]> git.sur5r.net Git - openldap/blob - servers/slapd/daemon.c
Avoid filling the wake_sds when massive numbers of connections close at once.
[openldap] / servers / slapd / daemon.c
1 /* $OpenLDAP$ */
2 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
3  *
4  * Copyright 1998-2004 The OpenLDAP Foundation.
5  * All rights reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted only as authorized by the OpenLDAP
9  * Public License.
10  *
11  * A copy of this license is available in the file LICENSE in the
12  * top-level directory of the distribution or, alternatively, at
13  * <http://www.OpenLDAP.org/license.html>.
14  */
15 /* Portions Copyright (c) 1995 Regents of the University of Michigan.
16  * All rights reserved.
17  *
18  * Redistribution and use in source and binary forms are permitted
19  * provided that this notice is preserved and that due credit is given
20  * to the University of Michigan at Ann Arbor. The name of the University
21  * may not be used to endorse or promote products derived from this
22  * software without specific prior written permission. This software
23  * is provided ``as is'' without express or implied warranty.
24  */
25
26 #include "portable.h"
27
28 #include <stdio.h>
29
30 #include <ac/ctype.h>
31 #include <ac/errno.h>
32 #include <ac/socket.h>
33 #include <ac/string.h>
34 #include <ac/time.h>
35 #include <ac/unistd.h>
36
37 #include "slap.h"
38 #include "ldap_pvt_thread.h"
39 #include "lutil.h"
40
41 #include "ldap_rq.h"
42
43 #ifdef HAVE_TCPD
44 #include <tcpd.h>
45 #define SLAP_STRING_UNKNOWN     STRING_UNKNOWN
46
47 int allow_severity = LOG_INFO;
48 int deny_severity = LOG_NOTICE;
49 #else /* ! TCP Wrappers */
50 #define SLAP_STRING_UNKNOWN     "unknown"
51 #endif /* ! TCP Wrappers */
52
53 #ifdef LDAP_PF_LOCAL
54 #include <sys/stat.h>
55 /* this should go in <ldap.h> as soon as it is accepted */
56 #define LDAPI_MOD_URLEXT                "x-mod"
57 #endif /* LDAP_PF_LOCAL */
58
59 #ifdef LDAP_PF_INET6
60 int slap_inet4or6 = AF_UNSPEC;
61 #else
62 int slap_inet4or6 = AF_INET;
63 #endif
64
65 /* globals */
66 time_t starttime;
67 ber_socket_t dtblsize;
68 slap_ssf_t local_ssf = LDAP_PVT_SASL_LOCAL_SSF;
69
70 Listener **slap_listeners = NULL;
71
72 #define SLAPD_LISTEN 10
73
74 static ber_socket_t wake_sds[2];
75 static int emfile;
76
77 static int waking;
78 #define WAKE_LISTENER(w) \
79 do { if (w && !waking) tcp_write( wake_sds[1], "0", 1 ); waking=w; } while(0)
80
81 volatile sig_atomic_t slapd_shutdown = 0, slapd_gentle_shutdown = 0;
82 volatile sig_atomic_t slapd_abrupt_shutdown = 0;
83
84 static struct slap_daemon {
85         ldap_pvt_thread_mutex_t sd_mutex;
86
87         ber_socket_t sd_nactives;
88
89 #ifndef HAVE_WINSOCK
90         /* In winsock, accept() returns values higher than dtblsize
91                 so don't bother with this optimization */
92         int sd_nfds;
93 #endif
94
95         fd_set sd_actives;
96         fd_set sd_readers;
97         fd_set sd_writers;
98 } slap_daemon;
99
100
101
102 #ifdef HAVE_SLP
103 /*
104  * SLP related functions
105  */
106 #include <slp.h>
107
108 #define LDAP_SRVTYPE_PREFIX "service:ldap://"
109 #define LDAPS_SRVTYPE_PREFIX "service:ldaps://"
110 static char** slapd_srvurls = NULL;
111 static SLPHandle slapd_hslp = 0;
112 int slapd_register_slp = 0;
113
114 void slapd_slp_init( const char* urls ) {
115         int i;
116
117         slapd_srvurls = ldap_str2charray( urls, " " );
118
119         if( slapd_srvurls == NULL ) return;
120
121         /* find and expand INADDR_ANY URLs */
122         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
123                 if( strcmp( slapd_srvurls[i], "ldap:///" ) == 0) {
124                         char *host = ldap_pvt_get_fqdn( NULL );
125                         if ( host != NULL ) {
126                                 slapd_srvurls[i] = (char *) ch_realloc( slapd_srvurls[i],
127                                         strlen( host ) +
128                                         sizeof( LDAP_SRVTYPE_PREFIX ) );
129                                 strcpy( lutil_strcopy(slapd_srvurls[i],
130                                         LDAP_SRVTYPE_PREFIX ), host );
131
132                                 ch_free( host );
133                         }
134
135                 } else if ( strcmp( slapd_srvurls[i], "ldaps:///" ) == 0) {
136                         char *host = ldap_pvt_get_fqdn( NULL );
137                         if ( host != NULL ) {
138                                 slapd_srvurls[i] = (char *) ch_realloc( slapd_srvurls[i],
139                                         strlen( host ) +
140                                         sizeof( LDAPS_SRVTYPE_PREFIX ) );
141                                 strcpy( lutil_strcopy(slapd_srvurls[i],
142                                         LDAPS_SRVTYPE_PREFIX ), host );
143
144                                 ch_free( host );
145                         }
146                 }
147         }
148
149         /* open the SLP handle */
150         SLPOpen( "en", 0, &slapd_hslp );
151 }
152
153 void slapd_slp_deinit() {
154         if( slapd_srvurls == NULL ) return;
155
156         ldap_charray_free( slapd_srvurls );
157         slapd_srvurls = NULL;
158
159         /* close the SLP handle */
160         SLPClose( slapd_hslp );
161 }
162
163 void slapd_slp_regreport(
164         SLPHandle hslp,
165         SLPError errcode,
166         void* cookie )
167 {
168         /* empty report */
169 }
170
171 void slapd_slp_reg() {
172         int i;
173
174         if( slapd_srvurls == NULL ) return;
175
176         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
177                 if( strncmp( slapd_srvurls[i], LDAP_SRVTYPE_PREFIX,
178                                 sizeof( LDAP_SRVTYPE_PREFIX ) - 1 ) == 0 ||
179                     strncmp( slapd_srvurls[i], LDAPS_SRVTYPE_PREFIX,
180                                 sizeof( LDAPS_SRVTYPE_PREFIX ) - 1 ) == 0 )
181                 {
182                         SLPReg( slapd_hslp,
183                                 slapd_srvurls[i],
184                                 SLP_LIFETIME_MAXIMUM,
185                                 "ldap",
186                                 "",
187                                 1,
188                                 slapd_slp_regreport,
189                                 NULL );
190                 }
191         }
192 }
193
194 void slapd_slp_dereg() {
195         int i;
196
197         if( slapd_srvurls == NULL ) return;
198
199         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
200                 SLPDereg( slapd_hslp,
201                         slapd_srvurls[i],
202                         slapd_slp_regreport,
203                         NULL );
204         }
205 }
206 #endif /* HAVE_SLP */
207
208 /*
209  * Add a descriptor to daemon control
210  *
211  * If isactive, the descriptor is a live server session and is subject
212  * to idletimeout control. Otherwise, the descriptor is a passive
213  * listener or an outbound client session, and not subject to
214  * idletimeout.
215  */
216 static void slapd_add(ber_socket_t s, int isactive) {
217         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
218
219         assert( !FD_ISSET( s, &slap_daemon.sd_actives ));
220         assert( !FD_ISSET( s, &slap_daemon.sd_readers ));
221         assert( !FD_ISSET( s, &slap_daemon.sd_writers ));
222
223 #ifndef HAVE_WINSOCK
224         if (s >= slap_daemon.sd_nfds) {
225                 slap_daemon.sd_nfds = s + 1;
226         }
227 #endif
228
229         if ( isactive ) {
230                 slap_daemon.sd_nactives++;
231         }
232
233         FD_SET( s, &slap_daemon.sd_actives );
234         FD_SET( s, &slap_daemon.sd_readers );
235
236         Debug( LDAP_DEBUG_CONNS, "daemon: added %ld%s%s\n",
237                 (long) s,
238             FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
239                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : "" );
240         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
241 }
242
243 /*
244  * Remove the descriptor from daemon control
245  */
246 void slapd_remove(ber_socket_t s, int wasactive, int wake) {
247         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
248
249         if ( wasactive ) {
250                 slap_daemon.sd_nactives--;
251         }
252
253         Debug( LDAP_DEBUG_CONNS, "daemon: removing %ld%s%s\n",
254                 (long) s,
255             FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
256                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : "" );
257         FD_CLR( s, &slap_daemon.sd_actives );
258         FD_CLR( s, &slap_daemon.sd_readers );
259         FD_CLR( s, &slap_daemon.sd_writers );
260
261         /* If we ran out of file descriptors, we dropped a listener from
262          * the select() loop. Now that we're removing a session from our
263          * control, we can try to resume a dropped listener to use.
264          */
265         if ( emfile ) {
266                 int i;
267                 for ( i = 0; slap_listeners[i] != NULL; i++ ) {
268                         if ( slap_listeners[i]->sl_sd != AC_SOCKET_INVALID ) {
269                                 if ( slap_listeners[i]->sl_sd == s ) continue;
270                                 if ( slap_listeners[i]->sl_is_mute ) {
271                                         slap_listeners[i]->sl_is_mute = 0;
272                                         emfile--;
273                                         break;
274                                 }
275                         }
276                 }
277                 /* Walked the entire list without enabling anything; emfile
278                  * counter is stale. Reset it.
279                  */
280                 if ( slap_listeners[i] == NULL )
281                         emfile = 0;
282         }
283         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
284         WAKE_LISTENER(wake || slapd_gentle_shutdown == 2);
285 }
286
287 void slapd_clr_write(ber_socket_t s, int wake) {
288         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
289
290         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
291         FD_CLR( s, &slap_daemon.sd_writers );
292
293         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
294         WAKE_LISTENER(wake);
295 }
296
297 void slapd_set_write(ber_socket_t s, int wake) {
298         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
299
300         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
301         if (!FD_ISSET(s, &slap_daemon.sd_writers))
302             FD_SET( (unsigned) s, &slap_daemon.sd_writers );
303
304         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
305         WAKE_LISTENER(wake);
306 }
307
308 void slapd_clr_read(ber_socket_t s, int wake) {
309         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
310
311         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
312         FD_CLR( s, &slap_daemon.sd_readers );
313
314         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
315         WAKE_LISTENER(wake);
316 }
317
318 void slapd_set_read(ber_socket_t s, int wake) {
319         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
320
321         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
322         if (!FD_ISSET(s, &slap_daemon.sd_readers))
323             FD_SET( s, &slap_daemon.sd_readers );
324
325         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
326         WAKE_LISTENER(wake);
327 }
328
329 static void slapd_close(ber_socket_t s) {
330         Debug( LDAP_DEBUG_CONNS, "daemon: closing %ld\n",
331                 (long) s, 0, 0 );
332         tcp_close(s);
333 }
334
335 static void slap_free_listener_addresses(struct sockaddr **sal)
336 {
337         struct sockaddr **sap;
338
339         if (sal == NULL) {
340                 return;
341         }
342
343         for (sap = sal; *sap != NULL; sap++) {
344                 ch_free(*sap);
345         }
346
347         ch_free(sal);
348 }
349
350 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
351 static int get_url_perms(
352         char    **exts,
353         mode_t  *perms,
354         int     *crit )
355 {
356         int     i;
357
358         assert( exts );
359         assert( perms );
360         assert( crit );
361
362         *crit = 0;
363         for ( i = 0; exts[ i ]; i++ ) {
364                 char    *type = exts[ i ];
365                 int     c = 0;
366
367                 if ( type[ 0 ] == '!' ) {
368                         c = 1;
369                         type++;
370                 }
371
372                 if ( strncasecmp( type, LDAPI_MOD_URLEXT "=", sizeof(LDAPI_MOD_URLEXT "=") - 1 ) == 0 ) {
373                         char    *value = type
374                                 + ( sizeof(LDAPI_MOD_URLEXT "=") - 1 );
375                         mode_t  p = 0;
376                         int     j;
377
378                         switch (strlen(value)) {
379                         case 4:
380                                 /* skip leading '0' */
381                                 if ( value[ 0 ] != '0' ) {
382                                         return LDAP_OTHER;
383                                 }
384                                 value++;
385
386                         case 3:
387                                 for ( j = 0; j < 3; j++) {
388                                         int     v;
389
390                                         v = value[ j ] - '0';
391
392                                         if ( v < 0 || v > 7 ) {
393                                                 return LDAP_OTHER;
394                                         }
395
396                                         p |= v << 3*(2-j);
397                                 }
398                                 break;
399
400                         case 10:
401                                 for ( j = 1; j < 10; j++ ) {
402                                         static mode_t   m[] = { 0, 
403                                                 S_IRUSR, S_IWUSR, S_IXUSR,
404                                                 S_IRGRP, S_IWGRP, S_IXGRP,
405                                                 S_IROTH, S_IWOTH, S_IXOTH
406                                         };
407                                         static char     c[] = "-rwxrwxrwx"; 
408
409                                         if ( value[ j ] == c[ j ] ) {
410                                                 p |= m[ j ];
411         
412                                         } else if ( value[ j ] != '-' ) {
413                                                 return LDAP_OTHER;
414                                         }
415                                 }
416                                 break;
417
418                         default:
419                                 return LDAP_OTHER;
420                         } 
421
422                         *crit = c;
423                         *perms = p;
424
425                         return LDAP_SUCCESS;
426                 }
427         }
428
429         return LDAP_OTHER;
430 }
431 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
432
433 /* port = 0 indicates AF_LOCAL */
434 static int slap_get_listener_addresses(
435         const char *host,
436         unsigned short port,
437         struct sockaddr ***sal)
438 {
439         struct sockaddr **sap;
440
441 #ifdef LDAP_PF_LOCAL
442         if ( port == 0 ) {
443                 *sal = ch_malloc(2 * sizeof(void *));
444                 if (*sal == NULL) {
445                         return -1;
446                 }
447
448                 sap = *sal;
449                 *sap = ch_malloc(sizeof(struct sockaddr_un));
450                 if (*sap == NULL)
451                         goto errexit;
452                 sap[1] = NULL;
453
454                 if ( strlen(host) >
455                      (sizeof(((struct sockaddr_un *)*sap)->sun_path) - 1) ) {
456                         Debug( LDAP_DEBUG_ANY,
457                                "daemon: domain socket path (%s) too long in URL",
458                                host, 0, 0);
459                         goto errexit;
460                 }
461
462                 (void)memset( (void *)*sap, '\0', sizeof(struct sockaddr_un) );
463                 (*sap)->sa_family = AF_LOCAL;
464                 strcpy( ((struct sockaddr_un *)*sap)->sun_path, host );
465         } else
466 #endif
467         {
468 #ifdef HAVE_GETADDRINFO
469                 struct addrinfo hints, *res, *sai;
470                 int n, err;
471                 char serv[7];
472
473                 memset( &hints, '\0', sizeof(hints) );
474                 hints.ai_flags = AI_PASSIVE;
475                 hints.ai_socktype = SOCK_STREAM;
476                 hints.ai_family = slap_inet4or6;
477                 snprintf(serv, sizeof serv, "%d", port);
478
479                 if ( (err = getaddrinfo(host, serv, &hints, &res)) ) {
480                         Debug( LDAP_DEBUG_ANY, "daemon: getaddrinfo failed: %s\n",
481                                 AC_GAI_STRERROR(err), 0, 0);
482                         return -1;
483                 }
484
485                 sai = res;
486                 for (n=2; (sai = sai->ai_next) != NULL; n++) {
487                         /* EMPTY */ ;
488                 }
489                 *sal = ch_calloc(n, sizeof(void *));
490                 if (*sal == NULL) {
491                         return -1;
492                 }
493
494                 sap = *sal;
495                 *sap = NULL;
496
497                 for ( sai=res; sai; sai=sai->ai_next ) {
498                         if( sai->ai_addr == NULL ) {
499                                 Debug( LDAP_DEBUG_ANY, "slap_get_listener_addresses: "
500                                         "getaddrinfo ai_addr is NULL?\n", 0, 0, 0 );
501                                 freeaddrinfo(res);
502                                 goto errexit;
503                         }
504
505                         switch (sai->ai_family) {
506 #  ifdef LDAP_PF_INET6
507                         case AF_INET6:
508                                 *sap = ch_malloc(sizeof(struct sockaddr_in6));
509                                 if (*sap == NULL) {
510                                         freeaddrinfo(res);
511                                         goto errexit;
512                                 }
513                                 *(struct sockaddr_in6 *)*sap =
514                                         *((struct sockaddr_in6 *)sai->ai_addr);
515                                 break;
516 #  endif
517                         case AF_INET:
518                                 *sap = ch_malloc(sizeof(struct sockaddr_in));
519                                 if (*sap == NULL) {
520                                         freeaddrinfo(res);
521                                         goto errexit;
522                                 }
523                                 *(struct sockaddr_in *)*sap =
524                                         *((struct sockaddr_in *)sai->ai_addr);
525                                 break;
526                         default:
527                                 *sap = NULL;
528                                 break;
529                         }
530
531                         if (*sap != NULL) {
532                                 (*sap)->sa_family = sai->ai_family;
533                                 sap++;
534                                 *sap = NULL;
535                         }
536                 }
537
538                 freeaddrinfo(res);
539 #else
540                 int i, n = 1;
541                 struct in_addr in;
542                 struct hostent *he = NULL;
543
544                 if ( host == NULL ) {
545                         in.s_addr = htonl(INADDR_ANY);
546
547                 } else if ( !inet_aton( host, &in ) ) {
548                         he = gethostbyname( host );
549                         if( he == NULL ) {
550                                 Debug( LDAP_DEBUG_ANY,
551                                        "daemon: invalid host %s", host, 0, 0);
552                                 return -1;
553                         }
554                         for (n = 0; he->h_addr_list[n]; n++) ;
555                 }
556
557                 *sal = ch_malloc((n+1) * sizeof(void *));
558                 if (*sal == NULL) {
559                         return -1;
560                 }
561
562                 sap = *sal;
563                 for ( i = 0; i<n; i++ ) {
564                         sap[i] = ch_malloc(sizeof(struct sockaddr_in));
565                         if (*sap == NULL) {
566                                 goto errexit;
567                         }
568                         (void)memset( (void *)sap[i], '\0', sizeof(struct sockaddr_in) );
569                         sap[i]->sa_family = AF_INET;
570                         ((struct sockaddr_in *)sap[i])->sin_port = htons(port);
571                         if (he) {
572                                 AC_MEMCPY( &((struct sockaddr_in *)sap[i])->sin_addr, he->h_addr_list[i], sizeof(struct in_addr) );
573                         } else {
574                                 AC_MEMCPY( &((struct sockaddr_in *)sap[i])->sin_addr, &in, sizeof(struct in_addr) );
575                         }
576                 }
577                 sap[i] = NULL;
578 #endif
579         }
580
581         return 0;
582
583 errexit:
584         slap_free_listener_addresses(*sal);
585         return -1;
586 }
587
588 static int slap_open_listener(
589         const char* url,
590         int *listeners,
591         int *cur
592         )
593 {
594         int     num, tmp, rc;
595         Listener l;
596         Listener *li;
597         LDAPURLDesc *lud;
598         unsigned short port;
599         int err, addrlen = 0;
600         struct sockaddr **sal, **psal;
601         int socktype = SOCK_STREAM;     /* default to COTS */
602
603 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
604         /*
605          * use safe defaults
606          */
607         int     crit = 1;
608 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
609
610         rc = ldap_url_parse( url, &lud );
611
612         if( rc != LDAP_URL_SUCCESS ) {
613                 Debug( LDAP_DEBUG_ANY,
614                         "daemon: listen URL \"%s\" parse error=%d\n",
615                         url, rc, 0 );
616                 return rc;
617         }
618
619         l.sl_url.bv_val = NULL;
620         l.sl_is_mute = 0;
621
622 #ifndef HAVE_TLS
623         if( ldap_pvt_url_scheme2tls( lud->lud_scheme ) ) {
624                 Debug( LDAP_DEBUG_ANY,
625                         "daemon: TLS not supported (%s)\n",
626                         url, 0, 0 );
627                 ldap_free_urldesc( lud );
628                 return -1;
629         }
630
631         if(! lud->lud_port ) {
632                 lud->lud_port = LDAP_PORT;
633         }
634
635 #else
636         l.sl_is_tls = ldap_pvt_url_scheme2tls( lud->lud_scheme );
637
638         if(! lud->lud_port ) {
639                 lud->lud_port = l.sl_is_tls ? LDAPS_PORT : LDAP_PORT;
640         }
641 #endif
642
643         port = (unsigned short) lud->lud_port;
644
645         tmp = ldap_pvt_url_scheme2proto(lud->lud_scheme);
646         if ( tmp == LDAP_PROTO_IPC ) {
647 #ifdef LDAP_PF_LOCAL
648                 if ( lud->lud_host == NULL || lud->lud_host[0] == '\0' ) {
649                         err = slap_get_listener_addresses(LDAPI_SOCK, 0, &sal);
650                 } else {
651                         err = slap_get_listener_addresses(lud->lud_host, 0, &sal);
652                 }
653 #else
654
655                 Debug( LDAP_DEBUG_ANY, "daemon: URL scheme not supported: %s",
656                         url, 0, 0);
657                 ldap_free_urldesc( lud );
658                 return -1;
659 #endif
660         } else {
661                 if( lud->lud_host == NULL || lud->lud_host[0] == '\0'
662                         || strcmp(lud->lud_host, "*") == 0 )
663                 {
664                         err = slap_get_listener_addresses(NULL, port, &sal);
665                 } else {
666                         err = slap_get_listener_addresses(lud->lud_host, port, &sal);
667                 }
668         }
669 #ifdef LDAP_CONNECTIONLESS
670         l.sl_is_udp = ( tmp == LDAP_PROTO_UDP );
671 #endif
672
673 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
674         if ( lud->lud_exts ) {
675                 err = get_url_perms( lud->lud_exts, &l.sl_perms, &crit );
676         } else {
677                 l.sl_perms = S_IRWXU | S_IRWXO;
678         }
679 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
680
681         ldap_free_urldesc( lud );
682         if ( err ) {
683                 return -1;
684         }
685
686         /* If we got more than one address returned, we need to make space
687          * for it in the slap_listeners array.
688          */
689         for ( num=0; sal[num]; num++ );
690         if ( num > 1 ) {
691                 *listeners += num-1;
692                 slap_listeners = ch_realloc( slap_listeners, (*listeners + 1) * sizeof(Listener *) );
693         }
694
695         psal = sal;
696         while ( *sal != NULL ) {
697                 char *af;
698                 switch( (*sal)->sa_family ) {
699                 case AF_INET:
700                         af = "IPv4";
701                         break;
702 #ifdef LDAP_PF_INET6
703                 case AF_INET6:
704                         af = "IPv6";
705                         break;
706 #endif
707 #ifdef LDAP_PF_LOCAL
708                 case AF_LOCAL:
709                         af = "Local";
710                         break;
711 #endif
712                 default:
713                         sal++;
714                         continue;
715                 }
716 #ifdef LDAP_CONNECTIONLESS
717                 if( l.sl_is_udp ) socktype = SOCK_DGRAM;
718 #endif
719                 l.sl_sd = socket( (*sal)->sa_family, socktype, 0);
720                 if ( l.sl_sd == AC_SOCKET_INVALID ) {
721                         int err = sock_errno();
722                         Debug( LDAP_DEBUG_ANY,
723                                 "daemon: %s socket() failed errno=%d (%s)\n",
724                                 af, err, sock_errstr(err) );
725                         sal++;
726                         continue;
727                 }
728 #ifndef HAVE_WINSOCK
729                 if ( l.sl_sd >= dtblsize ) {
730                         Debug( LDAP_DEBUG_ANY,
731                                 "daemon: listener descriptor %ld is too great %ld\n",
732                                 (long) l.sl_sd, (long) dtblsize, 0 );
733                         tcp_close( l.sl_sd );
734                         sal++;
735                         continue;
736                 }
737 #endif
738 #ifdef LDAP_PF_LOCAL
739                 if ( (*sal)->sa_family == AF_LOCAL ) {
740                         unlink ( ((struct sockaddr_un *)*sal)->sun_path );
741                 } else
742 #endif
743                 {
744 #ifdef SO_REUSEADDR
745                         /* enable address reuse */
746                         tmp = 1;
747                         rc = setsockopt( l.sl_sd, SOL_SOCKET, SO_REUSEADDR,
748                                 (char *) &tmp, sizeof(tmp) );
749                         if ( rc == AC_SOCKET_ERROR ) {
750                                 int err = sock_errno();
751                                 Debug( LDAP_DEBUG_ANY,
752                                        "slapd(%ld): setsockopt(SO_REUSEADDR) failed errno=%d (%s)\n",
753                                        (long) l.sl_sd, err, sock_errstr(err) );
754                         }
755 #endif
756                 }
757
758                 switch( (*sal)->sa_family ) {
759                 case AF_INET:
760                         addrlen = sizeof(struct sockaddr_in);
761                         break;
762 #ifdef LDAP_PF_INET6
763                 case AF_INET6:
764 #ifdef IPV6_V6ONLY
765                         /* Try to use IPv6 sockets for IPv6 only */
766                         tmp = 1;
767                         rc = setsockopt( l.sl_sd, IPPROTO_IPV6, IPV6_V6ONLY,
768                                          (char *) &tmp, sizeof(tmp) );
769                         if ( rc == AC_SOCKET_ERROR ) {
770                                 int err = sock_errno();
771                                 Debug( LDAP_DEBUG_ANY,
772                                        "slapd(%ld): setsockopt(IPV6_V6ONLY) failed errno=%d (%s)\n",
773                                        (long) l.sl_sd, err, sock_errstr(err) );
774                         }
775 #endif
776                         addrlen = sizeof(struct sockaddr_in6);
777                         break;
778 #endif
779 #ifdef LDAP_PF_LOCAL
780                 case AF_LOCAL:
781                         addrlen = sizeof(struct sockaddr_un);
782                         break;
783 #endif
784                 }
785
786                 if (bind(l.sl_sd, *sal, addrlen)) {
787                         err = sock_errno();
788                 Debug( LDAP_DEBUG_ANY, "daemon: bind(%ld) failed errno=%d (%s)\n",
789                        (long) l.sl_sd, err, sock_errstr(err) );
790                         tcp_close( l.sl_sd );
791                         sal++;
792                         continue;
793                 }
794
795         switch ( (*sal)->sa_family ) {
796 #ifdef LDAP_PF_LOCAL
797         case AF_LOCAL: {
798                 char *addr = ((struct sockaddr_un *)*sal)->sun_path;
799 #if 0 /* don't muck with socket perms */
800                 if ( chmod( addr, l.sl_perms ) < 0 && crit ) {
801                         int err = sock_errno();
802                         Debug( LDAP_DEBUG_ANY, "daemon: fchmod(%ld) failed errno=%d (%s)",
803                                (long) l.sl_sd, err, sock_errstr(err) );
804                         tcp_close( l.sl_sd );
805                         slap_free_listener_addresses(psal);
806                         return -1;
807                 }
808 #endif
809                 l.sl_name.bv_len = strlen(addr) + sizeof("PATH=") - 1;
810                 l.sl_name.bv_val = ber_memalloc( l.sl_name.bv_len + 1 );
811                 snprintf( l.sl_name.bv_val, l.sl_name.bv_len + 1, 
812                                 "PATH=%s", addr );
813         } break;
814 #endif /* LDAP_PF_LOCAL */
815
816         case AF_INET: {
817                 char *s;
818 #if defined( HAVE_GETADDRINFO ) && defined( HAVE_INET_NTOP )
819                 char addr[INET_ADDRSTRLEN];
820                 inet_ntop( AF_INET, &((struct sockaddr_in *)*sal)->sin_addr,
821                            addr, sizeof(addr) );
822                 s = addr;
823 #else
824                 s = inet_ntoa( ((struct sockaddr_in *) *sal)->sin_addr );
825 #endif
826                 port = ntohs( ((struct sockaddr_in *)*sal) ->sin_port );
827                 l.sl_name.bv_val = ber_memalloc( sizeof("IP=255.255.255.255:65535") );
828                 snprintf( l.sl_name.bv_val, sizeof("IP=255.255.255.255:65535"),
829                         "IP=%s:%d",
830                          s != NULL ? s : SLAP_STRING_UNKNOWN, port );
831                 l.sl_name.bv_len = strlen( l.sl_name.bv_val );
832         } break;
833
834 #ifdef LDAP_PF_INET6
835         case AF_INET6: {
836                 char addr[INET6_ADDRSTRLEN];
837                 inet_ntop( AF_INET6, &((struct sockaddr_in6 *)*sal)->sin6_addr,
838                            addr, sizeof addr);
839                 port = ntohs( ((struct sockaddr_in6 *)*sal)->sin6_port );
840                 l.sl_name.bv_len = strlen(addr) + sizeof("IP= 65535");
841                 l.sl_name.bv_val = ber_memalloc( l.sl_name.bv_len );
842                 snprintf( l.sl_name.bv_val, l.sl_name.bv_len, "IP=%s %d", 
843                                 addr, port );
844                 l.sl_name.bv_len = strlen( l.sl_name.bv_val );
845         } break;
846 #endif /* LDAP_PF_INET6 */
847
848         default:
849                 Debug( LDAP_DEBUG_ANY, "daemon: unsupported address family (%d)\n",
850                         (int) (*sal)->sa_family, 0, 0 );
851                 break;
852         }
853
854         AC_MEMCPY(&l.sl_sa, *sal, addrlen);
855         ber_str2bv( url, 0, 1, &l.sl_url);
856         li = ch_malloc( sizeof( Listener ) );
857         *li = l;
858         slap_listeners[*cur] = li;
859         (*cur)++;
860         sal++;
861
862         } /* while ( *sal != NULL ) */
863
864         slap_free_listener_addresses(psal);
865
866         if ( l.sl_url.bv_val == NULL )
867         {
868                 Debug( LDAP_DEBUG_TRACE,
869                         "slap_open_listener: failed on %s\n", url, 0, 0 );
870                 return -1;
871         }
872
873         Debug( LDAP_DEBUG_TRACE, "daemon: initialized %s\n",
874                 l.sl_url.bv_val, 0, 0 );
875         return 0;
876 }
877
878 static int sockinit(void);
879 static int sockdestroy(void);
880
881 int slapd_daemon_init( const char *urls )
882 {
883         int i, j, n, rc;
884         char **u;
885
886         Debug( LDAP_DEBUG_ARGS, "daemon_init: %s\n",
887                 urls ? urls : "<null>", 0, 0 );
888         if( (rc = sockinit()) != 0 ) {
889                 return rc;
890         }
891
892 #ifdef HAVE_SYSCONF
893         dtblsize = sysconf( _SC_OPEN_MAX );
894 #elif HAVE_GETDTABLESIZE
895         dtblsize = getdtablesize();
896 #else
897         dtblsize = FD_SETSIZE;
898 #endif
899
900 #ifdef FD_SETSIZE
901         if(dtblsize > FD_SETSIZE) {
902                 dtblsize = FD_SETSIZE;
903         }
904 #endif  /* !FD_SETSIZE */
905
906         /* open a pipe (or something equivalent connected to itself).
907          * we write a byte on this fd whenever we catch a signal. The main
908          * loop will be select'ing on this socket, and will wake up when
909          * this byte arrives.
910          */
911         if( (rc = lutil_pair( wake_sds )) < 0 ) {
912                 Debug( LDAP_DEBUG_ANY,
913                         "daemon: lutil_pair() failed rc=%d\n", rc, 0, 0 );
914                 return rc;
915         }
916
917         FD_ZERO( &slap_daemon.sd_readers );
918         FD_ZERO( &slap_daemon.sd_writers );
919
920         if( urls == NULL ) {
921                 urls = "ldap:///";
922         }
923
924         u = ldap_str2charray( urls, " " );
925
926         if( u == NULL || u[0] == NULL ) {
927                 Debug( LDAP_DEBUG_ANY, "daemon_init: no urls (%s) provided.\n",
928                         urls, 0, 0 );
929                 return -1;
930         }
931
932         for( i=0; u[i] != NULL; i++ ) {
933                 Debug( LDAP_DEBUG_TRACE, "daemon_init: listen on %s\n",
934                         u[i], 0, 0 );
935         }
936
937         if( i == 0 ) {
938                 Debug( LDAP_DEBUG_ANY, "daemon_init: no listeners to open (%s)\n",
939                         urls, 0, 0 );
940                 ldap_charray_free( u );
941                 return -1;
942         }
943
944         Debug( LDAP_DEBUG_TRACE, "daemon_init: %d listeners to open...\n",
945                 i, 0, 0 );
946         slap_listeners = ch_malloc( (i+1)*sizeof(Listener *) );
947
948         for(n = 0, j = 0; u[n]; n++ ) {
949                 if ( slap_open_listener( u[n], &i, &j ) ) {
950                         ldap_charray_free( u );
951                         return -1;
952                 }
953         }
954         slap_listeners[j] = NULL;
955
956         Debug( LDAP_DEBUG_TRACE, "daemon_init: %d listeners opened\n",
957                 i, 0, 0 );
958
959 #ifdef HAVE_SLP
960         if( slapd_register_slp ) {
961                 slapd_slp_init( urls );
962                 slapd_slp_reg();
963         }
964 #endif
965
966         ldap_charray_free( u );
967         ldap_pvt_thread_mutex_init( &slap_daemon.sd_mutex );
968         return !i;
969 }
970
971
972 int
973 slapd_daemon_destroy(void)
974 {
975         connections_destroy();
976         tcp_close( wake_sds[1] );
977         tcp_close( wake_sds[0] );
978         sockdestroy();
979
980 #ifdef HAVE_SLP
981         if( slapd_register_slp ) {
982                 slapd_slp_dereg();
983                 slapd_slp_deinit();
984         }
985 #endif
986
987         return 0;
988 }
989
990
991 static void
992 close_listeners(
993         int remove
994 )
995 {
996         int l;
997
998         for ( l = 0; slap_listeners[l] != NULL; l++ ) {
999                 if ( slap_listeners[l]->sl_sd != AC_SOCKET_INVALID ) {
1000                         if ( remove )
1001                                 slapd_remove( slap_listeners[l]->sl_sd, 0, 0 );
1002 #ifdef LDAP_PF_LOCAL
1003                         if ( slap_listeners[l]->sl_sa.sa_addr.sa_family == AF_LOCAL ) {
1004                                 unlink( slap_listeners[l]->sl_sa.sa_un_addr.sun_path );
1005                         }
1006 #endif /* LDAP_PF_LOCAL */
1007                         slapd_close( slap_listeners[l]->sl_sd );
1008                 }
1009                 if ( slap_listeners[l]->sl_url.bv_val )
1010                         ber_memfree( slap_listeners[l]->sl_url.bv_val );
1011                 if ( slap_listeners[l]->sl_name.bv_val )
1012                         ber_memfree( slap_listeners[l]->sl_name.bv_val );
1013                 free ( slap_listeners[l] );
1014                 slap_listeners[l] = NULL;
1015         }
1016 }
1017
1018
1019 static void *
1020 slapd_daemon_task(
1021         void *ptr
1022 )
1023 {
1024         int l;
1025         time_t  last_idle_check = 0;
1026         struct timeval idle;
1027
1028 #define SLAPD_IDLE_CHECK_LIMIT 4
1029
1030         if ( global_idletimeout > 0 ) {
1031                 last_idle_check = slap_get_time();
1032                 /* Set the select timeout.
1033                  * Don't just truncate, preserve the fractions of
1034                  * seconds to prevent sleeping for zero time.
1035                  */
1036                 idle.tv_sec = global_idletimeout/SLAPD_IDLE_CHECK_LIMIT;
1037                 idle.tv_usec = global_idletimeout - idle.tv_sec * SLAPD_IDLE_CHECK_LIMIT;
1038                 idle.tv_usec *= 1000000 / SLAPD_IDLE_CHECK_LIMIT;
1039         } else {
1040                 idle.tv_sec = 0;
1041                 idle.tv_usec = 0;
1042         }
1043
1044         for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1045                 if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1046                         continue;
1047 #ifdef LDAP_CONNECTIONLESS
1048                 /* Since this is connectionless, the data port is the
1049                  * listening port. The listen() and accept() calls
1050                  * are unnecessary.
1051                  */
1052                 if ( slap_listeners[l]->sl_is_udp ) {
1053                         slapd_add( slap_listeners[l]->sl_sd, 1 );
1054                         continue;
1055                 }
1056 #endif
1057
1058                 if ( listen( slap_listeners[l]->sl_sd, SLAPD_LISTEN ) == -1 ) {
1059                         int err = sock_errno();
1060
1061 #ifdef LDAP_PF_INET6
1062                         /* If error is EADDRINUSE, we are trying to listen to INADDR_ANY and
1063                          * we are already listening to in6addr_any, then we want to ignore
1064                          * this and continue.
1065                          */
1066                         if ( err == EADDRINUSE ) {
1067                                 int i;
1068                                 struct sockaddr_in sa = slap_listeners[l]->sl_sa.sa_in_addr;
1069                                 struct sockaddr_in6 sa6;
1070                                 
1071                                 if ( sa.sin_family == AF_INET &&
1072                                      sa.sin_addr.s_addr == htonl(INADDR_ANY) ) {
1073                                         for ( i = 0 ; i < l; i++ ) {
1074                                                 sa6 = slap_listeners[i]->sl_sa.sa_in6_addr;
1075                                                 if ( sa6.sin6_family == AF_INET6 &&
1076                                                      !memcmp( &sa6.sin6_addr, &in6addr_any, sizeof(struct in6_addr) ) )
1077                                                         break;
1078                                         }
1079
1080                                         if ( i < l ) {
1081                                                 /* We are already listening to in6addr_any */
1082                                                 Debug( LDAP_DEBUG_CONNS,
1083                                                        "daemon: Attempt to listen to 0.0.0.0 failed, already listening on ::, assuming IPv4 included\n",
1084                                                        0, 0, 0 );
1085                                                 slapd_close( slap_listeners[l]->sl_sd );
1086                                                 slap_listeners[l]->sl_sd = AC_SOCKET_INVALID;
1087                                                 continue;
1088                                         }
1089                                 }
1090                         }
1091 #endif                          
1092                         Debug( LDAP_DEBUG_ANY,
1093                                 "daemon: listen(%s, 5) failed errno=%d (%s)\n",
1094                                         slap_listeners[l]->sl_url.bv_val, err,
1095                                         sock_errstr(err) );
1096                         return( (void*)-1 );
1097                 }
1098
1099                 slapd_add( slap_listeners[l]->sl_sd, 0 );
1100         }
1101
1102 #ifdef HAVE_NT_SERVICE_MANAGER
1103         if ( started_event != NULL ) {
1104                 ldap_pvt_thread_cond_signal( &started_event );
1105         }
1106 #endif
1107         /* initialization complete. Here comes the loop. */
1108
1109         while ( !slapd_shutdown ) {
1110                 ber_socket_t i;
1111                 int ns;
1112                 int at;
1113                 ber_socket_t nfds, nrfds, nwfds;
1114 #define SLAPD_EBADF_LIMIT 16
1115                 int ebadf = 0;
1116
1117                 time_t  now;
1118
1119                 fd_set                  readfds;
1120                 fd_set                  writefds;
1121                 Sockaddr                from;
1122
1123                 struct timeval          tv;
1124                 struct timeval          *tvp;
1125
1126                 struct timeval          *cat;
1127                 time_t                          tdelta = 1;
1128                 struct re_s*            rtask;
1129                 now = slap_get_time();
1130
1131                 if( ( global_idletimeout > 0 ) &&
1132                         difftime( last_idle_check +
1133                         global_idletimeout/SLAPD_IDLE_CHECK_LIMIT, now ) < 0 ) {
1134                         connections_timeout_idle( now );
1135                         last_idle_check = now;
1136                 }
1137                 tv = idle;
1138
1139 #ifdef SIGHUP
1140                 if( slapd_gentle_shutdown ) {
1141                         ber_socket_t active;
1142
1143                         if( slapd_gentle_shutdown == 1 ) {
1144                                 Debug( LDAP_DEBUG_ANY, "slapd gentle shutdown\n", 0, 0, 0 );
1145                                 close_listeners( 1 );
1146                                 frontendDB->be_restrictops |= SLAP_RESTRICT_OP_WRITES;
1147                                 slapd_gentle_shutdown = 2;
1148                         }
1149
1150                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1151                         active = slap_daemon.sd_nactives;
1152                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1153                         if( active == 0 ) {
1154                                 slapd_shutdown = 2;
1155                                 break;
1156                         }
1157                 }
1158 #endif
1159
1160                 FD_ZERO( &writefds );
1161                 FD_ZERO( &readfds );
1162
1163                 at = 0;
1164
1165                 ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1166
1167 #ifdef FD_SET_MANUAL_COPY
1168                 for( s = 0; s < nfds; s++ ) {
1169                         if(FD_ISSET( &slap_sd_readers, s )) {
1170                                 FD_SET( s, &readfds );
1171                         }
1172                         if(FD_ISSET( &slap_sd_writers, s )) {
1173                                 FD_SET( s, &writefds );
1174                         }
1175                 }
1176 #else
1177                 AC_MEMCPY( &readfds, &slap_daemon.sd_readers, sizeof(fd_set) );
1178                 AC_MEMCPY( &writefds, &slap_daemon.sd_writers, sizeof(fd_set) );
1179 #endif
1180                 assert(!FD_ISSET(wake_sds[0], &readfds));
1181                 FD_SET( wake_sds[0], &readfds );
1182
1183                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1184                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1185                                 continue;
1186                         if ( slap_listeners[l]->sl_is_mute )
1187                                 FD_CLR( slap_listeners[l]->sl_sd, &readfds );
1188                         else
1189                         if (!FD_ISSET(slap_listeners[l]->sl_sd, &readfds))
1190                             FD_SET( slap_listeners[l]->sl_sd, &readfds );
1191                 }
1192
1193 #ifndef HAVE_WINSOCK
1194                 nfds = slap_daemon.sd_nfds;
1195 #else
1196                 nfds = dtblsize;
1197 #endif
1198                 if ( global_idletimeout && slap_daemon.sd_nactives )
1199                         at = 1;
1200
1201                 ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1202
1203                 if ( at 
1204 #if defined(HAVE_YIELDING_SELECT) || defined(NO_THREADS)
1205                         &&  ( tv.tv_sec || tv.tv_usec )
1206 #endif
1207                         )
1208                         tvp = &tv;
1209                 else
1210                         tvp = NULL;
1211
1212                 ldap_pvt_thread_mutex_lock( &syncrepl_rq.rq_mutex );
1213                 rtask = ldap_pvt_runqueue_next_sched( &syncrepl_rq, &cat );
1214                 while ( cat && cat->tv_sec && cat->tv_sec <= now ) {
1215                         if ( ldap_pvt_runqueue_isrunning( &syncrepl_rq, rtask )) {
1216                                 ldap_pvt_runqueue_resched( &syncrepl_rq, rtask, 0 );
1217                         } else {
1218                                 ldap_pvt_runqueue_runtask( &syncrepl_rq, rtask );
1219                                 ldap_pvt_runqueue_resched( &syncrepl_rq, rtask, 0 );
1220                                 ldap_pvt_thread_mutex_unlock( &syncrepl_rq.rq_mutex );
1221                                 ldap_pvt_thread_pool_submit( &connection_pool,
1222                                                                                         rtask->routine, (void *) rtask );
1223                                 ldap_pvt_thread_mutex_lock( &syncrepl_rq.rq_mutex );
1224                         }
1225                         rtask = ldap_pvt_runqueue_next_sched( &syncrepl_rq, &cat );
1226                 }
1227                 ldap_pvt_thread_mutex_unlock( &syncrepl_rq.rq_mutex );
1228
1229                 if ( cat != NULL ) {
1230                         time_t diff = difftime( cat->tv_sec, now );
1231                         if ( diff == 0 )
1232                                 diff = tdelta;
1233                         if ( tvp == NULL || diff < tv.tv_sec ) {
1234                                 tv.tv_sec = diff;
1235                                 tv.tv_usec = 0;
1236                                 tvp = &tv;
1237                         }
1238                 }
1239
1240                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1241                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID ||
1242                             slap_listeners[l]->sl_is_mute )
1243                                 continue;
1244
1245                         Debug( LDAP_DEBUG_CONNS,
1246                                 "daemon: select: listen=%d active_threads=%d tvp=%s\n",
1247                                         slap_listeners[l]->sl_sd, at,
1248                                         tvp == NULL ? "NULL" : "zero" );
1249                 }
1250
1251                 switch(ns = select( nfds, &readfds,
1252 #ifdef HAVE_WINSOCK
1253                         /* don't pass empty fd_set */
1254                         ( writefds.fd_count > 0 ? &writefds : NULL ),
1255 #else
1256                         &writefds,
1257 #endif
1258                         NULL, tvp ))
1259                 {
1260                 case -1: {      /* failure - try again */
1261                                 int err = sock_errno();
1262
1263                                 if( err == EBADF
1264 #ifdef WSAENOTSOCK
1265                                         /* you'd think this would be EBADF */
1266                                         || err == WSAENOTSOCK
1267 #endif
1268                                 ) {
1269                                         if (++ebadf < SLAPD_EBADF_LIMIT)
1270                                                 continue;
1271                                 }
1272
1273                                 if( err != EINTR ) {
1274                                         Debug( LDAP_DEBUG_CONNS,
1275                                                 "daemon: select failed (%d): %s\n",
1276                                                 err, sock_errstr(err), 0 );
1277                                         slapd_shutdown = 2;
1278                                 }
1279                         }
1280                         continue;
1281
1282                 case 0:         /* timeout - let threads run */
1283                         ebadf = 0;
1284                         Debug( LDAP_DEBUG_CONNS, "daemon: select timeout - yielding\n",
1285                             0, 0, 0 );
1286
1287                         ldap_pvt_thread_yield();
1288                         continue;
1289
1290                 default:        /* something happened - deal with it */
1291                         if( slapd_shutdown ) continue;
1292
1293                         ebadf = 0;
1294                         Debug( LDAP_DEBUG_CONNS, "daemon: activity on %d descriptors\n",
1295                                 ns, 0, 0 );
1296                         /* FALL THRU */
1297                 }
1298
1299                 if( FD_ISSET( wake_sds[0], &readfds ) ) {
1300                         char c[BUFSIZ];
1301                         tcp_read( wake_sds[0], c, sizeof(c) );
1302                         waking = 0;
1303                         ns--;
1304                         continue;
1305                 }
1306
1307                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1308                         ber_socket_t s;
1309                         socklen_t len = sizeof(from);
1310                         long id;
1311                         slap_ssf_t ssf = 0;
1312                         struct berval authid = BER_BVNULL;
1313 #ifdef SLAPD_RLOOKUPS
1314                         char hbuf[NI_MAXHOST];
1315 #endif
1316
1317                         char    *dnsname = NULL;
1318                         char    *peeraddr = NULL;
1319 #ifdef LDAP_PF_LOCAL
1320                         char peername[MAXPATHLEN + sizeof("PATH=")];
1321 #elif defined(LDAP_PF_INET6)
1322                         char peername[sizeof(
1323                                 "IP=ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff 65535")];
1324 #else
1325                         char peername[sizeof("IP=255.255.255.255:65336")];
1326 #endif /* LDAP_PF_LOCAL */
1327
1328                         peername[0] = '\0';
1329
1330                         if ( ns <= 0 ) break;
1331
1332                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1333                                 continue;
1334
1335                         if ( !FD_ISSET( slap_listeners[l]->sl_sd, &readfds ) )
1336                                 continue;
1337                         
1338                         ns--;
1339
1340 #ifdef LDAP_CONNECTIONLESS
1341                         if ( slap_listeners[l]->sl_is_udp ) {
1342                                 /* The first time we receive a query, we set this
1343                                  * up as a "connection". It remains open for the life
1344                                  * of the slapd.
1345                                  */
1346                                 if ( slap_listeners[l]->sl_is_udp < 2 ) {
1347                                         id = connection_init(
1348                                                 slap_listeners[l]->sl_sd,
1349                                                 slap_listeners[l], "", "",
1350                                                 CONN_IS_UDP, ssf, NULL );
1351                                     slap_listeners[l]->sl_is_udp++;
1352                                 }
1353                                 continue;
1354                         }
1355 #endif
1356
1357                         /* Don't need to look at this in the data loops */
1358                         FD_CLR( slap_listeners[l]->sl_sd, &readfds );
1359                         FD_CLR( slap_listeners[l]->sl_sd, &writefds );
1360
1361 #  ifdef LDAP_PF_LOCAL
1362                         /* FIXME: apparently accept doesn't fill
1363                          * the sun_path sun_path member */
1364                         from.sa_un_addr.sun_path[0] = '\0';
1365 #  endif /* LDAP_PF_LOCAL */
1366                         s = accept( slap_listeners[l]->sl_sd,
1367                                 (struct sockaddr *) &from, &len );
1368                         if ( s == AC_SOCKET_INVALID ) {
1369                                 int err = sock_errno();
1370
1371                                 if(
1372 #ifdef EMFILE
1373                                     err == EMFILE ||
1374 #endif
1375 #ifdef ENFILE
1376                                     err == ENFILE ||
1377 #endif
1378                                     0 )
1379                                 {
1380                                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1381                                         emfile++;
1382                                         /* Stop listening until an existing session closes */
1383                                         slap_listeners[l]->sl_is_mute = 1;
1384                                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1385                                 }
1386
1387                                 Debug( LDAP_DEBUG_ANY,
1388                                         "daemon: accept(%ld) failed errno=%d (%s)\n",
1389                                         (long) slap_listeners[l]->sl_sd, err,
1390                                         sock_errstr(err) );
1391                                 ldap_pvt_thread_yield();
1392                                 continue;
1393                         }
1394
1395 #ifndef HAVE_WINSOCK
1396                         /* make sure descriptor number isn't too great */
1397                         if ( s >= dtblsize ) {
1398                                 Debug( LDAP_DEBUG_ANY,
1399                                         "daemon: %ld beyond descriptor table size %ld\n",
1400                                         (long) s, (long) dtblsize, 0 );
1401
1402                                 slapd_close(s);
1403                                 ldap_pvt_thread_yield();
1404                                 continue;
1405                         }
1406 #endif
1407
1408 #ifdef LDAP_DEBUG
1409                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1410
1411                         /* newly accepted stream should not be in any of the FD SETS */
1412                         assert( !FD_ISSET( s, &slap_daemon.sd_actives) );
1413                         assert( !FD_ISSET( s, &slap_daemon.sd_readers) );
1414                         assert( !FD_ISSET( s, &slap_daemon.sd_writers) );
1415
1416                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1417 #endif
1418
1419 #if defined( SO_KEEPALIVE ) || defined( TCP_NODELAY )
1420 #ifdef LDAP_PF_LOCAL
1421                         /* for IPv4 and IPv6 sockets only */
1422                         if ( from.sa_addr.sa_family != AF_LOCAL )
1423 #endif /* LDAP_PF_LOCAL */
1424                         {
1425                                 int rc;
1426                                 int tmp;
1427 #ifdef SO_KEEPALIVE
1428                                 /* enable keep alives */
1429                                 tmp = 1;
1430                                 rc = setsockopt( s, SOL_SOCKET, SO_KEEPALIVE,
1431                                         (char *) &tmp, sizeof(tmp) );
1432                                 if ( rc == AC_SOCKET_ERROR ) {
1433                                         int err = sock_errno();
1434                                         Debug( LDAP_DEBUG_ANY,
1435                                                 "slapd(%ld): setsockopt(SO_KEEPALIVE) failed "
1436                                                 "errno=%d (%s)\n", (long) s, err, sock_errstr(err) );
1437                                 }
1438 #endif
1439 #ifdef TCP_NODELAY
1440                                 /* enable no delay */
1441                                 tmp = 1;
1442                                 rc = setsockopt( s, IPPROTO_TCP, TCP_NODELAY,
1443                                         (char *)&tmp, sizeof(tmp) );
1444                                 if ( rc == AC_SOCKET_ERROR ) {
1445                                         int err = sock_errno();
1446                                         Debug( LDAP_DEBUG_ANY,
1447                                                 "slapd(%ld): setsockopt(TCP_NODELAY) failed "
1448                                                 "errno=%d (%s)\n", (long) s, err, sock_errstr(err) );
1449                                 }
1450 #endif
1451                         }
1452 #endif
1453
1454                         Debug( LDAP_DEBUG_CONNS, "daemon: new connection on %ld\n",
1455                                 (long) s, 0, 0 );
1456                         switch ( from.sa_addr.sa_family ) {
1457 #  ifdef LDAP_PF_LOCAL
1458                         case AF_LOCAL:
1459                                 /* FIXME: apparently accept doesn't fill
1460                                  * the sun_path sun_path member */
1461                                 if ( from.sa_un_addr.sun_path[0] == '\0' ) {
1462                                         AC_MEMCPY( from.sa_un_addr.sun_path,
1463                                                         slap_listeners[l]->sl_sa.sa_un_addr.sun_path,
1464                                                         sizeof( from.sa_un_addr.sun_path ) );
1465                                 }
1466
1467                                 sprintf( peername, "PATH=%s", from.sa_un_addr.sun_path );
1468                                 ssf = local_ssf;
1469                                 {
1470                                         uid_t uid;
1471                                         gid_t gid;
1472
1473                                         if( getpeereid( s, &uid, &gid ) == 0 ) {
1474                                                 authid.bv_val = ch_malloc(
1475                                                         sizeof("uidnumber=4294967295+gidnumber=4294967295,"
1476                                                         "cn=peercred,cn=external,cn=auth"));
1477                                                 authid.bv_len = sprintf( authid.bv_val,
1478                                                         "uidnumber=%d+gidnumber=%d,"
1479                                                         "cn=peercred,cn=external,cn=auth",
1480                                                         (int) uid, (int) gid);
1481                                         }
1482                                 }
1483                                 dnsname = "local";
1484                                 break;
1485 #endif /* LDAP_PF_LOCAL */
1486
1487 #  ifdef LDAP_PF_INET6
1488                         case AF_INET6:
1489                         if ( IN6_IS_ADDR_V4MAPPED(&from.sa_in6_addr.sin6_addr) ) {
1490                                 peeraddr = inet_ntoa( *((struct in_addr *)
1491                                                         &from.sa_in6_addr.sin6_addr.s6_addr[12]) );
1492                                 sprintf( peername, "IP=%s:%d",
1493                                          peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1494                                          (unsigned) ntohs( from.sa_in6_addr.sin6_port ) );
1495                         } else {
1496                                 char addr[INET6_ADDRSTRLEN];
1497
1498                                 peeraddr = (char *) inet_ntop( AF_INET6,
1499                                                       &from.sa_in6_addr.sin6_addr,
1500                                                       addr, sizeof addr );
1501                                 sprintf( peername, "IP=%s %d",
1502                                          peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1503                                          (unsigned) ntohs( from.sa_in6_addr.sin6_port ) );
1504                         }
1505                         break;
1506 #  endif /* LDAP_PF_INET6 */
1507
1508                         case AF_INET:
1509                         peeraddr = inet_ntoa( from.sa_in_addr.sin_addr );
1510                         sprintf( peername, "IP=%s:%d",
1511                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1512                                 (unsigned) ntohs( from.sa_in_addr.sin_port ) );
1513                                 break;
1514
1515                         default:
1516                                 slapd_close(s);
1517                                 continue;
1518                         }
1519
1520                         if ( ( from.sa_addr.sa_family == AF_INET )
1521 #ifdef LDAP_PF_INET6
1522                                 || ( from.sa_addr.sa_family == AF_INET6 )
1523 #endif
1524                         ) {
1525 #ifdef SLAPD_RLOOKUPS
1526                                 if ( use_reverse_lookup ) {
1527                                         char *herr;
1528                                         if (ldap_pvt_get_hname( (const struct sockaddr *)&from, len, hbuf,
1529                                                 sizeof(hbuf), &herr ) == 0) {
1530                                                 ldap_pvt_str2lower( hbuf );
1531                                                 dnsname = hbuf;
1532                                         }
1533                                 }
1534 #else
1535                                 dnsname = NULL;
1536 #endif /* SLAPD_RLOOKUPS */
1537
1538 #ifdef HAVE_TCPD
1539                                 if ( !hosts_ctl("slapd",
1540                                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1541                                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1542                                                 SLAP_STRING_UNKNOWN ))
1543                                 {
1544                                         /* DENY ACCESS */
1545                                         Statslog( LDAP_DEBUG_STATS,
1546                                                 "fd=%ld DENIED from %s (%s)\n",
1547                                                 (long) s,
1548                                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1549                                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1550                                                 0, 0 );
1551                                         slapd_close(s);
1552                                         continue;
1553                                 }
1554 #endif /* HAVE_TCPD */
1555                         }
1556
1557                         id = connection_init(s,
1558                                 slap_listeners[l],
1559                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1560                                 peername,
1561 #ifdef HAVE_TLS
1562                                 slap_listeners[l]->sl_is_tls ? CONN_IS_TLS : 0,
1563 #else
1564                                 0,
1565 #endif
1566                                 ssf,
1567                                 authid.bv_val ? &authid : NULL );
1568
1569                         if( authid.bv_val ) ch_free(authid.bv_val);
1570
1571                         if( id < 0 ) {
1572                                 Debug( LDAP_DEBUG_ANY,
1573                                         "daemon: connection_init(%ld, %s, %s) "
1574                                         "failed.\n",
1575                                         (long) s,
1576                                         peername,
1577                                         slap_listeners[l]->sl_name.bv_val );
1578                                 slapd_close(s);
1579                                 continue;
1580                         }
1581
1582                         Statslog( LDAP_DEBUG_STATS,
1583                                 "conn=%ld fd=%ld ACCEPT from %s (%s)\n",
1584                                 id, (long) s,
1585                                 peername,
1586                                 slap_listeners[l]->sl_name.bv_val,
1587                                 0 );
1588
1589                         slapd_add( s, 1 );
1590                         continue;
1591                 }
1592
1593                 /* bypass the following tests if no descriptors left */
1594                 if ( ns <= 0 ) {
1595                         ldap_pvt_thread_yield();
1596                         continue;
1597                 }
1598
1599                 Debug( LDAP_DEBUG_CONNS, "daemon: activity on:", 0, 0, 0 );
1600 #ifdef HAVE_WINSOCK
1601                 nrfds = readfds.fd_count;
1602                 nwfds = writefds.fd_count;
1603                 for ( i = 0; i < readfds.fd_count; i++ ) {
1604                         Debug( LDAP_DEBUG_CONNS, " %d%s",
1605                                 readfds.fd_array[i], "r", 0 );
1606                 }
1607                 for ( i = 0; i < writefds.fd_count; i++ ) {
1608                         Debug( LDAP_DEBUG_CONNS, " %d%s",
1609                                 writefds.fd_array[i], "w", 0 );
1610                 }
1611
1612 #else
1613                 nrfds = 0;
1614                 nwfds = 0;
1615                 for ( i = 0; i < nfds; i++ ) {
1616                         int     r, w;
1617
1618                         r = FD_ISSET( i, &readfds );
1619                         w = FD_ISSET( i, &writefds );
1620                         if ( r || w ) {
1621                                 Debug( LDAP_DEBUG_CONNS, " %d%s%s", i,
1622                                     r ? "r" : "", w ? "w" : "" );
1623                                 if ( r ) {
1624                                         nrfds++;
1625                                         ns--;
1626                                 }
1627                                 if ( w ) {
1628                                         nwfds++;
1629                                         ns--;
1630                                 }
1631                         }
1632                         if ( ns <= 0 ) break;
1633                 }
1634 #endif
1635                 Debug( LDAP_DEBUG_CONNS, "\n", 0, 0, 0 );
1636
1637
1638                 /* loop through the writers */
1639                 for ( i = 0; nwfds > 0; i++ )
1640                 {
1641                         ber_socket_t wd;
1642 #ifdef HAVE_WINSOCK
1643                         wd = writefds.fd_array[i];
1644 #else
1645                         if( ! FD_ISSET( i, &writefds ) ) {
1646                                 continue;
1647                         }
1648                         wd = i;
1649 #endif
1650                         nwfds--;
1651
1652                         Debug( LDAP_DEBUG_CONNS,
1653                                 "daemon: write active on %d\n",
1654                                 wd, 0, 0 );
1655                         /*
1656                          * NOTE: it is possible that the connection was closed
1657                          * and that the stream is now inactive.
1658                          * connection_write() must valid the stream is still
1659                          * active.
1660                          */
1661
1662                         if ( connection_write( wd ) < 0 ) {
1663                                 FD_CLR( (unsigned) wd, &readfds );
1664                                 slapd_close( wd );
1665                         }
1666                 }
1667
1668                 for ( i = 0; nrfds > 0; i++ )
1669                 {
1670                         ber_socket_t rd;
1671 #ifdef HAVE_WINSOCK
1672                         rd = readfds.fd_array[i];
1673 #else
1674                         if( ! FD_ISSET( i, &readfds ) ) {
1675                                 continue;
1676                         }
1677                         rd = i;
1678 #endif
1679                         nrfds--;
1680
1681                         Debug ( LDAP_DEBUG_CONNS,
1682                                 "daemon: read activity on %d\n", rd, 0, 0 );
1683                         /*
1684                          * NOTE: it is possible that the connection was closed
1685                          * and that the stream is now inactive.
1686                          * connection_read() must valid the stream is still
1687                          * active.
1688                          */
1689
1690                         if ( connection_read( rd ) < 0 ) {
1691                                 slapd_close( rd );
1692                         }
1693                 }
1694                 ldap_pvt_thread_yield();
1695         }
1696
1697         if( slapd_shutdown == 1 ) {
1698                 Debug( LDAP_DEBUG_TRACE,
1699                         "daemon: shutdown requested and initiated.\n",
1700                         0, 0, 0 );
1701
1702         } else if ( slapd_shutdown == 2 ) {
1703 #ifdef HAVE_NT_SERVICE_MANAGER
1704                         Debug( LDAP_DEBUG_TRACE,
1705                                "daemon: shutdown initiated by Service Manager.\n",
1706                                0, 0, 0);
1707 #else /* !HAVE_NT_SERVICE_MANAGER */
1708                         Debug( LDAP_DEBUG_TRACE,
1709                                "daemon: abnormal condition, shutdown initiated.\n",
1710                                0, 0, 0 );
1711 #endif /* !HAVE_NT_SERVICE_MANAGER */
1712         } else {
1713                 Debug( LDAP_DEBUG_TRACE,
1714                        "daemon: no active streams, shutdown initiated.\n",
1715                        0, 0, 0 );
1716         }
1717
1718         if( slapd_gentle_shutdown != 2 ) {
1719                 close_listeners ( 0 );
1720         }
1721
1722         free ( slap_listeners );
1723         slap_listeners = NULL;
1724
1725         if( !slapd_gentle_shutdown ) {
1726                 slapd_abrupt_shutdown = 1;
1727                 connections_shutdown();
1728         }
1729
1730         Debug( LDAP_DEBUG_ANY,
1731             "slapd shutdown: waiting for %d threads to terminate\n",
1732             ldap_pvt_thread_pool_backload(&connection_pool), 0, 0 );
1733         ldap_pvt_thread_pool_destroy(&connection_pool, 1);
1734
1735         return NULL;
1736 }
1737
1738
1739 int slapd_daemon( void )
1740 {
1741         int rc;
1742
1743         connections_init();
1744
1745 #define SLAPD_LISTENER_THREAD 1
1746 #if defined( SLAPD_LISTENER_THREAD )
1747         {
1748                 ldap_pvt_thread_t       listener_tid;
1749
1750                 /* listener as a separate THREAD */
1751                 rc = ldap_pvt_thread_create( &listener_tid,
1752                         0, slapd_daemon_task, NULL );
1753
1754                 if ( rc != 0 ) {
1755                         Debug( LDAP_DEBUG_ANY,
1756                         "listener ldap_pvt_thread_create failed (%d)\n", rc, 0, 0 );
1757                         return rc;
1758                 }
1759  
1760                 /* wait for the listener thread to complete */
1761                 ldap_pvt_thread_join( listener_tid, (void *) NULL );
1762         }
1763 #else
1764         /* experimental code */
1765         slapd_daemon_task( NULL );
1766 #endif
1767
1768         return 0;
1769
1770 }
1771
1772 int sockinit(void)
1773 {
1774 #if defined( HAVE_WINSOCK2 )
1775     WORD wVersionRequested;
1776         WSADATA wsaData;
1777         int err;
1778
1779         wVersionRequested = MAKEWORD( 2, 0 );
1780
1781         err = WSAStartup( wVersionRequested, &wsaData );
1782         if ( err != 0 ) {
1783                 /* Tell the user that we couldn't find a usable */
1784                 /* WinSock DLL.                                  */
1785                 return -1;
1786         }
1787
1788         /* Confirm that the WinSock DLL supports 2.0.*/
1789         /* Note that if the DLL supports versions greater    */
1790         /* than 2.0 in addition to 2.0, it will still return */
1791         /* 2.0 in wVersion since that is the version we      */
1792         /* requested.                                        */
1793
1794         if ( LOBYTE( wsaData.wVersion ) != 2 ||
1795                 HIBYTE( wsaData.wVersion ) != 0 )
1796         {
1797             /* Tell the user that we couldn't find a usable */
1798             /* WinSock DLL.                                  */
1799             WSACleanup();
1800             return -1;
1801         }
1802
1803         /* The WinSock DLL is acceptable. Proceed. */
1804 #elif defined( HAVE_WINSOCK )
1805         WSADATA wsaData;
1806         if ( WSAStartup( 0x0101, &wsaData ) != 0 ) {
1807             return -1;
1808         }
1809 #endif
1810         return 0;
1811 }
1812
1813 int sockdestroy(void)
1814 {
1815 #if defined( HAVE_WINSOCK2 ) || defined( HAVE_WINSOCK )
1816         WSACleanup();
1817 #endif
1818         return 0;
1819 }
1820
1821 RETSIGTYPE
1822 slap_sig_shutdown( int sig )
1823 {
1824 #if 0
1825         Debug(LDAP_DEBUG_TRACE, "slap_sig_shutdown: signal %d\n", sig, 0, 0);
1826 #endif
1827
1828         /*
1829          * If the NT Service Manager is controlling the server, we don't
1830          * want SIGBREAK to kill the server. For some strange reason,
1831          * SIGBREAK is generated when a user logs out.
1832          */
1833
1834 #if HAVE_NT_SERVICE_MANAGER && SIGBREAK
1835         if (is_NT_Service && sig == SIGBREAK)
1836                 ;
1837         else
1838 #endif
1839 #ifdef SIGHUP
1840         if (sig == SIGHUP && global_gentlehup && slapd_gentle_shutdown == 0)
1841                 slapd_gentle_shutdown = 1;
1842         else
1843 #endif
1844         slapd_shutdown = 1;
1845         WAKE_LISTENER(1);
1846
1847         /* reinstall self */
1848         (void) SIGNAL_REINSTALL( sig, slap_sig_shutdown );
1849 }
1850
1851 RETSIGTYPE
1852 slap_sig_wake( int sig )
1853 {
1854         WAKE_LISTENER(1);
1855
1856         /* reinstall self */
1857         (void) SIGNAL_REINSTALL( sig, slap_sig_wake );
1858 }
1859
1860
1861 void slapd_add_internal(ber_socket_t s, int isactive) {
1862         slapd_add(s, isactive);
1863 }
1864
1865 Listener ** slapd_get_listeners(void) {
1866         return slap_listeners;
1867 }
1868
1869 void slap_wake_listener()
1870 {
1871         WAKE_LISTENER(1);
1872 }