- Shipped
- September 29, 2026 at 2:29 AM UTC
- Author
- Kamo
- Commit
- 3ae4903
Round 2 review (email-fix-review-2.md) found the round 1 fix for MAJOR #3 (multiple root domains) still reopened the original bug: - BLOCKER: kamouniverse.com is, live, simultaneously a proven root (org_domains, ownership-verified, no parent) AND the default alias domain (org_alias_domains) for org 1168485648209608710 — the exact org this report is about — while the real mailbox lives only on the canonical domain (sage@kamocrm.com). The round 1 guard `!rootDomains.contains(domain)` skipped the multi-root retry whenever the candidate's own domain was already a root, on the assumption a root-domain address "must already have been tried directly" — false for a dual-registered domain. sage@kamouniverse.com was refused again. The guard is removed: the retry now runs unconditionally after the direct check misses, for every owned root, whether or not the candidate's own domain happens to be one of them. Redundant-but-harmless for the common case (the direct check already covers a literal root-domain address); load-bearing whenever a domain is dual-registered like kamouniverse.com. - MAJOR: the round 1 +tag fold (sage+urgent@kamocrm.com -> sage@kamocrm.com) is removed entirely rather than scoped to "mailbox tables only" as first proposed. Checked live against the actual mail stack per the review's own instruction to confirm against Postfix/Dovecot behaviour: `recipient_delimiter` is commented out in both postfix's main.cf and dovecot's 15-lda.conf, and virtual_mailbox_maps / virtual_alias_maps both resolve the RCPT TO address with a literal `WHERE email = '%s'` / `WHERE source = '%s'` — no delimiter stripping anywhere, for any table. Folding here would have certified a +tag'd address deliverable that Postfix would still 550 — false confidence in the opposite direction from round 1's original bug, not a fix scoped narrowly enough to be correct. This is a deviation from the literal round 2 instruction (which presumed some table does fold), made on the live evidence the instruction itself asked to gather; recorded as a ruling. - MINOR: EmailAddress.parse() returning null (its local-part charset is stricter than what alias/shared-mailbox/mailbox creation itself enforces) no longer silently disables the multi-root retry. A plain substring-before-the-last-@ fallback extracts the local part so the retry still runs. Tests: RecipientDomainValidatorTest rewritten with a table-aware fake EntityManager (inspects the SQL text to route a table's own known-address set, per the review's "make the test double tell tables apart") so a test can now assert e.g. "known only as an alias" and have it mean something. New/changed cases confirmed RED against the unmodified round-1 RecipientDomainValidator.java (temporarily restored via `git stash` of just that file, then popped back): the live-shape regression case, two +tag-no-longer-folds cases, the alias-only +tag case, and the EmailAddress.parse()- rejects case — 5 failures, exactly the cases this round changes. All green after. heavy mvn test **************** 80 run, 0 failures.
