New version of POP3 and IMAP4 server Dovecot 2.3.21

A new version of the multi-platform high-performance POP3/IMAP4 server Dovecot 2.3.21 has been released, supporting the POP3 and IMAP4rev1 protocols with popular extensions such as SORT, THREAD, and IDLE, along with authentication and encryption mechanisms (SASL, TLS, SCRAM). Dovecot maintains full compatibility with classic mbox and Maildir by applying external indexes to enhance performance. Plugins can be used to extend functionality (for example, quotas and ACLs are implemented through plugins). The project's code is distributed under LGPL and MIT licenses.

Key Changes:

  • lib-oauth2: JWT token verification has been enabled without the 'typ' field. The 'typ' field is not used by some key issuers to save space, particularly in Kubernetes. Now its absence is allowed, but if it is present, it must still be 'jwt'.
  • auth: The 'Auth' response from passdb and userdb may contain the value 'event_=value', which will be added to the login event and mail user event, respectively.
  • lib-master: It sets the process header at various initialization stages to clarify what the process expects.
  • lib-storage: The mail_temp_scan_interval is now increased by 0...30% depending on the user name hash to reduce the likelihood of load spikes.
  • lib-storage: Scanning of the temporary file has been moved from the moment the mailbox is opened to when it is closed, to reduce the latency experienced by users.
  • stats: If the metric specifies fields, all these fields are exported as counters for Prometheus in the exposition format.
  • "*-login": Processes could crash on improper SSL connection termination. — acl: The flags \\HasChildren and \\HasNoChildren were incorrectly calculated for mailboxes containing '*' and '%' in their names when loading the plugin.
  • auth: A failure occurred when attempting to connect to the PostgreSQL DBMS during startup.
  • auth: When logging in with incorrect passwords (for example, with an unknown scheme), the passdb reported a 'password mismatch' error instead of an 'internal error'.
  • auth: The XOAUTH2 and OAUTHBEARER mechanisms did not provide a protocol-specific error message for any errors. This particularly hindered OIDC detection.
  • dbox: If the last_temp_file_scan header was not set (especially after a dsync migration), the temporary files scan would always run upon the next mailbox opening. This could cause a spike in load after migrations. Fixed by using the mailbox directory's atime in the absence of the header, which typically shifts the scan time into the future.
  • dict-redis: A failure occurred during transaction rollbacks.
  • dsync: When deleting a mailbox on the remote end, if the hierarchy level delimiters did not match, an infinite loop occurred that led to an out-of-memory error.
  • dsync: Incremental dsync was not performed for folder names ending with '%' unless the BROKENCHAR value was set. Additionally, folder names with '%' in other places caused unnecessary renaming of the folder to a temporary name and back during each incremental dsync. Regression in v2.3.19.
  • imap-hibernate: If there was a timeout with the message "(version received)" when unlocking the IMAP client, the unlocking could later succeed and continue normal operation. This caused confusion as imap-hibernate had already recorded that the client had disconnected. This can be avoided by forcing the connection to time out upon hibernation completion.
  • imapc: Crash when a folder displayed through a virtual plugin disappeared from the storage.
  • imapc: Responses EXPUNGE, EXISTS, or FETCH with server could be processed as if they belonged to the newly selected mailbox. This could lead to warnings.
  • lib-http: The Dovecot HTTP server (doveadm, stats/openmetrics) could disconnect HTTP clients before fully sending the response. This only happened on heavily loaded servers where the kernel socket buffers were significantly overfilled.
  • lib-http: Fixed a potential crash of the HTTP server in case of an early client disconnection. Regression in 2.3.18.
  • lib-index: Corruption of the index file could lead to a crash. Resolved: Panic: file mail-transaction-log-view.c: line 165 (mail_transaction_log_view_set): assertion failed: (min_file_seq <= max_file_seq).
  • lib-index: Clearing an existing cache file larger than 1 GB could cause a crash. Now, after clearing the cache, any cache files exceeding 1 GB are removed. Fixed: Panic: file mail-index-util.c: line 10 (mail_index_uint32_to_offset): assertion failed: (offset < 0x40000000).
  • lib-lua: The HTTP client could not resolve DNS names in mail processes because it expected the 'dns-client' socket to be in the current directory.
  • lib-oauth2: Dovecot sent client_id and client_secret as POST parameters to the introspection server. However, when using Basic auth, their usage is optional.
  • lib-oauth2: Validation of JWT 'aud' was not performed if 'aud' was absent in the token but configured in Dovecot.
  • lib-oauth2: Too strict checking of the JWT key type.
  • lib-oauth2: The audience of the JWT token was not checked against client_id as specified.
  • lib-ssl-iostream: Using the parameter ssl_require_crl=yes could lead to failures in CRL checking for outgoing SSL/TLS connections, although it was intended to affect CRL checking only for clients. SSL certificates. v2.3.17 regression.
  • lib-sql: The MySQL driver allowed memory leaks on failed connections.
  • lib-storage: Various fixes for low disk space issues.
  • master: The idle_kill service configuration was not functioning properly on busy servers. It was highly unlikely that any process would idle long enough to be killed. Additionally, with a large number of processes (e.g., imap), the idle_kill handling code used significant CPU on the main process. Now, each idle_kill time interval will track the least number of idling processes and then kill that number.
  • mdbox: Temporary file checks were performed for always empty directories.
  • mdbox: When writing emails, the fdatasync() call was executed in the wrong parent directory. This also caused a crash instead of logging an error.
  • notify_status: The plugin crashes on failed user initialization. — pop3: Sending a command with the ':' character led to an 'assert-crash'. Regression in release 2.3.18.
  • stats: Fixed a panic occurring when accessing a non-existent event exporter while dynamically adding a new metric using the 'doveadm stats add' command. Now a correct error is returned.
  • stats: If the process exported many events and then ended, some of the last events may have been lost.
  • stats: Incorrect Prometheus label names were created under certain histogram group_by configurations. Prometheus rejected these labels.
  • welcome: The plugin did not execute in certain situations when the INBOX was created but not opened, for instance, if GETMETADATA was used before opening the INBOX.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster