mirror of
https://github.com/profullstack/agentbbs.git
synced 2026-10-01 19:43:49 +00:00
fix(mail): unbreak join@ registration when the Mailu cert lapses (#129)
Registration has been dead since 2026-09-13. `ssh join@bbs.profullstack.com` creates the account, then fails at the confirmation step with "couldn't email the code" and disconnects, so nobody can finish signing up. Cause: Caddy owns ACME for mail.profullstack.com and renewed on 2026-08-14 (valid to Nov 12), but Mailu went on serving the certificate it loaded at container start (Jun 15 -> Sep 13). When that lapsed, the STARTTLS handshake from internal/mail started failing verification and every transactional send died with it -- confirmation codes, signup notifications, credential mail. Reproduced against production; 25/465/993 all still present the expired cert while :443 serves the renewed one. Three things let a single stale certificate take registration down: - setup.sh installed the refresher and enabled its *timer*, but never ran it. `systemctl enable --now <timer>` starts the timer, not the service, so a redeploy left a stale cert in place (and did nothing at all if the timer was never scheduled). The news and IRC sections already run theirs at provision time; the Mailu section now does too, which is what repairs the live host. - refresh-certs.sh only compared files, so a copy whose reload silently failed left a fresh cert on disk and an expiring one on the wire -- invisible. It now reads back what the relay actually serves, forces a reload when that disagrees with /certs, refuses to copy a source cert that is itself expired, and no longer swallows the `docker compose restart` failure. It restarts `front` alone, the only container that mounts ./certs. - internal/mail verified the relay's certificate even on loopback, where there is nothing to intercept. It now skips verification for a loopback relay (the reasoning docs/mail.md already applies to the plaintext Dovecot hand-off) and gains AGENTBBS_SMTP_SERVERNAME, mirroring AGENTBBS_MAIL_SMTP_SERVERNAME, so the documented 127.0.0.1:25 config can verify against the mail host instead of an IP literal. A non-loopback relay is still verified. Errors are wrapped with the address and the failing stage so the next failure is one journal line to diagnose rather than nine days of silence. Tests cover the envelope, the unreachable-relay message, and both halves of the TLS decision: a loopback relay with an expired cert delivers, a non-loopback one with the same cert is refused. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
af47cab5e4
commit
249a4e669b
6 changed files with 520 additions and 30 deletions
11
setup.sh
11
setup.sh
|
|
@ -1243,6 +1243,11 @@ if [ "$MAIL_STACK" = "1" ]; then
|
|||
# (its cert is for ${MAIL_DOMAIN}, never 127.0.0.1) — no /etc/hosts hack needed.
|
||||
upsert_env AGENTBBS_MAIL_SMTP_SERVERNAME "${MAIL_DOMAIN}"
|
||||
|
||||
# The transactional sender (join@ confirmation codes, notify-creds) verifies
|
||||
# the relay's STARTTLS cert against the mail host. When it dials the co-located
|
||||
# relay on loopback there is no name to verify against, so hand it one.
|
||||
upsert_env AGENTBBS_SMTP_SERVERNAME "${MAIL_DOMAIN}"
|
||||
|
||||
# Cert refresher: copy Caddy's mail cert into Mailu on renewal (like news/IRC).
|
||||
install -m 0755 "${MAILU_DIR}/refresh-certs.sh" /usr/local/bin/agentbbs-mailu-certs
|
||||
cat > /etc/systemd/system/agentbbs-mailu-certs.service <<UNIT
|
||||
|
|
@ -1270,6 +1275,12 @@ WantedBy=timers.target
|
|||
UNIT
|
||||
systemctl daemon-reload
|
||||
systemctl enable --now agentbbs-mailu-certs.timer >/dev/null 2>&1 || true
|
||||
# `enable --now` starts the TIMER, not the service, so a redeploy would
|
||||
# otherwise leave a stale cert in place until the next tick (and do nothing at
|
||||
# all if the timer was never scheduled). Run the refresher now, like the news
|
||||
# and IRC sections do -- this is the step that repairs an expired mail cert.
|
||||
DOMAIN="${DOMAIN#*.}" MAIL_HOST="${MAIL_DOMAIN}" MAILU_DIR="${MAILU_DIR}" \
|
||||
/usr/local/bin/agentbbs-mailu-certs || warn "mailu: cert refresh failed — mail TLS may be stale (see: journalctl -u agentbbs-mailu-certs)"
|
||||
|
||||
# Open the mail ports; bring Mailu up only once the operator has created
|
||||
# mailu.env (it carries SECRET_KEY + admin password — never auto-generated).
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue