val usr = ref ""
fun getUser () = !usr
+val fakePrivs = ref false
+val isClient = ref false
val your_doms = ref SS.empty
fun your_domains () = !your_doms
val your_pths = ref SS.empty
fun your_paths () = !your_pths
+val your_ipss = ref SS.empty
+fun your_ips () = !your_ipss
+
val world_readable = SS.addList (SS.empty, Config.worldReadable)
val readable_pths = ref world_readable
fun readable_paths () = !readable_pths
val your_paths = Acl.class {user = getUser (),
class = "path"}
in
+ fakePrivs := false;
your_doms := Acl.class {user = getUser (),
class = "domain"};
your_usrs := Acl.class {user = getUser (),
your_grps := Acl.class {user = getUser (),
class = "group"};
your_pths := your_paths;
- readable_pths := SS.union (your_paths, world_readable)
+ readable_pths := SS.union (your_paths, world_readable);
+ your_ipss := Acl.class {user = getUser (),
+ class = "ip"}
end
+fun declareClient () = isClient := true
+fun fakePrivileges () = if !isClient then
+ fakePrivs := true
+ else
+ raise Fail "Tried to fake privileges as non-client"
+
fun validIp s =
case map Int.fromString (String.fields (fn ch => ch = #".") s) of
[SOME n1, SOME n2, SOME n3, SOME n4] =>
n1 >= 0 andalso n1 < 256 andalso n2 >= 0 andalso n2 < 256 andalso n3 >= 0 andalso n3 < 256 andalso n4 >= 0 andalso n4 < 256
| _ => false
+fun isHexDigit ch = Char.isDigit ch orelse (ord ch >= ord #"a" andalso ord ch <= ord #"f")
+
+fun validIpv6 s =
+ let
+ val fields = String.fields (fn ch => ch = #":") s
+
+ val empties = foldl (fn ("", n) => n + 1
+ | (_, n) => n) 0 fields
+
+ fun noIpv4 maxLen =
+ length fields >= 2
+ andalso length fields <= maxLen
+ andalso empties <= 1
+ andalso List.all (fn "" => true
+ | s => size s <= 4
+ andalso CharVector.all isHexDigit s) fields
+
+ fun hasIpv4 () =
+ length fields > 0
+ andalso
+ let
+ val maybeIpv4 = List.last fields
+ val theRest = List.take (fields, length fields - 1)
+ in
+ validIp maybeIpv4 andalso noIpv4 6
+ end
+ in
+ noIpv4 8 orelse hasIpv4 ()
+ end
+
fun isIdent ch = Char.isLower ch orelse Char.isDigit ch
fun validHost s =
- size s > 0 andalso size s < 20
+ size s > 0 andalso size s < 50
andalso CharVector.all (fn ch => isIdent ch orelse ch = #"-") s
fun validDomain s =
- size s > 0 andalso size s < 100
+ size s > 0 andalso size s < 200
andalso List.all validHost (String.fields (fn ch => ch = #".") s)
fun validNode s = List.exists (fn s' => s = s') nodes
-fun yourDomain s = SS.member (your_domains (), s)
+fun yourDomain s = !fakePrivs orelse SS.member (your_domains (), s)
fun yourUser s = SS.member (your_users (), s)
fun yourGroup s = SS.member (your_groups (), s)
fun checkPath paths path =
- List.all (fn s => s <> "..") (String.fields (fn ch => ch = #"/") path)
- andalso CharVector.all (fn ch => Char.isAlphaNum ch orelse ch = #"." orelse ch = #"/"
- orelse ch = #"-" orelse ch = #"_") path
- andalso SS.exists (fn s' => path = s' orelse String.isPrefix (s' ^ "/") path) (paths ())
+ (List.all (fn s => s <> "..") (String.fields (fn ch => ch = #"/") path)
+ andalso CharVector.all (fn ch => Char.isAlphaNum ch orelse ch = #"." orelse ch = #"/"
+ orelse ch = #"-" orelse ch = #"_") path
+ andalso SS.exists (fn s' => path = s' orelse String.isPrefix (s' ^ "/") path) (paths ()))
val yourPath = checkPath your_paths
val readablePath = checkPath readable_paths
+fun yourIp s = !fakePrivs orelse SS.member (your_ips (), s)
fun yourDomainHost s =
- yourDomain s
+ !fakePrivs
+ orelse yourDomain s
orelse let
val (pref, suf) = Substring.splitl (fn ch => ch <> #".") (Substring.full s)
in
val _ = Env.type_one "no_newlines"
Env.string
(CharVector.all (fn ch => Char.isPrint ch andalso ch <> #"\n" andalso ch <> #"\r"
- andalso ch <> #"\"" andalso ch <> #"'"))
+ andalso ch <> #"\""))
val _ = Env.type_one "ip"
Env.string
validIp
+val _ = Env.type_one "ipv6"
+ Env.string
+ validIpv6
+
val _ = Env.type_one "host"
Env.string
validHost
Env.string
readablePath
+val _ = Env.type_one "your_ip"
+ Env.string
+ yourIp
+
val _ = Env.type_one "node"
Env.string
validNode
+val _ = Env.type_one "mime_type"
+ Env.string
+ (CharVector.exists (fn ch => ch = #"/"))
+
+val _ = Env.registerFunction ("your_ip_to_ip",
+ fn [e] => SOME e
+ | _ => NONE)
+
val _ = Env.registerFunction ("dns_node_to_node",
fn [e] => SOME e
| _ => NONE)
val _ = Env.registerFunction ("mail_node_to_node",
fn [e] => SOME e
| _ => NONE)
+
+
open Ast
val dl = ErrorMsg.dummyLoc
+val _ = Env.registerFunction ("end_in_slash",
+ fn [(EString "", _)] => SOME (EString "/", dl)
+ | [(EString s, _)] =>
+ SOME (EString (if String.sub (s, size s - 1) = #"/" then
+ s
+ else
+ s ^ "/"), dl)
+ | _ => NONE)
+
+
val nsD = (EString Config.defaultNs, dl)
val serialD = (EVar "serialAuto", dl)
val refD = (EInt Config.defaultRefresh, dl)
fun saveSoa (kind, soa : soa) node =
let
- val {write, writeDom, close} = domainsFile {node = node, name = "soa"}
+ val {write, writeDom, close} = domainsFile {node = node, name = "soa.conf"}
in
write kind;
write "\n";
write "\t};\n")
| _ => (write "\tmasters { ";
write masterIp;
- write "; };\n");
+ write "; };\n";
+ write "// Updated: ";
+ write (Time.toString (Time.now ()));
+ write "\n");
write "};\n";
close ()
end
if site = Config.defaultNode then
Slave.handleChanges files
else let
- val bio = OpenSSL.connect (valOf (!ssl_context),
- nodeIp site
- ^ ":"
- ^ Int.toString Config.slavePort)
+ val bio = OpenSSL.connect true (valOf (!ssl_context),
+ nodeIp site
+ ^ ":"
+ ^ Int.toString Config.slavePort)
in
app (fn file => Msg.send (bio, MsgFile file)) files;
Msg.send (bio, MsgDoFiles);
case d of
Filename {filename, heading, showEmpty} =>
if fname = filename then
- entries := readFile showEmpty ("\n" :: line :: ":\n" :: heading :: line :: !entries)
+ entries := readFile showEmpty ("\n" :: line :: "\n" :: heading :: line :: !entries)
else
()
| Extension {extension, heading} =>
NONE => ()
| SOME extension' =>
if extension' = extension then
- entries := readFile true ("\n" :: line :: ":\n" :: heading base :: line :: !entries)
+ entries := readFile true ("\n" :: line :: "\n" :: heading base :: line :: !entries)
else
()
end
""
end
-val () = registerDescriber (considerAll [Filename {filename = "soa",
- heading = "DNS SOA",
+val () = registerDescriber (considerAll [Filename {filename = "soa.conf",
+ heading = "DNS SOA:",
showEmpty = false}])
val () = Env.registerAction ("domainHost",
(EString (host ^ "." ^ currentDomain ()), dl))
| (_, args) => Env.badArgs ("domainHost", args))
+val ouc = ref (fn () => ())
+
+fun registerOnUsersChange f =
+ let
+ val f' = !ouc
+ in
+ ouc := (fn () => (f' (); f ()))
+ end
+
+fun onUsersChange () = !ouc ()
+
end