TLS: ALPN options
[exim.git] / src / src / globals.c
1 /*************************************************
2 *     Exim - an Internet mail transport agent    *
3 *************************************************/
4
5 /* Copyright (c) University of Cambridge 1995 - 2018 */
6 /* Copyright (c) The Exim Maintainers 2020 */
7 /* See the file NOTICE for conditions of use and distribution. */
8
9 /* All the global variables are defined together in this one module, so
10 that they are easy to find. */
11
12 #include "exim.h"
13
14
15 /* Generic options for auths, all of which live inside auth_instance
16 data blocks and hence have the opt_public flag set. */
17
18 optionlist optionlist_auths[] = {
19   { "client_condition", opt_stringptr | opt_public,
20                  OPT_OFF(auth_instance, client_condition) },
21   { "client_set_id", opt_stringptr | opt_public,
22                  OPT_OFF(auth_instance, set_client_id) },
23   { "driver",        opt_stringptr | opt_public,
24                  OPT_OFF(auth_instance, driver_name) },
25   { "public_name",   opt_stringptr | opt_public,
26                  OPT_OFF(auth_instance, public_name) },
27   { "server_advertise_condition", opt_stringptr | opt_public,
28                  OPT_OFF(auth_instance, advertise_condition)},
29   { "server_condition", opt_stringptr | opt_public,
30                  OPT_OFF(auth_instance, server_condition) },
31   { "server_debug_print", opt_stringptr | opt_public,
32                  OPT_OFF(auth_instance, server_debug_string) },
33   { "server_mail_auth_condition", opt_stringptr | opt_public,
34                  OPT_OFF(auth_instance, mail_auth_condition) },
35   { "server_set_id", opt_stringptr | opt_public,
36                  OPT_OFF(auth_instance, set_id) }
37 };
38
39 int     optionlist_auths_size = nelem(optionlist_auths);
40
41 /* An empty host aliases list. */
42
43 uschar *no_aliases             = NULL;
44
45
46 /* For comments on these variables, see globals.h. I'm too idle to
47 duplicate them here... */
48
49 #ifdef EXIM_PERL
50 uschar *opt_perl_startup       = NULL;
51 BOOL    opt_perl_at_start      = FALSE;
52 BOOL    opt_perl_started       = FALSE;
53 BOOL    opt_perl_taintmode     = FALSE;
54 #endif
55
56 #ifdef EXPAND_DLFUNC
57 tree_node *dlobj_anchor        = NULL;
58 #endif
59
60 #ifdef LOOKUP_IBASE
61 uschar *ibase_servers          = NULL;
62 #endif
63
64 #ifdef LOOKUP_LDAP
65 uschar *eldap_ca_cert_dir      = NULL;
66 uschar *eldap_ca_cert_file     = NULL;
67 uschar *eldap_cert_file        = NULL;
68 uschar *eldap_cert_key         = NULL;
69 uschar *eldap_cipher_suite     = NULL;
70 uschar *eldap_default_servers  = NULL;
71 uschar *eldap_require_cert     = NULL;
72 int     eldap_version          = -1;
73 BOOL    eldap_start_tls        = FALSE;
74 #endif
75
76 #ifdef LOOKUP_MYSQL
77 uschar *mysql_servers          = NULL;
78 #endif
79
80 #ifdef LOOKUP_ORACLE
81 uschar *oracle_servers         = NULL;
82 #endif
83
84 #ifdef LOOKUP_PGSQL
85 uschar *pgsql_servers          = NULL;
86 #endif
87
88 #ifdef LOOKUP_REDIS
89 uschar *redis_servers          = NULL;
90 #endif
91
92 #ifdef LOOKUP_SQLITE
93 uschar *sqlite_dbfile          = NULL;
94 int     sqlite_lock_timeout    = 5;
95 #endif
96
97 #ifdef SUPPORT_MOVE_FROZEN_MESSAGES
98 BOOL    move_frozen_messages   = FALSE;
99 #endif
100
101 #ifdef ALLOW_INSECURE_TAINTED_DATA
102 BOOL    allow_insecure_tainted_data = FALSE;
103 #endif
104
105 /* These variables are outside the #ifdef because it keeps the code less
106 cluttered in several places (e.g. during logging) if we can always refer to
107 them. Also, the tls_ variables are now always visible.  Note that these are
108 only used for smtp connections, not for service-daemon access. */
109
110 tls_support tls_in = {
111  .active =              {.sock = -1}
112  /* all other elements zero */
113 };
114 tls_support tls_out = {
115  .active =              {.sock = -1},
116  /* all other elements zero */
117 };
118
119 uschar *dsn_envid              = NULL;
120 int     dsn_ret                = 0;
121 const pcre  *regex_DSN         = NULL;
122 uschar *dsn_advertise_hosts    = NULL;
123
124 #ifndef DISABLE_TLS
125 BOOL    gnutls_compat_mode     = FALSE;
126 BOOL    gnutls_allow_auto_pkcs11 = FALSE;
127 uschar *hosts_require_alpn     = NULL;
128 uschar *openssl_options        = NULL;
129 const pcre *regex_STARTTLS     = NULL;
130 uschar *tls_advertise_hosts    = US"*";
131 uschar *tls_alpn               = US"smtp:esmtp";
132 uschar *tls_certificate        = NULL;
133 uschar *tls_crl                = NULL;
134 /* This default matches NSS DH_MAX_P_BITS value at current time (2012), because
135 that's the interop problem which has been observed: GnuTLS suggesting a higher
136 bit-count as "NORMAL" (2432) and Thunderbird dropping connection. */
137 int     tls_dh_max_bits        = 2236;
138 uschar *tls_dhparam            = NULL;
139 uschar *tls_eccurve            = US"auto";
140 # ifndef DISABLE_OCSP
141 uschar *tls_ocsp_file          = NULL;
142 # endif
143 uschar *tls_privatekey         = NULL;
144 BOOL    tls_remember_esmtp     = FALSE;
145 uschar *tls_require_ciphers    = NULL;
146 # ifndef DISABLE_TLS_RESUME
147 uschar *tls_resumption_hosts   = NULL;
148 # endif
149 uschar *tls_try_verify_hosts   = NULL;
150 #if defined(SUPPORT_SYSDEFAULT_CABUNDLE) || !defined(USE_GNUTLS)
151 uschar *tls_verify_certificates= US"system";
152 #else
153 uschar *tls_verify_certificates= NULL;
154 #endif
155 uschar *tls_verify_hosts       = NULL;
156 int     tls_watch_fd           = -1;
157 time_t  tls_watch_trigger_time = (time_t)0;
158 #else   /*DISABLE_TLS*/
159 uschar *tls_advertise_hosts    = NULL;
160 #endif
161
162 #ifndef DISABLE_PRDR
163 /* Per Recipient Data Response variables */
164 BOOL    prdr_enable            = FALSE;
165 BOOL    prdr_requested         = FALSE;
166 const pcre *regex_PRDR         = NULL;
167 #endif
168
169 #ifdef SUPPORT_I18N
170 const pcre *regex_UTF8         = NULL;
171 #endif
172
173 /* Input-reading functions for messages, so we can use special ones for
174 incoming TCP/IP. The defaults use stdin. We never need these for any
175 stand-alone tests. */
176
177 #if !defined(STAND_ALONE) && !defined(MACRO_PREDEF)
178 int (*lwr_receive_getc)(unsigned) = stdin_getc;
179 uschar * (*lwr_receive_getbuf)(unsigned *) = NULL;
180 int (*lwr_receive_ungetc)(int) = stdin_ungetc;
181 int (*receive_getc)(unsigned)  = stdin_getc;
182 uschar * (*receive_getbuf)(unsigned *)  = NULL;
183 void (*receive_get_cache)(void)= NULL;
184 int (*receive_ungetc)(int)     = stdin_ungetc;
185 int (*receive_feof)(void)      = stdin_feof;
186 int (*receive_ferror)(void)    = stdin_ferror;
187 BOOL (*receive_smtp_buffered)(void) = NULL;   /* Only used for SMTP */
188 #endif
189
190
191 /* List of per-address expansion variables for clearing and saving/restoring
192 when verifying one address while routing/verifying another. We have to have
193 the size explicit, because it is referenced from more than one module. */
194
195 const uschar **address_expansions[ADDRESS_EXPANSIONS_COUNT] = {
196   CUSS &deliver_address_data,
197   CUSS &deliver_domain,
198   CUSS &deliver_domain_data,
199   CUSS &deliver_domain_orig,
200   CUSS &deliver_domain_parent,
201   CUSS &deliver_localpart,
202   CUSS &deliver_localpart_data,
203   CUSS &deliver_localpart_orig,
204   CUSS &deliver_localpart_parent,
205   CUSS &deliver_localpart_prefix,
206   CUSS &deliver_localpart_suffix,
207   CUSS (uschar **)(&deliver_recipients),
208   CUSS &deliver_host,
209   CUSS &deliver_home,
210   CUSS &address_file,
211   CUSS &address_pipe,
212   CUSS &self_hostname,
213   NULL };
214
215 int address_expansions_count = sizeof(address_expansions)/sizeof(uschar **);
216
217 /******************************************************************************/
218 /* General global variables.  Boolean flags are done as a group
219 so that only one bit each is needed, packed, for all those we never
220 need to take a pointer - and only a char for the rest.
221 This means a struct, unfortunately since it clutters the sourcecode. */
222
223 struct global_flags f =
224 {
225         .acl_temp_details       = FALSE,
226         .active_local_from_check = FALSE,
227         .active_local_sender_retain = FALSE,
228         .address_test_mode      = FALSE,
229         .admin_user             = FALSE,
230         .allow_auth_unadvertised= FALSE,
231         .allow_unqualified_recipient = TRUE,    /* For local messages */
232         .allow_unqualified_sender = TRUE,       /* Reset for SMTP */
233         .authentication_local   = FALSE,
234
235         .background_daemon      = TRUE,
236         .bdat_readers_wanted    = FALSE,
237
238         .chunking_offered       = FALSE,
239         .config_changed         = FALSE,
240         .continue_more          = FALSE,
241
242         .daemon_listen          = FALSE,
243         .debug_daemon           = FALSE,
244         .deliver_firsttime      = FALSE,
245         .deliver_force          = FALSE,
246         .deliver_freeze         = FALSE,
247         .deliver_force_thaw     = FALSE,
248         .deliver_manual_thaw    = FALSE,
249         .deliver_selectstring_regex = FALSE,
250         .deliver_selectstring_sender_regex = FALSE,
251         .disable_callout_flush  = FALSE,
252         .disable_delay_flush    = FALSE,
253         .disable_logging        = FALSE,
254 #ifndef DISABLE_DKIM
255         .dkim_disable_verify      = FALSE,
256         .dkim_init_done           = FALSE,
257 #endif
258 #ifdef SUPPORT_DMARC
259         .dmarc_has_been_checked  = FALSE,
260         .dmarc_disable_verify    = FALSE,
261         .dmarc_enable_forensic   = FALSE,
262 #endif
263         .dont_deliver           = FALSE,
264         .dot_ends               = TRUE,
265
266         .enable_dollar_recipients = FALSE,
267         .expand_string_forcedfail = FALSE,
268
269         .filter_running         = FALSE,
270
271         .header_rewritten       = FALSE,
272         .helo_verified          = FALSE,
273         .helo_verify_failed     = FALSE,
274         .host_checking_callout  = FALSE,
275         .host_find_failed_syntax= FALSE,
276
277         .inetd_wait_mode        = FALSE,
278         .is_inetd               = FALSE,
279
280         .local_error_message    = FALSE,
281         .log_testing_mode       = FALSE,
282
283 #ifdef WITH_CONTENT_SCAN
284         .no_mbox_unspool        = FALSE,
285 #endif
286         .no_multiline_responses = FALSE,
287
288         .parse_allow_group      = FALSE,
289         .parse_found_group      = FALSE,
290         .pipelining_enable      = TRUE,
291 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
292         .proxy_session_failed   = FALSE,
293 #endif
294
295         .queue_2stage           = FALSE,
296         .queue_only_policy      = FALSE,
297         .queue_run_first_delivery = FALSE,
298         .queue_run_force        = FALSE,
299         .queue_run_local        = FALSE,
300         .queue_running          = FALSE,
301         .queue_smtp             = FALSE,
302
303         .really_exim            = TRUE,
304         .receive_call_bombout   = FALSE,
305         .recipients_discarded   = FALSE,
306         .running_in_test_harness = FALSE,
307
308         .search_find_defer      = FALSE,
309         .sender_address_forced  = FALSE,
310         .sender_host_notsocket  = FALSE,
311         .sender_host_unknown    = FALSE,
312         .sender_local           = FALSE,
313         .sender_name_forced     = FALSE,
314         .sender_set_untrusted   = FALSE,
315         .smtp_authenticated     = FALSE,
316 #ifndef DISABLE_PIPE_CONNECT
317         .smtp_in_early_pipe_advertised = FALSE,
318         .smtp_in_early_pipe_no_auth = FALSE,
319         .smtp_in_early_pipe_used = FALSE,
320 #endif
321         .smtp_in_pipelining_advertised = FALSE,
322         .smtp_in_pipelining_used = FALSE,
323         .smtp_in_quit           = FALSE,
324         .spool_file_wireformat  = FALSE,
325         .submission_mode        = FALSE,
326         .suppress_local_fixups  = FALSE,
327         .suppress_local_fixups_default = FALSE,
328         .synchronous_delivery   = FALSE,
329         .system_filtering       = FALSE,
330
331         .taint_check_slow       = FALSE,
332         .testsuite_delays       = TRUE,
333         .tcp_fastopen_ok        = FALSE,
334         .tcp_in_fastopen        = FALSE,
335         .tcp_in_fastopen_data   = FALSE,
336         .tcp_in_fastopen_logged = FALSE,
337         .tcp_out_fastopen_logged= FALSE,
338         .timestamps_utc         = FALSE,
339         .transport_filter_timed_out = FALSE,
340         .trusted_caller         = FALSE,
341         .trusted_config         = TRUE,
342 };
343
344 /******************************************************************************/
345 /* These are the flags which are either variables or mainsection options,
346 so an address is needed for access, or are exported to local_scan. */
347
348 BOOL    accept_8bitmime        = TRUE; /* deliberately not RFC compliant */
349 BOOL    allow_domain_literals  = FALSE;
350 BOOL    allow_mx_to_ip         = FALSE;
351 BOOL    allow_utf8_domains     = FALSE;
352 BOOL    authentication_failed  = FALSE;
353
354 BOOL    bounce_return_body     = TRUE;
355 BOOL    bounce_return_message  = TRUE;
356 BOOL    check_rfc2047_length   = TRUE;
357 BOOL    commandline_checks_require_admin = FALSE;
358
359 #ifdef EXPERIMENTAL_DCC
360 BOOL    dcc_direct_add_header  = FALSE;
361 #endif
362 BOOL    debug_store            = FALSE;
363 BOOL    delivery_date_remove   = TRUE;
364 BOOL    deliver_drop_privilege = FALSE;
365 #ifdef ENABLE_DISABLE_FSYNC
366 BOOL    disable_fsync          = FALSE;
367 #endif
368 BOOL    disable_ipv6           = FALSE;
369 BOOL    dns_csa_use_reverse    = TRUE;
370 BOOL    drop_cr                = FALSE;         /* No longer used */
371
372 BOOL    envelope_to_remove     = TRUE;
373 BOOL    exim_gid_set           = TRUE;          /* This gid is always set */
374 BOOL    exim_uid_set           = TRUE;          /* This uid is always set */
375 BOOL    extract_addresses_remove_arguments = TRUE;
376
377 BOOL    host_checking          = FALSE;
378 BOOL    host_lookup_deferred   = FALSE;
379 BOOL    host_lookup_failed     = FALSE;
380 BOOL    ignore_fromline_local  = FALSE;
381
382 BOOL    local_from_check       = TRUE;
383 BOOL    local_sender_retain    = FALSE;
384 BOOL    log_timezone           = FALSE;
385 BOOL    message_body_newlines  = FALSE;
386 BOOL    message_logs           = TRUE;
387 #ifdef SUPPORT_I18N
388 BOOL    message_smtputf8       = FALSE;
389 #endif
390 BOOL    mua_wrapper            = FALSE;
391
392 BOOL    preserve_message_logs  = FALSE;
393 BOOL    print_topbitchars      = FALSE;
394 BOOL    prod_requires_admin    = TRUE;
395 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
396 BOOL    proxy_session          = FALSE;
397 #endif
398
399 #ifndef DISABLE_QUEUE_RAMP
400 BOOL    queue_fast_ramp         = FALSE;
401 #endif
402 BOOL    queue_list_requires_admin = TRUE;
403 BOOL    queue_only             = FALSE;
404 BOOL    queue_only_load_latch  = TRUE;
405 BOOL    queue_only_override    = TRUE;
406 BOOL    queue_run_in_order     = FALSE;
407 BOOL    recipients_max_reject  = FALSE;
408 BOOL    return_path_remove     = TRUE;
409
410 BOOL    smtp_batched_input     = FALSE;
411 BOOL    sender_helo_dnssec     = FALSE;
412 BOOL    sender_host_dnssec     = FALSE;
413 BOOL    smtp_accept_keepalive  = TRUE;
414 BOOL    smtp_check_spool_space = TRUE;
415 BOOL    smtp_enforce_sync      = TRUE;
416 BOOL    smtp_etrn_serialize    = TRUE;
417 BOOL    smtp_input             = FALSE;
418 BOOL    smtp_return_error_details = FALSE;
419 #ifdef SUPPORT_SPF
420 BOOL    spf_result_guessed     = FALSE;
421 #endif
422 BOOL    split_spool_directory  = FALSE;
423 BOOL    spool_wireformat       = FALSE;
424 #ifdef EXPERIMENTAL_SRS_ALT
425 BOOL    srs_usehash            = TRUE;
426 BOOL    srs_usetimestamp       = TRUE;
427 #endif
428 BOOL    strict_acl_vars        = FALSE;
429 BOOL    strip_excess_angle_brackets = FALSE;
430 BOOL    strip_trailing_dot     = FALSE;
431 BOOL    syslog_duplication     = TRUE;
432 BOOL    syslog_pid             = TRUE;
433 BOOL    syslog_timestamp       = TRUE;
434 BOOL    system_filter_gid_set  = FALSE;
435 BOOL    system_filter_uid_set  = FALSE;
436
437 BOOL    tcp_nodelay            = TRUE;
438 BOOL    write_rejectlog        = TRUE;
439
440 /******************************************************************************/
441
442 header_line *acl_added_headers = NULL;
443 tree_node *acl_anchor          = NULL;
444 uschar *acl_arg[9]             = {NULL, NULL, NULL, NULL, NULL,
445                                   NULL, NULL, NULL, NULL};
446 int     acl_narg               = 0;
447
448 int     acl_level              = 0;
449
450 uschar *acl_not_smtp           = NULL;
451 #ifdef WITH_CONTENT_SCAN
452 uschar *acl_not_smtp_mime      = NULL;
453 #endif
454 uschar *acl_not_smtp_start     = NULL;
455 uschar *acl_removed_headers    = NULL;
456 uschar *acl_smtp_auth          = NULL;
457 uschar *acl_smtp_connect       = NULL;
458 uschar *acl_smtp_data          = NULL;
459 #ifndef DISABLE_PRDR
460 uschar *acl_smtp_data_prdr     = US"accept";
461 #endif
462 #ifndef DISABLE_DKIM
463 uschar *acl_smtp_dkim          = NULL;
464 #endif
465 uschar *acl_smtp_etrn          = NULL;
466 uschar *acl_smtp_expn          = NULL;
467 uschar *acl_smtp_helo          = NULL;
468 uschar *acl_smtp_mail          = NULL;
469 uschar *acl_smtp_mailauth      = NULL;
470 #ifdef WITH_CONTENT_SCAN
471 uschar *acl_smtp_mime          = NULL;
472 #endif
473 uschar *acl_smtp_notquit       = NULL;
474 uschar *acl_smtp_predata       = NULL;
475 uschar *acl_smtp_quit          = NULL;
476 uschar *acl_smtp_rcpt          = NULL;
477 uschar *acl_smtp_starttls      = NULL;
478 uschar *acl_smtp_vrfy          = NULL;
479
480 tree_node *acl_var_c           = NULL;
481 tree_node *acl_var_m           = NULL;
482 uschar *acl_verify_message     = NULL;
483 string_item *acl_warn_logged   = NULL;
484
485 /* Names of SMTP places for use in ACL error messages, and corresponding SMTP
486 error codes - keep in step with definitions of ACL_WHERE_xxxx in macros.h. */
487
488 uschar *acl_wherenames[]       = { US"RCPT",
489                                    US"MAIL",
490                                    US"PREDATA",
491                                    US"MIME",
492                                    US"DKIM",
493                                    US"DATA",
494 #ifndef DISABLE_PRDR
495                                    US"PRDR",
496 #endif
497                                    US"non-SMTP",
498                                    US"AUTH",
499                                    US"connection",
500                                    US"ETRN",
501                                    US"EXPN",
502                                    US"EHLO or HELO",
503                                    US"MAILAUTH",
504                                    US"non-SMTP-start",
505                                    US"NOTQUIT",
506                                    US"QUIT",
507                                    US"STARTTLS",
508                                    US"VRFY",
509                                    US"delivery",
510                                    US"unknown"
511                                  };
512
513 uschar *acl_wherecodes[]       = { US"550",     /* RCPT */
514                                    US"550",     /* MAIL */
515                                    US"550",     /* PREDATA */
516                                    US"550",     /* MIME */
517                                    US"550",     /* DKIM */
518                                    US"550",     /* DATA */
519 #ifndef DISABLE_PRDR
520                                    US"550",    /* RCPT PRDR */
521 #endif
522                                    US"0",       /* not SMTP; not relevant */
523                                    US"503",     /* AUTH */
524                                    US"550",     /* connect */
525                                    US"458",     /* ETRN */
526                                    US"550",     /* EXPN */
527                                    US"550",     /* HELO/EHLO */
528                                    US"0",       /* MAILAUTH; not relevant */
529                                    US"0",       /* not SMTP; not relevant */
530                                    US"0",       /* NOTQUIT; not relevant */
531                                    US"0",       /* QUIT; not relevant */
532                                    US"550",     /* STARTTLS */
533                                    US"252",     /* VRFY */
534                                    US"0",       /* delivery; not relevant */
535                                    US"0"        /* unknown; not relevant */
536                                  };
537
538 uschar *add_environment        = NULL;
539 address_item  *addr_duplicate  = NULL;
540
541 address_item address_defaults = {
542   .next =               NULL,
543   .parent =             NULL,
544   .first =              NULL,
545   .dupof =              NULL,
546   .start_router =       NULL,
547   .router =             NULL,
548   .transport =          NULL,
549   .host_list =          NULL,
550   .host_used =          NULL,
551   .fallback_hosts =     NULL,
552   .reply =              NULL,
553   .retries =            NULL,
554   .address =            NULL,
555   .unique =             NULL,
556   .cc_local_part =      NULL,
557   .lc_local_part =      NULL,
558   .local_part =         NULL,
559   .prefix =             NULL,
560   .prefix_v =           NULL,
561   .suffix =             NULL,
562   .suffix_v =           NULL,
563   .domain =             NULL,
564   .address_retry_key =  NULL,
565   .domain_retry_key =   NULL,
566   .current_dir =        NULL,
567   .home_dir =           NULL,
568   .message =            NULL,
569   .user_message =       NULL,
570   .onetime_parent =     NULL,
571   .pipe_expandn =       NULL,
572   .return_filename =    NULL,
573   .self_hostname =      NULL,
574   .shadow_message =     NULL,
575 #ifndef DISABLE_TLS
576   .cipher =             NULL,
577   .ourcert =            NULL,
578   .peercert =           NULL,
579   .peerdn =             NULL,
580   .ocsp =               OCSP_NOT_REQ,
581 #endif
582 #ifdef EXPERIMENTAL_DSN_INFO
583   .smtp_greeting =      NULL,
584   .helo_response =      NULL,
585 #endif
586   .authenticator =      NULL,
587   .auth_id =            NULL,
588   .auth_sndr =          NULL,
589   .dsn_orcpt =          NULL,
590   .dsn_flags =          0,
591   .dsn_aware =          0,
592   .uid =                (uid_t)(-1),
593   .gid =                (gid_t)(-1),
594   .flags =              { 0 },
595   .domain_cache =       { 0 },                /* domain_cache - any larger array should be zeroed */
596   .localpart_cache =    { 0 },                /* localpart_cache - ditto */
597   .mode =               -1,
598   .more_errno =         0,
599   .delivery_time =      {.tv_sec = 0, .tv_usec = 0},
600   .basic_errno =        ERRNO_UNKNOWNERROR,
601   .child_count =        0,
602   .return_file =        -1,
603   .special_action =     SPECIAL_NONE,
604   .transport_return =   DEFER,
605   .prop = {                                     /* fields that are propagated to children */
606     .address_data =     NULL,
607     .domain_data =      NULL,
608     .localpart_data =   NULL,
609     .errors_address =   NULL,
610     .extra_headers =    NULL,
611     .remove_headers =   NULL,
612     .variables =        NULL,
613 #ifdef EXPERIMENTAL_SRS_ALT
614     .srs_sender =       NULL,
615 #endif
616     .ignore_error =     FALSE,
617 #ifdef SUPPORT_I18N
618     .utf8_msg =         FALSE,
619     .utf8_downcvt =     FALSE,
620     .utf8_downcvt_maybe = FALSE
621 #endif
622   }
623 };
624
625 uschar *address_file           = NULL;
626 uschar *address_pipe           = NULL;
627 tree_node *addresslist_anchor  = NULL;
628 int     addresslist_count      = 0;
629 gid_t  *admin_groups           = NULL;
630
631 #ifdef EXPERIMENTAL_ARC
632 struct arc_set *arc_received    = NULL;
633 int     arc_received_instance   = 0;
634 int     arc_oldest_pass         = 0;
635 const uschar *arc_state         = NULL;
636 const uschar *arc_state_reason  = NULL;
637 #endif
638
639 uschar *authenticated_fail_id  = NULL;
640 uschar *authenticated_id       = NULL;
641 uschar *authenticated_sender   = NULL;
642 auth_instance  *auths          = NULL;
643 uschar *auth_advertise_hosts   = US"*";
644 auth_instance auth_defaults    = {
645     .next =             NULL,
646     .name =             NULL,
647     .info =             NULL,
648     .options_block =    NULL,
649     .driver_name =      NULL,
650     .advertise_condition = NULL,
651     .client_condition = NULL,
652     .public_name =      NULL,
653     .set_id =           NULL,
654     .set_client_id =    NULL,
655     .mail_auth_condition = NULL,
656     .server_debug_string = NULL,
657     .server_condition = NULL,
658     .client =           FALSE,
659     .server =           FALSE,
660     .advertised =       FALSE
661 };
662
663 uschar *auth_defer_msg         = US"reason not recorded";
664 uschar *auth_defer_user_msg    = US"";
665 uschar *auth_vars[AUTH_VARS];
666 int     auto_thaw              = 0;
667 #ifdef WITH_CONTENT_SCAN
668 int     av_failed              = FALSE; /* boolean but accessed as vtype_int*/
669 uschar *av_scanner             = US"sophie:/var/run/sophie";  /* AV scanner */
670 #endif
671
672 #if BASE_62 == 62
673 uschar *base62_chars=
674     US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";
675 #else
676 uschar *base62_chars= US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ";
677 #endif
678
679 uschar *bi_command             = NULL;
680 uschar *big_buffer             = NULL;
681 int     big_buffer_size        = BIG_BUFFER_SIZE;
682 #ifdef EXPERIMENTAL_BRIGHTMAIL
683 uschar *bmi_alt_location       = NULL;
684 uschar *bmi_base64_tracker_verdict = NULL;
685 uschar *bmi_base64_verdict     = NULL;
686 uschar *bmi_config_file        = US"/opt/brightmail/etc/brightmail.cfg";
687 int     bmi_deliver            = 1;
688 int     bmi_run                = 0;
689 uschar *bmi_verdicts           = NULL;
690 #endif
691 int     bsmtp_transaction_linecount = 0;
692 int     body_8bitmime          = 0;
693 int     body_linecount         = 0;
694 int     body_zerocount         = 0;
695 uschar *bounce_message_file    = NULL;
696 uschar *bounce_message_text    = NULL;
697 uschar *bounce_recipient       = NULL;
698 int     bounce_return_linesize_limit = 998;
699 int     bounce_return_size_limit = 100*1024;
700 uschar *bounce_sender_authentication = NULL;
701
702 uschar *callout_address        = NULL;
703 int     callout_cache_domain_positive_expire = 7*24*60*60;
704 int     callout_cache_domain_negative_expire = 3*60*60;
705 int     callout_cache_positive_expire = 24*60*60;
706 int     callout_cache_negative_expire = 2*60*60;
707 uschar *callout_random_local_part = US"$primary_hostname-$tod_epoch-testing";
708 uschar *check_dns_names_pattern= US"(?i)^(?>(?(1)\\.|())[^\\W](?>[a-z0-9/_-]*[^\\W])?)+(\\.?)$";
709 int     check_log_inodes       = 100;
710 int_eximarith_t check_log_space = 10*1024;      /* 10K Kbyte == 10MB */
711 int     check_spool_inodes     = 100;
712 int_eximarith_t check_spool_space = 10*1024;    /* 10K Kbyte == 10MB */
713
714 uschar *chunking_advertise_hosts = US"*";
715 unsigned chunking_datasize     = 0;
716 unsigned chunking_data_left    = 0;
717 chunking_state_t chunking_state= CHUNKING_NOT_OFFERED;
718 const pcre *regex_CHUNKING     = NULL;
719
720 #ifdef EXPERIMENTAL_ESMTP_LIMITS
721 const pcre *regex_LIMITS        = NULL;
722 #endif
723
724 uschar *client_authenticator   = NULL;
725 uschar *client_authenticated_id = NULL;
726 uschar *client_authenticated_sender = NULL;
727 int     clmacro_count          = 0;
728 uschar *clmacros[MAX_CLMACROS];
729 FILE   *config_file            = NULL;
730 const uschar *config_filename  = NULL;
731 int     config_lineno          = 0;
732 #ifdef CONFIGURE_GROUP
733 gid_t   config_gid             = CONFIGURE_GROUP;
734 #else
735 gid_t   config_gid             = 0;
736 #endif
737 uschar *config_main_filelist   = US CONFIGURE_FILE
738                          "\0<-----------Space to patch configure_filename->";
739 uschar *config_main_filename   = NULL;
740 uschar *config_main_directory  = NULL;
741
742 #ifdef CONFIGURE_OWNER
743 uid_t   config_uid             = CONFIGURE_OWNER;
744 #else
745 uid_t   config_uid             = 0;
746 #endif
747
748 int     connection_max_messages= -1;
749 uschar *continue_proxy_cipher  = NULL;
750 BOOL    continue_proxy_dane    = FALSE;
751 uschar *continue_proxy_sni     = NULL;
752 uschar *continue_hostname      = NULL;
753 uschar *continue_host_address  = NULL;
754 int     continue_sequence      = 1;
755 uschar *continue_transport     = NULL;
756 #ifdef EXPERIMENTAL_ESMTP_LIMITS
757 unsigned continue_limit_mail   = 0;
758 unsigned continue_limit_rcpt   = 0;
759 unsigned continue_limit_rcptdom= 0;
760 #endif
761
762 uschar *csa_status             = NULL;
763 cut_t   cutthrough = {
764   .callout_hold_only =  FALSE,                          /* verify-only: normal delivery */
765   .delivery =           FALSE,                          /* when to attempt */
766   .defer_pass =         FALSE,                          /* on defer: spool locally */
767   .is_tls =             FALSE,                          /* not a TLS conn yet */
768   .cctx =               {.sock = -1},                   /* open connection */
769   .nrcpt =              0,                              /* number of addresses */
770 };
771
772 int     daemon_notifier_fd     = -1;
773 uschar *daemon_smtp_port       = US"smtp";
774 int     daemon_startup_retries = 9;
775 int     daemon_startup_sleep   = 30;
776
777 #ifdef EXPERIMENTAL_DCC
778 uschar *dcc_header             = NULL;
779 uschar *dcc_result             = NULL;
780 uschar *dccifd_address         = US"/usr/local/dcc/var/dccifd";
781 uschar *dccifd_options         = US"header";
782 #endif
783
784 int     debug_fd               = -1;
785 FILE   *debug_file             = NULL;
786 int     debug_notall[]         = {
787   Di_memory,
788   Di_noutf8,
789   -1
790 };
791 bit_table debug_options[]      = { /* must be in alphabetical order and use
792                                  only the enum values from macro.h */
793   BIT_TABLE(D, acl),
794   BIT_TABLE(D, all),
795   BIT_TABLE(D, auth),
796   BIT_TABLE(D, deliver),
797   BIT_TABLE(D, dns),
798   BIT_TABLE(D, dnsbl),
799   BIT_TABLE(D, exec),
800   BIT_TABLE(D, expand),
801   BIT_TABLE(D, filter),
802   BIT_TABLE(D, hints_lookup),
803   BIT_TABLE(D, host_lookup),
804   BIT_TABLE(D, ident),
805   BIT_TABLE(D, interface),
806   BIT_TABLE(D, lists),
807   BIT_TABLE(D, load),
808   BIT_TABLE(D, local_scan),
809   BIT_TABLE(D, lookup),
810   BIT_TABLE(D, memory),
811   BIT_TABLE(D, noutf8),
812   BIT_TABLE(D, pid),
813   BIT_TABLE(D, process_info),
814   BIT_TABLE(D, queue_run),
815   BIT_TABLE(D, receive),
816   BIT_TABLE(D, resolver),
817   BIT_TABLE(D, retry),
818   BIT_TABLE(D, rewrite),
819   BIT_TABLE(D, route),
820   BIT_TABLE(D, timestamp),
821   BIT_TABLE(D, tls),
822   BIT_TABLE(D, transport),
823   BIT_TABLE(D, uid),
824   BIT_TABLE(D, verify),
825 };
826 int     debug_options_count    = nelem(debug_options);
827
828 unsigned int debug_selector    = 0;
829 int     delay_warning[DELAY_WARNING_SIZE] = { DELAY_WARNING_SIZE, 1, 24*60*60 };
830 uschar *delay_warning_condition=
831   US"${if or {"
832             "{ !eq{$h_list-id:$h_list-post:$h_list-subscribe:}{} }"
833             "{ match{$h_precedence:}{(?i)bulk|list|junk} }"
834             "{ match{$h_auto-submitted:}{(?i)auto-generated|auto-replied} }"
835             "} {no}{yes}}";
836 uschar *deliver_address_data   = NULL;
837 int     deliver_datafile       = -1;
838 const uschar *deliver_domain   = NULL;
839 uschar *deliver_domain_data    = NULL;
840 const uschar *deliver_domain_orig = NULL;
841 const uschar *deliver_domain_parent = NULL;
842 time_t  deliver_frozen_at      = 0;
843 uschar *deliver_home           = NULL;
844 const uschar *deliver_host     = NULL;
845 const uschar *deliver_host_address = NULL;
846 int     deliver_host_port      = 0;
847 uschar *deliver_in_buffer      = NULL;
848 ino_t   deliver_inode          = 0;
849 uschar *deliver_localpart      = NULL;
850 uschar *deliver_localpart_data = NULL;
851 uschar *deliver_localpart_orig = NULL;
852 uschar *deliver_localpart_parent = NULL;
853 uschar *deliver_localpart_prefix = NULL;
854 uschar *deliver_localpart_prefix_v = NULL;
855 uschar *deliver_localpart_suffix = NULL;
856 uschar *deliver_localpart_suffix_v = NULL;
857 uschar *deliver_out_buffer     = NULL;
858 int     deliver_queue_load_max = -1;
859 address_item  *deliver_recipients = NULL;
860 uschar *deliver_selectstring   = NULL;
861 uschar *deliver_selectstring_sender = NULL;
862
863 #ifndef DISABLE_DKIM
864 unsigned dkim_collect_input      = 0;
865 uschar *dkim_cur_signer          = NULL;
866 int     dkim_key_length          = 0;
867 void   *dkim_signatures          = NULL;
868 uschar *dkim_signers             = NULL;
869 uschar *dkim_signing_domain      = NULL;
870 uschar *dkim_signing_selector    = NULL;
871 uschar *dkim_verify_hashes       = US"sha256:sha512";
872 uschar *dkim_verify_keytypes     = US"ed25519:rsa";
873 uschar *dkim_verify_min_keysizes = US"rsa=1024 ed25519=250";
874 BOOL    dkim_verify_minimal      = FALSE;
875 uschar *dkim_verify_overall      = NULL;
876 uschar *dkim_verify_signers      = US"$dkim_signers";
877 uschar *dkim_verify_status       = NULL;
878 uschar *dkim_verify_reason       = NULL;
879 #endif
880 #ifdef SUPPORT_DMARC
881 uschar *dmarc_domain_policy     = NULL;
882 uschar *dmarc_forensic_sender   = NULL;
883 uschar *dmarc_history_file      = NULL;
884 uschar *dmarc_status            = NULL;
885 uschar *dmarc_status_text       = NULL;
886 uschar *dmarc_tld_file          = NULL;
887 uschar *dmarc_used_domain       = NULL;
888 #endif
889
890 uschar *dns_again_means_nonexist = NULL;
891 int     dns_csa_search_limit   = 5;
892 int     dns_cname_loops        = 1;
893 #ifdef SUPPORT_DANE
894 int     dns_dane_ok            = -1;
895 #endif
896 uschar *dns_ipv4_lookup        = NULL;
897 int     dns_retrans            = 0;
898 int     dns_retry              = 0;
899 int     dns_dnssec_ok          = -1; /* <0 = not coerced */
900 uschar *dns_trust_aa           = NULL;
901 int     dns_use_edns0          = -1; /* <0 = not coerced */
902 uschar *dnslist_domain         = NULL;
903 uschar *dnslist_matched        = NULL;
904 uschar *dnslist_text           = NULL;
905 uschar *dnslist_value          = NULL;
906 tree_node *domainlist_anchor   = NULL;
907 int     domainlist_count       = 0;
908 uschar *dsn_from               = US DEFAULT_DSN_FROM;
909
910 int     errno_quota            = ERRNO_QUOTA;
911 uschar *errors_copy            = NULL;
912 int     error_handling         = ERRORS_SENDER;
913 uschar *errors_reply_to        = NULL;
914 int     errors_sender_rc       = EXIT_FAILURE;
915 #ifndef DISABLE_EVENT
916 uschar *event_action             = NULL;        /* expansion for delivery events */
917 uschar *event_data               = NULL;        /* auxiliary data variable for event */
918 int     event_defer_errno        = 0;
919 const uschar *event_name         = NULL;        /* event name variable */
920 #endif
921
922
923 gid_t   exim_gid               = EXIM_GID;
924 uschar *exim_path              = US BIN_DIRECTORY "/exim"
925                         "\0<---------------Space to patch exim_path->";
926 uid_t   exim_uid               = EXIM_UID;
927 int     expand_level           = 0;             /* Nesting depth, indent for debug */
928 int     expand_forbid          = 0;
929 int     expand_nlength[EXPAND_MAXN+1];
930 int     expand_nmax            = -1;
931 uschar *expand_nstring[EXPAND_MAXN+1];
932 uschar *expand_string_message;
933 uschar *extra_local_interfaces = NULL;
934
935 int     fake_response          = OK;
936 uschar *fake_response_text     = US"Your message has been rejected but is "
937                                    "being kept for evaluation.\nIf it was a "
938                                    "legitimate message, it may still be "
939                                    "delivered to the target recipient(s).";
940 int     filter_n[FILTER_VARIABLE_COUNT];
941 int     filter_sn[FILTER_VARIABLE_COUNT];
942 int     filter_test            = FTEST_NONE;
943 uschar *filter_test_sfile      = NULL;
944 uschar *filter_test_ufile      = NULL;
945 uschar *filter_thisaddress     = NULL;
946 int     finduser_retries       = 0;
947 uid_t   fixed_never_users[]    = { FIXED_NEVER_USERS };
948 uschar *freeze_tell            = NULL;
949 uschar *freeze_tell_config     = NULL;
950 uschar *fudged_queue_times     = US"";
951
952 uschar *gecos_name             = NULL;
953 uschar *gecos_pattern          = NULL;
954 rewrite_rule  *global_rewrite_rules = NULL;
955
956 volatile sig_atomic_t had_command_timeout = 0;
957 volatile sig_atomic_t had_command_sigterm = 0;
958 volatile sig_atomic_t had_data_timeout    = 0;
959 volatile sig_atomic_t had_data_sigint     = 0;
960 uschar *headers_charset        = US HEADERS_CHARSET;
961 int     header_insert_maxlen   = 64 * 1024;
962 header_line  *header_last      = NULL;
963 header_line  *header_list      = NULL;
964 int     header_maxsize         = HEADER_MAXSIZE;
965 int     header_line_maxsize    = 0;
966
967 header_name header_names[] = {
968   /* name               len     allow_resent    htype */
969   { US"bcc",            3,      TRUE,           htype_bcc },
970   { US"cc",             2,      TRUE,           htype_cc },
971   { US"date",           4,      TRUE,           htype_date },
972   { US"delivery-date", 13,      FALSE,          htype_delivery_date },
973   { US"envelope-to",   11,      FALSE,          htype_envelope_to },
974   { US"from",           4,      TRUE,           htype_from },
975   { US"message-id",    10,      TRUE,           htype_id },
976   { US"received",       8,      FALSE,          htype_received },
977   { US"reply-to",       8,      FALSE,          htype_reply_to },
978   { US"return-path",   11,      FALSE,          htype_return_path },
979   { US"sender",         6,      TRUE,           htype_sender },
980   { US"subject",        7,      FALSE,          htype_subject },
981   { US"to",             2,      TRUE,           htype_to }
982 };
983
984 int header_names_size          = nelem(header_names);
985
986 uschar *helo_accept_junk_hosts = NULL;
987 uschar *helo_allow_chars       = US"";
988 uschar *helo_lookup_domains    = US"@ : @[]";
989 uschar *helo_try_verify_hosts  = NULL;
990 uschar *helo_verify_hosts      = NULL;
991 const uschar *hex_digits       = CUS"0123456789abcdef";
992 uschar *hold_domains           = NULL;
993 uschar *host_data              = NULL;
994 uschar *host_lookup            = NULL;
995 uschar *host_lookup_order      = US"bydns:byaddr";
996 uschar *host_lookup_msg        = US"";
997 int     host_number            = 0;
998 uschar *host_number_string     = NULL;
999 uschar *host_reject_connection = NULL;
1000 tree_node *hostlist_anchor     = NULL;
1001 int     hostlist_count         = 0;
1002 uschar *hosts_treat_as_local   = NULL;
1003 uschar *hosts_require_helo     = US"*";
1004 uschar *hosts_connection_nolog = NULL;
1005
1006 int     ignore_bounce_errors_after = 10*7*24*60*60;  /* 10 weeks */
1007 uschar *ignore_fromline_hosts  = NULL;
1008 int     inetd_wait_timeout     = -1;
1009 uschar *initial_cwd            = NULL;
1010 uschar *interface_address      = NULL;
1011 int     interface_port         = -1;
1012 uschar *iterate_item           = NULL;
1013
1014 int     journal_fd             = -1;
1015
1016 uschar *keep_environment       = NULL;
1017
1018 int     keep_malformed         = 4*24*60*60;    /* 4 days */
1019
1020 uschar *eldap_dn               = NULL;
1021 #ifdef EXPERIMENTAL_ESMTP_LIMITS
1022 uschar *limits_advertise_hosts = US"*";
1023 #endif
1024 int     load_average           = -2;
1025 uschar *local_from_prefix      = NULL;
1026 uschar *local_from_suffix      = NULL;
1027
1028 #if HAVE_IPV6
1029 uschar *local_interfaces       = US"<; ::0 ; 0.0.0.0";
1030 #else
1031 uschar *local_interfaces       = US"0.0.0.0";
1032 #endif
1033
1034 #ifdef HAVE_LOCAL_SCAN
1035 uschar *local_scan_data        = NULL;
1036 int     local_scan_timeout     = 5*60;
1037 #endif
1038 gid_t   local_user_gid         = (gid_t)(-1);
1039 uid_t   local_user_uid         = (uid_t)(-1);
1040
1041 tree_node *localpartlist_anchor= NULL;
1042 int     localpartlist_count    = 0;
1043 uschar *log_buffer             = NULL;
1044
1045 int     log_default[]          = { /* for initializing log_selector */
1046   Li_acl_warn_skipped,
1047   Li_connection_reject,
1048   Li_delay_delivery,
1049   Li_dkim,
1050   Li_dnslist_defer,
1051   Li_etrn,
1052   Li_host_lookup_failed,
1053   Li_lost_incoming_connection,
1054   Li_outgoing_interface, /* see d_log_interface in deliver.c */
1055   Li_msg_id,
1056   Li_queue_run,
1057   Li_queue_time_exclusive,
1058   Li_rejected_header,
1059   Li_retry_defer,
1060   Li_sender_verify_fail,
1061   Li_size_reject,
1062   Li_skip_delivery,
1063   Li_smtp_confirmation,
1064 #ifdef ALLOW_INSECURE_TAINTED_DATA
1065   Li_tainted,
1066 #endif
1067   Li_tls_certificate_verified,
1068   Li_tls_cipher,
1069   -1
1070 };
1071
1072 uschar *log_file_path          = US LOG_FILE_PATH
1073                            "\0<--------------Space to patch log_file_path->";
1074
1075 int     log_notall[]           = {
1076   -1
1077 };
1078 bit_table log_options[]        = { /* must be in alphabetical order,
1079                                 with definitions from enum logbit. */
1080   BIT_TABLE(L, 8bitmime),
1081   BIT_TABLE(L, acl_warn_skipped),
1082   BIT_TABLE(L, address_rewrite),
1083   BIT_TABLE(L, all),
1084   BIT_TABLE(L, all_parents),
1085   BIT_TABLE(L, arguments),
1086   BIT_TABLE(L, connection_reject),
1087   BIT_TABLE(L, delay_delivery),
1088   BIT_TABLE(L, deliver_time),
1089   BIT_TABLE(L, delivery_size),
1090 #ifndef DISABLE_DKIM
1091   BIT_TABLE(L, dkim),
1092   BIT_TABLE(L, dkim_verbose),
1093 #endif
1094   BIT_TABLE(L, dnslist_defer),
1095   BIT_TABLE(L, dnssec),
1096   BIT_TABLE(L, etrn),
1097   BIT_TABLE(L, host_lookup_failed),
1098   BIT_TABLE(L, ident_timeout),
1099   BIT_TABLE(L, incoming_interface),
1100   BIT_TABLE(L, incoming_port),
1101   BIT_TABLE(L, lost_incoming_connection),
1102   BIT_TABLE(L, millisec),
1103   BIT_TABLE(L, msg_id),
1104   BIT_TABLE(L, msg_id_created),
1105   BIT_TABLE(L, outgoing_interface),
1106   BIT_TABLE(L, outgoing_port),
1107   BIT_TABLE(L, pid),
1108   BIT_TABLE(L, pipelining),
1109   BIT_TABLE(L, protocol_detail),
1110 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1111   BIT_TABLE(L, proxy),
1112 #endif
1113   BIT_TABLE(L, queue_run),
1114   BIT_TABLE(L, queue_time),
1115   BIT_TABLE(L, queue_time_exclusive),
1116   BIT_TABLE(L, queue_time_overall),
1117   BIT_TABLE(L, receive_time),
1118   BIT_TABLE(L, received_recipients),
1119   BIT_TABLE(L, received_sender),
1120   BIT_TABLE(L, rejected_header),
1121   { US"rejected_headers", Li_rejected_header },
1122   BIT_TABLE(L, retry_defer),
1123   BIT_TABLE(L, return_path_on_delivery),
1124   BIT_TABLE(L, sender_on_delivery),
1125   BIT_TABLE(L, sender_verify_fail),
1126   BIT_TABLE(L, size_reject),
1127   BIT_TABLE(L, skip_delivery),
1128   BIT_TABLE(L, smtp_confirmation),
1129   BIT_TABLE(L, smtp_connection),
1130   BIT_TABLE(L, smtp_incomplete_transaction),
1131   BIT_TABLE(L, smtp_mailauth),
1132   BIT_TABLE(L, smtp_no_mail),
1133   BIT_TABLE(L, smtp_protocol_error),
1134   BIT_TABLE(L, smtp_syntax_error),
1135   BIT_TABLE(L, subject),
1136 #ifdef ALLOW_INSECURE_TAINTED_DATA
1137   BIT_TABLE(L, tainted),
1138 #endif
1139   BIT_TABLE(L, tls_certificate_verified),
1140   BIT_TABLE(L, tls_cipher),
1141   BIT_TABLE(L, tls_peerdn),
1142   BIT_TABLE(L, tls_resumption),
1143   BIT_TABLE(L, tls_sni),
1144   BIT_TABLE(L, unknown_in_list),
1145 };
1146 int     log_options_count      = nelem(log_options);
1147
1148 int     log_reject_target      = 0;
1149 unsigned int log_selector[log_selector_size]; /* initialized in main() */
1150 uschar *log_selector_string    = NULL;
1151 FILE   *log_stderr             = NULL;
1152 uschar *login_sender_address   = NULL;
1153 uschar *lookup_dnssec_authenticated = NULL;
1154 int     lookup_open_max        = 25;
1155 uschar *lookup_value           = NULL;
1156
1157 macro_item *macros_user        = NULL;
1158 uschar *mailstore_basename     = NULL;
1159 #ifdef WITH_CONTENT_SCAN
1160 uschar *malware_name           = NULL;  /* Virus Name */
1161 #endif
1162 int     max_received_linelength= 0;
1163 int     max_username_length    = 0;
1164 int     message_age            = 0;
1165 uschar *message_body           = NULL;
1166 uschar *message_body_end       = NULL;
1167 int     message_body_size      = 0;
1168 int     message_body_visible   = 500;
1169 int     message_ended          = END_NOTSTARTED;
1170 uschar *message_headers        = NULL;
1171 uschar *message_id;
1172 uschar *message_id_domain      = NULL;
1173 uschar *message_id_text        = NULL;
1174 struct timeval message_id_tv   = { 0, 0 };
1175 uschar  message_id_option[MESSAGE_ID_LENGTH + 3];
1176 uschar *message_id_external;
1177 int     message_linecount      = 0;
1178 int     message_size           = 0;
1179 uschar *message_size_limit     = US"50M";
1180 #ifdef SUPPORT_I18N
1181 int     message_utf8_downconvert = 0;   /* -1 ifneeded; 0 never; 1 always */
1182 #endif
1183 uschar  message_subdir[2]      = { 0, 0 };
1184 uschar *message_reference      = NULL;
1185
1186 /* MIME ACL expandables */
1187 #ifdef WITH_CONTENT_SCAN
1188 int     mime_anomaly_level     = 0;
1189 const uschar *mime_anomaly_text      = NULL;
1190 uschar *mime_boundary          = NULL;
1191 uschar *mime_charset           = NULL;
1192 uschar *mime_content_description = NULL;
1193 uschar *mime_content_disposition = NULL;
1194 uschar *mime_content_id        = NULL;
1195 unsigned int mime_content_size = 0;
1196 uschar *mime_content_transfer_encoding = NULL;
1197 uschar *mime_content_type      = NULL;
1198 uschar *mime_decoded_filename  = NULL;
1199 uschar *mime_filename          = NULL;
1200 int     mime_is_multipart      = 0;
1201 int     mime_is_coverletter    = 0;
1202 int     mime_is_rfc822         = 0;
1203 int     mime_part_count        = -1;
1204 #endif
1205
1206 uid_t  *never_users            = NULL;
1207 uschar *notifier_socket        = US"$spool_directory/" NOTIFIER_SOCKET_NAME ;
1208
1209 const int on                   = 1;     /* for setsockopt */
1210 const int off                  = 0;
1211
1212 uid_t   original_euid;
1213 gid_t   originator_gid;
1214 uschar *originator_login       = NULL;
1215 uschar *originator_name        = NULL;
1216 uid_t   originator_uid;
1217 uschar *override_local_interfaces = NULL;
1218 uschar *override_pid_file_path = NULL;
1219
1220 uschar *percent_hack_domains   = NULL;
1221 uschar *pid_file_path          = US PID_FILE_PATH
1222                            "\0<--------------Space to patch pid_file_path->";
1223 #ifndef DISABLE_PIPE_CONNECT
1224 uschar *pipe_connect_advertise_hosts = US"*";
1225 #endif
1226 uschar *pipelining_advertise_hosts = US"*";
1227 uschar *primary_hostname       = NULL;
1228 uschar *process_info;
1229 int     process_info_len       = 0;
1230 uschar *process_log_path       = NULL;
1231 const uschar *process_purpose  = US"fresh-exec";
1232
1233 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1234 uschar *hosts_proxy            = NULL;
1235 uschar *proxy_external_address = NULL;
1236 int     proxy_external_port    = 0;
1237 uschar *proxy_local_address    = NULL;
1238 int     proxy_local_port       = 0;
1239 int     proxy_protocol_timeout = 3;
1240 #endif
1241
1242 uschar *prvscheck_address      = NULL;
1243 uschar *prvscheck_keynum       = NULL;
1244 uschar *prvscheck_result       = NULL;
1245
1246
1247 const uschar *qualify_domain_recipient = NULL;
1248 uschar *qualify_domain_sender  = NULL;
1249 uschar *queue_domains          = NULL;
1250 int     queue_interval         = -1;
1251 uschar *queue_name             = US"";
1252 uschar *queue_name_dest        = NULL;
1253 uschar *queue_only_file        = NULL;
1254 int     queue_only_load        = -1;
1255 uschar *queue_run_max          = US"5";
1256 pid_t   queue_run_pid          = (pid_t)0;
1257 int     queue_run_pipe         = -1;
1258 unsigned queue_size            = 0;
1259 time_t  queue_size_next        = 0;
1260 uschar *queue_smtp_domains     = NULL;
1261
1262 uint32_t random_seed           = 0;
1263 tree_node *ratelimiters_cmd    = NULL;
1264 tree_node *ratelimiters_conn   = NULL;
1265 tree_node *ratelimiters_mail   = NULL;
1266 uschar *raw_active_hostname    = NULL;
1267 uschar *raw_sender             = NULL;
1268 uschar **raw_recipients        = NULL;
1269 int     raw_recipients_count   = 0;
1270
1271 int     rcpt_count             = 0;
1272 int     rcpt_fail_count        = 0;
1273 int     rcpt_defer_count       = 0;
1274 gid_t   real_gid;
1275 uid_t   real_uid;
1276 int     receive_linecount      = 0;
1277 int     receive_messagecount   = 0;
1278 int     receive_timeout        = 0;
1279 int     received_count         = 0;
1280 uschar *received_for           = NULL;
1281
1282 /*  This is the default text for Received headers generated by Exim. The
1283 date  will be automatically added on the end. */
1284
1285 uschar *received_header_text   = US
1286      "Received: "
1287      "${if def:sender_rcvhost {from $sender_rcvhost\n\t}"
1288        "{${if def:sender_ident {from ${quote_local_part:$sender_ident} }}"
1289          "${if def:sender_helo_name {(helo=$sender_helo_name)\n\t}}}}"
1290      "by $primary_hostname "
1291      "${if def:received_protocol {with $received_protocol }}"
1292 #ifndef DISABLE_TLS
1293      "${if def:tls_in_ver        { ($tls_in_ver)}}"
1294      "${if def:tls_in_cipher_std { tls $tls_in_cipher_std\n\t}}"
1295 #endif
1296      "(Exim $version_number)\n\t"
1297      "${if def:sender_address {(envelope-from <$sender_address>)\n\t}}"
1298      "id $message_exim_id"
1299      "${if def:received_for {\n\tfor $received_for}}"
1300      "\0<---------------Space to patch received_header_text->";
1301
1302 int     received_headers_max   = 30;
1303 uschar *received_protocol      = NULL;
1304 struct timeval received_time   = { 0, 0 };
1305 struct timeval received_time_complete = { 0, 0 };
1306 uschar *recipient_data         = NULL;
1307 uschar *recipient_unqualified_hosts = NULL;
1308 uschar *recipient_verify_failure = NULL;
1309 int     recipients_count       = 0;
1310 recipient_item  *recipients_list = NULL;
1311 int     recipients_list_max    = 0;
1312 int     recipients_max         = 50000;
1313 const pcre *regex_AUTH         = NULL;
1314 const pcre *regex_check_dns_names = NULL;
1315 const pcre *regex_From         = NULL;
1316 const pcre *regex_IGNOREQUOTA  = NULL;
1317 const pcre *regex_PIPELINING   = NULL;
1318 const pcre *regex_SIZE         = NULL;
1319 #ifndef DISABLE_PIPE_CONNECT
1320 const pcre *regex_EARLY_PIPE   = NULL;
1321 #endif
1322 const pcre *regex_ismsgid      = NULL;
1323 const pcre *regex_smtp_code    = NULL;
1324 uschar *regex_vars[REGEX_VARS];
1325 #ifdef WHITELIST_D_MACROS
1326 const pcre *regex_whitelisted_macro = NULL;
1327 #endif
1328 #ifdef WITH_CONTENT_SCAN
1329 uschar *regex_match_string     = NULL;
1330 #endif
1331 int     remote_delivery_count  = 0;
1332 int     remote_max_parallel    = 2;
1333 uschar *remote_sort_domains    = NULL;
1334 int     retry_data_expire      = 7*24*60*60;
1335 int     retry_interval_max     = 24*60*60;
1336 int     retry_maximum_timeout  = 0;        /* set from retry config */
1337 retry_config  *retries         = NULL;
1338 uschar *return_path            = NULL;
1339 int     rewrite_existflags     = 0;
1340 uschar *rfc1413_hosts          = US"@[]";
1341 int     rfc1413_query_timeout  = 0;
1342 uid_t   root_gid               = ROOT_GID;
1343 uid_t   root_uid               = ROOT_UID;
1344
1345 router_instance  *routers  = NULL;
1346 router_instance  router_defaults = {
1347     .next =                     NULL,
1348     .name =                     NULL,
1349     .info =                     NULL,
1350     .options_block =            NULL,
1351     .driver_name =              NULL,
1352
1353     .address_data =             NULL,
1354 #ifdef EXPERIMENTAL_BRIGHTMAIL
1355     .bmi_rule =                 NULL,
1356 #endif
1357     .cannot_route_message =     NULL,
1358     .condition =                NULL,
1359     .current_directory =        NULL,
1360     .debug_string =             NULL,
1361     .domains =                  NULL,
1362     .errors_to =                NULL,
1363     .expand_gid =               NULL,
1364     .expand_uid =               NULL,
1365     .expand_more =              NULL,
1366     .expand_unseen =            NULL,
1367     .extra_headers =            NULL,
1368     .fallback_hosts =           NULL,
1369     .home_directory =           NULL,
1370     .ignore_target_hosts =      NULL,
1371     .local_parts =              NULL,
1372     .pass_router_name =         NULL,
1373     .prefix =                   NULL,
1374     .redirect_router_name =     NULL,
1375     .remove_headers =           NULL,
1376     .require_files =            NULL,
1377     .router_home_directory =    NULL,
1378     .self =                     US"freeze",
1379     .senders =                  NULL,
1380     .suffix =                   NULL,
1381     .translate_ip_address =     NULL,
1382     .transport_name =           NULL,
1383
1384     .address_test =             TRUE,
1385 #ifdef EXPERIMENTAL_BRIGHTMAIL
1386     .bmi_deliver_alternate =    FALSE,
1387     .bmi_deliver_default =      FALSE,
1388     .bmi_dont_deliver =         FALSE,
1389 #endif
1390     .expn =                     TRUE,
1391     .caseful_local_part =       FALSE,
1392     .check_local_user =         FALSE,
1393     .disable_logging =          FALSE,
1394     .fail_verify_recipient =    FALSE,
1395     .fail_verify_sender =       FALSE,
1396     .gid_set =                  FALSE,
1397     .initgroups =               FALSE,
1398     .log_as_local =             TRUE_UNSET,
1399     .more =                     TRUE,
1400     .pass_on_timeout =          FALSE,
1401     .prefix_optional =          FALSE,
1402     .repeat_use =               TRUE,
1403     .retry_use_local_part =     TRUE_UNSET,
1404     .same_domain_copy_routing = FALSE,
1405     .self_rewrite =             FALSE,
1406     .set =                      NULL,
1407     .suffix_optional =          FALSE,
1408     .verify_only =              FALSE,
1409     .verify_recipient =         TRUE,
1410     .verify_sender =            TRUE,
1411     .uid_set =                  FALSE,
1412     .unseen =                   FALSE,
1413     .dsn_lasthop =              FALSE,
1414
1415     .self_code =                self_freeze,
1416     .uid =                      (uid_t)(-1),
1417     .gid =                      (gid_t)(-1),
1418
1419     .fallback_hostlist =        NULL,
1420     .transport =                NULL,
1421     .pass_router =              NULL,
1422     .redirect_router =          NULL,
1423
1424     .dnssec =                   { .request= US"*", .require=NULL },
1425 };
1426
1427 uschar *router_name            = NULL;
1428 tree_node *router_var          = NULL;
1429
1430 ip_address_item *running_interfaces = NULL;
1431
1432 /* This is a weird one. The following string gets patched in the binary by the
1433 script that sets up a copy of Exim for running in the test harness. It seems
1434 that compilers are now clever, and share constant strings if they can.
1435 Elsewhere in Exim the string "<" is used. The compiler optimization seems to
1436 make use of the end of this string in order to save space. So the patching then
1437 wrecks this. We defeat this optimization by adding some additional characters
1438 onto the end of the string. */
1439
1440 uschar *running_status         = US">>>running<<<" "\0EXTRA";
1441
1442 int     runrc                  = 0;
1443
1444 uschar *search_error_message   = NULL;
1445 uschar *self_hostname          = NULL;
1446 uschar *sender_address         = NULL;
1447 unsigned int sender_address_cache[(MAX_NAMED_LIST * 2)/32];
1448 uschar *sender_address_data    = NULL;
1449 uschar *sender_address_unrewritten = NULL;
1450 uschar *sender_data            = NULL;
1451 unsigned int sender_domain_cache[(MAX_NAMED_LIST * 2)/32];
1452 uschar *sender_fullhost        = NULL;
1453 uschar *sender_helo_name       = NULL;
1454 uschar **sender_host_aliases   = &no_aliases;
1455 uschar *sender_host_address    = NULL;
1456 uschar *sender_host_authenticated = NULL;
1457 uschar *sender_host_auth_pubname  = NULL;
1458 unsigned int sender_host_cache[(MAX_NAMED_LIST * 2)/32];
1459 uschar *sender_host_name       = NULL;
1460 int     sender_host_port       = 0;
1461 uschar *sender_ident           = NULL;
1462 uschar *sender_rate            = NULL;
1463 uschar *sender_rate_limit      = NULL;
1464 uschar *sender_rate_period     = NULL;
1465 uschar *sender_rcvhost         = NULL;
1466 uschar *sender_unqualified_hosts = NULL;
1467 uschar *sender_verify_failure = NULL;
1468 address_item *sender_verified_list  = NULL;
1469 address_item *sender_verified_failed = NULL;
1470 int     sender_verified_rc     = -1;
1471 uschar *sending_ip_address     = NULL;
1472 int     sending_port           = -1;
1473 SIGNAL_BOOL sigalrm_seen       = FALSE;
1474 const uschar *sigalarm_setter  = NULL;
1475 uschar **sighup_argv           = NULL;
1476 int     slow_lookup_log        = 0;     /* millisecs, zero disables */
1477 int     smtp_accept_count      = 0;
1478 int     smtp_accept_max        = 20;
1479 int     smtp_accept_max_nonmail= 10;
1480 uschar *smtp_accept_max_nonmail_hosts = US"*";
1481 uschar *smtp_accept_max_per_connection = US"1000";
1482 uschar *smtp_accept_max_per_host = NULL;
1483 int     smtp_accept_queue      = 0;
1484 int     smtp_accept_queue_per_connection = 10;
1485 int     smtp_accept_reserve    = 0;
1486 uschar *smtp_active_hostname   = NULL;
1487 int     smtp_backlog_monitor   = 0;
1488 uschar *smtp_banner            = US"$smtp_active_hostname ESMTP "
1489                              "Exim $version_number $tod_full"
1490                              "\0<---------------Space to patch smtp_banner->";
1491 int     smtp_ch_index          = 0;
1492 uschar *smtp_cmd_argument      = NULL;
1493 uschar *smtp_cmd_buffer        = NULL;
1494 struct timeval smtp_connection_start  = {0,0};
1495 uschar  smtp_connection_had[SMTP_HBUFF_SIZE];
1496 int     smtp_connect_backlog   = 20;
1497 double  smtp_delay_mail        = 0.0;
1498 double  smtp_delay_rcpt        = 0.0;
1499 FILE   *smtp_in                = NULL;
1500 int     smtp_listen_backlog    = 0;
1501 int     smtp_load_reserve      = -1;
1502 int     smtp_mailcmd_count     = 0;
1503 int     smtp_mailcmd_max       = -1;
1504 FILE   *smtp_out               = NULL;
1505 uschar *smtp_etrn_command      = NULL;
1506 int     smtp_max_synprot_errors= 3;
1507 int     smtp_max_unknown_commands = 3;
1508 uschar *smtp_notquit_reason    = NULL;
1509 unsigned smtp_peer_options     = 0;
1510 unsigned smtp_peer_options_wrap= 0;
1511 uschar *smtp_ratelimit_hosts   = NULL;
1512 uschar *smtp_ratelimit_mail    = NULL;
1513 uschar *smtp_ratelimit_rcpt    = NULL;
1514 uschar *smtp_read_error        = US"";
1515 int     smtp_receive_timeout   = 5*60;
1516 uschar *smtp_receive_timeout_s = NULL;
1517 uschar *smtp_reserve_hosts     = NULL;
1518 int     smtp_rlm_base          = 0;
1519 double  smtp_rlm_factor        = 0.0;
1520 int     smtp_rlm_limit         = 0;
1521 int     smtp_rlm_threshold     = INT_MAX;
1522 int     smtp_rlr_base          = 0;
1523 double  smtp_rlr_factor        = 0.0;
1524 int     smtp_rlr_limit         = 0;
1525 int     smtp_rlr_threshold     = INT_MAX;
1526 #ifdef SUPPORT_I18N
1527 uschar *smtputf8_advertise_hosts = US"*";       /* overridden under test-harness */
1528 #endif
1529
1530 #ifdef WITH_CONTENT_SCAN
1531 uschar *spamd_address          = US"127.0.0.1 783";
1532 uschar *spam_bar               = NULL;
1533 uschar *spam_report            = NULL;
1534 uschar *spam_action            = NULL;
1535 uschar *spam_score             = NULL;
1536 uschar *spam_score_int         = NULL;
1537 #endif
1538 #ifdef SUPPORT_SPF
1539 uschar *spf_guess              = US"v=spf1 a/24 mx/24 ptr ?all";
1540 uschar *spf_header_comment     = NULL;
1541 uschar *spf_received           = NULL;
1542 uschar *spf_result             = NULL;
1543 uschar *spf_smtp_comment       = NULL;
1544 uschar *spf_smtp_comment_template
1545                     /* Used to be: "Please%_see%_http://www.open-spf.org/Why?id=%{S}&ip=%{C}&receiver=%{R}" */
1546                                = US"Please%_see%_http://www.open-spf.org/Why";
1547
1548 #endif
1549
1550 FILE   *spool_data_file        = NULL;
1551 uschar *spool_directory        = US SPOOL_DIRECTORY
1552                            "\0<--------------Space to patch spool_directory->";
1553 #ifdef EXPERIMENTAL_SRS_ALT
1554 uschar *srs_config             = NULL;
1555 uschar *srs_db_address         = NULL;
1556 uschar *srs_db_key             = NULL;
1557 int     srs_hashlength         = 6;
1558 int     srs_hashmin            = -1;
1559 int     srs_maxage             = 31;
1560 uschar *srs_orig_recipient     = NULL;
1561 uschar *srs_orig_sender        = NULL;
1562 uschar *srs_recipient          = NULL;
1563 uschar *srs_secrets            = NULL;
1564 uschar *srs_status             = NULL;
1565 #endif
1566 #ifdef SUPPORT_SRS
1567 uschar *srs_recipient          = NULL;
1568 #endif
1569 int     string_datestamp_offset= -1;
1570 int     string_datestamp_length= 0;
1571 int     string_datestamp_type  = -1;
1572 const uschar *submission_domain = NULL;
1573 const uschar *submission_name  = NULL;
1574 int     syslog_facility        = LOG_MAIL;
1575 uschar *syslog_processname     = US"exim";
1576 uschar *system_filter          = NULL;
1577
1578 uschar *system_filter_directory_transport = NULL;
1579 uschar *system_filter_file_transport = NULL;
1580 uschar *system_filter_pipe_transport = NULL;
1581 uschar *system_filter_reply_transport = NULL;
1582
1583 gid_t   system_filter_gid      = 0;
1584 uid_t   system_filter_uid      = (uid_t)-1;
1585
1586 blob    tcp_fastopen_nodata    = { .data = NULL, .len = 0 };
1587 tfo_state_t tcp_out_fastopen   = TFO_NOT_USED;
1588 #ifdef USE_TCP_WRAPPERS
1589 uschar *tcp_wrappers_daemon_name = US TCP_WRAPPERS_DAEMON_NAME;
1590 #endif
1591 int     test_harness_load_avg  = 0;
1592 int     thismessage_size_limit = 0;
1593 int     timeout_frozen_after   = 0;
1594 #ifdef MEASURE_TIMING
1595 struct timeval timestamp_startup;
1596 #endif
1597
1598 transport_instance  *transports = NULL;
1599
1600 transport_instance  transport_defaults = {
1601     /* All non-mentioned elements zero/NULL/FALSE */
1602     .batch_max =                1,
1603     .multi_domain =             TRUE,
1604     .max_addresses =            100,
1605     .connection_max_messages =  500,
1606     .uid =                      (uid_t)(-1),
1607     .gid =                      (gid_t)(-1),
1608     .filter_timeout =           300,
1609     .retry_use_local_part =     TRUE_UNSET,     /* retry_use_local_part: BOOL, but set neither
1610                                                  1 nor 0 so can detect unset */
1611 };
1612
1613 int     transport_count;
1614 uschar *transport_name          = NULL;
1615 int     transport_newlines;
1616 const uschar **transport_filter_argv  = NULL;
1617 int     transport_filter_timeout;
1618 int     transport_write_timeout= 0;
1619
1620 tree_node  *tree_dns_fails     = NULL;
1621 tree_node  *tree_duplicates    = NULL;
1622 tree_node  *tree_nonrecipients = NULL;
1623 tree_node  *tree_unusable      = NULL;
1624
1625 gid_t  *trusted_groups         = NULL;
1626 uid_t  *trusted_users          = NULL;
1627 uschar *timezone_string        = US TIMEZONE_DEFAULT;
1628
1629 uschar *unknown_login          = NULL;
1630 uschar *unknown_username       = NULL;
1631 uschar *untrusted_set_sender   = NULL;
1632
1633 /*  A regex for matching a "From_" line in an incoming message, in the form
1634
1635     From ph10 Fri Jan  5 12:35 GMT 1996
1636
1637 which  the "mail" commands send to the MTA (undocumented, of course), or in
1638 the  form
1639
1640     From ph10 Fri, 7 Jan 97 14:00:00 GMT
1641
1642 which  is apparently used by some UUCPs, despite it not being in RFC 976.
1643 Because  of variations in time formats, just match up to the minutes. That
1644 should  be sufficient. Examples have been seen of time fields like 12:1:03,
1645 so  just require one digit for hours and minutes. The weekday is also absent
1646 in  some forms. */
1647
1648 uschar *uucp_from_pattern      = US
1649    "^From\\s+(\\S+)\\s+(?:[a-zA-Z]{3},?\\s+)?"    /* Common start */
1650    "(?:"                                          /* Non-extracting bracket */
1651    "[a-zA-Z]{3}\\s+\\d?\\d|"                      /* First form */
1652    "\\d?\\d\\s+[a-zA-Z]{3}\\s+\\d\\d(?:\\d\\d)?"  /* Second form */
1653    ")"                                            /* End alternation */
1654    "\\s+\\d\\d?:\\d\\d?";                         /* Start of time */
1655
1656 uschar *uucp_from_sender       = US"$1";
1657
1658 uschar *verify_mode            = NULL;
1659 uschar *version_copyright      =
1660  US"Copyright (c) University of Cambridge, 1995 - 2018\n"
1661    "(c) The Exim Maintainers and contributors in ACKNOWLEDGMENTS file, 2007 - 2020";
1662 uschar *version_date           = US"?";
1663 uschar *version_cnumber        = US"????";
1664 uschar *version_string         = US"?";
1665
1666 uschar *warn_message_file      = NULL;
1667 int     warning_count          = 0;
1668 uschar *warnmsg_delay          = NULL;
1669 uschar *warnmsg_recipients     = NULL;
1670
1671
1672 /*  End of globals.c */