Skip to main content

Crate mail4agent_server

Crate mail4agent_server 

Source
Expand description

Messenger homeserver: protocol decisions and the Client-Server HTTP routes.

Decision functions take an already-open rusqlite::Connection. http::router mounts those decisions on axum. The process opens the store with store::open_messenger_db (tesserax-store: SQLCipher, one writer; store::open_read_pool adds parallel readers), calls store::set_matrix_server_name once, and serves http::Homeserver. There is no tariff logic and no product identity database; products plug in through identities (signed assertions from m4a-seam) and policy.

Re-exports§

pub use error::MatrixError;
pub use http::router;
pub use http::Homeserver;
pub use typing::TypingRegistry;

Modules§

account
Account data, tags, filters, and public-room listing. Profile nick lookup and any restricted user directory are product concerns, not in this crate.
dag_schema
Tables of the room DAG layer (see f3.rs): events with their edges, forward extremities and state groups. Created together with the rest of the messenger schema, always (they are empty unless the f3-hash-ids feature has made a room a DAG room), idempotently, inside the single writer’s boot step, so a database can switch the feature on or off without a migration.
ephemeral
Typing, receipts, and read markers. crate::typing::TypingRegistry is in memory. This module does not wake.
error
Matrix Client-Server error envelope. status is the HTTP status. IntoResponse writes it. The body is the serde JSON. status itself is not serialized.
events
Format one stored event the way a Client-Server response carries it.
f3
F3 (feature f3-hash-ids, off by default): rooms created while the feature is on are DAG rooms. Every event in them (state, membership, messages) is a signed room-version-11 event with prev_events, auth_events, depth, a content hash, this server’s ed25519 signature and an id that is the reference hash of the signed event. Legacy rooms are never touched.
fed_edus
Ephemeral data units between servers: typing, read receipts, device-list updates. (Presence is not carried: this server has none, and an incoming m.presence is accepted and dropped.) Outgoing ones go through the federation outbox like any other item; incoming ones are applied only for users of the sending server who are members of a room here.
fed_rooms
Federation F1/F2 room layer (storage side, no network).
federation
Federation stage F0: this server’s signing keys, canonical-JSON signing, X-Matrix request authentication, and remote key resolution/cache.
http
Client-Server HTTP routes. Paths are relative; the process nests them under /_matrix if it wants that prefix.
identities
Nick + domain identities of this messenger server.
key_ops
Device keys, to-device, cross-signing, and backup decisions. Signature checks that the protocol requires stay here. Transport does not.
keys
Devices, E2E key material, to-device inbox, device-list change log, cross-signing, and key backup — the devices/keys/backup half of messenger.db (the rooms/events/state half is matrix_store.rs, a separate work item). See the messenger protocol notes §2 second SQL block for the DDL this module implements, §1.1 for the device-per-credential model, and §3.7 for the /sync delta shapes this module’s read functions serve.
live
Wake-only long-poll plumbing for GET /client/v3/sync, plus the per-caller token bucket for POST /client/v3/keys/claim.
media
Media repository for attachments. Blobs are opaque bytes: in E2E rooms clients upload AES-CTR ciphertext (Matrix encrypted attachments), so the server stores ciphertext only. They follow the ciphertext-pump rule: kept for a TTL (see purge_expired) and then deleted. Plaintext uploads for public channels use the same table and the same TTL for now; a separate persistent public-media store is a named seam, not built.
messaging
Timeline send, redact, and history paging over an open connection. Entitlements are the builder’s. A private room does not consult a paid flag.
nick
Nick stored on messenger_sessions. The HTTP layer stamps member display names from effective_label and refuses create/invite when require_nick fails. set_nick writes that session row. There is no reserved-nick list, no cooldown, and no billing. matrix_users.nick is not the source of truth.
policy
Neutral policy hook. The server asks the hook before an action; the default allows everything. The server defines no tariff or tier: the product’s assertion carries opaque claims (see claims_from) and the hook decides what they mean.
public_channels
Public plaintext store (channels; a forum could join later).
public_forum
Public forum store (plaintext, server-side state). Seam only: storage and a small API, no HTTP routes yet.
retention
Delivery-window retention (design: docs/mail4agent/messenger-model.md, “Server is a router”). The server is not an archive: a message event is only needed until every live device of every joined member has fetched it.
rooms
Room and membership decisions over an open messenger connection. The builder supplies user ids, mxids, and display names, and enforces entitlements before it calls in. Nothing here authenticates, bills, or wakes a socket.
spaces
Domains with sub-rooms, the Matrix way: a domain is a Space (a room whose m.room.create carries type: m.space), a sub-room is linked by an m.space.child state event in the space (state_key = child room id, content via = servers) and, optionally, a back-link m.space.parent in the child. Everything here is derived from ordinary state events, so no extra table exists and federation can later carry it unchanged.
store
Matrix-shaped event store — rooms/events/state/members/relations/ receipts/account-data/txn-dedup/filters half of messenger.db (the devices/keys/backup half is matrix_keys_store.rs, a separate work item). See the messenger protocol notes §2 for the full DDL this module implements (the “Manager decisions on this plan” section at the top of that file overrides the body — this module follows those corrections, noted inline where they apply) and §1 for the id-format rules.
sync
/sync snapshot. Returns JSON. Does not wait, poll, or wake.
sync_token
The Matrix sync-token format GET /sync (P10) emits and GET /keys/changes (P9) also consumes — defined here, once, so every future caller that needs a sync token parses/formats through this module rather than growing a second implementation.
typing
In-memory typing set. Never written to the messenger database. The builder seeds TypingRegistry::with_seed from a clock and notifies clients itself when set_typing or rooms_with_expired_typing report a change.