aboutsummaryrefslogtreecommitdiffstats
path: root/src/notmuchworker.cpp
blob: 2c03226c781bf508fd57542fe1e2b9706cfe97bc (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
1001
1002
1003
1004
1005
1006
1007
1008
1009
1010
1011
1012
1013
1014
1015
1016
1017
1018
1019
1020
/*
 * qtmaildir - a Qt6 mail client for notmuch-indexed Maildirs
 * Copyright (C) 2026 Danilo M. <danix@danix.xyz>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software
 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
 */

#include "notmuchworker.h"

#include <notmuch.h>

#include <QDir>
#include <QDirIterator>
#include <QFileInfo>
#include <QSet>

#include <cstdlib>

#include "mimeparser.h"
#include "nmraii.h"

namespace {

QStringList tagsOf(notmuch_message_t *message)
{
    QStringList result;
    NmTags tags(notmuch_message_get_tags(message));
    for (; notmuch_tags_valid(tags.get()); notmuch_tags_move_to_next(tags.get()))
        result.append(QString::fromUtf8(notmuch_tags_get(tags.get())));
    return result;
}

QStringList tagsOf(notmuch_thread_t *thread)
{
    QStringList result;
    NmTags tags(notmuch_thread_get_tags(thread));
    for (; notmuch_tags_valid(tags.get()); notmuch_tags_move_to_next(tags.get()))
        result.append(QString::fromUtf8(notmuch_tags_get(tags.get())));
    return result;
}

/// Who a thread's messages were addressed to, summarised for one line.
///
/// EXPENSIVE, and only called when a query asks. "To" is not served from
/// notmuch's index, so every call here reads message FILES: 8.7 ms per thread
/// measured against a real database, which is 38 seconds over a 4411-thread
/// inbox. See ThreadSummary::recipients.
///
/// The messages come from the THREAD and are owned by it, freed when it is
/// freed (notmuch.h:1637). They are therefore held raw and never wrapped in
/// NmMessage, which would call notmuch_message_destroy on memory the thread
/// frees again, and the walk finishes before the caller drops the thread. This
/// is the same rule walkReplies follows, and getting it wrong is a double-free
/// rather than a leak.
QString recipientsOf(notmuch_thread_t *thread)
{
    // The first message with a usable To wins. A thread is one conversation,
    // and the alternative, folding every message's recipients together, is the
    // participants-list problem item 2 rejected: it produces a union that
    // misdescribes itself the moment a thread has replies going both ways.
    notmuch_messages_t *messages = notmuch_thread_get_messages(thread);
    for (; notmuch_messages_valid(messages);
         notmuch_messages_move_to_next(messages)) {
        notmuch_message_t *message = notmuch_messages_get(messages);
        if (!message)
            continue;

        // Returns "" for a missing header and NULL on error, and the two mean
        // different things only to notmuch: both are "nothing to show" here.
        const char *to = notmuch_message_get_header(message, "To");
        if (!to || !*to)
            continue;

        const QString summary = recipientSummary(QString::fromUtf8(to));
        if (!summary.isEmpty())
            return summary;
    }
    return QString();
}

/// Collects the message ids a query matches. Returns false if the query could
/// not be run at all, which is different from a query that matched nothing.
bool collectMessageIds(notmuch_database_t *db, const QString &query,
                       QStringList *ids)
{
    NmQuery nmQuery(notmuch_query_create(db, query.toUtf8().constData()));
    if (!nmQuery)
        return false;

    notmuch_messages_t *raw = nullptr;
    if (notmuch_query_search_messages(nmQuery.get(), &raw) != NOTMUCH_STATUS_SUCCESS)
        return false;

    NmMessages messages(raw);
    for (; notmuch_messages_valid(messages.get());
           notmuch_messages_move_to_next(messages.get())) {
        NmMessage message(notmuch_messages_get(messages.get()));
        if (message)
            ids->append(QString::fromUtf8(notmuch_message_get_message_id(message.get())));
    }
    return true;
}

/// Walks a thread's reply structure depth-first, appending each message with
/// its depth.
///
/// Takes RAW notmuch_message_t*, deliberately, against the rule that every
/// handle in this file is RAII-owned. Messages reached through a thread belong
/// to that thread and are freed with it (notmuch.h:1637), so wrapping one in
/// NmMessage would call notmuch_message_destroy on memory the thread frees
/// again. The NmThread in the caller is what keeps every pointer here alive,
/// and this must not outlive it.
///
/// No match-set argument, unlike loadThread. A row is drawn for every message
/// in the thread regardless of the query: the list is where the user goes to
/// SEE the thread's shape, and hiding replies that did not match would make the
/// reply count disagree with the rows beneath it.
void walkReplies(notmuch_messages_t *messages, int depth,
                 QVector<MessageNode> *out)
{
    for (; notmuch_messages_valid(messages);
           notmuch_messages_move_to_next(messages)) {

        notmuch_message_t *message = notmuch_messages_get(messages);
        if (!message)
            continue;

        MessageNode node;
        node.messageId =
            QString::fromUtf8(notmuch_message_get_message_id(message));
        node.threadId =
            QString::fromUtf8(notmuch_message_get_thread_id(message));
        node.filePath =
            QString::fromUtf8(notmuch_message_get_filename(message));
        node.from =
            QString::fromUtf8(notmuch_message_get_header(message, "from"));
        node.subject =
            QString::fromUtf8(notmuch_message_get_header(message, "subject"));
        node.date =
            QDateTime::fromSecsSinceEpoch(notmuch_message_get_date(message));
        node.tags = tagsOf(message);
        node.depth = depth;
        out->append(node);

        // NULL is a legitimate "no replies" here: notmuch_messages_valid
        // accepts it and returns FALSE (notmuch.h:1630), so a leaf needs no
        // guard of its own.
        walkReplies(notmuch_message_get_replies(message), depth + 1, out);
    }
}

/// The Maildir FOLDER a message file sits in, relative to the database root.
///
/// `<root>/acct/inbox/cur/12345` becomes `acct/inbox`: the `cur`/`new` segment
/// is stripped because it is Maildir's read-state bookkeeping rather than part
/// of the folder's name, and moveMessages() takes a folder without one. That
/// makes the value round-trip: what comes out here can be handed straight back
/// to move a message home.
///
/// Empty when the file is not under the root at all, which the caller treats as
/// "origin unknown" rather than guessing. A wrong folder here would send a
/// restored message somewhere the user never had it.
QString folderOfMessageFile(const QString &root, const QString &filePath)
{
    const QString rootPath = QDir(root).absolutePath();
    const QString dir = QFileInfo(filePath).absolutePath();

    const QString relative = QDir(rootPath).relativeFilePath(dir);
    // relativeFilePath happily walks upwards, so a path outside the root comes
    // back as `../something` rather than as a failure.
    if (relative.isEmpty() || relative == QStringLiteral(".")
        || relative.startsWith(QStringLiteral("../"))) {
        return QString();
    }

    QStringList parts = relative.split(QLatin1Char('/'), Qt::SkipEmptyParts);
    if (!parts.isEmpty()
        && (parts.last() == QStringLiteral("cur")
            || parts.last() == QStringLiteral("new"))) {
        parts.removeLast();
    }
    return parts.join(QLatin1Char('/'));
}

} // namespace

/// Registers SortOrder for queued calls, once, before main() runs.
///
/// Q_ENUM alone is NOT enough for a queued Q_ARG: it gives the enum a
/// meta-object entry, not a metatype registered under the name invokeMethod
/// resolves, so MainWindow's queued runQuery would drop its sort argument at
/// runtime with a warning and every query would silently run newest-first.
///
/// Here rather than in MainWindow's constructor, because the registration
/// belongs to the type rather than to one consumer: a caller that never
/// constructs a MainWindow (a test, or a future headless mode) needs it too,
/// and that is exactly how the first attempt at this passed by accident and
/// failed under test.
static const int kSortOrderMetaType =
    qRegisterMetaType<NotmuchWorker::SortOrder>("NotmuchWorker::SortOrder");

NotmuchWorker::NotmuchWorker(const QString &notmuchConfigPath, QObject *parent)
    : QObject(parent), m_configPath(notmuchConfigPath)
{
    Q_UNUSED(kSortOrderMetaType);
}

NotmuchWorker::~NotmuchWorker()
{
    close();
}

/// An empty config path means "let notmuch resolve its own config", which
/// libnotmuch spells as NULL. The QByteArray is returned by value so callers
/// keep it alive for as long as they use constData().
QByteArray NotmuchWorker::configPathArg() const
{
    return m_configPath.isEmpty() ? QByteArray() : m_configPath.toLocal8Bit();
}

bool NotmuchWorker::openReadOnly()
{
    if (m_db)
        return true;

    const QByteArray configPath = configPathArg();
    char *error = nullptr;
    const notmuch_status_t status = notmuch_database_open_with_config(
        nullptr,                                        // let config decide path
        NOTMUCH_DATABASE_MODE_READ_ONLY,
        configPath.isEmpty() ? nullptr : configPath.constData(),
        nullptr,
        &m_db,
        &error);

    if (status != NOTMUCH_STATUS_SUCCESS) {
        emit errorOccurred(QStringLiteral("Cannot open notmuch database: %1")
            .arg(QString::fromUtf8(error ? error : notmuch_status_to_string(status))));
        free(error);
        m_db = nullptr;
        return false;
    }
    return true;
}

void NotmuchWorker::close()
{
    if (m_db) {
        notmuch_database_destroy(m_db);
        m_db = nullptr;
    }
}

void NotmuchWorker::runQuery(const QString &query, quint64 generation,
                             SortOrder sort, bool withRecipients)
{
    if (!openReadOnly())
        return;

    NmQuery nmQuery(notmuch_query_create(m_db, query.toUtf8().constData()));
    if (!nmQuery) {
        emit errorOccurred(QStringLiteral("Invalid query: %1").arg(query));
        return;
    }
    notmuch_query_set_sort(nmQuery.get(),
                           sort == OldestFirst ? NOTMUCH_SORT_OLDEST_FIRST
                                               : NOTMUCH_SORT_NEWEST_FIRST);

    notmuch_threads_t *rawThreads = nullptr;
    const notmuch_status_t status =
        notmuch_query_search_threads(nmQuery.get(), &rawThreads);
    if (status != NOTMUCH_STATUS_SUCCESS) {
        emit errorOccurred(QStringLiteral("Query failed: %1")
            .arg(QString::fromUtf8(notmuch_status_to_string(status))));
        return;
    }
    NmThreads threads(rawThreads);

    // Message paths are reported RELATIVE to this. An absolute path would be
    // useless to the UI, which knows accounts only by their maildir, a
    // database-relative prefix: comparing the two never matched and left every
    // row resolving to no account at all.
    const QString dbRoot =
        QDir(QString::fromUtf8(notmuch_database_get_path(m_db))).absolutePath();

    QVector<ThreadSummary> batch;
    batch.reserve(kBatchSize);
    int total = 0;

    for (; notmuch_threads_valid(threads.get());
           notmuch_threads_move_to_next(threads.get())) {

        NmThread thread(notmuch_threads_get(threads.get()));
        if (!thread)
            continue;

        ThreadSummary summary;
        summary.threadId = QString::fromUtf8(notmuch_thread_get_thread_id(thread.get()));
        summary.subject = QString::fromUtf8(notmuch_thread_get_subject(thread.get()));
        summary.authors = QString::fromUtf8(notmuch_thread_get_authors(thread.get()));
        summary.date = QDateTime::fromSecsSinceEpoch(
            notmuch_thread_get_newest_date(thread.get()));
        summary.totalCount = notmuch_thread_get_total_messages(thread.get());
        summary.matchedCount = notmuch_thread_get_matched_messages(thread.get());
        summary.tags = tagsOf(thread.get());
        if (withRecipients)
            summary.recipients = recipientsOf(thread.get());

        // The message the row's card stands for. Raw pointers on purpose:
        // messages reached through a thread are owned by the THREAD and freed
        // with it (notmuch.h:1637), so an NmMessage wrapper here would destroy
        // memory the thread frees again. Everything must be read while
        // `thread` is alive, which it is for the rest of this iteration.
        //
        // Index-only, so it costs nothing measurable: see
        // ThreadSummary::firstMessageId.
        //
        // Two different questions, and the Sent view asks the second one. A
        // normal row stands for the thread's OPENING message. A Sent row
        // stands for what the USER sent, usually a reply and often not the
        // opening message at all, so it takes the first message the query
        // MATCHED. withRecipients is exactly the Sent query, which is why it
        // selects between them rather than carrying a second flag that could
        // disagree with it.
        //
        // Note notmuch_thread_get_matched_messages returns a COUNT, not an
        // iterator; there is no matched-messages list. The match state is a
        // per-message flag, so the Sent branch walks in oldest-first order and
        // stops at the first match. Measured at 0.146s against a 0.143s
        // baseline over 4,515 threads: the walk stops early and reads the
        // index, so it is as free as the toplevel call.
        if (withRecipients) {
            notmuch_messages_t *all = notmuch_thread_get_messages(thread.get());
            for (; all && notmuch_messages_valid(all);
                   notmuch_messages_move_to_next(all)) {
                notmuch_message_t *message = notmuch_messages_get(all);
                if (!message)
                    continue;
                notmuch_bool_t matched = FALSE;
                notmuch_message_get_flag_st(message,
                                            NOTMUCH_MESSAGE_FLAG_MATCH,
                                            &matched);
                if (matched) {
                    summary.firstMessageId = QString::fromUtf8(
                        notmuch_message_get_message_id(message));
                    // The card's own tags, beside the thread's union above.
                    // Same walk, same index read, no extra query.
                    summary.firstMessageTags = tagsOf(message);
                    // Which account this belongs to, for Delete's destination.
                    summary.firstMessagePath = QDir(dbRoot).relativeFilePath(
                        QString::fromUtf8(
                            notmuch_message_get_filename(message)));
                    break;
                }
            }
        } else if (notmuch_messages_t *top =
                       notmuch_thread_get_toplevel_messages(thread.get())) {
            if (notmuch_messages_valid(top)) {
                if (notmuch_message_t *first = notmuch_messages_get(top)) {
                    summary.firstMessageId = QString::fromUtf8(
                        notmuch_message_get_message_id(first));
                    // The card's own tags, beside the thread's union above.
                    // Same walk, same index read, no extra query.
                    summary.firstMessageTags = tagsOf(first);
                    // Which account this belongs to, for Delete's destination.
                    summary.firstMessagePath = QDir(dbRoot).relativeFilePath(
                        QString::fromUtf8(
                            notmuch_message_get_filename(first)));
                }
            }
        }

        batch.append(summary);
        ++total;

        if (batch.size() >= kBatchSize) {
            emit threadsReady(batch, generation);
            batch.clear();
            batch.reserve(kBatchSize);
        }
    }

    if (!batch.isEmpty())
        emit threadsReady(batch, generation);

    emit queryFinished(total, generation);
}

void NotmuchWorker::loadThread(const QString &threadId,
                               const QString &matchQuery,
                               quint64 generation, bool matchedOnly)
{
    if (!openReadOnly())
        return;

    // Which messages of the thread matched the user's query. Running the query
    // intersected with the thread is cheaper than testing each message.
    //
    // haveMatchSet distinguishes "no query was given, so everything counts as
    // matched" from "a query was given and matched nothing in this thread".
    // Collapsing those would render a whole thread expanded precisely when the
    // user filtered it down to nothing.
    QSet<QString> matchedIds;
    bool haveMatchSet = false;
    if (!matchQuery.trimmed().isEmpty()) {
        const QString intersect =
            QStringLiteral("thread:%1 and (%2)").arg(threadId, matchQuery);
        QStringList ids;
        if (collectMessageIds(m_db, intersect, &ids)) {
            matchedIds = QSet<QString>(ids.begin(), ids.end());
            haveMatchSet = true;
        }
    }

    const QString query = QStringLiteral("thread:%1").arg(threadId);
    NmQuery nmQuery(notmuch_query_create(m_db, query.toUtf8().constData()));
    if (!nmQuery) {
        emit errorOccurred(QStringLiteral("Cannot load thread %1").arg(threadId));
        return;
    }
    notmuch_query_set_sort(nmQuery.get(), NOTMUCH_SORT_OLDEST_FIRST);

    notmuch_messages_t *rawMessages = nullptr;
    if (notmuch_query_search_messages(nmQuery.get(), &rawMessages)
            != NOTMUCH_STATUS_SUCCESS) {
        emit errorOccurred(QStringLiteral("Cannot search thread %1").arg(threadId));
        return;
    }
    NmMessages messages(rawMessages);

    QVector<MessageRef> result;
    for (; notmuch_messages_valid(messages.get());
           notmuch_messages_move_to_next(messages.get())) {

        NmMessage message(notmuch_messages_get(messages.get()));
        if (!message)
            continue;

        MessageRef ref;
        ref.messageId = QString::fromUtf8(notmuch_message_get_message_id(message.get()));
        ref.filePath = QString::fromUtf8(notmuch_message_get_filename(message.get()));
        ref.tags = tagsOf(message.get());
        ref.matched = !haveMatchSet || matchedIds.contains(ref.messageId);

        // Dropped rather than rendered as a stub.
        //
        // haveMatchSet is redundant here and kept deliberately: ref.matched is
        // already true for every message when no query was given, so the two
        // conditions cannot disagree today. It states the invariant this
        // depends on at the point that depends on it, so a later change to how
        // ref.matched is computed cannot silently empty the pane.
        if (matchedOnly && haveMatchSet && !ref.matched)
            continue;

        result.append(ref);
    }

    emit threadLoaded(result, generation);
}

void NotmuchWorker::loadThreadTree(const QString &threadId,
                                   const QString &matchQuery,
                                   quint64 generation)
{
    // Accepted for signature symmetry with loadThread, and unused on purpose:
    // see walkReplies on why every message in the thread gets a row.
    Q_UNUSED(matchQuery);

    if (!openReadOnly())
        return;

    const QString query = QStringLiteral("thread:%1").arg(threadId);
    NmQuery nmQuery(notmuch_query_create(m_db, query.toUtf8().constData()));
    if (!nmQuery) {
        emit errorOccurred(
            QStringLiteral("Cannot load thread %1").arg(threadId));
        return;
    }

    // search_threads, not search_messages. The messages have to come from a
    // notmuch_thread_t or notmuch_message_get_replies returns NULL for every
    // one of them and the walk below produces a flat list at depth 0.
    notmuch_threads_t *rawThreads = nullptr;
    if (notmuch_query_search_threads(nmQuery.get(), &rawThreads)
            != NOTMUCH_STATUS_SUCCESS) {
        emit errorOccurred(
            QStringLiteral("Cannot search thread %1").arg(threadId));
        return;
    }
    NmThreads threads(rawThreads);

    QVector<MessageNode> nodes;
    if (notmuch_threads_valid(threads.get())) {
        // Held for the whole walk: every message pointer inside belongs to this
        // thread and dies with it.
        NmThread thread(notmuch_threads_get(threads.get()));
        if (thread) {
            walkReplies(notmuch_thread_get_toplevel_messages(thread.get()), 0,
                        &nodes);
        }
    }

    emit threadTreeLoaded(nodes, generation);
}

void NotmuchWorker::loadMessage(const QString &messageId, quint64 generation)
{
    if (!openReadOnly())
        return;

    // id: is an exact-match prefix, and the id is quoted because a message id
    // can legitimately contain characters notmuch's parser would otherwise read
    // as query syntax.
    const QString query = QStringLiteral("id:\"%1\"").arg(messageId);
    NmQuery nmQuery(notmuch_query_create(m_db, query.toUtf8().constData()));
    if (!nmQuery) {
        emit errorOccurred(
            QStringLiteral("Cannot load message %1").arg(messageId));
        return;
    }

    notmuch_messages_t *rawMessages = nullptr;
    if (notmuch_query_search_messages(nmQuery.get(), &rawMessages)
            != NOTMUCH_STATUS_SUCCESS) {
        emit errorOccurred(
            QStringLiteral("Cannot search message %1").arg(messageId));
        return;
    }
    NmMessages messages(rawMessages);

    QVector<MessageRef> result;
    if (notmuch_messages_valid(messages.get())) {
        NmMessage message(notmuch_messages_get(messages.get()));
        if (message) {
            MessageRef ref;
            ref.messageId = QString::fromUtf8(
                notmuch_message_get_message_id(message.get()));
            ref.filePath = QString::fromUtf8(
                notmuch_message_get_filename(message.get()));
            ref.tags = tagsOf(message.get());

            // Always matched: the user asked for this message by clicking its
            // row, so rendering it as a stub would answer the wrong question.
            ref.matched = true;
            result.append(ref);
        }
    }

    // Emitted even when empty, so the UI's handler runs and can decide what to
    // do rather than waiting for a reply that never comes.
    emit messageLoaded(result, generation);
}

void NotmuchWorker::applyTagsToThreads(const QStringList &threadIds,
                                       const QStringList &add,
                                       const QStringList &remove,
                                       const QString &description)
{
    if (threadIds.isEmpty())
        return;

    if (!openReadOnly())
        return;

    // Resolve every thread to its message ids in ONE query. Issuing a query per
    // thread would reopen the same Xapian cursor hundreds of times on a large
    // selection.
    QStringList terms;
    terms.reserve(threadIds.size());
    for (const QString &id : threadIds)
        terms.append(QStringLiteral("thread:%1").arg(id));

    QStringList messageIds;
    if (!collectMessageIds(m_db, terms.join(QStringLiteral(" or ")), &messageIds)) {
        emit errorOccurred(QStringLiteral("Cannot resolve selected threads"));
        return;
    }

    if (messageIds.isEmpty()) {
        emit errorOccurred(QStringLiteral("Selected threads contain no messages"));
        return;
    }

    applyTags(TagChange{ messageIds, add, remove, description });
}

void NotmuchWorker::applyTags(const TagChange &change)
{
    if (change.messageIds.isEmpty())
        return;

    // The read-only handle must be closed first: notmuch allows only one open
    // handle per process.
    close();

    const QByteArray configPath = configPathArg();
    notmuch_database_t *db = nullptr;
    char *error = nullptr;
    const notmuch_status_t status = notmuch_database_open_with_config(
        nullptr,
        NOTMUCH_DATABASE_MODE_READ_WRITE,
        configPath.isEmpty() ? nullptr : configPath.constData(),
        nullptr,
        &db,
        &error);

    if (status != NOTMUCH_STATUS_SUCCESS) {
        // NOT reached by lock contention, despite the wording. Measured
        // 2026-08-04: this call BLOCKS on a held write lock and then returns
        // SUCCESS (9.158s against a 12s hold), so a running sync never lands
        // here. What does land here is a genuinely broken open: bad
        // permissions, a corrupt index, a missing database. None of those are
        // helped by waiting, so the UI reverts rather than retrying.
        //
        // The stall a running sync DOES cause is avoided upstream, in
        // MainWindow, by not sending the write at all while the lock is held.
        emit errorOccurred(
            QStringLiteral("Cannot open database for writing: %1")
                .arg(QString::fromUtf8(error ? error
                                             : notmuch_status_to_string(status))));
        free(error);
        return;
    }

    for (const QString &id : change.messageIds) {
        notmuch_message_t *raw = nullptr;
        // find_message reports SUCCESS with a null message when the id is not
        // in the database, so both have to be checked. A stale id must not
        // abort the batch: the live ids alongside it still need tagging.
        if (notmuch_database_find_message(db, id.toUtf8().constData(), &raw)
                != NOTMUCH_STATUS_SUCCESS || !raw) {
            continue;
        }
        NmMessage message(raw);

        notmuch_message_freeze(message.get());
        for (const QString &tag : change.removed)
            notmuch_message_remove_tag(message.get(), tag.toUtf8().constData());
        for (const QString &tag : change.added)
            notmuch_message_add_tag(message.get(), tag.toUtf8().constData());
        notmuch_message_thaw(message.get());

        // Renames the file on disk when the seen/flagged tags changed, keeping
        // the Maildir and the index in agreement for the next `notmuch new`.
        notmuch_message_tags_to_maildir_flags(message.get());
    }

    notmuch_database_close(db);
    notmuch_database_destroy(db);

    emit tagsApplied(change);
}

void NotmuchWorker::moveMessages(const QStringList &messageIds,
                                 const QString &destFolder)
{
    if (messageIds.isEmpty() || destFolder.isEmpty())
        return;

    // The read-only handle must be closed first: notmuch allows only one open
    // handle per process. Same ordering as applyTags, for the same reason.
    close();

    const QByteArray configPath = configPathArg();
    notmuch_database_t *db = nullptr;
    char *error = nullptr;
    const notmuch_status_t status = notmuch_database_open_with_config(
        nullptr,
        NOTMUCH_DATABASE_MODE_READ_WRITE,
        configPath.isEmpty() ? nullptr : configPath.constData(),
        nullptr,
        &db,
        &error);

    if (status != NOTMUCH_STATUS_SUCCESS) {
        emit errorOccurred(
            QStringLiteral("Cannot open database for writing: %1")
                .arg(QString::fromUtf8(error ? error
                                             : notmuch_status_to_string(status))));
        free(error);
        return;
    }

    const QString root = QString::fromUtf8(notmuch_database_get_path(db));
    const QString destDir =
        root + QLatin1Char('/') + destFolder + QStringLiteral("/cur");

    QStringList moved;
    QMap<QString, QString> origins;
    for (const QString &id : messageIds) {
        notmuch_message_t *raw = nullptr;
        // find_message reports SUCCESS with a null message when the id is not
        // in the database, so both have to be checked. A stale id must not
        // abort the batch: the live ids alongside it still need moving.
        if (notmuch_database_find_message(db, id.toUtf8().constData(), &raw)
                != NOTMUCH_STATUS_SUCCESS || !raw) {
            continue;
        }
        NmMessage message(raw);

        const char *rawName = notmuch_message_get_filename(message.get());
        if (!rawName)
            continue;
        const QString from = QString::fromUtf8(rawName);
        // The handle is released before the file moves under it.
        message.reset();

        // Where it is coming FROM, captured here because this is the only
        // moment the old filename exists. See messagesMovedFrom().
        const QString origin = folderOfMessageFile(root, from);

        // cur/, never new/. A file dropped in new/ is re-announced as fresh
        // mail by every reader of the Maildir.
        if (!QDir().mkpath(destDir)) {
            emit errorOccurred(QStringLiteral("Cannot create folder %1")
                                   .arg(destDir));
            continue;
        }

        const QString to = destDir + QLatin1Char('/') + QFileInfo(from).fileName();
        if (from == to) {
            // Already where it was asked to go. Reported as moved, since the
            // caller's request is satisfied.
            moved.append(id);
            origins.insert(id, origin);
            continue;
        }

        if (!QFile::rename(from, to)) {
            emit errorOccurred(QStringLiteral("Cannot move %1 to %2")
                                   .arg(QFileInfo(from).fileName(), destFolder));
            continue;
        }

        // Index the NEW path BEFORE dropping the old one. The reverse order
        // removes the last filename for this message id, which deletes the
        // database entry and every tag on it; the file then reindexes as a
        // brand new message with default tags, silently.
        notmuch_message_t *indexed = nullptr;
        const notmuch_status_t added = notmuch_database_index_file(
            db, to.toUtf8().constData(), nullptr, &indexed);
        if (indexed)
            notmuch_message_destroy(indexed);

        // DUPLICATE_MESSAGE_ID is success here: it means the id was already
        // known, which is exactly the case for a file this just moved.
        if (added != NOTMUCH_STATUS_SUCCESS
            && added != NOTMUCH_STATUS_DUPLICATE_MESSAGE_ID) {
            QFile::rename(to, from);
            emit errorOccurred(QStringLiteral("Cannot index %1 at its new path: %2")
                                   .arg(id, QString::fromUtf8(
                                                notmuch_status_to_string(added))));
            continue;
        }

        notmuch_database_remove_message(db, from.toUtf8().constData());
        moved.append(id);
        origins.insert(id, origin);
    }

    notmuch_database_close(db);
    notmuch_database_destroy(db);

    emit messagesMoved(moved, destFolder);
    emit messagesMovedFrom(origins, destFolder);
}

void NotmuchWorker::resolveMessages(const QStringList &messageIds,
                                   const QString &requestTag)
{
    if (messageIds.isEmpty())
        return;

    QStringList terms;
    terms.reserve(messageIds.size());
    for (const QString &id : messageIds)
        terms.append(QStringLiteral("id:%1").arg(id));

    resolveQuery(terms.join(QStringLiteral(" or ")), requestTag);
}

void NotmuchWorker::resolveThreadMessages(const QStringList &threadIds,
                                          const QString &requestTag)
{
    if (threadIds.isEmpty())
        return;

    // One combined query, for the reason applyTagsToThreads() gives: a query
    // per thread reopens the same Xapian cursor once per selected row.
    QStringList terms;
    terms.reserve(threadIds.size());
    for (const QString &id : threadIds)
        terms.append(QStringLiteral("thread:%1").arg(id));

    resolveQuery(terms.join(QStringLiteral(" or ")), requestTag);
}

void NotmuchWorker::resolveQuery(const QString &query,
                                 const QString &requestTag)
{
    if (!openReadOnly())
        return;

    NmQuery nmQuery(notmuch_query_create(m_db, query.toUtf8().constData()));
    if (!nmQuery) {
        emit errorOccurred(QStringLiteral("Cannot resolve selected threads"));
        return;
    }

    notmuch_messages_t *raw = nullptr;
    if (notmuch_query_search_messages(nmQuery.get(), &raw)
        != NOTMUCH_STATUS_SUCCESS) {
        emit errorOccurred(QStringLiteral("Cannot resolve selected threads"));
        return;
    }

    // Paths are reported RELATIVE to the database root, matching
    // ThreadSummary::firstMessagePath: the UI knows accounts only by their
    // maildir, itself a database-relative prefix.
    const QString dbRoot =
        QDir(QString::fromUtf8(notmuch_database_get_path(m_db))).absolutePath();

    QStringList messageIds;
    QStringList paths;
    QStringList tags;
    NmMessages messages(raw);
    for (; notmuch_messages_valid(messages.get());
           notmuch_messages_move_to_next(messages.get())) {
        NmMessage message(notmuch_messages_get(messages.get()));
        if (!message)
            continue;
        const char *rawName = notmuch_message_get_filename(message.get());
        if (!rawName)
            continue;
        messageIds.append(
            QString::fromUtf8(notmuch_message_get_message_id(message.get())));
        paths.append(
            QDir(dbRoot).relativeFilePath(QString::fromUtf8(rawName)));
        // Joined by a TAB, not a space. A notmuch tag may absolutely contain
        // a space: a Maildir folder named "Inbox/SlackBuilds users" produces
        // `deleted-from:Inbox/SlackBuilds users`, and splitting that on spaces
        // truncated the folder to "Inbox/SlackBuilds". Restore then moved the
        // messages into a folder of that name, CREATING it, so four real
        // messages ended up in a directory mbsync does not sync and the user
        // could not find them. A tab cannot appear in a tag, because notmuch's
        // own dump/restore format is whitespace-delimited by line.
        tags.append(tagsOf(message.get()).join(QLatin1Char('\t')));
    }

    emit threadMessagesResolved(messageIds, paths, tags, requestTag);
}

void NotmuchWorker::requestAllTags(quint64 generation)
{
    if (!openReadOnly())
        return;

    NmTags tags(notmuch_database_get_all_tags(m_db));
    if (!tags) {
        emit errorOccurred(QStringLiteral("Cannot list tags"));
        return;
    }

    QStringList result;
    for (; notmuch_tags_valid(tags.get()); notmuch_tags_move_to_next(tags.get()))
        result.append(QString::fromUtf8(notmuch_tags_get(tags.get())));

    // Sorted once here so no consumer has to sort again. notmuch returns tags
    // in Xapian term order, which is byte order, not the user's locale order.
    result.sort();
    emit allTagsReady(result, generation);
}

void NotmuchWorker::requestDatabaseStats(quint64 generation)
{
    if (!openReadOnly())
        return;

    DatabaseStats stats;

    // "*" is notmuch's match-everything query. Counting messages and threads
    // needs two calls on it: the numbers differ by the reply depth of the
    // database and there is no single call that yields both.
    NmQuery all(notmuch_query_create(m_db, "*"));
    if (all) {
        unsigned int messages = 0;
        if (notmuch_query_count_messages(all.get(), &messages)
            == NOTMUCH_STATUS_SUCCESS) {
            stats.messages = static_cast<int>(messages);
        }
    }

    // A second query object rather than reusing the one above: notmuch caches
    // results on a query, and counting both ways from one has bitten people.
    NmQuery allThreads(notmuch_query_create(m_db, "*"));
    if (allThreads) {
        unsigned int threads = 0;
        if (notmuch_query_count_threads(allThreads.get(), &threads)
            == NOTMUCH_STATUS_SUCCESS) {
            stats.threads = static_cast<int>(threads);
        }
    }

    // Already enumerated for the completer, so this costs nothing extra.
    NmTags tags(notmuch_database_get_all_tags(m_db));
    if (tags) {
        int count = 0;
        for (; notmuch_tags_valid(tags.get()); notmuch_tags_move_to_next(tags.get()))
            ++count;
        stats.tags = count;
    }

    emit databaseStatsReady(stats, generation);
}

void NotmuchWorker::requestCounts(const QStringList &queries, quint64 generation)
{
    if (!openReadOnly())
        return;

    QVector<int> counts;
    counts.reserve(queries.size());

    for (const QString &query : queries) {
        NmQuery nmQuery(notmuch_query_create(m_db, query.toUtf8().constData()));

        unsigned int count = 0;
        // -1 rather than a skipped entry: the caller pairs these with its own
        // labels positionally, so a dropped answer would put a real number
        // against the wrong name, which is worse than showing none.
        if (!nmQuery ||
            notmuch_query_count_threads(nmQuery.get(), &count)
                != NOTMUCH_STATUS_SUCCESS) {
            counts.append(-1);
            continue;
        }

        // Threads, matching what the thread list shows. A message count would
        // disagree with the number of rows a click on this line produces.
        counts.append(static_cast<int>(count));
    }

    emit countsReady(counts, generation);
}

void NotmuchWorker::requestMessageCounts(const QStringList &queries,
                                         quint64 generation)
{
    if (!openReadOnly())
        return;

    QVector<int> counts;
    counts.reserve(queries.size());

    for (const QString &query : queries) {
        NmQuery nmQuery(notmuch_query_create(m_db, query.toUtf8().constData()));

        unsigned int count = 0;
        // -1 rather than a skipped entry, matching requestCounts: the caller
        // pairs these with its own rules positionally, so a dropped answer
        // would put a real number against the wrong rule.
        if (!nmQuery ||
            notmuch_query_count_messages(nmQuery.get(), &count)
                != NOTMUCH_STATUS_SUCCESS) {
            counts.append(-1);
            continue;
        }

        // Messages, not threads: a rule tags messages, so counting threads
        // would understate a rule matching part of a large thread.
        counts.append(static_cast<int>(count));
    }

    emit messageCountsReady(counts, generation);
}

void NotmuchWorker::requestFolders()
{
    if (!openReadOnly())
        return;

    const QString root = QString::fromUtf8(notmuch_database_get_path(m_db));
    if (root.isEmpty()) {
        emit errorOccurred(
            QStringLiteral("notmuch reports no database path."));
        return;
    }

    // A Maildir folder is a directory holding cur/. Testing for that rather
    // than listing every directory keeps the plumbing (cur, new, tmp) and an
    // account's container directory out of the list; neither is somewhere mail
    // is filed. Hidden directories are skipped, which is what excludes
    // .notmuch itself.
    QStringList folders;
    QDirIterator it(root, QDir::Dirs | QDir::NoDotAndDotDot,
                    QDirIterator::Subdirectories);
    const QDir rootDir(root);
    while (it.hasNext()) {
        const QString path = it.next();
        if (!QFileInfo::exists(path + QStringLiteral("/cur")))
            continue;
        folders.append(rootDir.relativeFilePath(path));
    }

    // Sorted, so the dropdown keeps one order across openings. QDirIterator
    // walks in filesystem order, which is neither stable nor alphabetical.
    folders.sort();
    emit foldersReady(folders);
}