Merge branch 'jk/send-email-ssl-errors' into maint
[git] / git-send-email.perl
1 #!/usr/bin/perl
2 #
3 # Copyright 2002,2005 Greg Kroah-Hartman <greg@kroah.com>
4 # Copyright 2005 Ryan Anderson <ryan@michonline.com>
5 #
6 # GPL v2 (See COPYING)
7 #
8 # Ported to support git "mbox" format files by Ryan Anderson <ryan@michonline.com>
9 #
10 # Sends a collection of emails to the given email addresses, disturbingly fast.
11 #
12 # Supports two formats:
13 # 1. mbox format files (ignoring most headers and MIME formatting - this is designed for sending patches)
14 # 2. The original format support by Greg's script:
15 #    first line of the message is who to CC,
16 #    and second line is the subject of the message.
17 #
18
19 use 5.008;
20 use strict;
21 use warnings;
22 use Term::ReadLine;
23 use Getopt::Long;
24 use Text::ParseWords;
25 use Data::Dumper;
26 use Term::ANSIColor;
27 use File::Temp qw/ tempdir tempfile /;
28 use File::Spec::Functions qw(catfile);
29 use Error qw(:try);
30 use Git;
31
32 Getopt::Long::Configure qw/ pass_through /;
33
34 package FakeTerm;
35 sub new {
36         my ($class, $reason) = @_;
37         return bless \$reason, shift;
38 }
39 sub readline {
40         my $self = shift;
41         die "Cannot use readline on FakeTerm: $$self";
42 }
43 package main;
44
45
46 sub usage {
47         print <<EOT;
48 git send-email [options] <file | directory | rev-list options >
49
50   Composing:
51     --from                  <str>  * Email From:
52     --[no-]to               <str>  * Email To:
53     --[no-]cc               <str>  * Email Cc:
54     --[no-]bcc              <str>  * Email Bcc:
55     --subject               <str>  * Email "Subject:"
56     --in-reply-to           <str>  * Email "In-Reply-To:"
57     --[no-]xmailer                 * Add "X-Mailer:" header (default).
58     --[no-]annotate                * Review each patch that will be sent in an editor.
59     --compose                      * Open an editor for introduction.
60     --compose-encoding      <str>  * Encoding to assume for introduction.
61     --8bit-encoding         <str>  * Encoding to assume 8bit mails if undeclared
62     --transfer-encoding     <str>  * Transfer encoding to use (quoted-printable, 8bit, base64)
63
64   Sending:
65     --envelope-sender       <str>  * Email envelope sender.
66     --smtp-server       <str:int>  * Outgoing SMTP server to use. The port
67                                      is optional. Default 'localhost'.
68     --smtp-server-option    <str>  * Outgoing SMTP server option to use.
69     --smtp-server-port      <int>  * Outgoing SMTP server port.
70     --smtp-user             <str>  * Username for SMTP-AUTH.
71     --smtp-pass             <str>  * Password for SMTP-AUTH; not necessary.
72     --smtp-encryption       <str>  * tls or ssl; anything else disables.
73     --smtp-ssl                     * Deprecated. Use '--smtp-encryption ssl'.
74     --smtp-ssl-cert-path    <str>  * Path to ca-certificates (either directory or file).
75                                      Pass an empty string to disable certificate
76                                      verification.
77     --smtp-domain           <str>  * The domain name sent to HELO/EHLO handshake
78     --smtp-auth             <str>  * Space-separated list of allowed AUTH mechanisms.
79                                      This setting forces to use one of the listed mechanisms.
80     --smtp-debug            <0|1>  * Disable, enable Net::SMTP debug.
81
82   Automating:
83     --identity              <str>  * Use the sendemail.<id> options.
84     --to-cmd                <str>  * Email To: via `<str> \$patch_path`
85     --cc-cmd                <str>  * Email Cc: via `<str> \$patch_path`
86     --suppress-cc           <str>  * author, self, sob, cc, cccmd, body, bodycc, all.
87     --[no-]cc-cover                * Email Cc: addresses in the cover letter.
88     --[no-]to-cover                * Email To: addresses in the cover letter.
89     --[no-]signed-off-by-cc        * Send to Signed-off-by: addresses. Default on.
90     --[no-]suppress-from           * Send to self. Default off.
91     --[no-]chain-reply-to          * Chain In-Reply-To: fields. Default off.
92     --[no-]thread                  * Use In-Reply-To: field. Default on.
93
94   Administering:
95     --confirm               <str>  * Confirm recipients before sending;
96                                      auto, cc, compose, always, or never.
97     --quiet                        * Output one line of info per email.
98     --dry-run                      * Don't actually send the emails.
99     --[no-]validate                * Perform patch sanity checks. Default on.
100     --[no-]format-patch            * understand any non optional arguments as
101                                      `git format-patch` ones.
102     --force                        * Send even if safety checks would prevent it.
103
104 EOT
105         exit(1);
106 }
107
108 # most mail servers generate the Date: header, but not all...
109 sub format_2822_time {
110         my ($time) = @_;
111         my @localtm = localtime($time);
112         my @gmttm = gmtime($time);
113         my $localmin = $localtm[1] + $localtm[2] * 60;
114         my $gmtmin = $gmttm[1] + $gmttm[2] * 60;
115         if ($localtm[0] != $gmttm[0]) {
116                 die "local zone differs from GMT by a non-minute interval\n";
117         }
118         if ((($gmttm[6] + 1) % 7) == $localtm[6]) {
119                 $localmin += 1440;
120         } elsif ((($gmttm[6] - 1) % 7) == $localtm[6]) {
121                 $localmin -= 1440;
122         } elsif ($gmttm[6] != $localtm[6]) {
123                 die "local time offset greater than or equal to 24 hours\n";
124         }
125         my $offset = $localmin - $gmtmin;
126         my $offhour = $offset / 60;
127         my $offmin = abs($offset % 60);
128         if (abs($offhour) >= 24) {
129                 die ("local time offset greater than or equal to 24 hours\n");
130         }
131
132         return sprintf("%s, %2d %s %d %02d:%02d:%02d %s%02d%02d",
133                        qw(Sun Mon Tue Wed Thu Fri Sat)[$localtm[6]],
134                        $localtm[3],
135                        qw(Jan Feb Mar Apr May Jun
136                           Jul Aug Sep Oct Nov Dec)[$localtm[4]],
137                        $localtm[5]+1900,
138                        $localtm[2],
139                        $localtm[1],
140                        $localtm[0],
141                        ($offset >= 0) ? '+' : '-',
142                        abs($offhour),
143                        $offmin,
144                        );
145 }
146
147 my $have_email_valid = eval { require Email::Valid; 1 };
148 my $have_mail_address = eval { require Mail::Address; 1 };
149 my $smtp;
150 my $auth;
151
152 # Regexes for RFC 2047 productions.
153 my $re_token = qr/[^][()<>@,;:\\"\/?.= \000-\037\177-\377]+/;
154 my $re_encoded_text = qr/[^? \000-\037\177-\377]+/;
155 my $re_encoded_word = qr/=\?($re_token)\?($re_token)\?($re_encoded_text)\?=/;
156
157 # Variables we fill in automatically, or via prompting:
158 my (@to,$no_to,@initial_to,@cc,$no_cc,@initial_cc,@bcclist,$no_bcc,@xh,
159         $initial_reply_to,$initial_subject,@files,
160         $author,$sender,$smtp_authpass,$annotate,$use_xmailer,$compose,$time);
161
162 my $envelope_sender;
163
164 # Example reply to:
165 #$initial_reply_to = ''; #<20050203173208.GA23964@foobar.com>';
166
167 my $repo = eval { Git->repository() };
168 my @repo = $repo ? ($repo) : ();
169 my $term = eval {
170         $ENV{"GIT_SEND_EMAIL_NOTTY"}
171                 ? new Term::ReadLine 'git-send-email', \*STDIN, \*STDOUT
172                 : new Term::ReadLine 'git-send-email';
173 };
174 if ($@) {
175         $term = new FakeTerm "$@: going non-interactive";
176 }
177
178 # Behavior modification variables
179 my ($quiet, $dry_run) = (0, 0);
180 my $format_patch;
181 my $compose_filename;
182 my $force = 0;
183
184 # Handle interactive edition of files.
185 my $multiedit;
186 my $editor;
187
188 sub do_edit {
189         if (!defined($editor)) {
190                 $editor = Git::command_oneline('var', 'GIT_EDITOR');
191         }
192         if (defined($multiedit) && !$multiedit) {
193                 map {
194                         system('sh', '-c', $editor.' "$@"', $editor, $_);
195                         if (($? & 127) || ($? >> 8)) {
196                                 die("the editor exited uncleanly, aborting everything");
197                         }
198                 } @_;
199         } else {
200                 system('sh', '-c', $editor.' "$@"', $editor, @_);
201                 if (($? & 127) || ($? >> 8)) {
202                         die("the editor exited uncleanly, aborting everything");
203                 }
204         }
205 }
206
207 # Variables with corresponding config settings
208 my ($thread, $chain_reply_to, $suppress_from, $signed_off_by_cc);
209 my ($cover_cc, $cover_to);
210 my ($to_cmd, $cc_cmd);
211 my ($smtp_server, $smtp_server_port, @smtp_server_options);
212 my ($smtp_authuser, $smtp_encryption, $smtp_ssl_cert_path);
213 my ($identity, $aliasfiletype, @alias_files, $smtp_domain, $smtp_auth);
214 my ($validate, $confirm);
215 my (@suppress_cc);
216 my ($auto_8bit_encoding);
217 my ($compose_encoding);
218 my ($target_xfer_encoding);
219
220 my ($debug_net_smtp) = 0;               # Net::SMTP, see send_message()
221
222 my %config_bool_settings = (
223     "thread" => [\$thread, 1],
224     "chainreplyto" => [\$chain_reply_to, 0],
225     "suppressfrom" => [\$suppress_from, undef],
226     "signedoffbycc" => [\$signed_off_by_cc, undef],
227     "cccover" => [\$cover_cc, undef],
228     "tocover" => [\$cover_to, undef],
229     "signedoffcc" => [\$signed_off_by_cc, undef],      # Deprecated
230     "validate" => [\$validate, 1],
231     "multiedit" => [\$multiedit, undef],
232     "annotate" => [\$annotate, undef],
233     "xmailer" => [\$use_xmailer, 1]
234 );
235
236 my %config_settings = (
237     "smtpserver" => \$smtp_server,
238     "smtpserverport" => \$smtp_server_port,
239     "smtpserveroption" => \@smtp_server_options,
240     "smtpuser" => \$smtp_authuser,
241     "smtppass" => \$smtp_authpass,
242     "smtpsslcertpath" => \$smtp_ssl_cert_path,
243     "smtpdomain" => \$smtp_domain,
244     "smtpauth" => \$smtp_auth,
245     "to" => \@initial_to,
246     "tocmd" => \$to_cmd,
247     "cc" => \@initial_cc,
248     "cccmd" => \$cc_cmd,
249     "aliasfiletype" => \$aliasfiletype,
250     "bcc" => \@bcclist,
251     "suppresscc" => \@suppress_cc,
252     "envelopesender" => \$envelope_sender,
253     "confirm"   => \$confirm,
254     "from" => \$sender,
255     "assume8bitencoding" => \$auto_8bit_encoding,
256     "composeencoding" => \$compose_encoding,
257     "transferencoding" => \$target_xfer_encoding,
258 );
259
260 my %config_path_settings = (
261     "aliasesfile" => \@alias_files,
262 );
263
264 # Handle Uncouth Termination
265 sub signal_handler {
266
267         # Make text normal
268         print color("reset"), "\n";
269
270         # SMTP password masked
271         system "stty echo";
272
273         # tmp files from --compose
274         if (defined $compose_filename) {
275                 if (-e $compose_filename) {
276                         print "'$compose_filename' contains an intermediate version of the email you were composing.\n";
277                 }
278                 if (-e ($compose_filename . ".final")) {
279                         print "'$compose_filename.final' contains the composed email.\n"
280                 }
281         }
282
283         exit;
284 };
285
286 $SIG{TERM} = \&signal_handler;
287 $SIG{INT}  = \&signal_handler;
288
289 # Begin by accumulating all the variables (defined above), that we will end up
290 # needing, first, from the command line:
291
292 my $help;
293 my $rc = GetOptions("h" => \$help,
294                     "sender|from=s" => \$sender,
295                     "in-reply-to=s" => \$initial_reply_to,
296                     "subject=s" => \$initial_subject,
297                     "to=s" => \@initial_to,
298                     "to-cmd=s" => \$to_cmd,
299                     "no-to" => \$no_to,
300                     "cc=s" => \@initial_cc,
301                     "no-cc" => \$no_cc,
302                     "bcc=s" => \@bcclist,
303                     "no-bcc" => \$no_bcc,
304                     "chain-reply-to!" => \$chain_reply_to,
305                     "no-chain-reply-to" => sub {$chain_reply_to = 0},
306                     "smtp-server=s" => \$smtp_server,
307                     "smtp-server-option=s" => \@smtp_server_options,
308                     "smtp-server-port=s" => \$smtp_server_port,
309                     "smtp-user=s" => \$smtp_authuser,
310                     "smtp-pass:s" => \$smtp_authpass,
311                     "smtp-ssl" => sub { $smtp_encryption = 'ssl' },
312                     "smtp-encryption=s" => \$smtp_encryption,
313                     "smtp-ssl-cert-path=s" => \$smtp_ssl_cert_path,
314                     "smtp-debug:i" => \$debug_net_smtp,
315                     "smtp-domain:s" => \$smtp_domain,
316                     "smtp-auth=s" => \$smtp_auth,
317                     "identity=s" => \$identity,
318                     "annotate!" => \$annotate,
319                     "no-annotate" => sub {$annotate = 0},
320                     "compose" => \$compose,
321                     "quiet" => \$quiet,
322                     "cc-cmd=s" => \$cc_cmd,
323                     "suppress-from!" => \$suppress_from,
324                     "no-suppress-from" => sub {$suppress_from = 0},
325                     "suppress-cc=s" => \@suppress_cc,
326                     "signed-off-cc|signed-off-by-cc!" => \$signed_off_by_cc,
327                     "no-signed-off-cc|no-signed-off-by-cc" => sub {$signed_off_by_cc = 0},
328                     "cc-cover|cc-cover!" => \$cover_cc,
329                     "no-cc-cover" => sub {$cover_cc = 0},
330                     "to-cover|to-cover!" => \$cover_to,
331                     "no-to-cover" => sub {$cover_to = 0},
332                     "confirm=s" => \$confirm,
333                     "dry-run" => \$dry_run,
334                     "envelope-sender=s" => \$envelope_sender,
335                     "thread!" => \$thread,
336                     "no-thread" => sub {$thread = 0},
337                     "validate!" => \$validate,
338                     "no-validate" => sub {$validate = 0},
339                     "transfer-encoding=s" => \$target_xfer_encoding,
340                     "format-patch!" => \$format_patch,
341                     "no-format-patch" => sub {$format_patch = 0},
342                     "8bit-encoding=s" => \$auto_8bit_encoding,
343                     "compose-encoding=s" => \$compose_encoding,
344                     "force" => \$force,
345                     "xmailer!" => \$use_xmailer,
346                     "no-xmailer" => sub {$use_xmailer = 0},
347          );
348
349 usage() if $help;
350 unless ($rc) {
351     usage();
352 }
353
354 die "Cannot run git format-patch from outside a repository\n"
355         if $format_patch and not $repo;
356
357 # Now, let's fill any that aren't set in with defaults:
358
359 sub read_config {
360         my ($prefix) = @_;
361
362         foreach my $setting (keys %config_bool_settings) {
363                 my $target = $config_bool_settings{$setting}->[0];
364                 $$target = Git::config_bool(@repo, "$prefix.$setting") unless (defined $$target);
365         }
366
367         foreach my $setting (keys %config_path_settings) {
368                 my $target = $config_path_settings{$setting};
369                 if (ref($target) eq "ARRAY") {
370                         unless (@$target) {
371                                 my @values = Git::config_path(@repo, "$prefix.$setting");
372                                 @$target = @values if (@values && defined $values[0]);
373                         }
374                 }
375                 else {
376                         $$target = Git::config_path(@repo, "$prefix.$setting") unless (defined $$target);
377                 }
378         }
379
380         foreach my $setting (keys %config_settings) {
381                 my $target = $config_settings{$setting};
382                 next if $setting eq "to" and defined $no_to;
383                 next if $setting eq "cc" and defined $no_cc;
384                 next if $setting eq "bcc" and defined $no_bcc;
385                 if (ref($target) eq "ARRAY") {
386                         unless (@$target) {
387                                 my @values = Git::config(@repo, "$prefix.$setting");
388                                 @$target = @values if (@values && defined $values[0]);
389                         }
390                 }
391                 else {
392                         $$target = Git::config(@repo, "$prefix.$setting") unless (defined $$target);
393                 }
394         }
395
396         if (!defined $smtp_encryption) {
397                 my $enc = Git::config(@repo, "$prefix.smtpencryption");
398                 if (defined $enc) {
399                         $smtp_encryption = $enc;
400                 } elsif (Git::config_bool(@repo, "$prefix.smtpssl")) {
401                         $smtp_encryption = 'ssl';
402                 }
403         }
404 }
405
406 # read configuration from [sendemail "$identity"], fall back on [sendemail]
407 $identity = Git::config(@repo, "sendemail.identity") unless (defined $identity);
408 read_config("sendemail.$identity") if (defined $identity);
409 read_config("sendemail");
410
411 # fall back on builtin bool defaults
412 foreach my $setting (values %config_bool_settings) {
413         ${$setting->[0]} = $setting->[1] unless (defined (${$setting->[0]}));
414 }
415
416 # 'default' encryption is none -- this only prevents a warning
417 $smtp_encryption = '' unless (defined $smtp_encryption);
418
419 # Set CC suppressions
420 my(%suppress_cc);
421 if (@suppress_cc) {
422         foreach my $entry (@suppress_cc) {
423                 die "Unknown --suppress-cc field: '$entry'\n"
424                         unless $entry =~ /^(?:all|cccmd|cc|author|self|sob|body|bodycc)$/;
425                 $suppress_cc{$entry} = 1;
426         }
427 }
428
429 if ($suppress_cc{'all'}) {
430         foreach my $entry (qw (cccmd cc author self sob body bodycc)) {
431                 $suppress_cc{$entry} = 1;
432         }
433         delete $suppress_cc{'all'};
434 }
435
436 # If explicit old-style ones are specified, they trump --suppress-cc.
437 $suppress_cc{'self'} = $suppress_from if defined $suppress_from;
438 $suppress_cc{'sob'} = !$signed_off_by_cc if defined $signed_off_by_cc;
439
440 if ($suppress_cc{'body'}) {
441         foreach my $entry (qw (sob bodycc)) {
442                 $suppress_cc{$entry} = 1;
443         }
444         delete $suppress_cc{'body'};
445 }
446
447 # Set confirm's default value
448 my $confirm_unconfigured = !defined $confirm;
449 if ($confirm_unconfigured) {
450         $confirm = scalar %suppress_cc ? 'compose' : 'auto';
451 };
452 die "Unknown --confirm setting: '$confirm'\n"
453         unless $confirm =~ /^(?:auto|cc|compose|always|never)/;
454
455 # Debugging, print out the suppressions.
456 if (0) {
457         print "suppressions:\n";
458         foreach my $entry (keys %suppress_cc) {
459                 printf "  %-5s -> $suppress_cc{$entry}\n", $entry;
460         }
461 }
462
463 my ($repoauthor, $repocommitter);
464 ($repoauthor) = Git::ident_person(@repo, 'author');
465 ($repocommitter) = Git::ident_person(@repo, 'committer');
466
467 sub parse_address_line {
468         if ($have_mail_address) {
469                 return map { $_->format } Mail::Address->parse($_[0]);
470         } else {
471                 return Git::parse_mailboxes($_[0]);
472         }
473 }
474
475 sub split_addrs {
476         return quotewords('\s*,\s*', 1, @_);
477 }
478
479 my %aliases;
480
481 sub parse_sendmail_alias {
482         local $_ = shift;
483         if (/"/) {
484                 print STDERR "warning: sendmail alias with quotes is not supported: $_\n";
485         } elsif (/:include:/) {
486                 print STDERR "warning: `:include:` not supported: $_\n";
487         } elsif (/[\/|]/) {
488                 print STDERR "warning: `/file` or `|pipe` redirection not supported: $_\n";
489         } elsif (/^(\S+?)\s*:\s*(.+)$/) {
490                 my ($alias, $addr) = ($1, $2);
491                 $aliases{$alias} = [ split_addrs($addr) ];
492         } else {
493                 print STDERR "warning: sendmail line is not recognized: $_\n";
494         }
495 }
496
497 sub parse_sendmail_aliases {
498         my $fh = shift;
499         my $s = '';
500         while (<$fh>) {
501                 chomp;
502                 next if /^\s*$/ || /^\s*#/;
503                 $s .= $_, next if $s =~ s/\\$// || s/^\s+//;
504                 parse_sendmail_alias($s) if $s;
505                 $s = $_;
506         }
507         $s =~ s/\\$//; # silently tolerate stray '\' on last line
508         parse_sendmail_alias($s) if $s;
509 }
510
511 my %parse_alias = (
512         # multiline formats can be supported in the future
513         mutt => sub { my $fh = shift; while (<$fh>) {
514                 if (/^\s*alias\s+(?:-group\s+\S+\s+)*(\S+)\s+(.*)$/) {
515                         my ($alias, $addr) = ($1, $2);
516                         $addr =~ s/#.*$//; # mutt allows # comments
517                          # commas delimit multiple addresses
518                         $aliases{$alias} = [ split_addrs($addr) ];
519                 }}},
520         mailrc => sub { my $fh = shift; while (<$fh>) {
521                 if (/^alias\s+(\S+)\s+(.*)$/) {
522                         # spaces delimit multiple addresses
523                         $aliases{$1} = [ quotewords('\s+', 0, $2) ];
524                 }}},
525         pine => sub { my $fh = shift; my $f='\t[^\t]*';
526                 for (my $x = ''; defined($x); $x = $_) {
527                         chomp $x;
528                         $x .= $1 while(defined($_ = <$fh>) && /^ +(.*)$/);
529                         $x =~ /^(\S+)$f\t\(?([^\t]+?)\)?(:?$f){0,2}$/ or next;
530                         $aliases{$1} = [ split_addrs($2) ];
531                 }},
532         elm => sub  { my $fh = shift;
533                       while (<$fh>) {
534                           if (/^(\S+)\s+=\s+[^=]+=\s(\S+)/) {
535                               my ($alias, $addr) = ($1, $2);
536                                $aliases{$alias} = [ split_addrs($addr) ];
537                           }
538                       } },
539         sendmail => \&parse_sendmail_aliases,
540         gnus => sub { my $fh = shift; while (<$fh>) {
541                 if (/\(define-mail-alias\s+"(\S+?)"\s+"(\S+?)"\)/) {
542                         $aliases{$1} = [ $2 ];
543                 }}}
544 );
545
546 if (@alias_files and $aliasfiletype and defined $parse_alias{$aliasfiletype}) {
547         foreach my $file (@alias_files) {
548                 open my $fh, '<', $file or die "opening $file: $!\n";
549                 $parse_alias{$aliasfiletype}->($fh);
550                 close $fh;
551         }
552 }
553
554 # is_format_patch_arg($f) returns 0 if $f names a patch, or 1 if
555 # $f is a revision list specification to be passed to format-patch.
556 sub is_format_patch_arg {
557         return unless $repo;
558         my $f = shift;
559         try {
560                 $repo->command('rev-parse', '--verify', '--quiet', $f);
561                 if (defined($format_patch)) {
562                         return $format_patch;
563                 }
564                 die(<<EOF);
565 File '$f' exists but it could also be the range of commits
566 to produce patches for.  Please disambiguate by...
567
568     * Saying "./$f" if you mean a file; or
569     * Giving --format-patch option if you mean a range.
570 EOF
571         } catch Git::Error::Command with {
572                 # Not a valid revision.  Treat it as a filename.
573                 return 0;
574         }
575 }
576
577 # Now that all the defaults are set, process the rest of the command line
578 # arguments and collect up the files that need to be processed.
579 my @rev_list_opts;
580 while (defined(my $f = shift @ARGV)) {
581         if ($f eq "--") {
582                 push @rev_list_opts, "--", @ARGV;
583                 @ARGV = ();
584         } elsif (-d $f and !is_format_patch_arg($f)) {
585                 opendir my $dh, $f
586                         or die "Failed to opendir $f: $!";
587
588                 push @files, grep { -f $_ } map { catfile($f, $_) }
589                                 sort readdir $dh;
590                 closedir $dh;
591         } elsif ((-f $f or -p $f) and !is_format_patch_arg($f)) {
592                 push @files, $f;
593         } else {
594                 push @rev_list_opts, $f;
595         }
596 }
597
598 if (@rev_list_opts) {
599         die "Cannot run git format-patch from outside a repository\n"
600                 unless $repo;
601         push @files, $repo->command('format-patch', '-o', tempdir(CLEANUP => 1), @rev_list_opts);
602 }
603
604 if ($validate) {
605         foreach my $f (@files) {
606                 unless (-p $f) {
607                         my $error = validate_patch($f);
608                         $error and die "fatal: $f: $error\nwarning: no patches were sent\n";
609                 }
610         }
611 }
612
613 if (@files) {
614         unless ($quiet) {
615                 print $_,"\n" for (@files);
616         }
617 } else {
618         print STDERR "\nNo patch files specified!\n\n";
619         usage();
620 }
621
622 sub get_patch_subject {
623         my $fn = shift;
624         open (my $fh, '<', $fn);
625         while (my $line = <$fh>) {
626                 next unless ($line =~ /^Subject: (.*)$/);
627                 close $fh;
628                 return "GIT: $1\n";
629         }
630         close $fh;
631         die "No subject line in $fn ?";
632 }
633
634 if ($compose) {
635         # Note that this does not need to be secure, but we will make a small
636         # effort to have it be unique
637         $compose_filename = ($repo ?
638                 tempfile(".gitsendemail.msg.XXXXXX", DIR => $repo->repo_path()) :
639                 tempfile(".gitsendemail.msg.XXXXXX", DIR => "."))[1];
640         open my $c, ">", $compose_filename
641                 or die "Failed to open for writing $compose_filename: $!";
642
643
644         my $tpl_sender = $sender || $repoauthor || $repocommitter || '';
645         my $tpl_subject = $initial_subject || '';
646         my $tpl_reply_to = $initial_reply_to || '';
647
648         print $c <<EOT;
649 From $tpl_sender # This line is ignored.
650 GIT: Lines beginning in "GIT:" will be removed.
651 GIT: Consider including an overall diffstat or table of contents
652 GIT: for the patch you are writing.
653 GIT:
654 GIT: Clear the body content if you don't wish to send a summary.
655 From: $tpl_sender
656 Subject: $tpl_subject
657 In-Reply-To: $tpl_reply_to
658
659 EOT
660         for my $f (@files) {
661                 print $c get_patch_subject($f);
662         }
663         close $c;
664
665         if ($annotate) {
666                 do_edit($compose_filename, @files);
667         } else {
668                 do_edit($compose_filename);
669         }
670
671         open my $c2, ">", $compose_filename . ".final"
672                 or die "Failed to open $compose_filename.final : " . $!;
673
674         open $c, "<", $compose_filename
675                 or die "Failed to open $compose_filename : " . $!;
676
677         my $need_8bit_cte = file_has_nonascii($compose_filename);
678         my $in_body = 0;
679         my $summary_empty = 1;
680         if (!defined $compose_encoding) {
681                 $compose_encoding = "UTF-8";
682         }
683         while(<$c>) {
684                 next if m/^GIT:/;
685                 if ($in_body) {
686                         $summary_empty = 0 unless (/^\n$/);
687                 } elsif (/^\n$/) {
688                         $in_body = 1;
689                         if ($need_8bit_cte) {
690                                 print $c2 "MIME-Version: 1.0\n",
691                                          "Content-Type: text/plain; ",
692                                            "charset=$compose_encoding\n",
693                                          "Content-Transfer-Encoding: 8bit\n";
694                         }
695                 } elsif (/^MIME-Version:/i) {
696                         $need_8bit_cte = 0;
697                 } elsif (/^Subject:\s*(.+)\s*$/i) {
698                         $initial_subject = $1;
699                         my $subject = $initial_subject;
700                         $_ = "Subject: " .
701                                 quote_subject($subject, $compose_encoding) .
702                                 "\n";
703                 } elsif (/^In-Reply-To:\s*(.+)\s*$/i) {
704                         $initial_reply_to = $1;
705                         next;
706                 } elsif (/^From:\s*(.+)\s*$/i) {
707                         $sender = $1;
708                         next;
709                 } elsif (/^(?:To|Cc|Bcc):/i) {
710                         print "To/Cc/Bcc fields are not interpreted yet, they have been ignored\n";
711                         next;
712                 }
713                 print $c2 $_;
714         }
715         close $c;
716         close $c2;
717
718         if ($summary_empty) {
719                 print "Summary email is empty, skipping it\n";
720                 $compose = -1;
721         }
722 } elsif ($annotate) {
723         do_edit(@files);
724 }
725
726 sub ask {
727         my ($prompt, %arg) = @_;
728         my $valid_re = $arg{valid_re};
729         my $default = $arg{default};
730         my $confirm_only = $arg{confirm_only};
731         my $resp;
732         my $i = 0;
733         return defined $default ? $default : undef
734                 unless defined $term->IN and defined fileno($term->IN) and
735                        defined $term->OUT and defined fileno($term->OUT);
736         while ($i++ < 10) {
737                 $resp = $term->readline($prompt);
738                 if (!defined $resp) { # EOF
739                         print "\n";
740                         return defined $default ? $default : undef;
741                 }
742                 if ($resp eq '' and defined $default) {
743                         return $default;
744                 }
745                 if (!defined $valid_re or $resp =~ /$valid_re/) {
746                         return $resp;
747                 }
748                 if ($confirm_only) {
749                         my $yesno = $term->readline("Are you sure you want to use <$resp> [y/N]? ");
750                         if (defined $yesno && $yesno =~ /y/i) {
751                                 return $resp;
752                         }
753                 }
754         }
755         return;
756 }
757
758 my %broken_encoding;
759
760 sub file_declares_8bit_cte {
761         my $fn = shift;
762         open (my $fh, '<', $fn);
763         while (my $line = <$fh>) {
764                 last if ($line =~ /^$/);
765                 return 1 if ($line =~ /^Content-Transfer-Encoding: .*8bit.*$/);
766         }
767         close $fh;
768         return 0;
769 }
770
771 foreach my $f (@files) {
772         next unless (body_or_subject_has_nonascii($f)
773                      && !file_declares_8bit_cte($f));
774         $broken_encoding{$f} = 1;
775 }
776
777 if (!defined $auto_8bit_encoding && scalar %broken_encoding) {
778         print "The following files are 8bit, but do not declare " .
779                 "a Content-Transfer-Encoding.\n";
780         foreach my $f (sort keys %broken_encoding) {
781                 print "    $f\n";
782         }
783         $auto_8bit_encoding = ask("Which 8bit encoding should I declare [UTF-8]? ",
784                                   valid_re => qr/.{4}/, confirm_only => 1,
785                                   default => "UTF-8");
786 }
787
788 if (!$force) {
789         for my $f (@files) {
790                 if (get_patch_subject($f) =~ /\Q*** SUBJECT HERE ***\E/) {
791                         die "Refusing to send because the patch\n\t$f\n"
792                                 . "has the template subject '*** SUBJECT HERE ***'. "
793                                 . "Pass --force if you really want to send.\n";
794                 }
795         }
796 }
797
798 if (defined $sender) {
799         $sender =~ s/^\s+|\s+$//g;
800         ($sender) = expand_aliases($sender);
801 } else {
802         $sender = $repoauthor || $repocommitter || '';
803 }
804
805 # $sender could be an already sanitized address
806 # (e.g. sendemail.from could be manually sanitized by user).
807 # But it's a no-op to run sanitize_address on an already sanitized address.
808 $sender = sanitize_address($sender);
809
810 my $prompting = 0;
811 if (!@initial_to && !defined $to_cmd) {
812         my $to = ask("Who should the emails be sent to (if any)? ",
813                      default => "",
814                      valid_re => qr/\@.*\./, confirm_only => 1);
815         push @initial_to, parse_address_line($to) if defined $to; # sanitized/validated later
816         $prompting++;
817 }
818
819 sub expand_aliases {
820         return map { expand_one_alias($_) } @_;
821 }
822
823 my %EXPANDED_ALIASES;
824 sub expand_one_alias {
825         my $alias = shift;
826         if ($EXPANDED_ALIASES{$alias}) {
827                 die "fatal: alias '$alias' expands to itself\n";
828         }
829         local $EXPANDED_ALIASES{$alias} = 1;
830         return $aliases{$alias} ? expand_aliases(@{$aliases{$alias}}) : $alias;
831 }
832
833 @initial_to = process_address_list(@initial_to);
834 @initial_cc = process_address_list(@initial_cc);
835 @bcclist = process_address_list(@bcclist);
836
837 if ($thread && !defined $initial_reply_to && $prompting) {
838         $initial_reply_to = ask(
839                 "Message-ID to be used as In-Reply-To for the first email (if any)? ",
840                 default => "",
841                 valid_re => qr/\@.*\./, confirm_only => 1);
842 }
843 if (defined $initial_reply_to) {
844         $initial_reply_to =~ s/^\s*<?//;
845         $initial_reply_to =~ s/>?\s*$//;
846         $initial_reply_to = "<$initial_reply_to>" if $initial_reply_to ne '';
847 }
848
849 if (!defined $smtp_server) {
850         foreach (qw( /usr/sbin/sendmail /usr/lib/sendmail )) {
851                 if (-x $_) {
852                         $smtp_server = $_;
853                         last;
854                 }
855         }
856         $smtp_server ||= 'localhost'; # could be 127.0.0.1, too... *shrug*
857 }
858
859 if ($compose && $compose > 0) {
860         @files = ($compose_filename . ".final", @files);
861 }
862
863 # Variables we set as part of the loop over files
864 our ($message_id, %mail, $subject, $reply_to, $references, $message,
865         $needs_confirm, $message_num, $ask_default);
866
867 sub extract_valid_address {
868         my $address = shift;
869         my $local_part_regexp = qr/[^<>"\s@]+/;
870         my $domain_regexp = qr/[^.<>"\s@]+(?:\.[^.<>"\s@]+)+/;
871
872         # check for a local address:
873         return $address if ($address =~ /^($local_part_regexp)$/);
874
875         $address =~ s/^\s*<(.*)>\s*$/$1/;
876         if ($have_email_valid) {
877                 return scalar Email::Valid->address($address);
878         }
879
880         # less robust/correct than the monster regexp in Email::Valid,
881         # but still does a 99% job, and one less dependency
882         return $1 if $address =~ /($local_part_regexp\@$domain_regexp)/;
883         return;
884 }
885
886 sub extract_valid_address_or_die {
887         my $address = shift;
888         $address = extract_valid_address($address);
889         die "error: unable to extract a valid address from: $address\n"
890                 if !$address;
891         return $address;
892 }
893
894 sub validate_address {
895         my $address = shift;
896         while (!extract_valid_address($address)) {
897                 print STDERR "error: unable to extract a valid address from: $address\n";
898                 $_ = ask("What to do with this address? ([q]uit|[d]rop|[e]dit): ",
899                         valid_re => qr/^(?:quit|q|drop|d|edit|e)/i,
900                         default => 'q');
901                 if (/^d/i) {
902                         return undef;
903                 } elsif (/^q/i) {
904                         cleanup_compose_files();
905                         exit(0);
906                 }
907                 $address = ask("Who should the email be sent to (if any)? ",
908                         default => "",
909                         valid_re => qr/\@.*\./, confirm_only => 1);
910         }
911         return $address;
912 }
913
914 sub validate_address_list {
915         return (grep { defined $_ }
916                 map { validate_address($_) } @_);
917 }
918
919 # Usually don't need to change anything below here.
920
921 # we make a "fake" message id by taking the current number
922 # of seconds since the beginning of Unix time and tacking on
923 # a random number to the end, in case we are called quicker than
924 # 1 second since the last time we were called.
925
926 # We'll setup a template for the message id, using the "from" address:
927
928 my ($message_id_stamp, $message_id_serial);
929 sub make_message_id {
930         my $uniq;
931         if (!defined $message_id_stamp) {
932                 $message_id_stamp = sprintf("%s-%s", time, $$);
933                 $message_id_serial = 0;
934         }
935         $message_id_serial++;
936         $uniq = "$message_id_stamp-$message_id_serial";
937
938         my $du_part;
939         for ($sender, $repocommitter, $repoauthor) {
940                 $du_part = extract_valid_address(sanitize_address($_));
941                 last if (defined $du_part and $du_part ne '');
942         }
943         if (not defined $du_part or $du_part eq '') {
944                 require Sys::Hostname;
945                 $du_part = 'user@' . Sys::Hostname::hostname();
946         }
947         my $message_id_template = "<%s-git-send-email-%s>";
948         $message_id = sprintf($message_id_template, $uniq, $du_part);
949         #print "new message id = $message_id\n"; # Was useful for debugging
950 }
951
952
953
954 $time = time - scalar $#files;
955
956 sub unquote_rfc2047 {
957         local ($_) = @_;
958         my $charset;
959         my $sep = qr/[ \t]+/;
960         s{$re_encoded_word(?:$sep$re_encoded_word)*}{
961                 my @words = split $sep, $&;
962                 foreach (@words) {
963                         m/$re_encoded_word/;
964                         $charset = $1;
965                         my $encoding = $2;
966                         my $text = $3;
967                         if ($encoding eq 'q' || $encoding eq 'Q') {
968                                 $_ = $text;
969                                 s/_/ /g;
970                                 s/=([0-9A-F]{2})/chr(hex($1))/egi;
971                         } else {
972                                 # other encodings not supported yet
973                         }
974                 }
975                 join '', @words;
976         }eg;
977         return wantarray ? ($_, $charset) : $_;
978 }
979
980 sub quote_rfc2047 {
981         local $_ = shift;
982         my $encoding = shift || 'UTF-8';
983         s/([^-a-zA-Z0-9!*+\/])/sprintf("=%02X", ord($1))/eg;
984         s/(.*)/=\?$encoding\?q\?$1\?=/;
985         return $_;
986 }
987
988 sub is_rfc2047_quoted {
989         my $s = shift;
990         length($s) <= 75 &&
991         $s =~ m/^(?:"[[:ascii:]]*"|$re_encoded_word)$/o;
992 }
993
994 sub subject_needs_rfc2047_quoting {
995         my $s = shift;
996
997         return ($s =~ /[^[:ascii:]]/) || ($s =~ /=\?/);
998 }
999
1000 sub quote_subject {
1001         local $subject = shift;
1002         my $encoding = shift || 'UTF-8';
1003
1004         if (subject_needs_rfc2047_quoting($subject)) {
1005                 return quote_rfc2047($subject, $encoding);
1006         }
1007         return $subject;
1008 }
1009
1010 # use the simplest quoting being able to handle the recipient
1011 sub sanitize_address {
1012         my ($recipient) = @_;
1013
1014         # remove garbage after email address
1015         $recipient =~ s/(.*>).*$/$1/;
1016
1017         my ($recipient_name, $recipient_addr) = ($recipient =~ /^(.*?)\s*(<.*)/);
1018
1019         if (not $recipient_name) {
1020                 return $recipient;
1021         }
1022
1023         # if recipient_name is already quoted, do nothing
1024         if (is_rfc2047_quoted($recipient_name)) {
1025                 return $recipient;
1026         }
1027
1028         # remove non-escaped quotes
1029         $recipient_name =~ s/(^|[^\\])"/$1/g;
1030
1031         # rfc2047 is needed if a non-ascii char is included
1032         if ($recipient_name =~ /[^[:ascii:]]/) {
1033                 $recipient_name = quote_rfc2047($recipient_name);
1034         }
1035
1036         # double quotes are needed if specials or CTLs are included
1037         elsif ($recipient_name =~ /[][()<>@,;:\\".\000-\037\177]/) {
1038                 $recipient_name =~ s/([\\\r])/\\$1/g;
1039                 $recipient_name = qq["$recipient_name"];
1040         }
1041
1042         return "$recipient_name $recipient_addr";
1043
1044 }
1045
1046 sub sanitize_address_list {
1047         return (map { sanitize_address($_) } @_);
1048 }
1049
1050 sub process_address_list {
1051         my @addr_list = map { parse_address_line($_) } @_;
1052         @addr_list = expand_aliases(@addr_list);
1053         @addr_list = sanitize_address_list(@addr_list);
1054         @addr_list = validate_address_list(@addr_list);
1055         return @addr_list;
1056 }
1057
1058 # Returns the local Fully Qualified Domain Name (FQDN) if available.
1059 #
1060 # Tightly configured MTAa require that a caller sends a real DNS
1061 # domain name that corresponds the IP address in the HELO/EHLO
1062 # handshake. This is used to verify the connection and prevent
1063 # spammers from trying to hide their identity. If the DNS and IP don't
1064 # match, the receiveing MTA may deny the connection.
1065 #
1066 # Here is a deny example of Net::SMTP with the default "localhost.localdomain"
1067 #
1068 # Net::SMTP=GLOB(0x267ec28)>>> EHLO localhost.localdomain
1069 # Net::SMTP=GLOB(0x267ec28)<<< 550 EHLO argument does not match calling host
1070 #
1071 # This maildomain*() code is based on ideas in Perl library Test::Reporter
1072 # /usr/share/perl5/Test/Reporter/Mail/Util.pm ==> sub _maildomain ()
1073
1074 sub valid_fqdn {
1075         my $domain = shift;
1076         return defined $domain && !($^O eq 'darwin' && $domain =~ /\.local$/) && $domain =~ /\./;
1077 }
1078
1079 sub maildomain_net {
1080         my $maildomain;
1081
1082         if (eval { require Net::Domain; 1 }) {
1083                 my $domain = Net::Domain::domainname();
1084                 $maildomain = $domain if valid_fqdn($domain);
1085         }
1086
1087         return $maildomain;
1088 }
1089
1090 sub maildomain_mta {
1091         my $maildomain;
1092
1093         if (eval { require Net::SMTP; 1 }) {
1094                 for my $host (qw(mailhost localhost)) {
1095                         my $smtp = Net::SMTP->new($host);
1096                         if (defined $smtp) {
1097                                 my $domain = $smtp->domain;
1098                                 $smtp->quit;
1099
1100                                 $maildomain = $domain if valid_fqdn($domain);
1101
1102                                 last if $maildomain;
1103                         }
1104                 }
1105         }
1106
1107         return $maildomain;
1108 }
1109
1110 sub maildomain {
1111         return maildomain_net() || maildomain_mta() || 'localhost.localdomain';
1112 }
1113
1114 sub smtp_host_string {
1115         if (defined $smtp_server_port) {
1116                 return "$smtp_server:$smtp_server_port";
1117         } else {
1118                 return $smtp_server;
1119         }
1120 }
1121
1122 # Returns 1 if authentication succeeded or was not necessary
1123 # (smtp_user was not specified), and 0 otherwise.
1124
1125 sub smtp_auth_maybe {
1126         if (!defined $smtp_authuser || $auth) {
1127                 return 1;
1128         }
1129
1130         # Workaround AUTH PLAIN/LOGIN interaction defect
1131         # with Authen::SASL::Cyrus
1132         eval {
1133                 require Authen::SASL;
1134                 Authen::SASL->import(qw(Perl));
1135         };
1136
1137         # Check mechanism naming as defined in:
1138         # https://tools.ietf.org/html/rfc4422#page-8
1139         if ($smtp_auth && $smtp_auth !~ /^(\b[A-Z0-9-_]{1,20}\s*)*$/) {
1140                 die "invalid smtp auth: '${smtp_auth}'";
1141         }
1142
1143         # TODO: Authentication may fail not because credentials were
1144         # invalid but due to other reasons, in which we should not
1145         # reject credentials.
1146         $auth = Git::credential({
1147                 'protocol' => 'smtp',
1148                 'host' => smtp_host_string(),
1149                 'username' => $smtp_authuser,
1150                 # if there's no password, "git credential fill" will
1151                 # give us one, otherwise it'll just pass this one.
1152                 'password' => $smtp_authpass
1153         }, sub {
1154                 my $cred = shift;
1155
1156                 if ($smtp_auth) {
1157                         my $sasl = Authen::SASL->new(
1158                                 mechanism => $smtp_auth,
1159                                 callback => {
1160                                         user => $cred->{'username'},
1161                                         pass => $cred->{'password'},
1162                                         authname => $cred->{'username'},
1163                                 }
1164                         );
1165
1166                         return !!$smtp->auth($sasl);
1167                 }
1168
1169                 return !!$smtp->auth($cred->{'username'}, $cred->{'password'});
1170         });
1171
1172         return $auth;
1173 }
1174
1175 sub ssl_verify_params {
1176         eval {
1177                 require IO::Socket::SSL;
1178                 IO::Socket::SSL->import(qw/SSL_VERIFY_PEER SSL_VERIFY_NONE/);
1179         };
1180         if ($@) {
1181                 print STDERR "Not using SSL_VERIFY_PEER due to out-of-date IO::Socket::SSL.\n";
1182                 return;
1183         }
1184
1185         if (!defined $smtp_ssl_cert_path) {
1186                 # use the OpenSSL defaults
1187                 return (SSL_verify_mode => SSL_VERIFY_PEER());
1188         }
1189
1190         if ($smtp_ssl_cert_path eq "") {
1191                 return (SSL_verify_mode => SSL_VERIFY_NONE());
1192         } elsif (-d $smtp_ssl_cert_path) {
1193                 return (SSL_verify_mode => SSL_VERIFY_PEER(),
1194                         SSL_ca_path => $smtp_ssl_cert_path);
1195         } elsif (-f $smtp_ssl_cert_path) {
1196                 return (SSL_verify_mode => SSL_VERIFY_PEER(),
1197                         SSL_ca_file => $smtp_ssl_cert_path);
1198         } else {
1199                 print STDERR "Not using SSL_VERIFY_PEER because the CA path does not exist.\n";
1200                 return (SSL_verify_mode => SSL_VERIFY_NONE());
1201         }
1202 }
1203
1204 sub file_name_is_absolute {
1205         my ($path) = @_;
1206
1207         # msys does not grok DOS drive-prefixes
1208         if ($^O eq 'msys') {
1209                 return ($path =~ m#^/# || $path =~ m#^[a-zA-Z]\:#)
1210         }
1211
1212         require File::Spec::Functions;
1213         return File::Spec::Functions::file_name_is_absolute($path);
1214 }
1215
1216 # Returns 1 if the message was sent, and 0 otherwise.
1217 # In actuality, the whole program dies when there
1218 # is an error sending a message.
1219
1220 sub send_message {
1221         my @recipients = unique_email_list(@to);
1222         @cc = (grep { my $cc = extract_valid_address_or_die($_);
1223                       not grep { $cc eq $_ || $_ =~ /<\Q${cc}\E>$/ } @recipients
1224                     }
1225                @cc);
1226         my $to = join (",\n\t", @recipients);
1227         @recipients = unique_email_list(@recipients,@cc,@bcclist);
1228         @recipients = (map { extract_valid_address_or_die($_) } @recipients);
1229         my $date = format_2822_time($time++);
1230         my $gitversion = '@@GIT_VERSION@@';
1231         if ($gitversion =~ m/..GIT_VERSION../) {
1232             $gitversion = Git::version();
1233         }
1234
1235         my $cc = join(",\n\t", unique_email_list(@cc));
1236         my $ccline = "";
1237         if ($cc ne '') {
1238                 $ccline = "\nCc: $cc";
1239         }
1240         make_message_id() unless defined($message_id);
1241
1242         my $header = "From: $sender
1243 To: $to${ccline}
1244 Subject: $subject
1245 Date: $date
1246 Message-Id: $message_id
1247 ";
1248         if ($use_xmailer) {
1249                 $header .= "X-Mailer: git-send-email $gitversion\n";
1250         }
1251         if ($reply_to) {
1252
1253                 $header .= "In-Reply-To: $reply_to\n";
1254                 $header .= "References: $references\n";
1255         }
1256         if (@xh) {
1257                 $header .= join("\n", @xh) . "\n";
1258         }
1259
1260         my @sendmail_parameters = ('-i', @recipients);
1261         my $raw_from = $sender;
1262         if (defined $envelope_sender && $envelope_sender ne "auto") {
1263                 $raw_from = $envelope_sender;
1264         }
1265         $raw_from = extract_valid_address($raw_from);
1266         unshift (@sendmail_parameters,
1267                         '-f', $raw_from) if(defined $envelope_sender);
1268
1269         if ($needs_confirm && !$dry_run) {
1270                 print "\n$header\n";
1271                 if ($needs_confirm eq "inform") {
1272                         $confirm_unconfigured = 0; # squelch this message for the rest of this run
1273                         $ask_default = "y"; # assume yes on EOF since user hasn't explicitly asked for confirmation
1274                         print "    The Cc list above has been expanded by additional\n";
1275                         print "    addresses found in the patch commit message. By default\n";
1276                         print "    send-email prompts before sending whenever this occurs.\n";
1277                         print "    This behavior is controlled by the sendemail.confirm\n";
1278                         print "    configuration setting.\n";
1279                         print "\n";
1280                         print "    For additional information, run 'git send-email --help'.\n";
1281                         print "    To retain the current behavior, but squelch this message,\n";
1282                         print "    run 'git config --global sendemail.confirm auto'.\n\n";
1283                 }
1284                 $_ = ask("Send this email? ([y]es|[n]o|[q]uit|[a]ll): ",
1285                          valid_re => qr/^(?:yes|y|no|n|quit|q|all|a)/i,
1286                          default => $ask_default);
1287                 die "Send this email reply required" unless defined $_;
1288                 if (/^n/i) {
1289                         return 0;
1290                 } elsif (/^q/i) {
1291                         cleanup_compose_files();
1292                         exit(0);
1293                 } elsif (/^a/i) {
1294                         $confirm = 'never';
1295                 }
1296         }
1297
1298         unshift (@sendmail_parameters, @smtp_server_options);
1299
1300         if ($dry_run) {
1301                 # We don't want to send the email.
1302         } elsif (file_name_is_absolute($smtp_server)) {
1303                 my $pid = open my $sm, '|-';
1304                 defined $pid or die $!;
1305                 if (!$pid) {
1306                         exec($smtp_server, @sendmail_parameters) or die $!;
1307                 }
1308                 print $sm "$header\n$message";
1309                 close $sm or die $!;
1310         } else {
1311
1312                 if (!defined $smtp_server) {
1313                         die "The required SMTP server is not properly defined."
1314                 }
1315
1316                 if ($smtp_encryption eq 'ssl') {
1317                         $smtp_server_port ||= 465; # ssmtp
1318                         require Net::SMTP::SSL;
1319                         $smtp_domain ||= maildomain();
1320                         require IO::Socket::SSL;
1321
1322                         # Suppress "variable accessed once" warning.
1323                         {
1324                                 no warnings 'once';
1325                                 $IO::Socket::SSL::DEBUG = 1;
1326                         }
1327
1328                         # Net::SMTP::SSL->new() does not forward any SSL options
1329                         IO::Socket::SSL::set_client_defaults(
1330                                 ssl_verify_params());
1331                         $smtp ||= Net::SMTP::SSL->new($smtp_server,
1332                                                       Hello => $smtp_domain,
1333                                                       Port => $smtp_server_port,
1334                                                       Debug => $debug_net_smtp);
1335                 }
1336                 else {
1337                         require Net::SMTP;
1338                         $smtp_domain ||= maildomain();
1339                         $smtp_server_port ||= 25;
1340                         $smtp ||= Net::SMTP->new($smtp_server,
1341                                                  Hello => $smtp_domain,
1342                                                  Debug => $debug_net_smtp,
1343                                                  Port => $smtp_server_port);
1344                         if ($smtp_encryption eq 'tls' && $smtp) {
1345                                 require Net::SMTP::SSL;
1346                                 $smtp->command('STARTTLS');
1347                                 $smtp->response();
1348                                 if ($smtp->code == 220) {
1349                                         $smtp = Net::SMTP::SSL->start_SSL($smtp,
1350                                                                           ssl_verify_params())
1351                                                 or die "STARTTLS failed! ".IO::Socket::SSL::errstr();
1352                                         $smtp_encryption = '';
1353                                         # Send EHLO again to receive fresh
1354                                         # supported commands
1355                                         $smtp->hello($smtp_domain);
1356                                 } else {
1357                                         die "Server does not support STARTTLS! ".$smtp->message;
1358                                 }
1359                         }
1360                 }
1361
1362                 if (!$smtp) {
1363                         die "Unable to initialize SMTP properly. Check config and use --smtp-debug. ",
1364                             "VALUES: server=$smtp_server ",
1365                             "encryption=$smtp_encryption ",
1366                             "hello=$smtp_domain",
1367                             defined $smtp_server_port ? " port=$smtp_server_port" : "";
1368                 }
1369
1370                 smtp_auth_maybe or die $smtp->message;
1371
1372                 $smtp->mail( $raw_from ) or die $smtp->message;
1373                 $smtp->to( @recipients ) or die $smtp->message;
1374                 $smtp->data or die $smtp->message;
1375                 $smtp->datasend("$header\n") or die $smtp->message;
1376                 my @lines = split /^/, $message;
1377                 foreach my $line (@lines) {
1378                         $smtp->datasend("$line") or die $smtp->message;
1379                 }
1380                 $smtp->dataend() or die $smtp->message;
1381                 $smtp->code =~ /250|200/ or die "Failed to send $subject\n".$smtp->message;
1382         }
1383         if ($quiet) {
1384                 printf (($dry_run ? "Dry-" : "")."Sent %s\n", $subject);
1385         } else {
1386                 print (($dry_run ? "Dry-" : "")."OK. Log says:\n");
1387                 if (!file_name_is_absolute($smtp_server)) {
1388                         print "Server: $smtp_server\n";
1389                         print "MAIL FROM:<$raw_from>\n";
1390                         foreach my $entry (@recipients) {
1391                             print "RCPT TO:<$entry>\n";
1392                         }
1393                 } else {
1394                         print "Sendmail: $smtp_server ".join(' ',@sendmail_parameters)."\n";
1395                 }
1396                 print $header, "\n";
1397                 if ($smtp) {
1398                         print "Result: ", $smtp->code, ' ',
1399                                 ($smtp->message =~ /\n([^\n]+\n)$/s), "\n";
1400                 } else {
1401                         print "Result: OK\n";
1402                 }
1403         }
1404
1405         return 1;
1406 }
1407
1408 $reply_to = $initial_reply_to;
1409 $references = $initial_reply_to || '';
1410 $subject = $initial_subject;
1411 $message_num = 0;
1412
1413 foreach my $t (@files) {
1414         open my $fh, "<", $t or die "can't open file $t";
1415
1416         my $author = undef;
1417         my $sauthor = undef;
1418         my $author_encoding;
1419         my $has_content_type;
1420         my $body_encoding;
1421         my $xfer_encoding;
1422         my $has_mime_version;
1423         @to = ();
1424         @cc = ();
1425         @xh = ();
1426         my $input_format = undef;
1427         my @header = ();
1428         $message = "";
1429         $message_num++;
1430         # First unfold multiline header fields
1431         while(<$fh>) {
1432                 last if /^\s*$/;
1433                 if (/^\s+\S/ and @header) {
1434                         chomp($header[$#header]);
1435                         s/^\s+/ /;
1436                         $header[$#header] .= $_;
1437             } else {
1438                         push(@header, $_);
1439                 }
1440         }
1441         # Now parse the header
1442         foreach(@header) {
1443                 if (/^From /) {
1444                         $input_format = 'mbox';
1445                         next;
1446                 }
1447                 chomp;
1448                 if (!defined $input_format && /^[-A-Za-z]+:\s/) {
1449                         $input_format = 'mbox';
1450                 }
1451
1452                 if (defined $input_format && $input_format eq 'mbox') {
1453                         if (/^Subject:\s+(.*)$/i) {
1454                                 $subject = $1;
1455                         }
1456                         elsif (/^From:\s+(.*)$/i) {
1457                                 ($author, $author_encoding) = unquote_rfc2047($1);
1458                                 $sauthor = sanitize_address($author);
1459                                 next if $suppress_cc{'author'};
1460                                 next if $suppress_cc{'self'} and $sauthor eq $sender;
1461                                 printf("(mbox) Adding cc: %s from line '%s'\n",
1462                                         $1, $_) unless $quiet;
1463                                 push @cc, $1;
1464                         }
1465                         elsif (/^To:\s+(.*)$/i) {
1466                                 foreach my $addr (parse_address_line($1)) {
1467                                         printf("(mbox) Adding to: %s from line '%s'\n",
1468                                                 $addr, $_) unless $quiet;
1469                                         push @to, $addr;
1470                                 }
1471                         }
1472                         elsif (/^Cc:\s+(.*)$/i) {
1473                                 foreach my $addr (parse_address_line($1)) {
1474                                         my $qaddr = unquote_rfc2047($addr);
1475                                         my $saddr = sanitize_address($qaddr);
1476                                         if ($saddr eq $sender) {
1477                                                 next if ($suppress_cc{'self'});
1478                                         } else {
1479                                                 next if ($suppress_cc{'cc'});
1480                                         }
1481                                         printf("(mbox) Adding cc: %s from line '%s'\n",
1482                                                 $addr, $_) unless $quiet;
1483                                         push @cc, $addr;
1484                                 }
1485                         }
1486                         elsif (/^Content-type:/i) {
1487                                 $has_content_type = 1;
1488                                 if (/charset="?([^ "]+)/) {
1489                                         $body_encoding = $1;
1490                                 }
1491                                 push @xh, $_;
1492                         }
1493                         elsif (/^MIME-Version/i) {
1494                                 $has_mime_version = 1;
1495                                 push @xh, $_;
1496                         }
1497                         elsif (/^Message-Id: (.*)/i) {
1498                                 $message_id = $1;
1499                         }
1500                         elsif (/^Content-Transfer-Encoding: (.*)/i) {
1501                                 $xfer_encoding = $1 if not defined $xfer_encoding;
1502                         }
1503                         elsif (!/^Date:\s/i && /^[-A-Za-z]+:\s+\S/) {
1504                                 push @xh, $_;
1505                         }
1506
1507                 } else {
1508                         # In the traditional
1509                         # "send lots of email" format,
1510                         # line 1 = cc
1511                         # line 2 = subject
1512                         # So let's support that, too.
1513                         $input_format = 'lots';
1514                         if (@cc == 0 && !$suppress_cc{'cc'}) {
1515                                 printf("(non-mbox) Adding cc: %s from line '%s'\n",
1516                                         $_, $_) unless $quiet;
1517                                 push @cc, $_;
1518                         } elsif (!defined $subject) {
1519                                 $subject = $_;
1520                         }
1521                 }
1522         }
1523         # Now parse the message body
1524         while(<$fh>) {
1525                 $message .=  $_;
1526                 if (/^(Signed-off-by|Cc): (.*)$/i) {
1527                         chomp;
1528                         my ($what, $c) = ($1, $2);
1529                         chomp $c;
1530                         my $sc = sanitize_address($c);
1531                         if ($sc eq $sender) {
1532                                 next if ($suppress_cc{'self'});
1533                         } else {
1534                                 next if $suppress_cc{'sob'} and $what =~ /Signed-off-by/i;
1535                                 next if $suppress_cc{'bodycc'} and $what =~ /Cc/i;
1536                         }
1537                         push @cc, $c;
1538                         printf("(body) Adding cc: %s from line '%s'\n",
1539                                 $c, $_) unless $quiet;
1540                 }
1541         }
1542         close $fh;
1543
1544         push @to, recipients_cmd("to-cmd", "to", $to_cmd, $t)
1545                 if defined $to_cmd;
1546         push @cc, recipients_cmd("cc-cmd", "cc", $cc_cmd, $t)
1547                 if defined $cc_cmd && !$suppress_cc{'cccmd'};
1548
1549         if ($broken_encoding{$t} && !$has_content_type) {
1550                 $xfer_encoding = '8bit' if not defined $xfer_encoding;
1551                 $has_content_type = 1;
1552                 push @xh, "Content-Type: text/plain; charset=$auto_8bit_encoding";
1553                 $body_encoding = $auto_8bit_encoding;
1554         }
1555
1556         if ($broken_encoding{$t} && !is_rfc2047_quoted($subject)) {
1557                 $subject = quote_subject($subject, $auto_8bit_encoding);
1558         }
1559
1560         if (defined $sauthor and $sauthor ne $sender) {
1561                 $message = "From: $author\n\n$message";
1562                 if (defined $author_encoding) {
1563                         if ($has_content_type) {
1564                                 if ($body_encoding eq $author_encoding) {
1565                                         # ok, we already have the right encoding
1566                                 }
1567                                 else {
1568                                         # uh oh, we should re-encode
1569                                 }
1570                         }
1571                         else {
1572                                 $xfer_encoding = '8bit' if not defined $xfer_encoding;
1573                                 $has_content_type = 1;
1574                                 push @xh,
1575                                   "Content-Type: text/plain; charset=$author_encoding";
1576                         }
1577                 }
1578         }
1579         if (defined $target_xfer_encoding) {
1580                 $xfer_encoding = '8bit' if not defined $xfer_encoding;
1581                 $message = apply_transfer_encoding(
1582                         $message, $xfer_encoding, $target_xfer_encoding);
1583                 $xfer_encoding = $target_xfer_encoding;
1584         }
1585         if (defined $xfer_encoding) {
1586                 push @xh, "Content-Transfer-Encoding: $xfer_encoding";
1587         }
1588         if (defined $xfer_encoding or $has_content_type) {
1589                 unshift @xh, 'MIME-Version: 1.0' unless $has_mime_version;
1590         }
1591
1592         $needs_confirm = (
1593                 $confirm eq "always" or
1594                 ($confirm =~ /^(?:auto|cc)$/ && @cc) or
1595                 ($confirm =~ /^(?:auto|compose)$/ && $compose && $message_num == 1));
1596         $needs_confirm = "inform" if ($needs_confirm && $confirm_unconfigured && @cc);
1597
1598         @to = process_address_list(@to);
1599         @cc = process_address_list(@cc);
1600
1601         @to = (@initial_to, @to);
1602         @cc = (@initial_cc, @cc);
1603
1604         if ($message_num == 1) {
1605                 if (defined $cover_cc and $cover_cc) {
1606                         @initial_cc = @cc;
1607                 }
1608                 if (defined $cover_to and $cover_to) {
1609                         @initial_to = @to;
1610                 }
1611         }
1612
1613         my $message_was_sent = send_message();
1614
1615         # set up for the next message
1616         if ($thread && $message_was_sent &&
1617                 ($chain_reply_to || !defined $reply_to || length($reply_to) == 0 ||
1618                 $message_num == 1)) {
1619                 $reply_to = $message_id;
1620                 if (length $references > 0) {
1621                         $references .= "\n $message_id";
1622                 } else {
1623                         $references = "$message_id";
1624                 }
1625         }
1626         $message_id = undef;
1627 }
1628
1629 # Execute a command (e.g. $to_cmd) to get a list of email addresses
1630 # and return a results array
1631 sub recipients_cmd {
1632         my ($prefix, $what, $cmd, $file) = @_;
1633
1634         my @addresses = ();
1635         open my $fh, "-|", "$cmd \Q$file\E"
1636             or die "($prefix) Could not execute '$cmd'";
1637         while (my $address = <$fh>) {
1638                 $address =~ s/^\s*//g;
1639                 $address =~ s/\s*$//g;
1640                 $address = sanitize_address($address);
1641                 next if ($address eq $sender and $suppress_cc{'self'});
1642                 push @addresses, $address;
1643                 printf("($prefix) Adding %s: %s from: '%s'\n",
1644                        $what, $address, $cmd) unless $quiet;
1645                 }
1646         close $fh
1647             or die "($prefix) failed to close pipe to '$cmd'";
1648         return @addresses;
1649 }
1650
1651 cleanup_compose_files();
1652
1653 sub cleanup_compose_files {
1654         unlink($compose_filename, $compose_filename . ".final") if $compose;
1655 }
1656
1657 $smtp->quit if $smtp;
1658
1659 sub apply_transfer_encoding {
1660         my $message = shift;
1661         my $from = shift;
1662         my $to = shift;
1663
1664         return $message if ($from eq $to and $from ne '7bit');
1665
1666         require MIME::QuotedPrint;
1667         require MIME::Base64;
1668
1669         $message = MIME::QuotedPrint::decode($message)
1670                 if ($from eq 'quoted-printable');
1671         $message = MIME::Base64::decode($message)
1672                 if ($from eq 'base64');
1673
1674         die "cannot send message as 7bit"
1675                 if ($to eq '7bit' and $message =~ /[^[:ascii:]]/);
1676         return $message
1677                 if ($to eq '7bit' or $to eq '8bit');
1678         return MIME::QuotedPrint::encode($message, "\n", 0)
1679                 if ($to eq 'quoted-printable');
1680         return MIME::Base64::encode($message, "\n")
1681                 if ($to eq 'base64');
1682         die "invalid transfer encoding";
1683 }
1684
1685 sub unique_email_list {
1686         my %seen;
1687         my @emails;
1688
1689         foreach my $entry (@_) {
1690                 my $clean = extract_valid_address_or_die($entry);
1691                 $seen{$clean} ||= 0;
1692                 next if $seen{$clean}++;
1693                 push @emails, $entry;
1694         }
1695         return @emails;
1696 }
1697
1698 sub validate_patch {
1699         my $fn = shift;
1700         open(my $fh, '<', $fn)
1701                 or die "unable to open $fn: $!\n";
1702         while (my $line = <$fh>) {
1703                 if (length($line) > 998) {
1704                         return "$.: patch contains a line longer than 998 characters";
1705                 }
1706         }
1707         return;
1708 }
1709
1710 sub file_has_nonascii {
1711         my $fn = shift;
1712         open(my $fh, '<', $fn)
1713                 or die "unable to open $fn: $!\n";
1714         while (my $line = <$fh>) {
1715                 return 1 if $line =~ /[^[:ascii:]]/;
1716         }
1717         return 0;
1718 }
1719
1720 sub body_or_subject_has_nonascii {
1721         my $fn = shift;
1722         open(my $fh, '<', $fn)
1723                 or die "unable to open $fn: $!\n";
1724         while (my $line = <$fh>) {
1725                 last if $line =~ /^$/;
1726                 return 1 if $line =~ /^Subject.*[^[:ascii:]]/;
1727         }
1728         while (my $line = <$fh>) {
1729                 return 1 if $line =~ /[^[:ascii:]]/;
1730         }
1731         return 0;
1732 }