Harden plaintext authenticator
[users/heiko/exim.git] / src / src / globals.c
1 /*************************************************
2 *     Exim - an Internet mail transport agent    *
3 *************************************************/
4
5 /* Copyright (c) University of Cambridge 1995 - 2018 */
6 /* See the file NOTICE for conditions of use and distribution. */
7
8 /* All the global variables are defined together in this one module, so
9 that they are easy to find. */
10
11 #include "exim.h"
12
13
14 /* Generic options for auths, all of which live inside auth_instance
15 data blocks and hence have the opt_public flag set. */
16
17 optionlist optionlist_auths[] = {
18   { "client_condition", opt_stringptr | opt_public,
19                  (void *)(offsetof(auth_instance, client_condition)) },
20   { "client_set_id", opt_stringptr | opt_public,
21                  (void *)(offsetof(auth_instance, set_client_id)) },
22   { "driver",        opt_stringptr | opt_public,
23                  (void *)(offsetof(auth_instance, driver_name)) },
24   { "public_name",   opt_stringptr | opt_public,
25                  (void *)(offsetof(auth_instance, public_name)) },
26   { "server_advertise_condition", opt_stringptr | opt_public,
27                  (void *)(offsetof(auth_instance, advertise_condition))},
28   { "server_condition", opt_stringptr | opt_public,
29                  (void *)(offsetof(auth_instance, server_condition)) },
30   { "server_debug_print", opt_stringptr | opt_public,
31                  (void *)(offsetof(auth_instance, server_debug_string)) },
32   { "server_mail_auth_condition", opt_stringptr | opt_public,
33                  (void *)(offsetof(auth_instance, mail_auth_condition)) },
34   { "server_set_id", opt_stringptr | opt_public,
35                  (void *)(offsetof(auth_instance, set_id)) }
36 };
37
38 int     optionlist_auths_size = nelem(optionlist_auths);
39
40 /* An empty host aliases list. */
41
42 uschar *no_aliases             = NULL;
43
44
45 /* For comments on these variables, see globals.h. I'm too idle to
46 duplicate them here... */
47
48 #ifdef EXIM_PERL
49 uschar *opt_perl_startup       = NULL;
50 BOOL    opt_perl_at_start      = FALSE;
51 BOOL    opt_perl_started       = FALSE;
52 BOOL    opt_perl_taintmode     = FALSE;
53 #endif
54
55 #ifdef EXPAND_DLFUNC
56 tree_node *dlobj_anchor        = NULL;
57 #endif
58
59 #ifdef LOOKUP_IBASE
60 uschar *ibase_servers          = NULL;
61 #endif
62
63 #ifdef LOOKUP_LDAP
64 uschar *eldap_ca_cert_dir      = NULL;
65 uschar *eldap_ca_cert_file     = NULL;
66 uschar *eldap_cert_file        = NULL;
67 uschar *eldap_cert_key         = NULL;
68 uschar *eldap_cipher_suite     = NULL;
69 uschar *eldap_default_servers  = NULL;
70 uschar *eldap_require_cert     = NULL;
71 int     eldap_version          = -1;
72 BOOL    eldap_start_tls        = FALSE;
73 #endif
74
75 #ifdef LOOKUP_MYSQL
76 uschar *mysql_servers          = NULL;
77 #endif
78
79 #ifdef LOOKUP_ORACLE
80 uschar *oracle_servers         = NULL;
81 #endif
82
83 #ifdef LOOKUP_PGSQL
84 uschar *pgsql_servers          = NULL;
85 #endif
86
87 #ifdef LOOKUP_REDIS
88 uschar *redis_servers          = NULL;
89 #endif
90
91 #ifdef LOOKUP_SQLITE
92 int     sqlite_lock_timeout    = 5;
93 #endif
94
95 #ifdef SUPPORT_MOVE_FROZEN_MESSAGES
96 BOOL    move_frozen_messages   = FALSE;
97 #endif
98
99 /* These variables are outside the #ifdef because it keeps the code less
100 cluttered in several places (e.g. during logging) if we can always refer to
101 them. Also, the tls_ variables are now always visible.  Note that these are
102 only used for smtp connections, not for service-daemon access. */
103
104 tls_support tls_in = {
105  .active =              {.sock = -1},
106  .bits =                0,
107  .certificate_verified = FALSE,
108 #ifdef SUPPORT_DANE
109  .dane_verified =       FALSE,
110  .tlsa_usage =          0,
111 #endif
112  .cipher =              NULL,
113  .on_connect =          FALSE,
114  .on_connect_ports =    NULL,
115  .ourcert =             NULL,
116  .peercert =            NULL,
117  .peerdn =              NULL,
118  .sni =                 NULL,
119  .ocsp =                OCSP_NOT_REQ
120 };
121 tls_support tls_out = {
122  .active =              {.sock = -1},
123  .bits =                0,
124  .certificate_verified = FALSE,
125 #ifdef SUPPORT_DANE
126  .dane_verified =       FALSE,
127  .tlsa_usage =          0,
128 #endif
129  .cipher =              NULL,
130  .on_connect =          FALSE,
131  .on_connect_ports =    NULL,
132  .ourcert =             NULL,
133  .peercert =            NULL,
134  .peerdn =              NULL,
135  .sni =                 NULL,
136  .ocsp =                OCSP_NOT_REQ
137 };
138
139 uschar *dsn_envid              = NULL;
140 int     dsn_ret                = 0;
141 const pcre  *regex_DSN         = NULL;
142 uschar *dsn_advertise_hosts    = NULL;
143
144 #ifdef SUPPORT_TLS
145 BOOL    gnutls_compat_mode     = FALSE;
146 BOOL    gnutls_allow_auto_pkcs11 = FALSE;
147 uschar *openssl_options        = NULL;
148 const pcre *regex_STARTTLS     = NULL;
149 uschar *tls_advertise_hosts    = US"*";
150 uschar *tls_certificate        = NULL;
151 uschar *tls_crl                = NULL;
152 /* This default matches NSS DH_MAX_P_BITS value at current time (2012), because
153 that's the interop problem which has been observed: GnuTLS suggesting a higher
154 bit-count as "NORMAL" (2432) and Thunderbird dropping connection. */
155 int     tls_dh_max_bits        = 2236;
156 uschar *tls_dhparam            = NULL;
157 uschar *tls_eccurve            = US"auto";
158 # ifndef DISABLE_OCSP
159 uschar *tls_ocsp_file          = NULL;
160 # endif
161 uschar *tls_privatekey         = NULL;
162 BOOL    tls_remember_esmtp     = FALSE;
163 uschar *tls_require_ciphers    = NULL;
164 uschar *tls_try_verify_hosts   = NULL;
165 uschar *tls_verify_certificates= US"system";
166 uschar *tls_verify_hosts       = NULL;
167 #else   /*!SUPPORT_TLS*/
168 uschar *tls_advertise_hosts    = NULL;
169 #endif
170
171 #ifndef DISABLE_PRDR
172 /* Per Recipient Data Response variables */
173 BOOL    prdr_enable            = FALSE;
174 BOOL    prdr_requested         = FALSE;
175 const pcre *regex_PRDR         = NULL;
176 #endif
177
178 #ifdef SUPPORT_I18N
179 const pcre *regex_UTF8         = NULL;
180 #endif
181
182 /* Input-reading functions for messages, so we can use special ones for
183 incoming TCP/IP. The defaults use stdin. We never need these for any
184 stand-alone tests. */
185
186 #if !defined(STAND_ALONE) && !defined(MACRO_PREDEF)
187 int (*lwr_receive_getc)(unsigned) = stdin_getc;
188 uschar * (*lwr_receive_getbuf)(unsigned *) = NULL;
189 int (*lwr_receive_ungetc)(int) = stdin_ungetc;
190 int (*receive_getc)(unsigned)  = stdin_getc;
191 uschar * (*receive_getbuf)(unsigned *)  = NULL;
192 void (*receive_get_cache)(void)= NULL;
193 int (*receive_ungetc)(int)     = stdin_ungetc;
194 int (*receive_feof)(void)      = stdin_feof;
195 int (*receive_ferror)(void)    = stdin_ferror;
196 BOOL (*receive_smtp_buffered)(void) = NULL;   /* Only used for SMTP */
197 #endif
198
199
200 /* List of per-address expansion variables for clearing and saving/restoring
201 when verifying one address while routing/verifying another. We have to have
202 the size explicit, because it is referenced from more than one module. */
203
204 const uschar **address_expansions[ADDRESS_EXPANSIONS_COUNT] = {
205   CUSS &deliver_address_data,
206   CUSS &deliver_domain,
207   CUSS &deliver_domain_data,
208   CUSS &deliver_domain_orig,
209   CUSS &deliver_domain_parent,
210   CUSS &deliver_localpart,
211   CUSS &deliver_localpart_data,
212   CUSS &deliver_localpart_orig,
213   CUSS &deliver_localpart_parent,
214   CUSS &deliver_localpart_prefix,
215   CUSS &deliver_localpart_suffix,
216   CUSS (uschar **)(&deliver_recipients),
217   CUSS &deliver_host,
218   CUSS &deliver_home,
219   CUSS &address_file,
220   CUSS &address_pipe,
221   CUSS &self_hostname,
222   NULL };
223
224 int address_expansions_count = sizeof(address_expansions)/sizeof(uschar **);
225
226 /******************************************************************************/
227 /* General global variables.  Boolean flags are done as a group
228 so that only one bit each is needed, packed, for all those we never
229 need to take a pointer - and only a char for the rest.
230 This means a struct, unfortunately since it clutters the sourcecode. */
231
232 struct global_flags f =
233 {
234         .acl_temp_details       = FALSE,
235         .active_local_from_check = FALSE,
236         .active_local_sender_retain = FALSE,
237         .address_test_mode      = FALSE,
238         .admin_user             = FALSE,
239         .allow_auth_unadvertised= FALSE,
240         .allow_unqualified_recipient = TRUE,    /* For local messages */
241         .allow_unqualified_sender = TRUE,       /* Reset for SMTP */
242         .authentication_local   = FALSE,
243
244         .background_daemon      = TRUE,
245
246         .chunking_offered       = FALSE,
247         .config_changed         = FALSE,
248         .continue_more          = FALSE,
249
250         .daemon_listen          = FALSE,
251         .debug_daemon           = FALSE,
252         .deliver_firsttime      = FALSE,
253         .deliver_force          = FALSE,
254         .deliver_freeze         = FALSE,
255         .deliver_force_thaw     = FALSE,
256         .deliver_manual_thaw    = FALSE,
257         .deliver_selectstring_regex = FALSE,
258         .deliver_selectstring_sender_regex = FALSE,
259         .disable_callout_flush  = FALSE,
260         .disable_delay_flush    = FALSE,
261         .disable_logging        = FALSE,
262 #ifndef DISABLE_DKIM
263         .dkim_disable_verify      = FALSE,
264 #endif
265 #ifdef EXPERIMENTAL_DMARC
266         .dmarc_has_been_checked  = FALSE,
267         .dmarc_disable_verify    = FALSE,
268         .dmarc_enable_forensic   = FALSE,
269 #endif
270         .dont_deliver           = FALSE,
271         .dot_ends               = TRUE,
272
273         .enable_dollar_recipients = FALSE,
274         .expand_string_forcedfail = FALSE,
275
276         .filter_running         = FALSE,
277
278         .header_rewritten       = FALSE,
279         .helo_verified          = FALSE,
280         .helo_verify_failed     = FALSE,
281         .host_checking_callout  = FALSE,
282         .host_find_failed_syntax= FALSE,
283
284         .inetd_wait_mode        = FALSE,
285         .is_inetd               = FALSE,
286
287         .local_error_message    = FALSE,
288         .log_testing_mode       = FALSE,
289
290 #ifdef WITH_CONTENT_SCAN
291         .no_mbox_unspool        = FALSE,
292 #endif
293         .no_multiline_responses = FALSE,
294
295         .parse_allow_group      = FALSE,
296         .parse_found_group      = FALSE,
297         .pipelining_enable      = TRUE,
298 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
299         .proxy_session_failed   = FALSE,
300 #endif
301
302         .queue_2stage           = FALSE,
303         .queue_only_policy      = FALSE,
304         .queue_run_first_delivery = FALSE,
305         .queue_run_force        = FALSE,
306         .queue_run_local        = FALSE,
307         .queue_running          = FALSE,
308         .queue_smtp             = FALSE,
309
310         .really_exim            = TRUE,
311         .receive_call_bombout   = FALSE,
312         .recipients_discarded   = FALSE,
313         .running_in_test_harness = FALSE,
314
315         .search_find_defer      = FALSE,
316         .sender_address_forced  = FALSE,
317         .sender_host_notsocket  = FALSE,
318         .sender_host_unknown    = FALSE,
319         .sender_local           = FALSE,
320         .sender_name_forced     = FALSE,
321         .sender_set_untrusted   = FALSE,
322         .smtp_authenticated     = FALSE,
323 #ifdef EXPERIMENTAL_PIPE_CONNECT
324         .smtp_in_early_pipe_advertised = FALSE,
325         .smtp_in_early_pipe_no_auth = FALSE,
326         .smtp_in_early_pipe_used = FALSE,
327 #endif
328         .smtp_in_pipelining_advertised = FALSE,
329         .smtp_in_pipelining_used = FALSE,
330         .spool_file_wireformat  = FALSE,
331         .submission_mode        = FALSE,
332         .suppress_local_fixups  = FALSE,
333         .suppress_local_fixups_default = FALSE,
334         .synchronous_delivery   = FALSE,
335         .system_filtering       = FALSE,
336
337         .tcp_fastopen_ok        = FALSE,
338         .tcp_in_fastopen        = FALSE,
339         .tcp_in_fastopen_data   = FALSE,
340         .tcp_in_fastopen_logged = FALSE,
341         .tcp_out_fastopen_logged= FALSE,
342         .timestamps_utc         = FALSE,
343         .transport_filter_timed_out = FALSE,
344         .trusted_caller         = FALSE,
345         .trusted_config         = TRUE,
346 };
347
348 /******************************************************************************/
349 /* These are the flags which are either variables or mainsection options,
350 so an address is needed for access, or are exported to local_scan. */
351
352 BOOL    accept_8bitmime        = TRUE; /* deliberately not RFC compliant */
353 BOOL    allow_domain_literals  = FALSE;
354 BOOL    allow_mx_to_ip         = FALSE;
355 BOOL    allow_utf8_domains     = FALSE;
356 BOOL    authentication_failed  = FALSE;
357
358 BOOL    bounce_return_body     = TRUE;
359 BOOL    bounce_return_message  = TRUE;
360 BOOL    check_rfc2047_length   = TRUE;
361 BOOL    commandline_checks_require_admin = FALSE;
362
363 #ifdef EXPERIMENTAL_DCC
364 BOOL    dcc_direct_add_header  = FALSE;
365 #endif
366 BOOL    debug_store            = FALSE;
367 BOOL    delivery_date_remove   = TRUE;
368 BOOL    deliver_drop_privilege = FALSE;
369 #ifdef ENABLE_DISABLE_FSYNC
370 BOOL    disable_fsync          = FALSE;
371 #endif
372 BOOL    disable_ipv6           = FALSE;
373 BOOL    dns_csa_use_reverse    = TRUE;
374 BOOL    drop_cr                = FALSE;         /* No longer used */
375
376 BOOL    envelope_to_remove     = TRUE;
377 BOOL    exim_gid_set           = TRUE;          /* This gid is always set */
378 BOOL    exim_uid_set           = TRUE;          /* This uid is always set */
379 BOOL    extract_addresses_remove_arguments = TRUE;
380
381 BOOL    host_checking          = FALSE;
382 BOOL    host_lookup_deferred   = FALSE;
383 BOOL    host_lookup_failed     = FALSE;
384 BOOL    ignore_fromline_local  = FALSE;
385
386 BOOL    local_from_check       = TRUE;
387 BOOL    local_sender_retain    = FALSE;
388 BOOL    log_timezone           = FALSE;
389 BOOL    message_body_newlines  = FALSE;
390 BOOL    message_logs           = TRUE;
391 #ifdef SUPPORT_I18N
392 BOOL    message_smtputf8       = FALSE;
393 #endif
394 BOOL    mua_wrapper            = FALSE;
395
396 BOOL    preserve_message_logs  = FALSE;
397 BOOL    print_topbitchars      = FALSE;
398 BOOL    prod_requires_admin    = TRUE;
399 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
400 BOOL    proxy_session          = FALSE;
401 #endif
402
403 BOOL    queue_list_requires_admin = TRUE;
404 BOOL    queue_only             = FALSE;
405 BOOL    queue_only_load_latch  = TRUE;
406 BOOL    queue_only_override    = TRUE;
407 BOOL    queue_run_in_order     = FALSE;
408 BOOL    recipients_max_reject  = FALSE;
409 BOOL    return_path_remove     = TRUE;
410
411 BOOL    smtp_batched_input     = FALSE;
412 BOOL    sender_helo_dnssec     = FALSE;
413 BOOL    sender_host_dnssec     = FALSE;
414 BOOL    smtp_accept_keepalive  = TRUE;
415 BOOL    smtp_check_spool_space = TRUE;
416 BOOL    smtp_enforce_sync      = TRUE;
417 BOOL    smtp_etrn_serialize    = TRUE;
418 BOOL    smtp_input             = FALSE;
419 BOOL    smtp_return_error_details = FALSE;
420 #ifdef SUPPORT_SPF
421 BOOL    spf_result_guessed     = FALSE;
422 #endif
423 BOOL    split_spool_directory  = FALSE;
424 BOOL    spool_wireformat       = FALSE;
425 #ifdef EXPERIMENTAL_SRS
426 BOOL    srs_usehash            = TRUE;
427 BOOL    srs_usetimestamp       = TRUE;
428 #endif
429 BOOL    strict_acl_vars        = FALSE;
430 BOOL    strip_excess_angle_brackets = FALSE;
431 BOOL    strip_trailing_dot     = FALSE;
432 BOOL    syslog_duplication     = TRUE;
433 BOOL    syslog_pid             = TRUE;
434 BOOL    syslog_timestamp       = TRUE;
435 BOOL    system_filter_gid_set  = FALSE;
436 BOOL    system_filter_uid_set  = FALSE;
437
438 BOOL    tcp_nodelay            = TRUE;
439 BOOL    write_rejectlog        = TRUE;
440
441 /******************************************************************************/
442
443 header_line *acl_added_headers = NULL;
444 tree_node *acl_anchor          = NULL;
445 uschar *acl_arg[9]             = {NULL, NULL, NULL, NULL, NULL,
446                                   NULL, NULL, NULL, NULL};
447 int     acl_narg               = 0;
448
449 int     acl_level              = 0;
450
451 uschar *acl_not_smtp           = NULL;
452 #ifdef WITH_CONTENT_SCAN
453 uschar *acl_not_smtp_mime      = NULL;
454 #endif
455 uschar *acl_not_smtp_start     = NULL;
456 uschar *acl_removed_headers    = NULL;
457 uschar *acl_smtp_auth          = NULL;
458 uschar *acl_smtp_connect       = NULL;
459 uschar *acl_smtp_data          = NULL;
460 #ifndef DISABLE_PRDR
461 uschar *acl_smtp_data_prdr     = US"accept";
462 #endif
463 #ifndef DISABLE_DKIM
464 uschar *acl_smtp_dkim          = NULL;
465 #endif
466 uschar *acl_smtp_etrn          = NULL;
467 uschar *acl_smtp_expn          = NULL;
468 uschar *acl_smtp_helo          = NULL;
469 uschar *acl_smtp_mail          = NULL;
470 uschar *acl_smtp_mailauth      = NULL;
471 #ifdef WITH_CONTENT_SCAN
472 uschar *acl_smtp_mime          = NULL;
473 #endif
474 uschar *acl_smtp_notquit       = NULL;
475 uschar *acl_smtp_predata       = NULL;
476 uschar *acl_smtp_quit          = NULL;
477 uschar *acl_smtp_rcpt          = NULL;
478 uschar *acl_smtp_starttls      = NULL;
479 uschar *acl_smtp_vrfy          = NULL;
480
481 tree_node *acl_var_c           = NULL;
482 tree_node *acl_var_m           = NULL;
483 uschar *acl_verify_message     = NULL;
484 string_item *acl_warn_logged   = NULL;
485
486 /* Names of SMTP places for use in ACL error messages, and corresponding SMTP
487 error codes - keep in step with definitions of ACL_WHERE_xxxx in macros.h. */
488
489 uschar *acl_wherenames[]       = { US"RCPT",
490                                    US"MAIL",
491                                    US"PREDATA",
492                                    US"MIME",
493                                    US"DKIM",
494                                    US"DATA",
495 #ifndef DISABLE_PRDR
496                                    US"PRDR",
497 #endif
498                                    US"non-SMTP",
499                                    US"AUTH",
500                                    US"connection",
501                                    US"ETRN",
502                                    US"EXPN",
503                                    US"EHLO or HELO",
504                                    US"MAILAUTH",
505                                    US"non-SMTP-start",
506                                    US"NOTQUIT",
507                                    US"QUIT",
508                                    US"STARTTLS",
509                                    US"VRFY",
510                                    US"delivery",
511                                    US"unknown"
512                                  };
513
514 uschar *acl_wherecodes[]       = { US"550",     /* RCPT */
515                                    US"550",     /* MAIL */
516                                    US"550",     /* PREDATA */
517                                    US"550",     /* MIME */
518                                    US"550",     /* DKIM */
519                                    US"550",     /* DATA */
520 #ifndef DISABLE_PRDR
521                                    US"550",    /* RCPT PRDR */
522 #endif
523                                    US"0",       /* not SMTP; not relevant */
524                                    US"503",     /* AUTH */
525                                    US"550",     /* connect */
526                                    US"458",     /* ETRN */
527                                    US"550",     /* EXPN */
528                                    US"550",     /* HELO/EHLO */
529                                    US"0",       /* MAILAUTH; not relevant */
530                                    US"0",       /* not SMTP; not relevant */
531                                    US"0",       /* NOTQUIT; not relevant */
532                                    US"0",       /* QUIT; not relevant */
533                                    US"550",     /* STARTTLS */
534                                    US"252",     /* VRFY */
535                                    US"0",       /* delivery; not relevant */
536                                    US"0"        /* unknown; not relevant */
537                                  };
538
539 uschar *add_environment        = NULL;
540 address_item  *addr_duplicate  = NULL;
541
542 address_item address_defaults = {
543   .next =               NULL,
544   .parent =             NULL,
545   .first =              NULL,
546   .dupof =              NULL,
547   .start_router =       NULL,
548   .router =             NULL,
549   .transport =          NULL,
550   .host_list =          NULL,
551   .host_used =          NULL,
552   .fallback_hosts =     NULL,
553   .reply =              NULL,
554   .retries =            NULL,
555   .address =            NULL,
556   .unique =             NULL,
557   .cc_local_part =      NULL,
558   .lc_local_part =      NULL,
559   .local_part =         NULL,
560   .prefix =             NULL,
561   .suffix =             NULL,
562   .domain =             NULL,
563   .address_retry_key =  NULL,
564   .domain_retry_key =   NULL,
565   .current_dir =        NULL,
566   .home_dir =           NULL,
567   .message =            NULL,
568   .user_message =       NULL,
569   .onetime_parent =     NULL,
570   .pipe_expandn =       NULL,
571   .return_filename =    NULL,
572   .self_hostname =      NULL,
573   .shadow_message =     NULL,
574 #ifdef SUPPORT_TLS
575   .cipher =             NULL,
576   .ourcert =            NULL,
577   .peercert =           NULL,
578   .peerdn =             NULL,
579   .ocsp =               OCSP_NOT_REQ,
580 #endif
581 #ifdef EXPERIMENTAL_DSN_INFO
582   .smtp_greeting =      NULL,
583   .helo_response =      NULL,
584 #endif
585   .authenticator =      NULL,
586   .auth_id =            NULL,
587   .auth_sndr =          NULL,
588   .dsn_orcpt =          NULL,
589   .dsn_flags =          0,
590   .dsn_aware =          0,
591   .uid =                (uid_t)(-1),
592   .gid =                (gid_t)(-1),
593   .flags =              { 0 },
594   .domain_cache =       { 0 },                /* domain_cache - any larger array should be zeroed */
595   .localpart_cache =    { 0 },                /* localpart_cache - ditto */
596   .mode =               -1,
597   .more_errno =         0,
598   .delivery_usec =      0,
599   .basic_errno =        ERRNO_UNKNOWNERROR,
600   .child_count =        0,
601   .return_file =        -1,
602   .special_action =     SPECIAL_NONE,
603   .transport_return =   DEFER,
604   .prop = {                                     /* fields that are propagated to children */
605     .address_data =     NULL,
606     .domain_data =      NULL,
607     .localpart_data =   NULL,
608     .errors_address =   NULL,
609     .extra_headers =    NULL,
610     .remove_headers =   NULL,
611 #ifdef EXPERIMENTAL_SRS
612     .srs_sender =       NULL,
613 #endif
614     .ignore_error =     FALSE,
615 #ifdef SUPPORT_I18N
616     .utf8_msg =         FALSE,
617     .utf8_downcvt =     FALSE,
618     .utf8_downcvt_maybe = FALSE
619 #endif
620   }
621 };
622
623 uschar *address_file           = NULL;
624 uschar *address_pipe           = NULL;
625 tree_node *addresslist_anchor  = NULL;
626 int     addresslist_count      = 0;
627 gid_t  *admin_groups           = NULL;
628
629 #ifdef EXPERIMENTAL_ARC
630 struct arc_set *arc_received    = NULL;
631 int     arc_received_instance   = 0;
632 int     arc_oldest_pass         = 0;
633 const uschar *arc_state         = NULL;
634 const uschar *arc_state_reason  = NULL;
635 #endif
636
637 uschar *authenticated_fail_id  = NULL;
638 uschar *authenticated_id       = NULL;
639 uschar *authenticated_sender   = NULL;
640 auth_instance  *auths          = NULL;
641 uschar *auth_advertise_hosts   = US"*";
642 auth_instance auth_defaults    = {
643     .next =             NULL,
644     .name =             NULL,
645     .info =             NULL,
646     .options_block =    NULL,
647     .driver_name =      NULL,
648     .advertise_condition = NULL,
649     .client_condition = NULL,
650     .public_name =      NULL,
651     .set_id =           NULL,
652     .set_client_id =    NULL,
653     .mail_auth_condition = NULL,
654     .server_debug_string = NULL,
655     .server_condition = NULL,
656     .client =           FALSE,
657     .server =           FALSE,
658     .advertised =       FALSE
659 };
660
661 uschar *auth_defer_msg         = US"reason not recorded";
662 uschar *auth_defer_user_msg    = US"";
663 uschar *auth_vars[AUTH_VARS];
664 int     auto_thaw              = 0;
665 #ifdef WITH_CONTENT_SCAN
666 int     av_failed              = FALSE; /* boolean but accessed as vtype_int*/
667 uschar *av_scanner             = US"sophie:/var/run/sophie";  /* AV scanner */
668 #endif
669
670 #if BASE_62 == 62
671 uschar *base62_chars=
672     US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";
673 #else
674 uschar *base62_chars= US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ";
675 #endif
676
677 uschar *bi_command             = NULL;
678 uschar *big_buffer             = NULL;
679 int     big_buffer_size        = BIG_BUFFER_SIZE;
680 #ifdef EXPERIMENTAL_BRIGHTMAIL
681 uschar *bmi_alt_location       = NULL;
682 uschar *bmi_base64_tracker_verdict = NULL;
683 uschar *bmi_base64_verdict     = NULL;
684 uschar *bmi_config_file        = US"/opt/brightmail/etc/brightmail.cfg";
685 int     bmi_deliver            = 1;
686 int     bmi_run                = 0;
687 uschar *bmi_verdicts           = NULL;
688 #endif
689 int     bsmtp_transaction_linecount = 0;
690 int     body_8bitmime          = 0;
691 int     body_linecount         = 0;
692 int     body_zerocount         = 0;
693 uschar *bounce_message_file    = NULL;
694 uschar *bounce_message_text    = NULL;
695 uschar *bounce_recipient       = NULL;
696 int     bounce_return_linesize_limit = 998;
697 int     bounce_return_size_limit = 100*1024;
698 uschar *bounce_sender_authentication = NULL;
699
700 uschar *callout_address        = NULL;
701 int     callout_cache_domain_positive_expire = 7*24*60*60;
702 int     callout_cache_domain_negative_expire = 3*60*60;
703 int     callout_cache_positive_expire = 24*60*60;
704 int     callout_cache_negative_expire = 2*60*60;
705 uschar *callout_random_local_part = US"$primary_hostname-$tod_epoch-testing";
706 uschar *check_dns_names_pattern= US"(?i)^(?>(?(1)\\.|())[^\\W](?>[a-z0-9/_-]*[^\\W])?)+(\\.?)$";
707 int     check_log_inodes       = 100;
708 int_eximarith_t check_log_space = 10*1024;      /* 10K Kbyte == 10MB */
709 int     check_spool_inodes     = 100;
710 int_eximarith_t check_spool_space = 10*1024;    /* 10K Kbyte == 10MB */
711
712 uschar *chunking_advertise_hosts = US"*";
713 unsigned chunking_datasize     = 0;
714 unsigned chunking_data_left    = 0;
715 chunking_state_t chunking_state= CHUNKING_NOT_OFFERED;
716 const pcre *regex_CHUNKING     = NULL;
717
718 uschar *client_authenticator   = NULL;
719 uschar *client_authenticated_id = NULL;
720 uschar *client_authenticated_sender = NULL;
721 int     clmacro_count          = 0;
722 uschar *clmacros[MAX_CLMACROS];
723 FILE   *config_file            = NULL;
724 const uschar *config_filename  = NULL;
725 int     config_lineno          = 0;
726 #ifdef CONFIGURE_GROUP
727 gid_t   config_gid             = CONFIGURE_GROUP;
728 #else
729 gid_t   config_gid             = 0;
730 #endif
731 uschar *config_main_filelist   = US CONFIGURE_FILE
732                          "\0<-----------Space to patch configure_filename->";
733 uschar *config_main_filename   = NULL;
734 uschar *config_main_directory  = NULL;
735
736 #ifdef CONFIGURE_OWNER
737 uid_t   config_uid             = CONFIGURE_OWNER;
738 #else
739 uid_t   config_uid             = 0;
740 #endif
741
742 int     connection_max_messages= -1;
743 uschar *continue_proxy_cipher  = NULL;
744 uschar *continue_hostname      = NULL;
745 uschar *continue_host_address  = NULL;
746 int     continue_sequence      = 1;
747 uschar *continue_transport     = NULL;
748
749 uschar *csa_status             = NULL;
750 cut_t   cutthrough = {
751   .callout_hold_only =  FALSE,                          /* verify-only: normal delivery */
752   .delivery =           FALSE,                          /* when to attempt */
753   .defer_pass =         FALSE,                          /* on defer: spool locally */
754   .is_tls =             FALSE,                          /* not a TLS conn yet */
755   .cctx =               {.sock = -1},                   /* open connection */
756   .nrcpt =              0,                              /* number of addresses */
757 };
758
759 uschar *daemon_smtp_port       = US"smtp";
760 int     daemon_startup_retries = 9;
761 int     daemon_startup_sleep   = 30;
762
763 #ifdef EXPERIMENTAL_DCC
764 uschar *dcc_header             = NULL;
765 uschar *dcc_result             = NULL;
766 uschar *dccifd_address         = US"/usr/local/dcc/var/dccifd";
767 uschar *dccifd_options         = US"header";
768 #endif
769
770 int     debug_fd               = -1;
771 FILE   *debug_file             = NULL;
772 int     debug_notall[]         = {
773   Di_memory,
774   Di_noutf8,
775   -1
776 };
777 bit_table debug_options[]      = { /* must be in alphabetical order and use
778                                  only the enum values from macro.h */
779   BIT_TABLE(D, acl),
780   BIT_TABLE(D, all),
781   BIT_TABLE(D, auth),
782   BIT_TABLE(D, deliver),
783   BIT_TABLE(D, dns),
784   BIT_TABLE(D, dnsbl),
785   BIT_TABLE(D, exec),
786   BIT_TABLE(D, expand),
787   BIT_TABLE(D, filter),
788   BIT_TABLE(D, hints_lookup),
789   BIT_TABLE(D, host_lookup),
790   BIT_TABLE(D, ident),
791   BIT_TABLE(D, interface),
792   BIT_TABLE(D, lists),
793   BIT_TABLE(D, load),
794   BIT_TABLE(D, local_scan),
795   BIT_TABLE(D, lookup),
796   BIT_TABLE(D, memory),
797   BIT_TABLE(D, noutf8),
798   BIT_TABLE(D, pid),
799   BIT_TABLE(D, process_info),
800   BIT_TABLE(D, queue_run),
801   BIT_TABLE(D, receive),
802   BIT_TABLE(D, resolver),
803   BIT_TABLE(D, retry),
804   BIT_TABLE(D, rewrite),
805   BIT_TABLE(D, route),
806   BIT_TABLE(D, timestamp),
807   BIT_TABLE(D, tls),
808   BIT_TABLE(D, transport),
809   BIT_TABLE(D, uid),
810   BIT_TABLE(D, verify),
811 };
812 int     debug_options_count    = nelem(debug_options);
813
814 unsigned int debug_selector    = 0;
815 int     delay_warning[DELAY_WARNING_SIZE] = { DELAY_WARNING_SIZE, 1, 24*60*60 };
816 uschar *delay_warning_condition=
817   US"${if or {"
818             "{ !eq{$h_list-id:$h_list-post:$h_list-subscribe:}{} }"
819             "{ match{$h_precedence:}{(?i)bulk|list|junk} }"
820             "{ match{$h_auto-submitted:}{(?i)auto-generated|auto-replied} }"
821             "} {no}{yes}}";
822 uschar *deliver_address_data   = NULL;
823 int     deliver_datafile       = -1;
824 const uschar *deliver_domain   = NULL;
825 uschar *deliver_domain_data    = NULL;
826 const uschar *deliver_domain_orig = NULL;
827 const uschar *deliver_domain_parent = NULL;
828 time_t  deliver_frozen_at      = 0;
829 uschar *deliver_home           = NULL;
830 const uschar *deliver_host     = NULL;
831 const uschar *deliver_host_address = NULL;
832 int     deliver_host_port      = 0;
833 uschar *deliver_in_buffer      = NULL;
834 ino_t   deliver_inode          = 0;
835 uschar *deliver_localpart      = NULL;
836 uschar *deliver_localpart_data = NULL;
837 uschar *deliver_localpart_orig = NULL;
838 uschar *deliver_localpart_parent = NULL;
839 uschar *deliver_localpart_prefix = NULL;
840 uschar *deliver_localpart_suffix = NULL;
841 uschar *deliver_out_buffer     = NULL;
842 int     deliver_queue_load_max = -1;
843 address_item  *deliver_recipients = NULL;
844 uschar *deliver_selectstring   = NULL;
845 uschar *deliver_selectstring_sender = NULL;
846
847 #ifndef DISABLE_DKIM
848 unsigned dkim_collect_input      = 0;
849 uschar *dkim_cur_signer          = NULL;
850 int     dkim_key_length          = 0;
851 void   *dkim_signatures          = NULL;
852 uschar *dkim_signers             = NULL;
853 uschar *dkim_signing_domain      = NULL;
854 uschar *dkim_signing_selector    = NULL;
855 uschar *dkim_verify_overall      = NULL;
856 uschar *dkim_verify_signers      = US"$dkim_signers";
857 uschar *dkim_verify_status       = NULL;
858 uschar *dkim_verify_reason       = NULL;
859 #endif
860 #ifdef EXPERIMENTAL_DMARC
861 uschar *dmarc_domain_policy     = NULL;
862 uschar *dmarc_forensic_sender   = NULL;
863 uschar *dmarc_history_file      = NULL;
864 uschar *dmarc_status            = NULL;
865 uschar *dmarc_status_text       = NULL;
866 uschar *dmarc_tld_file          = NULL;
867 uschar *dmarc_used_domain       = NULL;
868 #endif
869
870 uschar *dns_again_means_nonexist = NULL;
871 int     dns_csa_search_limit   = 5;
872 int     dns_cname_loops        = 1;
873 #ifdef SUPPORT_DANE
874 int     dns_dane_ok            = -1;
875 #endif
876 uschar *dns_ipv4_lookup        = NULL;
877 int     dns_retrans            = 0;
878 int     dns_retry              = 0;
879 int     dns_dnssec_ok          = -1; /* <0 = not coerced */
880 uschar *dns_trust_aa           = NULL;
881 int     dns_use_edns0          = -1; /* <0 = not coerced */
882 uschar *dnslist_domain         = NULL;
883 uschar *dnslist_matched        = NULL;
884 uschar *dnslist_text           = NULL;
885 uschar *dnslist_value          = NULL;
886 tree_node *domainlist_anchor   = NULL;
887 int     domainlist_count       = 0;
888 uschar *dsn_from               = US DEFAULT_DSN_FROM;
889
890 int     errno_quota            = ERRNO_QUOTA;
891 uschar *errors_copy            = NULL;
892 int     error_handling         = ERRORS_SENDER;
893 uschar *errors_reply_to        = NULL;
894 int     errors_sender_rc       = EXIT_FAILURE;
895 #ifndef DISABLE_EVENT
896 uschar *event_action             = NULL;        /* expansion for delivery events */
897 uschar *event_data               = NULL;        /* auxiliary data variable for event */
898 int     event_defer_errno        = 0;
899 const uschar *event_name         = NULL;        /* event name variable */
900 #endif
901
902
903 gid_t   exim_gid               = EXIM_GID;
904 uschar *exim_path              = US BIN_DIRECTORY "/exim"
905                         "\0<---------------Space to patch exim_path->";
906 uid_t   exim_uid               = EXIM_UID;
907 int     expand_level           = 0;             /* Nesting depth, indent for debug */
908 int     expand_forbid          = 0;
909 int     expand_nlength[EXPAND_MAXN+1];
910 int     expand_nmax            = -1;
911 uschar *expand_nstring[EXPAND_MAXN+1];
912 uschar *expand_string_message;
913 uschar *extra_local_interfaces = NULL;
914
915 int     fake_response          = OK;
916 uschar *fake_response_text     = US"Your message has been rejected but is "
917                                    "being kept for evaluation.\nIf it was a "
918                                    "legitimate message, it may still be "
919                                    "delivered to the target recipient(s).";
920 int     filter_n[FILTER_VARIABLE_COUNT];
921 int     filter_sn[FILTER_VARIABLE_COUNT];
922 int     filter_test            = FTEST_NONE;
923 uschar *filter_test_sfile      = NULL;
924 uschar *filter_test_ufile      = NULL;
925 uschar *filter_thisaddress     = NULL;
926 int     finduser_retries       = 0;
927 uid_t   fixed_never_users[]    = { FIXED_NEVER_USERS };
928 uschar *freeze_tell            = NULL;
929 uschar *freeze_tell_config     = NULL;
930 uschar *fudged_queue_times     = US"";
931
932 uschar *gecos_name             = NULL;
933 uschar *gecos_pattern          = NULL;
934 rewrite_rule  *global_rewrite_rules = NULL;
935
936 volatile sig_atomic_t had_command_timeout = 0;
937 volatile sig_atomic_t had_command_sigterm = 0;
938 volatile sig_atomic_t had_data_timeout    = 0;
939 volatile sig_atomic_t had_data_sigint     = 0;
940 uschar *headers_charset        = US HEADERS_CHARSET;
941 int     header_insert_maxlen   = 64 * 1024;
942 header_line  *header_last      = NULL;
943 header_line  *header_list      = NULL;
944 int     header_maxsize         = HEADER_MAXSIZE;
945 int     header_line_maxsize    = 0;
946
947 header_name header_names[] = {
948   /* name               len     allow_resent    htype */
949   { US"bcc",            3,      TRUE,           htype_bcc },
950   { US"cc",             2,      TRUE,           htype_cc },
951   { US"date",           4,      TRUE,           htype_date },
952   { US"delivery-date", 13,      FALSE,          htype_delivery_date },
953   { US"envelope-to",   11,      FALSE,          htype_envelope_to },
954   { US"from",           4,      TRUE,           htype_from },
955   { US"message-id",    10,      TRUE,           htype_id },
956   { US"received",       8,      FALSE,          htype_received },
957   { US"reply-to",       8,      FALSE,          htype_reply_to },
958   { US"return-path",   11,      FALSE,          htype_return_path },
959   { US"sender",         6,      TRUE,           htype_sender },
960   { US"subject",        7,      FALSE,          htype_subject },
961   { US"to",             2,      TRUE,           htype_to }
962 };
963
964 int header_names_size          = nelem(header_names);
965
966 uschar *helo_accept_junk_hosts = NULL;
967 uschar *helo_allow_chars       = US"";
968 uschar *helo_lookup_domains    = US"@ : @[]";
969 uschar *helo_try_verify_hosts  = NULL;
970 uschar *helo_verify_hosts      = NULL;
971 const uschar *hex_digits       = CUS"0123456789abcdef";
972 uschar *hold_domains           = NULL;
973 uschar *host_data              = NULL;
974 uschar *host_lookup            = NULL;
975 uschar *host_lookup_order      = US"bydns:byaddr";
976 uschar *host_lookup_msg        = US"";
977 int     host_number            = 0;
978 uschar *host_number_string     = NULL;
979 uschar *host_reject_connection = NULL;
980 tree_node *hostlist_anchor     = NULL;
981 int     hostlist_count         = 0;
982 uschar *hosts_treat_as_local   = NULL;
983 uschar *hosts_connection_nolog = NULL;
984
985 int     ignore_bounce_errors_after = 10*7*24*60*60;  /* 10 weeks */
986 uschar *ignore_fromline_hosts  = NULL;
987 int     inetd_wait_timeout     = -1;
988 uschar *initial_cwd            = NULL;
989 uschar *interface_address      = NULL;
990 int     interface_port         = -1;
991 uschar *iterate_item           = NULL;
992
993 int     journal_fd             = -1;
994
995 uschar *keep_environment       = NULL;
996
997 int     keep_malformed         = 4*24*60*60;    /* 4 days */
998
999 uschar *eldap_dn               = NULL;
1000 int     load_average           = -2;
1001 uschar *local_from_prefix      = NULL;
1002 uschar *local_from_suffix      = NULL;
1003
1004 #if HAVE_IPV6
1005 uschar *local_interfaces       = US"<; ::0 ; 0.0.0.0";
1006 #else
1007 uschar *local_interfaces       = US"0.0.0.0";
1008 #endif
1009
1010 #ifdef HAVE_LOCAL_SCAN
1011 uschar *local_scan_data        = NULL;
1012 int     local_scan_timeout     = 5*60;
1013 #endif
1014 gid_t   local_user_gid         = (gid_t)(-1);
1015 uid_t   local_user_uid         = (uid_t)(-1);
1016
1017 tree_node *localpartlist_anchor= NULL;
1018 int     localpartlist_count    = 0;
1019 uschar *log_buffer             = NULL;
1020
1021 int     log_default[]          = { /* for initializing log_selector */
1022   Li_acl_warn_skipped,
1023   Li_connection_reject,
1024   Li_delay_delivery,
1025   Li_dkim,
1026   Li_dnslist_defer,
1027   Li_etrn,
1028   Li_host_lookup_failed,
1029   Li_lost_incoming_connection,
1030   Li_outgoing_interface, /* see d_log_interface in deliver.c */
1031   Li_msg_id,
1032   Li_queue_run,
1033   Li_rejected_header,
1034   Li_retry_defer,
1035   Li_sender_verify_fail,
1036   Li_size_reject,
1037   Li_skip_delivery,
1038   Li_smtp_confirmation,
1039   Li_tls_certificate_verified,
1040   Li_tls_cipher,
1041   -1
1042 };
1043
1044 uschar *log_file_path          = US LOG_FILE_PATH
1045                            "\0<--------------Space to patch log_file_path->";
1046
1047 int     log_notall[]           = {
1048   -1
1049 };
1050 bit_table log_options[]        = { /* must be in alphabetical order */
1051   BIT_TABLE(L, 8bitmime),
1052   BIT_TABLE(L, acl_warn_skipped),
1053   BIT_TABLE(L, address_rewrite),
1054   BIT_TABLE(L, all),
1055   BIT_TABLE(L, all_parents),
1056   BIT_TABLE(L, arguments),
1057   BIT_TABLE(L, connection_reject),
1058   BIT_TABLE(L, delay_delivery),
1059   BIT_TABLE(L, deliver_time),
1060   BIT_TABLE(L, delivery_size),
1061 #ifndef DISABLE_DKIM
1062   BIT_TABLE(L, dkim),
1063   BIT_TABLE(L, dkim_verbose),
1064 #endif
1065   BIT_TABLE(L, dnslist_defer),
1066   BIT_TABLE(L, dnssec),
1067   BIT_TABLE(L, etrn),
1068   BIT_TABLE(L, host_lookup_failed),
1069   BIT_TABLE(L, ident_timeout),
1070   BIT_TABLE(L, incoming_interface),
1071   BIT_TABLE(L, incoming_port),
1072   BIT_TABLE(L, lost_incoming_connection),
1073   BIT_TABLE(L, millisec),
1074   BIT_TABLE(L, msg_id),
1075   BIT_TABLE(L, msg_id_created),
1076   BIT_TABLE(L, outgoing_interface),
1077   BIT_TABLE(L, outgoing_port),
1078   BIT_TABLE(L, pid),
1079   BIT_TABLE(L, pipelining),
1080 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1081   BIT_TABLE(L, proxy),
1082 #endif
1083   BIT_TABLE(L, queue_run),
1084   BIT_TABLE(L, queue_time),
1085   BIT_TABLE(L, queue_time_overall),
1086   BIT_TABLE(L, receive_time),
1087   BIT_TABLE(L, received_recipients),
1088   BIT_TABLE(L, received_sender),
1089   BIT_TABLE(L, rejected_header),
1090   { US"rejected_headers", Li_rejected_header },
1091   BIT_TABLE(L, retry_defer),
1092   BIT_TABLE(L, return_path_on_delivery),
1093   BIT_TABLE(L, sender_on_delivery),
1094   BIT_TABLE(L, sender_verify_fail),
1095   BIT_TABLE(L, size_reject),
1096   BIT_TABLE(L, skip_delivery),
1097   BIT_TABLE(L, smtp_confirmation),
1098   BIT_TABLE(L, smtp_connection),
1099   BIT_TABLE(L, smtp_incomplete_transaction),
1100   BIT_TABLE(L, smtp_mailauth),
1101   BIT_TABLE(L, smtp_no_mail),
1102   BIT_TABLE(L, smtp_protocol_error),
1103   BIT_TABLE(L, smtp_syntax_error),
1104   BIT_TABLE(L, subject),
1105   BIT_TABLE(L, tls_certificate_verified),
1106   BIT_TABLE(L, tls_cipher),
1107   BIT_TABLE(L, tls_peerdn),
1108   BIT_TABLE(L, tls_sni),
1109   BIT_TABLE(L, unknown_in_list),
1110 };
1111 int     log_options_count      = nelem(log_options);
1112
1113 int     log_reject_target      = 0;
1114 unsigned int log_selector[log_selector_size]; /* initialized in main() */
1115 uschar *log_selector_string    = NULL;
1116 FILE   *log_stderr             = NULL;
1117 uschar *login_sender_address   = NULL;
1118 uschar *lookup_dnssec_authenticated = NULL;
1119 int     lookup_open_max        = 25;
1120 uschar *lookup_value           = NULL;
1121
1122 macro_item *macros_user        = NULL;
1123 uschar *mailstore_basename     = NULL;
1124 #ifdef WITH_CONTENT_SCAN
1125 uschar *malware_name           = NULL;  /* Virus Name */
1126 #endif
1127 int     max_received_linelength= 0;
1128 int     max_username_length    = 0;
1129 int     message_age            = 0;
1130 uschar *message_body           = NULL;
1131 uschar *message_body_end       = NULL;
1132 int     message_body_size      = 0;
1133 int     message_body_visible   = 500;
1134 int     message_ended          = END_NOTSTARTED;
1135 uschar *message_headers        = NULL;
1136 uschar *message_id;
1137 uschar *message_id_domain      = NULL;
1138 uschar *message_id_text        = NULL;
1139 struct timeval message_id_tv   = { 0, 0 };
1140 uschar  message_id_option[MESSAGE_ID_LENGTH + 3];
1141 uschar *message_id_external;
1142 int     message_linecount      = 0;
1143 int     message_size           = 0;
1144 uschar *message_size_limit     = US"50M";
1145 #ifdef SUPPORT_I18N
1146 int     message_utf8_downconvert = 0;   /* -1 ifneeded; 0 never; 1 always */
1147 #endif
1148 uschar  message_subdir[2]      = { 0, 0 };
1149 uschar *message_reference      = NULL;
1150
1151 /* MIME ACL expandables */
1152 #ifdef WITH_CONTENT_SCAN
1153 int     mime_anomaly_level     = 0;
1154 const uschar *mime_anomaly_text      = NULL;
1155 uschar *mime_boundary          = NULL;
1156 uschar *mime_charset           = NULL;
1157 uschar *mime_content_description = NULL;
1158 uschar *mime_content_disposition = NULL;
1159 uschar *mime_content_id        = NULL;
1160 unsigned int mime_content_size = 0;
1161 uschar *mime_content_transfer_encoding = NULL;
1162 uschar *mime_content_type      = NULL;
1163 uschar *mime_decoded_filename  = NULL;
1164 uschar *mime_filename          = NULL;
1165 int     mime_is_multipart      = 0;
1166 int     mime_is_coverletter    = 0;
1167 int     mime_is_rfc822         = 0;
1168 int     mime_part_count        = -1;
1169 #endif
1170
1171 uid_t  *never_users            = NULL;
1172
1173 const int on                   = 1;     /* for setsockopt */
1174 const int off                  = 0;
1175
1176 uid_t   original_euid;
1177 gid_t   originator_gid;
1178 uschar *originator_login       = NULL;
1179 uschar *originator_name        = NULL;
1180 uid_t   originator_uid;
1181 uschar *override_local_interfaces = NULL;
1182 uschar *override_pid_file_path = NULL;
1183
1184 uschar *percent_hack_domains   = NULL;
1185 uschar *pid_file_path          = US PID_FILE_PATH
1186                            "\0<--------------Space to patch pid_file_path->";
1187 #ifdef EXPERIMENTAL_PIPE_CONNECT
1188 uschar *pipe_connect_advertise_hosts = US"*";
1189 #endif
1190 uschar *pipelining_advertise_hosts = US"*";
1191 uschar *primary_hostname       = NULL;
1192 uschar  process_info[PROCESS_INFO_SIZE];
1193 int     process_info_len       = 0;
1194 uschar *process_log_path       = NULL;
1195
1196 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1197 uschar *hosts_proxy            = NULL;
1198 uschar *proxy_external_address = NULL;
1199 int     proxy_external_port    = 0;
1200 uschar *proxy_local_address    = NULL;
1201 int     proxy_local_port       = 0;
1202 #endif
1203
1204 uschar *prvscheck_address      = NULL;
1205 uschar *prvscheck_keynum       = NULL;
1206 uschar *prvscheck_result       = NULL;
1207
1208
1209 const uschar *qualify_domain_recipient = NULL;
1210 uschar *qualify_domain_sender  = NULL;
1211 uschar *queue_domains          = NULL;
1212 int     queue_interval         = -1;
1213 uschar *queue_name             = US"";
1214 uschar *queue_only_file        = NULL;
1215 int     queue_only_load        = -1;
1216 uschar *queue_run_max          = US"5";
1217 pid_t   queue_run_pid          = (pid_t)0;
1218 int     queue_run_pipe         = -1;
1219 uschar *queue_smtp_domains     = NULL;
1220
1221 uint32_t random_seed           = 0;
1222 tree_node *ratelimiters_cmd    = NULL;
1223 tree_node *ratelimiters_conn   = NULL;
1224 tree_node *ratelimiters_mail   = NULL;
1225 uschar *raw_active_hostname    = NULL;
1226 uschar *raw_sender             = NULL;
1227 uschar **raw_recipients        = NULL;
1228 int     raw_recipients_count   = 0;
1229
1230 int     rcpt_count             = 0;
1231 int     rcpt_fail_count        = 0;
1232 int     rcpt_defer_count       = 0;
1233 gid_t   real_gid;
1234 uid_t   real_uid;
1235 int     receive_linecount      = 0;
1236 int     receive_messagecount   = 0;
1237 int     receive_timeout        = 0;
1238 int     received_count         = 0;
1239 uschar *received_for           = NULL;
1240
1241 /*  This is the default text for Received headers generated by Exim. The
1242 date  will be automatically added on the end. */
1243
1244 uschar *received_header_text   = US
1245      "Received: "
1246      "${if def:sender_rcvhost {from $sender_rcvhost\n\t}"
1247        "{${if def:sender_ident {from ${quote_local_part:$sender_ident} }}"
1248          "${if def:sender_helo_name {(helo=$sender_helo_name)\n\t}}}}"
1249      "by $primary_hostname "
1250      "${if def:received_protocol {with $received_protocol }}"
1251 #ifdef SUPPORT_TLS
1252      "${if def:tls_in_cipher_std { tls $tls_in_cipher_std\n\t}}"
1253 #endif
1254      "(Exim $version_number)\n\t"
1255      "${if def:sender_address {(envelope-from <$sender_address>)\n\t}}"
1256      "id $message_exim_id"
1257      "${if def:received_for {\n\tfor $received_for}}"
1258      "\0<---------------Space to patch received_header_text->";
1259
1260 int     received_headers_max   = 30;
1261 uschar *received_protocol      = NULL;
1262 struct timeval received_time   = { 0, 0 };
1263 struct timeval received_time_taken = { 0, 0 };
1264 uschar *recipient_data         = NULL;
1265 uschar *recipient_unqualified_hosts = NULL;
1266 uschar *recipient_verify_failure = NULL;
1267 int     recipients_count       = 0;
1268 recipient_item  *recipients_list = NULL;
1269 int     recipients_list_max    = 0;
1270 int     recipients_max         = 0;
1271 const pcre *regex_AUTH         = NULL;
1272 const pcre *regex_check_dns_names = NULL;
1273 const pcre *regex_From         = NULL;
1274 const pcre *regex_IGNOREQUOTA  = NULL;
1275 const pcre *regex_PIPELINING   = NULL;
1276 const pcre *regex_SIZE         = NULL;
1277 #ifdef EXPERIMENTAL_PIPE_CONNECT
1278 const pcre *regex_EARLY_PIPE   = NULL;
1279 #endif
1280 const pcre *regex_ismsgid      = NULL;
1281 const pcre *regex_smtp_code    = NULL;
1282 uschar *regex_vars[REGEX_VARS];
1283 #ifdef WHITELIST_D_MACROS
1284 const pcre *regex_whitelisted_macro = NULL;
1285 #endif
1286 #ifdef WITH_CONTENT_SCAN
1287 uschar *regex_match_string     = NULL;
1288 #endif
1289 int     remote_delivery_count  = 0;
1290 int     remote_max_parallel    = 2;
1291 uschar *remote_sort_domains    = NULL;
1292 int     retry_data_expire      = 7*24*60*60;
1293 int     retry_interval_max     = 24*60*60;
1294 int     retry_maximum_timeout  = 0;        /* set from retry config */
1295 retry_config  *retries         = NULL;
1296 uschar *return_path            = NULL;
1297 int     rewrite_existflags     = 0;
1298 uschar *rfc1413_hosts          = US"@[]";
1299 int     rfc1413_query_timeout  = 0;
1300 uid_t   root_gid               = ROOT_GID;
1301 uid_t   root_uid               = ROOT_UID;
1302
1303 router_instance  *routers  = NULL;
1304 router_instance  router_defaults = {
1305     .next =                     NULL,
1306     .name =                     NULL,
1307     .info =                     NULL,
1308     .options_block =            NULL,
1309     .driver_name =              NULL,
1310
1311     .address_data =             NULL,
1312 #ifdef EXPERIMENTAL_BRIGHTMAIL
1313     .bmi_rule =                 NULL,
1314 #endif
1315     .cannot_route_message =     NULL,
1316     .condition =                NULL,
1317     .current_directory =        NULL,
1318     .debug_string =             NULL,
1319     .domains =                  NULL,
1320     .errors_to =                NULL,
1321     .expand_gid =               NULL,
1322     .expand_uid =               NULL,
1323     .expand_more =              NULL,
1324     .expand_unseen =            NULL,
1325     .extra_headers =            NULL,
1326     .fallback_hosts =           NULL,
1327     .home_directory =           NULL,
1328     .ignore_target_hosts =      NULL,
1329     .local_parts =              NULL,
1330     .pass_router_name =         NULL,
1331     .prefix =                   NULL,
1332     .redirect_router_name =     NULL,
1333     .remove_headers =           NULL,
1334     .require_files =            NULL,
1335     .router_home_directory =    NULL,
1336     .self =                     US"freeze",
1337     .senders =                  NULL,
1338     .suffix =                   NULL,
1339     .translate_ip_address =     NULL,
1340     .transport_name =           NULL,
1341
1342     .address_test =             TRUE,
1343 #ifdef EXPERIMENTAL_BRIGHTMAIL
1344     .bmi_deliver_alternate =    FALSE,
1345     .bmi_deliver_default =      FALSE,
1346     .bmi_dont_deliver =         FALSE,
1347 #endif
1348     .expn =                     TRUE,
1349     .caseful_local_part =       FALSE,
1350     .check_local_user =         FALSE,
1351     .disable_logging =          FALSE,
1352     .fail_verify_recipient =    FALSE,
1353     .fail_verify_sender =       FALSE,
1354     .gid_set =                  FALSE,
1355     .initgroups =               FALSE,
1356     .log_as_local =             TRUE_UNSET,
1357     .more =                     TRUE,
1358     .pass_on_timeout =          FALSE,
1359     .prefix_optional =          FALSE,
1360     .repeat_use =               TRUE,
1361     .retry_use_local_part =     TRUE_UNSET,
1362     .same_domain_copy_routing = FALSE,
1363     .self_rewrite =             FALSE,
1364     .suffix_optional =          FALSE,
1365     .verify_only =              FALSE,
1366     .verify_recipient =         TRUE,
1367     .verify_sender =            TRUE,
1368     .uid_set =                  FALSE,
1369     .unseen =                   FALSE,
1370     .dsn_lasthop =              FALSE,
1371
1372     .self_code =                self_freeze,
1373     .uid =                      (uid_t)(-1),
1374     .gid =                      (gid_t)(-1),
1375
1376     .fallback_hostlist =        NULL,
1377     .transport =                NULL,
1378     .pass_router =              NULL,
1379     .redirect_router =          NULL,
1380
1381     .dnssec =                   { NULL, NULL },            /* dnssec_domains {require,request} */
1382 };
1383
1384 uschar *router_name            = NULL;
1385
1386 ip_address_item *running_interfaces = NULL;
1387
1388 /* This is a weird one. The following string gets patched in the binary by the
1389 script that sets up a copy of Exim for running in the test harness. It seems
1390 that compilers are now clever, and share constant strings if they can.
1391 Elsewhere in Exim the string "<" is used. The compiler optimization seems to
1392 make use of the end of this string in order to save space. So the patching then
1393 wrecks this. We defeat this optimization by adding some additional characters
1394 onto the end of the string. */
1395
1396 uschar *running_status         = US">>>running<<<" "\0EXTRA";
1397
1398 int     runrc                  = 0;
1399
1400 uschar *search_error_message   = NULL;
1401 uschar *self_hostname          = NULL;
1402 uschar *sender_address         = NULL;
1403 unsigned int sender_address_cache[(MAX_NAMED_LIST * 2)/32];
1404 uschar *sender_address_data    = NULL;
1405 uschar *sender_address_unrewritten = NULL;
1406 uschar *sender_data            = NULL;
1407 unsigned int sender_domain_cache[(MAX_NAMED_LIST * 2)/32];
1408 uschar *sender_fullhost        = NULL;
1409 uschar *sender_helo_name       = NULL;
1410 uschar **sender_host_aliases   = &no_aliases;
1411 uschar *sender_host_address    = NULL;
1412 uschar *sender_host_authenticated = NULL;
1413 uschar *sender_host_auth_pubname  = NULL;
1414 unsigned int sender_host_cache[(MAX_NAMED_LIST * 2)/32];
1415 uschar *sender_host_name       = NULL;
1416 int     sender_host_port       = 0;
1417 uschar *sender_ident           = NULL;
1418 uschar *sender_rate            = NULL;
1419 uschar *sender_rate_limit      = NULL;
1420 uschar *sender_rate_period     = NULL;
1421 uschar *sender_rcvhost         = NULL;
1422 uschar *sender_unqualified_hosts = NULL;
1423 uschar *sender_verify_failure = NULL;
1424 address_item *sender_verified_list  = NULL;
1425 address_item *sender_verified_failed = NULL;
1426 int     sender_verified_rc     = -1;
1427 uschar *sending_ip_address     = NULL;
1428 int     sending_port           = -1;
1429 SIGNAL_BOOL sigalrm_seen       = FALSE;
1430 const uschar *sigalarm_setter  = NULL;
1431 uschar **sighup_argv           = NULL;
1432 int     slow_lookup_log        = 0;     /* millisecs, zero disables */
1433 int     smtp_accept_count      = 0;
1434 int     smtp_accept_max        = 20;
1435 int     smtp_accept_max_nonmail= 10;
1436 uschar *smtp_accept_max_nonmail_hosts = US"*";
1437 int     smtp_accept_max_per_connection = 1000;
1438 uschar *smtp_accept_max_per_host = NULL;
1439 int     smtp_accept_queue      = 0;
1440 int     smtp_accept_queue_per_connection = 10;
1441 int     smtp_accept_reserve    = 0;
1442 uschar *smtp_active_hostname   = NULL;
1443 uschar *smtp_banner            = US"$smtp_active_hostname ESMTP "
1444                              "Exim $version_number $tod_full"
1445                              "\0<---------------Space to patch smtp_banner->";
1446 int     smtp_ch_index          = 0;
1447 uschar *smtp_cmd_argument      = NULL;
1448 uschar *smtp_cmd_buffer        = NULL;
1449 struct timeval smtp_connection_start  = {0,0};
1450 uschar  smtp_connection_had[SMTP_HBUFF_SIZE];
1451 int     smtp_connect_backlog   = 20;
1452 double  smtp_delay_mail        = 0.0;
1453 double  smtp_delay_rcpt        = 0.0;
1454 FILE   *smtp_in                = NULL;
1455 int     smtp_load_reserve      = -1;
1456 int     smtp_mailcmd_count     = 0;
1457 FILE   *smtp_out               = NULL;
1458 uschar *smtp_etrn_command      = NULL;
1459 int     smtp_max_synprot_errors= 3;
1460 int     smtp_max_unknown_commands = 3;
1461 uschar *smtp_notquit_reason    = NULL;
1462 uschar *smtp_ratelimit_hosts   = NULL;
1463 uschar *smtp_ratelimit_mail    = NULL;
1464 uschar *smtp_ratelimit_rcpt    = NULL;
1465 uschar *smtp_read_error        = US"";
1466 int     smtp_receive_timeout   = 5*60;
1467 uschar *smtp_receive_timeout_s = NULL;
1468 uschar *smtp_reserve_hosts     = NULL;
1469 int     smtp_rlm_base          = 0;
1470 double  smtp_rlm_factor        = 0.0;
1471 int     smtp_rlm_limit         = 0;
1472 int     smtp_rlm_threshold     = INT_MAX;
1473 int     smtp_rlr_base          = 0;
1474 double  smtp_rlr_factor        = 0.0;
1475 int     smtp_rlr_limit         = 0;
1476 int     smtp_rlr_threshold     = INT_MAX;
1477 unsigned smtp_peer_options     = 0;
1478 unsigned smtp_peer_options_wrap= 0;
1479 #ifdef SUPPORT_I18N
1480 uschar *smtputf8_advertise_hosts = US"*";       /* overridden under test-harness */
1481 #endif
1482
1483 #ifdef WITH_CONTENT_SCAN
1484 uschar *spamd_address          = US"127.0.0.1 783";
1485 uschar *spam_bar               = NULL;
1486 uschar *spam_report            = NULL;
1487 uschar *spam_action            = NULL;
1488 uschar *spam_score             = NULL;
1489 uschar *spam_score_int         = NULL;
1490 #endif
1491 #ifdef SUPPORT_SPF
1492 uschar *spf_guess              = US"v=spf1 a/24 mx/24 ptr ?all";
1493 uschar *spf_header_comment     = NULL;
1494 uschar *spf_received           = NULL;
1495 uschar *spf_result             = NULL;
1496 uschar *spf_smtp_comment       = NULL;
1497 #endif
1498
1499 FILE   *spool_data_file        = NULL;
1500 uschar *spool_directory        = US SPOOL_DIRECTORY
1501                            "\0<--------------Space to patch spool_directory->";
1502 #ifdef EXPERIMENTAL_SRS
1503 uschar *srs_config             = NULL;
1504 uschar *srs_db_address         = NULL;
1505 uschar *srs_db_key             = NULL;
1506 int     srs_hashlength         = 6;
1507 int     srs_hashmin            = -1;
1508 int     srs_maxage             = 31;
1509 uschar *srs_orig_recipient     = NULL;
1510 uschar *srs_orig_sender        = NULL;
1511 uschar *srs_recipient          = NULL;
1512 uschar *srs_secrets            = NULL;
1513 uschar *srs_status             = NULL;
1514 #endif
1515 int     string_datestamp_offset= -1;
1516 int     string_datestamp_length= 0;
1517 int     string_datestamp_type  = -1;
1518 uschar *submission_domain      = NULL;
1519 uschar *submission_name        = NULL;
1520 int     syslog_facility        = LOG_MAIL;
1521 uschar *syslog_processname     = US"exim";
1522 uschar *system_filter          = NULL;
1523
1524 uschar *system_filter_directory_transport = NULL;
1525 uschar *system_filter_file_transport = NULL;
1526 uschar *system_filter_pipe_transport = NULL;
1527 uschar *system_filter_reply_transport = NULL;
1528
1529 gid_t   system_filter_gid      = 0;
1530 uid_t   system_filter_uid      = (uid_t)-1;
1531
1532 blob    tcp_fastopen_nodata    = { .data = NULL, .len = 0 };
1533 tfo_state_t tcp_out_fastopen   = TFO_NOT_USED;
1534 #ifdef USE_TCP_WRAPPERS
1535 uschar *tcp_wrappers_daemon_name = US TCP_WRAPPERS_DAEMON_NAME;
1536 #endif
1537 int     test_harness_load_avg  = 0;
1538 int     thismessage_size_limit = 0;
1539 int     timeout_frozen_after   = 0;
1540
1541 transport_instance  *transports = NULL;
1542
1543 transport_instance  transport_defaults = {
1544     .next =                     NULL,
1545     .name =                     NULL,
1546     .info =                     NULL,
1547     .options_block =            NULL,
1548     .driver_name =              NULL,
1549     .setup =                    NULL,
1550     .batch_max =                1,
1551     .batch_id =                 NULL,
1552     .home_dir =                 NULL,
1553     .current_dir =              NULL,
1554     .expand_multi_domain =      NULL,
1555     .multi_domain =             TRUE,
1556     .overrides_hosts =          FALSE,
1557     .max_addresses =            100,
1558     .connection_max_messages =  500,
1559     .deliver_as_creator =       FALSE,
1560     .disable_logging =          FALSE,
1561     .initgroups =               FALSE,
1562     .uid_set =                  FALSE,
1563     .gid_set =                  FALSE,
1564     .uid =                      (uid_t)(-1),
1565     .gid =                      (gid_t)(-1),
1566     .expand_uid =               NULL,
1567     .expand_gid =               NULL,
1568     .warn_message =             NULL,
1569     .shadow =                   NULL,
1570     .shadow_condition =         NULL,
1571     .filter_command =           NULL,
1572     .add_headers =              NULL,
1573     .remove_headers =           NULL,
1574     .return_path =              NULL,
1575     .debug_string =             NULL,
1576     .max_parallel =             NULL,
1577     .message_size_limit =       NULL,
1578     .headers_rewrite =          NULL,
1579     .rewrite_rules =            NULL,
1580     .rewrite_existflags =       0,
1581     .filter_timeout =           300,
1582     .body_only =                FALSE,
1583     .delivery_date_add =        FALSE,
1584     .envelope_to_add =          FALSE,
1585     .headers_only =             FALSE,
1586     .rcpt_include_affixes =     FALSE,
1587     .return_path_add =          FALSE,
1588     .return_output =            FALSE,
1589     .return_fail_output =       FALSE,
1590     .log_output =               FALSE,
1591     .log_fail_output =          FALSE,
1592     .log_defer_output =         FALSE,
1593     .retry_use_local_part =     TRUE_UNSET,     /* retry_use_local_part: BOOL, but set neither
1594                                                  1 nor 0 so can detect unset */
1595 #ifndef DISABLE_EVENT
1596    .event_action =              NULL
1597 #endif
1598 };
1599
1600 int     transport_count;
1601 uschar *transport_name          = NULL;
1602 int     transport_newlines;
1603 const uschar **transport_filter_argv  = NULL;
1604 int     transport_filter_timeout;
1605 int     transport_write_timeout= 0;
1606
1607 tree_node  *tree_dns_fails     = NULL;
1608 tree_node  *tree_duplicates    = NULL;
1609 tree_node  *tree_nonrecipients = NULL;
1610 tree_node  *tree_unusable      = NULL;
1611
1612 gid_t  *trusted_groups         = NULL;
1613 uid_t  *trusted_users          = NULL;
1614 uschar *timezone_string        = US TIMEZONE_DEFAULT;
1615
1616 uschar *unknown_login          = NULL;
1617 uschar *unknown_username       = NULL;
1618 uschar *untrusted_set_sender   = NULL;
1619
1620 /*  A regex for matching a "From_" line in an incoming message, in the form
1621
1622     From ph10 Fri Jan  5 12:35 GMT 1996
1623
1624 which  the "mail" commands send to the MTA (undocumented, of course), or in
1625 the  form
1626
1627     From ph10 Fri, 7 Jan 97 14:00:00 GMT
1628
1629 which  is apparently used by some UUCPs, despite it not being in RFC 976.
1630 Because  of variations in time formats, just match up to the minutes. That
1631 should  be sufficient. Examples have been seen of time fields like 12:1:03,
1632 so  just require one digit for hours and minutes. The weekday is also absent
1633 in  some forms. */
1634
1635 uschar *uucp_from_pattern      = US
1636    "^From\\s+(\\S+)\\s+(?:[a-zA-Z]{3},?\\s+)?"    /* Common start */
1637    "(?:"                                          /* Non-extracting bracket */
1638    "[a-zA-Z]{3}\\s+\\d?\\d|"                      /* First form */
1639    "\\d?\\d\\s+[a-zA-Z]{3}\\s+\\d\\d(?:\\d\\d)?"  /* Second form */
1640    ")"                                            /* End alternation */
1641    "\\s+\\d\\d?:\\d\\d?";                         /* Start of time */
1642
1643 uschar *uucp_from_sender       = US"$1";
1644
1645 uschar *verify_mode            = NULL;
1646 uschar *version_copyright      =
1647  US"Copyright (c) University of Cambridge, 1995 - 2018\n"
1648    "(c) The Exim Maintainers and contributors in ACKNOWLEDGMENTS file, 2007 - 2018";
1649 uschar *version_date           = US"?";
1650 uschar *version_cnumber        = US"????";
1651 uschar *version_string         = US"?";
1652
1653 uschar *warn_message_file      = NULL;
1654 int     warning_count          = 0;
1655 uschar *warnmsg_delay          = NULL;
1656 uschar *warnmsg_recipients     = NULL;
1657
1658
1659 /*  End of globals.c */