xref: /freebsd/contrib/sendmail/src/readcf.c (revision 7bd6fde3)
1 /*
2  * Copyright (c) 1998-2006 Sendmail, Inc. and its suppliers.
3  *	All rights reserved.
4  * Copyright (c) 1983, 1995-1997 Eric P. Allman.  All rights reserved.
5  * Copyright (c) 1988, 1993
6  *	The Regents of the University of California.  All rights reserved.
7  *
8  * By using this file, you agree to the terms and conditions set
9  * forth in the LICENSE file which can be found at the top level of
10  * the sendmail distribution.
11  *
12  */
13 
14 #include <sendmail.h>
15 
16 SM_RCSID("@(#)$Id: readcf.c,v 8.651 2006/03/02 19:17:09 ca Exp $")
17 
18 #if NETINET || NETINET6
19 # include <arpa/inet.h>
20 #endif /* NETINET || NETINET6 */
21 
22 #define SECONDS
23 #define MINUTES	* 60
24 #define HOUR	* 3600
25 #define HOURS	HOUR
26 
27 static void	fileclass __P((int, char *, char *, bool, bool, bool));
28 static char	**makeargv __P((char *));
29 static void	settimeout __P((char *, char *, bool));
30 static void	toomany __P((int, int));
31 static char	*extrquotstr __P((char *, char **, char *, bool *));
32 static void	parse_class_words __P((int, char *));
33 
34 /*
35 **  READCF -- read configuration file.
36 **
37 **	This routine reads the configuration file and builds the internal
38 **	form.
39 **
40 **	The file is formatted as a sequence of lines, each taken
41 **	atomically.  The first character of each line describes how
42 **	the line is to be interpreted.  The lines are:
43 **		Dxval		Define macro x to have value val.
44 **		Cxword		Put word into class x.
45 **		Fxfile [fmt]	Read file for lines to put into
46 **				class x.  Use scanf string 'fmt'
47 **				or "%s" if not present.  Fmt should
48 **				only produce one string-valued result.
49 **		Hname: value	Define header with field-name 'name'
50 **				and value as specified; this will be
51 **				macro expanded immediately before
52 **				use.
53 **		Sn		Use rewriting set n.
54 **		Rlhs rhs	Rewrite addresses that match lhs to
55 **				be rhs.
56 **		Mn arg=val...	Define mailer.  n is the internal name.
57 **				Args specify mailer parameters.
58 **		Oxvalue		Set option x to value.
59 **		O option value	Set option (long name) to value.
60 **		Pname=value	Set precedence name to value.
61 **		Qn arg=val...	Define queue groups.  n is the internal name.
62 **				Args specify queue parameters.
63 **		Vversioncode[/vendorcode]
64 **				Version level/vendor name of
65 **				configuration syntax.
66 **		Kmapname mapclass arguments....
67 **				Define keyed lookup of a given class.
68 **				Arguments are class dependent.
69 **		Eenvar=value	Set the environment value to the given value.
70 **
71 **	Parameters:
72 **		cfname -- configuration file name.
73 **		safe -- true if this is the system config file;
74 **			false otherwise.
75 **		e -- the main envelope.
76 **
77 **	Returns:
78 **		none.
79 **
80 **	Side Effects:
81 **		Builds several internal tables.
82 */
83 
84 void
85 readcf(cfname, safe, e)
86 	char *cfname;
87 	bool safe;
88 	register ENVELOPE *e;
89 {
90 	SM_FILE_T *cf;
91 	int ruleset = -1;
92 	char *q;
93 	struct rewrite *rwp = NULL;
94 	char *bp;
95 	auto char *ep;
96 	int nfuzzy;
97 	char *file;
98 	bool optional;
99 	bool ok;
100 	bool ismap;
101 	int mid;
102 	register char *p;
103 	long sff = SFF_OPENASROOT;
104 	struct stat statb;
105 	char buf[MAXLINE];
106 	char exbuf[MAXLINE];
107 	char pvpbuf[MAXLINE + MAXATOM];
108 	static char *null_list[1] = { NULL };
109 	extern unsigned char TokTypeNoC[];
110 
111 	FileName = cfname;
112 	LineNumber = 0;
113 
114 	if (DontLockReadFiles)
115 		sff |= SFF_NOLOCK;
116 	cf = safefopen(cfname, O_RDONLY, 0444, sff);
117 	if (cf == NULL)
118 	{
119 		syserr("cannot open");
120 		finis(false, true, EX_OSFILE);
121 	}
122 
123 	if (fstat(sm_io_getinfo(cf, SM_IO_WHAT_FD, NULL), &statb) < 0)
124 	{
125 		syserr("cannot fstat");
126 		finis(false, true, EX_OSFILE);
127 	}
128 
129 	if (!S_ISREG(statb.st_mode))
130 	{
131 		syserr("not a plain file");
132 		finis(false, true, EX_OSFILE);
133 	}
134 
135 	if (OpMode != MD_TEST && bitset(S_IWGRP|S_IWOTH, statb.st_mode))
136 	{
137 		if (OpMode == MD_DAEMON || OpMode == MD_INITALIAS)
138 			(void) sm_io_fprintf(smioerr, SM_TIME_DEFAULT,
139 					     "%s: WARNING: dangerous write permissions\n",
140 					     FileName);
141 		if (LogLevel > 0)
142 			sm_syslog(LOG_CRIT, NOQID,
143 				  "%s: WARNING: dangerous write permissions",
144 				  FileName);
145 	}
146 
147 #if XLA
148 	xla_zero();
149 #endif /* XLA */
150 
151 	while ((bp = fgetfolded(buf, sizeof buf, cf)) != NULL)
152 	{
153 		if (bp[0] == '#')
154 		{
155 			if (bp != buf)
156 				sm_free(bp); /* XXX */
157 			continue;
158 		}
159 
160 		/* do macro expansion mappings */
161 		translate_dollars(bp);
162 
163 		/* interpret this line */
164 		errno = 0;
165 		switch (bp[0])
166 		{
167 		  case '\0':
168 		  case '#':		/* comment */
169 			break;
170 
171 		  case 'R':		/* rewriting rule */
172 			if (ruleset < 0)
173 			{
174 				syserr("missing valid ruleset for \"%s\"", bp);
175 				break;
176 			}
177 			for (p = &bp[1]; *p != '\0' && *p != '\t'; p++)
178 				continue;
179 
180 			if (*p == '\0')
181 			{
182 				syserr("invalid rewrite line \"%s\" (tab expected)", bp);
183 				break;
184 			}
185 
186 			/* allocate space for the rule header */
187 			if (rwp == NULL)
188 			{
189 				RewriteRules[ruleset] = rwp =
190 					(struct rewrite *) xalloc(sizeof *rwp);
191 			}
192 			else
193 			{
194 				rwp->r_next = (struct rewrite *) xalloc(sizeof *rwp);
195 				rwp = rwp->r_next;
196 			}
197 			rwp->r_next = NULL;
198 
199 			/* expand and save the LHS */
200 			*p = '\0';
201 			expand(&bp[1], exbuf, sizeof exbuf, e);
202 			rwp->r_lhs = prescan(exbuf, '\t', pvpbuf,
203 					     sizeof pvpbuf, NULL,
204 					     ConfigLevel >= 9 ? TokTypeNoC : NULL,
205 					     true);
206 			nfuzzy = 0;
207 			if (rwp->r_lhs != NULL)
208 			{
209 				register char **ap;
210 
211 				rwp->r_lhs = copyplist(rwp->r_lhs, true, NULL);
212 
213 				/* count the number of fuzzy matches in LHS */
214 				for (ap = rwp->r_lhs; *ap != NULL; ap++)
215 				{
216 					char *botch;
217 
218 					botch = NULL;
219 					switch (**ap & 0377)
220 					{
221 					  case MATCHZANY:
222 					  case MATCHANY:
223 					  case MATCHONE:
224 					  case MATCHCLASS:
225 					  case MATCHNCLASS:
226 						nfuzzy++;
227 						break;
228 
229 					  case MATCHREPL:
230 						botch = "$0-$9";
231 						break;
232 
233 					  case CANONUSER:
234 						botch = "$:";
235 						break;
236 
237 					  case CALLSUBR:
238 						botch = "$>";
239 						break;
240 
241 					  case CONDIF:
242 						botch = "$?";
243 						break;
244 
245 					  case CONDFI:
246 						botch = "$.";
247 						break;
248 
249 					  case HOSTBEGIN:
250 						botch = "$[";
251 						break;
252 
253 					  case HOSTEND:
254 						botch = "$]";
255 						break;
256 
257 					  case LOOKUPBEGIN:
258 						botch = "$(";
259 						break;
260 
261 					  case LOOKUPEND:
262 						botch = "$)";
263 						break;
264 					}
265 					if (botch != NULL)
266 						syserr("Inappropriate use of %s on LHS",
267 							botch);
268 				}
269 				rwp->r_line = LineNumber;
270 			}
271 			else
272 			{
273 				syserr("R line: null LHS");
274 				rwp->r_lhs = null_list;
275 			}
276 			if (nfuzzy > MAXMATCH)
277 			{
278 				syserr("R line: too many wildcards");
279 				rwp->r_lhs = null_list;
280 			}
281 
282 			/* expand and save the RHS */
283 			while (*++p == '\t')
284 				continue;
285 			q = p;
286 			while (*p != '\0' && *p != '\t')
287 				p++;
288 			*p = '\0';
289 			expand(q, exbuf, sizeof exbuf, e);
290 			rwp->r_rhs = prescan(exbuf, '\t', pvpbuf,
291 					     sizeof pvpbuf, NULL,
292 					     ConfigLevel >= 9 ? TokTypeNoC : NULL,
293 					     true);
294 			if (rwp->r_rhs != NULL)
295 			{
296 				register char **ap;
297 				int args, endtoken;
298 #if _FFR_EXTRA_MAP_CHECK
299 				int nexttoken;
300 #endif /* _FFR_EXTRA_MAP_CHECK */
301 				bool inmap;
302 
303 				rwp->r_rhs = copyplist(rwp->r_rhs, true, NULL);
304 
305 				/* check no out-of-bounds replacements */
306 				nfuzzy += '0';
307 				inmap = false;
308 				args = 0;
309 				endtoken = 0;
310 				for (ap = rwp->r_rhs; *ap != NULL; ap++)
311 				{
312 					char *botch;
313 
314 					botch = NULL;
315 					switch (**ap & 0377)
316 					{
317 					  case MATCHREPL:
318 						if ((*ap)[1] <= '0' || (*ap)[1] > nfuzzy)
319 						{
320 							syserr("replacement $%c out of bounds",
321 								(*ap)[1]);
322 						}
323 						break;
324 
325 					  case MATCHZANY:
326 						botch = "$*";
327 						break;
328 
329 					  case MATCHANY:
330 						botch = "$+";
331 						break;
332 
333 					  case MATCHONE:
334 						botch = "$-";
335 						break;
336 
337 					  case MATCHCLASS:
338 						botch = "$=";
339 						break;
340 
341 					  case MATCHNCLASS:
342 						botch = "$~";
343 						break;
344 
345 					  case CANONHOST:
346 						if (!inmap)
347 							break;
348 						if (++args >= MAX_MAP_ARGS)
349 							syserr("too many arguments for map lookup");
350 						break;
351 
352 					  case HOSTBEGIN:
353 						endtoken = HOSTEND;
354 						/* FALLTHROUGH */
355 					  case LOOKUPBEGIN:
356 						/* see above... */
357 						if ((**ap & 0377) == LOOKUPBEGIN)
358 							endtoken = LOOKUPEND;
359 						if (inmap)
360 							syserr("cannot nest map lookups");
361 						inmap = true;
362 						args = 0;
363 #if _FFR_EXTRA_MAP_CHECK
364 						if (*(ap + 1) == NULL)
365 						{
366 							syserr("syntax error in map lookup");
367 							break;
368 						}
369 						nexttoken = **(ap + 1) & 0377;
370 						if (nexttoken == CANONHOST ||
371 						    nexttoken == CANONUSER ||
372 						    nexttoken == endtoken)
373 						{
374 							syserr("missing map name for lookup");
375 							break;
376 						}
377 						if (*(ap + 2) == NULL)
378 						{
379 							syserr("syntax error in map lookup");
380 							break;
381 						}
382 						if ((**ap & 0377) == HOSTBEGIN)
383 							break;
384 						nexttoken = **(ap + 2) & 0377;
385 						if (nexttoken == CANONHOST ||
386 						    nexttoken == CANONUSER ||
387 						    nexttoken == endtoken)
388 						{
389 							syserr("missing key name for lookup");
390 							break;
391 						}
392 #endif /* _FFR_EXTRA_MAP_CHECK */
393 						break;
394 
395 					  case HOSTEND:
396 					  case LOOKUPEND:
397 						if ((**ap & 0377) != endtoken)
398 							break;
399 						inmap = false;
400 						endtoken = 0;
401 						break;
402 
403 
404 #if 0
405 /*
406 **  This doesn't work yet as there are maps defined *after* the cf
407 **  is read such as host, user, and alias.  So for now, it's removed.
408 **  When it comes back, the RELEASE_NOTES entry will be:
409 **	Emit warnings for unknown maps when reading the .cf file.  Based on
410 **		patch from Robert Harker of Harker Systems.
411 */
412 
413 					  case LOOKUPBEGIN:
414 						/*
415 						**  Got a database lookup,
416 						**  check if map is defined.
417 						*/
418 
419 						ep = *(ap + 1);
420 						if ((*ep & 0377) != MACRODEXPAND &&
421 						    stab(ep, ST_MAP,
422 							 ST_FIND) == NULL)
423 						{
424 							(void) sm_io_fprintf(smioout,
425 									     SM_TIME_DEFAULT,
426 									     "Warning: %s: line %d: map %s not found\n",
427 									     FileName,
428 									     LineNumber,
429 									     ep);
430 						}
431 						break;
432 #endif /* 0 */
433 					}
434 					if (botch != NULL)
435 						syserr("Inappropriate use of %s on RHS",
436 							botch);
437 				}
438 				if (inmap)
439 					syserr("missing map closing token");
440 			}
441 			else
442 			{
443 				syserr("R line: null RHS");
444 				rwp->r_rhs = null_list;
445 			}
446 			break;
447 
448 		  case 'S':		/* select rewriting set */
449 			expand(&bp[1], exbuf, sizeof exbuf, e);
450 			ruleset = strtorwset(exbuf, NULL, ST_ENTER);
451 			if (ruleset < 0)
452 				break;
453 
454 			rwp = RewriteRules[ruleset];
455 			if (rwp != NULL)
456 			{
457 				if (OpMode == MD_TEST)
458 					(void) sm_io_fprintf(smioout,
459 							     SM_TIME_DEFAULT,
460 							     "WARNING: Ruleset %s has multiple definitions\n",
461 							    &bp[1]);
462 				if (tTd(37, 1))
463 					sm_dprintf("WARNING: Ruleset %s has multiple definitions\n",
464 						   &bp[1]);
465 				while (rwp->r_next != NULL)
466 					rwp = rwp->r_next;
467 			}
468 			break;
469 
470 		  case 'D':		/* macro definition */
471 			mid = macid_parse(&bp[1], &ep);
472 			if (mid == 0)
473 				break;
474 			p = munchstring(ep, NULL, '\0');
475 			macdefine(&e->e_macro, A_TEMP, mid, p);
476 			break;
477 
478 		  case 'H':		/* required header line */
479 			(void) chompheader(&bp[1], CHHDR_DEF, NULL, e);
480 			break;
481 
482 		  case 'C':		/* word class */
483 		  case 'T':		/* trusted user (set class `t') */
484 			if (bp[0] == 'C')
485 			{
486 				mid = macid_parse(&bp[1], &ep);
487 				if (mid == 0)
488 					break;
489 				expand(ep, exbuf, sizeof exbuf, e);
490 				p = exbuf;
491 			}
492 			else
493 			{
494 				mid = 't';
495 				p = &bp[1];
496 			}
497 			while (*p != '\0')
498 			{
499 				register char *wd;
500 				char delim;
501 
502 				while (*p != '\0' && isascii(*p) && isspace(*p))
503 					p++;
504 				wd = p;
505 				while (*p != '\0' && !(isascii(*p) && isspace(*p)))
506 					p++;
507 				delim = *p;
508 				*p = '\0';
509 				if (wd[0] != '\0')
510 					setclass(mid, wd);
511 				*p = delim;
512 			}
513 			break;
514 
515 		  case 'F':		/* word class from file */
516 			mid = macid_parse(&bp[1], &ep);
517 			if (mid == 0)
518 				break;
519 			for (p = ep; isascii(*p) && isspace(*p); )
520 				p++;
521 			if (p[0] == '-' && p[1] == 'o')
522 			{
523 				optional = true;
524 				while (*p != '\0' &&
525 				       !(isascii(*p) && isspace(*p)))
526 					p++;
527 				while (isascii(*p) && isspace(*p))
528 					p++;
529 				file = p;
530 			}
531 			else
532 				optional = false;
533 
534 			/* check if [key]@map:spec */
535 			ismap = false;
536 			if (!SM_IS_DIR_DELIM(*p) &&
537 			    *p != '|' &&
538 			    (q = strchr(p, '@')) != NULL)
539 			{
540 				q++;
541 
542 				/* look for @LDAP or @map: in string */
543 				if (strcmp(q, "LDAP") == 0 ||
544 				    (*q != ':' &&
545 				     strchr(q, ':') != NULL))
546 					ismap = true;
547 			}
548 
549 			if (ismap)
550 			{
551 				/* use entire spec */
552 				file = p;
553 			}
554 			else
555 			{
556 				file = extrquotstr(p, &q, " ", &ok);
557 				if (!ok)
558 				{
559 					syserr("illegal filename '%s'", p);
560 					break;
561 				}
562 			}
563 
564 			if (*file == '|' || ismap)
565 				p = "%s";
566 			else
567 			{
568 				p = q;
569 				if (*p == '\0')
570 					p = "%s";
571 				else
572 				{
573 					*p = '\0';
574 					while (isascii(*++p) && isspace(*p))
575 						continue;
576 				}
577 			}
578 			fileclass(mid, file, p, ismap, safe, optional);
579 			break;
580 
581 #if XLA
582 		  case 'L':		/* extended load average description */
583 			xla_init(&bp[1]);
584 			break;
585 #endif /* XLA */
586 
587 #if defined(SUN_EXTENSIONS) && defined(SUN_LOOKUP_MACRO)
588 		  case 'L':		/* lookup macro */
589 		  case 'G':		/* lookup class */
590 			/* reserved for Sun -- NIS+ database lookup */
591 			if (VendorCode != VENDOR_SUN)
592 				goto badline;
593 			sun_lg_config_line(bp, e);
594 			break;
595 #endif /* defined(SUN_EXTENSIONS) && defined(SUN_LOOKUP_MACRO) */
596 
597 		  case 'M':		/* define mailer */
598 			makemailer(&bp[1]);
599 			break;
600 
601 		  case 'O':		/* set option */
602 			setoption(bp[1], &bp[2], safe, false, e);
603 			break;
604 
605 		  case 'P':		/* set precedence */
606 			if (NumPriorities >= MAXPRIORITIES)
607 			{
608 				toomany('P', MAXPRIORITIES);
609 				break;
610 			}
611 			for (p = &bp[1]; *p != '\0' && *p != '='; p++)
612 				continue;
613 			if (*p == '\0')
614 				goto badline;
615 			*p = '\0';
616 			Priorities[NumPriorities].pri_name = newstr(&bp[1]);
617 			Priorities[NumPriorities].pri_val = atoi(++p);
618 			NumPriorities++;
619 			break;
620 
621 		  case 'Q':		/* define queue */
622 			makequeue(&bp[1], true);
623 			break;
624 
625 		  case 'V':		/* configuration syntax version */
626 			for (p = &bp[1]; isascii(*p) && isspace(*p); p++)
627 				continue;
628 			if (!isascii(*p) || !isdigit(*p))
629 			{
630 				syserr("invalid argument to V line: \"%.20s\"",
631 					&bp[1]);
632 				break;
633 			}
634 			ConfigLevel = strtol(p, &ep, 10);
635 
636 			/*
637 			**  Do heuristic tweaking for back compatibility.
638 			*/
639 
640 			if (ConfigLevel >= 5)
641 			{
642 				/* level 5 configs have short name in $w */
643 				p = macvalue('w', e);
644 				if (p != NULL && (p = strchr(p, '.')) != NULL)
645 				{
646 					*p = '\0';
647 					macdefine(&e->e_macro, A_TEMP, 'w',
648 						  macvalue('w', e));
649 				}
650 			}
651 			if (ConfigLevel >= 6)
652 			{
653 				ColonOkInAddr = false;
654 			}
655 
656 			/*
657 			**  Look for vendor code.
658 			*/
659 
660 			if (*ep++ == '/')
661 			{
662 				/* extract vendor code */
663 				for (p = ep; isascii(*p) && isalpha(*p); )
664 					p++;
665 				*p = '\0';
666 
667 				if (!setvendor(ep))
668 					syserr("invalid V line vendor code: \"%s\"",
669 						ep);
670 			}
671 			break;
672 
673 		  case 'K':
674 			expand(&bp[1], exbuf, sizeof exbuf, e);
675 			(void) makemapentry(exbuf);
676 			break;
677 
678 		  case 'E':
679 			p = strchr(bp, '=');
680 			if (p != NULL)
681 				*p++ = '\0';
682 			sm_setuserenv(&bp[1], p);
683 			break;
684 
685 		  case 'X':		/* mail filter */
686 #if MILTER
687 			milter_setup(&bp[1]);
688 #else /* MILTER */
689 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
690 					     "Warning: Filter usage ('X') requires Milter support (-DMILTER)\n");
691 #endif /* MILTER */
692 			break;
693 
694 		  default:
695 		  badline:
696 			syserr("unknown configuration line \"%s\"", bp);
697 		}
698 		if (bp != buf)
699 			sm_free(bp); /* XXX */
700 	}
701 	if (sm_io_error(cf))
702 	{
703 		syserr("I/O read error");
704 		finis(false, true, EX_OSFILE);
705 	}
706 	(void) sm_io_close(cf, SM_TIME_DEFAULT);
707 	FileName = NULL;
708 
709 	/* initialize host maps from local service tables */
710 	inithostmaps();
711 
712 	/* initialize daemon (if not defined yet) */
713 	initdaemon();
714 
715 	/* determine if we need to do special name-server frotz */
716 	{
717 		int nmaps;
718 		char *maptype[MAXMAPSTACK];
719 		short mapreturn[MAXMAPACTIONS];
720 
721 		nmaps = switch_map_find("hosts", maptype, mapreturn);
722 		UseNameServer = false;
723 		if (nmaps > 0 && nmaps <= MAXMAPSTACK)
724 		{
725 			register int mapno;
726 
727 			for (mapno = 0; mapno < nmaps && !UseNameServer;
728 			     mapno++)
729 			{
730 				if (strcmp(maptype[mapno], "dns") == 0)
731 					UseNameServer = true;
732 			}
733 		}
734 	}
735 }
736 /*
737 **  TRANSLATE_DOLLARS -- convert $x into internal form
738 **
739 **	Actually does all appropriate pre-processing of a config line
740 **	to turn it into internal form.
741 **
742 **	Parameters:
743 **		bp -- the buffer to translate.
744 **
745 **	Returns:
746 **		None.  The buffer is translated in place.  Since the
747 **		translations always make the buffer shorter, this is
748 **		safe without a size parameter.
749 */
750 
751 void
752 translate_dollars(bp)
753 	char *bp;
754 {
755 	register char *p;
756 	auto char *ep;
757 
758 	for (p = bp; *p != '\0'; p++)
759 	{
760 		if (*p == '#' && p > bp && ConfigLevel >= 3)
761 		{
762 			register char *e;
763 
764 			switch (*--p & 0377)
765 			{
766 			  case MACROEXPAND:
767 				/* it's from $# -- let it go through */
768 				p++;
769 				break;
770 
771 			  case '\\':
772 				/* it's backslash escaped */
773 				(void) sm_strlcpy(p, p + 1, strlen(p));
774 				break;
775 
776 			  default:
777 				/* delete leading white space */
778 				while (isascii(*p) && isspace(*p) &&
779 				       *p != '\n' && p > bp)
780 					p--;
781 				if ((e = strchr(++p, '\n')) != NULL)
782 					(void) sm_strlcpy(p, e, strlen(p));
783 				else
784 					*p-- = '\0';
785 				break;
786 			}
787 			continue;
788 		}
789 
790 		if (*p != '$' || p[1] == '\0')
791 			continue;
792 
793 		if (p[1] == '$')
794 		{
795 			/* actual dollar sign.... */
796 			(void) sm_strlcpy(p, p + 1, strlen(p));
797 			continue;
798 		}
799 
800 		/* convert to macro expansion character */
801 		*p++ = MACROEXPAND;
802 
803 		/* special handling for $=, $~, $&, and $? */
804 		if (*p == '=' || *p == '~' || *p == '&' || *p == '?')
805 			p++;
806 
807 		/* convert macro name to code */
808 		*p = macid_parse(p, &ep);
809 		if (ep != p + 1)
810 			(void) sm_strlcpy(p + 1, ep, strlen(p + 1));
811 	}
812 
813 	/* strip trailing white space from the line */
814 	while (--p > bp && isascii(*p) && isspace(*p))
815 		*p = '\0';
816 }
817 /*
818 **  TOOMANY -- signal too many of some option
819 **
820 **	Parameters:
821 **		id -- the id of the error line
822 **		maxcnt -- the maximum possible values
823 **
824 **	Returns:
825 **		none.
826 **
827 **	Side Effects:
828 **		gives a syserr.
829 */
830 
831 static void
832 toomany(id, maxcnt)
833 	int id;
834 	int maxcnt;
835 {
836 	syserr("too many %c lines, %d max", id, maxcnt);
837 }
838 /*
839 **  FILECLASS -- read members of a class from a file
840 **
841 **	Parameters:
842 **		class -- class to define.
843 **		filename -- name of file to read.
844 **		fmt -- scanf string to use for match.
845 **		ismap -- if set, this is a map lookup.
846 **		safe -- if set, this is a safe read.
847 **		optional -- if set, it is not an error for the file to
848 **			not exist.
849 **
850 **	Returns:
851 **		none
852 **
853 **	Side Effects:
854 **		puts all lines in filename that match a scanf into
855 **			the named class.
856 */
857 
858 /*
859 **  Break up the match into words and add to class.
860 */
861 
862 static void
863 parse_class_words(class, line)
864 	int class;
865 	char *line;
866 {
867 	while (line != NULL && *line != '\0')
868 	{
869 		register char *q;
870 
871 		/* strip leading spaces */
872 		while (isascii(*line) && isspace(*line))
873 			line++;
874 		if (*line == '\0')
875 			break;
876 
877 		/* find the end of the word */
878 		q = line;
879 		while (*line != '\0' && !(isascii(*line) && isspace(*line)))
880 			line++;
881 		if (*line != '\0')
882 			*line++ = '\0';
883 
884 		/* enter the word in the symbol table */
885 		setclass(class, q);
886 	}
887 }
888 
889 static void
890 fileclass(class, filename, fmt, ismap, safe, optional)
891 	int class;
892 	char *filename;
893 	char *fmt;
894 	bool ismap;
895 	bool safe;
896 	bool optional;
897 {
898 	SM_FILE_T *f;
899 	long sff;
900 	pid_t pid;
901 	register char *p;
902 	char buf[MAXLINE];
903 
904 	if (tTd(37, 2))
905 		sm_dprintf("fileclass(%s, fmt=%s)\n", filename, fmt);
906 
907 	if (*filename == '\0')
908 	{
909 		syserr("fileclass: missing file name");
910 		return;
911 	}
912 	else if (ismap)
913 	{
914 		int status = 0;
915 		char *key;
916 		char *mn;
917 		char *cl, *spec;
918 		STAB *mapclass;
919 		MAP map;
920 
921 		mn = newstr(macname(class));
922 
923 		key = filename;
924 
925 		/* skip past key */
926 		if ((p = strchr(filename, '@')) == NULL)
927 		{
928 			/* should not happen */
929 			syserr("fileclass: bogus map specification");
930 			sm_free(mn);
931 			return;
932 		}
933 
934 		/* skip past '@' */
935 		*p++ = '\0';
936 		cl = p;
937 
938 #if LDAPMAP
939 		if (strcmp(cl, "LDAP") == 0)
940 		{
941 			int n;
942 			char *lc;
943 			char jbuf[MAXHOSTNAMELEN];
944 			char lcbuf[MAXLINE];
945 
946 			/* Get $j */
947 			expand("\201j", jbuf, sizeof jbuf, &BlankEnvelope);
948 			if (jbuf[0] == '\0')
949 			{
950 				(void) sm_strlcpy(jbuf, "localhost",
951 						  sizeof jbuf);
952 			}
953 
954 			/* impose the default schema */
955 			lc = macvalue(macid("{sendmailMTACluster}"), CurEnv);
956 			if (lc == NULL)
957 				lc = "";
958 			else
959 			{
960 				expand(lc, lcbuf, sizeof lcbuf, CurEnv);
961 				lc = lcbuf;
962 			}
963 
964 			cl = "ldap";
965 			n = sm_snprintf(buf, sizeof buf,
966 					"-k (&(objectClass=sendmailMTAClass)(sendmailMTAClassName=%s)(|(sendmailMTACluster=%s)(sendmailMTAHost=%s))) -v sendmailMTAClassValue,sendmailMTAClassSearch:FILTER:sendmailMTAClass,sendmailMTAClassURL:URL:sendmailMTAClass",
967 					mn, lc, jbuf);
968 			if (n >= sizeof buf)
969 			{
970 				syserr("fileclass: F{%s}: Default LDAP string too long",
971 				       mn);
972 				sm_free(mn);
973 				return;
974 			}
975 			spec = buf;
976 		}
977 		else
978 #endif /* LDAPMAP */
979 		{
980 			if ((spec = strchr(cl, ':')) == NULL)
981 			{
982 				syserr("fileclass: F{%s}: missing map class",
983 				       mn);
984 				sm_free(mn);
985 				return;
986 			}
987 			*spec++ ='\0';
988 		}
989 
990 		/* set up map structure */
991 		mapclass = stab(cl, ST_MAPCLASS, ST_FIND);
992 		if (mapclass == NULL)
993 		{
994 			syserr("fileclass: F{%s}: class %s not available",
995 			       mn, cl);
996 			sm_free(mn);
997 			return;
998 		}
999 		memset(&map, '\0', sizeof map);
1000 		map.map_class = &mapclass->s_mapclass;
1001 		map.map_mname = mn;
1002 		map.map_mflags |= MF_FILECLASS;
1003 
1004 		if (tTd(37, 5))
1005 			sm_dprintf("fileclass: F{%s}: map class %s, key %s, spec %s\n",
1006 				   mn, cl, key, spec);
1007 
1008 
1009 		/* parse map spec */
1010 		if (!map.map_class->map_parse(&map, spec))
1011 		{
1012 			/* map_parse() showed the error already */
1013 			sm_free(mn);
1014 			return;
1015 		}
1016 		map.map_mflags |= MF_VALID;
1017 
1018 		/* open map */
1019 		if (map.map_class->map_open(&map, O_RDONLY))
1020 		{
1021 			map.map_mflags |= MF_OPEN;
1022 			map.map_pid = getpid();
1023 		}
1024 		else
1025 		{
1026 			if (!optional &&
1027 			    !bitset(MF_OPTIONAL, map.map_mflags))
1028 				syserr("fileclass: F{%s}: map open failed",
1029 				       mn);
1030 			sm_free(mn);
1031 			return;
1032 		}
1033 
1034 		/* lookup */
1035 		p = (*map.map_class->map_lookup)(&map, key, NULL, &status);
1036 		if (status != EX_OK && status != EX_NOTFOUND)
1037 		{
1038 			if (!optional)
1039 				syserr("fileclass: F{%s}: map lookup failed",
1040 				       mn);
1041 			p = NULL;
1042 		}
1043 
1044 		/* use the results */
1045 		if (p != NULL)
1046 			parse_class_words(class, p);
1047 
1048 		/* close map */
1049 		map.map_mflags |= MF_CLOSING;
1050 		map.map_class->map_close(&map);
1051 		map.map_mflags &= ~(MF_OPEN|MF_WRITABLE|MF_CLOSING);
1052 		sm_free(mn);
1053 		return;
1054 	}
1055 	else if (filename[0] == '|')
1056 	{
1057 		auto int fd;
1058 		int i;
1059 		char *argv[MAXPV + 1];
1060 
1061 		i = 0;
1062 		for (p = strtok(&filename[1], " \t");
1063 		     p != NULL && i < MAXPV;
1064 		     p = strtok(NULL, " \t"))
1065 			argv[i++] = p;
1066 		argv[i] = NULL;
1067 		pid = prog_open(argv, &fd, CurEnv);
1068 		if (pid < 0)
1069 			f = NULL;
1070 		else
1071 			f = sm_io_open(SmFtStdiofd, SM_TIME_DEFAULT,
1072 				       (void *) &fd, SM_IO_RDONLY, NULL);
1073 	}
1074 	else
1075 	{
1076 		pid = -1;
1077 		sff = SFF_REGONLY;
1078 		if (!bitnset(DBS_CLASSFILEINUNSAFEDIRPATH, DontBlameSendmail))
1079 			sff |= SFF_SAFEDIRPATH;
1080 		if (!bitnset(DBS_LINKEDCLASSFILEINWRITABLEDIR,
1081 			     DontBlameSendmail))
1082 			sff |= SFF_NOWLINK;
1083 		if (safe)
1084 			sff |= SFF_OPENASROOT;
1085 		else if (RealUid == 0)
1086 			sff |= SFF_ROOTOK;
1087 		if (DontLockReadFiles)
1088 			sff |= SFF_NOLOCK;
1089 		f = safefopen(filename, O_RDONLY, 0, sff);
1090 	}
1091 	if (f == NULL)
1092 	{
1093 		if (!optional)
1094 			syserr("fileclass: cannot open '%s'", filename);
1095 		return;
1096 	}
1097 
1098 	while (sm_io_fgets(f, SM_TIME_DEFAULT, buf, sizeof buf) != NULL)
1099 	{
1100 #if SCANF
1101 		char wordbuf[MAXLINE + 1];
1102 #endif /* SCANF */
1103 
1104 		if (buf[0] == '#')
1105 			continue;
1106 #if SCANF
1107 		if (sm_io_sscanf(buf, fmt, wordbuf) != 1)
1108 			continue;
1109 		p = wordbuf;
1110 #else /* SCANF */
1111 		p = buf;
1112 #endif /* SCANF */
1113 
1114 		parse_class_words(class, p);
1115 
1116 		/*
1117 		**  If anything else is added here,
1118 		**  check if the '@' map case above
1119 		**  needs the code as well.
1120 		*/
1121 	}
1122 
1123 	(void) sm_io_close(f, SM_TIME_DEFAULT);
1124 	if (pid > 0)
1125 		(void) waitfor(pid);
1126 }
1127 /*
1128 **  MAKEMAILER -- define a new mailer.
1129 **
1130 **	Parameters:
1131 **		line -- description of mailer.  This is in labeled
1132 **			fields.  The fields are:
1133 **			   A -- the argv for this mailer
1134 **			   C -- the character set for MIME conversions
1135 **			   D -- the directory to run in
1136 **			   E -- the eol string
1137 **			   F -- the flags associated with the mailer
1138 **			   L -- the maximum line length
1139 **			   M -- the maximum message size
1140 **			   N -- the niceness at which to run
1141 **			   P -- the path to the mailer
1142 **			   Q -- the queue group for the mailer
1143 **			   R -- the recipient rewriting set
1144 **			   S -- the sender rewriting set
1145 **			   T -- the mailer type (for DSNs)
1146 **			   U -- the uid to run as
1147 **			   W -- the time to wait at the end
1148 **			   m -- maximum messages per connection
1149 **			   r -- maximum number of recipients per message
1150 **			   / -- new root directory
1151 **			The first word is the canonical name of the mailer.
1152 **
1153 **	Returns:
1154 **		none.
1155 **
1156 **	Side Effects:
1157 **		enters the mailer into the mailer table.
1158 */
1159 
1160 void
1161 makemailer(line)
1162 	char *line;
1163 {
1164 	register char *p;
1165 	register struct mailer *m;
1166 	register STAB *s;
1167 	int i;
1168 	char fcode;
1169 	auto char *endp;
1170 	static int nextmailer = 0;	/* "free" index into Mailer struct */
1171 
1172 	/* allocate a mailer and set up defaults */
1173 	m = (struct mailer *) xalloc(sizeof *m);
1174 	memset((char *) m, '\0', sizeof *m);
1175 	errno = 0; /* avoid bogus error text */
1176 
1177 	/* collect the mailer name */
1178 	for (p = line;
1179 	     *p != '\0' && *p != ',' && !(isascii(*p) && isspace(*p));
1180 	     p++)
1181 		continue;
1182 	if (*p != '\0')
1183 		*p++ = '\0';
1184 	if (line[0] == '\0')
1185 	{
1186 		syserr("name required for mailer");
1187 		return;
1188 	}
1189 	m->m_name = newstr(line);
1190 	m->m_qgrp = NOQGRP;
1191 	m->m_uid = NO_UID;
1192 	m->m_gid = NO_GID;
1193 
1194 	/* now scan through and assign info from the fields */
1195 	while (*p != '\0')
1196 	{
1197 		auto char *delimptr;
1198 
1199 		while (*p != '\0' &&
1200 		       (*p == ',' || (isascii(*p) && isspace(*p))))
1201 			p++;
1202 
1203 		/* p now points to field code */
1204 		fcode = *p;
1205 		while (*p != '\0' && *p != '=' && *p != ',')
1206 			p++;
1207 		if (*p++ != '=')
1208 		{
1209 			syserr("mailer %s: `=' expected", m->m_name);
1210 			return;
1211 		}
1212 		while (isascii(*p) && isspace(*p))
1213 			p++;
1214 
1215 		/* p now points to the field body */
1216 		p = munchstring(p, &delimptr, ',');
1217 
1218 		/* install the field into the mailer struct */
1219 		switch (fcode)
1220 		{
1221 		  case 'P':		/* pathname */
1222 			if (*p != '\0')	/* error is issued below */
1223 				m->m_mailer = newstr(p);
1224 			break;
1225 
1226 		  case 'F':		/* flags */
1227 			for (; *p != '\0'; p++)
1228 			{
1229 				if (!(isascii(*p) && isspace(*p)))
1230 				{
1231 #if _FFR_DEPRECATE_MAILER_FLAG_I
1232 					if (*p == M_INTERNAL)
1233 						sm_syslog(LOG_WARNING, NOQID,
1234 							  "WARNING: mailer=%s, flag=%c deprecated",
1235 							  m->m_name, *p);
1236 #endif /* _FFR_DEPRECATE_MAILER_FLAG_I */
1237 					setbitn(bitidx(*p), m->m_flags);
1238 				}
1239 			}
1240 			break;
1241 
1242 		  case 'S':		/* sender rewriting ruleset */
1243 		  case 'R':		/* recipient rewriting ruleset */
1244 			i = strtorwset(p, &endp, ST_ENTER);
1245 			if (i < 0)
1246 				return;
1247 			if (fcode == 'S')
1248 				m->m_sh_rwset = m->m_se_rwset = i;
1249 			else
1250 				m->m_rh_rwset = m->m_re_rwset = i;
1251 
1252 			p = endp;
1253 			if (*p++ == '/')
1254 			{
1255 				i = strtorwset(p, NULL, ST_ENTER);
1256 				if (i < 0)
1257 					return;
1258 				if (fcode == 'S')
1259 					m->m_sh_rwset = i;
1260 				else
1261 					m->m_rh_rwset = i;
1262 			}
1263 			break;
1264 
1265 		  case 'E':		/* end of line string */
1266 			if (*p == '\0')
1267 				syserr("mailer %s: null end-of-line string",
1268 					m->m_name);
1269 			else
1270 				m->m_eol = newstr(p);
1271 			break;
1272 
1273 		  case 'A':		/* argument vector */
1274 			if (*p != '\0')	/* error is issued below */
1275 				m->m_argv = makeargv(p);
1276 			break;
1277 
1278 		  case 'M':		/* maximum message size */
1279 			m->m_maxsize = atol(p);
1280 			break;
1281 
1282 		  case 'm':		/* maximum messages per connection */
1283 			m->m_maxdeliveries = atoi(p);
1284 			break;
1285 
1286 		  case 'r':		/* max recipient per envelope */
1287 			m->m_maxrcpt = atoi(p);
1288 			break;
1289 
1290 		  case 'L':		/* maximum line length */
1291 			m->m_linelimit = atoi(p);
1292 			if (m->m_linelimit < 0)
1293 				m->m_linelimit = 0;
1294 			break;
1295 
1296 		  case 'N':		/* run niceness */
1297 			m->m_nice = atoi(p);
1298 			break;
1299 
1300 		  case 'D':		/* working directory */
1301 			if (*p == '\0')
1302 				syserr("mailer %s: null working directory",
1303 					m->m_name);
1304 			else
1305 				m->m_execdir = newstr(p);
1306 			break;
1307 
1308 		  case 'C':		/* default charset */
1309 			if (*p == '\0')
1310 				syserr("mailer %s: null charset", m->m_name);
1311 			else
1312 				m->m_defcharset = newstr(p);
1313 			break;
1314 
1315 		  case 'Q':		/* queue for this mailer */
1316 			if (*p == '\0')
1317 			{
1318 				syserr("mailer %s: null queue", m->m_name);
1319 				break;
1320 			}
1321 			s = stab(p, ST_QUEUE, ST_FIND);
1322 			if (s == NULL)
1323 				syserr("mailer %s: unknown queue %s",
1324 					m->m_name, p);
1325 			else
1326 				m->m_qgrp = s->s_quegrp->qg_index;
1327 			break;
1328 
1329 		  case 'T':		/* MTA-Name/Address/Diagnostic types */
1330 			/* extract MTA name type; default to "dns" */
1331 			m->m_mtatype = newstr(p);
1332 			p = strchr(m->m_mtatype, '/');
1333 			if (p != NULL)
1334 			{
1335 				*p++ = '\0';
1336 				if (*p == '\0')
1337 					p = NULL;
1338 			}
1339 			if (*m->m_mtatype == '\0')
1340 				m->m_mtatype = "dns";
1341 
1342 			/* extract address type; default to "rfc822" */
1343 			m->m_addrtype = p;
1344 			if (p != NULL)
1345 				p = strchr(p, '/');
1346 			if (p != NULL)
1347 			{
1348 				*p++ = '\0';
1349 				if (*p == '\0')
1350 					p = NULL;
1351 			}
1352 			if (m->m_addrtype == NULL || *m->m_addrtype == '\0')
1353 				m->m_addrtype = "rfc822";
1354 
1355 			/* extract diagnostic type; default to "smtp" */
1356 			m->m_diagtype = p;
1357 			if (m->m_diagtype == NULL || *m->m_diagtype == '\0')
1358 				m->m_diagtype = "smtp";
1359 			break;
1360 
1361 		  case 'U':		/* user id */
1362 			if (isascii(*p) && !isdigit(*p))
1363 			{
1364 				char *q = p;
1365 				struct passwd *pw;
1366 
1367 				while (*p != '\0' && isascii(*p) &&
1368 				       (isalnum(*p) || strchr("-_", *p) != NULL))
1369 					p++;
1370 				while (isascii(*p) && isspace(*p))
1371 					*p++ = '\0';
1372 				if (*p != '\0')
1373 					*p++ = '\0';
1374 				if (*q == '\0')
1375 				{
1376 					syserr("mailer %s: null user name",
1377 						m->m_name);
1378 					break;
1379 				}
1380 				pw = sm_getpwnam(q);
1381 				if (pw == NULL)
1382 				{
1383 					syserr("readcf: mailer U= flag: unknown user %s", q);
1384 					break;
1385 				}
1386 				else
1387 				{
1388 					m->m_uid = pw->pw_uid;
1389 					m->m_gid = pw->pw_gid;
1390 				}
1391 			}
1392 			else
1393 			{
1394 				auto char *q;
1395 
1396 				m->m_uid = strtol(p, &q, 0);
1397 				p = q;
1398 				while (isascii(*p) && isspace(*p))
1399 					p++;
1400 				if (*p != '\0')
1401 					p++;
1402 			}
1403 			while (isascii(*p) && isspace(*p))
1404 				p++;
1405 			if (*p == '\0')
1406 				break;
1407 			if (isascii(*p) && !isdigit(*p))
1408 			{
1409 				char *q = p;
1410 				struct group *gr;
1411 
1412 				while (isascii(*p) && isalnum(*p))
1413 					p++;
1414 				*p++ = '\0';
1415 				if (*q == '\0')
1416 				{
1417 					syserr("mailer %s: null group name",
1418 						m->m_name);
1419 					break;
1420 				}
1421 				gr = getgrnam(q);
1422 				if (gr == NULL)
1423 				{
1424 					syserr("readcf: mailer U= flag: unknown group %s", q);
1425 					break;
1426 				}
1427 				else
1428 					m->m_gid = gr->gr_gid;
1429 			}
1430 			else
1431 			{
1432 				m->m_gid = strtol(p, NULL, 0);
1433 			}
1434 			break;
1435 
1436 		  case 'W':		/* wait timeout */
1437 			m->m_wait = convtime(p, 's');
1438 			break;
1439 
1440 		  case '/':		/* new root directory */
1441 			if (*p == '\0')
1442 				syserr("mailer %s: null root directory",
1443 					m->m_name);
1444 			else
1445 				m->m_rootdir = newstr(p);
1446 			break;
1447 
1448 		  default:
1449 			syserr("M%s: unknown mailer equate %c=",
1450 			       m->m_name, fcode);
1451 			break;
1452 		}
1453 
1454 		p = delimptr;
1455 	}
1456 
1457 #if !HASRRESVPORT
1458 	if (bitnset(M_SECURE_PORT, m->m_flags))
1459 	{
1460 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1461 				     "M%s: Warning: F=%c set on system that doesn't support rresvport()\n",
1462 				     m->m_name, M_SECURE_PORT);
1463 	}
1464 #endif /* !HASRRESVPORT */
1465 
1466 #if !HASNICE
1467 	if (m->m_nice != 0)
1468 	{
1469 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1470 				     "M%s: Warning: N= set on system that doesn't support nice()\n",
1471 				     m->m_name);
1472 	}
1473 #endif /* !HASNICE */
1474 
1475 	/* do some rationality checking */
1476 	if (m->m_argv == NULL)
1477 	{
1478 		syserr("M%s: A= argument required", m->m_name);
1479 		return;
1480 	}
1481 	if (m->m_mailer == NULL)
1482 	{
1483 		syserr("M%s: P= argument required", m->m_name);
1484 		return;
1485 	}
1486 
1487 	if (nextmailer >= MAXMAILERS)
1488 	{
1489 		syserr("too many mailers defined (%d max)", MAXMAILERS);
1490 		return;
1491 	}
1492 
1493 	if (m->m_maxrcpt <= 0)
1494 		m->m_maxrcpt = DEFAULT_MAX_RCPT;
1495 
1496 	/* do some heuristic cleanup for back compatibility */
1497 	if (bitnset(M_LIMITS, m->m_flags))
1498 	{
1499 		if (m->m_linelimit == 0)
1500 			m->m_linelimit = SMTPLINELIM;
1501 		if (ConfigLevel < 2)
1502 			setbitn(M_7BITS, m->m_flags);
1503 	}
1504 
1505 	if (strcmp(m->m_mailer, "[TCP]") == 0)
1506 	{
1507 		syserr("M%s: P=[TCP] must be replaced by P=[IPC]", m->m_name);
1508 		return;
1509 	}
1510 
1511 	if (strcmp(m->m_mailer, "[IPC]") == 0)
1512 	{
1513 		/* Use the second argument for host or path to socket */
1514 		if (m->m_argv[0] == NULL || m->m_argv[1] == NULL ||
1515 		    m->m_argv[1][0] == '\0')
1516 		{
1517 			syserr("M%s: too few parameters for %s mailer",
1518 			       m->m_name, m->m_mailer);
1519 			return;
1520 		}
1521 		if (strcmp(m->m_argv[0], "TCP") != 0
1522 #if NETUNIX
1523 		    && strcmp(m->m_argv[0], "FILE") != 0
1524 #endif /* NETUNIX */
1525 		    )
1526 		{
1527 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
1528 					     "M%s: Warning: first argument in %s mailer must be %s\n",
1529 					     m->m_name, m->m_mailer,
1530 #if NETUNIX
1531 					     "TCP or FILE"
1532 #else /* NETUNIX */
1533 					     "TCP"
1534 #endif /* NETUNIX */
1535 				     );
1536 		}
1537 		if (m->m_mtatype == NULL)
1538 			m->m_mtatype = "dns";
1539 		if (m->m_addrtype == NULL)
1540 			m->m_addrtype = "rfc822";
1541 		if (m->m_diagtype == NULL)
1542 		{
1543 			if (m->m_argv[0] != NULL &&
1544 			    strcmp(m->m_argv[0], "FILE") == 0)
1545 				m->m_diagtype = "x-unix";
1546 			else
1547 				m->m_diagtype = "smtp";
1548 		}
1549 	}
1550 	else if (strcmp(m->m_mailer, "[FILE]") == 0)
1551 	{
1552 		/* Use the second argument for filename */
1553 		if (m->m_argv[0] == NULL || m->m_argv[1] == NULL ||
1554 		    m->m_argv[2] != NULL)
1555 		{
1556 			syserr("M%s: too %s parameters for [FILE] mailer",
1557 			       m->m_name,
1558 			       (m->m_argv[0] == NULL ||
1559 				m->m_argv[1] == NULL) ? "few" : "many");
1560 			return;
1561 		}
1562 		else if (strcmp(m->m_argv[0], "FILE") != 0)
1563 		{
1564 			syserr("M%s: first argument in [FILE] mailer must be FILE",
1565 			       m->m_name);
1566 			return;
1567 		}
1568 	}
1569 
1570 	if (m->m_eol == NULL)
1571 	{
1572 		char **pp;
1573 
1574 		/* default for SMTP is \r\n; use \n for local delivery */
1575 		for (pp = m->m_argv; *pp != NULL; pp++)
1576 		{
1577 			for (p = *pp; *p != '\0'; )
1578 			{
1579 				if ((*p++ & 0377) == MACROEXPAND && *p == 'u')
1580 					break;
1581 			}
1582 			if (*p != '\0')
1583 				break;
1584 		}
1585 		if (*pp == NULL)
1586 			m->m_eol = "\r\n";
1587 		else
1588 			m->m_eol = "\n";
1589 	}
1590 
1591 	/* enter the mailer into the symbol table */
1592 	s = stab(m->m_name, ST_MAILER, ST_ENTER);
1593 	if (s->s_mailer != NULL)
1594 	{
1595 		i = s->s_mailer->m_mno;
1596 		sm_free(s->s_mailer); /* XXX */
1597 	}
1598 	else
1599 	{
1600 		i = nextmailer++;
1601 	}
1602 	Mailer[i] = s->s_mailer = m;
1603 	m->m_mno = i;
1604 }
1605 /*
1606 **  MUNCHSTRING -- translate a string into internal form.
1607 **
1608 **	Parameters:
1609 **		p -- the string to munch.
1610 **		delimptr -- if non-NULL, set to the pointer of the
1611 **			field delimiter character.
1612 **		delim -- the delimiter for the field.
1613 **
1614 **	Returns:
1615 **		the munched string.
1616 **
1617 **	Side Effects:
1618 **		the munched string is a local static buffer.
1619 **		it must be copied before the function is called again.
1620 */
1621 
1622 char *
1623 munchstring(p, delimptr, delim)
1624 	register char *p;
1625 	char **delimptr;
1626 	int delim;
1627 {
1628 	register char *q;
1629 	bool backslash = false;
1630 	bool quotemode = false;
1631 	static char buf[MAXLINE];
1632 
1633 	for (q = buf; *p != '\0' && q < &buf[sizeof buf - 1]; p++)
1634 	{
1635 		if (backslash)
1636 		{
1637 			/* everything is roughly literal */
1638 			backslash = false;
1639 			switch (*p)
1640 			{
1641 			  case 'r':		/* carriage return */
1642 				*q++ = '\r';
1643 				continue;
1644 
1645 			  case 'n':		/* newline */
1646 				*q++ = '\n';
1647 				continue;
1648 
1649 			  case 'f':		/* form feed */
1650 				*q++ = '\f';
1651 				continue;
1652 
1653 			  case 'b':		/* backspace */
1654 				*q++ = '\b';
1655 				continue;
1656 			}
1657 			*q++ = *p;
1658 		}
1659 		else
1660 		{
1661 			if (*p == '\\')
1662 				backslash = true;
1663 			else if (*p == '"')
1664 				quotemode = !quotemode;
1665 			else if (quotemode || *p != delim)
1666 				*q++ = *p;
1667 			else
1668 				break;
1669 		}
1670 	}
1671 
1672 	if (delimptr != NULL)
1673 		*delimptr = p;
1674 	*q++ = '\0';
1675 	return buf;
1676 }
1677 /*
1678 **  EXTRQUOTSTR -- extract a (quoted) string.
1679 **
1680 **	This routine deals with quoted (") strings and escaped
1681 **	spaces (\\ ).
1682 **
1683 **	Parameters:
1684 **		p -- source string.
1685 **		delimptr -- if non-NULL, set to the pointer of the
1686 **			field delimiter character.
1687 **		delimbuf -- delimiters for the field.
1688 **		st -- if non-NULL, store the return value (whether the
1689 **			string was correctly quoted) here.
1690 **
1691 **	Returns:
1692 **		the extracted string.
1693 **
1694 **	Side Effects:
1695 **		the returned string is a local static buffer.
1696 **		it must be copied before the function is called again.
1697 */
1698 
1699 static char *
1700 extrquotstr(p, delimptr, delimbuf, st)
1701 	register char *p;
1702 	char **delimptr;
1703 	char *delimbuf;
1704 	bool *st;
1705 {
1706 	register char *q;
1707 	bool backslash = false;
1708 	bool quotemode = false;
1709 	static char buf[MAXLINE];
1710 
1711 	for (q = buf; *p != '\0' && q < &buf[sizeof buf - 1]; p++)
1712 	{
1713 		if (backslash)
1714 		{
1715 			backslash = false;
1716 			if (*p != ' ')
1717 				*q++ = '\\';
1718 		}
1719 		if (*p == '\\')
1720 			backslash = true;
1721 		else if (*p == '"')
1722 			quotemode = !quotemode;
1723 		else if (quotemode ||
1724 			 strchr(delimbuf, (int) *p) == NULL)
1725 			*q++ = *p;
1726 		else
1727 			break;
1728 	}
1729 
1730 	if (delimptr != NULL)
1731 		*delimptr = p;
1732 	*q++ = '\0';
1733 	if (st != NULL)
1734 		*st = !(quotemode || backslash);
1735 	return buf;
1736 }
1737 /*
1738 **  MAKEARGV -- break up a string into words
1739 **
1740 **	Parameters:
1741 **		p -- the string to break up.
1742 **
1743 **	Returns:
1744 **		a char **argv (dynamically allocated)
1745 **
1746 **	Side Effects:
1747 **		munges p.
1748 */
1749 
1750 static char **
1751 makeargv(p)
1752 	register char *p;
1753 {
1754 	char *q;
1755 	int i;
1756 	char **avp;
1757 	char *argv[MAXPV + 1];
1758 
1759 	/* take apart the words */
1760 	i = 0;
1761 	while (*p != '\0' && i < MAXPV)
1762 	{
1763 		q = p;
1764 		while (*p != '\0' && !(isascii(*p) && isspace(*p)))
1765 			p++;
1766 		while (isascii(*p) && isspace(*p))
1767 			*p++ = '\0';
1768 		argv[i++] = newstr(q);
1769 	}
1770 	argv[i++] = NULL;
1771 
1772 	/* now make a copy of the argv */
1773 	avp = (char **) xalloc(sizeof *avp * i);
1774 	memmove((char *) avp, (char *) argv, sizeof *avp * i);
1775 
1776 	return avp;
1777 }
1778 /*
1779 **  PRINTRULES -- print rewrite rules (for debugging)
1780 **
1781 **	Parameters:
1782 **		none.
1783 **
1784 **	Returns:
1785 **		none.
1786 **
1787 **	Side Effects:
1788 **		prints rewrite rules.
1789 */
1790 
1791 void
1792 printrules()
1793 {
1794 	register struct rewrite *rwp;
1795 	register int ruleset;
1796 
1797 	for (ruleset = 0; ruleset < 10; ruleset++)
1798 	{
1799 		if (RewriteRules[ruleset] == NULL)
1800 			continue;
1801 		sm_dprintf("\n----Rule Set %d:", ruleset);
1802 
1803 		for (rwp = RewriteRules[ruleset]; rwp != NULL; rwp = rwp->r_next)
1804 		{
1805 			sm_dprintf("\nLHS:");
1806 			printav(sm_debug_file(), rwp->r_lhs);
1807 			sm_dprintf("RHS:");
1808 			printav(sm_debug_file(), rwp->r_rhs);
1809 		}
1810 	}
1811 }
1812 /*
1813 **  PRINTMAILER -- print mailer structure (for debugging)
1814 **
1815 **	Parameters:
1816 **		fp -- output file
1817 **		m -- the mailer to print
1818 **
1819 **	Returns:
1820 **		none.
1821 */
1822 
1823 void
1824 printmailer(fp, m)
1825 	SM_FILE_T *fp;
1826 	register MAILER *m;
1827 {
1828 	int j;
1829 
1830 	(void) sm_io_fprintf(fp, SM_TIME_DEFAULT,
1831 			     "mailer %d (%s): P=%s S=", m->m_mno, m->m_name,
1832 			     m->m_mailer);
1833 	if (RuleSetNames[m->m_se_rwset] == NULL)
1834 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%d/",
1835 				     m->m_se_rwset);
1836 	else
1837 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%s/",
1838 				     RuleSetNames[m->m_se_rwset]);
1839 	if (RuleSetNames[m->m_sh_rwset] == NULL)
1840 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%d R=",
1841 				     m->m_sh_rwset);
1842 	else
1843 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%s R=",
1844 				     RuleSetNames[m->m_sh_rwset]);
1845 	if (RuleSetNames[m->m_re_rwset] == NULL)
1846 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%d/",
1847 				     m->m_re_rwset);
1848 	else
1849 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%s/",
1850 				     RuleSetNames[m->m_re_rwset]);
1851 	if (RuleSetNames[m->m_rh_rwset] == NULL)
1852 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%d ",
1853 				     m->m_rh_rwset);
1854 	else
1855 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "%s ",
1856 				     RuleSetNames[m->m_rh_rwset]);
1857 	(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "M=%ld U=%d:%d F=",
1858 			     m->m_maxsize, (int) m->m_uid, (int) m->m_gid);
1859 	for (j = '\0'; j <= '\177'; j++)
1860 		if (bitnset(j, m->m_flags))
1861 			(void) sm_io_putc(fp, SM_TIME_DEFAULT, j);
1862 	(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, " L=%d E=",
1863 			     m->m_linelimit);
1864 	xputs(fp, m->m_eol);
1865 	if (m->m_defcharset != NULL)
1866 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, " C=%s",
1867 				     m->m_defcharset);
1868 	(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, " T=%s/%s/%s",
1869 			     m->m_mtatype == NULL
1870 				? "<undefined>" : m->m_mtatype,
1871 			     m->m_addrtype == NULL
1872 				? "<undefined>" : m->m_addrtype,
1873 			     m->m_diagtype == NULL
1874 				? "<undefined>" : m->m_diagtype);
1875 	(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, " r=%d", m->m_maxrcpt);
1876 	if (m->m_argv != NULL)
1877 	{
1878 		char **a = m->m_argv;
1879 
1880 		(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, " A=");
1881 		while (*a != NULL)
1882 		{
1883 			if (a != m->m_argv)
1884 				(void) sm_io_fprintf(fp, SM_TIME_DEFAULT,
1885 						     " ");
1886 			xputs(fp, *a++);
1887 		}
1888 	}
1889 	(void) sm_io_fprintf(fp, SM_TIME_DEFAULT, "\n");
1890 }
1891 /*
1892 **  SETOPTION -- set global processing option
1893 **
1894 **	Parameters:
1895 **		opt -- option name.
1896 **		val -- option value (as a text string).
1897 **		safe -- set if this came from a configuration file.
1898 **			Some options (if set from the command line) will
1899 **			reset the user id to avoid security problems.
1900 **		sticky -- if set, don't let other setoptions override
1901 **			this value.
1902 **		e -- the main envelope.
1903 **
1904 **	Returns:
1905 **		none.
1906 **
1907 **	Side Effects:
1908 **		Sets options as implied by the arguments.
1909 */
1910 
1911 static BITMAP256	StickyOpt;		/* set if option is stuck */
1912 
1913 #if NAMED_BIND
1914 
1915 static struct resolverflags
1916 {
1917 	char	*rf_name;	/* name of the flag */
1918 	long	rf_bits;	/* bits to set/clear */
1919 } ResolverFlags[] =
1920 {
1921 	{ "debug",	RES_DEBUG	},
1922 	{ "aaonly",	RES_AAONLY	},
1923 	{ "usevc",	RES_USEVC	},
1924 	{ "primary",	RES_PRIMARY	},
1925 	{ "igntc",	RES_IGNTC	},
1926 	{ "recurse",	RES_RECURSE	},
1927 	{ "defnames",	RES_DEFNAMES	},
1928 	{ "stayopen",	RES_STAYOPEN	},
1929 	{ "dnsrch",	RES_DNSRCH	},
1930 # ifdef RES_USE_INET6
1931 	{ "use_inet6",	RES_USE_INET6	},
1932 # endif /* RES_USE_INET6 */
1933 	{ "true",	0		},	/* avoid error on old syntax */
1934 	{ NULL,		0		}
1935 };
1936 
1937 #endif /* NAMED_BIND */
1938 
1939 #define OI_NONE		0	/* no special treatment */
1940 #define OI_SAFE		0x0001	/* safe for random people to use */
1941 #define OI_SUBOPT	0x0002	/* option has suboptions */
1942 
1943 static struct optioninfo
1944 {
1945 	char		*o_name;	/* long name of option */
1946 	unsigned char	o_code;		/* short name of option */
1947 	unsigned short	o_flags;	/* option flags */
1948 } OptionTab[] =
1949 {
1950 #if defined(SUN_EXTENSIONS) && defined(REMOTE_MODE)
1951 	{ "RemoteMode",			'>',		OI_NONE	},
1952 #endif /* defined(SUN_EXTENSIONS) && defined(REMOTE_MODE) */
1953 	{ "SevenBitInput",		'7',		OI_SAFE	},
1954 	{ "EightBitMode",		'8',		OI_SAFE	},
1955 	{ "AliasFile",			'A',		OI_NONE	},
1956 	{ "AliasWait",			'a',		OI_NONE	},
1957 	{ "BlankSub",			'B',		OI_NONE	},
1958 	{ "MinFreeBlocks",		'b',		OI_SAFE	},
1959 	{ "CheckpointInterval",		'C',		OI_SAFE	},
1960 	{ "HoldExpensive",		'c',		OI_NONE	},
1961 	{ "DeliveryMode",		'd',		OI_SAFE	},
1962 	{ "ErrorHeader",		'E',		OI_NONE	},
1963 	{ "ErrorMode",			'e',		OI_SAFE	},
1964 	{ "TempFileMode",		'F',		OI_NONE	},
1965 	{ "SaveFromLine",		'f',		OI_NONE	},
1966 	{ "MatchGECOS",			'G',		OI_NONE	},
1967 
1968 	/* no long name, just here to avoid problems in setoption */
1969 	{ "",				'g',		OI_NONE	},
1970 	{ "HelpFile",			'H',		OI_NONE	},
1971 	{ "MaxHopCount",		'h',		OI_NONE	},
1972 	{ "ResolverOptions",		'I',		OI_NONE	},
1973 	{ "IgnoreDots",			'i',		OI_SAFE	},
1974 	{ "ForwardPath",		'J',		OI_NONE	},
1975 	{ "SendMimeErrors",		'j',		OI_SAFE	},
1976 	{ "ConnectionCacheSize",	'k',		OI_NONE	},
1977 	{ "ConnectionCacheTimeout",	'K',		OI_NONE	},
1978 	{ "UseErrorsTo",		'l',		OI_NONE	},
1979 	{ "LogLevel",			'L',		OI_SAFE	},
1980 	{ "MeToo",			'm',		OI_SAFE	},
1981 
1982 	/* no long name, just here to avoid problems in setoption */
1983 	{ "",				'M',		OI_NONE	},
1984 	{ "CheckAliases",		'n',		OI_NONE	},
1985 	{ "OldStyleHeaders",		'o',		OI_SAFE	},
1986 	{ "DaemonPortOptions",		'O',		OI_NONE	},
1987 	{ "PrivacyOptions",		'p',		OI_SAFE	},
1988 	{ "PostmasterCopy",		'P',		OI_NONE	},
1989 	{ "QueueFactor",		'q',		OI_NONE	},
1990 	{ "QueueDirectory",		'Q',		OI_NONE	},
1991 	{ "DontPruneRoutes",		'R',		OI_NONE	},
1992 	{ "Timeout",			'r',		OI_SUBOPT },
1993 	{ "StatusFile",			'S',		OI_NONE	},
1994 	{ "SuperSafe",			's',		OI_SAFE	},
1995 	{ "QueueTimeout",		'T',		OI_NONE	},
1996 	{ "TimeZoneSpec",		't',		OI_NONE	},
1997 	{ "UserDatabaseSpec",		'U',		OI_NONE	},
1998 	{ "DefaultUser",		'u',		OI_NONE	},
1999 	{ "FallbackMXhost",		'V',		OI_NONE	},
2000 	{ "Verbose",			'v',		OI_SAFE	},
2001 	{ "TryNullMXList",		'w',		OI_NONE	},
2002 	{ "QueueLA",			'x',		OI_NONE	},
2003 	{ "RefuseLA",			'X',		OI_NONE	},
2004 	{ "RecipientFactor",		'y',		OI_NONE	},
2005 	{ "ForkEachJob",		'Y',		OI_NONE	},
2006 	{ "ClassFactor",		'z',		OI_NONE	},
2007 	{ "RetryFactor",		'Z',		OI_NONE	},
2008 #define O_QUEUESORTORD	0x81
2009 	{ "QueueSortOrder",		O_QUEUESORTORD,	OI_SAFE	},
2010 #define O_HOSTSFILE	0x82
2011 	{ "HostsFile",			O_HOSTSFILE,	OI_NONE	},
2012 #define O_MQA		0x83
2013 	{ "MinQueueAge",		O_MQA,		OI_SAFE	},
2014 #define O_DEFCHARSET	0x85
2015 	{ "DefaultCharSet",		O_DEFCHARSET,	OI_SAFE	},
2016 #define O_SSFILE	0x86
2017 	{ "ServiceSwitchFile",		O_SSFILE,	OI_NONE	},
2018 #define O_DIALDELAY	0x87
2019 	{ "DialDelay",			O_DIALDELAY,	OI_SAFE	},
2020 #define O_NORCPTACTION	0x88
2021 	{ "NoRecipientAction",		O_NORCPTACTION,	OI_SAFE	},
2022 #define O_SAFEFILEENV	0x89
2023 	{ "SafeFileEnvironment",	O_SAFEFILEENV,	OI_NONE	},
2024 #define O_MAXMSGSIZE	0x8a
2025 	{ "MaxMessageSize",		O_MAXMSGSIZE,	OI_NONE	},
2026 #define O_COLONOKINADDR	0x8b
2027 	{ "ColonOkInAddr",		O_COLONOKINADDR, OI_SAFE },
2028 #define O_MAXQUEUERUN	0x8c
2029 	{ "MaxQueueRunSize",		O_MAXQUEUERUN,	OI_SAFE	},
2030 #define O_MAXCHILDREN	0x8d
2031 	{ "MaxDaemonChildren",		O_MAXCHILDREN,	OI_NONE	},
2032 #define O_KEEPCNAMES	0x8e
2033 	{ "DontExpandCnames",		O_KEEPCNAMES,	OI_NONE	},
2034 #define O_MUSTQUOTE	0x8f
2035 	{ "MustQuoteChars",		O_MUSTQUOTE,	OI_NONE	},
2036 #define O_SMTPGREETING	0x90
2037 	{ "SmtpGreetingMessage",	O_SMTPGREETING,	OI_NONE	},
2038 #define O_UNIXFROM	0x91
2039 	{ "UnixFromLine",		O_UNIXFROM,	OI_NONE	},
2040 #define O_OPCHARS	0x92
2041 	{ "OperatorChars",		O_OPCHARS,	OI_NONE	},
2042 #define O_DONTINITGRPS	0x93
2043 	{ "DontInitGroups",		O_DONTINITGRPS,	OI_NONE	},
2044 #define O_SLFH		0x94
2045 	{ "SingleLineFromHeader",	O_SLFH,		OI_SAFE	},
2046 #define O_ABH		0x95
2047 	{ "AllowBogusHELO",		O_ABH,		OI_SAFE	},
2048 #define O_CONNTHROT	0x97
2049 	{ "ConnectionRateThrottle",	O_CONNTHROT,	OI_NONE	},
2050 #define O_UGW		0x99
2051 	{ "UnsafeGroupWrites",		O_UGW,		OI_NONE	},
2052 #define O_DBLBOUNCE	0x9a
2053 	{ "DoubleBounceAddress",	O_DBLBOUNCE,	OI_NONE	},
2054 #define O_HSDIR		0x9b
2055 	{ "HostStatusDirectory",	O_HSDIR,	OI_NONE	},
2056 #define O_SINGTHREAD	0x9c
2057 	{ "SingleThreadDelivery",	O_SINGTHREAD,	OI_NONE	},
2058 #define O_RUNASUSER	0x9d
2059 	{ "RunAsUser",			O_RUNASUSER,	OI_NONE	},
2060 #define O_DSN_RRT	0x9e
2061 	{ "RrtImpliesDsn",		O_DSN_RRT,	OI_NONE	},
2062 #define O_PIDFILE	0x9f
2063 	{ "PidFile",			O_PIDFILE,	OI_NONE	},
2064 #define O_DONTBLAMESENDMAIL	0xa0
2065 	{ "DontBlameSendmail",		O_DONTBLAMESENDMAIL,	OI_NONE	},
2066 #define O_DPI		0xa1
2067 	{ "DontProbeInterfaces",	O_DPI,		OI_NONE	},
2068 #define O_MAXRCPT	0xa2
2069 	{ "MaxRecipientsPerMessage",	O_MAXRCPT,	OI_SAFE	},
2070 #define O_DEADLETTER	0xa3
2071 	{ "DeadLetterDrop",		O_DEADLETTER,	OI_NONE	},
2072 #if _FFR_DONTLOCKFILESFORREAD_OPTION
2073 # define O_DONTLOCK	0xa4
2074 	{ "DontLockFilesForRead",	O_DONTLOCK,	OI_NONE	},
2075 #endif /* _FFR_DONTLOCKFILESFORREAD_OPTION */
2076 #define O_MAXALIASRCSN	0xa5
2077 	{ "MaxAliasRecursion",		O_MAXALIASRCSN,	OI_NONE	},
2078 #define O_CNCTONLYTO	0xa6
2079 	{ "ConnectOnlyTo",		O_CNCTONLYTO,	OI_NONE	},
2080 #define O_TRUSTUSER	0xa7
2081 	{ "TrustedUser",		O_TRUSTUSER,	OI_NONE	},
2082 #define O_MAXMIMEHDRLEN	0xa8
2083 	{ "MaxMimeHeaderLength",	O_MAXMIMEHDRLEN,	OI_NONE	},
2084 #define O_CONTROLSOCKET	0xa9
2085 	{ "ControlSocketName",		O_CONTROLSOCKET,	OI_NONE	},
2086 #define O_MAXHDRSLEN	0xaa
2087 	{ "MaxHeadersLength",		O_MAXHDRSLEN,	OI_NONE	},
2088 #if _FFR_MAX_FORWARD_ENTRIES
2089 # define O_MAXFORWARD	0xab
2090 	{ "MaxForwardEntries",		O_MAXFORWARD,	OI_NONE	},
2091 #endif /* _FFR_MAX_FORWARD_ENTRIES */
2092 #define O_PROCTITLEPREFIX	0xac
2093 	{ "ProcessTitlePrefix",		O_PROCTITLEPREFIX,	OI_NONE	},
2094 #define O_SASLINFO	0xad
2095 #if _FFR_ALLOW_SASLINFO
2096 	{ "DefaultAuthInfo",		O_SASLINFO,	OI_SAFE	},
2097 #else /* _FFR_ALLOW_SASLINFO */
2098 	{ "DefaultAuthInfo",		O_SASLINFO,	OI_NONE	},
2099 #endif /* _FFR_ALLOW_SASLINFO */
2100 #define O_SASLMECH	0xae
2101 	{ "AuthMechanisms",		O_SASLMECH,	OI_NONE	},
2102 #define O_CLIENTPORT	0xaf
2103 	{ "ClientPortOptions",		O_CLIENTPORT,	OI_NONE	},
2104 #define O_DF_BUFSIZE	0xb0
2105 	{ "DataFileBufferSize",		O_DF_BUFSIZE,	OI_NONE	},
2106 #define O_XF_BUFSIZE	0xb1
2107 	{ "XscriptFileBufferSize",	O_XF_BUFSIZE,	OI_NONE	},
2108 #define O_LDAPDEFAULTSPEC	0xb2
2109 	{ "LDAPDefaultSpec",		O_LDAPDEFAULTSPEC,	OI_NONE	},
2110 #define O_SRVCERTFILE	0xb4
2111 	{ "ServerCertFile",		O_SRVCERTFILE,	OI_NONE	},
2112 #define O_SRVKEYFILE	0xb5
2113 	{ "ServerKeyFile",		O_SRVKEYFILE,	OI_NONE	},
2114 #define O_CLTCERTFILE	0xb6
2115 	{ "ClientCertFile",		O_CLTCERTFILE,	OI_NONE	},
2116 #define O_CLTKEYFILE	0xb7
2117 	{ "ClientKeyFile",		O_CLTKEYFILE,	OI_NONE	},
2118 #define O_CACERTFILE	0xb8
2119 	{ "CACertFile",			O_CACERTFILE,	OI_NONE	},
2120 #define O_CACERTPATH	0xb9
2121 	{ "CACertPath",			O_CACERTPATH,	OI_NONE	},
2122 #define O_DHPARAMS	0xba
2123 	{ "DHParameters",		O_DHPARAMS,	OI_NONE	},
2124 #define O_INPUTMILTER	0xbb
2125 	{ "InputMailFilters",		O_INPUTMILTER,	OI_NONE	},
2126 #define O_MILTER	0xbc
2127 	{ "Milter",			O_MILTER,	OI_SUBOPT	},
2128 #define O_SASLOPTS	0xbd
2129 	{ "AuthOptions",		O_SASLOPTS,	OI_NONE	},
2130 #define O_QUEUE_FILE_MODE	0xbe
2131 	{ "QueueFileMode",		O_QUEUE_FILE_MODE, OI_NONE	},
2132 #if _FFR_TLS_1
2133 # define O_DHPARAMS5	0xbf
2134 	{ "DHParameters512",		O_DHPARAMS5,	OI_NONE	},
2135 # define O_CIPHERLIST	0xc0
2136 	{ "CipherList",			O_CIPHERLIST,	OI_NONE	},
2137 #endif /* _FFR_TLS_1 */
2138 #define O_RANDFILE	0xc1
2139 	{ "RandFile",			O_RANDFILE,	OI_NONE	},
2140 #define O_TLS_SRV_OPTS	0xc2
2141 	{ "TLSSrvOptions",		O_TLS_SRV_OPTS,	OI_NONE	},
2142 #define O_RCPTTHROT	0xc3
2143 	{ "BadRcptThrottle",		O_RCPTTHROT,	OI_SAFE	},
2144 #define O_DLVR_MIN	0xc4
2145 	{ "DeliverByMin",		O_DLVR_MIN,	OI_NONE	},
2146 #define O_MAXQUEUECHILDREN	0xc5
2147 	{ "MaxQueueChildren",		O_MAXQUEUECHILDREN,	OI_NONE	},
2148 #define O_MAXRUNNERSPERQUEUE	0xc6
2149 	{ "MaxRunnersPerQueue",		O_MAXRUNNERSPERQUEUE,	OI_NONE },
2150 #define O_DIRECTSUBMODIFIERS	0xc7
2151 	{ "DirectSubmissionModifiers",	O_DIRECTSUBMODIFIERS,	OI_NONE },
2152 #define O_NICEQUEUERUN	0xc8
2153 	{ "NiceQueueRun",		O_NICEQUEUERUN,	OI_NONE	},
2154 #define O_SHMKEY	0xc9
2155 	{ "SharedMemoryKey",		O_SHMKEY,	OI_NONE	},
2156 #define O_SASLBITS	0xca
2157 	{ "AuthMaxBits",		O_SASLBITS,	OI_NONE	},
2158 #define O_MBDB		0xcb
2159 	{ "MailboxDatabase",		O_MBDB,		OI_NONE	},
2160 #define O_MSQ		0xcc
2161 	{ "UseMSP",	O_MSQ,		OI_NONE	},
2162 #define O_DELAY_LA	0xcd
2163 	{ "DelayLA",	O_DELAY_LA,	OI_NONE	},
2164 #define O_FASTSPLIT	0xce
2165 	{ "FastSplit",	O_FASTSPLIT,	OI_NONE	},
2166 #if _FFR_SOFT_BOUNCE
2167 # define O_SOFTBOUNCE	0xcf
2168 	{ "SoftBounce",	O_SOFTBOUNCE,	OI_NONE	},
2169 #endif /* _FFR_SOFT_BOUNCE */
2170 #if _FFR_SELECT_SHM
2171 # define O_SHMKEYFILE	0xd0
2172 	{ "SharedMemoryKeyFile",	O_SHMKEYFILE,	OI_NONE	},
2173 #endif /* _FFR_SELECT_SHM */
2174 #define O_REJECTLOGINTERVAL	0xd1
2175 	{ "RejectLogInterval",	O_REJECTLOGINTERVAL,	OI_NONE	},
2176 #define O_REQUIRES_DIR_FSYNC	0xd2
2177 	{ "RequiresDirfsync",	O_REQUIRES_DIR_FSYNC,	OI_NONE	},
2178 #define O_CONNECTION_RATE_WINDOW_SIZE	0xd3
2179 	{ "ConnectionRateWindowSize", O_CONNECTION_RATE_WINDOW_SIZE, OI_NONE },
2180 #define O_CRLFILE	0xd4
2181 	{ "CRLFile",		O_CRLFILE,	OI_NONE	},
2182 #define O_FALLBACKSMARTHOST	0xd5
2183 	{ "FallbackSmartHost",		O_FALLBACKSMARTHOST,	OI_NONE	},
2184 #define O_SASLREALM	0xd6
2185 	{ "AuthRealm",		O_SASLREALM,	OI_NONE	},
2186 #if _FFR_CRLPATH
2187 # define O_CRLPATH	0xd7
2188 	{ "CRLPath",		O_CRLPATH,	OI_NONE	},
2189 #endif /* _FFR_CRLPATH */
2190 #if _FFR_HELONAME
2191 # define O_HELONAME 0xd8
2192 	{ "HeloName",   O_HELONAME,     OI_NONE },
2193 #endif /* _FFR_HELONAME */
2194 #if _FFR_MEMSTAT
2195 # define O_REFUSELOWMEM	0xd9
2196 	{ "RefuseLowMem",	O_REFUSELOWMEM,	OI_NONE },
2197 # define O_QUEUELOWMEM	0xda
2198 	{ "QueueLowMem",	O_QUEUELOWMEM,	OI_NONE },
2199 # define O_MEMRESOURCE	0xdb
2200 	{ "MemoryResource",	O_MEMRESOURCE,	OI_NONE },
2201 #endif /* _FFR_MEMSTAT */
2202 #if _FFR_MAXNOOPCOMMANDS
2203 # define O_MAXNOOPCOMMANDS 0xdc
2204 	{ "MaxNOOPCommands",	O_MAXNOOPCOMMANDS,	OI_NONE },
2205 #endif /* _FFR_MAXNOOPCOMMANDS */
2206 #if _FFR_MSG_ACCEPT
2207 # define O_MSG_ACCEPT 0xdd
2208 	{ "MessageAccept",	O_MSG_ACCEPT,	OI_NONE },
2209 #endif /* _FFR_MSG_ACCEPT */
2210 #if _FFR_QUEUE_RUN_PARANOIA
2211 # define O_CHK_Q_RUNNERS 0xde
2212 	{ "CheckQueueRunners",	O_CHK_Q_RUNNERS,	OI_NONE },
2213 #endif /* _FFR_QUEUE_RUN_PARANOIA */
2214 
2215 	{ NULL,				'\0',		OI_NONE	}
2216 };
2217 
2218 # define CANONIFY(val)
2219 
2220 # define SET_OPT_DEFAULT(opt, val)	opt = val
2221 
2222 /* set a string option by expanding the value and assigning it */
2223 /* WARNING this belongs ONLY into a case statement! */
2224 #define SET_STRING_EXP(str)	\
2225 		expand(val, exbuf, sizeof exbuf, e);	\
2226 		newval = sm_pstrdup_x(exbuf);		\
2227 		if (str != NULL)	\
2228 			sm_free(str);	\
2229 		CANONIFY(newval);	\
2230 		str = newval;		\
2231 		break
2232 
2233 #define OPTNAME	o->o_name == NULL ? "<unknown>" : o->o_name
2234 
2235 void
2236 setoption(opt, val, safe, sticky, e)
2237 	int opt;
2238 	char *val;
2239 	bool safe;
2240 	bool sticky;
2241 	register ENVELOPE *e;
2242 {
2243 	register char *p;
2244 	register struct optioninfo *o;
2245 	char *subopt;
2246 	int mid;
2247 	bool can_setuid = RunAsUid == 0;
2248 	auto char *ep;
2249 	char buf[50];
2250 	extern bool Warn_Q_option;
2251 #if _FFR_ALLOW_SASLINFO
2252 	extern unsigned int SubmitMode;
2253 #endif /* _FFR_ALLOW_SASLINFO */
2254 #if STARTTLS || (_FFR_SELECT_SHM && SM_CONF_SHM)
2255 	char *newval;
2256 	char exbuf[MAXLINE];
2257 #endif /* STARTTLS || (_FFR_SELECT_SHM && SM_CONF_SHM) */
2258 
2259 	errno = 0;
2260 	if (opt == ' ')
2261 	{
2262 		/* full word options */
2263 		struct optioninfo *sel;
2264 
2265 		p = strchr(val, '=');
2266 		if (p == NULL)
2267 			p = &val[strlen(val)];
2268 		while (*--p == ' ')
2269 			continue;
2270 		while (*++p == ' ')
2271 			*p = '\0';
2272 		if (p == val)
2273 		{
2274 			syserr("readcf: null option name");
2275 			return;
2276 		}
2277 		if (*p == '=')
2278 			*p++ = '\0';
2279 		while (*p == ' ')
2280 			p++;
2281 		subopt = strchr(val, '.');
2282 		if (subopt != NULL)
2283 			*subopt++ = '\0';
2284 		sel = NULL;
2285 		for (o = OptionTab; o->o_name != NULL; o++)
2286 		{
2287 			if (sm_strncasecmp(o->o_name, val, strlen(val)) != 0)
2288 				continue;
2289 			if (strlen(o->o_name) == strlen(val))
2290 			{
2291 				/* completely specified -- this must be it */
2292 				sel = NULL;
2293 				break;
2294 			}
2295 			if (sel != NULL)
2296 				break;
2297 			sel = o;
2298 		}
2299 		if (sel != NULL && o->o_name == NULL)
2300 			o = sel;
2301 		else if (o->o_name == NULL)
2302 		{
2303 			syserr("readcf: unknown option name %s", val);
2304 			return;
2305 		}
2306 		else if (sel != NULL)
2307 		{
2308 			syserr("readcf: ambiguous option name %s (matches %s and %s)",
2309 				val, sel->o_name, o->o_name);
2310 			return;
2311 		}
2312 		if (strlen(val) != strlen(o->o_name))
2313 		{
2314 			int oldVerbose = Verbose;
2315 
2316 			Verbose = 1;
2317 			message("Option %s used as abbreviation for %s",
2318 				val, o->o_name);
2319 			Verbose = oldVerbose;
2320 		}
2321 		opt = o->o_code;
2322 		val = p;
2323 	}
2324 	else
2325 	{
2326 		for (o = OptionTab; o->o_name != NULL; o++)
2327 		{
2328 			if (o->o_code == opt)
2329 				break;
2330 		}
2331 		if (o->o_name == NULL)
2332 		{
2333 			syserr("readcf: unknown option name 0x%x", opt & 0xff);
2334 			return;
2335 		}
2336 		subopt = NULL;
2337 	}
2338 
2339 	if (subopt != NULL && !bitset(OI_SUBOPT, o->o_flags))
2340 	{
2341 		if (tTd(37, 1))
2342 			sm_dprintf("setoption: %s does not support suboptions, ignoring .%s\n",
2343 				   OPTNAME, subopt);
2344 		subopt = NULL;
2345 	}
2346 
2347 	if (tTd(37, 1))
2348 	{
2349 		sm_dprintf(isascii(opt) && isprint(opt) ?
2350 			   "setoption %s (%c)%s%s=" :
2351 			   "setoption %s (0x%x)%s%s=",
2352 			   OPTNAME, opt, subopt == NULL ? "" : ".",
2353 			   subopt == NULL ? "" : subopt);
2354 		xputs(sm_debug_file(), val);
2355 	}
2356 
2357 	/*
2358 	**  See if this option is preset for us.
2359 	*/
2360 
2361 	if (!sticky && bitnset(opt, StickyOpt))
2362 	{
2363 		if (tTd(37, 1))
2364 			sm_dprintf(" (ignored)\n");
2365 		return;
2366 	}
2367 
2368 	/*
2369 	**  Check to see if this option can be specified by this user.
2370 	*/
2371 
2372 	if (!safe && RealUid == 0)
2373 		safe = true;
2374 	if (!safe && !bitset(OI_SAFE, o->o_flags))
2375 	{
2376 		if (opt != 'M' || (val[0] != 'r' && val[0] != 's'))
2377 		{
2378 			int dp;
2379 
2380 			if (tTd(37, 1))
2381 				sm_dprintf(" (unsafe)");
2382 			dp = drop_privileges(true);
2383 			setstat(dp);
2384 		}
2385 	}
2386 	if (tTd(37, 1))
2387 		sm_dprintf("\n");
2388 
2389 	switch (opt & 0xff)
2390 	{
2391 	  case '7':		/* force seven-bit input */
2392 		SevenBitInput = atobool(val);
2393 		break;
2394 
2395 	  case '8':		/* handling of 8-bit input */
2396 #if MIME8TO7
2397 		switch (*val)
2398 		{
2399 		  case 'p':		/* pass 8 bit, convert MIME */
2400 			MimeMode = MM_CVTMIME|MM_PASS8BIT;
2401 			break;
2402 
2403 		  case 'm':		/* convert 8-bit, convert MIME */
2404 			MimeMode = MM_CVTMIME|MM_MIME8BIT;
2405 			break;
2406 
2407 		  case 's':		/* strict adherence */
2408 			MimeMode = MM_CVTMIME;
2409 			break;
2410 
2411 # if 0
2412 		  case 'r':		/* reject 8-bit, don't convert MIME */
2413 			MimeMode = 0;
2414 			break;
2415 
2416 		  case 'j':		/* "just send 8" */
2417 			MimeMode = MM_PASS8BIT;
2418 			break;
2419 
2420 		  case 'a':		/* encode 8 bit if available */
2421 			MimeMode = MM_MIME8BIT|MM_PASS8BIT|MM_CVTMIME;
2422 			break;
2423 
2424 		  case 'c':		/* convert 8 bit to MIME, never 7 bit */
2425 			MimeMode = MM_MIME8BIT;
2426 			break;
2427 # endif /* 0 */
2428 
2429 		  default:
2430 			syserr("Unknown 8-bit mode %c", *val);
2431 			finis(false, true, EX_USAGE);
2432 		}
2433 #else /* MIME8TO7 */
2434 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
2435 				     "Warning: Option: %s requires MIME8TO7 support\n",
2436 				     OPTNAME);
2437 #endif /* MIME8TO7 */
2438 		break;
2439 
2440 	  case 'A':		/* set default alias file */
2441 		if (val[0] == '\0')
2442 		{
2443 			char *al;
2444 
2445 			SET_OPT_DEFAULT(al, "aliases");
2446 			setalias(al);
2447 		}
2448 		else
2449 			setalias(val);
2450 		break;
2451 
2452 	  case 'a':		/* look N minutes for "@:@" in alias file */
2453 		if (val[0] == '\0')
2454 			SafeAlias = 5 MINUTES;
2455 		else
2456 			SafeAlias = convtime(val, 'm');
2457 		break;
2458 
2459 	  case 'B':		/* substitution for blank character */
2460 		SpaceSub = val[0];
2461 		if (SpaceSub == '\0')
2462 			SpaceSub = ' ';
2463 		break;
2464 
2465 	  case 'b':		/* min blocks free on queue fs/max msg size */
2466 		p = strchr(val, '/');
2467 		if (p != NULL)
2468 		{
2469 			*p++ = '\0';
2470 			MaxMessageSize = atol(p);
2471 		}
2472 		MinBlocksFree = atol(val);
2473 		break;
2474 
2475 	  case 'c':		/* don't connect to "expensive" mailers */
2476 		NoConnect = atobool(val);
2477 		break;
2478 
2479 	  case 'C':		/* checkpoint every N addresses */
2480 		if (safe || CheckpointInterval > atoi(val))
2481 			CheckpointInterval = atoi(val);
2482 		break;
2483 
2484 	  case 'd':		/* delivery mode */
2485 		switch (*val)
2486 		{
2487 		  case '\0':
2488 			set_delivery_mode(SM_DELIVER, e);
2489 			break;
2490 
2491 		  case SM_QUEUE:	/* queue only */
2492 		  case SM_DEFER:	/* queue only and defer map lookups */
2493 		  case SM_DELIVER:	/* do everything */
2494 		  case SM_FORK:		/* fork after verification */
2495 #if _FFR_DM_ONE
2496 		/* deliver first TA in background, then queue */
2497 		  case SM_DM_ONE:
2498 #endif /* _FFR_DM_ONE */
2499 			set_delivery_mode(*val, e);
2500 			break;
2501 
2502 		  default:
2503 			syserr("Unknown delivery mode %c", *val);
2504 			finis(false, true, EX_USAGE);
2505 		}
2506 		break;
2507 
2508 	  case 'E':		/* error message header/header file */
2509 		if (*val != '\0')
2510 			ErrMsgFile = newstr(val);
2511 		break;
2512 
2513 	  case 'e':		/* set error processing mode */
2514 		switch (*val)
2515 		{
2516 		  case EM_QUIET:	/* be silent about it */
2517 		  case EM_MAIL:		/* mail back */
2518 		  case EM_BERKNET:	/* do berknet error processing */
2519 		  case EM_WRITE:	/* write back (or mail) */
2520 		  case EM_PRINT:	/* print errors normally (default) */
2521 			e->e_errormode = *val;
2522 			break;
2523 		}
2524 		break;
2525 
2526 	  case 'F':		/* file mode */
2527 		FileMode = atooct(val) & 0777;
2528 		break;
2529 
2530 	  case 'f':		/* save Unix-style From lines on front */
2531 		SaveFrom = atobool(val);
2532 		break;
2533 
2534 	  case 'G':		/* match recipients against GECOS field */
2535 		MatchGecos = atobool(val);
2536 		break;
2537 
2538 	  case 'g':		/* default gid */
2539   g_opt:
2540 		if (isascii(*val) && isdigit(*val))
2541 			DefGid = atoi(val);
2542 		else
2543 		{
2544 			register struct group *gr;
2545 
2546 			DefGid = -1;
2547 			gr = getgrnam(val);
2548 			if (gr == NULL)
2549 				syserr("readcf: option %c: unknown group %s",
2550 					opt, val);
2551 			else
2552 				DefGid = gr->gr_gid;
2553 		}
2554 		break;
2555 
2556 	  case 'H':		/* help file */
2557 		if (val[0] == '\0')
2558 		{
2559 			SET_OPT_DEFAULT(HelpFile, "helpfile");
2560 		}
2561 		else
2562 		{
2563 			CANONIFY(val);
2564 			HelpFile = newstr(val);
2565 		}
2566 		break;
2567 
2568 	  case 'h':		/* maximum hop count */
2569 		MaxHopCount = atoi(val);
2570 		break;
2571 
2572 	  case 'I':		/* use internet domain name server */
2573 #if NAMED_BIND
2574 		for (p = val; *p != 0; )
2575 		{
2576 			bool clearmode;
2577 			char *q;
2578 			struct resolverflags *rfp;
2579 
2580 			while (*p == ' ')
2581 				p++;
2582 			if (*p == '\0')
2583 				break;
2584 			clearmode = false;
2585 			if (*p == '-')
2586 				clearmode = true;
2587 			else if (*p != '+')
2588 				p--;
2589 			p++;
2590 			q = p;
2591 			while (*p != '\0' && !(isascii(*p) && isspace(*p)))
2592 				p++;
2593 			if (*p != '\0')
2594 				*p++ = '\0';
2595 			if (sm_strcasecmp(q, "HasWildcardMX") == 0)
2596 			{
2597 				HasWildcardMX = !clearmode;
2598 				continue;
2599 			}
2600 			if (sm_strcasecmp(q, "WorkAroundBrokenAAAA") == 0)
2601 			{
2602 				WorkAroundBrokenAAAA = !clearmode;
2603 				continue;
2604 			}
2605 			for (rfp = ResolverFlags; rfp->rf_name != NULL; rfp++)
2606 			{
2607 				if (sm_strcasecmp(q, rfp->rf_name) == 0)
2608 					break;
2609 			}
2610 			if (rfp->rf_name == NULL)
2611 				syserr("readcf: I option value %s unrecognized", q);
2612 			else if (clearmode)
2613 				_res.options &= ~rfp->rf_bits;
2614 			else
2615 				_res.options |= rfp->rf_bits;
2616 		}
2617 		if (tTd(8, 2))
2618 			sm_dprintf("_res.options = %x, HasWildcardMX = %d\n",
2619 				   (unsigned int) _res.options, HasWildcardMX);
2620 #else /* NAMED_BIND */
2621 		usrerr("name server (I option) specified but BIND not compiled in");
2622 #endif /* NAMED_BIND */
2623 		break;
2624 
2625 	  case 'i':		/* ignore dot lines in message */
2626 		IgnrDot = atobool(val);
2627 		break;
2628 
2629 	  case 'j':		/* send errors in MIME (RFC 1341) format */
2630 		SendMIMEErrors = atobool(val);
2631 		break;
2632 
2633 	  case 'J':		/* .forward search path */
2634 		CANONIFY(val);
2635 		ForwardPath = newstr(val);
2636 		break;
2637 
2638 	  case 'k':		/* connection cache size */
2639 		MaxMciCache = atoi(val);
2640 		if (MaxMciCache < 0)
2641 			MaxMciCache = 0;
2642 		break;
2643 
2644 	  case 'K':		/* connection cache timeout */
2645 		MciCacheTimeout = convtime(val, 'm');
2646 		break;
2647 
2648 	  case 'l':		/* use Errors-To: header */
2649 		UseErrorsTo = atobool(val);
2650 		break;
2651 
2652 	  case 'L':		/* log level */
2653 		if (safe || LogLevel < atoi(val))
2654 			LogLevel = atoi(val);
2655 		break;
2656 
2657 	  case 'M':		/* define macro */
2658 		sticky = false;
2659 		mid = macid_parse(val, &ep);
2660 		if (mid == 0)
2661 			break;
2662 		p = newstr(ep);
2663 		if (!safe)
2664 			cleanstrcpy(p, p, strlen(p) + 1);
2665 		macdefine(&CurEnv->e_macro, A_TEMP, mid, p);
2666 		break;
2667 
2668 	  case 'm':		/* send to me too */
2669 		MeToo = atobool(val);
2670 		break;
2671 
2672 	  case 'n':		/* validate RHS in newaliases */
2673 		CheckAliases = atobool(val);
2674 		break;
2675 
2676 	    /* 'N' available -- was "net name" */
2677 
2678 	  case 'O':		/* daemon options */
2679 		if (!setdaemonoptions(val))
2680 			syserr("too many daemons defined (%d max)", MAXDAEMONS);
2681 		break;
2682 
2683 	  case 'o':		/* assume old style headers */
2684 		if (atobool(val))
2685 			CurEnv->e_flags |= EF_OLDSTYLE;
2686 		else
2687 			CurEnv->e_flags &= ~EF_OLDSTYLE;
2688 		break;
2689 
2690 	  case 'p':		/* select privacy level */
2691 		p = val;
2692 		for (;;)
2693 		{
2694 			register struct prival *pv;
2695 			extern struct prival PrivacyValues[];
2696 
2697 			while (isascii(*p) && (isspace(*p) || ispunct(*p)))
2698 				p++;
2699 			if (*p == '\0')
2700 				break;
2701 			val = p;
2702 			while (isascii(*p) && isalnum(*p))
2703 				p++;
2704 			if (*p != '\0')
2705 				*p++ = '\0';
2706 
2707 			for (pv = PrivacyValues; pv->pv_name != NULL; pv++)
2708 			{
2709 				if (sm_strcasecmp(val, pv->pv_name) == 0)
2710 					break;
2711 			}
2712 			if (pv->pv_name == NULL)
2713 				syserr("readcf: Op line: %s unrecognized", val);
2714 			else
2715 				PrivacyFlags |= pv->pv_flag;
2716 		}
2717 		sticky = false;
2718 		break;
2719 
2720 	  case 'P':		/* postmaster copy address for returned mail */
2721 		PostMasterCopy = newstr(val);
2722 		break;
2723 
2724 	  case 'q':		/* slope of queue only function */
2725 		QueueFactor = atoi(val);
2726 		break;
2727 
2728 	  case 'Q':		/* queue directory */
2729 		if (val[0] == '\0')
2730 		{
2731 			QueueDir = "mqueue";
2732 		}
2733 		else
2734 		{
2735 			QueueDir = newstr(val);
2736 		}
2737 		if (RealUid != 0 && !safe)
2738 			Warn_Q_option = true;
2739 		break;
2740 
2741 	  case 'R':		/* don't prune routes */
2742 		DontPruneRoutes = atobool(val);
2743 		break;
2744 
2745 	  case 'r':		/* read timeout */
2746 		if (subopt == NULL)
2747 			inittimeouts(val, sticky);
2748 		else
2749 			settimeout(subopt, val, sticky);
2750 		break;
2751 
2752 	  case 'S':		/* status file */
2753 		if (val[0] == '\0')
2754 		{
2755 			SET_OPT_DEFAULT(StatFile, "statistics");
2756 		}
2757 		else
2758 		{
2759 			CANONIFY(val);
2760 			StatFile = newstr(val);
2761 		}
2762 		break;
2763 
2764 	  case 's':		/* be super safe, even if expensive */
2765 		if (tolower(*val) == 'i')
2766 			SuperSafe = SAFE_INTERACTIVE;
2767 		else if (tolower(*val) == 'p')
2768 #if MILTER
2769 			SuperSafe = SAFE_REALLY_POSTMILTER;
2770 #else /* MILTER */
2771 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
2772 				"Warning: SuperSafe=PostMilter requires Milter support (-DMILTER)\n");
2773 #endif /* MILTER */
2774 		else
2775 			SuperSafe = atobool(val) ? SAFE_REALLY : SAFE_NO;
2776 		break;
2777 
2778 	  case 'T':		/* queue timeout */
2779 		p = strchr(val, '/');
2780 		if (p != NULL)
2781 		{
2782 			*p++ = '\0';
2783 			settimeout("queuewarn", p, sticky);
2784 		}
2785 		settimeout("queuereturn", val, sticky);
2786 		break;
2787 
2788 	  case 't':		/* time zone name */
2789 		TimeZoneSpec = newstr(val);
2790 		break;
2791 
2792 	  case 'U':		/* location of user database */
2793 		UdbSpec = newstr(val);
2794 		break;
2795 
2796 	  case 'u':		/* set default uid */
2797 		for (p = val; *p != '\0'; p++)
2798 		{
2799 # if _FFR_DOTTED_USERNAMES
2800 			if (*p == '/' || *p == ':')
2801 # else /* _FFR_DOTTED_USERNAMES */
2802 			if (*p == '.' || *p == '/' || *p == ':')
2803 # endif /* _FFR_DOTTED_USERNAMES */
2804 			{
2805 				*p++ = '\0';
2806 				break;
2807 			}
2808 		}
2809 		if (isascii(*val) && isdigit(*val))
2810 		{
2811 			DefUid = atoi(val);
2812 			setdefuser();
2813 		}
2814 		else
2815 		{
2816 			register struct passwd *pw;
2817 
2818 			DefUid = -1;
2819 			pw = sm_getpwnam(val);
2820 			if (pw == NULL)
2821 			{
2822 				syserr("readcf: option u: unknown user %s", val);
2823 				break;
2824 			}
2825 			else
2826 			{
2827 				DefUid = pw->pw_uid;
2828 				DefGid = pw->pw_gid;
2829 				DefUser = newstr(pw->pw_name);
2830 			}
2831 		}
2832 
2833 # ifdef UID_MAX
2834 		if (DefUid > UID_MAX)
2835 		{
2836 			syserr("readcf: option u: uid value (%ld) > UID_MAX (%ld); ignored",
2837 				(long)DefUid, (long)UID_MAX);
2838 			break;
2839 		}
2840 # endif /* UID_MAX */
2841 
2842 		/* handle the group if it is there */
2843 		if (*p == '\0')
2844 			break;
2845 		val = p;
2846 		goto g_opt;
2847 
2848 	  case 'V':		/* fallback MX host */
2849 		if (val[0] != '\0')
2850 			FallbackMX = newstr(val);
2851 		break;
2852 
2853 	  case 'v':		/* run in verbose mode */
2854 		Verbose = atobool(val) ? 1 : 0;
2855 		break;
2856 
2857 	  case 'w':		/* if we are best MX, try host directly */
2858 		TryNullMXList = atobool(val);
2859 		break;
2860 
2861 	    /* 'W' available -- was wizard password */
2862 
2863 	  case 'x':		/* load avg at which to auto-queue msgs */
2864 		QueueLA = atoi(val);
2865 		break;
2866 
2867 	  case 'X':	/* load avg at which to auto-reject connections */
2868 		RefuseLA = atoi(val);
2869 		break;
2870 
2871 	  case O_DELAY_LA:	/* load avg at which to delay connections */
2872 		DelayLA = atoi(val);
2873 		break;
2874 
2875 	  case 'y':		/* work recipient factor */
2876 		WkRecipFact = atoi(val);
2877 		break;
2878 
2879 	  case 'Y':		/* fork jobs during queue runs */
2880 		ForkQueueRuns = atobool(val);
2881 		break;
2882 
2883 	  case 'z':		/* work message class factor */
2884 		WkClassFact = atoi(val);
2885 		break;
2886 
2887 	  case 'Z':		/* work time factor */
2888 		WkTimeFact = atoi(val);
2889 		break;
2890 
2891 
2892 #if _FFR_QUEUE_GROUP_SORTORDER
2893 	/* coordinate this with makequeue() */
2894 #endif /* _FFR_QUEUE_GROUP_SORTORDER */
2895 	  case O_QUEUESORTORD:	/* queue sorting order */
2896 		switch (*val)
2897 		{
2898 		  case 'f':	/* File Name */
2899 		  case 'F':
2900 			QueueSortOrder = QSO_BYFILENAME;
2901 			break;
2902 
2903 		  case 'h':	/* Host first */
2904 		  case 'H':
2905 			QueueSortOrder = QSO_BYHOST;
2906 			break;
2907 
2908 		  case 'm':	/* Modification time */
2909 		  case 'M':
2910 			QueueSortOrder = QSO_BYMODTIME;
2911 			break;
2912 
2913 		  case 'p':	/* Priority order */
2914 		  case 'P':
2915 			QueueSortOrder = QSO_BYPRIORITY;
2916 			break;
2917 
2918 		  case 't':	/* Submission time */
2919 		  case 'T':
2920 			QueueSortOrder = QSO_BYTIME;
2921 			break;
2922 
2923 		  case 'r':	/* Random */
2924 		  case 'R':
2925 			QueueSortOrder = QSO_RANDOM;
2926 			break;
2927 
2928 #if _FFR_RHS
2929 		  case 's':	/* Shuffled host name */
2930 		  case 'S':
2931 			QueueSortOrder = QSO_BYSHUFFLE;
2932 			break;
2933 #endif /* _FFR_RHS */
2934 
2935 		  case 'n':	/* none */
2936 		  case 'N':
2937 			QueueSortOrder = QSO_NONE;
2938 			break;
2939 
2940 		  default:
2941 			syserr("Invalid queue sort order \"%s\"", val);
2942 		}
2943 		break;
2944 
2945 	  case O_HOSTSFILE:	/* pathname of /etc/hosts file */
2946 		CANONIFY(val);
2947 		HostsFile = newstr(val);
2948 		break;
2949 
2950 	  case O_MQA:		/* minimum queue age between deliveries */
2951 		MinQueueAge = convtime(val, 'm');
2952 		break;
2953 
2954 	  case O_DEFCHARSET:	/* default character set for mimefying */
2955 		DefaultCharSet = newstr(denlstring(val, true, true));
2956 		break;
2957 
2958 	  case O_SSFILE:	/* service switch file */
2959 		CANONIFY(val);
2960 		ServiceSwitchFile = newstr(val);
2961 		break;
2962 
2963 	  case O_DIALDELAY:	/* delay for dial-on-demand operation */
2964 		DialDelay = convtime(val, 's');
2965 		break;
2966 
2967 	  case O_NORCPTACTION:	/* what to do if no recipient */
2968 		if (sm_strcasecmp(val, "none") == 0)
2969 			NoRecipientAction = NRA_NO_ACTION;
2970 		else if (sm_strcasecmp(val, "add-to") == 0)
2971 			NoRecipientAction = NRA_ADD_TO;
2972 		else if (sm_strcasecmp(val, "add-apparently-to") == 0)
2973 			NoRecipientAction = NRA_ADD_APPARENTLY_TO;
2974 		else if (sm_strcasecmp(val, "add-bcc") == 0)
2975 			NoRecipientAction = NRA_ADD_BCC;
2976 		else if (sm_strcasecmp(val, "add-to-undisclosed") == 0)
2977 			NoRecipientAction = NRA_ADD_TO_UNDISCLOSED;
2978 		else
2979 			syserr("Invalid NoRecipientAction: %s", val);
2980 		break;
2981 
2982 	  case O_SAFEFILEENV:	/* chroot() environ for writing to files */
2983 		if (*val == '\0')
2984 			break;
2985 
2986 		/* strip trailing slashes */
2987 		p = val + strlen(val) - 1;
2988 		while (p >= val && *p == '/')
2989 			*p-- = '\0';
2990 
2991 		if (*val == '\0')
2992 			break;
2993 
2994 		SafeFileEnv = newstr(val);
2995 		break;
2996 
2997 	  case O_MAXMSGSIZE:	/* maximum message size */
2998 		MaxMessageSize = atol(val);
2999 		break;
3000 
3001 	  case O_COLONOKINADDR:	/* old style handling of colon addresses */
3002 		ColonOkInAddr = atobool(val);
3003 		break;
3004 
3005 	  case O_MAXQUEUERUN:	/* max # of jobs in a single queue run */
3006 		MaxQueueRun = atoi(val);
3007 		break;
3008 
3009 	  case O_MAXCHILDREN:	/* max # of children of daemon */
3010 		MaxChildren = atoi(val);
3011 		break;
3012 
3013 	  case O_MAXQUEUECHILDREN: /* max # of children of daemon */
3014 		MaxQueueChildren = atoi(val);
3015 		break;
3016 
3017 	  case O_MAXRUNNERSPERQUEUE: /* max # runners in a queue group */
3018 		MaxRunnersPerQueue = atoi(val);
3019 		break;
3020 
3021 	  case O_NICEQUEUERUN:		/* nice queue runs */
3022 #if !HASNICE
3023 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3024 				     "Warning: NiceQueueRun set on system that doesn't support nice()\n");
3025 #endif /* !HASNICE */
3026 
3027 		/* XXX do we want to check the range? > 0 ? */
3028 		NiceQueueRun = atoi(val);
3029 		break;
3030 
3031 	  case O_SHMKEY:		/* shared memory key */
3032 #if SM_CONF_SHM
3033 		ShmKey = atol(val);
3034 #else /* SM_CONF_SHM */
3035 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3036 				     "Warning: Option: %s requires shared memory support (-DSM_CONF_SHM)\n",
3037 				     OPTNAME);
3038 #endif /* SM_CONF_SHM */
3039 		break;
3040 
3041 #if _FFR_SELECT_SHM
3042 	  case O_SHMKEYFILE:		/* shared memory key file */
3043 # if SM_CONF_SHM
3044 		SET_STRING_EXP(ShmKeyFile);
3045 # else /* SM_CONF_SHM */
3046 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3047 				     "Warning: Option: %s requires shared memory support (-DSM_CONF_SHM)\n",
3048 				     OPTNAME);
3049 		break;
3050 # endif /* SM_CONF_SHM */
3051 #endif /* _FFR_SELECT_SHM */
3052 
3053 #if _FFR_MAX_FORWARD_ENTRIES
3054 	  case O_MAXFORWARD:	/* max # of forward entries */
3055 		MaxForwardEntries = atoi(val);
3056 		break;
3057 #endif /* _FFR_MAX_FORWARD_ENTRIES */
3058 
3059 	  case O_KEEPCNAMES:	/* don't expand CNAME records */
3060 		DontExpandCnames = atobool(val);
3061 		break;
3062 
3063 	  case O_MUSTQUOTE:	/* must quote these characters in phrases */
3064 		(void) sm_strlcpy(buf, "@,;:\\()[]", sizeof buf);
3065 		if (strlen(val) < sizeof buf - 10)
3066 			(void) sm_strlcat(buf, val, sizeof buf);
3067 		else
3068 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3069 					     "Warning: MustQuoteChars too long, ignored.\n");
3070 		MustQuoteChars = newstr(buf);
3071 		break;
3072 
3073 	  case O_SMTPGREETING:	/* SMTP greeting message (old $e macro) */
3074 		SmtpGreeting = newstr(munchstring(val, NULL, '\0'));
3075 		break;
3076 
3077 	  case O_UNIXFROM:	/* UNIX From_ line (old $l macro) */
3078 		UnixFromLine = newstr(munchstring(val, NULL, '\0'));
3079 		break;
3080 
3081 	  case O_OPCHARS:	/* operator characters (old $o macro) */
3082 		if (OperatorChars != NULL)
3083 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3084 					     "Warning: OperatorChars is being redefined.\n         It should only be set before ruleset definitions.\n");
3085 		OperatorChars = newstr(munchstring(val, NULL, '\0'));
3086 		break;
3087 
3088 	  case O_DONTINITGRPS:	/* don't call initgroups(3) */
3089 		DontInitGroups = atobool(val);
3090 		break;
3091 
3092 	  case O_SLFH:		/* make sure from fits on one line */
3093 		SingleLineFromHeader = atobool(val);
3094 		break;
3095 
3096 	  case O_ABH:		/* allow HELO commands with syntax errors */
3097 		AllowBogusHELO = atobool(val);
3098 		break;
3099 
3100 	  case O_CONNTHROT:	/* connection rate throttle */
3101 		ConnRateThrottle = atoi(val);
3102 		break;
3103 
3104 	  case O_UGW:		/* group writable files are unsafe */
3105 		if (!atobool(val))
3106 		{
3107 			setbitn(DBS_GROUPWRITABLEFORWARDFILESAFE,
3108 				DontBlameSendmail);
3109 			setbitn(DBS_GROUPWRITABLEINCLUDEFILESAFE,
3110 				DontBlameSendmail);
3111 		}
3112 		break;
3113 
3114 	  case O_DBLBOUNCE:	/* address to which to send double bounces */
3115 		DoubleBounceAddr = newstr(val);
3116 		break;
3117 
3118 	  case O_HSDIR:		/* persistent host status directory */
3119 		if (val[0] != '\0')
3120 		{
3121 			CANONIFY(val);
3122 			HostStatDir = newstr(val);
3123 		}
3124 		break;
3125 
3126 	  case O_SINGTHREAD:	/* single thread deliveries (requires hsdir) */
3127 		SingleThreadDelivery = atobool(val);
3128 		break;
3129 
3130 	  case O_RUNASUSER:	/* run bulk of code as this user */
3131 		for (p = val; *p != '\0'; p++)
3132 		{
3133 # if _FFR_DOTTED_USERNAMES
3134 			if (*p == '/' || *p == ':')
3135 # else /* _FFR_DOTTED_USERNAMES */
3136 			if (*p == '.' || *p == '/' || *p == ':')
3137 # endif /* _FFR_DOTTED_USERNAMES */
3138 			{
3139 				*p++ = '\0';
3140 				break;
3141 			}
3142 		}
3143 		if (isascii(*val) && isdigit(*val))
3144 		{
3145 			if (can_setuid)
3146 				RunAsUid = atoi(val);
3147 		}
3148 		else
3149 		{
3150 			register struct passwd *pw;
3151 
3152 			pw = sm_getpwnam(val);
3153 			if (pw == NULL)
3154 			{
3155 				syserr("readcf: option RunAsUser: unknown user %s", val);
3156 				break;
3157 			}
3158 			else if (can_setuid)
3159 			{
3160 				if (*p == '\0')
3161 					RunAsUserName = newstr(val);
3162 				RunAsUid = pw->pw_uid;
3163 				RunAsGid = pw->pw_gid;
3164 			}
3165 			else if (EffGid == pw->pw_gid)
3166 				RunAsGid = pw->pw_gid;
3167 			else if (UseMSP && *p == '\0')
3168 				(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3169 						     "WARNING: RunAsUser for MSP ignored, check group ids (egid=%d, want=%d)\n",
3170 						     (int) EffGid,
3171 						     (int) pw->pw_gid);
3172 		}
3173 # ifdef UID_MAX
3174 		if (RunAsUid > UID_MAX)
3175 		{
3176 			syserr("readcf: option RunAsUser: uid value (%ld) > UID_MAX (%ld); ignored",
3177 				(long) RunAsUid, (long) UID_MAX);
3178 			break;
3179 		}
3180 # endif /* UID_MAX */
3181 		if (*p != '\0')
3182 		{
3183 			if (isascii(*p) && isdigit(*p))
3184 			{
3185 				gid_t runasgid;
3186 
3187 				runasgid = (gid_t) atoi(p);
3188 				if (can_setuid || EffGid == runasgid)
3189 					RunAsGid = runasgid;
3190 				else if (UseMSP)
3191 					(void) sm_io_fprintf(smioout,
3192 							     SM_TIME_DEFAULT,
3193 							     "WARNING: RunAsUser for MSP ignored, check group ids (egid=%d, want=%d)\n",
3194 							     (int) EffGid,
3195 							     (int) runasgid);
3196 			}
3197 			else
3198 			{
3199 				register struct group *gr;
3200 
3201 				gr = getgrnam(p);
3202 				if (gr == NULL)
3203 					syserr("readcf: option RunAsUser: unknown group %s",
3204 						p);
3205 				else if (can_setuid || EffGid == gr->gr_gid)
3206 					RunAsGid = gr->gr_gid;
3207 				else if (UseMSP)
3208 					(void) sm_io_fprintf(smioout,
3209 							     SM_TIME_DEFAULT,
3210 							     "WARNING: RunAsUser for MSP ignored, check group ids (egid=%d, want=%d)\n",
3211 							     (int) EffGid,
3212 							     (int) gr->gr_gid);
3213 			}
3214 		}
3215 		if (tTd(47, 5))
3216 			sm_dprintf("readcf: RunAsUser = %d:%d\n",
3217 				   (int) RunAsUid, (int) RunAsGid);
3218 		break;
3219 
3220 	  case O_DSN_RRT:
3221 		RrtImpliesDsn = atobool(val);
3222 		break;
3223 
3224 	  case O_PIDFILE:
3225 		PSTRSET(PidFile, val);
3226 		break;
3227 
3228 	  case O_DONTBLAMESENDMAIL:
3229 		p = val;
3230 		for (;;)
3231 		{
3232 			register struct dbsval *dbs;
3233 			extern struct dbsval DontBlameSendmailValues[];
3234 
3235 			while (isascii(*p) && (isspace(*p) || ispunct(*p)))
3236 				p++;
3237 			if (*p == '\0')
3238 				break;
3239 			val = p;
3240 			while (isascii(*p) && isalnum(*p))
3241 				p++;
3242 			if (*p != '\0')
3243 				*p++ = '\0';
3244 
3245 			for (dbs = DontBlameSendmailValues;
3246 			     dbs->dbs_name != NULL; dbs++)
3247 			{
3248 				if (sm_strcasecmp(val, dbs->dbs_name) == 0)
3249 					break;
3250 			}
3251 			if (dbs->dbs_name == NULL)
3252 				syserr("readcf: DontBlameSendmail option: %s unrecognized", val);
3253 			else if (dbs->dbs_flag == DBS_SAFE)
3254 				clrbitmap(DontBlameSendmail);
3255 			else
3256 				setbitn(dbs->dbs_flag, DontBlameSendmail);
3257 		}
3258 		sticky = false;
3259 		break;
3260 
3261 	  case O_DPI:
3262 		if (sm_strcasecmp(val, "loopback") == 0)
3263 			DontProbeInterfaces = DPI_SKIPLOOPBACK;
3264 		else if (atobool(val))
3265 			DontProbeInterfaces = DPI_PROBENONE;
3266 		else
3267 			DontProbeInterfaces = DPI_PROBEALL;
3268 		break;
3269 
3270 	  case O_MAXRCPT:
3271 		MaxRcptPerMsg = atoi(val);
3272 		break;
3273 
3274 	  case O_RCPTTHROT:
3275 		BadRcptThrottle = atoi(val);
3276 		break;
3277 
3278 	  case O_DEADLETTER:
3279 		CANONIFY(val);
3280 		PSTRSET(DeadLetterDrop, val);
3281 		break;
3282 
3283 #if _FFR_DONTLOCKFILESFORREAD_OPTION
3284 	  case O_DONTLOCK:
3285 		DontLockReadFiles = atobool(val);
3286 		break;
3287 #endif /* _FFR_DONTLOCKFILESFORREAD_OPTION */
3288 
3289 	  case O_MAXALIASRCSN:
3290 		MaxAliasRecursion = atoi(val);
3291 		break;
3292 
3293 	  case O_CNCTONLYTO:
3294 		/* XXX should probably use gethostbyname */
3295 #if NETINET || NETINET6
3296 		ConnectOnlyTo.sa.sa_family = AF_UNSPEC;
3297 # if NETINET6
3298 		if (anynet_pton(AF_INET6, val,
3299 				&ConnectOnlyTo.sin6.sin6_addr) != 1)
3300 			ConnectOnlyTo.sa.sa_family = AF_INET6;
3301 		else
3302 # endif /* NETINET6 */
3303 # if NETINET
3304 		{
3305 			ConnectOnlyTo.sin.sin_addr.s_addr = inet_addr(val);
3306 			if (ConnectOnlyTo.sin.sin_addr.s_addr != INADDR_NONE)
3307 				ConnectOnlyTo.sa.sa_family = AF_INET;
3308 		}
3309 
3310 # endif /* NETINET */
3311 		if (ConnectOnlyTo.sa.sa_family == AF_UNSPEC)
3312 		{
3313 			syserr("readcf: option ConnectOnlyTo: invalid IP address %s",
3314 			       val);
3315 			break;
3316 		}
3317 #endif /* NETINET || NETINET6 */
3318 		break;
3319 
3320 	  case O_TRUSTUSER:
3321 # if !HASFCHOWN && !defined(_FFR_DROP_TRUSTUSER_WARNING)
3322 		if (!UseMSP)
3323 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3324 					     "readcf: option TrustedUser may cause problems on systems\n        which do not support fchown() if UseMSP is not set.\n");
3325 # endif /* !HASFCHOWN && !defined(_FFR_DROP_TRUSTUSER_WARNING) */
3326 		if (isascii(*val) && isdigit(*val))
3327 			TrustedUid = atoi(val);
3328 		else
3329 		{
3330 			register struct passwd *pw;
3331 
3332 			TrustedUid = 0;
3333 			pw = sm_getpwnam(val);
3334 			if (pw == NULL)
3335 			{
3336 				syserr("readcf: option TrustedUser: unknown user %s", val);
3337 				break;
3338 			}
3339 			else
3340 				TrustedUid = pw->pw_uid;
3341 		}
3342 
3343 # ifdef UID_MAX
3344 		if (TrustedUid > UID_MAX)
3345 		{
3346 			syserr("readcf: option TrustedUser: uid value (%ld) > UID_MAX (%ld)",
3347 				(long) TrustedUid, (long) UID_MAX);
3348 			TrustedUid = 0;
3349 		}
3350 # endif /* UID_MAX */
3351 		break;
3352 
3353 	  case O_MAXMIMEHDRLEN:
3354 		p = strchr(val, '/');
3355 		if (p != NULL)
3356 			*p++ = '\0';
3357 		MaxMimeHeaderLength = atoi(val);
3358 		if (p != NULL && *p != '\0')
3359 			MaxMimeFieldLength = atoi(p);
3360 		else
3361 			MaxMimeFieldLength = MaxMimeHeaderLength / 2;
3362 
3363 		if (MaxMimeHeaderLength <= 0)
3364 			MaxMimeHeaderLength = 0;
3365 		else if (MaxMimeHeaderLength < 128)
3366 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3367 					     "Warning: MaxMimeHeaderLength: header length limit set lower than 128\n");
3368 
3369 		if (MaxMimeFieldLength <= 0)
3370 			MaxMimeFieldLength = 0;
3371 		else if (MaxMimeFieldLength < 40)
3372 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3373 					     "Warning: MaxMimeHeaderLength: field length limit set lower than 40\n");
3374 		break;
3375 
3376 	  case O_CONTROLSOCKET:
3377 		PSTRSET(ControlSocketName, val);
3378 		break;
3379 
3380 	  case O_MAXHDRSLEN:
3381 		MaxHeadersLength = atoi(val);
3382 
3383 		if (MaxHeadersLength > 0 &&
3384 		    MaxHeadersLength < (MAXHDRSLEN / 2))
3385 			(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3386 					     "Warning: MaxHeadersLength: headers length limit set lower than %d\n",
3387 					     (MAXHDRSLEN / 2));
3388 		break;
3389 
3390 	  case O_PROCTITLEPREFIX:
3391 		PSTRSET(ProcTitlePrefix, val);
3392 		break;
3393 
3394 #if SASL
3395 	  case O_SASLINFO:
3396 # if _FFR_ALLOW_SASLINFO
3397 		/*
3398 		**  Allow users to select their own authinfo file
3399 		**  under certain circumstances, otherwise just ignore
3400 		**  the option.  If the option isn't ignored, several
3401 		**  commands don't work very well, e.g., mailq.
3402 		**  However, this is not a "perfect" solution.
3403 		**  If mail is queued, the authentication info
3404 		**  will not be used in subsequent delivery attempts.
3405 		**  If we really want to support this, then it has
3406 		**  to be stored in the queue file.
3407 		*/
3408 		if (!bitset(SUBMIT_MSA, SubmitMode) && RealUid != 0 &&
3409 		    RunAsUid != RealUid)
3410 			break;
3411 # endif /* _FFR_ALLOW_SASLINFO */
3412 		PSTRSET(SASLInfo, val);
3413 		break;
3414 
3415 	  case O_SASLMECH:
3416 		if (AuthMechanisms != NULL)
3417 			sm_free(AuthMechanisms); /* XXX */
3418 		if (*val != '\0')
3419 			AuthMechanisms = newstr(val);
3420 		else
3421 			AuthMechanisms = NULL;
3422 		break;
3423 
3424 	  case O_SASLREALM:
3425 		if (AuthRealm != NULL)
3426 			sm_free(AuthRealm);
3427 		if (*val != '\0')
3428 			AuthRealm = newstr(val);
3429 		else
3430 			AuthRealm = NULL;
3431 		break;
3432 
3433 	  case O_SASLOPTS:
3434 		while (val != NULL && *val != '\0')
3435 		{
3436 			switch (*val)
3437 			{
3438 			  case 'A':
3439 				SASLOpts |= SASL_AUTH_AUTH;
3440 				break;
3441 
3442 			  case 'a':
3443 				SASLOpts |= SASL_SEC_NOACTIVE;
3444 				break;
3445 
3446 			  case 'c':
3447 				SASLOpts |= SASL_SEC_PASS_CREDENTIALS;
3448 				break;
3449 
3450 			  case 'd':
3451 				SASLOpts |= SASL_SEC_NODICTIONARY;
3452 				break;
3453 
3454 			  case 'f':
3455 				SASLOpts |= SASL_SEC_FORWARD_SECRECY;
3456 				break;
3457 
3458 #  if SASL >= 20101
3459 			  case 'm':
3460 				SASLOpts |= SASL_SEC_MUTUAL_AUTH;
3461 				break;
3462 #  endif /* SASL >= 20101 */
3463 
3464 			  case 'p':
3465 				SASLOpts |= SASL_SEC_NOPLAINTEXT;
3466 				break;
3467 
3468 			  case 'y':
3469 				SASLOpts |= SASL_SEC_NOANONYMOUS;
3470 				break;
3471 
3472 			  case ' ':	/* ignore */
3473 			  case '\t':	/* ignore */
3474 			  case ',':	/* ignore */
3475 				break;
3476 
3477 			  default:
3478 				(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3479 						     "Warning: Option: %s unknown parameter '%c'\n",
3480 						     OPTNAME,
3481 						     (isascii(*val) &&
3482 							isprint(*val))
3483 							? *val : '?');
3484 				break;
3485 			}
3486 			++val;
3487 			val = strpbrk(val, ", \t");
3488 			if (val != NULL)
3489 				++val;
3490 		}
3491 		break;
3492 
3493 	  case O_SASLBITS:
3494 		MaxSLBits = atoi(val);
3495 		break;
3496 
3497 #else /* SASL */
3498 	  case O_SASLINFO:
3499 	  case O_SASLMECH:
3500 	  case O_SASLREALM:
3501 	  case O_SASLOPTS:
3502 	  case O_SASLBITS:
3503 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3504 				     "Warning: Option: %s requires SASL support (-DSASL)\n",
3505 				     OPTNAME);
3506 		break;
3507 #endif /* SASL */
3508 
3509 #if STARTTLS
3510 	  case O_SRVCERTFILE:
3511 		SET_STRING_EXP(SrvCertFile);
3512 	  case O_SRVKEYFILE:
3513 		SET_STRING_EXP(SrvKeyFile);
3514 	  case O_CLTCERTFILE:
3515 		SET_STRING_EXP(CltCertFile);
3516 	  case O_CLTKEYFILE:
3517 		SET_STRING_EXP(CltKeyFile);
3518 	  case O_CACERTFILE:
3519 		SET_STRING_EXP(CACertFile);
3520 	  case O_CACERTPATH:
3521 		SET_STRING_EXP(CACertPath);
3522 	  case O_DHPARAMS:
3523 		SET_STRING_EXP(DHParams);
3524 # if _FFR_TLS_1
3525 	  case O_DHPARAMS5:
3526 		SET_STRING_EXP(DHParams5);
3527 	  case O_CIPHERLIST:
3528 		SET_STRING_EXP(CipherList);
3529 # endif /* _FFR_TLS_1 */
3530 	  case O_CRLFILE:
3531 # if OPENSSL_VERSION_NUMBER > 0x00907000L
3532 		SET_STRING_EXP(CRLFile);
3533 # else /* OPENSSL_VERSION_NUMBER > 0x00907000L */
3534 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3535 				     "Warning: Option: %s requires at least OpenSSL 0.9.7\n",
3536 				     OPTNAME);
3537 		break;
3538 # endif /* OPENSSL_VERSION_NUMBER > 0x00907000L */
3539 
3540 # if _FFR_CRLPATH
3541 	  case O_CRLPATH:
3542 #  if OPENSSL_VERSION_NUMBER > 0x00907000L
3543 		SET_STRING_EXP(CRLPath);
3544 #  else /* OPENSSL_VERSION_NUMBER > 0x00907000L */
3545 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3546 				     "Warning: Option: %s requires at least OpenSSL 0.9.7\n",
3547 				     OPTNAME);
3548 		break;
3549 #  endif /* OPENSSL_VERSION_NUMBER > 0x00907000L */
3550 # endif /* _FFR_CRLPATH */
3551 
3552 	/*
3553 	**  XXX How about options per daemon/client instead of globally?
3554 	**  This doesn't work well for some options, e.g., no server cert,
3555 	**  but fine for others.
3556 	**
3557 	**  XXX Some people may want different certs per server.
3558 	**
3559 	**  See also srvfeatures()
3560 	*/
3561 
3562 	  case O_TLS_SRV_OPTS:
3563 		while (val != NULL && *val != '\0')
3564 		{
3565 			switch (*val)
3566 			{
3567 			  case 'V':
3568 				TLS_Srv_Opts |= TLS_I_NO_VRFY;
3569 				break;
3570 # if _FFR_TLS_1
3571 			/*
3572 			**  Server without a cert? That works only if
3573 			**  AnonDH is enabled as cipher, which is not in the
3574 			**  default list. Hence the CipherList option must
3575 			**  be available. Moreover: which clients support this
3576 			**  besides sendmail with this setting?
3577 			*/
3578 
3579 			  case 'C':
3580 				TLS_Srv_Opts &= ~TLS_I_SRV_CERT;
3581 				break;
3582 # endif /* _FFR_TLS_1 */
3583 			  case ' ':	/* ignore */
3584 			  case '\t':	/* ignore */
3585 			  case ',':	/* ignore */
3586 				break;
3587 			  default:
3588 				(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3589 						     "Warning: Option: %s unknown parameter '%c'\n",
3590 						     OPTNAME,
3591 						     (isascii(*val) &&
3592 							isprint(*val))
3593 							? *val : '?');
3594 				break;
3595 			}
3596 			++val;
3597 			val = strpbrk(val, ", \t");
3598 			if (val != NULL)
3599 				++val;
3600 		}
3601 		break;
3602 
3603 	  case O_RANDFILE:
3604 		PSTRSET(RandFile, val);
3605 		break;
3606 
3607 #else /* STARTTLS */
3608 	  case O_SRVCERTFILE:
3609 	  case O_SRVKEYFILE:
3610 	  case O_CLTCERTFILE:
3611 	  case O_CLTKEYFILE:
3612 	  case O_CACERTFILE:
3613 	  case O_CACERTPATH:
3614 	  case O_DHPARAMS:
3615 # if _FFR_TLS_1
3616 	  case O_DHPARAMS5:
3617 	  case O_CIPHERLIST:
3618 # endif /* _FFR_TLS_1 */
3619 	  case O_CRLFILE:
3620 # if _FFR_CRLPATH
3621 	  case O_CRLPATH:
3622 # endif /* _FFR_CRLPATH */
3623 	  case O_RANDFILE:
3624 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3625 				     "Warning: Option: %s requires TLS support\n",
3626 				     OPTNAME);
3627 		break;
3628 
3629 #endif /* STARTTLS */
3630 
3631 	  case O_CLIENTPORT:
3632 		setclientoptions(val);
3633 		break;
3634 
3635 	  case O_DF_BUFSIZE:
3636 		DataFileBufferSize = atoi(val);
3637 		break;
3638 
3639 	  case O_XF_BUFSIZE:
3640 		XscriptFileBufferSize = atoi(val);
3641 		break;
3642 
3643 	  case O_LDAPDEFAULTSPEC:
3644 #if LDAPMAP
3645 		ldapmap_set_defaults(val);
3646 #else /* LDAPMAP */
3647 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3648 				     "Warning: Option: %s requires LDAP support (-DLDAPMAP)\n",
3649 				     OPTNAME);
3650 #endif /* LDAPMAP */
3651 		break;
3652 
3653 	  case O_INPUTMILTER:
3654 #if MILTER
3655 		InputFilterList = newstr(val);
3656 #else /* MILTER */
3657 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3658 				     "Warning: Option: %s requires Milter support (-DMILTER)\n",
3659 				     OPTNAME);
3660 #endif /* MILTER */
3661 		break;
3662 
3663 	  case O_MILTER:
3664 #if MILTER
3665 		milter_set_option(subopt, val, sticky);
3666 #else /* MILTER */
3667 		(void) sm_io_fprintf(smioout, SM_TIME_DEFAULT,
3668 				     "Warning: Option: %s requires Milter support (-DMILTER)\n",
3669 				     OPTNAME);
3670 #endif /* MILTER */
3671 		break;
3672 
3673 	  case O_QUEUE_FILE_MODE:	/* queue file mode */
3674 		QueueFileMode = atooct(val) & 0777;
3675 		break;
3676 
3677 	  case O_DLVR_MIN:	/* deliver by minimum time */
3678 		DeliverByMin = convtime(val, 's');
3679 		break;
3680 
3681 	  /* modifiers {daemon_flags} for direct submissions */
3682 	  case O_DIRECTSUBMODIFIERS:
3683 		{
3684 			BITMAP256 m;	/* ignored */
3685 			extern ENVELOPE BlankEnvelope;
3686 
3687 			macdefine(&BlankEnvelope.e_macro, A_PERM,
3688 				  macid("{daemon_flags}"),
3689 				  getmodifiers(val, m));
3690 		}
3691 		break;
3692 
3693 	  case O_FASTSPLIT:
3694 		FastSplit = atoi(val);
3695 		break;
3696 
3697 	  case O_MBDB:
3698 		Mbdb = newstr(val);
3699 		break;
3700 
3701 	  case O_MSQ:
3702 		UseMSP = atobool(val);
3703 		break;
3704 
3705 #if _FFR_SOFT_BOUNCE
3706 	  case O_SOFTBOUNCE:
3707 		SoftBounce = atobool(val);
3708 		break;
3709 #endif /* _FFR_SOFT_BOUNCE */
3710 
3711 	  case O_REJECTLOGINTERVAL:	/* time btwn log msgs while refusing */
3712 		RejectLogInterval = convtime(val, 'h');
3713 		break;
3714 
3715 	  case O_REQUIRES_DIR_FSYNC:
3716 #if REQUIRES_DIR_FSYNC
3717 		RequiresDirfsync = atobool(val);
3718 #else /* REQUIRES_DIR_FSYNC */
3719 		/* silently ignored... required for cf file option */
3720 #endif /* REQUIRES_DIR_FSYNC */
3721 		break;
3722 
3723 	  case O_CONNECTION_RATE_WINDOW_SIZE:
3724 		ConnectionRateWindowSize = convtime(val, 's');
3725 		break;
3726 
3727 	  case O_FALLBACKSMARTHOST:	/* fallback smart host */
3728 		if (val[0] != '\0')
3729 			FallbackSmartHost = newstr(val);
3730 		break;
3731 
3732 #if _FFR_HELONAME
3733 	  case O_HELONAME:
3734 		HeloName = newstr(val);
3735 		break;
3736 #endif /* _FFR_HELONAME */
3737 #if _FFR_MEMSTAT
3738 	  case O_REFUSELOWMEM:
3739 		RefuseLowMem = atoi(val);
3740 		break;
3741 	  case O_QUEUELOWMEM:
3742 		QueueLowMem = atoi(val);
3743 		break;
3744 	  case O_MEMRESOURCE:
3745 		MemoryResource = newstr(val);
3746 		break;
3747 #endif /* _FFR_MEMSTAT */
3748 
3749 #if _FFR_MAXNOOPCOMMANDS
3750 	  case O_MAXNOOPCOMMANDS:
3751 		MaxNOOPCommands = atoi(val);
3752 		break;
3753 #endif /* _FFR_MAXNOOPCOMMANDS */
3754 
3755 #if _FFR_MSG_ACCEPT
3756 	  case O_MSG_ACCEPT:
3757 		MessageAccept = newstr(val);
3758 		break;
3759 #endif /* _FFR_MSG_ACCEPT */
3760 
3761 #if _FFR_QUEUE_RUN_PARANOIA
3762 	  case O_CHK_Q_RUNNERS:
3763 		CheckQueueRunners = atoi(val);
3764 		break;
3765 #endif /* _FFR_QUEUE_RUN_PARANOIA */
3766 
3767 	  default:
3768 		if (tTd(37, 1))
3769 		{
3770 			if (isascii(opt) && isprint(opt))
3771 				sm_dprintf("Warning: option %c unknown\n", opt);
3772 			else
3773 				sm_dprintf("Warning: option 0x%x unknown\n", opt);
3774 		}
3775 		break;
3776 	}
3777 
3778 	/*
3779 	**  Options with suboptions are responsible for taking care
3780 	**  of sticky-ness (e.g., that a command line setting is kept
3781 	**  when reading in the sendmail.cf file).  This has to be done
3782 	**  when the suboptions are parsed since each suboption must be
3783 	**  sticky, not the root option.
3784 	*/
3785 
3786 	if (sticky && !bitset(OI_SUBOPT, o->o_flags))
3787 		setbitn(opt, StickyOpt);
3788 }
3789 /*
3790 **  SETCLASS -- set a string into a class
3791 **
3792 **	Parameters:
3793 **		class -- the class to put the string in.
3794 **		str -- the string to enter
3795 **
3796 **	Returns:
3797 **		none.
3798 **
3799 **	Side Effects:
3800 **		puts the word into the symbol table.
3801 */
3802 
3803 void
3804 setclass(class, str)
3805 	int class;
3806 	char *str;
3807 {
3808 	register STAB *s;
3809 
3810 	if ((*str & 0377) == MATCHCLASS)
3811 	{
3812 		int mid;
3813 
3814 		str++;
3815 		mid = macid(str);
3816 		if (mid == 0)
3817 			return;
3818 
3819 		if (tTd(37, 8))
3820 			sm_dprintf("setclass(%s, $=%s)\n",
3821 				   macname(class), macname(mid));
3822 		copy_class(mid, class);
3823 	}
3824 	else
3825 	{
3826 		if (tTd(37, 8))
3827 			sm_dprintf("setclass(%s, %s)\n", macname(class), str);
3828 
3829 		s = stab(str, ST_CLASS, ST_ENTER);
3830 		setbitn(bitidx(class), s->s_class);
3831 	}
3832 }
3833 /*
3834 **  MAKEMAPENTRY -- create a map entry
3835 **
3836 **	Parameters:
3837 **		line -- the config file line
3838 **
3839 **	Returns:
3840 **		A pointer to the map that has been created.
3841 **		NULL if there was a syntax error.
3842 **
3843 **	Side Effects:
3844 **		Enters the map into the dictionary.
3845 */
3846 
3847 MAP *
3848 makemapentry(line)
3849 	char *line;
3850 {
3851 	register char *p;
3852 	char *mapname;
3853 	char *classname;
3854 	register STAB *s;
3855 	STAB *class;
3856 
3857 	for (p = line; isascii(*p) && isspace(*p); p++)
3858 		continue;
3859 	if (!(isascii(*p) && isalnum(*p)))
3860 	{
3861 		syserr("readcf: config K line: no map name");
3862 		return NULL;
3863 	}
3864 
3865 	mapname = p;
3866 	while ((isascii(*++p) && isalnum(*p)) || *p == '_' || *p == '.')
3867 		continue;
3868 	if (*p != '\0')
3869 		*p++ = '\0';
3870 	while (isascii(*p) && isspace(*p))
3871 		p++;
3872 	if (!(isascii(*p) && isalnum(*p)))
3873 	{
3874 		syserr("readcf: config K line, map %s: no map class", mapname);
3875 		return NULL;
3876 	}
3877 	classname = p;
3878 	while (isascii(*++p) && isalnum(*p))
3879 		continue;
3880 	if (*p != '\0')
3881 		*p++ = '\0';
3882 	while (isascii(*p) && isspace(*p))
3883 		p++;
3884 
3885 	/* look up the class */
3886 	class = stab(classname, ST_MAPCLASS, ST_FIND);
3887 	if (class == NULL)
3888 	{
3889 		syserr("readcf: map %s: class %s not available", mapname,
3890 			classname);
3891 		return NULL;
3892 	}
3893 
3894 	/* enter the map */
3895 	s = stab(mapname, ST_MAP, ST_ENTER);
3896 	s->s_map.map_class = &class->s_mapclass;
3897 	s->s_map.map_mname = newstr(mapname);
3898 
3899 	if (class->s_mapclass.map_parse(&s->s_map, p))
3900 		s->s_map.map_mflags |= MF_VALID;
3901 
3902 	if (tTd(37, 5))
3903 	{
3904 		sm_dprintf("map %s, class %s, flags %lx, file %s,\n",
3905 			   s->s_map.map_mname, s->s_map.map_class->map_cname,
3906 			   s->s_map.map_mflags, s->s_map.map_file);
3907 		sm_dprintf("\tapp %s, domain %s, rebuild %s\n",
3908 			   s->s_map.map_app, s->s_map.map_domain,
3909 			   s->s_map.map_rebuild);
3910 	}
3911 	return &s->s_map;
3912 }
3913 /*
3914 **  STRTORWSET -- convert string to rewriting set number
3915 **
3916 **	Parameters:
3917 **		p -- the pointer to the string to decode.
3918 **		endp -- if set, store the trailing delimiter here.
3919 **		stabmode -- ST_ENTER to create this entry, ST_FIND if
3920 **			it must already exist.
3921 **
3922 **	Returns:
3923 **		The appropriate ruleset number.
3924 **		-1 if it is not valid (error already printed)
3925 */
3926 
3927 int
3928 strtorwset(p, endp, stabmode)
3929 	char *p;
3930 	char **endp;
3931 	int stabmode;
3932 {
3933 	int ruleset;
3934 	static int nextruleset = MAXRWSETS;
3935 
3936 	while (isascii(*p) && isspace(*p))
3937 		p++;
3938 	if (!isascii(*p))
3939 	{
3940 		syserr("invalid ruleset name: \"%.20s\"", p);
3941 		return -1;
3942 	}
3943 	if (isdigit(*p))
3944 	{
3945 		ruleset = strtol(p, endp, 10);
3946 		if (ruleset >= MAXRWSETS / 2 || ruleset < 0)
3947 		{
3948 			syserr("bad ruleset %d (%d max)",
3949 				ruleset, MAXRWSETS / 2);
3950 			ruleset = -1;
3951 		}
3952 	}
3953 	else
3954 	{
3955 		STAB *s;
3956 		char delim;
3957 		char *q = NULL;
3958 
3959 		q = p;
3960 		while (*p != '\0' && isascii(*p) &&
3961 		       (isalnum(*p) || *p == '_'))
3962 			p++;
3963 		if (q == p || !(isascii(*q) && isalpha(*q)))
3964 		{
3965 			/* no valid characters */
3966 			syserr("invalid ruleset name: \"%.20s\"", q);
3967 			return -1;
3968 		}
3969 		while (isascii(*p) && isspace(*p))
3970 			*p++ = '\0';
3971 		delim = *p;
3972 		if (delim != '\0')
3973 			*p = '\0';
3974 		s = stab(q, ST_RULESET, stabmode);
3975 		if (delim != '\0')
3976 			*p = delim;
3977 
3978 		if (s == NULL)
3979 			return -1;
3980 
3981 		if (stabmode == ST_ENTER && delim == '=')
3982 		{
3983 			while (isascii(*++p) && isspace(*p))
3984 				continue;
3985 			if (!(isascii(*p) && isdigit(*p)))
3986 			{
3987 				syserr("bad ruleset definition \"%s\" (number required after `=')", q);
3988 				ruleset = -1;
3989 			}
3990 			else
3991 			{
3992 				ruleset = strtol(p, endp, 10);
3993 				if (ruleset >= MAXRWSETS / 2 || ruleset < 0)
3994 				{
3995 					syserr("bad ruleset number %d in \"%s\" (%d max)",
3996 						ruleset, q, MAXRWSETS / 2);
3997 					ruleset = -1;
3998 				}
3999 			}
4000 		}
4001 		else
4002 		{
4003 			if (endp != NULL)
4004 				*endp = p;
4005 			if (s->s_ruleset >= 0)
4006 				ruleset = s->s_ruleset;
4007 			else if ((ruleset = --nextruleset) < MAXRWSETS / 2)
4008 			{
4009 				syserr("%s: too many named rulesets (%d max)",
4010 					q, MAXRWSETS / 2);
4011 				ruleset = -1;
4012 			}
4013 		}
4014 		if (s->s_ruleset >= 0 &&
4015 		    ruleset >= 0 &&
4016 		    ruleset != s->s_ruleset)
4017 		{
4018 			syserr("%s: ruleset changed value (old %d, new %d)",
4019 				q, s->s_ruleset, ruleset);
4020 			ruleset = s->s_ruleset;
4021 		}
4022 		else if (ruleset >= 0)
4023 		{
4024 			s->s_ruleset = ruleset;
4025 		}
4026 		if (stabmode == ST_ENTER && ruleset >= 0)
4027 		{
4028 			char *h = NULL;
4029 
4030 			if (RuleSetNames[ruleset] != NULL)
4031 				sm_free(RuleSetNames[ruleset]); /* XXX */
4032 			if (delim != '\0' && (h = strchr(q, delim)) != NULL)
4033 				*h = '\0';
4034 			RuleSetNames[ruleset] = newstr(q);
4035 			if (delim == '/' && h != NULL)
4036 				*h = delim;	/* put back delim */
4037 		}
4038 	}
4039 	return ruleset;
4040 }
4041 /*
4042 **  SETTIMEOUT -- set an individual timeout
4043 **
4044 **	Parameters:
4045 **		name -- the name of the timeout.
4046 **		val -- the value of the timeout.
4047 **		sticky -- if set, don't let other setoptions override
4048 **			this value.
4049 **
4050 **	Returns:
4051 **		none.
4052 */
4053 
4054 /* set if Timeout sub-option is stuck */
4055 static BITMAP256	StickyTimeoutOpt;
4056 
4057 static struct timeoutinfo
4058 {
4059 	char		*to_name;	/* long name of timeout */
4060 	unsigned char	to_code;	/* code for option */
4061 } TimeOutTab[] =
4062 {
4063 #define TO_INITIAL			0x01
4064 	{ "initial",			TO_INITIAL			},
4065 #define TO_MAIL				0x02
4066 	{ "mail",			TO_MAIL				},
4067 #define TO_RCPT				0x03
4068 	{ "rcpt",			TO_RCPT				},
4069 #define TO_DATAINIT			0x04
4070 	{ "datainit",			TO_DATAINIT			},
4071 #define TO_DATABLOCK			0x05
4072 	{ "datablock",			TO_DATABLOCK			},
4073 #define TO_DATAFINAL			0x06
4074 	{ "datafinal",			TO_DATAFINAL			},
4075 #define TO_COMMAND			0x07
4076 	{ "command",			TO_COMMAND			},
4077 #define TO_RSET				0x08
4078 	{ "rset",			TO_RSET				},
4079 #define TO_HELO				0x09
4080 	{ "helo",			TO_HELO				},
4081 #define TO_QUIT				0x0A
4082 	{ "quit",			TO_QUIT				},
4083 #define TO_MISC				0x0B
4084 	{ "misc",			TO_MISC				},
4085 #define TO_IDENT			0x0C
4086 	{ "ident",			TO_IDENT			},
4087 #define TO_FILEOPEN			0x0D
4088 	{ "fileopen",			TO_FILEOPEN			},
4089 #define TO_CONNECT			0x0E
4090 	{ "connect",			TO_CONNECT			},
4091 #define TO_ICONNECT			0x0F
4092 	{ "iconnect",			TO_ICONNECT			},
4093 #define TO_QUEUEWARN			0x10
4094 	{ "queuewarn",			TO_QUEUEWARN			},
4095 	{ "queuewarn.*",		TO_QUEUEWARN			},
4096 #define TO_QUEUEWARN_NORMAL		0x11
4097 	{ "queuewarn.normal",		TO_QUEUEWARN_NORMAL		},
4098 #define TO_QUEUEWARN_URGENT		0x12
4099 	{ "queuewarn.urgent",		TO_QUEUEWARN_URGENT		},
4100 #define TO_QUEUEWARN_NON_URGENT		0x13
4101 	{ "queuewarn.non-urgent",	TO_QUEUEWARN_NON_URGENT		},
4102 #define TO_QUEUERETURN			0x14
4103 	{ "queuereturn",		TO_QUEUERETURN			},
4104 	{ "queuereturn.*",		TO_QUEUERETURN			},
4105 #define TO_QUEUERETURN_NORMAL		0x15
4106 	{ "queuereturn.normal",		TO_QUEUERETURN_NORMAL		},
4107 #define TO_QUEUERETURN_URGENT		0x16
4108 	{ "queuereturn.urgent",		TO_QUEUERETURN_URGENT		},
4109 #define TO_QUEUERETURN_NON_URGENT	0x17
4110 	{ "queuereturn.non-urgent",	TO_QUEUERETURN_NON_URGENT	},
4111 #define TO_HOSTSTATUS			0x18
4112 	{ "hoststatus",			TO_HOSTSTATUS			},
4113 #define TO_RESOLVER_RETRANS		0x19
4114 	{ "resolver.retrans",		TO_RESOLVER_RETRANS		},
4115 #define TO_RESOLVER_RETRANS_NORMAL	0x1A
4116 	{ "resolver.retrans.normal",	TO_RESOLVER_RETRANS_NORMAL	},
4117 #define TO_RESOLVER_RETRANS_FIRST	0x1B
4118 	{ "resolver.retrans.first",	TO_RESOLVER_RETRANS_FIRST	},
4119 #define TO_RESOLVER_RETRY		0x1C
4120 	{ "resolver.retry",		TO_RESOLVER_RETRY		},
4121 #define TO_RESOLVER_RETRY_NORMAL	0x1D
4122 	{ "resolver.retry.normal",	TO_RESOLVER_RETRY_NORMAL	},
4123 #define TO_RESOLVER_RETRY_FIRST		0x1E
4124 	{ "resolver.retry.first",	TO_RESOLVER_RETRY_FIRST		},
4125 #define TO_CONTROL			0x1F
4126 	{ "control",			TO_CONTROL			},
4127 #define TO_LHLO				0x20
4128 	{ "lhlo",			TO_LHLO				},
4129 #define TO_AUTH				0x21
4130 	{ "auth",			TO_AUTH				},
4131 #define TO_STARTTLS			0x22
4132 	{ "starttls",			TO_STARTTLS			},
4133 #define TO_ACONNECT			0x23
4134 	{ "aconnect",			TO_ACONNECT			},
4135 #define TO_QUEUEWARN_DSN		0x24
4136 	{ "queuewarn.dsn",		TO_QUEUEWARN_DSN		},
4137 #define TO_QUEUERETURN_DSN		0x25
4138 	{ "queuereturn.dsn",		TO_QUEUERETURN_DSN		},
4139 	{ NULL,				0				},
4140 };
4141 
4142 
4143 static void
4144 settimeout(name, val, sticky)
4145 	char *name;
4146 	char *val;
4147 	bool sticky;
4148 {
4149 	register struct timeoutinfo *to;
4150 	int i, addopts;
4151 	time_t toval;
4152 
4153 	if (tTd(37, 2))
4154 		sm_dprintf("settimeout(%s = %s)", name, val);
4155 
4156 	for (to = TimeOutTab; to->to_name != NULL; to++)
4157 	{
4158 		if (sm_strcasecmp(to->to_name, name) == 0)
4159 			break;
4160 	}
4161 
4162 	if (to->to_name == NULL)
4163 	{
4164 		errno = 0; /* avoid bogus error text */
4165 		syserr("settimeout: invalid timeout %s", name);
4166 		return;
4167 	}
4168 
4169 	/*
4170 	**  See if this option is preset for us.
4171 	*/
4172 
4173 	if (!sticky && bitnset(to->to_code, StickyTimeoutOpt))
4174 	{
4175 		if (tTd(37, 2))
4176 			sm_dprintf(" (ignored)\n");
4177 		return;
4178 	}
4179 
4180 	if (tTd(37, 2))
4181 		sm_dprintf("\n");
4182 
4183 	toval = convtime(val, 'm');
4184 	addopts = 0;
4185 
4186 	switch (to->to_code)
4187 	{
4188 	  case TO_INITIAL:
4189 		TimeOuts.to_initial = toval;
4190 		break;
4191 
4192 	  case TO_MAIL:
4193 		TimeOuts.to_mail = toval;
4194 		break;
4195 
4196 	  case TO_RCPT:
4197 		TimeOuts.to_rcpt = toval;
4198 		break;
4199 
4200 	  case TO_DATAINIT:
4201 		TimeOuts.to_datainit = toval;
4202 		break;
4203 
4204 	  case TO_DATABLOCK:
4205 		TimeOuts.to_datablock = toval;
4206 		break;
4207 
4208 	  case TO_DATAFINAL:
4209 		TimeOuts.to_datafinal = toval;
4210 		break;
4211 
4212 	  case TO_COMMAND:
4213 		TimeOuts.to_nextcommand = toval;
4214 		break;
4215 
4216 	  case TO_RSET:
4217 		TimeOuts.to_rset = toval;
4218 		break;
4219 
4220 	  case TO_HELO:
4221 		TimeOuts.to_helo = toval;
4222 		break;
4223 
4224 	  case TO_QUIT:
4225 		TimeOuts.to_quit = toval;
4226 		break;
4227 
4228 	  case TO_MISC:
4229 		TimeOuts.to_miscshort = toval;
4230 		break;
4231 
4232 	  case TO_IDENT:
4233 		TimeOuts.to_ident = toval;
4234 		break;
4235 
4236 	  case TO_FILEOPEN:
4237 		TimeOuts.to_fileopen = toval;
4238 		break;
4239 
4240 	  case TO_CONNECT:
4241 		TimeOuts.to_connect = toval;
4242 		break;
4243 
4244 	  case TO_ICONNECT:
4245 		TimeOuts.to_iconnect = toval;
4246 		break;
4247 
4248 	  case TO_ACONNECT:
4249 		TimeOuts.to_aconnect = toval;
4250 		break;
4251 
4252 	  case TO_QUEUEWARN:
4253 		toval = convtime(val, 'h');
4254 		TimeOuts.to_q_warning[TOC_NORMAL] = toval;
4255 		TimeOuts.to_q_warning[TOC_URGENT] = toval;
4256 		TimeOuts.to_q_warning[TOC_NONURGENT] = toval;
4257 		TimeOuts.to_q_warning[TOC_DSN] = toval;
4258 		addopts = 2;
4259 		break;
4260 
4261 	  case TO_QUEUEWARN_NORMAL:
4262 		toval = convtime(val, 'h');
4263 		TimeOuts.to_q_warning[TOC_NORMAL] = toval;
4264 		break;
4265 
4266 	  case TO_QUEUEWARN_URGENT:
4267 		toval = convtime(val, 'h');
4268 		TimeOuts.to_q_warning[TOC_URGENT] = toval;
4269 		break;
4270 
4271 	  case TO_QUEUEWARN_NON_URGENT:
4272 		toval = convtime(val, 'h');
4273 		TimeOuts.to_q_warning[TOC_NONURGENT] = toval;
4274 		break;
4275 
4276 	  case TO_QUEUEWARN_DSN:
4277 		toval = convtime(val, 'h');
4278 		TimeOuts.to_q_warning[TOC_DSN] = toval;
4279 		break;
4280 
4281 	  case TO_QUEUERETURN:
4282 		toval = convtime(val, 'd');
4283 		TimeOuts.to_q_return[TOC_NORMAL] = toval;
4284 		TimeOuts.to_q_return[TOC_URGENT] = toval;
4285 		TimeOuts.to_q_return[TOC_NONURGENT] = toval;
4286 		TimeOuts.to_q_return[TOC_DSN] = toval;
4287 		addopts = 2;
4288 		break;
4289 
4290 	  case TO_QUEUERETURN_NORMAL:
4291 		toval = convtime(val, 'd');
4292 		TimeOuts.to_q_return[TOC_NORMAL] = toval;
4293 		break;
4294 
4295 	  case TO_QUEUERETURN_URGENT:
4296 		toval = convtime(val, 'd');
4297 		TimeOuts.to_q_return[TOC_URGENT] = toval;
4298 		break;
4299 
4300 	  case TO_QUEUERETURN_NON_URGENT:
4301 		toval = convtime(val, 'd');
4302 		TimeOuts.to_q_return[TOC_NONURGENT] = toval;
4303 		break;
4304 
4305 	  case TO_QUEUERETURN_DSN:
4306 		toval = convtime(val, 'd');
4307 		TimeOuts.to_q_return[TOC_DSN] = toval;
4308 		break;
4309 
4310 	  case TO_HOSTSTATUS:
4311 		MciInfoTimeout = toval;
4312 		break;
4313 
4314 	  case TO_RESOLVER_RETRANS:
4315 		toval = convtime(val, 's');
4316 		TimeOuts.res_retrans[RES_TO_DEFAULT] = toval;
4317 		TimeOuts.res_retrans[RES_TO_FIRST] = toval;
4318 		TimeOuts.res_retrans[RES_TO_NORMAL] = toval;
4319 		addopts = 2;
4320 		break;
4321 
4322 	  case TO_RESOLVER_RETRY:
4323 		i = atoi(val);
4324 		TimeOuts.res_retry[RES_TO_DEFAULT] = i;
4325 		TimeOuts.res_retry[RES_TO_FIRST] = i;
4326 		TimeOuts.res_retry[RES_TO_NORMAL] = i;
4327 		addopts = 2;
4328 		break;
4329 
4330 	  case TO_RESOLVER_RETRANS_NORMAL:
4331 		TimeOuts.res_retrans[RES_TO_NORMAL] = convtime(val, 's');
4332 		break;
4333 
4334 	  case TO_RESOLVER_RETRY_NORMAL:
4335 		TimeOuts.res_retry[RES_TO_NORMAL] = atoi(val);
4336 		break;
4337 
4338 	  case TO_RESOLVER_RETRANS_FIRST:
4339 		TimeOuts.res_retrans[RES_TO_FIRST] = convtime(val, 's');
4340 		break;
4341 
4342 	  case TO_RESOLVER_RETRY_FIRST:
4343 		TimeOuts.res_retry[RES_TO_FIRST] = atoi(val);
4344 		break;
4345 
4346 	  case TO_CONTROL:
4347 		TimeOuts.to_control = toval;
4348 		break;
4349 
4350 	  case TO_LHLO:
4351 		TimeOuts.to_lhlo = toval;
4352 		break;
4353 
4354 #if SASL
4355 	  case TO_AUTH:
4356 		TimeOuts.to_auth = toval;
4357 		break;
4358 #endif /* SASL */
4359 
4360 #if STARTTLS
4361 	  case TO_STARTTLS:
4362 		TimeOuts.to_starttls = toval;
4363 		break;
4364 #endif /* STARTTLS */
4365 
4366 	  default:
4367 		syserr("settimeout: invalid timeout %s", name);
4368 		break;
4369 	}
4370 
4371 	if (sticky)
4372 	{
4373 		for (i = 0; i <= addopts; i++)
4374 			setbitn(to->to_code + i, StickyTimeoutOpt);
4375 	}
4376 }
4377 /*
4378 **  INITTIMEOUTS -- parse and set timeout values
4379 **
4380 **	Parameters:
4381 **		val -- a pointer to the values.  If NULL, do initial
4382 **			settings.
4383 **		sticky -- if set, don't let other setoptions override
4384 **			this suboption value.
4385 **
4386 **	Returns:
4387 **		none.
4388 **
4389 **	Side Effects:
4390 **		Initializes the TimeOuts structure
4391 */
4392 
4393 void
4394 inittimeouts(val, sticky)
4395 	register char *val;
4396 	bool sticky;
4397 {
4398 	register char *p;
4399 
4400 	if (tTd(37, 2))
4401 		sm_dprintf("inittimeouts(%s)\n", val == NULL ? "<NULL>" : val);
4402 	if (val == NULL)
4403 	{
4404 		TimeOuts.to_connect = (time_t) 0 SECONDS;
4405 		TimeOuts.to_aconnect = (time_t) 0 SECONDS;
4406 		TimeOuts.to_iconnect = (time_t) 0 SECONDS;
4407 		TimeOuts.to_initial = (time_t) 5 MINUTES;
4408 		TimeOuts.to_helo = (time_t) 5 MINUTES;
4409 		TimeOuts.to_mail = (time_t) 10 MINUTES;
4410 		TimeOuts.to_rcpt = (time_t) 1 HOUR;
4411 		TimeOuts.to_datainit = (time_t) 5 MINUTES;
4412 		TimeOuts.to_datablock = (time_t) 1 HOUR;
4413 		TimeOuts.to_datafinal = (time_t) 1 HOUR;
4414 		TimeOuts.to_rset = (time_t) 5 MINUTES;
4415 		TimeOuts.to_quit = (time_t) 2 MINUTES;
4416 		TimeOuts.to_nextcommand = (time_t) 1 HOUR;
4417 		TimeOuts.to_miscshort = (time_t) 2 MINUTES;
4418 #if IDENTPROTO
4419 		TimeOuts.to_ident = (time_t) 5 SECONDS;
4420 #else /* IDENTPROTO */
4421 		TimeOuts.to_ident = (time_t) 0 SECONDS;
4422 #endif /* IDENTPROTO */
4423 		TimeOuts.to_fileopen = (time_t) 60 SECONDS;
4424 		TimeOuts.to_control = (time_t) 2 MINUTES;
4425 		TimeOuts.to_lhlo = (time_t) 2 MINUTES;
4426 #if SASL
4427 		TimeOuts.to_auth = (time_t) 10 MINUTES;
4428 #endif /* SASL */
4429 #if STARTTLS
4430 		TimeOuts.to_starttls = (time_t) 1 HOUR;
4431 #endif /* STARTTLS */
4432 		if (tTd(37, 5))
4433 		{
4434 			sm_dprintf("Timeouts:\n");
4435 			sm_dprintf("  connect = %ld\n",
4436 				   (long) TimeOuts.to_connect);
4437 			sm_dprintf("  aconnect = %ld\n",
4438 				   (long) TimeOuts.to_aconnect);
4439 			sm_dprintf("  initial = %ld\n",
4440 				   (long) TimeOuts.to_initial);
4441 			sm_dprintf("  helo = %ld\n", (long) TimeOuts.to_helo);
4442 			sm_dprintf("  mail = %ld\n", (long) TimeOuts.to_mail);
4443 			sm_dprintf("  rcpt = %ld\n", (long) TimeOuts.to_rcpt);
4444 			sm_dprintf("  datainit = %ld\n",
4445 				   (long) TimeOuts.to_datainit);
4446 			sm_dprintf("  datablock = %ld\n",
4447 				   (long) TimeOuts.to_datablock);
4448 			sm_dprintf("  datafinal = %ld\n",
4449 				   (long) TimeOuts.to_datafinal);
4450 			sm_dprintf("  rset = %ld\n", (long) TimeOuts.to_rset);
4451 			sm_dprintf("  quit = %ld\n", (long) TimeOuts.to_quit);
4452 			sm_dprintf("  nextcommand = %ld\n",
4453 				   (long) TimeOuts.to_nextcommand);
4454 			sm_dprintf("  miscshort = %ld\n",
4455 				   (long) TimeOuts.to_miscshort);
4456 			sm_dprintf("  ident = %ld\n", (long) TimeOuts.to_ident);
4457 			sm_dprintf("  fileopen = %ld\n",
4458 				   (long) TimeOuts.to_fileopen);
4459 			sm_dprintf("  lhlo = %ld\n",
4460 				   (long) TimeOuts.to_lhlo);
4461 			sm_dprintf("  control = %ld\n",
4462 				   (long) TimeOuts.to_control);
4463 		}
4464 		return;
4465 	}
4466 
4467 	for (;; val = p)
4468 	{
4469 		while (isascii(*val) && isspace(*val))
4470 			val++;
4471 		if (*val == '\0')
4472 			break;
4473 		for (p = val; *p != '\0' && *p != ','; p++)
4474 			continue;
4475 		if (*p != '\0')
4476 			*p++ = '\0';
4477 
4478 		if (isascii(*val) && isdigit(*val))
4479 		{
4480 			/* old syntax -- set everything */
4481 			TimeOuts.to_mail = convtime(val, 'm');
4482 			TimeOuts.to_rcpt = TimeOuts.to_mail;
4483 			TimeOuts.to_datainit = TimeOuts.to_mail;
4484 			TimeOuts.to_datablock = TimeOuts.to_mail;
4485 			TimeOuts.to_datafinal = TimeOuts.to_mail;
4486 			TimeOuts.to_nextcommand = TimeOuts.to_mail;
4487 			if (sticky)
4488 			{
4489 				setbitn(TO_MAIL, StickyTimeoutOpt);
4490 				setbitn(TO_RCPT, StickyTimeoutOpt);
4491 				setbitn(TO_DATAINIT, StickyTimeoutOpt);
4492 				setbitn(TO_DATABLOCK, StickyTimeoutOpt);
4493 				setbitn(TO_DATAFINAL, StickyTimeoutOpt);
4494 				setbitn(TO_COMMAND, StickyTimeoutOpt);
4495 			}
4496 			continue;
4497 		}
4498 		else
4499 		{
4500 			register char *q = strchr(val, ':');
4501 
4502 			if (q == NULL && (q = strchr(val, '=')) == NULL)
4503 			{
4504 				/* syntax error */
4505 				continue;
4506 			}
4507 			*q++ = '\0';
4508 			settimeout(val, q, sticky);
4509 		}
4510 	}
4511 }
4512