Browse Source

Use access check for sendmail command

pull/7483/head
Patrick Bönisch 3 weeks ago
parent
commit
a93fedb863
  1. 19
      Cargo.lock
  2. 1
      Cargo.toml
  3. 7
      src/config.rs

19
Cargo.lock

@ -928,6 +928,12 @@ version = "1.0.4"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801" checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801"
[[package]]
name = "cfg_aliases"
version = "0.2.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "f079e83a288787bcd14a6aea84cee5c87a67c5a3e660c30f557a3d24761b3527"
[[package]] [[package]]
name = "chacha20" name = "chacha20"
version = "0.10.1" version = "0.10.1"
@ -3221,6 +3227,18 @@ version = "0.1.1"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "27b02d87554356db9e9a873add8782d4ea6e3e58ea071a9adb9a2e8ddb884a8b" checksum = "27b02d87554356db9e9a873add8782d4ea6e3e58ea071a9adb9a2e8ddb884a8b"
[[package]]
name = "nix"
version = "0.31.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "cf20d2fde8ff38632c426f1165ed7436270b44f199fc55284c38276f9db47c3d"
dependencies = [
"bitflags 2.13.1",
"cfg-if",
"cfg_aliases",
"libc",
]
[[package]] [[package]]
name = "nom" name = "nom"
version = "7.1.3" version = "7.1.3"
@ -5863,6 +5881,7 @@ dependencies = [
"macros", "macros",
"mimalloc", "mimalloc",
"moka", "moka",
"nix",
"num-derive", "num-derive",
"num-traits", "num-traits",
"opendal", "opendal",

1
Cargo.toml

@ -58,6 +58,7 @@ oidc-accept-string-booleans = ["openidconnect/accept-string-booleans"]
unstable = [] unstable = []
[target."cfg(unix)".dependencies] [target."cfg(unix)".dependencies]
nix = { version = "0.31.3", features = ["fs"] }
# Logging # Logging
syslog = "7.0.0" syslog = "7.0.0"

7
src/config.rs

@ -1157,11 +1157,8 @@ fn validate_config(cfg: &ConfigItems, on_update: bool) -> Result<(), Error> {
} }
#[cfg(unix)] #[cfg(unix)]
{ if nix::unistd::access(&path, nix::unistd::AccessFlags::X_OK).is_err() {
use std::os::unix::fs::PermissionsExt; err!(format!("sendmail command at `{path:?}` isn't executable"));
if metadata.permissions().mode() & 0o111 == 0 {
err!(format!("sendmail command at `{path:?}` isn't executable"));
}
} }
} }
} }

Loading…
Cancel
Save