main.sh 27 KB


  1. # Internal variables
  2. DATE=$(date +%F)
  3. TIME=$(date +%T)
  4. SCRIPT=$(basename $0)
  5. A1=$1
  6. A2=$2
  7. A3=$3
  8. A4=$4
  9. A5=$5
  10. A6=$6
  11. A7=$7
  12. A8=$8
  13. A9=$9
  14. EVENT="$DATE $TIME $SCRIPT $A1 $A2 $A3 $A4 $A5 $A6 $A7 $A8 $A9"
  15. HOMEDIR='/home'
  16. BACKUP='/backup'
  17. BACKUP_GZIP=5
  18. BACKUP_DISK_LIMIT=95
  19. BACKUP_LA_LIMIT=5
  20. RRD_STEP=300
  21. RRD_IFACE_EXCLUDE=lo
  22. PW_MATRIX='0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz'
  23. PW_LENGHT='10'
  24. BIN=$VESTA/bin
  25. USER_DATA=$VESTA/data/users/$user
  26. WEBTPL=$VESTA/data/templates/web
  27. DNSTPL=$VESTA/data/templates/dns
  28. RRD=$VESTA/web/rrd
  29. # Return codes
  30. OK=0
  31. E_ARGS=1
  32. E_INVALID=2
  33. E_NOTEXIST=3
  34. E_EXISTS=4
  35. E_SUSPENDED=5
  36. E_UNSUSPENDED=6
  37. E_INUSE=7
  38. E_LIMIT=8
  39. E_PASSWORD=9
  40. E_FORBIDEN=10
  41. E_DISABLED=11
  42. E_PARSING=12
  43. E_DISK=13
  44. E_LA=14
  45. E_CONNECT=15
  46. E_FTP=16
  47. E_DB=17
  48. E_RRD=18
  49. E_UPDATE=19
  50. E_RESTART=20
  51. # Log event function
  52. log_event() {
  53. if [ "$1" -eq 0 ]; then
  54. echo "$2" >> $VESTA/log/system.log
  55. else
  56. echo "$2 [Error $1]" >> $VESTA/log/error.log
  57. fi
  58. }
  59. # Log user history
  60. log_history() {
  61. cmd=$1
  62. undo=${2-no}
  63. log_user=${3-$user}
  64. log=$VESTA/data/users/$log_user/history.log
  65. touch $log
  66. if [ '99' -lt "$(wc -l $log |cut -f 1 -d ' ')" ]; then
  67. tail -n 49 $log > $log.moved
  68. mv -f $log.moved $log
  69. chmod 660 $log
  70. fi
  71. curr_str=$(grep "ID=" $log | cut -f 2 -d \' | sort -n | tail -n1)
  72. id="$((curr_str +1))"
  73. echo "ID='$id' DATE='$DATE' TIME='$TIME' CMD='$cmd' UNDO='$undo'" >> $log
  74. }
  75. # Argument list checker
  76. check_args() {
  77. if [ "$1" -gt "$2" ]; then
  78. echo "Error: not enought arguments"
  79. echo "Usage: $SCRIPT $3"
  80. log_event "$E_ARGS" "$EVENT"
  81. exit $E_ARGS
  82. fi
  83. }
  84. # Subsystem checker
  85. is_system_enabled() {
  86. if [ -z "$1" ] || [ "$1" = no ]; then
  87. echo "Error: $2 is not enabled in the $VESTA/conf/vesta.conf"
  88. log_event "$E_DISABLED" "$EVENT"
  89. exit $E_DISABLED
  90. fi
  91. }
  92. # User package check
  93. is_package_full() {
  94. case "$1" in
  95. WEB_DOMAINS) used=$(wc -l $USER_DATA/web.conf|cut -f1 -d \ );;
  96. WEB_ALIASES) used=$(grep "DOMAIN='$domain'" $USER_DATA/web.conf |\
  97. awk -F "ALIAS='" '{print $2}' | cut -f 1 -d \' | tr ',' '\n' |\
  98. wc -l );;
  99. DNS_DOMAINS) used=$(wc -l $USER_DATA/dns.conf |cut -f1 -d \ );;
  100. DNS_RECORDS) used=$(wc -l $USER_DATA/dns/$domain.conf |cut -f1 -d \ );;
  101. MAIL_DOMAINS) used=$(wc -l $USER_DATA/mail.conf |cut -f1 -d \ );;
  102. MAIL_ACCOUNTS) used=$(wc -l $USER_DATA/mail/$domain.conf |\
  103. cut -f1 -d \ );;
  104. DATABASES) used=$(wc -l $USER_DATA/db.conf |cut -f1 -d \ );;
  105. CRON_JOBS) used=$(wc -l $USER_DATA/cron.conf |cut -f1 -d \ );;
  106. esac
  107. limit=$(grep "^$1=" $USER_DATA/user.conf | cut -f 2 -d \' )
  108. if [ "$limit" != 'unlimited' ] && [ "$used" -ge "$limit" ]; then
  109. echo "Error: Limit is reached, please upgrade hosting package"
  110. log_event "$E_LIMIT" "$EVENT"
  111. exit $E_LIMIT
  112. fi
  113. }
  114. # Random password generator
  115. gen_password() {
  116. pw_matrix=${1-$PW_MATRIX}
  117. pw_lenght=${2-$PW_LENGHT}
  118. while [ ${n:=1} -le $pw_lenght ]; do
  119. pass="$pass${pw_matrix:$(($RANDOM%${#pw_matrix})):1}"
  120. let n+=1
  121. done
  122. echo "$pass"
  123. }
  124. # Package existance check
  125. is_package_valid() {
  126. if [ -z "$1" ]; then
  127. pkg_dir="$VESTA/data/packages"
  128. fi
  129. if [ ! -e "$pkg_dir/$package.pkg" ]; then
  130. echo "Error: package $package doesn't exist"
  131. log_event "$E_NOTEXIST" "$EVENT"
  132. exit $E_NOTEXIST
  133. fi
  134. }
  135. # Validate system type
  136. is_type_valid() {
  137. if [ -z "$(echo $1 | grep -w $2)" ]; then
  138. echo "Error: $2 is unknown type"
  139. log_event "$E_INVALID" "$EVENT"
  140. exit $E_INVALID
  141. fi
  142. }
  143. # Check if backup is available for user
  144. is_backup_available() {
  145. b_owner=$(echo $user |\
  146. sed -e "s/\.[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9].tar//")
  147. if [ "$user" != "$b_owner" ]; then
  148. echo "Error: User $user don't have permission to use $backup"
  149. log_event "$E_FORBIDEN" "$EVENT"
  150. exit $E_FORBIDEN
  151. fi
  152. }
  153. # Check user backup settings
  154. is_backup_enabled() {
  155. BACKUPS=$(grep "^BACKUPS=" $USER_DATA/user.conf | cut -f2 -d \')
  156. if [ -z "$BACKUPS" ] || [[ "$BACKUPS" -le '0' ]]; then
  157. echo "Error: user backup disabled"
  158. log_event "$E_DISABLED" "$EVENT"
  159. exit $E_DISABLED
  160. fi
  161. }
  162. # Check user backup settings
  163. is_backup_scheduled() {
  164. if [ -e "$VESTA/data/queue/backup.pipe" ]; then
  165. check_q=$(grep " $user " $VESTA/data/queue/backup.pipe | grep $1)
  166. if [ ! -z "$check_q" ]; then
  167. echo "Error: $1 is already scheduled"
  168. log_event "$E_EXISTS" "$EVENT"
  169. exit $E_EXISTS
  170. fi
  171. fi
  172. }
  173. # Check if object is new
  174. is_object_new() {
  175. if [ $2 = 'USER' ]; then
  176. if [ -d "$USER_DATA" ]; then
  177. object="OK"
  178. fi
  179. else
  180. object=$(grep "$2='$3'" $USER_DATA/$1.conf)
  181. fi
  182. if [ ! -z "$object" ]; then
  183. echo "Error: $2 with value $3 exists"
  184. log_event "$E_EXISTS" "$EVENT"
  185. exit $E_EXISTS
  186. fi
  187. }
  188. # Check if object exists and can be used
  189. is_object_valid() {
  190. if [ $2 = 'USER' ]; then
  191. if [ -d "$VESTA/data/users/$user" ]; then
  192. sobject="OK"
  193. fi
  194. else
  195. if [ $2 = 'DBHOST' ]; then
  196. sobject=$(grep "HOST='$host'" $VESTA/conf/$type.conf)
  197. else
  198. sobject=$(grep "$2='$3'" $VESTA/data/users/$user/$1.conf)
  199. fi
  200. fi
  201. if [ -z "$sobject" ]; then
  202. echo "Error: $2 $3 doesn't exist"
  203. log_event "$E_NOTEXIST" "$EVENT"
  204. exit $E_NOTEXIST
  205. fi
  206. }
  207. # Check if object is supended
  208. is_object_suspended() {
  209. if [ $2 = 'USER' ]; then
  210. spnd=$(cat $USER_DATA/$1.conf|grep "SUSPENDED='yes'")
  211. else
  212. spnd=$(grep "$2='$3'" $USER_DATA/$1.conf|grep "SUSPENDED='yes'")
  213. fi
  214. if [ -z "$spnd" ]; then
  215. echo "Error: $(basename $1) $3 is not suspended"
  216. log_event "$E_SUSPENDED" "$EVENT"
  217. exit $E_SUSPENDED
  218. fi
  219. }
  220. # Check if object is unsupended
  221. is_object_unsuspended() {
  222. if [ $2 = 'USER' ]; then
  223. spnd=$(cat $USER_DATA/$1.conf|grep "SUSPENDED='yes'")
  224. else
  225. spnd=$(grep "$2='$3'" $USER_DATA/$1.conf|grep "SUSPENDED='yes'")
  226. fi
  227. if [ ! -z "$spnd" ]; then
  228. echo "Error: $(basename $1) $3 is suspended"
  229. log_event "$E_UNSUSPENDED" "$EVENT"
  230. exit $E_UNSUSPENDED
  231. fi
  232. }
  233. # Check if object value is empty
  234. is_object_value_empty() {
  235. str=$(grep "$2='$3'" $USER_DATA/$1.conf)
  236. eval $str
  237. eval value=$4
  238. if [ ! -z "$value" ] && [ "$value" != 'no' ]; then
  239. echo "Error: ${4//$}=$value (not empty)"
  240. log_event "$E_EXISTS" "$EVENT"
  241. exit $E_EXISTS
  242. fi
  243. }
  244. # Check if object value is empty
  245. is_object_value_exist() {
  246. str=$(grep "$2='$3'" $USER_DATA/$1.conf)
  247. eval $str
  248. eval value=$4
  249. if [ -z "$value" ] || [ "$value" = 'no' ]; then
  250. echo "Error: ${4//$}=$value (doesn't exist)"
  251. log_event "$E_NOTEXIST" "$EVENT"
  252. exit $E_NOTEXIST
  253. fi
  254. }
  255. # Check if password is transmitted via file
  256. is_password_valid() {
  257. if [[ "$password" =~ ^/tmp/ ]]; then
  258. if [ -f "$password" ]; then
  259. password=$(head -n1 $password)
  260. fi
  261. fi
  262. }
  263. # Get object value
  264. get_object_value() {
  265. object=$(grep "$2='$3'" $USER_DATA/$1.conf)
  266. eval "$object"
  267. eval echo $4
  268. }
  269. # Update object value
  270. update_object_value() {
  271. row=$(grep -n "$2='$3'" $USER_DATA/$1.conf)
  272. lnr=$(echo $row | cut -f 1 -d ':')
  273. object=$(echo $row | sed "s/^$lnr://")
  274. eval "$object"
  275. eval old="$4"
  276. old=$(echo "$old" | sed -e 's/\\/\\\\/g' -e 's/&/\\&/g' -e 's/\//\\\//g')
  277. new=$(echo "$5" | sed -e 's/\\/\\\\/g' -e 's/&/\\&/g' -e 's/\//\\\//g')
  278. sed -i "$lnr s/${4//$/}='${old//\*/\\*}'/${4//$/}='${new//\*/\\*}'/g" \
  279. $USER_DATA/$1.conf
  280. }
  281. # Add object key
  282. add_object_key() {
  283. row=$(grep -n "$2='$3'" $USER_DATA/$1.conf)
  284. lnr=$(echo $row | cut -f 1 -d ':')
  285. object=$(echo $row | sed "s/^$lnr://")
  286. if [ -z "$(echo $object |grep $4=)" ]; then
  287. eval old="$4"
  288. sed -i "$lnr s/$5='/$4='' $5='/" $USER_DATA/$1.conf
  289. fi
  290. }
  291. # Search objects
  292. search_objects() {
  293. OLD_IFS="$IFS"
  294. IFS=$'\n'
  295. for line in $(grep $2=\'$3\' $USER_DATA/$1.conf); do
  296. eval $line
  297. eval echo \$$4
  298. done
  299. IFS="$OLD_IFS"
  300. }
  301. # Get user value
  302. get_user_value() {
  303. grep "^${1//$/}=" $USER_DATA/user.conf| cut -f 2 -d \'
  304. }
  305. # Update user value in user.conf
  306. update_user_value() {
  307. key="${2//$}"
  308. lnr=$(grep -n "^$key='" $VESTA/data/users/$1/user.conf |cut -f 1 -d ':')
  309. if [ ! -z "$lnr" ]; then
  310. sed -i "$lnr d" $VESTA/data/users/$1/user.conf
  311. sed -i "$lnr i\\$key='${3}'" $VESTA/data/users/$1/user.conf
  312. fi
  313. }
  314. # Increase user counter
  315. increase_user_value() {
  316. key="${2//$}"
  317. factor="${3-1}"
  318. conf="$VESTA/data/users/$1/user.conf"
  319. old=$(grep "$key=" $conf | cut -f 2 -d \')
  320. if [ -z "$old" ]; then
  321. old=0
  322. fi
  323. new=$((old + factor))
  324. sed -i "s/$key='$old'/$key='$new'/g" $conf
  325. }
  326. # Decrease user counter
  327. decrease_user_value() {
  328. key="${2//$}"
  329. factor="${3-1}"
  330. conf="$VESTA/data/users/$1/user.conf"
  331. old=$(grep "$key=" $conf | cut -f 2 -d \')
  332. if [ -z "$old" ]; then
  333. old=0
  334. fi
  335. if [ "$old" -le 1 ]; then
  336. new=0
  337. else
  338. new=$((old - factor))
  339. fi
  340. if [ "$new" -lt 0 ]; then
  341. new=0
  342. fi
  343. sed -i "s/$key='$old'/$key='$new'/g" $conf
  344. }
  345. # Json listing function
  346. json_list() {
  347. echo '{'
  348. fileds_count=$(echo $fields| wc -w )
  349. #for line in $(cat $conf); do
  350. while read line; do
  351. eval $line
  352. if [ -n "$data_output" ]; then
  353. echo -e ' },'
  354. fi
  355. i=1
  356. for field in $fields; do
  357. eval value=$field
  358. if [ $i -eq 1 ]; then
  359. (( ++i))
  360. echo -e "\t\"$value\": {"
  361. else
  362. if [ $i -lt $fileds_count ]; then
  363. (( ++i))
  364. echo -e "\t\t\"${field//$/}\": \"$value\","
  365. else
  366. echo -e "\t\t\"${field//$/}\": \"$value\""
  367. data_output=yes
  368. fi
  369. fi
  370. done
  371. done < $conf
  372. if [ "$data_output" = 'yes' ]; then
  373. echo -e ' }'
  374. fi
  375. echo -e '}'
  376. }
  377. # Shell listing function
  378. shell_list() {
  379. if [ -z "$nohead" ] ; then
  380. echo "${fields//$/}"
  381. for a in $fields; do
  382. echo -e "------ \c"
  383. done
  384. echo
  385. fi
  386. while read line ; do
  387. eval $line
  388. for field in $fields; do
  389. eval value=$field
  390. if [ -z "$value" ]; then
  391. value='NULL'
  392. fi
  393. echo -n "$value "
  394. done
  395. echo
  396. done < $conf
  397. }
  398. # Recalculate U_DISK value
  399. recalc_user_disk_usage() {
  400. u_usage=0
  401. if [ -f "$USER_DATA/web.conf" ]; then
  402. usage=0
  403. dusage=$(grep 'U_DISK=' $USER_DATA/web.conf |\
  404. awk -F "U_DISK='" '{print $2}' | cut -f 1 -d \')
  405. for disk_usage in $dusage; do
  406. usage=$((usage + disk_usage))
  407. done
  408. d=$(grep "U_DISK_WEB='" $USER_DATA/user.conf | cut -f 2 -d \')
  409. sed -i "s/U_DISK_WEB='$d'/U_DISK_WEB='$usage'/g" $USER_DATA/user.conf
  410. u_usage=$((u_usage + usage))
  411. fi
  412. if [ -f "$USER_DATA/mail.conf" ]; then
  413. usage=0
  414. dusage=$(grep 'U_DISK=' $USER_DATA/mail.conf |\
  415. awk -F "U_DISK='" '{print $2}' | cut -f 1 -d \')
  416. for disk_usage in $dusage; do
  417. usage=$((usage + disk_usage))
  418. done
  419. d=$(grep "U_DISK_MAIL='" $USER_DATA/user.conf | cut -f 2 -d \')
  420. sed -i "s/U_DISK_MAIL='$d'/U_DISK_MAIL='$usage'/g" $USER_DATA/user.conf
  421. u_usage=$((u_usage + usage))
  422. fi
  423. if [ -f "$USER_DATA/db.conf" ]; then
  424. usage=0
  425. dusage=$(grep 'U_DISK=' $USER_DATA/db.conf |\
  426. awk -F "U_DISK='" '{print $2}' | cut -f 1 -d \')
  427. for disk_usage in $dusage; do
  428. usage=$((usage + disk_usage))
  429. done
  430. d=$(grep "U_DISK_DB='" $USER_DATA/user.conf | cut -f 2 -d \')
  431. sed -i "s/U_DISK_DB='$d'/U_DISK_DB='$usage'/g" $USER_DATA/user.conf
  432. u_usage=$((u_usage + usage))
  433. fi
  434. usage=$(grep 'U_DISK_DIRS=' $USER_DATA/user.conf | cut -f 2 -d "'")
  435. u_usage=$((u_usage + usage))
  436. old=$(grep "U_DISK='" $USER_DATA/user.conf | cut -f 2 -d \')
  437. sed -i "s/U_DISK='$old'/U_DISK='$u_usage'/g" $USER_DATA/user.conf
  438. }
  439. # Recalculate U_BANDWIDTH value
  440. recalc_user_bandwidth_usage() {
  441. usage=0
  442. bandwidth_usage=$(grep 'U_BANDWIDTH=' $USER_DATA/web.conf |\
  443. awk -F "U_BANDWIDTH='" '{print $2}'|cut -f 1 -d \')
  444. for bandwidth in $bandwidth_usage; do
  445. usage=$((usage + bandwidth))
  446. done
  447. old=$(grep "U_BANDWIDTH='" $USER_DATA/user.conf | cut -f 2 -d \')
  448. sed -i "s/U_BANDWIDTH='$old'/U_BANDWIDTH='$usage'/g" $USER_DATA/user.conf
  449. }
  450. # Get next cron job id
  451. get_next_cronjob() {
  452. if [ -z "$job" ]; then
  453. curr_str=$(grep "JOB=" $USER_DATA/cron.conf|cut -f 2 -d \'|\
  454. sort -n|tail -n1)
  455. job="$((curr_str +1))"
  456. fi
  457. }
  458. # Sort cron jobs by id
  459. sort_cron_jobs() {
  460. cat $USER_DATA/cron.conf |sort -n -k 2 -t \' > $USER_DATA/cron.tmp
  461. mv -f $USER_DATA/cron.tmp $USER_DATA/cron.conf
  462. }
  463. # Sync cronjobs with system cron
  464. sync_cron_jobs() {
  465. source $USER_DATA/user.conf
  466. if [ -e "/var/spool/cron/crontabs" ]; then
  467. sys_cron="/var/spool/cron/crontabs/$user"
  468. else
  469. sys_cron="/var/spool/cron/$user"
  470. fi
  471. rm -f $sys_cron
  472. if [ "$CRON_REPORTS" = 'yes' ]; then
  473. echo "MAILTO=$CONTACT" > $sys_cron
  474. fi
  475. while read line; do
  476. eval $line
  477. if [ "$SUSPENDED" = 'no' ]; then
  478. echo "$MIN $HOUR $DAY $MONTH $WDAY $CMD" |\
  479. sed -e "s/%quote%/'/g" -e "s/%dots%/:/g" \
  480. >> $sys_cron
  481. fi
  482. done < $USER_DATA/cron.conf
  483. # Set proper permissions
  484. chown $user:$user $sys_cron
  485. chmod 600 $sys_cron
  486. }
  487. ### Format Validators ###
  488. # Shell
  489. validate_format_shell() {
  490. if [ -z "$(grep -w $1 /etc/shells)" ]; then
  491. echo "Error: shell $1 is not valid"
  492. log_event "$E_INVALID" "$EVENT"
  493. exit $E_INVALID
  494. fi
  495. }
  496. # Password
  497. validate_format_password() {
  498. if [ "${#1}" -lt '6' ]; then
  499. echo "Error: password is too short"
  500. log_event "$E_INVALID" "$EVENT"
  501. exit $E_INVALID
  502. fi
  503. }
  504. # Integer
  505. validate_format_int() {
  506. if ! [[ "$1" =~ ^[0-9]+$ ]] ; then
  507. echo "Error: $2 $1 is not valid"
  508. log_event "$E_INVALID" "$EVENT"
  509. exit $E_INVALID
  510. fi
  511. }
  512. # Boolean
  513. validate_format_boolean() {
  514. if [ "$1" != 'yes' ] && [ "$1" != 'no' ]; then
  515. echo "Error: $2 $1 is not valid"
  516. log_event "$E_INVALID" "$EVENT"
  517. exit $E_INVALID
  518. fi
  519. }
  520. # Network interface
  521. validate_format_interface() {
  522. netdevices=$(cat /proc/net/dev | grep : | cut -f 1 -d : | tr -d ' ')
  523. if [ -z $(echo "$netdevices"| grep -x $1) ]; then
  524. echo "Error: intreface $1 is not valid"
  525. log_event "$E_INVALID" "$EVENT"
  526. exit $E_INVALID
  527. fi
  528. }
  529. # IP address
  530. validate_format_ip() {
  531. t_ip=$(echo $1 |awk -F / '{print $1}')
  532. t_cidr=$(echo $1 |awk -F / '{print $2}')
  533. valid_octets=0
  534. valid_cidr=1
  535. for octet in ${t_ip//./ }; do
  536. if [[ $octet =~ ^[0-9]{1,3}$ ]] && [[ $octet -le 255 ]]; then
  537. ((++valid_octets))
  538. fi
  539. done
  540. if [ ! -z "$(echo $1|grep '/')" ]; then
  541. if [[ "$t_cidr" -lt 0 ]] || [[ "$t_cidr" -gt 32 ]]; then
  542. valid_cidr=0
  543. fi
  544. if ! [[ "$t_cidr" =~ ^[0-9]+$ ]]; then
  545. valid_cidr=0
  546. fi
  547. fi
  548. if [ "$valid_octets" -lt 4 ] || [ "$valid_cidr" -eq 0 ]; then
  549. echo "Error: ip $1 is not valid"
  550. log_event "$E_INVALID" "$EVENT"
  551. exit $E_INVALID
  552. fi
  553. }
  554. # IP address status
  555. validate_format_ip_status() {
  556. if [ -z "$(echo shared,dedicated | grep -w $1 )" ]; then
  557. echo "Error: ip_status $1 is not valid"
  558. log_event "$E_INVALID" "$EVENT"
  559. exit $E_INVALID
  560. fi
  561. }
  562. # Email address
  563. validate_format_email() {
  564. local_part=$(echo $1 | cut -s -f1 -d\@)
  565. remote_host=$(echo $1 | cut -s -f2 -d\@)
  566. mx_failed=1
  567. if [ ! -z "$remote_host" ] && [ ! -z "$local_part" ]; then
  568. /usr/bin/host -t mx "$remote_host" &> /dev/null
  569. mx_failed="$?"
  570. fi
  571. if [ "$mx_failed" -eq 1 ]; then
  572. echo "Error: email $1 is not valid"
  573. log_event "$E_INVALID" "$EVENT"
  574. exit $E_INVALID
  575. fi
  576. }
  577. # Name
  578. validate_format_name() {
  579. if ! [[ "$1" =~ ^[[:alnum:]][-|\.|_[:alnum:]]{0,28}[[:alnum:]]$ ]]; then
  580. echo "Error: $2 $1 is not valid"
  581. log_event "$E_INVALID" "$EVENT"
  582. exit $E_INVALID
  583. fi
  584. }
  585. # Name with space
  586. validate_format_name_s() {
  587. if ! [[ "$1" =~ ^[[:alnum:]][-|\ |\.|_[:alnum:]]{0,28}[[:alnum:]]$ ]]; then
  588. echo "Error: $2 $1 is not valid"
  589. log_event "$E_INVALID" "$EVENT"
  590. exit $E_INVALID
  591. fi
  592. }
  593. # Username
  594. validate_format_username() {
  595. if [ "${#1}" -eq 1 ]; then
  596. if ! [[ "$1" =~ [a-z] ]]; then
  597. echo "Error: $2 $1 is not valid"
  598. log_event "$E_INVALID" "$EVENT"
  599. exit 1
  600. fi
  601. else
  602. if ! [[ "$1" =~ ^[a-zA-Z0-9][-|\.|_|a-zA-Z0-9]{0,28}[a-zA-Z0-9]$ ]]
  603. then
  604. echo "Error: $2 $1 is not valid"
  605. log_event "$E_INVALID" "$EVENT"
  606. exit 1
  607. fi
  608. fi
  609. }
  610. # Domain
  611. validate_format_domain() {
  612. exclude="[!|@|#|$|^|&|*|(|)|+|=|{|}|:|,|<|>|?|_|/|\|\"|'|;|%|\`| ]"
  613. if [[ "$1" =~ $exclude ]] || [[ "$1" =~ "^[0-9]+$" ]]; then
  614. echo "Error: $2 $1 is not valid"
  615. log_event "$E_INVALID" "$EVENT"
  616. exit $E_INVALID
  617. fi
  618. }
  619. # Domain alias
  620. validate_format_domain_alias() {
  621. exclude="[!|@|#|$|^|&|(|)|+|=|{|}|:|,|<|>|?|_|/|\|\"|'|;|%|\`| ]"
  622. if [[ "$1" =~ $exclude ]] || [[ "$1" =~ "^[0-9]+$" ]]; then
  623. echo "Error: domain alias $1 is not valid"
  624. log_event "$E_INVALID" "$EVENT"
  625. exit $E_INVALID
  626. fi
  627. }
  628. # Database
  629. validate_format_database() {
  630. exclude="[!|@|#|$|^|&|*|(|)|+|=|{|}|:|,|<|>|?|/|\|\"|'|;|%|\`| ]"
  631. if [[ "$1" =~ $exclude ]] || [ 65 -le ${#1} ]; then
  632. echo "Error: $2 $1 is not valid"
  633. log_event "$E_INVALID" "$EVENT"
  634. exit $E_INVALID
  635. fi
  636. }
  637. # Database user
  638. validate_format_dbuser() {
  639. exclude="[!|@|#|$|^|&|*|(|)|+|=|{|}|:|,|<|>|?|/|\|\"|'|;|%|\`| ]"
  640. if [[ "$1" =~ $exclude ]] || [ 17 -le ${#1} ]; then
  641. echo "Error: $2 $1 is not valid"
  642. log_event "$E_INVALID" "$EVENT"
  643. exit $E_INVALID
  644. fi
  645. }
  646. # DNS type
  647. validate_format_dns_type() {
  648. known_dnstype='A,AAAA,NS,CNAME,MX,TXT,SRV,DNSKEY,KEY,IPSECKEY,PTR,SPF'
  649. if [ -z "$(echo $known_dnstype | grep -w $1)" ]; then
  650. echo "Error: dnstype $1 is not valid"
  651. log_event "$E_INVALID" "$EVENT"
  652. exit $E_INVALID
  653. fi
  654. }
  655. # DKIM key size
  656. validate_format_key_size() {
  657. known_size='128,256,512,768,1024,2048'
  658. if [ -z "$(echo $known_size | grep -w $1)" ]; then
  659. echo "Error: key_size $1 is not valid"
  660. log_event "$E_INVALID" "$EVENT"
  661. exit $E_INVALID
  662. fi
  663. }
  664. # Minute / Hour / Day / Month / Day of Week
  665. validate_format_mhdmw() {
  666. limit=60
  667. check_format=''
  668. if [ "$2" = 'day' ]; then
  669. limit=31
  670. fi
  671. if [ "$2" = 'month' ]; then
  672. limit=12
  673. fi
  674. if [ "$2" = 'wday' ]; then
  675. limit=7
  676. fi
  677. if [ "$1" = '*' ]; then
  678. check_format='ok'
  679. fi
  680. if [[ "$1" =~ ^[\*]+[/]+[0-9] ]]; then
  681. if [ "$(echo $1 |cut -f 2 -d /)" -lt $limit ]; then
  682. check_format='ok'
  683. fi
  684. fi
  685. if [[ "$1" =~ ^[0-9][-|,|0-9]{0,28}[0-9]$ ]]; then
  686. check_format='ok'
  687. crn_values=${1//,/ }
  688. crn_values=${crn_values//-/ }
  689. for crn_vl in $crn_values; do
  690. if [ "$crn_vl" -gt $limit ]; then
  691. check_format='invalid'
  692. fi
  693. done
  694. fi
  695. if [[ "$1" =~ ^[0-9]+$ ]] && [ "$1" -lt $limit ]; then
  696. check_format='ok'
  697. fi
  698. if [ "$check_format" != 'ok' ]; then
  699. echo "Error: $2 $1 is not valid"
  700. log_event "$E_INVALID" "$EVENT"
  701. exit $E_INVALID
  702. fi
  703. }
  704. # proxy extention or DNS record
  705. validate_format_common() {
  706. exclude="[!|#|$|^|&|(|)|+|=|{|}|:|<|>|?|/|\|\"|'|;|%|\`| ]"
  707. if [[ "$1" =~ $exclude ]]; then
  708. echo "Error: $2 $1 is not valid"
  709. log_event "$E_INVALID" "$EVENT"
  710. exit $E_INVALID
  711. fi
  712. if [ 400 -le ${#1} ]; then
  713. echo "Error: $2 $1 is too long"
  714. log_event "$E_INVALID" "$EVENT"
  715. exit $E_INVALID
  716. fi
  717. if [[ "$1" =~ @ ]] && [ ${#1} -gt 1 ] ; then
  718. echo "Error: @ can not be mixed"
  719. log_event "$E_INVALID" "$EVENT"
  720. exit $E_INVALID
  721. fi
  722. if [[ $1 =~ \* ]]; then
  723. if [[ ! $1 =~ \*$ ]]; then
  724. echo "Error: * can be used only at the end"
  725. log_event "$E_INVALID" "$EVENT"
  726. exit $E_INVALID
  727. fi
  728. if [ "$(echo $1 | grep -o '*'|wc -l)" -gt 1 ]; then
  729. log_event "$E_INVALID" "$EVENT"
  730. echo "Error: * can be used only once"
  731. fi
  732. fi
  733. }
  734. # DNS record value
  735. validate_format_dvalue() {
  736. record_types="$(echo A,AAAA,NS,CNAME | grep -w "$rtype")"
  737. if [[ "$1" =~ [\ ] ]] && [ ! -z "$record_types" ]; then
  738. echo "Error: dvalue $1 is not valid"
  739. log_event "$E_INVALID" "$EVENT"
  740. exit $E_INVALID
  741. fi
  742. if [ "$rtype" = 'A' ]; then
  743. validate_format_ip "$1"
  744. fi
  745. if [ "$rtype" = 'NS' ]; then
  746. validate_format_domain "$1" 'ns_record'
  747. fi
  748. if [ "$rtype" = 'MX' ]; then
  749. validate_format_domain "$1" 'mx_record'
  750. validate_format_int "$priority" 'priority_record'
  751. fi
  752. }
  753. # Date
  754. validate_format_date() {
  755. if ! [[ "$1" =~ ^[0-9][0-9][0-9][0-9]-[0-9][0-9]-[0-9][0-9]$ ]]; then
  756. echo "Error: date $1 is not valid"
  757. log_event "$E_INVALID" "$EVENT"
  758. exit $E_INVALID
  759. fi
  760. }
  761. # Autoreply
  762. validate_format_autoreply() {
  763. exclude="[$|\`]"
  764. if [[ "$1" =~ $exclude ]] || [ 10240 -le ${#1} ]; then
  765. echo "Error: autoreply is not valid"
  766. log_event "$E_INVALID" "$EVENT"
  767. exit $E_INVALID
  768. fi
  769. }
  770. # Firewall action
  771. validate_format_fw_action() {
  772. if [ "$1" != "ACCEPT" ] && [ "$1" != 'DROP' ] ; then
  773. echo "Error: $1 is not valid action"
  774. log_event "$E_INVALID" "$EVENT"
  775. exit $E_INVALID
  776. fi
  777. }
  778. # Firewall protocol
  779. validate_format_fw_protocol() {
  780. if [ "$1" != "ICMP" ] && [ "$1" != 'UDP' ] && [ "$1" != 'TCP' ] ; then
  781. echo "Error: $1 is not valid protocol"
  782. log_event "$E_INVALID" "$EVENT"
  783. exit $E_INVALID
  784. fi
  785. }
  786. # Firewall port
  787. validate_format_fw_port() {
  788. if [ "${#1}" -eq 1 ]; then
  789. if ! [[ "$1" =~ [0-9] ]]; then
  790. echo "Error: port $1 is not valid"
  791. log_event "$E_INVALID" "$EVENT"
  792. exit 1
  793. fi
  794. else
  795. if ! [[ "$1" =~ ^[0-9][-|,|:|0-9]{0,30}[0-9]$ ]]
  796. then
  797. echo "Error: port $1 is not valid"
  798. log_event "$E_INVALID" "$EVENT"
  799. exit 1
  800. fi
  801. fi
  802. }
  803. # Format validation controller
  804. validate_format(){
  805. for arg_name in $*; do
  806. eval arg=\$$arg_name
  807. if [ -z "$arg" ]; then
  808. echo "Error: argument $arg_name is not valid (empty)"
  809. log_event "$E_INVALID" "$EVENT"
  810. exit $E_INVALID
  811. fi
  812. case $arg_name in
  813. account) validate_format_username "$arg" "$arg_name" ;;
  814. action) validate_format_fw_action "$arg";;
  815. antispam) validate_format_boolean "$arg" 'antispam' ;;
  816. antivirus) validate_format_boolean "$arg" 'antivirus' ;;
  817. autoreply) validate_format_autoreply "$arg" ;;
  818. backup) validate_format_domain "$arg" 'backup' ;;
  819. charset) validate_format_name "$arg" "$arg_name" ;;
  820. charsets) validate_format_common "$arg" 'charsets' ;;
  821. comment) validate_format_name "$arg" 'comment' ;;
  822. database) validate_format_database "$arg" 'database';;
  823. day) validate_format_mhdmw "$arg" $arg_name ;;
  824. dbpass) validate_format_password "$arg" ;;
  825. dbuser) validate_format_dbuser "$arg" 'db_user';;
  826. dkim) validate_format_boolean "$arg" 'dkim' ;;
  827. dkim_size) validate_format_key_size "$arg" ;;
  828. domain) validate_format_domain "$arg" 'domain';;
  829. dom_alias) validate_format_domain_alias "$arg" 'alias';;
  830. dvalue) validate_format_dvalue "$arg";;
  831. email) validate_format_email "$arg" ;;
  832. exp) validate_format_date "$arg" ;;
  833. extentions) validate_format_common "$arg" 'extentions' ;;
  834. fname) validate_format_name_s "$arg" "$arg_name" ;;
  835. forward) validate_format_email "$arg" ;;
  836. ftp_password) validate_format_password "$arg" ;;
  837. ftp_user) validate_format_username "$arg" "$arg_name" ;;
  838. host) validate_format_domain "$arg" "$arg_name" 'host';;
  839. hour) validate_format_mhdmw "$arg" $arg_name ;;
  840. id) validate_format_int "$arg" 'id' ;;
  841. interface) validate_format_interface "$arg" ;;
  842. ip) validate_format_ip "$arg" ;;
  843. ip_name) validate_format_domain "$arg" 'domain';;
  844. ip_status) validate_format_ip_status "$arg" ;;
  845. job) validate_format_int "$arg" 'job' ;;
  846. key) validate_format_username "$arg" "$arg_name" ;;
  847. lname) validate_format_name_s "$arg" "$arg_name" ;;
  848. malias) validate_format_username "$arg" "$arg_name" ;;
  849. max_db) validate_format_int "$arg" 'max db';;
  850. min) validate_format_mhdmw "$arg" $arg_name ;;
  851. month) validate_format_mhdmw "$arg" $arg_name ;;
  852. nat_ip) validate_format_ip "$arg" ;;
  853. netmask) validate_format_ip "$arg" ;;
  854. newid) validate_format_int "$arg" 'id' ;;
  855. ns1) validate_format_domain "$arg" 'name_server';;
  856. ns2) validate_format_domain "$arg" 'name_server';;
  857. ns3) validate_format_domain "$arg" 'name_server';;
  858. ns4) validate_format_domain "$arg" 'name_server';;
  859. package) validate_format_name "$arg" "$arg_name" ;;
  860. password) validate_format_password "$arg" ;;
  861. port) validate_format_int "$arg" 'port' ;;
  862. port_ext) validate_format_fw_port "$arg";;
  863. protocol) validate_format_fw_protocol "$arg" ;;
  864. quota) validate_format_int "$arg" 'quota' ;;
  865. restart) validate_format_boolean "$arg" 'restart' ;;
  866. record) validate_format_common "$arg" 'record';;
  867. rtype) validate_format_dns_type "$arg" ;;
  868. rule) validate_format_int "$arg" "rule id" ;;
  869. shell) validate_format_shell "$arg" ;;
  870. soa) validate_format_domain "$arg" 'soa_record';;
  871. stats_pass) validate_format_password "$arg" ;;
  872. stats_user) validate_format_username "$arg" "$arg_name" ;;
  873. template) validate_format_name "$arg" "$arg_name" ;;
  874. ttl) validate_format_int "$arg" 'ttl';;
  875. user) validate_format_username "$arg" "$arg_name" ;;
  876. wday) validate_format_mhdmw "$arg" $arg_name ;;
  877. esac
  878. done
  879. }