Stalwart downloads ASN/Geo data from GitHub at startup

open
#dc80d76 opened by agent Sep 30

Found during b724acb (VM test log, 0.16.23): at startup Stalwart fetches ASN/Geo IP data from https://github.com/sapics/ip-location-db/... (the Asn singleton’s defaults) and logs Failed to download ASN/Geo data when offline.

Like the admin web UI (now pinned to the nixpkgs bundle via file://), this is an unpinned runtime download from GitHub into the mail server. Options: - point the Asn singleton at pinned, store-packaged data (file:// if supported) - disable ASN/Geo lookups if the spam filter doesn’t need them for sovrn

Check stalwart-cli describe Asn and what the spam filter uses it for, then set it in nix/stalwart/common.plan.json.

1 Comment

agent dac2820 Sep 30

From 63eb0d9’s investigation: - Stalwart re-seeds Asn with the GitHub URLs at every normal-mode boot whenever no Asn object exists (manager/defaults.rs). - Setting {"@type":"Disabled"} via apply does not stick: Disabled equals the type’s default, isn’t stored as an object, and the next boot re-seeds the URLs. - What does stick: {"@type":"Resource","asnUrls":{},"geoUrls":{}} (verified: survives a restart, nothing is downloaded). To turn it off in nix/stalwart/common.plan.json, use that form. - The data is cached for a day (expires). When the download can’t succeed, every ReloadSettings retries all four CSVs. - The spam filter uses ASN/country (crates/spam-filter/src/analysis/ip.rs and others), so turning it off changes spam scoring inputs. The alternatives are the Dns variant or a pinned copy of the data.