| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424 | #!/bin/bashtrap "postfix stop" EXIT[[ ! -d /opt/postfix/conf/sql/ ]] && mkdir -p /opt/postfix/conf/sql/# Wait for MySQL to warm-upwhile ! mysqladmin status --socket=/var/run/mysqld/mysqld.sock -u${DBUSER} -p${DBPASS} --silent; do  echo "Waiting for database to come up..."  sleep 2doneuntil dig +short mailcow.email > /dev/null; do  echo "Waiting for DNS..."  sleep 1donecat <<EOF > /etc/aliases# Autogenerated by mailcownull: /dev/nullwatchdog: /dev/nullham: "|/usr/local/bin/rspamd-pipe-ham"spam: "|/usr/local/bin/rspamd-pipe-spam"EOFnewaliases;# create sni configurationif [[ "${SKIP_LETS_ENCRYPT}" =~ ^([yY][eE][sS]|[yY])+$ ]]; then  echo -n "" > /opt/postfix/conf/sni.mapelse  echo -n "" > /opt/postfix/conf/sni.map;  for cert_dir in /etc/ssl/mail/*/ ; do    if [[ ! -f ${cert_dir}domains ]] || [[ ! -f ${cert_dir}cert.pem ]] || [[ ! -f ${cert_dir}key.pem ]]; then      continue;    fi    IFS=" " read -r -a domains <<< "$(cat "${cert_dir}domains")"    for domain in "${domains[@]}"; do      echo -n "${domain} ${cert_dir}key.pem ${cert_dir}cert.pem" >> /opt/postfix/conf/sni.map;      echo "" >> /opt/postfix/conf/sni.map;    done  donefipostmap -F hash:/opt/postfix/conf/sni.map;cat <<EOF > /opt/postfix/conf/sql/mysql_relay_ne.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT IF(EXISTS(SELECT address, domain FROM alias      WHERE address = '%s'        AND domain IN (          SELECT domain FROM domain            WHERE backupmx = '1'              AND relay_all_recipients = '1'              AND relay_unknown_only = '1')      ), 'lmtp:inet:dovecot:24', NULL) AS 'transport'EOFcat <<EOF > /opt/postfix/conf/sql/mysql_relay_recipient_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT DISTINCT  CASE WHEN '%d' IN (    SELECT domain FROM domain      WHERE relay_all_recipients=1        AND domain='%d'        AND backupmx=1  )  THEN '%s' ELSE (    SELECT goto FROM alias WHERE address='%s' AND active='1'  )  END AS result;EOFcat <<EOF > /opt/postfix/conf/sql/mysql_tls_policy_override_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT CONCAT(policy, ' ', parameters) AS tls_policy FROM tls_policy_override WHERE active = '1' AND dest = '%s'EOFcat <<EOF > /opt/postfix/conf/sql/mysql_tls_enforce_in_policy.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT IF(EXISTS(  SELECT 'TLS_ACTIVE' FROM alias    LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto      WHERE (address='%s'        OR address IN (          SELECT CONCAT('%u', '@', target_domain) FROM alias_domain            WHERE alias_domain='%d'        )      ) AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_in')) = '1' AND mailbox.active = '1'  ), 'reject_plaintext_session', NULL) AS 'tls_enforce_in';EOFcat <<EOF > /opt/postfix/conf/sql/mysql_sender_dependent_default_transport_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT GROUP_CONCAT(transport SEPARATOR '') AS transport_maps  FROM (    SELECT IF(EXISTS(SELECT 'smtp_type' FROM alias      LEFT OUTER JOIN mailbox ON mailbox.username = alias.goto        WHERE (address = '%s'          OR address IN (            SELECT CONCAT('%u', '@', target_domain) FROM alias_domain              WHERE alias_domain = '%d'          )        )        AND JSON_UNQUOTE(JSON_VALUE(attributes, '$.tls_enforce_out')) = '1'        AND mailbox.active = '1'    ), 'smtp_enforced_tls:', 'smtp:') AS 'transport'    UNION ALL    SELECT COALESCE(      (SELECT hostname FROM relayhosts      LEFT OUTER JOIN mailbox ON JSON_UNQUOTE(JSON_VALUE(mailbox.attributes, '$.relayhost')) = relayhosts.id        WHERE relayhosts.active = '1'          AND (            mailbox.username IN (SELECT alias.goto from alias              JOIN mailbox ON mailbox.username = alias.goto                WHERE alias.active = '1'                  AND alias.address = '%s'                  AND alias.address NOT LIKE '@%%'            )          )      ),      (SELECT hostname FROM relayhosts      LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id        WHERE relayhosts.active = '1'          AND (domain.domain = '%d'            OR domain.domain IN (              SELECT target_domain FROM alias_domain                WHERE alias_domain = '%d'            )          )      )    )  ) AS transport_view;EOFcat <<EOF > /opt/postfix/conf/sql/mysql_transport_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT CONCAT('smtp_via_transport_maps:', nexthop) AS transport FROM transports  WHERE active = '1'  AND destination = '%s';EOFcat <<EOF > /opt/postfix/conf/sql/mysql_virtual_resource_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT 'null@localhost' FROM mailbox  WHERE kind REGEXP 'location|thing|group' AND username = '%s';EOFcat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_sender_dependent.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM relayhosts  WHERE id IN (    SELECT COALESCE(      (SELECT id FROM relayhosts      LEFT OUTER JOIN domain ON domain.relayhost = relayhosts.id      WHERE relayhosts.active = '1'        AND (domain.domain = '%d'          OR domain.domain IN (            SELECT target_domain FROM alias_domain            WHERE alias_domain = '%d'          )        )      ),      (SELECT id FROM relayhosts      LEFT OUTER JOIN mailbox ON JSON_UNQUOTE(JSON_VALUE(mailbox.attributes, '$.relayhost')) = relayhosts.id      WHERE relayhosts.active = '1'        AND (          mailbox.username IN (            SELECT alias.goto from alias              JOIN mailbox ON mailbox.username = alias.goto                WHERE alias.active = '1'                  AND alias.address = '%s'                  AND alias.address NOT LIKE '@%%'          )        )      )    )  )  AND active = '1'  AND username != '';EOFcat <<EOF > /opt/postfix/conf/sql/mysql_sasl_passwd_maps_transport_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT CONCAT_WS(':', username, password) AS auth_data FROM transports  WHERE nexthop = '%s'  AND active = '1'  AND username != ''  LIMIT 1;EOFcat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_domain_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT username FROM mailbox, alias_domain  WHERE alias_domain.alias_domain = '%d'    AND mailbox.username = CONCAT('%u', '@', alias_domain.target_domain)    AND (mailbox.active = '1' OR mailbox.active = '2')    AND alias_domain.active='1'EOFcat <<EOF > /opt/postfix/conf/sql/mysql_virtual_alias_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT goto FROM alias  WHERE address='%s'    AND (active='1' OR active='2');EOFcat <<EOF > /opt/postfix/conf/sql/mysql_recipient_bcc_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT bcc_dest FROM bcc_maps  WHERE local_dest='%s'    AND type='rcpt'    AND active='1';EOFcat <<EOF > /opt/postfix/conf/sql/mysql_sender_bcc_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT bcc_dest FROM bcc_maps  WHERE local_dest='%s'    AND type='sender'    AND active='1';EOFcat <<EOF > /opt/postfix/conf/sql/mysql_recipient_canonical_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT new_dest FROM recipient_maps  WHERE old_dest='%s'    AND active='1';EOFcat <<EOF > /opt/postfix/conf/sql/mysql_virtual_domains_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT alias_domain from alias_domain WHERE alias_domain='%s' AND active='1'  UNION  SELECT domain FROM domain    WHERE domain='%s'      AND active = '1'      AND backupmx = '0'EOFcat <<EOF > /opt/postfix/conf/sql/mysql_virtual_mailbox_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT CONCAT(JSON_UNQUOTE(JSON_VALUE(attributes, '$.mailbox_format')), mailbox_path_prefix, '%d/%u/') FROM mailbox WHERE username='%s' AND (active = '1' OR active = '2')EOFcat <<EOF > /opt/postfix/conf/sql/mysql_virtual_relay_domain_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT domain FROM domain WHERE domain='%s' AND backupmx = '1' AND active = '1'EOFcat <<EOF > /opt/postfix/conf/sql/mysql_virtual_sender_acl.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}# First select queries domain and alias_domain to determine if domains are active.query = SELECT goto FROM alias  WHERE address='%s'    AND active='1'    AND (domain IN      (SELECT domain FROM domain        WHERE domain='%d'          AND active='1')      OR domain in (        SELECT alias_domain FROM alias_domain          WHERE alias_domain='%d'            AND active='1'      )    )  UNION  SELECT logged_in_as FROM sender_acl    WHERE send_as='@%d'      OR send_as='%s'      OR send_as='*'      OR send_as IN (        SELECT CONCAT('@',target_domain) FROM alias_domain          WHERE alias_domain = '%d')      OR send_as IN (        SELECT CONCAT('%u','@',target_domain) FROM alias_domain          WHERE alias_domain = '%d')      AND logged_in_as NOT IN (        SELECT goto FROM alias          WHERE address='%s')  UNION  SELECT username FROM mailbox, alias_domain    WHERE alias_domain.alias_domain = '%d'      AND mailbox.username = CONCAT('%u','@',alias_domain.target_domain)      AND (mailbox.active = '1' OR mailbox.active ='2')      AND alias_domain.active='1'EOF# MX based routingcat <<EOF > /opt/postfix/conf/sql/mysql_mbr_access_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT CONCAT('FILTER smtp_via_transport_maps:', nexthop) as transport FROM transports  WHERE '%s' REGEXP destination    AND active='1'    AND is_mx_based='1';EOFcat <<EOF > /opt/postfix/conf/sql/mysql_virtual_spamalias_maps.cf# Autogenerated by mailcowuser = ${DBUSER}password = ${DBPASS}hosts = unix:/var/run/mysqld/mysqld.sockdbname = ${DBNAME}query = SELECT goto FROM spamalias  WHERE address='%s'    AND validity >= UNIX_TIMESTAMP()EOFsed -i '/User overrides/q' /opt/postfix/conf/main.cfecho >> /opt/postfix/conf/main.cftouch /opt/postfix/conf/extra.cfsed -i '/myhostname/d' /opt/postfix/conf/extra.cfecho -e "myhostname = ${MAILCOW_HOSTNAME}\n$(cat /opt/postfix/conf/extra.cf)" > /opt/postfix/conf/extra.cfcat /opt/postfix/conf/extra.cf >> /opt/postfix/conf/main.cfif [ ! -f /opt/postfix/conf/custom_transport.pcre ]; then  echo "Creating dummy custom_transport.pcre"  touch /opt/postfix/conf/custom_transport.pcrefiif [[ ! -f /opt/postfix/conf/custom_postscreen_whitelist.cidr ]]; then  echo "Creating dummy custom_postscreen_whitelist.cidr"  cat <<EOF > /opt/postfix/conf/custom_postscreen_whitelist.cidr# Autogenerated by mailcow# Rules are evaluated in the order as specified.# Blacklist 192.168.* except 192.168.0.1.# 192.168.0.1          permit# 192.168.0.0/16       rejectEOFfi# Fix Postfix permissionschown -R root:postfix /opt/postfix/conf/sql/ /opt/postfix/conf/custom_transport.pcrechmod 640 /opt/postfix/conf/sql/*.cf /opt/postfix/conf/custom_transport.pcrechgrp -R postdrop /var/spool/postfix/publicchgrp -R postdrop /var/spool/postfix/maildroppostfix set-permissions# Check Postfix configurationpostconf -c /opt/postfix/conf > /dev/nullif [[ $? != 0 ]]; then  echo "Postfix configuration error, refusing to start."  exit 1else  postfix -c /opt/postfix/conf start  sleep 126144000fi
 |