Track tainted data and refuse to expand it
[exim.git] / src / src / lookups / nisplus.c
1 /*************************************************
2 * Exim - an Internet mail transport agent *
3 *************************************************/
4
5 /* Copyright (c) University of Cambridge 1995 - 2018 */
6 /* See the file NOTICE for conditions of use and distribution. */
7
8 #include "../exim.h"
9 #include "lf_functions.h"
10
11 #include <rpcsvc/nis.h>
12
13
14 /*************************************************
15 * Open entry point *
16 *************************************************/
17
18 /* See local README for interface description. */
19
20 static void *
21 nisplus_open(uschar *filename, uschar **errmsg)
22 {
23 return (void *)(1); /* Just return something non-null */
24 }
25
26
27
28 /*************************************************
29 * Find entry point *
30 *************************************************/
31
32 /* See local README for interface description. The format of queries for a
33 NIS+ search is
34
35 [field=value,...],table-name
36 or
37 [field=value,...],table-name:result-field-name
38
39 in other words, a normal NIS+ "indexed name", with an optional result field
40 name tagged on the end after a colon. If there is no result-field name, the
41 yield is the concatenation of all the fields, preceded by their names and an
42 equals sign. */
43
44 static int
45 nisplus_find(void *handle, uschar *filename, const uschar *query, int length,
46 uschar **result, uschar **errmsg, uint *do_cache)
47 {
48 int error_error = FAIL;
49 const uschar * field_name = NULL;
50 nis_result *nrt = NULL;
51 nis_result *nre = NULL;
52 nis_object *tno, *eno;
53 struct entry_obj *eo;
54 struct table_obj *ta;
55 const uschar * p = query + length;
56 gstring * yield = NULL;
57
58 do_cache = do_cache; /* Placate picky compilers */
59
60 /* Search backwards for a colon to see if a result field name
61 has been given. */
62
63 while (p > query && p[-1] != ':') p--;
64
65 if (p > query) /* get the query without the result-field */
66 {
67 uint len = p-1 - query;
68 field_name = p;
69 query = string_copyn(query, len);
70 p = query + len;
71 }
72 else
73 p = query + length;
74
75 /* Now search backwards to find the comma that starts the
76 table name. */
77
78 while (p > query && p[-1] != ',') p--;
79 if (p <= query)
80 {
81 *errmsg = US"NIS+ query malformed";
82 error_error = DEFER;
83 goto NISPLUS_EXIT;
84 }
85
86 /* Look up the data for the table, in order to get the field names,
87 check that we got back a table, and set up pointers so the field
88 names can be scanned. */
89
90 nrt = nis_lookup(CS p, EXPAND_NAME | NO_CACHE);
91 if (nrt->status != NIS_SUCCESS)
92 {
93 *errmsg = string_sprintf("NIS+ error accessing %s table: %s", p,
94 nis_sperrno(nrt->status));
95 if (nrt->status != NIS_NOTFOUND && nrt->status != NIS_NOSUCHTABLE)
96 error_error = DEFER;
97 goto NISPLUS_EXIT;
98 }
99 tno = nrt->objects.objects_val;
100 if (tno->zo_data.zo_type != TABLE_OBJ)
101 {
102 *errmsg = string_sprintf("NIS+ error: %s is not a table", p);
103 goto NISPLUS_EXIT;
104 }
105 ta = &tno->zo_data.objdata_u.ta_data;
106
107 /* Now look up the entry in the table, check that we got precisely one
108 object and that it is a table entry. */
109
110 nre = nis_list(CS query, EXPAND_NAME, NULL, NULL);
111 if (nre->status != NIS_SUCCESS)
112 {
113 *errmsg = string_sprintf("NIS+ error accessing entry %s: %s",
114 query, nis_sperrno(nre->status));
115 goto NISPLUS_EXIT;
116 }
117 if (nre->objects.objects_len > 1)
118 {
119 *errmsg = string_sprintf("NIS+ returned more than one object for %s",
120 query);
121 goto NISPLUS_EXIT;
122 }
123 else if (nre->objects.objects_len < 1)
124 {
125 *errmsg = string_sprintf("NIS+ returned no data for %s", query);
126 goto NISPLUS_EXIT;
127 }
128 eno = nre->objects.objects_val;
129 if (eno->zo_data.zo_type != ENTRY_OBJ)
130 {
131 *errmsg = string_sprintf("NIS+ error: %s is not an entry", query);
132 goto NISPLUS_EXIT;
133 }
134
135 /* Scan the columns in the entry and in the table. If a result field
136 was given, look for that field; otherwise concatenate all the fields
137 with their names. */
138
139 eo = &(eno->zo_data.objdata_u.en_data);
140 for (int i = 0; i < eo->en_cols.en_cols_len; i++)
141 {
142 table_col *tc = ta->ta_cols.ta_cols_val + i;
143 entry_col *ec = eo->en_cols.en_cols_val + i;
144 int len = ec->ec_value.ec_value_len;
145 uschar *value = US ec->ec_value.ec_value_val;
146
147 /* The value may be NULL for a zero-length field. Turn this into an
148 empty string for consistency. Remove trailing whitespace and zero
149 bytes. */
150
151 if (!value) value = US"";
152 else
153 while (len > 0 && (value[len-1] == 0 || isspace(value[len-1])))
154 len--;
155
156 /* Concatenate all fields if no specific one selected */
157
158 if (!field_name)
159 {
160 yield = string_cat (yield, US tc->tc_name);
161 yield = string_catn(yield, US"=", 1);
162
163 /* Quote the value if it contains spaces or is empty */
164
165 if (value[0] == 0 || Ustrchr(value, ' ') != NULL)
166 {
167 yield = string_catn(yield, US"\"", 1);
168 for (int j = 0; j < len; j++)
169 {
170 if (value[j] == '\"' || value[j] == '\\')
171 yield = string_catn(yield, US"\\", 1);
172 yield = string_catn(yield, value+j, 1);
173 }
174 yield = string_catn(yield, US"\"", 1);
175 }
176 else
177 yield = string_catn(yield, value, len);
178
179 yield = string_catn(yield, US" ", 1);
180 }
181
182 /* When the specified field is found, grab its data and finish */
183
184 else if (Ustrcmp(field_name, tc->tc_name) == 0)
185 {
186 yield = string_catn(yield, value, len);
187 goto NISPLUS_EXIT;
188 }
189 }
190
191 /* Error if a field name was specified and we didn't find it; if no
192 field name, ensure the concatenated data is zero-terminated. */
193
194 if (field_name)
195 *errmsg = string_sprintf("NIS+ field %s not found for %s", field_name,
196 query);
197 else
198 gstring_release_unused(yield);
199
200 /* Free result store before finishing. */
201
202 NISPLUS_EXIT:
203 if (nrt) nis_freeresult(nrt);
204 if (nre) nis_freeresult(nre);
205
206 if (yield)
207 {
208 *result = string_from_gstring(yield);
209 return OK;
210 }
211
212 return error_error; /* FAIL or DEFER */
213 }
214
215
216
217 /*************************************************
218 * Quote entry point *
219 *************************************************/
220
221 /* The only quoting that is necessary for NIS+ is to double any doublequote
222 characters. No options are recognized.
223
224 Arguments:
225 s the string to be quoted
226 opt additional option text or NULL if none
227
228 Returns: the processed string or NULL for a bad option
229 */
230
231 static uschar *
232 nisplus_quote(uschar *s, uschar *opt)
233 {
234 int count = 0;
235 uschar *quoted;
236 uschar *t = s;
237
238 if (opt != NULL) return NULL; /* No options recognized */
239
240 while (*t != 0) if (*t++ == '\"') count++;
241 if (count == 0) return s;
242
243 t = quoted = store_get(Ustrlen(s) + count + 1, is_tainted(s));
244
245 while (*s != 0)
246 {
247 *t++ = *s;
248 if (*s++ == '\"') *t++ = '\"';
249 }
250
251 *t = 0;
252 return quoted;
253 }
254
255
256 /*************************************************
257 * Version reporting entry point *
258 *************************************************/
259
260 /* See local README for interface description. */
261
262 #include "../version.h"
263
264 void
265 nisplus_version_report(FILE *f)
266 {
267 #ifdef DYNLOOKUP
268 fprintf(f, "Library version: NIS+: Exim version %s\n", EXIM_VERSION_STR);
269 #endif
270 }
271
272
273 static lookup_info _lookup_info = {
274 US"nisplus", /* lookup name */
275 lookup_querystyle, /* query-style lookup */
276 nisplus_open, /* open function */
277 NULL, /* check function */
278 nisplus_find, /* find function */
279 NULL, /* no close function */
280 NULL, /* no tidy function */
281 nisplus_quote, /* quoting function */
282 nisplus_version_report /* version reporting */
283 };
284
285 #ifdef DYNLOOKUP
286 #define nisplus_lookup_module_info _lookup_module_info
287 #endif
288
289 static lookup_info *_lookup_list[] = { &_lookup_info };
290 lookup_module_info nisplus_lookup_module_info = { LOOKUP_MODULE_INFO_MAGIC, _lookup_list, 1 };
291
292 /* End of lookups/nisplus.c */