main.sh 27 KB


  1. # Internal variables
  2. DATE=$(date +%F)
  3. TIME=$(date +%T)
  4. SCRIPT=$(basename $0)
  5. A1=$1
  6. A2=$2
  7. A3=$3
  8. A4=$4
  9. A5=$5
  10. A6=$6
  11. A7=$7
  12. A8=$8
  13. A9=$9
  14. EVENT="$DATE $TIME $SCRIPT $A1 $A2 $A3 $A4 $A5 $A6 $A7 $A8 $A9"
  15. HOMEDIR='/home'
  16. BACKUP='/backup'
  17. BACKUP_GZIP=5
  18. BACKUP_DISK_LIMIT=95
  19. BACKUP_LA_LIMIT=5
  20. RRD_STEP=300
  21. RRD_IFACE_EXCLUDE=lo
  22. PW_MATRIX='0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz'
  23. PW_LENGHT='10'
  24. BIN=$VESTA/bin
  25. USER_DATA=$VESTA/data/users/$user
  26. WEBTPL=$VESTA/data/templates/web
  27. DNSTPL=$VESTA/data/templates/dns
  28. RRD=$VESTA/web/rrd
  29. send_mail="$VESTA/web/inc/mail-wrapper.php"
  30. # Return codes
  31. OK=0
  32. E_ARGS=1
  33. E_INVALID=2
  34. E_NOTEXIST=3
  35. E_EXISTS=4
  36. E_SUSPENDED=5
  37. E_UNSUSPENDED=6
  38. E_INUSE=7
  39. E_LIMIT=8
  40. E_PASSWORD=9
  41. E_FORBIDEN=10
  42. E_DISABLED=11
  43. E_PARSING=12
  44. E_DISK=13
  45. E_LA=14
  46. E_CONNECT=15
  47. E_FTP=16
  48. E_DB=17
  49. E_RRD=18
  50. E_UPDATE=19
  51. E_RESTART=20
  52. # Log event function
  53. log_event() {
  54. if [ "$1" -eq 0 ]; then
  55. echo "$2" >> $VESTA/log/system.log
  56. else
  57. echo "$2 [Error $1]" >> $VESTA/log/error.log
  58. fi
  59. }
  60. # Log user history
  61. log_history() {
  62. cmd=$1
  63. undo=${2-no}
  64. log_user=${3-$user}
  65. log=$VESTA/data/users/$log_user/history.log
  66. touch $log
  67. if [ '99' -lt "$(wc -l $log |cut -f 1 -d ' ')" ]; then
  68. tail -n 49 $log > $log.moved
  69. mv -f $log.moved $log
  70. chmod 660 $log
  71. fi
  72. curr_str=$(grep "ID=" $log | cut -f 2 -d \' | sort -n | tail -n1)
  73. id="$((curr_str +1))"
  74. echo "ID='$id' DATE='$DATE' TIME='$TIME' CMD='$cmd' UNDO='$undo'" >> $log
  75. }
  76. # Argument list checker
  77. check_args() {
  78. if [ "$1" -gt "$2" ]; then
  79. echo "Error: not enought arguments"
  80. echo "Usage: $SCRIPT $3"
  81. log_event "$E_ARGS" "$EVENT"
  82. exit $E_ARGS
  83. fi
  84. }
  85. # Subsystem checker
  86. is_system_enabled() {
  87. if [ -z "$1" ] || [ "$1" = no ]; then
  88. echo "Error: $2 is not enabled in the $VESTA/conf/vesta.conf"
  89. log_event "$E_DISABLED" "$EVENT"
  90. exit $E_DISABLED
  91. fi
  92. }
  93. # User package check
  94. is_package_full() {
  95. case "$1" in
  96. WEB_DOMAINS) used=$(wc -l $USER_DATA/web.conf|cut -f1 -d \ );;
  97. WEB_ALIASES) used=$(grep "DOMAIN='$domain'" $USER_DATA/web.conf |\
  98. awk -F "ALIAS='" '{print $2}' | cut -f 1 -d \' | tr ',' '\n' |\
  99. wc -l );;
  100. DNS_DOMAINS) used=$(wc -l $USER_DATA/dns.conf |cut -f1 -d \ );;
  101. DNS_RECORDS) used=$(wc -l $USER_DATA/dns/$domain.conf |cut -f1 -d \ );;
  102. MAIL_DOMAINS) used=$(wc -l $USER_DATA/mail.conf |cut -f1 -d \ );;
  103. MAIL_ACCOUNTS) used=$(wc -l $USER_DATA/mail/$domain.conf |\
  104. cut -f1 -d \ );;
  105. DATABASES) used=$(wc -l $USER_DATA/db.conf |cut -f1 -d \ );;
  106. CRON_JOBS) used=$(wc -l $USER_DATA/cron.conf |cut -f1 -d \ );;
  107. esac
  108. limit=$(grep "^$1=" $USER_DATA/user.conf | cut -f 2 -d \' )
  109. if [ "$limit" != 'unlimited' ] && [ "$used" -ge "$limit" ]; then
  110. echo "Error: Limit is reached, please upgrade hosting package"
  111. log_event "$E_LIMIT" "$EVENT"
  112. exit $E_LIMIT
  113. fi
  114. }
  115. # Random password generator
  116. gen_password() {
  117. pw_matrix=${1-$PW_MATRIX}
  118. pw_lenght=${2-$PW_LENGHT}
  119. while [ ${n:=1} -le $pw_lenght ]; do
  120. pass="$pass${pw_matrix:$(($RANDOM%${#pw_matrix})):1}"
  121. let n+=1
  122. done
  123. echo "$pass"
  124. }
  125. # Package existance check
  126. is_package_valid() {
  127. if [ -z "$1" ]; then
  128. pkg_dir="$VESTA/data/packages"
  129. fi
  130. if [ ! -e "$pkg_dir/$package.pkg" ]; then
  131. echo "Error: package $package doesn't exist"
  132. log_event "$E_NOTEXIST" "$EVENT"
  133. exit $E_NOTEXIST
  134. fi
  135. }
  136. # Validate system type
  137. is_type_valid() {
  138. if [ -z "$(echo $1 | grep -w $2)" ]; then
  139. echo "Error: $2 is unknown type"
  140. log_event "$E_INVALID" "$EVENT"
  141. exit $E_INVALID
  142. fi
  143. }
  144. # Check if backup is available for user
  145. is_backup_available() {
  146. b_owner=$(echo $user |\
  147. sed -e "s/\.[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].tar//")
  148. if [ "$user" != "$b_owner" ]; then
  149. echo "Error: User $user don't have permission to use $backup"
  150. log_event "$E_FORBIDEN" "$EVENT"
  151. exit $E_FORBIDEN
  152. fi
  153. }
  154. # Check user backup settings
  155. is_backup_enabled() {
  156. BACKUPS=$(grep "^BACKUPS=" $USER_DATA/user.conf | cut -f2 -d \')
  157. if [ -z "$BACKUPS" ] || [[ "$BACKUPS" -le '0' ]]; then
  158. echo "Error: user backup disabled"
  159. log_event "$E_DISABLED" "$EVENT"
  160. exit $E_DISABLED
  161. fi
  162. }
  163. # Check user backup settings
  164. is_backup_scheduled() {
  165. if [ -e "$VESTA/data/queue/backup.pipe" ]; then
  166. check_q=$(grep " $user " $VESTA/data/queue/backup.pipe | grep $1)
  167. if [ ! -z "$check_q" ]; then
  168. echo "Error: $1 is already scheduled"
  169. log_event "$E_EXISTS" "$EVENT"
  170. exit $E_EXISTS
  171. fi
  172. fi
  173. }
  174. # Check if object is new
  175. is_object_new() {
  176. if [ $2 = 'USER' ]; then
  177. if [ -d "$USER_DATA" ]; then
  178. object="OK"
  179. fi
  180. else
  181. object=$(grep "$2='$3'" $USER_DATA/$1.conf)
  182. fi
  183. if [ ! -z "$object" ]; then
  184. echo "Error: $2 with value $3 exists"
  185. log_event "$E_EXISTS" "$EVENT"
  186. exit $E_EXISTS
  187. fi
  188. }
  189. # Check if object exists and can be used
  190. is_object_valid() {
  191. if [ $2 = 'USER' ]; then
  192. if [ -d "$VESTA/data/users/$user" ]; then
  193. sobject="OK"
  194. fi
  195. else
  196. if [ $2 = 'DBHOST' ]; then
  197. sobject=$(grep "HOST='$host'" $VESTA/conf/$type.conf)
  198. else
  199. sobject=$(grep "$2='$3'" $VESTA/data/users/$user/$1.conf)
  200. fi
  201. fi
  202. if [ -z "$sobject" ]; then
  203. echo "Error: $2 $3 doesn't exist"
  204. log_event "$E_NOTEXIST" "$EVENT"
  205. exit $E_NOTEXIST
  206. fi
  207. }
  208. # Check if object is supended
  209. is_object_suspended() {
  210. if [ $2 = 'USER' ]; then
  211. spnd=$(cat $USER_DATA/$1.conf|grep "SUSPENDED='yes'")
  212. else
  213. spnd=$(grep "$2='$3'" $USER_DATA/$1.conf|grep "SUSPENDED='yes'")
  214. fi
  215. if [ -z "$spnd" ]; then
  216. echo "Error: $(basename $1) $3 is not suspended"
  217. log_event "$E_SUSPENDED" "$EVENT"
  218. exit $E_SUSPENDED
  219. fi
  220. }
  221. # Check if object is unsupended
  222. is_object_unsuspended() {
  223. if [ $2 = 'USER' ]; then
  224. spnd=$(cat $USER_DATA/$1.conf|grep "SUSPENDED='yes'")
  225. else
  226. spnd=$(grep "$2='$3'" $USER_DATA/$1.conf|grep "SUSPENDED='yes'")
  227. fi
  228. if [ ! -z "$spnd" ]; then
  229. echo "Error: $(basename $1) $3 is suspended"
  230. log_event "$E_UNSUSPENDED" "$EVENT"
  231. exit $E_UNSUSPENDED
  232. fi
  233. }
  234. # Check if object value is empty
  235. is_object_value_empty() {
  236. str=$(grep "$2='$3'" $USER_DATA/$1.conf)
  237. eval $str
  238. eval value=$4
  239. if [ ! -z "$value" ] && [ "$value" != 'no' ]; then
  240. echo "Error: ${4//$}=$value (not empty)"
  241. log_event "$E_EXISTS" "$EVENT"
  242. exit $E_EXISTS
  243. fi
  244. }
  245. # Check if object value is empty
  246. is_object_value_exist() {
  247. str=$(grep "$2='$3'" $USER_DATA/$1.conf)
  248. eval $str
  249. eval value=$4
  250. if [ -z "$value" ] || [ "$value" = 'no' ]; then
  251. echo "Error: ${4//$}=$value (doesn't exist)"
  252. log_event "$E_NOTEXIST" "$EVENT"
  253. exit $E_NOTEXIST
  254. fi
  255. }
  256. # Check if password is transmitted via file
  257. is_password_valid() {
  258. if [[ "$password" =~ ^/tmp/ ]]; then
  259. if [ -f "$password" ]; then
  260. password=$(head -n1 $password)
  261. fi
  262. fi
  263. }
  264. # Get object value
  265. get_object_value() {
  266. object=$(grep "$2='$3'" $USER_DATA/$1.conf)
  267. eval "$object"
  268. eval echo $4
  269. }
  270. # Update object value
  271. update_object_value() {
  272. row=$(grep -n "$2='$3'" $USER_DATA/$1.conf)
  273. lnr=$(echo $row | cut -f 1 -d ':')
  274. object=$(echo $row | sed "s/^$lnr://")
  275. eval "$object"
  276. eval old="$4"
  277. old=$(echo "$old" | sed -e 's/\\/\\\\/g' -e 's/&/\\&/g' -e 's/\//\\\//g')
  278. new=$(echo "$5" | sed -e 's/\\/\\\\/g' -e 's/&/\\&/g' -e 's/\//\\\//g')
  279. sed -i "$lnr s/${4//$/}='${old//\*/\\*}'/${4//$/}='${new//\*/\\*}'/g" \
  280. $USER_DATA/$1.conf
  281. }
  282. # Add object key
  283. add_object_key() {
  284. row=$(grep -n "$2='$3'" $USER_DATA/$1.conf)
  285. lnr=$(echo $row | cut -f 1 -d ':')
  286. object=$(echo $row | sed "s/^$lnr://")
  287. if [ -z "$(echo $object |grep $4=)" ]; then
  288. eval old="$4"
  289. sed -i "$lnr s/$5='/$4='' $5='/" $USER_DATA/$1.conf
  290. fi
  291. }
  292. # Search objects
  293. search_objects() {
  294. OLD_IFS="$IFS"
  295. IFS=$'\n'
  296. for line in $(grep $2=\'$3\' $USER_DATA/$1.conf); do
  297. eval $line
  298. eval echo \$$4
  299. done
  300. IFS="$OLD_IFS"
  301. }
  302. # Get user value
  303. get_user_value() {
  304. grep "^${1//$/}=" $USER_DATA/user.conf| cut -f 2 -d \'
  305. }
  306. # Update user value in user.conf
  307. update_user_value() {
  308. key="${2//$}"
  309. lnr=$(grep -n "^$key='" $VESTA/data/users/$1/user.conf |cut -f 1 -d ':')
  310. if [ ! -z "$lnr" ]; then
  311. sed -i "$lnr d" $VESTA/data/users/$1/user.conf
  312. sed -i "$lnr i\\$key='${3}'" $VESTA/data/users/$1/user.conf
  313. fi
  314. }
  315. # Increase user counter
  316. increase_user_value() {
  317. key="${2//$}"
  318. factor="${3-1}"
  319. conf="$VESTA/data/users/$1/user.conf"
  320. old=$(grep "$key=" $conf | cut -f 2 -d \')
  321. if [ -z "$old" ]; then
  322. old=0
  323. fi
  324. new=$((old + factor))
  325. sed -i "s/$key='$old'/$key='$new'/g" $conf
  326. }
  327. # Decrease user counter
  328. decrease_user_value() {
  329. key="${2//$}"
  330. factor="${3-1}"
  331. conf="$VESTA/data/users/$1/user.conf"
  332. old=$(grep "$key=" $conf | cut -f 2 -d \')
  333. if [ -z "$old" ]; then
  334. old=0
  335. fi
  336. if [ "$old" -le 1 ]; then
  337. new=0
  338. else
  339. new=$((old - factor))
  340. fi
  341. if [ "$new" -lt 0 ]; then
  342. new=0
  343. fi
  344. sed -i "s/$key='$old'/$key='$new'/g" $conf
  345. }
  346. # Json listing function
  347. json_list() {
  348. echo '{'
  349. fileds_count=$(echo $fields| wc -w )
  350. #for line in $(cat $conf); do
  351. while read line; do
  352. eval $line
  353. if [ -n "$data_output" ]; then
  354. echo -e ' },'
  355. fi
  356. i=1
  357. for field in $fields; do
  358. eval value=$field
  359. if [ $i -eq 1 ]; then
  360. (( ++i))
  361. echo -e "\t\"$value\": {"
  362. else
  363. if [ $i -lt $fileds_count ]; then
  364. (( ++i))
  365. echo -e "\t\t\"${field//$/}\": \"$value\","
  366. else
  367. echo -e "\t\t\"${field//$/}\": \"$value\""
  368. data_output=yes
  369. fi
  370. fi
  371. done
  372. done < $conf
  373. if [ "$data_output" = 'yes' ]; then
  374. echo -e ' }'
  375. fi
  376. echo -e '}'
  377. }
  378. # Shell listing function
  379. shell_list() {
  380. if [ -z "$nohead" ] ; then
  381. echo "${fields//$/}"
  382. for a in $fields; do
  383. echo -e "------ \c"
  384. done
  385. echo
  386. fi
  387. while read line ; do
  388. eval $line
  389. for field in $fields; do
  390. eval value=$field
  391. if [ -z "$value" ]; then
  392. value='NULL'
  393. fi
  394. echo -n "$value "
  395. done
  396. echo
  397. done < $conf
  398. }
  399. # Recalculate U_DISK value
  400. recalc_user_disk_usage() {
  401. u_usage=0
  402. if [ -f "$USER_DATA/web.conf" ]; then
  403. usage=0
  404. dusage=$(grep 'U_DISK=' $USER_DATA/web.conf |\
  405. awk -F "U_DISK='" '{print $2}' | cut -f 1 -d \')
  406. for disk_usage in $dusage; do
  407. usage=$((usage + disk_usage))
  408. done
  409. d=$(grep "U_DISK_WEB='" $USER_DATA/user.conf | cut -f 2 -d \')
  410. sed -i "s/U_DISK_WEB='$d'/U_DISK_WEB='$usage'/g" $USER_DATA/user.conf
  411. u_usage=$((u_usage + usage))
  412. fi
  413. if [ -f "$USER_DATA/mail.conf" ]; then
  414. usage=0
  415. dusage=$(grep 'U_DISK=' $USER_DATA/mail.conf |\
  416. awk -F "U_DISK='" '{print $2}' | cut -f 1 -d \')
  417. for disk_usage in $dusage; do
  418. usage=$((usage + disk_usage))
  419. done
  420. d=$(grep "U_DISK_MAIL='" $USER_DATA/user.conf | cut -f 2 -d \')
  421. sed -i "s/U_DISK_MAIL='$d'/U_DISK_MAIL='$usage'/g" $USER_DATA/user.conf
  422. u_usage=$((u_usage + usage))
  423. fi
  424. if [ -f "$USER_DATA/db.conf" ]; then
  425. usage=0
  426. dusage=$(grep 'U_DISK=' $USER_DATA/db.conf |\
  427. awk -F "U_DISK='" '{print $2}' | cut -f 1 -d \')
  428. for disk_usage in $dusage; do
  429. usage=$((usage + disk_usage))
  430. done
  431. d=$(grep "U_DISK_DB='" $USER_DATA/user.conf | cut -f 2 -d \')
  432. sed -i "s/U_DISK_DB='$d'/U_DISK_DB='$usage'/g" $USER_DATA/user.conf
  433. u_usage=$((u_usage + usage))
  434. fi
  435. usage=$(grep 'U_DISK_DIRS=' $USER_DATA/user.conf | cut -f 2 -d "'")
  436. u_usage=$((u_usage + usage))
  437. old=$(grep "U_DISK='" $USER_DATA/user.conf | cut -f 2 -d \')
  438. sed -i "s/U_DISK='$old'/U_DISK='$u_usage'/g" $USER_DATA/user.conf
  439. }
  440. # Recalculate U_BANDWIDTH value
  441. recalc_user_bandwidth_usage() {
  442. usage=0
  443. bandwidth_usage=$(grep 'U_BANDWIDTH=' $USER_DATA/web.conf |\
  444. awk -F "U_BANDWIDTH='" '{print $2}'|cut -f 1 -d \')
  445. for bandwidth in $bandwidth_usage; do
  446. usage=$((usage + bandwidth))
  447. done
  448. old=$(grep "U_BANDWIDTH='" $USER_DATA/user.conf | cut -f 2 -d \')
  449. sed -i "s/U_BANDWIDTH='$old'/U_BANDWIDTH='$usage'/g" $USER_DATA/user.conf
  450. }
  451. # Get next cron job id
  452. get_next_cronjob() {
  453. if [ -z "$job" ]; then
  454. curr_str=$(grep "JOB=" $USER_DATA/cron.conf|cut -f 2 -d \'|\
  455. sort -n|tail -n1)
  456. job="$((curr_str +1))"
  457. fi
  458. }
  459. # Sort cron jobs by id
  460. sort_cron_jobs() {
  461. cat $USER_DATA/cron.conf |sort -n -k 2 -t \' > $USER_DATA/cron.tmp
  462. mv -f $USER_DATA/cron.tmp $USER_DATA/cron.conf
  463. }
  464. # Sync cronjobs with system cron
  465. sync_cron_jobs() {
  466. source $USER_DATA/user.conf
  467. if [ -e "/var/spool/cron/crontabs" ]; then
  468. sys_cron="/var/spool/cron/crontabs/$user"
  469. else
  470. sys_cron="/var/spool/cron/$user"
  471. fi
  472. rm -f $sys_cron
  473. if [ "$CRON_REPORTS" = 'yes' ]; then
  474. echo "MAILTO=$CONTACT" > $sys_cron
  475. fi
  476. while read line; do
  477. eval $line
  478. if [ "$SUSPENDED" = 'no' ]; then
  479. echo "$MIN $HOUR $DAY $MONTH $WDAY $CMD" |\
  480. sed -e "s/%quote%/'/g" -e "s/%dots%/:/g" \
  481. >> $sys_cron
  482. fi
  483. done < $USER_DATA/cron.conf
  484. # Set proper permissions
  485. chown $user:$user $sys_cron
  486. chmod 600 $sys_cron
  487. }
  488. ### Format Validators ###
  489. # Shell
  490. validate_format_shell() {
  491. if [ -z "$(grep -w $1 /etc/shells)" ]; then
  492. echo "Error: shell $1 is not valid"
  493. log_event "$E_INVALID" "$EVENT"
  494. exit $E_INVALID
  495. fi
  496. }
  497. # Password
  498. validate_format_password() {
  499. if [ "${#1}" -lt '6' ]; then
  500. echo "Error: password is too short"
  501. log_event "$E_INVALID" "$EVENT"
  502. exit $E_INVALID
  503. fi
  504. }
  505. # Integer
  506. validate_format_int() {
  507. if ! [[ "$1" =~ ^[0-9]+$ ]] ; then
  508. echo "Error: $2 $1 is not valid"
  509. log_event "$E_INVALID" "$EVENT"
  510. exit $E_INVALID
  511. fi
  512. }
  513. # Boolean
  514. validate_format_boolean() {
  515. if [ "$1" != 'yes' ] && [ "$1" != 'no' ]; then
  516. echo "Error: $2 $1 is not valid"
  517. log_event "$E_INVALID" "$EVENT"
  518. exit $E_INVALID
  519. fi
  520. }
  521. # Network interface
  522. validate_format_interface() {
  523. netdevices=$(cat /proc/net/dev | grep : | cut -f 1 -d : | tr -d ' ')
  524. if [ -z $(echo "$netdevices"| grep -x $1) ]; then
  525. echo "Error: intreface $1 is not valid"
  526. log_event "$E_INVALID" "$EVENT"
  527. exit $E_INVALID
  528. fi
  529. }
  530. # IP address
  531. validate_format_ip() {
  532. t_ip=$(echo $1 |awk -F / '{print $1}')
  533. t_cidr=$(echo $1 |awk -F / '{print $2}')
  534. valid_octets=0
  535. valid_cidr=1
  536. for octet in ${t_ip//./ }; do
  537. if [[ $octet =~ ^[0-9]{1,3}$ ]] && [[ $octet -le 255 ]]; then
  538. ((++valid_octets))
  539. fi
  540. done
  541. if [ ! -z "$(echo $1|grep '/')" ]; then
  542. if [[ "$t_cidr" -lt 0 ]] || [[ "$t_cidr" -gt 32 ]]; then
  543. valid_cidr=0
  544. fi
  545. if ! [[ "$t_cidr" =~ ^[0-9]+$ ]]; then
  546. valid_cidr=0
  547. fi
  548. fi
  549. if [ "$valid_octets" -lt 4 ] || [ "$valid_cidr" -eq 0 ]; then
  550. echo "Error: ip $1 is not valid"
  551. log_event "$E_INVALID" "$EVENT"
  552. exit $E_INVALID
  553. fi
  554. }
  555. # IP address status
  556. validate_format_ip_status() {
  557. if [ -z "$(echo shared,dedicated | grep -w $1 )" ]; then
  558. echo "Error: ip_status $1 is not valid"
  559. log_event "$E_INVALID" "$EVENT"
  560. exit $E_INVALID
  561. fi
  562. }
  563. # Email address
  564. validate_format_email() {
  565. if [[ ! "$1" =~ "@" ]] ; then
  566. echo "Error: email $1 is not valid"
  567. log_event "$E_INVALID" "$EVENT"
  568. exit $E_INVALID
  569. fi
  570. }
  571. # Name
  572. validate_format_name() {
  573. if ! [[ "$1" =~ ^[[:alnum:]][-|\.|_[:alnum:]]{0,28}[[:alnum:]]$ ]]; then
  574. echo "Error: $2 $1 is not valid"
  575. log_event "$E_INVALID" "$EVENT"
  576. exit $E_INVALID
  577. fi
  578. }
  579. # Name with space
  580. validate_format_name_s() {
  581. if ! [[ "$1" =~ ^[[:alnum:]][-|\ |\.|_[:alnum:]]{0,28}[[:alnum:]]$ ]]; then
  582. echo "Error: $2 $1 is not valid"
  583. log_event "$E_INVALID" "$EVENT"
  584. exit $E_INVALID
  585. fi
  586. }
  587. # Username
  588. validate_format_username() {
  589. if [ "${#1}" -eq 1 ]; then
  590. if ! [[ "$1" =~ [a-z] ]]; then
  591. echo "Error: $2 $1 is not valid"
  592. log_event "$E_INVALID" "$EVENT"
  593. exit 1
  594. fi
  595. else
  596. if ! [[ "$1" =~ ^[a-zA-Z0-9][-|\.|_|a-zA-Z0-9]{0,28}[a-zA-Z0-9]$ ]]
  597. then
  598. echo "Error: $2 $1 is not valid"
  599. log_event "$E_INVALID" "$EVENT"
  600. exit 1
  601. fi
  602. fi
  603. }
  604. # Domain
  605. validate_format_domain() {
  606. exclude="[!|@|#|$|^|&|*|(|)|+|=|{|}|:|,|<|>|?|_|/|\|\"|'|;|%|\`| ]"
  607. if [[ "$1" =~ $exclude ]] || [[ "$1" =~ "^[0-9]+$" ]]; then
  608. echo "Error: $2 $1 is not valid"
  609. log_event "$E_INVALID" "$EVENT"
  610. exit $E_INVALID
  611. fi
  612. }
  613. # Domain alias
  614. validate_format_domain_alias() {
  615. exclude="[!|@|#|$|^|&|(|)|+|=|{|}|:|,|<|>|?|_|/|\|\"|'|;|%|\`| ]"
  616. if [[ "$1" =~ $exclude ]] || [[ "$1" =~ "^[0-9]+$" ]]; then
  617. echo "Error: domain alias $1 is not valid"
  618. log_event "$E_INVALID" "$EVENT"
  619. exit $E_INVALID
  620. fi
  621. }
  622. # Database
  623. validate_format_database() {
  624. exclude="[!|@|#|$|^|&|*|(|)|+|=|{|}|:|,|<|>|?|/|\|\"|'|;|%|\`| ]"
  625. if [[ "$1" =~ $exclude ]] || [ 65 -le ${#1} ]; then
  626. echo "Error: $2 $1 is not valid"
  627. log_event "$E_INVALID" "$EVENT"
  628. exit $E_INVALID
  629. fi
  630. }
  631. # Database user
  632. validate_format_dbuser() {
  633. exclude="[!|@|#|$|^|&|*|(|)|+|=|{|}|:|,|<|>|?|/|\|\"|'|;|%|\`| ]"
  634. if [[ "$1" =~ $exclude ]] || [ 17 -le ${#1} ]; then
  635. echo "Error: $2 $1 is not valid"
  636. log_event "$E_INVALID" "$EVENT"
  637. exit $E_INVALID
  638. fi
  639. }
  640. # DNS type
  641. validate_format_dns_type() {
  642. known_dnstype='A,AAAA,NS,CNAME,MX,TXT,SRV,DNSKEY,KEY,IPSECKEY,PTR,SPF'
  643. if [ -z "$(echo $known_dnstype | grep -w $1)" ]; then
  644. echo "Error: dnstype $1 is not valid"
  645. log_event "$E_INVALID" "$EVENT"
  646. exit $E_INVALID
  647. fi
  648. }
  649. # DKIM key size
  650. validate_format_key_size() {
  651. known_size='128,256,512,768,1024,2048'
  652. if [ -z "$(echo $known_size | grep -w $1)" ]; then
  653. echo "Error: key_size $1 is not valid"
  654. log_event "$E_INVALID" "$EVENT"
  655. exit $E_INVALID
  656. fi
  657. }
  658. # Minute / Hour / Day / Month / Day of Week
  659. validate_format_mhdmw() {
  660. limit=60
  661. check_format=''
  662. if [ "$2" = 'day' ]; then
  663. limit=31
  664. fi
  665. if [ "$2" = 'month' ]; then
  666. limit=12
  667. fi
  668. if [ "$2" = 'wday' ]; then
  669. limit=7
  670. fi
  671. if [ "$1" = '*' ]; then
  672. check_format='ok'
  673. fi
  674. if [[ "$1" =~ ^[\*]+[/]+[0-9] ]]; then
  675. if [ "$(echo $1 |cut -f 2 -d /)" -lt $limit ]; then
  676. check_format='ok'
  677. fi
  678. fi
  679. if [[ "$1" =~ ^[0-9][-|,|0-9]{0,28}[0-9]$ ]]; then
  680. check_format='ok'
  681. crn_values=${1//,/ }
  682. crn_values=${crn_values//-/ }
  683. for crn_vl in $crn_values; do
  684. if [ "$crn_vl" -gt $limit ]; then
  685. check_format='invalid'
  686. fi
  687. done
  688. fi
  689. if [[ "$1" =~ ^[0-9]+$ ]] && [ "$1" -lt $limit ]; then
  690. check_format='ok'
  691. fi
  692. if [ "$check_format" != 'ok' ]; then
  693. echo "Error: $2 $1 is not valid"
  694. log_event "$E_INVALID" "$EVENT"
  695. exit $E_INVALID
  696. fi
  697. }
  698. # proxy extention or DNS record
  699. validate_format_common() {
  700. exclude="[!|#|$|^|&|(|)|+|=|{|}|:|<|>|?|/|\|\"|'|;|%|\`| ]"
  701. if [[ "$1" =~ $exclude ]]; then
  702. echo "Error: $2 $1 is not valid"
  703. log_event "$E_INVALID" "$EVENT"
  704. exit $E_INVALID
  705. fi
  706. if [ 400 -le ${#1} ]; then
  707. echo "Error: $2 $1 is too long"
  708. log_event "$E_INVALID" "$EVENT"
  709. exit $E_INVALID
  710. fi
  711. if [[ "$1" =~ @ ]] && [ ${#1} -gt 1 ] ; then
  712. echo "Error: @ can not be mixed"
  713. log_event "$E_INVALID" "$EVENT"
  714. exit $E_INVALID
  715. fi
  716. if [[ $1 =~ \* ]]; then
  717. if [ "$(echo $1 | grep -o '*'|wc -l)" -gt 1 ]; then
  718. log_event "$E_INVALID" "$EVENT"
  719. echo "Error: * can be used only once"
  720. fi
  721. fi
  722. }
  723. # DNS record value
  724. validate_format_dvalue() {
  725. record_types="$(echo A,AAAA,NS,CNAME | grep -w "$rtype")"
  726. if [[ "$1" =~ [\ ] ]] && [ ! -z "$record_types" ]; then
  727. echo "Error: dvalue $1 is not valid"
  728. log_event "$E_INVALID" "$EVENT"
  729. exit $E_INVALID
  730. fi
  731. if [ "$rtype" = 'A' ]; then
  732. validate_format_ip "$1"
  733. fi
  734. if [ "$rtype" = 'NS' ]; then
  735. validate_format_domain "$1" 'ns_record'
  736. fi
  737. if [ "$rtype" = 'MX' ]; then
  738. validate_format_domain "$1" 'mx_record'
  739. validate_format_int "$priority" 'priority_record'
  740. fi
  741. }
  742. # Date
  743. validate_format_date() {
  744. if ! [[ "$1" =~ ^[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]$ ]]; then
  745. echo "Error: date $1 is not valid"
  746. log_event "$E_INVALID" "$EVENT"
  747. exit $E_INVALID
  748. fi
  749. }
  750. # Autoreply
  751. validate_format_autoreply() {
  752. exclude="[$|\`]"
  753. if [[ "$1" =~ $exclude ]] || [ 10240 -le ${#1} ]; then
  754. echo "Error: autoreply is not valid"
  755. log_event "$E_INVALID" "$EVENT"
  756. exit $E_INVALID
  757. fi
  758. }
  759. # Firewall action
  760. validate_format_fw_action() {
  761. if [ "$1" != "ACCEPT" ] && [ "$1" != 'DROP' ] ; then
  762. echo "Error: $1 is not valid action"
  763. log_event "$E_INVALID" "$EVENT"
  764. exit $E_INVALID
  765. fi
  766. }
  767. # Firewall protocol
  768. validate_format_fw_protocol() {
  769. if [ "$1" != "ICMP" ] && [ "$1" != 'UDP' ] && [ "$1" != 'TCP' ] ; then
  770. echo "Error: $1 is not valid protocol"
  771. log_event "$E_INVALID" "$EVENT"
  772. exit $E_INVALID
  773. fi
  774. }
  775. # Firewall port
  776. validate_format_fw_port() {
  777. if [ "${#1}" -eq 1 ]; then
  778. if ! [[ "$1" =~ [0-9] ]]; then
  779. echo "Error: port $1 is not valid"
  780. log_event "$E_INVALID" "$EVENT"
  781. exit 1
  782. fi
  783. else
  784. if ! [[ "$1" =~ ^[0-9][-|,|:|0-9]{0,30}[0-9]$ ]]
  785. then
  786. echo "Error: port $1 is not valid"
  787. log_event "$E_INVALID" "$EVENT"
  788. exit 1
  789. fi
  790. fi
  791. }
  792. # Format validation controller
  793. validate_format(){
  794. for arg_name in $*; do
  795. eval arg=\$$arg_name
  796. if [ -z "$arg" ]; then
  797. echo "Error: argument $arg_name is not valid (empty)"
  798. log_event "$E_INVALID" "$EVENT"
  799. exit $E_INVALID
  800. fi
  801. case $arg_name in
  802. account) validate_format_username "$arg" "$arg_name" ;;
  803. action) validate_format_fw_action "$arg";;
  804. antispam) validate_format_boolean "$arg" 'antispam' ;;
  805. antivirus) validate_format_boolean "$arg" 'antivirus' ;;
  806. autoreply) validate_format_autoreply "$arg" ;;
  807. backup) validate_format_domain "$arg" 'backup' ;;
  808. charset) validate_format_name "$arg" "$arg_name" ;;
  809. charsets) validate_format_common "$arg" 'charsets' ;;
  810. comment) validate_format_name "$arg" 'comment' ;;
  811. database) validate_format_database "$arg" 'database';;
  812. day) validate_format_mhdmw "$arg" $arg_name ;;
  813. dbpass) validate_format_password "$arg" ;;
  814. dbuser) validate_format_dbuser "$arg" 'db_user';;
  815. dkim) validate_format_boolean "$arg" 'dkim' ;;
  816. dkim_size) validate_format_key_size "$arg" ;;
  817. domain) validate_format_domain "$arg" 'domain';;
  818. dom_alias) validate_format_domain_alias "$arg" 'alias';;
  819. dvalue) validate_format_dvalue "$arg";;
  820. email) validate_format_email "$arg" ;;
  821. exp) validate_format_date "$arg" ;;
  822. extentions) validate_format_common "$arg" 'extentions' ;;
  823. fname) validate_format_name_s "$arg" "$arg_name" ;;
  824. forward) validate_format_email "$arg" ;;
  825. ftp_password) validate_format_password "$arg" ;;
  826. ftp_user) validate_format_username "$arg" "$arg_name" ;;
  827. host) validate_format_domain "$arg" "$arg_name" 'host';;
  828. hour) validate_format_mhdmw "$arg" $arg_name ;;
  829. id) validate_format_int "$arg" 'id' ;;
  830. interface) validate_format_interface "$arg" ;;
  831. ip) validate_format_ip "$arg" ;;
  832. ip_name) validate_format_domain "$arg" 'domain';;
  833. ip_status) validate_format_ip_status "$arg" ;;
  834. job) validate_format_int "$arg" 'job' ;;
  835. key) validate_format_username "$arg" "$arg_name" ;;
  836. lname) validate_format_name_s "$arg" "$arg_name" ;;
  837. malias) validate_format_username "$arg" "$arg_name" ;;
  838. max_db) validate_format_int "$arg" 'max db';;
  839. min) validate_format_mhdmw "$arg" $arg_name ;;
  840. month) validate_format_mhdmw "$arg" $arg_name ;;
  841. nat_ip) validate_format_ip "$arg" ;;
  842. netmask) validate_format_ip "$arg" ;;
  843. newid) validate_format_int "$arg" 'id' ;;
  844. ns1) validate_format_domain "$arg" 'name_server';;
  845. ns2) validate_format_domain "$arg" 'name_server';;
  846. ns3) validate_format_domain "$arg" 'name_server';;
  847. ns4) validate_format_domain "$arg" 'name_server';;
  848. package) validate_format_name "$arg" "$arg_name" ;;
  849. password) validate_format_password "$arg" ;;
  850. port) validate_format_int "$arg" 'port' ;;
  851. port_ext) validate_format_fw_port "$arg";;
  852. protocol) validate_format_fw_protocol "$arg" ;;
  853. quota) validate_format_int "$arg" 'quota' ;;
  854. restart) validate_format_boolean "$arg" 'restart' ;;
  855. record) validate_format_common "$arg" 'record';;
  856. rtype) validate_format_dns_type "$arg" ;;
  857. rule) validate_format_int "$arg" "rule id" ;;
  858. shell) validate_format_shell "$arg" ;;
  859. soa) validate_format_domain "$arg" 'soa_record';;
  860. stats_pass) validate_format_password "$arg" ;;
  861. stats_user) validate_format_username "$arg" "$arg_name" ;;
  862. template) validate_format_name "$arg" "$arg_name" ;;
  863. ttl) validate_format_int "$arg" 'ttl';;
  864. user) validate_format_username "$arg" "$arg_name" ;;
  865. wday) validate_format_mhdmw "$arg" $arg_name ;;
  866. esac
  867. done
  868. }