Skip to content

stalwart-mail: Fix spam-filter missing from /etc - #422909

Merged
happysalada merged 3 commits into
NixOS:masterfrom
norpol:fix_stalwart_spam-filter_missing
Jul 22, 2025
Merged

happysalada merged 3 commits into
NixOS:masterfrom
norpol:fix_stalwart_spam-filter_missing

Conversation

@norpol

@norpol norpol commented Jul 6, 2025 •

Copy link
Copy Markdown
Contributor

Things done

  • add norpol to nixpkgs maintainers
  • chore work with nixpkgs style preferences in other sub packages
  • The current nix unstable package doesn't contain the spamfilter.toml anylonger. This pull requests packages the spam-filter as an additional package.
$ find /nix/store/jwznrq528mx0z844ka6j4rfqk5bhj463-stalwart-mail-0.12.4/
/nix/store/jwznrq528mx0z844ka6j4rfqk5bhj463-stalwart-mail-0.12.4/
/nix/store/jwznrq528mx0z844ka6j4rfqk5bhj463-stalwart-mail-0.12.4/bin
/nix/store/jwznrq528mx0z844ka6j4rfqk5bhj463-stalwart-mail-0.12.4/bin/stalwart-cli
/nix/store/jwznrq528mx0z844ka6j4rfqk5bhj463-stalwart-mail-0.12.4/bin/stalwart
/nix/store/jwznrq528mx0z844ka6j4rfqk5bhj463-stalwart-mail-0.12.4/lib
/nix/store/jwznrq528mx0z844ka6j4rfqk5bhj463-stalwart-mail-0.12.4/lib/systemd
/nix/store/jwznrq528mx0z844ka6j4rfqk5bhj463-stalwart-mail-0.12.4/lib/systemd/system
/nix/store/jwznrq528mx0z844ka6j4rfqk5bhj463-stalwart-mail-0.12.4/lib/systemd/system/stalwart-mail.service
/nix/store/jwznrq528mx0z844ka6j4rfqk5bhj463-stalwart-mail-0.12.4/etc
/nix/store/jwznrq528mx0z844ka6j4rfqk5bhj463-stalwart-mail-0.12.4/etc/stalwart

Note: Stalwart will still download additional data through the spam-filter.toml. I don't think this has changed across the releases. I don't see that the ASN IPs, geolite, domains_mx, free_email_providers, ... are feasible to package into nixpkgs. So I'm not even sure whether it is advisable to not pull the spam-filters automatically from GitHub as well (so staying with the upstream config).

Also I'm unsure whether the auto-update flag has only an impact on the filter rules or also the http URLs downloaded through the filters.

$ grep 'https://'  /nix/store/ij1msx3awgpajyk4ci3zws3pyyixawkf-spam-filter-2.0.3/spam-filter.toml
asn = [ "https://cdn.jsdelivr.net/npm/@ip-location-db/asn/asn-ipv4.csv",
        "https://cdn.jsdelivr.net/npm/@ip-location-db/asn/asn-ipv6.csv" ]
geo = [ "https://cdn.jsdelivr.net/npm/@ip-location-db/geolite2-geo-whois-asn-country/geolite2-geo-whois-asn-country-ipv4.csv",
        "https://cdn.jsdelivr.net/npm/@ip-location-db/geolite2-geo-whois-asn-country/geolite2-geo-whois-asn-country-ipv4.csv" ]
url = "https://openphish.com/feed.txt"
url = "https://disposable.github.io/disposable-email-domains/domains_mx.txt"
url = "https://gist.githubusercontent.com/okutbay/5b4974b70673dfdcc21c517632c1f984/raw/993a35930a8d24a1faab1b988d19d38d92afbba4/free_email_provider_domains.txt"

built generates the same result

sha256sum /nix/store/ij1msx3awgpajyk4ci3zws3pyyixawkf-spam-filter-2.0.3/spam-filter.toml <(curl -qs -L -o - https://github.com/stalwartlabs/spam-filter/releases/download/v2.0.3/spam-filter.toml)
1b614bc004284116f6c98b5dfb2ce663872b5f60a0a8782c06ded9dcf3da2cd2  /nix/store/ij1msx3awgpajyk4ci3zws3pyyixawkf-spam-filter-2.0.3/spam-filter.toml
1b614bc004284116f6c98b5dfb2ce663872b5f60a0a8782c06ded9dcf3da2cd2  /proc/self/fd/11
  • Built on platform(s)
    • x86_64-linux
    • aarch64-linux
    • x86_64-darwin
    • aarch64-darwin
  • For non-Linux: Is sandboxing enabled in nix.conf? (See Nix manual)
    • sandbox = relaxed
    • sandbox = true
  • Tested, as applicable:
  • Tested compilation of all packages that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD". Note: all changes have to be committed, also see nixpkgs-review usage
  • Tested basic functionality of all binary files (usually in ./result/bin/)
  • Nixpkgs 25.11 Release Notes (or backporting 25.05 Nixpkgs Release notes)
    • (Package updates) Added a release notes entry if the change is major or breaking
  • NixOS 25.11 Release Notes (or backporting 25.05 NixOS Release notes)
    • (Module updates) Added a release notes entry if the change is significant
    • (Module addition) Added a release notes entry if adding a new NixOS module
  • Fits CONTRIBUTING.md, pkgs/README.md, maintainers/README.md and other contributing documentation in corresponding paths.

Add a 👍 reaction to pull requests you find important.

@norpol

norpol commented Jul 6, 2025 •

Copy link
Copy Markdown
Contributor Author

FYI: @diogotcorreia I've seen you've adjusted the spam-filter topic in #412054. I can't pin-point the exact commit, but stalwart isn't shipping the rules through the Rust build any longer.

(CC also @provokateurin)

@nixpkgs-ci nixpkgs-ci Bot added 6.topic: nixos Issues or PRs affecting NixOS modules, or package usability issues specific to NixOS 8.has: module (update) This PR changes an existing module in `nixos/` labels Jul 6, 2025

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not sure whether this is advisable, I don't know how stalwart is downloading the https:// URLs inside the file itself.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

stalwartlabs/stalwart#1770

I've asked a question in the discussion channel.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is already disabled by default, so explicitly setting it shouldn't make a difference. From https://stalw.art/docs/spamfilter/settings/general/#automatic-updates :

Stalwart can be configured to automatically update the spam-filter rules on startup. This feature is disabled by default and can be enabled by setting the spam-filter.auto-update key to true.

As for downloading the https:// URLs inside, I believe stalwart downloads them anyway. That setting seems to only affect this whether rules are reloaded on startup or not: https://github.com/stalwartlabs/stalwart/blob/b2f05254232a16873f260c527f327b9d3623b7f2/crates/common/src/manager/boot.rs#L413-L425

On a related note, it might make sense to set this option to true instead, so that it always refreshes the rules (and also the webadmin) from the specified files. Otherwise I think it only updates when a user clicks the button on the admin panel (?). I would like some input from nixpkgs stalwart maintainers on this one @happysalada @onny @oddlama @Pandapip1

Comment thread pkgs/by-name/st/stalwart-mail/spam-filter.nix Outdated
@nixpkgs-ci nixpkgs-ci Bot added 10.rebuild-linux: 1-10 This PR causes between 1 and 10 packages to rebuild on Linux. 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. labels Jul 6, 2025
@diogotcorreia

diogotcorreia commented Jul 6, 2025 •

Copy link
Copy Markdown
Member

@norpol Seems to have been changed in this commit upstream: stalwartlabs/stalwart@38fa029 (0.11.0)

@norpol
norpol force-pushed the fix_stalwart_spam-filter_missing branch from 96d1044 to 5c9b7d5 Compare July 6, 2025 11:12
@norpol

norpol commented Jul 6, 2025

Copy link
Copy Markdown
Contributor Author

This line only creates an empty directory now:

mkdir -p $out/etc/stalwart

Safe bet would be to keep it for compatibility reasons, but practically it shouldn't be needed any longer.

Comment thread pkgs/by-name/st/stalwart-mail/spam-filter.nix Outdated
Comment thread pkgs/by-name/st/stalwart-mail/spam-filter.nix Outdated
Comment thread pkgs/by-name/st/stalwart-mail/spam-filter.nix Outdated
@norpol
norpol force-pushed the fix_stalwart_spam-filter_missing branch from 7c4e533 to c3523d2 Compare July 6, 2025 12:09
Comment thread pkgs/by-name/st/stalwart-mail/spam-filter.nix Outdated

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is already disabled by default, so explicitly setting it shouldn't make a difference. From https://stalw.art/docs/spamfilter/settings/general/#automatic-updates :

Stalwart can be configured to automatically update the spam-filter rules on startup. This feature is disabled by default and can be enabled by setting the spam-filter.auto-update key to true.

As for downloading the https:// URLs inside, I believe stalwart downloads them anyway. That setting seems to only affect this whether rules are reloaded on startup or not: https://github.com/stalwartlabs/stalwart/blob/b2f05254232a16873f260c527f327b9d3623b7f2/crates/common/src/manager/boot.rs#L413-L425

On a related note, it might make sense to set this option to true instead, so that it always refreshes the rules (and also the webadmin) from the specified files. Otherwise I think it only updates when a user clicks the button on the admin panel (?). I would like some input from nixpkgs stalwart maintainers on this one @happysalada @onny @oddlama @Pandapip1

Comment thread pkgs/by-name/st/stalwart-mail/spam-filter.nix Outdated
Comment thread pkgs/by-name/st/stalwart-mail/package.nix Outdated
Comment thread pkgs/by-name/st/stalwart-mail/spam-filter.nix Outdated
@norpol
norpol force-pushed the fix_stalwart_spam-filter_missing branch 2 times, most recently from 2a2f76a to 8bfa972 Compare July 7, 2025 21:00
@nixpkgs-ci nixpkgs-ci Bot added 10.rebuild-darwin: 1-10 This PR causes between 1 and 10 packages to rebuild on Darwin. 10.rebuild-darwin: 1 This PR causes 1 package to rebuild on Darwin. and removed 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. labels Jul 7, 2025
@norpol
norpol force-pushed the fix_stalwart_spam-filter_missing branch from 8bfa972 to 51f8cf2 Compare July 7, 2025 21:20
@norpol
norpol marked this pull request as draft July 7, 2025 21:20
@norpol norpol changed the title stalwart-mail: Fix spam-filter missing from /etc stalwart-mail: Fix spam-filter missing from /etc and bump to v0.12.5 + webadmin v0.1.28 Jul 7, 2025
@nixpkgs-ci nixpkgs-ci Bot added the 8.has: maintainer-list (update) This PR changes `maintainers/maintainer-list.nix` label Jul 7, 2025
@diogotcorreia

diogotcorreia commented Jul 7, 2025 •

Copy link
Copy Markdown
Member

Any reason for including the update to 0.12.5 here instead of on a separate PR?
As for the enterprise feature problem, we should definitely not enable the feature by default, and should instead apply a patch with this commit: stalwartlabs/stalwart@861471f

Edit: there are already open PRs that would update those packages:

@nixpkgs-ci nixpkgs-ci Bot removed the 10.rebuild-darwin: 1 This PR causes 1 package to rebuild on Darwin. label Jul 7, 2025
@norpol
norpol force-pushed the fix_stalwart_spam-filter_missing branch 4 times, most recently from 6d578ba to e0c982c Compare July 7, 2025 21:54
@norpol

norpol commented Jul 7, 2025

Copy link
Copy Markdown
Contributor Author

@diogotcorreia Just wanted to give the build a try, since there is plenty of feedback on the current PR I've switched it back to a draft since I'd expect more rounds. From the GitHub PRs in general it's not uncommon that one PR is addressing multiple things - although that makes back-porting sometimes harder. Just added the .patch with the upstream fix to see how it goes.

@diogotcorreia diogotcorreia left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A few more nitpicks:

  • add "Closes " for both the existing PRs that update stalwart (make sure to add "Closes" before both, otherwise they won't be closed)
  • you probably should squash some of the commits (e.g., the ones fixing the spam-filter package should just be merged into the first some)
  • the commit adding yourself to maintainer-list.nix should come first

Otherwise, LGTM I think

Comment thread pkgs/by-name/st/stalwart-mail/spam-filter.nix Outdated
Comment thread pkgs/by-name/st/stalwart-mail/webadmin.nix Outdated
Comment thread pkgs/by-name/st/stalwart-mail/package.nix Outdated
@nixpkgs-ci nixpkgs-ci Bot added the 2.status: merge conflict This PR has merge conflicts with the target branch label Jul 10, 2025
@norpol
norpol force-pushed the fix_stalwart_spam-filter_missing branch 2 times, most recently from a58ced8 to 0d57c7f Compare July 10, 2025 21:44
@ofborg ofborg Bot removed the 2.status: merge conflict This PR has merge conflicts with the target branch label Jul 10, 2025
@norpol

norpol commented Jul 10, 2025 •

Copy link
Copy Markdown
Contributor Author

Hey @diogotcorreia I've rebased and incoroporated your suggestions.

@norpol
norpol marked this pull request as ready for review July 10, 2025 21:52
@norpol
norpol force-pushed the fix_stalwart_spam-filter_missing branch from 0d57c7f to f64d755 Compare July 10, 2025 21:54
@norpol norpol changed the title stalwart-mail: Fix spam-filter missing from /etc and bump to v0.12.5 + webadmin v0.1.28 stalwart-mail: Fix spam-filter missing from /etc and bump + patch mail from v0.12.4 to v0.12.5 Jul 10, 2025
@norpol
norpol force-pushed the fix_stalwart_spam-filter_missing branch 2 times, most recently from 21a84a3 to c469e0e Compare July 10, 2025 22:04
@norpol norpol changed the title stalwart-mail: Fix spam-filter missing from /etc and bump + patch mail from v0.12.4 to v0.12.5 stalwart-mail: Fix spam-filter missing from /etc Jul 10, 2025
@norpol
norpol force-pushed the fix_stalwart_spam-filter_missing branch from c469e0e to c8bd8fc Compare July 11, 2025 09:51
@nixpkgs-ci nixpkgs-ci Bot added the 10.rebuild-darwin: 1 This PR causes 1 package to rebuild on Darwin. label Jul 11, 2025

@diogotcorreia diogotcorreia left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry it took so long, I was busy for the past few days
LGTM!

@nixpkgs-ci nixpkgs-ci Bot added the 12.approvals: 1 This PR was reviewed and approved by one person. label Jul 15, 2025
@norpol

norpol commented Jul 15, 2025

Copy link
Copy Markdown
Contributor Author

Thanks @diogotcorreia. I've created a separate PR for #425489 in the meanwhile.

@norpol

norpol commented Jul 17, 2025

Copy link
Copy Markdown
Contributor Author

There was a reply concerning asn.urls, file:/// URLs are supported, so technically if people prefer that they can also use nix to pull the ASN IPs. As these are not under free licenses usually, we of course put them into the default package.
Maybe I'll add in a follow up PR the option for people to use file:/// links inside the filter list that is shipped by nix, but I think for this PR we are good as is (as it's only repairing the previous state)

stalwartlabs/stalwart#1770 (comment)

@happysalada
happysalada merged commit 1f9fe92 into NixOS:master Jul 22, 2025
3 of 4 checks passed
@norpol
norpol deleted the fix_stalwart_spam-filter_missing branch July 27, 2025 16:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

6.topic: nixos Issues or PRs affecting NixOS modules, or package usability issues specific to NixOS 8.has: maintainer-list (update) This PR changes `maintainers/maintainer-list.nix` 8.has: module (update) This PR changes an existing module in `nixos/` 10.rebuild-darwin: 1-10 This PR causes between 1 and 10 packages to rebuild on Darwin. 10.rebuild-darwin: 1 This PR causes 1 package to rebuild on Darwin. 10.rebuild-linux: 1-10 This PR causes between 1 and 10 packages to rebuild on Linux. 12.approvals: 1 This PR was reviewed and approved by one person.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants