Request for Comments: 4551 Isode Ltd.
Updates: 3501 S. Hole
Category: Standards Track ACI WorldWide/MessagingDirect
June 2006
IMAP Extension for Conditional STORE Operation
or Quick Flag Changes Resynchronization
Status of This Memo
This document specifies an Internet standards track protocol for the
Internet community, and requests discussion and suggestions for
improvements. Please refer to the current edition of the "Internet
Official Protocol Standards" (STD 1) for the standardization state
and status of this protocol. Distribution of this memo is unlimited.
Copyright Notice
Copyright (C) The Internet Society (2006).
Abstract
Often, multiple IMAP (RFC 3501) clients need to coordinate changes to
a common IMAP mailbox. Examples include different clients working on
behalf of the same user, and multiple users accessing shared
mailboxes. These clients need a mechanism to synchronize state
changes for messages within the mailbox. They must be able to
guarantee that only one client can change message state (e.g.,
message flags) at any time. An example of such an application is use
of an IMAP mailbox as a message queue with multiple dequeueing
clients.
The Conditional Store facility provides a protected update mechanism
for message state information that can detect and resolve conflicts
between multiple writing mail clients.
The Conditional Store facility also allows a client to quickly
resynchronize mailbox flag changes.
This document defines an extension to IMAP (RFC 3501).
Table of Contents
1. Introduction and Overview ................................. 3
2. Conventions Used in This Document ......................... 5
3. IMAP Protocol Changes ..................................... 6
3.1. New OK untagged responses for SELECT and EXAMINE ......... 6
3.1.1. HIGHESTMODSEQ response code ............................ 6
3.1.2. NOMODSEQ response code ................................. 7
3.2. STORE and UID STORE Commands ............................. 7
3.3 FETCH and UID FETCH Commands ..............................13
3.3.1. CHANGEDSINCE FETCH modifier ............................13
3.3.2. MODSEQ message data item in FETCH Command ..............14
3.4. MODSEQ search criterion in SEARCH ........................16
3.5. Modified SEARCH untagged response ........................17
3.6. HIGHESTMODSEQ status data items ..........................17
3.7. CONDSTORE parameter to SELECT and EXAMINE ................18
3.8. Additional quality of implementation issues ..............18
4. Formal Syntax .............................................19
5. Server implementation considerations ......................21
6. Security Considerations ...................................22
7. IANA Considerations .......................................22
8. References ................................................23
8.1. Normative References .....................................23
8.2. Informative References ...................................23
9. Acknowledgements ..........................................23
1. Introduction and Overview
The Conditional STORE extension is present in any IMAP4
implementation that returns "CONDSTORE" as one of the supported
capabilities in the CAPABILITY command response.
An IMAP server that supports this extension MUST associate a positive
unsigned 64-bit value called a modification sequence (mod-sequence)
with every IMAP message. This is an opaque value updated by the
server whenever a metadata item is modified. The server MUST
guarantee that each STORE command performed on the same mailbox
(including simultaneous stores to different metadata items from
different connections) will get a different mod-sequence value.
Also, for any two successful STORE operations performed in the same
session on the same mailbox, the mod-sequence of the second completed
operation MUST be greater than the mod-sequence of the first
completed. Note that the latter rule disallows the use of the system
clock as a mod-sequence, because if system time changes (e.g., an NTP
[NTP] client adjusting the time), the next generated value might be
less than the previous one.
Mod-sequences allow a client that supports the CONDSTORE extension to
determine if a message metadata has changed since some known moment.
Whenever the state of a flag changes (i.e., the flag is added where
previously it wasn’t set, or the flag is removed and before it was
set) the value of the modification sequence for the message MUST be
updated. Adding the flag when it is already present or removing when
it is not present SHOULD NOT change the mod-sequence.
When a message is appended to a mailbox (via the IMAP APPEND command,
COPY to the mailbox, or using an external mechanism) the server
generates a new modification sequence that is higher than the highest
modification sequence of all messages in the mailbox and assigns it
to the appended message.
The server MAY store separate (per-message) modification sequence
values for different metadata items. If the server does so, per-
message mod-sequence is the highest mod-sequence of all metadata
items for the specified message.
The server that supports this extension is not required to be able to
store mod-sequences for every available mailbox. Section 3.1.2
describes how the server may act if a particular mailbox doesn’t
support the persistent storage of mod-sequences.
This extension makes the following changes to the IMAP4 protocol:
a) adds UNCHANGEDSINCE STORE modifier.
b) adds the MODIFIED response code which should be used with an OK
response to the STORE command. (It can also be used in a NO
response.)
c) adds a new MODSEQ message data item for use with the FETCH
command.
d) adds CHANGEDSINCE FETCH modifier.
e) adds a new MODSEQ search criterion.
f) extends the syntax of untagged SEARCH responses to include
mod-sequence.
g) adds new OK untagged responses for the SELECT and EXAMINE
commands.
h) defines an additional parameter to SELECT/EXAMINE commands.
i) adds the HIGHESTMODSEQ status data item to the STATUS command.
A client supporting CONDSTORE extension indicates its willingness to
receive mod-sequence updates in all untagged FETCH responses by
issuing:
- a SELECT or EXAMINE command with the CONDSTORE parameter,
- a STATUS (HIGHESTMODSEQ) command,
- a FETCH or SEARCH command that includes the MODSEQ message data
item,
- a FETCH command with the CHANGEDSINCE modifier, or
- a STORE command with the UNCHANGEDSINCE modifier.
The server MUST include mod-sequence data in all subsequent untagged
FETCH responses (until the connection is closed), whether they were
caused by a regular STORE, a STORE with UNCHANGEDSINCE modifier, or
an external agent.
This document uses the term "CONDSTORE-aware client" to refer to a
client that announces its willingness to receive mod-sequence updates
as described above. The term "CONDSTORE enabling command" will refer
any of the commands listed above. A future extension to this
document may extend the list of CONDSTORE enabling commands. A first
CONDSTORE enabling command executed in the session MUST cause the
server to return HIGHESTMODSEQ (Section 3.1.1) unless the server has
sent NOMODSEQ (Section 3.1.2) response code when the currently
selected mailbox was selected.
The rest of this document describes the protocol changes more
rigorously.
2. Conventions Used in This Document
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT",
"SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this
document are to be interpreted as described in RFC 2119 [KEYWORDS].
In examples, lines beginning with "S:" are sent by the IMAP server,
and lines beginning with "C:" are sent by the client. Line breaks
may appear in example commands solely for editorial clarity; when
present in the actual message, they are represented by "CRLF".
Formal syntax is defined using ABNF [ABNF].
The term "metadata" or "metadata item" is used throughout this
document. It refers to any system or user-defined keyword. Future
documents may extend "metadata" to include other dynamic message
data.
Some IMAP mailboxes are private, accessible only to the owning user.
Other mailboxes are not, either because the owner has set an Access
Control List [ACL] that permits access by other users, or because it
is a shared mailbox. Let’s call a metadata item "shared" for the
mailbox if any changes to the metadata items are persistent and
visible to all other users accessing the mailbox. Otherwise, the
metadata item is called "private". Note that private metadata items
are still visible to all sessions accessing the mailbox as the same
user. Also note that different mailboxes may have different metadata
items as shared.
See Section 1 for the definition of a "CONDSTORE-aware client" and a
"CONDSTORE enabling command".
3. IMAP Protocol Changes
3.1. New OK Untagged Responses for SELECT and EXAMINE
This document adds two new response codes, HIGHESTMODSEQ and
NOMODSEQ. One of those response codes MUST be returned in the OK
untagged response for a successful SELECT/EXAMINE command.
When opening a mailbox, the server must check if the mailbox supports
the persistent storage of mod-sequences. If the mailbox supports the
persistent storage of mod-sequences and the mailbox open operation
succeeds, the server MUST send the OK untagged response including
HIGHESTMODSEQ response code. If the persistent storage for the
mailbox is not supported, the server MUST send the OK untagged
response including NOMODSEQ response code instead.
3.1.1. HIGHESTMODSEQ Response Code
This document adds a new response code that is returned in the OK
untagged response for the SELECT and EXAMINE commands. A server
supporting the persistent storage of mod-sequences for the mailbox
MUST send the OK untagged response including HIGHESTMODSEQ response
code with every successful SELECT or EXAMINE command:
OK [HIGHESTMODSEQ <mod-sequence-value>]
where <mod-sequence-value> is the highest mod-sequence value of
all messages in the mailbox. When the server changes UIDVALIDITY
for a mailbox, it doesn’t have to keep the same HIGHESTMODSEQ for
the mailbox.
A disconnected client can use the value of HIGHESTMODSEQ to check if
it has to refetch metadata from the server. If the UIDVALIDITY value
has changed for the selected mailbox, the client MUST delete the
cached value of HIGHESTMODSEQ. If UIDVALIDITY for the mailbox is the
same, and if the HIGHESTMODSEQ value stored in the client’s cache is
less than the value returned by the server, then some metadata items
on the server have changed since the last synchronization, and the
client needs to update its cache. The client MAY use SEARCH MODSEQ
(Section 3.4) to find out exactly which metadata items have changed.
Alternatively, the client MAY issue FETCH with the CHANGEDSINCE
modifier (Section 3.3.1) in order to fetch data for all messages that
have metadata items changed since some known modification sequence.
Example 1:
C: A142 SELECT INBOX
S: * 172 EXISTS
S: * 1 RECENT
S: * OK [UNSEEN 12] Message 12 is first unseen
S: * OK [UIDVALIDITY 3857529045] UIDs valid
S: * OK [UIDNEXT 4392] Predicted next UID
S: * FLAGS (\Answered \Flagged \Deleted \Seen \Draft)
S: * OK [PERMANENTFLAGS (\Deleted \Seen \*)] Limited
S: * OK [HIGHESTMODSEQ 715194045007]
S: A142 OK [READ-WRITE] SELECT completed
3.1.2. NOMODSEQ Response Code
A server that doesn’t support the persistent storage of mod-sequences
for the mailbox MUST send the OK untagged response including NOMODSEQ
response code with every successful SELECT or EXAMINE command. A
server that returned NOMODSEQ response code for a mailbox, which
subsequently receives one of the following commands while the mailbox
is selected:
- a FETCH command with the CHANGEDSINCE modifier,
- a FETCH or SEARCH command that includes the MODSEQ message data
item, or
- a STORE command with the UNCHANGEDSINCE modifier
MUST reject any such command with the tagged BAD response.
Example 2:
C: A142 SELECT INBOX
S: * 172 EXISTS
S: * 1 RECENT
S: * OK [UNSEEN 12] Message 12 is first unseen
S: * OK [UIDVALIDITY 3857529045] UIDs valid
S: * OK [UIDNEXT 4392] Predicted next UID
S: * FLAGS (\Answered \Flagged \Deleted \Seen \Draft)
S: * OK [PERMANENTFLAGS (\Deleted \Seen \*)] Limited
S: * OK [NOMODSEQ] Sorry, this mailbox format doesn’t support
modsequences
S: A142 OK [READ-WRITE] SELECT completed
3.2. STORE and UID STORE Commands
This document defines the following STORE modifier (see Section 2.5
of [IMAPABNF]):
UNCHANGEDSINCE <mod-sequence>
For each message specified in the message set, the server performs
the following. If the mod-sequence of any metadata item of the
message is equal or less than the specified UNCHANGEDSINCE value,
then the requested operation (as described by the message data
item) is performed. If the operation is successful, the server
MUST update the mod-sequence attribute of the message. An
untagged FETCH response MUST be sent, even if the .SILENT suffix
is specified, and the response MUST include the MODSEQ message
data item. This is required to update the client’s cache with the
correct mod-sequence values. See Section 3.3.2 for more details.
However, if the mod-sequence of any metadata item of the message
is greater than the specified UNCHANGEDSINCE value, then the
requested operation MUST NOT be performed. In this case, the
mod-sequence attribute of the message is not updated, and the
message number (or unique identifier in the case of the UID STORE
command) is added to the list of messages that failed the
UNCHANGESINCE test.
When the server finished performing the operation on all the
messages in the message set, it checks for a non-empty list of
messages that failed the UNCHANGESINCE test. If this list is
non-empty, the server MUST return in the tagged response a
MODIFIED response code. The MODIFIED response code includes the
message set (for STORE) or set of UIDs (for UID STORE) of all
messages that failed the UNCHANGESINCE test.
Example 3:
All messages pass the UNCHANGESINCE test.
C: a103 UID STORE 6,4,8 (UNCHANGEDSINCE 12121230045)
+FLAGS.SILENT (\Deleted)
S: * 1 FETCH (UID 4 MODSEQ (12121231000))
S: * 2 FETCH (UID 6 MODSEQ (12121230852))
S: * 4 FETCH (UID 8 MODSEQ (12121130956))
S: a103 OK Conditional Store completed
Example 4:
C: a104 STORE * (UNCHANGEDSINCE 12121230045) +FLAGS.SILENT
(\Deleted $Processed)
S: * 50 FETCH (MODSEQ (12111230047))
S: a104 OK Store (conditional) completed
Example 5:
C: c101 STORE 1 (UNCHANGEDSINCE 12121230045) -FLAGS.SILENT
(\Deleted)
S: * OK [HIGHESTMODSEQ 12111230047]
S: * 50 FETCH (MODSEQ (12111230048))
S: c101 OK Store (conditional) completed
HIGHESTMODSEQ response code was sent by the server presumably
because this was the first CONDSTORE enabling command.
Example 6:
In spite of the failure of the conditional STORE operation for
message 7, the server continues to process the conditional STORE
in order to find all messages that fail the test.
C: d105 STORE 7,5,9 (UNCHANGEDSINCE 320162338)
+FLAGS.SILENT (\Deleted)
S: * 5 FETCH (MODSEQ (320162350))
S: d105 OK [MODIFIED 7,9] Conditional STORE failed
Example 7:
Same as above, but the server follows the SHOULD recommendation in
Section 6.4.6 of [IMAP4].
C: d105 STORE 7,5,9 (UNCHANGEDSINCE 320162338)
+FLAGS.SILENT (\Deleted)
S: * 7 FETCH (MODSEQ (320162342) FLAGS (\Seen \Deleted))
S: * 5 FETCH (MODSEQ (320162350))
S: * 9 FETCH (MODSEQ (320162349) FLAGS (\Answered))
S: d105 OK [MODIFIED 7,9] Conditional STORE failed
Use of UNCHANGEDSINCE with a modification sequence of 0 always
fails if the metadata item exists. A system flag MUST always be
considered existent, whether it was set or not.
Example 8:
C: a102 STORE 12 (UNCHANGEDSINCE 0)
+FLAGS.SILENT ($MDNSent)
S: a102 OK [MODIFIED 12] Conditional STORE failed
The client has tested the presence of the $MDNSent user-defined
keyword.
Note: A client trying to make an atomic change to the state of a
particular metadata item (or a set of metadata items) should be
prepared to deal with the case when the server returns the MODIFIED
response code if the state of the metadata item being watched hasn’t
changed (but the state of some other metadata item has). This is
necessary, because some servers don’t store separate mod-sequences
for different metadata items. However, a server implementation
SHOULD avoid generating spurious MODIFIED responses for +FLAGS/-FLAGS
STORE operations, even when the server stores a single mod-sequence
per message. Section 5 describes how this can be achieved.
Unless the server has included an unsolicited FETCH to update
client’s knowledge about messages that have failed the UNCHANGEDSINCE
test, upon receipt of the MODIFIED response code, the client SHOULD
try to figure out if the required metadata items have indeed changed
by issuing FETCH or NOOP command. It is RECOMMENDED that the server
avoids the need for the client to do that by sending an unsolicited
FETCH response (Examples 9 and 10).
If the required metadata items haven’t changed, the client SHOULD
retry the command with the new mod-sequence. The client SHOULD allow
for a configurable but reasonable number of retries (at least 2).
Example 9:
In the example below, the server returns the MODIFIED response
code without sending information describing why the STORE
UNCHANGEDSINCE operation has failed.
C: a106 STORE 100:150 (UNCHANGEDSINCE 212030000000)
+FLAGS.SILENT ($Processed)
S: * 100 FETCH (MODSEQ (303181230852))
S: * 102 FETCH (MODSEQ (303181230852))
...
S: * 150 FETCH (MODSEQ (303181230852))
S: a106 OK [MODIFIED 101] Conditional STORE failed
The flag $Processed was set on the message 101...
C: a107 NOOP
S: * 101 FETCH (MODSEQ (303011130956) FLAGS ($Processed))
S: a107 OK
Or the flag hasn’t changed, but another has (note that this server
behaviour is discouraged. Server implementers should also see
Section 5)...
C: b107 NOOP
S: * 101 FETCH (MODSEQ (303011130956) FLAGS (\Deleted \Answered))
S: b107 OK
...and the client retries the operation for the message 101 with
the updated UNCHANGEDSINCE value
C: b108 STORE 101 (UNCHANGEDSINCE 303011130956)
+FLAGS.SILENT ($Processed)
S: * 101 FETCH (MODSEQ (303181230852))
S: b108 OK Conditional Store completed
Example 10:
Same as above, but the server avoids the need for the client to
poll for changes.
The flag $Processed was set on the message 101 by another
client...
C: a106 STORE 100:150 (UNCHANGEDSINCE 212030000000)
+FLAGS.SILENT ($Processed)
S: * 100 FETCH (MODSEQ (303181230852))
S: * 101 FETCH (MODSEQ (303011130956) FLAGS ($Processed))
S: * 102 FETCH (MODSEQ (303181230852))
...
S: * 150 FETCH (MODSEQ (303181230852))
S: a106 OK [MODIFIED 101] Conditional STORE failed
Or the flag hasn’t changed, but another has (note that this server
behaviour is discouraged. Server implementers should also see
Section 5)...
C: a106 STORE 100:150 (UNCHANGEDSINCE 212030000000)
+FLAGS.SILENT ($Processed)
S: * 100 FETCH (MODSEQ (303181230852))
S: * 101 FETCH (MODSEQ (303011130956) FLAGS (\Deleted \Answered))
S: * 102 FETCH (MODSEQ (303181230852))
...
S: * 150 FETCH (MODSEQ (303181230852))
S: a106 OK [MODIFIED 101] Conditional STORE failed
...and the client retries the operation for the message 101 with
the updated UNCHANGEDSINCE value
C: b108 STORE 101 (UNCHANGEDSINCE 303011130956)
+FLAGS.SILENT ($Processed)
S: * 101 FETCH (MODSEQ (303181230852))
S: b108 OK Conditional Store completed
Or the flag hasn’t changed, but another has (nice server
behaviour. Server implementers should also see Section 5)...
C: a106 STORE 100:150 (UNCHANGEDSINCE 212030000000)
+FLAGS.SILENT ($Processed)
S: * 100 FETCH (MODSEQ (303181230852))
S: * 101 FETCH (MODSEQ (303011130956) FLAGS ($Processed \Deleted
\Answered))
S: * 102 FETCH (MODSEQ (303181230852))
...
S: * 150 FETCH (MODSEQ (303181230852))
S: a106 OK Conditional STORE completed
Example 11:
The following example is based on the example from the Section
4.2.3 of [RFC-2180] and demonstrates that the MODIFIED response
code may be also returned in the tagged NO response.
Client tries to conditionally STORE flags on a mixture of expunged
and non-expunged messages; one message fails the UNCHANGEDSINCE
test.
C: B001 STORE 1:7 (UNCHANGEDSINCE 320172338) +FLAGS (\SEEN)
S: * 1 FETCH (MODSEQ (320172342) FLAGS (\SEEN))
S: * 3 FETCH (MODSEQ (320172342) FLAGS (\SEEN))
S: B001 NO [MODIFIED 2] Some of the messages no longer exist.
C: B002 NOOP
S: * 4 EXPUNGE
S: * 4 EXPUNGE
S: * 4 EXPUNGE
S: * 4 EXPUNGE
S: * 2 FETCH (MODSEQ (320172340) FLAGS (\Deleted \Answered))
S: B002 OK NOOP Completed.
By receiving FETCH responses for messages 1 and 3, and EXPUNGE
responses that indicate that messages 4 through 7 have been
expunged, the client retries the operation only for the message 2.
The updated UNCHANGEDSINCE value is used.
C: b003 STORE 2 (UNCHANGEDSINCE 320172340) +FLAGS (\Seen)
S: * 2 FETCH (MODSEQ (320180050))
S: b003 OK Conditional Store completed
Note: If a message is specified multiple times in the message set,
and the server doesn’t internally eliminate duplicates from the
message set, it MUST NOT fail the conditional STORE operation for the
second (or subsequent) occurrence of the message if the operation
completed successfully for the first occurrence. For example, if the
client specifies:
e105 STORE 7,3:9 (UNCHANGEDSINCE 12121230045)
+FLAGS.SILENT (\Deleted)