Compare commits

..
Author SHA1 Message Date
milkmaker 905a4a6200 update postscreen_access.cidr 2026-10-01 00:35:21 +00:00
6 changed files with 22 additions and 24 deletions

No files matched your search

+1 -1
View File
@@ -4,7 +4,7 @@ WORKDIR /src
ENV CGO_ENABLED=0 \ ENV CGO_ENABLED=0 \
GO111MODULE=on \ GO111MODULE=on \
NOOPT=1 \ NOOPT=1 \
VERSION=1.14.0 VERSION=1.11.0
RUN git clone --branch v${VERSION} https://github.com/Zuplu/postfix-tlspol && \ RUN git clone --branch v${VERSION} https://github.com/Zuplu/postfix-tlspol && \
cd /src/postfix-tlspol && \ cd /src/postfix-tlspol && \
+1 -1
View File
@@ -2,7 +2,7 @@ FROM debian:trixie-slim
LABEL maintainer="The Infrastructure Company GmbH <info@servercow.de>" LABEL maintainer="The Infrastructure Company GmbH <info@servercow.de>"
ARG DEBIAN_FRONTEND=noninteractive ARG DEBIAN_FRONTEND=noninteractive
ARG RSPAMD_VER=rspamd_4.2.1-1~b7a16ae ARG RSPAMD_VER=rspamd_4.1.4-1~beb659b
ARG CODENAME=trixie ARG CODENAME=trixie
ENV LC_ALL=C ENV LC_ALL=C
+4 -6
View File
@@ -856,8 +856,6 @@ rspamd_config:register_symbol({
local seen_cte local seen_cte
local newline_s = newline(task) local newline_s = newline(task)
-- use the CTE add_text_footer actually applied
local new_cte = rewrite.new_cte or 'quoted-printable'
local function rewrite_ct_cb(name, hdr) local function rewrite_ct_cb(name, hdr)
if rewrite.need_rewrite_ct then if rewrite.need_rewrite_ct then
@@ -879,13 +877,13 @@ rspamd_config:register_symbol({
return return
elseif name:lower() == 'content-transfer-encoding' then elseif name:lower() == 'content-transfer-encoding' then
out[#out + 1] = string.format('%s: %s', out[#out + 1] = string.format('%s: %s',
'Content-Transfer-Encoding', new_cte) 'Content-Transfer-Encoding', 'quoted-printable')
-- update Content-Transfer-Encoding header -- update Content-Transfer-Encoding header
task:set_milter_reply({ task:set_milter_reply({
remove_headers = {['Content-Transfer-Encoding'] = 0}, remove_headers = {['Content-Transfer-Encoding'] = 0},
}) })
task:set_milter_reply({ task:set_milter_reply({
add_headers = {['Content-Transfer-Encoding'] = new_cte} add_headers = {['Content-Transfer-Encoding'] = 'quoted-printable'}
}) })
seen_cte = true seen_cte = true
return return
@@ -897,7 +895,7 @@ rspamd_config:register_symbol({
task:headers_foreach(rewrite_ct_cb, {full = true}) task:headers_foreach(rewrite_ct_cb, {full = true})
if not seen_cte and rewrite.need_rewrite_ct then if not seen_cte and rewrite.need_rewrite_ct then
out[#out + 1] = string.format('%s: %s', 'Content-Transfer-Encoding', new_cte) out[#out + 1] = string.format('%s: %s', 'Content-Transfer-Encoding', 'quoted-printable')
end end
-- End of headers -- End of headers
@@ -916,7 +914,7 @@ rspamd_config:register_symbol({
out_parts[#out_parts + 1] = o out_parts[#out_parts + 1] = o
out_parts[#out_parts + 1] = newline_s out_parts[#out_parts + 1] = newline_s
else else
local removePrefix = "--\x0D\x0AContent-" local removePrefix = "--\x0D\x0AContent-Type"
if string.lower(string.sub(tostring(o[1]), 1, string.len(removePrefix))) == string.lower(removePrefix) then if string.lower(string.sub(tostring(o[1]), 1, string.len(removePrefix))) == string.lower(removePrefix) then
o[1] = string.sub(tostring(o[1]), string.len("--\x0D\x0A") + 1) o[1] = string.sub(tostring(o[1]), string.len("--\x0D\x0A") + 1)
end end
+7 -7
View File
@@ -153,12 +153,12 @@ foreach ($rcpts as $rcpt) {
// Loop through all found gotos // Loop through all found gotos
foreach ($gotos_array as $index => &$goto) { foreach ($gotos_array as $index => &$goto) {
error_log("RCPT RESOLVER: http pipe: query " . $goto . " as username from mailbox" . PHP_EOL); error_log("RCPT RESOVLER: http pipe: query " . $goto . " as username from mailbox" . PHP_EOL);
$stmt = $pdo->prepare("SELECT `username` FROM `mailbox` WHERE `username` = :goto AND (`active`= '1' OR `active`= '2');"); $stmt = $pdo->prepare("SELECT `username` FROM `mailbox` WHERE `username` = :goto AND (`active`= '1' OR `active`= '2');");
$stmt->execute(array(':goto' => $goto)); $stmt->execute(array(':goto' => $goto));
$username = $stmt->fetch(PDO::FETCH_ASSOC)['username']; $username = $stmt->fetch(PDO::FETCH_ASSOC)['username'];
if (!empty($username)) { if (!empty($username)) {
error_log("RCPT RESOLVER: http pipe: mailbox found: " . $username . PHP_EOL); error_log("RCPT RESOVLER: http pipe: mailbox found: " . $username . PHP_EOL);
// Current goto is a mailbox, save to rcpt_final_mailboxes if not a duplicate // Current goto is a mailbox, save to rcpt_final_mailboxes if not a duplicate
if (!in_array($username, $rcpt_final_mailboxes)) { if (!in_array($username, $rcpt_final_mailboxes)) {
$rcpt_final_mailboxes[] = $username; $rcpt_final_mailboxes[] = $username;
@@ -167,21 +167,21 @@ foreach ($rcpts as $rcpt) {
else { else {
$parsed_goto = parse_email($goto); $parsed_goto = parse_email($goto);
if (!$redis->hGet('DOMAIN_MAP', $parsed_goto['domain'])) { if (!$redis->hGet('DOMAIN_MAP', $parsed_goto['domain'])) {
error_log("RCPT RESOLVER:" . $goto . " is not a mailcow handled mailbox or alias address" . PHP_EOL); error_log("RCPT RESOVLER:" . $goto . " is not a mailcow handled mailbox or alias address" . PHP_EOL);
} }
else { else {
$stmt = $pdo->prepare("SELECT `goto` FROM `alias` WHERE `address` = :goto AND `active` = '1'"); $stmt = $pdo->prepare("SELECT `goto` FROM `alias` WHERE `address` = :goto AND `active` = '1'");
$stmt->execute(array(':goto' => $goto)); $stmt->execute(array(':goto' => $goto));
$goto_branch = $stmt->fetch(PDO::FETCH_ASSOC)['goto']; $goto_branch = $stmt->fetch(PDO::FETCH_ASSOC)['goto'];
if ($goto_branch) { if ($goto_branch) {
error_log("RCPT RESOLVER: http pipe: goto address " . $goto . " is an alias branch for " . $goto_branch . PHP_EOL); error_log("RCPT RESOVLER: http pipe: goto address " . $goto . " is an alias branch for " . $goto_branch . PHP_EOL);
$goto_branch_array = explode(',', $goto_branch); $goto_branch_array = explode(',', $goto_branch);
} else { } else {
$stmt = $pdo->prepare("SELECT `target_domain` FROM `alias_domain` WHERE `alias_domain` = :domain AND `active` = '1'"); $stmt = $pdo->prepare("SELECT `target_domain` FROM `alias_domain` WHERE `alias_domain` = :domain AND `active` = '1'");
$stmt->execute(array(':domain' => $parsed_goto['domain'])); $stmt->execute(array(':domain' => $parsed_goto['domain']));
$goto_branch = $stmt->fetch(PDO::FETCH_ASSOC)['target_domain']; $goto_branch = $stmt->fetch(PDO::FETCH_ASSOC)['target_domain'];
if ($goto_branch) { if ($goto_branch) {
error_log("RCPT RESOLVER: http pipe: goto domain " . $parsed_goto['domain'] . " is a domain alias branch for " . $goto_branch . PHP_EOL); error_log("RCPT RESOVLER: http pipe: goto domain " . $parsed_goto['domain'] . " is a domain alias branch for " . $goto_branch . PHP_EOL);
$goto_branch_array = array($parsed_goto['local'] . '@' . $goto_branch); $goto_branch_array = array($parsed_goto['local'] . '@' . $goto_branch);
} }
} }
@@ -203,11 +203,11 @@ foreach ($rcpts as $rcpt) {
// Force exit if loop cannot be solved // Force exit if loop cannot be solved
// Postfix does not allow for alias loops, so this should never happen. // Postfix does not allow for alias loops, so this should never happen.
$loop_c++; $loop_c++;
error_log("RCPT RESOLVER: http pipe: goto array count on loop #". $loop_c . " is " . count($gotos_array) . PHP_EOL); error_log("RCPT RESOVLER: http pipe: goto array count on loop #". $loop_c . " is " . count($gotos_array) . PHP_EOL);
} }
} }
catch (PDOException $e) { catch (PDOException $e) {
error_log("RCPT RESOLVER: " . $e->getMessage() . PHP_EOL); error_log("RCPT RESOVLER: " . $e->getMessage() . PHP_EOL);
http_response_code(502); http_response_code(502);
exit; exit;
} }
+7 -7
View File
@@ -139,12 +139,12 @@ foreach ($rcpts as $rcpt) {
// Loop through all found gotos // Loop through all found gotos
foreach ($gotos_array as $index => &$goto) { foreach ($gotos_array as $index => &$goto) {
error_log("RCPT RESOLVER: http pipe: query " . $goto . " as username from mailbox" . PHP_EOL); error_log("RCPT RESOVLER: http pipe: query " . $goto . " as username from mailbox" . PHP_EOL);
$stmt = $pdo->prepare("SELECT `username` FROM `mailbox` WHERE `username` = :goto AND (`active`= '1' OR `active`= '2');"); $stmt = $pdo->prepare("SELECT `username` FROM `mailbox` WHERE `username` = :goto AND (`active`= '1' OR `active`= '2');");
$stmt->execute(array(':goto' => $goto)); $stmt->execute(array(':goto' => $goto));
$username = $stmt->fetch(PDO::FETCH_ASSOC)['username']; $username = $stmt->fetch(PDO::FETCH_ASSOC)['username'];
if (!empty($username)) { if (!empty($username)) {
error_log("RCPT RESOLVER: http pipe: mailbox found: " . $username . PHP_EOL); error_log("RCPT RESOVLER: http pipe: mailbox found: " . $username . PHP_EOL);
// Current goto is a mailbox, save to rcpt_final_mailboxes if not a duplicate // Current goto is a mailbox, save to rcpt_final_mailboxes if not a duplicate
if (!in_array($username, $rcpt_final_mailboxes)) { if (!in_array($username, $rcpt_final_mailboxes)) {
$rcpt_final_mailboxes[] = $username; $rcpt_final_mailboxes[] = $username;
@@ -153,21 +153,21 @@ foreach ($rcpts as $rcpt) {
else { else {
$parsed_goto = parse_email($goto); $parsed_goto = parse_email($goto);
if (!$redis->hGet('DOMAIN_MAP', $parsed_goto['domain'])) { if (!$redis->hGet('DOMAIN_MAP', $parsed_goto['domain'])) {
error_log("RCPT RESOLVER:" . $goto . " is not a mailcow handled mailbox or alias address" . PHP_EOL); error_log("RCPT RESOVLER:" . $goto . " is not a mailcow handled mailbox or alias address" . PHP_EOL);
} }
else { else {
$stmt = $pdo->prepare("SELECT `goto` FROM `alias` WHERE `address` = :goto AND `active` = '1'"); $stmt = $pdo->prepare("SELECT `goto` FROM `alias` WHERE `address` = :goto AND `active` = '1'");
$stmt->execute(array(':goto' => $goto)); $stmt->execute(array(':goto' => $goto));
$goto_branch = $stmt->fetch(PDO::FETCH_ASSOC)['goto']; $goto_branch = $stmt->fetch(PDO::FETCH_ASSOC)['goto'];
if ($goto_branch) { if ($goto_branch) {
error_log("RCPT RESOLVER: http pipe: goto address " . $goto . " is an alias branch for " . $goto_branch . PHP_EOL); error_log("RCPT RESOVLER: http pipe: goto address " . $goto . " is an alias branch for " . $goto_branch . PHP_EOL);
$goto_branch_array = explode(',', $goto_branch); $goto_branch_array = explode(',', $goto_branch);
} else { } else {
$stmt = $pdo->prepare("SELECT `target_domain` FROM `alias_domain` WHERE `alias_domain` = :domain AND `active` = '1'"); $stmt = $pdo->prepare("SELECT `target_domain` FROM `alias_domain` WHERE `alias_domain` = :domain AND `active` = '1'");
$stmt->execute(array(':domain' => $parsed_goto['domain'])); $stmt->execute(array(':domain' => $parsed_goto['domain']));
$goto_branch = $stmt->fetch(PDO::FETCH_ASSOC)['target_domain']; $goto_branch = $stmt->fetch(PDO::FETCH_ASSOC)['target_domain'];
if ($goto_branch) { if ($goto_branch) {
error_log("RCPT RESOLVER: http pipe: goto domain " . $parsed_goto['domain'] . " is a domain alias branch for " . $goto_branch . PHP_EOL); error_log("RCPT RESOVLER: http pipe: goto domain " . $parsed_goto['domain'] . " is a domain alias branch for " . $goto_branch . PHP_EOL);
$goto_branch_array = array($parsed_goto['local'] . '@' . $goto_branch); $goto_branch_array = array($parsed_goto['local'] . '@' . $goto_branch);
} }
} }
@@ -189,11 +189,11 @@ foreach ($rcpts as $rcpt) {
// Force exit if loop cannot be solved // Force exit if loop cannot be solved
// Postfix does not allow for alias loops, so this should never happen. // Postfix does not allow for alias loops, so this should never happen.
$loop_c++; $loop_c++;
error_log("RCPT RESOLVER: http pipe: goto array count on loop #". $loop_c . " is " . count($gotos_array) . PHP_EOL); error_log("RCPT RESOVLER: http pipe: goto array count on loop #". $loop_c . " is " . count($gotos_array) . PHP_EOL);
} }
} }
catch (PDOException $e) { catch (PDOException $e) {
error_log("RCPT RESOLVER: " . $e->getMessage() . PHP_EOL); error_log("RCPT RESOVLER: " . $e->getMessage() . PHP_EOL);
http_response_code(502); http_response_code(502);
exit; exit;
} }
+2 -2
View File
@@ -84,7 +84,7 @@ services:
- clamd - clamd
rspamd-mailcow: rspamd-mailcow:
image: ghcr.io/mailcow/rspamd:4.2.1-1 image: ghcr.io/mailcow/rspamd:4.1.4-1
stop_grace_period: 30s stop_grace_period: 30s
depends_on: depends_on:
- dovecot-mailcow - dovecot-mailcow
@@ -382,7 +382,7 @@ services:
- postfix - postfix
postfix-tlspol-mailcow: postfix-tlspol-mailcow:
image: ghcr.io/mailcow/postfix-tlspol:1.14.0 image: ghcr.io/mailcow/postfix-tlspol:1.11.0
depends_on: depends_on:
unbound-mailcow: unbound-mailcow:
condition: service_healthy condition: service_healthy