1 /*************************************************
2 *     Exim - an Internet mail transport agent    *
3 *************************************************/
4 
5 /* Copyright (c) University of Cambridge 1995 - 2018 */
6 /* Copyright (c) The Exim Maintainers 2020 */
7 /* See the file NOTICE for conditions of use and distribution. */
8 
9 /* All the global variables are defined together in this one module, so
10 that they are easy to find. */
11 
12 #include "exim.h"
13 
14 
15 /* Generic options for auths, all of which live inside auth_instance
16 data blocks and hence have the opt_public flag set. */
17 
18 optionlist optionlist_auths[] = {
19   { "client_condition", opt_stringptr | opt_public,
20                  OPT_OFF(auth_instance, client_condition) },
21   { "client_set_id", opt_stringptr | opt_public,
22                  OPT_OFF(auth_instance, set_client_id) },
23   { "driver",        opt_stringptr | opt_public,
24                  OPT_OFF(auth_instance, driver_name) },
25   { "public_name",   opt_stringptr | opt_public,
26                  OPT_OFF(auth_instance, public_name) },
27   { "server_advertise_condition", opt_stringptr | opt_public,
28                  OPT_OFF(auth_instance, advertise_condition)},
29   { "server_condition", opt_stringptr | opt_public,
30                  OPT_OFF(auth_instance, server_condition) },
31   { "server_debug_print", opt_stringptr | opt_public,
32                  OPT_OFF(auth_instance, server_debug_string) },
33   { "server_mail_auth_condition", opt_stringptr | opt_public,
34                  OPT_OFF(auth_instance, mail_auth_condition) },
35   { "server_set_id", opt_stringptr | opt_public,
36                  OPT_OFF(auth_instance, set_id) }
37 };
38 
39 int     optionlist_auths_size = nelem(optionlist_auths);
40 
41 /* An empty host aliases list. */
42 
43 uschar *no_aliases             = NULL;
44 
45 
46 /* For comments on these variables, see globals.h. I'm too idle to
47 duplicate them here... */
48 
49 #ifdef EXIM_PERL
50 uschar *opt_perl_startup       = NULL;
51 BOOL    opt_perl_at_start      = FALSE;
52 BOOL    opt_perl_started       = FALSE;
53 BOOL    opt_perl_taintmode     = FALSE;
54 #endif
55 
56 #ifdef EXPAND_DLFUNC
57 tree_node *dlobj_anchor        = NULL;
58 #endif
59 
60 #ifdef LOOKUP_IBASE
61 uschar *ibase_servers          = NULL;
62 #endif
63 
64 #ifdef LOOKUP_LDAP
65 uschar *eldap_ca_cert_dir      = NULL;
66 uschar *eldap_ca_cert_file     = NULL;
67 uschar *eldap_cert_file        = NULL;
68 uschar *eldap_cert_key         = NULL;
69 uschar *eldap_cipher_suite     = NULL;
70 uschar *eldap_default_servers  = NULL;
71 uschar *eldap_require_cert     = NULL;
72 int     eldap_version          = -1;
73 BOOL    eldap_start_tls        = FALSE;
74 #endif
75 
76 #ifdef LOOKUP_MYSQL
77 uschar *mysql_servers          = NULL;
78 #endif
79 
80 #ifdef LOOKUP_ORACLE
81 uschar *oracle_servers         = NULL;
82 #endif
83 
84 #ifdef LOOKUP_PGSQL
85 uschar *pgsql_servers          = NULL;
86 #endif
87 
88 #ifdef LOOKUP_REDIS
89 uschar *redis_servers          = NULL;
90 #endif
91 
92 #ifdef LOOKUP_SQLITE
93 uschar *sqlite_dbfile	       = NULL;
94 int     sqlite_lock_timeout    = 5;
95 #endif
96 
97 #ifdef SUPPORT_MOVE_FROZEN_MESSAGES
98 BOOL    move_frozen_messages   = FALSE;
99 #endif
100 
101 #ifdef ALLOW_INSECURE_TAINTED_DATA
102 BOOL    allow_insecure_tainted_data = FALSE;
103 #endif
104 
105 /* These variables are outside the #ifdef because it keeps the code less
106 cluttered in several places (e.g. during logging) if we can always refer to
107 them. Also, the tls_ variables are now always visible.  Note that these are
108 only used for smtp connections, not for service-daemon access. */
109 
110 tls_support tls_in = {
111  .active =		{.sock = -1}
112  /* all other elements zero */
113 };
114 tls_support tls_out = {
115  .active =		{.sock = -1},
116  /* all other elements zero */
117 };
118 
119 uschar *dsn_envid              = NULL;
120 int     dsn_ret                = 0;
121 const pcre  *regex_DSN         = NULL;
122 uschar *dsn_advertise_hosts    = NULL;
123 
124 #ifndef DISABLE_TLS
125 BOOL    gnutls_compat_mode     = FALSE;
126 BOOL    gnutls_allow_auto_pkcs11 = FALSE;
127 uschar *hosts_require_alpn     = NULL;
128 uschar *openssl_options        = NULL;
129 const pcre *regex_STARTTLS     = NULL;
130 uschar *tls_advertise_hosts    = US"*";
131 uschar *tls_alpn	       = US"smtp:esmtp";
132 uschar *tls_certificate        = NULL;
133 uschar *tls_crl                = NULL;
134 /* This default matches NSS DH_MAX_P_BITS value at current time (2012), because
135 that's the interop problem which has been observed: GnuTLS suggesting a higher
136 bit-count as "NORMAL" (2432) and Thunderbird dropping connection. */
137 int     tls_dh_max_bits        = 2236;
138 uschar *tls_dhparam            = NULL;
139 uschar *tls_eccurve            = US"auto";
140 # ifndef DISABLE_OCSP
141 uschar *tls_ocsp_file          = NULL;
142 # endif
143 uschar *tls_privatekey         = NULL;
144 BOOL    tls_remember_esmtp     = FALSE;
145 uschar *tls_require_ciphers    = NULL;
146 # ifndef DISABLE_TLS_RESUME
147 uschar *tls_resumption_hosts   = NULL;
148 # endif
149 uschar *tls_try_verify_hosts   = NULL;
150 uschar *tls_verify_certificates= US"system";
151 uschar *tls_verify_hosts       = NULL;
152 int     tls_watch_fd	       = -1;
153 time_t  tls_watch_trigger_time = (time_t)0;
154 #else	/*DISABLE_TLS*/
155 uschar *tls_advertise_hosts    = NULL;
156 #endif
157 
158 #ifndef DISABLE_PRDR
159 /* Per Recipient Data Response variables */
160 BOOL    prdr_enable            = FALSE;
161 BOOL    prdr_requested         = FALSE;
162 const pcre *regex_PRDR         = NULL;
163 #endif
164 
165 #ifdef SUPPORT_I18N
166 const pcre *regex_UTF8         = NULL;
167 #endif
168 
169 /* Input-reading functions for messages, so we can use special ones for
170 incoming TCP/IP. The defaults use stdin. We never need these for any
171 stand-alone tests. */
172 
173 #if !defined(STAND_ALONE) && !defined(MACRO_PREDEF)
174 int	(*lwr_receive_getc)(unsigned)	= stdin_getc;
175 uschar * (*lwr_receive_getbuf)(unsigned *) = NULL;
176 int	(*lwr_receive_ungetc)(int)	= stdin_ungetc;
177 BOOL	(*lwr_receive_hasc)(void)	= stdin_hasc;
178 
179 int	(*receive_getc)(unsigned) 	= stdin_getc;
180 uschar * (*receive_getbuf)(unsigned *) 	= NULL;
181 void	(*receive_get_cache)(unsigned)	= NULL;
182 BOOL	(*receive_hasc)(void)		= stdin_hasc;
183 int	(*receive_ungetc)(int)    	= stdin_ungetc;
184 int	(*receive_feof)(void)     	= stdin_feof;
185 int	(*receive_ferror)(void)   	= stdin_ferror;
186 BOOL	(*receive_smtp_buffered)(void)	= NULL;   /* Only used for SMTP */
187 #endif
188 
189 
190 /* List of per-address expansion variables for clearing and saving/restoring
191 when verifying one address while routing/verifying another. We have to have
192 the size explicit, because it is referenced from more than one module. */
193 
194 const uschar **address_expansions[ADDRESS_EXPANSIONS_COUNT] = {
195   CUSS &deliver_address_data,
196   CUSS &deliver_domain,
197   CUSS &deliver_domain_data,
198   CUSS &deliver_domain_orig,
199   CUSS &deliver_domain_parent,
200   CUSS &deliver_localpart,
201   CUSS &deliver_localpart_data,
202   CUSS &deliver_localpart_orig,
203   CUSS &deliver_localpart_parent,
204   CUSS &deliver_localpart_prefix,
205   CUSS &deliver_localpart_suffix,
206   CUSS (uschar **)(&deliver_recipients),
207   CUSS &deliver_host,
208   CUSS &deliver_home,
209   CUSS &address_file,
210   CUSS &address_pipe,
211   CUSS &self_hostname,
212   NULL };
213 
214 int address_expansions_count = sizeof(address_expansions)/sizeof(uschar **);
215 
216 /******************************************************************************/
217 /* General global variables.  Boolean flags are done as a group
218 so that only one bit each is needed, packed, for all those we never
219 need to take a pointer - and only a char for the rest.
220 This means a struct, unfortunately since it clutters the sourcecode. */
221 
222 struct global_flags f =
223 {
224 	.acl_temp_details       = FALSE,
225 	.active_local_from_check = FALSE,
226 	.active_local_sender_retain = FALSE,
227 	.address_test_mode      = FALSE,
228 	.admin_user             = FALSE,
229 	.allow_auth_unadvertised= FALSE,
230 	.allow_unqualified_recipient = TRUE,    /* For local messages */
231 	.allow_unqualified_sender = TRUE,       /* Reset for SMTP */
232 	.authentication_local   = FALSE,
233 
234 	.background_daemon      = TRUE,
235 	.bdat_readers_wanted    = FALSE,
236 
237 	.chunking_offered       = FALSE,
238 	.config_changed         = FALSE,
239 	.continue_more          = FALSE,
240 
241 	.daemon_listen          = FALSE,
242 	.debug_daemon           = FALSE,
243 	.deliver_firsttime      = FALSE,
244 	.deliver_force          = FALSE,
245 	.deliver_freeze         = FALSE,
246 	.deliver_force_thaw     = FALSE,
247 	.deliver_manual_thaw    = FALSE,
248 	.deliver_selectstring_regex = FALSE,
249 	.deliver_selectstring_sender_regex = FALSE,
250 	.disable_callout_flush  = FALSE,
251 	.disable_delay_flush    = FALSE,
252 	.disable_logging        = FALSE,
253 #ifndef DISABLE_DKIM
254 	.dkim_disable_verify      = FALSE,
255 	.dkim_init_done           = FALSE,
256 #endif
257 #ifdef SUPPORT_DMARC
258 	.dmarc_has_been_checked  = FALSE,
259 	.dmarc_disable_verify    = FALSE,
260 	.dmarc_enable_forensic   = FALSE,
261 #endif
262 	.dont_deliver           = FALSE,
263 	.dot_ends               = TRUE,
264 
265 	.enable_dollar_recipients = FALSE,
266 	.expand_string_forcedfail = FALSE,
267 
268 	.filter_running         = FALSE,
269 
270 	.header_rewritten       = FALSE,
271 	.helo_verified          = FALSE,
272 	.helo_verify_failed     = FALSE,
273 	.host_checking_callout  = FALSE,
274 	.host_find_failed_syntax= FALSE,
275 
276 	.inetd_wait_mode        = FALSE,
277 	.is_inetd               = FALSE,
278 
279 	.local_error_message    = FALSE,
280 	.log_testing_mode       = FALSE,
281 
282 #ifdef WITH_CONTENT_SCAN
283 	.no_mbox_unspool        = FALSE,
284 #endif
285 	.no_multiline_responses = FALSE,
286 
287 	.parse_allow_group      = FALSE,
288 	.parse_found_group      = FALSE,
289 	.pipelining_enable      = TRUE,
290 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
291 	.proxy_session_failed   = FALSE,
292 #endif
293 
294 	.queue_2stage           = FALSE,
295 	.queue_only_policy      = FALSE,
296 	.queue_run_first_delivery = FALSE,
297 	.queue_run_force        = FALSE,
298 	.queue_run_local        = FALSE,
299 	.queue_running          = FALSE,
300 	.queue_smtp             = FALSE,
301 
302 	.really_exim            = TRUE,
303 	.receive_call_bombout   = FALSE,
304 	.recipients_discarded   = FALSE,
305 	.running_in_test_harness = FALSE,
306 
307 	.search_find_defer      = FALSE,
308 	.sender_address_forced  = FALSE,
309 	.sender_host_notsocket  = FALSE,
310 	.sender_host_unknown    = FALSE,
311 	.sender_local           = FALSE,
312 	.sender_name_forced     = FALSE,
313 	.sender_set_untrusted   = FALSE,
314 	.smtp_authenticated     = FALSE,
315 #ifndef DISABLE_PIPE_CONNECT
316 	.smtp_in_early_pipe_advertised = FALSE,
317 	.smtp_in_early_pipe_no_auth = FALSE,
318 	.smtp_in_early_pipe_used = FALSE,
319 #endif
320 	.smtp_in_pipelining_advertised = FALSE,
321 	.smtp_in_pipelining_used = FALSE,
322 	.smtp_in_quit		= FALSE,
323 	.spool_file_wireformat  = FALSE,
324 	.submission_mode        = FALSE,
325 	.suppress_local_fixups  = FALSE,
326 	.suppress_local_fixups_default = FALSE,
327 	.synchronous_delivery   = FALSE,
328 	.system_filtering       = FALSE,
329 
330 	.taint_check_slow       = FALSE,
331 	.testsuite_delays	= TRUE,
332 	.tcp_fastopen_ok        = FALSE,
333 	.tcp_in_fastopen        = FALSE,
334 	.tcp_in_fastopen_data   = FALSE,
335 	.tcp_in_fastopen_logged = FALSE,
336 	.tcp_out_fastopen_logged= FALSE,
337 	.timestamps_utc         = FALSE,
338 	.transport_filter_timed_out = FALSE,
339 	.trusted_caller         = FALSE,
340 	.trusted_config         = TRUE,
341 };
342 
343 /******************************************************************************/
344 /* These are the flags which are either variables or mainsection options,
345 so an address is needed for access, or are exported to local_scan. */
346 
347 BOOL    accept_8bitmime        = TRUE; /* deliberately not RFC compliant */
348 BOOL    allow_domain_literals  = FALSE;
349 BOOL    allow_mx_to_ip         = FALSE;
350 BOOL    allow_utf8_domains     = FALSE;
351 BOOL    authentication_failed  = FALSE;
352 
353 BOOL    bounce_return_body     = TRUE;
354 BOOL    bounce_return_message  = TRUE;
355 BOOL    check_rfc2047_length   = TRUE;
356 BOOL    commandline_checks_require_admin = FALSE;
357 
358 #ifdef EXPERIMENTAL_DCC
359 BOOL    dcc_direct_add_header  = FALSE;
360 #endif
361 BOOL    debug_store            = FALSE;
362 BOOL    delivery_date_remove   = TRUE;
363 BOOL    deliver_drop_privilege = FALSE;
364 #ifdef ENABLE_DISABLE_FSYNC
365 BOOL    disable_fsync          = FALSE;
366 #endif
367 BOOL    disable_ipv6           = FALSE;
368 BOOL    dns_csa_use_reverse    = TRUE;
369 BOOL    drop_cr                = FALSE;         /* No longer used */
370 
371 BOOL    envelope_to_remove     = TRUE;
372 BOOL    exim_gid_set           = TRUE;          /* This gid is always set */
373 BOOL    exim_uid_set           = TRUE;          /* This uid is always set */
374 BOOL    extract_addresses_remove_arguments = TRUE;
375 
376 BOOL    host_checking          = FALSE;
377 BOOL    host_lookup_deferred   = FALSE;
378 BOOL    host_lookup_failed     = FALSE;
379 BOOL    ignore_fromline_local  = FALSE;
380 
381 BOOL    local_from_check       = TRUE;
382 BOOL    local_sender_retain    = FALSE;
383 BOOL    log_timezone           = FALSE;
384 BOOL    message_body_newlines  = FALSE;
385 BOOL    message_logs           = TRUE;
386 #ifdef SUPPORT_I18N
387 BOOL    message_smtputf8       = FALSE;
388 #endif
389 BOOL    mua_wrapper            = FALSE;
390 
391 BOOL    preserve_message_logs  = FALSE;
392 BOOL    print_topbitchars      = FALSE;
393 BOOL    prod_requires_admin    = TRUE;
394 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
395 BOOL    proxy_session          = FALSE;
396 #endif
397 
398 #ifndef DISABLE_QUEUE_RAMP
399 BOOL    queue_fast_ramp		= FALSE;
400 #endif
401 BOOL    queue_list_requires_admin = TRUE;
402 BOOL    queue_only             = FALSE;
403 BOOL    queue_only_load_latch  = TRUE;
404 BOOL    queue_only_override    = TRUE;
405 BOOL    queue_run_in_order     = FALSE;
406 BOOL    recipients_max_reject  = FALSE;
407 BOOL    return_path_remove     = TRUE;
408 
409 BOOL    smtp_batched_input     = FALSE;
410 BOOL    sender_helo_dnssec     = FALSE;
411 BOOL    sender_host_dnssec     = FALSE;
412 BOOL    smtp_accept_keepalive  = TRUE;
413 BOOL    smtp_check_spool_space = TRUE;
414 BOOL    smtp_enforce_sync      = TRUE;
415 BOOL    smtp_etrn_serialize    = TRUE;
416 BOOL    smtp_input             = FALSE;
417 BOOL    smtp_return_error_details = FALSE;
418 #ifdef SUPPORT_SPF
419 BOOL    spf_result_guessed     = FALSE;
420 #endif
421 BOOL    split_spool_directory  = FALSE;
422 BOOL    spool_wireformat       = FALSE;
423 #ifdef EXPERIMENTAL_SRS_ALT
424 BOOL    srs_usehash            = TRUE;
425 BOOL    srs_usetimestamp       = TRUE;
426 #endif
427 BOOL    strict_acl_vars        = FALSE;
428 BOOL    strip_excess_angle_brackets = FALSE;
429 BOOL    strip_trailing_dot     = FALSE;
430 BOOL    syslog_duplication     = TRUE;
431 BOOL    syslog_pid             = TRUE;
432 BOOL    syslog_timestamp       = TRUE;
433 BOOL    system_filter_gid_set  = FALSE;
434 BOOL    system_filter_uid_set  = FALSE;
435 
436 BOOL    tcp_nodelay            = TRUE;
437 BOOL    write_rejectlog        = TRUE;
438 
439 /******************************************************************************/
440 
441 header_line *acl_added_headers = NULL;
442 tree_node *acl_anchor          = NULL;
443 uschar *acl_arg[9]             = {NULL, NULL, NULL, NULL, NULL,
444                                   NULL, NULL, NULL, NULL};
445 int     acl_narg               = 0;
446 
447 int     acl_level	       = 0;
448 
449 uschar *acl_not_smtp           = NULL;
450 #ifdef WITH_CONTENT_SCAN
451 uschar *acl_not_smtp_mime      = NULL;
452 #endif
453 uschar *acl_not_smtp_start     = NULL;
454 uschar *acl_removed_headers    = NULL;
455 uschar *acl_smtp_auth          = NULL;
456 uschar *acl_smtp_connect       = NULL;
457 uschar *acl_smtp_data          = NULL;
458 #ifndef DISABLE_PRDR
459 uschar *acl_smtp_data_prdr     = US"accept";
460 #endif
461 #ifndef DISABLE_DKIM
462 uschar *acl_smtp_dkim          = NULL;
463 #endif
464 uschar *acl_smtp_etrn          = NULL;
465 uschar *acl_smtp_expn          = NULL;
466 uschar *acl_smtp_helo          = NULL;
467 uschar *acl_smtp_mail          = NULL;
468 uschar *acl_smtp_mailauth      = NULL;
469 #ifdef WITH_CONTENT_SCAN
470 uschar *acl_smtp_mime          = NULL;
471 #endif
472 uschar *acl_smtp_notquit       = NULL;
473 uschar *acl_smtp_predata       = NULL;
474 uschar *acl_smtp_quit          = NULL;
475 uschar *acl_smtp_rcpt          = NULL;
476 uschar *acl_smtp_starttls      = NULL;
477 uschar *acl_smtp_vrfy          = NULL;
478 
479 tree_node *acl_var_c           = NULL;
480 tree_node *acl_var_m           = NULL;
481 uschar *acl_verify_message     = NULL;
482 string_item *acl_warn_logged   = NULL;
483 
484 /* Names of SMTP places for use in ACL error messages, and corresponding SMTP
485 error codes - keep in step with definitions of ACL_WHERE_xxxx in macros.h. */
486 
487 uschar *acl_wherenames[]       = { US"RCPT",
488                                    US"MAIL",
489                                    US"PREDATA",
490                                    US"MIME",
491                                    US"DKIM",
492                                    US"DATA",
493 #ifndef DISABLE_PRDR
494                                    US"PRDR",
495 #endif
496                                    US"non-SMTP",
497                                    US"AUTH",
498                                    US"connection",
499                                    US"ETRN",
500                                    US"EXPN",
501                                    US"EHLO or HELO",
502                                    US"MAILAUTH",
503                                    US"non-SMTP-start",
504                                    US"NOTQUIT",
505                                    US"QUIT",
506                                    US"STARTTLS",
507                                    US"VRFY",
508 				   US"delivery",
509 				   US"unknown"
510                                  };
511 
512 uschar *acl_wherecodes[]       = { US"550",     /* RCPT */
513                                    US"550",     /* MAIL */
514                                    US"550",     /* PREDATA */
515                                    US"550",     /* MIME */
516                                    US"550",     /* DKIM */
517                                    US"550",     /* DATA */
518 #ifndef DISABLE_PRDR
519                                    US"550",    /* RCPT PRDR */
520 #endif
521                                    US"0",       /* not SMTP; not relevant */
522                                    US"503",     /* AUTH */
523                                    US"550",     /* connect */
524                                    US"458",     /* ETRN */
525                                    US"550",     /* EXPN */
526                                    US"550",     /* HELO/EHLO */
527                                    US"0",       /* MAILAUTH; not relevant */
528                                    US"0",       /* not SMTP; not relevant */
529                                    US"0",       /* NOTQUIT; not relevant */
530                                    US"0",       /* QUIT; not relevant */
531                                    US"550",     /* STARTTLS */
532                                    US"252",     /* VRFY */
533 				   US"0",       /* delivery; not relevant */
534 				   US"0"        /* unknown; not relevant */
535                                  };
536 
537 uschar *add_environment        = NULL;
538 address_item  *addr_duplicate  = NULL;
539 
540 address_item address_defaults = {
541   .next =		NULL,
542   .parent =		NULL,
543   .first =		NULL,
544   .dupof =		NULL,
545   .start_router =	NULL,
546   .router =		NULL,
547   .transport =		NULL,
548   .host_list =		NULL,
549   .host_used =		NULL,
550   .fallback_hosts =	NULL,
551   .reply =		NULL,
552   .retries =		NULL,
553   .address =		NULL,
554   .unique =		NULL,
555   .cc_local_part =	NULL,
556   .lc_local_part =	NULL,
557   .local_part =		NULL,
558   .prefix =		NULL,
559   .prefix_v =		NULL,
560   .suffix =		NULL,
561   .suffix_v =		NULL,
562   .domain =		NULL,
563   .address_retry_key =	NULL,
564   .domain_retry_key =	NULL,
565   .current_dir =	NULL,
566   .home_dir =		NULL,
567   .message =		NULL,
568   .user_message =	NULL,
569   .onetime_parent =	NULL,
570   .pipe_expandn =	NULL,
571   .return_filename =	NULL,
572   .self_hostname =	NULL,
573   .shadow_message =	NULL,
574 #ifndef DISABLE_TLS
575   .cipher =		NULL,
576   .ourcert =		NULL,
577   .peercert =		NULL,
578   .peerdn =		NULL,
579   .ocsp =		OCSP_NOT_REQ,
580 #endif
581 #ifdef EXPERIMENTAL_DSN_INFO
582   .smtp_greeting =	NULL,
583   .helo_response =	NULL,
584 #endif
585   .authenticator =	NULL,
586   .auth_id =		NULL,
587   .auth_sndr =		NULL,
588   .dsn_orcpt =		NULL,
589   .dsn_flags =		0,
590   .dsn_aware =		0,
591   .uid =		(uid_t)(-1),
592   .gid =		(gid_t)(-1),
593   .flags =		{ 0 },
594   .domain_cache =	{ 0 },                /* domain_cache - any larger array should be zeroed */
595   .localpart_cache =	{ 0 },                /* localpart_cache - ditto */
596   .mode =		-1,
597   .more_errno =		0,
598   .delivery_time =	{.tv_sec = 0, .tv_usec = 0},
599   .basic_errno =	ERRNO_UNKNOWNERROR,
600   .child_count =	0,
601   .return_file =	-1,
602   .special_action =	SPECIAL_NONE,
603   .transport_return =	DEFER,
604   .prop = {					/* fields that are propagated to children */
605     .address_data =	NULL,
606     .domain_data =	NULL,
607     .localpart_data =	NULL,
608     .errors_address =	NULL,
609     .extra_headers =	NULL,
610     .remove_headers =	NULL,
611     .variables =	NULL,
612 #ifdef EXPERIMENTAL_SRS_ALT
613     .srs_sender =	NULL,
614 #endif
615     .ignore_error =	FALSE,
616 #ifdef SUPPORT_I18N
617     .utf8_msg =		FALSE,
618     .utf8_downcvt =	FALSE,
619     .utf8_downcvt_maybe = FALSE
620 #endif
621   }
622 };
623 
624 uschar *address_file           = NULL;
625 uschar *address_pipe           = NULL;
626 tree_node *addresslist_anchor  = NULL;
627 int     addresslist_count      = 0;
628 gid_t  *admin_groups           = NULL;
629 
630 #ifdef EXPERIMENTAL_ARC
631 struct arc_set *arc_received	= NULL;
632 int     arc_received_instance	= 0;
633 int     arc_oldest_pass		= 0;
634 const uschar *arc_state		= NULL;
635 const uschar *arc_state_reason	= NULL;
636 #endif
637 
638 uschar *authenticated_fail_id  = NULL;
639 uschar *authenticated_id       = NULL;
640 uschar *authenticated_sender   = NULL;
641 auth_instance  *auths          = NULL;
642 uschar *auth_advertise_hosts   = US"*";
643 auth_instance auth_defaults    = {
644     .next =		NULL,
645     .name =		NULL,
646     .info =		NULL,
647     .options_block =	NULL,
648     .driver_name =	NULL,
649     .advertise_condition = NULL,
650     .client_condition =	NULL,
651     .public_name =	NULL,
652     .set_id =		NULL,
653     .set_client_id =	NULL,
654     .mail_auth_condition = NULL,
655     .server_debug_string = NULL,
656     .server_condition =	NULL,
657     .client =		FALSE,
658     .server =		FALSE,
659     .advertised =	FALSE
660 };
661 
662 uschar *auth_defer_msg         = US"reason not recorded";
663 uschar *auth_defer_user_msg    = US"";
664 uschar *auth_vars[AUTH_VARS];
665 int     auto_thaw              = 0;
666 #ifdef WITH_CONTENT_SCAN
667 int     av_failed              = FALSE;	/* boolean but accessed as vtype_int*/
668 uschar *av_scanner             = US"sophie:/var/run/sophie";  /* AV scanner */
669 #endif
670 
671 #if BASE_62 == 62
672 uschar *base62_chars=
673     US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz";
674 #else
675 uschar *base62_chars= US"0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ";
676 #endif
677 
678 uschar *bi_command             = NULL;
679 uschar *big_buffer             = NULL;
680 int     big_buffer_size        = BIG_BUFFER_SIZE;
681 #ifdef EXPERIMENTAL_BRIGHTMAIL
682 uschar *bmi_alt_location       = NULL;
683 uschar *bmi_base64_tracker_verdict = NULL;
684 uschar *bmi_base64_verdict     = NULL;
685 uschar *bmi_config_file        = US"/opt/brightmail/etc/brightmail.cfg";
686 int     bmi_deliver            = 1;
687 int     bmi_run                = 0;
688 uschar *bmi_verdicts           = NULL;
689 #endif
690 int     bsmtp_transaction_linecount = 0;
691 int     body_8bitmime          = 0;
692 int     body_linecount         = 0;
693 int     body_zerocount         = 0;
694 uschar *bounce_message_file    = NULL;
695 uschar *bounce_message_text    = NULL;
696 uschar *bounce_recipient       = NULL;
697 int     bounce_return_linesize_limit = 998;
698 int     bounce_return_size_limit = 100*1024;
699 uschar *bounce_sender_authentication = NULL;
700 
701 uschar *callout_address        = NULL;
702 int     callout_cache_domain_positive_expire = 7*24*60*60;
703 int     callout_cache_domain_negative_expire = 3*60*60;
704 int     callout_cache_positive_expire = 24*60*60;
705 int     callout_cache_negative_expire = 2*60*60;
706 uschar *callout_random_local_part = US"$primary_hostname-$tod_epoch-testing";
707 uschar *check_dns_names_pattern= US"(?i)^(?>(?(1)\\.|())[^\\W](?>[a-z0-9/_-]*[^\\W])?)+(\\.?)$";
708 int     check_log_inodes       = 100;
709 int_eximarith_t check_log_space = 10*1024;	/* 10K Kbyte == 10MB */
710 int     check_spool_inodes     = 100;
711 int_eximarith_t check_spool_space = 10*1024;	/* 10K Kbyte == 10MB */
712 
713 uschar *chunking_advertise_hosts = US"*";
714 unsigned chunking_datasize     = 0;
715 unsigned chunking_data_left    = 0;
716 chunking_state_t chunking_state= CHUNKING_NOT_OFFERED;
717 const pcre *regex_CHUNKING     = NULL;
718 
719 #ifdef EXPERIMENTAL_ESMTP_LIMITS
720 const pcre *regex_LIMITS        = NULL;
721 #endif
722 
723 uschar *client_authenticator   = NULL;
724 uschar *client_authenticated_id = NULL;
725 uschar *client_authenticated_sender = NULL;
726 int     clmacro_count          = 0;
727 uschar *clmacros[MAX_CLMACROS];
728 FILE   *config_file            = NULL;
729 const uschar *config_filename  = NULL;
730 int     config_lineno          = 0;
731 #ifdef CONFIGURE_GROUP
732 gid_t   config_gid             = CONFIGURE_GROUP;
733 #else
734 gid_t   config_gid             = 0;
735 #endif
736 uschar *config_main_filelist   = US CONFIGURE_FILE
737                          "\0<-----------Space to patch configure_filename->";
738 uschar *config_main_filename   = NULL;
739 uschar *config_main_directory  = NULL;
740 
741 #ifdef CONFIGURE_OWNER
742 uid_t   config_uid             = CONFIGURE_OWNER;
743 #else
744 uid_t   config_uid             = 0;
745 #endif
746 
747 int     connection_max_messages= -1;
748 uschar *continue_proxy_cipher  = NULL;
749 BOOL    continue_proxy_dane    = FALSE;
750 uschar *continue_proxy_sni     = NULL;
751 uschar *continue_hostname      = NULL;
752 uschar *continue_host_address  = NULL;
753 int     continue_sequence      = 1;
754 uschar *continue_transport     = NULL;
755 #ifdef EXPERIMENTAL_ESMTP_LIMITS
756 unsigned continue_limit_mail   = 0;
757 unsigned continue_limit_rcpt   = 0;
758 unsigned continue_limit_rcptdom= 0;
759 #endif
760 
761 uschar *csa_status             = NULL;
762 cut_t   cutthrough = {
763   .callout_hold_only =	FALSE,				/* verify-only: normal delivery */
764   .delivery =		FALSE,				/* when to attempt */
765   .defer_pass =		FALSE,				/* on defer: spool locally */
766   .is_tls =		FALSE,				/* not a TLS conn yet */
767   .cctx =		{.sock = -1},			/* open connection */
768   .nrcpt =		0,				/* number of addresses */
769 };
770 
771 int	daemon_notifier_fd     = -1;
772 uschar *daemon_smtp_port       = US"smtp";
773 int     daemon_startup_retries = 9;
774 int     daemon_startup_sleep   = 30;
775 
776 #ifdef EXPERIMENTAL_DCC
777 uschar *dcc_header             = NULL;
778 uschar *dcc_result             = NULL;
779 uschar *dccifd_address         = US"/usr/local/dcc/var/dccifd";
780 uschar *dccifd_options         = US"header";
781 #endif
782 
783 int     debug_fd               = -1;
784 FILE   *debug_file             = NULL;
785 int     debug_notall[]         = {
786   Di_memory,
787   Di_noutf8,
788   -1
789 };
790 bit_table debug_options[]      = { /* must be in alphabetical order and use
791 				 only the enum values from macro.h */
792   BIT_TABLE(D, acl),
793   BIT_TABLE(D, all),
794   BIT_TABLE(D, auth),
795   BIT_TABLE(D, deliver),
796   BIT_TABLE(D, dns),
797   BIT_TABLE(D, dnsbl),
798   BIT_TABLE(D, exec),
799   BIT_TABLE(D, expand),
800   BIT_TABLE(D, filter),
801   BIT_TABLE(D, hints_lookup),
802   BIT_TABLE(D, host_lookup),
803   BIT_TABLE(D, ident),
804   BIT_TABLE(D, interface),
805   BIT_TABLE(D, lists),
806   BIT_TABLE(D, load),
807   BIT_TABLE(D, local_scan),
808   BIT_TABLE(D, lookup),
809   BIT_TABLE(D, memory),
810   BIT_TABLE(D, noutf8),
811   BIT_TABLE(D, pid),
812   BIT_TABLE(D, process_info),
813   BIT_TABLE(D, queue_run),
814   BIT_TABLE(D, receive),
815   BIT_TABLE(D, resolver),
816   BIT_TABLE(D, retry),
817   BIT_TABLE(D, rewrite),
818   BIT_TABLE(D, route),
819   BIT_TABLE(D, timestamp),
820   BIT_TABLE(D, tls),
821   BIT_TABLE(D, transport),
822   BIT_TABLE(D, uid),
823   BIT_TABLE(D, verify),
824 };
825 int     debug_options_count    = nelem(debug_options);
826 
827 unsigned int debug_selector    = 0;
828 int     delay_warning[DELAY_WARNING_SIZE] = { DELAY_WARNING_SIZE, 1, 24*60*60 };
829 uschar *delay_warning_condition=
830   US"${if or {"
831             "{ !eq{$h_list-id:$h_list-post:$h_list-subscribe:}{} }"
832             "{ match{$h_precedence:}{(?i)bulk|list|junk} }"
833             "{ match{$h_auto-submitted:}{(?i)auto-generated|auto-replied} }"
834             "} {no}{yes}}";
835 uschar *deliver_address_data   = NULL;
836 int     deliver_datafile       = -1;
837 const uschar *deliver_domain   = NULL;
838 uschar *deliver_domain_data    = NULL;
839 const uschar *deliver_domain_orig = NULL;
840 const uschar *deliver_domain_parent = NULL;
841 time_t  deliver_frozen_at      = 0;
842 uschar *deliver_home           = NULL;
843 const uschar *deliver_host     = NULL;
844 const uschar *deliver_host_address = NULL;
845 int     deliver_host_port      = 0;
846 uschar *deliver_in_buffer      = NULL;
847 ino_t   deliver_inode          = 0;
848 uschar *deliver_localpart      = NULL;
849 uschar *deliver_localpart_data = NULL;
850 uschar *deliver_localpart_orig = NULL;
851 uschar *deliver_localpart_parent = NULL;
852 uschar *deliver_localpart_prefix = NULL;
853 uschar *deliver_localpart_prefix_v = NULL;
854 uschar *deliver_localpart_suffix = NULL;
855 uschar *deliver_localpart_suffix_v = NULL;
856 uschar *deliver_out_buffer     = NULL;
857 int     deliver_queue_load_max = -1;
858 address_item  *deliver_recipients = NULL;
859 uschar *deliver_selectstring   = NULL;
860 uschar *deliver_selectstring_sender = NULL;
861 
862 #ifndef DISABLE_DKIM
863 unsigned dkim_collect_input      = 0;
864 uschar *dkim_cur_signer          = NULL;
865 int     dkim_key_length          = 0;
866 void   *dkim_signatures		 = NULL;
867 uschar *dkim_signers             = NULL;
868 uschar *dkim_signing_domain      = NULL;
869 uschar *dkim_signing_selector    = NULL;
870 uschar *dkim_verify_hashes       = US"sha256:sha512";
871 uschar *dkim_verify_keytypes     = US"ed25519:rsa";
872 uschar *dkim_verify_min_keysizes = US"rsa=1024 ed25519=250";
873 BOOL	dkim_verify_minimal      = FALSE;
874 uschar *dkim_verify_overall      = NULL;
875 uschar *dkim_verify_signers      = US"$dkim_signers";
876 uschar *dkim_verify_status	 = NULL;
877 uschar *dkim_verify_reason	 = NULL;
878 #endif
879 #ifdef SUPPORT_DMARC
880 uschar *dmarc_domain_policy     = NULL;
881 uschar *dmarc_forensic_sender   = NULL;
882 uschar *dmarc_history_file      = NULL;
883 uschar *dmarc_status            = NULL;
884 uschar *dmarc_status_text       = NULL;
885 uschar *dmarc_tld_file          = NULL;
886 uschar *dmarc_used_domain       = NULL;
887 #endif
888 
889 uschar *dns_again_means_nonexist = NULL;
890 int     dns_csa_search_limit   = 5;
891 int	dns_cname_loops	       = 1;
892 #ifdef SUPPORT_DANE
893 int     dns_dane_ok            = -1;
894 #endif
895 uschar *dns_ipv4_lookup        = NULL;
896 int     dns_retrans            = 0;
897 int     dns_retry              = 0;
898 int     dns_dnssec_ok          = -1; /* <0 = not coerced */
899 uschar *dns_trust_aa           = NULL;
900 int     dns_use_edns0          = -1; /* <0 = not coerced */
901 uschar *dnslist_domain         = NULL;
902 uschar *dnslist_matched        = NULL;
903 uschar *dnslist_text           = NULL;
904 uschar *dnslist_value          = NULL;
905 tree_node *domainlist_anchor   = NULL;
906 int     domainlist_count       = 0;
907 uschar *dsn_from               = US DEFAULT_DSN_FROM;
908 
909 int     errno_quota            = ERRNO_QUOTA;
910 uschar *errors_copy            = NULL;
911 int     error_handling         = ERRORS_SENDER;
912 uschar *errors_reply_to        = NULL;
913 int     errors_sender_rc       = EXIT_FAILURE;
914 #ifndef DISABLE_EVENT
915 uschar *event_action             = NULL;	/* expansion for delivery events */
916 uschar *event_data               = NULL;	/* auxiliary data variable for event */
917 int     event_defer_errno        = 0;
918 const uschar *event_name         = NULL;	/* event name variable */
919 #endif
920 
921 
922 gid_t   exim_gid               = EXIM_GID;
923 uschar *exim_path              = US BIN_DIRECTORY "/exim"
924                         "\0<---------------Space to patch exim_path->";
925 uid_t   exim_uid               = EXIM_UID;
926 int     expand_level	       = 0;		/* Nesting depth, indent for debug */
927 int     expand_forbid          = 0;
928 int     expand_nlength[EXPAND_MAXN+1];
929 int     expand_nmax            = -1;
930 uschar *expand_nstring[EXPAND_MAXN+1];
931 uschar *expand_string_message;
932 uschar *extra_local_interfaces = NULL;
933 
934 int     fake_response          = OK;
935 uschar *fake_response_text     = US"Your message has been rejected but is "
936                                    "being kept for evaluation.\nIf it was a "
937                                    "legitimate message, it may still be "
938                                    "delivered to the target recipient(s).";
939 int     filter_n[FILTER_VARIABLE_COUNT];
940 int     filter_sn[FILTER_VARIABLE_COUNT];
941 int     filter_test            = FTEST_NONE;
942 uschar *filter_test_sfile      = NULL;
943 uschar *filter_test_ufile      = NULL;
944 uschar *filter_thisaddress     = NULL;
945 int     finduser_retries       = 0;
946 uid_t   fixed_never_users[]    = { FIXED_NEVER_USERS };
947 uschar *freeze_tell            = NULL;
948 uschar *freeze_tell_config     = NULL;
949 uschar *fudged_queue_times     = US"";
950 
951 uschar *gecos_name             = NULL;
952 uschar *gecos_pattern          = NULL;
953 rewrite_rule  *global_rewrite_rules = NULL;
954 
955 volatile sig_atomic_t had_command_timeout = 0;
956 volatile sig_atomic_t had_command_sigterm = 0;
957 volatile sig_atomic_t had_data_timeout    = 0;
958 volatile sig_atomic_t had_data_sigint     = 0;
959 uschar *headers_charset        = US HEADERS_CHARSET;
960 int     header_insert_maxlen   = 64 * 1024;
961 header_line  *header_last      = NULL;
962 header_line  *header_list      = NULL;
963 int     header_maxsize         = HEADER_MAXSIZE;
964 int     header_line_maxsize    = 0;
965 
966 header_name header_names[] = {
967   /* name		len	allow_resent	htype */
968   { US"bcc",            3,	TRUE,		htype_bcc },
969   { US"cc",             2,	TRUE,		htype_cc },
970   { US"date",           4,	TRUE,		htype_date },
971   { US"delivery-date", 13,	FALSE,		htype_delivery_date },
972   { US"envelope-to",   11,	FALSE,		htype_envelope_to },
973   { US"from",           4,	TRUE,		htype_from },
974   { US"message-id",    10,	TRUE,		htype_id },
975   { US"received",       8,	FALSE,		htype_received },
976   { US"reply-to",       8,	FALSE,		htype_reply_to },
977   { US"return-path",   11,	FALSE,		htype_return_path },
978   { US"sender",         6,	TRUE,		htype_sender },
979   { US"subject",        7,	FALSE,		htype_subject },
980   { US"to",             2,	TRUE,		htype_to }
981 };
982 
983 int header_names_size          = nelem(header_names);
984 
985 uschar *helo_accept_junk_hosts = NULL;
986 uschar *helo_allow_chars       = US"";
987 uschar *helo_lookup_domains    = US"@ : @[]";
988 uschar *helo_try_verify_hosts  = NULL;
989 uschar *helo_verify_hosts      = NULL;
990 const uschar *hex_digits       = CUS"0123456789abcdef";
991 uschar *hold_domains           = NULL;
992 uschar *host_data              = NULL;
993 uschar *host_lookup            = NULL;
994 uschar *host_lookup_order      = US"bydns:byaddr";
995 uschar *host_lookup_msg        = US"";
996 int     host_number            = 0;
997 uschar *host_number_string     = NULL;
998 uschar *host_reject_connection = NULL;
999 tree_node *hostlist_anchor     = NULL;
1000 int     hostlist_count         = 0;
1001 uschar *hosts_treat_as_local   = NULL;
1002 uschar *hosts_require_helo     = US"*";
1003 uschar *hosts_connection_nolog = NULL;
1004 
1005 int     ignore_bounce_errors_after = 10*7*24*60*60;  /* 10 weeks */
1006 uschar *ignore_fromline_hosts  = NULL;
1007 int     inetd_wait_timeout     = -1;
1008 uschar *initial_cwd            = NULL;
1009 uschar *interface_address      = NULL;
1010 int     interface_port         = -1;
1011 uschar *iterate_item           = NULL;
1012 
1013 int     journal_fd             = -1;
1014 
1015 uschar *keep_environment       = NULL;
1016 
1017 int     keep_malformed         = 4*24*60*60;    /* 4 days */
1018 
1019 uschar *eldap_dn               = NULL;
1020 #ifdef EXPERIMENTAL_ESMTP_LIMITS
1021 uschar *limits_advertise_hosts = US"*";
1022 #endif
1023 int     load_average           = -2;
1024 uschar *local_from_prefix      = NULL;
1025 uschar *local_from_suffix      = NULL;
1026 
1027 #if HAVE_IPV6
1028 uschar *local_interfaces       = US"<; ::0 ; 0.0.0.0";
1029 #else
1030 uschar *local_interfaces       = US"0.0.0.0";
1031 #endif
1032 
1033 #ifdef HAVE_LOCAL_SCAN
1034 uschar *local_scan_data        = NULL;
1035 int     local_scan_timeout     = 5*60;
1036 #endif
1037 gid_t   local_user_gid         = (gid_t)(-1);
1038 uid_t   local_user_uid         = (uid_t)(-1);
1039 
1040 tree_node *localpartlist_anchor= NULL;
1041 int     localpartlist_count    = 0;
1042 uschar *log_buffer             = NULL;
1043 
1044 int     log_default[]          = { /* for initializing log_selector */
1045   Li_acl_warn_skipped,
1046   Li_connection_reject,
1047   Li_delay_delivery,
1048   Li_dkim,
1049   Li_dnslist_defer,
1050   Li_etrn,
1051   Li_host_lookup_failed,
1052   Li_lost_incoming_connection,
1053   Li_outgoing_interface, /* see d_log_interface in deliver.c */
1054   Li_msg_id,
1055   Li_queue_run,
1056   Li_queue_time_exclusive,
1057   Li_rejected_header,
1058   Li_retry_defer,
1059   Li_sender_verify_fail,
1060   Li_size_reject,
1061   Li_skip_delivery,
1062   Li_smtp_confirmation,
1063 #ifdef ALLOW_INSECURE_TAINTED_DATA
1064   Li_tainted,
1065 #endif
1066   Li_tls_certificate_verified,
1067   Li_tls_cipher,
1068   -1
1069 };
1070 
1071 uschar *log_file_path          = US LOG_FILE_PATH
1072                            "\0<--------------Space to patch log_file_path->";
1073 
1074 int     log_notall[]           = {
1075   -1
1076 };
1077 bit_table log_options[]        = { /* must be in alphabetical order,
1078 				with definitions from enum logbit. */
1079   BIT_TABLE(L, 8bitmime),
1080   BIT_TABLE(L, acl_warn_skipped),
1081   BIT_TABLE(L, address_rewrite),
1082   BIT_TABLE(L, all),
1083   BIT_TABLE(L, all_parents),
1084   BIT_TABLE(L, arguments),
1085   BIT_TABLE(L, connection_reject),
1086   BIT_TABLE(L, delay_delivery),
1087   BIT_TABLE(L, deliver_time),
1088   BIT_TABLE(L, delivery_size),
1089 #ifndef DISABLE_DKIM
1090   BIT_TABLE(L, dkim),
1091   BIT_TABLE(L, dkim_verbose),
1092 #endif
1093   BIT_TABLE(L, dnslist_defer),
1094   BIT_TABLE(L, dnssec),
1095   BIT_TABLE(L, etrn),
1096   BIT_TABLE(L, host_lookup_failed),
1097   BIT_TABLE(L, ident_timeout),
1098   BIT_TABLE(L, incoming_interface),
1099   BIT_TABLE(L, incoming_port),
1100   BIT_TABLE(L, lost_incoming_connection),
1101   BIT_TABLE(L, millisec),
1102   BIT_TABLE(L, msg_id),
1103   BIT_TABLE(L, msg_id_created),
1104   BIT_TABLE(L, outgoing_interface),
1105   BIT_TABLE(L, outgoing_port),
1106   BIT_TABLE(L, pid),
1107   BIT_TABLE(L, pipelining),
1108   BIT_TABLE(L, protocol_detail),
1109 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1110   BIT_TABLE(L, proxy),
1111 #endif
1112   BIT_TABLE(L, queue_run),
1113   BIT_TABLE(L, queue_time),
1114   BIT_TABLE(L, queue_time_exclusive),
1115   BIT_TABLE(L, queue_time_overall),
1116   BIT_TABLE(L, receive_time),
1117   BIT_TABLE(L, received_recipients),
1118   BIT_TABLE(L, received_sender),
1119   BIT_TABLE(L, rejected_header),
1120   { US"rejected_headers", Li_rejected_header },
1121   BIT_TABLE(L, retry_defer),
1122   BIT_TABLE(L, return_path_on_delivery),
1123   BIT_TABLE(L, sender_on_delivery),
1124   BIT_TABLE(L, sender_verify_fail),
1125   BIT_TABLE(L, size_reject),
1126   BIT_TABLE(L, skip_delivery),
1127   BIT_TABLE(L, smtp_confirmation),
1128   BIT_TABLE(L, smtp_connection),
1129   BIT_TABLE(L, smtp_incomplete_transaction),
1130   BIT_TABLE(L, smtp_mailauth),
1131   BIT_TABLE(L, smtp_no_mail),
1132   BIT_TABLE(L, smtp_protocol_error),
1133   BIT_TABLE(L, smtp_syntax_error),
1134   BIT_TABLE(L, subject),
1135 #ifdef ALLOW_INSECURE_TAINTED_DATA
1136   BIT_TABLE(L, tainted),
1137 #endif
1138   BIT_TABLE(L, tls_certificate_verified),
1139   BIT_TABLE(L, tls_cipher),
1140   BIT_TABLE(L, tls_peerdn),
1141   BIT_TABLE(L, tls_resumption),
1142   BIT_TABLE(L, tls_sni),
1143   BIT_TABLE(L, unknown_in_list),
1144 };
1145 int     log_options_count      = nelem(log_options);
1146 
1147 int     log_reject_target      = 0;
1148 unsigned int log_selector[log_selector_size]; /* initialized in main() */
1149 uschar *log_selector_string    = NULL;
1150 FILE   *log_stderr             = NULL;
1151 uschar *login_sender_address   = NULL;
1152 uschar *lookup_dnssec_authenticated = NULL;
1153 int     lookup_open_max        = 25;
1154 uschar *lookup_value           = NULL;
1155 
1156 macro_item *macros_user        = NULL;
1157 uschar *mailstore_basename     = NULL;
1158 #ifdef WITH_CONTENT_SCAN
1159 uschar *malware_name           = NULL;  /* Virus Name */
1160 #endif
1161 int     max_received_linelength= 0;
1162 int     max_username_length    = 0;
1163 int     message_age            = 0;
1164 uschar *message_body           = NULL;
1165 uschar *message_body_end       = NULL;
1166 int     message_body_size      = 0;
1167 int     message_body_visible   = 500;
1168 int     message_ended          = END_NOTSTARTED;
1169 uschar *message_headers        = NULL;
1170 uschar *message_id;
1171 uschar *message_id_domain      = NULL;
1172 uschar *message_id_text        = NULL;
1173 struct timeval message_id_tv   = { 0, 0 };
1174 uschar  message_id_option[MESSAGE_ID_LENGTH + 3];
1175 uschar *message_id_external;
1176 int     message_linecount      = 0;
1177 int     message_size           = 0;
1178 uschar *message_size_limit     = US"50M";
1179 #ifdef SUPPORT_I18N
1180 int     message_utf8_downconvert = 0;	/* -1 ifneeded; 0 never; 1 always */
1181 #endif
1182 uschar  message_subdir[2]      = { 0, 0 };
1183 uschar *message_reference      = NULL;
1184 
1185 /* MIME ACL expandables */
1186 #ifdef WITH_CONTENT_SCAN
1187 int     mime_anomaly_level     = 0;
1188 const uschar *mime_anomaly_text      = NULL;
1189 uschar *mime_boundary          = NULL;
1190 uschar *mime_charset           = NULL;
1191 uschar *mime_content_description = NULL;
1192 uschar *mime_content_disposition = NULL;
1193 uschar *mime_content_id        = NULL;
1194 unsigned int mime_content_size = 0;
1195 uschar *mime_content_transfer_encoding = NULL;
1196 uschar *mime_content_type      = NULL;
1197 uschar *mime_decoded_filename  = NULL;
1198 uschar *mime_filename          = NULL;
1199 int     mime_is_multipart      = 0;
1200 int     mime_is_coverletter    = 0;
1201 int     mime_is_rfc822         = 0;
1202 int     mime_part_count        = -1;
1203 #endif
1204 
1205 uid_t  *never_users            = NULL;
1206 uschar *notifier_socket        = US"$spool_directory/" NOTIFIER_SOCKET_NAME ;
1207 
1208 const int on                   = 1;	/* for setsockopt */
1209 const int off                  = 0;
1210 
1211 uid_t   original_euid;
1212 gid_t   originator_gid;
1213 uschar *originator_login       = NULL;
1214 uschar *originator_name        = NULL;
1215 uid_t   originator_uid;
1216 uschar *override_local_interfaces = NULL;
1217 uschar *override_pid_file_path = NULL;
1218 
1219 uschar *percent_hack_domains   = NULL;
1220 uschar *pid_file_path          = US PID_FILE_PATH
1221                            "\0<--------------Space to patch pid_file_path->";
1222 #ifndef DISABLE_PIPE_CONNECT
1223 uschar *pipe_connect_advertise_hosts = US"*";
1224 #endif
1225 uschar *pipelining_advertise_hosts = US"*";
1226 uschar *primary_hostname       = NULL;
1227 uschar *process_info;
1228 int     process_info_len       = 0;
1229 uschar *process_log_path       = NULL;
1230 const uschar *process_purpose  = US"fresh-exec";
1231 
1232 #if defined(SUPPORT_PROXY) || defined(SUPPORT_SOCKS)
1233 uschar *hosts_proxy            = NULL;
1234 uschar *proxy_external_address = NULL;
1235 int     proxy_external_port    = 0;
1236 uschar *proxy_local_address    = NULL;
1237 int     proxy_local_port       = 0;
1238 int     proxy_protocol_timeout = 3;
1239 #endif
1240 
1241 uschar *prvscheck_address      = NULL;
1242 uschar *prvscheck_keynum       = NULL;
1243 uschar *prvscheck_result       = NULL;
1244 
1245 
1246 const uschar *qualify_domain_recipient = NULL;
1247 uschar *qualify_domain_sender  = NULL;
1248 uschar *queue_domains          = NULL;
1249 int     queue_interval         = -1;
1250 uschar *queue_name             = US"";
1251 uschar *queue_name_dest        = NULL;
1252 uschar *queue_only_file        = NULL;
1253 int     queue_only_load        = -1;
1254 uschar *queue_run_max          = US"5";
1255 pid_t   queue_run_pid          = (pid_t)0;
1256 int     queue_run_pipe         = -1;
1257 unsigned queue_size            = 0;
1258 time_t  queue_size_next        = 0;
1259 uschar *queue_smtp_domains     = NULL;
1260 
1261 uint32_t random_seed	       = 0;
1262 tree_node *ratelimiters_cmd    = NULL;
1263 tree_node *ratelimiters_conn   = NULL;
1264 tree_node *ratelimiters_mail   = NULL;
1265 uschar *raw_active_hostname    = NULL;
1266 uschar *raw_sender             = NULL;
1267 uschar **raw_recipients        = NULL;
1268 int     raw_recipients_count   = 0;
1269 
1270 int     rcpt_count             = 0;
1271 int     rcpt_fail_count        = 0;
1272 int     rcpt_defer_count       = 0;
1273 gid_t   real_gid;
1274 uid_t   real_uid;
1275 int     receive_linecount      = 0;
1276 int     receive_messagecount   = 0;
1277 int     receive_timeout        = 0;
1278 int     received_count         = 0;
1279 uschar *received_for           = NULL;
1280 
1281 /*  This is the default text for Received headers generated by Exim. The
1282 date  will be automatically added on the end. */
1283 
1284 uschar *received_header_text   = US
1285      "Received: "
1286      "${if def:sender_rcvhost {from $sender_rcvhost\n\t}"
1287        "{${if def:sender_ident {from ${quote_local_part:$sender_ident} }}"
1288          "${if def:sender_helo_name {(helo=$sender_helo_name)\n\t}}}}"
1289      "by $primary_hostname "
1290      "${if def:received_protocol {with $received_protocol }}"
1291 #ifndef DISABLE_TLS
1292      "${if def:tls_in_ver        { ($tls_in_ver)}}"
1293      "${if def:tls_in_cipher_std { tls $tls_in_cipher_std\n\t}}"
1294 #endif
1295      "(Exim $version_number)\n\t"
1296      "${if def:sender_address {(envelope-from <$sender_address>)\n\t}}"
1297      "id $message_exim_id"
1298      "${if def:received_for {\n\tfor $received_for}}"
1299      "\0<---------------Space to patch received_header_text->";
1300 
1301 int     received_headers_max   = 30;
1302 uschar *received_protocol      = NULL;
1303 struct timeval received_time   = { 0, 0 };
1304 struct timeval received_time_complete = { 0, 0 };
1305 uschar *recipient_data         = NULL;
1306 uschar *recipient_unqualified_hosts = NULL;
1307 uschar *recipient_verify_failure = NULL;
1308 int     recipients_count       = 0;
1309 recipient_item  *recipients_list = NULL;
1310 int     recipients_list_max    = 0;
1311 int     recipients_max         = 50000;
1312 const pcre *regex_AUTH         = NULL;
1313 const pcre *regex_check_dns_names = NULL;
1314 const pcre *regex_From         = NULL;
1315 const pcre *regex_IGNOREQUOTA  = NULL;
1316 const pcre *regex_PIPELINING   = NULL;
1317 const pcre *regex_SIZE         = NULL;
1318 #ifndef DISABLE_PIPE_CONNECT
1319 const pcre *regex_EARLY_PIPE   = NULL;
1320 #endif
1321 const pcre *regex_ismsgid      = NULL;
1322 const pcre *regex_smtp_code    = NULL;
1323 uschar *regex_vars[REGEX_VARS];
1324 #ifdef WHITELIST_D_MACROS
1325 const pcre *regex_whitelisted_macro = NULL;
1326 #endif
1327 #ifdef WITH_CONTENT_SCAN
1328 uschar *regex_match_string     = NULL;
1329 #endif
1330 int     remote_delivery_count  = 0;
1331 int     remote_max_parallel    = 2;
1332 uschar *remote_sort_domains    = NULL;
1333 int     retry_data_expire      = 7*24*60*60;
1334 int     retry_interval_max     = 24*60*60;
1335 int     retry_maximum_timeout  = 0;        /* set from retry config */
1336 retry_config  *retries         = NULL;
1337 uschar *return_path            = NULL;
1338 int     rewrite_existflags     = 0;
1339 uschar *rfc1413_hosts          = US"@[]";
1340 int     rfc1413_query_timeout  = 0;
1341 uid_t   root_gid               = ROOT_GID;
1342 uid_t   root_uid               = ROOT_UID;
1343 
1344 router_instance  *routers  = NULL;
1345 router_instance  router_defaults = {
1346     .next =			NULL,
1347     .name =			NULL,
1348     .info =			NULL,
1349     .options_block =		NULL,
1350     .driver_name =		NULL,
1351 
1352     .address_data =		NULL,
1353 #ifdef EXPERIMENTAL_BRIGHTMAIL
1354     .bmi_rule =			NULL,
1355 #endif
1356     .cannot_route_message =	NULL,
1357     .condition =		NULL,
1358     .current_directory =	NULL,
1359     .debug_string =		NULL,
1360     .domains =			NULL,
1361     .errors_to =		NULL,
1362     .expand_gid =		NULL,
1363     .expand_uid =		NULL,
1364     .expand_more =		NULL,
1365     .expand_unseen =		NULL,
1366     .extra_headers =		NULL,
1367     .fallback_hosts =		NULL,
1368     .home_directory =		NULL,
1369     .ignore_target_hosts =	NULL,
1370     .local_parts =		NULL,
1371     .pass_router_name =		NULL,
1372     .prefix =			NULL,
1373     .redirect_router_name =	NULL,
1374     .remove_headers =		NULL,
1375     .require_files =		NULL,
1376     .router_home_directory =	NULL,
1377     .self =			US"freeze",
1378     .senders =			NULL,
1379     .suffix =			NULL,
1380     .translate_ip_address =	NULL,
1381     .transport_name =		NULL,
1382 
1383     .address_test =		TRUE,
1384 #ifdef EXPERIMENTAL_BRIGHTMAIL
1385     .bmi_deliver_alternate =	FALSE,
1386     .bmi_deliver_default =	FALSE,
1387     .bmi_dont_deliver =		FALSE,
1388 #endif
1389     .expn =			TRUE,
1390     .caseful_local_part =	FALSE,
1391     .check_local_user =		FALSE,
1392     .disable_logging =		FALSE,
1393     .fail_verify_recipient =	FALSE,
1394     .fail_verify_sender =	FALSE,
1395     .gid_set =			FALSE,
1396     .initgroups =		FALSE,
1397     .log_as_local =		TRUE_UNSET,
1398     .more =			TRUE,
1399     .pass_on_timeout =		FALSE,
1400     .prefix_optional =		FALSE,
1401     .repeat_use =		TRUE,
1402     .retry_use_local_part =	TRUE_UNSET,
1403     .same_domain_copy_routing =	FALSE,
1404     .self_rewrite =		FALSE,
1405     .set =			NULL,
1406     .suffix_optional =		FALSE,
1407     .verify_only =		FALSE,
1408     .verify_recipient =		TRUE,
1409     .verify_sender =		TRUE,
1410     .uid_set =			FALSE,
1411     .unseen =			FALSE,
1412     .dsn_lasthop =		FALSE,
1413 
1414     .self_code =		self_freeze,
1415     .uid =			(uid_t)(-1),
1416     .gid =			(gid_t)(-1),
1417 
1418     .fallback_hostlist =	NULL,
1419     .transport =		NULL,
1420     .pass_router =		NULL,
1421     .redirect_router =		NULL,
1422 
1423     .dnssec =                   { .request= US"*", .require=NULL },
1424 };
1425 
1426 uschar *router_name            = NULL;
1427 tree_node *router_var	       = NULL;
1428 
1429 ip_address_item *running_interfaces = NULL;
1430 
1431 /* This is a weird one. The following string gets patched in the binary by the
1432 script that sets up a copy of Exim for running in the test harness. It seems
1433 that compilers are now clever, and share constant strings if they can.
1434 Elsewhere in Exim the string "<" is used. The compiler optimization seems to
1435 make use of the end of this string in order to save space. So the patching then
1436 wrecks this. We defeat this optimization by adding some additional characters
1437 onto the end of the string. */
1438 
1439 uschar *running_status         = US">>>running<<<" "\0EXTRA";
1440 
1441 int     runrc                  = 0;
1442 
1443 uschar *search_error_message   = NULL;
1444 uschar *self_hostname          = NULL;
1445 uschar *sender_address         = NULL;
1446 unsigned int sender_address_cache[(MAX_NAMED_LIST * 2)/32];
1447 uschar *sender_address_data    = NULL;
1448 uschar *sender_address_unrewritten = NULL;
1449 uschar *sender_data            = NULL;
1450 unsigned int sender_domain_cache[(MAX_NAMED_LIST * 2)/32];
1451 uschar *sender_fullhost        = NULL;
1452 uschar *sender_helo_name       = NULL;
1453 uschar **sender_host_aliases   = &no_aliases;
1454 uschar *sender_host_address    = NULL;
1455 uschar *sender_host_authenticated = NULL;
1456 uschar *sender_host_auth_pubname  = NULL;
1457 unsigned int sender_host_cache[(MAX_NAMED_LIST * 2)/32];
1458 uschar *sender_host_name       = NULL;
1459 int     sender_host_port       = 0;
1460 uschar *sender_ident           = NULL;
1461 uschar *sender_rate            = NULL;
1462 uschar *sender_rate_limit      = NULL;
1463 uschar *sender_rate_period     = NULL;
1464 uschar *sender_rcvhost         = NULL;
1465 uschar *sender_unqualified_hosts = NULL;
1466 uschar *sender_verify_failure = NULL;
1467 address_item *sender_verified_list  = NULL;
1468 address_item *sender_verified_failed = NULL;
1469 int     sender_verified_rc     = -1;
1470 uschar *sending_ip_address     = NULL;
1471 int     sending_port           = -1;
1472 SIGNAL_BOOL sigalrm_seen       = FALSE;
1473 const uschar *sigalarm_setter  = NULL;
1474 uschar **sighup_argv           = NULL;
1475 int     slow_lookup_log        = 0;	/* millisecs, zero disables */
1476 int     smtp_accept_count      = 0;
1477 int     smtp_accept_max        = 20;
1478 int     smtp_accept_max_nonmail= 10;
1479 uschar *smtp_accept_max_nonmail_hosts = US"*";
1480 uschar *smtp_accept_max_per_connection = US"1000";
1481 uschar *smtp_accept_max_per_host = NULL;
1482 int     smtp_accept_queue      = 0;
1483 int     smtp_accept_queue_per_connection = 10;
1484 int     smtp_accept_reserve    = 0;
1485 uschar *smtp_active_hostname   = NULL;
1486 int	smtp_backlog_monitor   = 0;
1487 uschar *smtp_banner            = US"$smtp_active_hostname ESMTP "
1488                              "Exim $version_number $tod_full"
1489                              "\0<---------------Space to patch smtp_banner->";
1490 int     smtp_ch_index          = 0;
1491 uschar *smtp_cmd_argument      = NULL;
1492 uschar *smtp_cmd_buffer        = NULL;
1493 struct timeval smtp_connection_start  = {0,0};
1494 uschar  smtp_connection_had[SMTP_HBUFF_SIZE];
1495 int     smtp_connect_backlog   = 20;
1496 double  smtp_delay_mail        = 0.0;
1497 double  smtp_delay_rcpt        = 0.0;
1498 FILE   *smtp_in                = NULL;
1499 int     smtp_listen_backlog    = 0;
1500 int     smtp_load_reserve      = -1;
1501 int     smtp_mailcmd_count     = 0;
1502 int     smtp_mailcmd_max       = -1;
1503 FILE   *smtp_out               = NULL;
1504 uschar *smtp_etrn_command      = NULL;
1505 int     smtp_max_synprot_errors= 3;
1506 int     smtp_max_unknown_commands = 3;
1507 uschar *smtp_notquit_reason    = NULL;
1508 unsigned smtp_peer_options     = 0;
1509 unsigned smtp_peer_options_wrap= 0;
1510 uschar *smtp_ratelimit_hosts   = NULL;
1511 uschar *smtp_ratelimit_mail    = NULL;
1512 uschar *smtp_ratelimit_rcpt    = NULL;
1513 uschar *smtp_read_error        = US"";
1514 int     smtp_receive_timeout   = 5*60;
1515 uschar *smtp_receive_timeout_s = NULL;
1516 uschar *smtp_reserve_hosts     = NULL;
1517 int     smtp_rlm_base          = 0;
1518 double  smtp_rlm_factor        = 0.0;
1519 int     smtp_rlm_limit         = 0;
1520 int     smtp_rlm_threshold     = INT_MAX;
1521 int     smtp_rlr_base          = 0;
1522 double  smtp_rlr_factor        = 0.0;
1523 int     smtp_rlr_limit         = 0;
1524 int     smtp_rlr_threshold     = INT_MAX;
1525 #ifdef SUPPORT_I18N
1526 uschar *smtputf8_advertise_hosts = US"*";	/* overridden under test-harness */
1527 #endif
1528 
1529 #ifdef WITH_CONTENT_SCAN
1530 uschar *spamd_address          = US"127.0.0.1 783";
1531 uschar *spam_bar               = NULL;
1532 uschar *spam_report            = NULL;
1533 uschar *spam_action            = NULL;
1534 uschar *spam_score             = NULL;
1535 uschar *spam_score_int         = NULL;
1536 #endif
1537 #ifdef SUPPORT_SPF
1538 uschar *spf_guess              = US"v=spf1 a/24 mx/24 ptr ?all";
1539 uschar *spf_header_comment     = NULL;
1540 uschar *spf_received           = NULL;
1541 uschar *spf_result             = NULL;
1542 uschar *spf_smtp_comment       = NULL;
1543 uschar *spf_smtp_comment_template
1544                     /* Used to be: "Please%_see%_http://www.open-spf.org/Why?id=%{S}&ip=%{C}&receiver=%{R}" */
1545                                = US"Please%_see%_http://www.open-spf.org/Why";
1546 
1547 #endif
1548 
1549 FILE   *spool_data_file	       = NULL;
1550 uschar *spool_directory        = US SPOOL_DIRECTORY
1551                            "\0<--------------Space to patch spool_directory->";
1552 #ifdef EXPERIMENTAL_SRS_ALT
1553 uschar *srs_config             = NULL;
1554 uschar *srs_db_address         = NULL;
1555 uschar *srs_db_key             = NULL;
1556 int     srs_hashlength         = 6;
1557 int     srs_hashmin            = -1;
1558 int     srs_maxage             = 31;
1559 uschar *srs_orig_recipient     = NULL;
1560 uschar *srs_orig_sender        = NULL;
1561 uschar *srs_recipient          = NULL;
1562 uschar *srs_secrets            = NULL;
1563 uschar *srs_status             = NULL;
1564 #endif
1565 #ifdef SUPPORT_SRS
1566 uschar *srs_recipient          = NULL;
1567 #endif
1568 int     string_datestamp_offset= -1;
1569 int     string_datestamp_length= 0;
1570 int     string_datestamp_type  = -1;
1571 const uschar *submission_domain = NULL;
1572 const uschar *submission_name  = NULL;
1573 int     syslog_facility        = LOG_MAIL;
1574 uschar *syslog_processname     = US"exim";
1575 uschar *system_filter          = NULL;
1576 
1577 uschar *system_filter_directory_transport = NULL;
1578 uschar *system_filter_file_transport = NULL;
1579 uschar *system_filter_pipe_transport = NULL;
1580 uschar *system_filter_reply_transport = NULL;
1581 
1582 gid_t   system_filter_gid      = 0;
1583 uid_t   system_filter_uid      = (uid_t)-1;
1584 
1585 blob	tcp_fastopen_nodata    = { .data = NULL, .len = 0 };
1586 tfo_state_t tcp_out_fastopen   = TFO_NOT_USED;
1587 #ifdef USE_TCP_WRAPPERS
1588 uschar *tcp_wrappers_daemon_name = US TCP_WRAPPERS_DAEMON_NAME;
1589 #endif
1590 int     test_harness_load_avg  = 0;
1591 int     thismessage_size_limit = 0;
1592 int     timeout_frozen_after   = 0;
1593 #ifdef MEASURE_TIMING
1594 struct timeval timestamp_startup;
1595 #endif
1596 
1597 transport_instance  *transports = NULL;
1598 
1599 transport_instance  transport_defaults = {
1600     /* All non-mentioned elements zero/NULL/FALSE */
1601     .batch_max =		1,
1602     .multi_domain =		TRUE,
1603     .max_addresses =		100,
1604     .connection_max_messages =	500,
1605     .uid =			(uid_t)(-1),
1606     .gid =			(gid_t)(-1),
1607     .filter_timeout =		300,
1608     .retry_use_local_part =	TRUE_UNSET,	/* retry_use_local_part: BOOL, but set neither
1609 						 1 nor 0 so can detect unset */
1610 };
1611 
1612 int     transport_count;
1613 uschar *transport_name          = NULL;
1614 int     transport_newlines;
1615 const uschar **transport_filter_argv  = NULL;
1616 int     transport_filter_timeout;
1617 int     transport_write_timeout= 0;
1618 
1619 tree_node  *tree_dns_fails     = NULL;
1620 tree_node  *tree_duplicates    = NULL;
1621 tree_node  *tree_nonrecipients = NULL;
1622 tree_node  *tree_unusable      = NULL;
1623 
1624 gid_t  *trusted_groups         = NULL;
1625 uid_t  *trusted_users          = NULL;
1626 uschar *timezone_string        = US TIMEZONE_DEFAULT;
1627 
1628 uschar *unknown_login          = NULL;
1629 uschar *unknown_username       = NULL;
1630 uschar *untrusted_set_sender   = NULL;
1631 
1632 /*  A regex for matching a "From_" line in an incoming message, in the form
1633 
1634     From ph10 Fri Jan  5 12:35 GMT 1996
1635 
1636 which  the "mail" commands send to the MTA (undocumented, of course), or in
1637 the  form
1638 
1639     From ph10 Fri, 7 Jan 97 14:00:00 GMT
1640 
1641 which  is apparently used by some UUCPs, despite it not being in RFC 976.
1642 Because  of variations in time formats, just match up to the minutes. That
1643 should  be sufficient. Examples have been seen of time fields like 12:1:03,
1644 so  just require one digit for hours and minutes. The weekday is also absent
1645 in  some forms. */
1646 
1647 uschar *uucp_from_pattern      = US
1648    "^From\\s+(\\S+)\\s+(?:[a-zA-Z]{3},?\\s+)?"    /* Common start */
1649    "(?:"                                          /* Non-extracting bracket */
1650    "[a-zA-Z]{3}\\s+\\d?\\d|"                      /* First form */
1651    "\\d?\\d\\s+[a-zA-Z]{3}\\s+\\d\\d(?:\\d\\d)?"  /* Second form */
1652    ")"                                            /* End alternation */
1653    "\\s+\\d\\d?:\\d\\d?";                         /* Start of time */
1654 
1655 uschar *uucp_from_sender       = US"$1";
1656 
1657 uschar *verify_mode	       = NULL;
1658 uschar *version_copyright      =
1659  US"Copyright (c) University of Cambridge, 1995 - 2018\n"
1660    "(c) The Exim Maintainers and contributors in ACKNOWLEDGMENTS file, 2007 - 2020";
1661 uschar *version_date           = US"?";
1662 uschar *version_cnumber        = US"????";
1663 uschar *version_string         = US"?";
1664 
1665 uschar *warn_message_file      = NULL;
1666 int     warning_count          = 0;
1667 uschar *warnmsg_delay          = NULL;
1668 uschar *warnmsg_recipients     = NULL;
1669 
1670 
1671 /*  End of globals.c */
1672