Skip to content

v2026.10.08.05 — 2026-10-08

  • merge: deleting a backup schedule keeps the key its repository needs, so the next schedule can still read the old snapshots
  • merge: the icon-only delete and revoke buttons a customer sees have a name a screen reader can read
  • docs(groupware): the appointment-notification line is the fix for the missing invitation, not just hardening
  • docs(notes): #850 resolved — SOGoAppointmentSendEMailNotifications=YES (153b68c02) produces a real queue-ID with the notification flag confirmed on and no suppression tag; lead-architect-2's source reading explains every prior run in this series
  • docs(notes): #850 — verified via network capture that the notification flag is correctly sent and the checkbox toggle works; the X-SOGO-SEND-APPOINTMENT-NOTIFICATIONS line is simply absent from the stored .ics regardless, and still zero mail
  • docs(notes): #850 — hardening confirmed not the fix (5/5 saves without queue-ID, key set or not); sogo_folder_info.c_location references a per-folder table that does not exist in our shared-store schema
  • docs(notes): #850 — decisive counter-check: no queue-ID even without the folder-resolution error, disproving it as the cause
  • docs(notes): #850 — no-attendee save is clean, organizer keeps her own event, error is nondeterministic not tied 1:1 to attendees; our SQL schema matches canonical SOGo layout
  • merge: a malware hit from another tenant's tmp is no longer this site's finding, and a skipped file is no longer counted against a server-wide tally
  • fix(malware): the coverage check derives its numbers from one webroot pass, not maldet's tmp-inclusive tally
  • fix(malware): a scan attributes a finding to this site only when it is actually this site's
  • docs(notes): #850 — internal silent-entry theory disproven, external attendee also produces zero mail; sogod logs a reproducible 'Did not find folder of content object' error at saveAsAppointment time
  • merge: whether an invitation leaves the server is written down, not inherited from an upstream default
  • fix(groupware): the appointment notification setting is written down instead of inherited from an upstream default
  • docs(notes): SOGoAppointmentSendEMailNotifications missing but defaults YES; .test TLD NXDOMAIN fully explains the Junk filing
  • docs(notes): confirm webmail send works, narrowing #850 to the invitation notification path
  • docs(notes): prove calendar and contact sharing with a real browser client, confirm the missing invitation mail
  • merge: a malware scan that skips files says so, per reason, instead of claiming a clean pass
  • fix(malware): the skip reason is three numbers the UI composes, not a German sentence from Go
  • fix(malware): a scan that skips files reports it instead of claiming a clean pass
  • merge: a single 700ms throttle tick no longer warns the customer or pitches a bigger package — only sustained throttling does
  • docs(notes): #100 customer settings audit — 6 of 6 account items tested, 2 findings
  • merge: reporting a malware finding as a false positive no longer hides it from the operator, the score or a later payload at the same path
  • fix(settings): add accessible names to icon-only revoke/delete buttons
  • fix(malware): the message for a finding without a content checksum names the limit of its own advice
  • fix(resources): decide CPU-throttle Now vs Sustained in one place, not per surface (#843)
  • fix(backup): a repository key outlives the plan it belonged to, and an existing repository is never assumed to be ours
  • docs(notes): the scan limit is 2 MB today, so the hash cap never binds — and that is the coupling to the scan-scope work
  • fix(malware): a false alarm is reported with a reason and bound to the file content, not clicked away
  • docs(notes): measure SOGo mail and groupware completeness and its update path on two full panels
  • docs(notes): the throttle warning does exist — four surfaces, three thresholds; and the malware ignore path is its own p1
  • docs(notes): #842 activity box does not reproduce on .93 — writes, query and UI auto-refresh all measured correct in v2.10.11
  • docs(notes): inventory of the panel's warnings and a proposal for the two switch levels
  • docs(notes): smoke-test stable v2.10.11 on the test box, package and running version agree
  • docs(notes): #839 — apt cache growth is Debian's own autoclean, not deploy-test.sh (which never produces a .deb)