This series makes it possible to do socket activation. It is written on top of the earlier patch series to make it easier to consider merging in sequence (it is also quite close to several bugfixes)
Enable sd_listen_fds(3)-style socket-activation support
I've added straightforward systemd unit files in
system/socket-activation/ that make use of this approach, and a
README.md in the same location that describes the tradeoffs.
We want to be able to select the default for Socket differently in the
future.
This change augments the API for dkimpy_milter.util.own_socketfile()
by adding an optional sockname argument. This is a
backward-compatible change. If we aren't committed to API stability
for this function, we could make a more invasive change that would
probably be a more reasonable API going forward, but this is probably
good enough.
The main work here is about bytes vs. strings. This work was
confusing for several reasons:
* pymilter thinks that headers are all strings, but body is bytes
* dkimpy wants to deal with bytes objects generally (though it
accepts a string object as an ed25519 secret key for some reason,
despite requiring bytes as an RSA secret key)
* authres.AuthenticationResultsHeader object converts easily to a
string, but has no direct bytes conversion. meanwhile, it wants
its arguments as strings, but will accept them if they are bytes
and convert them with something like str(), which leaves weird
cruft like "header.a=b'ed25519-sha256'"
* dkimpy_milter/utils.py contains fold() which expects bytes
* self.fp needs to accumulate the on-the-wire version of the message
as a whole (so it needs to be bytes). That means converting the
headers. Header names and values are US-ASCII, per ยง2.2 of RFC
5322, so they should be convertible cleanly, but we still have to
convert them explicitly so that python knows the right thing to do.
At any rate, tests/runtests all passes with these changes, and the
output for both Authentication-Results: and DKIM-Signature headers
looks the same.
Convert mostly to python3 (still need strings/bytes conversions)
This covers conversion of the whole project to python3, *except* for
the strings/bytes distinction in __init__.py, which i'm leaving for a
second commit.
The changes in this commit are intended to be relatively
uncontroversial, so that the following commit contains the tricky
bits.
This test makes use of DNSOverride and the new verifying milter to
ensure that signatures can be verified properly.
It doesn't test the actual interaction with the public DNS, but
getting that kind of test to work on arbitrary platforms might be more
trouble than it's worth.
I note that the DNSOverride only works as long as testkey.dns is a
single line, which is fine for ed25519, but maybe not for RSA.