Index | Thread | Search

From:
Kirill A. Korinsky <kirill@korins.ky>
Subject:
Re: smtpd: add TLS flag to envelopes
To:
"Omar Polo" <op@omarpolo.com>
Cc:
tech@openbsd.org, gilles@poolp.org
Date:
Sun, 13 Sep 2026 17:35:12 +0200

Download raw body.

Thread
On Sun, 13 Sep 2026 14:01:29 +0200,
"Omar Polo" <op@omarpolo.com> wrote:
> 
> from Johan Hattne via https://github.com/OpenSMTPD/OpenSMTPD/pull/1311
> 
> currently, a configuration like
> 
> 	match ... tls ... action foobar
> 
> which should specify that the transaction was over TLS, fails with 451
> because ruleset_match_smtp_starttls() is a stub that returns -1.
> 
> I'm adding the missing getflag() in smtpctl.c which otherwise was
> breaking `smtpctl show queue'.
> 
> ok?

makes sense and reads OK kirill@

> 
> diff /usr/src
> path + /usr/src
> commit - e03e9278c32b9eb8009e41e92cb2daeb3a75fabc
> blob - b433096b3a06f0b7e1e1beef3fe197e94c701001
> file + usr.sbin/smtpd/envelope.c
> --- usr.sbin/smtpd/envelope.c
> +++ usr.sbin/smtpd/envelope.c
> @@ -323,6 +323,8 @@ ascii_load_flags(enum envelope_flags *dest, char *buf)
>  			*dest |= EF_BOUNCE;
>  		else if (strcasecmp(flag, "internal") == 0)
>  			*dest |= EF_INTERNAL;
> +		else if (strcasecmp(flag, "tls") == 0)
> +			*dest |= EF_TLS;
>  		else
>  			return 0;
>  	}
> @@ -560,6 +562,11 @@ ascii_dump_flags(enum envelope_flags flags, char *buf,
>  				(void)strlcat(buf, " ", len);
>  			cpylen = strlcat(buf, "internal", len);
>  		}
> +		if (flags & EF_TLS) {
> +			if (buf[0] != '\0')
> +				(void)strlcat(buf, " ", len);
> +			cpylen = strlcat(buf, "tls", len);
> +		}
>  	}
>  
>  	return cpylen < len ? 1 : 0;
> commit - e03e9278c32b9eb8009e41e92cb2daeb3a75fabc
> blob - 5a268c9ae43064c6621a9abdabb9c5646b182171
> file + usr.sbin/smtpd/ruleset.c
> --- usr.sbin/smtpd/ruleset.c
> +++ usr.sbin/smtpd/ruleset.c
> @@ -129,11 +129,14 @@ ruleset_match_smtp_helo(struct rule *r, const struct e
>  static int
>  ruleset_match_smtp_starttls(struct rule *r, const struct envelope *evp)
>  {
> +	int	ret;
> +
>  	if (!r->flag_smtp_starttls)
>  		return 1;
>  
> -	/* XXX - not until TLS flag is added to envelope */
> -	return -1;
> +	ret = evp->flags & EF_TLS;
> +
> +	return MATCH_RESULT(ret, r->flag_smtp_starttls);
>  }
>  
>  static int
> commit - e03e9278c32b9eb8009e41e92cb2daeb3a75fabc
> blob - bc7d864fc54f5f682f2b73c21c0a6095f04a789b
> file + usr.sbin/smtpd/smtp_session.c
> --- usr.sbin/smtpd/smtp_session.c
> +++ usr.sbin/smtpd/smtp_session.c
> @@ -2321,6 +2321,8 @@ smtp_tx(struct smtp_session *s)
>  		tx->evp.flags |= EF_BOUNCE;
>  	if (s->flags & SF_AUTHENTICATED)
>  		tx->evp.flags |= EF_AUTHENTICATED;
> +	if (s->flags & SF_SECURE)
> +		tx->evp.flags |= EF_TLS;
>  
>  	if ((tx->parser = rfc5322_parser_new()) == NULL) {
>  		free(tx);
> commit - e03e9278c32b9eb8009e41e92cb2daeb3a75fabc
> blob - 3f94efa4d51106a53e0448e69568fef5495608a3
> file + usr.sbin/smtpd/smtpctl.c
> --- usr.sbin/smtpd/smtpctl.c
> +++ usr.sbin/smtpd/smtpctl.c
> @@ -1161,6 +1161,7 @@ show_queue_envelope(struct envelope *e, int online)
>  	getflag(&e->flags, EF_BOUNCE, "bounce", status, sizeof(status));
>  	getflag(&e->flags, EF_AUTHENTICATED, "auth", status, sizeof(status));
>  	getflag(&e->flags, EF_INTERNAL, "internal", status, sizeof(status));
> +	getflag(&e->flags, EF_TLS, "tls", status, sizeof(status));
>  	getflag(&e->flags, EF_SUSPEND, "suspend", status, sizeof(status));
>  	getflag(&e->flags, EF_HOLD, "hold", status, sizeof(status));
>  
> commit - e03e9278c32b9eb8009e41e92cb2daeb3a75fabc
> blob - 4f362dc7ad555afd2c73419d44991ee31da743b1
> file + usr.sbin/smtpd/smtpd-api.h
> --- usr.sbin/smtpd/smtpd-api.h
> +++ usr.sbin/smtpd/smtpd-api.h
> @@ -74,6 +74,7 @@ enum envelope_flags {
>  	EF_AUTHENTICATED	= 0x01,
>  	EF_BOUNCE		= 0x02,
>  	EF_INTERNAL		= 0x04, /* Internal expansion forward */
> +	EF_TLS			= 0x08,
>  
>  	/* runstate, not saved on disk */
>  
> 

-- 
wbr, Kirill