Commit | Line | Data |
---|---|---|
237e0016 RS |
1 | /* movemail foo bar -- move file foo to file bar, |
2 | locking file foo the way /bin/mail respects. | |
95df8112 GM |
3 | |
4 | Copyright (C) 1986, 1992-1994, 1996, 1999, 2001-2011 | |
5 | Free Software Foundation, Inc. | |
237e0016 RS |
6 | |
7 | This file is part of GNU Emacs. | |
8 | ||
294981c7 | 9 | GNU Emacs is free software: you can redistribute it and/or modify |
93320c23 | 10 | it under the terms of the GNU General Public License as published by |
294981c7 GM |
11 | the Free Software Foundation, either version 3 of the License, or |
12 | (at your option) any later version. | |
93320c23 | 13 | |
237e0016 | 14 | GNU Emacs is distributed in the hope that it will be useful, |
93320c23 JA |
15 | but WITHOUT ANY WARRANTY; without even the implied warranty of |
16 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
17 | GNU General Public License for more details. | |
237e0016 | 18 | |
93320c23 | 19 | You should have received a copy of the GNU General Public License |
294981c7 GM |
20 | along with GNU Emacs. If not, see <http://www.gnu.org/licenses/>. */ |
21 | ||
237e0016 | 22 | |
63cf923d RS |
23 | /* Important notice: defining MAIL_USE_FLOCK or MAIL_USE_LOCKF *will |
24 | cause loss of mail* if you do it on a system that does not normally | |
25 | use flock as its way of interlocking access to inbox files. The | |
26 | setting of MAIL_USE_FLOCK and MAIL_USE_LOCKF *must agree* with the | |
27 | system's own conventions. It is not a choice that is up to you. | |
08d0752f RS |
28 | |
29 | So, if your system uses lock files rather than flock, then the only way | |
30 | you can get proper operation is to enable movemail to write lockfiles there. | |
31 | This means you must either give that directory access modes | |
32 | that permit everyone to write lockfiles in it, or you must make movemail | |
33 | a setuid or setgid program. */ | |
34 | ||
237e0016 RS |
35 | /* |
36 | * Modified January, 1986 by Michael R. Gretzinger (Project Athena) | |
37 | * | |
88c40feb | 38 | * Added POP (Post Office Protocol) service. When compiled -DMAIL_USE_POP |
237e0016 RS |
39 | * movemail will accept input filename arguments of the form |
40 | * "po:username". This will cause movemail to open a connection to | |
41 | * a pop server running on $MAILHOST (environment variable). Movemail | |
42 | * must be setuid to root in order to work with POP. | |
177c0ea7 | 43 | * |
237e0016 RS |
44 | * New module: popmail.c |
45 | * Modified routines: | |
cfa191ff | 46 | * main - added code within #ifdef MAIL_USE_POP; added setuid (getuid ()) |
177c0ea7 | 47 | * after POP code. |
237e0016 RS |
48 | * New routines in movemail.c: |
49 | * get_errmsg - return pointer to system error message | |
50 | * | |
2e82e3c3 RS |
51 | * Modified August, 1993 by Jonathan Kamens (OpenVision Technologies) |
52 | * | |
53 | * Move all of the POP code into a separate file, "pop.c". | |
54 | * Use strerror instead of get_errmsg. | |
55 | * | |
237e0016 RS |
56 | */ |
57 | ||
752fb472 | 58 | #include <config.h> |
237e0016 RS |
59 | #include <sys/types.h> |
60 | #include <sys/stat.h> | |
61 | #include <sys/file.h> | |
e2f9d9af | 62 | #include <stdio.h> |
237e0016 | 63 | #include <errno.h> |
bd41a17d | 64 | #include <time.h> |
cc3b64e8 | 65 | |
fea4325c | 66 | #include <getopt.h> |
f72adc12 | 67 | #include <unistd.h> |
cc3b64e8 DL |
68 | #ifdef HAVE_FCNTL_H |
69 | #include <fcntl.h> | |
70 | #endif | |
1725ae55 AS |
71 | #ifdef HAVE_STRING_H |
72 | #include <string.h> | |
73 | #endif | |
f72adc12 | 74 | #include "syswait.h" |
2e82e3c3 RS |
75 | #ifdef MAIL_USE_POP |
76 | #include "pop.h" | |
77 | #endif | |
237e0016 | 78 | |
91cf09ac RS |
79 | #ifdef MSDOS |
80 | #undef access | |
81 | #endif /* MSDOS */ | |
82 | ||
7f75d5c6 | 83 | #ifdef WINDOWSNT |
677a7bcf | 84 | #include "ntlib.h" |
7f75d5c6 RS |
85 | #undef access |
86 | #undef unlink | |
87 | #define fork() 0 | |
4822b2e5 | 88 | #define wait(var) (*(var) = 0) |
7f75d5c6 RS |
89 | /* Unfortunately, Samba doesn't seem to properly lock Unix files even |
90 | though the locking call succeeds (and indeed blocks local access from | |
91 | other NT programs). If you have direct file access using an NFS | |
92 | client or something other than Samba, the locking call might work | |
677a7bcf RS |
93 | properly - make sure it does before you enable this! |
94 | ||
95 | [18-Feb-97 andrewi] I now believe my comment above to be incorrect, | |
96 | since it was based on a misunderstanding of how locking calls are | |
97 | implemented and used on Unix. */ | |
98 | //#define DISABLE_DIRECT_ACCESS | |
99 | ||
677a7bcf | 100 | #include <fcntl.h> |
7f75d5c6 RS |
101 | #endif /* WINDOWSNT */ |
102 | ||
4ec9a77a RS |
103 | #ifndef F_OK |
104 | #define F_OK 0 | |
105 | #define X_OK 1 | |
106 | #define W_OK 2 | |
107 | #define R_OK 4 | |
108 | #endif | |
237e0016 | 109 | |
76ed5e01 | 110 | #ifdef WINDOWSNT |
237e0016 RS |
111 | #include <sys/locking.h> |
112 | #endif | |
113 | ||
63cf923d RS |
114 | #ifdef MAIL_USE_LOCKF |
115 | #define MAIL_USE_SYSTEM_LOCK | |
116 | #endif | |
117 | ||
118 | #ifdef MAIL_USE_FLOCK | |
119 | #define MAIL_USE_SYSTEM_LOCK | |
120 | #endif | |
121 | ||
4293ba7f RS |
122 | #ifdef MAIL_USE_MMDF |
123 | extern int lk_open (), lk_close (); | |
124 | #endif | |
125 | ||
a4deff3c | 126 | #if !defined (MAIL_USE_SYSTEM_LOCK) && !defined (MAIL_USE_MMDF) && \ |
dd843b6a DL |
127 | (defined (HAVE_LIBMAIL) || defined (HAVE_LIBLOCKFILE)) && \ |
128 | defined (HAVE_MAILLOCK_H) | |
a4deff3c RS |
129 | #include <maillock.h> |
130 | /* We can't use maillock unless we know what directory system mail | |
131 | files appear in. */ | |
132 | #ifdef MAILDIR | |
133 | #define MAIL_USE_MAILLOCK | |
5a9c1e26 | 134 | static char *mail_spool_name (char *); |
a4deff3c RS |
135 | #endif |
136 | #endif | |
137 | ||
1725ae55 | 138 | #ifndef HAVE_STRERROR |
873fbd0b | 139 | char *strerror (int); |
1725ae55 | 140 | #endif |
e2f9d9af | 141 | |
988e88ab J |
142 | static void fatal (const char *s1, const char *s2, const char *s3) NO_RETURN; |
143 | static void error (const char *s1, const char *s2, const char *s3); | |
68441b90 DN |
144 | static void pfatal_with_name (char *name) NO_RETURN; |
145 | static void pfatal_and_delete (char *name) NO_RETURN; | |
988e88ab | 146 | static char *concat (const char *s1, const char *s2, const char *s3); |
1725ae55 | 147 | static long *xmalloc (unsigned int size); |
e2ad23ef | 148 | #ifdef MAIL_USE_POP |
1725ae55 AS |
149 | static int popmail (char *mailbox, char *outfile, int preserve, char *password, int reverse_order); |
150 | static int pop_retr (popserver server, int msgno, FILE *arg); | |
151 | static int mbx_write (char *line, int len, FILE *mbf); | |
152 | static int mbx_delimit_begin (FILE *mbf); | |
153 | static int mbx_delimit_end (FILE *mbf); | |
e2ad23ef | 154 | #endif |
237e0016 RS |
155 | |
156 | /* Nonzero means this is name of a lock file to delete on fatal error. */ | |
b23b5a5b | 157 | static char *delete_lockname; |
237e0016 | 158 | |
e2f9d9af | 159 | int |
873fbd0b | 160 | main (int argc, char **argv) |
237e0016 RS |
161 | { |
162 | char *inname, *outname; | |
163 | int indesc, outdesc; | |
728a982d | 164 | ssize_t nread; |
27d41fb4 | 165 | int wait_status; |
fea4325c | 166 | int c, preserve_mail = 0; |
237e0016 | 167 | |
63cf923d | 168 | #ifndef MAIL_USE_SYSTEM_LOCK |
237e0016 | 169 | struct stat st; |
237e0016 | 170 | int tem; |
529a133c | 171 | char *lockname; |
906ad89d | 172 | char *tempname; |
529a133c | 173 | size_t inname_dirlen; |
237e0016 | 174 | int desc; |
63cf923d | 175 | #endif /* not MAIL_USE_SYSTEM_LOCK */ |
237e0016 | 176 | |
a4deff3c RS |
177 | #ifdef MAIL_USE_MAILLOCK |
178 | char *spool_name; | |
179 | #endif | |
180 | ||
a2997b0f KH |
181 | #ifdef MAIL_USE_POP |
182 | int pop_reverse_order = 0; | |
183 | # define ARGSTR "pr" | |
184 | #else /* ! MAIL_USE_POP */ | |
185 | # define ARGSTR "p" | |
186 | #endif /* MAIL_USE_POP */ | |
187 | ||
51a91f9d CY |
188 | uid_t real_gid = getgid(); |
189 | uid_t priv_gid = getegid(); | |
190 | ||
9112a2a9 AI |
191 | #ifdef WINDOWSNT |
192 | /* Ensure all file i/o is in binary mode. */ | |
193 | _fmode = _O_BINARY; | |
194 | #endif | |
195 | ||
237e0016 RS |
196 | delete_lockname = 0; |
197 | ||
a2997b0f | 198 | while ((c = getopt (argc, argv, ARGSTR)) != EOF) |
e2f9d9af | 199 | { |
fea4325c | 200 | switch (c) { |
a2997b0f KH |
201 | #ifdef MAIL_USE_POP |
202 | case 'r': | |
203 | pop_reverse_order = 1; | |
204 | break; | |
205 | #endif | |
fea4325c RS |
206 | case 'p': |
207 | preserve_mail++; | |
208 | break; | |
209 | default: | |
65396510 | 210 | exit (EXIT_FAILURE); |
fea4325c RS |
211 | } |
212 | } | |
213 | ||
214 | if ( | |
215 | #ifdef MAIL_USE_POP | |
216 | (argc - optind < 2) || (argc - optind > 3) | |
217 | #else | |
218 | (argc - optind != 2) | |
219 | #endif | |
220 | ) | |
221 | { | |
fea4325c | 222 | #ifdef MAIL_USE_POP |
f213f2c0 | 223 | fprintf (stderr, "Usage: movemail [-p] [-r] inbox destfile%s\n", |
bb5618fe | 224 | " [POP-password]"); |
fea4325c | 225 | #else |
bb5618fe | 226 | fprintf (stderr, "Usage: movemail [-p] inbox destfile%s\n", ""); |
fea4325c | 227 | #endif |
65396510 | 228 | exit (EXIT_FAILURE); |
e2f9d9af | 229 | } |
237e0016 | 230 | |
fea4325c RS |
231 | inname = argv[optind]; |
232 | outname = argv[optind+1]; | |
237e0016 | 233 | |
4293ba7f RS |
234 | #ifdef MAIL_USE_MMDF |
235 | mmdf_init (argv[0]); | |
236 | #endif | |
237 | ||
af7bd34e | 238 | if (*outname == 0) |
a9eedf40 | 239 | fatal ("Destination file name is empty", 0, 0); |
af7bd34e | 240 | |
237e0016 | 241 | #ifdef MAIL_USE_POP |
12a0565a | 242 | if (!strncmp (inname, "po:", 3)) |
237e0016 | 243 | { |
b3112191 | 244 | int status; |
237e0016 | 245 | |
fea4325c | 246 | status = popmail (inname + 3, outname, preserve_mail, |
a2997b0f KH |
247 | (argc - optind == 3) ? argv[optind+2] : NULL, |
248 | pop_reverse_order); | |
237e0016 RS |
249 | exit (status); |
250 | } | |
251 | ||
51a91f9d CY |
252 | if (setuid (getuid ()) < 0) |
253 | fatal ("Failed to drop privileges", 0, 0); | |
254 | ||
237e0016 RS |
255 | #endif /* MAIL_USE_POP */ |
256 | ||
7f75d5c6 | 257 | #ifndef DISABLE_DIRECT_ACCESS |
4293ba7f | 258 | #ifndef MAIL_USE_MMDF |
63cf923d | 259 | #ifndef MAIL_USE_SYSTEM_LOCK |
a4deff3c RS |
260 | #ifdef MAIL_USE_MAILLOCK |
261 | spool_name = mail_spool_name (inname); | |
5a9c1e26 PE |
262 | if (spool_name) |
263 | { | |
264 | #ifdef lint | |
265 | lockname = 0; | |
266 | #endif | |
267 | } | |
268 | else | |
a4deff3c | 269 | #endif |
237e0016 | 270 | { |
5ecec6a7 PE |
271 | #ifndef DIRECTORY_SEP |
272 | #define DIRECTORY_SEP '/' | |
273 | #endif | |
274 | #ifndef IS_DIRECTORY_SEP | |
275 | #define IS_DIRECTORY_SEP(_c_) ((_c_) == DIRECTORY_SEP) | |
276 | #endif | |
277 | ||
a4deff3c RS |
278 | /* Use a lock file named after our first argument with .lock appended: |
279 | If it exists, the mail file is locked. */ | |
280 | /* Note: this locking mechanism is *required* by the mailer | |
281 | (on systems which use it) to prevent loss of mail. | |
282 | ||
283 | On systems that use a lock file, extracting the mail without locking | |
284 | WILL occasionally cause loss of mail due to timing errors! | |
285 | ||
286 | So, if creation of the lock file fails | |
287 | due to access permission on the mail spool directory, | |
288 | you simply MUST change the permission | |
289 | and/or make movemail a setgid program | |
290 | so it can create lock files properly. | |
291 | ||
292 | You might also wish to verify that your system is one | |
293 | which uses lock files for this purpose. Some systems use other methods. | |
294 | ||
295 | If your system uses the `flock' system call for mail locking, | |
296 | define MAIL_USE_SYSTEM_LOCK in config.h or the s-*.h file | |
297 | and recompile movemail. If the s- file for your system | |
298 | should define MAIL_USE_SYSTEM_LOCK but does not, send a bug report | |
299 | to bug-gnu-emacs@prep.ai.mit.edu so we can fix it. */ | |
300 | ||
301 | lockname = concat (inname, ".lock", ""); | |
529a133c PE |
302 | for (inname_dirlen = strlen (inname); |
303 | inname_dirlen && !IS_DIRECTORY_SEP (inname[inname_dirlen - 1]); | |
304 | inname_dirlen--) | |
305 | continue; | |
306 | tempname = (char *) xmalloc (inname_dirlen + sizeof "EXXXXXX"); | |
237e0016 | 307 | |
a4deff3c | 308 | while (1) |
237e0016 | 309 | { |
a4deff3c RS |
310 | /* Create the lock file, but not under the lock file name. */ |
311 | /* Give up if cannot do that. */ | |
529a133c PE |
312 | |
313 | memcpy (tempname, inname, inname_dirlen); | |
314 | strcpy (tempname + inname_dirlen, "EXXXXXX"); | |
315 | #ifdef HAVE_MKSTEMP | |
316 | desc = mkstemp (tempname); | |
317 | #else | |
318 | mktemp (tempname); | |
319 | if (!*tempname) | |
320 | desc = -1; | |
321 | else | |
322 | { | |
323 | unlink (tempname); | |
324 | desc = open (tempname, O_WRONLY | O_CREAT | O_EXCL, 0600); | |
325 | } | |
326 | #endif | |
a4deff3c RS |
327 | if (desc < 0) |
328 | { | |
529a133c | 329 | int mkstemp_errno = errno; |
a4deff3c | 330 | char *message = (char *) xmalloc (strlen (tempname) + 50); |
4b265472 | 331 | sprintf (message, "creating %s, which would become the lock file", |
a4deff3c | 332 | tempname); |
529a133c | 333 | errno = mkstemp_errno; |
a4deff3c RS |
334 | pfatal_with_name (message); |
335 | } | |
336 | close (desc); | |
337 | ||
338 | tem = link (tempname, lockname); | |
097e9c90 CY |
339 | |
340 | #ifdef EPERM | |
341 | if (tem < 0 && errno == EPERM) | |
342 | fatal ("Unable to create hard link between %s and %s", | |
343 | tempname, lockname); | |
344 | #endif | |
345 | ||
a4deff3c RS |
346 | unlink (tempname); |
347 | if (tem >= 0) | |
348 | break; | |
349 | sleep (1); | |
350 | ||
351 | /* If lock file is five minutes old, unlock it. | |
352 | Five minutes should be good enough to cope with crashes | |
353 | and wedgitude, and long enough to avoid being fooled | |
354 | by time differences between machines. */ | |
355 | if (stat (lockname, &st) >= 0) | |
356 | { | |
5a9c1e26 | 357 | time_t now = time (0); |
a4deff3c RS |
358 | if (st.st_ctime < now - 300) |
359 | unlink (lockname); | |
360 | } | |
237e0016 | 361 | } |
237e0016 | 362 | |
a4deff3c RS |
363 | delete_lockname = lockname; |
364 | } | |
63cf923d RS |
365 | #endif /* not MAIL_USE_SYSTEM_LOCK */ |
366 | #endif /* not MAIL_USE_MMDF */ | |
237e0016 | 367 | |
8ca83cfd RS |
368 | if (fork () == 0) |
369 | { | |
25025815 | 370 | int lockcount = 0; |
a4deff3c RS |
371 | int status = 0; |
372 | #if defined (MAIL_USE_MAILLOCK) && defined (HAVE_TOUCHLOCK) | |
5a9c1e26 PE |
373 | time_t touched_lock; |
374 | # ifdef lint | |
375 | touched_lock = 0; | |
376 | # endif | |
a4deff3c | 377 | #endif |
25025815 | 378 | |
fbf4af3a | 379 | if (setuid (getuid ()) < 0 || setregid (-1, real_gid) < 0) |
51a91f9d | 380 | fatal ("Failed to drop privileges", 0, 0); |
8ca83cfd | 381 | |
63cf923d RS |
382 | #ifndef MAIL_USE_MMDF |
383 | #ifdef MAIL_USE_SYSTEM_LOCK | |
8ca83cfd | 384 | indesc = open (inname, O_RDWR); |
63cf923d | 385 | #else /* if not MAIL_USE_SYSTEM_LOCK */ |
8ca83cfd | 386 | indesc = open (inname, O_RDONLY); |
63cf923d | 387 | #endif /* not MAIL_USE_SYSTEM_LOCK */ |
8ca83cfd RS |
388 | #else /* MAIL_USE_MMDF */ |
389 | indesc = lk_open (inname, O_RDONLY, 0, 0, 10); | |
4293ba7f RS |
390 | #endif /* MAIL_USE_MMDF */ |
391 | ||
8ca83cfd RS |
392 | if (indesc < 0) |
393 | pfatal_with_name (inname); | |
237e0016 | 394 | |
76ed5e01 | 395 | #ifdef BSD_SYSTEM |
8ca83cfd RS |
396 | /* In case movemail is setuid to root, make sure the user can |
397 | read the output file. */ | |
398 | /* This is desirable for all systems | |
399 | but I don't want to assume all have the umask system call */ | |
400 | umask (umask (0) & 0333); | |
76ed5e01 | 401 | #endif /* BSD_SYSTEM */ |
8ca83cfd RS |
402 | outdesc = open (outname, O_WRONLY | O_CREAT | O_EXCL, 0666); |
403 | if (outdesc < 0) | |
404 | pfatal_with_name (outname); | |
25025815 | 405 | |
fbf4af3a | 406 | if (setregid (-1, priv_gid) < 0) |
51a91f9d CY |
407 | fatal ("Failed to regain privileges", 0, 0); |
408 | ||
25025815 RS |
409 | /* This label exists so we can retry locking |
410 | after a delay, if it got EAGAIN or EBUSY. */ | |
411 | retry_lock: | |
412 | ||
413 | /* Try to lock it. */ | |
a4deff3c RS |
414 | #ifdef MAIL_USE_MAILLOCK |
415 | if (spool_name) | |
416 | { | |
417 | /* The "0 - " is to make it a negative number if maillock returns | |
418 | non-zero. */ | |
419 | status = 0 - maillock (spool_name, 1); | |
420 | #ifdef HAVE_TOUCHLOCK | |
421 | touched_lock = time (0); | |
422 | #endif | |
423 | lockcount = 5; | |
424 | } | |
425 | else | |
426 | #endif /* MAIL_USE_MAILLOCK */ | |
427 | { | |
63cf923d RS |
428 | #ifdef MAIL_USE_SYSTEM_LOCK |
429 | #ifdef MAIL_USE_LOCKF | |
a4deff3c | 430 | status = lockf (indesc, F_LOCK, 0); |
63cf923d | 431 | #else /* not MAIL_USE_LOCKF */ |
7f75d5c6 | 432 | #ifdef WINDOWSNT |
a4deff3c | 433 | status = locking (indesc, LK_RLCK, -1L); |
237e0016 | 434 | #else |
a4deff3c | 435 | status = flock (indesc, LOCK_EX); |
237e0016 | 436 | #endif |
63cf923d RS |
437 | #endif /* not MAIL_USE_LOCKF */ |
438 | #endif /* MAIL_USE_SYSTEM_LOCK */ | |
a4deff3c | 439 | } |
237e0016 | 440 | |
25025815 RS |
441 | /* If it fails, retry up to 5 times |
442 | for certain failure codes. */ | |
443 | if (status < 0) | |
444 | { | |
445 | if (++lockcount <= 5) | |
446 | { | |
447 | #ifdef EAGAIN | |
448 | if (errno == EAGAIN) | |
449 | { | |
450 | sleep (1); | |
451 | goto retry_lock; | |
452 | } | |
453 | #endif | |
454 | #ifdef EBUSY | |
455 | if (errno == EBUSY) | |
456 | { | |
457 | sleep (1); | |
458 | goto retry_lock; | |
459 | } | |
460 | #endif | |
461 | } | |
462 | ||
463 | pfatal_with_name (inname); | |
464 | } | |
177c0ea7 | 465 | |
08564963 | 466 | { |
8ca83cfd RS |
467 | char buf[1024]; |
468 | ||
469 | while (1) | |
08564963 | 470 | { |
8ca83cfd | 471 | nread = read (indesc, buf, sizeof buf); |
5e5b35c7 RS |
472 | if (nread < 0) |
473 | pfatal_with_name (inname); | |
8ca83cfd RS |
474 | if (nread != write (outdesc, buf, nread)) |
475 | { | |
476 | int saved_errno = errno; | |
477 | unlink (outname); | |
478 | errno = saved_errno; | |
479 | pfatal_with_name (outname); | |
480 | } | |
481 | if (nread < sizeof buf) | |
482 | break; | |
a4deff3c RS |
483 | #if defined (MAIL_USE_MAILLOCK) && defined (HAVE_TOUCHLOCK) |
484 | if (spool_name) | |
485 | { | |
5a9c1e26 | 486 | time_t now = time (0); |
a4deff3c RS |
487 | if (now - touched_lock > 60) |
488 | { | |
489 | touchlock (); | |
490 | touched_lock = now; | |
491 | } | |
492 | } | |
493 | #endif /* MAIL_USE_MAILLOCK */ | |
08564963 | 494 | } |
08564963 | 495 | } |
237e0016 | 496 | |
e397a017 | 497 | #ifdef BSD_SYSTEM |
8ca83cfd RS |
498 | if (fsync (outdesc) < 0) |
499 | pfatal_and_delete (outname); | |
237e0016 RS |
500 | #endif |
501 | ||
51a91f9d | 502 | /* Prevent symlink attacks truncating other users' mailboxes */ |
fbf4af3a | 503 | if (setregid (-1, real_gid) < 0) |
51a91f9d CY |
504 | fatal ("Failed to drop privileges", 0, 0); |
505 | ||
8ca83cfd RS |
506 | /* Check to make sure no errors before we zap the inbox. */ |
507 | if (close (outdesc) != 0) | |
508 | pfatal_and_delete (outname); | |
237e0016 | 509 | |
63cf923d | 510 | #ifdef MAIL_USE_SYSTEM_LOCK |
fea4325c RS |
511 | if (! preserve_mail) |
512 | { | |
9055082e PE |
513 | if (ftruncate (indesc, 0L) != 0) |
514 | pfatal_with_name (inname); | |
b1cb2966 | 515 | } |
63cf923d | 516 | #endif /* MAIL_USE_SYSTEM_LOCK */ |
4293ba7f RS |
517 | |
518 | #ifdef MAIL_USE_MMDF | |
8ca83cfd | 519 | lk_close (indesc, 0, 0, 0); |
4293ba7f | 520 | #else |
8ca83cfd | 521 | close (indesc); |
4293ba7f | 522 | #endif |
237e0016 | 523 | |
63cf923d | 524 | #ifndef MAIL_USE_SYSTEM_LOCK |
fea4325c RS |
525 | if (! preserve_mail) |
526 | { | |
527 | /* Delete the input file; if we can't, at least get rid of its | |
528 | contents. */ | |
e97dd183 | 529 | #ifdef MAIL_UNLINK_SPOOL |
fea4325c RS |
530 | /* This is generally bad to do, because it destroys the permissions |
531 | that were set on the file. Better to just empty the file. */ | |
532 | if (unlink (inname) < 0 && errno != ENOENT) | |
e97dd183 | 533 | #endif /* MAIL_UNLINK_SPOOL */ |
fea4325c RS |
534 | creat (inname, 0600); |
535 | } | |
63cf923d | 536 | #endif /* not MAIL_USE_SYSTEM_LOCK */ |
8ca83cfd | 537 | |
51a91f9d | 538 | /* End of mailbox truncation */ |
fbf4af3a | 539 | if (setregid (-1, priv_gid) < 0) |
51a91f9d CY |
540 | fatal ("Failed to regain privileges", 0, 0); |
541 | ||
a4deff3c RS |
542 | #ifdef MAIL_USE_MAILLOCK |
543 | /* This has to occur in the child, i.e., in the process that | |
544 | acquired the lock! */ | |
545 | if (spool_name) | |
546 | mailunlock (); | |
547 | #endif | |
65396510 | 548 | exit (EXIT_SUCCESS); |
8ca83cfd RS |
549 | } |
550 | ||
27d41fb4 PE |
551 | wait (&wait_status); |
552 | if (!WIFEXITED (wait_status)) | |
65396510 | 553 | exit (EXIT_FAILURE); |
27d41fb4 PE |
554 | else if (WRETCODE (wait_status) != 0) |
555 | exit (WRETCODE (wait_status)); | |
8ca83cfd | 556 | |
63cf923d | 557 | #if !defined (MAIL_USE_MMDF) && !defined (MAIL_USE_SYSTEM_LOCK) |
a4deff3c RS |
558 | #ifdef MAIL_USE_MAILLOCK |
559 | if (! spool_name) | |
560 | #endif /* MAIL_USE_MAILLOCK */ | |
561 | unlink (lockname); | |
63cf923d | 562 | #endif /* not MAIL_USE_MMDF and not MAIL_USE_SYSTEM_LOCK */ |
7f75d5c6 RS |
563 | |
564 | #endif /* ! DISABLE_DIRECT_ACCESS */ | |
565 | ||
65396510 | 566 | return EXIT_SUCCESS; |
237e0016 | 567 | } |
a4deff3c RS |
568 | |
569 | #ifdef MAIL_USE_MAILLOCK | |
570 | /* This function uses stat to confirm that the mail directory is | |
571 | identical to the directory of the input file, rather than just | |
572 | string-comparing the two paths, because one or both of them might | |
573 | be symbolic links pointing to some other directory. */ | |
574 | static char * | |
728a982d | 575 | mail_spool_name (char *inname) |
a4deff3c RS |
576 | { |
577 | struct stat stat1, stat2; | |
578 | char *indir, *fname; | |
579 | int status; | |
580 | ||
8966b757 | 581 | if (! (fname = strrchr (inname, '/'))) |
a4deff3c RS |
582 | return NULL; |
583 | ||
584 | fname++; | |
585 | ||
586 | if (stat (MAILDIR, &stat1) < 0) | |
587 | return NULL; | |
588 | ||
589 | indir = (char *) xmalloc (fname - inname + 1); | |
590 | strncpy (indir, inname, fname - inname); | |
591 | indir[fname-inname] = '\0'; | |
592 | ||
593 | ||
594 | status = stat (indir, &stat2); | |
595 | ||
596 | free (indir); | |
597 | ||
598 | if (status < 0) | |
599 | return NULL; | |
600 | ||
c4009c1f RS |
601 | if (stat1.st_dev == stat2.st_dev |
602 | && stat1.st_ino == stat2.st_ino) | |
a4deff3c RS |
603 | return fname; |
604 | ||
605 | return NULL; | |
606 | } | |
607 | #endif /* MAIL_USE_MAILLOCK */ | |
237e0016 RS |
608 | \f |
609 | /* Print error message and exit. */ | |
610 | ||
1725ae55 | 611 | static void |
988e88ab | 612 | fatal (const char *s1, const char *s2, const char *s3) |
237e0016 RS |
613 | { |
614 | if (delete_lockname) | |
615 | unlink (delete_lockname); | |
a9eedf40 | 616 | error (s1, s2, s3); |
65396510 | 617 | exit (EXIT_FAILURE); |
237e0016 RS |
618 | } |
619 | ||
cc3b64e8 DL |
620 | /* Print error message. `s1' is printf control string, `s2' and `s3' |
621 | are args for it or null. */ | |
237e0016 | 622 | |
1725ae55 | 623 | static void |
988e88ab | 624 | error (const char *s1, const char *s2, const char *s3) |
237e0016 | 625 | { |
e2f9d9af | 626 | fprintf (stderr, "movemail: "); |
cc3b64e8 DL |
627 | if (s3) |
628 | fprintf (stderr, s1, s2, s3); | |
629 | else if (s2) | |
630 | fprintf (stderr, s1, s2); | |
631 | else | |
3b3807f8 | 632 | fprintf (stderr, "%s", s1); |
e2f9d9af | 633 | fprintf (stderr, "\n"); |
237e0016 RS |
634 | } |
635 | ||
1725ae55 | 636 | static void |
873fbd0b | 637 | pfatal_with_name (char *name) |
237e0016 | 638 | { |
a9eedf40 | 639 | fatal ("%s for %s", strerror (errno), name); |
237e0016 RS |
640 | } |
641 | ||
1725ae55 | 642 | static void |
873fbd0b | 643 | pfatal_and_delete (char *name) |
cfa191ff | 644 | { |
a9eedf40 | 645 | char *s = strerror (errno); |
cfa191ff | 646 | unlink (name); |
a9eedf40 | 647 | fatal ("%s for %s", s, name); |
cfa191ff RS |
648 | } |
649 | ||
237e0016 RS |
650 | /* Return a newly-allocated string whose contents concatenate those of s1, s2, s3. */ |
651 | ||
1725ae55 | 652 | static char * |
988e88ab | 653 | concat (const char *s1, const char *s2, const char *s3) |
237e0016 | 654 | { |
728a982d | 655 | size_t len1 = strlen (s1), len2 = strlen (s2), len3 = strlen (s3); |
237e0016 RS |
656 | char *result = (char *) xmalloc (len1 + len2 + len3 + 1); |
657 | ||
658 | strcpy (result, s1); | |
659 | strcpy (result + len1, s2); | |
660 | strcpy (result + len1 + len2, s3); | |
661 | *(result + len1 + len2 + len3) = 0; | |
662 | ||
663 | return result; | |
664 | } | |
665 | ||
666 | /* Like malloc but get fatal error if memory is exhausted. */ | |
667 | ||
1725ae55 | 668 | static long * |
873fbd0b | 669 | xmalloc (unsigned int size) |
237e0016 | 670 | { |
2583d6d7 | 671 | long *result = (long *) malloc (size); |
237e0016 | 672 | if (!result) |
a9eedf40 | 673 | fatal ("virtual memory exhausted", 0, 0); |
237e0016 RS |
674 | return result; |
675 | } | |
676 | \f | |
677 | /* This is the guts of the interface to the Post Office Protocol. */ | |
678 | ||
679 | #ifdef MAIL_USE_POP | |
680 | ||
7f75d5c6 | 681 | #ifndef WINDOWSNT |
237e0016 RS |
682 | #include <sys/socket.h> |
683 | #include <netinet/in.h> | |
684 | #include <netdb.h> | |
7f75d5c6 RS |
685 | #else |
686 | #undef _WINSOCKAPI_ | |
687 | #include <winsock.h> | |
688 | #endif | |
cecf0f21 | 689 | #include <pwd.h> |
d228a23c | 690 | #include <string.h> |
237e0016 | 691 | |
237e0016 RS |
692 | #define NOTOK (-1) |
693 | #define OK 0 | |
237e0016 | 694 | |
b23b5a5b | 695 | static char Errmsg[200]; /* POP errors, at least, can exceed |
752fb472 | 696 | the original length of 80. */ |
237e0016 | 697 | |
476b2799 | 698 | /* |
4d90eee4 | 699 | * The full valid syntax for a POP mailbox specification for movemail |
476b2799 GM |
700 | * is "po:username:hostname". The ":hostname" is optional; if it is |
701 | * omitted, the MAILHOST environment variable will be consulted. Note | |
702 | * that by the time popmail() is called the "po:" has been stripped | |
703 | * off of the front of the mailbox name. | |
704 | * | |
705 | * If the mailbox is in the form "po:username:hostname", then it is | |
706 | * modified by this function -- the second colon is replaced by a | |
707 | * null. | |
65396510 TTN |
708 | * |
709 | * Return a value suitable for passing to `exit'. | |
476b2799 GM |
710 | */ |
711 | ||
1725ae55 | 712 | static int |
873fbd0b | 713 | popmail (char *mailbox, char *outfile, int preserve, char *password, int reverse_order) |
237e0016 | 714 | { |
b1ce62a8 | 715 | int nmsgs, nbytes; |
b1ce62a8 RS |
716 | register int i; |
717 | int mbfi; | |
718 | FILE *mbf; | |
873fbd0b | 719 | char *getenv (const char *); |
b32701a7 | 720 | popserver server; |
a2997b0f | 721 | int start, end, increment; |
476b2799 GM |
722 | char *user, *hostname; |
723 | ||
724 | user = mailbox; | |
8966b757 | 725 | if ((hostname = strchr (mailbox, ':'))) |
476b2799 | 726 | *hostname++ = '\0'; |
237e0016 | 727 | |
476b2799 | 728 | server = pop_open (hostname, user, password, POP_NO_GETPASS); |
2e82e3c3 | 729 | if (! server) |
b1ce62a8 | 730 | { |
cc3b64e8 | 731 | error ("Error connecting to POP server: %s", pop_error, 0); |
65396510 | 732 | return EXIT_FAILURE; |
237e0016 RS |
733 | } |
734 | ||
2e82e3c3 | 735 | if (pop_stat (server, &nmsgs, &nbytes)) |
b1ce62a8 | 736 | { |
cc3b64e8 | 737 | error ("Error getting message count from POP server: %s", pop_error, 0); |
65396510 | 738 | return EXIT_FAILURE; |
237e0016 RS |
739 | } |
740 | ||
b1ce62a8 RS |
741 | if (!nmsgs) |
742 | { | |
2e82e3c3 | 743 | pop_close (server); |
65396510 | 744 | return EXIT_SUCCESS; |
b1ce62a8 RS |
745 | } |
746 | ||
747 | mbfi = open (outfile, O_WRONLY | O_CREAT | O_EXCL, 0666); | |
748 | if (mbfi < 0) | |
749 | { | |
2e82e3c3 RS |
750 | pop_close (server); |
751 | error ("Error in open: %s, %s", strerror (errno), outfile); | |
65396510 | 752 | return EXIT_FAILURE; |
b1ce62a8 | 753 | } |
f0939c31 PE |
754 | |
755 | if (fchown (mbfi, getuid (), -1) != 0) | |
756 | { | |
757 | int fchown_errno = errno; | |
758 | struct stat st; | |
759 | if (fstat (mbfi, &st) != 0 || st.st_uid != getuid ()) | |
760 | { | |
761 | pop_close (server); | |
762 | error ("Error in fchown: %s, %s", strerror (fchown_errno), outfile); | |
763 | return EXIT_FAILURE; | |
764 | } | |
765 | } | |
b1ce62a8 | 766 | |
7f75d5c6 | 767 | if ((mbf = fdopen (mbfi, "wb")) == NULL) |
b1ce62a8 | 768 | { |
2e82e3c3 | 769 | pop_close (server); |
cc3b64e8 | 770 | error ("Error in fdopen: %s", strerror (errno), 0); |
2e82e3c3 RS |
771 | close (mbfi); |
772 | unlink (outfile); | |
65396510 | 773 | return EXIT_FAILURE; |
b1ce62a8 RS |
774 | } |
775 | ||
a2997b0f KH |
776 | if (reverse_order) |
777 | { | |
778 | start = nmsgs; | |
779 | end = 1; | |
780 | increment = -1; | |
781 | } | |
782 | else | |
783 | { | |
784 | start = 1; | |
785 | end = nmsgs; | |
786 | increment = 1; | |
787 | } | |
788 | ||
789 | for (i = start; i * increment <= end * increment; i += increment) | |
b1ce62a8 RS |
790 | { |
791 | mbx_delimit_begin (mbf); | |
ff804ff5 | 792 | if (pop_retr (server, i, mbf) != OK) |
b1ce62a8 | 793 | { |
17a60964 | 794 | error ("%s", Errmsg, 0); |
b1ce62a8 | 795 | close (mbfi); |
65396510 | 796 | return EXIT_FAILURE; |
237e0016 | 797 | } |
b1ce62a8 RS |
798 | mbx_delimit_end (mbf); |
799 | fflush (mbf); | |
2e82e3c3 RS |
800 | if (ferror (mbf)) |
801 | { | |
cc3b64e8 | 802 | error ("Error in fflush: %s", strerror (errno), 0); |
2e82e3c3 RS |
803 | pop_close (server); |
804 | close (mbfi); | |
65396510 | 805 | return EXIT_FAILURE; |
2e82e3c3 | 806 | } |
237e0016 RS |
807 | } |
808 | ||
2e82e3c3 RS |
809 | /* On AFS, a call to write only modifies the file in the local |
810 | * workstation's AFS cache. The changes are not written to the server | |
811 | * until a call to fsync or close is made. Users with AFS home | |
812 | * directories have lost mail when over quota because these checks were | |
813 | * not made in previous versions of movemail. */ | |
814 | ||
e397a017 | 815 | #ifdef BSD_SYSTEM |
cfa191ff RS |
816 | if (fsync (mbfi) < 0) |
817 | { | |
08fa58c9 | 818 | error ("Error in fsync: %s", strerror (errno), 0); |
65396510 | 819 | return EXIT_FAILURE; |
cfa191ff | 820 | } |
340ff9de | 821 | #endif |
cfa191ff RS |
822 | |
823 | if (close (mbfi) == -1) | |
824 | { | |
cc3b64e8 | 825 | error ("Error in close: %s", strerror (errno), 0); |
65396510 | 826 | return EXIT_FAILURE; |
cfa191ff RS |
827 | } |
828 | ||
fea4325c RS |
829 | if (! preserve) |
830 | for (i = 1; i <= nmsgs; i++) | |
831 | { | |
832 | if (pop_delete (server, i)) | |
833 | { | |
cc3b64e8 | 834 | error ("Error from POP server: %s", pop_error, 0); |
fea4325c | 835 | pop_close (server); |
65396510 | 836 | return EXIT_FAILURE; |
fea4325c RS |
837 | } |
838 | } | |
237e0016 | 839 | |
2e82e3c3 | 840 | if (pop_quit (server)) |
b1ce62a8 | 841 | { |
cc3b64e8 | 842 | error ("Error from POP server: %s", pop_error, 0); |
65396510 | 843 | return EXIT_FAILURE; |
237e0016 | 844 | } |
177c0ea7 | 845 | |
65396510 | 846 | return EXIT_SUCCESS; |
237e0016 RS |
847 | } |
848 | ||
1725ae55 | 849 | static int |
873fbd0b | 850 | pop_retr (popserver server, int msgno, FILE *arg) |
237e0016 | 851 | { |
2e82e3c3 RS |
852 | char *line; |
853 | int ret; | |
237e0016 | 854 | |
2e82e3c3 | 855 | if (pop_retrieve_first (server, msgno, &line)) |
b1ce62a8 | 856 | { |
27d41fb4 PE |
857 | char *msg = concat ("Error from POP server: ", pop_error, ""); |
858 | strncpy (Errmsg, msg, sizeof (Errmsg)); | |
2e82e3c3 | 859 | Errmsg[sizeof (Errmsg)-1] = '\0'; |
27d41fb4 | 860 | free (msg); |
2e82e3c3 | 861 | return (NOTOK); |
237e0016 RS |
862 | } |
863 | ||
d89d0243 | 864 | while ((ret = pop_retrieve_next (server, &line)) >= 0) |
b1ce62a8 | 865 | { |
2e82e3c3 RS |
866 | if (! line) |
867 | break; | |
868 | ||
d89d0243 | 869 | if (mbx_write (line, ret, arg) != OK) |
b1ce62a8 | 870 | { |
2e82e3c3 RS |
871 | strcpy (Errmsg, strerror (errno)); |
872 | pop_close (server); | |
873 | return (NOTOK); | |
237e0016 RS |
874 | } |
875 | } | |
237e0016 | 876 | |
2e82e3c3 | 877 | if (ret) |
b1ce62a8 | 878 | { |
27d41fb4 PE |
879 | char *msg = concat ("Error from POP server: ", pop_error, ""); |
880 | strncpy (Errmsg, msg, sizeof (Errmsg)); | |
2e82e3c3 | 881 | Errmsg[sizeof (Errmsg)-1] = '\0'; |
27d41fb4 | 882 | free (msg); |
2e82e3c3 | 883 | return (NOTOK); |
237e0016 RS |
884 | } |
885 | ||
2e82e3c3 | 886 | return (OK); |
237e0016 RS |
887 | } |
888 | ||
1725ae55 | 889 | static int |
873fbd0b | 890 | mbx_write (char *line, int len, FILE *mbf) |
237e0016 | 891 | { |
d04f5031 | 892 | #ifdef MOVEMAIL_QUOTE_POP_FROM_LINES |
5ecec6a7 PE |
893 | /* Do this as a macro instead of using strcmp to save on execution time. */ |
894 | # define IS_FROM_LINE(a) ((a[0] == 'F') \ | |
895 | && (a[1] == 'r') \ | |
896 | && (a[2] == 'o') \ | |
897 | && (a[3] == 'm') \ | |
898 | && (a[4] == ' ')) | |
2e82e3c3 RS |
899 | if (IS_FROM_LINE (line)) |
900 | { | |
901 | if (fputc ('>', mbf) == EOF) | |
902 | return (NOTOK); | |
903 | } | |
d04f5031 PE |
904 | #endif |
905 | if (line[0] == '\037') | |
906 | { | |
907 | if (fputs ("^_", mbf) == EOF) | |
908 | return (NOTOK); | |
909 | line++; | |
910 | len--; | |
911 | } | |
177c0ea7 | 912 | if (fwrite (line, 1, len, mbf) != len) |
2e82e3c3 RS |
913 | return (NOTOK); |
914 | if (fputc (0x0a, mbf) == EOF) | |
915 | return (NOTOK); | |
916 | return (OK); | |
237e0016 RS |
917 | } |
918 | ||
1725ae55 | 919 | static int |
873fbd0b | 920 | mbx_delimit_begin (FILE *mbf) |
237e0016 | 921 | { |
d228a23c GM |
922 | time_t now; |
923 | struct tm *ltime; | |
924 | char fromline[40] = "From movemail "; | |
925 | ||
926 | now = time (NULL); | |
927 | ltime = localtime (&now); | |
928 | ||
929 | strcat (fromline, asctime (ltime)); | |
930 | ||
931 | if (fputs (fromline, mbf) == EOF) | |
2e82e3c3 RS |
932 | return (NOTOK); |
933 | return (OK); | |
237e0016 RS |
934 | } |
935 | ||
1725ae55 | 936 | static int |
873fbd0b | 937 | mbx_delimit_end (FILE *mbf) |
237e0016 | 938 | { |
3f32be22 | 939 | if (putc ('\n', mbf) == EOF) |
2e82e3c3 RS |
940 | return (NOTOK); |
941 | return (OK); | |
237e0016 RS |
942 | } |
943 | ||
944 | #endif /* MAIL_USE_POP */ | |
e5f7ea68 RM |
945 | \f |
946 | #ifndef HAVE_STRERROR | |
947 | char * | |
948 | strerror (errnum) | |
949 | int errnum; | |
950 | { | |
951 | extern char *sys_errlist[]; | |
952 | extern int sys_nerr; | |
953 | ||
954 | if (errnum >= 0 && errnum < sys_nerr) | |
955 | return sys_errlist[errnum]; | |
956 | return (char *) "Unknown error"; | |
957 | } | |
958 | ||
959 | #endif /* ! HAVE_STRERROR */ | |
ab5796a9 | 960 | |
65396510 TTN |
961 | |
962 | /* movemail.c ends here */ |