Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-05 Thread Slawomir Dworaczek via Exim-users
[exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released) Victor Ustugov via Exim-users wrote on 05.05.2021 17:14: Heiko Schlittermann via Exim-users wrote on 05.05.2021 16:16: I'd just refuse to create a bloated 4.94+fixes, instead of releasing 4.95 as soon a

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-05 Thread Victor Ustugov via Exim-users
Victor Ustugov via Exim-users wrote on 05.05.2021 17:14: > Heiko Schlittermann via Exim-users wrote on 05.05.2021 16:16: >> I'd just refuse to create a bloated 4.94+fixes, instead of releasing >> 4.95 as soon as possible. > > Yesterday I built exim 4.94.2 with adapted code from Jer

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-05 Thread Victor Ustugov via Exim-users
Heiko Schlittermann via Exim-users wrote on 05.05.2021 16:16: > Victor Ustugov via Exim-users (Mi 05 Mai 2021 14:48:20 > CEST): >> Heiko Schlittermann via Exim-users wrote on 05.05.2021 14:57: >>> Victor Ustugov via Exim-users (Mi 05 Mai 2021 >>> 13:21:55 CEST): > I'd just refuse to create

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-05 Thread Heiko Schlittermann via Exim-users
Victor Ustugov via Exim-users (Mi 05 Mai 2021 14:48:20 CEST): > Heiko Schlittermann via Exim-users wrote on 05.05.2021 14:57: > > Victor Ustugov via Exim-users (Mi 05 Mai 2021 > > 13:21:55 CEST): > >>> I'd just refuse to create a bloated 4.94+fixes, instead of releasing > >>> 4.95 as soon as po

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-05 Thread Victor Ustugov via Exim-users
Heiko Schlittermann via Exim-users wrote on 05.05.2021 14:57: > Victor Ustugov via Exim-users (Mi 05 Mai 2021 13:21:55 > CEST): >>> I'd just refuse to create a bloated 4.94+fixes, instead of releasing >>> 4.95 as soon as possible. >> >> Yesterday I built exim 4.94.2 with adapted code from Jeremy'

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-05 Thread Heiko Schlittermann via Exim-users
Heiko Schlittermann (Mi 05 Mai 2021 14:04:10 CEST): > > What did you do? I just cherry-picked the mentioned commit > > 4a7dca52352d0976f200b89a50825433b7551554 > > > > But the error didn't disappear. I'll check in more detail now. > > seems to be relevant too: > b8514d1960e259d49ab2c84c89eba52a

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-05 Thread Heiko Schlittermann via Exim-users
Victor Ustugov via Exim-users (Mi 05 Mai 2021 13:21:55 CEST): > > I'd just refuse to create a bloated 4.94+fixes, instead of releasing > > 4.95 as soon as possible. > > Yesterday I build exim 4.94.2 with adapted code from Jeremy's commit. > It works as expected on FreeBSD (exim 4.94.2 from ports

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-05 Thread Heiko Schlittermann via Exim-users
Heiko Schlittermann (Mi 05 Mai 2021 13:57:32 CEST): > Victor Ustugov via Exim-users (Mi 05 Mai 2021 13:21:55 > CEST): > > > I'd just refuse to create a bloated 4.94+fixes, instead of releasing > > > 4.95 as soon as possible. > > > > Yesterday I build exim 4.94.2 with adapted code from Jeremy's

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-05 Thread Victor Ustugov via Exim-users
Heiko Schlittermann via Exim-users wrote on 05.05.2021 01:39: > Jeremy Harris via Exim-users (Mi 05 Mai 2021 00:11:59 > CEST): >> Having made me go and look... that is what I did, in b8514d1960 >> (which is since 4.94). A comma-sep option "file=/foo" after >> the word "sqlite". > > Yes, that's

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-04 Thread Heiko Schlittermann via Exim-users
Jeremy Harris via Exim-users (Mi 05 Mai 2021 00:11:59 CEST): > Having made me go and look... that is what I did, in b8514d1960 > (which is since 4.94). A comma-sep option "file=/foo" after > the word "sqlite". Yes, that's what I found. But I can't see this neither in 4.94, or 4.94+fixes. @Vict

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-04 Thread Jeremy Harris via Exim-users
On 04/05/2021 22:33, Evgeniy Berdnikov via Exim-users wrote: On Tue, May 04, 2021 at 08:39:43PM +0100, Jeremy Harris via Exim-users wrote: On 04/05/2021 20:10, Victor Ustugov via Exim-users wrote: Why? Many years it was possible to execute queries to different SQLite databases. Why do you want

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-04 Thread Evgeniy Berdnikov via Exim-users
On Tue, May 04, 2021 at 08:39:43PM +0100, Jeremy Harris via Exim-users wrote: > On 04/05/2021 20:10, Victor Ustugov via Exim-users wrote: > > Why? Many years it was possible to execute queries to different SQLite > > databases. Why do you want to drop this feathure? > > The syntax doesn't fit bein

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-04 Thread Jeremy Harris via Exim-users
On 04/05/2021 20:10, Victor Ustugov via Exim-users wrote: Why? Many years it was possible to execute queries to different SQLite databases. Why do you want to drop this feathure? The syntax doesn't fit being able to check for tainted data being used. We need to invent some new syntax in order

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-04 Thread Victor Ustugov via Exim-users
Heiko Schlittermann via Exim-users wrote on 04.05.2021 20:34: >>> I cannot find any reference to the syntax you're using. >>> Maybe I'm stupid. >> >> https://lists.exim.org/lurker/message/20200606.183617.325a7016.en.html >> >> https://git.exim.org/exim.git/commitdiff/b8514d1960e259d49ab2c84c89eba5

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-04 Thread Heiko Schlittermann via Exim-users
Hi Victor, Victor "Ustugov" via Exim-users (Di 04 Mai 2021 18:54:09 CEST): > > I cannot find any reference to the syntax you're using. > > Maybe I'm stupid. > > https://lists.exim.org/lurker/message/20200606.183617.325a7016.en.html > > https://git.exim.org/exim.git/commitdiff/b8514d1960e259d4

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-04 Thread Victor "Ustugov" via Exim-users
Heiko Schlittermann via Exim-users wrote on 04.05.2021 19:29: > Heiko Schlittermann via Exim-users (Di 04 Mai 2021 > 17:44:23 CEST): >> Odhiambo Washington via Exim-users (Di 04 Mai 2021 >> 17:00:36 CEST): >>> On Tue, May 4, 2021 at 4:52 PM Heiko Schlittermann via Exim-users < >>> temporarily r

Re: [exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-04 Thread Heiko Schlittermann via Exim-users
Heiko Schlittermann via Exim-users (Di 04 Mai 2021 17:44:23 CEST): > Odhiambo Washington via Exim-users (Di 04 Mai 2021 > 17:00:36 CEST): > > On Tue, May 4, 2021 at 4:52 PM Heiko Schlittermann via Exim-users < > > temporarily rejected after DATA: failed to expand ACL string "${lookup > > sqlite

[exim] Sqlite Lookup absolute filename (was Exim 4.94.2 - security update released)

2021-05-04 Thread Heiko Schlittermann via Exim-users
Odhiambo Washington via Exim-users (Di 04 Mai 2021 17:00:36 CEST): > On Tue, May 4, 2021 at 4:52 PM Heiko Schlittermann via Exim-users < > temporarily rejected after DATA: failed to expand ACL string "${lookup > sqlite,file=/var/spool/exim/db/greylist.db {SELECT host from resenders > WHERE helo='