xref: /freebsd/contrib/sendmail/src/readcf.c (revision 74bf4e164ba5851606a27d4feff27717452583e5)
1 /*
2  * Copyright (c) 1998-2004 Sendmail, Inc. and its suppliers.
3  *	All rights reserved.
4  * Copyright (c) 1983, 1995-1997 Eric P. Allman.  All rights reserved.
5  * Copyright (c) 1988, 1993
6  *	The Regents of the University of California.  All rights reserved.
7  *
8  * By using this file, you agree to the terms and conditions set
9  * forth in the LICENSE file which can be found at the top level of
10  * the sendmail distribution.
11  *
12  */
13 
14 #include <sendmail.h>
15 
16 SM_RCSID("@(#)$Id: readcf.c,v 8.641 2004/07/23 20:45:02 gshapiro Exp $")
17 
18 #if NETINET || NETINET6
19 # include <arpa/inet.h>
20 #endif /* NETINET || NETINET6 */
21 
22 #define SECONDS
23 #define MINUTES	* 60
24 #define HOUR	* 3600
25 #define HOURS	HOUR
26 
27 static void	fileclass __P((int, char *, char *, bool, bool, bool));
28 static char	**makeargv __P((char *));
29 static void	settimeout __P((char *, char *, bool));
30 static void	toomany __P((int, int));
31 static char	*extrquotstr __P((char *, char **, char *, bool *));
32 
33 /*
34 **  READCF -- read configuration file.
35 **
36 **	This routine reads the configuration file and builds the internal
37 **	form.
38 **
39 **	The file is formatted as a sequence of lines, each taken
40 **	atomically.  The first character of each line describes how
41 **	the line is to be interpreted.  The lines are:
42 **		Dxval		Define macro x to have value val.
43 **		Cxword		Put word into class x.
44 **		Fxfile [fmt]	Read file for lines to put into
45 **				class x.  Use scanf string 'fmt'
46 **				or "%s" if not present.  Fmt should
47 **				only produce one string-valued result.
48 **		Hname: value	Define header with field-name 'name'
49 **				and value as specified; this will be
50 **				macro expanded immediately before
51 **				use.
52 **		Sn		Use rewriting set n.
53 **		Rlhs rhs	Rewrite addresses that match lhs to
54 **				be rhs.
55 **		Mn arg=val...	Define mailer.  n is the internal name.
56 **				Args specify mailer parameters.
57 **		Oxvalue		Set option x to value.
58 **		O option value	Set option (long name) to value.
59 **		Pname=value	Set precedence name to value.
60 **		Qn arg=val...	Define queue groups.  n is the internal name.
61 **				Args specify queue parameters.
62 **		Vversioncode[/vendorcode]
63 **				Version level/vendor name of
64 **				configuration syntax.
65 **		Kmapname mapclass arguments....
66 **				Define keyed lookup of a given class.
67 **				Arguments are class dependent.
68 **		Eenvar=value	Set the environment value to the given value.
69 **
70 **	Parameters:
71 **		cfname -- configuration file name.
72 **		safe -- true if this is the system config file;
73 **			false otherwise.
74 **		e -- the main envelope.
75 **
76 **	Returns:
77 **		none.
78 **
79 **	Side Effects:
80 **		Builds several internal tables.
81 */
82 
83 void
84 readcf(cfname, safe, e)
85 	char *cfname;
86 	bool safe;
87 	register ENVELOPE *e;
88 {
89 	SM_FILE_T *cf;
90 	int ruleset = -1;
91 	char *q;
92 	struct rewrite *rwp = NULL;
93 	char *bp;
94 	auto char *ep;
95 	int nfuzzy;
96 	char *file;
97 	bool optional;
98 	bool ok;
99 	bool ismap;
100 	int mid;
101 	register char *p;
102 	long sff = SFF_OPENASROOT;
103 	struct stat statb;
104 	char buf[MAXLINE];
105 	char exbuf[MAXLINE];
106 	char pvpbuf[MAXLINE + MAXATOM];
107 	static char *null_list[1] = { NULL };
108 	extern unsigned char TokTypeNoC[];
109 
110 	FileName = cfname;
111 	LineNumber = 0;
112 
113 	if (DontLockReadFiles)
114 		sff |= SFF_NOLOCK;
115 	cf = safefopen(cfname, O_RDONLY, 0444, sff);
116 	if (cf == NULL)
117 	{
118 		syserr("cannot open");
119 		finis(false, true, EX_OSFILE);
120 	}
121 
122 	if (fstat(sm_io_getinfo(cf, SM_IO_WHAT_FD, NULL), &statb) < 0)
123 	{
124 		syserr("cannot fstat");
125 		finis(false, true, EX_OSFILE);
126 	}
127 
128 	if (!S_ISREG(statb.st_mode))
129 	{
130 		syserr("not a plain file");
131 		finis(false, true, EX_OSFILE);
132 	}
133 
134 	if (OpMode != MD_TEST && bitset(S_IWGRP|S_IWOTH, statb.st_mode))
135 	{
136 		if (OpMode == MD_DAEMON || OpMode == MD_INITALIAS)
137 			(void) sm_io_fprintf(smioerr, SM_TIME_DEFAULT,
138 					     "%s: WARNING: dangerous write permissions\n",
139 					     FileName);
140 		if (LogLevel > 0)
141 			sm_syslog(LOG_CRIT, NOQID,
142 				  "%s: WARNING: dangerous write permissions",
143 				  FileName);
144 	}
145 
146 #if XLA
147 	xla_zero();
148 #endif /* XLA */
149 
150 	while ((bp = fgetfolded(buf, sizeof buf, cf)) != NULL)
151 	{
152 		if (bp[0] == '#')
153 		{
154 			if (bp != buf)
155 				sm_free(bp); /* XXX */
156 			continue;
157 		}
158 
159 		/* do macro expansion mappings */
160 		translate_dollars(bp);
161 
162 		/* interpret this line */
163 		errno = 0;
164 		switch (bp[0])
165 		{
166 		  case '\0':
167 		  case '#':		/* comment */
168 			break;
169 
170 		  case 'R':		/* rewriting rule */
171 			if (ruleset < 0)
172 			{
173 				syserr("missing valid ruleset for \"%s\"", bp);
174 				break;
175 			}
176 			for (p = &bp[1]; *p != '\0' && *p != '\t'; p++)
177 				continue;
178 
179 			if (*p == '\0')
180 			{
181 				syserr("invalid rewrite line \"%s\" (tab expected)", bp);
182 				break;
183 			}
184 
185 			/* allocate space for the rule header */
186 			if (rwp == NULL)
187 			{
188 				RewriteRules[ruleset] = rwp =
189 					(struct rewrite *) xalloc(sizeof *rwp);
190 			}
191 			else
192 			{
193 				rwp->r_next = (struct rewrite *) xalloc(sizeof *rwp);
194 				rwp = rwp->r_next;
195 			}
196 			rwp->r_next = NULL;
197 
198 			/* expand and save the LHS */
199 			*p = '\0';
200 			expand(&bp[1], exbuf, sizeof exbuf, e);
201 			rwp->r_lhs = prescan(exbuf, '\t', pvpbuf,
202 					     sizeof pvpbuf, NULL,
203 					     ConfigLevel >= 9 ? TokTypeNoC : NULL,
204 					     true);
205 			nfuzzy = 0;
206 			if (rwp->r_lhs != NULL)
207 			{
208 				register char **ap;
209 
210 				rwp->r_lhs = copyplist(rwp->r_lhs, true, NULL);
211 
212 				/* count the number of fuzzy matches in LHS */
213 				for (ap = rwp->r_lhs; *ap != NULL; ap++)
214 				{
215 					char *botch;
216 
217 					botch = NULL;
218 					switch (**ap & 0377)
219 					{
220 					  case MATCHZANY:
221 					  case MATCHANY:
222 					  case MATCHONE:
223 					  case MATCHCLASS:
224 					  case MATCHNCLASS:
225 						nfuzzy++;
226 						break;
227 
228 					  case MATCHREPL:
229 						botch = "$0-$9";
230 						break;
231 
232 					  case CANONUSER:
233 						botch = "$:";
234 						break;
235 
236 					  case CALLSUBR:
237 						botch = "$>";
238 						break;
239 
240 					  case CONDIF:
241 						botch = "$?";
242 						break;
243 
244 					  case CONDFI:
245 						botch = "$.";
246 						break;
247 
248 					  case HOSTBEGIN:
249 						botch = "$[";
250 						break;
251 
252 					  case HOSTEND:
253 						botch = "$]";
254 						break;
255 
256 					  case LOOKUPBEGIN:
257 						botch = "$(";
258 						break;
259 
260 					  case LOOKUPEND:
261 						botch = "$)";
262 						break;
263 					}
264 					if (botch != NULL)
265 						syserr("Inappropriate use of %s on LHS",
266 							botch);
267 				}
268 				rwp->r_line = LineNumber;
269 			}
270 			else
271 			{
272 				syserr("R line: null LHS");
273 				rwp->r_lhs = null_list;
274 			}
275 			if (nfuzzy > MAXMATCH)
276 			{
277 				syserr("R line: too many wildcards");
278 				rwp->r_lhs = null_list;
279 			}
280 
281 			/* expand and save the RHS */
282 			while (*++p == '\t')
283 				continue;
284 			q = p;
285 			while (*p != '\0' && *p != '\t')
286 				p++;
287 			*p = '\0';
288 			expand(q, exbuf, sizeof exbuf, e);
289 			rwp->r_rhs = prescan(exbuf, '\t', pvpbuf,
290 					     sizeof pvpbuf, NULL,
291 					     ConfigLevel >= 9 ? TokTypeNoC : NULL,
292 					     true);
293 			if (rwp->r_rhs != NULL)
294 			{
295 				register char **ap;
296 				int args, endtoken;
297 #if _FFR_EXTRA_MAP_CHECK
298 				int nexttoken;
299 #endif /* _FFR_EXTRA_MAP_CHECK */
300 				bool inmap;
301 
302 				rwp->r_rhs = copyplist(rwp->r_rhs, true, NULL);
303 
304 				/* check no out-of-bounds replacements */
305 				nfuzzy += '0';
306 				inmap = false;
307 				args = 0;
308 				endtoken = 0;
309 				for (ap = rwp->r_rhs; *ap != NULL; ap++)
310 				{
311 					char *botch;
312 
313 					botch = NULL;
314 					switch (**ap & 0377)
315 					{
316 					  case MATCHREPL:
317 						if ((*ap)[1] <= '0' || (*ap)[1] > nfuzzy)
318 						{
319 							syserr("replacement $%c out of bounds",
320 								(*ap)[1]);
321 						}
322 						break;
323 
324 					  case MATCHZANY:
325 						botch = "$*";
326 						break;
327 
328 					  case MATCHANY:
329 						botch = "$+";
330 						break;
331 
332 					  case MATCHONE:
333 						botch = "$-";
334 						break;
335 
336 					  case MATCHCLASS:
337 						botch = "$=";
338 						break;
339 
340 					  case MATCHNCLASS:
341 						botch = "$~";
342 						break;
343 
344 					  case CANONHOST:
345 						if (!inmap)
346 							break;
347 						if (++args >= MAX_MAP_ARGS)
348 							syserr("too many arguments for map lookup");
349 						break;
350 
351 					  case HOSTBEGIN:
352 						endtoken = HOSTEND;
353 						/* FALLTHROUGH */
354 					  case LOOKUPBEGIN:
355 						/* see above... */
356 						if ((**ap & 0377) == LOOKUPBEGIN)
357 							endtoken = LOOKUPEND;
358 						if (inmap)
359 							syserr("cannot nest map lookups");
360 						inmap = true;
361 						args = 0;
362 #if _FFR_EXTRA_MAP_CHECK
363 						if (*(ap + 1) == NULL)
364 						{
365 							syserr("syntax error in map lookup");
366 							break;
367 						}
368 						nexttoken = **(ap + 1) & 0377;
369 						if (nexttoken == CANONHOST ||
370 						    nexttoken == CANONUSER ||
371 						    nexttoken == endtoken)
372 						{
373 							syserr("missing map name for lookup");
374 							break;
375 						}
376 						if (*(ap + 2) == NULL)
377 						{
378 							syserr("syntax error in map lookup");
379 							break;
380 						}
381 						if ((**ap & 0377) == HOSTBEGIN)
382 							break;
383 						nexttoken = **(ap + 2) & 0377;
384 						if (nexttoken == CANONHOST ||
385 						    nexttoken == CANONUSER ||
386 						    nexttoken == endtoken)
387 						{
388 							syserr("missing key name for lookup");
389 							break;
390 						}
391 #endif /* _FFR_EXTRA_MAP_CHECK */
392 						break;
393 
394 					  case HOSTEND:
395 					  case LOOKUPEND:
396 						if ((**ap & 0377) != endtoken)
397 							break;
398 						inmap = false;
399 						endtoken = 0;
400 						break;
401 
402 
403 #if 0
404 /*
405 **  This doesn't work yet as there are maps defined *after* the cf
406 **  is read such as host, user, and alias.  So for now, it's removed.
407 **  When it comes back, the RELEASE_NOTES entry will be:
408 **	Emit warnings for unknown maps when reading the .cf file.  Based on
409 **		patch from Robert Harker of Harker Systems.
410 */
411 
412 					  case LOOKUPBEGIN:
413 						/*
414 						**  Got a database lookup,
415 						**  check if map is defined.
416 						*/
417 
418 						ep = *(ap + 1);
419 						if ((*ep & 0377) != MACRODEXPAND &&
420 						    stab(ep, ST_MAP,
421 							 ST_FIND) == NULL)
422 						{
423 							(void) sm_io_fprintf(smioout,
424 									     SM_TIME_DEFAULT,
425 									     "Warning: %s: line %d: map %s not found\n",
426 									     FileName,
427 									     LineNumber,
428 									     ep);
429 						}
430 						break;
431 #endif /* 0 */
432 					}
433 					if (botch != NULL)
434 						syserr("Inappropriate use of %s on RHS",
435 							botch);
436 				}
437 				if (inmap)
438 					syserr("missing map closing token");
439 			}
440 			else
441 			{
442 				syserr("R line: null RHS");
443 				rwp->r_rhs = null_list;
444 			}
445 			break;
446 
447 		  case 'S':		/* select rewriting set */
448 			expand(&bp[1], exbuf, sizeof exbuf, e);
449 			ruleset = strtorwset(exbuf, NULL, ST_ENTER);
450 			if (ruleset < 0)
451 				break;
452 
453 			rwp = RewriteRules[ruleset];
454 			if (rwp != NULL)
455 			{
456 				if (OpMode == MD_TEST)
457 					(void) sm_io_fprintf(smioout,
458 							     SM_TIME_DEFAULT,
459 							     "WARNING: Ruleset %s has multiple definitions\n",
460 							    &bp[1]);
461 				if (tTd(37, 1))
462 					sm_dprintf("WARNING: Ruleset %s has multiple definitions\n",
463 						   &bp[1]);
464 				while (rwp->r_next != NULL)
465 					rwp = rwp->r_next;
466 			}
467 			break;
468 
469 		  case 'D':		/* macro definition */
470 			mid = macid_parse(&bp[1], &ep);
471 			if (mid == 0)
472 				break;
473 			p = munchstring(ep, NULL, '\0');
474 			macdefine(&e->e_macro, A_TEMP, mid, p);
475 			break;
476 
477 		  case 'H':		/* required header line */
478 			(void) chompheader(&bp[1], CHHDR_DEF, NULL, e);
479 			break;
480 
481 		  case 'C':		/* word class */
482 		  case 'T':		/* trusted user (set class `t') */
483 			if (bp[0] == 'C')
484 			{
485 				mid = macid_parse(&bp[1], &ep);
486 				if (mid == 0)
487 					break;
488 				expand(ep, exbuf, sizeof exbuf, e);
489 				p = exbuf;
490 			}
491 			else
492 			{
493 				mid = 't';
494 				p = &bp[1];
495 			}
496 			while (*p != '\0')
497 			{
498 				register char *wd;
499 				char delim;
500 
501 				while (*p != '\0' && isascii(*p) && isspace(*p))
502 					p++;
503 				wd = p;
504 				while (*p != '\0' && !(isascii(*p) && isspace(*p)))
505 					p++;
506 				delim = *p;
507 				*p = '\0';
508 				if (wd[0] != '\0')
509 					setclass(mid, wd);
510 				*p = delim;
511 			}
512 			break;
513 
514 		  case 'F':		/* word class from file */
515 			mid = macid_parse(&bp[1], &ep);
516 			if (mid == 0)
517 				break;
518 			for (p = ep; isascii(*p) && isspace(*p); )
519 				p++;
520 			if (p[0] == '-' && p[1] == 'o')
521 			{
522 				optional = true;
523 				while (*p != '\0' &&
524 				       !(isascii(*p) && isspace(*p)))
525 					p++;
526 				while (isascii(*p) && isspace(*p))
527 					p++;
528 				file = p;
529 			}
530 			else
531 				optional = false;
532 
533 			/* check if [key]@map:spec */
534 			ismap = false;
535 			if (!SM_IS_DIR_DELIM(*p) &&
536 			    *p != '|' &&
537 			    (q = strchr(p, '@')) != NULL)
538 			{
539 				q++;
540 
541 				/* look for @LDAP or @map: in string */
542 				if (strcmp(q, "LDAP") == 0 ||
543 				    (*q != ':' &&
544 				     strchr(q, ':') != NULL))
545 					ismap = true;
546 			}
547 
548 			if (ismap)
549 			{
550 				/* use entire spec */
551 				file = p;
552 			}
553 			else
554 			{
555 				file = extrquotstr(p, &q, " ", &ok);
556 				if (!ok)
557 				{
558 					syserr("illegal filename '%s'", p);
559 					break;
560 				}
561 			}
562 
563 			if (*file == '|' || ismap)
564 				p = "%s";
565 			else
566 			{
567 				p = q;
568 				if (*p == '\0')
569 					p = "%s";
570 				else
571 				{
572 					*p = '\0';
573 					while (isascii(*++p) && isspace(*p))
574 						continue;
575 				}
576 			}
577 			fileclass(mid, file, p, ismap, safe, optional);
578 			break;
579 
580 #if XLA
581 		  case 'L':		/* extended load average description */
582 			xla_init(&bp[1]);
583 			break;
584 #endif /* XLA */
585 
586 #if defined(SUN_EXTENSIONS) && defined(SUN_LOOKUP_MACRO)
587 		  case 'L':		/* lookup macro */
588 		  case 'G':		/* lookup class */
589 			/* reserved for Sun -- NIS+ database lookup */
590 			if (VendorCode != VENDOR_SUN)
591 				goto badline;
592 			sun_lg_config_line(bp, e);
593 			break;
594 #endif /* defined(SUN_EXTENSIONS) && defined(SUN_LOOKUP_MACRO) */
595 
596 		  case 'M':		/* define mailer */
597 			makemailer(&bp[1]);
598 			break;
599 
600 		  case 'O':		/* set option */
601 			setoption(bp[1], &bp[2], safe, false, e);
602 			break;
603 
604 		  case 'P':		/* set precedence */
605 			if (NumPriorities >= MAXPRIORITIES)
606 			{
607 				toomany('P', MAXPRIORITIES);
608 				break;
609 			}
610 			for (p = &bp[1]; *p != '\0' && *p != '='; p++)
611 				continue;
612 			if (*p == '\0')
613 				goto badline;
614 			*p = '\0';
615 			Priorities[NumPriorities].pri_name = newstr(&bp[1]);
616 			Priorities[NumPriorities].pri_val = atoi(++p);
617 			NumPriorities++;
618 			break;
619 
620 		  case 'Q':		/* define queue */
621 			makequeue(&bp[1], true);
622 			break;
623 
624 		  case 'V':		/* configuration syntax version */
625 			for (p = &bp[1]; isascii(*p) && isspace(*p); p++)
626 				continue;
627 			if (!isascii(*p) || !isdigit(*p))
628 			{
629 				syserr("invalid argument to V line: \"%.20s\"",
630 					&bp[1]);
631 				break;
632 			}
633 			ConfigLevel = strtol(p, &ep, 10);
634 
635 			/*
636 			**  Do heuristic tweaking for back compatibility.
637 			*/
638 
639 			if (ConfigLevel >= 5)
640 			{
641 				/* level 5 configs have short name in $w */
642 				p = macvalue('w', e);
643 				if (p != NULL && (p = strchr(p, '.')) != NULL)
644 				{
645 					*p = '\0';
646 					macdefine(&e->e_macro, A_TEMP, 'w',
647 						  macvalue('w', e));
648 				}
649 			}
650 			if (ConfigLevel >= 6)
651 			{
652 				ColonOkInAddr = false;
653 			}
654 
655 			/*
656 			**  Look for vendor code.
657 			*/
658 
659 			if (*ep++ == '/')
660 			{
661 				/* extract vendor code */
662 				for (p = ep; isascii(*p) && isalpha(*p); )
663 					p++;
664 				*p = '\0';
665 
666 				if (!setvendor(ep))
667 					syserr("invalid V line vendor code: \"%s\"",
668 						ep);
669 			}
670 			break;
671 
672 		  case 'K':
673 			expand(&bp[1], exbuf, sizeof exbuf, e);
674 			(void) makemapentry(exbuf);
675 			break;
676 
677 		  case 'E':
678 			p = strchr(bp, '=');
679 			if (p != NULL)
680 				*p++ = '\0';
681 			setuserenv(&bp[1], p);
682 			break;
683 
684 		  case 'X':		/* mail filter */
685 #if MILTER
686 			milter_setup(&bp[1]);
687 #else /* MILTER */
688 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
689 					     "Warning: Filter usage ('X') requires Milter support (-DMILTER)\n");
690 #endif /* MILTER */
691 			break;
692 
693 		  default:
694 		  badline:
695 			syserr("unknown configuration line \"%s\"", bp);
696 		}
697 		if (bp != buf)
698 			sm_free(bp); /* XXX */
699 	}
700 	if (sm_io_error(cf))
701 	{
702 		syserr("I/O read error");
703 		finis(false, true, EX_OSFILE);
704 	}
705 	(void) sm_io_close(cf, SM_TIME_DEFAULT);
706 	FileName = NULL;
707 
708 	/* initialize host maps from local service tables */
709 	inithostmaps();
710 
711 	/* initialize daemon (if not defined yet) */
712 	initdaemon();
713 
714 	/* determine if we need to do special name-server frotz */
715 	{
716 		int nmaps;
717 		char *maptype[MAXMAPSTACK];
718 		short mapreturn[MAXMAPACTIONS];
719 
720 		nmaps = switch_map_find("hosts", maptype, mapreturn);
721 		UseNameServer = false;
722 		if (nmaps > 0 && nmaps <= MAXMAPSTACK)
723 		{
724 			register int mapno;
725 
726 			for (mapno = 0; mapno < nmaps && !UseNameServer;
727 			     mapno++)
728 			{
729 				if (strcmp(maptype[mapno], "dns") == 0)
730 					UseNameServer = true;
731 			}
732 		}
733 	}
734 }
735 /*
736 **  TRANSLATE_DOLLARS -- convert $x into internal form
737 **
738 **	Actually does all appropriate pre-processing of a config line
739 **	to turn it into internal form.
740 **
741 **	Parameters:
742 **		bp -- the buffer to translate.
743 **
744 **	Returns:
745 **		None.  The buffer is translated in place.  Since the
746 **		translations always make the buffer shorter, this is
747 **		safe without a size parameter.
748 */
749 
750 void
751 translate_dollars(bp)
752 	char *bp;
753 {
754 	register char *p;
755 	auto char *ep;
756 
757 	for (p = bp; *p != '\0'; p++)
758 	{
759 		if (*p == '#' && p > bp && ConfigLevel >= 3)
760 		{
761 			register char *e;
762 
763 			switch (*--p & 0377)
764 			{
765 			  case MACROEXPAND:
766 				/* it's from $# -- let it go through */
767 				p++;
768 				break;
769 
770 			  case '\\':
771 				/* it's backslash escaped */
772 				(void) sm_strlcpy(p, p + 1, strlen(p));
773 				break;
774 
775 			  default:
776 				/* delete leading white space */
777 				while (isascii(*p) && isspace(*p) &&
778 				       *p != '\n' && p > bp)
779 					p--;
780 				if ((e = strchr(++p, '\n')) != NULL)
781 					(void) sm_strlcpy(p, e, strlen(p));
782 				else
783 					*p-- = '\0';
784 				break;
785 			}
786 			continue;
787 		}
788 
789 		if (*p != '$' || p[1] == '\0')
790 			continue;
791 
792 		if (p[1] == '$')
793 		{
794 			/* actual dollar sign.... */
795 			(void) sm_strlcpy(p, p + 1, strlen(p));
796 			continue;
797 		}
798 
799 		/* convert to macro expansion character */
800 		*p++ = MACROEXPAND;
801 
802 		/* special handling for $=, $~, $&, and $? */
803 		if (*p == '=' || *p == '~' || *p == '&' || *p == '?')
804 			p++;
805 
806 		/* convert macro name to code */
807 		*p = macid_parse(p, &ep);
808 		if (ep != p + 1)
809 			(void) sm_strlcpy(p + 1, ep, strlen(p + 1));
810 	}
811 
812 	/* strip trailing white space from the line */
813 	while (--p > bp && isascii(*p) && isspace(*p))
814 		*p = '\0';
815 }
816 /*
817 **  TOOMANY -- signal too many of some option
818 **
819 **	Parameters:
820 **		id -- the id of the error line
821 **		maxcnt -- the maximum possible values
822 **
823 **	Returns:
824 **		none.
825 **
826 **	Side Effects:
827 **		gives a syserr.
828 */
829 
830 static void
831 toomany(id, maxcnt)
832 	int id;
833 	int maxcnt;
834 {
835 	syserr("too many %c lines, %d max", id, maxcnt);
836 }
837 /*
838 **  FILECLASS -- read members of a class from a file
839 **
840 **	Parameters:
841 **		class -- class to define.
842 **		filename -- name of file to read.
843 **		fmt -- scanf string to use for match.
844 **		ismap -- if set, this is a map lookup.
845 **		safe -- if set, this is a safe read.
846 **		optional -- if set, it is not an error for the file to
847 **			not exist.
848 **
849 **	Returns:
850 **		none
851 **
852 **	Side Effects:
853 **		puts all lines in filename that match a scanf into
854 **			the named class.
855 */
856 
857 /*
858 **  Break up the match into words and add to class.
859 */
860 
861 static void
862 parse_class_words(class, line)
863 	int class;
864 	char *line;
865 {
866 	while (line != NULL && *line != '\0')
867 	{
868 		register char *q;
869 
870 		/* strip leading spaces */
871 		while (isascii(*line) && isspace(*line))
872 			line++;
873 		if (*line == '\0')
874 			break;
875 
876 		/* find the end of the word */
877 		q = line;
878 		while (*line != '\0' && !(isascii(*line) && isspace(*line)))
879 			line++;
880 		if (*line != '\0')
881 			*line++ = '\0';
882 
883 		/* enter the word in the symbol table */
884 		setclass(class, q);
885 	}
886 }
887 
888 static void
889 fileclass(class, filename, fmt, ismap, safe, optional)
890 	int class;
891 	char *filename;
892 	char *fmt;
893 	bool ismap;
894 	bool safe;
895 	bool optional;
896 {
897 	SM_FILE_T *f;
898 	long sff;
899 	pid_t pid;
900 	register char *p;
901 	char buf[MAXLINE];
902 
903 	if (tTd(37, 2))
904 		sm_dprintf("fileclass(%s, fmt=%s)\n", filename, fmt);
905 
906 	if (*filename == '\0')
907 	{
908 		syserr("fileclass: missing file name");
909 		return;
910 	}
911 	else if (ismap)
912 	{
913 		int status = 0;
914 		char *key;
915 		char *mn;
916 		char *cl, *spec;
917 		STAB *mapclass;
918 		MAP map;
919 
920 		mn = newstr(macname(class));
921 
922 		key = filename;
923 
924 		/* skip past key */
925 		if ((p = strchr(filename, '@')) == NULL)
926 		{
927 			/* should not happen */
928 			syserr("fileclass: bogus map specification");
929 			sm_free(mn);
930 			return;
931 		}
932 
933 		/* skip past '@' */
934 		*p++ = '\0';
935 		cl = p;
936 
937 #if LDAPMAP
938 		if (strcmp(cl, "LDAP") == 0)
939 		{
940 			int n;
941 			char *lc;
942 			char jbuf[MAXHOSTNAMELEN];
943 			char lcbuf[MAXLINE];
944 
945 			/* Get $j */
946 			expand("\201j", jbuf, sizeof jbuf, &BlankEnvelope);
947 			if (jbuf[0] == '\0')
948 			{
949 				(void) sm_strlcpy(jbuf, "localhost",
950 						  sizeof jbuf);
951 			}
952 
953 			/* impose the default schema */
954 			lc = macvalue(macid("{sendmailMTACluster}"), CurEnv);
955 			if (lc == NULL)
956 				lc = "";
957 			else
958 			{
959 				expand(lc, lcbuf, sizeof lcbuf, CurEnv);
960 				lc = lcbuf;
961 			}
962 
963 			cl = "ldap";
964 			n = sm_snprintf(buf, sizeof buf,
965 					"-k (&(objectClass=sendmailMTAClass)(sendmailMTAClassName=%s)(|(sendmailMTACluster=%s)(sendmailMTAHost=%s))) -v sendmailMTAClassValue,sendmailMTAClassSearch:FILTER:sendmailMTAClass,sendmailMTAClassURL:URL:sendmailMTAClass",
966 					mn, lc, jbuf);
967 			if (n >= sizeof buf)
968 			{
969 				syserr("fileclass: F{%s}: Default LDAP string too long",
970 				       mn);
971 				sm_free(mn);
972 				return;
973 			}
974 			spec = buf;
975 		}
976 		else
977 #endif /* LDAPMAP */
978 		{
979 			if ((spec = strchr(cl, ':')) == NULL)
980 			{
981 				syserr("fileclass: F{%s}: missing map class",
982 				       mn);
983 				sm_free(mn);
984 				return;
985 			}
986 			*spec++ ='\0';
987 		}
988 
989 		/* set up map structure */
990 		mapclass = stab(cl, ST_MAPCLASS, ST_FIND);
991 		if (mapclass == NULL)
992 		{
993 			syserr("fileclass: F{%s}: class %s not available",
994 			       mn, cl);
995 			sm_free(mn);
996 			return;
997 		}
998 		memset(&map, '\0', sizeof map);
999 		map.map_class = &mapclass->s_mapclass;
1000 		map.map_mname = mn;
1001 		map.map_mflags |= MF_FILECLASS;
1002 
1003 		if (tTd(37, 5))
1004 			sm_dprintf("fileclass: F{%s}: map class %s, key %s, spec %s\n",
1005 				   mn, cl, key, spec);
1006 
1007 
1008 		/* parse map spec */
1009 		if (!map.map_class->map_parse(&map, spec))
1010 		{
1011 			/* map_parse() showed the error already */
1012 			sm_free(mn);
1013 			return;
1014 		}
1015 		map.map_mflags |= MF_VALID;
1016 
1017 		/* open map */
1018 		if (map.map_class->map_open(&map, O_RDONLY))
1019 		{
1020 			map.map_mflags |= MF_OPEN;
1021 			map.map_pid = getpid();
1022 		}
1023 		else
1024 		{
1025 			if (!optional &&
1026 			    !bitset(MF_OPTIONAL, map.map_mflags))
1027 				syserr("fileclass: F{%s}: map open failed",
1028 				       mn);
1029 			sm_free(mn);
1030 			return;
1031 		}
1032 
1033 		/* lookup */
1034 		p = (*map.map_class->map_lookup)(&map, key, NULL, &status);
1035 		if (status != EX_OK && status != EX_NOTFOUND)
1036 		{
1037 			if (!optional)
1038 				syserr("fileclass: F{%s}: map lookup failed",
1039 				       mn);
1040 			p = NULL;
1041 		}
1042 
1043 		/* use the results */
1044 		if (p != NULL)
1045 			parse_class_words(class, p);
1046 
1047 		/* close map */
1048 		map.map_mflags |= MF_CLOSING;
1049 		map.map_class->map_close(&map);
1050 		map.map_mflags &= ~(MF_OPEN|MF_WRITABLE|MF_CLOSING);
1051 		sm_free(mn);
1052 		return;
1053 	}
1054 	else if (filename[0] == '|')
1055 	{
1056 		auto int fd;
1057 		int i;
1058 		char *argv[MAXPV + 1];
1059 
1060 		i = 0;
1061 		for (p = strtok(&filename[1], " \t");
1062 		     p != NULL && i < MAXPV;
1063 		     p = strtok(NULL, " \t"))
1064 			argv[i++] = p;
1065 		argv[i] = NULL;
1066 		pid = prog_open(argv, &fd, CurEnv);
1067 		if (pid < 0)
1068 			f = NULL;
1069 		else
1070 			f = sm_io_open(SmFtStdiofd, SM_TIME_DEFAULT,
1071 				       (void *) &fd, SM_IO_RDONLY, NULL);
1072 	}
1073 	else
1074 	{
1075 		pid = -1;
1076 		sff = SFF_REGONLY;
1077 		if (!bitnset(DBS_CLASSFILEINUNSAFEDIRPATH, DontBlameSendmail))
1078 			sff |= SFF_SAFEDIRPATH;
1079 		if (!bitnset(DBS_LINKEDCLASSFILEINWRITABLEDIR,
1080 			     DontBlameSendmail))
1081 			sff |= SFF_NOWLINK;
1082 		if (safe)
1083 			sff |= SFF_OPENASROOT;
1084 		else if (RealUid == 0)
1085 			sff |= SFF_ROOTOK;
1086 		if (DontLockReadFiles)
1087 			sff |= SFF_NOLOCK;
1088 		f = safefopen(filename, O_RDONLY, 0, sff);
1089 	}
1090 	if (f == NULL)
1091 	{
1092 		if (!optional)
1093 			syserr("fileclass: cannot open '%s'", filename);
1094 		return;
1095 	}
1096 
1097 	while (sm_io_fgets(f, SM_TIME_DEFAULT, buf, sizeof buf) != NULL)
1098 	{
1099 #if SCANF
1100 		char wordbuf[MAXLINE + 1];
1101 #endif /* SCANF */
1102 
1103 		if (buf[0] == '#')
1104 			continue;
1105 #if SCANF
1106 		if (sm_io_sscanf(buf, fmt, wordbuf) != 1)
1107 			continue;
1108 		p = wordbuf;
1109 #else /* SCANF */
1110 		p = buf;
1111 #endif /* SCANF */
1112 
1113 		parse_class_words(class, p);
1114 
1115 		/*
1116 		**  If anything else is added here,
1117 		**  check if the '@' map case above
1118 		**  needs the code as well.
1119 		*/
1120 	}
1121 
1122 	(void) sm_io_close(f, SM_TIME_DEFAULT);
1123 	if (pid > 0)
1124 		(void) waitfor(pid);
1125 }
1126 /*
1127 **  MAKEMAILER -- define a new mailer.
1128 **
1129 **	Parameters:
1130 **		line -- description of mailer.  This is in labeled
1131 **			fields.  The fields are:
1132 **			   A -- the argv for this mailer
1133 **			   C -- the character set for MIME conversions
1134 **			   D -- the directory to run in
1135 **			   E -- the eol string
1136 **			   F -- the flags associated with the mailer
1137 **			   L -- the maximum line length
1138 **			   M -- the maximum message size
1139 **			   N -- the niceness at which to run
1140 **			   P -- the path to the mailer
1141 **			   Q -- the queue group for the mailer
1142 **			   R -- the recipient rewriting set
1143 **			   S -- the sender rewriting set
1144 **			   T -- the mailer type (for DSNs)
1145 **			   U -- the uid to run as
1146 **			   W -- the time to wait at the end
1147 **			   m -- maximum messages per connection
1148 **			   r -- maximum number of recipients per message
1149 **			   / -- new root directory
1150 **			The first word is the canonical name of the mailer.
1151 **
1152 **	Returns:
1153 **		none.
1154 **
1155 **	Side Effects:
1156 **		enters the mailer into the mailer table.
1157 */
1158 
1159 void
1160 makemailer(line)
1161 	char *line;
1162 {
1163 	register char *p;
1164 	register struct mailer *m;
1165 	register STAB *s;
1166 	int i;
1167 	char fcode;
1168 	auto char *endp;
1169 	static int nextmailer = 0;	/* "free" index into Mailer struct */
1170 
1171 	/* allocate a mailer and set up defaults */
1172 	m = (struct mailer *) xalloc(sizeof *m);
1173 	memset((char *) m, '\0', sizeof *m);
1174 	errno = 0; /* avoid bogus error text */
1175 
1176 	/* collect the mailer name */
1177 	for (p = line;
1178 	     *p != '\0' && *p != ',' && !(isascii(*p) && isspace(*p));
1179 	     p++)
1180 		continue;
1181 	if (*p != '\0')
1182 		*p++ = '\0';
1183 	if (line[0] == '\0')
1184 	{
1185 		syserr("name required for mailer");
1186 		return;
1187 	}
1188 	m->m_name = newstr(line);
1189 	m->m_qgrp = NOQGRP;
1190 	m->m_uid = NO_UID;
1191 	m->m_gid = NO_GID;
1192 
1193 	/* now scan through and assign info from the fields */
1194 	while (*p != '\0')
1195 	{
1196 		auto char *delimptr;
1197 
1198 		while (*p != '\0' &&
1199 		       (*p == ',' || (isascii(*p) && isspace(*p))))
1200 			p++;
1201 
1202 		/* p now points to field code */
1203 		fcode = *p;
1204 		while (*p != '\0' && *p != '=' && *p != ',')
1205 			p++;
1206 		if (*p++ != '=')
1207 		{
1208 			syserr("mailer %s: `=' expected", m->m_name);
1209 			return;
1210 		}
1211 		while (isascii(*p) && isspace(*p))
1212 			p++;
1213 
1214 		/* p now points to the field body */
1215 		p = munchstring(p, &delimptr, ',');
1216 
1217 		/* install the field into the mailer struct */
1218 		switch (fcode)
1219 		{
1220 		  case 'P':		/* pathname */
1221 			if (*p != '\0')	/* error is issued below */
1222 				m->m_mailer = newstr(p);
1223 			break;
1224 
1225 		  case 'F':		/* flags */
1226 			for (; *p != '\0'; p++)
1227 			{
1228 				if (!(isascii(*p) && isspace(*p)))
1229 				{
1230 #if _FFR_DEPRECATE_MAILER_FLAG_I
1231 					if (*p == M_INTERNAL)
1232 						sm_syslog(LOG_WARNING, NOQID,
1233 							  "WARNING: mailer=%s, flag=%c deprecated",
1234 							  m->m_name, *p);
1235 #endif /* _FFR_DEPRECATE_MAILER_FLAG_I */
1236 					setbitn(bitidx(*p), m->m_flags);
1237 				}
1238 			}
1239 			break;
1240 
1241 		  case 'S':		/* sender rewriting ruleset */
1242 		  case 'R':		/* recipient rewriting ruleset */
1243 			i = strtorwset(p, &endp, ST_ENTER);
1244 			if (i < 0)
1245 				return;
1246 			if (fcode == 'S')
1247 				m->m_sh_rwset = m->m_se_rwset = i;
1248 			else
1249 				m->m_rh_rwset = m->m_re_rwset = i;
1250 
1251 			p = endp;
1252 			if (*p++ == '/')
1253 			{
1254 				i = strtorwset(p, NULL, ST_ENTER);
1255 				if (i < 0)
1256 					return;
1257 				if (fcode == 'S')
1258 					m->m_sh_rwset = i;
1259 				else
1260 					m->m_rh_rwset = i;
1261 			}
1262 			break;
1263 
1264 		  case 'E':		/* end of line string */
1265 			if (*p == '\0')
1266 				syserr("mailer %s: null end-of-line string",
1267 					m->m_name);
1268 			else
1269 				m->m_eol = newstr(p);
1270 			break;
1271 
1272 		  case 'A':		/* argument vector */
1273 			if (*p != '\0')	/* error is issued below */
1274 				m->m_argv = makeargv(p);
1275 			break;
1276 
1277 		  case 'M':		/* maximum message size */
1278 			m->m_maxsize = atol(p);
1279 			break;
1280 
1281 		  case 'm':		/* maximum messages per connection */
1282 			m->m_maxdeliveries = atoi(p);
1283 			break;
1284 
1285 		  case 'r':		/* max recipient per envelope */
1286 			m->m_maxrcpt = atoi(p);
1287 			break;
1288 
1289 		  case 'L':		/* maximum line length */
1290 			m->m_linelimit = atoi(p);
1291 			if (m->m_linelimit < 0)
1292 				m->m_linelimit = 0;
1293 			break;
1294 
1295 		  case 'N':		/* run niceness */
1296 			m->m_nice = atoi(p);
1297 			break;
1298 
1299 		  case 'D':		/* working directory */
1300 			if (*p == '\0')
1301 				syserr("mailer %s: null working directory",
1302 					m->m_name);
1303 			else
1304 				m->m_execdir = newstr(p);
1305 			break;
1306 
1307 		  case 'C':		/* default charset */
1308 			if (*p == '\0')
1309 				syserr("mailer %s: null charset", m->m_name);
1310 			else
1311 				m->m_defcharset = newstr(p);
1312 			break;
1313 
1314 		  case 'Q':		/* queue for this mailer */
1315 			if (*p == '\0')
1316 			{
1317 				syserr("mailer %s: null queue", m->m_name);
1318 				break;
1319 			}
1320 			s = stab(p, ST_QUEUE, ST_FIND);
1321 			if (s == NULL)
1322 				syserr("mailer %s: unknown queue %s",
1323 					m->m_name, p);
1324 			else
1325 				m->m_qgrp = s->s_quegrp->qg_index;
1326 			break;
1327 
1328 		  case 'T':		/* MTA-Name/Address/Diagnostic types */
1329 			/* extract MTA name type; default to "dns" */
1330 			m->m_mtatype = newstr(p);
1331 			p = strchr(m->m_mtatype, '/');
1332 			if (p != NULL)
1333 			{
1334 				*p++ = '\0';
1335 				if (*p == '\0')
1336 					p = NULL;
1337 			}
1338 			if (*m->m_mtatype == '\0')
1339 				m->m_mtatype = "dns";
1340 
1341 			/* extract address type; default to "rfc822" */
1342 			m->m_addrtype = p;
1343 			if (p != NULL)
1344 				p = strchr(p, '/');
1345 			if (p != NULL)
1346 			{
1347 				*p++ = '\0';
1348 				if (*p == '\0')
1349 					p = NULL;
1350 			}
1351 			if (m->m_addrtype == NULL || *m->m_addrtype == '\0')
1352 				m->m_addrtype = "rfc822";
1353 
1354 			/* extract diagnostic type; default to "smtp" */
1355 			m->m_diagtype = p;
1356 			if (m->m_diagtype == NULL || *m->m_diagtype == '\0')
1357 				m->m_diagtype = "smtp";
1358 			break;
1359 
1360 		  case 'U':		/* user id */
1361 			if (isascii(*p) && !isdigit(*p))
1362 			{
1363 				char *q = p;
1364 				struct passwd *pw;
1365 
1366 				while (*p != '\0' && isascii(*p) &&
1367 				       (isalnum(*p) || strchr("-_", *p) != NULL))
1368 					p++;
1369 				while (isascii(*p) && isspace(*p))
1370 					*p++ = '\0';
1371 				if (*p != '\0')
1372 					*p++ = '\0';
1373 				if (*q == '\0')
1374 				{
1375 					syserr("mailer %s: null user name",
1376 						m->m_name);
1377 					break;
1378 				}
1379 				pw = sm_getpwnam(q);
1380 				if (pw == NULL)
1381 				{
1382 					syserr("readcf: mailer U= flag: unknown user %s", q);
1383 					break;
1384 				}
1385 				else
1386 				{
1387 					m->m_uid = pw->pw_uid;
1388 					m->m_gid = pw->pw_gid;
1389 				}
1390 			}
1391 			else
1392 			{
1393 				auto char *q;
1394 
1395 				m->m_uid = strtol(p, &q, 0);
1396 				p = q;
1397 				while (isascii(*p) && isspace(*p))
1398 					p++;
1399 				if (*p != '\0')
1400 					p++;
1401 			}
1402 			while (isascii(*p) && isspace(*p))
1403 				p++;
1404 			if (*p == '\0')
1405 				break;
1406 			if (isascii(*p) && !isdigit(*p))
1407 			{
1408 				char *q = p;
1409 				struct group *gr;
1410 
1411 				while (isascii(*p) && isalnum(*p))
1412 					p++;
1413 				*p++ = '\0';
1414 				if (*q == '\0')
1415 				{
1416 					syserr("mailer %s: null group name",
1417 						m->m_name);
1418 					break;
1419 				}
1420 				gr = getgrnam(q);
1421 				if (gr == NULL)
1422 				{
1423 					syserr("readcf: mailer U= flag: unknown group %s", q);
1424 					break;
1425 				}
1426 				else
1427 					m->m_gid = gr->gr_gid;
1428 			}
1429 			else
1430 			{
1431 				m->m_gid = strtol(p, NULL, 0);
1432 			}
1433 			break;
1434 
1435 		  case 'W':		/* wait timeout */
1436 			m->m_wait = convtime(p, 's');
1437 			break;
1438 
1439 		  case '/':		/* new root directory */
1440 			if (*p == '\0')
1441 				syserr("mailer %s: null root directory",
1442 					m->m_name);
1443 			else
1444 				m->m_rootdir = newstr(p);
1445 			break;
1446 
1447 		  default:
1448 			syserr("M%s: unknown mailer equate %c=",
1449 			       m->m_name, fcode);
1450 			break;
1451 		}
1452 
1453 		p = delimptr;
1454 	}
1455 
1456 #if !HASRRESVPORT
1457 	if (bitnset(M_SECURE_PORT, m->m_flags))
1458 	{
1459 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1460 				     "M%s: Warning: F=%c set on system that doesn't support rresvport()\n",
1461 				     m->m_name, M_SECURE_PORT);
1462 	}
1463 #endif /* !HASRRESVPORT */
1464 
1465 #if !HASNICE
1466 	if (m->m_nice != 0)
1467 	{
1468 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1469 				     "M%s: Warning: N= set on system that doesn't support nice()\n",
1470 				     m->m_name);
1471 	}
1472 #endif /* !HASNICE */
1473 
1474 	/* do some rationality checking */
1475 	if (m->m_argv == NULL)
1476 	{
1477 		syserr("M%s: A= argument required", m->m_name);
1478 		return;
1479 	}
1480 	if (m->m_mailer == NULL)
1481 	{
1482 		syserr("M%s: P= argument required", m->m_name);
1483 		return;
1484 	}
1485 
1486 	if (nextmailer >= MAXMAILERS)
1487 	{
1488 		syserr("too many mailers defined (%d max)", MAXMAILERS);
1489 		return;
1490 	}
1491 
1492 	if (m->m_maxrcpt <= 0)
1493 		m->m_maxrcpt = DEFAULT_MAX_RCPT;
1494 
1495 	/* do some heuristic cleanup for back compatibility */
1496 	if (bitnset(M_LIMITS, m->m_flags))
1497 	{
1498 		if (m->m_linelimit == 0)
1499 			m->m_linelimit = SMTPLINELIM;
1500 		if (ConfigLevel < 2)
1501 			setbitn(M_7BITS, m->m_flags);
1502 	}
1503 
1504 	if (strcmp(m->m_mailer, "[TCP]") == 0)
1505 	{
1506 		syserr("M%s: P=[TCP] must be replaced by P=[IPC]", m->m_name);
1507 		return;
1508 	}
1509 
1510 	if (strcmp(m->m_mailer, "[IPC]") == 0)
1511 	{
1512 		/* Use the second argument for host or path to socket */
1513 		if (m->m_argv[0] == NULL || m->m_argv[1] == NULL ||
1514 		    m->m_argv[1][0] == '\0')
1515 		{
1516 			syserr("M%s: too few parameters for %s mailer",
1517 			       m->m_name, m->m_mailer);
1518 			return;
1519 		}
1520 		if (strcmp(m->m_argv[0], "TCP") != 0
1521 #if NETUNIX
1522 		    && strcmp(m->m_argv[0], "FILE") != 0
1523 #endif /* NETUNIX */
1524 		    )
1525 		{
1526 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1527 					     "M%s: Warning: first argument in %s mailer must be %s\n",
1528 					     m->m_name, m->m_mailer,
1529 #if NETUNIX
1530 					     "TCP or FILE"
1531 #else /* NETUNIX */
1532 					     "TCP"
1533 #endif /* NETUNIX */
1534 				     );
1535 		}
1536 		if (m->m_mtatype == NULL)
1537 			m->m_mtatype = "dns";
1538 		if (m->m_addrtype == NULL)
1539 			m->m_addrtype = "rfc822";
1540 		if (m->m_diagtype == NULL)
1541 		{
1542 			if (m->m_argv[0] != NULL &&
1543 			    strcmp(m->m_argv[0], "FILE") == 0)
1544 				m->m_diagtype = "x-unix";
1545 			else
1546 				m->m_diagtype = "smtp";
1547 		}
1548 	}
1549 	else if (strcmp(m->m_mailer, "[FILE]") == 0)
1550 	{
1551 		/* Use the second argument for filename */
1552 		if (m->m_argv[0] == NULL || m->m_argv[1] == NULL ||
1553 		    m->m_argv[2] != NULL)
1554 		{
1555 			syserr("M%s: too %s parameters for [FILE] mailer",
1556 			       m->m_name,
1557 			       (m->m_argv[0] == NULL ||
1558 				m->m_argv[1] == NULL) ? "few" : "many");
1559 			return;
1560 		}
1561 		else if (strcmp(m->m_argv[0], "FILE") != 0)
1562 		{
1563 			syserr("M%s: first argument in [FILE] mailer must be FILE",
1564 			       m->m_name);
1565 			return;
1566 		}
1567 	}
1568 
1569 	if (m->m_eol == NULL)
1570 	{
1571 		char **pp;
1572 
1573 		/* default for SMTP is \r\n; use \n for local delivery */
1574 		for (pp = m->m_argv; *pp != NULL; pp++)
1575 		{
1576 			for (p = *pp; *p != '\0'; )
1577 			{
1578 				if ((*p++ & 0377) == MACROEXPAND && *p == 'u')
1579 					break;
1580 			}
1581 			if (*p != '\0')
1582 				break;
1583 		}
1584 		if (*pp == NULL)
1585 			m->m_eol = "\r\n";
1586 		else
1587 			m->m_eol = "\n";
1588 	}
1589 
1590 	/* enter the mailer into the symbol table */
1591 	s = stab(m->m_name, ST_MAILER, ST_ENTER);
1592 	if (s->s_mailer != NULL)
1593 	{
1594 		i = s->s_mailer->m_mno;
1595 		sm_free(s->s_mailer); /* XXX */
1596 	}
1597 	else
1598 	{
1599 		i = nextmailer++;
1600 	}
1601 	Mailer[i] = s->s_mailer = m;
1602 	m->m_mno = i;
1603 }
1604 /*
1605 **  MUNCHSTRING -- translate a string into internal form.
1606 **
1607 **	Parameters:
1608 **		p -- the string to munch.
1609 **		delimptr -- if non-NULL, set to the pointer of the
1610 **			field delimiter character.
1611 **		delim -- the delimiter for the field.
1612 **
1613 **	Returns:
1614 **		the munched string.
1615 **
1616 **	Side Effects:
1617 **		the munched string is a local static buffer.
1618 **		it must be copied before the function is called again.
1619 */
1620 
1621 char *
1622 munchstring(p, delimptr, delim)
1623 	register char *p;
1624 	char **delimptr;
1625 	int delim;
1626 {
1627 	register char *q;
1628 	bool backslash = false;
1629 	bool quotemode = false;
1630 	static char buf[MAXLINE];
1631 
1632 	for (q = buf; *p != '\0' && q < &buf[sizeof buf - 1]; p++)
1633 	{
1634 		if (backslash)
1635 		{
1636 			/* everything is roughly literal */
1637 			backslash = false;
1638 			switch (*p)
1639 			{
1640 			  case 'r':		/* carriage return */
1641 				*q++ = '\r';
1642 				continue;
1643 
1644 			  case 'n':		/* newline */
1645 				*q++ = '\n';
1646 				continue;
1647 
1648 			  case 'f':		/* form feed */
1649 				*q++ = '\f';
1650 				continue;
1651 
1652 			  case 'b':		/* backspace */
1653 				*q++ = '\b';
1654 				continue;
1655 			}
1656 			*q++ = *p;
1657 		}
1658 		else
1659 		{
1660 			if (*p == '\\')
1661 				backslash = true;
1662 			else if (*p == '"')
1663 				quotemode = !quotemode;
1664 			else if (quotemode || *p != delim)
1665 				*q++ = *p;
1666 			else
1667 				break;
1668 		}
1669 	}
1670 
1671 	if (delimptr != NULL)
1672 		*delimptr = p;
1673 	*q++ = '\0';
1674 	return buf;
1675 }
1676 /*
1677 **  EXTRQUOTSTR -- extract a (quoted) string.
1678 **
1679 **	This routine deals with quoted (") strings and escaped
1680 **	spaces (\\ ).
1681 **
1682 **	Parameters:
1683 **		p -- source string.
1684 **		delimptr -- if non-NULL, set to the pointer of the
1685 **			field delimiter character.
1686 **		delimbuf -- delimiters for the field.
1687 **		st -- if non-NULL, store the return value (whether the
1688 **			string was correctly quoted) here.
1689 **
1690 **	Returns:
1691 **		the extracted string.
1692 **
1693 **	Side Effects:
1694 **		the returned string is a local static buffer.
1695 **		it must be copied before the function is called again.
1696 */
1697 
1698 static char *
1699 extrquotstr(p, delimptr, delimbuf, st)
1700 	register char *p;
1701 	char **delimptr;
1702 	char *delimbuf;
1703 	bool *st;
1704 {
1705 	register char *q;
1706 	bool backslash = false;
1707 	bool quotemode = false;
1708 	static char buf[MAXLINE];
1709 
1710 	for (q = buf; *p != '\0' && q < &buf[sizeof buf - 1]; p++)
1711 	{
1712 		if (backslash)
1713 		{
1714 			backslash = false;
1715 			if (*p != ' ')
1716 				*q++ = '\\';
1717 		}
1718 		if (*p == '\\')
1719 			backslash = true;
1720 		else if (*p == '"')
1721 			quotemode = !quotemode;
1722 		else if (quotemode ||
1723 			 strchr(delimbuf, (int) *p) == NULL)
1724 			*q++ = *p;
1725 		else
1726 			break;
1727 	}
1728 
1729 	if (delimptr != NULL)
1730 		*delimptr = p;
1731 	*q++ = '\0';
1732 	if (st != NULL)
1733 		*st = !(quotemode || backslash);
1734 	return buf;
1735 }
1736 /*
1737 **  MAKEARGV -- break up a string into words
1738 **
1739 **	Parameters:
1740 **		p -- the string to break up.
1741 **
1742 **	Returns:
1743 **		a char **argv (dynamically allocated)
1744 **
1745 **	Side Effects:
1746 **		munges p.
1747 */
1748 
1749 static char **
1750 makeargv(p)
1751 	register char *p;
1752 {
1753 	char *q;
1754 	int i;
1755 	char **avp;
1756 	char *argv[MAXPV + 1];
1757 
1758 	/* take apart the words */
1759 	i = 0;
1760 	while (*p != '\0' && i < MAXPV)
1761 	{
1762 		q = p;
1763 		while (*p != '\0' && !(isascii(*p) && isspace(*p)))
1764 			p++;
1765 		while (isascii(*p) && isspace(*p))
1766 			*p++ = '\0';
1767 		argv[i++] = newstr(q);
1768 	}
1769 	argv[i++] = NULL;
1770 
1771 	/* now make a copy of the argv */
1772 	avp = (char **) xalloc(sizeof *avp * i);
1773 	memmove((char *) avp, (char *) argv, sizeof *avp * i);
1774 
1775 	return avp;
1776 }
1777 /*
1778 **  PRINTRULES -- print rewrite rules (for debugging)
1779 **
1780 **	Parameters:
1781 **		none.
1782 **
1783 **	Returns:
1784 **		none.
1785 **
1786 **	Side Effects:
1787 **		prints rewrite rules.
1788 */
1789 
1790 void
1791 printrules()
1792 {
1793 	register struct rewrite *rwp;
1794 	register int ruleset;
1795 
1796 	for (ruleset = 0; ruleset < 10; ruleset++)
1797 	{
1798 		if (RewriteRules[ruleset] == NULL)
1799 			continue;
1800 		sm_dprintf("\n----Rule Set %d:", ruleset);
1801 
1802 		for (rwp = RewriteRules[ruleset]; rwp != NULL; rwp = rwp->r_next)
1803 		{
1804 			sm_dprintf("\nLHS:");
1805 			printav(sm_debug_file(), rwp->r_lhs);
1806 			sm_dprintf("RHS:");
1807 			printav(sm_debug_file(), rwp->r_rhs);
1808 		}
1809 	}
1810 }
1811 /*
1812 **  PRINTMAILER -- print mailer structure (for debugging)
1813 **
1814 **	Parameters:
1815 **		fp -- output file
1816 **		m -- the mailer to print
1817 **
1818 **	Returns:
1819 **		none.
1820 */
1821 
1822 void
1823 printmailer(fp, m)
1824 	SM_FILE_T *fp;
1825 	register MAILER *m;
1826 {
1827 	int j;
1828 
1829 	(void) sm_io_fprintf(fp, SM_TIME_DEFAULT,
1830 			     "mailer %d (%s): P=%s S=", m->m_mno, m->m_name,
1831 			     m->m_mailer);
1832 	if (RuleSetNames[m->m_se_rwset] == NULL)
1833 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%d/",
1834 				     m->m_se_rwset);
1835 	else
1836 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%s/",
1837 				     RuleSetNames[m->m_se_rwset]);
1838 	if (RuleSetNames[m->m_sh_rwset] == NULL)
1839 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%d R=",
1840 				     m->m_sh_rwset);
1841 	else
1842 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%s R=",
1843 				     RuleSetNames[m->m_sh_rwset]);
1844 	if (RuleSetNames[m->m_re_rwset] == NULL)
1845 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%d/",
1846 				     m->m_re_rwset);
1847 	else
1848 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%s/",
1849 				     RuleSetNames[m->m_re_rwset]);
1850 	if (RuleSetNames[m->m_rh_rwset] == NULL)
1851 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%d ",
1852 				     m->m_rh_rwset);
1853 	else
1854 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%s ",
1855 				     RuleSetNames[m->m_rh_rwset]);
1856 	(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "M=%ld U=%d:%d F=",
1857 			     m->m_maxsize, (int) m->m_uid, (int) m->m_gid);
1858 	for (j = '\0'; j <= '\177'; j++)
1859 		if (bitnset(j, m->m_flags))
1860 			(void) sm_io_putc(fp, SM_TIME_DEFAULT, j);
1861 	(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, " L=%d E=",
1862 			     m->m_linelimit);
1863 	xputs(fp, m->m_eol);
1864 	if (m->m_defcharset != NULL)
1865 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, " C=%s",
1866 				     m->m_defcharset);
1867 	(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, " T=%s/%s/%s",
1868 			     m->m_mtatype == NULL
1869 				? "<undefined>" : m->m_mtatype,
1870 			     m->m_addrtype == NULL
1871 				? "<undefined>" : m->m_addrtype,
1872 			     m->m_diagtype == NULL
1873 				? "<undefined>" : m->m_diagtype);
1874 	(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, " r=%d", m->m_maxrcpt);
1875 	if (m->m_argv != NULL)
1876 	{
1877 		char **a = m->m_argv;
1878 
1879 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, " A=");
1880 		while (*a != NULL)
1881 		{
1882 			if (a != m->m_argv)
1883 				(void) sm_io_fprintf(fp, SM_TIME_DEFAULT,
1884 						     " ");
1885 			xputs(fp, *a++);
1886 		}
1887 	}
1888 	(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "\n");
1889 }
1890 /*
1891 **  SETOPTION -- set global processing option
1892 **
1893 **	Parameters:
1894 **		opt -- option name.
1895 **		val -- option value (as a text string).
1896 **		safe -- set if this came from a configuration file.
1897 **			Some options (if set from the command line) will
1898 **			reset the user id to avoid security problems.
1899 **		sticky -- if set, don't let other setoptions override
1900 **			this value.
1901 **		e -- the main envelope.
1902 **
1903 **	Returns:
1904 **		none.
1905 **
1906 **	Side Effects:
1907 **		Sets options as implied by the arguments.
1908 */
1909 
1910 static BITMAP256	StickyOpt;		/* set if option is stuck */
1911 
1912 #if NAMED_BIND
1913 
1914 static struct resolverflags
1915 {
1916 	char	*rf_name;	/* name of the flag */
1917 	long	rf_bits;	/* bits to set/clear */
1918 } ResolverFlags[] =
1919 {
1920 	{ "debug",	RES_DEBUG	},
1921 	{ "aaonly",	RES_AAONLY	},
1922 	{ "usevc",	RES_USEVC	},
1923 	{ "primary",	RES_PRIMARY	},
1924 	{ "igntc",	RES_IGNTC	},
1925 	{ "recurse",	RES_RECURSE	},
1926 	{ "defnames",	RES_DEFNAMES	},
1927 	{ "stayopen",	RES_STAYOPEN	},
1928 	{ "dnsrch",	RES_DNSRCH	},
1929 # ifdef RES_USE_INET6
1930 	{ "use_inet6",	RES_USE_INET6	},
1931 # endif /* RES_USE_INET6 */
1932 	{ "true",	0		},	/* avoid error on old syntax */
1933 	{ NULL,		0		}
1934 };
1935 
1936 #endif /* NAMED_BIND */
1937 
1938 #define OI_NONE		0	/* no special treatment */
1939 #define OI_SAFE		0x0001	/* safe for random people to use */
1940 #define OI_SUBOPT	0x0002	/* option has suboptions */
1941 
1942 static struct optioninfo
1943 {
1944 	char		*o_name;	/* long name of option */
1945 	unsigned char	o_code;		/* short name of option */
1946 	unsigned short	o_flags;	/* option flags */
1947 } OptionTab[] =
1948 {
1949 #if defined(SUN_EXTENSIONS) && defined(REMOTE_MODE)
1950 	{ "RemoteMode",			'>',		OI_NONE	},
1951 #endif /* defined(SUN_EXTENSIONS) && defined(REMOTE_MODE) */
1952 	{ "SevenBitInput",		'7',		OI_SAFE	},
1953 	{ "EightBitMode",		'8',		OI_SAFE	},
1954 	{ "AliasFile",			'A',		OI_NONE	},
1955 	{ "AliasWait",			'a',		OI_NONE	},
1956 	{ "BlankSub",			'B',		OI_NONE	},
1957 	{ "MinFreeBlocks",		'b',		OI_SAFE	},
1958 	{ "CheckpointInterval",		'C',		OI_SAFE	},
1959 	{ "HoldExpensive",		'c',		OI_NONE	},
1960 	{ "DeliveryMode",		'd',		OI_SAFE	},
1961 	{ "ErrorHeader",		'E',		OI_NONE	},
1962 	{ "ErrorMode",			'e',		OI_SAFE	},
1963 	{ "TempFileMode",		'F',		OI_NONE	},
1964 	{ "SaveFromLine",		'f',		OI_NONE	},
1965 	{ "MatchGECOS",			'G',		OI_NONE	},
1966 
1967 	/* no long name, just here to avoid problems in setoption */
1968 	{ "",				'g',		OI_NONE	},
1969 	{ "HelpFile",			'H',		OI_NONE	},
1970 	{ "MaxHopCount",		'h',		OI_NONE	},
1971 	{ "ResolverOptions",		'I',		OI_NONE	},
1972 	{ "IgnoreDots",			'i',		OI_SAFE	},
1973 	{ "ForwardPath",		'J',		OI_NONE	},
1974 	{ "SendMimeErrors",		'j',		OI_SAFE	},
1975 	{ "ConnectionCacheSize",	'k',		OI_NONE	},
1976 	{ "ConnectionCacheTimeout",	'K',		OI_NONE	},
1977 	{ "UseErrorsTo",		'l',		OI_NONE	},
1978 	{ "LogLevel",			'L',		OI_SAFE	},
1979 	{ "MeToo",			'm',		OI_SAFE	},
1980 
1981 	/* no long name, just here to avoid problems in setoption */
1982 	{ "",				'M',		OI_NONE	},
1983 	{ "CheckAliases",		'n',		OI_NONE	},
1984 	{ "OldStyleHeaders",		'o',		OI_SAFE	},
1985 	{ "DaemonPortOptions",		'O',		OI_NONE	},
1986 	{ "PrivacyOptions",		'p',		OI_SAFE	},
1987 	{ "PostmasterCopy",		'P',		OI_NONE	},
1988 	{ "QueueFactor",		'q',		OI_NONE	},
1989 	{ "QueueDirectory",		'Q',		OI_NONE	},
1990 	{ "DontPruneRoutes",		'R',		OI_NONE	},
1991 	{ "Timeout",			'r',		OI_SUBOPT },
1992 	{ "StatusFile",			'S',		OI_NONE	},
1993 	{ "SuperSafe",			's',		OI_SAFE	},
1994 	{ "QueueTimeout",		'T',		OI_NONE	},
1995 	{ "TimeZoneSpec",		't',		OI_NONE	},
1996 	{ "UserDatabaseSpec",		'U',		OI_NONE	},
1997 	{ "DefaultUser",		'u',		OI_NONE	},
1998 	{ "FallbackMXhost",		'V',		OI_NONE	},
1999 	{ "Verbose",			'v',		OI_SAFE	},
2000 	{ "TryNullMXList",		'w',		OI_NONE	},
2001 	{ "QueueLA",			'x',		OI_NONE	},
2002 	{ "RefuseLA",			'X',		OI_NONE	},
2003 	{ "RecipientFactor",		'y',		OI_NONE	},
2004 	{ "ForkEachJob",		'Y',		OI_NONE	},
2005 	{ "ClassFactor",		'z',		OI_NONE	},
2006 	{ "RetryFactor",		'Z',		OI_NONE	},
2007 #define O_QUEUESORTORD	0x81
2008 	{ "QueueSortOrder",		O_QUEUESORTORD,	OI_SAFE	},
2009 #define O_HOSTSFILE	0x82
2010 	{ "HostsFile",			O_HOSTSFILE,	OI_NONE	},
2011 #define O_MQA		0x83
2012 	{ "MinQueueAge",		O_MQA,		OI_SAFE	},
2013 #define O_DEFCHARSET	0x85
2014 	{ "DefaultCharSet",		O_DEFCHARSET,	OI_SAFE	},
2015 #define O_SSFILE	0x86
2016 	{ "ServiceSwitchFile",		O_SSFILE,	OI_NONE	},
2017 #define O_DIALDELAY	0x87
2018 	{ "DialDelay",			O_DIALDELAY,	OI_SAFE	},
2019 #define O_NORCPTACTION	0x88
2020 	{ "NoRecipientAction",		O_NORCPTACTION,	OI_SAFE	},
2021 #define O_SAFEFILEENV	0x89
2022 	{ "SafeFileEnvironment",	O_SAFEFILEENV,	OI_NONE	},
2023 #define O_MAXMSGSIZE	0x8a
2024 	{ "MaxMessageSize",		O_MAXMSGSIZE,	OI_NONE	},
2025 #define O_COLONOKINADDR	0x8b
2026 	{ "ColonOkInAddr",		O_COLONOKINADDR, OI_SAFE },
2027 #define O_MAXQUEUERUN	0x8c
2028 	{ "MaxQueueRunSize",		O_MAXQUEUERUN,	OI_SAFE	},
2029 #define O_MAXCHILDREN	0x8d
2030 	{ "MaxDaemonChildren",		O_MAXCHILDREN,	OI_NONE	},
2031 #define O_KEEPCNAMES	0x8e
2032 	{ "DontExpandCnames",		O_KEEPCNAMES,	OI_NONE	},
2033 #define O_MUSTQUOTE	0x8f
2034 	{ "MustQuoteChars",		O_MUSTQUOTE,	OI_NONE	},
2035 #define O_SMTPGREETING	0x90
2036 	{ "SmtpGreetingMessage",	O_SMTPGREETING,	OI_NONE	},
2037 #define O_UNIXFROM	0x91
2038 	{ "UnixFromLine",		O_UNIXFROM,	OI_NONE	},
2039 #define O_OPCHARS	0x92
2040 	{ "OperatorChars",		O_OPCHARS,	OI_NONE	},
2041 #define O_DONTINITGRPS	0x93
2042 	{ "DontInitGroups",		O_DONTINITGRPS,	OI_NONE	},
2043 #define O_SLFH		0x94
2044 	{ "SingleLineFromHeader",	O_SLFH,		OI_SAFE	},
2045 #define O_ABH		0x95
2046 	{ "AllowBogusHELO",		O_ABH,		OI_SAFE	},
2047 #define O_CONNTHROT	0x97
2048 	{ "ConnectionRateThrottle",	O_CONNTHROT,	OI_NONE	},
2049 #define O_UGW		0x99
2050 	{ "UnsafeGroupWrites",		O_UGW,		OI_NONE	},
2051 #define O_DBLBOUNCE	0x9a
2052 	{ "DoubleBounceAddress",	O_DBLBOUNCE,	OI_NONE	},
2053 #define O_HSDIR		0x9b
2054 	{ "HostStatusDirectory",	O_HSDIR,	OI_NONE	},
2055 #define O_SINGTHREAD	0x9c
2056 	{ "SingleThreadDelivery",	O_SINGTHREAD,	OI_NONE	},
2057 #define O_RUNASUSER	0x9d
2058 	{ "RunAsUser",			O_RUNASUSER,	OI_NONE	},
2059 #define O_DSN_RRT	0x9e
2060 	{ "RrtImpliesDsn",		O_DSN_RRT,	OI_NONE	},
2061 #define O_PIDFILE	0x9f
2062 	{ "PidFile",			O_PIDFILE,	OI_NONE	},
2063 #define O_DONTBLAMESENDMAIL	0xa0
2064 	{ "DontBlameSendmail",		O_DONTBLAMESENDMAIL,	OI_NONE	},
2065 #define O_DPI		0xa1
2066 	{ "DontProbeInterfaces",	O_DPI,		OI_NONE	},
2067 #define O_MAXRCPT	0xa2
2068 	{ "MaxRecipientsPerMessage",	O_MAXRCPT,	OI_SAFE	},
2069 #define O_DEADLETTER	0xa3
2070 	{ "DeadLetterDrop",		O_DEADLETTER,	OI_NONE	},
2071 #if _FFR_DONTLOCKFILESFORREAD_OPTION
2072 # define O_DONTLOCK	0xa4
2073 	{ "DontLockFilesForRead",	O_DONTLOCK,	OI_NONE	},
2074 #endif /* _FFR_DONTLOCKFILESFORREAD_OPTION */
2075 #define O_MAXALIASRCSN	0xa5
2076 	{ "MaxAliasRecursion",		O_MAXALIASRCSN,	OI_NONE	},
2077 #define O_CNCTONLYTO	0xa6
2078 	{ "ConnectOnlyTo",		O_CNCTONLYTO,	OI_NONE	},
2079 #define O_TRUSTUSER	0xa7
2080 	{ "TrustedUser",		O_TRUSTUSER,	OI_NONE	},
2081 #define O_MAXMIMEHDRLEN	0xa8
2082 	{ "MaxMimeHeaderLength",	O_MAXMIMEHDRLEN,	OI_NONE	},
2083 #define O_CONTROLSOCKET	0xa9
2084 	{ "ControlSocketName",		O_CONTROLSOCKET,	OI_NONE	},
2085 #define O_MAXHDRSLEN	0xaa
2086 	{ "MaxHeadersLength",		O_MAXHDRSLEN,	OI_NONE	},
2087 #if _FFR_MAX_FORWARD_ENTRIES
2088 # define O_MAXFORWARD	0xab
2089 	{ "MaxForwardEntries",		O_MAXFORWARD,	OI_NONE	},
2090 #endif /* _FFR_MAX_FORWARD_ENTRIES */
2091 #define O_PROCTITLEPREFIX	0xac
2092 	{ "ProcessTitlePrefix",		O_PROCTITLEPREFIX,	OI_NONE	},
2093 #define O_SASLINFO	0xad
2094 #if _FFR_ALLOW_SASLINFO
2095 	{ "DefaultAuthInfo",		O_SASLINFO,	OI_SAFE	},
2096 #else /* _FFR_ALLOW_SASLINFO */
2097 	{ "DefaultAuthInfo",		O_SASLINFO,	OI_NONE	},
2098 #endif /* _FFR_ALLOW_SASLINFO */
2099 #define O_SASLMECH	0xae
2100 	{ "AuthMechanisms",		O_SASLMECH,	OI_NONE	},
2101 #define O_CLIENTPORT	0xaf
2102 	{ "ClientPortOptions",		O_CLIENTPORT,	OI_NONE	},
2103 #define O_DF_BUFSIZE	0xb0
2104 	{ "DataFileBufferSize",		O_DF_BUFSIZE,	OI_NONE	},
2105 #define O_XF_BUFSIZE	0xb1
2106 	{ "XscriptFileBufferSize",	O_XF_BUFSIZE,	OI_NONE	},
2107 #define O_LDAPDEFAULTSPEC	0xb2
2108 	{ "LDAPDefaultSpec",		O_LDAPDEFAULTSPEC,	OI_NONE	},
2109 #define O_SRVCERTFILE	0xb4
2110 	{ "ServerCertFile",		O_SRVCERTFILE,	OI_NONE	},
2111 #define O_SRVKEYFILE	0xb5
2112 	{ "ServerKeyFile",		O_SRVKEYFILE,	OI_NONE	},
2113 #define O_CLTCERTFILE	0xb6
2114 	{ "ClientCertFile",		O_CLTCERTFILE,	OI_NONE	},
2115 #define O_CLTKEYFILE	0xb7
2116 	{ "ClientKeyFile",		O_CLTKEYFILE,	OI_NONE	},
2117 #define O_CACERTFILE	0xb8
2118 	{ "CACertFile",			O_CACERTFILE,	OI_NONE	},
2119 #define O_CACERTPATH	0xb9
2120 	{ "CACertPath",			O_CACERTPATH,	OI_NONE	},
2121 #define O_DHPARAMS	0xba
2122 	{ "DHParameters",		O_DHPARAMS,	OI_NONE	},
2123 #define O_INPUTMILTER	0xbb
2124 	{ "InputMailFilters",		O_INPUTMILTER,	OI_NONE	},
2125 #define O_MILTER	0xbc
2126 	{ "Milter",			O_MILTER,	OI_SUBOPT	},
2127 #define O_SASLOPTS	0xbd
2128 	{ "AuthOptions",		O_SASLOPTS,	OI_NONE	},
2129 #define O_QUEUE_FILE_MODE	0xbe
2130 	{ "QueueFileMode",		O_QUEUE_FILE_MODE, OI_NONE	},
2131 #if _FFR_TLS_1
2132 # define O_DHPARAMS5	0xbf
2133 	{ "DHParameters512",		O_DHPARAMS5,	OI_NONE	},
2134 # define O_CIPHERLIST	0xc0
2135 	{ "CipherList",			O_CIPHERLIST,	OI_NONE	},
2136 #endif /* _FFR_TLS_1 */
2137 #define O_RANDFILE	0xc1
2138 	{ "RandFile",			O_RANDFILE,	OI_NONE	},
2139 #define O_TLS_SRV_OPTS	0xc2
2140 	{ "TLSSrvOptions",		O_TLS_SRV_OPTS,	OI_NONE	},
2141 #define O_RCPTTHROT	0xc3
2142 	{ "BadRcptThrottle",		O_RCPTTHROT,	OI_SAFE	},
2143 #define O_DLVR_MIN	0xc4
2144 	{ "DeliverByMin",		O_DLVR_MIN,	OI_NONE	},
2145 #define O_MAXQUEUECHILDREN	0xc5
2146 	{ "MaxQueueChildren",		O_MAXQUEUECHILDREN,	OI_NONE	},
2147 #define O_MAXRUNNERSPERQUEUE	0xc6
2148 	{ "MaxRunnersPerQueue",		O_MAXRUNNERSPERQUEUE,	OI_NONE },
2149 #define O_DIRECTSUBMODIFIERS	0xc7
2150 	{ "DirectSubmissionModifiers",	O_DIRECTSUBMODIFIERS,	OI_NONE },
2151 #define O_NICEQUEUERUN	0xc8
2152 	{ "NiceQueueRun",		O_NICEQUEUERUN,	OI_NONE	},
2153 #define O_SHMKEY	0xc9
2154 	{ "SharedMemoryKey",		O_SHMKEY,	OI_NONE	},
2155 #define O_SASLBITS	0xca
2156 	{ "AuthMaxBits",		O_SASLBITS,	OI_NONE	},
2157 #define O_MBDB		0xcb
2158 	{ "MailboxDatabase",		O_MBDB,		OI_NONE	},
2159 #define O_MSQ		0xcc
2160 	{ "UseMSP",	O_MSQ,		OI_NONE	},
2161 #define O_DELAY_LA	0xcd
2162 	{ "DelayLA",	O_DELAY_LA,	OI_NONE	},
2163 #define O_FASTSPLIT	0xce
2164 	{ "FastSplit",	O_FASTSPLIT,	OI_NONE	},
2165 #if _FFR_SOFT_BOUNCE
2166 # define O_SOFTBOUNCE	0xcf
2167 	{ "SoftBounce",	O_SOFTBOUNCE,	OI_NONE	},
2168 #endif /* _FFR_SOFT_BOUNCE */
2169 #if _FFR_SELECT_SHM
2170 # define O_SHMKEYFILE	0xd0
2171 	{ "SharedMemoryKeyFile",	O_SHMKEYFILE,	OI_NONE	},
2172 #endif /* _FFR_SELECT_SHM */
2173 #define O_REJECTLOGINTERVAL	0xd1
2174 	{ "RejectLogInterval",	O_REJECTLOGINTERVAL,	OI_NONE	},
2175 #define O_REQUIRES_DIR_FSYNC	0xd2
2176 	{ "RequiresDirfsync",	O_REQUIRES_DIR_FSYNC,	OI_NONE	},
2177 #define O_CONNECTION_RATE_WINDOW_SIZE	0xd3
2178 	{ "ConnectionRateWindowSize", O_CONNECTION_RATE_WINDOW_SIZE, OI_NONE },
2179 #define O_CRLFILE	0xd4
2180 	{ "CRLFile",		O_CRLFILE,	OI_NONE	},
2181 #define O_FALLBACKSMARTHOST	0xd5
2182 	{ "FallbackSmartHost",		O_FALLBACKSMARTHOST,	OI_NONE	},
2183 #define O_SASLREALM	0xd6
2184 	{ "AuthRealm",		O_SASLREALM,	OI_NONE	},
2185 #if _FFR_CRLPATH
2186 # define O_CRLPATH	0xd7
2187 	{ "CRLPath",		O_CRLPATH,	OI_NONE	},
2188 #endif /* _FFR_CRLPATH */
2189 #if _FFR_HELONAME
2190 # define O_HELONAME 0xd8
2191 	{ "HeloName",   O_HELONAME,     OI_NONE },
2192 #endif /* _FFR_HELONAME */
2193 
2194 	{ NULL,				'\0',		OI_NONE	}
2195 };
2196 
2197 # define CANONIFY(val)
2198 
2199 # define SET_OPT_DEFAULT(opt, val)	opt = val
2200 
2201 /* set a string option by expanding the value and assigning it */
2202 /* WARNING this belongs ONLY into a case statement! */
2203 #define SET_STRING_EXP(str)	\
2204 		expand(val, exbuf, sizeof exbuf, e);	\
2205 		newval = sm_pstrdup_x(exbuf);		\
2206 		if (str != NULL)	\
2207 			sm_free(str);	\
2208 		CANONIFY(newval);	\
2209 		str = newval;		\
2210 		break
2211 
2212 #define OPTNAME	o->o_name == NULL ? "<unknown>" : o->o_name
2213 
2214 void
2215 setoption(opt, val, safe, sticky, e)
2216 	int opt;
2217 	char *val;
2218 	bool safe;
2219 	bool sticky;
2220 	register ENVELOPE *e;
2221 {
2222 	register char *p;
2223 	register struct optioninfo *o;
2224 	char *subopt;
2225 	int mid;
2226 	bool can_setuid = RunAsUid == 0;
2227 	auto char *ep;
2228 	char buf[50];
2229 	extern bool Warn_Q_option;
2230 #if _FFR_ALLOW_SASLINFO
2231 	extern unsigned int SubmitMode;
2232 #endif /* _FFR_ALLOW_SASLINFO */
2233 #if STARTTLS
2234 	char *newval;
2235 	char exbuf[MAXLINE];
2236 #endif /* STARTTLS */
2237 
2238 	errno = 0;
2239 	if (opt == ' ')
2240 	{
2241 		/* full word options */
2242 		struct optioninfo *sel;
2243 
2244 		p = strchr(val, '=');
2245 		if (p == NULL)
2246 			p = &val[strlen(val)];
2247 		while (*--p == ' ')
2248 			continue;
2249 		while (*++p == ' ')
2250 			*p = '\0';
2251 		if (p == val)
2252 		{
2253 			syserr("readcf: null option name");
2254 			return;
2255 		}
2256 		if (*p == '=')
2257 			*p++ = '\0';
2258 		while (*p == ' ')
2259 			p++;
2260 		subopt = strchr(val, '.');
2261 		if (subopt != NULL)
2262 			*subopt++ = '\0';
2263 		sel = NULL;
2264 		for (o = OptionTab; o->o_name != NULL; o++)
2265 		{
2266 			if (sm_strncasecmp(o->o_name, val, strlen(val)) != 0)
2267 				continue;
2268 			if (strlen(o->o_name) == strlen(val))
2269 			{
2270 				/* completely specified -- this must be it */
2271 				sel = NULL;
2272 				break;
2273 			}
2274 			if (sel != NULL)
2275 				break;
2276 			sel = o;
2277 		}
2278 		if (sel != NULL && o->o_name == NULL)
2279 			o = sel;
2280 		else if (o->o_name == NULL)
2281 		{
2282 			syserr("readcf: unknown option name %s", val);
2283 			return;
2284 		}
2285 		else if (sel != NULL)
2286 		{
2287 			syserr("readcf: ambiguous option name %s (matches %s and %s)",
2288 				val, sel->o_name, o->o_name);
2289 			return;
2290 		}
2291 		if (strlen(val) != strlen(o->o_name))
2292 		{
2293 			int oldVerbose = Verbose;
2294 
2295 			Verbose = 1;
2296 			message("Option %s used as abbreviation for %s",
2297 				val, o->o_name);
2298 			Verbose = oldVerbose;
2299 		}
2300 		opt = o->o_code;
2301 		val = p;
2302 	}
2303 	else
2304 	{
2305 		for (o = OptionTab; o->o_name != NULL; o++)
2306 		{
2307 			if (o->o_code == opt)
2308 				break;
2309 		}
2310 		if (o->o_name == NULL)
2311 		{
2312 			syserr("readcf: unknown option name 0x%x", opt & 0xff);
2313 			return;
2314 		}
2315 		subopt = NULL;
2316 	}
2317 
2318 	if (subopt != NULL && !bitset(OI_SUBOPT, o->o_flags))
2319 	{
2320 		if (tTd(37, 1))
2321 			sm_dprintf("setoption: %s does not support suboptions, ignoring .%s\n",
2322 				   OPTNAME, subopt);
2323 		subopt = NULL;
2324 	}
2325 
2326 	if (tTd(37, 1))
2327 	{
2328 		sm_dprintf(isascii(opt) && isprint(opt) ?
2329 			   "setoption %s (%c)%s%s=" :
2330 			   "setoption %s (0x%x)%s%s=",
2331 			   OPTNAME, opt, subopt == NULL ? "" : ".",
2332 			   subopt == NULL ? "" : subopt);
2333 		xputs(sm_debug_file(), val);
2334 	}
2335 
2336 	/*
2337 	**  See if this option is preset for us.
2338 	*/
2339 
2340 	if (!sticky && bitnset(opt, StickyOpt))
2341 	{
2342 		if (tTd(37, 1))
2343 			sm_dprintf(" (ignored)\n");
2344 		return;
2345 	}
2346 
2347 	/*
2348 	**  Check to see if this option can be specified by this user.
2349 	*/
2350 
2351 	if (!safe && RealUid == 0)
2352 		safe = true;
2353 	if (!safe && !bitset(OI_SAFE, o->o_flags))
2354 	{
2355 		if (opt != 'M' || (val[0] != 'r' && val[0] != 's'))
2356 		{
2357 			int dp;
2358 
2359 			if (tTd(37, 1))
2360 				sm_dprintf(" (unsafe)");
2361 			dp = drop_privileges(true);
2362 			setstat(dp);
2363 		}
2364 	}
2365 	if (tTd(37, 1))
2366 		sm_dprintf("\n");
2367 
2368 	switch (opt & 0xff)
2369 	{
2370 	  case '7':		/* force seven-bit input */
2371 		SevenBitInput = atobool(val);
2372 		break;
2373 
2374 	  case '8':		/* handling of 8-bit input */
2375 #if MIME8TO7
2376 		switch (*val)
2377 		{
2378 		  case 'p':		/* pass 8 bit, convert MIME */
2379 			MimeMode = MM_CVTMIME|MM_PASS8BIT;
2380 			break;
2381 
2382 		  case 'm':		/* convert 8-bit, convert MIME */
2383 			MimeMode = MM_CVTMIME|MM_MIME8BIT;
2384 			break;
2385 
2386 		  case 's':		/* strict adherence */
2387 			MimeMode = MM_CVTMIME;
2388 			break;
2389 
2390 # if 0
2391 		  case 'r':		/* reject 8-bit, don't convert MIME */
2392 			MimeMode = 0;
2393 			break;
2394 
2395 		  case 'j':		/* "just send 8" */
2396 			MimeMode = MM_PASS8BIT;
2397 			break;
2398 
2399 		  case 'a':		/* encode 8 bit if available */
2400 			MimeMode = MM_MIME8BIT|MM_PASS8BIT|MM_CVTMIME;
2401 			break;
2402 
2403 		  case 'c':		/* convert 8 bit to MIME, never 7 bit */
2404 			MimeMode = MM_MIME8BIT;
2405 			break;
2406 # endif /* 0 */
2407 
2408 		  default:
2409 			syserr("Unknown 8-bit mode %c", *val);
2410 			finis(false, true, EX_USAGE);
2411 		}
2412 #else /* MIME8TO7 */
2413 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
2414 				     "Warning: Option: %s requires MIME8TO7 support\n",
2415 				     OPTNAME);
2416 #endif /* MIME8TO7 */
2417 		break;
2418 
2419 	  case 'A':		/* set default alias file */
2420 		if (val[0] == '\0')
2421 		{
2422 			char *al;
2423 
2424 			SET_OPT_DEFAULT(al, "aliases");
2425 			setalias(al);
2426 		}
2427 		else
2428 			setalias(val);
2429 		break;
2430 
2431 	  case 'a':		/* look N minutes for "@:@" in alias file */
2432 		if (val[0] == '\0')
2433 			SafeAlias = 5 MINUTES;
2434 		else
2435 			SafeAlias = convtime(val, 'm');
2436 		break;
2437 
2438 	  case 'B':		/* substitution for blank character */
2439 		SpaceSub = val[0];
2440 		if (SpaceSub == '\0')
2441 			SpaceSub = ' ';
2442 		break;
2443 
2444 	  case 'b':		/* min blocks free on queue fs/max msg size */
2445 		p = strchr(val, '/');
2446 		if (p != NULL)
2447 		{
2448 			*p++ = '\0';
2449 			MaxMessageSize = atol(p);
2450 		}
2451 		MinBlocksFree = atol(val);
2452 		break;
2453 
2454 	  case 'c':		/* don't connect to "expensive" mailers */
2455 		NoConnect = atobool(val);
2456 		break;
2457 
2458 	  case 'C':		/* checkpoint every N addresses */
2459 		if (safe || CheckpointInterval > atoi(val))
2460 			CheckpointInterval = atoi(val);
2461 		break;
2462 
2463 	  case 'd':		/* delivery mode */
2464 		switch (*val)
2465 		{
2466 		  case '\0':
2467 			set_delivery_mode(SM_DELIVER, e);
2468 			break;
2469 
2470 		  case SM_QUEUE:	/* queue only */
2471 		  case SM_DEFER:	/* queue only and defer map lookups */
2472 		  case SM_DELIVER:	/* do everything */
2473 		  case SM_FORK:		/* fork after verification */
2474 			set_delivery_mode(*val, e);
2475 			break;
2476 
2477 		  default:
2478 			syserr("Unknown delivery mode %c", *val);
2479 			finis(false, true, EX_USAGE);
2480 		}
2481 		break;
2482 
2483 	  case 'E':		/* error message header/header file */
2484 		if (*val != '\0')
2485 			ErrMsgFile = newstr(val);
2486 		break;
2487 
2488 	  case 'e':		/* set error processing mode */
2489 		switch (*val)
2490 		{
2491 		  case EM_QUIET:	/* be silent about it */
2492 		  case EM_MAIL:		/* mail back */
2493 		  case EM_BERKNET:	/* do berknet error processing */
2494 		  case EM_WRITE:	/* write back (or mail) */
2495 		  case EM_PRINT:	/* print errors normally (default) */
2496 			e->e_errormode = *val;
2497 			break;
2498 		}
2499 		break;
2500 
2501 	  case 'F':		/* file mode */
2502 		FileMode = atooct(val) & 0777;
2503 		break;
2504 
2505 	  case 'f':		/* save Unix-style From lines on front */
2506 		SaveFrom = atobool(val);
2507 		break;
2508 
2509 	  case 'G':		/* match recipients against GECOS field */
2510 		MatchGecos = atobool(val);
2511 		break;
2512 
2513 	  case 'g':		/* default gid */
2514   g_opt:
2515 		if (isascii(*val) && isdigit(*val))
2516 			DefGid = atoi(val);
2517 		else
2518 		{
2519 			register struct group *gr;
2520 
2521 			DefGid = -1;
2522 			gr = getgrnam(val);
2523 			if (gr == NULL)
2524 				syserr("readcf: option %c: unknown group %s",
2525 					opt, val);
2526 			else
2527 				DefGid = gr->gr_gid;
2528 		}
2529 		break;
2530 
2531 	  case 'H':		/* help file */
2532 		if (val[0] == '\0')
2533 		{
2534 			SET_OPT_DEFAULT(HelpFile, "helpfile");
2535 		}
2536 		else
2537 		{
2538 			CANONIFY(val);
2539 			HelpFile = newstr(val);
2540 		}
2541 		break;
2542 
2543 	  case 'h':		/* maximum hop count */
2544 		MaxHopCount = atoi(val);
2545 		break;
2546 
2547 	  case 'I':		/* use internet domain name server */
2548 #if NAMED_BIND
2549 		for (p = val; *p != 0; )
2550 		{
2551 			bool clearmode;
2552 			char *q;
2553 			struct resolverflags *rfp;
2554 
2555 			while (*p == ' ')
2556 				p++;
2557 			if (*p == '\0')
2558 				break;
2559 			clearmode = false;
2560 			if (*p == '-')
2561 				clearmode = true;
2562 			else if (*p != '+')
2563 				p--;
2564 			p++;
2565 			q = p;
2566 			while (*p != '\0' && !(isascii(*p) && isspace(*p)))
2567 				p++;
2568 			if (*p != '\0')
2569 				*p++ = '\0';
2570 			if (sm_strcasecmp(q, "HasWildcardMX") == 0)
2571 			{
2572 				HasWildcardMX = !clearmode;
2573 				continue;
2574 			}
2575 			if (sm_strcasecmp(q, "WorkAroundBrokenAAAA") == 0)
2576 			{
2577 				WorkAroundBrokenAAAA = !clearmode;
2578 				continue;
2579 			}
2580 			for (rfp = ResolverFlags; rfp->rf_name != NULL; rfp++)
2581 			{
2582 				if (sm_strcasecmp(q, rfp->rf_name) == 0)
2583 					break;
2584 			}
2585 			if (rfp->rf_name == NULL)
2586 				syserr("readcf: I option value %s unrecognized", q);
2587 			else if (clearmode)
2588 				_res.options &= ~rfp->rf_bits;
2589 			else
2590 				_res.options |= rfp->rf_bits;
2591 		}
2592 		if (tTd(8, 2))
2593 			sm_dprintf("_res.options = %x, HasWildcardMX = %d\n",
2594 				   (unsigned int) _res.options, HasWildcardMX);
2595 #else /* NAMED_BIND */
2596 		usrerr("name server (I option) specified but BIND not compiled in");
2597 #endif /* NAMED_BIND */
2598 		break;
2599 
2600 	  case 'i':		/* ignore dot lines in message */
2601 		IgnrDot = atobool(val);
2602 		break;
2603 
2604 	  case 'j':		/* send errors in MIME (RFC 1341) format */
2605 		SendMIMEErrors = atobool(val);
2606 		break;
2607 
2608 	  case 'J':		/* .forward search path */
2609 		CANONIFY(val);
2610 		ForwardPath = newstr(val);
2611 		break;
2612 
2613 	  case 'k':		/* connection cache size */
2614 		MaxMciCache = atoi(val);
2615 		if (MaxMciCache < 0)
2616 			MaxMciCache = 0;
2617 		break;
2618 
2619 	  case 'K':		/* connection cache timeout */
2620 		MciCacheTimeout = convtime(val, 'm');
2621 		break;
2622 
2623 	  case 'l':		/* use Errors-To: header */
2624 		UseErrorsTo = atobool(val);
2625 		break;
2626 
2627 	  case 'L':		/* log level */
2628 		if (safe || LogLevel < atoi(val))
2629 			LogLevel = atoi(val);
2630 		break;
2631 
2632 	  case 'M':		/* define macro */
2633 		sticky = false;
2634 		mid = macid_parse(val, &ep);
2635 		if (mid == 0)
2636 			break;
2637 		p = newstr(ep);
2638 		if (!safe)
2639 			cleanstrcpy(p, p, strlen(p) + 1);
2640 		macdefine(&CurEnv->e_macro, A_TEMP, mid, p);
2641 		break;
2642 
2643 	  case 'm':		/* send to me too */
2644 		MeToo = atobool(val);
2645 		break;
2646 
2647 	  case 'n':		/* validate RHS in newaliases */
2648 		CheckAliases = atobool(val);
2649 		break;
2650 
2651 	    /* 'N' available -- was "net name" */
2652 
2653 	  case 'O':		/* daemon options */
2654 		if (!setdaemonoptions(val))
2655 			syserr("too many daemons defined (%d max)", MAXDAEMONS);
2656 		break;
2657 
2658 	  case 'o':		/* assume old style headers */
2659 		if (atobool(val))
2660 			CurEnv->e_flags |= EF_OLDSTYLE;
2661 		else
2662 			CurEnv->e_flags &= ~EF_OLDSTYLE;
2663 		break;
2664 
2665 	  case 'p':		/* select privacy level */
2666 		p = val;
2667 		for (;;)
2668 		{
2669 			register struct prival *pv;
2670 			extern struct prival PrivacyValues[];
2671 
2672 			while (isascii(*p) && (isspace(*p) || ispunct(*p)))
2673 				p++;
2674 			if (*p == '\0')
2675 				break;
2676 			val = p;
2677 			while (isascii(*p) && isalnum(*p))
2678 				p++;
2679 			if (*p != '\0')
2680 				*p++ = '\0';
2681 
2682 			for (pv = PrivacyValues; pv->pv_name != NULL; pv++)
2683 			{
2684 				if (sm_strcasecmp(val, pv->pv_name) == 0)
2685 					break;
2686 			}
2687 			if (pv->pv_name == NULL)
2688 				syserr("readcf: Op line: %s unrecognized", val);
2689 			else
2690 				PrivacyFlags |= pv->pv_flag;
2691 		}
2692 		sticky = false;
2693 		break;
2694 
2695 	  case 'P':		/* postmaster copy address for returned mail */
2696 		PostMasterCopy = newstr(val);
2697 		break;
2698 
2699 	  case 'q':		/* slope of queue only function */
2700 		QueueFactor = atoi(val);
2701 		break;
2702 
2703 	  case 'Q':		/* queue directory */
2704 		if (val[0] == '\0')
2705 		{
2706 			QueueDir = "mqueue";
2707 		}
2708 		else
2709 		{
2710 			QueueDir = newstr(val);
2711 		}
2712 		if (RealUid != 0 && !safe)
2713 			Warn_Q_option = true;
2714 		break;
2715 
2716 	  case 'R':		/* don't prune routes */
2717 		DontPruneRoutes = atobool(val);
2718 		break;
2719 
2720 	  case 'r':		/* read timeout */
2721 		if (subopt == NULL)
2722 			inittimeouts(val, sticky);
2723 		else
2724 			settimeout(subopt, val, sticky);
2725 		break;
2726 
2727 	  case 'S':		/* status file */
2728 		if (val[0] == '\0')
2729 		{
2730 			SET_OPT_DEFAULT(StatFile, "statistics");
2731 		}
2732 		else
2733 		{
2734 			CANONIFY(val);
2735 			StatFile = newstr(val);
2736 		}
2737 		break;
2738 
2739 	  case 's':		/* be super safe, even if expensive */
2740 		if (tolower(*val) == 'i')
2741 			SuperSafe = SAFE_INTERACTIVE;
2742 		else if (tolower(*val) == 'p')
2743 #if MILTER
2744 			SuperSafe = SAFE_REALLY_POSTMILTER;
2745 #else /* MILTER */
2746 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
2747 				"Warning: SuperSafe=PostMilter requires Milter support (-DMILTER)\n");
2748 #endif /* MILTER */
2749 		else
2750 			SuperSafe = atobool(val) ? SAFE_REALLY : SAFE_NO;
2751 		break;
2752 
2753 	  case 'T':		/* queue timeout */
2754 		p = strchr(val, '/');
2755 		if (p != NULL)
2756 		{
2757 			*p++ = '\0';
2758 			settimeout("queuewarn", p, sticky);
2759 		}
2760 		settimeout("queuereturn", val, sticky);
2761 		break;
2762 
2763 	  case 't':		/* time zone name */
2764 		TimeZoneSpec = newstr(val);
2765 		break;
2766 
2767 	  case 'U':		/* location of user database */
2768 		UdbSpec = newstr(val);
2769 		break;
2770 
2771 	  case 'u':		/* set default uid */
2772 		for (p = val; *p != '\0'; p++)
2773 		{
2774 # if _FFR_DOTTED_USERNAMES
2775 			if (*p == '/' || *p == ':')
2776 # else /* _FFR_DOTTED_USERNAMES */
2777 			if (*p == '.' || *p == '/' || *p == ':')
2778 # endif /* _FFR_DOTTED_USERNAMES */
2779 			{
2780 				*p++ = '\0';
2781 				break;
2782 			}
2783 		}
2784 		if (isascii(*val) && isdigit(*val))
2785 		{
2786 			DefUid = atoi(val);
2787 			setdefuser();
2788 		}
2789 		else
2790 		{
2791 			register struct passwd *pw;
2792 
2793 			DefUid = -1;
2794 			pw = sm_getpwnam(val);
2795 			if (pw == NULL)
2796 			{
2797 				syserr("readcf: option u: unknown user %s", val);
2798 				break;
2799 			}
2800 			else
2801 			{
2802 				DefUid = pw->pw_uid;
2803 				DefGid = pw->pw_gid;
2804 				DefUser = newstr(pw->pw_name);
2805 			}
2806 		}
2807 
2808 # ifdef UID_MAX
2809 		if (DefUid > UID_MAX)
2810 		{
2811 			syserr("readcf: option u: uid value (%ld) > UID_MAX (%ld); ignored",
2812 				(long)DefUid, (long)UID_MAX);
2813 			break;
2814 		}
2815 # endif /* UID_MAX */
2816 
2817 		/* handle the group if it is there */
2818 		if (*p == '\0')
2819 			break;
2820 		val = p;
2821 		goto g_opt;
2822 
2823 	  case 'V':		/* fallback MX host */
2824 		if (val[0] != '\0')
2825 			FallbackMX = newstr(val);
2826 		break;
2827 
2828 	  case 'v':		/* run in verbose mode */
2829 		Verbose = atobool(val) ? 1 : 0;
2830 		break;
2831 
2832 	  case 'w':		/* if we are best MX, try host directly */
2833 		TryNullMXList = atobool(val);
2834 		break;
2835 
2836 	    /* 'W' available -- was wizard password */
2837 
2838 	  case 'x':		/* load avg at which to auto-queue msgs */
2839 		QueueLA = atoi(val);
2840 		break;
2841 
2842 	  case 'X':	/* load avg at which to auto-reject connections */
2843 		RefuseLA = atoi(val);
2844 		break;
2845 
2846 	  case O_DELAY_LA:	/* load avg at which to delay connections */
2847 		DelayLA = atoi(val);
2848 		break;
2849 
2850 	  case 'y':		/* work recipient factor */
2851 		WkRecipFact = atoi(val);
2852 		break;
2853 
2854 	  case 'Y':		/* fork jobs during queue runs */
2855 		ForkQueueRuns = atobool(val);
2856 		break;
2857 
2858 	  case 'z':		/* work message class factor */
2859 		WkClassFact = atoi(val);
2860 		break;
2861 
2862 	  case 'Z':		/* work time factor */
2863 		WkTimeFact = atoi(val);
2864 		break;
2865 
2866 
2867 #if _FFR_QUEUE_GROUP_SORTORDER
2868 	/* coordinate this with makequeue() */
2869 #endif /* _FFR_QUEUE_GROUP_SORTORDER */
2870 	  case O_QUEUESORTORD:	/* queue sorting order */
2871 		switch (*val)
2872 		{
2873 		  case 'f':	/* File Name */
2874 		  case 'F':
2875 			QueueSortOrder = QSO_BYFILENAME;
2876 			break;
2877 
2878 		  case 'h':	/* Host first */
2879 		  case 'H':
2880 			QueueSortOrder = QSO_BYHOST;
2881 			break;
2882 
2883 		  case 'm':	/* Modification time */
2884 		  case 'M':
2885 			QueueSortOrder = QSO_BYMODTIME;
2886 			break;
2887 
2888 		  case 'p':	/* Priority order */
2889 		  case 'P':
2890 			QueueSortOrder = QSO_BYPRIORITY;
2891 			break;
2892 
2893 		  case 't':	/* Submission time */
2894 		  case 'T':
2895 			QueueSortOrder = QSO_BYTIME;
2896 			break;
2897 
2898 		  case 'r':	/* Random */
2899 		  case 'R':
2900 			QueueSortOrder = QSO_RANDOM;
2901 			break;
2902 
2903 #if _FFR_RHS
2904 		  case 's':	/* Shuffled host name */
2905 		  case 'S':
2906 			QueueSortOrder = QSO_BYSHUFFLE;
2907 			break;
2908 #endif /* _FFR_RHS */
2909 
2910 		  case 'n':	/* none */
2911 		  case 'N':
2912 			QueueSortOrder = QSO_NONE;
2913 			break;
2914 
2915 		  default:
2916 			syserr("Invalid queue sort order \"%s\"", val);
2917 		}
2918 		break;
2919 
2920 	  case O_HOSTSFILE:	/* pathname of /etc/hosts file */
2921 		CANONIFY(val);
2922 		HostsFile = newstr(val);
2923 		break;
2924 
2925 	  case O_MQA:		/* minimum queue age between deliveries */
2926 		MinQueueAge = convtime(val, 'm');
2927 		break;
2928 
2929 	  case O_DEFCHARSET:	/* default character set for mimefying */
2930 		DefaultCharSet = newstr(denlstring(val, true, true));
2931 		break;
2932 
2933 	  case O_SSFILE:	/* service switch file */
2934 		CANONIFY(val);
2935 		ServiceSwitchFile = newstr(val);
2936 		break;
2937 
2938 	  case O_DIALDELAY:	/* delay for dial-on-demand operation */
2939 		DialDelay = convtime(val, 's');
2940 		break;
2941 
2942 	  case O_NORCPTACTION:	/* what to do if no recipient */
2943 		if (sm_strcasecmp(val, "none") == 0)
2944 			NoRecipientAction = NRA_NO_ACTION;
2945 		else if (sm_strcasecmp(val, "add-to") == 0)
2946 			NoRecipientAction = NRA_ADD_TO;
2947 		else if (sm_strcasecmp(val, "add-apparently-to") == 0)
2948 			NoRecipientAction = NRA_ADD_APPARENTLY_TO;
2949 		else if (sm_strcasecmp(val, "add-bcc") == 0)
2950 			NoRecipientAction = NRA_ADD_BCC;
2951 		else if (sm_strcasecmp(val, "add-to-undisclosed") == 0)
2952 			NoRecipientAction = NRA_ADD_TO_UNDISCLOSED;
2953 		else
2954 			syserr("Invalid NoRecipientAction: %s", val);
2955 		break;
2956 
2957 	  case O_SAFEFILEENV:	/* chroot() environ for writing to files */
2958 		if (*val == '\0')
2959 			break;
2960 
2961 		/* strip trailing slashes */
2962 		p = val + strlen(val) - 1;
2963 		while (p >= val && *p == '/')
2964 			*p-- = '\0';
2965 
2966 		if (*val == '\0')
2967 			break;
2968 
2969 		SafeFileEnv = newstr(val);
2970 		break;
2971 
2972 	  case O_MAXMSGSIZE:	/* maximum message size */
2973 		MaxMessageSize = atol(val);
2974 		break;
2975 
2976 	  case O_COLONOKINADDR:	/* old style handling of colon addresses */
2977 		ColonOkInAddr = atobool(val);
2978 		break;
2979 
2980 	  case O_MAXQUEUERUN:	/* max # of jobs in a single queue run */
2981 		MaxQueueRun = atoi(val);
2982 		break;
2983 
2984 	  case O_MAXCHILDREN:	/* max # of children of daemon */
2985 		MaxChildren = atoi(val);
2986 		break;
2987 
2988 	  case O_MAXQUEUECHILDREN: /* max # of children of daemon */
2989 		MaxQueueChildren = atoi(val);
2990 		break;
2991 
2992 	  case O_MAXRUNNERSPERQUEUE: /* max # runners in a queue group */
2993 		MaxRunnersPerQueue = atoi(val);
2994 		break;
2995 
2996 	  case O_NICEQUEUERUN:		/* nice queue runs */
2997 #if !HASNICE
2998 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
2999 				     "Warning: NiceQueueRun set on system that doesn't support nice()\n");
3000 #endif /* !HASNICE */
3001 
3002 		/* XXX do we want to check the range? > 0 ? */
3003 		NiceQueueRun = atoi(val);
3004 		break;
3005 
3006 	  case O_SHMKEY:		/* shared memory key */
3007 #if SM_CONF_SHM
3008 		ShmKey = atol(val);
3009 #else /* SM_CONF_SHM */
3010 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3011 				     "Warning: Option: %s requires shared memory support (-DSM_CONF_SHM)\n",
3012 				     OPTNAME);
3013 #endif /* SM_CONF_SHM */
3014 		break;
3015 
3016 #if _FFR_SELECT_SHM
3017 	  case O_SHMKEYFILE:		/* shared memory key file */
3018 # if SM_CONF_SHM
3019 		SET_STRING_EXP(ShmKeyFile);
3020 # else /* SM_CONF_SHM */
3021 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3022 				     "Warning: Option: %s requires shared memory support (-DSM_CONF_SHM)\n",
3023 				     OPTNAME);
3024 		break;
3025 # endif /* SM_CONF_SHM */
3026 #endif /* _FFR_SELECT_SHM */
3027 
3028 #if _FFR_MAX_FORWARD_ENTRIES
3029 	  case O_MAXFORWARD:	/* max # of forward entries */
3030 		MaxForwardEntries = atoi(val);
3031 		break;
3032 #endif /* _FFR_MAX_FORWARD_ENTRIES */
3033 
3034 	  case O_KEEPCNAMES:	/* don't expand CNAME records */
3035 		DontExpandCnames = atobool(val);
3036 		break;
3037 
3038 	  case O_MUSTQUOTE:	/* must quote these characters in phrases */
3039 		(void) sm_strlcpy(buf, "@,;:\\()[]", sizeof buf);
3040 		if (strlen(val) < sizeof buf - 10)
3041 			(void) sm_strlcat(buf, val, sizeof buf);
3042 		else
3043 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3044 					     "Warning: MustQuoteChars too long, ignored.\n");
3045 		MustQuoteChars = newstr(buf);
3046 		break;
3047 
3048 	  case O_SMTPGREETING:	/* SMTP greeting message (old $e macro) */
3049 		SmtpGreeting = newstr(munchstring(val, NULL, '\0'));
3050 		break;
3051 
3052 	  case O_UNIXFROM:	/* UNIX From_ line (old $l macro) */
3053 		UnixFromLine = newstr(munchstring(val, NULL, '\0'));
3054 		break;
3055 
3056 	  case O_OPCHARS:	/* operator characters (old $o macro) */
3057 		if (OperatorChars != NULL)
3058 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3059 					     "Warning: OperatorChars is being redefined.\n         It should only be set before ruleset definitions.\n");
3060 		OperatorChars = newstr(munchstring(val, NULL, '\0'));
3061 		break;
3062 
3063 	  case O_DONTINITGRPS:	/* don't call initgroups(3) */
3064 		DontInitGroups = atobool(val);
3065 		break;
3066 
3067 	  case O_SLFH:		/* make sure from fits on one line */
3068 		SingleLineFromHeader = atobool(val);
3069 		break;
3070 
3071 	  case O_ABH:		/* allow HELO commands with syntax errors */
3072 		AllowBogusHELO = atobool(val);
3073 		break;
3074 
3075 	  case O_CONNTHROT:	/* connection rate throttle */
3076 		ConnRateThrottle = atoi(val);
3077 		break;
3078 
3079 	  case O_UGW:		/* group writable files are unsafe */
3080 		if (!atobool(val))
3081 		{
3082 			setbitn(DBS_GROUPWRITABLEFORWARDFILESAFE,
3083 				DontBlameSendmail);
3084 			setbitn(DBS_GROUPWRITABLEINCLUDEFILESAFE,
3085 				DontBlameSendmail);
3086 		}
3087 		break;
3088 
3089 	  case O_DBLBOUNCE:	/* address to which to send double bounces */
3090 		DoubleBounceAddr = newstr(val);
3091 		break;
3092 
3093 	  case O_HSDIR:		/* persistent host status directory */
3094 		if (val[0] != '\0')
3095 		{
3096 			CANONIFY(val);
3097 			HostStatDir = newstr(val);
3098 		}
3099 		break;
3100 
3101 	  case O_SINGTHREAD:	/* single thread deliveries (requires hsdir) */
3102 		SingleThreadDelivery = atobool(val);
3103 		break;
3104 
3105 	  case O_RUNASUSER:	/* run bulk of code as this user */
3106 		for (p = val; *p != '\0'; p++)
3107 		{
3108 # if _FFR_DOTTED_USERNAMES
3109 			if (*p == '/' || *p == ':')
3110 # else /* _FFR_DOTTED_USERNAMES */
3111 			if (*p == '.' || *p == '/' || *p == ':')
3112 # endif /* _FFR_DOTTED_USERNAMES */
3113 			{
3114 				*p++ = '\0';
3115 				break;
3116 			}
3117 		}
3118 		if (isascii(*val) && isdigit(*val))
3119 		{
3120 			if (can_setuid)
3121 				RunAsUid = atoi(val);
3122 		}
3123 		else
3124 		{
3125 			register struct passwd *pw;
3126 
3127 			pw = sm_getpwnam(val);
3128 			if (pw == NULL)
3129 			{
3130 				syserr("readcf: option RunAsUser: unknown user %s", val);
3131 				break;
3132 			}
3133 			else if (can_setuid)
3134 			{
3135 				if (*p == '\0')
3136 					RunAsUserName = newstr(val);
3137 				RunAsUid = pw->pw_uid;
3138 				RunAsGid = pw->pw_gid;
3139 			}
3140 			else if (EffGid == pw->pw_gid)
3141 				RunAsGid = pw->pw_gid;
3142 			else if (UseMSP && *p == '\0')
3143 				(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3144 						     "WARNING: RunAsUser for MSP ignored, check group ids (egid=%d, want=%d)\n",
3145 						     (int) EffGid,
3146 						     (int) pw->pw_gid);
3147 		}
3148 # ifdef UID_MAX
3149 		if (RunAsUid > UID_MAX)
3150 		{
3151 			syserr("readcf: option RunAsUser: uid value (%ld) > UID_MAX (%ld); ignored",
3152 				(long) RunAsUid, (long) UID_MAX);
3153 			break;
3154 		}
3155 # endif /* UID_MAX */
3156 		if (*p != '\0')
3157 		{
3158 			if (isascii(*p) && isdigit(*p))
3159 			{
3160 				gid_t runasgid;
3161 
3162 				runasgid = (gid_t) atoi(p);
3163 				if (can_setuid || EffGid == runasgid)
3164 					RunAsGid = runasgid;
3165 				else if (UseMSP)
3166 					(void) sm_io_fprintf(smioout,
3167 							     SM_TIME_DEFAULT,
3168 							     "WARNING: RunAsUser for MSP ignored, check group ids (egid=%d, want=%d)\n",
3169 							     (int) EffGid,
3170 							     (int) runasgid);
3171 			}
3172 			else
3173 			{
3174 				register struct group *gr;
3175 
3176 				gr = getgrnam(p);
3177 				if (gr == NULL)
3178 					syserr("readcf: option RunAsUser: unknown group %s",
3179 						p);
3180 				else if (can_setuid || EffGid == gr->gr_gid)
3181 					RunAsGid = gr->gr_gid;
3182 				else if (UseMSP)
3183 					(void) sm_io_fprintf(smioout,
3184 							     SM_TIME_DEFAULT,
3185 							     "WARNING: RunAsUser for MSP ignored, check group ids (egid=%d, want=%d)\n",
3186 							     (int) EffGid,
3187 							     (int) gr->gr_gid);
3188 			}
3189 		}
3190 		if (tTd(47, 5))
3191 			sm_dprintf("readcf: RunAsUser = %d:%d\n",
3192 				   (int) RunAsUid, (int) RunAsGid);
3193 		break;
3194 
3195 	  case O_DSN_RRT:
3196 		RrtImpliesDsn = atobool(val);
3197 		break;
3198 
3199 	  case O_PIDFILE:
3200 		PSTRSET(PidFile, val);
3201 		break;
3202 
3203 	  case O_DONTBLAMESENDMAIL:
3204 		p = val;
3205 		for (;;)
3206 		{
3207 			register struct dbsval *dbs;
3208 			extern struct dbsval DontBlameSendmailValues[];
3209 
3210 			while (isascii(*p) && (isspace(*p) || ispunct(*p)))
3211 				p++;
3212 			if (*p == '\0')
3213 				break;
3214 			val = p;
3215 			while (isascii(*p) && isalnum(*p))
3216 				p++;
3217 			if (*p != '\0')
3218 				*p++ = '\0';
3219 
3220 			for (dbs = DontBlameSendmailValues;
3221 			     dbs->dbs_name != NULL; dbs++)
3222 			{
3223 				if (sm_strcasecmp(val, dbs->dbs_name) == 0)
3224 					break;
3225 			}
3226 			if (dbs->dbs_name == NULL)
3227 				syserr("readcf: DontBlameSendmail option: %s unrecognized", val);
3228 			else if (dbs->dbs_flag == DBS_SAFE)
3229 				clrbitmap(DontBlameSendmail);
3230 			else
3231 				setbitn(dbs->dbs_flag, DontBlameSendmail);
3232 		}
3233 		sticky = false;
3234 		break;
3235 
3236 	  case O_DPI:
3237 		if (sm_strcasecmp(val, "loopback") == 0)
3238 			DontProbeInterfaces = DPI_SKIPLOOPBACK;
3239 		else if (atobool(val))
3240 			DontProbeInterfaces = DPI_PROBENONE;
3241 		else
3242 			DontProbeInterfaces = DPI_PROBEALL;
3243 		break;
3244 
3245 	  case O_MAXRCPT:
3246 		MaxRcptPerMsg = atoi(val);
3247 		break;
3248 
3249 	  case O_RCPTTHROT:
3250 		BadRcptThrottle = atoi(val);
3251 		break;
3252 
3253 	  case O_DEADLETTER:
3254 		CANONIFY(val);
3255 		PSTRSET(DeadLetterDrop, val);
3256 		break;
3257 
3258 #if _FFR_DONTLOCKFILESFORREAD_OPTION
3259 	  case O_DONTLOCK:
3260 		DontLockReadFiles = atobool(val);
3261 		break;
3262 #endif /* _FFR_DONTLOCKFILESFORREAD_OPTION */
3263 
3264 	  case O_MAXALIASRCSN:
3265 		MaxAliasRecursion = atoi(val);
3266 		break;
3267 
3268 	  case O_CNCTONLYTO:
3269 		/* XXX should probably use gethostbyname */
3270 #if NETINET || NETINET6
3271 		ConnectOnlyTo.sa.sa_family = AF_UNSPEC;
3272 # if NETINET6
3273 		if (anynet_pton(AF_INET6, val,
3274 				&ConnectOnlyTo.sin6.sin6_addr) != 1)
3275 			ConnectOnlyTo.sa.sa_family = AF_INET6;
3276 		else
3277 # endif /* NETINET6 */
3278 # if NETINET
3279 		{
3280 			ConnectOnlyTo.sin.sin_addr.s_addr = inet_addr(val);
3281 			if (ConnectOnlyTo.sin.sin_addr.s_addr != INADDR_NONE)
3282 				ConnectOnlyTo.sa.sa_family = AF_INET;
3283 		}
3284 
3285 # endif /* NETINET */
3286 		if (ConnectOnlyTo.sa.sa_family == AF_UNSPEC)
3287 		{
3288 			syserr("readcf: option ConnectOnlyTo: invalid IP address %s",
3289 			       val);
3290 			break;
3291 		}
3292 #endif /* NETINET || NETINET6 */
3293 		break;
3294 
3295 	  case O_TRUSTUSER:
3296 # if !HASFCHOWN && !defined(_FFR_DROP_TRUSTUSER_WARNING)
3297 		if (!UseMSP)
3298 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3299 					     "readcf: option TrustedUser may cause problems on systems\n        which do not support fchown() if UseMSP is not set.\n");
3300 # endif /* !HASFCHOWN && !defined(_FFR_DROP_TRUSTUSER_WARNING) */
3301 		if (isascii(*val) && isdigit(*val))
3302 			TrustedUid = atoi(val);
3303 		else
3304 		{
3305 			register struct passwd *pw;
3306 
3307 			TrustedUid = 0;
3308 			pw = sm_getpwnam(val);
3309 			if (pw == NULL)
3310 			{
3311 				syserr("readcf: option TrustedUser: unknown user %s", val);
3312 				break;
3313 			}
3314 			else
3315 				TrustedUid = pw->pw_uid;
3316 		}
3317 
3318 # ifdef UID_MAX
3319 		if (TrustedUid > UID_MAX)
3320 		{
3321 			syserr("readcf: option TrustedUser: uid value (%ld) > UID_MAX (%ld)",
3322 				(long) TrustedUid, (long) UID_MAX);
3323 			TrustedUid = 0;
3324 		}
3325 # endif /* UID_MAX */
3326 		break;
3327 
3328 	  case O_MAXMIMEHDRLEN:
3329 		p = strchr(val, '/');
3330 		if (p != NULL)
3331 			*p++ = '\0';
3332 		MaxMimeHeaderLength = atoi(val);
3333 		if (p != NULL && *p != '\0')
3334 			MaxMimeFieldLength = atoi(p);
3335 		else
3336 			MaxMimeFieldLength = MaxMimeHeaderLength / 2;
3337 
3338 		if (MaxMimeHeaderLength <= 0)
3339 			MaxMimeHeaderLength = 0;
3340 		else if (MaxMimeHeaderLength < 128)
3341 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3342 					     "Warning: MaxMimeHeaderLength: header length limit set lower than 128\n");
3343 
3344 		if (MaxMimeFieldLength <= 0)
3345 			MaxMimeFieldLength = 0;
3346 		else if (MaxMimeFieldLength < 40)
3347 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3348 					     "Warning: MaxMimeHeaderLength: field length limit set lower than 40\n");
3349 		break;
3350 
3351 	  case O_CONTROLSOCKET:
3352 		PSTRSET(ControlSocketName, val);
3353 		break;
3354 
3355 	  case O_MAXHDRSLEN:
3356 		MaxHeadersLength = atoi(val);
3357 
3358 		if (MaxHeadersLength > 0 &&
3359 		    MaxHeadersLength < (MAXHDRSLEN / 2))
3360 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3361 					     "Warning: MaxHeadersLength: headers length limit set lower than %d\n",
3362 					     (MAXHDRSLEN / 2));
3363 		break;
3364 
3365 	  case O_PROCTITLEPREFIX:
3366 		PSTRSET(ProcTitlePrefix, val);
3367 		break;
3368 
3369 #if SASL
3370 	  case O_SASLINFO:
3371 # if _FFR_ALLOW_SASLINFO
3372 		/*
3373 		**  Allow users to select their own authinfo file
3374 		**  under certain circumstances, otherwise just ignore
3375 		**  the option.  If the option isn't ignored, several
3376 		**  commands don't work very well, e.g., mailq.
3377 		**  However, this is not a "perfect" solution.
3378 		**  If mail is queued, the authentication info
3379 		**  will not be used in subsequent delivery attempts.
3380 		**  If we really want to support this, then it has
3381 		**  to be stored in the queue file.
3382 		*/
3383 		if (!bitset(SUBMIT_MSA, SubmitMode) && RealUid != 0 &&
3384 		    RunAsUid != RealUid)
3385 			break;
3386 # endif /* _FFR_ALLOW_SASLINFO */
3387 		PSTRSET(SASLInfo, val);
3388 		break;
3389 
3390 	  case O_SASLMECH:
3391 		if (AuthMechanisms != NULL)
3392 			sm_free(AuthMechanisms); /* XXX */
3393 		if (*val != '\0')
3394 			AuthMechanisms = newstr(val);
3395 		else
3396 			AuthMechanisms = NULL;
3397 		break;
3398 
3399 	  case O_SASLREALM:
3400 		if (AuthRealm != NULL)
3401 			sm_free(AuthRealm);
3402 		if (*val != '\0')
3403 			AuthRealm = newstr(val);
3404 		else
3405 			AuthRealm = NULL;
3406 		break;
3407 
3408 	  case O_SASLOPTS:
3409 		while (val != NULL && *val != '\0')
3410 		{
3411 			switch (*val)
3412 			{
3413 			  case 'A':
3414 				SASLOpts |= SASL_AUTH_AUTH;
3415 				break;
3416 
3417 			  case 'a':
3418 				SASLOpts |= SASL_SEC_NOACTIVE;
3419 				break;
3420 
3421 			  case 'c':
3422 				SASLOpts |= SASL_SEC_PASS_CREDENTIALS;
3423 				break;
3424 
3425 			  case 'd':
3426 				SASLOpts |= SASL_SEC_NODICTIONARY;
3427 				break;
3428 
3429 			  case 'f':
3430 				SASLOpts |= SASL_SEC_FORWARD_SECRECY;
3431 				break;
3432 
3433 #  if SASL >= 20101
3434 			  case 'm':
3435 				SASLOpts |= SASL_SEC_MUTUAL_AUTH;
3436 				break;
3437 #  endif /* SASL >= 20101 */
3438 
3439 			  case 'p':
3440 				SASLOpts |= SASL_SEC_NOPLAINTEXT;
3441 				break;
3442 
3443 			  case 'y':
3444 				SASLOpts |= SASL_SEC_NOANONYMOUS;
3445 				break;
3446 
3447 			  case ' ':	/* ignore */
3448 			  case '\t':	/* ignore */
3449 			  case ',':	/* ignore */
3450 				break;
3451 
3452 			  default:
3453 				(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3454 						     "Warning: Option: %s unknown parameter '%c'\n",
3455 						     OPTNAME,
3456 						     (isascii(*val) &&
3457 							isprint(*val))
3458 							? *val : '?');
3459 				break;
3460 			}
3461 			++val;
3462 			val = strpbrk(val, ", \t");
3463 			if (val != NULL)
3464 				++val;
3465 		}
3466 		break;
3467 
3468 	  case O_SASLBITS:
3469 		MaxSLBits = atoi(val);
3470 		break;
3471 
3472 #else /* SASL */
3473 	  case O_SASLINFO:
3474 	  case O_SASLMECH:
3475 	  case O_SASLREALM:
3476 	  case O_SASLOPTS:
3477 	  case O_SASLBITS:
3478 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3479 				     "Warning: Option: %s requires SASL support (-DSASL)\n",
3480 				     OPTNAME);
3481 		break;
3482 #endif /* SASL */
3483 
3484 #if STARTTLS
3485 	  case O_SRVCERTFILE:
3486 		SET_STRING_EXP(SrvCertFile);
3487 	  case O_SRVKEYFILE:
3488 		SET_STRING_EXP(SrvKeyFile);
3489 	  case O_CLTCERTFILE:
3490 		SET_STRING_EXP(CltCertFile);
3491 	  case O_CLTKEYFILE:
3492 		SET_STRING_EXP(CltKeyFile);
3493 	  case O_CACERTFILE:
3494 		SET_STRING_EXP(CACertFile);
3495 	  case O_CACERTPATH:
3496 		SET_STRING_EXP(CACertPath);
3497 	  case O_DHPARAMS:
3498 		SET_STRING_EXP(DHParams);
3499 # if _FFR_TLS_1
3500 	  case O_DHPARAMS5:
3501 		SET_STRING_EXP(DHParams5);
3502 	  case O_CIPHERLIST:
3503 		SET_STRING_EXP(CipherList);
3504 # endif /* _FFR_TLS_1 */
3505 	  case O_CRLFILE:
3506 # if OPENSSL_VERSION_NUMBER > 0x00907000L
3507 		SET_STRING_EXP(CRLFile);
3508 # else /* OPENSSL_VERSION_NUMBER > 0x00907000L */
3509 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3510 				     "Warning: Option: %s requires at least OpenSSL 0.9.7\n",
3511 				     OPTNAME);
3512 		break;
3513 # endif /* OPENSSL_VERSION_NUMBER > 0x00907000L */
3514 
3515 # if _FFR_CRLPATH
3516 	  case O_CRLPATH:
3517 #  if OPENSSL_VERSION_NUMBER > 0x00907000L
3518 		SET_STRING_EXP(CRLPath);
3519 #  else /* OPENSSL_VERSION_NUMBER > 0x00907000L */
3520 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3521 				     "Warning: Option: %s requires at least OpenSSL 0.9.7\n",
3522 				     OPTNAME);
3523 		break;
3524 #  endif /* OPENSSL_VERSION_NUMBER > 0x00907000L */
3525 # endif /* _FFR_CRLPATH */
3526 
3527 	/*
3528 	**  XXX How about options per daemon/client instead of globally?
3529 	**  This doesn't work well for some options, e.g., no server cert,
3530 	**  but fine for others.
3531 	**
3532 	**  XXX Some people may want different certs per server.
3533 	**
3534 	**  See also srvfeatures()
3535 	*/
3536 
3537 	  case O_TLS_SRV_OPTS:
3538 		while (val != NULL && *val != '\0')
3539 		{
3540 			switch (*val)
3541 			{
3542 			  case 'V':
3543 				TLS_Srv_Opts |= TLS_I_NO_VRFY;
3544 				break;
3545 # if _FFR_TLS_1
3546 			/*
3547 			**  Server without a cert? That works only if
3548 			**  AnonDH is enabled as cipher, which is not in the
3549 			**  default list. Hence the CipherList option must
3550 			**  be available. Moreover: which clients support this
3551 			**  besides sendmail with this setting?
3552 			*/
3553 
3554 			  case 'C':
3555 				TLS_Srv_Opts &= ~TLS_I_SRV_CERT;
3556 				break;
3557 # endif /* _FFR_TLS_1 */
3558 			  case ' ':	/* ignore */
3559 			  case '\t':	/* ignore */
3560 			  case ',':	/* ignore */
3561 				break;
3562 			  default:
3563 				(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3564 						     "Warning: Option: %s unknown parameter '%c'\n",
3565 						     OPTNAME,
3566 						     (isascii(*val) &&
3567 							isprint(*val))
3568 							? *val : '?');
3569 				break;
3570 			}
3571 			++val;
3572 			val = strpbrk(val, ", \t");
3573 			if (val != NULL)
3574 				++val;
3575 		}
3576 		break;
3577 
3578 	  case O_RANDFILE:
3579 		PSTRSET(RandFile, val);
3580 		break;
3581 
3582 #else /* STARTTLS */
3583 	  case O_SRVCERTFILE:
3584 	  case O_SRVKEYFILE:
3585 	  case O_CLTCERTFILE:
3586 	  case O_CLTKEYFILE:
3587 	  case O_CACERTFILE:
3588 	  case O_CACERTPATH:
3589 	  case O_DHPARAMS:
3590 # if _FFR_TLS_1
3591 	  case O_DHPARAMS5:
3592 	  case O_CIPHERLIST:
3593 # endif /* _FFR_TLS_1 */
3594 	  case O_CRLFILE:
3595 # if _FFR_CRLPATH
3596 	  case O_CRLPATH:
3597 # endif /* _FFR_CRLPATH */
3598 	  case O_RANDFILE:
3599 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3600 				     "Warning: Option: %s requires TLS support\n",
3601 				     OPTNAME);
3602 		break;
3603 
3604 #endif /* STARTTLS */
3605 
3606 	  case O_CLIENTPORT:
3607 		setclientoptions(val);
3608 		break;
3609 
3610 	  case O_DF_BUFSIZE:
3611 		DataFileBufferSize = atoi(val);
3612 		break;
3613 
3614 	  case O_XF_BUFSIZE:
3615 		XscriptFileBufferSize = atoi(val);
3616 		break;
3617 
3618 	  case O_LDAPDEFAULTSPEC:
3619 #if LDAPMAP
3620 		ldapmap_set_defaults(val);
3621 #else /* LDAPMAP */
3622 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3623 				     "Warning: Option: %s requires LDAP support (-DLDAPMAP)\n",
3624 				     OPTNAME);
3625 #endif /* LDAPMAP */
3626 		break;
3627 
3628 	  case O_INPUTMILTER:
3629 #if MILTER
3630 		InputFilterList = newstr(val);
3631 #else /* MILTER */
3632 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3633 				     "Warning: Option: %s requires Milter support (-DMILTER)\n",
3634 				     OPTNAME);
3635 #endif /* MILTER */
3636 		break;
3637 
3638 	  case O_MILTER:
3639 #if MILTER
3640 		milter_set_option(subopt, val, sticky);
3641 #else /* MILTER */
3642 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3643 				     "Warning: Option: %s requires Milter support (-DMILTER)\n",
3644 				     OPTNAME);
3645 #endif /* MILTER */
3646 		break;
3647 
3648 	  case O_QUEUE_FILE_MODE:	/* queue file mode */
3649 		QueueFileMode = atooct(val) & 0777;
3650 		break;
3651 
3652 	  case O_DLVR_MIN:	/* deliver by minimum time */
3653 		DeliverByMin = convtime(val, 's');
3654 		break;
3655 
3656 	  /* modifiers {daemon_flags} for direct submissions */
3657 	  case O_DIRECTSUBMODIFIERS:
3658 		{
3659 			BITMAP256 m;	/* ignored */
3660 			extern ENVELOPE BlankEnvelope;
3661 
3662 			macdefine(&BlankEnvelope.e_macro, A_PERM,
3663 				  macid("{daemon_flags}"),
3664 				  getmodifiers(val, m));
3665 		}
3666 		break;
3667 
3668 	  case O_FASTSPLIT:
3669 		FastSplit = atoi(val);
3670 		break;
3671 
3672 	  case O_MBDB:
3673 		Mbdb = newstr(val);
3674 		break;
3675 
3676 	  case O_MSQ:
3677 		UseMSP = atobool(val);
3678 		break;
3679 
3680 #if _FFR_SOFT_BOUNCE
3681 	  case O_SOFTBOUNCE:
3682 		SoftBounce = atobool(val);
3683 		break;
3684 #endif /* _FFR_SOFT_BOUNCE */
3685 
3686 	  case O_REJECTLOGINTERVAL:	/* time btwn log msgs while refusing */
3687 		RejectLogInterval = convtime(val, 'h');
3688 		break;
3689 
3690 	  case O_REQUIRES_DIR_FSYNC:
3691 #if REQUIRES_DIR_FSYNC
3692 		RequiresDirfsync = atobool(val);
3693 #else /* REQUIRES_DIR_FSYNC */
3694 		/* silently ignored... required for cf file option */
3695 #endif /* REQUIRES_DIR_FSYNC */
3696 		break;
3697 
3698 	  case O_CONNECTION_RATE_WINDOW_SIZE:
3699 		ConnectionRateWindowSize = convtime(val, 's');
3700 		break;
3701 
3702 	  case O_FALLBACKSMARTHOST:	/* fallback smart host */
3703 		if (val[0] != '\0')
3704 			FallbackSmartHost = newstr(val);
3705 		break;
3706 
3707 #if _FFR_HELONAME
3708 	  case O_HELONAME:
3709 	        HeloName = newstr(val);
3710 	        break;
3711 #endif /* _FFR_HELONAME */
3712 
3713 	  default:
3714 		if (tTd(37, 1))
3715 		{
3716 			if (isascii(opt) && isprint(opt))
3717 				sm_dprintf("Warning: option %c unknown\n", opt);
3718 			else
3719 				sm_dprintf("Warning: option 0x%x unknown\n", opt);
3720 		}
3721 		break;
3722 	}
3723 
3724 	/*
3725 	**  Options with suboptions are responsible for taking care
3726 	**  of sticky-ness (e.g., that a command line setting is kept
3727 	**  when reading in the sendmail.cf file).  This has to be done
3728 	**  when the suboptions are parsed since each suboption must be
3729 	**  sticky, not the root option.
3730 	*/
3731 
3732 	if (sticky && !bitset(OI_SUBOPT, o->o_flags))
3733 		setbitn(opt, StickyOpt);
3734 }
3735 /*
3736 **  SETCLASS -- set a string into a class
3737 **
3738 **	Parameters:
3739 **		class -- the class to put the string in.
3740 **		str -- the string to enter
3741 **
3742 **	Returns:
3743 **		none.
3744 **
3745 **	Side Effects:
3746 **		puts the word into the symbol table.
3747 */
3748 
3749 void
3750 setclass(class, str)
3751 	int class;
3752 	char *str;
3753 {
3754 	register STAB *s;
3755 
3756 	if ((*str & 0377) == MATCHCLASS)
3757 	{
3758 		int mid;
3759 
3760 		str++;
3761 		mid = macid(str);
3762 		if (mid == 0)
3763 			return;
3764 
3765 		if (tTd(37, 8))
3766 			sm_dprintf("setclass(%s, $=%s)\n",
3767 				   macname(class), macname(mid));
3768 		copy_class(mid, class);
3769 	}
3770 	else
3771 	{
3772 		if (tTd(37, 8))
3773 			sm_dprintf("setclass(%s, %s)\n", macname(class), str);
3774 
3775 		s = stab(str, ST_CLASS, ST_ENTER);
3776 		setbitn(bitidx(class), s->s_class);
3777 	}
3778 }
3779 /*
3780 **  MAKEMAPENTRY -- create a map entry
3781 **
3782 **	Parameters:
3783 **		line -- the config file line
3784 **
3785 **	Returns:
3786 **		A pointer to the map that has been created.
3787 **		NULL if there was a syntax error.
3788 **
3789 **	Side Effects:
3790 **		Enters the map into the dictionary.
3791 */
3792 
3793 MAP *
3794 makemapentry(line)
3795 	char *line;
3796 {
3797 	register char *p;
3798 	char *mapname;
3799 	char *classname;
3800 	register STAB *s;
3801 	STAB *class;
3802 
3803 	for (p = line; isascii(*p) && isspace(*p); p++)
3804 		continue;
3805 	if (!(isascii(*p) && isalnum(*p)))
3806 	{
3807 		syserr("readcf: config K line: no map name");
3808 		return NULL;
3809 	}
3810 
3811 	mapname = p;
3812 	while ((isascii(*++p) && isalnum(*p)) || *p == '_' || *p == '.')
3813 		continue;
3814 	if (*p != '\0')
3815 		*p++ = '\0';
3816 	while (isascii(*p) && isspace(*p))
3817 		p++;
3818 	if (!(isascii(*p) && isalnum(*p)))
3819 	{
3820 		syserr("readcf: config K line, map %s: no map class", mapname);
3821 		return NULL;
3822 	}
3823 	classname = p;
3824 	while (isascii(*++p) && isalnum(*p))
3825 		continue;
3826 	if (*p != '\0')
3827 		*p++ = '\0';
3828 	while (isascii(*p) && isspace(*p))
3829 		p++;
3830 
3831 	/* look up the class */
3832 	class = stab(classname, ST_MAPCLASS, ST_FIND);
3833 	if (class == NULL)
3834 	{
3835 		syserr("readcf: map %s: class %s not available", mapname,
3836 			classname);
3837 		return NULL;
3838 	}
3839 
3840 	/* enter the map */
3841 	s = stab(mapname, ST_MAP, ST_ENTER);
3842 	s->s_map.map_class = &class->s_mapclass;
3843 	s->s_map.map_mname = newstr(mapname);
3844 
3845 	if (class->s_mapclass.map_parse(&s->s_map, p))
3846 		s->s_map.map_mflags |= MF_VALID;
3847 
3848 	if (tTd(37, 5))
3849 	{
3850 		sm_dprintf("map %s, class %s, flags %lx, file %s,\n",
3851 			   s->s_map.map_mname, s->s_map.map_class->map_cname,
3852 			   s->s_map.map_mflags, s->s_map.map_file);
3853 		sm_dprintf("\tapp %s, domain %s, rebuild %s\n",
3854 			   s->s_map.map_app, s->s_map.map_domain,
3855 			   s->s_map.map_rebuild);
3856 	}
3857 	return &s->s_map;
3858 }
3859 /*
3860 **  STRTORWSET -- convert string to rewriting set number
3861 **
3862 **	Parameters:
3863 **		p -- the pointer to the string to decode.
3864 **		endp -- if set, store the trailing delimiter here.
3865 **		stabmode -- ST_ENTER to create this entry, ST_FIND if
3866 **			it must already exist.
3867 **
3868 **	Returns:
3869 **		The appropriate ruleset number.
3870 **		-1 if it is not valid (error already printed)
3871 */
3872 
3873 int
3874 strtorwset(p, endp, stabmode)
3875 	char *p;
3876 	char **endp;
3877 	int stabmode;
3878 {
3879 	int ruleset;
3880 	static int nextruleset = MAXRWSETS;
3881 
3882 	while (isascii(*p) && isspace(*p))
3883 		p++;
3884 	if (!isascii(*p))
3885 	{
3886 		syserr("invalid ruleset name: \"%.20s\"", p);
3887 		return -1;
3888 	}
3889 	if (isdigit(*p))
3890 	{
3891 		ruleset = strtol(p, endp, 10);
3892 		if (ruleset >= MAXRWSETS / 2 || ruleset < 0)
3893 		{
3894 			syserr("bad ruleset %d (%d max)",
3895 				ruleset, MAXRWSETS / 2);
3896 			ruleset = -1;
3897 		}
3898 	}
3899 	else
3900 	{
3901 		STAB *s;
3902 		char delim;
3903 		char *q = NULL;
3904 
3905 		q = p;
3906 		while (*p != '\0' && isascii(*p) &&
3907 		       (isalnum(*p) || *p == '_'))
3908 			p++;
3909 		if (q == p || !(isascii(*q) && isalpha(*q)))
3910 		{
3911 			/* no valid characters */
3912 			syserr("invalid ruleset name: \"%.20s\"", q);
3913 			return -1;
3914 		}
3915 		while (isascii(*p) && isspace(*p))
3916 			*p++ = '\0';
3917 		delim = *p;
3918 		if (delim != '\0')
3919 			*p = '\0';
3920 		s = stab(q, ST_RULESET, stabmode);
3921 		if (delim != '\0')
3922 			*p = delim;
3923 
3924 		if (s == NULL)
3925 			return -1;
3926 
3927 		if (stabmode == ST_ENTER && delim == '=')
3928 		{
3929 			while (isascii(*++p) && isspace(*p))
3930 				continue;
3931 			if (!(isascii(*p) && isdigit(*p)))
3932 			{
3933 				syserr("bad ruleset definition \"%s\" (number required after `=')", q);
3934 				ruleset = -1;
3935 			}
3936 			else
3937 			{
3938 				ruleset = strtol(p, endp, 10);
3939 				if (ruleset >= MAXRWSETS / 2 || ruleset < 0)
3940 				{
3941 					syserr("bad ruleset number %d in \"%s\" (%d max)",
3942 						ruleset, q, MAXRWSETS / 2);
3943 					ruleset = -1;
3944 				}
3945 			}
3946 		}
3947 		else
3948 		{
3949 			if (endp != NULL)
3950 				*endp = p;
3951 			if (s->s_ruleset >= 0)
3952 				ruleset = s->s_ruleset;
3953 			else if ((ruleset = --nextruleset) < MAXRWSETS / 2)
3954 			{
3955 				syserr("%s: too many named rulesets (%d max)",
3956 					q, MAXRWSETS / 2);
3957 				ruleset = -1;
3958 			}
3959 		}
3960 		if (s->s_ruleset >= 0 &&
3961 		    ruleset >= 0 &&
3962 		    ruleset != s->s_ruleset)
3963 		{
3964 			syserr("%s: ruleset changed value (old %d, new %d)",
3965 				q, s->s_ruleset, ruleset);
3966 			ruleset = s->s_ruleset;
3967 		}
3968 		else if (ruleset >= 0)
3969 		{
3970 			s->s_ruleset = ruleset;
3971 		}
3972 		if (stabmode == ST_ENTER && ruleset >= 0)
3973 		{
3974 			char *h = NULL;
3975 
3976 			if (RuleSetNames[ruleset] != NULL)
3977 				sm_free(RuleSetNames[ruleset]); /* XXX */
3978 			if (delim != '\0' && (h = strchr(q, delim)) != NULL)
3979 				*h = '\0';
3980 			RuleSetNames[ruleset] = newstr(q);
3981 			if (delim == '/' && h != NULL)
3982 				*h = delim;	/* put back delim */
3983 		}
3984 	}
3985 	return ruleset;
3986 }
3987 /*
3988 **  SETTIMEOUT -- set an individual timeout
3989 **
3990 **	Parameters:
3991 **		name -- the name of the timeout.
3992 **		val -- the value of the timeout.
3993 **		sticky -- if set, don't let other setoptions override
3994 **			this value.
3995 **
3996 **	Returns:
3997 **		none.
3998 */
3999 
4000 /* set if Timeout sub-option is stuck */
4001 static BITMAP256	StickyTimeoutOpt;
4002 
4003 static struct timeoutinfo
4004 {
4005 	char		*to_name;	/* long name of timeout */
4006 	unsigned char	to_code;	/* code for option */
4007 } TimeOutTab[] =
4008 {
4009 #define TO_INITIAL			0x01
4010 	{ "initial",			TO_INITIAL			},
4011 #define TO_MAIL				0x02
4012 	{ "mail",			TO_MAIL				},
4013 #define TO_RCPT				0x03
4014 	{ "rcpt",			TO_RCPT				},
4015 #define TO_DATAINIT			0x04
4016 	{ "datainit",			TO_DATAINIT			},
4017 #define TO_DATABLOCK			0x05
4018 	{ "datablock",			TO_DATABLOCK			},
4019 #define TO_DATAFINAL			0x06
4020 	{ "datafinal",			TO_DATAFINAL			},
4021 #define TO_COMMAND			0x07
4022 	{ "command",			TO_COMMAND			},
4023 #define TO_RSET				0x08
4024 	{ "rset",			TO_RSET				},
4025 #define TO_HELO				0x09
4026 	{ "helo",			TO_HELO				},
4027 #define TO_QUIT				0x0A
4028 	{ "quit",			TO_QUIT				},
4029 #define TO_MISC				0x0B
4030 	{ "misc",			TO_MISC				},
4031 #define TO_IDENT			0x0C
4032 	{ "ident",			TO_IDENT			},
4033 #define TO_FILEOPEN			0x0D
4034 	{ "fileopen",			TO_FILEOPEN			},
4035 #define TO_CONNECT			0x0E
4036 	{ "connect",			TO_CONNECT			},
4037 #define TO_ICONNECT			0x0F
4038 	{ "iconnect",			TO_ICONNECT			},
4039 #define TO_QUEUEWARN			0x10
4040 	{ "queuewarn",			TO_QUEUEWARN			},
4041 	{ "queuewarn.*",		TO_QUEUEWARN			},
4042 #define TO_QUEUEWARN_NORMAL		0x11
4043 	{ "queuewarn.normal",		TO_QUEUEWARN_NORMAL		},
4044 #define TO_QUEUEWARN_URGENT		0x12
4045 	{ "queuewarn.urgent",		TO_QUEUEWARN_URGENT		},
4046 #define TO_QUEUEWARN_NON_URGENT		0x13
4047 	{ "queuewarn.non-urgent",	TO_QUEUEWARN_NON_URGENT		},
4048 #define TO_QUEUERETURN			0x14
4049 	{ "queuereturn",		TO_QUEUERETURN			},
4050 	{ "queuereturn.*",		TO_QUEUERETURN			},
4051 #define TO_QUEUERETURN_NORMAL		0x15
4052 	{ "queuereturn.normal",		TO_QUEUERETURN_NORMAL		},
4053 #define TO_QUEUERETURN_URGENT		0x16
4054 	{ "queuereturn.urgent",		TO_QUEUERETURN_URGENT		},
4055 #define TO_QUEUERETURN_NON_URGENT	0x17
4056 	{ "queuereturn.non-urgent",	TO_QUEUERETURN_NON_URGENT	},
4057 #define TO_HOSTSTATUS			0x18
4058 	{ "hoststatus",			TO_HOSTSTATUS			},
4059 #define TO_RESOLVER_RETRANS		0x19
4060 	{ "resolver.retrans",		TO_RESOLVER_RETRANS		},
4061 #define TO_RESOLVER_RETRANS_NORMAL	0x1A
4062 	{ "resolver.retrans.normal",	TO_RESOLVER_RETRANS_NORMAL	},
4063 #define TO_RESOLVER_RETRANS_FIRST	0x1B
4064 	{ "resolver.retrans.first",	TO_RESOLVER_RETRANS_FIRST	},
4065 #define TO_RESOLVER_RETRY		0x1C
4066 	{ "resolver.retry",		TO_RESOLVER_RETRY		},
4067 #define TO_RESOLVER_RETRY_NORMAL	0x1D
4068 	{ "resolver.retry.normal",	TO_RESOLVER_RETRY_NORMAL	},
4069 #define TO_RESOLVER_RETRY_FIRST		0x1E
4070 	{ "resolver.retry.first",	TO_RESOLVER_RETRY_FIRST		},
4071 #define TO_CONTROL			0x1F
4072 	{ "control",			TO_CONTROL			},
4073 #define TO_LHLO				0x20
4074 	{ "lhlo",			TO_LHLO				},
4075 #define TO_AUTH				0x21
4076 	{ "auth",			TO_AUTH				},
4077 #define TO_STARTTLS			0x22
4078 	{ "starttls",			TO_STARTTLS			},
4079 #define TO_ACONNECT			0x23
4080 	{ "aconnect",			TO_ACONNECT			},
4081 #define TO_QUEUEWARN_DSN		0x24
4082 	{ "queuewarn.dsn",		TO_QUEUEWARN_DSN		},
4083 #define TO_QUEUERETURN_DSN		0x25
4084 	{ "queuereturn.dsn",		TO_QUEUERETURN_DSN		},
4085 	{ NULL,				0				},
4086 };
4087 
4088 
4089 static void
4090 settimeout(name, val, sticky)
4091 	char *name;
4092 	char *val;
4093 	bool sticky;
4094 {
4095 	register struct timeoutinfo *to;
4096 	int i, addopts;
4097 	time_t toval;
4098 
4099 	if (tTd(37, 2))
4100 		sm_dprintf("settimeout(%s = %s)", name, val);
4101 
4102 	for (to = TimeOutTab; to->to_name != NULL; to++)
4103 	{
4104 		if (sm_strcasecmp(to->to_name, name) == 0)
4105 			break;
4106 	}
4107 
4108 	if (to->to_name == NULL)
4109 	{
4110 		errno = 0; /* avoid bogus error text */
4111 		syserr("settimeout: invalid timeout %s", name);
4112 		return;
4113 	}
4114 
4115 	/*
4116 	**  See if this option is preset for us.
4117 	*/
4118 
4119 	if (!sticky && bitnset(to->to_code, StickyTimeoutOpt))
4120 	{
4121 		if (tTd(37, 2))
4122 			sm_dprintf(" (ignored)\n");
4123 		return;
4124 	}
4125 
4126 	if (tTd(37, 2))
4127 		sm_dprintf("\n");
4128 
4129 	toval = convtime(val, 'm');
4130 	addopts = 0;
4131 
4132 	switch (to->to_code)
4133 	{
4134 	  case TO_INITIAL:
4135 		TimeOuts.to_initial = toval;
4136 		break;
4137 
4138 	  case TO_MAIL:
4139 		TimeOuts.to_mail = toval;
4140 		break;
4141 
4142 	  case TO_RCPT:
4143 		TimeOuts.to_rcpt = toval;
4144 		break;
4145 
4146 	  case TO_DATAINIT:
4147 		TimeOuts.to_datainit = toval;
4148 		break;
4149 
4150 	  case TO_DATABLOCK:
4151 		TimeOuts.to_datablock = toval;
4152 		break;
4153 
4154 	  case TO_DATAFINAL:
4155 		TimeOuts.to_datafinal = toval;
4156 		break;
4157 
4158 	  case TO_COMMAND:
4159 		TimeOuts.to_nextcommand = toval;
4160 		break;
4161 
4162 	  case TO_RSET:
4163 		TimeOuts.to_rset = toval;
4164 		break;
4165 
4166 	  case TO_HELO:
4167 		TimeOuts.to_helo = toval;
4168 		break;
4169 
4170 	  case TO_QUIT:
4171 		TimeOuts.to_quit = toval;
4172 		break;
4173 
4174 	  case TO_MISC:
4175 		TimeOuts.to_miscshort = toval;
4176 		break;
4177 
4178 	  case TO_IDENT:
4179 		TimeOuts.to_ident = toval;
4180 		break;
4181 
4182 	  case TO_FILEOPEN:
4183 		TimeOuts.to_fileopen = toval;
4184 		break;
4185 
4186 	  case TO_CONNECT:
4187 		TimeOuts.to_connect = toval;
4188 		break;
4189 
4190 	  case TO_ICONNECT:
4191 		TimeOuts.to_iconnect = toval;
4192 		break;
4193 
4194 	  case TO_ACONNECT:
4195 		TimeOuts.to_aconnect = toval;
4196 		break;
4197 
4198 	  case TO_QUEUEWARN:
4199 		toval = convtime(val, 'h');
4200 		TimeOuts.to_q_warning[TOC_NORMAL] = toval;
4201 		TimeOuts.to_q_warning[TOC_URGENT] = toval;
4202 		TimeOuts.to_q_warning[TOC_NONURGENT] = toval;
4203 		TimeOuts.to_q_warning[TOC_DSN] = toval;
4204 		addopts = 2;
4205 		break;
4206 
4207 	  case TO_QUEUEWARN_NORMAL:
4208 		toval = convtime(val, 'h');
4209 		TimeOuts.to_q_warning[TOC_NORMAL] = toval;
4210 		break;
4211 
4212 	  case TO_QUEUEWARN_URGENT:
4213 		toval = convtime(val, 'h');
4214 		TimeOuts.to_q_warning[TOC_URGENT] = toval;
4215 		break;
4216 
4217 	  case TO_QUEUEWARN_NON_URGENT:
4218 		toval = convtime(val, 'h');
4219 		TimeOuts.to_q_warning[TOC_NONURGENT] = toval;
4220 		break;
4221 
4222 	  case TO_QUEUEWARN_DSN:
4223 		toval = convtime(val, 'h');
4224 		TimeOuts.to_q_warning[TOC_DSN] = toval;
4225 		break;
4226 
4227 	  case TO_QUEUERETURN:
4228 		toval = convtime(val, 'd');
4229 		TimeOuts.to_q_return[TOC_NORMAL] = toval;
4230 		TimeOuts.to_q_return[TOC_URGENT] = toval;
4231 		TimeOuts.to_q_return[TOC_NONURGENT] = toval;
4232 		TimeOuts.to_q_return[TOC_DSN] = toval;
4233 		addopts = 2;
4234 		break;
4235 
4236 	  case TO_QUEUERETURN_NORMAL:
4237 		toval = convtime(val, 'd');
4238 		TimeOuts.to_q_return[TOC_NORMAL] = toval;
4239 		break;
4240 
4241 	  case TO_QUEUERETURN_URGENT:
4242 		toval = convtime(val, 'd');
4243 		TimeOuts.to_q_return[TOC_URGENT] = toval;
4244 		break;
4245 
4246 	  case TO_QUEUERETURN_NON_URGENT:
4247 		toval = convtime(val, 'd');
4248 		TimeOuts.to_q_return[TOC_NONURGENT] = toval;
4249 		break;
4250 
4251 	  case TO_QUEUERETURN_DSN:
4252 		toval = convtime(val, 'd');
4253 		TimeOuts.to_q_return[TOC_DSN] = toval;
4254 		break;
4255 
4256 	  case TO_HOSTSTATUS:
4257 		MciInfoTimeout = toval;
4258 		break;
4259 
4260 	  case TO_RESOLVER_RETRANS:
4261 		toval = convtime(val, 's');
4262 		TimeOuts.res_retrans[RES_TO_DEFAULT] = toval;
4263 		TimeOuts.res_retrans[RES_TO_FIRST] = toval;
4264 		TimeOuts.res_retrans[RES_TO_NORMAL] = toval;
4265 		addopts = 2;
4266 		break;
4267 
4268 	  case TO_RESOLVER_RETRY:
4269 		i = atoi(val);
4270 		TimeOuts.res_retry[RES_TO_DEFAULT] = i;
4271 		TimeOuts.res_retry[RES_TO_FIRST] = i;
4272 		TimeOuts.res_retry[RES_TO_NORMAL] = i;
4273 		addopts = 2;
4274 		break;
4275 
4276 	  case TO_RESOLVER_RETRANS_NORMAL:
4277 		TimeOuts.res_retrans[RES_TO_NORMAL] = convtime(val, 's');
4278 		break;
4279 
4280 	  case TO_RESOLVER_RETRY_NORMAL:
4281 		TimeOuts.res_retry[RES_TO_NORMAL] = atoi(val);
4282 		break;
4283 
4284 	  case TO_RESOLVER_RETRANS_FIRST:
4285 		TimeOuts.res_retrans[RES_TO_FIRST] = convtime(val, 's');
4286 		break;
4287 
4288 	  case TO_RESOLVER_RETRY_FIRST:
4289 		TimeOuts.res_retry[RES_TO_FIRST] = atoi(val);
4290 		break;
4291 
4292 	  case TO_CONTROL:
4293 		TimeOuts.to_control = toval;
4294 		break;
4295 
4296 	  case TO_LHLO:
4297 		TimeOuts.to_lhlo = toval;
4298 		break;
4299 
4300 #if SASL
4301 	  case TO_AUTH:
4302 		TimeOuts.to_auth = toval;
4303 		break;
4304 #endif /* SASL */
4305 
4306 #if STARTTLS
4307 	  case TO_STARTTLS:
4308 		TimeOuts.to_starttls = toval;
4309 		break;
4310 #endif /* STARTTLS */
4311 
4312 	  default:
4313 		syserr("settimeout: invalid timeout %s", name);
4314 		break;
4315 	}
4316 
4317 	if (sticky)
4318 	{
4319 		for (i = 0; i <= addopts; i++)
4320 			setbitn(to->to_code + i, StickyTimeoutOpt);
4321 	}
4322 }
4323 /*
4324 **  INITTIMEOUTS -- parse and set timeout values
4325 **
4326 **	Parameters:
4327 **		val -- a pointer to the values.  If NULL, do initial
4328 **			settings.
4329 **		sticky -- if set, don't let other setoptions override
4330 **			this suboption value.
4331 **
4332 **	Returns:
4333 **		none.
4334 **
4335 **	Side Effects:
4336 **		Initializes the TimeOuts structure
4337 */
4338 
4339 void
4340 inittimeouts(val, sticky)
4341 	register char *val;
4342 	bool sticky;
4343 {
4344 	register char *p;
4345 
4346 	if (tTd(37, 2))
4347 		sm_dprintf("inittimeouts(%s)\n", val == NULL ? "<NULL>" : val);
4348 	if (val == NULL)
4349 	{
4350 		TimeOuts.to_connect = (time_t) 0 SECONDS;
4351 		TimeOuts.to_aconnect = (time_t) 0 SECONDS;
4352 		TimeOuts.to_iconnect = (time_t) 0 SECONDS;
4353 		TimeOuts.to_initial = (time_t) 5 MINUTES;
4354 		TimeOuts.to_helo = (time_t) 5 MINUTES;
4355 		TimeOuts.to_mail = (time_t) 10 MINUTES;
4356 		TimeOuts.to_rcpt = (time_t) 1 HOUR;
4357 		TimeOuts.to_datainit = (time_t) 5 MINUTES;
4358 		TimeOuts.to_datablock = (time_t) 1 HOUR;
4359 		TimeOuts.to_datafinal = (time_t) 1 HOUR;
4360 		TimeOuts.to_rset = (time_t) 5 MINUTES;
4361 		TimeOuts.to_quit = (time_t) 2 MINUTES;
4362 		TimeOuts.to_nextcommand = (time_t) 1 HOUR;
4363 		TimeOuts.to_miscshort = (time_t) 2 MINUTES;
4364 #if IDENTPROTO
4365 		TimeOuts.to_ident = (time_t) 5 SECONDS;
4366 #else /* IDENTPROTO */
4367 		TimeOuts.to_ident = (time_t) 0 SECONDS;
4368 #endif /* IDENTPROTO */
4369 		TimeOuts.to_fileopen = (time_t) 60 SECONDS;
4370 		TimeOuts.to_control = (time_t) 2 MINUTES;
4371 		TimeOuts.to_lhlo = (time_t) 2 MINUTES;
4372 #if SASL
4373 		TimeOuts.to_auth = (time_t) 10 MINUTES;
4374 #endif /* SASL */
4375 #if STARTTLS
4376 		TimeOuts.to_starttls = (time_t) 1 HOUR;
4377 #endif /* STARTTLS */
4378 		if (tTd(37, 5))
4379 		{
4380 			sm_dprintf("Timeouts:\n");
4381 			sm_dprintf("  connect = %ld\n",
4382 				   (long) TimeOuts.to_connect);
4383 			sm_dprintf("  aconnect = %ld\n",
4384 				   (long) TimeOuts.to_aconnect);
4385 			sm_dprintf("  initial = %ld\n",
4386 				   (long) TimeOuts.to_initial);
4387 			sm_dprintf("  helo = %ld\n", (long) TimeOuts.to_helo);
4388 			sm_dprintf("  mail = %ld\n", (long) TimeOuts.to_mail);
4389 			sm_dprintf("  rcpt = %ld\n", (long) TimeOuts.to_rcpt);
4390 			sm_dprintf("  datainit = %ld\n",
4391 				   (long) TimeOuts.to_datainit);
4392 			sm_dprintf("  datablock = %ld\n",
4393 				   (long) TimeOuts.to_datablock);
4394 			sm_dprintf("  datafinal = %ld\n",
4395 				   (long) TimeOuts.to_datafinal);
4396 			sm_dprintf("  rset = %ld\n", (long) TimeOuts.to_rset);
4397 			sm_dprintf("  quit = %ld\n", (long) TimeOuts.to_quit);
4398 			sm_dprintf("  nextcommand = %ld\n",
4399 				   (long) TimeOuts.to_nextcommand);
4400 			sm_dprintf("  miscshort = %ld\n",
4401 				   (long) TimeOuts.to_miscshort);
4402 			sm_dprintf("  ident = %ld\n", (long) TimeOuts.to_ident);
4403 			sm_dprintf("  fileopen = %ld\n",
4404 				   (long) TimeOuts.to_fileopen);
4405 			sm_dprintf("  lhlo = %ld\n",
4406 				   (long) TimeOuts.to_lhlo);
4407 			sm_dprintf("  control = %ld\n",
4408 				   (long) TimeOuts.to_control);
4409 		}
4410 		return;
4411 	}
4412 
4413 	for (;; val = p)
4414 	{
4415 		while (isascii(*val) && isspace(*val))
4416 			val++;
4417 		if (*val == '\0')
4418 			break;
4419 		for (p = val; *p != '\0' && *p != ','; p++)
4420 			continue;
4421 		if (*p != '\0')
4422 			*p++ = '\0';
4423 
4424 		if (isascii(*val) && isdigit(*val))
4425 		{
4426 			/* old syntax -- set everything */
4427 			TimeOuts.to_mail = convtime(val, 'm');
4428 			TimeOuts.to_rcpt = TimeOuts.to_mail;
4429 			TimeOuts.to_datainit = TimeOuts.to_mail;
4430 			TimeOuts.to_datablock = TimeOuts.to_mail;
4431 			TimeOuts.to_datafinal = TimeOuts.to_mail;
4432 			TimeOuts.to_nextcommand = TimeOuts.to_mail;
4433 			if (sticky)
4434 			{
4435 				setbitn(TO_MAIL, StickyTimeoutOpt);
4436 				setbitn(TO_RCPT, StickyTimeoutOpt);
4437 				setbitn(TO_DATAINIT, StickyTimeoutOpt);
4438 				setbitn(TO_DATABLOCK, StickyTimeoutOpt);
4439 				setbitn(TO_DATAFINAL, StickyTimeoutOpt);
4440 				setbitn(TO_COMMAND, StickyTimeoutOpt);
4441 			}
4442 			continue;
4443 		}
4444 		else
4445 		{
4446 			register char *q = strchr(val, ':');
4447 
4448 			if (q == NULL && (q = strchr(val, '=')) == NULL)
4449 			{
4450 				/* syntax error */
4451 				continue;
4452 			}
4453 			*q++ = '\0';
4454 			settimeout(val, q, sticky);
4455 		}
4456 	}
4457 }
4458