mail-storage-service.c revision 691f802ef6ec2105079d420ba26b21088402c6da
a8c5a86d183db25a57bf193c06b41e092ec2e151Timo Sirainen/* Copyright (c) 2009-2015 Dovecot authors, see the included COPYING file */
8c8f7ac580b661aee3d8b8dd37df4a9b41c77000Timo Sirainen/* If time moves backwards more than this, kill ourself instead of sleeping. */
8c8f7ac580b661aee3d8b8dd37df4a9b41c77000Timo Sirainen "Invalid user settings. Refer to server log for more information."
0dc7891233a973829f00371b27810f849b987c66Timo Sirainen struct auth_master_connection *conn, *iter_conn;
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen const char *set_cache_module, *set_cache_service;
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen struct master_service_settings_cache *set_cache;
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen const char *const **userdb_next_fieldsp;
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen const char *log_prefix, *auth_token, *auth_user;
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen const char *system_groups_user, *uid_source, *gid_source;
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainenstruct module *mail_storage_service_modules = NULL;
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainenmail_user_set_get_mail_debug(const struct setting_parser_info *user_info,
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen mail_set = mail_user_set_get_driver_settings(user_info, user_set,
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainenstatic void set_keyval(struct mail_storage_service_ctx *ctx,
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen struct setting_parser_context *set_parser = user->set_parser;
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen const char *str;
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen if (master_service_set_has_config_override(ctx->service, key)) {
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen /* this setting was already overridden with -o parameter */
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen if (mail_user_set_get_mail_debug(user->user_info,
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen i_debug("Ignoring overridden (-o) userdb setting: %s",
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen if (settings_parse_line(set_parser, str) < 0) {
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainenstatic int set_line(struct mail_storage_service_ctx *ctx,
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen struct setting_parser_context *set_parser = user->set_parser;
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen const char *key, *orig_key, *append_value = NULL;
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen unsigned int len;
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen mail_debug = mail_user_set_get_mail_debug(user->user_info,
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen /* key+=value */
02b32cf39a098edf60981fc228e4b034f11f3b90Timo Sirainen if (!settings_parse_is_valid_key(set_parser, key)) {
0dc7891233a973829f00371b27810f849b987c66Timo Sirainen /* assume it's a plugin setting */
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen if (master_service_set_has_config_override(ctx->service, key)) {
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen /* this setting was already overridden with -o parameter */
0dc7891233a973829f00371b27810f849b987c66Timo Sirainen i_debug("Ignoring overridden (-o) userdb setting: %s",
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen value = settings_parse_get_value(set_parser, key, &type);
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen "'+' can only be used for strings.", orig_key);
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen /* possibly a password field (e.g. imapc_password).
0dc7891233a973829f00371b27810f849b987c66Timo Sirainen hide the value. */
2767104d81e97a109f0aa9758792bfa1da325a97Timo Sirainen "Unknown userdb setting: %s" :
9e86ad9eb313004cd4c8b5427daeb4c241b57af6Timo Sirainenstatic bool validate_chroot(const struct mail_user_settings *user_set,
0dc7891233a973829f00371b27810f849b987c66Timo Sirainen const char *dir)
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen const char *const *chroot_dirs;
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen chroot_dirs = t_strsplit(user_set->valid_chroot_dirs, ":");
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen strncmp(dir, *chroot_dirs, strlen(*chroot_dirs)) == 0)
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainenuser_reply_handle(struct mail_storage_service_ctx *ctx,
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen const char **error_r)
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen unsigned int i, count;
0dc7891233a973829f00371b27810f849b987c66Timo Sirainen set_keyval(ctx, user, "mail_uid", dec2str(reply->uid));
0dc7891233a973829f00371b27810f849b987c66Timo Sirainen set_keyval(ctx, user, "mail_gid", dec2str(reply->gid));
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen /* wu-ftpd like <chroot>/./<home> - check only if there's even
b5ff746939712c6a9bef71405fa786d5471cf177Timo Sirainen a possibility of using them (non-empty valid_chroot_dirs) */
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen if (!validate_chroot(user->user_set, chroot)) {
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen "userdb returned invalid chroot directory: %s "
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen str = array_get(&reply->extra_fields, &count);
0dc7891233a973829f00371b27810f849b987c66Timo Sirainen for (i = 0; i < count; i++) {
0dc7891233a973829f00371b27810f849b987c66Timo Sirainen if (strncmp(line, "system_groups_user=", 19) == 0) {
0dc7891233a973829f00371b27810f849b987c66Timo Sirainen i_error("userdb returned invalid nice value %s",
0dc7891233a973829f00371b27810f849b987c66Timo Sirainen } else if (n != 0) {
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen } else if (strncmp(line, "auth_token=", 11) == 0) {
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen user->auth_token = p_strdup(user->pool, line+11);
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen } else if (strncmp(line, "auth_user=", 10) == 0) {
0dc7891233a973829f00371b27810f849b987c66Timo Sirainen user->auth_user = p_strdup(user->pool, line+10);
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen user->admin = line[6] == 'y' || line[6] == 'Y' ||
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen *error_r = t_strdup_printf("Invalid userdb input '%s': %s",
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen str[i], settings_parser_get_error(user->set_parser));
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainenservice_auth_userdb_lookup(struct mail_storage_service_ctx *ctx,
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen const struct mail_storage_service_input *input,
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen const char *const **fields_r,
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen const char **error_r)
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen info.service = input->service != NULL ? input->service :
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen ret = auth_master_user_lookup(ctx->conn, *user, &info, pool,
d9fdacd5fb3e07997e5c389739d2054f0c8441d8Timo Sirainen i_debug("changed username to %s", new_username);
} else if (ret == 0)
return ret;
return TRUE;
return FALSE;
return FALSE;
return TRUE;
return TRUE;
return FALSE;
return FALSE;
return TRUE;
static const struct var_expand_table *
return tab;
const struct var_expand_table *
const char *str)
const char **error_r)
static void mail_storage_service_seteuid_root(void)
if (seteuid(0) < 0) {
&error)) {
if (disallow_root &&
if (keep_setuid_root) {
if (current_euid != 0) {
if (!setenv_only) {
const char **error_r)
unsigned int i, field_name_len;
return NULL;
field_name_len) == 0 &&
return NULL;
T_BEGIN {
} T_END;
user);
if (diff > 0) {
diff++;
struct mail_storage_service_ctx *
const char *version;
unsigned int count;
geteuid() != 0) {
count = 0;
return ctx;
struct auth_master_connection *
static enum mail_storage_service_flags
return flags;
const char **error_r)
i_unreached();
const char **error_r)
bool update_log_prefix,
const char **error_r)
void **sets;
geteuid() != 0) {
&error) < 0) {
if (update_log_prefix)
error_r);
if (ret <= 0) {
return ret;
if (ret > 0) {
&error) < 0) {
return ret;
const char **error_r)
bool update_log_prefix;
int ret;
return ret;
const char *error;
unsigned int len;
bool disallow_root =
bool temp_priv_drop =
bool use_chroot;
if (use_chroot) {
if (!temp_priv_drop ||
int ret;
return ret;
const char *error;
const char **error_r)
int ret;
if (ret <= 0)
return ret;
if (ret < 0) {
return ret;
const char *error;
void **sets;
&error) < 0)
int ret = 0;
return ret;
flags);
const char **username_r)
const struct mail_storage_settings *
const struct mail_storage_service_input *
struct setting_parser_context *
struct mail_storage_service_ctx *
T_BEGIN {
} T_END;
return set;