git-send-email.perlon commit t5313: test bounds-checks of corrupted/malicious pack/idx files (a128386)
   1#!/usr/bin/perl
   2#
   3# Copyright 2002,2005 Greg Kroah-Hartman <greg@kroah.com>
   4# Copyright 2005 Ryan Anderson <ryan@michonline.com>
   5#
   6# GPL v2 (See COPYING)
   7#
   8# Ported to support git "mbox" format files by Ryan Anderson <ryan@michonline.com>
   9#
  10# Sends a collection of emails to the given email addresses, disturbingly fast.
  11#
  12# Supports two formats:
  13# 1. mbox format files (ignoring most headers and MIME formatting - this is designed for sending patches)
  14# 2. The original format support by Greg's script:
  15#    first line of the message is who to CC,
  16#    and second line is the subject of the message.
  17#
  18
  19use 5.008;
  20use strict;
  21use warnings;
  22use Term::ReadLine;
  23use Getopt::Long;
  24use Text::ParseWords;
  25use Data::Dumper;
  26use Term::ANSIColor;
  27use File::Temp qw/ tempdir tempfile /;
  28use File::Spec::Functions qw(catfile);
  29use Error qw(:try);
  30use Git;
  31
  32Getopt::Long::Configure qw/ pass_through /;
  33
  34package FakeTerm;
  35sub new {
  36        my ($class, $reason) = @_;
  37        return bless \$reason, shift;
  38}
  39sub readline {
  40        my $self = shift;
  41        die "Cannot use readline on FakeTerm: $$self";
  42}
  43package main;
  44
  45
  46sub usage {
  47        print <<EOT;
  48git send-email [options] <file | directory | rev-list options >
  49
  50  Composing:
  51    --from                  <str>  * Email From:
  52    --[no-]to               <str>  * Email To:
  53    --[no-]cc               <str>  * Email Cc:
  54    --[no-]bcc              <str>  * Email Bcc:
  55    --subject               <str>  * Email "Subject:"
  56    --in-reply-to           <str>  * Email "In-Reply-To:"
  57    --[no-]xmailer                 * Add "X-Mailer:" header (default).
  58    --[no-]annotate                * Review each patch that will be sent in an editor.
  59    --compose                      * Open an editor for introduction.
  60    --compose-encoding      <str>  * Encoding to assume for introduction.
  61    --8bit-encoding         <str>  * Encoding to assume 8bit mails if undeclared
  62    --transfer-encoding     <str>  * Transfer encoding to use (quoted-printable, 8bit, base64)
  63
  64  Sending:
  65    --envelope-sender       <str>  * Email envelope sender.
  66    --smtp-server       <str:int>  * Outgoing SMTP server to use. The port
  67                                     is optional. Default 'localhost'.
  68    --smtp-server-option    <str>  * Outgoing SMTP server option to use.
  69    --smtp-server-port      <int>  * Outgoing SMTP server port.
  70    --smtp-user             <str>  * Username for SMTP-AUTH.
  71    --smtp-pass             <str>  * Password for SMTP-AUTH; not necessary.
  72    --smtp-encryption       <str>  * tls or ssl; anything else disables.
  73    --smtp-ssl                     * Deprecated. Use '--smtp-encryption ssl'.
  74    --smtp-ssl-cert-path    <str>  * Path to ca-certificates (either directory or file).
  75                                     Pass an empty string to disable certificate
  76                                     verification.
  77    --smtp-domain           <str>  * The domain name sent to HELO/EHLO handshake
  78    --smtp-debug            <0|1>  * Disable, enable Net::SMTP debug.
  79
  80  Automating:
  81    --identity              <str>  * Use the sendemail.<id> options.
  82    --to-cmd                <str>  * Email To: via `<str> \$patch_path`
  83    --cc-cmd                <str>  * Email Cc: via `<str> \$patch_path`
  84    --suppress-cc           <str>  * author, self, sob, cc, cccmd, body, bodycc, all.
  85    --[no-]cc-cover                * Email Cc: addresses in the cover letter.
  86    --[no-]to-cover                * Email To: addresses in the cover letter.
  87    --[no-]signed-off-by-cc        * Send to Signed-off-by: addresses. Default on.
  88    --[no-]suppress-from           * Send to self. Default off.
  89    --[no-]chain-reply-to          * Chain In-Reply-To: fields. Default off.
  90    --[no-]thread                  * Use In-Reply-To: field. Default on.
  91
  92  Administering:
  93    --confirm               <str>  * Confirm recipients before sending;
  94                                     auto, cc, compose, always, or never.
  95    --quiet                        * Output one line of info per email.
  96    --dry-run                      * Don't actually send the emails.
  97    --[no-]validate                * Perform patch sanity checks. Default on.
  98    --[no-]format-patch            * understand any non optional arguments as
  99                                     `git format-patch` ones.
 100    --force                        * Send even if safety checks would prevent it.
 101
 102EOT
 103        exit(1);
 104}
 105
 106# most mail servers generate the Date: header, but not all...
 107sub format_2822_time {
 108        my ($time) = @_;
 109        my @localtm = localtime($time);
 110        my @gmttm = gmtime($time);
 111        my $localmin = $localtm[1] + $localtm[2] * 60;
 112        my $gmtmin = $gmttm[1] + $gmttm[2] * 60;
 113        if ($localtm[0] != $gmttm[0]) {
 114                die "local zone differs from GMT by a non-minute interval\n";
 115        }
 116        if ((($gmttm[6] + 1) % 7) == $localtm[6]) {
 117                $localmin += 1440;
 118        } elsif ((($gmttm[6] - 1) % 7) == $localtm[6]) {
 119                $localmin -= 1440;
 120        } elsif ($gmttm[6] != $localtm[6]) {
 121                die "local time offset greater than or equal to 24 hours\n";
 122        }
 123        my $offset = $localmin - $gmtmin;
 124        my $offhour = $offset / 60;
 125        my $offmin = abs($offset % 60);
 126        if (abs($offhour) >= 24) {
 127                die ("local time offset greater than or equal to 24 hours\n");
 128        }
 129
 130        return sprintf("%s, %2d %s %d %02d:%02d:%02d %s%02d%02d",
 131                       qw(Sun Mon Tue Wed Thu Fri Sat)[$localtm[6]],
 132                       $localtm[3],
 133                       qw(Jan Feb Mar Apr May Jun
 134                          Jul Aug Sep Oct Nov Dec)[$localtm[4]],
 135                       $localtm[5]+1900,
 136                       $localtm[2],
 137                       $localtm[1],
 138                       $localtm[0],
 139                       ($offset >= 0) ? '+' : '-',
 140                       abs($offhour),
 141                       $offmin,
 142                       );
 143}
 144
 145my $have_email_valid = eval { require Email::Valid; 1 };
 146my $have_mail_address = eval { require Mail::Address; 1 };
 147my $smtp;
 148my $auth;
 149
 150# Regexes for RFC 2047 productions.
 151my $re_token = qr/[^][()<>@,;:\\"\/?.= \000-\037\177-\377]+/;
 152my $re_encoded_text = qr/[^? \000-\037\177-\377]+/;
 153my $re_encoded_word = qr/=\?($re_token)\?($re_token)\?($re_encoded_text)\?=/;
 154
 155# Variables we fill in automatically, or via prompting:
 156my (@to,$no_to,@initial_to,@cc,$no_cc,@initial_cc,@bcclist,$no_bcc,@xh,
 157        $initial_reply_to,$initial_subject,@files,
 158        $author,$sender,$smtp_authpass,$annotate,$use_xmailer,$compose,$time);
 159
 160my $envelope_sender;
 161
 162# Example reply to:
 163#$initial_reply_to = ''; #<20050203173208.GA23964@foobar.com>';
 164
 165my $repo = eval { Git->repository() };
 166my @repo = $repo ? ($repo) : ();
 167my $term = eval {
 168        $ENV{"GIT_SEND_EMAIL_NOTTY"}
 169                ? new Term::ReadLine 'git-send-email', \*STDIN, \*STDOUT
 170                : new Term::ReadLine 'git-send-email';
 171};
 172if ($@) {
 173        $term = new FakeTerm "$@: going non-interactive";
 174}
 175
 176# Behavior modification variables
 177my ($quiet, $dry_run) = (0, 0);
 178my $format_patch;
 179my $compose_filename;
 180my $force = 0;
 181
 182# Handle interactive edition of files.
 183my $multiedit;
 184my $editor;
 185
 186sub do_edit {
 187        if (!defined($editor)) {
 188                $editor = Git::command_oneline('var', 'GIT_EDITOR');
 189        }
 190        if (defined($multiedit) && !$multiedit) {
 191                map {
 192                        system('sh', '-c', $editor.' "$@"', $editor, $_);
 193                        if (($? & 127) || ($? >> 8)) {
 194                                die("the editor exited uncleanly, aborting everything");
 195                        }
 196                } @_;
 197        } else {
 198                system('sh', '-c', $editor.' "$@"', $editor, @_);
 199                if (($? & 127) || ($? >> 8)) {
 200                        die("the editor exited uncleanly, aborting everything");
 201                }
 202        }
 203}
 204
 205# Variables with corresponding config settings
 206my ($thread, $chain_reply_to, $suppress_from, $signed_off_by_cc);
 207my ($cover_cc, $cover_to);
 208my ($to_cmd, $cc_cmd);
 209my ($smtp_server, $smtp_server_port, @smtp_server_options);
 210my ($smtp_authuser, $smtp_encryption, $smtp_ssl_cert_path);
 211my ($identity, $aliasfiletype, @alias_files, $smtp_domain);
 212my ($validate, $confirm);
 213my (@suppress_cc);
 214my ($auto_8bit_encoding);
 215my ($compose_encoding);
 216my ($target_xfer_encoding);
 217
 218my ($debug_net_smtp) = 0;               # Net::SMTP, see send_message()
 219
 220my %config_bool_settings = (
 221    "thread" => [\$thread, 1],
 222    "chainreplyto" => [\$chain_reply_to, 0],
 223    "suppressfrom" => [\$suppress_from, undef],
 224    "signedoffbycc" => [\$signed_off_by_cc, undef],
 225    "cccover" => [\$cover_cc, undef],
 226    "tocover" => [\$cover_to, undef],
 227    "signedoffcc" => [\$signed_off_by_cc, undef],      # Deprecated
 228    "validate" => [\$validate, 1],
 229    "multiedit" => [\$multiedit, undef],
 230    "annotate" => [\$annotate, undef],
 231    "xmailer" => [\$use_xmailer, 1]
 232);
 233
 234my %config_settings = (
 235    "smtpserver" => \$smtp_server,
 236    "smtpserverport" => \$smtp_server_port,
 237    "smtpserveroption" => \@smtp_server_options,
 238    "smtpuser" => \$smtp_authuser,
 239    "smtppass" => \$smtp_authpass,
 240    "smtpsslcertpath" => \$smtp_ssl_cert_path,
 241    "smtpdomain" => \$smtp_domain,
 242    "to" => \@initial_to,
 243    "tocmd" => \$to_cmd,
 244    "cc" => \@initial_cc,
 245    "cccmd" => \$cc_cmd,
 246    "aliasfiletype" => \$aliasfiletype,
 247    "bcc" => \@bcclist,
 248    "suppresscc" => \@suppress_cc,
 249    "envelopesender" => \$envelope_sender,
 250    "confirm"   => \$confirm,
 251    "from" => \$sender,
 252    "assume8bitencoding" => \$auto_8bit_encoding,
 253    "composeencoding" => \$compose_encoding,
 254    "transferencoding" => \$target_xfer_encoding,
 255);
 256
 257my %config_path_settings = (
 258    "aliasesfile" => \@alias_files,
 259);
 260
 261# Handle Uncouth Termination
 262sub signal_handler {
 263
 264        # Make text normal
 265        print color("reset"), "\n";
 266
 267        # SMTP password masked
 268        system "stty echo";
 269
 270        # tmp files from --compose
 271        if (defined $compose_filename) {
 272                if (-e $compose_filename) {
 273                        print "'$compose_filename' contains an intermediate version of the email you were composing.\n";
 274                }
 275                if (-e ($compose_filename . ".final")) {
 276                        print "'$compose_filename.final' contains the composed email.\n"
 277                }
 278        }
 279
 280        exit;
 281};
 282
 283$SIG{TERM} = \&signal_handler;
 284$SIG{INT}  = \&signal_handler;
 285
 286# Begin by accumulating all the variables (defined above), that we will end up
 287# needing, first, from the command line:
 288
 289my $help;
 290my $rc = GetOptions("h" => \$help,
 291                    "sender|from=s" => \$sender,
 292                    "in-reply-to=s" => \$initial_reply_to,
 293                    "subject=s" => \$initial_subject,
 294                    "to=s" => \@initial_to,
 295                    "to-cmd=s" => \$to_cmd,
 296                    "no-to" => \$no_to,
 297                    "cc=s" => \@initial_cc,
 298                    "no-cc" => \$no_cc,
 299                    "bcc=s" => \@bcclist,
 300                    "no-bcc" => \$no_bcc,
 301                    "chain-reply-to!" => \$chain_reply_to,
 302                    "no-chain-reply-to" => sub {$chain_reply_to = 0},
 303                    "smtp-server=s" => \$smtp_server,
 304                    "smtp-server-option=s" => \@smtp_server_options,
 305                    "smtp-server-port=s" => \$smtp_server_port,
 306                    "smtp-user=s" => \$smtp_authuser,
 307                    "smtp-pass:s" => \$smtp_authpass,
 308                    "smtp-ssl" => sub { $smtp_encryption = 'ssl' },
 309                    "smtp-encryption=s" => \$smtp_encryption,
 310                    "smtp-ssl-cert-path=s" => \$smtp_ssl_cert_path,
 311                    "smtp-debug:i" => \$debug_net_smtp,
 312                    "smtp-domain:s" => \$smtp_domain,
 313                    "identity=s" => \$identity,
 314                    "annotate!" => \$annotate,
 315                    "no-annotate" => sub {$annotate = 0},
 316                    "compose" => \$compose,
 317                    "quiet" => \$quiet,
 318                    "cc-cmd=s" => \$cc_cmd,
 319                    "suppress-from!" => \$suppress_from,
 320                    "no-suppress-from" => sub {$suppress_from = 0},
 321                    "suppress-cc=s" => \@suppress_cc,
 322                    "signed-off-cc|signed-off-by-cc!" => \$signed_off_by_cc,
 323                    "no-signed-off-cc|no-signed-off-by-cc" => sub {$signed_off_by_cc = 0},
 324                    "cc-cover|cc-cover!" => \$cover_cc,
 325                    "no-cc-cover" => sub {$cover_cc = 0},
 326                    "to-cover|to-cover!" => \$cover_to,
 327                    "no-to-cover" => sub {$cover_to = 0},
 328                    "confirm=s" => \$confirm,
 329                    "dry-run" => \$dry_run,
 330                    "envelope-sender=s" => \$envelope_sender,
 331                    "thread!" => \$thread,
 332                    "no-thread" => sub {$thread = 0},
 333                    "validate!" => \$validate,
 334                    "no-validate" => sub {$validate = 0},
 335                    "transfer-encoding=s" => \$target_xfer_encoding,
 336                    "format-patch!" => \$format_patch,
 337                    "no-format-patch" => sub {$format_patch = 0},
 338                    "8bit-encoding=s" => \$auto_8bit_encoding,
 339                    "compose-encoding=s" => \$compose_encoding,
 340                    "force" => \$force,
 341                    "xmailer!" => \$use_xmailer,
 342                    "no-xmailer" => sub {$use_xmailer = 0},
 343         );
 344
 345usage() if $help;
 346unless ($rc) {
 347    usage();
 348}
 349
 350die "Cannot run git format-patch from outside a repository\n"
 351        if $format_patch and not $repo;
 352
 353# Now, let's fill any that aren't set in with defaults:
 354
 355sub read_config {
 356        my ($prefix) = @_;
 357
 358        foreach my $setting (keys %config_bool_settings) {
 359                my $target = $config_bool_settings{$setting}->[0];
 360                $$target = Git::config_bool(@repo, "$prefix.$setting") unless (defined $$target);
 361        }
 362
 363        foreach my $setting (keys %config_path_settings) {
 364                my $target = $config_path_settings{$setting};
 365                if (ref($target) eq "ARRAY") {
 366                        unless (@$target) {
 367                                my @values = Git::config_path(@repo, "$prefix.$setting");
 368                                @$target = @values if (@values && defined $values[0]);
 369                        }
 370                }
 371                else {
 372                        $$target = Git::config_path(@repo, "$prefix.$setting") unless (defined $$target);
 373                }
 374        }
 375
 376        foreach my $setting (keys %config_settings) {
 377                my $target = $config_settings{$setting};
 378                next if $setting eq "to" and defined $no_to;
 379                next if $setting eq "cc" and defined $no_cc;
 380                next if $setting eq "bcc" and defined $no_bcc;
 381                if (ref($target) eq "ARRAY") {
 382                        unless (@$target) {
 383                                my @values = Git::config(@repo, "$prefix.$setting");
 384                                @$target = @values if (@values && defined $values[0]);
 385                        }
 386                }
 387                else {
 388                        $$target = Git::config(@repo, "$prefix.$setting") unless (defined $$target);
 389                }
 390        }
 391
 392        if (!defined $smtp_encryption) {
 393                my $enc = Git::config(@repo, "$prefix.smtpencryption");
 394                if (defined $enc) {
 395                        $smtp_encryption = $enc;
 396                } elsif (Git::config_bool(@repo, "$prefix.smtpssl")) {
 397                        $smtp_encryption = 'ssl';
 398                }
 399        }
 400}
 401
 402# read configuration from [sendemail "$identity"], fall back on [sendemail]
 403$identity = Git::config(@repo, "sendemail.identity") unless (defined $identity);
 404read_config("sendemail.$identity") if (defined $identity);
 405read_config("sendemail");
 406
 407# fall back on builtin bool defaults
 408foreach my $setting (values %config_bool_settings) {
 409        ${$setting->[0]} = $setting->[1] unless (defined (${$setting->[0]}));
 410}
 411
 412# 'default' encryption is none -- this only prevents a warning
 413$smtp_encryption = '' unless (defined $smtp_encryption);
 414
 415# Set CC suppressions
 416my(%suppress_cc);
 417if (@suppress_cc) {
 418        foreach my $entry (@suppress_cc) {
 419                die "Unknown --suppress-cc field: '$entry'\n"
 420                        unless $entry =~ /^(?:all|cccmd|cc|author|self|sob|body|bodycc)$/;
 421                $suppress_cc{$entry} = 1;
 422        }
 423}
 424
 425if ($suppress_cc{'all'}) {
 426        foreach my $entry (qw (cccmd cc author self sob body bodycc)) {
 427                $suppress_cc{$entry} = 1;
 428        }
 429        delete $suppress_cc{'all'};
 430}
 431
 432# If explicit old-style ones are specified, they trump --suppress-cc.
 433$suppress_cc{'self'} = $suppress_from if defined $suppress_from;
 434$suppress_cc{'sob'} = !$signed_off_by_cc if defined $signed_off_by_cc;
 435
 436if ($suppress_cc{'body'}) {
 437        foreach my $entry (qw (sob bodycc)) {
 438                $suppress_cc{$entry} = 1;
 439        }
 440        delete $suppress_cc{'body'};
 441}
 442
 443# Set confirm's default value
 444my $confirm_unconfigured = !defined $confirm;
 445if ($confirm_unconfigured) {
 446        $confirm = scalar %suppress_cc ? 'compose' : 'auto';
 447};
 448die "Unknown --confirm setting: '$confirm'\n"
 449        unless $confirm =~ /^(?:auto|cc|compose|always|never)/;
 450
 451# Debugging, print out the suppressions.
 452if (0) {
 453        print "suppressions:\n";
 454        foreach my $entry (keys %suppress_cc) {
 455                printf "  %-5s -> $suppress_cc{$entry}\n", $entry;
 456        }
 457}
 458
 459my ($repoauthor, $repocommitter);
 460($repoauthor) = Git::ident_person(@repo, 'author');
 461($repocommitter) = Git::ident_person(@repo, 'committer');
 462
 463# Verify the user input
 464
 465foreach my $entry (@initial_to) {
 466        die "Comma in --to entry: $entry'\n" unless $entry !~ m/,/;
 467}
 468
 469foreach my $entry (@initial_cc) {
 470        die "Comma in --cc entry: $entry'\n" unless $entry !~ m/,/;
 471}
 472
 473foreach my $entry (@bcclist) {
 474        die "Comma in --bcclist entry: $entry'\n" unless $entry !~ m/,/;
 475}
 476
 477sub parse_address_line {
 478        if ($have_mail_address) {
 479                return map { $_->format } Mail::Address->parse($_[0]);
 480        } else {
 481                return split_addrs($_[0]);
 482        }
 483}
 484
 485sub split_addrs {
 486        return quotewords('\s*,\s*', 1, @_);
 487}
 488
 489my %aliases;
 490my %parse_alias = (
 491        # multiline formats can be supported in the future
 492        mutt => sub { my $fh = shift; while (<$fh>) {
 493                if (/^\s*alias\s+(?:-group\s+\S+\s+)*(\S+)\s+(.*)$/) {
 494                        my ($alias, $addr) = ($1, $2);
 495                        $addr =~ s/#.*$//; # mutt allows # comments
 496                         # commas delimit multiple addresses
 497                        $aliases{$alias} = [ split_addrs($addr) ];
 498                }}},
 499        mailrc => sub { my $fh = shift; while (<$fh>) {
 500                if (/^alias\s+(\S+)\s+(.*)$/) {
 501                        # spaces delimit multiple addresses
 502                        $aliases{$1} = [ quotewords('\s+', 0, $2) ];
 503                }}},
 504        pine => sub { my $fh = shift; my $f='\t[^\t]*';
 505                for (my $x = ''; defined($x); $x = $_) {
 506                        chomp $x;
 507                        $x .= $1 while(defined($_ = <$fh>) && /^ +(.*)$/);
 508                        $x =~ /^(\S+)$f\t\(?([^\t]+?)\)?(:?$f){0,2}$/ or next;
 509                        $aliases{$1} = [ split_addrs($2) ];
 510                }},
 511        elm => sub  { my $fh = shift;
 512                      while (<$fh>) {
 513                          if (/^(\S+)\s+=\s+[^=]+=\s(\S+)/) {
 514                              my ($alias, $addr) = ($1, $2);
 515                               $aliases{$alias} = [ split_addrs($addr) ];
 516                          }
 517                      } },
 518
 519        gnus => sub { my $fh = shift; while (<$fh>) {
 520                if (/\(define-mail-alias\s+"(\S+?)"\s+"(\S+?)"\)/) {
 521                        $aliases{$1} = [ $2 ];
 522                }}}
 523);
 524
 525if (@alias_files and $aliasfiletype and defined $parse_alias{$aliasfiletype}) {
 526        foreach my $file (@alias_files) {
 527                open my $fh, '<', $file or die "opening $file: $!\n";
 528                $parse_alias{$aliasfiletype}->($fh);
 529                close $fh;
 530        }
 531}
 532
 533($sender) = expand_aliases($sender) if defined $sender;
 534
 535# is_format_patch_arg($f) returns 0 if $f names a patch, or 1 if
 536# $f is a revision list specification to be passed to format-patch.
 537sub is_format_patch_arg {
 538        return unless $repo;
 539        my $f = shift;
 540        try {
 541                $repo->command('rev-parse', '--verify', '--quiet', $f);
 542                if (defined($format_patch)) {
 543                        return $format_patch;
 544                }
 545                die(<<EOF);
 546File '$f' exists but it could also be the range of commits
 547to produce patches for.  Please disambiguate by...
 548
 549    * Saying "./$f" if you mean a file; or
 550    * Giving --format-patch option if you mean a range.
 551EOF
 552        } catch Git::Error::Command with {
 553                # Not a valid revision.  Treat it as a filename.
 554                return 0;
 555        }
 556}
 557
 558# Now that all the defaults are set, process the rest of the command line
 559# arguments and collect up the files that need to be processed.
 560my @rev_list_opts;
 561while (defined(my $f = shift @ARGV)) {
 562        if ($f eq "--") {
 563                push @rev_list_opts, "--", @ARGV;
 564                @ARGV = ();
 565        } elsif (-d $f and !is_format_patch_arg($f)) {
 566                opendir my $dh, $f
 567                        or die "Failed to opendir $f: $!";
 568
 569                push @files, grep { -f $_ } map { catfile($f, $_) }
 570                                sort readdir $dh;
 571                closedir $dh;
 572        } elsif ((-f $f or -p $f) and !is_format_patch_arg($f)) {
 573                push @files, $f;
 574        } else {
 575                push @rev_list_opts, $f;
 576        }
 577}
 578
 579if (@rev_list_opts) {
 580        die "Cannot run git format-patch from outside a repository\n"
 581                unless $repo;
 582        push @files, $repo->command('format-patch', '-o', tempdir(CLEANUP => 1), @rev_list_opts);
 583}
 584
 585if ($validate) {
 586        foreach my $f (@files) {
 587                unless (-p $f) {
 588                        my $error = validate_patch($f);
 589                        $error and die "fatal: $f: $error\nwarning: no patches were sent\n";
 590                }
 591        }
 592}
 593
 594if (@files) {
 595        unless ($quiet) {
 596                print $_,"\n" for (@files);
 597        }
 598} else {
 599        print STDERR "\nNo patch files specified!\n\n";
 600        usage();
 601}
 602
 603sub get_patch_subject {
 604        my $fn = shift;
 605        open (my $fh, '<', $fn);
 606        while (my $line = <$fh>) {
 607                next unless ($line =~ /^Subject: (.*)$/);
 608                close $fh;
 609                return "GIT: $1\n";
 610        }
 611        close $fh;
 612        die "No subject line in $fn ?";
 613}
 614
 615if ($compose) {
 616        # Note that this does not need to be secure, but we will make a small
 617        # effort to have it be unique
 618        $compose_filename = ($repo ?
 619                tempfile(".gitsendemail.msg.XXXXXX", DIR => $repo->repo_path()) :
 620                tempfile(".gitsendemail.msg.XXXXXX", DIR => "."))[1];
 621        open my $c, ">", $compose_filename
 622                or die "Failed to open for writing $compose_filename: $!";
 623
 624
 625        my $tpl_sender = $sender || $repoauthor || $repocommitter || '';
 626        my $tpl_subject = $initial_subject || '';
 627        my $tpl_reply_to = $initial_reply_to || '';
 628
 629        print $c <<EOT;
 630From $tpl_sender # This line is ignored.
 631GIT: Lines beginning in "GIT:" will be removed.
 632GIT: Consider including an overall diffstat or table of contents
 633GIT: for the patch you are writing.
 634GIT:
 635GIT: Clear the body content if you don't wish to send a summary.
 636From: $tpl_sender
 637Subject: $tpl_subject
 638In-Reply-To: $tpl_reply_to
 639
 640EOT
 641        for my $f (@files) {
 642                print $c get_patch_subject($f);
 643        }
 644        close $c;
 645
 646        if ($annotate) {
 647                do_edit($compose_filename, @files);
 648        } else {
 649                do_edit($compose_filename);
 650        }
 651
 652        open my $c2, ">", $compose_filename . ".final"
 653                or die "Failed to open $compose_filename.final : " . $!;
 654
 655        open $c, "<", $compose_filename
 656                or die "Failed to open $compose_filename : " . $!;
 657
 658        my $need_8bit_cte = file_has_nonascii($compose_filename);
 659        my $in_body = 0;
 660        my $summary_empty = 1;
 661        if (!defined $compose_encoding) {
 662                $compose_encoding = "UTF-8";
 663        }
 664        while(<$c>) {
 665                next if m/^GIT:/;
 666                if ($in_body) {
 667                        $summary_empty = 0 unless (/^\n$/);
 668                } elsif (/^\n$/) {
 669                        $in_body = 1;
 670                        if ($need_8bit_cte) {
 671                                print $c2 "MIME-Version: 1.0\n",
 672                                         "Content-Type: text/plain; ",
 673                                           "charset=$compose_encoding\n",
 674                                         "Content-Transfer-Encoding: 8bit\n";
 675                        }
 676                } elsif (/^MIME-Version:/i) {
 677                        $need_8bit_cte = 0;
 678                } elsif (/^Subject:\s*(.+)\s*$/i) {
 679                        $initial_subject = $1;
 680                        my $subject = $initial_subject;
 681                        $_ = "Subject: " .
 682                                quote_subject($subject, $compose_encoding) .
 683                                "\n";
 684                } elsif (/^In-Reply-To:\s*(.+)\s*$/i) {
 685                        $initial_reply_to = $1;
 686                        next;
 687                } elsif (/^From:\s*(.+)\s*$/i) {
 688                        $sender = $1;
 689                        next;
 690                } elsif (/^(?:To|Cc|Bcc):/i) {
 691                        print "To/Cc/Bcc fields are not interpreted yet, they have been ignored\n";
 692                        next;
 693                }
 694                print $c2 $_;
 695        }
 696        close $c;
 697        close $c2;
 698
 699        if ($summary_empty) {
 700                print "Summary email is empty, skipping it\n";
 701                $compose = -1;
 702        }
 703} elsif ($annotate) {
 704        do_edit(@files);
 705}
 706
 707sub ask {
 708        my ($prompt, %arg) = @_;
 709        my $valid_re = $arg{valid_re};
 710        my $default = $arg{default};
 711        my $confirm_only = $arg{confirm_only};
 712        my $resp;
 713        my $i = 0;
 714        return defined $default ? $default : undef
 715                unless defined $term->IN and defined fileno($term->IN) and
 716                       defined $term->OUT and defined fileno($term->OUT);
 717        while ($i++ < 10) {
 718                $resp = $term->readline($prompt);
 719                if (!defined $resp) { # EOF
 720                        print "\n";
 721                        return defined $default ? $default : undef;
 722                }
 723                if ($resp eq '' and defined $default) {
 724                        return $default;
 725                }
 726                if (!defined $valid_re or $resp =~ /$valid_re/) {
 727                        return $resp;
 728                }
 729                if ($confirm_only) {
 730                        my $yesno = $term->readline("Are you sure you want to use <$resp> [y/N]? ");
 731                        if (defined $yesno && $yesno =~ /y/i) {
 732                                return $resp;
 733                        }
 734                }
 735        }
 736        return;
 737}
 738
 739my %broken_encoding;
 740
 741sub file_declares_8bit_cte {
 742        my $fn = shift;
 743        open (my $fh, '<', $fn);
 744        while (my $line = <$fh>) {
 745                last if ($line =~ /^$/);
 746                return 1 if ($line =~ /^Content-Transfer-Encoding: .*8bit.*$/);
 747        }
 748        close $fh;
 749        return 0;
 750}
 751
 752foreach my $f (@files) {
 753        next unless (body_or_subject_has_nonascii($f)
 754                     && !file_declares_8bit_cte($f));
 755        $broken_encoding{$f} = 1;
 756}
 757
 758if (!defined $auto_8bit_encoding && scalar %broken_encoding) {
 759        print "The following files are 8bit, but do not declare " .
 760                "a Content-Transfer-Encoding.\n";
 761        foreach my $f (sort keys %broken_encoding) {
 762                print "    $f\n";
 763        }
 764        $auto_8bit_encoding = ask("Which 8bit encoding should I declare [UTF-8]? ",
 765                                  valid_re => qr/.{4}/, confirm_only => 1,
 766                                  default => "UTF-8");
 767}
 768
 769if (!$force) {
 770        for my $f (@files) {
 771                if (get_patch_subject($f) =~ /\Q*** SUBJECT HERE ***\E/) {
 772                        die "Refusing to send because the patch\n\t$f\n"
 773                                . "has the template subject '*** SUBJECT HERE ***'. "
 774                                . "Pass --force if you really want to send.\n";
 775                }
 776        }
 777}
 778
 779if (!defined $sender) {
 780        $sender = $repoauthor || $repocommitter || '';
 781}
 782
 783# $sender could be an already sanitized address
 784# (e.g. sendemail.from could be manually sanitized by user).
 785# But it's a no-op to run sanitize_address on an already sanitized address.
 786$sender = sanitize_address($sender);
 787
 788my $prompting = 0;
 789if (!@initial_to && !defined $to_cmd) {
 790        my $to = ask("Who should the emails be sent to (if any)? ",
 791                     default => "",
 792                     valid_re => qr/\@.*\./, confirm_only => 1);
 793        push @initial_to, parse_address_line($to) if defined $to; # sanitized/validated later
 794        $prompting++;
 795}
 796
 797sub expand_aliases {
 798        return map { expand_one_alias($_) } @_;
 799}
 800
 801my %EXPANDED_ALIASES;
 802sub expand_one_alias {
 803        my $alias = shift;
 804        if ($EXPANDED_ALIASES{$alias}) {
 805                die "fatal: alias '$alias' expands to itself\n";
 806        }
 807        local $EXPANDED_ALIASES{$alias} = 1;
 808        return $aliases{$alias} ? expand_aliases(@{$aliases{$alias}}) : $alias;
 809}
 810
 811@initial_to = expand_aliases(@initial_to);
 812@initial_to = validate_address_list(sanitize_address_list(@initial_to));
 813@initial_cc = expand_aliases(@initial_cc);
 814@initial_cc = validate_address_list(sanitize_address_list(@initial_cc));
 815@bcclist = expand_aliases(@bcclist);
 816@bcclist = validate_address_list(sanitize_address_list(@bcclist));
 817
 818if ($thread && !defined $initial_reply_to && $prompting) {
 819        $initial_reply_to = ask(
 820                "Message-ID to be used as In-Reply-To for the first email (if any)? ",
 821                default => "",
 822                valid_re => qr/\@.*\./, confirm_only => 1);
 823}
 824if (defined $initial_reply_to) {
 825        $initial_reply_to =~ s/^\s*<?//;
 826        $initial_reply_to =~ s/>?\s*$//;
 827        $initial_reply_to = "<$initial_reply_to>" if $initial_reply_to ne '';
 828}
 829
 830if (!defined $smtp_server) {
 831        foreach (qw( /usr/sbin/sendmail /usr/lib/sendmail )) {
 832                if (-x $_) {
 833                        $smtp_server = $_;
 834                        last;
 835                }
 836        }
 837        $smtp_server ||= 'localhost'; # could be 127.0.0.1, too... *shrug*
 838}
 839
 840if ($compose && $compose > 0) {
 841        @files = ($compose_filename . ".final", @files);
 842}
 843
 844# Variables we set as part of the loop over files
 845our ($message_id, %mail, $subject, $reply_to, $references, $message,
 846        $needs_confirm, $message_num, $ask_default);
 847
 848sub extract_valid_address {
 849        my $address = shift;
 850        my $local_part_regexp = qr/[^<>"\s@]+/;
 851        my $domain_regexp = qr/[^.<>"\s@]+(?:\.[^.<>"\s@]+)+/;
 852
 853        # check for a local address:
 854        return $address if ($address =~ /^($local_part_regexp)$/);
 855
 856        $address =~ s/^\s*<(.*)>\s*$/$1/;
 857        if ($have_email_valid) {
 858                return scalar Email::Valid->address($address);
 859        }
 860
 861        # less robust/correct than the monster regexp in Email::Valid,
 862        # but still does a 99% job, and one less dependency
 863        return $1 if $address =~ /($local_part_regexp\@$domain_regexp)/;
 864        return;
 865}
 866
 867sub extract_valid_address_or_die {
 868        my $address = shift;
 869        $address = extract_valid_address($address);
 870        die "error: unable to extract a valid address from: $address\n"
 871                if !$address;
 872        return $address;
 873}
 874
 875sub validate_address {
 876        my $address = shift;
 877        while (!extract_valid_address($address)) {
 878                print STDERR "error: unable to extract a valid address from: $address\n";
 879                $_ = ask("What to do with this address? ([q]uit|[d]rop|[e]dit): ",
 880                        valid_re => qr/^(?:quit|q|drop|d|edit|e)/i,
 881                        default => 'q');
 882                if (/^d/i) {
 883                        return undef;
 884                } elsif (/^q/i) {
 885                        cleanup_compose_files();
 886                        exit(0);
 887                }
 888                $address = ask("Who should the email be sent to (if any)? ",
 889                        default => "",
 890                        valid_re => qr/\@.*\./, confirm_only => 1);
 891        }
 892        return $address;
 893}
 894
 895sub validate_address_list {
 896        return (grep { defined $_ }
 897                map { validate_address($_) } @_);
 898}
 899
 900# Usually don't need to change anything below here.
 901
 902# we make a "fake" message id by taking the current number
 903# of seconds since the beginning of Unix time and tacking on
 904# a random number to the end, in case we are called quicker than
 905# 1 second since the last time we were called.
 906
 907# We'll setup a template for the message id, using the "from" address:
 908
 909my ($message_id_stamp, $message_id_serial);
 910sub make_message_id {
 911        my $uniq;
 912        if (!defined $message_id_stamp) {
 913                $message_id_stamp = sprintf("%s-%s", time, $$);
 914                $message_id_serial = 0;
 915        }
 916        $message_id_serial++;
 917        $uniq = "$message_id_stamp-$message_id_serial";
 918
 919        my $du_part;
 920        for ($sender, $repocommitter, $repoauthor) {
 921                $du_part = extract_valid_address(sanitize_address($_));
 922                last if (defined $du_part and $du_part ne '');
 923        }
 924        if (not defined $du_part or $du_part eq '') {
 925                require Sys::Hostname;
 926                $du_part = 'user@' . Sys::Hostname::hostname();
 927        }
 928        my $message_id_template = "<%s-git-send-email-%s>";
 929        $message_id = sprintf($message_id_template, $uniq, $du_part);
 930        #print "new message id = $message_id\n"; # Was useful for debugging
 931}
 932
 933
 934
 935$time = time - scalar $#files;
 936
 937sub unquote_rfc2047 {
 938        local ($_) = @_;
 939        my $charset;
 940        my $sep = qr/[ \t]+/;
 941        s{$re_encoded_word(?:$sep$re_encoded_word)*}{
 942                my @words = split $sep, $&;
 943                foreach (@words) {
 944                        m/$re_encoded_word/;
 945                        $charset = $1;
 946                        my $encoding = $2;
 947                        my $text = $3;
 948                        if ($encoding eq 'q' || $encoding eq 'Q') {
 949                                $_ = $text;
 950                                s/_/ /g;
 951                                s/=([0-9A-F]{2})/chr(hex($1))/egi;
 952                        } else {
 953                                # other encodings not supported yet
 954                        }
 955                }
 956                join '', @words;
 957        }eg;
 958        return wantarray ? ($_, $charset) : $_;
 959}
 960
 961sub quote_rfc2047 {
 962        local $_ = shift;
 963        my $encoding = shift || 'UTF-8';
 964        s/([^-a-zA-Z0-9!*+\/])/sprintf("=%02X", ord($1))/eg;
 965        s/(.*)/=\?$encoding\?q\?$1\?=/;
 966        return $_;
 967}
 968
 969sub is_rfc2047_quoted {
 970        my $s = shift;
 971        length($s) <= 75 &&
 972        $s =~ m/^(?:"[[:ascii:]]*"|$re_encoded_word)$/o;
 973}
 974
 975sub subject_needs_rfc2047_quoting {
 976        my $s = shift;
 977
 978        return ($s =~ /[^[:ascii:]]/) || ($s =~ /=\?/);
 979}
 980
 981sub quote_subject {
 982        local $subject = shift;
 983        my $encoding = shift || 'UTF-8';
 984
 985        if (subject_needs_rfc2047_quoting($subject)) {
 986                return quote_rfc2047($subject, $encoding);
 987        }
 988        return $subject;
 989}
 990
 991# use the simplest quoting being able to handle the recipient
 992sub sanitize_address {
 993        my ($recipient) = @_;
 994
 995        # remove garbage after email address
 996        $recipient =~ s/(.*>).*$/$1/;
 997
 998        my ($recipient_name, $recipient_addr) = ($recipient =~ /^(.*?)\s*(<.*)/);
 999
1000        if (not $recipient_name) {
1001                return $recipient;
1002        }
1003
1004        # if recipient_name is already quoted, do nothing
1005        if (is_rfc2047_quoted($recipient_name)) {
1006                return $recipient;
1007        }
1008
1009        # rfc2047 is needed if a non-ascii char is included
1010        if ($recipient_name =~ /[^[:ascii:]]/) {
1011                $recipient_name =~ s/^"(.*)"$/$1/;
1012                $recipient_name = quote_rfc2047($recipient_name);
1013        }
1014
1015        # double quotes are needed if specials or CTLs are included
1016        elsif ($recipient_name =~ /[][()<>@,;:\\".\000-\037\177]/) {
1017                $recipient_name =~ s/(["\\\r])/\\$1/g;
1018                $recipient_name = qq["$recipient_name"];
1019        }
1020
1021        return "$recipient_name $recipient_addr";
1022
1023}
1024
1025sub sanitize_address_list {
1026        return (map { sanitize_address($_) } @_);
1027}
1028
1029# Returns the local Fully Qualified Domain Name (FQDN) if available.
1030#
1031# Tightly configured MTAa require that a caller sends a real DNS
1032# domain name that corresponds the IP address in the HELO/EHLO
1033# handshake. This is used to verify the connection and prevent
1034# spammers from trying to hide their identity. If the DNS and IP don't
1035# match, the receiveing MTA may deny the connection.
1036#
1037# Here is a deny example of Net::SMTP with the default "localhost.localdomain"
1038#
1039# Net::SMTP=GLOB(0x267ec28)>>> EHLO localhost.localdomain
1040# Net::SMTP=GLOB(0x267ec28)<<< 550 EHLO argument does not match calling host
1041#
1042# This maildomain*() code is based on ideas in Perl library Test::Reporter
1043# /usr/share/perl5/Test/Reporter/Mail/Util.pm ==> sub _maildomain ()
1044
1045sub valid_fqdn {
1046        my $domain = shift;
1047        return defined $domain && !($^O eq 'darwin' && $domain =~ /\.local$/) && $domain =~ /\./;
1048}
1049
1050sub maildomain_net {
1051        my $maildomain;
1052
1053        if (eval { require Net::Domain; 1 }) {
1054                my $domain = Net::Domain::domainname();
1055                $maildomain = $domain if valid_fqdn($domain);
1056        }
1057
1058        return $maildomain;
1059}
1060
1061sub maildomain_mta {
1062        my $maildomain;
1063
1064        if (eval { require Net::SMTP; 1 }) {
1065                for my $host (qw(mailhost localhost)) {
1066                        my $smtp = Net::SMTP->new($host);
1067                        if (defined $smtp) {
1068                                my $domain = $smtp->domain;
1069                                $smtp->quit;
1070
1071                                $maildomain = $domain if valid_fqdn($domain);
1072
1073                                last if $maildomain;
1074                        }
1075                }
1076        }
1077
1078        return $maildomain;
1079}
1080
1081sub maildomain {
1082        return maildomain_net() || maildomain_mta() || 'localhost.localdomain';
1083}
1084
1085sub smtp_host_string {
1086        if (defined $smtp_server_port) {
1087                return "$smtp_server:$smtp_server_port";
1088        } else {
1089                return $smtp_server;
1090        }
1091}
1092
1093# Returns 1 if authentication succeeded or was not necessary
1094# (smtp_user was not specified), and 0 otherwise.
1095
1096sub smtp_auth_maybe {
1097        if (!defined $smtp_authuser || $auth) {
1098                return 1;
1099        }
1100
1101        # Workaround AUTH PLAIN/LOGIN interaction defect
1102        # with Authen::SASL::Cyrus
1103        eval {
1104                require Authen::SASL;
1105                Authen::SASL->import(qw(Perl));
1106        };
1107
1108        # TODO: Authentication may fail not because credentials were
1109        # invalid but due to other reasons, in which we should not
1110        # reject credentials.
1111        $auth = Git::credential({
1112                'protocol' => 'smtp',
1113                'host' => smtp_host_string(),
1114                'username' => $smtp_authuser,
1115                # if there's no password, "git credential fill" will
1116                # give us one, otherwise it'll just pass this one.
1117                'password' => $smtp_authpass
1118        }, sub {
1119                my $cred = shift;
1120                return !!$smtp->auth($cred->{'username'}, $cred->{'password'});
1121        });
1122
1123        return $auth;
1124}
1125
1126sub ssl_verify_params {
1127        eval {
1128                require IO::Socket::SSL;
1129                IO::Socket::SSL->import(qw/SSL_VERIFY_PEER SSL_VERIFY_NONE/);
1130        };
1131        if ($@) {
1132                print STDERR "Not using SSL_VERIFY_PEER due to out-of-date IO::Socket::SSL.\n";
1133                return;
1134        }
1135
1136        if (!defined $smtp_ssl_cert_path) {
1137                # use the OpenSSL defaults
1138                return (SSL_verify_mode => SSL_VERIFY_PEER());
1139        }
1140
1141        if ($smtp_ssl_cert_path eq "") {
1142                return (SSL_verify_mode => SSL_VERIFY_NONE());
1143        } elsif (-d $smtp_ssl_cert_path) {
1144                return (SSL_verify_mode => SSL_VERIFY_PEER(),
1145                        SSL_ca_path => $smtp_ssl_cert_path);
1146        } elsif (-f $smtp_ssl_cert_path) {
1147                return (SSL_verify_mode => SSL_VERIFY_PEER(),
1148                        SSL_ca_file => $smtp_ssl_cert_path);
1149        } else {
1150                print STDERR "Not using SSL_VERIFY_PEER because the CA path does not exist.\n";
1151                return (SSL_verify_mode => SSL_VERIFY_NONE());
1152        }
1153}
1154
1155sub file_name_is_absolute {
1156        my ($path) = @_;
1157
1158        # msys does not grok DOS drive-prefixes
1159        if ($^O eq 'msys') {
1160                return ($path =~ m#^/# || $path =~ m#^[a-zA-Z]\:#)
1161        }
1162
1163        require File::Spec::Functions;
1164        return File::Spec::Functions::file_name_is_absolute($path);
1165}
1166
1167# Returns 1 if the message was sent, and 0 otherwise.
1168# In actuality, the whole program dies when there
1169# is an error sending a message.
1170
1171sub send_message {
1172        my @recipients = unique_email_list(@to);
1173        @cc = (grep { my $cc = extract_valid_address_or_die($_);
1174                      not grep { $cc eq $_ || $_ =~ /<\Q${cc}\E>$/ } @recipients
1175                    }
1176               @cc);
1177        my $to = join (",\n\t", @recipients);
1178        @recipients = unique_email_list(@recipients,@cc,@bcclist);
1179        @recipients = (map { extract_valid_address_or_die($_) } @recipients);
1180        my $date = format_2822_time($time++);
1181        my $gitversion = '@@GIT_VERSION@@';
1182        if ($gitversion =~ m/..GIT_VERSION../) {
1183            $gitversion = Git::version();
1184        }
1185
1186        my $cc = join(",\n\t", unique_email_list(@cc));
1187        my $ccline = "";
1188        if ($cc ne '') {
1189                $ccline = "\nCc: $cc";
1190        }
1191        make_message_id() unless defined($message_id);
1192
1193        my $header = "From: $sender
1194To: $to${ccline}
1195Subject: $subject
1196Date: $date
1197Message-Id: $message_id
1198";
1199        if ($use_xmailer) {
1200                $header .= "X-Mailer: git-send-email $gitversion\n";
1201        }
1202        if ($reply_to) {
1203
1204                $header .= "In-Reply-To: $reply_to\n";
1205                $header .= "References: $references\n";
1206        }
1207        if (@xh) {
1208                $header .= join("\n", @xh) . "\n";
1209        }
1210
1211        my @sendmail_parameters = ('-i', @recipients);
1212        my $raw_from = $sender;
1213        if (defined $envelope_sender && $envelope_sender ne "auto") {
1214                $raw_from = $envelope_sender;
1215        }
1216        $raw_from = extract_valid_address($raw_from);
1217        unshift (@sendmail_parameters,
1218                        '-f', $raw_from) if(defined $envelope_sender);
1219
1220        if ($needs_confirm && !$dry_run) {
1221                print "\n$header\n";
1222                if ($needs_confirm eq "inform") {
1223                        $confirm_unconfigured = 0; # squelch this message for the rest of this run
1224                        $ask_default = "y"; # assume yes on EOF since user hasn't explicitly asked for confirmation
1225                        print "    The Cc list above has been expanded by additional\n";
1226                        print "    addresses found in the patch commit message. By default\n";
1227                        print "    send-email prompts before sending whenever this occurs.\n";
1228                        print "    This behavior is controlled by the sendemail.confirm\n";
1229                        print "    configuration setting.\n";
1230                        print "\n";
1231                        print "    For additional information, run 'git send-email --help'.\n";
1232                        print "    To retain the current behavior, but squelch this message,\n";
1233                        print "    run 'git config --global sendemail.confirm auto'.\n\n";
1234                }
1235                $_ = ask("Send this email? ([y]es|[n]o|[q]uit|[a]ll): ",
1236                         valid_re => qr/^(?:yes|y|no|n|quit|q|all|a)/i,
1237                         default => $ask_default);
1238                die "Send this email reply required" unless defined $_;
1239                if (/^n/i) {
1240                        return 0;
1241                } elsif (/^q/i) {
1242                        cleanup_compose_files();
1243                        exit(0);
1244                } elsif (/^a/i) {
1245                        $confirm = 'never';
1246                }
1247        }
1248
1249        unshift (@sendmail_parameters, @smtp_server_options);
1250
1251        if ($dry_run) {
1252                # We don't want to send the email.
1253        } elsif (file_name_is_absolute($smtp_server)) {
1254                my $pid = open my $sm, '|-';
1255                defined $pid or die $!;
1256                if (!$pid) {
1257                        exec($smtp_server, @sendmail_parameters) or die $!;
1258                }
1259                print $sm "$header\n$message";
1260                close $sm or die $!;
1261        } else {
1262
1263                if (!defined $smtp_server) {
1264                        die "The required SMTP server is not properly defined."
1265                }
1266
1267                if ($smtp_encryption eq 'ssl') {
1268                        $smtp_server_port ||= 465; # ssmtp
1269                        require Net::SMTP::SSL;
1270                        $smtp_domain ||= maildomain();
1271                        require IO::Socket::SSL;
1272                        # Net::SMTP::SSL->new() does not forward any SSL options
1273                        IO::Socket::SSL::set_client_defaults(
1274                                ssl_verify_params());
1275                        $smtp ||= Net::SMTP::SSL->new($smtp_server,
1276                                                      Hello => $smtp_domain,
1277                                                      Port => $smtp_server_port,
1278                                                      Debug => $debug_net_smtp);
1279                }
1280                else {
1281                        require Net::SMTP;
1282                        $smtp_domain ||= maildomain();
1283                        $smtp_server_port ||= 25;
1284                        $smtp ||= Net::SMTP->new($smtp_server,
1285                                                 Hello => $smtp_domain,
1286                                                 Debug => $debug_net_smtp,
1287                                                 Port => $smtp_server_port);
1288                        if ($smtp_encryption eq 'tls' && $smtp) {
1289                                require Net::SMTP::SSL;
1290                                $smtp->command('STARTTLS');
1291                                $smtp->response();
1292                                if ($smtp->code == 220) {
1293                                        $smtp = Net::SMTP::SSL->start_SSL($smtp,
1294                                                                          ssl_verify_params())
1295                                                or die "STARTTLS failed! ".IO::Socket::SSL::errstr();
1296                                        $smtp_encryption = '';
1297                                        # Send EHLO again to receive fresh
1298                                        # supported commands
1299                                        $smtp->hello($smtp_domain);
1300                                } else {
1301                                        die "Server does not support STARTTLS! ".$smtp->message;
1302                                }
1303                        }
1304                }
1305
1306                if (!$smtp) {
1307                        die "Unable to initialize SMTP properly. Check config and use --smtp-debug. ",
1308                            "VALUES: server=$smtp_server ",
1309                            "encryption=$smtp_encryption ",
1310                            "hello=$smtp_domain",
1311                            defined $smtp_server_port ? " port=$smtp_server_port" : "";
1312                }
1313
1314                smtp_auth_maybe or die $smtp->message;
1315
1316                $smtp->mail( $raw_from ) or die $smtp->message;
1317                $smtp->to( @recipients ) or die $smtp->message;
1318                $smtp->data or die $smtp->message;
1319                $smtp->datasend("$header\n$message") or die $smtp->message;
1320                $smtp->dataend() or die $smtp->message;
1321                $smtp->code =~ /250|200/ or die "Failed to send $subject\n".$smtp->message;
1322        }
1323        if ($quiet) {
1324                printf (($dry_run ? "Dry-" : "")."Sent %s\n", $subject);
1325        } else {
1326                print (($dry_run ? "Dry-" : "")."OK. Log says:\n");
1327                if (!file_name_is_absolute($smtp_server)) {
1328                        print "Server: $smtp_server\n";
1329                        print "MAIL FROM:<$raw_from>\n";
1330                        foreach my $entry (@recipients) {
1331                            print "RCPT TO:<$entry>\n";
1332                        }
1333                } else {
1334                        print "Sendmail: $smtp_server ".join(' ',@sendmail_parameters)."\n";
1335                }
1336                print $header, "\n";
1337                if ($smtp) {
1338                        print "Result: ", $smtp->code, ' ',
1339                                ($smtp->message =~ /\n([^\n]+\n)$/s), "\n";
1340                } else {
1341                        print "Result: OK\n";
1342                }
1343        }
1344
1345        return 1;
1346}
1347
1348$reply_to = $initial_reply_to;
1349$references = $initial_reply_to || '';
1350$subject = $initial_subject;
1351$message_num = 0;
1352
1353foreach my $t (@files) {
1354        open my $fh, "<", $t or die "can't open file $t";
1355
1356        my $author = undef;
1357        my $sauthor = undef;
1358        my $author_encoding;
1359        my $has_content_type;
1360        my $body_encoding;
1361        my $xfer_encoding;
1362        my $has_mime_version;
1363        @to = ();
1364        @cc = ();
1365        @xh = ();
1366        my $input_format = undef;
1367        my @header = ();
1368        $message = "";
1369        $message_num++;
1370        # First unfold multiline header fields
1371        while(<$fh>) {
1372                last if /^\s*$/;
1373                if (/^\s+\S/ and @header) {
1374                        chomp($header[$#header]);
1375                        s/^\s+/ /;
1376                        $header[$#header] .= $_;
1377            } else {
1378                        push(@header, $_);
1379                }
1380        }
1381        # Now parse the header
1382        foreach(@header) {
1383                if (/^From /) {
1384                        $input_format = 'mbox';
1385                        next;
1386                }
1387                chomp;
1388                if (!defined $input_format && /^[-A-Za-z]+:\s/) {
1389                        $input_format = 'mbox';
1390                }
1391
1392                if (defined $input_format && $input_format eq 'mbox') {
1393                        if (/^Subject:\s+(.*)$/i) {
1394                                $subject = $1;
1395                        }
1396                        elsif (/^From:\s+(.*)$/i) {
1397                                ($author, $author_encoding) = unquote_rfc2047($1);
1398                                $sauthor = sanitize_address($author);
1399                                next if $suppress_cc{'author'};
1400                                next if $suppress_cc{'self'} and $sauthor eq $sender;
1401                                printf("(mbox) Adding cc: %s from line '%s'\n",
1402                                        $1, $_) unless $quiet;
1403                                push @cc, $1;
1404                        }
1405                        elsif (/^To:\s+(.*)$/i) {
1406                                foreach my $addr (parse_address_line($1)) {
1407                                        printf("(mbox) Adding to: %s from line '%s'\n",
1408                                                $addr, $_) unless $quiet;
1409                                        push @to, $addr;
1410                                }
1411                        }
1412                        elsif (/^Cc:\s+(.*)$/i) {
1413                                foreach my $addr (parse_address_line($1)) {
1414                                        my $qaddr = unquote_rfc2047($addr);
1415                                        my $saddr = sanitize_address($qaddr);
1416                                        if ($saddr eq $sender) {
1417                                                next if ($suppress_cc{'self'});
1418                                        } else {
1419                                                next if ($suppress_cc{'cc'});
1420                                        }
1421                                        printf("(mbox) Adding cc: %s from line '%s'\n",
1422                                                $addr, $_) unless $quiet;
1423                                        push @cc, $addr;
1424                                }
1425                        }
1426                        elsif (/^Content-type:/i) {
1427                                $has_content_type = 1;
1428                                if (/charset="?([^ "]+)/) {
1429                                        $body_encoding = $1;
1430                                }
1431                                push @xh, $_;
1432                        }
1433                        elsif (/^MIME-Version/i) {
1434                                $has_mime_version = 1;
1435                                push @xh, $_;
1436                        }
1437                        elsif (/^Message-Id: (.*)/i) {
1438                                $message_id = $1;
1439                        }
1440                        elsif (/^Content-Transfer-Encoding: (.*)/i) {
1441                                $xfer_encoding = $1 if not defined $xfer_encoding;
1442                        }
1443                        elsif (!/^Date:\s/i && /^[-A-Za-z]+:\s+\S/) {
1444                                push @xh, $_;
1445                        }
1446
1447                } else {
1448                        # In the traditional
1449                        # "send lots of email" format,
1450                        # line 1 = cc
1451                        # line 2 = subject
1452                        # So let's support that, too.
1453                        $input_format = 'lots';
1454                        if (@cc == 0 && !$suppress_cc{'cc'}) {
1455                                printf("(non-mbox) Adding cc: %s from line '%s'\n",
1456                                        $_, $_) unless $quiet;
1457                                push @cc, $_;
1458                        } elsif (!defined $subject) {
1459                                $subject = $_;
1460                        }
1461                }
1462        }
1463        # Now parse the message body
1464        while(<$fh>) {
1465                $message .=  $_;
1466                if (/^(Signed-off-by|Cc): (.*)$/i) {
1467                        chomp;
1468                        my ($what, $c) = ($1, $2);
1469                        chomp $c;
1470                        my $sc = sanitize_address($c);
1471                        if ($sc eq $sender) {
1472                                next if ($suppress_cc{'self'});
1473                        } else {
1474                                next if $suppress_cc{'sob'} and $what =~ /Signed-off-by/i;
1475                                next if $suppress_cc{'bodycc'} and $what =~ /Cc/i;
1476                        }
1477                        push @cc, $c;
1478                        printf("(body) Adding cc: %s from line '%s'\n",
1479                                $c, $_) unless $quiet;
1480                }
1481        }
1482        close $fh;
1483
1484        push @to, recipients_cmd("to-cmd", "to", $to_cmd, $t)
1485                if defined $to_cmd;
1486        push @cc, recipients_cmd("cc-cmd", "cc", $cc_cmd, $t)
1487                if defined $cc_cmd && !$suppress_cc{'cccmd'};
1488
1489        if ($broken_encoding{$t} && !$has_content_type) {
1490                $xfer_encoding = '8bit' if not defined $xfer_encoding;
1491                $has_content_type = 1;
1492                push @xh, "Content-Type: text/plain; charset=$auto_8bit_encoding";
1493                $body_encoding = $auto_8bit_encoding;
1494        }
1495
1496        if ($broken_encoding{$t} && !is_rfc2047_quoted($subject)) {
1497                $subject = quote_subject($subject, $auto_8bit_encoding);
1498        }
1499
1500        if (defined $sauthor and $sauthor ne $sender) {
1501                $message = "From: $author\n\n$message";
1502                if (defined $author_encoding) {
1503                        if ($has_content_type) {
1504                                if ($body_encoding eq $author_encoding) {
1505                                        # ok, we already have the right encoding
1506                                }
1507                                else {
1508                                        # uh oh, we should re-encode
1509                                }
1510                        }
1511                        else {
1512                                $xfer_encoding = '8bit' if not defined $xfer_encoding;
1513                                $has_content_type = 1;
1514                                push @xh,
1515                                  "Content-Type: text/plain; charset=$author_encoding";
1516                        }
1517                }
1518        }
1519        if (defined $target_xfer_encoding) {
1520                $xfer_encoding = '8bit' if not defined $xfer_encoding;
1521                $message = apply_transfer_encoding(
1522                        $message, $xfer_encoding, $target_xfer_encoding);
1523                $xfer_encoding = $target_xfer_encoding;
1524        }
1525        if (defined $xfer_encoding) {
1526                push @xh, "Content-Transfer-Encoding: $xfer_encoding";
1527        }
1528        if (defined $xfer_encoding or $has_content_type) {
1529                unshift @xh, 'MIME-Version: 1.0' unless $has_mime_version;
1530        }
1531
1532        $needs_confirm = (
1533                $confirm eq "always" or
1534                ($confirm =~ /^(?:auto|cc)$/ && @cc) or
1535                ($confirm =~ /^(?:auto|compose)$/ && $compose && $message_num == 1));
1536        $needs_confirm = "inform" if ($needs_confirm && $confirm_unconfigured && @cc);
1537
1538        @to = validate_address_list(sanitize_address_list(@to));
1539        @cc = validate_address_list(sanitize_address_list(@cc));
1540
1541        @to = (@initial_to, @to);
1542        @cc = (@initial_cc, @cc);
1543
1544        if ($message_num == 1) {
1545                if (defined $cover_cc and $cover_cc) {
1546                        @initial_cc = @cc;
1547                }
1548                if (defined $cover_to and $cover_to) {
1549                        @initial_to = @to;
1550                }
1551        }
1552
1553        my $message_was_sent = send_message();
1554
1555        # set up for the next message
1556        if ($thread && $message_was_sent &&
1557                ($chain_reply_to || !defined $reply_to || length($reply_to) == 0 ||
1558                $message_num == 1)) {
1559                $reply_to = $message_id;
1560                if (length $references > 0) {
1561                        $references .= "\n $message_id";
1562                } else {
1563                        $references = "$message_id";
1564                }
1565        }
1566        $message_id = undef;
1567}
1568
1569# Execute a command (e.g. $to_cmd) to get a list of email addresses
1570# and return a results array
1571sub recipients_cmd {
1572        my ($prefix, $what, $cmd, $file) = @_;
1573
1574        my @addresses = ();
1575        open my $fh, "-|", "$cmd \Q$file\E"
1576            or die "($prefix) Could not execute '$cmd'";
1577        while (my $address = <$fh>) {
1578                $address =~ s/^\s*//g;
1579                $address =~ s/\s*$//g;
1580                $address = sanitize_address($address);
1581                next if ($address eq $sender and $suppress_cc{'self'});
1582                push @addresses, $address;
1583                printf("($prefix) Adding %s: %s from: '%s'\n",
1584                       $what, $address, $cmd) unless $quiet;
1585                }
1586        close $fh
1587            or die "($prefix) failed to close pipe to '$cmd'";
1588        return @addresses;
1589}
1590
1591cleanup_compose_files();
1592
1593sub cleanup_compose_files {
1594        unlink($compose_filename, $compose_filename . ".final") if $compose;
1595}
1596
1597$smtp->quit if $smtp;
1598
1599sub apply_transfer_encoding {
1600        my $message = shift;
1601        my $from = shift;
1602        my $to = shift;
1603
1604        return $message if ($from eq $to and $from ne '7bit');
1605
1606        require MIME::QuotedPrint;
1607        require MIME::Base64;
1608
1609        $message = MIME::QuotedPrint::decode($message)
1610                if ($from eq 'quoted-printable');
1611        $message = MIME::Base64::decode($message)
1612                if ($from eq 'base64');
1613
1614        die "cannot send message as 7bit"
1615                if ($to eq '7bit' and $message =~ /[^[:ascii:]]/);
1616        return $message
1617                if ($to eq '7bit' or $to eq '8bit');
1618        return MIME::QuotedPrint::encode($message, "\n", 0)
1619                if ($to eq 'quoted-printable');
1620        return MIME::Base64::encode($message, "\n")
1621                if ($to eq 'base64');
1622        die "invalid transfer encoding";
1623}
1624
1625sub unique_email_list {
1626        my %seen;
1627        my @emails;
1628
1629        foreach my $entry (@_) {
1630                my $clean = extract_valid_address_or_die($entry);
1631                $seen{$clean} ||= 0;
1632                next if $seen{$clean}++;
1633                push @emails, $entry;
1634        }
1635        return @emails;
1636}
1637
1638sub validate_patch {
1639        my $fn = shift;
1640        open(my $fh, '<', $fn)
1641                or die "unable to open $fn: $!\n";
1642        while (my $line = <$fh>) {
1643                if (length($line) > 998) {
1644                        return "$.: patch contains a line longer than 998 characters";
1645                }
1646        }
1647        return;
1648}
1649
1650sub file_has_nonascii {
1651        my $fn = shift;
1652        open(my $fh, '<', $fn)
1653                or die "unable to open $fn: $!\n";
1654        while (my $line = <$fh>) {
1655                return 1 if $line =~ /[^[:ascii:]]/;
1656        }
1657        return 0;
1658}
1659
1660sub body_or_subject_has_nonascii {
1661        my $fn = shift;
1662        open(my $fh, '<', $fn)
1663                or die "unable to open $fn: $!\n";
1664        while (my $line = <$fh>) {
1665                last if $line =~ /^$/;
1666                return 1 if $line =~ /^Subject.*[^[:ascii:]]/;
1667        }
1668        while (my $line = <$fh>) {
1669                return 1 if $line =~ /[^[:ascii:]]/;
1670        }
1671        return 0;
1672}