1 /*	$NetBSD: cleanup_init.c,v 1.3 2010/06/17 18:18:15 tron Exp $	*/
2 
3 /*++
4 /* NAME
5 /*	cleanup_init 3
6 /* SUMMARY
7 /*	cleanup callable interface, initializations
8 /* SYNOPSIS
9 /*	#include "cleanup.h"
10 /*
11 /*	CONFIG_BOOL_TABLE cleanup_bool_table[];
12 /*
13 /*	CONFIG_INT_TABLE cleanup_int_table[];
14 /*
15 /*	CONFIG_BOOL_TABLE cleanup_bool_table[];
16 /*
17 /*	CONFIG_STR_TABLE cleanup_str_table[];
18 /*
19 /*	CONFIG_TIME_TABLE cleanup_time_table[];
20 /*
21 /*	void	cleanup_pre_jail(service_name, argv)
22 /*	char	*service_name;
23 /*	char	**argv;
24 /*
25 /*	void	cleanup_post_jail(service_name, argv)
26 /*	char	*service_name;
27 /*	char	**argv;
28 /*
29 /*	char	*cleanup_path;
30 /*	VSTRING	*cleanup_trace_path;
31 /*
32 /*	void	cleanup_all()
33 /*
34 /*	void	cleanup_sig(sigval)
35 /*	int	sigval;
36 /* DESCRIPTION
37 /*	This module implements a callable interface to the cleanup service
38 /*	for one-time initializations that must be done before any message
39 /*	processing can take place.
40 /*
41 /*	cleanup_{bool,int,str,time}_table[] specify configuration
42 /*	parameters that must be initialized before calling any functions
43 /*	in this module. These tables satisfy the interface as specified in
44 /*	single_service(3).
45 /*
46 /*	cleanup_pre_jail() and cleanup_post_jail() perform mandatory
47 /*	initializations before and after the process enters the optional
48 /*	chroot jail. These functions satisfy the interface as specified
49 /*	in single_service(3).
50 /*
51 /*	cleanup_path is either a null pointer or it is the name of a queue
52 /*	file that currently is being written. This information is used
53 /*	by cleanup_all() to remove incomplete files after a fatal error,
54 /*	or by cleanup_sig() after arrival of a SIGTERM signal.
55 /*
56 /*	cleanup_trace_path is either a null pointer or the pathname of a
57 /*	trace logfile with DSN SUCCESS notifications. This information is
58 /*	used to remove a trace file when the mail transaction is canceled.
59 /*
60 /*	cleanup_all() must be called in case of fatal error, in order
61 /*	to remove an incomplete queue file.
62 /*
63 /*	cleanup_sig() must be called in case of SIGTERM, in order
64 /*	to remove an incomplete queue file.
65 /* DIAGNOSTICS
66 /*	Problems and transactions are logged to \fBsyslogd\fR(8).
67 /* SEE ALSO
68 /*	cleanup_api(3) cleanup callable interface, message processing
69 /* LICENSE
70 /* .ad
71 /* .fi
72 /*	The Secure Mailer license must be distributed with this software.
73 /* AUTHOR(S)
74 /*	Wietse Venema
75 /*	IBM T.J. Watson Research
76 /*	P.O. Box 704
77 /*	Yorktown Heights, NY 10598, USA
78 /*--*/
79 
80 /* System library. */
81 
82 #include <sys_defs.h>
83 #include <signal.h>
84 #include <string.h>
85 
86 /* Utility library. */
87 
88 #include <msg.h>
89 #include <iostuff.h>
90 #include <name_mask.h>
91 #include <stringops.h>
92 
93 /* Global library. */
94 
95 #include <mail_addr.h>
96 #include <mail_params.h>
97 #include <mail_version.h>		/* milter_macro_v */
98 #include <ext_prop.h>
99 #include <flush_clnt.h>
100 
101 /* Application-specific. */
102 
103 #include "cleanup.h"
104 
105  /*
106   * Global state: any queue files that we have open, so that the error
107   * handler can clean up in case of trouble.
108   */
109 char   *cleanup_path;			/* queue file name */
110 
111  /*
112   * Another piece of global state: pathnames of partial bounce or trace
113   * logfiles that need to be cleaned up when the cleanup request is aborted.
114   */
115 VSTRING *cleanup_trace_path;
116 
117  /*
118   * Tunable parameters.
119   */
120 int     var_hopcount_limit;		/* max mailer hop count */
121 char   *var_canonical_maps;		/* common canonical maps */
122 char   *var_send_canon_maps;		/* sender canonical maps */
123 char   *var_rcpt_canon_maps;		/* recipient canonical maps */
124 char   *var_canon_classes;		/* what to canonicalize */
125 char   *var_send_canon_classes;		/* what sender to canonicalize */
126 char   *var_rcpt_canon_classes;		/* what recipient to canonicalize */
127 char   *var_virt_alias_maps;		/* virtual alias maps */
128 char   *var_masq_domains;		/* masquerade domains */
129 char   *var_masq_exceptions;		/* users not masqueraded */
130 char   *var_header_checks;		/* primary header checks */
131 char   *var_mimehdr_checks;		/* mime header checks */
132 char   *var_nesthdr_checks;		/* nested header checks */
133 char   *var_body_checks;		/* any body checks */
134 int     var_dup_filter_limit;		/* recipient dup filter */
135 bool    var_enable_orcpt;		/* Include orcpt in dup filter? */
136 char   *var_empty_addr;			/* destination of bounced bounces */
137 int     var_delay_warn_time;		/* delay that triggers warning */
138 char   *var_prop_extension;		/* propagate unmatched extension */
139 char   *var_always_bcc;			/* big brother */
140 char   *var_rcpt_witheld;		/* recipients not disclosed */
141 bool    var_canon_env_rcpt;		/* canonicalize envelope recipient */
142 char   *var_masq_classes;		/* what to masquerade */
143 int     var_qattr_count_limit;		/* named attribute limit */
144 int     var_virt_recur_limit;		/* maximum virtual alias recursion */
145 int     var_virt_expan_limit;		/* maximum virtual alias expansion */
146 int     var_body_check_len;		/* when to stop body scan */
147 char   *var_send_bcc_maps;		/* sender auto-bcc maps */
148 char   *var_rcpt_bcc_maps;		/* recipient auto-bcc maps */
149 char   *var_remote_rwr_domain;		/* header-only surrogate */
150 char   *var_msg_reject_chars;		/* reject these characters */
151 char   *var_msg_strip_chars;		/* strip these characters */
152 int     var_verp_bounce_off;		/* don't verp the bounces */
153 int     var_milt_conn_time;		/* milter connect/handshake timeout */
154 int     var_milt_cmd_time;		/* milter command timeout */
155 int     var_milt_msg_time;		/* milter content timeout */
156 char   *var_milt_protocol;		/* Sendmail 8 milter protocol */
157 char   *var_milt_def_action;		/* default milter action */
158 char   *var_milt_daemon_name;		/* {daemon_name} macro value */
159 char   *var_milt_v;			/* {v} macro value */
160 char   *var_milt_conn_macros;		/* connect macros */
161 char   *var_milt_helo_macros;		/* HELO macros */
162 char   *var_milt_mail_macros;		/* MAIL FROM macros */
163 char   *var_milt_rcpt_macros;		/* RCPT TO macros */
164 char   *var_milt_data_macros;		/* DATA macros */
165 char   *var_milt_eoh_macros;		/* end-of-header macros */
166 char   *var_milt_eod_macros;		/* end-of-data macros */
167 char   *var_milt_unk_macros;		/* unknown command macros */
168 char   *var_cleanup_milters;		/* non-SMTP mail */
169 char   *var_milt_head_checks;		/* post-Milter header checks */
170 int     var_auto_8bit_enc_hdr;		/* auto-detect 8bit encoding header */
171 int     var_always_add_hdrs;		/* always add missing headers */
172 
173 CONFIG_INT_TABLE cleanup_int_table[] = {
174     VAR_HOPCOUNT_LIMIT, DEF_HOPCOUNT_LIMIT, &var_hopcount_limit, 1, 0,
175     VAR_DUP_FILTER_LIMIT, DEF_DUP_FILTER_LIMIT, &var_dup_filter_limit, 0, 0,
176     VAR_QATTR_COUNT_LIMIT, DEF_QATTR_COUNT_LIMIT, &var_qattr_count_limit, 1, 0,
177     VAR_VIRT_RECUR_LIMIT, DEF_VIRT_RECUR_LIMIT, &var_virt_recur_limit, 1, 0,
178     VAR_VIRT_EXPAN_LIMIT, DEF_VIRT_EXPAN_LIMIT, &var_virt_expan_limit, 1, 0,
179     VAR_BODY_CHECK_LEN, DEF_BODY_CHECK_LEN, &var_body_check_len, 0, 0,
180     0,
181 };
182 
183 CONFIG_BOOL_TABLE cleanup_bool_table[] = {
184     VAR_ENABLE_ORCPT, DEF_ENABLE_ORCPT, &var_enable_orcpt,
185     VAR_VERP_BOUNCE_OFF, DEF_VERP_BOUNCE_OFF, &var_verp_bounce_off,
186     VAR_AUTO_8BIT_ENC_HDR, DEF_AUTO_8BIT_ENC_HDR, &var_auto_8bit_enc_hdr,
187     VAR_ALWAYS_ADD_HDRS, DEF_ALWAYS_ADD_HDRS, &var_always_add_hdrs,
188     0,
189 };
190 
191 CONFIG_TIME_TABLE cleanup_time_table[] = {
192     VAR_DELAY_WARN_TIME, DEF_DELAY_WARN_TIME, &var_delay_warn_time, 0, 0,
193     VAR_MILT_CONN_TIME, DEF_MILT_CONN_TIME, &var_milt_conn_time, 1, 0,
194     VAR_MILT_CMD_TIME, DEF_MILT_CMD_TIME, &var_milt_cmd_time, 1, 0,
195     VAR_MILT_MSG_TIME, DEF_MILT_MSG_TIME, &var_milt_msg_time, 1, 0,
196     0,
197 };
198 
199 CONFIG_STR_TABLE cleanup_str_table[] = {
200     VAR_CANONICAL_MAPS, DEF_CANONICAL_MAPS, &var_canonical_maps, 0, 0,
201     VAR_SEND_CANON_MAPS, DEF_SEND_CANON_MAPS, &var_send_canon_maps, 0, 0,
202     VAR_RCPT_CANON_MAPS, DEF_RCPT_CANON_MAPS, &var_rcpt_canon_maps, 0, 0,
203     VAR_CANON_CLASSES, DEF_CANON_CLASSES, &var_canon_classes, 1, 0,
204     VAR_SEND_CANON_CLASSES, DEF_SEND_CANON_CLASSES, &var_send_canon_classes, 1, 0,
205     VAR_RCPT_CANON_CLASSES, DEF_RCPT_CANON_CLASSES, &var_rcpt_canon_classes, 1, 0,
206     VAR_VIRT_ALIAS_MAPS, DEF_VIRT_ALIAS_MAPS, &var_virt_alias_maps, 0, 0,
207     VAR_MASQ_DOMAINS, DEF_MASQ_DOMAINS, &var_masq_domains, 0, 0,
208     VAR_EMPTY_ADDR, DEF_EMPTY_ADDR, &var_empty_addr, 1, 0,
209     VAR_MASQ_EXCEPTIONS, DEF_MASQ_EXCEPTIONS, &var_masq_exceptions, 0, 0,
210     VAR_HEADER_CHECKS, DEF_HEADER_CHECKS, &var_header_checks, 0, 0,
211     VAR_MIMEHDR_CHECKS, DEF_MIMEHDR_CHECKS, &var_mimehdr_checks, 0, 0,
212     VAR_NESTHDR_CHECKS, DEF_NESTHDR_CHECKS, &var_nesthdr_checks, 0, 0,
213     VAR_BODY_CHECKS, DEF_BODY_CHECKS, &var_body_checks, 0, 0,
214     VAR_PROP_EXTENSION, DEF_PROP_EXTENSION, &var_prop_extension, 0, 0,
215     VAR_ALWAYS_BCC, DEF_ALWAYS_BCC, &var_always_bcc, 0, 0,
216     VAR_RCPT_WITHELD, DEF_RCPT_WITHELD, &var_rcpt_witheld, 0, 0,
217     VAR_MASQ_CLASSES, DEF_MASQ_CLASSES, &var_masq_classes, 0, 0,
218     VAR_SEND_BCC_MAPS, DEF_SEND_BCC_MAPS, &var_send_bcc_maps, 0, 0,
219     VAR_RCPT_BCC_MAPS, DEF_RCPT_BCC_MAPS, &var_rcpt_bcc_maps, 0, 0,
220     VAR_REM_RWR_DOMAIN, DEF_REM_RWR_DOMAIN, &var_remote_rwr_domain, 0, 0,
221     VAR_MSG_REJECT_CHARS, DEF_MSG_REJECT_CHARS, &var_msg_reject_chars, 0, 0,
222     VAR_MSG_STRIP_CHARS, DEF_MSG_STRIP_CHARS, &var_msg_strip_chars, 0, 0,
223     VAR_MILT_PROTOCOL, DEF_MILT_PROTOCOL, &var_milt_protocol, 1, 0,
224     VAR_MILT_DEF_ACTION, DEF_MILT_DEF_ACTION, &var_milt_def_action, 1, 0,
225     VAR_MILT_DAEMON_NAME, DEF_MILT_DAEMON_NAME, &var_milt_daemon_name, 1, 0,
226     VAR_MILT_V, DEF_MILT_V, &var_milt_v, 1, 0,
227     VAR_MILT_CONN_MACROS, DEF_MILT_CONN_MACROS, &var_milt_conn_macros, 0, 0,
228     VAR_MILT_HELO_MACROS, DEF_MILT_HELO_MACROS, &var_milt_helo_macros, 0, 0,
229     VAR_MILT_MAIL_MACROS, DEF_MILT_MAIL_MACROS, &var_milt_mail_macros, 0, 0,
230     VAR_MILT_RCPT_MACROS, DEF_MILT_RCPT_MACROS, &var_milt_rcpt_macros, 0, 0,
231     VAR_MILT_DATA_MACROS, DEF_MILT_DATA_MACROS, &var_milt_data_macros, 0, 0,
232     VAR_MILT_EOH_MACROS, DEF_MILT_EOH_MACROS, &var_milt_eoh_macros, 0, 0,
233     VAR_MILT_EOD_MACROS, DEF_MILT_EOD_MACROS, &var_milt_eod_macros, 0, 0,
234     VAR_MILT_UNK_MACROS, DEF_MILT_UNK_MACROS, &var_milt_unk_macros, 0, 0,
235     VAR_CLEANUP_MILTERS, DEF_CLEANUP_MILTERS, &var_cleanup_milters, 0, 0,
236     VAR_MILT_HEAD_CHECKS, DEF_MILT_HEAD_CHECKS, &var_milt_head_checks, 0, 0,
237     0,
238 };
239 
240  /*
241   * Mappings.
242   */
243 MAPS   *cleanup_comm_canon_maps;
244 MAPS   *cleanup_send_canon_maps;
245 MAPS   *cleanup_rcpt_canon_maps;
246 int     cleanup_comm_canon_flags;
247 int     cleanup_send_canon_flags;
248 int     cleanup_rcpt_canon_flags;
249 MAPS   *cleanup_header_checks;
250 MAPS   *cleanup_mimehdr_checks;
251 MAPS   *cleanup_nesthdr_checks;
252 MAPS   *cleanup_body_checks;
253 MAPS   *cleanup_virt_alias_maps;
254 ARGV   *cleanup_masq_domains;
255 STRING_LIST *cleanup_masq_exceptions;
256 int     cleanup_masq_flags;
257 MAPS   *cleanup_send_bcc_maps;
258 MAPS   *cleanup_rcpt_bcc_maps;
259 
260  /*
261   * Character filters.
262   */
263 VSTRING *cleanup_reject_chars;
264 VSTRING *cleanup_strip_chars;
265 
266  /*
267   * Address extension propagation restrictions.
268   */
269 int     cleanup_ext_prop_mask;
270 
271  /*
272   * Milter support.
273   */
274 MILTERS *cleanup_milters;
275 
276 /* cleanup_all - callback for the runtime error handler */
277 
278 void    cleanup_all(void)
279 {
280     cleanup_sig(0);
281 }
282 
283 /* cleanup_sig - callback for the SIGTERM handler */
284 
285 void    cleanup_sig(int sig)
286 {
287 
288     /*
289      * msg_fatal() is safe against calling itself recursively, but signals
290      * need extra safety.
291      *
292      * XXX While running as a signal handler, can't ask the memory manager to
293      * release VSTRING storage.
294      */
295     if (signal(SIGTERM, SIG_IGN) != SIG_IGN) {
296 	if (cleanup_trace_path) {
297 	    (void) REMOVE(vstring_str(cleanup_trace_path));
298 	    cleanup_trace_path = 0;
299 	}
300 	if (cleanup_path) {
301 	    (void) REMOVE(cleanup_path);
302 	    cleanup_path = 0;
303 	}
304 	if (sig)
305 	    _exit(sig);
306     }
307 }
308 
309 /* cleanup_pre_jail - initialize before entering the chroot jail */
310 
311 void    cleanup_pre_jail(char *unused_name, char **unused_argv)
312 {
313     static const NAME_MASK send_canon_class_table[] = {
314 	CANON_CLASS_ENV_FROM, CLEANUP_CANON_FLAG_ENV_FROM,
315 	CANON_CLASS_HDR_FROM, CLEANUP_CANON_FLAG_HDR_FROM,
316 	0,
317     };
318     static const NAME_MASK rcpt_canon_class_table[] = {
319 	CANON_CLASS_ENV_RCPT, CLEANUP_CANON_FLAG_ENV_RCPT,
320 	CANON_CLASS_HDR_RCPT, CLEANUP_CANON_FLAG_HDR_RCPT,
321 	0,
322     };
323     static const NAME_MASK canon_class_table[] = {
324 	CANON_CLASS_ENV_FROM, CLEANUP_CANON_FLAG_ENV_FROM,
325 	CANON_CLASS_ENV_RCPT, CLEANUP_CANON_FLAG_ENV_RCPT,
326 	CANON_CLASS_HDR_FROM, CLEANUP_CANON_FLAG_HDR_FROM,
327 	CANON_CLASS_HDR_RCPT, CLEANUP_CANON_FLAG_HDR_RCPT,
328 	0,
329     };
330     static const NAME_MASK masq_class_table[] = {
331 	MASQ_CLASS_ENV_FROM, CLEANUP_MASQ_FLAG_ENV_FROM,
332 	MASQ_CLASS_ENV_RCPT, CLEANUP_MASQ_FLAG_ENV_RCPT,
333 	MASQ_CLASS_HDR_FROM, CLEANUP_MASQ_FLAG_HDR_FROM,
334 	MASQ_CLASS_HDR_RCPT, CLEANUP_MASQ_FLAG_HDR_RCPT,
335 	0,
336     };
337 
338     if (*var_canonical_maps)
339 	cleanup_comm_canon_maps =
340 	    maps_create(VAR_CANONICAL_MAPS, var_canonical_maps,
341 			DICT_FLAG_LOCK | DICT_FLAG_FOLD_FIX);
342     if (*var_send_canon_maps)
343 	cleanup_send_canon_maps =
344 	    maps_create(VAR_SEND_CANON_MAPS, var_send_canon_maps,
345 			DICT_FLAG_LOCK | DICT_FLAG_FOLD_FIX);
346     if (*var_rcpt_canon_maps)
347 	cleanup_rcpt_canon_maps =
348 	    maps_create(VAR_RCPT_CANON_MAPS, var_rcpt_canon_maps,
349 			DICT_FLAG_LOCK | DICT_FLAG_FOLD_FIX);
350     if (*var_virt_alias_maps)
351 	cleanup_virt_alias_maps = maps_create(VAR_VIRT_ALIAS_MAPS,
352 					      var_virt_alias_maps,
353 					      DICT_FLAG_LOCK
354 					      | DICT_FLAG_FOLD_FIX);
355     if (*var_canon_classes)
356 	cleanup_comm_canon_flags =
357 	    name_mask(VAR_CANON_CLASSES, canon_class_table,
358 		      var_canon_classes);
359     if (*var_send_canon_classes)
360 	cleanup_send_canon_flags =
361 	    name_mask(VAR_CANON_CLASSES, send_canon_class_table,
362 		      var_send_canon_classes);
363     if (*var_rcpt_canon_classes)
364 	cleanup_rcpt_canon_flags =
365 	    name_mask(VAR_CANON_CLASSES, rcpt_canon_class_table,
366 		      var_rcpt_canon_classes);
367     if (*var_masq_domains)
368 	cleanup_masq_domains = argv_split(var_masq_domains, " ,\t\r\n");
369     if (*var_header_checks)
370 	cleanup_header_checks =
371 	    maps_create(VAR_HEADER_CHECKS, var_header_checks, DICT_FLAG_LOCK);
372     if (*var_mimehdr_checks)
373 	cleanup_mimehdr_checks =
374 	    maps_create(VAR_MIMEHDR_CHECKS, var_mimehdr_checks, DICT_FLAG_LOCK);
375     if (*var_nesthdr_checks)
376 	cleanup_nesthdr_checks =
377 	    maps_create(VAR_NESTHDR_CHECKS, var_nesthdr_checks, DICT_FLAG_LOCK);
378     if (*var_body_checks)
379 	cleanup_body_checks =
380 	    maps_create(VAR_BODY_CHECKS, var_body_checks, DICT_FLAG_LOCK);
381     if (*var_masq_exceptions)
382 	cleanup_masq_exceptions =
383 	    string_list_init(MATCH_FLAG_NONE, var_masq_exceptions);
384     if (*var_masq_classes)
385 	cleanup_masq_flags = name_mask(VAR_MASQ_CLASSES, masq_class_table,
386 				       var_masq_classes);
387     if (*var_send_bcc_maps)
388 	cleanup_send_bcc_maps =
389 	    maps_create(VAR_SEND_BCC_MAPS, var_send_bcc_maps,
390 			DICT_FLAG_LOCK | DICT_FLAG_FOLD_FIX);
391     if (*var_rcpt_bcc_maps)
392 	cleanup_rcpt_bcc_maps =
393 	    maps_create(VAR_RCPT_BCC_MAPS, var_rcpt_bcc_maps,
394 			DICT_FLAG_LOCK | DICT_FLAG_FOLD_FIX);
395     if (*var_cleanup_milters)
396 	cleanup_milters = milter_create(var_cleanup_milters,
397 					var_milt_conn_time,
398 					var_milt_cmd_time,
399 					var_milt_msg_time,
400 					var_milt_protocol,
401 					var_milt_def_action,
402 					var_milt_conn_macros,
403 					var_milt_helo_macros,
404 					var_milt_mail_macros,
405 					var_milt_rcpt_macros,
406 					var_milt_data_macros,
407 					var_milt_eoh_macros,
408 					var_milt_eod_macros,
409 					var_milt_unk_macros);
410 
411     flush_init();
412 }
413 
414 /* cleanup_post_jail - initialize after entering the chroot jail */
415 
416 void    cleanup_post_jail(char *unused_name, char **unused_argv)
417 {
418 
419     /*
420      * Optionally set the file size resource limit. XXX This limits the
421      * message content to somewhat less than requested, because the total
422      * queue file size also includes envelope information. Unless people set
423      * really low limit, the difference is going to matter only when a queue
424      * file has lots of recipients.
425      */
426     if (var_message_limit > 0)
427 	set_file_limit((off_t) var_message_limit);
428 
429     /*
430      * Control how unmatched extensions are propagated.
431      */
432     cleanup_ext_prop_mask =
433 	ext_prop_mask(VAR_PROP_EXTENSION, var_prop_extension);
434 
435     /*
436      * Setup the filters for characters that should be rejected, and for
437      * characters that should be removed.
438      */
439     if (*var_msg_reject_chars) {
440 	cleanup_reject_chars = vstring_alloc(strlen(var_msg_reject_chars));
441 	unescape(cleanup_reject_chars, var_msg_reject_chars);
442     }
443     if (*var_msg_strip_chars) {
444 	cleanup_strip_chars = vstring_alloc(strlen(var_msg_strip_chars));
445 	unescape(cleanup_strip_chars, var_msg_strip_chars);
446     }
447 }
448