Home | History | Annotate | Line # | Download | only in sendmail
      1 /*	$NetBSD: sendmail.c,v 1.6 2026/05/09 18:49:20 christos Exp $	*/
      2 
      3 /*++
      4 /* NAME
      5 /*	sendmail 1
      6 /* SUMMARY
      7 /*	Postfix to Sendmail compatibility interface
      8 /* SYNOPSIS
      9 /*	\fBsendmail\fR [\fIoption ...\fR] [\fIrecipient ...\fR]
     10 /*
     11 /*	\fBmailq\fR
     12 /*	\fBsendmail -bp\fR
     13 /*
     14 /*	\fBnewaliases\fR
     15 /*	\fBsendmail -I\fR
     16 /* DESCRIPTION
     17 /*	The Postfix \fBsendmail\fR(1) command implements the Postfix
     18 /*	to Sendmail compatibility interface.
     19 /*	For the sake of compatibility with existing applications, some
     20 /*	Sendmail command-line options are recognized but silently ignored.
     21 /*
     22 /*	By default, Postfix \fBsendmail\fR(1) reads a message from
     23 /*	standard input
     24 /*	until EOF or until it reads a line with only a \fB.\fR character,
     25 /*	and arranges for delivery.  Postfix \fBsendmail\fR(1) relies on the
     26 /*	\fBpostdrop\fR(1) command to create a queue file in the \fBmaildrop\fR
     27 /*	directory.
     28 /*
     29 /*	Specific command aliases are provided for other common modes of
     30 /*	operation:
     31 /* .IP \fBmailq\fR
     32 /*	List the mail queue. Each entry shows the queue file ID, message
     33 /*	size, arrival time, sender, and the recipients that still need to
     34 /*	be delivered.  If mail could not be delivered upon the last attempt,
     35 /*	the reason for failure is shown. The queue ID string is
     36 /*	followed by an optional status character:
     37 /* .RS
     38 /* .IP \fB*\fR
     39 /*	The message is in the \fBactive\fR queue, i.e. the message is
     40 /*	selected for delivery.
     41 /* .IP \fB!\fR
     42 /*	The message is in the \fBhold\fR queue, i.e. no further delivery
     43 /*	attempt will be made until the mail is taken off hold.
     44 /* .IP \fB#\fR
     45 /*	The message is forced to expire. See the \fBpostsuper\fR(1)
     46 /*	options \fB-e\fR or \fB-f\fR.
     47 /* .RE
     48 /* .IP
     49 /*	This mode of operation is implemented by executing the
     50 /*	\fBpostqueue\fR(1) command.
     51 /* .IP \fBnewaliases\fR
     52 /*	Initialize the alias database.  If no input file is specified (with
     53 /*	the \fB-oA\fR option, see below), the program processes the file(s)
     54 /*	specified with the \fBalias_database\fR configuration parameter.
     55 /*	If no alias database type is specified, the program uses the type
     56 /*	specified with the \fBdefault_database_type\fR configuration parameter.
     57 /*	This mode of operation is implemented by running the \fBpostalias\fR(1)
     58 /*	command.
     59 /* .sp
     60 /*	Note: it may take a minute or so before an alias database update
     61 /*	becomes visible. Use the "\fBpostfix reload\fR" command to eliminate
     62 /*	this delay.
     63 /* .PP
     64 /*	These and other features can be selected by specifying the
     65 /*	appropriate combination of command-line options. Some features are
     66 /*	controlled by parameters in the \fBmain.cf\fR configuration file.
     67 /*
     68 /*	The following options are recognized:
     69 /* .IP "\fB-Am\fR (ignored)"
     70 /* .IP "\fB-Ac\fR (ignored)"
     71 /*	Postfix sendmail uses the same configuration file regardless of
     72 /*	whether or not a message is an initial submission.
     73 /* .IP "\fB-B \fIbody_type\fR"
     74 /*	The message body MIME type: \fB7BIT\fR or \fB8BITMIME\fR.
     75 /* .IP \fB-bd\fR
     76 /*	Go into daemon mode. This mode of operation is implemented by
     77 /*	executing the "\fBpostfix start\fR" command.
     78 /* .IP "\fB-bh\fR (ignored)"
     79 /* .IP "\fB-bH\fR (ignored)"
     80 /*	Postfix has no persistent host status database.
     81 /* .IP \fB-bi\fR
     82 /*	Initialize alias database. See the \fBnewaliases\fR
     83 /*	command above.
     84 /* .IP \fB-bl\fR
     85 /*	Go into daemon mode. To accept only local connections as
     86 /*	with Sendmail's \fB-bl\fR option, specify "\fBinet_interfaces
     87 /*	= loopback\fR" in the Postfix \fBmain.cf\fR configuration
     88 /*	file.
     89 /* .IP \fB-bm\fR
     90 /*	Read mail from standard input and arrange for delivery.
     91 /*	This is the default mode of operation.
     92 /* .IP \fB-bp\fR
     93 /*	List the mail queue. See the \fBmailq\fR command above.
     94 /* .IP \fB-bs\fR
     95 /*	Stand-alone SMTP server mode. Read SMTP commands from
     96 /*	standard input, and write responses to standard output.
     97 /*	In stand-alone SMTP server mode, mail relaying and other
     98 /*	access controls are disabled by default. To enable them,
     99 /*	run the process as the \fBmail_owner\fR user.
    100 /* .sp
    101 /*	This mode of operation is implemented by running the
    102 /*	\fBsmtpd\fR(8) daemon.
    103 /* .IP \fB-bv\fR
    104 /*	Do not collect or deliver a message. Instead, send an email
    105 /*	report after verifying each recipient address.  This is useful
    106 /*	for testing address rewriting and routing configurations.
    107 /* .sp
    108 /*	This feature is available in Postfix version 2.1 and later.
    109 /* .IP "\fB-C \fIconfig_file\fR"
    110 /* .IP "\fB-C \fIconfig_dir\fR"
    111 /*	The path name of the Postfix \fBmain.cf\fR file, or of its
    112 /*	parent directory. This information is ignored with Postfix
    113 /*	versions before 2.3.
    114 /*
    115 /*	With Postfix version 3.2 and later, a non-default directory
    116 /*	must be authorized in the default \fBmain.cf\fR file, through
    117 /*	the alternate_config_directories or multi_instance_directories
    118 /*	parameters.
    119 /*
    120 /*	With all Postfix versions, you can specify a directory pathname
    121 /*	with the MAIL_CONFIG environment variable to override the
    122 /*	location of configuration files.
    123 /* .IP "\fB-F \fIfull_name\fR"
    124 /*	Set the sender full name. This overrides the NAME environment
    125 /*	variable, and is used only with messages that
    126 /*	have no \fBFrom:\fR message header.
    127 /* .IP "\fB-f \fIsender\fR"
    128 /*	Set the envelope sender address. This is the address where
    129 /*	delivery problems are sent to. With Postfix versions before 2.1, the
    130 /*	\fBErrors-To:\fR message header overrides the error return address.
    131 /* .IP \fB-G\fR
    132 /*	Gateway (relay) submission, as opposed to initial user
    133 /*	submission.  Either do not rewrite addresses at all, or
    134 /*	update incomplete addresses with the domain information
    135 /*	specified with \fBremote_header_rewrite_domain\fR.
    136 /*
    137 /*	This option is ignored before Postfix version 2.3.
    138 /* .IP "\fB-h \fIhop_count\fR (ignored)"
    139 /*	Hop count limit. Use the \fBhopcount_limit\fR configuration
    140 /*	parameter instead.
    141 /* .IP \fB-I\fR
    142 /*	Initialize alias database. See the \fBnewaliases\fR
    143 /*	command above.
    144 /* .IP "\fB-i\fR"
    145 /*	When reading a message from standard input, don't treat a line
    146 /*	with only a \fB.\fR character as the end of input.
    147 /* .IP "\fB-L \fIlabel\fR (ignored)"
    148 /*	The logging label. Use the \fBsyslog_name\fR configuration
    149 /*	parameter instead.
    150 /* .IP "\fB-m\fR (ignored)"
    151 /*	Backwards compatibility.
    152 /* .IP "\fB-N \fIdsn\fR (default: 'delay, failure')"
    153 /*	Delivery status notification control. Specify either a
    154 /*	comma-separated list with one or more of \fBfailure\fR (send
    155 /*	notification when delivery fails), \fBdelay\fR (send
    156 /*	notification when delivery is delayed), or \fBsuccess\fR
    157 /*	(send notification when the message is delivered); or specify
    158 /*	\fBnever\fR (don't send any notifications at all).
    159 /*
    160 /*	This feature is available in Postfix 2.3 and later.
    161 /* .IP "\fB-n\fR (ignored)"
    162 /*	Backwards compatibility.
    163 /* .IP "\fB-O requiretls=yes\fR"
    164 /* .IP "\fB-O requiretls=no\fR"
    165 /*	When delivering a message to an SMTP or LMTP server, the
    166 /*	connection must use TLS with a verified server certificate,
    167 /*	and that server must support REQUIRETLS. The "requiretls" name
    168 /*	and option value are case-insensitive. REQUIRETLS enforcement
    169 /*	is controlled with the configuration parameters requiretls_enable,
    170 /*	smtp_requiretls_policy, and lmtp_requiretls_policy.
    171 /*
    172 /*	This feature is available in Postfix 3.11 and later.
    173 /* .IP "\fB-O smtputf8=yes\fR"
    174 /* .IP "\fB-O smtputf8=no\fR"
    175 /*	When delivering a message to an SMTP or LMTP server, and an
    176 /*	envelope address or message header contains UTF8 text, that server
    177 /*	must support SMTPUTF8. The "smtputf8" option name and value
    178 /*	are case-insensitive.
    179 /*
    180 /*	This feature is available in Postfix 3.11 and later.
    181 /* .IP "\fB-O \fIoption=value\fR (ignored)"
    182 /*	Set the named \fIoption\fR to \fIvalue\fR. Use the equivalent
    183 /*	configuration parameter in \fBmain.cf\fR instead.
    184 /* .IP "\fB-oA\fIalias_database\fR"
    185 /*	Non-default alias database. Specify \fIpathname\fR or
    186 /*	\fItype\fR:\fIpathname\fR. See \fBpostalias\fR(1) for details.
    187 /* .IP "\fB-o7\fR (ignored)"
    188 /* .IP "\fB-o8\fR (ignored)"
    189 /*	To send 8-bit or binary content, use an appropriate MIME encapsulation
    190 /*	and specify the appropriate \fB-B\fR command-line option.
    191 /* .IP "\fB-oi\fR"
    192 /*	When reading a message from standard input, don't treat a line
    193 /*	with only a \fB.\fR character as the end of input.
    194 /* .IP "\fB-om\fR (ignored)"
    195 /*	The sender is never eliminated from alias etc. expansions.
    196 /* .IP "\fB-o \fIx value\fR (ignored)"
    197 /*	Set option \fIx\fR to \fIvalue\fR. Use the equivalent
    198 /*	configuration parameter in \fBmain.cf\fR instead.
    199 /* .IP "\fB-r \fIsender\fR"
    200 /*	Set the envelope sender address. This is the address where
    201 /*	delivery problems are sent to. With Postfix versions before 2.1, the
    202 /*	\fBErrors-To:\fR message header overrides the error return address.
    203 /* .IP "\fB-R \fIreturn\fR"
    204 /*	Delivery status notification control.  Specify "hdrs" to
    205 /*	return only the header when a message bounces, "full" to
    206 /*	return a full copy (the default behavior).
    207 /*
    208 /*	The \fB-R\fR option specifies an upper bound; Postfix will
    209 /*	return only the header, when a full copy would exceed the
    210 /*	bounce_size_limit setting.
    211 /*
    212 /*	This option is ignored before Postfix version 2.10.
    213 /* .IP \fB-q\fR
    214 /*	Attempt to deliver all queued mail. This is implemented by
    215 /*	executing the \fBpostqueue\fR(1) command.
    216 /*
    217 /*	Warning: flushing undeliverable mail frequently will result in
    218 /*	poor delivery performance of all other mail.
    219 /* .IP "\fB-q\fIinterval\fR (ignored)"
    220 /*	The interval between queue runs. Use the \fBqueue_run_delay\fR
    221 /*	configuration parameter instead.
    222 /* .IP \fB-qI\fIqueueid\fR
    223 /*	Schedule immediate delivery of mail with the specified queue
    224 /*	ID.  This option is implemented by executing the
    225 /*	\fBpostqueue\fR(1) command, and is available with Postfix
    226 /*	version 2.4 and later.
    227 /* .IP \fB-qR\fIsite\fR
    228 /*	Schedule immediate delivery of all mail that is queued for the named
    229 /*	\fIsite\fR. This option accepts only \fIsite\fR names that are
    230 /*	eligible for the "fast flush" service, and is implemented by
    231 /*	executing the \fBpostqueue\fR(1) command.
    232 /*	See \fBflush\fR(8) for more information about the "fast flush"
    233 /*	service.
    234 /* .IP \fB-qS\fIsite\fR
    235 /*	This command is not implemented. Use the slower "\fBsendmail -q\fR"
    236 /*	command instead.
    237 /* .IP \fB-t\fR
    238 /*	Extract recipients from message headers. These are added to any
    239 /*	recipients specified on the command line.
    240 /*
    241 /*	With Postfix versions prior to 2.1, this option requires that
    242 /*	no recipient addresses are specified on the command line.
    243 /* .IP "\fB-U\fR (ignored)"
    244 /*	Initial user submission.
    245 /* .IP "\fB-V \fIenvid\fR"
    246 /*	Specify the envelope ID for notification by servers that
    247 /*	support DSN.
    248 /*
    249 /*	This feature is available in Postfix 2.3 and later.
    250 /* .IP "\fB-XV\fR (Postfix 2.2 and earlier: \fB-V\fR)"
    251 /*	Variable Envelope Return Path. Given an envelope sender address
    252 /*	of the form \fIowner-listname\fR@\fIorigin\fR, each recipient
    253 /*	\fIuser\fR@\fIdomain\fR receives mail with a personalized envelope
    254 /*	sender address.
    255 /* .sp
    256 /*	By default, the personalized envelope sender address is
    257 /*	\fIowner-listname\fB+\fIuser\fB=\fIdomain\fR@\fIorigin\fR. The default
    258 /*	\fB+\fR and \fB=\fR characters are configurable with the
    259 /*	\fBdefault_verp_delimiters\fR configuration parameter.
    260 /* .IP "\fB-XV\fIxy\fR (Postfix 2.2 and earlier: \fB-V\fIxy\fR)"
    261 /*	As \fB-XV\fR, but uses \fIx\fR and \fIy\fR as the VERP delimiter
    262 /*	characters, instead of the characters specified with the
    263 /*	\fBdefault_verp_delimiters\fR configuration parameter.
    264 /* .IP \fB-v\fR
    265 /*	Send an email report of the first delivery attempt (Postfix
    266 /*	versions 2.1 and later). Mail delivery
    267 /*	always happens in the background. When multiple \fB-v\fR
    268 /*	options are given, enable verbose logging for debugging purposes.
    269 /* .IP "\fB-X \fIlog_file\fR (ignored)"
    270 /*	Log mailer traffic. Use the \fBdebug_peer_list\fR and
    271 /*	\fBdebug_peer_level\fR configuration parameters instead.
    272 /* SECURITY
    273 /* .ad
    274 /* .fi
    275 /*	By design, this program is not set-user (or group) id.
    276 /*	It is prepared to handle message content from untrusted,
    277 /*	possibly remote, users.
    278 /*
    279 /*	However, like most Postfix programs, this program does not
    280 /*	enforce a security policy on its command-line arguments.
    281 /*	Instead, it relies on the UNIX system to enforce access
    282 /*	policies based on the effective user and group IDs of the
    283 /*	process. Concretely, this means that running Postfix commands
    284 /*	as root (from sudo or equivalent) on behalf of a non-root
    285 /*	user is likely to create privilege escalation opportunities.
    286 /*
    287 /*	If an application runs any Postfix programs on behalf of
    288 /*	users that do not have normal shell access to Postfix
    289 /*	commands, then that application MUST restrict user-specified
    290 /*	command-line arguments to avoid privilege escalation.
    291 /* .IP \(bu
    292 /*	Filter all command-line arguments, for example arguments
    293 /*	that contain a pathname or that specify a database access
    294 /*	method. These pathname checks must reject user-controlled
    295 /*	symlinks or hardlinks to sensitive files, and must not be
    296 /*	vulnerable to TOCTOU race attacks.
    297 /* .IP \(bu
    298 /*	Disable command options processing for all command arguments
    299 /*	that contain user-specified data. For example, the Postfix
    300 /*	\fBsendmail\fR(1) command line MUST be structured as follows:
    301 /*
    302 /* .nf
    303 /*	    \fB/path/to/sendmail\fR \fIsystem-arguments\fR \fB--\fR \fIuser-arguments\fR
    304 /* .fi
    305 /*
    306 /*	Here, the "\fB--\fR" disables command option processing for
    307 /*	all \fIuser-arguments\fR that follow.
    308 /* .IP
    309 /*	Without the "\fB--\fR", a malicious user could enable Postfix
    310 /*	\fBsendmail\fR(1) command options, by specifying an email
    311 /*	address that starts with "\fB-\fR".
    312 /* DIAGNOSTICS
    313 /*	Problems are logged to \fBsyslogd\fR(8) or \fBpostlogd\fR(8),
    314 /*	and to the standard error stream.
    315 /* ENVIRONMENT
    316 /* .ad
    317 /* .fi
    318 /* .IP \fBMAIL_CONFIG\fR
    319 /*	Directory with Postfix configuration files.
    320 /* .IP "\fBMAIL_VERBOSE\fR (value does not matter)"
    321 /*	Enable verbose logging for debugging purposes.
    322 /* .IP "\fBMAIL_DEBUG\fR (value does not matter)"
    323 /*	Enable debugging with an external command, as specified with the
    324 /*	\fBdebugger_command\fR configuration parameter.
    325 /* .IP \fBNAME\fR
    326 /*	The sender full name. This is used only with messages that
    327 /*	have no \fBFrom:\fR message header. See also the \fB-F\fR
    328 /*	option above.
    329 /* CONFIGURATION PARAMETERS
    330 /* .ad
    331 /* .fi
    332 /*	The following \fBmain.cf\fR parameters are especially relevant to
    333 /*	this program.
    334 /*	The text below provides only a parameter summary. See
    335 /*	\fBpostconf\fR(5) for more details including examples.
    336 /* COMPATIBILITY CONTROLS
    337 /* .ad
    338 /* .fi
    339 /*	Available with Postfix 2.9 and later:
    340 /* .IP "\fBsendmail_fix_line_endings (always)\fR"
    341 /*	Controls how the Postfix sendmail command converts email message
    342 /*	line endings from <CR><LF> into UNIX format (<LF>).
    343 /* TROUBLE SHOOTING CONTROLS
    344 /* .ad
    345 /* .fi
    346 /*	The DEBUG_README file gives examples of how to troubleshoot a
    347 /*	Postfix system.
    348 /* .IP "\fBdebugger_command (empty)\fR"
    349 /*	The external command to execute when a Postfix daemon program is
    350 /*	invoked with the -D option.
    351 /* .IP "\fBdebug_peer_level (2)\fR"
    352 /*	The increment in verbose logging level when a nexthop destination,
    353 /*	remote client or server name or network address matches a pattern
    354 /*	given with the debug_peer_list parameter.
    355 /* .IP "\fBdebug_peer_list (empty)\fR"
    356 /*	Optional list of nexthop destination, remote client or server
    357 /*	name or network address patterns that, if matched, cause the verbose
    358 /*	logging level to increase by the amount specified in $debug_peer_level.
    359 /* ACCESS CONTROLS
    360 /* .ad
    361 /* .fi
    362 /*	Available in Postfix version 2.2 and later:
    363 /* .IP "\fBauthorized_flush_users (static:anyone)\fR"
    364 /*	List of users who are authorized to flush the queue.
    365 /* .IP "\fBauthorized_mailq_users (static:anyone)\fR"
    366 /*	List of users who are authorized to view the queue.
    367 /* .IP "\fBauthorized_submit_users (static:anyone)\fR"
    368 /*	List of users who are authorized to submit mail with the \fBsendmail\fR(1)
    369 /*	command (and with the privileged \fBpostdrop\fR(1) helper command).
    370 /* RESOURCE AND RATE CONTROLS
    371 /* .ad
    372 /* .fi
    373 /* .IP "\fBbounce_size_limit (50000)\fR"
    374 /*	The maximal amount of original message text that is sent in a
    375 /*	non-delivery notification.
    376 /* .IP "\fBfork_attempts (5)\fR"
    377 /*	The maximal number of attempts to fork() a child process.
    378 /* .IP "\fBfork_delay (1s)\fR"
    379 /*	The delay between attempts to fork() a child process.
    380 /* .IP "\fBhopcount_limit (50)\fR"
    381 /*	The maximal number of Received:  message headers that is allowed
    382 /*	in the primary message headers.
    383 /* .IP "\fBqueue_run_delay (300s)\fR"
    384 /*	The time between deferred queue scans by the queue manager;
    385 /*	prior to Postfix 2.4 the default value was 1000s.
    386 /* FAST FLUSH CONTROLS
    387 /* .ad
    388 /* .fi
    389 /*	The ETRN_README file describes configuration and operation
    390 /*	details for the Postfix "fast flush" service.
    391 /* .IP "\fBfast_flush_domains ($relay_domains)\fR"
    392 /*	Optional list of destinations that are eligible for per-destination
    393 /*	logfiles with mail that is queued to those destinations.
    394 /* VERP CONTROLS
    395 /* .ad
    396 /* .fi
    397 /*	The VERP_README file describes configuration and operation
    398 /*	details of Postfix support for variable envelope return
    399 /*	path addresses.
    400 /* .IP "\fBdefault_verp_delimiters (+=)\fR"
    401 /*	The two default VERP delimiter characters.
    402 /* .IP "\fBverp_delimiter_filter (-=+)\fR"
    403 /*	The characters Postfix accepts as VERP delimiter characters on the
    404 /*	Postfix \fBsendmail\fR(1) command line and in SMTP commands.
    405 /* MISCELLANEOUS CONTROLS
    406 /* .ad
    407 /* .fi
    408 /* .IP "\fBalias_database (see 'postconf -d' output)\fR"
    409 /*	The alias databases for \fBlocal\fR(8) delivery that are updated with
    410 /*	"\fBnewaliases\fR" or with "\fBsendmail -bi\fR".
    411 /* .IP "\fBcommand_directory (see 'postconf -d' output)\fR"
    412 /*	The location of all postfix administrative commands.
    413 /* .IP "\fBconfig_directory (see 'postconf -d' output)\fR"
    414 /*	The default location of the Postfix main.cf and master.cf
    415 /*	configuration files.
    416 /* .IP "\fBdaemon_directory (see 'postconf -d' output)\fR"
    417 /*	The directory with Postfix support programs and daemon programs.
    418 /* .IP "\fBdefault_database_type (see 'postconf -d' output)\fR"
    419 /*	The default database type for use in \fBnewaliases\fR(1), \fBpostalias\fR(1)
    420 /*	and \fBpostmap\fR(1) commands.
    421 /* .IP "\fBdelay_warning_time (0h)\fR"
    422 /*	The time after which the sender receives a copy of the message
    423 /*	headers of mail that is still queued.
    424 /* .IP "\fBimport_environment (see 'postconf -d' output)\fR"
    425 /*	The list of environment variables that a privileged Postfix
    426 /*	process will import from a non-Postfix parent process, or name=value
    427 /*	environment overrides.
    428 /* .IP "\fBmail_owner (postfix)\fR"
    429 /*	The UNIX system account that owns the Postfix queue and most Postfix
    430 /*	daemon processes.
    431 /* .IP "\fBqueue_directory (see 'postconf -d' output)\fR"
    432 /*	The location of the Postfix top-level queue directory.
    433 /* .IP "\fBremote_header_rewrite_domain (empty)\fR"
    434 /*	Rewrite or add message headers in mail from remote clients if
    435 /*	the remote_header_rewrite_domain parameter value is non-empty,
    436 /*	updating incomplete addresses with the domain specified in the
    437 /*	remote_header_rewrite_domain parameter, and adding missing headers.
    438 /* .IP "\fBsyslog_facility (mail)\fR"
    439 /*	The syslog facility of Postfix logging.
    440 /* .IP "\fBsyslog_name (see 'postconf -d' output)\fR"
    441 /*	A prefix that is prepended to the process name in syslog
    442 /*	records, so that, for example, "smtpd" becomes "prefix/smtpd".
    443 /* .PP
    444 /*	Postfix 3.2 and later:
    445 /* .IP "\fBalternate_config_directories (empty)\fR"
    446 /*	A list of non-default Postfix configuration directories that may
    447 /*	be specified with "-c config_directory" on the command line (in the
    448 /*	case of \fBsendmail\fR(1), with the "-C" option), or via the MAIL_CONFIG
    449 /*	environment parameter.
    450 /* .IP "\fBmulti_instance_directories (empty)\fR"
    451 /*	An optional list of non-default Postfix configuration directories;
    452 /*	these directories belong to additional Postfix instances that share
    453 /*	the Postfix executable files and documentation with the default
    454 /*	Postfix instance, and that are started, stopped, etc., together
    455 /*	with the default Postfix instance.
    456 /* .PP
    457 /*	Postfix 3.11 and later:
    458 /* .IP "\fBrequiretls_enable (yes)\fR"
    459 /*	Enable support for the ESMTP verb "REQUIRETLS" in the "MAIL
    460 /*	FROM" command.
    461 /* FILES
    462 /*	/var/spool/postfix, mail queue
    463 /*	/etc/postfix, configuration files
    464 /* SEE ALSO
    465 /*	pickup(8), mail pickup daemon
    466 /*	qmgr(8), queue manager
    467 /*	smtpd(8), SMTP server
    468 /*	flush(8), fast flush service
    469 /*	postsuper(1), queue maintenance
    470 /*	postalias(1), create/update/query alias database
    471 /*	postdrop(1), mail posting utility
    472 /*	postfix(1), mail system control
    473 /*	postqueue(1), mail queue control
    474 /*	postlogd(8), Postfix logging
    475 /*	syslogd(8), system logging
    476 /* README_FILES
    477 /* .ad
    478 /* .fi
    479 /*	Use "\fBpostconf readme_directory\fR" or
    480 /*	"\fBpostconf html_directory\fR" to locate this information.
    481 /* .na
    482 /* .nf
    483 /*	DEBUG_README, Postfix debugging howto
    484 /*	ETRN_README, Postfix ETRN howto
    485 /*	VERP_README, Postfix VERP howto
    486 /* LICENSE
    487 /* .ad
    488 /* .fi
    489 /*	The Secure Mailer license must be distributed with this software.
    490 /* AUTHOR(S)
    491 /*	Wietse Venema
    492 /*	IBM T.J. Watson Research
    493 /*	P.O. Box 704
    494 /*	Yorktown Heights, NY 10598, USA
    495 /*
    496 /*	Wietse Venema
    497 /*	Google, Inc.
    498 /*	111 8th Avenue
    499 /*	New York, NY 10011, USA
    500 /*--*/
    501 
    502 /* System library. */
    503 
    504 #include <sys_defs.h>
    505 #include <sys/stat.h>
    506 #include <unistd.h>
    507 #include <string.h>
    508 #include <stdio.h>			/* remove() */
    509 #include <stdlib.h>
    510 #include <signal.h>
    511 #include <fcntl.h>
    512 #include <time.h>
    513 #include <errno.h>
    514 #include <ctype.h>
    515 #include <stdarg.h>
    516 #include <sysexits.h>
    517 
    518 /* Utility library. */
    519 
    520 #include <msg.h>
    521 #include <mymalloc.h>
    522 #include <vstream.h>
    523 #include <msg_vstream.h>
    524 #include <vstring_vstream.h>
    525 #include <username.h>
    526 #include <fullname.h>
    527 #include <argv.h>
    528 #include <safe.h>
    529 #include <iostuff.h>
    530 #include <stringops.h>
    531 #include <set_ugid.h>
    532 #include <connect.h>
    533 #include <split_at.h>
    534 #include <name_code.h>
    535 #include <warn_stat.h>
    536 #include <clean_env.h>
    537 #include <maillog_client.h>
    538 
    539 /* Global library. */
    540 
    541 #include <mail_queue.h>
    542 #include <mail_proto.h>
    543 #include <mail_params.h>
    544 #include <mail_version.h>
    545 #include <record.h>
    546 #include <rec_type.h>
    547 #include <rec_streamlf.h>
    548 #include <mail_conf.h>
    549 #include <cleanup_user.h>
    550 #include <mail_task.h>
    551 #include <mail_run.h>
    552 #include <debug_process.h>
    553 #include <tok822.h>
    554 #include <mail_flush.h>
    555 #include <mail_stream.h>
    556 #include <verp_sender.h>
    557 #include <deliver_request.h>
    558 #include <mime_state.h>
    559 #include <header_opts.h>
    560 #include <mail_dict.h>
    561 #include <user_acl.h>
    562 #include <dsn_mask.h>
    563 #include <mail_parm_split.h>
    564 #include <sendopts.h>
    565 
    566 /* Application-specific. */
    567 
    568  /*
    569   * Modes of operation.
    570   */
    571 #define SM_MODE_ENQUEUE		1	/* delivery mode */
    572 #define SM_MODE_NEWALIAS	2	/* initialize alias database */
    573 #define SM_MODE_MAILQ		3	/* list mail queue */
    574 #define SM_MODE_DAEMON		4	/* daemon mode */
    575 #define SM_MODE_USER		5	/* user (stand-alone) mode */
    576 #define SM_MODE_FLUSHQ		6	/* user (stand-alone) mode */
    577 #define SM_MODE_IGNORE		7	/* ignore this mode */
    578 
    579  /*
    580   * Flag parade. Flags 8-15 are reserved for delivery request trace flags.
    581   */
    582 #define SM_FLAG_AEOF	(1<<0)		/* archaic EOF */
    583 #define SM_FLAG_XRCPT	(1<<1)		/* extract recipients from headers */
    584 
    585 #define SM_FLAG_DEFAULT	(SM_FLAG_AEOF)
    586 
    587  /*
    588   * VERP support.
    589   */
    590 static char *verp_delims;
    591 
    592  /*
    593   * Callback context for extracting recipients.
    594   */
    595 typedef struct SM_STATE {
    596     VSTREAM *dst;			/* output stream */
    597     ARGV   *recipients;			/* recipients from regular headers */
    598     ARGV   *resent_recip;		/* recipients from resent headers */
    599     int     resent;			/* resent flag */
    600     const char *saved_sender;		/* for error messages */
    601     uid_t   uid;			/* for error messages */
    602     VSTRING *temp;			/* scratch buffer */
    603 } SM_STATE;
    604 
    605  /*
    606   * Mail submission ACL, line-end fixing.
    607   */
    608 char   *var_submit_acl;
    609 char   *var_sm_fix_eol;
    610 
    611 static const CONFIG_STR_TABLE str_table[] = {
    612     VAR_SUBMIT_ACL, DEF_SUBMIT_ACL, &var_submit_acl, 0, 0,
    613     VAR_SM_FIX_EOL, DEF_SM_FIX_EOL, &var_sm_fix_eol, 1, 0,
    614     0,
    615 };
    616 
    617  /*
    618   * Sender options.
    619   */
    620 static int sm_sendopts;
    621 
    622  /*
    623   * Silly little macros (SLMs).
    624   */
    625 #define STR	vstring_str
    626 
    627 /* output_text - output partial or complete text line */
    628 
    629 static void output_text(void *context, int rec_type, const char *buf, ssize_t len,
    630 			        off_t unused_offset)
    631 {
    632     SM_STATE *state = (SM_STATE *) context;
    633 
    634     if (rec_put(state->dst, rec_type, buf, len) < 0)
    635 	msg_fatal_status(EX_TEMPFAIL,
    636 			 "%s(%ld): error writing queue file: %m",
    637 			 state->saved_sender, (long) state->uid);
    638 }
    639 
    640 /* output_header - output one message header */
    641 
    642 static void output_header(void *context, int header_class,
    643 			          const HEADER_OPTS *header_info,
    644 			          VSTRING *buf, off_t offset)
    645 {
    646     SM_STATE *state = (SM_STATE *) context;
    647     TOK822 *tree;
    648     TOK822 **addr_list;
    649     TOK822 **tpp;
    650     ARGV   *rcpt;
    651     char   *start;
    652     char   *line;
    653     char   *next_line;
    654     ssize_t len;
    655 
    656     /*
    657      * Parse the header line, and save copies of recipient addresses in the
    658      * appropriate place.
    659      */
    660     if (header_class == MIME_HDR_PRIMARY
    661 	&& header_info
    662 	&& (header_info->flags & HDR_OPT_RECIP)
    663 	&& (header_info->flags & HDR_OPT_EXTRACT)
    664 	&& (state->resent == 0 || (header_info->flags & HDR_OPT_RR))) {
    665 	if (header_info->flags & HDR_OPT_RR) {
    666 	    rcpt = state->resent_recip;
    667 	    if (state->resent == 0)
    668 		state->resent = 1;
    669 	} else
    670 	    rcpt = state->recipients;
    671 	tree = tok822_parse(STR(buf) + strlen(header_info->name) + 1);
    672 	addr_list = tok822_grep(tree, TOK822_ADDR);
    673 	for (tpp = addr_list; *tpp; tpp++) {
    674 	    tok822_internalize(state->temp, tpp[0]->head, TOK822_STR_DEFL);
    675 	    argv_add(rcpt, STR(state->temp), (char *) 0);
    676 	}
    677 	myfree((void *) addr_list);
    678 	tok822_free_tree(tree);
    679     }
    680 
    681     /*
    682      * Pipe the unmodified message header through the header line folding
    683      * routine, and ensure that long lines are chopped appropriately.
    684      */
    685     for (line = start = STR(buf); line; line = next_line) {
    686 	next_line = split_at(line, '\n');
    687 	len = next_line ? next_line - line - 1 : strlen(line);
    688 	do {
    689 	    if (len > var_line_limit) {
    690 		output_text(context, REC_TYPE_CONT, line, var_line_limit, offset);
    691 		line += var_line_limit;
    692 		len -= var_line_limit;
    693 		offset += var_line_limit;
    694 	    } else {
    695 		output_text(context, REC_TYPE_NORM, line, len, offset);
    696 		offset += len;
    697 		break;
    698 	    }
    699 	} while (len > 0);
    700 	offset += 1;
    701     }
    702 }
    703 
    704 /* enqueue - post one message */
    705 
    706 static void enqueue(const int flags, const char *encoding,
    707 		         const char *dsn_envid, int dsn_ret, int dsn_notify,
    708 		            const char *rewrite_context, const char *sender,
    709 		            const char *full_name, char **recipients)
    710 {
    711     VSTRING *buf;
    712     VSTREAM *dst;
    713     char   *saved_sender;
    714     char  **cpp;
    715     int     type;
    716     char   *start;
    717     int     skip_from_;
    718     TOK822 *tree;
    719     TOK822 *tp;
    720     int     rcpt_count = 0;
    721     enum {
    722 	STRIP_CR_DUNNO, STRIP_CR_DO, STRIP_CR_DONT, STRIP_CR_ERROR
    723     }       strip_cr;
    724     MAIL_STREAM *handle;
    725     VSTRING *postdrop_command;
    726     uid_t   uid = getuid();
    727     int     status;
    728     VSTRING *why;			/* postdrop status message */
    729     int     naddr;
    730     int     prev_type;
    731     MIME_STATE *mime_state = 0;
    732     SM_STATE state;
    733     int     mime_errs;
    734     const char *errstr;
    735     int     addr_count;
    736     int     level;
    737     static NAME_CODE sm_fix_eol_table[] = {
    738 	SM_FIX_EOL_ALWAYS, STRIP_CR_DO,
    739 	SM_FIX_EOL_STRICT, STRIP_CR_DUNNO,
    740 	SM_FIX_EOL_NEVER, STRIP_CR_DONT,
    741 	0, STRIP_CR_ERROR,
    742     };
    743 
    744     /*
    745      * Access control is enforced in the postdrop command. The code here
    746      * merely produces a more user-friendly interface.
    747      */
    748     if ((errstr = check_user_acl_byuid(VAR_SUBMIT_ACL,
    749 				       var_submit_acl, uid)) != 0)
    750 	msg_fatal_status(EX_NOPERM,
    751 	  "User %s(%ld) is not allowed to submit mail", errstr, (long) uid);
    752 
    753     /*
    754      * Initialize.
    755      */
    756     buf = vstring_alloc(100);
    757 
    758     /*
    759      * Stop run-away process accidents by limiting the queue file size. This
    760      * is not a defense against DOS attack.
    761      */
    762     if (ENFORCING_SIZE_LIMIT(var_message_limit)
    763 	&& get_file_limit() > var_message_limit)
    764 	set_file_limit((off_t) var_message_limit);
    765 
    766     /*
    767      * The sender name is provided by the user. In principle, the mail pickup
    768      * service could deduce the sender name from queue file ownership, but:
    769      * pickup would not be able to run chrooted, and it may not be desirable
    770      * to use login names at all.
    771      */
    772     if (sender != 0) {
    773 	VSTRING_RESET(buf);
    774 	VSTRING_TERMINATE(buf);
    775 	tree = tok822_parse(sender);
    776 	for (naddr = 0, tp = tree; tp != 0; tp = tp->next)
    777 	    if (tp->type == TOK822_ADDR && naddr++ == 0)
    778 		tok822_internalize(buf, tp->head, TOK822_STR_DEFL);
    779 	tok822_free_tree(tree);
    780 	saved_sender = mystrdup(STR(buf));
    781 	if (naddr > 1)
    782 	    msg_warn("-f option specified malformed sender: %s", sender);
    783     } else {
    784 	if ((sender = username()) == 0)
    785 	    msg_fatal_status(EX_OSERR, "no login name found for user ID %lu",
    786 			     (unsigned long) uid);
    787 	saved_sender = mystrdup(sender);
    788     }
    789 
    790     /*
    791      * Let the postdrop command open the queue file for us, and sanity check
    792      * the content. XXX Make postdrop a manifest constant.
    793      */
    794     errno = 0;
    795     postdrop_command = vstring_alloc(1000);
    796     vstring_sprintf(postdrop_command, "%s/postdrop -r", var_command_dir);
    797     for (level = 0; level < msg_verbose; level++)
    798 	vstring_strcat(postdrop_command, " -v");
    799     if ((handle = mail_stream_command(STR(postdrop_command))) == 0)
    800 	msg_fatal_status(EX_UNAVAILABLE, "%s(%ld): unable to execute %s: %m",
    801 			 saved_sender, (long) uid, STR(postdrop_command));
    802     vstring_free(postdrop_command);
    803     dst = handle->stream;
    804 
    805     /*
    806      * First, write envelope information to the output stream.
    807      *
    808      * For sendmail compatibility, parse each command-line recipient as if it
    809      * were an RFC 822 message header; some MUAs specify comma-separated
    810      * recipient lists; and some MUAs even specify "word word <address>".
    811      *
    812      * Sort-uniq-ing the recipient list is done after address canonicalization,
    813      * before recipients are written to queue file. That's cleaner than
    814      * having the queue manager nuke duplicate recipient status records.
    815      *
    816      * XXX Should limit the size of envelope records.
    817      *
    818      * With "sendmail -N", instead of a per-message NOTIFY record we store one
    819      * per recipient so that we can simplify the implementation somewhat.
    820      */
    821     if (sm_sendopts)
    822 	rec_fprintf(dst, REC_TYPE_SIZE, REC_TYPE_SIZE_FORMAT,
    823 		    (REC_TYPE_SIZE_CAST1) ~ 0,	/* message segment size */
    824 		    (REC_TYPE_SIZE_CAST2) ~ 0,	/* content offset */
    825 		    (REC_TYPE_SIZE_CAST3) ~ 0,	/* recipient count */
    826 		    (REC_TYPE_SIZE_CAST4) ~ 0,	/* qmgr options */
    827 		    (REC_TYPE_SIZE_CAST5) ~ 0,	/* content length */
    828 		    (REC_TYPE_SIZE_CAST6) sm_sendopts);
    829     if (dsn_envid)
    830 	rec_fprintf(dst, REC_TYPE_ATTR, "%s=%s",
    831 		    MAIL_ATTR_DSN_ENVID, dsn_envid);
    832     if (dsn_ret)
    833 	rec_fprintf(dst, REC_TYPE_ATTR, "%s=%d",
    834 		    MAIL_ATTR_DSN_RET, dsn_ret);
    835     rec_fprintf(dst, REC_TYPE_ATTR, "%s=%s",
    836 		MAIL_ATTR_RWR_CONTEXT, rewrite_context);
    837     if (full_name || (full_name = fullname()) != 0)
    838 	rec_fputs(dst, REC_TYPE_FULL, full_name);
    839     rec_fputs(dst, REC_TYPE_FROM, saved_sender);
    840     if (verp_delims && *saved_sender == 0)
    841 	msg_fatal_status(EX_USAGE,
    842 		      "%s(%ld): -V option requires non-null sender address",
    843 			 saved_sender, (long) uid);
    844     if (encoding)
    845 	rec_fprintf(dst, REC_TYPE_ATTR, "%s=%s", MAIL_ATTR_ENCODING, encoding);
    846     if (DEL_REQ_TRACE_FLAGS(flags))
    847 	rec_fprintf(dst, REC_TYPE_ATTR, "%s=%d", MAIL_ATTR_TRACE_FLAGS,
    848 		    DEL_REQ_TRACE_FLAGS(flags));
    849     if (verp_delims)
    850 	rec_fputs(dst, REC_TYPE_VERP, verp_delims);
    851     if (recipients) {
    852 	for (cpp = recipients; *cpp != 0; cpp++) {
    853 	    tree = tok822_parse(*cpp);
    854 	    for (addr_count = 0, tp = tree; tp != 0; tp = tp->next) {
    855 		if (tp->type == TOK822_ADDR) {
    856 		    tok822_internalize(buf, tp->head, TOK822_STR_DEFL);
    857 		    if (dsn_notify)
    858 			rec_fprintf(dst, REC_TYPE_ATTR, "%s=%d",
    859 				    MAIL_ATTR_DSN_NOTIFY, dsn_notify);
    860 		    if (REC_PUT_BUF(dst, REC_TYPE_RCPT, buf) < 0)
    861 			msg_fatal_status(EX_TEMPFAIL,
    862 				    "%s(%ld): error writing queue file: %m",
    863 					 saved_sender, (long) uid);
    864 		    ++rcpt_count;
    865 		    ++addr_count;
    866 		}
    867 	    }
    868 	    tok822_free_tree(tree);
    869 	    if (addr_count == 0) {
    870 		if (rec_put(dst, REC_TYPE_RCPT, "", 0) < 0)
    871 		    msg_fatal_status(EX_TEMPFAIL,
    872 				     "%s(%ld): error writing queue file: %m",
    873 				     saved_sender, (long) uid);
    874 		++rcpt_count;
    875 	    }
    876 	}
    877     }
    878 
    879     /*
    880      * Append the message contents to the queue file. Write chunks of at most
    881      * 1kbyte. Internally, we use different record types for data ending in
    882      * LF and for data that doesn't, so we can actually be binary transparent
    883      * for local mail. Unfortunately, SMTP has no record continuation
    884      * convention, so there is no guarantee that arbitrary data will be
    885      * delivered intact via SMTP. Strip leading From_ lines. For the benefit
    886      * of UUCP environments, also get rid of leading >>>From_ lines.
    887      */
    888     rec_fputs(dst, REC_TYPE_MESG, "");
    889     if (DEL_REQ_TRACE_ONLY(flags) != 0) {
    890 	if (flags & SM_FLAG_XRCPT)
    891 	    msg_fatal_status(EX_USAGE, "%s(%ld): -t option cannot be used with -bv",
    892 			     saved_sender, (long) uid);
    893 	if (*saved_sender)
    894 	    rec_fprintf(dst, REC_TYPE_NORM, "From: %s", saved_sender);
    895 	rec_fprintf(dst, REC_TYPE_NORM, "Subject: probe");
    896 	if (recipients) {
    897 	    rec_fprintf(dst, REC_TYPE_CONT, "To:");
    898 	    for (cpp = recipients; *cpp != 0; cpp++) {
    899 		rec_fprintf(dst, REC_TYPE_NORM, "	%s%s",
    900 			    *cpp, cpp[1] ? "," : "");
    901 	    }
    902 	}
    903     } else {
    904 
    905 	/*
    906 	 * Initialize the MIME processor and set up the callback context.
    907 	 */
    908 	if (flags & SM_FLAG_XRCPT) {
    909 	    state.dst = dst;
    910 	    state.recipients = argv_alloc(2);
    911 	    state.resent_recip = argv_alloc(2);
    912 	    state.resent = 0;
    913 	    state.saved_sender = saved_sender;
    914 	    state.uid = uid;
    915 	    state.temp = vstring_alloc(10);
    916 	    mime_state = mime_state_alloc(MIME_OPT_DISABLE_MIME
    917 					  | MIME_OPT_REPORT_TRUNC_HEADER,
    918 					  output_header,
    919 					  (MIME_STATE_ANY_END) 0,
    920 					  output_text,
    921 					  (MIME_STATE_ANY_END) 0,
    922 					  (MIME_STATE_ERR_PRINT) 0,
    923 					  (void *) &state);
    924 	}
    925 
    926 	/*
    927 	 * Process header/body lines.
    928 	 */
    929 	skip_from_ = 1;
    930 	strip_cr = name_code(sm_fix_eol_table, NAME_CODE_FLAG_STRICT_CASE,
    931 			     var_sm_fix_eol);
    932 	if (strip_cr == STRIP_CR_ERROR)
    933 	    msg_fatal_status(EX_USAGE,
    934 		    "invalid %s value: %s", VAR_SM_FIX_EOL, var_sm_fix_eol);
    935 	for (prev_type = 0; (type = rec_streamlf_get(VSTREAM_IN, buf, var_line_limit))
    936 	     != REC_TYPE_EOF; prev_type = type) {
    937 	    if (strip_cr == STRIP_CR_DUNNO && type == REC_TYPE_NORM) {
    938 		if (VSTRING_LEN(buf) > 0 && vstring_end(buf)[-1] == '\r')
    939 		    strip_cr = STRIP_CR_DO;
    940 		else
    941 		    strip_cr = STRIP_CR_DONT;
    942 	    }
    943 	    if (skip_from_) {
    944 		if (type == REC_TYPE_NORM) {
    945 		    start = STR(buf);
    946 		    if (strncmp(start + strspn(start, ">"), "From ", 5) == 0)
    947 			continue;
    948 		}
    949 		skip_from_ = 0;
    950 	    }
    951 	    if (strip_cr == STRIP_CR_DO && type == REC_TYPE_NORM)
    952 		while (VSTRING_LEN(buf) > 0 && vstring_end(buf)[-1] == '\r')
    953 		    vstring_truncate(buf, VSTRING_LEN(buf) - 1);
    954 	    if ((flags & SM_FLAG_AEOF) && prev_type != REC_TYPE_CONT
    955 		&& VSTRING_LEN(buf) == 1 && *STR(buf) == '.')
    956 		break;
    957 	    if (mime_state) {
    958 		mime_errs = mime_state_update(mime_state, type, STR(buf),
    959 					      VSTRING_LEN(buf));
    960 		if (mime_errs)
    961 		    msg_fatal_status(EX_DATAERR,
    962 				"%s(%ld): unable to extract recipients: %s",
    963 				     saved_sender, (long) uid,
    964 				     mime_state_error(mime_errs));
    965 	    } else {
    966 		if (REC_PUT_BUF(dst, type, buf) < 0)
    967 		    msg_fatal_status(EX_TEMPFAIL,
    968 				     "%s(%ld): error writing queue file: %m",
    969 				     saved_sender, (long) uid);
    970 	    }
    971 	}
    972     }
    973 
    974     /*
    975      * Finish MIME processing. We need a final mime_state_update() call in
    976      * order to flush text that is still buffered. That can happen when the
    977      * last line did not end in newline.
    978      */
    979     if (mime_state) {
    980 	mime_errs = mime_state_update(mime_state, REC_TYPE_EOF, "", 0);
    981 	if (mime_errs)
    982 	    msg_fatal_status(EX_DATAERR,
    983 			     "%s(%ld): unable to extract recipients: %s",
    984 			     saved_sender, (long) uid,
    985 			     mime_state_error(mime_errs));
    986 	mime_state = mime_state_free(mime_state);
    987     }
    988 
    989     /*
    990      * Append recipient addresses that were extracted from message headers.
    991      */
    992     rec_fputs(dst, REC_TYPE_XTRA, "");
    993     if (flags & SM_FLAG_XRCPT) {
    994 	for (cpp = state.resent ? state.resent_recip->argv :
    995 	     state.recipients->argv; *cpp; cpp++) {
    996 	    if (dsn_notify)
    997 		rec_fprintf(dst, REC_TYPE_ATTR, "%s=%d",
    998 			    MAIL_ATTR_DSN_NOTIFY, dsn_notify);
    999 	    if (rec_put(dst, REC_TYPE_RCPT, *cpp, strlen(*cpp)) < 0)
   1000 		msg_fatal_status(EX_TEMPFAIL,
   1001 				 "%s(%ld): error writing queue file: %m",
   1002 				 saved_sender, (long) uid);
   1003 	    ++rcpt_count;
   1004 	}
   1005 	argv_free(state.recipients);
   1006 	argv_free(state.resent_recip);
   1007 	vstring_free(state.temp);
   1008     }
   1009     if (rcpt_count == 0)
   1010 	msg_fatal_status(EX_USAGE, (flags & SM_FLAG_XRCPT) ?
   1011 		 "%s(%ld): No recipient addresses found in message header" :
   1012 			 "%s(%ld): Recipient addresses must be specified on"
   1013 			 " the command line or via the -t option",
   1014 			 saved_sender, (long) uid);
   1015 
   1016     /*
   1017      * Identify the end of the queue file.
   1018      */
   1019     rec_fputs(dst, REC_TYPE_END, "");
   1020 
   1021     /*
   1022      * Make sure that the message makes it to the file system. Once we have
   1023      * terminated with successful exit status we cannot lose the message due
   1024      * to "frivolous reasons". If all goes well, prevent the run-time error
   1025      * handler from removing the file.
   1026      */
   1027     if (vstream_ferror(VSTREAM_IN))
   1028 	msg_fatal_status(EX_DATAERR, "%s(%ld): error reading input: %m",
   1029 			 saved_sender, (long) uid);
   1030     why = vstring_alloc(100);
   1031     if ((status = mail_stream_finish(handle, why)) != CLEANUP_STAT_OK)
   1032 	msg_fatal_status((status & CLEANUP_STAT_BAD) ? EX_SOFTWARE :
   1033 			 (status & CLEANUP_STAT_WRITE) ? EX_TEMPFAIL :
   1034 			 (status & CLEANUP_STAT_NOPERM) ? EX_NOPERM :
   1035 			 EX_UNAVAILABLE, "%s(%ld): %s", saved_sender,
   1036 			 (long) uid, VSTRING_LEN(why) ?
   1037 			 STR(why) : cleanup_strerror(status));
   1038     vstring_free(why);
   1039 
   1040     /*
   1041      * Don't leave them in the dark.
   1042      */
   1043     if (DEL_REQ_TRACE_FLAGS(flags)) {
   1044 	vstream_printf("Mail Delivery Status Report will be mailed to <%s>.\n",
   1045 		       saved_sender);
   1046 	vstream_fflush(VSTREAM_OUT);
   1047     }
   1048 
   1049     /*
   1050      * Cleanup. Not really necessary as we're about to exit, but good for
   1051      * debugging purposes.
   1052      */
   1053     vstring_free(buf);
   1054     myfree(saved_sender);
   1055 }
   1056 
   1057 /* tempfail - sanitize exit status after library run-time error */
   1058 
   1059 static void tempfail(void)
   1060 {
   1061     exit(EX_TEMPFAIL);
   1062 }
   1063 
   1064 MAIL_VERSION_STAMP_DECLARE;
   1065 
   1066 /* main - the main program */
   1067 
   1068 int     main(int argc, char **argv)
   1069 {
   1070     static char *full_name = 0;		/* sendmail -F */
   1071     struct stat st;
   1072     char   *slash;
   1073     char   *sender = 0;			/* sendmail -f */
   1074     int     c;
   1075     int     fd;
   1076     int     mode;
   1077     ARGV   *ext_argv;
   1078     int     debug_me = 0;
   1079     int     err;
   1080     int     n;
   1081     int     flags = SM_FLAG_DEFAULT;
   1082     char   *site_to_flush = 0;
   1083     char   *id_to_flush = 0;
   1084     char   *encoding = 0;
   1085     char   *qtime = 0;
   1086     const char *errstr;
   1087     uid_t   uid;
   1088     const char *rewrite_context = MAIL_ATTR_RWR_LOCAL;
   1089     int     dsn_notify = 0;
   1090     int     dsn_ret = 0;
   1091     const char *dsn_envid = 0;
   1092     int     saved_optind;
   1093     ARGV   *import_env;
   1094     char   *alias_map_from_args = 0;
   1095     const char *oval;
   1096 
   1097     /*
   1098      * Fingerprint executables and core dumps.
   1099      */
   1100     MAIL_VERSION_STAMP_ALLOCATE;
   1101 
   1102     /*
   1103      * Be consistent with file permissions.
   1104      */
   1105     umask(022);
   1106 
   1107     /*
   1108      * To minimize confusion, make sure that the standard file descriptors
   1109      * are open before opening anything else. XXX Work around for 44BSD where
   1110      * fstat can return EBADF on an open file descriptor.
   1111      */
   1112     for (fd = 0; fd < 3; fd++)
   1113 	if (fstat(fd, &st) == -1
   1114 	    && (close(fd), open("/dev/null", O_RDWR, 0)) != fd)
   1115 	    msg_fatal_status(EX_OSERR, "open /dev/null: %m");
   1116 
   1117     /*
   1118      * The CDE desktop calendar manager leaks a parent file descriptor into
   1119      * the child process. For the sake of sendmail compatibility we have to
   1120      * close the file descriptor otherwise mail notification will hang.
   1121      */
   1122     for ( /* void */ ; fd < 100; fd++)
   1123 	(void) close(fd);
   1124 
   1125     /*
   1126      * Process environment options as early as we can. We might be called
   1127      * from a set-uid (set-gid) program, so be careful with importing
   1128      * environment variables.
   1129      */
   1130     if (safe_getenv(CONF_ENV_VERB))
   1131 	msg_verbose = 1;
   1132     if (safe_getenv(CONF_ENV_DEBUG))
   1133 	debug_me = 1;
   1134 
   1135     /*
   1136      * Initialize. Set up logging. Read the global configuration file after
   1137      * command-line processing. Set up signal handlers so that we can clean
   1138      * up incomplete output.
   1139      */
   1140     if ((slash = strrchr(argv[0], '/')) != 0 && slash[1])
   1141 	argv[0] = slash + 1;
   1142     msg_vstream_init(argv[0], VSTREAM_ERR);
   1143     msg_cleanup(tempfail);
   1144     maillog_client_init(mail_task("sendmail"), MAILLOG_CLIENT_FLAG_NONE);
   1145     set_mail_conf_str(VAR_PROCNAME, var_procname = mystrdup(argv[0]));
   1146 
   1147     /*
   1148      * Check the Postfix library version as soon as we enable logging.
   1149      */
   1150     MAIL_VERSION_CHECK;
   1151 
   1152     /*
   1153      * Some sites mistakenly install Postfix sendmail as set-uid root. Drop
   1154      * set-uid privileges only when root, otherwise some systems will not
   1155      * reset the saved set-userid, which would be a security vulnerability.
   1156      */
   1157     if (geteuid() == 0 && getuid() != 0) {
   1158 	msg_warn("the Postfix sendmail command has set-uid root file permissions");
   1159 	msg_warn("or the command is run from a set-uid root process");
   1160 	msg_warn("the Postfix sendmail command must be installed without set-uid root file permissions");
   1161 	set_ugid(getuid(), getgid());
   1162     }
   1163 
   1164     /*
   1165      * Further initialization. Load main.cf first, so that command-line
   1166      * options can override main.cf settings. Pre-scan the argument list so
   1167      * that we load the right main.cf file.
   1168      */
   1169 #define GETOPT_LIST "A:B:C:F:GIL:N:O:R:UV:X:b:ce:f:h:imno:p:r:q:tvx"
   1170 
   1171     saved_optind = optind;
   1172     while (argv[OPTIND] != 0) {
   1173 	if (strcmp(argv[OPTIND], "-q") == 0) {	/* not getopt compatible */
   1174 	    optind++;
   1175 	    continue;
   1176 	}
   1177 	if ((c = GETOPT(argc, argv, GETOPT_LIST)) <= 0)
   1178 	    break;
   1179 	if (c == 'C') {
   1180 	    VSTRING *buf = vstring_alloc(1);
   1181 	    char   *dir;
   1182 
   1183 	    dir = strcmp(sane_basename(buf, optarg), MAIN_CONF_FILE) == 0 ?
   1184 		sane_dirname(buf, optarg) : optarg;
   1185 	    if (strcmp(dir, DEF_CONFIG_DIR) != 0 && geteuid() != 0)
   1186 		mail_conf_checkdir(dir);
   1187 	    if (setenv(CONF_ENV_PATH, dir, 1) < 0)
   1188 		msg_fatal_status(EX_UNAVAILABLE, "out of memory");
   1189 	    vstring_free(buf);
   1190 	}
   1191     }
   1192     optind = saved_optind;
   1193     mail_conf_read();
   1194     /* Enforce consistent operation of different Postfix parts.	 */
   1195     import_env = mail_parm_split(VAR_IMPORT_ENVIRON, var_import_environ);
   1196     update_env(import_env->argv);
   1197     argv_free(import_env);
   1198     /* Re-evaluate mail_task() after reading main.cf. */
   1199     maillog_client_init(mail_task("sendmail"), MAILLOG_CLIENT_FLAG_NONE);
   1200     get_mail_conf_str_table(str_table);
   1201 
   1202     mail_dict_init();
   1203 
   1204     if (chdir(var_queue_dir))
   1205 	msg_fatal_status(EX_UNAVAILABLE, "chdir %s: %m", var_queue_dir);
   1206 
   1207     signal(SIGPIPE, SIG_IGN);
   1208 
   1209     /*
   1210      * Optionally start the debugger on ourself. This must be done after
   1211      * reading the global configuration file, because that file specifies
   1212      * what debugger command to execute.
   1213      */
   1214     if (debug_me)
   1215 	debug_process();
   1216 
   1217     /*
   1218      * The default mode of operation is determined by the process name. It
   1219      * can, however, be changed via command-line options (for example,
   1220      * "newaliases -bp" will show the mail queue).
   1221      */
   1222     if (strcmp(argv[0], "mailq") == 0) {
   1223 	mode = SM_MODE_MAILQ;
   1224     } else if (strcmp(argv[0], "newaliases") == 0) {
   1225 	mode = SM_MODE_NEWALIAS;
   1226     } else if (strcmp(argv[0], "smtpd") == 0) {
   1227 	mode = SM_MODE_DAEMON;
   1228     } else {
   1229 	mode = SM_MODE_ENQUEUE;
   1230     }
   1231 
   1232     /*
   1233      * Parse JCL. Sendmail has been around for a long time, and has acquired
   1234      * a large number of options in the course of time. Some options such as
   1235      * -q are not parsable with GETOPT() and get special treatment.
   1236      */
   1237 #define OPTIND  (optind > 0 ? optind : 1)
   1238 
   1239     while (argv[OPTIND] != 0) {
   1240 	if (strcmp(argv[OPTIND], "-q") == 0) {
   1241 	    if (mode == SM_MODE_DAEMON)
   1242 		msg_warn("ignoring -q option in daemon mode");
   1243 	    else
   1244 		mode = SM_MODE_FLUSHQ;
   1245 	    optind++;
   1246 	    continue;
   1247 	}
   1248 	if (strcmp(argv[OPTIND], "-V") == 0
   1249 	    && argv[OPTIND + 1] != 0 && strlen(argv[OPTIND + 1]) == 2) {
   1250 	    msg_warn("option -V is deprecated with Postfix 2.3; "
   1251 		     "specify -XV instead");
   1252 	    argv[OPTIND] = "-XV";
   1253 	}
   1254 	if (strncmp(argv[OPTIND], "-V", 2) == 0 && strlen(argv[OPTIND]) == 4) {
   1255 	    msg_warn("option %s is deprecated with Postfix 2.3; "
   1256 		     "specify -X%s instead",
   1257 		     argv[OPTIND], argv[OPTIND] + 1);
   1258 	    argv[OPTIND] = concatenate("-X", argv[OPTIND] + 1, (char *) 0);
   1259 	}
   1260 	if (strcmp(argv[OPTIND], "-XV") == 0) {
   1261 	    verp_delims = var_verp_delims;
   1262 	    optind++;
   1263 	    continue;
   1264 	}
   1265 	if ((c = GETOPT(argc, argv, GETOPT_LIST)) <= 0)
   1266 	    break;
   1267 	switch (c) {
   1268 	default:
   1269 	    if (msg_verbose)
   1270 		msg_info("-%c option ignored", c);
   1271 	    break;
   1272 	case 'n':
   1273 	    msg_fatal_status(EX_USAGE, "-%c option not supported", c);
   1274 	case 'B':
   1275 	    if (strcmp(optarg, "8BITMIME") == 0)/* RFC 1652 */
   1276 		encoding = MAIL_ATTR_ENC_8BIT;
   1277 	    else if (strcmp(optarg, "7BIT") == 0)	/* RFC 1652 */
   1278 		encoding = MAIL_ATTR_ENC_7BIT;
   1279 	    else
   1280 		msg_fatal_status(EX_USAGE, "-B option needs 8BITMIME or 7BIT");
   1281 	    break;
   1282 	case 'F':				/* full name */
   1283 	    full_name = optarg;
   1284 	    break;
   1285 	case 'G':				/* gateway submission */
   1286 	    rewrite_context = MAIL_ATTR_RWR_REMOTE;
   1287 	    break;
   1288 	case 'I':				/* newaliases */
   1289 	    mode = SM_MODE_NEWALIAS;
   1290 	    break;
   1291 	case 'N':
   1292 	    if ((dsn_notify = dsn_notify_mask(optarg)) == 0)
   1293 		msg_warn("bad -N option value: '%s' -- ignored", optarg);
   1294 	    break;
   1295 	case 'O':
   1296 	    if ((oval = optarg + strcspn(optarg, "="))[0] != 0)
   1297 		oval += 1;
   1298 	    if (strncasecmp(optarg, "REQUIRETLS=", oval - optarg) == 0) {
   1299 		if (var_reqtls_enable == 0) {
   1300 		    msg_warn("Ignoring option '-O %s, because the "
   1301 			     "configuration is '%s = %s'", optarg,
   1302 			     VAR_REQTLS_ENABLE, CONFIG_BOOL_NO);
   1303 		    continue;
   1304 		} else if (strcasecmp(oval, CONFIG_BOOL_YES) == 0) {
   1305 		    sm_sendopts |= SOPT_REQUIRETLS_ESMTP;
   1306 		    continue;
   1307 		} else if (strcasecmp(oval, CONFIG_BOOL_NO) == 0) {
   1308 		    sm_sendopts &= ~SOPT_REQUIRETLS_ESMTP;
   1309 		    continue;
   1310 		}
   1311 		msg_warn("bad -O option: '%s' -- ignored", optarg);
   1312 	    } else if (strncasecmp(optarg, "SMTPUTF8=", oval - optarg) == 0) {
   1313 		if (var_smtputf8_enable == 0) {
   1314 		    msg_warn("'-O %s' was requested, but the "
   1315 			     "configuration is '%s = %s'", optarg,
   1316 			     VAR_SMTPUTF8_ENABLE, CONFIG_BOOL_NO);
   1317 		    continue;
   1318 		} else if (strcasecmp(oval, CONFIG_BOOL_YES) == 0) {
   1319 		    sm_sendopts |= SOPT_SMTPUTF8_REQUESTED;
   1320 		    continue;
   1321 		} else if (strcasecmp(oval, CONFIG_BOOL_NO) == 0) {
   1322 		    sm_sendopts &= ~SOPT_SMTPUTF8_REQUESTED;
   1323 		    continue;
   1324 		}
   1325 		msg_warn("bad -O option: '%s' -- ignored", optarg);
   1326 	    }
   1327 	    break;
   1328 	case 'R':
   1329 	    if ((dsn_ret = dsn_ret_code(optarg)) == 0)
   1330 		msg_warn("bad -R option value -- ignored");
   1331 	    break;
   1332 	case 'V':				/* DSN, was: VERP */
   1333 	    if (strlen(optarg) > 100)
   1334 		msg_warn("too long -V option value -- ignored");
   1335 	    else if (!allprint(optarg))
   1336 		msg_warn("bad syntax in -V option value -- ignored");
   1337 	    else
   1338 		dsn_envid = optarg;
   1339 	    break;
   1340 	case 'X':
   1341 	    switch (*optarg) {
   1342 	    default:
   1343 		msg_fatal_status(EX_USAGE, "unsupported: -%c%c", c, *optarg);
   1344 	    case 'V':				/* VERP */
   1345 		if (verp_delims_verify(optarg + 1) != 0)
   1346 		    msg_fatal_status(EX_USAGE, "-V requires two characters from %s",
   1347 				     var_verp_filter);
   1348 		verp_delims = optarg + 1;
   1349 		break;
   1350 	    }
   1351 	    break;
   1352 	case 'b':
   1353 	    switch (*optarg) {
   1354 	    default:
   1355 		msg_fatal_status(EX_USAGE, "unsupported: -%c%c", c, *optarg);
   1356 	    case 'd':				/* daemon mode */
   1357 	    case 'l':				/* daemon mode */
   1358 		if (mode == SM_MODE_FLUSHQ)
   1359 		    msg_warn("ignoring -q option in daemon mode");
   1360 		mode = SM_MODE_DAEMON;
   1361 		break;
   1362 	    case 'h':				/* print host status */
   1363 	    case 'H':				/* flush host status */
   1364 		mode = SM_MODE_IGNORE;
   1365 		break;
   1366 	    case 'i':				/* newaliases */
   1367 		mode = SM_MODE_NEWALIAS;
   1368 		break;
   1369 	    case 'm':				/* deliver mail */
   1370 		mode = SM_MODE_ENQUEUE;
   1371 		break;
   1372 	    case 'p':				/* mailq */
   1373 		mode = SM_MODE_MAILQ;
   1374 		break;
   1375 	    case 's':				/* stand-alone mode */
   1376 		mode = SM_MODE_USER;
   1377 		break;
   1378 	    case 'v':				/* expand recipients */
   1379 		flags |= DEL_REQ_FLAG_USR_VRFY;
   1380 		break;
   1381 	    }
   1382 	    break;
   1383 	case 'f':
   1384 	    sender = optarg;
   1385 	    break;
   1386 	case 'i':
   1387 	    flags &= ~SM_FLAG_AEOF;
   1388 	    break;
   1389 	case 'o':
   1390 	    switch (*optarg) {
   1391 	    default:
   1392 		if (msg_verbose)
   1393 		    msg_info("-%c%c option ignored", c, *optarg);
   1394 		break;
   1395 	    case 'A':
   1396 		if (optarg[1] == 0)
   1397 		    msg_fatal_status(EX_USAGE, "-oA requires pathname");
   1398 		alias_map_from_args = optarg + 1;
   1399 		break;
   1400 	    case '7':
   1401 	    case '8':
   1402 		break;
   1403 	    case 'i':
   1404 		flags &= ~SM_FLAG_AEOF;
   1405 		break;
   1406 	    case 'm':
   1407 		break;
   1408 	    }
   1409 	    break;
   1410 	case 'r':				/* obsoleted by -f */
   1411 	    sender = optarg;
   1412 	    break;
   1413 	case 'q':
   1414 	    if (ISDIGIT(optarg[0])) {
   1415 		qtime = optarg;
   1416 	    } else if (optarg[0] == 'R') {
   1417 		site_to_flush = optarg + 1;
   1418 		if (*site_to_flush == 0)
   1419 		    msg_fatal_status(EX_USAGE, "specify: -qRsitename");
   1420 	    } else if (optarg[0] == 'I') {
   1421 		id_to_flush = optarg + 1;
   1422 		if (*id_to_flush == 0)
   1423 		    msg_fatal_status(EX_USAGE, "specify: -qIqueueid");
   1424 	    } else {
   1425 		msg_fatal_status(EX_USAGE, "-q%c is not implemented",
   1426 				 optarg[0]);
   1427 	    }
   1428 	    break;
   1429 	case 't':
   1430 	    flags |= SM_FLAG_XRCPT;
   1431 	    break;
   1432 	case 'v':
   1433 	    msg_verbose++;
   1434 	    break;
   1435 	case '?':
   1436 	    msg_fatal_status(EX_USAGE, "usage: %s [options]", argv[0]);
   1437 	}
   1438     }
   1439 
   1440     /*
   1441      * Look for conflicting options and arguments.
   1442      */
   1443     if ((flags & SM_FLAG_XRCPT) && mode != SM_MODE_ENQUEUE)
   1444 	msg_fatal_status(EX_USAGE, "-t can be used only in delivery mode");
   1445 
   1446     if (site_to_flush && mode != SM_MODE_ENQUEUE)
   1447 	msg_fatal_status(EX_USAGE, "-qR can be used only in delivery mode");
   1448 
   1449     if (id_to_flush && mode != SM_MODE_ENQUEUE)
   1450 	msg_fatal_status(EX_USAGE, "-qI can be used only in delivery mode");
   1451 
   1452     if (flags & DEL_REQ_FLAG_USR_VRFY) {
   1453 	if (flags & SM_FLAG_XRCPT)
   1454 	    msg_fatal_status(EX_USAGE, "-t option cannot be used with -bv");
   1455 	if (dsn_notify)
   1456 	    msg_fatal_status(EX_USAGE, "-N option cannot be used with -bv");
   1457 	if (dsn_ret)
   1458 	    msg_fatal_status(EX_USAGE, "-R option cannot be used with -bv");
   1459 	if (msg_verbose == 1)
   1460 	    msg_fatal_status(EX_USAGE, "-v option cannot be used with -bv");
   1461     }
   1462 
   1463     /*
   1464      * The -v option plays double duty. One requests verbose delivery, more
   1465      * than one requests verbose logging.
   1466      */
   1467     if (msg_verbose == 1 && mode == SM_MODE_ENQUEUE) {
   1468 	msg_verbose = 0;
   1469 	flags |= DEL_REQ_FLAG_RECORD;
   1470     }
   1471 
   1472     /*
   1473      * Start processing. Everything is delegated to external commands.
   1474      */
   1475     if (qtime && mode != SM_MODE_DAEMON)
   1476 	exit(0);
   1477     switch (mode) {
   1478     default:
   1479 	msg_panic("unknown operation mode: %d", mode);
   1480 	/* NOTREACHED */
   1481     case SM_MODE_ENQUEUE:
   1482 	if (site_to_flush) {
   1483 	    if (argv[OPTIND])
   1484 		msg_fatal_status(EX_USAGE, "flush site requires no recipient");
   1485 	    ext_argv = argv_alloc(2);
   1486 	    argv_add(ext_argv, "postqueue", "-s", site_to_flush, (char *) 0);
   1487 	    for (n = 0; n < msg_verbose; n++)
   1488 		argv_add(ext_argv, "-v", (char *) 0);
   1489 	    argv_terminate(ext_argv);
   1490 	    mail_run_replace(var_command_dir, ext_argv->argv);
   1491 	    /* NOTREACHED */
   1492 	} else if (id_to_flush) {
   1493 	    if (argv[OPTIND])
   1494 		msg_fatal_status(EX_USAGE, "flush queue_id requires no recipient");
   1495 	    ext_argv = argv_alloc(2);
   1496 	    argv_add(ext_argv, "postqueue", "-i", id_to_flush, (char *) 0);
   1497 	    for (n = 0; n < msg_verbose; n++)
   1498 		argv_add(ext_argv, "-v", (char *) 0);
   1499 	    argv_terminate(ext_argv);
   1500 	    mail_run_replace(var_command_dir, ext_argv->argv);
   1501 	    /* NOTREACHED */
   1502 	} else {
   1503 	    enqueue(flags, encoding, dsn_envid, dsn_ret, dsn_notify,
   1504 		    rewrite_context, sender, full_name, argv + OPTIND);
   1505 	    exit(0);
   1506 	    /* NOTREACHED */
   1507 	}
   1508 	break;
   1509     case SM_MODE_MAILQ:
   1510 	if (argv[OPTIND])
   1511 	    msg_fatal_status(EX_USAGE,
   1512 			     "display queue mode requires no recipient");
   1513 	ext_argv = argv_alloc(2);
   1514 	argv_add(ext_argv, "postqueue", "-p", (char *) 0);
   1515 	for (n = 0; n < msg_verbose; n++)
   1516 	    argv_add(ext_argv, "-v", (char *) 0);
   1517 	argv_terminate(ext_argv);
   1518 	mail_run_replace(var_command_dir, ext_argv->argv);
   1519 	/* NOTREACHED */
   1520     case SM_MODE_FLUSHQ:
   1521 	if (argv[OPTIND])
   1522 	    msg_fatal_status(EX_USAGE,
   1523 			     "flush queue mode requires no recipient");
   1524 	ext_argv = argv_alloc(2);
   1525 	argv_add(ext_argv, "postqueue", "-f", (char *) 0);
   1526 	for (n = 0; n < msg_verbose; n++)
   1527 	    argv_add(ext_argv, "-v", (char *) 0);
   1528 	argv_terminate(ext_argv);
   1529 	mail_run_replace(var_command_dir, ext_argv->argv);
   1530 	/* NOTREACHED */
   1531     case SM_MODE_DAEMON:
   1532 	if (argv[OPTIND])
   1533 	    msg_fatal_status(EX_USAGE, "daemon mode requires no recipient");
   1534 	ext_argv = argv_alloc(2);
   1535 	argv_add(ext_argv, "postfix", (char *) 0);
   1536 	for (n = 0; n < msg_verbose; n++)
   1537 	    argv_add(ext_argv, "-v", (char *) 0);
   1538 	argv_add(ext_argv, "start", (char *) 0);
   1539 	argv_terminate(ext_argv);
   1540 	err = (mail_run_background(var_command_dir, ext_argv->argv) < 0);
   1541 	argv_free(ext_argv);
   1542 	exit(err);
   1543 	break;
   1544     case SM_MODE_NEWALIAS:
   1545 	if (argv[OPTIND])
   1546 	    msg_fatal_status(EX_USAGE,
   1547 			 "alias initialization mode requires no recipient");
   1548 	if (alias_map_from_args == 0 && *var_alias_db_map == 0)
   1549 	    return (0);
   1550 	ext_argv = argv_alloc(3);
   1551 	argv_add(ext_argv, "postalias", (char *) 0);
   1552 	for (n = 0; n < msg_verbose; n++)
   1553 	    argv_add(ext_argv, "-v", (char *) 0);
   1554 	argv_add(ext_argv, "--", (char *) 0);
   1555 	if (alias_map_from_args != 0)
   1556 	    argv_add(ext_argv, alias_map_from_args, (char *) 0);
   1557 	else
   1558 	    argv_split_append(ext_argv, var_alias_db_map, CHARS_COMMA_SP);
   1559 	argv_terminate(ext_argv);
   1560 	mail_run_replace(var_command_dir, ext_argv->argv);
   1561 	/* NOTREACHED */
   1562     case SM_MODE_USER:
   1563 	if (argv[OPTIND])
   1564 	    msg_fatal_status(EX_USAGE,
   1565 			     "stand-alone mode requires no recipient");
   1566 	/* The actual enforcement happens in the postdrop command. */
   1567 	if ((errstr = check_user_acl_byuid(VAR_SUBMIT_ACL, var_submit_acl,
   1568 					   uid = getuid())) != 0)
   1569 	    msg_fatal_status(EX_NOPERM,
   1570 			     "User %s(%ld) is not allowed to submit mail",
   1571 			     errstr, (long) uid);
   1572 	ext_argv = argv_alloc(2);
   1573 	argv_add(ext_argv, "smtpd", "-S", (char *) 0);
   1574 	for (n = 0; n < msg_verbose; n++)
   1575 	    argv_add(ext_argv, "-v", (char *) 0);
   1576 	argv_terminate(ext_argv);
   1577 	mail_run_replace(var_daemon_dir, ext_argv->argv);
   1578 	/* NOTREACHED */
   1579     case SM_MODE_IGNORE:
   1580 	exit(0);
   1581 	/* NOTREACHED */
   1582     }
   1583 }
   1584