mail-storage-service.c revision 39f5c2b2143842ff6f827b7198cae8853b8c5bba
e59faf65ce864fe95dc00f5d52b8323cdbd0608aTimo Sirainen/* Copyright (c) 2009-2015 Dovecot authors, see the included COPYING file */
bca919b207e27d0d08b431bdb0f2ac099ef8b512Timo Sirainen/* If time moves backwards more than this, kill ourself instead of sleeping. */
bca919b207e27d0d08b431bdb0f2ac099ef8b512Timo Sirainen "Invalid user settings. Refer to server log for more information."
3b32bc12710240f86465a00fbb2bd1ef030e6c40Timo Sirainen struct auth_master_connection *conn, *iter_conn;
d22301419109ed4a38351715e6760011421dadecTimo Sirainen const char *set_cache_module, *set_cache_service;
d22301419109ed4a38351715e6760011421dadecTimo Sirainen struct master_service_settings_cache *set_cache;
d22301419109ed4a38351715e6760011421dadecTimo Sirainen const char *const **userdb_next_fieldsp;
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen const char *log_prefix, *auth_token, *auth_user;
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen const char *system_groups_user, *uid_source, *gid_source;
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainenstruct module *mail_storage_service_modules = NULL;
4b2a4c8c762e3eaddf7fd2abfe7d4cca6e5e3fd8Timo Sirainenmail_user_set_get_mail_debug(const struct setting_parser_info *user_info,
4b2a4c8c762e3eaddf7fd2abfe7d4cca6e5e3fd8Timo Sirainen mail_set = mail_user_set_get_driver_settings(user_info, user_set,
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainenstatic void set_keyval(struct mail_storage_service_ctx *ctx,
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen struct setting_parser_context *set_parser = user->set_parser;
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen const char *str;
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen if (master_service_set_has_config_override(ctx->service, key)) {
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen /* this setting was already overridden with -o parameter */
4b2a4c8c762e3eaddf7fd2abfe7d4cca6e5e3fd8Timo Sirainen if (mail_user_set_get_mail_debug(user->user_info,
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen i_debug("Ignoring overridden (-o) userdb setting: %s",
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen if (settings_parse_line(set_parser, str) < 0) {
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainenstatic int set_line(struct mail_storage_service_ctx *ctx,
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen struct setting_parser_context *set_parser = user->set_parser;
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen const char *key, *orig_key, *append_value = NULL;
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen unsigned int len;
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen mail_debug = mail_user_set_get_mail_debug(user->user_info,
547e916f4e6f01af682f8b6e032c337f2a699364Timo Sirainen /* key+=value */
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen if (!settings_parse_is_valid_key(set_parser, key)) {
46219292a55094fa49aae33eee681ed075d30e17Timo Sirainen /* assume it's a plugin setting */
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen if (master_service_set_has_config_override(ctx->service, key)) {
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen /* this setting was already overridden with -o parameter */
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen i_debug("Ignoring overridden (-o) userdb setting: %s",
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen value = settings_parse_get_value(set_parser, key, &type);
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen "'+' can only be used for strings.", orig_key);
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen /* possibly a password field (e.g. imapc_password).
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen hide the value. */
888ab4e17f7441b4dcca4a01886d055b57f4586dTimo Sirainen "Unknown userdb setting: %s" :
5b62dea2f88165f3f4d87bba9011343f3ff415ffTimo Sirainenstatic bool validate_chroot(const struct mail_user_settings *user_set,
5b62dea2f88165f3f4d87bba9011343f3ff415ffTimo Sirainen const char *dir)
fbd918f47f591f8084fd52b207ef29515ddd11b9Timo Sirainen const char *const *chroot_dirs;
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen chroot_dirs = t_strsplit(user_set->valid_chroot_dirs, ":");
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen strncmp(dir, *chroot_dirs, strlen(*chroot_dirs)) == 0)
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainenuser_reply_handle(struct mail_storage_service_ctx *ctx,
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen const char **error_r)
5539418f448cd9bb38fc085e654861479dd1130bTimo Sirainen unsigned int i, count;
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen set_keyval(ctx, user, "mail_uid", dec2str(reply->uid));
dca6d617a23e3f93af3b8df59acb46478179fe55Timo Sirainen set_keyval(ctx, user, "mail_gid", dec2str(reply->gid));
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen /* wu-ftpd like <chroot>/./<home> - check only if there's even
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen a possibility of using them (non-empty valid_chroot_dirs) */
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen if (!validate_chroot(user->user_set, chroot)) {
61b0637759146621cbb7edcbd0b03a71cfd66dfeTimo Sirainen "userdb returned invalid chroot directory: %s "
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen str = array_get(&reply->extra_fields, &count);
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen for (i = 0; i < count; i++) {
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen if (strncmp(line, "system_groups_user=", 19) == 0) {
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen if (n != 0) {
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen } else if (strncmp(line, "auth_token=", 11) == 0) {
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen user->auth_token = p_strdup(user->pool, line+11);
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen } else if (strncmp(line, "auth_user=", 10) == 0) {
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen user->auth_user = p_strdup(user->pool, line+10);
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen user->admin = line[6] == 'y' || line[6] == 'Y' ||
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen *error_r = t_strdup_printf("Invalid userdb input '%s': %s",
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen str[i], settings_parser_get_error(user->set_parser));
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainenservice_auth_userdb_lookup(struct mail_storage_service_ctx *ctx,
5b62dea2f88165f3f4d87bba9011343f3ff415ffTimo Sirainen const struct mail_storage_service_input *input,
1ac7c8e9040e0d0b7e9f849e45b94bfe919595a9Timo Sirainen const char *const **fields_r,
const char **error_r)
const char *new_username;
int ret;
if (ret > 0) {
} else if (ret == 0)
return ret;
return TRUE;
return FALSE;
return FALSE;
return TRUE;
return TRUE;
return FALSE;
return FALSE;
return TRUE;
static const struct var_expand_table *
return tab;
const struct var_expand_table *
const char *str)
const char **error_r)
static void mail_storage_service_seteuid_root(void)
if (seteuid(0) < 0) {
&error)) {
if (disallow_root &&
if (keep_setuid_root) {
if (current_euid != 0) {
if (!setenv_only) {
const char **error_r)
T_BEGIN {
} T_END;
user);
if (diff > 0) {
diff++;
struct mail_storage_service_ctx *
const char *version;
unsigned int count;
geteuid() != 0) {
count = 0;
return ctx;
struct auth_master_connection *
static enum mail_storage_service_flags
return flags;
const char **error_r)
i_unreached();
bool update_log_prefix,
const char **error_r)
void **sets;
geteuid() != 0) {
&error) < 0) {
if (update_log_prefix)
error_r);
if (ret <= 0) {
return ret;
if (ret > 0) {
return ret;
const char **error_r)
bool update_log_prefix;
int ret;
return ret;
const char *error;
unsigned int len;
bool disallow_root =
bool temp_priv_drop =
bool use_chroot;
if (use_chroot) {
if (!temp_priv_drop ||
int ret;
return ret;
const char *error;
const char **error_r)
int ret;
if (ret <= 0)
return ret;
if (ret < 0) {
return ret;
const char *error;
void **sets;
&error) < 0)
int ret = 0;
return ret;
flags);
const char **username_r)
const struct mail_storage_settings *
const struct mail_storage_service_input *
struct setting_parser_context *
T_BEGIN {
} T_END;
return set;