floor>>(key(KIND_FLOOR, &[node]))
.await
.caused_by(trc::location!())?
.map(|Json(floor)| floor)
.unwrap_or(Floor {
seq: 1,
prev: String::new(),
}))
}
/// Removes, from the start of every node's chain, the entries older than
/// `cutoff` (ms), stopping at the first one that is newer or that `keep`
/// holds on to (AU-7, LH-6). The chain stays verifiable: its new start and
/// the hash that start names are recorded. Returns how many were removed.
pub async fn purge(
data: &Store,
cutoff: u64,
keep: impl Fn(&Record) -> bool + Sync + Send,
) -> trc::Result<usize> {
let mut removed = 0;
for node in nodes(data).await? {
let start = floor(data, node).await?;
let mut doomed: Vec<(u64, Stored)> = Vec::new();
let mut new_floor = None;
data.iterate(
IterateParams::new(
key(KIND_ENTRY, &[node, start.seq]),
key(KIND_ENTRY, &[node, u64::MAX]),
)
.ascending(),
|key, value| {
let Some(parts) = parse_key(key, KIND_ENTRY, 2) else {
return Ok(true);
};
let Json(stored) = Json::<Stored>::deserialize(value)?;
let held = matches!(&stored.entry, Entry::Event { record } if keep(record));
if stored.entry.at() >= cutoff || held || doomed.len() >= 100_000 {
new_floor = Some(Floor {
seq: parts[1],
prev: stored.prev,
});
return Ok(false);
}
doomed.push((parts[1], stored));
Ok(true)
},
)
.await
.caused_by(trc::location!())?;
if doomed.is_empty() {
continue;
}
// With nothing newer, the chain continues from its head
let new_floor = match new_floor {
Some(floor) => floor,
None => {
let head = head(data, node).await?.unwrap_or_default();
Floor {
seq: head.seq + 1,
prev: head.hash,
}
}
};
// The floor moves first: a purge cut short leaves entries before it,
// which the next run clears, never a chain that looks broken
let mut batch = BatchBuilder::new();
batch.set(class(KIND_FLOOR, &[node]), Json(&new_floor).serialize()?);
data.write(batch.build_all())
.await
.caused_by(trc::location!())?;
for chunk in doomed.chunks(PURGE_BATCH / 3) {
let mut batch = BatchBuilder::new();
for (seq, stored) in chunk {
batch.clear(class(KIND_ENTRY, &[node, *seq]));
match &stored.entry {
Entry::Event { record } => {
batch
.clear(class(KIND_TIME, &[record.at, node, *seq]))
.clear(class(KIND_OUTCOME, &[node, *seq]));
}
Entry::Outcome { .. } => {}
}
}
data.write(batch.build_all())
.await
.caused_by(trc::location!())?;
removed += chunk.len();
}
}
Ok(removed)
}
/// Rechecks every node's chain (AU-6): each entry must name the hash of the
/// one before it, seqs must run without gaps from the chain's start, and the
/// head must match the last entry.
pub async fn verify(data: &Store) -> trc::Result<Vec<ChainReport>> {
let mut reports = Vec::new();
for node in nodes(data).await? {
let start = floor(data, node).await?;
let head = head(data, node).await?.unwrap_or_default();
let mut report = ChainReport {
node,
entries: 0,
first_seq: start.seq,
last_seq: start.seq.saturating_sub(1),
broken_at: None,
reason: None,
unfinished: 0,
};
let mut expected_seq = start.seq;
let mut expected_prev = start.prev.clone();
let mut pending: ahash::AHashSet<u64> = Default::default();
data.iterate(
IterateParams::new(
key(KIND_ENTRY, &[node, start.seq]),
key(KIND_ENTRY, &[node, u64::MAX]),
)
.ascending(),
|key, value| {
let Some(parts) = parse_key(key, KIND_ENTRY, 2) else {
return Ok(true);
};
let seq = parts[1];
let broken = |report: &mut ChainReport, reason: String| {
report.broken_at = Some(EntryId { node, seq }.to_string());
report.reason = Some(reason);
};
let Raw(bytes) = Raw::deserialize(value)?;
let Ok(Json(stored)) = Json::<Stored>::deserialize(&bytes) else {
broken(&mut report, "The entry can't be read.".into());
return Ok(false);
};
if seq != expected_seq || stored.seq != seq {
broken(
&mut report,
format!("Entry {expected_seq} is missing; the next one found is {seq}."),
);
return Ok(false);
}
if stored.prev != expected_prev {
broken(
&mut report,
"The entry doesn't follow from the one before it: one of them was changed."
.into(),
);
return Ok(false);
}
match &stored.entry {
Entry::Event { record } if record.outcome == Outcome::Pending => {
pending.insert(seq);
}
Entry::Outcome { of, .. } => {
pending.remove(of);
}
Entry::Event { .. } => {}
}
expected_prev = hash(&bytes);
expected_seq = seq + 1;
report.entries += 1;
report.last_seq = seq;
Ok(true)
},
)
.await
.caused_by(trc::location!())?;
if report.broken_at.is_none() {
if head.seq != report.last_seq || (report.entries > 0 && head.hash != expected_prev) {
report.broken_at = Some(
EntryId {
node,
seq: report.last_seq,
}
.to_string(),
);
report.reason = Some(
"The chain's recorded end doesn't match its last entry: entries were \
removed or changed at the end."
.into(),
);
}
}
report.unfinished = pending.len() as u64;
reports.push(report);
}
Ok(reports)
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn keys_read_back() {
let ValueClass::Any(any) = class(KIND_TIME, &[5, 3, 9]) else {
panic!()
};
assert_eq!(parse_key(&any.key, KIND_TIME, 3), Some(vec![5, 3, 9]));
let mut with_subspace = vec![SUBSPACE_INBUXA];
with_subspace.extend_from_slice(&any.key);
assert_eq!(parse_key(&with_subspace, KIND_TIME, 3), Some(vec![5, 3, 9]));
assert_eq!(parse_key(&any.key, KIND_ENTRY, 3), None);
}
#[test]
fn ids_read_back() {
let id = EntryId { node: 2, seq: 1042 };
assert_eq!(id.to_string(), "2-1042");
assert_eq!("2-1042".parse::<EntryId>(), Ok(id));
assert!("2".parse::<EntryId>().is_err());
assert!("a-1".parse::<EntryId>().is_err());
assert_eq!(EntryId::from_u64(id.to_u64()), id);
let big = EntryId {
node: 65535,
seq: (1 << 48) - 1,
};
assert_eq!(EntryId::from_u64(big.to_u64()), big);
}
#[test]
fn filters() {
use crate::audit::record::{Actor, Target};
let record = Record {
at: 1000,
actor: Actor::account(7, "[email protected]", Some(4)),
via: None,
remote_ip: None,
action: Action::Update,
target: Target {
kind: "x:Domain".into(),
id: Some("d".into()),
name: Some("example.org".into()),
tenant_id: Some(9),
..Default::default()
},
changes: vec![],
details: None,
reason: None,
outcome: Outcome::success(),
};
let yes = |filter: Filter| assert!(filter.matches(&record), "{filter:?}");
let no = |filter: Filter| assert!(!filter.matches(&record), "{filter:?}");
yes(Filter::default());
yes(Filter {
after: Some(1000),
before: Some(1001),
..Default::default()
});
no(Filter {
before: Some(1000),
..Default::default()
});
yes(Filter {
tenant_id: Some(4),
..Default::default()
});
yes(Filter {
tenant_id: Some(9),
..Default::default()
});
no(Filter {
tenant_id: Some(5),
..Default::default()
});
yes(Filter {
text: Some("admin EXAMPLE.ORG".into()),
..Default::default()
});
no(Filter {
text: Some("admin other".into()),
..Default::default()
});
yes(Filter {
outcome: Some("success".into()),
action: Some(Action::Update),
target_kind: Some("x:domain".into()),
..Default::default()
});
no(Filter {
actor_id: Some(8),
..Default::default()
});
}
#[test]
fn heads_read_back() {
let head = Head {
seq: 77,
hash: hash(b"x"),
};
let bytes = head.to_bytes();
assert!(AssertValue::U64(77).matches(&bytes));
assert!(!AssertValue::U64(76).matches(&bytes));
assert_eq!(Head::deserialize(&bytes).unwrap(), head);
assert!(Head::deserialize(b"short").is_err());
}
#[test]
fn hashes_are_sha256_hex() {
assert_eq!(
hash(b""),
"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
);
}
}
+23
View File
@@ -0,0 +1,23 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! The audit log (audit-hold-lock spec, AU-1 to AU-11): a permanent record
//! of what administrators and the server itself did to the control plane,
//! kept in the fork's own subspace as one hash chain per node.
//!
//! - `record`: what one entry says.
//! - `log`: appending to the chain, reading, querying, purging, verifying.
//! - `scope`: who is acting, carried with the task, so a registry write the
//! server makes on its own is told apart from one a request made.
//! - `diff`: what changed in a registry object, with secrets redacted.
pub mod diff;
pub mod log;
pub mod record;
pub mod scope;
pub use log::{AuditLog, EntryId};
pub use record::{Action, Actor, Change, Outcome, Record, Target, Via};
+349
View File
@@ -0,0 +1,349 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! What an audit entry holds (AU-4). Stored as JSON, so entries written by
//! one version of the fork read back in the next.
use serde::{Deserialize, Serialize};
use serde_json::Value;
use std::net::IpAddr;
/// Longest value kept for one side of a change; longer ones are cut, with
/// their original length noted.
pub const MAX_VALUE_LEN: usize = 2048;
/// One thing that happened.
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct Record {
/// Milliseconds since the epoch.
pub at: u64,
pub actor: Actor,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub via: Option<Via>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub remote_ip: Option<IpAddr>,
pub action: Action,
pub target: Target,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub changes: Vec<Change>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub details: Option<String>,
/// Why, as the actor gave it: required for holds, locks and exports,
/// optional for everything else.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub reason: Option<String>,
pub outcome: Outcome,
}
/// Who acted: an account, named as it was then, or the server itself.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct Actor {
#[serde(default, skip_serializing_if = "Option::is_none")]
pub account_id: Option<u32>,
/// The account's name, or `system:<subsystem>`.
pub name: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub tenant_id: Option<u32>,
}
impl Actor {
pub fn account(account_id: u32, name: impl Into<String>, tenant_id: Option<u32>) -> Self {
Actor {
account_id: Some(account_id),
name: name.into(),
tenant_id,
}
}
pub fn system(subsystem: &str) -> Self {
Actor {
account_id: None,
name: format!("system:{subsystem}"),
tenant_id: None,
}
}
pub fn is_system(&self) -> bool {
self.account_id.is_none()
}
}
/// How the actor signed in (AU-5).
#[derive(Debug, Clone, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(tag = "kind", rename_all = "camelCase")]
pub enum Via {
Password,
AppPassword {
id: u32,
},
ApiKey {
id: u32,
},
#[serde(rename = "oauth")]
OAuth {
client: String,
},
/// A token from an external directory (OIDC).
Directory,
/// Signed in as someone else with a master user's password.
#[serde(rename_all = "camelCase")]
Master {
#[serde(default, skip_serializing_if = "Option::is_none")]
account_id: Option<u32>,
name: String,
},
/// The recovery administrator from the server's own configuration.
Recovery,
}
/// What kind of thing happened.
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub enum Action {
Create,
Update,
Destroy,
SignIn,
SignInFailed,
/// JMAP access to another account through `Impersonate`.
AccountAccess,
/// A blob of another account read through `FetchAnyBlob`.
BlobAccess,
Export,
Verify,
}
impl Action {
pub fn as_str(&self) -> &'static str {
match self {
Action::Create => "create",
Action::Update => "update",
Action::Destroy => "destroy",
Action::SignIn => "signIn",
Action::SignInFailed => "signInFailed",
Action::AccountAccess => "accountAccess",
Action::BlobAccess => "blobAccess",
Action::Export => "export",
Action::Verify => "verify",
}
}
pub fn parse(value: &str) -> Option<Self> {
Some(match value {
"create" => Action::Create,
"update" => Action::Update,
"destroy" => Action::Destroy,
"signIn" => Action::SignIn,
"signInFailed" => Action::SignInFailed,
"accountAccess" => Action::AccountAccess,
"blobAccess" => Action::BlobAccess,
"export" => Action::Export,
"verify" => Action::Verify,
_ => return None,
})
}
}
/// What it happened to.
#[derive(Debug, Clone, PartialEq, Eq, Default, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct Target {
/// An object type (`x:Domain`, `inbuxa:ProtocolPolicy`), or `account`
/// for sign-ins and access.
pub kind: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub id: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub name: Option<String>,
/// The account the object belongs to, when it belongs to one.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub account_id: Option<u32>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub tenant_id: Option<u32>,
}
/// One property's change. A secret is never stored: `redacted` says it
/// changed, and both sides are left out (AU-4).
#[derive(Debug, Clone, PartialEq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct Change {
pub field: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub before: Option<Value>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub after: Option<Value>,
#[serde(default, skip_serializing_if = "std::ops::Not::not")]
pub redacted: bool,
}
impl Change {
pub fn new(field: impl Into<String>, before: Option<Value>, after: Option<Value>) -> Self {
Change {
field: field.into(),
before: before.map(shorten),
after: after.map(shorten),
redacted: false,
}
}
pub fn redacted(field: impl Into<String>) -> Self {
Change {
field: field.into(),
before: None,
after: None,
redacted: true,
}
}
}
/// How it ended.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(
tag = "status",
rename_all = "camelCase",
rename_all_fields = "camelCase"
)]
pub enum Outcome {
Success {
/// The id a create was given.
#[serde(default, skip_serializing_if = "Option::is_none")]
created_id: Option<String>,
},
Refused {
/// The JMAP error type (`forbidden`, `invalidProperties`, …).
error: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
description: Option<String>,
},
/// Written before the change was tried; its outcome follows in a later
/// entry, or never if the server stopped in between (AU-3).
Pending,
}
impl Outcome {
pub fn success() -> Self {
Outcome::Success { created_id: None }
}
pub fn refused(error: impl Into<String>, description: Option<String>) -> Self {
Outcome::Refused {
error: error.into(),
description: description.map(|d| shorten_str(d, 500)),
}
}
pub fn as_str(&self) -> &'static str {
match self {
Outcome::Success { .. } => "success",
Outcome::Refused { .. } => "refused",
Outcome::Pending => "pending",
}
}
}
/// Cuts a long value, keeping it valid JSON.
pub fn shorten(value: Value) -> Value {
match value {
Value::String(s) if s.len() > MAX_VALUE_LEN => Value::String(shorten_str(s, MAX_VALUE_LEN)),
Value::String(_) | Value::Null | Value::Bool(_) | Value::Number(_) => value,
other => {
let text = other.to_string();
if text.len() > MAX_VALUE_LEN {
Value::String(shorten_str(text, MAX_VALUE_LEN))
} else {
other
}
}
}
}
fn shorten_str(s: String, max: usize) -> String {
if s.len() <= max {
return s;
}
let mut end = max;
while !s.is_char_boundary(end) {
end -= 1;
}
format!("{}… ({} bytes in all)", &s[..end], s.len())
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn reads_back_as_written() {
let record = Record {
at: 1_800_000_000_000,
actor: Actor::account(3, "[email protected]", None),
via: Some(Via::OAuth {
client: "inbuxa-admin".into(),
}),
remote_ip: Some("192.0.2.1".parse().unwrap()),
action: Action::Update,
target: Target {
kind: "x:Domain".into(),
id: Some("b".into()),
name: Some("example.com".into()),
..Default::default()
},
changes: vec![
Change::new("isEnabled", Some(true.into()), Some(false.into())),
Change::redacted("secret"),
],
details: None,
reason: Some("Ticket 42".into()),
outcome: Outcome::Pending,
};
let json = serde_json::to_string(&record).unwrap();
assert!(json.contains("\"kind\":\"oauth\""));
let created = serde_json::to_string(&Outcome::Success {
created_id: Some("c".into()),
})
.unwrap();
assert_eq!(created, r#"{"status":"success","createdId":"c"}"#);
assert!(json.contains("\"redacted\":true"));
assert!(!json.contains("\"details\""));
assert_eq!(serde_json::from_str::<Record>(&json).unwrap(), record);
}
#[test]
fn long_values_are_cut() {
let long = "é".repeat(MAX_VALUE_LEN);
let Value::String(cut) = shorten(Value::String(long.clone())) else {
panic!()
};
assert!(cut.len() < long.len());
assert!(cut.ends_with(&format!("({} bytes in all)", long.len())));
let array = Value::Array((0..2000).map(Value::from).collect());
assert!(shorten(array).is_string());
assert_eq!(shorten(Value::from(5)), Value::from(5));
}
#[test]
fn actions_round_trip() {
for action in [
Action::Create,
Action::Update,
Action::Destroy,
Action::SignIn,
Action::SignInFailed,
Action::AccountAccess,
Action::BlobAccess,
Action::Export,
Action::Verify,
] {
assert_eq!(Action::parse(action.as_str()), Some(action));
assert_eq!(
serde_json::to_value(action).unwrap(),
Value::String(action.as_str().into())
);
}
}
}
+70
View File
@@ -0,0 +1,70 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Who a registry write is for, carried with the task that makes it.
//!
//! A JMAP request records its own changes, with the actor and what was
//! asked (AU-1.1), so the registry's write hook stays quiet inside one. A
//! write outside any request is the server acting on its own (AU-1.10) and
//! is recorded by the hook, under the subsystem named here or as
//! `system:server` when none is.
use std::future::Future;
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub enum Scope {
/// A request that records its own changes.
Request,
/// The server acting on its own, in the named subsystem.
System(&'static str),
/// Writes counted, not recorded one by one: a bulk update records one
/// summary itself (spam rules from an update, for one).
Quiet,
}
tokio::task_local! {
static SCOPE: Scope;
}
/// Runs `f` as a request that records its own changes.
pub async fn request<F: Future>(f: F) -> F::Output {
SCOPE.scope(Scope::Request, f).await
}
/// Runs `f` as the server's own `subsystem`.
pub async fn system<F: Future>(subsystem: &'static str, f: F) -> F::Output {
SCOPE.scope(Scope::System(subsystem), f).await
}
/// Runs `f` without recording its registry writes one by one.
pub async fn quiet<F: Future>(f: F) -> F::Output {
SCOPE.scope(Scope::Quiet, f).await
}
/// The scope the current task runs in, if any.
pub fn current() -> Option<Scope> {
SCOPE.try_with(|scope| *scope).ok()
}
#[cfg(test)]
mod tests {
use super::*;
#[tokio::test]
async fn nested_scopes() {
assert_eq!(current(), None);
system("acme", async {
assert_eq!(current(), Some(Scope::System("acme")));
request(async {
assert_eq!(current(), Some(Scope::Request));
})
.await;
assert_eq!(current(), Some(Scope::System("acme")));
})
.await;
assert_eq!(current(), None);
}
}
+772
View File
@@ -0,0 +1,772 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Legal holds (audit-hold-lock spec, LH-1 to LH-14).
//!
//! A hold names a case and what it covers: accounts, groups, domains,
//! tenants or the whole server, optionally only items dated inside a range.
//! While any active hold covers an item, nothing may destroy it. A hold is
//! never deleted: releasing it keeps it, read-only, for the audit trail.
//!
//! Kept in the fork's subspace (`store::SUBSPACE_INBUXA`). Every key starts
//! with `H`, then one byte for the kind:
//!
//! - `h` + hold id (u32): the hold, as JSON.
//!
//! Numbers are big-endian. There are few holds, so they're read whole.
use registry::schema::{prelude::ObjectInner, structs::Account};
use serde::{Deserialize as SerdeDeserialize, Serialize as SerdeSerialize};
use store::{
Deserialize, IterateParams, SUBSPACE_INBUXA, Serialize, Store, ValueKey,
write::{AnyClass, BatchBuilder, ValueClass, assert::AssertValue},
};
use trc::AddContext;
/// The deadline a held archived item carries: the last second of 9999. It
/// never passes, so every expiry check keeps the item without knowing about
/// holds (LH-4, LH-5); releasing a hold gives it a real deadline (LH-10).
pub const HELD_UNTIL: u64 = 253_402_300_799;
/// Whether an archived item's deadline marks it as held. Anything past the
/// year 9000 counts, so a deadline computed from a hold a moment earlier or
/// later still reads as held.
pub fn is_held_until(until: u64) -> bool {
until >= 221_845_392_000
}
/// A day, in seconds: the slack either side of a range for an event's start,
/// whose time zone isn't known here.
const DAY: u64 = 86_400;
/// How an account's deleted items are kept: its holds' ranges, and the
/// undelete period for whatever no hold covers (LH-3, LH-4).
#[derive(Debug, Clone, Default, PartialEq, Eq)]
pub struct Keeping {
/// `archiveDeletedItemsFor`, in seconds, if undelete is on.
pub retention: Option<u64>,
/// Each active hold's range on this account; `(None, None)` is a whole
/// account. Empty when nothing holds it.
pub ranges: Vec<(Option<u64>, Option<u64>)>,
}
impl Keeping {
pub fn new(retention: Option<u64>, holds: &[Hold]) -> Keeping {
Keeping {
retention,
ranges: holds.iter().map(|h| (h.from, h.to)).collect(),
}
}
/// Whether any hold reaches the account at all.
pub fn is_held(&self) -> bool {
!self.ranges.is_empty()
}
/// Whether deleted items need noting: something may keep them.
pub fn keeps_anything(&self) -> bool {
self.is_held() || self.retention.is_some()
}
/// Whether a hold covers an item dated `date`. No date means the item is
/// held whole, whatever the range (LH-3).
pub fn covers(&self, date: Option<u64>) -> bool {
self.ranges.iter().any(|(from, to)| match date {
None => true,
Some(at) => {
from.is_none_or(|from| at >= from) && to.is_none_or(|to| at <= to)
}
})
}
/// Like `covers`, for an event's start: a day of slack either side, since
/// its time zone isn't known here.
pub fn covers_event(&self, start: Option<u64>) -> bool {
self.ranges.iter().any(|(from, to)| match start {
None => true,
Some(at) => {
from.is_none_or(|from| at + DAY >= from)
&& to.is_none_or(|to| at <= to.saturating_add(DAY))
}
})
}
/// Until when an item deleted at `now` is kept: held, the undelete
/// period, or not at all.
pub fn until(&self, now: u64, held: bool) -> Option<u64> {
if held {
Some(HELD_UNTIL)
} else {
self.retention.map(|retention| now + retention)
}
}
}
const FEATURE: u8 = b'H';
const KIND_HOLD: u8 = b'h';
const KIND_ORIGINAL: u8 = b'o';
const KIND_EXPORT: u8 = b'e';
/// How far a hold export has got (LH-12).
#[derive(Debug, Clone, Copy, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub enum ExportStatus {
Running,
Ready,
Failed,
}
/// A collection of what a hold keeps, as a ZIP (LH-12).
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub struct Export {
pub id: u32,
pub hold_id: u32,
/// The accounts asked for; empty for every account the hold covers.
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub accounts: Vec<u32>,
pub reason: String,
pub created_at: u64,
pub created_by: String,
/// Whose blob the ZIP is, so only they download it.
pub created_by_id: u32,
pub status: ExportStatus,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub finished_at: Option<u64>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub blob_id: Option<String>,
#[serde(default)]
pub size: u64,
#[serde(default)]
pub items: u64,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub sha256: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub error: Option<String>,
}
/// How many times creating a hold retries when another node took its id.
const CREATE_ATTEMPTS: usize = 5;
/// What a hold covers (LH-1, LH-2). Domains and tenants are resolved live,
/// so an account added to one later is held too.
#[derive(Debug, Clone, Default, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub struct Scope {
/// Every account on the server.
#[serde(default, skip_serializing_if = "std::ops::Not::not")]
pub server: bool,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub accounts: Vec<u32>,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub groups: Vec<u32>,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub domains: Vec<u32>,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub tenants: Vec<u32>,
}
impl Scope {
pub fn is_empty(&self) -> bool {
!self.server
&& self.accounts.is_empty()
&& self.groups.is_empty()
&& self.domains.is_empty()
&& self.tenants.is_empty()
}
/// Whether this scope covers everything `other` does, entry by entry.
/// A scope may only grow (LH-3's rule for ranges, applied to scope):
/// taking something out would free what it held.
pub fn contains(&self, other: &Scope) -> bool {
let all = |mine: &[u32], theirs: &[u32]| theirs.iter().all(|id| mine.contains(id));
(self.server || !other.server)
&& all(&self.accounts, &other.accounts)
&& all(&self.groups, &other.groups)
&& all(&self.domains, &other.domains)
&& all(&self.tenants, &other.tenants)
}
fn normalize(&mut self) {
for list in [
&mut self.accounts,
&mut self.groups,
&mut self.domains,
&mut self.tenants,
] {
list.sort_unstable();
list.dedup();
}
}
}
/// What decides whether a hold's scope reaches an account: the domains of
/// its addresses, its groups and its tenant (LH-2).
#[derive(Debug, Clone, Default, PartialEq, Eq)]
pub struct Member {
pub account: u32,
pub domains: Vec<u32>,
pub groups: Vec<u32>,
pub tenant: Option<u32>,
}
impl Member {
/// A person's account as the registry stores it; `None` for a group,
/// whose own data is held through its members.
pub fn of(account_id: u32, object: &ObjectInner) -> Option<Member> {
let ObjectInner::Account(Account::User(user)) = object else {
return None;
};
let mut domains = vec![user.domain_id.document_id()];
domains.extend(user.aliases.iter().map(|alias| alias.domain_id.document_id()));
domains.sort_unstable();
domains.dedup();
Some(Member {
account: account_id,
domains,
groups: user.member_group_ids.iter().map(|id| id.document_id()).collect(),
tenant: user.member_tenant_id.map(|id| id.document_id()),
})
}
}
impl Scope {
/// Whether this scope reaches `member`, directly or through its domains,
/// groups or tenant, as they are now (LH-2).
pub fn covers(&self, member: &Member) -> bool {
self.server
|| self.accounts.contains(&member.account)
|| member.domains.iter().any(|d| self.domains.contains(d))
|| member.groups.iter().any(|g| self.groups.contains(g))
|| member.tenant.is_some_and(|t| self.tenants.contains(&t))
}
}
/// When and why a hold was released (LH-10).
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub struct Release {
pub at: u64,
pub by: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub by_id: Option<u32>,
pub reason: String,
}
/// A legal hold (LH-1).
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub struct Hold {
pub id: u32,
/// The case name.
pub name: String,
/// A matter or ticket number.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub reference: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub description: Option<String>,
pub scope: Scope,
/// Seconds since the epoch. Items dated before aren't held (LH-3).
#[serde(default, skip_serializing_if = "Option::is_none")]
pub from: Option<u64>,
/// Seconds since the epoch. Items dated after aren't held (LH-3).
#[serde(default, skip_serializing_if = "Option::is_none")]
pub to: Option<u64>,
pub placed_at: u64,
pub placed_by: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub placed_by_id: Option<u32>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub released: Option<Release>,
}
/// Why a change to a hold is refused.
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub enum Refusal {
/// A released hold is read-only (LH-1).
Released,
/// The range may only widen (LH-3).
Narrowed,
/// The scope may only grow.
ScopeShrunk,
/// A hold has to cover something.
EmptyScope,
/// `from` after `to`.
Backwards,
}
impl Refusal {
pub fn describe(self) -> &'static str {
match self {
Refusal::Released => "A released hold can't be changed; place a new one instead.",
Refusal::Narrowed => {
"A hold's date range can only be widened. To hold less, release it and place a new hold."
}
Refusal::ScopeShrunk => {
"Nothing can be taken out of a hold's scope. To hold less, release it and place a new hold."
}
Refusal::EmptyScope => "A hold has to cover at least one account, group, domain or tenant, or the whole server.",
Refusal::Backwards => "The range starts after it ends.",
}
}
}
impl Hold {
pub fn is_active(&self) -> bool {
self.released.is_none()
}
/// Whether an item dated `at` (seconds) falls in the hold's range. With
/// no range, everything does (LH-3).
pub fn covers_date(&self, at: u64) -> bool {
self.from.is_none_or(|from| at >= from) && self.to.is_none_or(|to| at <= to)
}
/// Checks a new hold, and tidies its scope.
pub fn check_new(&mut self) -> Result<(), Refusal> {
self.scope.normalize();
if self.scope.is_empty() {
return Err(Refusal::EmptyScope);
}
if let (Some(from), Some(to)) = (self.from, self.to)
&& from > to
{
return Err(Refusal::Backwards);
}
Ok(())
}
/// Checks that `next` is an allowed change of `self`: names and notes
/// may change, the range may only widen, the scope may only grow, and a
/// released hold may not change at all.
pub fn check_update(&self, next: &mut Hold) -> Result<(), Refusal> {
if !self.is_active() {
return Err(Refusal::Released);
}
next.check_new()?;
// An open end can't be closed, and a set end can only move outward
let from_ok = match (self.from, next.from) {
(None, Some(_)) => false,
(Some(old), Some(new)) => new <= old,
(_, None) => true,
};
let to_ok = match (self.to, next.to) {
(None, Some(_)) => false,
(Some(old), Some(new)) => new >= old,
(_, None) => true,
};
if !from_ok || !to_ok {
return Err(Refusal::Narrowed);
}
if !next.scope.contains(&self.scope) {
return Err(Refusal::ScopeShrunk);
}
Ok(())
}
}
struct Json<T>(T);
impl<T: SerdeSerialize> Serialize for Json<T> {
fn serialize(&self) -> trc::Result<Vec<u8>> {
serde_json::to_vec(&self.0).map_err(|err| {
trc::StoreEvent::UnexpectedError
.into_err()
.details("Failed to serialize legal hold")
.reason(err)
})
}
}
impl<T: serde::de::DeserializeOwned + Sync + Send> Deserialize for Json<T> {
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
serde_json::from_slice(bytes).map(Json).map_err(|err| {
trc::StoreEvent::DataCorruption
.into_err()
.details("Invalid legal hold")
.reason(err)
})
}
}
fn class(id: u32) -> ValueClass {
let mut key = Vec::with_capacity(6);
key.push(FEATURE);
key.push(KIND_HOLD);
key.extend_from_slice(&id.to_be_bytes());
ValueClass::Any(AnyClass {
subspace: SUBSPACE_INBUXA,
key,
})
}
fn key(id: u32) -> ValueKey<ValueClass> {
ValueKey::from(class(id))
}
fn original_class(item_id: u64) -> ValueClass {
let mut key = Vec::with_capacity(10);
key.push(FEATURE);
key.push(KIND_ORIGINAL);
key.extend_from_slice(&item_id.to_be_bytes());
ValueClass::Any(AnyClass {
subspace: SUBSPACE_INBUXA,
key,
})
}
/// LH-10: an archived item's deadline from before a hold froze it, so a
/// release can give it back (or a later one). None for an item held from
/// its deletion, which never had one.
pub async fn original_deadline(data: &Store, item_id: u64) -> trc::Result<Option<u64>> {
data.get_value::<u64>(ValueKey::from(original_class(item_id)))
.await
.caused_by(trc::location!())
}
/// Notes (`Some`) or forgets (`None`) an item's deadline from before it
/// was frozen.
pub async fn set_original_deadline(data: &Store, item_id: u64, until: Option<u64>) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
match until {
Some(until) => batch.set(original_class(item_id), until.to_be_bytes().to_vec()),
None => batch.clear(original_class(item_id)),
};
data.write(batch.build_all())
.await
.caused_by(trc::location!())
.map(|_| ())
}
fn export_class(id: u32) -> ValueClass {
let mut key = Vec::with_capacity(6);
key.push(FEATURE);
key.push(KIND_EXPORT);
key.extend_from_slice(&id.to_be_bytes());
ValueClass::Any(AnyClass {
subspace: SUBSPACE_INBUXA,
key,
})
}
/// Every hold export, oldest first.
pub async fn exports(data: &Store) -> trc::Result<Vec<Export>> {
let mut exports = Vec::new();
data.iterate(
IterateParams::new(ValueKey::from(export_class(0)), ValueKey::from(export_class(u32::MAX))),
|_, value| {
if let Ok(Json(export)) = Json::<Export>::deserialize(value) {
exports.push(export);
}
Ok(true)
},
)
.await
.caused_by(trc::location!())?;
Ok(exports)
}
/// Writes a new export under the next free id, which it returns.
pub async fn create_export(data: &Store, export: &Export) -> trc::Result<u32> {
let mut attempt = 0;
loop {
attempt += 1;
let id = exports(data).await?.iter().map(|e| e.id).max().unwrap_or(0) + 1;
let stored = Export {
id,
..export.clone()
};
let mut batch = BatchBuilder::new();
batch.assert_value(export_class(id), AssertValue::None);
batch.set(export_class(id), Json(&stored).serialize()?);
match data.write(batch.build_all()).await {
Ok(_) => return Ok(id),
Err(err)
if attempt < CREATE_ATTEMPTS
&& matches!(
err.as_ref(),
trc::EventType::Store(trc::StoreEvent::AssertValueFailed)
) => {}
Err(err) => return Err(err.caused_by(trc::location!())),
}
}
}
/// Saves an export's progress.
pub async fn update_export(data: &Store, export: &Export) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
batch.set(export_class(export.id), Json(export).serialize()?);
data.write(batch.build_all())
.await
.caused_by(trc::location!())
.map(|_| ())
}
/// One hold, released or not.
pub async fn get(data: &Store, id: u32) -> trc::Result<Option<Hold>> {
Ok(data
.get_value::<Json<Hold>>(key(id))
.await
.caused_by(trc::location!())?
.map(|Json(hold)| hold))
}
/// Every hold, released ones included, oldest first.
pub async fn all(data: &Store) -> trc::Result<Vec<Hold>> {
let mut holds = Vec::new();
data.iterate(IterateParams::new(key(0), key(u32::MAX)), |_, value| {
if let Ok(Json(hold)) = Json::<Hold>::deserialize(value) {
holds.push(hold);
}
Ok(true)
})
.await
.caused_by(trc::location!())?;
Ok(holds)
}
/// The holds still in force.
pub async fn active(data: &Store) -> trc::Result<Vec<Hold>> {
Ok(all(data).await?.into_iter().filter(Hold::is_active).collect())
}
/// Writes a new hold under the next free id, which it returns. Two nodes
/// placing holds at once can't take the same id: the key must be absent.
pub async fn create(data: &Store, hold: &Hold) -> trc::Result<u32> {
let mut attempt = 0;
loop {
attempt += 1;
let id = all(data).await?.iter().map(|h| h.id).max().unwrap_or(0) + 1;
let stored = Hold {
id,
..hold.clone()
};
let mut batch = BatchBuilder::new();
batch.assert_value(class(id), AssertValue::None);
batch.set(class(id), Json(&stored).serialize()?);
match data.write(batch.build_all()).await {
Ok(_) => return Ok(id),
Err(err)
if attempt < CREATE_ATTEMPTS
&& matches!(
err.as_ref(),
trc::EventType::Store(trc::StoreEvent::AssertValueFailed)
) => {}
Err(err) => return Err(err.caused_by(trc::location!())),
}
}
}
/// The active holds that reach `member` (LH-2, LH-11).
pub async fn covering(data: &Store, member: &Member) -> trc::Result<Vec<Hold>> {
Ok(active(data)
.await?
.into_iter()
.filter(|hold| hold.scope.covers(member))
.collect())
}
/// LH-2: an account a hold reached through its domain, group or tenant stays
/// held when it leaves them: it is added to the hold by name. Called for
/// every change to an account, so no move escapes a hold.
pub async fn keep_moved(data: &Store, before: &Member, after: &Member) -> trc::Result<()> {
if before == after {
return Ok(());
}
for mut hold in active(data).await? {
if hold.scope.covers(before) && !hold.scope.covers(after) {
hold.scope.accounts.push(after.account);
hold.scope.accounts.sort_unstable();
hold.scope.accounts.dedup();
update(data, &hold).await?;
}
}
Ok(())
}
/// LH-8: names `account_id` in every hold that reaches it, so a deleted
/// account, no longer in any domain or tenant, stays held.
pub async fn pin_account(data: &Store, member: &Member) -> trc::Result<()> {
for mut hold in covering(data, member).await? {
if !hold.scope.accounts.contains(&member.account) {
hold.scope.accounts.push(member.account);
hold.scope.accounts.sort_unstable();
update(data, &hold).await?;
}
}
Ok(())
}
/// Replaces a hold that `check_update` allowed.
pub async fn update(data: &Store, hold: &Hold) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
batch.set(class(hold.id), Json(hold).serialize()?);
data.write(batch.build_all())
.await
.caused_by(trc::location!())
.map(|_| ())
}
#[cfg(test)]
mod tests {
use super::*;
fn hold(scope: Scope, from: Option<u64>, to: Option<u64>) -> Hold {
Hold {
id: 1,
name: "Matter 4411".into(),
reference: Some("4411".into()),
description: None,
scope,
from,
to,
placed_at: 10,
placed_by: "admin".into(),
placed_by_id: None,
released: None,
}
}
fn accounts(ids: &[u32]) -> Scope {
Scope {
accounts: ids.to_vec(),
..Default::default()
}
}
#[test]
fn a_hold_needs_a_scope_and_a_forward_range() {
assert_eq!(hold(Scope::default(), None, None).check_new(), Err(Refusal::EmptyScope));
assert_eq!(hold(accounts(&[2]), Some(20), Some(10)).check_new(), Err(Refusal::Backwards));
let mut ok = hold(accounts(&[3, 2, 3]), None, None);
assert_eq!(ok.check_new(), Ok(()));
assert_eq!(ok.scope.accounts, vec![2, 3], "sorted, once each");
}
#[test]
fn the_range_only_widens() {
let current = hold(accounts(&[2]), Some(100), Some(200));
let widened = |from, to| {
let mut next = hold(accounts(&[2]), from, to);
current.check_update(&mut next)
};
assert_eq!(widened(Some(50), Some(300)), Ok(()));
assert_eq!(widened(None, None), Ok(()), "opening both ends widens");
assert_eq!(widened(Some(150), Some(200)), Err(Refusal::Narrowed));
assert_eq!(widened(Some(100), Some(150)), Err(Refusal::Narrowed));
let open = hold(accounts(&[2]), None, None);
let mut closed = hold(accounts(&[2]), Some(1), None);
assert_eq!(open.check_update(&mut closed), Err(Refusal::Narrowed), "an open end stays open");
}
#[test]
fn the_scope_only_grows() {
let current = hold(
Scope {
accounts: vec![2],
domains: vec![7],
..Default::default()
},
None,
None,
);
let mut grown = hold(
Scope {
accounts: vec![2, 3],
domains: vec![7],
tenants: vec![1],
..Default::default()
},
None,
None,
);
assert_eq!(current.check_update(&mut grown), Ok(()));
let mut shrunk = hold(accounts(&[2, 3]), None, None);
assert_eq!(current.check_update(&mut shrunk), Err(Refusal::ScopeShrunk));
let server = hold(Scope { server: true, ..Default::default() }, None, None);
let mut less = hold(accounts(&[2]), None, None);
assert_eq!(server.check_update(&mut less), Err(Refusal::ScopeShrunk));
}
#[test]
fn a_released_hold_is_read_only() {
let mut released = hold(accounts(&[2]), None, None);
released.released = Some(Release {
at: 50,
by: "admin".into(),
by_id: None,
reason: "Settled".into(),
});
let mut next = released.clone();
next.name = "Renamed".into();
assert_eq!(released.check_update(&mut next), Err(Refusal::Released));
assert!(!released.is_active());
}
#[test]
fn dates_in_range() {
let whole = hold(accounts(&[2]), None, None);
assert!(whole.covers_date(0) && whole.covers_date(u64::MAX));
let ranged = hold(accounts(&[2]), Some(100), Some(200));
assert!(ranged.covers_date(100) && ranged.covers_date(200));
assert!(!ranged.covers_date(99) && !ranged.covers_date(201));
let open_ended = hold(accounts(&[2]), Some(100), None);
assert!(open_ended.covers_date(u64::MAX), "no `to` also catches mail still to come");
}
#[test]
fn a_scope_reaches_members_through_domain_group_and_tenant() {
let member = Member {
account: 9,
domains: vec![3, 4],
groups: vec![20],
tenant: Some(7),
};
let reaches = |scope: Scope| scope.covers(&member);
assert!(reaches(accounts(&[9])));
assert!(reaches(Scope { domains: vec![4], ..Default::default() }), "an alias's domain counts");
assert!(reaches(Scope { groups: vec![20], ..Default::default() }));
assert!(reaches(Scope { tenants: vec![7], ..Default::default() }));
assert!(reaches(Scope { server: true, ..Default::default() }));
assert!(!reaches(Scope { domains: vec![5], tenants: vec![8], ..Default::default() }));
// LH-2: leaving the held domain would free it, so the hold must name it
let held = hold(Scope { domains: vec![3], ..Default::default() }, None, None);
let moved = Member { domains: vec![6], ..member.clone() };
assert!(held.scope.covers(&member) && !held.scope.covers(&moved));
}
#[test]
fn keeping_deleted_items() {
let whole = Keeping::new(None, &[hold(accounts(&[2]), None, None)]);
assert!(whole.covers(Some(5)) && whole.covers(None));
assert_eq!(whole.until(100, whole.covers(Some(5))), Some(HELD_UNTIL));
assert!(is_held_until(whole.until(100, true).unwrap()));
// LH-3: a range holds only what's inside it; outside, undelete's rules
let ranged = Keeping::new(Some(30), &[hold(accounts(&[2]), Some(1_000), Some(2_000))]);
assert!(ranged.covers(Some(1_500)) && !ranged.covers(Some(2_500)));
assert!(ranged.covers(None), "contacts, files and scripts are held whole");
assert_eq!(ranged.until(100, ranged.covers(Some(2_500))), Some(130));
assert!(ranged.covers_event(Some(2_000 + 3_600)), "a day of slack for an event");
// Neither held nor undelete: nothing is kept
let none = Keeping::new(None, &[]);
assert!(!none.keeps_anything());
assert_eq!(none.until(100, false), None);
assert!(!is_held_until(100 + 30 * 365 * 86_400));
}
#[test]
fn stored_as_json() {
let current = hold(accounts(&[2]), Some(100), None);
let json = serde_json::to_string(&current).unwrap();
assert_eq!(serde_json::from_str::<Hold>(&json).unwrap(), current);
assert!(json.contains("\"scope\":{\"accounts\":[2]}"), "{json}");
}
}
+5
View File
@@ -19,8 +19,13 @@
//! `common::Server`.
pub mod ai;
pub mod audit;
pub mod branding;
pub mod hold;
pub mod lock;
pub mod mailflow;
pub mod masked_email;
pub mod privacy;
pub mod security;
pub mod tenancy;
pub mod undelete;
+653
View File
@@ -0,0 +1,653 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Account lock with delegation (audit-hold-lock spec, AL-1 to AL-12).
//!
//! A locked account keeps receiving mail but can't sign in, by any means,
//! and sends nothing on its own. Delegates open it as a separate account,
//! through real ACL grants on its containers (the sharing every protocol
//! already honors), at a level the administrator chose.
//!
//! Kept in the fork's subspace (`store::SUBSPACE_INBUXA`). Every key starts
//! with `K`, then one byte for the kind:
//!
//! - `l` + account: the lock, as JSON.
//! - `d` + delegate + account: an index, so a delegate's access token can
//! find the accounts delegated to it with one scan.
//!
//! Numbers are big-endian. Nothing is cached in memory: the access token is
//! the cache, built from these keys and invalidated on every change.
use serde::{Deserialize as SerdeDeserialize, Serialize as SerdeSerialize};
use store::{
Deserialize, IterateParams, SUBSPACE_INBUXA, Serialize, Store, ValueKey,
write::{AnyClass, BatchBuilder, ValueClass},
};
use trc::AddContext;
use types::{
acl::{Acl, AclGrant},
collection::Collection,
};
use utils::map::bitmap::Bitmap;
/// Rung when a lock is written, so this node's expiry timer re-reads the
/// `until` dates (AL-5): a delegation ends at its time, not at a sweep.
pub static UNTIL_CHANGED: tokio::sync::Notify = tokio::sync::Notify::const_new();
/// The soonest `until` still ahead of `now`, across every lock.
pub fn next_until(locks: &[Lock], now: u64) -> Option<u64> {
locks
.iter()
.flat_map(|lock| &lock.delegates)
.filter_map(|delegate| delegate.until)
.filter(|until| *until > now)
.min()
}
/// Locks with a delegation that ended in `(after, now]`.
pub fn ended_between(locks: &[Lock], after: u64, now: u64) -> impl Iterator<Item = u32> + '_ {
locks
.iter()
.filter(move |lock| {
lock.delegates
.iter()
.any(|d| d.until.is_some_and(|until| until > after && until <= now))
})
.map(|lock| lock.account_id)
}
const FEATURE: u8 = b'K';
const KIND_LOCK: u8 = b'l';
const KIND_DELEGATE: u8 = b'd';
/// Most delegates one lock may have (AL-5).
pub const MAX_DELEGATES: usize = 10;
/// What a delegate may do in the locked account (AL-6).
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub enum Access {
/// See and download everything; change nothing, not even `$seen`.
Read,
/// Read, set keywords, move mail and create and rename folders; never
/// destroy.
Organize,
/// Everything the owner could do. Deletions are still kept under a hold.
Full,
}
impl Access {
pub fn as_str(&self) -> &'static str {
match self {
Access::Read => "read",
Access::Organize => "organize",
Access::Full => "full",
}
}
pub fn parse(value: &str) -> Option<Self> {
match value {
"read" => Some(Access::Read),
"organize" => Some(Access::Organize),
"full" => Some(Access::Full),
_ => None,
}
}
/// Whether a delegate at this level may destroy anything.
pub fn may_destroy(&self) -> bool {
matches!(self, Access::Full)
}
/// The rights granted on one container. `is_trash` marks a mailbox with
/// the Trash or Junk role: an organizing delegate may read it, but not
/// move mail into it, since mail there is destroyed in time.
pub fn grants(&self, collection: Collection, is_trash: bool) -> Bitmap<Acl> {
let read = [Acl::Read, Acl::ReadItems];
let rights: &[Acl] = match (self, collection) {
(Access::Read, _) => &read,
(Access::Organize, Collection::Mailbox) if is_trash => &read,
(Access::Organize, Collection::Mailbox) => &[
Acl::Read,
Acl::ReadItems,
Acl::Modify,
Acl::AddItems,
Acl::ModifyItems,
Acl::RemoveItems,
Acl::CreateChild,
],
// Calendars, address books and files have no "move": organizing
// there is adding and changing, never removing
(Access::Organize, _) => &[
Acl::Read,
Acl::ReadItems,
Acl::AddItems,
Acl::ModifyItems,
Acl::CreateChild,
],
(Access::Full, _) => &[
Acl::Read,
Acl::Modify,
Acl::Delete,
Acl::ReadItems,
Acl::AddItems,
Acl::ModifyItems,
Acl::RemoveItems,
Acl::CreateChild,
Acl::Submit,
Acl::ModifyItemsOwn,
Acl::ModifyPrivateProperties,
Acl::ModifyRSVP,
Acl::SchedulingReadFreeBusy,
Acl::SchedulingInvite,
Acl::SchedulingReply,
],
};
Bitmap::from_iter(rights.iter().copied())
}
}
/// One person the locked account is handed to (AL-5).
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub struct Delegate {
pub account_id: u32,
pub access: Access,
/// May send from the locked account's identities (AL-8). Needs
/// `organize` or `full`: a message is made in its Drafts first.
#[serde(default)]
pub send_as: bool,
/// Seconds since the epoch; the delegation ends then on its own.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub until: Option<u64>,
}
impl Delegate {
pub fn is_current(&self, now: u64) -> bool {
self.until.is_none_or(|until| until > now)
}
}
/// A delegate's rights a lock replaced on one container, put back when the
/// lock or that delegation ends (AL-10). A container with no entry had no
/// grant for that delegate before.
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub struct Replaced {
pub collection: u8,
pub document_id: u32,
pub delegate: u32,
/// The rights as a bitmap's raw value.
pub rights: u64,
}
/// An account's lock (AL-1).
#[derive(Debug, Clone, PartialEq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub struct Lock {
pub account_id: u32,
pub reason: String,
/// Seconds since the epoch.
pub locked_at: u64,
pub locked_by: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub locked_by_id: Option<u32>,
#[serde(default)]
pub delegates: Vec<Delegate>,
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub replaced: Vec<Replaced>,
}
impl Lock {
pub fn delegate(&self, account_id: u32) -> Option<&Delegate> {
self.delegates.iter().find(|d| d.account_id == account_id)
}
/// The grants a new container of this account gets: one per current
/// delegate (AL-7, containers made later).
pub fn grants_for_new(
&self,
collection: Collection,
is_trash: bool,
now: u64,
) -> Vec<(u32, Bitmap<Acl>)> {
self.delegates
.iter()
.filter(|d| d.is_current(now))
.map(|d| (d.account_id, d.access.grants(collection, is_trash)))
.collect()
}
}
/// One container's ACL as a lock change leaves it (AL-7, AL-10).
///
/// Delegates in `new` get their level's rights. The first time a delegate
/// is given a container, whatever it had there before is noted in
/// `replaced`; entries `old` already noted are carried over. Delegates only
/// in `old` get back what they had before, or nothing. Returns the new ACL
/// when it differs from `current`.
pub fn merge_grants(
current: &[AclGrant],
collection: Collection,
document_id: u32,
is_trash: bool,
old: Option<&Lock>,
new: Option<&Lock>,
now: u64,
replaced: &mut Vec<Replaced>,
) -> Option<Vec<AclGrant>> {
let mut acls = current.to_vec();
let collection_id = collection as u8;
let noted = |lock: &Lock, delegate: u32| {
lock.replaced
.iter()
.find(|r| {
r.collection == collection_id && r.document_id == document_id && r.delegate == delegate
})
.cloned()
};
let is_current = |lock: Option<&Lock>, delegate: u32| {
lock.and_then(|lock| lock.delegate(delegate))
.is_some_and(|d| d.is_current(now))
};
let set = |acls: &mut Vec<AclGrant>, account_id: u32, grants: Bitmap<Acl>| {
acls.retain(|a| a.account_id != account_id);
if !grants.is_empty() {
acls.push(AclGrant { account_id, grants });
}
};
// Delegations that ended get back what they had
if let Some(old) = old {
for delegate in &old.delegates {
if is_current(new, delegate.account_id) {
continue;
}
let note = noted(old, delegate.account_id);
let before = note
.as_ref()
.map(|r| Bitmap::from(r.rights))
.unwrap_or_default();
set(&mut acls, delegate.account_id, before);
// Still listed but past its `until`: keep the note, so running
// this again puts back the same share instead of removing it
if let Some(note) = note
&& new.is_some_and(|new| new.delegate(delegate.account_id).is_some())
{
replaced.push(note);
}
}
}
// Current delegations get their level
if let Some(new) = new {
for delegate in new.delegates.iter().filter(|d| d.is_current(now)) {
let had = old.and_then(|old| {
is_current(Some(old), delegate.account_id)
.then(|| noted(old, delegate.account_id))
.flatten()
});
match had {
Some(entry) => replaced.push(entry),
None if !is_current(old, delegate.account_id) => {
if let Some(existing) = current.iter().find(|a| a.account_id == delegate.account_id) {
replaced.push(Replaced {
collection: collection_id,
document_id,
delegate: delegate.account_id,
rights: existing.grants.into(),
});
}
}
None => {}
}
set(
&mut acls,
delegate.account_id,
delegate.access.grants(collection, is_trash),
);
}
}
let sorted = |acls: &[AclGrant]| {
let mut v = acls.iter().map(|a| (a.account_id, u64::from(a.grants))).collect::<Vec<_>>();
v.sort();
v
};
(sorted(&acls) != sorted(current)).then_some(acls)
}
struct Json<T>(T);
impl<T: SerdeSerialize> Serialize for Json<T> {
fn serialize(&self) -> trc::Result<Vec<u8>> {
serde_json::to_vec(&self.0).map_err(|err| {
trc::StoreEvent::UnexpectedError
.into_err()
.details("Failed to serialize account lock")
.reason(err)
})
}
}
impl<T: serde::de::DeserializeOwned + Sync + Send> Deserialize for Json<T> {
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
serde_json::from_slice(bytes).map(Json).map_err(|err| {
trc::StoreEvent::DataCorruption
.into_err()
.details("Invalid account lock")
.reason(err)
})
}
}
fn class(kind: u8, parts: &[u32]) -> ValueClass {
let mut key = Vec::with_capacity(2 + parts.len() * 4);
key.push(FEATURE);
key.push(kind);
for part in parts {
key.extend_from_slice(&part.to_be_bytes());
}
ValueClass::Any(AnyClass {
subspace: SUBSPACE_INBUXA,
key,
})
}
fn key(kind: u8, parts: &[u32]) -> ValueKey<ValueClass> {
ValueKey::from(class(kind, parts))
}
/// The numbers after the kind byte, from the key's tail (the iterator may or
/// may not hand back the subspace byte).
fn parse_key(key: &[u8], kind: u8, parts: usize) -> Option<Vec<u32>> {
let len = 2 + parts * 4;
let tail = key.get(key.len().checked_sub(len)?..)?;
(tail[0] == FEATURE && tail[1] == kind).then_some(())?;
Some(
tail[2..]
.chunks_exact(4)
.map(|chunk| u32::from_be_bytes(chunk.try_into().unwrap()))
.collect(),
)
}
/// An account's lock, if it is locked.
pub async fn get(data: &Store, account_id: u32) -> trc::Result<Option<Lock>> {
Ok(data
.get_value::<Json<Lock>>(key(KIND_LOCK, &[account_id]))
.await
.caused_by(trc::location!())?
.map(|Json(lock)| lock))
}
/// Every lock, for the console's list.
pub async fn all(data: &Store) -> trc::Result<Vec<Lock>> {
let mut locks = Vec::new();
data.iterate(
IterateParams::new(key(KIND_LOCK, &[0]), key(KIND_LOCK, &[u32::MAX])),
|_, value| {
if let Ok(Json(lock)) = Json::<Lock>::deserialize(value) {
locks.push(lock);
}
Ok(true)
},
)
.await
.caused_by(trc::location!())?;
Ok(locks)
}
/// The accounts delegated to `delegate`, with its delegation in each.
pub async fn delegated_to(data: &Store, delegate: u32) -> trc::Result<Vec<(u32, Delegate)>> {
let mut locked = Vec::new();
data.iterate(
IterateParams::new(
key(KIND_DELEGATE, &[delegate, 0]),
key(KIND_DELEGATE, &[delegate, u32::MAX]),
)
.no_values(),
|key, _| {
if let Some(parts) = parse_key(key, KIND_DELEGATE, 2) {
locked.push(parts[1]);
}
Ok(true)
},
)
.await
.caused_by(trc::location!())?;
let mut delegations = Vec::with_capacity(locked.len());
for account_id in locked {
if let Some(lock) = get(data, account_id).await?
&& let Some(delegation) = lock.delegate(delegate)
{
delegations.push((account_id, delegation.clone()));
}
}
Ok(delegations)
}
/// Writes a lock, keeping the delegate index in step with `previous`.
pub async fn set(data: &Store, lock: &Lock, previous: Option<&Lock>) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
if let Some(previous) = previous {
for delegate in &previous.delegates {
if lock.delegate(delegate.account_id).is_none() {
batch.clear(class(KIND_DELEGATE, &[delegate.account_id, lock.account_id]));
}
}
}
for delegate in &lock.delegates {
batch.set(
class(KIND_DELEGATE, &[delegate.account_id, lock.account_id]),
vec![],
);
}
batch.set(class(KIND_LOCK, &[lock.account_id]), Json(lock).serialize()?);
data.write(batch.build_all())
.await
.caused_by(trc::location!())?;
UNTIL_CHANGED.notify_one();
Ok(())
}
/// Removes a lock and its delegate index.
pub async fn remove(data: &Store, lock: &Lock) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
for delegate in &lock.delegates {
batch.clear(class(KIND_DELEGATE, &[delegate.account_id, lock.account_id]));
}
batch.clear(class(KIND_LOCK, &[lock.account_id]));
data.write(batch.build_all())
.await
.caused_by(trc::location!())
.map(|_| ())
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn keys_read_back() {
let ValueClass::Any(any) = class(KIND_DELEGATE, &[7, 9]) else {
panic!()
};
assert_eq!(parse_key(&any.key, KIND_DELEGATE, 2), Some(vec![7, 9]));
let mut with_subspace = vec![SUBSPACE_INBUXA];
with_subspace.extend_from_slice(&any.key);
assert_eq!(parse_key(&with_subspace, KIND_DELEGATE, 2), Some(vec![7, 9]));
assert_eq!(parse_key(&any.key, KIND_LOCK, 2), None);
}
#[test]
fn levels_grant_what_they_say() {
let read = Access::Read.grants(Collection::Mailbox, false);
assert!(read.contains(Acl::ReadItems));
assert!(!read.contains(Acl::ModifyItems), "read can't set $seen");
assert!(!read.contains(Acl::RemoveItems));
let organize = Access::Organize.grants(Collection::Mailbox, false);
assert!(organize.contains(Acl::RemoveItems), "moving needs it");
assert!(!organize.contains(Acl::Delete));
assert!(!organize.contains(Acl::Submit));
let trash = Access::Organize.grants(Collection::Mailbox, true);
assert!(!trash.contains(Acl::AddItems), "nothing moved into Trash");
let calendar = Access::Organize.grants(Collection::Calendar, false);
assert!(!calendar.contains(Acl::RemoveItems));
let full = Access::Full.grants(Collection::Mailbox, false);
assert!(full.contains(Acl::Delete) && full.contains(Acl::RemoveItems));
assert!(!full.contains(Acl::Share), "a delegate can't pass it on");
assert!(Access::Full.may_destroy() && !Access::Organize.may_destroy());
}
fn lock_with(delegates: Vec<Delegate>, replaced: Vec<Replaced>) -> Lock {
Lock {
account_id: 1,
reason: "r".into(),
locked_at: 0,
locked_by: "admin".into(),
locked_by_id: None,
delegates,
replaced,
}
}
fn delegate(account_id: u32, access: Access) -> Delegate {
Delegate {
account_id,
access,
send_as: false,
until: None,
}
}
#[test]
fn grants_are_added_and_restored() {
let read = Access::Read.grants(Collection::Mailbox, false);
let full = Access::Full.grants(Collection::Mailbox, false);
// Delegate 2 already had a share here; delegate 3 had nothing
let earlier: Bitmap<Acl> = Bitmap::from_iter([Acl::Read]);
let current = vec![AclGrant {
account_id: 2,
grants: earlier,
}];
let lock = lock_with(
vec![delegate(2, Access::Full), delegate(3, Access::Read)],
vec![],
);
let mut replaced = Vec::new();
let acls = merge_grants(&current, Collection::Mailbox, 5, false, None, Some(&lock), 0, &mut replaced)
.unwrap();
assert!(acls.contains(&AclGrant { account_id: 2, grants: full }));
assert!(acls.contains(&AclGrant { account_id: 3, grants: read }));
assert_eq!(replaced.len(), 1, "only 2 had rights to put back");
assert_eq!(replaced[0].rights, u64::from(earlier));
// Running it again changes nothing and keeps the note
let locked = Lock { replaced: replaced.clone(), ..lock.clone() };
let mut again = Vec::new();
assert!(merge_grants(&acls, Collection::Mailbox, 5, false, Some(&locked), Some(&locked), 0, &mut again).is_none());
assert_eq!(again, replaced);
// Unlocking puts 2's share back and removes 3
let mut none = Vec::new();
let back = merge_grants(&acls, Collection::Mailbox, 5, false, Some(&locked), None, 0, &mut none).unwrap();
assert_eq!(back, vec![AclGrant { account_id: 2, grants: earlier }]);
// Ending one delegation keeps the other
let fewer = lock_with(vec![delegate(3, Access::Read)], vec![]);
let mut kept = Vec::new();
let after = merge_grants(&acls, Collection::Mailbox, 5, false, Some(&locked), Some(&fewer), 0, &mut kept).unwrap();
assert!(after.contains(&AclGrant { account_id: 2, grants: earlier }));
assert!(after.contains(&AclGrant { account_id: 3, grants: read }));
}
#[test]
fn an_expired_delegation_gives_back_its_share_every_time() {
let earlier: Bitmap<Acl> = Bitmap::from_iter([Acl::Read]);
let note = Replaced {
collection: Collection::Mailbox as u8,
document_id: 5,
delegate: 2,
rights: u64::from(earlier),
};
let mut ending = delegate(2, Access::Full);
ending.until = Some(200);
let lock = lock_with(vec![ending], vec![note.clone()]);
let during = vec![AclGrant {
account_id: 2,
grants: Access::Full.grants(Collection::Mailbox, false),
}];
// At its `until`, the share it had before comes back, and the note stays
let mut replaced = Vec::new();
let after = merge_grants(&during, Collection::Mailbox, 5, false, Some(&lock), Some(&lock), 300, &mut replaced)
.unwrap();
assert_eq!(after, vec![AclGrant { account_id: 2, grants: earlier }]);
assert_eq!(replaced, vec![note.clone()]);
// The next sweep changes nothing, rather than removing that share
let swept = Lock { replaced: replaced.clone(), ..lock };
let mut again = Vec::new();
assert!(
merge_grants(&after, Collection::Mailbox, 5, false, Some(&swept), Some(&swept), 400, &mut again).is_none()
);
assert_eq!(again, vec![note]);
}
#[test]
fn the_timer_finds_the_next_end() {
let ends_at = |account_id, until| {
let mut d = delegate(account_id, Access::Read);
d.until = until;
d
};
let a = Lock { account_id: 10, ..lock_with(vec![ends_at(2, Some(500)), ends_at(3, None)], vec![]) };
let b = Lock { account_id: 11, ..lock_with(vec![ends_at(4, Some(300))], vec![]) };
let locks = vec![a, b];
assert_eq!(next_until(&locks, 100), Some(300));
assert_eq!(next_until(&locks, 300), Some(500));
assert_eq!(next_until(&locks, 500), None);
assert_eq!(ended_between(&locks, 100, 300).collect::<Vec<_>>(), vec![11]);
assert_eq!(ended_between(&locks, 300, 600).collect::<Vec<_>>(), vec![10]);
assert!(ended_between(&locks, 600, 900).next().is_none());
}
#[test]
fn expired_delegations_grant_nothing() {
let lock = Lock {
account_id: 1,
reason: "Left the company".into(),
locked_at: 100,
locked_by: "admin".into(),
locked_by_id: None,
delegates: vec![
Delegate {
account_id: 2,
access: Access::Read,
send_as: false,
until: Some(200),
},
Delegate {
account_id: 3,
access: Access::Full,
send_as: true,
until: None,
},
],
replaced: vec![],
};
let grants = lock.grants_for_new(Collection::Mailbox, false, 300);
assert_eq!(grants.len(), 1);
assert_eq!(grants[0].0, 3);
let json = serde_json::to_string(&lock).unwrap();
assert_eq!(serde_json::from_str::<Lock>(&json).unwrap(), lock);
assert!(json.contains("\"access\":\"full\""));
}
}
+53
View File
@@ -0,0 +1,53 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! The compiled rules, kept per node so a message doesn't read the store.
//! A change made on this node applies at once; one made on another node
//! within [`TTL`], when the copy here is next refreshed.
use super::{engine::Compiled, rules};
use std::{
sync::{Arc, RwLock},
time::{Duration, Instant},
};
use store::Store;
/// How long a node keeps its copy before reading the rules again.
pub const TTL: Duration = Duration::from_secs(30);
static CACHE: RwLock<Option<(Instant, Arc<Compiled>)>> = RwLock::new(None);
/// Forgets the copy, so the next message reads the rules again.
pub fn invalidate() {
if let Ok(mut cache) = CACHE.write() {
*cache = None;
}
}
/// The enabled rules, compiled. A rule that no longer compiles is left out
/// and reported, once per refresh.
pub async fn compiled(data: &Store) -> trc::Result<Arc<Compiled>> {
if let Ok(cache) = CACHE.read()
&& let Some((at, compiled)) = cache.as_ref()
&& at.elapsed() < TTL
{
return Ok(compiled.clone());
}
let (compiled, skipped) = Compiled::new(&rules::all(data).await?);
for (id, reason) in skipped {
trc::event!(
Store(trc::StoreEvent::DataCorruption),
Id = u64::from(id),
Reason = reason,
Details = "Mail rule skipped: it no longer compiles"
);
}
let compiled = Arc::new(compiled);
if let Ok(mut cache) = CACHE.write() {
*cache = Some((Instant::now(), compiled.clone()));
}
Ok(compiled)
}
@@ -0,0 +1,49 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! African identifiers (§2.3): South Africa's ID number.
use super::{Detector, Findings, Region, Strength, checks, valid_short_date};
use regex::Regex;
use std::sync::LazyLock;
pub static DETECTORS: &[Detector] = &[Detector::new(
"za-id",
"South Africa: ID number",
Region::Africa,
Strength::Checked,
za_id,
)];
/// Birth date `YYMMDD`, four digits, citizenship (0, 1 or 2), 8 or 9, a Luhn
/// check digit. The date and the two fixed digits make it strong enough to
/// count alone.
static ZA_ID: LazyLock<Regex> = LazyLock::new(|| {
Regex::new(r"\b(\d{2})(\d{2})(\d{2})\d{4}[012][89]\d\b").expect("detector pattern")
});
fn za_id(text: &str, findings: &mut Findings) {
for c in ZA_ID.captures_iter(text) {
let n = &c[0];
let num = |s: &str| s.parse::<u32>().unwrap_or(0);
if valid_short_date(num(&c[1]), num(&c[2]), num(&c[3])) && checks::luhn(n) {
findings.insert(n);
}
}
}
#[cfg(test)]
mod tests {
use crate::mailflow::detectors::by_id;
#[test]
fn south_africa() {
let detector = by_id("za-id").unwrap();
assert_eq!(detector.count("ID 8001015009087"), 1);
assert_eq!(detector.count("8001015009088"), 0);
assert_eq!(detector.count("8013015009087"), 0);
}
}
@@ -0,0 +1,172 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Identifiers from the Americas outside the US and Canada (§2.3): Brazil's
//! CPF and CNPJ, and Mexico's CURP.
use super::{Detector, Findings, Region, Strength, digit_values, valid_short_date, word_near};
use regex::Regex;
use std::sync::LazyLock;
pub static DETECTORS: &[Detector] = &[
Detector::new(
"br-cpf",
"Brazil: CPF",
Region::Americas,
Strength::Checked,
br_cpf,
),
Detector::new(
"br-cnpj",
"Brazil: CNPJ",
Region::Americas,
Strength::Checked,
br_cnpj,
),
Detector::new(
"mx-curp",
"Mexico: CURP",
Region::Americas,
Strength::Checked,
mx_curp,
),
];
fn re(pattern: &str) -> Regex {
Regex::new(pattern).expect("detector pattern")
}
/// Brazil's mod 11 check digit over `digits` with `weights`.
fn br_check(digits: &[u32], weights: &[u32]) -> u32 {
match digits.iter().zip(weights).map(|(a, w)| a * w).sum::<u32>() % 11 {
0 | 1 => 0,
r => 11 - r,
}
}
/// `111.444.777-35`, or eleven bare digits.
static CPF: LazyLock<Regex> = LazyLock::new(|| re(r"\b\d{3}(\.?)\d{3}(\.?)\d{3}(-?)\d{2}\b"));
pub fn cpf_valid(n: &str) -> bool {
let d = digit_values(n);
// A run of one digit passes the arithmetic but is never issued
d.len() == 11
&& d.iter().any(|x| *x != d[0])
&& br_check(&d[..9], &[10, 9, 8, 7, 6, 5, 4, 3, 2]) == d[9]
&& br_check(&d[..10], &[11, 10, 9, 8, 7, 6, 5, 4, 3, 2]) == d[10]
}
const CPF_WORDS: &[&str] = &[
"cpf",
"cadastro de pessoas físicas",
"cadastro de pessoa física",
];
fn br_cpf(text: &str, findings: &mut Findings) {
for c in CPF.captures_iter(text) {
let whole = c.get(0).unwrap();
let written = &c[1] == "." && &c[2] == "." && &c[3] == "-";
let n: String = whole
.as_str()
.chars()
.filter(char::is_ascii_digit)
.collect();
if cpf_valid(&n) && (written || word_near(text, whole.start(), whole.end(), CPF_WORDS)) {
findings.insert(n);
}
}
}
/// `11.222.333/0001-81`, or fourteen bare digits.
static CNPJ: LazyLock<Regex> =
LazyLock::new(|| re(r"\b\d{2}(\.?)\d{3}(\.?)\d{3}(/?)\d{4}(-?)\d{2}\b"));
pub fn cnpj_valid(n: &str) -> bool {
let d = digit_values(n);
d.len() == 14
&& d.iter().any(|x| *x != d[0])
&& br_check(&d[..12], &[5, 4, 3, 2, 9, 8, 7, 6, 5, 4, 3, 2]) == d[12]
&& br_check(&d[..13], &[6, 5, 4, 3, 2, 9, 8, 7, 6, 5, 4, 3, 2]) == d[13]
}
const CNPJ_WORDS: &[&str] = &["cnpj", "cadastro nacional da pessoa jurídica"];
fn br_cnpj(text: &str, findings: &mut Findings) {
for c in CNPJ.captures_iter(text) {
let whole = c.get(0).unwrap();
let written = &c[1] == "." && &c[2] == "." && &c[3] == "/" && &c[4] == "-";
let n: String = whole
.as_str()
.chars()
.filter(char::is_ascii_digit)
.collect();
if cnpj_valid(&n) && (written || word_near(text, whole.start(), whole.end(), CNPJ_WORDS)) {
findings.insert(n);
}
}
}
/// Four letters, the birth date, sex (H, M or X), the state, three
/// consonants, a character that tells the century apart, the check digit.
static CURP: LazyLock<Regex> = LazyLock::new(|| {
re(r"(?i)\b[A-Z]{4}(\d{2})(\d{2})(\d{2})[HMX][A-Z]{2}[B-DF-HJ-NP-TV-Z]{3}[A-Z0-9]\d\b")
});
/// RENAPO's check: each character's place in `0-9 A-N Ñ O-Z`, weighted 18
/// down to 2; the digit is 10 minus the sum mod 10 (10 becomes 0).
pub fn curp_valid(curp: &str) -> bool {
const ALPHABET: &str = "0123456789ABCDEFGHIJKLMNÑOPQRSTUVWXYZ";
let mut sum = 0u32;
for (i, c) in curp.chars().take(17).enumerate() {
let Some(value) = ALPHABET.chars().position(|a| a == c) else {
return false;
};
sum += value as u32 * (18 - i as u32);
}
curp.chars().nth(17).and_then(|c| c.to_digit(10)) == Some((10 - sum % 10) % 10)
}
fn mx_curp(text: &str, findings: &mut Findings) {
for c in CURP.captures_iter(text) {
let curp = c[0].to_ascii_uppercase();
if valid_short_date(num(&c[1]), num(&c[2]), num(&c[3])) && curp_valid(&curp) {
findings.insert(curp);
}
}
}
fn num(s: &str) -> u32 {
s.parse().unwrap_or(0)
}
#[cfg(test)]
mod tests {
use crate::mailflow::detectors::by_id;
fn count(id: &str, text: &str) -> usize {
by_id(id).unwrap().count(text)
}
#[test]
fn brazil() {
assert_eq!(count("br-cpf", "CPF 111.444.777-35"), 1);
assert_eq!(count("br-cpf", "111.444.777-36"), 0);
assert_eq!(count("br-cpf", "pedido 11144477735"), 0);
assert_eq!(count("br-cpf", "cpf: 11144477735"), 1);
assert_eq!(count("br-cpf", "CPF 111.111.111-11"), 0);
assert_eq!(count("br-cnpj", "11.222.333/0001-81"), 1);
assert_eq!(count("br-cnpj", "11.222.333/0001-82"), 0);
assert_eq!(count("br-cnpj", "CNPJ 11222333000181"), 1);
}
#[test]
fn mexico() {
// python-stdnum's documented example
assert_eq!(count("mx-curp", "CURP BOXW310820HNERXN09"), 1);
assert_eq!(count("mx-curp", "BOXW310820HNERXN08"), 0);
assert_eq!(count("mx-curp", "BOXW311320HNERXN09"), 0);
}
}
@@ -0,0 +1,511 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Detectors that aren't tied to one country (§2.3, region "Any").
use super::{
Detector, Findings, Region, Strength, checks, digits, stands_alone, valid_date, word_near,
};
use regex::Regex;
use std::sync::LazyLock;
pub static DETECTORS: &[Detector] = &[
Detector::new(
"payment-card",
"Payment card number",
Region::Any,
Strength::Checked,
payment_card,
),
Detector::new("iban", "IBAN", Region::Any, Strength::Checked, iban),
Detector::new(
"swift-bic",
"SWIFT/BIC code",
Region::Any,
Strength::NeedsWord,
swift_bic,
),
Detector::new(
"email-addresses",
"Email addresses",
Region::Any,
Strength::Checked,
email_addresses,
),
Detector::new(
"phone-numbers",
"Phone numbers",
Region::Any,
Strength::NeedsWord,
phone_numbers,
),
Detector::new(
"date-of-birth",
"Date of birth",
Region::Any,
Strength::NeedsWord,
date_of_birth,
),
Detector::new(
"passport",
"Passport number",
Region::Any,
Strength::NeedsWord,
passport,
),
Detector::new(
"private-key",
"Private key",
Region::Any,
Strength::Checked,
private_key,
),
Detector::new(
"credentials",
"Cloud and service credentials",
Region::Any,
Strength::Checked,
credentials,
),
];
fn re(pattern: &str) -> Regex {
Regex::new(pattern).expect("detector pattern")
}
// --- Payment cards --------------------------------------------------------
/// Issuer prefixes (ISO/IEC 7812 IINs) and the lengths each network issues.
fn card_network(number: &str) -> bool {
let len = number.len();
let prefix = |n: usize| number[..n].parse::<u32>().unwrap_or(0);
match number.as_bytes()[0] {
// Visa
b'4' => matches!(len, 13 | 16 | 19),
b'5' => {
// Mastercard 51–55; Maestro 50, 56–58
(51..=55).contains(&prefix(2)) && len == 16
|| matches!(prefix(2), 50 | 56..=58) && (12..=19).contains(&len)
}
// Mastercard 2221–2720
b'2' => (2221..=2720).contains(&prefix(4)) && len == 16,
b'3' => {
// American Express 34, 37; JCB 3528–3589; Diners 300–305, 36, 38, 39
matches!(prefix(2), 34 | 37) && len == 15
|| (3528..=3589).contains(&prefix(4)) && (16..=19).contains(&len)
|| ((300..=305).contains(&prefix(3)) || matches!(prefix(2), 36 | 38 | 39))
&& (14..=19).contains(&len)
}
// Discover 6011, 644–649, 65; UnionPay 62; Maestro 6x
b'6' => (12..=19).contains(&len),
_ => false,
}
}
fn is_card(number: &str) -> bool {
(12..=19).contains(&number.len()) && card_network(number) && checks::luhn(number)
}
static CARD: LazyLock<Regex> = LazyLock::new(|| re(r"\b\d(?:[ -]?\d){11,18}\b"));
fn payment_card(text: &str, findings: &mut Findings) {
for m in CARD.find_iter(text) {
if !stands_alone(text, m.start(), m.end()) {
continue;
}
let whole = digits(m.as_str());
if is_card(&whole) {
findings.insert(whole);
continue;
}
// Two numbers side by side ("4242 4242 4242 4242 2031"): try each
// run of whole groups
let groups: Vec<String> = m.as_str().split([' ', '-']).map(digits).collect();
'runs: for from in 0..groups.len() {
let mut number = String::new();
for group in &groups[from..] {
number.push_str(group);
if is_card(&number) {
findings.insert(number);
break 'runs;
}
}
}
}
}
// --- IBAN -----------------------------------------------------------------
static IBAN: LazyLock<Regex> =
LazyLock::new(|| re(r"\b[A-Za-z]{2}\d{2}(?:[ ]?[A-Za-z0-9]){11,30}"));
fn iban(text: &str, findings: &mut Findings) {
// The pattern can run on into the next words, even the next IBAN: after
// each hit, look again from where that IBAN ended
let mut from = 0;
while let Some(m) = IBAN.find_at(text, from) {
from = m.start() + 1;
let compact = m.as_str().replace(' ', "").to_ascii_uppercase();
let Some(len) = checks::iban_length(&compact[..2]) else {
continue;
};
if compact.len() < len {
continue;
}
// Where the country's length ends in the text, spaces counted
let mut seen = 0;
let Some(end) = m
.as_str()
.char_indices()
.find(|(_, c)| {
if *c != ' ' {
seen += 1;
}
seen == len
})
.map(|(i, c)| m.start() + i + c.len_utf8())
else {
continue;
};
let candidate = &compact[..len];
if stands_alone(text, m.start(), end) && checks::iban(candidate) {
findings.insert(candidate);
from = end;
}
}
}
// --- SWIFT/BIC ------------------------------------------------------------
static BIC: LazyLock<Regex> =
LazyLock::new(|| re(r"\b[A-Z]{4}[A-Z]{2}[A-Z0-9]{2}(?:[A-Z0-9]{3})?\b"));
const BIC_WORDS: &[&str] = &[
"swift",
"bic",
"swift/bic",
"bank",
"banque",
"bankverbindung",
];
fn swift_bic(text: &str, findings: &mut Findings) {
for m in BIC.find_iter(text) {
let code = m.as_str();
if checks::is_country(&code[4..6]) && word_near(text, m.start(), m.end(), BIC_WORDS) {
findings.insert(code);
}
}
}
// --- Contact lists --------------------------------------------------------
static EMAIL: LazyLock<Regex> =
LazyLock::new(|| re(r"(?i)\b[a-z0-9._%+-]+@[a-z0-9-]+(?:\.[a-z0-9-]+)*\.[a-z]{2,}\b"));
fn email_addresses(text: &str, findings: &mut Findings) {
for m in EMAIL.find_iter(text) {
findings.insert(m.as_str().to_lowercase());
}
}
/// International form: found alone. National form: only with a word.
static PHONE_INTL: LazyLock<Regex> = LazyLock::new(|| re(r"\+\d{1,3}(?:[ .-]?\(?\d{1,4}\)?){2,5}"));
static PHONE_NATIONAL: LazyLock<Regex> =
LazyLock::new(|| re(r"\(?\d{2,4}\)?[ .-]\d{3,4}[ .-]\d{3,4}"));
const PHONE_WORDS: &[&str] = &[
"phone",
"tel",
"telephone",
"mobile",
"cell",
"fax",
"telefon",
"téléphone",
"teléfono",
"telefono",
"handy",
"portable",
"móvil",
"cellulare",
"mobiel",
];
fn phone_numbers(text: &str, findings: &mut Findings) {
let mut international = Vec::new();
for m in PHONE_INTL.find_iter(text) {
let number = digits(m.as_str());
if (8..=15).contains(&number.len()) && stands_alone(text, m.start() + 1, m.end()) {
findings.insert(number);
international.push(m.range());
}
}
for m in PHONE_NATIONAL.find_iter(text) {
let number = digits(m.as_str());
// Not the tail of an international number already counted
if international.iter().any(|r| r.contains(&m.start())) {
continue;
}
if (9..=11).contains(&number.len())
&& stands_alone(text, m.start(), m.end())
&& !text[..m.start()].ends_with('+')
&& word_near(text, m.start(), m.end(), PHONE_WORDS)
{
findings.insert(number);
}
}
}
// --- Date of birth --------------------------------------------------------
static DATE_ISO: LazyLock<Regex> = LazyLock::new(|| re(r"\b(\d{4})-(\d{2})-(\d{2})\b"));
static DATE_NUMERIC: LazyLock<Regex> =
LazyLock::new(|| re(r"\b(\d{1,2})[./-](\d{1,2})[./-](\d{4})\b"));
static DATE_WORDS: LazyLock<Regex> = LazyLock::new(|| {
re(
r"(?i)\b(?:(\d{1,2})\s+(jan|feb|mar|apr|may|jun|jul|aug|sep|oct|nov|dec)[a-z]*\.?,?\s+(\d{4})|(jan|feb|mar|apr|may|jun|jul|aug|sep|oct|nov|dec)[a-z]*\.?\s+(\d{1,2}),?\s+(\d{4}))\b",
)
});
const BIRTH_WORDS: &[&str] = &[
"born",
"birth",
"dob",
"d.o.b",
"birthday",
"birthdate",
"geburtsdatum",
"geboren",
"naissance",
"né le",
"née le",
"nacimiento",
"nacido",
"nacida",
"nascita",
"nato il",
"nata il",
"geboortedatum",
"födelsedatum",
"fødselsdato",
"syntymäaika",
"urodzenia",
"nascimento",
];
fn month_number(name: &str) -> u32 {
const MONTHS: [&str; 12] = [
"jan", "feb", "mar", "apr", "may", "jun", "jul", "aug", "sep", "oct", "nov", "dec",
];
let name = name.to_lowercase();
MONTHS
.iter()
.position(|m| *m == name)
.map_or(0, |i| i as u32 + 1)
}
fn date_of_birth(text: &str, findings: &mut Findings) {
let mut add = |start: usize, end: usize, key: String| {
if word_near(text, start, end, BIRTH_WORDS) {
findings.insert(key);
}
};
let num = |s: &str| s.parse::<u32>().unwrap_or(0);
for c in DATE_ISO.captures_iter(text) {
let (y, m, d) = (num(&c[1]), num(&c[2]), num(&c[3]));
let whole = c.get(0).unwrap();
if valid_date(y, m, d) {
add(whole.start(), whole.end(), format!("{y:04}{m:02}{d:02}"));
}
}
for c in DATE_NUMERIC.captures_iter(text) {
let (a, b, y) = (num(&c[1]), num(&c[2]), num(&c[3]));
let whole = c.get(0).unwrap();
// Day first or month first: either reading that is a real date
if valid_date(y, b, a) || valid_date(y, a, b) {
add(whole.start(), whole.end(), whole.as_str().to_string());
}
}
for c in DATE_WORDS.captures_iter(text) {
let whole = c.get(0).unwrap();
let (d, m, y) = match (c.get(1), c.get(4)) {
(Some(d), _) => (num(d.as_str()), month_number(&c[2]), num(&c[3])),
(_, Some(m)) => (num(&c[5]), month_number(m.as_str()), num(&c[6])),
_ => continue,
};
if valid_date(y, m, d) {
add(whole.start(), whole.end(), format!("{y:04}{m:02}{d:02}"));
}
}
}
// --- Passport -------------------------------------------------------------
static PASSPORT: LazyLock<Regex> = LazyLock::new(|| re(r"\b[A-Z0-9]{6,9}\b"));
const PASSPORT_WORDS: &[&str] = &[
"passport",
"passeport",
"reisepass",
"pasaporte",
"passaporto",
"paspoort",
"passnummer",
"pass-nr",
"passport no",
"pasaporte n.º",
"passaporte",
];
fn passport(text: &str, findings: &mut Findings) {
for m in PASSPORT.find_iter(text) {
let value = m.as_str();
if value.bytes().filter(u8::is_ascii_digit).count() >= 5
&& word_near(text, m.start(), m.end(), PASSPORT_WORDS)
{
findings.insert(value);
}
}
}
// --- Keys and credentials -------------------------------------------------
static PRIVATE_KEY: LazyLock<Regex> = LazyLock::new(|| {
re(
r"-----BEGIN (?:(?:RSA|EC|DSA|OPENSSH|ENCRYPTED|PGP) )?PRIVATE KEY(?: BLOCK)?-----\s*([A-Za-z0-9+/=:\s-]{0,64})",
)
});
fn private_key(text: &str, findings: &mut Findings) {
for c in PRIVATE_KEY.captures_iter(text) {
// Each key once, by the start of its body
let body: String = c[1].chars().filter(|c| !c.is_whitespace()).collect();
let whole = c.get(0).unwrap();
findings.insert(if body.is_empty() {
format!("@{}", whole.start())
} else {
body
});
}
}
/// Published token formats: AWS access key IDs, GitHub tokens, Slack
/// tokens, Stripe live secret and restricted keys, Google API keys.
static CREDENTIAL: LazyLock<Regex> = LazyLock::new(|| {
re(concat!(
r"\b(?:",
r"(?:AKIA|ASIA|ABIA|ACCA)[A-Z0-9]{16}",
r"|gh[pousr]_[A-Za-z0-9]{36}",
r"|github_pat_[A-Za-z0-9_]{82}",
r"|xox[abposr]-[A-Za-z0-9-]{10,72}",
r"|(?:sk|rk)_live_[A-Za-z0-9]{24,99}",
r"|AIza[0-9A-Za-z_-]{35}",
r")\b"
))
});
fn credentials(text: &str, findings: &mut Findings) {
for m in CREDENTIAL.find_iter(text) {
findings.insert(m.as_str());
}
}
#[cfg(test)]
mod tests {
use crate::mailflow::detectors::by_id;
fn count(id: &str, text: &str) -> usize {
by_id(id).unwrap().count(text)
}
#[test]
fn payment_cards() {
// Networks' and processors' published test numbers
let text = "Visa 4242 4242 4242 4242, MC 5555-5555-5555-4444, Amex 378282246310005, \
Discover 6011111111111117, JCB 3566002020360505, Diners 30569309025904, \
UnionPay 6200000000000005, Mastercard 2-series 2223003122003222";
assert_eq!(count("payment-card", text), 8);
// Luhn fails, wrong network length, inside a longer number
assert_eq!(count("payment-card", "4242424242424241"), 0);
assert_eq!(count("payment-card", "378282246310005 0"), 1);
assert_eq!(count("payment-card", "order 94242424242424242 shipped"), 0);
// The same number twice counts once
assert_eq!(
count("payment-card", "4242424242424242 and 4242-4242-4242-4242"),
1
);
// A card followed by a year
assert_eq!(count("payment-card", "card 4242 4242 4242 4242 2031"), 1);
}
#[test]
fn ibans() {
let text =
"Pay GB29 NWBK 6016 1331 9268 19 or de89370400440532013000 (NL91ABNA0417164300).";
assert_eq!(count("iban", text), 3);
assert_eq!(count("iban", "GB29 NWBK 6016 1331 9268 18"), 0);
// Runs into the next word: still found at the country's length
assert_eq!(count("iban", "IBAN NL91ABNA0417164300 BIC ABNANL2A"), 1);
}
#[test]
fn swift_codes_need_a_word() {
assert_eq!(count("swift-bic", "SWIFT: DEUTDEFF500"), 1);
assert_eq!(count("swift-bic", "BIC NWBKGB2L"), 1);
assert_eq!(count("swift-bic", "HAPPYDAYS DEUTDEFF"), 0);
// Not a country in positions 5–6
assert_eq!(count("swift-bic", "BIC DEUTZZFF"), 0);
}
#[test]
fn email_and_phone_lists() {
let list = "[email protected], [email protected], [email protected], [email protected]";
assert_eq!(count("email-addresses", list), 3);
assert_eq!(
count("phone-numbers", "+44 20 7946 0958, +1 (415) 555-2671"),
2
);
assert_eq!(count("phone-numbers", "call 020 7946 0958"), 0);
assert_eq!(count("phone-numbers", "Tel: 020 7946 0958"), 1);
assert_eq!(count("phone-numbers", "invoice 020 7946 0958"), 0);
// One number, not also its national tail
assert_eq!(count("phone-numbers", "Tel: +44 20 7946 0958"), 1);
}
#[test]
fn dates_of_birth() {
assert_eq!(count("date-of-birth", "DOB: 1984-02-29"), 1);
assert_eq!(count("date-of-birth", "Geburtsdatum 31.12.1970"), 1);
assert_eq!(count("date-of-birth", "born on March 3, 1962"), 1);
assert_eq!(count("date-of-birth", "date of birth 3 Mar 1962"), 1);
// Not a real date, no word, a meeting
assert_eq!(count("date-of-birth", "DOB: 1985-02-29"), 0);
assert_eq!(count("date-of-birth", "invoice 1984-02-29"), 0);
assert_eq!(count("date-of-birth", "Meeting on 12/05/2026"), 0);
}
#[test]
fn passports_need_a_word() {
assert_eq!(count("passport", "Passport number: 533380006"), 1);
assert_eq!(count("passport", "Reisepass C01X00T47"), 1);
assert_eq!(count("passport", "Order 533380006 shipped"), 0);
// Mostly letters: a word, not a number
assert_eq!(count("passport", "passport PASSWORD"), 0);
}
#[test]
fn keys_and_credentials() {
let key = "-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQ\n-----END OPENSSH PRIVATE KEY-----";
assert_eq!(count("private-key", key), 1);
assert_eq!(count("private-key", "-----BEGIN PUBLIC KEY-----\nMFkw"), 0);
// Documentation examples of each format
let tokens = "AKIAIOSFODNN7EXAMPLE ghp_0123456789abcdefghijklmnopqrstuvwxyz \
AIzaSyA-0123456789abcdefghijklmnopqrstu";
assert_eq!(count("credentials", tokens), 3);
assert_eq!(count("credentials", "AKIA123 ghp_short"), 0);
}
}
@@ -0,0 +1,281 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Asian identifiers (§2.3): India's Aadhaar and PAN, China's resident ID,
//! Japan's My Number, Singapore's NRIC and FIN, and South Korea's resident
//! registration number.
use super::{
Detector, Findings, Region, Strength, digit_values, valid_date, valid_short_date, word_near,
};
use regex::Regex;
use std::sync::LazyLock;
pub static DETECTORS: &[Detector] = &[
Detector::new(
"in-aadhaar",
"India: Aadhaar",
Region::Asia,
Strength::Checked,
in_aadhaar,
),
Detector::new(
"in-pan",
"India: PAN",
Region::Asia,
Strength::NeedsWord,
in_pan,
),
Detector::new(
"cn-resident-id",
"China: resident ID",
Region::Asia,
Strength::Checked,
cn_resident_id,
),
Detector::new(
"jp-my-number",
"Japan: My Number",
Region::Asia,
Strength::Checked,
jp_my_number,
),
Detector::new(
"sg-nric",
"Singapore: NRIC and FIN",
Region::Asia,
Strength::Checked,
sg_nric,
),
Detector::new(
"kr-rrn",
"South Korea: resident registration number",
Region::Asia,
Strength::NeedsWord,
kr_rrn,
),
];
fn re(pattern: &str) -> Regex {
Regex::new(pattern).expect("detector pattern")
}
/// Twelve digits written in fours, or bare.
static TWELVE: LazyLock<Regex> = LazyLock::new(|| re(r"\b(\d{4})( ?)(\d{4})( ?)(\d{4})\b"));
const VERHOEFF_D: [[u8; 10]; 10] = [
[0, 1, 2, 3, 4, 5, 6, 7, 8, 9],
[1, 2, 3, 4, 0, 6, 7, 8, 9, 5],
[2, 3, 4, 0, 1, 7, 8, 9, 5, 6],
[3, 4, 0, 1, 2, 8, 9, 5, 6, 7],
[4, 0, 1, 2, 3, 9, 5, 6, 7, 8],
[5, 9, 8, 7, 6, 0, 4, 3, 2, 1],
[6, 5, 9, 8, 7, 1, 0, 4, 3, 2],
[7, 6, 5, 9, 8, 2, 1, 0, 4, 3],
[8, 7, 6, 5, 9, 3, 2, 1, 0, 4],
[9, 8, 7, 6, 5, 4, 3, 2, 1, 0],
];
const VERHOEFF_P: [[u8; 10]; 8] = [
[0, 1, 2, 3, 4, 5, 6, 7, 8, 9],
[1, 5, 7, 6, 2, 8, 3, 0, 9, 4],
[5, 8, 0, 3, 7, 9, 6, 1, 4, 2],
[8, 9, 1, 6, 0, 4, 3, 5, 2, 7],
[9, 4, 5, 3, 1, 2, 6, 8, 7, 0],
[4, 2, 8, 6, 5, 7, 3, 9, 0, 1],
[2, 7, 9, 3, 8, 0, 6, 4, 1, 5],
[7, 0, 4, 6, 9, 1, 3, 2, 5, 8],
];
/// The Verhoeff check (dihedral group D5).
pub fn verhoeff(n: &str) -> bool {
let mut c = 0u8;
for (i, b) in n.bytes().rev().enumerate() {
c = VERHOEFF_D[c as usize][VERHOEFF_P[i % 8][(b - b'0') as usize] as usize];
}
c == 0
}
const AADHAAR_WORDS: &[&str] = &["aadhaar", "aadhar", "uidai", "uid"];
fn in_aadhaar(text: &str, findings: &mut Findings) {
for c in TWELVE.captures_iter(text) {
let whole = c.get(0).unwrap();
let n = format!("{}{}{}", &c[1], &c[3], &c[5]);
let written = &c[2] == " " && &c[4] == " ";
// Never starts with 0 or 1
if !n.starts_with(['0', '1'])
&& verhoeff(&n)
&& (written || word_near(text, whole.start(), whole.end(), AADHAAR_WORDS))
{
findings.insert(n);
}
}
}
/// Five letters (the fourth names the holder's type), four digits, a letter.
static PAN: LazyLock<Regex> = LazyLock::new(|| re(r"\b[A-Z]{3}[ABCFGHLJPTK][A-Z]\d{4}[A-Z]\b"));
const PAN_WORDS: &[&str] = &["pan", "pan card", "permanent account number", "income tax"];
fn in_pan(text: &str, findings: &mut Findings) {
for m in PAN.find_iter(text) {
if word_near(text, m.start(), m.end(), PAN_WORDS) {
findings.insert(m.as_str());
}
}
}
/// Region, birth date `YYYYMMDD`, sequence, then the ISO 7064 MOD 11-2
/// check (0–9 or X).
static CN_ID: LazyLock<Regex> =
LazyLock::new(|| re(r"(?i)\b[1-8]\d{5}(\d{4})(\d{2})(\d{2})\d{3}[\dX]\b"));
pub fn cn_id_valid(id: &str) -> bool {
const WEIGHTS: [u32; 17] = [7, 9, 10, 5, 8, 4, 2, 1, 6, 3, 7, 9, 10, 5, 8, 4, 2];
const CHECKS: &[u8] = b"10X98765432";
let sum: u32 = digit_values(&id[..17])
.iter()
.zip(WEIGHTS)
.map(|(a, w)| a * w)
.sum();
CHECKS[(sum % 11) as usize] == id.as_bytes()[17].to_ascii_uppercase()
}
fn cn_resident_id(text: &str, findings: &mut Findings) {
for c in CN_ID.captures_iter(text) {
let id = c[0].to_ascii_uppercase();
let (y, m, d) = (num(&c[1]), num(&c[2]), num(&c[3]));
if valid_date(y, m, d) && cn_id_valid(&id) {
findings.insert(id);
}
}
}
/// My Number: weights 2–7 then 2–6 from the right; a remainder of 0 or 1
/// gives 0, else 11 minus it.
pub fn my_number_valid(n: &str) -> bool {
let d = digit_values(n);
let sum: u32 = (1..=11)
.map(|i| d[11 - i] * if i <= 6 { i as u32 + 1 } else { i as u32 - 5 })
.sum();
let check = match sum % 11 {
0 | 1 => 0,
r => 11 - r,
};
check == d[11]
}
const MY_NUMBER_WORDS: &[&str] = &[
"my number",
"mynumber",
"マイナンバー",
"個人番号",
"kojin bango",
];
fn jp_my_number(text: &str, findings: &mut Findings) {
for c in TWELVE.captures_iter(text) {
let whole = c.get(0).unwrap();
let n = format!("{}{}{}", &c[1], &c[3], &c[5]);
let written = &c[2] == " " && &c[4] == " ";
if my_number_valid(&n)
&& (written || word_near(text, whole.start(), whole.end(), MY_NUMBER_WORDS))
{
findings.insert(n);
}
}
}
static NRIC: LazyLock<Regex> = LazyLock::new(|| re(r"(?i)\b([STFGM])(\d{7})([A-Z])\b"));
/// Weights 2, 7, 6, 5, 4, 3, 2; T and G add 4, M adds 3; each series has its
/// own table of check letters.
fn nric_valid(prefix: u8, digits: &str, check: u8) -> bool {
let sum: u32 = digit_values(digits)
.iter()
.zip([2, 7, 6, 5, 4, 3, 2])
.map(|(a, w)| a * w)
.sum::<u32>()
+ match prefix {
b'T' | b'G' => 4,
b'M' => 3,
_ => 0,
};
let table: &[u8] = match prefix {
b'S' | b'T' => b"JZIHGFEDCBA",
b'F' | b'G' => b"XWUTRQPNMLK",
_ => b"KLJNPQRTUWX",
};
table[(sum % 11) as usize] == check
}
fn sg_nric(text: &str, findings: &mut Findings) {
for c in NRIC.captures_iter(text) {
let id = c[0].to_ascii_uppercase();
let bytes = id.as_bytes();
if nric_valid(bytes[0], &c[2], bytes[8]) {
findings.insert(id);
}
}
}
/// `YYMMDD-GNNNNNN`, the seventh digit giving sex and century.
static RRN: LazyLock<Regex> = LazyLock::new(|| re(r"\b(\d{2})(\d{2})(\d{2})-?([1-8])\d{6}\b"));
const RRN_WORDS: &[&str] = &["주민등록번호", "주민번호", "resident registration", "rrn"];
fn kr_rrn(text: &str, findings: &mut Findings) {
for c in RRN.captures_iter(text) {
let whole = c.get(0).unwrap();
if valid_short_date(num(&c[1]), num(&c[2]), num(&c[3]))
&& word_near(text, whole.start(), whole.end(), RRN_WORDS)
{
findings.insert(whole.as_str().replace('-', ""));
}
}
}
fn num(s: &str) -> u32 {
s.parse().unwrap_or(0)
}
#[cfg(test)]
mod tests {
use crate::mailflow::detectors::by_id;
fn count(id: &str, text: &str) -> usize {
by_id(id).unwrap().count(text)
}
#[test]
fn india() {
assert_eq!(count("in-aadhaar", "2345 6789 0124"), 1);
assert_eq!(count("in-aadhaar", "2345 6789 0125"), 0);
assert_eq!(count("in-aadhaar", "order 234567890124"), 0);
assert_eq!(count("in-aadhaar", "Aadhaar 234567890124"), 1);
assert_eq!(count("in-pan", "PAN: ABCPE1234F"), 1);
assert_eq!(count("in-pan", "ABCPE1234F"), 0);
}
#[test]
fn china_japan() {
assert_eq!(count("cn-resident-id", "11010519491231002X"), 1);
assert_eq!(count("cn-resident-id", "110105194912310021"), 0);
assert_eq!(count("cn-resident-id", "11010519491331002X"), 0);
assert_eq!(count("jp-my-number", "1234 5678 9018"), 1);
assert_eq!(count("jp-my-number", "1234 5678 9017"), 0);
assert_eq!(count("jp-my-number", "マイナンバー 123456789018"), 1);
}
#[test]
fn singapore_korea() {
assert_eq!(count("sg-nric", "S1234567D and T1234567J"), 2);
assert_eq!(count("sg-nric", "S1234567E"), 0);
assert_eq!(count("kr-rrn", "주민등록번호 800101-1234567"), 1);
assert_eq!(count("kr-rrn", "800101-1234567"), 0);
assert_eq!(count("kr-rrn", "RRN 801301-1234567"), 0);
}
}
@@ -0,0 +1,128 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Australian identifiers (§2.3): the ATO's Tax File Number and the Medicare
//! card number.
use super::{Detector, Findings, Region, Strength, word_near};
use regex::Regex;
use std::sync::LazyLock;
pub static DETECTORS: &[Detector] = &[
Detector::new(
"au-tfn",
"Australian Tax File Number",
Region::Australia,
Strength::Checked,
tfn,
),
Detector::new(
"au-medicare",
"Australian Medicare number",
Region::Australia,
Strength::Checked,
medicare,
),
];
fn re(pattern: &str) -> Regex {
Regex::new(pattern).expect("detector pattern")
}
/// `NNN NNN NNN` stands alone; bare digits (eight or nine) need a word.
static TFN: LazyLock<Regex> = LazyLock::new(|| re(r"\b(\d{3})( ?)(\d{3})( ?)(\d{2,3})\b"));
/// Weighted sum mod 11, with the ATO's weights for 9- and 8-digit numbers.
pub fn tfn_valid(n: &str) -> bool {
let weights: &[u32] = match n.len() {
9 => &[1, 4, 3, 7, 5, 8, 6, 9, 10],
8 => &[10, 7, 8, 4, 6, 3, 5, 1],
_ => return false,
};
n.bytes()
.zip(weights)
.map(|(b, w)| u32::from(b - b'0') * w)
.sum::<u32>()
% 11
== 0
}
const TFN_WORDS: &[&str] = &["tfn", "tax file number", "tax file no"];
fn tfn(text: &str, findings: &mut Findings) {
for c in TFN.captures_iter(text) {
let whole = c.get(0).unwrap();
let n = format!("{}{}{}", &c[1], &c[3], &c[5]);
let written = n.len() == 9 && c[2] == *" " && c[4] == *" ";
if tfn_valid(&n) && (written || word_near(text, whole.start(), whole.end(), TFN_WORDS)) {
findings.insert(n);
}
}
}
/// `NNNN NNNNN N` (and an optional issue number) stands alone; bare digits
/// need a word.
static MEDICARE: LazyLock<Regex> =
LazyLock::new(|| re(r"\b([2-6]\d{3})( ?)(\d{5})( ?)(\d)(?:[ -]?\d)?\b"));
/// The ninth digit is the weighted sum (1, 3, 7, 9, 1, 3, 7, 9) of the first
/// eight, mod 10.
pub fn medicare_valid(n: &str) -> bool {
let d: Vec<u32> = n.bytes().map(|b| u32::from(b - b'0')).collect();
d.len() >= 9
&& d[..8]
.iter()
.zip([1, 3, 7, 9, 1, 3, 7, 9])
.map(|(a, w)| a * w)
.sum::<u32>()
% 10
== d[8]
}
const MEDICARE_WORDS: &[&str] = &[
"medicare",
"medicare card",
"medicare no",
"medicare number",
];
fn medicare(text: &str, findings: &mut Findings) {
for c in MEDICARE.captures_iter(text) {
let whole = c.get(0).unwrap();
let n = format!("{}{}{}", &c[1], &c[3], &c[5]);
let written = c[2] == *" " && c[4] == *" ";
if medicare_valid(&n)
&& (written || word_near(text, whole.start(), whole.end(), MEDICARE_WORDS))
{
findings.insert(n);
}
}
}
#[cfg(test)]
mod tests {
use crate::mailflow::detectors::by_id;
fn count(id: &str, text: &str) -> usize {
by_id(id).unwrap().count(text)
}
#[test]
fn tax_file_numbers() {
assert_eq!(count("au-tfn", "TFN 123 456 782"), 1);
assert_eq!(count("au-tfn", "123 456 789"), 0);
assert_eq!(count("au-tfn", "order 123456782"), 0);
assert_eq!(count("au-tfn", "tax file number 123456782"), 1);
}
#[test]
fn medicare_numbers() {
assert_eq!(count("au-medicare", "2123 45670 1"), 1);
assert_eq!(count("au-medicare", "2123 45671 1"), 0);
assert_eq!(count("au-medicare", "ref 2123456701"), 0);
assert_eq!(count("au-medicare", "Medicare 2123456701"), 1);
}
}
@@ -0,0 +1,66 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Canadian identifiers (§2.3): the Social Insurance Number.
use super::{Detector, Findings, Region, Strength, checks, word_near};
use regex::Regex;
use std::sync::LazyLock;
pub static DETECTORS: &[Detector] = &[Detector::new(
"ca-sin",
"Canadian Social Insurance Number",
Region::Canada,
Strength::Checked,
sin,
)];
/// `NNN NNN NNN` or `NNN-NNN-NNN` stands alone; nine bare digits need a word.
static SIN: LazyLock<Regex> = LazyLock::new(|| {
Regex::new(r"\b(\d{3})([ -]?)(\d{3})([ -]?)(\d{3})\b").expect("detector pattern")
});
const SIN_WORDS: &[&str] = &[
"sin",
"social insurance",
"nas",
"numéro d'assurance sociale",
"assurance sociale",
];
fn sin(text: &str, findings: &mut Findings) {
for c in SIN.captures_iter(text) {
let whole = c.get(0).unwrap();
let n = format!("{}{}{}", &c[1], &c[3], &c[5]);
let written = !c[2].is_empty() && c[2] == c[4];
// 0 and 8 are never issued as a first digit
if !n.starts_with(['0', '8'])
&& checks::luhn(&n)
&& (written || word_near(text, whole.start(), whole.end(), SIN_WORDS))
{
findings.insert(n);
}
}
}
#[cfg(test)]
mod tests {
use crate::mailflow::detectors::by_id;
fn count(text: &str) -> usize {
by_id("ca-sin").unwrap().count(text)
}
#[test]
fn social_insurance_numbers() {
assert_eq!(count("130 692 544 and 193-456-787"), 2);
assert_eq!(count("130 692 545"), 0);
// The government's printed example starts with 0, never issued
assert_eq!(count("046 454 286"), 0);
assert_eq!(count("order 130692544"), 0);
assert_eq!(count("SIN: 130692544"), 1);
}
}
@@ -0,0 +1,227 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Check-digit algorithms, each from its public definition.
/// The Luhn check (ISO/IEC 7812-1, Annex B) over a string of ASCII digits.
pub fn luhn(digits: &str) -> bool {
if digits.len() < 2 || !digits.bytes().all(|b| b.is_ascii_digit()) {
return false;
}
let sum: u32 = digits
.bytes()
.rev()
.enumerate()
.map(|(i, b)| {
let d = u32::from(b - b'0');
if i % 2 == 1 {
let d = d * 2;
if d > 9 { d - 9 } else { d }
} else {
d
}
})
.sum();
sum.is_multiple_of(10)
}
/// ISO 13616 IBAN lengths, by country, from the IBAN registry.
const IBAN_LENGTHS: &[(&str, usize)] = &[
("AD", 24),
("AE", 23),
("AL", 28),
("AT", 20),
("AZ", 28),
("BA", 20),
("BE", 16),
("BG", 22),
("BH", 22),
("BI", 27),
("BR", 29),
("BY", 28),
("CH", 21),
("CR", 22),
("CY", 28),
("CZ", 24),
("DE", 22),
("DJ", 27),
("DK", 18),
("DO", 28),
("EE", 20),
("EG", 29),
("ES", 24),
("FI", 18),
("FK", 18),
("FO", 18),
("FR", 27),
("GB", 22),
("GE", 22),
("GI", 23),
("GL", 18),
("GR", 27),
("GT", 28),
("HN", 28),
("HR", 21),
("HU", 28),
("IE", 22),
("IL", 23),
("IQ", 23),
("IS", 26),
("IT", 27),
("JO", 30),
("KW", 30),
("KZ", 20),
("LB", 28),
("LC", 32),
("LI", 21),
("LT", 20),
("LU", 20),
("LV", 21),
("LY", 25),
("MC", 27),
("MD", 24),
("ME", 22),
("MK", 19),
("MN", 20),
("MR", 27),
("MT", 31),
("MU", 30),
("NI", 28),
("NL", 18),
("NO", 15),
("OM", 23),
("PK", 24),
("PL", 28),
("PS", 29),
("PT", 25),
("QA", 29),
("RO", 24),
("RS", 22),
("RU", 33),
("SA", 24),
("SC", 31),
("SD", 18),
("SE", 24),
("SI", 19),
("SK", 24),
("SM", 27),
("SO", 23),
("ST", 25),
("SV", 28),
("TL", 23),
("TN", 24),
("TR", 26),
("UA", 29),
("VA", 22),
("VG", 24),
("XK", 20),
("YE", 30),
];
/// The IBAN length for a country code, if the country uses IBANs.
pub fn iban_length(country: &str) -> Option<usize> {
IBAN_LENGTHS
.iter()
.find(|(code, _)| *code == country)
.map(|(_, len)| *len)
}
/// ISO 13616 / ISO 7064 MOD 97-10 over an IBAN with no spaces, upper case:
/// move the first four characters to the end, turn letters into 10–35, and
/// the number mod 97 must be 1. Also checks the country's length.
pub fn iban(iban: &str) -> bool {
if iban.len() < 5
|| !iban
.bytes()
.all(|b| b.is_ascii_uppercase() || b.is_ascii_digit())
{
return false;
}
if iban_length(&iban[..2]) != Some(iban.len())
|| !iban[2..4].bytes().all(|b| b.is_ascii_digit())
{
return false;
}
let mut remainder: u32 = 0;
for b in iban[4..].bytes().chain(iban[..4].bytes()) {
let value = if b.is_ascii_digit() {
u32::from(b - b'0')
} else {
u32::from(b - b'A') + 10
};
remainder = if value >= 10 {
(remainder * 100 + value) % 97
} else {
(remainder * 10 + value) % 97
};
}
remainder == 1
}
/// ISO 3166-1 alpha-2 country codes, for SWIFT/BIC positions 5–6.
const COUNTRIES: &str = "AD AE AF AG AI AL AM AO AQ AR AS AT AU AW AX AZ BA BB BD BE BF BG BH BI BJ \
BL BM BN BO BQ BR BS BT BV BW BY BZ CA CC CD CF CG CH CI CK CL CM CN CO CR CU CV CW CX CY CZ DE DJ \
DK DM DO DZ EC EE EG EH ER ES ET FI FJ FK FM FO FR GA GB GD GE GF GG GH GI GL GM GN GP GQ GR GS GT \
GU GW GY HK HM HN HR HT HU ID IE IL IM IN IO IQ IR IS IT JE JM JO JP KE KG KH KI KM KN KP KR KW KY \
KZ LA LB LC LI LK LR LS LT LU LV LY MA MC MD ME MF MG MH MK ML MM MN MO MP MQ MR MS MT MU MV MW MX \
MY MZ NA NC NE NF NG NI NL NO NP NR NU NZ OM PA PE PF PG PH PK PL PM PN PR PS PT PW PY QA RE RO RS \
RU RW SA SB SC SD SE SG SH SI SJ SK SL SM SN SO SR SS ST SV SX SY SZ TC TD TF TG TH TJ TK TL TM TN \
TO TR TT TV TW TZ UA UG UM US UY UZ VA VC VE VG VI VN VU WF WS XK YE YT ZA ZM ZW";
pub fn is_country(code: &str) -> bool {
code.len() == 2 && COUNTRIES.split(' ').any(|c| c == code)
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn luhn_known_numbers() {
// Published test card numbers
for good in [
"4242424242424242",
"5555555555554444",
"378282246310005",
"79927398713",
] {
assert!(luhn(good), "{good}");
}
for bad in ["4242424242424241", "79927398710", "1", "12a4"] {
assert!(!luhn(bad), "{bad}");
}
}
#[test]
fn iban_registry_examples() {
// The IBAN registry's own examples
for good in [
"GB29NWBK60161331926819",
"DE89370400440532013000",
"FR1420041010050500013M02606",
"NL91ABNA0417164300",
"BE68539007547034",
"NO9386011117947",
"CH9300762011623852957",
] {
assert!(iban(good), "{good}");
}
for bad in [
"GB29NWBK60161331926818", // check fails
"GB29NWBK6016133192681", // too short for GB
"ZZ29NWBK60161331926819", // no such country
"DE8937040044053201300A", // letters where DE has none still fail mod 97
] {
assert!(!iban(bad), "{bad}");
}
}
#[test]
fn countries() {
assert!(is_country("DE") && is_country("US") && is_country("XK"));
assert!(!is_country("ZZ") && !is_country("D"));
}
}
@@ -0,0 +1,646 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! European Union national identifiers (§2.3), each from its issuer's
//! published rules. An identifier that is only digits and whose check a
//! random number passes often (mod 10, mod 11) counts alone only in its
//! written form, and as bare digits only beside a word.
use super::{
Detector, Findings, Region, Strength, checks, digit_values, stands_alone, valid_short_date,
word_near,
};
use regex::Regex;
use std::sync::LazyLock;
pub static DETECTORS: &[Detector] = &[
Detector::new(
"de-tax-id",
"Germany: tax ID (Steuer-ID)",
Region::Eu,
Strength::Checked,
de_tax_id,
),
Detector::new(
"de-id-card",
"Germany: ID card number",
Region::Eu,
Strength::Checked,
de_id_card,
),
Detector::new(
"fr-nir",
"France: social security number (NIR)",
Region::Eu,
Strength::Checked,
fr_nir,
),
Detector::new(
"es-dni-nie",
"Spain: DNI and NIE",
Region::Eu,
Strength::Checked,
es_dni_nie,
),
Detector::new(
"it-codice-fiscale",
"Italy: codice fiscale",
Region::Eu,
Strength::Checked,
it_codice_fiscale,
),
Detector::new(
"nl-bsn",
"Netherlands: BSN",
Region::Eu,
Strength::Checked,
nl_bsn,
),
Detector::new(
"be-national-number",
"Belgium: national number",
Region::Eu,
Strength::Checked,
be_national_number,
),
Detector::new(
"pl-pesel",
"Poland: PESEL",
Region::Eu,
Strength::Checked,
pl_pesel,
),
Detector::new(
"se-personnummer",
"Sweden: personnummer",
Region::Eu,
Strength::Checked,
se_personnummer,
),
Detector::new(
"dk-cpr",
"Denmark: CPR number",
Region::Eu,
Strength::NeedsWord,
dk_cpr,
),
Detector::new(
"fi-hetu",
"Finland: personal identity code",
Region::Eu,
Strength::Checked,
fi_hetu,
),
Detector::new(
"ie-pps",
"Ireland: PPS number",
Region::Eu,
Strength::Checked,
ie_pps,
),
Detector::new(
"pt-nif",
"Portugal: NIF",
Region::Eu,
Strength::Checked,
pt_nif,
),
Detector::new(
"at-svnr",
"Austria: social insurance number",
Region::Eu,
Strength::Checked,
at_svnr,
),
];
fn re(pattern: &str) -> Regex {
Regex::new(pattern).expect("detector pattern")
}
fn num(s: &str) -> u32 {
s.parse().unwrap_or(0)
}
// --- Germany --------------------------------------------------------------
/// Eleven digits, written `86 095 742 719` on the BZSt's letters.
static DE_TAX: LazyLock<Regex> = LazyLock::new(|| re(r"\b\d{2}( ?)\d{3}( ?)\d{3}( ?)\d{3}\b"));
/// ISO 7064 MOD 11,10; no leading zero; in the first ten digits one digit
/// appears two or three times and every other at most once.
pub fn de_tax_id_valid(n: &str) -> bool {
let d = digit_values(n);
if d.len() != 11 || d[0] == 0 {
return false;
}
let mut counts = [0u8; 10];
for &x in &d[..10] {
counts[x as usize] += 1;
}
let repeated = counts.iter().filter(|&&c| c >= 2).count();
if repeated != 1 || counts.iter().any(|&c| c > 3) {
return false;
}
let mut product = 10;
for &x in &d[..10] {
let mut sum = (x + product) % 10;
if sum == 0 {
sum = 10;
}
product = (2 * sum) % 11;
}
let check = match 11 - product {
10 => 0,
c => c,
};
check == d[10]
}
const DE_TAX_WORDS: &[&str] = &[
"steuer-id",
"steueridentifikationsnummer",
"steuerliche identifikationsnummer",
"idnr",
"identifikationsnummer",
"tax id",
];
fn de_tax_id(text: &str, findings: &mut Findings) {
for c in DE_TAX.captures_iter(text) {
let whole = c.get(0).unwrap();
let written = [&c[1], &c[2], &c[3]].iter().all(|s| *s == " ");
let n: String = whole.as_str().replace(' ', "");
if de_tax_id_valid(&n)
&& (written || word_near(text, whole.start(), whole.end(), DE_TAX_WORDS))
{
findings.insert(n);
}
}
}
/// The ID card's document number: a letter from the card's alphabet, eight
/// more characters from it, then the check digit.
static DE_ID: LazyLock<Regex> =
LazyLock::new(|| re(r"\b[CFGHJKLMNPRTVWXYZ][CFGHJKLMNPRTVWXYZ0-9]{8}\d\b"));
/// ICAO 9303 check digit: weights 7, 3, 1; letters A=10 … Z=35.
pub fn icao_check(chars: &str, check: u32) -> bool {
let value = |c: char| c.to_digit(10).unwrap_or_else(|| c as u32 - 'A' as u32 + 10);
let sum: u32 = chars
.chars()
.zip([7, 3, 1].iter().cycle())
.map(|(c, w)| value(c) * w)
.sum();
sum % 10 == check
}
fn de_id_card(text: &str, findings: &mut Findings) {
for m in DE_ID.find_iter(text) {
let s = m.as_str();
if icao_check(&s[..9], num(&s[9..])) {
findings.insert(s);
}
}
}
// --- France ---------------------------------------------------------------
/// Sex, year, month, department (with Corsica's 2A and 2B), commune, order,
/// then the two-digit key, spaces allowed between groups.
static FR_NIR: LazyLock<Regex> = LazyLock::new(|| {
re(r"\b([1-478]) ?(\d{2}) ?(\d{2}) ?(\d{2}|2[AB]) ?(\d{3}) ?(\d{3}) ?(\d{2})\b")
});
fn fr_nir(text: &str, findings: &mut Findings) {
for c in FR_NIR.captures_iter(text) {
let month = num(&c[3]);
if !(matches!(month, 1..=12 | 20..=42 | 50..=99)) {
continue;
}
let department = match &c[4] {
"2A" => "19",
"2B" => "18",
d => d,
};
let body = format!(
"{}{}{}{}{}{}",
&c[1], &c[2], &c[3], department, &c[5], &c[6]
);
let Ok(value) = body.parse::<u64>() else {
continue;
};
if 97 - value % 97 == u64::from(num(&c[7])) {
findings.insert(format!(
"{}{}{}{}{}{}{}",
&c[1], &c[2], &c[3], &c[4], &c[5], &c[6], &c[7]
));
}
}
}
// --- Spain ----------------------------------------------------------------
static ES_ID: LazyLock<Regex> = LazyLock::new(|| re(r"(?i)\b([XYZ]?)[ -]?(\d{7,8})[ -]?([A-Z])\b"));
const DNI_LETTERS: &[u8] = b"TRWAGMYFPDXBNJZSQVHLCKE";
fn es_dni_nie(text: &str, findings: &mut Findings) {
for c in ES_ID.captures_iter(text) {
let prefix = c[1].to_ascii_uppercase();
let digits = &c[2];
// DNI: eight digits; NIE: X, Y or Z and seven digits
let number = match (prefix.as_str(), digits.len()) {
("", 8) => digits.to_string(),
("X", 7) => format!("0{digits}"),
("Y", 7) => format!("1{digits}"),
("Z", 7) => format!("2{digits}"),
_ => continue,
};
let letter = c[3].to_ascii_uppercase();
if DNI_LETTERS[(num(&number) % 23) as usize] == letter.as_bytes()[0] {
findings.insert(format!("{prefix}{digits}{letter}"));
}
}
}
// --- Italy ----------------------------------------------------------------
/// Surname and name letters, year, month letter, day, place code, check
/// letter; digits may be replaced by letters (omocodia).
static IT_CF: LazyLock<Regex> = LazyLock::new(|| {
let d = "[0-9LMNPQRSTUV]";
re(&format!(
r"(?i)\b[A-Z]{{6}}{d}{{2}}[ABCDEHLMPRST]{d}{{2}}[A-Z]{d}{{3}}[A-Z]\b"
))
});
/// The Ministry's odd-position values for 0–9 and A–Z.
const CF_ODD: [u32; 36] = [
1, 0, 5, 7, 9, 13, 15, 17, 19, 21, // 0-9
1, 0, 5, 7, 9, 13, 15, 17, 19, 21, 2, 4, 18, 20, 11, 3, 6, 8, 12, 14, 16, 10, 22, 25, 24,
23, // A-Z
];
pub fn codice_fiscale_valid(cf: &str) -> bool {
let index = |c: u8| {
if c.is_ascii_digit() {
(c - b'0') as usize
} else {
(c - b'A') as usize + 10
}
};
let even = |c: u8| {
if c.is_ascii_digit() {
u32::from(c - b'0')
} else {
u32::from(c - b'A')
}
};
let bytes = cf.as_bytes();
let sum: u32 = bytes[..15]
.iter()
.enumerate()
.map(|(i, &c)| {
if i % 2 == 0 {
CF_ODD[index(c)]
} else {
even(c)
}
})
.sum();
u32::from(bytes[15] - b'A') == sum % 26
}
fn it_codice_fiscale(text: &str, findings: &mut Findings) {
for m in IT_CF.find_iter(text) {
let cf = m.as_str().to_ascii_uppercase();
if codice_fiscale_valid(&cf) {
findings.insert(cf);
}
}
}
// --- Netherlands ----------------------------------------------------------
/// Nine digits, sometimes written `1112.22.333`.
static NL_BSN: LazyLock<Regex> = LazyLock::new(|| re(r"\b(\d{4})(\.?)(\d{2})(\.?)(\d{3})\b"));
/// The eleven test: weights 9 down to 2, and −1 for the last digit.
pub fn bsn_valid(n: &str) -> bool {
let d = digit_values(n);
let sum: i64 = d[..8]
.iter()
.zip((2..=9).rev())
.map(|(a, w)| i64::from(a * w))
.sum::<i64>()
- i64::from(d[8]);
sum != 0 && sum % 11 == 0
}
const BSN_WORDS: &[&str] = &[
"bsn",
"burgerservicenummer",
"sofinummer",
"sofi-nummer",
"citizen service number",
];
fn nl_bsn(text: &str, findings: &mut Findings) {
for c in NL_BSN.captures_iter(text) {
let whole = c.get(0).unwrap();
let n = format!("{}{}{}", &c[1], &c[3], &c[5]);
let written = &c[2] == "." && &c[4] == ".";
if bsn_valid(&n) && (written || word_near(text, whole.start(), whole.end(), BSN_WORDS)) {
findings.insert(n);
}
}
}
// --- Belgium --------------------------------------------------------------
/// `YY.MM.DD-XXX.CC` or eleven digits.
static BE_NN: LazyLock<Regex> =
LazyLock::new(|| re(r"\b(\d{2})\.?(\d{2})\.?(\d{2})-?(\d{3})\.?(\d{2})\b"));
fn be_national_number(text: &str, findings: &mut Findings) {
for c in BE_NN.captures_iter(text) {
let (month, day) = (num(&c[2]), num(&c[3]));
// Month 0 and day 0 mean unknown; bis numbers add 20 or 40 to the month
if !(month <= 12 || (20..=32).contains(&month) || (40..=52).contains(&month)) || day > 31 {
continue;
}
let body = format!("{}{}{}{}", &c[1], &c[2], &c[3], &c[4]);
let check = u64::from(num(&c[5]));
let before_2000 = 97 - body.parse::<u64>().unwrap_or(0) % 97;
let since_2000 = 97 - format!("2{body}").parse::<u64>().unwrap_or(0) % 97;
if check == before_2000 || check == since_2000 {
findings.insert(format!("{body}{}", &c[5]));
}
}
}
// --- Poland ---------------------------------------------------------------
static ELEVEN: LazyLock<Regex> = LazyLock::new(|| re(r"\b\d{11}\b"));
/// Weights 1, 3, 7, 9 repeating; the birth date encodes the century in the
/// month (+80 for the 1800s, +20 for the 2000s, and so on).
pub fn pesel_valid(n: &str) -> bool {
let d = digit_values(n);
let sum: u32 = d[..10]
.iter()
.zip([1, 3, 7, 9].iter().cycle())
.map(|(a, w)| a * w)
.sum();
let month = d[2] * 10 + d[3];
let (century, month) = match month {
81..=92 => (1800, month - 80),
1..=12 => (1900, month),
21..=32 => (2000, month - 20),
41..=52 => (2100, month - 40),
_ => return false,
};
let year = century + d[0] * 10 + d[1];
(10 - sum % 10) % 10 == d[10] && (1..=super::days_in(year, month)).contains(&(d[4] * 10 + d[5]))
}
const PESEL_WORDS: &[&str] = &["pesel", "numer pesel", "nr pesel"];
fn pl_pesel(text: &str, findings: &mut Findings) {
for m in ELEVEN.find_iter(text) {
if pesel_valid(m.as_str()) && word_near(text, m.start(), m.end(), PESEL_WORDS) {
findings.insert(m.as_str());
}
}
}
// --- Sweden ---------------------------------------------------------------
/// `YYMMDD-NNNN`, `YYYYMMDD-NNNN` (`+` after 100), or the bare digits.
static SE_PNR: LazyLock<Regex> =
LazyLock::new(|| re(r"\b(?:\d{2})?(\d{2})(\d{2})(\d{2})([-+]?)(\d{4})\b"));
const SE_WORDS: &[&str] = &[
"personnummer",
"personnr",
"person nr",
"samordningsnummer",
"pnr",
];
fn se_personnummer(text: &str, findings: &mut Findings) {
for c in SE_PNR.captures_iter(text) {
let whole = c.get(0).unwrap();
let (yy, month, day) = (num(&c[1]), num(&c[2]), num(&c[3]));
// Coordination numbers add 60 to the day
let day = if day > 60 { day - 60 } else { day };
let ten = format!("{}{}{}{}", &c[1], &c[2], &c[3], &c[5]);
let written = !c[4].is_empty();
if valid_short_date(yy, month, day)
&& checks::luhn(&ten)
&& (written || word_near(text, whole.start(), whole.end(), SE_WORDS))
{
findings.insert(ten);
}
}
}
// --- Denmark --------------------------------------------------------------
static DK_CPR: LazyLock<Regex> = LazyLock::new(|| re(r"\b(\d{2})(\d{2})(\d{2})-?(\d{4})\b"));
const CPR_WORDS: &[&str] = &["cpr", "cpr-nr", "cpr nr", "cpr-nummer", "personnummer"];
fn dk_cpr(text: &str, findings: &mut Findings) {
for c in DK_CPR.captures_iter(text) {
let whole = c.get(0).unwrap();
if valid_short_date(num(&c[3]), num(&c[2]), num(&c[1]))
&& word_near(text, whole.start(), whole.end(), CPR_WORDS)
{
findings.insert(whole.as_str().replace('-', ""));
}
}
}
// --- Finland --------------------------------------------------------------
static FI_HETU: LazyLock<Regex> =
LazyLock::new(|| re(r"(?i)\b(\d{2})(\d{2})(\d{2})[-+ABCDEFYXWVU](\d{3})([0-9A-Y])\b"));
const HETU_CHECK: &[u8] = b"0123456789ABCDEFHJKLMNPRSTUVWXY";
fn fi_hetu(text: &str, findings: &mut Findings) {
for c in FI_HETU.captures_iter(text) {
let (day, month, yy) = (num(&c[1]), num(&c[2]), num(&c[3]));
let n: u64 = format!("{}{}{}{}", &c[1], &c[2], &c[3], &c[4])
.parse()
.unwrap_or(0);
let check = c[5].to_ascii_uppercase().as_bytes()[0];
if valid_short_date(yy, month, day) && HETU_CHECK[(n % 31) as usize] == check {
findings.insert(c[0].to_ascii_uppercase());
}
}
}
// --- Ireland --------------------------------------------------------------
static IE_PPS: LazyLock<Regex> = LazyLock::new(|| re(r"(?i)\b(\d{7})([A-W])([ABHW]?)\b"));
const PPS_CHECK: &[u8] = b"WABCDEFGHIJKLMNOPQRSTUV";
fn ie_pps(text: &str, findings: &mut Findings) {
for c in IE_PPS.captures_iter(text) {
let mut sum: u32 = digit_values(&c[1])
.iter()
.zip((2..=8).rev())
.map(|(a, w)| a * w)
.sum();
// The second letter counts, times 9; W (the old form) counts as 0
let second = c[3].to_ascii_uppercase();
if let Some(&letter) = second.as_bytes().first()
&& letter != b'W'
{
sum += u32::from(letter - b'A' + 1) * 9;
}
let check = c[2].to_ascii_uppercase().as_bytes()[0];
if PPS_CHECK[(sum % 23) as usize] == check {
findings.insert(c[0].to_ascii_uppercase());
}
}
}
// --- Portugal -------------------------------------------------------------
static NINE: LazyLock<Regex> = LazyLock::new(|| re(r"\b\d{9}\b"));
/// Mod 11 over weights 9 down to 2; a check of 10 or 11 becomes 0.
pub fn nif_valid(n: &str) -> bool {
let d = digit_values(n);
let sum: u32 = d[..8].iter().zip((2..=9).rev()).map(|(a, w)| a * w).sum();
let check = match 11 - sum % 11 {
10 | 11 => 0,
c => c,
};
matches!(d[0], 1 | 2 | 3 | 5 | 6 | 8 | 9) && check == d[8]
}
const NIF_WORDS: &[&str] = &[
"nif",
"contribuinte",
"número de identificação fiscal",
"numero de contribuinte",
];
fn pt_nif(text: &str, findings: &mut Findings) {
for m in NINE.find_iter(text) {
if nif_valid(m.as_str()) && word_near(text, m.start(), m.end(), NIF_WORDS) {
findings.insert(m.as_str());
}
}
}
// --- Austria --------------------------------------------------------------
/// A serial and check digit, then the birth date: `1237 010180`.
static AT_SVNR: LazyLock<Regex> = LazyLock::new(|| re(r"\b(\d{3})(\d)( ?)(\d{2})(\d{2})(\d{2})\b"));
const SVNR_WORDS: &[&str] = &[
"sozialversicherungsnummer",
"svnr",
"sv-nr",
"sv-nummer",
"versicherungsnummer",
];
fn at_svnr(text: &str, findings: &mut Findings) {
for c in AT_SVNR.captures_iter(text) {
let whole = c.get(0).unwrap();
let n = format!("{}{}{}{}{}", &c[1], &c[2], &c[4], &c[5], &c[6]);
let d = digit_values(&n);
let sum: u32 = d
.iter()
.zip([3, 7, 9, 0, 5, 8, 4, 2, 1, 6])
.map(|(a, w)| a * w)
.sum();
let written = &c[3] == " ";
if d[0] != 0
&& sum % 11 == d[3]
&& valid_short_date(num(&c[6]), num(&c[5]), num(&c[4]))
&& (written || word_near(text, whole.start(), whole.end(), SVNR_WORDS))
&& stands_alone(text, whole.start(), whole.end())
{
findings.insert(n);
}
}
}
#[cfg(test)]
mod tests {
use crate::mailflow::detectors::by_id;
fn count(id: &str, text: &str) -> usize {
by_id(id).unwrap().count(text)
}
#[test]
fn germany() {
assert_eq!(count("de-tax-id", "86 095 742 719"), 1);
assert_eq!(count("de-tax-id", "Steuer-ID: 86095742719"), 1);
assert_eq!(count("de-tax-id", "Rechnung 86095742719"), 0);
assert_eq!(count("de-tax-id", "86 095 742 718"), 0);
// ICAO 9303's German specimen card
assert_eq!(count("de-id-card", "Ausweis T220001293"), 1);
assert_eq!(count("de-id-card", "T220001294"), 0);
}
#[test]
fn france_spain_italy() {
assert_eq!(count("fr-nir", "2 55 08 14 168 025 38"), 1);
assert_eq!(count("fr-nir", "255081416802539"), 0);
assert_eq!(count("es-dni-nie", "DNI 12345678Z, NIE X-1234567-L"), 2);
assert_eq!(count("es-dni-nie", "12345678A"), 0);
assert_eq!(count("it-codice-fiscale", "CF: RSSMRA85T10A562S"), 1);
assert_eq!(count("it-codice-fiscale", "RSSMRA85T10A562T"), 0);
}
#[test]
fn benelux() {
assert_eq!(count("nl-bsn", "1112.22.333"), 1);
assert_eq!(count("nl-bsn", "BSN 111222333"), 1);
assert_eq!(count("nl-bsn", "order 111222333"), 0);
assert_eq!(count("nl-bsn", "BSN 111222334"), 0);
assert_eq!(count("be-national-number", "85.07.30-033.28"), 1);
assert_eq!(count("be-national-number", "85073003329"), 0);
}
#[test]
fn nordics() {
assert_eq!(count("se-personnummer", "811218-9876"), 1);
assert_eq!(count("se-personnummer", "811218-9875"), 0);
assert_eq!(count("se-personnummer", "order 8112189876"), 0);
assert_eq!(count("se-personnummer", "personnummer 198112189876"), 1);
assert_eq!(count("dk-cpr", "CPR-nr: 010170-1234"), 1);
assert_eq!(count("dk-cpr", "010170-1234"), 0);
assert_eq!(count("dk-cpr", "CPR 320170-1234"), 0);
assert_eq!(count("fi-hetu", "131052-308T"), 1);
assert_eq!(count("fi-hetu", "131052-308U"), 0);
}
#[test]
fn poland_ireland_portugal_austria() {
assert_eq!(count("pl-pesel", "PESEL 44051401359, pesel 02070803628"), 2);
assert_eq!(count("pl-pesel", "PESEL 44051401358"), 0);
assert_eq!(count("pl-pesel", "44051401359"), 0);
assert_eq!(count("ie-pps", "PPS 1234567T and 1234567FA"), 2);
assert_eq!(count("ie-pps", "1234567U"), 0);
assert_eq!(count("pt-nif", "NIF 123456789"), 1);
assert_eq!(count("pt-nif", "NIF 123456788"), 0);
assert_eq!(count("at-svnr", "1237 010180"), 1);
assert_eq!(count("at-svnr", "SVNR 1237010180"), 1);
assert_eq!(count("at-svnr", "1238 010180"), 0);
}
}
@@ -0,0 +1,116 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! European identifiers outside the EU (§2.3): Norway's national identity
//! number and Switzerland's AHV number.
use super::{Detector, Findings, Region, Strength, digit_values, valid_short_date};
use regex::Regex;
use std::sync::LazyLock;
pub static DETECTORS: &[Detector] = &[
Detector::new(
"no-fnr",
"Norway: national identity number",
Region::Europe,
Strength::Checked,
no_fnr,
),
Detector::new(
"ch-ahv",
"Switzerland: AHV number",
Region::Europe,
Strength::Checked,
ch_ahv,
),
];
static ELEVEN: LazyLock<Regex> =
LazyLock::new(|| Regex::new(r"\b\d{6} ?\d{5}\b").expect("detector pattern"));
/// Two mod 11 check digits over a birth date (D-numbers add 40 to the day,
/// H-numbers 40 to the month): strong enough to count alone.
pub fn fnr_valid(n: &str) -> bool {
let d = digit_values(n);
if d.len() != 11 {
return false;
}
let check =
|weights: &[u32]| match 11 - d.iter().zip(weights).map(|(a, w)| a * w).sum::<u32>() % 11 {
11 => Some(0),
10 => None,
c => Some(c),
};
let day = d[0] * 10 + d[1];
let month = d[2] * 10 + d[3];
let day = if day > 40 { day - 40 } else { day };
let month = if month > 40 { month - 40 } else { month };
valid_short_date(d[4] * 10 + d[5], month, day)
&& check(&[3, 7, 6, 1, 8, 9, 4, 5, 2]) == Some(d[9])
&& check(&[5, 4, 3, 2, 7, 6, 5, 4, 3, 2]) == Some(d[10])
}
fn no_fnr(text: &str, findings: &mut Findings) {
for m in ELEVEN.find_iter(text) {
let n = m.as_str().replace(' ', "");
if fnr_valid(&n) {
findings.insert(n);
}
}
}
/// `756.1234.5678.97`: the country prefix, then an EAN-13 check digit.
static AHV: LazyLock<Regex> = LazyLock::new(|| {
Regex::new(r"\b756[. ]?\d{4}[. ]?\d{4}[. ]?\d{2}\b").expect("detector pattern")
});
pub fn ean13_valid(n: &str) -> bool {
let d = digit_values(n);
if d.len() != 13 {
return false;
}
let sum: u32 = d[..12]
.iter()
.enumerate()
.map(|(i, x)| if i % 2 == 0 { *x } else { x * 3 })
.sum();
(10 - sum % 10) % 10 == d[12]
}
fn ch_ahv(text: &str, findings: &mut Findings) {
for m in AHV.find_iter(text) {
let n: String = m.as_str().chars().filter(char::is_ascii_digit).collect();
if ean13_valid(&n) {
findings.insert(n);
}
}
}
#[cfg(test)]
mod tests {
use crate::mailflow::detectors::by_id;
fn count(id: &str, text: &str) -> usize {
by_id(id).unwrap().count(text)
}
#[test]
fn norway() {
assert_eq!(count("no-fnr", "01019000083"), 1);
assert_eq!(count("no-fnr", "010190 00083"), 1);
assert_eq!(count("no-fnr", "01019000084"), 0);
// Not a date
assert_eq!(count("no-fnr", "32019000083"), 0);
}
#[test]
fn switzerland() {
// The federal example
assert_eq!(count("ch-ahv", "AHV 756.9217.0769.85"), 1);
assert_eq!(count("ch-ahv", "7569217076985"), 1);
assert_eq!(count("ch-ahv", "756.9217.0769.86"), 0);
}
}
@@ -0,0 +1,278 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Detectors (dlp-and-mail-flow-rules spec, §2.3): each finds one kind of
//! identifier in text and reports the distinct ones it found.
//!
//! A detector is one of two strengths:
//!
//! - **Checked**: the identifier carries a published check digit or
//! checksum, so a random number rarely passes; found on its own.
//! - **Needs a word**: the format alone is too common, so a candidate counts
//! only with a corroborating word within [`WINDOW`] characters either
//! side.
//!
//! Findings are distinct normalized values (digits only, upper case), so the
//! same card number pasted twice counts once. They stay in memory: callers
//! read only [`Findings::len`].
pub mod africa;
pub mod americas;
pub mod any;
pub mod asia;
pub mod australia;
pub mod canada;
pub mod checks;
pub mod eu;
pub mod europe;
pub mod templates;
pub mod uk;
pub mod us;
use ahash::AHashSet;
/// How far, in characters, a corroborating word may be from a candidate.
pub const WINDOW: usize = 50;
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub enum Strength {
Checked,
NeedsWord,
}
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub enum Region {
Any,
Us,
Uk,
Canada,
Australia,
Eu,
Europe,
Asia,
Americas,
Africa,
}
/// The distinct values one detector found.
#[derive(Debug, Default)]
pub struct Findings(AHashSet<String>);
impl Findings {
pub fn insert(&mut self, value: impl Into<String>) {
self.0.insert(value.into());
}
pub fn len(&self) -> usize {
self.0.len()
}
pub fn is_empty(&self) -> bool {
self.0.is_empty()
}
}
pub struct Detector {
/// Stable id, stored in rules: `payment-card`, `iban`, `us-ssn`.
pub id: &'static str,
pub name: &'static str,
pub region: Region,
pub strength: Strength,
find: fn(&str, &mut Findings),
}
impl Detector {
pub const fn new(
id: &'static str,
name: &'static str,
region: Region,
strength: Strength,
find: fn(&str, &mut Findings),
) -> Self {
Self {
id,
name,
region,
strength,
find,
}
}
/// Adds what this detector finds in `text` to `findings`. Call once per
/// piece of text (subject, each part, each attachment) with the same
/// `findings`, then read its length.
pub fn find(&self, text: &str, findings: &mut Findings) {
(self.find)(text, findings)
}
/// The distinct values found in one text.
pub fn count(&self, text: &str) -> usize {
let mut findings = Findings::default();
self.find(text, &mut findings);
findings.len()
}
}
/// Every detector, in the order the console lists them.
pub fn all() -> impl Iterator<Item = &'static Detector> {
[
any::DETECTORS,
us::DETECTORS,
uk::DETECTORS,
canada::DETECTORS,
australia::DETECTORS,
eu::DETECTORS,
europe::DETECTORS,
asia::DETECTORS,
americas::DETECTORS,
africa::DETECTORS,
]
.into_iter()
.flatten()
}
pub fn by_id(id: &str) -> Option<&'static Detector> {
all().find(|detector| detector.id == id)
}
/// Whether one of `words` appears, as a whole word and ignoring case, within
/// [`WINDOW`] characters before `start` or after `end` (byte offsets of the
/// candidate in `text`). The window is widened by the longest word, so a
/// word that reaches into it still counts whole.
pub fn word_near(text: &str, start: usize, end: usize, words: &[&str]) -> bool {
let reach = WINDOW + words.iter().map(|w| w.chars().count()).max().unwrap_or(0);
let before = text[..start]
.char_indices()
.rev()
.nth(reach - 1)
.map_or(0, |(i, _)| i);
let after = text[end..]
.char_indices()
.nth(reach)
.map_or(text.len(), |(i, _)| end + i);
let window = text[before..after].to_lowercase();
words.iter().any(|word| contains_word(&window, word))
}
/// Whether `word` (lower case) appears in `haystack` (lower case) with no
/// letter or digit on either side.
pub fn contains_word(haystack: &str, word: &str) -> bool {
haystack.match_indices(word).any(|(i, _)| {
let before_ok = haystack[..i]
.chars()
.next_back()
.is_none_or(|c| !c.is_alphanumeric());
let after_ok = haystack[i + word.len()..]
.chars()
.next()
.is_none_or(|c| !c.is_alphanumeric());
before_ok && after_ok
})
}
/// Whether the match at `start..end` stands alone: no digit or letter
/// directly before or after it, so `123-45-6789` isn't found inside a
/// longer run of digits.
pub fn stands_alone(text: &str, start: usize, end: usize) -> bool {
let before = text[..start].chars().next_back();
let after = text[end..].chars().next();
before.is_none_or(|c| !c.is_alphanumeric()) && after.is_none_or(|c| !c.is_alphanumeric())
}
/// Days in `month` of `year` (0 for a month that doesn't exist).
pub fn days_in(year: u32, month: u32) -> u32 {
match month {
1 | 3 | 5 | 7 | 8 | 10 | 12 => 31,
4 | 6 | 9 | 11 => 30,
2 if year.is_multiple_of(4) && (!year.is_multiple_of(100) || year.is_multiple_of(400)) => {
29
}
2 => 28,
_ => 0,
}
}
/// Whether `year`-`month`-`day` is a real date between 1900 and 2100.
pub fn valid_date(year: u32, month: u32, day: u32) -> bool {
(1900..=2100).contains(&year) && (1..=days_in(year, month)).contains(&day)
}
/// Whether a two-digit year, month and day make a real date in either the
/// 1900s or the 2000s.
pub fn valid_short_date(yy: u32, month: u32, day: u32) -> bool {
valid_date(1900 + yy, month, day) || valid_date(2000 + yy, month, day)
}
/// The value of each digit in `s`.
pub fn digit_values(s: &str) -> Vec<u32> {
s.bytes()
.filter(u8::is_ascii_digit)
.map(|b| u32::from(b - b'0'))
.collect()
}
/// The ASCII digits of `s`.
pub fn digits(s: &str) -> String {
s.chars().filter(char::is_ascii_digit).collect()
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn words_are_whole_and_near() {
let text = "Your passport number is X1234567, thanks";
let start = text.find("X123").unwrap();
assert!(word_near(text, start, start + 8, &["passport"]));
assert!(!word_near(text, start, start + 8, &["pass"]));
let far = format!("passport{}X1234567", " ".repeat(60));
let start = far.find("X123").unwrap();
assert!(!word_near(&far, start, start + 8, &["passport"]));
}
#[test]
fn near_counts_characters_not_bytes() {
// 45 two-byte characters between the word and the candidate: within
// 50 characters, though over 50 bytes
let text = format!("passport {} X1234567", "é".repeat(45));
let start = text.find("X123").unwrap();
assert!(word_near(&text, start, start + 8, &["passport"]));
}
/// An ordinary business email: order, invoice and tracking numbers,
/// dates, amounts, a street address. Nothing here is an identifier, so
/// no detector may fire, except the contact ones on the signature.
#[test]
fn ordinary_mail_finds_nothing() {
let text = "Hi Dana,\n\nThanks for order 4471-2290 placed 2026-09-14. Invoice INV-2026-00917 \
for $12,480.00 is due 10/31/2026; PO 7731902 covers lines 1-14. Tracking \
1Z999AA10123456784, parcel 3 of 5, 12.5 kg, box 40x30x20 cm. Meeting moved to \
Tuesday 9:30-10:15 in room 2B, building 1177. Ticket #5520318, case 20260914-0042. \
Version 2026.9.28.4, build 118822, commit 5a73a118. Serial SN-88213-X. \
Ship to 1600 Amphitheatre Pkwy, Mountain View, CA 94043. Revenue grew 18% to \
1,204,332 units; see figures 3.1-3.4 and table 12.\n\nBest,\nSam\n\
Sam Rivera | +1 (415) 555-2671 | sam@example.com";
let quiet = ["email-addresses", "phone-numbers"];
for detector in all().filter(|d| !quiet.contains(&d.id)) {
assert_eq!(
detector.count(text),
0,
"{} fired on ordinary mail",
detector.id
);
}
}
#[test]
fn ids_are_unique() {
let mut seen = AHashSet::new();
for detector in all() {
assert!(seen.insert(detector.id), "duplicate id {}", detector.id);
assert!(by_id(detector.id).is_some());
}
}
}
@@ -0,0 +1,97 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Templates (§2.3): named sets of detectors, so a policy doesn't pick forty
//! one at a time. Each is named for what it finds, never for a law, and is a
//! starting point: once added to a rule, its detectors can be changed.
pub struct Template {
pub id: &'static str,
pub name: &'static str,
pub detectors: &'static [&'static str],
}
pub static TEMPLATES: &[Template] = &[
Template {
id: "payment-and-bank",
name: "Payment cards and bank accounts",
detectors: &["payment-card", "iban", "swift-bic", "us-aba-routing"],
},
Template {
id: "us-personal",
name: "US personal identifiers",
detectors: &[
"us-ssn",
"us-itin",
"us-ein",
"us-drivers-license",
"passport",
"date-of-birth",
],
},
Template {
id: "uk-personal",
name: "UK personal identifiers",
detectors: &["uk-nino", "uk-utr", "uk-nhs", "passport", "date-of-birth"],
},
Template {
id: "eu-national",
name: "EU national identifiers",
detectors: &[
"de-tax-id",
"de-id-card",
"fr-nir",
"es-dni-nie",
"it-codice-fiscale",
"nl-bsn",
"be-national-number",
"pl-pesel",
"se-personnummer",
"dk-cpr",
"fi-hetu",
"ie-pps",
"pt-nif",
"at-svnr",
],
},
Template {
id: "health",
name: "Health identifiers",
detectors: &["uk-nhs", "us-mbi", "us-npi", "us-dea", "au-medicare"],
},
Template {
id: "credentials",
name: "Credentials and keys",
detectors: &["private-key", "credentials"],
},
Template {
id: "contact-lists",
name: "Contact lists",
detectors: &["email-addresses", "phone-numbers"],
},
];
pub fn by_id(id: &str) -> Option<&'static Template> {
TEMPLATES.iter().find(|template| template.id == id)
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn every_template_names_real_detectors() {
for template in TEMPLATES {
for id in template.detectors {
assert!(
super::super::by_id(id).is_some(),
"{}: no detector {id}",
template.id
);
}
}
}
}
@@ -0,0 +1,155 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! United Kingdom identifiers (§2.3): HMRC's National Insurance number and
//! Unique Taxpayer Reference, and the NHS number.
use super::{Detector, Findings, Region, Strength, word_near};
use regex::Regex;
use std::sync::LazyLock;
pub static DETECTORS: &[Detector] = &[
Detector::new(
"uk-nino",
"UK National Insurance number",
Region::Uk,
Strength::Checked,
nino,
),
Detector::new(
"uk-nhs",
"UK NHS number",
Region::Uk,
Strength::Checked,
nhs,
),
Detector::new(
"uk-utr",
"UK Unique Taxpayer Reference",
Region::Uk,
Strength::NeedsWord,
utr,
),
];
fn re(pattern: &str) -> Regex {
Regex::new(pattern).expect("detector pattern")
}
/// Two letters, six digits (often in pairs), a suffix A–D.
static NINO: LazyLock<Regex> =
LazyLock::new(|| re(r"(?i)\b([A-Z])([A-Z]) ?(\d{2}) ?(\d{2}) ?(\d{2}) ?([A-D])\b"));
/// HMRC's rules: D, F, I, Q, U and V are never used; O never second; and
/// BG, GB, KN, NK, NT, TN and ZZ are never allocated.
fn nino_prefix(first: char, second: char) -> bool {
const NEVER: &str = "DFIQUV";
let pair: String = [first, second].iter().collect();
!NEVER.contains(first)
&& !NEVER.contains(second)
&& second != 'O'
&& !["BG", "GB", "KN", "NK", "NT", "TN", "ZZ"].contains(&pair.as_str())
}
fn nino(text: &str, findings: &mut Findings) {
for c in NINO.captures_iter(text) {
let first = c[1].to_ascii_uppercase().chars().next().unwrap();
let second = c[2].to_ascii_uppercase().chars().next().unwrap();
if nino_prefix(first, second) {
findings.insert(format!(
"{first}{second}{}{}{}{}",
&c[3],
&c[4],
&c[5],
c[6].to_ascii_uppercase()
));
}
}
}
/// `NNN NNN NNNN` stands alone; ten bare digits need a word.
static NHS: LazyLock<Regex> = LazyLock::new(|| re(r"\b(\d{3})([ -]?)(\d{3})([ -]?)(\d{4})\b"));
/// Mod 11: weights 10 down to 2 over the first nine digits; the check digit
/// is 11 minus the remainder (11 becomes 0; 10 is never issued).
pub fn nhs_valid(n: &str) -> bool {
let d: Vec<u32> = n.bytes().map(|b| u32::from(b - b'0')).collect();
let sum: u32 = d[..9].iter().zip((2..=10).rev()).map(|(a, w)| a * w).sum();
match 11 - sum % 11 {
11 => d[9] == 0,
10 => false,
check => d[9] == check,
}
}
const NHS_WORDS: &[&str] = &["nhs", "nhs number", "nhs no"];
fn nhs(text: &str, findings: &mut Findings) {
for c in NHS.captures_iter(text) {
let whole = c.get(0).unwrap();
let n = format!("{}{}{}", &c[1], &c[3], &c[5]);
let written = !c[2].is_empty() && c[2] == c[4];
if nhs_valid(&n) && (written || word_near(text, whole.start(), whole.end(), NHS_WORDS)) {
findings.insert(n);
}
}
}
static UTR: LazyLock<Regex> = LazyLock::new(|| re(r"\b\d{5} ?\d{5}\b"));
const UTR_WORDS: &[&str] = &[
"utr",
"unique taxpayer reference",
"tax reference",
"self assessment",
];
fn utr(text: &str, findings: &mut Findings) {
for m in UTR.find_iter(text) {
if word_near(text, m.start(), m.end(), UTR_WORDS) {
findings.insert(m.as_str().replace(' ', ""));
}
}
}
#[cfg(test)]
mod tests {
use crate::mailflow::detectors::by_id;
fn count(id: &str, text: &str) -> usize {
by_id(id).unwrap().count(text)
}
#[test]
fn national_insurance() {
assert_eq!(count("uk-nino", "NI: AB 12 34 56 C, ce123456d"), 2);
// Letters never used, pairs never allocated, a suffix past D
for bad in [
"QQ123456C",
"AO123456C",
"GB123456A",
"AB123456E",
"DA123456A",
] {
assert_eq!(count("uk-nino", bad), 0, "{bad}");
}
}
#[test]
fn nhs_numbers() {
// The NHS's own example
assert_eq!(count("uk-nhs", "943 476 5919"), 1);
assert_eq!(count("uk-nhs", "943 476 5918"), 0);
assert_eq!(count("uk-nhs", "order 9434765919"), 0);
assert_eq!(count("uk-nhs", "NHS number 9434765919"), 1);
}
#[test]
fn utr() {
assert_eq!(count("uk-utr", "UTR 12345 67890"), 1);
assert_eq!(count("uk-utr", "order 1234567890"), 0);
}
}
@@ -0,0 +1,304 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! United States identifiers (§2.3), each from its issuer's published rules:
//! the SSA (SSN), the IRS (ITIN, EIN), the ABA (routing numbers), CMS (MBI,
//! NPI) and the DEA.
use super::{Detector, Findings, Region, Strength, checks, digits, stands_alone, word_near};
use regex::Regex;
use std::sync::LazyLock;
pub static DETECTORS: &[Detector] = &[
Detector::new(
"us-ssn",
"US Social Security number",
Region::Us,
Strength::Checked,
ssn,
),
Detector::new("us-itin", "US ITIN", Region::Us, Strength::Checked, itin),
Detector::new("us-ein", "US EIN", Region::Us, Strength::NeedsWord, ein),
Detector::new(
"us-aba-routing",
"US bank routing number",
Region::Us,
Strength::NeedsWord,
aba_routing,
),
Detector::new(
"us-drivers-license",
"US driver's license",
Region::Us,
Strength::NeedsWord,
drivers_license,
),
Detector::new(
"us-mbi",
"US Medicare Beneficiary Identifier",
Region::Us,
Strength::Checked,
mbi,
),
Detector::new(
"us-npi",
"US National Provider Identifier",
Region::Us,
Strength::NeedsWord,
npi,
),
Detector::new(
"us-dea",
"US DEA registration number",
Region::Us,
Strength::Checked,
dea,
),
];
fn re(pattern: &str) -> Regex {
Regex::new(pattern).expect("detector pattern")
}
/// `AAA-GG-SSSS` (dashes or spaces), or nine bare digits.
static NINE: LazyLock<Regex> = LazyLock::new(|| re(r"\b(\d{3})([ -]?)(\d{2})([ -]?)(\d{4})\b"));
/// Numbers the SSA has published as never valid: widely printed examples.
const SSN_EXAMPLES: &[&str] = &["078051120", "219099999"];
fn ssn_rules(area: u32, group: u32, serial: u32) -> bool {
area != 0 && area != 666 && area < 900 && group != 0 && serial != 0
}
const SSN_WORDS: &[&str] = &["ssn", "social security", "soc sec", "ss#", "ss no"];
fn ssn(text: &str, findings: &mut Findings) {
for c in NINE.captures_iter(text) {
let whole = c.get(0).unwrap();
let (area, group, serial) = (num(&c[1]), num(&c[3]), num(&c[5]));
let number = format!("{}{}{}", &c[1], &c[3], &c[5]);
// Written form (with both separators, the same one) stands alone;
// nine bare digits need a word
let written = !c[2].is_empty() && c[2] == c[4];
if ssn_rules(area, group, serial)
&& !SSN_EXAMPLES.contains(&number.as_str())
&& (written || word_near(text, whole.start(), whole.end(), SSN_WORDS))
{
findings.insert(number);
}
}
}
/// ITINs: 9XX, then a group in the IRS's ranges.
fn itin_group(group: u32) -> bool {
matches!(group, 50..=65 | 70..=88 | 90..=92 | 94..=99)
}
const ITIN_WORDS: &[&str] = &["itin", "taxpayer identification", "tax id"];
fn itin(text: &str, findings: &mut Findings) {
for c in NINE.captures_iter(text) {
let whole = c.get(0).unwrap();
let written = !c[2].is_empty() && c[2] == c[4];
if c[1].starts_with('9')
&& itin_group(num(&c[3]))
&& (written || word_near(text, whole.start(), whole.end(), ITIN_WORDS))
{
findings.insert(format!("{}{}{}", &c[1], &c[3], &c[5]));
}
}
}
static EIN: LazyLock<Regex> = LazyLock::new(|| re(r"\b(\d{2})-?(\d{7})\b"));
/// The prefixes the IRS assigns to its campuses and internet EINs.
fn ein_prefix(prefix: u32) -> bool {
matches!(prefix, 1..=6 | 10..=16 | 20..=27 | 30..=48 | 50..=68 | 71..=77 | 80..=88 | 90..=95 | 98 | 99)
}
const EIN_WORDS: &[&str] = &[
"ein",
"fein",
"employer identification",
"tax id",
"tin",
"federal tax",
];
fn ein(text: &str, findings: &mut Findings) {
for c in EIN.captures_iter(text) {
let whole = c.get(0).unwrap();
if ein_prefix(num(&c[1])) && word_near(text, whole.start(), whole.end(), EIN_WORDS) {
findings.insert(format!("{}{}", &c[1], &c[2]));
}
}
}
static ROUTING: LazyLock<Regex> = LazyLock::new(|| re(r"\b\d{9}\b"));
/// The ABA check: 3, 7 and 1 weights, mod 10; and a Federal Reserve prefix.
pub fn aba_valid(n: &str) -> bool {
let d: Vec<u32> = n.bytes().map(|b| u32::from(b - b'0')).collect();
let prefix = d[0] * 10 + d[1];
matches!(prefix, 0..=12 | 21..=32 | 61..=72 | 80)
&& (3 * (d[0] + d[3] + d[6]) + 7 * (d[1] + d[4] + d[7]) + (d[2] + d[5] + d[8]))
.is_multiple_of(10)
}
const ROUTING_WORDS: &[&str] = &["routing", "aba", "rtn", "routing number", "transit"];
fn aba_routing(text: &str, findings: &mut Findings) {
for m in ROUTING.find_iter(text) {
// One random number in ten passes the check: always needs a word
if aba_valid(m.as_str()) && word_near(text, m.start(), m.end(), ROUTING_WORDS) {
findings.insert(m.as_str());
}
}
}
/// The shapes states issue: up to two letters, then 5–14 digits, dashes
/// allowed (Florida and Illinois print them).
static LICENSE: LazyLock<Regex> = LazyLock::new(|| re(r"\b[A-Z]{0,2}\d[\d-]{3,16}\d\b"));
const LICENSE_WORDS: &[&str] = &[
"driver's license",
"drivers license",
"driver license",
"driver's licence",
"dl",
"dl#",
"license number",
"lic no",
"dmv",
];
fn drivers_license(text: &str, findings: &mut Findings) {
for m in LICENSE.find_iter(text) {
let n = digits(m.as_str());
if (5..=14).contains(&n.len()) && word_near(text, m.start(), m.end(), LICENSE_WORDS) {
findings.insert(m.as_str().replace('-', ""));
}
}
}
/// CMS's MBI: 11 characters in a fixed pattern of digits, letters and
/// either, the letters S, L, O, I, B and Z never used; dashes may follow the
/// 4th and 7th.
static MBI: LazyLock<Regex> = LazyLock::new(|| {
let c = "[AC-HJKMNP-RT-Y]";
let an = "[AC-HJKMNP-RT-Y0-9]";
re(&format!(
r"\b[1-9]{c}{an}[0-9]-?{c}{an}[0-9]-?{c}{c}[0-9][0-9]\b"
))
});
fn mbi(text: &str, findings: &mut Findings) {
for m in MBI.find_iter(text) {
findings.insert(m.as_str().replace('-', ""));
}
}
static TEN: LazyLock<Regex> = LazyLock::new(|| re(r"\b[12]\d{9}\b"));
const NPI_WORDS: &[&str] = &["npi", "national provider", "provider id", "provider number"];
/// NPI: Luhn over the ISO card-issuer prefix 80840 and the number.
fn npi(text: &str, findings: &mut Findings) {
for m in TEN.find_iter(text) {
if checks::luhn(&format!("80840{}", m.as_str()))
&& word_near(text, m.start(), m.end(), NPI_WORDS)
{
findings.insert(m.as_str());
}
}
}
static DEA: LazyLock<Regex> = LazyLock::new(|| re(r"\b([ABCDEFGHJKLMPRSTUX][A-Z9])(\d{7})\b"));
/// DEA: (1st + 3rd + 5th) + 2 × (2nd + 4th + 6th) ends in the 7th digit.
fn dea(text: &str, findings: &mut Findings) {
for c in DEA.captures_iter(text) {
let d: Vec<u32> = c[2].bytes().map(|b| u32::from(b - b'0')).collect();
if ((d[0] + d[2] + d[4]) + 2 * (d[1] + d[3] + d[5])) % 10 == d[6] {
let whole = c.get(0).unwrap();
if stands_alone(text, whole.start(), whole.end()) {
findings.insert(whole.as_str());
}
}
}
}
fn num(s: &str) -> u32 {
s.parse().unwrap_or(0)
}
#[cfg(test)]
mod tests {
use crate::mailflow::detectors::by_id;
fn count(id: &str, text: &str) -> usize {
by_id(id).unwrap().count(text)
}
#[test]
fn ssn() {
assert_eq!(count("us-ssn", "SSN 536-22-1234, also 536 22 1235"), 2);
// Bare digits: only with a word
assert_eq!(count("us-ssn", "ref 536221234"), 0);
assert_eq!(count("us-ssn", "social security: 536221234"), 1);
// Never issued, the SSA's printed examples, mixed separators
for bad in [
"000-12-3456",
"666-12-3456",
"912-12-3456",
"123-00-4567",
"123-45-0000",
"078-05-1120",
"536-22 1234",
] {
assert_eq!(count("us-ssn", bad), 0, "{bad}");
}
}
#[test]
fn itin_and_ein() {
assert_eq!(count("us-itin", "912-70-1234"), 1);
assert_eq!(count("us-itin", "912-69-1234"), 0);
assert_eq!(count("us-ssn", "912-70-1234"), 0);
assert_eq!(count("us-ein", "EIN: 12-3456789"), 1);
assert_eq!(count("us-ein", "part 12-3456789"), 0);
assert_eq!(count("us-ein", "EIN 07-3456789"), 0);
}
#[test]
fn routing_needs_a_word() {
assert_eq!(count("us-aba-routing", "Routing number 011000015"), 1);
assert_eq!(count("us-aba-routing", "ABA 021000021"), 1);
assert_eq!(count("us-aba-routing", "invoice 011000015"), 0);
assert_eq!(count("us-aba-routing", "routing 011000016"), 0);
}
#[test]
fn licenses() {
assert_eq!(count("us-drivers-license", "Driver's license: D1234567"), 1);
assert_eq!(count("us-drivers-license", "DL# S123-456-78-901-0"), 1);
assert_eq!(count("us-drivers-license", "Order D1234567"), 0);
}
#[test]
fn health_identifiers() {
// CMS's own MBI example
assert_eq!(count("us-mbi", "Medicare 1EG4-TE5-MK73"), 1);
assert_eq!(count("us-mbi", "1EG4TE5MK73"), 1);
assert_eq!(count("us-mbi", "1EG4-TE5-MK7S"), 0);
// CMS's NPI example
assert_eq!(count("us-npi", "NPI 1234567893"), 1);
assert_eq!(count("us-npi", "NPI 1234567894"), 0);
assert_eq!(count("us-npi", "call 1234567893"), 0);
assert_eq!(count("us-dea", "DEA AB1234563"), 1);
assert_eq!(count("us-dea", "AB1234564"), 0);
}
}
+695
View File
@@ -0,0 +1,695 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Evaluating rules against a message (§2.1–§2.4). Rules are compiled once,
//! when they change: word lists become automata, patterns regexes. A message
//! is then checked against every enabled rule in order; each detector runs
//! at most once per message, and only when some rule asks for it.
//!
//! Pure: the caller parses the message, extracts attachment text
//! ([`super::extract`]) and knows the sender's groups and tenant. What comes
//! back is which rules matched, with each detector's count, and what DLP
//! decided; the matched text itself never leaves here (§2.7).
use super::{
detectors::{self, Findings},
extract::Extracted,
rules::{Action, Condition, Direction, Kind, Rule},
words::{Pattern, WordList},
};
use ahash::AHashMap;
use std::borrow::Cow;
/// Who sent a message, and to whom.
#[derive(Debug, Clone, Default)]
pub struct Envelope<'a> {
/// Outgoing (an authenticated sender) or incoming.
pub outgoing: bool,
pub sender: &'a str,
pub sender_groups: &'a [u32],
pub sender_tenant: Option<u32>,
pub recipients: Vec<Recipient<'a>>,
}
#[derive(Debug, Clone, Default)]
pub struct Recipient<'a> {
pub address: &'a str,
/// At a domain this server hosts.
pub local: bool,
pub groups: &'a [u32],
}
#[derive(Debug, Clone)]
pub struct Attachment<'a> {
pub name: Option<&'a str>,
/// Declared type, or detected where the caller knows better.
pub content_type: &'a str,
pub size: u64,
pub extracted: Extracted,
}
/// What rules look at.
#[derive(Debug, Clone, Default)]
pub struct Content<'a> {
pub subject: &'a str,
/// Each text and HTML part, as text.
pub bodies: Vec<Cow<'a, str>>,
pub headers: Vec<(&'a str, &'a str)>,
pub attachments: Vec<Attachment<'a>>,
pub size: u64,
/// Text past the inspection limit wasn't read.
pub truncated: bool,
}
impl Content<'_> {
fn texts(&self) -> impl Iterator<Item = &str> {
std::iter::once(self.subject)
.chain(self.bodies.iter().map(|b| b.as_ref()))
.chain(self.attachments.iter().filter_map(|a| match &a.extracted {
Extracted::Text(text) => Some(text.as_str()),
_ => None,
}))
}
fn cant_be_inspected(&self) -> bool {
self.truncated
|| self
.attachments
.iter()
.any(|a| matches!(a.extracted, Extracted::NotInspectable(_)))
}
}
enum Check {
Plain(Condition),
Words(WordList, u32),
Pattern(Pattern, u32),
Header {
name: String,
contains: Option<String>,
matches: Option<Pattern>,
},
AttachmentName(Pattern),
}
struct CompiledRule {
rule: Rule,
conditions: Vec<Check>,
exceptions: Vec<Check>,
}
/// The enabled rules, ready to run.
pub struct Compiled {
rules: Vec<CompiledRule>,
}
/// A rule reference, for notices and the audit record.
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct RuleRef {
pub id: u32,
pub name: String,
pub notice: String,
}
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct Match {
pub rule_id: u32,
pub name: String,
pub kind: Kind,
pub actions: Vec<Action>,
/// Each detector (or `words`, `pattern`) that counted, and its count.
pub counts: Vec<(String, usize)>,
}
#[derive(Debug, Default)]
pub struct Outcome {
pub matched: Vec<Match>,
pub blocks: Vec<RuleRef>,
pub holds: Vec<(RuleRef, bool)>,
pub warns: Vec<RuleRef>,
}
/// What DLP decided, strictest first (§2.4).
#[derive(Debug, Clone, PartialEq, Eq)]
pub enum Decision {
Pass,
Block(Vec<RuleRef>),
Hold {
rules: Vec<RuleRef>,
notify_sender: bool,
},
Warn(Vec<RuleRef>),
}
impl Outcome {
/// Block beats hold beats warn. An override (§2.5) answers the warnings
/// only: a block or hold still applies.
pub fn decision(&self, overridden: bool) -> Decision {
if !self.blocks.is_empty() {
Decision::Block(self.blocks.clone())
} else if !self.holds.is_empty() {
Decision::Hold {
rules: self.holds.iter().map(|(r, _)| r.clone()).collect(),
notify_sender: self.holds.iter().any(|(_, notify)| *notify),
}
} else if !self.warns.is_empty() && !overridden {
Decision::Warn(self.warns.clone())
} else {
Decision::Pass
}
}
}
fn compile_check(condition: &Condition) -> Result<Check, String> {
Ok(match condition {
Condition::Words { words, at_least } => Check::Words(WordList::new(words)?, *at_least),
Condition::Pattern { pattern, at_least } => {
Check::Pattern(Pattern::new(pattern)?, *at_least)
}
Condition::Header {
name,
contains,
matches,
} => Check::Header {
name: name.to_ascii_lowercase(),
contains: contains.as_ref().map(|c| c.to_lowercase()),
matches: matches.as_deref().map(Pattern::new).transpose()?,
},
Condition::AttachmentName { pattern } => Check::AttachmentName(Pattern::new(pattern)?),
other => Check::Plain(other.clone()),
})
}
impl Compiled {
/// Compiles the enabled rules; one that no longer compiles (a detector
/// renamed since it was saved) is skipped and named in the second list.
pub fn new(rules: &[Rule]) -> (Self, Vec<(u32, String)>) {
let mut compiled = Vec::new();
let mut skipped = Vec::new();
for rule in rules.iter().filter(|r| r.enabled) {
let result = rule.validate().map_err(|e| e.reason).and_then(|_| {
Ok(CompiledRule {
rule: rule.clone(),
conditions: rule
.conditions
.iter()
.map(compile_check)
.collect::<Result<_, _>>()?,
exceptions: rule
.exceptions
.iter()
.map(compile_check)
.collect::<Result<_, _>>()?,
})
});
match result {
Ok(c) => compiled.push(c),
Err(reason) => skipped.push((rule.id, reason)),
}
}
compiled.sort_by_key(|c| (c.rule.priority, c.rule.id));
(Self { rules: compiled }, skipped)
}
pub fn is_empty(&self) -> bool {
self.rules.is_empty()
}
/// Whether any rule could apply to mail going this way, so a caller can
/// skip parsing when none can.
pub fn applies_to(&self, outgoing: bool) -> bool {
self.rules
.iter()
.any(|c| direction_matches(c.rule.direction, outgoing))
}
pub fn evaluate(&self, envelope: &Envelope<'_>, content: &Content<'_>) -> Outcome {
let mut state = State {
content,
detected: AHashMap::new(),
};
let mut outcome = Outcome::default();
for compiled in &self.rules {
let rule = &compiled.rule;
if !direction_matches(rule.direction, envelope.outgoing) {
continue;
}
let mut counts = Vec::new();
let all_match = compiled
.conditions
.iter()
.all(|check| state.check(check, envelope, &mut counts));
if !all_match {
continue;
}
let mut ignored = Vec::new();
if compiled
.exceptions
.iter()
.any(|check| state.check(check, envelope, &mut ignored))
{
continue;
}
for action in &rule.actions {
let reference = |notice: &str| RuleRef {
id: rule.id,
name: rule.name.clone(),
notice: notice.to_string(),
};
match action {
Action::Block { notice } => outcome.blocks.push(reference(notice)),
Action::Hold {
notice,
notify_sender,
} => outcome.holds.push((reference(notice), *notify_sender)),
Action::Warn { notice } => outcome.warns.push(reference(notice)),
_ => {}
}
}
outcome.matched.push(Match {
rule_id: rule.id,
name: rule.name.clone(),
kind: rule.kind,
actions: rule.actions.clone(),
counts,
});
if rule.stop_processing {
break;
}
}
outcome
}
}
fn direction_matches(direction: Direction, outgoing: bool) -> bool {
match direction {
Direction::Any => true,
Direction::Outgoing => outgoing,
Direction::Incoming => !outgoing,
}
}
fn domain_of(address: &str) -> &str {
address.rsplit_once('@').map_or("", |(_, d)| d)
}
fn in_list(value: &str, list: &[String]) -> bool {
list.iter().any(|v| v.eq_ignore_ascii_case(value))
}
struct State<'c, 'a> {
content: &'c Content<'a>,
/// Each detector's count, run once per message.
detected: AHashMap<&'static str, usize>,
}
impl State<'_, '_> {
fn detector_count(&mut self, id: &str) -> usize {
let Some(detector) = detectors::by_id(id) else {
return 0;
};
if let Some(count) = self.detected.get(detector.id) {
return *count;
}
let mut findings = Findings::default();
for text in self.content.texts() {
detector.find(text, &mut findings);
}
self.detected.insert(detector.id, findings.len());
findings.len()
}
fn check(
&mut self,
check: &Check,
envelope: &Envelope<'_>,
counts: &mut Vec<(String, usize)>,
) -> bool {
let content = self.content;
match check {
Check::Words(list, at_least) => {
let n: usize = content.texts().map(|t| list.count(t)).sum();
counts.push(("words".into(), n));
n >= *at_least as usize
}
Check::Pattern(pattern, at_least) => {
let n: usize = content.texts().map(|t| pattern.count(t)).sum();
counts.push(("pattern".into(), n));
n >= *at_least as usize
}
Check::Header {
name,
contains,
matches,
} => content
.headers
.iter()
.filter(|(n, _)| n.eq_ignore_ascii_case(name))
.any(|(_, value)| match (contains, matches) {
(Some(needle), _) => value.to_lowercase().contains(needle.as_str()),
(_, Some(pattern)) => pattern.count(value) > 0,
_ => true,
}),
Check::AttachmentName(pattern) => content
.attachments
.iter()
.any(|a| a.name.is_some_and(|n| pattern.count(n) > 0)),
Check::Plain(condition) => match condition {
Condition::SenderAddress { addresses } => in_list(envelope.sender, addresses),
Condition::SenderDomain { domains } => in_list(domain_of(envelope.sender), domains),
Condition::SenderGroup { groups } => {
envelope.sender_groups.iter().any(|g| groups.contains(g))
}
Condition::SenderTenant { tenants } => {
envelope.sender_tenant.is_some_and(|t| tenants.contains(&t))
}
Condition::RecipientAddress { addresses } => envelope
.recipients
.iter()
.any(|r| in_list(r.address, addresses)),
Condition::RecipientDomain { domains } => envelope
.recipients
.iter()
.any(|r| in_list(domain_of(r.address), domains)),
Condition::RecipientGroup { groups } => envelope
.recipients
.iter()
.any(|r| r.groups.iter().any(|g| groups.contains(g))),
Condition::RecipientOutside => envelope.recipients.iter().any(|r| !r.local),
Condition::AttachmentType { types } => content.attachments.iter().any(|a| {
let ct = a.content_type.to_ascii_lowercase();
types
.iter()
.any(|t| ct.starts_with(&t.to_ascii_lowercase()))
}),
Condition::AttachmentExtension { extensions } => {
content.attachments.iter().any(|a| {
a.name
.and_then(|n| n.rsplit_once('.'))
.is_some_and(|(_, ext)| {
extensions
.iter()
.any(|e| e.trim_start_matches('.').eq_ignore_ascii_case(ext))
})
})
}
Condition::AttachmentSizeOver { bytes } => {
content.attachments.iter().any(|a| a.size > *bytes)
}
Condition::AttachmentCountOver { count } => {
content.attachments.len() > *count as usize
}
Condition::CantBeInspected => content.cant_be_inspected(),
Condition::MessageSizeOver { bytes } => content.size > *bytes,
Condition::Detected { detectors } => {
let mut any = false;
for d in detectors {
let n = self.detector_count(&d.id);
counts.push((d.id.clone(), n));
any |= n >= d.at_least as usize;
}
any
}
// Compiled into their own checks
Condition::Words { .. }
| Condition::Pattern { .. }
| Condition::Header { .. }
| Condition::AttachmentName { .. } => false,
},
}
}
}
#[cfg(test)]
mod tests {
use super::*;
use crate::mailflow::{
extract::Why,
rules::{DetectorMin, Position},
};
fn rule(id: u32, kind: Kind, conditions: Vec<Condition>, action: Action) -> Rule {
Rule {
id,
name: format!("rule {id}"),
description: String::new(),
kind,
enabled: true,
priority: id as i32,
direction: if kind == Kind::Dlp {
Direction::Outgoing
} else {
Direction::Any
},
conditions,
exceptions: vec![],
actions: vec![action],
stop_processing: false,
created_by: String::new(),
created_at: 0,
updated_at: 0,
}
}
fn envelope(outside: bool) -> Envelope<'static> {
Envelope {
outgoing: true,
sender: "[email protected]",
sender_groups: &[7],
sender_tenant: None,
recipients: vec![Recipient {
address: if outside {
"[email protected]"
} else {
"[email protected]"
},
local: !outside,
groups: &[],
}],
}
}
fn cards(n: usize) -> Content<'static> {
let body: String = [
"4242 4242 4242 4242",
"5555-5555-5555-4444",
"378282246310005",
"6011111111111117",
"3566002020360505",
]
.iter()
.take(n)
.map(|c| format!("card {c}\n"))
.collect();
Content {
subject: "Numbers",
bodies: vec![body.into()],
..Default::default()
}
}
fn five_cards_outside(action: Action) -> Rule {
rule(
1,
Kind::Dlp,
vec![
Condition::RecipientOutside,
Condition::Detected {
detectors: vec![DetectorMin {
id: "payment-card".into(),
at_least: 5,
}],
},
],
action,
)
}
#[test]
fn detector_threshold_and_recipients() {
let (rules, skipped) = Compiled::new(&[five_cards_outside(Action::Hold {
notice: "Held".into(),
notify_sender: true,
})]);
assert!(skipped.is_empty());
let outcome = rules.evaluate(&envelope(true), &cards(5));
assert_eq!(
outcome.matched[0].counts,
vec![("payment-card".to_string(), 5)]
);
assert!(matches!(
outcome.decision(false),
Decision::Hold {
notify_sender: true,
..
}
));
// Four cards, or everyone inside: nothing
assert_eq!(
rules.evaluate(&envelope(true), &cards(4)).decision(false),
Decision::Pass
);
assert_eq!(
rules.evaluate(&envelope(false), &cards(5)).decision(false),
Decision::Pass
);
}
#[test]
fn strictest_wins_and_override_answers_warnings_only() {
let warn = five_cards_outside(Action::Warn {
notice: "Sure?".into(),
});
let mut block = five_cards_outside(Action::Block {
notice: "No".into(),
});
block.id = 2;
let (rules, _) = Compiled::new(&[warn.clone(), block]);
let outcome = rules.evaluate(&envelope(true), &cards(5));
assert!(matches!(outcome.decision(true), Decision::Block(_)));
let (rules, _) = Compiled::new(&[warn]);
let outcome = rules.evaluate(&envelope(true), &cards(5));
assert!(matches!(outcome.decision(false), Decision::Warn(ref w) if w[0].notice == "Sure?"));
assert_eq!(outcome.decision(true), Decision::Pass);
}
#[test]
fn exceptions_order_and_stop_processing() {
let disclaimer = |id| {
rule(
id,
Kind::Transport,
vec![Condition::RecipientOutside],
Action::AddDisclaimer {
text: "t".into(),
html: None,
position: Position::Bottom,
},
)
};
let mut first = disclaimer(1);
first.stop_processing = true;
let (rules, _) = Compiled::new(&[disclaimer(2), first.clone()]);
let outcome = rules.evaluate(&envelope(true), &cards(0));
assert_eq!(
outcome
.matched
.iter()
.map(|m| m.rule_id)
.collect::<Vec<_>>(),
vec![1]
);
first.stop_processing = false;
first.exceptions = vec![Condition::SenderGroup { groups: vec![7] }];
let (rules, _) = Compiled::new(&[disclaimer(2), first]);
let outcome = rules.evaluate(&envelope(true), &cards(0));
assert_eq!(
outcome
.matched
.iter()
.map(|m| m.rule_id)
.collect::<Vec<_>>(),
vec![2]
);
}
#[test]
fn content_conditions() {
let content = Content {
subject: "Project Falcon",
bodies: vec!["see attached".into()],
headers: vec![("X-Class", "Internal only")],
attachments: vec![
Attachment {
name: Some("plan.docx"),
content_type: "application/vnd.openxmlformats-officedocument.wordprocessingml.document",
size: 40_000,
extracted: Extracted::Text("IBAN GB29 NWBK 6016 1331 9268 19".into()),
},
Attachment {
name: Some("scan.pdf"),
content_type: "application/pdf",
size: 900_000,
extracted: Extracted::NotInspectable(Why::Pdf),
},
],
size: 1_000_000,
truncated: false,
};
let block = || Action::Block { notice: "n".into() };
let checks = [
(
Condition::Words {
words: vec!["project falcon".into()],
at_least: 1,
},
true,
),
(
Condition::Header {
name: "x-class".into(),
contains: Some("internal".into()),
matches: None,
},
true,
),
(
Condition::AttachmentExtension {
extensions: vec![".PDF".into()],
},
true,
),
(
Condition::AttachmentType {
types: vec!["image/".into()],
},
false,
),
(Condition::AttachmentSizeOver { bytes: 500_000 }, true),
(Condition::AttachmentCountOver { count: 2 }, false),
(Condition::CantBeInspected, true),
(Condition::MessageSizeOver { bytes: 2_000_000 }, false),
(
Condition::Detected {
detectors: vec![DetectorMin {
id: "iban".into(),
at_least: 1,
}],
},
true,
),
(
Condition::SenderDomain {
domains: vec!["EXAMPLE.com".into()],
},
true,
),
];
for (condition, expected) in checks {
let (rules, skipped) =
Compiled::new(&[rule(1, Kind::Dlp, vec![condition.clone()], block())]);
assert!(skipped.is_empty(), "{condition:?}");
let matched = !rules.evaluate(&envelope(true), &content).matched.is_empty();
assert_eq!(matched, expected, "{condition:?}");
}
}
#[test]
fn direction_and_disabled_rules() {
let mut r = five_cards_outside(Action::Block { notice: "n".into() });
let (rules, _) = Compiled::new(std::slice::from_ref(&r));
assert!(rules.applies_to(true) && !rules.applies_to(false));
let mut incoming = envelope(true);
incoming.outgoing = false;
assert_eq!(
rules.evaluate(&incoming, &cards(5)).decision(false),
Decision::Pass
);
r.enabled = false;
assert!(Compiled::new(&[r]).0.is_empty());
}
}
+694
View File
@@ -0,0 +1,694 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! The text of an attachment, for the detectors (§2.3), or why there isn't
//! one.
//!
//! Read: text files (plain, CSV, JSON, XML, HTML), Office Open XML (DOCX,
//! XLSX, PPTX) and OpenDocument (ODT, ODS, ODP) documents, and ZIP archives
//! one level deep. **Can't be inspected**: encrypted or password-protected
//! files, PDF (settled answer 2), the older binary Office formats, archives
//! inside archives, and anything past the limits. Everything else (images,
//! audio, programs) has no text to read and is neither.
//!
//! Office files are ZIP archives of XML, read here with the `zip` and
//! `quick-xml` crates the server already uses: no outside converter runs.
use quick_xml::{Reader, XmlVersion, events::Event};
use std::io::{Cursor, Read};
/// How much may be unpacked from one attachment, and from how many entries.
#[derive(Debug, Clone, Copy)]
pub struct Limits {
pub max_unpacked: u64,
pub max_entries: usize,
}
impl Default for Limits {
fn default() -> Self {
Self {
max_unpacked: 50 * 1024 * 1024,
max_entries: 10_000,
}
}
}
#[derive(Debug, Clone, PartialEq, Eq)]
pub enum Extracted {
/// The text to check.
Text(String),
/// A kind of file with no text in it: nothing to check, nothing missed.
NoText,
/// A file that may hold text the detectors couldn't read.
NotInspectable(Why),
}
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub enum Why {
Encrypted,
Pdf,
LegacyOffice,
NestedArchive,
TooLarge,
Damaged,
}
impl Why {
pub fn as_str(&self) -> &'static str {
match self {
Why::Encrypted => "encrypted",
Why::Pdf => "pdf",
Why::LegacyOffice => "legacy-office",
Why::NestedArchive => "nested-archive",
Why::TooLarge => "too-large",
Why::Damaged => "damaged",
}
}
}
const OLE_MAGIC: &[u8] = &[0xD0, 0xCF, 0x11, 0xE0, 0xA1, 0xB1, 0x1A, 0xE1];
const ZIP_MAGIC: &[u8] = b"PK\x03\x04";
/// What an attachment says, from its declared type, its file name and, above
/// all, its first bytes.
pub fn extract(
content_type: &str,
file_name: Option<&str>,
data: &[u8],
limits: &Limits,
) -> Extracted {
extract_at(content_type, file_name, data, limits, 0)
}
fn extract_at(
content_type: &str,
file_name: Option<&str>,
data: &[u8],
limits: &Limits,
depth: u8,
) -> Extracted {
let content_type = content_type.to_ascii_lowercase();
let extension = file_name
.and_then(|name| name.rsplit_once('.'))
.map(|(_, ext)| ext.to_ascii_lowercase())
.unwrap_or_default();
if data.len() as u64 > limits.max_unpacked {
return Extracted::NotInspectable(Why::TooLarge);
}
if data.starts_with(b"%PDF-") || content_type == "application/pdf" || extension == "pdf" {
return Extracted::NotInspectable(Why::Pdf);
}
if data.starts_with(OLE_MAGIC) {
// An encrypted OOXML file is an OLE container holding the encrypted
// package; any other OLE file is a legacy .doc, .xls or .ppt
return Extracted::NotInspectable(if has_utf16(data, "EncryptedPackage") {
Why::Encrypted
} else {
Why::LegacyOffice
});
}
if data.starts_with(ZIP_MAGIC) {
if depth > 0 {
return Extracted::NotInspectable(Why::NestedArchive);
}
return zip(data, limits);
}
if is_text(&content_type, &extension) {
let text = decode_text(data);
return Extracted::Text(
if content_type == "text/html" || matches!(extension.as_str(), "html" | "htm") {
strip_html(&text)
} else {
text
},
);
}
Extracted::NoText
}
fn is_text(content_type: &str, extension: &str) -> bool {
content_type.starts_with("text/")
|| matches!(
content_type,
"application/json"
| "application/xml"
| "application/csv"
| "application/x-csv"
| "message/rfc822"
)
|| matches!(
extension,
"txt"
| "csv"
| "tsv"
| "json"
| "xml"
| "md"
| "log"
| "html"
| "htm"
| "eml"
| "ics"
| "vcf"
)
}
/// UTF-16 with a byte order mark, else UTF-8 (lossy).
fn decode_text(data: &[u8]) -> String {
let utf16 = |bytes: &[u8], big: bool| {
let units: Vec<u16> = bytes
.as_chunks::<2>()
.0
.iter()
.map(|&c| {
if big {
u16::from_be_bytes(c)
} else {
u16::from_le_bytes(c)
}
})
.collect();
String::from_utf16_lossy(&units)
};
match data {
[0xFF, 0xFE, rest @ ..] => utf16(rest, false),
[0xFE, 0xFF, rest @ ..] => utf16(rest, true),
[0xEF, 0xBB, 0xBF, rest @ ..] => String::from_utf8_lossy(rest).into_owned(),
_ => String::from_utf8_lossy(data).into_owned(),
}
}
fn has_utf16(data: &[u8], needle: &str) -> bool {
let needle: Vec<u8> = needle.encode_utf16().flat_map(u16::to_le_bytes).collect();
data.windows(needle.len()).any(|w| w == needle.as_slice())
}
/// Tags out, the common entities decoded, block ends as new lines.
fn strip_html(html: &str) -> String {
let mut out = String::with_capacity(html.len());
let mut in_tag = false;
let mut skip_until: Option<&str> = None;
let lower = html.to_ascii_lowercase();
let mut i = 0;
let bytes = html.as_bytes();
while i < bytes.len() {
if let Some(end) = skip_until {
match lower[i..].find(end) {
Some(at) => {
i += at + end.len();
skip_until = None;
}
None => break,
}
continue;
}
let c = bytes[i];
if in_tag {
if c == b'>' {
in_tag = false;
}
i += 1;
continue;
}
if c == b'<' {
if lower[i..].starts_with("<script") {
skip_until = Some("</script>");
} else if lower[i..].starts_with("<style") {
skip_until = Some("</style>");
} else {
if [
"<br", "<p", "</p", "<div", "</div", "<tr", "<li", "<td", "<th",
]
.iter()
.any(|t| lower[i..].starts_with(t))
{
out.push(
if lower[i..].starts_with("<td") || lower[i..].starts_with("<th") {
'\t'
} else {
'\n'
},
);
}
in_tag = true;
}
i += 1;
continue;
}
// Copy up to the next tag
let next = html[i..].find('<').map_or(html.len(), |at| i + at);
out.push_str(&html[i..next]);
i = next;
}
for (entity, text) in [
("&nbsp;", " "),
("&lt;", "<"),
("&gt;", ">"),
("&quot;", "\""),
("&#39;", "'"),
("&amp;", "&"),
] {
out = out.replace(entity, text);
}
out
}
/// A ZIP file: an Office document, an OpenDocument, or an archive.
fn zip(data: &[u8], limits: &Limits) -> Extracted {
let Ok(mut archive) = zip::ZipArchive::new(Cursor::new(data)) else {
return Extracted::NotInspectable(Why::Damaged);
};
if archive.len() > limits.max_entries {
return Extracted::NotInspectable(Why::TooLarge);
}
let mut names = Vec::with_capacity(archive.len());
let mut declared: u64 = 0;
for i in 0..archive.len() {
let Ok(entry) = archive.by_index_raw(i) else {
return Extracted::NotInspectable(Why::Damaged);
};
if entry.encrypted() {
return Extracted::NotInspectable(Why::Encrypted);
}
declared = declared.saturating_add(entry.size());
names.push(entry.name().to_string());
}
if declared > limits.max_unpacked {
return Extracted::NotInspectable(Why::TooLarge);
}
let mut budget = limits.max_unpacked;
let mut read =
|archive: &mut zip::ZipArchive<Cursor<&[u8]>>, name: &str| -> Result<Vec<u8>, Why> {
let entry = archive.by_name(name).map_err(|_| Why::Damaged)?;
let mut bytes = Vec::new();
// Declared sizes can lie: stop at the budget whatever they say
entry
.take(budget + 1)
.read_to_end(&mut bytes)
.map_err(|_| Why::Damaged)?;
if bytes.len() as u64 > budget {
return Err(Why::TooLarge);
}
budget -= bytes.len() as u64;
Ok(bytes)
};
let has = |name: &str| names.iter().any(|n| n == name);
let mut text = String::new();
let result: Result<(), Why> = (|| {
if has("[Content_Types].xml") {
// Office Open XML: the parts that hold what a person wrote
let mut shared = Vec::new();
if has("xl/sharedStrings.xml") {
shared = xml_strings(&read(&mut archive, "xl/sharedStrings.xml")?, "si");
}
for name in names.iter().filter(|n| ooxml_text_part(n)) {
let xml = read(&mut archive, name)?;
if name.starts_with("xl/worksheets/") {
xlsx_sheet(&xml, &mut text);
} else {
xml_text(&xml, &mut text);
}
text.push('\n');
}
text.extend(shared.iter().map(|s| format!("{s}\n")));
} else if names.first().is_some_and(|n| n == "mimetype")
&& read(&mut archive, "mimetype")?.starts_with(b"application/vnd.oasis.opendocument")
{
// OpenDocument: an encrypted one says so in its manifest
if has("META-INF/manifest.xml")
&& contains(
&read(&mut archive, "META-INF/manifest.xml")?,
b"encryption-data",
)
{
return Err(Why::Encrypted);
}
for name in ["content.xml", "styles.xml"] {
if has(name) {
xml_text(&read(&mut archive, name)?, &mut text);
text.push('\n');
}
}
} else {
// An archive: each file inside, one level deep
for name in names.iter().filter(|n| !n.ends_with('/')) {
let bytes = read(&mut archive, name)?;
match extract_at("", Some(name), &bytes, limits, 1) {
Extracted::Text(inner) => {
text.push_str(&inner);
text.push('\n');
}
Extracted::NoText => {}
Extracted::NotInspectable(why) => return Err(why),
}
}
}
Ok(())
})();
match result {
Ok(()) => Extracted::Text(text),
Err(why) => Extracted::NotInspectable(why),
}
}
fn ooxml_text_part(name: &str) -> bool {
let xml = name.ends_with(".xml");
xml && (name == "word/document.xml"
|| [
"word/header",
"word/footer",
"word/footnotes",
"word/endnotes",
"word/comments",
]
.iter()
.any(|p| name.starts_with(p))
|| name.starts_with("xl/worksheets/sheet")
|| name.starts_with("ppt/slides/slide")
|| name.starts_with("ppt/notesSlides/"))
}
fn contains(haystack: &[u8], needle: &[u8]) -> bool {
haystack.windows(needle.len()).any(|w| w == needle)
}
/// The local name of a tag, without its namespace prefix.
fn local(name: &[u8]) -> &[u8] {
name.rsplit(|b| *b == b':').next().unwrap_or(name)
}
fn push_entity(entity: &[u8], out: &mut String) {
match entity {
b"lt" => out.push('<'),
b"gt" => out.push('>'),
b"amp" => out.push('&'),
b"apos" => out.push('\''),
b"quot" => out.push('"'),
_ => {
let code = match entity {
[b'#', b'x' | b'X', hex @ ..] => std::str::from_utf8(hex)
.ok()
.and_then(|h| u32::from_str_radix(h, 16).ok()),
[b'#', dec @ ..] => std::str::from_utf8(dec).ok().and_then(|d| d.parse().ok()),
_ => None,
};
if let Some(c) = code.and_then(char::from_u32) {
out.push(c);
}
}
}
}
/// Every text node, runs joined as written, a new line after each paragraph
/// or row and a tab after each cell, so a number split across runs is whole
/// again.
fn xml_text(xml: &[u8], out: &mut String) {
let mut reader = Reader::from_reader(xml);
let mut buf = Vec::new();
loop {
match reader.read_event_into(&mut buf) {
Ok(Event::Text(t)) => {
if let Ok(text) = t.xml_content(XmlVersion::Implicit1_0) {
out.push_str(&text);
}
}
Ok(Event::CData(t)) => out.push_str(&String::from_utf8_lossy(&t)),
Ok(Event::GeneralRef(entity)) => push_entity(&entity, out),
Ok(Event::End(e)) => match local(e.name().as_ref()) {
b"p" | b"h" | b"tr" | b"row" | b"table-row" | b"br" => out.push('\n'),
b"tc" | b"c" | b"table-cell" | b"tab" => out.push('\t'),
_ => {}
},
Ok(Event::Empty(e)) => match local(e.name().as_ref()) {
b"br" | b"line-break" => out.push('\n'),
b"tab" | b"s" => out.push(' '),
_ => {}
},
Ok(Event::Eof) | Err(_) => break,
_ => {}
}
buf.clear();
}
}
/// The text of each `item` element (a shared string in XLSX).
fn xml_strings(xml: &[u8], item: &str) -> Vec<String> {
let mut reader = Reader::from_reader(xml);
let mut buf = Vec::new();
let mut items = Vec::new();
let mut current: Option<String> = None;
loop {
match reader.read_event_into(&mut buf) {
Ok(Event::Start(e)) if local(e.name().as_ref()) == item.as_bytes() => {
current = Some(String::new())
}
Ok(Event::End(e)) if local(e.name().as_ref()) == item.as_bytes() => {
items.extend(current.take());
}
Ok(Event::Text(t)) => {
if let (Some(s), Ok(text)) =
(current.as_mut(), t.xml_content(XmlVersion::Implicit1_0))
{
s.push_str(&text);
}
}
Ok(Event::GeneralRef(entity)) => {
if let Some(s) = current.as_mut() {
push_entity(&entity, s);
}
}
Ok(Event::Eof) | Err(_) => break,
_ => {}
}
buf.clear();
}
items
}
/// A worksheet's cell values: numbers and inline strings. Cells holding a
/// shared string are skipped here; the shared strings are read whole.
fn xlsx_sheet(xml: &[u8], out: &mut String) {
let mut reader = Reader::from_reader(xml);
let mut buf = Vec::new();
let mut shared_cell = false;
let mut in_value = false;
loop {
match reader.read_event_into(&mut buf) {
Ok(Event::Start(e)) => match local(e.name().as_ref()) {
b"c" => {
shared_cell = e
.attributes()
.flatten()
.any(|a| a.key.as_ref() == b"t" && a.value.as_ref() == b"s");
}
b"v" | b"t" => in_value = true,
_ => {}
},
Ok(Event::End(e)) => match local(e.name().as_ref()) {
b"v" | b"t" => in_value = false,
b"c" => out.push('\t'),
b"row" => out.push('\n'),
_ => {}
},
// A shared string's cell holds only its index: the string itself
// is added with the shared strings
Ok(Event::Text(t)) if in_value && !shared_cell => {
if let Ok(text) = t.xml_content(XmlVersion::Implicit1_0) {
out.push_str(&text);
}
}
Ok(Event::Eof) | Err(_) => break,
_ => {}
}
buf.clear();
}
}
#[cfg(test)]
mod tests {
use super::*;
use std::io::Write;
use zip::{ZipWriter, write::SimpleFileOptions};
fn zip_of(files: &[(&str, &str)]) -> Vec<u8> {
let mut zip = ZipWriter::new(Cursor::new(Vec::new()));
for (name, body) in files {
zip.start_file(*name, SimpleFileOptions::default()).unwrap();
zip.write_all(body.as_bytes()).unwrap();
}
zip.finish().unwrap().into_inner()
}
fn text_of(extracted: Extracted) -> String {
match extracted {
Extracted::Text(text) => text,
other => panic!("expected text, got {other:?}"),
}
}
#[test]
fn plain_text_and_html() {
let limits = Limits::default();
assert_eq!(
text_of(extract("text/plain", None, b"card 4242", &limits)),
"card 4242"
);
let utf16: Vec<u8> = [0xFF, 0xFE]
.into_iter()
.chain("héllo".encode_utf16().flat_map(u16::to_le_bytes))
.collect();
assert_eq!(
text_of(extract(
"application/octet-stream",
Some("a.csv"),
&utf16,
&limits
)),
"héllo"
);
let html = "<html><style>p{}</style><p>Card&nbsp;4242</p><script>x()</script><td>a</td><td>b</td></html>";
let text = text_of(extract("text/html", None, html.as_bytes(), &limits));
assert!(
text.contains("Card 4242") && !text.contains("x()") && !text.contains("p{}"),
"{text:?}"
);
assert_eq!(
extract("image/png", Some("a.png"), b"\x89PNG....", &limits),
Extracted::NoText
);
}
#[test]
fn docx_joins_split_runs() {
let doc = r#"<w:document xmlns:w="w"><w:body><w:p><w:r><w:t>Card 4242 42</w:t></w:r><w:r><w:t>42 4242 4242</w:t></w:r></w:p><w:p><w:r><w:t>A &amp; B</w:t></w:r></w:p></w:body></w:document>"#;
let docx = zip_of(&[
("[Content_Types].xml", "<Types/>"),
("word/document.xml", doc),
]);
let text = text_of(extract(
"application/vnd.openxmlformats-officedocument.wordprocessingml.document",
Some("a.docx"),
&docx,
&Limits::default(),
));
assert!(text.contains("Card 4242 4242 4242 4242\nA & B"), "{text:?}");
}
#[test]
fn xlsx_numbers_and_shared_strings() {
let sheet = r#"<worksheet><sheetData><row><c r="A1" t="s"><v>0</v></c><c r="B1"><v>4242424242424242</v></c></row></sheetData></worksheet>"#;
let shared = r#"<sst><si><t>IBAN GB29 NWBK 6016 1331 9268 19</t></si></sst>"#;
let xlsx = zip_of(&[
("[Content_Types].xml", "<Types/>"),
("xl/sharedStrings.xml", shared),
("xl/worksheets/sheet1.xml", sheet),
]);
let text = text_of(extract("", Some("book.xlsx"), &xlsx, &Limits::default()));
assert!(
text.contains("4242424242424242") && text.contains("GB29 NWBK 6016 1331 9268 19"),
"{text:?}"
);
// The shared string's index isn't read as a value
assert!(
!text.contains("\t0\t") && !text.starts_with('0'),
"{text:?}"
);
}
#[test]
fn opendocument_and_encrypted_opendocument() {
let content = r#"<office:document-content xmlns:text="t"><text:p>SSN 078-05-1120</text:p></office:document-content>"#;
let odt = zip_of(&[
("mimetype", "application/vnd.oasis.opendocument.text"),
("content.xml", content),
]);
assert!(
text_of(extract("", Some("a.odt"), &odt, &Limits::default()))
.contains("SSN 078-05-1120")
);
let manifest = r#"<manifest:manifest><manifest:file-entry><manifest:encryption-data/></manifest:file-entry></manifest:manifest>"#;
let locked = zip_of(&[
("mimetype", "application/vnd.oasis.opendocument.text"),
("META-INF/manifest.xml", manifest),
("content.xml", "x"),
]);
assert_eq!(
extract("", Some("a.odt"), &locked, &Limits::default()),
Extracted::NotInspectable(Why::Encrypted)
);
}
#[test]
fn archives() {
let limits = Limits::default();
let archive = zip_of(&[
("notes/a.txt", "card 4242424242424242"),
("b.png", "\u{89}PNG"),
]);
assert!(
text_of(extract("application/zip", Some("x.zip"), &archive, &limits))
.contains("4242424242424242")
);
let nested = zip_of(&[(
"inner.zip",
std::str::from_utf8(&[b'P', b'K', 3, 4]).unwrap(),
)]);
assert_eq!(
extract("application/zip", Some("x.zip"), &nested, &limits),
Extracted::NotInspectable(Why::NestedArchive)
);
// Password-protected
let mut zip = ZipWriter::new(Cursor::new(Vec::new()));
zip.start_file(
"secret.txt",
SimpleFileOptions::default().with_aes_encryption(zip::AesMode::Aes256, "pw"),
)
.unwrap();
zip.write_all(b"4242424242424242").unwrap();
let locked = zip.finish().unwrap().into_inner();
assert_eq!(
extract("application/zip", Some("x.zip"), &locked, &limits),
Extracted::NotInspectable(Why::Encrypted)
);
// Past the limits
let small = Limits {
max_unpacked: 10,
max_entries: 1,
};
assert_eq!(
extract("application/zip", Some("x.zip"), &archive, &small),
Extracted::NotInspectable(Why::TooLarge)
);
assert_eq!(
extract("application/zip", None, b"PK\x03\x04garbage", &limits),
Extracted::NotInspectable(Why::Damaged)
);
}
#[test]
fn not_inspectable_kinds() {
let limits = Limits::default();
assert_eq!(
extract("application/octet-stream", None, b"%PDF-1.7 ...", &limits),
Extracted::NotInspectable(Why::Pdf)
);
let mut ole = OLE_MAGIC.to_vec();
ole.extend(std::iter::repeat_n(0, 64));
assert_eq!(
extract("", Some("old.doc"), &ole, &limits),
Extracted::NotInspectable(Why::LegacyOffice)
);
ole.extend("EncryptedPackage".encode_utf16().flat_map(u16::to_le_bytes));
assert_eq!(
extract("", Some("new.docx"), &ole, &limits),
Extracted::NotInspectable(Why::Encrypted)
);
}
}
+29
View File
@@ -0,0 +1,29 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Data loss prevention and mail flow rules (dlp-and-mail-flow-rules spec).
//!
//! Mostly pure functions over text and attachment bytes, unit-tested
//! without a server:
//!
//! - [`detectors`]: find identifiers in text (payment cards, IBANs,
//! national ID numbers, keys), each by its published format and check
//! (§2.3);
//! - [`words`]: an organization's own word lists and patterns;
//! - [`extract`]: the text of an attachment, or why it can't be read;
//! - [`rules`]: what a rule is, its checks, and where rules are kept;
//! - [`engine`]: rules compiled and run against a message;
//! - [`cache`]: each node's compiled copy.
//!
//! Nothing here writes what it finds anywhere: callers get counts, and the
//! matched text never leaves the evaluation (§2.7).
pub mod cache;
pub mod detectors;
pub mod engine;
pub mod extract;
pub mod rules;
pub mod words;
+717
View File
@@ -0,0 +1,717 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Mail flow rules and DLP rules (dlp-and-mail-flow-rules spec, §2.2–§2.4):
//! what a rule is, what makes one valid, and where it's kept.
//!
//! Kept in the fork's subspace (`store::SUBSPACE_INBUXA`), never in the
//! registry, so an upstream schema import never touches them. Every key
//! starts with `R`, then one byte for the kind:
//!
//! - `r` + rule id (u32): the rule, as JSON.
//!
//! Numbers are big-endian. There are few rules, so they're read whole.
use super::{detectors, words};
use serde::{Deserialize as SerdeDeserialize, Serialize as SerdeSerialize, de::DeserializeOwned};
use store::{
Deserialize, IterateParams, SUBSPACE_INBUXA, Serialize, Store, ValueKey,
write::{AnyClass, BatchBuilder, ValueClass, assert::AssertValue},
};
use trc::AddContext;
const FEATURE: u8 = b'R';
const KIND_RULE: u8 = b'r';
const CREATE_ATTEMPTS: usize = 5;
/// Longest text a rule may carry (a notice, a disclaimer), in bytes.
const MAX_TEXT: usize = 16 * 1024;
/// Most entries in one list (words, addresses, domains).
const MAX_LIST: usize = 5_000;
#[derive(Debug, Clone, Copy, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub enum Kind {
Dlp,
Transport,
}
#[derive(Debug, Clone, Copy, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub enum Direction {
/// Mail an authenticated sender submits, over SMTP or JMAP.
Outgoing,
/// Everything else the server accepts.
Incoming,
Any,
}
#[derive(Debug, Clone, Copy, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub enum Position {
Top,
Bottom,
}
fn one() -> u32 {
1
}
/// A detector and the least it must find.
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub struct DetectorMin {
pub id: String,
#[serde(default = "one")]
pub at_least: u32,
}
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(
tag = "type",
rename_all = "camelCase",
rename_all_fields = "camelCase"
)]
pub enum Condition {
SenderAddress {
addresses: Vec<String>,
},
SenderDomain {
domains: Vec<String>,
},
SenderGroup {
groups: Vec<u32>,
},
SenderTenant {
tenants: Vec<u32>,
},
/// Any recipient is one of these.
RecipientAddress {
addresses: Vec<String>,
},
RecipientDomain {
domains: Vec<String>,
},
RecipientGroup {
groups: Vec<u32>,
},
/// Any recipient isn't at a domain this server hosts.
RecipientOutside,
/// Words or phrases in the subject, body or readable attachments.
Words {
words: Vec<String>,
#[serde(default = "one")]
at_least: u32,
},
/// The organization's regular expression, in the same places.
Pattern {
pattern: String,
#[serde(default = "one")]
at_least: u32,
},
/// A header exists, or its value contains or matches.
Header {
name: String,
#[serde(default)]
contains: Option<String>,
#[serde(default)]
matches: Option<String>,
},
/// An attachment's declared or detected type starts with one of these.
AttachmentType {
types: Vec<String>,
},
AttachmentExtension {
extensions: Vec<String>,
},
AttachmentName {
pattern: String,
},
AttachmentSizeOver {
bytes: u64,
},
AttachmentCountOver {
count: u32,
},
/// An attachment is encrypted, a PDF, a legacy Office file, an archive
/// inside an archive, or past the inspection limit.
CantBeInspected,
MessageSizeOver {
bytes: u64,
},
/// Any of these detectors finds at least its minimum (DLP rules only).
Detected {
detectors: Vec<DetectorMin>,
},
}
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(
tag = "type",
rename_all = "camelCase",
rename_all_fields = "camelCase"
)]
pub enum Action {
// Transport actions
AddDisclaimer {
text: String,
#[serde(default)]
html: Option<String>,
position: Position,
},
AddHeader {
name: String,
value: String,
},
RemoveHeader {
name: String,
},
PrefixSubject {
text: String,
},
AddRecipient {
address: String,
},
Redirect {
addresses: Vec<String>,
},
Refuse {
text: String,
},
Route {
queue: String,
},
// DLP actions
Block {
notice: String,
},
Warn {
notice: String,
},
Hold {
notice: String,
#[serde(default)]
notify_sender: bool,
},
}
impl Action {
pub fn is_dlp(&self) -> bool {
matches!(
self,
Action::Block { .. } | Action::Warn { .. } | Action::Hold { .. }
)
}
}
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub struct Rule {
#[serde(default)]
pub id: u32,
pub name: String,
#[serde(default)]
pub description: String,
pub kind: Kind,
#[serde(default = "enabled")]
pub enabled: bool,
#[serde(default)]
pub priority: i32,
pub direction: Direction,
#[serde(default)]
pub conditions: Vec<Condition>,
#[serde(default)]
pub exceptions: Vec<Condition>,
pub actions: Vec<Action>,
#[serde(default)]
pub stop_processing: bool,
#[serde(default)]
pub created_by: String,
#[serde(default)]
pub created_at: u64,
#[serde(default)]
pub updated_at: u64,
}
fn enabled() -> bool {
true
}
/// Why a rule can't be saved: the property at fault, and a sentence.
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct Invalid {
pub property: &'static str,
pub reason: String,
}
fn invalid(property: &'static str, reason: impl Into<String>) -> Invalid {
Invalid {
property,
reason: reason.into(),
}
}
impl Rule {
/// Everything that can be checked without the rest of the server: the
/// shape (§2.2, §2.4), the detectors, word lists and patterns.
pub fn validate(&self) -> Result<(), Invalid> {
if self.name.trim().is_empty() {
return Err(invalid("name", "A rule needs a name."));
}
if self.name.len() > 200 || self.description.len() > MAX_TEXT {
return Err(invalid("name", "The name or description is too long."));
}
if self.actions.is_empty() {
return Err(invalid("actions", "A rule needs something to do."));
}
let dlp_actions = self.actions.iter().filter(|a| a.is_dlp()).count();
match self.kind {
Kind::Dlp => {
if self.direction != Direction::Outgoing {
return Err(invalid("direction", "DLP rules check outgoing mail only."));
}
if dlp_actions != 1 || self.actions.len() != 1 {
return Err(invalid(
"actions",
"A DLP rule has exactly one action: block, warn or hold.",
));
}
}
Kind::Transport => {
if dlp_actions > 0 {
return Err(invalid(
"actions",
"Block, warn and hold belong to DLP rules.",
));
}
if self
.conditions
.iter()
.chain(&self.exceptions)
.any(|c| matches!(c, Condition::Detected { .. }))
{
return Err(invalid("conditions", "Detectors belong to DLP rules."));
}
}
}
for (property, list) in [
("conditions", &self.conditions),
("exceptions", &self.exceptions),
] {
for condition in list {
validate_condition(condition).map_err(|reason| invalid(property, reason))?;
}
}
for action in &self.actions {
validate_action(action).map_err(|reason| invalid("actions", reason))?;
}
Ok(())
}
}
fn nonempty_list<T>(list: &[T], what: &str) -> Result<(), String> {
if list.is_empty() {
Err(format!("The {what} list is empty."))
} else if list.len() > MAX_LIST {
Err(format!(
"The {what} list is longer than {MAX_LIST} entries."
))
} else {
Ok(())
}
}
fn header_name(name: &str) -> Result<(), String> {
if !name.is_empty()
&& name.len() <= 100
&& name.bytes().all(|b| b.is_ascii_graphic() && b != b':')
{
Ok(())
} else {
Err(format!("\"{name}\" isn't a header name."))
}
}
fn text(value: &str, what: &str) -> Result<(), String> {
if value.trim().is_empty() {
Err(format!("The {what} is empty."))
} else if value.len() > MAX_TEXT {
Err(format!("The {what} is longer than {MAX_TEXT} bytes."))
} else {
Ok(())
}
}
fn validate_condition(condition: &Condition) -> Result<(), String> {
match condition {
Condition::SenderAddress { addresses } | Condition::RecipientAddress { addresses } => {
nonempty_list(addresses, "address")
}
Condition::SenderDomain { domains } | Condition::RecipientDomain { domains } => {
nonempty_list(domains, "domain")
}
Condition::SenderGroup { groups } | Condition::RecipientGroup { groups } => {
nonempty_list(groups, "group")
}
Condition::SenderTenant { tenants } => nonempty_list(tenants, "tenant"),
Condition::Words { words, at_least } => {
nonempty_list(words, "word")?;
if *at_least == 0 {
return Err("The least number of words must be 1 or more.".into());
}
words::WordList::new(words).map(|_| ())
}
Condition::Pattern { pattern, at_least } => {
if *at_least == 0 {
return Err("The least number of matches must be 1 or more.".into());
}
words::Pattern::new(pattern).map(|_| ())
}
Condition::Header {
name,
contains,
matches,
} => {
header_name(name)?;
if let Some(pattern) = matches {
words::Pattern::new(pattern)?;
}
if contains.is_some() && matches.is_some() {
return Err("A header condition is either contains or matches.".into());
}
Ok(())
}
Condition::AttachmentType { types } => nonempty_list(types, "type"),
Condition::AttachmentExtension { extensions } => nonempty_list(extensions, "extension"),
Condition::AttachmentName { pattern } => words::Pattern::new(pattern).map(|_| ()),
Condition::Detected { detectors } => {
nonempty_list(detectors, "detector")?;
for d in detectors {
if detectors::by_id(&d.id).is_none() {
return Err(format!("There is no detector \"{}\".", d.id));
}
if d.at_least == 0 {
return Err("A detector's least count must be 1 or more.".into());
}
}
Ok(())
}
Condition::RecipientOutside
| Condition::AttachmentSizeOver { .. }
| Condition::AttachmentCountOver { .. }
| Condition::CantBeInspected
| Condition::MessageSizeOver { .. } => Ok(()),
}
}
fn validate_action(action: &Action) -> Result<(), String> {
match action {
Action::AddDisclaimer { text: t, html, .. } => {
text(t, "disclaimer")?;
html.as_deref()
.map_or(Ok(()), |h| text(h, "disclaimer's HTML"))
}
Action::AddHeader { name, value } => {
header_name(name)?;
if value.len() > 998 || value.contains(['\r', '\n']) {
Err("A header value is one line of at most 998 characters.".into())
} else {
Ok(())
}
}
Action::RemoveHeader { name } => header_name(name),
Action::PrefixSubject { text: t } => text(t, "subject prefix"),
Action::AddRecipient { address } => {
if address.contains('@') {
Ok(())
} else {
Err(format!("\"{address}\" isn't an address."))
}
}
Action::Redirect { addresses } => {
nonempty_list(addresses, "address")?;
match addresses.iter().find(|a| !a.contains('@')) {
Some(a) => Err(format!("\"{a}\" isn't an address.")),
None => Ok(()),
}
}
Action::Refuse { text: t } => text(t, "refusal text"),
Action::Route { queue } => text(queue, "queue"),
Action::Block { notice } | Action::Warn { notice } | Action::Hold { notice, .. } => {
text(notice, "notice")
}
}
}
// --- Storage --------------------------------------------------------------
struct Json<T>(T);
impl<T: SerdeSerialize> Serialize for Json<T> {
fn serialize(&self) -> trc::Result<Vec<u8>> {
serde_json::to_vec(&self.0).map_err(|err| {
trc::StoreEvent::UnexpectedError
.into_err()
.details("Failed to serialize mail rule")
.reason(err)
})
}
}
impl<T: DeserializeOwned + Sync + Send> Deserialize for Json<T> {
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
serde_json::from_slice(bytes).map(Json).map_err(|err| {
trc::StoreEvent::DataCorruption
.into_err()
.details("Invalid mail rule")
.reason(err)
})
}
}
fn class(id: u32) -> ValueClass {
let mut key = Vec::with_capacity(6);
key.push(FEATURE);
key.push(KIND_RULE);
key.extend_from_slice(&id.to_be_bytes());
ValueClass::Any(AnyClass {
subspace: SUBSPACE_INBUXA,
key,
})
}
fn key(id: u32) -> ValueKey<ValueClass> {
ValueKey::from(class(id))
}
pub async fn get(data: &Store, id: u32) -> trc::Result<Option<Rule>> {
Ok(data
.get_value::<Json<Rule>>(key(id))
.await
.caused_by(trc::location!())?
.map(|Json(rule)| rule))
}
/// Every rule, in the order they run: by priority, then oldest first.
pub async fn all(data: &Store) -> trc::Result<Vec<Rule>> {
let mut rules = Vec::new();
data.iterate(IterateParams::new(key(0), key(u32::MAX)), |_, value| {
if let Ok(Json(rule)) = Json::<Rule>::deserialize(value) {
rules.push(rule);
}
Ok(true)
})
.await
.caused_by(trc::location!())?;
rules.sort_by_key(|rule| (rule.priority, rule.id));
Ok(rules)
}
/// Writes a new rule under the next free id, which it returns. Two nodes
/// creating rules at once can't take the same id: the key must be absent.
pub async fn create(data: &Store, rule: &Rule) -> trc::Result<u32> {
let mut attempt = 0;
loop {
attempt += 1;
let id = all(data).await?.iter().map(|r| r.id).max().unwrap_or(0) + 1;
let stored = Rule { id, ..rule.clone() };
let mut batch = BatchBuilder::new();
batch.assert_value(class(id), AssertValue::None);
batch.set(class(id), Json(&stored).serialize()?);
match data.write(batch.build_all()).await {
Ok(_) => {
super::cache::invalidate();
return Ok(id);
}
Err(err)
if attempt < CREATE_ATTEMPTS
&& matches!(
err.as_ref(),
trc::EventType::Store(trc::StoreEvent::AssertValueFailed)
) => {}
Err(err) => return Err(err.caused_by(trc::location!())),
}
}
}
/// Replaces a stored rule (same id).
pub async fn update(data: &Store, rule: &Rule) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
batch.set(class(rule.id), Json(rule).serialize()?);
data.write(batch.build_all())
.await
.caused_by(trc::location!())?;
super::cache::invalidate();
Ok(())
}
pub async fn delete(data: &Store, id: u32) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
batch.clear(class(id));
data.write(batch.build_all())
.await
.caused_by(trc::location!())?;
super::cache::invalidate();
Ok(())
}
#[cfg(test)]
mod tests {
use super::*;
fn rule(kind: Kind, actions: Vec<Action>) -> Rule {
Rule {
id: 0,
name: "Cards outside".into(),
description: String::new(),
kind,
enabled: true,
priority: 0,
direction: Direction::Outgoing,
conditions: vec![Condition::RecipientOutside],
exceptions: vec![],
actions,
stop_processing: false,
created_by: String::new(),
created_at: 0,
updated_at: 0,
}
}
#[test]
fn wire_format() {
let json = r#"{"name":"Cards","kind":"dlp","direction":"outgoing",
"conditions":[{"type":"recipientOutside"},{"type":"detected","detectors":[{"id":"payment-card","atLeast":5}]}],
"actions":[{"type":"hold","notice":"Held for review","notifySender":true}]}"#;
let parsed: Rule = serde_json::from_str(json).unwrap();
assert!(parsed.enabled);
assert_eq!(
parsed.conditions[1],
Condition::Detected {
detectors: vec![DetectorMin {
id: "payment-card".into(),
at_least: 5
}]
}
);
assert_eq!(
parsed.actions[0],
Action::Hold {
notice: "Held for review".into(),
notify_sender: true
}
);
assert!(parsed.validate().is_ok());
let back = serde_json::to_value(&parsed).unwrap();
assert_eq!(back["actions"][0]["notifySender"], true);
}
#[test]
fn dlp_rules_have_one_dlp_action_on_outgoing_mail() {
let block = Action::Block {
notice: "No.".into(),
};
assert!(rule(Kind::Dlp, vec![block.clone()]).validate().is_ok());
let two = rule(
Kind::Dlp,
vec![
block.clone(),
Action::Warn {
notice: "Hm.".into(),
},
],
);
assert_eq!(two.validate().unwrap_err().property, "actions");
let mixed = rule(
Kind::Dlp,
vec![block.clone(), Action::PrefixSubject { text: "[x]".into() }],
);
assert_eq!(mixed.validate().unwrap_err().property, "actions");
let mut inbound = rule(Kind::Dlp, vec![block.clone()]);
inbound.direction = Direction::Incoming;
assert_eq!(inbound.validate().unwrap_err().property, "direction");
assert_eq!(
rule(Kind::Transport, vec![block])
.validate()
.unwrap_err()
.property,
"actions"
);
}
#[test]
fn conditions_and_actions_are_checked() {
let disclaimer = Action::AddDisclaimer {
text: "Sent from Example Co.".into(),
html: None,
position: Position::Bottom,
};
let mut r = rule(Kind::Transport, vec![disclaimer]);
assert!(r.validate().is_ok());
r.conditions.push(Condition::Detected {
detectors: vec![DetectorMin {
id: "iban".into(),
at_least: 1,
}],
});
assert_eq!(r.validate().unwrap_err().property, "conditions");
let mut r = rule(
Kind::Dlp,
vec![Action::Block {
notice: "No.".into(),
}],
);
r.conditions = vec![Condition::Detected {
detectors: vec![DetectorMin {
id: "nope".into(),
at_least: 1,
}],
}];
assert!(r.validate().unwrap_err().reason.contains("nope"));
r.conditions = vec![Condition::Pattern {
pattern: "(".into(),
at_least: 1,
}];
assert!(r.validate().is_err());
r.conditions = vec![Condition::Words {
words: vec![],
at_least: 1,
}];
assert!(r.validate().is_err());
r.exceptions = vec![Condition::Header {
name: "X-Bad: yes".into(),
contains: None,
matches: None,
}];
r.conditions = vec![];
assert_eq!(r.validate().unwrap_err().property, "exceptions");
let header = rule(
Kind::Transport,
vec![Action::AddHeader {
name: "X-Tag".into(),
value: "a\r\nBcc: x@y".into(),
}],
);
assert!(header.validate().is_err());
let redirect = rule(
Kind::Transport,
vec![Action::Redirect {
addresses: vec!["nobody".into()],
}],
);
assert!(redirect.validate().is_err());
let mut unnamed = rule(
Kind::Transport,
vec![Action::RemoveHeader {
name: "X-Tag".into(),
}],
);
unnamed.name = " ".into();
assert_eq!(unnamed.validate().unwrap_err().property, "name");
}
}
+109
View File
@@ -0,0 +1,109 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! An organization's own word lists and patterns (§2.3). Both count
//! occurrences, not distinct values: "confidential" three times is three.
use aho_corasick::{AhoCorasick, AhoCorasickBuilder, MatchKind};
use regex::{Regex, RegexBuilder};
/// How large a compiled pattern may grow. Keeps a rule someone writes from
/// making every message slow to send.
const PATTERN_SIZE_LIMIT: usize = 1 << 20;
/// Words and phrases, matched whole and ignoring case.
#[derive(Debug, Clone)]
pub struct WordList {
matcher: AhoCorasick,
}
impl WordList {
/// Builds a list from words or phrases; empty entries are skipped.
pub fn new<I, S>(words: I) -> Result<Self, String>
where
I: IntoIterator<Item = S>,
S: AsRef<str>,
{
let words: Vec<String> = words
.into_iter()
.map(|w| w.as_ref().trim().to_lowercase())
.filter(|w| !w.is_empty())
.collect();
if words.is_empty() {
return Err("The list has no words".into());
}
AhoCorasickBuilder::new()
.match_kind(MatchKind::LeftmostLongest)
.build(&words)
.map(|matcher| Self { matcher })
.map_err(|err| err.to_string())
}
/// How many times any word of the list appears in `text`.
pub fn count(&self, text: &str) -> usize {
let text = text.to_lowercase();
self.matcher
.find_iter(&text)
.filter(|m| super::detectors::stands_alone(&text, m.start(), m.end()))
.count()
}
}
/// An organization's regular expression.
#[derive(Debug, Clone)]
pub struct Pattern {
regex: Regex,
}
impl Pattern {
/// Compiles `pattern`, or says why it can't be used. Matching ignores
/// case unless the pattern turns that off with `(?-i)`.
pub fn new(pattern: &str) -> Result<Self, String> {
RegexBuilder::new(pattern)
.case_insensitive(true)
.size_limit(PATTERN_SIZE_LIMIT)
.build()
.map(|regex| Self { regex })
.map_err(|err| err.to_string())
}
/// How many times the pattern matches in `text`.
pub fn count(&self, text: &str) -> usize {
self.regex.find_iter(text).filter(|m| !m.is_empty()).count()
}
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn words_whole_and_any_case() {
let list = WordList::new(["Project Falcon", "confidential", " "]).unwrap();
assert_eq!(
list.count(
"CONFIDENTIAL: project falcon notes. Not confidentiality, not projectfalcon."
),
2
);
assert_eq!(list.count("Confidential, confidential and confidential"), 3);
// Non-ASCII case folding
let list = WordList::new(["GEHEIM", "Straße"]).unwrap();
assert_eq!(list.count("streng geheim, STRASSE ist nicht Straße"), 2);
assert!(WordList::new(["", " "]).is_err());
}
#[test]
fn patterns() {
let pattern = Pattern::new(r"\bPRJ-\d{4}\b").unwrap();
assert_eq!(pattern.count("prj-1234 and PRJ-5678, not PRJ-12"), 2);
assert!(Pattern::new("(unclosed").is_err());
// Too large to compile within the limit
assert!(Pattern::new(r"\w{1000}\w{1000}\w{1000}").is_err());
// Empty matches don't count
assert_eq!(Pattern::new("x*").unwrap().count("abc"), 0);
}
}
+486
View File
@@ -0,0 +1,486 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! The personal-data catalog, evaluated (personal-data catalog spec, §6).
//!
//! `resources/privacy/catalog.toml` says what the server *can* hold; this
//! module turns it into what *this* server holds, given the live facts the
//! caller gathers from its settings ([`LiveFacts`]). Facts in, facts out:
//! nothing here judges, and nothing here reads the store, so every
//! configuration can be tested with made-up facts.
pub mod snapshot;
use serde::{Deserialize, Serialize};
use std::collections::{BTreeMap, BTreeSet};
use std::sync::OnceLock;
/// The catalog, as shipped with this build.
pub const CATALOG: &str = include_str!("../../../../resources/privacy/catalog.toml");
#[derive(Debug, Clone, Deserialize)]
#[serde(untagged)]
pub enum Retention {
Word(String),
Setting { setting: String },
}
#[derive(Debug, Clone, Default, Deserialize)]
pub struct ObjectEntry {
#[serde(default)]
pub whose: Vec<String>,
#[serde(default, rename = "where")]
pub location: Vec<String>,
pub scope: Option<String>,
pub retention: Option<Retention>,
#[serde(default)]
pub properties: BTreeMap<String, Vec<String>>,
}
#[derive(Debug, Clone, Default, Deserialize)]
pub struct SourceEntry {
#[serde(default)]
pub categories: Vec<String>,
#[serde(default)]
pub whose: Vec<String>,
#[serde(default, rename = "where")]
pub location: Vec<String>,
pub scope: Option<String>,
pub retention: Option<Retention>,
#[serde(default)]
pub enabled_by: Vec<String>,
#[serde(default)]
pub captures: Vec<String>,
#[serde(default)]
pub leaves_host: bool,
}
#[derive(Debug, Clone, Default, Deserialize)]
pub struct Catalog {
#[serde(default)]
pub object: BTreeMap<String, ObjectEntry>,
#[serde(default)]
pub source: BTreeMap<String, SourceEntry>,
}
/// The shipped catalog, parsed once. It is checked in CI
/// (`tools/fork/privacy-check.py`), so a parse failure is a build bug.
pub fn catalog() -> &'static Catalog {
static CATALOG_PARSED: OnceLock<Catalog> = OnceLock::new();
CATALOG_PARSED.get_or_init(|| toml::from_str(CATALOG).expect("resources/privacy/catalog.toml parses"))
}
/// A duration setting's live value.
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub enum Days {
/// Set, in whole days (rounded up).
Days(u64),
/// Unset: nothing bounds it.
Unbounded,
}
/// Everything the evaluation needs from the running server.
#[derive(Debug, Clone, Default)]
pub struct LiveFacts {
/// Duration settings by name (`x:DataRetention.holdTracesFor`,
/// `inbuxa:AuditSettings.keepForDays` ...). A setting not here is
/// reported by name, without a value.
pub durations: BTreeMap<String, Days>,
/// Whether each source or object is collected at all, by catalog id. An
/// id not here is taken as collected.
pub collected: BTreeMap<String, bool>,
/// The endpoints each source or object sends to, by catalog id: hosts or
/// URLs as configured. Loopback endpoints are left out: what goes there
/// stays on the host ([`is_loopback`]).
pub endpoints: BTreeMap<String, Vec<String>>,
/// Stores pointed at a remote backend, by location (`data-store`,
/// `blob-store`, `search-store`, `in-memory-store`), with the host.
pub remote_stores: BTreeMap<String, String>,
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct RetentionOut {
/// `unbounded`, `days`, `object-life`, `receiver`, or `setting` (named but
/// not evaluated).
pub kind: String,
#[serde(skip_serializing_if = "Option::is_none")]
pub days: Option<u64>,
#[serde(skip_serializing_if = "Option::is_none")]
pub setting: Option<String>,
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct Item {
pub id: String,
/// `object` or `source`.
pub kind: String,
pub categories: Vec<String>,
pub whose: Vec<String>,
#[serde(rename = "where")]
pub location: Vec<String>,
pub scope: String,
pub collected: bool,
pub retention: RetentionOut,
pub leaves_host: bool,
pub controlled_by: Vec<String>,
pub endpoints: Vec<String>,
}
/// A host that receives personal data: a candidate processor, since whether
/// it is one in law is the operator's determination.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct Processor {
pub host: String,
pub receives: Vec<String>,
pub sources: Vec<String>,
}
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct Inventory {
pub items: Vec<Item>,
pub processors: Vec<Processor>,
}
/// Counts for a snapshot's summary and the Overview.
#[derive(Debug, Clone, Default, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct Summary {
pub collected: u64,
pub unbounded: u64,
pub leaving_host: u64,
pub processors: u64,
}
impl Inventory {
pub fn summary(&self) -> Summary {
let collected = self.items.iter().filter(|i| i.collected);
Summary {
collected: collected.clone().count() as u64,
unbounded: collected
.clone()
.filter(|i| i.retention.kind == "unbounded")
.count() as u64,
leaving_host: collected.filter(|i| i.leaves_host).count() as u64,
processors: self.processors.len() as u64,
}
}
}
/// The host part of an endpoint as configured: a URL's host, or the string
/// itself when it is a bare host or zone.
pub fn host_of(endpoint: &str) -> String {
let rest = endpoint.split_once("://").map_or(endpoint, |(_, rest)| rest);
let rest = rest.rsplit_once('@').map_or(rest, |(_, host)| host);
let host = rest.split(['/', '?', '#']).next().unwrap_or(rest);
let host = if host.starts_with('[') {
host.split_once(']').map_or(host, |(h, _)| h.trim_start_matches('['))
} else {
host.rsplit_once(':')
.filter(|(_, port)| port.chars().all(|c| c.is_ascii_digit()))
.map_or(host, |(h, _)| h)
};
host.trim().trim_end_matches('.').to_ascii_lowercase()
}
/// Whether an endpoint is this host: what is sent there stays here.
pub fn is_loopback(endpoint: &str) -> bool {
let host = host_of(endpoint);
host == "localhost"
|| host.ends_with(".localhost")
|| host == "::1"
|| host.parse::<std::net::IpAddr>().is_ok_and(|ip| ip.is_loopback())
}
fn retention_out(retention: Option<&Retention>, facts: &LiveFacts) -> RetentionOut {
match retention {
Some(Retention::Setting { setting }) => match facts.durations.get(setting) {
Some(Days::Days(days)) => RetentionOut {
kind: "days".into(),
days: Some(*days),
setting: Some(setting.clone()),
},
Some(Days::Unbounded) => RetentionOut {
kind: "unbounded".into(),
days: None,
setting: Some(setting.clone()),
},
None => RetentionOut {
kind: "setting".into(),
days: None,
setting: Some(setting.clone()),
},
},
Some(Retention::Word(word)) => RetentionOut {
kind: word.clone(),
days: None,
setting: None,
},
None => RetentionOut {
kind: "object-life".into(),
days: None,
setting: None,
},
}
}
/// What the catalog says `id` holds, evaluated against `facts`. Objects with
/// nothing personal are left out. `tenant_only` keeps the entries a tenant
/// can be told about: tenant-scoped, and none of the server's processors.
pub fn evaluate(catalog: &Catalog, facts: &LiveFacts, tenant_only: bool) -> Inventory {
let mut items = Vec::new();
let mut add = |id: &str,
kind: &str,
categories: Vec<String>,
whose: &[String],
location: &[String],
scope: Option<&String>,
retention: Option<&Retention>,
controlled_by: Vec<String>,
leaves: bool| {
let scope = scope.cloned().unwrap_or_else(|| "server".into());
if tenant_only && scope != "tenant" {
return;
}
let mut endpoints: Vec<String> = facts.endpoints.get(id).cloned().unwrap_or_default();
// Anything sent to an endpoint off this host leaves it
let mut leaves_host = leaves || !endpoints.is_empty();
for place in location {
if let Some(host) = facts.remote_stores.get(place) {
leaves_host = true;
endpoints.push(host.clone());
}
}
endpoints.sort();
endpoints.dedup();
items.push(Item {
id: id.to_string(),
kind: kind.to_string(),
categories,
whose: whose.to_vec(),
location: location.to_vec(),
scope,
collected: facts.collected.get(id).copied().unwrap_or(true),
retention: retention_out(retention, facts),
leaves_host,
controlled_by,
endpoints,
});
};
for (id, entry) in &catalog.source {
let controlled_by = entry
.enabled_by
.iter()
.chain(&entry.captures)
.cloned()
.collect();
add(
id,
"source",
entry.categories.clone(),
&entry.whose,
&entry.location,
entry.scope.as_ref(),
entry.retention.as_ref(),
controlled_by,
entry.leaves_host,
);
}
for (id, entry) in &catalog.object {
if entry.properties.is_empty() || entry.whose.is_empty() {
// Nothing personal, or a credential field of a configuration
// object with no place of its own in the inventory
continue;
}
let categories: BTreeSet<String> = entry.properties.values().flatten().cloned().collect();
let leaves = entry.location.iter().any(|place| place == "external");
add(
id,
"object",
categories.into_iter().collect(),
&entry.whose,
&entry.location,
entry.scope.as_ref(),
entry.retention.as_ref(),
Vec::new(),
leaves,
);
}
// Candidate processors: each host that receives something, once
let mut processors: BTreeMap<String, (BTreeSet<String>, BTreeSet<String>)> = BTreeMap::new();
if !tenant_only {
for item in items.iter().filter(|i| i.collected && i.leaves_host) {
for endpoint in &item.endpoints {
let entry = processors.entry(host_of(endpoint)).or_default();
entry.0.extend(item.categories.iter().cloned());
entry.1.insert(item.id.clone());
}
}
}
Inventory {
items,
processors: processors
.into_iter()
.filter(|(host, _)| !host.is_empty())
.map(|(host, (receives, sources))| Processor {
host,
receives: receives.into_iter().collect(),
sources: sources.into_iter().collect(),
})
.collect(),
}
}
#[cfg(test)]
mod tests {
use super::*;
fn facts() -> LiveFacts {
LiveFacts::default()
}
fn item<'a>(inventory: &'a Inventory, id: &str) -> &'a Item {
inventory
.items
.iter()
.find(|i| i.id == id)
.unwrap_or_else(|| panic!("{id} not in the inventory"))
}
#[test]
fn the_shipped_catalog_parses() {
let catalog = catalog();
assert!(catalog.source.contains_key("log-file"));
assert!(catalog.object.contains_key("x:UserAccount"));
}
#[test]
fn defaults_a_new_install_would_report() {
let mut facts = facts();
facts
.durations
.insert("x:DataRetention.holdTracesFor".into(), Days::Days(14));
facts
.durations
.insert("inbuxa:LogSettings.keepForDays".into(), Days::Days(30));
facts.endpoints.insert("spam-pyzor".into(), vec!["public.pyzor.org:24441".into()]);
facts.collected.insert("spam-pyzor".into(), false);
facts.endpoints.insert(
"spam-dnsbl".into(),
vec!["zen.spamhaus.org".into(), "bl.spamcop.net".into()],
);
let inventory = evaluate(catalog(), &facts, false);
let trace = item(&inventory, "x:Trace");
assert_eq!(trace.retention.kind, "days");
assert_eq!(trace.retention.days, Some(14));
assert!(!trace.leaves_host);
assert_eq!(item(&inventory, "log-file").retention.days, Some(30));
// Pyzor off: listed, not collected, not a processor
assert!(!item(&inventory, "spam-pyzor").collected);
let hosts: Vec<_> = inventory.processors.iter().map(|p| p.host.as_str()).collect();
assert_eq!(hosts, vec!["bl.spamcop.net", "zen.spamhaus.org"]);
// Nothing personal isn't listed
assert!(inventory.items.iter().all(|i| i.id != "x:Http"));
}
#[test]
fn an_external_store_makes_what_lives_there_leave_the_host() {
let mut facts = facts();
facts
.remote_stores
.insert("blob-store".into(), "https://s3.example.net/mail".into());
let inventory = evaluate(catalog(), &facts, false);
let archived = item(&inventory, "x:ArchivedEmail");
assert!(archived.leaves_host);
assert_eq!(archived.endpoints, vec!["https://s3.example.net/mail"]);
assert!(inventory.processors.iter().any(|p| p.host == "s3.example.net"
&& p.sources.contains(&"x:ArchivedEmail".to_string())));
// What lives only in the data store stays
assert!(!item(&inventory, "x:UserAccount").leaves_host);
}
#[test]
fn a_hosted_ai_endpoint_is_a_processor_of_content() {
let mut facts = facts();
facts.collected.insert("spam-llm".into(), true);
facts
.endpoints
.insert("spam-llm".into(), vec!["https://api.example-ai.com/v1".into()]);
let inventory = evaluate(catalog(), &facts, false);
let ai = inventory
.processors
.iter()
.find(|p| p.host == "api.example-ai.com")
.expect("the AI endpoint is listed");
assert_eq!(ai.receives, vec!["content"]);
}
#[test]
fn telemetry_off_is_reported_as_not_collected() {
let mut facts = facts();
for id in ["x:Trace", "trace-index", "log-file"] {
facts.collected.insert(id.into(), false);
}
let inventory = evaluate(catalog(), &facts, false);
for id in ["x:Trace", "trace-index", "log-file"] {
assert!(!item(&inventory, id).collected, "{id}");
}
assert_eq!(item(&inventory, "log-file").retention.kind, "setting");
}
#[test]
fn a_tenant_sees_its_slice_and_no_processors() {
let mut facts = facts();
facts.endpoints.insert("spam-dnsbl".into(), vec!["zen.spamhaus.org".into()]);
let inventory = evaluate(catalog(), &facts, true);
assert!(inventory.items.iter().all(|i| i.scope == "tenant"));
assert!(inventory.items.iter().any(|i| i.id == "x:UserAccount"));
assert!(inventory.items.iter().all(|i| i.id != "log-file"));
assert!(inventory.processors.is_empty());
}
#[test]
fn hosts_are_read_from_urls_and_bare_names() {
assert_eq!(host_of("https://user:[email protected]:8443/path?x"), "hooks.example.com");
assert_eq!(host_of("public.pyzor.org:24441"), "public.pyzor.org");
assert_eq!(host_of("zen.spamhaus.org."), "zen.spamhaus.org");
assert_eq!(host_of("http://[::1]:11434/v1"), "::1");
assert_eq!(host_of("postgres://db.internal:5432/mail"), "db.internal");
}
#[test]
fn loopback_stays_on_the_host() {
assert!(is_loopback("http://127.0.0.1:11434/v1"));
assert!(is_loopback("http://localhost:8080"));
assert!(is_loopback("http://[::1]:11434"));
assert!(!is_loopback("http://10.77.0.2:11434"), "another node leaves the host");
assert!(!is_loopback("https://api.example-ai.com"));
}
#[test]
fn a_configured_endpoint_means_it_leaves() {
let mut facts = facts();
facts.endpoints.insert("x:Trace".into(), vec!["postgres://traces.example.net".into()]);
let inventory = evaluate(catalog(), &facts, false);
assert!(item(&inventory, "x:Trace").leaves_host);
}
#[test]
fn a_summary_counts_what_is_collected() {
let mut facts = facts();
facts.collected.insert("log-file".into(), true);
let inventory = evaluate(catalog(), &facts, false);
let summary = inventory.summary();
assert!(summary.collected > 10);
assert!(summary.unbounded >= 1, "sources the catalog marks unbounded");
}
}
+155
View File
@@ -0,0 +1,155 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! Dated copies of the evaluated inventory (personal-data catalog spec, §6,
//! `inbuxa:InventorySnapshot`), so the Overview can show when and why what
//! the server holds changed. Stored as JSON under `C` `i` and the time taken
//! (seconds, big-endian) in the fork's subspace; kept as long as the audit
//! log keeps its records (settled 2026-09-28).
use super::{Inventory, Summary};
use serde::{Deserialize as SerdeDeserialize, Serialize as SerdeSerialize};
use store::{
Deserialize, IterateParams, SUBSPACE_INBUXA, Store, U64_LEN, ValueKey,
write::{AnyClass, BatchBuilder, ValueClass, key::DeserializeBigEndian},
};
use trc::AddContext;
const PREFIX: &[u8] = b"Ci";
/// Why a snapshot was taken.
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase", tag = "kind")]
pub enum Trigger {
/// A setting the catalog names changed: the object type that changed.
SettingChanged { setting: String },
/// The daily snapshot.
Daily,
}
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase")]
pub struct Snapshot {
/// Seconds since the epoch; also the snapshot's id.
pub taken_at: u64,
pub trigger: Trigger,
pub summary: Summary,
pub inventory: Inventory,
}
fn key(taken_at: u64) -> Vec<u8> {
let mut key = PREFIX.to_vec();
key.extend_from_slice(&taken_at.to_be_bytes());
key
}
fn class(taken_at: u64) -> ValueClass {
ValueClass::Any(AnyClass {
subspace: SUBSPACE_INBUXA,
key: key(taken_at),
})
}
struct Json(Snapshot);
impl Deserialize for Json {
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
serde_json::from_slice(bytes).map(Json).map_err(|err| {
trc::StoreEvent::DataCorruption
.caused_by(trc::location!())
.reason(err)
})
}
}
/// Stores a snapshot. Two in the same second: the later one wins.
pub async fn record(data: &Store, snapshot: &Snapshot) -> trc::Result<()> {
let bytes = serde_json::to_vec(snapshot).map_err(|err| {
trc::StoreEvent::UnexpectedError
.caused_by(trc::location!())
.reason(err)
})?;
let mut batch = BatchBuilder::new();
batch.set(class(snapshot.taken_at), bytes);
data.write(batch.build_all())
.await
.caused_by(trc::location!())
.map(|_| ())
}
/// One snapshot, by the time it was taken.
pub async fn get(data: &Store, taken_at: u64) -> trc::Result<Option<Snapshot>> {
Ok(data
.get_value::<Json>(ValueKey::from(class(taken_at)))
.await
.caused_by(trc::location!())?
.map(|Json(snapshot)| snapshot))
}
/// The times snapshots were taken between `after` and `before` (inclusive,
/// seconds), newest first.
pub async fn list(data: &Store, after: u64, before: u64) -> trc::Result<Vec<u64>> {
let mut times = Vec::new();
data.iterate(
IterateParams::new(
ValueKey::from(class(after)),
ValueKey::from(class(before)),
)
.no_values(),
|key, _| {
times.push(key.deserialize_be_u64(key.len() - U64_LEN)?);
Ok(true)
},
)
.await
.caused_by(trc::location!())?;
times.reverse();
Ok(times)
}
/// The newest snapshot's time, if any.
pub async fn latest(data: &Store) -> trc::Result<Option<u64>> {
Ok(list(data, 0, u64::MAX).await?.first().copied())
}
/// Removes snapshots taken before `before` (seconds). Returns how many went.
pub async fn purge(data: &Store, before: u64) -> trc::Result<usize> {
let old = list(data, 0, before.saturating_sub(1)).await?;
if old.is_empty() {
return Ok(0);
}
let mut batch = BatchBuilder::new();
for taken_at in &old {
batch.clear(class(*taken_at));
}
data.write(batch.build_all())
.await
.caused_by(trc::location!())?;
Ok(old.len())
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn keys_sort_by_time() {
assert!(key(1) < key(2));
assert!(key(255) < key(256));
assert_eq!(&key(7)[..2], PREFIX);
}
#[test]
fn a_trigger_reads_as_json_names_it() {
let changed = serde_json::to_value(Trigger::SettingChanged {
setting: "x:DataRetention".into(),
})
.unwrap();
assert_eq!(changed["kind"], "settingChanged");
assert_eq!(changed["setting"], "x:DataRetention");
assert_eq!(serde_json::to_value(Trigger::Daily).unwrap()["kind"], "daily");
}
}
+243
View File
@@ -0,0 +1,243 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! `inbuxa:LogSettings`, how long rotated log files are kept (personal-data
//! catalog spec, default D1, settled 2026-09-28). Stored as JSON under `T` +
//! `l` in the fork's subspace, not on `x:TracerLog`: that object is also
//! stored inside `x:Bootstrap` with fields after it, so a new field there
//! would change `x:Bootstrap`'s stored format.
//!
//! Unset, files are kept as they always were: forever. A new install sets
//! 30 days. Each node deletes its own files, since log files are local.
use serde::{Deserialize as SerdeDeserialize, Serialize as SerdeSerialize};
use std::{
path::{Path, PathBuf},
time::{Duration, SystemTime},
};
use store::{
Deserialize, SUBSPACE_INBUXA, Store, ValueKey,
write::{AnyClass, BatchBuilder, ValueClass},
};
use trc::AddContext;
/// The fewest days a limit may keep, so a typo can't empty the log directory
/// of what an incident needs.
pub const MIN_KEEP_DAYS: u64 = 1;
/// The days a new install keeps (D1).
pub const NEW_INSTALL_KEEP_DAYS: u64 = 30;
/// Rung when the settings change here, so this node purges at once; other
/// nodes read the settings again within the hour.
pub static CHANGED: tokio::sync::Notify = tokio::sync::Notify::const_new();
#[derive(Debug, Clone, Default, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase", default)]
pub struct LogSettings {
/// Rotated log files older than this many days are deleted; `None`
/// keeps them all.
pub keep_for_days: Option<u64>,
}
/// The properties `inbuxa:LogSettings` has, as they appear over JMAP.
pub const PROPERTIES: &[&str] = &["keepForDays"];
impl LogSettings {
/// What's wrong with these values, naming the property.
pub fn check(&self) -> Result<(), (&'static str, String)> {
match self.keep_for_days {
Some(days) if days < MIN_KEEP_DAYS => Err((
"keepForDays",
format!("must be at least {MIN_KEEP_DAYS}, or null to keep every file"),
)),
_ => Ok(()),
}
}
}
fn key() -> ValueClass {
ValueClass::Any(AnyClass {
subspace: SUBSPACE_INBUXA,
key: b"Tl".to_vec(),
})
}
struct Json(LogSettings);
impl Deserialize for Json {
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
serde_json::from_slice(bytes).map(Json).map_err(|err| {
trc::StoreEvent::DataCorruption
.caused_by(trc::location!())
.reason(err)
})
}
}
/// The settings in force; unset reads as keep everything.
pub async fn get(data: &Store) -> trc::Result<LogSettings> {
Ok(data
.get_value::<Json>(ValueKey::from(key()))
.await
.caused_by(trc::location!())?
.map(|Json(settings)| settings)
.unwrap_or_default())
}
/// Whether anything was ever stored: a new install writes its default only
/// when nothing is there.
pub async fn is_set(data: &Store) -> trc::Result<bool> {
Ok(data
.get_value::<Json>(ValueKey::from(key()))
.await
.caused_by(trc::location!())?
.is_some())
}
/// Stores new settings.
pub async fn set(data: &Store, settings: &LogSettings) -> trc::Result<()> {
let bytes = serde_json::to_vec(settings).map_err(|err| {
trc::StoreEvent::UnexpectedError
.caused_by(trc::location!())
.reason(err)
})?;
let mut batch = BatchBuilder::new();
batch.set(key(), bytes);
data.write(batch.build_all())
.await
.caused_by(trc::location!())
.map(|_| ())
}
/// A file in a log directory: its path, name, and when it last changed.
pub struct LogFile {
pub path: PathBuf,
pub name: String,
pub modified: SystemTime,
pub is_file: bool,
}
/// The files to delete: regular files named `<prefix>.<something>`, whose
/// last change is more than `keep` ago. The file being written changes all
/// the time, so it is never old enough; anything not named for this log is
/// never touched.
pub fn expired<'a>(
files: &'a [LogFile],
prefix: &str,
keep: Duration,
now: SystemTime,
) -> impl Iterator<Item = &'a Path> + 'a {
let lead = format!("{prefix}.");
files.iter().filter_map(move |file| {
(file.is_file
&& file.name.starts_with(&lead)
&& now
.duration_since(file.modified)
.is_ok_and(|age| age > keep))
.then_some(file.path.as_path())
})
}
/// Deletes this log's expired files in `dir`, returning how many went.
pub fn purge(dir: &Path, prefix: &str, keep: Duration) -> std::io::Result<usize> {
let mut files = Vec::new();
for entry in std::fs::read_dir(dir)? {
let entry = entry?;
let meta = entry.metadata()?;
files.push(LogFile {
path: entry.path(),
name: entry.file_name().to_string_lossy().into_owned(),
modified: meta.modified()?,
is_file: meta.is_file(),
});
}
let mut removed = 0;
for path in expired(&files, prefix, keep, SystemTime::now()) {
std::fs::remove_file(path)?;
removed += 1;
}
Ok(removed)
}
#[cfg(test)]
mod tests {
use super::*;
const DAY: Duration = Duration::from_secs(86_400);
fn file(name: &str, age_days: u64, now: SystemTime) -> LogFile {
LogFile {
path: PathBuf::from(format!("/var/log/inbuxa/{name}")),
name: name.to_string(),
modified: now - DAY * age_days as u32,
is_file: true,
}
}
#[test]
fn only_this_logs_old_files_go() {
let now = SystemTime::now();
let files = [
file("inbuxa.log.2026-08-01", 58, now),
file("inbuxa.log.2026-09-27", 1, now),
file("inbuxa.log", 0, now),
file("other.log.2026-01-01", 270, now),
file("inbuxa.logs.old", 90, now),
LogFile {
is_file: false,
..file("inbuxa.log.dir", 90, now)
},
];
let gone: Vec<_> = expired(&files, "inbuxa.log", 30 * DAY, now)
.map(|p| p.file_name().unwrap().to_string_lossy().into_owned())
.collect();
assert_eq!(gone, vec!["inbuxa.log.2026-08-01"]);
}
#[test]
fn unset_keeps_everything_and_zero_is_refused() {
assert_eq!(LogSettings::default().keep_for_days, None);
assert!(LogSettings::default().check().is_ok());
let zero = LogSettings {
keep_for_days: Some(0),
};
assert_eq!(zero.check().unwrap_err().0, "keepForDays");
let json: LogSettings = serde_json::from_str("{}").unwrap();
assert_eq!(json, LogSettings::default());
}
#[test]
fn purge_deletes_on_disk() {
let dir = std::env::temp_dir().join(format!("inbuxa-log-purge-{}", std::process::id()));
std::fs::create_dir_all(&dir).unwrap();
let old = dir.join("inbuxa.log.2020-01-01");
let new = dir.join("inbuxa.log.today");
let other = dir.join("keep-me.txt");
for path in [&old, &new, &other] {
std::fs::write(path, b"x").unwrap();
}
let long_ago = SystemTime::now() - 60 * DAY;
std::fs::File::options()
.write(true)
.open(&old)
.unwrap()
.set_modified(long_ago)
.unwrap();
std::fs::File::options()
.write(true)
.open(&other)
.unwrap()
.set_modified(long_ago)
.unwrap();
assert_eq!(purge(&dir, "inbuxa.log", 30 * DAY).unwrap(), 1);
assert!(!old.exists());
assert!(new.exists());
assert!(other.exists(), "a file not named for the log is never touched");
std::fs::remove_dir_all(&dir).unwrap();
}
}
+1
View File
@@ -11,6 +11,7 @@
//! `legacy-protocols.md`.
pub mod legacy_use;
pub mod log_files;
pub mod listeners;
pub mod protocol_policy;
pub mod tenant_protocol_policy;
+229 -11
View File
@@ -8,6 +8,17 @@
//! (legacy-protocols spec, data model and LP-1 to LP-8). Stored as JSON under
//! `P` + `p` in the fork's subspace; unset fields read as the defaults.
//!
//! Each mail-app protocol has its own switch (legacy-protocols spec,
//! "Revisit: one switch per protocol"): IMAP, POP3 and ManageSieve.
//! `legacyProtocols` is the kill-all: setting it sets all three, and it reads
//! `disabled` exactly when all three are off. A policy stored before the
//! per-protocol switches has only `legacyProtocols`, and reads as all three
//! at that value.
//!
//! SMTP submission has no switch of its own here: sign-in over it is refused
//! only when all three are off, as it was by the single switch (LP-6), so
//! turning off one protocol never stops a mail app sending.
//!
//! This module is the fact, not the act. It holds what the operator chose and
//! which listeners were taken away to honour it. Closing sockets belongs to
//! `common`, which owns the listener registry, and removing the listener
@@ -59,12 +70,30 @@ pub struct SavedListener {
pub object: serde_json::Value,
}
/// The server-wide switch.
/// The protocols with a switch of their own, as the schema and JMAP spell
/// them.
pub const SWITCHED: &[&str] = &["imap", "pop3", "manageSieve"];
/// The name sign-in uses for SMTP AUTH, which follows the kill-all.
pub const SUBMISSION: &str = "submission";
/// The server-wide switches.
#[derive(Debug, Clone, PartialEq, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase", default)]
pub struct ProtocolPolicy {
/// The switch itself.
/// The kill-all: `disabled` exactly when all three protocols are off,
/// once [`ProtocolPolicy::normalize`] has run. In a policy stored before
/// the per-protocol switches, it is the value of all three.
pub legacy_protocols: LegacyProtocols,
/// IMAP's switch. Unset reads as `legacy_protocols`.
#[serde(skip_serializing_if = "Option::is_none")]
pub imap: Option<LegacyProtocols>,
/// POP3's switch. Unset reads as `legacy_protocols`.
#[serde(skip_serializing_if = "Option::is_none")]
pub pop3: Option<LegacyProtocols>,
/// ManageSieve's switch. Unset reads as `legacy_protocols`.
#[serde(skip_serializing_if = "Option::is_none")]
pub manage_sieve: Option<LegacyProtocols>,
/// With `disabled`, also close SMTP submission (LP-3). The inbound
/// listener on port 25 is never closed, whatever this says.
pub close_submission: bool,
@@ -80,6 +109,9 @@ impl Default for ProtocolPolicy {
fn default() -> Self {
ProtocolPolicy {
legacy_protocols: LegacyProtocols::Enabled,
imap: None,
pop3: None,
manage_sieve: None,
close_submission: true,
saved_listeners: Vec::new(),
changed_at: None,
@@ -91,6 +123,9 @@ impl Default for ProtocolPolicy {
/// The properties `inbuxa:ProtocolPolicy` has, as they appear over JMAP.
pub const PROPERTIES: &[&str] = &[
"legacyProtocols",
"imap",
"pop3",
"manageSieve",
"closeSubmission",
"savedListeners",
"changedAt",
@@ -129,23 +164,137 @@ pub fn is_locked(protocol: &str) -> bool {
.any(|locked| locked.eq_ignore_ascii_case(protocol))
}
impl ProtocolPolicy {
/// Whether a listener of this protocol and these ports is one the switch
/// closes. A listener bound to port 25 is inbound whatever its name, and
/// any other SMTP listener counts as submission (LP-3).
pub fn closes(&self, protocol: &str, ports: &[u16]) -> bool {
if !self.legacy_protocols.is_disabled() {
return false;
/// The switch fields, by protocol name.
pub trait Switches {
/// The kill-all, which an unset per-protocol switch reads as.
fn all(&self) -> LegacyProtocols;
fn slot(&self, protocol: &str) -> Option<&Option<LegacyProtocols>>;
fn slot_mut(&mut self, protocol: &str) -> Option<&mut Option<LegacyProtocols>>;
fn set_all_field(&mut self, value: LegacyProtocols);
/// One protocol's switch. `submission` follows the kill-all: it is off
/// only when all three are. Anything else has no switch and is on.
fn switch(&self, protocol: &str) -> LegacyProtocols {
if protocol == SUBMISSION {
return if self.all_off() {
LegacyProtocols::Disabled
} else {
LegacyProtocols::Enabled
};
}
match self.slot(protocol) {
Some(value) => value.unwrap_or(self.all()),
None => LegacyProtocols::Enabled,
}
}
/// Whether this protocol is off.
fn is_off(&self, protocol: &str) -> bool {
self.switch(protocol).is_disabled()
}
/// Whether all three protocols are off.
fn all_off(&self) -> bool {
SWITCHED.iter().all(|protocol| {
self.slot(protocol)
.and_then(|value| *value)
.unwrap_or(self.all())
.is_disabled()
})
}
/// Sets one protocol's switch; false if it has none.
fn set(&mut self, protocol: &str, value: LegacyProtocols) -> bool {
match self.slot_mut(protocol) {
Some(slot) => {
*slot = Some(value);
true
}
None => false,
}
}
/// The kill-all: all three at once.
fn set_all(&mut self, value: LegacyProtocols) {
for protocol in SWITCHED {
self.set(protocol, value);
}
self.set_all_field(value);
}
/// Writes out every switch and derives the kill-all from them, so what is
/// stored and shown never depends on how it was reached.
fn normalize(&mut self) {
let values: Vec<_> = SWITCHED.iter().map(|p| self.switch(p)).collect();
for (protocol, value) in SWITCHED.iter().zip(values) {
self.set(protocol, value);
}
let all = if self.all_off() {
LegacyProtocols::Disabled
} else {
LegacyProtocols::Enabled
};
self.set_all_field(all);
}
/// The protocols that are off.
fn off(&self) -> Vec<&'static str> {
SWITCHED
.iter()
.copied()
.filter(|p| self.is_off(p))
.collect()
}
}
macro_rules! switches {
($t:ty) => {
impl Switches for $t {
fn all(&self) -> LegacyProtocols {
self.legacy_protocols
}
fn slot(&self, protocol: &str) -> Option<&Option<LegacyProtocols>> {
match protocol {
"imap" => Some(&self.imap),
"pop3" => Some(&self.pop3),
"manageSieve" => Some(&self.manage_sieve),
_ => None,
}
}
fn slot_mut(&mut self, protocol: &str) -> Option<&mut Option<LegacyProtocols>> {
match protocol {
"imap" => Some(&mut self.imap),
"pop3" => Some(&mut self.pop3),
"manageSieve" => Some(&mut self.manage_sieve),
_ => None,
}
}
fn set_all_field(&mut self, value: LegacyProtocols) {
self.legacy_protocols = value;
}
}
};
}
pub(crate) use switches;
switches!(ProtocolPolicy);
impl ProtocolPolicy {
/// Whether a listener of this protocol and these ports is one the
/// switches close. A listener bound to port 25 is inbound whatever its
/// name, and any other SMTP listener counts as submission (LP-3), closed
/// only with all three off and `closeSubmission`.
pub fn closes(&self, protocol: &str, ports: &[u16]) -> bool {
// The lock is checked first and answers for every caller, so no
// request phrasing can reach past it (LP-21).
if is_locked(protocol) {
return false;
}
if LEGACY_PROTOCOLS.contains(&protocol) {
return true;
return self.is_off(protocol);
}
protocol.eq_ignore_ascii_case("smtp")
&& self.all_off()
&& self.close_submission
&& !ports.contains(&INBOUND_SMTP_PORT)
}
@@ -258,7 +407,10 @@ mod tests {
"an unset closeSubmission reads as the default, true"
);
let json = serde_json::to_value(&policy).unwrap();
// As shown: normalized, every switch written out.
let mut shown = policy.clone();
shown.normalize();
let json = serde_json::to_value(&shown).unwrap();
for property in PROPERTIES {
assert!(json.get(property).is_some(), "{property}");
}
@@ -410,6 +562,72 @@ mod tests {
);
}
/// A policy stored before the per-protocol switches reads as all three
/// at its one value.
#[test]
fn an_old_policy_reads_as_all_three() {
let old: ProtocolPolicy =
serde_json::from_str(r#"{"legacyProtocols": "disabled"}"#).unwrap();
for p in SWITCHED {
assert!(old.is_off(p), "{p}");
}
assert!(old.all_off() && old.is_off(SUBMISSION));
let old: ProtocolPolicy =
serde_json::from_str(r#"{"legacyProtocols": "enabled"}"#).unwrap();
assert!(old.off().is_empty() && !old.is_off(SUBMISSION));
}
/// One protocol off closes only its listeners, and leaves sending alone.
#[test]
fn one_protocol_off() {
let mut policy = ProtocolPolicy::default();
policy.set("pop3", LegacyProtocols::Disabled);
policy.normalize();
assert!(policy.closes("pop3", &[995]));
assert!(!policy.closes("imap", &[993]));
assert!(!policy.closes("manageSieve", &[4190]));
assert!(!policy.is_off(SUBMISSION), "sending goes on");
assert_eq!(policy.legacy_protocols, LegacyProtocols::Enabled);
assert_eq!(policy.off(), vec!["pop3"]);
let json = serde_json::to_value(&policy).unwrap();
assert_eq!(json["pop3"], "disabled");
assert_eq!(json["imap"], "enabled");
}
/// Turning the three off one at a time is the kill-all, and the kill-all
/// back on turns all three on.
#[test]
fn the_kill_all_is_all_three() {
let mut policy = ProtocolPolicy::default();
for p in SWITCHED {
policy.set(p, LegacyProtocols::Disabled);
}
policy.normalize();
assert!(policy.legacy_protocols.is_disabled());
assert!(policy.is_off(SUBMISSION));
policy.set_all(LegacyProtocols::Enabled);
policy.normalize();
assert!(policy.off().is_empty());
assert!(!policy.legacy_protocols.is_disabled());
// The kill-all then one back on: no longer all off.
policy.set_all(LegacyProtocols::Disabled);
policy.set("imap", LegacyProtocols::Enabled);
policy.normalize();
assert!(!policy.legacy_protocols.is_disabled());
assert_eq!(policy.off(), vec!["pop3", "manageSieve"]);
}
/// Protocols without a switch are never off.
#[test]
fn unswitched_protocols_are_on() {
let policy = disabled();
for p in ["smtp", "http", "lmtp", "jmap"] {
assert!(!policy.is_off(p), "{p}");
}
}
/// A saved listener with no id is refused, naming the property.
#[test]
fn a_nameless_saved_listener_is_refused() {
@@ -9,12 +9,18 @@
//! the tenant id in the fork's subspace; a tenant with nothing stored has
//! legacy protocols on.
//!
//! A tenant has the same three switches as the server (IMAP, POP3,
//! ManageSieve) and the same kill-all; a protocol off server-wide is off for
//! every tenant whatever the tenant's own switch says.
//!
//! A tenant's switch closes no port -- other tenants share them (LP-13). It
//! refuses sign-in on the tenant's domains, and keeps client configuration
//! for them from offering what's refused. That is all it is: one fact per
//! tenant, easy to turn back, touching no listener, role or permission.
use crate::security::protocol_policy::{LegacyProtocols, ProtocolPolicy};
use crate::security::protocol_policy::{
LegacyProtocols, ProtocolPolicy, SUBMISSION, SWITCHED, Switches, switches,
};
use serde::{Deserialize as SerdeDeserialize, Serialize as SerdeSerialize};
use store::{
Deserialize, SUBSPACE_INBUXA, Store, ValueKey,
@@ -26,24 +32,92 @@ use trc::AddContext;
#[derive(Debug, Clone, PartialEq, Default, SerdeSerialize, SerdeDeserialize)]
#[serde(rename_all = "camelCase", default)]
pub struct TenantProtocolPolicy {
/// The switch itself.
/// The kill-all, as on the server's policy.
pub legacy_protocols: LegacyProtocols,
/// IMAP's switch. Unset reads as `legacy_protocols`.
#[serde(skip_serializing_if = "Option::is_none")]
pub imap: Option<LegacyProtocols>,
/// POP3's switch. Unset reads as `legacy_protocols`.
#[serde(skip_serializing_if = "Option::is_none")]
pub pop3: Option<LegacyProtocols>,
/// ManageSieve's switch. Unset reads as `legacy_protocols`.
#[serde(skip_serializing_if = "Option::is_none")]
pub manage_sieve: Option<LegacyProtocols>,
/// When it last changed, in milliseconds since the epoch.
pub changed_at: Option<u64>,
/// The account that last changed it.
pub changed_by: Option<String>,
}
/// Why a tenant's switch can't be set this way, if it can't (LP-9).
switches!(TenantProtocolPolicy);
/// Why a tenant's switches can't be set this way, if they can't (LP-9).
///
/// A tenant can always turn legacy protocols off for itself. It can turn
/// them back on only while the server has them on: server off means off for
/// everyone.
pub fn refusal(server: &ProtocolPolicy, requested: LegacyProtocols) -> Option<&'static str> {
(server.legacy_protocols.is_disabled() && !requested.is_disabled()).then_some(
"Legacy mail protocols are off for the whole server (inbuxa:ProtocolPolicy), \
so they can't be turned back on for one organization.",
)
/// A tenant can always turn a protocol off for itself. It can turn one on
/// only while the server has it on: server off means off for everyone.
/// `turned_on` is what the request sets to `enabled`, by protocol name.
pub fn refusal(server: &ProtocolPolicy, turned_on: &[&str]) -> Option<String> {
let blocked: Vec<&str> = turned_on
.iter()
.copied()
.filter(|protocol| server.is_off(protocol))
.collect();
(!blocked.is_empty()).then(|| {
format!(
"{} off for the whole server (inbuxa:ProtocolPolicy), so {} can't be turned \
back on for one organization.",
names(&blocked),
if blocked.len() == 1 { "it" } else { "they" }
)
})
}
/// Protocol names as people read them: "IMAP and POP3 are", "POP3 is".
fn names(protocols: &[&str]) -> String {
let named: Vec<&str> = protocols
.iter()
.map(|p| match *p {
"imap" => "IMAP",
"pop3" => "POP3",
"manageSieve" => "ManageSieve",
other => other,
})
.collect();
let list = match named.as_slice() {
[one] => one.to_string(),
[rest @ .., last] => format!("{} and {last}", rest.join(", ")),
[] => String::new(),
};
format!("{list} {}", if named.len() == 1 { "is" } else { "are" })
}
/// Whose switch turns a protocol off, if any.
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub enum OffBy {
Server,
Tenant,
}
/// Whether this protocol is off for an account or domain, and by whose
/// switch: the server's first (LP-6), then the tenant's (LP-10). Submission
/// is off when all three protocols are, counting both switches together.
pub fn off_by(
server: &ProtocolPolicy,
tenant: Option<&TenantProtocolPolicy>,
protocol: &str,
) -> Option<OffBy> {
if server.is_off(protocol) {
return Some(OffBy::Server);
}
let tenant = tenant?;
let off = if protocol == SUBMISSION {
SWITCHED
.iter()
.all(|p| server.is_off(p) || tenant.is_off(p))
} else {
tenant.is_off(protocol)
};
off.then_some(OffBy::Tenant)
}
fn key(tenant_id: u32) -> ValueClass {
@@ -115,6 +189,15 @@ mod tests {
}
}
fn tenant_off(protocols: &[&str]) -> TenantProtocolPolicy {
let mut policy = TenantProtocolPolicy::default();
for p in protocols {
policy.set(p, LegacyProtocols::Disabled);
}
policy.normalize();
policy
}
#[test]
fn a_tenant_starts_with_legacy_protocols_on() {
assert!(
@@ -127,20 +210,59 @@ mod tests {
#[test]
fn a_tenant_can_always_turn_them_off() {
for s in [LegacyProtocols::Enabled, LegacyProtocols::Disabled] {
assert_eq!(refusal(&server(s), LegacyProtocols::Disabled), None);
assert_eq!(refusal(&server(s), &[]), None);
}
}
#[test]
fn a_tenant_can_turn_them_on_only_while_the_server_has_them_on() {
// LP-9, acceptance test 9.
assert_eq!(
refusal(&server(LegacyProtocols::Enabled), LegacyProtocols::Enabled),
None
);
let why =
refusal(&server(LegacyProtocols::Disabled), LegacyProtocols::Enabled).expect("refused");
assert_eq!(refusal(&server(LegacyProtocols::Enabled), SWITCHED), None);
let why = refusal(&server(LegacyProtocols::Disabled), SWITCHED).expect("refused");
assert!(why.contains("inbuxa:ProtocolPolicy"), "{why}");
assert!(
why.starts_with("IMAP, POP3 and ManageSieve are off"),
"{why}"
);
}
#[test]
fn a_tenant_can_turn_on_what_the_server_allows() {
// The server has only POP3 off: IMAP may come back, POP3 may not.
let mut s = ProtocolPolicy::default();
s.set("pop3", LegacyProtocols::Disabled);
assert_eq!(refusal(&s, &["imap"]), None);
let why = refusal(&s, &["imap", "pop3"]).expect("refused");
assert!(why.starts_with("POP3 is off"), "{why}");
}
#[test]
fn whose_switch_turns_a_protocol_off() {
let mut s = ProtocolPolicy::default();
s.set("pop3", LegacyProtocols::Disabled);
let t = tenant_off(&["imap"]);
assert_eq!(off_by(&s, Some(&t), "pop3"), Some(OffBy::Server));
assert_eq!(off_by(&s, Some(&t), "imap"), Some(OffBy::Tenant));
assert_eq!(off_by(&s, Some(&t), "manageSieve"), None);
assert_eq!(off_by(&s, None, "imap"), None);
// Sending goes on while any protocol is still allowed.
assert_eq!(off_by(&s, Some(&t), SUBMISSION), None);
// Between them, all three off: submission follows (LP-6, LP-10).
let t = tenant_off(&["imap", "manageSieve"]);
assert_eq!(off_by(&s, Some(&t), SUBMISSION), Some(OffBy::Tenant));
assert_eq!(
off_by(&server(LegacyProtocols::Disabled), None, SUBMISSION),
Some(OffBy::Server)
);
}
#[test]
fn an_old_tenant_policy_reads_as_all_three() {
let Json(old) = Json::deserialize(br#"{"legacyProtocols":"disabled"}"#).unwrap();
for p in SWITCHED {
assert!(old.is_off(p), "{p}");
}
assert!(old.is_off(SUBMISSION));
}
#[test]
@@ -158,6 +280,7 @@ mod tests {
legacy_protocols: LegacyProtocols::Disabled,
changed_at: Some(1),
changed_by: Some("b".into()),
..Default::default()
};
let Json(back) = Json::deserialize(&serde_json::to_vec(&policy).unwrap()).unwrap();
assert_eq!(back, policy);
+15
View File
@@ -123,6 +123,14 @@ pub struct EmailNote {
pub size: u64,
pub mailboxes: Vec<u32>,
pub keywords: Vec<String>,
/// LH-3: the ranges of the holds on the account when it was deleted.
/// Its received date is only known when it's archived, which decides
/// whether a hold keeps it after all.
#[serde(default, skip_serializing_if = "Vec::is_empty")]
pub held_ranges: Vec<(Option<u64>, Option<u64>)>,
/// The undelete deadline for when no range covers it.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub otherwise_until: Option<u64>,
}
/// What restore needs beyond the kept copy (UD-4, UD-8).
@@ -462,8 +470,15 @@ mod tests {
size: 3,
mailboxes: vec![1],
keywords: vec![],
held_ranges: vec![(Some(10), None)],
otherwise_until: Some(20),
};
let bytes = Json(&note).serialize().unwrap();
assert_eq!(Json::<EmailNote>::deserialize(&bytes).unwrap().0, note);
// A note written before legal holds still reads, as not held
let old = br#"{"archived_at":1,"archived_until":2,"size":3,"mailboxes":[1],"keywords":[]}"#;
let read = Json::<EmailNote>::deserialize(old).unwrap().0;
assert!(read.held_ranges.is_empty() && read.otherwise_until.is_none());
}
}
+37 -7
View File
@@ -12,9 +12,12 @@
//! is made if archiving is on, fixing the deadline then. When the data is
//! finally removed, a noted message becomes an archived item.
use crate::undelete::{
data::{self, EmailNote, Extra},
records,
use crate::{
hold::Keeping,
undelete::{
data::{self, EmailNote, Extra},
records,
},
};
use registry::{
schema::structs::{ArchivedEmail, ArchivedItem},
@@ -26,10 +29,12 @@ use store::{
};
use types::{blob::BlobId, blob_hash::BlobHash};
/// Notes a deleted message, when archiving is on (`retention` seconds).
/// Notes a deleted message, when anything keeps it: undelete, or a legal
/// hold on the account (LH-4). A held note keeps it until it's archived,
/// when its received date says whether the hold's range covers it.
pub fn note(
batch: &mut BatchBuilder,
retention: u64,
keeping: &Keeping,
account_id: u32,
document_id: u32,
size: u64,
@@ -37,16 +42,23 @@ pub fn note(
keywords: Vec<String>,
) -> trc::Result<()> {
let archived_at = now();
// Held until the date is known; the undelete deadline otherwise
let otherwise_until = keeping.until(archived_at, false);
let Some(archived_until) = keeping.until(archived_at, keeping.is_held()) else {
return Ok(());
};
data::note_email(
batch,
account_id,
document_id,
&EmailNote {
archived_at,
archived_until: archived_at + retention,
archived_until,
size,
mailboxes,
keywords,
held_ranges: keeping.ranges.clone(),
otherwise_until: if keeping.is_held() { otherwise_until } else { None },
},
)
}
@@ -78,9 +90,27 @@ pub async fn archive(
document_id: u32,
summary: Summary<'_>,
) -> trc::Result<bool> {
let Some(note) = data::email_note(data, account_id, document_id).await? else {
let Some(mut note) = data::email_note(data, account_id, document_id).await? else {
return Ok(false);
};
// LH-3: a held note's range decides now that the date is known; outside
// it, undelete's deadline, or nothing kept at all
if !note.held_ranges.is_empty() {
let keeping = Keeping {
retention: None,
ranges: std::mem::take(&mut note.held_ranges),
};
if !keeping.covers(Some(summary.received_at)) {
match note.otherwise_until {
Some(until) => note.archived_until = until,
None => {
let mut batch = BatchBuilder::new();
data::clear_email_note(&mut batch, account_id, document_id);
return data.write(batch.build_all()).await.map(|_| false);
}
}
}
}
let item = ArchivedItem::Email(ArchivedEmail {
from: summary.from.unwrap_or_default().to_string(),
subject: summary.subject.unwrap_or_default().to_string(),
+33
View File
@@ -97,6 +97,39 @@ pub async fn take(
Ok(Some(note))
}
/// A note, left in place: for a held account it's cleared only once its item
/// is archived, so a failure leaves it for the retry (LH-5).
pub async fn peek(
data: &Store,
kind: Kind,
account_id: u32,
document_id: u32,
) -> trc::Result<Option<Note>> {
Ok(data
.get_value::<Json<Note>>(ValueKey::from(note_class(kind, account_id, document_id)))
.await?
.map(|Json(note)| note))
}
/// Removes a note once its item is archived or needn't be.
pub async fn clear(data: &Store, kind: Kind, account_id: u32, document_id: u32) -> trc::Result<()> {
let mut batch = BatchBuilder::new();
batch.clear(note_class(kind, account_id, document_id));
data.write(batch.build_all()).await.map(|_| ())
}
/// An event's start, for a hold's range (LH-3). None for a recurring event,
/// which may have an occurrence anywhere, so a hold keeps it whole.
pub fn event_start(note: &Note) -> Option<u64> {
let text = note.content.as_deref()?;
if property(text, "RRULE").is_some() || property(text, "RDATE").is_some() {
return None;
}
property(text, "DTSTART")
.and_then(|v| ical_time(&v))
.map(|t| t.max(0) as u64)
}
/// The value of the first line starting with `name` (as `NAME:` or
/// `NAME;params:`) in iCalendar or vCard text, unfolded.
fn property(text: &str, name: &str) -> Option<String> {
+76 -5
View File
@@ -89,6 +89,54 @@ pub async fn insert(
Ok(id)
}
/// Moves an archived item's deadline, and its kept copy's with it: frozen
/// by a hold (LH-6) or given a real one on release (LH-10). Returns the
/// item as it now is.
pub async fn set_deadline(
data: &Store,
registry: &RegistryStore,
id: Id,
item: &ArchivedItem,
until: u64,
) -> trc::Result<ArchivedItem> {
let account_id = item.account_id().document_id();
let blob_hash = item.blob_id().hash.clone();
let before = item.archived_until().timestamp() as u64;
let mut updated = item.clone();
updated.set_archived_until(registry::types::datetime::UTCDateTime::from_timestamp(until as i64));
// The new link first, so the kept copy is never unlinked in between
let mut batch = BatchBuilder::new();
batch
.with_account_id(account_id)
.set(
BlobOp::Link {
hash: blob_hash.clone(),
to: BlobLink::Temporary { until },
},
vec![],
);
if before != until {
batch.clear(BlobOp::Link {
hash: blob_hash,
to: BlobLink::Temporary { until: before },
});
}
data::log_change(&mut batch, account_id, registry.assign_id(), id, Change::Updated);
data.write(batch.build_all())
.await
.caused_by(trc::location!())?;
let mut batch = BatchBuilder::new();
batch.set(item_class(id.id()), updated.to_pickled_vec());
registry
.store()
.write(batch.build_all())
.await
.caused_by(trc::location!())?;
Ok(updated)
}
/// Removes an archived item and releases its kept copy: on restore (UD-9),
/// on destroy (UD-12) and past its deadline (UD-13).
pub async fn remove(
@@ -184,15 +232,38 @@ pub async fn get(
}
}
/// Every archived item on the server, account by account. Items are
/// indexed by account only, so the registry's query without a filter,
/// which reads its all-ids index, finds none of them.
pub async fn all(data: &Store, registry: &RegistryStore) -> trc::Result<Vec<Id>> {
let mut accounts = registry
.query::<Vec<Id>>(RegistryQuery::new(ObjectType::Account))
.await
.caused_by(trc::location!())?
.into_iter()
.map(|id| id.document_id())
.collect::<Vec<_>>();
// Deleted accounts still kept have archived items too
accounts.extend(data::kept_accounts(data).await?.into_iter().map(|(id, _)| id));
accounts.sort_unstable();
accounts.dedup();
let mut items = Vec::new();
for account_id in accounts {
items.extend(
registry
.query::<Vec<Id>>(RegistryQuery::new(ObjectType::ArchivedItem).with_account(account_id))
.await
.caused_by(trc::location!())?,
);
}
Ok(items)
}
/// Removes every expired archived item on the server (UD-13), for the
/// scheduled clean-up.
pub async fn remove_expired(data: &Store, registry: &RegistryStore) -> trc::Result<usize> {
let mut removed = 0;
for id in registry
.query::<Vec<Id>>(RegistryQuery::new(ObjectType::ArchivedItem))
.await
.caused_by(trc::location!())?
{
for id in all(data, registry).await? {
if let Some(item) = registry.object::<ArchivedItem>(id).await?
&& is_expired(&item)
{
+1 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "groupware"
version = "0.16.23"
version = "0.16.24"
edition = "2024"
[dependencies]
+221
View File
@@ -0,0 +1,221 @@
/*
* SPDX-FileCopyrightText: 2026 Coffey Labs
*
* SPDX-License-Identifier: AGPL-3.0-only
*/
//! inbuxa: a locked account's grants on its calendars, address books, file
//! folders and top-level files (audit-hold-lock spec, AL-7, AL-10). The
//! mailbox half, and the whole, are in `email::inbuxa_lock`; this half is
//! here so DAV, which sees only these, can grant on what it creates.
use crate::{cache::GroupwareCache, calendar::Calendar, contact::AddressBook, file::FileNode};
use common::{
DavResourceMetadata, Server,
auth::AccountTenantIds,
cache::invalidate::CacheInvalidationBuilder,
ipc::CacheInvalidation,
};
use inbuxa_features::lock::{self, Lock, Replaced};
use store::{
ValueKey,
write::{AlignedBytes, Archive, BatchBuilder, now},
};
use trc::AddContext;
use types::collection::{Collection, SyncCollection};
/// The collections this half covers.
pub const DAV_COLLECTIONS: [Collection; 3] = [
Collection::Calendar,
Collection::AddressBook,
Collection::FileNode,
];
/// Who a lock's grant changes are recorded as having been made by: the
/// locked account itself, as the server acting for it.
pub async fn changed_by(server: &Server, account_id: u32) -> AccountTenantIds {
AccountTenantIds {
account_id,
tenant_id: server.account(account_id).await.ok().and_then(|a| a.id_tenant),
}
}
/// Grants on calendars, address books, file folders and top-level files,
/// into `batch`, with what they replaced into `replaced`.
#[allow(clippy::too_many_arguments)]
pub async fn apply_dav_grants(
server: &Server,
account_id: u32,
old: Option<&Lock>,
new: Option<&Lock>,
now: u64,
replaced: &mut Vec<Replaced>,
batch: &mut BatchBuilder,
) -> trc::Result<()> {
let changed_by = changed_by(server, account_id).await;
for (sync, collection) in [
(SyncCollection::Calendar, Collection::Calendar),
(SyncCollection::AddressBook, Collection::AddressBook),
(SyncCollection::FileNode, Collection::FileNode),
] {
let resources = server
.fetch_dav_resources(account_id, account_id, sync)
.await
.caused_by(trc::location!())?;
for resource in &resources.resources {
// A folder covers what's in it; a file outside any folder
// needs its own grant
let top_level_file = matches!(
&resource.data,
DavResourceMetadata::File {
parent_id: None,
..
}
);
if !resource.is_container() && !top_level_file {
continue;
}
let Some(current) = resource.acls() else {
continue;
};
let Some(acls) = lock::merge_grants(
current,
collection,
resource.document_id,
false,
old,
new,
now,
replaced,
) else {
continue;
};
let Some(archive) = server
.store()
.get_value::<Archive<AlignedBytes>>(ValueKey::archive(
account_id,
collection,
resource.document_id,
))
.await
.caused_by(trc::location!())?
else {
continue;
};
match collection {
Collection::Calendar => {
let current = archive
.to_unarchived::<Calendar>()
.caused_by(trc::location!())?;
let mut changed = current
.deserialize::<Calendar>()
.caused_by(trc::location!())?;
changed.acls = acls;
changed
.update(changed_by, current, account_id, resource.document_id, batch)
.caused_by(trc::location!())?;
}
Collection::AddressBook => {
let current = archive
.to_unarchived::<AddressBook>()
.caused_by(trc::location!())?;
let mut changed = current
.deserialize::<AddressBook>()
.caused_by(trc::location!())?;
changed.acls = acls;
changed
.update(changed_by, current, account_id, resource.document_id, batch)
.caused_by(trc::location!())?;
}
_ => {
let current = archive
.to_unarchived::<FileNode>()
.caused_by(trc::location!())?;
let mut changed = current
.deserialize::<FileNode>()
.caused_by(trc::location!())?;
changed.acls = acls;
changed
.update(
changed_by,
current,
account_id,
resource.document_id,
false,
batch,
)
.caused_by(trc::location!())?;
}
}
}
}
Ok(())
}
/// Every token a lock change touches is rebuilt on its next use, on every
/// node: the locked account's and each delegate's, before and after.
pub async fn invalidate(
server: &Server,
account_id: u32,
old: Option<&Lock>,
new: Option<&Lock>,
) -> trc::Result<()> {
let mut builder = CacheInvalidationBuilder::default();
builder.invalidate(CacheInvalidation::AccessToken(account_id));
for delegate in old.into_iter().chain(new).flat_map(|l| &l.delegates) {
builder.invalidate(CacheInvalidation::AccessToken(delegate.account_id));
}
server.invalidate_caches(builder).await
}
/// Whether two lists of replaced rights say the same, in any order.
pub fn same_replaced(a: &[Replaced], b: &[Replaced]) -> bool {
let key = |r: &Replaced| (r.collection, r.document_id, r.delegate, r.rights);
let mut a = a.iter().map(key).collect::<Vec<_>>();
let mut b = b.iter().map(key).collect::<Vec<_>>();
a.sort();
b.sort();
a == b
}
/// Grants the lock on `account_id`, if any, on calendars, address books and
/// files made since. For DAV, after a delegate creates one there.
pub async fn reconcile_dav(server: &Server, account_id: u32) -> trc::Result<()> {
let data = server.store();
let Some(current) = lock::get(data, account_id).await? else {
return Ok(());
};
// Mailbox entries aren't this half's to change
let mut replaced = current
.replaced
.iter()
.filter(|r| !DAV_COLLECTIONS.iter().any(|c| *c as u8 == r.collection))
.cloned()
.collect::<Vec<_>>();
let mut batch = BatchBuilder::new();
apply_dav_grants(
server,
account_id,
Some(&current),
Some(&current),
now(),
&mut replaced,
&mut batch,
)
.await?;
if batch.is_empty() {
return Ok(());
}
server
.commit_batch(batch)
.await
.caused_by(trc::location!())?;
if !same_replaced(&replaced, &current.replaced) {
let updated = Lock {
replaced,
..current.clone()
};
lock::set(data, &updated, Some(&current)).await?;
}
invalidate(server, account_id, Some(&current), Some(&current)).await
}
+1
View File
@@ -23,6 +23,7 @@ pub mod calendar;
pub mod contact;
pub mod file;
pub mod inbuxa; // inbuxa: undelete notes
pub mod inbuxa_lock; // inbuxa: account lock grants
pub mod scheduling;
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
+1 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "http_proto"
version = "0.16.23"
version = "0.16.24"
edition = "2024"
[dependencies]
+1 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "http"
version = "0.16.23"
version = "0.16.24"
edition = "2024"
[dependencies]
+103 -70
View File
@@ -12,7 +12,7 @@ use common::{
},
};
use hyper::body::{Bytes, Frame};
use mail_auth::{IpLookupStrategy, mta_sts::TlsRpt};
use mail_auth::{DnssecStatus, IpLookupStrategy, mta_sts::TlsRpt};
use serde::{Deserialize, Serialize};
use smtp::outbound::{
client::{SmtpClient, StartTlsResult},
@@ -382,81 +382,25 @@ async fn delivery_diagnose(
}
}
// Fetch TLSA record
tx.send(DeliveryStage::TlsaLookupStart).await?;
let now = Instant::now();
let dane_policy = match server.tlsa_lookup(format!("_25._tcp.{hostname}.")).await {
Ok(TlsaResult::Secure(tlsa)) if tlsa.has_end_entities => {
tx.send(DeliveryStage::TlsaLookupSuccess {
record: tlsa.as_ref().clone(),
elapsed: now.elapsed_ms(),
})
.await?;
Some(tlsa)
}
Ok(TlsaResult::Secure(_)) => {
tx.send(DeliveryStage::TlsaLookupError {
elapsed: now.elapsed_ms(),
reason: "TLSA record does not have end entities".to_string(),
})
.await?;
None
}
Ok(TlsaResult::Bogus) => {
tx.send(DeliveryStage::TlsaLookupError {
elapsed: now.elapsed_ms(),
reason: "Bogus TLSA record".to_string(),
})
.await?;
continue 'outer;
}
Ok(TlsaResult::Missing) => {
tx.send(DeliveryStage::TlsaNotFound {
elapsed: now.elapsed_ms(),
reason: "No TLSA DNSSEC records found".to_string(),
})
.await?;
None
}
Err(err) => {
if matches!(
&err,
mail_auth::Error::Dns(mail_auth::DnsError::RecordNotFound(_))
) {
tx.send(DeliveryStage::TlsaNotFound {
elapsed: now.elapsed_ms(),
reason: "No TLSA records found for MX".to_string(),
})
.await?;
None
} else {
tx.send(DeliveryStage::TlsaLookupError {
elapsed: now.elapsed_ms(),
reason: err.to_string(),
})
.await?;
continue 'outer;
}
}
};
tx.send(DeliveryStage::IpLookupStart).await?;
let now = Instant::now();
let remote_ips = match host.fqdn_hostname() {
let validate_addresses = server.core.smtp.resolvers.dnssec_available
&& host.dnssec_status() == DnssecStatus::Secure;
let (remote_ips, addresses_dnssec_status) = match host.fqdn_hostname() {
HostOrIp::Host(hostname) => {
match server
.ip_lookup(&hostname, IpLookupStrategy::Ipv4thenIpv6, usize::MAX, false)
.ip_lookup(
&hostname,
IpLookupStrategy::Ipv4thenIpv6,
usize::MAX,
validate_addresses,
)
.await
{
Ok((remote_ips, _)) if !remote_ips.is_empty() => remote_ips,
Ok((remote_ips, dnssec_status)) if !remote_ips.is_empty() => {
(remote_ips, dnssec_status)
}
Ok(_) => {
tx.send(DeliveryStage::IpLookupError {
reason: "No IP addresses found for host".to_string(),
@@ -475,7 +419,7 @@ async fn delivery_diagnose(
}
}
}
HostOrIp::Ip(ip) => vec![ip],
HostOrIp::Ip(ip) => (vec![ip], DnssecStatus::Indeterminate),
};
tx.send(DeliveryStage::IpLookupSuccess {
@@ -484,6 +428,95 @@ async fn delivery_diagnose(
})
.await?;
// Fetch TLSA record
tx.send(DeliveryStage::TlsaLookupStart).await?;
let now = Instant::now();
let dane_policy = match host.dane_status(addresses_dnssec_status) {
(DnssecStatus::Secure, _) => {
match server.tlsa_lookup(format!("_25._tcp.{hostname}.")).await {
Ok(TlsaResult::Secure(tlsa)) if tlsa.has_end_entities => {
tx.send(DeliveryStage::TlsaLookupSuccess {
record: tlsa.as_ref().clone(),
elapsed: now.elapsed_ms(),
})
.await?;
Some(tlsa)
}
Ok(TlsaResult::Secure(_)) => {
tx.send(DeliveryStage::TlsaLookupError {
elapsed: now.elapsed_ms(),
reason: "TLSA record does not have end entities".to_string(),
})
.await?;
None
}
Ok(TlsaResult::Bogus) => {
tx.send(DeliveryStage::TlsaLookupError {
elapsed: now.elapsed_ms(),
reason: "Bogus TLSA record".to_string(),
})
.await?;
continue 'outer;
}
Ok(TlsaResult::Missing) => {
tx.send(DeliveryStage::TlsaNotFound {
elapsed: now.elapsed_ms(),
reason: "No TLSA DNSSEC records found".to_string(),
})
.await?;
None
}
Err(err) => {
if matches!(
&err,
mail_auth::Error::Dns(mail_auth::DnsError::RecordNotFound(_))
) {
tx.send(DeliveryStage::TlsaNotFound {
elapsed: now.elapsed_ms(),
reason: "No TLSA records found for MX".to_string(),
})
.await?;
None
} else {
tx.send(DeliveryStage::TlsaLookupError {
elapsed: now.elapsed_ms(),
reason: err.to_string(),
})
.await?;
continue 'outer;
}
}
}
}
(DnssecStatus::Bogus, dnssec_entity) => {
tx.send(DeliveryStage::TlsaLookupError {
elapsed: now.elapsed_ms(),
reason: format!("Bogus {dnssec_entity} records were found"),
})
.await?;
continue 'outer;
}
(_, dnssec_entity) => {
tx.send(DeliveryStage::TlsaNotFound {
elapsed: now.elapsed_ms(),
reason: format!(
"{dnssec_entity} records are not DNSSEC signed, DANE does not apply"
),
})
.await?;
None
}
};
for remote_ip in remote_ips {
// Start connection
tx.send(DeliveryStage::ConnectionStart { remote_ip })
+34
View File
@@ -120,6 +120,40 @@ impl ManagementApi for Server {
jmap::inbuxa::explanation::question(self, &access_token, &subject).await?;
Ok(explain_stream(self.clone(), access_token, question, in_flight))
}
// inbuxa: try a saved directory before anything signs in through it
"directory" if is_post && path.get(1).copied() == Some("test") => {
let (_in_flight, access_token) = self.authenticate_headers(req, session).await?;
jmap::inbuxa::directory_test::assert_allowed(&access_token)?;
let request = body
.as_deref()
.and_then(|body| serde_json::from_slice::<serde_json::Value>(body).ok())
.unwrap_or_default();
let answer = jmap::inbuxa::directory_test::test(self, &request).await?;
Ok(JsonResponse::new(answer).no_cache().into_http_response())
}
// inbuxa: send one sample event to a saved webhook
"webhook" if is_post && path.get(1).copied() == Some("test") => {
let (_in_flight, access_token) = self.authenticate_headers(req, session).await?;
jmap::inbuxa::webhook_test::assert_allowed(&access_token)?;
let request = body
.as_deref()
.and_then(|body| serde_json::from_slice::<serde_json::Value>(body).ok())
.unwrap_or_default();
let answer = jmap::inbuxa::webhook_test::test(self, &request).await?;
Ok(JsonResponse::new(answer).no_cache().into_http_response())
}
// inbuxa: whether the outside world reaches each node's ports
"ports" if path.get(1).copied() == Some("check") => {
let (_in_flight, access_token) = self.authenticate_headers(req, session).await?;
if access_token.tenant_id().is_some() {
return Err(trc::JmapEvent::Forbidden
.into_err()
.details("Port checks are for server-level administrators."));
}
access_token.enforce_permission(Permission::SysNetworkListenerGet)?;
let answer = common::reachability::report(self).await?;
Ok(JsonResponse::new(answer).no_cache().into_http_response())
}
"account" => {
// Authenticate request
let (_in_flight, access_token) = self.authenticate_headers(req, session).await?;
+6 -1
View File
@@ -2,6 +2,8 @@
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
*
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
*
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use common::auth::AccessToken;
@@ -36,7 +38,9 @@ impl Authenticator for Server {
self.access_token(http_cache.account_id).await?,
http_cache.credential_id,
session.remote_ip,
)?;
)?
// inbuxa: AU-5
.with_origin_arc(http_cache.origin.clone());
if access_token.revision() == http_cache.revision {
// Enforce authenticated rate limit
@@ -99,6 +103,7 @@ impl Authenticator for Server {
credential_id: access_token.credential_id(),
expires: Instant::now()
+ Duration::from_secs(self.core.oauth.oauth_expiry_token),
origin: access_token.origin_arc(),
},
);
+10 -6
View File
@@ -2,6 +2,8 @@
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
*
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
*
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use super::ErrorType;
@@ -164,9 +166,10 @@ impl ClientRegistrationHandler for Server {
.await
.caused_by(trc::location!())?;
let result = self
.registry()
.write(RegistryWrite::insert(
// inbuxa: AU-1.10: a client registering itself
let result = inbuxa_features::audit::scope::system(
"oauth-registration",
self.registry().write(RegistryWrite::insert(
&OAuthClient {
client_id: client_id.clone(),
description: request.client_name.clone(),
@@ -179,9 +182,10 @@ impl ClientRegistrationHandler for Server {
..Default::default()
}
.into(),
))
.await
.caused_by(trc::location!())?;
)),
)
.await
.caused_by(trc::location!())?;
if !matches!(result, RegistryWriteResult::Success(_)) {
return Err(trc::StoreEvent::UnexpectedError
+17 -3
View File
@@ -2,6 +2,8 @@
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
*
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
*
* Modified by Coffey Labs in 2026 for INBUXA.
*/
use super::{
@@ -237,10 +239,20 @@ impl TokenHandler for Server {
.validate_access_token(GrantType::RefreshToken.into(), refresh_token)
.await
{
// inbuxa: AL-2: a locked account gets no new tokens
Ok(token_info)
if self
.access_token(token_info.account_id)
.await
.is_ok_and(|token| token.is_locked()) =>
{
TokenResponse::error(ErrorType::InvalidGrant)
}
Ok(token_info) => self
.issue_token(
token_info.account_id,
"",
// inbuxa: AU-5: the client travels in the refresh token
token_info.claims.as_deref().unwrap_or_default(),
issuer,
None,
None,
@@ -327,7 +339,8 @@ impl TokenHandler for Server {
account_id,
account_name,
self.core.oauth.oauth_expiry_token,
None,
// inbuxa: AU-5: the token names the client it was issued to
Some(client_id),
credential_version.into(),
)
.await?,
@@ -339,7 +352,8 @@ impl TokenHandler for Server {
account_id,
account_name,
self.core.oauth.oauth_expiry_refresh_token,
None,
// inbuxa: AU-5: so a refreshed access token still names it
Some(client_id),
credential_version.into(),
)
.await?
+3 -1
View File
@@ -36,7 +36,7 @@ use hyper::{
server::conn::http1,
service::service_fn,
};
use hyper_util::rt::TokioIo;
use hyper_util::rt::{TokioIo, TokioTimer};
use jmap::{
api::{
ToJmapHttpResponse, event_source::EventSourceHandler, request::RequestHandler,
@@ -690,6 +690,7 @@ async fn handle_session<T: SessionStream>(inner: Arc<Inner>, session: SessionDat
let is_tls = session.stream.is_tls();
if let Err(http_err) = http1::Builder::new()
.timer(TokioTimer::new())
.keep_alive(true)
.serve_connection(
TokioIo::new(session.stream),
@@ -875,6 +876,7 @@ async fn handle_session<T: SessionStream>(inner: Arc<Inner>, session: SessionDat
)
.with_upgrades()
.await
&& !http_err.is_timeout()
{
if http_err.is_parse() {
let server = inner.build_server();
+1 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "imap_proto"
version = "0.16.23"
version = "0.16.24"
edition = "2024"
[dependencies]
+1 -1
View File
@@ -1,6 +1,6 @@
[package]
name = "imap"
version = "0.16.23"
version = "0.16.24"
edition = "2024"
[dependencies]

Some files were not shown because too many files have changed in this diff Show More