No description
  • Scheme 77.1%
  • Python 13.8%
  • Shell 4.4%
  • C 3.8%
  • Makefile 0.8%
Find a file
ober 7341879df0
All checks were successful
required-ci / required (push) Successful in 9m41s
Merge pull request #19
2026-09-21 21:31:55 -04:00
.forgejo Use FreeBSD Forgejo CI runner 2026-08-03 14:47:59 -06:00
.jerboa Resolve security audit findings 2026-07-11 17:22:32 -06:00
android Harden API 26 attachment picker cancellation 2026-09-21 19:23:31 -06:00
corpus/mail Security hardening and release readiness 2026-06-23 10:50:39 -06:00
docs Cover clamped TUI index navigation 2026-09-21 18:15:58 -06:00
jerboa-mail perf(encoding): bulk bytevector/string ops for whitespace strip and lossy decode 2026-07-22 13:51:00 -06:00
lib/jmail Route composed mail through a message record 2026-09-21 18:41:01 -06:00
scripts Add release evidence and Linux musl build pipeline 2026-09-21 18:15:49 -06:00
support Add encrypted first-run mail account setup 2026-09-21 18:15:54 -06:00
test Harden the shipped MIME parser and verification 2026-09-21 18:15:44 -06:00
tests Route composed mail through a message record 2026-09-21 18:41:01 -06:00
vendor Complete jmail backend synchronization and tests 2026-09-17 17:16:36 -06:00
.dockerignore Add reproducible Linux Docker build and native smoke checks 2026-09-21 16:39:20 -06:00
.gitignore Add typed Android mail account and offline preview app 2026-09-21 18:15:31 -06:00
.gitsafeignore Set up Forgejo CI/CD policy 2026-08-03 12:50:51 -06:00
.jerbuild Link and smoke-test native age crypto 2026-09-21 18:15:54 -06:00
AGENTS.md docs(agents): add checkout hygiene policy (work dirs under ~/work, cleanup when done) 2026-09-12 19:10:36 -06:00
Dockerfile Add reproducible Linux Docker build and native smoke checks 2026-09-21 16:39:20 -06:00
jpkg.sexp Bump Android notification release version 2026-09-21 19:13:40 -06:00
LICENSE Switch to MIT license 2026-07-21 13:42:18 -06:00
main.ss Add encrypted local contact management 2026-09-21 18:15:54 -06:00
Makefile Create MIME fixture directory for clean tests 2026-09-21 18:23:07 -06:00
README.md Implement typed Android JMAP sending 2026-09-21 18:33:09 -06:00
SECURITY.md Resolve security audit findings 2026-07-11 17:22:32 -06:00
VERSION Harden API 26 attachment picker cancellation 2026-09-21 19:23:31 -06:00

jerboa-mail

jmail is a pine/alpine-style terminal mail client written in Jerboa. It supports Proton Bridge over loopback IMAP/SMTP and the encrypted jerboa-jmap service over pinned TLS.

A typed-Jerboa Android companion app is under android/. It stores JMAP account settings with Android Keystore-backed encryption and supports Inbox/Trash search, paging, message detail, server-confirmed read/star/delete/restore actions, an encrypted Inbox snapshot for offline viewing, and single-recipient JMAP message submission. Background synchronization and offline action queuing are not implemented; see android/README.md for current limits and emulator validation.

Features

  • Locked startup with scrypt-derived master key.
  • AES-256-GCM encrypted credentials in ~/.local/share/jmail/secrets.enc.
  • Column-level encrypted message data in the jsqlite mail database.
  • Age-v1 and jsmtp ECIES message decryption.
  • Proton Bridge IMAP folder/message synchronization and SMTP sending.
  • JMAP mailbox/query/message synchronization and RFC 8621 EmailSubmission sending.
  • Compose with To/Cc/Bcc, multiline plain-text bodies, and visible Bcc privacy on SMTP delivery.
  • Save, list, resume, and delete postponed drafts; recipients, content, and reply-thread metadata are encrypted at rest.
  • Wrapped, terminal-safe message reading with body scrolling and independent message navigation.
  • Termbox2 TUI with unlock, folder list, index, message view, compose, and help screens.
  • Search, sorting, complete message-body retrieval, and MIME attachment listing with safe export to an existing directory.
  • Remote seen/star/delete/restore actions, with targeted IMAP UID expunge or confirmed JMAP destroy and cache reconciliation after complete sync inventories.

The mail database intentionally leaves account, backend, folder, UID, flags, timestamps, and sizes available for synchronization and ordering. Subject, addresses, dates, snippets, bodies, raw messages, message IDs, references, and attachment metadata remain encrypted. Postponed drafts are stored in the separate DELETE-journal outbox database; all compose fields and reply metadata are encrypted, while account/backend identifiers and timestamps remain available for filtering and ordering.

Security

The application starts locked. Network credentials are loaded only after unlock and are wiped from the in-memory cache on relock. The JMAP transport requires the configured SHA-256 certificate-DER pin and has no unpinned fallback. Proton Bridge credentials are used only with 127.0.0.1.

On a fresh home directory, jmail runs interactive setup before starting the TUI. It supports Proton Bridge IMAP/SMTP and JMAP over pinned TLS, prompts for the vault passphrase twice, and collects credentials without terminal echo. Use jmail --setup later to update the account configuration. Setup writes credentials only to the encrypted secrets store; it does not depend on or create ~/proton-pass.

Usage

jmail --help and jmail --version work without starting the TUI. Use jmail --setup to create or update encrypted connection settings. Contacts are managed from the command line with jmail --contact-add 'Name' mailbox@example.com, jmail --contacts, and jmail --contact-delete ID; each command asks for the vault passphrase, and contacts are scoped to the configured account with both name and mailbox encrypted in the local outbox database. In the TUI, use j/k or the arrow keys to move through folders and messages, Enter to open a message, n/p to move between messages while reading, and the arrow or page keys to scroll the body. In the index, / starts where-is search, # jumps to a message number, o cycles sorting, d marks deleted, u restores, and x requires the same UID to be selected for two immediate presses before expunge. In message view, r replies, R replies to the sender and other recipients, F starts a forward with the original headers and text body, and a lists attachments and prompts for a numbered save to an existing directory. Reply-all filters the configured Bridge address; JMAP does not store the sending identity locally, so review/remove your address from recipients before sending. Press b in the folder list to switch Bridge/JMAP, $ to sync, p to open postponed drafts, c to compose, and ? for help. In compose, Tab or Enter advances through To, Cc, Bcc, and Subject; Enter in the body inserts a newline; Ctrl-O saves or updates the current draft without sending; Ctrl-X sends and removes its saved draft after handing the message to the send path; Ctrl-C returns to the index while leaving a previously saved draft available. In the drafts list, Enter resumes, d deletes, and q returns to folders.

Development

make test
make build
make binary
make native-smoke
make binary-smoke
make docker-build

make binary produces dist/jmail on macOS. Native dependencies are vendored under vendor/ and the termbox shim is statically included in the standalone binary. make docker-build builds the Linux release in a Debian Bookworm image with the Rust and native crypto toolchain installed from the image's pinned distribution. The resulting image contains dist/jmail and starts with --help by default.