1 // Transmit outbound SMTP mail to the big wide world of the Internet
3 // This is the new, exciting, clever version that makes libcurl do all the work :)
5 // Copyright (c) 1997-2024 by the citadel.org team
7 // This program is open source software. Use, duplication, or disclosure
8 // is subject to the terms of the GNU General Public License, version 3.
17 #include <sys/types.h>
19 #include <libcitadel.h>
20 #include <curl/curl.h>
21 #include "../../sysconfig.h"
22 #include "../../citadel_defs.h"
23 #include "../../server.h"
24 #include "../../citserver.h"
25 #include "../../support.h"
26 #include "../../config.h"
27 #include "../../ctdl_module.h"
28 #include "../../clientsocket.h"
29 #include "../../msgbase.h"
30 #include "../../domain.h"
31 #include "../../internet_addressing.h"
32 #include "../../citadel_dirs.h"
33 #include "../smtp/smtp_util.h"
35 long last_queue_job_submitted = 0;
36 long last_queue_job_processed = 0;
38 struct smtpmsgsrc { // Data passed in and out of libcurl for message upload
44 // Initialize the SMTP outbound queue
45 void smtp_init_spoolout(void) {
46 struct ctdlroom qrbuf;
48 // Create the room. This will silently fail if the room already
49 // exists, and that's perfectly ok, because we want it to exist.
50 CtdlCreateRoom(SMTP_SPOOLOUT_ROOM, 3, "", 0, 1, 0, VIEW_QUEUE);
52 // Make sure it's set to be a "system room" so it doesn't show up
53 // in the <K>nown rooms list for administrators.
54 if (CtdlGetRoomLock(&qrbuf, SMTP_SPOOLOUT_ROOM) == 0) {
55 qrbuf.QRflags2 |= QR2_SYSTEM;
56 CtdlPutRoomLock(&qrbuf);
61 // For internet mail, generate a delivery job.
62 // Yes, this is recursive. Deal with it. Infinite recursion does
63 // not happen because the message containing the delivery job does not
65 int smtp_aftersave(struct CtdlMessage *msg, struct recptypes *recps) {
66 if ((recps != NULL) && (recps->num_internet > 0)) {
67 struct CtdlMessage *imsg = NULL;
69 StrBuf *SpoolMsg = NewStrBuf();
73 syslog(LOG_DEBUG, "smtpclient: generating delivery job");
75 StrBufPrintf(SpoolMsg,
76 "Content-type: " SPOOLMIME "\n"
79 "submitted|%ld\n" "bounceto|%s\n", msg->cm_fields[eVltMsgNum], (long) time(NULL), recps->bounce_to);
81 if (recps->envelope_from != NULL) {
82 StrBufAppendBufPlain(SpoolMsg, HKEY("envelope_from|"), 0);
83 StrBufAppendBufPlain(SpoolMsg, recps->envelope_from, -1, 0);
84 StrBufAppendBufPlain(SpoolMsg, HKEY("\n"), 0);
86 if (recps->sending_room != NULL) {
87 StrBufAppendBufPlain(SpoolMsg, HKEY("source_room|"), 0);
88 StrBufAppendBufPlain(SpoolMsg, recps->sending_room, -1, 0);
89 StrBufAppendBufPlain(SpoolMsg, HKEY("\n"), 0);
92 nTokens = num_tokens(recps->recp_internet, '|');
93 for (i = 0; i < nTokens; i++) {
95 len = extract_token(recipient, recps->recp_internet, i, '|', sizeof recipient);
97 StrBufAppendBufPlain(SpoolMsg, HKEY("remote|"), 0);
98 StrBufAppendBufPlain(SpoolMsg, recipient, len, 0);
99 StrBufAppendBufPlain(SpoolMsg, HKEY("|0||\n"), 0);
103 imsg = malloc(sizeof(struct CtdlMessage));
104 memset(imsg, 0, sizeof(struct CtdlMessage));
105 imsg->cm_magic = CTDLMESSAGE_MAGIC;
106 imsg->cm_anon_type = MES_NORMAL;
107 imsg->cm_format_type = FMT_RFC822;
108 CM_SetField(imsg, eMsgSubject, "QMSG");
109 CM_SetField(imsg, eAuthor, "Citadel");
110 CM_SetField(imsg, eJournal, "do not journal");
111 CM_SetAsFieldSB(imsg, eMessageText, &SpoolMsg);
112 last_queue_job_submitted = CtdlSubmitMsg(imsg, NULL, SMTP_SPOOLOUT_ROOM);
119 // Callback for smtp_attempt_delivery() to supply libcurl with upload data.
120 static size_t upload_source(void *ptr, size_t size, size_t nmemb, void *userp) {
121 struct smtpmsgsrc *s = (struct smtpmsgsrc *) userp;
123 const char *send_this = NULL;
125 sendbytes = (size * nmemb);
127 if (s->bytes_sent >= s->bytes_total) {
128 return (0); // no data remaining; we are done
131 if (sendbytes > (s->bytes_total - s->bytes_sent)) {
132 sendbytes = s->bytes_total - s->bytes_sent; // can't send more than we have
135 send_this = ChrPtr(s->TheMessage);
136 send_this += s->bytes_sent; // start where we last left off
138 memcpy(ptr, send_this, sendbytes);
139 s->bytes_sent += sendbytes;
140 return(sendbytes); // return the number of bytes _actually_ copied
144 // The libcurl API doesn't provide a way to capture the actual SMTP result message returned
145 // by the remote server. This is an ugly way to extract it, by capturing debug data from
146 // the library and filtering on the lines we want.
147 int ctdl_libcurl_smtp_debug_callback(CURL *handle, curl_infotype type, char *data, size_t size, void *userptr) {
148 if (type != CURLINFO_HEADER_IN)
152 char *debugbuf = (char *) userptr;
154 int len = strlen(debugbuf);
155 if (len + size > SIZ)
158 memcpy(&debugbuf[len], data, size);
159 debugbuf[len + size] = 0;
164 // Go through the debug output of an SMTP transaction, and boil it down to just the final success or error response message.
165 void trim_response(long response_code, char *response) {
166 if ((response_code < 100) || (response_code > 999) || (IsEmptyStr(response))) {
171 for (p = response; *p != 0; ++p) {
172 if ( (*p != '\n') && (!isprint(*p)) ) { // expunge any nonprintables except for newlines
177 char response_code_str[4];
178 snprintf(response_code_str, sizeof response_code_str, "%ld", response_code);
179 char *respstart = strstr(response, response_code_str);
180 if (respstart == NULL) { // If we have a response code but no response text,
181 strcpy(response, smtpstatus(response_code)); // use one of our canned messages.
184 strcpy(response, respstart);
186 p = strstr(response, "\n");
193 // Attempt a delivery to one recipient.
194 // Returns a three-digit SMTP status code.
195 int smtp_attempt_delivery(long msgid, char *recp, char *envelope_from, char *source_room, char *response) {
197 char *fromaddr = NULL;
199 CURLcode res = CURLE_OK;
200 struct curl_slist *recipients = NULL;
201 long response_code = 421;
207 char try_this_mx[256];
211 syslog(LOG_DEBUG, "smtpclient: smtp_attempt_delivery(%ld, %s)", msgid, recp);
213 process_rfc822_addr(recp, user, node, name); // split recipient address into username, hostname, displayname
214 num_mx = getmx(mxes, node);
219 CC->redirect_buffer = NewStrBufPlain(NULL, SIZ);
221 // If we have a source room, it's probably a mailing list message; generate an unsubscribe header
222 if (!IsEmptyStr(source_room)) {
224 char unsubscribe_url[SIZ];
225 snprintf(base_url, sizeof base_url, "https://%s/listsub", CtdlGetConfigStr("c_fqdn"));
226 generate_one_click_url(unsubscribe_url, base_url, "unsubscribe", source_room, recp);
227 cprintf("List-Unsubscribe: <%s>\r\n", unsubscribe_url); // RFC 2369
228 cprintf("List-Unsubscribe-Post: List-Unsubscribe=One-Click\r\n"); // RFC 8058
231 CtdlOutputMsg(msgid, MT_RFC822, HEADERS_ALL, 0, 1, NULL, 0, NULL, &fromaddr, NULL);
232 s.TheMessage = CC->redirect_buffer;
233 CC->redirect_buffer = NULL;
235 // If we have a DKIM key, try to sign the message.
236 char *dkim_private_key = CtdlGetConfigStr("dkim_private_key");
237 char *dkim_selector = CtdlGetConfigStr("dkim_selector");
238 char *dkim_from_domain = (strchr(fromaddr, '@') ? strchr(fromaddr, '@')+1 : NULL);
240 !IsEmptyStr(dkim_from_domain) // Is the sending domain non-empty?
241 && IsDirectory(fromaddr, 0) // and is it one of "our" domains?
242 && !IsEmptyStr(dkim_private_key) // Do we have a private signing key?
243 && !IsEmptyStr(dkim_selector) // and a selector to go with it?
245 // If you answered "yes" to all of the above questions, congratulations! We get to sign the message!
246 syslog(LOG_DEBUG, "smtpclient: dkim-signing for selector <%s> in domain <%s>", dkim_selector, dkim_from_domain);
248 // Remember, the dkim_sign() function is capable of handling a PEM-encoded PKCS#7 private key that
249 // has had all of its newlines replaced by underscores -- which is exactly how we store it.
250 dkim_sign(s.TheMessage,dkim_private_key, dkim_from_domain, dkim_selector);
253 // Prepare the buffer for transmittal
254 s.bytes_total = StrLength(s.TheMessage);
259 // Keep trying MXes until one works or we run out.
260 for (i = 0; ((i < num_mx) && ((response_code / 100) == 4)); ++i) {
261 response_code = 421; // default 421 makes non-protocol errors transient
262 s.bytes_sent = 0; // rewind our buffer in case we try multiple MXes
264 curl = curl_easy_init();
268 if (!IsEmptyStr(envelope_from)) {
269 curl_easy_setopt(curl, CURLOPT_MAIL_FROM, envelope_from);
272 curl_easy_setopt(curl, CURLOPT_MAIL_FROM, fromaddr);
275 recipients = curl_slist_append(recipients, recp);
276 curl_easy_setopt(curl, CURLOPT_MAIL_RCPT, recipients);
277 curl_easy_setopt(curl, CURLOPT_READFUNCTION, upload_source);
278 curl_easy_setopt(curl, CURLOPT_READDATA, &s);
279 curl_easy_setopt(curl, CURLOPT_UPLOAD, 1); // tell libcurl we are uploading
280 curl_easy_setopt(curl, CURLOPT_TIMEOUT, 20L); // Time out after 20 seconds
281 if (CtdlGetConfigInt("c_smtpclient_disable_starttls") == 0) {
282 curl_easy_setopt(curl, CURLOPT_USE_SSL, CURLUSESSL_TRY); // Attempt STARTTLS if offered
284 curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, 0L);
285 curl_easy_setopt(curl, CURLOPT_SSL_VERIFYHOST, 0L);
286 curl_easy_setopt(curl, CURLOPT_DEBUGFUNCTION, ctdl_libcurl_smtp_debug_callback);
287 curl_easy_setopt(curl, CURLOPT_DEBUGDATA, (void *) response);
288 curl_easy_setopt(curl, CURLOPT_VERBOSE, 1L);
290 // Construct an SMTP URL in the form of:
291 // smtp[s]://target_host/source_host
292 // This looks weird but libcurl uses that last part to set our name for EHLO or HELO.
293 // We check for "smtp://" and "smtps://" because an admin may have put those prefixes in a smart-host entry
294 // If there is no prefix we add "smtp://"
295 extract_token(try_this_mx, mxes, i, '|', (sizeof try_this_mx - 7));
296 snprintf(smtp_url, sizeof smtp_url,
298 (((!strncasecmp(try_this_mx, HKEY("smtp://")))
299 || (!strncasecmp(try_this_mx, HKEY("smtps://")))) ? "" : "smtp://"),
300 try_this_mx, CtdlGetConfigStr("c_fqdn")
302 curl_easy_setopt(curl, CURLOPT_URL, smtp_url);
303 syslog(LOG_DEBUG, "smtpclient: trying MX %d of %d <%s>", i+1, num_mx, smtp_url); // send the message
304 res = curl_easy_perform(curl);
305 curl_easy_getinfo(curl, CURLINFO_RESPONSE_CODE, &response_code);
307 "smtpclient: libcurl returned %d (%s) , SMTP response %ld",
308 res, curl_easy_strerror(res), response_code
311 if ((res != CURLE_OK) && (response_code == 0)) { // check for errors
315 curl_slist_free_all(recipients);
316 recipients = NULL; // this gets reused; avoid double-free
317 curl_easy_cleanup(curl);
318 curl = NULL; // this gets reused; avoid double-free
320 // Trim the error message buffer down to just the actual message
321 trim_response(response_code, response);
325 FreeStrBuf(&s.TheMessage);
329 return ((int) response_code);
333 // Process one outbound message.
334 void smtp_process_one_msg(long qmsgnum) {
335 struct CtdlMessage *msg = NULL;
342 int delete_this_queue = 0;
343 char server_response[SIZ];
345 msg = CtdlFetchMessage(qmsgnum, 1);
347 syslog(LOG_WARNING, "smtpclient: msg#%ld does not exist", qmsgnum);
351 instr = msg->cm_fields[eMessageText];
352 msg->cm_fields[eMessageText] = NULL;
355 // if the queue job message has any CRLF's convert them to LF's
357 while (crlf = strstr(instr, "\r\n"), crlf != NULL) {
358 strcpy(crlf, crlf + 1);
361 // Strip out the headers and we are now left with just the instructions.
362 char *soi = strstr(instr, "\n\n");
364 strcpy(instr, soi + 2);
368 time_t submitted = time(NULL);
369 time_t attempted = 0;
370 char *bounceto = NULL;
371 char *envelope_from = NULL;
372 char *source_room = NULL;
375 for (i = 0; i < num_tokens(instr, '\n'); ++i) {
376 extract_token(cfgline, instr, i, '\n', sizeof cfgline);
377 if (!strncasecmp(cfgline, HKEY("msgid|"))) msgid = atol(&cfgline[6]);
378 if (!strncasecmp(cfgline, HKEY("submitted|"))) submitted = atol(&cfgline[10]);
379 if (!strncasecmp(cfgline, HKEY("attempted|"))) attempted = atol(&cfgline[10]);
380 if (!strncasecmp(cfgline, HKEY("bounceto|"))) bounceto = strdup(&cfgline[9]);
381 if (!strncasecmp(cfgline, HKEY("envelope_from|"))) envelope_from = strdup(&cfgline[14]);
382 if (!strncasecmp(cfgline, HKEY("source_room|"))) source_room = strdup(&cfgline[12]);
385 int should_try_now = 0;
386 if (attempted < submitted) { // If no attempts have been made yet, try now
389 else if ((attempted - submitted) <= 14400) {
390 if ((time(NULL) - attempted) > 1800) { // First four hours, retry every 30 minutes
395 if ((time(NULL) - attempted) > 14400) { // After that, retry once every 4 hours
400 if (should_try_now) {
401 syslog(LOG_DEBUG, "smtpclient: attempting delivery of message <%ld> now", qmsgnum);
403 syslog(LOG_DEBUG, "smtpclient: this message originated in <%s>", source_room);
405 StrBuf *NewInstr = NewStrBuf();
406 StrBufAppendPrintf(NewInstr, "Content-type: " SPOOLMIME "\n\n");
407 StrBufAppendPrintf(NewInstr, "msgid|%ld\n", msgid);
408 StrBufAppendPrintf(NewInstr, "submitted|%ld\n", submitted);
410 StrBufAppendPrintf(NewInstr, "bounceto|%s\n", bounceto);
413 StrBufAppendPrintf(NewInstr, "envelope_from|%s\n", envelope_from);
415 for (i = 0; i < num_tokens(instr, '\n'); ++i) {
416 extract_token(cfgline, instr, i, '\n', sizeof cfgline);
417 if (!strncasecmp(cfgline, HKEY("remote|"))) {
419 int previous_result = extract_int(cfgline, 2);
420 if ((previous_result == 0) || (previous_result == 4)) {
421 int new_result = 421;
422 extract_token(recp, cfgline, 1, '|', sizeof recp);
423 new_result = smtp_attempt_delivery(msgid, recp, envelope_from, source_room, server_response);
424 syslog(LOG_DEBUG, "smtpclient: recp: <%s> , result: %d (%s)", recp, new_result, server_response);
425 if ((new_result / 100) == 2) {
429 if ((new_result / 100) == 5) {
435 StrBufAppendPrintf(NewInstr, "remote|%s|%ld|%ld (%s)\n", recp, (new_result / 100), new_result, server_response);
441 StrBufAppendPrintf(NewInstr, "attempted|%ld\n", time(NULL));
443 // All deliveries have now been attempted. Now determine the disposition of this queue entry.
445 time_t age = time(NULL) - submitted;
447 "smtpclient: submission age: %ldd%ldh%ldm%lds",
448 (age / 86400), ((age % 86400) / 3600), ((age % 3600) / 60), (age % 60));
449 syslog(LOG_DEBUG, "smtpclient: num_success=%d , num_fail=%d , num_delayed=%d", num_success, num_fail, num_delayed);
451 // If there are permanent fails on this attempt, deliver a bounce to the user.
452 // The 5XX fails will be recorded in the rewritten queue, but they will be removed before the next attempt.
454 smtp_do_bounce(ChrPtr(NewInstr), SDB_BOUNCE_FATALS);
456 // If all deliveries have either succeeded or failed, we are finished with this queue entry.
457 if (num_delayed == 0) {
458 delete_this_queue = 1;
460 // If it's been more than five days, give up and tell the sender that delivery failed
461 else if ((time(NULL) - submitted) > SMTP_DELIVER_FAIL) {
462 smtp_do_bounce(ChrPtr(NewInstr), SDB_BOUNCE_ALL);
463 delete_this_queue = 1;
465 // If it's been more than four hours but less than five days, warn the sender that delivery is delayed
466 else if (((attempted - submitted) < SMTP_DELIVER_WARN) && ((time(NULL) - submitted) >= SMTP_DELIVER_WARN)) {
467 smtp_do_bounce(ChrPtr(NewInstr), SDB_WARN);
470 if (delete_this_queue) {
471 syslog(LOG_DEBUG, "smtpclient: %ld deleting", qmsgnum);
472 deletes[0] = qmsgnum;
474 CtdlDeleteMessages(SMTP_SPOOLOUT_ROOM, deletes, 2, "");
475 FreeStrBuf(&NewInstr); // We have to free NewInstr here, no longer needed
478 // replace the old queue entry with the new one
479 syslog(LOG_DEBUG, "smtpclient: %ld rewriting", qmsgnum);
480 msg = convert_internet_message_buf(&NewInstr); // This function will free NewInstr for us
481 CtdlSubmitMsg(msg, NULL, SMTP_SPOOLOUT_ROOM);
483 CtdlDeleteMessages(SMTP_SPOOLOUT_ROOM, &qmsgnum, 1, "");
487 syslog(LOG_DEBUG, "smtpclient: msg#%ld retry time not reached", qmsgnum);
490 if (bounceto != NULL) {
493 if (envelope_from != NULL) {
496 if (source_room != NULL) {
503 // Callback for smtp_do_queue()
504 void smtp_add_msg(long msgnum, void *userdata) {
505 Array *smtp_queue = (Array *) userdata;
506 array_append(smtp_queue, &msgnum);
511 FULL_QUEUE_RUN, // try to process the entire queue, including messages that have already been attempted
512 QUICK_QUEUE_RUN // only process jobs in the queue that have not been tried yet
516 // Run through the queue sending out messages.
517 void smtp_do_queue(int type_of_queue_run) {
518 static int doing_smtpclient = 0;
521 // This is a concurrency check to make sure only one smtpclient run is done at a time.
522 begin_critical_section(S_SMTPQUEUE);
523 if (doing_smtpclient) {
524 end_critical_section(S_SMTPQUEUE);
527 doing_smtpclient = 1;
528 end_critical_section(S_SMTPQUEUE);
530 syslog(LOG_DEBUG, "smtpclient: start %s queue run , last_queue_job_processed=%ld , last_queue_job_submitted=%ld",
531 (type_of_queue_run == QUICK_QUEUE_RUN ? "quick" : "full"),
532 last_queue_job_processed, last_queue_job_submitted
535 if (CtdlGetRoom(&CC->room, SMTP_SPOOLOUT_ROOM) != 0) {
536 syslog(LOG_WARNING, "smtpclient: cannot find room <%s>", SMTP_SPOOLOUT_ROOM);
537 doing_smtpclient = 0;
541 // This array will hold the list of queue job messages
542 Array *smtp_queue = array_new(sizeof(long));
543 if (smtp_queue == NULL) {
544 syslog(LOG_WARNING, "smtpclient: cannot allocate queue array");
545 doing_smtpclient = 0;
549 // Put the queue in memory so we can close the db cursor
551 (type_of_queue_run == QUICK_QUEUE_RUN ? MSGS_GT : MSGS_ALL), // quick = new jobs; full = all jobs
552 (type_of_queue_run == QUICK_QUEUE_RUN ? last_queue_job_processed : 0), // quick = new jobs; full = all jobs
554 SPOOLMIME, // Searching for Content-type of SPOOLIME will give us only queue instruction messages
556 smtp_add_msg, // That's our callback function to add a job to the queue
560 // We are ready to run through the queue now.
561 syslog(LOG_DEBUG, "smtpclient: %d messages to be processed", array_len(smtp_queue));
562 for (i = 0; i < array_len(smtp_queue); ++i) {
564 memcpy(&m, array_get_element_at(smtp_queue, i), sizeof(long));
565 smtp_process_one_msg(m);
568 array_free(smtp_queue);
569 last_queue_job_processed = last_queue_job_submitted;
570 doing_smtpclient = 0;
571 syslog(LOG_DEBUG, "smtpclient: end %s queue run , last_queue_job_processed=%ld , last_queue_job_submitted=%ld",
572 (type_of_queue_run == QUICK_QUEUE_RUN ? "quick" : "full"),
573 last_queue_job_processed, last_queue_job_submitted
578 // The "full" queue run goes through the entire queue, attempting delivery for newly submitted messages,
579 // retrying failed deliveries periodically, and handling undeliverable messages.
580 void smtp_do_queue_full(void) {
581 smtp_do_queue(FULL_QUEUE_RUN);
585 // The "quick" queue run only handles newly submitted messages, allowing them to be delivered immediately
586 // instead of waiting for the next "full" queue run.
587 void smtp_do_queue_quick(void) {
588 if (last_queue_job_submitted > last_queue_job_processed) {
589 smtp_do_queue(QUICK_QUEUE_RUN);
594 // Initialization function, called from modules_init.c
595 char *ctdl_module_init_smtpclient(void) {
597 CtdlRegisterMessageHook(smtp_aftersave, EVT_AFTERSAVE);
598 CtdlRegisterSessionHook(smtp_do_queue_quick, EVT_HOUSE, PRIO_AGGR + 51);
599 CtdlRegisterSessionHook(smtp_do_queue_full, EVT_TIMER, PRIO_AGGR + 51);
600 smtp_init_spoolout();
604 // return our module id for the log