Variable expansion syntax: Filter "default" throws error (unwanted)
I am using dovecot 2.4.2 (almost) with new config language and I have a working configuration. However, the check for disabled users throws permanently errors in the log file, whenever a user is missing the ldap attribute for disabled. This is - in my view - due to a misfunction of Filter "default".
passdb ldap { driver = ldap ldap_bind = yes ldap_filter = (&(|(objectClass=posixAccount)(objectClass=mailAccount))(uid=%{user})) fields { user = %{ldap:uid} nologin = %{ldap:shadowInactive | default(null)} reason = The account for this email address is disabled. } }
This results in the following log line: 2026-03-31T00:46:31.102690+02:00 mailserver dovecot: auth(test,ipv4,sasl:plain)<YE81n0VOVuofEeSD>: Error: ldap: auth_passdb_post settings: Failed to parse configuration: Failed to expand passdb_fields/nologin setting variables: ldap: No such attribute 'shadowinactive'
The right behaviour would be no logging on login success. Because the Filter "default" is intended to suppress any errors ("When value is missing or empty, you can use the default filter to provide value. Missing variables will cause errors and must be negated with default. This does not apply to all providers, some providers return empty when value is missing."). https://doc.dovecot.org/2.4.2/core/settings/variables.html#variable-expansio...
As you may have seen I had to borrow null-value from sql db config also to make nologin ignoring a non present attribute. This is undocumented obviously. Instead, a non-working tip is provided ("Changed: 2.4.0 Extra fields can now also be set to empty string, "). However, the following does not work: "nologin = {ldap:shadowinactive | default("")}". https://doc.dovecot.org/2.4.2/core/settings/variables.html
Also, the documentation is missing/hiding the part which explains that "default()" can be used to avoid error logs. PR regarding the documentation source is sent already. See "Fails if the attribute is not present, unless the ` <missing part>" https://doc.dovecot.org/2.4.0/core/config/auth/databases/ldap.html#ldap-spec...
Is there another way to verify if account is disabled?
Johannes Nohl postmaster i-t-cloud
-- Johannes Nohl postmaster@i-t-cloud.de
I am using dovecot 2.4.2 (almost) with new config language and I have a working configuration. However, the check for disabled users throws permanently errors in the log file, whenever a user is missing the ldap attribute for disabled. This is - in my view - due to a misfunction of Filter "default". passdb ldap { driver = ldap ldap_bind = yes ldap_filter = (&(|(objectClass=posixAccount)(objectClass=mailAccount))(uid=%{user})) fields { user = %{ldap:uid} nologin = %{ldap:shadowInactive | default(null)} reason = The account for this email address is disabled. } } This results in the following log line: *2026-03-31T00:46:31.102690+02:00 mailserver dovecot: auth(test,ipv4,sasl:plain)<YE81n0VOVuofEeSD>: Error: ldap: auth_passdb_post settings: Failed to parse configuration: Failed to expand passdb_fields/nologin setting variables: ldap: No such attribute 'shadowinactive' The right behaviour would be no logging on login success. Because the Filter "default" is intended to suppress any errors ("When value is missing or empty, you can use the default filter to provide value. Missing variables will cause errors and must be negated with default. This does not apply to all providers, some providers return empty when value is missing."). https://doc.dovecot.org/2.4.2/core/settings/variables.html#variable-expansio... As you may have seen I had to borrow null-value from sql db config also to make nologin ignoring a non present attribute. This is undocumented obviously. Instead, a non-working tip is provided ("Changed: 2.4.0 Extra fields can now also be set to empty string, "). However, the following does not work: "nologin = {ldap:shadowinactive | default("")}". https://doc.dovecot.org/2.4.2/core/settings/variables.html Also, the documentation is missing/hiding the part which explains that "default()" can be used to avoid error logs. PR regarding the documentation source is sent already. See "Fails if the attribute is not present, unless the ` <missing part>" https://doc.dovecot.org/2.4.0/core/config/auth/databases/ldap.html#ldap-spec... Is there another way to verify if account is disabled?
Johannes Nohl postmaster i-t-cloud
-- Johannes Nohl postmaster@i-t-cloud.de
On 31/03/2026 02:25 EEST Johannes Nohl via dovecot <dovecot@dovecot.org> wrote:
I am using dovecot 2.4.2 (almost) with new config language and I have a working configuration. However, the check for disabled users throws permanently errors in the log file, whenever a user is missing the ldap attribute for disabled. This is - in my view - due to a misfunction of Filter "default".
passdb ldap { driver = ldap ldap_bind = yes ldap_filter = (&(|(objectClass=posixAccount)(objectClass=mailAccount))(uid=%{user})) fields { user = %{ldap:uid} nologin = %{ldap:shadowInactive | default(null)} reason = The account for this email address is disabled. } }
This results in the following log line: 2026-03-31T00:46:31.102690+02:00 mailserver dovecot: auth(test,ipv4,sasl:plain)<YE81n0VOVuofEeSD>: Error: ldap: auth_passdb_post settings: Failed to parse configuration: Failed to expand passdb_fields/nologin setting variables: ldap: No such attribute 'shadowinactive'
The right behaviour would be no logging on login success. Because the Filter "default" is intended to suppress any errors ("When value is missing or empty, you can use the default filter to provide value. Missing variables will cause errors and must be negated with default. This does not apply to all providers, some providers return empty when value is missing."). https://doc.dovecot.org/2.4.2/core/settings/variables.html#variable-expansio...
As you may have seen I had to borrow null-value from sql db config also to make nologin ignoring a non present attribute. This is undocumented obviously. Instead, a non-working tip is provided ("Changed: 2.4.0 Extra fields can now also be set to empty string, "). However, the following does not work: "nologin = {ldap:shadowinactive | default("")}". https://doc.dovecot.org/2.4.2/core/settings/variables.html
Also, the documentation is missing/hiding the part which explains that "default()" can be used to avoid error logs. PR regarding the documentation source is sent already. See "Fails if the attribute is not present, unless the ` <missing part>" https://doc.dovecot.org/2.4.0/core/config/auth/databases/ldap.html#ldap-spec...
Is there another way to verify if account is disabled?
Johannes Nohl postmaster i-t-cloud
-- Johannes Nohl postmaster@i-t-cloud.de I am using dovecot 2.4.2 (almost) with new config language and I have a working configuration. However, the check for disabled users throws permanently errors in the log file, whenever a user is missing the ldap attribute for disabled. This is - in my view - due to a misfunction of Filter "default". passdb ldap { driver = ldap ldap_bind = yes ldap_filter = (&(|(objectClass=posixAccount)(objectClass=mailAccount))(uid=%{user})) fields { user = %{ldap:uid} nologin = %{ldap:shadowInactive | default(null)} reason = The account for this email address is disabled. } } This results in the following log line: *2026-03-31T00:46:31.102690+02:00 mailserver dovecot: auth(test,ipv4,sasl:plain)<YE81n0VOVuofEeSD>: Error: ldap: auth_passdb_post settings: Failed to parse configuration: Failed to expand passdb_fields/nologin setting variables: ldap: No such attribute 'shadowinactive' The right behaviour would be no logging on login success. Because the Filter "default" is intended to suppress any errors ("When value is missing or empty, you can use the default filter to provide value. Missing variables will cause errors and must be negated with default. This does not apply to all providers, some providers return empty when value is missing."). https://doc.dovecot.org/2.4.2/core/settings/variables.html#variable-expansio... As you may have seen I had to borrow null-value from sql db config also to make nologin ignoring a non present attribute. This is undocumented obviously. Instead, a non-working tip is provided ("Changed: 2.4.0 Extra fields can now also be set to empty string, "). However, the following does not work: "nologin = {ldap:shadowinactive | default("")}". https://doc.dovecot.org/2.4.2/core/settings/variables.html Also, the documentation is missing/hiding the part which explains that "default()" can be used to avoid error logs. PR regarding the documentation source is sent already. See "Fails if the attribute is not present, unless the ` <missing part>" https://doc.dovecot.org/2.4.0/core/config/auth/databases/ldap.html#ldap-spec... Is there another way to verify if account is disabled?
Johannes Nohl postmaster i-t-cloud
Hi!
Try %{ldap:shadowInactive | default}
default(null) refers to variable null, which does not exist.
Aki
openSUSE 16.0
dovecot --version 2.4.5 (c2b286c37a)
For testing I do setenforce 0 (SELINUX permissive). I can access user data as expected (sudo -u dovesrv -g dovesrv ...).
I can see that imap-login is passed successfully. By doing IMAP manually, I can startup imap and catch the pid before it hangs with 99.9% cpu usage.
strace -tt -o log -p 38339
The log reads:
12:19:26.132613 epoll_wait(12, [{events=EPOLLIN, data=0x563fe74a18a0}], 8, 1783633) = 1 12:19:52.572739 read(9, "A005 LIST \"\" *\n", 8192) = 15 12:19:52.573009 write(7, "CATEGORY\tmailbox\tstorage\n", 25) = 25 12:19:52.573227 brk(0x563fe74ee000) = 0x563fe74ee000
Dovecot 2.4.4 worked as expected. Downgrading "fixes" the issue, however I feel that it is related to one of the CVEs.
Initially I suspected quota (but not acl, it ran through), because last debug messages are
dovecot: quota-status(user)<26312><SoNJOgYPr2rIZgAAluaoaw>: Debug: acl: initializing backend vfile dovecot: quota-status(user)<26312><SoNJOgYPr2rIZgAAluaoaw>: Debug: acl: acl username = florian dovecot: quota-status(user)<26312><SoNJOgYPr2rIZgAAluaoaw>: Debug: acl: owner = no dovecot: quota-status(user)<26312><SoNJOgYPr2rIZgAAluaoaw>: Debug: acl: ignore = no dovecot: quota-status(user)<26312><SoNJOgYPr2rIZgAAluaoaw>: Debug: quota-count: quota_over_status check: quota_over_mask unset - skipping dovecot: quota-status(user)<26312><SoNJOgYPr2rIZgAAluaoaw>: Debug: quota-count: quota_over_status check: quota_over_mask unset - skipping
Disabling quota-status service did not help though.
doveadm mailbox ... has the same effect.
Freeing cpu requires a kill -9 of imap, regular kill does not work.
Little wired is the package info, I guess packaging did not update the meta data. zypper info dovecot24 prints (see Version):
Repository : repo-oss (16.0) Name : dovecot24 Version : 2.4.4-160000.2.1 Arch : x86_64 Anbieter : SUSE LLC <https://www.suse.com/> Installierte Größe : 15,2 MiB Installiert : Ja Status : aktuell Quellpaket : dovecot24-2.4.4-160000.2.1.src Upstream-URL : https://www.dovecot.org Zusammenfassung : IMAP and POP3 Server Written Primarily with Security in Mind
-- Best Johannes Nohl
participants (2)
-
Aki Tuomi
-
Johannes Nohl