main.sh 27 KB


  1. # Internal variables
  2. DATE=$(date +%F)
  3. TIME=$(date +%T)
  4. SCRIPT=$(basename $0)
  5. HOMEDIR='/home'
  6. BACKUP='/backup'
  7. BACKUP_GZIP=5
  8. BACKUP_DISK_LIMIT=95
  9. BACKUP_LA_LIMIT=5
  10. RRD_STEP=300
  11. RRD_IFACE_EXCLUDE=lo
  12. PW_MATRIX='0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz'
  13. PW_LENGHT='10'
  14. BIN=$VESTA/bin
  15. USER_DATA=$VESTA/data/users/$user
  16. WEBTPL=$VESTA/data/templates/web
  17. DNSTPL=$VESTA/data/templates/dns
  18. RRD=$VESTA/web/rrd
  19. send_mail="$VESTA/web/inc/mail-wrapper.php"
  20. # Return codes
  21. OK=0
  22. E_ARGS=1
  23. E_INVALID=2
  24. E_NOTEXIST=3
  25. E_EXISTS=4
  26. E_SUSPENDED=5
  27. E_UNSUSPENDED=6
  28. E_INUSE=7
  29. E_LIMIT=8
  30. E_PASSWORD=9
  31. E_FORBIDEN=10
  32. E_DISABLED=11
  33. E_PARSING=12
  34. E_DISK=13
  35. E_LA=14
  36. E_CONNECT=15
  37. E_FTP=16
  38. E_DB=17
  39. E_RRD=18
  40. E_UPDATE=19
  41. E_RESTART=20
  42. # Event string for logger
  43. EVENT="$DATE $TIME $SCRIPT"
  44. for ((I=1; I <= $# ; I++)); do
  45. if [[ "$HIDE" != $I ]]; then
  46. EVENT="$EVENT '$(eval echo \$${I})'"
  47. else
  48. EVENT="$EVENT '******'"
  49. fi
  50. done
  51. # Log event function
  52. log_event() {
  53. if [ "$1" -eq 0 ]; then
  54. echo "$2" >> $VESTA/log/system.log
  55. else
  56. echo "$2 [Error $1]" >> $VESTA/log/error.log
  57. fi
  58. }
  59. # Log user history
  60. log_history() {
  61. cmd=$1
  62. undo=${2-no}
  63. log_user=${3-$user}
  64. log=$VESTA/data/users/$log_user/history.log
  65. touch $log
  66. if [ '99' -lt "$(wc -l $log |cut -f 1 -d ' ')" ]; then
  67. tail -n 49 $log > $log.moved
  68. mv -f $log.moved $log
  69. chmod 660 $log
  70. fi
  71. curr_str=$(grep "ID=" $log | cut -f 2 -d \' | sort -n | tail -n1)
  72. id="$((curr_str +1))"
  73. echo "ID='$id' DATE='$DATE' TIME='$TIME' CMD='$cmd' UNDO='$undo'" >> $log
  74. }
  75. # Result checker
  76. check_result() {
  77. if [ $1 -ne 0 ]; then
  78. echo "Error: $2"
  79. if [ ! -z "$3" ]; then
  80. log_event $3 $EVENT
  81. exit $3
  82. else
  83. log_event $1 $EVENT
  84. exit $1
  85. fi
  86. fi
  87. }
  88. # Argument list checker
  89. check_args() {
  90. if [ "$1" -gt "$2" ]; then
  91. echo "Error: not enought arguments"
  92. echo "Usage: $SCRIPT $3"
  93. log_event "$E_ARGS" "$EVENT"
  94. exit $E_ARGS
  95. fi
  96. }
  97. # Subsystem checker
  98. is_system_enabled() {
  99. if [ -z "$1" ] || [ "$1" = no ]; then
  100. echo "Error: $2 is not enabled in the $VESTA/conf/vesta.conf"
  101. log_event "$E_DISABLED" "$EVENT"
  102. exit $E_DISABLED
  103. fi
  104. }
  105. # User package check
  106. is_package_full() {
  107. case "$1" in
  108. WEB_DOMAINS) used=$(wc -l $USER_DATA/web.conf|cut -f1 -d \ );;
  109. WEB_ALIASES) used=$(grep "DOMAIN='$domain'" $USER_DATA/web.conf |\
  110. awk -F "ALIAS='" '{print $2}' | cut -f 1 -d \' | tr ',' '\n' |\
  111. wc -l );;
  112. DNS_DOMAINS) used=$(wc -l $USER_DATA/dns.conf |cut -f1 -d \ );;
  113. DNS_RECORDS) used=$(wc -l $USER_DATA/dns/$domain.conf |cut -f1 -d \ );;
  114. MAIL_DOMAINS) used=$(wc -l $USER_DATA/mail.conf |cut -f1 -d \ );;
  115. MAIL_ACCOUNTS) used=$(wc -l $USER_DATA/mail/$domain.conf |\
  116. cut -f1 -d \ );;
  117. DATABASES) used=$(wc -l $USER_DATA/db.conf |cut -f1 -d \ );;
  118. CRON_JOBS) used=$(wc -l $USER_DATA/cron.conf |cut -f1 -d \ );;
  119. esac
  120. limit=$(grep "^$1=" $USER_DATA/user.conf | cut -f 2 -d \' )
  121. if [ "$limit" != 'unlimited' ] && [ "$used" -ge "$limit" ]; then
  122. echo "Error: Limit is reached, please upgrade hosting package"
  123. log_event "$E_LIMIT" "$EVENT"
  124. exit $E_LIMIT
  125. fi
  126. }
  127. # Random password generator
  128. gen_password() {
  129. pw_matrix=${1-$PW_MATRIX}
  130. pw_lenght=${2-$PW_LENGHT}
  131. while [ ${n:=1} -le $pw_lenght ]; do
  132. pass="$pass${pw_matrix:$(($RANDOM%${#pw_matrix})):1}"
  133. let n+=1
  134. done
  135. echo "$pass"
  136. }
  137. # Package existance check
  138. is_package_valid() {
  139. if [ -z "$1" ]; then
  140. pkg_dir="$VESTA/data/packages"
  141. fi
  142. if [ ! -e "$pkg_dir/$package.pkg" ]; then
  143. echo "Error: package $package doesn't exist"
  144. log_event "$E_NOTEXIST" "$EVENT"
  145. exit $E_NOTEXIST
  146. fi
  147. }
  148. # Validate system type
  149. is_type_valid() {
  150. if [ -z "$(echo $1 | grep -w $2)" ]; then
  151. echo "Error: $2 is unknown type"
  152. log_event "$E_INVALID" "$EVENT"
  153. exit $E_INVALID
  154. fi
  155. }
  156. # Check if backup is available for user
  157. is_backup_available() {
  158. b_owner=$(echo $user |\
  159. sed -e "s/\.[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].tar//")
  160. if [ "$user" != "$b_owner" ]; then
  161. echo "Error: User $user don't have permission to use $backup"
  162. log_event "$E_FORBIDEN" "$EVENT"
  163. exit $E_FORBIDEN
  164. fi
  165. }
  166. # Check user backup settings
  167. is_backup_enabled() {
  168. BACKUPS=$(grep "^BACKUPS=" $USER_DATA/user.conf | cut -f2 -d \')
  169. if [ -z "$BACKUPS" ] || [[ "$BACKUPS" -le '0' ]]; then
  170. echo "Error: user backup disabled"
  171. log_event "$E_DISABLED" "$EVENT"
  172. exit $E_DISABLED
  173. fi
  174. }
  175. # Check user backup settings
  176. is_backup_scheduled() {
  177. if [ -e "$VESTA/data/queue/backup.pipe" ]; then
  178. check_q=$(grep " $user " $VESTA/data/queue/backup.pipe | grep $1)
  179. if [ ! -z "$check_q" ]; then
  180. echo "Error: $1 is already scheduled"
  181. log_event "$E_EXISTS" "$EVENT"
  182. exit $E_EXISTS
  183. fi
  184. fi
  185. }
  186. # Check if object is new
  187. is_object_new() {
  188. if [ $2 = 'USER' ]; then
  189. if [ -d "$USER_DATA" ]; then
  190. object="OK"
  191. fi
  192. else
  193. object=$(grep "$2='$3'" $USER_DATA/$1.conf)
  194. fi
  195. if [ ! -z "$object" ]; then
  196. echo "Error: $2 with value $3 exists"
  197. log_event "$E_EXISTS" "$EVENT"
  198. exit $E_EXISTS
  199. fi
  200. }
  201. # Check if object exists and can be used
  202. is_object_valid() {
  203. if [ $2 = 'USER' ]; then
  204. if [ -d "$VESTA/data/users/$user" ]; then
  205. sobject="OK"
  206. fi
  207. else
  208. if [ $2 = 'DBHOST' ]; then
  209. sobject=$(grep "HOST='$host'" $VESTA/conf/$type.conf)
  210. else
  211. sobject=$(grep "$2='$3'" $VESTA/data/users/$user/$1.conf)
  212. fi
  213. fi
  214. if [ -z "$sobject" ]; then
  215. echo "Error: $2 $3 doesn't exist"
  216. log_event "$E_NOTEXIST" "$EVENT"
  217. exit $E_NOTEXIST
  218. fi
  219. }
  220. # Check if object is supended
  221. is_object_suspended() {
  222. if [ $2 = 'USER' ]; then
  223. spnd=$(cat $USER_DATA/$1.conf|grep "SUSPENDED='yes'")
  224. else
  225. spnd=$(grep "$2='$3'" $USER_DATA/$1.conf|grep "SUSPENDED='yes'")
  226. fi
  227. if [ -z "$spnd" ]; then
  228. echo "Error: $(basename $1) $3 is not suspended"
  229. log_event "$E_SUSPENDED" "$EVENT"
  230. exit $E_SUSPENDED
  231. fi
  232. }
  233. # Check if object is unsupended
  234. is_object_unsuspended() {
  235. if [ $2 = 'USER' ]; then
  236. spnd=$(cat $USER_DATA/$1.conf|grep "SUSPENDED='yes'")
  237. else
  238. spnd=$(grep "$2='$3'" $USER_DATA/$1.conf|grep "SUSPENDED='yes'")
  239. fi
  240. if [ ! -z "$spnd" ]; then
  241. echo "Error: $(basename $1) $3 is suspended"
  242. log_event "$E_UNSUSPENDED" "$EVENT"
  243. exit $E_UNSUSPENDED
  244. fi
  245. }
  246. # Check if object value is empty
  247. is_object_value_empty() {
  248. str=$(grep "$2='$3'" $USER_DATA/$1.conf)
  249. eval $str
  250. eval value=$4
  251. if [ ! -z "$value" ] && [ "$value" != 'no' ]; then
  252. echo "Error: ${4//$}=$value (not empty)"
  253. log_event "$E_EXISTS" "$EVENT"
  254. exit $E_EXISTS
  255. fi
  256. }
  257. # Check if object value is empty
  258. is_object_value_exist() {
  259. str=$(grep "$2='$3'" $USER_DATA/$1.conf)
  260. eval $str
  261. eval value=$4
  262. if [ -z "$value" ] || [ "$value" = 'no' ]; then
  263. echo "Error: ${4//$}=$value (doesn't exist)"
  264. log_event "$E_NOTEXIST" "$EVENT"
  265. exit $E_NOTEXIST
  266. fi
  267. }
  268. # Check if password is transmitted via file
  269. is_password_valid() {
  270. if [[ "$password" =~ ^/tmp/ ]]; then
  271. if [ -f "$password" ]; then
  272. password=$(head -n1 $password)
  273. fi
  274. fi
  275. }
  276. # Get object value
  277. get_object_value() {
  278. object=$(grep "$2='$3'" $USER_DATA/$1.conf)
  279. eval "$object"
  280. eval echo $4
  281. }
  282. # Update object value
  283. update_object_value() {
  284. row=$(grep -nF "$2='$3'" $USER_DATA/$1.conf)
  285. lnr=$(echo $row | cut -f 1 -d ':')
  286. object=$(echo $row | sed "s/^$lnr://")
  287. eval "$object"
  288. eval old="$4"
  289. old=$(echo "$old" | sed -e 's/\\/\\\\/g' -e 's/&/\\&/g' -e 's/\//\\\//g')
  290. new=$(echo "$5" | sed -e 's/\\/\\\\/g' -e 's/&/\\&/g' -e 's/\//\\\//g')
  291. sed -i "$lnr s/${4//$/}='${old//\*/\\*}'/${4//$/}='${new//\*/\\*}'/g" \
  292. $USER_DATA/$1.conf
  293. }
  294. # Add object key
  295. add_object_key() {
  296. row=$(grep -n "$2='$3'" $USER_DATA/$1.conf)
  297. lnr=$(echo $row | cut -f 1 -d ':')
  298. object=$(echo $row | sed "s/^$lnr://")
  299. if [ -z "$(echo $object |grep $4=)" ]; then
  300. eval old="$4"
  301. sed -i "$lnr s/$5='/$4='' $5='/" $USER_DATA/$1.conf
  302. fi
  303. }
  304. # Search objects
  305. search_objects() {
  306. OLD_IFS="$IFS"
  307. IFS=$'\n'
  308. for line in $(grep $2=\'$3\' $USER_DATA/$1.conf); do
  309. eval $line
  310. eval echo \$$4
  311. done
  312. IFS="$OLD_IFS"
  313. }
  314. # Get user value
  315. get_user_value() {
  316. grep "^${1//$/}=" $USER_DATA/user.conf| cut -f 2 -d \'
  317. }
  318. # Update user value in user.conf
  319. update_user_value() {
  320. key="${2//$}"
  321. lnr=$(grep -n "^$key='" $VESTA/data/users/$1/user.conf |cut -f 1 -d ':')
  322. if [ ! -z "$lnr" ]; then
  323. sed -i "$lnr d" $VESTA/data/users/$1/user.conf
  324. sed -i "$lnr i\\$key='${3}'" $VESTA/data/users/$1/user.conf
  325. fi
  326. }
  327. # Increase user counter
  328. increase_user_value() {
  329. key="${2//$}"
  330. factor="${3-1}"
  331. conf="$VESTA/data/users/$1/user.conf"
  332. old=$(grep "$key=" $conf | cut -f 2 -d \')
  333. if [ -z "$old" ]; then
  334. old=0
  335. fi
  336. new=$((old + factor))
  337. sed -i "s/$key='$old'/$key='$new'/g" $conf
  338. }
  339. # Decrease user counter
  340. decrease_user_value() {
  341. key="${2//$}"
  342. factor="${3-1}"
  343. conf="$VESTA/data/users/$1/user.conf"
  344. old=$(grep "$key=" $conf | cut -f 2 -d \')
  345. if [ -z "$old" ]; then
  346. old=0
  347. fi
  348. if [ "$old" -le 1 ]; then
  349. new=0
  350. else
  351. new=$((old - factor))
  352. fi
  353. if [ "$new" -lt 0 ]; then
  354. new=0
  355. fi
  356. sed -i "s/$key='$old'/$key='$new'/g" $conf
  357. }
  358. # Json listing function
  359. json_list() {
  360. echo '{'
  361. fileds_count=$(echo $fields| wc -w )
  362. #for line in $(cat $conf); do
  363. while read line; do
  364. eval $line
  365. if [ -n "$data_output" ]; then
  366. echo -e ' },'
  367. fi
  368. i=1
  369. for field in $fields; do
  370. eval value=$field
  371. if [ $i -eq 1 ]; then
  372. (( ++i))
  373. echo -e "\t\"$value\": {"
  374. else
  375. if [ $i -lt $fileds_count ]; then
  376. (( ++i))
  377. echo -e "\t\t\"${field//$/}\": \"$value\","
  378. else
  379. echo -e "\t\t\"${field//$/}\": \"$value\""
  380. data_output=yes
  381. fi
  382. fi
  383. done
  384. done < $conf
  385. if [ "$data_output" = 'yes' ]; then
  386. echo -e ' }'
  387. fi
  388. echo -e '}'
  389. }
  390. # Shell listing function
  391. shell_list() {
  392. if [ -z "$nohead" ] ; then
  393. echo "${fields//$/}"
  394. for a in $fields; do
  395. echo -e "------ \c"
  396. done
  397. echo
  398. fi
  399. while read line ; do
  400. eval $line
  401. for field in $fields; do
  402. eval value=$field
  403. if [ -z "$value" ]; then
  404. value='NULL'
  405. fi
  406. echo -n "$value "
  407. done
  408. echo
  409. done < $conf
  410. }
  411. # Recalculate U_DISK value
  412. recalc_user_disk_usage() {
  413. u_usage=0
  414. if [ -f "$USER_DATA/web.conf" ]; then
  415. usage=0
  416. dusage=$(grep 'U_DISK=' $USER_DATA/web.conf |\
  417. awk -F "U_DISK='" '{print $2}' | cut -f 1 -d \')
  418. for disk_usage in $dusage; do
  419. usage=$((usage + disk_usage))
  420. done
  421. d=$(grep "U_DISK_WEB='" $USER_DATA/user.conf | cut -f 2 -d \')
  422. sed -i "s/U_DISK_WEB='$d'/U_DISK_WEB='$usage'/g" $USER_DATA/user.conf
  423. u_usage=$((u_usage + usage))
  424. fi
  425. if [ -f "$USER_DATA/mail.conf" ]; then
  426. usage=0
  427. dusage=$(grep 'U_DISK=' $USER_DATA/mail.conf |\
  428. awk -F "U_DISK='" '{print $2}' | cut -f 1 -d \')
  429. for disk_usage in $dusage; do
  430. usage=$((usage + disk_usage))
  431. done
  432. d=$(grep "U_DISK_MAIL='" $USER_DATA/user.conf | cut -f 2 -d \')
  433. sed -i "s/U_DISK_MAIL='$d'/U_DISK_MAIL='$usage'/g" $USER_DATA/user.conf
  434. u_usage=$((u_usage + usage))
  435. fi
  436. if [ -f "$USER_DATA/db.conf" ]; then
  437. usage=0
  438. dusage=$(grep 'U_DISK=' $USER_DATA/db.conf |\
  439. awk -F "U_DISK='" '{print $2}' | cut -f 1 -d \')
  440. for disk_usage in $dusage; do
  441. usage=$((usage + disk_usage))
  442. done
  443. d=$(grep "U_DISK_DB='" $USER_DATA/user.conf | cut -f 2 -d \')
  444. sed -i "s/U_DISK_DB='$d'/U_DISK_DB='$usage'/g" $USER_DATA/user.conf
  445. u_usage=$((u_usage + usage))
  446. fi
  447. usage=$(grep 'U_DISK_DIRS=' $USER_DATA/user.conf | cut -f 2 -d "'")
  448. u_usage=$((u_usage + usage))
  449. old=$(grep "U_DISK='" $USER_DATA/user.conf | cut -f 2 -d \')
  450. sed -i "s/U_DISK='$old'/U_DISK='$u_usage'/g" $USER_DATA/user.conf
  451. }
  452. # Recalculate U_BANDWIDTH value
  453. recalc_user_bandwidth_usage() {
  454. usage=0
  455. bandwidth_usage=$(grep 'U_BANDWIDTH=' $USER_DATA/web.conf |\
  456. awk -F "U_BANDWIDTH='" '{print $2}'|cut -f 1 -d \')
  457. for bandwidth in $bandwidth_usage; do
  458. usage=$((usage + bandwidth))
  459. done
  460. old=$(grep "U_BANDWIDTH='" $USER_DATA/user.conf | cut -f 2 -d \')
  461. sed -i "s/U_BANDWIDTH='$old'/U_BANDWIDTH='$usage'/g" $USER_DATA/user.conf
  462. }
  463. # Get next cron job id
  464. get_next_cronjob() {
  465. if [ -z "$job" ]; then
  466. curr_str=$(grep "JOB=" $USER_DATA/cron.conf|cut -f 2 -d \'|\
  467. sort -n|tail -n1)
  468. job="$((curr_str +1))"
  469. fi
  470. }
  471. # Sort cron jobs by id
  472. sort_cron_jobs() {
  473. cat $USER_DATA/cron.conf |sort -n -k 2 -t \' > $USER_DATA/cron.tmp
  474. mv -f $USER_DATA/cron.tmp $USER_DATA/cron.conf
  475. }
  476. # Sync cronjobs with system cron
  477. sync_cron_jobs() {
  478. source $USER_DATA/user.conf
  479. if [ -e "/var/spool/cron/crontabs" ]; then
  480. sys_cron="/var/spool/cron/crontabs/$user"
  481. else
  482. sys_cron="/var/spool/cron/$user"
  483. fi
  484. rm -f $sys_cron
  485. if [ "$CRON_REPORTS" = 'yes' ]; then
  486. echo "MAILTO=$CONTACT" > $sys_cron
  487. fi
  488. while read line; do
  489. eval $line
  490. if [ "$SUSPENDED" = 'no' ]; then
  491. echo "$MIN $HOUR $DAY $MONTH $WDAY $CMD" |\
  492. sed -e "s/%quote%/'/g" -e "s/%dots%/:/g" \
  493. >> $sys_cron
  494. fi
  495. done < $USER_DATA/cron.conf
  496. # Set proper permissions
  497. chown $user:$user $sys_cron
  498. chmod 600 $sys_cron
  499. }
  500. ### Format Validators ###
  501. # Shell
  502. validate_format_shell() {
  503. if [ -z "$(grep -w $1 /etc/shells)" ]; then
  504. echo "Error: shell $1 is not valid"
  505. log_event "$E_INVALID" "$EVENT"
  506. exit $E_INVALID
  507. fi
  508. }
  509. # Password
  510. validate_format_password() {
  511. if [ "${#1}" -lt '6' ]; then
  512. echo "Error: password is too short"
  513. log_event "$E_INVALID" "$EVENT"
  514. exit $E_INVALID
  515. fi
  516. }
  517. # Integer
  518. validate_format_int() {
  519. if ! [[ "$1" =~ ^[0-9]+$ ]] ; then
  520. echo "Error: $2 $1 is not valid"
  521. log_event "$E_INVALID" "$EVENT"
  522. exit $E_INVALID
  523. fi
  524. }
  525. # Boolean
  526. validate_format_boolean() {
  527. if [ "$1" != 'yes' ] && [ "$1" != 'no' ]; then
  528. echo "Error: $2 $1 is not valid"
  529. log_event "$E_INVALID" "$EVENT"
  530. exit $E_INVALID
  531. fi
  532. }
  533. # Network interface
  534. validate_format_interface() {
  535. netdevices=$(cat /proc/net/dev | grep : | cut -f 1 -d : | tr -d ' ')
  536. if [ -z $(echo "$netdevices"| grep -x $1) ]; then
  537. echo "Error: intreface $1 is not valid"
  538. log_event "$E_INVALID" "$EVENT"
  539. exit $E_INVALID
  540. fi
  541. }
  542. # IP address
  543. validate_format_ip() {
  544. t_ip=$(echo $1 |awk -F / '{print $1}')
  545. t_cidr=$(echo $1 |awk -F / '{print $2}')
  546. valid_octets=0
  547. valid_cidr=1
  548. for octet in ${t_ip//./ }; do
  549. if [[ $octet =~ ^[0-9]{1,3}$ ]] && [[ $octet -le 255 ]]; then
  550. ((++valid_octets))
  551. fi
  552. done
  553. if [ ! -z "$(echo $1|grep '/')" ]; then
  554. if [[ "$t_cidr" -lt 0 ]] || [[ "$t_cidr" -gt 32 ]]; then
  555. valid_cidr=0
  556. fi
  557. if ! [[ "$t_cidr" =~ ^[0-9]+$ ]]; then
  558. valid_cidr=0
  559. fi
  560. fi
  561. if [ "$valid_octets" -lt 4 ] || [ "$valid_cidr" -eq 0 ]; then
  562. echo "Error: ip $1 is not valid"
  563. log_event "$E_INVALID" "$EVENT"
  564. exit $E_INVALID
  565. fi
  566. }
  567. # IP address status
  568. validate_format_ip_status() {
  569. if [ -z "$(echo shared,dedicated | grep -w $1 )" ]; then
  570. echo "Error: ip_status $1 is not valid"
  571. log_event "$E_INVALID" "$EVENT"
  572. exit $E_INVALID
  573. fi
  574. }
  575. # Email address
  576. validate_format_email() {
  577. if [[ ! "$1" =~ "@" ]] ; then
  578. echo "Error: email $1 is not valid"
  579. log_event "$E_INVALID" "$EVENT"
  580. exit $E_INVALID
  581. fi
  582. }
  583. # Name
  584. validate_format_name() {
  585. if ! [[ "$1" =~ ^[[:alnum:]][-|\.|_[:alnum:]]{0,28}[[:alnum:]]$ ]]; then
  586. echo "Error: $2 $1 is not valid"
  587. log_event "$E_INVALID" "$EVENT"
  588. exit $E_INVALID
  589. fi
  590. }
  591. # Name with space
  592. validate_format_name_s() {
  593. if ! [[ "$1" =~ ^[[:alnum:]][-|\ |\.|_[:alnum:]]{0,28}[[:alnum:]]$ ]]; then
  594. echo "Error: $2 $1 is not valid"
  595. log_event "$E_INVALID" "$EVENT"
  596. exit $E_INVALID
  597. fi
  598. }
  599. # Username
  600. validate_format_username() {
  601. if [ "${#1}" -eq 1 ]; then
  602. if ! [[ "$1" =~ [a-z] ]]; then
  603. echo "Error: $2 $1 is not valid"
  604. log_event "$E_INVALID" "$EVENT"
  605. exit 1
  606. fi
  607. else
  608. if ! [[ "$1" =~ ^[a-zA-Z0-9][-|\.|_|a-zA-Z0-9]{0,28}[a-zA-Z0-9]$ ]]
  609. then
  610. echo "Error: $2 $1 is not valid"
  611. log_event "$E_INVALID" "$EVENT"
  612. exit 1
  613. fi
  614. fi
  615. }
  616. # Domain
  617. validate_format_domain() {
  618. exclude="[!|@|#|$|^|&|*|(|)|+|=|{|}|:|,|<|>|?|_|/|\|\"|'|;|%|\`| ]"
  619. if [[ "$1" =~ $exclude ]] || [[ "$1" =~ "^[0-9]+$" ]]; then
  620. echo "Error: $2 $1 is not valid"
  621. log_event "$E_INVALID" "$EVENT"
  622. exit $E_INVALID
  623. fi
  624. }
  625. # Domain alias
  626. validate_format_domain_alias() {
  627. exclude="[!|@|#|$|^|&|(|)|+|=|{|}|:|,|<|>|?|_|/|\|\"|'|;|%|\`| ]"
  628. if [[ "$1" =~ $exclude ]] || [[ "$1" =~ "^[0-9]+$" ]]; then
  629. echo "Error: $2 $1 is not valid"
  630. log_event "$E_INVALID" "$EVENT"
  631. exit $E_INVALID
  632. fi
  633. }
  634. # Database
  635. validate_format_database() {
  636. exclude="[!|@|#|$|^|&|*|(|)|+|=|{|}|:|,|<|>|?|/|\|\"|'|;|%|\`| ]"
  637. if [[ "$1" =~ $exclude ]] || [ 65 -le ${#1} ]; then
  638. echo "Error: $2 $1 is not valid"
  639. log_event "$E_INVALID" "$EVENT"
  640. exit $E_INVALID
  641. fi
  642. }
  643. # Database user
  644. validate_format_dbuser() {
  645. exclude="[!|@|#|$|^|&|*|(|)|+|=|{|}|:|,|<|>|?|/|\|\"|'|;|%|\`| ]"
  646. if [[ "$1" =~ $exclude ]] || [ 17 -le ${#1} ]; then
  647. echo "Error: $2 $1 is not valid"
  648. log_event "$E_INVALID" "$EVENT"
  649. exit $E_INVALID
  650. fi
  651. }
  652. # DNS type
  653. validate_format_dns_type() {
  654. known_dnstype='A,AAAA,NS,CNAME,MX,TXT,SRV,DNSKEY,KEY,IPSECKEY,PTR,SPF'
  655. if [ -z "$(echo $known_dnstype | grep -w $1)" ]; then
  656. echo "Error: dnstype $1 is not valid"
  657. log_event "$E_INVALID" "$EVENT"
  658. exit $E_INVALID
  659. fi
  660. }
  661. # DKIM key size
  662. validate_format_key_size() {
  663. known_size='128,256,512,768,1024,2048'
  664. if [ -z "$(echo $known_size | grep -w $1)" ]; then
  665. echo "Error: key_size $1 is not valid"
  666. log_event "$E_INVALID" "$EVENT"
  667. exit $E_INVALID
  668. fi
  669. }
  670. # Minute / Hour / Day / Month / Day of Week
  671. validate_format_mhdmw() {
  672. limit=60
  673. check_format=''
  674. if [ "$2" = 'day' ]; then
  675. limit=31
  676. fi
  677. if [ "$2" = 'month' ]; then
  678. limit=12
  679. fi
  680. if [ "$2" = 'wday' ]; then
  681. limit=7
  682. fi
  683. if [ "$1" = '*' ]; then
  684. check_format='ok'
  685. fi
  686. if [[ "$1" =~ ^[\*]+[/]+[0-9] ]]; then
  687. if [ "$(echo $1 |cut -f 2 -d /)" -lt $limit ]; then
  688. check_format='ok'
  689. fi
  690. fi
  691. if [[ "$1" =~ ^[0-9][-|,|0-9]{0,28}[0-9]$ ]]; then
  692. check_format='ok'
  693. crn_values=${1//,/ }
  694. crn_values=${crn_values//-/ }
  695. for crn_vl in $crn_values; do
  696. if [ "$crn_vl" -gt $limit ]; then
  697. check_format='invalid'
  698. fi
  699. done
  700. fi
  701. if [[ "$1" =~ ^[0-9]+$ ]] && [ "$1" -lt $limit ]; then
  702. check_format='ok'
  703. fi
  704. if [ "$check_format" != 'ok' ]; then
  705. echo "Error: $2 $1 is not valid"
  706. log_event "$E_INVALID" "$EVENT"
  707. exit $E_INVALID
  708. fi
  709. }
  710. # proxy extention or DNS record
  711. validate_format_common() {
  712. exclude="[!|#|$|^|&|(|)|+|=|{|}|:|<|>|?|/|\|\"|'|;|%|\`| ]"
  713. if [[ "$1" =~ $exclude ]]; then
  714. echo "Error: $2 $1 is not valid"
  715. log_event "$E_INVALID" "$EVENT"
  716. exit $E_INVALID
  717. fi
  718. if [ 400 -le ${#1} ]; then
  719. echo "Error: $2 $1 is too long"
  720. log_event "$E_INVALID" "$EVENT"
  721. exit $E_INVALID
  722. fi
  723. if [[ "$1" =~ @ ]] && [ ${#1} -gt 1 ] ; then
  724. echo "Error: @ can not be mixed"
  725. log_event "$E_INVALID" "$EVENT"
  726. exit $E_INVALID
  727. fi
  728. if [[ $1 =~ \* ]]; then
  729. if [ "$(echo $1 | grep -o '*'|wc -l)" -gt 1 ]; then
  730. log_event "$E_INVALID" "$EVENT"
  731. echo "Error: * can be used only once"
  732. fi
  733. fi
  734. }
  735. # DNS record value
  736. validate_format_dvalue() {
  737. record_types="$(echo A,AAAA,NS,CNAME | grep -w "$rtype")"
  738. if [[ "$1" =~ [\ ] ]] && [ ! -z "$record_types" ]; then
  739. echo "Error: dvalue $1 is not valid"
  740. log_event "$E_INVALID" "$EVENT"
  741. exit $E_INVALID
  742. fi
  743. if [ "$rtype" = 'A' ]; then
  744. validate_format_ip "$1"
  745. fi
  746. if [ "$rtype" = 'NS' ]; then
  747. validate_format_domain "$1" 'ns_record'
  748. fi
  749. if [ "$rtype" = 'MX' ]; then
  750. validate_format_domain "$1" 'mx_record'
  751. validate_format_int "$priority" 'priority_record'
  752. fi
  753. }
  754. # Date
  755. validate_format_date() {
  756. if ! [[ "$1" =~ ^[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]$ ]]; then
  757. echo "Error: date $1 is not valid"
  758. log_event "$E_INVALID" "$EVENT"
  759. exit $E_INVALID
  760. fi
  761. }
  762. # Autoreply
  763. validate_format_autoreply() {
  764. exclude="[$|\`]"
  765. if [[ "$1" =~ $exclude ]] || [ 10240 -le ${#1} ]; then
  766. echo "Error: autoreply is not valid"
  767. log_event "$E_INVALID" "$EVENT"
  768. exit $E_INVALID
  769. fi
  770. }
  771. # Firewall action
  772. validate_format_fw_action() {
  773. if [ "$1" != "ACCEPT" ] && [ "$1" != 'DROP' ] ; then
  774. echo "Error: $1 is not valid action"
  775. log_event "$E_INVALID" "$EVENT"
  776. exit $E_INVALID
  777. fi
  778. }
  779. # Firewall protocol
  780. validate_format_fw_protocol() {
  781. if [ "$1" != "ICMP" ] && [ "$1" != 'UDP' ] && [ "$1" != 'TCP' ] ; then
  782. echo "Error: $1 is not valid protocol"
  783. log_event "$E_INVALID" "$EVENT"
  784. exit $E_INVALID
  785. fi
  786. }
  787. # Firewall port
  788. validate_format_fw_port() {
  789. if [ "${#1}" -eq 1 ]; then
  790. if ! [[ "$1" =~ [0-9] ]]; then
  791. echo "Error: port $1 is not valid"
  792. log_event "$E_INVALID" "$EVENT"
  793. exit 1
  794. fi
  795. else
  796. if ! [[ "$1" =~ ^[0-9][-|,|:|0-9]{0,30}[0-9]$ ]]
  797. then
  798. echo "Error: port $1 is not valid"
  799. log_event "$E_INVALID" "$EVENT"
  800. exit 1
  801. fi
  802. fi
  803. }
  804. # Format validation controller
  805. validate_format(){
  806. for arg_name in $*; do
  807. eval arg=\$$arg_name
  808. if [ -z "$arg" ]; then
  809. echo "Error: argument $arg_name is not valid (empty)"
  810. log_event "$E_INVALID" "$EVENT"
  811. exit $E_INVALID
  812. fi
  813. case $arg_name in
  814. account) validate_format_username "$arg" "$arg_name" ;;
  815. action) validate_format_fw_action "$arg";;
  816. antispam) validate_format_boolean "$arg" 'antispam' ;;
  817. antivirus) validate_format_boolean "$arg" 'antivirus' ;;
  818. autoreply) validate_format_autoreply "$arg" ;;
  819. backup) validate_format_domain "$arg" 'backup' ;;
  820. charset) validate_format_name "$arg" "$arg_name" ;;
  821. charsets) validate_format_common "$arg" 'charsets' ;;
  822. comment) validate_format_name "$arg" 'comment' ;;
  823. database) validate_format_database "$arg" 'database';;
  824. day) validate_format_mhdmw "$arg" $arg_name ;;
  825. dbpass) validate_format_password "$arg" ;;
  826. dbuser) validate_format_dbuser "$arg" 'db_user';;
  827. dkim) validate_format_boolean "$arg" 'dkim' ;;
  828. dkim_size) validate_format_key_size "$arg" ;;
  829. domain) validate_format_domain "$arg" 'domain';;
  830. dom_alias) validate_format_domain_alias "$arg" 'alias';;
  831. dvalue) validate_format_dvalue "$arg";;
  832. email) validate_format_email "$arg" ;;
  833. exp) validate_format_date "$arg" ;;
  834. extentions) validate_format_common "$arg" 'extentions' ;;
  835. fname) validate_format_name_s "$arg" "$arg_name" ;;
  836. forward) validate_format_email "$arg" ;;
  837. ftp_password) validate_format_password "$arg" ;;
  838. ftp_user) validate_format_username "$arg" "$arg_name" ;;
  839. host) validate_format_domain "$arg" "$arg_name" 'host';;
  840. hour) validate_format_mhdmw "$arg" $arg_name ;;
  841. id) validate_format_int "$arg" 'id' ;;
  842. interface) validate_format_interface "$arg" ;;
  843. ip) validate_format_ip "$arg" ;;
  844. ip_name) validate_format_domain "$arg" 'domain';;
  845. ip_status) validate_format_ip_status "$arg" ;;
  846. job) validate_format_int "$arg" 'job' ;;
  847. key) validate_format_username "$arg" "$arg_name" ;;
  848. lname) validate_format_name_s "$arg" "$arg_name" ;;
  849. malias) validate_format_username "$arg" "$arg_name" ;;
  850. max_db) validate_format_int "$arg" 'max db';;
  851. min) validate_format_mhdmw "$arg" $arg_name ;;
  852. month) validate_format_mhdmw "$arg" $arg_name ;;
  853. nat_ip) validate_format_ip "$arg" ;;
  854. netmask) validate_format_ip "$arg" ;;
  855. newid) validate_format_int "$arg" 'id' ;;
  856. ns1) validate_format_domain "$arg" 'name_server';;
  857. ns2) validate_format_domain "$arg" 'name_server';;
  858. ns3) validate_format_domain "$arg" 'name_server';;
  859. ns4) validate_format_domain "$arg" 'name_server';;
  860. object) validate_format_name_s "$arg" 'object';;
  861. package) validate_format_name "$arg" "$arg_name" ;;
  862. password) validate_format_password "$arg" ;;
  863. port) validate_format_int "$arg" 'port' ;;
  864. port_ext) validate_format_fw_port "$arg";;
  865. protocol) validate_format_fw_protocol "$arg" ;;
  866. quota) validate_format_int "$arg" 'quota' ;;
  867. restart) validate_format_boolean "$arg" 'restart' ;;
  868. record) validate_format_common "$arg" 'record';;
  869. rtype) validate_format_dns_type "$arg" ;;
  870. rule) validate_format_int "$arg" "rule id" ;;
  871. shell) validate_format_shell "$arg" ;;
  872. soa) validate_format_domain "$arg" 'soa_record';;
  873. stats_pass) validate_format_password "$arg" ;;
  874. stats_user) validate_format_username "$arg" "$arg_name" ;;
  875. template) validate_format_name "$arg" "$arg_name" ;;
  876. ttl) validate_format_int "$arg" 'ttl';;
  877. user) validate_format_username "$arg" "$arg_name" ;;
  878. wday) validate_format_mhdmw "$arg" $arg_name ;;
  879. esac
  880. done
  881. }