1 (* HCoop
Domtool (http
://hcoop
.sourceforge
.net
/)
2 * Copyright (c
) 2006, Adam Chlipala
4 * This program is free software
; you can redistribute it
and/or
5 * modify it under the terms
of the GNU General Public License
6 * as published by the Free Software Foundation
; either version
2
7 * of the License
, or (at your option
) any later version
.
9 * This program is distributed
in the hope that it will be useful
,
10 * but WITHOUT ANY WARRANTY
; without even the implied warranty
of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE
. See the
12 * GNU General Public License for more details
.
14 * You should have received a copy
of the GNU General Public License
15 * along
with this program
; if not
, write to the Free Software
16 * Foundation
, Inc
., 51 Franklin Street
, Fifth Floor
, Boston
, MA
02110-1301, USA
.
21 structure Main
:> MAIN
= struct
23 open Ast MsgTypes Print
25 structure SM
= StringMap
27 fun init () = Acl
.read Config
.aclFile
31 val prog
= Parse
.parse fname
33 if !ErrorMsg
.anyErrors
then
36 Tycheck
.checkFile
G (Defaults
.tInit ()) prog
41 val dir
= Posix
.FileSys
.opendir Config
.libRoot
44 case Posix
.FileSys
.readdir dir
of
45 NONE
=> (Posix
.FileSys
.closedir dir
;
48 if String.isSuffix
".dtl" fname
then
49 loop (OS
.Path
.joinDirFile
{dir
= Config
.libRoot
,
56 val (_
, files
) = Order
.order NONE files
58 if !ErrorMsg
.anyErrors
then
61 (Tycheck
.allowExterns ();
62 foldl (fn (fname
, G
) => check
' G fname
) Env
.empty files
63 before Tycheck
.disallowExterns ())
68 val _
= ErrorMsg
.reset ()
69 val _
= Env
.preTycheck ()
73 if !ErrorMsg
.anyErrors
then
77 val _
= Tycheck
.disallowExterns ()
78 val _
= ErrorMsg
.reset ()
79 val prog
= Parse
.parse fname
81 if !ErrorMsg
.anyErrors
then
85 val G
' = Tycheck
.checkFile
b (Defaults
.tInit ()) prog
87 if !ErrorMsg
.anyErrors
then
95 val notTmp
= CharVector
.all (fn ch
=> Char.isAlphaNum ch
orelse ch
= #
"." orelse ch
= #
"_" orelse ch
= #
"-")
101 val dir
= Posix
.FileSys
.opendir dname
104 case Posix
.FileSys
.readdir dir
of
105 NONE
=> (Posix
.FileSys
.closedir dir
;
109 loop (OS
.Path
.joinDirFile
{dir
= dname
,
116 val (_
, files
) = Order
.order (SOME b
) files
118 if !ErrorMsg
.anyErrors
then
121 (foldl (fn (fname
, G
) => check
' G fname
) b files
;
122 if !ErrorMsg
.anyErrors
then
130 val (G
, body
) = check fname
132 if !ErrorMsg
.anyErrors
then
138 val body
' = Reduce
.reduceExp G body
140 (*printd (PD
.hovBox (PD
.PPS
.Rel
0,
141 [PD
.string "Result:",
152 if !ErrorMsg
.anyErrors
then
155 Eval
.exec (Defaults
.eInit ()) body
'
156 | NONE
=> raise ErrorMsg
.Error
161 if !ErrorMsg
.anyErrors
then
164 ignore (Eval
.exec
' (Defaults
.eInit ()) body
')
165 | NONE
=> raise ErrorMsg
.Error
168 Config
.dispatcher ^
":" ^
Int.toString Config
.dispatcherPort
171 "localhost:" ^
Int.toString Config
.slavePort
173 fun requestContext f
=
175 val uid
= Posix
.ProcEnv
.getuid ()
176 val user
= Posix
.SysDB
.Passwd
.name (Posix
.SysDB
.getpwuid uid
)
178 val () = Acl
.read Config
.aclFile
179 val () = Domain
.setUser user
183 val context
= OpenSSL
.context (Config
.certDir ^
"/" ^ user ^
".pem",
184 Config
.keyDir ^
"/" ^ user ^
"/key.pem",
192 val (user
, context
) = requestContext f
194 (user
, OpenSSL
.connect (context
, dispatcher
))
197 fun requestSlaveBio () =
199 val (user
, context
) = requestContext (fn () => ())
201 (user
, OpenSSL
.connect (context
, self
))
206 val (user
, bio
) = requestBio (fn () => ignore (check fname
))
208 val inf
= TextIO.openIn fname
211 case TextIO.inputLine inf
of
212 NONE
=> String.concat (List.rev lines
)
213 | SOME line
=> loop (line
:: lines
)
218 Msg
.send (bio
, MsgConfig code
);
220 NONE
=> print
"Server closed connection unexpectedly.\n"
223 MsgOk
=> print
"Configuration succeeded.\n"
224 | MsgError s
=> print ("Configuration failed: " ^ s ^
"\n")
225 | _
=> print
"Unexpected server reply.\n";
228 handle ErrorMsg
.Error
=> ()
230 fun requestDir dname
=
232 val _
= ErrorMsg
.reset ()
234 val (user
, bio
) = requestBio (fn () => checkDir dname
)
238 val dir
= Posix
.FileSys
.opendir dname
241 case Posix
.FileSys
.readdir dir
of
242 NONE
=> (Posix
.FileSys
.closedir dir
;
246 loop (OS
.Path
.joinDirFile
{dir
= dname
,
253 val (_
, files
) = Order
.order (SOME b
) files
255 val _
= if !ErrorMsg
.anyErrors
then
260 val codes
= map (fn fname
=>
262 val inf
= TextIO.openIn fname
265 case TextIO.inputLine inf
of
266 NONE
=> String.concat (rev lines
)
267 | SOME line
=> loop (line
:: lines
)
270 before TextIO.closeIn inf
273 if !ErrorMsg
.anyErrors
then
276 (Msg
.send (bio
, MsgMultiConfig codes
);
278 NONE
=> print
"Server closed connection unexpectedly.\n"
281 MsgOk
=> print
"Configuration succeeded.\n"
282 | MsgError s
=> print ("Configuration failed: " ^ s ^
"\n")
283 | _
=> print
"Unexpected server reply.\n";
286 handle ErrorMsg
.Error
=> ()
290 val (_
, bio
) = requestBio (fn () => ())
295 handle _
=> OS
.Process
.failure
297 fun requestShutdown () =
299 val (_
, bio
) = requestBio (fn () => ())
301 Msg
.send (bio
, MsgShutdown
);
303 NONE
=> print
"Server closed connection unexpectedly.\n"
306 MsgOk
=> print
"Shutdown begun.\n"
307 | MsgError s
=> print ("Shutdown failed: " ^ s ^
"\n")
308 | _
=> print
"Unexpected server reply.\n";
312 fun requestSlavePing () =
314 val (_
, bio
) = requestSlaveBio ()
319 handle _
=> OS
.Process
.failure
321 fun requestSlaveShutdown () =
323 val (_
, bio
) = requestSlaveBio ()
325 Msg
.send (bio
, MsgShutdown
);
327 NONE
=> print
"Server closed connection unexpectedly.\n"
330 MsgOk
=> print
"Shutdown begun.\n"
331 | MsgError s
=> print ("Shutdown failed: " ^ s ^
"\n")
332 | _
=> print
"Unexpected server reply.\n";
336 fun requestGrant acl
=
338 val (user
, bio
) = requestBio (fn () => ())
340 Msg
.send (bio
, MsgGrant acl
);
342 NONE
=> print
"Server closed connection unexpectedly.\n"
345 MsgOk
=> print
"Grant succeeded.\n"
346 | MsgError s
=> print ("Grant failed: " ^ s ^
"\n")
347 | _
=> print
"Unexpected server reply.\n";
351 fun requestRevoke acl
=
353 val (user
, bio
) = requestBio (fn () => ())
355 Msg
.send (bio
, MsgRevoke acl
);
357 NONE
=> print
"Server closed connection unexpectedly.\n"
360 MsgOk
=> print
"Revoke succeeded.\n"
361 | MsgError s
=> print ("Revoke failed: " ^ s ^
"\n")
362 | _
=> print
"Unexpected server reply.\n";
366 fun requestListPerms user
=
368 val (_
, bio
) = requestBio (fn () => ())
370 Msg
.send (bio
, MsgListPerms user
);
371 (case Msg
.recv bio
of
372 NONE
=> (print
"Server closed connection unexpectedly.\n";
376 MsgPerms perms
=> SOME perms
377 | MsgError s
=> (print ("Listing failed: " ^ s ^
"\n");
379 | _
=> (print
"Unexpected server reply.\n";
381 before OpenSSL
.close bio
384 fun requestWhoHas perm
=
386 val (_
, bio
) = requestBio (fn () => ())
388 Msg
.send (bio
, MsgWhoHas perm
);
389 (case Msg
.recv bio
of
390 NONE
=> (print
"Server closed connection unexpectedly.\n";
394 MsgWhoHasResponse users
=> SOME users
395 | MsgError s
=> (print ("whohas failed: " ^ s ^
"\n");
397 | _
=> (print
"Unexpected server reply.\n";
399 before OpenSSL
.close bio
402 fun requestRegen () =
404 val (_
, bio
) = requestBio (fn () => ())
406 Msg
.send (bio
, MsgRegenerate
);
408 NONE
=> print
"Server closed connection unexpectedly.\n"
411 MsgOk
=> print
"Regeneration succeeded.\n"
412 | MsgError s
=> print ("Regeneration failed: " ^ s ^
"\n")
413 | _
=> print
"Unexpected server reply.\n";
417 fun requestRmdom dom
=
419 val (_
, bio
) = requestBio (fn () => ())
421 Msg
.send (bio
, MsgRmdom dom
);
423 NONE
=> print
"Server closed connection unexpectedly.\n"
426 MsgOk
=> print
"Removal succeeded.\n"
427 | MsgError s
=> print ("Removal failed: " ^ s ^
"\n")
428 | _
=> print
"Unexpected server reply.\n";
432 fun requestRmuser user
=
434 val (_
, bio
) = requestBio (fn () => ())
436 Msg
.send (bio
, MsgRmuser user
);
438 NONE
=> print
"Server closed connection unexpectedly.\n"
441 MsgOk
=> print
"Removal succeeded.\n"
442 | MsgError s
=> print ("Removal failed: " ^ s ^
"\n")
443 | _
=> print
"Unexpected server reply.\n";
447 fun requestDbUser dbtype
=
449 val (_
, bio
) = requestBio (fn () => ())
451 Msg
.send (bio
, MsgCreateDbUser dbtype
);
453 NONE
=> print
"Server closed connection unexpectedly.\n"
456 MsgOk
=> print
"Your user has been created.\n"
457 | MsgError s
=> print ("Creation failed: " ^ s ^
"\n")
458 | _
=> print
"Unexpected server reply.\n";
462 fun requestDbPasswd rc
=
464 val (_
, bio
) = requestBio (fn () => ())
466 Msg
.send (bio
, MsgDbPasswd rc
);
468 NONE
=> print
"Server closed connection unexpectedly.\n"
471 MsgOk
=> print
"Your password has been changed.\n"
472 | MsgError s
=> print ("Password set failed: " ^ s ^
"\n")
473 | _
=> print
"Unexpected server reply.\n";
477 fun requestDbTable p
=
479 val (user
, bio
) = requestBio (fn () => ())
481 Msg
.send (bio
, MsgCreateDbTable p
);
483 NONE
=> print
"Server closed connection unexpectedly.\n"
486 MsgOk
=> print ("Your database " ^ user ^
"_" ^ #dbname p ^
" has been created.\n")
487 | MsgError s
=> print ("Creation failed: " ^ s ^
"\n")
488 | _
=> print
"Unexpected server reply.\n";
492 fun requestListMailboxes domain
=
494 val (_
, bio
) = requestBio (fn () => ())
496 Msg
.send (bio
, MsgListMailboxes domain
);
497 (case Msg
.recv bio
of
498 NONE
=> Vmail
.Error
"Server closed connection unexpectedly."
501 MsgMailboxes users
=> (Msg
.send (bio
, MsgOk
);
503 | MsgError s
=> Vmail
.Error ("Creation failed: " ^ s
)
504 | _
=> Vmail
.Error
"Unexpected server reply.")
505 before OpenSSL
.close bio
508 fun requestNewMailbox p
=
510 val (_
, bio
) = requestBio (fn () => ())
512 Msg
.send (bio
, MsgNewMailbox p
);
514 NONE
=> print
"Server closed connection unexpectedly.\n"
517 MsgOk
=> print ("A mapping for " ^ #user p ^
"@" ^ #domain p ^
" has been created.\n")
518 | MsgError s
=> print ("Creation failed: " ^ s ^
"\n")
519 | _
=> print
"Unexpected server reply.\n";
523 fun requestPasswdMailbox p
=
525 val (_
, bio
) = requestBio (fn () => ())
527 Msg
.send (bio
, MsgPasswdMailbox p
);
529 NONE
=> print
"Server closed connection unexpectedly.\n"
532 MsgOk
=> print ("The password for " ^ #user p ^
"@" ^ #domain p ^
" has been changed.\n")
533 | MsgError s
=> print ("Set failed: " ^ s ^
"\n")
534 | _
=> print
"Unexpected server reply.\n";
538 fun requestRmMailbox p
=
540 val (_
, bio
) = requestBio (fn () => ())
542 Msg
.send (bio
, MsgRmMailbox p
);
544 NONE
=> print
"Server closed connection unexpectedly.\n"
547 MsgOk
=> print ("The mapping for mailbox " ^ #user p ^
"@" ^ #domain p ^
" has been deleted.\n")
548 | MsgError s
=> print ("Remove failed: " ^ s ^
"\n")
549 | _
=> print
"Unexpected server reply.\n";
553 fun requestSaQuery addr
=
555 val (_
, bio
) = requestBio (fn () => ())
557 Msg
.send (bio
, MsgSaQuery addr
);
558 (case Msg
.recv bio
of
559 NONE
=> print
"Server closed connection unexpectedly.\n"
562 MsgSaStatus b
=> (print ("SpamAssassin filtering for " ^ addr ^
" is "
563 ^
(if b
then "ON" else "OFF") ^
".\n");
564 Msg
.send (bio
, MsgOk
))
565 | MsgError s
=> print ("Query failed: " ^ s ^
"\n")
566 | _
=> print
"Unexpected server reply.\n")
567 before OpenSSL
.close bio
572 val (_
, bio
) = requestBio (fn () => ())
574 Msg
.send (bio
, MsgSaSet p
);
576 NONE
=> print
"Server closed connection unexpectedly.\n"
579 MsgOk
=> print ("SpamAssassin filtering for " ^ #
1 p ^
" is now "
580 ^
(if #
2 p
then "ON" else "OFF") ^
".\n")
581 | MsgError s
=> print ("Set failed: " ^ s ^
"\n")
582 | _
=> print
"Unexpected server reply.\n";
586 fun requestSmtpLog domain
=
588 val (_
, bio
) = requestBio (fn () => ())
590 val _
= Msg
.send (bio
, MsgSmtpLogReq domain
)
594 NONE
=> print
"Server closed connection unexpectedly.\n"
598 | MsgSmtpLogRes line
=> (print line
;
600 | MsgError s
=> print ("Log search failed: " ^ s ^
"\n")
601 | _
=> print
"Unexpected server reply.\n"
607 fun requestApt
{node
, pkg
} =
609 val (user
, context
) = requestContext (fn () => ())
610 val bio
= OpenSSL
.connect (context
, if node
= Config
.masterNode
then
613 Domain
.nodeIp node ^
":" ^
Int.toString Config
.slavePort
)
615 val _
= Msg
.send (bio
, MsgQuery (QApt pkg
))
619 NONE
=> (print
"Server closed connection unexpectedly.\n";
623 MsgYes
=> (print
"Package is installed.\n";
625 | MsgNo
=> (print
"Package is not installed.\n";
627 | MsgError s
=> (print ("APT query failed: " ^ s ^
"\n");
629 | _
=> (print
"Unexpected server reply.\n";
633 before OpenSSL
.close bio
636 fun requestCron
{node
, uname
} =
638 val (user
, context
) = requestContext (fn () => ())
639 val bio
= OpenSSL
.connect (context
, if node
= Config
.masterNode
then
642 Domain
.nodeIp node ^
":" ^
Int.toString Config
.slavePort
)
644 val _
= Msg
.send (bio
, MsgQuery (QCron uname
))
648 NONE
=> (print
"Server closed connection unexpectedly.\n";
652 MsgYes
=> (print
"User has cron permissions.\n";
654 | MsgNo
=> (print
"User does not have cron permissions.\n";
656 | MsgError s
=> (print ("Cron query failed: " ^ s ^
"\n");
658 | _
=> (print
"Unexpected server reply.\n";
662 before OpenSSL
.close bio
665 fun requestFtp
{node
, uname
} =
667 val (user
, context
) = requestContext (fn () => ())
668 val bio
= OpenSSL
.connect (context
, if node
= Config
.masterNode
then
671 Domain
.nodeIp node ^
":" ^
Int.toString Config
.slavePort
)
673 val _
= Msg
.send (bio
, MsgQuery (QFtp uname
))
677 NONE
=> (print
"Server closed connection unexpectedly.\n";
681 MsgYes
=> (print
"User has FTP permissions.\n";
683 | MsgNo
=> (print
"User does not have FTP permissions.\n";
685 | MsgError s
=> (print ("FTP query failed: " ^ s ^
"\n");
687 | _
=> (print
"Unexpected server reply.\n";
691 before OpenSSL
.close bio
694 fun requestTrustedPath
{node
, uname
} =
696 val (user
, context
) = requestContext (fn () => ())
697 val bio
= OpenSSL
.connect (context
, if node
= Config
.masterNode
then
700 Domain
.nodeIp node ^
":" ^
Int.toString Config
.slavePort
)
702 val _
= Msg
.send (bio
, MsgQuery (QTrustedPath uname
))
706 NONE
=> (print
"Server closed connection unexpectedly.\n";
710 MsgYes
=> (print
"User has trusted path restriction.\n";
712 | MsgNo
=> (print
"User does not have trusted path restriction.\n";
714 | MsgError s
=> (print ("Trusted path query failed: " ^ s ^
"\n");
716 | _
=> (print
"Unexpected server reply.\n";
720 before OpenSSL
.close bio
723 fun requestSocketPerm
{node
, uname
} =
725 val (user
, context
) = requestContext (fn () => ())
726 val bio
= OpenSSL
.connect (context
, if node
= Config
.masterNode
then
729 Domain
.nodeIp node ^
":" ^
Int.toString Config
.slavePort
)
731 val _
= Msg
.send (bio
, MsgQuery (QSocket uname
))
735 NONE
=> (print
"Server closed connection unexpectedly.\n";
739 MsgSocket p
=> (case p
of
741 | Client
=> print
"Client\n"
742 | Server
=> print
"Server\n"
743 | Nada
=> print
"Nada\n";
745 | MsgError s
=> (print ("Socket permission query failed: " ^ s ^
"\n");
747 | _
=> (print
"Unexpected server reply.\n";
751 before OpenSSL
.close bio
754 fun requestFirewall
{node
, uname
} =
756 val (user
, context
) = requestContext (fn () => ())
757 val bio
= OpenSSL
.connect (context
, if node
= Config
.masterNode
then
760 Domain
.nodeIp node ^
":" ^
Int.toString Config
.slavePort
)
762 val _
= Msg
.send (bio
, MsgQuery (QFirewall uname
))
766 NONE
=> (print
"Server closed connection unexpectedly.\n";
770 MsgFirewall ls
=> (app (fn s
=> (print s
; print
"\n")) ls
;
772 | MsgError s
=> (print ("Firewall query failed: " ^ s ^
"\n");
774 | _
=> (print
"Unexpected server reply.\n";
778 before OpenSSL
.close bio
781 fun regenerate context
=
784 val () = Tycheck
.disallowExterns ()
786 val () = Domain
.resetGlobal ()
788 fun contactNode (node
, ip
) =
789 if node
= Config
.defaultNode
then
792 val bio
= OpenSSL
.connect (context
,
795 ^
Int.toString Config
.slavePort
)
797 Msg
.send (bio
, MsgRegenerate
);
799 NONE
=> print
"Slave closed connection unexpectedly\n"
802 MsgOk
=> print ("Slave " ^ node ^
" pre-regeneration finished\n")
803 | MsgError s
=> print ("Slave " ^ node
804 ^
" returned error: " ^
806 | _
=> print ("Slave " ^ node
807 ^
" returned unexpected command\n");
813 val _
= Domain
.setUser user
814 val _
= ErrorMsg
.reset ()
816 val dname
= Config
.domtoolDir user
818 val dir
= Posix
.FileSys
.opendir dname
821 case Posix
.FileSys
.readdir dir
of
822 NONE
=> (Posix
.FileSys
.closedir dir
;
826 loop (OS
.Path
.joinDirFile
{dir
= dname
,
833 val (_
, files
) = Order
.order (SOME b
) files
835 if !ErrorMsg
.anyErrors
then
836 print ("User " ^ user ^
"'s configuration has errors!\n")
841 | OS
.SysErr (s
, _
) => print ("System error processing user " ^ user ^
": " ^ s ^
"\n")
842 | ErrorMsg
.Error
=> print ("User " ^ user ^
" had a compilation error.\n")
844 app contactNode Config
.nodeIps
;
846 app
doUser (Acl
.users ());
852 val doms
= Acl
.class
{user
= user
, class
= "domain"}
853 val doms
= List.filter (fn dom
=>
854 case Acl
.whoHas
{class
= "domain", value
= dom
} of
856 | _
=> false) (StringSet
.listItems doms
)
862 fun now () = Date
.toString (Date
.fromTimeUniv (Time
.now ()))
866 QApt pkg
=> if Apt
.installed pkg
then MsgYes
else MsgNo
867 | QCron user
=> if Cron
.allowed user
then MsgYes
else MsgNo
868 | QFtp user
=> if Ftp
.allowed user
then MsgYes
else MsgNo
869 | QTrustedPath user
=> if TrustedPath
.query user
then MsgYes
else MsgNo
870 | QSocket user
=> MsgSocket (SocketPerm
.query user
)
871 | QFirewall user
=> MsgFirewall (Firewall
.query user
)
873 fun describeQuery q
=
875 QApt pkg
=> "Requested installation status of package " ^ pkg
876 | QCron user
=> "Asked about cron permissions for user " ^ user
877 | QFtp user
=> "Asked about FTP permissions for user " ^ user
878 | QTrustedPath user
=> "Asked about trusted path settings for user " ^ user
879 | QSocket user
=> "Asked about socket permissions for user " ^ user
880 | QFirewall user
=> "Asked about firewall rules for user " ^ user
884 val () = Acl
.read Config
.aclFile
886 val context
= OpenSSL
.context (Config
.serverCert
,
889 val _
= Domain
.set_context context
891 val sock
= OpenSSL
.listen (context
, Config
.dispatcherPort
)
894 case OpenSSL
.accept sock
of
898 val user
= OpenSSL
.peerCN bio
899 val () = print ("\nConnection from " ^ user ^
" at " ^
now () ^
"\n")
900 val () = Domain
.setUser user
904 (msgLocal
, SOME msgRemote
) =>
907 Msg
.send (bio
, MsgError msgRemote
))
908 |
(msgLocal
, NONE
) =>
911 Msg
.send (bio
, MsgOk
)))
912 handle OpenSSL
.OpenSSL _
=>
913 print
"OpenSSL error\n"
914 | OS
.SysErr (s
, _
) =>
915 (print
"System error: ";
918 Msg
.send (bio
, MsgError ("System error: " ^ s
))
919 handle OpenSSL
.OpenSSL _
=> ())
924 Msg
.send (bio
, MsgError ("Failure: " ^ s
))
925 handle OpenSSL
.OpenSSL _
=> ())
927 (print
"Compilation error\n";
928 Msg
.send (bio
, MsgError
"Error during configuration evaluation")
929 handle OpenSSL
.OpenSSL _
=> ());
931 ignore (OpenSSL
.readChar bio
);
933 handle OpenSSL
.OpenSSL _
=> ();
938 val _
= print
"Configuration:\n"
939 val _
= app (fn s
=> (print s
; print
"\n")) codes
942 val outname
= OS
.FileSys
.tmpName ()
946 val outf
= TextIO.openOut outname
948 TextIO.output (outf
, code
);
949 TextIO.closeOut outf
;
953 doIt (fn () => (Env
.pre ();
956 Msg
.send (bio
, MsgOk
);
957 ("Configuration complete.", NONE
)))
958 (fn () => OS
.FileSys
.remove outname
)
962 case String.fields (fn ch
=> ch
= #
"@") s
of
969 if Domain
.validEmailUser user
' andalso Domain
.yourDomain domain
then
977 NONE
=> (OpenSSL
.close bio
978 handle OpenSSL
.OpenSSL _
=> ();
982 MsgConfig code
=> doConfig
[code
]
983 | MsgMultiConfig codes
=> doConfig codes
986 if Acl
.query
{user
= user
, class
= "priv", value
= "all"}
987 orelse Acl
.query
{user
= user
, class
= "priv", value
= "shutdown"} then
988 print ("Domtool dispatcher shutting down at " ^
now () ^
"\n\n")
990 (print
"Unauthorized shutdown command!\n";
992 handle OpenSSL
.OpenSSL _
=> ();
997 if Acl
.query
{user
= user
, class
= "priv", value
= "all"} then
999 Acl
.write Config
.aclFile
;
1000 ("Granted permission " ^ #value acl ^
" to " ^ #user acl ^
" in " ^ #class acl ^
".",
1003 ("Unauthorized user asked to grant a permission!",
1004 SOME
"Not authorized to grant privileges"))
1009 if Acl
.query
{user
= user
, class
= "priv", value
= "all"} then
1011 Acl
.write Config
.aclFile
;
1012 ("Revoked permission " ^ #value acl ^
" from " ^ #user acl ^
" in " ^ #class acl ^
".",
1015 ("Unauthorized user asked to revoke a permission!",
1016 SOME
"Not authorized to revoke privileges"))
1019 | MsgListPerms user
=>
1021 (Msg
.send (bio
, MsgPerms (Acl
.queryAll user
));
1022 ("Sent permission list for user " ^ user ^
".",
1028 (Msg
.send (bio
, MsgWhoHasResponse (Acl
.whoHas perm
));
1029 ("Sent whohas response for " ^ #class perm ^
" / " ^ #value perm ^
".",
1035 if Acl
.query
{user
= user
, class
= "priv", value
= "all"}
1036 orelse List.all (fn dom
=> Acl
.query
{user
= user
, class
= "domain", value
= dom
}) doms
then
1039 Acl
.revokeFromAll
{class
= "domain", value
= dom
}) doms
;
1040 Acl
.write Config
.aclFile
;
1041 ("Removed domains" ^
foldl (fn (d
, s
) => s ^
" " ^ d
) "" doms ^
".",
1044 ("Unauthorized user asked to remove a domain!",
1045 SOME
"Not authorized to remove that domain"))
1050 if Acl
.query
{user
= user
, class
= "priv", value
= "regen"}
1051 orelse Acl
.query
{user
= user
, class
= "priv", value
= "all"} then
1052 (regenerate context
;
1053 ("Regenerated all configuration.",
1056 ("Unauthorized user asked to regenerate!",
1057 SOME
"Not authorized to regenerate"))
1060 | MsgRmuser user
' =>
1062 if Acl
.query
{user
= user
, class
= "priv", value
= "all"} then
1064 Acl
.write Config
.aclFile
;
1065 ("Removed user " ^ user
' ^
".",
1068 ("Unauthorized user asked to remove a user!",
1069 SOME
"Not authorized to remove users"))
1072 | MsgCreateDbUser
{dbtype
, passwd
} =>
1074 case Dbms
.lookup dbtype
of
1075 NONE
=> ("Database user creation request with unknown datatype type " ^ dbtype
,
1076 SOME ("Unknown database type " ^ dbtype
))
1078 case #adduser handler
{user
= user
, passwd
= passwd
} of
1079 NONE
=> ("Added " ^ dbtype ^
" user " ^ user ^
".",
1082 ("Error adding a " ^ dbtype ^
" user " ^ user ^
": " ^ msg
,
1083 SOME ("Error adding user: " ^ msg
)))
1086 | MsgDbPasswd
{dbtype
, passwd
} =>
1088 case Dbms
.lookup dbtype
of
1089 NONE
=> ("Database passwd request with unknown datatype type " ^ dbtype
,
1090 SOME ("Unknown database type " ^ dbtype
))
1092 case #passwd handler
{user
= user
, passwd
= passwd
} of
1093 NONE
=> ("Changed " ^ dbtype ^
" password of user " ^ user ^
".",
1096 ("Error setting " ^ dbtype ^
" password of user " ^ user ^
": " ^ msg
,
1097 SOME ("Error adding user: " ^ msg
)))
1100 | MsgCreateDbTable
{dbtype
, dbname
} =>
1102 if Dbms
.validDbname dbname
then
1103 case Dbms
.lookup dbtype
of
1104 NONE
=> ("Database creation request with unknown datatype type " ^ dbtype
,
1105 SOME ("Unknown database type " ^ dbtype
))
1107 case #createdb handler
{user
= user
, dbname
= dbname
} of
1108 NONE
=> ("Created database " ^ user ^
"_" ^ dbname ^
".",
1110 | SOME msg
=> ("Error creating database " ^ user ^
"_" ^ dbname ^
": " ^ msg
,
1111 SOME ("Error creating database: " ^ msg
))
1113 ("Invalid database name " ^ user ^
"_" ^ dbname
,
1114 SOME ("Invalid database name " ^ dbname
)))
1117 | MsgListMailboxes domain
=>
1119 if not (Domain
.yourDomain domain
) then
1120 ("User wasn't authorized to list mailboxes for " ^ domain
,
1121 SOME
"You're not authorized to configure that domain.")
1123 case Vmail
.list domain
of
1124 Vmail
.Listing users
=> (Msg
.send (bio
, MsgMailboxes users
);
1125 ("Sent mailbox list for " ^ domain
,
1127 | Vmail
.Error msg
=> ("Error listing mailboxes for " ^ domain ^
": " ^ msg
,
1131 | MsgNewMailbox
{domain
, user
= emailUser
, passwd
, mailbox
} =>
1133 if not (Domain
.yourDomain domain
) then
1134 ("User wasn't authorized to add a mailbox to " ^ domain
,
1135 SOME
"You're not authorized to configure that domain.")
1136 else if not (Domain
.validEmailUser emailUser
) then
1137 ("Invalid e-mail username " ^ emailUser
,
1138 SOME
"Invalid e-mail username")
1139 else if not (CharVector
.all
Char.isGraph passwd
) then
1140 ("Invalid password",
1141 SOME
"Invalid password; may only contain printable, non-space characters")
1142 else if not (Domain
.yourPath mailbox
) then
1143 ("User wasn't authorized to add a mailbox at " ^ mailbox
,
1144 SOME
"You're not authorized to use that mailbox location.")
1146 case Vmail
.add
{requester
= user
,
1147 domain
= domain
, user
= emailUser
,
1148 passwd
= passwd
, mailbox
= mailbox
} of
1149 NONE
=> ("Added mailbox " ^ emailUser ^
"@" ^ domain ^
" at " ^ mailbox
,
1151 | SOME msg
=> ("Error adding mailbox " ^ emailUser ^
"@" ^ domain ^
": " ^ msg
,
1155 | MsgPasswdMailbox
{domain
, user
= emailUser
, passwd
} =>
1157 if not (Domain
.yourDomain domain
) then
1158 ("User wasn't authorized to change password of a mailbox for " ^ domain
,
1159 SOME
"You're not authorized to configure that domain.")
1160 else if not (Domain
.validEmailUser emailUser
) then
1161 ("Invalid e-mail username " ^ emailUser
,
1162 SOME
"Invalid e-mail username")
1163 else if not (CharVector
.all
Char.isGraph passwd
) then
1164 ("Invalid password",
1165 SOME
"Invalid password; may only contain printable, non-space characters")
1167 case Vmail
.passwd
{domain
= domain
, user
= emailUser
,
1169 NONE
=> ("Changed password of mailbox " ^ emailUser ^
"@" ^ domain
,
1171 | SOME msg
=> ("Error changing mailbox password for " ^ emailUser ^
"@" ^ domain ^
": " ^ msg
,
1175 | MsgRmMailbox
{domain
, user
= emailUser
} =>
1177 if not (Domain
.yourDomain domain
) then
1178 ("User wasn't authorized to change password of a mailbox for " ^ domain
,
1179 SOME
"You're not authorized to configure that domain.")
1180 else if not (Domain
.validEmailUser emailUser
) then
1181 ("Invalid e-mail username " ^ emailUser
,
1182 SOME
"Invalid e-mail username")
1184 case Vmail
.rm
{domain
= domain
, user
= emailUser
} of
1185 NONE
=> ("Deleted mailbox " ^ emailUser ^
"@" ^ domain
,
1187 | SOME msg
=> ("Error deleting mailbox " ^ emailUser ^
"@" ^ domain ^
": " ^ msg
,
1191 | MsgSaQuery addr
=>
1193 case checkAddr addr
of
1194 NONE
=> ("User tried to query SA filtering for " ^ addr
,
1195 SOME
"You aren't allowed to configure SA filtering for that recipient.")
1196 | SOME addr
' => (Msg
.send (bio
, MsgSaStatus (SetSA
.query addr
'));
1197 ("Queried SA filtering status for " ^ addr
,
1201 |
MsgSaSet (addr
, b
) =>
1203 case checkAddr addr
of
1204 NONE
=> ("User tried to set SA filtering for " ^ addr
,
1205 SOME
"You aren't allowed to configure SA filtering for that recipient.")
1206 | SOME addr
' => (SetSA
.set (addr
', b
);
1207 Msg
.send (bio
, MsgOk
);
1208 ("Set SA filtering status for " ^ addr ^
" to "
1209 ^
(if b
then "ON" else "OFF"),
1213 | MsgSmtpLogReq domain
=>
1215 if not (Domain
.yourDomain domain
) then
1216 ("Unauthorized user tried to request SMTP logs for " ^ domain
,
1217 SOME
"You aren't authorized to configure that domain.")
1219 (SmtpLog
.search (fn line
=> Msg
.send (bio
, MsgSmtpLogRes line
))
1221 ("Requested SMTP logs for " ^ domain
,
1226 doIt (fn () => (Msg
.send (bio
, answerQuery q
);
1232 doIt (fn () => ("Unexpected command",
1233 SOME
"Unexpected command"))
1238 handle OpenSSL
.OpenSSL s
=>
1239 (print ("OpenSSL error: " ^ s ^
"\n");
1241 handle OpenSSL
.OpenSSL _
=> ();
1243 | OS
.SysErr (s
, _
) =>
1244 (print ("System error: " ^ s ^
"\n");
1246 handle OpenSSL
.OpenSSL _
=> ();
1249 print ("Domtool dispatcher starting up at " ^
now () ^
"\n");
1250 print
"Listening for connections....\n";
1252 OpenSSL
.shutdown sock
1257 val host
= Slave
.hostname ()
1259 val context
= OpenSSL
.context (Config
.certDir ^
"/" ^ host ^
".pem",
1260 Config
.keyDir ^
"/" ^ host ^
"/key.pem",
1263 val sock
= OpenSSL
.listen (context
, Config
.slavePort
)
1265 val _
= print ("Slave server starting at " ^
now () ^
"\n")
1268 case OpenSSL
.accept sock
of
1272 val peer
= OpenSSL
.peerCN bio
1273 val () = print ("\nConnection from " ^ peer ^
" at " ^
now () ^
"\n")
1275 if peer
= Config
.dispatcherName
then let
1277 case Msg
.recv bio
of
1278 NONE
=> print
"Dispatcher closed connection unexpectedly\n"
1281 MsgFile file
=> loop
' (file
:: files
)
1282 | MsgDoFiles
=> (Slave
.handleChanges files
;
1283 Msg
.send (bio
, MsgOk
))
1284 | MsgRegenerate
=> (Domain
.resetLocal ();
1285 Msg
.send (bio
, MsgOk
))
1286 | _
=> (print
"Dispatcher sent unexpected command\n";
1287 Msg
.send (bio
, MsgError
"Unexpected command"))
1290 ignore (OpenSSL
.readChar bio
);
1294 else if peer
= "domtool" then
1295 case Msg
.recv bio
of
1296 SOME MsgShutdown
=> (OpenSSL
.close bio
;
1297 print ("Shutting down at " ^
now () ^
"\n\n"))
1298 | _
=> (OpenSSL
.close bio
;
1301 case Msg
.recv bio
of
1302 SOME (MsgQuery q
) => (print (describeQuery q ^
"\n");
1303 Msg
.send (bio
, answerQuery q
);
1304 ignore (OpenSSL
.readChar bio
);
1307 | _
=> (OpenSSL
.close bio
;
1309 end handle OpenSSL
.OpenSSL s
=>
1310 (print ("OpenSSL error: "^ s ^
"\n");
1312 handle OpenSSL
.OpenSSL _
=> ();
1314 | OS
.SysErr (s
, _
) =>
1315 (print ("System error: "^ s ^
"\n");
1317 handle OpenSSL
.OpenSSL _
=> ();
1321 OpenSSL
.shutdown sock
1326 val dir
= Posix
.FileSys
.opendir Config
.libRoot
1329 case Posix
.FileSys
.readdir dir
of
1330 NONE
=> (Posix
.FileSys
.closedir dir
;
1333 if String.isSuffix
".dtl" fname
then
1334 loop (OS
.Path
.joinDirFile
{dir
= Config
.libRoot
,
1343 fun autodocBasis outdir
=
1344 Autodoc
.autodoc
{outdir
= outdir
, infiles
= listBasis ()}