Merge upstream v0.16.25 #155

Merged
jcoffey-dev merged 3 commits from merge/upstream-v0.16.25 into main 2026-10-06 07:30:13 +00:00
Owner

Brings in upstream v0.16.25 as a stripped snapshot (72f8ddd, branch
import/upstream-v0.16.25; fast-forward upstream to it after this
lands). No release is planned yet.

v0.16.25 only fixes bugs:

  • DKIM rotation: a key retired before its successor was published
    (mail sent unsigned, task reporting success); keys made under manual
    DNS never rotating after switching to automatic; manual DNS
    activating an unpublished key.
  • IMAP: failed LOGIN/AUTHENTICATE answered with an untagged NO, which
    left clients waiting for a timeout.
  • Spam filter: DNSBL scoring only the first of several return codes and
    caching "not listed" for 24 hours; Pyzor digesting empty input; a
    duplicate-sample removal clearing the kept sample's blob link.
  • MTA: queue quotas with an empty match never enforced.
  • RocksDB: info log (LOG) growing without limit.
  • JMAP MaskedEmail with several domains; Autodiscover answering other
    schemas (ActiveSync) with the Outlook settings instead of error 601.
  • WebUI download stopped by a blob store error at startup.

Strip: clean; same Enterprise footprint as v0.16.24; no new third-party
code; privacy catalog complete; build check clean.

Merge (db4135e):

  • crates/main/Cargo.toml: inbuxa's name, AGPL-only license, 0.16.25.
  • SECURITY.md, .github/PULL_REQUEST_TEMPLATE.md: inbuxa's.
  • Cargo.lock: upstream's, re-resolved against inbuxa's manifests.
  • autodiscover.rs: upstream now parses the request into a struct, so
    the legacy-protocol switch (LP-7) reads request.email.
  • Schema: unchanged upstream apart from two labels main already had.
  • AGENTS.md (new upstream, about contributing upstream) left out.

Test fix (b252583): the spam classifier test now resets the upload
TTL/count/quota the quota test leaves at one second / three / 50 kB.
After the merge it failed two runs in three with BlobNotFound on an
import; reverting upstream's sample-deadline change (now() + hold
instead of midnight + hold) made it pass, so that change tips the
timing. Production keeps uploads an hour and samples ninety days.

Checked locally: every fork check (name, notice, context, privacy,
expr-schema, tool tests); workspace build and cargo test --workspace --no-run; workspace unit tests (582 passed; smtp's lib tests need the
tests crate's features and were built, not run); SMTP group serially
(78 passed; the three live-network tests skipped: asn, milter,
dane_live); IMAP suite; automation suite (ACME, DKIM, DNS).

System suite flakiness, checked: the suite has several one-second
timing races (uploads the quota test leaves at a 1 s TTL, a masked
address that expires in 1 s, SMTP response timeouts) and fails now and
then on every variant tried, alternated on the same machine:

  • main: 14/16 (both failures BlobNotFound in the purge test)
  • this branch: 16/21, plus 6/6 with server tracing on
  • this branch with upstream's sample-deadline change reverted: 12/13
    Failures were spread over purge, quota, delivery and security, on all
    three. Timing probes on every step of the delivery test (5 runs each,
    branch vs reverted deadline) show no slower step: 11.75 s vs 11.66 s
    in total, the largest per-step gap 67 ms. Machine load stayed below
    1.2 on 16 cores. Not a regression from this merge.
Brings in upstream v0.16.25 as a stripped snapshot (72f8ddd, branch import/upstream-v0.16.25; fast-forward `upstream` to it after this lands). No release is planned yet. v0.16.25 only fixes bugs: - DKIM rotation: a key retired before its successor was published (mail sent unsigned, task reporting success); keys made under manual DNS never rotating after switching to automatic; manual DNS activating an unpublished key. - IMAP: failed LOGIN/AUTHENTICATE answered with an untagged NO, which left clients waiting for a timeout. - Spam filter: DNSBL scoring only the first of several return codes and caching "not listed" for 24 hours; Pyzor digesting empty input; a duplicate-sample removal clearing the kept sample's blob link. - MTA: queue quotas with an empty `match` never enforced. - RocksDB: info log (`LOG`) growing without limit. - JMAP MaskedEmail with several domains; Autodiscover answering other schemas (ActiveSync) with the Outlook settings instead of error 601. - WebUI download stopped by a blob store error at startup. Strip: clean; same Enterprise footprint as v0.16.24; no new third-party code; privacy catalog complete; build check clean. Merge (db4135e): - crates/main/Cargo.toml: inbuxa's name, AGPL-only license, 0.16.25. - SECURITY.md, .github/PULL_REQUEST_TEMPLATE.md: inbuxa's. - Cargo.lock: upstream's, re-resolved against inbuxa's manifests. - autodiscover.rs: upstream now parses the request into a struct, so the legacy-protocol switch (LP-7) reads request.email. - Schema: unchanged upstream apart from two labels main already had. - AGENTS.md (new upstream, about contributing upstream) left out. Test fix (b252583): the spam classifier test now resets the upload TTL/count/quota the quota test leaves at one second / three / 50 kB. After the merge it failed two runs in three with BlobNotFound on an import; reverting upstream's sample-deadline change (now() + hold instead of midnight + hold) made it pass, so that change tips the timing. Production keeps uploads an hour and samples ninety days. Checked locally: every fork check (name, notice, context, privacy, expr-schema, tool tests); workspace build and `cargo test --workspace --no-run`; workspace unit tests (582 passed; smtp's lib tests need the tests crate's features and were built, not run); SMTP group serially (78 passed; the three live-network tests skipped: asn, milter, dane_live); IMAP suite; automation suite (ACME, DKIM, DNS). System suite flakiness, checked: the suite has several one-second timing races (uploads the quota test leaves at a 1 s TTL, a masked address that expires in 1 s, SMTP response timeouts) and fails now and then on every variant tried, alternated on the same machine: - main: 14/16 (both failures BlobNotFound in the purge test) - this branch: 16/21, plus 6/6 with server tracing on - this branch with upstream's sample-deadline change reverted: 12/13 Failures were spread over purge, quota, delivery and security, on all three. Timing probes on every step of the delivery test (5 runs each, branch vs reverted deadline) show no slower step: 11.75 s vs 11.66 s in total, the largest per-step gap 67 ms. Machine load stayed below 1.2 on 16 cores. Not a regression from this merge.
jcoffey-dev added 3 commits 2026-10-06 05:39:02 +00:00
Upstream commit: 3f657330c0f49a015a3a372fb59669b5cccbca6d
Enterprise-only files removed or emptied: 63
Enterprise-only snippets removed: 118 in 50 files
Dangling module declarations removed: 5
Edits turning enterprise off: 25
Third-party code: 14 files, 0 not in THIRD-PARTY.md
Renamed identifiers: 67 in 19 files
Verification: clean

The same Enterprise footprint as v0.16.24. The build check is clean
apart from the expected errors in the rebuilt-feature tests. A
bug-fix release: DKIM rotation, IMAP failed-login answers, DNSBL
multi-code scoring and negative TTLs, Pyzor on short messages, queue
quotas with an empty match, RocksDB info-log rotation, and
Autodiscover schema handling.
Brings in the stripped v0.16.25 snapshot (72f8ddd), a bug-fix release:
DKIM rotation (keys retired before their successor is published, keys
made under manual DNS never rotating, manual DNS activating an
unpublished key), IMAP answering failed logins with an untagged NO,
DNSBL scoring only the first return code and caching "not listed" for
24 hours, Pyzor digesting empty input, queue quotas with an empty match
never enforced, RocksDB's info log growing without limit, MaskedEmail
creation with several domains, and Autodiscover answering other schemas
with the Outlook settings.

Conflicts:
- crates/main/Cargo.toml: inbuxa's name and AGPL-only license, version
  0.16.25.
- SECURITY.md and .github/PULL_REQUEST_TEMPLATE.md: inbuxa's own.
- Cargo.lock: upstream's, re-resolved against inbuxa's manifests.
- crates/common/src/network/autoconfig/autodiscover.rs: upstream now
  parses the request into a struct, so the legacy-protocol switch
  (LP-7) reads the address from request.email; ActiveSync and other
  schemas get upstream's error 601 untouched.
- resources/schema: unchanged upstream apart from two labels the rename
  pass now covers, which main already had.

AGENTS.md, new upstream, is left out: it is about contributing to
upstream, which doesn't apply to this repository.
Give the spam classifier test its own upload limits
ci / fork-checks (pull_request) Skipped
ci / build (pull_request) Skipped
github/ci (branch) GitHub Actions
ci / github (pull_request) Successful in 7m48s
b25258330c
The quota test, which runs earlier in the same system suite, leaves
uploads expiring after one second, at most three at a time, and the
spam classifier test inherited that. It imports twenty samples, each an
upload followed by an import; when the step between them takes longer
than a second, the import fails with BlobNotFound.

After the v0.16.25 merge this failed in two runs out of three, where
main passed three out of three. Putting back the old midnight rounding
of a training sample's deadline (upstream now uses now() + hold, which
is now() in this suite since the purge test holds samples for zero
seconds) made it pass, so that change is what tips the timing; exactly
how it slows the import loop wasn't traced.

The test now resets the upload TTL, count and quota to their defaults
before it starts. Production isn't affected: uploads are kept for an
hour by default and samples for ninety days.
jcoffey-dev merged commit b64f6690f6 into main 2026-10-06 07:30:13 +00:00
jcoffey-dev deleted branch merge/upstream-v0.16.25 2026-10-06 07:30:13 +00:00
Sign in to join this conversation.