122710Sdist /* 234921Sbostic * Copyright (c) 1983 Eric P. Allman 363589Sbostic * Copyright (c) 1988, 1993 463589Sbostic * The Regents of the University of California. All rights reserved. 533731Sbostic * 642829Sbostic * %sccs.include.redist.c% 733731Sbostic */ 822710Sdist 922710Sdist #ifndef lint 10*65948Seric static char sccsid[] = "@(#)recipient.c 8.42 (Berkeley) 01/31/94"; 1133731Sbostic #endif /* not lint */ 1222710Sdist 1358332Seric # include "sendmail.h" 144174Seric # include <pwd.h> 154174Seric 164174Seric /* 179622Seric ** SENDTOLIST -- Designate a send list. 184174Seric ** 194174Seric ** The parameter is a comma-separated list of people to send to. 204174Seric ** This routine arranges to send to all of them. 214174Seric ** 224174Seric ** Parameters: 234174Seric ** list -- the send list. 244399Seric ** ctladdr -- the address template for the person to 254399Seric ** send to -- effective uid/gid are important. 265006Seric ** This is typically the alias that caused this 275006Seric ** expansion. 285006Seric ** sendq -- a pointer to the head of a queue to put 295006Seric ** these people into. 3058247Seric ** e -- the envelope in which to add these recipients. 314174Seric ** 324174Seric ** Returns: 3358082Seric ** The number of addresses actually on the list. 344174Seric ** 354174Seric ** Side Effects: 364174Seric ** none. 374174Seric */ 384174Seric 394174Seric # define MAXRCRSN 10 404174Seric 4155012Seric sendtolist(list, ctladdr, sendq, e) 424174Seric char *list; 434399Seric ADDRESS *ctladdr; 445198Seric ADDRESS **sendq; 4555012Seric register ENVELOPE *e; 464174Seric { 474174Seric register char *p; 488223Seric register ADDRESS *al; /* list of addresses to send to */ 494423Seric bool firstone; /* set on first address sent */ 5011446Seric char delimiter; /* the address delimiter */ 5158082Seric int naddrs; 5263847Seric char *oldto = e->e_to; 534174Seric 5464131Seric if (list == NULL) 5564131Seric { 5664131Seric syserr("sendtolist: null list"); 5764131Seric return 0; 5864131Seric } 5964131Seric 607676Seric if (tTd(25, 1)) 614444Seric { 624444Seric printf("sendto: %s\n ctladdr=", list); 634444Seric printaddr(ctladdr, FALSE); 644444Seric } 654324Seric 668223Seric /* heuristic to determine old versus new style addresses */ 678230Seric if (ctladdr == NULL && 6856795Seric (strchr(list, ',') != NULL || strchr(list, ';') != NULL || 6956795Seric strchr(list, '<') != NULL || strchr(list, '(') != NULL)) 7055012Seric e->e_flags &= ~EF_OLDSTYLE; 7111446Seric delimiter = ' '; 7255012Seric if (!bitset(EF_OLDSTYLE, e->e_flags) || ctladdr != NULL) 7311446Seric delimiter = ','; 748223Seric 754423Seric firstone = TRUE; 764324Seric al = NULL; 7758082Seric naddrs = 0; 788223Seric 798081Seric for (p = list; *p != '\0'; ) 804174Seric { 8158333Seric auto char *delimptr; 828081Seric register ADDRESS *a; 834319Seric 848081Seric /* parse the address */ 8558050Seric while ((isascii(*p) && isspace(*p)) || *p == ',') 864174Seric p++; 8764284Seric a = parseaddr(p, NULLADDR, RF_COPYALL, delimiter, &delimptr, e); 8858333Seric p = delimptr; 899297Seric if (a == NULL) 904174Seric continue; 914324Seric a->q_next = al; 924399Seric a->q_alias = ctladdr; 934444Seric 944444Seric /* see if this should be marked as a primary address */ 954423Seric if (ctladdr == NULL || 968081Seric (firstone && *p == '\0' && bitset(QPRIMARY, ctladdr->q_flags))) 974423Seric a->q_flags |= QPRIMARY; 984444Seric 999379Seric if (ctladdr != NULL && sameaddr(ctladdr, a)) 10058061Seric ctladdr->q_flags |= QSELFREF; 10157731Seric al = a; 1024423Seric firstone = FALSE; 1034324Seric } 1044324Seric 1054324Seric /* arrange to send to everyone on the local send list */ 1064324Seric while (al != NULL) 1074324Seric { 1084324Seric register ADDRESS *a = al; 1094324Seric 1104324Seric al = a->q_next; 11155012Seric a = recipient(a, sendq, e); 1124993Seric 1134998Seric /* arrange to inherit full name */ 1144998Seric if (a->q_fullname == NULL && ctladdr != NULL) 1154998Seric a->q_fullname = ctladdr->q_fullname; 11658082Seric naddrs++; 1174174Seric } 1184324Seric 11963847Seric e->e_to = oldto; 12058082Seric return (naddrs); 1214174Seric } 1224174Seric /* 1234174Seric ** RECIPIENT -- Designate a message recipient 1244174Seric ** 1254174Seric ** Saves the named person for future mailing. 1264174Seric ** 1274174Seric ** Parameters: 1284174Seric ** a -- the (preparsed) address header for the recipient. 1295006Seric ** sendq -- a pointer to the head of a queue to put the 1305006Seric ** recipient in. Duplicate supression is done 1315006Seric ** in this queue. 13257731Seric ** e -- the current envelope. 1334174Seric ** 1344174Seric ** Returns: 13512613Seric ** The actual address in the queue. This will be "a" if 13612613Seric ** the address is not a duplicate, else the original address. 1374174Seric ** 1384174Seric ** Side Effects: 1394174Seric ** none. 1404174Seric */ 1414174Seric 14212613Seric ADDRESS * 14355012Seric recipient(a, sendq, e) 1444174Seric register ADDRESS *a; 1455006Seric register ADDRESS **sendq; 14655012Seric register ENVELOPE *e; 1474174Seric { 1484174Seric register ADDRESS *q; 1494319Seric ADDRESS **pq; 1504174Seric register struct mailer *m; 1519210Seric register char *p; 1529210Seric bool quoted = FALSE; /* set if the addr has a quote bit */ 15353735Seric int findusercount = 0; 1549210Seric char buf[MAXNAME]; /* unquoted image of the user name */ 15558247Seric extern int safefile(); 1564174Seric 15755012Seric e->e_to = a->q_paddr; 1584600Seric m = a->q_mailer; 1594174Seric errno = 0; 1607676Seric if (tTd(26, 1)) 1614444Seric { 1624444Seric printf("\nrecipient: "); 1634444Seric printaddr(a, FALSE); 1644444Seric } 1654174Seric 16664146Seric /* if this is primary, add it to the original recipient list */ 16764146Seric if (a->q_alias == NULL) 16864146Seric { 16964146Seric if (e->e_origrcpt == NULL) 17064146Seric e->e_origrcpt = a->q_paddr; 17164146Seric else if (e->e_origrcpt != a->q_paddr) 17264146Seric e->e_origrcpt = ""; 17364146Seric } 17464146Seric 1754174Seric /* break aliasing loops */ 1764174Seric if (AliasLevel > MAXRCRSN) 1774174Seric { 17858151Seric usrerr("554 aliasing/forwarding loop broken"); 17912613Seric return (a); 1804174Seric } 1814174Seric 1824174Seric /* 1834627Seric ** Finish setting up address structure. 1844174Seric */ 1854174Seric 18616160Seric /* set the queue timeout */ 18758737Seric a->q_timeout = TimeOuts.to_q_return; 1884627Seric 18916160Seric /* get unquoted user for file, program or user.name check */ 1909210Seric (void) strcpy(buf, a->q_user); 1919210Seric for (p = buf; *p != '\0' && !quoted; p++) 1929210Seric { 19354993Seric if (*p == '\\') 1949210Seric quoted = TRUE; 1959210Seric } 19654983Seric stripquotes(buf); 1979210Seric 19857402Seric /* check for direct mailing to restricted mailers */ 19965496Seric if (m == ProgMailer) 2004174Seric { 20165496Seric if (a->q_alias == NULL) 20265496Seric { 20365496Seric a->q_flags |= QBADADDR; 20465496Seric usrerr("550 Cannot mail directly to programs"); 20565496Seric } 20665496Seric else if (bitset(QBOGUSSHELL, a->q_alias->q_flags)) 20765496Seric { 20865496Seric a->q_flags |= QBADADDR; 20965496Seric usrerr("550 User %s@%s doesn't have a valid shell for mailing to programs", 21065496Seric a->q_alias->q_ruser, MyHostName); 21165496Seric } 21265496Seric else if (bitset(QUNSAFEADDR, a->q_alias->q_flags)) 21365496Seric { 21465496Seric a->q_flags |= QBADADDR; 21565496Seric usrerr("550 Address %s is unsafe for mailing to programs", 21665496Seric a->q_alias->q_paddr); 21765496Seric } 2184174Seric } 2194174Seric 2204174Seric /* 2214419Seric ** Look up this person in the recipient list. 2224419Seric ** If they are there already, return, otherwise continue. 2234419Seric ** If the list is empty, just add it. Notice the cute 2244419Seric ** hack to make from addresses suppress things correctly: 2254419Seric ** the QDONTSEND bit will be set in the send list. 2264419Seric ** [Please note: the emphasis is on "hack."] 2274174Seric */ 2284174Seric 2295006Seric for (pq = sendq; (q = *pq) != NULL; pq = &q->q_next) 2304174Seric { 23158294Seric if (sameaddr(q, a)) 2324174Seric { 2337676Seric if (tTd(26, 1)) 2344444Seric { 2354444Seric printf("%s in sendq: ", a->q_paddr); 2364444Seric printaddr(q, FALSE); 2374444Seric } 23865593Seric if (!bitset(QPRIMARY, q->q_flags)) 23958065Seric { 24065593Seric if (!bitset(QDONTSEND, a->q_flags)) 24158151Seric message("duplicate suppressed"); 24265593Seric q->q_flags |= a->q_flags; 24365593Seric } 24465593Seric else if (bitset(QSELFREF, q->q_flags)) 24565579Seric q->q_flags |= a->q_flags & ~QDONTSEND; 24663847Seric a = q; 24763847Seric goto testselfdestruct; 2484174Seric } 2494319Seric } 2504174Seric 2514319Seric /* add address on list */ 25258884Seric *pq = a; 25358884Seric a->q_next = NULL; 2544174Seric 2554174Seric /* 25657402Seric ** Alias the name and handle special mailer types. 2574174Seric */ 2584174Seric 25953735Seric trylocaluser: 26055354Seric if (tTd(29, 7)) 26155354Seric printf("at trylocaluser %s\n", a->q_user); 26255354Seric 26358680Seric if (bitset(QDONTSEND|QBADADDR|QVERIFIED, a->q_flags)) 26463847Seric goto testselfdestruct; 26557402Seric 26657402Seric if (m == InclMailer) 2674174Seric { 26857402Seric a->q_flags |= QDONTSEND; 26964761Seric if (a->q_alias == NULL) 2704174Seric { 27158680Seric a->q_flags |= QBADADDR; 27258151Seric usrerr("550 Cannot mail directly to :include:s"); 2734174Seric } 2744174Seric else 27550556Seric { 27659563Seric int ret; 27758247Seric 27858151Seric message("including file %s", a->q_user); 27959563Seric ret = include(a->q_user, FALSE, a, sendq, e); 28059563Seric if (transienterror(ret)) 28159563Seric { 28259563Seric #ifdef LOG 28359563Seric if (LogLevel > 2) 28459615Seric syslog(LOG_ERR, "%s: include %s: transient error: %e", 28559623Seric e->e_id, a->q_user, errstring(ret)); 28659563Seric #endif 28763853Seric a->q_flags |= QQUEUEUP; 28865215Seric a->q_flags &= ~QDONTSEND; 28959563Seric usrerr("451 Cannot open %s: %s", 29059563Seric a->q_user, errstring(ret)); 29159563Seric } 29259563Seric else if (ret != 0) 29359563Seric { 29463938Seric a->q_flags |= QBADADDR; 29559563Seric usrerr("550 Cannot open %s: %s", 29659563Seric a->q_user, errstring(ret)); 29759563Seric } 29850556Seric } 2994174Seric } 30057642Seric else if (m == FileMailer) 3014174Seric { 3024329Seric extern bool writable(); 3034174Seric 30451317Seric /* check if writable or creatable */ 30564761Seric if (a->q_alias == NULL) 3064174Seric { 30758680Seric a->q_flags |= QBADADDR; 30858151Seric usrerr("550 Cannot mail directly to files"); 3094174Seric } 31065496Seric else if (bitset(QBOGUSSHELL, a->q_alias->q_flags)) 31165496Seric { 31265496Seric a->q_flags |= QBADADDR; 31365496Seric usrerr("550 User %s@%s doesn't have a valid shell for mailing to files", 31465496Seric a->q_alias->q_ruser, MyHostName); 31565496Seric } 31665496Seric else if (bitset(QUNSAFEADDR, a->q_alias->q_flags)) 31765496Seric { 31865496Seric a->q_flags |= QBADADDR; 31965496Seric usrerr("550 Address %s is unsafe for mailing to files", 32065496Seric a->q_alias->q_paddr); 32165496Seric } 32265112Seric else if (!writable(buf, getctladdr(a), SFF_ANYFILE)) 32351317Seric { 32458680Seric a->q_flags |= QBADADDR; 32564771Seric giveresponse(EX_CANTCREAT, m, NULL, a->q_alias, e); 32651317Seric } 32751317Seric } 32851317Seric 32957402Seric if (m != LocalMailer) 33057642Seric { 33157642Seric if (!bitset(QDONTSEND, a->q_flags)) 33257642Seric e->e_nrcpts++; 33363847Seric goto testselfdestruct; 33457642Seric } 33557402Seric 33657402Seric /* try aliasing */ 33757402Seric alias(a, sendq, e); 33857402Seric 33957402Seric # ifdef USERDB 34057402Seric /* if not aliased, look it up in the user database */ 34158918Seric if (!bitset(QDONTSEND|QNOTREMOTE|QVERIFIED, a->q_flags)) 34257402Seric { 34357402Seric extern int udbexpand(); 34457402Seric 34557402Seric if (udbexpand(a, sendq, e) == EX_TEMPFAIL) 34657402Seric { 34763853Seric a->q_flags |= QQUEUEUP; 34857402Seric if (e->e_message == NULL) 34957402Seric e->e_message = newstr("Deferred: user database error"); 35057402Seric # ifdef LOG 35158020Seric if (LogLevel > 8) 35259623Seric syslog(LOG_INFO, "%s: deferred: udbexpand: %s", 35359623Seric e->e_id, errstring(errno)); 35457402Seric # endif 35559615Seric message("queued (user database error): %s", 35659615Seric errstring(errno)); 35757642Seric e->e_nrcpts++; 35863847Seric goto testselfdestruct; 35957402Seric } 36057402Seric } 36157402Seric # endif 36257402Seric 36357402Seric /* if it was an alias or a UDB expansion, just return now */ 36458247Seric if (bitset(QDONTSEND|QQUEUEUP|QVERIFIED, a->q_flags)) 36563847Seric goto testselfdestruct; 36657402Seric 36751317Seric /* 36851317Seric ** If we have a level two config file, then pass the name through 36951317Seric ** Ruleset 5 before sending it off. Ruleset 5 has the right 37051317Seric ** to send rewrite it to another mailer. This gives us a hook 37151317Seric ** after local aliasing has been done. 37251317Seric */ 37351317Seric 37451317Seric if (tTd(29, 5)) 37551317Seric { 37651317Seric printf("recipient: testing local? cl=%d, rr5=%x\n\t", 37751317Seric ConfigLevel, RewriteRules[5]); 37851317Seric printaddr(a, FALSE); 37951317Seric } 38051317Seric if (!bitset(QNOTREMOTE, a->q_flags) && ConfigLevel >= 2 && 38151317Seric RewriteRules[5] != NULL) 38251317Seric { 38355012Seric maplocaluser(a, sendq, e); 38451317Seric } 38551317Seric 38651317Seric /* 38751317Seric ** If it didn't get rewritten to another mailer, go ahead 38851317Seric ** and deliver it. 38951317Seric */ 39051317Seric 39158247Seric if (!bitset(QDONTSEND|QQUEUEUP, a->q_flags)) 39251317Seric { 39355354Seric auto bool fuzzy; 39451317Seric register struct passwd *pw; 39551317Seric extern struct passwd *finduser(); 39651317Seric 39751317Seric /* warning -- finduser may trash buf */ 39855354Seric pw = finduser(buf, &fuzzy); 39951317Seric if (pw == NULL) 40051317Seric { 40158680Seric a->q_flags |= QBADADDR; 40264771Seric giveresponse(EX_NOUSER, m, NULL, a->q_alias, e); 40351317Seric } 4044174Seric else 4054174Seric { 40651317Seric char nbuf[MAXNAME]; 4074373Seric 40855354Seric if (fuzzy) 4094174Seric { 41053735Seric /* name was a fuzzy match */ 41151317Seric a->q_user = newstr(pw->pw_name); 41253735Seric if (findusercount++ > 3) 41353735Seric { 41458680Seric a->q_flags |= QBADADDR; 41558151Seric usrerr("554 aliasing/forwarding loop for %s broken", 41653735Seric pw->pw_name); 41753735Seric return (a); 41853735Seric } 41953735Seric 42053735Seric /* see if it aliases */ 42151317Seric (void) strcpy(buf, pw->pw_name); 42253735Seric goto trylocaluser; 4234174Seric } 42465822Seric if (strcmp(pw->pw_dir, "/") == 0) 42565822Seric a->q_home = ""; 42665822Seric else 42765822Seric a->q_home = newstr(pw->pw_dir); 42851317Seric a->q_uid = pw->pw_uid; 42951317Seric a->q_gid = pw->pw_gid; 43059083Seric a->q_ruser = newstr(pw->pw_name); 43151317Seric a->q_flags |= QGOODUID; 43251317Seric buildfname(pw->pw_gecos, pw->pw_name, nbuf); 43351317Seric if (nbuf[0] != '\0') 43451317Seric a->q_fullname = newstr(nbuf); 43565211Seric if (pw->pw_shell != NULL && pw->pw_shell[0] != '\0' && 43665211Seric !usershellok(pw->pw_shell)) 43765206Seric { 43865211Seric a->q_flags |= QBOGUSSHELL; 43965206Seric } 44051317Seric if (!quoted) 44155012Seric forward(a, sendq, e); 4424174Seric } 4434174Seric } 44457642Seric if (!bitset(QDONTSEND, a->q_flags)) 44557642Seric e->e_nrcpts++; 44663847Seric 44763847Seric testselfdestruct: 44863978Seric if (tTd(26, 8)) 44963847Seric { 45063978Seric printf("testselfdestruct: "); 45163978Seric printaddr(a, TRUE); 45263978Seric } 45363978Seric if (a->q_alias == NULL && a != &e->e_from && 45463978Seric bitset(QDONTSEND, a->q_flags)) 45563978Seric { 45663978Seric q = *sendq; 45763965Seric while (q != NULL && bitset(QDONTSEND, q->q_flags)) 45863847Seric q = q->q_next; 45963978Seric if (q == NULL) 46063847Seric { 46163847Seric a->q_flags |= QBADADDR; 46263847Seric usrerr("554 aliasing/forwarding loop broken"); 46363847Seric } 46463847Seric } 46512613Seric return (a); 4664174Seric } 4674174Seric /* 4684373Seric ** FINDUSER -- find the password entry for a user. 4694373Seric ** 4704373Seric ** This looks a lot like getpwnam, except that it may want to 4714373Seric ** do some fancier pattern matching in /etc/passwd. 4724373Seric ** 4739379Seric ** This routine contains most of the time of many sendmail runs. 4749379Seric ** It deserves to be optimized. 4759379Seric ** 4764373Seric ** Parameters: 4774373Seric ** name -- the name to match against. 47855354Seric ** fuzzyp -- an outarg that is set to TRUE if this entry 47955354Seric ** was found using the fuzzy matching algorithm; 48055354Seric ** set to FALSE otherwise. 4814373Seric ** 4824373Seric ** Returns: 4834373Seric ** A pointer to a pw struct. 4844373Seric ** NULL if name is unknown or ambiguous. 4854373Seric ** 4864373Seric ** Side Effects: 4874407Seric ** may modify name. 4884373Seric */ 4894373Seric 4904373Seric struct passwd * 49155354Seric finduser(name, fuzzyp) 4924373Seric char *name; 49355354Seric bool *fuzzyp; 4944373Seric { 4954376Seric register struct passwd *pw; 4964407Seric register char *p; 49715325Seric extern struct passwd *getpwent(); 49815325Seric extern struct passwd *getpwnam(); 4994373Seric 50055354Seric if (tTd(29, 4)) 50155354Seric printf("finduser(%s): ", name); 50255354Seric 50355354Seric *fuzzyp = FALSE; 5044407Seric 50564673Seric /* DEC Hesiod getpwnam accepts numeric strings -- short circuit it */ 50664673Seric for (p = name; *p != '\0'; p++) 50764673Seric if (!isascii(*p) || !isdigit(*p)) 50864673Seric break; 50964673Seric if (*p == '\0') 51064673Seric { 51164673Seric if (tTd(29, 4)) 51264673Seric printf("failed (numeric input)\n"); 51364673Seric return NULL; 51464673Seric } 51564673Seric 51625777Seric /* look up this login name using fast path */ 51712634Seric if ((pw = getpwnam(name)) != NULL) 51855354Seric { 51955354Seric if (tTd(29, 4)) 52055354Seric printf("found (non-fuzzy)\n"); 52112634Seric return (pw); 52255354Seric } 52312634Seric 52453735Seric #ifdef MATCHGECOS 52553735Seric /* see if fuzzy matching allowed */ 52653735Seric if (!MatchGecos) 52755354Seric { 52855354Seric if (tTd(29, 4)) 52955354Seric printf("not found (fuzzy disabled)\n"); 53053735Seric return NULL; 53155354Seric } 53253735Seric 53312634Seric /* search for a matching full name instead */ 53425777Seric for (p = name; *p != '\0'; p++) 53525777Seric { 53625777Seric if (*p == (SpaceSub & 0177) || *p == '_') 53725777Seric *p = ' '; 53825777Seric } 53923107Seric (void) setpwent(); 5404376Seric while ((pw = getpwent()) != NULL) 5414376Seric { 5424998Seric char buf[MAXNAME]; 5434376Seric 5444998Seric buildfname(pw->pw_gecos, pw->pw_name, buf); 54556795Seric if (strchr(buf, ' ') != NULL && !strcasecmp(buf, name)) 5464381Seric { 54755354Seric if (tTd(29, 4)) 54855354Seric printf("fuzzy matches %s\n", pw->pw_name); 54958151Seric message("sending to login name %s", pw->pw_name); 55055354Seric *fuzzyp = TRUE; 5514376Seric return (pw); 5524377Seric } 5534376Seric } 55455354Seric if (tTd(29, 4)) 55555354Seric printf("no fuzzy match found\n"); 55659015Seric #else 55759015Seric if (tTd(29, 4)) 55859015Seric printf("not found (fuzzy disabled)\n"); 55959015Seric #endif 5604376Seric return (NULL); 5614373Seric } 5624373Seric /* 5634329Seric ** WRITABLE -- predicate returning if the file is writable. 5644329Seric ** 5654329Seric ** This routine must duplicate the algorithm in sys/fio.c. 5664329Seric ** Unfortunately, we cannot use the access call since we 5674329Seric ** won't necessarily be the real uid when we try to 5684329Seric ** actually open the file. 5694329Seric ** 5704329Seric ** Notice that ANY file with ANY execute bit is automatically 5714329Seric ** not writable. This is also enforced by mailfile. 5724329Seric ** 5734329Seric ** Parameters: 57465064Seric ** filename -- the file name to check. 57565112Seric ** ctladdr -- the controlling address for this file. 57665064Seric ** flags -- SFF_* flags to control the function. 5774329Seric ** 5784329Seric ** Returns: 5794329Seric ** TRUE -- if we will be able to write this file. 5804329Seric ** FALSE -- if we cannot write this file. 5814329Seric ** 5824329Seric ** Side Effects: 5834329Seric ** none. 5844329Seric */ 5854329Seric 5864329Seric bool 58765112Seric writable(filename, ctladdr, flags) 58864819Seric char *filename; 58965112Seric ADDRESS *ctladdr; 59065064Seric int flags; 5914329Seric { 59255372Seric uid_t euid; 59355372Seric gid_t egid; 5944329Seric int bits; 59564944Seric register char *p; 59664944Seric char *uname; 59764944Seric struct stat stb; 59864944Seric extern char RealUserName[]; 5994329Seric 60064819Seric if (tTd(29, 5)) 60165064Seric printf("writable(%s, %x)\n", filename, flags); 60264944Seric 60364944Seric #ifdef HASLSTAT 60465064Seric if ((bitset(SFF_NOSLINK, flags) ? lstat(filename, &stb) 60565064Seric : stat(filename, &stb)) < 0) 60664944Seric #else 60764944Seric if (stat(filename, &stb) < 0) 60864944Seric #endif 60964944Seric { 61064944Seric /* file does not exist -- see if directory is safe */ 61164944Seric p = strrchr(filename, '/'); 61264944Seric if (p == NULL) 61364944Seric { 61465067Seric errno = ENOTDIR; 61564944Seric return FALSE; 61664944Seric } 61765067Seric *p = '\0'; 61865067Seric errno = safefile(filename, RealUid, RealGid, RealUserName, 61965067Seric SFF_MUSTOWN, S_IWRITE|S_IEXEC); 62064944Seric *p = '/'; 62165067Seric return errno == 0; 62264944Seric } 62364944Seric 62465225Seric #ifdef SUID_ROOT_FILES_OK 62565225Seric /* really ought to be passed down -- and not a good idea */ 62665225Seric flags |= SFF_ROOTOK; 62765225Seric #endif 62865225Seric 62964944Seric /* 63064944Seric ** File does exist -- check that it is writable. 63164944Seric */ 63264944Seric 63364944Seric if (bitset(0111, stb.st_mode)) 63465022Seric { 63565022Seric if (tTd(29, 5)) 63665022Seric printf("failed (mode %o: x bits)\n", stb.st_mode); 63765067Seric errno = EPERM; 6384329Seric return (FALSE); 63965022Seric } 64064944Seric 64165112Seric if (ctladdr != NULL && geteuid() == 0) 64264944Seric { 64365112Seric euid = ctladdr->q_uid; 64465112Seric egid = ctladdr->q_gid; 64565112Seric uname = ctladdr->q_user; 64664944Seric } 64765112Seric else 64865112Seric { 64965112Seric euid = RealUid; 65065112Seric egid = RealGid; 65165112Seric uname = RealUserName; 65265112Seric } 65365138Seric if (euid == 0) 65465138Seric { 65565138Seric euid = DefUid; 65665138Seric uname = DefUser; 65765138Seric } 65865138Seric if (egid == 0) 65965138Seric egid = DefGid; 6604329Seric if (geteuid() == 0) 6614329Seric { 66265225Seric if (bitset(S_ISUID, stb.st_mode) && 66365225Seric (stb.st_uid != 0 || bitset(SFF_ROOTOK, flags))) 66464944Seric { 66564944Seric euid = stb.st_uid; 66664944Seric uname = NULL; 66764944Seric } 66865225Seric if (bitset(S_ISGID, stb.st_mode) && 66965225Seric (stb.st_gid != 0 || bitset(SFF_ROOTOK, flags))) 67064944Seric egid = stb.st_gid; 6714329Seric } 6724329Seric 67364819Seric if (tTd(29, 5)) 67464819Seric printf("\teu/gid=%d/%d, st_u/gid=%d/%d\n", 67564944Seric euid, egid, stb.st_uid, stb.st_gid); 67664819Seric 67765067Seric errno = safefile(filename, euid, egid, uname, flags, S_IWRITE); 67865067Seric return errno == 0; 6794329Seric } 6804329Seric /* 6814174Seric ** INCLUDE -- handle :include: specification. 6824174Seric ** 6834174Seric ** Parameters: 6844174Seric ** fname -- filename to include. 68553037Seric ** forwarding -- if TRUE, we are reading a .forward file. 68653037Seric ** if FALSE, it's a :include: file. 6874399Seric ** ctladdr -- address template to use to fill in these 6884399Seric ** addresses -- effective user/group id are 6894399Seric ** the important things. 6905006Seric ** sendq -- a pointer to the head of the send queue 6915006Seric ** to put these addresses in. 6924174Seric ** 6934174Seric ** Returns: 69457136Seric ** open error status 6954174Seric ** 6964174Seric ** Side Effects: 6974174Seric ** reads the :include: file and sends to everyone 6984174Seric ** listed in that file. 69965909Seric ** 70065909Seric ** Security Note: 70165909Seric ** If you have restricted chown (that is, you can't 70265909Seric ** give a file away), it is reasonable to allow programs 70365909Seric ** and files called from this :include: file to be to be 70465909Seric ** run as the owner of the :include: file. This is bogus 70565909Seric ** if there is any chance of someone giving away a file. 70665909Seric ** We assume that pre-POSIX systems can give away files. 70765909Seric ** 70865909Seric ** There is an additional restriction that if you 70965909Seric ** forward to a :include: file, it will not take on 71065909Seric ** the ownership of the :include: file. This may not 71165909Seric ** be necessary, but shouldn't hurt. 7124174Seric */ 7134174Seric 71453037Seric static jmp_buf CtxIncludeTimeout; 71563937Seric static int includetimeout(); 71653037Seric 71765496Seric #ifndef S_IWOTH 71865496Seric # define S_IWOTH (S_IWRITE >> 6) 71965496Seric #endif 72065496Seric 72157136Seric int 72255012Seric include(fname, forwarding, ctladdr, sendq, e) 7234174Seric char *fname; 72453037Seric bool forwarding; 7254399Seric ADDRESS *ctladdr; 7265006Seric ADDRESS **sendq; 72755012Seric ENVELOPE *e; 7284174Seric { 72964570Seric register FILE *fp = NULL; 73055012Seric char *oldto = e->e_to; 7319379Seric char *oldfilename = FileName; 7329379Seric int oldlinenumber = LineNumber; 73353037Seric register EVENT *ev = NULL; 73458082Seric int nincludes; 73564325Seric register ADDRESS *ca; 73664325Seric uid_t saveduid, uid; 73764325Seric gid_t savedgid, gid; 73864083Seric char *uname; 73964325Seric int rval = 0; 74065064Seric int sfflags = forwarding ? SFF_MUSTOWN : SFF_ANYFILE; 74165496Seric struct stat st; 742*65948Seric char buf[MAXLINE]; 74365909Seric #ifdef _POSIX_CHOWN_RESTRICTED 744*65948Seric # if _POSIX_CHOWN_RESTRICTED == -1 745*65948Seric # define safechown FALSE 746*65948Seric # else 747*65948Seric # define safechown TRUE 748*65948Seric # endif 749*65948Seric #else 750*65948Seric # ifdef _PC_CHOWN_RESTRICTED 75165909Seric bool safechown; 752*65948Seric # else 753*65948Seric # ifdef BSD 754*65948Seric # define safechown TRUE 755*65948Seric # else 756*65948Seric # define safechown FALSE 757*65948Seric # endif 758*65948Seric # endif 75965909Seric #endif 760*65948Seric extern bool chownsafe(); 7614174Seric 76257186Seric if (tTd(27, 2)) 76357186Seric printf("include(%s)\n", fname); 76463902Seric if (tTd(27, 4)) 76563902Seric printf(" ruid=%d euid=%d\n", getuid(), geteuid()); 76663581Seric if (tTd(27, 14)) 76763581Seric { 76863581Seric printf("ctladdr "); 76963581Seric printaddr(ctladdr, FALSE); 77063581Seric } 77157186Seric 77264325Seric if (tTd(27, 9)) 77364325Seric printf("include: old uid = %d/%d\n", getuid(), geteuid()); 77453037Seric 77563581Seric ca = getctladdr(ctladdr); 77663581Seric if (ca == NULL) 77764083Seric { 77864846Seric uid = DefUid; 77964846Seric gid = DefGid; 78064846Seric uname = DefUser; 78164325Seric saveduid = -1; 78264083Seric } 78363581Seric else 78464083Seric { 78563581Seric uid = ca->q_uid; 78664083Seric gid = ca->q_gid; 78764083Seric uname = ca->q_user; 78864325Seric #ifdef HASSETREUID 78964325Seric saveduid = geteuid(); 79064325Seric savedgid = getegid(); 79164325Seric if (saveduid == 0) 79264325Seric { 79364325Seric initgroups(uname, gid); 79464325Seric if (uid != 0) 79564325Seric (void) setreuid(0, uid); 79664325Seric } 79764325Seric #endif 79864083Seric } 79963581Seric 80064325Seric if (tTd(27, 9)) 80164325Seric printf("include: new uid = %d/%d\n", getuid(), geteuid()); 80264325Seric 80364325Seric /* 80464325Seric ** If home directory is remote mounted but server is down, 80564325Seric ** this can hang or give errors; use a timeout to avoid this 80664325Seric */ 80764325Seric 80853037Seric if (setjmp(CtxIncludeTimeout) != 0) 80953037Seric { 81063853Seric ctladdr->q_flags |= QQUEUEUP; 81153037Seric errno = 0; 81263993Seric 81363993Seric /* return pseudo-error code */ 81464325Seric rval = EOPENTIMEOUT; 81564325Seric goto resetuid; 81653037Seric } 81753037Seric ev = setevent((time_t) 60, includetimeout, 0); 81853037Seric 81963581Seric /* the input file must be marked safe */ 82064944Seric rval = safefile(fname, uid, gid, uname, sfflags, S_IREAD); 82164329Seric if (rval != 0) 82253037Seric { 82364325Seric /* don't use this :include: file */ 82457186Seric if (tTd(27, 4)) 82558247Seric printf("include: not safe (uid=%d): %s\n", 82664329Seric uid, errstring(rval)); 82753037Seric } 82865496Seric else 8294174Seric { 83065496Seric fp = fopen(fname, "r"); 83165496Seric if (fp == NULL) 83258061Seric { 83364329Seric rval = errno; 83465496Seric if (tTd(27, 4)) 83565496Seric printf("include: open: %s\n", errstring(rval)); 83658061Seric } 8374406Seric } 83853037Seric clrevent(ev); 83953037Seric 84064570Seric resetuid: 84164570Seric 84264570Seric #ifdef HASSETREUID 84364570Seric if (saveduid == 0) 84464570Seric { 84564570Seric if (uid != 0) 84664570Seric if (setreuid(-1, 0) < 0 || setreuid(RealUid, 0) < 0) 84764570Seric syserr("setreuid(%d, 0) failure (real=%d, eff=%d)", 84864570Seric RealUid, getuid(), geteuid()); 84964570Seric setgid(savedgid); 85064570Seric } 85164570Seric #endif 85264570Seric 85364570Seric if (tTd(27, 9)) 85464570Seric printf("include: reset uid = %d/%d\n", getuid(), geteuid()); 85564570Seric 85665593Seric if (rval == EOPENTIMEOUT) 85765593Seric usrerr("451 open timeout on %s", fname); 85865593Seric 85964570Seric if (fp == NULL) 86064570Seric return rval; 86164570Seric 86265496Seric if (fstat(fileno(fp), &st) < 0) 86365496Seric { 86465496Seric rval = errno; 86565496Seric syserr("Cannot fstat %s!", fname); 86665496Seric return rval; 86765496Seric } 86865496Seric 869*65948Seric #ifndef safechown 870*65948Seric safechown = chownsafe(fileno(fp)); 871*65948Seric #endif 87265909Seric if (ca == NULL && safechown) 87365496Seric { 87465496Seric ctladdr->q_uid = st.st_uid; 87565496Seric ctladdr->q_gid = st.st_gid; 87665496Seric ctladdr->q_flags |= QGOODUID; 87765496Seric } 87865496Seric if (ca != NULL && ca->q_uid == st.st_uid) 87965496Seric { 88065496Seric /* optimization -- avoid getpwuid if we already have info */ 88165496Seric ctladdr->q_flags |= ca->q_flags & QBOGUSSHELL; 88265496Seric ctladdr->q_ruser = ca->q_ruser; 88365496Seric } 88465496Seric else 88565496Seric { 88665909Seric char *sh; 88765496Seric register struct passwd *pw; 88865496Seric 88965909Seric sh = "/SENDMAIL/ANY/SHELL/"; 89065496Seric pw = getpwuid(st.st_uid); 89165909Seric if (pw != NULL) 89265496Seric { 89365496Seric ctladdr->q_ruser = newstr(pw->pw_name); 89465909Seric if (safechown) 89565909Seric sh = pw->pw_shell; 89665909Seric } 89765909Seric if (pw == NULL) 89865496Seric ctladdr->q_flags |= QBOGUSSHELL; 89965909Seric else if(!usershellok(sh)) 90065909Seric { 90165909Seric if (safechown) 90265909Seric ctladdr->q_flags |= QBOGUSSHELL; 90365909Seric else 90465909Seric ctladdr->q_flags |= QUNSAFEADDR; 90565496Seric } 90665496Seric } 90765496Seric 90858092Seric if (bitset(EF_VRFYONLY, e->e_flags)) 90958092Seric { 91058092Seric /* don't do any more now */ 91158868Seric ctladdr->q_flags |= QVERIFIED; 91258884Seric e->e_nrcpts++; 91358680Seric xfclose(fp, "include", fname); 91464570Seric return rval; 91558092Seric } 91658092Seric 91765496Seric /* 91865496Seric ** Check to see if some bad guy can write this file 91965496Seric ** 92065496Seric ** This should really do something clever with group 92165496Seric ** permissions; currently we just view world writable 92265496Seric ** as unsafe. Also, we don't check for writable 92365496Seric ** directories in the path. We've got to leave 92465496Seric ** something for the local sysad to do. 92565496Seric */ 92665496Seric 92765496Seric if (bitset(S_IWOTH, st.st_mode)) 92865496Seric ctladdr->q_flags |= QUNSAFEADDR; 92965496Seric 9304174Seric /* read the file -- each line is a comma-separated list. */ 9319379Seric FileName = fname; 9329379Seric LineNumber = 0; 93358082Seric ctladdr->q_flags &= ~QSELFREF; 93458082Seric nincludes = 0; 9354174Seric while (fgets(buf, sizeof buf, fp) != NULL) 9364174Seric { 93756795Seric register char *p = strchr(buf, '\n'); 9384174Seric 93940963Sbostic LineNumber++; 9404174Seric if (p != NULL) 9414174Seric *p = '\0'; 94257186Seric if (buf[0] == '#' || buf[0] == '\0') 94357139Seric continue; 94458008Seric e->e_to = NULL; 94558151Seric message("%s to %s", 94653037Seric forwarding ? "forwarding" : "sending", buf); 94757977Seric #ifdef LOG 94858020Seric if (forwarding && LogLevel > 9) 94957977Seric syslog(LOG_INFO, "%s: forward %s => %s", 95057977Seric e->e_id, oldto, buf); 95157977Seric #endif 95257977Seric 9534176Seric AliasLevel++; 95458082Seric nincludes += sendtolist(buf, ctladdr, sendq, e); 9554176Seric AliasLevel--; 9564174Seric } 95763902Seric 95863902Seric if (ferror(fp) && tTd(27, 3)) 95963902Seric printf("include: read error: %s\n", errstring(errno)); 96058082Seric if (nincludes > 0 && !bitset(QSELFREF, ctladdr->q_flags)) 96158065Seric { 96258065Seric if (tTd(27, 5)) 96358065Seric { 96458065Seric printf("include: QDONTSEND "); 96558065Seric printaddr(ctladdr, FALSE); 96658065Seric } 96758065Seric ctladdr->q_flags |= QDONTSEND; 96858065Seric } 9694174Seric 97058680Seric (void) xfclose(fp, "include", fname); 9719379Seric FileName = oldfilename; 9729379Seric LineNumber = oldlinenumber; 97363847Seric e->e_to = oldto; 97464325Seric return rval; 9754174Seric } 97653037Seric 97753037Seric static 97853037Seric includetimeout() 97953037Seric { 98053037Seric longjmp(CtxIncludeTimeout, 1); 98153037Seric } 9824324Seric /* 9834324Seric ** SENDTOARGV -- send to an argument vector. 9844324Seric ** 9854324Seric ** Parameters: 9864324Seric ** argv -- argument vector to send to. 98758247Seric ** e -- the current envelope. 9884324Seric ** 9894324Seric ** Returns: 9904324Seric ** none. 9914324Seric ** 9924324Seric ** Side Effects: 9934324Seric ** puts all addresses on the argument vector onto the 9944324Seric ** send queue. 9954324Seric */ 9964324Seric 99755012Seric sendtoargv(argv, e) 9984324Seric register char **argv; 99955012Seric register ENVELOPE *e; 10004324Seric { 10014324Seric register char *p; 10024324Seric 10034324Seric while ((p = *argv++) != NULL) 10044324Seric { 100564284Seric (void) sendtolist(p, NULLADDR, &e->e_sendqueue, e); 10064324Seric } 10074324Seric } 10084399Seric /* 10094399Seric ** GETCTLADDR -- get controlling address from an address header. 10104399Seric ** 10114399Seric ** If none, get one corresponding to the effective userid. 10124399Seric ** 10134399Seric ** Parameters: 10144399Seric ** a -- the address to find the controller of. 10154399Seric ** 10164399Seric ** Returns: 10174399Seric ** the controlling address. 10184399Seric ** 10194399Seric ** Side Effects: 10204399Seric ** none. 10214399Seric */ 10224399Seric 10234399Seric ADDRESS * 10244399Seric getctladdr(a) 10254399Seric register ADDRESS *a; 10264399Seric { 10274404Seric while (a != NULL && !bitset(QGOODUID, a->q_flags)) 10284399Seric a = a->q_alias; 10294399Seric return (a); 10304399Seric } 1031