1 /* $NetBSD: sendmail.c,v 1.6 2026/05/09 18:49:20 christos Exp $ */ 2 3 /*++ 4 /* NAME 5 /* sendmail 1 6 /* SUMMARY 7 /* Postfix to Sendmail compatibility interface 8 /* SYNOPSIS 9 /* \fBsendmail\fR [\fIoption ...\fR] [\fIrecipient ...\fR] 10 /* 11 /* \fBmailq\fR 12 /* \fBsendmail -bp\fR 13 /* 14 /* \fBnewaliases\fR 15 /* \fBsendmail -I\fR 16 /* DESCRIPTION 17 /* The Postfix \fBsendmail\fR(1) command implements the Postfix 18 /* to Sendmail compatibility interface. 19 /* For the sake of compatibility with existing applications, some 20 /* Sendmail command-line options are recognized but silently ignored. 21 /* 22 /* By default, Postfix \fBsendmail\fR(1) reads a message from 23 /* standard input 24 /* until EOF or until it reads a line with only a \fB.\fR character, 25 /* and arranges for delivery. Postfix \fBsendmail\fR(1) relies on the 26 /* \fBpostdrop\fR(1) command to create a queue file in the \fBmaildrop\fR 27 /* directory. 28 /* 29 /* Specific command aliases are provided for other common modes of 30 /* operation: 31 /* .IP \fBmailq\fR 32 /* List the mail queue. Each entry shows the queue file ID, message 33 /* size, arrival time, sender, and the recipients that still need to 34 /* be delivered. If mail could not be delivered upon the last attempt, 35 /* the reason for failure is shown. The queue ID string is 36 /* followed by an optional status character: 37 /* .RS 38 /* .IP \fB*\fR 39 /* The message is in the \fBactive\fR queue, i.e. the message is 40 /* selected for delivery. 41 /* .IP \fB!\fR 42 /* The message is in the \fBhold\fR queue, i.e. no further delivery 43 /* attempt will be made until the mail is taken off hold. 44 /* .IP \fB#\fR 45 /* The message is forced to expire. See the \fBpostsuper\fR(1) 46 /* options \fB-e\fR or \fB-f\fR. 47 /* .RE 48 /* .IP 49 /* This mode of operation is implemented by executing the 50 /* \fBpostqueue\fR(1) command. 51 /* .IP \fBnewaliases\fR 52 /* Initialize the alias database. If no input file is specified (with 53 /* the \fB-oA\fR option, see below), the program processes the file(s) 54 /* specified with the \fBalias_database\fR configuration parameter. 55 /* If no alias database type is specified, the program uses the type 56 /* specified with the \fBdefault_database_type\fR configuration parameter. 57 /* This mode of operation is implemented by running the \fBpostalias\fR(1) 58 /* command. 59 /* .sp 60 /* Note: it may take a minute or so before an alias database update 61 /* becomes visible. Use the "\fBpostfix reload\fR" command to eliminate 62 /* this delay. 63 /* .PP 64 /* These and other features can be selected by specifying the 65 /* appropriate combination of command-line options. Some features are 66 /* controlled by parameters in the \fBmain.cf\fR configuration file. 67 /* 68 /* The following options are recognized: 69 /* .IP "\fB-Am\fR (ignored)" 70 /* .IP "\fB-Ac\fR (ignored)" 71 /* Postfix sendmail uses the same configuration file regardless of 72 /* whether or not a message is an initial submission. 73 /* .IP "\fB-B \fIbody_type\fR" 74 /* The message body MIME type: \fB7BIT\fR or \fB8BITMIME\fR. 75 /* .IP \fB-bd\fR 76 /* Go into daemon mode. This mode of operation is implemented by 77 /* executing the "\fBpostfix start\fR" command. 78 /* .IP "\fB-bh\fR (ignored)" 79 /* .IP "\fB-bH\fR (ignored)" 80 /* Postfix has no persistent host status database. 81 /* .IP \fB-bi\fR 82 /* Initialize alias database. See the \fBnewaliases\fR 83 /* command above. 84 /* .IP \fB-bl\fR 85 /* Go into daemon mode. To accept only local connections as 86 /* with Sendmail's \fB-bl\fR option, specify "\fBinet_interfaces 87 /* = loopback\fR" in the Postfix \fBmain.cf\fR configuration 88 /* file. 89 /* .IP \fB-bm\fR 90 /* Read mail from standard input and arrange for delivery. 91 /* This is the default mode of operation. 92 /* .IP \fB-bp\fR 93 /* List the mail queue. See the \fBmailq\fR command above. 94 /* .IP \fB-bs\fR 95 /* Stand-alone SMTP server mode. Read SMTP commands from 96 /* standard input, and write responses to standard output. 97 /* In stand-alone SMTP server mode, mail relaying and other 98 /* access controls are disabled by default. To enable them, 99 /* run the process as the \fBmail_owner\fR user. 100 /* .sp 101 /* This mode of operation is implemented by running the 102 /* \fBsmtpd\fR(8) daemon. 103 /* .IP \fB-bv\fR 104 /* Do not collect or deliver a message. Instead, send an email 105 /* report after verifying each recipient address. This is useful 106 /* for testing address rewriting and routing configurations. 107 /* .sp 108 /* This feature is available in Postfix version 2.1 and later. 109 /* .IP "\fB-C \fIconfig_file\fR" 110 /* .IP "\fB-C \fIconfig_dir\fR" 111 /* The path name of the Postfix \fBmain.cf\fR file, or of its 112 /* parent directory. This information is ignored with Postfix 113 /* versions before 2.3. 114 /* 115 /* With Postfix version 3.2 and later, a non-default directory 116 /* must be authorized in the default \fBmain.cf\fR file, through 117 /* the alternate_config_directories or multi_instance_directories 118 /* parameters. 119 /* 120 /* With all Postfix versions, you can specify a directory pathname 121 /* with the MAIL_CONFIG environment variable to override the 122 /* location of configuration files. 123 /* .IP "\fB-F \fIfull_name\fR" 124 /* Set the sender full name. This overrides the NAME environment 125 /* variable, and is used only with messages that 126 /* have no \fBFrom:\fR message header. 127 /* .IP "\fB-f \fIsender\fR" 128 /* Set the envelope sender address. This is the address where 129 /* delivery problems are sent to. With Postfix versions before 2.1, the 130 /* \fBErrors-To:\fR message header overrides the error return address. 131 /* .IP \fB-G\fR 132 /* Gateway (relay) submission, as opposed to initial user 133 /* submission. Either do not rewrite addresses at all, or 134 /* update incomplete addresses with the domain information 135 /* specified with \fBremote_header_rewrite_domain\fR. 136 /* 137 /* This option is ignored before Postfix version 2.3. 138 /* .IP "\fB-h \fIhop_count\fR (ignored)" 139 /* Hop count limit. Use the \fBhopcount_limit\fR configuration 140 /* parameter instead. 141 /* .IP \fB-I\fR 142 /* Initialize alias database. See the \fBnewaliases\fR 143 /* command above. 144 /* .IP "\fB-i\fR" 145 /* When reading a message from standard input, don't treat a line 146 /* with only a \fB.\fR character as the end of input. 147 /* .IP "\fB-L \fIlabel\fR (ignored)" 148 /* The logging label. Use the \fBsyslog_name\fR configuration 149 /* parameter instead. 150 /* .IP "\fB-m\fR (ignored)" 151 /* Backwards compatibility. 152 /* .IP "\fB-N \fIdsn\fR (default: 'delay, failure')" 153 /* Delivery status notification control. Specify either a 154 /* comma-separated list with one or more of \fBfailure\fR (send 155 /* notification when delivery fails), \fBdelay\fR (send 156 /* notification when delivery is delayed), or \fBsuccess\fR 157 /* (send notification when the message is delivered); or specify 158 /* \fBnever\fR (don't send any notifications at all). 159 /* 160 /* This feature is available in Postfix 2.3 and later. 161 /* .IP "\fB-n\fR (ignored)" 162 /* Backwards compatibility. 163 /* .IP "\fB-O requiretls=yes\fR" 164 /* .IP "\fB-O requiretls=no\fR" 165 /* When delivering a message to an SMTP or LMTP server, the 166 /* connection must use TLS with a verified server certificate, 167 /* and that server must support REQUIRETLS. The "requiretls" name 168 /* and option value are case-insensitive. REQUIRETLS enforcement 169 /* is controlled with the configuration parameters requiretls_enable, 170 /* smtp_requiretls_policy, and lmtp_requiretls_policy. 171 /* 172 /* This feature is available in Postfix 3.11 and later. 173 /* .IP "\fB-O smtputf8=yes\fR" 174 /* .IP "\fB-O smtputf8=no\fR" 175 /* When delivering a message to an SMTP or LMTP server, and an 176 /* envelope address or message header contains UTF8 text, that server 177 /* must support SMTPUTF8. The "smtputf8" option name and value 178 /* are case-insensitive. 179 /* 180 /* This feature is available in Postfix 3.11 and later. 181 /* .IP "\fB-O \fIoption=value\fR (ignored)" 182 /* Set the named \fIoption\fR to \fIvalue\fR. Use the equivalent 183 /* configuration parameter in \fBmain.cf\fR instead. 184 /* .IP "\fB-oA\fIalias_database\fR" 185 /* Non-default alias database. Specify \fIpathname\fR or 186 /* \fItype\fR:\fIpathname\fR. See \fBpostalias\fR(1) for details. 187 /* .IP "\fB-o7\fR (ignored)" 188 /* .IP "\fB-o8\fR (ignored)" 189 /* To send 8-bit or binary content, use an appropriate MIME encapsulation 190 /* and specify the appropriate \fB-B\fR command-line option. 191 /* .IP "\fB-oi\fR" 192 /* When reading a message from standard input, don't treat a line 193 /* with only a \fB.\fR character as the end of input. 194 /* .IP "\fB-om\fR (ignored)" 195 /* The sender is never eliminated from alias etc. expansions. 196 /* .IP "\fB-o \fIx value\fR (ignored)" 197 /* Set option \fIx\fR to \fIvalue\fR. Use the equivalent 198 /* configuration parameter in \fBmain.cf\fR instead. 199 /* .IP "\fB-r \fIsender\fR" 200 /* Set the envelope sender address. This is the address where 201 /* delivery problems are sent to. With Postfix versions before 2.1, the 202 /* \fBErrors-To:\fR message header overrides the error return address. 203 /* .IP "\fB-R \fIreturn\fR" 204 /* Delivery status notification control. Specify "hdrs" to 205 /* return only the header when a message bounces, "full" to 206 /* return a full copy (the default behavior). 207 /* 208 /* The \fB-R\fR option specifies an upper bound; Postfix will 209 /* return only the header, when a full copy would exceed the 210 /* bounce_size_limit setting. 211 /* 212 /* This option is ignored before Postfix version 2.10. 213 /* .IP \fB-q\fR 214 /* Attempt to deliver all queued mail. This is implemented by 215 /* executing the \fBpostqueue\fR(1) command. 216 /* 217 /* Warning: flushing undeliverable mail frequently will result in 218 /* poor delivery performance of all other mail. 219 /* .IP "\fB-q\fIinterval\fR (ignored)" 220 /* The interval between queue runs. Use the \fBqueue_run_delay\fR 221 /* configuration parameter instead. 222 /* .IP \fB-qI\fIqueueid\fR 223 /* Schedule immediate delivery of mail with the specified queue 224 /* ID. This option is implemented by executing the 225 /* \fBpostqueue\fR(1) command, and is available with Postfix 226 /* version 2.4 and later. 227 /* .IP \fB-qR\fIsite\fR 228 /* Schedule immediate delivery of all mail that is queued for the named 229 /* \fIsite\fR. This option accepts only \fIsite\fR names that are 230 /* eligible for the "fast flush" service, and is implemented by 231 /* executing the \fBpostqueue\fR(1) command. 232 /* See \fBflush\fR(8) for more information about the "fast flush" 233 /* service. 234 /* .IP \fB-qS\fIsite\fR 235 /* This command is not implemented. Use the slower "\fBsendmail -q\fR" 236 /* command instead. 237 /* .IP \fB-t\fR 238 /* Extract recipients from message headers. These are added to any 239 /* recipients specified on the command line. 240 /* 241 /* With Postfix versions prior to 2.1, this option requires that 242 /* no recipient addresses are specified on the command line. 243 /* .IP "\fB-U\fR (ignored)" 244 /* Initial user submission. 245 /* .IP "\fB-V \fIenvid\fR" 246 /* Specify the envelope ID for notification by servers that 247 /* support DSN. 248 /* 249 /* This feature is available in Postfix 2.3 and later. 250 /* .IP "\fB-XV\fR (Postfix 2.2 and earlier: \fB-V\fR)" 251 /* Variable Envelope Return Path. Given an envelope sender address 252 /* of the form \fIowner-listname\fR@\fIorigin\fR, each recipient 253 /* \fIuser\fR@\fIdomain\fR receives mail with a personalized envelope 254 /* sender address. 255 /* .sp 256 /* By default, the personalized envelope sender address is 257 /* \fIowner-listname\fB+\fIuser\fB=\fIdomain\fR@\fIorigin\fR. The default 258 /* \fB+\fR and \fB=\fR characters are configurable with the 259 /* \fBdefault_verp_delimiters\fR configuration parameter. 260 /* .IP "\fB-XV\fIxy\fR (Postfix 2.2 and earlier: \fB-V\fIxy\fR)" 261 /* As \fB-XV\fR, but uses \fIx\fR and \fIy\fR as the VERP delimiter 262 /* characters, instead of the characters specified with the 263 /* \fBdefault_verp_delimiters\fR configuration parameter. 264 /* .IP \fB-v\fR 265 /* Send an email report of the first delivery attempt (Postfix 266 /* versions 2.1 and later). Mail delivery 267 /* always happens in the background. When multiple \fB-v\fR 268 /* options are given, enable verbose logging for debugging purposes. 269 /* .IP "\fB-X \fIlog_file\fR (ignored)" 270 /* Log mailer traffic. Use the \fBdebug_peer_list\fR and 271 /* \fBdebug_peer_level\fR configuration parameters instead. 272 /* SECURITY 273 /* .ad 274 /* .fi 275 /* By design, this program is not set-user (or group) id. 276 /* It is prepared to handle message content from untrusted, 277 /* possibly remote, users. 278 /* 279 /* However, like most Postfix programs, this program does not 280 /* enforce a security policy on its command-line arguments. 281 /* Instead, it relies on the UNIX system to enforce access 282 /* policies based on the effective user and group IDs of the 283 /* process. Concretely, this means that running Postfix commands 284 /* as root (from sudo or equivalent) on behalf of a non-root 285 /* user is likely to create privilege escalation opportunities. 286 /* 287 /* If an application runs any Postfix programs on behalf of 288 /* users that do not have normal shell access to Postfix 289 /* commands, then that application MUST restrict user-specified 290 /* command-line arguments to avoid privilege escalation. 291 /* .IP \(bu 292 /* Filter all command-line arguments, for example arguments 293 /* that contain a pathname or that specify a database access 294 /* method. These pathname checks must reject user-controlled 295 /* symlinks or hardlinks to sensitive files, and must not be 296 /* vulnerable to TOCTOU race attacks. 297 /* .IP \(bu 298 /* Disable command options processing for all command arguments 299 /* that contain user-specified data. For example, the Postfix 300 /* \fBsendmail\fR(1) command line MUST be structured as follows: 301 /* 302 /* .nf 303 /* \fB/path/to/sendmail\fR \fIsystem-arguments\fR \fB--\fR \fIuser-arguments\fR 304 /* .fi 305 /* 306 /* Here, the "\fB--\fR" disables command option processing for 307 /* all \fIuser-arguments\fR that follow. 308 /* .IP 309 /* Without the "\fB--\fR", a malicious user could enable Postfix 310 /* \fBsendmail\fR(1) command options, by specifying an email 311 /* address that starts with "\fB-\fR". 312 /* DIAGNOSTICS 313 /* Problems are logged to \fBsyslogd\fR(8) or \fBpostlogd\fR(8), 314 /* and to the standard error stream. 315 /* ENVIRONMENT 316 /* .ad 317 /* .fi 318 /* .IP \fBMAIL_CONFIG\fR 319 /* Directory with Postfix configuration files. 320 /* .IP "\fBMAIL_VERBOSE\fR (value does not matter)" 321 /* Enable verbose logging for debugging purposes. 322 /* .IP "\fBMAIL_DEBUG\fR (value does not matter)" 323 /* Enable debugging with an external command, as specified with the 324 /* \fBdebugger_command\fR configuration parameter. 325 /* .IP \fBNAME\fR 326 /* The sender full name. This is used only with messages that 327 /* have no \fBFrom:\fR message header. See also the \fB-F\fR 328 /* option above. 329 /* CONFIGURATION PARAMETERS 330 /* .ad 331 /* .fi 332 /* The following \fBmain.cf\fR parameters are especially relevant to 333 /* this program. 334 /* The text below provides only a parameter summary. See 335 /* \fBpostconf\fR(5) for more details including examples. 336 /* COMPATIBILITY CONTROLS 337 /* .ad 338 /* .fi 339 /* Available with Postfix 2.9 and later: 340 /* .IP "\fBsendmail_fix_line_endings (always)\fR" 341 /* Controls how the Postfix sendmail command converts email message 342 /* line endings from <CR><LF> into UNIX format (<LF>). 343 /* TROUBLE SHOOTING CONTROLS 344 /* .ad 345 /* .fi 346 /* The DEBUG_README file gives examples of how to troubleshoot a 347 /* Postfix system. 348 /* .IP "\fBdebugger_command (empty)\fR" 349 /* The external command to execute when a Postfix daemon program is 350 /* invoked with the -D option. 351 /* .IP "\fBdebug_peer_level (2)\fR" 352 /* The increment in verbose logging level when a nexthop destination, 353 /* remote client or server name or network address matches a pattern 354 /* given with the debug_peer_list parameter. 355 /* .IP "\fBdebug_peer_list (empty)\fR" 356 /* Optional list of nexthop destination, remote client or server 357 /* name or network address patterns that, if matched, cause the verbose 358 /* logging level to increase by the amount specified in $debug_peer_level. 359 /* ACCESS CONTROLS 360 /* .ad 361 /* .fi 362 /* Available in Postfix version 2.2 and later: 363 /* .IP "\fBauthorized_flush_users (static:anyone)\fR" 364 /* List of users who are authorized to flush the queue. 365 /* .IP "\fBauthorized_mailq_users (static:anyone)\fR" 366 /* List of users who are authorized to view the queue. 367 /* .IP "\fBauthorized_submit_users (static:anyone)\fR" 368 /* List of users who are authorized to submit mail with the \fBsendmail\fR(1) 369 /* command (and with the privileged \fBpostdrop\fR(1) helper command). 370 /* RESOURCE AND RATE CONTROLS 371 /* .ad 372 /* .fi 373 /* .IP "\fBbounce_size_limit (50000)\fR" 374 /* The maximal amount of original message text that is sent in a 375 /* non-delivery notification. 376 /* .IP "\fBfork_attempts (5)\fR" 377 /* The maximal number of attempts to fork() a child process. 378 /* .IP "\fBfork_delay (1s)\fR" 379 /* The delay between attempts to fork() a child process. 380 /* .IP "\fBhopcount_limit (50)\fR" 381 /* The maximal number of Received: message headers that is allowed 382 /* in the primary message headers. 383 /* .IP "\fBqueue_run_delay (300s)\fR" 384 /* The time between deferred queue scans by the queue manager; 385 /* prior to Postfix 2.4 the default value was 1000s. 386 /* FAST FLUSH CONTROLS 387 /* .ad 388 /* .fi 389 /* The ETRN_README file describes configuration and operation 390 /* details for the Postfix "fast flush" service. 391 /* .IP "\fBfast_flush_domains ($relay_domains)\fR" 392 /* Optional list of destinations that are eligible for per-destination 393 /* logfiles with mail that is queued to those destinations. 394 /* VERP CONTROLS 395 /* .ad 396 /* .fi 397 /* The VERP_README file describes configuration and operation 398 /* details of Postfix support for variable envelope return 399 /* path addresses. 400 /* .IP "\fBdefault_verp_delimiters (+=)\fR" 401 /* The two default VERP delimiter characters. 402 /* .IP "\fBverp_delimiter_filter (-=+)\fR" 403 /* The characters Postfix accepts as VERP delimiter characters on the 404 /* Postfix \fBsendmail\fR(1) command line and in SMTP commands. 405 /* MISCELLANEOUS CONTROLS 406 /* .ad 407 /* .fi 408 /* .IP "\fBalias_database (see 'postconf -d' output)\fR" 409 /* The alias databases for \fBlocal\fR(8) delivery that are updated with 410 /* "\fBnewaliases\fR" or with "\fBsendmail -bi\fR". 411 /* .IP "\fBcommand_directory (see 'postconf -d' output)\fR" 412 /* The location of all postfix administrative commands. 413 /* .IP "\fBconfig_directory (see 'postconf -d' output)\fR" 414 /* The default location of the Postfix main.cf and master.cf 415 /* configuration files. 416 /* .IP "\fBdaemon_directory (see 'postconf -d' output)\fR" 417 /* The directory with Postfix support programs and daemon programs. 418 /* .IP "\fBdefault_database_type (see 'postconf -d' output)\fR" 419 /* The default database type for use in \fBnewaliases\fR(1), \fBpostalias\fR(1) 420 /* and \fBpostmap\fR(1) commands. 421 /* .IP "\fBdelay_warning_time (0h)\fR" 422 /* The time after which the sender receives a copy of the message 423 /* headers of mail that is still queued. 424 /* .IP "\fBimport_environment (see 'postconf -d' output)\fR" 425 /* The list of environment variables that a privileged Postfix 426 /* process will import from a non-Postfix parent process, or name=value 427 /* environment overrides. 428 /* .IP "\fBmail_owner (postfix)\fR" 429 /* The UNIX system account that owns the Postfix queue and most Postfix 430 /* daemon processes. 431 /* .IP "\fBqueue_directory (see 'postconf -d' output)\fR" 432 /* The location of the Postfix top-level queue directory. 433 /* .IP "\fBremote_header_rewrite_domain (empty)\fR" 434 /* Rewrite or add message headers in mail from remote clients if 435 /* the remote_header_rewrite_domain parameter value is non-empty, 436 /* updating incomplete addresses with the domain specified in the 437 /* remote_header_rewrite_domain parameter, and adding missing headers. 438 /* .IP "\fBsyslog_facility (mail)\fR" 439 /* The syslog facility of Postfix logging. 440 /* .IP "\fBsyslog_name (see 'postconf -d' output)\fR" 441 /* A prefix that is prepended to the process name in syslog 442 /* records, so that, for example, "smtpd" becomes "prefix/smtpd". 443 /* .PP 444 /* Postfix 3.2 and later: 445 /* .IP "\fBalternate_config_directories (empty)\fR" 446 /* A list of non-default Postfix configuration directories that may 447 /* be specified with "-c config_directory" on the command line (in the 448 /* case of \fBsendmail\fR(1), with the "-C" option), or via the MAIL_CONFIG 449 /* environment parameter. 450 /* .IP "\fBmulti_instance_directories (empty)\fR" 451 /* An optional list of non-default Postfix configuration directories; 452 /* these directories belong to additional Postfix instances that share 453 /* the Postfix executable files and documentation with the default 454 /* Postfix instance, and that are started, stopped, etc., together 455 /* with the default Postfix instance. 456 /* .PP 457 /* Postfix 3.11 and later: 458 /* .IP "\fBrequiretls_enable (yes)\fR" 459 /* Enable support for the ESMTP verb "REQUIRETLS" in the "MAIL 460 /* FROM" command. 461 /* FILES 462 /* /var/spool/postfix, mail queue 463 /* /etc/postfix, configuration files 464 /* SEE ALSO 465 /* pickup(8), mail pickup daemon 466 /* qmgr(8), queue manager 467 /* smtpd(8), SMTP server 468 /* flush(8), fast flush service 469 /* postsuper(1), queue maintenance 470 /* postalias(1), create/update/query alias database 471 /* postdrop(1), mail posting utility 472 /* postfix(1), mail system control 473 /* postqueue(1), mail queue control 474 /* postlogd(8), Postfix logging 475 /* syslogd(8), system logging 476 /* README_FILES 477 /* .ad 478 /* .fi 479 /* Use "\fBpostconf readme_directory\fR" or 480 /* "\fBpostconf html_directory\fR" to locate this information. 481 /* .na 482 /* .nf 483 /* DEBUG_README, Postfix debugging howto 484 /* ETRN_README, Postfix ETRN howto 485 /* VERP_README, Postfix VERP howto 486 /* LICENSE 487 /* .ad 488 /* .fi 489 /* The Secure Mailer license must be distributed with this software. 490 /* AUTHOR(S) 491 /* Wietse Venema 492 /* IBM T.J. Watson Research 493 /* P.O. Box 704 494 /* Yorktown Heights, NY 10598, USA 495 /* 496 /* Wietse Venema 497 /* Google, Inc. 498 /* 111 8th Avenue 499 /* New York, NY 10011, USA 500 /*--*/ 501 502 /* System library. */ 503 504 #include <sys_defs.h> 505 #include <sys/stat.h> 506 #include <unistd.h> 507 #include <string.h> 508 #include <stdio.h> /* remove() */ 509 #include <stdlib.h> 510 #include <signal.h> 511 #include <fcntl.h> 512 #include <time.h> 513 #include <errno.h> 514 #include <ctype.h> 515 #include <stdarg.h> 516 #include <sysexits.h> 517 518 /* Utility library. */ 519 520 #include <msg.h> 521 #include <mymalloc.h> 522 #include <vstream.h> 523 #include <msg_vstream.h> 524 #include <vstring_vstream.h> 525 #include <username.h> 526 #include <fullname.h> 527 #include <argv.h> 528 #include <safe.h> 529 #include <iostuff.h> 530 #include <stringops.h> 531 #include <set_ugid.h> 532 #include <connect.h> 533 #include <split_at.h> 534 #include <name_code.h> 535 #include <warn_stat.h> 536 #include <clean_env.h> 537 #include <maillog_client.h> 538 539 /* Global library. */ 540 541 #include <mail_queue.h> 542 #include <mail_proto.h> 543 #include <mail_params.h> 544 #include <mail_version.h> 545 #include <record.h> 546 #include <rec_type.h> 547 #include <rec_streamlf.h> 548 #include <mail_conf.h> 549 #include <cleanup_user.h> 550 #include <mail_task.h> 551 #include <mail_run.h> 552 #include <debug_process.h> 553 #include <tok822.h> 554 #include <mail_flush.h> 555 #include <mail_stream.h> 556 #include <verp_sender.h> 557 #include <deliver_request.h> 558 #include <mime_state.h> 559 #include <header_opts.h> 560 #include <mail_dict.h> 561 #include <user_acl.h> 562 #include <dsn_mask.h> 563 #include <mail_parm_split.h> 564 #include <sendopts.h> 565 566 /* Application-specific. */ 567 568 /* 569 * Modes of operation. 570 */ 571 #define SM_MODE_ENQUEUE 1 /* delivery mode */ 572 #define SM_MODE_NEWALIAS 2 /* initialize alias database */ 573 #define SM_MODE_MAILQ 3 /* list mail queue */ 574 #define SM_MODE_DAEMON 4 /* daemon mode */ 575 #define SM_MODE_USER 5 /* user (stand-alone) mode */ 576 #define SM_MODE_FLUSHQ 6 /* user (stand-alone) mode */ 577 #define SM_MODE_IGNORE 7 /* ignore this mode */ 578 579 /* 580 * Flag parade. Flags 8-15 are reserved for delivery request trace flags. 581 */ 582 #define SM_FLAG_AEOF (1<<0) /* archaic EOF */ 583 #define SM_FLAG_XRCPT (1<<1) /* extract recipients from headers */ 584 585 #define SM_FLAG_DEFAULT (SM_FLAG_AEOF) 586 587 /* 588 * VERP support. 589 */ 590 static char *verp_delims; 591 592 /* 593 * Callback context for extracting recipients. 594 */ 595 typedef struct SM_STATE { 596 VSTREAM *dst; /* output stream */ 597 ARGV *recipients; /* recipients from regular headers */ 598 ARGV *resent_recip; /* recipients from resent headers */ 599 int resent; /* resent flag */ 600 const char *saved_sender; /* for error messages */ 601 uid_t uid; /* for error messages */ 602 VSTRING *temp; /* scratch buffer */ 603 } SM_STATE; 604 605 /* 606 * Mail submission ACL, line-end fixing. 607 */ 608 char *var_submit_acl; 609 char *var_sm_fix_eol; 610 611 static const CONFIG_STR_TABLE str_table[] = { 612 VAR_SUBMIT_ACL, DEF_SUBMIT_ACL, &var_submit_acl, 0, 0, 613 VAR_SM_FIX_EOL, DEF_SM_FIX_EOL, &var_sm_fix_eol, 1, 0, 614 0, 615 }; 616 617 /* 618 * Sender options. 619 */ 620 static int sm_sendopts; 621 622 /* 623 * Silly little macros (SLMs). 624 */ 625 #define STR vstring_str 626 627 /* output_text - output partial or complete text line */ 628 629 static void output_text(void *context, int rec_type, const char *buf, ssize_t len, 630 off_t unused_offset) 631 { 632 SM_STATE *state = (SM_STATE *) context; 633 634 if (rec_put(state->dst, rec_type, buf, len) < 0) 635 msg_fatal_status(EX_TEMPFAIL, 636 "%s(%ld): error writing queue file: %m", 637 state->saved_sender, (long) state->uid); 638 } 639 640 /* output_header - output one message header */ 641 642 static void output_header(void *context, int header_class, 643 const HEADER_OPTS *header_info, 644 VSTRING *buf, off_t offset) 645 { 646 SM_STATE *state = (SM_STATE *) context; 647 TOK822 *tree; 648 TOK822 **addr_list; 649 TOK822 **tpp; 650 ARGV *rcpt; 651 char *start; 652 char *line; 653 char *next_line; 654 ssize_t len; 655 656 /* 657 * Parse the header line, and save copies of recipient addresses in the 658 * appropriate place. 659 */ 660 if (header_class == MIME_HDR_PRIMARY 661 && header_info 662 && (header_info->flags & HDR_OPT_RECIP) 663 && (header_info->flags & HDR_OPT_EXTRACT) 664 && (state->resent == 0 || (header_info->flags & HDR_OPT_RR))) { 665 if (header_info->flags & HDR_OPT_RR) { 666 rcpt = state->resent_recip; 667 if (state->resent == 0) 668 state->resent = 1; 669 } else 670 rcpt = state->recipients; 671 tree = tok822_parse(STR(buf) + strlen(header_info->name) + 1); 672 addr_list = tok822_grep(tree, TOK822_ADDR); 673 for (tpp = addr_list; *tpp; tpp++) { 674 tok822_internalize(state->temp, tpp[0]->head, TOK822_STR_DEFL); 675 argv_add(rcpt, STR(state->temp), (char *) 0); 676 } 677 myfree((void *) addr_list); 678 tok822_free_tree(tree); 679 } 680 681 /* 682 * Pipe the unmodified message header through the header line folding 683 * routine, and ensure that long lines are chopped appropriately. 684 */ 685 for (line = start = STR(buf); line; line = next_line) { 686 next_line = split_at(line, '\n'); 687 len = next_line ? next_line - line - 1 : strlen(line); 688 do { 689 if (len > var_line_limit) { 690 output_text(context, REC_TYPE_CONT, line, var_line_limit, offset); 691 line += var_line_limit; 692 len -= var_line_limit; 693 offset += var_line_limit; 694 } else { 695 output_text(context, REC_TYPE_NORM, line, len, offset); 696 offset += len; 697 break; 698 } 699 } while (len > 0); 700 offset += 1; 701 } 702 } 703 704 /* enqueue - post one message */ 705 706 static void enqueue(const int flags, const char *encoding, 707 const char *dsn_envid, int dsn_ret, int dsn_notify, 708 const char *rewrite_context, const char *sender, 709 const char *full_name, char **recipients) 710 { 711 VSTRING *buf; 712 VSTREAM *dst; 713 char *saved_sender; 714 char **cpp; 715 int type; 716 char *start; 717 int skip_from_; 718 TOK822 *tree; 719 TOK822 *tp; 720 int rcpt_count = 0; 721 enum { 722 STRIP_CR_DUNNO, STRIP_CR_DO, STRIP_CR_DONT, STRIP_CR_ERROR 723 } strip_cr; 724 MAIL_STREAM *handle; 725 VSTRING *postdrop_command; 726 uid_t uid = getuid(); 727 int status; 728 VSTRING *why; /* postdrop status message */ 729 int naddr; 730 int prev_type; 731 MIME_STATE *mime_state = 0; 732 SM_STATE state; 733 int mime_errs; 734 const char *errstr; 735 int addr_count; 736 int level; 737 static NAME_CODE sm_fix_eol_table[] = { 738 SM_FIX_EOL_ALWAYS, STRIP_CR_DO, 739 SM_FIX_EOL_STRICT, STRIP_CR_DUNNO, 740 SM_FIX_EOL_NEVER, STRIP_CR_DONT, 741 0, STRIP_CR_ERROR, 742 }; 743 744 /* 745 * Access control is enforced in the postdrop command. The code here 746 * merely produces a more user-friendly interface. 747 */ 748 if ((errstr = check_user_acl_byuid(VAR_SUBMIT_ACL, 749 var_submit_acl, uid)) != 0) 750 msg_fatal_status(EX_NOPERM, 751 "User %s(%ld) is not allowed to submit mail", errstr, (long) uid); 752 753 /* 754 * Initialize. 755 */ 756 buf = vstring_alloc(100); 757 758 /* 759 * Stop run-away process accidents by limiting the queue file size. This 760 * is not a defense against DOS attack. 761 */ 762 if (ENFORCING_SIZE_LIMIT(var_message_limit) 763 && get_file_limit() > var_message_limit) 764 set_file_limit((off_t) var_message_limit); 765 766 /* 767 * The sender name is provided by the user. In principle, the mail pickup 768 * service could deduce the sender name from queue file ownership, but: 769 * pickup would not be able to run chrooted, and it may not be desirable 770 * to use login names at all. 771 */ 772 if (sender != 0) { 773 VSTRING_RESET(buf); 774 VSTRING_TERMINATE(buf); 775 tree = tok822_parse(sender); 776 for (naddr = 0, tp = tree; tp != 0; tp = tp->next) 777 if (tp->type == TOK822_ADDR && naddr++ == 0) 778 tok822_internalize(buf, tp->head, TOK822_STR_DEFL); 779 tok822_free_tree(tree); 780 saved_sender = mystrdup(STR(buf)); 781 if (naddr > 1) 782 msg_warn("-f option specified malformed sender: %s", sender); 783 } else { 784 if ((sender = username()) == 0) 785 msg_fatal_status(EX_OSERR, "no login name found for user ID %lu", 786 (unsigned long) uid); 787 saved_sender = mystrdup(sender); 788 } 789 790 /* 791 * Let the postdrop command open the queue file for us, and sanity check 792 * the content. XXX Make postdrop a manifest constant. 793 */ 794 errno = 0; 795 postdrop_command = vstring_alloc(1000); 796 vstring_sprintf(postdrop_command, "%s/postdrop -r", var_command_dir); 797 for (level = 0; level < msg_verbose; level++) 798 vstring_strcat(postdrop_command, " -v"); 799 if ((handle = mail_stream_command(STR(postdrop_command))) == 0) 800 msg_fatal_status(EX_UNAVAILABLE, "%s(%ld): unable to execute %s: %m", 801 saved_sender, (long) uid, STR(postdrop_command)); 802 vstring_free(postdrop_command); 803 dst = handle->stream; 804 805 /* 806 * First, write envelope information to the output stream. 807 * 808 * For sendmail compatibility, parse each command-line recipient as if it 809 * were an RFC 822 message header; some MUAs specify comma-separated 810 * recipient lists; and some MUAs even specify "word word <address>". 811 * 812 * Sort-uniq-ing the recipient list is done after address canonicalization, 813 * before recipients are written to queue file. That's cleaner than 814 * having the queue manager nuke duplicate recipient status records. 815 * 816 * XXX Should limit the size of envelope records. 817 * 818 * With "sendmail -N", instead of a per-message NOTIFY record we store one 819 * per recipient so that we can simplify the implementation somewhat. 820 */ 821 if (sm_sendopts) 822 rec_fprintf(dst, REC_TYPE_SIZE, REC_TYPE_SIZE_FORMAT, 823 (REC_TYPE_SIZE_CAST1) ~ 0, /* message segment size */ 824 (REC_TYPE_SIZE_CAST2) ~ 0, /* content offset */ 825 (REC_TYPE_SIZE_CAST3) ~ 0, /* recipient count */ 826 (REC_TYPE_SIZE_CAST4) ~ 0, /* qmgr options */ 827 (REC_TYPE_SIZE_CAST5) ~ 0, /* content length */ 828 (REC_TYPE_SIZE_CAST6) sm_sendopts); 829 if (dsn_envid) 830 rec_fprintf(dst, REC_TYPE_ATTR, "%s=%s", 831 MAIL_ATTR_DSN_ENVID, dsn_envid); 832 if (dsn_ret) 833 rec_fprintf(dst, REC_TYPE_ATTR, "%s=%d", 834 MAIL_ATTR_DSN_RET, dsn_ret); 835 rec_fprintf(dst, REC_TYPE_ATTR, "%s=%s", 836 MAIL_ATTR_RWR_CONTEXT, rewrite_context); 837 if (full_name || (full_name = fullname()) != 0) 838 rec_fputs(dst, REC_TYPE_FULL, full_name); 839 rec_fputs(dst, REC_TYPE_FROM, saved_sender); 840 if (verp_delims && *saved_sender == 0) 841 msg_fatal_status(EX_USAGE, 842 "%s(%ld): -V option requires non-null sender address", 843 saved_sender, (long) uid); 844 if (encoding) 845 rec_fprintf(dst, REC_TYPE_ATTR, "%s=%s", MAIL_ATTR_ENCODING, encoding); 846 if (DEL_REQ_TRACE_FLAGS(flags)) 847 rec_fprintf(dst, REC_TYPE_ATTR, "%s=%d", MAIL_ATTR_TRACE_FLAGS, 848 DEL_REQ_TRACE_FLAGS(flags)); 849 if (verp_delims) 850 rec_fputs(dst, REC_TYPE_VERP, verp_delims); 851 if (recipients) { 852 for (cpp = recipients; *cpp != 0; cpp++) { 853 tree = tok822_parse(*cpp); 854 for (addr_count = 0, tp = tree; tp != 0; tp = tp->next) { 855 if (tp->type == TOK822_ADDR) { 856 tok822_internalize(buf, tp->head, TOK822_STR_DEFL); 857 if (dsn_notify) 858 rec_fprintf(dst, REC_TYPE_ATTR, "%s=%d", 859 MAIL_ATTR_DSN_NOTIFY, dsn_notify); 860 if (REC_PUT_BUF(dst, REC_TYPE_RCPT, buf) < 0) 861 msg_fatal_status(EX_TEMPFAIL, 862 "%s(%ld): error writing queue file: %m", 863 saved_sender, (long) uid); 864 ++rcpt_count; 865 ++addr_count; 866 } 867 } 868 tok822_free_tree(tree); 869 if (addr_count == 0) { 870 if (rec_put(dst, REC_TYPE_RCPT, "", 0) < 0) 871 msg_fatal_status(EX_TEMPFAIL, 872 "%s(%ld): error writing queue file: %m", 873 saved_sender, (long) uid); 874 ++rcpt_count; 875 } 876 } 877 } 878 879 /* 880 * Append the message contents to the queue file. Write chunks of at most 881 * 1kbyte. Internally, we use different record types for data ending in 882 * LF and for data that doesn't, so we can actually be binary transparent 883 * for local mail. Unfortunately, SMTP has no record continuation 884 * convention, so there is no guarantee that arbitrary data will be 885 * delivered intact via SMTP. Strip leading From_ lines. For the benefit 886 * of UUCP environments, also get rid of leading >>>From_ lines. 887 */ 888 rec_fputs(dst, REC_TYPE_MESG, ""); 889 if (DEL_REQ_TRACE_ONLY(flags) != 0) { 890 if (flags & SM_FLAG_XRCPT) 891 msg_fatal_status(EX_USAGE, "%s(%ld): -t option cannot be used with -bv", 892 saved_sender, (long) uid); 893 if (*saved_sender) 894 rec_fprintf(dst, REC_TYPE_NORM, "From: %s", saved_sender); 895 rec_fprintf(dst, REC_TYPE_NORM, "Subject: probe"); 896 if (recipients) { 897 rec_fprintf(dst, REC_TYPE_CONT, "To:"); 898 for (cpp = recipients; *cpp != 0; cpp++) { 899 rec_fprintf(dst, REC_TYPE_NORM, " %s%s", 900 *cpp, cpp[1] ? "," : ""); 901 } 902 } 903 } else { 904 905 /* 906 * Initialize the MIME processor and set up the callback context. 907 */ 908 if (flags & SM_FLAG_XRCPT) { 909 state.dst = dst; 910 state.recipients = argv_alloc(2); 911 state.resent_recip = argv_alloc(2); 912 state.resent = 0; 913 state.saved_sender = saved_sender; 914 state.uid = uid; 915 state.temp = vstring_alloc(10); 916 mime_state = mime_state_alloc(MIME_OPT_DISABLE_MIME 917 | MIME_OPT_REPORT_TRUNC_HEADER, 918 output_header, 919 (MIME_STATE_ANY_END) 0, 920 output_text, 921 (MIME_STATE_ANY_END) 0, 922 (MIME_STATE_ERR_PRINT) 0, 923 (void *) &state); 924 } 925 926 /* 927 * Process header/body lines. 928 */ 929 skip_from_ = 1; 930 strip_cr = name_code(sm_fix_eol_table, NAME_CODE_FLAG_STRICT_CASE, 931 var_sm_fix_eol); 932 if (strip_cr == STRIP_CR_ERROR) 933 msg_fatal_status(EX_USAGE, 934 "invalid %s value: %s", VAR_SM_FIX_EOL, var_sm_fix_eol); 935 for (prev_type = 0; (type = rec_streamlf_get(VSTREAM_IN, buf, var_line_limit)) 936 != REC_TYPE_EOF; prev_type = type) { 937 if (strip_cr == STRIP_CR_DUNNO && type == REC_TYPE_NORM) { 938 if (VSTRING_LEN(buf) > 0 && vstring_end(buf)[-1] == '\r') 939 strip_cr = STRIP_CR_DO; 940 else 941 strip_cr = STRIP_CR_DONT; 942 } 943 if (skip_from_) { 944 if (type == REC_TYPE_NORM) { 945 start = STR(buf); 946 if (strncmp(start + strspn(start, ">"), "From ", 5) == 0) 947 continue; 948 } 949 skip_from_ = 0; 950 } 951 if (strip_cr == STRIP_CR_DO && type == REC_TYPE_NORM) 952 while (VSTRING_LEN(buf) > 0 && vstring_end(buf)[-1] == '\r') 953 vstring_truncate(buf, VSTRING_LEN(buf) - 1); 954 if ((flags & SM_FLAG_AEOF) && prev_type != REC_TYPE_CONT 955 && VSTRING_LEN(buf) == 1 && *STR(buf) == '.') 956 break; 957 if (mime_state) { 958 mime_errs = mime_state_update(mime_state, type, STR(buf), 959 VSTRING_LEN(buf)); 960 if (mime_errs) 961 msg_fatal_status(EX_DATAERR, 962 "%s(%ld): unable to extract recipients: %s", 963 saved_sender, (long) uid, 964 mime_state_error(mime_errs)); 965 } else { 966 if (REC_PUT_BUF(dst, type, buf) < 0) 967 msg_fatal_status(EX_TEMPFAIL, 968 "%s(%ld): error writing queue file: %m", 969 saved_sender, (long) uid); 970 } 971 } 972 } 973 974 /* 975 * Finish MIME processing. We need a final mime_state_update() call in 976 * order to flush text that is still buffered. That can happen when the 977 * last line did not end in newline. 978 */ 979 if (mime_state) { 980 mime_errs = mime_state_update(mime_state, REC_TYPE_EOF, "", 0); 981 if (mime_errs) 982 msg_fatal_status(EX_DATAERR, 983 "%s(%ld): unable to extract recipients: %s", 984 saved_sender, (long) uid, 985 mime_state_error(mime_errs)); 986 mime_state = mime_state_free(mime_state); 987 } 988 989 /* 990 * Append recipient addresses that were extracted from message headers. 991 */ 992 rec_fputs(dst, REC_TYPE_XTRA, ""); 993 if (flags & SM_FLAG_XRCPT) { 994 for (cpp = state.resent ? state.resent_recip->argv : 995 state.recipients->argv; *cpp; cpp++) { 996 if (dsn_notify) 997 rec_fprintf(dst, REC_TYPE_ATTR, "%s=%d", 998 MAIL_ATTR_DSN_NOTIFY, dsn_notify); 999 if (rec_put(dst, REC_TYPE_RCPT, *cpp, strlen(*cpp)) < 0) 1000 msg_fatal_status(EX_TEMPFAIL, 1001 "%s(%ld): error writing queue file: %m", 1002 saved_sender, (long) uid); 1003 ++rcpt_count; 1004 } 1005 argv_free(state.recipients); 1006 argv_free(state.resent_recip); 1007 vstring_free(state.temp); 1008 } 1009 if (rcpt_count == 0) 1010 msg_fatal_status(EX_USAGE, (flags & SM_FLAG_XRCPT) ? 1011 "%s(%ld): No recipient addresses found in message header" : 1012 "%s(%ld): Recipient addresses must be specified on" 1013 " the command line or via the -t option", 1014 saved_sender, (long) uid); 1015 1016 /* 1017 * Identify the end of the queue file. 1018 */ 1019 rec_fputs(dst, REC_TYPE_END, ""); 1020 1021 /* 1022 * Make sure that the message makes it to the file system. Once we have 1023 * terminated with successful exit status we cannot lose the message due 1024 * to "frivolous reasons". If all goes well, prevent the run-time error 1025 * handler from removing the file. 1026 */ 1027 if (vstream_ferror(VSTREAM_IN)) 1028 msg_fatal_status(EX_DATAERR, "%s(%ld): error reading input: %m", 1029 saved_sender, (long) uid); 1030 why = vstring_alloc(100); 1031 if ((status = mail_stream_finish(handle, why)) != CLEANUP_STAT_OK) 1032 msg_fatal_status((status & CLEANUP_STAT_BAD) ? EX_SOFTWARE : 1033 (status & CLEANUP_STAT_WRITE) ? EX_TEMPFAIL : 1034 (status & CLEANUP_STAT_NOPERM) ? EX_NOPERM : 1035 EX_UNAVAILABLE, "%s(%ld): %s", saved_sender, 1036 (long) uid, VSTRING_LEN(why) ? 1037 STR(why) : cleanup_strerror(status)); 1038 vstring_free(why); 1039 1040 /* 1041 * Don't leave them in the dark. 1042 */ 1043 if (DEL_REQ_TRACE_FLAGS(flags)) { 1044 vstream_printf("Mail Delivery Status Report will be mailed to <%s>.\n", 1045 saved_sender); 1046 vstream_fflush(VSTREAM_OUT); 1047 } 1048 1049 /* 1050 * Cleanup. Not really necessary as we're about to exit, but good for 1051 * debugging purposes. 1052 */ 1053 vstring_free(buf); 1054 myfree(saved_sender); 1055 } 1056 1057 /* tempfail - sanitize exit status after library run-time error */ 1058 1059 static void tempfail(void) 1060 { 1061 exit(EX_TEMPFAIL); 1062 } 1063 1064 MAIL_VERSION_STAMP_DECLARE; 1065 1066 /* main - the main program */ 1067 1068 int main(int argc, char **argv) 1069 { 1070 static char *full_name = 0; /* sendmail -F */ 1071 struct stat st; 1072 char *slash; 1073 char *sender = 0; /* sendmail -f */ 1074 int c; 1075 int fd; 1076 int mode; 1077 ARGV *ext_argv; 1078 int debug_me = 0; 1079 int err; 1080 int n; 1081 int flags = SM_FLAG_DEFAULT; 1082 char *site_to_flush = 0; 1083 char *id_to_flush = 0; 1084 char *encoding = 0; 1085 char *qtime = 0; 1086 const char *errstr; 1087 uid_t uid; 1088 const char *rewrite_context = MAIL_ATTR_RWR_LOCAL; 1089 int dsn_notify = 0; 1090 int dsn_ret = 0; 1091 const char *dsn_envid = 0; 1092 int saved_optind; 1093 ARGV *import_env; 1094 char *alias_map_from_args = 0; 1095 const char *oval; 1096 1097 /* 1098 * Fingerprint executables and core dumps. 1099 */ 1100 MAIL_VERSION_STAMP_ALLOCATE; 1101 1102 /* 1103 * Be consistent with file permissions. 1104 */ 1105 umask(022); 1106 1107 /* 1108 * To minimize confusion, make sure that the standard file descriptors 1109 * are open before opening anything else. XXX Work around for 44BSD where 1110 * fstat can return EBADF on an open file descriptor. 1111 */ 1112 for (fd = 0; fd < 3; fd++) 1113 if (fstat(fd, &st) == -1 1114 && (close(fd), open("/dev/null", O_RDWR, 0)) != fd) 1115 msg_fatal_status(EX_OSERR, "open /dev/null: %m"); 1116 1117 /* 1118 * The CDE desktop calendar manager leaks a parent file descriptor into 1119 * the child process. For the sake of sendmail compatibility we have to 1120 * close the file descriptor otherwise mail notification will hang. 1121 */ 1122 for ( /* void */ ; fd < 100; fd++) 1123 (void) close(fd); 1124 1125 /* 1126 * Process environment options as early as we can. We might be called 1127 * from a set-uid (set-gid) program, so be careful with importing 1128 * environment variables. 1129 */ 1130 if (safe_getenv(CONF_ENV_VERB)) 1131 msg_verbose = 1; 1132 if (safe_getenv(CONF_ENV_DEBUG)) 1133 debug_me = 1; 1134 1135 /* 1136 * Initialize. Set up logging. Read the global configuration file after 1137 * command-line processing. Set up signal handlers so that we can clean 1138 * up incomplete output. 1139 */ 1140 if ((slash = strrchr(argv[0], '/')) != 0 && slash[1]) 1141 argv[0] = slash + 1; 1142 msg_vstream_init(argv[0], VSTREAM_ERR); 1143 msg_cleanup(tempfail); 1144 maillog_client_init(mail_task("sendmail"), MAILLOG_CLIENT_FLAG_NONE); 1145 set_mail_conf_str(VAR_PROCNAME, var_procname = mystrdup(argv[0])); 1146 1147 /* 1148 * Check the Postfix library version as soon as we enable logging. 1149 */ 1150 MAIL_VERSION_CHECK; 1151 1152 /* 1153 * Some sites mistakenly install Postfix sendmail as set-uid root. Drop 1154 * set-uid privileges only when root, otherwise some systems will not 1155 * reset the saved set-userid, which would be a security vulnerability. 1156 */ 1157 if (geteuid() == 0 && getuid() != 0) { 1158 msg_warn("the Postfix sendmail command has set-uid root file permissions"); 1159 msg_warn("or the command is run from a set-uid root process"); 1160 msg_warn("the Postfix sendmail command must be installed without set-uid root file permissions"); 1161 set_ugid(getuid(), getgid()); 1162 } 1163 1164 /* 1165 * Further initialization. Load main.cf first, so that command-line 1166 * options can override main.cf settings. Pre-scan the argument list so 1167 * that we load the right main.cf file. 1168 */ 1169 #define GETOPT_LIST "A:B:C:F:GIL:N:O:R:UV:X:b:ce:f:h:imno:p:r:q:tvx" 1170 1171 saved_optind = optind; 1172 while (argv[OPTIND] != 0) { 1173 if (strcmp(argv[OPTIND], "-q") == 0) { /* not getopt compatible */ 1174 optind++; 1175 continue; 1176 } 1177 if ((c = GETOPT(argc, argv, GETOPT_LIST)) <= 0) 1178 break; 1179 if (c == 'C') { 1180 VSTRING *buf = vstring_alloc(1); 1181 char *dir; 1182 1183 dir = strcmp(sane_basename(buf, optarg), MAIN_CONF_FILE) == 0 ? 1184 sane_dirname(buf, optarg) : optarg; 1185 if (strcmp(dir, DEF_CONFIG_DIR) != 0 && geteuid() != 0) 1186 mail_conf_checkdir(dir); 1187 if (setenv(CONF_ENV_PATH, dir, 1) < 0) 1188 msg_fatal_status(EX_UNAVAILABLE, "out of memory"); 1189 vstring_free(buf); 1190 } 1191 } 1192 optind = saved_optind; 1193 mail_conf_read(); 1194 /* Enforce consistent operation of different Postfix parts. */ 1195 import_env = mail_parm_split(VAR_IMPORT_ENVIRON, var_import_environ); 1196 update_env(import_env->argv); 1197 argv_free(import_env); 1198 /* Re-evaluate mail_task() after reading main.cf. */ 1199 maillog_client_init(mail_task("sendmail"), MAILLOG_CLIENT_FLAG_NONE); 1200 get_mail_conf_str_table(str_table); 1201 1202 mail_dict_init(); 1203 1204 if (chdir(var_queue_dir)) 1205 msg_fatal_status(EX_UNAVAILABLE, "chdir %s: %m", var_queue_dir); 1206 1207 signal(SIGPIPE, SIG_IGN); 1208 1209 /* 1210 * Optionally start the debugger on ourself. This must be done after 1211 * reading the global configuration file, because that file specifies 1212 * what debugger command to execute. 1213 */ 1214 if (debug_me) 1215 debug_process(); 1216 1217 /* 1218 * The default mode of operation is determined by the process name. It 1219 * can, however, be changed via command-line options (for example, 1220 * "newaliases -bp" will show the mail queue). 1221 */ 1222 if (strcmp(argv[0], "mailq") == 0) { 1223 mode = SM_MODE_MAILQ; 1224 } else if (strcmp(argv[0], "newaliases") == 0) { 1225 mode = SM_MODE_NEWALIAS; 1226 } else if (strcmp(argv[0], "smtpd") == 0) { 1227 mode = SM_MODE_DAEMON; 1228 } else { 1229 mode = SM_MODE_ENQUEUE; 1230 } 1231 1232 /* 1233 * Parse JCL. Sendmail has been around for a long time, and has acquired 1234 * a large number of options in the course of time. Some options such as 1235 * -q are not parsable with GETOPT() and get special treatment. 1236 */ 1237 #define OPTIND (optind > 0 ? optind : 1) 1238 1239 while (argv[OPTIND] != 0) { 1240 if (strcmp(argv[OPTIND], "-q") == 0) { 1241 if (mode == SM_MODE_DAEMON) 1242 msg_warn("ignoring -q option in daemon mode"); 1243 else 1244 mode = SM_MODE_FLUSHQ; 1245 optind++; 1246 continue; 1247 } 1248 if (strcmp(argv[OPTIND], "-V") == 0 1249 && argv[OPTIND + 1] != 0 && strlen(argv[OPTIND + 1]) == 2) { 1250 msg_warn("option -V is deprecated with Postfix 2.3; " 1251 "specify -XV instead"); 1252 argv[OPTIND] = "-XV"; 1253 } 1254 if (strncmp(argv[OPTIND], "-V", 2) == 0 && strlen(argv[OPTIND]) == 4) { 1255 msg_warn("option %s is deprecated with Postfix 2.3; " 1256 "specify -X%s instead", 1257 argv[OPTIND], argv[OPTIND] + 1); 1258 argv[OPTIND] = concatenate("-X", argv[OPTIND] + 1, (char *) 0); 1259 } 1260 if (strcmp(argv[OPTIND], "-XV") == 0) { 1261 verp_delims = var_verp_delims; 1262 optind++; 1263 continue; 1264 } 1265 if ((c = GETOPT(argc, argv, GETOPT_LIST)) <= 0) 1266 break; 1267 switch (c) { 1268 default: 1269 if (msg_verbose) 1270 msg_info("-%c option ignored", c); 1271 break; 1272 case 'n': 1273 msg_fatal_status(EX_USAGE, "-%c option not supported", c); 1274 case 'B': 1275 if (strcmp(optarg, "8BITMIME") == 0)/* RFC 1652 */ 1276 encoding = MAIL_ATTR_ENC_8BIT; 1277 else if (strcmp(optarg, "7BIT") == 0) /* RFC 1652 */ 1278 encoding = MAIL_ATTR_ENC_7BIT; 1279 else 1280 msg_fatal_status(EX_USAGE, "-B option needs 8BITMIME or 7BIT"); 1281 break; 1282 case 'F': /* full name */ 1283 full_name = optarg; 1284 break; 1285 case 'G': /* gateway submission */ 1286 rewrite_context = MAIL_ATTR_RWR_REMOTE; 1287 break; 1288 case 'I': /* newaliases */ 1289 mode = SM_MODE_NEWALIAS; 1290 break; 1291 case 'N': 1292 if ((dsn_notify = dsn_notify_mask(optarg)) == 0) 1293 msg_warn("bad -N option value: '%s' -- ignored", optarg); 1294 break; 1295 case 'O': 1296 if ((oval = optarg + strcspn(optarg, "="))[0] != 0) 1297 oval += 1; 1298 if (strncasecmp(optarg, "REQUIRETLS=", oval - optarg) == 0) { 1299 if (var_reqtls_enable == 0) { 1300 msg_warn("Ignoring option '-O %s, because the " 1301 "configuration is '%s = %s'", optarg, 1302 VAR_REQTLS_ENABLE, CONFIG_BOOL_NO); 1303 continue; 1304 } else if (strcasecmp(oval, CONFIG_BOOL_YES) == 0) { 1305 sm_sendopts |= SOPT_REQUIRETLS_ESMTP; 1306 continue; 1307 } else if (strcasecmp(oval, CONFIG_BOOL_NO) == 0) { 1308 sm_sendopts &= ~SOPT_REQUIRETLS_ESMTP; 1309 continue; 1310 } 1311 msg_warn("bad -O option: '%s' -- ignored", optarg); 1312 } else if (strncasecmp(optarg, "SMTPUTF8=", oval - optarg) == 0) { 1313 if (var_smtputf8_enable == 0) { 1314 msg_warn("'-O %s' was requested, but the " 1315 "configuration is '%s = %s'", optarg, 1316 VAR_SMTPUTF8_ENABLE, CONFIG_BOOL_NO); 1317 continue; 1318 } else if (strcasecmp(oval, CONFIG_BOOL_YES) == 0) { 1319 sm_sendopts |= SOPT_SMTPUTF8_REQUESTED; 1320 continue; 1321 } else if (strcasecmp(oval, CONFIG_BOOL_NO) == 0) { 1322 sm_sendopts &= ~SOPT_SMTPUTF8_REQUESTED; 1323 continue; 1324 } 1325 msg_warn("bad -O option: '%s' -- ignored", optarg); 1326 } 1327 break; 1328 case 'R': 1329 if ((dsn_ret = dsn_ret_code(optarg)) == 0) 1330 msg_warn("bad -R option value -- ignored"); 1331 break; 1332 case 'V': /* DSN, was: VERP */ 1333 if (strlen(optarg) > 100) 1334 msg_warn("too long -V option value -- ignored"); 1335 else if (!allprint(optarg)) 1336 msg_warn("bad syntax in -V option value -- ignored"); 1337 else 1338 dsn_envid = optarg; 1339 break; 1340 case 'X': 1341 switch (*optarg) { 1342 default: 1343 msg_fatal_status(EX_USAGE, "unsupported: -%c%c", c, *optarg); 1344 case 'V': /* VERP */ 1345 if (verp_delims_verify(optarg + 1) != 0) 1346 msg_fatal_status(EX_USAGE, "-V requires two characters from %s", 1347 var_verp_filter); 1348 verp_delims = optarg + 1; 1349 break; 1350 } 1351 break; 1352 case 'b': 1353 switch (*optarg) { 1354 default: 1355 msg_fatal_status(EX_USAGE, "unsupported: -%c%c", c, *optarg); 1356 case 'd': /* daemon mode */ 1357 case 'l': /* daemon mode */ 1358 if (mode == SM_MODE_FLUSHQ) 1359 msg_warn("ignoring -q option in daemon mode"); 1360 mode = SM_MODE_DAEMON; 1361 break; 1362 case 'h': /* print host status */ 1363 case 'H': /* flush host status */ 1364 mode = SM_MODE_IGNORE; 1365 break; 1366 case 'i': /* newaliases */ 1367 mode = SM_MODE_NEWALIAS; 1368 break; 1369 case 'm': /* deliver mail */ 1370 mode = SM_MODE_ENQUEUE; 1371 break; 1372 case 'p': /* mailq */ 1373 mode = SM_MODE_MAILQ; 1374 break; 1375 case 's': /* stand-alone mode */ 1376 mode = SM_MODE_USER; 1377 break; 1378 case 'v': /* expand recipients */ 1379 flags |= DEL_REQ_FLAG_USR_VRFY; 1380 break; 1381 } 1382 break; 1383 case 'f': 1384 sender = optarg; 1385 break; 1386 case 'i': 1387 flags &= ~SM_FLAG_AEOF; 1388 break; 1389 case 'o': 1390 switch (*optarg) { 1391 default: 1392 if (msg_verbose) 1393 msg_info("-%c%c option ignored", c, *optarg); 1394 break; 1395 case 'A': 1396 if (optarg[1] == 0) 1397 msg_fatal_status(EX_USAGE, "-oA requires pathname"); 1398 alias_map_from_args = optarg + 1; 1399 break; 1400 case '7': 1401 case '8': 1402 break; 1403 case 'i': 1404 flags &= ~SM_FLAG_AEOF; 1405 break; 1406 case 'm': 1407 break; 1408 } 1409 break; 1410 case 'r': /* obsoleted by -f */ 1411 sender = optarg; 1412 break; 1413 case 'q': 1414 if (ISDIGIT(optarg[0])) { 1415 qtime = optarg; 1416 } else if (optarg[0] == 'R') { 1417 site_to_flush = optarg + 1; 1418 if (*site_to_flush == 0) 1419 msg_fatal_status(EX_USAGE, "specify: -qRsitename"); 1420 } else if (optarg[0] == 'I') { 1421 id_to_flush = optarg + 1; 1422 if (*id_to_flush == 0) 1423 msg_fatal_status(EX_USAGE, "specify: -qIqueueid"); 1424 } else { 1425 msg_fatal_status(EX_USAGE, "-q%c is not implemented", 1426 optarg[0]); 1427 } 1428 break; 1429 case 't': 1430 flags |= SM_FLAG_XRCPT; 1431 break; 1432 case 'v': 1433 msg_verbose++; 1434 break; 1435 case '?': 1436 msg_fatal_status(EX_USAGE, "usage: %s [options]", argv[0]); 1437 } 1438 } 1439 1440 /* 1441 * Look for conflicting options and arguments. 1442 */ 1443 if ((flags & SM_FLAG_XRCPT) && mode != SM_MODE_ENQUEUE) 1444 msg_fatal_status(EX_USAGE, "-t can be used only in delivery mode"); 1445 1446 if (site_to_flush && mode != SM_MODE_ENQUEUE) 1447 msg_fatal_status(EX_USAGE, "-qR can be used only in delivery mode"); 1448 1449 if (id_to_flush && mode != SM_MODE_ENQUEUE) 1450 msg_fatal_status(EX_USAGE, "-qI can be used only in delivery mode"); 1451 1452 if (flags & DEL_REQ_FLAG_USR_VRFY) { 1453 if (flags & SM_FLAG_XRCPT) 1454 msg_fatal_status(EX_USAGE, "-t option cannot be used with -bv"); 1455 if (dsn_notify) 1456 msg_fatal_status(EX_USAGE, "-N option cannot be used with -bv"); 1457 if (dsn_ret) 1458 msg_fatal_status(EX_USAGE, "-R option cannot be used with -bv"); 1459 if (msg_verbose == 1) 1460 msg_fatal_status(EX_USAGE, "-v option cannot be used with -bv"); 1461 } 1462 1463 /* 1464 * The -v option plays double duty. One requests verbose delivery, more 1465 * than one requests verbose logging. 1466 */ 1467 if (msg_verbose == 1 && mode == SM_MODE_ENQUEUE) { 1468 msg_verbose = 0; 1469 flags |= DEL_REQ_FLAG_RECORD; 1470 } 1471 1472 /* 1473 * Start processing. Everything is delegated to external commands. 1474 */ 1475 if (qtime && mode != SM_MODE_DAEMON) 1476 exit(0); 1477 switch (mode) { 1478 default: 1479 msg_panic("unknown operation mode: %d", mode); 1480 /* NOTREACHED */ 1481 case SM_MODE_ENQUEUE: 1482 if (site_to_flush) { 1483 if (argv[OPTIND]) 1484 msg_fatal_status(EX_USAGE, "flush site requires no recipient"); 1485 ext_argv = argv_alloc(2); 1486 argv_add(ext_argv, "postqueue", "-s", site_to_flush, (char *) 0); 1487 for (n = 0; n < msg_verbose; n++) 1488 argv_add(ext_argv, "-v", (char *) 0); 1489 argv_terminate(ext_argv); 1490 mail_run_replace(var_command_dir, ext_argv->argv); 1491 /* NOTREACHED */ 1492 } else if (id_to_flush) { 1493 if (argv[OPTIND]) 1494 msg_fatal_status(EX_USAGE, "flush queue_id requires no recipient"); 1495 ext_argv = argv_alloc(2); 1496 argv_add(ext_argv, "postqueue", "-i", id_to_flush, (char *) 0); 1497 for (n = 0; n < msg_verbose; n++) 1498 argv_add(ext_argv, "-v", (char *) 0); 1499 argv_terminate(ext_argv); 1500 mail_run_replace(var_command_dir, ext_argv->argv); 1501 /* NOTREACHED */ 1502 } else { 1503 enqueue(flags, encoding, dsn_envid, dsn_ret, dsn_notify, 1504 rewrite_context, sender, full_name, argv + OPTIND); 1505 exit(0); 1506 /* NOTREACHED */ 1507 } 1508 break; 1509 case SM_MODE_MAILQ: 1510 if (argv[OPTIND]) 1511 msg_fatal_status(EX_USAGE, 1512 "display queue mode requires no recipient"); 1513 ext_argv = argv_alloc(2); 1514 argv_add(ext_argv, "postqueue", "-p", (char *) 0); 1515 for (n = 0; n < msg_verbose; n++) 1516 argv_add(ext_argv, "-v", (char *) 0); 1517 argv_terminate(ext_argv); 1518 mail_run_replace(var_command_dir, ext_argv->argv); 1519 /* NOTREACHED */ 1520 case SM_MODE_FLUSHQ: 1521 if (argv[OPTIND]) 1522 msg_fatal_status(EX_USAGE, 1523 "flush queue mode requires no recipient"); 1524 ext_argv = argv_alloc(2); 1525 argv_add(ext_argv, "postqueue", "-f", (char *) 0); 1526 for (n = 0; n < msg_verbose; n++) 1527 argv_add(ext_argv, "-v", (char *) 0); 1528 argv_terminate(ext_argv); 1529 mail_run_replace(var_command_dir, ext_argv->argv); 1530 /* NOTREACHED */ 1531 case SM_MODE_DAEMON: 1532 if (argv[OPTIND]) 1533 msg_fatal_status(EX_USAGE, "daemon mode requires no recipient"); 1534 ext_argv = argv_alloc(2); 1535 argv_add(ext_argv, "postfix", (char *) 0); 1536 for (n = 0; n < msg_verbose; n++) 1537 argv_add(ext_argv, "-v", (char *) 0); 1538 argv_add(ext_argv, "start", (char *) 0); 1539 argv_terminate(ext_argv); 1540 err = (mail_run_background(var_command_dir, ext_argv->argv) < 0); 1541 argv_free(ext_argv); 1542 exit(err); 1543 break; 1544 case SM_MODE_NEWALIAS: 1545 if (argv[OPTIND]) 1546 msg_fatal_status(EX_USAGE, 1547 "alias initialization mode requires no recipient"); 1548 if (alias_map_from_args == 0 && *var_alias_db_map == 0) 1549 return (0); 1550 ext_argv = argv_alloc(3); 1551 argv_add(ext_argv, "postalias", (char *) 0); 1552 for (n = 0; n < msg_verbose; n++) 1553 argv_add(ext_argv, "-v", (char *) 0); 1554 argv_add(ext_argv, "--", (char *) 0); 1555 if (alias_map_from_args != 0) 1556 argv_add(ext_argv, alias_map_from_args, (char *) 0); 1557 else 1558 argv_split_append(ext_argv, var_alias_db_map, CHARS_COMMA_SP); 1559 argv_terminate(ext_argv); 1560 mail_run_replace(var_command_dir, ext_argv->argv); 1561 /* NOTREACHED */ 1562 case SM_MODE_USER: 1563 if (argv[OPTIND]) 1564 msg_fatal_status(EX_USAGE, 1565 "stand-alone mode requires no recipient"); 1566 /* The actual enforcement happens in the postdrop command. */ 1567 if ((errstr = check_user_acl_byuid(VAR_SUBMIT_ACL, var_submit_acl, 1568 uid = getuid())) != 0) 1569 msg_fatal_status(EX_NOPERM, 1570 "User %s(%ld) is not allowed to submit mail", 1571 errstr, (long) uid); 1572 ext_argv = argv_alloc(2); 1573 argv_add(ext_argv, "smtpd", "-S", (char *) 0); 1574 for (n = 0; n < msg_verbose; n++) 1575 argv_add(ext_argv, "-v", (char *) 0); 1576 argv_terminate(ext_argv); 1577 mail_run_replace(var_daemon_dir, ext_argv->argv); 1578 /* NOTREACHED */ 1579 case SM_MODE_IGNORE: 1580 exit(0); 1581 /* NOTREACHED */ 1582 } 1583 } 1584