send-email: provide whitelist of SMTP AUTH mechanisms
[git] / git-send-email.perl
1 #!/usr/bin/perl
2 #
3 # Copyright 2002,2005 Greg Kroah-Hartman <greg@kroah.com>
4 # Copyright 2005 Ryan Anderson <ryan@michonline.com>
5 #
6 # GPL v2 (See COPYING)
7 #
8 # Ported to support git "mbox" format files by Ryan Anderson <ryan@michonline.com>
9 #
10 # Sends a collection of emails to the given email addresses, disturbingly fast.
11 #
12 # Supports two formats:
13 # 1. mbox format files (ignoring most headers and MIME formatting - this is designed for sending patches)
14 # 2. The original format support by Greg's script:
15 #    first line of the message is who to CC,
16 #    and second line is the subject of the message.
17 #
18
19 use 5.008;
20 use strict;
21 use warnings;
22 use Term::ReadLine;
23 use Getopt::Long;
24 use Text::ParseWords;
25 use Data::Dumper;
26 use Term::ANSIColor;
27 use File::Temp qw/ tempdir tempfile /;
28 use File::Spec::Functions qw(catfile);
29 use Error qw(:try);
30 use Git;
31
32 Getopt::Long::Configure qw/ pass_through /;
33
34 package FakeTerm;
35 sub new {
36         my ($class, $reason) = @_;
37         return bless \$reason, shift;
38 }
39 sub readline {
40         my $self = shift;
41         die "Cannot use readline on FakeTerm: $$self";
42 }
43 package main;
44
45
46 sub usage {
47         print <<EOT;
48 git send-email [options] <file | directory | rev-list options >
49
50   Composing:
51     --from                  <str>  * Email From:
52     --[no-]to               <str>  * Email To:
53     --[no-]cc               <str>  * Email Cc:
54     --[no-]bcc              <str>  * Email Bcc:
55     --subject               <str>  * Email "Subject:"
56     --in-reply-to           <str>  * Email "In-Reply-To:"
57     --[no-]xmailer                 * Add "X-Mailer:" header (default).
58     --[no-]annotate                * Review each patch that will be sent in an editor.
59     --compose                      * Open an editor for introduction.
60     --compose-encoding      <str>  * Encoding to assume for introduction.
61     --8bit-encoding         <str>  * Encoding to assume 8bit mails if undeclared
62     --transfer-encoding     <str>  * Transfer encoding to use (quoted-printable, 8bit, base64)
63
64   Sending:
65     --envelope-sender       <str>  * Email envelope sender.
66     --smtp-server       <str:int>  * Outgoing SMTP server to use. The port
67                                      is optional. Default 'localhost'.
68     --smtp-server-option    <str>  * Outgoing SMTP server option to use.
69     --smtp-server-port      <int>  * Outgoing SMTP server port.
70     --smtp-user             <str>  * Username for SMTP-AUTH.
71     --smtp-pass             <str>  * Password for SMTP-AUTH; not necessary.
72     --smtp-encryption       <str>  * tls or ssl; anything else disables.
73     --smtp-ssl                     * Deprecated. Use '--smtp-encryption ssl'.
74     --smtp-ssl-cert-path    <str>  * Path to ca-certificates (either directory or file).
75                                      Pass an empty string to disable certificate
76                                      verification.
77     --smtp-domain           <str>  * The domain name sent to HELO/EHLO handshake
78     --smtp-auth             <str>  * Space-separated list of allowed AUTH mechanisms.
79                                      This setting forces to use one of the listed mechanisms.
80     --smtp-debug            <0|1>  * Disable, enable Net::SMTP debug.
81
82   Automating:
83     --identity              <str>  * Use the sendemail.<id> options.
84     --to-cmd                <str>  * Email To: via `<str> \$patch_path`
85     --cc-cmd                <str>  * Email Cc: via `<str> \$patch_path`
86     --suppress-cc           <str>  * author, self, sob, cc, cccmd, body, bodycc, all.
87     --[no-]cc-cover                * Email Cc: addresses in the cover letter.
88     --[no-]to-cover                * Email To: addresses in the cover letter.
89     --[no-]signed-off-by-cc        * Send to Signed-off-by: addresses. Default on.
90     --[no-]suppress-from           * Send to self. Default off.
91     --[no-]chain-reply-to          * Chain In-Reply-To: fields. Default off.
92     --[no-]thread                  * Use In-Reply-To: field. Default on.
93
94   Administering:
95     --confirm               <str>  * Confirm recipients before sending;
96                                      auto, cc, compose, always, or never.
97     --quiet                        * Output one line of info per email.
98     --dry-run                      * Don't actually send the emails.
99     --[no-]validate                * Perform patch sanity checks. Default on.
100     --[no-]format-patch            * understand any non optional arguments as
101                                      `git format-patch` ones.
102     --force                        * Send even if safety checks would prevent it.
103
104 EOT
105         exit(1);
106 }
107
108 # most mail servers generate the Date: header, but not all...
109 sub format_2822_time {
110         my ($time) = @_;
111         my @localtm = localtime($time);
112         my @gmttm = gmtime($time);
113         my $localmin = $localtm[1] + $localtm[2] * 60;
114         my $gmtmin = $gmttm[1] + $gmttm[2] * 60;
115         if ($localtm[0] != $gmttm[0]) {
116                 die "local zone differs from GMT by a non-minute interval\n";
117         }
118         if ((($gmttm[6] + 1) % 7) == $localtm[6]) {
119                 $localmin += 1440;
120         } elsif ((($gmttm[6] - 1) % 7) == $localtm[6]) {
121                 $localmin -= 1440;
122         } elsif ($gmttm[6] != $localtm[6]) {
123                 die "local time offset greater than or equal to 24 hours\n";
124         }
125         my $offset = $localmin - $gmtmin;
126         my $offhour = $offset / 60;
127         my $offmin = abs($offset % 60);
128         if (abs($offhour) >= 24) {
129                 die ("local time offset greater than or equal to 24 hours\n");
130         }
131
132         return sprintf("%s, %2d %s %d %02d:%02d:%02d %s%02d%02d",
133                        qw(Sun Mon Tue Wed Thu Fri Sat)[$localtm[6]],
134                        $localtm[3],
135                        qw(Jan Feb Mar Apr May Jun
136                           Jul Aug Sep Oct Nov Dec)[$localtm[4]],
137                        $localtm[5]+1900,
138                        $localtm[2],
139                        $localtm[1],
140                        $localtm[0],
141                        ($offset >= 0) ? '+' : '-',
142                        abs($offhour),
143                        $offmin,
144                        );
145 }
146
147 my $have_email_valid = eval { require Email::Valid; 1 };
148 my $have_mail_address = eval { require Mail::Address; 1 };
149 my $smtp;
150 my $auth;
151
152 # Regexes for RFC 2047 productions.
153 my $re_token = qr/[^][()<>@,;:\\"\/?.= \000-\037\177-\377]+/;
154 my $re_encoded_text = qr/[^? \000-\037\177-\377]+/;
155 my $re_encoded_word = qr/=\?($re_token)\?($re_token)\?($re_encoded_text)\?=/;
156
157 # Variables we fill in automatically, or via prompting:
158 my (@to,$no_to,@initial_to,@cc,$no_cc,@initial_cc,@bcclist,$no_bcc,@xh,
159         $initial_reply_to,$initial_subject,@files,
160         $author,$sender,$smtp_authpass,$annotate,$use_xmailer,$compose,$time);
161
162 my $envelope_sender;
163
164 # Example reply to:
165 #$initial_reply_to = ''; #<20050203173208.GA23964@foobar.com>';
166
167 my $repo = eval { Git->repository() };
168 my @repo = $repo ? ($repo) : ();
169 my $term = eval {
170         $ENV{"GIT_SEND_EMAIL_NOTTY"}
171                 ? new Term::ReadLine 'git-send-email', \*STDIN, \*STDOUT
172                 : new Term::ReadLine 'git-send-email';
173 };
174 if ($@) {
175         $term = new FakeTerm "$@: going non-interactive";
176 }
177
178 # Behavior modification variables
179 my ($quiet, $dry_run) = (0, 0);
180 my $format_patch;
181 my $compose_filename;
182 my $force = 0;
183
184 # Handle interactive edition of files.
185 my $multiedit;
186 my $editor;
187
188 sub do_edit {
189         if (!defined($editor)) {
190                 $editor = Git::command_oneline('var', 'GIT_EDITOR');
191         }
192         if (defined($multiedit) && !$multiedit) {
193                 map {
194                         system('sh', '-c', $editor.' "$@"', $editor, $_);
195                         if (($? & 127) || ($? >> 8)) {
196                                 die("the editor exited uncleanly, aborting everything");
197                         }
198                 } @_;
199         } else {
200                 system('sh', '-c', $editor.' "$@"', $editor, @_);
201                 if (($? & 127) || ($? >> 8)) {
202                         die("the editor exited uncleanly, aborting everything");
203                 }
204         }
205 }
206
207 # Variables with corresponding config settings
208 my ($thread, $chain_reply_to, $suppress_from, $signed_off_by_cc);
209 my ($cover_cc, $cover_to);
210 my ($to_cmd, $cc_cmd);
211 my ($smtp_server, $smtp_server_port, @smtp_server_options);
212 my ($smtp_authuser, $smtp_encryption, $smtp_ssl_cert_path);
213 my ($identity, $aliasfiletype, @alias_files, $smtp_domain, $smtp_auth);
214 my ($validate, $confirm);
215 my (@suppress_cc);
216 my ($auto_8bit_encoding);
217 my ($compose_encoding);
218 my ($target_xfer_encoding);
219
220 my ($debug_net_smtp) = 0;               # Net::SMTP, see send_message()
221
222 my %config_bool_settings = (
223     "thread" => [\$thread, 1],
224     "chainreplyto" => [\$chain_reply_to, 0],
225     "suppressfrom" => [\$suppress_from, undef],
226     "signedoffbycc" => [\$signed_off_by_cc, undef],
227     "cccover" => [\$cover_cc, undef],
228     "tocover" => [\$cover_to, undef],
229     "signedoffcc" => [\$signed_off_by_cc, undef],      # Deprecated
230     "validate" => [\$validate, 1],
231     "multiedit" => [\$multiedit, undef],
232     "annotate" => [\$annotate, undef],
233     "xmailer" => [\$use_xmailer, 1]
234 );
235
236 my %config_settings = (
237     "smtpserver" => \$smtp_server,
238     "smtpserverport" => \$smtp_server_port,
239     "smtpserveroption" => \@smtp_server_options,
240     "smtpuser" => \$smtp_authuser,
241     "smtppass" => \$smtp_authpass,
242     "smtpsslcertpath" => \$smtp_ssl_cert_path,
243     "smtpdomain" => \$smtp_domain,
244     "smtpauth" => \$smtp_auth,
245     "to" => \@initial_to,
246     "tocmd" => \$to_cmd,
247     "cc" => \@initial_cc,
248     "cccmd" => \$cc_cmd,
249     "aliasfiletype" => \$aliasfiletype,
250     "bcc" => \@bcclist,
251     "suppresscc" => \@suppress_cc,
252     "envelopesender" => \$envelope_sender,
253     "confirm"   => \$confirm,
254     "from" => \$sender,
255     "assume8bitencoding" => \$auto_8bit_encoding,
256     "composeencoding" => \$compose_encoding,
257     "transferencoding" => \$target_xfer_encoding,
258 );
259
260 my %config_path_settings = (
261     "aliasesfile" => \@alias_files,
262 );
263
264 # Handle Uncouth Termination
265 sub signal_handler {
266
267         # Make text normal
268         print color("reset"), "\n";
269
270         # SMTP password masked
271         system "stty echo";
272
273         # tmp files from --compose
274         if (defined $compose_filename) {
275                 if (-e $compose_filename) {
276                         print "'$compose_filename' contains an intermediate version of the email you were composing.\n";
277                 }
278                 if (-e ($compose_filename . ".final")) {
279                         print "'$compose_filename.final' contains the composed email.\n"
280                 }
281         }
282
283         exit;
284 };
285
286 $SIG{TERM} = \&signal_handler;
287 $SIG{INT}  = \&signal_handler;
288
289 # Begin by accumulating all the variables (defined above), that we will end up
290 # needing, first, from the command line:
291
292 my $help;
293 my $rc = GetOptions("h" => \$help,
294                     "sender|from=s" => \$sender,
295                     "in-reply-to=s" => \$initial_reply_to,
296                     "subject=s" => \$initial_subject,
297                     "to=s" => \@initial_to,
298                     "to-cmd=s" => \$to_cmd,
299                     "no-to" => \$no_to,
300                     "cc=s" => \@initial_cc,
301                     "no-cc" => \$no_cc,
302                     "bcc=s" => \@bcclist,
303                     "no-bcc" => \$no_bcc,
304                     "chain-reply-to!" => \$chain_reply_to,
305                     "no-chain-reply-to" => sub {$chain_reply_to = 0},
306                     "smtp-server=s" => \$smtp_server,
307                     "smtp-server-option=s" => \@smtp_server_options,
308                     "smtp-server-port=s" => \$smtp_server_port,
309                     "smtp-user=s" => \$smtp_authuser,
310                     "smtp-pass:s" => \$smtp_authpass,
311                     "smtp-ssl" => sub { $smtp_encryption = 'ssl' },
312                     "smtp-encryption=s" => \$smtp_encryption,
313                     "smtp-ssl-cert-path=s" => \$smtp_ssl_cert_path,
314                     "smtp-debug:i" => \$debug_net_smtp,
315                     "smtp-domain:s" => \$smtp_domain,
316                     "smtp-auth=s" => \$smtp_auth,
317                     "identity=s" => \$identity,
318                     "annotate!" => \$annotate,
319                     "no-annotate" => sub {$annotate = 0},
320                     "compose" => \$compose,
321                     "quiet" => \$quiet,
322                     "cc-cmd=s" => \$cc_cmd,
323                     "suppress-from!" => \$suppress_from,
324                     "no-suppress-from" => sub {$suppress_from = 0},
325                     "suppress-cc=s" => \@suppress_cc,
326                     "signed-off-cc|signed-off-by-cc!" => \$signed_off_by_cc,
327                     "no-signed-off-cc|no-signed-off-by-cc" => sub {$signed_off_by_cc = 0},
328                     "cc-cover|cc-cover!" => \$cover_cc,
329                     "no-cc-cover" => sub {$cover_cc = 0},
330                     "to-cover|to-cover!" => \$cover_to,
331                     "no-to-cover" => sub {$cover_to = 0},
332                     "confirm=s" => \$confirm,
333                     "dry-run" => \$dry_run,
334                     "envelope-sender=s" => \$envelope_sender,
335                     "thread!" => \$thread,
336                     "no-thread" => sub {$thread = 0},
337                     "validate!" => \$validate,
338                     "no-validate" => sub {$validate = 0},
339                     "transfer-encoding=s" => \$target_xfer_encoding,
340                     "format-patch!" => \$format_patch,
341                     "no-format-patch" => sub {$format_patch = 0},
342                     "8bit-encoding=s" => \$auto_8bit_encoding,
343                     "compose-encoding=s" => \$compose_encoding,
344                     "force" => \$force,
345                     "xmailer!" => \$use_xmailer,
346                     "no-xmailer" => sub {$use_xmailer = 0},
347          );
348
349 usage() if $help;
350 unless ($rc) {
351     usage();
352 }
353
354 die "Cannot run git format-patch from outside a repository\n"
355         if $format_patch and not $repo;
356
357 # Now, let's fill any that aren't set in with defaults:
358
359 sub read_config {
360         my ($prefix) = @_;
361
362         foreach my $setting (keys %config_bool_settings) {
363                 my $target = $config_bool_settings{$setting}->[0];
364                 $$target = Git::config_bool(@repo, "$prefix.$setting") unless (defined $$target);
365         }
366
367         foreach my $setting (keys %config_path_settings) {
368                 my $target = $config_path_settings{$setting};
369                 if (ref($target) eq "ARRAY") {
370                         unless (@$target) {
371                                 my @values = Git::config_path(@repo, "$prefix.$setting");
372                                 @$target = @values if (@values && defined $values[0]);
373                         }
374                 }
375                 else {
376                         $$target = Git::config_path(@repo, "$prefix.$setting") unless (defined $$target);
377                 }
378         }
379
380         foreach my $setting (keys %config_settings) {
381                 my $target = $config_settings{$setting};
382                 next if $setting eq "to" and defined $no_to;
383                 next if $setting eq "cc" and defined $no_cc;
384                 next if $setting eq "bcc" and defined $no_bcc;
385                 if (ref($target) eq "ARRAY") {
386                         unless (@$target) {
387                                 my @values = Git::config(@repo, "$prefix.$setting");
388                                 @$target = @values if (@values && defined $values[0]);
389                         }
390                 }
391                 else {
392                         $$target = Git::config(@repo, "$prefix.$setting") unless (defined $$target);
393                 }
394         }
395
396         if (!defined $smtp_encryption) {
397                 my $enc = Git::config(@repo, "$prefix.smtpencryption");
398                 if (defined $enc) {
399                         $smtp_encryption = $enc;
400                 } elsif (Git::config_bool(@repo, "$prefix.smtpssl")) {
401                         $smtp_encryption = 'ssl';
402                 }
403         }
404 }
405
406 # read configuration from [sendemail "$identity"], fall back on [sendemail]
407 $identity = Git::config(@repo, "sendemail.identity") unless (defined $identity);
408 read_config("sendemail.$identity") if (defined $identity);
409 read_config("sendemail");
410
411 # fall back on builtin bool defaults
412 foreach my $setting (values %config_bool_settings) {
413         ${$setting->[0]} = $setting->[1] unless (defined (${$setting->[0]}));
414 }
415
416 # 'default' encryption is none -- this only prevents a warning
417 $smtp_encryption = '' unless (defined $smtp_encryption);
418
419 # Set CC suppressions
420 my(%suppress_cc);
421 if (@suppress_cc) {
422         foreach my $entry (@suppress_cc) {
423                 die "Unknown --suppress-cc field: '$entry'\n"
424                         unless $entry =~ /^(?:all|cccmd|cc|author|self|sob|body|bodycc)$/;
425                 $suppress_cc{$entry} = 1;
426         }
427 }
428
429 if ($suppress_cc{'all'}) {
430         foreach my $entry (qw (cccmd cc author self sob body bodycc)) {
431                 $suppress_cc{$entry} = 1;
432         }
433         delete $suppress_cc{'all'};
434 }
435
436 # If explicit old-style ones are specified, they trump --suppress-cc.
437 $suppress_cc{'self'} = $suppress_from if defined $suppress_from;
438 $suppress_cc{'sob'} = !$signed_off_by_cc if defined $signed_off_by_cc;
439
440 if ($suppress_cc{'body'}) {
441         foreach my $entry (qw (sob bodycc)) {
442                 $suppress_cc{$entry} = 1;
443         }
444         delete $suppress_cc{'body'};
445 }
446
447 # Set confirm's default value
448 my $confirm_unconfigured = !defined $confirm;
449 if ($confirm_unconfigured) {
450         $confirm = scalar %suppress_cc ? 'compose' : 'auto';
451 };
452 die "Unknown --confirm setting: '$confirm'\n"
453         unless $confirm =~ /^(?:auto|cc|compose|always|never)/;
454
455 # Debugging, print out the suppressions.
456 if (0) {
457         print "suppressions:\n";
458         foreach my $entry (keys %suppress_cc) {
459                 printf "  %-5s -> $suppress_cc{$entry}\n", $entry;
460         }
461 }
462
463 my ($repoauthor, $repocommitter);
464 ($repoauthor) = Git::ident_person(@repo, 'author');
465 ($repocommitter) = Git::ident_person(@repo, 'committer');
466
467 # Verify the user input
468
469 foreach my $entry (@initial_to) {
470         die "Comma in --to entry: $entry'\n" unless $entry !~ m/,/;
471 }
472
473 foreach my $entry (@initial_cc) {
474         die "Comma in --cc entry: $entry'\n" unless $entry !~ m/,/;
475 }
476
477 foreach my $entry (@bcclist) {
478         die "Comma in --bcclist entry: $entry'\n" unless $entry !~ m/,/;
479 }
480
481 sub parse_address_line {
482         if ($have_mail_address) {
483                 return map { $_->format } Mail::Address->parse($_[0]);
484         } else {
485                 return split_addrs($_[0]);
486         }
487 }
488
489 sub split_addrs {
490         return quotewords('\s*,\s*', 1, @_);
491 }
492
493 my %aliases;
494
495 sub parse_sendmail_alias {
496         local $_ = shift;
497         if (/"/) {
498                 print STDERR "warning: sendmail alias with quotes is not supported: $_\n";
499         } elsif (/:include:/) {
500                 print STDERR "warning: `:include:` not supported: $_\n";
501         } elsif (/[\/|]/) {
502                 print STDERR "warning: `/file` or `|pipe` redirection not supported: $_\n";
503         } elsif (/^(\S+?)\s*:\s*(.+)$/) {
504                 my ($alias, $addr) = ($1, $2);
505                 $aliases{$alias} = [ split_addrs($addr) ];
506         } else {
507                 print STDERR "warning: sendmail line is not recognized: $_\n";
508         }
509 }
510
511 sub parse_sendmail_aliases {
512         my $fh = shift;
513         my $s = '';
514         while (<$fh>) {
515                 chomp;
516                 next if /^\s*$/ || /^\s*#/;
517                 $s .= $_, next if $s =~ s/\\$// || s/^\s+//;
518                 parse_sendmail_alias($s) if $s;
519                 $s = $_;
520         }
521         $s =~ s/\\$//; # silently tolerate stray '\' on last line
522         parse_sendmail_alias($s) if $s;
523 }
524
525 my %parse_alias = (
526         # multiline formats can be supported in the future
527         mutt => sub { my $fh = shift; while (<$fh>) {
528                 if (/^\s*alias\s+(?:-group\s+\S+\s+)*(\S+)\s+(.*)$/) {
529                         my ($alias, $addr) = ($1, $2);
530                         $addr =~ s/#.*$//; # mutt allows # comments
531                          # commas delimit multiple addresses
532                         $aliases{$alias} = [ split_addrs($addr) ];
533                 }}},
534         mailrc => sub { my $fh = shift; while (<$fh>) {
535                 if (/^alias\s+(\S+)\s+(.*)$/) {
536                         # spaces delimit multiple addresses
537                         $aliases{$1} = [ quotewords('\s+', 0, $2) ];
538                 }}},
539         pine => sub { my $fh = shift; my $f='\t[^\t]*';
540                 for (my $x = ''; defined($x); $x = $_) {
541                         chomp $x;
542                         $x .= $1 while(defined($_ = <$fh>) && /^ +(.*)$/);
543                         $x =~ /^(\S+)$f\t\(?([^\t]+?)\)?(:?$f){0,2}$/ or next;
544                         $aliases{$1} = [ split_addrs($2) ];
545                 }},
546         elm => sub  { my $fh = shift;
547                       while (<$fh>) {
548                           if (/^(\S+)\s+=\s+[^=]+=\s(\S+)/) {
549                               my ($alias, $addr) = ($1, $2);
550                                $aliases{$alias} = [ split_addrs($addr) ];
551                           }
552                       } },
553         sendmail => \&parse_sendmail_aliases,
554         gnus => sub { my $fh = shift; while (<$fh>) {
555                 if (/\(define-mail-alias\s+"(\S+?)"\s+"(\S+?)"\)/) {
556                         $aliases{$1} = [ $2 ];
557                 }}}
558 );
559
560 if (@alias_files and $aliasfiletype and defined $parse_alias{$aliasfiletype}) {
561         foreach my $file (@alias_files) {
562                 open my $fh, '<', $file or die "opening $file: $!\n";
563                 $parse_alias{$aliasfiletype}->($fh);
564                 close $fh;
565         }
566 }
567
568 ($sender) = expand_aliases($sender) if defined $sender;
569
570 # is_format_patch_arg($f) returns 0 if $f names a patch, or 1 if
571 # $f is a revision list specification to be passed to format-patch.
572 sub is_format_patch_arg {
573         return unless $repo;
574         my $f = shift;
575         try {
576                 $repo->command('rev-parse', '--verify', '--quiet', $f);
577                 if (defined($format_patch)) {
578                         return $format_patch;
579                 }
580                 die(<<EOF);
581 File '$f' exists but it could also be the range of commits
582 to produce patches for.  Please disambiguate by...
583
584     * Saying "./$f" if you mean a file; or
585     * Giving --format-patch option if you mean a range.
586 EOF
587         } catch Git::Error::Command with {
588                 # Not a valid revision.  Treat it as a filename.
589                 return 0;
590         }
591 }
592
593 # Now that all the defaults are set, process the rest of the command line
594 # arguments and collect up the files that need to be processed.
595 my @rev_list_opts;
596 while (defined(my $f = shift @ARGV)) {
597         if ($f eq "--") {
598                 push @rev_list_opts, "--", @ARGV;
599                 @ARGV = ();
600         } elsif (-d $f and !is_format_patch_arg($f)) {
601                 opendir my $dh, $f
602                         or die "Failed to opendir $f: $!";
603
604                 push @files, grep { -f $_ } map { catfile($f, $_) }
605                                 sort readdir $dh;
606                 closedir $dh;
607         } elsif ((-f $f or -p $f) and !is_format_patch_arg($f)) {
608                 push @files, $f;
609         } else {
610                 push @rev_list_opts, $f;
611         }
612 }
613
614 if (@rev_list_opts) {
615         die "Cannot run git format-patch from outside a repository\n"
616                 unless $repo;
617         push @files, $repo->command('format-patch', '-o', tempdir(CLEANUP => 1), @rev_list_opts);
618 }
619
620 if ($validate) {
621         foreach my $f (@files) {
622                 unless (-p $f) {
623                         my $error = validate_patch($f);
624                         $error and die "fatal: $f: $error\nwarning: no patches were sent\n";
625                 }
626         }
627 }
628
629 if (@files) {
630         unless ($quiet) {
631                 print $_,"\n" for (@files);
632         }
633 } else {
634         print STDERR "\nNo patch files specified!\n\n";
635         usage();
636 }
637
638 sub get_patch_subject {
639         my $fn = shift;
640         open (my $fh, '<', $fn);
641         while (my $line = <$fh>) {
642                 next unless ($line =~ /^Subject: (.*)$/);
643                 close $fh;
644                 return "GIT: $1\n";
645         }
646         close $fh;
647         die "No subject line in $fn ?";
648 }
649
650 if ($compose) {
651         # Note that this does not need to be secure, but we will make a small
652         # effort to have it be unique
653         $compose_filename = ($repo ?
654                 tempfile(".gitsendemail.msg.XXXXXX", DIR => $repo->repo_path()) :
655                 tempfile(".gitsendemail.msg.XXXXXX", DIR => "."))[1];
656         open my $c, ">", $compose_filename
657                 or die "Failed to open for writing $compose_filename: $!";
658
659
660         my $tpl_sender = $sender || $repoauthor || $repocommitter || '';
661         my $tpl_subject = $initial_subject || '';
662         my $tpl_reply_to = $initial_reply_to || '';
663
664         print $c <<EOT;
665 From $tpl_sender # This line is ignored.
666 GIT: Lines beginning in "GIT:" will be removed.
667 GIT: Consider including an overall diffstat or table of contents
668 GIT: for the patch you are writing.
669 GIT:
670 GIT: Clear the body content if you don't wish to send a summary.
671 From: $tpl_sender
672 Subject: $tpl_subject
673 In-Reply-To: $tpl_reply_to
674
675 EOT
676         for my $f (@files) {
677                 print $c get_patch_subject($f);
678         }
679         close $c;
680
681         if ($annotate) {
682                 do_edit($compose_filename, @files);
683         } else {
684                 do_edit($compose_filename);
685         }
686
687         open my $c2, ">", $compose_filename . ".final"
688                 or die "Failed to open $compose_filename.final : " . $!;
689
690         open $c, "<", $compose_filename
691                 or die "Failed to open $compose_filename : " . $!;
692
693         my $need_8bit_cte = file_has_nonascii($compose_filename);
694         my $in_body = 0;
695         my $summary_empty = 1;
696         if (!defined $compose_encoding) {
697                 $compose_encoding = "UTF-8";
698         }
699         while(<$c>) {
700                 next if m/^GIT:/;
701                 if ($in_body) {
702                         $summary_empty = 0 unless (/^\n$/);
703                 } elsif (/^\n$/) {
704                         $in_body = 1;
705                         if ($need_8bit_cte) {
706                                 print $c2 "MIME-Version: 1.0\n",
707                                          "Content-Type: text/plain; ",
708                                            "charset=$compose_encoding\n",
709                                          "Content-Transfer-Encoding: 8bit\n";
710                         }
711                 } elsif (/^MIME-Version:/i) {
712                         $need_8bit_cte = 0;
713                 } elsif (/^Subject:\s*(.+)\s*$/i) {
714                         $initial_subject = $1;
715                         my $subject = $initial_subject;
716                         $_ = "Subject: " .
717                                 quote_subject($subject, $compose_encoding) .
718                                 "\n";
719                 } elsif (/^In-Reply-To:\s*(.+)\s*$/i) {
720                         $initial_reply_to = $1;
721                         next;
722                 } elsif (/^From:\s*(.+)\s*$/i) {
723                         $sender = $1;
724                         next;
725                 } elsif (/^(?:To|Cc|Bcc):/i) {
726                         print "To/Cc/Bcc fields are not interpreted yet, they have been ignored\n";
727                         next;
728                 }
729                 print $c2 $_;
730         }
731         close $c;
732         close $c2;
733
734         if ($summary_empty) {
735                 print "Summary email is empty, skipping it\n";
736                 $compose = -1;
737         }
738 } elsif ($annotate) {
739         do_edit(@files);
740 }
741
742 sub ask {
743         my ($prompt, %arg) = @_;
744         my $valid_re = $arg{valid_re};
745         my $default = $arg{default};
746         my $confirm_only = $arg{confirm_only};
747         my $resp;
748         my $i = 0;
749         return defined $default ? $default : undef
750                 unless defined $term->IN and defined fileno($term->IN) and
751                        defined $term->OUT and defined fileno($term->OUT);
752         while ($i++ < 10) {
753                 $resp = $term->readline($prompt);
754                 if (!defined $resp) { # EOF
755                         print "\n";
756                         return defined $default ? $default : undef;
757                 }
758                 if ($resp eq '' and defined $default) {
759                         return $default;
760                 }
761                 if (!defined $valid_re or $resp =~ /$valid_re/) {
762                         return $resp;
763                 }
764                 if ($confirm_only) {
765                         my $yesno = $term->readline("Are you sure you want to use <$resp> [y/N]? ");
766                         if (defined $yesno && $yesno =~ /y/i) {
767                                 return $resp;
768                         }
769                 }
770         }
771         return;
772 }
773
774 my %broken_encoding;
775
776 sub file_declares_8bit_cte {
777         my $fn = shift;
778         open (my $fh, '<', $fn);
779         while (my $line = <$fh>) {
780                 last if ($line =~ /^$/);
781                 return 1 if ($line =~ /^Content-Transfer-Encoding: .*8bit.*$/);
782         }
783         close $fh;
784         return 0;
785 }
786
787 foreach my $f (@files) {
788         next unless (body_or_subject_has_nonascii($f)
789                      && !file_declares_8bit_cte($f));
790         $broken_encoding{$f} = 1;
791 }
792
793 if (!defined $auto_8bit_encoding && scalar %broken_encoding) {
794         print "The following files are 8bit, but do not declare " .
795                 "a Content-Transfer-Encoding.\n";
796         foreach my $f (sort keys %broken_encoding) {
797                 print "    $f\n";
798         }
799         $auto_8bit_encoding = ask("Which 8bit encoding should I declare [UTF-8]? ",
800                                   valid_re => qr/.{4}/, confirm_only => 1,
801                                   default => "UTF-8");
802 }
803
804 if (!$force) {
805         for my $f (@files) {
806                 if (get_patch_subject($f) =~ /\Q*** SUBJECT HERE ***\E/) {
807                         die "Refusing to send because the patch\n\t$f\n"
808                                 . "has the template subject '*** SUBJECT HERE ***'. "
809                                 . "Pass --force if you really want to send.\n";
810                 }
811         }
812 }
813
814 if (!defined $sender) {
815         $sender = $repoauthor || $repocommitter || '';
816 }
817
818 # $sender could be an already sanitized address
819 # (e.g. sendemail.from could be manually sanitized by user).
820 # But it's a no-op to run sanitize_address on an already sanitized address.
821 $sender = sanitize_address($sender);
822
823 my $prompting = 0;
824 if (!@initial_to && !defined $to_cmd) {
825         my $to = ask("Who should the emails be sent to (if any)? ",
826                      default => "",
827                      valid_re => qr/\@.*\./, confirm_only => 1);
828         push @initial_to, parse_address_line($to) if defined $to; # sanitized/validated later
829         $prompting++;
830 }
831
832 sub expand_aliases {
833         return map { expand_one_alias($_) } @_;
834 }
835
836 my %EXPANDED_ALIASES;
837 sub expand_one_alias {
838         my $alias = shift;
839         if ($EXPANDED_ALIASES{$alias}) {
840                 die "fatal: alias '$alias' expands to itself\n";
841         }
842         local $EXPANDED_ALIASES{$alias} = 1;
843         return $aliases{$alias} ? expand_aliases(@{$aliases{$alias}}) : $alias;
844 }
845
846 @initial_to = expand_aliases(@initial_to);
847 @initial_to = validate_address_list(sanitize_address_list(@initial_to));
848 @initial_cc = expand_aliases(@initial_cc);
849 @initial_cc = validate_address_list(sanitize_address_list(@initial_cc));
850 @bcclist = expand_aliases(@bcclist);
851 @bcclist = validate_address_list(sanitize_address_list(@bcclist));
852
853 if ($thread && !defined $initial_reply_to && $prompting) {
854         $initial_reply_to = ask(
855                 "Message-ID to be used as In-Reply-To for the first email (if any)? ",
856                 default => "",
857                 valid_re => qr/\@.*\./, confirm_only => 1);
858 }
859 if (defined $initial_reply_to) {
860         $initial_reply_to =~ s/^\s*<?//;
861         $initial_reply_to =~ s/>?\s*$//;
862         $initial_reply_to = "<$initial_reply_to>" if $initial_reply_to ne '';
863 }
864
865 if (!defined $smtp_server) {
866         foreach (qw( /usr/sbin/sendmail /usr/lib/sendmail )) {
867                 if (-x $_) {
868                         $smtp_server = $_;
869                         last;
870                 }
871         }
872         $smtp_server ||= 'localhost'; # could be 127.0.0.1, too... *shrug*
873 }
874
875 if ($compose && $compose > 0) {
876         @files = ($compose_filename . ".final", @files);
877 }
878
879 # Variables we set as part of the loop over files
880 our ($message_id, %mail, $subject, $reply_to, $references, $message,
881         $needs_confirm, $message_num, $ask_default);
882
883 sub extract_valid_address {
884         my $address = shift;
885         my $local_part_regexp = qr/[^<>"\s@]+/;
886         my $domain_regexp = qr/[^.<>"\s@]+(?:\.[^.<>"\s@]+)+/;
887
888         # check for a local address:
889         return $address if ($address =~ /^($local_part_regexp)$/);
890
891         $address =~ s/^\s*<(.*)>\s*$/$1/;
892         if ($have_email_valid) {
893                 return scalar Email::Valid->address($address);
894         }
895
896         # less robust/correct than the monster regexp in Email::Valid,
897         # but still does a 99% job, and one less dependency
898         return $1 if $address =~ /($local_part_regexp\@$domain_regexp)/;
899         return;
900 }
901
902 sub extract_valid_address_or_die {
903         my $address = shift;
904         $address = extract_valid_address($address);
905         die "error: unable to extract a valid address from: $address\n"
906                 if !$address;
907         return $address;
908 }
909
910 sub validate_address {
911         my $address = shift;
912         while (!extract_valid_address($address)) {
913                 print STDERR "error: unable to extract a valid address from: $address\n";
914                 $_ = ask("What to do with this address? ([q]uit|[d]rop|[e]dit): ",
915                         valid_re => qr/^(?:quit|q|drop|d|edit|e)/i,
916                         default => 'q');
917                 if (/^d/i) {
918                         return undef;
919                 } elsif (/^q/i) {
920                         cleanup_compose_files();
921                         exit(0);
922                 }
923                 $address = ask("Who should the email be sent to (if any)? ",
924                         default => "",
925                         valid_re => qr/\@.*\./, confirm_only => 1);
926         }
927         return $address;
928 }
929
930 sub validate_address_list {
931         return (grep { defined $_ }
932                 map { validate_address($_) } @_);
933 }
934
935 # Usually don't need to change anything below here.
936
937 # we make a "fake" message id by taking the current number
938 # of seconds since the beginning of Unix time and tacking on
939 # a random number to the end, in case we are called quicker than
940 # 1 second since the last time we were called.
941
942 # We'll setup a template for the message id, using the "from" address:
943
944 my ($message_id_stamp, $message_id_serial);
945 sub make_message_id {
946         my $uniq;
947         if (!defined $message_id_stamp) {
948                 $message_id_stamp = sprintf("%s-%s", time, $$);
949                 $message_id_serial = 0;
950         }
951         $message_id_serial++;
952         $uniq = "$message_id_stamp-$message_id_serial";
953
954         my $du_part;
955         for ($sender, $repocommitter, $repoauthor) {
956                 $du_part = extract_valid_address(sanitize_address($_));
957                 last if (defined $du_part and $du_part ne '');
958         }
959         if (not defined $du_part or $du_part eq '') {
960                 require Sys::Hostname;
961                 $du_part = 'user@' . Sys::Hostname::hostname();
962         }
963         my $message_id_template = "<%s-git-send-email-%s>";
964         $message_id = sprintf($message_id_template, $uniq, $du_part);
965         #print "new message id = $message_id\n"; # Was useful for debugging
966 }
967
968
969
970 $time = time - scalar $#files;
971
972 sub unquote_rfc2047 {
973         local ($_) = @_;
974         my $charset;
975         my $sep = qr/[ \t]+/;
976         s{$re_encoded_word(?:$sep$re_encoded_word)*}{
977                 my @words = split $sep, $&;
978                 foreach (@words) {
979                         m/$re_encoded_word/;
980                         $charset = $1;
981                         my $encoding = $2;
982                         my $text = $3;
983                         if ($encoding eq 'q' || $encoding eq 'Q') {
984                                 $_ = $text;
985                                 s/_/ /g;
986                                 s/=([0-9A-F]{2})/chr(hex($1))/egi;
987                         } else {
988                                 # other encodings not supported yet
989                         }
990                 }
991                 join '', @words;
992         }eg;
993         return wantarray ? ($_, $charset) : $_;
994 }
995
996 sub quote_rfc2047 {
997         local $_ = shift;
998         my $encoding = shift || 'UTF-8';
999         s/([^-a-zA-Z0-9!*+\/])/sprintf("=%02X", ord($1))/eg;
1000         s/(.*)/=\?$encoding\?q\?$1\?=/;
1001         return $_;
1002 }
1003
1004 sub is_rfc2047_quoted {
1005         my $s = shift;
1006         length($s) <= 75 &&
1007         $s =~ m/^(?:"[[:ascii:]]*"|$re_encoded_word)$/o;
1008 }
1009
1010 sub subject_needs_rfc2047_quoting {
1011         my $s = shift;
1012
1013         return ($s =~ /[^[:ascii:]]/) || ($s =~ /=\?/);
1014 }
1015
1016 sub quote_subject {
1017         local $subject = shift;
1018         my $encoding = shift || 'UTF-8';
1019
1020         if (subject_needs_rfc2047_quoting($subject)) {
1021                 return quote_rfc2047($subject, $encoding);
1022         }
1023         return $subject;
1024 }
1025
1026 # use the simplest quoting being able to handle the recipient
1027 sub sanitize_address {
1028         my ($recipient) = @_;
1029
1030         # remove garbage after email address
1031         $recipient =~ s/(.*>).*$/$1/;
1032
1033         my ($recipient_name, $recipient_addr) = ($recipient =~ /^(.*?)\s*(<.*)/);
1034
1035         if (not $recipient_name) {
1036                 return $recipient;
1037         }
1038
1039         # if recipient_name is already quoted, do nothing
1040         if (is_rfc2047_quoted($recipient_name)) {
1041                 return $recipient;
1042         }
1043
1044         # rfc2047 is needed if a non-ascii char is included
1045         if ($recipient_name =~ /[^[:ascii:]]/) {
1046                 $recipient_name =~ s/^"(.*)"$/$1/;
1047                 $recipient_name = quote_rfc2047($recipient_name);
1048         }
1049
1050         # double quotes are needed if specials or CTLs are included
1051         elsif ($recipient_name =~ /[][()<>@,;:\\".\000-\037\177]/) {
1052                 $recipient_name =~ s/(["\\\r])/\\$1/g;
1053                 $recipient_name = qq["$recipient_name"];
1054         }
1055
1056         return "$recipient_name $recipient_addr";
1057
1058 }
1059
1060 sub sanitize_address_list {
1061         return (map { sanitize_address($_) } @_);
1062 }
1063
1064 # Returns the local Fully Qualified Domain Name (FQDN) if available.
1065 #
1066 # Tightly configured MTAa require that a caller sends a real DNS
1067 # domain name that corresponds the IP address in the HELO/EHLO
1068 # handshake. This is used to verify the connection and prevent
1069 # spammers from trying to hide their identity. If the DNS and IP don't
1070 # match, the receiveing MTA may deny the connection.
1071 #
1072 # Here is a deny example of Net::SMTP with the default "localhost.localdomain"
1073 #
1074 # Net::SMTP=GLOB(0x267ec28)>>> EHLO localhost.localdomain
1075 # Net::SMTP=GLOB(0x267ec28)<<< 550 EHLO argument does not match calling host
1076 #
1077 # This maildomain*() code is based on ideas in Perl library Test::Reporter
1078 # /usr/share/perl5/Test/Reporter/Mail/Util.pm ==> sub _maildomain ()
1079
1080 sub valid_fqdn {
1081         my $domain = shift;
1082         return defined $domain && !($^O eq 'darwin' && $domain =~ /\.local$/) && $domain =~ /\./;
1083 }
1084
1085 sub maildomain_net {
1086         my $maildomain;
1087
1088         if (eval { require Net::Domain; 1 }) {
1089                 my $domain = Net::Domain::domainname();
1090                 $maildomain = $domain if valid_fqdn($domain);
1091         }
1092
1093         return $maildomain;
1094 }
1095
1096 sub maildomain_mta {
1097         my $maildomain;
1098
1099         if (eval { require Net::SMTP; 1 }) {
1100                 for my $host (qw(mailhost localhost)) {
1101                         my $smtp = Net::SMTP->new($host);
1102                         if (defined $smtp) {
1103                                 my $domain = $smtp->domain;
1104                                 $smtp->quit;
1105
1106                                 $maildomain = $domain if valid_fqdn($domain);
1107
1108                                 last if $maildomain;
1109                         }
1110                 }
1111         }
1112
1113         return $maildomain;
1114 }
1115
1116 sub maildomain {
1117         return maildomain_net() || maildomain_mta() || 'localhost.localdomain';
1118 }
1119
1120 sub smtp_host_string {
1121         if (defined $smtp_server_port) {
1122                 return "$smtp_server:$smtp_server_port";
1123         } else {
1124                 return $smtp_server;
1125         }
1126 }
1127
1128 # Returns 1 if authentication succeeded or was not necessary
1129 # (smtp_user was not specified), and 0 otherwise.
1130
1131 sub smtp_auth_maybe {
1132         if (!defined $smtp_authuser || $auth) {
1133                 return 1;
1134         }
1135
1136         # Workaround AUTH PLAIN/LOGIN interaction defect
1137         # with Authen::SASL::Cyrus
1138         eval {
1139                 require Authen::SASL;
1140                 Authen::SASL->import(qw(Perl));
1141         };
1142
1143         # Check mechanism naming as defined in:
1144         # https://tools.ietf.org/html/rfc4422#page-8
1145         if ($smtp_auth !~ /^(\b[A-Z0-9-_]{1,20}\s*)*$/) {
1146                 die "invalid smtp auth: '${smtp_auth}'";
1147         }
1148
1149         # TODO: Authentication may fail not because credentials were
1150         # invalid but due to other reasons, in which we should not
1151         # reject credentials.
1152         $auth = Git::credential({
1153                 'protocol' => 'smtp',
1154                 'host' => smtp_host_string(),
1155                 'username' => $smtp_authuser,
1156                 # if there's no password, "git credential fill" will
1157                 # give us one, otherwise it'll just pass this one.
1158                 'password' => $smtp_authpass
1159         }, sub {
1160                 my $cred = shift;
1161
1162                 if ($smtp_auth) {
1163                         my $sasl = Authen::SASL->new(
1164                                 mechanism => $smtp_auth,
1165                                 callback => {
1166                                         user => $cred->{'username'},
1167                                         pass => $cred->{'password'},
1168                                         authname => $cred->{'username'},
1169                                 }
1170                         );
1171
1172                         return !!$smtp->auth($sasl);
1173                 }
1174
1175                 return !!$smtp->auth($cred->{'username'}, $cred->{'password'});
1176         });
1177
1178         return $auth;
1179 }
1180
1181 sub ssl_verify_params {
1182         eval {
1183                 require IO::Socket::SSL;
1184                 IO::Socket::SSL->import(qw/SSL_VERIFY_PEER SSL_VERIFY_NONE/);
1185         };
1186         if ($@) {
1187                 print STDERR "Not using SSL_VERIFY_PEER due to out-of-date IO::Socket::SSL.\n";
1188                 return;
1189         }
1190
1191         if (!defined $smtp_ssl_cert_path) {
1192                 # use the OpenSSL defaults
1193                 return (SSL_verify_mode => SSL_VERIFY_PEER());
1194         }
1195
1196         if ($smtp_ssl_cert_path eq "") {
1197                 return (SSL_verify_mode => SSL_VERIFY_NONE());
1198         } elsif (-d $smtp_ssl_cert_path) {
1199                 return (SSL_verify_mode => SSL_VERIFY_PEER(),
1200                         SSL_ca_path => $smtp_ssl_cert_path);
1201         } elsif (-f $smtp_ssl_cert_path) {
1202                 return (SSL_verify_mode => SSL_VERIFY_PEER(),
1203                         SSL_ca_file => $smtp_ssl_cert_path);
1204         } else {
1205                 print STDERR "Not using SSL_VERIFY_PEER because the CA path does not exist.\n";
1206                 return (SSL_verify_mode => SSL_VERIFY_NONE());
1207         }
1208 }
1209
1210 sub file_name_is_absolute {
1211         my ($path) = @_;
1212
1213         # msys does not grok DOS drive-prefixes
1214         if ($^O eq 'msys') {
1215                 return ($path =~ m#^/# || $path =~ m#^[a-zA-Z]\:#)
1216         }
1217
1218         require File::Spec::Functions;
1219         return File::Spec::Functions::file_name_is_absolute($path);
1220 }
1221
1222 # Returns 1 if the message was sent, and 0 otherwise.
1223 # In actuality, the whole program dies when there
1224 # is an error sending a message.
1225
1226 sub send_message {
1227         my @recipients = unique_email_list(@to);
1228         @cc = (grep { my $cc = extract_valid_address_or_die($_);
1229                       not grep { $cc eq $_ || $_ =~ /<\Q${cc}\E>$/ } @recipients
1230                     }
1231                @cc);
1232         my $to = join (",\n\t", @recipients);
1233         @recipients = unique_email_list(@recipients,@cc,@bcclist);
1234         @recipients = (map { extract_valid_address_or_die($_) } @recipients);
1235         my $date = format_2822_time($time++);
1236         my $gitversion = '@@GIT_VERSION@@';
1237         if ($gitversion =~ m/..GIT_VERSION../) {
1238             $gitversion = Git::version();
1239         }
1240
1241         my $cc = join(",\n\t", unique_email_list(@cc));
1242         my $ccline = "";
1243         if ($cc ne '') {
1244                 $ccline = "\nCc: $cc";
1245         }
1246         make_message_id() unless defined($message_id);
1247
1248         my $header = "From: $sender
1249 To: $to${ccline}
1250 Subject: $subject
1251 Date: $date
1252 Message-Id: $message_id
1253 ";
1254         if ($use_xmailer) {
1255                 $header .= "X-Mailer: git-send-email $gitversion\n";
1256         }
1257         if ($reply_to) {
1258
1259                 $header .= "In-Reply-To: $reply_to\n";
1260                 $header .= "References: $references\n";
1261         }
1262         if (@xh) {
1263                 $header .= join("\n", @xh) . "\n";
1264         }
1265
1266         my @sendmail_parameters = ('-i', @recipients);
1267         my $raw_from = $sender;
1268         if (defined $envelope_sender && $envelope_sender ne "auto") {
1269                 $raw_from = $envelope_sender;
1270         }
1271         $raw_from = extract_valid_address($raw_from);
1272         unshift (@sendmail_parameters,
1273                         '-f', $raw_from) if(defined $envelope_sender);
1274
1275         if ($needs_confirm && !$dry_run) {
1276                 print "\n$header\n";
1277                 if ($needs_confirm eq "inform") {
1278                         $confirm_unconfigured = 0; # squelch this message for the rest of this run
1279                         $ask_default = "y"; # assume yes on EOF since user hasn't explicitly asked for confirmation
1280                         print "    The Cc list above has been expanded by additional\n";
1281                         print "    addresses found in the patch commit message. By default\n";
1282                         print "    send-email prompts before sending whenever this occurs.\n";
1283                         print "    This behavior is controlled by the sendemail.confirm\n";
1284                         print "    configuration setting.\n";
1285                         print "\n";
1286                         print "    For additional information, run 'git send-email --help'.\n";
1287                         print "    To retain the current behavior, but squelch this message,\n";
1288                         print "    run 'git config --global sendemail.confirm auto'.\n\n";
1289                 }
1290                 $_ = ask("Send this email? ([y]es|[n]o|[q]uit|[a]ll): ",
1291                          valid_re => qr/^(?:yes|y|no|n|quit|q|all|a)/i,
1292                          default => $ask_default);
1293                 die "Send this email reply required" unless defined $_;
1294                 if (/^n/i) {
1295                         return 0;
1296                 } elsif (/^q/i) {
1297                         cleanup_compose_files();
1298                         exit(0);
1299                 } elsif (/^a/i) {
1300                         $confirm = 'never';
1301                 }
1302         }
1303
1304         unshift (@sendmail_parameters, @smtp_server_options);
1305
1306         if ($dry_run) {
1307                 # We don't want to send the email.
1308         } elsif (file_name_is_absolute($smtp_server)) {
1309                 my $pid = open my $sm, '|-';
1310                 defined $pid or die $!;
1311                 if (!$pid) {
1312                         exec($smtp_server, @sendmail_parameters) or die $!;
1313                 }
1314                 print $sm "$header\n$message";
1315                 close $sm or die $!;
1316         } else {
1317
1318                 if (!defined $smtp_server) {
1319                         die "The required SMTP server is not properly defined."
1320                 }
1321
1322                 if ($smtp_encryption eq 'ssl') {
1323                         $smtp_server_port ||= 465; # ssmtp
1324                         require Net::SMTP::SSL;
1325                         $smtp_domain ||= maildomain();
1326                         require IO::Socket::SSL;
1327                         # Net::SMTP::SSL->new() does not forward any SSL options
1328                         IO::Socket::SSL::set_client_defaults(
1329                                 ssl_verify_params());
1330                         $smtp ||= Net::SMTP::SSL->new($smtp_server,
1331                                                       Hello => $smtp_domain,
1332                                                       Port => $smtp_server_port,
1333                                                       Debug => $debug_net_smtp);
1334                 }
1335                 else {
1336                         require Net::SMTP;
1337                         $smtp_domain ||= maildomain();
1338                         $smtp_server_port ||= 25;
1339                         $smtp ||= Net::SMTP->new($smtp_server,
1340                                                  Hello => $smtp_domain,
1341                                                  Debug => $debug_net_smtp,
1342                                                  Port => $smtp_server_port);
1343                         if ($smtp_encryption eq 'tls' && $smtp) {
1344                                 require Net::SMTP::SSL;
1345                                 $smtp->command('STARTTLS');
1346                                 $smtp->response();
1347                                 if ($smtp->code == 220) {
1348                                         $smtp = Net::SMTP::SSL->start_SSL($smtp,
1349                                                                           ssl_verify_params())
1350                                                 or die "STARTTLS failed! ".IO::Socket::SSL::errstr();
1351                                         $smtp_encryption = '';
1352                                         # Send EHLO again to receive fresh
1353                                         # supported commands
1354                                         $smtp->hello($smtp_domain);
1355                                 } else {
1356                                         die "Server does not support STARTTLS! ".$smtp->message;
1357                                 }
1358                         }
1359                 }
1360
1361                 if (!$smtp) {
1362                         die "Unable to initialize SMTP properly. Check config and use --smtp-debug. ",
1363                             "VALUES: server=$smtp_server ",
1364                             "encryption=$smtp_encryption ",
1365                             "hello=$smtp_domain",
1366                             defined $smtp_server_port ? " port=$smtp_server_port" : "";
1367                 }
1368
1369                 smtp_auth_maybe or die $smtp->message;
1370
1371                 $smtp->mail( $raw_from ) or die $smtp->message;
1372                 $smtp->to( @recipients ) or die $smtp->message;
1373                 $smtp->data or die $smtp->message;
1374                 $smtp->datasend("$header\n$message") or die $smtp->message;
1375                 $smtp->dataend() or die $smtp->message;
1376                 $smtp->code =~ /250|200/ or die "Failed to send $subject\n".$smtp->message;
1377         }
1378         if ($quiet) {
1379                 printf (($dry_run ? "Dry-" : "")."Sent %s\n", $subject);
1380         } else {
1381                 print (($dry_run ? "Dry-" : "")."OK. Log says:\n");
1382                 if (!file_name_is_absolute($smtp_server)) {
1383                         print "Server: $smtp_server\n";
1384                         print "MAIL FROM:<$raw_from>\n";
1385                         foreach my $entry (@recipients) {
1386                             print "RCPT TO:<$entry>\n";
1387                         }
1388                 } else {
1389                         print "Sendmail: $smtp_server ".join(' ',@sendmail_parameters)."\n";
1390                 }
1391                 print $header, "\n";
1392                 if ($smtp) {
1393                         print "Result: ", $smtp->code, ' ',
1394                                 ($smtp->message =~ /\n([^\n]+\n)$/s), "\n";
1395                 } else {
1396                         print "Result: OK\n";
1397                 }
1398         }
1399
1400         return 1;
1401 }
1402
1403 $reply_to = $initial_reply_to;
1404 $references = $initial_reply_to || '';
1405 $subject = $initial_subject;
1406 $message_num = 0;
1407
1408 foreach my $t (@files) {
1409         open my $fh, "<", $t or die "can't open file $t";
1410
1411         my $author = undef;
1412         my $sauthor = undef;
1413         my $author_encoding;
1414         my $has_content_type;
1415         my $body_encoding;
1416         my $xfer_encoding;
1417         my $has_mime_version;
1418         @to = ();
1419         @cc = ();
1420         @xh = ();
1421         my $input_format = undef;
1422         my @header = ();
1423         $message = "";
1424         $message_num++;
1425         # First unfold multiline header fields
1426         while(<$fh>) {
1427                 last if /^\s*$/;
1428                 if (/^\s+\S/ and @header) {
1429                         chomp($header[$#header]);
1430                         s/^\s+/ /;
1431                         $header[$#header] .= $_;
1432             } else {
1433                         push(@header, $_);
1434                 }
1435         }
1436         # Now parse the header
1437         foreach(@header) {
1438                 if (/^From /) {
1439                         $input_format = 'mbox';
1440                         next;
1441                 }
1442                 chomp;
1443                 if (!defined $input_format && /^[-A-Za-z]+:\s/) {
1444                         $input_format = 'mbox';
1445                 }
1446
1447                 if (defined $input_format && $input_format eq 'mbox') {
1448                         if (/^Subject:\s+(.*)$/i) {
1449                                 $subject = $1;
1450                         }
1451                         elsif (/^From:\s+(.*)$/i) {
1452                                 ($author, $author_encoding) = unquote_rfc2047($1);
1453                                 $sauthor = sanitize_address($author);
1454                                 next if $suppress_cc{'author'};
1455                                 next if $suppress_cc{'self'} and $sauthor eq $sender;
1456                                 printf("(mbox) Adding cc: %s from line '%s'\n",
1457                                         $1, $_) unless $quiet;
1458                                 push @cc, $1;
1459                         }
1460                         elsif (/^To:\s+(.*)$/i) {
1461                                 foreach my $addr (parse_address_line($1)) {
1462                                         printf("(mbox) Adding to: %s from line '%s'\n",
1463                                                 $addr, $_) unless $quiet;
1464                                         push @to, $addr;
1465                                 }
1466                         }
1467                         elsif (/^Cc:\s+(.*)$/i) {
1468                                 foreach my $addr (parse_address_line($1)) {
1469                                         my $qaddr = unquote_rfc2047($addr);
1470                                         my $saddr = sanitize_address($qaddr);
1471                                         if ($saddr eq $sender) {
1472                                                 next if ($suppress_cc{'self'});
1473                                         } else {
1474                                                 next if ($suppress_cc{'cc'});
1475                                         }
1476                                         printf("(mbox) Adding cc: %s from line '%s'\n",
1477                                                 $addr, $_) unless $quiet;
1478                                         push @cc, $addr;
1479                                 }
1480                         }
1481                         elsif (/^Content-type:/i) {
1482                                 $has_content_type = 1;
1483                                 if (/charset="?([^ "]+)/) {
1484                                         $body_encoding = $1;
1485                                 }
1486                                 push @xh, $_;
1487                         }
1488                         elsif (/^MIME-Version/i) {
1489                                 $has_mime_version = 1;
1490                                 push @xh, $_;
1491                         }
1492                         elsif (/^Message-Id: (.*)/i) {
1493                                 $message_id = $1;
1494                         }
1495                         elsif (/^Content-Transfer-Encoding: (.*)/i) {
1496                                 $xfer_encoding = $1 if not defined $xfer_encoding;
1497                         }
1498                         elsif (!/^Date:\s/i && /^[-A-Za-z]+:\s+\S/) {
1499                                 push @xh, $_;
1500                         }
1501
1502                 } else {
1503                         # In the traditional
1504                         # "send lots of email" format,
1505                         # line 1 = cc
1506                         # line 2 = subject
1507                         # So let's support that, too.
1508                         $input_format = 'lots';
1509                         if (@cc == 0 && !$suppress_cc{'cc'}) {
1510                                 printf("(non-mbox) Adding cc: %s from line '%s'\n",
1511                                         $_, $_) unless $quiet;
1512                                 push @cc, $_;
1513                         } elsif (!defined $subject) {
1514                                 $subject = $_;
1515                         }
1516                 }
1517         }
1518         # Now parse the message body
1519         while(<$fh>) {
1520                 $message .=  $_;
1521                 if (/^(Signed-off-by|Cc): (.*)$/i) {
1522                         chomp;
1523                         my ($what, $c) = ($1, $2);
1524                         chomp $c;
1525                         my $sc = sanitize_address($c);
1526                         if ($sc eq $sender) {
1527                                 next if ($suppress_cc{'self'});
1528                         } else {
1529                                 next if $suppress_cc{'sob'} and $what =~ /Signed-off-by/i;
1530                                 next if $suppress_cc{'bodycc'} and $what =~ /Cc/i;
1531                         }
1532                         push @cc, $c;
1533                         printf("(body) Adding cc: %s from line '%s'\n",
1534                                 $c, $_) unless $quiet;
1535                 }
1536         }
1537         close $fh;
1538
1539         push @to, recipients_cmd("to-cmd", "to", $to_cmd, $t)
1540                 if defined $to_cmd;
1541         push @cc, recipients_cmd("cc-cmd", "cc", $cc_cmd, $t)
1542                 if defined $cc_cmd && !$suppress_cc{'cccmd'};
1543
1544         if ($broken_encoding{$t} && !$has_content_type) {
1545                 $xfer_encoding = '8bit' if not defined $xfer_encoding;
1546                 $has_content_type = 1;
1547                 push @xh, "Content-Type: text/plain; charset=$auto_8bit_encoding";
1548                 $body_encoding = $auto_8bit_encoding;
1549         }
1550
1551         if ($broken_encoding{$t} && !is_rfc2047_quoted($subject)) {
1552                 $subject = quote_subject($subject, $auto_8bit_encoding);
1553         }
1554
1555         if (defined $sauthor and $sauthor ne $sender) {
1556                 $message = "From: $author\n\n$message";
1557                 if (defined $author_encoding) {
1558                         if ($has_content_type) {
1559                                 if ($body_encoding eq $author_encoding) {
1560                                         # ok, we already have the right encoding
1561                                 }
1562                                 else {
1563                                         # uh oh, we should re-encode
1564                                 }
1565                         }
1566                         else {
1567                                 $xfer_encoding = '8bit' if not defined $xfer_encoding;
1568                                 $has_content_type = 1;
1569                                 push @xh,
1570                                   "Content-Type: text/plain; charset=$author_encoding";
1571                         }
1572                 }
1573         }
1574         if (defined $target_xfer_encoding) {
1575                 $xfer_encoding = '8bit' if not defined $xfer_encoding;
1576                 $message = apply_transfer_encoding(
1577                         $message, $xfer_encoding, $target_xfer_encoding);
1578                 $xfer_encoding = $target_xfer_encoding;
1579         }
1580         if (defined $xfer_encoding) {
1581                 push @xh, "Content-Transfer-Encoding: $xfer_encoding";
1582         }
1583         if (defined $xfer_encoding or $has_content_type) {
1584                 unshift @xh, 'MIME-Version: 1.0' unless $has_mime_version;
1585         }
1586
1587         $needs_confirm = (
1588                 $confirm eq "always" or
1589                 ($confirm =~ /^(?:auto|cc)$/ && @cc) or
1590                 ($confirm =~ /^(?:auto|compose)$/ && $compose && $message_num == 1));
1591         $needs_confirm = "inform" if ($needs_confirm && $confirm_unconfigured && @cc);
1592
1593         @to = validate_address_list(sanitize_address_list(@to));
1594         @cc = validate_address_list(sanitize_address_list(@cc));
1595
1596         @to = (@initial_to, @to);
1597         @cc = (@initial_cc, @cc);
1598
1599         if ($message_num == 1) {
1600                 if (defined $cover_cc and $cover_cc) {
1601                         @initial_cc = @cc;
1602                 }
1603                 if (defined $cover_to and $cover_to) {
1604                         @initial_to = @to;
1605                 }
1606         }
1607
1608         my $message_was_sent = send_message();
1609
1610         # set up for the next message
1611         if ($thread && $message_was_sent &&
1612                 ($chain_reply_to || !defined $reply_to || length($reply_to) == 0 ||
1613                 $message_num == 1)) {
1614                 $reply_to = $message_id;
1615                 if (length $references > 0) {
1616                         $references .= "\n $message_id";
1617                 } else {
1618                         $references = "$message_id";
1619                 }
1620         }
1621         $message_id = undef;
1622 }
1623
1624 # Execute a command (e.g. $to_cmd) to get a list of email addresses
1625 # and return a results array
1626 sub recipients_cmd {
1627         my ($prefix, $what, $cmd, $file) = @_;
1628
1629         my @addresses = ();
1630         open my $fh, "-|", "$cmd \Q$file\E"
1631             or die "($prefix) Could not execute '$cmd'";
1632         while (my $address = <$fh>) {
1633                 $address =~ s/^\s*//g;
1634                 $address =~ s/\s*$//g;
1635                 $address = sanitize_address($address);
1636                 next if ($address eq $sender and $suppress_cc{'self'});
1637                 push @addresses, $address;
1638                 printf("($prefix) Adding %s: %s from: '%s'\n",
1639                        $what, $address, $cmd) unless $quiet;
1640                 }
1641         close $fh
1642             or die "($prefix) failed to close pipe to '$cmd'";
1643         return @addresses;
1644 }
1645
1646 cleanup_compose_files();
1647
1648 sub cleanup_compose_files {
1649         unlink($compose_filename, $compose_filename . ".final") if $compose;
1650 }
1651
1652 $smtp->quit if $smtp;
1653
1654 sub apply_transfer_encoding {
1655         my $message = shift;
1656         my $from = shift;
1657         my $to = shift;
1658
1659         return $message if ($from eq $to and $from ne '7bit');
1660
1661         require MIME::QuotedPrint;
1662         require MIME::Base64;
1663
1664         $message = MIME::QuotedPrint::decode($message)
1665                 if ($from eq 'quoted-printable');
1666         $message = MIME::Base64::decode($message)
1667                 if ($from eq 'base64');
1668
1669         die "cannot send message as 7bit"
1670                 if ($to eq '7bit' and $message =~ /[^[:ascii:]]/);
1671         return $message
1672                 if ($to eq '7bit' or $to eq '8bit');
1673         return MIME::QuotedPrint::encode($message, "\n", 0)
1674                 if ($to eq 'quoted-printable');
1675         return MIME::Base64::encode($message, "\n")
1676                 if ($to eq 'base64');
1677         die "invalid transfer encoding";
1678 }
1679
1680 sub unique_email_list {
1681         my %seen;
1682         my @emails;
1683
1684         foreach my $entry (@_) {
1685                 my $clean = extract_valid_address_or_die($entry);
1686                 $seen{$clean} ||= 0;
1687                 next if $seen{$clean}++;
1688                 push @emails, $entry;
1689         }
1690         return @emails;
1691 }
1692
1693 sub validate_patch {
1694         my $fn = shift;
1695         open(my $fh, '<', $fn)
1696                 or die "unable to open $fn: $!\n";
1697         while (my $line = <$fh>) {
1698                 if (length($line) > 998) {
1699                         return "$.: patch contains a line longer than 998 characters";
1700                 }
1701         }
1702         return;
1703 }
1704
1705 sub file_has_nonascii {
1706         my $fn = shift;
1707         open(my $fh, '<', $fn)
1708                 or die "unable to open $fn: $!\n";
1709         while (my $line = <$fh>) {
1710                 return 1 if $line =~ /[^[:ascii:]]/;
1711         }
1712         return 0;
1713 }
1714
1715 sub body_or_subject_has_nonascii {
1716         my $fn = shift;
1717         open(my $fh, '<', $fn)
1718                 or die "unable to open $fn: $!\n";
1719         while (my $line = <$fh>) {
1720                 last if $line =~ /^$/;
1721                 return 1 if $line =~ /^Subject.*[^[:ascii:]]/;
1722         }
1723         while (my $line = <$fh>) {
1724                 return 1 if $line =~ /[^[:ascii:]]/;
1725         }
1726         return 0;
1727 }