Commit Graph
464 Commits
Author SHA1 Message Date
Mike Hillyer 164f109326 Traffic Shaping Refactor First Pass 2026-06-09 13:23:56 -04:00
Wez Furlong 4eedf9361e fix punycode normalization for STARTTLS
I believe this to be a relatively recent regression since we started
to preserve the incoming domain name in RCPT TO, rather than
normalizing it. (2026.04.09-ea3b2a9b)

refs: https://github.com/KumoCorp/kumomta/issues/533
2026-05-30 17:35:28 +01:00
Harsh JhaandWez Furlong 00f3131f7d Allow configuring which records TSA skips
Closes: https://github.com/KumoCorp/kumomta/pull/525

Co-authored-by: Wez Furlong <wez@wezfurlong.org>
2026-05-29 15:02:31 +01:00
Aditya GantiandWez Furlong 7bfbbe720a fix(mod-aws-sigv4): apply Trimall, require host header, fix S3 content-sha256
Co-authored-by: Wez Furlong <wez@wezfurlong.org>
Closes: https://github.com/KumoCorp/kumomta/pull/522
2026-05-29 10:16:06 +01:00
Wez Furlong 5fb9dd104d fix regression in serializing original_message in ARF
This got overlooked around the time that 7518ca6de was pushed.
The intent was to serialize as a string when possible, bytes otherwise.
2026-05-29 09:45:22 +01:00
Wez Furlong 06a26f4ba6 kumo-jsonl: make tailer more tolerant of errors
Two main cases:

 * If the user accidentally places files in the directory that
   are not kumo-jsonl compatible segments, then we won't trip
   over them and stop processing.

 * If the log segments are incomplete (eg: kumod was SIGKILL'd)
   then we log the issue and avance to the next segment
2026-05-29 08:57:47 +01:00
Wez Furlong 5a7aa96cf1 docs: update for 2026.05.12-a6845223 release 2026-05-27 06:47:55 +01:00
Wez Furlong 62de291279 docs: suggest folks prefix their metadata names
Should help to avoid possible conflicts with the core metadata names.
2026-05-12 14:35:16 +01:00
Harsh JhaandWez Furlong 7cba56bc06 http injection: allow static per-recipient metadata
That metadata is accessible in to via msg:get_meta('extra')

closes: https://github.com/KumoCorp/kumomta/pull/516
Co-authored-by: Wez Furlong <wez@wezfurlong.org>
2026-05-12 14:25:46 +01:00
kay ozakiandWez Furlong 1febfcc55e lua counter series using kumo-counter-series
Co-authored-by: Wez Furlong <wez@wezfurlong.org>
closes: https://github.com/KumoCorp/kumomta/pull/507
2026-05-07 15:35:17 +01:00
Wez Furlong 421bff1a41 docs: changelog for #504 2026-05-07 14:21:01 +01:00
JackandWez Furlong c4dbaa743b proxy-server: add tcp_keepalive option
Some upstream peers (e.g. QQ Mail's rate-limiter) silently hold a
proxied TCP connection open indefinitely — sending no data, FIN, or RST
— rather than cleanly refusing.  Without some kind of timeout
management, the two file descriptors for such a session remain open for
the lifetime of the process, slowly exhausting the kernel's
file-descriptor table and occupying proxy-server worker slots.

This commit configures kernel level keepalive options with reasonable
defaults to detect and close out this class of connection.

Co-authored-by: Wez Furlong <wez@wezfurlong.org>

Closes: https://github.com/KumoCorp/kumomta/pull/509
2026-05-06 21:09:10 +01:00
Wez Furlong ee1e5b980e message: add msg:import_headers, a flexible alternative to import_x_headers
import_headers takes an array of per-spec option tables, each describing
how a single header name or pattern should be imported into the message
metadata. Compared to import_x_headers it adds:

 * Trailing-`*` wildcard patterns (e.g. `X-*`) alongside exact names.
   Bare/leading/interior wildcards are rejected at compile time.
 * `match` of `first`, `last` (default), or `all`. `all` captures every
   matching header instance as an array of strings; the others capture
   a string. Specs that produce no matches write nothing.
 * `transform` selects the metadata key style: `snake_case` (default,
   matches the existing import_x_headers behavior), `kebab_case`,
   `camel_case`, or `pascal_case`. Header matching itself is always
   case-insensitive.
 * `target` overrides the metadata key for exact-name specs.
 * `remove` strips the matched headers from the message body in a
   single follow-up pass.

When more than one spec could match a header, the first matching spec
wins, so callers can place specific rules ahead of a wildcard catch-all.

import_x_headers now delegates to import_headers, so its behavior is
unchanged and the two share a single implementation.

retain_headers now passes the header index alongside the &Header to its
closure, which import_headers uses for its post-pass removal step
instead of tracking a parallel counter. Existing callers that don't
need the index ignore it with `_`.

Closes: #515
2026-05-06 16:30:36 +01:00
Wez Furlong 4ab07b7f1c Fix EnvelopeAddress::parse("")
This is similar to https://github.com/KumoCorp/kumomta/pull/512, but
whereas that one was a parser precedence issue, this one is due to
how Null is represented outside of the context of rfc5321.

refs: https://github.com/KumoCorp/kumomta/issues/511
2026-05-05 19:39:27 +01:00
kay ozaki a997a6664b make_message fails for from address which starts with postmaster
closes: https://github.com/KumoCorp/kumomta/pull/512
2026-05-05 19:30:26 +01:00
kay ozaki 7921fa5a19 typing.lua boolean-true default prevents mail_auth modules from being disabled
refs: https://github.com/KumoCorp/kumomta/pull/505
2026-04-29 12:06:35 +01:00
kay ozaki de95e63b2a multipart/mixed > multipart/related was not parsing
closes: https://github.com/KumoCorp/kumomta/pull/506
2026-04-29 11:58:03 +01:00
Wez Furlong 37236c40b1 docs: update for the 2026.04.09-ea3b2a9b release 2026-04-29 08:07:13 +01:00
Wez Furlong ea87ea6ab3 make HeaderAddress localpart consistent with EnvelopeAddress
This was previously just returning everything before the final at-sign.
Now we use the same parsing approach and return the normalized local
part.

This is technically a breaking change, but it is minor and improves
the overall state of things.
2026-04-09 15:42:40 +01:00
Wez Furlong a800f49d7d docs: changelog for https://github.com/KumoCorp/kumomta/pull/497 2026-04-04 19:55:43 +01:00
Wez Furlong 7cf2e04bee docs: changelog for kumo.jsonl 2026-04-04 12:26:05 +01:00
Wez Furlong 6479810368 queue helper: add invalidate_with_epoch option to queue_helper_data cache 2026-04-02 08:55:13 +01:00
Wez Furlong 43dfae466c docs: restore and correct changelog for #496
This got lost during merge conflict resolution, as well as
incorrectly indicated that it applied to rustls in the original
draft, when it was in fact only applicable to openssl.
2026-04-02 05:28:10 +01:00
Harsh Jha f08b184037 feat: pre-define to_header substitution in HTTP injection API
Pre-populate a `to_header` template substitution with the default
formatted `To` header for each recipient. Users can reference it via
`{{ to_header }}` and override it per-recipient in substitutions.

closes: https://github.com/KumoCorp/kumomta/pull/501
2026-04-01 08:17:12 +01:00
Wez Furlong b68f8245f4 docs: changelog for #496 2026-04-01 07:22:07 +01:00
kay ozaki 77a8e951c5 mod-string: add ends_with, starts_with
closes: https://github.com/KumoCorp/kumomta/pull/498
2026-03-31 15:23:49 +01:00
Wez Furlong a3801e8973 docs: changelog for recent connection failure summary changes 2026-03-28 07:29:20 +00:00
Wez Furlong ee637fb51d docs: changelog entry about recent mailparsing changes 2026-03-28 07:20:35 +00:00
Wez Furlong 937611feb9 rfc5321: improve handling of quoted local parts in envelope addresses
This commit refactors the EnvelopeAddress types(!) so that the brains
of them are centralized in the rfc5321 crate, removes the one from
the log-types crate, and replaces the internals of the one in the
message crate with the rfc5321 implementation.

This revised implementation accommodates quoted local parts more
consistently and exposes the local part via a normalizing accessor which
is in turn used when comparing addresses for equality.

This means that `"foo"@` and `foo@` now compare the same, and if you
have setup a maildir that generates per-user maildirs, we'll use the
normalized form of the local part rather than whatever is on the
incoming address.

Another side effect of this commit is that we can now accept exotic
quoted addresses like `"info@"@example.com` without falsely complaining
about having too many `@` signs in the address.

closes:  https://github.com/KumoCorp/kumomta/issues/495
2026-03-28 07:20:35 +00:00
Wez Furlong b679166fe2 smtp_server: Fix handling invalid EnvelopeAddress in MAIL or RCPT commands
We were propagating the parse error as a server error and mapping it
to the 421 technical difficulties response instead of returning
the appropriate syntax error response defined by SMTP.

refs: https://github.com/KumoCorp/kumomta/issues/495
2026-03-28 07:20:35 +00:00
Wez Furlong 8cb8b3fa7e new: kumo.encode.charset_decode/kumo.encode.charset_encode
These are more immediately useful to me for writing tests, but are
generally useful when you have a policy that might need to to deal
with legacy encoding schemes more directly.
2026-03-28 07:20:34 +00:00
Wez Furlong 084389b7ae dkim: remove implicit policy status for mismatching From/Signing domains
It was pointed out that we had this policy and that it wasn't part of
the spec.

That behavior was imported along with the crate when we forked it from
the cloudflare implementation.

Let's remove it; folks that need it can use a couple of lines of lua to
recreate it if they need it.
2026-03-28 07:20:08 +00:00
Wez Furlong d48ad3cb5b mod-serde: sort pretty-printed json object keys
This makes things a bit easier for human consumption, especially
for the `resolve-shaping-domain` utility.
2026-03-16 08:35:00 +00:00
Wez Furlong c0440ea138 rfc3464: fix issue with addresses enclosed in <>
This is a follow on from the previous commit; apparently some sites
will enclose addresses in <> even though this is not covered in the
RFC.

Let's cut the address parsing over to the SMTP parser rather than
the mail header parser, as they have rather different semantics
and both ARF and OOB are SMTP-centric.
2026-03-16 08:06:35 +00:00
Wez Furlong 813c7935d6 rfc5965: fix an issue with addressed enclosed in <>
We had a report that the enclosing <> were being passed through
to the JsonLogRecord in some log hook flows, which meant that
we'd try to parse them as EnvelopeAddresses and fail.
2026-03-13 10:36:36 +00:00
Wez Furlong c151016472 lruttl: add consistency/robustness check
In our thundering herd protection we intentionally limit the number of
pending lookups for a given key to just 1.  That is controlled via
a semaphore.

We have pre-existing logic that checks to see if the semaphore has been
closed (eg: by a task being cancelled), but despite this, we do
occasionally have reports from users with `timed out after 120s on
semaphore acquire while waiting for cache to populate` for the shaping
data cache.

This typically correlates with eg: long IO waits due to eg: a spike in
transient failures and usually some sort of logging of headers, but not
always.

The not always situation bothers me as we don't currently have a good
explanation of what might be causing the excessive delay.

This commit adds an additional sanity check: when a new lookup is
initiated, if the semaphore is still open (not cancelled), but has been
open for longer than the populate timeout, then we treat this similarly
to the semaphore being closed: we'll create a new semaphore, reset the
expiration and the caller will typically then promote itself to the task
that will satisfy the lookup.

The side effect of this all waiters should become unblocked and awake
either with an error status or with the result of the new lookup, which
should help to clear any persistent/recurring blocking state associated
with this.

This change doesn't provide more insight (I have something in mind for a
follow-on commit for that), but should help make forward progress.
2026-03-11 15:19:23 +00:00
Wez Furlong e4594e8550 sources.lua: fix defining empty egress pools
The example in the FAQ does this but it did not validate because the
associated structure was not defined, because there were no sources
in the pool!

Fix up the logic to allow creating an empty pool.

https://docs.kumomta.com/faq/how_do_i_create_an_always_suspended_queue/
2026-03-05 16:57:51 +00:00
Wez Furlong 654f9b88f5 new: ip_lookup_strategy option in make_egress_path
This provides control over IPv4 and IPv6 lookups based on the source
and/or destination.
2026-03-04 16:33:32 +00:00
Wez Furlong 332595ee2a queue.lua: add typing to setup methods
We had an issue where a typo resulted in a relatively inscrutable
error at runtime:

```lua
local queue_helper =  queue_module:setup ('/opt/kumomta/etc/policy/queues.toml')
```

produced this:

```
problem initializing: call validate_config callback: runtime error: /opt/kumomta/share/policy-extras/queue.lua:602: bad argument #1 to 'for iterator' (table expected, got nil)
stack traceback:
        [C]: in function 'next'
        /opt/kumomta/share/policy-extras/queue.lua:602: in function </opt/kumomta/share/policy-extras/queue.lua:551>
Error: Initialization raised an error: call validate_config callback: runtime error: /opt/kumomta/share/policy-extras/queue.lua:602: bad argument #1 to 'for iterator' (table expected, got nil)
stack traceback:
        [C]: in function 'next'
        /opt/kumomta/share/policy-extras/queue.lua:602: in function </opt/kumomta/share/policy-extras/queue.lua:551>
```

with the changes in this commit we'll present this issue like this,
during server startup, which points a little more clearly at the setup
call and the file names parameter, and suggests more strongly that it
should be a list of strings (or config objects):

```
    runtime error: [string "./simple_policy.lua"]:52: assets/policy-extras/queue.lua:463 QueueHelperSetup: invalid value for field 'file_names'
    assets/policy-extras/queue.lua:463 Expected value of type 'list<variant<string,QueueHelperConfig>>' but got type 'string' '/opt/kumomta/etc/policy/queues.toml'
    stack traceback:
        [C]: in function 'error'
        assets/policy-extras/typing.lua:78: in method 'raise'
        assets/policy-extras/typing.lua:249: in metamethod 'newindex'
        assets/policy-extras/typing.lua:258: in function <assets/policy-extras/typing.lua:253>
        (...tail calls...)
        assets/policy-extras/queue.lua:463: in function 'policy-extras.queue.setup_with_options'
        (...tail calls...)
        [string "./simple_policy.lua"]:52: in main chunk
```

this change actually surfaced a minor issue in the ndr.lua file that is
part of an integration test, as well as in my adhoc simple_policy file.
2026-03-04 09:23:08 +00:00
Wez Furlong 030520b04c docs: update changelog for stable release 2026-03-04 08:05:09 +00:00
Aditya Ganti f0e48bdb27 dkim: fix wrapping issue
It was reported that AWS SES could mark the DKIM signature as failed
when using a specific combination of headers in the header list,
with specific lengths of the other fields.

The reason for this is that we had two passes of wrapping applied
to the header, and they might not agree on the formatting of
the header.

The solution is to remove the second pass and just take a bit more
care to emit the header in a wrapped form in the first instance,
that way there can be no discrepancy or conflict.

closes: https://github.com/KumoCorp/kumomta/pull/483
2026-02-28 08:17:09 +00:00
Wez Furlong 04076707ec http injection: template errors are now reported with status 422
As part of this, we move template compilation to happen before
we queue up deferred generation; the compilation step should
be plenty fast enough that we can reasonably do that synchronously
and report any compilation errors back to the peer.
2026-02-25 14:25:38 +00:00
Wez Furlong d8a7b0170e add new cpu usage metrics
refs: https://github.com/KumoCorp/kumomta/issues/186
2026-02-24 12:19:54 +00:00
Wez Furlong 9847867dc4 smtp_dispatcher: improve dead connection detection between sends
This is an alternative implementation of
https://github.com/KumoCorp/kumomta/pull/482 that checks for a
unilateral response as part of deciding whether we can re-use
the current connection.

By detecting this condition before we've popped a message, we avoid
classifying that message attempt as a transient connection failure, and
can send it with lower latency overall.

closes: https://github.com/KumoCorp/kumomta/pull/482
2026-02-21 07:25:40 +00:00
Wez Furlong 80decbc08e redis: add redis_operation_latency histogram
This enables tracking the latency and status of redis operations.
2026-02-20 08:15:09 +00:00
Wez Furlong 5f7fae1d6b tsa: add basic /tsa/status endpoint
This simply returns a 200 response and can be used to determine
that TSA service is up.
2026-02-20 06:51:23 +00:00
Wez Furlong 26135a2b53 filter out not-relevant-to-TSA events earlier in the logging
I believe this to be more of a micro optimization, because the
heavy lifting was already being done in the should_enq function,
which filters out before we commit the event to the spool.

Thanks to @smsvip for noticing that there was a discrepancy
between the UNINTERESTING_LOG_RECORD_TYPES and the per-record
configuration; we now use the former to derive the latter.

I've add more obviously irrelevant to TSA types to the config
as part of this commit.

refs: https://github.com/KumoCorp/kumomta/pull/481
refs: https://github.com/KumoCorp/kumomta/issues/478
2026-02-18 15:05:18 +00:00
Wez Furlong b2b3889077 docs: changelog for #480 2026-02-16 11:04:27 +00:00
Wez Furlong 6193331a4a http/xfer injection: grab Activity handle for duration of request
I noticed that we weren't grabbing the Activity handle for injection
requests.  Doing so allows us to reject a request that comes in
while we are shutting down the service, rather than accept it to
have it potentially dropped as we shut down.

I also realized that we need to make the xfer injection handler
match the same set of rules for the http injection handler, so
this commit refactors that logic to reuse it in both places.
2026-02-11 06:17:17 +00:00
Wez Furlong 188356e64d http injection: fix early startup race condition w/ spool
If you start up while injectors are actively trying to send,
you might trigger a race condition where the spool isn't fully
assigned by the time that an injection request wants to store
a message to the spool.

Add a similar check for spool readiness to what we have in
the smtp server path.
2026-02-10 06:57:01 +00:00