gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit84e1b3e184e1b3e1tracker: reports 025 + 026mre84e1b3e1/plugins/smtp/README.md

5.6 KB

  1. # `hl:smtp` — sending mail
  2. An SMTP **submission client**. Server realm. Mission 137.
  3. ```hybriel
  4. import { Mailer } from 'hl:smtp'
  5. m = new Mailer("mail.example.com", 587, {
  6. user = "[email protected]"
  7. pass = "…"
  8. "from" = "[email protected]"
  9. })
  10. m.send({ to = "[email protected]"; subject = "Hello"; text = "Hi there" })
  11. for (r of m.results()) {
  12. console.log(r.ok + " " + r.code + " " + r.message)
  13. }
  14. ```
  15. ## `new Mailer(host, port, options)`
  16. `host` / `port` / `options` are the first three declared properties, so the
  17. positional form above reads as written (SPEC.md "The file root is the
  18. constructor").
  19. | option | default | meaning |
  20. |---|---|---|
  21. | `"from"` / `sender` | — | the envelope sender and the `From:` header. A mailer without one constructs; a `send()` whose message names no sender either is refused at that call. |
  22. | `user` / `pass` | — | credentials; absent = no AUTH at all |
  23. | `tls` | `"starttls"` | `"starttls"` · `"implicit"` (SMTPS, port 465) · `"none"` |
  24. | `auth` | `"auto"` | `"auto"` (PLAIN unless only LOGIN is offered) · `"plain"` · `"login"` · `"none"` |
  25. | `caFile` | — | an EXTRA trust anchor beside the system store — a private CA, or a test fixture's certificate |
  26. | `verify` | `true` | peer chain + hostname. `false` is an explicit opt-out and is logged at every handshake |
  27. | `allowInsecureAuth` | `false` | permit AUTH on a connection that never became TLS |
  28. | `timeout` | `30000` | milliseconds, bounding the connect and every read/write |
  29. | `helo` | `"localhost"` | the EHLO name and the `Message-ID` domain |
  30. **`from` is a reserved word** in Hybriel (`import X from './x.hl'`), so the key
  31. is written quoted — `"from" = …`. `sender` is the same field under a bare
  32. identifier; use whichever reads better.
  33. ## `m.send(message)` — non-blocking
  34. | key | meaning |
  35. |---|---|
  36. | `to` | one address, or a list of them — ONE message, several `RCPT TO` |
  37. | `subject` | ASCII passes through; anything else becomes an RFC 2047 encoded-word |
  38. | `text` | the `text/plain` part |
  39. | `html` | the `text/html` part; with both, a `multipart/alternative` body |
  40. | `"from"` / `sender` | overrides the mailer's sender for this message |
  41. Returns a **job id**. The conversation runs on the mailer's own worker thread
  42. and the answer arrives later.
  43. Everything that can fail LOCALLY is decided before the job leaves — on the
  44. caller's thread, so it is a **located error at the caller's line**, catchable via
  45. `on Error(e)` like any other plugin failure:
  46. * a CR or LF in `to`, `"from"` or `subject` — **header injection is refused, never
  47. stripped and never escaped.** `subject = "hi\r\nBcc: everyone@…"` is how a
  48. contact form becomes an open relay; silently dropping the bytes would deliver a
  49. message the author did not write.
  50. * an address carrying `<`, `>` or whitespace, or no `@` at all
  51. * an empty recipient list, a message with neither `text` nor `html`
  52. ## The result
  53. `m.results()` is the mailer's ONE result source. Drain it (`for (r of
  54. m.results())`, which ENDS when every accepted send has been answered — that is
  55. what lets a mail-only script terminate), or hand it to the event loop with
  56. `m.deliver()` and handle `on m.sent(r)` / `on m.failed(r)`. Use one or the other:
  57. they take from the same queue, and asking for both is a refusal.
  58. ```
  59. { id, ok, code, stage, message, secure, to }
  60. ```
  61. `stage` names the step that answered: `connect`, `greeting`, `ehlo`, `starttls`,
  62. `auth`, `mail`, `rcpt`, `data`, `body`, `done`. `secure` says whether the message
  63. was written inside TLS. A server's own refusal text arrives in `message`
  64. verbatim.
  65. `m.pending()` is how many sends have not been answered; `m.close()` stops the
  66. worker (a job already in conversation finishes — abandoning a socket between
  67. `DATA` and its `250` is how a message gets delivered twice).
  68. ## What it does on the wire
  69. `EHLO` · optional `STARTTLS` + a re-issued `EHLO` inside TLS (RFC 3207 §4.2 —
  70. capabilities learned in the clear are discarded) · `AUTH PLAIN` (RFC 4616) or
  71. `AUTH LOGIN` · `MAIL FROM` · one `RCPT TO` per recipient (a rejected recipient
  72. fails the whole send) · `DATA` · the message · `QUIT`.
  73. CRLF discipline and **dot-stuffing** (RFC 5321 §4.5.2) are applied to the whole
  74. payload: a body line beginning with `.` is sent as `..`, or it truncates the
  75. mail. Headers written: `From`, `To`, `Subject`, `Date`, `Message-ID`,
  76. `MIME-Version`, `Content-Type`, `Content-Transfer-Encoding: 8bit`.
  77. ## TLS
  78. There is **no TLS implementation in this plugin.** It calls the client half of
  79. `plugins/http/tls_common.zig` — the same dlopen'd OpenSSL the HTTP servers use
  80. (mission 121, extended in 137). `native/test_smtp.sh` carries the grep gate that
  81. keeps it that way.
  82. ## Not in scope
  83. * **Receiving** (IMAP/POP) — a different protocol and a different plugin.
  84. * **DKIM signing** — later. It needs a key store and a canonicalisation pass over
  85. the rendered message; the rendering seam is `renderMessage` in `smtp.zig` and
  86. the signature would be one more header written there.
  87. * **Queuing and retry** — the app's business. A `4xx` result is a retryable one
  88. and the app knows what its retry policy is; a library that retried on its own
  89. would send twice the moment the app also did.
  90. * **`cc` / `bcc` headers, attachments** — not written. Extra recipients go in
  91. `to`; an attachment needs a `multipart/mixed` builder that does not exist yet.
  92. ## Tests
  93. `bash native/test_smtp.sh` (61 checks). The only peer is
  94. `tests/native/plugins/045_smtp_fixture.js`, a local fixture that asserts the
  95. exact wire; **no test in this repo ever contacts a real mail server.** Ports come
  96. from `HL_SMTP_PORT_BASE` (default 14700) and the harness moves itself rather than
  97. touching a listener it did not start.

Branches

Latest commits

  • 84e1b3e1tracker: reports 025 + 026mre
  • dc40d859tracker#31 (mission 026): duplicate titles merged — the 68 type+tmdbId pairs held by 157 records were the old tracker's (all migrated); merge.hl repair job (own clock, before the TMDB jobs) keeps one keeper per title (follows/watches > old short id > oldest), moves follows, watches, seasons, cast, credits, timelines, tombstones the rest (mergedInto, never deleted), slugs + short ids 301 to the keeper; stray seasons merged into their listed twin (Reacher S3 watches) or linked when watched; search import re-checks before its put; deploy.sh waits up to 90 s for 200; real copy 68 -> 0 dup ids, az5b2 follows/watches equal; gates 342/0, 32/0, 52/0mre
  • 2667da05tracker#30 (mission 025): /my/ pages from slim cached title cards, episode rows and watch sets (after the jobs /my/series 1.8 s -> 0.06 s, /my/unwatched 4.1 -> 0.18 s); timeline page shows its name once; franchise widget under the poster/title; movies with TV leftovers (First Contact) go through the details repair; tools/count-tmdb-ids.hl; gates 327/0, 52/0, 32/0mre
  • 3909810dantcolony#40: mission references in README/STATUS/docs point to the moved missionsmre
  • e63b1d28antcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • 1cda451dtracker: Hybriel master 190aa11d (#127 both shapes, GC correctness fc838894) — conductor adopts despite /my/series 2.4x after jobs (memory 8.0 → 1.7 GB boot); see reports/071mre
  • c1fa2f2etracker (mission 071): Hybriel master 190aa11d measured on the real copy vs the live binary 8590df63 — NOT adopted (after the first-start jobs /my/series 2.4x slower, /series 1.6x, RSS swings 7.4-12.2 GB; fresh it is flat at 1.7-2.2 GB and /my/unwatched faster), vendor stays 8efba065, candidate kept in .scratch/w071/vendor-190aa11d; tests/kinds.mjs: collection seed off (its TMDB request broke check 1 in 1 of 4 runs); tests/realdata-071.sh + realdata-071-bench.mjs + tools/realdata-071-table.py; README + STATUS (numbers, how to repeat); gates 325/0, 32/0, 50/0mre
  • 8081350atracker docs (mission 070): README (summary, Config HL_GC_BYTES — kept at Hybriel's default, the 256 MiB setting is taken out of docker-compose.yml again: the jobs grew to 12+ GB with it too, see STATUS), Test (three gates), Deploy (first start ~50 min: kinds then seed, restart once after collections done, memory numbers), Vendored Hybriel 8efba065 + #48 audit, Files; STATUS mission 070 entry (merges, migrated counts, lambda audit, gates, RSS old vs new, how to repeat, open points); docs/kinds.md + docs/franchises.md job order; tests/realdata-070-*.sh, tools/count-migrated.hl, tools/ref-params.py, tools/lambda-audit.pymre
  • 1ad19c8ctracker: re-vendor Hybriel master 8efba065 (#126 GC by bytes, #48 lambda parameters copy) (mission 070): bin/hybriel sha256 50361e95…, plugins core crypto data fetch fs http http1 mpackdb proc smtp time web; lambda audit: 13 lambdas change a passed record/list (11 through a local alias), no caller relies on it — unchanged; 319 read-only lambda parameters get & (no copy per call: /my/schedule 2.35 → 0.46 s, /my/unwatched 13.7 → 5.7 s on the real copy); /my/unwatched one merge sort instead of n² inserts; docker-compose HL_GC_BYTES=268435456; deploy.sh runs kinds.mjs + franchises.mjs too (default ports 8700–8710); tests/realdata-070.mjs; gates browser 325/0, kinds 32/0, franchises 50/0mre
  • 46b21389tracker (mission 070, conductor): the sync never destroys migrated data — the one-time summary step MOVES a copied summary to migratedSummary (marker summaries-moved.txt) instead of clearing it; a migrated record's first title/genres/homepage/tagline TMDB replaces → migratedTitle/migratedGenres/migratedHomepage/migratedTagline, a migrated season's/episode's title/summary → migratedTitle/migratedSummary (set once); tests/peek-shows.hl prints them; gate 325/0mre
  • 749019b0Merge t19 (tracker#19 franchises + timelines) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/browser.mjs/faketmdb.mjs, both sides kept; franchise/timeline pages get #20's typed heading (Franchise | …, Timeline | …), their title links via titlePath (/movies|/series|/shows); the collection seed waits for repair, kinds and credits too; franchises.mjs URLs + 2 new checks; gates browser 323/0, kinds 32/0, franchises 50/0mre
  • daf49feaMerge t20 (tracker#20 typed headings + #21 series/shows split) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/search.hl/components/search.hl/browser.mjs/faketmdb.mjs, both sides kept; clock order backfill → repair → kinds → credits; withDetailsFields stores tmdbType + kind; gates: browser.mjs URLs → /series|/movies, typed h1 selectors; kinds.mjs repair/credits off, fixture name = seed name; browser 323/0, kinds 32/0mre
  • 20e09d89Merge t18 (tracker#18 delta sync) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/browser.mjs, both sides kept; pageShowOf summary = summaryOfmre
  • f83571c3tracker#18 (mission 067): daily sync by change lists — TMDB /tv|movie/changes (since the stored day, paged) + TVmaze /updates/shows → only our changed titles (followed: full step, unfollowed: light step — changed seasons, no TVmaze), full walk on first run / gap > 14 days / failed list; show record refreshed (title, tmdbSummary, tagline, status, genres …; renamed titles re-indexed); summary = the creator's own text (page: summary > tmdbSummary > tvmazeSummary), one-time clear of copied summaries (9,647 on the live copy); gate 261, tests/realdata-018*.mjs, README + STATUSmre
  • 1ed5457etracker#20 + #21 (mission 068): typed headings "<Type> | <name>" in type colours; TV titles split into Series (/series) and Shows (/shows) by TMDB type + Reality/Talk/News genres — kind stored by sync/import/adult backfill + new kind backfill (resumes), /movies/<slug>, /shows/<slug> of a series/movie → 301, /my/series + /my/shows, home 5 tiles + 3 rows, search/filmography labels; gates kinds 32 + browser 266, tests/realdata-068.mjs, tools/count-kinds.hl, docs/kinds.md, README + STATUSmre
  • f2b00674Merge t26 (tracker#26 + #28) into main (mission 062): short ids for every new person (castPersonId, guest route), guest stars stored on the title and created as people only when opened (/person/tmdb/<id>?show=<id> → 302), lean watch/follow clicks (showRow a small object, cast/crew from the slug, watches cached per user, face rows only after a season toggle); gate 311, tests/realdata-062.mjs, README + STATUSmre
  • 0553b51ftracker#19 (mission 066): franchises and timelines — tables, /franchises, /franchises/<slug>, /timelines/<slug> (Timeline | Release sort, series by last episode), the Prequel | Timeline | Sequel widget with the franchise above, the creator's editor, TMDB collection seed in the app (resumes, paced); gate tests/franchises.mjs 48/0 + browser.mjs 266/0, tests/realdata-066.mjs, docs/franchises.md, README + STATUSmre
  • fa1f9dfatracker#29 (mission 063): unwatched check muted grey outline + check (accent only on hover), watched stays solid — no code regression, the accent outline read as ticked; gate checks real checks visibly (computed style + screenshot pixel) on /my/unwatched, show, movie, /my/movies; gate 266, tests/realdata-063.mjs, README + STATUSmre
  • 10bb3f93tracker#28 (mission 061): full cast (all seasons, main cast by episodes, guest stars) + crew (created by, directed by, written by, screenplay, story, music) — stored by the details completion, the daily sync, the search import (one details request) and a background credits job (resumes, RSS limit); show page collapsed after 20 with client-side Show all; showBySlug via a slug map; gate 249, tests/realdata-028.mjs, README + STATUSmre
  • d8b12d67tracker#27 (mission 060): short ids for movies, series and persons — old 702 kept (data/old-short-ids.json), new random [a-z0-9]{5} unique across both, claimed at creation, background backfill (resumes), shown under poster/photo, /<shortId> → 301; gate 259, tests/realdata-060*, README + STATUSmre