A 3-node rehearsal (PostgreSQL + NATS + Garage) found two ways a crash leaves work stuck: Pool hangs. The PostgreSQL pool (deadpool) was built with no timeouts, so a request waited for a free connection, and for one to be opened or recycled, for as long as it took: forever when the server stopped answering. MySQL's pool (mysql_async) has no wait timeout at all. - PostgreSQL: wait 30 s (or the store's timeout if longer), create the store's timeout or 15 s (it bounds the whole handshake, where tokio-postgres's connect_timeout covers only the TCP connect), recycle 10 s. The pool config is now always set, not only with poolMaxConnections. - MySQL: every connection is taken through MysqlStore::conn(), which gives up after 30 s. - Both: TCP keepalive after 60 s idle, so a server that vanished without closing the connection is noticed in minutes rather than the two-hour system default. The DataStore schema has no pool timeout settings, so these are fixed defaults; the store's own timeout bounds connecting on PostgreSQL. Task locks. A task lock lasted an hour, so after a hard crash the dead node's tasks waited up to an hour and five minutes. The lock is now a five-minute lease: while this node runs a task, the task manager renews its lock every third of the lifetime (InMemoryStore::renew_lock, a compare-and-set on the store backends and SET XX EX on Redis, which leaves a lock that already expired alone). A killed node's tasks run elsewhere within about five minutes plus the claim recheck. A task this node holds isn't handed to a worker again by the scan. store::pool_timeout (new): a local listener that accepts connections and never answers plays a hung server; a PostgreSQL store with a 2 s timeout returns an error in about 4 s, and a MySQL store in 30 s. Without the timeouts both wait for good. store::task_locks gains a task held for 1.5 lock lifetimes: its lease is still held, and released when the task ends.
A complete mail and collaboration server, every feature included, under the AGPL
inbuxa is a mail and collaboration server: JMAP, IMAP, POP3, SMTP, CalDAV, CardDAV and WebDAV, in one Rust binary, with ihasmail as its web front end. It is a fork of Stalwart. Project site: inbuxa.org. Documentation: docs.inbuxa.org.
Stalwart ships some features only in a paid Enterprise Edition: multi-tenancy, masked email, undelete and others. inbuxa ships everything to everybody under the AGPL-3.0, rebuilding those features independently and without using any of Stalwart's Enterprise code.
What's different from Stalwart
- Every feature, one edition. No license key, no edition checks, no
upsell. See
docs/spec/SPEC.md§4 for the features being rebuilt, anddocs/spec/features/for each one's specification. - Webmail and administration by ihasmail, as a separate service that can run beside the server or elsewhere. Stalwart's own web interface is removed, so there's no web front end on the mail host.
- Clean-room rebuilds. Enterprise-only code is stripped from every
upstream release before it's imported. The rebuilt features are written
from specifications that use only public sources (
docs/spec/SPEC.md§3).
How the fork is kept
Upstream releases arrive as stripped snapshots, never with upstream's git
history, which contains Enterprise code. tools/fork/strip.py builds each
snapshot on top of upstream's own ossify.py, then verifies it independently.
The report for every import is in docs/fork/strip-reports/. See
docs/spec/SPEC.md §2.
Building
cargo build --release -p inbuxa # the binary is target/release/inbuxa
docker build -t inbuxa . # or the container image
Settings are read from INBUXA_* environment variables. An existing Stalwart
install's STALWART_* variables aren't read: the server stops at startup and
names each one to rename.
New installs keep their data in /var/lib/inbuxa and logs in
/var/log/inbuxa. Existing installs keep the paths their configuration
already names, so none of their data moves.
License and credits
inbuxa is free software under the GNU Affero General Public License, version 3.
It is a fork of Stalwart, copyright © Stalwart Labs LLC, modified by Coffey Labs in 2026. Upstream's copyright notices are kept on every file they cover, and every upstream file this fork changed says so in its header, under the notice it came with. Stalwart's files are dual-licensed AGPL-3.0-only or Stalwart's Enterprise License, and inbuxa takes them under the AGPL-3.0 only. A few of those files also carry code from other projects under MIT or BSD licenses, which stays under those licenses; THIRD-PARTY.md lists it with its notices. "Stalwart" is Stalwart Labs' name. inbuxa isn't affiliated with or endorsed by Stalwart Labs.
The inbuxa mark reuses ihasmail's cat-and-envelope artwork.