You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CentOS下Exim邮件过滤器失效,提示Tainted name错误求解决

问题分析与解决

报错原因

Tainted name 是Exim的安全防护机制:当使用用户可控的输入数据(比如邮件地址的local_part、domain,或通过lookup获取的动态值)构建文件路径时,Exim会将这些数据标记为"tainted"(受污染的),禁止直接用于文件读取操作,防止路径注入、目录遍历等攻击行为。

你的报错路径/etc/exim/users/soft/204.compilor.com/soft/filter中,soft(lookup获取的用户值)和soft(邮件local_part)均未经过安全净化,导致整个路径被标记为tainted,触发读取权限限制。

解决方案

核心思路是:对所有用于构建文件路径的动态变量执行untaint(净化)操作,移除其中的不安全字符,让Exim认定路径合法。

步骤1:添加安全的untaint Perl函数

在Exim主配置文件开头添加自定义的净化函数(比默认untaint更严格,只保留安全字符):

perl_startup = <<PERL
sub untaint_safe {
    my $str = shift;
    $str =~ s/[^a-zA-Z0-9._-]//g; # 仅保留字母、数字、点、下划线、连字符
    return $str;
}
PERL

步骤2:修改路由配置中的路径字段

将require_files、condition、file三个字段里的动态变量全部替换为净化后的值:

email_filter:
    driver = redirect
    allow_filter
    allow_fail
    forbid_filter_run
    forbid_filter_perl
    forbid_filter_lookup
    forbid_filter_readfile
    forbid_filter_readsocket
    no_check_local_user
    domains = lsearch;/etc/userdomains
    # 对lookup结果、domain、local_part都做净化
    require_files = "/etc/exim/users/${perl{untaint_safe}{${lookup{$domain}lsearch{/etc/userdomains}{$value}}}}/${perl{untaint_safe}{$domain}}/${perl{untaint_safe}{$local_part}}/filter"
    condition = "${extract \
        {size} \
        {${stat:/etc/exim/users/${perl{untaint_safe}{${lookup{$domain}lsearch{/etc/userdomains}{$value}}}}/${perl{untaint_safe}{$domain}}/${perl{untaint_safe}{$local_part}}/filter}} \
    }"
    file = /etc/exim/users/${perl{untaint_safe}{${lookup{$domain}lsearch{/etc/userdomains}{$value}}}}/${perl{untaint_safe}{$domain}}/${perl{untaint_safe}{$local_part}}/filter
    file_transport = address_file
    directory_transport = address_directory
    reply_transport = address_reply
    router_home_directory = ${extract \
        {5} \
        {::} \
        {${lookup passwd \
            {${perl{untaint_safe}{${lookup{$domain}lsearch{/etc/userdomains}{$value}}}}} \
            {$value} \
        }} \
    }
    user = "${perl{untaint_safe}{${lookup{$domain}lsearch{/etc/userdomains}{$value}}}}"
    group = "${perl{untaint_safe}{${lookup{$domain}lsearch{/etc/userdomains}{$value}}}}"
    local_part_suffix = +*
    local_part_suffix_optional
    retry_use_local_part
    no_verify

额外检查项

  1. 文件权限:确保过滤器文件/etc/exim/users/[user]/[domain]/[local_part]/filter的所属用户/组与配置中user、group字段一致,权限设置为644(禁止其他用户修改)。
  2. 路径存在性:确认上述路径真实存在,且/etc/userdomains中domain与用户的映射关系正确。

内容的提问来源于stack exchange,提问作者be MrZulf

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 09:24:25