1 (* HCoop
Domtool (http
://hcoop
.sourceforge
.net
/)
2 * Copyright (c
) 2006, Adam Chlipala
4 * This program is free software
; you can redistribute it
and/or
5 * modify it under the terms
of the GNU General Public License
6 * as published by the Free Software Foundation
; either version
2
7 * of the License
, or (at your option
) any later version
.
9 * This program is distributed
in the hope that it will be useful
,
10 * but WITHOUT ANY WARRANTY
; without even the implied warranty
of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE
. See the
12 * GNU General Public License for more details
.
14 * You should have received a copy
of the GNU General Public License
15 * along
with this program
; if not
, write to the Free Software
16 * Foundation
, Inc
., 51 Franklin Street
, Fifth Floor
, Boston
, MA
02110-1301, USA
.
21 structure Main
:> MAIN
= struct
23 open Ast MsgTypes Print
25 structure SM
= StringMap
27 fun init () = Acl
.read Config
.aclFile
31 val prog
= Parse
.parse fname
33 if !ErrorMsg
.anyErrors
then
36 Tycheck
.checkFile
G (Defaults
.tInit ()) prog
41 val dir
= Posix
.FileSys
.opendir Config
.libRoot
44 case Posix
.FileSys
.readdir dir
of
45 NONE
=> (Posix
.FileSys
.closedir dir
;
48 if String.isSuffix
".dtl" fname
then
49 loop (OS
.Path
.joinDirFile
{dir
= Config
.libRoot
,
56 val (_
, files
) = Order
.order NONE files
58 if !ErrorMsg
.anyErrors
then
61 (Tycheck
.allowExterns ();
62 foldl (fn (fname
, G
) => check
' G fname
) Env
.empty files
63 before Tycheck
.disallowExterns ())
68 val _
= ErrorMsg
.reset ()
69 val _
= Env
.preTycheck ()
73 if !ErrorMsg
.anyErrors
then
77 val _
= Tycheck
.disallowExterns ()
78 val _
= ErrorMsg
.reset ()
79 val prog
= Parse
.parse fname
81 if !ErrorMsg
.anyErrors
then
85 val G
' = Tycheck
.checkFile
b (Defaults
.tInit ()) prog
87 if !ErrorMsg
.anyErrors
then
95 val notTmp
= CharVector
.all (fn ch
=> Char.isAlphaNum ch
orelse ch
= #
"." orelse ch
= #
"_" orelse ch
= #
"-")
101 val dir
= Posix
.FileSys
.opendir dname
104 case Posix
.FileSys
.readdir dir
of
105 NONE
=> (Posix
.FileSys
.closedir dir
;
109 loop (OS
.Path
.joinDirFile
{dir
= dname
,
116 val (_
, files
) = Order
.order (SOME b
) files
118 if !ErrorMsg
.anyErrors
then
121 (foldl (fn (fname
, G
) => check
' G fname
) b files
;
122 if !ErrorMsg
.anyErrors
then
130 val (G
, body
) = check fname
132 if !ErrorMsg
.anyErrors
then
138 val body
' = Reduce
.reduceExp G body
140 (*printd (PD
.hovBox (PD
.PPS
.Rel
0,
141 [PD
.string "Result:",
152 if !ErrorMsg
.anyErrors
then
155 Eval
.exec (Defaults
.eInit ()) body
'
156 | NONE
=> raise ErrorMsg
.Error
161 if !ErrorMsg
.anyErrors
then
164 ignore (Eval
.exec
' (Defaults
.eInit ()) body
')
165 | NONE
=> raise ErrorMsg
.Error
168 Config
.dispatcher ^
":" ^
Int.toString Config
.dispatcherPort
170 fun requestContext f
=
172 val uid
= Posix
.ProcEnv
.getuid ()
173 val user
= Posix
.SysDB
.Passwd
.name (Posix
.SysDB
.getpwuid uid
)
175 val () = Acl
.read Config
.aclFile
176 val () = Domain
.setUser user
180 val context
= OpenSSL
.context (Config
.certDir ^
"/" ^ user ^
".pem",
181 Config
.keyDir ^
"/" ^ user ^
"/key.pem",
189 val (user
, context
) = requestContext f
191 (user
, OpenSSL
.connect (context
, dispatcher
))
196 val (user
, bio
) = requestBio (fn () => ignore (check fname
))
198 val inf
= TextIO.openIn fname
201 case TextIO.inputLine inf
of
202 NONE
=> String.concat (List.rev lines
)
203 | SOME line
=> loop (line
:: lines
)
208 Msg
.send (bio
, MsgConfig code
);
210 NONE
=> print
"Server closed connection unexpectedly.\n"
213 MsgOk
=> print
"Configuration succeeded.\n"
214 | MsgError s
=> print ("Configuration failed: " ^ s ^
"\n")
215 | _
=> print
"Unexpected server reply.\n";
218 handle ErrorMsg
.Error
=> ()
220 fun requestDir dname
=
222 val _
= ErrorMsg
.reset ()
224 val (user
, bio
) = requestBio (fn () => checkDir dname
)
228 val dir
= Posix
.FileSys
.opendir dname
231 case Posix
.FileSys
.readdir dir
of
232 NONE
=> (Posix
.FileSys
.closedir dir
;
236 loop (OS
.Path
.joinDirFile
{dir
= dname
,
243 val (_
, files
) = Order
.order (SOME b
) files
245 val _
= if !ErrorMsg
.anyErrors
then
250 val codes
= map (fn fname
=>
252 val inf
= TextIO.openIn fname
255 case TextIO.inputLine inf
of
256 NONE
=> String.concat (rev lines
)
257 | SOME line
=> loop (line
:: lines
)
260 before TextIO.closeIn inf
263 if !ErrorMsg
.anyErrors
then
266 (Msg
.send (bio
, MsgMultiConfig codes
);
268 NONE
=> print
"Server closed connection unexpectedly.\n"
271 MsgOk
=> print
"Configuration succeeded.\n"
272 | MsgError s
=> print ("Configuration failed: " ^ s ^
"\n")
273 | _
=> print
"Unexpected server reply.\n";
276 handle ErrorMsg
.Error
=> ()
278 fun requestGrant acl
=
280 val (user
, bio
) = requestBio (fn () => ())
282 Msg
.send (bio
, MsgGrant acl
);
284 NONE
=> print
"Server closed connection unexpectedly.\n"
287 MsgOk
=> print
"Grant succeeded.\n"
288 | MsgError s
=> print ("Grant failed: " ^ s ^
"\n")
289 | _
=> print
"Unexpected server reply.\n";
293 fun requestRevoke acl
=
295 val (user
, bio
) = requestBio (fn () => ())
297 Msg
.send (bio
, MsgRevoke acl
);
299 NONE
=> print
"Server closed connection unexpectedly.\n"
302 MsgOk
=> print
"Revoke succeeded.\n"
303 | MsgError s
=> print ("Revoke failed: " ^ s ^
"\n")
304 | _
=> print
"Unexpected server reply.\n";
308 fun requestListPerms user
=
310 val (_
, bio
) = requestBio (fn () => ())
312 Msg
.send (bio
, MsgListPerms user
);
313 (case Msg
.recv bio
of
314 NONE
=> (print
"Server closed connection unexpectedly.\n";
318 MsgPerms perms
=> SOME perms
319 | MsgError s
=> (print ("Listing failed: " ^ s ^
"\n");
321 | _
=> (print
"Unexpected server reply.\n";
323 before OpenSSL
.close bio
326 fun requestWhoHas perm
=
328 val (_
, bio
) = requestBio (fn () => ())
330 Msg
.send (bio
, MsgWhoHas perm
);
331 (case Msg
.recv bio
of
332 NONE
=> (print
"Server closed connection unexpectedly.\n";
336 MsgWhoHasResponse users
=> SOME users
337 | MsgError s
=> (print ("whohas failed: " ^ s ^
"\n");
339 | _
=> (print
"Unexpected server reply.\n";
341 before OpenSSL
.close bio
344 fun requestRegen () =
346 val (_
, bio
) = requestBio (fn () => ())
348 Msg
.send (bio
, MsgRegenerate
);
350 NONE
=> print
"Server closed connection unexpectedly.\n"
353 MsgOk
=> print
"Regeneration succeeded.\n"
354 | MsgError s
=> print ("Regeneration failed: " ^ s ^
"\n")
355 | _
=> print
"Unexpected server reply.\n";
359 fun requestRmdom dom
=
361 val (_
, bio
) = requestBio (fn () => ())
363 Msg
.send (bio
, MsgRmdom dom
);
365 NONE
=> print
"Server closed connection unexpectedly.\n"
368 MsgOk
=> print
"Removal succeeded.\n"
369 | MsgError s
=> print ("Removal failed: " ^ s ^
"\n")
370 | _
=> print
"Unexpected server reply.\n";
374 fun requestRmuser user
=
376 val (_
, bio
) = requestBio (fn () => ())
378 Msg
.send (bio
, MsgRmuser user
);
380 NONE
=> print
"Server closed connection unexpectedly.\n"
383 MsgOk
=> print
"Removal succeeded.\n"
384 | MsgError s
=> print ("Removal failed: " ^ s ^
"\n")
385 | _
=> print
"Unexpected server reply.\n";
389 fun requestDbUser dbtype
=
391 val (_
, bio
) = requestBio (fn () => ())
393 Msg
.send (bio
, MsgCreateDbUser dbtype
);
395 NONE
=> print
"Server closed connection unexpectedly.\n"
398 MsgOk
=> print
"Your user has been created.\n"
399 | MsgError s
=> print ("Creation failed: " ^ s ^
"\n")
400 | _
=> print
"Unexpected server reply.\n";
404 fun requestDbTable p
=
406 val (user
, bio
) = requestBio (fn () => ())
408 Msg
.send (bio
, MsgCreateDbTable p
);
410 NONE
=> print
"Server closed connection unexpectedly.\n"
413 MsgOk
=> print ("Your database " ^ user ^
"_" ^ #dbname p ^
" has been created.\n")
414 | MsgError s
=> print ("Creation failed: " ^ s ^
"\n")
415 | _
=> print
"Unexpected server reply.\n";
419 fun requestNewMailbox p
=
421 val (_
, bio
) = requestBio (fn () => ())
423 Msg
.send (bio
, MsgNewMailbox p
);
425 NONE
=> print
"Server closed connection unexpectedly.\n"
428 MsgOk
=> print ("A mapping for " ^ #user p ^
"@" ^ #domain p ^
" has been created.\n")
429 | MsgError s
=> print ("Creation failed: " ^ s ^
"\n")
430 | _
=> print
"Unexpected server reply.\n";
434 fun requestPasswdMailbox p
=
436 val (_
, bio
) = requestBio (fn () => ())
438 Msg
.send (bio
, MsgPasswdMailbox p
);
440 NONE
=> print
"Server closed connection unexpectedly.\n"
443 MsgOk
=> print ("The password for " ^ #user p ^
"@" ^ #domain p ^
" has been changed.\n")
444 | MsgError s
=> print ("Set failed: " ^ s ^
"\n")
445 | _
=> print
"Unexpected server reply.\n";
449 fun requestRmMailbox p
=
451 val (_
, bio
) = requestBio (fn () => ())
453 Msg
.send (bio
, MsgRmMailbox p
);
455 NONE
=> print
"Server closed connection unexpectedly.\n"
458 MsgOk
=> print ("The mapping for mailbox " ^ #user p ^
"@" ^ #domain p ^
" has been deleted.\n")
459 | MsgError s
=> print ("Remove failed: " ^ s ^
"\n")
460 | _
=> print
"Unexpected server reply.\n";
464 fun regenerate context
=
467 val () = Tycheck
.disallowExterns ()
469 val () = Domain
.resetGlobal ()
471 fun contactNode (node
, ip
) =
472 if node
= Config
.defaultNode
then
475 val bio
= OpenSSL
.connect (context
,
478 ^
Int.toString Config
.slavePort
)
480 Msg
.send (bio
, MsgRegenerate
);
482 NONE
=> print
"Slave closed connection unexpectedly\n"
485 MsgOk
=> print ("Slave " ^ node ^
" pre-regeneration finished\n")
486 | MsgError s
=> print ("Slave " ^ node
487 ^
" returned error: " ^
489 | _
=> print ("Slave " ^ node
490 ^
" returned unexpected command\n");
496 val _
= Domain
.setUser user
497 val _
= ErrorMsg
.reset ()
499 val dname
= Config
.domtoolDir user
501 val dir
= Posix
.FileSys
.opendir dname
504 case Posix
.FileSys
.readdir dir
of
505 NONE
=> (Posix
.FileSys
.closedir dir
;
509 loop (OS
.Path
.joinDirFile
{dir
= dname
,
516 val (_
, files
) = Order
.order (SOME b
) files
518 if !ErrorMsg
.anyErrors
then
519 print ("User " ^ user ^
"'s configuration has errors!\n")
524 | OS
.SysErr (s
, _
) => print ("System error processing user " ^ user ^
": " ^ s ^
"\n")
526 app contactNode Config
.nodeIps
;
528 app
doUser (Acl
.users ());
534 val doms
= Acl
.class
{user
= user
, class
= "domain"}
535 val doms
= List.filter (fn dom
=>
536 case Acl
.whoHas
{class
= "domain", value
= dom
} of
538 | _
=> false) (StringSet
.listItems doms
)
546 val () = Acl
.read Config
.aclFile
548 val context
= OpenSSL
.context (Config
.serverCert
,
551 val _
= Domain
.set_context context
553 val sock
= OpenSSL
.listen (context
, Config
.dispatcherPort
)
556 case OpenSSL
.accept sock
of
560 val user
= OpenSSL
.peerCN bio
561 val () = print ("\nConnection from " ^ user ^
"\n")
562 val () = Domain
.setUser user
566 (msgLocal
, SOME msgRemote
) =>
569 Msg
.send (bio
, MsgError msgRemote
))
570 |
(msgLocal
, NONE
) =>
573 Msg
.send (bio
, MsgOk
)))
574 handle OpenSSL
.OpenSSL _
=>
575 print
"OpenSSL error\n"
576 | OS
.SysErr (s
, _
) =>
577 (print
"System error: ";
580 Msg
.send (bio
, MsgError ("System error: " ^ s
))
581 handle OpenSSL
.OpenSSL _
=> ())
586 Msg
.send (bio
, MsgError ("Failure: " ^ s
))
587 handle OpenSSL
.OpenSSL _
=> ())
589 (print
"Compilation error\n";
590 Msg
.send (bio
, MsgError
"Error during configuration evaluation")
591 handle OpenSSL
.OpenSSL _
=> ());
593 ignore (OpenSSL
.readChar bio
);
595 handle OpenSSL
.OpenSSL _
=> ();
600 val _
= print
"Configuration:\n"
601 val _
= app (fn s
=> (print s
; print
"\n")) codes
604 val outname
= OS
.FileSys
.tmpName ()
608 val outf
= TextIO.openOut outname
610 TextIO.output (outf
, code
);
611 TextIO.closeOut outf
;
615 doIt (fn () => (Env
.pre ();
618 Msg
.send (bio
, MsgOk
);
619 ("Configuration complete.", NONE
)))
620 (fn () => OS
.FileSys
.remove outname
)
625 NONE
=> (OpenSSL
.close bio
626 handle OpenSSL
.OpenSSL _
=> ();
630 MsgConfig code
=> doConfig
[code
]
631 | MsgMultiConfig codes
=> doConfig codes
635 if Acl
.query
{user
= user
, class
= "priv", value
= "all"} then
637 Acl
.write Config
.aclFile
;
638 ("Granted permission " ^ #value acl ^
" to " ^ #user acl ^
" in " ^ #class acl ^
".",
641 ("Unauthorized user asked to grant a permission!",
642 SOME
"Not authorized to grant privileges"))
647 if Acl
.query
{user
= user
, class
= "priv", value
= "all"} then
649 Acl
.write Config
.aclFile
;
650 ("Revoked permission " ^ #value acl ^
" from " ^ #user acl ^
" in " ^ #class acl ^
".",
653 ("Unauthorized user asked to revoke a permission!",
654 SOME
"Not authorized to revoke privileges"))
657 | MsgListPerms user
=>
659 (Msg
.send (bio
, MsgPerms (Acl
.queryAll user
));
660 ("Sent permission list for user " ^ user ^
".",
666 (Msg
.send (bio
, MsgWhoHasResponse (Acl
.whoHas perm
));
667 ("Sent whohas response for " ^ #class perm ^
" / " ^ #value perm ^
".",
673 if Acl
.query
{user
= user
, class
= "priv", value
= "all"}
674 orelse List.all (fn dom
=> Acl
.query
{user
= user
, class
= "domain", value
= dom
}) doms
then
677 Acl
.revokeFromAll
{class
= "domain", value
= dom
}) doms
;
678 Acl
.write Config
.aclFile
;
679 ("Removed domains" ^
foldl (fn (d
, s
) => s ^
" " ^ d
) "" doms ^
".",
682 ("Unauthorized user asked to remove a domain!",
683 SOME
"Not authorized to remove that domain"))
688 if Acl
.query
{user
= user
, class
= "priv", value
= "regen"}
689 orelse Acl
.query
{user
= user
, class
= "priv", value
= "all"} then
691 ("Regenerated all configuration.",
694 ("Unauthorized user asked to regenerate!",
695 SOME
"Not authorized to regenerate"))
700 if Acl
.query
{user
= user
, class
= "priv", value
= "all"} then
702 Acl
.write Config
.aclFile
;
703 ("Removed user " ^ user
' ^
".",
706 ("Unauthorized user asked to remove a user!",
707 SOME
"Not authorized to remove users"))
710 | MsgCreateDbUser
{dbtype
, passwd
} =>
712 case Dbms
.lookup dbtype
of
713 NONE
=> ("Database user creation request with unknown datatype type " ^ dbtype
,
714 SOME ("Unknown database type " ^ dbtype
))
716 case #adduser handler
{user
= user
, passwd
= passwd
} of
717 NONE
=> ("Added " ^ dbtype ^
" user " ^ user ^
".",
720 ("Error adding a " ^ dbtype ^
" user " ^ user ^
": " ^ msg
,
721 SOME ("Error adding user: " ^ msg
)))
724 | MsgCreateDbTable
{dbtype
, dbname
} =>
726 if Dbms
.validDbname dbname
then
727 case Dbms
.lookup dbtype
of
728 NONE
=> ("Database creation request with unknown datatype type " ^ dbtype
,
729 SOME ("Unknown database type " ^ dbtype
))
731 case #createdb handler
{user
= user
, dbname
= dbname
} of
732 NONE
=> ("Created database " ^ user ^
"_" ^ dbname ^
".",
734 | SOME msg
=> ("Error creating database " ^ user ^
"_" ^ dbname ^
": " ^ msg
,
735 SOME ("Error creating database: " ^ msg
))
737 ("Invalid database name " ^ user ^
"_" ^ dbname
,
738 SOME ("Invalid database name " ^ dbname
)))
741 | MsgNewMailbox
{domain
, user
= emailUser
, passwd
, mailbox
} =>
743 if not (Domain
.yourDomain domain
) then
744 ("User wasn't authorized to add a mailbox to " ^ domain
,
745 SOME
"You're not authorized to configure that domain.")
746 else if not (Domain
.validUser emailUser
) then
747 ("Invalid e-mail username " ^ emailUser
,
748 SOME
"Invalid e-mail username")
749 else if not (CharVector
.all
Char.isGraph passwd
) then
751 SOME
"Invalid password; may only contain printable, non-space characters")
752 else if not (Domain
.yourPath mailbox
) then
753 ("User wasn't authorized to add a mailbox at " ^ mailbox
,
754 SOME
"You're not authorized to use that mailbox location.")
756 case Vmail
.add
{requester
= user
,
757 domain
= domain
, user
= emailUser
,
758 passwd
= passwd
, mailbox
= mailbox
} of
759 NONE
=> ("Added mailbox " ^ emailUser ^
"@" ^ domain ^
" at " ^ mailbox
,
761 | SOME msg
=> ("Error adding mailbox: " ^ msg
,
765 | MsgPasswdMailbox
{domain
, user
= emailUser
, passwd
} =>
767 if not (Domain
.yourDomain domain
) then
768 ("User wasn't authorized to change password of a mailbox for " ^ domain
,
769 SOME
"You're not authorized to configure that domain.")
770 else if not (Domain
.validUser emailUser
) then
771 ("Invalid e-mail username " ^ emailUser
,
772 SOME
"Invalid e-mail username")
773 else if not (CharVector
.all
Char.isGraph passwd
) then
775 SOME
"Invalid password; may only contain printable, non-space characters")
777 case Vmail
.passwd
{domain
= domain
, user
= emailUser
,
779 NONE
=> ("Changed password of mailbox " ^ emailUser ^
"@" ^ domain
,
781 | SOME msg
=> ("Error changing mailbox password: " ^ msg
,
785 | MsgRmMailbox
{domain
, user
= emailUser
} =>
787 if not (Domain
.yourDomain domain
) then
788 ("User wasn't authorized to change password of a mailbox for " ^ domain
,
789 SOME
"You're not authorized to configure that domain.")
790 else if not (Domain
.validUser emailUser
) then
791 ("Invalid e-mail username " ^ emailUser
,
792 SOME
"Invalid e-mail username")
794 case Vmail
.rm
{domain
= domain
, user
= emailUser
} of
795 NONE
=> ("Deleted mailbox " ^ emailUser ^
"@" ^ domain
,
797 | SOME msg
=> ("Error deleting mailbox: " ^ msg
,
802 doIt (fn () => ("Unexpected command",
803 SOME
"Unexpected command"))
808 handle OpenSSL
.OpenSSL s
=>
809 (print ("OpenSSL error: " ^ s ^
"\n");
811 handle OpenSSL
.OpenSSL _
=> ();
813 | OS
.SysErr (s
, _
) =>
814 (print ("System error: " ^ s ^
"\n");
816 handle OpenSSL
.OpenSSL _
=> ();
819 print
"Listening for connections....\n";
821 OpenSSL
.shutdown sock
826 val host
= Slave
.hostname ()
828 val context
= OpenSSL
.context (Config
.certDir ^
"/" ^ host ^
".pem",
829 Config
.keyDir ^
"/" ^ host ^
"/key.pem",
832 val sock
= OpenSSL
.listen (context
, Config
.slavePort
)
835 case OpenSSL
.accept sock
of
839 val peer
= OpenSSL
.peerCN bio
840 val () = print ("\nConnection from " ^ peer ^
"\n")
842 if peer
<> Config
.dispatcherName
then
843 (print
"Not authorized!\n";
849 NONE
=> print
"Dispatcher closed connection unexpectedly\n"
852 MsgFile file
=> loop
' (file
:: files
)
853 | MsgDoFiles
=> (Slave
.handleChanges files
;
854 Msg
.send (bio
, MsgOk
))
855 | MsgRegenerate
=> (Domain
.resetLocal ();
856 Msg
.send (bio
, MsgOk
))
857 | _
=> (print
"Dispatcher sent unexpected command\n";
858 Msg
.send (bio
, MsgError
"Unexpected command"))
861 ignore (OpenSSL
.readChar bio
);
865 end handle OpenSSL
.OpenSSL s
=>
866 (print ("OpenSSL error: "^ s ^
"\n");
868 handle OpenSSL
.OpenSSL _
=> ();
870 | OS
.SysErr (s
, _
) =>
871 (print ("System error: "^ s ^
"\n");
873 handle OpenSSL
.OpenSSL _
=> ();
877 OpenSSL
.shutdown sock
882 val dir
= Posix
.FileSys
.opendir Config
.libRoot
885 case Posix
.FileSys
.readdir dir
of
886 NONE
=> (Posix
.FileSys
.closedir dir
;
889 if String.isSuffix
".dtl" fname
then
890 loop (OS
.Path
.joinDirFile
{dir
= Config
.libRoot
,
899 fun autodocBasis outdir
=
900 Autodoc
.autodoc
{outdir
= outdir
, infiles
= listBasis ()}