Hi Guix!

I've been working really hard to complete a complete guix interfce to
the Exim service, but I'm havig trouble with a particularly free-form
portion of the configuration: Access Control Lists.

acl_check_data:
  deny    condition  = ${if > {$max_received_linelength}{998}}
          message    = maximum allowed line length is 998 octets, \
                       got $max_received_linelength
  deny    !verify =     header_syntax
          message =     header syntax
          log_message = header syntax ($acl_verify_message)
  accept

An access control in exim is a name, followed by a list of statements.
A statement is a verb followed by a list of clauses.  I could define
some configs like

(define-configuration acl
  (name string "")
  (body list ""))
(define-configuration acl-statement
  (verb string "")
  (body list "")
(define-condition acl-clause
...)

then I could translate the above to

(acl (name "acl_check_data")
     (body (list (acl-statement (verb "deny")
                                (body (list (acl-clause (condition "${if > 
{$max_received_linelength}{998}}"))
                                            (acl-clause (message "maximum 
allowed line length is 998 octets, got $max_received_linelength")))))
                 (acl-statement (verb "deny")
                                (body (list
                                       (acl-clause (!verify "header_syntax"))
                                       (acl-clause (message "header syntax"))
                                       (acl-clause (log-message "header syntax 
($acl_verify_message)"))))))))

But that feels excessive.  Most these records are just an identifier,
followed by a free-form list.  Isn't current item plus a list the
definition of a list?  The guix docs say we shouldn't "abuse lists", but
this feels like abuse of records".  The alternative to the above using
lists would be:

'("acl_check_data"
  (deny (condition "${if > {$max_received_linelength}{998}}")
        (message "maximum allowed line length is 998 octets, got 
$max_received_linelength"))
  (deny (!verify "header_syntax")
        (message "header syntax")
        (log-message "header syntax ($acl_verify_message)")))

Which feels cleaner to me.  Now, acl-clause above gives some benefit as
far as detecting typos and some syntax verification, so maybe I need
something in-between.

Any thoughts?  Should I keep the acl-statement and acl configuration
record types, or is it ok to use lists here?


-Zacchae

  • At the boundry be... Development of GNU Guix and the GNU System distribution.
    • Re: At the b... Development of GNU Guix and the GNU System distribution.
      • Re: At t... Development of GNU Guix and the GNU System distribution.
        • Re: ... Development of GNU Guix and the GNU System distribution.
          • ... Sergio Pastor Pérez
            • ... Development of GNU Guix and the GNU System distribution.
              • ... Development of GNU Guix and the GNU System distribution.
                • ... Sergio Pastor Pérez
                • ... Tomas Volf
                • ... Sergio Pastor Pérez
                • ... Ludovic Courtès

Reply via email to