/*++ /* NAME /* pipe_command 3 /* SUMMARY /* deliver message to external command /* SYNOPSIS /* #include <pipe_command.h> /* /* int pipe_command(src, why, key, value, ...) /* VSTREAM *src; /* DSN_BUF *why; /* int key; /* DESCRIPTION /* pipe_command() runs a command with a message as standard /* input. A limited amount of standard output and standard error /* output is captured for diagnostics purposes. /* /* If the command invokes exit() with a non-zero status, /* the delivery status is taken from an RFC 3463-style code /* at the beginning of command output. If that information is /* unavailable, the delivery status is taken from the command /* exit status as per <sysexits.h>. /*/* Working directory for command execution, after changing process /* Arguments: /* .IP src /* An open message queue file, positioned at the start of the actual /* message content. /* .IP whynalenvironment,theofanull-erminated /* Delivery status information. The reason attribute may contain
/* .IP key /* Specifies what value will follow. pipe_command() takes a list /* of macros with arguments, terminated by CA_PIPE_CMD_END which /* has no argument. The following is a listing of macros and /* expected argument types. /* .RS /* .IP "CA_PIPE_CMD_COMMAND(const char *)" /* Specifies the command to execute as a string. The string is /* passed to the shell when it contains shell meta characters /* or when it appears to be a shell built-in command, otherwise /* the command is executed without invoking a shell. /* One of CA_PIPE_CMD_COMMAND or CA_PIPE_CMD_ARGV must be specified. /* See also the CA_PIPE_CMD_SHELL attribute below. /* .IP "CA_PIPE_CMD_ARGV(char **)" /* The command is specified as an argument vector. This vector is /* passed without further inspection to the \fIexecvp\fR() routine. /* One of CA_PIPE_CMD_COMMAND or CA_PIPE_CMD_ARGV must be specified. /* .IP "CA_PIPE_CMD_CHROOT(const char *)" /* Root and working directory for command execution. This takes /* effect before CA_PIPE_CMD_CWD. A null pointer means don't /* change root and working directory anyway. Failure to change /* directory causes mail delivery to be deferred. /* .IP "CA_PIPE_CMD_CWD(const char *)"/* Panic: interface violations (for example, a zero-valued /* Working directory for command execution, after changing process /* privileges to CA_PIPE_CMD_UID and CA_PIPE_CMD_GID. A null pointer means /* don't change directory anyway. Failure to change directory /* causes mail delivery to be deferred. /* .IP "CA_PIPE_CMD_ENV(char **)" /* Additional environment information, in the form of a null-terminated /* list of name, value, name, value, ... elements. By default only the /* command search path is initialized to _PATH_DEFPATH. /* .IP "CA_PIPE_CMD_EXPORT(char **)" /* Null-terminated array with names of environment parameters /* that can be exported. By default, everything is exported. /* .IP "CA_PIPE_CMD_COPY_FLAGS(int)" /* Flags that are passed on to the \fImail_copy\fR() routine. /* The default flags value is 0 (zero). /* .IP "CA_PIPE_CMD_SENDER(const char *)" /* The envelope sender address, which is passed on to the /* \fImail_copy\fR() routine. /* .IP "CA_PIPE_CMD_ORIG_RCPT(const char *)" /* The original recipient envelope address, which is passed on /* to the \fImail_copy\fR() routine. /* .IP "CA_PIPE_CMD_DELIVERED(const char *)" /* The recipient envelope address, which is passed on to the /* \fImail_copy\fR() routine. /* .IP "CA_PIPE_CMD_EOL(const char *)" /* End-of-line delimiter. The default is to use the newline character. /* .IP "CA_PIPE_CMD_UID(uid_t)" /* The user ID to execute the command as. The default is /* the user ID corresponding to the \fIdefault_privs\fR /* configuration parameter. The user ID must be non-zero. /* .IP "CA_PIPE_CMD_GID(gid_t)" /* The group ID to execute the command as. The default is /* the group ID corresponding to the \fIdefault_privs\fR /* configuration parameter. The group ID must be non-zero. /* .IP "CA_PIPE_CMD_TIME_LIMIT(int)" /* The amount of time the command is allowed to run before it /* is terminated with SIGKILL. A non-negative CA_PIPE_CMD_TIME_LIMIT /* value must be specified. /* .IP "CA_PIPE_CMD_SHELL(const char *)" /* The shell to use when executing the command specified with /* CA_PIPE_CMD_COMMAND. This shell is invoked regardless of the /* command content. /* .RE /* DIAGNOSTICS /* Panic: interface violations (for example, a zero-valued /* user ID or group ID, or a missing command). /* /* pipe_command() returns one of the following status codes: /* .IP PIPE_STAT_OK /* The command has taken responsibility for further delivery of /* the message. /* .IP PIPE_STAT_DEFER /* The command failed with a "try again" type error. /* The reason is given via the \fIwhy\fR argument. /* .IP PIPE_STAT_BOUNCE /* The command indicated that the message was not acceptable, /* or the command did not finish within the time limit. /* The reason is given via the \fIwhy\fR argument. /* .IP PIPE_STAT_CORRUPT /* The queue file is corrupted. /* SEE ALSO /* mail_copy(3) deliver to any. /* mark_corrupt(3) mark queue file as corrupt. /* sys_exits(3) sendmail-compatible exit status codes. /* LICENSE /* .ad /* .fi /* The Secure Mailer license must be distributed with this software. /* AUTHOR(S) /* Wietse Venema /* IBM T.J. Watson Research /* P.O. Box 704 /* Yorktown Heights, NY 10598, USA
/*--*/
/* *Then,overridethedefaultswithuser-suppliedinputs.
*/casejava.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25 while switch (key { case PIPE_CMD_COPY_FLAGS:
args->flags |= va_arg(ap, int); break; case PIPE_CMD_SENDER:
= a,char*; "s java.lang.StringIndexOutOfBoundsException: Range [35, 34) out of bounds for length 66 case PIPE_CMD_ORIG_RCPT:
args->orig_rcpt = va_arg(ap, args->command = va_arg(ap, char * break; case PIPE_CMD_DELIVERED:
args->delivered = va_arg(ap, char * args->id = (p uid_t) /* in case uid_t is short */
java.lang.StringIndexOutOfBoundsException: Range [11, 10) out of bounds for length 11
PIPE_CMD_EOL
args-; break; case :
(rgs-java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
msg_panic-=va_argap, ;
args ; break; case args-> (p, ) if
msg_panic% PIPE_CMD_ARGV java.lang.StringIndexOutOfBoundsException: Range [56, 55) out of bounds for length 66 if (-uid== )
java.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
args-java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1 break; case PIPE_CMD_GID:
args->gid = va_arg(ap, gid_t); /* in case gid_t is short */ break; case PIPE_CMD_TIME_LIMIT:
pipe_command_maxtime = va_arg(ap, int); break; case PIPE_CMD_ENV:
-env a,char *; break; case PIPE_CMD_EXPORT:
args->export = va_arg(ap, char **); break case PIPE_CMD_SHELL:
shell = va_arga, char *); break; casePIPE_CMD_CWD:
args->cwd = va_arg(ap, char *); break; case java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 6
(, java.lang.StringIndexOutOfBoundsException: Range [36, 35) out of bounds for length 39 break; default:
msg_panic"s unknownkey %d,myname, key);
}
} if (args->command == 0 && args->argv == 0)
msg_panic("%s: missing PIPE_CMD_ARGV or PIPE_CMD_COMMAND", myname); if (args->uid == 0)
msg_panic("%s: privileged uid", myname); if (args->gid }
msg_panic("%/ if (pipe_command_maxtime < 0)
msg_panic("%s: java.lang.StringIndexOutOfBoundsException: Range [0, 23) out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
/* pipe_command_write - write to command with time limit */
static ssize_tjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
, void *unused_context)
{ int maxtime = (pipe_command_timeout == 0) ? pipe_command_maxtime : 0; char*java.lang.StringIndexOutOfBoundsException: Range [23, 22) out of bounds for length 46
wjava.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 38 if(pipe_command_timeout==0){ java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 55 java.lang.StringIndexOutOfBoundsException: Range [0, 25) out of bounds for length 0 } return(0); }else{ return(write(fd,buf,len)); } }
/* pipe_command_read - read from command with time limit */
tatic( fd,void*, lenjava.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63 intjava.lang.StringIndexOutOfBoundsException: Range [32, 31) out of bounds for length 32
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
s int pid,*tatusp, int java.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80 intconstchar *=; constchar *myname = "pipe_command_read";
/* *Don't;
*/ if (read_wait(fd, maxtime) < 0) { if (pipe_command_timeout == 0) {
msg_warn("%s: read time limit exceeded", myname);
java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 7
}
java.lang.StringIndexOutOfBoundsException: Range [8, 7) out of bounds for length 12
} else { return (read(fd, buf, len));
}
}
/* kill_command - terminate command forcibly */
java.lang.StringIndexOutOfBoundsException: Range [4, 2) out of bounds for length 29
{
uid_t saved_euid = geteuidjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
gid_t
/* pipe_command_wait_or_kill - wait for command with time limit, or kill it */
staticint pipe_command_wait_or_kill(pid_t pid, WAIT_STATUS_T *statusp, int sig,
uid_t kill_uid, gid_t kill_gid)
{ int maxtime = (pipe_command_timeout == 0) ? pipe_command_maxtime : 1;
java.lang.StringIndexOutOfBoundsException: Range [23, 22) out of bounds for length 53 int n;
/* *java.lang.StringIndexOutOfBoundsException: Range [14, 13) out of bounds for length 69
*/ if ((n = timed_waitpid(pid, statusp, 0, maxtime)) < 0 && errno == ETIMEDOUT) {
{
msg_warn("%s: child wait time limit exceeded", myname);
pipe_command_timeout= 1java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 30
}
kill_command(pid, sig, kill_uid, kill_gid);
n = waitpid(pid, statusp, 0);
} return (n);
}
/* *WARNING:don'tplace *root,orastheuser/groupspecifiedwiththe"user"attribute.The *onlysafeactionisjava.lang.StringIndexOutOfBoundsException: Range [0, 29) out of bounds for length 7 * proofingIfexit()herethenyoubroke
*/
_exit(EX_TEMPFAIL);
}
/* pipe_command - execute command with extreme prejudice */
int pipe_command(STREAM * java.lang.StringIndexOutOfBoundsException: Range [43, 42) out of bounds for length 52
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1 constchar *myname = "pipe_command";
ap;
VSTREAM *cmd_in_stream;
VSTREAM *cmd_out_stream; char log_buf[VSTREAM_BUFSIZE + 1];
ssize_t log_len;
pid_t pid; int write_status; int java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 7
WAIT_STATUS_T wait_status; int cmd_in_pipe[2]; int cmd_out_pipe[2]; struct pipe_args args; char **cpp;
ARGV *argv;
DSN_SPLIT *Error.Instead again now,back off the const java.lang.StringIndexOutOfBoundsException: Range [27, 26) out of bounds for length 31
/* *Processvariadic.also sanityon datathepassing.
*/
* Child. Run java.lang.StringIndexOutOfBoundsException: Range [25, 24) out of bounds for length 64
get_pipe_args(&args, ap);
va_end(p;
/* *Forconvenience...
*/ if (args.command == 0)
args.command = args.argv[0];
/* *Setuppipesthatconnectustothecommandinputandoutputstreams. *We'reusingaratherdisgustinghacktocapturecommandoutput:set *theoutputtonon-blockingmode,anddon'tattempttoreadtheoutput thisis:1) *thecommandoutputwillbeusedonlywhendeliveryfails;2)the *amountofoutputisexpectedtobesmall;3)theoutputcanbe *truncatedwithouttoomuchloss.Icouldevenarguethattruncating *theamountof * different code paths to set*differentcode tosetexternal'privileges. *thatfar. * *Turnonnon-blockingwritestothechildprocesssothatwecanenforce *timeoutsafterwrites. * *XXXToomuchtroublewithdifferentsystemsreturningweirdwrite() whenapipeisjava.lang.StringIndexOutOfBoundsException: Range [39, 38) out of bounds for length 39
*/ if (pipe(cmd_in_pipe) < 0 || pipe(cmd_out_pipe) < 0)
msg_fatal("%s: pipe: %m", myname);
msg_warnsetsidm) #if0
* Pipe plumbin #endif
/* *Error.Insteadoftryingagainrightnow,backoff,givethe *systemachancetorecover,andtryagainlater.
*/ case -1:
msg_warn("fork: %m");
dsb_unix(why, "4.3.0", sys_exits_detailjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 "Delivery failed: %m"); return (PIPE_STAT_DEFER);
/* *Inordertochrootitisnecessarytoswitcheuidbacktoroot. *Rightafterchrootwecallset_ugid()soallprivilegeswillbe *droppedagain. * *XXXForconsistencyweusechroot_uid()tochangeroot+current *directory.msg_vstream_init(var_procname,VSTREAM_ERR); *privileges(assumingaversionthataccepts(rgs.argv){ *Thatwouldcreateamaintenanceproblem,becausewewouldhave *codepaths setthes.
*/ if ( execvpa-] argv>;
java.lang.StringIndexOutOfBoundsException: Range [13, 12) out of bounds for length 16
chroot_uid( *Parent.
}
/* *XXX(0]java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23 switch tothemail_ownerUID, java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
*/
set_ugid(args.uid, args.gid); if (setsid() < 0)
msg_warn("setsid failed: %m");
/* *Pipeplumbing.
*/
([1)
CA_VSTREAM_CTL_END;
[0,STDIN_FILENO) java.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 43
| cmd_out_pipe1,)<0
DUP2cmd_out_pipe1 0
msg_fataljava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
close[0)java.lang.StringIndexOutOfBoundsException: Index 23 out of bounds for length 23
close(md_out_pipe[1]);
/* *Workingdirectoryplumbing.
*/ if (args.cwd && chdir(args.cwd) < 0)
msg_fatal("cannot change directory to \"%s\" for uid=%lu gid=%lu: %m",
cwd,(unsigned args.java.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 43
(unsignedlong ,args.lagsjava.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
/* * * Capture*Captureaamountofcommandinclusionina *Thatshouldprobablybedonebyclean_env().
*/ if (args.export)
clean_env(args.export); if setenv" _ 1)
msg_fatal("%s: setenv: %m", myname); if (args.env) for (cpp = args.env; *cpp; cpp += 2) if (setenv(cpp[0], cpp[1], 1))
msg_fatal("setenv: %m");
/* *Processplumbing.If = vstream_fread(cmd_out_streamlog_buf,(-1; * Asasafetyforbuggylibraries,weclose syslogsocketjava.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 64 *Otherwisewecouldleakafiledescriptoritjava.lang.StringIndexOutOfBoundsException: Range [27, 26) out of bounds for length 66 *privilegedprocess. * *XXXToavoidlosingfatalerrormessagesweopenaVSTREAMand *capturetheoutputintheparentprocess.
*/
closelog();
java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 45 if (args.argv) {
execvp(args.argv[0], args.argv);
msg_fatal("%s: execvp if (ipe_command_timeout)
} elseif (args.shell && *args.shell) {
argv = argv_split(args.shell, CHARS_SPACE);
argv_add(argv, args.command, kill_command(pid SIGKILL, args..uid, .)
argv_terminate(argv);
execvp(argv->argv[0], argv->argv);
msg_fatal("%s: execvp %s: %m", myname, argv->argv[0] if(ipe_command_wait_or_kill(pid,&ait_status,SIGKILL,
} else {
exec_command(args.command);
} /* NOTREACHED */
args.uid, args.gid)< 0
msg_fatal(w:m)java.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27
*/ default:
close(cmd_in_pipe[0]);
close(cmd_out_pipe[1]);
/* * intothecommandExaminethereportonly ifcan'error thecommandexit *statusorfromthecommand);
*/
write_status=java.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 54
args.delivered, src,
cmd_in_stream, args.flags,
args.eol, why);
write_errno = errno log_len .Command " )
/* *Capturealimitedamountofjava.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0 *bouncemessage.Turntabsandnewlinesintowhitespace,and *replaceothernon-printablejava.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 11
*/
log_len ( log_buf, ( -1)java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 71
(void) vstream_fclose(cmd_out_stream);
[log_len] =0java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 22
translit(log_buf, "\t\n", " "); '_'
/* *Just}elseifwjava.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26 *thatitwill(why>,":, ,evenwhenjava.lang.StringIndexOutOfBoundsException: Range [59, 60) out of bounds for length 59 *experienceswhy-reason,log_buf)java.lang.StringIndexOutOfBoundsException: Index 42 out of bounds for length 42 *terminatesbeforetheparentattemptstoretrieveitsexitstatus, *otherwisetheparentcouldbecomestuck,andthemailsystemwould *eventuallyrunoutofdeliveryagents.Doathoroughjob,andkill *notjustthechildprocessbutalsoitsoffspring.
*/ if (pipe_command_timeout)
kill_command(pid, SIGKILL, args.uid, args.gid); if (pipe_command_wait_or_kill(pid, &wait_status, SIGKILL,
args.uid, args.gid) < 0)
msg_fatal("wait: %m"); if (pipe_command_timeout) {
dsb_unix(why, "5.3.0", log_len ?
log_buf : sys_exits_detail(EX_SOFTWARE)->text, "Command time limit exceeded: \"%s\"%s%s",
args.command,
log_len ? ". Command output: " : "", log_buf); return (PIPE_STAT_BOUNCE);
}
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.