rash of crashes: likely patch included

John Clements <[email protected]> Mon, 20 Apr 2009 12:24:39 -0700
Newsgroups gmane.mail.spam.spf.devel
Message-ID <[email protected]>
--Apple-Mail-8--44718510
Content-Type: text/plain;
	charset=US-ASCII;
	format=flowed;
	delsp=yes
Content-Transfer-Encoding: 7bit

For about half an hour this morning, policyd-spf was halting with  
error 1 on many spf checks.  One such crash was reported in mail.log  
as follows:

Apr 20 05:33:12 computer policyd-spf[24302]: None; identity=helo;  
client-ip=78.62.105.82; helo=78-56-134-24.static.zebra.lt; envelope- 
from=tin.it; [email protected]
Apr 20 05:33:13 computer policyd-spf[24302]: Traceback (most recent  
call last):
Apr 20 05:33:13 computer policyd-spf[24302]:   File "/usr/local/bin/ 
policyd-spf", line 420, in <module>
Apr 20 05:33:13 computer policyd-spf[24302]:     instance_dict,  
configData)
Apr 20 05:33:13 computer policyd-spf[24302]:   File "/usr/local/bin/ 
policyd-spf", line 343, in spfcheck
Apr 20 05:33:13 computer policyd-spf[24302]:     mfrom_resultpolicy,  
local = get_resultcodes(configData, 'mfrom')
Apr 20 05:33:13 computer policyd-spf[24302]:   File "/usr/local/bin/ 
policyd-spf", line 122, in get_resultcodes
Apr 20 05:33:13 computer policyd-spf[24302]:     if  
spf.domainmatch(reject_domain_list, sender_domain[1]):
Apr 20 05:33:13 computer policyd-spf[24302]: IndexError: list index  
out of range
Apr 20 05:33:13 computer postfix/spawn[24301]: warning: command /usr/ 
local/bin/policyd-spf exit status 1
Apr 20 05:33:13 computer postfix/smtpd[24300]: warning: premature end- 
of-input on private/policyd-spf while reading input attribute name

Looking through the source, I see that the crash is on the second of  
these two lines:

         sender_domain = string.split(sender, '@', 1)
         if spf.domainmatch(reject_domain_list, sender_domain[1]):

... and sure enough, the offending e-mail is missing an '@'.  My guess  
(my Python is basically nonexistent) is that the string.split on the  
prior line therefore returns a list of length 1, and that the  
expression 'sender_domain[1]' then fails.

As I say, I don't know python.  I'm guessing that the fix should be as  
simple as taking the last element of the list, like this:

         split_sender = string.split(sender, '@', 1);
	;; there might not be a '@', so take the last element of the list:
	sender_domain = split_sender[len(split_sender)-1];
         if spf.domainmatch(reject_domain_list, sender_domain):
...

If there was a built-in 'last' operation on a list, this would be even  
tidier:

	;; there might not be a '@', so take the last element of the list:
         sender_domain = string.split(sender, '@', 1).last();
         if spf.domainmatch(reject_domain_list, sender_domain):
...

Also, I haven't read the relevant RFCs, so I'm guessing that the  
current behavior (that is, everything after the first '@' is part of  
the domain) matches the RFC spec (though I do find that a bit  
surprising).

John Clements









-------------------------------------------
Sender Policy Framework: http://www.openspf.org
Modify Your Subscription: http://www.listbox.com/member/
Archives: https://www.listbox.com/member/archive/1007/=now
RSS Feed: https://www.listbox.com/member/archive/rss/1007/
Powered by Listbox: http://www.listbox.com

--Apple-Mail-8--44718510
Content-Disposition: attachment;
	filename=smime.p7s
Content-Type: application/pkcs7-signature;
	name=smime.p7s
Content-Transfer-Encoding: base64

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEH
AQAAoIIGZjCCAx8wggKIoAMCAQICEHJ+EkGR37a5IToZ9cXjMlgwDQYJKoZI
hvcNAQEFBQAwYjELMAkGA1UEBhMCWkExJTAjBgNVBAoTHFRoYXd0ZSBDb25z
dWx0aW5nIChQdHkpIEx0ZC4xLDAqBgNVBAMTI1RoYXd0ZSBQZXJzb25hbCBG
cmVlbWFpbCBJc3N1aW5nIENBMB4XDTA5MDQwMTE4NDQ0N1oXDTEwMDQwMTE4
NDQ0N1owfjERMA8GA1UEBBMIQ2xlbWVudHMxGjAYBgNVBCoTEUpvaG4gQnJp
bmNrZXJob2ZmMSMwIQYDVQQDExpKb2huIEJyaW5ja2VyaG9mZiBDbGVtZW50
czEoMCYGCSqGSIb3DQEJARYZY2xlbWVudHNAYnJpbmNrZXJob2ZmLm9yZzCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALCXj+0En7xyTFxGmlHy
/EGab+Qo3I5rT44NJ4U7/CGWWXLFL3oiIrE+aldmxtUSVD/tfgBZqde4IUPy
ue14e5Qr42Uagk2ctTy3+OZS/esZ2/qDWqMZ3/2g0QxdM5W1cU1L3R0XzPus
vkpwKhr/tmkMC7fWVCFJjOqlnxK15BOJYgHxZJh69GFgFEIZPc0S98x8ATVi
ZMC75zV88rmt04ocgyZkA1q7cFBtZ9H7gVwdrSc2nj4u83IlfboVwKHWmipM
IFoCNJel0x0CiRP2q+zKFFbzjoEzztHNs9vyuHpNXO/NRLJzqUEcgaDNKiFV
O2y9clMMDrm4sshr3x+u8kcCAwEAAaM2MDQwJAYDVR0RBB0wG4EZY2xlbWVu
dHNAYnJpbmNrZXJob2ZmLm9yZzAMBgNVHRMBAf8EAjAAMA0GCSqGSIb3DQEB
BQUAA4GBAD12ultvwiXn211hMSo1XFh288pr5Nv4cyIRcfzqS+1jgVi0mEJI
qskNTmuHwm2ToNY1DRVtAVMIFQ8vyF5QIeuDK01J6BEh8S5HOMqmK9n+oTJd
1Q4hx9Y039ECLusmRwYmN4VpVeTOP/YVD9A8NuWSxDMjgieWkMmkncAF6WNZ
MIIDPzCCAqigAwIBAgIBDTANBgkqhkiG9w0BAQUFADCB0TELMAkGA1UEBhMC
WkExFTATBgNVBAgTDFdlc3Rlcm4gQ2FwZTESMBAGA1UEBxMJQ2FwZSBUb3du
MRowGAYDVQQKExFUaGF3dGUgQ29uc3VsdGluZzEoMCYGA1UECxMfQ2VydGlm
aWNhdGlvbiBTZXJ2aWNlcyBEaXZpc2lvbjEkMCIGA1UEAxMbVGhhd3RlIFBl
cnNvbmFsIEZyZWVtYWlsIENBMSswKQYJKoZIhvcNAQkBFhxwZXJzb25hbC1m
cmVlbWFpbEB0aGF3dGUuY29tMB4XDTAzMDcxNzAwMDAwMFoXDTEzMDcxNjIz
NTk1OVowYjELMAkGA1UEBhMCWkExJTAjBgNVBAoTHFRoYXd0ZSBDb25zdWx0
aW5nIChQdHkpIEx0ZC4xLDAqBgNVBAMTI1RoYXd0ZSBQZXJzb25hbCBGcmVl
bWFpbCBJc3N1aW5nIENBMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDE
pjxVc1X7TrnKmVoeaMB1BHCd3+n/ox7svc31W/Iadr1/DDph8r9RzgHU5VAK
MNcCY1osiRVwjt3J8CuFWqo/cVbLrzwLB+fxH5E2JCoTzyvV84J3PQO+K/67
GD4Hv0CAAmTXp6a7n2XRxSpUhQ9IBH+nttE8YQRAHmQZcmC3+wIDAQABo4GU
MIGRMBIGA1UdEwEB/wQIMAYBAf8CAQAwQwYDVR0fBDwwOjA4oDagNIYyaHR0
cDovL2NybC50aGF3dGUuY29tL1RoYXd0ZVBlcnNvbmFsRnJlZW1haWxDQS5j
cmwwCwYDVR0PBAQDAgEGMCkGA1UdEQQiMCCkHjAcMRowGAYDVQQDExFQcml2
YXRlTGFiZWwyLTEzODANBgkqhkiG9w0BAQUFAAOBgQBIjNFQg+oLLswNo2as
Zw9/r6y+whehQ5aUnX9MIbj4Nh+qLZ82L8D0HFAgk3A8/a3hYWLD2ToZfoSx
mRsAxRoLgnSeJVCUYsfbJ3FXJY3dqZw5jowgT2Vfldr394fWxghOrvbqNOUQ
Gls1TXfjViF4gtwhGTXeJLHTHUb/XV9lTzGCAxAwggMMAgEBMHYwYjELMAkG
A1UEBhMCWkExJTAjBgNVBAoTHFRoYXd0ZSBDb25zdWx0aW5nIChQdHkpIEx0
ZC4xLDAqBgNVBAMTI1RoYXd0ZSBQZXJzb25hbCBGcmVlbWFpbCBJc3N1aW5n
IENBAhByfhJBkd+2uSE6GfXF4zJYMAkGBSsOAwIaBQCgggFvMBgGCSqGSIb3
DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTA5MDQyMDE5MjQ0
MFowIwYJKoZIhvcNAQkEMRYEFC6ux0B9XuTQKeuCsxsVgHs5AIHaMIGFBgkr
BgEEAYI3EAQxeDB2MGIxCzAJBgNVBAYTAlpBMSUwIwYDVQQKExxUaGF3dGUg
Q29uc3VsdGluZyAoUHR5KSBMdGQuMSwwKgYDVQQDEyNUaGF3dGUgUGVyc29u
YWwgRnJlZW1haWwgSXNzdWluZyBDQQIQcn4SQZHftrkhOhn1xeMyWDCBhwYL
KoZIhvcNAQkQAgsxeKB2MGIxCzAJBgNVBAYTAlpBMSUwIwYDVQQKExxUaGF3
dGUgQ29uc3VsdGluZyAoUHR5KSBMdGQuMSwwKgYDVQQDEyNUaGF3dGUgUGVy
c29uYWwgRnJlZW1haWwgSXNzdWluZyBDQQIQcn4SQZHftrkhOhn1xeMyWDAN
BgkqhkiG9w0BAQEFAASCAQCNbdlqjM6SbpPfOq40x0ci+wK24dYb+BonGRBn
a4R0q45psdgcoBLJqiUK1xorlbZPxEIDhSW+aE7mUIRdEQXSBT9V50zLpFvM
5D7iQwjOXPOldnikHywy83fwXHRT8Sf6yzwLIJp7nvAs4rmO13VfIi9yNP39
AE1qupzvM7quJEQVlStRqtKZfqLEyGe3ye6GjUNoztTXfOzFQ0mKeUbzA78c
WWqAMWdvAudNQ3hfdZvcIeqHUU53J9I8pHOmVAwHKZXXDF8BLT6NQmMfA7Q4
IsisbljSp/pUghJm0rfvi7QxrNlk6ddUWeaU2JZm/Zx7Xwi/WzBzHc+x+REq
M3bqAAAAAAAA

--Apple-Mail-8--44718510--