commit e8ac8be0a3d56ba0a189fb970c339ac6e84769be Author: Heiko Schlittermann (HS12-RIPE) Date: Mon May 3 15:53:28 2021 +0200 Fix DANE + SNI handling (Bug 2265) Broken in d8e99d6047e709b35eabb1395c2046100d1a1dda Thanks to JGH and Wolfgang Breyha for contributions. diff --git a/src/src/transports/smtp.c b/src/src/transports/smtp.c index f26e2337a..9ee6a578a 100644 --- a/src/src/transports/smtp.c +++ b/src/src/transports/smtp.c @@ -2015,7 +2015,7 @@ if (continue_hostname && continue_proxy_cipher) { case OK: sx->conn_args.dane = TRUE; ob->tls_tempfail_tryclear = FALSE; /* force TLS */ - ob->tls_sni = sx->first_addr->domain; /* force SNI */ + ob->tls_sni = sx->conn_args.host->name; /* force SNI */ break; case FAIL_FORCED: break; default: set_errno_nohost(sx->addrlist, ERRNO_DNSDEFER, @@ -2097,7 +2097,7 @@ if (!continue_hostname) { case OK: sx->conn_args.dane = TRUE; ob->tls_tempfail_tryclear = FALSE; /* force TLS */ - ob->tls_sni = sx->first_addr->domain; /* force SNI */ + ob->tls_sni = sx->conn_args.host->name; /* force SNI */ break; case FAIL_FORCED: break; default: set_errno_nohost(sx->addrlist, ERRNO_DNSDEFER, commit ed64b5c2f0f44db27ae48128fc97d5ad8406a28e Author: Jeremy Harris Date: Tue May 4 13:06:31 2021 +0100 Fix ${ipv6norm:} (cherry picked from commit 8b4b6ac90766b11fa74fa3001778b49456adbe42) diff --git a/src/src/host.c b/src/src/host.c index dbc7ce20d..ee9d323a7 100644 --- a/src/src/host.c +++ b/src/src/host.c @@ -1197,9 +1197,9 @@ for (c = buffer, k = -1, i = 0; i < 8; i++) c++; } -c[-1] = '\0'; /* drop trailing colon */ +*--c = '\0'; /* drop trailing colon */ -/* debug_printf("%s: D k %d <%s> <%s>\n", __FUNCTION__, k, d, d + 2*(k+1)); */ +/* debug_printf("%s: D k %d <%s> <%s>\n", __FUNCTION__, k, buffer, buffer + 2*(k+1)); */ if (k >= 0) { /* collapse */ c = d + 2*(k+1); commit e3311bc211d20617d90e75ea8ec7e01e6210483d Merge: 6429b0fc7 ed64b5c2f Author: Heiko Schlittermann (HS12-RIPE) Date: Sun May 9 11:25:09 2021 +0200 Merge branch 'exim-4.94+fixes' of ssh://git.exim.org/home/git/exim into exim-4.94+fixes commit 53b8b89b51a9b3f28b8e476528be0237c628261c Merge: e8ac8be0a e3311bc21 Author: Heiko Schlittermann (HS12-RIPE) Date: Sun May 9 11:26:03 2021 +0200 Merge branch 'exim-4.94+fixes' into exim-4.94.2+fixes commit c1faf04b865465894c7ca41ab4585fb69d4a5936 Author: Jeremy Harris Date: Wed May 12 15:01:12 2021 +0100 Named Queues: fix immediate-delivery. Bug 2743 (cherry picked from commit 159cf206c97f876b07829d92db2217689745c1e8) diff --git a/src/src/exim.c b/src/src/exim.c index ee75739ec..7411f0467 100644 --- a/src/src/exim.c +++ b/src/src/exim.c @@ -2789,9 +2789,11 @@ on the second character (the one after '-'), to save some effort. */ else badarg = TRUE; break; - /* -MCG: set the queue name, to a non-default value */ + /* -MCG: set the queue name, to a non-default value. Arguably, anything + from the commandline should be tainted - but we will need an untainted + value for the spoolfile when doing a -odi delivery process. */ - case 'G': if (++i < argc) queue_name = string_copy_taint(exim_str_fail_toolong(argv[i], EXIM_DRIVERNAME_MAX, "-MCG"), TRUE); + case 'G': if (++i < argc) queue_name = string_copy_taint(exim_str_fail_toolong(argv[i], EXIM_DRIVERNAME_MAX, "-MCG"), FALSE); else badarg = TRUE; break; commit 1e7013764134c0a4a0f1fedbf33d87a21d76b3b5 Merge: 53b8b89b5 c1faf04b8 Author: Heiko Schlittermann (HS12-RIPE) Date: Thu May 13 08:31:37 2021 +0200 Merge branch 'exim-4.94+fixes' into exim-4.94.2+fixes How to make sure that cherry-picking to a +fixes branch goes to the *latest* +fixes branch? commit 20812729e3e47a193a21d326ecd036d67a8b2724 Author: Heiko Schlittermann (HS12-RIPE) Date: Sun May 16 19:11:19 2021 +0200 Fix host_name_lookup (Close 2747) Thanks to Nico R for providing a reproducing configuration. host_lookup = * message_size_limit = ${if def:sender_host_name {32M}{32M}} acl_smtp_connect = acl_smtp_connect acl_smtp_rcpt = acl_smtp_rcpt begin acl acl_smtp_connect: warn ratelimit = 256 / 1m / per_conn accept acl_smtp_rcpt: accept hosts = 127.0.0.* begin routers null: driver = accept transport = null begin transports null: driver = appendfile file = /dev/null Tested with swaks -f mailbox@example.org -t mailbox@example.org --pipe 'exim -bh 127.0.0.1 -C /opt/exim/etc/exim-bug.conf' The IP must have a PTR to "localhost." to reproduce it. diff --git a/src/src/host.c b/src/src/host.c index ee9d323a7..2047b9798 100644 --- a/src/src/host.c +++ b/src/src/host.c @@ -1581,7 +1581,7 @@ Put it in permanent memory. */ if (hosts->h_aliases) { - int count = 1; + int count = 1; /* need 1 more for terminating NULL */ uschar **ptr; for (uschar ** aliases = USS hosts->h_aliases; *aliases; aliases++) count++; @@ -1690,7 +1690,7 @@ while ((ordername = string_nextinlist(&list, &sep, NULL, 0))) { uschar **aptr = NULL; int ssize = 264; - int count = 0; + int count = 1; /* need 1 more for terminating NULL */ int old_pool = store_pool; sender_host_dnssec = dns_is_secure(dnsa);