How does it communicates to smtpd, lmtp or reading it's maildirs
or other methods?

On Sat, 22 Aug 2026 12:08:56 -0700
David Williams <[email protected]> wrote:

> Hi all,
> 
> I wanted to check in early, per the Porting Guide's own advice, before
> putting more time into something that might duplicate existing work.
> 
> I've been building OpenIMAPD, a from-scratch IMAP4rev2 (RFC 9051) server
> in C, following the same privsep tradition as smtpd/httpd/ntpd: a root
> parent that reads config and binds sockets, an unprivileged listener that
> terminates TLS and speaks the wire protocol, a separate auth process, and
> a store process forked per authenticated session that chroots and drops
> privileges before ever touching a mailbox. pledge(2)/unveil(2)/chroot(2)
> enforce the boundaries, not just convention.
> 
> I've been able to compile and launch it cleanly. It's been running
> on a bare-metal OpenBSD box for a few days, using
> Apple Mail as the client. Implemented so far: STARTTLS + implicit TLS
> (RFC 8314) via libtls, dual-stack IPv4/IPv6 listen support, AUTH=PLAIN
> gated on TLS, SELECT/EXAMINE, multi-mailbox CREATE/DELETE/RENAME/LIST,
> FETCH (including ENVELOPE, BODYSTRUCTURE, and MIME-part-addressed
> BODY[<part>]), STORE, SEARCH, APPEND, COPY/MOVE to any mailbox, EXPUNGE,
> UID forms of everything that supports it, CONDSTORE/QRESYNC (RFC 7162),
> IDLE with real cross-session push, and SIGHUP config/cert reload
> (matching httpd(8)'s own documented behavior). A real imapd.conf grammar
> (hand-written parse.y, ntpd/smtpd-style) and an rc.d(8) script are both
> in place.
> 
> Hardening steps I've taken so far: WARNS=6 build, OpenBSD malloc hardening, 
> an ASan/UBSan fuzzing pass against the command parser, and two 
> security-review passes, which found and fixed several bugs :/
> 
> Scope has been kept small. SUBSCRIBE/UNSUBSCRIBE and ACL have been left out, 
> for example.
> 
> Two questions before I go further:
> 
> 1. Is anyone already working on a from-scratch IMAP daemon port for OpenBSD? 
> I don't want to duplicate effort.
> 2. Is this worth continuing to work on...toward a port submission,
>    or is there prior work I should know about?
> 
> It's not hosted publicly yet -- no tagged release or web-browsable tree
> -- but there is a real source tarball (imapd-0.1.tar.gz) that builds
> clean out of the box (verified with a fresh extract and `make`, no
> warnings under WARNS=6). Happy to share it directly with anyone
> interested in taking an early look.
> 
> Thanks for your time,
> 
> David
> [email protected]


-- 
chara <[email protected]>

Reply via email to