libclamav/mbox.c
b151ef55
 /*
  *  Copyright (C) 2002 Nigel Horne <njh@bandsman.co.uk>
  *
  *  This program is free software; you can redistribute it and/or modify
  *  it under the terms of the GNU General Public License as published by
  *  the Free Software Foundation; either version 2 of the License, or
  *  (at your option) any later version.
  *
  *  This program is distributed in the hope that it will be useful,
  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
  *  GNU General Public License for more details.
  *
  *  You should have received a copy of the GNU General Public License
  *  along with this program; if not, write to the Free Software
  *  Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA.
7cef72ea
  *
  * Change History:
  * $Log: mbox.c,v $
7fca6080
  * Revision 1.21  2003/12/11 14:35:48  nigelhorne
  * Better handling of encapsulated messages
  *
f5e9abc8
  * Revision 1.20  2003/12/06 04:03:26  nigelhorne
  * Handle hand crafted emails that incorrectly set multipart headers
  *
2227f20e
  * Revision 1.19  2003/11/21 07:26:31  nigelhorne
  * Scan multipart alternatives that have no boundaries, finds some uuencoded happy99
  *
181c7548
  * Revision 1.18  2003/11/17 08:13:21  nigelhorne
  * Handle spaces at the end of lines of MIME headers
  *
04421a14
  * Revision 1.17  2003/11/06 05:06:42  nigelhorne
  * Some applications weren't being scanned
  *
295e425f
  * Revision 1.16  2003/11/04 08:24:00  nigelhorne
  * Handle multipart messages that have no text portion
  *
07cbf822
  * Revision 1.15  2003/10/12 20:13:49  nigelhorne
  * Use NO_STRTOK_R consistent with message.c
  *
fdc8a467
  * Revision 1.14  2003/10/12 12:37:11  nigelhorne
  * Appledouble encoded EICAR now found
  *
4674dc9a
  * Revision 1.13  2003/10/01 09:27:42  nigelhorne
  * Handle content-type header going over to a new line
  *
6ecba059
  * Revision 1.12  2003/09/29 17:10:19  nigelhorne
  * Moved stub from heap to stack since its maximum size is known
  *
47ab99fa
  * Revision 1.11  2003/09/29 12:58:32  nigelhorne
  * Handle Content-Type: /; name="eicar.com"
  *
7cef72ea
  * Revision 1.10  2003/09/28 10:06:34  nigelhorne
  * Compilable under SCO; removed duplicate code with message.c
  *
b151ef55
  */
7fca6080
 static	char	const	rcsid[] = "$Id: mbox.c,v 1.21 2003/12/11 14:35:48 nigelhorne Exp $";
b151ef55
 
 #ifndef	CL_DEBUG
0bcad2b1
 /*#define	NDEBUG	/* map CLAMAV debug onto standard */
b151ef55
 #endif
 
 #ifdef CL_THREAD_SAFE
f5e9abc8
 #ifndef	_REENTRANT
b151ef55
 #define	_REENTRANT	/* for Solaris 2.8 */
 #endif
f5e9abc8
 #endif
b151ef55
 
 #include <stdio.h>
 #include <stdlib.h>
 #include <errno.h>
 #include <assert.h>
 #include <string.h>
 #include <strings.h>
 #include <ctype.h>
 #include <time.h>
 #include <unistd.h>
 #include <fcntl.h>
 #include <sys/stat.h>
 #include <sys/types.h>
0bcad2b1
 #include <sys/param.h>
b151ef55
 #include <clamav.h>
 
 #include "table.h"
 #include "mbox.h"
 #include "blob.h"
 #include "text.h"
 #include "message.h"
 #include "others.h"
 #include "defaults.h"
7fca6080
 #include "str.h"
b151ef55
 
07cbf822
 #if	defined(NO_STRTOK_R) || !defined(CL_THREAD_SAFE)
b151ef55
 #undef strtok_r
 #undef __strtok_r
 #define strtok_r(a,b,c)	strtok(a,b)
 #endif
 
 /* required for AIX and Tru64 */
 #ifdef TRUE
 #undef TRUE
 #endif
 #ifdef FALSE
 #undef FALSE
 #endif
 
 typedef enum    { FALSE = 0, TRUE = 1 } bool;
 
7fca6080
 static	void	parseEmailHeaders(message *m, table_t *rfc821Table);
 static	int	parseEmailBody(message *mainMessage, blob **blobsIn, int nBlobs, text *textIn, const char *dir, table_t *rfc821Table, table_t *subtypeTable);
b151ef55
 static	int	boundaryStart(const char *line, const char *boundary);
 static	int	endOfMessage(const char *line, const char *boundary);
 static	int	initialiseTables(table_t **rfc821Table, table_t **subtypeTable);
 static	int	getTextPart(message *const messages[], size_t size);
 static	size_t	strip(char *buf, int len);
 static	size_t	strstrip(char *s);
 static	bool	continuationMarker(const char *line);
 static	int	parseMimeHeader(message *m, const char *cmd, const table_t *rfc821Table, const char *arg);
0bcad2b1
 static	bool	saveFile(const blob *b, const char *dir);
b151ef55
 
 /* Maximum number of attachements that we accept */
 #define	MAX_ATTACHMENTS	10
 
 /* Maximum line length according to RFC821 */
 #define	LINE_LENGTH	1000
 
 /* Hashcodes for our hash tables */
 #define	CONTENT_TYPE			1
 #define	CONTENT_TRANSFER_ENCODING	2
 #define	CONTENT_DISPOSITION		3
 
 /* Mime sub types */
 #define	PLAIN		1
 #define	ENRICHED	2
 #define	HTML		3
 #define	RICHTEXT	4
 #define	MIXED		5
 #define	ALTERNATIVE	6
 #define	DIGEST		7
 #define	SIGNED		8
 #define	PARALLEL	9
 #define	RELATED		10	/* RFC2387 */
 #define	REPORT		11	/* RFC1892 */
fdc8a467
 #define	APPLEDOUBLE	12	/* Handling of this in only noddy for now */
b151ef55
 
 static	const	struct tableinit {
 	const	char	*key;
 	int	value;
 } rfc821headers[] = {
 	{	"Content-Type:",		CONTENT_TYPE		},
 	{	"Content-Transfer-Encoding:",	CONTENT_TRANSFER_ENCODING	},
 	{	"Content-Disposition:",		CONTENT_DISPOSITION	},
 	{	NULL,				0			}
 }, mimeSubtypes[] = {
 		/* subtypes of Text */
 	{	"plain",	PLAIN		},
 	{	"enriched",	ENRICHED	},
 	{	"html",		HTML		},
 	{	"richtext",	RICHTEXT	},
 		/* subtypes of Multipart */
 	{	"mixed",	MIXED		},
 	{	"alternative",	ALTERNATIVE	},
 	{	"digest",	DIGEST		},
 	{	"signed",	SIGNED		},
 	{	"parallel",	PARALLEL	},
 	{	"related",	RELATED		},
 	{	"report",	REPORT		},
fdc8a467
 	{	"appledouble",	APPLEDOUBLE	},
b151ef55
 	{	NULL,		0		}
 };
 
7cef72ea
 /* Maximum filenames under various systems */
 #ifndef	NAME_MAX	/* e.g. Linux */
 
 #ifdef	MAXNAMELEN	/* e.g. Solaris */
 #define	NAME_MAX	MAXNAMELEN
 #else
 
 #ifdef	FILENAME_MAX	/* e.g. SCO */
 #define	NAME_MAX	FILENAME_MAX
 #endif
 
 #endif
 
 #endif
 
b151ef55
 /*
  * TODO: when signal handling is added, need to remove temp files when a
  * signal is received
  * TODO: add option to scan in memory not via temp files, perhaps with a
  * named pipe or memory mapped file?
15c8cace
  * TODO: if debug is enabled, catch a segfault and dump the current e-mail
  * in it's entirety, then call abort()
c6259ac5
  * TODO: parse .msg format files
fdc8a467
  * TODO: fully handle AppleDouble format, see
  * http://www.lazerware.com/formats/Specs/AppleSingle_AppleDouble.pdf
b151ef55
  */
 int
 cl_mbox(const char *dir, int desc)
 {
c6259ac5
 	int retcode, i;
 	bool isMbox;	/*
 			 * is it a UNIX style mbox with more than one
 			 * mail message, or just a single mail message?
 			 */
b151ef55
 	message *m;
 	table_t	*rfc821Table, *subtypeTable;
 	FILE *fd;
c6259ac5
 	char buffer[LINE_LENGTH];
 #ifdef CL_THREAD_SAFE
 	char *strptr;
 #endif
b151ef55
 
 	cli_dbgmsg("in mbox()\n");
 
c6259ac5
 	i = dup(desc);
 	if((fd = fdopen(i, "rb")) == NULL) {
 		cli_errmsg("Can't open descriptor %d\n", desc);
 		close(i);
b151ef55
 		return -1;
c6259ac5
 	}
 	if(fgets(buffer, sizeof(buffer), fd) == NULL) {
 		/* empty message */
 		fclose(fd);
 		return 0;
 	}
b151ef55
 	m = messageCreate();
 	assert(m != NULL);
 
c6259ac5
 	if(initialiseTables(&rfc821Table, &subtypeTable) < 0) {
 		messageDestroy(m);
 		fclose(fd);
0bcad2b1
 		return -1;
b151ef55
 	}
 
c6259ac5
 	isMbox = (strncmp(buffer, "From ", 5) == 0);
b151ef55
 
c6259ac5
 	if(isMbox) {
b151ef55
 		/*
c6259ac5
 		 * Have been asked to check a UNIX style mbox file, which
 		 * may contain more than one e-mail message to decode
b151ef55
 		 */
c6259ac5
 		bool inHeader = FALSE;
 		bool inMimeHeader = FALSE;
 		bool lastLineWasEmpty = TRUE;
 		bool first = TRUE;
b151ef55
 
c6259ac5
 		do {
 			/*cli_dbgmsg("read: %s", buffer);*/
b151ef55
 
 			/*
c6259ac5
 			 * Handle this where we're mid point through this stuff
 			 *	Content-Type: multipart/alternative;
 			 *		boundary="----foo"
b151ef55
 			 */
c6259ac5
 			if(inHeader && ((buffer[0] == '\t') || (buffer[0] == ' ')))
 				inMimeHeader = TRUE;
 			if(inMimeHeader) {
 				const char *ptr;
 
 				assert(!first);
 
 				if(!continuationMarker(buffer))
 					inMimeHeader = FALSE;	 /* no more args */
b151ef55
 
 				/*
c6259ac5
 				 * Add all the arguments on the line
b151ef55
 				 */
c6259ac5
 				for(ptr = strtok_r(buffer, ";\r\n", &strptr); ptr; ptr = strtok_r(NULL, ":\r\n", &strptr))
 					messageAddArgument(m, ptr);
 
 			} else if((!inHeader) && lastLineWasEmpty && (strncmp(buffer, "From ", 5) == 0)) {
b151ef55
 				/*
c6259ac5
 				 * New message, save the previous message, if any
b151ef55
 				 */
c6259ac5
 				if(!first) {
 					/*
 					 * End of the current message, add it and look
 					 * for the start of the next one
 					 */
 					messageClean(m);
 					if(messageGetBody(m))
7fca6080
 						if(!parseEmailBody(m,  NULL, 0, NULL, dir, rfc821Table, subtypeTable))
c6259ac5
 							break;
 					/*
 					 * Starting a new message, throw away all the
 					 * information about the old one
 					 */
 					messageReset(m);
 				} else
 					first = FALSE;
b151ef55
 
c6259ac5
 				lastLineWasEmpty = inHeader = TRUE;
 				cli_dbgmsg("Finished processing message\n");
 			} else if(inHeader) {
0bcad2b1
 
c6259ac5
 				cli_dbgmsg("Deal with header %s", buffer);
b151ef55
 
c6259ac5
 				/*
 				 * A blank line signifies the end of the header and
 				 * the start of the text
 				 */
 				if((strstrip(buffer) == 0) || (buffer[0] == '\n') || (buffer[0] == '\r')) {
 					cli_dbgmsg("End of header information\n");
 					inHeader = FALSE;
 				} else {
 					const bool isLastLine = !continuationMarker(buffer);
 					const char *cmd = strtok_r(buffer, " \t", &strptr);
 
 					if (cmd && *cmd) {
 						const char *arg = strtok_r(NULL, "\r\n", &strptr);
 
 						if(arg)
 							if(parseMimeHeader(m, cmd, rfc821Table, arg) == CONTENT_TYPE)
 								inMimeHeader = !isLastLine;
 					}
b151ef55
 				}
c6259ac5
 			} else {
 				assert(!first);
b151ef55
 
c6259ac5
 				/*cli_dbgmsg("adding line %s", buffer);*/
b151ef55
 
c6259ac5
 				lastLineWasEmpty = ((buffer[0] == '\n') || (buffer[0] == '\r'));
 				/*
 				 * Add this line to the end of the linked list
 				 * of lines. This isn't needed when using
 				 * .forward since the rest of the file *must*
 				 * be the text so a single fread() should
 				 * suffice. Still, it does no harm and is more
 				 * flexible this way
 				 *
 				 * Note that the terminating newline is not
 				 * added
 				 */
 				messageAddLine(m, strtok_r(buffer, "\r\n", &strptr));
 			}
 		} while(fgets(buffer, sizeof(buffer), fd) != NULL);
 	} else {
7fca6080
 		/*
 		 * It's a single message, parse the headers then the body
 		 */
c6259ac5
 		do {
b151ef55
 			/*
7fca6080
 			 * cli_chomp coredumps for cli_chomp("")
 			 * or cli_chomp("\r");
c6259ac5
 			 */
7fca6080
 			/*cli_chomp(buffer);*/
 			char *ptr = strrchr(buffer, '\n');
 			if(ptr)
 				*ptr = '\0';
 			ptr = strrchr(buffer, '\r');
 			if(ptr)
 				*ptr = '\0';
 
 			messageAddLine(m, buffer);
c6259ac5
 		} while(fgets(buffer, sizeof(buffer), fd) != NULL);
7fca6080
 
 		parseEmailHeaders(m, rfc821Table);
b151ef55
 	}
 
 	fclose(fd);
 
c6259ac5
 	retcode = 0;
 
b151ef55
 	/*
 	 * Write out the last entry in the mailbox
 	 */
c6259ac5
 	messageClean(m);
 	if(messageGetBody(m))
7fca6080
 		if(!parseEmailBody(m, NULL, 0, NULL, dir, rfc821Table, subtypeTable))
c6259ac5
 			retcode = -1;
b151ef55
 
 	/*
 	 * Tidy up and quit
 	 */
 	messageDestroy(m);
 
 	tableDestroy(rfc821Table);
 	tableDestroy(subtypeTable);
 
 	cli_dbgmsg("cli_mbox returning %d\n", retcode);
 
 	return retcode;
 }
 
 /*
7fca6080
  * The given message contains a raw e-mail.
  *
  * This function parses the headers of m and sets the message's arguments
  */
 static void
 parseEmailHeaders(message *m, table_t *rfc821Table)
 {
 	/* !isMbox => single mail message */
 	bool inHeader = TRUE;
 	bool inMimeHeader = FALSE;
 	text *t, *msgText = messageToText(m);
 
 	t = msgText;
 	assert(t != NULL);
 
 	do {
 		char *buffer = strdup(t->t_text);
 #ifdef CL_THREAD_SAFE
 		char *strptr;
 #endif
 
 		/*cli_chomp(buffer);*/
 		char *ptr = strrchr(buffer, '\n');
 		if(ptr)
 			*ptr = '\0';
 		ptr = strrchr(buffer, '\r');
 		if(ptr)
 			*ptr = '\0';
 		/*
 		 * State machine:
 		 *	inMimeHeader	= handling mime commands over
 		 *				more than one line
 		 *	inHeader	= handling e-mail header
 		 *	otherwise	= handling e-mail body
 		 */
 
 		/*
 		 * Section B.2 of RFC822 says TAB or SPACE means
 		 * a continuation of the previous entry
 		 */
 		if(inHeader && ((buffer[0] == '\t') || (buffer[0] == ' ')))
 			inMimeHeader = TRUE;
 		if(inMimeHeader) {
 			const char *ptr;
 
 			assert(inHeader);
 
 			if(!continuationMarker(buffer))
 				inMimeHeader = FALSE;	 /* no more args */
 
 			/*
 			 * Add all the arguments on the line
 			 */
 			for(ptr = strtok_r(buffer, ";", &strptr); ptr; ptr = strtok_r(NULL, ":", &strptr))
 				messageAddArgument(m, ptr);
 		} else if(inHeader) {
 
 			cli_dbgmsg("Deal with header %s\n", buffer);
 
 			/*
 			 * A blank line signifies the end of the header and
 			 * the start of the text
 			 */
 			if(strstrip(buffer) == 0) {
 				cli_dbgmsg("End of header information\n");
 				break;
 			} else {
 				const bool isLastLine = !continuationMarker(buffer);
 				const char *cmd = strtok_r(buffer, " \t", &strptr);
 
 				if (cmd && *cmd) {
 					const char *arg = strtok_r(NULL, "", &strptr);
 
 					if(arg)
 						if(parseMimeHeader(m, cmd, rfc821Table, arg) == CONTENT_TYPE)
 							inMimeHeader = !isLastLine;
 				}
 			}
 		}
 	} while((t = t->t_next) != NULL);
 
 	textDestroy(msgText);
 }
 
 /*
b151ef55
  * This is a recursive routine.
  *
7fca6080
  * This function parses the body of mainMessage and saves its attachments in dir
  *
b151ef55
  * mainMessage is the buffer to be parsed. First time of calling it'll be
  *	the whole message. Later it'll be parts of a multipart message
  * textIn is the plain text message being built up so far
  * blobsIn contains the array of attachments found so far
  *
0bcad2b1
  * Returns:
b151ef55
  *	0 for fail
  *	1 for success, attachements saved
  *	2 for success, attachements not saved
  */
 static int	/* success or fail */
7fca6080
 parseEmailBody(message *mainMessage, blob **blobsIn, int nBlobs, text *textIn, const char *dir, table_t *rfc821Table, table_t *subtypeTable)
b151ef55
 {
 	char *ptr;
 	message *messages[MAXALTERNATIVE];
0bcad2b1
 	int inhead, inMimeHead, i, rc, htmltextPart, multiparts = 0;
b151ef55
 	text *aText;
 	blob *blobList[MAX_ATTACHMENTS], **blobs;
 	const char *cptr;
 
7fca6080
 	cli_dbgmsg("in parseEmailBody(nBlobs = %d)\n", nBlobs);
b151ef55
 
 	/* Pre-assertions */
 	if(nBlobs >= MAX_ATTACHMENTS) {
 		cli_warnmsg("Not all attachments will be scanned\n");
 		return 2;
 	}
 
 	aText = textIn;
 	blobs = blobsIn;
 
 	/* Anything left to be parsed? */
0bcad2b1
 	if(mainMessage && (messageGetBody(mainMessage) != NULL)) {
b151ef55
 		int numberOfAttachments = 0;
 		mime_type mimeType;
 		const char *mimeSubtype;
 		const text *t_line;
f5e9abc8
 		/*bool isAlternative;*/
b151ef55
 		const char *boundary;
 		message *aMessage;
 #ifdef CL_THREAD_SAFE
 		char *strptr;
 #endif
 
c6259ac5
 		cli_dbgmsg("Parsing mail file\n");
 
b151ef55
 		mimeType = messageGetMimeType(mainMessage);
 		mimeSubtype = messageGetMimeSubtype(mainMessage);
 
 		if((mimeType == TEXT) && (tableFind(subtypeTable, mimeSubtype) == PLAIN)) {
 			/*
 			 * This is effectively no encoding, notice that we
 			 * don't check that charset is us-ascii
 			 */
 			cli_dbgmsg("assume no encoding\n");
 			mimeType = NOMIME;
 		}
 
c6259ac5
 		cli_dbgmsg("mimeType = %d\n", mimeType);
 
b151ef55
 		switch(mimeType) {
 		case NOMIME:
 			aText = textAddMessage(aText, mainMessage);
 			break;
 		case TEXT:
 			if(tableFind(subtypeTable, mimeSubtype) == PLAIN)
 				aText = textCopy(messageGetBody(mainMessage));
 			break;
 		case MULTIPART:
c6259ac5
 
b151ef55
 			assert(mimeSubtype[0] != '\0');
 
 			boundary = messageFindArgument(mainMessage, "boundary");
 
 			if(boundary == NULL) {
 				cli_warnmsg("Multipart MIME message contains no boundaries\n");
2227f20e
 				/* Broken e-mail message */
 				mimeType = NOMIME;
 				/*
 				 * The break means that we will still
 				 * check if the file contains a uuencoded file
 				 */
 				break;
b151ef55
 			}
 
 			/*
 			 * Get to the start of the first message
 			 */
bf8ea488
 			for(t_line = messageGetBody(mainMessage); t_line; t_line = t_line->t_next)
 				if(boundaryStart(t_line->t_text, boundary))
b151ef55
 					break;
 
 			if(t_line == NULL) {
 				cli_warnmsg("Multipart MIME message contains no parts\n");
bf8ea488
 				/*
 				 * Free added by Thomas Lamy
 				 * <Thomas.Lamy@in-online.net>
 				 */
 				free((char *)boundary);
2227f20e
 				mimeType = NOMIME;
 				/*
 				 * The break means that we will still
 				 * check if the file contains a uuencoded file
 				 */
 				break;
b151ef55
 			}
 			/*
 			 * Build up a table of all of the parts of this
 			 * multipart message. Remember, each part may itself
 			 * be a multipart message.
 			 */
 			inhead = 1;
 			inMimeHead = 0;
 
 			for(multiparts = 0; t_line && (multiparts < MAXALTERNATIVE); multiparts++) {
 				aMessage = messages[multiparts] = messageCreate();
 
 				cli_dbgmsg("Now read in part %d\n", multiparts);
 
 				/* tk: shut up parentheses warning */
 				while((t_line = t_line->t_next)) {
 					const char *line = t_line->t_text;
 
 					/*cli_dbgmsg("inMimeHead %d inhead %d boundary %s line %s\n",
 						inMimeHead, inhead, boundary, line);*/
 
 					if(inMimeHead) {
 						while(isspace((int)*line))
 							line++;
 
 						if(*line == '\0') {
 							inhead = inMimeHead = 0;
 							continue;
 						}
 						cli_dbgmsg("About to add mime Argument '%s'\n",
 							line);
 						/*
 						 * This may cause a trailing ';'
 						 * to be added if this test
 						 * fails - TODO: verify this
 						 */
 						inMimeHead = continuationMarker(line);
 						messageAddArgument(aMessage, line);
 					} else if(inhead) {
 						char *copy, *arg;
 
 						if(strlen(line) == 0) {
 							inhead = 0;
 							continue;
 						}
 						/*
 						 * Some clients are broken and
 						 * put white space after the ;
 						 */
 						inMimeHead = continuationMarker(line);
4674dc9a
 						if(!inMimeHead)
 							if(t_line->t_next && ((t_line->t_next->t_text[0] == '\t') || (t_line->t_next->t_text[0] == ' ')))
 								inMimeHead = TRUE;
b151ef55
 						copy = strdup(line);
 						ptr = strtok_r(copy, " \t", &strptr);
 
 						switch(tableFind(rfc821Table, ptr)) {
 						case CONTENT_TYPE:
 							cli_dbgmsg("insert content-type: parse line '%s'\n", line);
 							arg = strtok_r(NULL, "\r\n", &strptr);
 							if((arg == NULL) || (strchr(arg, '/') == NULL)) {
f5e9abc8
 								if(arg == NULL)
bf8ea488
 									cli_warnmsg("Empty content-type received, assuming text/plain; charset=us-ascii\n", arg);
 								else
 									cli_warnmsg("Invalid content-type '%s' received, no subtype specified, assuming text/plain; charset=us-ascii\n", arg);
 								messageSetMimeType(aMessage, "text");
b151ef55
 								messageSetMimeSubtype(aMessage, "plain");
 							} else {
47ab99fa
 								if(*arg == '/') {
 									cli_warnmsg("Content-type '/' received, assuming application/octet-stream\n");
 									messageSetMimeType(aMessage, "application");
 									messageSetMimeSubtype(aMessage, "octet-stream");
 									ptr = strtok_r(arg, ";", &strptr);
 								} else {
 									messageSetMimeType(aMessage, strtok_r(arg, "/", &strptr));
 									messageSetMimeSubtype(aMessage, strtok_r(NULL, ";", &strptr));
 								}
 								if((ptr = strtok_r(NULL, "\r\n", &strptr)) != NULL)
b151ef55
 									messageAddArguments(aMessage, ptr);
 							}
 							break;
 						case CONTENT_TRANSFER_ENCODING:
4674dc9a
 							ptr = strtok_r(NULL, "", &strptr);
 							if(ptr) {
 								messageSetEncoding(aMessage, ptr);
 								break;
 							}
 							/*
 							 * Encoding type not found
 							 */
 							if(!inMimeHead) {
 								cli_warnmsg("Empty encoding type, assuming none");
 								messageSetEncoding(aMessage, "7bit");
 								break;
 							}
 							/*
 							 * Handle the case
 							 * when it flows over
 							 * to the next line.
 							 *
 							 * Content-type:
 							 *	quoted-printable
 							 */
 							if(t_line->t_next) {
 								t_line = t_line->t_next;
 								messageSetEncoding(aMessage, t_line->t_text);
 
 								break;
 							}
 							cli_warnmsg("Empty encoding type, assuming none");
 							messageSetEncoding(aMessage, "7bit");
 
b151ef55
 							break;
 						case CONTENT_DISPOSITION:
 							messageSetDispositionType(aMessage, strtok_r(NULL, ";", &strptr));
 							messageAddArgument(aMessage, strtok_r(NULL, "", &strptr));
 							break;
 						}
 						free(copy);
 					} else if(boundaryStart(line, boundary)) {
 						inhead = 1;
 						break;
 					} else if(endOfMessage(line, boundary)) {
 						/*
 						 * Some viruses put information
 						 * *after* the end of message,
 						 * which presumably some broken
 						 * mail clients find, so we
 						 * can't assume that this
 						 * is the end of the message
 						 */
 						/* t_line = NULL;*/
 						break;
 					} else
 						messageAddLine(aMessage, line);
 				}
 				messageClean(aMessage);
 			}
 
 			free((char *)boundary);
 
 			if(multiparts == 0)
 				return 2;	/* Nothing to do */
 
 			cli_dbgmsg("The message has %d parts\n", multiparts);
 			cli_dbgmsg("Find out the multipart type(%s)\n", mimeSubtype);
 
 			switch(tableFind(subtypeTable, mimeSubtype)) {
 			case RELATED:
 				/*
295e425f
 				 * Have a look to see if there's HTML code
 				 * which will need scanning
b151ef55
 				 */
 				aMessage = NULL;
 				assert(multiparts > 0);
 
0bcad2b1
 				htmltextPart = getTextPart(messages, multiparts);
b151ef55
 
0bcad2b1
 				if(htmltextPart >= 0)
 					aText = textAddMessage(aText, messages[htmltextPart]);
b151ef55
 				else
 					/*
295e425f
 					 * There isn't an HTML bit. If there's a
 					 * multipart bit, it'll may be in there
 					 * somewhere
b151ef55
 					 */
 					for(i = 0; i < multiparts; i++)
 						if(messageGetMimeType(messages[i]) == MULTIPART) {
 							aMessage = messages[i];
0bcad2b1
 							htmltextPart = i;
b151ef55
 							break;
 						}
 
295e425f
 				if(htmltextPart == -1) {
 					cli_dbgmsg("No HTML code found to be scanned");
 					rc = 0;
 				} else
7fca6080
 					rc = parseEmailBody(aMessage, blobs, nBlobs, aText, dir, rfc821Table, subtypeTable);
b151ef55
 				blobArrayDestroy(blobs, nBlobs);
c6259ac5
 				blobs = NULL;
 				nBlobs = 0;
b151ef55
 
 				/*
 				 * Fixed based on an idea from Stephen White <stephen@earth.li>
 				 * The message is confused about the difference
 				 * between alternative and related. Badtrans.B
 				 * suffers from this problem.
 				 *
 				 * Fall through in this case:
 				 * Content-Type: multipart/related;
 				 *	type="multipart/alternative"
 				 */
f5e9abc8
 				/*
 				 * Changed to always fall through based on
 				 * an idea from Michael Dankov <misha@btrc.ru>
 				 * that some viruses are completely confused
 				 * about the difference between related
 				 * and mixed
 				 */
 				/*cptr = messageFindArgument(mainMessage, "type");
b151ef55
 				if(cptr == NULL)
 					break;
 				isAlternative = (bool)(strcasecmp(cptr, "multipart/alternative") == 0);
 				free((char *)cptr);
 				if(!isAlternative)
f5e9abc8
 					break;*/
b151ef55
 			case ALTERNATIVE:
 				cli_dbgmsg("Multipart alternative handler\n");
 
0bcad2b1
 				htmltextPart = getTextPart(messages, multiparts);
b151ef55
 
0bcad2b1
 				if(htmltextPart == -1)
 					htmltextPart = 0;
b151ef55
 
0bcad2b1
 				aMessage = messages[htmltextPart];
b151ef55
 				aText = textAddMessage(aText, aMessage);
 
7fca6080
 				rc = parseEmailBody(NULL, blobs, nBlobs, aText, dir, rfc821Table, subtypeTable);
b151ef55
 				if(rc == 1) {
 					/*
 					 * Alternative message has saved its
 					 * attachments, ensure we don't do
 					 * the same thing
 					 */
d3d2fb1e
 					blobArrayDestroy(blobs, nBlobs);
 					blobs = NULL;
b151ef55
 					nBlobs = 0;
 					rc = 2;
 				}
 				/*
 				 * Fall through - some clients are broken and
 				 * say alternative instead of mixed. The Klez
 				 * virus is broken that way
 				 */
 			case REPORT:
 				/*
 				 * According to section 1 of RFC1892, the
 				 * syntax of multipart/report is the same
 				 * as multipart/mixed. There are some required
 				 * parameters, but there's no need for us to
 				 * verify that they exist
 				 */
 			case MIXED:
fdc8a467
 			case APPLEDOUBLE:	/* not really supported */
b151ef55
 				/*
 				 * Look for attachments
 				 *
 				 * Not all formats are supported. If an
 				 * unsupported format turns out to be
 				 * common enough to implement, it is a simple
 				 * matter to add it
 				 */
 				if(aText)
 					mainMessage = NULL;
 
 #ifdef	CL_DEBUG
 				cli_dbgmsg("Mixed message with %d parts\n", multiparts);
 #endif
 				for(i = 0; i < multiparts; i++) {
 					bool addAttachment = FALSE;
 					bool addToText = FALSE;
 					const char *dtype;
c6259ac5
 					text *t;
b151ef55
 
 					aMessage = messages[i];
 
 					assert(aMessage != NULL);
 
 					dtype = messageGetDispositionType(aMessage);
0bcad2b1
 					cptr = messageGetMimeSubtype(aMessage);
b151ef55
 
 #ifdef	CL_DEBUG
 					cli_dbgmsg("Mixed message part %d is of type %d\n",
 						i, messageGetMimeType(aMessage));
 #endif
 
 					switch(messageGetMimeType(aMessage)) {
 					case APPLICATION:
c6259ac5
 #if	0
 						/* strict checking... */
b151ef55
 						if((strcasecmp(dtype, "attachment") == 0) ||
0bcad2b1
 						   (strcasecmp(cptr, "x-msdownload") == 0) ||
c6259ac5
 						   (strcasecmp(cptr, "octet-stream") == 0) ||
0bcad2b1
 						   (strcasecmp(dtype, "octet-stream") == 0))
b151ef55
 							addAttachment = TRUE;
 						else {
c6259ac5
 							cli_dbgmsg("Discarded mixed/application not sent as attachment\n");
b151ef55
 							continue;
 						}
c6259ac5
 #endif
 						addAttachment = TRUE;
b151ef55
 
 						break;
 					case NOMIME:
 						mainMessage = NULL;
 						addToText = TRUE;
 						if(messageGetBody(aMessage) == NULL)
 							/*
 							 * No plain text version
 							 */
 							messageAddLine(aMessage, "No plain text alternative");
 						assert(messageGetBody(aMessage) != NULL);
 						break;
 					case TEXT:
 						if(strcasecmp(dtype, "attachment") == 0)
 							addAttachment = TRUE;
 						else if((*dtype == '\0') || (strcasecmp(dtype, "inline") == 0)) {
 							mainMessage = NULL;
 							/*
 							 * Strictly speaking
 							 * a text/html part is
 							 * not an attachment. We
 							 * pretend it is so that
 							 * we can decode and
 							 * scan it
 							 */
 							if(strcasecmp(messageGetMimeSubtype(aMessage), "plain") == 0)
 								addToText = TRUE;
 							else {
 								messageAddArgument(aMessage, "filename=textportion");
 								addAttachment = TRUE;
 							}
 						} else {
 							cli_dbgmsg("Text type %s is not supported", dtype);
 							continue;
 						}
 						break;
 					case MESSAGE:
 						cli_dbgmsg("Found message inside multipart\n");
7fca6080
 						rc = parseEmailBody(aMessage, blobs, nBlobs, NULL, dir, rfc821Table, subtypeTable);
b151ef55
 						continue;
 					case MULTIPART:
 						/*
 						 * It's a multi part within a multi part
 						 * Run the message parser on this bit, it won't
 						 * be an attachment
 						 *
 						 */
 						cli_dbgmsg("Found multipart inside multipart\n");
c6259ac5
 						t = messageToText(aMessage);
7fca6080
 						rc = parseEmailBody(aMessage, blobs, nBlobs, t, dir, rfc821Table, subtypeTable);
c6259ac5
 						textDestroy(t);
b151ef55
 
 						mainMessage = aMessage;
 						continue;
 					case AUDIO:
 					case IMAGE:
 						/*
 						 * TODO: it may be nice to
 						 * have an option to throw
 						 * away all images and sound
 						 * files for ultra-secure sites
 						 */
 						addAttachment = TRUE;
 						break;
 					default:
 						cli_dbgmsg("Only text and application attachments are supported, type = %d\n",
 							messageGetMimeType(aMessage));
 						continue;
 					}
 
 					/*
 					 * It must be either text or
 					 * an attachment. It can't be both
 					 */
 					assert(addToText || addAttachment);
 					assert(!(addToText && addAttachment));
 
 					if(addToText)
 						aText = textAdd(aText, messageGetBody(aMessage));
 					else if(addAttachment) {
 						blob *aBlob = messageToBlob(aMessage);
 
 						if(aBlob) {
 							assert(blobGetFilename(aBlob) != NULL);
 							/*if(blobGetDataSize(aBlob) > 0)*/
 								blobList[numberOfAttachments++] = aBlob;
 						}
 					}
 				}
 
 				if(numberOfAttachments == 0) {
 					/* No usable attachment was found */
7fca6080
 					rc = parseEmailBody(NULL, NULL, 0, aText, dir, rfc821Table, subtypeTable);
b151ef55
 					break;
 				}
 				/*
 				 * Store any existing attachments at the end of
 				 * the list we've just built up
 				 */
 				for(i = 0; i < nBlobs; i++) {
0bcad2b1
 #ifdef	CL_DEBUG
b151ef55
 					assert(blobs[i]->magic == BLOB);
0bcad2b1
 #endif
b151ef55
 					blobList[numberOfAttachments++] = blobs[i];
 				}
 
7fca6080
 				rc = parseEmailBody(mainMessage, blobList, numberOfAttachments, aText, dir, rfc821Table, subtypeTable);
b151ef55
 				break;
 			case DIGEST:
 			case SIGNED:
 			case PARALLEL:
 				/*
 				 * If we're here it could be because we have a
 				 * multipart/mixed message, consisting of a
 				 * message followed by an attachment. That
 				 * message itself is a multipart/alternative
 				 * message and we need to dig out the plain
 				 * text part of that alternative
 				 */
0bcad2b1
 				htmltextPart = getTextPart(messages, multiparts);
 				if(htmltextPart == -1)
 					htmltextPart = 0;
b151ef55
 
7fca6080
 				rc = parseEmailBody(messages[htmltextPart], blobs, nBlobs, aText, dir, rfc821Table, subtypeTable);
b151ef55
 				blobArrayDestroy(blobs, nBlobs);
c6259ac5
 				blobs = NULL;
 				nBlobs = 0;
b151ef55
 				break;
 			default:
 				/*
 				 * According to section 7.2.6 of RFC1521,
 				 * unrecognised multiparts should be treated as
 				 * multipart/mixed. I don't do this yet so
 				 * that I can see what comes along...
 				 */
 				cli_warnmsg("Unsupported multipart format `%s'\n", mimeSubtype);
 				rc = 0;
 			}
 
 			for(i = 0; i < multiparts; i++)
 				messageDestroy(messages[i]);
 
 			if(blobs && (blobsIn == NULL))
 				puts("arraydestroy");
 
c6259ac5
 			if(aText && (textIn == NULL))
 				textDestroy(aText);
 
b151ef55
 			return rc;
 
 		case MESSAGE:
 			/*
 			 * Check for forbidden encodings
 			 */
 			switch(messageGetEncoding(mainMessage)) {
 				case NOENCODING:
 				case EIGHTBIT:
 				case BINARY:
 					break;
 				default:
c6259ac5
 					cli_warnmsg("MIME type 'message' cannot be decoded\n");
b151ef55
 					break;
 			}
c6259ac5
 			if((strcasecmp(mimeSubtype, "rfc822") == 0) ||
 			   (strcasecmp(mimeSubtype, "delivery-status") == 0)) {
b151ef55
 				/*
7fca6080
 				 * Found a message encapsulated within
 				 * another message
bf8ea488
 				 *
 				 * Thomas Lamy <Thomas.Lamy@in-online.net>:
 				 * ensure t is correctly freed
b151ef55
 				 */
bf8ea488
 				text *t, *msgText = messageToText(mainMessage);
b151ef55
 				message *m;
0bcad2b1
 
bf8ea488
 				t = msgText;
0bcad2b1
 				assert(t != NULL);
 
b151ef55
 				m = messageCreate();
 				assert(m != NULL);
 
 				cli_dbgmsg("Decode rfc822");
 
 				do {
 					char *buffer = strdup(t->t_text);
 
7fca6080
 					/*cli_chomp(buffer);*/
 					char *ptr = strrchr(buffer, '\n');
 					if(ptr)
 						*ptr = '\0';
 					ptr = strrchr(buffer, '\r');
 					if(ptr)
 						*ptr = '\0';
0bcad2b1
 
7fca6080
 					messageAddLine(m, buffer);
b151ef55
 					free(buffer);
 				} while((t = t->t_next) != NULL);
 
d3d2fb1e
 				textDestroy(msgText);
7fca6080
 
 				parseEmailHeaders(m, rfc821Table);
 
b151ef55
 				messageClean(m);
 				if(messageGetBody(m))
7fca6080
 					rc = parseEmailBody(m, NULL, 0, NULL, dir, rfc821Table, subtypeTable);
b151ef55
 
 				messageDestroy(m);
 
 				break;
bf8ea488
 			} else if(strcasecmp(mimeSubtype, "partial") == 0)
b151ef55
 				/* TODO */
 				cli_warnmsg("Content-type message/partial not yet supported");
bf8ea488
 			else if(strcasecmp(mimeSubtype, "external-body") == 0)
b151ef55
 				/*
 				 * I don't believe that we should be going
 				 * around the Internet looking for referenced
 				 * files...
 				 */
 				cli_warnmsg("Attempt to send Content-type message/external-body trapped");
bf8ea488
 			else
b151ef55
 				cli_warnmsg("Unsupported message format `%s'\n", mimeSubtype);
 
 			return 0;
 
 		case APPLICATION:
0bcad2b1
 			cptr = messageGetMimeSubtype(mainMessage);
 
04421a14
 			/*if((strcasecmp(cptr, "octet-stream") == 0) ||
 			   (strcasecmp(cptr, "x-msdownload") == 0)) {*/
 			{
b151ef55
 				blob *aBlob = messageToBlob(mainMessage);
 
 				if(aBlob) {
 					cli_dbgmsg("Saving main message as attachment %d\n", nBlobs);
 					assert(blobGetFilename(aBlob) != NULL);
 					/*
 					 * It's likely that we won't have built
 					 * a set of attachments
 					 */
 					if(blobs == NULL)
 						blobs = blobList;
c6259ac5
 					for(i = 0; i < nBlobs; i++)
 						if(blobs[i] == NULL)
 							break;
 					blobs[i] = aBlob;
 					if(i == nBlobs) {
 						nBlobs++;
 						assert(nBlobs < MAX_ATTACHMENTS);
 					}
b151ef55
 				}
04421a14
 			} /*else
 				cli_warnmsg("Discarded application not sent as attachment\n");*/
b151ef55
 			break;
 
 		case AUDIO:
 		case VIDEO:
 		case IMAGE:
 			break;
 
 		default:
 			cli_warnmsg("Message received with unknown mime encoding");
 			break;
 		}
 	}
 
 	cli_dbgmsg("%d attachments found\n", nBlobs);
 
0bcad2b1
 	if(nBlobs == 0) {
 		blob *b;
 
b151ef55
 		/*
15c8cace
 		 * No attachments - scan the text portions, often files
 		 * are hidden in HTML code
b151ef55
 		 */
 
0bcad2b1
 #ifdef	CL_DEBUG
 		cli_dbgmsg("%d multiparts found\n", multiparts);
 #endif
15c8cace
 		for(i = 0; i < multiparts; i++) {
 			b = messageToBlob(messages[i]);
b151ef55
 
0bcad2b1
 			assert(b != NULL);
 
 #ifdef	CL_DEBUG
15c8cace
 			cli_dbgmsg("Saving multipart %d, encoded with scheme %d\n",
 				i, messageGetEncoding(messages[i]));
0bcad2b1
 #endif
 
 			(void)saveFile(b, dir);
b151ef55
 
 			blobDestroy(b);
 		}
0bcad2b1
 
 		if(mainMessage) {
 			/*
 			 * Look for uu-encoded main file
 			 */
7cef72ea
 			const text *t_line = uuencodeBegin(mainMessage);
0bcad2b1
 
 			if(t_line != NULL) {
2227f20e
 				cli_dbgmsg("Found uuencoded file\n");
 
15c8cace
 				/*
 				 * Main part contains uuencoded section
 				 */
0bcad2b1
 				messageSetEncoding(mainMessage,	"x-uuencode");
 
 				if((b = messageToBlob(mainMessage)) != NULL) {
 					if((cptr = blobGetFilename(b)) != NULL) {
 						cli_dbgmsg("Found uuencoded message %s\n", cptr);
 
 						(void)saveFile(b, dir);
 					}
 					blobDestroy(b);
 				}
15c8cace
 			} else {
2227f20e
 				cli_dbgmsg("Not found uuencoded file\n");
 
15c8cace
 				messageAddArgument(mainMessage, "filename=textportion");
 				if((b = messageToBlob(mainMessage)) != NULL) {
 					/*
 					 * Save main part to scan that
 					 */
 					cli_dbgmsg("Saving main message, encoded with scheme %d\n",
 						messageGetEncoding(mainMessage));
 
 					(void)saveFile(b, dir);
 
 					blobDestroy(b);
 				}
0bcad2b1
 			}
 		}
b151ef55
 	} else {
 		short attachmentNumber;
 
 		for(attachmentNumber = 0; attachmentNumber < nBlobs; attachmentNumber++) {
 			blob *b = blobs[attachmentNumber];
 
c6259ac5
 			if(b) {
 				if(!saveFile(b, dir))
 					break;
 				blobDestroy(b);
 				blobs[attachmentNumber] = NULL;
 			}
b151ef55
 		}
 	}
 
 	if(aText && (textIn == NULL))
 		textDestroy(aText);
 
 	/* Already done */
c6259ac5
 	if(blobs && (blobsIn == NULL))
 		blobArrayDestroy(blobs, nBlobs);
b151ef55
 
7fca6080
 	cli_dbgmsg("parseEmailBody() returning 1\n");
b151ef55
 
 	return 1;
 }
 
 /*
  * Is the current line the start of a new section?
  *
  * New sections start with --boundary
  */
 static int
 boundaryStart(const char *line, const char *boundary)
 {
 	/*
 	 * Gibe.B3 is broken it has:
 	 *	boundary="---- =_NextPart_000_01C31177.9DC7C000"
 	 * but it's boundaries look like
 	 *	------ =_NextPart_000_01C31177.9DC7C000
 	 * notice the extra '-'
 	 */
 	if(strstr(line, boundary) != NULL) {
 		cli_dbgmsg("found %s in %s\n", boundary, line);
 		return 1;
 	}
 	if(*line++ != '-')
 		return 0;
 	if(*line++ != '-')
 		return 0;
 	return strcasecmp(line, boundary) == 0;
 }
 
 /*
  * Is the current line the end?
  *
  * The message ends with with --boundary--
  */
 static int
 endOfMessage(const char *line, const char *boundary)
 {
 	size_t len;
 
 	if(*line++ != '-')
 		return 0;
 	if(*line++ != '-')
 		return 0;
 	len = strlen(boundary);
c6259ac5
 	if(strncasecmp(line, boundary, len) != 0)
 		return 0;
b151ef55
 	if(strlen(line) != (len + 2))
 		return 0;
 	line = &line[len];
 	if(*line++ != '-')
 		return 0;
 	return *line == '-';
 }
 
 /*
  * Initialise the various lookup tables
  */
 static int
 initialiseTables(table_t **rfc821Table, table_t **subtypeTable)
 {
 	const struct tableinit *tableinit;
 
 	/*
 	 * Initialise the various look up tables
 	 */
 	*rfc821Table = tableCreate();
 	assert(*rfc821Table != NULL);
 
 	for(tableinit = rfc821headers; tableinit->key; tableinit++)
 		if(tableInsert(*rfc821Table, tableinit->key, tableinit->value) < 0)
 			return -1;
 
 	*subtypeTable = tableCreate();
 	assert(*subtypeTable != NULL);
 
 	for(tableinit = mimeSubtypes; tableinit->key; tableinit++)
 		if(tableInsert(*subtypeTable, tableinit->key, tableinit->value) < 0) {
 			tableDestroy(*rfc821Table);
 			return -1;
 		}
 
 	return 0;
 }
 
 /*
0bcad2b1
  * If there's a HTML text version use that, otherwise
b151ef55
  * use the first text part, otherwise just use the
0bcad2b1
  * first one around. HTML text is most likely to include
  * a scripting worm
b151ef55
  *
  * If we can't find one, return -1
  */
 static int
 getTextPart(message *const messages[], size_t size)
 {
 	size_t i;
 
 	for(i = 0; i < size; i++) {
 		assert(messages[i] != NULL);
 		if((messageGetMimeType(messages[i]) == TEXT) &&
0bcad2b1
 		   (strcasecmp(messageGetMimeSubtype(messages[i]), "html") == 0))
b151ef55
 			return (int)i;
 	}
 	for(i = 0; i < size; i++)
 		if(messageGetMimeType(messages[i]) == TEXT)
 			return (int)i;
 
 	return -1;
 }
 
 /*
  * strip -
  *	Remove the trailing spaces from a buffer
  * Returns it's new length (a la strlen)
  *
  * len must be int not size_t because of the >= 0 test, it is sizeof(buf)
  *	not strlen(buf)
  */
 static size_t
 strip(char *buf, int len)
 {
 	register char *ptr;
 	register size_t i;
 
 	if((buf == NULL) || (len <= 0))
 		return(0);
 
 	i = strlen(buf);
 	if(len > (int)(i + 1))
 		return(i);
 
 	ptr = &buf[--len];
 
 #if	defined(UNIX) || defined(C_LINUX) || defined(C_DARWIN)	/* watch - it may be in shared text area */
 	do
 		if(*ptr)
 			*ptr = '\0';
 	while((--len >= 0) && !isgraph(*--ptr) && (*ptr != '\n') && (*ptr != '\r'));
 #else	/* more characters can be displayed on DOS */
 	do
 #ifndef	REAL_MODE_DOS
 		if(*ptr)	/* C8.0 puts into a text area */
 #endif
 			*ptr = '\0';
 	while((--len >= 0) && ((*--ptr == '\0') || (isspace((int)*ptr))));
 #endif
 	return((size_t)(len + 1));
 }
 
 /*
  * strstrip:
  *	Strip a given string
  */
 static size_t
 strstrip(char *s)
 {
 	if(s == (char *)NULL)
 		return(0);
 	return(strip(s, strlen(s) + 1));
 }
 
 /*
  * When parsing a MIME header see if this spans more than one line. A
  * semi-colon at the end of the line indicates that the MIME information
  * is continued on the next line.
  *
  * Some clients are broken and put white space after the ;
  */
 static bool
 continuationMarker(const char *line)
 {
 	const char *ptr;
 
 	assert(line != NULL);
 
 #ifdef	CL_DEBUG
 	cli_dbgmsg("continuationMarker(%s)\n", line);
 #endif
 
 	if(strlen(line) == 0)
 		return FALSE;
 
 	ptr = strchr(line, '\0');
 
 	assert(ptr != NULL);
 
752c34b9
 	while(ptr > line)
b151ef55
 		switch(*--ptr) {
 			case '\n':
 			case '\r':
 			case ' ':
 			case '\t':
 				continue;
 			case ';':
 				return TRUE;
 			default:
 				return FALSE;
 		}
 
 	return FALSE;
 }
 
 static int
 parseMimeHeader(message *m, const char *cmd, const table_t *rfc821Table, const char *arg)
 {
 	int type = tableFind(rfc821Table, cmd);
 #ifdef CL_THREAD_SAFE
 	char *strptr;
 #endif
 	char *copy = strdup(arg);
c6259ac5
 	char *ptr = copy;
b151ef55
 
 	cli_dbgmsg("parseMimeHeader: cmd='%s', arg='%s'\n", cmd, arg);
181c7548
 	strstrip(copy);
b151ef55
 
 	switch(type) {
 		case CONTENT_TYPE:
 			/*
 			 * Fix for non RFC1521 compliant mailers
 			 * that send content-type: Text instead
 			 * of content-type: Text/Plain, or
 			 * just simply "Content-Type:"
 			 */
a8c7e017
 			if(arg == NULL)
b151ef55
 				  cli_warnmsg("Empty content-type received, no subtype specified, assuming text/plain; charset=us-ascii\n");
 			else if(strchr(copy, '/') == NULL)
 				  cli_warnmsg("Invalid content-type '%s' received, no subtype specified, assuming text/plain; charset=us-ascii\n", copy);
 			else {
 				char *s;
 				/*
 				 * Some clients are broken and
 				 * put white space after the ;
 				 */
 				strstrip(copy);
 				messageSetMimeType(m, strtok_r(copy, "/", &strptr));
 
 				/*
 				 * Stephen White <stephen@earth.li>
 				 * Some clients put space after
 				 * the mime type but before
 				 * the ;
 				 */
 				s = strtok_r(NULL, ";", &strptr);
 				strstrip(s);
 				messageSetMimeSubtype(m, s);
 
 				/*
 				 * Add in all the arguments.
 				 */
 				while((copy = strtok_r(NULL, "\r\n \t", &strptr)))
 					messageAddArgument(m, copy);
 			}
 			break;
 		case CONTENT_TRANSFER_ENCODING:
 			messageSetEncoding(m, copy);
 			break;
 		case CONTENT_DISPOSITION:
 			messageSetDispositionType(m, strtok_r(copy, ";", &strptr));
 			messageAddArgument(m, strtok_r(NULL, "\r\n", &strptr));
 	}
c6259ac5
 	free(ptr);
b151ef55
 
 	return type;
 }
 
0bcad2b1
 static bool
b151ef55
 saveFile(const blob *b, const char *dir)
 {
 	unsigned long nbytes = blobGetDataSize(b);
181c7548
 	size_t len = 0;
b151ef55
 	int fd;
0bcad2b1
 	const char *cptr, *suffix;
701a425d
 	char filename[NAME_MAX + 1];
b151ef55
 
 	assert(dir != NULL);
 
 	if(nbytes == 0)
0bcad2b1
 		return TRUE;
b151ef55
 
 	cptr = blobGetFilename(b);
 
 	if(cptr == NULL) {
 		cptr = "unknown";
 		suffix = "";
 	} else {
 		/*
 		 * Some programs are broken and use an idea of a ".suffix"
 		 * to determine the file type rather than looking up the
 		 * magic number. CPM has a lot to answer for...
 		 * FIXME: the suffix now appears twice in the filename...
 		 */
 		suffix = strrchr(cptr, '.');
 		if(suffix == NULL)
 			suffix = "";
181c7548
 		else
 			len = strlen(suffix);
b151ef55
 	}
 	cli_dbgmsg("Saving attachment in %s/%s\n", dir, cptr);
 
0bcad2b1
 	/*
 	 * Allow for very long filenames. We have to truncate them to fit
 	 */
181c7548
 	snprintf(filename, sizeof(filename) - 1 - len, "%s/%.*sXXXXXX", dir,
f5e9abc8
 		(int)(sizeof(filename) - 9 - len - strlen(dir)), cptr);
b151ef55
 
 	/*
181c7548
 	 * TODO: add a HAVE_MKSTEMP property
b151ef55
 	 */
 #if	defined(C_LINUX) || defined(C_BSD) || defined(HAVE_MKSTEMP)
 	fd = mkstemp(filename);
 #else
 	(void)mktemp(filename);
c6259ac5
 	fd = open(filename, O_WRONLY|O_CREAT|O_EXCL|O_TRUNC, 0600);
b151ef55
 #endif
 
 	if(fd < 0) {
181c7548
 		cli_errmsg("Can't create temporary file %s: %s\n", filename, strerror(errno));
0bcad2b1
 		return FALSE;
b151ef55
 	}
 
 	/*
c6259ac5
 	 * Add the suffix back to the end of the filename. Tut-tut, filenames
 	 * should be independant of their usage on UNIX type systems.
b151ef55
 	 */
181c7548
 	if(len > 1) {
6ecba059
 		char stub[NAME_MAX + 1];
c6259ac5
 
181c7548
 		snprintf(stub, sizeof(stub), "%s%s", filename, suffix);
a8c7e017
 #ifdef	C_LINUX
 		rename(stub, filename);
 #else
b151ef55
 		link(stub, filename);
 		unlink(stub);
a8c7e017
 #endif
b151ef55
 	}
 
 	write(fd, blobGetData(b), (size_t)nbytes);
c6259ac5
 	cli_dbgmsg("Attachment saved as %s (%lu bytes long)\n",
b151ef55
 		filename, nbytes);
 
c6259ac5
 	return (close(fd) >= 0);
b151ef55
 }