]>
Commit | Line | Data |
---|---|---|
7e0e6dbe DM |
1 | package PMG::Config::Base; |
2 | ||
3 | use strict; | |
4 | use warnings; | |
5 | use Data::Dumper; | |
6 | ||
7 | use PVE::Tools; | |
8 | use PVE::JSONSchema qw(get_standard_option); | |
9 | use PVE::SectionConfig; | |
10 | ||
11 | use base qw(PVE::SectionConfig); | |
12 | ||
13 | my $defaultData = { | |
14 | propertyList => { | |
15 | type => { description => "Section type." }, | |
ef6f5dd1 | 16 | section => { |
7e0e6dbe DM |
17 | description => "Secion ID.", |
18 | type => 'string', format => 'pve-configid', | |
19 | }, | |
20 | }, | |
21 | }; | |
22 | ||
23 | sub private { | |
24 | return $defaultData; | |
25 | } | |
26 | ||
27 | sub format_section_header { | |
28 | my ($class, $type, $sectionId) = @_; | |
29 | ||
d79b9b0c DM |
30 | die "internal error ($type ne $sectionId)" if $type ne $sectionId; |
31 | ||
32 | return "section: $type\n"; | |
7e0e6dbe DM |
33 | } |
34 | ||
35 | ||
36 | sub parse_section_header { | |
37 | my ($class, $line) = @_; | |
38 | ||
d79b9b0c DM |
39 | if ($line =~ m/^section:\s*(\S+)\s*$/) { |
40 | my $section = $1; | |
7e0e6dbe | 41 | my $errmsg = undef; # set if you want to skip whole section |
d79b9b0c | 42 | eval { PVE::JSONSchema::pve_verify_configid($section); }; |
7e0e6dbe DM |
43 | $errmsg = $@ if $@; |
44 | my $config = {}; # to return additional attributes | |
d79b9b0c | 45 | return ($section, $section, $errmsg, $config); |
7e0e6dbe DM |
46 | } |
47 | return undef; | |
48 | } | |
49 | ||
ac5d1312 | 50 | package PMG::Config::Admin; |
7e0e6dbe DM |
51 | |
52 | use strict; | |
53 | use warnings; | |
54 | ||
55 | use base qw(PMG::Config::Base); | |
56 | ||
57 | sub type { | |
ac5d1312 | 58 | return 'admin'; |
7e0e6dbe DM |
59 | } |
60 | ||
61 | sub properties { | |
62 | return { | |
63 | dailyreport => { | |
64 | description => "Send daily reports.", | |
65 | type => 'boolean', | |
66 | default => 1, | |
67 | }, | |
f62194b2 DM |
68 | demo => { |
69 | description => "Demo mode - do not start SMTP filter.", | |
70 | type => 'boolean', | |
71 | default => 0, | |
72 | }, | |
73 | email => { | |
74 | description => "Administrator E-Mail address.", | |
75 | type => 'string', format => 'email', | |
76 | default => 'admin@domain.tld', | |
ac5d1312 DM |
77 | }, |
78 | proxyport => { | |
79 | description => "HTTP proxy port.", | |
80 | type => 'integer', | |
81 | minimum => 1, | |
82 | default => 8080, | |
83 | }, | |
84 | proxyserver => { | |
85 | description => "HTTP proxy server address.", | |
86 | type => 'string', | |
87 | }, | |
88 | proxyuser => { | |
89 | description => "HTTP proxy user name.", | |
90 | type => 'string', | |
91 | }, | |
92 | proxypassword => { | |
93 | description => "HTTP proxy password.", | |
94 | type => 'string', | |
95 | }, | |
7e0e6dbe DM |
96 | }; |
97 | } | |
98 | ||
99 | sub options { | |
100 | return { | |
101 | dailyreport => { optional => 1 }, | |
f62194b2 | 102 | demo => { optional => 1 }, |
3d812daf | 103 | email => { optional => 1 }, |
ac5d1312 DM |
104 | proxyport => { optional => 1 }, |
105 | proxyserver => { optional => 1 }, | |
106 | proxyuser => { optional => 1 }, | |
107 | proxypassword => { optional => 1 }, | |
7e0e6dbe DM |
108 | }; |
109 | } | |
110 | ||
111 | package PMG::Config::Spam; | |
112 | ||
113 | use strict; | |
114 | use warnings; | |
115 | ||
116 | use base qw(PMG::Config::Base); | |
117 | ||
118 | sub type { | |
119 | return 'spam'; | |
120 | } | |
121 | ||
122 | sub properties { | |
123 | return { | |
1ccc8e95 DM |
124 | languages => { |
125 | description => "This option is used to specify which languages are considered OK for incoming mail.", | |
126 | type => 'string', | |
127 | pattern => '(all|([a-z][a-z])+( ([a-z][a-z])+)*)', | |
128 | default => 'all', | |
129 | }, | |
130 | use_bayes => { | |
131 | description => "Whether to use the naive-Bayesian-style classifier.", | |
132 | type => 'boolean', | |
133 | default => 1, | |
134 | }, | |
582cfacf DM |
135 | use_awl => { |
136 | description => "Use the Auto-Whitelist plugin.", | |
137 | type => 'boolean', | |
138 | default => 1, | |
139 | }, | |
140 | use_razor => { | |
141 | description => "Whether to use Razor2, if it is available.", | |
142 | type => 'boolean', | |
143 | default => 1, | |
144 | }, | |
03ac6d8f DM |
145 | use_ocr => { |
146 | description => "Enable OCR to scan pictures.", | |
147 | type => 'boolean', | |
148 | default => 0, | |
149 | }, | |
1ccc8e95 DM |
150 | wl_bounce_relays => { |
151 | description => "Whitelist legitimate bounce relays.", | |
152 | type => 'string', | |
153 | }, | |
7e0e6dbe DM |
154 | bounce_score => { |
155 | description => "Additional score for bounce mails.", | |
156 | type => 'integer', | |
157 | minimum => 0, | |
158 | maximum => 1000, | |
159 | default => 0, | |
160 | }, | |
f62194b2 DM |
161 | rbl_checks => { |
162 | description => "Enable real time blacklists (RBL) checks.", | |
163 | type => 'boolean', | |
164 | default => 1, | |
165 | }, | |
166 | maxspamsize => { | |
167 | description => "Maximum size of spam messages in bytes.", | |
168 | type => 'integer', | |
4d76e24e | 169 | minimum => 64, |
f62194b2 DM |
170 | default => 200*1024, |
171 | }, | |
7e0e6dbe DM |
172 | }; |
173 | } | |
174 | ||
175 | sub options { | |
176 | return { | |
582cfacf DM |
177 | use_awl => { optional => 1 }, |
178 | use_razor => { optional => 1 }, | |
03ac6d8f | 179 | use_ocr => { optional => 1 }, |
1ccc8e95 DM |
180 | wl_bounce_relays => { optional => 1 }, |
181 | languages => { optional => 1 }, | |
182 | use_bayes => { optional => 1 }, | |
7e0e6dbe | 183 | bounce_score => { optional => 1 }, |
f62194b2 DM |
184 | rbl_checks => { optional => 1 }, |
185 | maxspamsize => { optional => 1 }, | |
186 | }; | |
187 | } | |
188 | ||
189 | package PMG::Config::ClamAV; | |
190 | ||
191 | use strict; | |
192 | use warnings; | |
193 | ||
194 | use base qw(PMG::Config::Base); | |
195 | ||
196 | sub type { | |
197 | return 'clamav'; | |
198 | } | |
199 | ||
200 | sub properties { | |
201 | return { | |
ac5d1312 DM |
202 | dbmirror => { |
203 | description => "ClamAV database mirror server.", | |
204 | type => 'string', | |
205 | default => 'database.clamav.net', | |
206 | }, | |
207 | archiveblockencrypted => { | |
208 | description => "Wether to block encrypted archives. Mark encrypted archives as viruses.", | |
209 | type => 'boolean', | |
210 | default => 0, | |
211 | }, | |
212 | archivemaxrec => { | |
213 | description => "Nested archives are scanned recursively, e.g. if a ZIP archive contains a TAR file, all files within it will also be scanned. This options specifies how deeply the process should be continued. Warning: setting this limit too high may result in severe damage to the system.", | |
1baec5ab | 214 | type => 'integer', |
ac5d1312 DM |
215 | minimum => 1, |
216 | default => 5, | |
217 | }, | |
f62194b2 | 218 | archivemaxfiles => { |
ac5d1312 | 219 | description => "Number of files to be scanned within an archive, a document, or any other kind of container. Warning: disabling this limit or setting it too high may result in severe damage to the system.", |
f62194b2 DM |
220 | type => 'integer', |
221 | minimum => 0, | |
222 | default => 1000, | |
223 | }, | |
ac5d1312 DM |
224 | archivemaxsize => { |
225 | description => "Files larger than this limit won't be scanned.", | |
226 | type => 'integer', | |
227 | minimum => 1000000, | |
228 | default => 25000000, | |
229 | }, | |
230 | maxscansize => { | |
231 | description => "Sets the maximum amount of data to be scanned for each input file.", | |
232 | type => 'integer', | |
233 | minimum => 1000000, | |
234 | default => 100000000, | |
235 | }, | |
236 | maxcccount => { | |
237 | description => "This option sets the lowest number of Credit Card or Social Security numbers found in a file to generate a detect.", | |
238 | type => 'integer', | |
239 | minimum => 0, | |
240 | default => 0, | |
241 | }, | |
f62194b2 DM |
242 | }; |
243 | } | |
244 | ||
245 | sub options { | |
246 | return { | |
ac5d1312 DM |
247 | archiveblockencrypted => { optional => 1 }, |
248 | archivemaxrec => { optional => 1 }, | |
f62194b2 | 249 | archivemaxfiles => { optional => 1 }, |
ac5d1312 DM |
250 | archivemaxsize => { optional => 1 }, |
251 | maxscansize => { optional => 1 }, | |
252 | dbmirror => { optional => 1 }, | |
253 | maxcccount => { optional => 1 }, | |
7e0e6dbe DM |
254 | }; |
255 | } | |
256 | ||
d9dc3c08 DM |
257 | package PMG::Config::Mail; |
258 | ||
259 | use strict; | |
260 | use warnings; | |
261 | ||
f62194b2 DM |
262 | use PVE::ProcFSTools; |
263 | ||
d9dc3c08 DM |
264 | use base qw(PMG::Config::Base); |
265 | ||
266 | sub type { | |
267 | return 'mail'; | |
268 | } | |
269 | ||
f62194b2 DM |
270 | my $physicalmem = 0; |
271 | sub physical_memory { | |
272 | ||
273 | return $physicalmem if $physicalmem; | |
274 | ||
275 | my $info = PVE::ProcFSTools::read_meminfo(); | |
276 | my $total = int($info->{memtotal} / (1024*1024)); | |
277 | ||
278 | return $total; | |
279 | } | |
280 | ||
281 | sub get_max_filters { | |
282 | # estimate optimal number of filter servers | |
283 | ||
284 | my $max_servers = 5; | |
285 | my $servermem = 120; | |
286 | my $memory = physical_memory(); | |
287 | my $add_servers = int(($memory - 512)/$servermem); | |
288 | $max_servers += $add_servers if $add_servers > 0; | |
289 | $max_servers = 40 if $max_servers > 40; | |
290 | ||
291 | return $max_servers - 2; | |
292 | } | |
293 | ||
f609bf7f DM |
294 | sub get_max_smtpd { |
295 | # estimate optimal number of smtpd daemons | |
296 | ||
297 | my $max_servers = 25; | |
298 | my $servermem = 20; | |
299 | my $memory = physical_memory(); | |
300 | my $add_servers = int(($memory - 512)/$servermem); | |
301 | $max_servers += $add_servers if $add_servers > 0; | |
302 | $max_servers = 100 if $max_servers > 100; | |
303 | return $max_servers; | |
304 | } | |
305 | ||
03907162 DM |
306 | sub get_max_policy { |
307 | # estimate optimal number of proxpolicy servers | |
308 | my $max_servers = 2; | |
309 | my $memory = physical_memory(); | |
310 | $max_servers = 5 if $memory >= 500; | |
311 | return $max_servers; | |
312 | } | |
f609bf7f | 313 | |
d9dc3c08 DM |
314 | sub properties { |
315 | return { | |
75a20f14 DM |
316 | int_port => { |
317 | description => "SMTP port number for outgoing mail (trusted).", | |
318 | type => 'integer', | |
319 | minimum => 1, | |
320 | maximum => 65535, | |
321 | default => 25, | |
322 | }, | |
323 | ext_port => { | |
7b19cc5c | 324 | description => "SMTP port number for incoming mail (untrusted). This must be a different number than 'int_port'.", |
75a20f14 DM |
325 | type => 'integer', |
326 | minimum => 1, | |
327 | maximum => 65535, | |
328 | default => 26, | |
329 | }, | |
f609bf7f DM |
330 | relay => { |
331 | description => "The default mail delivery transport (incoming mails).", | |
66af5153 | 332 | type => 'string', format => 'address', |
f609bf7f DM |
333 | }, |
334 | relayport => { | |
335 | description => "SMTP port number for relay host.", | |
336 | type => 'integer', | |
337 | minimum => 1, | |
338 | maximum => 65535, | |
339 | default => 25, | |
340 | }, | |
341 | relaynomx => { | |
342 | description => "Disable MX lookups for default relay.", | |
343 | type => 'boolean', | |
344 | default => 0, | |
345 | }, | |
346 | smarthost => { | |
347 | description => "When set, all outgoing mails are deliverd to the specified smarthost.", | |
3bb296d4 | 348 | type => 'string', format => 'address', |
f609bf7f | 349 | }, |
d9dc3c08 DM |
350 | banner => { |
351 | description => "ESMTP banner.", | |
352 | type => 'string', | |
353 | maxLength => 1024, | |
354 | default => 'ESMTP Proxmox', | |
355 | }, | |
f62194b2 | 356 | max_filters => { |
03907162 | 357 | description => "Maximum number of pmg-smtp-filter processes.", |
f62194b2 DM |
358 | type => 'integer', |
359 | minimum => 3, | |
360 | maximum => 40, | |
361 | default => get_max_filters(), | |
362 | }, | |
03907162 DM |
363 | max_policy => { |
364 | description => "Maximum number of pmgpolicy processes.", | |
365 | type => 'integer', | |
366 | minimum => 2, | |
367 | maximum => 10, | |
368 | default => get_max_policy(), | |
369 | }, | |
f609bf7f DM |
370 | max_smtpd_in => { |
371 | description => "Maximum number of SMTP daemon processes (in).", | |
372 | type => 'integer', | |
373 | minimum => 3, | |
374 | maximum => 100, | |
375 | default => get_max_smtpd(), | |
376 | }, | |
377 | max_smtpd_out => { | |
378 | description => "Maximum number of SMTP daemon processes (out).", | |
379 | type => 'integer', | |
380 | minimum => 3, | |
381 | maximum => 100, | |
382 | default => get_max_smtpd(), | |
383 | }, | |
384 | conn_count_limit => { | |
385 | description => "How many simultaneous connections any client is allowed to make to this service. To disable this feature, specify a limit of 0.", | |
386 | type => 'integer', | |
387 | minimum => 0, | |
388 | default => 50, | |
389 | }, | |
390 | conn_rate_limit => { | |
391 | description => "The maximal number of connection attempts any client is allowed to make to this service per minute. To disable this feature, specify a limit of 0.", | |
392 | type => 'integer', | |
393 | minimum => 0, | |
394 | default => 0, | |
395 | }, | |
396 | message_rate_limit => { | |
397 | description => "The maximal number of message delivery requests that any client is allowed to make to this service per minute.To disable this feature, specify a limit of 0.", | |
398 | type => 'integer', | |
399 | minimum => 0, | |
400 | default => 0, | |
401 | }, | |
f62194b2 DM |
402 | hide_received => { |
403 | description => "Hide received header in outgoing mails.", | |
404 | type => 'boolean', | |
ac5d1312 DM |
405 | default => 0, |
406 | }, | |
f609bf7f | 407 | maxsize => { |
ac5d1312 DM |
408 | description => "Maximum email size. Larger mails are rejected.", |
409 | type => 'integer', | |
410 | minimum => 1024, | |
411 | default => 1024*1024*10, | |
f62194b2 | 412 | }, |
f609bf7f DM |
413 | dwarning => { |
414 | description => "SMTP delay warning time (in hours).", | |
415 | type => 'integer', | |
416 | minimum => 0, | |
417 | default => 4, | |
418 | }, | |
419 | use_rbl => { | |
4d76e24e | 420 | description => "Use Realtime Blacklists.", |
f609bf7f DM |
421 | type => 'boolean', |
422 | default => 1, | |
423 | }, | |
424 | tls => { | |
4d76e24e | 425 | description => "Use TLS.", |
f609bf7f DM |
426 | type => 'boolean', |
427 | default => 0, | |
428 | }, | |
429 | spf => { | |
4d76e24e | 430 | description => "Use Sender Policy Framework.", |
f609bf7f DM |
431 | type => 'boolean', |
432 | default => 1, | |
433 | }, | |
434 | greylist => { | |
4d76e24e | 435 | description => "Use Greylisting.", |
f609bf7f DM |
436 | type => 'boolean', |
437 | default => 1, | |
438 | }, | |
439 | helotests => { | |
4d76e24e | 440 | description => "Use SMTP HELO tests.", |
f609bf7f DM |
441 | type => 'boolean', |
442 | default => 0, | |
443 | }, | |
444 | rejectunknown => { | |
4d76e24e | 445 | description => "Reject unknown clients.", |
f609bf7f DM |
446 | type => 'boolean', |
447 | default => 0, | |
448 | }, | |
449 | rejectunknownsender => { | |
4d76e24e | 450 | description => "Reject unknown senders.", |
f609bf7f DM |
451 | type => 'boolean', |
452 | default => 0, | |
453 | }, | |
454 | verifyreceivers => { | |
3791e936 | 455 | description => "Enable receiver verification. The value spefifies the numerical reply code when the Postfix SMTP server rejects a recipient address.", |
90822f27 DM |
456 | type => 'string', |
457 | enum => ['450', '550'], | |
f609bf7f DM |
458 | }, |
459 | dnsbl_sites => { | |
460 | description => "Optional list of DNS white/blacklist domains (see postscreen_dnsbl_sites parameter).", | |
461 | type => 'string', | |
462 | }, | |
d9dc3c08 DM |
463 | }; |
464 | } | |
465 | ||
466 | sub options { | |
467 | return { | |
75a20f14 DM |
468 | int_port => { optional => 1 }, |
469 | ext_port => { optional => 1 }, | |
3d9837d9 | 470 | smarthost => { optional => 1 }, |
f609bf7f DM |
471 | relay => { optional => 1 }, |
472 | relayport => { optional => 1 }, | |
473 | relaynomx => { optional => 1 }, | |
474 | dwarning => { optional => 1 }, | |
475 | max_smtpd_in => { optional => 1 }, | |
476 | max_smtpd_out => { optional => 1 }, | |
477 | greylist => { optional => 1 }, | |
478 | helotests => { optional => 1 }, | |
479 | use_rbl => { optional => 1 }, | |
480 | tls => { optional => 1 }, | |
481 | spf => { optional => 1 }, | |
482 | maxsize => { optional => 1 }, | |
d9dc3c08 | 483 | banner => { optional => 1 }, |
f62194b2 | 484 | max_filters => { optional => 1 }, |
03907162 | 485 | max_policy => { optional => 1 }, |
f62194b2 | 486 | hide_received => { optional => 1 }, |
f609bf7f DM |
487 | rejectunknown => { optional => 1 }, |
488 | rejectunknownsender => { optional => 1 }, | |
489 | conn_count_limit => { optional => 1 }, | |
490 | conn_rate_limit => { optional => 1 }, | |
491 | message_rate_limit => { optional => 1 }, | |
492 | verifyreceivers => { optional => 1 }, | |
493 | dnsbl_sites => { optional => 1 }, | |
d9dc3c08 DM |
494 | }; |
495 | } | |
7e0e6dbe DM |
496 | package PMG::Config; |
497 | ||
498 | use strict; | |
499 | use warnings; | |
9123cab5 | 500 | use IO::File; |
7e0e6dbe | 501 | use Data::Dumper; |
4ccdc564 | 502 | use Template; |
7e0e6dbe | 503 | |
9123cab5 | 504 | use PVE::SafeSyslog; |
7e0e6dbe DM |
505 | use PVE::Tools; |
506 | use PVE::INotify; | |
507 | ||
ac5d1312 | 508 | PMG::Config::Admin->register(); |
d9dc3c08 | 509 | PMG::Config::Mail->register(); |
7e0e6dbe | 510 | PMG::Config::Spam->register(); |
f62194b2 | 511 | PMG::Config::ClamAV->register(); |
7e0e6dbe DM |
512 | |
513 | # initialize all plugins | |
514 | PMG::Config::Base->init(); | |
515 | ||
f62194b2 DM |
516 | |
517 | sub new { | |
518 | my ($type) = @_; | |
519 | ||
520 | my $class = ref($type) || $type; | |
521 | ||
522 | my $cfg = PVE::INotify::read_file("pmg.conf"); | |
523 | ||
524 | return bless $cfg, $class; | |
525 | } | |
526 | ||
be6e2db9 DM |
527 | sub write { |
528 | my ($self) = @_; | |
529 | ||
530 | PVE::INotify::write_file("pmg.conf", $self); | |
531 | } | |
532 | ||
f21d933c DM |
533 | my $lockfile = "/var/lock/pmgconfig.lck"; |
534 | ||
535 | sub lock_config { | |
536 | my ($code, $errmsg) = @_; | |
537 | ||
538 | my $p = PVE::Tools::lock_file($lockfile, undef, $code); | |
539 | if (my $err = $@) { | |
540 | $errmsg ? die "$errmsg: $err" : die $err; | |
541 | } | |
542 | } | |
543 | ||
062f0498 | 544 | # set section values |
062f0498 DM |
545 | sub set { |
546 | my ($self, $section, $key, $value) = @_; | |
547 | ||
548 | my $pdata = PMG::Config::Base->private(); | |
549 | ||
062f0498 DM |
550 | my $plugin = $pdata->{plugins}->{$section}; |
551 | die "no such section '$section'" if !$plugin; | |
552 | ||
062f0498 DM |
553 | if (defined($value)) { |
554 | my $tmp = PMG::Config::Base->check_value($section, $key, $value, $section, 0); | |
d79b9b0c DM |
555 | $self->{ids}->{$section} = { type => $section } if !defined($self->{ids}->{$section}); |
556 | $self->{ids}->{$section}->{$key} = PMG::Config::Base->decode_value($section, $key, $tmp); | |
062f0498 | 557 | } else { |
d79b9b0c DM |
558 | if (defined($self->{ids}->{$section})) { |
559 | delete $self->{ids}->{$section}->{$key}; | |
062f0498 DM |
560 | } |
561 | } | |
562 | ||
563 | return undef; | |
564 | } | |
565 | ||
f62194b2 | 566 | # get section value or default |
f62194b2 DM |
567 | sub get { |
568 | my ($self, $section, $key) = @_; | |
569 | ||
570 | my $pdata = PMG::Config::Base->private(); | |
f62194b2 | 571 | my $pdesc = $pdata->{propertyList}->{$key}; |
3d9837d9 DM |
572 | die "no such property '$section/$key'\n" |
573 | if !(defined($pdesc) && defined($pdata->{options}->{$section}) && | |
574 | defined($pdata->{options}->{$section}->{$key})); | |
f62194b2 | 575 | |
d79b9b0c DM |
576 | if (defined($self->{ids}->{$section}) && |
577 | defined(my $value = $self->{ids}->{$section}->{$key})) { | |
f62194b2 | 578 | return $value; |
1ccc8e95 | 579 | } |
f62194b2 DM |
580 | |
581 | return $pdesc->{default}; | |
582 | } | |
583 | ||
1ccc8e95 | 584 | # get a whole section with default value |
1ccc8e95 DM |
585 | sub get_section { |
586 | my ($self, $section) = @_; | |
587 | ||
588 | my $pdata = PMG::Config::Base->private(); | |
589 | return undef if !defined($pdata->{options}->{$section}); | |
590 | ||
591 | my $res = {}; | |
592 | ||
593 | foreach my $key (keys %{$pdata->{options}->{$section}}) { | |
594 | ||
595 | my $pdesc = $pdata->{propertyList}->{$key}; | |
596 | ||
d79b9b0c DM |
597 | if (defined($self->{ids}->{$section}) && |
598 | defined(my $value = $self->{ids}->{$section}->{$key})) { | |
1ccc8e95 DM |
599 | $res->{$key} = $value; |
600 | next; | |
601 | } | |
602 | $res->{$key} = $pdesc->{default}; | |
603 | } | |
604 | ||
605 | return $res; | |
606 | } | |
607 | ||
be16be07 | 608 | # get a whole config with default values |
be16be07 DM |
609 | sub get_config { |
610 | my ($self) = @_; | |
611 | ||
9dab5fe5 DM |
612 | my $pdata = PMG::Config::Base->private(); |
613 | ||
be16be07 DM |
614 | my $res = {}; |
615 | ||
9dab5fe5 | 616 | foreach my $type (keys %{$pdata->{plugins}}) { |
9dab5fe5 DM |
617 | my $plugin = $pdata->{plugins}->{$type}; |
618 | $res->{$type} = $self->get_section($type); | |
be16be07 DM |
619 | } |
620 | ||
621 | return $res; | |
622 | } | |
623 | ||
7e0e6dbe DM |
624 | sub read_pmg_conf { |
625 | my ($filename, $fh) = @_; | |
f62194b2 | 626 | |
7e0e6dbe | 627 | local $/ = undef; # slurp mode |
f62194b2 | 628 | |
9dfe7c16 | 629 | my $raw = <$fh> if defined($fh); |
7e0e6dbe DM |
630 | |
631 | return PMG::Config::Base->parse_config($filename, $raw); | |
632 | } | |
633 | ||
634 | sub write_pmg_conf { | |
635 | my ($filename, $fh, $cfg) = @_; | |
636 | ||
637 | my $raw = PMG::Config::Base->write_config($filename, $cfg); | |
638 | ||
639 | PVE::Tools::safe_print($filename, $fh, $raw); | |
640 | } | |
641 | ||
3278b571 | 642 | PVE::INotify::register_file('pmg.conf', "/etc/pmg/pmg.conf", |
f62194b2 | 643 | \&read_pmg_conf, |
9dfe7c16 DM |
644 | \&write_pmg_conf, |
645 | undef, always_call_parser => 1); | |
7e0e6dbe | 646 | |
f609bf7f DM |
647 | # parsers/writers for other files |
648 | ||
3278b571 | 649 | my $domainsfilename = "/etc/pmg/domains"; |
f609bf7f DM |
650 | |
651 | sub read_pmg_domains { | |
652 | my ($filename, $fh) = @_; | |
653 | ||
654 | my $domains = []; | |
655 | ||
656 | if (defined($fh)) { | |
657 | while (defined(my $line = <$fh>)) { | |
658 | if ($line =~ m/^\s*(\S+)\s*$/) { | |
659 | my $domain = $1; | |
660 | push @$domains, $domain; | |
661 | } | |
662 | } | |
663 | } | |
664 | ||
665 | return $domains; | |
666 | } | |
667 | ||
668 | sub write_pmg_domains { | |
669 | my ($filename, $fh, $domain) = @_; | |
670 | ||
671 | foreach my $domain (sort @$domain) { | |
672 | PVE::Tools::safe_print($filename, $fh, "$domain\n"); | |
673 | } | |
674 | } | |
675 | ||
676 | PVE::INotify::register_file('domains', $domainsfilename, | |
677 | \&read_pmg_domains, | |
678 | \&write_pmg_domains, | |
679 | undef, always_call_parser => 1); | |
680 | ||
3546daf0 DM |
681 | my $transport_map_filename = "/etc/postfix/transport"; |
682 | ||
683 | sub read_transport_map { | |
684 | my ($filename, $fh) = @_; | |
685 | ||
686 | return [] if !defined($fh); | |
687 | ||
688 | my $res = {}; | |
689 | ||
690 | while (defined(my $line = <$fh>)) { | |
691 | chomp $line; | |
692 | next if $line =~ m/^\s*$/; | |
693 | next if $line =~ m/^\s*\#/; | |
694 | ||
695 | if ($line =~ m/^(\S+)\s+smtp:([^\s:]+):(\d+)\s*$/) { | |
696 | my $domain = $1; | |
697 | my $host = $2; | |
698 | my $port =$3; | |
699 | my $nomx; | |
700 | ||
701 | if ($host =~ m/^\[(.*)\]$/) { | |
702 | $host = $1; | |
703 | $nomx = 1; | |
704 | } | |
705 | ||
706 | my $key = "$host:$port"; | |
707 | ||
708 | $res->{$key}->{nomx} = $nomx; | |
709 | $res->{$key}->{host} = $host; | |
710 | $res->{$key}->{port} = $port; | |
711 | $res->{$key}->{transport} = $key; | |
712 | ||
713 | push @{$res->{$key}->{domains}}, $domain; | |
714 | } | |
715 | } | |
716 | ||
717 | my $ta = []; | |
718 | ||
719 | foreach my $t (sort keys %$res) { | |
720 | push @$ta, $res->{$t}; | |
721 | } | |
722 | ||
723 | return $ta; | |
724 | } | |
725 | ||
726 | sub write_ransport_map { | |
727 | my ($filename, $fh, $tmap) = @_; | |
728 | ||
729 | return if !$tmap; | |
730 | ||
731 | foreach my $t (sort { $a->{transport} cmp $b->{transport} } @$tmap) { | |
732 | my $domains = $t->{domains}; | |
733 | ||
734 | foreach my $d (sort @$domains) { | |
735 | if ($t->{nomx}) { | |
736 | PVE::Tools::safe_print($filename, $fh, "$d smtp:[$t->{host}]:$t->{port}\n"); | |
737 | } else { | |
738 | PVE::Tools::safe_print($filename, $fh, "$d smtp:$t->{host}:$t->{port}\n"); | |
739 | } | |
740 | } | |
741 | } | |
742 | } | |
743 | ||
744 | PVE::INotify::register_file('transport', $transport_map_filename, | |
745 | \&read_transport_map, | |
746 | \&write_ransport_map, | |
747 | undef, always_call_parser => 1); | |
7e0e6dbe | 748 | |
4ccdc564 DM |
749 | # config file generation using templates |
750 | ||
07b3face DM |
751 | sub get_template_vars { |
752 | my ($self) = @_; | |
4ccdc564 DM |
753 | |
754 | my $vars = { pmg => $self->get_config() }; | |
755 | ||
f609bf7f DM |
756 | my $nodename = PVE::INotify::nodename(); |
757 | my $int_ip = PMG::Cluster::remote_node_ip($nodename); | |
758 | my $int_net_cidr = PMG::Utils::find_local_network_for_ip($int_ip); | |
f609bf7f DM |
759 | $vars->{ipconfig}->{int_ip} = $int_ip; |
760 | # $vars->{ipconfig}->{int_net_cidr} = $int_net_cidr; | |
f609bf7f DM |
761 | |
762 | my $transportnets = []; # fixme | |
763 | $vars->{postfix}->{transportnets} = join(' ', @$transportnets); | |
764 | ||
765 | my $mynetworks = [ '127.0.0.0/8', '[::1]/128' ]; | |
766 | push @$mynetworks, @$transportnets; | |
767 | push @$mynetworks, $int_net_cidr; | |
768 | ||
769 | # add default relay to mynetworks | |
770 | if (my $relay = $self->get('mail', 'relay')) { | |
771 | if (Net::IP::ip_is_ipv4($relay)) { | |
772 | push @$mynetworks, "$relay/32"; | |
773 | } elsif (Net::IP::ip_is_ipv6($relay)) { | |
774 | push @$mynetworks, "[$relay]/128"; | |
775 | } else { | |
66af5153 | 776 | # DNS name - do nothing ? |
f609bf7f DM |
777 | } |
778 | } | |
779 | ||
780 | $vars->{postfix}->{mynetworks} = join(' ', @$mynetworks); | |
781 | ||
782 | my $usepolicy = 0; | |
783 | $usepolicy = 1 if $self->get('mail', 'greylist') || | |
784 | $self->get('mail', 'spf') || $self->get('mail', 'use_rbl'); | |
785 | $vars->{postfix}->{usepolicy} = $usepolicy; | |
786 | ||
787 | my $resolv = PVE::INotify::read_file('resolvconf'); | |
788 | $vars->{dns}->{hostname} = $nodename; | |
789 | $vars->{dns}->{domain} = $resolv->{search}; | |
790 | ||
07b3face DM |
791 | return $vars; |
792 | } | |
793 | ||
794 | # rewrite file from template | |
795 | # return true if file has changed | |
796 | sub rewrite_config_file { | |
797 | my ($self, $tmplname, $dstfn) = @_; | |
798 | ||
799 | my $demo = $self->get('admin', 'demo'); | |
800 | ||
801 | my $srcfn = ($tmplname =~ m|^.?/|) ? | |
802 | $tmplname : "/var/lib/pmg/templates/$tmplname"; | |
803 | ||
804 | if ($demo) { | |
805 | my $demosrc = "$srcfn.demo"; | |
806 | $srcfn = $demosrc if -f $demosrc; | |
807 | } | |
808 | ||
c248d69f | 809 | my ($perm, $uid, $gid); |
07b3face DM |
810 | |
811 | my $srcfd = IO::File->new ($srcfn, "r") | |
812 | || die "cant read template '$srcfn' - $!: ERROR"; | |
813 | ||
814 | if ($dstfn eq '/etc/fetchmailrc') { | |
815 | (undef, undef, $uid, $gid) = getpwnam('fetchmail'); | |
816 | $perm = 0600; | |
817 | } elsif ($dstfn eq '/etc/clamav/freshclam.conf') { | |
818 | # needed if file contains a HTTPProxyPasswort | |
819 | ||
820 | $uid = getpwnam('clamav'); | |
821 | $gid = getgrnam('adm'); | |
822 | $perm = 0600; | |
823 | } | |
824 | ||
825 | my $template = Template->new({}); | |
826 | ||
827 | my $vars = $self->get_template_vars(); | |
828 | ||
c248d69f | 829 | my $output = ''; |
07b3face DM |
830 | |
831 | $template->process($srcfd, $vars, \$output) || | |
4ccdc564 DM |
832 | die $template->error(); |
833 | ||
834 | $srcfd->close(); | |
07b3face DM |
835 | |
836 | my $old = PVE::Tools::file_get_contents($dstfn, 128*1024) if -f $dstfn; | |
837 | ||
838 | return 0 if defined($old) && ($old eq $output); # no change | |
839 | ||
840 | PVE::Tools::file_set_contents($dstfn, $output, $perm); | |
841 | ||
842 | if (defined($uid) && defined($gid)) { | |
843 | chown($uid, $gid, $dstfn); | |
844 | } | |
845 | ||
846 | return 1; | |
4ccdc564 DM |
847 | } |
848 | ||
9123cab5 DM |
849 | # rewrite spam configuration |
850 | sub rewrite_config_spam { | |
851 | my ($self) = @_; | |
852 | ||
853 | my $use_awl = $self->get('spam', 'use_awl'); | |
854 | my $use_bayes = $self->get('spam', 'use_bayes'); | |
855 | my $use_razor = $self->get('spam', 'use_razor'); | |
856 | ||
17424665 DM |
857 | my $changes = 0; |
858 | ||
9123cab5 | 859 | # delete AW and bayes databases if those features are disabled |
17424665 DM |
860 | if (!$use_awl) { |
861 | $changes = 1 if unlink '/root/.spamassassin/auto-whitelist'; | |
862 | } | |
863 | ||
9123cab5 | 864 | if (!$use_bayes) { |
17424665 DM |
865 | $changes = 1 if unlink '/root/.spamassassin/bayes_journal'; |
866 | $changes = 1 if unlink '/root/.spamassassin/bayes_seen'; | |
867 | $changes = 1 if unlink '/root/.spamassassin/bayes_toks'; | |
9123cab5 DM |
868 | } |
869 | ||
870 | # make sure we have a custom.cf file (else cluster sync fails) | |
871 | IO::File->new('/etc/mail/spamassassin/custom.cf', 'a', 0644); | |
872 | ||
17424665 DM |
873 | $changes = 1 if $self->rewrite_config_file( |
874 | 'local.cf.in', '/etc/mail/spamassassin/local.cf'); | |
875 | ||
876 | $changes = 1 if $self->rewrite_config_file( | |
877 | 'init.pre.in', '/etc/mail/spamassassin/init.pre'); | |
878 | ||
879 | $changes = 1 if $self->rewrite_config_file( | |
880 | 'v310.pre.in', '/etc/mail/spamassassin/v310.pre'); | |
881 | ||
882 | $changes = 1 if $self->rewrite_config_file( | |
883 | 'v320.pre.in', '/etc/mail/spamassassin/v320.pre'); | |
9123cab5 DM |
884 | |
885 | if ($use_razor) { | |
886 | mkdir "/root/.razor"; | |
17424665 DM |
887 | |
888 | $changes = 1 if $self->rewrite_config_file( | |
889 | 'razor-agent.conf.in', '/root/.razor/razor-agent.conf'); | |
890 | ||
9123cab5 DM |
891 | if (! -e '/root/.razor/identity') { |
892 | eval { | |
893 | my $timeout = 30; | |
17424665 DM |
894 | PVE::Tools::run_command(['razor-admin', '-discover'], timeout => $timeout); |
895 | PVE::Tools::run_command(['razor-admin', '-register'], timeout => $timeout); | |
9123cab5 DM |
896 | }; |
897 | my $err = $@; | |
898 | syslog('info', msgquote ("registering razor failed: $err")) if $err; | |
899 | } | |
900 | } | |
17424665 DM |
901 | |
902 | return $changes; | |
9123cab5 DM |
903 | } |
904 | ||
ac5d1312 DM |
905 | # rewrite ClamAV configuration |
906 | sub rewrite_config_clam { | |
907 | my ($self) = @_; | |
908 | ||
17424665 DM |
909 | return $self->rewrite_config_file( |
910 | 'clamd.conf.in', '/etc/clamav/clamd.conf'); | |
911 | } | |
912 | ||
913 | sub rewrite_config_freshclam { | |
914 | my ($self) = @_; | |
915 | ||
916 | return $self->rewrite_config_file( | |
917 | 'freshclam.conf.in', '/etc/clamav/freshclam.conf'); | |
ac5d1312 DM |
918 | } |
919 | ||
86737f12 DM |
920 | sub rewrite_config_postgres { |
921 | my ($self) = @_; | |
922 | ||
923 | my $pgconfdir = "/etc/postgresql/9.6/main"; | |
924 | ||
17424665 DM |
925 | my $changes = 0; |
926 | ||
927 | $changes = 1 if $self->rewrite_config_file( | |
928 | 'pg_hba.conf.in', "$pgconfdir/pg_hba.conf"); | |
929 | ||
930 | $changes = 1 if $self->rewrite_config_file( | |
931 | 'postgresql.conf.in', "$pgconfdir/postgresql.conf"); | |
932 | ||
933 | return $changes; | |
86737f12 DM |
934 | } |
935 | ||
936 | # rewrite /root/.forward | |
937 | sub rewrite_dot_forward { | |
938 | my ($self) = @_; | |
939 | ||
c248d69f | 940 | my $dstfn = '/root/.forward'; |
86737f12 | 941 | |
0bb9a01a | 942 | my $email = $self->get('admin', 'email'); |
c248d69f | 943 | |
e14fda7a | 944 | my $output = ''; |
86737f12 | 945 | if ($email && $email =~ m/\s*(\S+)\s*/) { |
c248d69f | 946 | $output = "$1\n"; |
86737f12 DM |
947 | } else { |
948 | # empty .forward does not forward mails (see man local) | |
949 | } | |
17424665 | 950 | |
c248d69f DM |
951 | my $old = PVE::Tools::file_get_contents($dstfn, 128*1024) if -f $dstfn; |
952 | ||
953 | return 0 if defined($old) && ($old eq $output); # no change | |
954 | ||
955 | PVE::Tools::file_set_contents($dstfn, $output); | |
956 | ||
957 | return 1; | |
86737f12 DM |
958 | } |
959 | ||
f609bf7f DM |
960 | # rewrite /etc/postfix/* |
961 | sub rewrite_config_postfix { | |
962 | my ($self) = @_; | |
963 | ||
3546daf0 | 964 | # make sure we have required files (else postfix start fails) |
f609bf7f | 965 | IO::File->new($domainsfilename, 'a', 0644); |
3546daf0 | 966 | IO::File->new($transport_map_filename, 'a', 0644); |
f609bf7f | 967 | |
17424665 DM |
968 | my $changes = 0; |
969 | ||
f609bf7f DM |
970 | if ($self->get('mail', 'tls')) { |
971 | eval { | |
bc44eb02 | 972 | PMG::Utils::gen_proxmox_tls_cert(); |
f609bf7f DM |
973 | }; |
974 | syslog ('info', msgquote ("generating certificate failed: $@")) if $@; | |
975 | } | |
976 | ||
17424665 DM |
977 | $changes = 1 if $self->rewrite_config_file( |
978 | 'main.cf.in', '/etc/postfix/main.cf'); | |
979 | ||
980 | $changes = 1 if $self->rewrite_config_file( | |
981 | 'master.cf.in', '/etc/postfix/master.cf'); | |
982 | ||
f609bf7f DM |
983 | #rewrite_config_transports ($class); |
984 | #rewrite_config_whitelist ($class); | |
985 | #rewrite_config_tls_policy ($class); | |
986 | ||
987 | # make sure aliases.db is up to date | |
988 | system('/usr/bin/newaliases'); | |
17424665 DM |
989 | |
990 | return $changes; | |
f609bf7f DM |
991 | } |
992 | ||
f983300f | 993 | sub rewrite_config { |
c248d69f DM |
994 | my ($self, $restart_services) = @_; |
995 | ||
996 | if ($self->rewrite_config_postfix() && $restart_services) { | |
997 | PMG::Utils::service_cmd('postfix', 'restart'); | |
998 | } | |
999 | ||
1000 | if ($self->rewrite_dot_forward() && $restart_services) { | |
1001 | # no need to restart anything | |
1002 | } | |
1003 | ||
1004 | if ($self->rewrite_config_postgres() && $restart_services) { | |
1005 | # do nothing (too many side effects)? | |
1006 | # does not happen anyways, because config does not change. | |
1007 | } | |
f983300f | 1008 | |
c248d69f DM |
1009 | if ($self->rewrite_config_spam() && $restart_services) { |
1010 | PMG::Utils::service_cmd('pmg-smtp-filter', 'restart'); | |
1011 | } | |
1012 | ||
1013 | if ($self->rewrite_config_clam() && $restart_services) { | |
8f87fe74 | 1014 | PMG::Utils::service_cmd('clamav-daemon', 'restart'); |
c248d69f DM |
1015 | } |
1016 | ||
1017 | if ($self->rewrite_config_freshclam() && $restart_services) { | |
8f87fe74 | 1018 | PMG::Utils::service_cmd('clamav-freshclam', 'restart'); |
c248d69f | 1019 | } |
17424665 | 1020 | |
f983300f DM |
1021 | } |
1022 | ||
7e0e6dbe | 1023 | 1; |