mail relay configured
This commit is contained in:
+85
-2
@@ -6,7 +6,7 @@ Compiler environment.
|
||||
| | |
|
||||
|---|---|
|
||||
| Scope | All instances. Staging entries are marked `srv-b`. |
|
||||
| Updated | 2026-08-16, after staging acceptance |
|
||||
| Updated | 2026-08-17, after work order 002 |
|
||||
| Rule | Append only. Never edit an entry except to add a `Resolution` line. |
|
||||
| Numbering | Sequential, never reused. See §0 on the renumbering. |
|
||||
|
||||
@@ -445,6 +445,87 @@ divergence between `/var/spool/postfix` copies and their host originals,
|
||||
including `/etc/hosts` and NSS libraries — a known cause of resolution failure
|
||||
inside the chroot, and adjacent enough to this failure to be checked first.
|
||||
|
||||
**Resolution (2026-08-17):** Cause proven, three hops downstream of the origin.
|
||||
`mx1` runs `permit_mynetworks, permit_auth_destination, reject` on both relay
|
||||
and recipient restrictions. `wg-pk` connected from public addresses absent from
|
||||
`mx1`'s `mynetworks`, and `kane-il.us` is not an authorised destination there,
|
||||
so `RCPT TO <sandor@kane-il.us>` was rejected `554 5.7.1 Access denied` over
|
||||
both IPv4 and IPv6. Added only `198.58.111.109/32` and
|
||||
`[2600:3c00::f03c:92ff:fe42:43d7]/128` to `mx1`'s `mynetworks` and reloaded.
|
||||
|
||||
Four hypotheses were tested and ruled out with evidence before any change: the
|
||||
`srv-b` alias (`postalias -q root` resolved correctly and the journal showed
|
||||
`orig_to=<root>` forwarded), sender-domain rejection (`wg-pk` rewrites the
|
||||
sender to `postmaster@diagnostics.kane-il.us` and `MAIL FROM` was accepted),
|
||||
address-family asymmetry (both families failed identically), and routing on
|
||||
`wg-pk` (it connected and received the rejection).
|
||||
|
||||
Method worth reusing: **RCPT-only probes before and after the change, over both
|
||||
address families, with no message body.** `554` before, `250` after. That
|
||||
proves the change caused the fix rather than coinciding with it — the standard
|
||||
F-012 was written to enforce. Two messages then delivered end to end with full
|
||||
headers captured, empty queue, no deferred entries. **Closed.**
|
||||
|
||||
---
|
||||
|
||||
### F-024 — work order specified a log file that does not exist
|
||||
`srv-b`. Work order 002.
|
||||
|
||||
**Observed:** WORK ORDER 002 instructed `grep /var/log/mail.log`. The file does
|
||||
not exist on `srv-b`.
|
||||
**Cause:** **Proven.** Proxmox VE ships without `rsyslog`. Postfix logs to
|
||||
journald only.
|
||||
**Correction:** The operator used `journalctl -u postfix@-` and completed the
|
||||
diagnosis. No configuration was changed; installing `rsyslog` to satisfy a
|
||||
document would have been the wrong direction.
|
||||
**Consequence:** **Specification defect.** All log inspection on a Proxmox host
|
||||
uses `journalctl`, not files under `/var/log`. Corrected in `ENVIRONMENT.md`
|
||||
revision 5. Automation that greps a logfile path will silently find nothing,
|
||||
which is worse than failing.
|
||||
|
||||
---
|
||||
|
||||
### F-025 — the F-023 correction granted wider relay than required
|
||||
`mx1`, `wg-pk`. Estate scope.
|
||||
|
||||
**Observed:** Adding `wg-pk`'s two public addresses to `mx1`'s `mynetworks`
|
||||
authorises them under `permit_mynetworks`, which appears in **both**
|
||||
`smtpd_relay_restrictions` and `smtpd_recipient_restrictions`. That grants relay
|
||||
to **any** destination, not only to `kane-il.us`.
|
||||
|
||||
`wg-pk` in turn carries `mynetworks = 10.110.0.0/22` with
|
||||
`permit_mynetworks permit_sasl_authenticated defer_unauth_destination`. The
|
||||
resulting chain:
|
||||
|
||||
```
|
||||
any peer on 10.110.0.0/22 (including CT 100 and CT 101, which arrive
|
||||
as 10.110.0.12 through the srv-b masquerade)
|
||||
-> wg-pk permit_mynetworks
|
||||
-> mx1 permit_mynetworks
|
||||
-> any destination on the internet, as kane-il.us infrastructure
|
||||
```
|
||||
|
||||
Before the correction `mx1` rejected at the final hop, so the path was closed by
|
||||
accident rather than by policy.
|
||||
|
||||
**Cause:** **Proven.** `permit_mynetworks` is destination-agnostic by design.
|
||||
**Correction:** **Pending — operator decision.** Two independent parts:
|
||||
|
||||
- *Ours:* block SMTP egress from the container network at `srv-b`. The
|
||||
containers have no reason to originate mail; if they ever should, that is a
|
||||
deliberate decision rather than something inherited from a masquerade. Local,
|
||||
precise, touches no estate policy.
|
||||
- *Estate:* whether `wg-pk`'s `mynetworks` should be explicit `/32` entries for
|
||||
the hosts that legitimately originate mail rather than the whole tunnel range.
|
||||
|
||||
**Constraint:** `wg-pk` must continue to relay to arbitrary external
|
||||
destinations — that is its purpose, since Hubzilla registration and notification
|
||||
mail depends on it and the ISP blocks port 25. Restricting it by *recipient*
|
||||
would break that. The question is which clients may ask, not where it may send.
|
||||
|
||||
**Consequence:** A correction that fixes the observed failure may widen an
|
||||
adjacent boundary. Record what a trust change grants, not only what it repairs.
|
||||
|
||||
---
|
||||
|
||||
## Open, not closed
|
||||
@@ -456,6 +537,8 @@ inside the chroot, and adjacent enough to this failure to be checked first.
|
||||
| F-019 | **Corrected** 2026-08-16. Reboot persistence proven. |
|
||||
| F-021 | **Corrected** 2026-08-16. Reboot persistence proven. |
|
||||
| F-022 | **Open** — cause unproven, no correction applied. |
|
||||
| F-023 | **Deferred** — downstream mail failure, cause unproven. Hypothesis recorded. |
|
||||
| F-023 | **Closed** 2026-08-17. Cause proven at `mx1`; delivery proven twice. |
|
||||
| F-024 | **Closed** 2026-08-17. Specification corrected. |
|
||||
| F-025 | **Open** — correction pending operator decision. |
|
||||
|
||||
Everything else is closed with a proven cause and a proven correction.
|
||||
|
||||
Reference in New Issue
Block a user