GnuTLS: Fix client detection of server reject of client cert under TLS1.3
[exim.git] / src / src / globals.c
1 /*************************************************
2 * Exim - an Internet mail transport agent *
3 *************************************************/
4
5 /* Copyright (c) University of Cambridge 1995 - 2018 */
6 /* See the file NOTICE for conditions of use and distribution. */
7
8 /* All the global variables are defined together in this one module, so
9 that they are easy to find. */
10
11 #include "exim.h"
12
13
14 /* Generic options for auths, all of which live inside auth_instance
15 data blocks and hence have the opt_public flag set. */
16
17 optionlist optionlist_auths[] = {
18 { "client_condition", opt_stringptr | opt_public,
19 (void *)(offsetof(auth_instance, client_condition)) },
20 { "client_set_id", opt_stringptr | opt_public,
21 (void *)(offsetof(auth_instance, set_client_id)) },
22 { "driver", opt_stringptr | opt_public,
23 (void *)(offsetof(auth_instance, driver_name)) },
24 { "public_name", opt_stringptr | opt_public,
25 (void *)(offsetof(auth_instance, public_name)) },
26 { "server_advertise_condition", opt_stringptr | opt_public,
27 (void *)(offsetof(auth_instance, advertise_condition))},
28 { "server_condition", opt_stringptr | opt_public,
29 (void *)(offsetof(auth_instance, server_condition)) },
30 { "server_debug_print", opt_stringptr | opt_public,
31 (void *)(offsetof(auth_instance, server_debug_string)) },
32 { "server_mail_auth_condition", opt_stringptr | opt_public,
33 (void *)(offsetof(auth_instance, mail_auth_condition)) },
34 { "server_set_id", opt_stringptr | opt_public,
35 (void *)(offsetof(auth_instance, set_id)) }
36 };
37
38 int optionlist_auths_size = nelem(optionlist_auths);
39
40 /* An empty host aliases list. */
41
42 uschar *no_aliases = NULL;
43
44
45 /* For comments on these variables, see globals.h. I'm too idle to
46 duplicate them here... */
47
48 #ifdef EXIM_PERL
49 uschar *opt_perl_startup = NULL;
50 BOOL opt_perl_at_start = FALSE;
51 BOOL opt_perl_started = FALSE;
52 BOOL opt_perl_taintmode = FALSE;
53 #endif
54
55 #ifdef EXPAND_DLFUNC
56 tree_node *dlobj_anchor = NULL;
57 #endif
58
59 #ifdef LOOKUP_IBASE
60 uschar *ibase_servers = NULL;
61 #endif
62
63 #ifdef LOOKUP_LDAP
64 uschar *eldap_ca_cert_dir = NULL;
65 uschar *eldap_ca_cert_file = NULL;
66 uschar *eldap_cert_file = NULL;
67 uschar *eldap_cert_key = NULL;
68 uschar *eldap_cipher_suite = NULL;
69 uschar *eldap_default_servers = NULL;
70 uschar *eldap_require_cert = NULL;
71 int eldap_version = -1;
72 BOOL eldap_start_tls = FALSE;
73 #endif
74
75 #ifdef LOOKUP_MYSQL
76 uschar *mysql_servers = NULL;
77 #endif
78
79 #ifdef LOOKUP_ORACLE
80 uschar *oracle_servers = NULL;
81 #endif
82
83 #ifdef LOOKUP_PGSQL
84 uschar *pgsql_servers = NULL;
85 #endif
86
87 #ifdef LOOKUP_REDIS
88 uschar *redis_servers = NULL;
89 #endif
90
91 #ifdef LOOKUP_SQLITE
92 int sqlite_lock_timeout = 5;
93 #endif
94
95 #ifdef SUPPORT_MOVE_FROZEN_MESSAGES
96 BOOL move_frozen_messages = FALSE;
97 #endif
98
99 /* These variables are outside the #ifdef because it keeps the code less
100 cluttered in several places (e.g. during logging) if we can always refer to
101 them. Also, the tls_ variables are now always visible. Note that these are
102 only used for smtp connections, not for service-daemon access. */
103
104 tls_support tls_in = {
105 .active = {.sock = -1},
106 .bits = 0,
107 .certificate_verified = FALSE,
108 #ifdef SUPPORT_DANE
109 .dane_verified = FALSE,
110 .tlsa_usage = 0,
111 #endif
112 .cipher = NULL,
113 .on_connect = FALSE,
114 .on_connect_ports = NULL,
115 .ourcert = NULL,
116 .peercert = NULL,
117 .peerdn = NULL,
118 .sni = NULL,
119 .ocsp = OCSP_NOT_REQ
120 };
121 tls_support tls_out = {
122 .active = {.sock = -1},
123 .bits = 0,
124 .certificate_verified = FALSE,
125 #ifdef SUPPORT_DANE
126 .dane_verified = FALSE,
127 .tlsa_usage = 0,
128 #endif
129 .cipher = NULL,
130 .on_connect = FALSE,
131 .on_connect_ports = NULL,
132 .ourcert = NULL,
133 .peercert = NULL,
134 .peerdn = NULL,
135 .sni = NULL,
136 .ocsp = OCSP_NOT_REQ
137 };
138
139 uschar *dsn_envid = NULL;
140 int dsn_ret = 0;
141 const pcre *regex_DSN = NULL;
142 uschar *dsn_advertise_hosts = NULL;
143
144 #ifdef SUPPORT_TLS
145 BOOL gnutls_compat_mode = FALSE;
146 BOOL gnutls_allow_auto_pkcs11 = FALSE;
147 uschar *openssl_options = NULL;
148 const pcre *regex_STARTTLS = NULL;
149 uschar *tls_advertise_hosts = US"*";
150 uschar *tls_certificate = NULL;
151 uschar *tls_crl = NULL;
152 /* This default matches NSS DH_MAX_P_BITS value at current time (2012), because
153 that's the interop problem which has been observed: GnuTLS suggesting a higher
154 bit-count as "NORMAL" (2432) and Thunderbird dropping connection. */
155 int tls_dh_max_bits = 2236;
156 uschar *tls_dhparam = NULL;
157 uschar *tls_eccurve = US"auto";
158 # ifndef DISABLE_OCSP
159 uschar *tls_ocsp_file = NULL;
160 # endif
161 uschar *tls_privatekey = NULL;
162 BOOL tls_remember_esmtp = FALSE;
163 uschar *tls_require_ciphers = NULL;
164 # ifdef EXPERIMENTAL_REQUIRETLS
165 uschar tls_requiretls = 0; /* REQUIRETLS_MSG etc. bit #defines */
166 uschar *tls_advertise_requiretls = US"*";
167 const pcre *regex_REQUIRETLS = NULL;
168 # endif
169 uschar *tls_try_verify_hosts = NULL;
170 uschar *tls_verify_certificates= US"system";
171 uschar *tls_verify_hosts = NULL;
172 #else /*!SUPPORT_TLS*/
173 uschar *tls_advertise_hosts = NULL;
174 #endif
175
176 #ifndef DISABLE_PRDR
177 /* Per Recipient Data Response variables */
178 BOOL prdr_enable = FALSE;
179 BOOL prdr_requested = FALSE;
180 const pcre *regex_PRDR = NULL;
181 #endif
182
183 #ifdef SUPPORT_I18N
184 const pcre *regex_UTF8 = NULL;
185 #endif
186
187 /* Input-reading functions for messages, so we can use special ones for
188 incoming TCP/IP. The defaults use stdin. We never need these for any
189 stand-alone tests. */
190
191 #if !defined(STAND_ALONE) && !defined(MACRO_PREDEF)
192 int (*lwr_receive_getc)(unsigned) = stdin_getc;
193 uschar * (*lwr_receive_getbuf)(unsigned *) = NULL;
194 int (*lwr_receive_ungetc)(int) = stdin_ungetc;
195 int (*receive_getc)(unsigned) = stdin_getc;
196 uschar * (*receive_getbuf)(unsigned *) = NULL;
197 void (*receive_get_cache)(void)= NULL;
198 int (*receive_ungetc)(int) = stdin_ungetc;
199 int (*receive_feof)(void) = stdin_feof;
200 int (*receive_ferror)(void) = stdin_ferror;
201 BOOL (*receive_smtp_buffered)(void) = NULL; /* Only used for SMTP */
202 #endif
203
204
205 /* List of per-address expansion variables for clearing and saving/restoring
206 when verifying one address while routing/verifying another. We have to have
207 the size explicit, because it is referenced from more than one module. */
208
209 const uschar **address_expansions[ADDRESS_EXPANSIONS_COUNT] = {
210 CUSS &deliver_address_data,
211 CUSS &deliver_domain,
212 CUSS &deliver_domain_data,
213 CUSS &deliver_domain_orig,
214 CUSS &deliver_domain_parent,
215 CUSS &deliver_localpart,
216 CUSS &deliver_localpart_data,
217 CUSS &deliver_localpart_orig,
218 CUSS &deliver_localpart_parent,
219 CUSS &deliver_localpart_prefix,
220 CUSS &deliver_localpart_suffix,
221 CUSS (uschar **)(&deliver_recipients),
222 CUSS &deliver_host,
223 CUSS &deliver_home,
224 CUSS &address_file,
225 CUSS &address_pipe,
226 CUSS &self_hostname,
227 NULL };
228
229 int address_expansions_count = sizeof(address_expansions)/sizeof(uschar **);
230
231 /******************************************************************************/
232 /* General global variables. Boolean flags are done as a group
233 so that only one bit each is needed, packed, for all those we never
234 need to take a pointer - and only a char for the rest.
235 This means a struct, unfortunately since it clutters the sourcecode. */
236
237 struct global_flags f =
238 {
239 .acl_temp_details = FALSE,
240 .active_local_from_check = FALSE,
241 .active_local_sender_retain = FALSE,
242 .address_test_mode = FALSE,
243 .admin_user = FALSE,
244 .allow_auth_unadvertised= FALSE,
245 .allow_unqualified_recipient = TRUE, /* For local messages */
246 .allow_unqualified_sender = TRUE, /* Reset for SMTP */
247 .authentication_local = FALSE,
248
249 .background_daemon = TRUE,
250
251 .chunking_offered = FALSE,
252 .config_changed = FALSE,
253 .continue_more = FALSE,
254
255 .daemon_listen = FALSE,
256 .debug_daemon = FALSE,
257 .deliver_firsttime = FALSE,
258 .deliver_force = FALSE,
259 .deliver_freeze = FALSE,
260 .deliver_force_thaw = FALSE,
261 .deliver_manual_thaw = FALSE,
262 .deliver_selectstring_regex = FALSE,
263 .deliver_selectstring_sender_regex = FALSE,
264 .disable_callout_flush = FALSE,
265 .disable_delay_flush = FALSE,
266 .disable_logging = FALSE,
267 #ifndef DISABLE_DKIM
268 .dkim_disable_verify = FALSE,
269 #endif
270 #ifdef EXPERIMENTAL_DMARC
271 .dmarc_has_been_checked = FALSE,
272 .dmarc_disable_verify = FALSE,
273 .dmarc_enable_forensic = FALSE,
274 #endif
275 .dont_deliver = FALSE,
276 .dot_ends = TRUE,
277
278 .enable_dollar_recipients = FALSE,
279 .expand_string_forcedfail = FALSE,
280
281 .filter_running = FALSE,
282
283 .header_rewritten = FALSE,
284 .helo_verified = FALSE,
285 .helo_verify_failed = FALSE,
286 .host_checking_callout = FALSE,
287 .host_find_failed_syntax= FALSE,
288
289 .inetd_wait_mode = FALSE,
290 .is_inetd = FALSE,
291
292 .local_error_message = FALSE,
293 .log_testing_mode = FALSE,
294
295 #ifdef WITH_CONTENT_SCAN
296 .no_mbox_unspool = FALSE,
297 #endif
298 .no_multiline_responses = FALSE,
299
300 .parse_allow_group = FALSE,
301 .parse_found_group = FALSE,
302 .pipelining_enable = TRUE,
303 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
304 .proxy_session_failed = FALSE,
305 #endif
306
307 .queue_2stage = FALSE,
308 .queue_only_policy = FALSE,
309 .queue_run_first_delivery = FALSE,
310 .queue_run_force = FALSE,
311 .queue_run_local = FALSE,
312 .queue_running = FALSE,
313 .queue_smtp = FALSE,
314
315 .really_exim = TRUE,
316 .receive_call_bombout = FALSE,
317 .recipients_discarded = FALSE,
318 .running_in_test_harness = FALSE,
319
320 .search_find_defer = FALSE,
321 .sender_address_forced = FALSE,
322 .sender_host_notsocket = FALSE,
323 .sender_host_unknown = FALSE,
324 .sender_local = FALSE,
325 .sender_name_forced = FALSE,
326 .sender_set_untrusted = FALSE,
327 .smtp_authenticated = FALSE,
328 #ifdef EXPERIMENTAL_PIPE_CONNECT
329 .smtp_in_early_pipe_advertised = FALSE,
330 .smtp_in_early_pipe_no_auth = FALSE,
331 .smtp_in_early_pipe_used = FALSE,
332 #endif
333 .smtp_in_pipelining_advertised = FALSE,
334 .smtp_in_pipelining_used = FALSE,
335 .spool_file_wireformat = FALSE,
336 .submission_mode = FALSE,
337 .suppress_local_fixups = FALSE,
338 .suppress_local_fixups_default = FALSE,
339 .synchronous_delivery = FALSE,
340 .system_filtering = FALSE,
341
342 .tcp_fastopen_ok = FALSE,
343 .tcp_in_fastopen = FALSE,
344 .tcp_in_fastopen_data = FALSE,
345 .tcp_in_fastopen_logged = FALSE,
346 .tcp_out_fastopen_logged= FALSE,
347 .timestamps_utc = FALSE,
348 .transport_filter_timed_out = FALSE,
349 .trusted_caller = FALSE,
350 .trusted_config = TRUE,
351 };
352
353 /******************************************************************************/
354 /* These are the flags which are either variables or mainsection options,
355 so an address is needed for access, or are exported to local_scan. */
356
357 BOOL accept_8bitmime = TRUE; /* deliberately not RFC compliant */
358 BOOL allow_domain_literals = FALSE;
359 BOOL allow_mx_to_ip = FALSE;
360 BOOL allow_utf8_domains = FALSE;
361 BOOL authentication_failed = FALSE;
362
363 BOOL bounce_return_body = TRUE;
364 BOOL bounce_return_message = TRUE;
365 BOOL check_rfc2047_length = TRUE;
366 BOOL commandline_checks_require_admin = FALSE;
367
368 #ifdef EXPERIMENTAL_DCC
369 BOOL dcc_direct_add_header = FALSE;
370 #endif
371 BOOL debug_store = FALSE;
372 BOOL delivery_date_remove = TRUE;
373 BOOL deliver_drop_privilege = FALSE;
374 #ifdef ENABLE_DISABLE_FSYNC
375 BOOL disable_fsync = FALSE;
376 #endif
377 BOOL disable_ipv6 = FALSE;
378 BOOL dns_csa_use_reverse = TRUE;
379 BOOL drop_cr = FALSE; /* No longer used */
380
381 BOOL envelope_to_remove = TRUE;
382 BOOL exim_gid_set = TRUE; /* This gid is always set */
383 BOOL exim_uid_set = TRUE; /* This uid is always set */
384 BOOL extract_addresses_remove_arguments = TRUE;
385
386 BOOL host_checking = FALSE;
387 BOOL host_lookup_deferred = FALSE;
388 BOOL host_lookup_failed = FALSE;
389 BOOL ignore_fromline_local = FALSE;
390
391 BOOL local_from_check = TRUE;
392 BOOL local_sender_retain = FALSE;
393 BOOL log_timezone = FALSE;
394 BOOL message_body_newlines = FALSE;
395 BOOL message_logs = TRUE;
396 #ifdef SUPPORT_I18N
397 BOOL message_smtputf8 = FALSE;
398 #endif
399 BOOL mua_wrapper = FALSE;
400
401 BOOL preserve_message_logs = FALSE;
402 BOOL print_topbitchars = FALSE;
403 BOOL prod_requires_admin = TRUE;
404 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
405 BOOL proxy_session = FALSE;
406 #endif
407
408 BOOL queue_list_requires_admin = TRUE;
409 BOOL queue_only = FALSE;
410 BOOL queue_only_load_latch = TRUE;
411 BOOL queue_only_override = TRUE;
412 BOOL queue_run_in_order = FALSE;
413 BOOL recipients_max_reject = FALSE;
414 BOOL return_path_remove = TRUE;
415
416 BOOL smtp_batched_input = FALSE;
417 BOOL sender_helo_dnssec = FALSE;
418 BOOL sender_host_dnssec = FALSE;
419 BOOL smtp_accept_keepalive = TRUE;
420 BOOL smtp_check_spool_space = TRUE;
421 BOOL smtp_enforce_sync = TRUE;
422 BOOL smtp_etrn_serialize = TRUE;
423 BOOL smtp_input = FALSE;
424 BOOL smtp_return_error_details = FALSE;
425 #ifdef SUPPORT_SPF
426 BOOL spf_result_guessed = FALSE;
427 #endif
428 BOOL split_spool_directory = FALSE;
429 BOOL spool_wireformat = FALSE;
430 #ifdef EXPERIMENTAL_SRS
431 BOOL srs_usehash = TRUE;
432 BOOL srs_usetimestamp = TRUE;
433 #endif
434 BOOL strict_acl_vars = FALSE;
435 BOOL strip_excess_angle_brackets = FALSE;
436 BOOL strip_trailing_dot = FALSE;
437 BOOL syslog_duplication = TRUE;
438 BOOL syslog_pid = TRUE;
439 BOOL syslog_timestamp = TRUE;
440 BOOL system_filter_gid_set = FALSE;
441 BOOL system_filter_uid_set = FALSE;
442
443 BOOL tcp_nodelay = TRUE;
444 BOOL write_rejectlog = TRUE;
445
446 /******************************************************************************/
447
448 header_line *acl_added_headers = NULL;
449 tree_node *acl_anchor = NULL;
450 uschar *acl_arg[9] = {NULL, NULL, NULL, NULL, NULL,
451 NULL, NULL, NULL, NULL};
452 int acl_narg = 0;
453
454 int acl_level = 0;
455
456 uschar *acl_not_smtp = NULL;
457 #ifdef WITH_CONTENT_SCAN
458 uschar *acl_not_smtp_mime = NULL;
459 #endif
460 uschar *acl_not_smtp_start = NULL;
461 uschar *acl_removed_headers = NULL;
462 uschar *acl_smtp_auth = NULL;
463 uschar *acl_smtp_connect = NULL;
464 uschar *acl_smtp_data = NULL;
465 #ifndef DISABLE_PRDR
466 uschar *acl_smtp_data_prdr = US"accept";
467 #endif
468 #ifndef DISABLE_DKIM
469 uschar *acl_smtp_dkim = NULL;
470 #endif
471 uschar *acl_smtp_etrn = NULL;
472 uschar *acl_smtp_expn = NULL;
473 uschar *acl_smtp_helo = NULL;
474 uschar *acl_smtp_mail = NULL;
475 uschar *acl_smtp_mailauth = NULL;
476 #ifdef WITH_CONTENT_SCAN
477 uschar *acl_smtp_mime = NULL;
478 #endif
479 uschar *acl_smtp_notquit = NULL;
480 uschar *acl_smtp_predata = NULL;
481 uschar *acl_smtp_quit = NULL;
482 uschar *acl_smtp_rcpt = NULL;
483 uschar *acl_smtp_starttls = NULL;
484 uschar *acl_smtp_vrfy = NULL;
485
486 tree_node *acl_var_c = NULL;
487 tree_node *acl_var_m = NULL;
488 uschar *acl_verify_message = NULL;
489 string_item *acl_warn_logged = NULL;
490
491 /* Names of SMTP places for use in ACL error messages, and corresponding SMTP
492 error codes - keep in step with definitions of ACL_WHERE_xxxx in macros.h. */
493
494 uschar *acl_wherenames[] = { US"RCPT",
495 US"MAIL",
496 US"PREDATA",
497 US"MIME",
498 US"DKIM",
499 US"DATA",
500 #ifndef DISABLE_PRDR
501 US"PRDR",
502 #endif
503 US"non-SMTP",
504 US"AUTH",
505 US"connection",
506 US"ETRN",
507 US"EXPN",
508 US"EHLO or HELO",
509 US"MAILAUTH",
510 US"non-SMTP-start",
511 US"NOTQUIT",
512 US"QUIT",
513 US"STARTTLS",
514 US"VRFY",
515 US"delivery",
516 US"unknown"
517 };
518
519 uschar *acl_wherecodes[] = { US"550", /* RCPT */
520 US"550", /* MAIL */
521 US"550", /* PREDATA */
522 US"550", /* MIME */
523 US"550", /* DKIM */
524 US"550", /* DATA */
525 #ifndef DISABLE_PRDR
526 US"550", /* RCPT PRDR */
527 #endif
528 US"0", /* not SMTP; not relevant */
529 US"503", /* AUTH */
530 US"550", /* connect */
531 US"458", /* ETRN */
532 US"550", /* EXPN */
533 US"550", /* HELO/EHLO */
534 US"0", /* MAILAUTH; not relevant */
535 US"0", /* not SMTP; not relevant */
536 US"0", /* NOTQUIT; not relevant */
537 US"0", /* QUIT; not relevant */
538 US"550", /* STARTTLS */
539 US"252", /* VRFY */
540 US"0", /* delivery; not relevant */
541 US"0" /* unknown; not relevant */
542 };
543
544 uschar *add_environment = NULL;
545 address_item *addr_duplicate = NULL;
546
547 address_item address_defaults = {
548 .next = NULL,
549 .parent = NULL,
550 .first = NULL,
551 .dupof = NULL,
552 .start_router = NULL,
553 .router = NULL,
554 .transport = NULL,
555 .host_list = NULL,
556 .host_used = NULL,
557 .fallback_hosts = NULL,
558 .reply = NULL,
559 .retries = NULL,
560 .address = NULL,
561 .unique = NULL,
562 .cc_local_part = NULL,
563 .lc_local_part = NULL,
564 .local_part = NULL,
565 .prefix = NULL,
566 .suffix = NULL,
567 .domain = NULL,
568 .address_retry_key = NULL,
569 .domain_retry_key = NULL,
570 .current_dir = NULL,
571 .home_dir = NULL,
572 .message = NULL,
573 .user_message = NULL,
574 .onetime_parent = NULL,
575 .pipe_expandn = NULL,
576 .return_filename = NULL,
577 .self_hostname = NULL,
578 .shadow_message = NULL,
579 #ifdef SUPPORT_TLS
580 .cipher = NULL,
581 .ourcert = NULL,
582 .peercert = NULL,
583 .peerdn = NULL,
584 .ocsp = OCSP_NOT_REQ,
585 #endif
586 #ifdef EXPERIMENTAL_DSN_INFO
587 .smtp_greeting = NULL,
588 .helo_response = NULL,
589 #endif
590 .authenticator = NULL,
591 .auth_id = NULL,
592 .auth_sndr = NULL,
593 .dsn_orcpt = NULL,
594 .dsn_flags = 0,
595 .dsn_aware = 0,
596 .uid = (uid_t)(-1),
597 .gid = (gid_t)(-1),
598 .flags = { 0 },
599 .domain_cache = { 0 }, /* domain_cache - any larger array should be zeroed */
600 .localpart_cache = { 0 }, /* localpart_cache - ditto */
601 .mode = -1,
602 .more_errno = 0,
603 .delivery_usec = 0,
604 .basic_errno = ERRNO_UNKNOWNERROR,
605 .child_count = 0,
606 .return_file = -1,
607 .special_action = SPECIAL_NONE,
608 .transport_return = DEFER,
609 .prop = { /* fields that are propagated to children */
610 .address_data = NULL,
611 .domain_data = NULL,
612 .localpart_data = NULL,
613 .errors_address = NULL,
614 .extra_headers = NULL,
615 .remove_headers = NULL,
616 #ifdef EXPERIMENTAL_SRS
617 .srs_sender = NULL,
618 #endif
619 .ignore_error = FALSE,
620 #ifdef SUPPORT_I18N
621 .utf8_msg = FALSE,
622 .utf8_downcvt = FALSE,
623 .utf8_downcvt_maybe = FALSE
624 #endif
625 }
626 };
627
628 uschar *address_file = NULL;
629 uschar *address_pipe = NULL;
630 tree_node *addresslist_anchor = NULL;
631 int addresslist_count = 0;
632 gid_t *admin_groups = NULL;
633
634 #ifdef EXPERIMENTAL_ARC
635 struct arc_set *arc_received = NULL;
636 int arc_received_instance = 0;
637 int arc_oldest_pass = 0;
638 const uschar *arc_state = NULL;
639 const uschar *arc_state_reason = NULL;
640 #endif
641
642 uschar *authenticated_fail_id = NULL;
643 uschar *authenticated_id = NULL;
644 uschar *authenticated_sender = NULL;
645 auth_instance *auths = NULL;
646 uschar *auth_advertise_hosts = US"*";
647 auth_instance auth_defaults = {
648 .next = NULL,
649 .name = NULL,
650 .info = NULL,
651 .options_block = NULL,
652 .driver_name = NULL,
653 .advertise_condition = NULL,
654 .client_condition = NULL,
655 .public_name = NULL,
656 .set_id = NULL,
657 .set_client_id = NULL,
658 .mail_auth_condition = NULL,
659 .server_debug_string = NULL,
660 .server_condition = NULL,
661 .client = FALSE,
662 .server = FALSE,
663 .advertised = FALSE
664 };
665
666 uschar *auth_defer_msg = US"reason not recorded";
667 uschar *auth_defer_user_msg = US"";
668 uschar *auth_vars[AUTH_VARS];
669 int auto_thaw = 0;
670 #ifdef WITH_CONTENT_SCAN
671 int av_failed = FALSE; /* boolean but accessed as vtype_int*/
672 uschar *av_scanner = US"sophie:/var/run/sophie"; /* AV scanner */
673 #endif
674
675 #if BASE_62 == 62
676 uschar *base62_chars=
677 US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";
678 #else
679 uschar *base62_chars= US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ";
680 #endif
681
682 uschar *bi_command = NULL;
683 uschar *big_buffer = NULL;
684 int big_buffer_size = BIG_BUFFER_SIZE;
685 #ifdef EXPERIMENTAL_BRIGHTMAIL
686 uschar *bmi_alt_location = NULL;
687 uschar *bmi_base64_tracker_verdict = NULL;
688 uschar *bmi_base64_verdict = NULL;
689 uschar *bmi_config_file = US"/opt/brightmail/etc/brightmail.cfg";
690 int bmi_deliver = 1;
691 int bmi_run = 0;
692 uschar *bmi_verdicts = NULL;
693 #endif
694 int bsmtp_transaction_linecount = 0;
695 int body_8bitmime = 0;
696 int body_linecount = 0;
697 int body_zerocount = 0;
698 uschar *bounce_message_file = NULL;
699 uschar *bounce_message_text = NULL;
700 uschar *bounce_recipient = NULL;
701 int bounce_return_linesize_limit = 998;
702 int bounce_return_size_limit = 100*1024;
703 uschar *bounce_sender_authentication = NULL;
704
705 uschar *callout_address = NULL;
706 int callout_cache_domain_positive_expire = 7*24*60*60;
707 int callout_cache_domain_negative_expire = 3*60*60;
708 int callout_cache_positive_expire = 24*60*60;
709 int callout_cache_negative_expire = 2*60*60;
710 uschar *callout_random_local_part = US"$primary_hostname-$tod_epoch-testing";
711 uschar *check_dns_names_pattern= US"(?i)^(?>(?(1)\\.|())[^\\W](?>[a-z0-9/_-]*[^\\W])?)+(\\.?)$";
712 int check_log_inodes = 100;
713 int_eximarith_t check_log_space = 10*1024; /* 10K Kbyte == 10MB */
714 int check_spool_inodes = 100;
715 int_eximarith_t check_spool_space = 10*1024; /* 10K Kbyte == 10MB */
716
717 uschar *chunking_advertise_hosts = US"*";
718 unsigned chunking_datasize = 0;
719 unsigned chunking_data_left = 0;
720 chunking_state_t chunking_state= CHUNKING_NOT_OFFERED;
721 const pcre *regex_CHUNKING = NULL;
722
723 uschar *client_authenticator = NULL;
724 uschar *client_authenticated_id = NULL;
725 uschar *client_authenticated_sender = NULL;
726 int clmacro_count = 0;
727 uschar *clmacros[MAX_CLMACROS];
728 FILE *config_file = NULL;
729 const uschar *config_filename = NULL;
730 int config_lineno = 0;
731 #ifdef CONFIGURE_GROUP
732 gid_t config_gid = CONFIGURE_GROUP;
733 #else
734 gid_t config_gid = 0;
735 #endif
736 uschar *config_main_filelist = US CONFIGURE_FILE
737 "\0<-----------Space to patch configure_filename->";
738 uschar *config_main_filename = NULL;
739 uschar *config_main_directory = NULL;
740
741 #ifdef CONFIGURE_OWNER
742 uid_t config_uid = CONFIGURE_OWNER;
743 #else
744 uid_t config_uid = 0;
745 #endif
746
747 int connection_max_messages= -1;
748 uschar *continue_proxy_cipher = NULL;
749 uschar *continue_hostname = NULL;
750 uschar *continue_host_address = NULL;
751 int continue_sequence = 1;
752 uschar *continue_transport = NULL;
753
754 uschar *csa_status = NULL;
755 cut_t cutthrough = {
756 .callout_hold_only = FALSE, /* verify-only: normal delivery */
757 .delivery = FALSE, /* when to attempt */
758 .defer_pass = FALSE, /* on defer: spool locally */
759 .is_tls = FALSE, /* not a TLS conn yet */
760 .cctx = {.sock = -1}, /* open connection */
761 .nrcpt = 0, /* number of addresses */
762 };
763
764 uschar *daemon_smtp_port = US"smtp";
765 int daemon_startup_retries = 9;
766 int daemon_startup_sleep = 30;
767
768 #ifdef EXPERIMENTAL_DCC
769 uschar *dcc_header = NULL;
770 uschar *dcc_result = NULL;
771 uschar *dccifd_address = US"/usr/local/dcc/var/dccifd";
772 uschar *dccifd_options = US"header";
773 #endif
774
775 int debug_fd = -1;
776 FILE *debug_file = NULL;
777 int debug_notall[] = {
778 Di_memory,
779 Di_noutf8,
780 -1
781 };
782 bit_table debug_options[] = { /* must be in alphabetical order and use
783 only the enum values from macro.h */
784 BIT_TABLE(D, acl),
785 BIT_TABLE(D, all),
786 BIT_TABLE(D, auth),
787 BIT_TABLE(D, deliver),
788 BIT_TABLE(D, dns),
789 BIT_TABLE(D, dnsbl),
790 BIT_TABLE(D, exec),
791 BIT_TABLE(D, expand),
792 BIT_TABLE(D, filter),
793 BIT_TABLE(D, hints_lookup),
794 BIT_TABLE(D, host_lookup),
795 BIT_TABLE(D, ident),
796 BIT_TABLE(D, interface),
797 BIT_TABLE(D, lists),
798 BIT_TABLE(D, load),
799 BIT_TABLE(D, local_scan),
800 BIT_TABLE(D, lookup),
801 BIT_TABLE(D, memory),
802 BIT_TABLE(D, noutf8),
803 BIT_TABLE(D, pid),
804 BIT_TABLE(D, process_info),
805 BIT_TABLE(D, queue_run),
806 BIT_TABLE(D, receive),
807 BIT_TABLE(D, resolver),
808 BIT_TABLE(D, retry),
809 BIT_TABLE(D, rewrite),
810 BIT_TABLE(D, route),
811 BIT_TABLE(D, timestamp),
812 BIT_TABLE(D, tls),
813 BIT_TABLE(D, transport),
814 BIT_TABLE(D, uid),
815 BIT_TABLE(D, verify),
816 };
817 int debug_options_count = nelem(debug_options);
818
819 unsigned int debug_selector = 0;
820 int delay_warning[DELAY_WARNING_SIZE] = { DELAY_WARNING_SIZE, 1, 24*60*60 };
821 uschar *delay_warning_condition=
822 US"${if or {"
823 "{ !eq{$h_list-id:$h_list-post:$h_list-subscribe:}{} }"
824 "{ match{$h_precedence:}{(?i)bulk|list|junk} }"
825 "{ match{$h_auto-submitted:}{(?i)auto-generated|auto-replied} }"
826 "} {no}{yes}}";
827 uschar *deliver_address_data = NULL;
828 int deliver_datafile = -1;
829 const uschar *deliver_domain = NULL;
830 uschar *deliver_domain_data = NULL;
831 const uschar *deliver_domain_orig = NULL;
832 const uschar *deliver_domain_parent = NULL;
833 time_t deliver_frozen_at = 0;
834 uschar *deliver_home = NULL;
835 const uschar *deliver_host = NULL;
836 const uschar *deliver_host_address = NULL;
837 int deliver_host_port = 0;
838 uschar *deliver_in_buffer = NULL;
839 ino_t deliver_inode = 0;
840 uschar *deliver_localpart = NULL;
841 uschar *deliver_localpart_data = NULL;
842 uschar *deliver_localpart_orig = NULL;
843 uschar *deliver_localpart_parent = NULL;
844 uschar *deliver_localpart_prefix = NULL;
845 uschar *deliver_localpart_suffix = NULL;
846 uschar *deliver_out_buffer = NULL;
847 int deliver_queue_load_max = -1;
848 address_item *deliver_recipients = NULL;
849 uschar *deliver_selectstring = NULL;
850 uschar *deliver_selectstring_sender = NULL;
851
852 #ifndef DISABLE_DKIM
853 unsigned dkim_collect_input = 0;
854 uschar *dkim_cur_signer = NULL;
855 int dkim_key_length = 0;
856 void *dkim_signatures = NULL;
857 uschar *dkim_signers = NULL;
858 uschar *dkim_signing_domain = NULL;
859 uschar *dkim_signing_selector = NULL;
860 uschar *dkim_verify_overall = NULL;
861 uschar *dkim_verify_signers = US"$dkim_signers";
862 uschar *dkim_verify_status = NULL;
863 uschar *dkim_verify_reason = NULL;
864 #endif
865 #ifdef EXPERIMENTAL_DMARC
866 uschar *dmarc_domain_policy = NULL;
867 uschar *dmarc_forensic_sender = NULL;
868 uschar *dmarc_history_file = NULL;
869 uschar *dmarc_status = NULL;
870 uschar *dmarc_status_text = NULL;
871 uschar *dmarc_tld_file = NULL;
872 uschar *dmarc_used_domain = NULL;
873 #endif
874
875 uschar *dns_again_means_nonexist = NULL;
876 int dns_csa_search_limit = 5;
877 int dns_cname_loops = 1;
878 #ifdef SUPPORT_DANE
879 int dns_dane_ok = -1;
880 #endif
881 uschar *dns_ipv4_lookup = NULL;
882 int dns_retrans = 0;
883 int dns_retry = 0;
884 int dns_dnssec_ok = -1; /* <0 = not coerced */
885 uschar *dns_trust_aa = NULL;
886 int dns_use_edns0 = -1; /* <0 = not coerced */
887 uschar *dnslist_domain = NULL;
888 uschar *dnslist_matched = NULL;
889 uschar *dnslist_text = NULL;
890 uschar *dnslist_value = NULL;
891 tree_node *domainlist_anchor = NULL;
892 int domainlist_count = 0;
893 uschar *dsn_from = US DEFAULT_DSN_FROM;
894
895 int errno_quota = ERRNO_QUOTA;
896 uschar *errors_copy = NULL;
897 int error_handling = ERRORS_SENDER;
898 uschar *errors_reply_to = NULL;
899 int errors_sender_rc = EXIT_FAILURE;
900 #ifndef DISABLE_EVENT
901 uschar *event_action = NULL; /* expansion for delivery events */
902 uschar *event_data = NULL; /* auxiliary data variable for event */
903 int event_defer_errno = 0;
904 const uschar *event_name = NULL; /* event name variable */
905 #endif
906
907
908 gid_t exim_gid = EXIM_GID;
909 uschar *exim_path = US BIN_DIRECTORY "/exim"
910 "\0<---------------Space to patch exim_path->";
911 uid_t exim_uid = EXIM_UID;
912 int expand_level = 0; /* Nesting depth, indent for debug */
913 int expand_forbid = 0;
914 int expand_nlength[EXPAND_MAXN+1];
915 int expand_nmax = -1;
916 uschar *expand_nstring[EXPAND_MAXN+1];
917 uschar *expand_string_message;
918 uschar *extra_local_interfaces = NULL;
919
920 int fake_response = OK;
921 uschar *fake_response_text = US"Your message has been rejected but is "
922 "being kept for evaluation.\nIf it was a "
923 "legitimate message, it may still be "
924 "delivered to the target recipient(s).";
925 int filter_n[FILTER_VARIABLE_COUNT];
926 int filter_sn[FILTER_VARIABLE_COUNT];
927 int filter_test = FTEST_NONE;
928 uschar *filter_test_sfile = NULL;
929 uschar *filter_test_ufile = NULL;
930 uschar *filter_thisaddress = NULL;
931 int finduser_retries = 0;
932 uid_t fixed_never_users[] = { FIXED_NEVER_USERS };
933 uschar *freeze_tell = NULL;
934 uschar *freeze_tell_config = NULL;
935 uschar *fudged_queue_times = US"";
936
937 uschar *gecos_name = NULL;
938 uschar *gecos_pattern = NULL;
939 rewrite_rule *global_rewrite_rules = NULL;
940
941 volatile sig_atomic_t had_command_timeout = 0;
942 volatile sig_atomic_t had_command_sigterm = 0;
943 volatile sig_atomic_t had_data_timeout = 0;
944 volatile sig_atomic_t had_data_sigint = 0;
945 uschar *headers_charset = US HEADERS_CHARSET;
946 int header_insert_maxlen = 64 * 1024;
947 header_line *header_last = NULL;
948 header_line *header_list = NULL;
949 int header_maxsize = HEADER_MAXSIZE;
950 int header_line_maxsize = 0;
951
952 header_name header_names[] = {
953 /* name len allow_resent htype */
954 { US"bcc", 3, TRUE, htype_bcc },
955 { US"cc", 2, TRUE, htype_cc },
956 { US"date", 4, TRUE, htype_date },
957 { US"delivery-date", 13, FALSE, htype_delivery_date },
958 { US"envelope-to", 11, FALSE, htype_envelope_to },
959 { US"from", 4, TRUE, htype_from },
960 { US"message-id", 10, TRUE, htype_id },
961 { US"received", 8, FALSE, htype_received },
962 { US"reply-to", 8, FALSE, htype_reply_to },
963 { US"return-path", 11, FALSE, htype_return_path },
964 { US"sender", 6, TRUE, htype_sender },
965 { US"subject", 7, FALSE, htype_subject },
966 { US"to", 2, TRUE, htype_to }
967 };
968
969 int header_names_size = nelem(header_names);
970
971 uschar *helo_accept_junk_hosts = NULL;
972 uschar *helo_allow_chars = US"";
973 uschar *helo_lookup_domains = US"@ : @[]";
974 uschar *helo_try_verify_hosts = NULL;
975 uschar *helo_verify_hosts = NULL;
976 const uschar *hex_digits = CUS"0123456789abcdef";
977 uschar *hold_domains = NULL;
978 uschar *host_data = NULL;
979 uschar *host_lookup = NULL;
980 uschar *host_lookup_order = US"bydns:byaddr";
981 uschar *host_lookup_msg = US"";
982 int host_number = 0;
983 uschar *host_number_string = NULL;
984 uschar *host_reject_connection = NULL;
985 tree_node *hostlist_anchor = NULL;
986 int hostlist_count = 0;
987 uschar *hosts_treat_as_local = NULL;
988 uschar *hosts_connection_nolog = NULL;
989
990 int ignore_bounce_errors_after = 10*7*24*60*60; /* 10 weeks */
991 uschar *ignore_fromline_hosts = NULL;
992 int inetd_wait_timeout = -1;
993 uschar *initial_cwd = NULL;
994 uschar *interface_address = NULL;
995 int interface_port = -1;
996 uschar *iterate_item = NULL;
997
998 int journal_fd = -1;
999
1000 uschar *keep_environment = NULL;
1001
1002 int keep_malformed = 4*24*60*60; /* 4 days */
1003
1004 uschar *eldap_dn = NULL;
1005 int load_average = -2;
1006 uschar *local_from_prefix = NULL;
1007 uschar *local_from_suffix = NULL;
1008
1009 #if HAVE_IPV6
1010 uschar *local_interfaces = US"<; ::0 ; 0.0.0.0";
1011 #else
1012 uschar *local_interfaces = US"0.0.0.0";
1013 #endif
1014
1015 #ifdef HAVE_LOCAL_SCAN
1016 uschar *local_scan_data = NULL;
1017 int local_scan_timeout = 5*60;
1018 #endif
1019 gid_t local_user_gid = (gid_t)(-1);
1020 uid_t local_user_uid = (uid_t)(-1);
1021
1022 tree_node *localpartlist_anchor= NULL;
1023 int localpartlist_count = 0;
1024 uschar *log_buffer = NULL;
1025
1026 int log_default[] = { /* for initializing log_selector */
1027 Li_acl_warn_skipped,
1028 Li_connection_reject,
1029 Li_delay_delivery,
1030 Li_dkim,
1031 Li_dnslist_defer,
1032 Li_etrn,
1033 Li_host_lookup_failed,
1034 Li_lost_incoming_connection,
1035 Li_outgoing_interface, /* see d_log_interface in deliver.c */
1036 Li_msg_id,
1037 Li_queue_run,
1038 Li_rejected_header,
1039 Li_retry_defer,
1040 Li_sender_verify_fail,
1041 Li_size_reject,
1042 Li_skip_delivery,
1043 Li_smtp_confirmation,
1044 Li_tls_certificate_verified,
1045 Li_tls_cipher,
1046 -1
1047 };
1048
1049 uschar *log_file_path = US LOG_FILE_PATH
1050 "\0<--------------Space to patch log_file_path->";
1051
1052 int log_notall[] = {
1053 -1
1054 };
1055 bit_table log_options[] = { /* must be in alphabetical order */
1056 BIT_TABLE(L, 8bitmime),
1057 BIT_TABLE(L, acl_warn_skipped),
1058 BIT_TABLE(L, address_rewrite),
1059 BIT_TABLE(L, all),
1060 BIT_TABLE(L, all_parents),
1061 BIT_TABLE(L, arguments),
1062 BIT_TABLE(L, connection_reject),
1063 BIT_TABLE(L, delay_delivery),
1064 BIT_TABLE(L, deliver_time),
1065 BIT_TABLE(L, delivery_size),
1066 #ifndef DISABLE_DKIM
1067 BIT_TABLE(L, dkim),
1068 BIT_TABLE(L, dkim_verbose),
1069 #endif
1070 BIT_TABLE(L, dnslist_defer),
1071 BIT_TABLE(L, dnssec),
1072 BIT_TABLE(L, etrn),
1073 BIT_TABLE(L, host_lookup_failed),
1074 BIT_TABLE(L, ident_timeout),
1075 BIT_TABLE(L, incoming_interface),
1076 BIT_TABLE(L, incoming_port),
1077 BIT_TABLE(L, lost_incoming_connection),
1078 BIT_TABLE(L, millisec),
1079 BIT_TABLE(L, msg_id),
1080 BIT_TABLE(L, msg_id_created),
1081 BIT_TABLE(L, outgoing_interface),
1082 BIT_TABLE(L, outgoing_port),
1083 BIT_TABLE(L, pid),
1084 BIT_TABLE(L, pipelining),
1085 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1086 BIT_TABLE(L, proxy),
1087 #endif
1088 BIT_TABLE(L, queue_run),
1089 BIT_TABLE(L, queue_time),
1090 BIT_TABLE(L, queue_time_overall),
1091 BIT_TABLE(L, receive_time),
1092 BIT_TABLE(L, received_recipients),
1093 BIT_TABLE(L, received_sender),
1094 BIT_TABLE(L, rejected_header),
1095 { US"rejected_headers", Li_rejected_header },
1096 BIT_TABLE(L, retry_defer),
1097 BIT_TABLE(L, return_path_on_delivery),
1098 BIT_TABLE(L, sender_on_delivery),
1099 BIT_TABLE(L, sender_verify_fail),
1100 BIT_TABLE(L, size_reject),
1101 BIT_TABLE(L, skip_delivery),
1102 BIT_TABLE(L, smtp_confirmation),
1103 BIT_TABLE(L, smtp_connection),
1104 BIT_TABLE(L, smtp_incomplete_transaction),
1105 BIT_TABLE(L, smtp_mailauth),
1106 BIT_TABLE(L, smtp_no_mail),
1107 BIT_TABLE(L, smtp_protocol_error),
1108 BIT_TABLE(L, smtp_syntax_error),
1109 BIT_TABLE(L, subject),
1110 BIT_TABLE(L, tls_certificate_verified),
1111 BIT_TABLE(L, tls_cipher),
1112 BIT_TABLE(L, tls_peerdn),
1113 BIT_TABLE(L, tls_sni),
1114 BIT_TABLE(L, unknown_in_list),
1115 };
1116 int log_options_count = nelem(log_options);
1117
1118 int log_reject_target = 0;
1119 unsigned int log_selector[log_selector_size]; /* initialized in main() */
1120 uschar *log_selector_string = NULL;
1121 FILE *log_stderr = NULL;
1122 uschar *login_sender_address = NULL;
1123 uschar *lookup_dnssec_authenticated = NULL;
1124 int lookup_open_max = 25;
1125 uschar *lookup_value = NULL;
1126
1127 macro_item *macros_user = NULL;
1128 uschar *mailstore_basename = NULL;
1129 #ifdef WITH_CONTENT_SCAN
1130 uschar *malware_name = NULL; /* Virus Name */
1131 #endif
1132 int max_received_linelength= 0;
1133 int max_username_length = 0;
1134 int message_age = 0;
1135 uschar *message_body = NULL;
1136 uschar *message_body_end = NULL;
1137 int message_body_size = 0;
1138 int message_body_visible = 500;
1139 int message_ended = END_NOTSTARTED;
1140 uschar *message_headers = NULL;
1141 uschar *message_id;
1142 uschar *message_id_domain = NULL;
1143 uschar *message_id_text = NULL;
1144 struct timeval message_id_tv = { 0, 0 };
1145 uschar message_id_option[MESSAGE_ID_LENGTH + 3];
1146 uschar *message_id_external;
1147 int message_linecount = 0;
1148 int message_size = 0;
1149 uschar *message_size_limit = US"50M";
1150 #ifdef SUPPORT_I18N
1151 int message_utf8_downconvert = 0; /* -1 ifneeded; 0 never; 1 always */
1152 #endif
1153 uschar message_subdir[2] = { 0, 0 };
1154 uschar *message_reference = NULL;
1155
1156 /* MIME ACL expandables */
1157 #ifdef WITH_CONTENT_SCAN
1158 int mime_anomaly_level = 0;
1159 const uschar *mime_anomaly_text = NULL;
1160 uschar *mime_boundary = NULL;
1161 uschar *mime_charset = NULL;
1162 uschar *mime_content_description = NULL;
1163 uschar *mime_content_disposition = NULL;
1164 uschar *mime_content_id = NULL;
1165 unsigned int mime_content_size = 0;
1166 uschar *mime_content_transfer_encoding = NULL;
1167 uschar *mime_content_type = NULL;
1168 uschar *mime_decoded_filename = NULL;
1169 uschar *mime_filename = NULL;
1170 int mime_is_multipart = 0;
1171 int mime_is_coverletter = 0;
1172 int mime_is_rfc822 = 0;
1173 int mime_part_count = -1;
1174 #endif
1175
1176 uid_t *never_users = NULL;
1177
1178 const int on = 1; /* for setsockopt */
1179 const int off = 0;
1180
1181 uid_t original_euid;
1182 gid_t originator_gid;
1183 uschar *originator_login = NULL;
1184 uschar *originator_name = NULL;
1185 uid_t originator_uid;
1186 uschar *override_local_interfaces = NULL;
1187 uschar *override_pid_file_path = NULL;
1188
1189 uschar *percent_hack_domains = NULL;
1190 uschar *pid_file_path = US PID_FILE_PATH
1191 "\0<--------------Space to patch pid_file_path->";
1192 #ifdef EXPERIMENTAL_PIPE_CONNECT
1193 uschar *pipe_connect_advertise_hosts = US"*";
1194 #endif
1195 uschar *pipelining_advertise_hosts = US"*";
1196 uschar *primary_hostname = NULL;
1197 uschar process_info[PROCESS_INFO_SIZE];
1198 int process_info_len = 0;
1199 uschar *process_log_path = NULL;
1200
1201 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1202 uschar *hosts_proxy = NULL;
1203 uschar *proxy_external_address = NULL;
1204 int proxy_external_port = 0;
1205 uschar *proxy_local_address = NULL;
1206 int proxy_local_port = 0;
1207 #endif
1208
1209 uschar *prvscheck_address = NULL;
1210 uschar *prvscheck_keynum = NULL;
1211 uschar *prvscheck_result = NULL;
1212
1213
1214 const uschar *qualify_domain_recipient = NULL;
1215 uschar *qualify_domain_sender = NULL;
1216 uschar *queue_domains = NULL;
1217 int queue_interval = -1;
1218 uschar *queue_name = US"";
1219 uschar *queue_only_file = NULL;
1220 int queue_only_load = -1;
1221 uschar *queue_run_max = US"5";
1222 pid_t queue_run_pid = (pid_t)0;
1223 int queue_run_pipe = -1;
1224 uschar *queue_smtp_domains = NULL;
1225
1226 uint32_t random_seed = 0;
1227 tree_node *ratelimiters_cmd = NULL;
1228 tree_node *ratelimiters_conn = NULL;
1229 tree_node *ratelimiters_mail = NULL;
1230 uschar *raw_active_hostname = NULL;
1231 uschar *raw_sender = NULL;
1232 uschar **raw_recipients = NULL;
1233 int raw_recipients_count = 0;
1234
1235 int rcpt_count = 0;
1236 int rcpt_fail_count = 0;
1237 int rcpt_defer_count = 0;
1238 gid_t real_gid;
1239 uid_t real_uid;
1240 int receive_linecount = 0;
1241 int receive_messagecount = 0;
1242 int receive_timeout = 0;
1243 int received_count = 0;
1244 uschar *received_for = NULL;
1245
1246 /* This is the default text for Received headers generated by Exim. The
1247 date will be automatically added on the end. */
1248
1249 uschar *received_header_text = US
1250 "Received: "
1251 "${if def:sender_rcvhost {from $sender_rcvhost\n\t}"
1252 "{${if def:sender_ident {from ${quote_local_part:$sender_ident} }}"
1253 "${if def:sender_helo_name {(helo=$sender_helo_name)\n\t}}}}"
1254 "by $primary_hostname "
1255 "${if def:received_protocol {with $received_protocol }}"
1256 #ifdef SUPPORT_TLS
1257 "${if def:tls_in_cipher_std { tls $tls_in_cipher_std\n\t}}"
1258 #endif
1259 "(Exim $version_number)\n\t"
1260 "${if def:sender_address {(envelope-from <$sender_address>)\n\t}}"
1261 "id $message_exim_id"
1262 "${if def:received_for {\n\tfor $received_for}}"
1263 "\0<---------------Space to patch received_header_text->";
1264
1265 int received_headers_max = 30;
1266 uschar *received_protocol = NULL;
1267 struct timeval received_time = { 0, 0 };
1268 struct timeval received_time_taken = { 0, 0 };
1269 uschar *recipient_data = NULL;
1270 uschar *recipient_unqualified_hosts = NULL;
1271 uschar *recipient_verify_failure = NULL;
1272 int recipients_count = 0;
1273 recipient_item *recipients_list = NULL;
1274 int recipients_list_max = 0;
1275 int recipients_max = 0;
1276 const pcre *regex_AUTH = NULL;
1277 const pcre *regex_check_dns_names = NULL;
1278 const pcre *regex_From = NULL;
1279 const pcre *regex_IGNOREQUOTA = NULL;
1280 const pcre *regex_PIPELINING = NULL;
1281 const pcre *regex_SIZE = NULL;
1282 #ifdef EXPERIMENTAL_PIPE_CONNECT
1283 const pcre *regex_EARLY_PIPE = NULL;
1284 #endif
1285 const pcre *regex_ismsgid = NULL;
1286 const pcre *regex_smtp_code = NULL;
1287 uschar *regex_vars[REGEX_VARS];
1288 #ifdef WHITELIST_D_MACROS
1289 const pcre *regex_whitelisted_macro = NULL;
1290 #endif
1291 #ifdef WITH_CONTENT_SCAN
1292 uschar *regex_match_string = NULL;
1293 #endif
1294 int remote_delivery_count = 0;
1295 int remote_max_parallel = 2;
1296 uschar *remote_sort_domains = NULL;
1297 int retry_data_expire = 7*24*60*60;
1298 int retry_interval_max = 24*60*60;
1299 int retry_maximum_timeout = 0; /* set from retry config */
1300 retry_config *retries = NULL;
1301 uschar *return_path = NULL;
1302 int rewrite_existflags = 0;
1303 uschar *rfc1413_hosts = US"@[]";
1304 int rfc1413_query_timeout = 0;
1305 uid_t root_gid = ROOT_GID;
1306 uid_t root_uid = ROOT_UID;
1307
1308 router_instance *routers = NULL;
1309 router_instance router_defaults = {
1310 .next = NULL,
1311 .name = NULL,
1312 .info = NULL,
1313 .options_block = NULL,
1314 .driver_name = NULL,
1315
1316 .address_data = NULL,
1317 #ifdef EXPERIMENTAL_BRIGHTMAIL
1318 .bmi_rule = NULL,
1319 #endif
1320 .cannot_route_message = NULL,
1321 .condition = NULL,
1322 .current_directory = NULL,
1323 .debug_string = NULL,
1324 .domains = NULL,
1325 .errors_to = NULL,
1326 .expand_gid = NULL,
1327 .expand_uid = NULL,
1328 .expand_more = NULL,
1329 .expand_unseen = NULL,
1330 .extra_headers = NULL,
1331 .fallback_hosts = NULL,
1332 .home_directory = NULL,
1333 .ignore_target_hosts = NULL,
1334 .local_parts = NULL,
1335 .pass_router_name = NULL,
1336 .prefix = NULL,
1337 .redirect_router_name = NULL,
1338 .remove_headers = NULL,
1339 .require_files = NULL,
1340 .router_home_directory = NULL,
1341 .self = US"freeze",
1342 .senders = NULL,
1343 .suffix = NULL,
1344 .translate_ip_address = NULL,
1345 .transport_name = NULL,
1346
1347 .address_test = TRUE,
1348 #ifdef EXPERIMENTAL_BRIGHTMAIL
1349 .bmi_deliver_alternate = FALSE,
1350 .bmi_deliver_default = FALSE,
1351 .bmi_dont_deliver = FALSE,
1352 #endif
1353 .expn = TRUE,
1354 .caseful_local_part = FALSE,
1355 .check_local_user = FALSE,
1356 .disable_logging = FALSE,
1357 .fail_verify_recipient = FALSE,
1358 .fail_verify_sender = FALSE,
1359 .gid_set = FALSE,
1360 .initgroups = FALSE,
1361 .log_as_local = TRUE_UNSET,
1362 .more = TRUE,
1363 .pass_on_timeout = FALSE,
1364 .prefix_optional = FALSE,
1365 .repeat_use = TRUE,
1366 .retry_use_local_part = TRUE_UNSET,
1367 .same_domain_copy_routing = FALSE,
1368 .self_rewrite = FALSE,
1369 .suffix_optional = FALSE,
1370 .verify_only = FALSE,
1371 .verify_recipient = TRUE,
1372 .verify_sender = TRUE,
1373 .uid_set = FALSE,
1374 .unseen = FALSE,
1375 .dsn_lasthop = FALSE,
1376
1377 .self_code = self_freeze,
1378 .uid = (uid_t)(-1),
1379 .gid = (gid_t)(-1),
1380
1381 .fallback_hostlist = NULL,
1382 .transport = NULL,
1383 .pass_router = NULL,
1384 .redirect_router = NULL,
1385
1386 .dnssec = { NULL, NULL }, /* dnssec_domains {require,request} */
1387 };
1388
1389 uschar *router_name = NULL;
1390
1391 ip_address_item *running_interfaces = NULL;
1392
1393 /* This is a weird one. The following string gets patched in the binary by the
1394 script that sets up a copy of Exim for running in the test harness. It seems
1395 that compilers are now clever, and share constant strings if they can.
1396 Elsewhere in Exim the string "<" is used. The compiler optimization seems to
1397 make use of the end of this string in order to save space. So the patching then
1398 wrecks this. We defeat this optimization by adding some additional characters
1399 onto the end of the string. */
1400
1401 uschar *running_status = US">>>running<<<" "\0EXTRA";
1402
1403 int runrc = 0;
1404
1405 uschar *search_error_message = NULL;
1406 uschar *self_hostname = NULL;
1407 uschar *sender_address = NULL;
1408 unsigned int sender_address_cache[(MAX_NAMED_LIST * 2)/32];
1409 uschar *sender_address_data = NULL;
1410 uschar *sender_address_unrewritten = NULL;
1411 uschar *sender_data = NULL;
1412 unsigned int sender_domain_cache[(MAX_NAMED_LIST * 2)/32];
1413 uschar *sender_fullhost = NULL;
1414 uschar *sender_helo_name = NULL;
1415 uschar **sender_host_aliases = &no_aliases;
1416 uschar *sender_host_address = NULL;
1417 uschar *sender_host_authenticated = NULL;
1418 uschar *sender_host_auth_pubname = NULL;
1419 unsigned int sender_host_cache[(MAX_NAMED_LIST * 2)/32];
1420 uschar *sender_host_name = NULL;
1421 int sender_host_port = 0;
1422 uschar *sender_ident = NULL;
1423 uschar *sender_rate = NULL;
1424 uschar *sender_rate_limit = NULL;
1425 uschar *sender_rate_period = NULL;
1426 uschar *sender_rcvhost = NULL;
1427 uschar *sender_unqualified_hosts = NULL;
1428 uschar *sender_verify_failure = NULL;
1429 address_item *sender_verified_list = NULL;
1430 address_item *sender_verified_failed = NULL;
1431 int sender_verified_rc = -1;
1432 uschar *sending_ip_address = NULL;
1433 int sending_port = -1;
1434 SIGNAL_BOOL sigalrm_seen = FALSE;
1435 const uschar *sigalarm_setter = NULL;
1436 uschar **sighup_argv = NULL;
1437 int slow_lookup_log = 0; /* millisecs, zero disables */
1438 int smtp_accept_count = 0;
1439 int smtp_accept_max = 20;
1440 int smtp_accept_max_nonmail= 10;
1441 uschar *smtp_accept_max_nonmail_hosts = US"*";
1442 int smtp_accept_max_per_connection = 1000;
1443 uschar *smtp_accept_max_per_host = NULL;
1444 int smtp_accept_queue = 0;
1445 int smtp_accept_queue_per_connection = 10;
1446 int smtp_accept_reserve = 0;
1447 uschar *smtp_active_hostname = NULL;
1448 uschar *smtp_banner = US"$smtp_active_hostname ESMTP "
1449 "Exim $version_number $tod_full"
1450 "\0<---------------Space to patch smtp_banner->";
1451 int smtp_ch_index = 0;
1452 uschar *smtp_cmd_argument = NULL;
1453 uschar *smtp_cmd_buffer = NULL;
1454 struct timeval smtp_connection_start = {0,0};
1455 uschar smtp_connection_had[SMTP_HBUFF_SIZE];
1456 int smtp_connect_backlog = 20;
1457 double smtp_delay_mail = 0.0;
1458 double smtp_delay_rcpt = 0.0;
1459 FILE *smtp_in = NULL;
1460 int smtp_load_reserve = -1;
1461 int smtp_mailcmd_count = 0;
1462 FILE *smtp_out = NULL;
1463 uschar *smtp_etrn_command = NULL;
1464 int smtp_max_synprot_errors= 3;
1465 int smtp_max_unknown_commands = 3;
1466 uschar *smtp_notquit_reason = NULL;
1467 uschar *smtp_ratelimit_hosts = NULL;
1468 uschar *smtp_ratelimit_mail = NULL;
1469 uschar *smtp_ratelimit_rcpt = NULL;
1470 uschar *smtp_read_error = US"";
1471 int smtp_receive_timeout = 5*60;
1472 uschar *smtp_receive_timeout_s = NULL;
1473 uschar *smtp_reserve_hosts = NULL;
1474 int smtp_rlm_base = 0;
1475 double smtp_rlm_factor = 0.0;
1476 int smtp_rlm_limit = 0;
1477 int smtp_rlm_threshold = INT_MAX;
1478 int smtp_rlr_base = 0;
1479 double smtp_rlr_factor = 0.0;
1480 int smtp_rlr_limit = 0;
1481 int smtp_rlr_threshold = INT_MAX;
1482 unsigned smtp_peer_options = 0;
1483 unsigned smtp_peer_options_wrap= 0;
1484 #ifdef SUPPORT_I18N
1485 uschar *smtputf8_advertise_hosts = US"*"; /* overridden under test-harness */
1486 #endif
1487
1488 #ifdef WITH_CONTENT_SCAN
1489 uschar *spamd_address = US"127.0.0.1 783";
1490 uschar *spam_bar = NULL;
1491 uschar *spam_report = NULL;
1492 uschar *spam_action = NULL;
1493 uschar *spam_score = NULL;
1494 uschar *spam_score_int = NULL;
1495 #endif
1496 #ifdef SUPPORT_SPF
1497 uschar *spf_guess = US"v=spf1 a/24 mx/24 ptr ?all";
1498 uschar *spf_header_comment = NULL;
1499 uschar *spf_received = NULL;
1500 uschar *spf_result = NULL;
1501 uschar *spf_smtp_comment = NULL;
1502 #endif
1503
1504 FILE *spool_data_file = NULL;
1505 uschar *spool_directory = US SPOOL_DIRECTORY
1506 "\0<--------------Space to patch spool_directory->";
1507 #ifdef EXPERIMENTAL_SRS
1508 uschar *srs_config = NULL;
1509 uschar *srs_db_address = NULL;
1510 uschar *srs_db_key = NULL;
1511 int srs_hashlength = 6;
1512 int srs_hashmin = -1;
1513 int srs_maxage = 31;
1514 uschar *srs_orig_recipient = NULL;
1515 uschar *srs_orig_sender = NULL;
1516 uschar *srs_recipient = NULL;
1517 uschar *srs_secrets = NULL;
1518 uschar *srs_status = NULL;
1519 #endif
1520 int string_datestamp_offset= -1;
1521 int string_datestamp_length= 0;
1522 int string_datestamp_type = -1;
1523 uschar *submission_domain = NULL;
1524 uschar *submission_name = NULL;
1525 int syslog_facility = LOG_MAIL;
1526 uschar *syslog_processname = US"exim";
1527 uschar *system_filter = NULL;
1528
1529 uschar *system_filter_directory_transport = NULL;
1530 uschar *system_filter_file_transport = NULL;
1531 uschar *system_filter_pipe_transport = NULL;
1532 uschar *system_filter_reply_transport = NULL;
1533
1534 gid_t system_filter_gid = 0;
1535 uid_t system_filter_uid = (uid_t)-1;
1536
1537 blob tcp_fastopen_nodata = { .data = NULL, .len = 0 };
1538 tfo_state_t tcp_out_fastopen = TFO_NOT_USED;
1539 #ifdef USE_TCP_WRAPPERS
1540 uschar *tcp_wrappers_daemon_name = US TCP_WRAPPERS_DAEMON_NAME;
1541 #endif
1542 int test_harness_load_avg = 0;
1543 int thismessage_size_limit = 0;
1544 int timeout_frozen_after = 0;
1545
1546 transport_instance *transports = NULL;
1547
1548 transport_instance transport_defaults = {
1549 .next = NULL,
1550 .name = NULL,
1551 .info = NULL,
1552 .options_block = NULL,
1553 .driver_name = NULL,
1554 .setup = NULL,
1555 .batch_max = 1,
1556 .batch_id = NULL,
1557 .home_dir = NULL,
1558 .current_dir = NULL,
1559 .expand_multi_domain = NULL,
1560 .multi_domain = TRUE,
1561 .overrides_hosts = FALSE,
1562 .max_addresses = 100,
1563 .connection_max_messages = 500,
1564 .deliver_as_creator = FALSE,
1565 .disable_logging = FALSE,
1566 .initgroups = FALSE,
1567 .uid_set = FALSE,
1568 .gid_set = FALSE,
1569 .uid = (uid_t)(-1),
1570 .gid = (gid_t)(-1),
1571 .expand_uid = NULL,
1572 .expand_gid = NULL,
1573 .warn_message = NULL,
1574 .shadow = NULL,
1575 .shadow_condition = NULL,
1576 .filter_command = NULL,
1577 .add_headers = NULL,
1578 .remove_headers = NULL,
1579 .return_path = NULL,
1580 .debug_string = NULL,
1581 .max_parallel = NULL,
1582 .message_size_limit = NULL,
1583 .headers_rewrite = NULL,
1584 .rewrite_rules = NULL,
1585 .rewrite_existflags = 0,
1586 .filter_timeout = 300,
1587 .body_only = FALSE,
1588 .delivery_date_add = FALSE,
1589 .envelope_to_add = FALSE,
1590 .headers_only = FALSE,
1591 .rcpt_include_affixes = FALSE,
1592 .return_path_add = FALSE,
1593 .return_output = FALSE,
1594 .return_fail_output = FALSE,
1595 .log_output = FALSE,
1596 .log_fail_output = FALSE,
1597 .log_defer_output = FALSE,
1598 .retry_use_local_part = TRUE_UNSET, /* retry_use_local_part: BOOL, but set neither
1599 1 nor 0 so can detect unset */
1600 #ifndef DISABLE_EVENT
1601 .event_action = NULL
1602 #endif
1603 };
1604
1605 int transport_count;
1606 uschar *transport_name = NULL;
1607 int transport_newlines;
1608 const uschar **transport_filter_argv = NULL;
1609 int transport_filter_timeout;
1610 int transport_write_timeout= 0;
1611
1612 tree_node *tree_dns_fails = NULL;
1613 tree_node *tree_duplicates = NULL;
1614 tree_node *tree_nonrecipients = NULL;
1615 tree_node *tree_unusable = NULL;
1616
1617 gid_t *trusted_groups = NULL;
1618 uid_t *trusted_users = NULL;
1619 uschar *timezone_string = US TIMEZONE_DEFAULT;
1620
1621 uschar *unknown_login = NULL;
1622 uschar *unknown_username = NULL;
1623 uschar *untrusted_set_sender = NULL;
1624
1625 /* A regex for matching a "From_" line in an incoming message, in the form
1626
1627 From ph10 Fri Jan 5 12:35 GMT 1996
1628
1629 which the "mail" commands send to the MTA (undocumented, of course), or in
1630 the form
1631
1632 From ph10 Fri, 7 Jan 97 14:00:00 GMT
1633
1634 which is apparently used by some UUCPs, despite it not being in RFC 976.
1635 Because of variations in time formats, just match up to the minutes. That
1636 should be sufficient. Examples have been seen of time fields like 12:1:03,
1637 so just require one digit for hours and minutes. The weekday is also absent
1638 in some forms. */
1639
1640 uschar *uucp_from_pattern = US
1641 "^From\\s+(\\S+)\\s+(?:[a-zA-Z]{3},?\\s+)?" /* Common start */
1642 "(?:" /* Non-extracting bracket */
1643 "[a-zA-Z]{3}\\s+\\d?\\d|" /* First form */
1644 "\\d?\\d\\s+[a-zA-Z]{3}\\s+\\d\\d(?:\\d\\d)?" /* Second form */
1645 ")" /* End alternation */
1646 "\\s+\\d\\d?:\\d\\d?"; /* Start of time */
1647
1648 uschar *uucp_from_sender = US"$1";
1649
1650 uschar *verify_mode = NULL;
1651 uschar *version_copyright =
1652 US"Copyright (c) University of Cambridge, 1995 - 2018\n"
1653 "(c) The Exim Maintainers and contributors in ACKNOWLEDGMENTS file, 2007 - 2018";
1654 uschar *version_date = US"?";
1655 uschar *version_cnumber = US"????";
1656 uschar *version_string = US"?";
1657
1658 uschar *warn_message_file = NULL;
1659 int warning_count = 0;
1660 uschar *warnmsg_delay = NULL;
1661 uschar *warnmsg_recipients = NULL;
1662
1663
1664 /* End of globals.c */