Compare commits
195
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b62713bb8d | ||
|
|
ef56eb33ed | ||
|
|
b64f6690f6 | ||
|
|
bf7c84bc15 | ||
|
|
b07e69b5ed | ||
|
|
ce8284df6c | ||
|
|
966241070e | ||
|
|
b25258330c | ||
|
|
db4135e481 | ||
|
|
72f8ddd5e7 | ||
|
|
88e756bc3a | ||
|
|
f77d171063 | ||
|
|
79db6c537b | ||
|
|
1a23243cc1 | ||
|
|
ca4bf75c1b | ||
|
|
8a596c44ac | ||
|
|
c50d5eb109 | ||
|
|
098abb102a | ||
|
|
c1702a00bb | ||
|
|
a24ed3b60a | ||
|
|
f791c78d17 | ||
|
|
461f5fab3c | ||
|
|
4f25927d18 | ||
|
|
fb785b8635 | ||
|
|
50a03df30b | ||
|
|
9976d52e29 | ||
|
|
58d2804278 | ||
|
|
5f6548bfdd | ||
|
|
daa484efbc | ||
|
|
1aedc77791 | ||
|
|
a19d9eec89 | ||
|
|
5c1c4c6248 | ||
|
|
2d8728793c | ||
|
|
9429f1de00 | ||
|
|
76c170db9d | ||
|
|
d7bebd454d | ||
|
|
282ad5fc13 | ||
|
|
133d41df36 | ||
|
|
c4a6e4d117 | ||
|
|
f59a9de4dc | ||
|
|
083f22d6fb | ||
|
|
c43abef8ab | ||
|
|
c9f8028502 | ||
|
|
cd7a0f4163 | ||
|
|
30d4cef0e7 | ||
|
|
6c1eeea038 | ||
|
|
ea9a6f0c58 | ||
|
|
1c1838af05 | ||
|
|
78c9490b1e | ||
|
|
ce2742fc80 | ||
|
|
81deaa69c4 | ||
|
|
d9754c46a6 | ||
|
|
4481279f1c | ||
|
|
20abf69d31 | ||
|
|
69ef48239a | ||
|
|
00f00d6d75 | ||
|
|
68d3ad795e | ||
|
|
d486747c11 | ||
|
|
e69df1ae8d | ||
|
|
031d028ba4 | ||
|
|
6d7afc3c06 | ||
|
|
3d5a1692ab | ||
|
|
1de77316f0 | ||
|
|
26c7c6a897 | ||
|
|
4ba1896eb1 | ||
|
|
b0e53ef966 | ||
|
|
dd57709522 | ||
|
|
3450c31345 | ||
|
|
29d3a5f779 | ||
|
|
f1f112fc38 | ||
|
|
96be849976 | ||
|
|
a5c8927dbc | ||
|
|
ad09eeeefb | ||
|
|
7e06a3b1f6 | ||
|
|
e147206e82 | ||
|
|
ca6484c356 | ||
|
|
faf3d1e056 | ||
|
|
ffcfde0b5a | ||
|
|
f1f05db790 | ||
|
|
e1076a04b2 | ||
|
|
8fc8d94bbc | ||
|
|
0c600a63fa | ||
|
|
f78925b316 | ||
|
|
6ee7ba1b7e | ||
|
|
a992caf810 | ||
|
|
daa486f7e7 | ||
|
|
9c29fb2bea | ||
|
|
abd5811420 | ||
|
|
80051539d5 | ||
|
|
64550ebbd0 | ||
|
|
eea96e8674 | ||
|
|
4c5583e725 | ||
|
|
441ad0b18e | ||
|
|
792ff9d1ee | ||
|
|
af49e94d97 | ||
|
|
37c00b609c | ||
|
|
94a3a762b0 | ||
|
|
9a7d678532 | ||
|
|
823d42d528 | ||
|
|
de514115dd | ||
|
|
0f8816f659 | ||
|
|
b59eebf1e7 | ||
|
|
f4061f542c | ||
|
|
e99f84bd01 | ||
|
|
9653219c53 | ||
|
|
f44382fb09 | ||
|
|
dd73e0ad74 | ||
|
|
7f045c626a | ||
|
|
e99d26de89 | ||
|
|
7f22006e97 | ||
|
|
e35fc3e6d6 | ||
|
|
5f52dad5f1 | ||
|
|
15064d6fd5 | ||
|
|
e0060c9e6e | ||
|
|
a3a36cd5d7 | ||
|
|
8afaee7d21 | ||
|
|
c8280de9c3 | ||
|
|
f8b9df6438 | ||
|
|
92d14fbd60 | ||
|
|
01f6b99631 | ||
|
|
8d5e4ee052 | ||
|
|
213c7f0362 | ||
|
|
9e0aab6b6a | ||
|
|
3eb5a454fd | ||
|
|
dc49bf4d14 | ||
|
|
f7fb115a0f | ||
|
|
3199a6f1fb | ||
|
|
2b45a2e412 | ||
|
|
3fadf82909 | ||
|
|
2a851ea230 | ||
|
|
0502eb45ed | ||
|
|
11ba361c8c | ||
|
|
ba75ab4ecc | ||
|
|
afffa0fc96 | ||
|
|
32b22d0828 | ||
|
|
558b776e9f | ||
|
|
ac3a63973d | ||
|
|
e61a475859 | ||
|
|
6c862e4971 | ||
|
|
beb6c33e63 | ||
|
|
5a73a1183a | ||
|
|
ac204078eb | ||
|
|
728586998b | ||
|
|
cca49de92c | ||
|
|
b20b09f81a | ||
|
|
7bbbff0648 | ||
|
|
a8fb10458b | ||
|
|
c61497e2b2 | ||
|
|
7285b3e38a | ||
|
|
9893452ca2 | ||
|
|
63adb4e2b8 | ||
|
|
d107c1b2bb | ||
|
|
1d5a49409f | ||
|
|
80d6c09c59 | ||
|
|
480d93f4d6 | ||
|
|
f47371b3a1 | ||
|
|
bdd97c5828 | ||
|
|
a0ffdb8071 | ||
|
|
18b28fad27 | ||
|
|
a8dde68800 | ||
|
|
09c55ba503 | ||
|
|
eac3db34e9 | ||
|
|
6945714aa9 | ||
|
|
b2453d066b | ||
|
|
f59b084ce5 | ||
|
|
85ea0c80e9 | ||
|
|
a588a8aa7d | ||
|
|
35cf3f405f | ||
|
|
de275bac60 | ||
|
|
305406a331 | ||
|
|
f5888d79b0 | ||
|
|
8e9cedbe97 | ||
|
|
5ba54e8fb7 | ||
|
|
db817dd507 | ||
|
|
b7e3a765ca | ||
|
|
7ba9ec9fa0 | ||
|
|
4c07779c16 | ||
|
|
e1e8a9aeb0 | ||
|
|
5c506b9d2b | ||
|
|
3978cf5785 | ||
|
|
815a642cc4 | ||
|
|
1d5f4a2cd3 | ||
|
|
68dd749291 | ||
|
|
b1bc5ed6e0 | ||
|
|
b074c73219 | ||
|
|
3046c418cd | ||
|
|
faeb1fed86 | ||
|
|
c1b5bf956c | ||
|
|
3217aae4e8 | ||
|
|
538ae107d7 | ||
|
|
39707cd2e8 | ||
|
|
8d3e99bc00 | ||
|
|
7b97efbb7f | ||
|
|
318783f444 | ||
|
|
5d2e35b2dc |
No files matched your search
+54
-1
@@ -7,7 +7,12 @@
|
|||||||
# instance resolves short `uses:` against itself, never GitHub, so nothing
|
# instance resolves short `uses:` against itself, never GitHub, so nothing
|
||||||
# unreviewed can be pulled in.
|
# unreviewed can be pulled in.
|
||||||
#
|
#
|
||||||
# Not ported, as on GitLab: publish.yml and release.yml still need doing.
|
# BUILD_ON: when the Actions variable BUILD_ON is 'github' (org or repo),
|
||||||
|
# fork-checks and build skip here and the `github` job below waits for the
|
||||||
|
# same work done by .github/workflows/ci.yml on the GitHub mirror, passing or
|
||||||
|
# failing with it -- so this run still carries the answer pull requests and
|
||||||
|
# merges look at. Unset, everything builds here as before. If GitHub is
|
||||||
|
# unavailable, unset BUILD_ON and nothing else has to change.
|
||||||
name: ci
|
name: ci
|
||||||
|
|
||||||
on:
|
on:
|
||||||
@@ -25,6 +30,7 @@ jobs:
|
|||||||
# without the AGPL 5(a) notice. Seconds, and needs no toolchain. The notice
|
# without the AGPL 5(a) notice. Seconds, and needs no toolchain. The notice
|
||||||
# check diffs against the upstream snapshot branch, hence the full fetch.
|
# check diffs against the upstream snapshot branch, hence the full fetch.
|
||||||
fork-checks:
|
fork-checks:
|
||||||
|
if: ${{ vars.BUILD_ON != 'github' }}
|
||||||
runs-on: light
|
runs-on: light
|
||||||
container:
|
container:
|
||||||
image: python:3.13-slim@sha256:8d9d0b8bcf6506481eae4907c18f5e3e7902e629f5f6d684f9e7c32e85e3ddf0 # 3.13-slim
|
image: python:3.13-slim@sha256:8d9d0b8bcf6506481eae4907c18f5e3e7902e629f5f6d684f9e7c32e85e3ddf0 # 3.13-slim
|
||||||
@@ -40,8 +46,19 @@ jobs:
|
|||||||
# nothing. CI never sees the difference; a release does.
|
# nothing. CI never sees the difference; a release does.
|
||||||
- if: always()
|
- if: always()
|
||||||
run: python3 tools/fork/context-check.py
|
run: python3 tools/fork/context-check.py
|
||||||
|
# The personal-data catalog must classify every object and field the
|
||||||
|
# schema has, and name nothing that is gone.
|
||||||
|
- if: always()
|
||||||
|
run: python3 tools/fork/privacy-check.py
|
||||||
|
# The admin reads each expression field's allowed values and variables
|
||||||
|
# from the schema; they're generated from the registry and must match it.
|
||||||
|
- if: always()
|
||||||
|
run: python3 tools/fork/expr-schema.py --check
|
||||||
|
- if: always()
|
||||||
|
run: python3 -m unittest discover -s tools/fork/tests
|
||||||
|
|
||||||
build:
|
build:
|
||||||
|
if: ${{ vars.BUILD_ON != 'github' }}
|
||||||
# Either runner (host1 or host2): the build needs no docker socket.
|
# Either runner (host1 or host2): the build needs no docker socket.
|
||||||
runs-on: light
|
runs-on: light
|
||||||
container:
|
container:
|
||||||
@@ -91,3 +108,39 @@ jobs:
|
|||||||
used=$(du -s --block-size=1G /cache/target 2>/dev/null | cut -f1)
|
used=$(du -s --block-size=1G /cache/target 2>/dev/null | cut -f1)
|
||||||
echo "target dir: ${used:-0} GB"
|
echo "target dir: ${used:-0} GB"
|
||||||
if [ "${used:-0}" -gt 60 ]; then rm -rf /cache/target && echo "over 60 GB: target dir cleared"; fi
|
if [ "${used:-0}" -gt 60 ]; then rm -rf /cache/target && echo "over 60 GB: target dir cleared"; fi
|
||||||
|
|
||||||
|
# BUILD_ON=github: the GitHub mirror builds this commit and posts the result
|
||||||
|
# back as the commit status "github/ci (branch)". This waits for that status
|
||||||
|
# and takes its answer. The mirror pushes on every commit, so a missing
|
||||||
|
# status means GitHub has not got the push or is not running: after the
|
||||||
|
# timeout this fails, which is the cue to unset BUILD_ON.
|
||||||
|
github:
|
||||||
|
if: ${{ vars.BUILD_ON == 'github' }}
|
||||||
|
# Its own runner label with plenty of slots: this job only polls, but holds a slot
|
||||||
|
# for as long as the GitHub build takes, and must not starve the build runners.
|
||||||
|
runs-on: wait
|
||||||
|
timeout-minutes: 150
|
||||||
|
container:
|
||||||
|
image: python:3.13-slim@sha256:8d9d0b8bcf6506481eae4907c18f5e3e7902e629f5f6d684f9e7c32e85e3ddf0 # 3.13-slim
|
||||||
|
steps:
|
||||||
|
- env:
|
||||||
|
TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
SHA: ${{ github.event.pull_request.head.sha || github.sha }}
|
||||||
|
CONTEXT: github/ci (branch)
|
||||||
|
run: |
|
||||||
|
python3 - <<'EOF'
|
||||||
|
import json, os, time, urllib.request
|
||||||
|
url = (f"{os.environ['CI_SERVER_INTERNAL']}/api/v1/repos/{os.environ['GITHUB_REPOSITORY']}"
|
||||||
|
f"/commits/{os.environ['SHA']}/statuses?limit=50")
|
||||||
|
req = urllib.request.Request(url, headers={"Authorization": f"token {os.environ['TOKEN']}"})
|
||||||
|
ctx, last = os.environ["CONTEXT"], None
|
||||||
|
print(f"waiting for '{ctx}' on {os.environ['SHA']}", flush=True)
|
||||||
|
while True:
|
||||||
|
mine = [s for s in json.load(urllib.request.urlopen(req)) if s["context"] == ctx]
|
||||||
|
state = max(mine, key=lambda s: s["id"]) if mine else None
|
||||||
|
if state and state["status"] != last:
|
||||||
|
last = state["status"]; print(f"{ctx}: {last} {state.get('target_url', '')}", flush=True)
|
||||||
|
if last == "success": raise SystemExit(0)
|
||||||
|
if last in ("failure", "error"): raise SystemExit(1)
|
||||||
|
time.sleep(20)
|
||||||
|
EOF
|
||||||
@@ -42,6 +42,14 @@
|
|||||||
#
|
#
|
||||||
# The push logs in with PACKAGE_TOKEN (jcoffey-dev, write:package): the job's
|
# The push logs in with PACKAGE_TOKEN (jcoffey-dev, write:package): the job's
|
||||||
# own token is refused by the container registry.
|
# own token is refused by the container registry.
|
||||||
|
#
|
||||||
|
# BUILD_ON: when the Actions variable BUILD_ON is 'github' (org or repo), every
|
||||||
|
# job here but the announcement skips, and the tag is published by
|
||||||
|
# .github/workflows/ci.yml on the GitHub mirror instead -- same guards, same
|
||||||
|
# tags, the same Release and binaries, created here through the API. The
|
||||||
|
# `github` job waits for that run's commit status, "github/ci (tag)", and the
|
||||||
|
# announcement follows it as it follows the binaries here. Unset, everything
|
||||||
|
# runs here as before.
|
||||||
name: publish
|
name: publish
|
||||||
|
|
||||||
on:
|
on:
|
||||||
@@ -50,6 +58,7 @@ on:
|
|||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
version:
|
version:
|
||||||
|
if: ${{ vars.BUILD_ON != 'github' }}
|
||||||
runs-on: light
|
runs-on: light
|
||||||
container:
|
container:
|
||||||
image: python:3.13-slim@sha256:8d9d0b8bcf6506481eae4907c18f5e3e7902e629f5f6d684f9e7c32e85e3ddf0 # 3.13-slim
|
image: python:3.13-slim@sha256:8d9d0b8bcf6506481eae4907c18f5e3e7902e629f5f6d684f9e7c32e85e3ddf0 # 3.13-slim
|
||||||
@@ -88,6 +97,7 @@ jobs:
|
|||||||
echo "version $V"
|
echo "version $V"
|
||||||
|
|
||||||
publish-amd64:
|
publish-amd64:
|
||||||
|
if: ${{ vars.BUILD_ON != 'github' }}
|
||||||
needs: [version]
|
needs: [version]
|
||||||
runs-on: docker
|
runs-on: docker
|
||||||
container:
|
container:
|
||||||
@@ -128,6 +138,7 @@ jobs:
|
|||||||
run: docker logout "$REGISTRY" || true
|
run: docker logout "$REGISTRY" || true
|
||||||
|
|
||||||
publish-arm64:
|
publish-arm64:
|
||||||
|
if: ${{ vars.BUILD_ON != 'github' }}
|
||||||
needs: [version, publish-amd64]
|
needs: [version, publish-amd64]
|
||||||
runs-on: docker
|
runs-on: docker
|
||||||
container:
|
container:
|
||||||
@@ -162,11 +173,46 @@ jobs:
|
|||||||
- if: always()
|
- if: always()
|
||||||
run: docker logout "$REGISTRY" || true
|
run: docker logout "$REGISTRY" || true
|
||||||
|
|
||||||
|
# BUILD_ON=github: waits for the GitHub mirror's run for this tag, which
|
||||||
|
# posts its result back as the commit status "github/ci (tag)", and takes
|
||||||
|
# its answer. Fails after the timeout if no answer comes.
|
||||||
|
github:
|
||||||
|
if: ${{ vars.BUILD_ON == 'github' }}
|
||||||
|
# Its own runner label with plenty of slots: this job only polls, but holds a slot
|
||||||
|
# for as long as the GitHub build takes, and must not starve the build runners.
|
||||||
|
runs-on: wait
|
||||||
|
timeout-minutes: 240
|
||||||
|
container:
|
||||||
|
image: python:3.13-slim@sha256:8d9d0b8bcf6506481eae4907c18f5e3e7902e629f5f6d684f9e7c32e85e3ddf0 # 3.13-slim
|
||||||
|
steps:
|
||||||
|
- env:
|
||||||
|
TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
SHA: ${{ github.sha }}
|
||||||
|
CONTEXT: github/ci (tag)
|
||||||
|
run: |
|
||||||
|
python3 - <<'EOF'
|
||||||
|
import json, os, time, urllib.request
|
||||||
|
url = (f"{os.environ['CI_SERVER_INTERNAL']}/api/v1/repos/{os.environ['GITHUB_REPOSITORY']}"
|
||||||
|
f"/commits/{os.environ['SHA']}/statuses?limit=50")
|
||||||
|
req = urllib.request.Request(url, headers={"Authorization": f"token {os.environ['TOKEN']}"})
|
||||||
|
ctx, last = os.environ["CONTEXT"], None
|
||||||
|
print(f"waiting for '{ctx}' on {os.environ['SHA']}", flush=True)
|
||||||
|
while True:
|
||||||
|
mine = [s for s in json.load(urllib.request.urlopen(req)) if s["context"] == ctx]
|
||||||
|
state = max(mine, key=lambda s: s["id"]) if mine else None
|
||||||
|
if state and state["status"] != last:
|
||||||
|
last = state["status"]; print(f"{ctx}: {last} {state.get('target_url', '')}", flush=True)
|
||||||
|
if last == "success": raise SystemExit(0)
|
||||||
|
if last in ("failure", "error"): raise SystemExit(1)
|
||||||
|
time.sleep(20)
|
||||||
|
EOF
|
||||||
|
|
||||||
# The weekly release creates its Release (and so the tag) first; a tag
|
# The weekly release creates its Release (and so the tag) first; a tag
|
||||||
# pushed by hand has none. Either way the tag ends up with exactly one
|
# pushed by hand has none. Either way the tag ends up with exactly one
|
||||||
# Release, created once the amd64 image exists so its pull instructions
|
# Release, created once the amd64 image exists so its pull instructions
|
||||||
# work; arm64 and the binaries follow.
|
# work; arm64 and the binaries follow.
|
||||||
release:
|
release:
|
||||||
|
if: ${{ vars.BUILD_ON != 'github' }}
|
||||||
needs: [version, publish-amd64]
|
needs: [version, publish-amd64]
|
||||||
runs-on: light
|
runs-on: light
|
||||||
container:
|
container:
|
||||||
@@ -216,6 +262,7 @@ jobs:
|
|||||||
# `docker create` does not start anything, so pulling an arm64 image on an
|
# `docker create` does not start anything, so pulling an arm64 image on an
|
||||||
# amd64 runner and copying a file out of it needs no emulation.
|
# amd64 runner and copying a file out of it needs no emulation.
|
||||||
binaries:
|
binaries:
|
||||||
|
if: ${{ vars.BUILD_ON != 'github' }}
|
||||||
needs: [version, publish-arm64, release]
|
needs: [version, publish-arm64, release]
|
||||||
runs-on: docker
|
runs-on: docker
|
||||||
container:
|
container:
|
||||||
@@ -289,8 +336,14 @@ jobs:
|
|||||||
# The release above is made with the job's own token, and Gitea starts no
|
# The release above is made with the job's own token, and Gitea starts no
|
||||||
# workflow for events the Actions bot causes -- announce.yml's
|
# workflow for events the Actions bot causes -- announce.yml's
|
||||||
# 'on: release' never fires for it -- so announce it from here.
|
# 'on: release' never fires for it -- so announce it from here.
|
||||||
|
#
|
||||||
|
# With BUILD_ON=github the release and binaries come from the GitHub run,
|
||||||
|
# so the announcement waits for the `github` job instead. The Release that
|
||||||
|
# run creates for a hand-pushed tag is made with a user token, so
|
||||||
|
# announce.yml fires for it too; discourse-release keeps one topic per tag.
|
||||||
announce:
|
announce:
|
||||||
needs: [release, binaries]
|
needs: [release, binaries, github]
|
||||||
|
if: ${{ always() && ((needs.release.result == 'success' && needs.binaries.result == 'success') || needs.github.result == 'success') }}
|
||||||
runs-on: light
|
runs-on: light
|
||||||
steps:
|
steps:
|
||||||
- uses: coffey-labs/actions/discourse-release@e9293996e2efa770839121fa8f8da93083f216be
|
- uses: coffey-labs/actions/discourse-release@e9293996e2efa770839121fa8f8da93083f216be
|
||||||
|
|||||||
@@ -5,11 +5,6 @@
|
|||||||
|
|
||||||
version: 2
|
version: 2
|
||||||
updates:
|
updates:
|
||||||
- package-ecosystem: "cargo" # See documentation for possible values
|
|
||||||
directory: "/" # Location of package manifests
|
|
||||||
schedule:
|
|
||||||
interval: "weekly"
|
|
||||||
|
|
||||||
# Enable version updates for GitHub Actions
|
# Enable version updates for GitHub Actions
|
||||||
- package-ecosystem: "github-actions"
|
- package-ecosystem: "github-actions"
|
||||||
# Workflow files stored in the default location of `.github/workflows`
|
# Workflow files stored in the default location of `.github/workflows`
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Close issues from non-allowed authors
|
- name: Close issues from non-allowed authors
|
||||||
uses: actions/github-script@v7
|
uses: actions/github-script@v9
|
||||||
with:
|
with:
|
||||||
script: |
|
script: |
|
||||||
// Users allowed to open issues directly. All other authors will have
|
// Users allowed to open issues directly. All other authors will have
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ jobs:
|
|||||||
sparse-checkout-cone-mode: false
|
sparse-checkout-cone-mode: false
|
||||||
|
|
||||||
- name: Close PRs from non-allowed authors
|
- name: Close PRs from non-allowed authors
|
||||||
uses: actions/github-script@v7
|
uses: actions/github-script@v9
|
||||||
with:
|
with:
|
||||||
script: |
|
script: |
|
||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ jobs:
|
|||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: Post support portal redirect
|
- name: Post support portal redirect
|
||||||
uses: actions/github-script@v7
|
uses: actions/github-script@v9
|
||||||
with:
|
with:
|
||||||
script: |
|
script: |
|
||||||
const discussion = context.payload.discussion;
|
const discussion = context.payload.discussion;
|
||||||
|
|||||||
@@ -73,6 +73,6 @@ jobs:
|
|||||||
# Upload the results to GitHub's code scanning dashboard (optional).
|
# Upload the results to GitHub's code scanning dashboard (optional).
|
||||||
# Commenting out will disable upload of results to your repo's Code Scanning dashboard
|
# Commenting out will disable upload of results to your repo's Code Scanning dashboard
|
||||||
- name: "Upload to code-scanning"
|
- name: "Upload to code-scanning"
|
||||||
uses: github/codeql-action/[email protected]7.4
|
uses: github/codeql-action/[email protected]8.2
|
||||||
with:
|
with:
|
||||||
sarif_file: results.sarif
|
sarif_file: results.sarif
|
||||||
@@ -36,6 +36,6 @@ jobs:
|
|||||||
severity: 'CRITICAL,HIGH'
|
severity: 'CRITICAL,HIGH'
|
||||||
|
|
||||||
- name: Upload Trivy scan results to GitHub Security tab
|
- name: Upload Trivy scan results to GitHub Security tab
|
||||||
uses: github/codeql-action/[email protected]7.4
|
uses: github/codeql-action/[email protected]8.2
|
||||||
with:
|
with:
|
||||||
sarif_file: 'trivy-results.sarif'
|
sarif_file: 'trivy-results.sarif'
|
||||||
@@ -1,42 +0,0 @@
|
|||||||
version: 2
|
|
||||||
updates:
|
|
||||||
# Cargo. One entry: the workspace has a single lockfile at the root, and
|
|
||||||
# ~30 manifests that upstream bumps on every release -- pointing entries at
|
|
||||||
# individual crates would find manifests with no lockfile beside them.
|
|
||||||
#
|
|
||||||
# Minor and patch arrive as one pull request a week. Majors are left out of
|
|
||||||
# the group on purpose: they are migrations rather than bumps, and each one
|
|
||||||
# deserves its own pull request and its own CI run.
|
|
||||||
- package-ecosystem: cargo
|
|
||||||
directory: "/"
|
|
||||||
schedule:
|
|
||||||
interval: weekly
|
|
||||||
day: tuesday
|
|
||||||
time: "09:00"
|
|
||||||
timezone: Etc/UTC
|
|
||||||
open-pull-requests-limit: 5
|
|
||||||
groups:
|
|
||||||
minor-and-patch:
|
|
||||||
update-types:
|
|
||||||
- minor
|
|
||||||
- patch
|
|
||||||
- package-ecosystem: github-actions
|
|
||||||
directory: "/"
|
|
||||||
schedule:
|
|
||||||
interval: weekly
|
|
||||||
day: tuesday
|
|
||||||
time: "09:00"
|
|
||||||
timezone: Etc/UTC
|
|
||||||
groups:
|
|
||||||
actions:
|
|
||||||
patterns:
|
|
||||||
- "*"
|
|
||||||
# The Dockerfiles pin their base images, so this is what keeps a published
|
|
||||||
# image off a stale base between releases.
|
|
||||||
- package-ecosystem: docker
|
|
||||||
directory: "/"
|
|
||||||
schedule:
|
|
||||||
interval: weekly
|
|
||||||
day: tuesday
|
|
||||||
time: "09:00"
|
|
||||||
timezone: Etc/UTC
|
|
||||||
+469
-38
@@ -1,51 +1,482 @@
|
|||||||
# What CI can check without a mail server's worth of infrastructure.
|
# CI and publishing on GitHub, for the repository Gitea mirrors here.
|
||||||
#
|
#
|
||||||
# The build, and that every test target compiles. It deliberately does not
|
# Gitea (git.coffeylabs.org) is where this project lives: pull requests,
|
||||||
# *run* the test suites: the unit tests only build with the integration crate
|
# issues, releases and the container registry are all there, and it pushes
|
||||||
# in the graph, because that is what switches on the `test_mode` features they
|
# every branch and tag to this GitHub copy as it changes. GitHub's hosted
|
||||||
# rely on (docs/spec/SPEC.md 2.2b), and the integration suites need a `STORE`,
|
# runners are faster than the self-hosted ones -- and have native arm64 -- so
|
||||||
# fixed ports, and in most cases a container apiece (docs/spec/
|
# the building happens here, and the answer goes back to Gitea as a commit
|
||||||
# container-tests.md). Running them here would mean either a green tick that
|
# status that Gitea's own ci.yml / publish.yml wait on.
|
||||||
# skipped everything, or a red one that means "the runner has no Redis".
|
|
||||||
#
|
#
|
||||||
# So this catches what it can honestly catch -- code that does not compile,
|
# One switch decides which side builds: the Actions variable BUILD_ON, set on
|
||||||
# including test code -- and the suites are run by hand, one at a time, as
|
# both forges. BUILD_ON=github runs every job below and turns Gitea's heavy
|
||||||
# that page describes. If that changes, it changes because someone made the
|
# jobs into a wait for this one; anything else leaves Gitea building exactly
|
||||||
# suites runnable unattended, not because CI started ignoring failures.
|
# as before and every job here skips. If GitHub is ever unavailable, unset it
|
||||||
name: CI
|
# on Gitea and nothing else has to change.
|
||||||
|
#
|
||||||
|
# Needs, as organization settings rather than anything in this file:
|
||||||
|
# variables BUILD_ON=github, REGISTRY (the Gitea container registry),
|
||||||
|
# GITEA_URL (the Gitea base URL)
|
||||||
|
# secret GITEA_TOKEN -- jcoffey-dev, write:repository + write:package:
|
||||||
|
# commit statuses, the release and its assets, the registry push
|
||||||
|
#
|
||||||
|
# There is no pull_request trigger: pull requests happen on Gitea, and their
|
||||||
|
# branch arrives here as an ordinary push. Branch pushes get what Gitea's
|
||||||
|
# ci.yml checks; v* tags get what its publish.yml does. Schedules (the weekly
|
||||||
|
# release, the upstream watch) and the release announcement stay on Gitea.
|
||||||
|
#
|
||||||
|
# Every `uses:` is pinned to a full commit SHA with the release in the
|
||||||
|
# trailing comment. A tag is a mutable pointer; do not "simplify" a pin back
|
||||||
|
# to one. Only GitHub's own actions and the three docker/* ones are used.
|
||||||
|
name: ci
|
||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
branches: [main]
|
branches: ['**']
|
||||||
pull_request:
|
tags: ['**']
|
||||||
# Lets CI be run by hand against any ref, including one that predates a CI
|
|
||||||
# change, without pushing an empty commit to move it.
|
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
# A second push to a branch cancels the run still going for the first: the
|
# A newer push to a branch cancels the run for the older one, whose answer is
|
||||||
# older run's answer is about code nobody is looking at any more.
|
# about code nobody is looking at any more. A tag run is never cancelled: it
|
||||||
|
# publishes.
|
||||||
concurrency:
|
concurrency:
|
||||||
group: ci-${{ github.ref }}
|
group: ci-${{ github.ref }}
|
||||||
cancel-in-progress: true
|
cancel-in-progress: ${{ github.ref_type == 'branch' }}
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
env:
|
||||||
|
GITEA_URL: ${{ vars.GITEA_URL }}
|
||||||
|
# The Gitea status this run answers for. Gitea waits on the one matching
|
||||||
|
# its own event: "(branch)" from ci.yml, "(tag)" from publish.yml.
|
||||||
|
STATUS_CONTEXT: github/ci (${{ github.ref_type }})
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
# Tells Gitea a run has started, so a pull request shows it as pending
|
||||||
|
# rather than missing while the build is still going.
|
||||||
|
start:
|
||||||
|
if: ${{ vars.BUILD_ON == 'github' }}
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- env:
|
||||||
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||||
|
run: |
|
||||||
|
jq -n --arg c "$STATUS_CONTEXT" \
|
||||||
|
--arg u "$GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID" \
|
||||||
|
'{state:"pending", context:$c, target_url:$u, description:"GitHub Actions"}' |
|
||||||
|
curl -fsS -o /dev/null -X POST -H "Authorization: token $GITEA_TOKEN" \
|
||||||
|
-H 'Content-Type: application/json' --data @- \
|
||||||
|
"$GITEA_URL/api/v1/repos/$GITHUB_REPOSITORY/statuses/$GITHUB_SHA"
|
||||||
|
|
||||||
|
# ----------------------------------------------------------- branches ------
|
||||||
|
# What an upstream merge can bring in or leave behind without a conflict:
|
||||||
|
# the upstream name in a new string literal, and a changed upstream file
|
||||||
|
# without the AGPL 5(a) notice. Seconds, and needs no toolchain. The notice
|
||||||
|
# check diffs against the upstream snapshot in the history, hence the full
|
||||||
|
# fetch.
|
||||||
|
fork-checks:
|
||||||
|
if: ${{ vars.BUILD_ON == 'github' && github.ref_type == 'branch' }}
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
# Every `uses:` here is pinned to a full commit SHA, with the release it
|
|
||||||
# belongs to in the trailing comment. A tag is a mutable pointer, so
|
|
||||||
# trusting `@v7` is trusting every future version of that action,
|
|
||||||
# including one pushed by whoever compromises the account. Dependabot
|
|
||||||
# updates both halves together -- do not "simplify" a pin back to a tag.
|
|
||||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||||
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
|
with:
|
||||||
- name: System dependencies
|
fetch-depth: 0
|
||||||
# foundationdb and the search backends are off by default, but the
|
- run: python3 tools/fork/name-check.py
|
||||||
# default feature set still links against the system's C libraries.
|
- if: always()
|
||||||
run: sudo apt-get update && sudo apt-get install -y --no-install-recommends clang
|
run: python3 tools/fork/notice-check.py
|
||||||
- name: Build the server
|
# Cargo can patch a dependency to a directory in this repository, and
|
||||||
run: cargo build -p inbuxa --locked
|
# the image builds from a context .dockerignore prunes to almost
|
||||||
- name: Compile every test target
|
# nothing. CI never sees the difference; a release does.
|
||||||
# `--no-run` is the point: it builds the unit tests and the integration
|
- if: always()
|
||||||
# crate together, which is the combination that resolves the test
|
run: python3 tools/fork/context-check.py
|
||||||
# features, and stops short of running anything that wants a store.
|
# The personal-data catalog must classify every object and field the
|
||||||
run: cargo test --workspace --locked --no-run
|
# schema has, and name nothing that is gone.
|
||||||
|
- if: always()
|
||||||
|
run: python3 tools/fork/privacy-check.py
|
||||||
|
# The admin reads each expression field's allowed values and variables
|
||||||
|
# from the schema; they're generated from the registry and must match it.
|
||||||
|
- if: always()
|
||||||
|
run: python3 tools/fork/expr-schema.py --check
|
||||||
|
- if: always()
|
||||||
|
run: python3 -m unittest discover -s tools/fork/tests
|
||||||
|
|
||||||
|
# The build, and that every test target compiles. The suites are not run:
|
||||||
|
# they need a store, fixed ports and containers (docs/spec/
|
||||||
|
# container-tests.md), and are run by hand.
|
||||||
|
build:
|
||||||
|
if: ${{ vars.BUILD_ON == 'github' && github.ref_type == 'branch' }}
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
env:
|
||||||
|
CARGO_INCREMENTAL: "0"
|
||||||
|
# Debug info is most of a dev target dir, and nothing here runs a
|
||||||
|
# debugger. Without it the dev and test builds fit the runner's disk and
|
||||||
|
# the cache below stays small enough to be worth restoring.
|
||||||
|
CARGO_PROFILE_DEV_DEBUG: "0"
|
||||||
|
CARGO_PROFILE_TEST_DEBUG: "0"
|
||||||
|
steps:
|
||||||
|
# The hosted image carries toolchains this build never touches; a dev,
|
||||||
|
# test and release build of RocksDB and the workspace needs the room.
|
||||||
|
- run: |
|
||||||
|
sudo rm -rf /usr/share/dotnet /usr/local/lib/android /opt/ghc /opt/hostedtoolcache/CodeQL
|
||||||
|
df -h /
|
||||||
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||||
|
# Current stable, as Gitea's rust:1 image is.
|
||||||
|
- id: rust
|
||||||
|
run: |
|
||||||
|
rustup toolchain install stable --profile minimal
|
||||||
|
rustup default stable
|
||||||
|
echo "version=$(rustc -V | cut -d' ' -f2)" >> "$GITHUB_OUTPUT"
|
||||||
|
- run: sudo apt-get update -qq && sudo apt-get install -y -qq --no-install-recommends clang >/dev/null
|
||||||
|
# Cargo's download cache and the dev/test target dir, keyed on the
|
||||||
|
# lockfile and the compiler. Saved from main only, so the one cache
|
||||||
|
# every branch restores is main's, and branches cannot evict it.
|
||||||
|
- uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
||||||
|
with:
|
||||||
|
path: |
|
||||||
|
~/.cargo/registry/index
|
||||||
|
~/.cargo/registry/cache
|
||||||
|
~/.cargo/git/db
|
||||||
|
target/debug
|
||||||
|
key: cargo-${{ steps.rust.outputs.version }}-${{ hashFiles('Cargo.lock') }}
|
||||||
|
restore-keys: cargo-${{ steps.rust.outputs.version }}-
|
||||||
|
- run: cargo build -p inbuxa --locked
|
||||||
|
# --no-run: compiles every test target without running them, which
|
||||||
|
# catches a test that no longer builds without needing a store.
|
||||||
|
- run: cargo test --workspace --locked --no-run
|
||||||
|
- if: github.ref == 'refs/heads/main'
|
||||||
|
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
|
||||||
|
with:
|
||||||
|
path: |
|
||||||
|
~/.cargo/registry/index
|
||||||
|
~/.cargo/registry/cache
|
||||||
|
~/.cargo/git/db
|
||||||
|
target/debug
|
||||||
|
key: cargo-${{ steps.rust.outputs.version }}-${{ hashFiles('Cargo.lock') }}
|
||||||
|
# The release profile, on main only. It is the profile the image is
|
||||||
|
# built with, and it fails in ways the dev profile does not: v2026.9.24
|
||||||
|
# was tagged on a commit whose CI was green and whose release build
|
||||||
|
# could not compile the scim crate at all.
|
||||||
|
- if: github.ref == 'refs/heads/main'
|
||||||
|
run: cargo build -p inbuxa --locked --release
|
||||||
|
|
||||||
|
# --------------------------------------------------------------- tags ------
|
||||||
|
# Two guards before anything is pushed, the same as Gitea's publish.yml:
|
||||||
|
# * the tag must be v<brand_version!>. The version is a string in
|
||||||
|
# crates/types/src/branding.rs, not Cargo.toml, and the image is tagged
|
||||||
|
# with it, so a tag beside an unbumped macro would publish an image that
|
||||||
|
# reports a different version from its tag.
|
||||||
|
# * the tag must be on main or on a release/* branch, so an image never
|
||||||
|
# describes code that was never reviewed onto one of them. A release/*
|
||||||
|
# branch carries a hotfix cut from an earlier release tag.
|
||||||
|
version:
|
||||||
|
if: ${{ vars.BUILD_ON == 'github' && github.ref_type == 'tag' && startsWith(github.ref_name, 'v') }}
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
outputs:
|
||||||
|
version: ${{ steps.v.outputs.version }}
|
||||||
|
steps:
|
||||||
|
# Full history, and every branch as origin/*: the ancestry check cannot
|
||||||
|
# be answered from a shallow clone.
|
||||||
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
- id: v
|
||||||
|
env:
|
||||||
|
TAG: ${{ github.ref_name }}
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
# Scoped to the macro body: branding.rs holds other string literals,
|
||||||
|
# and tagging an image from one of those would be worse than failing.
|
||||||
|
V="$(awk '/macro_rules! brand_version /,/^}/' crates/types/src/branding.rs \
|
||||||
|
| grep -om1 '"[0-9][^"]*"' | tr -d '"')"
|
||||||
|
[ -n "$V" ] || { echo "could not read brand_version! from branding.rs" >&2; exit 1; }
|
||||||
|
if [ "$TAG" != "v$V" ]; then
|
||||||
|
echo "Tag $TAG names a commit whose brand_version! says $V." >&2
|
||||||
|
echo "Refusing to publish an image that would report the wrong version." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
commit="$(git rev-parse "${TAG}^{commit}")"
|
||||||
|
on=""
|
||||||
|
for ref in origin/main $(git for-each-ref --format='%(refname:short)' 'refs/remotes/origin/release/*'); do
|
||||||
|
if git merge-base --is-ancestor "$commit" "$ref"; then on="$ref"; break; fi
|
||||||
|
done
|
||||||
|
[ -n "$on" ] || { echo "$TAG is not on main or a release/* branch" >&2; exit 1; }
|
||||||
|
echo "$TAG is on $on"
|
||||||
|
echo "version=$V" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
|
# Each architecture on its own native runner, side by side. The Dockerfile
|
||||||
|
# cross-compiles from the build platform, and on the self-hosted runners one
|
||||||
|
# machine built both one after the other; here two machines build at once,
|
||||||
|
# each natively (the builder stage picks the matching target, and the
|
||||||
|
# aarch64 toolchain it installs exists on arm64 too), and the small final
|
||||||
|
# stage needs no QEMU. amd64 also moves :<version> as soon as it is done, so
|
||||||
|
# a production deploy can start from it; :latest waits for the index below,
|
||||||
|
# so it never names an image without arm64.
|
||||||
|
publish:
|
||||||
|
needs: [version]
|
||||||
|
runs-on: ${{ matrix.runner }}
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
matrix:
|
||||||
|
include:
|
||||||
|
- arch: amd64
|
||||||
|
runner: ubuntu-latest
|
||||||
|
- arch: arm64
|
||||||
|
runner: ubuntu-24.04-arm
|
||||||
|
env:
|
||||||
|
VERSION: ${{ needs.version.outputs.version }}
|
||||||
|
steps:
|
||||||
|
- run: |
|
||||||
|
sudo rm -rf /usr/share/dotnet /usr/local/lib/android /opt/ghc /opt/hostedtoolcache/CodeQL
|
||||||
|
echo "IMAGE=${{ vars.REGISTRY }}/${GITHUB_REPOSITORY,,}" >> "$GITHUB_ENV"
|
||||||
|
# The release link (fat LTO, one codegen unit) outgrows the runner's
|
||||||
|
# 16 GB: v2026.9.30's arm64 link was killed for memory. Swap gives it
|
||||||
|
# room; buildx's container has no memory limit of its own, so it
|
||||||
|
# reaches the host's swap.
|
||||||
|
- run: |
|
||||||
|
sudo fallocate -l 16G /swap.release
|
||||||
|
sudo chmod 600 /swap.release
|
||||||
|
sudo mkswap /swap.release >/dev/null
|
||||||
|
sudo swapon /swap.release
|
||||||
|
free -g
|
||||||
|
df -h /
|
||||||
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||||
|
- uses: docker/setup-buildx-action@594f3bf4285d9ea8dc53c9a0c9c4092420091003 # v4.4.0
|
||||||
|
- uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
||||||
|
with:
|
||||||
|
registry: ${{ vars.REGISTRY }}
|
||||||
|
username: jcoffey-dev
|
||||||
|
password: ${{ secrets.GITEA_TOKEN }}
|
||||||
|
# Attestations off: they add manifests of their own, and the index
|
||||||
|
# should hold the two images and nothing else. No build cache: GitHub
|
||||||
|
# scopes a tag run's cache to that tag, so the next release could never
|
||||||
|
# read it, and each one would park several GB in the repository's 10 GB
|
||||||
|
# cache and evict main's cargo cache.
|
||||||
|
- uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
|
||||||
|
with:
|
||||||
|
context: .
|
||||||
|
platforms: linux/${{ matrix.arch }}
|
||||||
|
provenance: false
|
||||||
|
sbom: false
|
||||||
|
push: true
|
||||||
|
tags: |
|
||||||
|
${{ env.IMAGE }}:${{ env.VERSION }}-${{ matrix.arch }}
|
||||||
|
${{ matrix.arch == 'amd64' && format('{0}:{1}', env.IMAGE, env.VERSION) || '' }}
|
||||||
|
|
||||||
|
# Joins the two per-architecture tags into :<version> and :latest. Built
|
||||||
|
# from the per-architecture tags rather than :<version>, which by now is
|
||||||
|
# the amd64 image and would be read as such.
|
||||||
|
index:
|
||||||
|
needs: [version, publish]
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
env:
|
||||||
|
VERSION: ${{ needs.version.outputs.version }}
|
||||||
|
steps:
|
||||||
|
- run: echo "IMAGE=${{ vars.REGISTRY }}/${GITHUB_REPOSITORY,,}" >> "$GITHUB_ENV"
|
||||||
|
- uses: docker/setup-buildx-action@594f3bf4285d9ea8dc53c9a0c9c4092420091003 # v4.4.0
|
||||||
|
- uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
||||||
|
with:
|
||||||
|
registry: ${{ vars.REGISTRY }}
|
||||||
|
username: jcoffey-dev
|
||||||
|
password: ${{ secrets.GITEA_TOKEN }}
|
||||||
|
- run: |
|
||||||
|
docker buildx imagetools create \
|
||||||
|
--tag "$IMAGE:$VERSION" \
|
||||||
|
--tag "$IMAGE:latest" \
|
||||||
|
"$IMAGE:$VERSION-amd64" "$IMAGE:$VERSION-arm64"
|
||||||
|
docker buildx imagetools inspect "$IMAGE:$VERSION"
|
||||||
|
# Gitea keeps a container package on its owner; linking it shows it on
|
||||||
|
# the repository's Packages tab. Idempotent.
|
||||||
|
- env:
|
||||||
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||||
|
run: |
|
||||||
|
owner="${GITHUB_REPOSITORY%%/*}"; name="${GITHUB_REPOSITORY#*/}"
|
||||||
|
curl -fsS -o /dev/null -X POST -H "Authorization: token $GITEA_TOKEN" \
|
||||||
|
"$GITEA_URL/api/v1/packages/${owner,,}/container/$name/-/link/$name" \
|
||||||
|
|| echo "package already linked (or link refused); not fatal"
|
||||||
|
|
||||||
|
# The weekly release creates its Release (and so the tag) on Gitea first; a
|
||||||
|
# tag pushed by hand has none. Either way the tag ends up with exactly one
|
||||||
|
# Release there, created once the image exists so its pull instructions
|
||||||
|
# work.
|
||||||
|
release:
|
||||||
|
needs: [version, index]
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- env:
|
||||||
|
TAG: ${{ github.ref_name }}
|
||||||
|
VERSION: ${{ needs.version.outputs.version }}
|
||||||
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||||
|
REGISTRY: ${{ vars.REGISTRY }}
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
api="$GITEA_URL/api/v1/repos/$GITHUB_REPOSITORY"
|
||||||
|
code="$(curl -sS -o /dev/null -w '%{http_code}' -H "Authorization: token $GITEA_TOKEN" "$api/releases/tags/$TAG")"
|
||||||
|
if [ "$code" = 200 ]; then echo "$TAG already has a release"; exit 0; fi
|
||||||
|
[ "$code" = 404 ] || { echo "looking up the release for $TAG answered $code" >&2; exit 1; }
|
||||||
|
image="$REGISTRY/${GITHUB_REPOSITORY,,}:$VERSION"
|
||||||
|
body="Container image: \`$image\` (linux/amd64, linux/arm64); also \`:latest\`.
|
||||||
|
|
||||||
|
Binaries for a host install are attached: \`inbuxa-linux-amd64.tar.gz\` and \`inbuxa-linux-arm64.tar.gz\`, with \`SHA256SUMS\`. Each is the binary out of this release's image for that architecture, so it is the same build. The image grants it \`cap_net_bind_service\`; a host install has to grant that itself (\`setcap\`, or \`AmbientCapabilities\` in the unit) to bind port 25."
|
||||||
|
jq -n --arg tag "$TAG" --arg name "INBUXA $VERSION" --arg body "$body" \
|
||||||
|
'{tag_name:$tag, name:$name, body:$body}' |
|
||||||
|
curl -fsS -X POST -H "Authorization: token $GITEA_TOKEN" -H 'Content-Type: application/json' \
|
||||||
|
--data @- "$api/releases" | jq -r '"created release " + .tag_name'
|
||||||
|
|
||||||
|
# The binaries for a host install, taken out of the image that was just
|
||||||
|
# pushed rather than compiled again: the binary in the tarball is the file
|
||||||
|
# the image runs. `docker create` starts nothing, so copying a file out of
|
||||||
|
# the arm64 image on an amd64 runner needs no emulation.
|
||||||
|
binaries:
|
||||||
|
needs: [version, index, release]
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
env:
|
||||||
|
VERSION: ${{ needs.version.outputs.version }}
|
||||||
|
TAG: ${{ github.ref_name }}
|
||||||
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||||
|
steps:
|
||||||
|
- run: echo "IMAGE=${{ vars.REGISTRY }}/${GITHUB_REPOSITORY,,}" >> "$GITHUB_ENV"
|
||||||
|
- uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
||||||
|
with:
|
||||||
|
registry: ${{ vars.REGISTRY }}
|
||||||
|
username: jcoffey-dev
|
||||||
|
password: ${{ secrets.GITEA_TOKEN }}
|
||||||
|
- name: take the binaries out of the image
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
mkdir -p out && cd out
|
||||||
|
for arch in amd64 arm64; do
|
||||||
|
docker pull -q --platform "linux/$arch" "$IMAGE:$VERSION"
|
||||||
|
id="$(docker create --platform "linux/$arch" "$IMAGE:$VERSION")"
|
||||||
|
docker cp "$id:/usr/local/bin/inbuxa" inbuxa
|
||||||
|
docker rm -f "$id" >/dev/null
|
||||||
|
chmod 0755 inbuxa
|
||||||
|
tar -czf "inbuxa-linux-$arch.tar.gz" inbuxa
|
||||||
|
rm inbuxa
|
||||||
|
done
|
||||||
|
sha256sum inbuxa-linux-*.tar.gz > SHA256SUMS
|
||||||
|
cat SHA256SUMS
|
||||||
|
# A re-run of a tag replaces its assets rather than leaving two files
|
||||||
|
# with the same name and different contents.
|
||||||
|
#
|
||||||
|
# The uploads cross Cloudflare, which dropped 50 MB HTTP/2 uploads
|
||||||
|
# part-way for v2026.9.30.1 (curl 92, PROTOCOL_ERROR; origin logged
|
||||||
|
# 400), once on each of two runs. Uploads go over HTTP/1.1 and retry.
|
||||||
|
- name: attach them to the release
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
api="$GITEA_URL/api/v1/repos/$GITHUB_REPOSITORY"
|
||||||
|
auth="Authorization: token $GITEA_TOKEN"
|
||||||
|
retry=(--retry 5 --retry-all-errors --retry-delay 15)
|
||||||
|
rel="$(curl -fsS "${retry[@]}" -H "$auth" "$api/releases/tags/$TAG" | jq -r .id)"
|
||||||
|
assets="$(curl -fsS "${retry[@]}" -H "$auth" "$api/releases/$rel/assets")"
|
||||||
|
for f in out/inbuxa-linux-amd64.tar.gz out/inbuxa-linux-arm64.tar.gz out/SHA256SUMS; do
|
||||||
|
name="$(basename "$f")"
|
||||||
|
old="$(jq -r --arg n "$name" '.[] | select(.name == $n) | .id' <<<"$assets")"
|
||||||
|
for id in $old; do curl -fsS "${retry[@]}" -o /dev/null -X DELETE -H "$auth" "$api/releases/$rel/assets/$id"; done
|
||||||
|
curl -fsS --http1.1 "${retry[@]}" -o /dev/null -X POST -H "$auth" -F "attachment=@$f" "$api/releases/$rel/assets?name=$name"
|
||||||
|
echo "attached $name"
|
||||||
|
done
|
||||||
|
|
||||||
|
# ------------------------------------------------------ ghcr replica ------
|
||||||
|
# Copies the release image from the Gitea registry, which stays the
|
||||||
|
# authoritative one, to ghcr.io under the same version tag and :latest. It is
|
||||||
|
# a copy, not a second build: the digest on GHCR is the digest on the
|
||||||
|
# registry, so `docker pull ghcr.io/...` gets exactly the same image. Left
|
||||||
|
# out of the report to Gitea, like the release copy, so a GHCR problem
|
||||||
|
# cannot fail a release.
|
||||||
|
ghcr:
|
||||||
|
if: ${{ vars.BUILD_ON == 'github' && github.ref_type == 'tag' }}
|
||||||
|
needs: [version, index]
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
packages: write
|
||||||
|
steps:
|
||||||
|
- env:
|
||||||
|
GH_TOKEN: ${{ github.token }}
|
||||||
|
TAG: ${{ needs.version.outputs.version }}
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
src="${{ vars.REGISTRY }}/${GITHUB_REPOSITORY,,}"
|
||||||
|
dst="ghcr.io/${GITHUB_REPOSITORY,,}"
|
||||||
|
tag="$TAG"
|
||||||
|
echo "$GH_TOKEN" | docker login ghcr.io -u "$GITHUB_ACTOR" --password-stdin
|
||||||
|
docker buildx imagetools create -t "$dst:$tag" -t "$dst:latest" "$src:$tag"
|
||||||
|
want="$(docker buildx imagetools inspect "$src:$tag" --format '{{json .Manifest.Digest}}')"
|
||||||
|
got="$(docker buildx imagetools inspect "$dst:$tag" --format '{{json .Manifest.Digest}}')"
|
||||||
|
echo "registry $src:$tag = $want"
|
||||||
|
echo "ghcr $dst:$tag = $got"
|
||||||
|
[ "$want" = "$got" ] || echo "::warning::GHCR digest differs from the registry's"
|
||||||
|
docker logout ghcr.io
|
||||||
|
|
||||||
|
# ---------------------------------------------------- github release ------
|
||||||
|
# Copies this tag's Gitea release -- notes and files -- to a GitHub release,
|
||||||
|
# so the replica's Releases page, and anyone watching it, keeps up. Gitea's
|
||||||
|
# release is the real one; this is left out of the report to Gitea, so a
|
||||||
|
# failure here cannot fail a release. PR and issue numbers in the notes are
|
||||||
|
# rewritten to Gitea links: on GitHub a bare #16 is some other PR.
|
||||||
|
github-release:
|
||||||
|
if: ${{ vars.BUILD_ON == 'github' && github.ref_type == 'tag' }}
|
||||||
|
needs: [binaries]
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
env:
|
||||||
|
GITEA_URL: ${{ vars.GITEA_URL }}
|
||||||
|
GH_TOKEN: ${{ github.token }}
|
||||||
|
TAG: ${{ github.ref_name }}
|
||||||
|
steps:
|
||||||
|
- run: |
|
||||||
|
set -euo pipefail
|
||||||
|
if gh release view "$TAG" --repo "$GITHUB_REPOSITORY" >/dev/null 2>&1; then
|
||||||
|
echo "GitHub already has a release for $TAG"; exit 0
|
||||||
|
fi
|
||||||
|
# The Gitea release exists by now if this run made it; if the weekly
|
||||||
|
# release job made it, it came before the tag. Allow a few minutes.
|
||||||
|
code=0
|
||||||
|
for _ in $(seq 1 15); do
|
||||||
|
code="$(curl -sS -o rel.json -w '%{http_code}' "$GITEA_URL/api/v1/repos/$GITHUB_REPOSITORY/releases/tags/$TAG")"
|
||||||
|
[ "$code" = 200 ] && break
|
||||||
|
sleep 20
|
||||||
|
done
|
||||||
|
if [ "$code" != 200 ]; then echo "No Gitea release for $TAG; nothing to copy"; exit 0; fi
|
||||||
|
if [ "$(jq -r .draft rel.json)" = true ]; then echo "The Gitea release is a draft; not copying"; exit 0; fi
|
||||||
|
export BASE="$(jq -r '.html_url | sub("/releases/tag/.*$"; "")' rel.json)"
|
||||||
|
jq -r '.body // ""' rel.json | perl -pe 's{(?<![\w/&\[])#(\d+)\b}{[#$1]($ENV{BASE}/pulls/$1)}g' > notes.md
|
||||||
|
printf '\n\n_Mirrored from [the Gitea release](%s); report issues on [Gitea](%s/issues)._\n' \
|
||||||
|
"$(jq -r .html_url rel.json)" "$BASE" >> notes.md
|
||||||
|
files=()
|
||||||
|
mkdir -p files
|
||||||
|
while IFS=$'\t' read -r name url; do
|
||||||
|
curl -fsSL -o "files/$name" "$url"; files+=("files/$name")
|
||||||
|
done < <(jq -r '.assets[]? | [.name, .browser_download_url] | @tsv' rel.json)
|
||||||
|
title="$(jq -r '.name // ""' rel.json)"; [ -n "$title" ] || title="$TAG"
|
||||||
|
if [ "$(jq -r .prerelease rel.json)" = true ]; then kind=--prerelease; else kind=--latest; fi
|
||||||
|
gh release create "$TAG" --repo "$GITHUB_REPOSITORY" --verify-tag --title "$title" \
|
||||||
|
--notes-file notes.md "$kind" "${files[@]}"
|
||||||
|
echo "created the GitHub release for $TAG with ${#files[@]} file(s)"
|
||||||
|
|
||||||
|
# ------------------------------------------------------------- report ------
|
||||||
|
# One commit status on Gitea for the whole run: what Gitea's ci.yml and
|
||||||
|
# publish.yml wait on. Skipped jobs (the tag jobs on a branch, and the other
|
||||||
|
# way round) count as passing; a failed or cancelled one does not.
|
||||||
|
report:
|
||||||
|
if: ${{ always() && vars.BUILD_ON == 'github' }}
|
||||||
|
needs: [start, fork-checks, build, version, publish, index, release, binaries]
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- env:
|
||||||
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||||
|
STATE: ${{ contains(needs.*.result, 'failure') && 'failure' || (contains(needs.*.result, 'cancelled') && 'cancelled' || 'success') }}
|
||||||
|
run: |
|
||||||
|
# A cancelled run was superseded by a newer run for the same commit (the
|
||||||
|
# mirror can push one commit twice); that run reports. Posting "failure"
|
||||||
|
# here would fail the Gitea check while the real build is still going.
|
||||||
|
if [ "$STATE" = cancelled ]; then echo "cancelled: leaving the result to the newer run"; exit 0; fi
|
||||||
|
jq -n --arg s "$STATE" --arg c "$STATUS_CONTEXT" \
|
||||||
|
--arg u "$GITHUB_SERVER_URL/$GITHUB_REPOSITORY/actions/runs/$GITHUB_RUN_ID" \
|
||||||
|
'{state:$s, context:$c, target_url:$u, description:"GitHub Actions"}' |
|
||||||
|
curl -fsS -o /dev/null -X POST -H "Authorization: token $GITEA_TOKEN" \
|
||||||
|
-H 'Content-Type: application/json' --data @- \
|
||||||
|
"$GITEA_URL/api/v1/repos/$GITHUB_REPOSITORY/statuses/$GITHUB_SHA"
|
||||||
|
echo "$STATUS_CONTEXT: $STATE"
|
||||||
@@ -1,69 +0,0 @@
|
|||||||
# Prune old image versions from GHCR.
|
|
||||||
#
|
|
||||||
# Releases are kept forever -- they carry no assets and their generated notes
|
|
||||||
# are this project's only changelog, so deleting one destroys history that
|
|
||||||
# cannot be reconstructed for nothing saved. Images are the opposite: a
|
|
||||||
# multi-arch build a week, and the by-digest push in publish.yml leaves two
|
|
||||||
# untagged per-architecture manifests behind each time on top of the tagged
|
|
||||||
# index. Those accumulate and nobody wants fifty of them.
|
|
||||||
#
|
|
||||||
# THE FOOTGUN: the obvious tool for this -- delete-package-versions with
|
|
||||||
# `delete-only-untagged-versions` -- will happily delete the per-architecture
|
|
||||||
# manifests that a multi-arch tag points *at*, because they are untagged by
|
|
||||||
# design. Nothing appears to break: the tag still exists, and pulls simply
|
|
||||||
# start failing for one architecture. This action understands manifest lists
|
|
||||||
# and will not orphan a retained index, and `validate` re-checks every
|
|
||||||
# multi-arch manifest against the registry afterwards.
|
|
||||||
#
|
|
||||||
# Separate from publish.yml, and dispatchable on its own, so `dry_run` can show
|
|
||||||
# exactly what would be deleted without rebuilding and re-pushing an image to
|
|
||||||
# find out.
|
|
||||||
name: Prune images
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_call:
|
|
||||||
inputs:
|
|
||||||
dry_run:
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
dry_run:
|
|
||||||
description: "List what would be deleted, delete nothing"
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
prune:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
permissions:
|
|
||||||
packages: write
|
|
||||||
steps:
|
|
||||||
# The only third-party action here that is not published by GitHub or
|
|
||||||
# Docker, and the one with the most to lose: it is handed
|
|
||||||
# `packages: write` and its whole job is deletion, so a ref repointed at
|
|
||||||
# something else -- by a compromise or a mistake upstream -- is a bad
|
|
||||||
# day. It was pinned to a commit long before the rest of them were.
|
|
||||||
- uses: dataaxiom/ghcr-cleanup-action@d52806a0dc70b430571a37da1fde39733ffd640f # v1.2.2
|
|
||||||
with:
|
|
||||||
owner: inbuxa
|
|
||||||
package: inbuxa-server
|
|
||||||
token: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
# Ten weekly releases is roughly a quarter of history, which is more
|
|
||||||
# than enough to roll back to and far less than the year's worth that
|
|
||||||
# would otherwise pile up. Older *releases* stay either way; this
|
|
||||||
# only removes the images.
|
|
||||||
keep-n-tagged: 10
|
|
||||||
# Belt and braces on top of the action's own manifest awareness:
|
|
||||||
# `latest` is never a candidate for deletion under any counting.
|
|
||||||
exclude-tags: latest
|
|
||||||
delete-untagged: true
|
|
||||||
# Sweeps the wreckage of a half-failed run: an index whose platform
|
|
||||||
# images did not all land, and referrers whose parent is gone.
|
|
||||||
delete-partial-images: true
|
|
||||||
delete-orphaned-images: true
|
|
||||||
# Checks every remaining multi-architecture manifest still resolves
|
|
||||||
# in the registry. This is the step that would catch the footgun
|
|
||||||
# above rather than leaving a reader to discover it on `docker pull`.
|
|
||||||
validate: true
|
|
||||||
dry-run: ${{ inputs.dry_run }}
|
|
||||||
@@ -1,198 +0,0 @@
|
|||||||
# Publish the container image to GHCR.
|
|
||||||
#
|
|
||||||
# The README and the docs site have told people to run
|
|
||||||
# `ghcr.io/inbuxa/inbuxa-server:latest` for a long time, and nothing ever
|
|
||||||
# pushed it: `docker pull` answered `denied`, because the package did not
|
|
||||||
# exist. This is the workflow that makes those instructions true. It is also
|
|
||||||
# the prerequisite for the self-hosted app catalogs -- TrueNAS and Unraid
|
|
||||||
# both install by pulling an image and neither builds from source.
|
|
||||||
#
|
|
||||||
# FIRST RUN: a package GHCR creates for the first time is **private**, even in
|
|
||||||
# a public repository, and an anonymous `docker pull` will still answer
|
|
||||||
# `denied`. Nothing in a workflow can change that -- the visibility is set once
|
|
||||||
# by hand under the package's settings, and until it is, this looks like it
|
|
||||||
# worked while the docs stay just as wrong as before. Check with a logged-out
|
|
||||||
# pull, not with one from a machine that has credentials.
|
|
||||||
#
|
|
||||||
# Two architectures, each built on its own native runner rather than under
|
|
||||||
# QEMU. Emulated arm64 has to run `npm ci` and the Vite build through
|
|
||||||
# instruction translation, which takes tens of minutes and occasionally runs
|
|
||||||
# out of memory; `ubuntu-24.04-arm` is free for public repositories and does
|
|
||||||
# the same work at native speed. The cost is the by-digest dance below: each
|
|
||||||
# runner pushes an untagged image, and a final job joins the two digests into
|
|
||||||
# one multi-arch tag.
|
|
||||||
name: Publish image
|
|
||||||
|
|
||||||
on:
|
|
||||||
release:
|
|
||||||
types: [published]
|
|
||||||
# Callable, so release.yml can build the release it just cut. This is not a
|
|
||||||
# stylistic choice: a release created with GITHUB_TOKEN does **not** raise a
|
|
||||||
# `release` event -- GitHub refuses to let a token trigger another workflow,
|
|
||||||
# to stop a workflow looping on its own output. A scheduled job that cut a
|
|
||||||
# release and expected this file to notice would silently never publish. The
|
|
||||||
# alternatives are a personal access token kept as a secret, or calling the
|
|
||||||
# workflow directly. This is the one that needs no credential.
|
|
||||||
workflow_call:
|
|
||||||
inputs:
|
|
||||||
ref:
|
|
||||||
description: "Tag, branch or SHA to build"
|
|
||||||
required: true
|
|
||||||
type: string
|
|
||||||
tag_latest:
|
|
||||||
description: "Also move :latest to this build"
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
# Same reasoning as ci.yml's dispatch trigger: a run GitHub queues and then
|
|
||||||
# orphans can be neither rerun nor canceled, and this workflow otherwise
|
|
||||||
# only fires on a release -- which is not something to cut twice because a
|
|
||||||
# runner died. `ref` also allows publishing an image for a tag that predates
|
|
||||||
# this workflow, which is how the first one gets built.
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
ref:
|
|
||||||
description: "Tag, branch or SHA to build"
|
|
||||||
required: true
|
|
||||||
default: main
|
|
||||||
tag_latest:
|
|
||||||
description: "Also move :latest to this build"
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
|
|
||||||
env:
|
|
||||||
# Hardcoded rather than derived from github.repository, which would have to
|
|
||||||
# be lowercased to be a legal registry path. This is the string the docs name.
|
|
||||||
IMAGE: ghcr.io/inbuxa/inbuxa-server
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
# The version is read once and handed to both builds, so the two
|
|
||||||
# architectures cannot disagree about what they are. It is read from the
|
|
||||||
# macro the binary itself compiles in, which the weekly release commits
|
|
||||||
# before this runs -- so the image is tagged with the version it reports.
|
|
||||||
version:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
outputs:
|
|
||||||
version: ${{ steps.v.outputs.version }}
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
||||||
with:
|
|
||||||
ref: ${{ inputs.ref || github.ref }}
|
|
||||||
- id: v
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
# Scoped to the macro body: branding.rs holds other string literals,
|
|
||||||
# and tagging an image from one of those would be worse than failing.
|
|
||||||
V="$(awk '/macro_rules! brand_version/,/^}/' crates/types/src/branding.rs \
|
|
||||||
| grep -om1 '"[0-9][^"]*"' | tr -d '"')"
|
|
||||||
[ -n "$V" ] || { echo "could not read brand_version! from branding.rs" >&2; exit 1; }
|
|
||||||
# A date version carries nothing a Docker tag objects to, so there is
|
|
||||||
# no second, sanitized form of it here.
|
|
||||||
echo "version=$V" >> "$GITHUB_OUTPUT"
|
|
||||||
echo "version $V"
|
|
||||||
|
|
||||||
build:
|
|
||||||
needs: version
|
|
||||||
runs-on: ${{ matrix.runner }}
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
packages: write
|
|
||||||
strategy:
|
|
||||||
fail-fast: false
|
|
||||||
matrix:
|
|
||||||
include:
|
|
||||||
- platform: linux/amd64
|
|
||||||
runner: ubuntu-latest
|
|
||||||
- platform: linux/arm64
|
|
||||||
runner: ubuntu-24.04-arm
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
||||||
with:
|
|
||||||
ref: ${{ inputs.ref || github.ref }}
|
|
||||||
- uses: docker/setup-buildx-action@594f3bf4285d9ea8dc53c9a0c9c4092420091003 # v4.4.0
|
|
||||||
- uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
|
||||||
with:
|
|
||||||
registry: ghcr.io
|
|
||||||
username: ${{ github.actor }}
|
|
||||||
password: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
- name: Build and push by digest
|
|
||||||
id: push
|
|
||||||
uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0
|
|
||||||
with:
|
|
||||||
context: .
|
|
||||||
platforms: ${{ matrix.platform }}
|
|
||||||
# Attestations are off deliberately: they add manifests of their own
|
|
||||||
# to the index, and `imagetools create` below expects the two entries
|
|
||||||
# it pushed rather than four.
|
|
||||||
provenance: false
|
|
||||||
sbom: false
|
|
||||||
cache-from: type=gha,scope=${{ matrix.platform }}
|
|
||||||
cache-to: type=gha,mode=max,scope=${{ matrix.platform }}
|
|
||||||
outputs: type=image,name=${{ env.IMAGE }},push-by-digest=true,name-canonical=true,push=true
|
|
||||||
- name: Save the digest
|
|
||||||
run: |
|
|
||||||
mkdir -p /tmp/digests
|
|
||||||
# The prefix is stripped here and put back in the merge job, so the
|
|
||||||
# filename is the bare hash. Leaving it on produces
|
|
||||||
# `image@sha256:sha256:...` when the reference is rebuilt.
|
|
||||||
digest="${{ steps.push.outputs.digest }}"
|
|
||||||
touch "/tmp/digests/${digest#sha256:}"
|
|
||||||
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
||||||
with:
|
|
||||||
# One artifact per platform; the merge job globs them back together.
|
|
||||||
name: digest-${{ strategy.job-index }}
|
|
||||||
path: /tmp/digests/*
|
|
||||||
retention-days: 1
|
|
||||||
if-no-files-found: error
|
|
||||||
|
|
||||||
# Joins the per-architecture digests into a single tagged manifest, so
|
|
||||||
# `docker pull ghcr.io/inbuxa/inbuxa-server:<tag>` resolves on both.
|
|
||||||
publish:
|
|
||||||
needs: [version, build]
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
packages: write
|
|
||||||
steps:
|
|
||||||
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
||||||
with:
|
|
||||||
path: /tmp/digests
|
|
||||||
pattern: digest-*
|
|
||||||
merge-multiple: true
|
|
||||||
- uses: docker/setup-buildx-action@594f3bf4285d9ea8dc53c9a0c9c4092420091003 # v4.4.0
|
|
||||||
- uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
|
||||||
with:
|
|
||||||
registry: ghcr.io
|
|
||||||
username: ${{ github.actor }}
|
|
||||||
password: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
- name: Create the manifest
|
|
||||||
run: |
|
|
||||||
# Arrays rather than a string: the tags and the digest references
|
|
||||||
# have to reach docker as separate arguments, and building them by
|
|
||||||
# word-splitting an unquoted variable is the version of this that
|
|
||||||
# breaks the day a value contains a space.
|
|
||||||
tags=(-t "${IMAGE}:${{ needs.version.outputs.version }}")
|
|
||||||
# :latest follows real releases only. A prerelease that moved it
|
|
||||||
# would hand every `:latest` deployment an unfinished build, and a
|
|
||||||
# dispatch run has to ask for it on purpose.
|
|
||||||
if [ "${{ github.event_name }}" = "release" ] && [ "${{ github.event.release.prerelease }}" = "false" ]; then
|
|
||||||
tags+=(-t "${IMAGE}:latest")
|
|
||||||
elif [ "${{ inputs.tag_latest }}" = "true" ]; then
|
|
||||||
tags+=(-t "${IMAGE}:latest")
|
|
||||||
fi
|
|
||||||
refs=()
|
|
||||||
for f in /tmp/digests/*; do
|
|
||||||
refs+=("${IMAGE}@sha256:$(basename "$f")")
|
|
||||||
done
|
|
||||||
echo "tags: ${tags[*]}"
|
|
||||||
echo "refs: ${refs[*]}"
|
|
||||||
docker buildx imagetools create "${tags[@]}" "${refs[@]}"
|
|
||||||
- name: Show what landed
|
|
||||||
run: docker buildx imagetools inspect "${IMAGE}:${{ needs.version.outputs.version }}"
|
|
||||||
|
|
||||||
# Runs only after a successful publish, because that is the only moment the
|
|
||||||
# package grows. See cleanup.yml for why this is not the obvious one-liner.
|
|
||||||
prune:
|
|
||||||
needs: publish
|
|
||||||
permissions:
|
|
||||||
packages: write
|
|
||||||
uses: ./.github/workflows/cleanup.yml
|
|
||||||
@@ -1,246 +0,0 @@
|
|||||||
# Cut a release once a week, but only if there is something in it.
|
|
||||||
#
|
|
||||||
# It does nothing on a quiet week. A release with no commits in it is worse
|
|
||||||
# than no release: it moves `:latest` to an identical build, spends a version
|
|
||||||
# number, and mails everybody watching the repository about nothing.
|
|
||||||
#
|
|
||||||
# INBUXA's version is a string in crates/types/src/branding.rs, deliberately
|
|
||||||
# not in Cargo.toml so that upstream's version bumps merge without conflicts.
|
|
||||||
# So this writes it: the bump is committed to main, and the tag names that
|
|
||||||
# commit. The tree a tag points at therefore reports the version the tag
|
|
||||||
# claims, which a tag placed beside an unbumped macro cannot promise.
|
|
||||||
name: Weekly release
|
|
||||||
|
|
||||||
on:
|
|
||||||
schedule:
|
|
||||||
# Mondays, 10:07 UTC, and last of the three: INBUXA Admin and the webmail
|
|
||||||
# release ahead of the server they talk to. Staggered rather than
|
|
||||||
# simultaneous so three releases do not compete for runners, and so a bad
|
|
||||||
# Monday names one repository instead of three. GitHub runs scheduled jobs
|
|
||||||
# best-effort and can delay a run considerably, so the exact minute is not
|
|
||||||
# a promise; the odd minute keeps it off the crowded top of the hour.
|
|
||||||
#
|
|
||||||
# Note also that GitHub disables scheduled workflows in a repository with
|
|
||||||
# no activity for 60 days, which is worth checking for before assuming
|
|
||||||
# this file is broken.
|
|
||||||
- cron: "7 10 * * 1"
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
dry_run:
|
|
||||||
description: "Work out what would be released, then stop"
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
|
|
||||||
# One at a time. Two overlapping runs would race to write the same version and
|
|
||||||
# create the same tag, and the loser fails noisily for a reason that has
|
|
||||||
# nothing to do with the code.
|
|
||||||
concurrency:
|
|
||||||
group: weekly-release
|
|
||||||
cancel-in-progress: false
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
check:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
outputs:
|
|
||||||
should_release: ${{ steps.decide.outputs.should_release }}
|
|
||||||
version: ${{ steps.decide.outputs.version }}
|
|
||||||
tag: ${{ steps.decide.outputs.tag }}
|
|
||||||
previous: ${{ steps.decide.outputs.previous }}
|
|
||||||
count: ${{ steps.decide.outputs.count }}
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
||||||
with:
|
|
||||||
ref: main
|
|
||||||
fetch-depth: 0
|
|
||||||
- id: decide
|
|
||||||
env:
|
|
||||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
# The newest published release, or empty on a repository that has
|
|
||||||
# never had one -- in which case everything counts as new. Drafts are
|
|
||||||
# excluded: an unpublished draft is not a release anybody has, so
|
|
||||||
# counting from it would hide commits that have never shipped.
|
|
||||||
previous="$(gh release list --limit 1 --exclude-drafts --json tagName --jq '.[0].tagName // ""')"
|
|
||||||
# A tag named by a release is normally present after a full checkout,
|
|
||||||
# but a release can outlive its tag. Falling back to the whole
|
|
||||||
# history is the safe direction to be wrong in: it over-counts, which
|
|
||||||
# cuts a release that was due anyway, where under-counting would skip
|
|
||||||
# one that was.
|
|
||||||
if [ -n "$previous" ] && git rev-parse -q --verify "refs/tags/${previous}" >/dev/null; then
|
|
||||||
count="$(git rev-list --count "${previous}..HEAD")"
|
|
||||||
else
|
|
||||||
count="$(git rev-list --count HEAD)"
|
|
||||||
fi
|
|
||||||
|
|
||||||
# INBUXA's version is the date: YYYY.M.D, unpadded, as branding.rs
|
|
||||||
# documents. A second release on one day takes a `.N` suffix,
|
|
||||||
# counting from 2, which is why this asks the tags rather than
|
|
||||||
# assuming today is free.
|
|
||||||
today="$(date -u +%Y.%-m.%-d)"
|
|
||||||
version="$today"
|
|
||||||
n=2
|
|
||||||
while git rev-parse -q --verify "refs/tags/v${version}" >/dev/null; do
|
|
||||||
version="${today}.${n}"
|
|
||||||
n=$((n + 1))
|
|
||||||
done
|
|
||||||
|
|
||||||
should_release=true
|
|
||||||
reason=""
|
|
||||||
if [ "$count" -eq 0 ]; then
|
|
||||||
should_release=false
|
|
||||||
reason="no commits since ${previous}"
|
|
||||||
fi
|
|
||||||
|
|
||||||
{
|
|
||||||
echo "should_release=$should_release"
|
|
||||||
echo "version=$version"
|
|
||||||
echo "tag=v${version}"
|
|
||||||
echo "previous=$previous"
|
|
||||||
echo "count=$count"
|
|
||||||
} >> "$GITHUB_OUTPUT"
|
|
||||||
|
|
||||||
# Written to the run summary so a skipped week reads as a decision
|
|
||||||
# rather than as a workflow that quietly did nothing.
|
|
||||||
{
|
|
||||||
echo "### Weekly release"
|
|
||||||
echo
|
|
||||||
if [ "$should_release" = "true" ]; then
|
|
||||||
echo "Releasing **v${version}** — ${count} commit(s) since ${previous:-the beginning}."
|
|
||||||
else
|
|
||||||
echo "Nothing to release: ${reason}."
|
|
||||||
fi
|
|
||||||
} >> "$GITHUB_STEP_SUMMARY"
|
|
||||||
|
|
||||||
cut:
|
|
||||||
needs: check
|
|
||||||
if: needs.check.outputs.should_release == 'true' && !inputs.dry_run
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
pull-requests: write
|
|
||||||
outputs:
|
|
||||||
sha: ${{ steps.land.outputs.sha }}
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
||||||
with:
|
|
||||||
ref: main
|
|
||||||
fetch-depth: 0
|
|
||||||
- id: bump
|
|
||||||
env:
|
|
||||||
VERSION: ${{ needs.check.outputs.version }}
|
|
||||||
BRANCH: release/v${{ needs.check.outputs.version }}
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
# Scoped to the macro body rather than replacing the first quoted
|
|
||||||
# string in the file, and asserted to have matched exactly once.
|
|
||||||
# branding.rs holds other string literals, and a bump that silently
|
|
||||||
# edited one of those -- or none -- would ship a build whose version
|
|
||||||
# disagrees with its tag.
|
|
||||||
python3 - <<'PY'
|
|
||||||
import os, re
|
|
||||||
path = "crates/types/src/branding.rs"
|
|
||||||
src = open(path, encoding="utf-8").read()
|
|
||||||
pattern = re.compile(r'(macro_rules! brand_version \{\s*\(\) => \{\s*")[^"]+(")')
|
|
||||||
out, n = pattern.subn(lambda m: m.group(1) + os.environ["VERSION"] + m.group(2), src, count=1)
|
|
||||||
assert n == 1, f"brand_version! not found in {path}"
|
|
||||||
open(path, "w", encoding="utf-8").write(out)
|
|
||||||
PY
|
|
||||||
|
|
||||||
git config user.name "github-actions[bot]"
|
|
||||||
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
|
|
||||||
git add crates/types/src/branding.rs
|
|
||||||
git commit -m "Version ${VERSION}"
|
|
||||||
git push origin "HEAD:refs/heads/${BRANCH}"
|
|
||||||
|
|
||||||
# main is protected: it takes a pull request with a green build, and
|
|
||||||
# GITHUB_TOKEN is not among the bypass actors. So the bump lands the way
|
|
||||||
# every other change does. The alternative was to hand the release a
|
|
||||||
# credential that outranks the rule, which is a worse thing to own than
|
|
||||||
# a slower Monday.
|
|
||||||
- id: land
|
|
||||||
env:
|
|
||||||
VERSION: ${{ needs.check.outputs.version }}
|
|
||||||
BRANCH: release/v${{ needs.check.outputs.version }}
|
|
||||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
url="$(gh pr create --base main --head "${BRANCH}" \
|
|
||||||
--title "Version ${VERSION}" \
|
|
||||||
--body "Weekly release. Bumps \`brand_version!\` to ${VERSION} so the tag names a tree that reports the version the tag claims.")"
|
|
||||||
# The number, not the branch: the branch is deleted on merge, and a
|
|
||||||
# deleted branch no longer resolves to its pull request.
|
|
||||||
pr="${url##*/}"
|
|
||||||
echo "Opened #${pr}"
|
|
||||||
|
|
||||||
# The build is what the rule actually requires, and it is also the
|
|
||||||
# thing worth waiting for: a release cut from a tree that does not
|
|
||||||
# compile is the failure this whole arrangement exists to prevent.
|
|
||||||
# A full build of this tree is long, so the deadline is generous.
|
|
||||||
deadline=$(( SECONDS + 3600 ))
|
|
||||||
while :; do
|
|
||||||
state="$(gh pr view "${pr}" --json statusCheckRollup \
|
|
||||||
--jq '[.statusCheckRollup[]? | .conclusion // "PENDING"] | join(",")')"
|
|
||||||
case "${state}" in
|
|
||||||
*FAILURE*|*CANCELLED*|*TIMED_OUT*)
|
|
||||||
echo "::error::CI failed on ${BRANCH} (${state}); no release cut. PR #${pr} is left open."
|
|
||||||
exit 1 ;;
|
|
||||||
*SUCCESS*) break ;;
|
|
||||||
esac
|
|
||||||
if [ "${SECONDS}" -ge "${deadline}" ]; then
|
|
||||||
echo "::error::timed out waiting for CI on ${BRANCH}. PR #${pr} is left open."
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
sleep 30
|
|
||||||
done
|
|
||||||
|
|
||||||
gh pr merge "${pr}" --rebase --delete-branch
|
|
||||||
|
|
||||||
# A rebase merge rewrites the commit, so the sha to tag is the one
|
|
||||||
# GitHub recorded for the merge, not the tip that was pushed. It can
|
|
||||||
# take a moment to appear.
|
|
||||||
sha=""
|
|
||||||
for _ in $(seq 1 30); do
|
|
||||||
sha="$(gh pr view "${pr}" --json mergeCommit --jq '.mergeCommit.oid // ""')"
|
|
||||||
[ -n "${sha}" ] && break
|
|
||||||
sleep 5
|
|
||||||
done
|
|
||||||
if [ -z "${sha}" ]; then
|
|
||||||
echo "::error::#${pr} merged but GitHub reported no merge commit; nothing safe to tag."
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo "sha=${sha}" >> "$GITHUB_OUTPUT"
|
|
||||||
- env:
|
|
||||||
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
args=(--target "${{ steps.land.outputs.sha }}"
|
|
||||||
--title "INBUXA ${{ needs.check.outputs.version }}"
|
|
||||||
--generate-notes)
|
|
||||||
# Bound the notes to what is actually new. Without a start tag the
|
|
||||||
# generator reaches back to whatever it decides is previous, which on
|
|
||||||
# a repository carrying upstream's tag shapes is not always the last
|
|
||||||
# release.
|
|
||||||
if [ -n "${{ needs.check.outputs.previous }}" ]; then
|
|
||||||
args+=(--notes-start-tag "${{ needs.check.outputs.previous }}")
|
|
||||||
fi
|
|
||||||
gh release create "${{ needs.check.outputs.tag }}" "${args[@]}"
|
|
||||||
|
|
||||||
# Called rather than left to the `release` trigger on purpose: see the note
|
|
||||||
# at the top of publish.yml. A release created with GITHUB_TOKEN raises no
|
|
||||||
# event, so without this the tag would exist and no image would follow it.
|
|
||||||
publish:
|
|
||||||
needs: [check, cut]
|
|
||||||
permissions:
|
|
||||||
contents: read
|
|
||||||
packages: write
|
|
||||||
uses: ./.github/workflows/publish.yml
|
|
||||||
with:
|
|
||||||
ref: ${{ needs.cut.outputs.sha }}
|
|
||||||
tag_latest: true
|
|
||||||
@@ -2,6 +2,66 @@
|
|||||||
|
|
||||||
All notable changes to this project will be documented in this file. This project adheres to [Semantic Versioning](http://semver.org/).
|
All notable changes to this project will be documented in this file. This project adheres to [Semantic Versioning](http://semver.org/).
|
||||||
|
|
||||||
|
## [0.16.25] - 2026-10-05
|
||||||
|
|
||||||
|
If you are upgrading from v0.16.x, replace the binary (or run `docker pull`). If you are upgrading from v0.15.x and below, please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md) for more information on how to upgrade from previous versions.
|
||||||
|
|
||||||
|
## Added
|
||||||
|
|
||||||
|
## Changed
|
||||||
|
|
||||||
|
## Fixed
|
||||||
|
- JMAP: Creating a `MaskedEmail` with `emailDomain` fails with `forbidden` for every domain when the account has addresses on more than one domain.
|
||||||
|
- Autodiscover: Requests for a response schema other than Outlook's, such as ActiveSync (`mobilesync`), are answered with the Outlook settings instead of error 601.
|
||||||
|
- IMAP:
|
||||||
|
- `LOGIN` and `AUTHENTICATE` with a wrong, expired or unknown app password or API key are answered with an untagged `NO`, so clients keep waiting for the command to complete until the connection times out.
|
||||||
|
- The failed login that exceeds the maximum number of authentication failures is answered with an untagged `NO` before the connection is closed.
|
||||||
|
- DKIM:
|
||||||
|
- A rotation moves the active key to retiring even when its successor fails to publish or propagate, so outgoing mail is sent unsigned until a retry publishes the new key. The DNS write failure is also not logged and the task reports success.
|
||||||
|
- Keys created while DNS management was manual, or before DKIM was added to the published records, are never rotated after DNS management becomes automatic. Domains already affected start rotating once a `DkimManagement` task is created for them.
|
||||||
|
- After switching DNS management from automatic to manual, a due rotation activates a new key that was never published in DNS, so signatures fail verification, and retiring the old key is retried forever.
|
||||||
|
- Spam filter:
|
||||||
|
- Messages with no text line long enough for a Pyzor digest are checked with the digest of empty input and tagged `PYZOR`.
|
||||||
|
- DNSBL answers with several return codes, such as a Spamhaus ZEN listing in both SBL and PBL, are scored for only the first code returned.
|
||||||
|
- DNSBL lookups that return "not listed" are cached for 24 hours regardless of the zone's negative TTL.
|
||||||
|
- Removing a duplicate training sample of a message reclassified on the same day clears the blob link of the sample that is kept.
|
||||||
|
- MTA: Queue quotas with an empty `match` expression are never enforced, including the global queue quota created on first start.
|
||||||
|
- RocksDB: The info log (`LOG`, `LOG.old.*`) grows without limit because log rotation and retention are left at RocksDB defaults.
|
||||||
|
- WebUI: A blob store read error at startup, such as an S3 authentication failure, stops the web interface from being downloaded.
|
||||||
|
|
||||||
|
## [0.16.24] - 2026-09-27
|
||||||
|
|
||||||
|
If you are upgrading from v0.16.x, replace the binary (or run `docker pull`). If you are upgrading from v0.15.x and below, please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md) for more information on how to upgrade from previous versions.
|
||||||
|
|
||||||
|
## Added
|
||||||
|
- DNS: PowerDNS Authoritative provider for automatic DNS record management.
|
||||||
|
|
||||||
|
## Changed
|
||||||
|
|
||||||
|
## Fixed
|
||||||
|
- Troubleshoot tool: `TLSA` records are looked up for every MX host, including hosts whose zone is not DNSSEC signed.
|
||||||
|
- Spam filter:
|
||||||
|
- OpenPhish and PhishTank entries containing uppercase characters never match, since message URLs are lowercased while HTTP lookup entries keep their original case. HTTP lookups now match keys case-insensitively.
|
||||||
|
- URL shortener links are followed using the lowercased URL, so case-sensitive short links resolve to the wrong destination or not at all.
|
||||||
|
- Incremental training never advances its position past the first run, so every retained sample added since then is trained again, and counted again in the reservoir, on each run until it expires.
|
||||||
|
- Updating the rules only adds new objects, so upstream changes to existing rules, DNSBL servers, HTTP lookups, lookup keys and file extensions never reach an existing installation.
|
||||||
|
- Updating the rules reports success when objects fail to import, or when a configuration error stops the updated settings from being activated.
|
||||||
|
- JMAP:
|
||||||
|
- A `PushSubscription` created within the verification rate limit window of another one on the same account never receives its `PushVerification`, since the blocked verification is dropped instead of being sent once the window expires.
|
||||||
|
- A push notification retried after a failed delivery can report an older state than a change queued during the failed attempt, since the older state changes are merged last and overwrite the newer ones.
|
||||||
|
- Changes made while a push request is in flight are not delivered until the next change reaches the same subscription, since a successful delivery cancels the pending retry.
|
||||||
|
- The VAPID `aud` claim is derived from a hand-written parse of the push URL, so a crafted push URL can make the server sign a token for a push service other than the one the request is sent to.
|
||||||
|
- `Email/import` rejects a `blobId` that refers to a `Blob/upload` creation id in the same request (`"#u0"`) with `Invalid blob id.`.
|
||||||
|
- `Email/set` with a full `mailboxIds` object identical to the current mailboxes, together with a keyword change, stores the message with IMAP UID 0, so IMAP clients stop seeing it.
|
||||||
|
- MTA:
|
||||||
|
- A node without the `outboundMta` role stops replying to `DATA` and to JMAP submissions once about 1024 messages have been queued on it.
|
||||||
|
- MX records are resolved through the DNSSEC-validating resolver even when DANE is disabled.
|
||||||
|
- A `DATA` stage Sieve script does not see headers added by milters or MTA hooks, and discards every milter and MTA hook change when it edits the message.
|
||||||
|
- MySQL: Range deletions and search index removals start with a single unbounded `DELETE` and switch to chunks only after a timeout.
|
||||||
|
- IMAP: `COPY` and `MOVE` fail with `NO [CONTACTADMIN]` when another session changes the same message at the same time.
|
||||||
|
- Autodiscover: Implicit TLS ports (993, 995, 465) are advertised with `<Encryption>TLS</Encryption>`, which Outlook reads as STARTTLS.
|
||||||
|
- HTTP: Idle keep-alive connections are never closed.
|
||||||
|
|
||||||
## [0.16.23] - 2026-09-21
|
## [0.16.23] - 2026-09-21
|
||||||
|
|
||||||
If you are upgrading from v0.16.x, replace the binary (or run `docker pull`). If you are upgrading from v0.15.x and below, please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md) for more information on how to upgrade from previous versions.
|
If you are upgrading from v0.16.x, replace the binary (or run `docker pull`). If you are upgrading from v0.15.x and below, please read the [upgrading documentation](https://github.com/stalwartlabs/stalwart/blob/main/UPGRADING/v0_16.md) for more information on how to upgrade from previous versions.
|
||||||
|
|||||||
+1
-1
@@ -60,7 +60,7 @@ representative at an online or offline event.
|
|||||||
|
|
||||||
Instances of abusive, harassing, or otherwise unacceptable behavior may be
|
Instances of abusive, harassing, or otherwise unacceptable behavior may be
|
||||||
reported to the community leaders responsible for enforcement at
|
reported to the community leaders responsible for enforcement at
|
||||||
**johnellisATlinuxDOTcom**.
|
**communityATcoffeylabsDOTorg**.
|
||||||
All complaints will be reviewed and investigated promptly and fairly.
|
All complaints will be reviewed and investigated promptly and fairly.
|
||||||
|
|
||||||
All community leaders are obligated to respect the privacy and security of the
|
All community leaders are obligated to respect the privacy and security of the
|
||||||
|
|||||||
+1
-1
@@ -54,7 +54,7 @@ Coffey Labs" line in place. New files carry:
|
|||||||
|
|
||||||
```
|
```
|
||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
Generated
+233
-215
File diff suppressed because it is too large.
Load diff
+1
-1
@@ -4,7 +4,7 @@
|
|||||||
# *****************
|
# *****************
|
||||||
# Base image for planner & builder
|
# Base image for planner & builder
|
||||||
# *****************
|
# *****************
|
||||||
FROM --platform=$BUILDPLATFORM rust:slim-trixie AS base
|
FROM --platform=$BUILDPLATFORM rust:1.98.1-slim-trixie AS base
|
||||||
|
|
||||||
ENV DEBIAN_FRONTEND="noninteractive" \
|
ENV DEBIAN_FRONTEND="noninteractive" \
|
||||||
BINSTALL_DISABLE_TELEMETRY=true \
|
BINSTALL_DISABLE_TELEMETRY=true \
|
||||||
|
|||||||
@@ -8,6 +8,10 @@
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
> [!NOTE]
|
||||||
|
> Development happens on [git.coffeylabs.org/inbuxa/inbuxa-server](https://git.coffeylabs.org/inbuxa/inbuxa-server); the copy on GitHub is a read-only mirror.
|
||||||
|
> Report issues at **[git.coffeylabs.org/inbuxa/inbuxa-server/issues](https://git.coffeylabs.org/inbuxa/inbuxa-server/issues)**, and join discussions at **[community.coffeylabs.org](https://community.coffeylabs.org)**.
|
||||||
|
|
||||||
**inbuxa** is a mail and collaboration server: JMAP, IMAP, POP3, SMTP,
|
**inbuxa** is a mail and collaboration server: JMAP, IMAP, POP3, SMTP,
|
||||||
CalDAV, CardDAV and WebDAV, in one Rust binary, with ihasmail as its web front
|
CalDAV, CardDAV and WebDAV, in one Rust binary, with ihasmail as its web front
|
||||||
end. It is a fork of [Stalwart](https://github.com/stalwartlabs/stalwart).
|
end. It is a fork of [Stalwart](https://github.com/stalwartlabs/stalwart).
|
||||||
|
|||||||
+2
-2
@@ -17,7 +17,7 @@ visible to everyone, including whoever would use it, before there is a fix.
|
|||||||
|
|
||||||
Report it privately by email to:
|
Report it privately by email to:
|
||||||
|
|
||||||
**johnellisATlinuxDOTcom**
|
**securityATcoffeylabsDOTorg**
|
||||||
|
|
||||||
Include as much as you can of:
|
Include as much as you can of:
|
||||||
|
|
||||||
@@ -36,7 +36,7 @@ to Stalwart Labs with credit to you, and you'll be told that has happened.
|
|||||||
This repository is the mail server. The web front ends have their own:
|
This repository is the mail server. The web front ends have their own:
|
||||||
|
|
||||||
- [inbuxa-admin](https://git.coffeylabs.org/inbuxa/inbuxa-admin)
|
- [inbuxa-admin](https://git.coffeylabs.org/inbuxa/inbuxa-admin)
|
||||||
- [ihasmail-inbuxa](https://git.coffeylabs.org/inbuxa/ihasmail-inbuxa)
|
- [inbuxa-webmail](https://git.coffeylabs.org/inbuxa/inbuxa-webmail)
|
||||||
|
|
||||||
Upstream's own security documents are kept in `.github-upstream/` for
|
Upstream's own security documents are kept in `.github-upstream/` for
|
||||||
reference. They describe Stalwart Labs' process, not this project's.
|
reference. They describe Stalwart Labs' process, not this project's.
|
||||||
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "common"
|
name = "common"
|
||||||
version = "0.16.23"
|
version = "0.16.25"
|
||||||
edition = "2024"
|
edition = "2024"
|
||||||
build = "build.rs"
|
build = "build.rs"
|
||||||
|
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
@@ -14,6 +14,7 @@ use crate::{
|
|||||||
auth::{AccessToken, AuthRequest, permissions::DefaultPermissions},
|
auth::{AccessToken, AuthRequest, permissions::DefaultPermissions},
|
||||||
};
|
};
|
||||||
use directory::Credentials;
|
use directory::Credentials;
|
||||||
|
use inbuxa_features::hold::{self, Member};
|
||||||
use inbuxa_features::audit::{
|
use inbuxa_features::audit::{
|
||||||
Action, Actor, AuditLog, EntryId, Outcome, Record, Target, Via, diff, log, scope,
|
Action, Actor, AuditLog, EntryId, Outcome, Record, Target, Via, diff, log, scope,
|
||||||
};
|
};
|
||||||
@@ -444,11 +445,77 @@ impl Server {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// MA-D0a: a message sent from an address that isn't the sender's own:
|
||||||
|
/// a group's or a shared mailbox's. The message itself only says
|
||||||
|
/// `From:` that address, so the audit log is where the person who sent
|
||||||
|
/// it is named. A locked account's delegate's send is AL-9's record, not
|
||||||
|
/// this one.
|
||||||
|
pub async fn audit_send_as(
|
||||||
|
&self,
|
||||||
|
token: &AccessToken,
|
||||||
|
submission_account_id: u32,
|
||||||
|
submission_id: u32,
|
||||||
|
address: &str,
|
||||||
|
) {
|
||||||
|
let Ok(Some(as_account_id)) = self.account_id_from_email(address, true).await else {
|
||||||
|
return;
|
||||||
|
};
|
||||||
|
if as_account_id == token.account_id()
|
||||||
|
|| token
|
||||||
|
.delegation(as_account_id)
|
||||||
|
.is_some_and(|delegation| delegation.kind.is_lock())
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
let actor = self.audit_actor(token).await;
|
||||||
|
let tenant_id = self
|
||||||
|
.account(as_account_id)
|
||||||
|
.await
|
||||||
|
.ok()
|
||||||
|
.and_then(|account| account.id_tenant);
|
||||||
|
let details = if submission_account_id == as_account_id {
|
||||||
|
format!("Sent as {address}")
|
||||||
|
} else {
|
||||||
|
format!(
|
||||||
|
"Sent as {address}, from {}",
|
||||||
|
self.audit_account_name(submission_account_id).await
|
||||||
|
)
|
||||||
|
};
|
||||||
|
self.audit_note(Record {
|
||||||
|
at: ms(),
|
||||||
|
actor,
|
||||||
|
via: token.origin().cloned(),
|
||||||
|
remote_ip: None,
|
||||||
|
action: Action::Create,
|
||||||
|
target: Target {
|
||||||
|
kind: "EmailSubmission".into(),
|
||||||
|
id: Some(Id::from(submission_id).to_string()),
|
||||||
|
name: Some(address.to_string()),
|
||||||
|
account_id: Some(as_account_id),
|
||||||
|
tenant_id,
|
||||||
|
},
|
||||||
|
changes: vec![],
|
||||||
|
details: Some(details),
|
||||||
|
reason: None,
|
||||||
|
outcome: Outcome::success(),
|
||||||
|
})
|
||||||
|
.await;
|
||||||
|
}
|
||||||
|
|
||||||
/// AU-7: removes entries past the retention period.
|
/// AU-7: removes entries past the retention period.
|
||||||
pub async fn audit_purge(&self) -> trc::Result<usize> {
|
pub async fn audit_purge(&self) -> trc::Result<usize> {
|
||||||
let settings = log::settings(self.store()).await?;
|
let settings = log::settings(self.store()).await?;
|
||||||
let cutoff = ms().saturating_sub(settings.keep_for_secs.saturating_mul(1000));
|
let cutoff = ms().saturating_sub(settings.keep_for_secs.saturating_mul(1000));
|
||||||
log::purge(self.store(), cutoff, |_| false).await
|
// LH-6, AU-7: a record about a held account stays while it's held.
|
||||||
|
// Worked out before the purge, which can't wait on lookups.
|
||||||
|
let held = self.held_accounts().await?;
|
||||||
|
log::purge(self.store(), cutoff, |record| {
|
||||||
|
record
|
||||||
|
.target
|
||||||
|
.account_id
|
||||||
|
.is_some_and(|account_id| held.contains(&account_id))
|
||||||
|
})
|
||||||
|
.await
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -495,6 +562,20 @@ impl RegistryWriteHook for SystemWrites {
|
|||||||
change: RegistryChange<'a>,
|
change: RegistryChange<'a>,
|
||||||
) -> Pin<Box<dyn Future<Output = ()> + Send + 'a>> {
|
) -> Pin<Box<dyn Future<Output = ()> + Send + 'a>> {
|
||||||
Box::pin(async move {
|
Box::pin(async move {
|
||||||
|
// LH-2: every change to an account, whoever makes it: one that
|
||||||
|
// leaves a held domain, group or tenant stays held by name
|
||||||
|
if change.object_type == ObjectType::Account
|
||||||
|
&& let (Some(before), Some(after)) = (change.before, change.after)
|
||||||
|
&& let (Some(before), Some(after)) = (
|
||||||
|
Member::of(change.id.document_id(), &before.inner),
|
||||||
|
Member::of(change.id.document_id(), &after.inner),
|
||||||
|
)
|
||||||
|
&& let Err(err) = hold::keep_moved(&self.data, &before, &after).await
|
||||||
|
{
|
||||||
|
trc::error!(err
|
||||||
|
.account_id(after.account)
|
||||||
|
.details("Failed to keep a moved account under its legal hold"));
|
||||||
|
}
|
||||||
let subsystem = match scope::current() {
|
let subsystem = match scope::current() {
|
||||||
Some(scope::Scope::Request | scope::Scope::Quiet) => return,
|
Some(scope::Scope::Request | scope::Scope::Quiet) => return,
|
||||||
Some(scope::Scope::System(subsystem)) => subsystem,
|
Some(scope::Scope::System(subsystem)) => subsystem,
|
||||||
|
|||||||
@@ -36,6 +36,32 @@ use utils::map::bitmap::{Bitmap, BitmapItem};
|
|||||||
use xxhash_rust::xxh3;
|
use xxhash_rust::xxh3;
|
||||||
|
|
||||||
impl Server {
|
impl Server {
|
||||||
|
/// inbuxa: MA-C: whether people in `owner`'s tenant may share their mail
|
||||||
|
/// (the server's switch, narrowed by the tenant's).
|
||||||
|
pub async fn mail_sharing_allowed(&self, owner: u32) -> trc::Result<bool> {
|
||||||
|
let tenant_id = self.account(owner).await.ok().and_then(|account| account.id_tenant);
|
||||||
|
Ok(
|
||||||
|
inbuxa_features::security::sharing_policy::effective_for(self.store(), tenant_id)
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
.mail_sharing,
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// inbuxa: MA-C: whether `owner`'s mail shares give access now. A locked
|
||||||
|
/// account's or shared mailbox's grants are an administrator's and always
|
||||||
|
/// do; anyone else's only while their tenant allows mail sharing.
|
||||||
|
pub async fn mail_shares_honored(&self, owner: u32) -> trc::Result<bool> {
|
||||||
|
if inbuxa_features::lock::get(self.store(), owner)
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
.is_some()
|
||||||
|
{
|
||||||
|
return Ok(true);
|
||||||
|
}
|
||||||
|
self.mail_sharing_allowed(owner).await
|
||||||
|
}
|
||||||
|
|
||||||
async fn build_access_token(
|
async fn build_access_token(
|
||||||
&self,
|
&self,
|
||||||
account: Account,
|
account: Account,
|
||||||
@@ -46,19 +72,22 @@ impl Server {
|
|||||||
// inbuxa: AL-2, AL-5: whether this account is locked, and which
|
// inbuxa: AL-2, AL-5: whether this account is locked, and which
|
||||||
// locked accounts are handed to it. The token is their cache: every
|
// locked accounts are handed to it. The token is their cache: every
|
||||||
// change to a lock invalidates the tokens it touches.
|
// change to a lock invalidates the tokens it touches.
|
||||||
let locked = inbuxa_features::lock::get(self.store(), account_id)
|
let lock_kind = inbuxa_features::lock::get(self.store(), account_id)
|
||||||
.await
|
.await
|
||||||
.caused_by(trc::location!())?
|
.caused_by(trc::location!())?
|
||||||
.is_some();
|
.map(|lock| lock.kind);
|
||||||
|
let locked = lock_kind.is_some();
|
||||||
|
let shared_mailbox = lock_kind == Some(inbuxa_features::lock::Kind::SharedMailbox);
|
||||||
let now_secs = now();
|
let now_secs = now();
|
||||||
let delegations: Box<[super::Delegation]> =
|
let delegations: Box<[super::Delegation]> =
|
||||||
inbuxa_features::lock::delegated_to(self.store(), account_id)
|
inbuxa_features::lock::delegated_to(self.store(), account_id)
|
||||||
.await
|
.await
|
||||||
.caused_by(trc::location!())?
|
.caused_by(trc::location!())?
|
||||||
.into_iter()
|
.into_iter()
|
||||||
.filter(|(_, delegate)| delegate.is_current(now_secs))
|
.filter(|(_, delegate, _)| delegate.is_current(now_secs))
|
||||||
.map(|(locked_id, delegate)| super::Delegation {
|
.map(|(locked_id, delegate, kind)| super::Delegation {
|
||||||
account_id: locked_id,
|
account_id: locked_id,
|
||||||
|
kind,
|
||||||
access: delegate.access,
|
access: delegate.access,
|
||||||
send_as: delegate.send_as,
|
send_as: delegate.send_as,
|
||||||
until: delegate.until,
|
until: delegate.until,
|
||||||
@@ -97,6 +126,9 @@ impl Server {
|
|||||||
.map(|m| m.id() as u32)
|
.map(|m| m.id() as u32)
|
||||||
.collect::<TinyVec<[u32; 3]>>();
|
.collect::<TinyVec<[u32; 3]>>();
|
||||||
let mut access_to: Vec<AccessTo> = Vec::new();
|
let mut access_to: Vec<AccessTo> = Vec::new();
|
||||||
|
// inbuxa: MA-C: whether an owner's mail shares are honored,
|
||||||
|
// looked up once per owner
|
||||||
|
let mut mail_shares_honored: Vec<(u32, bool)> = Vec::new();
|
||||||
for grant_account_id in [account_id].into_iter().chain(member_of.iter().copied()) {
|
for grant_account_id in [account_id].into_iter().chain(member_of.iter().copied()) {
|
||||||
for acl_item in self
|
for acl_item in self
|
||||||
.store()
|
.store()
|
||||||
@@ -117,6 +149,27 @@ impl Server {
|
|||||||
.caused_by(trc::location!()));
|
.caused_by(trc::location!()));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// inbuxa: MA-C: a mail share from an account whose
|
||||||
|
// tenant (or server) has mail sharing off gives
|
||||||
|
// nothing while it is off. It stays stored, so it
|
||||||
|
// comes back when sharing does. A lock's and a
|
||||||
|
// shared mailbox's grants are an administrator's,
|
||||||
|
// and always count.
|
||||||
|
if collection == Collection::Mailbox {
|
||||||
|
let owner = acl_item.to_account_id;
|
||||||
|
let honored = match mail_shares_honored.iter().find(|(id, _)| *id == owner) {
|
||||||
|
Some((_, honored)) => *honored,
|
||||||
|
None => {
|
||||||
|
let honored = self.mail_shares_honored(owner).await?;
|
||||||
|
mail_shares_honored.push((owner, honored));
|
||||||
|
honored
|
||||||
|
}
|
||||||
|
};
|
||||||
|
if !honored {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
let mut collections: Bitmap<Collection> = Bitmap::new();
|
let mut collections: Bitmap<Collection> = Bitmap::new();
|
||||||
if acl.contains(Acl::Read) {
|
if acl.contains(Acl::Read) {
|
||||||
collections.insert(collection);
|
collections.insert(collection);
|
||||||
@@ -247,6 +300,7 @@ impl Server {
|
|||||||
.map(ConcurrencyLimiter::new),
|
.map(ConcurrencyLimiter::new),
|
||||||
obj_size: 0,
|
obj_size: 0,
|
||||||
locked,
|
locked,
|
||||||
|
shared_mailbox,
|
||||||
delegations: delegations.clone(),
|
delegations: delegations.clone(),
|
||||||
revision,
|
revision,
|
||||||
revision_account,
|
revision_account,
|
||||||
@@ -300,6 +354,7 @@ impl Server {
|
|||||||
.map(ConcurrencyLimiter::new),
|
.map(ConcurrencyLimiter::new),
|
||||||
obj_size: 0,
|
obj_size: 0,
|
||||||
locked,
|
locked,
|
||||||
|
shared_mailbox,
|
||||||
delegations: delegations.clone(),
|
delegations: delegations.clone(),
|
||||||
revision,
|
revision,
|
||||||
revision_account,
|
revision_account,
|
||||||
@@ -553,6 +608,16 @@ impl AccessToken {
|
|||||||
|| self.inner.access_to.iter().any(|a| a.account_id == account_id)
|
|| self.inner.access_to.iter().any(|a| a.account_id == account_id)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// inbuxa: MA-D0: in the account only because it is a group this token
|
||||||
|
/// belongs to. Such a member has the group's mailbox but may not share it
|
||||||
|
/// on: who is in a group is an administrator's decision, and a share
|
||||||
|
/// would let anyone in.
|
||||||
|
pub fn is_group_member_only(&self, account_id: u32) -> bool {
|
||||||
|
self.inner.account_id != account_id
|
||||||
|
&& self.inner.member_of.contains(&account_id)
|
||||||
|
&& !self.has_permission(Permission::Impersonate)
|
||||||
|
}
|
||||||
|
|
||||||
pub fn is_account_id(&self, account_id: u32) -> bool {
|
pub fn is_account_id(&self, account_id: u32) -> bool {
|
||||||
self.inner.account_id == account_id
|
self.inner.account_id == account_id
|
||||||
}
|
}
|
||||||
@@ -648,6 +713,7 @@ impl AccessToken {
|
|||||||
credential_version: old_inner.credential_version,
|
credential_version: old_inner.credential_version,
|
||||||
obj_size: old_inner.obj_size,
|
obj_size: old_inner.obj_size,
|
||||||
locked: old_inner.locked,
|
locked: old_inner.locked,
|
||||||
|
shared_mailbox: old_inner.shared_mailbox,
|
||||||
delegations: old_inner.delegations.clone(),
|
delegations: old_inner.delegations.clone(),
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -838,6 +904,18 @@ impl AccessToken {
|
|||||||
self.inner.locked
|
self.inner.locked
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// inbuxa: MA-S: the account is a shared mailbox (a lock of that kind).
|
||||||
|
pub fn is_shared_mailbox(&self) -> bool {
|
||||||
|
self.inner.shared_mailbox
|
||||||
|
}
|
||||||
|
|
||||||
|
/// inbuxa: MA-S: this account's delegation into `account_id` is to a
|
||||||
|
/// shared mailbox, not a locked account.
|
||||||
|
pub fn delegated_shared_mailbox(&self, account_id: u32) -> bool {
|
||||||
|
self.delegation(account_id)
|
||||||
|
.is_some_and(|d| d.kind == inbuxa_features::lock::Kind::SharedMailbox)
|
||||||
|
}
|
||||||
|
|
||||||
/// inbuxa: AL-5: this account's delegation into a locked account, if it
|
/// inbuxa: AL-5: this account's delegation into a locked account, if it
|
||||||
/// has one that hasn't ended.
|
/// has one that hasn't ended.
|
||||||
/// inbuxa: AL-6, AL-7: a delegate at organize or full, who may add to
|
/// inbuxa: AL-6, AL-7: a delegate at organize or full, who may add to
|
||||||
@@ -918,6 +996,7 @@ impl AccessToken {
|
|||||||
credential_version: Default::default(),
|
credential_version: Default::default(),
|
||||||
obj_size: Default::default(),
|
obj_size: Default::default(),
|
||||||
locked: false,
|
locked: false,
|
||||||
|
shared_mailbox: false,
|
||||||
delegations: Default::default(),
|
delegations: Default::default(),
|
||||||
}),
|
}),
|
||||||
}
|
}
|
||||||
@@ -978,6 +1057,7 @@ impl AccessTokenInner {
|
|||||||
credential_version: Default::default(),
|
credential_version: Default::default(),
|
||||||
obj_size: Default::default(),
|
obj_size: Default::default(),
|
||||||
locked: false,
|
locked: false,
|
||||||
|
shared_mailbox: false,
|
||||||
delegations: Default::default(),
|
delegations: Default::default(),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -152,6 +152,8 @@ pub struct AccessTokenInner {
|
|||||||
pub(crate) obj_size: u64,
|
pub(crate) obj_size: u64,
|
||||||
// inbuxa: AL-2: the account is locked; it may not authenticate
|
// inbuxa: AL-2: the account is locked; it may not authenticate
|
||||||
pub(crate) locked: bool,
|
pub(crate) locked: bool,
|
||||||
|
// inbuxa: MA-S: the lock is a shared mailbox
|
||||||
|
pub(crate) shared_mailbox: bool,
|
||||||
// inbuxa: AL-5: locked accounts handed to this one
|
// inbuxa: AL-5: locked accounts handed to this one
|
||||||
pub(crate) delegations: Box<[Delegation]>,
|
pub(crate) delegations: Box<[Delegation]>,
|
||||||
}
|
}
|
||||||
@@ -165,6 +167,8 @@ pub struct Delegation {
|
|||||||
pub send_as: bool,
|
pub send_as: bool,
|
||||||
/// Seconds since the epoch.
|
/// Seconds since the epoch.
|
||||||
pub until: Option<u64>,
|
pub until: Option<u64>,
|
||||||
|
/// MA-S: a locked account, or a shared mailbox.
|
||||||
|
pub kind: inbuxa_features::lock::Kind,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Debug, Default, Hash, Clone)]
|
#[derive(Debug, Default, Hash, Clone)]
|
||||||
|
|||||||
@@ -104,6 +104,19 @@ impl Server {
|
|||||||
ceiling(base, policy).apply(&mut permissions.enabled, &mut permissions.disabled);
|
ceiling(base, policy).apply(&mut permissions.enabled, &mut permissions.disabled);
|
||||||
// inbuxa: MT-1, MT-15: impersonation would reach beyond the tenant
|
// inbuxa: MT-1, MT-15: impersonation would reach beyond the tenant
|
||||||
permissions.disabled.set(Permission::Impersonate as usize);
|
permissions.disabled.set(Permission::Impersonate as usize);
|
||||||
|
// inbuxa: LH-13: only server-level administrators see or place
|
||||||
|
// holds, and a hold may concern the tenant's own administrator
|
||||||
|
for permission in [
|
||||||
|
Permission::SysLegalHoldGet,
|
||||||
|
Permission::SysLegalHoldCreate,
|
||||||
|
Permission::SysLegalHoldUpdate,
|
||||||
|
Permission::SysLegalHoldExport,
|
||||||
|
// inbuxa: DL-20: the lists and the check are the server's
|
||||||
|
Permission::SysDeliverabilityUpdate,
|
||||||
|
Permission::SysDeliverabilityCheck,
|
||||||
|
] {
|
||||||
|
permissions.disabled.set(permission as usize);
|
||||||
|
}
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
@@ -155,6 +168,14 @@ impl AccessToken {
|
|||||||
mut requested_permissions: Permissions,
|
mut requested_permissions: Permissions,
|
||||||
) -> Result<(), Vec<Permission>> {
|
) -> Result<(), Vec<Permission>> {
|
||||||
requested_permissions.difference(self.permissions_bits());
|
requested_permissions.difference(self.permissions_bits());
|
||||||
|
// inbuxa: journaling, JR-18: whoever sets up journals may give
|
||||||
|
// others (or, through a role, themselves) the reading of them,
|
||||||
|
// which administrators don't hold by default; the role change is
|
||||||
|
// in the audit log
|
||||||
|
if self.has_permission(Permission::SysJournalUpdate) {
|
||||||
|
requested_permissions.clear(Permission::SysJournalSearch as usize);
|
||||||
|
requested_permissions.clear(Permission::SysJournalExport as usize);
|
||||||
|
}
|
||||||
if requested_permissions.is_empty() {
|
if requested_permissions.is_empty() {
|
||||||
Ok(())
|
Ok(())
|
||||||
} else {
|
} else {
|
||||||
@@ -254,6 +275,11 @@ impl Default for DefaultPermissions {
|
|||||||
default.tenant.push(permission);
|
default.tenant.push(permission);
|
||||||
}
|
}
|
||||||
Permission::Impersonate
|
Permission::Impersonate
|
||||||
|
// inbuxa: LH-13: holds are the server administrator's alone
|
||||||
|
| Permission::SysLegalHoldGet
|
||||||
|
| Permission::SysLegalHoldCreate
|
||||||
|
| Permission::SysLegalHoldUpdate
|
||||||
|
| Permission::SysLegalHoldExport
|
||||||
| Permission::UnlimitedRequests
|
| Permission::UnlimitedRequests
|
||||||
| Permission::UnlimitedUploads
|
| Permission::UnlimitedUploads
|
||||||
| Permission::LiveMetrics
|
| Permission::LiveMetrics
|
||||||
@@ -275,6 +301,43 @@ impl Default for DefaultPermissions {
|
|||||||
default.superuser.push(permission);
|
default.superuser.push(permission);
|
||||||
default.tenant.push(permission);
|
default.tenant.push(permission);
|
||||||
}
|
}
|
||||||
|
// inbuxa: personal-data catalog: the data inventory, the
|
||||||
|
// server's or, inside a tenant, the tenant's slice
|
||||||
|
Permission::SysComplianceGet => {
|
||||||
|
default.superuser.push(permission);
|
||||||
|
default.tenant.push(permission);
|
||||||
|
}
|
||||||
|
// inbuxa: deliverability spec, DL-20: a tenant administrator
|
||||||
|
// reads its own domains' findings; the lists and the check
|
||||||
|
// itself are the server's
|
||||||
|
Permission::SysDeliverabilityGet => {
|
||||||
|
default.superuser.push(permission);
|
||||||
|
default.tenant.push(permission);
|
||||||
|
}
|
||||||
|
Permission::SysDeliverabilityUpdate | Permission::SysDeliverabilityCheck => {
|
||||||
|
default.superuser.push(permission);
|
||||||
|
}
|
||||||
|
// inbuxa: DLP and mail flow rules, and held mail, are the
|
||||||
|
// server's: never a tenant's (dlp-and-mail-flow-rules spec,
|
||||||
|
// settled answer 3)
|
||||||
|
Permission::SysMailRuleGet
|
||||||
|
| Permission::SysMailRuleUpdate
|
||||||
|
| Permission::SysDlpPolicyGet
|
||||||
|
| Permission::SysDlpPolicyUpdate
|
||||||
|
| Permission::SysDlpReviewGet
|
||||||
|
| Permission::SysDlpReviewUpdate
|
||||||
|
// inbuxa: every security check is server-wide (security
|
||||||
|
// to-do list spec)
|
||||||
|
| Permission::SysSecurityAccept => {
|
||||||
|
default.superuser.push(permission);
|
||||||
|
}
|
||||||
|
// inbuxa: journals are the server's; administrators set them
|
||||||
|
// up but read what's journaled only if granted it
|
||||||
|
// (journaling spec, JR-18, settled answer 5)
|
||||||
|
Permission::SysJournalGet | Permission::SysJournalUpdate => {
|
||||||
|
default.superuser.push(permission);
|
||||||
|
}
|
||||||
|
Permission::SysJournalSearch | Permission::SysJournalExport => {}
|
||||||
// inbuxa: AL-12: tenant administrators lock and delegate
|
// inbuxa: AL-12: tenant administrators lock and delegate
|
||||||
// within their tenant
|
// within their tenant
|
||||||
Permission::SysAccountLockGet
|
Permission::SysAccountLockGet
|
||||||
|
|||||||
@@ -46,10 +46,10 @@ pub struct Network {
|
|||||||
|
|
||||||
#[derive(Clone)]
|
#[derive(Clone)]
|
||||||
pub struct NetworkInfo {
|
pub struct NetworkInfo {
|
||||||
pub pacc: Pacc,
|
/// inbuxa: the document once per combination of legacy protocols off,
|
||||||
/// inbuxa: the same document without IMAP, POP3, SMTP and ManageSieve,
|
/// indexed by `LegacyOff::index` (legacy-protocols LP-7, one switch per
|
||||||
/// served while legacy protocols are off (legacy-protocols LP-7).
|
/// protocol); index 0 is the full document.
|
||||||
pub pacc_jmap_only: Pacc,
|
pub pacc: Vec<Pacc>,
|
||||||
pub mxs: Vec<MailExchanger>,
|
pub mxs: Vec<MailExchanger>,
|
||||||
pub services: VecMap<ServiceProtocol, Service>,
|
pub services: VecMap<ServiceProtocol, Service>,
|
||||||
}
|
}
|
||||||
@@ -72,6 +72,10 @@ pub struct Http {
|
|||||||
pub cors_origins: Vec<hyper::header::HeaderValue>,
|
pub cors_origins: Vec<hyper::header::HeaderValue>,
|
||||||
pub use_forwarded: bool,
|
pub use_forwarded: bool,
|
||||||
pub redirect_root: Option<String>,
|
pub redirect_root: Option<String>,
|
||||||
|
/// inbuxa: HTTP Basic accepted on every endpoint, not only DAV (contract
|
||||||
|
/// C-23). True in bootstrap and recovery mode, or with
|
||||||
|
/// `INBUXA_HTTP_BASIC_AUTH=all`.
|
||||||
|
pub basic_auth_everywhere: bool,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Clone)]
|
#[derive(Clone)]
|
||||||
@@ -333,16 +337,27 @@ impl Network {
|
|||||||
})
|
})
|
||||||
.unwrap()
|
.unwrap()
|
||||||
};
|
};
|
||||||
// inbuxa: legacy-protocols LP-7
|
// inbuxa: legacy-protocols LP-7, one document per combination of
|
||||||
let pacc_jmap_only = {
|
// protocols off, bits as `LegacyOff::index`: IMAP, POP3, ManageSieve,
|
||||||
|
// submission.
|
||||||
|
let pacc = (0..16usize)
|
||||||
|
.map(|off| {
|
||||||
let mut pacc = pacc.clone();
|
let mut pacc = pacc.clone();
|
||||||
|
if off & 1 != 0 {
|
||||||
pacc.protocols.imap = None;
|
pacc.protocols.imap = None;
|
||||||
|
}
|
||||||
|
if off & 2 != 0 {
|
||||||
pacc.protocols.pop3 = None;
|
pacc.protocols.pop3 = None;
|
||||||
pacc.protocols.smtp = None;
|
}
|
||||||
|
if off & 4 != 0 {
|
||||||
pacc.protocols.managesieve = None;
|
pacc.protocols.managesieve = None;
|
||||||
|
}
|
||||||
|
if off & 8 != 0 {
|
||||||
|
pacc.protocols.smtp = None;
|
||||||
|
}
|
||||||
split(&pacc)
|
split(&pacc)
|
||||||
};
|
})
|
||||||
let pacc = split(&pacc);
|
.collect();
|
||||||
let mut network = Network {
|
let mut network = Network {
|
||||||
node_id: bp.node_id() as u64,
|
node_id: bp.node_id() as u64,
|
||||||
server_name: default_hostname.to_string(),
|
server_name: default_hostname.to_string(),
|
||||||
@@ -358,7 +373,6 @@ impl Network {
|
|||||||
mxs: system.mail_exchangers.into_iter().collect(),
|
mxs: system.mail_exchangers.into_iter().collect(),
|
||||||
services: system.services,
|
services: system.services,
|
||||||
pacc,
|
pacc,
|
||||||
pacc_jmap_only,
|
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -443,6 +457,35 @@ impl Http {
|
|||||||
.collect()
|
.collect()
|
||||||
};
|
};
|
||||||
|
|
||||||
|
// inbuxa: outside DAV, HTTP sign-in is a token unless the operator
|
||||||
|
// says otherwise (contract C-23). The integration suites sign in with
|
||||||
|
// passwords over JMAP and the API, so test builds accept Basic
|
||||||
|
// everywhere.
|
||||||
|
#[cfg(feature = "test_mode")]
|
||||||
|
let basic_auth_everywhere = true;
|
||||||
|
|
||||||
|
#[cfg(not(feature = "test_mode"))]
|
||||||
|
let basic_auth_everywhere = bp.registry.is_recovery_mode()
|
||||||
|
|| bp.registry.is_bootstrap_mode()
|
||||||
|
|| match types::branding::env_var("HTTP_BASIC_AUTH") {
|
||||||
|
Ok(value) if value.trim().eq_ignore_ascii_case("all") => true,
|
||||||
|
Ok(value)
|
||||||
|
if value.trim().is_empty() || value.trim().eq_ignore_ascii_case("dav") =>
|
||||||
|
{
|
||||||
|
false
|
||||||
|
}
|
||||||
|
Ok(value) => {
|
||||||
|
bp.build_warning(
|
||||||
|
ObjectType::Http.singleton(),
|
||||||
|
format!(
|
||||||
|
"INBUXA_HTTP_BASIC_AUTH is {value:?}; expected \"dav\" or \"all\". Basic authentication stays on DAV only."
|
||||||
|
),
|
||||||
|
);
|
||||||
|
false
|
||||||
|
}
|
||||||
|
Err(_) => false,
|
||||||
|
};
|
||||||
|
|
||||||
if use_permissive_cors {
|
if use_permissive_cors {
|
||||||
http_headers.push((
|
http_headers.push((
|
||||||
hyper::header::ACCESS_CONTROL_ALLOW_ORIGIN,
|
hyper::header::ACCESS_CONTROL_ALLOW_ORIGIN,
|
||||||
@@ -502,6 +545,7 @@ impl Http {
|
|||||||
cors_origins,
|
cors_origins,
|
||||||
use_forwarded: http.use_x_forwarded,
|
use_forwarded: http.use_x_forwarded,
|
||||||
redirect_root: http.redirect_root,
|
redirect_root: http.redirect_root,
|
||||||
|
basic_auth_everywhere,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -483,8 +483,16 @@ impl Tracers {
|
|||||||
};
|
};
|
||||||
|
|
||||||
// Parse webhook events
|
// Parse webhook events
|
||||||
|
// inbuxa: personal-data catalog, finding 1: an include list is
|
||||||
|
// sent as named; otherwise a webhook honors its level as a
|
||||||
|
// tracer does, and never sends a protocol's raw input or
|
||||||
|
// output (whole messages)
|
||||||
|
let level = Level::from(hook.level);
|
||||||
|
let named = (hook.events_policy == EventPolicy::Include)
|
||||||
|
.then(|| hook.events.iter().copied().collect::<AHashSet<_>>())
|
||||||
|
.unwrap_or_default();
|
||||||
apply_events(hook.events, hook.events_policy, |event_type| {
|
apply_events(hook.events, hook.events_policy, |event_type| {
|
||||||
if event_type != EventType::Telemetry(TelemetryEvent::WebhookError) {
|
if webhook_wants(event_type, level, &custom_levels, &named) {
|
||||||
tracer.interests.set(event_type);
|
tracer.interests.set(event_type);
|
||||||
global_interests.set(event_type);
|
global_interests.set(event_type);
|
||||||
}
|
}
|
||||||
@@ -743,6 +751,31 @@ fn tracer_settings(tracer: &Tracer) -> u64 {
|
|||||||
settings_hash(&tracer)
|
settings_hash(&tracer)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// inbuxa: whether a webhook at `level` receives this event type. Its own
|
||||||
|
/// error event never, or a failing webhook would report itself to itself.
|
||||||
|
/// An event `named` in an include list always: naming it is the choice.
|
||||||
|
/// Otherwise (the exclude policy, the default) only events at or above its
|
||||||
|
/// level, as for a tracer, and never a protocol's raw input or output, which
|
||||||
|
/// carries whole messages and credentials.
|
||||||
|
fn webhook_wants(
|
||||||
|
event_type: EventType,
|
||||||
|
level: Level,
|
||||||
|
custom_levels: &AHashMap<EventType, Level>,
|
||||||
|
named: &AHashSet<EventType>,
|
||||||
|
) -> bool {
|
||||||
|
if event_type == EventType::Telemetry(TelemetryEvent::WebhookError) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
if named.contains(&event_type) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
let event_level = custom_levels
|
||||||
|
.get(&event_type)
|
||||||
|
.copied()
|
||||||
|
.unwrap_or(event_type.level());
|
||||||
|
level.is_contained(event_level) && !event_type.is_raw_io()
|
||||||
|
}
|
||||||
|
|
||||||
fn webhook_settings(hook: &WebHook) -> u64 {
|
fn webhook_settings(hook: &WebHook) -> u64 {
|
||||||
let mut hook = hook.clone();
|
let mut hook = hook.clone();
|
||||||
in_place_reset!(hook);
|
in_place_reset!(hook);
|
||||||
@@ -804,3 +837,61 @@ impl std::fmt::Debug for OtelMetrics {
|
|||||||
.finish()
|
.finish()
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
use trc::{AuthEvent, SmtpEvent};
|
||||||
|
|
||||||
|
fn wants(event: EventType, level: Level, named: &[EventType]) -> bool {
|
||||||
|
webhook_wants(
|
||||||
|
event,
|
||||||
|
level,
|
||||||
|
&AHashMap::new(),
|
||||||
|
&named.iter().copied().collect(),
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn a_webhook_honors_its_level() {
|
||||||
|
let success = EventType::Auth(AuthEvent::Success);
|
||||||
|
assert!(wants(success, Level::Info, &[]));
|
||||||
|
assert!(!wants(success, Level::Error, &[]), "info is below error");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn raw_io_goes_out_only_when_named() {
|
||||||
|
let raw = EventType::Smtp(SmtpEvent::RawInput);
|
||||||
|
assert!(raw.is_raw_io());
|
||||||
|
// Not with the exclude policy, even at trace
|
||||||
|
assert!(!wants(raw, Level::Info, &[]));
|
||||||
|
assert!(!wants(raw, Level::Trace, &[]));
|
||||||
|
// Named in an include list, whatever the level
|
||||||
|
assert!(wants(raw, Level::Info, &[raw]));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn a_named_event_is_sent_whatever_its_level() {
|
||||||
|
let start = EventType::Smtp(SmtpEvent::ConnectionStart);
|
||||||
|
assert!(!Level::Info.is_contained(start.level()), "below info");
|
||||||
|
assert!(!wants(start, Level::Info, &[]));
|
||||||
|
assert!(wants(start, Level::Info, &[start]));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn a_custom_level_counts() {
|
||||||
|
let start = EventType::Smtp(SmtpEvent::ConnectionStart);
|
||||||
|
let custom = [(start, Level::Info)].into_iter().collect::<AHashMap<_, _>>();
|
||||||
|
assert!(webhook_wants(start, Level::Info, &custom, &AHashSet::new()));
|
||||||
|
// Raw I/O raised to info still needs naming
|
||||||
|
let raw = EventType::Smtp(SmtpEvent::RawInput);
|
||||||
|
let custom = [(raw, Level::Info)].into_iter().collect::<AHashMap<_, _>>();
|
||||||
|
assert!(!webhook_wants(raw, Level::Info, &custom, &AHashSet::new()));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn a_webhook_never_hears_its_own_errors() {
|
||||||
|
let own = EventType::Telemetry(TelemetryEvent::WebhookError);
|
||||||
|
assert!(!wants(own, Level::Trace, &[own]));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -0,0 +1,282 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! inbuxa: which legal holds cover an account (audit-hold-lock spec, LH-2,
|
||||||
|
//! LH-11), for the paths that destroy data. Read from the store every time,
|
||||||
|
//! not cached: a hold placed on one node must bind every node at once, and
|
||||||
|
//! there are few holds.
|
||||||
|
|
||||||
|
use crate::Server;
|
||||||
|
use ahash::AHashMap;
|
||||||
|
use inbuxa_features::{
|
||||||
|
hold::{self, HELD_UNTIL, Hold, Keeping, Member, is_held_until},
|
||||||
|
undelete::records,
|
||||||
|
};
|
||||||
|
use inbuxa_features::undelete::data::{self as undelete_data, KeptAccount};
|
||||||
|
use registry::{
|
||||||
|
pickle::PickledStream,
|
||||||
|
schema::{
|
||||||
|
prelude::{ObjectInner, ObjectType},
|
||||||
|
structs::ArchivedItem,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
use store::{registry::RegistryQuery, write::now};
|
||||||
|
use trc::AddContext;
|
||||||
|
use types::id::Id;
|
||||||
|
|
||||||
|
/// The grace a released item gets at least (LH-10): a release made in error
|
||||||
|
/// can be undone by placing a new hold within it.
|
||||||
|
const RELEASE_GRACE: u64 = 30 * 86_400;
|
||||||
|
|
||||||
|
/// What a settle pass changed.
|
||||||
|
#[derive(Debug, Default, Clone, Copy, PartialEq, Eq)]
|
||||||
|
pub struct Settled {
|
||||||
|
pub frozen: usize,
|
||||||
|
pub released: usize,
|
||||||
|
/// Deleted accounts kept by a hold, or let go by a release (LH-8, LH-10).
|
||||||
|
pub accounts_frozen: usize,
|
||||||
|
pub accounts_released: usize,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// What one hold keeps (LH-9).
|
||||||
|
#[derive(Debug, Default, Clone, Copy, PartialEq, Eq)]
|
||||||
|
pub struct HoldSummary {
|
||||||
|
pub accounts: u64,
|
||||||
|
pub items: u64,
|
||||||
|
pub size: u64,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A kept account as it was when deleted, for a hold's scope: its record
|
||||||
|
/// still names its domain, groups and tenant.
|
||||||
|
pub fn kept_member(account_id: u32, kept: &KeptAccount) -> Member {
|
||||||
|
PickledStream::new(&kept.record)
|
||||||
|
.and_then(|mut stream| ObjectInner::unpickle(ObjectType::Account, &mut stream))
|
||||||
|
.and_then(|inner| Member::of(account_id, &inner))
|
||||||
|
.unwrap_or(Member {
|
||||||
|
account: account_id,
|
||||||
|
..Default::default()
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Server {
|
||||||
|
/// What decides whether a hold reaches a live account; None if it's gone.
|
||||||
|
pub async fn member_of(&self, account_id: u32) -> Option<Member> {
|
||||||
|
let account = self.account(account_id).await.ok()?;
|
||||||
|
let mut domains = account
|
||||||
|
.addresses
|
||||||
|
.iter()
|
||||||
|
.map(|address| address.domain_id)
|
||||||
|
.collect::<Vec<_>>();
|
||||||
|
domains.sort_unstable();
|
||||||
|
domains.dedup();
|
||||||
|
Some(Member {
|
||||||
|
account: account_id,
|
||||||
|
domains,
|
||||||
|
groups: account.id_member_of.iter().copied().collect(),
|
||||||
|
tenant: account.id_tenant,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// LH-9, the console's "what's held": per active hold, the accounts it
|
||||||
|
/// covers now (deleted ones it keeps included), and the archived items
|
||||||
|
/// it keeps with their size. One pass over accounts and archive.
|
||||||
|
pub async fn hold_summaries(&self) -> trc::Result<AHashMap<u32, HoldSummary>> {
|
||||||
|
let data = self.store();
|
||||||
|
let registry = self.registry();
|
||||||
|
let holds = hold::active(data).await?;
|
||||||
|
let mut summaries: AHashMap<u32, HoldSummary> =
|
||||||
|
holds.iter().map(|h| (h.id, HoldSummary::default())).collect();
|
||||||
|
if holds.is_empty() {
|
||||||
|
return Ok(summaries);
|
||||||
|
}
|
||||||
|
let mut members: AHashMap<u32, Member> = AHashMap::new();
|
||||||
|
for id in registry
|
||||||
|
.query::<Vec<Id>>(RegistryQuery::new(ObjectType::Account))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
{
|
||||||
|
if let Some(member) = self.member_of(id.document_id()).await {
|
||||||
|
members.insert(id.document_id(), member);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
for (account_id, kept) in undelete_data::kept_accounts(data).await? {
|
||||||
|
members.insert(account_id, kept_member(account_id, &kept));
|
||||||
|
}
|
||||||
|
for member in members.values() {
|
||||||
|
for hold in holds.iter().filter(|h| h.scope.covers(member)) {
|
||||||
|
summaries.entry(hold.id).or_default().accounts += 1;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
for id in records::all(data, registry).await? {
|
||||||
|
let Some(item) = registry.object::<ArchivedItem>(id).await? else {
|
||||||
|
continue;
|
||||||
|
};
|
||||||
|
if !is_held_until(item.archived_until().timestamp().max(0) as u64) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
let Some(member) = members.get(&item.account_id().document_id()) else {
|
||||||
|
continue;
|
||||||
|
};
|
||||||
|
let size = match &item {
|
||||||
|
ArchivedItem::Email(email) => email.size,
|
||||||
|
ArchivedItem::FileNode(_) => match undelete_data::extra(data, id).await? {
|
||||||
|
Some(inbuxa_features::undelete::data::Extra::FileNode { size, .. }) => size as u64,
|
||||||
|
_ => 0,
|
||||||
|
},
|
||||||
|
_ => 0,
|
||||||
|
};
|
||||||
|
for hold in holds.iter().filter(|h| h.scope.covers(member)) {
|
||||||
|
let summary = summaries.entry(hold.id).or_default();
|
||||||
|
summary.items += 1;
|
||||||
|
summary.size += size;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Ok(summaries)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The active holds covering `account_id`, through its own name, its
|
||||||
|
/// addresses' domains, its groups or its tenant. Empty for an account
|
||||||
|
/// that no longer exists: a deleted one is kept by LH-8's own check.
|
||||||
|
pub async fn holds_on(&self, account_id: u32) -> trc::Result<Vec<Hold>> {
|
||||||
|
let Ok(account) = self.account(account_id).await else {
|
||||||
|
return Ok(Vec::new());
|
||||||
|
};
|
||||||
|
let mut domains = account
|
||||||
|
.addresses
|
||||||
|
.iter()
|
||||||
|
.map(|address| address.domain_id)
|
||||||
|
.collect::<Vec<_>>();
|
||||||
|
domains.sort_unstable();
|
||||||
|
domains.dedup();
|
||||||
|
let member = Member {
|
||||||
|
account: account_id,
|
||||||
|
domains,
|
||||||
|
groups: account.id_member_of.iter().copied().collect(),
|
||||||
|
tenant: account.id_tenant,
|
||||||
|
};
|
||||||
|
hold::covering(self.store(), &member).await
|
||||||
|
}
|
||||||
|
|
||||||
|
/// How `account_id`'s deleted items are kept: its holds' ranges and the
|
||||||
|
/// undelete period in force now (LH-4, UD-6a).
|
||||||
|
pub async fn keeping(&self, account_id: u32) -> trc::Result<Keeping> {
|
||||||
|
let retention = inbuxa_features::undelete::settings::retention(self.registry())
|
||||||
|
.await?
|
||||||
|
.items;
|
||||||
|
Ok(Keeping::new(retention, &self.holds_on(account_id).await?))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// LH-6, LH-10, LH-11: brings the whole archive in line with the active
|
||||||
|
/// holds. An archived item a hold covers is frozen (no deadline), its
|
||||||
|
/// old deadline noted; a frozen one no hold covers any more gets that
|
||||||
|
/// deadline back, or release plus 30 days if later. Run after every
|
||||||
|
/// change to a hold; it changes nothing twice.
|
||||||
|
pub async fn settle_archive(&self) -> trc::Result<Settled> {
|
||||||
|
let data = self.store();
|
||||||
|
let registry = self.registry();
|
||||||
|
let any_active = !hold::active(data).await?.is_empty();
|
||||||
|
let now = now();
|
||||||
|
let mut keeping: AHashMap<u32, Option<Keeping>> = AHashMap::new();
|
||||||
|
let mut settled = Settled::default();
|
||||||
|
for id in records::all(data, registry).await? {
|
||||||
|
let Some(item) = registry.object::<ArchivedItem>(id).await? else {
|
||||||
|
continue;
|
||||||
|
};
|
||||||
|
let account_id = item.account_id().document_id();
|
||||||
|
if !keeping.contains_key(&account_id) {
|
||||||
|
// An account that's gone can't be placed in a domain or
|
||||||
|
// tenant any more: None, and its items are left as they are
|
||||||
|
let known = self.account(account_id).await.is_ok();
|
||||||
|
let value = if known { Some(self.keeping(account_id).await?) } else { None };
|
||||||
|
keeping.insert(account_id, value);
|
||||||
|
}
|
||||||
|
let until = item.archived_until().timestamp().max(0) as u64;
|
||||||
|
let held = is_held_until(until);
|
||||||
|
let covered = match keeping.get(&account_id).and_then(Option::as_ref) {
|
||||||
|
Some(keeping) => match &item {
|
||||||
|
ArchivedItem::Email(email) => {
|
||||||
|
keeping.covers(Some(email.received_at.timestamp().max(0) as u64))
|
||||||
|
}
|
||||||
|
ArchivedItem::CalendarEvent(event) => keeping
|
||||||
|
.covers_event(event.start_time.map(|t| t.timestamp().max(0) as u64)),
|
||||||
|
_ => keeping.covers(None),
|
||||||
|
},
|
||||||
|
// Gone: release only once no hold is active anywhere
|
||||||
|
None => held && any_active,
|
||||||
|
};
|
||||||
|
if covered && !held {
|
||||||
|
hold::set_original_deadline(data, id.id(), Some(until)).await?;
|
||||||
|
records::set_deadline(data, registry, id, &item, HELD_UNTIL).await?;
|
||||||
|
settled.frozen += 1;
|
||||||
|
} else if !covered && held {
|
||||||
|
let original = hold::original_deadline(data, id.id()).await?.unwrap_or(0);
|
||||||
|
records::set_deadline(data, registry, id, &item, original.max(now + RELEASE_GRACE))
|
||||||
|
.await?;
|
||||||
|
hold::set_original_deadline(data, id.id(), None).await?;
|
||||||
|
settled.released += 1;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// LH-8, LH-10: deleted accounts kept by undelete follow the holds
|
||||||
|
// too. Their DestroyAccount task defers itself while they're kept.
|
||||||
|
let retention = inbuxa_features::undelete::settings::retention(registry)
|
||||||
|
.await?
|
||||||
|
.accounts;
|
||||||
|
for (account_id, mut kept) in undelete_data::kept_accounts(data).await? {
|
||||||
|
let covered = !hold::covering(data, &kept_member(account_id, &kept)).await?.is_empty();
|
||||||
|
let held = is_held_until(kept.kept_until);
|
||||||
|
let until = if covered && !held {
|
||||||
|
settled.accounts_frozen += 1;
|
||||||
|
HELD_UNTIL
|
||||||
|
} else if !covered && held {
|
||||||
|
settled.accounts_released += 1;
|
||||||
|
(kept.deleted_at + retention.unwrap_or(0)).max(now + RELEASE_GRACE)
|
||||||
|
} else {
|
||||||
|
continue;
|
||||||
|
};
|
||||||
|
kept.kept_until = until;
|
||||||
|
let mut batch = store::write::BatchBuilder::new();
|
||||||
|
undelete_data::set_kept_account(&mut batch, account_id, &kept)?;
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
}
|
||||||
|
Ok(settled)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// LH-8: whether a hold covers a deleted account undelete keeps.
|
||||||
|
pub async fn is_kept_held(&self, account_id: u32, kept: &KeptAccount) -> trc::Result<bool> {
|
||||||
|
Ok(!hold::covering(self.store(), &kept_member(account_id, kept))
|
||||||
|
.await?
|
||||||
|
.is_empty())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Every account an active hold covers now. Empty, without looking at
|
||||||
|
/// accounts, when nothing is held.
|
||||||
|
pub async fn held_accounts(&self) -> trc::Result<ahash::AHashSet<u32>> {
|
||||||
|
let mut held = ahash::AHashSet::new();
|
||||||
|
if hold::active(self.store()).await?.is_empty() {
|
||||||
|
return Ok(held);
|
||||||
|
}
|
||||||
|
for id in self
|
||||||
|
.registry()
|
||||||
|
.query::<Vec<Id>>(RegistryQuery::new(ObjectType::Account))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
{
|
||||||
|
let account_id = id.document_id();
|
||||||
|
if self.is_held(account_id).await? {
|
||||||
|
held.insert(account_id);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Ok(held)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Whether any active hold covers `account_id` at all.
|
||||||
|
pub async fn is_held(&self, account_id: u32) -> trc::Result<bool> {
|
||||||
|
Ok(!self.holds_on(account_id).await?.is_empty())
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -88,6 +88,8 @@ pub enum BroadcastEvent {
|
|||||||
QueueRefresh,
|
QueueRefresh,
|
||||||
// inbuxa: AL-3: end an account's open sessions on every node
|
// inbuxa: AL-3: end an account's open sessions on every node
|
||||||
EndSessions(u32),
|
EndSessions(u32),
|
||||||
|
// inbuxa: deliverability spec, DL-15: every node checks itself now
|
||||||
|
DeliverabilityCheck,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Debug, Clone, Copy)]
|
#[derive(Debug, Clone, Copy)]
|
||||||
|
|||||||
@@ -68,6 +68,9 @@ use utils::{
|
|||||||
pub mod auth;
|
pub mod auth;
|
||||||
pub mod cache;
|
pub mod cache;
|
||||||
pub mod audit; // inbuxa: the audit log (audit-hold-lock spec, AU)
|
pub mod audit; // inbuxa: the audit log (audit-hold-lock spec, AU)
|
||||||
|
pub mod hold; // inbuxa: legal holds (audit-hold-lock spec, LH)
|
||||||
|
pub mod privacy; // inbuxa: the personal-data catalog, evaluated
|
||||||
|
pub mod reachability; // inbuxa: whether the outside world reaches each node's ports
|
||||||
pub mod config;
|
pub mod config;
|
||||||
pub mod expr;
|
pub mod expr;
|
||||||
pub mod i18n;
|
pub mod i18n;
|
||||||
@@ -127,6 +130,8 @@ pub const KV_LOCK_QUEUE_MESSAGE: u8 = 21;
|
|||||||
pub const KV_LOCK_TASK: u8 = 23;
|
pub const KV_LOCK_TASK: u8 = 23;
|
||||||
pub const KV_LOCK_DAV: u8 = 25;
|
pub const KV_LOCK_DAV: u8 = 25;
|
||||||
pub const KV_SIEVE_ID: u8 = 26;
|
pub const KV_SIEVE_ID: u8 = 26;
|
||||||
|
// inbuxa: far above upstream's prefixes, so a new one of theirs never collides
|
||||||
|
pub const KV_PORT_REACHABILITY: u8 = 200;
|
||||||
|
|
||||||
#[derive(Clone)]
|
#[derive(Clone)]
|
||||||
pub struct Server {
|
pub struct Server {
|
||||||
@@ -220,7 +225,7 @@ pub struct Caches {
|
|||||||
pub dns_ipv6: CacheWithTtl<Box<str>, RecordSet<Ipv6Addr>>,
|
pub dns_ipv6: CacheWithTtl<Box<str>, RecordSet<Ipv6Addr>>,
|
||||||
pub dns_tlsa: CacheWithTtl<Box<str>, Arc<Tlsa>>,
|
pub dns_tlsa: CacheWithTtl<Box<str>, Arc<Tlsa>>,
|
||||||
pub dns_mta_sts: CacheWithTtl<Box<str>, Arc<Policy>>,
|
pub dns_mta_sts: CacheWithTtl<Box<str>, Arc<Policy>>,
|
||||||
pub dns_rbl: CacheWithTtl<Box<str>, Option<Arc<IpResolver>>>,
|
pub dns_rbl: CacheWithTtl<Box<str>, Option<Arc<[IpResolver]>>>,
|
||||||
|
|
||||||
pub negative_cache_ttl: Duration,
|
pub negative_cache_ttl: Duration,
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -227,10 +227,22 @@ impl WebApplicationManager {
|
|||||||
let cached = if force_refresh {
|
let cached = if force_refresh {
|
||||||
None
|
None
|
||||||
} else {
|
} else {
|
||||||
server
|
match server
|
||||||
.blob_store()
|
.blob_store()
|
||||||
.get_blob(self.blob_key.as_slice(), 0..usize::MAX)
|
.get_blob(self.blob_key.as_slice(), 0..usize::MAX)
|
||||||
.await?
|
.await
|
||||||
|
{
|
||||||
|
Ok(cached) => cached,
|
||||||
|
Err(err) => {
|
||||||
|
trc::event!(
|
||||||
|
Resource(trc::ResourceEvent::Error),
|
||||||
|
Reason = err,
|
||||||
|
Url = self.url.clone(),
|
||||||
|
Details = "Failed to read cached application bundle, downloading it again"
|
||||||
|
);
|
||||||
|
None
|
||||||
|
}
|
||||||
|
}
|
||||||
};
|
};
|
||||||
let is_cached = cached.is_some();
|
let is_cached = cached.is_some();
|
||||||
let bundle = match cached {
|
let bundle = match cached {
|
||||||
|
|||||||
@@ -0,0 +1,298 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! The compliance roles (personal-data catalog spec, §7; settled
|
||||||
|
//! 2026-09-28): a server-level Compliance Officer, and one Compliance
|
||||||
|
//! Officer role in each tenant. A tenant's accounts can hold only roles of
|
||||||
|
//! their own tenant (MT-3), so the tenant role is made per tenant: once for
|
||||||
|
//! each tenant a server already has, and whenever a tenant is created.
|
||||||
|
//!
|
||||||
|
//! Each creation is recorded under `P` `c` in the fork's subspace, so a
|
||||||
|
//! role an administrator deletes stays deleted. A tenant's role, while
|
||||||
|
//! nobody holds it, is removed with the tenant so it doesn't block the
|
||||||
|
//! delete.
|
||||||
|
//!
|
||||||
|
//! Both read what compliance work needs and change no server setting. The
|
||||||
|
//! server-level officer also places, widens, releases and exports legal
|
||||||
|
//! holds: that is the job, and each is audited with its reason. A tenant's
|
||||||
|
//! role has no holds, which are server-level only (LH-13), and the tenant
|
||||||
|
//! ceiling keeps it within the tenant. Each role carries a user's own
|
||||||
|
//! permissions too (signing in, mail), since roles given to a person replace
|
||||||
|
//! the default user role, and a tenant's accounts can't hold the
|
||||||
|
//! server-level User role.
|
||||||
|
|
||||||
|
use registry::schema::{
|
||||||
|
enums::Permission,
|
||||||
|
prelude::ObjectType,
|
||||||
|
structs::{Role, Tenant},
|
||||||
|
};
|
||||||
|
use registry::types::map::Map;
|
||||||
|
use store::{
|
||||||
|
RegistryStore, SUBSPACE_INBUXA, Store, ValueKey,
|
||||||
|
registry::write::{RegistryWrite, RegistryWriteResult},
|
||||||
|
write::{AnyClass, BatchBuilder, ValueClass},
|
||||||
|
};
|
||||||
|
use trc::AddContext;
|
||||||
|
use types::id::Id;
|
||||||
|
|
||||||
|
/// The role's name, in the server's roles and in each tenant's.
|
||||||
|
pub const NAME: &str = "Compliance Officer";
|
||||||
|
|
||||||
|
/// Reading who and what records refer to, for both roles.
|
||||||
|
const READS: &[Permission] = &[
|
||||||
|
Permission::SysAccountGet,
|
||||||
|
Permission::SysAccountQuery,
|
||||||
|
Permission::SysMailingListGet,
|
||||||
|
Permission::SysMailingListQuery,
|
||||||
|
Permission::SysDomainGet,
|
||||||
|
Permission::SysDomainQuery,
|
||||||
|
Permission::SysTenantGet,
|
||||||
|
Permission::SysTenantQuery,
|
||||||
|
Permission::SysRoleGet,
|
||||||
|
Permission::SysRoleQuery,
|
||||||
|
];
|
||||||
|
|
||||||
|
/// What the server-level officer holds besides [`READS`].
|
||||||
|
const OFFICER: &[Permission] = &[
|
||||||
|
Permission::SysComplianceGet,
|
||||||
|
Permission::SysAuditGet,
|
||||||
|
Permission::SysAuditExport,
|
||||||
|
Permission::SysLegalHoldGet,
|
||||||
|
Permission::SysLegalHoldCreate,
|
||||||
|
Permission::SysLegalHoldUpdate,
|
||||||
|
Permission::SysLegalHoldExport,
|
||||||
|
Permission::SysAccountLockGet,
|
||||||
|
// dlp-and-mail-flow-rules spec, §2.8: see DLP rules, review held mail
|
||||||
|
Permission::SysDlpPolicyGet,
|
||||||
|
Permission::SysDlpReviewGet,
|
||||||
|
Permission::SysDlpReviewUpdate,
|
||||||
|
// journaling spec, JR-18: see journals, search and export them
|
||||||
|
Permission::SysJournalGet,
|
||||||
|
Permission::SysJournalSearch,
|
||||||
|
Permission::SysJournalExport,
|
||||||
|
];
|
||||||
|
|
||||||
|
/// What a tenant's officer holds besides [`READS`].
|
||||||
|
const TENANT_OFFICER: &[Permission] = &[
|
||||||
|
Permission::SysComplianceGet,
|
||||||
|
Permission::SysAuditGet,
|
||||||
|
Permission::SysAuditExport,
|
||||||
|
Permission::SysAccountLockGet,
|
||||||
|
];
|
||||||
|
|
||||||
|
fn role(own: &[Permission], tenant: Option<Id>) -> Role {
|
||||||
|
let mut permissions = crate::auth::permissions::DefaultPermissions::default().user;
|
||||||
|
for permission in own.iter().chain(READS) {
|
||||||
|
if !permissions.contains(permission) {
|
||||||
|
permissions.push(*permission);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Role {
|
||||||
|
description: NAME.into(),
|
||||||
|
enabled_permissions: Map::new(permissions),
|
||||||
|
member_tenant_id: tenant,
|
||||||
|
..Default::default()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The server-level Compliance Officer role.
|
||||||
|
pub fn officer_role() -> Role {
|
||||||
|
role(OFFICER, None)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A tenant's Compliance Officer role.
|
||||||
|
pub fn tenant_role(tenant: Id) -> Role {
|
||||||
|
role(TENANT_OFFICER, Some(tenant))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Where a creation is recorded: the server's role, or a tenant's. The value
|
||||||
|
/// is the role's id.
|
||||||
|
fn created_key(tenant: Option<Id>) -> ValueClass {
|
||||||
|
let mut key = b"Pc".to_vec();
|
||||||
|
if let Some(tenant) = tenant {
|
||||||
|
key.extend_from_slice(&tenant.id().to_be_bytes());
|
||||||
|
}
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace: SUBSPACE_INBUXA,
|
||||||
|
key,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The server-level Compliance Officer role the server made, if it has.
|
||||||
|
pub async fn server_role(data: &Store) -> trc::Result<Option<Id>> {
|
||||||
|
recorded(data, None).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn recorded(data: &Store, tenant: Option<Id>) -> trc::Result<Option<Id>> {
|
||||||
|
Ok(data
|
||||||
|
.get_value::<u64>(ValueKey::from(created_key(tenant)))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
.map(Id::from))
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn record(data: &Store, tenant: Option<Id>, role: Option<Id>) -> trc::Result<()> {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
match role {
|
||||||
|
Some(role) => batch.set(created_key(tenant), role.id().to_be_bytes().to_vec()),
|
||||||
|
None => batch.clear(created_key(tenant)),
|
||||||
|
};
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())
|
||||||
|
.map(|_| ())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Creates a role, unless one was created for this place before, and records
|
||||||
|
/// it. Returns the new role's id.
|
||||||
|
async fn create_once(
|
||||||
|
registry: &RegistryStore,
|
||||||
|
data: &Store,
|
||||||
|
tenant: Option<Id>,
|
||||||
|
role: Role,
|
||||||
|
) -> trc::Result<Option<Id>> {
|
||||||
|
if recorded(data, tenant).await?.is_some() {
|
||||||
|
return Ok(None);
|
||||||
|
}
|
||||||
|
match registry.write(RegistryWrite::insert(&role.into())).await? {
|
||||||
|
RegistryWriteResult::Success(id) => {
|
||||||
|
record(data, tenant, Some(id)).await?;
|
||||||
|
Ok(Some(id))
|
||||||
|
}
|
||||||
|
err => {
|
||||||
|
trc::error!(
|
||||||
|
trc::EventType::Registry(trc::RegistryEvent::ValidationError)
|
||||||
|
.into_err()
|
||||||
|
.details(format!("Failed to create the {NAME} role: {err}"))
|
||||||
|
);
|
||||||
|
Ok(None)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Once per server: the officer role, and one in each tenant it already has.
|
||||||
|
pub async fn ensure_compliance_roles(registry: &RegistryStore, data: &Store) -> trc::Result<()> {
|
||||||
|
create_once(registry, data, None, officer_role()).await?;
|
||||||
|
for tenant in registry.list::<Tenant>().await? {
|
||||||
|
let tenant = Id::from(tenant.id.id());
|
||||||
|
create_once(registry, data, Some(tenant), tenant_role(tenant)).await?;
|
||||||
|
}
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A new tenant gets its Compliance Officer role.
|
||||||
|
pub async fn tenant_created(registry: &RegistryStore, data: &Store, tenant: Id) -> trc::Result<()> {
|
||||||
|
create_once(registry, data, Some(tenant), tenant_role(tenant))
|
||||||
|
.await
|
||||||
|
.map(|_| ())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Before a tenant is deleted: removes its Compliance Officer role if nobody
|
||||||
|
/// holds it, so the role doesn't block the delete. Returns whether it did,
|
||||||
|
/// so a delete refused for another reason can put it back.
|
||||||
|
pub async fn tenant_deleting(
|
||||||
|
registry: &RegistryStore,
|
||||||
|
data: &Store,
|
||||||
|
tenant: Id,
|
||||||
|
) -> trc::Result<bool> {
|
||||||
|
let Some(role) = recorded(data, Some(tenant)).await? else {
|
||||||
|
return Ok(false);
|
||||||
|
};
|
||||||
|
match registry
|
||||||
|
.write(RegistryWrite::delete(ObjectType::Role.id(role)))
|
||||||
|
.await?
|
||||||
|
{
|
||||||
|
RegistryWriteResult::Success(_) | RegistryWriteResult::NotFound { .. } => {
|
||||||
|
record(data, Some(tenant), None).await?;
|
||||||
|
Ok(true)
|
||||||
|
}
|
||||||
|
// Held by someone: the tenant's delete is refused for that anyway
|
||||||
|
_ => Ok(false),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A tenant's delete was refused after its role went: the role comes back.
|
||||||
|
pub async fn tenant_kept(registry: &RegistryStore, data: &Store, tenant: Id) -> trc::Result<()> {
|
||||||
|
tenant_created(registry, data, tenant).await
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
use registry::types::EnumImpl;
|
||||||
|
|
||||||
|
fn permissions(role: &Role) -> Vec<Permission> {
|
||||||
|
role.enabled_permissions.iter().copied().collect()
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn neither_role_changes_a_setting() {
|
||||||
|
let user = crate::auth::permissions::DefaultPermissions::default().user;
|
||||||
|
for role in [officer_role(), tenant_role(Id::from(7u64))] {
|
||||||
|
let all = permissions(&role);
|
||||||
|
for permission in user.iter() {
|
||||||
|
assert!(all.contains(permission), "a user's own {permission:?}");
|
||||||
|
}
|
||||||
|
// Beyond what any user holds for their own account
|
||||||
|
for permission in all.into_iter().filter(|p| !user.contains(p)) {
|
||||||
|
let name = permission.as_str();
|
||||||
|
// Placing holds and reviewing held mail are the officer's
|
||||||
|
// job, not settings (settled answers 2 and 4)
|
||||||
|
let holds = name.starts_with("sysLegalHold") || name.starts_with("sysDlpReview");
|
||||||
|
assert!(
|
||||||
|
!(name.ends_with("Update") && !holds)
|
||||||
|
&& !(name.ends_with("Create") && !holds)
|
||||||
|
&& !name.ends_with("Destroy")
|
||||||
|
&& permission != Permission::Impersonate
|
||||||
|
&& permission != Permission::FetchAnyBlob,
|
||||||
|
"{} holds {name}",
|
||||||
|
role.description
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn the_officer_places_and_releases_holds_a_tenants_does_not() {
|
||||||
|
let officer = permissions(&officer_role());
|
||||||
|
let tenant = tenant_role(Id::from(7u64));
|
||||||
|
assert_eq!(tenant.member_tenant_id, Some(Id::from(7u64)));
|
||||||
|
let tenant = permissions(&tenant);
|
||||||
|
for hold in [
|
||||||
|
Permission::SysLegalHoldGet,
|
||||||
|
Permission::SysLegalHoldCreate,
|
||||||
|
Permission::SysLegalHoldUpdate,
|
||||||
|
Permission::SysLegalHoldExport,
|
||||||
|
] {
|
||||||
|
assert!(officer.contains(&hold));
|
||||||
|
assert!(!tenant.contains(&hold));
|
||||||
|
}
|
||||||
|
for both in [
|
||||||
|
Permission::SysComplianceGet,
|
||||||
|
Permission::SysAuditGet,
|
||||||
|
Permission::SysAccountGet,
|
||||||
|
] {
|
||||||
|
assert!(officer.contains(&both) && tenant.contains(&both));
|
||||||
|
}
|
||||||
|
assert!(!officer.contains(&Permission::SysAuditSettingsUpdate));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn records_are_per_place() {
|
||||||
|
let ValueClass::Any(server) = created_key(None) else {
|
||||||
|
panic!()
|
||||||
|
};
|
||||||
|
let ValueClass::Any(a) = created_key(Some(Id::from(1u64))) else {
|
||||||
|
panic!()
|
||||||
|
};
|
||||||
|
let ValueClass::Any(b) = created_key(Some(Id::from(2u64))) else {
|
||||||
|
panic!()
|
||||||
|
};
|
||||||
|
assert_eq!(server.key, b"Pc");
|
||||||
|
assert_ne!(a.key, b.key);
|
||||||
|
assert!(a.key.starts_with(b"Pc"));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -14,7 +14,7 @@ use aws_lc_rs::{
|
|||||||
use registry::{
|
use registry::{
|
||||||
schema::{
|
schema::{
|
||||||
enums::*,
|
enums::*,
|
||||||
prelude::{ObjectType, SocketAddr},
|
prelude::{Object, ObjectType, SocketAddr},
|
||||||
structs::*,
|
structs::*,
|
||||||
},
|
},
|
||||||
types::{duration::Duration, error::Error, list::List, map::Map},
|
types::{duration::Duration, error::Error, list::List, map::Map},
|
||||||
@@ -388,6 +388,45 @@ async fn insert_safe_defaults(bp: &mut Bootstrap) -> trc::Result<()> {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// inbuxa: personal-data catalog, defaults D2, D3, D4 and D6 (settled
|
||||||
|
// 2026-09-28): privacy-leaning values, for new installs only. A server
|
||||||
|
// with roles is not new, and keeps its settings whether saved or left at
|
||||||
|
// the default. Each singleton is read, changed and written back whole, so
|
||||||
|
// anything already in it stays.
|
||||||
|
#[cfg(not(feature = "test_mode"))]
|
||||||
|
if bp.registry.count_object(ObjectType::Role).await? == 0 {
|
||||||
|
let mut security = bp.setting_infallible::<Security>().await;
|
||||||
|
let mut classifier = bp.setting_infallible::<SpamClassifier>().await;
|
||||||
|
let mut pyzor = bp.setting_infallible::<SpamPyzor>().await;
|
||||||
|
let mut retention = bp.setting_infallible::<DataRetention>().await;
|
||||||
|
new_install_privacy_defaults(&mut security, &mut classifier, &mut pyzor, &mut retention);
|
||||||
|
for object in [
|
||||||
|
Object::from(security),
|
||||||
|
classifier.into(),
|
||||||
|
pyzor.into(),
|
||||||
|
retention.into(),
|
||||||
|
] {
|
||||||
|
bp.registry.write(RegistryWrite::insert(&object)).await?;
|
||||||
|
}
|
||||||
|
|
||||||
|
// D5: the blocklist sent hashed email addresses starts off; the
|
||||||
|
// rules load later, from a task, which acts on this note
|
||||||
|
super::spam_rules::mark_new_install(&bp.data_store).await?;
|
||||||
|
|
||||||
|
// D1: rotated log files are kept 30 days (a fork-owned setting,
|
||||||
|
// since x:TracerLog is also stored inside x:Bootstrap)
|
||||||
|
use inbuxa_features::security::log_files;
|
||||||
|
if !log_files::is_set(&bp.data_store).await? {
|
||||||
|
log_files::set(
|
||||||
|
&bp.data_store,
|
||||||
|
&log_files::LogSettings {
|
||||||
|
keep_for_days: Some(log_files::NEW_INSTALL_KEEP_DAYS),
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await?;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if bp.registry.count_object(ObjectType::Role).await? == 0 {
|
if bp.registry.count_object(ObjectType::Role).await? == 0 {
|
||||||
let permissions = DefaultPermissions::default();
|
let permissions = DefaultPermissions::default();
|
||||||
let mut role_ids = Vec::with_capacity(4);
|
let mut role_ids = Vec::with_capacity(4);
|
||||||
@@ -447,6 +486,8 @@ async fn insert_safe_defaults(bp: &mut Bootstrap) -> trc::Result<()> {
|
|||||||
|
|
||||||
// inbuxa: administrator roles stored before a permission existed get it once
|
// inbuxa: administrator roles stored before a permission existed get it once
|
||||||
super::granted_permissions::grant_new_admin_permissions(bp).await?;
|
super::granted_permissions::grant_new_admin_permissions(bp).await?;
|
||||||
|
// inbuxa: personal-data catalog: the compliance roles, once per server
|
||||||
|
super::compliance_roles::ensure_compliance_roles(&bp.registry, &bp.data_store).await?;
|
||||||
|
|
||||||
if bp
|
if bp
|
||||||
.registry
|
.registry
|
||||||
@@ -535,8 +576,8 @@ async fn insert_safe_defaults(bp: &mut Bootstrap) -> trc::Result<()> {
|
|||||||
|
|
||||||
// inbuxa: rules are always to hand, since a copy ships with the server
|
// inbuxa: rules are always to hand, since a copy ships with the server
|
||||||
// (spam_rules). They load on first boot, and again when the bundled
|
// (spam_rules). They load on first boot, and again when the bundled
|
||||||
// version differs from the one last loaded, which only adds what's
|
// rules differ from the ones last loaded: new tags and rules, fixes to
|
||||||
// missing: new tags and rules, never a changed score.
|
// rules nobody edited, never a changed score or an admin's edit.
|
||||||
let rules_url = super::spam_rules::rules_url(
|
let rules_url = super::spam_rules::rules_url(
|
||||||
bp.registry
|
bp.registry
|
||||||
.object::<SpamSettings>(Id::singleton())
|
.object::<SpamSettings>(Id::singleton())
|
||||||
@@ -547,7 +588,7 @@ async fn insert_safe_defaults(bp: &mut Bootstrap) -> trc::Result<()> {
|
|||||||
&& super::spam_rules::applied_version(&bp.data_store)
|
&& super::spam_rules::applied_version(&bp.data_store)
|
||||||
.await?
|
.await?
|
||||||
.as_deref()
|
.as_deref()
|
||||||
!= Some(super::spam_rules::BUNDLED_SPAM_RULES_VERSION);
|
!= Some(super::spam_rules::BUNDLED_SPAM_RULES_APPLIED);
|
||||||
if bp.registry.count_object(ObjectType::SpamRule).await? == 0 || bundled_is_new {
|
if bp.registry.count_object(ObjectType::SpamRule).await? == 0 || bundled_is_new {
|
||||||
let mut batch = BatchBuilder::new();
|
let mut batch = BatchBuilder::new();
|
||||||
batch.schedule_task(Task::SpamFilterMaintenance(TaskSpamFilterMaintenance {
|
batch.schedule_task(Task::SpamFilterMaintenance(TaskSpamFilterMaintenance {
|
||||||
@@ -560,3 +601,81 @@ async fn insert_safe_defaults(bp: &mut Bootstrap) -> trc::Result<()> {
|
|||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// inbuxa: the new-install values of defaults D2, D3, D4 and D6 from the
|
||||||
|
/// personal-data catalog spec. Automatic IP bans expire after 30 days instead
|
||||||
|
/// of never; spam training samples are kept 90 days instead of 180; Pyzor,
|
||||||
|
/// which sends a digest of each message's text to a public server, is off;
|
||||||
|
/// delivery history is kept 14 days instead of 30.
|
||||||
|
fn new_install_privacy_defaults(
|
||||||
|
security: &mut Security,
|
||||||
|
classifier: &mut SpamClassifier,
|
||||||
|
pyzor: &mut SpamPyzor,
|
||||||
|
retention: &mut DataRetention,
|
||||||
|
) {
|
||||||
|
const DAY: u64 = 24 * 60 * 60 * 1000;
|
||||||
|
let ban_period = Some(Duration::from_millis(30 * DAY));
|
||||||
|
security.auth_ban_period = ban_period;
|
||||||
|
security.abuse_ban_period = ban_period;
|
||||||
|
security.loiter_ban_period = ban_period;
|
||||||
|
security.scan_ban_period = ban_period;
|
||||||
|
classifier.hold_samples_for = Duration::from_millis(90 * DAY);
|
||||||
|
pyzor.enable = false;
|
||||||
|
retention.hold_traces_for = Some(Duration::from_millis(14 * DAY));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
const DAY: u64 = 24 * 60 * 60 * 1000;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn new_installs_get_the_privacy_defaults() {
|
||||||
|
let (mut security, mut classifier, mut pyzor, mut retention) = (
|
||||||
|
Security::default(),
|
||||||
|
SpamClassifier::default(),
|
||||||
|
SpamPyzor::default(),
|
||||||
|
DataRetention::default(),
|
||||||
|
);
|
||||||
|
// What an install gets without them: bans that never lift, 180-day
|
||||||
|
// samples, Pyzor on, 30-day traces.
|
||||||
|
assert_eq!(security.auth_ban_period, None);
|
||||||
|
assert!(pyzor.enable);
|
||||||
|
|
||||||
|
new_install_privacy_defaults(&mut security, &mut classifier, &mut pyzor, &mut retention);
|
||||||
|
|
||||||
|
for period in [
|
||||||
|
security.auth_ban_period,
|
||||||
|
security.abuse_ban_period,
|
||||||
|
security.loiter_ban_period,
|
||||||
|
security.scan_ban_period,
|
||||||
|
] {
|
||||||
|
assert_eq!(period.map(|p| p.into_inner().as_millis() as u64), Some(30 * DAY));
|
||||||
|
}
|
||||||
|
assert_eq!(classifier.hold_samples_for.into_inner().as_millis() as u64, 90 * DAY);
|
||||||
|
assert!(!pyzor.enable);
|
||||||
|
assert_eq!(
|
||||||
|
retention.hold_traces_for.map(|p| p.into_inner().as_millis() as u64),
|
||||||
|
Some(14 * DAY)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn everything_else_in_the_settings_stays() {
|
||||||
|
let mut retention = DataRetention {
|
||||||
|
archive_deleted_items_for: Some(Duration::from_millis(7 * DAY)),
|
||||||
|
..Default::default()
|
||||||
|
};
|
||||||
|
let before = retention.clone();
|
||||||
|
new_install_privacy_defaults(
|
||||||
|
&mut Security::default(),
|
||||||
|
&mut SpamClassifier::default(),
|
||||||
|
&mut SpamPyzor::default(),
|
||||||
|
&mut retention,
|
||||||
|
);
|
||||||
|
assert_eq!(retention.archive_deleted_items_for, before.archive_deleted_items_for);
|
||||||
|
assert_eq!(retention.hold_metrics_for, before.hold_metrics_for);
|
||||||
|
assert_eq!(retention.expunge_trash_after, before.expunge_trash_after);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
@@ -14,7 +14,7 @@
|
|||||||
//! application names another;
|
//! application names another;
|
||||||
//! - INBUXA Admin hosted elsewhere, as `inbuxa-admin`, when `INBUXA_ADMIN_URL`
|
//! - INBUXA Admin hosted elsewhere, as `inbuxa-admin`, when `INBUXA_ADMIN_URL`
|
||||||
//! is set;
|
//! is set;
|
||||||
//! - ihasmail-inbuxa, as the confidential client `ihasmail-inbuxa`, when
|
//! - inbuxa-webmail, as the confidential client `ihasmail-inbuxa`, when
|
||||||
//! `INBUXA_WEBMAIL_URL` and `INBUXA_WEBMAIL_CLIENT_SECRET` are set.
|
//! `INBUXA_WEBMAIL_URL` and `INBUXA_WEBMAIL_CLIENT_SECRET` are set.
|
||||||
//!
|
//!
|
||||||
//! inbuxa: the environment variables stand in for `x:FrontEnds` (C-4) until
|
//! inbuxa: the environment variables stand in for `x:FrontEnds` (C-4) until
|
||||||
@@ -22,7 +22,7 @@
|
|||||||
//! it instead.
|
//! it instead.
|
||||||
//!
|
//!
|
||||||
//! A missing client is created. An existing one gains any redirect URI it
|
//! A missing client is created. An existing one gains any redirect URI it
|
||||||
//! lacks and, for ihasmail-inbuxa, the configured secret; nothing an operator
|
//! lacks and, for inbuxa-webmail, the configured secret; nothing an operator
|
||||||
//! added is removed.
|
//! added is removed.
|
||||||
|
|
||||||
use directory::core::secret::{hash_secret, verify_secret_hash};
|
use directory::core::secret::{hash_secret, verify_secret_hash};
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
@@ -29,8 +29,11 @@ use trc::AddContext;
|
|||||||
use types::id::Id;
|
use types::id::Id;
|
||||||
|
|
||||||
/// Granted to the default administrator roles: "Explain this"
|
/// Granted to the default administrator roles: "Explain this"
|
||||||
/// (ai-explain spec, EX-4: superuser by default), and the audit log
|
/// (ai-explain spec, EX-4: superuser by default), the audit log, account
|
||||||
/// (audit-hold-lock spec, AU-9).
|
/// locks and legal holds (audit-hold-lock spec, AU-9, AL-12, LH-13), and
|
||||||
|
/// the data inventory (personal-data catalog spec), accepting security
|
||||||
|
/// to-do items (security to-do list spec), and the deliverability check
|
||||||
|
/// (deliverability spec).
|
||||||
const ADMIN_GRANTS: &[Permission] = &[
|
const ADMIN_GRANTS: &[Permission] = &[
|
||||||
Permission::SysAiExplain,
|
Permission::SysAiExplain,
|
||||||
Permission::SysAuditGet,
|
Permission::SysAuditGet,
|
||||||
@@ -40,11 +43,42 @@ const ADMIN_GRANTS: &[Permission] = &[
|
|||||||
Permission::SysAccountLockCreate,
|
Permission::SysAccountLockCreate,
|
||||||
Permission::SysAccountLockUpdate,
|
Permission::SysAccountLockUpdate,
|
||||||
Permission::SysAccountLockDestroy,
|
Permission::SysAccountLockDestroy,
|
||||||
|
Permission::SysLegalHoldGet,
|
||||||
|
Permission::SysLegalHoldCreate,
|
||||||
|
Permission::SysLegalHoldUpdate,
|
||||||
|
Permission::SysLegalHoldExport,
|
||||||
|
Permission::SysComplianceGet,
|
||||||
|
Permission::SysMailRuleGet,
|
||||||
|
Permission::SysMailRuleUpdate,
|
||||||
|
Permission::SysDlpPolicyGet,
|
||||||
|
Permission::SysDlpPolicyUpdate,
|
||||||
|
Permission::SysDlpReviewGet,
|
||||||
|
Permission::SysDlpReviewUpdate,
|
||||||
|
Permission::SysJournalGet,
|
||||||
|
Permission::SysJournalUpdate,
|
||||||
|
Permission::SysSecurityAccept,
|
||||||
|
Permission::SysDeliverabilityGet,
|
||||||
|
Permission::SysDeliverabilityUpdate,
|
||||||
|
Permission::SysDeliverabilityCheck,
|
||||||
|
];
|
||||||
|
|
||||||
|
/// Granted to the server-level Compliance Officer role once it exists:
|
||||||
|
/// seeing DLP rules and reviewing held mail (dlp-and-mail-flow-rules spec,
|
||||||
|
/// §2.8, settled answer 4). A new install's role has them from the start.
|
||||||
|
const OFFICER_GRANTS: &[Permission] = &[
|
||||||
|
Permission::SysDlpPolicyGet,
|
||||||
|
Permission::SysDlpReviewGet,
|
||||||
|
Permission::SysDlpReviewUpdate,
|
||||||
|
// journaling spec, JR-18: see journals, search and export them
|
||||||
|
Permission::SysJournalGet,
|
||||||
|
Permission::SysJournalSearch,
|
||||||
|
Permission::SysJournalExport,
|
||||||
];
|
];
|
||||||
|
|
||||||
/// Granted to the default tenant administrator roles: reading and exporting
|
/// Granted to the default tenant administrator roles: reading and exporting
|
||||||
/// the tenant's audit log (AU-9), and locking and delegating its accounts
|
/// the tenant's audit log (AU-9), locking and delegating its accounts
|
||||||
/// (AL-12).
|
/// (AL-12), the tenant's slice of the data inventory, and its own domains'
|
||||||
|
/// deliverability findings (DL-20).
|
||||||
const TENANT_GRANTS: &[Permission] = &[
|
const TENANT_GRANTS: &[Permission] = &[
|
||||||
Permission::SysAuditGet,
|
Permission::SysAuditGet,
|
||||||
Permission::SysAuditExport,
|
Permission::SysAuditExport,
|
||||||
@@ -52,19 +86,24 @@ const TENANT_GRANTS: &[Permission] = &[
|
|||||||
Permission::SysAccountLockCreate,
|
Permission::SysAccountLockCreate,
|
||||||
Permission::SysAccountLockUpdate,
|
Permission::SysAccountLockUpdate,
|
||||||
Permission::SysAccountLockDestroy,
|
Permission::SysAccountLockDestroy,
|
||||||
|
Permission::SysComplianceGet,
|
||||||
|
Permission::SysDeliverabilityGet,
|
||||||
];
|
];
|
||||||
|
|
||||||
#[derive(Clone, Copy, PartialEq, Eq)]
|
#[derive(Clone, Copy, PartialEq, Eq)]
|
||||||
enum Audience {
|
enum Audience {
|
||||||
Admin,
|
Admin,
|
||||||
Tenant,
|
Tenant,
|
||||||
|
Officer,
|
||||||
}
|
}
|
||||||
|
|
||||||
fn granted_key(permission: Permission, audience: Audience) -> ValueClass {
|
fn granted_key(permission: Permission, audience: Audience) -> ValueClass {
|
||||||
let mut key = b"Pg".to_vec();
|
let mut key = b"Pg".to_vec();
|
||||||
// Admin grants keep the key they were first recorded under
|
// Admin grants keep the key they were first recorded under
|
||||||
if audience == Audience::Tenant {
|
match audience {
|
||||||
key.extend_from_slice(b"tenant:");
|
Audience::Admin => {}
|
||||||
|
Audience::Tenant => key.extend_from_slice(b"tenant:"),
|
||||||
|
Audience::Officer => key.extend_from_slice(b"officer:"),
|
||||||
}
|
}
|
||||||
key.extend_from_slice(permission.as_str().as_bytes());
|
key.extend_from_slice(permission.as_str().as_bytes());
|
||||||
ValueClass::Any(AnyClass {
|
ValueClass::Any(AnyClass {
|
||||||
@@ -75,7 +114,8 @@ fn granted_key(permission: Permission, audience: Audience) -> ValueClass {
|
|||||||
|
|
||||||
pub(crate) async fn grant_new_admin_permissions(bp: &mut Bootstrap) -> trc::Result<()> {
|
pub(crate) async fn grant_new_admin_permissions(bp: &mut Bootstrap) -> trc::Result<()> {
|
||||||
grant(bp, Audience::Admin, ADMIN_GRANTS).await?;
|
grant(bp, Audience::Admin, ADMIN_GRANTS).await?;
|
||||||
grant(bp, Audience::Tenant, TENANT_GRANTS).await
|
grant(bp, Audience::Tenant, TENANT_GRANTS).await?;
|
||||||
|
grant(bp, Audience::Officer, OFFICER_GRANTS).await
|
||||||
}
|
}
|
||||||
|
|
||||||
async fn grant(bp: &mut Bootstrap, audience: Audience, grants: &[Permission]) -> trc::Result<()> {
|
async fn grant(bp: &mut Bootstrap, audience: Audience, grants: &[Permission]) -> trc::Result<()> {
|
||||||
@@ -94,10 +134,17 @@ async fn grant(bp: &mut Bootstrap, audience: Audience, grants: &[Permission]) ->
|
|||||||
if pending.is_empty() {
|
if pending.is_empty() {
|
||||||
return Ok(());
|
return Ok(());
|
||||||
}
|
}
|
||||||
|
// The officer role is the one the server made, if it has made it yet: a
|
||||||
|
// new install makes it after this, with the permissions already in it
|
||||||
|
let admin_roles: Vec<Id> = if audience == Audience::Officer {
|
||||||
|
super::compliance_roles::server_role(&bp.data_store)
|
||||||
|
.await?
|
||||||
|
.into_iter()
|
||||||
|
.collect()
|
||||||
|
} else {
|
||||||
// An administrator's default roles include the plain User role, which
|
// An administrator's default roles include the plain User role, which
|
||||||
// every user also holds; only roles that are the audience's alone get it
|
// every user also holds; only roles that are the audience's alone get it
|
||||||
let admin_roles: Vec<Id> = bp
|
bp.registry
|
||||||
.registry
|
|
||||||
.object::<Authentication>(Id::singleton())
|
.object::<Authentication>(Id::singleton())
|
||||||
.await?
|
.await?
|
||||||
.map(|auth| {
|
.map(|auth| {
|
||||||
@@ -111,7 +158,7 @@ async fn grant(bp: &mut Bootstrap, audience: Audience, grants: &[Permission]) ->
|
|||||||
]
|
]
|
||||||
.concat(),
|
.concat(),
|
||||||
),
|
),
|
||||||
Audience::Tenant => (
|
Audience::Tenant | Audience::Officer => (
|
||||||
auth.default_tenant_role_ids.as_slice(),
|
auth.default_tenant_role_ids.as_slice(),
|
||||||
[
|
[
|
||||||
auth.default_user_role_ids.as_slice(),
|
auth.default_user_role_ids.as_slice(),
|
||||||
@@ -126,7 +173,8 @@ async fn grant(bp: &mut Bootstrap, audience: Audience, grants: &[Permission]) ->
|
|||||||
.copied()
|
.copied()
|
||||||
.collect()
|
.collect()
|
||||||
})
|
})
|
||||||
.unwrap_or_default();
|
.unwrap_or_default()
|
||||||
|
};
|
||||||
// Fetched by id: the registry's listing doesn't reach stored roles
|
// Fetched by id: the registry's listing doesn't reach stored roles
|
||||||
for role_id in admin_roles {
|
for role_id in admin_roles {
|
||||||
let Some(stored) = bp
|
let Some(stored) = bp
|
||||||
|
|||||||
@@ -18,6 +18,7 @@ use utils::HttpLimitResponse;
|
|||||||
pub mod application;
|
pub mod application;
|
||||||
pub mod backup;
|
pub mod backup;
|
||||||
pub mod boot;
|
pub mod boot;
|
||||||
|
pub mod compliance_roles; // inbuxa: personal-data catalog, the compliance roles
|
||||||
pub mod console;
|
pub mod console;
|
||||||
pub mod defaults;
|
pub mod defaults;
|
||||||
pub mod first_party;
|
pub mod first_party;
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
@@ -12,11 +12,16 @@
|
|||||||
//! and license) and uses it whenever no other source is configured. The rules
|
//! and license) and uses it whenever no other source is configured. The rules
|
||||||
//! URL remains an operator override (`https://` or `file://`).
|
//! URL remains an operator override (`https://` or `file://`).
|
||||||
//!
|
//!
|
||||||
//! Loading rules only ever adds what's missing, never changes an existing rule
|
//! Loading rules adds what's missing and brings an existing rule up to date,
|
||||||
//! or score. They load on first boot, and again whenever the bundled version
|
//! but never touches one an admin edited: every object an update writes is
|
||||||
//! differs from the one last applied, so an upgrade brings new tags (the AI
|
//! fingerprinted, and one that no longer matches its fingerprint is kept as
|
||||||
//! classifier's `LLM_*` scores, say) to an install that already had rules.
|
//! it is. Tags (scores) are never replaced. Switching a rule on or off isn't
|
||||||
|
//! an edit, and is kept either way. They load on first boot, and again
|
||||||
|
//! whenever the bundled rules differ from the ones last applied, so an
|
||||||
|
//! upgrade brings new tags (the AI classifier's `LLM_*` scores, say) and
|
||||||
|
//! fixed rules to an install that already had rules.
|
||||||
|
|
||||||
|
use registry::{schema::prelude::ObjectType, types::EnumImpl};
|
||||||
use std::io::Read;
|
use std::io::Read;
|
||||||
use store::{
|
use store::{
|
||||||
SUBSPACE_INBUXA, Store, ValueKey,
|
SUBSPACE_INBUXA, Store, ValueKey,
|
||||||
@@ -27,13 +32,17 @@ use trc::AddContext;
|
|||||||
/// The version of spam-filter the embedded rules come from.
|
/// The version of spam-filter the embedded rules come from.
|
||||||
pub const BUNDLED_SPAM_RULES_VERSION: &str = "3.0.2";
|
pub const BUNDLED_SPAM_RULES_VERSION: &str = "3.0.2";
|
||||||
|
|
||||||
|
/// What's recorded once the bundled rules are loaded: their version, then the
|
||||||
|
/// fork's own generation of the update, so a change to how an update applies
|
||||||
|
/// runs it once more. Generation 2 fingerprints (upstream v0.16.24).
|
||||||
|
pub const BUNDLED_SPAM_RULES_APPLIED: &str = "3.0.2+2";
|
||||||
|
|
||||||
static BUNDLED_SPAM_RULES: &[u8] =
|
static BUNDLED_SPAM_RULES: &[u8] =
|
||||||
include_bytes!("../../../../resources/spam-filter/spam-filter-rules.json.gz");
|
include_bytes!("../../../../resources/spam-filter/spam-filter-rules.json.gz");
|
||||||
|
|
||||||
/// Upstream's default rules source, the value every install created before
|
/// Upstream's default rules source, the value every install created before
|
||||||
/// the rules were bundled has saved. Read only to treat it as unset.
|
/// the rules were bundled has saved. Read only to treat it as unset.
|
||||||
const LEGACY_DEFAULT_URL: &str =
|
const LEGACY_DEFAULT_URL: &str = "https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz";
|
||||||
"https://github.com/stalwartlabs/spam-filter/releases/latest/download/spam-filter-rules.json.gz";
|
|
||||||
|
|
||||||
/// The URL to fetch rules from, or `None` for the bundled rules. An empty
|
/// The URL to fetch rules from, or `None` for the bundled rules. An empty
|
||||||
/// setting and upstream's old default both mean the bundled rules.
|
/// setting and upstream's old default both mean the bundled rules.
|
||||||
@@ -57,14 +66,49 @@ fn applied_key() -> ValueClass {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
/// The bundled version last loaded into the registry, if any.
|
fn fingerprint_key(object: ObjectType, id: u64) -> ValueClass {
|
||||||
|
let mut key = b"Sf".to_vec();
|
||||||
|
key.extend_from_slice(object.as_str().as_bytes());
|
||||||
|
key.push(0);
|
||||||
|
key.extend_from_slice(&id.to_be_bytes());
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace: SUBSPACE_INBUXA,
|
||||||
|
key,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The fingerprint of what a rules update last wrote to this object, if one
|
||||||
|
/// did.
|
||||||
|
pub async fn fingerprint(data: &Store, object: ObjectType, id: u64) -> trc::Result<Option<String>> {
|
||||||
|
data.get_value::<String>(ValueKey::from(fingerprint_key(object, id)))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Records the fingerprint of what a rules update wrote to this object.
|
||||||
|
pub async fn set_fingerprint(
|
||||||
|
data: &Store,
|
||||||
|
object: ObjectType,
|
||||||
|
id: u64,
|
||||||
|
fingerprint: &str,
|
||||||
|
) -> trc::Result<()> {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.set(fingerprint_key(object, id), fingerprint.as_bytes().to_vec());
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())
|
||||||
|
.map(|_| ())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The bundled rules last loaded into the registry, if any
|
||||||
|
/// ([`BUNDLED_SPAM_RULES_APPLIED`]'s form).
|
||||||
pub async fn applied_version(data: &Store) -> trc::Result<Option<String>> {
|
pub async fn applied_version(data: &Store) -> trc::Result<Option<String>> {
|
||||||
data.get_value::<String>(ValueKey::from(applied_key()))
|
data.get_value::<String>(ValueKey::from(applied_key()))
|
||||||
.await
|
.await
|
||||||
.caused_by(trc::location!())
|
.caused_by(trc::location!())
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Records that the bundled rules of this version have been loaded.
|
/// Records that the bundled rules have been loaded.
|
||||||
pub async fn set_applied_version(data: &Store, version: &str) -> trc::Result<()> {
|
pub async fn set_applied_version(data: &Store, version: &str) -> trc::Result<()> {
|
||||||
let mut batch = BatchBuilder::new();
|
let mut batch = BatchBuilder::new();
|
||||||
batch.set(applied_key(), version.as_bytes().to_vec());
|
batch.set(applied_key(), version.as_bytes().to_vec());
|
||||||
@@ -74,6 +118,78 @@ pub async fn set_applied_version(data: &Store, version: &str) -> trc::Result<()>
|
|||||||
.map(|_| ())
|
.map(|_| ())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// The blocklists a new install starts with switched off (personal-data
|
||||||
|
/// catalog spec, default D5, settled 2026-09-28): the one that is sent a
|
||||||
|
/// hash of every email address it's asked about.
|
||||||
|
pub const NEW_INSTALL_OFF: &[&str] = &["STWT_MSBL_EBL_EMAIL"];
|
||||||
|
|
||||||
|
fn new_install_key() -> ValueClass {
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace: SUBSPACE_INBUXA,
|
||||||
|
key: b"Sn".to_vec(),
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Notes, on a new install's first boot, that [`NEW_INSTALL_OFF`] is to be
|
||||||
|
/// switched off once the rules are in: they load later, from a task.
|
||||||
|
pub async fn mark_new_install(data: &Store) -> trc::Result<()> {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.set(new_install_key(), b"D5".to_vec());
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())
|
||||||
|
.map(|_| ())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// After rules load: on a new install, switches [`NEW_INSTALL_OFF`] off and
|
||||||
|
/// forgets the note, so it happens once. Returns whether anything changed.
|
||||||
|
/// An existing server has no note, and keeps every blocklist as it is.
|
||||||
|
pub async fn apply_new_install(
|
||||||
|
registry: &store::RegistryStore,
|
||||||
|
data: &Store,
|
||||||
|
) -> trc::Result<bool> {
|
||||||
|
use registry::schema::{prelude::Object, structs::SpamDnsblServer};
|
||||||
|
use store::registry::write::RegistryWrite;
|
||||||
|
|
||||||
|
if data
|
||||||
|
.get_value::<String>(ValueKey::from(new_install_key()))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
.is_none()
|
||||||
|
{
|
||||||
|
return Ok(false);
|
||||||
|
}
|
||||||
|
let mut changed = false;
|
||||||
|
for server in registry.list::<SpamDnsblServer>().await? {
|
||||||
|
let mut updated = server.object.clone();
|
||||||
|
let SpamDnsblServer::Email(email) = &mut updated else {
|
||||||
|
continue;
|
||||||
|
};
|
||||||
|
if !NEW_INSTALL_OFF.contains(&email.name.as_str()) || !email.enable {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
email.enable = false;
|
||||||
|
let old = Object {
|
||||||
|
inner: server.object.into(),
|
||||||
|
revision: server.revision,
|
||||||
|
};
|
||||||
|
let new = Object {
|
||||||
|
inner: updated.into(),
|
||||||
|
revision: server.revision,
|
||||||
|
};
|
||||||
|
registry
|
||||||
|
.write(RegistryWrite::update(types::id::Id::from(server.id.id()), &new, &old))
|
||||||
|
.await?;
|
||||||
|
changed = true;
|
||||||
|
}
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.clear(new_install_key());
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
Ok(changed)
|
||||||
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
mod tests {
|
mod tests {
|
||||||
use super::*;
|
use super::*;
|
||||||
@@ -90,6 +206,15 @@ mod tests {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn applied_marker_names_the_bundled_version() {
|
||||||
|
assert!(
|
||||||
|
BUNDLED_SPAM_RULES_APPLIED
|
||||||
|
.strip_prefix(BUNDLED_SPAM_RULES_VERSION)
|
||||||
|
.is_some_and(|generation| generation.starts_with('+'))
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn bundled_rules_parse_and_score_the_ai_tags() {
|
fn bundled_rules_parse_and_score_the_ai_tags() {
|
||||||
let rules: serde_json::Value = serde_json::from_slice(&bundled_rules().unwrap()).unwrap();
|
let rules: serde_json::Value = serde_json::from_slice(&bundled_rules().unwrap()).unwrap();
|
||||||
|
|||||||
@@ -1,7 +1,10 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
|
* SPDX-FileCopyrightText: 2020 Stalwart Labs LLC <hello@stalw.art>
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
* SPDX-License-Identifier: AGPL-3.0-only OR LicenseRef-SEL
|
||||||
|
*
|
||||||
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::{
|
use crate::{
|
||||||
@@ -72,11 +75,22 @@ impl Server {
|
|||||||
.acme_certificate_renewal_due(&domains, renew_before, now())
|
.acme_certificate_renewal_due(&domains, renew_before, now())
|
||||||
.await?
|
.await?
|
||||||
{
|
{
|
||||||
return Err(AcmeError::NotDue(format!(
|
// INBUXA: a certificate already covering these names (one stored by
|
||||||
"Certificate for domain {} is still valid; renewal is not due until {}",
|
// hand before the domain was switched to automatic, say) isn't a
|
||||||
domain.name,
|
// failure: schedule the renewal for when it falls due. Returning
|
||||||
UTCDateTime::from_timestamp(renew_at as i64)
|
// NotDue here ended the task for good, and nothing renewed the
|
||||||
)));
|
// certificate before it expired.
|
||||||
|
trc::event!(
|
||||||
|
Acme(trc::AcmeEvent::RenewBackoff),
|
||||||
|
Domain = domain.name.clone(),
|
||||||
|
Hostname = domains.as_slice(),
|
||||||
|
Details = "A valid certificate already covers these names",
|
||||||
|
NextRetry = trc::Value::Timestamp(renew_at),
|
||||||
|
);
|
||||||
|
return Ok(vec![Task::AcmeRenewal(TaskDomainManagement {
|
||||||
|
domain_id,
|
||||||
|
status: TaskStatus::at(renew_at as i64),
|
||||||
|
})]);
|
||||||
}
|
}
|
||||||
|
|
||||||
let dns_parameters = match &domain.dns_management {
|
let dns_parameters = match &domain.dns_management {
|
||||||
|
|||||||
@@ -6,12 +6,13 @@
|
|||||||
* Modified by Coffey Labs in 2026 for INBUXA.
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::{Server, manager::application::Resource, network::legacy::is_legacy_service};
|
use crate::{Server, manager::application::Resource};
|
||||||
use quick_xml::Reader;
|
use quick_xml::Reader;
|
||||||
use quick_xml::XmlVersion;
|
use quick_xml::XmlVersion;
|
||||||
use quick_xml::events::Event;
|
use quick_xml::events::Event;
|
||||||
use registry::schema::enums::ServiceProtocol;
|
use registry::schema::{enums::ServiceProtocol, structs::Service};
|
||||||
use std::fmt::Write;
|
use std::{borrow::Cow, fmt::Write};
|
||||||
|
use utils::map::vec_map::VecMap;
|
||||||
|
|
||||||
impl Server {
|
impl Server {
|
||||||
pub async fn handle_autodiscover_request(
|
pub async fn handle_autodiscover_request(
|
||||||
@@ -19,15 +20,84 @@ impl Server {
|
|||||||
body: Option<Vec<u8>>,
|
body: Option<Vec<u8>>,
|
||||||
) -> trc::Result<Resource<Vec<u8>>> {
|
) -> trc::Result<Resource<Vec<u8>>> {
|
||||||
// Obtain parameters
|
// Obtain parameters
|
||||||
let emailaddress = parse_autodiscover_request(body.as_deref().unwrap_or_default())
|
let request =
|
||||||
.map_err(|err| {
|
parse_autodiscover_request(body.as_deref().unwrap_or_default()).map_err(|err| {
|
||||||
trc::ResourceEvent::BadParameters
|
trc::ResourceEvent::BadParameters
|
||||||
.into_err()
|
.into_err()
|
||||||
.details("Failed to parse autodiscover request")
|
.details("Failed to parse autodiscover request")
|
||||||
.ctx(trc::Key::Reason, err)
|
.ctx(trc::Key::Reason, err)
|
||||||
})?;
|
})?;
|
||||||
let default_host = &self.core.network.server_name;
|
// inbuxa: legacy-protocols LP-7, LP-14a
|
||||||
|
let legacy_off = match request.email.rsplit_once('@') {
|
||||||
|
Some((_, domain)) => self.legacy_off_for(domain).await?,
|
||||||
|
None => self.legacy_off_for("").await?,
|
||||||
|
};
|
||||||
|
|
||||||
|
let response = match request.response_schema {
|
||||||
|
ResponseSchema::Outlook => build_autodiscover_response(
|
||||||
|
&request.email,
|
||||||
|
&self.core.network.server_name,
|
||||||
|
&self.core.network.info.services,
|
||||||
|
|protocol| legacy_off.service(protocol),
|
||||||
|
)
|
||||||
|
.into_bytes(),
|
||||||
|
ResponseSchema::Unsupported => PROVIDER_NOT_AVAILABLE_RESPONSE.as_bytes().to_vec(),
|
||||||
|
};
|
||||||
|
|
||||||
|
Ok(Resource::new("application/xml; charset=utf-8", response))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const OUTLOOK_RESPONSE_SCHEMA: &str =
|
||||||
|
"http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a";
|
||||||
|
|
||||||
|
const PROVIDER_NOT_AVAILABLE_RESPONSE: &str = concat!(
|
||||||
|
"<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n",
|
||||||
|
"<Autodiscover xmlns=\"http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006\">\n",
|
||||||
|
"\t<Response>\n",
|
||||||
|
"\t\t<Error>\n",
|
||||||
|
"\t\t\t<ErrorCode>601</ErrorCode>\n",
|
||||||
|
"\t\t\t<Message>Provider is not available</Message>\n",
|
||||||
|
"\t\t\t<DebugData />\n",
|
||||||
|
"\t\t</Error>\n",
|
||||||
|
"\t</Response>\n",
|
||||||
|
"</Autodiscover>\n",
|
||||||
|
);
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||||
|
enum ResponseSchema {
|
||||||
|
Outlook,
|
||||||
|
Unsupported,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl ResponseSchema {
|
||||||
|
fn parse(value: &str) -> Self {
|
||||||
|
if value.trim().eq_ignore_ascii_case(OUTLOOK_RESPONSE_SCHEMA) {
|
||||||
|
ResponseSchema::Outlook
|
||||||
|
} else {
|
||||||
|
ResponseSchema::Unsupported
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, PartialEq, Eq)]
|
||||||
|
struct AutodiscoverRequest {
|
||||||
|
email: String,
|
||||||
|
response_schema: ResponseSchema,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Clone, Copy)]
|
||||||
|
enum RequestField {
|
||||||
|
EmailAddress,
|
||||||
|
ResponseSchema,
|
||||||
|
}
|
||||||
|
|
||||||
|
fn build_autodiscover_response(
|
||||||
|
emailaddress: &str,
|
||||||
|
default_host: &str,
|
||||||
|
services: &VecMap<ServiceProtocol, Service>,
|
||||||
|
switched_off: impl Fn(&ServiceProtocol) -> bool,
|
||||||
|
) -> String {
|
||||||
// Build XML response
|
// Build XML response
|
||||||
let mut config = String::with_capacity(1024);
|
let mut config = String::with_capacity(1024);
|
||||||
let _ = writeln!(&mut config, "<?xml version=\"1.0\" encoding=\"UTF-8\"?>");
|
let _ = writeln!(&mut config, "<?xml version=\"1.0\" encoding=\"UTF-8\"?>");
|
||||||
@@ -57,24 +127,20 @@ impl Server {
|
|||||||
let _ = writeln!(&mut config, "\t\t<Account>");
|
let _ = writeln!(&mut config, "\t\t<Account>");
|
||||||
let _ = writeln!(&mut config, "\t\t\t<AccountType>email</AccountType>");
|
let _ = writeln!(&mut config, "\t\t\t<AccountType>email</AccountType>");
|
||||||
let _ = writeln!(&mut config, "\t\t\t<Action>settings</Action>");
|
let _ = writeln!(&mut config, "\t\t\t<Action>settings</Action>");
|
||||||
// inbuxa: legacy-protocols LP-7, LP-14a
|
for (protocol, service) in services {
|
||||||
let legacy_off = match emailaddress.rsplit_once('@') {
|
if switched_off(protocol) {
|
||||||
Some((_, domain)) => self.legacy_protocols_off_for(domain).await?,
|
|
||||||
None => self.legacy_protocols_off_for("").await?,
|
|
||||||
};
|
|
||||||
for (protocol, service) in &self.core.network.info.services {
|
|
||||||
if legacy_off && is_legacy_service(protocol) {
|
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
let (protocol, ports) = match protocol {
|
let (protocol, ports) = match protocol {
|
||||||
ServiceProtocol::Imap => ("IMAP", [143, 993]),
|
ServiceProtocol::Imap => ("IMAP", [(993, true), (143, false)]),
|
||||||
ServiceProtocol::Pop3 => ("POP3", [110, 995]),
|
ServiceProtocol::Pop3 => ("POP3", [(995, true), (110, false)]),
|
||||||
ServiceProtocol::Smtp => ("SMTP", [587, 465]),
|
ServiceProtocol::Smtp => ("SMTP", [(465, true), (587, false)]),
|
||||||
_ => continue,
|
_ => continue,
|
||||||
};
|
};
|
||||||
|
|
||||||
for (is_tls, port) in ports.into_iter().enumerate() {
|
// Implicit TLS is listed first so that it is preferred (RFC 8314)
|
||||||
if is_tls == 1 || service.cleartext {
|
for (port, is_tls) in ports {
|
||||||
|
if is_tls || service.cleartext {
|
||||||
let server_name = service.hostname.as_deref().unwrap_or(default_host);
|
let server_name = service.hostname.as_deref().unwrap_or(default_host);
|
||||||
let _ = writeln!(&mut config, "\t\t\t<Protocol>");
|
let _ = writeln!(&mut config, "\t\t\t<Protocol>");
|
||||||
let _ = writeln!(&mut config, "\t\t\t\t<Type>{protocol}</Type>",);
|
let _ = writeln!(&mut config, "\t\t\t\t<Type>{protocol}</Type>",);
|
||||||
@@ -84,14 +150,13 @@ impl Server {
|
|||||||
let _ = writeln!(&mut config, "\t\t\t\t<AuthRequired>on</AuthRequired>");
|
let _ = writeln!(&mut config, "\t\t\t\t<AuthRequired>on</AuthRequired>");
|
||||||
let _ = writeln!(&mut config, "\t\t\t\t<DirectoryPort>0</DirectoryPort>");
|
let _ = writeln!(&mut config, "\t\t\t\t<DirectoryPort>0</DirectoryPort>");
|
||||||
let _ = writeln!(&mut config, "\t\t\t\t<ReferralPort>0</ReferralPort>");
|
let _ = writeln!(&mut config, "\t\t\t\t<ReferralPort>0</ReferralPort>");
|
||||||
let _ = writeln!(
|
let (ssl, encryption) = if is_tls {
|
||||||
&mut config,
|
("on", "SSL")
|
||||||
"\t\t\t\t<SSL>{}</SSL>",
|
} else {
|
||||||
if is_tls == 1 { "on" } else { "off" }
|
("off", "TLS")
|
||||||
);
|
};
|
||||||
if is_tls == 1 {
|
let _ = writeln!(&mut config, "\t\t\t\t<SSL>{ssl}</SSL>");
|
||||||
let _ = writeln!(&mut config, "\t\t\t\t<Encryption>TLS</Encryption>");
|
let _ = writeln!(&mut config, "\t\t\t\t<Encryption>{encryption}</Encryption>");
|
||||||
}
|
|
||||||
let _ = writeln!(&mut config, "\t\t\t\t<SPA>off</SPA>");
|
let _ = writeln!(&mut config, "\t\t\t\t<SPA>off</SPA>");
|
||||||
let _ = writeln!(&mut config, "\t\t\t</Protocol>");
|
let _ = writeln!(&mut config, "\t\t\t</Protocol>");
|
||||||
}
|
}
|
||||||
@@ -102,14 +167,10 @@ impl Server {
|
|||||||
let _ = writeln!(&mut config, "\t</Response>");
|
let _ = writeln!(&mut config, "\t</Response>");
|
||||||
let _ = writeln!(&mut config, "</Autodiscover>");
|
let _ = writeln!(&mut config, "</Autodiscover>");
|
||||||
|
|
||||||
Ok(Resource::new(
|
config
|
||||||
"application/xml; charset=utf-8",
|
|
||||||
config.into_bytes(),
|
|
||||||
))
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
fn parse_autodiscover_request(bytes: &[u8]) -> Result<String, String> {
|
fn parse_autodiscover_request(bytes: &[u8]) -> Result<AutodiscoverRequest, String> {
|
||||||
if bytes.is_empty() {
|
if bytes.is_empty() {
|
||||||
return Err("Empty request body".to_string());
|
return Err("Empty request body".to_string());
|
||||||
}
|
}
|
||||||
@@ -117,8 +178,9 @@ fn parse_autodiscover_request(bytes: &[u8]) -> Result<String, String> {
|
|||||||
let mut reader = Reader::from_reader(bytes);
|
let mut reader = Reader::from_reader(bytes);
|
||||||
reader.config_mut().trim_text(true);
|
reader.config_mut().trim_text(true);
|
||||||
let mut buf = Vec::with_capacity(128);
|
let mut buf = Vec::with_capacity(128);
|
||||||
|
let mut value_buf = Vec::with_capacity(128);
|
||||||
|
|
||||||
'outer: for tag_name in ["Autodiscover", "Request", "EMailAddress"] {
|
'outer: for tag_name in ["Autodiscover", "Request"] {
|
||||||
loop {
|
loop {
|
||||||
match reader.read_event_into(&mut buf) {
|
match reader.read_event_into(&mut buf) {
|
||||||
Ok(Event::Start(e)) => {
|
Ok(Event::Start(e)) => {
|
||||||
@@ -128,30 +190,6 @@ fn parse_autodiscover_request(bytes: &[u8]) -> Result<String, String> {
|
|||||||
.eq_ignore_ascii_case(found_tag_name.as_ref())
|
.eq_ignore_ascii_case(found_tag_name.as_ref())
|
||||||
{
|
{
|
||||||
continue 'outer;
|
continue 'outer;
|
||||||
} else if tag_name == "EMailAddress" {
|
|
||||||
// Skip unsupported tags under Request, such as AcceptableResponseSchema
|
|
||||||
let mut tag_count = 0;
|
|
||||||
loop {
|
|
||||||
match reader.read_event_into(&mut buf) {
|
|
||||||
Ok(Event::End(_)) => {
|
|
||||||
if tag_count == 0 {
|
|
||||||
break;
|
|
||||||
} else {
|
|
||||||
tag_count -= 1;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
Ok(Event::Start(_)) => {
|
|
||||||
tag_count += 1;
|
|
||||||
}
|
|
||||||
Ok(Event::Eof) => {
|
|
||||||
return Err(format!(
|
|
||||||
"Expected value, found unexpected EOF at position {}.",
|
|
||||||
reader.buffer_position()
|
|
||||||
));
|
|
||||||
}
|
|
||||||
_ => (),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
} else {
|
} else {
|
||||||
return Err(format!(
|
return Err(format!(
|
||||||
"Expected tag {}, found unexpected tag {} at position {}.",
|
"Expected tag {}, found unexpected tag {} at position {}.",
|
||||||
@@ -180,35 +218,244 @@ fn parse_autodiscover_request(bytes: &[u8]) -> Result<String, String> {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if let Ok(Event::Text(text)) = reader.read_event_into(&mut buf)
|
let mut email = None;
|
||||||
&& let Ok(text) = text.xml_content(XmlVersion::Implicit1_0)
|
let mut response_schema = ResponseSchema::Outlook;
|
||||||
&& text.contains('@')
|
|
||||||
{
|
loop {
|
||||||
return Ok(text.trim().to_lowercase());
|
match reader.read_event_into(&mut buf) {
|
||||||
|
Ok(Event::Start(e)) => {
|
||||||
|
let local_name = e.local_name();
|
||||||
|
let field = hashify::tiny_map_ignore_case!(local_name.as_ref(),
|
||||||
|
b"EMailAddress" => RequestField::EmailAddress,
|
||||||
|
b"AcceptableResponseSchema" => RequestField::ResponseSchema,
|
||||||
|
);
|
||||||
|
|
||||||
|
let value = match reader.read_event_into(&mut value_buf) {
|
||||||
|
Ok(Event::End(_)) => None,
|
||||||
|
Ok(event) => {
|
||||||
|
let value = match event {
|
||||||
|
Event::Text(text) => text
|
||||||
|
.xml_content(XmlVersion::Implicit1_0)
|
||||||
|
.ok()
|
||||||
|
.map(Cow::into_owned),
|
||||||
|
_ => None,
|
||||||
|
};
|
||||||
|
reader
|
||||||
|
.read_to_end_into(e.name(), &mut value_buf)
|
||||||
|
.map_err(|err| {
|
||||||
|
format!("Error at position {}: {:?}", reader.buffer_position(), err)
|
||||||
|
})?;
|
||||||
|
value
|
||||||
|
}
|
||||||
|
Err(err) => {
|
||||||
|
return Err(format!(
|
||||||
|
"Error at position {}: {:?}",
|
||||||
|
reader.buffer_position(),
|
||||||
|
err
|
||||||
|
));
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
match (field, value) {
|
||||||
|
(Some(RequestField::EmailAddress), Some(value)) => {
|
||||||
|
email = Some(value);
|
||||||
|
}
|
||||||
|
(Some(RequestField::ResponseSchema), Some(value)) => {
|
||||||
|
response_schema = ResponseSchema::parse(&value);
|
||||||
|
}
|
||||||
|
_ => (),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Ok(Event::End(_) | Event::Eof) => break,
|
||||||
|
Ok(_) => (),
|
||||||
|
Err(e) => {
|
||||||
|
return Err(format!(
|
||||||
|
"Error at position {}: {:?}",
|
||||||
|
reader.buffer_position(),
|
||||||
|
e
|
||||||
|
));
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
Err(format!(
|
match email {
|
||||||
|
Some(email) if email.contains('@') => Ok(AutodiscoverRequest {
|
||||||
|
email: email.trim().to_lowercase(),
|
||||||
|
response_schema,
|
||||||
|
}),
|
||||||
|
_ => Err(format!(
|
||||||
"Expected email address, found unexpected value at position {}.",
|
"Expected email address, found unexpected value at position {}.",
|
||||||
reader.buffer_position()
|
reader.buffer_position()
|
||||||
))
|
)),
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
mod tests {
|
mod tests {
|
||||||
|
use super::{AutodiscoverRequest, ResponseSchema, parse_autodiscover_request};
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn parse_autodiscover() {
|
fn parse_autodiscover() {
|
||||||
let r = r#"<?xml version="1.0" encoding="utf-8"?>
|
const OUTLOOK: &str =
|
||||||
|
"http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a";
|
||||||
|
const MOBILESYNC: &str =
|
||||||
|
"http://schemas.microsoft.com/exchange/autodiscover/mobilesync/responseschema/2006";
|
||||||
|
|
||||||
|
for (request, expected) in [
|
||||||
|
(
|
||||||
|
format!(
|
||||||
|
r#"<?xml version="1.0" encoding="utf-8"?>
|
||||||
<Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/requestschema/2006">
|
<Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/requestschema/2006">
|
||||||
<Request>
|
<Request>
|
||||||
<EMailAddress>email@example.com</EMailAddress>
|
<EMailAddress>Email@Example.com</EMailAddress>
|
||||||
<AcceptableResponseSchema>http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a</AcceptableResponseSchema>
|
<AcceptableResponseSchema>{OUTLOOK}</AcceptableResponseSchema>
|
||||||
</Request>
|
</Request>
|
||||||
</Autodiscover>"#;
|
</Autodiscover>"#
|
||||||
|
),
|
||||||
|
ResponseSchema::Outlook,
|
||||||
|
),
|
||||||
|
(
|
||||||
|
format!(
|
||||||
|
r#"<Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/requestschema/2006">
|
||||||
|
<Request>
|
||||||
|
<AcceptableResponseSchema>{OUTLOOK}</AcceptableResponseSchema>
|
||||||
|
<EMailAddress>email@example.com</EMailAddress>
|
||||||
|
</Request>
|
||||||
|
</Autodiscover>"#
|
||||||
|
),
|
||||||
|
ResponseSchema::Outlook,
|
||||||
|
),
|
||||||
|
(
|
||||||
|
r#"<Autodiscover>
|
||||||
|
<Request>
|
||||||
|
<EMailAddress>email@example.com</EMailAddress>
|
||||||
|
</Request>
|
||||||
|
</Autodiscover>"#
|
||||||
|
.to_string(),
|
||||||
|
ResponseSchema::Outlook,
|
||||||
|
),
|
||||||
|
(
|
||||||
|
format!(
|
||||||
|
r#"<?xml version="1.0" encoding="utf-8"?>
|
||||||
|
<Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/mobilesync/requestschema/2006">
|
||||||
|
<Request>
|
||||||
|
<EMailAddress>email@example.com</EMailAddress>
|
||||||
|
<AcceptableResponseSchema>{MOBILESYNC}</AcceptableResponseSchema>
|
||||||
|
</Request>
|
||||||
|
</Autodiscover>"#
|
||||||
|
),
|
||||||
|
ResponseSchema::Unsupported,
|
||||||
|
),
|
||||||
|
(
|
||||||
|
format!(
|
||||||
|
r#"<Autodiscover>
|
||||||
|
<Request>
|
||||||
|
<LegacyDN>/o=Example/ou=Users/cn=email</LegacyDN>
|
||||||
|
<Unknown><Nested>value</Nested><Empty/></Unknown>
|
||||||
|
<AcceptableResponseSchema>{MOBILESYNC}</AcceptableResponseSchema>
|
||||||
|
<EMailAddress>email@example.com</EMailAddress>
|
||||||
|
</Request>
|
||||||
|
</Autodiscover>"#
|
||||||
|
),
|
||||||
|
ResponseSchema::Unsupported,
|
||||||
|
),
|
||||||
|
] {
|
||||||
assert_eq!(
|
assert_eq!(
|
||||||
super::parse_autodiscover_request(r.as_bytes()).unwrap(),
|
parse_autodiscover_request(request.as_bytes()).expect("valid request"),
|
||||||
"[email protected]"
|
AutodiscoverRequest {
|
||||||
|
email: "[email protected]".to_string(),
|
||||||
|
response_schema: expected,
|
||||||
|
},
|
||||||
|
"{request}"
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
for request in [
|
||||||
|
"",
|
||||||
|
"<Autodiscover><Request></Request></Autodiscover>",
|
||||||
|
"<Autodiscover><Request><EMailAddress>no-domain</EMailAddress></Request></Autodiscover>",
|
||||||
|
"<Autodiscover><Request><EMailAddress>[email protected]</Request></Autodiscover>",
|
||||||
|
"<Request><EMailAddress>[email protected]</EMailAddress></Request>",
|
||||||
|
] {
|
||||||
|
assert!(
|
||||||
|
parse_autodiscover_request(request.as_bytes()).is_err(),
|
||||||
|
"{request}"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn autodiscover_encryption() {
|
||||||
|
use registry::schema::{enums::ServiceProtocol, structs::Service};
|
||||||
|
use utils::map::vec_map::VecMap;
|
||||||
|
|
||||||
|
fn tag<'x>(block: &'x str, name: &str) -> &'x str {
|
||||||
|
block
|
||||||
|
.split_once(&format!("<{name}>"))
|
||||||
|
.and_then(|(_, rest)| rest.split_once(&format!("</{name}>")))
|
||||||
|
.map(|(value, _)| value)
|
||||||
|
.unwrap()
|
||||||
|
}
|
||||||
|
|
||||||
|
for (cleartext, expected) in [
|
||||||
|
(
|
||||||
|
false,
|
||||||
|
vec![
|
||||||
|
("IMAP", "993", "on", "SSL"),
|
||||||
|
("POP3", "995", "on", "SSL"),
|
||||||
|
("SMTP", "465", "on", "SSL"),
|
||||||
|
],
|
||||||
|
),
|
||||||
|
(
|
||||||
|
true,
|
||||||
|
vec![
|
||||||
|
("IMAP", "993", "on", "SSL"),
|
||||||
|
("IMAP", "143", "off", "TLS"),
|
||||||
|
("POP3", "995", "on", "SSL"),
|
||||||
|
("POP3", "110", "off", "TLS"),
|
||||||
|
("SMTP", "465", "on", "SSL"),
|
||||||
|
("SMTP", "587", "off", "TLS"),
|
||||||
|
],
|
||||||
|
),
|
||||||
|
] {
|
||||||
|
let services: VecMap<ServiceProtocol, Service> = [
|
||||||
|
ServiceProtocol::Imap,
|
||||||
|
ServiceProtocol::Pop3,
|
||||||
|
ServiceProtocol::Smtp,
|
||||||
|
ServiceProtocol::Jmap,
|
||||||
|
]
|
||||||
|
.into_iter()
|
||||||
|
.map(|protocol| {
|
||||||
|
(
|
||||||
|
protocol,
|
||||||
|
Service {
|
||||||
|
hostname: None,
|
||||||
|
cleartext,
|
||||||
|
},
|
||||||
|
)
|
||||||
|
})
|
||||||
|
.collect();
|
||||||
|
let response = super::build_autodiscover_response(
|
||||||
|
"[email protected]",
|
||||||
|
"mail.example.com",
|
||||||
|
&services,
|
||||||
|
|_| false,
|
||||||
|
);
|
||||||
|
|
||||||
|
assert_eq!(
|
||||||
|
response
|
||||||
|
.split("<Protocol>")
|
||||||
|
.skip(1)
|
||||||
|
.map(|block| (
|
||||||
|
tag(block, "Type"),
|
||||||
|
tag(block, "Port"),
|
||||||
|
tag(block, "SSL"),
|
||||||
|
tag(block, "Encryption"),
|
||||||
|
))
|
||||||
|
.collect::<Vec<_>>(),
|
||||||
|
expected,
|
||||||
|
"cleartext: {cleartext}"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
@@ -6,7 +6,7 @@
|
|||||||
* Modified by Coffey Labs in 2026 for INBUXA.
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::{Server, manager::application::Resource, network::legacy::is_legacy_service};
|
use crate::{Server, manager::application::Resource};
|
||||||
use registry::schema::enums::ServiceProtocol;
|
use registry::schema::enums::ServiceProtocol;
|
||||||
use std::fmt::Write;
|
use std::fmt::Write;
|
||||||
use utils::url_params::UrlParams;
|
use utils::url_params::UrlParams;
|
||||||
@@ -31,7 +31,7 @@ impl Server {
|
|||||||
};
|
};
|
||||||
|
|
||||||
// inbuxa: legacy-protocols LP-7, LP-14a
|
// inbuxa: legacy-protocols LP-7, LP-14a
|
||||||
let legacy_off = self.legacy_protocols_off_for(domain).await?;
|
let legacy_off = self.legacy_off_for(domain).await?;
|
||||||
|
|
||||||
// Build XML response
|
// Build XML response
|
||||||
let mut config = String::with_capacity(1024);
|
let mut config = String::with_capacity(1024);
|
||||||
@@ -45,7 +45,7 @@ impl Server {
|
|||||||
"\t\t<displayShortName>{domain}</displayShortName>"
|
"\t\t<displayShortName>{domain}</displayShortName>"
|
||||||
);
|
);
|
||||||
for (protocol, service) in &self.core.network.info.services {
|
for (protocol, service) in &self.core.network.info.services {
|
||||||
if legacy_off && is_legacy_service(protocol) {
|
if legacy_off.service(protocol) {
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
let (protocol, tag, ports) = match protocol {
|
let (protocol, tag, ports) = match protocol {
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -6,11 +6,7 @@
|
|||||||
* Modified by Coffey Labs in 2026 for INBUXA.
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
use crate::{
|
use crate::{Server, config::network::Pacc, network::dkim::generate_dkim_dns_record};
|
||||||
Server,
|
|
||||||
config::network::Pacc,
|
|
||||||
network::{dkim::generate_dkim_dns_record, legacy::is_legacy_service},
|
|
||||||
};
|
|
||||||
use ahash::{AHashMap, AHashSet};
|
use ahash::{AHashMap, AHashSet};
|
||||||
use base64::{Engine, engine::general_purpose};
|
use base64::{Engine, engine::general_purpose};
|
||||||
use dns_update::{
|
use dns_update::{
|
||||||
@@ -41,7 +37,7 @@ impl Server {
|
|||||||
let default_host = network.server_name.as_str();
|
let default_host = network.server_name.as_str();
|
||||||
let domain_name = domain.name.as_str();
|
let domain_name = domain.name.as_str();
|
||||||
// inbuxa: legacy-protocols LP-7, LP-14a
|
// inbuxa: legacy-protocols LP-7, LP-14a
|
||||||
let legacy_off = self.legacy_protocols_off_for(domain_name).await?;
|
let legacy_off = self.legacy_off_for(domain_name).await?;
|
||||||
let domain_name_suffix = format!(".{domain_name}");
|
let domain_name_suffix = format!(".{domain_name}");
|
||||||
|
|
||||||
for record_type in record_types {
|
for record_type in record_types {
|
||||||
@@ -205,7 +201,7 @@ impl Server {
|
|||||||
// name says "not offered" -- target "." (RFC 6186 section
|
// name says "not offered" -- target "." (RFC 6186 section
|
||||||
// 3.4) -- rather than vanishing, so a client that looks
|
// 3.4) -- rather than vanishing, so a client that looks
|
||||||
// is told, and an old record left in the zone is replaced.
|
// is told, and an old record left in the zone is replaced.
|
||||||
if legacy_off && is_legacy_service(protocol) {
|
if legacy_off.service(protocol) {
|
||||||
for (service_name, _) in services {
|
for (service_name, _) in services {
|
||||||
records.push(NamedDnsRecord {
|
records.push(NamedDnsRecord {
|
||||||
name: format!("_{service_name}._tcp.{domain_name}."),
|
name: format!("_{service_name}._tcp.{domain_name}."),
|
||||||
@@ -307,8 +303,8 @@ impl Server {
|
|||||||
// inbuxa: legacy-protocols LP-7. No TLS pin for a port
|
// inbuxa: legacy-protocols LP-7. No TLS pin for a port
|
||||||
// the switch has closed. Submission's port stays open
|
// the switch has closed. Submission's port stays open
|
||||||
// (the SMTP lock), so its record stays.
|
// (the SMTP lock), so its record stays.
|
||||||
if legacy_off
|
if matches!(protocol, ServiceProtocol::Imap | ServiceProtocol::Pop3)
|
||||||
&& matches!(protocol, ServiceProtocol::Imap | ServiceProtocol::Pop3)
|
&& legacy_off.service(protocol)
|
||||||
{
|
{
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
@@ -418,11 +414,8 @@ impl Server {
|
|||||||
|
|
||||||
pub async fn get_pacc_for_domain(&self, domain_name: &str) -> trc::Result<String> {
|
pub async fn get_pacc_for_domain(&self, domain_name: &str) -> trc::Result<String> {
|
||||||
// inbuxa: legacy-protocols LP-7, LP-14a
|
// inbuxa: legacy-protocols LP-7, LP-14a
|
||||||
let pacc = if self.legacy_protocols_off_for(domain_name).await? {
|
let off = self.legacy_off_for(domain_name).await?;
|
||||||
&self.core.network.info.pacc_jmap_only
|
let pacc = &self.core.network.info.pacc[off.index()];
|
||||||
} else {
|
|
||||||
&self.core.network.info.pacc
|
|
||||||
};
|
|
||||||
self.get_directory_for_domain(domain_name)
|
self.get_directory_for_domain(domain_name)
|
||||||
.await
|
.await
|
||||||
.caused_by(trc::location!())
|
.caused_by(trc::location!())
|
||||||
|
|||||||
@@ -961,6 +961,20 @@ impl DnsUpdater {
|
|||||||
)
|
)
|
||||||
.map_err(|err| format!("Failed to build DNS updater: {}", err))?,
|
.map_err(|err| format!("Failed to build DNS updater: {}", err))?,
|
||||||
}),
|
}),
|
||||||
|
DnsServer::PowerDns(server) => Ok(DnsUpdater {
|
||||||
|
polling_interval: server.polling_interval.into_inner(),
|
||||||
|
propagation_timeout: server.propagation_timeout.into_inner(),
|
||||||
|
propagation_delay: server.propagation_delay.map(|d| d.into_inner()),
|
||||||
|
ttl: server.ttl.into_inner(),
|
||||||
|
core,
|
||||||
|
updater: dns_update::DnsUpdater::new_pdns(
|
||||||
|
server.api_key.secret().await?,
|
||||||
|
server.endpoint,
|
||||||
|
server.server_id,
|
||||||
|
server.timeout.into_inner().into(),
|
||||||
|
)
|
||||||
|
.map_err(|err| format!("Failed to build DNS updater: {}", err))?,
|
||||||
|
}),
|
||||||
DnsServer::Safedns(server) => Ok(DnsUpdater {
|
DnsServer::Safedns(server) => Ok(DnsUpdater {
|
||||||
polling_interval: server.polling_interval.into_inner(),
|
polling_interval: server.polling_interval.into_inner(),
|
||||||
propagation_timeout: server.propagation_timeout.into_inner(),
|
propagation_timeout: server.propagation_timeout.into_inner(),
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
@@ -35,8 +35,8 @@ use directory::Credentials;
|
|||||||
use inbuxa_features::security::{
|
use inbuxa_features::security::{
|
||||||
legacy_use::{self, LegacyUse},
|
legacy_use::{self, LegacyUse},
|
||||||
listeners,
|
listeners,
|
||||||
protocol_policy::{self, ProtocolPolicy, SavedListener},
|
protocol_policy::{self, ProtocolPolicy, SUBMISSION, SWITCHED, SavedListener, Switches},
|
||||||
tenant_protocol_policy,
|
tenant_protocol_policy::{self, OffBy, TenantProtocolPolicy},
|
||||||
};
|
};
|
||||||
use registry::schema::enums::ServiceProtocol;
|
use registry::schema::enums::ServiceProtocol;
|
||||||
use registry::types::{error::Error, id::ObjectId};
|
use registry::types::{error::Error, id::ObjectId};
|
||||||
@@ -97,40 +97,48 @@ impl Server {
|
|||||||
// this, and a /set that omitted it must not lose the listeners still
|
// this, and a /set that omitted it must not lose the listeners still
|
||||||
// waiting to come back.
|
// waiting to come back.
|
||||||
let previous = self.protocol_policy().await?;
|
let previous = self.protocol_policy().await?;
|
||||||
policy.saved_listeners = previous.saved_listeners;
|
policy.saved_listeners = previous.saved_listeners.clone();
|
||||||
policy.changed_at = Some(store::write::now() * 1000);
|
policy.changed_at = Some(store::write::now() * 1000);
|
||||||
policy.changed_by = changed_by;
|
policy.changed_by = changed_by;
|
||||||
|
policy.normalize();
|
||||||
|
|
||||||
if policy.legacy_protocols.is_disabled() {
|
// Each protocol on its own switch: close what is off now, and put
|
||||||
self.close_legacy_listeners(&mut policy, &mut change).await?;
|
// back what was saved for a protocol that is on again. Either may
|
||||||
} else {
|
// happen in one change, when one protocol goes off as another comes
|
||||||
|
// back.
|
||||||
|
self.close_legacy_listeners(&mut policy, &mut change)
|
||||||
|
.await?;
|
||||||
self.reopen_legacy_listeners(&mut policy, &mut change)
|
self.reopen_legacy_listeners(&mut policy, &mut change)
|
||||||
.await?;
|
.await?;
|
||||||
}
|
|
||||||
|
|
||||||
protocol_policy::set(&self.core.storage.data, &policy).await?;
|
protocol_policy::set(&self.core.storage.data, &policy).await?;
|
||||||
|
|
||||||
// LP-8. Raised here rather than by the JMAP method, so whatever turns
|
// LP-8. Raised here rather than by the JMAP method, so whatever turns
|
||||||
// the switch is reported. A /set that changed nothing -- the switch
|
// a switch is reported. A /set that changed nothing -- every switch
|
||||||
// already where it was asked to be, nothing to close or reopen -- is
|
// already where it was asked to be, nothing to close or reopen -- is
|
||||||
// not a change.
|
// not a change.
|
||||||
if previous.legacy_protocols != policy.legacy_protocols || !change.is_empty() {
|
let mut before = previous;
|
||||||
let (moved, direction) = if policy.legacy_protocols.is_disabled() {
|
before.normalize();
|
||||||
(&change.closed, "closed")
|
if before.off() != policy.off() || !change.is_empty() {
|
||||||
} else {
|
// The closed first, then the reopened; `Details` says which.
|
||||||
(&change.reopened, "reopened")
|
let moved = change
|
||||||
};
|
.closed
|
||||||
|
.iter()
|
||||||
|
.chain(change.reopened.iter())
|
||||||
|
.map(|l| l.id.clone());
|
||||||
trc::event!(
|
trc::event!(
|
||||||
Security(trc::SecurityEvent::LegacyProtocolsChanged),
|
Security(trc::SecurityEvent::LegacyProtocolsChanged),
|
||||||
Policy = "server",
|
Policy = "server",
|
||||||
Value = if policy.legacy_protocols.is_disabled() {
|
Value = switches_value(&policy),
|
||||||
"disabled"
|
|
||||||
} else {
|
|
||||||
"enabled"
|
|
||||||
},
|
|
||||||
AccountId = policy.changed_by.clone(),
|
AccountId = policy.changed_by.clone(),
|
||||||
Details = direction,
|
Details = if change.closed.is_empty() {
|
||||||
ListenerId = listener_names(moved.iter().map(|l| l.id.clone())),
|
"reopened"
|
||||||
|
} else if change.reopened.is_empty() {
|
||||||
|
"closed"
|
||||||
|
} else {
|
||||||
|
"closed and reopened"
|
||||||
|
},
|
||||||
|
ListenerId = listener_names(moved),
|
||||||
// Only when a listener could not be put back (LP-5).
|
// Only when a listener could not be put back (LP-5).
|
||||||
Reason = (!change.failed.is_empty()).then(|| listener_names(
|
Reason = (!change.failed.is_empty()).then(|| listener_names(
|
||||||
change
|
change
|
||||||
@@ -165,21 +173,27 @@ impl Server {
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Puts back every saved listener and starts it again (LP-5).
|
/// Puts back every saved listener whose protocol is on again, and starts
|
||||||
|
/// it (LP-5). The rest stay saved.
|
||||||
async fn reopen_legacy_listeners(
|
async fn reopen_legacy_listeners(
|
||||||
&self,
|
&self,
|
||||||
policy: &mut ProtocolPolicy,
|
policy: &mut ProtocolPolicy,
|
||||||
change: &mut PolicyChange,
|
change: &mut PolicyChange,
|
||||||
) -> trc::Result<()> {
|
) -> trc::Result<()> {
|
||||||
if policy.saved_listeners.is_empty() {
|
let (wanted, still_closed): (Vec<_>, Vec<_>) = std::mem::take(&mut policy.saved_listeners)
|
||||||
|
.into_iter()
|
||||||
|
.partition(|saved| !policy.closes(&saved.protocol, &saved.ports));
|
||||||
|
policy.saved_listeners = still_closed;
|
||||||
|
if wanted.is_empty() {
|
||||||
return Ok(());
|
return Ok(());
|
||||||
}
|
}
|
||||||
|
|
||||||
let saved = std::mem::take(&mut policy.saved_listeners);
|
let (restored, failed) = listeners::reopen(self.registry(), &wanted).await?;
|
||||||
let (restored, failed) = listeners::reopen(self.registry(), &saved).await?;
|
|
||||||
|
|
||||||
// A listener that could not be put back stays saved for another try.
|
// A listener that could not be put back stays saved for another try.
|
||||||
policy.saved_listeners = failed.iter().map(|(listener, _)| listener.clone()).collect();
|
policy
|
||||||
|
.saved_listeners
|
||||||
|
.extend(failed.iter().map(|(listener, _)| listener.clone()));
|
||||||
change.failed = failed;
|
change.failed = failed;
|
||||||
|
|
||||||
if !restored.is_empty() {
|
if !restored.is_empty() {
|
||||||
@@ -254,6 +268,17 @@ impl Server {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// The switches as an event value: `disabled` or `enabled` when all three
|
||||||
|
/// agree, otherwise which are off, such as `pop3 disabled` (LP-8).
|
||||||
|
pub fn switches_value(policy: &impl Switches) -> String {
|
||||||
|
let off = policy.off();
|
||||||
|
match off.len() {
|
||||||
|
0 => "enabled".to_string(),
|
||||||
|
n if n == SWITCHED.len() => "disabled".to_string(),
|
||||||
|
_ => format!("{} disabled", off.join(", ")),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/// Names for an event field: the listeners a change closed, reopened or
|
/// Names for an event field: the listeners a change closed, reopened or
|
||||||
/// failed to reopen (LP-8).
|
/// failed to reopen (LP-8).
|
||||||
fn listener_names<T: Into<trc::Value>>(names: impl Iterator<Item = T>) -> trc::Value {
|
fn listener_names<T: Into<trc::Value>>(names: impl Iterator<Item = T>) -> trc::Value {
|
||||||
@@ -395,16 +420,19 @@ impl Server {
|
|||||||
credentials: &Credentials,
|
credentials: &Credentials,
|
||||||
) -> trc::Result<()> {
|
) -> trc::Result<()> {
|
||||||
let domain = domain_of(credentials);
|
let domain = domain_of(credentials);
|
||||||
if self.protocol_policy().await?.legacy_protocols.is_disabled() {
|
let server = self.protocol_policy().await?;
|
||||||
|
if server.is_off(protocol.as_str()) {
|
||||||
return Err(protocol.refused(RefusalScope::Server, domain));
|
return Err(protocol.refused(RefusalScope::Server, domain));
|
||||||
}
|
}
|
||||||
if let Some(name) = &domain
|
if let Some(name) = &domain
|
||||||
&& let Some(domain) = self.domain(name).await?
|
&& let Some(domain) = self.domain(name).await?
|
||||||
&& let Some(tenant_id) = domain.id_tenant
|
&& let Some(tenant_id) = domain.id_tenant
|
||||||
&& self.tenant_legacy_protocols_off(tenant_id).await?
|
|
||||||
{
|
{
|
||||||
|
let tenant = self.tenant_protocol_policy(tenant_id).await?;
|
||||||
|
if tenant_protocol_policy::off_by(&server, Some(&tenant), protocol.as_str()).is_some() {
|
||||||
return Err(protocol.refused(RefusalScope::Tenant(tenant_id), Some(name.clone())));
|
return Err(protocol.refused(RefusalScope::Tenant(tenant_id), Some(name.clone())));
|
||||||
}
|
}
|
||||||
|
}
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -422,11 +450,17 @@ impl Server {
|
|||||||
protocol: LegacyProtocol,
|
protocol: LegacyProtocol,
|
||||||
access_token: &AccessToken,
|
access_token: &AccessToken,
|
||||||
) -> trc::Result<()> {
|
) -> trc::Result<()> {
|
||||||
if let Some(tenant_id) = access_token.tenant_id()
|
if let Some(tenant_id) = access_token.tenant_id() {
|
||||||
&& self.tenant_legacy_protocols_off(tenant_id).await?
|
let server = self.protocol_policy().await?;
|
||||||
{
|
let tenant = self.tenant_protocol_policy(tenant_id).await?;
|
||||||
|
match tenant_protocol_policy::off_by(&server, Some(&tenant), protocol.as_str()) {
|
||||||
|
Some(OffBy::Server) => return Err(protocol.refused(RefusalScope::Server, None)),
|
||||||
|
Some(OffBy::Tenant) => {
|
||||||
return Err(protocol.refused(RefusalScope::Tenant(tenant_id), None));
|
return Err(protocol.refused(RefusalScope::Tenant(tenant_id), None));
|
||||||
}
|
}
|
||||||
|
None => {}
|
||||||
|
}
|
||||||
|
}
|
||||||
if let Err(err) = legacy_use::record(
|
if let Err(err) = legacy_use::record(
|
||||||
&self.core.storage.data,
|
&self.core.storage.data,
|
||||||
access_token.account_id(),
|
access_token.account_id(),
|
||||||
@@ -463,31 +497,96 @@ impl Server {
|
|||||||
Ok(recent)
|
Ok(recent)
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Whether legacy protocols are off for this account: the stricter of the
|
/// Which legacy protocols are off for this account: each the stricter of
|
||||||
/// server's switch and its tenant's. What the JMAP session tells the
|
/// the server's switch and its tenant's. What the JMAP session tells the
|
||||||
/// account's apps (legacy-protocols spec, Interfaces), so the webmail can
|
/// account's apps (legacy-protocols spec, Interfaces), so the webmail can
|
||||||
/// say why a mail app won't connect (LP-19).
|
/// say why a mail app won't connect (LP-19).
|
||||||
pub async fn legacy_protocols_off_for_account(
|
pub async fn legacy_off_for_account(
|
||||||
&self,
|
&self,
|
||||||
access_token: &AccessToken,
|
access_token: &AccessToken,
|
||||||
) -> trc::Result<bool> {
|
) -> trc::Result<LegacyOff> {
|
||||||
if self.protocol_policy().await?.legacy_protocols.is_disabled() {
|
let server = self.protocol_policy().await?;
|
||||||
return Ok(true);
|
let tenant = match access_token.tenant_id() {
|
||||||
|
Some(tenant_id) => Some(self.tenant_protocol_policy(tenant_id).await?),
|
||||||
|
None => None,
|
||||||
|
};
|
||||||
|
Ok(LegacyOff::of(&server, tenant.as_ref()))
|
||||||
}
|
}
|
||||||
match access_token.tenant_id() {
|
|
||||||
Some(tenant_id) => self.tenant_legacy_protocols_off(tenant_id).await,
|
/// A tenant's switches, or all on when it has never set them (LP-10).
|
||||||
None => Ok(false),
|
pub async fn tenant_protocol_policy(
|
||||||
|
&self,
|
||||||
|
tenant_id: u32,
|
||||||
|
) -> trc::Result<TenantProtocolPolicy> {
|
||||||
|
tenant_protocol_policy::get(&self.core.storage.data, tenant_id).await
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Which legacy protocols are off, for one account or one domain: the server's
|
||||||
|
/// switches and the tenant's together. Submission is off only when all three
|
||||||
|
/// are.
|
||||||
|
#[derive(Debug, Clone, Copy, Default, PartialEq, Eq)]
|
||||||
|
pub struct LegacyOff {
|
||||||
|
pub imap: bool,
|
||||||
|
pub pop3: bool,
|
||||||
|
pub manage_sieve: bool,
|
||||||
|
pub submission: bool,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl LegacyOff {
|
||||||
|
pub fn of(server: &ProtocolPolicy, tenant: Option<&TenantProtocolPolicy>) -> Self {
|
||||||
|
let off = |protocol| tenant_protocol_policy::off_by(server, tenant, protocol).is_some();
|
||||||
|
LegacyOff {
|
||||||
|
imap: off("imap"),
|
||||||
|
pop3: off("pop3"),
|
||||||
|
manage_sieve: off("manageSieve"),
|
||||||
|
submission: off(SUBMISSION),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Whether a tenant has turned legacy protocols off for itself (LP-10).
|
/// Whether this configured service must not be offered (LP-7). SMTP here
|
||||||
pub async fn tenant_legacy_protocols_off(&self, tenant_id: u32) -> trc::Result<bool> {
|
/// is submission; inbound mail is never a configured service.
|
||||||
Ok(
|
pub fn service(&self, protocol: &ServiceProtocol) -> bool {
|
||||||
tenant_protocol_policy::get(&self.core.storage.data, tenant_id)
|
match protocol {
|
||||||
.await?
|
ServiceProtocol::Imap => self.imap,
|
||||||
.legacy_protocols
|
ServiceProtocol::Pop3 => self.pop3,
|
||||||
.is_disabled(),
|
ServiceProtocol::Managesieve => self.manage_sieve,
|
||||||
)
|
ServiceProtocol::Smtp => self.submission,
|
||||||
|
_ => false,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Whether anything is off.
|
||||||
|
pub fn any(&self) -> bool {
|
||||||
|
self.imap || self.pop3 || self.manage_sieve || self.submission
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Whether everything is off: the kill-all's effect.
|
||||||
|
pub fn all(&self) -> bool {
|
||||||
|
self.imap && self.pop3 && self.manage_sieve && self.submission
|
||||||
|
}
|
||||||
|
|
||||||
|
/// An index for answers prepared once per combination (the PACC
|
||||||
|
/// document): one bit per protocol.
|
||||||
|
pub fn index(&self) -> usize {
|
||||||
|
(self.imap as usize)
|
||||||
|
| (self.pop3 as usize) << 1
|
||||||
|
| (self.manage_sieve as usize) << 2
|
||||||
|
| (self.submission as usize) << 3
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The protocols that are still allowed, by JMAP name, for the session.
|
||||||
|
pub fn allowed(&self) -> Vec<&'static str> {
|
||||||
|
[
|
||||||
|
("imap", self.imap),
|
||||||
|
("pop3", self.pop3),
|
||||||
|
("manageSieve", self.manage_sieve),
|
||||||
|
(SUBMISSION, self.submission),
|
||||||
|
]
|
||||||
|
.into_iter()
|
||||||
|
.filter(|(_, off)| !off)
|
||||||
|
.map(|(name, _)| name)
|
||||||
|
.collect()
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -505,21 +604,20 @@ pub fn is_legacy_service(protocol: &ServiceProtocol) -> bool {
|
|||||||
}
|
}
|
||||||
|
|
||||||
impl Server {
|
impl Server {
|
||||||
/// Whether legacy services are off for this domain, for the answers that
|
/// Which legacy services are off for this domain, for the answers that
|
||||||
/// must stop offering them: off for the whole server (LP-7), or for the
|
/// must stop offering them: off for the whole server (LP-7), or for the
|
||||||
/// tenant the domain belongs to (LP-14a). Read per answer, as sign-in
|
/// tenant the domain belongs to (LP-14a). Read per answer, as sign-in
|
||||||
/// reads it. A name that is no domain here answers for the server alone.
|
/// reads it. A name that is no domain here answers for the server alone.
|
||||||
pub async fn legacy_protocols_off_for(&self, domain_name: &str) -> trc::Result<bool> {
|
pub async fn legacy_off_for(&self, domain_name: &str) -> trc::Result<LegacyOff> {
|
||||||
if self.protocol_policy().await?.legacy_protocols.is_disabled() {
|
let server = self.protocol_policy().await?;
|
||||||
return Ok(true);
|
let tenant = match self.domain(domain_name).await? {
|
||||||
}
|
|
||||||
match self.domain(domain_name).await? {
|
|
||||||
Some(domain) => match domain.id_tenant {
|
Some(domain) => match domain.id_tenant {
|
||||||
Some(tenant_id) => self.tenant_legacy_protocols_off(tenant_id).await,
|
Some(tenant_id) => Some(self.tenant_protocol_policy(tenant_id).await?),
|
||||||
None => Ok(false),
|
None => None,
|
||||||
},
|
},
|
||||||
None => Ok(false),
|
None => None,
|
||||||
}
|
};
|
||||||
|
Ok(LegacyOff::of(&server, tenant.as_ref()))
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -619,6 +717,36 @@ mod tests {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn what_is_off_for_one_account_or_domain() {
|
||||||
|
use inbuxa_features::security::protocol_policy::LegacyProtocols;
|
||||||
|
let mut server = ProtocolPolicy::default();
|
||||||
|
server.set("pop3", LegacyProtocols::Disabled);
|
||||||
|
let mut tenant = TenantProtocolPolicy::default();
|
||||||
|
tenant.set("manageSieve", LegacyProtocols::Disabled);
|
||||||
|
|
||||||
|
let off = LegacyOff::of(&server, Some(&tenant));
|
||||||
|
assert!(off.pop3 && off.manage_sieve && !off.imap && !off.submission);
|
||||||
|
assert!(off.service(&ServiceProtocol::Pop3));
|
||||||
|
assert!(!off.service(&ServiceProtocol::Imap));
|
||||||
|
assert!(
|
||||||
|
!off.service(&ServiceProtocol::Smtp),
|
||||||
|
"sending is still offered"
|
||||||
|
);
|
||||||
|
assert!(!off.service(&ServiceProtocol::Jmap));
|
||||||
|
assert_eq!(off.allowed(), vec!["imap", "submission"]);
|
||||||
|
assert!(off.any() && !off.all());
|
||||||
|
|
||||||
|
let off = LegacyOff::of(&server, None);
|
||||||
|
assert_eq!(off.index(), 0b0010);
|
||||||
|
|
||||||
|
server.set_all(LegacyProtocols::Disabled);
|
||||||
|
let off = LegacyOff::of(&server, None);
|
||||||
|
assert!(off.all());
|
||||||
|
assert_eq!(off.index(), 0b1111);
|
||||||
|
assert!(off.allowed().is_empty());
|
||||||
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn the_domain_comes_from_the_name_given() {
|
fn the_domain_comes_from_the_name_given() {
|
||||||
assert_eq!(domain_of(&basic("[email protected]")), Some("b.test".to_string()));
|
assert_eq!(domain_of(&basic("[email protected]")), Some("b.test".to_string()));
|
||||||
|
|||||||
@@ -426,6 +426,37 @@ impl Server {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
impl Server {
|
||||||
|
/// inbuxa: personal-data catalog, D2: removes bans whose period is over.
|
||||||
|
/// They already stop blocking when they expire, and go when settings are
|
||||||
|
/// next loaded; the daily clean-up makes sure a server that seldom
|
||||||
|
/// reloads doesn't keep them.
|
||||||
|
pub async fn purge_expired_blocked_ips(&self) -> trc::Result<()> {
|
||||||
|
let now = now() as i64;
|
||||||
|
let mut expired = Vec::new();
|
||||||
|
for ip in self.registry().list::<BlockedIp>().await? {
|
||||||
|
if ip.object.expires_at.as_ref().is_some_and(|at| at.timestamp() <= now) {
|
||||||
|
let address = ip.object.address.clone();
|
||||||
|
let object = Object {
|
||||||
|
inner: ip.object.into(),
|
||||||
|
revision: ip.revision,
|
||||||
|
};
|
||||||
|
self.registry()
|
||||||
|
.write(RegistryWrite::delete_object(ip.id, &object))
|
||||||
|
.await?;
|
||||||
|
expired.push(trc::Value::from(address.into_inner().0));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !expired.is_empty() {
|
||||||
|
trc::event!(
|
||||||
|
Security(trc::SecurityEvent::IpBlockExpired),
|
||||||
|
Details = expired
|
||||||
|
);
|
||||||
|
}
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
impl BlockedIps {
|
impl BlockedIps {
|
||||||
pub async fn parse(bp: &mut Bootstrap) -> Self {
|
pub async fn parse(bp: &mut Bootstrap) -> Self {
|
||||||
let mut ips = Self::default();
|
let mut ips = Self::default();
|
||||||
|
|||||||
@@ -6,33 +6,79 @@
|
|||||||
* Modified by Coffey Labs in 2026 for INBUXA.
|
* Modified by Coffey Labs in 2026 for INBUXA.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
use ahash::AHashMap;
|
||||||
use base64::{Engine, engine::general_purpose::URL_SAFE_NO_PAD};
|
use base64::{Engine, engine::general_purpose::URL_SAFE_NO_PAD};
|
||||||
use p256::{
|
use p256::{
|
||||||
SecretKey,
|
SecretKey,
|
||||||
ecdsa::{Signature, SigningKey, signature::Signer},
|
ecdsa::{Signature, SigningKey, signature::Signer},
|
||||||
pkcs8::{DecodePrivateKey, PrivateKeyInfo, der::SecretDocument},
|
pkcs8::{DecodePrivateKey, PrivateKeyInfo, der::SecretDocument},
|
||||||
};
|
};
|
||||||
|
use parking_lot::Mutex;
|
||||||
|
use reqwest::{Url, header::HeaderValue};
|
||||||
|
use std::sync::Arc;
|
||||||
|
|
||||||
const VAPID_TOKEN_TTL: u64 = 12 * 60 * 60;
|
const VAPID_TOKEN_TTL: u64 = 12 * 60 * 60;
|
||||||
|
const VAPID_TOKEN_REFRESH: u64 = VAPID_TOKEN_TTL / 2;
|
||||||
|
|
||||||
#[derive(Clone)]
|
#[derive(Clone)]
|
||||||
pub struct Vapid {
|
pub struct Vapid {
|
||||||
key: VapidKey,
|
key: VapidKey,
|
||||||
contact: Option<String>,
|
contact: Option<String>,
|
||||||
|
tokens: Arc<Mutex<AHashMap<String, VapidToken>>>,
|
||||||
|
}
|
||||||
|
|
||||||
|
struct VapidToken {
|
||||||
|
authorization: HeaderValue,
|
||||||
|
issued_at: u64,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl Vapid {
|
impl Vapid {
|
||||||
pub fn new(key: VapidKey, contact: Option<String>) -> Self {
|
pub fn new(key: VapidKey, contact: Option<String>) -> Self {
|
||||||
Self { key, contact }
|
Self {
|
||||||
|
key,
|
||||||
|
contact,
|
||||||
|
tokens: Arc::default(),
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
pub fn public_key(&self) -> &str {
|
pub fn public_key(&self) -> &str {
|
||||||
self.key.public_key()
|
self.key.public_key()
|
||||||
}
|
}
|
||||||
|
|
||||||
pub fn authorization(&self, endpoint: &str, now: u64) -> Option<String> {
|
pub fn authorization(&self, endpoint: &str, now: u64) -> Option<HeaderValue> {
|
||||||
self.key
|
let prefix = endpoint_prefix(endpoint)?;
|
||||||
.authorization(endpoint, self.contact.as_deref(), now)
|
if let Some(token) = self
|
||||||
|
.tokens
|
||||||
|
.lock()
|
||||||
|
.get(prefix)
|
||||||
|
.filter(|token| token.is_fresh(now))
|
||||||
|
{
|
||||||
|
return Some(token.authorization.clone());
|
||||||
|
}
|
||||||
|
|
||||||
|
let authorization = HeaderValue::try_from(self.key.authorization(
|
||||||
|
endpoint,
|
||||||
|
self.contact.as_deref(),
|
||||||
|
now,
|
||||||
|
)?)
|
||||||
|
.ok()?;
|
||||||
|
let mut tokens = self.tokens.lock();
|
||||||
|
tokens.retain(|_, token| token.is_fresh(now));
|
||||||
|
tokens.insert(
|
||||||
|
prefix.to_string(),
|
||||||
|
VapidToken {
|
||||||
|
authorization: authorization.clone(),
|
||||||
|
issued_at: now,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
Some(authorization)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl VapidToken {
|
||||||
|
fn is_fresh(&self, now: u64) -> bool {
|
||||||
|
now.checked_sub(self.issued_at)
|
||||||
|
.is_some_and(|age| age < VAPID_TOKEN_REFRESH)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -105,41 +151,15 @@ impl VapidKey {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
fn endpoint_origin(url: &str) -> Option<String> {
|
fn endpoint_prefix(url: &str) -> Option<&str> {
|
||||||
let (scheme, rest) = url.split_once("://")?;
|
let (scheme, rest) = url.split_once("://")?;
|
||||||
let scheme = scheme.to_ascii_lowercase();
|
|
||||||
let authority = rest.split(['/', '?', '#']).next()?;
|
let authority = rest.split(['/', '?', '#']).next()?;
|
||||||
let authority = authority
|
url.get(..scheme.len() + "://".len() + authority.len())
|
||||||
.rsplit_once('@')
|
}
|
||||||
.map(|(_, host)| host)
|
|
||||||
.unwrap_or(authority);
|
|
||||||
if authority.is_empty() {
|
|
||||||
return None;
|
|
||||||
}
|
|
||||||
|
|
||||||
let (host, port) = if let Some(rest) = authority.strip_prefix('[') {
|
fn endpoint_origin(url: &str) -> Option<String> {
|
||||||
let (addr, tail) = rest.split_once(']')?;
|
let origin = Url::parse(url).ok()?.origin();
|
||||||
(
|
origin.is_tuple().then(|| origin.ascii_serialization())
|
||||||
format!("[{}]", addr.to_ascii_lowercase()),
|
|
||||||
tail.strip_prefix(':').filter(|port| !port.is_empty()),
|
|
||||||
)
|
|
||||||
} else if let Some((host, port)) = authority.rsplit_once(':') {
|
|
||||||
(
|
|
||||||
host.to_ascii_lowercase(),
|
|
||||||
Some(port).filter(|p| !p.is_empty()),
|
|
||||||
)
|
|
||||||
} else {
|
|
||||||
(authority.to_ascii_lowercase(), None)
|
|
||||||
};
|
|
||||||
|
|
||||||
match port {
|
|
||||||
Some(port)
|
|
||||||
if !((scheme == "https" && port == "443") || (scheme == "http" && port == "80")) =>
|
|
||||||
{
|
|
||||||
Some(format!("{scheme}://{host}:{port}"))
|
|
||||||
}
|
|
||||||
_ => Some(format!("{scheme}://{host}")),
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
pub fn normalize_contact(contact: &str) -> Option<String> {
|
pub fn normalize_contact(contact: &str) -> Option<String> {
|
||||||
@@ -206,7 +226,12 @@ mod tests {
|
|||||||
endpoint_origin("http://[2001:DB8::1]:80/p").unwrap(),
|
endpoint_origin("http://[2001:DB8::1]:80/p").unwrap(),
|
||||||
"http://[2001:db8::1]"
|
"http://[2001:db8::1]"
|
||||||
);
|
);
|
||||||
|
assert_eq!(
|
||||||
|
endpoint_origin("https://attacker.example\\@fcm.googleapis.com/fcm/send/x").unwrap(),
|
||||||
|
"https://attacker.example"
|
||||||
|
);
|
||||||
assert!(endpoint_origin("not-a-url").is_none());
|
assert!(endpoint_origin("not-a-url").is_none());
|
||||||
|
assert!(endpoint_origin("mailto:[email protected]").is_none());
|
||||||
}
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
@@ -336,6 +361,47 @@ B4yDfR2rGOd2H6Kv3fQNHPj9Nu5Tks8QYMLzrX8ONCNoFnNUQl9S0r0QS6phVqD0
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn authorization_is_reused_per_endpoint_prefix() {
|
||||||
|
let vapid = Vapid::new(test_key(), None);
|
||||||
|
let now = 1_700_000_000;
|
||||||
|
let token = vapid
|
||||||
|
.authorization("https://push.example.com/push/a", now)
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
assert_eq!(
|
||||||
|
vapid
|
||||||
|
.authorization("https://push.example.com/push/b?x=1", now + 60)
|
||||||
|
.unwrap(),
|
||||||
|
token
|
||||||
|
);
|
||||||
|
assert_ne!(
|
||||||
|
vapid
|
||||||
|
.authorization("https://other.example.com/push/a", now)
|
||||||
|
.unwrap(),
|
||||||
|
token
|
||||||
|
);
|
||||||
|
assert_ne!(
|
||||||
|
vapid
|
||||||
|
.authorization("https://push.example.com/push/a", now - 1)
|
||||||
|
.unwrap(),
|
||||||
|
token
|
||||||
|
);
|
||||||
|
let refreshed = vapid
|
||||||
|
.authorization("https://push.example.com/push/a", now + VAPID_TOKEN_REFRESH)
|
||||||
|
.unwrap();
|
||||||
|
assert_ne!(refreshed, token);
|
||||||
|
assert_eq!(
|
||||||
|
vapid
|
||||||
|
.authorization(
|
||||||
|
"https://push.example.com/push/c",
|
||||||
|
now + VAPID_TOKEN_REFRESH + 1
|
||||||
|
)
|
||||||
|
.unwrap(),
|
||||||
|
refreshed
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn authorization_omits_subject_when_no_contact() {
|
fn authorization_omits_subject_when_no_contact() {
|
||||||
let key = test_key();
|
let key = test_key();
|
||||||
|
|||||||
@@ -0,0 +1,434 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! The live facts the personal-data catalog is evaluated against
|
||||||
|
//! (personal-data catalog spec, §6): which sources are switched on, what
|
||||||
|
//! bounds each one's retention, which stores and endpoints are elsewhere.
|
||||||
|
//! Read from the registry on each request, so every node answers alike.
|
||||||
|
|
||||||
|
use crate::Server;
|
||||||
|
use inbuxa_features::privacy::{
|
||||||
|
self, Days, Inventory, LiveFacts, is_loopback,
|
||||||
|
snapshot::{self, Snapshot, Trigger},
|
||||||
|
};
|
||||||
|
use registry::schema::{
|
||||||
|
prelude::Object,
|
||||||
|
structs::{
|
||||||
|
AiModel, BlobStore, DataRetention, DataStore, InMemoryStore, Jmap, MtaHook, MtaMilter,
|
||||||
|
MtaRoute, Search, SearchStore, SpamClassifier, SpamClassifierModel, SpamDnsblServer,
|
||||||
|
SpamLlm, SpamPyzor, Tracer, TracingStore, WebHook,
|
||||||
|
},
|
||||||
|
};
|
||||||
|
use registry::types::duration::Duration;
|
||||||
|
use serde_json::Value;
|
||||||
|
use types::id::Id;
|
||||||
|
|
||||||
|
/// The objects [`Server::privacy_facts`] reads: a write to one may change
|
||||||
|
/// the inventory.
|
||||||
|
pub const INVENTORY_OBJECTS: &[&str] = &[
|
||||||
|
"x:DataRetention",
|
||||||
|
"x:SpamClassifier",
|
||||||
|
"x:Jmap",
|
||||||
|
"x:TracingStore",
|
||||||
|
"x:Search",
|
||||||
|
"x:Tracer",
|
||||||
|
"x:WebHook",
|
||||||
|
"x:AiModel",
|
||||||
|
"x:SpamLlm",
|
||||||
|
"x:SpamDnsblServer",
|
||||||
|
"x:SpamPyzor",
|
||||||
|
"x:MtaMilter",
|
||||||
|
"x:MtaHook",
|
||||||
|
"x:MtaRoute",
|
||||||
|
"x:DataStore",
|
||||||
|
"x:BlobStore",
|
||||||
|
"x:SearchStore",
|
||||||
|
"x:InMemoryStore",
|
||||||
|
"inbuxa:AuditSettings",
|
||||||
|
"inbuxa:LogSettings",
|
||||||
|
"inbuxa:AiLimits",
|
||||||
|
];
|
||||||
|
|
||||||
|
/// A store or endpoint object's type and host, from its JSON: local types
|
||||||
|
/// stay on the host.
|
||||||
|
fn remote_host(value: &Value) -> Option<String> {
|
||||||
|
let kind = value.get("@type").and_then(Value::as_str).unwrap_or_default();
|
||||||
|
if matches!(kind, "" | "RocksDb" | "Sqlite" | "FileSystem" | "Default" | "Disabled") {
|
||||||
|
return None;
|
||||||
|
}
|
||||||
|
for key in ["host", "url", "endpoint", "address", "hostname"] {
|
||||||
|
if let Some(host) = value.get(key).and_then(Value::as_str).filter(|h| !h.is_empty()) {
|
||||||
|
return Some(host.to_string());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// A list of URLs, as an array or as a map keyed by URL
|
||||||
|
match value.get("urls") {
|
||||||
|
Some(Value::Array(urls)) => {
|
||||||
|
if let Some(url) = urls.first().and_then(Value::as_str) {
|
||||||
|
return Some(url.to_string());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Some(Value::Object(urls)) => {
|
||||||
|
if let Some(url) = urls.keys().next() {
|
||||||
|
return Some(url.clone());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
_ => {}
|
||||||
|
}
|
||||||
|
Some(kind.to_string())
|
||||||
|
}
|
||||||
|
|
||||||
|
fn days(duration: Option<&Duration>) -> Days {
|
||||||
|
match duration {
|
||||||
|
Some(d) => Days::Days(d.into_inner().as_secs().div_ceil(86_400)),
|
||||||
|
None => Days::Unbounded,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The zones a DNSBL's zone expression can query: each quoted literal that
|
||||||
|
/// starts with a dot, in any branch (`ip_reverse + '.zen.spamhaus.org'`).
|
||||||
|
fn zone_hosts(value: &Value) -> Vec<String> {
|
||||||
|
let mut hosts = Vec::new();
|
||||||
|
let mut texts = Vec::new();
|
||||||
|
fn collect<'a>(value: &'a Value, texts: &mut Vec<&'a str>) {
|
||||||
|
match value {
|
||||||
|
Value::String(s) => texts.push(s),
|
||||||
|
Value::Array(items) => items.iter().for_each(|v| collect(v, texts)),
|
||||||
|
Value::Object(map) => map.values().for_each(|v| collect(v, texts)),
|
||||||
|
_ => {}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
collect(value, &mut texts);
|
||||||
|
for text in texts {
|
||||||
|
for literal in text.split('\'').skip(1).step_by(2) {
|
||||||
|
if let Some(zone) = literal.strip_prefix('.')
|
||||||
|
&& zone.contains('.')
|
||||||
|
&& !hosts.iter().any(|h| h == zone)
|
||||||
|
{
|
||||||
|
hosts.push(zone.to_string());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
hosts
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Server {
|
||||||
|
async fn singleton<T: registry::types::ObjectImpl + From<Object> + Default>(&self) -> trc::Result<T> {
|
||||||
|
Ok(self.registry().object::<T>(Id::singleton()).await?.unwrap_or_default())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The facts the catalog is evaluated against, from the live settings.
|
||||||
|
pub async fn privacy_facts(&self) -> trc::Result<LiveFacts> {
|
||||||
|
let mut facts = LiveFacts::default();
|
||||||
|
let data = &self.core.storage.data;
|
||||||
|
let endpoint = |facts: &mut LiveFacts, id: &str, url: String| {
|
||||||
|
if !url.is_empty() && !is_loopback(&url) {
|
||||||
|
facts.endpoints.entry(id.to_string()).or_default().push(url);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
// Retention
|
||||||
|
let retention = self.singleton::<DataRetention>().await?;
|
||||||
|
for (name, value) in [
|
||||||
|
("x:DataRetention.holdTracesFor", &retention.hold_traces_for),
|
||||||
|
("x:DataRetention.holdMetricsFor", &retention.hold_metrics_for),
|
||||||
|
("x:DataRetention.holdMtaReportsFor", &retention.hold_mta_reports_for),
|
||||||
|
("x:DataRetention.archiveDeletedItemsFor", &retention.archive_deleted_items_for),
|
||||||
|
("x:DataRetention.archiveDeletedAccountsFor", &retention.archive_deleted_accounts_for),
|
||||||
|
("x:DataRetention.expungeTrashAfter", &retention.expunge_trash_after),
|
||||||
|
("x:DataRetention.expungeSubmissionsAfter", &retention.expunge_submissions_after),
|
||||||
|
] {
|
||||||
|
facts.durations.insert(name.into(), days(value.as_ref()));
|
||||||
|
}
|
||||||
|
let classifier = self.singleton::<SpamClassifier>().await?;
|
||||||
|
facts.durations.insert(
|
||||||
|
"x:SpamClassifier.holdSamplesFor".into(),
|
||||||
|
days(Some(&classifier.hold_samples_for)),
|
||||||
|
);
|
||||||
|
let jmap = self.singleton::<Jmap>().await?;
|
||||||
|
facts
|
||||||
|
.durations
|
||||||
|
.insert("x:Jmap.uploadTtl".into(), days(Some(&jmap.upload_ttl)));
|
||||||
|
let audit = inbuxa_features::audit::log::settings(data).await?;
|
||||||
|
facts.durations.insert(
|
||||||
|
"inbuxa:AuditSettings.keepForDays".into(),
|
||||||
|
Days::Days(audit.keep_for_secs.div_ceil(86_400)),
|
||||||
|
);
|
||||||
|
let logs = inbuxa_features::security::log_files::get(data).await?;
|
||||||
|
facts.durations.insert(
|
||||||
|
"inbuxa:LogSettings.keepForDays".into(),
|
||||||
|
logs.keep_for_days.map_or(Days::Unbounded, Days::Days),
|
||||||
|
);
|
||||||
|
|
||||||
|
// What's switched on
|
||||||
|
let tracing = self.singleton::<TracingStore>().await?;
|
||||||
|
let tracing_on = !matches!(tracing, TracingStore::Disabled);
|
||||||
|
let search = self.singleton::<Search>().await?;
|
||||||
|
for id in ["x:Trace", "x:TraceEvent", "x:TraceKeyValue", "x:TraceValueIpAddr", "x:TraceValueString"] {
|
||||||
|
facts.collected.insert(id.into(), tracing_on);
|
||||||
|
}
|
||||||
|
facts
|
||||||
|
.collected
|
||||||
|
.insert("trace-index".into(), tracing_on && search.index_telemetry);
|
||||||
|
facts.collected.insert(
|
||||||
|
"full-text-index".into(),
|
||||||
|
search.index_email || search.index_calendar || search.index_contacts,
|
||||||
|
);
|
||||||
|
let archive_on = retention.archive_deleted_items_for.is_some();
|
||||||
|
for id in [
|
||||||
|
"x:ArchivedEmail",
|
||||||
|
"x:ArchivedFileNode",
|
||||||
|
"x:ArchivedCalendarEvent",
|
||||||
|
"x:ArchivedContactCard",
|
||||||
|
"x:ArchivedSieveScript",
|
||||||
|
] {
|
||||||
|
facts.collected.insert(id.into(), archive_on);
|
||||||
|
}
|
||||||
|
facts.collected.insert(
|
||||||
|
"inbuxa:DeletedAccount".into(),
|
||||||
|
retention.archive_deleted_accounts_for.is_some(),
|
||||||
|
);
|
||||||
|
let reports_on = retention.hold_mta_reports_for.is_some();
|
||||||
|
for id in [
|
||||||
|
"x:ArfExternalReport",
|
||||||
|
"x:ArfFeedbackReport",
|
||||||
|
"x:DmarcExternalReport",
|
||||||
|
"x:DmarcReport",
|
||||||
|
"x:DmarcReportRecord",
|
||||||
|
"x:TlsExternalReport",
|
||||||
|
"x:TlsReport",
|
||||||
|
"x:TlsFailureDetails",
|
||||||
|
] {
|
||||||
|
facts.collected.insert(id.into(), reports_on);
|
||||||
|
}
|
||||||
|
let classifier_on = !matches!(classifier.model, SpamClassifierModel::Disabled);
|
||||||
|
facts
|
||||||
|
.collected
|
||||||
|
.insert("x:SpamTrainingSample".into(), classifier_on);
|
||||||
|
facts
|
||||||
|
.collected
|
||||||
|
.insert("spam-trainer-state".into(), classifier_on);
|
||||||
|
|
||||||
|
// Tracers
|
||||||
|
let (mut log_on, mut console_on, mut otel_on) = (false, false, false);
|
||||||
|
for tracer in self.registry().list::<Tracer>().await? {
|
||||||
|
match tracer.object {
|
||||||
|
Tracer::Log(t) => log_on |= t.enable,
|
||||||
|
Tracer::Stdout(t) => console_on |= t.enable,
|
||||||
|
Tracer::Journal(t) => console_on |= t.enable,
|
||||||
|
Tracer::OtelHttp(t) if t.enable => {
|
||||||
|
otel_on = true;
|
||||||
|
endpoint(&mut facts, "otel-tracer", t.endpoint);
|
||||||
|
}
|
||||||
|
Tracer::OtelGrpc(t) if t.enable => {
|
||||||
|
otel_on = true;
|
||||||
|
endpoint(&mut facts, "otel-tracer", t.endpoint.unwrap_or_default());
|
||||||
|
}
|
||||||
|
_ => {}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
facts.collected.insert("log-file".into(), log_on);
|
||||||
|
facts.collected.insert("x:Log".into(), log_on);
|
||||||
|
facts.collected.insert("console-and-journal".into(), console_on);
|
||||||
|
facts.collected.insert("otel-tracer".into(), otel_on);
|
||||||
|
|
||||||
|
// Webhooks
|
||||||
|
let mut hooks_on = false;
|
||||||
|
for hook in self.registry().list::<WebHook>().await? {
|
||||||
|
if hook.object.enable {
|
||||||
|
hooks_on = true;
|
||||||
|
endpoint(&mut facts, "webhooks", hook.object.url);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
facts.collected.insert("webhooks".into(), hooks_on);
|
||||||
|
|
||||||
|
// AI: the classifier's model, and Explain's
|
||||||
|
let models = self.registry().list::<AiModel>().await?;
|
||||||
|
let model_url = |id: Id| {
|
||||||
|
models
|
||||||
|
.iter()
|
||||||
|
.find(|m| Id::from(m.id.id()) == id)
|
||||||
|
.map(|m| m.object.url.clone())
|
||||||
|
};
|
||||||
|
let llm_on = match self.singleton::<SpamLlm>().await? {
|
||||||
|
SpamLlm::Enable(props) => {
|
||||||
|
if let Some(url) = model_url(props.model_id) {
|
||||||
|
endpoint(&mut facts, "spam-llm", url);
|
||||||
|
}
|
||||||
|
true
|
||||||
|
}
|
||||||
|
SpamLlm::Disable => false,
|
||||||
|
};
|
||||||
|
facts.collected.insert("spam-llm".into(), llm_on);
|
||||||
|
let limits = self.ai_limits().await;
|
||||||
|
let explain = self.ai_explain_model(&limits).await;
|
||||||
|
if let Some((_, model)) = &explain {
|
||||||
|
endpoint(&mut facts, "inbuxa:Explanation", model.url.clone());
|
||||||
|
}
|
||||||
|
facts
|
||||||
|
.collected
|
||||||
|
.insert("explain-cache".into(), explain.is_some());
|
||||||
|
facts
|
||||||
|
.collected
|
||||||
|
.insert("inbuxa:Explanation".into(), explain.is_some());
|
||||||
|
|
||||||
|
// Spam lookups off the host
|
||||||
|
let mut dnsbl_on = false;
|
||||||
|
for server in self.registry().list::<SpamDnsblServer>().await? {
|
||||||
|
let value = serde_json::to_value(&server.object).unwrap_or_default();
|
||||||
|
if value.get("enable").and_then(Value::as_bool).unwrap_or(false) {
|
||||||
|
dnsbl_on = true;
|
||||||
|
for zone in value.get("zone").map(zone_hosts).unwrap_or_default() {
|
||||||
|
endpoint(&mut facts, "spam-dnsbl", zone);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
facts.collected.insert("spam-dnsbl".into(), dnsbl_on);
|
||||||
|
let pyzor = self.singleton::<SpamPyzor>().await?;
|
||||||
|
if pyzor.enable {
|
||||||
|
endpoint(&mut facts, "spam-pyzor", format!("{}:{}", pyzor.host, pyzor.port));
|
||||||
|
}
|
||||||
|
facts.collected.insert("spam-pyzor".into(), pyzor.enable);
|
||||||
|
|
||||||
|
// Mail handed to others
|
||||||
|
let mut hooks = false;
|
||||||
|
for milter in self.registry().list::<MtaMilter>().await? {
|
||||||
|
hooks = true;
|
||||||
|
endpoint(
|
||||||
|
&mut facts,
|
||||||
|
"mta-milter-and-hooks",
|
||||||
|
format!("{}:{}", milter.object.hostname, milter.object.port),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
for hook in self.registry().list::<MtaHook>().await? {
|
||||||
|
hooks = true;
|
||||||
|
endpoint(&mut facts, "mta-milter-and-hooks", hook.object.url);
|
||||||
|
}
|
||||||
|
facts.collected.insert("mta-milter-and-hooks".into(), hooks);
|
||||||
|
let mut relays = false;
|
||||||
|
for route in self.registry().list::<MtaRoute>().await? {
|
||||||
|
if let MtaRoute::Relay(relay) = route.object {
|
||||||
|
relays = true;
|
||||||
|
endpoint(&mut facts, "relay", format!("{}:{}", relay.address, relay.port));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
facts.collected.insert("relay".into(), relays);
|
||||||
|
|
||||||
|
// Stores elsewhere
|
||||||
|
let stores = [
|
||||||
|
("data-store", serde_json::to_value(self.singleton::<DataStore>().await.ok()).unwrap_or_default()),
|
||||||
|
("blob-store", serde_json::to_value(self.singleton::<BlobStore>().await?).unwrap_or_default()),
|
||||||
|
("search-store", serde_json::to_value(self.singleton::<SearchStore>().await?).unwrap_or_default()),
|
||||||
|
("in-memory-store", serde_json::to_value(self.singleton::<InMemoryStore>().await?).unwrap_or_default()),
|
||||||
|
];
|
||||||
|
for (place, value) in stores {
|
||||||
|
if let Some(host) = remote_host(&value) {
|
||||||
|
facts.remote_stores.insert(place.into(), host);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if let Some(host) = remote_host(&serde_json::to_value(&tracing).unwrap_or_default()) {
|
||||||
|
for id in ["x:Trace", "x:TraceEvent", "x:TraceKeyValue", "x:TraceValueIpAddr", "x:TraceValueString"] {
|
||||||
|
endpoint(&mut facts, id, host.clone());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok(facts)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The server's inventory, or a tenant's slice of it.
|
||||||
|
pub async fn data_inventory(&self, tenant_only: bool) -> trc::Result<Inventory> {
|
||||||
|
let facts = self.privacy_facts().await?;
|
||||||
|
Ok(privacy::evaluate(privacy::catalog(), &facts, tenant_only))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Records a snapshot of the server's inventory if it differs from the
|
||||||
|
/// newest one, or if there is none: the history shows when what the
|
||||||
|
/// server holds changed, not a copy a day. Returns whether it recorded.
|
||||||
|
pub async fn inventory_snapshot(&self, trigger: Trigger) -> trc::Result<bool> {
|
||||||
|
let data = &self.core.storage.data;
|
||||||
|
let inventory = self.data_inventory(false).await?;
|
||||||
|
if let Some(latest) = snapshot::latest(data).await?
|
||||||
|
&& let Some(previous) = snapshot::get(data, latest).await?
|
||||||
|
&& previous.inventory == inventory
|
||||||
|
{
|
||||||
|
return Ok(false);
|
||||||
|
}
|
||||||
|
snapshot::record(
|
||||||
|
data,
|
||||||
|
&Snapshot {
|
||||||
|
taken_at: store::write::now(),
|
||||||
|
trigger,
|
||||||
|
summary: inventory.summary(),
|
||||||
|
inventory,
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await?;
|
||||||
|
Ok(true)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A snapshot after a registry write, when the object is one the
|
||||||
|
/// inventory reads. Failures are logged: a snapshot is history, not
|
||||||
|
/// worth failing the write over.
|
||||||
|
pub async fn inventory_snapshot_after(&self, object: &str) {
|
||||||
|
if !INVENTORY_OBJECTS.contains(&object) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if let Err(err) = self
|
||||||
|
.inventory_snapshot(Trigger::SettingChanged {
|
||||||
|
setting: object.to_string(),
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
{
|
||||||
|
trc::error!(err.details("Failed to record an inventory snapshot"));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Removes snapshots past the audit log's retention (settled
|
||||||
|
/// 2026-09-28: snapshots are kept as long as audit records).
|
||||||
|
pub async fn purge_inventory_snapshots(&self) -> trc::Result<usize> {
|
||||||
|
let data = &self.core.storage.data;
|
||||||
|
let keep = inbuxa_features::audit::log::settings(data).await?.keep_for_secs;
|
||||||
|
snapshot::purge(data, store::write::now().saturating_sub(keep)).await
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
use serde_json::json;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn local_stores_stay_and_others_name_their_host() {
|
||||||
|
assert_eq!(remote_host(&json!({"@type": "RocksDb", "path": "/var/lib"})), None);
|
||||||
|
assert_eq!(remote_host(&json!({"@type": "Default"})), None);
|
||||||
|
assert_eq!(
|
||||||
|
remote_host(&json!({"@type": "PostgreSql", "host": "db.example.net"})),
|
||||||
|
Some("db.example.net".into())
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
remote_host(&json!({"@type": "ElasticSearch", "url": "https://es.example.net:9200"})),
|
||||||
|
Some("https://es.example.net:9200".into())
|
||||||
|
);
|
||||||
|
assert_eq!(remote_host(&json!({"@type": "S3", "bucket": "mail"})), Some("S3".into()));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn zones_come_from_every_branch() {
|
||||||
|
let zone = json!({"else": "false", "match": {"0": {"if": "location == 'tcp'",
|
||||||
|
"then": "ip_reverse + '.rep.mailspike.net'"}}});
|
||||||
|
assert_eq!(zone_hosts(&zone), vec!["rep.mailspike.net"]);
|
||||||
|
let zone = json!({"else": "hash(email, 'sha1') + '.ebl.msbl.org'", "match": {}});
|
||||||
|
assert_eq!(zone_hosts(&zone), vec!["ebl.msbl.org"], "not 'sha1'");
|
||||||
|
assert!(zone_hosts(&json!({"else": "false"})).is_empty());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn days_round_up() {
|
||||||
|
assert_eq!(days(Some(&Duration::from_millis(86_400_000))), Days::Days(1));
|
||||||
|
assert_eq!(days(Some(&Duration::from_millis(3_600_000))), Days::Days(1));
|
||||||
|
assert_eq!(days(None), Days::Unbounded);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,293 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! Whether the outside world can reach each node's ports (settings-reorg,
|
||||||
|
//! Ports: the reachability check).
|
||||||
|
//!
|
||||||
|
//! A server can't answer this about itself: a connection to its own public
|
||||||
|
//! address never leaves the machine, so it passes whatever the firewall in
|
||||||
|
//! front says. In a cluster the other nodes are outside that machine. Every
|
||||||
|
//! ten minutes each node resolves every other active node's hostname, as a
|
||||||
|
//! sender would, and tries a TCP connection to each listener port on each
|
||||||
|
//! address. What it saw goes in the shared in-memory store for an hour, under
|
||||||
|
//! (target, prober), so whichever node the admin asks can report it all.
|
||||||
|
//!
|
||||||
|
//! A single server has no one outside to ask. It reports only whether each
|
||||||
|
//! port is listening, and says so.
|
||||||
|
//!
|
||||||
|
//! A connection is all that's tried: nothing is sent, so no protocol logs a
|
||||||
|
//! session and no rate limit counts it.
|
||||||
|
|
||||||
|
use crate::{KV_PORT_REACHABILITY, Server};
|
||||||
|
use registry::schema::{enums::ClusterNodeStatus, structs::NetworkListener};
|
||||||
|
use serde::{Deserialize, Serialize};
|
||||||
|
use serde_json::{Value, json};
|
||||||
|
use std::{
|
||||||
|
collections::BTreeSet,
|
||||||
|
net::{IpAddr, Ipv4Addr, Ipv6Addr, SocketAddr},
|
||||||
|
time::{Duration, Instant},
|
||||||
|
};
|
||||||
|
use store::{dispatch::lookup::KeyValue, write::now};
|
||||||
|
|
||||||
|
/// How often each node probes the others.
|
||||||
|
pub const PROBE_INTERVAL: Duration = Duration::from_secs(600);
|
||||||
|
/// How long one node's view of another is kept: long enough to span a missed round.
|
||||||
|
const KEEP_FOR: u64 = 3600;
|
||||||
|
const CONNECT_TIMEOUT: Duration = Duration::from_secs(5);
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
|
||||||
|
pub struct Probe {
|
||||||
|
pub port: u16,
|
||||||
|
pub address: String,
|
||||||
|
pub ok: bool,
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub error: Option<String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
|
||||||
|
pub struct Report {
|
||||||
|
/// Unix seconds.
|
||||||
|
pub checked_at: u64,
|
||||||
|
pub probes: Vec<Probe>,
|
||||||
|
/// The hostname didn't resolve, so nothing could be tried.
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub error: Option<String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The ports a sender or client could reach: every listener's port, leaving
|
||||||
|
/// out listeners bound only to loopback, which are private by design.
|
||||||
|
pub fn public_ports<'x>(listeners: impl IntoIterator<Item = &'x NetworkListener>) -> Vec<u16> {
|
||||||
|
listeners
|
||||||
|
.into_iter()
|
||||||
|
.flat_map(|l| l.bind.iter())
|
||||||
|
.map(|addr| addr.0)
|
||||||
|
.filter(|addr| !addr.ip().is_loopback())
|
||||||
|
.map(|addr| addr.port())
|
||||||
|
.collect::<BTreeSet<_>>()
|
||||||
|
.into_iter()
|
||||||
|
.collect()
|
||||||
|
}
|
||||||
|
|
||||||
|
fn key(target: &str, prober: &str) -> Vec<u8> {
|
||||||
|
format!("{target}\n{prober}").into_bytes()
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn connect(address: SocketAddr) -> Result<(), String> {
|
||||||
|
match tokio::time::timeout(CONNECT_TIMEOUT, tokio::net::TcpStream::connect(address)).await {
|
||||||
|
Ok(Ok(_)) => Ok(()),
|
||||||
|
Ok(Err(err)) => Err(err.to_string()),
|
||||||
|
Err(_) => Err("no answer within 5 seconds".into()),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Tries each port on each address `hostname` resolves to.
|
||||||
|
pub async fn probe_host(hostname: &str, ports: &[u16]) -> Report {
|
||||||
|
let checked_at = now();
|
||||||
|
let addresses = match tokio::net::lookup_host((hostname, 0)).await {
|
||||||
|
Ok(found) => found.map(|a| a.ip()).collect::<BTreeSet<_>>(),
|
||||||
|
Err(err) => {
|
||||||
|
return Report {
|
||||||
|
checked_at,
|
||||||
|
probes: vec![],
|
||||||
|
error: Some(format!("{hostname} doesn't resolve: {err}")),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
};
|
||||||
|
let tries = addresses.iter().flat_map(|ip| {
|
||||||
|
ports.iter().map(move |port| {
|
||||||
|
let address = SocketAddr::new(*ip, *port);
|
||||||
|
async move {
|
||||||
|
let result = connect(address).await;
|
||||||
|
Probe {
|
||||||
|
port: *port,
|
||||||
|
address: ip.to_string(),
|
||||||
|
ok: result.is_ok(),
|
||||||
|
error: result.err(),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
})
|
||||||
|
});
|
||||||
|
Report {
|
||||||
|
checked_at,
|
||||||
|
probes: futures::future::join_all(tries).await,
|
||||||
|
error: None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn listeners(server: &Server) -> trc::Result<Vec<NetworkListener>> {
|
||||||
|
Ok(server
|
||||||
|
.registry()
|
||||||
|
.list::<NetworkListener>()
|
||||||
|
.await?
|
||||||
|
.into_iter()
|
||||||
|
.map(|l| l.object)
|
||||||
|
.collect())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Where to knock to see a port listening on this machine: the bound
|
||||||
|
/// address, or loopback of the same family for a wildcard bind.
|
||||||
|
pub fn local_targets<'x>(
|
||||||
|
listeners: impl IntoIterator<Item = &'x NetworkListener>,
|
||||||
|
) -> Vec<SocketAddr> {
|
||||||
|
listeners
|
||||||
|
.into_iter()
|
||||||
|
.flat_map(|l| l.bind.iter())
|
||||||
|
.map(|addr| addr.0)
|
||||||
|
.filter(|addr| !addr.ip().is_loopback())
|
||||||
|
.map(|addr| match addr.ip() {
|
||||||
|
IpAddr::V4(ip) if ip.is_unspecified() => {
|
||||||
|
SocketAddr::new(Ipv4Addr::LOCALHOST.into(), addr.port())
|
||||||
|
}
|
||||||
|
IpAddr::V6(ip) if ip.is_unspecified() => {
|
||||||
|
SocketAddr::new(Ipv6Addr::LOCALHOST.into(), addr.port())
|
||||||
|
}
|
||||||
|
_ => addr,
|
||||||
|
})
|
||||||
|
.collect::<BTreeSet<_>>()
|
||||||
|
.into_iter()
|
||||||
|
.collect()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// One round: this node probes every other active node and records what it saw.
|
||||||
|
pub async fn probe_peers(server: &Server) -> trc::Result<()> {
|
||||||
|
let nodes = server.registry().cluster_node_list().await?;
|
||||||
|
let me = server.registry().node_id() as u64;
|
||||||
|
let Some(prober) = nodes
|
||||||
|
.iter()
|
||||||
|
.find(|n| n.node_id == me)
|
||||||
|
.map(|n| n.hostname.clone())
|
||||||
|
else {
|
||||||
|
return Ok(());
|
||||||
|
};
|
||||||
|
let ports = public_ports(&listeners(server).await?);
|
||||||
|
for target in nodes.iter().filter(|n| {
|
||||||
|
n.node_id != me && n.status == ClusterNodeStatus::Active && n.hostname != prober
|
||||||
|
}) {
|
||||||
|
let report = probe_host(&target.hostname, &ports).await;
|
||||||
|
server
|
||||||
|
.in_memory_store()
|
||||||
|
.key_set(
|
||||||
|
KeyValue::with_prefix(
|
||||||
|
KV_PORT_REACHABILITY,
|
||||||
|
key(&target.hostname, &prober),
|
||||||
|
serde_json::to_vec(&report).unwrap_or_default(),
|
||||||
|
)
|
||||||
|
.expires(KEEP_FOR),
|
||||||
|
)
|
||||||
|
.await?;
|
||||||
|
}
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// What `GET /api/ports/check` answers.
|
||||||
|
pub async fn report(server: &Server) -> trc::Result<Value> {
|
||||||
|
let listeners = listeners(server).await?;
|
||||||
|
let ports = public_ports(&listeners);
|
||||||
|
let nodes = if server.core.storage.coordinator.is_enabled() {
|
||||||
|
server.registry().cluster_node_list().await?
|
||||||
|
} else {
|
||||||
|
vec![]
|
||||||
|
};
|
||||||
|
let active = nodes
|
||||||
|
.iter()
|
||||||
|
.filter(|n| n.status == ClusterNodeStatus::Active)
|
||||||
|
.collect::<Vec<_>>();
|
||||||
|
|
||||||
|
if active.len() < 2 {
|
||||||
|
// No one outside to ask: only whether each port is listening here.
|
||||||
|
let started = Instant::now();
|
||||||
|
let listening = futures::future::join_all(local_targets(&listeners).into_iter().map(
|
||||||
|
|address| async move {
|
||||||
|
let result = connect(address).await;
|
||||||
|
json!({ "port": address.port(), "address": address.ip().to_string(), "listening": result.is_ok() })
|
||||||
|
},
|
||||||
|
))
|
||||||
|
.await;
|
||||||
|
return Ok(json!({
|
||||||
|
"mode": "local",
|
||||||
|
"ports": ports,
|
||||||
|
"listening": listening,
|
||||||
|
"ms": started.elapsed().as_millis() as u64,
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
|
||||||
|
let mut out = Vec::new();
|
||||||
|
for target in &active {
|
||||||
|
let mut seen_by = Vec::new();
|
||||||
|
for prober in active.iter().filter(|p| p.node_id != target.node_id) {
|
||||||
|
let stored = server
|
||||||
|
.in_memory_store()
|
||||||
|
.key_get::<String>(KeyValue::<()>::build_key(
|
||||||
|
KV_PORT_REACHABILITY,
|
||||||
|
key(&target.hostname, &prober.hostname),
|
||||||
|
))
|
||||||
|
.await?;
|
||||||
|
let report = stored.and_then(|raw| serde_json::from_str::<Report>(&raw).ok());
|
||||||
|
seen_by.push(json!({ "prober": prober.hostname, "report": report }));
|
||||||
|
}
|
||||||
|
out.push(json!({ "hostname": target.hostname, "seenBy": seen_by }));
|
||||||
|
}
|
||||||
|
Ok(json!({
|
||||||
|
"mode": "cluster",
|
||||||
|
"ports": ports,
|
||||||
|
"intervalSeconds": PROBE_INTERVAL.as_secs(),
|
||||||
|
"nodes": out,
|
||||||
|
}))
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
fn listener(binds: &[&str]) -> NetworkListener {
|
||||||
|
NetworkListener {
|
||||||
|
bind: registry::schema::prelude::Map::new(
|
||||||
|
binds.iter().map(|b| b.parse().unwrap()).collect(),
|
||||||
|
),
|
||||||
|
..Default::default()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn public_ports_leave_out_loopback_only_listeners() {
|
||||||
|
let listeners = [
|
||||||
|
listener(&["[::]:25"]),
|
||||||
|
listener(&["0.0.0.0:993", "[::]:993"]),
|
||||||
|
listener(&["127.0.0.1:8080"]),
|
||||||
|
listener(&["203.0.113.5:465"]),
|
||||||
|
];
|
||||||
|
assert_eq!(public_ports(listeners.iter()), vec![25, 465, 993]);
|
||||||
|
assert_eq!(
|
||||||
|
local_targets(listeners.iter())
|
||||||
|
.iter()
|
||||||
|
.map(ToString::to_string)
|
||||||
|
.collect::<Vec<_>>(),
|
||||||
|
vec!["127.0.0.1:993", "203.0.113.5:465", "[::1]:25", "[::1]:993"]
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn probe_host_reports_open_and_closed_ports() {
|
||||||
|
let open = tokio::net::TcpListener::bind("127.0.0.1:0").await.unwrap();
|
||||||
|
let open_port = open.local_addr().unwrap().port();
|
||||||
|
let closed_port = {
|
||||||
|
let l = std::net::TcpListener::bind("127.0.0.1:0").unwrap();
|
||||||
|
l.local_addr().unwrap().port()
|
||||||
|
};
|
||||||
|
let report = probe_host("127.0.0.1", &[open_port, closed_port]).await;
|
||||||
|
assert_eq!(report.error, None);
|
||||||
|
let ok = |port| report.probes.iter().find(|p| p.port == port).unwrap().ok;
|
||||||
|
assert!(ok(open_port));
|
||||||
|
assert!(!ok(closed_port));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn probe_host_says_when_a_name_does_not_resolve() {
|
||||||
|
let report = probe_host("does-not-exist.invalid", &[25]).await;
|
||||||
|
assert!(report.probes.is_empty());
|
||||||
|
assert!(report.error.unwrap().contains("doesn't resolve"));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
@@ -104,14 +104,31 @@ impl StoredMetric {
|
|||||||
pub fn timestamp(&self) -> u64 {
|
pub fn timestamp(&self) -> u64 {
|
||||||
SnowflakeIdGenerator::to_timestamp(self.id)
|
SnowflakeIdGenerator::to_timestamp(self.id)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// The node that wrote the sample. Histogram totals are per node, so a
|
||||||
|
/// reader diffs them per node.
|
||||||
|
pub fn node_id(&self) -> u64 {
|
||||||
|
SnowflakeIdGenerator::to_node_id(self.id)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/// What the node wrote last, so counters and histograms are written as
|
/// What the node wrote last, so counters and histograms are written as
|
||||||
/// changes (MON-4). Per process: a restart counts from the start.
|
/// changes (MON-4). Per process: a restart counts from the start.
|
||||||
static LAST: Mutex<Option<AHashMap<MetricType, (u64, u64)>>> = Mutex::new(None);
|
static LAST: Mutex<Option<AHashMap<MetricType, (u64, u64)>>> = Mutex::new(None);
|
||||||
|
|
||||||
/// One tick's samples (MON-4 to MON-6).
|
/// Gauges that count the whole cluster's data, not this node's. Only the node
|
||||||
pub fn sample() -> Vec<Metric> {
|
/// that computes them (the metrics-calculation role) has a true reading; on
|
||||||
|
/// the others the queue gauge only moves with local queue events and drifts
|
||||||
|
/// below zero, and the account and domain counts stay at 0.
|
||||||
|
const CLUSTER_GAUGES: [MetricType; 3] = [
|
||||||
|
MetricType::QueueCount,
|
||||||
|
MetricType::UserCount,
|
||||||
|
MetricType::DomainCount,
|
||||||
|
];
|
||||||
|
|
||||||
|
/// One tick's samples (MON-4 to MON-6). `calculates` is whether this node
|
||||||
|
/// computes the cluster-wide gauges; a node that doesn't leaves them out.
|
||||||
|
pub fn sample(calculates: bool) -> Vec<Metric> {
|
||||||
let mut last_guard = LAST.lock().unwrap();
|
let mut last_guard = LAST.lock().unwrap();
|
||||||
let last = last_guard.get_or_insert_with(AHashMap::new);
|
let last = last_guard.get_or_insert_with(AHashMap::new);
|
||||||
let mut samples = Vec::new();
|
let mut samples = Vec::new();
|
||||||
@@ -134,6 +151,9 @@ pub fn sample() -> Vec<Metric> {
|
|||||||
|
|
||||||
// Gauges: the reading, always (MON-5)
|
// Gauges: the reading, always (MON-5)
|
||||||
for gauge in Collector::collect_gauges() {
|
for gauge in Collector::collect_gauges() {
|
||||||
|
if !calculates && CLUSTER_GAUGES.contains(&gauge.id()) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
samples.push(Metric::Gauge(MetricCount {
|
samples.push(Metric::Gauge(MetricCount {
|
||||||
count: gauge.get(),
|
count: gauge.get(),
|
||||||
metric: gauge.id(),
|
metric: gauge.id(),
|
||||||
@@ -175,7 +195,7 @@ impl Server {
|
|||||||
if store.is_none() {
|
if store.is_none() {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
let samples = sample();
|
let samples = sample(self.core.network.roles.metrics_calculate);
|
||||||
let count = samples.len();
|
let count = samples.len();
|
||||||
let started = std::time::Instant::now();
|
let started = std::time::Instant::now();
|
||||||
match store.write_metrics(samples, now()).await {
|
match store.write_metrics(samples, now()).await {
|
||||||
@@ -265,3 +285,41 @@ impl Server {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
fn gauges(samples: &[Metric]) -> Vec<MetricType> {
|
||||||
|
samples
|
||||||
|
.iter()
|
||||||
|
.filter_map(|m| match m {
|
||||||
|
Metric::Gauge(g) => Some(g.metric),
|
||||||
|
_ => None,
|
||||||
|
})
|
||||||
|
.collect()
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn only_the_calculating_node_stores_cluster_gauges() {
|
||||||
|
let all = gauges(&sample(true));
|
||||||
|
let local = gauges(&sample(false));
|
||||||
|
for metric in CLUSTER_GAUGES {
|
||||||
|
assert!(
|
||||||
|
all.contains(&metric),
|
||||||
|
"{metric:?} missing on the calculating node"
|
||||||
|
);
|
||||||
|
assert!(
|
||||||
|
!local.contains(&metric),
|
||||||
|
"{metric:?} stored by a node that doesn't compute it"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
// Per-node gauges are stored either way
|
||||||
|
for metric in [MetricType::ServerMemory, MetricType::HttpActiveConnections] {
|
||||||
|
assert!(
|
||||||
|
all.contains(&metric) && local.contains(&metric),
|
||||||
|
"{metric:?}"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -156,15 +156,7 @@ async fn post_webhook_events(
|
|||||||
|
|
||||||
// Add HMAC-SHA256 signature
|
// Add HMAC-SHA256 signature
|
||||||
let mut headers = settings.headers.clone();
|
let mut headers = settings.headers.clone();
|
||||||
if !settings.key.is_empty() {
|
sign(&mut headers, &settings.key, &body);
|
||||||
let key = hmac::Key::new(hmac::HMAC_SHA256, settings.key.as_bytes());
|
|
||||||
let tag = hmac::sign(&key, body.as_bytes());
|
|
||||||
|
|
||||||
headers.insert(
|
|
||||||
"X-Signature",
|
|
||||||
STANDARD.encode(tag.as_ref()).parse().unwrap(),
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
// Send request
|
// Send request
|
||||||
let response = settings
|
let response = settings
|
||||||
@@ -188,3 +180,150 @@ async fn post_webhook_events(
|
|||||||
))
|
))
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Adds the HMAC-SHA256 `X-Signature` a receiver checks, when the webhook has a key.
|
||||||
|
fn sign(headers: &mut hyper::HeaderMap, key: &str, body: &str) {
|
||||||
|
if !key.is_empty() {
|
||||||
|
let key = hmac::Key::new(hmac::HMAC_SHA256, key.as_bytes());
|
||||||
|
let tag = hmac::sign(&key, body.as_bytes());
|
||||||
|
|
||||||
|
headers.insert(
|
||||||
|
"X-Signature",
|
||||||
|
STANDARD.encode(tag.as_ref()).parse().unwrap(),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// inbuxa: "Send test" for a saved webhook (settings-reorg, Webhooks). One
|
||||||
|
/// sample event, sent the way a real batch is: the same URL, headers, sign-in,
|
||||||
|
/// signature, timeout and certificate checks. The event's type,
|
||||||
|
/// `webhook.test`, is none the server raises, and an `X-Inbuxa-Test` header
|
||||||
|
/// marks it, so a receiver can tell it apart. Answers the HTTP status, or why
|
||||||
|
/// nothing came back.
|
||||||
|
pub async fn send_test(hook: ®istry::schema::structs::WebHook) -> Result<u16, String> {
|
||||||
|
let mut headers = hook
|
||||||
|
.http_auth
|
||||||
|
.build_headers(hook.http_headers.clone(), "application/json".into())
|
||||||
|
.await
|
||||||
|
.map_err(|err| format!("Unable to build HTTP headers: {err}"))?;
|
||||||
|
let key = hook
|
||||||
|
.signature_key
|
||||||
|
.secret()
|
||||||
|
.await
|
||||||
|
.map_err(|err| format!("Unable to retrieve signature key: {err}"))?
|
||||||
|
.unwrap_or_default()
|
||||||
|
.into_owned();
|
||||||
|
|
||||||
|
let created = now();
|
||||||
|
let body = serde_json::json!({
|
||||||
|
"events": [{
|
||||||
|
"id": format!("test-{created}"),
|
||||||
|
"createdAt": mail_parser::DateTime::from_timestamp(created as i64).to_rfc3339(),
|
||||||
|
"type": "webhook.test",
|
||||||
|
"data": { "details": "A test from inbuxa Admin. Nothing happened on the server." },
|
||||||
|
}]
|
||||||
|
})
|
||||||
|
.to_string();
|
||||||
|
sign(&mut headers, &key, &body);
|
||||||
|
headers.insert("X-Inbuxa-Test", "true".parse().unwrap());
|
||||||
|
|
||||||
|
let response = utils::http::http_client_builder(hook.allow_invalid_certs)
|
||||||
|
.build()
|
||||||
|
.map_err(|err| format!("Unable to build an HTTP client: {err}"))?
|
||||||
|
.post(&hook.url)
|
||||||
|
.timeout(hook.timeout.into_inner())
|
||||||
|
.headers(headers)
|
||||||
|
.body(body)
|
||||||
|
.send()
|
||||||
|
.await
|
||||||
|
.map_err(|err| format!("Webhook request to {} failed: {err}", hook.url))?;
|
||||||
|
Ok(response.status().as_u16())
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
use registry::schema::structs::{SecretKeyOptional, SecretKeyValue, WebHook};
|
||||||
|
use tokio::io::{AsyncReadExt, AsyncWriteExt};
|
||||||
|
|
||||||
|
/// One request in, the given status out; hands back what was received.
|
||||||
|
async fn receiver(status: &'static str) -> (String, tokio::task::JoinHandle<String>) {
|
||||||
|
let listener = tokio::net::TcpListener::bind("127.0.0.1:0").await.unwrap();
|
||||||
|
let url = format!("http://{}/hook", listener.local_addr().unwrap());
|
||||||
|
let task = tokio::spawn(async move {
|
||||||
|
let (mut socket, _) = listener.accept().await.unwrap();
|
||||||
|
let mut buf = Vec::new();
|
||||||
|
let mut chunk = [0u8; 4096];
|
||||||
|
loop {
|
||||||
|
let n = socket.read(&mut chunk).await.unwrap();
|
||||||
|
buf.extend_from_slice(&chunk[..n]);
|
||||||
|
let text = String::from_utf8_lossy(&buf);
|
||||||
|
if let Some(end) = text.find("\r\n\r\n") {
|
||||||
|
let length = text[..end]
|
||||||
|
.lines()
|
||||||
|
.find_map(|l| {
|
||||||
|
l.to_ascii_lowercase()
|
||||||
|
.strip_prefix("content-length:")
|
||||||
|
.map(|v| v.trim().parse::<usize>().unwrap())
|
||||||
|
})
|
||||||
|
.unwrap_or(0);
|
||||||
|
if buf.len() >= end + 4 + length || n == 0 {
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
socket
|
||||||
|
.write_all(
|
||||||
|
format!("HTTP/1.1 {status}\r\ncontent-length: 0\r\nconnection: close\r\n\r\n")
|
||||||
|
.as_bytes(),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
String::from_utf8_lossy(&buf).into_owned()
|
||||||
|
});
|
||||||
|
(url, task)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn send_test_signs_and_marks_the_sample() {
|
||||||
|
let (url, task) = receiver("204 No Content").await;
|
||||||
|
let hook = WebHook {
|
||||||
|
url,
|
||||||
|
enable: false,
|
||||||
|
signature_key: SecretKeyOptional::Value(SecretKeyValue { secret: "k".into() }),
|
||||||
|
..Default::default()
|
||||||
|
};
|
||||||
|
assert_eq!(send_test(&hook).await, Ok(204));
|
||||||
|
|
||||||
|
let request = task.await.unwrap();
|
||||||
|
let (head, body) = request.split_once("\r\n\r\n").unwrap();
|
||||||
|
let head = head.to_ascii_lowercase();
|
||||||
|
assert!(head.contains("x-inbuxa-test: true"), "{head}");
|
||||||
|
let parsed: serde_json::Value = serde_json::from_str(body).unwrap();
|
||||||
|
assert_eq!(parsed["events"][0]["type"], "webhook.test");
|
||||||
|
let tag = hmac::sign(&hmac::Key::new(hmac::HMAC_SHA256, b"k"), body.as_bytes());
|
||||||
|
assert!(
|
||||||
|
head.contains(&format!(
|
||||||
|
"x-signature: {}",
|
||||||
|
STANDARD.encode(tag.as_ref()).to_ascii_lowercase()
|
||||||
|
)),
|
||||||
|
"{head}"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn send_test_reports_what_came_back() {
|
||||||
|
let (url, _task) = receiver("403 Forbidden").await;
|
||||||
|
let hook = WebHook {
|
||||||
|
url,
|
||||||
|
..Default::default()
|
||||||
|
};
|
||||||
|
assert_eq!(send_test(&hook).await, Ok(403));
|
||||||
|
|
||||||
|
let hook = WebHook {
|
||||||
|
url: "http://127.0.0.1:9/hook".into(),
|
||||||
|
..Default::default()
|
||||||
|
};
|
||||||
|
assert!(send_test(&hook).await.unwrap_err().contains("failed"));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "coordinator"
|
name = "coordinator"
|
||||||
version = "0.16.23"
|
version = "0.16.25"
|
||||||
edition = "2024"
|
edition = "2024"
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "dav-proto"
|
name = "dav-proto"
|
||||||
version = "0.16.23"
|
version = "0.16.25"
|
||||||
edition = "2024"
|
edition = "2024"
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "dav"
|
name = "dav"
|
||||||
version = "0.16.23"
|
version = "0.16.25"
|
||||||
edition = "2024"
|
edition = "2024"
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
|
|||||||
@@ -133,6 +133,10 @@ impl DavAclHandler for Server {
|
|||||||
{
|
{
|
||||||
return Err(DavError::Code(StatusCode::FORBIDDEN));
|
return Err(DavError::Code(StatusCode::FORBIDDEN));
|
||||||
}
|
}
|
||||||
|
// inbuxa: MA-D0: a group's members don't share what it owns on.
|
||||||
|
if access_token.is_group_member_only(account_id) {
|
||||||
|
return Err(DavError::Code(StatusCode::FORBIDDEN));
|
||||||
|
}
|
||||||
|
|
||||||
// Validate ACEs
|
// Validate ACEs
|
||||||
let grants = self
|
let grants = self
|
||||||
@@ -565,7 +569,13 @@ impl Privileges for AccessToken {
|
|||||||
grants: &ArchivedVec<ArchivedAclGrant>,
|
grants: &ArchivedVec<ArchivedAclGrant>,
|
||||||
is_calendar: bool,
|
is_calendar: bool,
|
||||||
) -> Vec<Privilege> {
|
) -> Vec<Privilege> {
|
||||||
if self.is_member(account_id) {
|
if self.is_group_member_only(account_id) {
|
||||||
|
// inbuxa: MA-D0: everything but sharing it on.
|
||||||
|
Privilege::all(is_calendar)
|
||||||
|
.into_iter()
|
||||||
|
.filter(|privilege| !matches!(privilege, Privilege::All | Privilege::WriteAcl))
|
||||||
|
.collect()
|
||||||
|
} else if self.is_member(account_id) {
|
||||||
Privilege::all(is_calendar)
|
Privilege::all(is_calendar)
|
||||||
} else {
|
} else {
|
||||||
current_user_privilege_set(grants.effective_acl(self))
|
current_user_privilege_set(grants.effective_acl(self))
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "directory"
|
name = "directory"
|
||||||
version = "0.16.23"
|
version = "0.16.25"
|
||||||
edition = "2024"
|
edition = "2024"
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "email"
|
name = "email"
|
||||||
version = "0.16.23"
|
version = "0.16.25"
|
||||||
edition = "2024"
|
edition = "2024"
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -92,10 +92,8 @@ impl MailboxDestroy for Server {
|
|||||||
|
|
||||||
let mut deleted_ids = RoaringBitmap::new();
|
let mut deleted_ids = RoaringBitmap::new();
|
||||||
let mut thread_ids = RoaringBitmap::new();
|
let mut thread_ids = RoaringBitmap::new();
|
||||||
// inbuxa: UD-1, UD-6a: the retention in force now
|
// inbuxa: UD-1, UD-6a, LH-4: how this account's deletions are kept
|
||||||
let retention = inbuxa_features::undelete::settings::retention(self.registry())
|
let keeping = self.keeping(account_id).await?;
|
||||||
.await?
|
|
||||||
.items;
|
|
||||||
self.archives(
|
self.archives(
|
||||||
account_id,
|
account_id,
|
||||||
Collection::Email,
|
Collection::Email,
|
||||||
@@ -125,10 +123,10 @@ impl MailboxDestroy for Server {
|
|||||||
deleted_ids.insert(message_id);
|
deleted_ids.insert(message_id);
|
||||||
thread_ids.insert(prev_message_data.inner.thread_id.to_native());
|
thread_ids.insert(prev_message_data.inner.thread_id.to_native());
|
||||||
// inbuxa: UD-1, UD-4: a deleted message is noted for archiving
|
// inbuxa: UD-1, UD-4: a deleted message is noted for archiving
|
||||||
if let Some(retention) = retention {
|
if keeping.keeps_anything() {
|
||||||
inbuxa_features::undelete::email::note(
|
inbuxa_features::undelete::email::note(
|
||||||
&mut batch,
|
&mut batch,
|
||||||
retention,
|
&keeping,
|
||||||
account_id,
|
account_id,
|
||||||
message_id,
|
message_id,
|
||||||
prev_message_data.inner.size.to_native() as u64,
|
prev_message_data.inner.size.to_native() as u64,
|
||||||
|
|||||||
@@ -69,10 +69,8 @@ impl EmailDeletion for Server {
|
|||||||
batch
|
batch
|
||||||
.with_account_id(account_id)
|
.with_account_id(account_id)
|
||||||
.with_collection(Collection::Email);
|
.with_collection(Collection::Email);
|
||||||
// inbuxa: UD-1, UD-6a: the retention in force now
|
// inbuxa: UD-1, UD-6a, LH-4: how this account's deletions are kept
|
||||||
let retention = inbuxa_features::undelete::settings::retention(self.registry())
|
let keeping = self.keeping(account_id).await?;
|
||||||
.await?
|
|
||||||
.items;
|
|
||||||
self.archives(
|
self.archives(
|
||||||
account_id,
|
account_id,
|
||||||
Collection::Email,
|
Collection::Email,
|
||||||
@@ -90,10 +88,10 @@ impl EmailDeletion for Server {
|
|||||||
}
|
}
|
||||||
thread_ids.insert(metadata.inner.thread_id.to_native());
|
thread_ids.insert(metadata.inner.thread_id.to_native());
|
||||||
// inbuxa: UD-1, UD-4: a deleted message is noted for archiving
|
// inbuxa: UD-1, UD-4: a deleted message is noted for archiving
|
||||||
if let Some(retention) = retention {
|
if keeping.keeps_anything() {
|
||||||
inbuxa_features::undelete::email::note(
|
inbuxa_features::undelete::email::note(
|
||||||
batch,
|
batch,
|
||||||
retention,
|
&keeping,
|
||||||
account_id,
|
account_id,
|
||||||
document_id,
|
document_id,
|
||||||
metadata.inner.size.to_native() as u64,
|
metadata.inner.size.to_native() as u64,
|
||||||
|
|||||||
@@ -20,7 +20,7 @@ use groupware::{
|
|||||||
scheduling::{ItipError, ItipMessages},
|
scheduling::{ItipError, ItipMessages},
|
||||||
};
|
};
|
||||||
use mail_parser::{
|
use mail_parser::{
|
||||||
DateTime, Header, HeaderName, HeaderValue, Message, MessageParser, MimeHeaders, PartType,
|
Header, HeaderName, HeaderValue, Message, MessageParser, MimeHeaders, PartType,
|
||||||
parsers::fields::thread::thread_name,
|
parsers::fields::thread::thread_name,
|
||||||
};
|
};
|
||||||
use registry::{
|
use registry::{
|
||||||
@@ -924,11 +924,7 @@ impl EmailIngest for Server {
|
|||||||
span_id: u64,
|
span_id: u64,
|
||||||
) {
|
) {
|
||||||
if let Some(config) = &self.core.spam.classifier {
|
if let Some(config) = &self.core.spam.classifier {
|
||||||
let mut dt = DateTime::from_timestamp(now() as i64);
|
let until = now() + config.hold_samples_for;
|
||||||
dt.hour = 0;
|
|
||||||
dt.minute = 0;
|
|
||||||
dt.second = 0;
|
|
||||||
let until = dt.to_timestamp() as u64 + config.hold_samples_for;
|
|
||||||
|
|
||||||
let sample = SpamTrainingSample {
|
let sample = SpamTrainingSample {
|
||||||
account_id: Some(Id::from(account_id)),
|
account_id: Some(Id::from(account_id)),
|
||||||
|
|||||||
@@ -44,12 +44,12 @@ impl SieveScriptDelete for Server {
|
|||||||
))
|
))
|
||||||
.await?
|
.await?
|
||||||
{
|
{
|
||||||
// inbuxa: UD-1: a deleted script is kept, when archiving is on
|
// inbuxa: UD-1, LH-4: a deleted script is kept, when archiving
|
||||||
if let Some(retention) =
|
// is on or a hold covers the account (whole: scripts have no date)
|
||||||
inbuxa_features::undelete::settings::retention(self.registry())
|
let keeping = self.keeping(account_id).await?;
|
||||||
.await?
|
let now = store::write::now();
|
||||||
.items
|
if let Some(until) = keeping.until(now, keeping.is_held()) {
|
||||||
{
|
let retention = until.saturating_sub(now);
|
||||||
let script = obj_
|
let script = obj_
|
||||||
.deserialize::<SieveScript>()
|
.deserialize::<SieveScript>()
|
||||||
.caused_by(trc::location!())?;
|
.caused_by(trc::location!())?;
|
||||||
|
|||||||
@@ -290,7 +290,11 @@ impl SieveScriptIngest for Server {
|
|||||||
// inbuxa: AL-4: a locked account answers no sender, so a
|
// inbuxa: AL-4: a locked account answers no sender, so a
|
||||||
// rejection is kept instead; sieve has already cleared
|
// rejection is kept instead; sieve has already cleared
|
||||||
// the implicit keep, so it is filed here
|
// the implicit keep, so it is filed here
|
||||||
Event::Reject { .. } if access_token.is_locked() => {
|
// A shared mailbox (MA-S) is a role address and answers
|
||||||
|
// as one: its Sieve script runs as written
|
||||||
|
Event::Reject { .. }
|
||||||
|
if access_token.is_locked() && !access_token.is_shared_mailbox() =>
|
||||||
|
{
|
||||||
if let Some(message) = messages.get_mut(0)
|
if let Some(message) = messages.get_mut(0)
|
||||||
&& !message.file_into.contains(&INBOX_ID)
|
&& !message.file_into.contains(&INBOX_ID)
|
||||||
{
|
{
|
||||||
@@ -403,7 +407,11 @@ impl SieveScriptIngest for Server {
|
|||||||
// inbuxa: AL-4: a locked account sends nothing on its
|
// inbuxa: AL-4: a locked account sends nothing on its
|
||||||
// own: no redirect, vacation reply or notification. An
|
// own: no redirect, vacation reply or notification. An
|
||||||
// unsent redirect leaves the message to be kept.
|
// unsent redirect leaves the message to be kept.
|
||||||
Event::SendMessage { .. } if access_token.is_locked() => {
|
// A shared mailbox's acknowledgements and redirects go
|
||||||
|
// out (MA-S).
|
||||||
|
Event::SendMessage { .. }
|
||||||
|
if access_token.is_locked() && !access_token.is_shared_mailbox() =>
|
||||||
|
{
|
||||||
trc::event!(
|
trc::event!(
|
||||||
Sieve(SieveEvent::ActionReject),
|
Sieve(SieveEvent::ActionReject),
|
||||||
Details = "Account is locked: nothing is sent",
|
Details = "Account is locked: nothing is sent",
|
||||||
|
|||||||
@@ -15,11 +15,19 @@ utils = { path = "../utils" }
|
|||||||
ahash = { version = "0.8.12", features = ["serde"] }
|
ahash = { version = "0.8.12", features = ["serde"] }
|
||||||
serde = { version = "1.0", features = ["derive"] }
|
serde = { version = "1.0", features = ["derive"] }
|
||||||
serde_json = "1.0"
|
serde_json = "1.0"
|
||||||
|
toml = "1.1"
|
||||||
xxhash-rust = { version = "0.8.18", features = ["xxh3"] }
|
xxhash-rust = { version = "0.8.18", features = ["xxh3"] }
|
||||||
base64 = "0.23"
|
base64 = "0.23"
|
||||||
sha2 = "0.11"
|
sha2 = "0.11"
|
||||||
flate2 = "1.1"
|
flate2 = "1.1"
|
||||||
tokio = { version = "1.53", features = ["sync", "rt"] }
|
tokio = { version = "1.53", features = ["sync", "rt"] }
|
||||||
|
# inbuxa: DLP detectors and attachment text (dlp-and-mail-flow-rules spec)
|
||||||
|
regex = "1.13.1"
|
||||||
|
aho-corasick = "1.1"
|
||||||
|
zip = "8.6"
|
||||||
|
quick-xml = "0.41"
|
||||||
|
mail-parser = { version = "0.11", features = ["full_encoding"] }
|
||||||
|
mail-builder = { version = "1.0" }
|
||||||
|
|
||||||
[dev-dependencies]
|
[dev-dependencies]
|
||||||
tokio = { version = "1.53", features = ["macros", "rt"] }
|
tokio = { version = "1.53", features = ["macros", "rt"] }
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -0,0 +1,282 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! The blocklists a node asks about itself (deliverability spec, DL-6), and
|
||||||
|
//! how to read each one's answer.
|
||||||
|
//!
|
||||||
|
//! A list answers with an address in 127.0.0.0/8. Each list says which of
|
||||||
|
//! those mean "listed" and which mean "I won't answer you": Spamhaus, for
|
||||||
|
//! one, answers `127.255.255.254` to a query that came through a public
|
||||||
|
//! resolver. A refusal is never read as a listing (DL-4).
|
||||||
|
|
||||||
|
use std::net::{IpAddr, Ipv4Addr};
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||||
|
pub enum Scope {
|
||||||
|
/// Looked up by the reversed address: `2.0.0.127.zen.spamhaus.org`.
|
||||||
|
Ip,
|
||||||
|
/// Looked up by name: `example.org.dbl.spamhaus.org`.
|
||||||
|
Domain,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Copy)]
|
||||||
|
pub struct BlockList {
|
||||||
|
/// What the page and the settings call it.
|
||||||
|
pub name: &'static str,
|
||||||
|
pub zone: &'static str,
|
||||||
|
pub scope: Scope,
|
||||||
|
/// Where an administrator looks the address up and asks for removal.
|
||||||
|
pub lookup: &'static str,
|
||||||
|
/// Something the page says beside the list.
|
||||||
|
pub note: Option<&'static str>,
|
||||||
|
read: fn(Ipv4Addr) -> Answer,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// What a list's answer means.
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||||
|
pub enum Answer {
|
||||||
|
Listed(&'static str),
|
||||||
|
/// The list won't answer this resolver, or not now.
|
||||||
|
Refused(&'static str),
|
||||||
|
/// A code the list doesn't define: neither listed nor clean.
|
||||||
|
Unknown,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl BlockList {
|
||||||
|
pub fn read(&self, answer: Ipv4Addr) -> Answer {
|
||||||
|
(self.read)(answer)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The name to look up for `subject`, or None when the subject doesn't
|
||||||
|
/// suit the list (a domain on an IP list, or an IPv6 address: none of
|
||||||
|
/// these lists publish IPv6 zones worth asking).
|
||||||
|
pub fn query(&self, subject: &Subject<'_>) -> Option<String> {
|
||||||
|
match (self.scope, subject) {
|
||||||
|
(Scope::Ip, Subject::Ip(IpAddr::V4(ip))) => {
|
||||||
|
let [a, b, c, d] = ip.octets();
|
||||||
|
Some(format!("{d}.{c}.{b}.{a}.{}.", self.zone))
|
||||||
|
}
|
||||||
|
(Scope::Domain, Subject::Domain(domain)) => {
|
||||||
|
Some(format!("{}.{}.", domain.trim_end_matches('.'), self.zone))
|
||||||
|
}
|
||||||
|
_ => None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pub enum Subject<'x> {
|
||||||
|
Ip(IpAddr),
|
||||||
|
Domain(&'x str),
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Spamhaus' error codes, the same on every Spamhaus zone.
|
||||||
|
fn spamhaus_refusal(ip: Ipv4Addr) -> Option<Answer> {
|
||||||
|
match ip.octets() {
|
||||||
|
[127, 255, 255, 252] => Some(Answer::Refused("The query was malformed")),
|
||||||
|
[127, 255, 255, 254] => Some(Answer::Refused(
|
||||||
|
"Spamhaus doesn't answer public resolvers; use the server's own",
|
||||||
|
)),
|
||||||
|
[127, 255, 255, 255] => Some(Answer::Refused("Too many queries from this resolver")),
|
||||||
|
_ => None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn zen(ip: Ipv4Addr) -> Answer {
|
||||||
|
if let Some(refused) = spamhaus_refusal(ip) {
|
||||||
|
return refused;
|
||||||
|
}
|
||||||
|
match ip.octets() {
|
||||||
|
[127, 0, 0, 2] => Answer::Listed("SBL: a known spam source"),
|
||||||
|
[127, 0, 0, 3] => Answer::Listed("CSS: sent spam recently"),
|
||||||
|
[127, 0, 0, 4..=7] => Answer::Listed("XBL: a compromised or infected host"),
|
||||||
|
[127, 0, 0, 9] => Answer::Listed("DROP: a hijacked or criminal network"),
|
||||||
|
[127, 0, 0, 10 | 11] => {
|
||||||
|
Answer::Listed("PBL: an address that isn't meant to send mail directly")
|
||||||
|
}
|
||||||
|
_ => Answer::Unknown,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn dbl(ip: Ipv4Addr) -> Answer {
|
||||||
|
if let Some(refused) = spamhaus_refusal(ip) {
|
||||||
|
return refused;
|
||||||
|
}
|
||||||
|
match ip.octets() {
|
||||||
|
[127, 0, 1, 2] => Answer::Listed("A spam domain"),
|
||||||
|
[127, 0, 1, 4] => Answer::Listed("A phishing domain"),
|
||||||
|
[127, 0, 1, 5] => Answer::Listed("A malware domain"),
|
||||||
|
[127, 0, 1, 6] => Answer::Listed("A botnet controller"),
|
||||||
|
[127, 0, 1, 102..=106] => Answer::Listed("A legitimate domain being abused"),
|
||||||
|
[127, 0, 1, 255] => Answer::Refused("The query was malformed"),
|
||||||
|
_ => Answer::Unknown,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Most lists answer 127.0.0.2 for "listed" and define nothing else.
|
||||||
|
fn just_two(ip: Ipv4Addr) -> Answer {
|
||||||
|
match ip.octets() {
|
||||||
|
[127, 0, 0, 2] => Answer::Listed("Listed"),
|
||||||
|
_ => Answer::Unknown,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn surbl(ip: Ipv4Addr) -> Answer {
|
||||||
|
match ip.octets() {
|
||||||
|
[127, 0, 0, 1] => Answer::Refused("SURBL doesn't answer this resolver"),
|
||||||
|
[127, 0, 0, bits] if bits & (8 | 16 | 64 | 128) != 0 => {
|
||||||
|
Answer::Listed("Seen in phishing, malware, abuse or cracked sites")
|
||||||
|
}
|
||||||
|
_ => Answer::Unknown,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn uribl(ip: Ipv4Addr) -> Answer {
|
||||||
|
match ip.octets() {
|
||||||
|
[127, 0, 0, 1] => Answer::Refused("URIBL doesn't answer public resolvers"),
|
||||||
|
[127, 0, 0, bits] if bits & (2 | 8) != 0 => Answer::Listed("Seen in spam"),
|
||||||
|
[127, 0, 0, bits] if bits & 4 != 0 => {
|
||||||
|
Answer::Listed("Grey: seen in bulk mail some people don't want")
|
||||||
|
}
|
||||||
|
_ => Answer::Unknown,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pub const LISTS: &[BlockList] = &[
|
||||||
|
BlockList {
|
||||||
|
name: "Spamhaus ZEN",
|
||||||
|
zone: "zen.spamhaus.org",
|
||||||
|
scope: Scope::Ip,
|
||||||
|
lookup: "https://check.spamhaus.org/",
|
||||||
|
note: None,
|
||||||
|
read: zen,
|
||||||
|
},
|
||||||
|
BlockList {
|
||||||
|
name: "SpamCop",
|
||||||
|
zone: "bl.spamcop.net",
|
||||||
|
scope: Scope::Ip,
|
||||||
|
lookup: "https://www.spamcop.net/bl.shtml",
|
||||||
|
note: None,
|
||||||
|
read: just_two,
|
||||||
|
},
|
||||||
|
BlockList {
|
||||||
|
name: "Barracuda",
|
||||||
|
zone: "b.barracudacentral.org",
|
||||||
|
scope: Scope::Ip,
|
||||||
|
lookup: "https://www.barracudacentral.org/lookups",
|
||||||
|
note: Some(
|
||||||
|
"Barracuda answers only resolvers whose address is registered with it (free, at barracudacentral.org/rbl). Until then its lookups can't be checked.",
|
||||||
|
),
|
||||||
|
read: just_two,
|
||||||
|
},
|
||||||
|
BlockList {
|
||||||
|
name: "UCEPROTECT level 1",
|
||||||
|
zone: "dnsbl-1.uceprotect.net",
|
||||||
|
scope: Scope::Ip,
|
||||||
|
lookup: "https://www.uceprotect.net/en/rblcheck.php",
|
||||||
|
note: None,
|
||||||
|
read: just_two,
|
||||||
|
},
|
||||||
|
BlockList {
|
||||||
|
name: "Mailspike",
|
||||||
|
zone: "bl.mailspike.net",
|
||||||
|
scope: Scope::Ip,
|
||||||
|
lookup: "https://mailspike.org/iplookup.html",
|
||||||
|
note: None,
|
||||||
|
read: just_two,
|
||||||
|
},
|
||||||
|
BlockList {
|
||||||
|
name: "PSBL",
|
||||||
|
zone: "psbl.surriel.com",
|
||||||
|
scope: Scope::Ip,
|
||||||
|
lookup: "https://psbl.org/",
|
||||||
|
note: None,
|
||||||
|
read: just_two,
|
||||||
|
},
|
||||||
|
BlockList {
|
||||||
|
name: "Spamhaus DBL",
|
||||||
|
zone: "dbl.spamhaus.org",
|
||||||
|
scope: Scope::Domain,
|
||||||
|
lookup: "https://check.spamhaus.org/",
|
||||||
|
note: None,
|
||||||
|
read: dbl,
|
||||||
|
},
|
||||||
|
BlockList {
|
||||||
|
name: "SURBL",
|
||||||
|
zone: "multi.surbl.org",
|
||||||
|
scope: Scope::Domain,
|
||||||
|
lookup: "https://surbl.org/surbl-analysis",
|
||||||
|
note: None,
|
||||||
|
read: surbl,
|
||||||
|
},
|
||||||
|
BlockList {
|
||||||
|
name: "URIBL",
|
||||||
|
zone: "multi.uribl.com",
|
||||||
|
scope: Scope::Domain,
|
||||||
|
lookup: "https://admin.uribl.com/",
|
||||||
|
note: None,
|
||||||
|
read: uribl,
|
||||||
|
},
|
||||||
|
];
|
||||||
|
|
||||||
|
pub fn by_name(name: &str) -> Option<&'static BlockList> {
|
||||||
|
LISTS.iter().find(|list| list.name == name)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
fn ip(s: &str) -> Ipv4Addr {
|
||||||
|
s.parse().unwrap()
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn a_refusal_is_not_a_listing() {
|
||||||
|
let zen = by_name("Spamhaus ZEN").unwrap();
|
||||||
|
assert!(matches!(
|
||||||
|
zen.read(ip("127.255.255.254")),
|
||||||
|
Answer::Refused(_)
|
||||||
|
));
|
||||||
|
assert!(matches!(zen.read(ip("127.0.0.2")), Answer::Listed(_)));
|
||||||
|
assert!(matches!(zen.read(ip("127.0.0.10")), Answer::Listed(_)));
|
||||||
|
assert_eq!(zen.read(ip("127.0.0.200")), Answer::Unknown);
|
||||||
|
|
||||||
|
let uribl = by_name("URIBL").unwrap();
|
||||||
|
assert!(matches!(uribl.read(ip("127.0.0.1")), Answer::Refused(_)));
|
||||||
|
assert!(matches!(uribl.read(ip("127.0.0.2")), Answer::Listed(_)));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn queries_are_built_per_scope() {
|
||||||
|
let zen = by_name("Spamhaus ZEN").unwrap();
|
||||||
|
let dbl = by_name("Spamhaus DBL").unwrap();
|
||||||
|
let v4 = Subject::Ip("192.0.2.10".parse().unwrap());
|
||||||
|
let v6 = Subject::Ip("2001:db8::1".parse().unwrap());
|
||||||
|
let domain = Subject::Domain("example.org");
|
||||||
|
assert_eq!(
|
||||||
|
zen.query(&v4).as_deref(),
|
||||||
|
Some("10.2.0.192.zen.spamhaus.org.")
|
||||||
|
);
|
||||||
|
assert_eq!(zen.query(&v6), None);
|
||||||
|
assert_eq!(zen.query(&domain), None);
|
||||||
|
assert_eq!(
|
||||||
|
dbl.query(&domain).as_deref(),
|
||||||
|
Some("example.org.dbl.spamhaus.org.")
|
||||||
|
);
|
||||||
|
assert_eq!(dbl.query(&v4), None);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn names_are_unique() {
|
||||||
|
for (i, a) in LISTS.iter().enumerate() {
|
||||||
|
assert!(
|
||||||
|
LISTS[i + 1..].iter().all(|b| b.name != a.name),
|
||||||
|
"{}",
|
||||||
|
a.name
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,410 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! The deliverability check (deliverability spec): what other mail servers
|
||||||
|
//! see when this one sends. Not a rebuild of anything upstream ships.
|
||||||
|
//!
|
||||||
|
//! Every node that sends mail checks itself, because only it knows which
|
||||||
|
//! address it leaves from, and keeps one report. The report holds facts: an
|
||||||
|
//! address's reverse DNS, what each blocklist answered, what SPF said for
|
||||||
|
//! each address, whether a DKIM key in DNS matches the one signing. The
|
||||||
|
//! console grades them, so its wording can change without a server release.
|
||||||
|
//!
|
||||||
|
//! Kept in the fork's subspace (`store::SUBSPACE_INBUXA`). Every key starts
|
||||||
|
//! with `D`, then one byte for the kind:
|
||||||
|
//!
|
||||||
|
//! - `r` + node id (u64): that node's last report, as JSON.
|
||||||
|
//! - `s`: the settings, as JSON.
|
||||||
|
//!
|
||||||
|
//! Numbers are big-endian.
|
||||||
|
|
||||||
|
pub mod lists;
|
||||||
|
|
||||||
|
use serde::{Deserialize as SerdeDeserialize, Serialize as SerdeSerialize};
|
||||||
|
use store::{
|
||||||
|
Deserialize, IterateParams, SUBSPACE_INBUXA, Serialize, Store, ValueKey,
|
||||||
|
write::{AnyClass, BatchBuilder, ValueClass},
|
||||||
|
};
|
||||||
|
use trc::AddContext;
|
||||||
|
|
||||||
|
const FEATURE: u8 = b'D';
|
||||||
|
const KIND_REPORT: u8 = b'r';
|
||||||
|
const KIND_SETTINGS: u8 = b's';
|
||||||
|
|
||||||
|
/// DL-15: **Check now** runs a node again only this long after its last run.
|
||||||
|
pub const MIN_INTERVAL_SECS: u64 = 600;
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase", default)]
|
||||||
|
pub struct Report {
|
||||||
|
/// The node's cluster id, as metric samples carry it.
|
||||||
|
pub node_id: u64,
|
||||||
|
pub hostname: String,
|
||||||
|
/// Seconds since the epoch.
|
||||||
|
pub checked_at: u64,
|
||||||
|
pub addresses: Vec<Address>,
|
||||||
|
pub domains: Vec<DomainReport>,
|
||||||
|
pub certificates: Vec<Certificate>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase", default)]
|
||||||
|
pub struct Address {
|
||||||
|
pub ip: String,
|
||||||
|
/// DL-2: how the node came by the address.
|
||||||
|
pub source: AddressSource,
|
||||||
|
/// The connection strategy that sends from it.
|
||||||
|
pub strategy: String,
|
||||||
|
/// The name the node greets with from this address.
|
||||||
|
pub ehlo: String,
|
||||||
|
/// The PTR names, empty when there's none.
|
||||||
|
pub ptr: Vec<String>,
|
||||||
|
/// Some PTR name resolves back to the address.
|
||||||
|
pub forward_confirmed: bool,
|
||||||
|
/// The forward-confirmed name is the EHLO name.
|
||||||
|
pub ehlo_matches: bool,
|
||||||
|
/// Set when the reverse lookup itself failed, rather than found nothing.
|
||||||
|
pub ptr_error: Option<String>,
|
||||||
|
pub listings: Vec<Listing>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Copy, Default, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub enum AddressSource {
|
||||||
|
/// Set in the connection strategy's source addresses.
|
||||||
|
#[default]
|
||||||
|
Configured,
|
||||||
|
/// What the EHLO name resolves to.
|
||||||
|
Ehlo,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase", default)]
|
||||||
|
pub struct Listing {
|
||||||
|
/// The list's name, as in [`lists::LISTS`].
|
||||||
|
pub list: String,
|
||||||
|
pub state: ListingState,
|
||||||
|
/// The address the list answered, when it answered one.
|
||||||
|
pub code: Option<String>,
|
||||||
|
/// What the list says the answer means.
|
||||||
|
pub meaning: Option<String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Copy, Default, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub enum ListingState {
|
||||||
|
#[default]
|
||||||
|
Clean,
|
||||||
|
Listed,
|
||||||
|
/// The list wouldn't answer, or the lookup failed: neither listed nor clean.
|
||||||
|
Refused,
|
||||||
|
Error,
|
||||||
|
/// Switched off in the settings, so not asked.
|
||||||
|
Off,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase", default)]
|
||||||
|
pub struct DomainReport {
|
||||||
|
pub domain: String,
|
||||||
|
/// DL-20: a tenant administrator sees only their tenant's domains.
|
||||||
|
pub tenant_id: Option<u32>,
|
||||||
|
/// DL-7: what SPF says for each of the node's addresses.
|
||||||
|
pub spf: Vec<SpfResult>,
|
||||||
|
/// DL-8: each DKIM key the domain signs with.
|
||||||
|
pub dkim: Vec<DkimKey>,
|
||||||
|
/// DL-9: the DMARC record, if there's one.
|
||||||
|
pub dmarc: Option<Dmarc>,
|
||||||
|
/// DL-10.
|
||||||
|
pub mta_sts: MtaSts,
|
||||||
|
/// DL-11: there's a `_smtp._tls` record.
|
||||||
|
pub tls_rpt: bool,
|
||||||
|
/// DL-12.
|
||||||
|
pub listings: Vec<Listing>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase", default)]
|
||||||
|
pub struct SpfResult {
|
||||||
|
pub ip: String,
|
||||||
|
/// `pass`, `fail`, `softFail`, `neutral`, `none`, `tempError` or `permError`.
|
||||||
|
pub result: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase", default)]
|
||||||
|
pub struct DkimKey {
|
||||||
|
pub selector: String,
|
||||||
|
pub state: DkimState,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Copy, Default, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub enum DkimState {
|
||||||
|
#[default]
|
||||||
|
Matches,
|
||||||
|
/// Nothing published at `<selector>._domainkey.<domain>`.
|
||||||
|
Missing,
|
||||||
|
/// Published, but a different key.
|
||||||
|
Different,
|
||||||
|
/// The lookup failed.
|
||||||
|
Error,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase", default)]
|
||||||
|
pub struct Dmarc {
|
||||||
|
/// `none`, `quarantine` or `reject`.
|
||||||
|
pub policy: String,
|
||||||
|
/// DKIM alignment: `relaxed` or `strict`.
|
||||||
|
pub adkim: String,
|
||||||
|
/// SPF alignment: `relaxed` or `strict`.
|
||||||
|
pub aspf: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase", default)]
|
||||||
|
pub struct MtaSts {
|
||||||
|
/// The `_mta-sts` record's id; None when there's no record.
|
||||||
|
pub record_id: Option<String>,
|
||||||
|
/// The policy was fetched and parsed. False with a record means the
|
||||||
|
/// fetch or the parse failed, and `error` says why.
|
||||||
|
pub fetched: bool,
|
||||||
|
pub error: Option<String>,
|
||||||
|
/// `enforce`, `testing` or `none`.
|
||||||
|
pub mode: Option<String>,
|
||||||
|
pub max_age: Option<u64>,
|
||||||
|
/// The domain's MX names no `mx:` line matches.
|
||||||
|
pub mx_not_covered: Vec<String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase", default)]
|
||||||
|
pub struct Certificate {
|
||||||
|
/// The EHLO name, or an MX name that points at this node.
|
||||||
|
pub name: String,
|
||||||
|
/// The node holds a certificate for the name.
|
||||||
|
pub covered: bool,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase", default)]
|
||||||
|
pub struct Settings {
|
||||||
|
/// DL-6: lists not to ask, by name.
|
||||||
|
pub disabled_lists: Vec<String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Settings {
|
||||||
|
pub fn is_off(&self, list: &str) -> bool {
|
||||||
|
self.disabled_lists.iter().any(|name| name == list)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Only the built-in lists' names, once each.
|
||||||
|
pub fn validate(&self) -> Result<(), String> {
|
||||||
|
for (i, name) in self.disabled_lists.iter().enumerate() {
|
||||||
|
if lists::by_name(name).is_none() {
|
||||||
|
return Err(format!("There's no list called {name:?}."));
|
||||||
|
}
|
||||||
|
if self.disabled_lists[..i].contains(name) {
|
||||||
|
return Err(format!("{name:?} is named twice."));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Report {
|
||||||
|
/// DL-20: what a tenant administrator may see: their tenant's domains
|
||||||
|
/// and nothing about the node's addresses or certificates.
|
||||||
|
pub fn for_tenant(&self, tenant_id: u32) -> Report {
|
||||||
|
Report {
|
||||||
|
node_id: self.node_id,
|
||||||
|
hostname: self.hostname.clone(),
|
||||||
|
checked_at: self.checked_at,
|
||||||
|
addresses: Vec::new(),
|
||||||
|
domains: self
|
||||||
|
.domains
|
||||||
|
.iter()
|
||||||
|
.filter(|d| d.tenant_id == Some(tenant_id))
|
||||||
|
.cloned()
|
||||||
|
.collect(),
|
||||||
|
certificates: Vec::new(),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// --- Storage --------------------------------------------------------------
|
||||||
|
|
||||||
|
struct Json<T>(T);
|
||||||
|
|
||||||
|
impl<T: SerdeSerialize> Serialize for Json<T> {
|
||||||
|
fn serialize(&self) -> trc::Result<Vec<u8>> {
|
||||||
|
serde_json::to_vec(&self.0).map_err(|err| {
|
||||||
|
trc::StoreEvent::UnexpectedError
|
||||||
|
.into_err()
|
||||||
|
.details("Failed to serialize deliverability data")
|
||||||
|
.reason(err)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl<T: for<'de> SerdeDeserialize<'de> + Send + Sync> Deserialize for Json<T> {
|
||||||
|
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
|
||||||
|
serde_json::from_slice(bytes).map(Json).map_err(|err| {
|
||||||
|
trc::StoreEvent::DataCorruption
|
||||||
|
.into_err()
|
||||||
|
.details("Invalid deliverability data")
|
||||||
|
.reason(err)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn class(kind: u8, node_id: Option<u64>) -> ValueClass {
|
||||||
|
let mut key = Vec::with_capacity(10);
|
||||||
|
key.push(FEATURE);
|
||||||
|
key.push(kind);
|
||||||
|
if let Some(node_id) = node_id {
|
||||||
|
key.extend_from_slice(&node_id.to_be_bytes());
|
||||||
|
}
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace: SUBSPACE_INBUXA,
|
||||||
|
key,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
pub async fn report(data: &Store, node_id: u64) -> trc::Result<Option<Report>> {
|
||||||
|
Ok(data
|
||||||
|
.get_value::<Json<Report>>(ValueKey::from(class(KIND_REPORT, Some(node_id))))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
.map(|Json(report)| report))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Every node's report, by node id.
|
||||||
|
pub async fn reports(data: &Store) -> trc::Result<Vec<Report>> {
|
||||||
|
let mut out = Vec::new();
|
||||||
|
data.iterate(
|
||||||
|
IterateParams::new(
|
||||||
|
ValueKey::from(class(KIND_REPORT, Some(0))),
|
||||||
|
ValueKey::from(class(KIND_REPORT, Some(u64::MAX))),
|
||||||
|
),
|
||||||
|
|_, value| {
|
||||||
|
if let Ok(Json(report)) = Json::<Report>::deserialize(value) {
|
||||||
|
out.push(report);
|
||||||
|
}
|
||||||
|
Ok(true)
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
out.sort_by_key(|r| r.node_id);
|
||||||
|
Ok(out)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Replaces the node's report.
|
||||||
|
pub async fn put_report(data: &Store, report: &Report) -> trc::Result<()> {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.set(
|
||||||
|
class(KIND_REPORT, Some(report.node_id)),
|
||||||
|
Json(report).serialize()?,
|
||||||
|
);
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
pub async fn settings(data: &Store) -> trc::Result<Settings> {
|
||||||
|
Ok(data
|
||||||
|
.get_value::<Json<Settings>>(ValueKey::from(class(KIND_SETTINGS, None)))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
.map(|Json(settings)| settings)
|
||||||
|
.unwrap_or_default())
|
||||||
|
}
|
||||||
|
|
||||||
|
pub async fn put_settings(data: &Store, settings: &Settings) -> trc::Result<()> {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.set(class(KIND_SETTINGS, None), Json(settings).serialize()?);
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn settings_name_only_built_in_lists_once() {
|
||||||
|
let ok = Settings {
|
||||||
|
disabled_lists: vec!["Barracuda".into(), "URIBL".into()],
|
||||||
|
};
|
||||||
|
assert!(ok.validate().is_ok());
|
||||||
|
assert!(ok.is_off("Barracuda"));
|
||||||
|
assert!(!ok.is_off("SpamCop"));
|
||||||
|
let unknown = Settings {
|
||||||
|
disabled_lists: vec!["My list".into()],
|
||||||
|
};
|
||||||
|
assert!(unknown.validate().is_err());
|
||||||
|
let twice = Settings {
|
||||||
|
disabled_lists: vec!["URIBL".into(), "URIBL".into()],
|
||||||
|
};
|
||||||
|
assert!(twice.validate().is_err());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn a_tenant_sees_only_its_domains() {
|
||||||
|
let report = Report {
|
||||||
|
node_id: 2,
|
||||||
|
hostname: "mx2.example.org".into(),
|
||||||
|
checked_at: 1,
|
||||||
|
addresses: vec![Address {
|
||||||
|
ip: "192.0.2.10".into(),
|
||||||
|
..Default::default()
|
||||||
|
}],
|
||||||
|
domains: vec![
|
||||||
|
DomainReport {
|
||||||
|
domain: "a.example".into(),
|
||||||
|
tenant_id: Some(7),
|
||||||
|
..Default::default()
|
||||||
|
},
|
||||||
|
DomainReport {
|
||||||
|
domain: "b.example".into(),
|
||||||
|
tenant_id: Some(8),
|
||||||
|
..Default::default()
|
||||||
|
},
|
||||||
|
DomainReport {
|
||||||
|
domain: "server.example".into(),
|
||||||
|
tenant_id: None,
|
||||||
|
..Default::default()
|
||||||
|
},
|
||||||
|
],
|
||||||
|
certificates: vec![Certificate {
|
||||||
|
name: "mx2.example.org".into(),
|
||||||
|
covered: true,
|
||||||
|
}],
|
||||||
|
};
|
||||||
|
let seen = report.for_tenant(7);
|
||||||
|
assert!(seen.addresses.is_empty());
|
||||||
|
assert!(seen.certificates.is_empty());
|
||||||
|
assert_eq!(
|
||||||
|
seen.domains
|
||||||
|
.iter()
|
||||||
|
.map(|d| d.domain.as_str())
|
||||||
|
.collect::<Vec<_>>(),
|
||||||
|
["a.example"]
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn a_report_reads_back_with_missing_fields() {
|
||||||
|
let report: Report = serde_json::from_str(r#"{"nodeId": 3}"#).unwrap();
|
||||||
|
assert_eq!(report.node_id, 3);
|
||||||
|
assert!(report.domains.is_empty());
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,772 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! Legal holds (audit-hold-lock spec, LH-1 to LH-14).
|
||||||
|
//!
|
||||||
|
//! A hold names a case and what it covers: accounts, groups, domains,
|
||||||
|
//! tenants or the whole server, optionally only items dated inside a range.
|
||||||
|
//! While any active hold covers an item, nothing may destroy it. A hold is
|
||||||
|
//! never deleted: releasing it keeps it, read-only, for the audit trail.
|
||||||
|
//!
|
||||||
|
//! Kept in the fork's subspace (`store::SUBSPACE_INBUXA`). Every key starts
|
||||||
|
//! with `H`, then one byte for the kind:
|
||||||
|
//!
|
||||||
|
//! - `h` + hold id (u32): the hold, as JSON.
|
||||||
|
//!
|
||||||
|
//! Numbers are big-endian. There are few holds, so they're read whole.
|
||||||
|
|
||||||
|
use registry::schema::{prelude::ObjectInner, structs::Account};
|
||||||
|
use serde::{Deserialize as SerdeDeserialize, Serialize as SerdeSerialize};
|
||||||
|
use store::{
|
||||||
|
Deserialize, IterateParams, SUBSPACE_INBUXA, Serialize, Store, ValueKey,
|
||||||
|
write::{AnyClass, BatchBuilder, ValueClass, assert::AssertValue},
|
||||||
|
};
|
||||||
|
use trc::AddContext;
|
||||||
|
|
||||||
|
/// The deadline a held archived item carries: the last second of 9999. It
|
||||||
|
/// never passes, so every expiry check keeps the item without knowing about
|
||||||
|
/// holds (LH-4, LH-5); releasing a hold gives it a real deadline (LH-10).
|
||||||
|
pub const HELD_UNTIL: u64 = 253_402_300_799;
|
||||||
|
|
||||||
|
/// Whether an archived item's deadline marks it as held. Anything past the
|
||||||
|
/// year 9000 counts, so a deadline computed from a hold a moment earlier or
|
||||||
|
/// later still reads as held.
|
||||||
|
pub fn is_held_until(until: u64) -> bool {
|
||||||
|
until >= 221_845_392_000
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A day, in seconds: the slack either side of a range for an event's start,
|
||||||
|
/// whose time zone isn't known here.
|
||||||
|
const DAY: u64 = 86_400;
|
||||||
|
|
||||||
|
/// How an account's deleted items are kept: its holds' ranges, and the
|
||||||
|
/// undelete period for whatever no hold covers (LH-3, LH-4).
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, Eq)]
|
||||||
|
pub struct Keeping {
|
||||||
|
/// `archiveDeletedItemsFor`, in seconds, if undelete is on.
|
||||||
|
pub retention: Option<u64>,
|
||||||
|
/// Each active hold's range on this account; `(None, None)` is a whole
|
||||||
|
/// account. Empty when nothing holds it.
|
||||||
|
pub ranges: Vec<(Option<u64>, Option<u64>)>,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Keeping {
|
||||||
|
pub fn new(retention: Option<u64>, holds: &[Hold]) -> Keeping {
|
||||||
|
Keeping {
|
||||||
|
retention,
|
||||||
|
ranges: holds.iter().map(|h| (h.from, h.to)).collect(),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Whether any hold reaches the account at all.
|
||||||
|
pub fn is_held(&self) -> bool {
|
||||||
|
!self.ranges.is_empty()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Whether deleted items need noting: something may keep them.
|
||||||
|
pub fn keeps_anything(&self) -> bool {
|
||||||
|
self.is_held() || self.retention.is_some()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Whether a hold covers an item dated `date`. No date means the item is
|
||||||
|
/// held whole, whatever the range (LH-3).
|
||||||
|
pub fn covers(&self, date: Option<u64>) -> bool {
|
||||||
|
self.ranges.iter().any(|(from, to)| match date {
|
||||||
|
None => true,
|
||||||
|
Some(at) => {
|
||||||
|
from.is_none_or(|from| at >= from) && to.is_none_or(|to| at <= to)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Like `covers`, for an event's start: a day of slack either side, since
|
||||||
|
/// its time zone isn't known here.
|
||||||
|
pub fn covers_event(&self, start: Option<u64>) -> bool {
|
||||||
|
self.ranges.iter().any(|(from, to)| match start {
|
||||||
|
None => true,
|
||||||
|
Some(at) => {
|
||||||
|
from.is_none_or(|from| at + DAY >= from)
|
||||||
|
&& to.is_none_or(|to| at <= to.saturating_add(DAY))
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Until when an item deleted at `now` is kept: held, the undelete
|
||||||
|
/// period, or not at all.
|
||||||
|
pub fn until(&self, now: u64, held: bool) -> Option<u64> {
|
||||||
|
if held {
|
||||||
|
Some(HELD_UNTIL)
|
||||||
|
} else {
|
||||||
|
self.retention.map(|retention| now + retention)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const FEATURE: u8 = b'H';
|
||||||
|
const KIND_HOLD: u8 = b'h';
|
||||||
|
const KIND_ORIGINAL: u8 = b'o';
|
||||||
|
const KIND_EXPORT: u8 = b'e';
|
||||||
|
|
||||||
|
/// How far a hold export has got (LH-12).
|
||||||
|
#[derive(Debug, Clone, Copy, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub enum ExportStatus {
|
||||||
|
Running,
|
||||||
|
Ready,
|
||||||
|
Failed,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A collection of what a hold keeps, as a ZIP (LH-12).
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub struct Export {
|
||||||
|
pub id: u32,
|
||||||
|
pub hold_id: u32,
|
||||||
|
/// The accounts asked for; empty for every account the hold covers.
|
||||||
|
#[serde(default, skip_serializing_if = "Vec::is_empty")]
|
||||||
|
pub accounts: Vec<u32>,
|
||||||
|
pub reason: String,
|
||||||
|
pub created_at: u64,
|
||||||
|
pub created_by: String,
|
||||||
|
/// Whose blob the ZIP is, so only they download it.
|
||||||
|
pub created_by_id: u32,
|
||||||
|
pub status: ExportStatus,
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub finished_at: Option<u64>,
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub blob_id: Option<String>,
|
||||||
|
#[serde(default)]
|
||||||
|
pub size: u64,
|
||||||
|
#[serde(default)]
|
||||||
|
pub items: u64,
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub sha256: Option<String>,
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub error: Option<String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// How many times creating a hold retries when another node took its id.
|
||||||
|
const CREATE_ATTEMPTS: usize = 5;
|
||||||
|
|
||||||
|
/// What a hold covers (LH-1, LH-2). Domains and tenants are resolved live,
|
||||||
|
/// so an account added to one later is held too.
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub struct Scope {
|
||||||
|
/// Every account on the server.
|
||||||
|
#[serde(default, skip_serializing_if = "std::ops::Not::not")]
|
||||||
|
pub server: bool,
|
||||||
|
#[serde(default, skip_serializing_if = "Vec::is_empty")]
|
||||||
|
pub accounts: Vec<u32>,
|
||||||
|
#[serde(default, skip_serializing_if = "Vec::is_empty")]
|
||||||
|
pub groups: Vec<u32>,
|
||||||
|
#[serde(default, skip_serializing_if = "Vec::is_empty")]
|
||||||
|
pub domains: Vec<u32>,
|
||||||
|
#[serde(default, skip_serializing_if = "Vec::is_empty")]
|
||||||
|
pub tenants: Vec<u32>,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Scope {
|
||||||
|
pub fn is_empty(&self) -> bool {
|
||||||
|
!self.server
|
||||||
|
&& self.accounts.is_empty()
|
||||||
|
&& self.groups.is_empty()
|
||||||
|
&& self.domains.is_empty()
|
||||||
|
&& self.tenants.is_empty()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Whether this scope covers everything `other` does, entry by entry.
|
||||||
|
/// A scope may only grow (LH-3's rule for ranges, applied to scope):
|
||||||
|
/// taking something out would free what it held.
|
||||||
|
pub fn contains(&self, other: &Scope) -> bool {
|
||||||
|
let all = |mine: &[u32], theirs: &[u32]| theirs.iter().all(|id| mine.contains(id));
|
||||||
|
(self.server || !other.server)
|
||||||
|
&& all(&self.accounts, &other.accounts)
|
||||||
|
&& all(&self.groups, &other.groups)
|
||||||
|
&& all(&self.domains, &other.domains)
|
||||||
|
&& all(&self.tenants, &other.tenants)
|
||||||
|
}
|
||||||
|
|
||||||
|
fn normalize(&mut self) {
|
||||||
|
for list in [
|
||||||
|
&mut self.accounts,
|
||||||
|
&mut self.groups,
|
||||||
|
&mut self.domains,
|
||||||
|
&mut self.tenants,
|
||||||
|
] {
|
||||||
|
list.sort_unstable();
|
||||||
|
list.dedup();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// What decides whether a hold's scope reaches an account: the domains of
|
||||||
|
/// its addresses, its groups and its tenant (LH-2).
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, Eq)]
|
||||||
|
pub struct Member {
|
||||||
|
pub account: u32,
|
||||||
|
pub domains: Vec<u32>,
|
||||||
|
pub groups: Vec<u32>,
|
||||||
|
pub tenant: Option<u32>,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Member {
|
||||||
|
/// A person's account as the registry stores it; `None` for a group,
|
||||||
|
/// whose own data is held through its members.
|
||||||
|
pub fn of(account_id: u32, object: &ObjectInner) -> Option<Member> {
|
||||||
|
let ObjectInner::Account(Account::User(user)) = object else {
|
||||||
|
return None;
|
||||||
|
};
|
||||||
|
let mut domains = vec![user.domain_id.document_id()];
|
||||||
|
domains.extend(user.aliases.iter().map(|alias| alias.domain_id.document_id()));
|
||||||
|
domains.sort_unstable();
|
||||||
|
domains.dedup();
|
||||||
|
Some(Member {
|
||||||
|
account: account_id,
|
||||||
|
domains,
|
||||||
|
groups: user.member_group_ids.iter().map(|id| id.document_id()).collect(),
|
||||||
|
tenant: user.member_tenant_id.map(|id| id.document_id()),
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Scope {
|
||||||
|
/// Whether this scope reaches `member`, directly or through its domains,
|
||||||
|
/// groups or tenant, as they are now (LH-2).
|
||||||
|
pub fn covers(&self, member: &Member) -> bool {
|
||||||
|
self.server
|
||||||
|
|| self.accounts.contains(&member.account)
|
||||||
|
|| member.domains.iter().any(|d| self.domains.contains(d))
|
||||||
|
|| member.groups.iter().any(|g| self.groups.contains(g))
|
||||||
|
|| member.tenant.is_some_and(|t| self.tenants.contains(&t))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// When and why a hold was released (LH-10).
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub struct Release {
|
||||||
|
pub at: u64,
|
||||||
|
pub by: String,
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub by_id: Option<u32>,
|
||||||
|
pub reason: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A legal hold (LH-1).
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub struct Hold {
|
||||||
|
pub id: u32,
|
||||||
|
/// The case name.
|
||||||
|
pub name: String,
|
||||||
|
/// A matter or ticket number.
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub reference: Option<String>,
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub description: Option<String>,
|
||||||
|
pub scope: Scope,
|
||||||
|
/// Seconds since the epoch. Items dated before aren't held (LH-3).
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub from: Option<u64>,
|
||||||
|
/// Seconds since the epoch. Items dated after aren't held (LH-3).
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub to: Option<u64>,
|
||||||
|
pub placed_at: u64,
|
||||||
|
pub placed_by: String,
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub placed_by_id: Option<u32>,
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub released: Option<Release>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Why a change to a hold is refused.
|
||||||
|
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
||||||
|
pub enum Refusal {
|
||||||
|
/// A released hold is read-only (LH-1).
|
||||||
|
Released,
|
||||||
|
/// The range may only widen (LH-3).
|
||||||
|
Narrowed,
|
||||||
|
/// The scope may only grow.
|
||||||
|
ScopeShrunk,
|
||||||
|
/// A hold has to cover something.
|
||||||
|
EmptyScope,
|
||||||
|
/// `from` after `to`.
|
||||||
|
Backwards,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Refusal {
|
||||||
|
pub fn describe(self) -> &'static str {
|
||||||
|
match self {
|
||||||
|
Refusal::Released => "A released hold can't be changed; place a new one instead.",
|
||||||
|
Refusal::Narrowed => {
|
||||||
|
"A hold's date range can only be widened. To hold less, release it and place a new hold."
|
||||||
|
}
|
||||||
|
Refusal::ScopeShrunk => {
|
||||||
|
"Nothing can be taken out of a hold's scope. To hold less, release it and place a new hold."
|
||||||
|
}
|
||||||
|
Refusal::EmptyScope => "A hold has to cover at least one account, group, domain or tenant, or the whole server.",
|
||||||
|
Refusal::Backwards => "The range starts after it ends.",
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Hold {
|
||||||
|
pub fn is_active(&self) -> bool {
|
||||||
|
self.released.is_none()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Whether an item dated `at` (seconds) falls in the hold's range. With
|
||||||
|
/// no range, everything does (LH-3).
|
||||||
|
pub fn covers_date(&self, at: u64) -> bool {
|
||||||
|
self.from.is_none_or(|from| at >= from) && self.to.is_none_or(|to| at <= to)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Checks a new hold, and tidies its scope.
|
||||||
|
pub fn check_new(&mut self) -> Result<(), Refusal> {
|
||||||
|
self.scope.normalize();
|
||||||
|
if self.scope.is_empty() {
|
||||||
|
return Err(Refusal::EmptyScope);
|
||||||
|
}
|
||||||
|
if let (Some(from), Some(to)) = (self.from, self.to)
|
||||||
|
&& from > to
|
||||||
|
{
|
||||||
|
return Err(Refusal::Backwards);
|
||||||
|
}
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Checks that `next` is an allowed change of `self`: names and notes
|
||||||
|
/// may change, the range may only widen, the scope may only grow, and a
|
||||||
|
/// released hold may not change at all.
|
||||||
|
pub fn check_update(&self, next: &mut Hold) -> Result<(), Refusal> {
|
||||||
|
if !self.is_active() {
|
||||||
|
return Err(Refusal::Released);
|
||||||
|
}
|
||||||
|
next.check_new()?;
|
||||||
|
// An open end can't be closed, and a set end can only move outward
|
||||||
|
let from_ok = match (self.from, next.from) {
|
||||||
|
(None, Some(_)) => false,
|
||||||
|
(Some(old), Some(new)) => new <= old,
|
||||||
|
(_, None) => true,
|
||||||
|
};
|
||||||
|
let to_ok = match (self.to, next.to) {
|
||||||
|
(None, Some(_)) => false,
|
||||||
|
(Some(old), Some(new)) => new >= old,
|
||||||
|
(_, None) => true,
|
||||||
|
};
|
||||||
|
if !from_ok || !to_ok {
|
||||||
|
return Err(Refusal::Narrowed);
|
||||||
|
}
|
||||||
|
if !next.scope.contains(&self.scope) {
|
||||||
|
return Err(Refusal::ScopeShrunk);
|
||||||
|
}
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
struct Json<T>(T);
|
||||||
|
|
||||||
|
impl<T: SerdeSerialize> Serialize for Json<T> {
|
||||||
|
fn serialize(&self) -> trc::Result<Vec<u8>> {
|
||||||
|
serde_json::to_vec(&self.0).map_err(|err| {
|
||||||
|
trc::StoreEvent::UnexpectedError
|
||||||
|
.into_err()
|
||||||
|
.details("Failed to serialize legal hold")
|
||||||
|
.reason(err)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl<T: serde::de::DeserializeOwned + Sync + Send> Deserialize for Json<T> {
|
||||||
|
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
|
||||||
|
serde_json::from_slice(bytes).map(Json).map_err(|err| {
|
||||||
|
trc::StoreEvent::DataCorruption
|
||||||
|
.into_err()
|
||||||
|
.details("Invalid legal hold")
|
||||||
|
.reason(err)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn class(id: u32) -> ValueClass {
|
||||||
|
let mut key = Vec::with_capacity(6);
|
||||||
|
key.push(FEATURE);
|
||||||
|
key.push(KIND_HOLD);
|
||||||
|
key.extend_from_slice(&id.to_be_bytes());
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace: SUBSPACE_INBUXA,
|
||||||
|
key,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
fn key(id: u32) -> ValueKey<ValueClass> {
|
||||||
|
ValueKey::from(class(id))
|
||||||
|
}
|
||||||
|
|
||||||
|
fn original_class(item_id: u64) -> ValueClass {
|
||||||
|
let mut key = Vec::with_capacity(10);
|
||||||
|
key.push(FEATURE);
|
||||||
|
key.push(KIND_ORIGINAL);
|
||||||
|
key.extend_from_slice(&item_id.to_be_bytes());
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace: SUBSPACE_INBUXA,
|
||||||
|
key,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// LH-10: an archived item's deadline from before a hold froze it, so a
|
||||||
|
/// release can give it back (or a later one). None for an item held from
|
||||||
|
/// its deletion, which never had one.
|
||||||
|
pub async fn original_deadline(data: &Store, item_id: u64) -> trc::Result<Option<u64>> {
|
||||||
|
data.get_value::<u64>(ValueKey::from(original_class(item_id)))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Notes (`Some`) or forgets (`None`) an item's deadline from before it
|
||||||
|
/// was frozen.
|
||||||
|
pub async fn set_original_deadline(data: &Store, item_id: u64, until: Option<u64>) -> trc::Result<()> {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
match until {
|
||||||
|
Some(until) => batch.set(original_class(item_id), until.to_be_bytes().to_vec()),
|
||||||
|
None => batch.clear(original_class(item_id)),
|
||||||
|
};
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())
|
||||||
|
.map(|_| ())
|
||||||
|
}
|
||||||
|
|
||||||
|
fn export_class(id: u32) -> ValueClass {
|
||||||
|
let mut key = Vec::with_capacity(6);
|
||||||
|
key.push(FEATURE);
|
||||||
|
key.push(KIND_EXPORT);
|
||||||
|
key.extend_from_slice(&id.to_be_bytes());
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace: SUBSPACE_INBUXA,
|
||||||
|
key,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Every hold export, oldest first.
|
||||||
|
pub async fn exports(data: &Store) -> trc::Result<Vec<Export>> {
|
||||||
|
let mut exports = Vec::new();
|
||||||
|
data.iterate(
|
||||||
|
IterateParams::new(ValueKey::from(export_class(0)), ValueKey::from(export_class(u32::MAX))),
|
||||||
|
|_, value| {
|
||||||
|
if let Ok(Json(export)) = Json::<Export>::deserialize(value) {
|
||||||
|
exports.push(export);
|
||||||
|
}
|
||||||
|
Ok(true)
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
Ok(exports)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Writes a new export under the next free id, which it returns.
|
||||||
|
pub async fn create_export(data: &Store, export: &Export) -> trc::Result<u32> {
|
||||||
|
let mut attempt = 0;
|
||||||
|
loop {
|
||||||
|
attempt += 1;
|
||||||
|
let id = exports(data).await?.iter().map(|e| e.id).max().unwrap_or(0) + 1;
|
||||||
|
let stored = Export {
|
||||||
|
id,
|
||||||
|
..export.clone()
|
||||||
|
};
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.assert_value(export_class(id), AssertValue::None);
|
||||||
|
batch.set(export_class(id), Json(&stored).serialize()?);
|
||||||
|
match data.write(batch.build_all()).await {
|
||||||
|
Ok(_) => return Ok(id),
|
||||||
|
Err(err)
|
||||||
|
if attempt < CREATE_ATTEMPTS
|
||||||
|
&& matches!(
|
||||||
|
err.as_ref(),
|
||||||
|
trc::EventType::Store(trc::StoreEvent::AssertValueFailed)
|
||||||
|
) => {}
|
||||||
|
Err(err) => return Err(err.caused_by(trc::location!())),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Saves an export's progress.
|
||||||
|
pub async fn update_export(data: &Store, export: &Export) -> trc::Result<()> {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.set(export_class(export.id), Json(export).serialize()?);
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())
|
||||||
|
.map(|_| ())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// One hold, released or not.
|
||||||
|
pub async fn get(data: &Store, id: u32) -> trc::Result<Option<Hold>> {
|
||||||
|
Ok(data
|
||||||
|
.get_value::<Json<Hold>>(key(id))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
.map(|Json(hold)| hold))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Every hold, released ones included, oldest first.
|
||||||
|
pub async fn all(data: &Store) -> trc::Result<Vec<Hold>> {
|
||||||
|
let mut holds = Vec::new();
|
||||||
|
data.iterate(IterateParams::new(key(0), key(u32::MAX)), |_, value| {
|
||||||
|
if let Ok(Json(hold)) = Json::<Hold>::deserialize(value) {
|
||||||
|
holds.push(hold);
|
||||||
|
}
|
||||||
|
Ok(true)
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
Ok(holds)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The holds still in force.
|
||||||
|
pub async fn active(data: &Store) -> trc::Result<Vec<Hold>> {
|
||||||
|
Ok(all(data).await?.into_iter().filter(Hold::is_active).collect())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Writes a new hold under the next free id, which it returns. Two nodes
|
||||||
|
/// placing holds at once can't take the same id: the key must be absent.
|
||||||
|
pub async fn create(data: &Store, hold: &Hold) -> trc::Result<u32> {
|
||||||
|
let mut attempt = 0;
|
||||||
|
loop {
|
||||||
|
attempt += 1;
|
||||||
|
let id = all(data).await?.iter().map(|h| h.id).max().unwrap_or(0) + 1;
|
||||||
|
let stored = Hold {
|
||||||
|
id,
|
||||||
|
..hold.clone()
|
||||||
|
};
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.assert_value(class(id), AssertValue::None);
|
||||||
|
batch.set(class(id), Json(&stored).serialize()?);
|
||||||
|
match data.write(batch.build_all()).await {
|
||||||
|
Ok(_) => return Ok(id),
|
||||||
|
Err(err)
|
||||||
|
if attempt < CREATE_ATTEMPTS
|
||||||
|
&& matches!(
|
||||||
|
err.as_ref(),
|
||||||
|
trc::EventType::Store(trc::StoreEvent::AssertValueFailed)
|
||||||
|
) => {}
|
||||||
|
Err(err) => return Err(err.caused_by(trc::location!())),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The active holds that reach `member` (LH-2, LH-11).
|
||||||
|
pub async fn covering(data: &Store, member: &Member) -> trc::Result<Vec<Hold>> {
|
||||||
|
Ok(active(data)
|
||||||
|
.await?
|
||||||
|
.into_iter()
|
||||||
|
.filter(|hold| hold.scope.covers(member))
|
||||||
|
.collect())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// LH-2: an account a hold reached through its domain, group or tenant stays
|
||||||
|
/// held when it leaves them: it is added to the hold by name. Called for
|
||||||
|
/// every change to an account, so no move escapes a hold.
|
||||||
|
pub async fn keep_moved(data: &Store, before: &Member, after: &Member) -> trc::Result<()> {
|
||||||
|
if before == after {
|
||||||
|
return Ok(());
|
||||||
|
}
|
||||||
|
for mut hold in active(data).await? {
|
||||||
|
if hold.scope.covers(before) && !hold.scope.covers(after) {
|
||||||
|
hold.scope.accounts.push(after.account);
|
||||||
|
hold.scope.accounts.sort_unstable();
|
||||||
|
hold.scope.accounts.dedup();
|
||||||
|
update(data, &hold).await?;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// LH-8: names `account_id` in every hold that reaches it, so a deleted
|
||||||
|
/// account, no longer in any domain or tenant, stays held.
|
||||||
|
pub async fn pin_account(data: &Store, member: &Member) -> trc::Result<()> {
|
||||||
|
for mut hold in covering(data, member).await? {
|
||||||
|
if !hold.scope.accounts.contains(&member.account) {
|
||||||
|
hold.scope.accounts.push(member.account);
|
||||||
|
hold.scope.accounts.sort_unstable();
|
||||||
|
update(data, &hold).await?;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Replaces a hold that `check_update` allowed.
|
||||||
|
pub async fn update(data: &Store, hold: &Hold) -> trc::Result<()> {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.set(class(hold.id), Json(hold).serialize()?);
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())
|
||||||
|
.map(|_| ())
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
fn hold(scope: Scope, from: Option<u64>, to: Option<u64>) -> Hold {
|
||||||
|
Hold {
|
||||||
|
id: 1,
|
||||||
|
name: "Matter 4411".into(),
|
||||||
|
reference: Some("4411".into()),
|
||||||
|
description: None,
|
||||||
|
scope,
|
||||||
|
from,
|
||||||
|
to,
|
||||||
|
placed_at: 10,
|
||||||
|
placed_by: "admin".into(),
|
||||||
|
placed_by_id: None,
|
||||||
|
released: None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn accounts(ids: &[u32]) -> Scope {
|
||||||
|
Scope {
|
||||||
|
accounts: ids.to_vec(),
|
||||||
|
..Default::default()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn a_hold_needs_a_scope_and_a_forward_range() {
|
||||||
|
assert_eq!(hold(Scope::default(), None, None).check_new(), Err(Refusal::EmptyScope));
|
||||||
|
assert_eq!(hold(accounts(&[2]), Some(20), Some(10)).check_new(), Err(Refusal::Backwards));
|
||||||
|
let mut ok = hold(accounts(&[3, 2, 3]), None, None);
|
||||||
|
assert_eq!(ok.check_new(), Ok(()));
|
||||||
|
assert_eq!(ok.scope.accounts, vec![2, 3], "sorted, once each");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn the_range_only_widens() {
|
||||||
|
let current = hold(accounts(&[2]), Some(100), Some(200));
|
||||||
|
let widened = |from, to| {
|
||||||
|
let mut next = hold(accounts(&[2]), from, to);
|
||||||
|
current.check_update(&mut next)
|
||||||
|
};
|
||||||
|
assert_eq!(widened(Some(50), Some(300)), Ok(()));
|
||||||
|
assert_eq!(widened(None, None), Ok(()), "opening both ends widens");
|
||||||
|
assert_eq!(widened(Some(150), Some(200)), Err(Refusal::Narrowed));
|
||||||
|
assert_eq!(widened(Some(100), Some(150)), Err(Refusal::Narrowed));
|
||||||
|
|
||||||
|
let open = hold(accounts(&[2]), None, None);
|
||||||
|
let mut closed = hold(accounts(&[2]), Some(1), None);
|
||||||
|
assert_eq!(open.check_update(&mut closed), Err(Refusal::Narrowed), "an open end stays open");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn the_scope_only_grows() {
|
||||||
|
let current = hold(
|
||||||
|
Scope {
|
||||||
|
accounts: vec![2],
|
||||||
|
domains: vec![7],
|
||||||
|
..Default::default()
|
||||||
|
},
|
||||||
|
None,
|
||||||
|
None,
|
||||||
|
);
|
||||||
|
let mut grown = hold(
|
||||||
|
Scope {
|
||||||
|
accounts: vec![2, 3],
|
||||||
|
domains: vec![7],
|
||||||
|
tenants: vec![1],
|
||||||
|
..Default::default()
|
||||||
|
},
|
||||||
|
None,
|
||||||
|
None,
|
||||||
|
);
|
||||||
|
assert_eq!(current.check_update(&mut grown), Ok(()));
|
||||||
|
let mut shrunk = hold(accounts(&[2, 3]), None, None);
|
||||||
|
assert_eq!(current.check_update(&mut shrunk), Err(Refusal::ScopeShrunk));
|
||||||
|
|
||||||
|
let server = hold(Scope { server: true, ..Default::default() }, None, None);
|
||||||
|
let mut less = hold(accounts(&[2]), None, None);
|
||||||
|
assert_eq!(server.check_update(&mut less), Err(Refusal::ScopeShrunk));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn a_released_hold_is_read_only() {
|
||||||
|
let mut released = hold(accounts(&[2]), None, None);
|
||||||
|
released.released = Some(Release {
|
||||||
|
at: 50,
|
||||||
|
by: "admin".into(),
|
||||||
|
by_id: None,
|
||||||
|
reason: "Settled".into(),
|
||||||
|
});
|
||||||
|
let mut next = released.clone();
|
||||||
|
next.name = "Renamed".into();
|
||||||
|
assert_eq!(released.check_update(&mut next), Err(Refusal::Released));
|
||||||
|
assert!(!released.is_active());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn dates_in_range() {
|
||||||
|
let whole = hold(accounts(&[2]), None, None);
|
||||||
|
assert!(whole.covers_date(0) && whole.covers_date(u64::MAX));
|
||||||
|
let ranged = hold(accounts(&[2]), Some(100), Some(200));
|
||||||
|
assert!(ranged.covers_date(100) && ranged.covers_date(200));
|
||||||
|
assert!(!ranged.covers_date(99) && !ranged.covers_date(201));
|
||||||
|
let open_ended = hold(accounts(&[2]), Some(100), None);
|
||||||
|
assert!(open_ended.covers_date(u64::MAX), "no `to` also catches mail still to come");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn a_scope_reaches_members_through_domain_group_and_tenant() {
|
||||||
|
let member = Member {
|
||||||
|
account: 9,
|
||||||
|
domains: vec![3, 4],
|
||||||
|
groups: vec![20],
|
||||||
|
tenant: Some(7),
|
||||||
|
};
|
||||||
|
let reaches = |scope: Scope| scope.covers(&member);
|
||||||
|
assert!(reaches(accounts(&[9])));
|
||||||
|
assert!(reaches(Scope { domains: vec![4], ..Default::default() }), "an alias's domain counts");
|
||||||
|
assert!(reaches(Scope { groups: vec![20], ..Default::default() }));
|
||||||
|
assert!(reaches(Scope { tenants: vec![7], ..Default::default() }));
|
||||||
|
assert!(reaches(Scope { server: true, ..Default::default() }));
|
||||||
|
assert!(!reaches(Scope { domains: vec![5], tenants: vec![8], ..Default::default() }));
|
||||||
|
|
||||||
|
// LH-2: leaving the held domain would free it, so the hold must name it
|
||||||
|
let held = hold(Scope { domains: vec![3], ..Default::default() }, None, None);
|
||||||
|
let moved = Member { domains: vec![6], ..member.clone() };
|
||||||
|
assert!(held.scope.covers(&member) && !held.scope.covers(&moved));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn keeping_deleted_items() {
|
||||||
|
let whole = Keeping::new(None, &[hold(accounts(&[2]), None, None)]);
|
||||||
|
assert!(whole.covers(Some(5)) && whole.covers(None));
|
||||||
|
assert_eq!(whole.until(100, whole.covers(Some(5))), Some(HELD_UNTIL));
|
||||||
|
assert!(is_held_until(whole.until(100, true).unwrap()));
|
||||||
|
|
||||||
|
// LH-3: a range holds only what's inside it; outside, undelete's rules
|
||||||
|
let ranged = Keeping::new(Some(30), &[hold(accounts(&[2]), Some(1_000), Some(2_000))]);
|
||||||
|
assert!(ranged.covers(Some(1_500)) && !ranged.covers(Some(2_500)));
|
||||||
|
assert!(ranged.covers(None), "contacts, files and scripts are held whole");
|
||||||
|
assert_eq!(ranged.until(100, ranged.covers(Some(2_500))), Some(130));
|
||||||
|
assert!(ranged.covers_event(Some(2_000 + 3_600)), "a day of slack for an event");
|
||||||
|
|
||||||
|
// Neither held nor undelete: nothing is kept
|
||||||
|
let none = Keeping::new(None, &[]);
|
||||||
|
assert!(!none.keeps_anything());
|
||||||
|
assert_eq!(none.until(100, false), None);
|
||||||
|
assert!(!is_held_until(100 + 30 * 365 * 86_400));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn stored_as_json() {
|
||||||
|
let current = hold(accounts(&[2]), Some(100), None);
|
||||||
|
let json = serde_json::to_string(¤t).unwrap();
|
||||||
|
assert_eq!(serde_json::from_str::<Hold>(&json).unwrap(), current);
|
||||||
|
assert!(json.contains("\"scope\":{\"accounts\":[2]}"), "{json}");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,120 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! Reports on their way to an outside archive (JR-7). Keys, after `J`:
|
||||||
|
//!
|
||||||
|
//! - `o` + the report's queue id: what goes into the built-in journal if
|
||||||
|
//! the archive never takes the report, as JSON. Cleared once it's
|
||||||
|
//! delivered or kept.
|
||||||
|
//! - `w` + journal id (u32): how often that journal's archive didn't take a
|
||||||
|
//! report, and the last time and reason, for the console's warning.
|
||||||
|
|
||||||
|
use super::{FEATURE, Json, entries::Entry};
|
||||||
|
use serde::{Deserialize as SerdeDeserialize, Serialize as SerdeSerialize};
|
||||||
|
use store::{
|
||||||
|
SUBSPACE_INBUXA, Serialize, Store, ValueKey,
|
||||||
|
write::{AnyClass, BatchBuilder, ValueClass},
|
||||||
|
};
|
||||||
|
use trc::AddContext;
|
||||||
|
|
||||||
|
const KIND_PENDING: u8 = b'o';
|
||||||
|
const KIND_FAILURES: u8 = b'w';
|
||||||
|
|
||||||
|
/// A report queued to an archive.
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub struct Pending {
|
||||||
|
pub address: String,
|
||||||
|
/// The entry, should the archive not take it: its own, with the
|
||||||
|
/// sending journals' retention, whatever else the built-in journal has.
|
||||||
|
pub entry: Entry,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// How a journal's archive has been taking its reports.
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub struct Failures {
|
||||||
|
pub count: u64,
|
||||||
|
/// Seconds.
|
||||||
|
pub last_at: u64,
|
||||||
|
pub last_reason: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
fn class(kind: u8, id: &[u8]) -> ValueClass {
|
||||||
|
let mut key = Vec::with_capacity(2 + id.len());
|
||||||
|
key.push(FEATURE);
|
||||||
|
key.push(kind);
|
||||||
|
key.extend_from_slice(id);
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace: SUBSPACE_INBUXA,
|
||||||
|
key,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
pub async fn set_pending(data: &Store, queue_id: u64, pending: &Pending) -> trc::Result<()> {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.set(
|
||||||
|
class(KIND_PENDING, &queue_id.to_be_bytes()),
|
||||||
|
Json(pending).serialize()?,
|
||||||
|
);
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
pub async fn pending(data: &Store, queue_id: u64) -> trc::Result<Option<Pending>> {
|
||||||
|
Ok(data
|
||||||
|
.get_value::<Json<Pending>>(ValueKey::from(class(KIND_PENDING, &queue_id.to_be_bytes())))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
.map(|Json(pending)| pending))
|
||||||
|
}
|
||||||
|
|
||||||
|
pub async fn clear_pending(data: &Store, queue_id: u64) -> trc::Result<()> {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.clear(class(KIND_PENDING, &queue_id.to_be_bytes()));
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
pub async fn failures(data: &Store, journal_id: u32) -> trc::Result<Failures> {
|
||||||
|
Ok(data
|
||||||
|
.get_value::<Json<Failures>>(ValueKey::from(class(
|
||||||
|
KIND_FAILURES,
|
||||||
|
&journal_id.to_be_bytes(),
|
||||||
|
)))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
.map(|Json(failures)| failures)
|
||||||
|
.unwrap_or_default())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Counts one report an archive didn't take, for each of `journals`.
|
||||||
|
pub async fn record_failure(
|
||||||
|
data: &Store,
|
||||||
|
journals: &[u32],
|
||||||
|
at: u64,
|
||||||
|
reason: &str,
|
||||||
|
) -> trc::Result<()> {
|
||||||
|
for journal_id in journals {
|
||||||
|
let mut failures = failures(data, *journal_id).await?;
|
||||||
|
failures.count += 1;
|
||||||
|
failures.last_at = at;
|
||||||
|
failures.last_reason = reason.chars().take(500).collect();
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.set(
|
||||||
|
class(KIND_FAILURES, &journal_id.to_be_bytes()),
|
||||||
|
Json(&failures).serialize()?,
|
||||||
|
);
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
}
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
@@ -0,0 +1,869 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! The built-in journal (JR-5, JR-6, JR-13). Keys, after `J`:
|
||||||
|
//!
|
||||||
|
//! - `e` + node + seq: a chain link: its seq, the hash of the link before
|
||||||
|
//! it, and the SHA-256 of its entry. One chain per node, as the audit log
|
||||||
|
//! keeps (AU-6), but a link names its entry by hash instead of holding it,
|
||||||
|
//! so an entry can go at the end of its own retention without breaking
|
||||||
|
//! the chain: entries don't expire in chain order.
|
||||||
|
//! - `c` + node + seq: the entry, as JSON; its bytes are what the link's
|
||||||
|
//! hash names.
|
||||||
|
//! - `p` + node + seq: when an entry past its retention was purged. A link
|
||||||
|
//! whose entry is gone without this marker is a broken chain.
|
||||||
|
//! - `t` + time + node + seq: the time index, for search.
|
||||||
|
//! - `x` + expiry + node + seq: the expiry index, for purge.
|
||||||
|
//! - `h` + node: the chain's head: its hash, then its seq as the last eight
|
||||||
|
//! bytes, which each append asserts.
|
||||||
|
//! - `f` + node: where the chain starts after purged links at its start
|
||||||
|
//! were cleared, and the hash the first kept link names.
|
||||||
|
//!
|
||||||
|
//! The report itself is a blob, kept by a temporary link that lasts until
|
||||||
|
//! its entry is purged. Nothing here changes or removes an entry before
|
||||||
|
//! its time; nothing in JMAP can.
|
||||||
|
|
||||||
|
use super::{Direction, FEATURE, Json};
|
||||||
|
use crate::hold::HELD_UNTIL;
|
||||||
|
use serde::{Deserialize as SerdeDeserialize, Serialize as SerdeSerialize};
|
||||||
|
use sha2::{Digest, Sha256};
|
||||||
|
use std::fmt;
|
||||||
|
use store::{
|
||||||
|
BlobStore, Deserialize, IterateParams, SUBSPACE_INBUXA, Serialize, Store, ValueKey,
|
||||||
|
write::{AnyClass, BatchBuilder, BlobLink, BlobOp, ValueClass, assert::AssertValue},
|
||||||
|
};
|
||||||
|
use tokio::sync::Mutex;
|
||||||
|
use trc::AddContext;
|
||||||
|
use types::blob_hash::BlobHash;
|
||||||
|
|
||||||
|
const KIND_LINK: u8 = b'e';
|
||||||
|
const KIND_CONTENT: u8 = b'c';
|
||||||
|
const KIND_PURGED: u8 = b'p';
|
||||||
|
const KIND_TIME: u8 = b't';
|
||||||
|
const KIND_EXPIRY: u8 = b'x';
|
||||||
|
const KIND_HEAD: u8 = b'h';
|
||||||
|
const KIND_FLOOR: u8 = b'f';
|
||||||
|
|
||||||
|
const APPEND_ATTEMPTS: usize = 5;
|
||||||
|
/// Entries purged per batch.
|
||||||
|
const PURGE_BATCH: usize = 100;
|
||||||
|
|
||||||
|
/// Where one entry sits: its node's chain and its place in it.
|
||||||
|
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, PartialOrd, Ord)]
|
||||||
|
pub struct EntryId {
|
||||||
|
pub node: u64,
|
||||||
|
pub seq: u64,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl EntryId {
|
||||||
|
/// As one number, for JMAP ids: the node in the top 16 bits.
|
||||||
|
pub fn to_u64(&self) -> u64 {
|
||||||
|
(self.node << 48) | (self.seq & ((1 << 48) - 1))
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn from_u64(id: u64) -> Self {
|
||||||
|
EntryId {
|
||||||
|
node: id >> 48,
|
||||||
|
seq: id & ((1 << 48) - 1),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl fmt::Display for EntryId {
|
||||||
|
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
|
||||||
|
write!(f, "{}-{}", self.node, self.seq)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// One journaled message (JR-5).
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub struct Entry {
|
||||||
|
pub queue_id: u64,
|
||||||
|
/// Seconds.
|
||||||
|
pub at: u64,
|
||||||
|
pub direction: Direction,
|
||||||
|
pub sender: String,
|
||||||
|
pub authenticated: bool,
|
||||||
|
pub recipients: Vec<String>,
|
||||||
|
pub subject: String,
|
||||||
|
pub message_id: String,
|
||||||
|
/// The people here on either side, whose holds keep the entry.
|
||||||
|
pub accounts: Vec<u32>,
|
||||||
|
pub tenants: Vec<u32>,
|
||||||
|
/// The journals that took it.
|
||||||
|
pub journals: Vec<u32>,
|
||||||
|
pub held: bool,
|
||||||
|
/// The report's blob, hex.
|
||||||
|
pub blob: String,
|
||||||
|
pub size: u64,
|
||||||
|
/// SHA-256 of the report, hex.
|
||||||
|
pub sha256: String,
|
||||||
|
/// Seconds.
|
||||||
|
pub expires_at: u64,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Entry {
|
||||||
|
pub fn blob_hash(&self) -> Option<BlobHash> {
|
||||||
|
let bytes = unhex(&self.blob)?;
|
||||||
|
BlobHash::try_from_hash_slice(&bytes).ok()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
struct Link {
|
||||||
|
seq: u64,
|
||||||
|
prev: String,
|
||||||
|
content: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
struct Floor {
|
||||||
|
seq: u64,
|
||||||
|
prev: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq)]
|
||||||
|
struct Head {
|
||||||
|
seq: u64,
|
||||||
|
hash: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Head {
|
||||||
|
fn to_bytes(&self) -> Vec<u8> {
|
||||||
|
let mut bytes = self.hash.as_bytes().to_vec();
|
||||||
|
bytes.extend_from_slice(&self.seq.to_be_bytes());
|
||||||
|
bytes
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Deserialize for Head {
|
||||||
|
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
|
||||||
|
let split = bytes.len().checked_sub(8).ok_or_else(|| {
|
||||||
|
trc::StoreEvent::DataCorruption
|
||||||
|
.into_err()
|
||||||
|
.details("Invalid journal chain head")
|
||||||
|
})?;
|
||||||
|
Ok(Head {
|
||||||
|
seq: u64::from_be_bytes(bytes[split..].try_into().unwrap()),
|
||||||
|
hash: String::from_utf8_lossy(&bytes[..split]).into_owned(),
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
struct Raw(Vec<u8>);
|
||||||
|
|
||||||
|
impl Deserialize for Raw {
|
||||||
|
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
|
||||||
|
Ok(Raw(bytes.to_vec()))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn class(kind: u8, parts: &[u64]) -> ValueClass {
|
||||||
|
let mut key = Vec::with_capacity(2 + parts.len() * 8);
|
||||||
|
key.push(FEATURE);
|
||||||
|
key.push(kind);
|
||||||
|
for part in parts {
|
||||||
|
key.extend_from_slice(&part.to_be_bytes());
|
||||||
|
}
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace: SUBSPACE_INBUXA,
|
||||||
|
key,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
fn key(kind: u8, parts: &[u64]) -> ValueKey<ValueClass> {
|
||||||
|
ValueKey::from(class(kind, parts))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Where an entry's content is kept, for tests that check tampering shows.
|
||||||
|
pub fn content_key(id: EntryId) -> ValueKey<ValueClass> {
|
||||||
|
key(KIND_CONTENT, &[id.node, id.seq])
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The numbers after the kind byte, from the key's tail.
|
||||||
|
fn parse_key(key: &[u8], kind: u8, parts: usize) -> Option<Vec<u64>> {
|
||||||
|
let len = 2 + parts * 8;
|
||||||
|
let tail = key.get(key.len().checked_sub(len)?..)?;
|
||||||
|
(tail[0] == FEATURE && tail[1] == kind).then_some(())?;
|
||||||
|
Some(
|
||||||
|
tail[2..]
|
||||||
|
.chunks_exact(8)
|
||||||
|
.map(|chunk| u64::from_be_bytes(chunk.try_into().unwrap()))
|
||||||
|
.collect(),
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn hex(bytes: &[u8]) -> String {
|
||||||
|
bytes.iter().map(|b| format!("{b:02x}")).collect()
|
||||||
|
}
|
||||||
|
|
||||||
|
fn unhex(value: &str) -> Option<Vec<u8>> {
|
||||||
|
(value.len() % 2 == 0).then_some(())?;
|
||||||
|
(0..value.len())
|
||||||
|
.step_by(2)
|
||||||
|
.map(|i| u8::from_str_radix(value.get(i..i + 2)?, 16).ok())
|
||||||
|
.collect()
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn sha256(bytes: &[u8]) -> String {
|
||||||
|
hex(&Sha256::digest(bytes))
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn head(data: &Store, node: u64) -> trc::Result<Option<Head>> {
|
||||||
|
data.get_value::<Head>(key(KIND_HEAD, &[node]))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn floor(data: &Store, node: u64) -> trc::Result<Floor> {
|
||||||
|
Ok(data
|
||||||
|
.get_value::<Json<Floor>>(key(KIND_FLOOR, &[node]))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
.map(|Json(floor)| floor)
|
||||||
|
.unwrap_or(Floor {
|
||||||
|
seq: 1,
|
||||||
|
prev: String::new(),
|
||||||
|
}))
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn nodes(data: &Store) -> trc::Result<Vec<u64>> {
|
||||||
|
let mut nodes = Vec::new();
|
||||||
|
data.iterate(
|
||||||
|
IterateParams::new(key(KIND_HEAD, &[0]), key(KIND_HEAD, &[u64::MAX])).no_values(),
|
||||||
|
|key, _| {
|
||||||
|
if let Some(parts) = parse_key(key, KIND_HEAD, 1) {
|
||||||
|
nodes.push(parts[0]);
|
||||||
|
}
|
||||||
|
Ok(true)
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
Ok(nodes)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Lines up this process's appends; the store's assert settles the rest.
|
||||||
|
static APPENDING: Mutex<()> = Mutex::const_new(());
|
||||||
|
|
||||||
|
/// Adds an entry to this node's chain, and links its report's blob (already
|
||||||
|
/// written) until the entry is purged. An error means nothing was written.
|
||||||
|
pub async fn append(data: &Store, node: u64, entry: &Entry) -> trc::Result<EntryId> {
|
||||||
|
let blob = entry.blob_hash().ok_or_else(|| {
|
||||||
|
trc::StoreEvent::UnexpectedError
|
||||||
|
.into_err()
|
||||||
|
.details("Journal entry without a blob")
|
||||||
|
})?;
|
||||||
|
let content = Json(entry).serialize()?;
|
||||||
|
let content_hash = sha256(&content);
|
||||||
|
let _appending = APPENDING.lock().await;
|
||||||
|
let mut attempt = 0;
|
||||||
|
loop {
|
||||||
|
attempt += 1;
|
||||||
|
let current = head(data, node).await?;
|
||||||
|
let (seq, prev) = current
|
||||||
|
.as_ref()
|
||||||
|
.map_or((1, String::new()), |head| (head.seq + 1, head.hash.clone()));
|
||||||
|
let link = Json(&Link {
|
||||||
|
seq,
|
||||||
|
prev,
|
||||||
|
content: content_hash.clone(),
|
||||||
|
})
|
||||||
|
.serialize()?;
|
||||||
|
let new_head = Head {
|
||||||
|
seq,
|
||||||
|
hash: sha256(&link),
|
||||||
|
};
|
||||||
|
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.assert_value(
|
||||||
|
class(KIND_HEAD, &[node]),
|
||||||
|
current.map_or(AssertValue::None, |head| AssertValue::U64(head.seq)),
|
||||||
|
);
|
||||||
|
batch
|
||||||
|
.set(class(KIND_LINK, &[node, seq]), link)
|
||||||
|
.set(class(KIND_CONTENT, &[node, seq]), content.clone())
|
||||||
|
.set(class(KIND_TIME, &[entry.at, node, seq]), vec![])
|
||||||
|
.set(class(KIND_EXPIRY, &[entry.expires_at, node, seq]), vec![])
|
||||||
|
.set(class(KIND_HEAD, &[node]), new_head.to_bytes())
|
||||||
|
.set(
|
||||||
|
BlobOp::Link {
|
||||||
|
hash: blob.clone(),
|
||||||
|
to: BlobLink::Temporary { until: HELD_UNTIL },
|
||||||
|
},
|
||||||
|
vec![],
|
||||||
|
)
|
||||||
|
.set(BlobOp::Commit { hash: blob.clone() }, vec![]);
|
||||||
|
match data.write(batch.build_all()).await {
|
||||||
|
Ok(_) => return Ok(EntryId { node, seq }),
|
||||||
|
Err(err)
|
||||||
|
if attempt < APPEND_ATTEMPTS
|
||||||
|
&& matches!(
|
||||||
|
err.as_ref(),
|
||||||
|
trc::EventType::Store(trc::StoreEvent::AssertValueFailed)
|
||||||
|
) => {}
|
||||||
|
Err(err) => return Err(err.caused_by(trc::location!())),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// One entry, unless it was purged.
|
||||||
|
pub async fn get(data: &Store, id: EntryId) -> trc::Result<Option<Entry>> {
|
||||||
|
Ok(data
|
||||||
|
.get_value::<Json<Entry>>(key(KIND_CONTENT, &[id.node, id.seq]))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
.map(|Json(entry)| entry))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Entries written in `[after, before)` (seconds), newest first, up to
|
||||||
|
/// `limit`.
|
||||||
|
pub async fn list(
|
||||||
|
data: &Store,
|
||||||
|
after: u64,
|
||||||
|
before: u64,
|
||||||
|
limit: usize,
|
||||||
|
) -> trc::Result<Vec<(EntryId, Entry)>> {
|
||||||
|
let mut ids = Vec::new();
|
||||||
|
data.iterate(
|
||||||
|
IterateParams::new(
|
||||||
|
key(KIND_TIME, &[after, 0, 0]),
|
||||||
|
key(KIND_TIME, &[before.saturating_sub(1), u64::MAX, u64::MAX]),
|
||||||
|
)
|
||||||
|
.descending()
|
||||||
|
.no_values(),
|
||||||
|
|key, _| {
|
||||||
|
if let Some(parts) = parse_key(key, KIND_TIME, 3) {
|
||||||
|
ids.push(EntryId {
|
||||||
|
node: parts[1],
|
||||||
|
seq: parts[2],
|
||||||
|
});
|
||||||
|
}
|
||||||
|
Ok(ids.len() < limit)
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
let mut out = Vec::with_capacity(ids.len());
|
||||||
|
for id in ids {
|
||||||
|
if let Some(entry) = get(data, id).await? {
|
||||||
|
out.push((id, entry));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Ok(out)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Most results one search page returns.
|
||||||
|
pub const MAX_QUERY_LIMIT: usize = 500;
|
||||||
|
|
||||||
|
/// A search of the journal (JR-15): conditions that must all hold.
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, Eq, SerdeSerialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub struct Filter {
|
||||||
|
/// From this time on, in seconds.
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub after: Option<u64>,
|
||||||
|
/// Before this time, in seconds.
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub before: Option<u64>,
|
||||||
|
/// Part of the sender's address, ignoring case.
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub sender: Option<String>,
|
||||||
|
/// Part of any recipient's address, ignoring case.
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub recipient: Option<String>,
|
||||||
|
/// Part of the sender's or any recipient's address.
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub address: Option<String>,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub direction: Option<Direction>,
|
||||||
|
/// Words that must all appear in the subject, ignoring case.
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub text: Option<String>,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub message_id: Option<String>,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub journal_id: Option<u32>,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Filter {
|
||||||
|
pub fn matches(&self, entry: &Entry) -> bool {
|
||||||
|
let has = |value: &str, part: &str| value.to_lowercase().contains(&part.to_lowercase());
|
||||||
|
self.after.is_none_or(|after| entry.at >= after)
|
||||||
|
&& self.before.is_none_or(|before| entry.at < before)
|
||||||
|
&& self.sender.as_deref().is_none_or(|s| has(&entry.sender, s))
|
||||||
|
&& self
|
||||||
|
.recipient
|
||||||
|
.as_deref()
|
||||||
|
.is_none_or(|r| entry.recipients.iter().any(|a| has(a, r)))
|
||||||
|
&& self
|
||||||
|
.address
|
||||||
|
.as_deref()
|
||||||
|
.is_none_or(|a| has(&entry.sender, a) || entry.recipients.iter().any(|r| has(r, a)))
|
||||||
|
&& self
|
||||||
|
.direction
|
||||||
|
.is_none_or(|d| d == Direction::Any || d == entry.direction)
|
||||||
|
&& self.text.as_deref().is_none_or(|text| {
|
||||||
|
let subject = entry.subject.to_lowercase();
|
||||||
|
text.to_lowercase()
|
||||||
|
.split_whitespace()
|
||||||
|
.all(|word| subject.contains(word))
|
||||||
|
})
|
||||||
|
&& self.message_id.as_deref().is_none_or(|id| {
|
||||||
|
entry.message_id.trim_matches(['<', '>']) == id.trim_matches(['<', '>'])
|
||||||
|
})
|
||||||
|
&& self.journal_id.is_none_or(|j| entry.journals.contains(&j))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Entries matching `filter`, newest first: a page from `position`, up to
|
||||||
|
/// `limit`, and, when asked, how many match in all.
|
||||||
|
pub async fn query(
|
||||||
|
data: &Store,
|
||||||
|
filter: &Filter,
|
||||||
|
position: usize,
|
||||||
|
limit: usize,
|
||||||
|
count_all: bool,
|
||||||
|
) -> trc::Result<(Vec<EntryId>, usize)> {
|
||||||
|
let after = filter.after.unwrap_or(0);
|
||||||
|
let before = filter.before.unwrap_or(u64::MAX);
|
||||||
|
let mut ids = Vec::new();
|
||||||
|
data.iterate(
|
||||||
|
IterateParams::new(
|
||||||
|
key(KIND_TIME, &[after, 0, 0]),
|
||||||
|
key(KIND_TIME, &[before.saturating_sub(1), u64::MAX, u64::MAX]),
|
||||||
|
)
|
||||||
|
.descending()
|
||||||
|
.no_values(),
|
||||||
|
|key, _| {
|
||||||
|
if let Some(parts) = parse_key(key, KIND_TIME, 3) {
|
||||||
|
ids.push(EntryId {
|
||||||
|
node: parts[1],
|
||||||
|
seq: parts[2],
|
||||||
|
});
|
||||||
|
}
|
||||||
|
Ok(true)
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
let mut page = Vec::new();
|
||||||
|
let mut total = 0;
|
||||||
|
for id in ids {
|
||||||
|
let Some(entry) = get(data, id).await? else {
|
||||||
|
continue;
|
||||||
|
};
|
||||||
|
if !filter.matches(&entry) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
if total >= position && page.len() < limit {
|
||||||
|
page.push(id);
|
||||||
|
}
|
||||||
|
total += 1;
|
||||||
|
if !count_all && page.len() >= limit {
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Ok((page, total))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// What a purge did.
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, Eq)]
|
||||||
|
pub struct Purged {
|
||||||
|
pub removed: usize,
|
||||||
|
/// Past their time, kept for a legal hold.
|
||||||
|
pub kept_for_hold: usize,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Removes entries past their retention (JR-13), except those `held` keeps:
|
||||||
|
/// the entry, its indexes and its blob's link go; the chain link stays,
|
||||||
|
/// with a purge marker. Then each chain's start moves past purged links.
|
||||||
|
pub async fn purge(
|
||||||
|
data: &Store,
|
||||||
|
now: u64,
|
||||||
|
held: impl Fn(&Entry) -> bool + Sync + Send,
|
||||||
|
) -> trc::Result<Purged> {
|
||||||
|
let mut due = Vec::new();
|
||||||
|
data.iterate(
|
||||||
|
IterateParams::new(
|
||||||
|
key(KIND_EXPIRY, &[0, 0, 0]),
|
||||||
|
key(KIND_EXPIRY, &[now, u64::MAX, u64::MAX]),
|
||||||
|
)
|
||||||
|
.ascending()
|
||||||
|
.no_values(),
|
||||||
|
|key, _| {
|
||||||
|
if let Some(parts) = parse_key(key, KIND_EXPIRY, 3) {
|
||||||
|
due.push((
|
||||||
|
parts[0],
|
||||||
|
EntryId {
|
||||||
|
node: parts[1],
|
||||||
|
seq: parts[2],
|
||||||
|
},
|
||||||
|
));
|
||||||
|
}
|
||||||
|
Ok(due.len() < 100_000)
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
|
||||||
|
let mut purged = Purged::default();
|
||||||
|
for chunk in due.chunks(PURGE_BATCH) {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
for (expires_at, id) in chunk {
|
||||||
|
let parts = [id.node, id.seq];
|
||||||
|
let Some(entry) = get(data, *id).await? else {
|
||||||
|
// Its entry is already gone: only the index is left
|
||||||
|
batch.clear(class(KIND_EXPIRY, &[*expires_at, id.node, id.seq]));
|
||||||
|
continue;
|
||||||
|
};
|
||||||
|
if held(&entry) {
|
||||||
|
purged.kept_for_hold += 1;
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
batch
|
||||||
|
.clear(class(KIND_CONTENT, &parts))
|
||||||
|
.clear(class(KIND_TIME, &[entry.at, id.node, id.seq]))
|
||||||
|
.clear(class(KIND_EXPIRY, &[*expires_at, id.node, id.seq]))
|
||||||
|
.set(class(KIND_PURGED, &parts), now.to_be_bytes().to_vec());
|
||||||
|
if let Some(blob) = entry.blob_hash() {
|
||||||
|
batch.clear(BlobOp::Link {
|
||||||
|
hash: blob,
|
||||||
|
to: BlobLink::Temporary { until: HELD_UNTIL },
|
||||||
|
});
|
||||||
|
}
|
||||||
|
purged.removed += 1;
|
||||||
|
}
|
||||||
|
if !batch.is_empty() {
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
for node in nodes(data).await? {
|
||||||
|
advance_floor(data, node).await?;
|
||||||
|
}
|
||||||
|
Ok(purged)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Clears the purged links at the start of a node's chain, recording where
|
||||||
|
/// it now starts and the hash that start names.
|
||||||
|
async fn advance_floor(data: &Store, node: u64) -> trc::Result<()> {
|
||||||
|
let start = floor(data, node).await?;
|
||||||
|
let mut cleared: Vec<u64> = Vec::new();
|
||||||
|
let mut next = start.clone();
|
||||||
|
let mut purged_seqs = Vec::new();
|
||||||
|
data.iterate(
|
||||||
|
IterateParams::new(
|
||||||
|
key(KIND_PURGED, &[node, start.seq]),
|
||||||
|
key(KIND_PURGED, &[node, u64::MAX]),
|
||||||
|
)
|
||||||
|
.ascending()
|
||||||
|
.no_values(),
|
||||||
|
|key, _| {
|
||||||
|
if let Some(parts) = parse_key(key, KIND_PURGED, 2) {
|
||||||
|
purged_seqs.push(parts[1]);
|
||||||
|
}
|
||||||
|
Ok(purged_seqs.len() < 100_000)
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
for seq in purged_seqs {
|
||||||
|
if seq != next.seq {
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
let Some(Raw(link)) = data
|
||||||
|
.get_value::<Raw>(key(KIND_LINK, &[node, seq]))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
else {
|
||||||
|
break;
|
||||||
|
};
|
||||||
|
next = Floor {
|
||||||
|
seq: seq + 1,
|
||||||
|
prev: sha256(&link),
|
||||||
|
};
|
||||||
|
cleared.push(seq);
|
||||||
|
}
|
||||||
|
if cleared.is_empty() {
|
||||||
|
return Ok(());
|
||||||
|
}
|
||||||
|
// The floor moves first: a run cut short leaves links before it, which
|
||||||
|
// the next run clears, never a chain that looks broken
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.set(class(KIND_FLOOR, &[node]), Json(&next).serialize()?);
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
for chunk in cleared.chunks(PURGE_BATCH) {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
for seq in chunk {
|
||||||
|
batch
|
||||||
|
.clear(class(KIND_LINK, &[node, *seq]))
|
||||||
|
.clear(class(KIND_PURGED, &[node, *seq]));
|
||||||
|
}
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
}
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// One node's chain, as [`verify`] found it.
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub struct ChainReport {
|
||||||
|
pub node: u64,
|
||||||
|
pub entries: u64,
|
||||||
|
pub purged: u64,
|
||||||
|
pub first_seq: u64,
|
||||||
|
pub last_seq: u64,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub broken_at: Option<String>,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub reason: Option<String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Rechecks every node's chain (JR-6): each link names the hash of the one
|
||||||
|
/// before it, seqs run without gaps, the head matches the last link, each
|
||||||
|
/// entry hashes to what its link names or was purged, and, with `blobs`,
|
||||||
|
/// each report is there and hashes to what its entry names.
|
||||||
|
pub async fn verify(data: &Store, blobs: Option<&BlobStore>) -> trc::Result<Vec<ChainReport>> {
|
||||||
|
let mut reports = Vec::new();
|
||||||
|
for node in nodes(data).await? {
|
||||||
|
let start = floor(data, node).await?;
|
||||||
|
let head = head(data, node).await?.unwrap_or_default();
|
||||||
|
let mut report = ChainReport {
|
||||||
|
node,
|
||||||
|
entries: 0,
|
||||||
|
purged: 0,
|
||||||
|
first_seq: start.seq,
|
||||||
|
last_seq: start.seq.saturating_sub(1),
|
||||||
|
broken_at: None,
|
||||||
|
reason: None,
|
||||||
|
};
|
||||||
|
let mut links = Vec::new();
|
||||||
|
data.iterate(
|
||||||
|
IterateParams::new(
|
||||||
|
key(KIND_LINK, &[node, start.seq]),
|
||||||
|
key(KIND_LINK, &[node, u64::MAX]),
|
||||||
|
)
|
||||||
|
.ascending(),
|
||||||
|
|key, value| {
|
||||||
|
if let Some(parts) = parse_key(key, KIND_LINK, 2) {
|
||||||
|
links.push((parts[1], value.to_vec()));
|
||||||
|
}
|
||||||
|
Ok(true)
|
||||||
|
},
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
|
||||||
|
let mut expected_seq = start.seq;
|
||||||
|
let mut expected_prev = start.prev.clone();
|
||||||
|
for (seq, bytes) in links {
|
||||||
|
let broken = |report: &mut ChainReport, reason: &str| {
|
||||||
|
report.broken_at = Some(EntryId { node, seq }.to_string());
|
||||||
|
report.reason = Some(reason.to_string());
|
||||||
|
};
|
||||||
|
let Ok(Json(link)) = Json::<Link>::deserialize(&bytes) else {
|
||||||
|
broken(&mut report, "The link can't be read.");
|
||||||
|
break;
|
||||||
|
};
|
||||||
|
if seq != expected_seq || link.seq != seq {
|
||||||
|
report.broken_at = Some(EntryId { node, seq }.to_string());
|
||||||
|
report.reason = Some(format!(
|
||||||
|
"Entry {expected_seq} is missing; the next one found is {seq}."
|
||||||
|
));
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
if link.prev != expected_prev {
|
||||||
|
broken(
|
||||||
|
&mut report,
|
||||||
|
"The link doesn't follow from the one before it: one of them was changed.",
|
||||||
|
);
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
match data
|
||||||
|
.get_value::<Raw>(key(KIND_CONTENT, &[node, seq]))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
{
|
||||||
|
Some(Raw(content)) => {
|
||||||
|
if sha256(&content) != link.content {
|
||||||
|
broken(&mut report, "The entry was changed after it was written.");
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
if let Some(blobs) = blobs {
|
||||||
|
let Ok(Json(entry)) = Json::<Entry>::deserialize(&content) else {
|
||||||
|
broken(&mut report, "The entry can't be read.");
|
||||||
|
break;
|
||||||
|
};
|
||||||
|
let report_bytes = match entry.blob_hash() {
|
||||||
|
Some(hash) => blobs
|
||||||
|
.get_blob(hash.as_slice(), 0..usize::MAX)
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?,
|
||||||
|
None => None,
|
||||||
|
};
|
||||||
|
match report_bytes {
|
||||||
|
Some(bytes) if sha256(&bytes) == entry.sha256 => {}
|
||||||
|
Some(_) => {
|
||||||
|
broken(&mut report, "The report doesn't match its entry.");
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
None => {
|
||||||
|
broken(&mut report, "The report is missing.");
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
report.entries += 1;
|
||||||
|
}
|
||||||
|
None => {
|
||||||
|
if data
|
||||||
|
.get_value::<Raw>(key(KIND_PURGED, &[node, seq]))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
.is_none()
|
||||||
|
{
|
||||||
|
broken(&mut report, "The entry was removed before its time.");
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
report.purged += 1;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
expected_prev = sha256(&bytes);
|
||||||
|
expected_seq = seq + 1;
|
||||||
|
report.last_seq = seq;
|
||||||
|
}
|
||||||
|
|
||||||
|
if report.broken_at.is_none()
|
||||||
|
&& (head.seq != report.last_seq
|
||||||
|
|| (report.last_seq >= report.first_seq && head.hash != expected_prev))
|
||||||
|
{
|
||||||
|
report.broken_at = Some(
|
||||||
|
EntryId {
|
||||||
|
node,
|
||||||
|
seq: report.last_seq,
|
||||||
|
}
|
||||||
|
.to_string(),
|
||||||
|
);
|
||||||
|
report.reason = Some(
|
||||||
|
"The chain's recorded end doesn't match its last link: entries were removed \
|
||||||
|
or changed at the end."
|
||||||
|
.into(),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
reports.push(report);
|
||||||
|
}
|
||||||
|
Ok(reports)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn keys_read_back() {
|
||||||
|
let ValueClass::Any(any) = class(KIND_EXPIRY, &[5, 3, 9]) else {
|
||||||
|
panic!()
|
||||||
|
};
|
||||||
|
assert_eq!(parse_key(&any.key, KIND_EXPIRY, 3), Some(vec![5, 3, 9]));
|
||||||
|
let mut with_subspace = vec![SUBSPACE_INBUXA];
|
||||||
|
with_subspace.extend_from_slice(&any.key);
|
||||||
|
assert_eq!(
|
||||||
|
parse_key(&with_subspace, KIND_EXPIRY, 3),
|
||||||
|
Some(vec![5, 3, 9])
|
||||||
|
);
|
||||||
|
assert_eq!(parse_key(&any.key, KIND_TIME, 3), None);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn filters_match() {
|
||||||
|
let entry = Entry {
|
||||||
|
queue_id: 1,
|
||||||
|
at: 100,
|
||||||
|
direction: Direction::Outgoing,
|
||||||
|
sender: "[email protected]".into(),
|
||||||
|
authenticated: true,
|
||||||
|
recipients: vec!["[email protected]".into()],
|
||||||
|
subject: "Q3 figures, final".into(),
|
||||||
|
message_id: "<[email protected]>".into(),
|
||||||
|
accounts: vec![3],
|
||||||
|
tenants: vec![],
|
||||||
|
journals: vec![2],
|
||||||
|
held: false,
|
||||||
|
blob: String::new(),
|
||||||
|
size: 0,
|
||||||
|
sha256: String::new(),
|
||||||
|
expires_at: 0,
|
||||||
|
};
|
||||||
|
let yes = |f: Filter| assert!(f.matches(&entry), "{f:?}");
|
||||||
|
let no = |f: Filter| assert!(!f.matches(&entry), "{f:?}");
|
||||||
|
yes(Filter::default());
|
||||||
|
yes(Filter {
|
||||||
|
sender: Some("alice@".into()),
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
yes(Filter {
|
||||||
|
address: Some("BANK".into()),
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
yes(Filter {
|
||||||
|
text: Some("final q3".into()),
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
yes(Filter {
|
||||||
|
message_id: Some("[email protected]".into()),
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
yes(Filter {
|
||||||
|
direction: Some(Direction::Any),
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
no(Filter {
|
||||||
|
direction: Some(Direction::Incoming),
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
no(Filter {
|
||||||
|
recipient: Some("alice".into()),
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
no(Filter {
|
||||||
|
before: Some(100),
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
yes(Filter {
|
||||||
|
after: Some(100),
|
||||||
|
journal_id: Some(2),
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
no(Filter {
|
||||||
|
journal_id: Some(5),
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn hex_round_trips() {
|
||||||
|
let bytes = [0u8, 1, 0xab, 0xff];
|
||||||
|
assert_eq!(unhex(&hex(&bytes)), Some(bytes.to_vec()));
|
||||||
|
assert_eq!(unhex("abc"), None);
|
||||||
|
assert_eq!(unhex("zz"), None);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn ids_read_back() {
|
||||||
|
let id = EntryId { node: 3, seq: 77 };
|
||||||
|
assert_eq!(EntryId::from_u64(id.to_u64()), id);
|
||||||
|
assert_eq!(id.to_string(), "3-77");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,512 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! Journaling (journaling spec, JR-1 to JR-18): a copy of each message the
|
||||||
|
//! server queues, with its envelope, kept where nothing in the product
|
||||||
|
//! changes or removes it before its retention ends.
|
||||||
|
//!
|
||||||
|
//! - this module: journals, what makes one valid, and where they're kept;
|
||||||
|
//! - [`report`]: the journal report around the untouched message (JR-3);
|
||||||
|
//! - [`entries`]: the built-in journal and its chain (JR-5, JR-6, JR-13).
|
||||||
|
//!
|
||||||
|
//! Kept in the fork's subspace (`store::SUBSPACE_INBUXA`). Every key starts
|
||||||
|
//! with `J`; journals are `j` + id (u32), as JSON. There are few, so they're
|
||||||
|
//! read whole.
|
||||||
|
|
||||||
|
pub mod archive;
|
||||||
|
pub mod entries;
|
||||||
|
pub mod report;
|
||||||
|
|
||||||
|
use crate::{hold::Member, mailflow::rules::jmap_ids};
|
||||||
|
use serde::{Deserialize as SerdeDeserialize, Serialize as SerdeSerialize, de::DeserializeOwned};
|
||||||
|
use std::{
|
||||||
|
sync::{Arc, RwLock},
|
||||||
|
time::{Duration, Instant},
|
||||||
|
};
|
||||||
|
use store::{
|
||||||
|
Deserialize, IterateParams, SUBSPACE_INBUXA, Serialize, Store, ValueKey,
|
||||||
|
write::{AnyClass, BatchBuilder, ValueClass, assert::AssertValue},
|
||||||
|
};
|
||||||
|
use trc::AddContext;
|
||||||
|
|
||||||
|
pub(crate) const FEATURE: u8 = b'J';
|
||||||
|
const KIND_JOURNAL: u8 = b'j';
|
||||||
|
const CREATE_ATTEMPTS: usize = 5;
|
||||||
|
|
||||||
|
/// Retention a journal may be given, in days (settled answer 3).
|
||||||
|
pub const MIN_RETENTION_DAYS: u32 = 30;
|
||||||
|
pub const MAX_RETENTION_DAYS: u32 = 3650;
|
||||||
|
/// Most entries in one scope list.
|
||||||
|
const MAX_LIST: usize = 5_000;
|
||||||
|
|
||||||
|
/// Which way a message goes, from this server's side (JR-9).
|
||||||
|
#[derive(Debug, Clone, Copy, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub enum Direction {
|
||||||
|
/// From someone here to at least one recipient elsewhere.
|
||||||
|
Outgoing,
|
||||||
|
/// From elsewhere to someone here.
|
||||||
|
Incoming,
|
||||||
|
/// From someone here, to people here only.
|
||||||
|
Internal,
|
||||||
|
Any,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Direction {
|
||||||
|
pub fn as_str(&self) -> &'static str {
|
||||||
|
match self {
|
||||||
|
Direction::Outgoing => "outgoing",
|
||||||
|
Direction::Incoming => "incoming",
|
||||||
|
Direction::Internal => "internal",
|
||||||
|
Direction::Any => "any",
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A message's direction: `Any` is never one.
|
||||||
|
pub fn of(sender_local: bool, any_remote: bool, any_local: bool) -> Direction {
|
||||||
|
match (sender_local, any_remote) {
|
||||||
|
(true, true) => Direction::Outgoing,
|
||||||
|
(true, false) => Direction::Internal,
|
||||||
|
(false, _) if any_local => Direction::Incoming,
|
||||||
|
// Nobody here on either side: relayed mail counts as outgoing
|
||||||
|
(false, _) => Direction::Outgoing,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn includes(&self, direction: Direction) -> bool {
|
||||||
|
*self == Direction::Any || *self == direction
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Whose mail a journal takes (JR-9): everyone, or people reached through
|
||||||
|
/// their account, domain, group or tenant. Ids are in the JMAP form.
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub struct Scope {
|
||||||
|
#[serde(default)]
|
||||||
|
pub everyone: bool,
|
||||||
|
#[serde(default, with = "jmap_ids")]
|
||||||
|
pub accounts: Vec<u32>,
|
||||||
|
#[serde(default, with = "jmap_ids")]
|
||||||
|
pub groups: Vec<u32>,
|
||||||
|
#[serde(default, with = "jmap_ids")]
|
||||||
|
pub domains: Vec<u32>,
|
||||||
|
#[serde(default, with = "jmap_ids")]
|
||||||
|
pub tenants: Vec<u32>,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Scope {
|
||||||
|
fn lists(&self) -> [&Vec<u32>; 4] {
|
||||||
|
[&self.accounts, &self.groups, &self.domains, &self.tenants]
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Whether this scope reaches one person here.
|
||||||
|
pub fn covers(&self, member: &Member) -> bool {
|
||||||
|
self.everyone
|
||||||
|
|| self.accounts.contains(&member.account)
|
||||||
|
|| member.domains.iter().any(|d| self.domains.contains(d))
|
||||||
|
|| member.groups.iter().any(|g| self.groups.contains(g))
|
||||||
|
|| member.tenant.is_some_and(|t| self.tenants.contains(&t))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A journal (JR-9): what it takes, and how long its entries are kept.
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub struct Journal {
|
||||||
|
#[serde(default)]
|
||||||
|
pub id: u32,
|
||||||
|
pub name: String,
|
||||||
|
#[serde(default)]
|
||||||
|
pub description: String,
|
||||||
|
#[serde(default)]
|
||||||
|
pub enabled: bool,
|
||||||
|
pub direction: Direction,
|
||||||
|
pub scope: Scope,
|
||||||
|
/// How long an entry this journal writes is kept. An entry keeps the
|
||||||
|
/// retention it was written with (JR-12).
|
||||||
|
pub retention_days: u32,
|
||||||
|
/// Whether entries go into the built-in journal (JR-5).
|
||||||
|
#[serde(default = "yes")]
|
||||||
|
pub built_in: bool,
|
||||||
|
/// An outside archive's journal address, sent each report (JR-7).
|
||||||
|
#[serde(default, skip_serializing_if = "Option::is_none")]
|
||||||
|
pub archive_address: Option<String>,
|
||||||
|
#[serde(default)]
|
||||||
|
pub created_by: String,
|
||||||
|
#[serde(default)]
|
||||||
|
pub created_at: u64,
|
||||||
|
#[serde(default)]
|
||||||
|
pub updated_at: u64,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Why a journal was refused: the property, and what to do.
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||||
|
pub struct Invalid {
|
||||||
|
pub property: &'static str,
|
||||||
|
pub reason: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
fn invalid(property: &'static str, reason: impl Into<String>) -> Result<(), Invalid> {
|
||||||
|
Err(Invalid {
|
||||||
|
property,
|
||||||
|
reason: reason.into(),
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Journal {
|
||||||
|
pub fn validate(&self) -> Result<(), Invalid> {
|
||||||
|
if self.name.trim().is_empty() {
|
||||||
|
return invalid("name", "Give the journal a name.");
|
||||||
|
}
|
||||||
|
if self.name.len() > 200 || self.description.len() > 2_000 {
|
||||||
|
return invalid("name", "The name or description is too long.");
|
||||||
|
}
|
||||||
|
if !(MIN_RETENTION_DAYS..=MAX_RETENTION_DAYS).contains(&self.retention_days) {
|
||||||
|
return invalid(
|
||||||
|
"retentionDays",
|
||||||
|
format!("Keep entries between {MIN_RETENTION_DAYS} and {MAX_RETENTION_DAYS} days."),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
// Neither is a journal only rules send mail to (JR-10)
|
||||||
|
let chosen = self.scope.lists().iter().any(|list| !list.is_empty());
|
||||||
|
if self.scope.everyone && chosen {
|
||||||
|
return invalid(
|
||||||
|
"scope",
|
||||||
|
"Journal everyone, or choose accounts, groups, domains or tenants; not both.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if !self.built_in && self.archive_address.is_none() {
|
||||||
|
return invalid(
|
||||||
|
"builtIn",
|
||||||
|
"Keep entries in the built-in journal, send them to an archive, or both.",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if let Some(address) = &self.archive_address
|
||||||
|
&& !is_address(address)
|
||||||
|
{
|
||||||
|
return invalid(
|
||||||
|
"archiveAddress",
|
||||||
|
format!("\"{address}\" isn't an email address."),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if self.scope.lists().iter().any(|list| list.len() > MAX_LIST) {
|
||||||
|
return invalid("scope", format!("Choose at most {MAX_LIST} of each."));
|
||||||
|
}
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Whether this journal takes a message going `direction` with these
|
||||||
|
/// people here on either side.
|
||||||
|
/// Whether only rules send this journal mail (JR-10).
|
||||||
|
pub fn rules_only(&self) -> bool {
|
||||||
|
!self.scope.everyone && self.scope.lists().iter().all(|list| list.is_empty())
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn takes(&self, direction: Direction, members: &[Member]) -> bool {
|
||||||
|
self.enabled
|
||||||
|
&& self.direction.includes(direction)
|
||||||
|
&& (self.scope.everyone || members.iter().any(|m| self.scope.covers(m)))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn yes() -> bool {
|
||||||
|
true
|
||||||
|
}
|
||||||
|
|
||||||
|
/// An address an archive can be sent to: one `@`, something either side,
|
||||||
|
/// nothing that would break an envelope.
|
||||||
|
fn is_address(address: &str) -> bool {
|
||||||
|
address.len() <= 320
|
||||||
|
&& address.split_once('@').is_some_and(|(local, domain)| {
|
||||||
|
!local.is_empty() && domain.contains('.') && !domain.contains('@')
|
||||||
|
})
|
||||||
|
&& !address
|
||||||
|
.chars()
|
||||||
|
.any(|c| c.is_whitespace() || c.is_control() || matches!(c, '<' | '>' | ',' | ';'))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A value stored as JSON.
|
||||||
|
pub(crate) struct Json<T>(pub T);
|
||||||
|
|
||||||
|
impl<T: SerdeSerialize> Serialize for Json<T> {
|
||||||
|
fn serialize(&self) -> trc::Result<Vec<u8>> {
|
||||||
|
serde_json::to_vec(&self.0).map_err(|err| {
|
||||||
|
trc::StoreEvent::UnexpectedError
|
||||||
|
.into_err()
|
||||||
|
.details("Failed to serialize a journal record")
|
||||||
|
.reason(err)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl<T: DeserializeOwned + Sync + Send> Deserialize for Json<T> {
|
||||||
|
fn deserialize(bytes: &[u8]) -> trc::Result<Self> {
|
||||||
|
serde_json::from_slice(bytes).map(Json).map_err(|err| {
|
||||||
|
trc::StoreEvent::DataCorruption
|
||||||
|
.into_err()
|
||||||
|
.details("Invalid journal record")
|
||||||
|
.reason(err)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn class(id: u32) -> ValueClass {
|
||||||
|
let mut key = Vec::with_capacity(6);
|
||||||
|
key.push(FEATURE);
|
||||||
|
key.push(KIND_JOURNAL);
|
||||||
|
key.extend_from_slice(&id.to_be_bytes());
|
||||||
|
ValueClass::Any(AnyClass {
|
||||||
|
subspace: SUBSPACE_INBUXA,
|
||||||
|
key,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
fn key(id: u32) -> ValueKey<ValueClass> {
|
||||||
|
ValueKey::from(class(id))
|
||||||
|
}
|
||||||
|
|
||||||
|
pub async fn get(data: &Store, id: u32) -> trc::Result<Option<Journal>> {
|
||||||
|
Ok(data
|
||||||
|
.get_value::<Json<Journal>>(key(id))
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?
|
||||||
|
.map(|Json(journal)| journal))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Every journal, oldest first.
|
||||||
|
pub async fn all(data: &Store) -> trc::Result<Vec<Journal>> {
|
||||||
|
let mut journals = Vec::new();
|
||||||
|
data.iterate(IterateParams::new(key(0), key(u32::MAX)), |_, value| {
|
||||||
|
if let Ok(Json(journal)) = Json::<Journal>::deserialize(value) {
|
||||||
|
journals.push(journal);
|
||||||
|
}
|
||||||
|
Ok(true)
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
journals.sort_by_key(|journal| journal.id);
|
||||||
|
Ok(journals)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Writes a new journal under the next free id, which it returns.
|
||||||
|
pub async fn create(data: &Store, journal: &Journal) -> trc::Result<u32> {
|
||||||
|
let mut attempt = 0;
|
||||||
|
loop {
|
||||||
|
attempt += 1;
|
||||||
|
let id = all(data).await?.iter().map(|j| j.id).max().unwrap_or(0) + 1;
|
||||||
|
let stored = Journal {
|
||||||
|
id,
|
||||||
|
..journal.clone()
|
||||||
|
};
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.assert_value(class(id), AssertValue::None);
|
||||||
|
batch.set(class(id), Json(&stored).serialize()?);
|
||||||
|
match data.write(batch.build_all()).await {
|
||||||
|
Ok(_) => {
|
||||||
|
invalidate();
|
||||||
|
return Ok(id);
|
||||||
|
}
|
||||||
|
Err(err)
|
||||||
|
if attempt < CREATE_ATTEMPTS
|
||||||
|
&& matches!(
|
||||||
|
err.as_ref(),
|
||||||
|
trc::EventType::Store(trc::StoreEvent::AssertValueFailed)
|
||||||
|
) => {}
|
||||||
|
Err(err) => return Err(err.caused_by(trc::location!())),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Replaces a stored journal (same id).
|
||||||
|
pub async fn update(data: &Store, journal: &Journal) -> trc::Result<()> {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.set(class(journal.id), Json(journal).serialize()?);
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
invalidate();
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Removes a journal. Its entries stay, each until its own time.
|
||||||
|
pub async fn delete(data: &Store, id: u32) -> trc::Result<()> {
|
||||||
|
let mut batch = BatchBuilder::new();
|
||||||
|
batch.clear(class(id));
|
||||||
|
data.write(batch.build_all())
|
||||||
|
.await
|
||||||
|
.caused_by(trc::location!())?;
|
||||||
|
invalidate();
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// How long a node keeps its copy of the journals before reading them again.
|
||||||
|
pub const TTL: Duration = Duration::from_secs(30);
|
||||||
|
|
||||||
|
type Cached = Option<(Instant, Arc<Vec<Journal>>)>;
|
||||||
|
static CACHE: RwLock<Cached> = RwLock::new(None);
|
||||||
|
|
||||||
|
/// Forgets this node's copy, so the next message reads the journals again.
|
||||||
|
pub fn invalidate() {
|
||||||
|
if let Ok(mut cache) = CACHE.write() {
|
||||||
|
*cache = None;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The enabled journals, from this node's copy (refreshed every [`TTL`]).
|
||||||
|
pub async fn enabled(data: &Store) -> trc::Result<Arc<Vec<Journal>>> {
|
||||||
|
if let Ok(cache) = CACHE.read()
|
||||||
|
&& let Some((at, journals)) = cache.as_ref()
|
||||||
|
&& at.elapsed() < TTL
|
||||||
|
{
|
||||||
|
return Ok(journals.clone());
|
||||||
|
}
|
||||||
|
let journals = Arc::new(
|
||||||
|
all(data)
|
||||||
|
.await?
|
||||||
|
.into_iter()
|
||||||
|
.filter(|journal| journal.enabled)
|
||||||
|
.collect::<Vec<_>>(),
|
||||||
|
);
|
||||||
|
if let Ok(mut cache) = CACHE.write() {
|
||||||
|
*cache = Some((Instant::now(), journals.clone()));
|
||||||
|
}
|
||||||
|
Ok(journals)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
fn journal(scope: Scope) -> Journal {
|
||||||
|
Journal {
|
||||||
|
id: 1,
|
||||||
|
name: "Finance".into(),
|
||||||
|
description: String::new(),
|
||||||
|
enabled: true,
|
||||||
|
direction: Direction::Any,
|
||||||
|
scope,
|
||||||
|
retention_days: 365,
|
||||||
|
built_in: true,
|
||||||
|
archive_address: None,
|
||||||
|
created_by: String::new(),
|
||||||
|
created_at: 0,
|
||||||
|
updated_at: 0,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn member(account: u32, groups: Vec<u32>) -> Member {
|
||||||
|
Member {
|
||||||
|
account,
|
||||||
|
domains: vec![1],
|
||||||
|
groups,
|
||||||
|
tenant: None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn scope_is_everyone_or_chosen() {
|
||||||
|
assert!(
|
||||||
|
journal(Scope {
|
||||||
|
everyone: true,
|
||||||
|
..Default::default()
|
||||||
|
})
|
||||||
|
.validate()
|
||||||
|
.is_ok()
|
||||||
|
);
|
||||||
|
// Nobody chosen: only rules send it mail
|
||||||
|
let rules_only = journal(Scope::default());
|
||||||
|
assert!(rules_only.validate().is_ok());
|
||||||
|
assert!(rules_only.rules_only());
|
||||||
|
assert!(!rules_only.takes(Direction::Any, &[member(3, vec![7])]));
|
||||||
|
let both = Scope {
|
||||||
|
everyone: true,
|
||||||
|
groups: vec![4],
|
||||||
|
..Default::default()
|
||||||
|
};
|
||||||
|
assert_eq!(journal(both).validate().unwrap_err().property, "scope");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn destinations() {
|
||||||
|
let mut j = journal(Scope {
|
||||||
|
everyone: true,
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
j.built_in = false;
|
||||||
|
assert_eq!(j.validate().unwrap_err().property, "builtIn");
|
||||||
|
j.archive_address = Some("[email protected]".into());
|
||||||
|
assert!(j.validate().is_ok());
|
||||||
|
for bad in [
|
||||||
|
"archive",
|
||||||
|
"a@b",
|
||||||
|
"a [email protected]",
|
||||||
|
"<[email protected]>",
|
||||||
|
"a@[email protected]",
|
||||||
|
] {
|
||||||
|
j.archive_address = Some(bad.into());
|
||||||
|
assert_eq!(
|
||||||
|
j.validate().unwrap_err().property,
|
||||||
|
"archiveAddress",
|
||||||
|
"{bad}"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
// Stored before destinations existed: the built-in journal
|
||||||
|
let old: Journal = serde_json::from_str(
|
||||||
|
r#"{"name":"Old","direction":"any","scope":{"everyone":true},"retentionDays":30}"#,
|
||||||
|
)
|
||||||
|
.unwrap();
|
||||||
|
assert!(old.built_in && old.archive_address.is_none());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn retention_has_bounds() {
|
||||||
|
let mut j = journal(Scope {
|
||||||
|
everyone: true,
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
j.retention_days = 29;
|
||||||
|
assert_eq!(j.validate().unwrap_err().property, "retentionDays");
|
||||||
|
j.retention_days = 3651;
|
||||||
|
assert!(j.validate().is_err());
|
||||||
|
j.retention_days = 3650;
|
||||||
|
assert!(j.validate().is_ok());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn takes_by_direction_and_member() {
|
||||||
|
let mut j = journal(Scope {
|
||||||
|
groups: vec![7],
|
||||||
|
..Default::default()
|
||||||
|
});
|
||||||
|
assert!(j.takes(Direction::Outgoing, &[member(3, vec![7])]));
|
||||||
|
assert!(!j.takes(Direction::Outgoing, &[member(3, vec![8])]));
|
||||||
|
assert!(!j.takes(Direction::Outgoing, &[]));
|
||||||
|
j.direction = Direction::Incoming;
|
||||||
|
assert!(!j.takes(Direction::Outgoing, &[member(3, vec![7])]));
|
||||||
|
j.enabled = false;
|
||||||
|
assert!(!j.takes(Direction::Incoming, &[member(3, vec![7])]));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn directions() {
|
||||||
|
assert_eq!(Direction::of(true, true, true), Direction::Outgoing);
|
||||||
|
assert_eq!(Direction::of(true, false, true), Direction::Internal);
|
||||||
|
assert_eq!(Direction::of(false, false, true), Direction::Incoming);
|
||||||
|
assert_eq!(Direction::of(false, true, true), Direction::Incoming);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn scope_ids_are_jmap_ids() {
|
||||||
|
let scope: Scope = serde_json::from_str(r#"{"groups":["b"],"tenants":[7]}"#).unwrap();
|
||||||
|
assert_eq!(scope.groups, vec![1]);
|
||||||
|
assert_eq!(scope.tenants, vec![7]);
|
||||||
|
assert_eq!(
|
||||||
|
serde_json::to_value(&scope).unwrap()["tenants"],
|
||||||
|
serde_json::json!(["h"])
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,385 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! The journal report (JR-3, JR-4): a message whose first part lists the
|
||||||
|
//! envelope, one field a line, and whose second part is the message as it
|
||||||
|
//! was queued, byte for byte, as `message/rfc822`. Field names are fixed
|
||||||
|
//! English: a report is a record, and scripts read it.
|
||||||
|
|
||||||
|
use super::Direction;
|
||||||
|
use mail_builder::headers::{Header, date::Date, text::Text};
|
||||||
|
use mail_parser::MessageParser;
|
||||||
|
use sha2::{Digest, Sha256};
|
||||||
|
|
||||||
|
/// One envelope recipient, with the address it was given as (a list's, for
|
||||||
|
/// the list's members).
|
||||||
|
#[derive(Debug, Clone, PartialEq, Eq)]
|
||||||
|
pub struct Recipient {
|
||||||
|
pub address: String,
|
||||||
|
pub orcpt: Option<String>,
|
||||||
|
/// The mail flow rule that added or redirected to it.
|
||||||
|
pub added_by: Option<String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// What the queue knows about a message.
|
||||||
|
#[derive(Debug, Clone)]
|
||||||
|
pub struct Envelope<'x> {
|
||||||
|
pub sender: &'x str,
|
||||||
|
pub authenticated: bool,
|
||||||
|
pub recipients: &'x [Recipient],
|
||||||
|
pub queue_id: u64,
|
||||||
|
/// Seconds.
|
||||||
|
pub received: u64,
|
||||||
|
pub direction: Direction,
|
||||||
|
pub held: bool,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// What a report says, besides the envelope's own fields.
|
||||||
|
#[derive(Debug, Clone, Default, PartialEq, Eq)]
|
||||||
|
pub struct Fields {
|
||||||
|
pub subject: String,
|
||||||
|
pub message_id: String,
|
||||||
|
pub to: Vec<String>,
|
||||||
|
pub cc: Vec<String>,
|
||||||
|
/// Envelope recipients in neither To nor Cc, nor reached through a list.
|
||||||
|
pub bcc: Vec<String>,
|
||||||
|
/// A list's address, and its members among the recipients.
|
||||||
|
pub expanded: Vec<(String, Vec<String>)>,
|
||||||
|
/// A rule's name, and the recipients it added.
|
||||||
|
pub added: Vec<(String, Vec<String>)>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// One line's worth of a value: no line breaks, no control characters.
|
||||||
|
fn line(value: &str) -> String {
|
||||||
|
value
|
||||||
|
.chars()
|
||||||
|
.map(|c| if c.is_control() { ' ' } else { c })
|
||||||
|
.collect::<String>()
|
||||||
|
.trim()
|
||||||
|
.to_string()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The address an ORCPT names, without its `rfc822;` type.
|
||||||
|
fn orcpt_address(orcpt: &str) -> String {
|
||||||
|
let orcpt = orcpt.trim();
|
||||||
|
let bare = match orcpt.split_once(';') {
|
||||||
|
Some((kind, address)) if kind.eq_ignore_ascii_case("rfc822") => address,
|
||||||
|
_ => orcpt,
|
||||||
|
};
|
||||||
|
bare.trim().to_lowercase()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Sorts the envelope's recipients by how they were addressed.
|
||||||
|
pub fn fields(envelope: &Envelope<'_>, original: &[u8]) -> Fields {
|
||||||
|
let parsed = MessageParser::default().parse_headers(original);
|
||||||
|
let headed = |which: Option<&mail_parser::Address<'_>>| -> Vec<String> {
|
||||||
|
which
|
||||||
|
.map(|list| {
|
||||||
|
list.iter()
|
||||||
|
.filter_map(|addr| addr.address())
|
||||||
|
.map(|address| address.to_lowercase())
|
||||||
|
.collect()
|
||||||
|
})
|
||||||
|
.unwrap_or_default()
|
||||||
|
};
|
||||||
|
let (subject, message_id, header_to, header_cc) = match &parsed {
|
||||||
|
Some(message) => (
|
||||||
|
message.subject().map(line).unwrap_or_default(),
|
||||||
|
message
|
||||||
|
.message_id()
|
||||||
|
.map(|id| format!("<{}>", line(id)))
|
||||||
|
.unwrap_or_default(),
|
||||||
|
headed(message.to()),
|
||||||
|
headed(message.cc()),
|
||||||
|
),
|
||||||
|
None => Default::default(),
|
||||||
|
};
|
||||||
|
|
||||||
|
let mut fields = Fields {
|
||||||
|
subject,
|
||||||
|
message_id,
|
||||||
|
..Default::default()
|
||||||
|
};
|
||||||
|
for rcpt in envelope.recipients {
|
||||||
|
let address = rcpt.address.to_lowercase();
|
||||||
|
let via = rcpt
|
||||||
|
.orcpt
|
||||||
|
.as_deref()
|
||||||
|
.map(orcpt_address)
|
||||||
|
.filter(|via| !via.is_empty() && *via != address);
|
||||||
|
if let Some(rule) = &rcpt.added_by {
|
||||||
|
match fields.added.iter_mut().find(|(name, _)| name == rule) {
|
||||||
|
Some((_, added)) => added.push(line(&rcpt.address)),
|
||||||
|
None => fields.added.push((line(rule), vec![line(&rcpt.address)])),
|
||||||
|
}
|
||||||
|
} else if header_to.contains(&address) {
|
||||||
|
fields.to.push(line(&rcpt.address));
|
||||||
|
} else if header_cc.contains(&address) {
|
||||||
|
fields.cc.push(line(&rcpt.address));
|
||||||
|
} else if let Some(via) = via {
|
||||||
|
match fields.expanded.iter_mut().find(|(list, _)| *list == via) {
|
||||||
|
Some((_, members)) => members.push(line(&rcpt.address)),
|
||||||
|
None => fields
|
||||||
|
.expanded
|
||||||
|
.push((line(&via), vec![line(&rcpt.address)])),
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
fields.bcc.push(line(&rcpt.address));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
fields
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The report's first part.
|
||||||
|
pub fn text(envelope: &Envelope<'_>, fields: &Fields) -> String {
|
||||||
|
let mut out = String::new();
|
||||||
|
let mut field = |name: &str, value: &str| {
|
||||||
|
if !value.is_empty() {
|
||||||
|
out.push_str(name);
|
||||||
|
out.push_str(": ");
|
||||||
|
out.push_str(value);
|
||||||
|
out.push_str("\r\n");
|
||||||
|
}
|
||||||
|
};
|
||||||
|
let sender = if envelope.sender.is_empty() {
|
||||||
|
"<>".to_string()
|
||||||
|
} else {
|
||||||
|
line(envelope.sender)
|
||||||
|
};
|
||||||
|
field("Sender", &sender);
|
||||||
|
field(
|
||||||
|
"Authenticated",
|
||||||
|
if envelope.authenticated { "yes" } else { "no" },
|
||||||
|
);
|
||||||
|
field("Subject", &fields.subject);
|
||||||
|
field("Message-ID", &fields.message_id);
|
||||||
|
field("Queue ID", &format!("{:x}", envelope.queue_id));
|
||||||
|
field(
|
||||||
|
"Received",
|
||||||
|
&mail_parser::DateTime::from_timestamp(envelope.received as i64).to_rfc3339(),
|
||||||
|
);
|
||||||
|
field("Direction", envelope.direction.as_str());
|
||||||
|
field("To", &fields.to.join(", "));
|
||||||
|
field("Cc", &fields.cc.join(", "));
|
||||||
|
field("Bcc", &fields.bcc.join(", "));
|
||||||
|
for (list, members) in &fields.expanded {
|
||||||
|
field("Expanded", &format!("{list} -> {}", members.join(", ")));
|
||||||
|
}
|
||||||
|
for (rule, added) in &fields.added {
|
||||||
|
field("Added by rule", &format!("{rule} -> {}", added.join(", ")));
|
||||||
|
}
|
||||||
|
if envelope.held {
|
||||||
|
field("Held for review", "yes");
|
||||||
|
}
|
||||||
|
out
|
||||||
|
}
|
||||||
|
|
||||||
|
fn hex(bytes: &[u8]) -> String {
|
||||||
|
bytes.iter().map(|b| format!("{b:02x}")).collect()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Whether a message can travel as 8bit: no NULs, no line past 998 bytes.
|
||||||
|
fn fits_8bit(message: &[u8]) -> bool {
|
||||||
|
!message.contains(&0) && message.split(|b| *b == b'\n').all(|l| l.len() <= 998)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The whole report: headers, the fields, then the original untouched.
|
||||||
|
/// `from` is the address the report is from; `host` names the server in its
|
||||||
|
/// Message-ID.
|
||||||
|
pub fn build(
|
||||||
|
envelope: &Envelope<'_>,
|
||||||
|
original: &[u8],
|
||||||
|
from: &str,
|
||||||
|
host: &str,
|
||||||
|
) -> (Vec<u8>, Fields) {
|
||||||
|
let fields = fields(envelope, original);
|
||||||
|
let body = text(envelope, &fields);
|
||||||
|
// A boundary that can't occur in the original
|
||||||
|
let mut boundary = format!("journal-{}", &hex(&Sha256::digest(original))[..32]);
|
||||||
|
while original
|
||||||
|
.windows(boundary.len())
|
||||||
|
.any(|window| window == boundary.as_bytes())
|
||||||
|
{
|
||||||
|
boundary.push('x');
|
||||||
|
}
|
||||||
|
|
||||||
|
let mut out: Vec<u8> = Vec::with_capacity(original.len() + body.len() + 1024);
|
||||||
|
out.extend_from_slice(format!("From: Journal <{}>\r\n", line(from)).as_bytes());
|
||||||
|
out.extend_from_slice(b"Date: ");
|
||||||
|
out.extend_from_slice(Date::new(envelope.received as i64).to_rfc822().as_bytes());
|
||||||
|
out.extend_from_slice(b"\r\n");
|
||||||
|
out.extend_from_slice(b"Subject: ");
|
||||||
|
let subject = if fields.subject.is_empty() {
|
||||||
|
"Journal report".to_string()
|
||||||
|
} else {
|
||||||
|
format!("Journal report: {}", fields.subject)
|
||||||
|
};
|
||||||
|
Text::new(subject).write_header(&mut out, "Subject: ".len());
|
||||||
|
out.extend_from_slice(
|
||||||
|
format!(
|
||||||
|
"Message-ID: <journal.{:x}.{}@{}>\r\n",
|
||||||
|
envelope.queue_id,
|
||||||
|
envelope.received,
|
||||||
|
line(host)
|
||||||
|
)
|
||||||
|
.as_bytes(),
|
||||||
|
);
|
||||||
|
out.extend_from_slice(format!("X-Inbuxa-Journal: {:x}\r\n", envelope.queue_id).as_bytes());
|
||||||
|
out.extend_from_slice(b"MIME-Version: 1.0\r\n");
|
||||||
|
out.extend_from_slice(
|
||||||
|
format!("Content-Type: multipart/mixed; boundary=\"{boundary}\"\r\n\r\n").as_bytes(),
|
||||||
|
);
|
||||||
|
out.extend_from_slice(format!("--{boundary}\r\n").as_bytes());
|
||||||
|
out.extend_from_slice(
|
||||||
|
b"Content-Type: text/plain; charset=utf-8\r\nContent-Transfer-Encoding: 8bit\r\n\r\n",
|
||||||
|
);
|
||||||
|
out.extend_from_slice(body.as_bytes());
|
||||||
|
out.extend_from_slice(format!("\r\n--{boundary}\r\n").as_bytes());
|
||||||
|
out.extend_from_slice(b"Content-Type: message/rfc822\r\n");
|
||||||
|
out.extend_from_slice(b"Content-Disposition: attachment; filename=\"original.eml\"\r\n");
|
||||||
|
out.extend_from_slice(if fits_8bit(original) {
|
||||||
|
b"Content-Transfer-Encoding: 8bit\r\n\r\n".as_slice()
|
||||||
|
} else {
|
||||||
|
b"Content-Transfer-Encoding: binary\r\n\r\n".as_slice()
|
||||||
|
});
|
||||||
|
out.extend_from_slice(original);
|
||||||
|
// The line break before a boundary belongs to the boundary: the
|
||||||
|
// original keeps its own last one
|
||||||
|
out.extend_from_slice(format!("\r\n--{boundary}--\r\n").as_bytes());
|
||||||
|
(out, fields)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Where the original starts and ends inside a report [`build`] made.
|
||||||
|
pub fn original(report: &[u8]) -> Option<&[u8]> {
|
||||||
|
let parsed = MessageParser::default().parse(report)?;
|
||||||
|
let part = parsed.attachment(0)?;
|
||||||
|
let start = part.raw_body_offset() as usize;
|
||||||
|
let end = part.raw_end_offset() as usize;
|
||||||
|
report.get(start..end)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
const ORIGINAL: &[u8] = b"From: [email protected]\r\n\
|
||||||
|
To: Bank <pay@bank.example>\r\n\
|
||||||
|
Cc: bob@example.com\r\n\
|
||||||
|
Subject: Q3 figures\r\n\
|
||||||
|
Message-ID: <abc@example.com>\r\n\
|
||||||
|
\r\n\
|
||||||
|
The figures.\r\n";
|
||||||
|
|
||||||
|
fn rcpt(address: &str, orcpt: Option<&str>) -> Recipient {
|
||||||
|
Recipient {
|
||||||
|
address: address.into(),
|
||||||
|
orcpt: orcpt.map(Into::into),
|
||||||
|
added_by: None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn envelope(recipients: &[Recipient]) -> Envelope<'_> {
|
||||||
|
Envelope {
|
||||||
|
sender: "[email protected]",
|
||||||
|
authenticated: true,
|
||||||
|
recipients,
|
||||||
|
queue_id: 0x1a2b,
|
||||||
|
received: 1_790_000_000,
|
||||||
|
direction: Direction::Outgoing,
|
||||||
|
held: false,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn recipients_sorted_by_how_they_were_addressed() {
|
||||||
|
let recipients = [
|
||||||
|
rcpt("[email protected]", None),
|
||||||
|
rcpt("[email protected]", Some("rfc822;[email protected]")),
|
||||||
|
rcpt("[email protected]", None),
|
||||||
|
rcpt("[email protected]", Some("[email protected]")),
|
||||||
|
rcpt("[email protected]", Some("rfc822;[email protected]")),
|
||||||
|
];
|
||||||
|
let fields = fields(&envelope(&recipients), ORIGINAL);
|
||||||
|
assert_eq!(fields.subject, "Q3 figures");
|
||||||
|
assert_eq!(fields.message_id, "<[email protected]>");
|
||||||
|
assert_eq!(fields.to, vec!["[email protected]"]);
|
||||||
|
assert_eq!(fields.cc, vec!["[email protected]"]);
|
||||||
|
assert_eq!(fields.bcc, vec!["[email protected]"]);
|
||||||
|
assert_eq!(
|
||||||
|
fields.expanded,
|
||||||
|
vec![(
|
||||||
|
"[email protected]".to_string(),
|
||||||
|
vec![
|
||||||
|
"[email protected]".to_string(),
|
||||||
|
"[email protected]".to_string()
|
||||||
|
]
|
||||||
|
)]
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn report_carries_the_original_untouched() {
|
||||||
|
let recipients = [
|
||||||
|
rcpt("[email protected]", None),
|
||||||
|
rcpt("[email protected]", None),
|
||||||
|
];
|
||||||
|
let (report, _) = build(
|
||||||
|
&envelope(&recipients),
|
||||||
|
ORIGINAL,
|
||||||
|
"[email protected]",
|
||||||
|
"mx.example.com",
|
||||||
|
);
|
||||||
|
let text = String::from_utf8_lossy(&report);
|
||||||
|
assert!(text.contains("Sender: [email protected]\r\n"));
|
||||||
|
assert!(text.contains("Bcc: [email protected]\r\n"));
|
||||||
|
assert!(text.contains("Queue ID: 1a2b\r\n"));
|
||||||
|
assert!(text.contains("Direction: outgoing\r\n"));
|
||||||
|
assert!(text.contains("Subject: Journal report: Q3 figures\r\n"));
|
||||||
|
assert!(!text.contains("Held for review"));
|
||||||
|
assert_eq!(original(&report), Some(ORIGINAL));
|
||||||
|
let unterminated = &ORIGINAL[..ORIGINAL.len() - 2];
|
||||||
|
let (report, _) = build(
|
||||||
|
&envelope(&recipients),
|
||||||
|
unterminated,
|
||||||
|
"[email protected]",
|
||||||
|
"mx.example.com",
|
||||||
|
);
|
||||||
|
assert_eq!(original(&report), Some(unterminated));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn rule_added_recipients_say_so() {
|
||||||
|
let mut copied = rcpt("[email protected]", None);
|
||||||
|
copied.added_by = Some("Copy finance".into());
|
||||||
|
let recipients = [rcpt("[email protected]", None), copied];
|
||||||
|
let env = envelope(&recipients);
|
||||||
|
let fields = fields(&env, ORIGINAL);
|
||||||
|
assert!(fields.bcc.is_empty(), "{fields:?}");
|
||||||
|
assert!(
|
||||||
|
text(&env, &fields).contains("Added by rule: Copy finance -> [email protected]\r\n")
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn values_stay_on_one_line() {
|
||||||
|
let recipients = [rcpt("[email protected]", None)];
|
||||||
|
let mut env = envelope(&recipients);
|
||||||
|
env.sender = "[email protected]\r\nBcc: [email protected]";
|
||||||
|
env.held = true;
|
||||||
|
let body = text(&env, &Fields::default());
|
||||||
|
assert_eq!(body.matches("\r\n").count(), body.lines().count());
|
||||||
|
assert!(body.contains("Sender: [email protected] Bcc: [email protected]\r\n"));
|
||||||
|
assert!(body.contains("Held for review: yes\r\n"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn an_empty_sender_is_shown_as_such() {
|
||||||
|
let recipients = [rcpt("[email protected]", None)];
|
||||||
|
let mut env = envelope(&recipients);
|
||||||
|
env.sender = "";
|
||||||
|
assert!(text(&env, &Fields::default()).starts_with("Sender: <>\r\n"));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
@@ -21,8 +21,13 @@
|
|||||||
pub mod ai;
|
pub mod ai;
|
||||||
pub mod audit;
|
pub mod audit;
|
||||||
pub mod branding;
|
pub mod branding;
|
||||||
|
pub mod deliverability; // inbuxa: the deliverability check (not a rebuild)
|
||||||
|
pub mod hold;
|
||||||
|
pub mod journal;
|
||||||
pub mod lock;
|
pub mod lock;
|
||||||
|
pub mod mailflow;
|
||||||
pub mod masked_email;
|
pub mod masked_email;
|
||||||
|
pub mod privacy;
|
||||||
pub mod security;
|
pub mod security;
|
||||||
pub mod tenancy;
|
pub mod tenancy;
|
||||||
pub mod undelete;
|
pub mod undelete;
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2026 Coffey Labs
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: AGPL-3.0-only
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
*/
|
*/
|
||||||
@@ -27,6 +27,11 @@ use store::{
|
|||||||
write::{AnyClass, BatchBuilder, ValueClass},
|
write::{AnyClass, BatchBuilder, ValueClass},
|
||||||
};
|
};
|
||||||
use trc::AddContext;
|
use trc::AddContext;
|
||||||
|
use types::{
|
||||||
|
acl::{Acl, AclGrant},
|
||||||
|
collection::Collection,
|
||||||
|
};
|
||||||
|
use utils::map::bitmap::Bitmap;
|
||||||
|
|
||||||
/// Rung when a lock is written, so this node's expiry timer re-reads the
|
/// Rung when a lock is written, so this node's expiry timer re-reads the
|
||||||
/// `until` dates (AL-5): a delegation ends at its time, not at a sweep.
|
/// `until` dates (AL-5): a delegation ends at its time, not at a sweep.
|
||||||
@@ -53,11 +58,6 @@ pub fn ended_between(locks: &[Lock], after: u64, now: u64) -> impl Iterator<Item
|
|||||||
})
|
})
|
||||||
.map(|lock| lock.account_id)
|
.map(|lock| lock.account_id)
|
||||||
}
|
}
|
||||||
use types::{
|
|
||||||
acl::{Acl, AclGrant},
|
|
||||||
collection::Collection,
|
|
||||||
};
|
|
||||||
use utils::map::bitmap::Bitmap;
|
|
||||||
|
|
||||||
const FEATURE: u8 = b'K';
|
const FEATURE: u8 = b'K';
|
||||||
const KIND_LOCK: u8 = b'l';
|
const KIND_LOCK: u8 = b'l';
|
||||||
@@ -66,6 +66,53 @@ const KIND_DELEGATE: u8 = b'd';
|
|||||||
/// Most delegates one lock may have (AL-5).
|
/// Most delegates one lock may have (AL-5).
|
||||||
pub const MAX_DELEGATES: usize = 10;
|
pub const MAX_DELEGATES: usize = 10;
|
||||||
|
|
||||||
|
/// Most people one shared mailbox may have (MA-S): a help desk is bigger
|
||||||
|
/// than the handful a departed colleague's mail is handed to.
|
||||||
|
pub const MAX_SHARED_MAILBOX_DELEGATES: usize = 100;
|
||||||
|
|
||||||
|
/// What a lock is for (multi-account spec, MA-S).
|
||||||
|
///
|
||||||
|
/// Both kinds keep receiving mail, can't be signed in to, and are opened by
|
||||||
|
/// delegates through real grants. A shared mailbox is a role address such
|
||||||
|
/// as support@: it needs no reason, holds more people, runs its own Sieve
|
||||||
|
/// replies (an automatic acknowledgement), records only what is sent as it,
|
||||||
|
/// and may only send as its own addresses.
|
||||||
|
#[derive(Debug, Clone, Copy, Default, PartialEq, Eq, Hash, SerdeSerialize, SerdeDeserialize)]
|
||||||
|
#[serde(rename_all = "camelCase")]
|
||||||
|
pub enum Kind {
|
||||||
|
#[default]
|
||||||
|
Lock,
|
||||||
|
SharedMailbox,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Kind {
|
||||||
|
pub fn as_str(&self) -> &'static str {
|
||||||
|
match self {
|
||||||
|
Kind::Lock => "lock",
|
||||||
|
Kind::SharedMailbox => "sharedMailbox",
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn parse(value: &str) -> Option<Self> {
|
||||||
|
match value {
|
||||||
|
"lock" => Some(Kind::Lock),
|
||||||
|
"sharedMailbox" => Some(Kind::SharedMailbox),
|
||||||
|
_ => None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn is_lock(&self) -> bool {
|
||||||
|
matches!(self, Kind::Lock)
|
||||||
|
}
|
||||||
|
|
||||||
|
pub fn max_delegates(&self) -> usize {
|
||||||
|
match self {
|
||||||
|
Kind::Lock => MAX_DELEGATES,
|
||||||
|
Kind::SharedMailbox => MAX_SHARED_MAILBOX_DELEGATES,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/// What a delegate may do in the locked account (AL-6).
|
/// What a delegate may do in the locked account (AL-6).
|
||||||
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, SerdeSerialize, SerdeDeserialize)]
|
#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, SerdeSerialize, SerdeDeserialize)]
|
||||||
#[serde(rename_all = "camelCase")]
|
#[serde(rename_all = "camelCase")]
|
||||||
@@ -189,6 +236,9 @@ pub struct Replaced {
|
|||||||
#[serde(rename_all = "camelCase")]
|
#[serde(rename_all = "camelCase")]
|
||||||
pub struct Lock {
|
pub struct Lock {
|
||||||
pub account_id: u32,
|
pub account_id: u32,
|
||||||
|
/// Absent on locks written before shared mailboxes existed: a lock.
|
||||||
|
#[serde(default, skip_serializing_if = "Kind::is_lock")]
|
||||||
|
pub kind: Kind,
|
||||||
pub reason: String,
|
pub reason: String,
|
||||||
/// Seconds since the epoch.
|
/// Seconds since the epoch.
|
||||||
pub locked_at: u64,
|
pub locked_at: u64,
|
||||||
@@ -401,8 +451,9 @@ pub async fn all(data: &Store) -> trc::Result<Vec<Lock>> {
|
|||||||
Ok(locks)
|
Ok(locks)
|
||||||
}
|
}
|
||||||
|
|
||||||
/// The accounts delegated to `delegate`, with its delegation in each.
|
/// The accounts delegated to `delegate`, with its delegation in each and
|
||||||
pub async fn delegated_to(data: &Store, delegate: u32) -> trc::Result<Vec<(u32, Delegate)>> {
|
/// the kind of lock it is in.
|
||||||
|
pub async fn delegated_to(data: &Store, delegate: u32) -> trc::Result<Vec<(u32, Delegate, Kind)>> {
|
||||||
let mut locked = Vec::new();
|
let mut locked = Vec::new();
|
||||||
data.iterate(
|
data.iterate(
|
||||||
IterateParams::new(
|
IterateParams::new(
|
||||||
@@ -425,7 +476,7 @@ pub async fn delegated_to(data: &Store, delegate: u32) -> trc::Result<Vec<(u32,
|
|||||||
if let Some(lock) = get(data, account_id).await?
|
if let Some(lock) = get(data, account_id).await?
|
||||||
&& let Some(delegation) = lock.delegate(delegate)
|
&& let Some(delegation) = lock.delegate(delegate)
|
||||||
{
|
{
|
||||||
delegations.push((account_id, delegation.clone()));
|
delegations.push((account_id, delegation.clone(), lock.kind));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Ok(delegations)
|
Ok(delegations)
|
||||||
@@ -472,6 +523,22 @@ pub async fn remove(data: &Store, lock: &Lock) -> trc::Result<()> {
|
|||||||
mod tests {
|
mod tests {
|
||||||
use super::*;
|
use super::*;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn kind_reads_back_and_defaults_to_lock() {
|
||||||
|
// MA-S: a lock stored before shared mailboxes existed has no kind
|
||||||
|
let stored = r#"{"accountId":1,"reason":"r","lockedAt":0,"lockedBy":"admin","delegates":[]}"#;
|
||||||
|
let lock: Lock = serde_json::from_str(stored).unwrap();
|
||||||
|
assert_eq!(lock.kind, Kind::Lock);
|
||||||
|
assert!(!serde_json::to_string(&lock).unwrap().contains("kind"), "a lock is written as before");
|
||||||
|
|
||||||
|
let shared = Lock { kind: Kind::SharedMailbox, ..lock };
|
||||||
|
let written = serde_json::to_string(&shared).unwrap();
|
||||||
|
assert!(written.contains(r#""kind":"sharedMailbox""#), "{written}");
|
||||||
|
assert_eq!(serde_json::from_str::<Lock>(&written).unwrap().kind, Kind::SharedMailbox);
|
||||||
|
assert_eq!(Kind::parse("sharedMailbox"), Some(Kind::SharedMailbox));
|
||||||
|
assert_eq!(Kind::SharedMailbox.max_delegates(), MAX_SHARED_MAILBOX_DELEGATES);
|
||||||
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn keys_read_back() {
|
fn keys_read_back() {
|
||||||
let ValueClass::Any(any) = class(KIND_DELEGATE, &[7, 9]) else {
|
let ValueClass::Any(any) = class(KIND_DELEGATE, &[7, 9]) else {
|
||||||
@@ -509,6 +576,7 @@ mod tests {
|
|||||||
fn lock_with(delegates: Vec<Delegate>, replaced: Vec<Replaced>) -> Lock {
|
fn lock_with(delegates: Vec<Delegate>, replaced: Vec<Replaced>) -> Lock {
|
||||||
Lock {
|
Lock {
|
||||||
account_id: 1,
|
account_id: 1,
|
||||||
|
kind: Kind::Lock,
|
||||||
reason: "r".into(),
|
reason: "r".into(),
|
||||||
locked_at: 0,
|
locked_at: 0,
|
||||||
locked_by: "admin".into(),
|
locked_by: "admin".into(),
|
||||||
@@ -623,6 +691,7 @@ mod tests {
|
|||||||
fn expired_delegations_grant_nothing() {
|
fn expired_delegations_grant_nothing() {
|
||||||
let lock = Lock {
|
let lock = Lock {
|
||||||
account_id: 1,
|
account_id: 1,
|
||||||
|
kind: Kind::Lock,
|
||||||
reason: "Left the company".into(),
|
reason: "Left the company".into(),
|
||||||
locked_at: 100,
|
locked_at: 100,
|
||||||
locked_by: "admin".into(),
|
locked_by: "admin".into(),
|
||||||
|
|||||||
@@ -0,0 +1,53 @@
|
|||||||
|
/*
|
||||||
|
* SPDX-FileCopyrightText: 2026 Coffey Labs LLC
|
||||||
|
*
|
||||||
|
* SPDX-License-Identifier: AGPL-3.0-only
|
||||||
|
*/
|
||||||
|
|
||||||
|
//! The compiled rules, kept per node so a message doesn't read the store.
|
||||||
|
//! A change made on this node applies at once; one made on another node
|
||||||
|
//! within [`TTL`], when the copy here is next refreshed.
|
||||||
|
|
||||||
|
use super::{engine::Compiled, rules};
|
||||||
|
use std::{
|
||||||
|
sync::{Arc, RwLock},
|
||||||
|
time::{Duration, Instant},
|
||||||
|
};
|
||||||
|
use store::Store;
|
||||||
|
|
||||||
|
/// How long a node keeps its copy before reading the rules again.
|
||||||
|
pub const TTL: Duration = Duration::from_secs(30);
|
||||||
|
|
||||||
|
static CACHE: RwLock<Option<(Instant, Arc<Compiled>)>> = RwLock::new(None);
|
||||||
|
|
||||||
|
/// Forgets the copy, so the next message reads the rules again.
|
||||||
|
pub fn invalidate() {
|
||||||
|
if let Ok(mut cache) = CACHE.write() {
|
||||||
|
*cache = None;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The enabled rules, compiled. A rule that no longer compiles is left out
|
||||||
|
/// and reported, once per refresh.
|
||||||
|
pub async fn compiled(data: &Store) -> trc::Result<Arc<Compiled>> {
|
||||||
|
if let Ok(cache) = CACHE.read()
|
||||||
|
&& let Some((at, compiled)) = cache.as_ref()
|
||||||
|
&& at.elapsed() < TTL
|
||||||
|
{
|
||||||
|
return Ok(compiled.clone());
|
||||||
|
}
|
||||||
|
let (compiled, skipped) = Compiled::new(&rules::all(data).await?);
|
||||||
|
for (id, reason) in skipped {
|
||||||
|
trc::event!(
|
||||||
|
Store(trc::StoreEvent::DataCorruption),
|
||||||
|
Id = u64::from(id),
|
||||||
|
Reason = reason,
|
||||||
|
Details = "Mail rule skipped: it no longer compiles"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
let compiled = Arc::new(compiled);
|
||||||
|
if let Ok(mut cache) = CACHE.write() {
|
||||||
|
*cache = Some((Instant::now(), compiled.clone()));
|
||||||
|
}
|
||||||
|
Ok(compiled)
|
||||||
|
}
|
||||||
Loaded 100 of 468 files, more files were not shown because too many files have changed in this diff.
Show more
Reference in new issue
Block a user