CVE-2020-28015+28021: New-line injection into spool header file
[exim.git] / src / src / globals.c
1 /*************************************************
2 *     Exim - an Internet mail transport agent    *
3 *************************************************/
4
5 /* Copyright (c) University of Cambridge 1995 - 2018 */
6 /* Copyright (c) The Exim Maintainers 2020 */
7 /* See the file NOTICE for conditions of use and distribution. */
8
9 /* All the global variables are defined together in this one module, so
10 that they are easy to find. */
11
12 #include "exim.h"
13
14
15 /* Generic options for auths, all of which live inside auth_instance
16 data blocks and hence have the opt_public flag set. */
17
18 optionlist optionlist_auths[] = {
19   { "client_condition", opt_stringptr | opt_public,
20                  OPT_OFF(auth_instance, client_condition) },
21   { "client_set_id", opt_stringptr | opt_public,
22                  OPT_OFF(auth_instance, set_client_id) },
23   { "driver",        opt_stringptr | opt_public,
24                  OPT_OFF(auth_instance, driver_name) },
25   { "public_name",   opt_stringptr | opt_public,
26                  OPT_OFF(auth_instance, public_name) },
27   { "server_advertise_condition", opt_stringptr | opt_public,
28                  OPT_OFF(auth_instance, advertise_condition)},
29   { "server_condition", opt_stringptr | opt_public,
30                  OPT_OFF(auth_instance, server_condition) },
31   { "server_debug_print", opt_stringptr | opt_public,
32                  OPT_OFF(auth_instance, server_debug_string) },
33   { "server_mail_auth_condition", opt_stringptr | opt_public,
34                  OPT_OFF(auth_instance, mail_auth_condition) },
35   { "server_set_id", opt_stringptr | opt_public,
36                  OPT_OFF(auth_instance, set_id) }
37 };
38
39 int     optionlist_auths_size = nelem(optionlist_auths);
40
41 /* An empty host aliases list. */
42
43 uschar *no_aliases             = NULL;
44
45
46 /* For comments on these variables, see globals.h. I'm too idle to
47 duplicate them here... */
48
49 #ifdef EXIM_PERL
50 uschar *opt_perl_startup       = NULL;
51 BOOL    opt_perl_at_start      = FALSE;
52 BOOL    opt_perl_started       = FALSE;
53 BOOL    opt_perl_taintmode     = FALSE;
54 #endif
55
56 #ifdef EXPAND_DLFUNC
57 tree_node *dlobj_anchor        = NULL;
58 #endif
59
60 #ifdef LOOKUP_IBASE
61 uschar *ibase_servers          = NULL;
62 #endif
63
64 #ifdef LOOKUP_LDAP
65 uschar *eldap_ca_cert_dir      = NULL;
66 uschar *eldap_ca_cert_file     = NULL;
67 uschar *eldap_cert_file        = NULL;
68 uschar *eldap_cert_key         = NULL;
69 uschar *eldap_cipher_suite     = NULL;
70 uschar *eldap_default_servers  = NULL;
71 uschar *eldap_require_cert     = NULL;
72 int     eldap_version          = -1;
73 BOOL    eldap_start_tls        = FALSE;
74 #endif
75
76 #ifdef LOOKUP_MYSQL
77 uschar *mysql_servers          = NULL;
78 #endif
79
80 #ifdef LOOKUP_ORACLE
81 uschar *oracle_servers         = NULL;
82 #endif
83
84 #ifdef LOOKUP_PGSQL
85 uschar *pgsql_servers          = NULL;
86 #endif
87
88 #ifdef LOOKUP_REDIS
89 uschar *redis_servers          = NULL;
90 #endif
91
92 #ifdef LOOKUP_SQLITE
93 uschar *sqlite_dbfile          = NULL;
94 int     sqlite_lock_timeout    = 5;
95 #endif
96
97 #ifdef SUPPORT_MOVE_FROZEN_MESSAGES
98 BOOL    move_frozen_messages   = FALSE;
99 #endif
100
101 /* These variables are outside the #ifdef because it keeps the code less
102 cluttered in several places (e.g. during logging) if we can always refer to
103 them. Also, the tls_ variables are now always visible.  Note that these are
104 only used for smtp connections, not for service-daemon access. */
105
106 tls_support tls_in = {
107  .active =              {.sock = -1}
108  /* all other elements zero */
109 };
110 tls_support tls_out = {
111  .active =              {.sock = -1},
112  /* all other elements zero */
113 };
114
115 uschar *dsn_envid              = NULL;
116 int     dsn_ret                = 0;
117 const pcre  *regex_DSN         = NULL;
118 uschar *dsn_advertise_hosts    = NULL;
119
120 #ifndef DISABLE_TLS
121 BOOL    gnutls_compat_mode     = FALSE;
122 BOOL    gnutls_allow_auto_pkcs11 = FALSE;
123 uschar *openssl_options        = NULL;
124 const pcre *regex_STARTTLS     = NULL;
125 uschar *tls_advertise_hosts    = US"*";
126 uschar *tls_certificate        = NULL;
127 uschar *tls_crl                = NULL;
128 /* This default matches NSS DH_MAX_P_BITS value at current time (2012), because
129 that's the interop problem which has been observed: GnuTLS suggesting a higher
130 bit-count as "NORMAL" (2432) and Thunderbird dropping connection. */
131 int     tls_dh_max_bits        = 2236;
132 uschar *tls_dhparam            = NULL;
133 uschar *tls_eccurve            = US"auto";
134 # ifndef DISABLE_OCSP
135 uschar *tls_ocsp_file          = NULL;
136 # endif
137 uschar *tls_privatekey         = NULL;
138 BOOL    tls_remember_esmtp     = FALSE;
139 uschar *tls_require_ciphers    = NULL;
140 # ifdef EXPERIMENTAL_TLS_RESUME
141 uschar *tls_resumption_hosts   = NULL;
142 # endif
143 uschar *tls_try_verify_hosts   = NULL;
144 uschar *tls_verify_certificates= US"system";
145 uschar *tls_verify_hosts       = NULL;
146 #else   /*DISABLE_TLS*/
147 uschar *tls_advertise_hosts    = NULL;
148 #endif
149
150 #ifndef DISABLE_PRDR
151 /* Per Recipient Data Response variables */
152 BOOL    prdr_enable            = FALSE;
153 BOOL    prdr_requested         = FALSE;
154 const pcre *regex_PRDR         = NULL;
155 #endif
156
157 #ifdef SUPPORT_I18N
158 const pcre *regex_UTF8         = NULL;
159 #endif
160
161 /* Input-reading functions for messages, so we can use special ones for
162 incoming TCP/IP. The defaults use stdin. We never need these for any
163 stand-alone tests. */
164
165 #if !defined(STAND_ALONE) && !defined(MACRO_PREDEF)
166 int (*lwr_receive_getc)(unsigned) = stdin_getc;
167 uschar * (*lwr_receive_getbuf)(unsigned *) = NULL;
168 int (*lwr_receive_ungetc)(int) = stdin_ungetc;
169 int (*receive_getc)(unsigned)  = stdin_getc;
170 uschar * (*receive_getbuf)(unsigned *)  = NULL;
171 void (*receive_get_cache)(void)= NULL;
172 int (*receive_ungetc)(int)     = stdin_ungetc;
173 int (*receive_feof)(void)      = stdin_feof;
174 int (*receive_ferror)(void)    = stdin_ferror;
175 BOOL (*receive_smtp_buffered)(void) = NULL;   /* Only used for SMTP */
176 #endif
177
178
179 /* List of per-address expansion variables for clearing and saving/restoring
180 when verifying one address while routing/verifying another. We have to have
181 the size explicit, because it is referenced from more than one module. */
182
183 const uschar **address_expansions[ADDRESS_EXPANSIONS_COUNT] = {
184   CUSS &deliver_address_data,
185   CUSS &deliver_domain,
186   CUSS &deliver_domain_data,
187   CUSS &deliver_domain_orig,
188   CUSS &deliver_domain_parent,
189   CUSS &deliver_localpart,
190   CUSS &deliver_localpart_data,
191   CUSS &deliver_localpart_orig,
192   CUSS &deliver_localpart_parent,
193   CUSS &deliver_localpart_prefix,
194   CUSS &deliver_localpart_suffix,
195   CUSS (uschar **)(&deliver_recipients),
196   CUSS &deliver_host,
197   CUSS &deliver_home,
198   CUSS &address_file,
199   CUSS &address_pipe,
200   CUSS &self_hostname,
201   NULL };
202
203 int address_expansions_count = sizeof(address_expansions)/sizeof(uschar **);
204
205 /******************************************************************************/
206 /* General global variables.  Boolean flags are done as a group
207 so that only one bit each is needed, packed, for all those we never
208 need to take a pointer - and only a char for the rest.
209 This means a struct, unfortunately since it clutters the sourcecode. */
210
211 struct global_flags f =
212 {
213         .acl_temp_details       = FALSE,
214         .active_local_from_check = FALSE,
215         .active_local_sender_retain = FALSE,
216         .address_test_mode      = FALSE,
217         .admin_user             = FALSE,
218         .allow_auth_unadvertised= FALSE,
219         .allow_unqualified_recipient = TRUE,    /* For local messages */
220         .allow_unqualified_sender = TRUE,       /* Reset for SMTP */
221         .authentication_local   = FALSE,
222
223         .background_daemon      = TRUE,
224         .bdat_readers_wanted    = FALSE,
225
226         .chunking_offered       = FALSE,
227         .config_changed         = FALSE,
228         .continue_more          = FALSE,
229
230         .daemon_listen          = FALSE,
231         .debug_daemon           = FALSE,
232         .deliver_firsttime      = FALSE,
233         .deliver_force          = FALSE,
234         .deliver_freeze         = FALSE,
235         .deliver_force_thaw     = FALSE,
236         .deliver_manual_thaw    = FALSE,
237         .deliver_selectstring_regex = FALSE,
238         .deliver_selectstring_sender_regex = FALSE,
239         .disable_callout_flush  = FALSE,
240         .disable_delay_flush    = FALSE,
241         .disable_logging        = FALSE,
242 #ifndef DISABLE_DKIM
243         .dkim_disable_verify      = FALSE,
244         .dkim_init_done           = FALSE,
245 #endif
246 #ifdef SUPPORT_DMARC
247         .dmarc_has_been_checked  = FALSE,
248         .dmarc_disable_verify    = FALSE,
249         .dmarc_enable_forensic   = FALSE,
250 #endif
251         .dont_deliver           = FALSE,
252         .dot_ends               = TRUE,
253
254         .enable_dollar_recipients = FALSE,
255         .expand_string_forcedfail = FALSE,
256
257         .filter_running         = FALSE,
258
259         .header_rewritten       = FALSE,
260         .helo_verified          = FALSE,
261         .helo_verify_failed     = FALSE,
262         .host_checking_callout  = FALSE,
263         .host_find_failed_syntax= FALSE,
264
265         .inetd_wait_mode        = FALSE,
266         .is_inetd               = FALSE,
267
268         .local_error_message    = FALSE,
269         .log_testing_mode       = FALSE,
270
271 #ifdef WITH_CONTENT_SCAN
272         .no_mbox_unspool        = FALSE,
273 #endif
274         .no_multiline_responses = FALSE,
275
276         .parse_allow_group      = FALSE,
277         .parse_found_group      = FALSE,
278         .pipelining_enable      = TRUE,
279 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
280         .proxy_session_failed   = FALSE,
281 #endif
282
283         .queue_2stage           = FALSE,
284         .queue_only_policy      = FALSE,
285         .queue_run_first_delivery = FALSE,
286         .queue_run_force        = FALSE,
287         .queue_run_local        = FALSE,
288         .queue_running          = FALSE,
289         .queue_smtp             = FALSE,
290
291         .really_exim            = TRUE,
292         .receive_call_bombout   = FALSE,
293         .recipients_discarded   = FALSE,
294         .running_in_test_harness = FALSE,
295
296         .search_find_defer      = FALSE,
297         .sender_address_forced  = FALSE,
298         .sender_host_notsocket  = FALSE,
299         .sender_host_unknown    = FALSE,
300         .sender_local           = FALSE,
301         .sender_name_forced     = FALSE,
302         .sender_set_untrusted   = FALSE,
303         .smtp_authenticated     = FALSE,
304 #ifndef DISABLE_PIPE_CONNECT
305         .smtp_in_early_pipe_advertised = FALSE,
306         .smtp_in_early_pipe_no_auth = FALSE,
307         .smtp_in_early_pipe_used = FALSE,
308 #endif
309         .smtp_in_pipelining_advertised = FALSE,
310         .smtp_in_pipelining_used = FALSE,
311         .spool_file_wireformat  = FALSE,
312         .submission_mode        = FALSE,
313         .suppress_local_fixups  = FALSE,
314         .suppress_local_fixups_default = FALSE,
315         .synchronous_delivery   = FALSE,
316         .system_filtering       = FALSE,
317
318         .taint_check_slow       = FALSE,
319         .testsuite_delays       = TRUE,
320         .tcp_fastopen_ok        = FALSE,
321         .tcp_in_fastopen        = FALSE,
322         .tcp_in_fastopen_data   = FALSE,
323         .tcp_in_fastopen_logged = FALSE,
324         .tcp_out_fastopen_logged= FALSE,
325         .timestamps_utc         = FALSE,
326         .transport_filter_timed_out = FALSE,
327         .trusted_caller         = FALSE,
328         .trusted_config         = TRUE,
329 };
330
331 /******************************************************************************/
332 /* These are the flags which are either variables or mainsection options,
333 so an address is needed for access, or are exported to local_scan. */
334
335 BOOL    accept_8bitmime        = TRUE; /* deliberately not RFC compliant */
336 BOOL    allow_domain_literals  = FALSE;
337 BOOL    allow_mx_to_ip         = FALSE;
338 BOOL    allow_utf8_domains     = FALSE;
339 BOOL    authentication_failed  = FALSE;
340
341 BOOL    bounce_return_body     = TRUE;
342 BOOL    bounce_return_message  = TRUE;
343 BOOL    check_rfc2047_length   = TRUE;
344 BOOL    commandline_checks_require_admin = FALSE;
345
346 #ifdef EXPERIMENTAL_DCC
347 BOOL    dcc_direct_add_header  = FALSE;
348 #endif
349 BOOL    debug_store            = FALSE;
350 BOOL    delivery_date_remove   = TRUE;
351 BOOL    deliver_drop_privilege = FALSE;
352 #ifdef ENABLE_DISABLE_FSYNC
353 BOOL    disable_fsync          = FALSE;
354 #endif
355 BOOL    disable_ipv6           = FALSE;
356 BOOL    dns_csa_use_reverse    = TRUE;
357 BOOL    drop_cr                = FALSE;         /* No longer used */
358
359 BOOL    envelope_to_remove     = TRUE;
360 BOOL    exim_gid_set           = TRUE;          /* This gid is always set */
361 BOOL    exim_uid_set           = TRUE;          /* This uid is always set */
362 BOOL    extract_addresses_remove_arguments = TRUE;
363
364 BOOL    host_checking          = FALSE;
365 BOOL    host_lookup_deferred   = FALSE;
366 BOOL    host_lookup_failed     = FALSE;
367 BOOL    ignore_fromline_local  = FALSE;
368
369 BOOL    local_from_check       = TRUE;
370 BOOL    local_sender_retain    = FALSE;
371 BOOL    log_timezone           = FALSE;
372 BOOL    message_body_newlines  = FALSE;
373 BOOL    message_logs           = TRUE;
374 #ifdef SUPPORT_I18N
375 BOOL    message_smtputf8       = FALSE;
376 #endif
377 BOOL    mua_wrapper            = FALSE;
378
379 BOOL    preserve_message_logs  = FALSE;
380 BOOL    print_topbitchars      = FALSE;
381 BOOL    prod_requires_admin    = TRUE;
382 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
383 BOOL    proxy_session          = FALSE;
384 #endif
385
386 #ifdef EXPERIMENTAL_QUEUE_RAMP
387 BOOL    queue_fast_ramp         = FALSE;
388 #endif
389 BOOL    queue_list_requires_admin = TRUE;
390 BOOL    queue_only             = FALSE;
391 BOOL    queue_only_load_latch  = TRUE;
392 BOOL    queue_only_override    = TRUE;
393 BOOL    queue_run_in_order     = FALSE;
394 BOOL    recipients_max_reject  = FALSE;
395 BOOL    return_path_remove     = TRUE;
396
397 BOOL    smtp_batched_input     = FALSE;
398 BOOL    sender_helo_dnssec     = FALSE;
399 BOOL    sender_host_dnssec     = FALSE;
400 BOOL    smtp_accept_keepalive  = TRUE;
401 BOOL    smtp_check_spool_space = TRUE;
402 BOOL    smtp_enforce_sync      = TRUE;
403 BOOL    smtp_etrn_serialize    = TRUE;
404 BOOL    smtp_input             = FALSE;
405 BOOL    smtp_return_error_details = FALSE;
406 #ifdef SUPPORT_SPF
407 BOOL    spf_result_guessed     = FALSE;
408 #endif
409 BOOL    split_spool_directory  = FALSE;
410 BOOL    spool_wireformat       = FALSE;
411 #ifdef EXPERIMENTAL_SRS
412 BOOL    srs_usehash            = TRUE;
413 BOOL    srs_usetimestamp       = TRUE;
414 #endif
415 BOOL    strict_acl_vars        = FALSE;
416 BOOL    strip_excess_angle_brackets = FALSE;
417 BOOL    strip_trailing_dot     = FALSE;
418 BOOL    syslog_duplication     = TRUE;
419 BOOL    syslog_pid             = TRUE;
420 BOOL    syslog_timestamp       = TRUE;
421 BOOL    system_filter_gid_set  = FALSE;
422 BOOL    system_filter_uid_set  = FALSE;
423
424 BOOL    tcp_nodelay            = TRUE;
425 BOOL    write_rejectlog        = TRUE;
426
427 /******************************************************************************/
428
429 header_line *acl_added_headers = NULL;
430 tree_node *acl_anchor          = NULL;
431 uschar *acl_arg[9]             = {NULL, NULL, NULL, NULL, NULL,
432                                   NULL, NULL, NULL, NULL};
433 int     acl_narg               = 0;
434
435 int     acl_level              = 0;
436
437 uschar *acl_not_smtp           = NULL;
438 #ifdef WITH_CONTENT_SCAN
439 uschar *acl_not_smtp_mime      = NULL;
440 #endif
441 uschar *acl_not_smtp_start     = NULL;
442 uschar *acl_removed_headers    = NULL;
443 uschar *acl_smtp_auth          = NULL;
444 uschar *acl_smtp_connect       = NULL;
445 uschar *acl_smtp_data          = NULL;
446 #ifndef DISABLE_PRDR
447 uschar *acl_smtp_data_prdr     = US"accept";
448 #endif
449 #ifndef DISABLE_DKIM
450 uschar *acl_smtp_dkim          = NULL;
451 #endif
452 uschar *acl_smtp_etrn          = NULL;
453 uschar *acl_smtp_expn          = NULL;
454 uschar *acl_smtp_helo          = NULL;
455 uschar *acl_smtp_mail          = NULL;
456 uschar *acl_smtp_mailauth      = NULL;
457 #ifdef WITH_CONTENT_SCAN
458 uschar *acl_smtp_mime          = NULL;
459 #endif
460 uschar *acl_smtp_notquit       = NULL;
461 uschar *acl_smtp_predata       = NULL;
462 uschar *acl_smtp_quit          = NULL;
463 uschar *acl_smtp_rcpt          = NULL;
464 uschar *acl_smtp_starttls      = NULL;
465 uschar *acl_smtp_vrfy          = NULL;
466
467 tree_node *acl_var_c           = NULL;
468 tree_node *acl_var_m           = NULL;
469 uschar *acl_verify_message     = NULL;
470 string_item *acl_warn_logged   = NULL;
471
472 /* Names of SMTP places for use in ACL error messages, and corresponding SMTP
473 error codes - keep in step with definitions of ACL_WHERE_xxxx in macros.h. */
474
475 uschar *acl_wherenames[]       = { US"RCPT",
476                                    US"MAIL",
477                                    US"PREDATA",
478                                    US"MIME",
479                                    US"DKIM",
480                                    US"DATA",
481 #ifndef DISABLE_PRDR
482                                    US"PRDR",
483 #endif
484                                    US"non-SMTP",
485                                    US"AUTH",
486                                    US"connection",
487                                    US"ETRN",
488                                    US"EXPN",
489                                    US"EHLO or HELO",
490                                    US"MAILAUTH",
491                                    US"non-SMTP-start",
492                                    US"NOTQUIT",
493                                    US"QUIT",
494                                    US"STARTTLS",
495                                    US"VRFY",
496                                    US"delivery",
497                                    US"unknown"
498                                  };
499
500 uschar *acl_wherecodes[]       = { US"550",     /* RCPT */
501                                    US"550",     /* MAIL */
502                                    US"550",     /* PREDATA */
503                                    US"550",     /* MIME */
504                                    US"550",     /* DKIM */
505                                    US"550",     /* DATA */
506 #ifndef DISABLE_PRDR
507                                    US"550",    /* RCPT PRDR */
508 #endif
509                                    US"0",       /* not SMTP; not relevant */
510                                    US"503",     /* AUTH */
511                                    US"550",     /* connect */
512                                    US"458",     /* ETRN */
513                                    US"550",     /* EXPN */
514                                    US"550",     /* HELO/EHLO */
515                                    US"0",       /* MAILAUTH; not relevant */
516                                    US"0",       /* not SMTP; not relevant */
517                                    US"0",       /* NOTQUIT; not relevant */
518                                    US"0",       /* QUIT; not relevant */
519                                    US"550",     /* STARTTLS */
520                                    US"252",     /* VRFY */
521                                    US"0",       /* delivery; not relevant */
522                                    US"0"        /* unknown; not relevant */
523                                  };
524
525 uschar *add_environment        = NULL;
526 address_item  *addr_duplicate  = NULL;
527
528 address_item address_defaults = {
529   .next =               NULL,
530   .parent =             NULL,
531   .first =              NULL,
532   .dupof =              NULL,
533   .start_router =       NULL,
534   .router =             NULL,
535   .transport =          NULL,
536   .host_list =          NULL,
537   .host_used =          NULL,
538   .fallback_hosts =     NULL,
539   .reply =              NULL,
540   .retries =            NULL,
541   .address =            NULL,
542   .unique =             NULL,
543   .cc_local_part =      NULL,
544   .lc_local_part =      NULL,
545   .local_part =         NULL,
546   .prefix =             NULL,
547   .prefix_v =           NULL,
548   .suffix =             NULL,
549   .suffix_v =           NULL,
550   .domain =             NULL,
551   .address_retry_key =  NULL,
552   .domain_retry_key =   NULL,
553   .current_dir =        NULL,
554   .home_dir =           NULL,
555   .message =            NULL,
556   .user_message =       NULL,
557   .onetime_parent =     NULL,
558   .pipe_expandn =       NULL,
559   .return_filename =    NULL,
560   .self_hostname =      NULL,
561   .shadow_message =     NULL,
562 #ifndef DISABLE_TLS
563   .cipher =             NULL,
564   .ourcert =            NULL,
565   .peercert =           NULL,
566   .peerdn =             NULL,
567   .ocsp =               OCSP_NOT_REQ,
568 #endif
569 #ifdef EXPERIMENTAL_DSN_INFO
570   .smtp_greeting =      NULL,
571   .helo_response =      NULL,
572 #endif
573   .authenticator =      NULL,
574   .auth_id =            NULL,
575   .auth_sndr =          NULL,
576   .dsn_orcpt =          NULL,
577   .dsn_flags =          0,
578   .dsn_aware =          0,
579   .uid =                (uid_t)(-1),
580   .gid =                (gid_t)(-1),
581   .flags =              { 0 },
582   .domain_cache =       { 0 },                /* domain_cache - any larger array should be zeroed */
583   .localpart_cache =    { 0 },                /* localpart_cache - ditto */
584   .mode =               -1,
585   .more_errno =         0,
586   .delivery_time =      {.tv_sec = 0, .tv_usec = 0},
587   .basic_errno =        ERRNO_UNKNOWNERROR,
588   .child_count =        0,
589   .return_file =        -1,
590   .special_action =     SPECIAL_NONE,
591   .transport_return =   DEFER,
592   .prop = {                                     /* fields that are propagated to children */
593     .address_data =     NULL,
594     .domain_data =      NULL,
595     .localpart_data =   NULL,
596     .errors_address =   NULL,
597     .extra_headers =    NULL,
598     .remove_headers =   NULL,
599     .variables =        NULL,
600 #ifdef EXPERIMENTAL_SRS
601     .srs_sender =       NULL,
602 #endif
603     .ignore_error =     FALSE,
604 #ifdef SUPPORT_I18N
605     .utf8_msg =         FALSE,
606     .utf8_downcvt =     FALSE,
607     .utf8_downcvt_maybe = FALSE
608 #endif
609   }
610 };
611
612 uschar *address_file           = NULL;
613 uschar *address_pipe           = NULL;
614 tree_node *addresslist_anchor  = NULL;
615 int     addresslist_count      = 0;
616 gid_t  *admin_groups           = NULL;
617
618 #ifdef EXPERIMENTAL_ARC
619 struct arc_set *arc_received    = NULL;
620 int     arc_received_instance   = 0;
621 int     arc_oldest_pass         = 0;
622 const uschar *arc_state         = NULL;
623 const uschar *arc_state_reason  = NULL;
624 #endif
625
626 uschar *authenticated_fail_id  = NULL;
627 uschar *authenticated_id       = NULL;
628 uschar *authenticated_sender   = NULL;
629 auth_instance  *auths          = NULL;
630 uschar *auth_advertise_hosts   = US"*";
631 auth_instance auth_defaults    = {
632     .next =             NULL,
633     .name =             NULL,
634     .info =             NULL,
635     .options_block =    NULL,
636     .driver_name =      NULL,
637     .advertise_condition = NULL,
638     .client_condition = NULL,
639     .public_name =      NULL,
640     .set_id =           NULL,
641     .set_client_id =    NULL,
642     .mail_auth_condition = NULL,
643     .server_debug_string = NULL,
644     .server_condition = NULL,
645     .client =           FALSE,
646     .server =           FALSE,
647     .advertised =       FALSE
648 };
649
650 uschar *auth_defer_msg         = US"reason not recorded";
651 uschar *auth_defer_user_msg    = US"";
652 uschar *auth_vars[AUTH_VARS];
653 int     auto_thaw              = 0;
654 #ifdef WITH_CONTENT_SCAN
655 int     av_failed              = FALSE; /* boolean but accessed as vtype_int*/
656 uschar *av_scanner             = US"sophie:/var/run/sophie";  /* AV scanner */
657 #endif
658
659 #if BASE_62 == 62
660 uschar *base62_chars=
661     US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";
662 #else
663 uschar *base62_chars= US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ";
664 #endif
665
666 uschar *bi_command             = NULL;
667 uschar *big_buffer             = NULL;
668 int     big_buffer_size        = BIG_BUFFER_SIZE;
669 #ifdef EXPERIMENTAL_BRIGHTMAIL
670 uschar *bmi_alt_location       = NULL;
671 uschar *bmi_base64_tracker_verdict = NULL;
672 uschar *bmi_base64_verdict     = NULL;
673 uschar *bmi_config_file        = US"/opt/brightmail/etc/brightmail.cfg";
674 int     bmi_deliver            = 1;
675 int     bmi_run                = 0;
676 uschar *bmi_verdicts           = NULL;
677 #endif
678 int     bsmtp_transaction_linecount = 0;
679 int     body_8bitmime          = 0;
680 int     body_linecount         = 0;
681 int     body_zerocount         = 0;
682 uschar *bounce_message_file    = NULL;
683 uschar *bounce_message_text    = NULL;
684 uschar *bounce_recipient       = NULL;
685 int     bounce_return_linesize_limit = 998;
686 int     bounce_return_size_limit = 100*1024;
687 uschar *bounce_sender_authentication = NULL;
688
689 uschar *callout_address        = NULL;
690 int     callout_cache_domain_positive_expire = 7*24*60*60;
691 int     callout_cache_domain_negative_expire = 3*60*60;
692 int     callout_cache_positive_expire = 24*60*60;
693 int     callout_cache_negative_expire = 2*60*60;
694 uschar *callout_random_local_part = US"$primary_hostname-$tod_epoch-testing";
695 uschar *check_dns_names_pattern= US"(?i)^(?>(?(1)\\.|())[^\\W](?>[a-z0-9/_-]*[^\\W])?)+(\\.?)$";
696 int     check_log_inodes       = 100;
697 int_eximarith_t check_log_space = 10*1024;      /* 10K Kbyte == 10MB */
698 int     check_spool_inodes     = 100;
699 int_eximarith_t check_spool_space = 10*1024;    /* 10K Kbyte == 10MB */
700
701 uschar *chunking_advertise_hosts = US"*";
702 unsigned chunking_datasize     = 0;
703 unsigned chunking_data_left    = 0;
704 chunking_state_t chunking_state= CHUNKING_NOT_OFFERED;
705 const pcre *regex_CHUNKING     = NULL;
706
707 uschar *client_authenticator   = NULL;
708 uschar *client_authenticated_id = NULL;
709 uschar *client_authenticated_sender = NULL;
710 int     clmacro_count          = 0;
711 uschar *clmacros[MAX_CLMACROS];
712 FILE   *config_file            = NULL;
713 const uschar *config_filename  = NULL;
714 int     config_lineno          = 0;
715 #ifdef CONFIGURE_GROUP
716 gid_t   config_gid             = CONFIGURE_GROUP;
717 #else
718 gid_t   config_gid             = 0;
719 #endif
720 uschar *config_main_filelist   = US CONFIGURE_FILE
721                          "\0<-----------Space to patch configure_filename->";
722 uschar *config_main_filename   = NULL;
723 uschar *config_main_directory  = NULL;
724
725 #ifdef CONFIGURE_OWNER
726 uid_t   config_uid             = CONFIGURE_OWNER;
727 #else
728 uid_t   config_uid             = 0;
729 #endif
730
731 int     connection_max_messages= -1;
732 uschar *continue_proxy_cipher  = NULL;
733 BOOL    continue_proxy_dane    = FALSE;
734 uschar *continue_proxy_sni     = NULL;
735 uschar *continue_hostname      = NULL;
736 uschar *continue_host_address  = NULL;
737 int     continue_sequence      = 1;
738 uschar *continue_transport     = NULL;
739
740 uschar *csa_status             = NULL;
741 cut_t   cutthrough = {
742   .callout_hold_only =  FALSE,                          /* verify-only: normal delivery */
743   .delivery =           FALSE,                          /* when to attempt */
744   .defer_pass =         FALSE,                          /* on defer: spool locally */
745   .is_tls =             FALSE,                          /* not a TLS conn yet */
746   .cctx =               {.sock = -1},                   /* open connection */
747   .nrcpt =              0,                              /* number of addresses */
748 };
749
750 int     daemon_notifier_fd     = -1;
751 uschar *daemon_smtp_port       = US"smtp";
752 int     daemon_startup_retries = 9;
753 int     daemon_startup_sleep   = 30;
754
755 #ifdef EXPERIMENTAL_DCC
756 uschar *dcc_header             = NULL;
757 uschar *dcc_result             = NULL;
758 uschar *dccifd_address         = US"/usr/local/dcc/var/dccifd";
759 uschar *dccifd_options         = US"header";
760 #endif
761
762 int     debug_fd               = -1;
763 FILE   *debug_file             = NULL;
764 int     debug_notall[]         = {
765   Di_memory,
766   Di_noutf8,
767   -1
768 };
769 bit_table debug_options[]      = { /* must be in alphabetical order and use
770                                  only the enum values from macro.h */
771   BIT_TABLE(D, acl),
772   BIT_TABLE(D, all),
773   BIT_TABLE(D, auth),
774   BIT_TABLE(D, deliver),
775   BIT_TABLE(D, dns),
776   BIT_TABLE(D, dnsbl),
777   BIT_TABLE(D, exec),
778   BIT_TABLE(D, expand),
779   BIT_TABLE(D, filter),
780   BIT_TABLE(D, hints_lookup),
781   BIT_TABLE(D, host_lookup),
782   BIT_TABLE(D, ident),
783   BIT_TABLE(D, interface),
784   BIT_TABLE(D, lists),
785   BIT_TABLE(D, load),
786   BIT_TABLE(D, local_scan),
787   BIT_TABLE(D, lookup),
788   BIT_TABLE(D, memory),
789   BIT_TABLE(D, noutf8),
790   BIT_TABLE(D, pid),
791   BIT_TABLE(D, process_info),
792   BIT_TABLE(D, queue_run),
793   BIT_TABLE(D, receive),
794   BIT_TABLE(D, resolver),
795   BIT_TABLE(D, retry),
796   BIT_TABLE(D, rewrite),
797   BIT_TABLE(D, route),
798   BIT_TABLE(D, timestamp),
799   BIT_TABLE(D, tls),
800   BIT_TABLE(D, transport),
801   BIT_TABLE(D, uid),
802   BIT_TABLE(D, verify),
803 };
804 int     debug_options_count    = nelem(debug_options);
805
806 unsigned int debug_selector    = 0;
807 int     delay_warning[DELAY_WARNING_SIZE] = { DELAY_WARNING_SIZE, 1, 24*60*60 };
808 uschar *delay_warning_condition=
809   US"${if or {"
810             "{ !eq{$h_list-id:$h_list-post:$h_list-subscribe:}{} }"
811             "{ match{$h_precedence:}{(?i)bulk|list|junk} }"
812             "{ match{$h_auto-submitted:}{(?i)auto-generated|auto-replied} }"
813             "} {no}{yes}}";
814 uschar *deliver_address_data   = NULL;
815 int     deliver_datafile       = -1;
816 const uschar *deliver_domain   = NULL;
817 uschar *deliver_domain_data    = NULL;
818 const uschar *deliver_domain_orig = NULL;
819 const uschar *deliver_domain_parent = NULL;
820 time_t  deliver_frozen_at      = 0;
821 uschar *deliver_home           = NULL;
822 const uschar *deliver_host     = NULL;
823 const uschar *deliver_host_address = NULL;
824 int     deliver_host_port      = 0;
825 uschar *deliver_in_buffer      = NULL;
826 ino_t   deliver_inode          = 0;
827 uschar *deliver_localpart      = NULL;
828 uschar *deliver_localpart_data = NULL;
829 uschar *deliver_localpart_orig = NULL;
830 uschar *deliver_localpart_parent = NULL;
831 uschar *deliver_localpart_prefix = NULL;
832 uschar *deliver_localpart_prefix_v = NULL;
833 uschar *deliver_localpart_suffix = NULL;
834 uschar *deliver_localpart_suffix_v = NULL;
835 uschar *deliver_out_buffer     = NULL;
836 int     deliver_queue_load_max = -1;
837 address_item  *deliver_recipients = NULL;
838 uschar *deliver_selectstring   = NULL;
839 uschar *deliver_selectstring_sender = NULL;
840
841 #ifndef DISABLE_DKIM
842 unsigned dkim_collect_input      = 0;
843 uschar *dkim_cur_signer          = NULL;
844 int     dkim_key_length          = 0;
845 void   *dkim_signatures          = NULL;
846 uschar *dkim_signers             = NULL;
847 uschar *dkim_signing_domain      = NULL;
848 uschar *dkim_signing_selector    = NULL;
849 uschar *dkim_verify_hashes       = US"sha256:sha512";
850 uschar *dkim_verify_keytypes     = US"ed25519:rsa";
851 uschar *dkim_verify_min_keysizes = US"rsa=1024 ed25519=250";
852 BOOL    dkim_verify_minimal      = FALSE;
853 uschar *dkim_verify_overall      = NULL;
854 uschar *dkim_verify_signers      = US"$dkim_signers";
855 uschar *dkim_verify_status       = NULL;
856 uschar *dkim_verify_reason       = NULL;
857 #endif
858 #ifdef SUPPORT_DMARC
859 uschar *dmarc_domain_policy     = NULL;
860 uschar *dmarc_forensic_sender   = NULL;
861 uschar *dmarc_history_file      = NULL;
862 uschar *dmarc_status            = NULL;
863 uschar *dmarc_status_text       = NULL;
864 uschar *dmarc_tld_file          = NULL;
865 uschar *dmarc_used_domain       = NULL;
866 #endif
867
868 uschar *dns_again_means_nonexist = NULL;
869 int     dns_csa_search_limit   = 5;
870 int     dns_cname_loops        = 1;
871 #ifdef SUPPORT_DANE
872 int     dns_dane_ok            = -1;
873 #endif
874 uschar *dns_ipv4_lookup        = NULL;
875 int     dns_retrans            = 0;
876 int     dns_retry              = 0;
877 int     dns_dnssec_ok          = -1; /* <0 = not coerced */
878 uschar *dns_trust_aa           = NULL;
879 int     dns_use_edns0          = -1; /* <0 = not coerced */
880 uschar *dnslist_domain         = NULL;
881 uschar *dnslist_matched        = NULL;
882 uschar *dnslist_text           = NULL;
883 uschar *dnslist_value          = NULL;
884 tree_node *domainlist_anchor   = NULL;
885 int     domainlist_count       = 0;
886 uschar *dsn_from               = US DEFAULT_DSN_FROM;
887
888 int     errno_quota            = ERRNO_QUOTA;
889 uschar *errors_copy            = NULL;
890 int     error_handling         = ERRORS_SENDER;
891 uschar *errors_reply_to        = NULL;
892 int     errors_sender_rc       = EXIT_FAILURE;
893 #ifndef DISABLE_EVENT
894 uschar *event_action             = NULL;        /* expansion for delivery events */
895 uschar *event_data               = NULL;        /* auxiliary data variable for event */
896 int     event_defer_errno        = 0;
897 const uschar *event_name         = NULL;        /* event name variable */
898 #endif
899
900
901 gid_t   exim_gid               = EXIM_GID;
902 uschar *exim_path              = US BIN_DIRECTORY "/exim"
903                         "\0<---------------Space to patch exim_path->";
904 uid_t   exim_uid               = EXIM_UID;
905 int     expand_level           = 0;             /* Nesting depth, indent for debug */
906 int     expand_forbid          = 0;
907 int     expand_nlength[EXPAND_MAXN+1];
908 int     expand_nmax            = -1;
909 uschar *expand_nstring[EXPAND_MAXN+1];
910 uschar *expand_string_message;
911 uschar *extra_local_interfaces = NULL;
912
913 int     fake_response          = OK;
914 uschar *fake_response_text     = US"Your message has been rejected but is "
915                                    "being kept for evaluation.\nIf it was a "
916                                    "legitimate message, it may still be "
917                                    "delivered to the target recipient(s).";
918 int     filter_n[FILTER_VARIABLE_COUNT];
919 int     filter_sn[FILTER_VARIABLE_COUNT];
920 int     filter_test            = FTEST_NONE;
921 uschar *filter_test_sfile      = NULL;
922 uschar *filter_test_ufile      = NULL;
923 uschar *filter_thisaddress     = NULL;
924 int     finduser_retries       = 0;
925 uid_t   fixed_never_users[]    = { FIXED_NEVER_USERS };
926 uschar *freeze_tell            = NULL;
927 uschar *freeze_tell_config     = NULL;
928 uschar *fudged_queue_times     = US"";
929
930 uschar *gecos_name             = NULL;
931 uschar *gecos_pattern          = NULL;
932 rewrite_rule  *global_rewrite_rules = NULL;
933
934 volatile sig_atomic_t had_command_timeout = 0;
935 volatile sig_atomic_t had_command_sigterm = 0;
936 volatile sig_atomic_t had_data_timeout    = 0;
937 volatile sig_atomic_t had_data_sigint     = 0;
938 uschar *headers_charset        = US HEADERS_CHARSET;
939 int     header_insert_maxlen   = 64 * 1024;
940 header_line  *header_last      = NULL;
941 header_line  *header_list      = NULL;
942 int     header_maxsize         = HEADER_MAXSIZE;
943 int     header_line_maxsize    = 0;
944
945 header_name header_names[] = {
946   /* name               len     allow_resent    htype */
947   { US"bcc",            3,      TRUE,           htype_bcc },
948   { US"cc",             2,      TRUE,           htype_cc },
949   { US"date",           4,      TRUE,           htype_date },
950   { US"delivery-date", 13,      FALSE,          htype_delivery_date },
951   { US"envelope-to",   11,      FALSE,          htype_envelope_to },
952   { US"from",           4,      TRUE,           htype_from },
953   { US"message-id",    10,      TRUE,           htype_id },
954   { US"received",       8,      FALSE,          htype_received },
955   { US"reply-to",       8,      FALSE,          htype_reply_to },
956   { US"return-path",   11,      FALSE,          htype_return_path },
957   { US"sender",         6,      TRUE,           htype_sender },
958   { US"subject",        7,      FALSE,          htype_subject },
959   { US"to",             2,      TRUE,           htype_to }
960 };
961
962 int header_names_size          = nelem(header_names);
963
964 uschar *helo_accept_junk_hosts = NULL;
965 uschar *helo_allow_chars       = US"";
966 uschar *helo_lookup_domains    = US"@ : @[]";
967 uschar *helo_try_verify_hosts  = NULL;
968 uschar *helo_verify_hosts      = NULL;
969 const uschar *hex_digits       = CUS"0123456789abcdef";
970 uschar *hold_domains           = NULL;
971 uschar *host_data              = NULL;
972 uschar *host_lookup            = NULL;
973 uschar *host_lookup_order      = US"bydns:byaddr";
974 uschar *host_lookup_msg        = US"";
975 int     host_number            = 0;
976 uschar *host_number_string     = NULL;
977 uschar *host_reject_connection = NULL;
978 tree_node *hostlist_anchor     = NULL;
979 int     hostlist_count         = 0;
980 uschar *hosts_treat_as_local   = NULL;
981 uschar *hosts_connection_nolog = NULL;
982
983 int     ignore_bounce_errors_after = 10*7*24*60*60;  /* 10 weeks */
984 uschar *ignore_fromline_hosts  = NULL;
985 int     inetd_wait_timeout     = -1;
986 uschar *initial_cwd            = NULL;
987 uschar *interface_address      = NULL;
988 int     interface_port         = -1;
989 uschar *iterate_item           = NULL;
990
991 int     journal_fd             = -1;
992
993 uschar *keep_environment       = NULL;
994
995 int     keep_malformed         = 4*24*60*60;    /* 4 days */
996
997 uschar *eldap_dn               = NULL;
998 int     load_average           = -2;
999 uschar *local_from_prefix      = NULL;
1000 uschar *local_from_suffix      = NULL;
1001
1002 #if HAVE_IPV6
1003 uschar *local_interfaces       = US"<; ::0 ; 0.0.0.0";
1004 #else
1005 uschar *local_interfaces       = US"0.0.0.0";
1006 #endif
1007
1008 #ifdef HAVE_LOCAL_SCAN
1009 uschar *local_scan_data        = NULL;
1010 int     local_scan_timeout     = 5*60;
1011 #endif
1012 gid_t   local_user_gid         = (gid_t)(-1);
1013 uid_t   local_user_uid         = (uid_t)(-1);
1014
1015 tree_node *localpartlist_anchor= NULL;
1016 int     localpartlist_count    = 0;
1017 uschar *log_buffer             = NULL;
1018
1019 int     log_default[]          = { /* for initializing log_selector */
1020   Li_acl_warn_skipped,
1021   Li_connection_reject,
1022   Li_delay_delivery,
1023   Li_dkim,
1024   Li_dnslist_defer,
1025   Li_etrn,
1026   Li_host_lookup_failed,
1027   Li_lost_incoming_connection,
1028   Li_outgoing_interface, /* see d_log_interface in deliver.c */
1029   Li_msg_id,
1030   Li_queue_run,
1031   Li_rejected_header,
1032   Li_retry_defer,
1033   Li_sender_verify_fail,
1034   Li_size_reject,
1035   Li_skip_delivery,
1036   Li_smtp_confirmation,
1037   Li_tls_certificate_verified,
1038   Li_tls_cipher,
1039   -1
1040 };
1041
1042 uschar *log_file_path          = US LOG_FILE_PATH
1043                            "\0<--------------Space to patch log_file_path->";
1044
1045 int     log_notall[]           = {
1046   -1
1047 };
1048 bit_table log_options[]        = { /* must be in alphabetical order,
1049                                 with definitions from enum logbit. */
1050   BIT_TABLE(L, 8bitmime),
1051   BIT_TABLE(L, acl_warn_skipped),
1052   BIT_TABLE(L, address_rewrite),
1053   BIT_TABLE(L, all),
1054   BIT_TABLE(L, all_parents),
1055   BIT_TABLE(L, arguments),
1056   BIT_TABLE(L, connection_reject),
1057   BIT_TABLE(L, delay_delivery),
1058   BIT_TABLE(L, deliver_time),
1059   BIT_TABLE(L, delivery_size),
1060 #ifndef DISABLE_DKIM
1061   BIT_TABLE(L, dkim),
1062   BIT_TABLE(L, dkim_verbose),
1063 #endif
1064   BIT_TABLE(L, dnslist_defer),
1065   BIT_TABLE(L, dnssec),
1066   BIT_TABLE(L, etrn),
1067   BIT_TABLE(L, host_lookup_failed),
1068   BIT_TABLE(L, ident_timeout),
1069   BIT_TABLE(L, incoming_interface),
1070   BIT_TABLE(L, incoming_port),
1071   BIT_TABLE(L, lost_incoming_connection),
1072   BIT_TABLE(L, millisec),
1073   BIT_TABLE(L, msg_id),
1074   BIT_TABLE(L, msg_id_created),
1075   BIT_TABLE(L, outgoing_interface),
1076   BIT_TABLE(L, outgoing_port),
1077   BIT_TABLE(L, pid),
1078   BIT_TABLE(L, pipelining),
1079 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1080   BIT_TABLE(L, proxy),
1081 #endif
1082   BIT_TABLE(L, queue_run),
1083   BIT_TABLE(L, queue_time),
1084   BIT_TABLE(L, queue_time_overall),
1085   BIT_TABLE(L, receive_time),
1086   BIT_TABLE(L, received_recipients),
1087   BIT_TABLE(L, received_sender),
1088   BIT_TABLE(L, rejected_header),
1089   { US"rejected_headers", Li_rejected_header },
1090   BIT_TABLE(L, retry_defer),
1091   BIT_TABLE(L, return_path_on_delivery),
1092   BIT_TABLE(L, sender_on_delivery),
1093   BIT_TABLE(L, sender_verify_fail),
1094   BIT_TABLE(L, size_reject),
1095   BIT_TABLE(L, skip_delivery),
1096   BIT_TABLE(L, smtp_confirmation),
1097   BIT_TABLE(L, smtp_connection),
1098   BIT_TABLE(L, smtp_incomplete_transaction),
1099   BIT_TABLE(L, smtp_mailauth),
1100   BIT_TABLE(L, smtp_no_mail),
1101   BIT_TABLE(L, smtp_protocol_error),
1102   BIT_TABLE(L, smtp_syntax_error),
1103   BIT_TABLE(L, subject),
1104   BIT_TABLE(L, tls_certificate_verified),
1105   BIT_TABLE(L, tls_cipher),
1106   BIT_TABLE(L, tls_peerdn),
1107   BIT_TABLE(L, tls_resumption),
1108   BIT_TABLE(L, tls_sni),
1109   BIT_TABLE(L, unknown_in_list),
1110 };
1111 int     log_options_count      = nelem(log_options);
1112
1113 int     log_reject_target      = 0;
1114 unsigned int log_selector[log_selector_size]; /* initialized in main() */
1115 uschar *log_selector_string    = NULL;
1116 FILE   *log_stderr             = NULL;
1117 uschar *login_sender_address   = NULL;
1118 uschar *lookup_dnssec_authenticated = NULL;
1119 int     lookup_open_max        = 25;
1120 uschar *lookup_value           = NULL;
1121
1122 macro_item *macros_user        = NULL;
1123 uschar *mailstore_basename     = NULL;
1124 #ifdef WITH_CONTENT_SCAN
1125 uschar *malware_name           = NULL;  /* Virus Name */
1126 #endif
1127 int     max_received_linelength= 0;
1128 int     max_username_length    = 0;
1129 int     message_age            = 0;
1130 uschar *message_body           = NULL;
1131 uschar *message_body_end       = NULL;
1132 int     message_body_size      = 0;
1133 int     message_body_visible   = 500;
1134 int     message_ended          = END_NOTSTARTED;
1135 uschar *message_headers        = NULL;
1136 uschar *message_id;
1137 uschar *message_id_domain      = NULL;
1138 uschar *message_id_text        = NULL;
1139 struct timeval message_id_tv   = { 0, 0 };
1140 uschar  message_id_option[MESSAGE_ID_LENGTH + 3];
1141 uschar *message_id_external;
1142 int     message_linecount      = 0;
1143 int     message_size           = 0;
1144 uschar *message_size_limit     = US"50M";
1145 #ifdef SUPPORT_I18N
1146 int     message_utf8_downconvert = 0;   /* -1 ifneeded; 0 never; 1 always */
1147 #endif
1148 uschar  message_subdir[2]      = { 0, 0 };
1149 uschar *message_reference      = NULL;
1150
1151 /* MIME ACL expandables */
1152 #ifdef WITH_CONTENT_SCAN
1153 int     mime_anomaly_level     = 0;
1154 const uschar *mime_anomaly_text      = NULL;
1155 uschar *mime_boundary          = NULL;
1156 uschar *mime_charset           = NULL;
1157 uschar *mime_content_description = NULL;
1158 uschar *mime_content_disposition = NULL;
1159 uschar *mime_content_id        = NULL;
1160 unsigned int mime_content_size = 0;
1161 uschar *mime_content_transfer_encoding = NULL;
1162 uschar *mime_content_type      = NULL;
1163 uschar *mime_decoded_filename  = NULL;
1164 uschar *mime_filename          = NULL;
1165 int     mime_is_multipart      = 0;
1166 int     mime_is_coverletter    = 0;
1167 int     mime_is_rfc822         = 0;
1168 int     mime_part_count        = -1;
1169 #endif
1170
1171 uid_t  *never_users            = NULL;
1172 uschar *notifier_socket        = US"$spool_directory/" NOTIFIER_SOCKET_NAME ;
1173
1174 const int on                   = 1;     /* for setsockopt */
1175 const int off                  = 0;
1176
1177 uid_t   original_euid;
1178 gid_t   originator_gid;
1179 uschar *originator_login       = NULL;
1180 uschar *originator_name        = NULL;
1181 uid_t   originator_uid;
1182 uschar *override_local_interfaces = NULL;
1183 uschar *override_pid_file_path = NULL;
1184
1185 uschar *percent_hack_domains   = NULL;
1186 uschar *pid_file_path          = US PID_FILE_PATH
1187                            "\0<--------------Space to patch pid_file_path->";
1188 #ifndef DISABLE_PIPE_CONNECT
1189 uschar *pipe_connect_advertise_hosts = US"*";
1190 #endif
1191 uschar *pipelining_advertise_hosts = US"*";
1192 uschar *primary_hostname       = NULL;
1193 uschar *process_info;
1194 int     process_info_len       = 0;
1195 uschar *process_log_path       = NULL;
1196 const uschar *process_purpose  = US"fresh-exec";
1197
1198 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1199 uschar *hosts_proxy            = NULL;
1200 uschar *proxy_external_address = NULL;
1201 int     proxy_external_port    = 0;
1202 uschar *proxy_local_address    = NULL;
1203 int     proxy_local_port       = 0;
1204 #endif
1205
1206 uschar *prvscheck_address      = NULL;
1207 uschar *prvscheck_keynum       = NULL;
1208 uschar *prvscheck_result       = NULL;
1209
1210
1211 const uschar *qualify_domain_recipient = NULL;
1212 uschar *qualify_domain_sender  = NULL;
1213 uschar *queue_domains          = NULL;
1214 int     queue_interval         = -1;
1215 uschar *queue_name             = US"";
1216 uschar *queue_name_dest        = NULL;
1217 uschar *queue_only_file        = NULL;
1218 int     queue_only_load        = -1;
1219 uschar *queue_run_max          = US"5";
1220 pid_t   queue_run_pid          = (pid_t)0;
1221 int     queue_run_pipe         = -1;
1222 unsigned queue_size            = 0;
1223 time_t  queue_size_next        = 0;
1224 uschar *queue_smtp_domains     = NULL;
1225
1226 uint32_t random_seed           = 0;
1227 tree_node *ratelimiters_cmd    = NULL;
1228 tree_node *ratelimiters_conn   = NULL;
1229 tree_node *ratelimiters_mail   = NULL;
1230 uschar *raw_active_hostname    = NULL;
1231 uschar *raw_sender             = NULL;
1232 uschar **raw_recipients        = NULL;
1233 int     raw_recipients_count   = 0;
1234
1235 int     rcpt_count             = 0;
1236 int     rcpt_fail_count        = 0;
1237 int     rcpt_defer_count       = 0;
1238 gid_t   real_gid;
1239 uid_t   real_uid;
1240 int     receive_linecount      = 0;
1241 int     receive_messagecount   = 0;
1242 int     receive_timeout        = 0;
1243 int     received_count         = 0;
1244 uschar *received_for           = NULL;
1245
1246 /*  This is the default text for Received headers generated by Exim. The
1247 date  will be automatically added on the end. */
1248
1249 uschar *received_header_text   = US
1250      "Received: "
1251      "${if def:sender_rcvhost {from $sender_rcvhost\n\t}"
1252        "{${if def:sender_ident {from ${quote_local_part:$sender_ident} }}"
1253          "${if def:sender_helo_name {(helo=$sender_helo_name)\n\t}}}}"
1254      "by $primary_hostname "
1255      "${if def:received_protocol {with $received_protocol }}"
1256 #ifndef DISABLE_TLS
1257      "${if def:tls_in_ver        { ($tls_in_ver)}}"
1258      "${if def:tls_in_cipher_std { tls $tls_in_cipher_std\n\t}}"
1259 #endif
1260      "(Exim $version_number)\n\t"
1261      "${if def:sender_address {(envelope-from <$sender_address>)\n\t}}"
1262      "id $message_exim_id"
1263      "${if def:received_for {\n\tfor $received_for}}"
1264      "\0<---------------Space to patch received_header_text->";
1265
1266 int     received_headers_max   = 30;
1267 uschar *received_protocol      = NULL;
1268 struct timeval received_time   = { 0, 0 };
1269 struct timeval received_time_taken = { 0, 0 };
1270 uschar *recipient_data         = NULL;
1271 uschar *recipient_unqualified_hosts = NULL;
1272 uschar *recipient_verify_failure = NULL;
1273 int     recipients_count       = 0;
1274 recipient_item  *recipients_list = NULL;
1275 int     recipients_list_max    = 0;
1276 int     recipients_max         = 50000;
1277 const pcre *regex_AUTH         = NULL;
1278 const pcre *regex_check_dns_names = NULL;
1279 const pcre *regex_From         = NULL;
1280 const pcre *regex_IGNOREQUOTA  = NULL;
1281 const pcre *regex_PIPELINING   = NULL;
1282 const pcre *regex_SIZE         = NULL;
1283 #ifndef DISABLE_PIPE_CONNECT
1284 const pcre *regex_EARLY_PIPE   = NULL;
1285 #endif
1286 const pcre *regex_ismsgid      = NULL;
1287 const pcre *regex_smtp_code    = NULL;
1288 uschar *regex_vars[REGEX_VARS];
1289 #ifdef WHITELIST_D_MACROS
1290 const pcre *regex_whitelisted_macro = NULL;
1291 #endif
1292 #ifdef WITH_CONTENT_SCAN
1293 uschar *regex_match_string     = NULL;
1294 #endif
1295 int     remote_delivery_count  = 0;
1296 int     remote_max_parallel    = 2;
1297 uschar *remote_sort_domains    = NULL;
1298 int     retry_data_expire      = 7*24*60*60;
1299 int     retry_interval_max     = 24*60*60;
1300 int     retry_maximum_timeout  = 0;        /* set from retry config */
1301 retry_config  *retries         = NULL;
1302 uschar *return_path            = NULL;
1303 int     rewrite_existflags     = 0;
1304 uschar *rfc1413_hosts          = US"@[]";
1305 int     rfc1413_query_timeout  = 0;
1306 uid_t   root_gid               = ROOT_GID;
1307 uid_t   root_uid               = ROOT_UID;
1308
1309 router_instance  *routers  = NULL;
1310 router_instance  router_defaults = {
1311     .next =                     NULL,
1312     .name =                     NULL,
1313     .info =                     NULL,
1314     .options_block =            NULL,
1315     .driver_name =              NULL,
1316
1317     .address_data =             NULL,
1318 #ifdef EXPERIMENTAL_BRIGHTMAIL
1319     .bmi_rule =                 NULL,
1320 #endif
1321     .cannot_route_message =     NULL,
1322     .condition =                NULL,
1323     .current_directory =        NULL,
1324     .debug_string =             NULL,
1325     .domains =                  NULL,
1326     .errors_to =                NULL,
1327     .expand_gid =               NULL,
1328     .expand_uid =               NULL,
1329     .expand_more =              NULL,
1330     .expand_unseen =            NULL,
1331     .extra_headers =            NULL,
1332     .fallback_hosts =           NULL,
1333     .home_directory =           NULL,
1334     .ignore_target_hosts =      NULL,
1335     .local_parts =              NULL,
1336     .pass_router_name =         NULL,
1337     .prefix =                   NULL,
1338     .redirect_router_name =     NULL,
1339     .remove_headers =           NULL,
1340     .require_files =            NULL,
1341     .router_home_directory =    NULL,
1342     .self =                     US"freeze",
1343     .senders =                  NULL,
1344     .suffix =                   NULL,
1345     .translate_ip_address =     NULL,
1346     .transport_name =           NULL,
1347
1348     .address_test =             TRUE,
1349 #ifdef EXPERIMENTAL_BRIGHTMAIL
1350     .bmi_deliver_alternate =    FALSE,
1351     .bmi_deliver_default =      FALSE,
1352     .bmi_dont_deliver =         FALSE,
1353 #endif
1354     .expn =                     TRUE,
1355     .caseful_local_part =       FALSE,
1356     .check_local_user =         FALSE,
1357     .disable_logging =          FALSE,
1358     .fail_verify_recipient =    FALSE,
1359     .fail_verify_sender =       FALSE,
1360     .gid_set =                  FALSE,
1361     .initgroups =               FALSE,
1362     .log_as_local =             TRUE_UNSET,
1363     .more =                     TRUE,
1364     .pass_on_timeout =          FALSE,
1365     .prefix_optional =          FALSE,
1366     .repeat_use =               TRUE,
1367     .retry_use_local_part =     TRUE_UNSET,
1368     .same_domain_copy_routing = FALSE,
1369     .self_rewrite =             FALSE,
1370     .set =                      NULL,
1371     .suffix_optional =          FALSE,
1372     .verify_only =              FALSE,
1373     .verify_recipient =         TRUE,
1374     .verify_sender =            TRUE,
1375     .uid_set =                  FALSE,
1376     .unseen =                   FALSE,
1377     .dsn_lasthop =              FALSE,
1378
1379     .self_code =                self_freeze,
1380     .uid =                      (uid_t)(-1),
1381     .gid =                      (gid_t)(-1),
1382
1383     .fallback_hostlist =        NULL,
1384     .transport =                NULL,
1385     .pass_router =              NULL,
1386     .redirect_router =          NULL,
1387
1388     .dnssec =                   { .request= US"*", .require=NULL },
1389 };
1390
1391 uschar *router_name            = NULL;
1392 tree_node *router_var          = NULL;
1393
1394 ip_address_item *running_interfaces = NULL;
1395
1396 /* This is a weird one. The following string gets patched in the binary by the
1397 script that sets up a copy of Exim for running in the test harness. It seems
1398 that compilers are now clever, and share constant strings if they can.
1399 Elsewhere in Exim the string "<" is used. The compiler optimization seems to
1400 make use of the end of this string in order to save space. So the patching then
1401 wrecks this. We defeat this optimization by adding some additional characters
1402 onto the end of the string. */
1403
1404 uschar *running_status         = US">>>running<<<" "\0EXTRA";
1405
1406 int     runrc                  = 0;
1407
1408 uschar *search_error_message   = NULL;
1409 uschar *self_hostname          = NULL;
1410 uschar *sender_address         = NULL;
1411 unsigned int sender_address_cache[(MAX_NAMED_LIST * 2)/32];
1412 uschar *sender_address_data    = NULL;
1413 uschar *sender_address_unrewritten = NULL;
1414 uschar *sender_data            = NULL;
1415 unsigned int sender_domain_cache[(MAX_NAMED_LIST * 2)/32];
1416 uschar *sender_fullhost        = NULL;
1417 uschar *sender_helo_name       = NULL;
1418 uschar **sender_host_aliases   = &no_aliases;
1419 uschar *sender_host_address    = NULL;
1420 uschar *sender_host_authenticated = NULL;
1421 uschar *sender_host_auth_pubname  = NULL;
1422 unsigned int sender_host_cache[(MAX_NAMED_LIST * 2)/32];
1423 uschar *sender_host_name       = NULL;
1424 int     sender_host_port       = 0;
1425 uschar *sender_ident           = NULL;
1426 uschar *sender_rate            = NULL;
1427 uschar *sender_rate_limit      = NULL;
1428 uschar *sender_rate_period     = NULL;
1429 uschar *sender_rcvhost         = NULL;
1430 uschar *sender_unqualified_hosts = NULL;
1431 uschar *sender_verify_failure = NULL;
1432 address_item *sender_verified_list  = NULL;
1433 address_item *sender_verified_failed = NULL;
1434 int     sender_verified_rc     = -1;
1435 uschar *sending_ip_address     = NULL;
1436 int     sending_port           = -1;
1437 SIGNAL_BOOL sigalrm_seen       = FALSE;
1438 const uschar *sigalarm_setter  = NULL;
1439 uschar **sighup_argv           = NULL;
1440 int     slow_lookup_log        = 0;     /* millisecs, zero disables */
1441 int     smtp_accept_count      = 0;
1442 int     smtp_accept_max        = 20;
1443 int     smtp_accept_max_nonmail= 10;
1444 uschar *smtp_accept_max_nonmail_hosts = US"*";
1445 int     smtp_accept_max_per_connection = 1000;
1446 uschar *smtp_accept_max_per_host = NULL;
1447 int     smtp_accept_queue      = 0;
1448 int     smtp_accept_queue_per_connection = 10;
1449 int     smtp_accept_reserve    = 0;
1450 uschar *smtp_active_hostname   = NULL;
1451 uschar *smtp_banner            = US"$smtp_active_hostname ESMTP "
1452                              "Exim $version_number $tod_full"
1453                              "\0<---------------Space to patch smtp_banner->";
1454 int     smtp_ch_index          = 0;
1455 uschar *smtp_cmd_argument      = NULL;
1456 uschar *smtp_cmd_buffer        = NULL;
1457 struct timeval smtp_connection_start  = {0,0};
1458 uschar  smtp_connection_had[SMTP_HBUFF_SIZE];
1459 int     smtp_connect_backlog   = 20;
1460 double  smtp_delay_mail        = 0.0;
1461 double  smtp_delay_rcpt        = 0.0;
1462 FILE   *smtp_in                = NULL;
1463 int     smtp_load_reserve      = -1;
1464 int     smtp_mailcmd_count     = 0;
1465 FILE   *smtp_out               = NULL;
1466 uschar *smtp_etrn_command      = NULL;
1467 int     smtp_max_synprot_errors= 3;
1468 int     smtp_max_unknown_commands = 3;
1469 uschar *smtp_notquit_reason    = NULL;
1470 uschar *smtp_ratelimit_hosts   = NULL;
1471 uschar *smtp_ratelimit_mail    = NULL;
1472 uschar *smtp_ratelimit_rcpt    = NULL;
1473 uschar *smtp_read_error        = US"";
1474 int     smtp_receive_timeout   = 5*60;
1475 uschar *smtp_receive_timeout_s = NULL;
1476 uschar *smtp_reserve_hosts     = NULL;
1477 int     smtp_rlm_base          = 0;
1478 double  smtp_rlm_factor        = 0.0;
1479 int     smtp_rlm_limit         = 0;
1480 int     smtp_rlm_threshold     = INT_MAX;
1481 int     smtp_rlr_base          = 0;
1482 double  smtp_rlr_factor        = 0.0;
1483 int     smtp_rlr_limit         = 0;
1484 int     smtp_rlr_threshold     = INT_MAX;
1485 unsigned smtp_peer_options     = 0;
1486 unsigned smtp_peer_options_wrap= 0;
1487 #ifdef SUPPORT_I18N
1488 uschar *smtputf8_advertise_hosts = US"*";       /* overridden under test-harness */
1489 #endif
1490
1491 #ifdef WITH_CONTENT_SCAN
1492 uschar *spamd_address          = US"127.0.0.1 783";
1493 uschar *spam_bar               = NULL;
1494 uschar *spam_report            = NULL;
1495 uschar *spam_action            = NULL;
1496 uschar *spam_score             = NULL;
1497 uschar *spam_score_int         = NULL;
1498 #endif
1499 #ifdef SUPPORT_SPF
1500 uschar *spf_guess              = US"v=spf1 a/24 mx/24 ptr ?all";
1501 uschar *spf_header_comment     = NULL;
1502 uschar *spf_received           = NULL;
1503 uschar *spf_result             = NULL;
1504 uschar *spf_smtp_comment       = NULL;
1505 uschar *spf_smtp_comment_template
1506                     /* Used to be: "Please%_see%_http://www.open-spf.org/Why?id=%{S}&ip=%{C}&receiver=%{R}" */
1507                                = US"Please%_see%_http://www.open-spf.org/Why";
1508
1509 #endif
1510
1511 FILE   *spool_data_file        = NULL;
1512 uschar *spool_directory        = US SPOOL_DIRECTORY
1513                            "\0<--------------Space to patch spool_directory->";
1514 #ifdef EXPERIMENTAL_SRS
1515 uschar *srs_config             = NULL;
1516 uschar *srs_db_address         = NULL;
1517 uschar *srs_db_key             = NULL;
1518 int     srs_hashlength         = 6;
1519 int     srs_hashmin            = -1;
1520 int     srs_maxage             = 31;
1521 uschar *srs_orig_recipient     = NULL;
1522 uschar *srs_orig_sender        = NULL;
1523 uschar *srs_recipient          = NULL;
1524 uschar *srs_secrets            = NULL;
1525 uschar *srs_status             = NULL;
1526 #endif
1527 #ifdef EXPERIMENTAL_SRS_NATIVE
1528 uschar *srs_recipient          = NULL;
1529 #endif
1530 int     string_datestamp_offset= -1;
1531 int     string_datestamp_length= 0;
1532 int     string_datestamp_type  = -1;
1533 uschar *submission_domain      = NULL;
1534 uschar *submission_name        = NULL;
1535 int     syslog_facility        = LOG_MAIL;
1536 uschar *syslog_processname     = US"exim";
1537 uschar *system_filter          = NULL;
1538
1539 uschar *system_filter_directory_transport = NULL;
1540 uschar *system_filter_file_transport = NULL;
1541 uschar *system_filter_pipe_transport = NULL;
1542 uschar *system_filter_reply_transport = NULL;
1543
1544 gid_t   system_filter_gid      = 0;
1545 uid_t   system_filter_uid      = (uid_t)-1;
1546
1547 blob    tcp_fastopen_nodata    = { .data = NULL, .len = 0 };
1548 tfo_state_t tcp_out_fastopen   = TFO_NOT_USED;
1549 #ifdef USE_TCP_WRAPPERS
1550 uschar *tcp_wrappers_daemon_name = US TCP_WRAPPERS_DAEMON_NAME;
1551 #endif
1552 int     test_harness_load_avg  = 0;
1553 int     thismessage_size_limit = 0;
1554 int     timeout_frozen_after   = 0;
1555 #ifdef MEASURE_TIMING
1556 struct timeval timestamp_startup;
1557 #endif
1558
1559 transport_instance  *transports = NULL;
1560
1561 transport_instance  transport_defaults = {
1562     .next =                     NULL,
1563     .name =                     NULL,
1564     .info =                     NULL,
1565     .options_block =            NULL,
1566     .driver_name =              NULL,
1567     .setup =                    NULL,
1568     .batch_max =                1,
1569     .batch_id =                 NULL,
1570     .home_dir =                 NULL,
1571     .current_dir =              NULL,
1572     .expand_multi_domain =      NULL,
1573     .multi_domain =             TRUE,
1574     .overrides_hosts =          FALSE,
1575     .max_addresses =            100,
1576     .connection_max_messages =  500,
1577     .deliver_as_creator =       FALSE,
1578     .disable_logging =          FALSE,
1579     .initgroups =               FALSE,
1580     .uid_set =                  FALSE,
1581     .gid_set =                  FALSE,
1582     .uid =                      (uid_t)(-1),
1583     .gid =                      (gid_t)(-1),
1584     .expand_uid =               NULL,
1585     .expand_gid =               NULL,
1586     .warn_message =             NULL,
1587     .shadow =                   NULL,
1588     .shadow_condition =         NULL,
1589     .filter_command =           NULL,
1590     .add_headers =              NULL,
1591     .remove_headers =           NULL,
1592     .return_path =              NULL,
1593     .debug_string =             NULL,
1594     .max_parallel =             NULL,
1595     .message_size_limit =       NULL,
1596     .headers_rewrite =          NULL,
1597     .rewrite_rules =            NULL,
1598     .rewrite_existflags =       0,
1599     .filter_timeout =           300,
1600     .body_only =                FALSE,
1601     .delivery_date_add =        FALSE,
1602     .envelope_to_add =          FALSE,
1603     .headers_only =             FALSE,
1604     .rcpt_include_affixes =     FALSE,
1605     .return_path_add =          FALSE,
1606     .return_output =            FALSE,
1607     .return_fail_output =       FALSE,
1608     .log_output =               FALSE,
1609     .log_fail_output =          FALSE,
1610     .log_defer_output =         FALSE,
1611     .retry_use_local_part =     TRUE_UNSET,     /* retry_use_local_part: BOOL, but set neither
1612                                                  1 nor 0 so can detect unset */
1613 #ifndef DISABLE_EVENT
1614    .event_action =              NULL
1615 #endif
1616 };
1617
1618 int     transport_count;
1619 uschar *transport_name          = NULL;
1620 int     transport_newlines;
1621 const uschar **transport_filter_argv  = NULL;
1622 int     transport_filter_timeout;
1623 int     transport_write_timeout= 0;
1624
1625 tree_node  *tree_dns_fails     = NULL;
1626 tree_node  *tree_duplicates    = NULL;
1627 tree_node  *tree_nonrecipients = NULL;
1628 tree_node  *tree_unusable      = NULL;
1629
1630 gid_t  *trusted_groups         = NULL;
1631 uid_t  *trusted_users          = NULL;
1632 uschar *timezone_string        = US TIMEZONE_DEFAULT;
1633
1634 uschar *unknown_login          = NULL;
1635 uschar *unknown_username       = NULL;
1636 uschar *untrusted_set_sender   = NULL;
1637
1638 /*  A regex for matching a "From_" line in an incoming message, in the form
1639
1640     From ph10 Fri Jan  5 12:35 GMT 1996
1641
1642 which  the "mail" commands send to the MTA (undocumented, of course), or in
1643 the  form
1644
1645     From ph10 Fri, 7 Jan 97 14:00:00 GMT
1646
1647 which  is apparently used by some UUCPs, despite it not being in RFC 976.
1648 Because  of variations in time formats, just match up to the minutes. That
1649 should  be sufficient. Examples have been seen of time fields like 12:1:03,
1650 so  just require one digit for hours and minutes. The weekday is also absent
1651 in  some forms. */
1652
1653 uschar *uucp_from_pattern      = US
1654    "^From\\s+(\\S+)\\s+(?:[a-zA-Z]{3},?\\s+)?"    /* Common start */
1655    "(?:"                                          /* Non-extracting bracket */
1656    "[a-zA-Z]{3}\\s+\\d?\\d|"                      /* First form */
1657    "\\d?\\d\\s+[a-zA-Z]{3}\\s+\\d\\d(?:\\d\\d)?"  /* Second form */
1658    ")"                                            /* End alternation */
1659    "\\s+\\d\\d?:\\d\\d?";                         /* Start of time */
1660
1661 uschar *uucp_from_sender       = US"$1";
1662
1663 uschar *verify_mode            = NULL;
1664 uschar *version_copyright      =
1665  US"Copyright (c) University of Cambridge, 1995 - 2018\n"
1666    "(c) The Exim Maintainers and contributors in ACKNOWLEDGMENTS file, 2007 - 2018";
1667 uschar *version_date           = US"?";
1668 uschar *version_cnumber        = US"????";
1669 uschar *version_string         = US"?";
1670
1671 uschar *warn_message_file      = NULL;
1672 int     warning_count          = 0;
1673 uschar *warnmsg_delay          = NULL;
1674 uschar *warnmsg_recipients     = NULL;
1675
1676
1677 /*  End of globals.c */