Files
openmail/docs/adr/0003-own-crates.md
Karti TripathiandClaude Opus 5 36b15ddcaf Rewrite as a Rust, Apache-2.0 workspace
Supersedes the Go + embed-Mox design. The Go tree is removed; its
architecture doc is preserved at docs/archive/ARCHITECTURE-go-embed-mox.md
because its competitive analysis and data model still hold.

Five decisions recorded as ADRs:

  0001  Rust, not Go — accepting ~5,500 lines of protocol code that Mox
        would have given us free, to get the first permissively licensed
        Rust mail server. Costs stated plainly.
  0002  Apache-2.0, not MIT or AGPL — patent grant, trademark, CLA-free
        contribution. Public on GitHub; Gitea stays as the private fallback.
  0003  Stalwart's primitive crates (Apache-2.0/MIT) yes; its AGPL server
        crates never. DANE and MTA-STS sit on the AGPL side of that line,
        which is why we write our own.
  0004  Milestones, reordered: embedded inbound is required at launch.
  0005  Oracle Cloud blocks outbound :25, so direct-to-MX is impossible on
        the launch host. Split delivery is mandatory, not an on-ramp.

Twelve crates in three tiers. Tier 1 (mail-dane, mail-mta-sts, mail-dsn)
is standalone and publishable — no `dane` or `mta-sts` crate exists on
crates.io at all today.

openmail-relay ships the provider table as data, with SES and Oracle from
the start. Oracle's and Resend's SPF includes are deliberately None: a
guessed include turns the DNS check green against a mechanism the provider
does not honour, and mail still fails SPF silently.

cargo check/test/clippy/fmt all green; unsafe_code is forbidden workspace
wide; cargo-deny enforces the licence policy in CI.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JkyvfNJGTshJNE9FtwPLk7
2026-09-02 13:08:05 -07:00

1.5 KiB

ADR 0003 — Write our own crates; use Stalwart's primitives, never its server

Status: Accepted, 2026-09-02.

The licence boundary

Stalwart Labs ships two distinct things:

Licence Us
The server (stalwartlabs/stalwart, crates/*) AGPL-3.0-only OR LicenseRef-SEL never
The primitives (mail-parser, mail-auth, mail-builder, mail-send, smtp-proto) Apache-2.0 OR MIT dependencies

DANE and MTA-STS live in crates/smtp and crates/commonon the AGPL side of that line. That is precisely why we write our own.

Rule

  • Depending on the permissive primitive crates is fine and intended.
  • Reading the AGPL server crates for understanding is fine.
  • Copying, adapting or transliterating any line from them is not, and would contaminate the whole workspace. When implementing DANE or MTA-STS, work from the RFCs (7672, 8461, 6698) — not from stalwart/crates/smtp.
  • The research mirror at ~/Desktop/ProjectMail/mail-servers/stalwart is read-only reference. Same for maddy (GPL-3) and BillionMail (AGPL).

Which of our crates get published

Tier 1 (mail-dane, mail-mta-sts, mail-dsn) are published standalone: they depend on nothing in this workspace, they fill real holes in the ecosystem, and their value to us is partly that other projects audit them. Names verified available on crates.io 2026-09-02, as is openmail itself — reserve early.

Tier 2 and 3 stay in-workspace until their APIs settle.