TLS: preload configuration items
[exim.git] / src / src / globals.c
1 /*************************************************
2 *     Exim - an Internet mail transport agent    *
3 *************************************************/
4
5 /* Copyright (c) University of Cambridge 1995 - 2018 */
6 /* Copyright (c) The Exim Maintainers 2020 */
7 /* See the file NOTICE for conditions of use and distribution. */
8
9 /* All the global variables are defined together in this one module, so
10 that they are easy to find. */
11
12 #include "exim.h"
13
14
15 /* Generic options for auths, all of which live inside auth_instance
16 data blocks and hence have the opt_public flag set. */
17
18 optionlist optionlist_auths[] = {
19   { "client_condition", opt_stringptr | opt_public,
20                  OPT_OFF(auth_instance, client_condition) },
21   { "client_set_id", opt_stringptr | opt_public,
22                  OPT_OFF(auth_instance, set_client_id) },
23   { "driver",        opt_stringptr | opt_public,
24                  OPT_OFF(auth_instance, driver_name) },
25   { "public_name",   opt_stringptr | opt_public,
26                  OPT_OFF(auth_instance, public_name) },
27   { "server_advertise_condition", opt_stringptr | opt_public,
28                  OPT_OFF(auth_instance, advertise_condition)},
29   { "server_condition", opt_stringptr | opt_public,
30                  OPT_OFF(auth_instance, server_condition) },
31   { "server_debug_print", opt_stringptr | opt_public,
32                  OPT_OFF(auth_instance, server_debug_string) },
33   { "server_mail_auth_condition", opt_stringptr | opt_public,
34                  OPT_OFF(auth_instance, mail_auth_condition) },
35   { "server_set_id", opt_stringptr | opt_public,
36                  OPT_OFF(auth_instance, set_id) }
37 };
38
39 int     optionlist_auths_size = nelem(optionlist_auths);
40
41 /* An empty host aliases list. */
42
43 uschar *no_aliases             = NULL;
44
45
46 /* For comments on these variables, see globals.h. I'm too idle to
47 duplicate them here... */
48
49 #ifdef EXIM_PERL
50 uschar *opt_perl_startup       = NULL;
51 BOOL    opt_perl_at_start      = FALSE;
52 BOOL    opt_perl_started       = FALSE;
53 BOOL    opt_perl_taintmode     = FALSE;
54 #endif
55
56 #ifdef EXPAND_DLFUNC
57 tree_node *dlobj_anchor        = NULL;
58 #endif
59
60 #ifdef LOOKUP_IBASE
61 uschar *ibase_servers          = NULL;
62 #endif
63
64 #ifdef LOOKUP_LDAP
65 uschar *eldap_ca_cert_dir      = NULL;
66 uschar *eldap_ca_cert_file     = NULL;
67 uschar *eldap_cert_file        = NULL;
68 uschar *eldap_cert_key         = NULL;
69 uschar *eldap_cipher_suite     = NULL;
70 uschar *eldap_default_servers  = NULL;
71 uschar *eldap_require_cert     = NULL;
72 int     eldap_version          = -1;
73 BOOL    eldap_start_tls        = FALSE;
74 #endif
75
76 #ifdef LOOKUP_MYSQL
77 uschar *mysql_servers          = NULL;
78 #endif
79
80 #ifdef LOOKUP_ORACLE
81 uschar *oracle_servers         = NULL;
82 #endif
83
84 #ifdef LOOKUP_PGSQL
85 uschar *pgsql_servers          = NULL;
86 #endif
87
88 #ifdef LOOKUP_REDIS
89 uschar *redis_servers          = NULL;
90 #endif
91
92 #ifdef LOOKUP_SQLITE
93 uschar *sqlite_dbfile          = NULL;
94 int     sqlite_lock_timeout    = 5;
95 #endif
96
97 #ifdef SUPPORT_MOVE_FROZEN_MESSAGES
98 BOOL    move_frozen_messages   = FALSE;
99 #endif
100
101 /* These variables are outside the #ifdef because it keeps the code less
102 cluttered in several places (e.g. during logging) if we can always refer to
103 them. Also, the tls_ variables are now always visible.  Note that these are
104 only used for smtp connections, not for service-daemon access. */
105
106 tls_support tls_in = {
107  .active =              {.sock = -1}
108  /* all other elements zero */
109 };
110 tls_support tls_out = {
111  .active =              {.sock = -1},
112  /* all other elements zero */
113 };
114
115 uschar *dsn_envid              = NULL;
116 int     dsn_ret                = 0;
117 const pcre  *regex_DSN         = NULL;
118 uschar *dsn_advertise_hosts    = NULL;
119
120 #ifndef DISABLE_TLS
121 BOOL    gnutls_compat_mode     = FALSE;
122 BOOL    gnutls_allow_auto_pkcs11 = FALSE;
123 uschar *openssl_options        = NULL;
124 const pcre *regex_STARTTLS     = NULL;
125 uschar *tls_advertise_hosts    = US"*";
126 uschar *tls_certificate        = NULL;
127 uschar *tls_crl                = NULL;
128 /* This default matches NSS DH_MAX_P_BITS value at current time (2012), because
129 that's the interop problem which has been observed: GnuTLS suggesting a higher
130 bit-count as "NORMAL" (2432) and Thunderbird dropping connection. */
131 int     tls_dh_max_bits        = 2236;
132 uschar *tls_dhparam            = NULL;
133 uschar *tls_eccurve            = US"auto";
134 # ifndef DISABLE_OCSP
135 uschar *tls_ocsp_file          = NULL;
136 # endif
137 uschar *tls_privatekey         = NULL;
138 BOOL    tls_remember_esmtp     = FALSE;
139 uschar *tls_require_ciphers    = NULL;
140 # ifndef DISABLE_TLS_RESUME
141 uschar *tls_resumption_hosts   = NULL;
142 # endif
143 uschar *tls_try_verify_hosts   = NULL;
144 uschar *tls_verify_certificates= US"system";
145 uschar *tls_verify_hosts       = NULL;
146 int     tls_watch_fd           = -1;
147 time_t  tls_watch_trigger_time = (time_t)0;
148 #else   /*DISABLE_TLS*/
149 uschar *tls_advertise_hosts    = NULL;
150 #endif
151
152 #ifndef DISABLE_PRDR
153 /* Per Recipient Data Response variables */
154 BOOL    prdr_enable            = FALSE;
155 BOOL    prdr_requested         = FALSE;
156 const pcre *regex_PRDR         = NULL;
157 #endif
158
159 #ifdef SUPPORT_I18N
160 const pcre *regex_UTF8         = NULL;
161 #endif
162
163 /* Input-reading functions for messages, so we can use special ones for
164 incoming TCP/IP. The defaults use stdin. We never need these for any
165 stand-alone tests. */
166
167 #if !defined(STAND_ALONE) && !defined(MACRO_PREDEF)
168 int (*lwr_receive_getc)(unsigned) = stdin_getc;
169 uschar * (*lwr_receive_getbuf)(unsigned *) = NULL;
170 int (*lwr_receive_ungetc)(int) = stdin_ungetc;
171 int (*receive_getc)(unsigned)  = stdin_getc;
172 uschar * (*receive_getbuf)(unsigned *)  = NULL;
173 void (*receive_get_cache)(void)= NULL;
174 int (*receive_ungetc)(int)     = stdin_ungetc;
175 int (*receive_feof)(void)      = stdin_feof;
176 int (*receive_ferror)(void)    = stdin_ferror;
177 BOOL (*receive_smtp_buffered)(void) = NULL;   /* Only used for SMTP */
178 #endif
179
180
181 /* List of per-address expansion variables for clearing and saving/restoring
182 when verifying one address while routing/verifying another. We have to have
183 the size explicit, because it is referenced from more than one module. */
184
185 const uschar **address_expansions[ADDRESS_EXPANSIONS_COUNT] = {
186   CUSS &deliver_address_data,
187   CUSS &deliver_domain,
188   CUSS &deliver_domain_data,
189   CUSS &deliver_domain_orig,
190   CUSS &deliver_domain_parent,
191   CUSS &deliver_localpart,
192   CUSS &deliver_localpart_data,
193   CUSS &deliver_localpart_orig,
194   CUSS &deliver_localpart_parent,
195   CUSS &deliver_localpart_prefix,
196   CUSS &deliver_localpart_suffix,
197   CUSS (uschar **)(&deliver_recipients),
198   CUSS &deliver_host,
199   CUSS &deliver_home,
200   CUSS &address_file,
201   CUSS &address_pipe,
202   CUSS &self_hostname,
203   NULL };
204
205 int address_expansions_count = sizeof(address_expansions)/sizeof(uschar **);
206
207 /******************************************************************************/
208 /* General global variables.  Boolean flags are done as a group
209 so that only one bit each is needed, packed, for all those we never
210 need to take a pointer - and only a char for the rest.
211 This means a struct, unfortunately since it clutters the sourcecode. */
212
213 struct global_flags f =
214 {
215         .acl_temp_details       = FALSE,
216         .active_local_from_check = FALSE,
217         .active_local_sender_retain = FALSE,
218         .address_test_mode      = FALSE,
219         .admin_user             = FALSE,
220         .allow_auth_unadvertised= FALSE,
221         .allow_unqualified_recipient = TRUE,    /* For local messages */
222         .allow_unqualified_sender = TRUE,       /* Reset for SMTP */
223         .authentication_local   = FALSE,
224
225         .background_daemon      = TRUE,
226
227         .chunking_offered       = FALSE,
228         .config_changed         = FALSE,
229         .continue_more          = FALSE,
230
231         .daemon_listen          = FALSE,
232         .debug_daemon           = FALSE,
233         .deliver_firsttime      = FALSE,
234         .deliver_force          = FALSE,
235         .deliver_freeze         = FALSE,
236         .deliver_force_thaw     = FALSE,
237         .deliver_manual_thaw    = FALSE,
238         .deliver_selectstring_regex = FALSE,
239         .deliver_selectstring_sender_regex = FALSE,
240         .disable_callout_flush  = FALSE,
241         .disable_delay_flush    = FALSE,
242         .disable_logging        = FALSE,
243 #ifndef DISABLE_DKIM
244         .dkim_disable_verify      = FALSE,
245         .dkim_init_done           = FALSE,
246 #endif
247 #ifdef SUPPORT_DMARC
248         .dmarc_has_been_checked  = FALSE,
249         .dmarc_disable_verify    = FALSE,
250         .dmarc_enable_forensic   = FALSE,
251 #endif
252         .dont_deliver           = FALSE,
253         .dot_ends               = TRUE,
254
255         .enable_dollar_recipients = FALSE,
256         .expand_string_forcedfail = FALSE,
257
258         .filter_running         = FALSE,
259
260         .header_rewritten       = FALSE,
261         .helo_verified          = FALSE,
262         .helo_verify_failed     = FALSE,
263         .host_checking_callout  = FALSE,
264         .host_find_failed_syntax= FALSE,
265
266         .inetd_wait_mode        = FALSE,
267         .is_inetd               = FALSE,
268
269         .local_error_message    = FALSE,
270         .log_testing_mode       = FALSE,
271
272 #ifdef WITH_CONTENT_SCAN
273         .no_mbox_unspool        = FALSE,
274 #endif
275         .no_multiline_responses = FALSE,
276
277         .parse_allow_group      = FALSE,
278         .parse_found_group      = FALSE,
279         .pipelining_enable      = TRUE,
280 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
281         .proxy_session_failed   = FALSE,
282 #endif
283
284         .queue_2stage           = FALSE,
285         .queue_only_policy      = FALSE,
286         .queue_run_first_delivery = FALSE,
287         .queue_run_force        = FALSE,
288         .queue_run_local        = FALSE,
289         .queue_running          = FALSE,
290         .queue_smtp             = FALSE,
291
292         .really_exim            = TRUE,
293         .receive_call_bombout   = FALSE,
294         .recipients_discarded   = FALSE,
295         .running_in_test_harness = FALSE,
296
297         .search_find_defer      = FALSE,
298         .sender_address_forced  = FALSE,
299         .sender_host_notsocket  = FALSE,
300         .sender_host_unknown    = FALSE,
301         .sender_local           = FALSE,
302         .sender_name_forced     = FALSE,
303         .sender_set_untrusted   = FALSE,
304         .smtp_authenticated     = FALSE,
305 #ifndef DISABLE_PIPE_CONNECT
306         .smtp_in_early_pipe_advertised = FALSE,
307         .smtp_in_early_pipe_no_auth = FALSE,
308         .smtp_in_early_pipe_used = FALSE,
309 #endif
310         .smtp_in_pipelining_advertised = FALSE,
311         .smtp_in_pipelining_used = FALSE,
312         .smtp_in_quit           = FALSE,
313         .spool_file_wireformat  = FALSE,
314         .submission_mode        = FALSE,
315         .suppress_local_fixups  = FALSE,
316         .suppress_local_fixups_default = FALSE,
317         .synchronous_delivery   = FALSE,
318         .system_filtering       = FALSE,
319
320         .taint_check_slow       = FALSE,
321         .testsuite_delays       = TRUE,
322         .tcp_fastopen_ok        = FALSE,
323         .tcp_in_fastopen        = FALSE,
324         .tcp_in_fastopen_data   = FALSE,
325         .tcp_in_fastopen_logged = FALSE,
326         .tcp_out_fastopen_logged= FALSE,
327         .timestamps_utc         = FALSE,
328         .transport_filter_timed_out = FALSE,
329         .trusted_caller         = FALSE,
330         .trusted_config         = TRUE,
331 };
332
333 /******************************************************************************/
334 /* These are the flags which are either variables or mainsection options,
335 so an address is needed for access, or are exported to local_scan. */
336
337 BOOL    accept_8bitmime        = TRUE; /* deliberately not RFC compliant */
338 BOOL    allow_domain_literals  = FALSE;
339 BOOL    allow_mx_to_ip         = FALSE;
340 BOOL    allow_utf8_domains     = FALSE;
341 BOOL    authentication_failed  = FALSE;
342
343 BOOL    bounce_return_body     = TRUE;
344 BOOL    bounce_return_message  = TRUE;
345 BOOL    check_rfc2047_length   = TRUE;
346 BOOL    commandline_checks_require_admin = FALSE;
347
348 #ifdef EXPERIMENTAL_DCC
349 BOOL    dcc_direct_add_header  = FALSE;
350 #endif
351 BOOL    debug_store            = FALSE;
352 BOOL    delivery_date_remove   = TRUE;
353 BOOL    deliver_drop_privilege = FALSE;
354 #ifdef ENABLE_DISABLE_FSYNC
355 BOOL    disable_fsync          = FALSE;
356 #endif
357 BOOL    disable_ipv6           = FALSE;
358 BOOL    dns_csa_use_reverse    = TRUE;
359 BOOL    drop_cr                = FALSE;         /* No longer used */
360
361 BOOL    envelope_to_remove     = TRUE;
362 BOOL    exim_gid_set           = TRUE;          /* This gid is always set */
363 BOOL    exim_uid_set           = TRUE;          /* This uid is always set */
364 BOOL    extract_addresses_remove_arguments = TRUE;
365
366 BOOL    host_checking          = FALSE;
367 BOOL    host_lookup_deferred   = FALSE;
368 BOOL    host_lookup_failed     = FALSE;
369 BOOL    ignore_fromline_local  = FALSE;
370
371 BOOL    local_from_check       = TRUE;
372 BOOL    local_sender_retain    = FALSE;
373 BOOL    log_timezone           = FALSE;
374 BOOL    message_body_newlines  = FALSE;
375 BOOL    message_logs           = TRUE;
376 #ifdef SUPPORT_I18N
377 BOOL    message_smtputf8       = FALSE;
378 #endif
379 BOOL    mua_wrapper            = FALSE;
380
381 BOOL    preserve_message_logs  = FALSE;
382 BOOL    print_topbitchars      = FALSE;
383 BOOL    prod_requires_admin    = TRUE;
384 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
385 BOOL    proxy_session          = FALSE;
386 #endif
387
388 #ifndef DISABLE_QUEUE_RAMP
389 BOOL    queue_fast_ramp         = FALSE;
390 #endif
391 BOOL    queue_list_requires_admin = TRUE;
392 BOOL    queue_only             = FALSE;
393 BOOL    queue_only_load_latch  = TRUE;
394 BOOL    queue_only_override    = TRUE;
395 BOOL    queue_run_in_order     = FALSE;
396 BOOL    recipients_max_reject  = FALSE;
397 BOOL    return_path_remove     = TRUE;
398
399 BOOL    smtp_batched_input     = FALSE;
400 BOOL    sender_helo_dnssec     = FALSE;
401 BOOL    sender_host_dnssec     = FALSE;
402 BOOL    smtp_accept_keepalive  = TRUE;
403 BOOL    smtp_check_spool_space = TRUE;
404 BOOL    smtp_enforce_sync      = TRUE;
405 BOOL    smtp_etrn_serialize    = TRUE;
406 BOOL    smtp_input             = FALSE;
407 BOOL    smtp_return_error_details = FALSE;
408 #ifdef SUPPORT_SPF
409 BOOL    spf_result_guessed     = FALSE;
410 #endif
411 BOOL    split_spool_directory  = FALSE;
412 BOOL    spool_wireformat       = FALSE;
413 #ifdef EXPERIMENTAL_SRS_ALT
414 BOOL    srs_usehash            = TRUE;
415 BOOL    srs_usetimestamp       = TRUE;
416 #endif
417 BOOL    strict_acl_vars        = FALSE;
418 BOOL    strip_excess_angle_brackets = FALSE;
419 BOOL    strip_trailing_dot     = FALSE;
420 BOOL    syslog_duplication     = TRUE;
421 BOOL    syslog_pid             = TRUE;
422 BOOL    syslog_timestamp       = TRUE;
423 BOOL    system_filter_gid_set  = FALSE;
424 BOOL    system_filter_uid_set  = FALSE;
425
426 BOOL    tcp_nodelay            = TRUE;
427 BOOL    write_rejectlog        = TRUE;
428
429 /******************************************************************************/
430
431 header_line *acl_added_headers = NULL;
432 tree_node *acl_anchor          = NULL;
433 uschar *acl_arg[9]             = {NULL, NULL, NULL, NULL, NULL,
434                                   NULL, NULL, NULL, NULL};
435 int     acl_narg               = 0;
436
437 int     acl_level              = 0;
438
439 uschar *acl_not_smtp           = NULL;
440 #ifdef WITH_CONTENT_SCAN
441 uschar *acl_not_smtp_mime      = NULL;
442 #endif
443 uschar *acl_not_smtp_start     = NULL;
444 uschar *acl_removed_headers    = NULL;
445 uschar *acl_smtp_auth          = NULL;
446 uschar *acl_smtp_connect       = NULL;
447 uschar *acl_smtp_data          = NULL;
448 #ifndef DISABLE_PRDR
449 uschar *acl_smtp_data_prdr     = US"accept";
450 #endif
451 #ifndef DISABLE_DKIM
452 uschar *acl_smtp_dkim          = NULL;
453 #endif
454 uschar *acl_smtp_etrn          = NULL;
455 uschar *acl_smtp_expn          = NULL;
456 uschar *acl_smtp_helo          = NULL;
457 uschar *acl_smtp_mail          = NULL;
458 uschar *acl_smtp_mailauth      = NULL;
459 #ifdef WITH_CONTENT_SCAN
460 uschar *acl_smtp_mime          = NULL;
461 #endif
462 uschar *acl_smtp_notquit       = NULL;
463 uschar *acl_smtp_predata       = NULL;
464 uschar *acl_smtp_quit          = NULL;
465 uschar *acl_smtp_rcpt          = NULL;
466 uschar *acl_smtp_starttls      = NULL;
467 uschar *acl_smtp_vrfy          = NULL;
468
469 tree_node *acl_var_c           = NULL;
470 tree_node *acl_var_m           = NULL;
471 uschar *acl_verify_message     = NULL;
472 string_item *acl_warn_logged   = NULL;
473
474 /* Names of SMTP places for use in ACL error messages, and corresponding SMTP
475 error codes - keep in step with definitions of ACL_WHERE_xxxx in macros.h. */
476
477 uschar *acl_wherenames[]       = { US"RCPT",
478                                    US"MAIL",
479                                    US"PREDATA",
480                                    US"MIME",
481                                    US"DKIM",
482                                    US"DATA",
483 #ifndef DISABLE_PRDR
484                                    US"PRDR",
485 #endif
486                                    US"non-SMTP",
487                                    US"AUTH",
488                                    US"connection",
489                                    US"ETRN",
490                                    US"EXPN",
491                                    US"EHLO or HELO",
492                                    US"MAILAUTH",
493                                    US"non-SMTP-start",
494                                    US"NOTQUIT",
495                                    US"QUIT",
496                                    US"STARTTLS",
497                                    US"VRFY",
498                                    US"delivery",
499                                    US"unknown"
500                                  };
501
502 uschar *acl_wherecodes[]       = { US"550",     /* RCPT */
503                                    US"550",     /* MAIL */
504                                    US"550",     /* PREDATA */
505                                    US"550",     /* MIME */
506                                    US"550",     /* DKIM */
507                                    US"550",     /* DATA */
508 #ifndef DISABLE_PRDR
509                                    US"550",    /* RCPT PRDR */
510 #endif
511                                    US"0",       /* not SMTP; not relevant */
512                                    US"503",     /* AUTH */
513                                    US"550",     /* connect */
514                                    US"458",     /* ETRN */
515                                    US"550",     /* EXPN */
516                                    US"550",     /* HELO/EHLO */
517                                    US"0",       /* MAILAUTH; not relevant */
518                                    US"0",       /* not SMTP; not relevant */
519                                    US"0",       /* NOTQUIT; not relevant */
520                                    US"0",       /* QUIT; not relevant */
521                                    US"550",     /* STARTTLS */
522                                    US"252",     /* VRFY */
523                                    US"0",       /* delivery; not relevant */
524                                    US"0"        /* unknown; not relevant */
525                                  };
526
527 uschar *add_environment        = NULL;
528 address_item  *addr_duplicate  = NULL;
529
530 address_item address_defaults = {
531   .next =               NULL,
532   .parent =             NULL,
533   .first =              NULL,
534   .dupof =              NULL,
535   .start_router =       NULL,
536   .router =             NULL,
537   .transport =          NULL,
538   .host_list =          NULL,
539   .host_used =          NULL,
540   .fallback_hosts =     NULL,
541   .reply =              NULL,
542   .retries =            NULL,
543   .address =            NULL,
544   .unique =             NULL,
545   .cc_local_part =      NULL,
546   .lc_local_part =      NULL,
547   .local_part =         NULL,
548   .prefix =             NULL,
549   .prefix_v =           NULL,
550   .suffix =             NULL,
551   .suffix_v =           NULL,
552   .domain =             NULL,
553   .address_retry_key =  NULL,
554   .domain_retry_key =   NULL,
555   .current_dir =        NULL,
556   .home_dir =           NULL,
557   .message =            NULL,
558   .user_message =       NULL,
559   .onetime_parent =     NULL,
560   .pipe_expandn =       NULL,
561   .return_filename =    NULL,
562   .self_hostname =      NULL,
563   .shadow_message =     NULL,
564 #ifndef DISABLE_TLS
565   .cipher =             NULL,
566   .ourcert =            NULL,
567   .peercert =           NULL,
568   .peerdn =             NULL,
569   .ocsp =               OCSP_NOT_REQ,
570 #endif
571 #ifdef EXPERIMENTAL_DSN_INFO
572   .smtp_greeting =      NULL,
573   .helo_response =      NULL,
574 #endif
575   .authenticator =      NULL,
576   .auth_id =            NULL,
577   .auth_sndr =          NULL,
578   .dsn_orcpt =          NULL,
579   .dsn_flags =          0,
580   .dsn_aware =          0,
581   .uid =                (uid_t)(-1),
582   .gid =                (gid_t)(-1),
583   .flags =              { 0 },
584   .domain_cache =       { 0 },                /* domain_cache - any larger array should be zeroed */
585   .localpart_cache =    { 0 },                /* localpart_cache - ditto */
586   .mode =               -1,
587   .more_errno =         0,
588   .delivery_time =      {.tv_sec = 0, .tv_usec = 0},
589   .basic_errno =        ERRNO_UNKNOWNERROR,
590   .child_count =        0,
591   .return_file =        -1,
592   .special_action =     SPECIAL_NONE,
593   .transport_return =   DEFER,
594   .prop = {                                     /* fields that are propagated to children */
595     .address_data =     NULL,
596     .domain_data =      NULL,
597     .localpart_data =   NULL,
598     .errors_address =   NULL,
599     .extra_headers =    NULL,
600     .remove_headers =   NULL,
601     .variables =        NULL,
602 #ifdef EXPERIMENTAL_SRS_ALT
603     .srs_sender =       NULL,
604 #endif
605     .ignore_error =     FALSE,
606 #ifdef SUPPORT_I18N
607     .utf8_msg =         FALSE,
608     .utf8_downcvt =     FALSE,
609     .utf8_downcvt_maybe = FALSE
610 #endif
611   }
612 };
613
614 uschar *address_file           = NULL;
615 uschar *address_pipe           = NULL;
616 tree_node *addresslist_anchor  = NULL;
617 int     addresslist_count      = 0;
618 gid_t  *admin_groups           = NULL;
619
620 #ifdef EXPERIMENTAL_ARC
621 struct arc_set *arc_received    = NULL;
622 int     arc_received_instance   = 0;
623 int     arc_oldest_pass         = 0;
624 const uschar *arc_state         = NULL;
625 const uschar *arc_state_reason  = NULL;
626 #endif
627
628 uschar *authenticated_fail_id  = NULL;
629 uschar *authenticated_id       = NULL;
630 uschar *authenticated_sender   = NULL;
631 auth_instance  *auths          = NULL;
632 uschar *auth_advertise_hosts   = US"*";
633 auth_instance auth_defaults    = {
634     .next =             NULL,
635     .name =             NULL,
636     .info =             NULL,
637     .options_block =    NULL,
638     .driver_name =      NULL,
639     .advertise_condition = NULL,
640     .client_condition = NULL,
641     .public_name =      NULL,
642     .set_id =           NULL,
643     .set_client_id =    NULL,
644     .mail_auth_condition = NULL,
645     .server_debug_string = NULL,
646     .server_condition = NULL,
647     .client =           FALSE,
648     .server =           FALSE,
649     .advertised =       FALSE
650 };
651
652 uschar *auth_defer_msg         = US"reason not recorded";
653 uschar *auth_defer_user_msg    = US"";
654 uschar *auth_vars[AUTH_VARS];
655 int     auto_thaw              = 0;
656 #ifdef WITH_CONTENT_SCAN
657 int     av_failed              = FALSE; /* boolean but accessed as vtype_int*/
658 uschar *av_scanner             = US"sophie:/var/run/sophie";  /* AV scanner */
659 #endif
660
661 #if BASE_62 == 62
662 uschar *base62_chars=
663     US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";
664 #else
665 uschar *base62_chars= US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ";
666 #endif
667
668 uschar *bi_command             = NULL;
669 uschar *big_buffer             = NULL;
670 int     big_buffer_size        = BIG_BUFFER_SIZE;
671 #ifdef EXPERIMENTAL_BRIGHTMAIL
672 uschar *bmi_alt_location       = NULL;
673 uschar *bmi_base64_tracker_verdict = NULL;
674 uschar *bmi_base64_verdict     = NULL;
675 uschar *bmi_config_file        = US"/opt/brightmail/etc/brightmail.cfg";
676 int     bmi_deliver            = 1;
677 int     bmi_run                = 0;
678 uschar *bmi_verdicts           = NULL;
679 #endif
680 int     bsmtp_transaction_linecount = 0;
681 int     body_8bitmime          = 0;
682 int     body_linecount         = 0;
683 int     body_zerocount         = 0;
684 uschar *bounce_message_file    = NULL;
685 uschar *bounce_message_text    = NULL;
686 uschar *bounce_recipient       = NULL;
687 int     bounce_return_linesize_limit = 998;
688 int     bounce_return_size_limit = 100*1024;
689 uschar *bounce_sender_authentication = NULL;
690
691 uschar *callout_address        = NULL;
692 int     callout_cache_domain_positive_expire = 7*24*60*60;
693 int     callout_cache_domain_negative_expire = 3*60*60;
694 int     callout_cache_positive_expire = 24*60*60;
695 int     callout_cache_negative_expire = 2*60*60;
696 uschar *callout_random_local_part = US"$primary_hostname-$tod_epoch-testing";
697 uschar *check_dns_names_pattern= US"(?i)^(?>(?(1)\\.|())[^\\W](?>[a-z0-9/_-]*[^\\W])?)+(\\.?)$";
698 int     check_log_inodes       = 100;
699 int_eximarith_t check_log_space = 10*1024;      /* 10K Kbyte == 10MB */
700 int     check_spool_inodes     = 100;
701 int_eximarith_t check_spool_space = 10*1024;    /* 10K Kbyte == 10MB */
702
703 uschar *chunking_advertise_hosts = US"*";
704 unsigned chunking_datasize     = 0;
705 unsigned chunking_data_left    = 0;
706 chunking_state_t chunking_state= CHUNKING_NOT_OFFERED;
707 const pcre *regex_CHUNKING     = NULL;
708
709 uschar *client_authenticator   = NULL;
710 uschar *client_authenticated_id = NULL;
711 uschar *client_authenticated_sender = NULL;
712 int     clmacro_count          = 0;
713 uschar *clmacros[MAX_CLMACROS];
714 FILE   *config_file            = NULL;
715 const uschar *config_filename  = NULL;
716 int     config_lineno          = 0;
717 #ifdef CONFIGURE_GROUP
718 gid_t   config_gid             = CONFIGURE_GROUP;
719 #else
720 gid_t   config_gid             = 0;
721 #endif
722 uschar *config_main_filelist   = US CONFIGURE_FILE
723                          "\0<-----------Space to patch configure_filename->";
724 uschar *config_main_filename   = NULL;
725 uschar *config_main_directory  = NULL;
726
727 #ifdef CONFIGURE_OWNER
728 uid_t   config_uid             = CONFIGURE_OWNER;
729 #else
730 uid_t   config_uid             = 0;
731 #endif
732
733 int     connection_max_messages= -1;
734 uschar *continue_proxy_cipher  = NULL;
735 BOOL    continue_proxy_dane    = FALSE;
736 uschar *continue_proxy_sni     = NULL;
737 uschar *continue_hostname      = NULL;
738 uschar *continue_host_address  = NULL;
739 int     continue_sequence      = 1;
740 uschar *continue_transport     = NULL;
741
742 uschar *csa_status             = NULL;
743 cut_t   cutthrough = {
744   .callout_hold_only =  FALSE,                          /* verify-only: normal delivery */
745   .delivery =           FALSE,                          /* when to attempt */
746   .defer_pass =         FALSE,                          /* on defer: spool locally */
747   .is_tls =             FALSE,                          /* not a TLS conn yet */
748   .cctx =               {.sock = -1},                   /* open connection */
749   .nrcpt =              0,                              /* number of addresses */
750 };
751
752 int     daemon_notifier_fd     = -1;
753 uschar *daemon_smtp_port       = US"smtp";
754 int     daemon_startup_retries = 9;
755 int     daemon_startup_sleep   = 30;
756
757 #ifdef EXPERIMENTAL_DCC
758 uschar *dcc_header             = NULL;
759 uschar *dcc_result             = NULL;
760 uschar *dccifd_address         = US"/usr/local/dcc/var/dccifd";
761 uschar *dccifd_options         = US"header";
762 #endif
763
764 int     debug_fd               = -1;
765 FILE   *debug_file             = NULL;
766 int     debug_notall[]         = {
767   Di_memory,
768   Di_noutf8,
769   -1
770 };
771 bit_table debug_options[]      = { /* must be in alphabetical order and use
772                                  only the enum values from macro.h */
773   BIT_TABLE(D, acl),
774   BIT_TABLE(D, all),
775   BIT_TABLE(D, auth),
776   BIT_TABLE(D, deliver),
777   BIT_TABLE(D, dns),
778   BIT_TABLE(D, dnsbl),
779   BIT_TABLE(D, exec),
780   BIT_TABLE(D, expand),
781   BIT_TABLE(D, filter),
782   BIT_TABLE(D, hints_lookup),
783   BIT_TABLE(D, host_lookup),
784   BIT_TABLE(D, ident),
785   BIT_TABLE(D, interface),
786   BIT_TABLE(D, lists),
787   BIT_TABLE(D, load),
788   BIT_TABLE(D, local_scan),
789   BIT_TABLE(D, lookup),
790   BIT_TABLE(D, memory),
791   BIT_TABLE(D, noutf8),
792   BIT_TABLE(D, pid),
793   BIT_TABLE(D, process_info),
794   BIT_TABLE(D, queue_run),
795   BIT_TABLE(D, receive),
796   BIT_TABLE(D, resolver),
797   BIT_TABLE(D, retry),
798   BIT_TABLE(D, rewrite),
799   BIT_TABLE(D, route),
800   BIT_TABLE(D, timestamp),
801   BIT_TABLE(D, tls),
802   BIT_TABLE(D, transport),
803   BIT_TABLE(D, uid),
804   BIT_TABLE(D, verify),
805 };
806 int     debug_options_count    = nelem(debug_options);
807
808 unsigned int debug_selector    = 0;
809 int     delay_warning[DELAY_WARNING_SIZE] = { DELAY_WARNING_SIZE, 1, 24*60*60 };
810 uschar *delay_warning_condition=
811   US"${if or {"
812             "{ !eq{$h_list-id:$h_list-post:$h_list-subscribe:}{} }"
813             "{ match{$h_precedence:}{(?i)bulk|list|junk} }"
814             "{ match{$h_auto-submitted:}{(?i)auto-generated|auto-replied} }"
815             "} {no}{yes}}";
816 uschar *deliver_address_data   = NULL;
817 int     deliver_datafile       = -1;
818 const uschar *deliver_domain   = NULL;
819 uschar *deliver_domain_data    = NULL;
820 const uschar *deliver_domain_orig = NULL;
821 const uschar *deliver_domain_parent = NULL;
822 time_t  deliver_frozen_at      = 0;
823 uschar *deliver_home           = NULL;
824 const uschar *deliver_host     = NULL;
825 const uschar *deliver_host_address = NULL;
826 int     deliver_host_port      = 0;
827 uschar *deliver_in_buffer      = NULL;
828 ino_t   deliver_inode          = 0;
829 uschar *deliver_localpart      = NULL;
830 uschar *deliver_localpart_data = NULL;
831 uschar *deliver_localpart_orig = NULL;
832 uschar *deliver_localpart_parent = NULL;
833 uschar *deliver_localpart_prefix = NULL;
834 uschar *deliver_localpart_prefix_v = NULL;
835 uschar *deliver_localpart_suffix = NULL;
836 uschar *deliver_localpart_suffix_v = NULL;
837 uschar *deliver_out_buffer     = NULL;
838 int     deliver_queue_load_max = -1;
839 address_item  *deliver_recipients = NULL;
840 uschar *deliver_selectstring   = NULL;
841 uschar *deliver_selectstring_sender = NULL;
842
843 #ifndef DISABLE_DKIM
844 unsigned dkim_collect_input      = 0;
845 uschar *dkim_cur_signer          = NULL;
846 int     dkim_key_length          = 0;
847 void   *dkim_signatures          = NULL;
848 uschar *dkim_signers             = NULL;
849 uschar *dkim_signing_domain      = NULL;
850 uschar *dkim_signing_selector    = NULL;
851 uschar *dkim_verify_hashes       = US"sha256:sha512";
852 uschar *dkim_verify_keytypes     = US"ed25519:rsa";
853 uschar *dkim_verify_min_keysizes = US"rsa=1024 ed25519=250";
854 BOOL    dkim_verify_minimal      = FALSE;
855 uschar *dkim_verify_overall      = NULL;
856 uschar *dkim_verify_signers      = US"$dkim_signers";
857 uschar *dkim_verify_status       = NULL;
858 uschar *dkim_verify_reason       = NULL;
859 #endif
860 #ifdef SUPPORT_DMARC
861 uschar *dmarc_domain_policy     = NULL;
862 uschar *dmarc_forensic_sender   = NULL;
863 uschar *dmarc_history_file      = NULL;
864 uschar *dmarc_status            = NULL;
865 uschar *dmarc_status_text       = NULL;
866 uschar *dmarc_tld_file          = NULL;
867 uschar *dmarc_used_domain       = NULL;
868 #endif
869
870 uschar *dns_again_means_nonexist = NULL;
871 int     dns_csa_search_limit   = 5;
872 int     dns_cname_loops        = 1;
873 #ifdef SUPPORT_DANE
874 int     dns_dane_ok            = -1;
875 #endif
876 uschar *dns_ipv4_lookup        = NULL;
877 int     dns_retrans            = 0;
878 int     dns_retry              = 0;
879 int     dns_dnssec_ok          = -1; /* <0 = not coerced */
880 uschar *dns_trust_aa           = NULL;
881 int     dns_use_edns0          = -1; /* <0 = not coerced */
882 uschar *dnslist_domain         = NULL;
883 uschar *dnslist_matched        = NULL;
884 uschar *dnslist_text           = NULL;
885 uschar *dnslist_value          = NULL;
886 tree_node *domainlist_anchor   = NULL;
887 int     domainlist_count       = 0;
888 uschar *dsn_from               = US DEFAULT_DSN_FROM;
889
890 int     errno_quota            = ERRNO_QUOTA;
891 uschar *errors_copy            = NULL;
892 int     error_handling         = ERRORS_SENDER;
893 uschar *errors_reply_to        = NULL;
894 int     errors_sender_rc       = EXIT_FAILURE;
895 #ifndef DISABLE_EVENT
896 uschar *event_action             = NULL;        /* expansion for delivery events */
897 uschar *event_data               = NULL;        /* auxiliary data variable for event */
898 int     event_defer_errno        = 0;
899 const uschar *event_name         = NULL;        /* event name variable */
900 #endif
901
902
903 gid_t   exim_gid               = EXIM_GID;
904 uschar *exim_path              = US BIN_DIRECTORY "/exim"
905                         "\0<---------------Space to patch exim_path->";
906 uid_t   exim_uid               = EXIM_UID;
907 int     expand_level           = 0;             /* Nesting depth, indent for debug */
908 int     expand_forbid          = 0;
909 int     expand_nlength[EXPAND_MAXN+1];
910 int     expand_nmax            = -1;
911 uschar *expand_nstring[EXPAND_MAXN+1];
912 uschar *expand_string_message;
913 uschar *extra_local_interfaces = NULL;
914
915 int     fake_response          = OK;
916 uschar *fake_response_text     = US"Your message has been rejected but is "
917                                    "being kept for evaluation.\nIf it was a "
918                                    "legitimate message, it may still be "
919                                    "delivered to the target recipient(s).";
920 int     filter_n[FILTER_VARIABLE_COUNT];
921 int     filter_sn[FILTER_VARIABLE_COUNT];
922 int     filter_test            = FTEST_NONE;
923 uschar *filter_test_sfile      = NULL;
924 uschar *filter_test_ufile      = NULL;
925 uschar *filter_thisaddress     = NULL;
926 int     finduser_retries       = 0;
927 uid_t   fixed_never_users[]    = { FIXED_NEVER_USERS };
928 uschar *freeze_tell            = NULL;
929 uschar *freeze_tell_config     = NULL;
930 uschar *fudged_queue_times     = US"";
931
932 uschar *gecos_name             = NULL;
933 uschar *gecos_pattern          = NULL;
934 rewrite_rule  *global_rewrite_rules = NULL;
935
936 volatile sig_atomic_t had_command_timeout = 0;
937 volatile sig_atomic_t had_command_sigterm = 0;
938 volatile sig_atomic_t had_data_timeout    = 0;
939 volatile sig_atomic_t had_data_sigint     = 0;
940 uschar *headers_charset        = US HEADERS_CHARSET;
941 int     header_insert_maxlen   = 64 * 1024;
942 header_line  *header_last      = NULL;
943 header_line  *header_list      = NULL;
944 int     header_maxsize         = HEADER_MAXSIZE;
945 int     header_line_maxsize    = 0;
946
947 header_name header_names[] = {
948   /* name               len     allow_resent    htype */
949   { US"bcc",            3,      TRUE,           htype_bcc },
950   { US"cc",             2,      TRUE,           htype_cc },
951   { US"date",           4,      TRUE,           htype_date },
952   { US"delivery-date", 13,      FALSE,          htype_delivery_date },
953   { US"envelope-to",   11,      FALSE,          htype_envelope_to },
954   { US"from",           4,      TRUE,           htype_from },
955   { US"message-id",    10,      TRUE,           htype_id },
956   { US"received",       8,      FALSE,          htype_received },
957   { US"reply-to",       8,      FALSE,          htype_reply_to },
958   { US"return-path",   11,      FALSE,          htype_return_path },
959   { US"sender",         6,      TRUE,           htype_sender },
960   { US"subject",        7,      FALSE,          htype_subject },
961   { US"to",             2,      TRUE,           htype_to }
962 };
963
964 int header_names_size          = nelem(header_names);
965
966 uschar *helo_accept_junk_hosts = NULL;
967 uschar *helo_allow_chars       = US"";
968 uschar *helo_lookup_domains    = US"@ : @[]";
969 uschar *helo_try_verify_hosts  = NULL;
970 uschar *helo_verify_hosts      = NULL;
971 const uschar *hex_digits       = CUS"0123456789abcdef";
972 uschar *hold_domains           = NULL;
973 uschar *host_data              = NULL;
974 uschar *host_lookup            = NULL;
975 uschar *host_lookup_order      = US"bydns:byaddr";
976 uschar *host_lookup_msg        = US"";
977 int     host_number            = 0;
978 uschar *host_number_string     = NULL;
979 uschar *host_reject_connection = NULL;
980 tree_node *hostlist_anchor     = NULL;
981 int     hostlist_count         = 0;
982 uschar *hosts_treat_as_local   = NULL;
983 uschar *hosts_connection_nolog = NULL;
984
985 int     ignore_bounce_errors_after = 10*7*24*60*60;  /* 10 weeks */
986 uschar *ignore_fromline_hosts  = NULL;
987 int     inetd_wait_timeout     = -1;
988 uschar *initial_cwd            = NULL;
989 uschar *interface_address      = NULL;
990 int     interface_port         = -1;
991 uschar *iterate_item           = NULL;
992
993 int     journal_fd             = -1;
994
995 uschar *keep_environment       = NULL;
996
997 int     keep_malformed         = 4*24*60*60;    /* 4 days */
998
999 uschar *eldap_dn               = NULL;
1000 int     load_average           = -2;
1001 uschar *local_from_prefix      = NULL;
1002 uschar *local_from_suffix      = NULL;
1003
1004 #if HAVE_IPV6
1005 uschar *local_interfaces       = US"<; ::0 ; 0.0.0.0";
1006 #else
1007 uschar *local_interfaces       = US"0.0.0.0";
1008 #endif
1009
1010 #ifdef HAVE_LOCAL_SCAN
1011 uschar *local_scan_data        = NULL;
1012 int     local_scan_timeout     = 5*60;
1013 #endif
1014 gid_t   local_user_gid         = (gid_t)(-1);
1015 uid_t   local_user_uid         = (uid_t)(-1);
1016
1017 tree_node *localpartlist_anchor= NULL;
1018 int     localpartlist_count    = 0;
1019 uschar *log_buffer             = NULL;
1020
1021 int     log_default[]          = { /* for initializing log_selector */
1022   Li_acl_warn_skipped,
1023   Li_connection_reject,
1024   Li_delay_delivery,
1025   Li_dkim,
1026   Li_dnslist_defer,
1027   Li_etrn,
1028   Li_host_lookup_failed,
1029   Li_lost_incoming_connection,
1030   Li_outgoing_interface, /* see d_log_interface in deliver.c */
1031   Li_msg_id,
1032   Li_queue_run,
1033   Li_rejected_header,
1034   Li_retry_defer,
1035   Li_sender_verify_fail,
1036   Li_size_reject,
1037   Li_skip_delivery,
1038   Li_smtp_confirmation,
1039   Li_tls_certificate_verified,
1040   Li_tls_cipher,
1041   -1
1042 };
1043
1044 uschar *log_file_path          = US LOG_FILE_PATH
1045                            "\0<--------------Space to patch log_file_path->";
1046
1047 int     log_notall[]           = {
1048   -1
1049 };
1050 bit_table log_options[]        = { /* must be in alphabetical order,
1051                                 with definitions from enum logbit. */
1052   BIT_TABLE(L, 8bitmime),
1053   BIT_TABLE(L, acl_warn_skipped),
1054   BIT_TABLE(L, address_rewrite),
1055   BIT_TABLE(L, all),
1056   BIT_TABLE(L, all_parents),
1057   BIT_TABLE(L, arguments),
1058   BIT_TABLE(L, connection_reject),
1059   BIT_TABLE(L, delay_delivery),
1060   BIT_TABLE(L, deliver_time),
1061   BIT_TABLE(L, delivery_size),
1062 #ifndef DISABLE_DKIM
1063   BIT_TABLE(L, dkim),
1064   BIT_TABLE(L, dkim_verbose),
1065 #endif
1066   BIT_TABLE(L, dnslist_defer),
1067   BIT_TABLE(L, dnssec),
1068   BIT_TABLE(L, etrn),
1069   BIT_TABLE(L, host_lookup_failed),
1070   BIT_TABLE(L, ident_timeout),
1071   BIT_TABLE(L, incoming_interface),
1072   BIT_TABLE(L, incoming_port),
1073   BIT_TABLE(L, lost_incoming_connection),
1074   BIT_TABLE(L, millisec),
1075   BIT_TABLE(L, msg_id),
1076   BIT_TABLE(L, msg_id_created),
1077   BIT_TABLE(L, outgoing_interface),
1078   BIT_TABLE(L, outgoing_port),
1079   BIT_TABLE(L, pid),
1080   BIT_TABLE(L, pipelining),
1081   BIT_TABLE(L, protocol_detail),
1082 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1083   BIT_TABLE(L, proxy),
1084 #endif
1085   BIT_TABLE(L, queue_run),
1086   BIT_TABLE(L, queue_time),
1087   BIT_TABLE(L, queue_time_overall),
1088   BIT_TABLE(L, receive_time),
1089   BIT_TABLE(L, received_recipients),
1090   BIT_TABLE(L, received_sender),
1091   BIT_TABLE(L, rejected_header),
1092   { US"rejected_headers", Li_rejected_header },
1093   BIT_TABLE(L, retry_defer),
1094   BIT_TABLE(L, return_path_on_delivery),
1095   BIT_TABLE(L, sender_on_delivery),
1096   BIT_TABLE(L, sender_verify_fail),
1097   BIT_TABLE(L, size_reject),
1098   BIT_TABLE(L, skip_delivery),
1099   BIT_TABLE(L, smtp_confirmation),
1100   BIT_TABLE(L, smtp_connection),
1101   BIT_TABLE(L, smtp_incomplete_transaction),
1102   BIT_TABLE(L, smtp_mailauth),
1103   BIT_TABLE(L, smtp_no_mail),
1104   BIT_TABLE(L, smtp_protocol_error),
1105   BIT_TABLE(L, smtp_syntax_error),
1106   BIT_TABLE(L, subject),
1107   BIT_TABLE(L, tls_certificate_verified),
1108   BIT_TABLE(L, tls_cipher),
1109   BIT_TABLE(L, tls_peerdn),
1110   BIT_TABLE(L, tls_resumption),
1111   BIT_TABLE(L, tls_sni),
1112   BIT_TABLE(L, unknown_in_list),
1113 };
1114 int     log_options_count      = nelem(log_options);
1115
1116 int     log_reject_target      = 0;
1117 unsigned int log_selector[log_selector_size]; /* initialized in main() */
1118 uschar *log_selector_string    = NULL;
1119 FILE   *log_stderr             = NULL;
1120 uschar *login_sender_address   = NULL;
1121 uschar *lookup_dnssec_authenticated = NULL;
1122 int     lookup_open_max        = 25;
1123 uschar *lookup_value           = NULL;
1124
1125 macro_item *macros_user        = NULL;
1126 uschar *mailstore_basename     = NULL;
1127 #ifdef WITH_CONTENT_SCAN
1128 uschar *malware_name           = NULL;  /* Virus Name */
1129 #endif
1130 int     max_received_linelength= 0;
1131 int     max_username_length    = 0;
1132 int     message_age            = 0;
1133 uschar *message_body           = NULL;
1134 uschar *message_body_end       = NULL;
1135 int     message_body_size      = 0;
1136 int     message_body_visible   = 500;
1137 int     message_ended          = END_NOTSTARTED;
1138 uschar *message_headers        = NULL;
1139 uschar *message_id;
1140 uschar *message_id_domain      = NULL;
1141 uschar *message_id_text        = NULL;
1142 struct timeval message_id_tv   = { 0, 0 };
1143 uschar  message_id_option[MESSAGE_ID_LENGTH + 3];
1144 uschar *message_id_external;
1145 int     message_linecount      = 0;
1146 int     message_size           = 0;
1147 uschar *message_size_limit     = US"50M";
1148 #ifdef SUPPORT_I18N
1149 int     message_utf8_downconvert = 0;   /* -1 ifneeded; 0 never; 1 always */
1150 #endif
1151 uschar  message_subdir[2]      = { 0, 0 };
1152 uschar *message_reference      = NULL;
1153
1154 /* MIME ACL expandables */
1155 #ifdef WITH_CONTENT_SCAN
1156 int     mime_anomaly_level     = 0;
1157 const uschar *mime_anomaly_text      = NULL;
1158 uschar *mime_boundary          = NULL;
1159 uschar *mime_charset           = NULL;
1160 uschar *mime_content_description = NULL;
1161 uschar *mime_content_disposition = NULL;
1162 uschar *mime_content_id        = NULL;
1163 unsigned int mime_content_size = 0;
1164 uschar *mime_content_transfer_encoding = NULL;
1165 uschar *mime_content_type      = NULL;
1166 uschar *mime_decoded_filename  = NULL;
1167 uschar *mime_filename          = NULL;
1168 int     mime_is_multipart      = 0;
1169 int     mime_is_coverletter    = 0;
1170 int     mime_is_rfc822         = 0;
1171 int     mime_part_count        = -1;
1172 #endif
1173
1174 uid_t  *never_users            = NULL;
1175 uschar *notifier_socket        = US"$spool_directory/" NOTIFIER_SOCKET_NAME ;
1176
1177 const int on                   = 1;     /* for setsockopt */
1178 const int off                  = 0;
1179
1180 uid_t   original_euid;
1181 gid_t   originator_gid;
1182 uschar *originator_login       = NULL;
1183 uschar *originator_name        = NULL;
1184 uid_t   originator_uid;
1185 uschar *override_local_interfaces = NULL;
1186 uschar *override_pid_file_path = NULL;
1187
1188 uschar *percent_hack_domains   = NULL;
1189 uschar *pid_file_path          = US PID_FILE_PATH
1190                            "\0<--------------Space to patch pid_file_path->";
1191 #ifndef DISABLE_PIPE_CONNECT
1192 uschar *pipe_connect_advertise_hosts = US"*";
1193 #endif
1194 uschar *pipelining_advertise_hosts = US"*";
1195 uschar *primary_hostname       = NULL;
1196 uschar *process_info;
1197 int     process_info_len       = 0;
1198 uschar *process_log_path       = NULL;
1199 const uschar *process_purpose  = US"fresh-exec";
1200
1201 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1202 uschar *hosts_proxy            = NULL;
1203 uschar *proxy_external_address = NULL;
1204 int     proxy_external_port    = 0;
1205 uschar *proxy_local_address    = NULL;
1206 int     proxy_local_port       = 0;
1207 #endif
1208
1209 uschar *prvscheck_address      = NULL;
1210 uschar *prvscheck_keynum       = NULL;
1211 uschar *prvscheck_result       = NULL;
1212
1213
1214 const uschar *qualify_domain_recipient = NULL;
1215 uschar *qualify_domain_sender  = NULL;
1216 uschar *queue_domains          = NULL;
1217 int     queue_interval         = -1;
1218 uschar *queue_name             = US"";
1219 uschar *queue_name_dest        = NULL;
1220 uschar *queue_only_file        = NULL;
1221 int     queue_only_load        = -1;
1222 uschar *queue_run_max          = US"5";
1223 pid_t   queue_run_pid          = (pid_t)0;
1224 int     queue_run_pipe         = -1;
1225 unsigned queue_size            = 0;
1226 time_t  queue_size_next        = 0;
1227 uschar *queue_smtp_domains     = NULL;
1228
1229 uint32_t random_seed           = 0;
1230 tree_node *ratelimiters_cmd    = NULL;
1231 tree_node *ratelimiters_conn   = NULL;
1232 tree_node *ratelimiters_mail   = NULL;
1233 uschar *raw_active_hostname    = NULL;
1234 uschar *raw_sender             = NULL;
1235 uschar **raw_recipients        = NULL;
1236 int     raw_recipients_count   = 0;
1237
1238 int     rcpt_count             = 0;
1239 int     rcpt_fail_count        = 0;
1240 int     rcpt_defer_count       = 0;
1241 gid_t   real_gid;
1242 uid_t   real_uid;
1243 int     receive_linecount      = 0;
1244 int     receive_messagecount   = 0;
1245 int     receive_timeout        = 0;
1246 int     received_count         = 0;
1247 uschar *received_for           = NULL;
1248
1249 /*  This is the default text for Received headers generated by Exim. The
1250 date  will be automatically added on the end. */
1251
1252 uschar *received_header_text   = US
1253      "Received: "
1254      "${if def:sender_rcvhost {from $sender_rcvhost\n\t}"
1255        "{${if def:sender_ident {from ${quote_local_part:$sender_ident} }}"
1256          "${if def:sender_helo_name {(helo=$sender_helo_name)\n\t}}}}"
1257      "by $primary_hostname "
1258      "${if def:received_protocol {with $received_protocol }}"
1259 #ifndef DISABLE_TLS
1260      "${if def:tls_in_ver        { ($tls_in_ver)}}"
1261      "${if def:tls_in_cipher_std { tls $tls_in_cipher_std\n\t}}"
1262 #endif
1263      "(Exim $version_number)\n\t"
1264      "${if def:sender_address {(envelope-from <$sender_address>)\n\t}}"
1265      "id $message_exim_id"
1266      "${if def:received_for {\n\tfor $received_for}}"
1267      "\0<---------------Space to patch received_header_text->";
1268
1269 int     received_headers_max   = 30;
1270 uschar *received_protocol      = NULL;
1271 struct timeval received_time   = { 0, 0 };
1272 struct timeval received_time_taken = { 0, 0 };
1273 uschar *recipient_data         = NULL;
1274 uschar *recipient_unqualified_hosts = NULL;
1275 uschar *recipient_verify_failure = NULL;
1276 int     recipients_count       = 0;
1277 recipient_item  *recipients_list = NULL;
1278 int     recipients_list_max    = 0;
1279 int     recipients_max         = 0;
1280 const pcre *regex_AUTH         = NULL;
1281 const pcre *regex_check_dns_names = NULL;
1282 const pcre *regex_From         = NULL;
1283 const pcre *regex_IGNOREQUOTA  = NULL;
1284 const pcre *regex_PIPELINING   = NULL;
1285 const pcre *regex_SIZE         = NULL;
1286 #ifndef DISABLE_PIPE_CONNECT
1287 const pcre *regex_EARLY_PIPE   = NULL;
1288 #endif
1289 const pcre *regex_ismsgid      = NULL;
1290 const pcre *regex_smtp_code    = NULL;
1291 uschar *regex_vars[REGEX_VARS];
1292 #ifdef WHITELIST_D_MACROS
1293 const pcre *regex_whitelisted_macro = NULL;
1294 #endif
1295 #ifdef WITH_CONTENT_SCAN
1296 uschar *regex_match_string     = NULL;
1297 #endif
1298 int     remote_delivery_count  = 0;
1299 int     remote_max_parallel    = 2;
1300 uschar *remote_sort_domains    = NULL;
1301 int     retry_data_expire      = 7*24*60*60;
1302 int     retry_interval_max     = 24*60*60;
1303 int     retry_maximum_timeout  = 0;        /* set from retry config */
1304 retry_config  *retries         = NULL;
1305 uschar *return_path            = NULL;
1306 int     rewrite_existflags     = 0;
1307 uschar *rfc1413_hosts          = US"@[]";
1308 int     rfc1413_query_timeout  = 0;
1309 uid_t   root_gid               = ROOT_GID;
1310 uid_t   root_uid               = ROOT_UID;
1311
1312 router_instance  *routers  = NULL;
1313 router_instance  router_defaults = {
1314     .next =                     NULL,
1315     .name =                     NULL,
1316     .info =                     NULL,
1317     .options_block =            NULL,
1318     .driver_name =              NULL,
1319
1320     .address_data =             NULL,
1321 #ifdef EXPERIMENTAL_BRIGHTMAIL
1322     .bmi_rule =                 NULL,
1323 #endif
1324     .cannot_route_message =     NULL,
1325     .condition =                NULL,
1326     .current_directory =        NULL,
1327     .debug_string =             NULL,
1328     .domains =                  NULL,
1329     .errors_to =                NULL,
1330     .expand_gid =               NULL,
1331     .expand_uid =               NULL,
1332     .expand_more =              NULL,
1333     .expand_unseen =            NULL,
1334     .extra_headers =            NULL,
1335     .fallback_hosts =           NULL,
1336     .home_directory =           NULL,
1337     .ignore_target_hosts =      NULL,
1338     .local_parts =              NULL,
1339     .pass_router_name =         NULL,
1340     .prefix =                   NULL,
1341     .redirect_router_name =     NULL,
1342     .remove_headers =           NULL,
1343     .require_files =            NULL,
1344     .router_home_directory =    NULL,
1345     .self =                     US"freeze",
1346     .senders =                  NULL,
1347     .suffix =                   NULL,
1348     .translate_ip_address =     NULL,
1349     .transport_name =           NULL,
1350
1351     .address_test =             TRUE,
1352 #ifdef EXPERIMENTAL_BRIGHTMAIL
1353     .bmi_deliver_alternate =    FALSE,
1354     .bmi_deliver_default =      FALSE,
1355     .bmi_dont_deliver =         FALSE,
1356 #endif
1357     .expn =                     TRUE,
1358     .caseful_local_part =       FALSE,
1359     .check_local_user =         FALSE,
1360     .disable_logging =          FALSE,
1361     .fail_verify_recipient =    FALSE,
1362     .fail_verify_sender =       FALSE,
1363     .gid_set =                  FALSE,
1364     .initgroups =               FALSE,
1365     .log_as_local =             TRUE_UNSET,
1366     .more =                     TRUE,
1367     .pass_on_timeout =          FALSE,
1368     .prefix_optional =          FALSE,
1369     .repeat_use =               TRUE,
1370     .retry_use_local_part =     TRUE_UNSET,
1371     .same_domain_copy_routing = FALSE,
1372     .self_rewrite =             FALSE,
1373     .set =                      NULL,
1374     .suffix_optional =          FALSE,
1375     .verify_only =              FALSE,
1376     .verify_recipient =         TRUE,
1377     .verify_sender =            TRUE,
1378     .uid_set =                  FALSE,
1379     .unseen =                   FALSE,
1380     .dsn_lasthop =              FALSE,
1381
1382     .self_code =                self_freeze,
1383     .uid =                      (uid_t)(-1),
1384     .gid =                      (gid_t)(-1),
1385
1386     .fallback_hostlist =        NULL,
1387     .transport =                NULL,
1388     .pass_router =              NULL,
1389     .redirect_router =          NULL,
1390
1391     .dnssec =                   { .request= US"*", .require=NULL },
1392 };
1393
1394 uschar *router_name            = NULL;
1395 tree_node *router_var          = NULL;
1396
1397 ip_address_item *running_interfaces = NULL;
1398
1399 /* This is a weird one. The following string gets patched in the binary by the
1400 script that sets up a copy of Exim for running in the test harness. It seems
1401 that compilers are now clever, and share constant strings if they can.
1402 Elsewhere in Exim the string "<" is used. The compiler optimization seems to
1403 make use of the end of this string in order to save space. So the patching then
1404 wrecks this. We defeat this optimization by adding some additional characters
1405 onto the end of the string. */
1406
1407 uschar *running_status         = US">>>running<<<" "\0EXTRA";
1408
1409 int     runrc                  = 0;
1410
1411 uschar *search_error_message   = NULL;
1412 uschar *self_hostname          = NULL;
1413 uschar *sender_address         = NULL;
1414 unsigned int sender_address_cache[(MAX_NAMED_LIST * 2)/32];
1415 uschar *sender_address_data    = NULL;
1416 uschar *sender_address_unrewritten = NULL;
1417 uschar *sender_data            = NULL;
1418 unsigned int sender_domain_cache[(MAX_NAMED_LIST * 2)/32];
1419 uschar *sender_fullhost        = NULL;
1420 uschar *sender_helo_name       = NULL;
1421 uschar **sender_host_aliases   = &no_aliases;
1422 uschar *sender_host_address    = NULL;
1423 uschar *sender_host_authenticated = NULL;
1424 uschar *sender_host_auth_pubname  = NULL;
1425 unsigned int sender_host_cache[(MAX_NAMED_LIST * 2)/32];
1426 uschar *sender_host_name       = NULL;
1427 int     sender_host_port       = 0;
1428 uschar *sender_ident           = NULL;
1429 uschar *sender_rate            = NULL;
1430 uschar *sender_rate_limit      = NULL;
1431 uschar *sender_rate_period     = NULL;
1432 uschar *sender_rcvhost         = NULL;
1433 uschar *sender_unqualified_hosts = NULL;
1434 uschar *sender_verify_failure = NULL;
1435 address_item *sender_verified_list  = NULL;
1436 address_item *sender_verified_failed = NULL;
1437 int     sender_verified_rc     = -1;
1438 uschar *sending_ip_address     = NULL;
1439 int     sending_port           = -1;
1440 SIGNAL_BOOL sigalrm_seen       = FALSE;
1441 const uschar *sigalarm_setter  = NULL;
1442 uschar **sighup_argv           = NULL;
1443 int     slow_lookup_log        = 0;     /* millisecs, zero disables */
1444 int     smtp_accept_count      = 0;
1445 int     smtp_accept_max        = 20;
1446 int     smtp_accept_max_nonmail= 10;
1447 uschar *smtp_accept_max_nonmail_hosts = US"*";
1448 int     smtp_accept_max_per_connection = 1000;
1449 uschar *smtp_accept_max_per_host = NULL;
1450 int     smtp_accept_queue      = 0;
1451 int     smtp_accept_queue_per_connection = 10;
1452 int     smtp_accept_reserve    = 0;
1453 uschar *smtp_active_hostname   = NULL;
1454 uschar *smtp_banner            = US"$smtp_active_hostname ESMTP "
1455                              "Exim $version_number $tod_full"
1456                              "\0<---------------Space to patch smtp_banner->";
1457 int     smtp_ch_index          = 0;
1458 uschar *smtp_cmd_argument      = NULL;
1459 uschar *smtp_cmd_buffer        = NULL;
1460 struct timeval smtp_connection_start  = {0,0};
1461 uschar  smtp_connection_had[SMTP_HBUFF_SIZE];
1462 int     smtp_connect_backlog   = 20;
1463 double  smtp_delay_mail        = 0.0;
1464 double  smtp_delay_rcpt        = 0.0;
1465 FILE   *smtp_in                = NULL;
1466 int     smtp_load_reserve      = -1;
1467 int     smtp_mailcmd_count     = 0;
1468 FILE   *smtp_out               = NULL;
1469 uschar *smtp_etrn_command      = NULL;
1470 int     smtp_max_synprot_errors= 3;
1471 int     smtp_max_unknown_commands = 3;
1472 uschar *smtp_notquit_reason    = NULL;
1473 unsigned smtp_peer_options     = 0;
1474 unsigned smtp_peer_options_wrap= 0;
1475 uschar *smtp_ratelimit_hosts   = NULL;
1476 uschar *smtp_ratelimit_mail    = NULL;
1477 uschar *smtp_ratelimit_rcpt    = NULL;
1478 uschar *smtp_read_error        = US"";
1479 int     smtp_receive_timeout   = 5*60;
1480 uschar *smtp_receive_timeout_s = NULL;
1481 uschar *smtp_reserve_hosts     = NULL;
1482 int     smtp_rlm_base          = 0;
1483 double  smtp_rlm_factor        = 0.0;
1484 int     smtp_rlm_limit         = 0;
1485 int     smtp_rlm_threshold     = INT_MAX;
1486 int     smtp_rlr_base          = 0;
1487 double  smtp_rlr_factor        = 0.0;
1488 int     smtp_rlr_limit         = 0;
1489 int     smtp_rlr_threshold     = INT_MAX;
1490 #ifdef SUPPORT_I18N
1491 uschar *smtputf8_advertise_hosts = US"*";       /* overridden under test-harness */
1492 #endif
1493
1494 #ifdef WITH_CONTENT_SCAN
1495 uschar *spamd_address          = US"127.0.0.1 783";
1496 uschar *spam_bar               = NULL;
1497 uschar *spam_report            = NULL;
1498 uschar *spam_action            = NULL;
1499 uschar *spam_score             = NULL;
1500 uschar *spam_score_int         = NULL;
1501 #endif
1502 #ifdef SUPPORT_SPF
1503 uschar *spf_guess              = US"v=spf1 a/24 mx/24 ptr ?all";
1504 uschar *spf_header_comment     = NULL;
1505 uschar *spf_received           = NULL;
1506 uschar *spf_result             = NULL;
1507 uschar *spf_smtp_comment       = NULL;
1508 uschar *spf_smtp_comment_template
1509                     /* Used to be: "Please%_see%_http://www.open-spf.org/Why?id=%{S}&ip=%{C}&receiver=%{R}" */
1510                                = US"Please%_see%_http://www.open-spf.org/Why";
1511
1512 #endif
1513
1514 FILE   *spool_data_file        = NULL;
1515 uschar *spool_directory        = US SPOOL_DIRECTORY
1516                            "\0<--------------Space to patch spool_directory->";
1517 #ifdef EXPERIMENTAL_SRS_ALT
1518 uschar *srs_config             = NULL;
1519 uschar *srs_db_address         = NULL;
1520 uschar *srs_db_key             = NULL;
1521 int     srs_hashlength         = 6;
1522 int     srs_hashmin            = -1;
1523 int     srs_maxage             = 31;
1524 uschar *srs_orig_recipient     = NULL;
1525 uschar *srs_orig_sender        = NULL;
1526 uschar *srs_recipient          = NULL;
1527 uschar *srs_secrets            = NULL;
1528 uschar *srs_status             = NULL;
1529 #endif
1530 #ifdef SUPPORT_SRS
1531 uschar *srs_recipient          = NULL;
1532 #endif
1533 int     string_datestamp_offset= -1;
1534 int     string_datestamp_length= 0;
1535 int     string_datestamp_type  = -1;
1536 const uschar *submission_domain = NULL;
1537 const uschar *submission_name  = NULL;
1538 int     syslog_facility        = LOG_MAIL;
1539 uschar *syslog_processname     = US"exim";
1540 uschar *system_filter          = NULL;
1541
1542 uschar *system_filter_directory_transport = NULL;
1543 uschar *system_filter_file_transport = NULL;
1544 uschar *system_filter_pipe_transport = NULL;
1545 uschar *system_filter_reply_transport = NULL;
1546
1547 gid_t   system_filter_gid      = 0;
1548 uid_t   system_filter_uid      = (uid_t)-1;
1549
1550 blob    tcp_fastopen_nodata    = { .data = NULL, .len = 0 };
1551 tfo_state_t tcp_out_fastopen   = TFO_NOT_USED;
1552 #ifdef USE_TCP_WRAPPERS
1553 uschar *tcp_wrappers_daemon_name = US TCP_WRAPPERS_DAEMON_NAME;
1554 #endif
1555 int     test_harness_load_avg  = 0;
1556 int     thismessage_size_limit = 0;
1557 int     timeout_frozen_after   = 0;
1558 #ifdef MEASURE_TIMING
1559 struct timeval timestamp_startup;
1560 #endif
1561
1562 transport_instance  *transports = NULL;
1563
1564 transport_instance  transport_defaults = {
1565     /* All non-mentioned elements zero/NULL/FALSE */
1566     .batch_max =                1,
1567     .multi_domain =             TRUE,
1568     .max_addresses =            100,
1569     .connection_max_messages =  500,
1570     .uid =                      (uid_t)(-1),
1571     .gid =                      (gid_t)(-1),
1572     .filter_timeout =           300,
1573     .retry_use_local_part =     TRUE_UNSET,     /* retry_use_local_part: BOOL, but set neither
1574                                                  1 nor 0 so can detect unset */
1575 };
1576
1577 int     transport_count;
1578 uschar *transport_name          = NULL;
1579 int     transport_newlines;
1580 const uschar **transport_filter_argv  = NULL;
1581 int     transport_filter_timeout;
1582 int     transport_write_timeout= 0;
1583
1584 tree_node  *tree_dns_fails     = NULL;
1585 tree_node  *tree_duplicates    = NULL;
1586 tree_node  *tree_nonrecipients = NULL;
1587 tree_node  *tree_unusable      = NULL;
1588
1589 gid_t  *trusted_groups         = NULL;
1590 uid_t  *trusted_users          = NULL;
1591 uschar *timezone_string        = US TIMEZONE_DEFAULT;
1592
1593 uschar *unknown_login          = NULL;
1594 uschar *unknown_username       = NULL;
1595 uschar *untrusted_set_sender   = NULL;
1596
1597 /*  A regex for matching a "From_" line in an incoming message, in the form
1598
1599     From ph10 Fri Jan  5 12:35 GMT 1996
1600
1601 which  the "mail" commands send to the MTA (undocumented, of course), or in
1602 the  form
1603
1604     From ph10 Fri, 7 Jan 97 14:00:00 GMT
1605
1606 which  is apparently used by some UUCPs, despite it not being in RFC 976.
1607 Because  of variations in time formats, just match up to the minutes. That
1608 should  be sufficient. Examples have been seen of time fields like 12:1:03,
1609 so  just require one digit for hours and minutes. The weekday is also absent
1610 in  some forms. */
1611
1612 uschar *uucp_from_pattern      = US
1613    "^From\\s+(\\S+)\\s+(?:[a-zA-Z]{3},?\\s+)?"    /* Common start */
1614    "(?:"                                          /* Non-extracting bracket */
1615    "[a-zA-Z]{3}\\s+\\d?\\d|"                      /* First form */
1616    "\\d?\\d\\s+[a-zA-Z]{3}\\s+\\d\\d(?:\\d\\d)?"  /* Second form */
1617    ")"                                            /* End alternation */
1618    "\\s+\\d\\d?:\\d\\d?";                         /* Start of time */
1619
1620 uschar *uucp_from_sender       = US"$1";
1621
1622 uschar *verify_mode            = NULL;
1623 uschar *version_copyright      =
1624  US"Copyright (c) University of Cambridge, 1995 - 2018\n"
1625    "(c) The Exim Maintainers and contributors in ACKNOWLEDGMENTS file, 2007 - 2020";
1626 uschar *version_date           = US"?";
1627 uschar *version_cnumber        = US"????";
1628 uschar *version_string         = US"?";
1629
1630 uschar *warn_message_file      = NULL;
1631 int     warning_count          = 0;
1632 uschar *warnmsg_delay          = NULL;
1633 uschar *warnmsg_recipients     = NULL;
1634
1635
1636 /*  End of globals.c */