view dnsbl.spec.in @ 48:5ef10dc14457

properly drop root privs
author carl
date Fri, 09 Jul 2004 13:57:59 -0700
parents acbe44bbba22
children 9f2971c692d0
line wrap: on
line source

Summary: DNSBL Sendmail Milter
Name: dnsbl
Version: 3.1
Release: 2
Copyright: GPL
Group: System Environment/Daemons
Source: http://www.five-ten-sg.com/util/dnsbl.tar.gz
Patch0: dnsbl.rc.patch
BuildRoot: %{_tmppath}/%{name}-%{version}

Requires(pre):  /usr/sbin/groupadd
Requires(pre):  /usr/sbin/useradd
Requires(pre):  /usr/bin/getent
Requires(postun):       /usr/sbin/userdel
Requires(postun):       /usr/sbin/groupdel
Requires(post,preun):   /sbin/chkconfig
BuildRequires:  sendmail-devel >= 8.12.1
Requires:       sendmail >= 8.12.1
Requires:       sendmail-cf


%description
We present here a mechanism whereby the backup mail server can use the correct set of DNSBLs for each recipient for each message. As a side-effect, it gives us the ability to customize the set of DNSBLs on a per-recipient basis, so that fred@example.com could use SPEWS and the SBL, where all other users @example.com use only the SBL.

This milter will also decode (base64, mime, html entity, url encodings) and scan for HTTP and HTTPS URLs and bare hostnames in the body of the mail. If any of those host names have A or NS records on the SBL (or a single configurable DNSBL), the mail will be rejected unless previously whitelisted. This milter also counts the number of invalid HTML tags, and can reject mail if that count exceeds your specified limit.

The DNSBL milter reads a text configuration file (dnsbl.conf) on startup, and whenever the config file (or any of the referenced include files) is changed. The entire configuration file is case insensitive.

%prep

%setup
%patch0 -p1

%build
pwd
g++ -c $CXXFLAGS -pthread dnsbl.cpp
g++ -o dnsbl dnsbl.o /usr/lib/libresolv.a -lmilter -pthread

%install
DST=%{buildroot}
if [ "%{buildroot}" = "/" -o -z "%{buildroot}" ] ; then
	echo sorry, you probably do not want me to delete the old buildroot at %{buildroot}
	exit 1
fi

rm -rf %{buildroot}
mkdir -p %{buildroot}/etc/dnsbl

install -m 644 dnsbl.conf %{buildroot}/etc/dnsbl/dnsbl.conf
install -m 644 html-tags.conf %{buildroot}/etc/dnsbl/html-tags.conf
install -m 644 tld.conf %{buildroot}/etc/dnsbl/tld.conf

mkdir -p %{buildroot}/usr/sbin
install -m 755 dnsbl %{buildroot}/usr/sbin/dnsbl

mkdir -p %{buildroot}/etc/init.d
install -m 755 dnsbl.rc %{buildroot}/etc/init.d/dnsbl

mkdir -p %{buildroot}/var/run/dnsbl

%pre
/usr/bin/getent passwd dnsbl ||
  useradd -r -d /etc/dnsbl -M -c "dnsbl pseudo-user" -s /sbin/nologin dnsbl

#[JOG] Attempt to migrate an existing, non-rpm install.
#      WARNING! This may cause blindness, loss of appetite, and a general
#      feeling of ill will towards the author of this script. Please refer
#      to the Licence file for warranty information...
if [ -f "/var/dnsbl/dnsbl.conf" -a ! -f "/etc/dnsbl/dnsbl.conf" ] ; then
	echo Existing installation found at /var/dnsbl/ Migrating configuation...
	# create the conf directory so rpm can find it in a minute...
	mkdir /etc/dnsbl/
	# and try to copy all of the relavent config files that are below this directory
	cd /var/dnsbl/
	grep '^include ' /var/dnsbl/dnsbl.conf  | cut -d ' ' -f 2 | grep -v '^/' | xargs cp --target-directory=/etc/dnsbl/ /var/dnsbl/dnsbl.conf
fi


%post
/sbin/chkconfig --add dnsbl
/sbin/chkconfig dnsbl on
/sbin/service dnsbl start

echo Remember to edit /etc/dnsbl.conf and add the following line to your sendmail.mc:
echo "INPUT_MAIL_FILTER(\`dnsbl\', \`S=local:/var/run/dnsbl/dnsbl.sock, F=T, T=C:30s;S:2m;R:2m;E:5m\')"
echo


%preun
if [ $1 -eq 0 ]; then
   /sbin/service dnsbl stop || :
   /sbin/chkconfig --del dnsbl
   userdel dnsbl || :
fi

%postun

%clean

%files
%defattr(-,root,root)
%config /etc/dnsbl/
/etc/init.d/dnsbl
/usr/sbin/dnsbl
%dir %attr(0750,dnsbl,root) /var/run/dnsbl

%changelog
* Mon Jul 05 2004 John Gunkel <jgunkel@palliser.ca> 1.2
- Fixed some typos
- removed patch into separate file
- added config migration as suggested by Carl
- Added reminder to edit sendmail.mc

* Wed Jun 30 2004 John Gunkel <jgunkel@palliser.ca> 1.1
- Initial revision of spec file. Need to add a better description, docs and a sendmail.mc message