annotate src/context.cpp @ 462:f3f1ece619ba stable-6-0-75

change dkim_from syntax to allow "signer1,signer2;spf data"
author Carl Byington <carl@five-ten-sg.com>
date Sat, 09 Mar 2019 18:46:25 -0800
parents ad05c61d6372
children 428de28b34b7
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1 /*
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2
270
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
3 Copyright (c) 2013 Carl Byington - 510 Software Group, released under
152
c7fc218686f5 gpl3, block mail to recipients that cannot reply
carl
parents: 149
diff changeset
4 the GPL version 3 or any later version at your choice available at
c7fc218686f5 gpl3, block mail to recipients that cannot reply
carl
parents: 149
diff changeset
5 http://www.gnu.org/licenses/gpl-3.0.txt
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
6
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
7 */
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
8
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
9 #include "includes.h"
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
10
160
b3ed72ee6564 allow manual updates to auto whitelist files
carl
parents: 156
diff changeset
11 #include <arpa/inet.h>
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
12 #include <net/if.h>
160
b3ed72ee6564 allow manual updates to auto whitelist files
carl
parents: 156
diff changeset
13 #include <netdb.h>
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
14 #include <netinet/in.h>
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
15 #include <netinet/tcp.h>
160
b3ed72ee6564 allow manual updates to auto whitelist files
carl
parents: 156
diff changeset
16 #include <sys/ioctl.h>
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
17 #include <sys/socket.h>
160
b3ed72ee6564 allow manual updates to auto whitelist files
carl
parents: 156
diff changeset
18 #include <sys/stat.h>
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
19 #include <sys/un.h>
160
b3ed72ee6564 allow manual updates to auto whitelist files
carl
parents: 156
diff changeset
20 #include <unistd.h>
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
21 #include <climits>
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
22
270
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
23 const char *token_asterisk;
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
24 const char *token_autowhite;
270
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
25 const char *token_bang;
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
26 const char *token_black;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
27 const char *token_content;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
28 const char *token_context;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
29 const char *token_dccbulk;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
30 const char *token_dccfrom;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
31 const char *token_dccgrey;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
32 const char *token_dccto;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
33 const char *token_default;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
34 const char *token_dnsbl;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
35 const char *token_dnsbll;
249
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
36 const char *token_dnswl;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
37 const char *token_dnswll;
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
38 const char *token_envfrom;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
39 const char *token_envto;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
40 const char *token_filter;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
41 const char *token_generic;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
42 const char *token_host_limit;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
43 const char *token_html_limit;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
44 const char *token_html_tags;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
45 const char *token_ignore;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
46 const char *token_include;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
47 const char *token_inherit;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
48 const char *token_lbrace;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
49 const char *token_mailhost;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
50 const char *token_many;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
51 const char *token_no;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
52 const char *token_off;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
53 const char *token_ok;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
54 const char *token_ok2;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
55 const char *token_on;
270
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
56 const char *token_period;
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
57 const char *token_rate;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
58 const char *token_rbrace;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
59 const char *token_require;
268
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
60 const char *token_requirerdns;
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
61 const char *token_semi;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
62 const char *token_soft;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
63 const char *token_spamassassin;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
64 const char *token_substitute;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
65 const char *token_tld;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
66 const char *token_unknown;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
67 const char *token_uribl;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
68 const char *token_verify;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
69 const char *token_white;
233
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
70 const char *token_white_regex;
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
71 const char *token_yes;
321
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
72 const char *token_dkim_signer;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
73 const char *token_dkim_from;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
74 const char *token_signed_white;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
75 const char *token_signed_black;
451
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
76 const char *token_unsigned_black;
321
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
77 const char *token_require_signed;
322
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
78 const char *token_myhostname;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
79
96
1edd4e8d3a60 fix missing include, not all systems define HOST_NAME_MAX
carl
parents: 94
diff changeset
80 #ifndef HOST_NAME_MAX
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
81 #define HOST_NAME_MAX 255
96
1edd4e8d3a60 fix missing include, not all systems define HOST_NAME_MAX
carl
parents: 94
diff changeset
82 #endif
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
83 char myhostname[HOST_NAME_MAX+1];
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
84
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
85 pthread_mutex_t verifier_mutex; // protect the verifier map
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
86 verify_map verifiers;
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
87
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
88 pthread_mutex_t whitelister_mutex; // protect the whitelisters map
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
89 whitelister_map whitelisters;
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
90
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
91 string_set all_strings; // owns all the strings, only modified by the config loader thread
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
92 const int maxlen = 1000; // used for snprintf buffers
178
d6531c702be3 embedded dcc filtering
carl
parents: 175
diff changeset
93 const int maxsmtp_age = 60;// smtp verify sockets older than this are ancient
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
94 const int maxauto_age = 600;// auto whitelister delay before flushing to file
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
95 extern int NULL_SOCKET;
129
c5cd1261394d ignore smtp connection attempts for 10 minutes when getting connection errors on verify hosts
carl
parents: 119
diff changeset
96 const time_t ERROR_SMTP_SOCKET_TIME = 600; // number of seconds between attempts to open a socket to an smtp server
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
97
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
98
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
99 int SMTP::writer() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
100 #ifdef VERIFY_DEBUG
316
f7c5cfb76e86 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 314
diff changeset
101 log("writer(%d) sees buffer with '%s'", buffer);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
102 #endif
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
103 int rs = 0;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
104 if (!error) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
105 int len = strlen(buffer);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
106 while (rs < len) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
107 int ws = write(fd, buffer+rs, len-rs);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
108 if (ws > 0) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
109 rs += ws;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
110 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
111 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
112 // peer closed the socket!
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
113 rs = 0;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
114 error = true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
115 break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
116 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
117 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
118 }
316
f7c5cfb76e86 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 314
diff changeset
119 #ifdef VERIFY_DEBUG
f7c5cfb76e86 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 314
diff changeset
120 log("writer(%d) sees error %d", (int)error);
f7c5cfb76e86 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 314
diff changeset
121 #endif
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
122 return rs;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
123 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
124
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
125
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
126 int SMTP::reader() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
127 // read some bytes terminated by lf or end of buffer.
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
128 // we may have a multi line response or part thereof in the buffer.
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
129 #ifdef VERIFY_DEBUG
314
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
130 log("reader(%d) sees error %d", (int)error);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
131 #endif
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
132 if (error) return 0;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
133 int len = maxlen-1; // room for null terminator
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
134 while (pending < len) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
135 int ws = read(fd, buffer+pending, len-pending);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
136 if (ws > 0) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
137 pending += ws;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
138 if (buffer[pending-1] == '\n') break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
139 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
140 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
141 // peer closed the socket!
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
142 pending = 0;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
143 error = true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
144 break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
145 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
146 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
147 buffer[pending] = '\0';
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
148 #ifdef VERIFY_DEBUG
316
f7c5cfb76e86 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 314
diff changeset
149 log("reader(%d) sees buffer with '%s'", buffer);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
150 #endif
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
151 return pending;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
152 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
153
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
154
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
155 int SMTP::read_line() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
156 char *lf = strchr(buffer, '\n');
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
157 if (!lf) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
158 reader(); // get a lf
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
159 lf = strchr(buffer, '\n');
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
160 if (!lf) lf = buffer + pending - 1;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
161 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
162 return (lf-buffer)+1; // number of bytes in this line
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
163 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
164
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
165
97
cc3b79349c9c fix int function not returning value
carl
parents: 96
diff changeset
166 void SMTP::flush_line(int r) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
167 if (pending > r) memmove(buffer, buffer+r, pending-r);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
168 pending -= r;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
169 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
170
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
171
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
172 int SMTP::read_response() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
173 pending = 0;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
174 buffer[pending] = '\0';
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
175 while (true) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
176 int r = read_line();
316
f7c5cfb76e86 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 314
diff changeset
177 log("verify::read_response(%d) sees line with '%s'", buffer);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
178 if (r == 0) return 0; // failed to read any bytes
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
179 if ((r > 4) && (buffer[3] == '-')) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
180 flush_line(r);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
181 continue;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
182 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
183 return atoi(buffer);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
184 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
185 return 0;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
186 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
187
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
188
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
189 int SMTP::cmd(const char *c) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
190 if (c) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
191 init();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
192 append(c);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
193 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
194 append("\r\n");
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
195 writer();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
196 return read_response();
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
197 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
198
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
199
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
200 int SMTP::helo() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
201 if (read_response() != 220) return 0;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
202 init();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
203 append("HELO ");
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
204 append(token_myhostname);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
205 return cmd(NULL);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
206 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
207
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
208
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
209 int SMTP::rset() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
210 efrom[0] = '\0';
316
f7c5cfb76e86 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 314
diff changeset
211 return cmd("RSET");
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
212 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
213
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
214
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
215 int SMTP::from(const char *f) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
216 // the mail from address was originally passed in from sendmail enclosed in
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
217 // <>. to_lower_string() removed the <> and converted the rest to lowercase,
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
218 // except in the case of an empty return path, which was left as the two
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
219 // character string <>.
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
220 if (strncmp(efrom, f, maxlen)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
221 strncpy(efrom, f, maxlen);
311
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
222 efrom[maxlen-1] = '\0'; // ensure null termination
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
223 init();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
224 append("MAIL FROM:<");
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
225 if (*f != '<') append(f);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
226 append(">");
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
227 return cmd(NULL);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
228 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
229 return 250; // pretend it worked
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
230 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
231
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
232
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
233 int SMTP::rcpt(const char *t) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
234 init();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
235 append("RCPT TO:<");
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
236 append(t);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
237 append(">");
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
238 return cmd(NULL);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
239 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
240
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
241
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
242 int SMTP::quit() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
243 return cmd("QUIT");
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
244 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
245
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
246
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
247 void SMTP::closefd() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
248 shutdown(fd, SHUT_RDWR);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
249 close(fd);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
250 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
251
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
252
311
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
253 void SMTP::log(const char *m, int v) {
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
254 char buf[maxlen];
314
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
255 snprintf(buf, maxlen, m, get_fd(), v);
311
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
256 my_syslog(queueid, buf);
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
257 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
258
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
259
311
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
260 void SMTP::log(const char *m, const char *v) {
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
261 char buf[maxlen];
314
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
262 snprintf(buf, maxlen, m, get_fd(), v);
311
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
263 my_syslog(queueid, buf);
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
264 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
265
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
266
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
267 ////////////////////////////////////////////////
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
268 // smtp verifier so backup mx machines can see the valid users
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
269 //
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
270 VERIFY::VERIFY(const char *h) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
271 host = h;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
272 last_err = 0;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
273 pthread_mutex_init(&mutex, 0);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
274 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
275
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
276
320
e27c24c1974a more smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 318
diff changeset
277 void VERIFY::log(const char *m, const char *q, const char *v) {
e27c24c1974a more smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 318
diff changeset
278 char buf[maxlen];
e27c24c1974a more smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 318
diff changeset
279 snprintf(buf, maxlen, m, v, host);
e27c24c1974a more smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 318
diff changeset
280 my_syslog(q, buf);
e27c24c1974a more smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 318
diff changeset
281 }
e27c24c1974a more smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 318
diff changeset
282
e27c24c1974a more smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 318
diff changeset
283
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
284 void VERIFY::closer() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
285 bool ok = true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
286 while (ok) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
287 SMTP *conn = NULL;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
288 pthread_mutex_lock(&mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
289 if (connections.empty()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
290 ok = false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
291 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
292 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
293 conn = connections.front();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
294 time_t now = time(NULL);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
295 if ((now - conn->get_stamp()) > maxsmtp_age) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
296 // this connection is ancient, remove it
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
297 connections.pop_front();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
298 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
299 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
300 ok = false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
301 conn = NULL;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
302 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
303 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
304 pthread_mutex_unlock(&mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
305 // avoid doing this work inside the mutex lock
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
306 if (conn) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
307 #ifdef VERIFY_DEBUG
314
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
308 conn->log("closer(%d) closes ancient socket %s", "");
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
309 #endif
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
310 delete conn;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
311 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
312 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
313 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
314
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
315
311
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
316 SMTP* VERIFY::get_connection(const char *queueid) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
317 SMTP *conn = NULL;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
318 pthread_mutex_lock(&mutex);
314
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
319 while (!connections.empty()) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
320 conn = connections.front();
314
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
321 time_t now = time(NULL);
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
322 if ((now - conn->get_stamp()) > maxsmtp_age) {
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
323 // this connection is ancient, remove it
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
324 conn->log("verify::get_connection(%d) closes ancient socket %s", "");
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
325 connections.pop_front();
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
326 delete conn;
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
327 conn = NULL;
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
328 }
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
329 else {
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
330 conn->set_id(queueid);
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
331 connections.pop_front();
318
e2dc882839f6 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 316
diff changeset
332 conn->log("verify::get_connection(%d) from cache %s", "");
314
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
333 break;
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
334 }
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
335 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
336 pthread_mutex_unlock(&mutex);
316
f7c5cfb76e86 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 314
diff changeset
337 if (conn) {
f7c5cfb76e86 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 314
diff changeset
338 int rc = conn->rset();
f7c5cfb76e86 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 314
diff changeset
339 conn->log("verify::getconnection(%d) rset sees %d", rc);
f7c5cfb76e86 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 314
diff changeset
340 if (rc == 250) return conn;
318
e2dc882839f6 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 316
diff changeset
341 delete conn;
e2dc882839f6 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 316
diff changeset
342 // old connection from cache was unusable, fall thru and make a new one
316
f7c5cfb76e86 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 314
diff changeset
343 }
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
344 int sock = NULL_SOCKET;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
345 if ((time(NULL) - last_err) > ERROR_SMTP_SOCKET_TIME) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
346 // nothing recent, maybe this time it will work
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
347 hostent *h = gethostbyname(host);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
348 if (h) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
349 sockaddr_in server;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
350 server.sin_family = h->h_addrtype;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
351 server.sin_port = htons(25);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
352 memcpy(&server.sin_addr, h->h_addr_list[0], h->h_length);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
353 sock = socket(PF_INET, SOCK_STREAM, 0);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
354 if (sock != NULL_SOCKET) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
355 bool rc = (connect(sock, (sockaddr *)&server, sizeof(server)) == 0);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
356 if (!rc) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
357 shutdown(sock, SHUT_RDWR);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
358 close(sock);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
359 sock = NULL_SOCKET;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
360 last_err = time(NULL);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
361 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
362 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
363 else last_err = time(NULL);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
364 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
365 else last_err = time(NULL);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
366 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
367 if (sock != NULL_SOCKET) {
314
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
368 struct timeval tv;
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
369 tv.tv_sec = 15;
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
370 tv.tv_usec = 0;
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
371 setsockopt(sock, SOL_SOCKET, SO_RCVTIMEO, (char *)&tv, sizeof(struct timeval));
316
f7c5cfb76e86 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 314
diff changeset
372 setsockopt(sock, SOL_SOCKET, SO_SNDTIMEO, (char *)&tv, sizeof(struct timeval));
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
373 conn = new SMTP(sock);
311
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
374 conn->set_id(queueid);
318
e2dc882839f6 better smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 316
diff changeset
375 conn->log("get_connection(%d) new socket %s", "");
311
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
376 int rc = conn->helo();
314
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
377 conn->log("verify::get_connection(%d) helo sees %d", rc);
311
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
378 if (rc == 250) return conn;
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
379 delete conn;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
380 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
381 return NULL;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
382 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
383
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
384
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
385 void VERIFY::put_connection(SMTP *conn) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
386 if (conn->err()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
387 #ifdef VERIFY_DEBUG
314
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
388 conn->log("put_socket(%d) with error %s", "");
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
389 #endif
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
390 delete conn;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
391 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
392 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
393 #ifdef VERIFY_DEBUG
314
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
394 conn->log("put_socket(%d) no error %s", "");
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
395 #endif
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
396 conn->now();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
397 pthread_mutex_lock(&mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
398 connections.push_back(conn);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
399 pthread_mutex_unlock(&mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
400 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
401 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
402
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
403
310
802e2b779ed1 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 278
diff changeset
404 bool VERIFY::ok(const char *queueid, const char *from, const char *to) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
405 if (host == token_myhostname) return true;
311
f5547e7b3a09 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 310
diff changeset
406 SMTP *conn = get_connection(queueid);
320
e27c24c1974a more smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 318
diff changeset
407 if (!conn) {
e27c24c1974a more smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 318
diff changeset
408 log("unable to verify %s with %s due to socket errors", queueid, to);
e27c24c1974a more smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 318
diff changeset
409 return true; // cannot verify right now, we have socket errors
e27c24c1974a more smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 318
diff changeset
410 }
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
411 int rc;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
412 rc = conn->from(from);
314
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
413 conn->log("verify::ok(%d) from sees %d", rc);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
414 if (rc != 250) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
415 put_connection(conn);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
416 return (rc >= 500) ? false : true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
417 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
418 rc = conn->rcpt(to);
314
ef5a6099cbe7 enable smtp verify logging
Carl Byington <carl@five-ten-sg.com>
parents: 311
diff changeset
419 conn->log("verify::ok(%d) rcpt sees %d", rc);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
420 put_connection(conn);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
421 return (rc >= 500) ? false : true;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
422 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
423
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
424
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
425 ////////////////////////////////////////////////
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
426 // setup a new smtp verify host
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
427 //
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
428 VERIFYP add_verify_host(const char *host);
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
429 VERIFYP add_verify_host(const char *host) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
430 VERIFYP rc = NULL;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
431 pthread_mutex_lock(&verifier_mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
432 verify_map::iterator i = verifiers.find(host);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
433 if (i == verifiers.end()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
434 rc = new VERIFY(host);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
435 verifiers[host] = rc;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
436 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
437 else rc = (*i).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
438 pthread_mutex_unlock(&verifier_mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
439 return rc;
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
440 }
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
441
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
442
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
443 ////////////////////////////////////////////////
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
444 // thread to check for verify hosts with old sockets that we can close
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
445 //
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
446 void* verify_closer(void *arg) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
447 while (true) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
448 sleep(maxsmtp_age);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
449 pthread_mutex_lock(&verifier_mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
450 for (verify_map::iterator i=verifiers.begin(); i!=verifiers.end(); i++) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
451 VERIFYP v = (*i).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
452 v->closer();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
453 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
454 pthread_mutex_unlock(&verifier_mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
455 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
456 return NULL;
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
457 }
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
458
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
459
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
460 ////////////////////////////////////////////////
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
461 // automatic whitelister
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
462 //
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
463 WHITELISTER::WHITELISTER(const char *f, int d) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
464 fn = f;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
465 days = d;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
466 pthread_mutex_init(&mutex, 0);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
467 need = false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
468 loaded = time(NULL);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
469 merge();
160
b3ed72ee6564 allow manual updates to auto whitelist files
carl
parents: 156
diff changeset
470 }
b3ed72ee6564 allow manual updates to auto whitelist files
carl
parents: 156
diff changeset
471
b3ed72ee6564 allow manual updates to auto whitelist files
carl
parents: 156
diff changeset
472
b3ed72ee6564 allow manual updates to auto whitelist files
carl
parents: 156
diff changeset
473 void WHITELISTER::merge() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
474 time_t now = time(NULL);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
475 ifstream ifs;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
476 ifs.open(fn);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
477 if (!ifs.fail()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
478 const int maxlen = 1000;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
479 char buf[maxlen];
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
480 while (ifs.getline(buf, maxlen)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
481 char *p = strchr(buf, ' ');
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
482 if (p) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
483 *p = '\0';
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
484 char *who = strdup(buf);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
485 time_t when = atoi(p+1);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
486 if ((when == 0) || (when > now)) when = now;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
487 autowhite_sent::iterator i = rcpts.find(who);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
488 if (i == rcpts.end()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
489 rcpts[who] = when;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
490 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
491 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
492 time_t wh = (*i).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
493 if ((when == 1) || (when > wh)) (*i).second = when;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
494 free(who);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
495 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
496 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
497 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
498 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
499 ifs.close();
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
500 }
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
501
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
502
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
503 void WHITELISTER::writer() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
504 pthread_mutex_lock(&mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
505 time_t limit = time(NULL) - days*86400;
160
b3ed72ee6564 allow manual updates to auto whitelist files
carl
parents: 156
diff changeset
506
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
507 // check for manually modified autowhitelist file
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
508 struct stat st;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
509 if (stat(fn, &st)) need = true; // file has disappeared
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
510 else if (st.st_mtime > loaded) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
511 // file has been manually updated, merge new entries
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
512 merge();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
513 need = true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
514 }
160
b3ed72ee6564 allow manual updates to auto whitelist files
carl
parents: 156
diff changeset
515
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
516 // purge old entries
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
517 for (autowhite_sent::iterator i=rcpts.begin(); i!=rcpts.end();) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
518 time_t when = (*i).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
519 if (when < limit) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
520 const char *who = (*i).first;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
521 free((void*)who);
195
797299e9fffc fix null dereference if missing _ macro
carl
parents: 192
diff changeset
522 rcpts.erase(i++);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
523 need = true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
524 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
525 else i++;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
526 }
160
b3ed72ee6564 allow manual updates to auto whitelist files
carl
parents: 156
diff changeset
527
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
528 if (need) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
529 // dump the file
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
530 ofstream ofs;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
531 ofs.open(fn);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
532 if (!ofs.fail()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
533 for (autowhite_sent::iterator i=rcpts.begin(); i!=rcpts.end(); i++) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
534 const char *who = (*i).first;
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
535 int when = (*i).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
536 if (!strchr(who, ' ')) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
537 ofs << who << " " << when << endl;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
538 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
539 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
540 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
541 ofs.close();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
542 need = false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
543 loaded = time(NULL); // update load time
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
544 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
545 pthread_mutex_unlock(&mutex);
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
546 }
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
547
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
548
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
549 void WHITELISTER::sent(const char *to) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
550 // we take ownership of the string
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
551 pthread_mutex_lock(&mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
552 need = true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
553 autowhite_sent::iterator i = rcpts.find(to);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
554 if (i == rcpts.end()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
555 rcpts[to] = time(NULL);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
556 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
557 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
558 (*i).second = time(NULL);
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
559 free((void*)to);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
560 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
561 pthread_mutex_unlock(&mutex);
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
562 }
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
563
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
564
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
565 bool WHITELISTER::is_white(const char *from) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
566 pthread_mutex_lock(&mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
567 autowhite_sent::iterator i = rcpts.find(from);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
568 bool rc = (i != rcpts.end());
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
569 pthread_mutex_unlock(&mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
570 return rc;
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
571 }
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
572
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
573
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
574 ////////////////////////////////////////////////
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
575 // setup a new auto whitelister file
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
576 //
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
577 WHITELISTERP add_whitelister_file(const char *fn, int days);
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
578 WHITELISTERP add_whitelister_file(const char *fn, int days) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
579 WHITELISTERP rc = NULL;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
580 pthread_mutex_lock(&whitelister_mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
581 whitelister_map::iterator i = whitelisters.find(fn);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
582 if (i == whitelisters.end()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
583 rc = new WHITELISTER(fn, days);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
584 whitelisters[fn] = rc;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
585 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
586 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
587 rc = (*i).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
588 rc->set_days(days);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
589 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
590 pthread_mutex_unlock(&whitelister_mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
591 return rc;
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
592 }
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
593
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
594
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
595 ////////////////////////////////////////////////
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
596 // thread to check for whitelister hosts with old sockets that we can close
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
597 //
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
598 void* whitelister_writer(void *arg) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
599 while (true) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
600 sleep(maxauto_age);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
601 pthread_mutex_lock(&whitelister_mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
602 for (whitelister_map::iterator i=whitelisters.begin(); i!=whitelisters.end(); i++) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
603 WHITELISTERP v = (*i).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
604 v->writer();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
605 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
606 pthread_mutex_unlock(&whitelister_mutex);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
607 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
608 return NULL;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
609 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
610
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
611
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
612 DELAYWHITE::DELAYWHITE(const char *loto_, WHITELISTERP w_, CONTEXTP con_) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
613 loto = loto_;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
614 w = w_;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
615 con = con_;
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
616 }
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
617
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
618
321
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
619 DKIM::DKIM(const char *action_, const char *signer_) {
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
620 action = action_;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
621 signer = signer_;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
622 }
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
623
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
624
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
625 DNSBL::DNSBL(const char *n, const char *s, const char *m) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
626 name = n;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
627 suffix = s;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
628 message = m;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
629 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
630
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
631
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
632 bool DNSBL::operator==(const DNSBL &rhs) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
633 return (strcmp(name, rhs.name) == 0) &&
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
634 (strcmp(suffix, rhs.suffix) == 0) &&
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
635 (strcmp(message, rhs.message) == 0);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
636 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
637
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
638
249
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
639 DNSWL::DNSWL(const char *n, const char *s, const int l) {
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
640 name = n;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
641 suffix = s;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
642 level = l;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
643 }
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
644
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
645
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
646 bool DNSWL::operator==(const DNSWL &rhs) {
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
647 return (strcmp(name, rhs.name) == 0) &&
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
648 (strcmp(suffix, rhs.suffix) == 0) &&
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
649 (level == rhs.level);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
650 }
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
651
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
652
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
653 CONFIG::CONFIG() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
654 reference_count = 0;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
655 generation = 0;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
656 load_time = 0;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
657 default_context = NULL;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
658 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
659
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
660
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
661 CONFIG::~CONFIG() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
662 if (debug_syslog) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
663 char buf[maxlen];
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
664 snprintf(buf, sizeof(buf), "freeing memory for old configuration generation %d", generation);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
665 my_syslog(buf);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
666 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
667 for (context_list::iterator i=contexts.begin(); i!=contexts.end(); i++) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
668 CONTEXT *c = *i;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
669 delete c;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
670 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
671 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
672
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
673
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
674 void CONFIG::add_context(CONTEXTP con) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
675 contexts.push_back(con);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
676 if (!default_context && !con->get_parent()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
677 // first global context
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
678 default_context = con;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
679 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
680 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
681
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
682
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
683 void CONFIG::add_to(const char *to, CONTEXTP con) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
684 context_map::iterator i = env_to.find(to);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
685 if (i != env_to.end()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
686 CONTEXTP c = (*i).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
687 if ((c != con) && (c != con->get_parent())) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
688 if (debug_syslog) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
689 char oldname[maxlen];
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
690 char newname[maxlen];
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
691 const char *oldn = c->get_full_name(oldname, maxlen);
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
692 const char *newn = con->get_full_name(newname, maxlen);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
693 char buf[maxlen*3];
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
694 snprintf(buf, maxlen*3, "both %s and %s claim envelope to %s, the second one wins", oldn, newn, to);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
695 my_syslog(buf);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
696 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
697 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
698 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
699 env_to[to] = con;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
700 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
701
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
702
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
703 CONTEXTP CONFIG::find_context(const char *to) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
704 context_map::iterator i = env_to.find(to);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
705 if (i != env_to.end()) return (*i).second; // found user@domain key
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
706 const char *x = strchr(to, '@');
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
707 if (x) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
708 x++;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
709 i = env_to.find(x);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
710 if (i != env_to.end()) return (*i).second; // found domain key
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
711 size_t len = x - to;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
712 char user[len+1];
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
713 memcpy(user, to, len);
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
714 user[len] = '\0';
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
715 i = env_to.find(user);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
716 if (i != env_to.end()) return (*i).second; // found user@ key
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
717 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
718 return default_context;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
719 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
720
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
721
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
722 void CONFIG::dump() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
723 bool spamass = false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
724 if (default_context) default_context->dump(true, spamass);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
725 for (context_list::iterator i=contexts.begin(); i!=contexts.end(); i++) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
726 CONTEXTP c = *i;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
727 CONTEXTP p = c->get_parent();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
728 if (!p && (c != default_context)) c->dump(false, spamass);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
729 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
730 char buf[maxlen];
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
731 for (context_map::iterator i=env_to.begin(); i!=env_to.end(); i++) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
732 const char *to = (*i).first;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
733 CONTEXTP con = (*i).second;
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
734 printf("// envelope to %s \t-> context %s \n", to, con->get_full_name(buf,maxlen));
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
735 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
736 if (spamass && (spamc == spamc_empty)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
737 printf("// *** warning - spamassassin filtering requested, but spamc not found by autoconf.\n");
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
738 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
739 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
740
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
741
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
742 CONTEXT::CONTEXT(CONTEXTP parent_, const char *name_) {
278
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
743 parent = parent_;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
744 name = name_;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
745 verify_host = NULL;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
746 verifier = NULL;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
747 generic_regx = NULL;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
748 generic_message = NULL;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
749 white_regx = NULL;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
750 autowhite_file = NULL;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
751 whitelister = NULL;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
752 env_from_default = (parent) ? token_inherit : token_unknown;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
753 content_filtering = (parent) ? parent->content_filtering : false;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
754 content_suffix = NULL;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
755 content_message = NULL;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
756 uribl_suffix = NULL;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
757 uribl_message = NULL;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
758 host_limit = (parent) ? parent->host_limit : 0;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
759 host_limit_message = NULL;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
760 host_random = (parent) ? parent->host_random : false;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
761 tag_limit = (parent) ? parent->tag_limit : 0;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
762 tag_limit_message = NULL;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
763 spamassassin_limit = (parent) ? parent->spamassassin_limit : 0;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
764 require_match = (parent) ? parent->require_match : false;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
765 require_rdns = (parent) ? parent->require_rdns : false;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
766 dcc_greylist = (parent) ? parent->dcc_greylist : false;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
767 dcc_bulk_threshold = (parent) ? parent->dcc_bulk_threshold : 0;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
768 dnsbl_list_parsed = false;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
769 dnswl_list_parsed = false;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
770 default_rate_limit = 36000; // 10 per second
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
771 default_address_limit = 10;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
772 daily_rate_multiple = 3;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
773 daily_address_multiple = 3;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
774 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
775
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
776
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
777 CONTEXT::~CONTEXT() {
321
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
778 for (dkimp_map::iterator i=dkim_from_names.begin(); i!=dkim_from_names.end(); i++) {
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
779 DKIMP d = (*i).second;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
780 // delete the underlying DKIM objects.
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
781 delete d;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
782 }
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
783 for (dnsblp_map::iterator i=dnsbl_names.begin(); i!=dnsbl_names.end(); i++) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
784 DNSBLP d = (*i).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
785 // delete the underlying DNSBL objects.
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
786 delete d;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
787 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
788 if (generic_regx) regfree(&generic_pattern);
233
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
789 if (white_regx) regfree(&white_pattern);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
790 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
791
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
792
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
793 bool CONTEXT::is_parent(CONTEXTP p) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
794 if (p == parent) return true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
795 if (!parent) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
796 return parent->is_parent(p);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
797 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
798
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
799
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
800 const char *CONTEXT::get_full_name(char *buffer, int size) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
801 if (!parent) return name;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
802 char buf[maxlen];
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
803 snprintf(buffer, size, "%s.%s", parent->get_full_name(buf, maxlen), name);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
804 return buffer;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
805 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
806
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
807
233
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
808 bool CONTEXT::set_white(const char *regx)
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
809 {
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
810 int rc = 0;
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
811 if (white_regx) regfree(&white_pattern);
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
812 white_regx = regx;
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
813 if (white_regx) {
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
814 rc = regcomp(&white_pattern, regx, REG_NOSUB | REG_ICASE | REG_EXTENDED);
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
815 }
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
816 return rc; // true iff bad pattern
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
817 }
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
818
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
819
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
820 bool CONTEXT::white_match(const char *from)
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
821 {
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
822 return (from &&
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
823 white_regx &&
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
824 (0 == regexec(&white_pattern, from, 0, NULL, 0)));
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
825 }
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
826
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
827
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
828 bool CONTEXT::set_generic(const char *regx, const char *msg)
168
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
829 {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
830 int rc = 0;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
831 if (generic_regx) regfree(&generic_pattern);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
832 generic_regx = regx;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
833 generic_message = msg;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
834 if (generic_regx) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
835 rc = regcomp(&generic_pattern, regx, REG_NOSUB | REG_ICASE | REG_EXTENDED);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
836 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
837 return rc; // true iff bad pattern
168
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
838 }
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
839
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
840
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
841 const char *CONTEXT::generic_match(const char *client)
168
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
842 {
195
797299e9fffc fix null dereference if missing _ macro
carl
parents: 192
diff changeset
843 if (!client) return NULL; // allow missing _ macro, which will disable generic checking
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
844 if (parent && !generic_regx) return parent->generic_match(client);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
845 if (!generic_regx) return NULL;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
846 if (0 == regexec(&generic_pattern, client, 0, NULL, 0)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
847 return generic_message;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
848 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
849 return NULL;
168
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
850 }
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
851
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
852
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
853 bool CONTEXT::cover_env_to(const char *to) {
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
854 const char *x = strchr(to, '@');
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
855 if (x) x++;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
856 else x = to;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
857 if (*x == '\0') return true; // always allow covering addresses with no domain name, eg abuse@
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
858 if (!parent && env_to.empty()) return true; // empty env_to at global level covers everything
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
859 string_set::iterator i = env_to.find(x);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
860 if (i != env_to.end()) return true; // we cover the entire domain
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
861 if (x != to) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
862 i = env_to.find(to);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
863 if (i != env_to.end()) return true; // we cover the specific email address
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
864 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
865 return false;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
866 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
867
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
868
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
869 VERIFYP CONTEXT::find_verify(const char *to) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
870 if (verifier && (verify_host != token_myhostname) && cover_env_to(to))
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
871 return verifier;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
872 else if (parent)
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
873 return parent->find_verify(to);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
874 else
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
875 return NULL;
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
876 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
877
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
878
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
879 WHITELISTERP CONTEXT::find_autowhite(const char *from, const char *to) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
880 if (whitelister && cover_env_to(to) && !cover_env_to(from))
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
881 return whitelister;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
882 else if (parent)
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
883 return parent->find_autowhite(from, to);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
884 else
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
885 return NULL;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
886 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
887
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
888
278
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
889 int CONTEXT::find_rate_limit(const char *user) {
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
890 if (rcpt_per_hour.empty()) return default_rate_limit;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
891 rates::iterator i = rcpt_per_hour.find(user); // look for authen id, or sender user@email limiting
259
be939802c64e add recipient rate limits by email from address or domain
Carl Byington <carl@five-ten-sg.com>
parents: 255
diff changeset
892 if (i != rcpt_per_hour.end()) return (*i).second; // found authen id, or user@email limiting
be939802c64e add recipient rate limits by email from address or domain
Carl Byington <carl@five-ten-sg.com>
parents: 255
diff changeset
893 const char *f = strchr(user, '@');
278
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
894 if (!f) return default_rate_limit;
259
be939802c64e add recipient rate limits by email from address or domain
Carl Byington <carl@five-ten-sg.com>
parents: 255
diff changeset
895 i = rcpt_per_hour.find(f); // look for @domain limiting
be939802c64e add recipient rate limits by email from address or domain
Carl Byington <carl@five-ten-sg.com>
parents: 255
diff changeset
896 if (i != rcpt_per_hour.end()) return (*i).second; // found @domain limiting
278
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
897 return default_rate_limit;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
898 }
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
899
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
900
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
901 int CONTEXT::find_address_limit(const char *user) {
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
902 if (addresses_per_hour.empty()) return default_address_limit;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
903 rates::iterator i = addresses_per_hour.find(user); // look for authen id, or sender user@email limiting
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
904 if (i != addresses_per_hour.end()) return (*i).second; // found authen id, or user@email limiting
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
905 const char *f = strchr(user, '@');
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
906 if (!f) return default_address_limit;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
907 i = addresses_per_hour.find(f); // look for @domain limiting
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
908 if (i != addresses_per_hour.end()) return (*i).second; // found @domain limiting
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
909 return default_address_limit;
259
be939802c64e add recipient rate limits by email from address or domain
Carl Byington <carl@five-ten-sg.com>
parents: 255
diff changeset
910 }
be939802c64e add recipient rate limits by email from address or domain
Carl Byington <carl@five-ten-sg.com>
parents: 255
diff changeset
911
be939802c64e add recipient rate limits by email from address or domain
Carl Byington <carl@five-ten-sg.com>
parents: 255
diff changeset
912
be939802c64e add recipient rate limits by email from address or domain
Carl Byington <carl@five-ten-sg.com>
parents: 255
diff changeset
913 bool CONTEXT::is_unauthenticated_limited(const char *user) {
278
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
914 rates::iterator i = rcpt_per_hour.find(user); // look for sender user@email limiting
259
be939802c64e add recipient rate limits by email from address or domain
Carl Byington <carl@five-ten-sg.com>
parents: 255
diff changeset
915 if (i != rcpt_per_hour.end()) return true; // found user@email limiting
be939802c64e add recipient rate limits by email from address or domain
Carl Byington <carl@five-ten-sg.com>
parents: 255
diff changeset
916 const char *f = strchr(user, '@');
266
582cfb9c4031 fix unauthenticated rate limit bug for empty mail from
Carl Byington <carl@five-ten-sg.com>
parents: 263
diff changeset
917 if (!f) return false;
259
be939802c64e add recipient rate limits by email from address or domain
Carl Byington <carl@five-ten-sg.com>
parents: 255
diff changeset
918 i = rcpt_per_hour.find(f); // look for sender @domain limiting
be939802c64e add recipient rate limits by email from address or domain
Carl Byington <carl@five-ten-sg.com>
parents: 255
diff changeset
919 return (i != rcpt_per_hour.end()); // found @domain limiting
136
f4746d8a12a3 add smtp auth rate limits
carl
parents: 129
diff changeset
920 }
f4746d8a12a3 add smtp auth rate limits
carl
parents: 129
diff changeset
921
f4746d8a12a3 add smtp auth rate limits
carl
parents: 129
diff changeset
922
233
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
923 const char *CONTEXT::find_from(const char *from, bool update_white, const char *queueid) {
211
4db1457cd11a Extend auto-whitelisting when receiving mail even if the auto whitelist is specified in a parent context.
Carl Byington <carl@five-ten-sg.com>
parents: 203
diff changeset
924 WHITELISTERP w = whitelister;
4db1457cd11a Extend auto-whitelisting when receiving mail even if the auto whitelist is specified in a parent context.
Carl Byington <carl@five-ten-sg.com>
parents: 203
diff changeset
925 CONTEXTP p = parent;
4db1457cd11a Extend auto-whitelisting when receiving mail even if the auto whitelist is specified in a parent context.
Carl Byington <carl@five-ten-sg.com>
parents: 203
diff changeset
926 while (!w && p) {
4db1457cd11a Extend auto-whitelisting when receiving mail even if the auto whitelist is specified in a parent context.
Carl Byington <carl@five-ten-sg.com>
parents: 203
diff changeset
927 w = p->whitelister;
4db1457cd11a Extend auto-whitelisting when receiving mail even if the auto whitelist is specified in a parent context.
Carl Byington <carl@five-ten-sg.com>
parents: 203
diff changeset
928 p = p->parent;
4db1457cd11a Extend auto-whitelisting when receiving mail even if the auto whitelist is specified in a parent context.
Carl Byington <carl@five-ten-sg.com>
parents: 203
diff changeset
929 }
4db1457cd11a Extend auto-whitelisting when receiving mail even if the auto whitelist is specified in a parent context.
Carl Byington <carl@five-ten-sg.com>
parents: 203
diff changeset
930 if (w && w->is_white(from)) {
233
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
931 if (update_white && queueid) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
932 // update senders timestamp to extend the whitelisting period
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
933 if (debug_syslog > 1) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
934 char buf[maxlen];
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
935 char msg[maxlen];
438
1686cb639269 code cleanup
Carl Byington <carl@five-ten-sg.com>
parents: 436
diff changeset
936 snprintf(msg, sizeof(msg), "extend whitelist reply from <%s> in context %s", from, get_full_name(buf,maxlen));
1686cb639269 code cleanup
Carl Byington <carl@five-ten-sg.com>
parents: 436
diff changeset
937 my_syslog(queueid, msg);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
938 }
211
4db1457cd11a Extend auto-whitelisting when receiving mail even if the auto whitelist is specified in a parent context.
Carl Byington <carl@five-ten-sg.com>
parents: 203
diff changeset
939 w->sent(strdup(from));
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
940 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
941 return token_white;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
942 }
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
943 const char *rc = env_from_default;
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
944 string_map::iterator i = env_from.find(from);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
945 if (i != env_from.end()) rc = (*i).second; // found user@domain key
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
946 else {
244
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
947 const char *x = strchr(from, '@');
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
948 if (x) {
244
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
949 char buf[200];
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
950 x++;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
951 i = env_from.find(x);
244
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
952 size_t n = x - from; // length of user name plus @
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
953 if (i != env_from.end()) rc = (*i).second; // found domain key
244
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
954 else if (n < sizeof(buf)) {
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
955 // we only test reasonably short user names, since we need
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
956 // to copy them to a buffer to avoid a dup/free cycle on every
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
957 // test here.
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
958 strncpy(buf, from, n);
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
959 buf[n] = '\0';
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
960 i = env_from.find(buf);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
961 if (i != env_from.end()) rc = (*i).second; // found user@ key
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
962 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
963 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
964 }
233
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
965 if ((rc == token_inherit) || (rc == token_unknown)) {
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
966 bool ok = white_match(from);
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
967 if (ok) rc = token_white;
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
968 }
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
969 if ((rc == token_inherit) && parent) return parent->find_from(from);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
970 return (rc == token_inherit) ? token_unknown : rc;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
971 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
972
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
973
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
974 CONTEXTP CONTEXT::find_context(const char *from) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
975 context_map::iterator i = env_from_context.find(from);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
976 if (i != env_from_context.end()) return (*i).second; // found user@domain key
244
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
977 const char *x = strchr(from, '@');
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
978 if (x) {
244
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
979 char buf[200];
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
980 x++;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
981 i = env_from_context.find(x);
244
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
982 size_t n = x - from; // length of user name plus @
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
983 if (i != env_from_context.end()) return (*i).second; // found domain key
244
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
984 else if (n < sizeof(buf)) {
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
985 // we only test reasonably short user names, since we need
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
986 // to copy them to a buffer to avoid a dup/free cycle on every
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
987 // test here.
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
988 strncpy(buf, from, n);
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
989 buf[n] = '\0';
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
990 i = env_from_context.find(buf);
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
991 if (i != env_from_context.end()) return (*i).second; // found user@ key
ef97c7cd4a6e const correctness fixes from new gcc, libresolv.a moved to glibc-static on newer distributions
Carl Byington <carl@five-ten-sg.com>
parents: 233
diff changeset
992 }
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
993 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
994 return this;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
995 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
996
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
997
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
998 CONTEXTP CONTEXT::find_from_context_name(const char *name) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
999 context_map::iterator i = children.find(name);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1000 if (i != children.end()) return (*i).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1001 return NULL;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1002 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1003
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1004
321
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1005 const char *CONTEXT::find_dkim_signer(const char *name) {
332
ed04479a8e12 allow missing domain in header from value
Carl Byington <carl@five-ten-sg.com>
parents: 331
diff changeset
1006 if (!name) return NULL;
321
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1007 string_map::iterator i = dkim_signer_names.find(name);
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1008 if (i != dkim_signer_names.end()) return (*i).second;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1009 if (parent) return parent->find_dkim_signer(name);
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1010 return NULL;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1011 }
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1012
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1013
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1014 DKIMP CONTEXT::find_dkim_from(const char *name) {
332
ed04479a8e12 allow missing domain in header from value
Carl Byington <carl@five-ten-sg.com>
parents: 331
diff changeset
1015 if (!name) return NULL;
321
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1016 dkimp_map::iterator i = dkim_from_names.find(name);
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1017 if (i != dkim_from_names.end()) return (*i).second;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1018 if (parent) return parent->find_dkim_from(name);
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1019 return NULL;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1020 }
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1021
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
1022
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1023 DNSBLP CONTEXT::find_dnsbl(const char *name) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1024 dnsblp_map::iterator i = dnsbl_names.find(name);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1025 if (i != dnsbl_names.end()) return (*i).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1026 if (parent) return parent->find_dnsbl(name);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1027 return NULL;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1028 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1029
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1030
249
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1031 DNSWLP CONTEXT::find_dnswl(const char *name) {
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1032 dnswlp_map::iterator i = dnswl_names.find(name);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1033 if (i != dnswl_names.end()) return (*i).second;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1034 if (parent) return parent->find_dnswl(name);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1035 return NULL;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1036 }
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1037
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1038
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1039 const char* CONTEXT::get_content_suffix() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1040 if (!content_suffix && parent) return parent->get_content_suffix();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1041 return content_suffix;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1042 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1043
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1044
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1045 const char* CONTEXT::get_uribl_suffix() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1046 if (!uribl_suffix && parent) return parent->get_uribl_suffix();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1047 return uribl_suffix;
119
d9d2f8699621 uribl patch from Jeff Evans <jeffe@tricab.com>
carl
parents: 117
diff changeset
1048 }
d9d2f8699621 uribl patch from Jeff Evans <jeffe@tricab.com>
carl
parents: 117
diff changeset
1049
d9d2f8699621 uribl patch from Jeff Evans <jeffe@tricab.com>
carl
parents: 117
diff changeset
1050
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1051 const char* CONTEXT::get_content_message() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1052 if (!content_message && parent) return parent->get_content_message();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1053 return content_message;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1054 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1055
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1056
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1057 const char* CONTEXT::get_uribl_message() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1058 if (!uribl_message && parent) return parent->get_uribl_message();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1059 return uribl_message;
119
d9d2f8699621 uribl patch from Jeff Evans <jeffe@tricab.com>
carl
parents: 117
diff changeset
1060 }
d9d2f8699621 uribl patch from Jeff Evans <jeffe@tricab.com>
carl
parents: 117
diff changeset
1061
d9d2f8699621 uribl patch from Jeff Evans <jeffe@tricab.com>
carl
parents: 117
diff changeset
1062
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1063 string_set& CONTEXT::get_content_host_ignore() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1064 if (content_host_ignore.empty() && parent) return parent->get_content_host_ignore();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1065 return content_host_ignore;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1066 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1067
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1068
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1069 string_set& CONTEXT::get_content_tlds() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1070 if (content_tlds.empty() && parent) return parent->get_content_tlds();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1071 return content_tlds;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1072 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1073
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1074
270
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1075 string_set& CONTEXT::get_content_tldwilds() {
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1076 if (content_tldwilds.empty() && parent) return parent->get_content_tldwilds();
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1077 return content_tldwilds;
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1078 }
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1079
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1080
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1081 string_set& CONTEXT::get_content_tldnots() {
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1082 if (content_tldnots.empty() && parent) return parent->get_content_tldnots();
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1083 return content_tldnots;
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1084 }
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1085
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1086
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1087 string_set& CONTEXT::get_html_tags() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1088 if (html_tags.empty() && parent) return parent->get_html_tags();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1089 return html_tags;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1090 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1091
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1092
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1093 dnsblp_list& CONTEXT::get_dnsbl_list() {
255
d6d5c50b9278 Allow dnswl_list and dnsbl_list to be empty, to override lists specified in the ancestor contexts. Add daily recipient limits as a multiple of the hourly limits.
Carl Byington <carl@five-ten-sg.com>
parents: 249
diff changeset
1094 if (!dnsbl_list_parsed && parent) return parent->get_dnsbl_list();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1095 return dnsbl_list;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1096 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1097
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1098
249
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1099 dnswlp_list& CONTEXT::get_dnswl_list() {
255
d6d5c50b9278 Allow dnswl_list and dnsbl_list to be empty, to override lists specified in the ancestor contexts. Add daily recipient limits as a multiple of the hourly limits.
Carl Byington <carl@five-ten-sg.com>
parents: 249
diff changeset
1100 if (!dnswl_list_parsed && parent) return parent->get_dnswl_list();
249
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1101 return dnswl_list;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1102 }
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1103
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1104
329
c9932c4d8053 allow multiple dkim signers in authentication results
Carl Byington <carl@five-ten-sg.com>
parents: 326
diff changeset
1105 void CONTEXT::log(const char *queueid, const char *msg, const char *v) {
330
b5b93a7e1e6d ignore envelope-from based whitelisting if we have a dkim requirement for that domain
Carl Byington <carl@five-ten-sg.com>
parents: 329
diff changeset
1106 if (debug_syslog > 1) {
b5b93a7e1e6d ignore envelope-from based whitelisting if we have a dkim requirement for that domain
Carl Byington <carl@five-ten-sg.com>
parents: 329
diff changeset
1107 char buf[maxlen];
b5b93a7e1e6d ignore envelope-from based whitelisting if we have a dkim requirement for that domain
Carl Byington <carl@five-ten-sg.com>
parents: 329
diff changeset
1108 snprintf(buf, maxlen, msg, v);
b5b93a7e1e6d ignore envelope-from based whitelisting if we have a dkim requirement for that domain
Carl Byington <carl@five-ten-sg.com>
parents: 329
diff changeset
1109 my_syslog(queueid, buf);
b5b93a7e1e6d ignore envelope-from based whitelisting if we have a dkim requirement for that domain
Carl Byington <carl@five-ten-sg.com>
parents: 329
diff changeset
1110 }
329
c9932c4d8053 allow multiple dkim signers in authentication results
Carl Byington <carl@five-ten-sg.com>
parents: 326
diff changeset
1111 }
c9932c4d8053 allow multiple dkim signers in authentication results
Carl Byington <carl@five-ten-sg.com>
parents: 326
diff changeset
1112
c9932c4d8053 allow multiple dkim signers in authentication results
Carl Byington <carl@five-ten-sg.com>
parents: 326
diff changeset
1113
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1114 const char *CONTEXT::extra_spf_data(const char *signers) {
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1115 const char *e = strchr(signers, ';');
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1116 if (e) e++;
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1117 return e;
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1118 }
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1119
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1120
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1121 bool CONTEXT::in_signing_set(const char *s, const char *signers) {
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1122 // s is an actual signer
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1123 // signers is the set of acceptable signers, separated by commas
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1124 size_t n = strlen(s);
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1125 const char *p = signers;
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1126 char *e = (char *)strchr(p, ';'); // only search up to ; which separates signers from extra spf data
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1127 if (e) *e = '\0';
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1128 bool rc = true;
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1129 do {
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1130 const char *c = strchr(p, ',');
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1131 size_t m = (c) ? c-p : strlen(p); // length of this element in the signing set
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1132 if ((m == n) && (strncasecmp(p, s, n) == 0)) break; // exact match
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1133 if ((*p == '*') && (n >= m)) {
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1134 if (strncasecmp(p+1, s+n-(m-1), m-1) == 0) break; // wildcard match
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1135 }
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1136 if (!c) {
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1137 rc = false;
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1138 break;
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1139 }
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1140 p = c + 1;
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1141 } while (true);
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1142 if (e) *e = ';';
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1143 return rc;
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1144 }
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1145
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1146
421
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1147 void CONTEXT::replace(char *buf, char *p, const char *what)
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1148 {
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1149 // replace 4 chars in buf starting at p with what
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1150 char repl[maxlen];
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1151 size_t bn = strlen(buf);
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1152 size_t wn = strlen(what);
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1153 if ((bn - 4 + wn) < (size_t)maxlen) {
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1154 size_t n = p - buf; // leading part length
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1155 strncpy(repl, buf, n); // leading part
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1156 strcpy(repl+n, what); // replacement
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1157 strcpy(repl+n+wn, buf+n+4); // trailing part
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1158 strcpy(buf, repl);
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1159 }
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1160 }
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1161
423
c9b7b6dd1206 use both envelope from and header from for spf checks when envelope from is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 421
diff changeset
1162
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1163 bool CONTEXT::resolve_spf(const char *from, uint32_t ip, mlfiPriv *priv, const char *signers)
381
879a470c6ac3 fetch spf txt records for required dkim signers
Carl Byington <carl@five-ten-sg.com>
parents: 368
diff changeset
1164 {
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1165 const char *extraspf = extra_spf_data(signers);
397
d08da4b058e8 only ntohl() once during recursive spf txt processing
Carl Byington <carl@five-ten-sg.com>
parents: 395
diff changeset
1166 // ip is in host order
423
c9b7b6dd1206 use both envelope from and header from for spf checks when envelope from is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 421
diff changeset
1167 if (priv->mailaddr) {
421
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1168 const char *f = strchr(priv->mailaddr, '@');
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1169 if (f) {
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1170 f++;
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1171 size_t efl = strlen(f); // envelope from domain
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1172 size_t hfl = strlen(from); // header from domain
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1173 if (efl > hfl) {
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1174 size_t off = efl - hfl;
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1175 if ((f[off-1] == '.') && (strcmp(f+off,from) == 0)) {
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1176 // envelope from is a strict child of header from
423
c9b7b6dd1206 use both envelope from and header from for spf checks when envelope from is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 421
diff changeset
1177 // use envelope from rather than header from
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1178 if (resolve_one_spf(f, ip, priv, extraspf)) return true;
421
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1179 }
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1180 }
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1181 }
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1182 }
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1183 return resolve_one_spf(from, ip, priv, extraspf);
423
c9b7b6dd1206 use both envelope from and header from for spf checks when envelope from is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 421
diff changeset
1184 }
c9b7b6dd1206 use both envelope from and header from for spf checks when envelope from is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 421
diff changeset
1185
c9b7b6dd1206 use both envelope from and header from for spf checks when envelope from is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 421
diff changeset
1186
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1187 bool CONTEXT::resolve_one_spf(const char *from, uint32_t ip, mlfiPriv *priv, const char *extraspf, int level)
423
c9b7b6dd1206 use both envelope from and header from for spf checks when envelope from is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 421
diff changeset
1188 {
428
6f2db3d19a34 allow 4000 byte spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 423
diff changeset
1189 char buf[maxdnslength];
384
7b7066a51c33 start parsing spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 382
diff changeset
1190 log(priv->queueid, "looking for %s txt record", from);
428
6f2db3d19a34 allow 4000 byte spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 423
diff changeset
1191 dns_interface(*priv, from, ns_t_txt, false, NULL, buf, maxdnslength);
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1192 if ((level == 0) &&
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1193 extraspf &&
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1194 ((strlen(buf) + strlen(extraspf) + 1) < sizeof(buf))) {
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1195 strcat(buf, " ");
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1196 strcat(buf, extraspf);
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1197 }
381
879a470c6ac3 fetch spf txt records for required dkim signers
Carl Byington <carl@five-ten-sg.com>
parents: 368
diff changeset
1198 if (*buf) {
384
7b7066a51c33 start parsing spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 382
diff changeset
1199 log(priv->queueid, "found txt record %s", buf);
414
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1200 // expand some macros here - a very restricted subset of all possible spf macros
421
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1201 // only expand the first instance of each.
414
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1202 char *p = strstr(buf, "%{i}");
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1203 if (p) {
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1204 char adr[sizeof "255.255.255.255 "];
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1205 adr[0] = '\0';
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1206 inet_ntop(AF_INET, (const u_char *)&priv->ip, adr, sizeof(adr));
421
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1207 replace(buf, p, adr);
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1208 log(priv->queueid, "have txt record %s", buf);
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1209 }
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1210 p = strstr(buf, "%{h}");
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1211 if (p) {
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1212 replace(buf, p, priv->helo);
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1213 log(priv->queueid, "have txt record %s", buf);
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1214 }
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1215 p = strstr(buf, "%{d}");
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1216 if (p) {
22027ad2a28f spf code now handles %{d} and %{h} macros; use envelope from value for spf if it is a subdomain of the header from domain
Carl Byington <carl@five-ten-sg.com>
parents: 419
diff changeset
1217 replace(buf, p, from);
414
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1218 log(priv->queueid, "have txt record %s", buf);
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1219 }
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1220 //
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1221 p = strchr(buf, ' '); // must start with 'v=spf1 '
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1222 if (!p) return false; // broken spf
382
c378e9d03f37 start parsing spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 381
diff changeset
1223 char *e = p + strlen(p); // point to trailing null
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1224 while (true) {
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1225 while (*p == ' ') p++;
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1226 if (p >= e) break;
382
c378e9d03f37 start parsing spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 381
diff changeset
1227 char *b = strchr(p, ' ');
c378e9d03f37 start parsing spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 381
diff changeset
1228 if (b) *b = '\0';
414
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1229 if ((*p != '-') && (*p != '~') && (*p != '?')) {
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1230 if (*p == '+') p++;
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1231 if (strncmp(p, "ip4:", 4) == 0) {
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1232 p += 4;
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1233 char *s = strchr(p, '/');
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1234 if (s) *s = '\0';
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1235 in_addr ipx;
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1236 if (inet_aton(p, &ipx)) {
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1237 uint32_t ipy = ntohl(ipx.s_addr);
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1238 int mask = (s) ? atoi(s+1) : 32;
460
ad05c61d6372 add debug code for spf check with microsoft /14
Carl Byington <carl@five-ten-sg.com>
parents: 455
diff changeset
1239 if ((mask >= 14) && (mask <= 32)) { // microsoft has a /14
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1240 uint32_t low = (1 << (32-mask)) - 1;
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1241 ipy &= low ^ 0xffffffff;
460
ad05c61d6372 add debug code for spf check with microsoft /14
Carl Byington <carl@five-ten-sg.com>
parents: 455
diff changeset
1242 {
ad05c61d6372 add debug code for spf check with microsoft /14
Carl Byington <carl@five-ten-sg.com>
parents: 455
diff changeset
1243 char buf[maxlen];
ad05c61d6372 add debug code for spf check with microsoft /14
Carl Byington <carl@five-ten-sg.com>
parents: 455
diff changeset
1244 snprintf(buf, maxlen, "ip=%08x, spf=%08x/%d, mask=%08x", ip, ipy, mask, low);
ad05c61d6372 add debug code for spf check with microsoft /14
Carl Byington <carl@five-ten-sg.com>
parents: 455
diff changeset
1245 log(priv->queueid, "spf check %s", buf);
ad05c61d6372 add debug code for spf check with microsoft /14
Carl Byington <carl@five-ten-sg.com>
parents: 455
diff changeset
1246 }
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1247 if ((ipy <= ip) && (ip <= ipy + low)) {
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1248 if (s) *s = '/';
414
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1249 log(priv->queueid, "match ip4:%s", p);
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1250 return true;
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1251 }
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1252 }
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1253 }
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1254 }
414
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1255 else if (strncmp(p, "all", 3) == 0) {
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1256 // ignore it before looking for (a or a:) below
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1257 }
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1258 else if (strncmp(p, "exists:", 7) == 0) {
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1259 p += 7;
428
6f2db3d19a34 allow 4000 byte spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 423
diff changeset
1260 char buf[maxdnslength];
6f2db3d19a34 allow 4000 byte spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 423
diff changeset
1261 dns_interface(*priv, p, ns_t_a, false, NULL, buf, maxdnslength);
414
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1262 uint32_t *a = (uint32_t *)buf;
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1263 if (a[0]) {
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1264 log(priv->queueid, "match exists:%s", p);
388
2354a1944e49 start parsing spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 384
diff changeset
1265 return true;
382
c378e9d03f37 start parsing spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 381
diff changeset
1266 }
c378e9d03f37 start parsing spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 381
diff changeset
1267 }
414
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1268 else if (strncmp(p, "mx", 2) == 0) {
449
d4275f26241c fix spf mx:domain.tld token parsing
Carl Byington <carl@five-ten-sg.com>
parents: 445
diff changeset
1269 const char *name = (p[2] == ':') ? p+3 : from;
428
6f2db3d19a34 allow 4000 byte spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 423
diff changeset
1270 char buf[maxdnslength];
6f2db3d19a34 allow 4000 byte spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 423
diff changeset
1271 dns_interface(*priv, name, ns_t_mx, false, NULL, buf, maxdnslength);
414
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1272 char *b = buf;
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1273 while (*b) {
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1274 log(priv->queueid, "found mx %s", b);
428
6f2db3d19a34 allow 4000 byte spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 423
diff changeset
1275 char buf[maxdnslength];
6f2db3d19a34 allow 4000 byte spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 423
diff changeset
1276 dns_interface(*priv, b, ns_t_a, false, NULL, buf, maxdnslength);
414
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1277 uint32_t *a = (uint32_t *)buf;
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1278 size_t c = a[0];
415
16451edcb962 spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 414
diff changeset
1279 for (size_t i=1; i<=c; i++) {
416
7431e948b5c3 spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 415
diff changeset
1280 uint32_t ipy = ntohl(a[i]);
419
91f2a127ec69 spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 417
diff changeset
1281 char adr[sizeof "255.255.255.255 "]; //!!
91f2a127ec69 spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 417
diff changeset
1282 adr[0] = '\0'; //!!
91f2a127ec69 spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 417
diff changeset
1283 inet_ntop(AF_INET, (const u_char *)&(a[i]), adr, sizeof(adr)); //!!
91f2a127ec69 spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 417
diff changeset
1284 log(priv->queueid, "found mx a %s", adr); //!!
414
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1285 if (ipy == ip) {
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1286 log(priv->queueid, "match mx:%s", name);
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1287 return true;
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1288 }
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1289 }
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1290 b += strlen(b) + 1;
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1291 }
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1292 }
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1293 else if (p[0] == 'a') {
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1294 const char *name = (p[1] == ':') ? p+2 : from;
428
6f2db3d19a34 allow 4000 byte spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 423
diff changeset
1295 char buf[maxdnslength];
6f2db3d19a34 allow 4000 byte spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 423
diff changeset
1296 dns_interface(*priv, name, ns_t_a, false, NULL, buf, maxdnslength);
414
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1297 uint32_t *a = (uint32_t *)buf;
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1298 size_t c = a[0];
415
16451edcb962 spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 414
diff changeset
1299 for (size_t i=1; i<=c; i++) {
416
7431e948b5c3 spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 415
diff changeset
1300 uint32_t ipy = ntohl(a[i]);
414
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1301 if (ipy == ip) {
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1302 log(priv->queueid, "match a:%s", name);
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1303 return true;
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1304 }
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1305 }
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1306 }
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1307 else if (priv->client_dns_name && (!priv->client_dns_forged) && (strncmp(p, "ptr", 3) == 0)) {
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1308 const char *name = (p[3] == ':') ? p+4 : from;
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1309 size_t n = strlen(name);
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1310 size_t d = strlen(priv->client_dns_name);
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1311 if (d >= n) {
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1312 if ((strncmp(priv->client_dns_name+d-n, name, n) == 0) && // trailing part matches
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1313 ((d == n) || (priv->client_dns_name[d-n-1] == '.'))) { // same length, or dot just before match
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1314 log(priv->queueid, "match ptr:%s", priv->client_dns_name);
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1315 return true;
d5a1ed33d3ae spf code now handles mx,exists,ptr tags, multiple A records, %{i} macro
Carl Byington <carl@five-ten-sg.com>
parents: 412
diff changeset
1316 }
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1317 }
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1318 }
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1319 else if ((level < 5) && (strncmp(p, "redirect=", 9) == 0)) {
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1320 p += 9;
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1321 if (resolve_one_spf(p, ip, priv, NULL, level+1)) return true;
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1322 }
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1323 else if ((level < 5) && (strncmp(p, "include:", 8) == 0)) {
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1324 p += 8;
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1325 if (resolve_one_spf(p, ip, priv, NULL, level+1)) return true;
400
b48ee4bc431b handle a and a: elements in spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 398
diff changeset
1326 }
b48ee4bc431b handle a and a: elements in spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 398
diff changeset
1327 }
412
e63c6b4835ef refactor spf code; allow wildcard *.example.com in dkim signing restrictions
Carl Byington <carl@five-ten-sg.com>
parents: 407
diff changeset
1328 p = (b) ? b+1 : e;
382
c378e9d03f37 start parsing spf txt records
Carl Byington <carl@five-ten-sg.com>
parents: 381
diff changeset
1329 }
381
879a470c6ac3 fetch spf txt records for required dkim signers
Carl Byington <carl@five-ten-sg.com>
parents: 368
diff changeset
1330 }
879a470c6ac3 fetch spf txt records for required dkim signers
Carl Byington <carl@five-ten-sg.com>
parents: 368
diff changeset
1331 return false;
879a470c6ac3 fetch spf txt records for required dkim signers
Carl Byington <carl@five-ten-sg.com>
parents: 368
diff changeset
1332 }
879a470c6ac3 fetch spf txt records for required dkim signers
Carl Byington <carl@five-ten-sg.com>
parents: 368
diff changeset
1333
879a470c6ac3 fetch spf txt records for required dkim signers
Carl Byington <carl@five-ten-sg.com>
parents: 368
diff changeset
1334
436
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1335 const char *CONTEXT::acceptable_content(bool local_source, recorder &memory, int score, int bulk, const char *queueid, string_set &signers, const char *from, mlfiPriv *priv, string& msg) {
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1336 if (!local_source) {
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1337 for (string_set::iterator s=signers.begin(); s!=signers.end(); s++) {
436
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1338 const char *st = find_dkim_signer(*s);
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1339 // signed by a white listed signer
436
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1340 if (st == token_white) {
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1341 log(queueid, "whitelisted dkim signer %s", *s);
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1342 return token_white;
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1343 }
436
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1344 }
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1345
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1346 DKIMP dk = find_dkim_from(from);
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1347 if (dk) {
455
48cfa55cd73b add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 453
diff changeset
1348 char buf[maxlen];
48cfa55cd73b add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 453
diff changeset
1349 snprintf(buf, sizeof(buf), "context %s found dkim from %s action %s", name, from, dk->action);
48cfa55cd73b add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 453
diff changeset
1350 my_syslog(queueid, buf);
436
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1351 const char *st = dk->action;
451
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1352 bool dmarc = false;
436
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1353 for (string_set::iterator s=signers.begin(); s!=signers.end(); s++) {
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1354 // signed by a white listed signer
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1355 if ((st == token_signed_white) && in_signing_set(*s,dk->signer)) {
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1356 log(queueid, "whitelisted dkim signer %s", *s);
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1357 return token_white;
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1358 }
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1359 // signed by a required signer
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1360 if ((st == token_require_signed) && in_signing_set(*s,dk->signer)) {
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1361 log(queueid, "required dkim signer %s", *s);
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1362 return token_white;
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1363 }
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1364 // signed by a black listed signer
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1365 if ((st == token_signed_black) && in_signing_set(*s,dk->signer)) {
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1366 char buf[maxlen];
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1367 snprintf(buf, sizeof(buf), "Mail rejected - dkim signed by %s", *s);
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1368 msg = string(buf);
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1369 return token_black;
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1370 }
451
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1371 if ((st == token_unsigned_black) && in_signing_set(*s,dk->signer)) {
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1372 dmarc = true;
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1373 }
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1374 }
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1375 if (st == token_unsigned_black) {
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1376 // enforce dmarc
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1377 if (!dmarc) {
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1378 dmarc = resolve_spf(from, ntohl(priv->ip), priv, dk->signer);
451
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1379 }
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1380 if (!dmarc) {
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1381 // not signed and does not pass spf, reject it
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1382 char buf[maxlen];
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1383 snprintf(buf, sizeof(buf), "Mail rejected - not dkim signed by %s", dk->signer);
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1384 msg = string(buf);
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1385 return token_black;
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
1386 }
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1387 }
436
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1388 if (st == token_signed_white) {
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1389 // not signed by a white listed signer, but maybe passes strong spf check
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1390 if (resolve_spf(from, ntohl(priv->ip), priv, dk->signer)) {
436
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1391 log(queueid, "spf pass for %s rather than whitelisted dkim signer", from);
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1392 return token_white;
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1393 }
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1394 }
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1395 if (st == token_require_signed) {
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1396 // not signed by a required signer, but maybe passes strong spf check
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1397 // only check spf if the list of required signers is not a single dot.
462
f3f1ece619ba change dkim_from syntax to allow "signer1,signer2;spf data"
Carl Byington <carl@five-ten-sg.com>
parents: 460
diff changeset
1398 if (strcmp(dk->signer, ".") && resolve_spf(from, ntohl(priv->ip), priv, dk->signer)) {
436
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1399 log(queueid, "spf pass for %s rather than required dkim signer", from);
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1400 return token_white;
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1401 }
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1402 // todo - we could also check spf for the rfc5321 envelope from domain,
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1403 // if it is dmarc aligned (relaxed) with the rfc5322 header from domain.
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1404 char buf[maxlen];
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1405 snprintf(buf, sizeof(buf), "Mail rejected - not dkim signed by %s", dk->signer);
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1406 msg = string(buf);
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1407 return token_black;
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1408 }
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1409 }
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1410
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1411 for (string_set::iterator s=signers.begin(); s!=signers.end(); s++) {
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1412 const char *st = find_dkim_signer(*s);
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1413 // signed by a black listed signer
436
7b072e16bd69 fix syslog for long messages, supress dkim checks for mail from localhost
Carl Byington <carl@five-ten-sg.com>
parents: 430
diff changeset
1414 if (st == token_black) {
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1415 char buf[maxlen];
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1416 snprintf(buf, sizeof(buf), "Mail rejected - dkim signed by %s", *s);
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1417 msg = string(buf);
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1418 return token_black;
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1419 }
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1420 }
326
5e4b5540c8cc allow multiple dkim signers in authentication results
Carl Byington <carl@five-ten-sg.com>
parents: 324
diff changeset
1421 }
5e4b5540c8cc allow multiple dkim signers in authentication results
Carl Byington <carl@five-ten-sg.com>
parents: 324
diff changeset
1422
445
78eedbbce636 round spamassassin scores; check >= rather than >
Carl Byington <carl@five-ten-sg.com>
parents: 438
diff changeset
1423 if (spamassassin_limit && (score >= spamassassin_limit)) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1424 char buf[maxlen];
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1425 snprintf(buf, sizeof(buf), "Mail rejected - spam assassin score %d", score);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1426 msg = string(buf);
331
9800776436b9 allow dkim whitelisting to override uribl hosts in the mail body
Carl Byington <carl@five-ten-sg.com>
parents: 330
diff changeset
1427 return token_black;
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1428 }
203
92a5c866bdfa Verify from/to pairs even if they might be explicitly whitelisted.
Carl Byington <carl@five-ten-sg.com>
parents: 195
diff changeset
1429 if (dcc_bulk_threshold && (bulk >= dcc_bulk_threshold)) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1430 char buf[maxlen];
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1431 snprintf(buf, sizeof(buf), "Mail rejected - dcc score %d", bulk);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1432 msg = string(buf);
331
9800776436b9 allow dkim whitelisting to override uribl hosts in the mail body
Carl Byington <carl@five-ten-sg.com>
parents: 330
diff changeset
1433 return token_black;
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1434 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1435 if (memory.excessive_bad_tags(tag_limit)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1436 msg = string(tag_limit_message);
331
9800776436b9 allow dkim whitelisting to override uribl hosts in the mail body
Carl Byington <carl@five-ten-sg.com>
parents: 330
diff changeset
1437 return token_black;
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1438 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1439 if (!host_random && memory.excessive_hosts(host_limit)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1440 msg = string(host_limit_message);
331
9800776436b9 allow dkim whitelisting to override uribl hosts in the mail body
Carl Byington <carl@five-ten-sg.com>
parents: 330
diff changeset
1441 return token_black;
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1442 }
331
9800776436b9 allow dkim whitelisting to override uribl hosts in the mail body
Carl Byington <carl@five-ten-sg.com>
parents: 330
diff changeset
1443 return token_unknown;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1444 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1445
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1446
167
9b129ed78d7d actually use spamassassin result, allow build without spam assassin, only call it if some recipient needs it.
carl
parents: 164
diff changeset
1447 void CONTEXT::dump(bool isdefault, bool &spamass, int level) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1448 char indent[maxlen];
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1449 int i = min(maxlen-1, level*4);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1450 memset(indent, ' ', i);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1451 indent[i] = '\0';
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1452 char buf[maxlen];
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1453 const char *fullname = get_full_name(buf,maxlen);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1454 printf("%s context %s { \t// %s\n", indent, name, fullname);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1455
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1456 for (dnsblp_map::iterator i=dnsbl_names.begin(); i!=dnsbl_names.end(); i++) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1457 const char *n = (*i).first;
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1458 DNSBL &d = *(*i).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1459 printf("%s dnsbl %s %s \"%s\"; \n", indent, n, d.suffix, d.message);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1460 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1461
249
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1462 for (dnswlp_map::iterator i=dnswl_names.begin(); i!=dnswl_names.end(); i++) {
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1463 const char *n = (*i).first;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1464 DNSWL &d = *(*i).second;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1465 printf("%s dnswl %s %s %d; \n", indent, n, d.suffix, d.level);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1466 }
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1467
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1468 {
255
d6d5c50b9278 Allow dnswl_list and dnsbl_list to be empty, to override lists specified in the ancestor contexts. Add daily recipient limits as a multiple of the hourly limits.
Carl Byington <carl@five-ten-sg.com>
parents: 249
diff changeset
1469 dnsblp_list dl = get_dnsbl_list();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1470 printf("%s dnsbl_list", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1471 for (dnsblp_list::iterator i=dl.begin(); i!=dl.end(); i++) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1472 DNSBL &d = *(*i);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1473 printf(" %s", d.name);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1474 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1475 printf("; \n");
268
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1476 printf("%s require_rdns %s; \n", indent, (require_rdns) ? "yes" : "no");
255
d6d5c50b9278 Allow dnswl_list and dnsbl_list to be empty, to override lists specified in the ancestor contexts. Add daily recipient limits as a multiple of the hourly limits.
Carl Byington <carl@five-ten-sg.com>
parents: 249
diff changeset
1477 }
249
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1478
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1479 {
255
d6d5c50b9278 Allow dnswl_list and dnsbl_list to be empty, to override lists specified in the ancestor contexts. Add daily recipient limits as a multiple of the hourly limits.
Carl Byington <carl@five-ten-sg.com>
parents: 249
diff changeset
1480 dnswlp_list dl = get_dnswl_list();
249
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1481 printf("%s dnswl_list", indent);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1482 for (dnswlp_list::iterator i=dl.begin(); i!=dl.end(); i++) {
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1483 DNSWL &d = *(*i);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1484 printf(" %s", d.name);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1485 }
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1486 printf("; \n");
255
d6d5c50b9278 Allow dnswl_list and dnsbl_list to be empty, to override lists specified in the ancestor contexts. Add daily recipient limits as a multiple of the hourly limits.
Carl Byington <carl@five-ten-sg.com>
parents: 249
diff changeset
1487 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1488
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1489 if (content_filtering) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1490 printf("%s content on { \n", indent);
322
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1491 printf("%s dkim_signer { \n", indent);
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1492 for (string_map::iterator i=dkim_signer_names.begin(); i!=dkim_signer_names.end(); i++) {
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1493 const char *n = (*i).first;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1494 const char *a = (*i).second;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1495 printf("%s %s %s; \n", indent, n, a);
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1496 }
329
c9932c4d8053 allow multiple dkim signers in authentication results
Carl Byington <carl@five-ten-sg.com>
parents: 326
diff changeset
1497 printf("%s }; \n", indent);
322
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1498 printf("%s dkim_from { \n", indent);
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1499 for (dkimp_map::iterator i=dkim_from_names.begin(); i!=dkim_from_names.end(); i++) {
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1500 const char *n = (*i).first;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1501 DKIM &d = *(*i).second;
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1502 printf("%s %s %s \"%s\"; \n", indent, n, d.action, d.signer);
322
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1503 }
329
c9932c4d8053 allow multiple dkim signers in authentication results
Carl Byington <carl@five-ten-sg.com>
parents: 326
diff changeset
1504 printf("%s }; \n", indent);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1505 if (content_suffix) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1506 printf("%s filter %s \"%s\"; \n", indent, content_suffix, content_message);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1507 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1508 if (uribl_suffix) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1509 printf("%s uribl %s \"%s\"; \n", indent, uribl_suffix, uribl_message);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1510 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1511 if (!content_host_ignore.empty()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1512 printf("%s ignore { \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1513 for (string_set::iterator i=content_host_ignore.begin(); i!=content_host_ignore.end(); i++) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1514 printf("%s %s; \n", indent, *i);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1515 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1516 printf("%s }; \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1517 }
270
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1518 if (!content_tlds.empty() || !content_tldwilds.empty() || !content_tldnots.empty()) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1519 printf("%s tld { \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1520 printf("%s ", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1521 for (string_set::iterator i=content_tlds.begin(); i!=content_tlds.end(); i++) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1522 printf("%s; ", *i);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1523 }
270
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1524 for (string_set::iterator i=content_tldwilds.begin(); i!=content_tldwilds.end(); i++) {
274
bdcf203e3f7b fix -c printing config
Carl Byington <carl@five-ten-sg.com>
parents: 272
diff changeset
1525 printf("*.%s; ", *i);
270
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1526 }
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1527 for (string_set::iterator i=content_tldnots.begin(); i!=content_tldnots.end(); i++) {
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1528 printf("!%s; ", *i);
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1529 }
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1530 printf("\n%s }; \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1531 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1532 if (!html_tags.empty()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1533 printf("%s html_tags { \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1534 printf("%s ", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1535 for (string_set::iterator i=html_tags.begin(); i!=html_tags.end(); i++) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1536 printf("%s; ", *i);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1537 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1538 printf("\n%s }; \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1539 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1540 if (host_limit_message) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1541 printf("%s host_limit on %d \"%s\"; \n", indent, host_limit, host_limit_message);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1542 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1543 else if (host_random) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1544 printf("%s host_limit soft %d; \n", indent, host_limit);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1545 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1546 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1547 printf("%s host_limit off; \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1548 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1549 if (tag_limit_message) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1550 printf("%s html_limit on %d \"%s\"; \n", indent, tag_limit, tag_limit_message);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1551 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1552 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1553 printf("%s html_limit off; \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1554 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1555 printf("%s spamassassin %d; \n", indent, spamassassin_limit);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1556 printf("%s require_match %s; \n", indent, (require_match) ? "yes" : "no");
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1557 printf("%s dcc_greylist %s; \n", indent, (dcc_greylist) ? "yes" : "no");
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1558 if (dcc_bulk_threshold == 0) printf("%s dcc_bulk_threshold off; \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1559 else if (dcc_bulk_threshold >= dccbulk) printf("%s dcc_bulk_threshold many; \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1560 else printf("%s dcc_bulk_threshold %d; \n", indent, dcc_bulk_threshold);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1561 printf("%s }; \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1562 spamass |= (spamassassin_limit != 0);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1563 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1564 else {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1565 printf("%s content off {}; \n", indent);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1566 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1567
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1568 printf("%s env_to { \t// %s\n", indent, fullname);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1569 for (string_set::iterator i=env_to.begin(); i!=env_to.end(); i++) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1570 printf("%s %s; \n", indent, *i);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1571 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1572 printf("%s }; \n", indent);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1573
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1574 if (verify_host) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1575 printf("%s verify %s; \n", indent, verify_host);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1576 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1577
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1578 if (generic_regx) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1579 printf("%s generic \"%s\" \n", indent, generic_regx);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1580 printf("%s \"%s\"; \n", indent, generic_message);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1581 }
168
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
1582
233
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
1583 if (white_regx) {
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
1584 printf("%s white_regex \"%s\"; \n", indent, white_regx);
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
1585 }
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
1586
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1587 if (autowhite_file && whitelister) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1588 printf("%s autowhite %d %s; \n", indent, whitelister->get_days(), autowhite_file);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1589 }
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
1590
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1591 for (context_map::iterator i=children.begin(); i!=children.end(); i++) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1592 CONTEXTP c = (*i).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1593 c->dump(false, spamass, level+1);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1594 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1595
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1596 printf("%s env_from %s { \t// %s\n", indent, env_from_default, fullname);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1597 if (!env_from.empty()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1598 printf("%s // white/black/unknown \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1599 for (string_map::iterator i=env_from.begin(); i!=env_from.end(); i++) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1600 const char *f = (*i).first;
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1601 const char *t = (*i).second;
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1602 printf("%s %s \t%s; \n", indent, f, t);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1603 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1604 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1605 if (!env_from_context.empty()) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1606 printf("%s // child contexts \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1607 for (context_map::iterator j=env_from_context.begin(); j!=env_from_context.end(); j++) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1608 const char *f = (*j).first;
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1609 CONTEXTP t = (*j).second;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1610 printf("%s %s \t%s; \n", indent, f, t->name);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1611 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1612 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1613 printf("%s }; \n", indent);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1614
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1615 if (isdefault) {
278
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
1616 printf("%s rate_limit %d %d %d %d { \n", indent, default_rate_limit, daily_rate_multiple, default_address_limit, daily_address_multiple);
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
1617 for (rates::iterator j=rcpt_per_hour.begin(); j!=rcpt_per_hour.end(); j++) {
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
1618 const char *u = (*j).first;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
1619 int l = (*j).second;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
1620 rates::iterator k = addresses_per_hour.find(u);
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
1621 int a = (k==addresses_per_hour.end()) ? default_address_limit : (*k).second;
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
1622 printf("%s \"%s\" \t%d %d; \n", indent, u, l, a);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1623 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1624 printf("%s }; \n", indent);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1625 }
136
f4746d8a12a3 add smtp auth rate limits
carl
parents: 129
diff changeset
1626
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1627 printf("%s }; \n", indent);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1628 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1629
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1630
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1631 ////////////////////////////////////////////////
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1632 // helper to discard the strings held by a string_set
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1633 //
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1634 void discard(string_set &s) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1635 for (string_set::iterator i=s.begin(); i!=s.end(); i++) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1636 free((void*)*i);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1637 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1638 s.clear();
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1639 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1640
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1641
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1642 ////////////////////////////////////////////////
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1643 // helper to register a string in a string set
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1644 //
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1645 const char* register_string(string_set &s, const char *name) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1646 string_set::iterator i = s.find(name);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1647 if (i != s.end()) return *i;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1648 char *x = strdup(name);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1649 s.insert(x);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1650 return x;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1651 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1652
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1653
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1654 ////////////////////////////////////////////////
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1655 // register a global string
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1656 //
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1657 const char* register_string(const char *name) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1658 return register_string(all_strings, name);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1659 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1660
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1661
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1662 ////////////////////////////////////////////////
164
5809bcdc325b spamassassin changes
carl
parents: 163
diff changeset
1663 // clear all global strings, helper for valgrind checking
5809bcdc325b spamassassin changes
carl
parents: 163
diff changeset
1664 //
5809bcdc325b spamassassin changes
carl
parents: 163
diff changeset
1665 void clear_strings() {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1666 discard(all_strings);
164
5809bcdc325b spamassassin changes
carl
parents: 163
diff changeset
1667 }
5809bcdc325b spamassassin changes
carl
parents: 163
diff changeset
1668
5809bcdc325b spamassassin changes
carl
parents: 163
diff changeset
1669
5809bcdc325b spamassassin changes
carl
parents: 163
diff changeset
1670 ////////////////////////////////////////////////
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1671 //
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1672 bool tsa(TOKEN &tok, const char *token);
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1673 bool tsa(TOKEN &tok, const char *token) {
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1674 const char *have = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1675 if (have == token) return true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1676 tok.token_error(token, have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1677 return false;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1678 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1679
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1680
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1681 ////////////////////////////////////////////////
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1682 //
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1683 bool parse_dnsbl(TOKEN &tok, CONFIG &dc, CONTEXT &me);
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1684 bool parse_dnsbl(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1685 const char *name = tok.next();
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1686 const char *suf = tok.next();
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1687 const char *msg = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1688 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1689 DNSBLP dnsnew = new DNSBL(name, suf, msg);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1690 DNSBLP dnsold = me.find_dnsbl(name);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1691 if (dnsold && (*dnsold == *dnsnew)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1692 // duplicate redefinition, ignore it
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1693 delete dnsnew;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1694 return true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1695 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1696 me.add_dnsbl(name, dnsnew);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1697 return true;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1698 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1699
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1700
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1701 ////////////////////////////////////////////////
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1702 //
249
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1703 bool parse_dnswl(TOKEN &tok, CONFIG &dc, CONTEXT &me);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1704 bool parse_dnswl(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1705 const char *name = tok.next();
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1706 const char *suf = tok.next();
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1707 const int lev = tok.nextint();
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1708 if (!tsa(tok, token_semi)) return false;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1709 DNSWLP dnsnew = new DNSWL(name, suf, lev);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1710 DNSWLP dnsold = me.find_dnswl(name);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1711 if (dnsold && (*dnsold == *dnsnew)) {
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1712 // duplicate redefinition, ignore it
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1713 delete dnsnew;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1714 return true;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1715 }
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1716 me.add_dnswl(name, dnsnew);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1717 return true;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1718 }
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1719
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1720
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1721 ////////////////////////////////////////////////
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1722 //
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1723 bool parse_dnsbll(TOKEN &tok, CONFIG &dc, CONTEXT &me);
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1724 bool parse_dnsbll(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1725 while (true) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1726 const char *have = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1727 if (!have) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1728 if (have == token_semi) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1729 DNSBLP dns = me.find_dnsbl(have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1730 if (dns) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1731 me.add_dnsbl(dns);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1732 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1733 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1734 tok.token_error("dnsbl name", have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1735 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1736 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1737 }
255
d6d5c50b9278 Allow dnswl_list and dnsbl_list to be empty, to override lists specified in the ancestor contexts. Add daily recipient limits as a multiple of the hourly limits.
Carl Byington <carl@five-ten-sg.com>
parents: 249
diff changeset
1738 me.set_dnsbll_parsed();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1739 return true;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1740 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1741
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1742
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1743 ////////////////////////////////////////////////
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1744 //
249
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1745 bool parse_dnswll(TOKEN &tok, CONFIG &dc, CONTEXT &me);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1746 bool parse_dnswll(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1747 while (true) {
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1748 const char *have = tok.next();
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1749 if (!have) break;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1750 if (have == token_semi) break;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1751 DNSWLP dns = me.find_dnswl(have);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1752 if (dns) {
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1753 me.add_dnswl(dns);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1754 }
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1755 else {
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1756 tok.token_error("dnswl name", have);
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1757 return false;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1758 }
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1759 }
255
d6d5c50b9278 Allow dnswl_list and dnsbl_list to be empty, to override lists specified in the ancestor contexts. Add daily recipient limits as a multiple of the hourly limits.
Carl Byington <carl@five-ten-sg.com>
parents: 249
diff changeset
1760 me.set_dnswll_parsed();
249
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1761 return true;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1762 }
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1763
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1764
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1765 ////////////////////////////////////////////////
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
1766 //
268
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1767 bool parse_requirerdns(TOKEN &tok, CONFIG &dc, CONTEXT &me);
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1768 bool parse_requirerdns(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1769 const char *have = tok.next();
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1770 if (have == token_yes) me.set_requirerdns(true);
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1771 else if (have == token_no) me.set_requirerdns(false);
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1772 else {
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1773 tok.token_error("yes/no", have);
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1774 return false;
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1775 }
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1776 if (!tsa(tok, token_semi)) return false;
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1777 return true;
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1778 }
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1779
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1780
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1781 ////////////////////////////////////////////////
f941563c2a95 Add require_rdns checking
Carl Byington <carl@five-ten-sg.com>
parents: 266
diff changeset
1782 //
322
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1783 bool parse_dkim_signer(TOKEN &tok, CONFIG &dc, CONTEXT &me);
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1784 bool parse_dkim_signer(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1785 if (!tsa(tok, token_lbrace)) return false;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1786 while (true) {
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1787 const char *have = tok.next();
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1788 if (!have) break;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1789 if (have == token_rbrace) break;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1790 if (have == token_semi) {
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1791 // optional separators
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1792 }
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1793 else {
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1794 const char *signer = have;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1795 const char *action = tok.next();
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1796 if ((action == token_white) || (action == token_black) || (action == token_unknown)) {
322
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1797 me.add_dkim_signer(signer, action);
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1798 }
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1799 else {
360
17f21fcd44a8 allow quoted comma separated multiple signers in the dkim_from config entries
Carl Byington <carl@five-ten-sg.com>
parents: 332
diff changeset
1800 tok.token_error("white/black/unknown", action);
322
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1801 }
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1802 }
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1803 }
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1804 return tsa(tok, token_semi);
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1805 }
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1806
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1807
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1808 ////////////////////////////////////////////////
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1809 //
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1810 bool parse_dkim_from(TOKEN &tok, CONFIG &dc, CONTEXT &me);
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1811 bool parse_dkim_from(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1812 if (!tsa(tok, token_lbrace)) return false;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1813 while (true) {
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1814 const char *have = tok.next();
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1815 if (!have) break;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1816 if (have == token_rbrace) break;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1817 if (have == token_semi) {
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1818 // optional separators
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1819 }
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1820 else {
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1821 const char *from = have;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1822 const char *action = tok.next();
453
8393ce4658cc add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 451
diff changeset
1823 if ((action == token_signed_white) || (action == token_signed_black) || (action == token_unsigned_black) || (action == token_require_signed)) {
322
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1824 const char *signer = tok.next();
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1825 if (!signer) break;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1826 else me.add_dkim_from(from, action, signer);
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1827 }
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1828 else {
453
8393ce4658cc add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 451
diff changeset
1829 tok.token_error("signed_white/signed_black/unsigned_black/require_signed", action);
322
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1830 }
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1831 }
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1832 }
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1833 return tsa(tok, token_semi);
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1834 }
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1835
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1836
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1837 ////////////////////////////////////////////////
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
1838 //
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1839 bool parse_content(TOKEN &tok, CONFIG &dc, CONTEXT &me);
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
1840 bool parse_content(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1841 const char *setting = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1842 if (setting == token_on) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1843 me.set_content_filtering(true);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1844 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1845 else if (setting == token_off) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1846 me.set_content_filtering(false);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1847 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1848 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1849 tok.token_error("on/off", setting);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1850 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1851 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1852 if (!tsa(tok, token_lbrace)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1853 while (true) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1854 const char *have = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1855 if (!have) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1856 if (have == token_filter) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1857 const char *suffix = tok.next();
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1858 const char *messag = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1859 me.set_content_suffix(suffix);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1860 me.set_content_message(messag);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1861 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1862 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1863 else if (have == token_uribl) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1864 const char *suffix = tok.next();
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1865 const char *messag = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1866 me.set_uribl_suffix(suffix);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1867 me.set_uribl_message(messag);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1868 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1869 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1870 else if (have == token_ignore) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1871 if (!tsa(tok, token_lbrace)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1872 while (true) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1873 if (!have) break;
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1874 const char *have = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1875 if (have == token_rbrace) break; // done
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1876 me.add_ignore(have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1877 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1878 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1879 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1880 else if (have == token_tld) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1881 if (!tsa(tok, token_lbrace)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1882 while (true) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1883 const char *have = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1884 if (!have) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1885 if (have == token_rbrace) break; // done
270
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1886 if (have == token_bang) {
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1887 have = tok.next();
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1888 if (!have) break;
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1889 if (have == token_rbrace) break; // done
272
a99b6c1f5f67 Code cleanup, increase minimum hostname length for uribl checking
Carl Byington <carl@five-ten-sg.com>
parents: 270
diff changeset
1890 me.add_tldnot(have);
270
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1891 }
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1892 else if (have == token_asterisk) {
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1893 have = tok.next();
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1894 if (!have) break;
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1895 if (have == token_rbrace) break; // done
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1896 if (have == token_period) {
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1897 have = tok.next();
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1898 if (!have) break;
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1899 if (have == token_rbrace) break; // done
272
a99b6c1f5f67 Code cleanup, increase minimum hostname length for uribl checking
Carl Byington <carl@five-ten-sg.com>
parents: 270
diff changeset
1900 me.add_tldwild(have);
270
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1901 }
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1902 }
f92f24950bd3 Use mozilla prefix list for tld checking, Enable surbl/uribl/dbl rhs lists
Carl Byington <carl@five-ten-sg.com>
parents: 268
diff changeset
1903 else me.add_tld(have);
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1904 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1905 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1906 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1907 else if (have == token_html_tags) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1908 if (!tsa(tok, token_lbrace)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1909 while (true) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
1910 const char *have = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1911 if (!have) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1912 if (have == token_rbrace) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1913 break; // done
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1914 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1915 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1916 me.add_tag(have); // base version
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1917 char buf[200];
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1918 snprintf(buf, sizeof(buf), "/%s", have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1919 me.add_tag(register_string(buf)); // leading /
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1920 snprintf(buf, sizeof(buf), "%s/", have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1921 me.add_tag(register_string(buf)); // trailing /
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1922 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1923 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1924 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1925 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1926 else if (have == token_html_limit) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1927 have = tok.next();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1928 if (have == token_on) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1929 me.set_tag_limit(tok.nextint());
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1930 me.set_tag_message(tok.next());
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1931 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1932 else if (have == token_off) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1933 me.set_tag_limit(0);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1934 me.set_tag_message(NULL);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1935 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1936 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1937 tok.token_error("on/off", have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1938 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1939 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1940 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1941 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1942 else if (have == token_host_limit) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1943 have = tok.next();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1944 if (have == token_on) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1945 me.set_host_limit(tok.nextint());
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1946 me.set_host_message(tok.next());
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1947 me.set_host_random(false);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1948 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1949 else if (have == token_off) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1950 me.set_host_limit(0);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1951 me.set_host_message(NULL);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1952 me.set_host_random(false);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1953 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1954 else if (have == token_soft) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1955 me.set_host_limit(tok.nextint());
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1956 me.set_host_message(NULL);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1957 me.set_host_random(true);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1958 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1959 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1960 tok.token_error("on/off/soft", have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1961 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1962 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1963 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1964 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1965 else if (have == token_spamassassin) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1966 me.set_spamassassin_limit(tok.nextint());
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1967 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1968 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1969 else if (have == token_require) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1970 have = tok.next();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1971 if (have == token_yes) me.set_require(true);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1972 else if (have == token_no) me.set_require(false);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1973 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1974 tok.token_error("yes/no", have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1975 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1976 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1977 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1978 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1979 else if (have == token_dccgrey) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1980 have = tok.next();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1981 if (have == token_yes) me.set_grey(true);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1982 else if (have == token_no) me.set_grey(false);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1983 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1984 tok.token_error("yes/no", have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1985 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1986 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1987 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1988 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1989 else if (have == token_dccbulk) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1990 have = tok.next();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1991 if (have == token_off) me.set_bulk(0);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1992 else if (have == token_many) me.set_bulk(dccbulk);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1993 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1994 char *e;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1995 long i = strtol(have, &e, 10);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1996 if (*e != '\0') {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1997 tok.token_error("integer", have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1998 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
1999 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2000 me.set_bulk((int)i);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2001 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2002 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2003 }
322
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
2004 else if (have == token_dkim_signer) {
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
2005 if (!parse_dkim_signer(tok, dc, me)) return false;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
2006 }
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
2007 else if (have == token_dkim_from) {
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
2008 if (!parse_dkim_from(tok, dc, me)) return false;
9f8411f3919c add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 321
diff changeset
2009 }
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2010 else if (have == token_rbrace) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2011 break; // done
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2012 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2013 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2014 tok.token_error("content keyword", have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2015 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2016 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2017 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2018 return tsa(tok, token_semi);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2019 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2020
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2021
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2022 ////////////////////////////////////////////////
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2023 //
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2024 bool parse_envto(TOKEN &tok, CONFIG &dc, CONTEXT &me);
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2025 bool parse_envto(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2026 if (!tsa(tok, token_lbrace)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2027 while (true) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2028 const char *have = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2029 if (!have) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2030 if (have == token_rbrace) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2031 if (have == token_semi) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2032 // optional separators
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2033 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2034 else if (have == token_dccto) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2035 const char *flavor = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2036 if (!tsa(tok, token_lbrace)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2037 bool keeping = false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2038 while (true) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2039 const char *have = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2040 if (!have) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2041 if (have == token_rbrace) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2042 if (have == flavor) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2043 keeping = true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2044 continue;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2045 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2046 else if ((have == token_ok) || (have == token_ok2) || (have == token_many)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2047 keeping = false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2048 continue;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2049 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2050 if (have == token_envto) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2051 have = tok.next();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2052 if (keeping) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2053 if (me.allow_env_to(have)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2054 me.add_to(have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2055 dc.add_to(have, &me);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2056 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2057 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2058 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2059 //else if (have == token_substitute) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2060 // if (tok.next() == token_mailhost) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2061 // have = tok.next();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2062 // if (keeping) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2063 // if (me.allow_env_to(have)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2064 // me.add_to(have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2065 // dc.add_to(have, &me);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2066 // }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2067 // }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2068 // }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2069 //}
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2070 tok.skipeol();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2071 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2072 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2073 else if (me.allow_env_to(have)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2074 me.add_to(have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2075 dc.add_to(have, &me);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2076 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2077 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2078 tok.token_error("user@ or user@domain.tld or domain.tld where domain.tld allowed by parent context", have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2079 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2080 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2081 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2082 return tsa(tok, token_semi);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2083 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2084
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2085
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2086 ////////////////////////////////////////////////
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2087 //
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2088 bool parse_verify(TOKEN &tok, CONFIG &dc, CONTEXT &me);
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2089 bool parse_verify(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2090 const char *host = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2091 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2092 me.set_verify(host);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2093 me.set_verifier(add_verify_host(host));
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2094 return true;
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
2095 }
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
2096
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
2097
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
2098 ////////////////////////////////////////////////
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
2099 //
168
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
2100 bool parse_generic(TOKEN &tok, CONFIG &dc, CONTEXT &me);
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
2101 bool parse_generic(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2102 const char *regx = tok.next();
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2103 const char *msg = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2104 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2105 if (me.set_generic(regx, msg)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2106 tok.token_error("invalid regular expression %s", regx, regx);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2107 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2108 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2109 return true;
168
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
2110 }
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
2111
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
2112
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
2113 ////////////////////////////////////////////////
6bac960af6b4 add generic reverse dns filtering regex
carl
parents: 167
diff changeset
2114 //
233
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2115 bool parse_white(TOKEN &tok, CONFIG &dc, CONTEXT &me);
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2116 bool parse_white(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2117 const char *regx = tok.next();
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2118 if (!tsa(tok, token_semi)) return false;
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2119 if (me.set_white(regx)) {
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2120 tok.token_error("invalid regular expression %s", regx, regx);
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2121 return false;
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2122 }
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2123 return true;
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2124 }
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2125
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2126
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2127 ////////////////////////////////////////////////
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2128 //
153
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
2129 bool parse_autowhite(TOKEN &tok, CONFIG &dc, CONTEXT &me);
8d7c439bb6fa add auto whitelisting
carl
parents: 152
diff changeset
2130 bool parse_autowhite(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2131 int days = tok.nextint();
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2132 const char *fn = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2133 if (!tsa(tok, token_semi)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2134 me.set_autowhite(fn);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2135 me.set_whitelister(add_whitelister_file(fn, days));
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2136 return true;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2137 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2138
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2139
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2140 ////////////////////////////////////////////////
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2141 //
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2142 bool parse_envfrom(TOKEN &tok, CONFIG &dc, CONTEXT &me);
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2143 bool parse_envfrom(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2144 const char *st = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2145 if ((st == token_black) || (st == token_white) || (st == token_unknown) || (st == token_inherit)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2146 me.set_from_default(st);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2147 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2148 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2149 tok.push(st);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2150 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2151 if (!tsa(tok, token_lbrace)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2152 while (true) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2153 const char *have = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2154 if (!have) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2155 if (have == token_rbrace) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2156 if (have == token_semi) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2157 // optional separators
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2158 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2159 else if (have == token_dccfrom) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2160 if (!tsa(tok, token_lbrace)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2161 bool keeping = false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2162 bool many = false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2163 while (true) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2164 const char *have = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2165 if (!have) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2166 if (have == token_rbrace) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2167 if (have == token_ok) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2168 keeping = true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2169 many = false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2170 continue;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2171 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2172 else if (have == token_many) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2173 keeping = true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2174 many = true;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2175 continue;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2176 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2177 else if (have == token_ok2) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2178 keeping = false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2179 continue;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2180 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2181 if (have == token_envfrom) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2182 have = tok.next();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2183 if (keeping) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2184 me.add_from(have, (many) ? token_black : token_white);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2185 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2186 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2187 else if (have == token_substitute) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2188 if (tok.next() == token_mailhost) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2189 have = tok.next();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2190 me.add_from(have, (many) ? token_black : token_white);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2191 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2192 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2193 tok.skipeol();
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2194 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2195 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2196 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2197 // may be a valid email address or domain name
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2198 const char *st = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2199 if ((st == token_white) || (st == token_black) || (st == token_unknown) || (st == token_inherit)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2200 me.add_from(have, st);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2201 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2202 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2203 CONTEXTP con = me.find_from_context_name(st);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2204 if (con) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2205 me.add_from_context(have, con);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2206 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2207 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2208 tok.token_error("white/black/unknown/inherit or child context name", st);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2209 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2210 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2211 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2212 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2213 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2214 return tsa(tok, token_semi);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2215 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2216
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2217
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2218 ////////////////////////////////////////////////
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2219 //
136
f4746d8a12a3 add smtp auth rate limits
carl
parents: 129
diff changeset
2220 bool parse_rate(TOKEN &tok, CONFIG &dc, CONTEXT &me);
f4746d8a12a3 add smtp auth rate limits
carl
parents: 129
diff changeset
2221 bool parse_rate(TOKEN &tok, CONFIG &dc, CONTEXT &me) {
278
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
2222 me.set_default_rate_limit(tok.nextint());
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
2223 me.set_daily_rate_multiple(tok.nextint());
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
2224 me.set_default_address_limit(tok.nextint());
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
2225 me.set_daily_address_multiple(tok.nextint());
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2226 if (!tsa(tok, token_lbrace)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2227 while (true) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2228 const char *have = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2229 if (!have) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2230 if (have == token_rbrace) break;
278
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
2231 me.add_rate_limit(have, tok.nextint());
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
2232 me.add_address_limit(have, tok.nextint());
368572c57013 add limits on unique ip addresses per hour per authenticated user
Carl Byington <carl@five-ten-sg.com>
parents: 274
diff changeset
2233 if (!tsa(tok, token_semi)) return false;
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2234 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2235 return tsa(tok, token_semi);
136
f4746d8a12a3 add smtp auth rate limits
carl
parents: 129
diff changeset
2236 }
f4746d8a12a3 add smtp auth rate limits
carl
parents: 129
diff changeset
2237
f4746d8a12a3 add smtp auth rate limits
carl
parents: 129
diff changeset
2238
f4746d8a12a3 add smtp auth rate limits
carl
parents: 129
diff changeset
2239 ////////////////////////////////////////////////
f4746d8a12a3 add smtp auth rate limits
carl
parents: 129
diff changeset
2240 //
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2241 bool parse_context(TOKEN &tok, CONFIG &dc, CONTEXTP parent);
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2242 bool parse_context(TOKEN &tok, CONFIG &dc, CONTEXTP parent) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2243 const char *name = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2244 if (!tsa(tok, token_lbrace)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2245 CONTEXTP con = new CONTEXT(parent, name);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2246
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2247 while (true) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2248 const char *have = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2249 if (!have) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2250 if (have == token_rbrace) break; // done
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2251 if (have == token_dnsbl) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2252 if (!parse_dnsbl(tok, dc, *con)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2253 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2254 else if (have == token_dnsbll) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2255 if (!parse_dnsbll(tok, dc, *con)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2256 }
249
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
2257 else if (have == token_dnswl) {
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
2258 if (!parse_dnswl(tok, dc, *con)) return false;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
2259 }
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
2260 else if (have == token_dnswll) {
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
2261 if (!parse_dnswll(tok, dc, *con)) return false;
15bf4f68a0b2 Add dnswl support
Carl Byington <carl@five-ten-sg.com>
parents: 244
diff changeset
2262 }
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2263 else if (have == token_content) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2264 if (!parse_content(tok, dc, *con)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2265 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2266 else if (have == token_envto) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2267 if (!parse_envto(tok, dc, *con)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2268 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2269 else if (have == token_verify) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2270 if (!parse_verify(tok, dc, *con)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2271 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2272 else if (have == token_generic) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2273 if (!parse_generic(tok, dc, *con)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2274 }
233
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2275 else if (have == token_white_regex) {
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2276 if (!parse_white(tok, dc, *con)) return false;
5c3e9bf45bb5 Add whitelisting by regex expression filtering.
Carl Byington <carl@five-ten-sg.com>
parents: 214
diff changeset
2277 }
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2278 else if (have == token_autowhite) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2279 if (!parse_autowhite(tok, dc, *con)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2280 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2281 else if (have == token_envfrom) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2282 if (!parse_envfrom(tok, dc, *con)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2283 }
321
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2284 else if (have == token_dkim_signer) {
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2285 if (!parse_dkim_signer(tok, dc, *con)) return false;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2286 }
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2287 else if (have == token_dkim_from) {
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2288 if (!parse_dkim_from(tok, dc, *con)) return false;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2289 }
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2290 else if (have == token_rate) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2291 if (parent || dc.default_context) tok.token_error("rate limit ignored in non default context");
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2292 if (!parse_rate(tok, dc, *con)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2293 }
321
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2294 else if (have == token_requirerdns) {
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2295 if (!parse_requirerdns(tok, dc, *con)) return false;
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2296 }
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2297 else if (have == token_context) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2298 if (!parse_context(tok, dc, con)) return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2299 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2300 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2301 tok.token_error("context keyword", have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2302 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2303 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2304 }
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2305
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2306 if (!tsa(tok, token_semi)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2307 delete con;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2308 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2309 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2310 dc.add_context(con);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2311 if (parent) parent->add_context(con);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2312 return true;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2313 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2314
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2315
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2316 ////////////////////////////////////////////////
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2317 // parse a config file
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2318 //
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2319 bool load_conf(CONFIG &dc, const char *fn) {
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2320 int count = 0;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2321 TOKEN tok(fn, &dc.config_files);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2322 while (true) {
214
82886d4dd71f Fixes to compile on Fedora 9 and for const correctness.
Carl Byington <carl@five-ten-sg.com>
parents: 211
diff changeset
2323 const char *have = tok.next();
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2324 if (!have) break;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2325 if (have == token_context) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2326 if (!parse_context(tok, dc, NULL)) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2327 tok.token_error("load_conf() failed to parse context");
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2328 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2329 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2330 else count++;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2331 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2332 else {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2333 tok.token_error(token_context, have);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2334 return false;
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2335 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2336 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2337 tok.token_error("load_conf() found %d contexts in %s", count, fn);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2338 return (dc.default_context) ? true : false;
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2339 }
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2340
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2341
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2342 ////////////////////////////////////////////////
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2343 // init the tokens
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2344 //
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2345 void token_init() {
321
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2346 token_asterisk = register_string("*");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2347 token_autowhite = register_string("autowhite");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2348 token_bang = register_string("!");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2349 token_black = register_string("black");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2350 token_content = register_string("content");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2351 token_context = register_string("context");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2352 token_dccbulk = register_string("dcc_bulk_threshold");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2353 token_dccfrom = register_string("dcc_from");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2354 token_dccgrey = register_string("dcc_greylist");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2355 token_dccto = register_string("dcc_to");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2356 token_default = register_string("default");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2357 token_dnsbl = register_string("dnsbl");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2358 token_dnsbll = register_string("dnsbl_list");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2359 token_dnswl = register_string("dnswl");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2360 token_dnswll = register_string("dnswl_list");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2361 token_envfrom = register_string("env_from");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2362 token_envto = register_string("env_to");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2363 token_filter = register_string("filter");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2364 token_generic = register_string("generic");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2365 token_host_limit = register_string("host_limit");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2366 token_html_limit = register_string("html_limit");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2367 token_html_tags = register_string("html_tags");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2368 token_ignore = register_string("ignore");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2369 token_include = register_string("include");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2370 token_inherit = register_string("inherit");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2371 token_lbrace = register_string("{");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2372 token_mailhost = register_string("mail_host");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2373 token_many = register_string("many");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2374 token_no = register_string("no");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2375 token_off = register_string("off");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2376 token_ok = register_string("ok");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2377 token_ok2 = register_string("ok2");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2378 token_on = register_string("on");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2379 token_period = register_string(".");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2380 token_rate = register_string("rate_limit");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2381 token_rbrace = register_string("}");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2382 token_require = register_string("require_match");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2383 token_requirerdns = register_string("require_rdns");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2384 token_semi = register_string(";");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2385 token_soft = register_string("soft");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2386 token_spamassassin = register_string("spamassassin");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2387 token_substitute = register_string("substitute");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2388 token_tld = register_string("tld");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2389 token_unknown = register_string("unknown");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2390 token_uribl = register_string("uribl");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2391 token_verify = register_string("verify");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2392 token_white = register_string("white");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2393 token_white_regex = register_string("white_regex");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2394 token_yes = register_string("yes");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2395 token_dkim_signer = register_string("dkim_signer");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2396 token_dkim_from = register_string("dkim_from");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2397 token_signed_white = register_string("signed_white");
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2398 token_signed_black = register_string("signed_black");
451
f2bc221240e8 add unsigned_black for enforcement of dmarc policy
Carl Byington <carl@five-ten-sg.com>
parents: 449
diff changeset
2399 token_unsigned_black = register_string("unsigned_black");
321
e172dc10fe24 add dkim white/black listing
Carl Byington <carl@five-ten-sg.com>
parents: 320
diff changeset
2400 token_require_signed = register_string("require_signed");
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2401
192
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2402 if (gethostname(myhostname, HOST_NAME_MAX+1) != 0) {
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2403 strncpy(myhostname, "localhost", HOST_NAME_MAX+1);
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2404 }
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2405 myhostname[HOST_NAME_MAX] = '\0'; // ensure null termination
8f4a9a37d4d9 delay autowhitelisting to avoid out of office reply bots
carl
parents: 180
diff changeset
2406 token_myhostname = register_string(myhostname);
94
e107ade3b1c0 fix dos line terminators
carl
parents: 92
diff changeset
2407 }