xref: /freebsd/contrib/sendmail/src/readcf.c (revision 7660b554bc59a07be0431c17e0e33815818baa69)
1 /*
2  * Copyright (c) 1998-2003 Sendmail, Inc. and its suppliers.
3  *	All rights reserved.
4  * Copyright (c) 1983, 1995-1997 Eric P. Allman.  All rights reserved.
5  * Copyright (c) 1988, 1993
6  *	The Regents of the University of California.  All rights reserved.
7  *
8  * By using this file, you agree to the terms and conditions set
9  * forth in the LICENSE file which can be found at the top level of
10  * the sendmail distribution.
11  *
12  */
13 
14 #include <sendmail.h>
15 
16 SM_RCSID("@(#)$Id: readcf.c,v 8.607.2.11 2003/04/03 23:04:06 ca Exp $")
17 
18 #if NETINET || NETINET6
19 # include <arpa/inet.h>
20 #endif /* NETINET || NETINET6 */
21 
22 #define SECONDS
23 #define MINUTES	* 60
24 #define HOUR	* 3600
25 #define HOURS	HOUR
26 
27 static void	fileclass __P((int, char *, char *, bool, bool, bool));
28 static char	**makeargv __P((char *));
29 static void	settimeout __P((char *, char *, bool));
30 static void	toomany __P((int, int));
31 static char	*extrquotstr __P((char *, char **, char *, bool *));
32 
33 /*
34 **  READCF -- read configuration file.
35 **
36 **	This routine reads the configuration file and builds the internal
37 **	form.
38 **
39 **	The file is formatted as a sequence of lines, each taken
40 **	atomically.  The first character of each line describes how
41 **	the line is to be interpreted.  The lines are:
42 **		Dxval		Define macro x to have value val.
43 **		Cxword		Put word into class x.
44 **		Fxfile [fmt]	Read file for lines to put into
45 **				class x.  Use scanf string 'fmt'
46 **				or "%s" if not present.  Fmt should
47 **				only produce one string-valued result.
48 **		Hname: value	Define header with field-name 'name'
49 **				and value as specified; this will be
50 **				macro expanded immediately before
51 **				use.
52 **		Sn		Use rewriting set n.
53 **		Rlhs rhs	Rewrite addresses that match lhs to
54 **				be rhs.
55 **		Mn arg=val...	Define mailer.  n is the internal name.
56 **				Args specify mailer parameters.
57 **		Oxvalue		Set option x to value.
58 **		O option value	Set option (long name) to value.
59 **		Pname=value	Set precedence name to value.
60 **		Qn arg=val...	Define queue groups.  n is the internal name.
61 **				Args specify queue parameters.
62 **		Vversioncode[/vendorcode]
63 **				Version level/vendor name of
64 **				configuration syntax.
65 **		Kmapname mapclass arguments....
66 **				Define keyed lookup of a given class.
67 **				Arguments are class dependent.
68 **		Eenvar=value	Set the environment value to the given value.
69 **
70 **	Parameters:
71 **		cfname -- configuration file name.
72 **		safe -- true if this is the system config file;
73 **			false otherwise.
74 **		e -- the main envelope.
75 **
76 **	Returns:
77 **		none.
78 **
79 **	Side Effects:
80 **		Builds several internal tables.
81 */
82 
83 void
84 readcf(cfname, safe, e)
85 	char *cfname;
86 	bool safe;
87 	register ENVELOPE *e;
88 {
89 	SM_FILE_T *cf;
90 	int ruleset = -1;
91 	char *q;
92 	struct rewrite *rwp = NULL;
93 	char *bp;
94 	auto char *ep;
95 	int nfuzzy;
96 	char *file;
97 	bool optional;
98 	bool ok;
99 	bool ismap;
100 	int mid;
101 	register char *p;
102 	long sff = SFF_OPENASROOT;
103 	struct stat statb;
104 	char buf[MAXLINE];
105 	char exbuf[MAXLINE];
106 	char pvpbuf[MAXLINE + MAXATOM];
107 	static char *null_list[1] = { NULL };
108 	extern unsigned char TokTypeNoC[];
109 
110 	FileName = cfname;
111 	LineNumber = 0;
112 
113 	if (DontLockReadFiles)
114 		sff |= SFF_NOLOCK;
115 	cf = safefopen(cfname, O_RDONLY, 0444, sff);
116 	if (cf == NULL)
117 	{
118 		syserr("cannot open");
119 		finis(false, true, EX_OSFILE);
120 	}
121 
122 	if (fstat(sm_io_getinfo(cf, SM_IO_WHAT_FD, NULL), &statb) < 0)
123 	{
124 		syserr("cannot fstat");
125 		finis(false, true, EX_OSFILE);
126 	}
127 
128 	if (!S_ISREG(statb.st_mode))
129 	{
130 		syserr("not a plain file");
131 		finis(false, true, EX_OSFILE);
132 	}
133 
134 	if (OpMode != MD_TEST && bitset(S_IWGRP|S_IWOTH, statb.st_mode))
135 	{
136 		if (OpMode == MD_DAEMON || OpMode == MD_INITALIAS)
137 			(void) sm_io_fprintf(smioerr, SM_TIME_DEFAULT,
138 					     "%s: WARNING: dangerous write permissions\n",
139 					     FileName);
140 		if (LogLevel > 0)
141 			sm_syslog(LOG_CRIT, NOQID,
142 				  "%s: WARNING: dangerous write permissions",
143 				  FileName);
144 	}
145 
146 #if XLA
147 	xla_zero();
148 #endif /* XLA */
149 
150 	while ((bp = fgetfolded(buf, sizeof buf, cf)) != NULL)
151 	{
152 		if (bp[0] == '#')
153 		{
154 			if (bp != buf)
155 				sm_free(bp); /* XXX */
156 			continue;
157 		}
158 
159 		/* do macro expansion mappings */
160 		translate_dollars(bp);
161 
162 		/* interpret this line */
163 		errno = 0;
164 		switch (bp[0])
165 		{
166 		  case '\0':
167 		  case '#':		/* comment */
168 			break;
169 
170 		  case 'R':		/* rewriting rule */
171 			if (ruleset < 0)
172 			{
173 				syserr("missing valid ruleset for \"%s\"", bp);
174 				break;
175 			}
176 			for (p = &bp[1]; *p != '\0' && *p != '\t'; p++)
177 				continue;
178 
179 			if (*p == '\0')
180 			{
181 				syserr("invalid rewrite line \"%s\" (tab expected)", bp);
182 				break;
183 			}
184 
185 			/* allocate space for the rule header */
186 			if (rwp == NULL)
187 			{
188 				RewriteRules[ruleset] = rwp =
189 					(struct rewrite *) xalloc(sizeof *rwp);
190 			}
191 			else
192 			{
193 				rwp->r_next = (struct rewrite *) xalloc(sizeof *rwp);
194 				rwp = rwp->r_next;
195 			}
196 			rwp->r_next = NULL;
197 
198 			/* expand and save the LHS */
199 			*p = '\0';
200 			expand(&bp[1], exbuf, sizeof exbuf, e);
201 			rwp->r_lhs = prescan(exbuf, '\t', pvpbuf,
202 					     sizeof pvpbuf, NULL,
203 					     ConfigLevel >= 9 ? TokTypeNoC : NULL);
204 			nfuzzy = 0;
205 			if (rwp->r_lhs != NULL)
206 			{
207 				register char **ap;
208 
209 				rwp->r_lhs = copyplist(rwp->r_lhs, true, NULL);
210 
211 				/* count the number of fuzzy matches in LHS */
212 				for (ap = rwp->r_lhs; *ap != NULL; ap++)
213 				{
214 					char *botch;
215 
216 					botch = NULL;
217 					switch (**ap & 0377)
218 					{
219 					  case MATCHZANY:
220 					  case MATCHANY:
221 					  case MATCHONE:
222 					  case MATCHCLASS:
223 					  case MATCHNCLASS:
224 						nfuzzy++;
225 						break;
226 
227 					  case MATCHREPL:
228 						botch = "$0-$9";
229 						break;
230 
231 					  case CANONUSER:
232 						botch = "$:";
233 						break;
234 
235 					  case CALLSUBR:
236 						botch = "$>";
237 						break;
238 
239 					  case CONDIF:
240 						botch = "$?";
241 						break;
242 
243 					  case CONDFI:
244 						botch = "$.";
245 						break;
246 
247 					  case HOSTBEGIN:
248 						botch = "$[";
249 						break;
250 
251 					  case HOSTEND:
252 						botch = "$]";
253 						break;
254 
255 					  case LOOKUPBEGIN:
256 						botch = "$(";
257 						break;
258 
259 					  case LOOKUPEND:
260 						botch = "$)";
261 						break;
262 					}
263 					if (botch != NULL)
264 						syserr("Inappropriate use of %s on LHS",
265 							botch);
266 				}
267 				rwp->r_line = LineNumber;
268 			}
269 			else
270 			{
271 				syserr("R line: null LHS");
272 				rwp->r_lhs = null_list;
273 			}
274 			if (nfuzzy > MAXMATCH)
275 			{
276 				syserr("R line: too many wildcards");
277 				rwp->r_lhs = null_list;
278 			}
279 
280 			/* expand and save the RHS */
281 			while (*++p == '\t')
282 				continue;
283 			q = p;
284 			while (*p != '\0' && *p != '\t')
285 				p++;
286 			*p = '\0';
287 			expand(q, exbuf, sizeof exbuf, e);
288 			rwp->r_rhs = prescan(exbuf, '\t', pvpbuf,
289 					     sizeof pvpbuf, NULL,
290 					     ConfigLevel >= 9 ? TokTypeNoC : NULL);
291 			if (rwp->r_rhs != NULL)
292 			{
293 				register char **ap;
294 				int args, endtoken;
295 #if _FFR_EXTRA_MAP_CHECK
296 				int nexttoken;
297 #endif /* _FFR_EXTRA_MAP_CHECK */
298 				bool inmap;
299 
300 				rwp->r_rhs = copyplist(rwp->r_rhs, true, NULL);
301 
302 				/* check no out-of-bounds replacements */
303 				nfuzzy += '0';
304 				inmap = false;
305 				args = 0;
306 				endtoken = 0;
307 				for (ap = rwp->r_rhs; *ap != NULL; ap++)
308 				{
309 					char *botch;
310 
311 					botch = NULL;
312 					switch (**ap & 0377)
313 					{
314 					  case MATCHREPL:
315 						if ((*ap)[1] <= '0' || (*ap)[1] > nfuzzy)
316 						{
317 							syserr("replacement $%c out of bounds",
318 								(*ap)[1]);
319 						}
320 						break;
321 
322 					  case MATCHZANY:
323 						botch = "$*";
324 						break;
325 
326 					  case MATCHANY:
327 						botch = "$+";
328 						break;
329 
330 					  case MATCHONE:
331 						botch = "$-";
332 						break;
333 
334 					  case MATCHCLASS:
335 						botch = "$=";
336 						break;
337 
338 					  case MATCHNCLASS:
339 						botch = "$~";
340 						break;
341 
342 					  case CANONHOST:
343 						if (!inmap)
344 							break;
345 						if (++args >= MAX_MAP_ARGS)
346 							syserr("too many arguments for map lookup");
347 						break;
348 
349 					  case HOSTBEGIN:
350 						endtoken = HOSTEND;
351 						/* FALLTHROUGH */
352 					  case LOOKUPBEGIN:
353 						/* see above... */
354 						if ((**ap & 0377) == LOOKUPBEGIN)
355 							endtoken = LOOKUPEND;
356 						if (inmap)
357 							syserr("cannot nest map lookups");
358 						inmap = true;
359 						args = 0;
360 #if _FFR_EXTRA_MAP_CHECK
361 						if (*(ap + 1) == NULL)
362 						{
363 							syserr("syntax error in map lookup");
364 							break;
365 						}
366 						nexttoken = **(ap + 1) & 0377;
367 						if (nexttoken == CANONHOST ||
368 						    nexttoken == CANONUSER ||
369 						    nexttoken == endtoken)
370 						{
371 							syserr("missing map name for lookup");
372 							break;
373 						}
374 						if (*(ap + 2) == NULL)
375 						{
376 							syserr("syntax error in map lookup");
377 							break;
378 						}
379 						if ((**ap & 0377) == HOSTBEGIN)
380 							break;
381 						nexttoken = **(ap + 2) & 0377;
382 						if (nexttoken == CANONHOST ||
383 						    nexttoken == CANONUSER ||
384 						    nexttoken == endtoken)
385 						{
386 							syserr("missing key name for lookup");
387 							break;
388 						}
389 #endif /* _FFR_EXTRA_MAP_CHECK */
390 						break;
391 
392 					  case HOSTEND:
393 					  case LOOKUPEND:
394 						if ((**ap & 0377) != endtoken)
395 							break;
396 						inmap = false;
397 						endtoken = 0;
398 						break;
399 
400 
401 #if 0
402 /*
403 **  This doesn't work yet as there are maps defined *after* the cf
404 **  is read such as host, user, and alias.  So for now, it's removed.
405 **  When it comes back, the RELEASE_NOTES entry will be:
406 **	Emit warnings for unknown maps when reading the .cf file.  Based on
407 **		patch from Robert Harker of Harker Systems.
408 */
409 
410 					  case LOOKUPBEGIN:
411 						/*
412 						**  Got a database lookup,
413 						**  check if map is defined.
414 						*/
415 
416 						ep = *(ap + 1);
417 						if ((*ep & 0377) != MACRODEXPAND &&
418 						    stab(ep, ST_MAP,
419 							 ST_FIND) == NULL)
420 						{
421 							(void) sm_io_fprintf(smioout,
422 									     SM_TIME_DEFAULT,
423 									     "Warning: %s: line %d: map %s not found\n",
424 									     FileName,
425 									     LineNumber,
426 									     ep);
427 						}
428 						break;
429 #endif /* 0 */
430 					}
431 					if (botch != NULL)
432 						syserr("Inappropriate use of %s on RHS",
433 							botch);
434 				}
435 				if (inmap)
436 					syserr("missing map closing token");
437 			}
438 			else
439 			{
440 				syserr("R line: null RHS");
441 				rwp->r_rhs = null_list;
442 			}
443 			break;
444 
445 		  case 'S':		/* select rewriting set */
446 			expand(&bp[1], exbuf, sizeof exbuf, e);
447 			ruleset = strtorwset(exbuf, NULL, ST_ENTER);
448 			if (ruleset < 0)
449 				break;
450 
451 			rwp = RewriteRules[ruleset];
452 			if (rwp != NULL)
453 			{
454 				if (OpMode == MD_TEST)
455 					(void) sm_io_fprintf(smioout,
456 							     SM_TIME_DEFAULT,
457 							     "WARNING: Ruleset %s has multiple definitions\n",
458 							    &bp[1]);
459 				if (tTd(37, 1))
460 					sm_dprintf("WARNING: Ruleset %s has multiple definitions\n",
461 						   &bp[1]);
462 				while (rwp->r_next != NULL)
463 					rwp = rwp->r_next;
464 			}
465 			break;
466 
467 		  case 'D':		/* macro definition */
468 			mid = macid_parse(&bp[1], &ep);
469 			if (mid == 0)
470 				break;
471 			p = munchstring(ep, NULL, '\0');
472 			macdefine(&e->e_macro, A_TEMP, mid, p);
473 			break;
474 
475 		  case 'H':		/* required header line */
476 			(void) chompheader(&bp[1], CHHDR_DEF, NULL, e);
477 			break;
478 
479 		  case 'C':		/* word class */
480 		  case 'T':		/* trusted user (set class `t') */
481 			if (bp[0] == 'C')
482 			{
483 				mid = macid_parse(&bp[1], &ep);
484 				if (mid == 0)
485 					break;
486 				expand(ep, exbuf, sizeof exbuf, e);
487 				p = exbuf;
488 			}
489 			else
490 			{
491 				mid = 't';
492 				p = &bp[1];
493 			}
494 			while (*p != '\0')
495 			{
496 				register char *wd;
497 				char delim;
498 
499 				while (*p != '\0' && isascii(*p) && isspace(*p))
500 					p++;
501 				wd = p;
502 				while (*p != '\0' && !(isascii(*p) && isspace(*p)))
503 					p++;
504 				delim = *p;
505 				*p = '\0';
506 				if (wd[0] != '\0')
507 					setclass(mid, wd);
508 				*p = delim;
509 			}
510 			break;
511 
512 		  case 'F':		/* word class from file */
513 			mid = macid_parse(&bp[1], &ep);
514 			if (mid == 0)
515 				break;
516 			for (p = ep; isascii(*p) && isspace(*p); )
517 				p++;
518 			if (p[0] == '-' && p[1] == 'o')
519 			{
520 				optional = true;
521 				while (*p != '\0' &&
522 				       !(isascii(*p) && isspace(*p)))
523 					p++;
524 				while (isascii(*p) && isspace(*p))
525 					p++;
526 				file = p;
527 			}
528 			else
529 				optional = false;
530 
531 			/* check if [key]@map:spec */
532 			ismap = false;
533 			if (!SM_IS_DIR_DELIM(*p) &&
534 			    *p != '|' &&
535 			    (q = strchr(p, '@')) != NULL)
536 			{
537 				q++;
538 
539 				/* look for @LDAP or @map: in string */
540 				if (strcmp(q, "LDAP") == 0 ||
541 				    (*q != ':' &&
542 				     strchr(q, ':') != NULL))
543 					ismap = true;
544 			}
545 
546 			if (ismap)
547 			{
548 				/* use entire spec */
549 				file = p;
550 			}
551 			else
552 			{
553 				file = extrquotstr(p, &q, " ", &ok);
554 				if (!ok)
555 				{
556 					syserr("illegal filename '%s'", p);
557 					break;
558 				}
559 			}
560 
561 			if (*file == '|' || ismap)
562 				p = "%s";
563 			else
564 			{
565 				p = q;
566 				if (*p == '\0')
567 					p = "%s";
568 				else
569 				{
570 					*p = '\0';
571 					while (isascii(*++p) && isspace(*p))
572 						continue;
573 				}
574 			}
575 			fileclass(mid, file, p, ismap, safe, optional);
576 			break;
577 
578 #if XLA
579 		  case 'L':		/* extended load average description */
580 			xla_init(&bp[1]);
581 			break;
582 #endif /* XLA */
583 
584 #if defined(SUN_EXTENSIONS) && defined(SUN_LOOKUP_MACRO)
585 		  case 'L':		/* lookup macro */
586 		  case 'G':		/* lookup class */
587 			/* reserved for Sun -- NIS+ database lookup */
588 			if (VendorCode != VENDOR_SUN)
589 				goto badline;
590 			sun_lg_config_line(bp, e);
591 			break;
592 #endif /* defined(SUN_EXTENSIONS) && defined(SUN_LOOKUP_MACRO) */
593 
594 		  case 'M':		/* define mailer */
595 			makemailer(&bp[1]);
596 			break;
597 
598 		  case 'O':		/* set option */
599 			setoption(bp[1], &bp[2], safe, false, e);
600 			break;
601 
602 		  case 'P':		/* set precedence */
603 			if (NumPriorities >= MAXPRIORITIES)
604 			{
605 				toomany('P', MAXPRIORITIES);
606 				break;
607 			}
608 			for (p = &bp[1]; *p != '\0' && *p != '='; p++)
609 				continue;
610 			if (*p == '\0')
611 				goto badline;
612 			*p = '\0';
613 			Priorities[NumPriorities].pri_name = newstr(&bp[1]);
614 			Priorities[NumPriorities].pri_val = atoi(++p);
615 			NumPriorities++;
616 			break;
617 
618 		  case 'Q':		/* define queue */
619 			makequeue(&bp[1], true);
620 			break;
621 
622 		  case 'V':		/* configuration syntax version */
623 			for (p = &bp[1]; isascii(*p) && isspace(*p); p++)
624 				continue;
625 			if (!isascii(*p) || !isdigit(*p))
626 			{
627 				syserr("invalid argument to V line: \"%.20s\"",
628 					&bp[1]);
629 				break;
630 			}
631 			ConfigLevel = strtol(p, &ep, 10);
632 
633 			/*
634 			**  Do heuristic tweaking for back compatibility.
635 			*/
636 
637 			if (ConfigLevel >= 5)
638 			{
639 				/* level 5 configs have short name in $w */
640 				p = macvalue('w', e);
641 				if (p != NULL && (p = strchr(p, '.')) != NULL)
642 				{
643 					*p = '\0';
644 					macdefine(&e->e_macro, A_TEMP, 'w',
645 						  macvalue('w', e));
646 				}
647 			}
648 			if (ConfigLevel >= 6)
649 			{
650 				ColonOkInAddr = false;
651 			}
652 
653 			/*
654 			**  Look for vendor code.
655 			*/
656 
657 			if (*ep++ == '/')
658 			{
659 				/* extract vendor code */
660 				for (p = ep; isascii(*p) && isalpha(*p); )
661 					p++;
662 				*p = '\0';
663 
664 				if (!setvendor(ep))
665 					syserr("invalid V line vendor code: \"%s\"",
666 						ep);
667 			}
668 			break;
669 
670 		  case 'K':
671 			expand(&bp[1], exbuf, sizeof exbuf, e);
672 			(void) makemapentry(exbuf);
673 			break;
674 
675 		  case 'E':
676 			p = strchr(bp, '=');
677 			if (p != NULL)
678 				*p++ = '\0';
679 			setuserenv(&bp[1], p);
680 			break;
681 
682 		  case 'X':		/* mail filter */
683 #if MILTER
684 			milter_setup(&bp[1]);
685 #else /* MILTER */
686 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
687 					     "Warning: Filter usage ('X') requires Milter support (-DMILTER)\n");
688 #endif /* MILTER */
689 			break;
690 
691 		  default:
692 		  badline:
693 			syserr("unknown configuration line \"%s\"", bp);
694 		}
695 		if (bp != buf)
696 			sm_free(bp); /* XXX */
697 	}
698 	if (sm_io_error(cf))
699 	{
700 		syserr("I/O read error");
701 		finis(false, true, EX_OSFILE);
702 	}
703 	(void) sm_io_close(cf, SM_TIME_DEFAULT);
704 	FileName = NULL;
705 
706 	/* initialize host maps from local service tables */
707 	inithostmaps();
708 
709 	/* initialize daemon (if not defined yet) */
710 	initdaemon();
711 
712 	/* determine if we need to do special name-server frotz */
713 	{
714 		int nmaps;
715 		char *maptype[MAXMAPSTACK];
716 		short mapreturn[MAXMAPACTIONS];
717 
718 		nmaps = switch_map_find("hosts", maptype, mapreturn);
719 		UseNameServer = false;
720 		if (nmaps > 0 && nmaps <= MAXMAPSTACK)
721 		{
722 			register int mapno;
723 
724 			for (mapno = 0; mapno < nmaps && !UseNameServer;
725 			     mapno++)
726 			{
727 				if (strcmp(maptype[mapno], "dns") == 0)
728 					UseNameServer = true;
729 			}
730 		}
731 	}
732 }
733 /*
734 **  TRANSLATE_DOLLARS -- convert $x into internal form
735 **
736 **	Actually does all appropriate pre-processing of a config line
737 **	to turn it into internal form.
738 **
739 **	Parameters:
740 **		bp -- the buffer to translate.
741 **
742 **	Returns:
743 **		None.  The buffer is translated in place.  Since the
744 **		translations always make the buffer shorter, this is
745 **		safe without a size parameter.
746 */
747 
748 void
749 translate_dollars(bp)
750 	char *bp;
751 {
752 	register char *p;
753 	auto char *ep;
754 
755 	for (p = bp; *p != '\0'; p++)
756 	{
757 		if (*p == '#' && p > bp && ConfigLevel >= 3)
758 		{
759 			register char *e;
760 
761 			switch (*--p & 0377)
762 			{
763 			  case MACROEXPAND:
764 				/* it's from $# -- let it go through */
765 				p++;
766 				break;
767 
768 			  case '\\':
769 				/* it's backslash escaped */
770 				(void) sm_strlcpy(p, p + 1, strlen(p));
771 				break;
772 
773 			  default:
774 				/* delete leading white space */
775 				while (isascii(*p) && isspace(*p) &&
776 				       *p != '\n' && p > bp)
777 					p--;
778 				if ((e = strchr(++p, '\n')) != NULL)
779 					(void) sm_strlcpy(p, e, strlen(p));
780 				else
781 					*p-- = '\0';
782 				break;
783 			}
784 			continue;
785 		}
786 
787 		if (*p != '$' || p[1] == '\0')
788 			continue;
789 
790 		if (p[1] == '$')
791 		{
792 			/* actual dollar sign.... */
793 			(void) sm_strlcpy(p, p + 1, strlen(p));
794 			continue;
795 		}
796 
797 		/* convert to macro expansion character */
798 		*p++ = MACROEXPAND;
799 
800 		/* special handling for $=, $~, $&, and $? */
801 		if (*p == '=' || *p == '~' || *p == '&' || *p == '?')
802 			p++;
803 
804 		/* convert macro name to code */
805 		*p = macid_parse(p, &ep);
806 		if (ep != p + 1)
807 			(void) sm_strlcpy(p + 1, ep, strlen(p + 1));
808 	}
809 
810 	/* strip trailing white space from the line */
811 	while (--p > bp && isascii(*p) && isspace(*p))
812 		*p = '\0';
813 }
814 /*
815 **  TOOMANY -- signal too many of some option
816 **
817 **	Parameters:
818 **		id -- the id of the error line
819 **		maxcnt -- the maximum possible values
820 **
821 **	Returns:
822 **		none.
823 **
824 **	Side Effects:
825 **		gives a syserr.
826 */
827 
828 static void
829 toomany(id, maxcnt)
830 	int id;
831 	int maxcnt;
832 {
833 	syserr("too many %c lines, %d max", id, maxcnt);
834 }
835 /*
836 **  FILECLASS -- read members of a class from a file
837 **
838 **	Parameters:
839 **		class -- class to define.
840 **		filename -- name of file to read.
841 **		fmt -- scanf string to use for match.
842 **		ismap -- if set, this is a map lookup.
843 **		safe -- if set, this is a safe read.
844 **		optional -- if set, it is not an error for the file to
845 **			not exist.
846 **
847 **	Returns:
848 **		none
849 **
850 **	Side Effects:
851 **		puts all lines in filename that match a scanf into
852 **			the named class.
853 */
854 
855 /*
856 **  Break up the match into words and add to class.
857 */
858 
859 static void
860 parse_class_words(class, line)
861 	int class;
862 	char *line;
863 {
864 	while (line != NULL && *line != '\0')
865 	{
866 		register char *q;
867 
868 		/* strip leading spaces */
869 		while (isascii(*line) && isspace(*line))
870 			line++;
871 		if (*line == '\0')
872 			break;
873 
874 		/* find the end of the word */
875 		q = line;
876 		while (*line != '\0' && !(isascii(*line) && isspace(*line)))
877 			line++;
878 		if (*line != '\0')
879 			*line++ = '\0';
880 
881 		/* enter the word in the symbol table */
882 		setclass(class, q);
883 	}
884 }
885 
886 static void
887 fileclass(class, filename, fmt, ismap, safe, optional)
888 	int class;
889 	char *filename;
890 	char *fmt;
891 	bool ismap;
892 	bool safe;
893 	bool optional;
894 {
895 	SM_FILE_T *f;
896 	long sff;
897 	pid_t pid;
898 	register char *p;
899 	char buf[MAXLINE];
900 
901 	if (tTd(37, 2))
902 		sm_dprintf("fileclass(%s, fmt=%s)\n", filename, fmt);
903 
904 	if (*filename == '\0')
905 	{
906 		syserr("fileclass: missing file name");
907 		return;
908 	}
909 	else if (ismap)
910 	{
911 		int status = 0;
912 		char *key;
913 		char *mn;
914 		char *cl, *spec;
915 		STAB *mapclass;
916 		MAP map;
917 
918 		mn = newstr(macname(class));
919 
920 		key = filename;
921 
922 		/* skip past key */
923 		if ((p = strchr(filename, '@')) == NULL)
924 		{
925 			/* should not happen */
926 			syserr("fileclass: bogus map specification");
927 			sm_free(mn);
928 			return;
929 		}
930 
931 		/* skip past '@' */
932 		*p++ = '\0';
933 		cl = p;
934 
935 #if LDAPMAP
936 		if (strcmp(cl, "LDAP") == 0)
937 		{
938 			int n;
939 			char *lc;
940 			char jbuf[MAXHOSTNAMELEN];
941 			char lcbuf[MAXLINE];
942 
943 			/* Get $j */
944 			expand("\201j", jbuf, sizeof jbuf, &BlankEnvelope);
945 			if (jbuf[0] == '\0')
946 			{
947 				(void) sm_strlcpy(jbuf, "localhost",
948 						  sizeof jbuf);
949 			}
950 
951 			/* impose the default schema */
952 			lc = macvalue(macid("{sendmailMTACluster}"), CurEnv);
953 			if (lc == NULL)
954 				lc = "";
955 			else
956 			{
957 				expand(lc, lcbuf, sizeof lcbuf, CurEnv);
958 				lc = lcbuf;
959 			}
960 
961 			cl = "ldap";
962 			n = sm_snprintf(buf, sizeof buf,
963 					"-k (&(objectClass=sendmailMTAClass)(sendmailMTAClassName=%s)(|(sendmailMTACluster=%s)(sendmailMTAHost=%s))) -v sendmailMTAClassValue",
964 					mn, lc, jbuf);
965 			if (n >= sizeof buf)
966 			{
967 				syserr("fileclass: F{%s}: Default LDAP string too long",
968 				       mn);
969 				sm_free(mn);
970 				return;
971 			}
972 			spec = buf;
973 		}
974 		else
975 #endif /* LDAPMAP */
976 		{
977 			if ((spec = strchr(cl, ':')) == NULL)
978 			{
979 				syserr("fileclass: F{%s}: missing map class",
980 				       mn);
981 				sm_free(mn);
982 				return;
983 			}
984 			*spec++ ='\0';
985 		}
986 
987 		/* set up map structure */
988 		mapclass = stab(cl, ST_MAPCLASS, ST_FIND);
989 		if (mapclass == NULL)
990 		{
991 			syserr("fileclass: F{%s}: class %s not available",
992 			       mn, cl);
993 			sm_free(mn);
994 			return;
995 		}
996 		memset(&map, '\0', sizeof map);
997 		map.map_class = &mapclass->s_mapclass;
998 		map.map_mname = mn;
999 		map.map_mflags |= MF_FILECLASS;
1000 
1001 		if (tTd(37, 5))
1002 			sm_dprintf("fileclass: F{%s}: map class %s, key %s, spec %s\n",
1003 				   mn, cl, key, spec);
1004 
1005 
1006 		/* parse map spec */
1007 		if (!map.map_class->map_parse(&map, spec))
1008 		{
1009 			/* map_parse() showed the error already */
1010 			sm_free(mn);
1011 			return;
1012 		}
1013 		map.map_mflags |= MF_VALID;
1014 
1015 		/* open map */
1016 		if (map.map_class->map_open(&map, O_RDONLY))
1017 		{
1018 			map.map_mflags |= MF_OPEN;
1019 			map.map_pid = getpid();
1020 		}
1021 		else
1022 		{
1023 			if (!optional &&
1024 			    !bitset(MF_OPTIONAL, map.map_mflags))
1025 				syserr("fileclass: F{%s}: map open failed",
1026 				       mn);
1027 			sm_free(mn);
1028 			return;
1029 		}
1030 
1031 		/* lookup */
1032 		p = (*map.map_class->map_lookup)(&map, key, NULL, &status);
1033 		if (status != EX_OK && status != EX_NOTFOUND)
1034 		{
1035 			if (!optional)
1036 				syserr("fileclass: F{%s}: map lookup failed",
1037 				       mn);
1038 			p = NULL;
1039 		}
1040 
1041 		/* use the results */
1042 		if (p != NULL)
1043 			parse_class_words(class, p);
1044 
1045 		/* close map */
1046 		map.map_mflags |= MF_CLOSING;
1047 		map.map_class->map_close(&map);
1048 		map.map_mflags &= ~(MF_OPEN|MF_WRITABLE|MF_CLOSING);
1049 		sm_free(mn);
1050 		return;
1051 	}
1052 	else if (filename[0] == '|')
1053 	{
1054 		auto int fd;
1055 		int i;
1056 		char *argv[MAXPV + 1];
1057 
1058 		i = 0;
1059 		for (p = strtok(&filename[1], " \t");
1060 		     p != NULL && i < MAXPV;
1061 		     p = strtok(NULL, " \t"))
1062 			argv[i++] = p;
1063 		argv[i] = NULL;
1064 		pid = prog_open(argv, &fd, CurEnv);
1065 		if (pid < 0)
1066 			f = NULL;
1067 		else
1068 			f = sm_io_open(SmFtStdiofd, SM_TIME_DEFAULT,
1069 				       (void *) &fd, SM_IO_RDONLY, NULL);
1070 	}
1071 	else
1072 	{
1073 		pid = -1;
1074 		sff = SFF_REGONLY;
1075 		if (!bitnset(DBS_CLASSFILEINUNSAFEDIRPATH, DontBlameSendmail))
1076 			sff |= SFF_SAFEDIRPATH;
1077 		if (!bitnset(DBS_LINKEDCLASSFILEINWRITABLEDIR,
1078 			     DontBlameSendmail))
1079 			sff |= SFF_NOWLINK;
1080 		if (safe)
1081 			sff |= SFF_OPENASROOT;
1082 		else if (RealUid == 0)
1083 			sff |= SFF_ROOTOK;
1084 		if (DontLockReadFiles)
1085 			sff |= SFF_NOLOCK;
1086 		f = safefopen(filename, O_RDONLY, 0, sff);
1087 	}
1088 	if (f == NULL)
1089 	{
1090 		if (!optional)
1091 			syserr("fileclass: cannot open '%s'", filename);
1092 		return;
1093 	}
1094 
1095 	while (sm_io_fgets(f, SM_TIME_DEFAULT, buf, sizeof buf) != NULL)
1096 	{
1097 #if SCANF
1098 		char wordbuf[MAXLINE + 1];
1099 #endif /* SCANF */
1100 
1101 		if (buf[0] == '#')
1102 			continue;
1103 #if SCANF
1104 		if (sm_io_sscanf(buf, fmt, wordbuf) != 1)
1105 			continue;
1106 		p = wordbuf;
1107 #else /* SCANF */
1108 		p = buf;
1109 #endif /* SCANF */
1110 
1111 		parse_class_words(class, p);
1112 
1113 		/*
1114 		**  If anything else is added here,
1115 		**  check if the '@' map case above
1116 		**  needs the code as well.
1117 		*/
1118 	}
1119 
1120 	(void) sm_io_close(f, SM_TIME_DEFAULT);
1121 	if (pid > 0)
1122 		(void) waitfor(pid);
1123 }
1124 /*
1125 **  MAKEMAILER -- define a new mailer.
1126 **
1127 **	Parameters:
1128 **		line -- description of mailer.  This is in labeled
1129 **			fields.  The fields are:
1130 **			   A -- the argv for this mailer
1131 **			   C -- the character set for MIME conversions
1132 **			   D -- the directory to run in
1133 **			   E -- the eol string
1134 **			   F -- the flags associated with the mailer
1135 **			   L -- the maximum line length
1136 **			   M -- the maximum message size
1137 **			   N -- the niceness at which to run
1138 **			   P -- the path to the mailer
1139 **			   Q -- the queue group for the mailer
1140 **			   R -- the recipient rewriting set
1141 **			   S -- the sender rewriting set
1142 **			   T -- the mailer type (for DSNs)
1143 **			   U -- the uid to run as
1144 **			   W -- the time to wait at the end
1145 **			   m -- maximum messages per connection
1146 **			   r -- maximum number of recipients per message
1147 **			   / -- new root directory
1148 **			The first word is the canonical name of the mailer.
1149 **
1150 **	Returns:
1151 **		none.
1152 **
1153 **	Side Effects:
1154 **		enters the mailer into the mailer table.
1155 */
1156 
1157 void
1158 makemailer(line)
1159 	char *line;
1160 {
1161 	register char *p;
1162 	register struct mailer *m;
1163 	register STAB *s;
1164 	int i;
1165 	char fcode;
1166 	auto char *endp;
1167 	static int nextmailer = 0;	/* "free" index into Mailer struct */
1168 
1169 	/* allocate a mailer and set up defaults */
1170 	m = (struct mailer *) xalloc(sizeof *m);
1171 	memset((char *) m, '\0', sizeof *m);
1172 	errno = 0; /* avoid bogus error text */
1173 
1174 	/* collect the mailer name */
1175 	for (p = line;
1176 	     *p != '\0' && *p != ',' && !(isascii(*p) && isspace(*p));
1177 	     p++)
1178 		continue;
1179 	if (*p != '\0')
1180 		*p++ = '\0';
1181 	if (line[0] == '\0')
1182 	{
1183 		syserr("name required for mailer");
1184 		return;
1185 	}
1186 	m->m_name = newstr(line);
1187 	m->m_qgrp = NOQGRP;
1188 
1189 	/* now scan through and assign info from the fields */
1190 	while (*p != '\0')
1191 	{
1192 		auto char *delimptr;
1193 
1194 		while (*p != '\0' &&
1195 		       (*p == ',' || (isascii(*p) && isspace(*p))))
1196 			p++;
1197 
1198 		/* p now points to field code */
1199 		fcode = *p;
1200 		while (*p != '\0' && *p != '=' && *p != ',')
1201 			p++;
1202 		if (*p++ != '=')
1203 		{
1204 			syserr("mailer %s: `=' expected", m->m_name);
1205 			return;
1206 		}
1207 		while (isascii(*p) && isspace(*p))
1208 			p++;
1209 
1210 		/* p now points to the field body */
1211 		p = munchstring(p, &delimptr, ',');
1212 
1213 		/* install the field into the mailer struct */
1214 		switch (fcode)
1215 		{
1216 		  case 'P':		/* pathname */
1217 			if (*p != '\0')	/* error is issued below */
1218 				m->m_mailer = newstr(p);
1219 			break;
1220 
1221 		  case 'F':		/* flags */
1222 			for (; *p != '\0'; p++)
1223 			{
1224 				if (!(isascii(*p) && isspace(*p)))
1225 				{
1226 #if _FFR_DEPRECATE_MAILER_FLAG_I
1227 					if (*p == M_INTERNAL)
1228 						sm_syslog(LOG_WARNING, NOQID,
1229 							  "WARNING: mailer=%s, flag=%c deprecated",
1230 							  m->m_name, *p);
1231 #endif /* _FFR_DEPRECATE_MAILER_FLAG_I */
1232 					setbitn(bitidx(*p), m->m_flags);
1233 				}
1234 			}
1235 			break;
1236 
1237 		  case 'S':		/* sender rewriting ruleset */
1238 		  case 'R':		/* recipient rewriting ruleset */
1239 			i = strtorwset(p, &endp, ST_ENTER);
1240 			if (i < 0)
1241 				return;
1242 			if (fcode == 'S')
1243 				m->m_sh_rwset = m->m_se_rwset = i;
1244 			else
1245 				m->m_rh_rwset = m->m_re_rwset = i;
1246 
1247 			p = endp;
1248 			if (*p++ == '/')
1249 			{
1250 				i = strtorwset(p, NULL, ST_ENTER);
1251 				if (i < 0)
1252 					return;
1253 				if (fcode == 'S')
1254 					m->m_sh_rwset = i;
1255 				else
1256 					m->m_rh_rwset = i;
1257 			}
1258 			break;
1259 
1260 		  case 'E':		/* end of line string */
1261 			if (*p == '\0')
1262 				syserr("mailer %s: null end-of-line string",
1263 					m->m_name);
1264 			else
1265 				m->m_eol = newstr(p);
1266 			break;
1267 
1268 		  case 'A':		/* argument vector */
1269 			if (*p != '\0')	/* error is issued below */
1270 				m->m_argv = makeargv(p);
1271 			break;
1272 
1273 		  case 'M':		/* maximum message size */
1274 			m->m_maxsize = atol(p);
1275 			break;
1276 
1277 		  case 'm':		/* maximum messages per connection */
1278 			m->m_maxdeliveries = atoi(p);
1279 			break;
1280 
1281 		  case 'r':		/* max recipient per envelope */
1282 			m->m_maxrcpt = atoi(p);
1283 			break;
1284 
1285 		  case 'L':		/* maximum line length */
1286 			m->m_linelimit = atoi(p);
1287 			if (m->m_linelimit < 0)
1288 				m->m_linelimit = 0;
1289 			break;
1290 
1291 		  case 'N':		/* run niceness */
1292 			m->m_nice = atoi(p);
1293 			break;
1294 
1295 		  case 'D':		/* working directory */
1296 			if (*p == '\0')
1297 				syserr("mailer %s: null working directory",
1298 					m->m_name);
1299 			else
1300 				m->m_execdir = newstr(p);
1301 			break;
1302 
1303 		  case 'C':		/* default charset */
1304 			if (*p == '\0')
1305 				syserr("mailer %s: null charset", m->m_name);
1306 			else
1307 				m->m_defcharset = newstr(p);
1308 			break;
1309 
1310 		  case 'Q':		/* queue for this mailer */
1311 			if (*p == '\0')
1312 			{
1313 				syserr("mailer %s: null queue", m->m_name);
1314 				break;
1315 			}
1316 			s = stab(p, ST_QUEUE, ST_FIND);
1317 			if (s == NULL)
1318 				syserr("mailer %s: unknown queue %s",
1319 					m->m_name, p);
1320 			else
1321 				m->m_qgrp = s->s_quegrp->qg_index;
1322 			break;
1323 
1324 		  case 'T':		/* MTA-Name/Address/Diagnostic types */
1325 			/* extract MTA name type; default to "dns" */
1326 			m->m_mtatype = newstr(p);
1327 			p = strchr(m->m_mtatype, '/');
1328 			if (p != NULL)
1329 			{
1330 				*p++ = '\0';
1331 				if (*p == '\0')
1332 					p = NULL;
1333 			}
1334 			if (*m->m_mtatype == '\0')
1335 				m->m_mtatype = "dns";
1336 
1337 			/* extract address type; default to "rfc822" */
1338 			m->m_addrtype = p;
1339 			if (p != NULL)
1340 				p = strchr(p, '/');
1341 			if (p != NULL)
1342 			{
1343 				*p++ = '\0';
1344 				if (*p == '\0')
1345 					p = NULL;
1346 			}
1347 			if (m->m_addrtype == NULL || *m->m_addrtype == '\0')
1348 				m->m_addrtype = "rfc822";
1349 
1350 			/* extract diagnostic type; default to "smtp" */
1351 			m->m_diagtype = p;
1352 			if (m->m_diagtype == NULL || *m->m_diagtype == '\0')
1353 				m->m_diagtype = "smtp";
1354 			break;
1355 
1356 		  case 'U':		/* user id */
1357 			if (isascii(*p) && !isdigit(*p))
1358 			{
1359 				char *q = p;
1360 				struct passwd *pw;
1361 
1362 				while (*p != '\0' && isascii(*p) &&
1363 				       (isalnum(*p) || strchr("-_", *p) != NULL))
1364 					p++;
1365 				while (isascii(*p) && isspace(*p))
1366 					*p++ = '\0';
1367 				if (*p != '\0')
1368 					*p++ = '\0';
1369 				if (*q == '\0')
1370 				{
1371 					syserr("mailer %s: null user name",
1372 						m->m_name);
1373 					break;
1374 				}
1375 				pw = sm_getpwnam(q);
1376 				if (pw == NULL)
1377 				{
1378 					syserr("readcf: mailer U= flag: unknown user %s", q);
1379 					break;
1380 				}
1381 				else
1382 				{
1383 					m->m_uid = pw->pw_uid;
1384 					m->m_gid = pw->pw_gid;
1385 				}
1386 			}
1387 			else
1388 			{
1389 				auto char *q;
1390 
1391 				m->m_uid = strtol(p, &q, 0);
1392 				p = q;
1393 				while (isascii(*p) && isspace(*p))
1394 					p++;
1395 				if (*p != '\0')
1396 					p++;
1397 			}
1398 			while (isascii(*p) && isspace(*p))
1399 				p++;
1400 			if (*p == '\0')
1401 				break;
1402 			if (isascii(*p) && !isdigit(*p))
1403 			{
1404 				char *q = p;
1405 				struct group *gr;
1406 
1407 				while (isascii(*p) && isalnum(*p))
1408 					p++;
1409 				*p++ = '\0';
1410 				if (*q == '\0')
1411 				{
1412 					syserr("mailer %s: null group name",
1413 						m->m_name);
1414 					break;
1415 				}
1416 				gr = getgrnam(q);
1417 				if (gr == NULL)
1418 				{
1419 					syserr("readcf: mailer U= flag: unknown group %s", q);
1420 					break;
1421 				}
1422 				else
1423 					m->m_gid = gr->gr_gid;
1424 			}
1425 			else
1426 			{
1427 				m->m_gid = strtol(p, NULL, 0);
1428 			}
1429 			break;
1430 
1431 		  case 'W':		/* wait timeout */
1432 			m->m_wait = convtime(p, 's');
1433 			break;
1434 
1435 		  case '/':		/* new root directory */
1436 			if (*p == '\0')
1437 				syserr("mailer %s: null root directory",
1438 					m->m_name);
1439 			else
1440 				m->m_rootdir = newstr(p);
1441 			break;
1442 
1443 		  default:
1444 			syserr("M%s: unknown mailer equate %c=",
1445 			       m->m_name, fcode);
1446 			break;
1447 		}
1448 
1449 		p = delimptr;
1450 	}
1451 
1452 #if !HASRRESVPORT
1453 	if (bitnset(M_SECURE_PORT, m->m_flags))
1454 	{
1455 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1456 				     "M%s: Warning: F=%c set on system that doesn't support rresvport()\n",
1457 				     m->m_name, M_SECURE_PORT);
1458 	}
1459 #endif /* !HASRRESVPORT */
1460 
1461 #if !HASNICE
1462 	if (m->m_nice != 0)
1463 	{
1464 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1465 				     "M%s: Warning: N= set on system that doesn't support nice()\n",
1466 				     m->m_name);
1467 	}
1468 #endif /* !HASNICE */
1469 
1470 	/* do some rationality checking */
1471 	if (m->m_argv == NULL)
1472 	{
1473 		syserr("M%s: A= argument required", m->m_name);
1474 		return;
1475 	}
1476 	if (m->m_mailer == NULL)
1477 	{
1478 		syserr("M%s: P= argument required", m->m_name);
1479 		return;
1480 	}
1481 
1482 	if (nextmailer >= MAXMAILERS)
1483 	{
1484 		syserr("too many mailers defined (%d max)", MAXMAILERS);
1485 		return;
1486 	}
1487 
1488 	if (m->m_maxrcpt <= 0)
1489 		m->m_maxrcpt = DEFAULT_MAX_RCPT;
1490 
1491 	/* do some heuristic cleanup for back compatibility */
1492 	if (bitnset(M_LIMITS, m->m_flags))
1493 	{
1494 		if (m->m_linelimit == 0)
1495 			m->m_linelimit = SMTPLINELIM;
1496 		if (ConfigLevel < 2)
1497 			setbitn(M_7BITS, m->m_flags);
1498 	}
1499 
1500 	if (strcmp(m->m_mailer, "[TCP]") == 0)
1501 	{
1502 		syserr("M%s: P=[TCP] must be replaced by P=[IPC]", m->m_name);
1503 		return;
1504 	}
1505 
1506 	if (strcmp(m->m_mailer, "[IPC]") == 0)
1507 	{
1508 		/* Use the second argument for host or path to socket */
1509 		if (m->m_argv[0] == NULL || m->m_argv[1] == NULL ||
1510 		    m->m_argv[1][0] == '\0')
1511 		{
1512 			syserr("M%s: too few parameters for %s mailer",
1513 			       m->m_name, m->m_mailer);
1514 			return;
1515 		}
1516 		if (strcmp(m->m_argv[0], "TCP") != 0
1517 #if NETUNIX
1518 		    && strcmp(m->m_argv[0], "FILE") != 0
1519 #endif /* NETUNIX */
1520 		    )
1521 		{
1522 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1523 					     "M%s: Warning: first argument in %s mailer must be %s\n",
1524 					     m->m_name, m->m_mailer,
1525 #if NETUNIX
1526 					     "TCP or FILE"
1527 #else /* NETUNIX */
1528 					     "TCP"
1529 #endif /* NETUNIX */
1530 				     );
1531 		}
1532 		if (m->m_mtatype == NULL)
1533 			m->m_mtatype = "dns";
1534 		if (m->m_addrtype == NULL)
1535 			m->m_addrtype = "rfc822";
1536 		if (m->m_diagtype == NULL)
1537 		{
1538 			if (m->m_argv[0] != NULL &&
1539 			    strcmp(m->m_argv[0], "FILE") == 0)
1540 				m->m_diagtype = "x-unix";
1541 			else
1542 				m->m_diagtype = "smtp";
1543 		}
1544 	}
1545 	else if (strcmp(m->m_mailer, "[FILE]") == 0)
1546 	{
1547 		/* Use the second argument for filename */
1548 		if (m->m_argv[0] == NULL || m->m_argv[1] == NULL ||
1549 		    m->m_argv[2] != NULL)
1550 		{
1551 			syserr("M%s: too %s parameters for [FILE] mailer",
1552 			       m->m_name,
1553 			       (m->m_argv[0] == NULL ||
1554 				m->m_argv[1] == NULL) ? "few" : "many");
1555 			return;
1556 		}
1557 		else if (strcmp(m->m_argv[0], "FILE") != 0)
1558 		{
1559 			syserr("M%s: first argument in [FILE] mailer must be FILE",
1560 			       m->m_name);
1561 			return;
1562 		}
1563 	}
1564 
1565 	if (m->m_eol == NULL)
1566 	{
1567 		char **pp;
1568 
1569 		/* default for SMTP is \r\n; use \n for local delivery */
1570 		for (pp = m->m_argv; *pp != NULL; pp++)
1571 		{
1572 			for (p = *pp; *p != '\0'; )
1573 			{
1574 				if ((*p++ & 0377) == MACROEXPAND && *p == 'u')
1575 					break;
1576 			}
1577 			if (*p != '\0')
1578 				break;
1579 		}
1580 		if (*pp == NULL)
1581 			m->m_eol = "\r\n";
1582 		else
1583 			m->m_eol = "\n";
1584 	}
1585 
1586 	/* enter the mailer into the symbol table */
1587 	s = stab(m->m_name, ST_MAILER, ST_ENTER);
1588 	if (s->s_mailer != NULL)
1589 	{
1590 		i = s->s_mailer->m_mno;
1591 		sm_free(s->s_mailer); /* XXX */
1592 	}
1593 	else
1594 	{
1595 		i = nextmailer++;
1596 	}
1597 	Mailer[i] = s->s_mailer = m;
1598 	m->m_mno = i;
1599 }
1600 /*
1601 **  MUNCHSTRING -- translate a string into internal form.
1602 **
1603 **	Parameters:
1604 **		p -- the string to munch.
1605 **		delimptr -- if non-NULL, set to the pointer of the
1606 **			field delimiter character.
1607 **		delim -- the delimiter for the field.
1608 **
1609 **	Returns:
1610 **		the munched string.
1611 **
1612 **	Side Effects:
1613 **		the munched string is a local static buffer.
1614 **		it must be copied before the function is called again.
1615 */
1616 
1617 char *
1618 munchstring(p, delimptr, delim)
1619 	register char *p;
1620 	char **delimptr;
1621 	int delim;
1622 {
1623 	register char *q;
1624 	bool backslash = false;
1625 	bool quotemode = false;
1626 	static char buf[MAXLINE];
1627 
1628 	for (q = buf; *p != '\0' && q < &buf[sizeof buf - 1]; p++)
1629 	{
1630 		if (backslash)
1631 		{
1632 			/* everything is roughly literal */
1633 			backslash = false;
1634 			switch (*p)
1635 			{
1636 			  case 'r':		/* carriage return */
1637 				*q++ = '\r';
1638 				continue;
1639 
1640 			  case 'n':		/* newline */
1641 				*q++ = '\n';
1642 				continue;
1643 
1644 			  case 'f':		/* form feed */
1645 				*q++ = '\f';
1646 				continue;
1647 
1648 			  case 'b':		/* backspace */
1649 				*q++ = '\b';
1650 				continue;
1651 			}
1652 			*q++ = *p;
1653 		}
1654 		else
1655 		{
1656 			if (*p == '\\')
1657 				backslash = true;
1658 			else if (*p == '"')
1659 				quotemode = !quotemode;
1660 			else if (quotemode || *p != delim)
1661 				*q++ = *p;
1662 			else
1663 				break;
1664 		}
1665 	}
1666 
1667 	if (delimptr != NULL)
1668 		*delimptr = p;
1669 	*q++ = '\0';
1670 	return buf;
1671 }
1672 /*
1673 **  EXTRQUOTSTR -- extract a (quoted) string.
1674 **
1675 **	This routine deals with quoted (") strings and escaped
1676 **	spaces (\\ ).
1677 **
1678 **	Parameters:
1679 **		p -- source string.
1680 **		delimptr -- if non-NULL, set to the pointer of the
1681 **			field delimiter character.
1682 **		delimbuf -- delimiters for the field.
1683 **		st -- if non-NULL, store the return value (whether the
1684 **			string was correctly quoted) here.
1685 **
1686 **	Returns:
1687 **		the extracted string.
1688 **
1689 **	Side Effects:
1690 **		the returned string is a local static buffer.
1691 **		it must be copied before the function is called again.
1692 */
1693 
1694 static char *
1695 extrquotstr(p, delimptr, delimbuf, st)
1696 	register char *p;
1697 	char **delimptr;
1698 	char *delimbuf;
1699 	bool *st;
1700 {
1701 	register char *q;
1702 	bool backslash = false;
1703 	bool quotemode = false;
1704 	static char buf[MAXLINE];
1705 
1706 	for (q = buf; *p != '\0' && q < &buf[sizeof buf - 1]; p++)
1707 	{
1708 		if (backslash)
1709 		{
1710 			backslash = false;
1711 			if (*p != ' ')
1712 				*q++ = '\\';
1713 		}
1714 		if (*p == '\\')
1715 			backslash = true;
1716 		else if (*p == '"')
1717 			quotemode = !quotemode;
1718 		else if (quotemode ||
1719 			 strchr(delimbuf, (int) *p) == NULL)
1720 			*q++ = *p;
1721 		else
1722 			break;
1723 	}
1724 
1725 	if (delimptr != NULL)
1726 		*delimptr = p;
1727 	*q++ = '\0';
1728 	if (st != NULL)
1729 		*st = !(quotemode || backslash);
1730 	return buf;
1731 }
1732 /*
1733 **  MAKEARGV -- break up a string into words
1734 **
1735 **	Parameters:
1736 **		p -- the string to break up.
1737 **
1738 **	Returns:
1739 **		a char **argv (dynamically allocated)
1740 **
1741 **	Side Effects:
1742 **		munges p.
1743 */
1744 
1745 static char **
1746 makeargv(p)
1747 	register char *p;
1748 {
1749 	char *q;
1750 	int i;
1751 	char **avp;
1752 	char *argv[MAXPV + 1];
1753 
1754 	/* take apart the words */
1755 	i = 0;
1756 	while (*p != '\0' && i < MAXPV)
1757 	{
1758 		q = p;
1759 		while (*p != '\0' && !(isascii(*p) && isspace(*p)))
1760 			p++;
1761 		while (isascii(*p) && isspace(*p))
1762 			*p++ = '\0';
1763 		argv[i++] = newstr(q);
1764 	}
1765 	argv[i++] = NULL;
1766 
1767 	/* now make a copy of the argv */
1768 	avp = (char **) xalloc(sizeof *avp * i);
1769 	memmove((char *) avp, (char *) argv, sizeof *avp * i);
1770 
1771 	return avp;
1772 }
1773 /*
1774 **  PRINTRULES -- print rewrite rules (for debugging)
1775 **
1776 **	Parameters:
1777 **		none.
1778 **
1779 **	Returns:
1780 **		none.
1781 **
1782 **	Side Effects:
1783 **		prints rewrite rules.
1784 */
1785 
1786 void
1787 printrules()
1788 {
1789 	register struct rewrite *rwp;
1790 	register int ruleset;
1791 
1792 	for (ruleset = 0; ruleset < 10; ruleset++)
1793 	{
1794 		if (RewriteRules[ruleset] == NULL)
1795 			continue;
1796 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1797 				     "\n----Rule Set %d:", ruleset);
1798 
1799 		for (rwp = RewriteRules[ruleset]; rwp != NULL; rwp = rwp->r_next)
1800 		{
1801 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1802 					     "\nLHS:");
1803 			printav(rwp->r_lhs);
1804 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1805 					     "RHS:");
1806 			printav(rwp->r_rhs);
1807 		}
1808 	}
1809 }
1810 /*
1811 **  PRINTMAILER -- print mailer structure (for debugging)
1812 **
1813 **	Parameters:
1814 **		m -- the mailer to print
1815 **
1816 **	Returns:
1817 **		none.
1818 */
1819 
1820 void
1821 printmailer(m)
1822 	register MAILER *m;
1823 {
1824 	int j;
1825 
1826 	(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1827 			     "mailer %d (%s): P=%s S=", m->m_mno, m->m_name,
1828 			     m->m_mailer);
1829 	if (RuleSetNames[m->m_se_rwset] == NULL)
1830 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, "%d/",
1831 				     m->m_se_rwset);
1832 	else
1833 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, "%s/",
1834 				     RuleSetNames[m->m_se_rwset]);
1835 	if (RuleSetNames[m->m_sh_rwset] == NULL)
1836 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, "%d R=",
1837 				     m->m_sh_rwset);
1838 	else
1839 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, "%s R=",
1840 				     RuleSetNames[m->m_sh_rwset]);
1841 	if (RuleSetNames[m->m_re_rwset] == NULL)
1842 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, "%d/",
1843 				     m->m_re_rwset);
1844 	else
1845 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, "%s/",
1846 				     RuleSetNames[m->m_re_rwset]);
1847 	if (RuleSetNames[m->m_rh_rwset] == NULL)
1848 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, "%d ",
1849 				     m->m_rh_rwset);
1850 	else
1851 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, "%s ",
1852 				     RuleSetNames[m->m_rh_rwset]);
1853 	(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, "M=%ld U=%d:%d F=",
1854 			     m->m_maxsize, (int) m->m_uid, (int) m->m_gid);
1855 	for (j = '\0'; j <= '\177'; j++)
1856 		if (bitnset(j, m->m_flags))
1857 			(void) sm_io_putc(smioout, SM_TIME_DEFAULT, j);
1858 	(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, " L=%d E=",
1859 			     m->m_linelimit);
1860 	xputs(m->m_eol);
1861 	if (m->m_defcharset != NULL)
1862 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, " C=%s",
1863 				     m->m_defcharset);
1864 	(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, " T=%s/%s/%s",
1865 			     m->m_mtatype == NULL
1866 				? "<undefined>" : m->m_mtatype,
1867 			     m->m_addrtype == NULL
1868 				? "<undefined>" : m->m_addrtype,
1869 			     m->m_diagtype == NULL
1870 				? "<undefined>" : m->m_diagtype);
1871 	(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, " r=%d", m->m_maxrcpt);
1872 	if (m->m_argv != NULL)
1873 	{
1874 		char **a = m->m_argv;
1875 
1876 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, " A=");
1877 		while (*a != NULL)
1878 		{
1879 			if (a != m->m_argv)
1880 				(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1881 						     " ");
1882 			xputs(*a++);
1883 		}
1884 	}
1885 	(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT, "\n");
1886 }
1887 /*
1888 **  SETOPTION -- set global processing option
1889 **
1890 **	Parameters:
1891 **		opt -- option name.
1892 **		val -- option value (as a text string).
1893 **		safe -- set if this came from a configuration file.
1894 **			Some options (if set from the command line) will
1895 **			reset the user id to avoid security problems.
1896 **		sticky -- if set, don't let other setoptions override
1897 **			this value.
1898 **		e -- the main envelope.
1899 **
1900 **	Returns:
1901 **		none.
1902 **
1903 **	Side Effects:
1904 **		Sets options as implied by the arguments.
1905 */
1906 
1907 static BITMAP256	StickyOpt;		/* set if option is stuck */
1908 
1909 #if NAMED_BIND
1910 
1911 static struct resolverflags
1912 {
1913 	char	*rf_name;	/* name of the flag */
1914 	long	rf_bits;	/* bits to set/clear */
1915 } ResolverFlags[] =
1916 {
1917 	{ "debug",	RES_DEBUG	},
1918 	{ "aaonly",	RES_AAONLY	},
1919 	{ "usevc",	RES_USEVC	},
1920 	{ "primary",	RES_PRIMARY	},
1921 	{ "igntc",	RES_IGNTC	},
1922 	{ "recurse",	RES_RECURSE	},
1923 	{ "defnames",	RES_DEFNAMES	},
1924 	{ "stayopen",	RES_STAYOPEN	},
1925 	{ "dnsrch",	RES_DNSRCH	},
1926 # ifdef RES_USE_INET6
1927 	{ "use_inet6",	RES_USE_INET6	},
1928 # endif /* RES_USE_INET6 */
1929 	{ "true",	0		},	/* avoid error on old syntax */
1930 	{ NULL,		0		}
1931 };
1932 
1933 #endif /* NAMED_BIND */
1934 
1935 #define OI_NONE		0	/* no special treatment */
1936 #define OI_SAFE		0x0001	/* safe for random people to use */
1937 #define OI_SUBOPT	0x0002	/* option has suboptions */
1938 
1939 static struct optioninfo
1940 {
1941 	char		*o_name;	/* long name of option */
1942 	unsigned char	o_code;		/* short name of option */
1943 	unsigned short	o_flags;	/* option flags */
1944 } OptionTab[] =
1945 {
1946 #if defined(SUN_EXTENSIONS) && defined(REMOTE_MODE)
1947 	{ "RemoteMode",			'>',		OI_NONE	},
1948 #endif /* defined(SUN_EXTENSIONS) && defined(REMOTE_MODE) */
1949 	{ "SevenBitInput",		'7',		OI_SAFE	},
1950 	{ "EightBitMode",		'8',		OI_SAFE	},
1951 	{ "AliasFile",			'A',		OI_NONE	},
1952 	{ "AliasWait",			'a',		OI_NONE	},
1953 	{ "BlankSub",			'B',		OI_NONE	},
1954 	{ "MinFreeBlocks",		'b',		OI_SAFE	},
1955 	{ "CheckpointInterval",		'C',		OI_SAFE	},
1956 	{ "HoldExpensive",		'c',		OI_NONE	},
1957 	{ "DeliveryMode",		'd',		OI_SAFE	},
1958 	{ "ErrorHeader",		'E',		OI_NONE	},
1959 	{ "ErrorMode",			'e',		OI_SAFE	},
1960 	{ "TempFileMode",		'F',		OI_NONE	},
1961 	{ "SaveFromLine",		'f',		OI_NONE	},
1962 	{ "MatchGECOS",			'G',		OI_NONE	},
1963 
1964 	/* no long name, just here to avoid problems in setoption */
1965 	{ "",				'g',		OI_NONE	},
1966 	{ "HelpFile",			'H',		OI_NONE	},
1967 	{ "MaxHopCount",		'h',		OI_NONE	},
1968 	{ "ResolverOptions",		'I',		OI_NONE	},
1969 	{ "IgnoreDots",			'i',		OI_SAFE	},
1970 	{ "ForwardPath",		'J',		OI_NONE	},
1971 	{ "SendMimeErrors",		'j',		OI_SAFE	},
1972 	{ "ConnectionCacheSize",	'k',		OI_NONE	},
1973 	{ "ConnectionCacheTimeout",	'K',		OI_NONE	},
1974 	{ "UseErrorsTo",		'l',		OI_NONE	},
1975 	{ "LogLevel",			'L',		OI_SAFE	},
1976 	{ "MeToo",			'm',		OI_SAFE	},
1977 
1978 	/* no long name, just here to avoid problems in setoption */
1979 	{ "",				'M',		OI_NONE	},
1980 	{ "CheckAliases",		'n',		OI_NONE	},
1981 	{ "OldStyleHeaders",		'o',		OI_SAFE	},
1982 	{ "DaemonPortOptions",		'O',		OI_NONE	},
1983 	{ "PrivacyOptions",		'p',		OI_SAFE	},
1984 	{ "PostmasterCopy",		'P',		OI_NONE	},
1985 	{ "QueueFactor",		'q',		OI_NONE	},
1986 	{ "QueueDirectory",		'Q',		OI_NONE	},
1987 	{ "DontPruneRoutes",		'R',		OI_NONE	},
1988 	{ "Timeout",			'r',		OI_SUBOPT },
1989 	{ "StatusFile",			'S',		OI_NONE	},
1990 	{ "SuperSafe",			's',		OI_SAFE	},
1991 	{ "QueueTimeout",		'T',		OI_NONE	},
1992 	{ "TimeZoneSpec",		't',		OI_NONE	},
1993 	{ "UserDatabaseSpec",		'U',		OI_NONE	},
1994 	{ "DefaultUser",		'u',		OI_NONE	},
1995 	{ "FallbackMXhost",		'V',		OI_NONE	},
1996 	{ "Verbose",			'v',		OI_SAFE	},
1997 	{ "TryNullMXList",		'w',		OI_NONE	},
1998 	{ "QueueLA",			'x',		OI_NONE	},
1999 	{ "RefuseLA",			'X',		OI_NONE	},
2000 	{ "RecipientFactor",		'y',		OI_NONE	},
2001 	{ "ForkEachJob",		'Y',		OI_NONE	},
2002 	{ "ClassFactor",		'z',		OI_NONE	},
2003 	{ "RetryFactor",		'Z',		OI_NONE	},
2004 #define O_QUEUESORTORD	0x81
2005 	{ "QueueSortOrder",		O_QUEUESORTORD,	OI_SAFE	},
2006 #define O_HOSTSFILE	0x82
2007 	{ "HostsFile",			O_HOSTSFILE,	OI_NONE	},
2008 #define O_MQA		0x83
2009 	{ "MinQueueAge",		O_MQA,		OI_SAFE	},
2010 #define O_DEFCHARSET	0x85
2011 	{ "DefaultCharSet",		O_DEFCHARSET,	OI_SAFE	},
2012 #define O_SSFILE	0x86
2013 	{ "ServiceSwitchFile",		O_SSFILE,	OI_NONE	},
2014 #define O_DIALDELAY	0x87
2015 	{ "DialDelay",			O_DIALDELAY,	OI_SAFE	},
2016 #define O_NORCPTACTION	0x88
2017 	{ "NoRecipientAction",		O_NORCPTACTION,	OI_SAFE	},
2018 #define O_SAFEFILEENV	0x89
2019 	{ "SafeFileEnvironment",	O_SAFEFILEENV,	OI_NONE	},
2020 #define O_MAXMSGSIZE	0x8a
2021 	{ "MaxMessageSize",		O_MAXMSGSIZE,	OI_NONE	},
2022 #define O_COLONOKINADDR	0x8b
2023 	{ "ColonOkInAddr",		O_COLONOKINADDR, OI_SAFE },
2024 #define O_MAXQUEUERUN	0x8c
2025 	{ "MaxQueueRunSize",		O_MAXQUEUERUN,	OI_SAFE	},
2026 #define O_MAXCHILDREN	0x8d
2027 	{ "MaxDaemonChildren",		O_MAXCHILDREN,	OI_NONE	},
2028 #define O_KEEPCNAMES	0x8e
2029 	{ "DontExpandCnames",		O_KEEPCNAMES,	OI_NONE	},
2030 #define O_MUSTQUOTE	0x8f
2031 	{ "MustQuoteChars",		O_MUSTQUOTE,	OI_NONE	},
2032 #define O_SMTPGREETING	0x90
2033 	{ "SmtpGreetingMessage",	O_SMTPGREETING,	OI_NONE	},
2034 #define O_UNIXFROM	0x91
2035 	{ "UnixFromLine",		O_UNIXFROM,	OI_NONE	},
2036 #define O_OPCHARS	0x92
2037 	{ "OperatorChars",		O_OPCHARS,	OI_NONE	},
2038 #define O_DONTINITGRPS	0x93
2039 	{ "DontInitGroups",		O_DONTINITGRPS,	OI_NONE	},
2040 #define O_SLFH		0x94
2041 	{ "SingleLineFromHeader",	O_SLFH,		OI_SAFE	},
2042 #define O_ABH		0x95
2043 	{ "AllowBogusHELO",		O_ABH,		OI_SAFE	},
2044 #define O_CONNTHROT	0x97
2045 	{ "ConnectionRateThrottle",	O_CONNTHROT,	OI_NONE	},
2046 #define O_UGW		0x99
2047 	{ "UnsafeGroupWrites",		O_UGW,		OI_NONE	},
2048 #define O_DBLBOUNCE	0x9a
2049 	{ "DoubleBounceAddress",	O_DBLBOUNCE,	OI_NONE	},
2050 #define O_HSDIR		0x9b
2051 	{ "HostStatusDirectory",	O_HSDIR,	OI_NONE	},
2052 #define O_SINGTHREAD	0x9c
2053 	{ "SingleThreadDelivery",	O_SINGTHREAD,	OI_NONE	},
2054 #define O_RUNASUSER	0x9d
2055 	{ "RunAsUser",			O_RUNASUSER,	OI_NONE	},
2056 #define O_DSN_RRT	0x9e
2057 	{ "RrtImpliesDsn",		O_DSN_RRT,	OI_NONE	},
2058 #define O_PIDFILE	0x9f
2059 	{ "PidFile",			O_PIDFILE,	OI_NONE	},
2060 #define O_DONTBLAMESENDMAIL	0xa0
2061 	{ "DontBlameSendmail",		O_DONTBLAMESENDMAIL,	OI_NONE	},
2062 #define O_DPI		0xa1
2063 	{ "DontProbeInterfaces",	O_DPI,		OI_NONE	},
2064 #define O_MAXRCPT	0xa2
2065 	{ "MaxRecipientsPerMessage",	O_MAXRCPT,	OI_SAFE	},
2066 #define O_DEADLETTER	0xa3
2067 	{ "DeadLetterDrop",		O_DEADLETTER,	OI_NONE	},
2068 #if _FFR_DONTLOCKFILESFORREAD_OPTION
2069 # define O_DONTLOCK	0xa4
2070 	{ "DontLockFilesForRead",	O_DONTLOCK,	OI_NONE	},
2071 #endif /* _FFR_DONTLOCKFILESFORREAD_OPTION */
2072 #define O_MAXALIASRCSN	0xa5
2073 	{ "MaxAliasRecursion",		O_MAXALIASRCSN,	OI_NONE	},
2074 #define O_CNCTONLYTO	0xa6
2075 	{ "ConnectOnlyTo",		O_CNCTONLYTO,	OI_NONE	},
2076 #define O_TRUSTUSER	0xa7
2077 	{ "TrustedUser",		O_TRUSTUSER,	OI_NONE	},
2078 #define O_MAXMIMEHDRLEN	0xa8
2079 	{ "MaxMimeHeaderLength",	O_MAXMIMEHDRLEN,	OI_NONE	},
2080 #define O_CONTROLSOCKET	0xa9
2081 	{ "ControlSocketName",		O_CONTROLSOCKET,	OI_NONE	},
2082 #define O_MAXHDRSLEN	0xaa
2083 	{ "MaxHeadersLength",		O_MAXHDRSLEN,	OI_NONE	},
2084 #if _FFR_MAX_FORWARD_ENTRIES
2085 # define O_MAXFORWARD	0xab
2086 	{ "MaxForwardEntries",		O_MAXFORWARD,	OI_NONE	},
2087 #endif /* _FFR_MAX_FORWARD_ENTRIES */
2088 #define O_PROCTITLEPREFIX	0xac
2089 	{ "ProcessTitlePrefix",		O_PROCTITLEPREFIX,	OI_NONE	},
2090 #define O_SASLINFO	0xad
2091 #if _FFR_ALLOW_SASLINFO
2092 	{ "DefaultAuthInfo",		O_SASLINFO,	OI_SAFE	},
2093 #else /* _FFR_ALLOW_SASLINFO */
2094 	{ "DefaultAuthInfo",		O_SASLINFO,	OI_NONE	},
2095 #endif /* _FFR_ALLOW_SASLINFO */
2096 #define O_SASLMECH	0xae
2097 	{ "AuthMechanisms",		O_SASLMECH,	OI_NONE	},
2098 #define O_CLIENTPORT	0xaf
2099 	{ "ClientPortOptions",		O_CLIENTPORT,	OI_NONE	},
2100 #define O_DF_BUFSIZE	0xb0
2101 	{ "DataFileBufferSize",		O_DF_BUFSIZE,	OI_NONE	},
2102 #define O_XF_BUFSIZE	0xb1
2103 	{ "XscriptFileBufferSize",	O_XF_BUFSIZE,	OI_NONE	},
2104 #define O_LDAPDEFAULTSPEC	0xb2
2105 	{ "LDAPDefaultSpec",		O_LDAPDEFAULTSPEC,	OI_NONE	},
2106 #if _FFR_QUEUEDELAY
2107 # define O_QUEUEDELAY	0xb3
2108 	{ "QueueDelay",			O_QUEUEDELAY,	OI_NONE	},
2109 #endif /* _FFR_QUEUEDELAY */
2110 #define O_SRVCERTFILE	0xb4
2111 	{ "ServerCertFile",		O_SRVCERTFILE,	OI_NONE	},
2112 #define O_SRVKEYFILE	0xb5
2113 	{ "ServerKeyFile",		O_SRVKEYFILE,	OI_NONE	},
2114 #define O_CLTCERTFILE	0xb6
2115 	{ "ClientCertFile",		O_CLTCERTFILE,	OI_NONE	},
2116 #define O_CLTKEYFILE	0xb7
2117 	{ "ClientKeyFile",		O_CLTKEYFILE,	OI_NONE	},
2118 #define O_CACERTFILE	0xb8
2119 	{ "CACertFile",			O_CACERTFILE,	OI_NONE	},
2120 #define O_CACERTPATH	0xb9
2121 	{ "CACertPath",			O_CACERTPATH,	OI_NONE	},
2122 #define O_DHPARAMS	0xba
2123 	{ "DHParameters",		O_DHPARAMS,	OI_NONE	},
2124 #define O_INPUTMILTER	0xbb
2125 	{ "InputMailFilters",		O_INPUTMILTER,	OI_NONE	},
2126 #define O_MILTER	0xbc
2127 	{ "Milter",			O_MILTER,	OI_SUBOPT	},
2128 #define O_SASLOPTS	0xbd
2129 	{ "AuthOptions",		O_SASLOPTS,	OI_NONE	},
2130 #define O_QUEUE_FILE_MODE	0xbe
2131 	{ "QueueFileMode",		O_QUEUE_FILE_MODE, OI_NONE	},
2132 #if _FFR_TLS_1
2133 # define O_DHPARAMS5	0xbf
2134 	{ "DHParameters512",		O_DHPARAMS5,	OI_NONE	},
2135 # define O_CIPHERLIST	0xc0
2136 	{ "CipherList",			O_CIPHERLIST,	OI_NONE	},
2137 #endif /* _FFR_TLS_1 */
2138 #define O_RANDFILE	0xc1
2139 	{ "RandFile",			O_RANDFILE,	OI_NONE	},
2140 #define O_TLS_SRV_OPTS	0xc2
2141 	{ "TLSSrvOptions",		O_TLS_SRV_OPTS,	OI_NONE	},
2142 #define O_RCPTTHROT	0xc3
2143 	{ "BadRcptThrottle",		O_RCPTTHROT,	OI_SAFE	},
2144 #define O_DLVR_MIN	0xc4
2145 	{ "DeliverByMin",		O_DLVR_MIN,	OI_NONE	},
2146 #define O_MAXQUEUECHILDREN	0xc5
2147 	{ "MaxQueueChildren",		O_MAXQUEUECHILDREN,	OI_NONE	},
2148 #define O_MAXRUNNERSPERQUEUE	0xc6
2149 	{ "MaxRunnersPerQueue",		O_MAXRUNNERSPERQUEUE,	OI_NONE },
2150 #define O_DIRECTSUBMODIFIERS	0xc7
2151 	{ "DirectSubmissionModifiers",	O_DIRECTSUBMODIFIERS,	OI_NONE },
2152 #define O_NICEQUEUERUN	0xc8
2153 	{ "NiceQueueRun",		O_NICEQUEUERUN,	OI_NONE	},
2154 #define O_SHMKEY	0xc9
2155 	{ "SharedMemoryKey",		O_SHMKEY,	OI_NONE	},
2156 #define O_SASLBITS	0xca
2157 	{ "AuthMaxBits",		O_SASLBITS,	OI_NONE	},
2158 #define O_MBDB		0xcb
2159 	{ "MailboxDatabase",		O_MBDB,		OI_NONE	},
2160 #define O_MSQ		0xcc
2161 	{ "UseMSP",	O_MSQ,		OI_NONE	},
2162 #define O_DELAY_LA	0xcd
2163 	{ "DelayLA",	O_DELAY_LA,	OI_NONE	},
2164 #define O_FASTSPLIT	0xce
2165 	{ "FastSplit",	O_FASTSPLIT,	OI_NONE	},
2166 #if _FFR_SOFT_BOUNCE
2167 # define O_SOFTBOUNCE	0xcf
2168 	{ "SoftBounce",	O_SOFTBOUNCE,	OI_NONE	},
2169 #endif /* _FFR_SOFT_BOUNCE */
2170 #if _FFR_SELECT_SHM
2171 # define O_SHMKEYFILE	0xd0
2172 	{ "SharedMemoryKeyFile",	O_SHMKEYFILE,	OI_NONE	},
2173 #endif /* _FFR_SELECT_SHM */
2174 #if _FFR_REJECT_LOG
2175 # define O_REJECTLOGINTERVAL	0xd1
2176 	{ "RejectLogInterval",	O_REJECTLOGINTERVAL,	OI_NONE	},
2177 #endif /* _FFR_REJECT_LOG */
2178 #if _FFR_REQ_DIR_FSYNC_OPT
2179 # define O_REQUIRES_DIR_FSYNC	0xd2
2180 	{ "RequiresDirfsync",	O_REQUIRES_DIR_FSYNC,	OI_NONE	},
2181 #endif /* _FFR_REQ_DIR_FSYNC_OPT */
2182 	{ NULL,				'\0',		OI_NONE	}
2183 };
2184 
2185 # define CANONIFY(val)
2186 
2187 # define SET_OPT_DEFAULT(opt, val)	opt = val
2188 
2189 /* set a string option by expanding the value and assigning it */
2190 /* WARNING this belongs ONLY into a case statement! */
2191 #define SET_STRING_EXP(str)	\
2192 		expand(val, exbuf, sizeof exbuf, e);	\
2193 		newval = sm_pstrdup_x(exbuf);		\
2194 		if (str != NULL)	\
2195 			sm_free(str);	\
2196 		CANONIFY(newval);	\
2197 		str = newval;		\
2198 		break
2199 
2200 #define OPTNAME	o->o_name == NULL ? "<unknown>" : o->o_name
2201 
2202 void
2203 setoption(opt, val, safe, sticky, e)
2204 	int opt;
2205 	char *val;
2206 	bool safe;
2207 	bool sticky;
2208 	register ENVELOPE *e;
2209 {
2210 	register char *p;
2211 	register struct optioninfo *o;
2212 	char *subopt;
2213 	int mid;
2214 	bool can_setuid = RunAsUid == 0;
2215 	auto char *ep;
2216 	char buf[50];
2217 	extern bool Warn_Q_option;
2218 #if _FFR_ALLOW_SASLINFO
2219 	extern unsigned int SubmitMode;
2220 #endif /* _FFR_ALLOW_SASLINFO */
2221 #if STARTTLS
2222 	char *newval;
2223 	char exbuf[MAXLINE];
2224 #endif /* STARTTLS */
2225 
2226 	errno = 0;
2227 	if (opt == ' ')
2228 	{
2229 		/* full word options */
2230 		struct optioninfo *sel;
2231 
2232 		p = strchr(val, '=');
2233 		if (p == NULL)
2234 			p = &val[strlen(val)];
2235 		while (*--p == ' ')
2236 			continue;
2237 		while (*++p == ' ')
2238 			*p = '\0';
2239 		if (p == val)
2240 		{
2241 			syserr("readcf: null option name");
2242 			return;
2243 		}
2244 		if (*p == '=')
2245 			*p++ = '\0';
2246 		while (*p == ' ')
2247 			p++;
2248 		subopt = strchr(val, '.');
2249 		if (subopt != NULL)
2250 			*subopt++ = '\0';
2251 		sel = NULL;
2252 		for (o = OptionTab; o->o_name != NULL; o++)
2253 		{
2254 			if (sm_strncasecmp(o->o_name, val, strlen(val)) != 0)
2255 				continue;
2256 			if (strlen(o->o_name) == strlen(val))
2257 			{
2258 				/* completely specified -- this must be it */
2259 				sel = NULL;
2260 				break;
2261 			}
2262 			if (sel != NULL)
2263 				break;
2264 			sel = o;
2265 		}
2266 		if (sel != NULL && o->o_name == NULL)
2267 			o = sel;
2268 		else if (o->o_name == NULL)
2269 		{
2270 			syserr("readcf: unknown option name %s", val);
2271 			return;
2272 		}
2273 		else if (sel != NULL)
2274 		{
2275 			syserr("readcf: ambiguous option name %s (matches %s and %s)",
2276 				val, sel->o_name, o->o_name);
2277 			return;
2278 		}
2279 		if (strlen(val) != strlen(o->o_name))
2280 		{
2281 			int oldVerbose = Verbose;
2282 
2283 			Verbose = 1;
2284 			message("Option %s used as abbreviation for %s",
2285 				val, o->o_name);
2286 			Verbose = oldVerbose;
2287 		}
2288 		opt = o->o_code;
2289 		val = p;
2290 	}
2291 	else
2292 	{
2293 		for (o = OptionTab; o->o_name != NULL; o++)
2294 		{
2295 			if (o->o_code == opt)
2296 				break;
2297 		}
2298 		if (o->o_name == NULL)
2299 		{
2300 			syserr("readcf: unknown option name 0x%x", opt & 0xff);
2301 			return;
2302 		}
2303 		subopt = NULL;
2304 	}
2305 
2306 	if (subopt != NULL && !bitset(OI_SUBOPT, o->o_flags))
2307 	{
2308 		if (tTd(37, 1))
2309 			sm_dprintf("setoption: %s does not support suboptions, ignoring .%s\n",
2310 				   OPTNAME, subopt);
2311 		subopt = NULL;
2312 	}
2313 
2314 	if (tTd(37, 1))
2315 	{
2316 		sm_dprintf(isascii(opt) && isprint(opt) ?
2317 			   "setoption %s (%c)%s%s=" :
2318 			   "setoption %s (0x%x)%s%s=",
2319 			   OPTNAME, opt, subopt == NULL ? "" : ".",
2320 			   subopt == NULL ? "" : subopt);
2321 		xputs(val);
2322 	}
2323 
2324 	/*
2325 	**  See if this option is preset for us.
2326 	*/
2327 
2328 	if (!sticky && bitnset(opt, StickyOpt))
2329 	{
2330 		if (tTd(37, 1))
2331 			sm_dprintf(" (ignored)\n");
2332 		return;
2333 	}
2334 
2335 	/*
2336 	**  Check to see if this option can be specified by this user.
2337 	*/
2338 
2339 	if (!safe && RealUid == 0)
2340 		safe = true;
2341 	if (!safe && !bitset(OI_SAFE, o->o_flags))
2342 	{
2343 		if (opt != 'M' || (val[0] != 'r' && val[0] != 's'))
2344 		{
2345 			int dp;
2346 
2347 			if (tTd(37, 1))
2348 				sm_dprintf(" (unsafe)");
2349 			dp = drop_privileges(true);
2350 			setstat(dp);
2351 		}
2352 	}
2353 	if (tTd(37, 1))
2354 		sm_dprintf("\n");
2355 
2356 	switch (opt & 0xff)
2357 	{
2358 	  case '7':		/* force seven-bit input */
2359 		SevenBitInput = atobool(val);
2360 		break;
2361 
2362 	  case '8':		/* handling of 8-bit input */
2363 #if MIME8TO7
2364 		switch (*val)
2365 		{
2366 		  case 'p':		/* pass 8 bit, convert MIME */
2367 			MimeMode = MM_CVTMIME|MM_PASS8BIT;
2368 			break;
2369 
2370 		  case 'm':		/* convert 8-bit, convert MIME */
2371 			MimeMode = MM_CVTMIME|MM_MIME8BIT;
2372 			break;
2373 
2374 		  case 's':		/* strict adherence */
2375 			MimeMode = MM_CVTMIME;
2376 			break;
2377 
2378 # if 0
2379 		  case 'r':		/* reject 8-bit, don't convert MIME */
2380 			MimeMode = 0;
2381 			break;
2382 
2383 		  case 'j':		/* "just send 8" */
2384 			MimeMode = MM_PASS8BIT;
2385 			break;
2386 
2387 		  case 'a':		/* encode 8 bit if available */
2388 			MimeMode = MM_MIME8BIT|MM_PASS8BIT|MM_CVTMIME;
2389 			break;
2390 
2391 		  case 'c':		/* convert 8 bit to MIME, never 7 bit */
2392 			MimeMode = MM_MIME8BIT;
2393 			break;
2394 # endif /* 0 */
2395 
2396 		  default:
2397 			syserr("Unknown 8-bit mode %c", *val);
2398 			finis(false, true, EX_USAGE);
2399 		}
2400 #else /* MIME8TO7 */
2401 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
2402 				     "Warning: Option: %s requires MIME8TO7 support\n",
2403 				     OPTNAME);
2404 #endif /* MIME8TO7 */
2405 		break;
2406 
2407 	  case 'A':		/* set default alias file */
2408 		if (val[0] == '\0')
2409 		{
2410 			char *al;
2411 
2412 			SET_OPT_DEFAULT(al, "aliases");
2413 			setalias(al);
2414 		}
2415 		else
2416 			setalias(val);
2417 		break;
2418 
2419 	  case 'a':		/* look N minutes for "@:@" in alias file */
2420 		if (val[0] == '\0')
2421 			SafeAlias = 5 MINUTES;
2422 		else
2423 			SafeAlias = convtime(val, 'm');
2424 		break;
2425 
2426 	  case 'B':		/* substitution for blank character */
2427 		SpaceSub = val[0];
2428 		if (SpaceSub == '\0')
2429 			SpaceSub = ' ';
2430 		break;
2431 
2432 	  case 'b':		/* min blocks free on queue fs/max msg size */
2433 		p = strchr(val, '/');
2434 		if (p != NULL)
2435 		{
2436 			*p++ = '\0';
2437 			MaxMessageSize = atol(p);
2438 		}
2439 		MinBlocksFree = atol(val);
2440 		break;
2441 
2442 	  case 'c':		/* don't connect to "expensive" mailers */
2443 		NoConnect = atobool(val);
2444 		break;
2445 
2446 	  case 'C':		/* checkpoint every N addresses */
2447 		CheckpointInterval = atoi(val);
2448 		break;
2449 
2450 	  case 'd':		/* delivery mode */
2451 		switch (*val)
2452 		{
2453 		  case '\0':
2454 			set_delivery_mode(SM_DELIVER, e);
2455 			break;
2456 
2457 		  case SM_QUEUE:	/* queue only */
2458 		  case SM_DEFER:	/* queue only and defer map lookups */
2459 		  case SM_DELIVER:	/* do everything */
2460 		  case SM_FORK:		/* fork after verification */
2461 			set_delivery_mode(*val, e);
2462 			break;
2463 
2464 		  default:
2465 			syserr("Unknown delivery mode %c", *val);
2466 			finis(false, true, EX_USAGE);
2467 		}
2468 		break;
2469 
2470 	  case 'E':		/* error message header/header file */
2471 		if (*val != '\0')
2472 			ErrMsgFile = newstr(val);
2473 		break;
2474 
2475 	  case 'e':		/* set error processing mode */
2476 		switch (*val)
2477 		{
2478 		  case EM_QUIET:	/* be silent about it */
2479 		  case EM_MAIL:		/* mail back */
2480 		  case EM_BERKNET:	/* do berknet error processing */
2481 		  case EM_WRITE:	/* write back (or mail) */
2482 		  case EM_PRINT:	/* print errors normally (default) */
2483 			e->e_errormode = *val;
2484 			break;
2485 		}
2486 		break;
2487 
2488 	  case 'F':		/* file mode */
2489 		FileMode = atooct(val) & 0777;
2490 		break;
2491 
2492 	  case 'f':		/* save Unix-style From lines on front */
2493 		SaveFrom = atobool(val);
2494 		break;
2495 
2496 	  case 'G':		/* match recipients against GECOS field */
2497 		MatchGecos = atobool(val);
2498 		break;
2499 
2500 	  case 'g':		/* default gid */
2501   g_opt:
2502 		if (isascii(*val) && isdigit(*val))
2503 			DefGid = atoi(val);
2504 		else
2505 		{
2506 			register struct group *gr;
2507 
2508 			DefGid = -1;
2509 			gr = getgrnam(val);
2510 			if (gr == NULL)
2511 				syserr("readcf: option %c: unknown group %s",
2512 					opt, val);
2513 			else
2514 				DefGid = gr->gr_gid;
2515 		}
2516 		break;
2517 
2518 	  case 'H':		/* help file */
2519 		if (val[0] == '\0')
2520 		{
2521 			SET_OPT_DEFAULT(HelpFile, "helpfile");
2522 		}
2523 		else
2524 		{
2525 			CANONIFY(val);
2526 			HelpFile = newstr(val);
2527 		}
2528 		break;
2529 
2530 	  case 'h':		/* maximum hop count */
2531 		MaxHopCount = atoi(val);
2532 		break;
2533 
2534 	  case 'I':		/* use internet domain name server */
2535 #if NAMED_BIND
2536 		for (p = val; *p != 0; )
2537 		{
2538 			bool clearmode;
2539 			char *q;
2540 			struct resolverflags *rfp;
2541 
2542 			while (*p == ' ')
2543 				p++;
2544 			if (*p == '\0')
2545 				break;
2546 			clearmode = false;
2547 			if (*p == '-')
2548 				clearmode = true;
2549 			else if (*p != '+')
2550 				p--;
2551 			p++;
2552 			q = p;
2553 			while (*p != '\0' && !(isascii(*p) && isspace(*p)))
2554 				p++;
2555 			if (*p != '\0')
2556 				*p++ = '\0';
2557 			if (sm_strcasecmp(q, "HasWildcardMX") == 0)
2558 			{
2559 				HasWildcardMX = !clearmode;
2560 				continue;
2561 			}
2562 			if (sm_strcasecmp(q, "WorkAroundBrokenAAAA") == 0)
2563 			{
2564 				WorkAroundBrokenAAAA = !clearmode;
2565 				continue;
2566 			}
2567 			for (rfp = ResolverFlags; rfp->rf_name != NULL; rfp++)
2568 			{
2569 				if (sm_strcasecmp(q, rfp->rf_name) == 0)
2570 					break;
2571 			}
2572 			if (rfp->rf_name == NULL)
2573 				syserr("readcf: I option value %s unrecognized", q);
2574 			else if (clearmode)
2575 				_res.options &= ~rfp->rf_bits;
2576 			else
2577 				_res.options |= rfp->rf_bits;
2578 		}
2579 		if (tTd(8, 2))
2580 			sm_dprintf("_res.options = %x, HasWildcardMX = %d\n",
2581 				   (unsigned int) _res.options, HasWildcardMX);
2582 #else /* NAMED_BIND */
2583 		usrerr("name server (I option) specified but BIND not compiled in");
2584 #endif /* NAMED_BIND */
2585 		break;
2586 
2587 	  case 'i':		/* ignore dot lines in message */
2588 		IgnrDot = atobool(val);
2589 		break;
2590 
2591 	  case 'j':		/* send errors in MIME (RFC 1341) format */
2592 		SendMIMEErrors = atobool(val);
2593 		break;
2594 
2595 	  case 'J':		/* .forward search path */
2596 		CANONIFY(val);
2597 		ForwardPath = newstr(val);
2598 		break;
2599 
2600 	  case 'k':		/* connection cache size */
2601 		MaxMciCache = atoi(val);
2602 		if (MaxMciCache < 0)
2603 			MaxMciCache = 0;
2604 		break;
2605 
2606 	  case 'K':		/* connection cache timeout */
2607 		MciCacheTimeout = convtime(val, 'm');
2608 		break;
2609 
2610 	  case 'l':		/* use Errors-To: header */
2611 		UseErrorsTo = atobool(val);
2612 		break;
2613 
2614 	  case 'L':		/* log level */
2615 		if (safe || LogLevel < atoi(val))
2616 			LogLevel = atoi(val);
2617 		break;
2618 
2619 	  case 'M':		/* define macro */
2620 		sticky = false;
2621 		mid = macid_parse(val, &ep);
2622 		if (mid == 0)
2623 			break;
2624 		p = newstr(ep);
2625 		if (!safe)
2626 			cleanstrcpy(p, p, strlen(p) + 1);
2627 		macdefine(&CurEnv->e_macro, A_TEMP, mid, p);
2628 		break;
2629 
2630 	  case 'm':		/* send to me too */
2631 		MeToo = atobool(val);
2632 		break;
2633 
2634 	  case 'n':		/* validate RHS in newaliases */
2635 		CheckAliases = atobool(val);
2636 		break;
2637 
2638 	    /* 'N' available -- was "net name" */
2639 
2640 	  case 'O':		/* daemon options */
2641 		if (!setdaemonoptions(val))
2642 			syserr("too many daemons defined (%d max)", MAXDAEMONS);
2643 		break;
2644 
2645 	  case 'o':		/* assume old style headers */
2646 		if (atobool(val))
2647 			CurEnv->e_flags |= EF_OLDSTYLE;
2648 		else
2649 			CurEnv->e_flags &= ~EF_OLDSTYLE;
2650 		break;
2651 
2652 	  case 'p':		/* select privacy level */
2653 		p = val;
2654 		for (;;)
2655 		{
2656 			register struct prival *pv;
2657 			extern struct prival PrivacyValues[];
2658 
2659 			while (isascii(*p) && (isspace(*p) || ispunct(*p)))
2660 				p++;
2661 			if (*p == '\0')
2662 				break;
2663 			val = p;
2664 			while (isascii(*p) && isalnum(*p))
2665 				p++;
2666 			if (*p != '\0')
2667 				*p++ = '\0';
2668 
2669 			for (pv = PrivacyValues; pv->pv_name != NULL; pv++)
2670 			{
2671 				if (sm_strcasecmp(val, pv->pv_name) == 0)
2672 					break;
2673 			}
2674 			if (pv->pv_name == NULL)
2675 				syserr("readcf: Op line: %s unrecognized", val);
2676 			else
2677 				PrivacyFlags |= pv->pv_flag;
2678 		}
2679 		sticky = false;
2680 		break;
2681 
2682 	  case 'P':		/* postmaster copy address for returned mail */
2683 		PostMasterCopy = newstr(val);
2684 		break;
2685 
2686 	  case 'q':		/* slope of queue only function */
2687 		QueueFactor = atoi(val);
2688 		break;
2689 
2690 	  case 'Q':		/* queue directory */
2691 		if (val[0] == '\0')
2692 		{
2693 			QueueDir = "mqueue";
2694 		}
2695 		else
2696 		{
2697 			QueueDir = newstr(val);
2698 		}
2699 		if (RealUid != 0 && !safe)
2700 			Warn_Q_option = true;
2701 		break;
2702 
2703 	  case 'R':		/* don't prune routes */
2704 		DontPruneRoutes = atobool(val);
2705 		break;
2706 
2707 	  case 'r':		/* read timeout */
2708 		if (subopt == NULL)
2709 			inittimeouts(val, sticky);
2710 		else
2711 			settimeout(subopt, val, sticky);
2712 		break;
2713 
2714 	  case 'S':		/* status file */
2715 		if (val[0] == '\0')
2716 		{
2717 			SET_OPT_DEFAULT(StatFile, "statistics");
2718 		}
2719 		else
2720 		{
2721 			CANONIFY(val);
2722 			StatFile = newstr(val);
2723 		}
2724 		break;
2725 
2726 	  case 's':		/* be super safe, even if expensive */
2727 		if (tolower(*val) == 'i')
2728 			SuperSafe = SAFE_INTERACTIVE;
2729 		else
2730 			SuperSafe = atobool(val) ? SAFE_REALLY : SAFE_NO;
2731 		break;
2732 
2733 	  case 'T':		/* queue timeout */
2734 		p = strchr(val, '/');
2735 		if (p != NULL)
2736 		{
2737 			*p++ = '\0';
2738 			settimeout("queuewarn", p, sticky);
2739 		}
2740 		settimeout("queuereturn", val, sticky);
2741 		break;
2742 
2743 	  case 't':		/* time zone name */
2744 		TimeZoneSpec = newstr(val);
2745 		break;
2746 
2747 	  case 'U':		/* location of user database */
2748 		UdbSpec = newstr(val);
2749 		break;
2750 
2751 	  case 'u':		/* set default uid */
2752 		for (p = val; *p != '\0'; p++)
2753 		{
2754 # if _FFR_DOTTED_USERNAMES
2755 			if (*p == '/' || *p == ':')
2756 # else /* _FFR_DOTTED_USERNAMES */
2757 			if (*p == '.' || *p == '/' || *p == ':')
2758 # endif /* _FFR_DOTTED_USERNAMES */
2759 			{
2760 				*p++ = '\0';
2761 				break;
2762 			}
2763 		}
2764 		if (isascii(*val) && isdigit(*val))
2765 		{
2766 			DefUid = atoi(val);
2767 			setdefuser();
2768 		}
2769 		else
2770 		{
2771 			register struct passwd *pw;
2772 
2773 			DefUid = -1;
2774 			pw = sm_getpwnam(val);
2775 			if (pw == NULL)
2776 			{
2777 				syserr("readcf: option u: unknown user %s", val);
2778 				break;
2779 			}
2780 			else
2781 			{
2782 				DefUid = pw->pw_uid;
2783 				DefGid = pw->pw_gid;
2784 				DefUser = newstr(pw->pw_name);
2785 			}
2786 		}
2787 
2788 # ifdef UID_MAX
2789 		if (DefUid > UID_MAX)
2790 		{
2791 			syserr("readcf: option u: uid value (%ld) > UID_MAX (%ld); ignored",
2792 				(long)DefUid, (long)UID_MAX);
2793 			break;
2794 		}
2795 # endif /* UID_MAX */
2796 
2797 		/* handle the group if it is there */
2798 		if (*p == '\0')
2799 			break;
2800 		val = p;
2801 		goto g_opt;
2802 
2803 	  case 'V':		/* fallback MX host */
2804 		if (val[0] != '\0')
2805 			FallBackMX = newstr(val);
2806 		break;
2807 
2808 	  case 'v':		/* run in verbose mode */
2809 		Verbose = atobool(val) ? 1 : 0;
2810 		break;
2811 
2812 	  case 'w':		/* if we are best MX, try host directly */
2813 		TryNullMXList = atobool(val);
2814 		break;
2815 
2816 	    /* 'W' available -- was wizard password */
2817 
2818 	  case 'x':		/* load avg at which to auto-queue msgs */
2819 		QueueLA = atoi(val);
2820 		break;
2821 
2822 	  case 'X':	/* load avg at which to auto-reject connections */
2823 		RefuseLA = atoi(val);
2824 		break;
2825 
2826 	  case O_DELAY_LA:	/* load avg at which to delay connections */
2827 		DelayLA = atoi(val);
2828 		break;
2829 
2830 	  case 'y':		/* work recipient factor */
2831 		WkRecipFact = atoi(val);
2832 		break;
2833 
2834 	  case 'Y':		/* fork jobs during queue runs */
2835 		ForkQueueRuns = atobool(val);
2836 		break;
2837 
2838 	  case 'z':		/* work message class factor */
2839 		WkClassFact = atoi(val);
2840 		break;
2841 
2842 	  case 'Z':		/* work time factor */
2843 		WkTimeFact = atoi(val);
2844 		break;
2845 
2846 
2847 #if _FFR_QUEUE_GROUP_SORTORDER
2848 	/* coordinate this with makequeue() */
2849 #endif /* _FFR_QUEUE_GROUP_SORTORDER */
2850 	  case O_QUEUESORTORD:	/* queue sorting order */
2851 		switch (*val)
2852 		{
2853 		  case 'f':	/* File Name */
2854 		  case 'F':
2855 			QueueSortOrder = QSO_BYFILENAME;
2856 			break;
2857 
2858 		  case 'h':	/* Host first */
2859 		  case 'H':
2860 			QueueSortOrder = QSO_BYHOST;
2861 			break;
2862 
2863 		  case 'm':	/* Modification time */
2864 		  case 'M':
2865 			QueueSortOrder = QSO_BYMODTIME;
2866 			break;
2867 
2868 		  case 'p':	/* Priority order */
2869 		  case 'P':
2870 			QueueSortOrder = QSO_BYPRIORITY;
2871 			break;
2872 
2873 		  case 't':	/* Submission time */
2874 		  case 'T':
2875 			QueueSortOrder = QSO_BYTIME;
2876 			break;
2877 
2878 		  case 'r':	/* Random */
2879 		  case 'R':
2880 			QueueSortOrder = QSO_RANDOM;
2881 			break;
2882 
2883 #if _FFR_RHS
2884 		  case 's':	/* Shuffled host name */
2885 		  case 'S':
2886 			QueueSortOrder = QSO_BYSHUFFLE;
2887 			break;
2888 #endif /* _FFR_RHS */
2889 
2890 		  default:
2891 			syserr("Invalid queue sort order \"%s\"", val);
2892 		}
2893 		break;
2894 
2895 #if _FFR_QUEUEDELAY
2896 	  case O_QUEUEDELAY:	/* queue delay algorithm */
2897 		switch (*val)
2898 		{
2899 		  case 'e':	/* exponential */
2900 		  case 'E':
2901 			QueueAlg = QD_EXP;
2902 			QueueInitDelay = 10 MINUTES;
2903 			QueueMaxDelay = 2 HOURS;
2904 			p = strchr(val, '/');
2905 			if (p != NULL)
2906 			{
2907 				char *q;
2908 
2909 				*p++ = '\0';
2910 				q = strchr(p, '/');
2911 				if (q != NULL)
2912 					*q++ = '\0';
2913 				QueueInitDelay = convtime(p, 's');
2914 				if (q != NULL)
2915 				{
2916 					QueueMaxDelay = convtime(q, 's');
2917 				}
2918 			}
2919 			break;
2920 
2921 		  case 'l':	/* linear */
2922 		  case 'L':
2923 			QueueAlg = QD_LINEAR;
2924 			break;
2925 
2926 		  default:
2927 			syserr("Invalid queue delay algorithm \"%s\"", val);
2928 		}
2929 		break;
2930 #endif /* _FFR_QUEUEDELAY */
2931 
2932 	  case O_HOSTSFILE:	/* pathname of /etc/hosts file */
2933 		CANONIFY(val);
2934 		HostsFile = newstr(val);
2935 		break;
2936 
2937 	  case O_MQA:		/* minimum queue age between deliveries */
2938 		MinQueueAge = convtime(val, 'm');
2939 		break;
2940 
2941 	  case O_DEFCHARSET:	/* default character set for mimefying */
2942 		DefaultCharSet = newstr(denlstring(val, true, true));
2943 		break;
2944 
2945 	  case O_SSFILE:	/* service switch file */
2946 		CANONIFY(val);
2947 		ServiceSwitchFile = newstr(val);
2948 		break;
2949 
2950 	  case O_DIALDELAY:	/* delay for dial-on-demand operation */
2951 		DialDelay = convtime(val, 's');
2952 		break;
2953 
2954 	  case O_NORCPTACTION:	/* what to do if no recipient */
2955 		if (sm_strcasecmp(val, "none") == 0)
2956 			NoRecipientAction = NRA_NO_ACTION;
2957 		else if (sm_strcasecmp(val, "add-to") == 0)
2958 			NoRecipientAction = NRA_ADD_TO;
2959 		else if (sm_strcasecmp(val, "add-apparently-to") == 0)
2960 			NoRecipientAction = NRA_ADD_APPARENTLY_TO;
2961 		else if (sm_strcasecmp(val, "add-bcc") == 0)
2962 			NoRecipientAction = NRA_ADD_BCC;
2963 		else if (sm_strcasecmp(val, "add-to-undisclosed") == 0)
2964 			NoRecipientAction = NRA_ADD_TO_UNDISCLOSED;
2965 		else
2966 			syserr("Invalid NoRecipientAction: %s", val);
2967 		break;
2968 
2969 	  case O_SAFEFILEENV:	/* chroot() environ for writing to files */
2970 		if (*val == '\0')
2971 			break;
2972 
2973 		/* strip trailing slashes */
2974 		p = val + strlen(val) - 1;
2975 		while (p >= val && *p == '/')
2976 			*p-- = '\0';
2977 
2978 		if (*val == '\0')
2979 			break;
2980 
2981 		SafeFileEnv = newstr(val);
2982 		break;
2983 
2984 	  case O_MAXMSGSIZE:	/* maximum message size */
2985 		MaxMessageSize = atol(val);
2986 		break;
2987 
2988 	  case O_COLONOKINADDR:	/* old style handling of colon addresses */
2989 		ColonOkInAddr = atobool(val);
2990 		break;
2991 
2992 	  case O_MAXQUEUERUN:	/* max # of jobs in a single queue run */
2993 		MaxQueueRun = atoi(val);
2994 		break;
2995 
2996 	  case O_MAXCHILDREN:	/* max # of children of daemon */
2997 		MaxChildren = atoi(val);
2998 		break;
2999 
3000 	  case O_MAXQUEUECHILDREN: /* max # of children of daemon */
3001 		MaxQueueChildren = atoi(val);
3002 		break;
3003 
3004 	  case O_MAXRUNNERSPERQUEUE: /* max # runners in a queue group */
3005 		MaxRunnersPerQueue = atoi(val);
3006 		break;
3007 
3008 	  case O_NICEQUEUERUN:		/* nice queue runs */
3009 #if !HASNICE
3010 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3011 				     "Warning: NiceQueueRun set on system that doesn't support nice()\n");
3012 #endif /* !HASNICE */
3013 
3014 		/* XXX do we want to check the range? > 0 ? */
3015 		NiceQueueRun = atoi(val);
3016 		break;
3017 
3018 	  case O_SHMKEY:		/* shared memory key */
3019 #if SM_CONF_SHM
3020 		ShmKey = atol(val);
3021 #else /* SM_CONF_SHM */
3022 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3023 				     "Warning: Option: %s requires shared memory support (-DSM_CONF_SHM)\n",
3024 				     OPTNAME);
3025 #endif /* SM_CONF_SHM */
3026 		break;
3027 
3028 #if _FFR_SELECT_SHM
3029 	  case O_SHMKEYFILE:		/* shared memory key file */
3030 # if SM_CONF_SHM
3031 		SET_STRING_EXP(ShmKeyFile);
3032 # else /* SM_CONF_SHM */
3033 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3034 				     "Warning: Option: %s requires shared memory support (-DSM_CONF_SHM)\n",
3035 				     OPTNAME);
3036 		break;
3037 # endif /* SM_CONF_SHM */
3038 #endif /* _FFR_SELECT_SHM */
3039 
3040 #if _FFR_MAX_FORWARD_ENTRIES
3041 	  case O_MAXFORWARD:	/* max # of forward entries */
3042 		MaxForwardEntries = atoi(val);
3043 		break;
3044 #endif /* _FFR_MAX_FORWARD_ENTRIES */
3045 
3046 	  case O_KEEPCNAMES:	/* don't expand CNAME records */
3047 		DontExpandCnames = atobool(val);
3048 		break;
3049 
3050 	  case O_MUSTQUOTE:	/* must quote these characters in phrases */
3051 		(void) sm_strlcpy(buf, "@,;:\\()[]", sizeof buf);
3052 		if (strlen(val) < sizeof buf - 10)
3053 			(void) sm_strlcat(buf, val, sizeof buf);
3054 		else
3055 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3056 					     "Warning: MustQuoteChars too long, ignored.\n");
3057 		MustQuoteChars = newstr(buf);
3058 		break;
3059 
3060 	  case O_SMTPGREETING:	/* SMTP greeting message (old $e macro) */
3061 		SmtpGreeting = newstr(munchstring(val, NULL, '\0'));
3062 		break;
3063 
3064 	  case O_UNIXFROM:	/* UNIX From_ line (old $l macro) */
3065 		UnixFromLine = newstr(munchstring(val, NULL, '\0'));
3066 		break;
3067 
3068 	  case O_OPCHARS:	/* operator characters (old $o macro) */
3069 		if (OperatorChars != NULL)
3070 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3071 					     "Warning: OperatorChars is being redefined.\n         It should only be set before ruleset definitions.\n");
3072 		OperatorChars = newstr(munchstring(val, NULL, '\0'));
3073 		break;
3074 
3075 	  case O_DONTINITGRPS:	/* don't call initgroups(3) */
3076 		DontInitGroups = atobool(val);
3077 		break;
3078 
3079 	  case O_SLFH:		/* make sure from fits on one line */
3080 		SingleLineFromHeader = atobool(val);
3081 		break;
3082 
3083 	  case O_ABH:		/* allow HELO commands with syntax errors */
3084 		AllowBogusHELO = atobool(val);
3085 		break;
3086 
3087 	  case O_CONNTHROT:	/* connection rate throttle */
3088 		ConnRateThrottle = atoi(val);
3089 		break;
3090 
3091 	  case O_UGW:		/* group writable files are unsafe */
3092 		if (!atobool(val))
3093 		{
3094 			setbitn(DBS_GROUPWRITABLEFORWARDFILESAFE,
3095 				DontBlameSendmail);
3096 			setbitn(DBS_GROUPWRITABLEINCLUDEFILESAFE,
3097 				DontBlameSendmail);
3098 		}
3099 		break;
3100 
3101 	  case O_DBLBOUNCE:	/* address to which to send double bounces */
3102 		DoubleBounceAddr = newstr(val);
3103 		break;
3104 
3105 	  case O_HSDIR:		/* persistent host status directory */
3106 		if (val[0] != '\0')
3107 		{
3108 			CANONIFY(val);
3109 			HostStatDir = newstr(val);
3110 		}
3111 		break;
3112 
3113 	  case O_SINGTHREAD:	/* single thread deliveries (requires hsdir) */
3114 		SingleThreadDelivery = atobool(val);
3115 		break;
3116 
3117 	  case O_RUNASUSER:	/* run bulk of code as this user */
3118 		for (p = val; *p != '\0'; p++)
3119 		{
3120 # if _FFR_DOTTED_USERNAMES
3121 			if (*p == '/' || *p == ':')
3122 # else /* _FFR_DOTTED_USERNAMES */
3123 			if (*p == '.' || *p == '/' || *p == ':')
3124 # endif /* _FFR_DOTTED_USERNAMES */
3125 			{
3126 				*p++ = '\0';
3127 				break;
3128 			}
3129 		}
3130 		if (isascii(*val) && isdigit(*val))
3131 		{
3132 			if (can_setuid)
3133 				RunAsUid = atoi(val);
3134 		}
3135 		else
3136 		{
3137 			register struct passwd *pw;
3138 
3139 			pw = sm_getpwnam(val);
3140 			if (pw == NULL)
3141 			{
3142 				syserr("readcf: option RunAsUser: unknown user %s", val);
3143 				break;
3144 			}
3145 			else if (can_setuid)
3146 			{
3147 				if (*p == '\0')
3148 					RunAsUserName = newstr(val);
3149 				RunAsUid = pw->pw_uid;
3150 				RunAsGid = pw->pw_gid;
3151 			}
3152 			else if (EffGid == pw->pw_gid)
3153 				RunAsGid = pw->pw_gid;
3154 			else if (UseMSP && *p == '\0')
3155 				(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3156 						     "WARNING: RunAsGid for MSP ignored, check group ids (egid=%d, want=%d)\n",
3157 						     (int) EffGid,
3158 						     (int) pw->pw_gid);
3159 		}
3160 # ifdef UID_MAX
3161 		if (RunAsUid > UID_MAX)
3162 		{
3163 			syserr("readcf: option RunAsUser: uid value (%ld) > UID_MAX (%ld); ignored",
3164 				(long) RunAsUid, (long) UID_MAX);
3165 			break;
3166 		}
3167 # endif /* UID_MAX */
3168 		if (*p != '\0')
3169 		{
3170 			if (isascii(*p) && isdigit(*p))
3171 			{
3172 				gid_t runasgid;
3173 
3174 				runasgid = (gid_t) atoi(p);
3175 				if (can_setuid || EffGid == runasgid)
3176 					RunAsGid = runasgid;
3177 				else if (UseMSP)
3178 					(void) sm_io_fprintf(smioout,
3179 							     SM_TIME_DEFAULT,
3180 							     "WARNING: RunAsGid for MSP ignored, check group ids (egid=%d, want=%d)\n",
3181 							     (int) EffGid,
3182 							     (int) runasgid);
3183 			}
3184 			else
3185 			{
3186 				register struct group *gr;
3187 
3188 				gr = getgrnam(p);
3189 				if (gr == NULL)
3190 					syserr("readcf: option RunAsUser: unknown group %s",
3191 						p);
3192 				else if (can_setuid || EffGid == gr->gr_gid)
3193 					RunAsGid = gr->gr_gid;
3194 				else if (UseMSP)
3195 					(void) sm_io_fprintf(smioout,
3196 							     SM_TIME_DEFAULT,
3197 							     "WARNING: RunAsGid for MSP ignored, check group ids (egid=%d, want=%d)\n",
3198 							     (int) EffGid,
3199 							     (int) gr->gr_gid);
3200 			}
3201 		}
3202 		if (tTd(47, 5))
3203 			sm_dprintf("readcf: RunAsUser = %d:%d\n",
3204 				   (int) RunAsUid, (int) RunAsGid);
3205 		break;
3206 
3207 	  case O_DSN_RRT:
3208 		RrtImpliesDsn = atobool(val);
3209 		break;
3210 
3211 	  case O_PIDFILE:
3212 		PSTRSET(PidFile, val);
3213 		break;
3214 
3215 	  case O_DONTBLAMESENDMAIL:
3216 		p = val;
3217 		for (;;)
3218 		{
3219 			register struct dbsval *dbs;
3220 			extern struct dbsval DontBlameSendmailValues[];
3221 
3222 			while (isascii(*p) && (isspace(*p) || ispunct(*p)))
3223 				p++;
3224 			if (*p == '\0')
3225 				break;
3226 			val = p;
3227 			while (isascii(*p) && isalnum(*p))
3228 				p++;
3229 			if (*p != '\0')
3230 				*p++ = '\0';
3231 
3232 			for (dbs = DontBlameSendmailValues;
3233 			     dbs->dbs_name != NULL; dbs++)
3234 			{
3235 				if (sm_strcasecmp(val, dbs->dbs_name) == 0)
3236 					break;
3237 			}
3238 			if (dbs->dbs_name == NULL)
3239 				syserr("readcf: DontBlameSendmail option: %s unrecognized", val);
3240 			else if (dbs->dbs_flag == DBS_SAFE)
3241 				clrbitmap(DontBlameSendmail);
3242 			else
3243 				setbitn(dbs->dbs_flag, DontBlameSendmail);
3244 		}
3245 		sticky = false;
3246 		break;
3247 
3248 	  case O_DPI:
3249 		if (sm_strcasecmp(val, "loopback") == 0)
3250 			DontProbeInterfaces = DPI_SKIPLOOPBACK;
3251 		else if (atobool(val))
3252 			DontProbeInterfaces = DPI_PROBENONE;
3253 		else
3254 			DontProbeInterfaces = DPI_PROBEALL;
3255 		break;
3256 
3257 	  case O_MAXRCPT:
3258 		MaxRcptPerMsg = atoi(val);
3259 		break;
3260 
3261 	  case O_RCPTTHROT:
3262 		BadRcptThrottle = atoi(val);
3263 		break;
3264 
3265 	  case O_DEADLETTER:
3266 		CANONIFY(val);
3267 		PSTRSET(DeadLetterDrop, val);
3268 		break;
3269 
3270 #if _FFR_DONTLOCKFILESFORREAD_OPTION
3271 	  case O_DONTLOCK:
3272 		DontLockReadFiles = atobool(val);
3273 		break;
3274 #endif /* _FFR_DONTLOCKFILESFORREAD_OPTION */
3275 
3276 	  case O_MAXALIASRCSN:
3277 		MaxAliasRecursion = atoi(val);
3278 		break;
3279 
3280 	  case O_CNCTONLYTO:
3281 		/* XXX should probably use gethostbyname */
3282 #if NETINET || NETINET6
3283 		ConnectOnlyTo.sa.sa_family = AF_UNSPEC;
3284 # if NETINET6
3285 		if (anynet_pton(AF_INET6, val,
3286 				&ConnectOnlyTo.sin6.sin6_addr) != 1)
3287 			ConnectOnlyTo.sa.sa_family = AF_INET6;
3288 		else
3289 # endif /* NETINET6 */
3290 # if NETINET
3291 		{
3292 			ConnectOnlyTo.sin.sin_addr.s_addr = inet_addr(val);
3293 			if (ConnectOnlyTo.sin.sin_addr.s_addr != INADDR_NONE)
3294 				ConnectOnlyTo.sa.sa_family = AF_INET;
3295 		}
3296 
3297 # endif /* NETINET */
3298 		if (ConnectOnlyTo.sa.sa_family == AF_UNSPEC)
3299 		{
3300 			syserr("readcf: option ConnectOnlyTo: invalid IP address %s",
3301 			       val);
3302 			break;
3303 		}
3304 #endif /* NETINET || NETINET6 */
3305 		break;
3306 
3307 	  case O_TRUSTUSER:
3308 # if !HASFCHOWN && !defined(_FFR_DROP_TRUSTUSER_WARNING)
3309 		if (!UseMSP)
3310 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3311 					     "readcf: option TrustedUser may cause problems on systems\n        which do not support fchown() if UseMSP is not set.\n");
3312 # endif /* !HASFCHOWN && !defined(_FFR_DROP_TRUSTUSER_WARNING) */
3313 		if (isascii(*val) && isdigit(*val))
3314 			TrustedUid = atoi(val);
3315 		else
3316 		{
3317 			register struct passwd *pw;
3318 
3319 			TrustedUid = 0;
3320 			pw = sm_getpwnam(val);
3321 			if (pw == NULL)
3322 			{
3323 				syserr("readcf: option TrustedUser: unknown user %s", val);
3324 				break;
3325 			}
3326 			else
3327 				TrustedUid = pw->pw_uid;
3328 		}
3329 
3330 # ifdef UID_MAX
3331 		if (TrustedUid > UID_MAX)
3332 		{
3333 			syserr("readcf: option TrustedUser: uid value (%ld) > UID_MAX (%ld)",
3334 				(long) TrustedUid, (long) UID_MAX);
3335 			TrustedUid = 0;
3336 		}
3337 # endif /* UID_MAX */
3338 		break;
3339 
3340 	  case O_MAXMIMEHDRLEN:
3341 		p = strchr(val, '/');
3342 		if (p != NULL)
3343 			*p++ = '\0';
3344 		MaxMimeHeaderLength = atoi(val);
3345 		if (p != NULL && *p != '\0')
3346 			MaxMimeFieldLength = atoi(p);
3347 		else
3348 			MaxMimeFieldLength = MaxMimeHeaderLength / 2;
3349 
3350 		if (MaxMimeHeaderLength <= 0)
3351 			MaxMimeHeaderLength = 0;
3352 		else if (MaxMimeHeaderLength < 128)
3353 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3354 					     "Warning: MaxMimeHeaderLength: header length limit set lower than 128\n");
3355 
3356 		if (MaxMimeFieldLength <= 0)
3357 			MaxMimeFieldLength = 0;
3358 		else if (MaxMimeFieldLength < 40)
3359 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3360 					     "Warning: MaxMimeHeaderLength: field length limit set lower than 40\n");
3361 		break;
3362 
3363 	  case O_CONTROLSOCKET:
3364 		PSTRSET(ControlSocketName, val);
3365 		break;
3366 
3367 	  case O_MAXHDRSLEN:
3368 		MaxHeadersLength = atoi(val);
3369 
3370 		if (MaxHeadersLength > 0 &&
3371 		    MaxHeadersLength < (MAXHDRSLEN / 2))
3372 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3373 					     "Warning: MaxHeadersLength: headers length limit set lower than %d\n",
3374 					     (MAXHDRSLEN / 2));
3375 		break;
3376 
3377 	  case O_PROCTITLEPREFIX:
3378 		PSTRSET(ProcTitlePrefix, val);
3379 		break;
3380 
3381 #if SASL
3382 	  case O_SASLINFO:
3383 # if _FFR_ALLOW_SASLINFO
3384 		/*
3385 		**  Allow users to select their own authinfo file
3386 		**  under certain circumstances, otherwise just ignore
3387 		**  the option.  If the option isn't ignored, several
3388 		**  commands don't work very well, e.g., mailq.
3389 		**  However, this is not a "perfect" solution.
3390 		**  If mail is queued, the authentication info
3391 		**  will not be used in subsequent delivery attempts.
3392 		**  If we really want to support this, then it has
3393 		**  to be stored in the queue file.
3394 		*/
3395 		if (!bitset(SUBMIT_MSA, SubmitMode) && RealUid != 0 &&
3396 		    RunAsUid != RealUid)
3397 			break;
3398 # endif /* _FFR_ALLOW_SASLINFO */
3399 		PSTRSET(SASLInfo, val);
3400 		break;
3401 
3402 	  case O_SASLMECH:
3403 		if (AuthMechanisms != NULL)
3404 			sm_free(AuthMechanisms); /* XXX */
3405 		if (*val != '\0')
3406 			AuthMechanisms = newstr(val);
3407 		else
3408 			AuthMechanisms = NULL;
3409 		break;
3410 
3411 	  case O_SASLOPTS:
3412 		while (val != NULL && *val != '\0')
3413 		{
3414 			switch (*val)
3415 			{
3416 			  case 'A':
3417 				SASLOpts |= SASL_AUTH_AUTH;
3418 				break;
3419 
3420 			  case 'a':
3421 				SASLOpts |= SASL_SEC_NOACTIVE;
3422 				break;
3423 
3424 			  case 'c':
3425 				SASLOpts |= SASL_SEC_PASS_CREDENTIALS;
3426 				break;
3427 
3428 			  case 'd':
3429 				SASLOpts |= SASL_SEC_NODICTIONARY;
3430 				break;
3431 
3432 			  case 'f':
3433 				SASLOpts |= SASL_SEC_FORWARD_SECRECY;
3434 				break;
3435 
3436 # if _FFR_SASL_OPT_M
3437 /* to be activated in 8.13 */
3438 #  if SASL >= 20101
3439 			  case 'm':
3440 				SASLOpts |= SASL_SEC_MUTUAL_AUTH;
3441 				break;
3442 #  endif /* SASL >= 20101 */
3443 # endif /* _FFR_SASL_OPT_M */
3444 
3445 			  case 'p':
3446 				SASLOpts |= SASL_SEC_NOPLAINTEXT;
3447 				break;
3448 
3449 			  case 'y':
3450 				SASLOpts |= SASL_SEC_NOANONYMOUS;
3451 				break;
3452 
3453 			  case ' ':	/* ignore */
3454 			  case '\t':	/* ignore */
3455 			  case ',':	/* ignore */
3456 				break;
3457 
3458 			  default:
3459 				(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3460 						     "Warning: Option: %s unknown parameter '%c'\n",
3461 						     OPTNAME,
3462 						     (isascii(*val) &&
3463 							isprint(*val))
3464 							? *val : '?');
3465 				break;
3466 			}
3467 			++val;
3468 			val = strpbrk(val, ", \t");
3469 			if (val != NULL)
3470 				++val;
3471 		}
3472 		break;
3473 
3474 	  case O_SASLBITS:
3475 		MaxSLBits = atoi(val);
3476 		break;
3477 
3478 #else /* SASL */
3479 	  case O_SASLINFO:
3480 	  case O_SASLMECH:
3481 	  case O_SASLOPTS:
3482 	  case O_SASLBITS:
3483 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3484 				     "Warning: Option: %s requires SASL support (-DSASL)\n",
3485 				     OPTNAME);
3486 		break;
3487 #endif /* SASL */
3488 
3489 #if STARTTLS
3490 	  case O_SRVCERTFILE:
3491 		SET_STRING_EXP(SrvCertFile);
3492 	  case O_SRVKEYFILE:
3493 		SET_STRING_EXP(SrvKeyFile);
3494 	  case O_CLTCERTFILE:
3495 		SET_STRING_EXP(CltCertFile);
3496 	  case O_CLTKEYFILE:
3497 		SET_STRING_EXP(CltKeyFile);
3498 	  case O_CACERTFILE:
3499 		SET_STRING_EXP(CACertFile);
3500 	  case O_CACERTPATH:
3501 		SET_STRING_EXP(CACertPath);
3502 	  case O_DHPARAMS:
3503 		SET_STRING_EXP(DHParams);
3504 # if _FFR_TLS_1
3505 	  case O_DHPARAMS5:
3506 		SET_STRING_EXP(DHParams5);
3507 	  case O_CIPHERLIST:
3508 		SET_STRING_EXP(CipherList);
3509 # endif /* _FFR_TLS_1 */
3510 
3511 	/*
3512 	**  XXX How about options per daemon/client instead of globally?
3513 	**  This doesn't work well for some options, e.g., no server cert,
3514 	**  but fine for others.
3515 	**
3516 	**  XXX Some people may want different certs per server.
3517 	**
3518 	**  See also srvfeatures()
3519 	*/
3520 
3521 	  case O_TLS_SRV_OPTS:
3522 		while (val != NULL && *val != '\0')
3523 		{
3524 			switch (*val)
3525 			{
3526 			  case 'V':
3527 				TLS_Srv_Opts |= TLS_I_NO_VRFY;
3528 				break;
3529 # if _FFR_TLS_1
3530 			/*
3531 			**  Server without a cert? That works only if
3532 			**  AnonDH is enabled as cipher, which is not in the
3533 			**  default list. Hence the CipherList option must
3534 			**  be available. Moreover: which clients support this
3535 			**  besides sendmail with this setting?
3536 			*/
3537 
3538 			  case 'C':
3539 				TLS_Srv_Opts &= ~TLS_I_SRV_CERT;
3540 				break;
3541 # endif /* _FFR_TLS_1 */
3542 			  case ' ':	/* ignore */
3543 			  case '\t':	/* ignore */
3544 			  case ',':	/* ignore */
3545 				break;
3546 			  default:
3547 				(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3548 						     "Warning: Option: %s unknown parameter '%c'\n",
3549 						     OPTNAME,
3550 						     (isascii(*val) &&
3551 							isprint(*val))
3552 							? *val : '?');
3553 				break;
3554 			}
3555 			++val;
3556 			val = strpbrk(val, ", \t");
3557 			if (val != NULL)
3558 				++val;
3559 		}
3560 		break;
3561 
3562 	  case O_RANDFILE:
3563 		PSTRSET(RandFile, val);
3564 		break;
3565 
3566 #else /* STARTTLS */
3567 	  case O_SRVCERTFILE:
3568 	  case O_SRVKEYFILE:
3569 	  case O_CLTCERTFILE:
3570 	  case O_CLTKEYFILE:
3571 	  case O_CACERTFILE:
3572 	  case O_CACERTPATH:
3573 	  case O_DHPARAMS:
3574 # if _FFR_TLS_1
3575 	  case O_DHPARAMS5:
3576 	  case O_CIPHERLIST:
3577 # endif /* _FFR_TLS_1 */
3578 	  case O_RANDFILE:
3579 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3580 				     "Warning: Option: %s requires TLS support\n",
3581 				     OPTNAME);
3582 		break;
3583 
3584 #endif /* STARTTLS */
3585 
3586 	  case O_CLIENTPORT:
3587 		setclientoptions(val);
3588 		break;
3589 
3590 	  case O_DF_BUFSIZE:
3591 		DataFileBufferSize = atoi(val);
3592 		break;
3593 
3594 	  case O_XF_BUFSIZE:
3595 		XscriptFileBufferSize = atoi(val);
3596 		break;
3597 
3598 	  case O_LDAPDEFAULTSPEC:
3599 #if LDAPMAP
3600 		ldapmap_set_defaults(val);
3601 #else /* LDAPMAP */
3602 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3603 				     "Warning: Option: %s requires LDAP support (-DLDAPMAP)\n",
3604 				     OPTNAME);
3605 #endif /* LDAPMAP */
3606 		break;
3607 
3608 	  case O_INPUTMILTER:
3609 #if MILTER
3610 		InputFilterList = newstr(val);
3611 #else /* MILTER */
3612 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3613 				     "Warning: Option: %s requires Milter support (-DMILTER)\n",
3614 				     OPTNAME);
3615 #endif /* MILTER */
3616 		break;
3617 
3618 	  case O_MILTER:
3619 #if MILTER
3620 		milter_set_option(subopt, val, sticky);
3621 #else /* MILTER */
3622 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3623 				     "Warning: Option: %s requires Milter support (-DMILTER)\n",
3624 				     OPTNAME);
3625 #endif /* MILTER */
3626 		break;
3627 
3628 	  case O_QUEUE_FILE_MODE:	/* queue file mode */
3629 		QueueFileMode = atooct(val) & 0777;
3630 		break;
3631 
3632 	  case O_DLVR_MIN:	/* deliver by minimum time */
3633 		DeliverByMin = convtime(val, 's');
3634 		break;
3635 
3636 	  /* modifiers {daemon_flags} for direct submissions */
3637 	  case O_DIRECTSUBMODIFIERS:
3638 		{
3639 			BITMAP256 m;	/* ignored */
3640 			extern ENVELOPE BlankEnvelope;
3641 
3642 			macdefine(&BlankEnvelope.e_macro, A_PERM,
3643 				  macid("{daemon_flags}"),
3644 				  getmodifiers(val, m));
3645 		}
3646 		break;
3647 
3648 	  case O_FASTSPLIT:
3649 		FastSplit = atoi(val);
3650 		break;
3651 
3652 	  case O_MBDB:
3653 		Mbdb = newstr(val);
3654 		break;
3655 
3656 	  case O_MSQ:
3657 		UseMSP = atobool(val);
3658 		break;
3659 
3660 #if _FFR_SOFT_BOUNCE
3661 	  case O_SOFTBOUNCE:
3662 		SoftBounce = atobool(val);
3663 		break;
3664 #endif /* _FFR_SOFT_BOUNCE */
3665 
3666 #if _FFR_REJECT_LOG
3667 	  case O_REJECTLOGINTERVAL:	/* time btwn log msgs while refusing */
3668 		RejectLogInterval = convtime(val, 'h');
3669 		break;
3670 #endif /* _FFR_REJECT_LOG */
3671 
3672 #if _FFR_REQ_DIR_FSYNC_OPT
3673 	  case O_REQUIRES_DIR_FSYNC:
3674 # if REQUIRES_DIR_FSYNC
3675 		RequiresDirfsync = atobool(val);
3676 # else /* REQUIRES_DIR_FSYNC */
3677 		/* silently ignored... required for cf file option */
3678 # endif /* REQUIRES_DIR_FSYNC */
3679 		break;
3680 #endif /* _FFR_REQ_DIR_FSYNC_OPT */
3681 
3682 	  default:
3683 		if (tTd(37, 1))
3684 		{
3685 			if (isascii(opt) && isprint(opt))
3686 				sm_dprintf("Warning: option %c unknown\n", opt);
3687 			else
3688 				sm_dprintf("Warning: option 0x%x unknown\n", opt);
3689 		}
3690 		break;
3691 	}
3692 
3693 	/*
3694 	**  Options with suboptions are responsible for taking care
3695 	**  of sticky-ness (e.g., that a command line setting is kept
3696 	**  when reading in the sendmail.cf file).  This has to be done
3697 	**  when the suboptions are parsed since each suboption must be
3698 	**  sticky, not the root option.
3699 	*/
3700 
3701 	if (sticky && !bitset(OI_SUBOPT, o->o_flags))
3702 		setbitn(opt, StickyOpt);
3703 }
3704 /*
3705 **  SETCLASS -- set a string into a class
3706 **
3707 **	Parameters:
3708 **		class -- the class to put the string in.
3709 **		str -- the string to enter
3710 **
3711 **	Returns:
3712 **		none.
3713 **
3714 **	Side Effects:
3715 **		puts the word into the symbol table.
3716 */
3717 
3718 void
3719 setclass(class, str)
3720 	int class;
3721 	char *str;
3722 {
3723 	register STAB *s;
3724 
3725 	if ((*str & 0377) == MATCHCLASS)
3726 	{
3727 		int mid;
3728 
3729 		str++;
3730 		mid = macid(str);
3731 		if (mid == 0)
3732 			return;
3733 
3734 		if (tTd(37, 8))
3735 			sm_dprintf("setclass(%s, $=%s)\n",
3736 				   macname(class), macname(mid));
3737 		copy_class(mid, class);
3738 	}
3739 	else
3740 	{
3741 		if (tTd(37, 8))
3742 			sm_dprintf("setclass(%s, %s)\n", macname(class), str);
3743 
3744 		s = stab(str, ST_CLASS, ST_ENTER);
3745 		setbitn(bitidx(class), s->s_class);
3746 	}
3747 }
3748 /*
3749 **  MAKEMAPENTRY -- create a map entry
3750 **
3751 **	Parameters:
3752 **		line -- the config file line
3753 **
3754 **	Returns:
3755 **		A pointer to the map that has been created.
3756 **		NULL if there was a syntax error.
3757 **
3758 **	Side Effects:
3759 **		Enters the map into the dictionary.
3760 */
3761 
3762 MAP *
3763 makemapentry(line)
3764 	char *line;
3765 {
3766 	register char *p;
3767 	char *mapname;
3768 	char *classname;
3769 	register STAB *s;
3770 	STAB *class;
3771 
3772 	for (p = line; isascii(*p) && isspace(*p); p++)
3773 		continue;
3774 	if (!(isascii(*p) && isalnum(*p)))
3775 	{
3776 		syserr("readcf: config K line: no map name");
3777 		return NULL;
3778 	}
3779 
3780 	mapname = p;
3781 	while ((isascii(*++p) && isalnum(*p)) || *p == '_' || *p == '.')
3782 		continue;
3783 	if (*p != '\0')
3784 		*p++ = '\0';
3785 	while (isascii(*p) && isspace(*p))
3786 		p++;
3787 	if (!(isascii(*p) && isalnum(*p)))
3788 	{
3789 		syserr("readcf: config K line, map %s: no map class", mapname);
3790 		return NULL;
3791 	}
3792 	classname = p;
3793 	while (isascii(*++p) && isalnum(*p))
3794 		continue;
3795 	if (*p != '\0')
3796 		*p++ = '\0';
3797 	while (isascii(*p) && isspace(*p))
3798 		p++;
3799 
3800 	/* look up the class */
3801 	class = stab(classname, ST_MAPCLASS, ST_FIND);
3802 	if (class == NULL)
3803 	{
3804 		syserr("readcf: map %s: class %s not available", mapname,
3805 			classname);
3806 		return NULL;
3807 	}
3808 
3809 	/* enter the map */
3810 	s = stab(mapname, ST_MAP, ST_ENTER);
3811 	s->s_map.map_class = &class->s_mapclass;
3812 	s->s_map.map_mname = newstr(mapname);
3813 
3814 	if (class->s_mapclass.map_parse(&s->s_map, p))
3815 		s->s_map.map_mflags |= MF_VALID;
3816 
3817 	if (tTd(37, 5))
3818 	{
3819 		sm_dprintf("map %s, class %s, flags %lx, file %s,\n",
3820 			   s->s_map.map_mname, s->s_map.map_class->map_cname,
3821 			   s->s_map.map_mflags, s->s_map.map_file);
3822 		sm_dprintf("\tapp %s, domain %s, rebuild %s\n",
3823 			   s->s_map.map_app, s->s_map.map_domain,
3824 			   s->s_map.map_rebuild);
3825 	}
3826 	return &s->s_map;
3827 }
3828 /*
3829 **  STRTORWSET -- convert string to rewriting set number
3830 **
3831 **	Parameters:
3832 **		p -- the pointer to the string to decode.
3833 **		endp -- if set, store the trailing delimiter here.
3834 **		stabmode -- ST_ENTER to create this entry, ST_FIND if
3835 **			it must already exist.
3836 **
3837 **	Returns:
3838 **		The appropriate ruleset number.
3839 **		-1 if it is not valid (error already printed)
3840 */
3841 
3842 int
3843 strtorwset(p, endp, stabmode)
3844 	char *p;
3845 	char **endp;
3846 	int stabmode;
3847 {
3848 	int ruleset;
3849 	static int nextruleset = MAXRWSETS;
3850 
3851 	while (isascii(*p) && isspace(*p))
3852 		p++;
3853 	if (!isascii(*p))
3854 	{
3855 		syserr("invalid ruleset name: \"%.20s\"", p);
3856 		return -1;
3857 	}
3858 	if (isdigit(*p))
3859 	{
3860 		ruleset = strtol(p, endp, 10);
3861 		if (ruleset >= MAXRWSETS / 2 || ruleset < 0)
3862 		{
3863 			syserr("bad ruleset %d (%d max)",
3864 				ruleset, MAXRWSETS / 2);
3865 			ruleset = -1;
3866 		}
3867 	}
3868 	else
3869 	{
3870 		STAB *s;
3871 		char delim;
3872 		char *q = NULL;
3873 
3874 		q = p;
3875 		while (*p != '\0' && isascii(*p) &&
3876 		       (isalnum(*p) || *p == '_'))
3877 			p++;
3878 		if (q == p || !(isascii(*q) && isalpha(*q)))
3879 		{
3880 			/* no valid characters */
3881 			syserr("invalid ruleset name: \"%.20s\"", q);
3882 			return -1;
3883 		}
3884 		while (isascii(*p) && isspace(*p))
3885 			*p++ = '\0';
3886 		delim = *p;
3887 		if (delim != '\0')
3888 			*p = '\0';
3889 		s = stab(q, ST_RULESET, stabmode);
3890 		if (delim != '\0')
3891 			*p = delim;
3892 
3893 		if (s == NULL)
3894 			return -1;
3895 
3896 		if (stabmode == ST_ENTER && delim == '=')
3897 		{
3898 			while (isascii(*++p) && isspace(*p))
3899 				continue;
3900 			if (!(isascii(*p) && isdigit(*p)))
3901 			{
3902 				syserr("bad ruleset definition \"%s\" (number required after `=')", q);
3903 				ruleset = -1;
3904 			}
3905 			else
3906 			{
3907 				ruleset = strtol(p, endp, 10);
3908 				if (ruleset >= MAXRWSETS / 2 || ruleset < 0)
3909 				{
3910 					syserr("bad ruleset number %d in \"%s\" (%d max)",
3911 						ruleset, q, MAXRWSETS / 2);
3912 					ruleset = -1;
3913 				}
3914 			}
3915 		}
3916 		else
3917 		{
3918 			if (endp != NULL)
3919 				*endp = p;
3920 			if (s->s_ruleset >= 0)
3921 				ruleset = s->s_ruleset;
3922 			else if ((ruleset = --nextruleset) < MAXRWSETS / 2)
3923 			{
3924 				syserr("%s: too many named rulesets (%d max)",
3925 					q, MAXRWSETS / 2);
3926 				ruleset = -1;
3927 			}
3928 		}
3929 		if (s->s_ruleset >= 0 &&
3930 		    ruleset >= 0 &&
3931 		    ruleset != s->s_ruleset)
3932 		{
3933 			syserr("%s: ruleset changed value (old %d, new %d)",
3934 				q, s->s_ruleset, ruleset);
3935 			ruleset = s->s_ruleset;
3936 		}
3937 		else if (ruleset >= 0)
3938 		{
3939 			s->s_ruleset = ruleset;
3940 		}
3941 		if (stabmode == ST_ENTER && ruleset >= 0)
3942 		{
3943 			char *h = NULL;
3944 
3945 			if (RuleSetNames[ruleset] != NULL)
3946 				sm_free(RuleSetNames[ruleset]); /* XXX */
3947 			if (delim != '\0' && (h = strchr(q, delim)) != NULL)
3948 				*h = '\0';
3949 			RuleSetNames[ruleset] = newstr(q);
3950 			if (delim == '/' && h != NULL)
3951 				*h = delim;	/* put back delim */
3952 		}
3953 	}
3954 	return ruleset;
3955 }
3956 /*
3957 **  SETTIMEOUT -- set an individual timeout
3958 **
3959 **	Parameters:
3960 **		name -- the name of the timeout.
3961 **		val -- the value of the timeout.
3962 **		sticky -- if set, don't let other setoptions override
3963 **			this value.
3964 **
3965 **	Returns:
3966 **		none.
3967 */
3968 
3969 /* set if Timeout sub-option is stuck */
3970 static BITMAP256	StickyTimeoutOpt;
3971 
3972 static struct timeoutinfo
3973 {
3974 	char		*to_name;	/* long name of timeout */
3975 	unsigned char	to_code;	/* code for option */
3976 } TimeOutTab[] =
3977 {
3978 #define TO_INITIAL			0x01
3979 	{ "initial",			TO_INITIAL			},
3980 #define TO_MAIL				0x02
3981 	{ "mail",			TO_MAIL				},
3982 #define TO_RCPT				0x03
3983 	{ "rcpt",			TO_RCPT				},
3984 #define TO_DATAINIT			0x04
3985 	{ "datainit",			TO_DATAINIT			},
3986 #define TO_DATABLOCK			0x05
3987 	{ "datablock",			TO_DATABLOCK			},
3988 #define TO_DATAFINAL			0x06
3989 	{ "datafinal",			TO_DATAFINAL			},
3990 #define TO_COMMAND			0x07
3991 	{ "command",			TO_COMMAND			},
3992 #define TO_RSET				0x08
3993 	{ "rset",			TO_RSET				},
3994 #define TO_HELO				0x09
3995 	{ "helo",			TO_HELO				},
3996 #define TO_QUIT				0x0A
3997 	{ "quit",			TO_QUIT				},
3998 #define TO_MISC				0x0B
3999 	{ "misc",			TO_MISC				},
4000 #define TO_IDENT			0x0C
4001 	{ "ident",			TO_IDENT			},
4002 #define TO_FILEOPEN			0x0D
4003 	{ "fileopen",			TO_FILEOPEN			},
4004 #define TO_CONNECT			0x0E
4005 	{ "connect",			TO_CONNECT			},
4006 #define TO_ICONNECT			0x0F
4007 	{ "iconnect",			TO_ICONNECT			},
4008 #define TO_QUEUEWARN			0x10
4009 	{ "queuewarn",			TO_QUEUEWARN			},
4010 	{ "queuewarn.*",		TO_QUEUEWARN			},
4011 #define TO_QUEUEWARN_NORMAL		0x11
4012 	{ "queuewarn.normal",		TO_QUEUEWARN_NORMAL		},
4013 #define TO_QUEUEWARN_URGENT		0x12
4014 	{ "queuewarn.urgent",		TO_QUEUEWARN_URGENT		},
4015 #define TO_QUEUEWARN_NON_URGENT		0x13
4016 	{ "queuewarn.non-urgent",	TO_QUEUEWARN_NON_URGENT		},
4017 #define TO_QUEUERETURN			0x14
4018 	{ "queuereturn",		TO_QUEUERETURN			},
4019 	{ "queuereturn.*",		TO_QUEUERETURN			},
4020 #define TO_QUEUERETURN_NORMAL		0x15
4021 	{ "queuereturn.normal",		TO_QUEUERETURN_NORMAL		},
4022 #define TO_QUEUERETURN_URGENT		0x16
4023 	{ "queuereturn.urgent",		TO_QUEUERETURN_URGENT		},
4024 #define TO_QUEUERETURN_NON_URGENT	0x17
4025 	{ "queuereturn.non-urgent",	TO_QUEUERETURN_NON_URGENT	},
4026 #define TO_HOSTSTATUS			0x18
4027 	{ "hoststatus",			TO_HOSTSTATUS			},
4028 #define TO_RESOLVER_RETRANS		0x19
4029 	{ "resolver.retrans",		TO_RESOLVER_RETRANS		},
4030 #define TO_RESOLVER_RETRANS_NORMAL	0x1A
4031 	{ "resolver.retrans.normal",	TO_RESOLVER_RETRANS_NORMAL	},
4032 #define TO_RESOLVER_RETRANS_FIRST	0x1B
4033 	{ "resolver.retrans.first",	TO_RESOLVER_RETRANS_FIRST	},
4034 #define TO_RESOLVER_RETRY		0x1C
4035 	{ "resolver.retry",		TO_RESOLVER_RETRY		},
4036 #define TO_RESOLVER_RETRY_NORMAL	0x1D
4037 	{ "resolver.retry.normal",	TO_RESOLVER_RETRY_NORMAL	},
4038 #define TO_RESOLVER_RETRY_FIRST		0x1E
4039 	{ "resolver.retry.first",	TO_RESOLVER_RETRY_FIRST		},
4040 #define TO_CONTROL			0x1F
4041 	{ "control",			TO_CONTROL			},
4042 #define TO_LHLO				0x20
4043 	{ "lhlo",			TO_LHLO				},
4044 #define TO_AUTH				0x21
4045 	{ "auth",			TO_AUTH				},
4046 #define TO_STARTTLS			0x22
4047 	{ "starttls",			TO_STARTTLS			},
4048 #define TO_ACONNECT			0x23
4049 	{ "aconnect",			TO_ACONNECT			},
4050 #if _FFR_QUEUERETURN_DSN
4051 # define TO_QUEUEWARN_DSN		0x24
4052 	{ "queuewarn.dsn",		TO_QUEUEWARN_DSN		},
4053 # define TO_QUEUERETURN_DSN		0x25
4054 	{ "queuereturn.dsn",		TO_QUEUERETURN_DSN		},
4055 #endif /* _FFR_QUEUERETURN_DSN */
4056 	{ NULL,				0				},
4057 };
4058 
4059 
4060 static void
4061 settimeout(name, val, sticky)
4062 	char *name;
4063 	char *val;
4064 	bool sticky;
4065 {
4066 	register struct timeoutinfo *to;
4067 	int i, addopts;
4068 	time_t toval;
4069 
4070 	if (tTd(37, 2))
4071 		sm_dprintf("settimeout(%s = %s)", name, val);
4072 
4073 	for (to = TimeOutTab; to->to_name != NULL; to++)
4074 	{
4075 		if (sm_strcasecmp(to->to_name, name) == 0)
4076 			break;
4077 	}
4078 
4079 	if (to->to_name == NULL)
4080 	{
4081 		errno = 0; /* avoid bogus error text */
4082 		syserr("settimeout: invalid timeout %s", name);
4083 		return;
4084 	}
4085 
4086 	/*
4087 	**  See if this option is preset for us.
4088 	*/
4089 
4090 	if (!sticky && bitnset(to->to_code, StickyTimeoutOpt))
4091 	{
4092 		if (tTd(37, 2))
4093 			sm_dprintf(" (ignored)\n");
4094 		return;
4095 	}
4096 
4097 	if (tTd(37, 2))
4098 		sm_dprintf("\n");
4099 
4100 	toval = convtime(val, 'm');
4101 	addopts = 0;
4102 
4103 	switch (to->to_code)
4104 	{
4105 	  case TO_INITIAL:
4106 		TimeOuts.to_initial = toval;
4107 		break;
4108 
4109 	  case TO_MAIL:
4110 		TimeOuts.to_mail = toval;
4111 		break;
4112 
4113 	  case TO_RCPT:
4114 		TimeOuts.to_rcpt = toval;
4115 		break;
4116 
4117 	  case TO_DATAINIT:
4118 		TimeOuts.to_datainit = toval;
4119 		break;
4120 
4121 	  case TO_DATABLOCK:
4122 		TimeOuts.to_datablock = toval;
4123 		break;
4124 
4125 	  case TO_DATAFINAL:
4126 		TimeOuts.to_datafinal = toval;
4127 		break;
4128 
4129 	  case TO_COMMAND:
4130 		TimeOuts.to_nextcommand = toval;
4131 		break;
4132 
4133 	  case TO_RSET:
4134 		TimeOuts.to_rset = toval;
4135 		break;
4136 
4137 	  case TO_HELO:
4138 		TimeOuts.to_helo = toval;
4139 		break;
4140 
4141 	  case TO_QUIT:
4142 		TimeOuts.to_quit = toval;
4143 		break;
4144 
4145 	  case TO_MISC:
4146 		TimeOuts.to_miscshort = toval;
4147 		break;
4148 
4149 	  case TO_IDENT:
4150 		TimeOuts.to_ident = toval;
4151 		break;
4152 
4153 	  case TO_FILEOPEN:
4154 		TimeOuts.to_fileopen = toval;
4155 		break;
4156 
4157 	  case TO_CONNECT:
4158 		TimeOuts.to_connect = toval;
4159 		break;
4160 
4161 	  case TO_ICONNECT:
4162 		TimeOuts.to_iconnect = toval;
4163 		break;
4164 
4165 	  case TO_ACONNECT:
4166 		TimeOuts.to_aconnect = toval;
4167 		break;
4168 
4169 	  case TO_QUEUEWARN:
4170 		toval = convtime(val, 'h');
4171 		TimeOuts.to_q_warning[TOC_NORMAL] = toval;
4172 		TimeOuts.to_q_warning[TOC_URGENT] = toval;
4173 		TimeOuts.to_q_warning[TOC_NONURGENT] = toval;
4174 #if _FFR_QUEUERETURN_DSN
4175 		TimeOuts.to_q_warning[TOC_DSN] = toval;
4176 #endif /* _FFR_QUEUERETURN_DSN */
4177 		addopts = 2;
4178 		break;
4179 
4180 	  case TO_QUEUEWARN_NORMAL:
4181 		toval = convtime(val, 'h');
4182 		TimeOuts.to_q_warning[TOC_NORMAL] = toval;
4183 		break;
4184 
4185 	  case TO_QUEUEWARN_URGENT:
4186 		toval = convtime(val, 'h');
4187 		TimeOuts.to_q_warning[TOC_URGENT] = toval;
4188 		break;
4189 
4190 	  case TO_QUEUEWARN_NON_URGENT:
4191 		toval = convtime(val, 'h');
4192 		TimeOuts.to_q_warning[TOC_NONURGENT] = toval;
4193 		break;
4194 
4195 #if _FFR_QUEUERETURN_DSN
4196 	  case TO_QUEUEWARN_DSN:
4197 		toval = convtime(val, 'h');
4198 		TimeOuts.to_q_warning[TOC_DSN] = toval;
4199 		break;
4200 #endif /* _FFR_QUEUERETURN_DSN */
4201 
4202 	  case TO_QUEUERETURN:
4203 		toval = convtime(val, 'd');
4204 		TimeOuts.to_q_return[TOC_NORMAL] = toval;
4205 		TimeOuts.to_q_return[TOC_URGENT] = toval;
4206 		TimeOuts.to_q_return[TOC_NONURGENT] = toval;
4207 #if _FFR_QUEUERETURN_DSN
4208 		TimeOuts.to_q_return[TOC_DSN] = toval;
4209 #endif /* _FFR_QUEUERETURN_DSN */
4210 		addopts = 2;
4211 		break;
4212 
4213 	  case TO_QUEUERETURN_NORMAL:
4214 		toval = convtime(val, 'd');
4215 		TimeOuts.to_q_return[TOC_NORMAL] = toval;
4216 		break;
4217 
4218 	  case TO_QUEUERETURN_URGENT:
4219 		toval = convtime(val, 'd');
4220 		TimeOuts.to_q_return[TOC_URGENT] = toval;
4221 		break;
4222 
4223 	  case TO_QUEUERETURN_NON_URGENT:
4224 		toval = convtime(val, 'd');
4225 		TimeOuts.to_q_return[TOC_NONURGENT] = toval;
4226 		break;
4227 
4228 #if _FFR_QUEUERETURN_DSN
4229 	  case TO_QUEUERETURN_DSN:
4230 		toval = convtime(val, 'd');
4231 		TimeOuts.to_q_return[TOC_DSN] = toval;
4232 		break;
4233 #endif /* _FFR_QUEUERETURN_DSN */
4234 
4235 	  case TO_HOSTSTATUS:
4236 		MciInfoTimeout = toval;
4237 		break;
4238 
4239 	  case TO_RESOLVER_RETRANS:
4240 		toval = convtime(val, 's');
4241 		TimeOuts.res_retrans[RES_TO_DEFAULT] = toval;
4242 		TimeOuts.res_retrans[RES_TO_FIRST] = toval;
4243 		TimeOuts.res_retrans[RES_TO_NORMAL] = toval;
4244 		addopts = 2;
4245 		break;
4246 
4247 	  case TO_RESOLVER_RETRY:
4248 		i = atoi(val);
4249 		TimeOuts.res_retry[RES_TO_DEFAULT] = i;
4250 		TimeOuts.res_retry[RES_TO_FIRST] = i;
4251 		TimeOuts.res_retry[RES_TO_NORMAL] = i;
4252 		addopts = 2;
4253 		break;
4254 
4255 	  case TO_RESOLVER_RETRANS_NORMAL:
4256 		TimeOuts.res_retrans[RES_TO_NORMAL] = convtime(val, 's');
4257 		break;
4258 
4259 	  case TO_RESOLVER_RETRY_NORMAL:
4260 		TimeOuts.res_retry[RES_TO_NORMAL] = atoi(val);
4261 		break;
4262 
4263 	  case TO_RESOLVER_RETRANS_FIRST:
4264 		TimeOuts.res_retrans[RES_TO_FIRST] = convtime(val, 's');
4265 		break;
4266 
4267 	  case TO_RESOLVER_RETRY_FIRST:
4268 		TimeOuts.res_retry[RES_TO_FIRST] = atoi(val);
4269 		break;
4270 
4271 	  case TO_CONTROL:
4272 		TimeOuts.to_control = toval;
4273 		break;
4274 
4275 	  case TO_LHLO:
4276 		TimeOuts.to_lhlo = toval;
4277 		break;
4278 
4279 #if SASL
4280 	  case TO_AUTH:
4281 		TimeOuts.to_auth = toval;
4282 		break;
4283 #endif /* SASL */
4284 
4285 #if STARTTLS
4286 	  case TO_STARTTLS:
4287 		TimeOuts.to_starttls = toval;
4288 		break;
4289 #endif /* STARTTLS */
4290 
4291 	  default:
4292 		syserr("settimeout: invalid timeout %s", name);
4293 		break;
4294 	}
4295 
4296 	if (sticky)
4297 	{
4298 		for (i = 0; i <= addopts; i++)
4299 			setbitn(to->to_code + i, StickyTimeoutOpt);
4300 	}
4301 }
4302 /*
4303 **  INITTIMEOUTS -- parse and set timeout values
4304 **
4305 **	Parameters:
4306 **		val -- a pointer to the values.  If NULL, do initial
4307 **			settings.
4308 **		sticky -- if set, don't let other setoptions override
4309 **			this suboption value.
4310 **
4311 **	Returns:
4312 **		none.
4313 **
4314 **	Side Effects:
4315 **		Initializes the TimeOuts structure
4316 */
4317 
4318 void
4319 inittimeouts(val, sticky)
4320 	register char *val;
4321 	bool sticky;
4322 {
4323 	register char *p;
4324 
4325 	if (tTd(37, 2))
4326 		sm_dprintf("inittimeouts(%s)\n", val == NULL ? "<NULL>" : val);
4327 	if (val == NULL)
4328 	{
4329 		TimeOuts.to_connect = (time_t) 0 SECONDS;
4330 		TimeOuts.to_aconnect = (time_t) 0 SECONDS;
4331 		TimeOuts.to_iconnect = (time_t) 0 SECONDS;
4332 		TimeOuts.to_initial = (time_t) 5 MINUTES;
4333 		TimeOuts.to_helo = (time_t) 5 MINUTES;
4334 		TimeOuts.to_mail = (time_t) 10 MINUTES;
4335 		TimeOuts.to_rcpt = (time_t) 1 HOUR;
4336 		TimeOuts.to_datainit = (time_t) 5 MINUTES;
4337 		TimeOuts.to_datablock = (time_t) 1 HOUR;
4338 		TimeOuts.to_datafinal = (time_t) 1 HOUR;
4339 		TimeOuts.to_rset = (time_t) 5 MINUTES;
4340 		TimeOuts.to_quit = (time_t) 2 MINUTES;
4341 		TimeOuts.to_nextcommand = (time_t) 1 HOUR;
4342 		TimeOuts.to_miscshort = (time_t) 2 MINUTES;
4343 #if IDENTPROTO
4344 		TimeOuts.to_ident = (time_t) 5 SECONDS;
4345 #else /* IDENTPROTO */
4346 		TimeOuts.to_ident = (time_t) 0 SECONDS;
4347 #endif /* IDENTPROTO */
4348 		TimeOuts.to_fileopen = (time_t) 60 SECONDS;
4349 		TimeOuts.to_control = (time_t) 2 MINUTES;
4350 		TimeOuts.to_lhlo = (time_t) 2 MINUTES;
4351 #if SASL
4352 		TimeOuts.to_auth = (time_t) 10 MINUTES;
4353 #endif /* SASL */
4354 #if STARTTLS
4355 		TimeOuts.to_starttls = (time_t) 1 HOUR;
4356 #endif /* STARTTLS */
4357 		if (tTd(37, 5))
4358 		{
4359 			sm_dprintf("Timeouts:\n");
4360 			sm_dprintf("  connect = %ld\n",
4361 				   (long) TimeOuts.to_connect);
4362 			sm_dprintf("  aconnect = %ld\n",
4363 				   (long) TimeOuts.to_aconnect);
4364 			sm_dprintf("  initial = %ld\n",
4365 				   (long) TimeOuts.to_initial);
4366 			sm_dprintf("  helo = %ld\n", (long) TimeOuts.to_helo);
4367 			sm_dprintf("  mail = %ld\n", (long) TimeOuts.to_mail);
4368 			sm_dprintf("  rcpt = %ld\n", (long) TimeOuts.to_rcpt);
4369 			sm_dprintf("  datainit = %ld\n",
4370 				   (long) TimeOuts.to_datainit);
4371 			sm_dprintf("  datablock = %ld\n",
4372 				   (long) TimeOuts.to_datablock);
4373 			sm_dprintf("  datafinal = %ld\n",
4374 				   (long) TimeOuts.to_datafinal);
4375 			sm_dprintf("  rset = %ld\n", (long) TimeOuts.to_rset);
4376 			sm_dprintf("  quit = %ld\n", (long) TimeOuts.to_quit);
4377 			sm_dprintf("  nextcommand = %ld\n",
4378 				   (long) TimeOuts.to_nextcommand);
4379 			sm_dprintf("  miscshort = %ld\n",
4380 				   (long) TimeOuts.to_miscshort);
4381 			sm_dprintf("  ident = %ld\n", (long) TimeOuts.to_ident);
4382 			sm_dprintf("  fileopen = %ld\n",
4383 				   (long) TimeOuts.to_fileopen);
4384 			sm_dprintf("  lhlo = %ld\n",
4385 				   (long) TimeOuts.to_lhlo);
4386 			sm_dprintf("  control = %ld\n",
4387 				   (long) TimeOuts.to_control);
4388 		}
4389 		return;
4390 	}
4391 
4392 	for (;; val = p)
4393 	{
4394 		while (isascii(*val) && isspace(*val))
4395 			val++;
4396 		if (*val == '\0')
4397 			break;
4398 		for (p = val; *p != '\0' && *p != ','; p++)
4399 			continue;
4400 		if (*p != '\0')
4401 			*p++ = '\0';
4402 
4403 		if (isascii(*val) && isdigit(*val))
4404 		{
4405 			/* old syntax -- set everything */
4406 			TimeOuts.to_mail = convtime(val, 'm');
4407 			TimeOuts.to_rcpt = TimeOuts.to_mail;
4408 			TimeOuts.to_datainit = TimeOuts.to_mail;
4409 			TimeOuts.to_datablock = TimeOuts.to_mail;
4410 			TimeOuts.to_datafinal = TimeOuts.to_mail;
4411 			TimeOuts.to_nextcommand = TimeOuts.to_mail;
4412 			if (sticky)
4413 			{
4414 				setbitn(TO_MAIL, StickyTimeoutOpt);
4415 				setbitn(TO_RCPT, StickyTimeoutOpt);
4416 				setbitn(TO_DATAINIT, StickyTimeoutOpt);
4417 				setbitn(TO_DATABLOCK, StickyTimeoutOpt);
4418 				setbitn(TO_DATAFINAL, StickyTimeoutOpt);
4419 				setbitn(TO_COMMAND, StickyTimeoutOpt);
4420 			}
4421 			continue;
4422 		}
4423 		else
4424 		{
4425 			register char *q = strchr(val, ':');
4426 
4427 			if (q == NULL && (q = strchr(val, '=')) == NULL)
4428 			{
4429 				/* syntax error */
4430 				continue;
4431 			}
4432 			*q++ = '\0';
4433 			settimeout(val, q, sticky);
4434 		}
4435 	}
4436 }
4437