main.c revision bcb4e51a409d94ae670de96afb8483a4f7855294
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen/* Copyright (c) 2002-2018 Dovecot authors, see the included COPYING file */
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen#include "login-common.h"
16f816d3f3c32ae3351834253f52ddd0212bcbf3Timo Sirainen#include "ioloop.h"
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen#include "array.h"
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen#include "str.h"
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen#include "randgen.h"
31ddc75584c5cde53d2e78a737587f2e7fdcb0d2Timo Sirainen#include "module-dir.h"
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen#include "process-title.h"
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen#include "restrict-access.h"
e86d0d34fe365da4c7ca4312d575bfcbf3a01c0eTimo Sirainen#include "restrict-process-size.h"
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen#include "master-auth.h"
da5d50534cfca45d0aaaf0bdac17b287b4588809Timo Sirainen#include "master-service.h"
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen#include "master-interface.h"
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen#include "iostream-ssl.h"
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen#include "client-common.h"
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen#include "access-lookup.h"
31ddc75584c5cde53d2e78a737587f2e7fdcb0d2Timo Sirainen#include "anvil-client.h"
31ddc75584c5cde53d2e78a737587f2e7fdcb0d2Timo Sirainen#include "auth-client.h"
e4b09b008ab544eb8994beecbfffefa21d855e43Timo Sirainen#include "dsasl-client.h"
4b231ca0bbe3b536acbd350101e183441ce0247aTimo Sirainen#include "master-service-ssl-settings.h"
4b231ca0bbe3b536acbd350101e183441ce0247aTimo Sirainen#include "login-proxy.h"
e4b09b008ab544eb8994beecbfffefa21d855e43Timo Sirainen
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen#include <unistd.h>
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen#include <syslog.h>
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen#define AUTH_CLIENT_IDLE_TIMEOUT_MSECS (1000*60)
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainenstruct login_access_lookup {
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen struct master_service_connection conn;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen struct io *io;
024815ea2ffdda9ea79919f18e865663977f73eaTimo Sirainen
367c05967091a2cbfce59b7f274f55b1a0f9e8c9Timo Sirainen char **sockets, **next_socket;
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen struct access_lookup *access;
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen};
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainenconst struct login_binary *login_binary;
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainenstruct auth_client *auth_client;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainenstruct master_auth *master_auth;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainenbool closing_down, login_debug;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainenstruct anvil_client *anvil;
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainenconst char *login_rawlog_dir = NULL;
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainenunsigned int initial_service_count;
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainenstruct login_module_register login_module_register;
41e1c7380edda701719d8ce1fb4d465d2ec4c84dTimo SirainenARRAY_TYPE(string) global_alt_usernames;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainenbool login_ssl_initialized;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainenconst struct login_settings *global_login_settings;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainenconst struct master_service_ssl_settings *global_ssl_settings;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainenvoid **global_other_settings;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainenconst struct ip_addr *login_source_ips;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainenunsigned int login_source_ips_idx, login_source_ips_count;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen
ee246b46953e4b94b2f22e093373674fa9155500Timo Sirainenstatic struct module *modules;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainenstatic struct timeout *auth_client_to;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainenstatic const char *post_login_socket;
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainenstatic bool shutting_down = FALSE;
41e1c7380edda701719d8ce1fb4d465d2ec4c84dTimo Sirainenstatic bool ssl_connections = FALSE;
ee246b46953e4b94b2f22e093373674fa9155500Timo Sirainenstatic bool auth_connected_once = FALSE;
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainenstatic void login_access_lookup_next(struct login_access_lookup *lookup);
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainenstatic bool get_first_client(struct client **client_r)
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen{
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen struct client *client = clients;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen if (client == NULL)
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen client = login_proxies_get_first_detached_client();
20a802016205bbcafc90f164f769ea801f88d014Timo Sirainen if (client == NULL)
20a802016205bbcafc90f164f769ea801f88d014Timo Sirainen client = clients_get_first_fd_proxy();
20a802016205bbcafc90f164f769ea801f88d014Timo Sirainen *client_r = client;
20a802016205bbcafc90f164f769ea801f88d014Timo Sirainen return client != NULL;
20a802016205bbcafc90f164f769ea801f88d014Timo Sirainen}
20a802016205bbcafc90f164f769ea801f88d014Timo Sirainen
20a802016205bbcafc90f164f769ea801f88d014Timo Sirainenvoid login_refresh_proctitle(void)
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen{
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen struct client *client;
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen const char *addr;
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen
8e7da21696c9f8a6d5e601243fb6172ec85d47b2Timo Sirainen if (!global_login_settings->verbose_proctitle)
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen return;
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen /* clients_get_count() includes all the clients being served.
024815ea2ffdda9ea79919f18e865663977f73eaTimo Sirainen Inside that there are 3 groups:
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen 1. pre-login clients
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen 2. post-login clients being proxied to remote hosts
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen 3. post-login clients being proxied to post-login processes
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen Currently the post-login proxying is done only for SSL/TLS
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen connections, so we're assuming that they're the same. */
024815ea2ffdda9ea79919f18e865663977f73eaTimo Sirainen string_t *str = t_str_new(64);
024815ea2ffdda9ea79919f18e865663977f73eaTimo Sirainen if (clients_get_count() == 0) {
1175f27441385a7011629f295f42708f9a3a4ffcTimo Sirainen /* no clients */
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen } else if (clients_get_count() > 1 || !get_first_client(&client)) {
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen str_printfa(str, "[%u pre-login", clients_get_count() -
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen login_proxies_get_detached_count() -
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen clients_get_fd_proxies_count());
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen if (login_proxies_get_detached_count() > 0) {
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen /* show detached proxies only if they exist, so
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen non-proxy servers don't unnecessarily show them. */
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen str_printfa(str, " + %u proxies",
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen login_proxies_get_detached_count());
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen }
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen if (clients_get_fd_proxies_count() > 0) {
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen /* show post-login proxies only if they exist, so
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen proxy-only servers don't unnecessarily show them. */
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen str_printfa(str, " + %u TLS proxies",
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen clients_get_fd_proxies_count());
de12ff295bb3d0873b4dced5840612cbacd635efTimo Sirainen }
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen str_append_c(str, ']');
de12ff295bb3d0873b4dced5840612cbacd635efTimo Sirainen } else {
de12ff295bb3d0873b4dced5840612cbacd635efTimo Sirainen str_append_c(str, '[');
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen addr = net_ip2addr(&client->ip);
de12ff295bb3d0873b4dced5840612cbacd635efTimo Sirainen if (addr[0] != '\0')
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen str_printfa(str, "%s ", addr);
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen if (client->fd_proxying)
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen str_append(str, "TLS proxy");
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen else if (client->destroyed)
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen str_append(str, "proxy");
de12ff295bb3d0873b4dced5840612cbacd635efTimo Sirainen else
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen str_append(str, "pre-login");
de12ff295bb3d0873b4dced5840612cbacd635efTimo Sirainen str_append_c(str, ']');
de12ff295bb3d0873b4dced5840612cbacd635efTimo Sirainen }
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen process_title_set(str_c(str));
de12ff295bb3d0873b4dced5840612cbacd635efTimo Sirainen}
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainenstatic void auth_client_idle_timeout(struct auth_client *auth_client)
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen{
5626ae5e3316eced244adb6485c0927f1c7fdc41Timo Sirainen i_assert(clients == NULL);
5626ae5e3316eced244adb6485c0927f1c7fdc41Timo Sirainen
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen auth_client_disconnect(auth_client, "idle disconnect");
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen timeout_remove(&auth_client_to);
5626ae5e3316eced244adb6485c0927f1c7fdc41Timo Sirainen}
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainenvoid login_client_destroyed(void)
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen{
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen if (clients == NULL && auth_client_to == NULL) {
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen auth_client_to = timeout_add(AUTH_CLIENT_IDLE_TIMEOUT_MSECS,
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen auth_client_idle_timeout,
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen auth_client);
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen }
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen}
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainenstatic void login_die(void)
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen{
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen shutting_down = TRUE;
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen login_proxy_kill_idle();
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen if (!auth_client_is_connected(auth_client)) {
c27f03fa8fd2ef4acd1db814fae7d90e0eb9d3aeTimo Sirainen /* we don't have auth client, and we might never get one */
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen clients_destroy_all();
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen }
f23298fea47eecbeded985ee2537a34c4c4ef56bTimo Sirainen}
f23298fea47eecbeded985ee2537a34c4c4ef56bTimo Sirainen
f23298fea47eecbeded985ee2537a34c4c4ef56bTimo Sirainenstatic void
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainenclient_connected_finish(const struct master_service_connection *conn)
f23298fea47eecbeded985ee2537a34c4c4ef56bTimo Sirainen{
f23298fea47eecbeded985ee2537a34c4c4ef56bTimo Sirainen struct client *client;
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen const struct login_settings *set;
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen const struct master_service_ssl_settings *ssl_set;
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen pool_t pool;
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen void **other_sets;
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen pool = pool_alloconly_create("login client", 8*1024);
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen set = login_settings_read(pool, &conn->local_ip,
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen &conn->remote_ip, NULL, &ssl_set, &other_sets);
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen client = client_alloc(conn->fd, pool, conn, set, ssl_set);
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen if (ssl_connections || conn->ssl) {
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen if (client_init_ssl(client) < 0) {
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen client_unref(&client);
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen net_disconnect(conn->fd);
519e0a461271843833a2b42626ad93f6e7ddc497Timo Sirainen master_service_client_connection_destroyed(master_service);
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen return;
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen }
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen }
367c05967091a2cbfce59b7f274f55b1a0f9e8c9Timo Sirainen client_init(client, other_sets);
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen timeout_remove(&auth_client_to);
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen}
367c05967091a2cbfce59b7f274f55b1a0f9e8c9Timo Sirainen
367c05967091a2cbfce59b7f274f55b1a0f9e8c9Timo Sirainenstatic void login_access_lookup_free(struct login_access_lookup *lookup)
367c05967091a2cbfce59b7f274f55b1a0f9e8c9Timo Sirainen{
367c05967091a2cbfce59b7f274f55b1a0f9e8c9Timo Sirainen io_remove(&lookup->io);
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen if (lookup->access != NULL)
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen access_lookup_destroy(&lookup->access);
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen if (lookup->conn.fd != -1) {
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen if (close(lookup->conn.fd) < 0)
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen i_error("close(client) failed: %m");
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen master_service_client_connection_destroyed(master_service);
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen }
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen p_strsplit_free(default_pool, lookup->sockets);
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen i_free(lookup);
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen}
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen
1175f27441385a7011629f295f42708f9a3a4ffcTimo Sirainenstatic void login_access_callback(bool success, void *context)
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen{
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen struct login_access_lookup *lookup = context;
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen if (!success) {
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen i_info("access(%s): Client refused (rip=%s)",
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen *lookup->next_socket,
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen net_ip2addr(&lookup->conn.remote_ip));
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen login_access_lookup_free(lookup);
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen } else {
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen lookup->next_socket++;
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen login_access_lookup_next(lookup);
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen }
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen}
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainenstatic void login_access_lookup_next(struct login_access_lookup *lookup)
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen{
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen if (*lookup->next_socket == NULL) {
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen /* last one */
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen io_remove(&lookup->io);
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen client_connected_finish(&lookup->conn);
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen lookup->conn.fd = -1;
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen login_access_lookup_free(lookup);
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen return;
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen }
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen lookup->access = access_lookup(*lookup->next_socket, lookup->conn.fd,
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen login_binary->protocol,
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen login_access_callback, lookup);
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen if (lookup->access == NULL)
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen login_access_lookup_free(lookup);
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen}
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen
1175f27441385a7011629f295f42708f9a3a4ffcTimo Sirainenstatic void client_input_error(struct login_access_lookup *lookup)
b79ec51bdeef6ef950eb5e890e65cc0491cf5fe9Timo Sirainen{
8e7da21696c9f8a6d5e601243fb6172ec85d47b2Timo Sirainen char c;
053843989f13d9013b265fb401a4bde7e0e6568eTimo Sirainen int ret;
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen ret = recv(lookup->conn.fd, &c, 1, MSG_PEEK);
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen if (ret <= 0) {
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen i_info("access(%s): Client disconnected during lookup (rip=%s)",
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen *lookup->next_socket,
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen net_ip2addr(&lookup->conn.remote_ip));
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen login_access_lookup_free(lookup);
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen } else {
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen /* actual input. stop listening until lookup is done. */
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen io_remove(&lookup->io);
ab286a8b58306eb8d22fc18342b6c199fd428e1eTimo Sirainen }
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen}
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainenstatic void client_connected(struct master_service_connection *conn)
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen{
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen const char *access_sockets =
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen global_login_settings->login_access_sockets;
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen struct login_access_lookup *lookup;
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen master_service_client_connection_accept(conn);
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen if (conn->remote_ip.family != 0) {
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen /* log the connection's IP address in case we crash. it's of
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen course possible that another earlier client causes the
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen crash, but this is better than nothing. */
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen i_set_failure_send_ip(&conn->remote_ip);
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen }
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen /* make sure we're connected (or attempting to connect) to auth */
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen auth_client_connect(auth_client);
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen if (*access_sockets == '\0') {
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen /* no access checks */
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen client_connected_finish(conn);
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen return;
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen }
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen lookup = i_new(struct login_access_lookup, 1);
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen lookup->conn = *conn;
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen lookup->io = io_add(conn->fd, IO_READ, client_input_error, lookup);
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen lookup->sockets = p_strsplit_spaces(default_pool, access_sockets, " ");
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen lookup->next_socket = lookup->sockets;
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen login_access_lookup_next(lookup);
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen}
1b3bb8d39686ed24730cbc31cc9a33dc62c8c6c3Timo Sirainen
1b3bb8d39686ed24730cbc31cc9a33dc62c8c6c3Timo Sirainenstatic void auth_connect_notify(struct auth_client *client ATTR_UNUSED,
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen bool connected, void *context ATTR_UNUSED)
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen{
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen if (connected) {
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen auth_connected_once = TRUE;
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen clients_notify_auth_connected();
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen } else if (shutting_down)
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen clients_destroy_all();
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen else if (!auth_connected_once) {
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen /* auth disconnected without having ever succeeded, so the
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen auth process is probably misconfigured. no point in
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen keeping the client connections hanging. */
1b3bb8d39686ed24730cbc31cc9a33dc62c8c6c3Timo Sirainen clients_destroy_all_reason("Disconnected: Auth process broken");
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen }
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen}
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainenstatic bool anvil_reconnect_callback(void)
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen{
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen /* we got disconnected from anvil. we can't reconnect to it since we're
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen chrooted, so just die after we've finished handling the current
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen connections. */
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen master_service_stop_new_connections(master_service);
1b3bb8d39686ed24730cbc31cc9a33dc62c8c6c3Timo Sirainen return FALSE;
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen}
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainenvoid login_anvil_init(void)
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen{
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen if (anvil != NULL)
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen return;
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen anvil = anvil_client_init("anvil", anvil_reconnect_callback, 0);
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen if (anvil_client_connect(anvil, TRUE) < 0)
b79ec51bdeef6ef950eb5e890e65cc0491cf5fe9Timo Sirainen i_fatal("Couldn't connect to anvil");
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen}
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainenstatic const struct ip_addr *
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainenparse_login_source_ips(const char *ips_str, unsigned int *count_r)
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen{
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen ARRAY(struct ip_addr) ips;
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen const char *const *tmp;
b79ec51bdeef6ef950eb5e890e65cc0491cf5fe9Timo Sirainen struct ip_addr *tmp_ips;
b79ec51bdeef6ef950eb5e890e65cc0491cf5fe9Timo Sirainen bool skip_nonworking = FALSE;
b79ec51bdeef6ef950eb5e890e65cc0491cf5fe9Timo Sirainen unsigned int i, tmp_ips_count;
b79ec51bdeef6ef950eb5e890e65cc0491cf5fe9Timo Sirainen int ret;
b79ec51bdeef6ef950eb5e890e65cc0491cf5fe9Timo Sirainen
b79ec51bdeef6ef950eb5e890e65cc0491cf5fe9Timo Sirainen if (ips_str[0] == '?') {
b79ec51bdeef6ef950eb5e890e65cc0491cf5fe9Timo Sirainen /* try binding to the IP immediately. if it doesn't
b79ec51bdeef6ef950eb5e890e65cc0491cf5fe9Timo Sirainen work, skip it. (this allows using the same config file for
b79ec51bdeef6ef950eb5e890e65cc0491cf5fe9Timo Sirainen all the servers.) */
64541374b58e4c702b1926e87df421d180ffa006Timo Sirainen skip_nonworking = TRUE;
64541374b58e4c702b1926e87df421d180ffa006Timo Sirainen ips_str++;
64541374b58e4c702b1926e87df421d180ffa006Timo Sirainen }
64541374b58e4c702b1926e87df421d180ffa006Timo Sirainen t_array_init(&ips, 4);
64541374b58e4c702b1926e87df421d180ffa006Timo Sirainen for (tmp = t_strsplit_spaces(ips_str, ", "); *tmp != NULL; tmp++) {
64541374b58e4c702b1926e87df421d180ffa006Timo Sirainen ret = net_gethostbyname(*tmp, &tmp_ips, &tmp_ips_count);
64541374b58e4c702b1926e87df421d180ffa006Timo Sirainen if (ret != 0) {
64541374b58e4c702b1926e87df421d180ffa006Timo Sirainen i_error("login_source_ips: net_gethostbyname(%s) failed: %s",
64541374b58e4c702b1926e87df421d180ffa006Timo Sirainen *tmp, net_gethosterror(ret));
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen continue;
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen }
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen for (i = 0; i < tmp_ips_count; i++) {
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen if (skip_nonworking && net_try_bind(&tmp_ips[i]) < 0)
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen continue;
6a19e109ee8c5a6f688da83a86a7f6abeb71abddTimo Sirainen array_append(&ips, &tmp_ips[i], 1);
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen }
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen }
bbf796c17f02538058d7559bfe96d677e5b55015Timo Sirainen return array_get(&ips, count_r);
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen}
5a07b37a9df398b5189c14872a600384208ab74bTimo Sirainen
8e7da21696c9f8a6d5e601243fb6172ec85d47b2Timo Sirainenstatic void login_load_modules(void)
8e7da21696c9f8a6d5e601243fb6172ec85d47b2Timo Sirainen{
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen struct module_dir_load_settings mod_set;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen if (global_login_settings->login_plugins[0] == '\0')
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen return;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen i_zero(&mod_set);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen mod_set.abi_version = DOVECOT_ABI_VERSION;
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen mod_set.binary_name = login_binary->process_name;
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen mod_set.setting_name = "login_plugins";
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen mod_set.require_init_funcs = TRUE;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen mod_set.debug = login_debug;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen modules = module_dir_load(global_login_settings->login_plugin_dir,
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen global_login_settings->login_plugins,
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen &mod_set);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen module_dir_init(modules);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen}
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainenstatic void login_ssl_init(void)
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen{
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen struct ssl_iostream_settings ssl_set;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen const char *error;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen if (strcmp(global_ssl_settings->ssl, "no") == 0)
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen return;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen master_service_ssl_settings_to_iostream_set(global_ssl_settings,
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen pool_datastack_create(),
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen MASTER_SERVICE_SSL_SETTINGS_TYPE_SERVER, &ssl_set);
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen if (io_stream_ssl_global_init(&ssl_set, &error) < 0)
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen i_fatal("Failed to initialize SSL library: %s", error);
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen login_ssl_initialized = TRUE;
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen}
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainenstatic void main_preinit(void)
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen{
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen unsigned int max_fds;
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen /* Initialize SSL proxy so it can read certificate and private
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen key file. */
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen login_ssl_init();
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen dsasl_clients_init();
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen client_common_init();
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen /* set the number of fds we want to use. it may get increased or
287ba82a8da3eaa473b5735d4eeac2fb4c5d8117Timo Sirainen decreased. leave a couple of extra fds for auth sockets and such.
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen worst case each connection can use:
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen - 1 for client
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen - 1 for login proxy
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen - 2 for client-side ssl proxy
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen - 2 for server-side ssl proxy (with login proxy)
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen However, login process nowadays supports plugins, there are rawlogs
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen and so on. Don't enforce the fd limit anymore, but use this value
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen for optimizing the ioloop's fd table size.
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen */
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen max_fds = MASTER_LISTEN_FD_FIRST + 16 +
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen master_service_get_socket_count(master_service) +
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen master_service_get_client_limit(master_service)*6;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen io_loop_set_max_fd_count(current_ioloop, max_fds);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen i_assert(strcmp(global_ssl_settings->ssl, "no") == 0 ||
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen login_ssl_initialized);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen if (global_login_settings->mail_max_userip_connections > 0)
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen login_anvil_init();
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen /* read the login_source_ips before chrooting so it can access
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen /etc/hosts */
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen login_source_ips = parse_login_source_ips(global_login_settings->login_source_ips,
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen &login_source_ips_count);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen if (login_source_ips_count > 0) {
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen /* randomize the initial index in case service_count=1
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen (although in that case it's unlikely this setting is
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen even used..) */
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen login_source_ips_idx = i_rand_limit(login_source_ips_count);
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen }
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen login_load_modules();
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen restrict_access_by_env(NULL, TRUE);
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen if (login_debug)
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen restrict_access_allow_coredumps(TRUE);
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen initial_service_count = master_service_get_service_count(master_service);
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen if (restrict_access_get_current_chroot() == NULL) {
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen if (chdir("login") < 0)
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen i_fatal("chdir(login) failed: %m");
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen }
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen
871c7b8969e8627dc4c8b3e56fd126f948e6bce6Timo Sirainen if (login_rawlog_dir != NULL &&
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen access(login_rawlog_dir, W_OK | X_OK) < 0) {
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen i_error("access(%s, wx) failed: %m - disabling rawlog",
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen login_rawlog_dir);
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen login_rawlog_dir = NULL;
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen }
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen}
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainenstatic void main_init(const char *login_socket)
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen{
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen /* make sure we can't fork() */
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen restrict_process_count(1);
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen i_array_init(&global_alt_usernames, 4);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen master_service_set_avail_overflow_callback(master_service,
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen client_destroy_oldest);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen master_service_set_die_callback(master_service, login_die);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen auth_client = auth_client_init(login_socket, (unsigned int)getpid(),
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen FALSE);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen auth_client_set_connect_notify(auth_client, auth_connect_notify, NULL);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen master_auth = master_auth_init(master_service, post_login_socket);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen login_binary->init();
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen login_proxy_init(global_login_settings->login_proxy_notify_path);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen}
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainenstatic void main_deinit(void)
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen{
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen client_destroy_fd_proxies();
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen ssl_iostream_context_cache_free();
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen login_proxy_deinit();
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen login_binary->deinit();
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen module_dir_unload(&modules);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen auth_client_deinit(&auth_client);
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen master_auth_deinit(&master_auth);
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen char **strp;
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen array_foreach_modifiable(&global_alt_usernames, strp)
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen i_free(*strp);
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen array_free(&global_alt_usernames);
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen if (anvil != NULL)
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen anvil_client_deinit(&anvil);
6a04c5112961c5f4fb2d2f25192b3dc424d62ad0Timo Sirainen timeout_remove(&auth_client_to);
bb10ebcf076c959c752f583746d83805d7686df8Timo Sirainen client_common_deinit();
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen dsasl_clients_deinit();
16c89b1260c9d07c01c83a9219424d3727069b2eTimo Sirainen login_settings_deinit();
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen}
31ddc75584c5cde53d2e78a737587f2e7fdcb0d2Timo Sirainen
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainenint login_binary_run(const struct login_binary *binary,
1b3bb8d39686ed24730cbc31cc9a33dc62c8c6c3Timo Sirainen int argc, char *argv[])
8e7da21696c9f8a6d5e601243fb6172ec85d47b2Timo Sirainen{
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen enum master_service_flags service_flags =
8e7da21696c9f8a6d5e601243fb6172ec85d47b2Timo Sirainen MASTER_SERVICE_FLAG_KEEP_CONFIG_OPEN |
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen MASTER_SERVICE_FLAG_TRACK_LOGIN_STATE |
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen MASTER_SERVICE_FLAG_USE_SSL_SETTINGS |
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen MASTER_SERVICE_FLAG_NO_SSL_INIT;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen pool_t set_pool;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen const char *login_socket;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen int c;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen login_binary = binary;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen login_socket = binary->default_login_socket != NULL ?
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen binary->default_login_socket : LOGIN_DEFAULT_SOCKET;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen post_login_socket = binary->protocol;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen master_service = master_service_init(login_binary->process_name,
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen service_flags, &argc, &argv,
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen "Dl:R:S");
1b3bb8d39686ed24730cbc31cc9a33dc62c8c6c3Timo Sirainen master_service_init_log(master_service, t_strconcat(
8830fab191cab8440281eb641dfdd93974b2933bTimo Sirainen login_binary->process_name, ": ", NULL));
b2105c78f0fd58281317e6d777ded860f33153a3Timo Sirainen
b2105c78f0fd58281317e6d777ded860f33153a3Timo Sirainen while ((c = master_getopt(master_service)) > 0) {
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen switch (c) {
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen case 'D':
92888ef30960c30ccc9e030fe7eab5d4d04a7d1cTimo Sirainen login_debug = TRUE;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen break;
92888ef30960c30ccc9e030fe7eab5d4d04a7d1cTimo Sirainen case 'l':
92888ef30960c30ccc9e030fe7eab5d4d04a7d1cTimo Sirainen post_login_socket = optarg;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen break;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen case 'R':
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen login_rawlog_dir = optarg;
7e94cf9d70ce9fdeccb7a85ff400b899e6386f36Timo Sirainen break;
8e7da21696c9f8a6d5e601243fb6172ec85d47b2Timo Sirainen case 'S':
7e94cf9d70ce9fdeccb7a85ff400b899e6386f36Timo Sirainen ssl_connections = TRUE;
8e7da21696c9f8a6d5e601243fb6172ec85d47b2Timo Sirainen break;
7e94cf9d70ce9fdeccb7a85ff400b899e6386f36Timo Sirainen default:
8e7da21696c9f8a6d5e601243fb6172ec85d47b2Timo Sirainen return FATAL_DEFAULT;
8e7da21696c9f8a6d5e601243fb6172ec85d47b2Timo Sirainen }
8e7da21696c9f8a6d5e601243fb6172ec85d47b2Timo Sirainen }
e12648867876aaec17e06ee4caef0bb60363449dTimo Sirainen if (argv[optind] != NULL)
e12648867876aaec17e06ee4caef0bb60363449dTimo Sirainen login_socket = argv[optind];
e12648867876aaec17e06ee4caef0bb60363449dTimo Sirainen
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen login_binary->preinit();
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen set_pool = pool_alloconly_create("global login settings", 4096);
d482b35af87f5fd872bad007da0475813a401a49Timo Sirainen global_login_settings =
d482b35af87f5fd872bad007da0475813a401a49Timo Sirainen login_settings_read(set_pool, NULL, NULL, NULL,
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen &global_ssl_settings,
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen &global_other_settings);
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen main_preinit();
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen master_service_init_finish(master_service);
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen main_init(login_socket);
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen
7797aa2479e99aeb71057b7a2584b2cb72e4d3f8Timo Sirainen master_service_run(master_service, client_connected);
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen main_deinit();
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen pool_unref(&set_pool);
31ddc75584c5cde53d2e78a737587f2e7fdcb0d2Timo Sirainen master_service_deinit(&master_service);
31ddc75584c5cde53d2e78a737587f2e7fdcb0d2Timo Sirainen return 0;
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen}
0cb2e8eb55e70f8ebe1e8349bdf49e4cbe5d8834Timo Sirainen