1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
|
/*++
/* NAME
/* smtp_stream 3
/* SUMMARY
/* smtp stream I/O support
/* SYNOPSIS
/* #include <smtp_stream.h>
/*
/* void smtp_stream_setup(stream, timeout, enable_deadline)
/* VSTREAM *stream;
/* int timeout;
/* int enable_deadline;
/*
/* void smtp_printf(stream, format, ...)
/* VSTREAM *stream;
/* const char *format;
/*
/* void smtp_flush(stream)
/* VSTREAM *stream;
/*
/* int smtp_fgetc(stream)
/* VSTREAM *stream;
/*
/* int smtp_get(vp, stream, maxlen, flags)
/* VSTRING *vp;
/* VSTREAM *stream;
/* ssize_t maxlen;
/* int flags;
/*
/* void smtp_fputs(str, len, stream)
/* const char *str;
/* ssize_t len;
/* VSTREAM *stream;
/*
/* void smtp_fwrite(str, len, stream)
/* const char *str;
/* ssize_t len;
/* VSTREAM *stream;
/*
/* void smtp_fread_buf(vp, len, stream)
/* VSTRING *vp;
/* ssize_t len;
/* VSTREAM *stream;
/*
/* void smtp_fputc(ch, stream)
/* int ch;
/* VSTREAM *stream;
/*
/* void smtp_vprintf(stream, format, ap)
/* VSTREAM *stream;
/* char *format;
/* va_list ap;
/*
/* int smtp_detect_bare_lf;
/* int smtp_got_bare_lf;
/* AUXILIARY API
/* int smtp_get_noexcept(vp, stream, maxlen, flags)
/* VSTRING *vp;
/* VSTREAM *stream;
/* ssize_t maxlen;
/* int flags;
/* LEGACY API
/* void smtp_timeout_setup(stream, timeout)
/* VSTREAM *stream;
/* int timeout;
/* int enable_deadline;
/* DESCRIPTION
/* This module reads and writes text records delimited by CR LF,
/* with error detection: timeouts or unexpected end-of-file.
/* A trailing CR LF is added upon writing and removed upon reading.
/*
/* smtp_stream_setup() prepares the specified stream for SMTP read
/* and write operations described below.
/* This routine alters the behavior of streams as follows:
/* .IP \(bu
/* When enable_deadline is non-zero, the stream is configured
/* to enforce a total time limit for each smtp_stream read/write
/* operation. Otherwise, the stream is configured to enforce
/* a time limit for each individual read/write system call.
/* .IP \f(bu
/* The stream is configured to use double buffering.
/* .IP \f(bu
/* The stream is configured to enable exception handling.
/* .PP
/* smtp_printf() formats its arguments and writes the result to
/* the named stream, followed by a CR LF pair. The stream is NOT flushed.
/* Long lines of text are not broken.
/*
/* smtp_flush() flushes the named stream.
/*
/* smtp_fgetc() reads one character from the named stream.
/*
/* smtp_get() reads the named stream up to and including
/* the next LF character and strips the trailing CR LF. The
/* \fImaxlen\fR argument limits the length of a line of text,
/* and protects the program against running out of memory.
/* Specify a zero bound to turn off bounds checking.
/* The result is the last character read, or VSTREAM_EOF.
/* The \fIflags\fR argument is zero or more of:
/* .RS
/* .IP SMTP_GET_FLAG_SKIP
/* Skip over input in excess of \fImaxlen\fR). Either way, a result
/* value of '\n' means that the input did not exceed \fImaxlen\fR.
/* .IP SMTP_GET_FLAG_APPEND
/* Append content to the buffer instead of overwriting it.
/* .RE
/* Specify SMTP_GET_FLAG_NONE for no special processing.
/*
/* smtp_fputs() writes its string argument to the named stream.
/* Long strings are not broken. Each string is followed by a
/* CR LF pair. The stream is not flushed.
/*
/* smtp_fwrite() writes its string argument to the named stream.
/* Long strings are not broken. No CR LF is appended. The stream
/* is not flushed.
/*
/* smtp_fread_buf() invokes vstream_fread_buf() to read the
/* specified number of unformatted bytes from the stream. The
/* result is not null-terminated. NOTE: do not skip calling
/* smtp_fread_buf() when len == 0. This function has side
/* effects including resetting the buffer write position, and
/* skipping the call would invalidate the buffer state.
/*
/* smtp_fputc() writes one character to the named stream.
/* The stream is not flushed.
/*
/* smtp_vprintf() is the machine underneath smtp_printf().
/*
/* smtp_get_noexcept() implements the subset of smtp_get()
/* without timeouts and without making long jumps. Instead,
/* query the stream status with vstream_feof() etc.
/*
/* This function assigns smtp_got_bare_lf = smtp_detect_bare_lf,
/* if smtp_detect_bare_lf is non-zero and the last read line
/* was terminated with a bare newline. Otherwise, this function
/* sets smtp_got_bare_lf to zero.
/*
/* smtp_timeout_setup() is a backwards-compatibility interface
/* for programs that don't require per-record deadline support.
/* DIAGNOSTICS
/* .fi
/* .ad
/* In case of error, a vstream_longjmp() call is performed to the
/* context specified with vstream_setjmp().
/* After write error, further writes to the socket are disabled.
/* This eliminates the need for clumsy code to avoid unwanted
/* I/O while shutting down a TLS engine or closing a VSTREAM.
/* Error codes passed along with vstream_longjmp() are:
/* .IP SMTP_ERR_EOF
/* An I/O error happened, or the peer has disconnected unexpectedly.
/* .IP SMTP_ERR_TIME
/* The time limit specified to smtp_stream_setup() was exceeded.
/* .PP
/* Additional error codes that may be used by applications:
/* .IP SMTP_ERR_QUIET
/* Perform silent cleanup; the error was already reported by
/* the application.
/* This error is never generated by the smtp_stream(3) module, but
/* is defined for application-specific use.
/* .IP SMTP_ERR_DATA
/* Application data error - the program cannot proceed with this
/* SMTP session.
/* .IP SMTP_ERR_NONE
/* A non-error code that makes setjmp()/longjmp() convenient
/* to use.
/* BUGS
/* The timeout deadline affects all I/O on the named stream, not
/* just the I/O done on behalf of this module.
/*
/* The timeout deadline overwrites any previously set up state on
/* the named stream.
/* LICENSE
/* .ad
/* .fi
/* The Secure Mailer license must be distributed with this software.
/* AUTHOR(S)
/* Wietse Venema
/* IBM T.J. Watson Research
/* P.O. Box 704
/* Yorktown Heights, NY 10598, USA
/*
/* Wietse Venema
/* Google, Inc.
/* 111 8th Avenue
/* New York, NY 10011, USA
/*--*/
/* System library. */
#include <sys_defs.h>
#include <sys/socket.h>
#include <sys/time.h>
#include <setjmp.h>
#include <stdlib.h>
#include <stdarg.h>
#include <unistd.h>
#include <string.h> /* FD_ZERO() needs bzero() prototype */
#include <errno.h>
/* Utility library. */
#include <vstring.h>
#include <vstream.h>
#include <vstring_vstream.h>
#include <msg.h>
#include <iostuff.h>
/* Application-specific. */
#include "smtp_stream.h"
int smtp_detect_bare_lf;
int smtp_got_bare_lf;
/* smtp_timeout_reset - reset per-stream error flags, restart deadline timer */
static void smtp_timeout_reset(VSTREAM *stream)
{
vstream_clearerr(stream);
/*
* Important: the time limit feature must not introduce any system calls
* when the input is already in the buffer, or when the output still fits
* in the buffer. Such system calls would really hurt when receiving or
* sending body content one line at a time.
*/
if (vstream_fstat(stream, VSTREAM_FLAG_DEADLINE))
vstream_control(stream, CA_VSTREAM_CTL_START_DEADLINE, CA_VSTREAM_CTL_END);
}
/* smtp_longjmp - raise an exception */
static NORETURN smtp_longjmp(VSTREAM *stream, int err, const char *context)
{
/*
* If we failed to write, don't bang our head against the wall another
* time when closing the stream. In the case of SMTP over TLS, poisoning
* the socket with shutdown() is more robust than purging the VSTREAM
* buffer or replacing the write function pointer with dummy_write().
*/
if (msg_verbose)
msg_info("%s: %s", context, err == SMTP_ERR_TIME ? "timeout" : "EOF");
if (vstream_wr_error(stream))
/* Don't report ECONNRESET (hangup), EINVAL (already shut down), etc. */
(void) shutdown(vstream_fileno(stream), SHUT_WR);
vstream_longjmp(stream, err);
}
/* smtp_stream_setup - configure timeout trap */
void smtp_stream_setup(VSTREAM *stream, int maxtime, int enable_deadline)
{
const char *myname = "smtp_stream_setup";
if (msg_verbose)
msg_info("%s: maxtime=%d enable_deadline=%d",
myname, maxtime, enable_deadline);
vstream_control(stream,
CA_VSTREAM_CTL_DOUBLE,
CA_VSTREAM_CTL_TIMEOUT(maxtime),
enable_deadline ? CA_VSTREAM_CTL_START_DEADLINE
: CA_VSTREAM_CTL_STOP_DEADLINE,
CA_VSTREAM_CTL_EXCEPT,
CA_VSTREAM_CTL_END);
}
/* smtp_flush - flush stream */
void smtp_flush(VSTREAM *stream)
{
int err;
/*
* Do the I/O, protected against timeout.
*/
smtp_timeout_reset(stream);
err = vstream_fflush(stream);
/*
* See if there was a problem.
*/
if (vstream_ftimeout(stream))
smtp_longjmp(stream, SMTP_ERR_TIME, "smtp_flush");
if (err != 0)
smtp_longjmp(stream, SMTP_ERR_EOF, "smtp_flush");
}
/* smtp_vprintf - write one line to SMTP peer */
void smtp_vprintf(VSTREAM *stream, const char *fmt, va_list ap)
{
int err;
/*
* Do the I/O, protected against timeout.
*/
smtp_timeout_reset(stream);
vstream_vfprintf(stream, fmt, ap);
vstream_fputs("\r\n", stream);
err = vstream_ferror(stream);
/*
* See if there was a problem.
*/
if (vstream_ftimeout(stream))
smtp_longjmp(stream, SMTP_ERR_TIME, "smtp_vprintf");
if (err != 0)
smtp_longjmp(stream, SMTP_ERR_EOF, "smtp_vprintf");
}
/* smtp_printf - write one line to SMTP peer */
void smtp_printf(VSTREAM *stream, const char *fmt,...)
{
va_list ap;
va_start(ap, fmt);
smtp_vprintf(stream, fmt, ap);
va_end(ap);
}
/* smtp_fgetc - read one character from SMTP peer */
int smtp_fgetc(VSTREAM *stream)
{
int ch;
/*
* Do the I/O, protected against timeout.
*/
smtp_timeout_reset(stream);
ch = VSTREAM_GETC(stream);
/*
* See if there was a problem.
*/
if (vstream_ftimeout(stream))
smtp_longjmp(stream, SMTP_ERR_TIME, "smtp_fgetc");
if (vstream_feof(stream) || vstream_ferror(stream))
smtp_longjmp(stream, SMTP_ERR_EOF, "smtp_fgetc");
return (ch);
}
/* smtp_get - read one line from SMTP peer */
int smtp_get(VSTRING *vp, VSTREAM *stream, ssize_t bound, int flags)
{
int last_char;
/*
* Do the I/O, protected against timeout.
*/
smtp_timeout_reset(stream);
last_char = smtp_get_noexcept(vp, stream, bound, flags);
/*
* EOF is bad, whether or not it happens in the middle of a record. Don't
* allow data that was truncated because of EOF.
*/
if (vstream_ftimeout(stream))
smtp_longjmp(stream, SMTP_ERR_TIME, "smtp_get");
if (vstream_feof(stream) || vstream_ferror(stream))
smtp_longjmp(stream, SMTP_ERR_EOF, "smtp_get");
return (last_char);
}
/* smtp_get_noexcept - read one line from SMTP peer, without exceptions */
int smtp_get_noexcept(VSTRING *vp, VSTREAM *stream, ssize_t bound, int flags)
{
int last_char;
int next_char;
smtp_got_bare_lf = 0;
/*
* It's painful to do I/O with records that may span multiple buffers.
* Allow for partial long lines (we will read the remainder later) and
* allow for lines ending in bare LF. The idea is to be liberal in what
* we accept, strict in what we send.
*
* XXX 2821: Section 4.1.1.4 says that an SMTP server must not recognize
* bare LF as record terminator.
*/
last_char = (bound == 0 ?
vstring_get_flags(vp, stream,
(flags & SMTP_GET_FLAG_APPEND) ?
VSTRING_GET_FLAG_APPEND : 0) :
vstring_get_flags_bound(vp, stream,
(flags & SMTP_GET_FLAG_APPEND) ?
VSTRING_GET_FLAG_APPEND : 0, bound));
switch (last_char) {
/*
* Do some repair in the rare case that we stopped reading in the
* middle of the CRLF record terminator.
*/
case '\r':
if ((next_char = VSTREAM_GETC(stream)) == '\n') {
VSTRING_ADDCH(vp, '\n');
last_char = '\n';
/* FALLTRHOUGH */
} else {
if (next_char != VSTREAM_EOF)
vstream_ungetc(stream, next_char);
break;
}
/*
* Strip off the record terminator: either CRLF or just bare LF.
*
* XXX RFC 2821 disallows sending bare CR everywhere. We remove bare CR
* if received before CRLF, and leave it alone otherwise.
*/
case '\n':
vstring_truncate(vp, VSTRING_LEN(vp) - 1);
if (smtp_detect_bare_lf) {
if (VSTRING_LEN(vp) == 0 || vstring_end(vp)[-1] != '\r')
smtp_got_bare_lf = smtp_detect_bare_lf;
else
vstring_truncate(vp, VSTRING_LEN(vp) - 1);
} else {
while (VSTRING_LEN(vp) > 0 && vstring_end(vp)[-1] == '\r')
vstring_truncate(vp, VSTRING_LEN(vp) - 1);
}
VSTRING_TERMINATE(vp);
/* FALLTRHOUGH */
/*
* Partial line: just read the remainder later. If we ran into EOF,
* the next test will deal with it.
*/
default:
break;
}
/*
* Optionally, skip over excess input, protected by the same time limit.
*/
if (last_char != '\n' && (flags & SMTP_GET_FLAG_SKIP)
&& vstream_feof(stream) == 0 && vstream_ferror(stream) == 0)
while ((next_char = VSTREAM_GETC(stream)) != VSTREAM_EOF
&& next_char != '\n')
/* void */ ;
return (last_char);
}
/* smtp_fputs - write one line to SMTP peer */
void smtp_fputs(const char *cp, ssize_t todo, VSTREAM *stream)
{
int err;
if (todo < 0)
msg_panic("smtp_fputs: negative todo %ld", (long) todo);
/*
* Do the I/O, protected against timeout.
*/
smtp_timeout_reset(stream);
err = (vstream_fwrite(stream, cp, todo) != todo
|| vstream_fputs("\r\n", stream) == VSTREAM_EOF);
/*
* See if there was a problem.
*/
if (vstream_ftimeout(stream))
smtp_longjmp(stream, SMTP_ERR_TIME, "smtp_fputs");
if (err != 0)
smtp_longjmp(stream, SMTP_ERR_EOF, "smtp_fputs");
}
/* smtp_fwrite - write one string to SMTP peer */
void smtp_fwrite(const char *cp, ssize_t todo, VSTREAM *stream)
{
int err;
if (todo < 0)
msg_panic("smtp_fwrite: negative todo %ld", (long) todo);
/*
* Do the I/O, protected against timeout.
*/
smtp_timeout_reset(stream);
err = (vstream_fwrite(stream, cp, todo) != todo);
/*
* See if there was a problem.
*/
if (vstream_ftimeout(stream))
smtp_longjmp(stream, SMTP_ERR_TIME, "smtp_fwrite");
if (err != 0)
smtp_longjmp(stream, SMTP_ERR_EOF, "smtp_fwrite");
}
/* smtp_fread_buf - read one buffer from SMTP peer */
void smtp_fread_buf(VSTRING *vp, ssize_t todo, VSTREAM *stream)
{
int err;
/*
* Do not return early if todo == 0. We still need the side effects from
* calling vstream_fread_buf() including resetting the buffer write
* position. Skipping the call would invalidate the buffer state.
*/
if (todo < 0)
msg_panic("smtp_fread_buf: negative todo %ld", (long) todo);
/*
* Do the I/O, protected against timeout.
*/
smtp_timeout_reset(stream);
err = (vstream_fread_buf(stream, vp, todo) != todo);
/*
* See if there was a problem.
*/
if (vstream_ftimeout(stream))
smtp_longjmp(stream, SMTP_ERR_TIME, "smtp_fread");
if (err != 0)
smtp_longjmp(stream, SMTP_ERR_EOF, "smtp_fread");
}
/* smtp_fputc - write to SMTP peer */
void smtp_fputc(int ch, VSTREAM *stream)
{
int stat;
/*
* Do the I/O, protected against timeout.
*/
smtp_timeout_reset(stream);
stat = VSTREAM_PUTC(ch, stream);
/*
* See if there was a problem.
*/
if (vstream_ftimeout(stream))
smtp_longjmp(stream, SMTP_ERR_TIME, "smtp_fputc");
if (stat == VSTREAM_EOF)
smtp_longjmp(stream, SMTP_ERR_EOF, "smtp_fputc");
}
|