]>
git.proxmox.com Git - pmg-api.git/blob - src/PMG/RuleCache.pm
1 package PMG
::RuleCache
;
13 my $ocache_size = 1023;
16 my ($type, $ruledb) = @_;
20 $self->{ruledb
} = $ruledb;
27 my $dbh = $ruledb->{dbh
};
29 my $sha1 = Digest
::SHA-
>new;
34 # read a consistent snapshot
35 $dbh->do("SET TRANSACTION ISOLATION LEVEL SERIALIZABLE");
37 my $sth = $dbh->prepare(
38 "SELECT ID, Name, Priority, Active, Direction FROM Rule " .
40 "ORDER BY Priority DESC");
44 while (my $ref = $sth->fetchrow_hashref()) {
45 my $ruleid = $ref->{id
};
46 my $rule = PMG
::RuleDB
::Rule-
>new(
47 $ref->{name
}, $ref->{priority
}, $ref->{active
},
50 $rule->{id
} = $ruleid;
53 $sha1->add(join(',', $ref->{id
}, $ref->{name
}, $ref->{priority
}, $ref->{active
},
54 $ref->{direction
}) . "|");
56 my ($from, $to, $when, $what, $action);
58 my $sth1 = $dbh->prepare(
59 "SELECT Objectgroup_ID, Grouptype FROM RuleGroup " .
60 "where RuleGroup.Rule_ID = '$ruleid' " .
61 "ORDER BY Grouptype, Objectgroup_ID");
64 while (my $ref1 = $sth1->fetchrow_hashref()) {
65 my $gtype = $ref1->{grouptype
};
66 my $groupid = $ref1->{objectgroup_id
};
68 # emtyp groups differ from non-existent groups!
70 if ($gtype == 0) { #from
71 $from = [] if !defined ($from);
72 } elsif ($gtype == 1) { # to
73 $to = [] if !defined ($to);
74 } elsif ($gtype == 2) { # when
75 $when = [] if !defined ($when);
76 } elsif ($gtype == 3) { # what
77 $what = [] if !defined ($what);
78 } elsif ($gtype == 4) { # action
79 $action = [] if !defined ($action);
82 my $sth2 = $dbh->prepare(
83 "SELECT ID FROM Object where Objectgroup_ID = '$groupid' " .
86 while (my $ref2 = $sth2->fetchrow_hashref()) {
87 my $objid = $ref2->{'id'};
88 my $obj = $self->_get_object($objid);
90 $sha1->add (join (',', $objid, $gtype, $groupid) . "|");
91 $sha1->add ($obj->{digest
}, "|");
93 if ($gtype == 0) { #from
95 } elsif ($gtype == 1) { # to
97 } elsif ($gtype == 2) { # when
99 } elsif ($gtype == 3) { # what
101 if ($obj->otype == PMG
::RuleDB
::ArchiveFilter-
>otype ||
102 $obj->otype == PMG
::RuleDB
::MatchArchiveFilename-
>otype)
104 if ($rule->{direction
} == 0) {
105 $self->{archivefilter_in
} = 1;
106 } elsif ($rule->{direction
} == 1) {
107 $self->{archivefilter_out
} = 1;
109 $self->{archivefilter_in
} = 1;
110 $self->{archivefilter_out
} = 1;
113 } elsif ($gtype == 4) { # action
115 $self->{"$ruleid:final"} = 1 if $obj->final();
123 $self->{"$ruleid:from"} = $from;
124 $self->{"$ruleid:to"} = $to;
125 $self->{"$ruleid:when"} = $when;
126 $self->{"$ruleid:what"} = $what;
127 $self->{"$ruleid:action"} = $action;
130 # Cache Greylist Exclusion
131 $sth = $dbh->prepare(
132 "SELECT object.id FROM object, objectgroup " .
133 "WHERE class = 'greylist' AND " .
134 "objectgroup.id = object.objectgroup_id " .
135 "ORDER BY object.id");
138 my $grey_excl_sender = ();
139 my $grey_excl_receiver = ();
140 while (my $ref2 = $sth->fetchrow_hashref()) {
141 my $obj = $self->_get_object ($ref2->{'id'});
143 if ($obj->receivertest()) {
144 push @$grey_excl_receiver, $obj;
146 push @$grey_excl_sender, $obj;
148 $sha1->add ($ref2->{'id'}, "|");
149 $sha1->add ($obj->{digest
}, "|");
152 $self->{"greylist:sender"} = $grey_excl_sender;
153 $self->{"greylist:receiver"} = $grey_excl_receiver;
159 $dbh->rollback; # end transaction
161 syslog
('err', "unable to load rulecache : $err") if $err;
163 $self->{rules
} = $rules;
165 $self->{digest
} = $sha1->hexdigest;
171 my ($self, $ruleid) = @_;
173 defined($ruleid) || die "undefined rule id: ERROR";
175 return $self->{"$ruleid:final"};
185 my ($self, $objid) = @_;
187 my $cid = $objid % $ocache_size;
189 my $obj = $self->{ocache
}[$cid];
191 if (!defined ($obj) || $obj->{id
} != $objid) {
192 $obj = $self->{ruledb
}->load_object($objid);
193 $self->{ocache
}[$cid] = $obj;
196 $obj || die "unable to get object $objid: ERROR";
202 my ($self, $ruleid) = @_;
204 defined($ruleid) || die "undefined rule id: ERROR";
206 return $self->{"$ruleid:action"};
210 my ($self, $addr, $ip) = @_;
212 my $grey = $self->{"greylist:sender"};
214 foreach my $obj (@$grey) {
215 if ($obj->who_match ($addr, $ip)) {
223 sub greylist_match_receiver
{
224 my ($self, $addr) = @_;
226 my $grey = $self->{"greylist:receiver"};
228 foreach my $obj (@$grey) {
229 if ($obj->who_match($addr)) {
238 my ($self, $ruleid, $addr, $ip, $ldap) = @_;
240 my $from = $self->{"$ruleid:from"};
242 return 1 if !defined ($from);
244 # postfix prefixes ipv6 addresses with IPv6:
245 if ($ip =~ /^IPv6:(.*)/) {
249 foreach my $obj (@$from) {
250 return 1 if $obj->who_match($addr, $ip, $ldap);
257 my ($self, $ruleid, $addr, $ldap) = @_;
259 my $to = $self->{"$ruleid:to"};
261 return 1 if !defined ($to);
263 foreach my $obj (@$to) {
264 return 1 if $obj->who_match($addr, undef, $ldap);
271 my ($self, $ruleid, $time) = @_;
273 my $when = $self->{"$ruleid:when"};
275 return 1 if !defined ($when);
277 foreach my $obj (@$when) {
278 return 1 if $obj->when_match($time);
285 my ($self, $ruleid, $queue, $element, $msginfo, $dbh) = @_;
287 my $what = $self->{"$ruleid:what"};
291 # $res->{marks} is used by mark specific actions like remove-attachments
292 # $res->{$target}->{marks} is only used in apply_rules() to exclude some
293 # targets (spam blacklist and whitelist)
295 if (!defined ($what)) {
297 foreach my $target (@{$msginfo->{targets
}}) {
298 $res->{$target}->{marks
} = [];
307 foreach my $obj (@$what) {
308 if (!$obj->can('what_match_targets')) {
309 if (my $match = $obj->what_match($queue, $element, $msginfo, $dbh)) {
310 push @$marks, @$match;
315 foreach my $target (@{$msginfo->{targets
}}) {
316 $res->{$target}->{marks
} = $marks;
317 $res->{marks
} = $marks;
320 foreach my $obj (@$what) {
321 if ($obj->can ("what_match_targets")) {
323 if ($target_info = $obj->what_match_targets($queue, $element, $msginfo, $dbh)) {
324 foreach my $k (keys %$target_info) {
325 my $cmarks = $target_info->{$k}->{marks
}; # make a copy
326 $res->{$k} = $target_info->{$k};
327 push @{$res->{$k}->{marks
}}, @$cmarks if $cmarks;