calternal_imap::wire
Bounded IMAP command framing for #428. Commands are decoded by imap-codec; client strings never become filesystem paths. Authentication data is never logged. A malformed or oversized frame poisons the reader, so literals cannot desynchronize a later command. #1038 sends a fixed BYE before closing failed command or IDLE reads; a socket EOF alone is not an IMAP rejection.
Source: crates/calternal-imap/src/wire.rs
Structs
Section titled “Structs”CommandReader
Section titled “CommandReader”pub struct CommandReader<S>Own the transport and parser so buffered bytes cannot escape into another session.
CommandReader::new
Section titled “CommandReader::new”pub fn new(stream: S, limits: Limits) -> io::Result<Self>Validate server-owned limits before accepting any command bytes.
CommandReader::into_stream
Section titled “CommandReader::into_stream”pub fn into_stream(self) -> SDiscard buffered cleartext on STARTTLS. RFC 3501 requires the client to wait for the tagged response; queued cleartext must never be decoded as authenticated commands after the upgrade (#428).
CommandReader::read
Section titled “CommandReader::read”pub async fn read(&mut self) -> io::Result<Command<'static>>Decode one command under an absolute timeout. Once a frame fails, the caller must close the transport; unread literal bytes are never commands. Report failure with a fixed BYE, without echoing an incomplete tag (#1038).
CommandReader::write_all
Section titled “CommandReader::write_all”pub async fn write_all(&mut self, bytes: &[u8]) -> io::Result<()>Responses share the owned transport; writes also have an absolute timeout.
CommandReader::idle
Section titled “CommandReader::idle”pub async fn idle<P: crate::store::NotesStore>( &mut self, session: &mut crate::session::Session<P>, changes: &mut dyn crate::store::Changes, idle_timeout: Duration, ) -> io::Result<()>Process IDLE and its DONE frame without cancelling an in-progress frame read. Plugin wakeups reconcile the same authenticated view; pipelined bytes stay in the Fragmentizer. IDLE never accepts a literal (#428). Timeout or revocation ends the session with a fixed BYE (#1038).
Source: crates/calternal-imap/src/wire.rs:34
Limits
Section titled “Limits”pub struct LimitsNamed per-connection parser limits; no field is inferred from client input.
Fields
pub max_command_bytes: usizepub max_literal_bytes: usizepub command_timeout: Duration
Implements: Clone, Copy, Default