Commit Graph
3 Commits
Author SHA1 Message Date
Karti TripathiandClaude Opus 5 7fba0ab0c3 CI: run every job on spark-1; drop rust-cache
Two failures, two causes.

GitHub-hosted jobs never started: 'recent account payments have failed or
your spending limit needs to be increased'. Not a config problem. Public
repos get hosted runners free, so this may resolve itself; meanwhile every
job runs on spark-1, which is also the deployment architecture (Oracle
Ampere A1 is aarch64), so this is an improvement rather than a workaround.

The aarch64 job failed with exit 127 — cargo not found — and kept failing
after each fix. Cause: Swatinem/rust-cache's post-step prunes ~/.cargo.
That is correct on a GitHub-hosted runner where ~/.cargo is disposable, and
destructive on a self-hosted one where it is the real toolchain. It deleted
~/.cargo/bin/rustup after the first successful run, leaving every shim a
dangling symlink. The action is removed and the toolchain moved to
/opt/rust, wired through the runner's .env and .path, so it is out of reach
even if someone re-adds it. Caching bought nothing here anyway — the runner
keeps its target dir between runs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JkyvfNJGTshJNE9FtwPLk7
2026-09-02 13:53:50 -07:00
Karti TripathiandClaude Opus 5 037e87bc60 Wire CI: match runner label case, commit Cargo.lock
The aarch64 job targets the spark-1 self-hosted runner, whose labels are
registered as 'Linux' not 'linux'. Cargo.lock is committed because the
Dockerfile builds with --locked and a lockfile-free reproducible build is
not reproducible.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JkyvfNJGTshJNE9FtwPLk7
2026-09-02 13:41:01 -07:00
Karti TripathiandClaude Opus 5 36b15ddcaf Rewrite as a Rust, Apache-2.0 workspace
Supersedes the Go + embed-Mox design. The Go tree is removed; its
architecture doc is preserved at docs/archive/ARCHITECTURE-go-embed-mox.md
because its competitive analysis and data model still hold.

Five decisions recorded as ADRs:

  0001  Rust, not Go — accepting ~5,500 lines of protocol code that Mox
        would have given us free, to get the first permissively licensed
        Rust mail server. Costs stated plainly.
  0002  Apache-2.0, not MIT or AGPL — patent grant, trademark, CLA-free
        contribution. Public on GitHub; Gitea stays as the private fallback.
  0003  Stalwart's primitive crates (Apache-2.0/MIT) yes; its AGPL server
        crates never. DANE and MTA-STS sit on the AGPL side of that line,
        which is why we write our own.
  0004  Milestones, reordered: embedded inbound is required at launch.
  0005  Oracle Cloud blocks outbound :25, so direct-to-MX is impossible on
        the launch host. Split delivery is mandatory, not an on-ramp.

Twelve crates in three tiers. Tier 1 (mail-dane, mail-mta-sts, mail-dsn)
is standalone and publishable — no `dane` or `mta-sts` crate exists on
crates.io at all today.

openmail-relay ships the provider table as data, with SES and Oracle from
the start. Oracle's and Resend's SPF includes are deliberately None: a
guessed include turns the DNS check green against a mechanism the provider
does not honour, and mail still fails SPF silently.

cargo check/test/clippy/fmt all green; unsafe_code is forbidden workspace
wide; cargo-deny enforces the licence policy in CI.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JkyvfNJGTshJNE9FtwPLk7
2026-09-02 13:08:05 -07:00