Tidy input buffer handling
[exim.git] / src / src / globals.c
1 /*************************************************
2 *     Exim - an Internet mail transport agent    *
3 *************************************************/
4
5 /* Copyright (c) University of Cambridge 1995 - 2018 */
6 /* Copyright (c) The Exim Maintainers 2020 - 2021 */
7 /* See the file NOTICE for conditions of use and distribution. */
8
9 /* All the global variables are defined together in this one module, so
10 that they are easy to find. */
11
12 #include "exim.h"
13
14
15 /* Generic options for auths, all of which live inside auth_instance
16 data blocks and hence have the opt_public flag set. */
17
18 optionlist optionlist_auths[] = {
19   { "client_condition", opt_stringptr | opt_public,
20                  OPT_OFF(auth_instance, client_condition) },
21   { "client_set_id", opt_stringptr | opt_public,
22                  OPT_OFF(auth_instance, set_client_id) },
23   { "driver",        opt_stringptr | opt_public,
24                  OPT_OFF(auth_instance, driver_name) },
25   { "public_name",   opt_stringptr | opt_public,
26                  OPT_OFF(auth_instance, public_name) },
27   { "server_advertise_condition", opt_stringptr | opt_public,
28                  OPT_OFF(auth_instance, advertise_condition)},
29   { "server_condition", opt_stringptr | opt_public,
30                  OPT_OFF(auth_instance, server_condition) },
31   { "server_debug_print", opt_stringptr | opt_public,
32                  OPT_OFF(auth_instance, server_debug_string) },
33   { "server_mail_auth_condition", opt_stringptr | opt_public,
34                  OPT_OFF(auth_instance, mail_auth_condition) },
35   { "server_set_id", opt_stringptr | opt_public,
36                  OPT_OFF(auth_instance, set_id) }
37 };
38
39 int     optionlist_auths_size = nelem(optionlist_auths);
40
41 /* An empty host aliases list. */
42
43 uschar *no_aliases             = NULL;
44
45
46 /* For comments on these variables, see globals.h. I'm too idle to
47 duplicate them here... */
48
49 #ifdef EXIM_PERL
50 uschar *opt_perl_startup       = NULL;
51 BOOL    opt_perl_at_start      = FALSE;
52 BOOL    opt_perl_started       = FALSE;
53 BOOL    opt_perl_taintmode     = FALSE;
54 #endif
55
56 #ifdef EXPAND_DLFUNC
57 tree_node *dlobj_anchor        = NULL;
58 #endif
59
60 #ifdef LOOKUP_IBASE
61 uschar *ibase_servers          = NULL;
62 #endif
63
64 #ifdef LOOKUP_LDAP
65 uschar *eldap_ca_cert_dir      = NULL;
66 uschar *eldap_ca_cert_file     = NULL;
67 uschar *eldap_cert_file        = NULL;
68 uschar *eldap_cert_key         = NULL;
69 uschar *eldap_cipher_suite     = NULL;
70 uschar *eldap_default_servers  = NULL;
71 uschar *eldap_require_cert     = NULL;
72 int     eldap_version          = -1;
73 BOOL    eldap_start_tls        = FALSE;
74 #endif
75
76 #ifdef LOOKUP_MYSQL
77 uschar *mysql_servers          = NULL;
78 #endif
79
80 #ifdef LOOKUP_ORACLE
81 uschar *oracle_servers         = NULL;
82 #endif
83
84 #ifdef LOOKUP_PGSQL
85 uschar *pgsql_servers          = NULL;
86 #endif
87
88 #ifdef LOOKUP_REDIS
89 uschar *redis_servers          = NULL;
90 #endif
91
92 #ifdef LOOKUP_SQLITE
93 uschar *sqlite_dbfile          = NULL;
94 int     sqlite_lock_timeout    = 5;
95 #endif
96
97 #ifdef SUPPORT_MOVE_FROZEN_MESSAGES
98 BOOL    move_frozen_messages   = FALSE;
99 #endif
100
101 #ifdef ALLOW_INSECURE_TAINTED_DATA
102 BOOL    allow_insecure_tainted_data = FALSE;
103 #endif
104
105 /* These variables are outside the #ifdef because it keeps the code less
106 cluttered in several places (e.g. during logging) if we can always refer to
107 them. Also, the tls_ variables are now always visible.  Note that these are
108 only used for smtp connections, not for service-daemon access. */
109
110 tls_support tls_in = {
111  .active =              {.sock = -1}
112  /* all other elements zero */
113 };
114 tls_support tls_out = {
115  .active =              {.sock = -1},
116  /* all other elements zero */
117 };
118
119 uschar *dsn_envid              = NULL;
120 int     dsn_ret                = 0;
121 const pcre2_code  *regex_DSN         = NULL;
122 uschar *dsn_advertise_hosts    = NULL;
123
124 #ifndef DISABLE_TLS
125 BOOL    gnutls_compat_mode     = FALSE;
126 BOOL    gnutls_allow_auto_pkcs11 = FALSE;
127 uschar *hosts_require_alpn     = NULL;
128 uschar *openssl_options        = NULL;
129 const pcre2_code *regex_STARTTLS     = NULL;
130 uschar *tls_advertise_hosts    = US"*";
131 uschar *tls_alpn               = US"smtp:esmtp";
132 uschar *tls_certificate        = NULL;
133 uschar *tls_crl                = NULL;
134 /* This default matches NSS DH_MAX_P_BITS value at current time (2012), because
135 that's the interop problem which has been observed: GnuTLS suggesting a higher
136 bit-count as "NORMAL" (2432) and Thunderbird dropping connection. */
137 int     tls_dh_max_bits        = 2236;
138 uschar *tls_dhparam            = NULL;
139 uschar *tls_eccurve            = US"auto";
140 # ifndef DISABLE_OCSP
141 uschar *tls_ocsp_file          = NULL;
142 # endif
143 uschar *tls_privatekey         = NULL;
144 BOOL    tls_remember_esmtp     = FALSE;
145 uschar *tls_require_ciphers    = NULL;
146 # ifndef DISABLE_TLS_RESUME
147 uschar *tls_resumption_hosts   = NULL;
148 # endif
149 uschar *tls_try_verify_hosts   = NULL;
150 uschar *tls_verify_certificates= US"system";
151 uschar *tls_verify_hosts       = NULL;
152 int     tls_watch_fd           = -1;
153 time_t  tls_watch_trigger_time = (time_t)0;
154 #else   /*DISABLE_TLS*/
155 uschar *tls_advertise_hosts    = NULL;
156 #endif
157
158 #ifndef DISABLE_PRDR
159 /* Per Recipient Data Response variables */
160 BOOL    prdr_enable            = FALSE;
161 BOOL    prdr_requested         = FALSE;
162 const pcre2_code *regex_PRDR         = NULL;
163 #endif
164
165 #ifdef SUPPORT_I18N
166 const pcre2_code *regex_UTF8         = NULL;
167 #endif
168
169 /* Input-reading functions for messages, so we can use special ones for
170 incoming TCP/IP. The defaults use stdin. We never need these for any
171 stand-alone tests. */
172
173 #if !defined(STAND_ALONE) && !defined(MACRO_PREDEF)
174 int     (*lwr_receive_getc)(unsigned)   = stdin_getc;
175 uschar * (*lwr_receive_getbuf)(unsigned *) = NULL;
176 int     (*lwr_receive_ungetc)(int)      = stdin_ungetc;
177 BOOL    (*lwr_receive_hasc)(void)       = stdin_hasc;
178
179 int     (*receive_getc)(unsigned)       = stdin_getc;
180 uschar * (*receive_getbuf)(unsigned *)  = NULL;
181 void    (*receive_get_cache)(unsigned)  = NULL;
182 BOOL    (*receive_hasc)(void)           = stdin_hasc;
183 int     (*receive_ungetc)(int)          = stdin_ungetc;
184 int     (*receive_feof)(void)           = stdin_feof;
185 int     (*receive_ferror)(void)         = stdin_ferror;
186 #endif
187
188
189 /* List of per-address expansion variables for clearing and saving/restoring
190 when verifying one address while routing/verifying another. We have to have
191 the size explicit, because it is referenced from more than one module. */
192
193 const uschar **address_expansions[ADDRESS_EXPANSIONS_COUNT] = {
194   CUSS &deliver_address_data,
195   CUSS &deliver_domain,
196   CUSS &deliver_domain_data,
197   CUSS &deliver_domain_orig,
198   CUSS &deliver_domain_parent,
199   CUSS &deliver_localpart,
200   CUSS &deliver_localpart_data,
201   CUSS &deliver_localpart_orig,
202   CUSS &deliver_localpart_parent,
203   CUSS &deliver_localpart_prefix,
204   CUSS &deliver_localpart_suffix,
205   CUSS (uschar **)(&deliver_recipients),
206   CUSS &deliver_host,
207   CUSS &deliver_home,
208   CUSS &address_file,
209   CUSS &address_pipe,
210   CUSS &self_hostname,
211   NULL };
212
213 int address_expansions_count = sizeof(address_expansions)/sizeof(uschar **);
214
215 /******************************************************************************/
216 /* General global variables.  Boolean flags are done as a group
217 so that only one bit each is needed, packed, for all those we never
218 need to take a pointer - and only a char for the rest.
219 This means a struct, unfortunately since it clutters the sourcecode. */
220
221 struct global_flags f =
222 {
223         .acl_temp_details       = FALSE,
224         .active_local_from_check = FALSE,
225         .active_local_sender_retain = FALSE,
226         .address_test_mode      = FALSE,
227         .admin_user             = FALSE,
228         .allow_auth_unadvertised= FALSE,
229         .allow_unqualified_recipient = TRUE,    /* For local messages */
230         .allow_unqualified_sender = TRUE,       /* Reset for SMTP */
231         .authentication_local   = FALSE,
232
233         .background_daemon      = TRUE,
234         .bdat_readers_wanted    = FALSE,
235
236         .chunking_offered       = FALSE,
237         .config_changed         = FALSE,
238         .continue_more          = FALSE,
239
240         .daemon_listen          = FALSE,
241         .debug_daemon           = FALSE,
242         .deliver_firsttime      = FALSE,
243         .deliver_force          = FALSE,
244         .deliver_freeze         = FALSE,
245         .deliver_force_thaw     = FALSE,
246         .deliver_manual_thaw    = FALSE,
247         .deliver_selectstring_regex = FALSE,
248         .deliver_selectstring_sender_regex = FALSE,
249         .disable_callout_flush  = FALSE,
250         .disable_delay_flush    = FALSE,
251         .disable_logging        = FALSE,
252 #ifndef DISABLE_DKIM
253         .dkim_disable_verify      = FALSE,
254         .dkim_init_done           = FALSE,
255 #endif
256 #ifdef SUPPORT_DMARC
257         .dmarc_has_been_checked  = FALSE,
258         .dmarc_disable_verify    = FALSE,
259         .dmarc_enable_forensic   = FALSE,
260 #endif
261         .dont_deliver           = FALSE,
262         .dot_ends               = TRUE,
263
264         .enable_dollar_recipients = FALSE,
265         .expand_string_forcedfail = FALSE,
266
267         .filter_running         = FALSE,
268
269         .header_rewritten       = FALSE,
270         .helo_verified          = FALSE,
271         .helo_verify_failed     = FALSE,
272         .host_checking_callout  = FALSE,
273         .host_find_failed_syntax= FALSE,
274
275         .inetd_wait_mode        = FALSE,
276         .is_inetd               = FALSE,
277
278         .local_error_message    = FALSE,
279         .log_testing_mode       = FALSE,
280
281 #ifdef WITH_CONTENT_SCAN
282         .no_mbox_unspool        = FALSE,
283 #endif
284         .no_multiline_responses = FALSE,
285
286         .parse_allow_group      = FALSE,
287         .parse_found_group      = FALSE,
288         .pipelining_enable      = TRUE,
289 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
290         .proxy_session_failed   = FALSE,
291 #endif
292
293         .queue_2stage           = FALSE,
294         .queue_only_policy      = FALSE,
295         .queue_run_first_delivery = FALSE,
296         .queue_run_force        = FALSE,
297         .queue_run_local        = FALSE,
298         .queue_running          = FALSE,
299         .queue_smtp             = FALSE,
300
301         .really_exim            = TRUE,
302         .receive_call_bombout   = FALSE,
303         .recipients_discarded   = FALSE,
304         .running_in_test_harness = FALSE,
305
306         .search_find_defer      = FALSE,
307         .sender_address_forced  = FALSE,
308         .sender_host_notsocket  = FALSE,
309         .sender_host_unknown    = FALSE,
310         .sender_local           = FALSE,
311         .sender_name_forced     = FALSE,
312         .sender_set_untrusted   = FALSE,
313         .smtp_authenticated     = FALSE,
314 #ifndef DISABLE_PIPE_CONNECT
315         .smtp_in_early_pipe_advertised = FALSE,
316         .smtp_in_early_pipe_no_auth = FALSE,
317         .smtp_in_early_pipe_used = FALSE,
318 #endif
319         .smtp_in_pipelining_advertised = FALSE,
320         .smtp_in_pipelining_used = FALSE,
321         .smtp_in_quit           = FALSE,
322         .spool_file_wireformat  = FALSE,
323         .submission_mode        = FALSE,
324         .suppress_local_fixups  = FALSE,
325         .suppress_local_fixups_default = FALSE,
326         .synchronous_delivery   = FALSE,
327         .system_filtering       = FALSE,
328
329         .taint_check_slow       = FALSE,
330         .testsuite_delays       = TRUE,
331         .tcp_fastopen_ok        = FALSE,
332         .tcp_in_fastopen        = FALSE,
333         .tcp_in_fastopen_data   = FALSE,
334         .tcp_in_fastopen_logged = FALSE,
335         .tcp_out_fastopen_logged= FALSE,
336         .timestamps_utc         = FALSE,
337         .transport_filter_timed_out = FALSE,
338         .trusted_caller         = FALSE,
339         .trusted_config         = TRUE,
340 };
341
342 /******************************************************************************/
343 /* These are the flags which are either variables or mainsection options,
344 so an address is needed for access, or are exported to local_scan. */
345
346 BOOL    accept_8bitmime        = TRUE; /* deliberately not RFC compliant */
347 BOOL    allow_domain_literals  = FALSE;
348 BOOL    allow_mx_to_ip         = FALSE;
349 BOOL    allow_utf8_domains     = FALSE;
350 BOOL    authentication_failed  = FALSE;
351
352 BOOL    bounce_return_body     = TRUE;
353 BOOL    bounce_return_message  = TRUE;
354 BOOL    check_rfc2047_length   = TRUE;
355 BOOL    commandline_checks_require_admin = FALSE;
356
357 #ifdef EXPERIMENTAL_DCC
358 BOOL    dcc_direct_add_header  = FALSE;
359 #endif
360 BOOL    debug_store            = FALSE;
361 BOOL    delivery_date_remove   = TRUE;
362 BOOL    deliver_drop_privilege = FALSE;
363 #ifdef ENABLE_DISABLE_FSYNC
364 BOOL    disable_fsync          = FALSE;
365 #endif
366 BOOL    disable_ipv6           = FALSE;
367 BOOL    dns_csa_use_reverse    = TRUE;
368 BOOL    drop_cr                = FALSE;         /* No longer used */
369
370 BOOL    envelope_to_remove     = TRUE;
371 BOOL    exim_gid_set           = TRUE;          /* This gid is always set */
372 BOOL    exim_uid_set           = TRUE;          /* This uid is always set */
373 BOOL    extract_addresses_remove_arguments = TRUE;
374
375 BOOL    host_checking          = FALSE;
376 BOOL    host_lookup_deferred   = FALSE;
377 BOOL    host_lookup_failed     = FALSE;
378 BOOL    ignore_fromline_local  = FALSE;
379
380 BOOL    local_from_check       = TRUE;
381 BOOL    local_sender_retain    = FALSE;
382 BOOL    log_timezone           = FALSE;
383 BOOL    message_body_newlines  = FALSE;
384 BOOL    message_logs           = TRUE;
385 #ifdef SUPPORT_I18N
386 BOOL    message_smtputf8       = FALSE;
387 #endif
388 BOOL    mua_wrapper            = FALSE;
389
390 BOOL    preserve_message_logs  = FALSE;
391 BOOL    print_topbitchars      = FALSE;
392 BOOL    prod_requires_admin    = TRUE;
393 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
394 BOOL    proxy_session          = FALSE;
395 #endif
396
397 #ifndef DISABLE_QUEUE_RAMP
398 BOOL    queue_fast_ramp         = FALSE;
399 #endif
400 BOOL    queue_list_requires_admin = TRUE;
401 BOOL    queue_only             = FALSE;
402 BOOL    queue_only_load_latch  = TRUE;
403 BOOL    queue_only_override    = TRUE;
404 BOOL    queue_run_in_order     = FALSE;
405 BOOL    recipients_max_reject  = FALSE;
406 BOOL    return_path_remove     = TRUE;
407
408 BOOL    smtp_batched_input     = FALSE;
409 BOOL    sender_helo_dnssec     = FALSE;
410 BOOL    sender_host_dnssec     = FALSE;
411 BOOL    smtp_accept_keepalive  = TRUE;
412 BOOL    smtp_check_spool_space = TRUE;
413 BOOL    smtp_enforce_sync      = TRUE;
414 BOOL    smtp_etrn_serialize    = TRUE;
415 BOOL    smtp_input             = FALSE;
416 BOOL    smtp_return_error_details = FALSE;
417 #ifdef SUPPORT_SPF
418 BOOL    spf_result_guessed     = FALSE;
419 #endif
420 BOOL    split_spool_directory  = FALSE;
421 BOOL    spool_wireformat       = FALSE;
422 #ifdef EXPERIMENTAL_SRS_ALT
423 BOOL    srs_usehash            = TRUE;
424 BOOL    srs_usetimestamp       = TRUE;
425 #endif
426 BOOL    strict_acl_vars        = FALSE;
427 BOOL    strip_excess_angle_brackets = FALSE;
428 BOOL    strip_trailing_dot     = FALSE;
429 BOOL    syslog_duplication     = TRUE;
430 BOOL    syslog_pid             = TRUE;
431 BOOL    syslog_timestamp       = TRUE;
432 BOOL    system_filter_gid_set  = FALSE;
433 BOOL    system_filter_uid_set  = FALSE;
434
435 BOOL    tcp_nodelay            = TRUE;
436 BOOL    write_rejectlog        = TRUE;
437
438 /******************************************************************************/
439
440 header_line *acl_added_headers = NULL;
441 tree_node *acl_anchor          = NULL;
442 uschar *acl_arg[9]             = {NULL, NULL, NULL, NULL, NULL,
443                                   NULL, NULL, NULL, NULL};
444 int     acl_narg               = 0;
445
446 int     acl_level              = 0;
447
448 uschar *acl_not_smtp           = NULL;
449 #ifdef WITH_CONTENT_SCAN
450 uschar *acl_not_smtp_mime      = NULL;
451 #endif
452 uschar *acl_not_smtp_start     = NULL;
453 uschar *acl_removed_headers    = NULL;
454 uschar *acl_smtp_auth          = NULL;
455 uschar *acl_smtp_connect       = NULL;
456 uschar *acl_smtp_data          = NULL;
457 #ifndef DISABLE_PRDR
458 uschar *acl_smtp_data_prdr     = US"accept";
459 #endif
460 #ifndef DISABLE_DKIM
461 uschar *acl_smtp_dkim          = NULL;
462 #endif
463 uschar *acl_smtp_etrn          = NULL;
464 uschar *acl_smtp_expn          = NULL;
465 uschar *acl_smtp_helo          = NULL;
466 uschar *acl_smtp_mail          = NULL;
467 uschar *acl_smtp_mailauth      = NULL;
468 #ifdef WITH_CONTENT_SCAN
469 uschar *acl_smtp_mime          = NULL;
470 #endif
471 uschar *acl_smtp_notquit       = NULL;
472 uschar *acl_smtp_predata       = NULL;
473 uschar *acl_smtp_quit          = NULL;
474 uschar *acl_smtp_rcpt          = NULL;
475 uschar *acl_smtp_starttls      = NULL;
476 uschar *acl_smtp_vrfy          = NULL;
477
478 tree_node *acl_var_c           = NULL;
479 tree_node *acl_var_m           = NULL;
480 uschar *acl_verify_message     = NULL;
481 string_item *acl_warn_logged   = NULL;
482
483 /* Names of SMTP places for use in ACL error messages, and corresponding SMTP
484 error codes - keep in step with definitions of ACL_WHERE_xxxx in macros.h. */
485
486 uschar *acl_wherenames[]       = { US"RCPT",
487                                    US"MAIL",
488                                    US"PREDATA",
489                                    US"MIME",
490                                    US"DKIM",
491                                    US"DATA",
492 #ifndef DISABLE_PRDR
493                                    US"PRDR",
494 #endif
495                                    US"non-SMTP",
496                                    US"AUTH",
497                                    US"connection",
498                                    US"ETRN",
499                                    US"EXPN",
500                                    US"EHLO or HELO",
501                                    US"MAILAUTH",
502                                    US"non-SMTP-start",
503                                    US"NOTQUIT",
504                                    US"QUIT",
505                                    US"STARTTLS",
506                                    US"VRFY",
507                                    US"delivery",
508                                    US"unknown"
509                                  };
510
511 uschar *acl_wherecodes[]       = { US"550",     /* RCPT */
512                                    US"550",     /* MAIL */
513                                    US"550",     /* PREDATA */
514                                    US"550",     /* MIME */
515                                    US"550",     /* DKIM */
516                                    US"550",     /* DATA */
517 #ifndef DISABLE_PRDR
518                                    US"550",    /* RCPT PRDR */
519 #endif
520                                    US"0",       /* not SMTP; not relevant */
521                                    US"503",     /* AUTH */
522                                    US"550",     /* connect */
523                                    US"458",     /* ETRN */
524                                    US"550",     /* EXPN */
525                                    US"550",     /* HELO/EHLO */
526                                    US"0",       /* MAILAUTH; not relevant */
527                                    US"0",       /* not SMTP; not relevant */
528                                    US"0",       /* NOTQUIT; not relevant */
529                                    US"0",       /* QUIT; not relevant */
530                                    US"550",     /* STARTTLS */
531                                    US"252",     /* VRFY */
532                                    US"0",       /* delivery; not relevant */
533                                    US"0"        /* unknown; not relevant */
534                                  };
535
536 uschar *add_environment        = NULL;
537 address_item  *addr_duplicate  = NULL;
538
539 address_item address_defaults = {
540   .next =               NULL,
541   .parent =             NULL,
542   .first =              NULL,
543   .dupof =              NULL,
544   .start_router =       NULL,
545   .router =             NULL,
546   .transport =          NULL,
547   .host_list =          NULL,
548   .host_used =          NULL,
549   .fallback_hosts =     NULL,
550   .reply =              NULL,
551   .retries =            NULL,
552   .address =            NULL,
553   .unique =             NULL,
554   .cc_local_part =      NULL,
555   .lc_local_part =      NULL,
556   .local_part =         NULL,
557   .prefix =             NULL,
558   .prefix_v =           NULL,
559   .suffix =             NULL,
560   .suffix_v =           NULL,
561   .domain =             NULL,
562   .address_retry_key =  NULL,
563   .domain_retry_key =   NULL,
564   .current_dir =        NULL,
565   .home_dir =           NULL,
566   .message =            NULL,
567   .user_message =       NULL,
568   .onetime_parent =     NULL,
569   .pipe_expandn =       NULL,
570   .return_filename =    NULL,
571   .self_hostname =      NULL,
572   .shadow_message =     NULL,
573 #ifndef DISABLE_TLS
574   .cipher =             NULL,
575   .ourcert =            NULL,
576   .peercert =           NULL,
577   .peerdn =             NULL,
578   .ocsp =               OCSP_NOT_REQ,
579 #endif
580 #ifdef EXPERIMENTAL_DSN_INFO
581   .smtp_greeting =      NULL,
582   .helo_response =      NULL,
583 #endif
584   .authenticator =      NULL,
585   .auth_id =            NULL,
586   .auth_sndr =          NULL,
587   .dsn_orcpt =          NULL,
588   .dsn_flags =          0,
589   .dsn_aware =          0,
590   .uid =                (uid_t)(-1),
591   .gid =                (gid_t)(-1),
592   .flags =              { 0 },
593   .domain_cache =       { 0 },                /* domain_cache - any larger array should be zeroed */
594   .localpart_cache =    { 0 },                /* localpart_cache - ditto */
595   .mode =               -1,
596   .more_errno =         0,
597   .delivery_time =      {.tv_sec = 0, .tv_usec = 0},
598   .basic_errno =        ERRNO_UNKNOWNERROR,
599   .child_count =        0,
600   .return_file =        -1,
601   .special_action =     SPECIAL_NONE,
602   .transport_return =   DEFER,
603   .prop = {                                     /* fields that are propagated to children */
604     .address_data =     NULL,
605     .domain_data =      NULL,
606     .localpart_data =   NULL,
607     .errors_address =   NULL,
608     .extra_headers =    NULL,
609     .remove_headers =   NULL,
610     .variables =        NULL,
611 #ifdef EXPERIMENTAL_SRS_ALT
612     .srs_sender =       NULL,
613 #endif
614     .ignore_error =     FALSE,
615 #ifdef SUPPORT_I18N
616     .utf8_msg =         FALSE,
617     .utf8_downcvt =     FALSE,
618     .utf8_downcvt_maybe = FALSE
619 #endif
620   }
621 };
622
623 uschar *address_file           = NULL;
624 uschar *address_pipe           = NULL;
625 tree_node *addresslist_anchor  = NULL;
626 int     addresslist_count      = 0;
627 gid_t  *admin_groups           = NULL;
628
629 #ifdef EXPERIMENTAL_ARC
630 struct arc_set *arc_received    = NULL;
631 int     arc_received_instance   = 0;
632 int     arc_oldest_pass         = 0;
633 const uschar *arc_state         = NULL;
634 const uschar *arc_state_reason  = NULL;
635 #endif
636
637 uschar *authenticated_fail_id  = NULL;
638 uschar *authenticated_id       = NULL;
639 uschar *authenticated_sender   = NULL;
640 auth_instance  *auths          = NULL;
641 uschar *auth_advertise_hosts   = US"*";
642 auth_instance auth_defaults    = {
643     .next =             NULL,
644     .name =             NULL,
645     .info =             NULL,
646     .options_block =    NULL,
647     .driver_name =      NULL,
648     .advertise_condition = NULL,
649     .client_condition = NULL,
650     .public_name =      NULL,
651     .set_id =           NULL,
652     .set_client_id =    NULL,
653     .mail_auth_condition = NULL,
654     .server_debug_string = NULL,
655     .server_condition = NULL,
656     .client =           FALSE,
657     .server =           FALSE,
658     .advertised =       FALSE
659 };
660
661 uschar *auth_defer_msg         = US"reason not recorded";
662 uschar *auth_defer_user_msg    = US"";
663 const uschar *auth_vars[AUTH_VARS];
664 int     auto_thaw              = 0;
665 #ifdef WITH_CONTENT_SCAN
666 int     av_failed              = FALSE; /* boolean but accessed as vtype_int*/
667 uschar *av_scanner             = US"sophie:/var/run/sophie";  /* AV scanner */
668 #endif
669
670 #if BASE_62 == 62
671 uschar *base62_chars=
672     US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";
673 #else
674 uschar *base62_chars= US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ";
675 #endif
676
677 uschar *bi_command             = NULL;
678 uschar *big_buffer             = NULL;
679 int     big_buffer_size        = BIG_BUFFER_SIZE;
680 #ifdef EXPERIMENTAL_BRIGHTMAIL
681 uschar *bmi_alt_location       = NULL;
682 uschar *bmi_base64_tracker_verdict = NULL;
683 uschar *bmi_base64_verdict     = NULL;
684 uschar *bmi_config_file        = US"/opt/brightmail/etc/brightmail.cfg";
685 int     bmi_deliver            = 1;
686 int     bmi_run                = 0;
687 uschar *bmi_verdicts           = NULL;
688 #endif
689 int     bsmtp_transaction_linecount = 0;
690 int     body_8bitmime          = 0;
691 int     body_linecount         = 0;
692 int     body_zerocount         = 0;
693 uschar *bounce_message_file    = NULL;
694 uschar *bounce_message_text    = NULL;
695 uschar *bounce_recipient       = NULL;
696 int     bounce_return_linesize_limit = 998;
697 int     bounce_return_size_limit = 100*1024;
698 uschar *bounce_sender_authentication = NULL;
699
700 uschar *callout_address        = NULL;
701 int     callout_cache_domain_positive_expire = 7*24*60*60;
702 int     callout_cache_domain_negative_expire = 3*60*60;
703 int     callout_cache_positive_expire = 24*60*60;
704 int     callout_cache_negative_expire = 2*60*60;
705 uschar *callout_random_local_part = US"$primary_hostname-$tod_epoch-testing";
706 uschar *check_dns_names_pattern= US"(?i)^(?>(?(1)\\.|())[^\\W](?>[a-z0-9/_-]*[^\\W])?)+(\\.?)$";
707 int     check_log_inodes       = 100;
708 int_eximarith_t check_log_space = 10*1024;      /* 10K Kbyte == 10MB */
709 int     check_spool_inodes     = 100;
710 int_eximarith_t check_spool_space = 10*1024;    /* 10K Kbyte == 10MB */
711
712 uschar *chunking_advertise_hosts = US"*";
713 unsigned chunking_datasize     = 0;
714 unsigned chunking_data_left    = 0;
715 chunking_state_t chunking_state= CHUNKING_NOT_OFFERED;
716 const pcre2_code *regex_CHUNKING     = NULL;
717
718 #ifdef EXPERIMENTAL_ESMTP_LIMITS
719 const pcre2_code *regex_LIMITS        = NULL;
720 #endif
721
722 uschar *client_authenticator   = NULL;
723 uschar *client_authenticated_id = NULL;
724 uschar *client_authenticated_sender = NULL;
725 int     clmacro_count          = 0;
726 uschar *clmacros[MAX_CLMACROS];
727 FILE   *config_file            = NULL;
728 const uschar *config_filename  = NULL;
729 int     config_lineno          = 0;
730 #ifdef CONFIGURE_GROUP
731 gid_t   config_gid             = CONFIGURE_GROUP;
732 #else
733 gid_t   config_gid             = 0;
734 #endif
735 uschar *config_main_filelist   = US CONFIGURE_FILE
736                          "\0<-----------Space to patch configure_filename->";
737 uschar *config_main_filename   = NULL;
738 uschar *config_main_directory  = NULL;
739
740 #ifdef CONFIGURE_OWNER
741 uid_t   config_uid             = CONFIGURE_OWNER;
742 #else
743 uid_t   config_uid             = 0;
744 #endif
745
746 int     connection_max_messages= -1;
747 uschar *continue_proxy_cipher  = NULL;
748 BOOL    continue_proxy_dane    = FALSE;
749 uschar *continue_proxy_sni     = NULL;
750 uschar *continue_hostname      = NULL;
751 uschar *continue_host_address  = NULL;
752 int     continue_sequence      = 1;
753 uschar *continue_transport     = NULL;
754 #ifdef EXPERIMENTAL_ESMTP_LIMITS
755 unsigned continue_limit_mail   = 0;
756 unsigned continue_limit_rcpt   = 0;
757 unsigned continue_limit_rcptdom= 0;
758 #endif
759
760 uschar *csa_status             = NULL;
761 cut_t   cutthrough = {
762   .callout_hold_only =  FALSE,                          /* verify-only: normal delivery */
763   .delivery =           FALSE,                          /* when to attempt */
764   .defer_pass =         FALSE,                          /* on defer: spool locally */
765   .is_tls =             FALSE,                          /* not a TLS conn yet */
766   .cctx =               {.sock = -1},                   /* open connection */
767   .nrcpt =              0,                              /* number of addresses */
768 };
769
770 int     daemon_notifier_fd     = -1;
771 uschar *daemon_smtp_port       = US"smtp";
772 int     daemon_startup_retries = 9;
773 int     daemon_startup_sleep   = 30;
774
775 #ifdef EXPERIMENTAL_DCC
776 uschar *dcc_header             = NULL;
777 uschar *dcc_result             = NULL;
778 uschar *dccifd_address         = US"/usr/local/dcc/var/dccifd";
779 uschar *dccifd_options         = US"header";
780 #endif
781
782 int     debug_fd               = -1;
783 FILE   *debug_file             = NULL;
784 int     debug_notall[]         = {
785   Di_memory,
786   Di_noutf8,
787   -1
788 };
789 bit_table debug_options[]      = { /* must be in alphabetical order and use
790                                  only the enum values from macro.h */
791   BIT_TABLE(D, acl),
792   BIT_TABLE(D, all),
793   BIT_TABLE(D, auth),
794   BIT_TABLE(D, deliver),
795   BIT_TABLE(D, dns),
796   BIT_TABLE(D, dnsbl),
797   BIT_TABLE(D, exec),
798   BIT_TABLE(D, expand),
799   BIT_TABLE(D, filter),
800   BIT_TABLE(D, hints_lookup),
801   BIT_TABLE(D, host_lookup),
802   BIT_TABLE(D, ident),
803   BIT_TABLE(D, interface),
804   BIT_TABLE(D, lists),
805   BIT_TABLE(D, load),
806   BIT_TABLE(D, local_scan),
807   BIT_TABLE(D, lookup),
808   BIT_TABLE(D, memory),
809   BIT_TABLE(D, noutf8),
810   BIT_TABLE(D, pid),
811   BIT_TABLE(D, process_info),
812   BIT_TABLE(D, queue_run),
813   BIT_TABLE(D, receive),
814   BIT_TABLE(D, resolver),
815   BIT_TABLE(D, retry),
816   BIT_TABLE(D, rewrite),
817   BIT_TABLE(D, route),
818   BIT_TABLE(D, timestamp),
819   BIT_TABLE(D, tls),
820   BIT_TABLE(D, transport),
821   BIT_TABLE(D, uid),
822   BIT_TABLE(D, verify),
823 };
824 int     debug_options_count    = nelem(debug_options);
825
826 unsigned int debug_selector    = 0;
827 int     delay_warning[DELAY_WARNING_SIZE] = { DELAY_WARNING_SIZE, 1, 24*60*60 };
828 uschar *delay_warning_condition=
829   US"${if or {"
830             "{ !eq{$h_list-id:$h_list-post:$h_list-subscribe:}{} }"
831             "{ match{$h_precedence:}{(?i)bulk|list|junk} }"
832             "{ match{$h_auto-submitted:}{(?i)auto-generated|auto-replied} }"
833             "} {no}{yes}}";
834 uschar *deliver_address_data   = NULL;
835 int     deliver_datafile       = -1;
836 const uschar *deliver_domain   = NULL;
837 uschar *deliver_domain_data    = NULL;
838 const uschar *deliver_domain_orig = NULL;
839 const uschar *deliver_domain_parent = NULL;
840 time_t  deliver_frozen_at      = 0;
841 uschar *deliver_home           = NULL;
842 const uschar *deliver_host     = NULL;
843 const uschar *deliver_host_address = NULL;
844 int     deliver_host_port      = 0;
845 uschar *deliver_in_buffer      = NULL;
846 ino_t   deliver_inode          = 0;
847 uschar *deliver_localpart      = NULL;
848 uschar *deliver_localpart_data = NULL;
849 uschar *deliver_localpart_orig = NULL;
850 uschar *deliver_localpart_parent = NULL;
851 uschar *deliver_localpart_prefix = NULL;
852 uschar *deliver_localpart_prefix_v = NULL;
853 uschar *deliver_localpart_suffix = NULL;
854 uschar *deliver_localpart_suffix_v = NULL;
855 uschar *deliver_out_buffer     = NULL;
856 int     deliver_queue_load_max = -1;
857 address_item  *deliver_recipients = NULL;
858 uschar *deliver_selectstring   = NULL;
859 uschar *deliver_selectstring_sender = NULL;
860
861 #ifndef DISABLE_DKIM
862 unsigned dkim_collect_input      = 0;
863 uschar *dkim_cur_signer          = NULL;
864 int     dkim_key_length          = 0;
865 void   *dkim_signatures          = NULL;
866 uschar *dkim_signers             = NULL;
867 uschar *dkim_signing_domain      = NULL;
868 uschar *dkim_signing_selector    = NULL;
869 uschar *dkim_verify_hashes       = US"sha256:sha512";
870 uschar *dkim_verify_keytypes     = US"ed25519:rsa";
871 uschar *dkim_verify_min_keysizes = US"rsa=1024 ed25519=250";
872 BOOL    dkim_verify_minimal      = FALSE;
873 uschar *dkim_verify_overall      = NULL;
874 uschar *dkim_verify_signers      = US"$dkim_signers";
875 uschar *dkim_verify_status       = NULL;
876 uschar *dkim_verify_reason       = NULL;
877 #endif
878 #ifdef SUPPORT_DMARC
879 uschar *dmarc_domain_policy     = NULL;
880 uschar *dmarc_forensic_sender   = NULL;
881 uschar *dmarc_history_file      = NULL;
882 uschar *dmarc_status            = NULL;
883 uschar *dmarc_status_text       = NULL;
884 uschar *dmarc_tld_file          = NULL;
885 uschar *dmarc_used_domain       = NULL;
886 #endif
887
888 uschar *dns_again_means_nonexist = NULL;
889 int     dns_csa_search_limit   = 5;
890 int     dns_cname_loops        = 1;
891 #ifdef SUPPORT_DANE
892 int     dns_dane_ok            = -1;
893 #endif
894 uschar *dns_ipv4_lookup        = NULL;
895 int     dns_retrans            = 0;
896 int     dns_retry              = 0;
897 int     dns_dnssec_ok          = -1; /* <0 = not coerced */
898 uschar *dns_trust_aa           = NULL;
899 int     dns_use_edns0          = -1; /* <0 = not coerced */
900 uschar *dnslist_domain         = NULL;
901 uschar *dnslist_matched        = NULL;
902 uschar *dnslist_text           = NULL;
903 uschar *dnslist_value          = NULL;
904 tree_node *domainlist_anchor   = NULL;
905 int     domainlist_count       = 0;
906 uschar *dsn_from               = US DEFAULT_DSN_FROM;
907
908 int     errno_quota            = ERRNO_QUOTA;
909 uschar *errors_copy            = NULL;
910 int     error_handling         = ERRORS_SENDER;
911 uschar *errors_reply_to        = NULL;
912 int     errors_sender_rc       = EXIT_FAILURE;
913 #ifndef DISABLE_EVENT
914 uschar *event_action             = NULL;        /* expansion for delivery events */
915 uschar *event_data               = NULL;        /* auxiliary data variable for event */
916 int     event_defer_errno        = 0;
917 const uschar *event_name         = NULL;        /* event name variable */
918 #endif
919
920
921 gid_t   exim_gid               = EXIM_GID;
922 uschar *exim_path              = US BIN_DIRECTORY "/exim"
923                         "\0<---------------Space to patch exim_path->";
924 uid_t   exim_uid               = EXIM_UID;
925 int     expand_level           = 0;             /* Nesting depth, indent for debug */
926 int     expand_forbid          = 0;
927 int     expand_nlength[EXPAND_MAXN+1];
928 int     expand_nmax            = -1;
929 const uschar *expand_nstring[EXPAND_MAXN+1];
930 uschar *expand_string_message;
931 uschar *extra_local_interfaces = NULL;
932
933 int     fake_response          = OK;
934 uschar *fake_response_text     = US"Your message has been rejected but is "
935                                    "being kept for evaluation.\nIf it was a "
936                                    "legitimate message, it may still be "
937                                    "delivered to the target recipient(s).";
938 int     filter_n[FILTER_VARIABLE_COUNT];
939 int     filter_sn[FILTER_VARIABLE_COUNT];
940 int     filter_test            = FTEST_NONE;
941 uschar *filter_test_sfile      = NULL;
942 uschar *filter_test_ufile      = NULL;
943 uschar *filter_thisaddress     = NULL;
944 int     finduser_retries       = 0;
945 uid_t   fixed_never_users[]    = { FIXED_NEVER_USERS };
946 uschar *freeze_tell            = NULL;
947 uschar *freeze_tell_config     = NULL;
948 uschar *fudged_queue_times     = US"";
949
950 uschar *gecos_name             = NULL;
951 uschar *gecos_pattern          = NULL;
952 rewrite_rule  *global_rewrite_rules = NULL;
953
954 volatile sig_atomic_t had_command_timeout = 0;
955 volatile sig_atomic_t had_command_sigterm = 0;
956 volatile sig_atomic_t had_data_timeout    = 0;
957 volatile sig_atomic_t had_data_sigint     = 0;
958 const uschar *headers_charset  = US HEADERS_CHARSET;
959 int     header_insert_maxlen   = 64 * 1024;
960 header_line  *header_last      = NULL;
961 header_line  *header_list      = NULL;
962 int     header_maxsize         = HEADER_MAXSIZE;
963 int     header_line_maxsize    = 0;
964
965 header_name header_names[] = {
966   /* name               len     allow_resent    htype */
967   { US"bcc",            3,      TRUE,           htype_bcc },
968   { US"cc",             2,      TRUE,           htype_cc },
969   { US"date",           4,      TRUE,           htype_date },
970   { US"delivery-date", 13,      FALSE,          htype_delivery_date },
971   { US"envelope-to",   11,      FALSE,          htype_envelope_to },
972   { US"from",           4,      TRUE,           htype_from },
973   { US"message-id",    10,      TRUE,           htype_id },
974   { US"received",       8,      FALSE,          htype_received },
975   { US"reply-to",       8,      FALSE,          htype_reply_to },
976   { US"return-path",   11,      FALSE,          htype_return_path },
977   { US"sender",         6,      TRUE,           htype_sender },
978   { US"subject",        7,      FALSE,          htype_subject },
979   { US"to",             2,      TRUE,           htype_to }
980 };
981
982 int header_names_size          = nelem(header_names);
983
984 uschar *helo_accept_junk_hosts = NULL;
985 uschar *helo_allow_chars       = US"";
986 uschar *helo_lookup_domains    = US"@ : @[]";
987 uschar *helo_try_verify_hosts  = NULL;
988 uschar *helo_verify_hosts      = NULL;
989 const uschar *hex_digits       = CUS"0123456789abcdef";
990 uschar *hold_domains           = NULL;
991 uschar *host_data              = NULL;
992 uschar *host_lookup            = NULL;
993 uschar *host_lookup_order      = US"bydns:byaddr";
994 uschar *host_lookup_msg        = US"";
995 int     host_number            = 0;
996 uschar *host_number_string     = NULL;
997 uschar *host_reject_connection = NULL;
998 tree_node *hostlist_anchor     = NULL;
999 int     hostlist_count         = 0;
1000 uschar *hosts_treat_as_local   = NULL;
1001 uschar *hosts_require_helo     = US"*";
1002 uschar *hosts_connection_nolog = NULL;
1003
1004 int     ignore_bounce_errors_after = 10*7*24*60*60;  /* 10 weeks */
1005 uschar *ignore_fromline_hosts  = NULL;
1006 int     inetd_wait_timeout     = -1;
1007 uschar *initial_cwd            = NULL;
1008 uschar *interface_address      = NULL;
1009 int     interface_port         = -1;
1010 uschar *iterate_item           = NULL;
1011
1012 int     journal_fd             = -1;
1013
1014 uschar *keep_environment       = NULL;
1015
1016 int     keep_malformed         = 4*24*60*60;    /* 4 days */
1017
1018 uschar *eldap_dn               = NULL;
1019 #ifdef EXPERIMENTAL_ESMTP_LIMITS
1020 uschar *limits_advertise_hosts = US"*";
1021 #endif
1022 int     load_average           = -2;
1023 uschar *local_from_prefix      = NULL;
1024 uschar *local_from_suffix      = NULL;
1025
1026 #if HAVE_IPV6
1027 uschar *local_interfaces       = US"<; ::0 ; 0.0.0.0";
1028 #else
1029 uschar *local_interfaces       = US"0.0.0.0";
1030 #endif
1031
1032 #ifdef HAVE_LOCAL_SCAN
1033 uschar *local_scan_data        = NULL;
1034 int     local_scan_timeout     = 5*60;
1035 #endif
1036 gid_t   local_user_gid         = (gid_t)(-1);
1037 uid_t   local_user_uid         = (uid_t)(-1);
1038
1039 tree_node *localpartlist_anchor= NULL;
1040 int     localpartlist_count    = 0;
1041 uschar *log_buffer             = NULL;
1042
1043 int     log_default[]          = { /* for initializing log_selector */
1044   Li_acl_warn_skipped,
1045   Li_connection_reject,
1046   Li_delay_delivery,
1047   Li_dkim,
1048   Li_dnslist_defer,
1049   Li_etrn,
1050   Li_host_lookup_failed,
1051   Li_lost_incoming_connection,
1052   Li_outgoing_interface, /* see d_log_interface in deliver.c */
1053   Li_msg_id,
1054   Li_queue_run,
1055   Li_queue_time_exclusive,
1056   Li_rejected_header,
1057   Li_retry_defer,
1058   Li_sender_verify_fail,
1059   Li_size_reject,
1060   Li_skip_delivery,
1061   Li_smtp_confirmation,
1062 #ifdef ALLOW_INSECURE_TAINTED_DATA
1063   Li_tainted,
1064 #endif
1065   Li_tls_certificate_verified,
1066   Li_tls_cipher,
1067   -1
1068 };
1069
1070 uschar *log_file_path          = US LOG_FILE_PATH
1071                            "\0<--------------Space to patch log_file_path->";
1072
1073 int     log_notall[]           = {
1074   -1
1075 };
1076 bit_table log_options[]        = { /* must be in alphabetical order,
1077                                 with definitions from enum logbit. */
1078   BIT_TABLE(L, 8bitmime),
1079   BIT_TABLE(L, acl_warn_skipped),
1080   BIT_TABLE(L, address_rewrite),
1081   BIT_TABLE(L, all),
1082   BIT_TABLE(L, all_parents),
1083   BIT_TABLE(L, arguments),
1084   BIT_TABLE(L, connection_reject),
1085   BIT_TABLE(L, delay_delivery),
1086   BIT_TABLE(L, deliver_time),
1087   BIT_TABLE(L, delivery_size),
1088 #ifndef DISABLE_DKIM
1089   BIT_TABLE(L, dkim),
1090   BIT_TABLE(L, dkim_verbose),
1091 #endif
1092   BIT_TABLE(L, dnslist_defer),
1093   BIT_TABLE(L, dnssec),
1094   BIT_TABLE(L, etrn),
1095   BIT_TABLE(L, host_lookup_failed),
1096   BIT_TABLE(L, ident_timeout),
1097   BIT_TABLE(L, incoming_interface),
1098   BIT_TABLE(L, incoming_port),
1099   BIT_TABLE(L, lost_incoming_connection),
1100   BIT_TABLE(L, millisec),
1101   BIT_TABLE(L, msg_id),
1102   BIT_TABLE(L, msg_id_created),
1103   BIT_TABLE(L, outgoing_interface),
1104   BIT_TABLE(L, outgoing_port),
1105   BIT_TABLE(L, pid),
1106   BIT_TABLE(L, pipelining),
1107   BIT_TABLE(L, protocol_detail),
1108 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1109   BIT_TABLE(L, proxy),
1110 #endif
1111   BIT_TABLE(L, queue_run),
1112   BIT_TABLE(L, queue_time),
1113   BIT_TABLE(L, queue_time_exclusive),
1114   BIT_TABLE(L, queue_time_overall),
1115   BIT_TABLE(L, receive_time),
1116   BIT_TABLE(L, received_recipients),
1117   BIT_TABLE(L, received_sender),
1118   BIT_TABLE(L, rejected_header),
1119   { US"rejected_headers", Li_rejected_header },
1120   BIT_TABLE(L, retry_defer),
1121   BIT_TABLE(L, return_path_on_delivery),
1122   BIT_TABLE(L, sender_on_delivery),
1123   BIT_TABLE(L, sender_verify_fail),
1124   BIT_TABLE(L, size_reject),
1125   BIT_TABLE(L, skip_delivery),
1126   BIT_TABLE(L, smtp_confirmation),
1127   BIT_TABLE(L, smtp_connection),
1128   BIT_TABLE(L, smtp_incomplete_transaction),
1129   BIT_TABLE(L, smtp_mailauth),
1130   BIT_TABLE(L, smtp_no_mail),
1131   BIT_TABLE(L, smtp_protocol_error),
1132   BIT_TABLE(L, smtp_syntax_error),
1133   BIT_TABLE(L, subject),
1134 #ifdef ALLOW_INSECURE_TAINTED_DATA
1135   BIT_TABLE(L, tainted),
1136 #endif
1137   BIT_TABLE(L, tls_certificate_verified),
1138   BIT_TABLE(L, tls_cipher),
1139   BIT_TABLE(L, tls_peerdn),
1140   BIT_TABLE(L, tls_resumption),
1141   BIT_TABLE(L, tls_sni),
1142   BIT_TABLE(L, unknown_in_list),
1143 };
1144 int     log_options_count      = nelem(log_options);
1145
1146 int     log_reject_target      = 0;
1147 unsigned int log_selector[log_selector_size]; /* initialized in main() */
1148 uschar *log_selector_string    = NULL;
1149 FILE   *log_stderr             = NULL;
1150 uschar *login_sender_address   = NULL;
1151 uschar *lookup_dnssec_authenticated = NULL;
1152 int     lookup_open_max        = 25;
1153 uschar *lookup_value           = NULL;
1154
1155 macro_item *macros_user        = NULL;
1156 uschar *mailstore_basename     = NULL;
1157 #ifdef WITH_CONTENT_SCAN
1158 uschar *malware_name           = NULL;  /* Virus Name */
1159 #endif
1160 int     max_received_linelength= 0;
1161 int     max_username_length    = 0;
1162 int     message_age            = 0;
1163 uschar *message_body           = NULL;
1164 uschar *message_body_end       = NULL;
1165 int     message_body_size      = 0;
1166 int     message_body_visible   = 500;
1167 int     message_ended          = END_NOTSTARTED;
1168 uschar *message_headers        = NULL;
1169 uschar *message_id;
1170 uschar *message_id_domain      = NULL;
1171 uschar *message_id_text        = NULL;
1172 uschar  message_id_option[MESSAGE_ID_LENGTH + 3];
1173 uschar *message_id_external;
1174 int     message_linecount      = 0;
1175 int     message_size           = 0;
1176 uschar *message_size_limit     = US"50M";
1177 #ifdef SUPPORT_I18N
1178 int     message_utf8_downconvert = 0;   /* -1 ifneeded; 0 never; 1 always */
1179 #endif
1180 uschar  message_subdir[2]      = { 0, 0 };
1181 uschar *message_reference      = NULL;
1182
1183 /* MIME ACL expandables */
1184 #ifdef WITH_CONTENT_SCAN
1185 int     mime_anomaly_level     = 0;
1186 const uschar *mime_anomaly_text      = NULL;
1187 uschar *mime_boundary          = NULL;
1188 uschar *mime_charset           = NULL;
1189 uschar *mime_content_description = NULL;
1190 uschar *mime_content_disposition = NULL;
1191 uschar *mime_content_id        = NULL;
1192 unsigned int mime_content_size = 0;
1193 uschar *mime_content_transfer_encoding = NULL;
1194 uschar *mime_content_type      = NULL;
1195 uschar *mime_decoded_filename  = NULL;
1196 uschar *mime_filename          = NULL;
1197 int     mime_is_multipart      = 0;
1198 int     mime_is_coverletter    = 0;
1199 int     mime_is_rfc822         = 0;
1200 int     mime_part_count        = -1;
1201 #endif
1202
1203 uid_t  *never_users            = NULL;
1204 uschar *notifier_socket        = US"$spool_directory/" NOTIFIER_SOCKET_NAME ;
1205
1206 const int on                   = 1;     /* for setsockopt */
1207 const int off                  = 0;
1208
1209 uid_t   original_euid;
1210 gid_t   originator_gid;
1211 uschar *originator_login       = NULL;
1212 uschar *originator_name        = NULL;
1213 uid_t   originator_uid;
1214 uschar *override_local_interfaces = NULL;
1215 uschar *override_pid_file_path = NULL;
1216
1217 pcre2_general_context * pcre_gen_ctx = NULL;
1218 pcre2_compile_context * pcre_cmp_ctx = NULL;
1219 pcre2_match_context * pcre_mtc_ctx = NULL;
1220
1221 uschar *percent_hack_domains   = NULL;
1222 uschar *pid_file_path          = US PID_FILE_PATH
1223                            "\0<--------------Space to patch pid_file_path->";
1224 #ifndef DISABLE_PIPE_CONNECT
1225 uschar *pipe_connect_advertise_hosts = US"*";
1226 #endif
1227 uschar *pipelining_advertise_hosts = US"*";
1228 uschar *primary_hostname       = NULL;
1229 uschar *process_info;
1230 int     process_info_len       = 0;
1231 uschar *process_log_path       = NULL;
1232 const uschar *process_purpose  = US"fresh-exec";
1233
1234 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1235 uschar *hosts_proxy            = NULL;
1236 uschar *proxy_external_address = NULL;
1237 int     proxy_external_port    = 0;
1238 uschar *proxy_local_address    = NULL;
1239 int     proxy_local_port       = 0;
1240 int     proxy_protocol_timeout = 3;
1241 #endif
1242
1243 uschar *prvscheck_address      = NULL;
1244 uschar *prvscheck_keynum       = NULL;
1245 uschar *prvscheck_result       = NULL;
1246
1247
1248 const uschar *qualify_domain_recipient = NULL;
1249 uschar *qualify_domain_sender  = NULL;
1250 uschar *queue_domains          = NULL;
1251 int     queue_interval         = -1;
1252 uschar *queue_name             = US"";
1253 uschar *queue_name_dest        = NULL;
1254 uschar *queue_only_file        = NULL;
1255 int     queue_only_load        = -1;
1256 uschar *queue_run_max          = US"5";
1257 pid_t   queue_run_pid          = (pid_t)0;
1258 int     queue_run_pipe         = -1;
1259 unsigned queue_size            = 0;
1260 time_t  queue_size_next        = 0;
1261 uschar *queue_smtp_domains     = NULL;
1262
1263 uint32_t random_seed           = 0;
1264 tree_node *ratelimiters_cmd    = NULL;
1265 tree_node *ratelimiters_conn   = NULL;
1266 tree_node *ratelimiters_mail   = NULL;
1267 uschar *raw_active_hostname    = NULL;
1268 uschar *raw_sender             = NULL;
1269 uschar **raw_recipients        = NULL;
1270 int     raw_recipients_count   = 0;
1271
1272 int     rcpt_count             = 0;
1273 int     rcpt_fail_count        = 0;
1274 int     rcpt_defer_count       = 0;
1275 gid_t   real_gid;
1276 uid_t   real_uid;
1277 int     receive_linecount      = 0;
1278 int     receive_messagecount   = 0;
1279 int     receive_timeout        = 0;
1280 int     received_count         = 0;
1281 uschar *received_for           = NULL;
1282
1283 /*  This is the default text for Received headers generated by Exim. The
1284 date  will be automatically added on the end. */
1285
1286 uschar *received_header_text   = US
1287      "Received: "
1288      "${if def:sender_rcvhost {from $sender_rcvhost\n\t}"
1289        "{${if def:sender_ident {from ${quote_local_part:$sender_ident} }}"
1290          "${if def:sender_helo_name {(helo=$sender_helo_name)\n\t}}}}"
1291      "by $primary_hostname "
1292      "${if def:received_protocol {with $received_protocol }}"
1293 #ifndef DISABLE_TLS
1294      "${if def:tls_in_ver        { ($tls_in_ver)}}"
1295      "${if def:tls_in_cipher_std { tls $tls_in_cipher_std\n\t}}"
1296 #endif
1297      "(Exim $version_number)\n\t"
1298      "${if def:sender_address {(envelope-from <$sender_address>)\n\t}}"
1299      "id $message_exim_id"
1300      "${if def:received_for {\n\tfor $received_for}}"
1301      "\0<---------------Space to patch received_header_text->";
1302
1303 int     received_headers_max   = 30;
1304 uschar *received_protocol      = NULL;
1305 struct timeval received_time   = { 0, 0 };
1306 struct timeval received_time_complete = { 0, 0 };
1307 uschar *recipient_data         = NULL;
1308 uschar *recipient_unqualified_hosts = NULL;
1309 uschar *recipient_verify_failure = NULL;
1310 int     recipients_count       = 0;
1311 recipient_item  *recipients_list = NULL;
1312 int     recipients_list_max    = 0;
1313 int     recipients_max         = 50000;
1314 const pcre2_code *regex_AUTH         = NULL;
1315 const pcre2_code *regex_check_dns_names = NULL;
1316 const pcre2_code *regex_From         = NULL;
1317 const pcre2_code *regex_IGNOREQUOTA  = NULL;
1318 const pcre2_code *regex_PIPELINING   = NULL;
1319 const pcre2_code *regex_SIZE         = NULL;
1320 #ifndef DISABLE_PIPE_CONNECT
1321 const pcre2_code *regex_EARLY_PIPE   = NULL;
1322 #endif
1323 const pcre2_code *regex_ismsgid      = NULL;
1324 const pcre2_code *regex_smtp_code    = NULL;
1325 const uschar *regex_vars[REGEX_VARS];
1326 #ifdef WHITELIST_D_MACROS
1327 const pcre2_code *regex_whitelisted_macro = NULL;
1328 #endif
1329 #ifdef WITH_CONTENT_SCAN
1330 uschar *regex_match_string     = NULL;
1331 #endif
1332 int     remote_delivery_count  = 0;
1333 int     remote_max_parallel    = 2;
1334 uschar *remote_sort_domains    = NULL;
1335 int     retry_data_expire      = 7*24*60*60;
1336 int     retry_interval_max     = 24*60*60;
1337 int     retry_maximum_timeout  = 0;        /* set from retry config */
1338 retry_config  *retries         = NULL;
1339 uschar *return_path            = NULL;
1340 int     rewrite_existflags     = 0;
1341 uschar *rfc1413_hosts          = US"@[]";
1342 int     rfc1413_query_timeout  = 0;
1343 uid_t   root_gid               = ROOT_GID;
1344 uid_t   root_uid               = ROOT_UID;
1345
1346 router_instance  *routers  = NULL;
1347 router_instance  router_defaults = {
1348     .next =                     NULL,
1349     .name =                     NULL,
1350     .info =                     NULL,
1351     .options_block =            NULL,
1352     .driver_name =              NULL,
1353
1354     .address_data =             NULL,
1355 #ifdef EXPERIMENTAL_BRIGHTMAIL
1356     .bmi_rule =                 NULL,
1357 #endif
1358     .cannot_route_message =     NULL,
1359     .condition =                NULL,
1360     .current_directory =        NULL,
1361     .debug_string =             NULL,
1362     .domains =                  NULL,
1363     .errors_to =                NULL,
1364     .expand_gid =               NULL,
1365     .expand_uid =               NULL,
1366     .expand_more =              NULL,
1367     .expand_unseen =            NULL,
1368     .extra_headers =            NULL,
1369     .fallback_hosts =           NULL,
1370     .home_directory =           NULL,
1371     .ignore_target_hosts =      NULL,
1372     .local_parts =              NULL,
1373     .pass_router_name =         NULL,
1374     .prefix =                   NULL,
1375     .redirect_router_name =     NULL,
1376     .remove_headers =           NULL,
1377     .require_files =            NULL,
1378     .router_home_directory =    NULL,
1379     .self =                     US"freeze",
1380     .senders =                  NULL,
1381     .suffix =                   NULL,
1382     .translate_ip_address =     NULL,
1383     .transport_name =           NULL,
1384
1385     .address_test =             TRUE,
1386 #ifdef EXPERIMENTAL_BRIGHTMAIL
1387     .bmi_deliver_alternate =    FALSE,
1388     .bmi_deliver_default =      FALSE,
1389     .bmi_dont_deliver =         FALSE,
1390 #endif
1391     .expn =                     TRUE,
1392     .caseful_local_part =       FALSE,
1393     .check_local_user =         FALSE,
1394     .disable_logging =          FALSE,
1395     .fail_verify_recipient =    FALSE,
1396     .fail_verify_sender =       FALSE,
1397     .gid_set =                  FALSE,
1398     .initgroups =               FALSE,
1399     .log_as_local =             TRUE_UNSET,
1400     .more =                     TRUE,
1401     .pass_on_timeout =          FALSE,
1402     .prefix_optional =          FALSE,
1403     .repeat_use =               TRUE,
1404     .retry_use_local_part =     TRUE_UNSET,
1405     .same_domain_copy_routing = FALSE,
1406     .self_rewrite =             FALSE,
1407     .set =                      NULL,
1408     .suffix_optional =          FALSE,
1409     .verify_only =              FALSE,
1410     .verify_recipient =         TRUE,
1411     .verify_sender =            TRUE,
1412     .uid_set =                  FALSE,
1413     .unseen =                   FALSE,
1414     .dsn_lasthop =              FALSE,
1415
1416     .self_code =                self_freeze,
1417     .uid =                      (uid_t)(-1),
1418     .gid =                      (gid_t)(-1),
1419
1420     .fallback_hostlist =        NULL,
1421     .transport =                NULL,
1422     .pass_router =              NULL,
1423     .redirect_router =          NULL,
1424
1425     .dnssec =                   { .request= US"*", .require=NULL },
1426 };
1427
1428 uschar *router_name            = NULL;
1429 tree_node *router_var          = NULL;
1430
1431 ip_address_item *running_interfaces = NULL;
1432
1433 /* This is a weird one. The following string gets patched in the binary by the
1434 script that sets up a copy of Exim for running in the test harness. It seems
1435 that compilers are now clever, and share constant strings if they can.
1436 Elsewhere in Exim the string "<" is used. The compiler optimization seems to
1437 make use of the end of this string in order to save space. So the patching then
1438 wrecks this. We defeat this optimization by adding some additional characters
1439 onto the end of the string. */
1440
1441 uschar *running_status         = US">>>running<<<" "\0EXTRA";
1442
1443 int     runrc                  = 0;
1444
1445 uschar *search_error_message   = NULL;
1446 uschar *self_hostname          = NULL;
1447 uschar *sender_address         = NULL;
1448 unsigned int sender_address_cache[(MAX_NAMED_LIST * 2)/32];
1449 uschar *sender_address_data    = NULL;
1450 uschar *sender_address_unrewritten = NULL;
1451 uschar *sender_data            = NULL;
1452 unsigned int sender_domain_cache[(MAX_NAMED_LIST * 2)/32];
1453 uschar *sender_fullhost        = NULL;
1454 uschar *sender_helo_name       = NULL;
1455 uschar **sender_host_aliases   = &no_aliases;
1456 uschar *sender_host_address    = NULL;
1457 uschar *sender_host_authenticated = NULL;
1458 uschar *sender_host_auth_pubname  = NULL;
1459 unsigned int sender_host_cache[(MAX_NAMED_LIST * 2)/32];
1460 uschar *sender_host_name       = NULL;
1461 int     sender_host_port       = 0;
1462 uschar *sender_ident           = NULL;
1463 uschar *sender_rate            = NULL;
1464 uschar *sender_rate_limit      = NULL;
1465 uschar *sender_rate_period     = NULL;
1466 uschar *sender_rcvhost         = NULL;
1467 uschar *sender_unqualified_hosts = NULL;
1468 uschar *sender_verify_failure = NULL;
1469 address_item *sender_verified_list  = NULL;
1470 address_item *sender_verified_failed = NULL;
1471 int     sender_verified_rc     = -1;
1472 uschar *sending_ip_address     = NULL;
1473 int     sending_port           = -1;
1474 SIGNAL_BOOL sigalrm_seen       = FALSE;
1475 const uschar *sigalarm_setter  = NULL;
1476 uschar **sighup_argv           = NULL;
1477 int     slow_lookup_log        = 0;     /* millisecs, zero disables */
1478 int     smtp_accept_count      = 0;
1479 int     smtp_accept_max        = 20;
1480 int     smtp_accept_max_nonmail= 10;
1481 uschar *smtp_accept_max_nonmail_hosts = US"*";
1482 uschar *smtp_accept_max_per_connection = US"1000";
1483 uschar *smtp_accept_max_per_host = NULL;
1484 int     smtp_accept_queue      = 0;
1485 int     smtp_accept_queue_per_connection = 10;
1486 int     smtp_accept_reserve    = 0;
1487 uschar *smtp_active_hostname   = NULL;
1488 int     smtp_backlog_monitor   = 0;
1489 uschar *smtp_banner            = US"$smtp_active_hostname ESMTP "
1490                              "Exim $version_number $tod_full"
1491                              "\0<---------------Space to patch smtp_banner->";
1492 int     smtp_ch_index          = 0;
1493 uschar *smtp_cmd_argument      = NULL;
1494 uschar *smtp_cmd_buffer        = NULL;
1495 struct timeval smtp_connection_start  = {0,0};
1496 uschar  smtp_connection_had[SMTP_HBUFF_SIZE];
1497 int     smtp_connect_backlog   = 20;
1498 double  smtp_delay_mail        = 0.0;
1499 double  smtp_delay_rcpt        = 0.0;
1500 FILE   *smtp_in                = NULL;
1501 int     smtp_listen_backlog    = 0;
1502 int     smtp_load_reserve      = -1;
1503 int     smtp_mailcmd_count     = 0;
1504 int     smtp_mailcmd_max       = -1;
1505 FILE   *smtp_out               = NULL;
1506 uschar *smtp_etrn_command      = NULL;
1507 int     smtp_max_synprot_errors= 3;
1508 int     smtp_max_unknown_commands = 3;
1509 uschar *smtp_notquit_reason    = NULL;
1510 unsigned smtp_peer_options     = 0;
1511 unsigned smtp_peer_options_wrap= 0;
1512 uschar *smtp_ratelimit_hosts   = NULL;
1513 uschar *smtp_ratelimit_mail    = NULL;
1514 uschar *smtp_ratelimit_rcpt    = NULL;
1515 uschar *smtp_read_error        = US"";
1516 int     smtp_receive_timeout   = 5*60;
1517 uschar *smtp_receive_timeout_s = NULL;
1518 uschar *smtp_reserve_hosts     = NULL;
1519 int     smtp_rlm_base          = 0;
1520 double  smtp_rlm_factor        = 0.0;
1521 int     smtp_rlm_limit         = 0;
1522 int     smtp_rlm_threshold     = INT_MAX;
1523 int     smtp_rlr_base          = 0;
1524 double  smtp_rlr_factor        = 0.0;
1525 int     smtp_rlr_limit         = 0;
1526 int     smtp_rlr_threshold     = INT_MAX;
1527 #ifdef SUPPORT_I18N
1528 uschar *smtputf8_advertise_hosts = US"*";       /* overridden under test-harness */
1529 #endif
1530
1531 #ifdef WITH_CONTENT_SCAN
1532 uschar *spamd_address          = US"127.0.0.1 783";
1533 uschar *spam_bar               = NULL;
1534 uschar *spam_report            = NULL;
1535 uschar *spam_action            = NULL;
1536 uschar *spam_score             = NULL;
1537 uschar *spam_score_int         = NULL;
1538 #endif
1539 #ifdef SUPPORT_SPF
1540 uschar *spf_guess              = US"v=spf1 a/24 mx/24 ptr ?all";
1541 uschar *spf_header_comment     = NULL;
1542 uschar *spf_received           = NULL;
1543 uschar *spf_result             = NULL;
1544 uschar *spf_smtp_comment       = NULL;
1545 uschar *spf_smtp_comment_template
1546                     /* Used to be: "Please%_see%_http://www.open-spf.org/Why?id=%{S}&ip=%{C}&receiver=%{R}" */
1547                                = US"Please%_see%_http://www.open-spf.org/Why";
1548
1549 #endif
1550
1551 FILE   *spool_data_file        = NULL;
1552 uschar *spool_directory        = US SPOOL_DIRECTORY
1553                            "\0<--------------Space to patch spool_directory->";
1554 #ifdef EXPERIMENTAL_SRS_ALT
1555 uschar *srs_config             = NULL;
1556 uschar *srs_db_address         = NULL;
1557 uschar *srs_db_key             = NULL;
1558 int     srs_hashlength         = 6;
1559 int     srs_hashmin            = -1;
1560 int     srs_maxage             = 31;
1561 uschar *srs_orig_recipient     = NULL;
1562 uschar *srs_orig_sender        = NULL;
1563 uschar *srs_recipient          = NULL;
1564 uschar *srs_secrets            = NULL;
1565 uschar *srs_status             = NULL;
1566 #endif
1567 #ifdef SUPPORT_SRS
1568 uschar *srs_recipient          = NULL;
1569 #endif
1570 int     string_datestamp_offset= -1;
1571 int     string_datestamp_length= 0;
1572 int     string_datestamp_type  = -1;
1573 const uschar *submission_domain = NULL;
1574 const uschar *submission_name  = NULL;
1575 int     syslog_facility        = LOG_MAIL;
1576 uschar *syslog_processname     = US"exim";
1577 uschar *system_filter          = NULL;
1578
1579 uschar *system_filter_directory_transport = NULL;
1580 uschar *system_filter_file_transport = NULL;
1581 uschar *system_filter_pipe_transport = NULL;
1582 uschar *system_filter_reply_transport = NULL;
1583
1584 gid_t   system_filter_gid      = 0;
1585 uid_t   system_filter_uid      = (uid_t)-1;
1586
1587 blob    tcp_fastopen_nodata    = { .data = NULL, .len = 0 };
1588 tfo_state_t tcp_out_fastopen   = TFO_NOT_USED;
1589 #ifdef USE_TCP_WRAPPERS
1590 uschar *tcp_wrappers_daemon_name = US TCP_WRAPPERS_DAEMON_NAME;
1591 #endif
1592 int     test_harness_load_avg  = 0;
1593 int     thismessage_size_limit = 0;
1594 int     timeout_frozen_after   = 0;
1595 #ifdef MEASURE_TIMING
1596 struct timeval timestamp_startup;
1597 #endif
1598
1599 transport_instance  *transports = NULL;
1600
1601 transport_instance  transport_defaults = {
1602     /* All non-mentioned elements zero/NULL/FALSE */
1603     .batch_max =                1,
1604     .multi_domain =             TRUE,
1605     .max_addresses =            100,
1606     .connection_max_messages =  500,
1607     .uid =                      (uid_t)(-1),
1608     .gid =                      (gid_t)(-1),
1609     .filter_timeout =           300,
1610     .retry_use_local_part =     TRUE_UNSET,     /* retry_use_local_part: BOOL, but set neither
1611                                                  1 nor 0 so can detect unset */
1612 };
1613
1614 int     transport_count;
1615 uschar *transport_name          = NULL;
1616 int     transport_newlines;
1617 const uschar **transport_filter_argv  = NULL;
1618 int     transport_filter_timeout;
1619 int     transport_write_timeout= 0;
1620
1621 tree_node  *tree_dns_fails     = NULL;
1622 tree_node  *tree_duplicates    = NULL;
1623 tree_node  *tree_nonrecipients = NULL;
1624 tree_node  *tree_unusable      = NULL;
1625
1626 gid_t  *trusted_groups         = NULL;
1627 uid_t  *trusted_users          = NULL;
1628 uschar *timezone_string        = US TIMEZONE_DEFAULT;
1629
1630 uschar *unknown_login          = NULL;
1631 uschar *unknown_username       = NULL;
1632 uschar *untrusted_set_sender   = NULL;
1633
1634 /*  A regex for matching a "From_" line in an incoming message, in the form
1635
1636     From ph10 Fri Jan  5 12:35 GMT 1996
1637
1638 which  the "mail" commands send to the MTA (undocumented, of course), or in
1639 the  form
1640
1641     From ph10 Fri, 7 Jan 97 14:00:00 GMT
1642
1643 which  is apparently used by some UUCPs, despite it not being in RFC 976.
1644 Because  of variations in time formats, just match up to the minutes. That
1645 should  be sufficient. Examples have been seen of time fields like 12:1:03,
1646 so  just require one digit for hours and minutes. The weekday is also absent
1647 in  some forms. */
1648
1649 uschar *uucp_from_pattern      = US
1650    "^From\\s+(\\S+)\\s+(?:[a-zA-Z]{3},?\\s+)?"    /* Common start */
1651    "(?:"                                          /* Non-extracting bracket */
1652    "[a-zA-Z]{3}\\s+\\d?\\d|"                      /* First form */
1653    "\\d?\\d\\s+[a-zA-Z]{3}\\s+\\d\\d(?:\\d\\d)?"  /* Second form */
1654    ")"                                            /* End alternation */
1655    "\\s+\\d\\d?:\\d\\d?";                         /* Start of time */
1656
1657 uschar *uucp_from_sender       = US"$1";
1658
1659 uschar *verify_mode            = NULL;
1660 uschar *version_copyright      =
1661  US"Copyright (c) University of Cambridge, 1995 - 2018\n"
1662    "(c) The Exim Maintainers and contributors in ACKNOWLEDGMENTS file, 2007 - 2020";
1663 uschar *version_date           = US"?";
1664 uschar *version_cnumber        = US"????";
1665 uschar *version_string         = US"?";
1666
1667 uschar *warn_message_file      = NULL;
1668 int     warning_count          = 0;
1669 uschar *warnmsg_delay          = NULL;
1670 uschar *warnmsg_recipients     = NULL;
1671
1672
1673 /*  End of globals.c */