Skip to content

zcore: build user EntryIDs from the whole address - #344

Open
ximalin wants to merge 1 commit into
grommunio:primefrom
ximalin:zcore-essdn-full-address
Open

ximalin wants to merge 1 commit into
grommunio:primefrom
ximalin:zcore-essdn-full-address

Conversation

@ximalin

@ximalin ximalin commented Sep 10, 2026 •

Copy link
Copy Markdown

zcore mints ESSDN EntryIDs that gromox itself cannot resolve back. Measured with cvt_username_to_essdn() followed by cvt_essdn_to_username():

input ESSDN resolves back to
sender@example.org .../cn=2200000011000000-sender sender@example.org
sender -- what the caller passes .../cn=2200000011000000-public.folder.root ecUnknownUser

Mechanism

common_util_username_to_entryid() cuts the domain off first, but cvt_username_to_essdn() splits the address itself, and a name with no @ selects the public-store branch da7de4c added. The numeric half of the cn still names the right user, so nothing fails where the EntryID is written; cvt_essdn_to_username() is the reader that checks the textual half, and it answers ecUnknownUser.

This is the username_to_entryid callback zcore installs for iCalendar import (cu_ical_to_message, cu_ical_to_message2), so it covers the organizer (PR_SENT_REPRESENTING_ENTRYID, PR_SENDER_ENTRYID) and every attendee of an appointment created over CalDAV or from the web client.

Where it comes from

common_util_username_to_entryid() composed the ESSDN itself with a single snprintf() until 14aacee replaced that with a call to the shared helper and kept the caller's split in place. da7de4c had landed twelve days earlier, so the public-store branch was already there to absorb the bare name; before it the helper answered ecInvalidParam, and the same mistake would have failed loudly. The two other call sites in this file pass the helper a whole address.

Change

Hand username to the helper instead of tmp_name. This also drops the early return FALSE for a name with no @ in it: the helper handles that shape deliberately, and mysql_adaptor_get_user_ids() has already accepted the name.

Test

tests/utiltest gains the round trip for a full address and the public-store branch for a bare name, so the requirement on the caller is written down somewhere. make check passes 3/3.

@ximalin
ximalin force-pushed the zcore-essdn-full-address branch 2 times, most recently from a9aa868 to 1745d68 Compare September 11, 2026 15:26
common_util_username_to_entryid() cuts the domain off the username
before handing it to cvt_username_to_essdn(), which splits the address
itself. The helper therefore sees a name with no '@' in it, and since
da7de4c ("usercvt: public store support for cvt_username_to_essdn")
that selects the public-store branch:

	/o=example/[...]/cn=2200000011000000-public.folder.root

where -sender belongs. The numeric half still names the right user, so
nothing fails where the EntryID is written, but cvt_essdn_to_username()
checks the textual half against the mailbox it resolved and returns
ecUnknownUser when the two disagree. This is the username_to_entryid
callback zcore installs for iCalendar import, so it covers the
organizer (PR_SENT_REPRESENTING_ENTRYID, PR_SENDER_ENTRYID) and every
attendee of an appointment created over CalDAV or from the web client.

The double split arrived with 14aacee ("exch: convert more sites
using EAG_RCPTS to usercvt functions"), which replaced the snprintf
that had composed the ESSDN in this function with a call to the shared
helper and kept the caller's split in place. It has been silent from
that day because da7de4c had given a name with no '@' a meaning
twelve days earlier; before that the helper answered ecInvalidParam.
The two other call sites in this file pass the helper a whole address.

Measured with cvt_username_to_essdn() followed by
cvt_essdn_to_username():

	sender@example.org -> [...]-sender             -> sender@example.org
	sender             -> [...]-public.folder.root -> ecUnknownUser

tests/utiltest gains the round trip for a full address and the
public-store branch for a bare name, so the requirement on the caller
is written down somewhere.
@ximalin
ximalin force-pushed the zcore-essdn-full-address branch from 1745d68 to e55683f Compare September 20, 2026 15:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant