]> dgit.raspbian.org Git - dovecot.git/commit
[PATCH 4/5] submission-login: client-authenticate - Reply 421 4.7.0 on mail_max_useri...
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Thu, 7 May 2026 10:58:12 +0000 (10:58 +0000)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
commitb82914446b4e39ba51427b121b3fbc036aed9e7b
tree6c9eaf1d67acb3290251dd05ff95b7bbbb23e026
parent2a33a46473ef25f012cd19d84d8e25014a6b4e86
[PATCH 4/5] submission-login: client-authenticate - Reply 421 4.7.0 on mail_max_userip_connections

Until now the connection limit was reported via the same 454 4.7.0 reply
that is used for generic temporary authentication failures. That makes
proxies (including Dovecot's own submission proxy) treat the rejection as
a transient auth error and retry, which is futile when the limit is hit
and only obscures the actual cause in the proxy log.

Reply with 421 4.7.0 instead. RFC 5321 Section 4.2.1 specifies 421 as
"service shutting down, closing transmission channel", which is the
right signal for "do not retry on this connection". The 421 + 4.7.0
combination is unique among the 421 replies emitted by submission and is
used by the submission proxy to recognize this specifically as a
connection-limit reply rather than a generic 421 internal/shutdown.

Gbp-Pq: Name 0004-submission-login-client-authenticate-Reply-421-4.7.0.patch
src/submission-login/client-authenticate.c