Eight conflicted files resolved, plus the lock file and the schema:
- crates/services/src/task_manager/spam_classifier.rs: upstream's rules
update now replaces existing rules, DNSBL servers, lookups and file
extensions, keeping only whether each is on. Taken, with one difference:
an object an admin edited is kept as it is. Every object an update writes
is fingerprinted (content without `enable`, SHA-256, stored under
SUBSPACE_INBUXA "Sf"), and only one that still matches is replaced.
Scores are never replaced, as upstream has it. The AU-1.10 summary record
now names what was added, replaced and kept, and the bundled rules are
marked applied only when the update fully succeeded, so a failure runs
again on the next start. The marker becomes "3.0.2+2", which runs the
update once on upgrade to fingerprint every rule still as bundled.
- crates/common/src/network/autoconfig/autodiscover.rs: upstream's rewrite
(implicit TLS first, labeled SSL), with the per-protocol switches (LP-7,
LP-14a) passed in as a filter.
- crates/store/src/backend/mysql/{search,write}.rs: upstream's chunked
deletes (no unbounded first DELETE, stop on a short chunk, halve the
chunk on the new chunk-too-large errors) inside the fork's query timeout.
- crates/smtp/src/lib.rs: the fork's queue spawn kept. It already fixed the
stall upstream fixes here (a node without outboundMta stops accepting
mail at about 1024 queued messages), and follows role changes live.
- crates/jmap/src/registry/mapping/bootstrap.rs: the log path stays
/var/log/inbuxa/; upstream's PowerDNS mapping taken.
- crates/main/Cargo.toml: the AGPL-only license kept, version 0.16.24.
- tests/src/jmap/principal/get.rs: the fork's capabilities kept.
- resources/schema/schema.json.gz: merged as JSON; upstream relabeled the
vendor Sieve extensions "(Stalwart)", kept as "(vnd.inbuxa)".
- Cargo.lock: upstream's, with the fork's crates added by Cargo.
Also:
- tests/src/smtp/inbound/spam_rules_kept.rs: an edited rule survives an
update, an unedited one is updated, rules from before fingerprints are
handled, and the audit summary says so. Upstream's own spam_rules test
passes unchanged.
- tests/src/smtp/reporting/reschedule.rs moves to port 19058; upstream's
new spam_rules test took 19057.
- tools/fork/renames.py renames the "(Stalwart)" labels and the default
log path, so neither conflicts again.
- tools/fork/notice-check.py compares against the newest snapshot in the
checked-out history instead of the upstream branch head, so moving the
branch no longer fails other open pull requests.
- tests/src/directory/issuer.rs (since v0.16.23) stays out, and is on the
build check's known list: it tests issuer-based directory routing, which
the fork doesn't have (DIR-2).
- Strip report: docs/fork/strip-reports/v0.16.24.{md,json}.
96 lines
3.9 KiB
Markdown
96 lines
3.9 KiB
Markdown
# Fork tooling
|
|
|
|
## strip.py
|
|
|
|
Makes an Enterprise-free snapshot of an upstream release. See the docstring
|
|
and docs/spec/SPEC.md §2.2 for what it does and why.
|
|
|
|
```bash
|
|
git clone https://github.com/stalwartlabs/stalwart.git ~/src/stalwart-upstream # outside this repo
|
|
git -C ~/src/stalwart-upstream fetch --tags
|
|
tools/fork/strip.py --upstream ~/src/stalwart-upstream --ref v0.16.22 --out /tmp/strip-v0.16.22
|
|
```
|
|
|
|
It writes `OUT/tree` (the stripped source) and `OUT/STRIP-REPORT.md` and
|
|
`.json`. Exit 0 means verified clean. Exit 1 means malformed markers, or
|
|
something Enterprise-only survived. Read the report's Problems section.
|
|
|
|
The report's Third-party code section lists upstream code under other
|
|
licenses. Files marked **new** need their notice added to `THIRD-PARTY.md`
|
|
at the repository root before the import is merged.
|
|
|
|
It needs Python 3.12+ (for `tarfile`'s `data` filter), git and cargo.
|
|
|
|
Two passes run after the strip:
|
|
|
|
- **Renames.** The upstream name is replaced where it's an identifier
|
|
clients, users or operators meet: wire-protocol names, the web interface's
|
|
client id, store keys, configuration defaults and the served schema, as
|
|
`renames.py` lists them. `main` was renamed with the same module. A
|
|
re-import arrives purged, so those lines never conflict. Copyright notices
|
|
and prose are left alone. The report lists every substitution by file.
|
|
- **Build check.** The stripped tree is compiled (`cargo check --workspace
|
|
--all-targets`) into `target/strip-check`, which stays warm between
|
|
imports. A file that survived the strip but calls code that didn't fails
|
|
the run; the report names it. Handle it in the merge into `main`, never on
|
|
`upstream`: `upstream` holds the strip's output and nothing else. Imports
|
|
the strip left unused are listed without failing. `--no-build-check`
|
|
skips the pass.
|
|
|
|
## name-check.py
|
|
|
|
Fails when the upstream project's name appears in a Rust string literal that
|
|
`name-allowlist.txt` doesn't list. CI runs it on every push and pull request,
|
|
so an upstream merge can't bring the name back into what users and operators
|
|
see. Comments, copyright headers and test directories aren't checked.
|
|
|
|
```bash
|
|
tools/fork/name-check.py # exit 1 on anything new
|
|
tools/fork/name-check.py --list # every finding, in allowlist format
|
|
```
|
|
|
|
Rename what it reports. If a string has to stay, such as a key-derivation
|
|
context or a wire-protocol identifier, add its `--list` line to the allowlist
|
|
under the reason it stays.
|
|
|
|
## notice-check.py
|
|
|
|
Fails when an upstream file the fork changed doesn't carry the AGPL 5(a)
|
|
notice, `Modified by Coffey Labs in <year> for INBUXA.`, under upstream's
|
|
license line. "Changed" means it differs from the newest `upstream` snapshot
|
|
in the checked-out history (found by its "Import upstream v…" subject, so CI
|
|
needs a full clone), so the list comes from the diff, not from memory. A
|
|
branch merging a new release is checked against that release, and other
|
|
branches aren't affected when the `upstream` branch moves. CI runs it beside
|
|
the name check.
|
|
|
|
```bash
|
|
tools/fork/notice-check.py # exit 1 on a missing notice
|
|
tools/fork/notice-check.py --fix # add it where it's missing
|
|
```
|
|
|
|
Run `--fix` after resolving an upstream merge: a conflict resolved by taking
|
|
upstream's side can drop a notice the file had.
|
|
|
|
## record-compat.py
|
|
|
|
Records what the `*_compat` tests compare against, from the Enterprise
|
|
server, while it is still running. Read-only: `/get` and `/query` only.
|
|
See `docs/spec/compat-tests.md`.
|
|
|
|
```bash
|
|
tools/fork/record-compat.py --server https://mail.example.org \
|
|
--admin '[email protected]:PASSWORD' --out ./compat \
|
|
--tenant-admin '[email protected]:PASSWORD'
|
|
```
|
|
|
|
## run-compat.sh
|
|
|
|
Runs the `*_compat` tests against a copy of INBUXA's RocksDB store, making
|
|
a fresh copy for each one. See `docs/spec/compat-tests.md`.
|
|
|
|
```bash
|
|
tools/fork/run-compat.sh --store /srv/inbuxa-copy/rocks.db \
|
|
--admin '[email protected]:PASSWORD' --recordings ~/compat
|
|
```
|