jcoffey-dev is traveling from Thursday 1 October through Sunday 4 October. Issues and pull requests are welcome, and will get an answer after that. Thanks for your patience.
Phase 2f of the DLP spec: rules now run on authenticated senders' mail, after the DATA system script and before headers and DKIM signing.
Block: 550 5.7.1 + the rule's notice; JMAP inbuxa:dlpBlocked with each rule's name and notice.
Warn: 550 5.7.1 + notice + how to override ([override: reason] subject tag, stripped before sending); JMAP inbuxa:dlpWarning, answered with inbuxa:dlpOverride: {reason} on the EmailSubmission.
Hold: blocks until phase 3 builds review.
Skipped when no enabled rule applies to outgoing mail; rules that can't load refuse with 451 (nothing unchecked leaves).
Audit: one record per match: sender as actor, create on a message, recipient domains, rules with detector counts, outcome, override reason; never the matched text. No new audit action (rollback safety; spec §2.7 updated).
Tests: mail_rules_tests covers the full flow over JMAP including the stripped subject on the delivered copy and no card/key text in audit records; smtp inbound tests pass; system_tests passed twice after one email-delivery timeout that didn't recur.
Phase 2f of the DLP spec: rules now run on authenticated senders' mail, after the DATA system script and before headers and DKIM signing.
- **Block**: `550 5.7.1` + the rule's notice; JMAP `inbuxa:dlpBlocked` with each rule's name and notice.
- **Warn**: `550 5.7.1` + notice + how to override (`[override: reason]` subject tag, stripped before sending); JMAP `inbuxa:dlpWarning`, answered with `inbuxa:dlpOverride: {reason}` on the EmailSubmission.
- **Hold**: blocks until phase 3 builds review.
- Skipped when no enabled rule applies to outgoing mail; rules that can't load refuse with `451` (nothing unchecked leaves).
- **Audit**: one record per match: sender as actor, `create` on a `message`, recipient domains, rules with detector counts, outcome, override reason; never the matched text. No new audit action (rollback safety; spec §2.7 updated).
Tests: `mail_rules_tests` covers the full flow over JMAP including the stripped subject on the delivered copy and no card/key text in audit records; smtp inbound tests pass; `system_tests` passed twice after one email-delivery timeout that didn't recur.
Phase 2f of the DLP and mail flow rules spec: the rules now run on mail
an authenticated sender submits, after the DATA system script and
before headers and DKIM signing (§2.1).
- smtp/inbound/mailflow.rs: builds what the rules look at from the
message (subject, the text version of each body, one level of attached
messages, attachment text via the extractor, 10 MB of text at most)
and the envelope (sender's groups and tenant; each recipient local or
not, and its groups). Skipped entirely when no enabled rule applies to
outgoing mail. Rules that can't be loaded refuse with a 451: nothing
unchecked leaves.
- Block: 550 5.7.1 with the rule's notice. Warn: 550 5.7.1 with the
notice and how to override: "[override: reason]" at the start of the
subject, taken out before the message goes on (settled answer 1).
Until phase 3, a hold rule blocks rather than let mail through.
- JMAP: EmailSubmission takes inbuxa:dlpOverride {reason}; a refusal
comes back as inbuxa:dlpWarning or inbuxa:dlpBlocked with each rule's
name and notice (description too, for older clients).
- Audit: one record per DLP match, the sender as actor, action create,
target a message: the recipient domains, each rule with its detectors'
counts, the outcome, an override's reason. Never the matched text. No
new audit action: an older node that meets one fails its daily
clean-up, which would make rolling back unsafe (spec §2.7 updated).
Tests: mail_rules_tests gains the DLP flow over JMAP (no rules, warning
with rule and notice, local recipient not warned, override with a
reason, block that no reason passes, the subject tag stripped from the
delivered message, audit records with no card or key text). smtp
inbound tests pass; system_tests passed twice after one timeout in the
email delivery tests that didn't recur.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Phase 2f of the DLP spec: rules now run on authenticated senders' mail, after the DATA system script and before headers and DKIM signing.
550 5.7.1+ the rule's notice; JMAPinbuxa:dlpBlockedwith each rule's name and notice.550 5.7.1+ notice + how to override ([override: reason]subject tag, stripped before sending); JMAPinbuxa:dlpWarning, answered withinbuxa:dlpOverride: {reason}on the EmailSubmission.451(nothing unchecked leaves).createon amessage, recipient domains, rules with detector counts, outcome, override reason; never the matched text. No new audit action (rollback safety; spec §2.7 updated).Tests:
mail_rules_testscovers the full flow over JMAP including the stripped subject on the delivered copy and no card/key text in audit records; smtp inbound tests pass;system_testspassed twice after one email-delivery timeout that didn't recur.Phase 2f of the DLP and mail flow rules spec: the rules now run on mail an authenticated sender submits, after the DATA system script and before headers and DKIM signing (§2.1). - smtp/inbound/mailflow.rs: builds what the rules look at from the message (subject, the text version of each body, one level of attached messages, attachment text via the extractor, 10 MB of text at most) and the envelope (sender's groups and tenant; each recipient local or not, and its groups). Skipped entirely when no enabled rule applies to outgoing mail. Rules that can't be loaded refuse with a 451: nothing unchecked leaves. - Block: 550 5.7.1 with the rule's notice. Warn: 550 5.7.1 with the notice and how to override: "[override: reason]" at the start of the subject, taken out before the message goes on (settled answer 1). Until phase 3, a hold rule blocks rather than let mail through. - JMAP: EmailSubmission takes inbuxa:dlpOverride {reason}; a refusal comes back as inbuxa:dlpWarning or inbuxa:dlpBlocked with each rule's name and notice (description too, for older clients). - Audit: one record per DLP match, the sender as actor, action create, target a message: the recipient domains, each rule with its detectors' counts, the outcome, an override's reason. Never the matched text. No new audit action: an older node that meets one fails its daily clean-up, which would make rolling back unsafe (spec §2.7 updated). Tests: mail_rules_tests gains the DLP flow over JMAP (no rules, warning with rule and notice, local recipient not warned, override with a reason, block that no reason passes, the subject tag stripped from the delivered message, audit records with no card or key text). smtp inbound tests pass; system_tests passed twice after one timeout in the email delivery tests that didn't recur.