]> git.sur5r.net Git - openldap/blob - servers/slapd/daemon.c
ITS#2607: improve socket() error logging with AF info
[openldap] / servers / slapd / daemon.c
1 /* $OpenLDAP$ */
2 /*
3  * Copyright 1998-2003 The OpenLDAP Foundation, All Rights Reserved.
4  * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
5  */
6
7 #include "portable.h"
8
9 #include <stdio.h>
10
11 #include <ac/ctype.h>
12 #include <ac/errno.h>
13 #include <ac/socket.h>
14 #include <ac/string.h>
15 #include <ac/time.h>
16 #include <ac/unistd.h>
17
18 #include "ldap_pvt.h"
19 #include "ldap_pvt_thread.h"
20 #include "lutil.h"
21 #include "slap.h"
22
23 #ifdef LDAP_SYNCREPL
24 #include "ldap_rq.h"
25 #endif
26
27 #ifdef HAVE_TCPD
28 #include <tcpd.h>
29 #define SLAP_STRING_UNKNOWN     STRING_UNKNOWN
30
31 int allow_severity = LOG_INFO;
32 int deny_severity = LOG_NOTICE;
33 #else /* ! TCP Wrappers */
34 #define SLAP_STRING_UNKNOWN     "unknown"
35 #endif /* ! TCP Wrappers */
36
37 #ifdef LDAP_PF_LOCAL
38 #include <sys/stat.h>
39 /* this should go in <ldap.h> as soon as it is accepted */
40 #define LDAPI_MOD_URLEXT                "x-mod"
41 #endif /* LDAP_PF_LOCAL */
42
43 #ifdef LDAP_PF_INET6
44 int slap_inet4or6 = AF_UNSPEC;
45 #else
46 int slap_inet4or6 = AF_INET;
47 #endif
48
49 /* globals */
50 time_t starttime;
51 ber_socket_t dtblsize;
52
53 Listener **slap_listeners = NULL;
54
55 #define SLAPD_LISTEN 10
56
57 static ber_socket_t wake_sds[2];
58 static int emfile;
59
60 #if defined(NO_THREADS) || defined(HAVE_GNU_PTH)
61 static int waking;
62 #define WAKE_LISTENER(w) \
63 ((w && !waking) ? tcp_write( wake_sds[1], "0", 1 ), waking=1 : 0)
64 #else
65 #define WAKE_LISTENER(w) \
66 do { if (w) tcp_write( wake_sds[1], "0", 1 ); } while(0)
67 #endif
68
69 #ifndef HAVE_WINSOCK
70 static
71 #endif
72 volatile sig_atomic_t slapd_shutdown = 0, slapd_gentle_shutdown = 0;
73
74 static struct slap_daemon {
75         ldap_pvt_thread_mutex_t sd_mutex;
76
77         ber_socket_t sd_nactives;
78
79 #ifndef HAVE_WINSOCK
80         /* In winsock, accept() returns values higher than dtblsize
81                 so don't bother with this optimization */
82         int sd_nfds;
83 #endif
84
85         fd_set sd_actives;
86         fd_set sd_readers;
87         fd_set sd_writers;
88 } slap_daemon;
89
90
91
92 #ifdef HAVE_SLP
93 /*
94  * SLP related functions
95  */
96 #include <slp.h>
97
98 #define LDAP_SRVTYPE_PREFIX "service:ldap://"
99 #define LDAPS_SRVTYPE_PREFIX "service:ldaps://"
100 static char** slapd_srvurls = NULL;
101 static SLPHandle slapd_hslp = 0;
102
103 void slapd_slp_init( const char* urls ) {
104         int i;
105
106         slapd_srvurls = ldap_str2charray( urls, " " );
107
108         if( slapd_srvurls == NULL ) return;
109
110         /* find and expand INADDR_ANY URLs */
111         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
112                 if( strcmp( slapd_srvurls[i], "ldap:///" ) == 0) {
113                         char *host = ldap_pvt_get_fqdn( NULL );
114                         if ( host != NULL ) {
115                                 slapd_srvurls[i] = (char *) ch_realloc( slapd_srvurls[i],
116                                         strlen( host ) +
117                                         sizeof( LDAP_SRVTYPE_PREFIX ) );
118                                 strcpy( lutil_strcopy(slapd_srvurls[i],
119                                         LDAP_SRVTYPE_PREFIX ), host );
120
121                                 ch_free( host );
122                         }
123
124                 } else if ( strcmp( slapd_srvurls[i], "ldaps:///" ) == 0) {
125                         char *host = ldap_pvt_get_fqdn( NULL );
126                         if ( host != NULL ) {
127                                 slapd_srvurls[i] = (char *) ch_realloc( slapd_srvurls[i],
128                                         strlen( host ) +
129                                         sizeof( LDAPS_SRVTYPE_PREFIX ) );
130                                 strcpy( lutil_strcopy(slapd_srvurls[i],
131                                         LDAPS_SRVTYPE_PREFIX ), host );
132
133                                 ch_free( host );
134                         }
135                 }
136         }
137
138         /* open the SLP handle */
139         SLPOpen( "en", 0, &slapd_hslp );
140 }
141
142 void slapd_slp_deinit() {
143         if( slapd_srvurls == NULL ) return;
144
145         ldap_charray_free( slapd_srvurls );
146         slapd_srvurls = NULL;
147
148         /* close the SLP handle */
149         SLPClose( slapd_hslp );
150 }
151
152 void slapd_slp_regreport(
153         SLPHandle hslp,
154         SLPError errcode,
155         void* cookie )
156 {
157         /* empty report */
158 }
159
160 void slapd_slp_reg() {
161         int i;
162
163         if( slapd_srvurls == NULL ) return;
164
165         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
166                 if( strncmp( slapd_srvurls[i], LDAP_SRVTYPE_PREFIX,
167                                 sizeof( LDAP_SRVTYPE_PREFIX ) - 1 ) == 0 ||
168                     strncmp( slapd_srvurls[i], LDAPS_SRVTYPE_PREFIX,
169                                 sizeof( LDAPS_SRVTYPE_PREFIX ) - 1 ) == 0 )
170                 {
171                         SLPReg( slapd_hslp,
172                                 slapd_srvurls[i],
173                                 SLP_LIFETIME_MAXIMUM,
174                                 "ldap",
175                                 "",
176                                 1,
177                                 slapd_slp_regreport,
178                                 NULL );
179                 }
180         }
181 }
182
183 void slapd_slp_dereg() {
184         int i;
185
186         if( slapd_srvurls == NULL ) return;
187
188         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
189                 SLPDereg( slapd_hslp,
190                         slapd_srvurls[i],
191                         slapd_slp_regreport,
192                         NULL );
193         }
194 }
195 #endif /* HAVE_SLP */
196
197 /*
198  * Add a descriptor to daemon control
199  */
200 static void slapd_add(ber_socket_t s) {
201         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
202
203         assert( !FD_ISSET( s, &slap_daemon.sd_actives ));
204         assert( !FD_ISSET( s, &slap_daemon.sd_readers ));
205         assert( !FD_ISSET( s, &slap_daemon.sd_writers ));
206
207 #ifndef HAVE_WINSOCK
208         if (s >= slap_daemon.sd_nfds) {
209                 slap_daemon.sd_nfds = s + 1;
210         }
211 #endif
212
213         slap_daemon.sd_nactives++;
214
215         FD_SET( s, &slap_daemon.sd_actives );
216         FD_SET( s, &slap_daemon.sd_readers );
217
218 #ifdef NEW_LOGGING
219         LDAP_LOG( CONNECTION, DETAIL1, 
220                 "slapd_add: added %ld%s%s\n", (long)s,
221                 FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
222                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : "" );
223 #else
224         Debug( LDAP_DEBUG_CONNS, "daemon: added %ld%s%s\n",
225                 (long) s,
226             FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
227                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : "" );
228 #endif
229         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
230 }
231
232 /*
233  * Remove the descriptor from daemon control
234  */
235 void slapd_remove(ber_socket_t s, int wake) {
236         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
237
238         slap_daemon.sd_nactives--;
239
240 #ifdef NEW_LOGGING
241         LDAP_LOG( CONNECTION, DETAIL1, 
242                 "slapd_remove: removing %ld%s%s\n", (long) s,
243                 FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
244                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : ""  );
245 #else
246         Debug( LDAP_DEBUG_CONNS, "daemon: removing %ld%s%s\n",
247                 (long) s,
248             FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
249                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : "" );
250 #endif
251         FD_CLR( s, &slap_daemon.sd_actives );
252         FD_CLR( s, &slap_daemon.sd_readers );
253         FD_CLR( s, &slap_daemon.sd_writers );
254
255         /* If we ran out of file descriptors, we dropped a listener from
256          * the select() loop. Now that we're removing a session from our
257          * control, we can try to resume a dropped listener to use.
258          */
259         if ( emfile ) {
260                 int i;
261                 for ( i = 0; slap_listeners[i] != NULL; i++ ) {
262                         if ( slap_listeners[i]->sl_sd != AC_SOCKET_INVALID ) {
263                                 if ( slap_listeners[i]->sl_sd == s ) continue;
264                                 if ( slap_listeners[i]->sl_is_mute ) {
265                                         slap_listeners[i]->sl_is_mute = 0;
266                                         emfile--;
267                                         break;
268                                 }
269                         }
270                 }
271                 /* Walked the entire list without enabling anything; emfile
272                  * counter is stale. Reset it.
273                  */
274                 if ( slap_listeners[i] == NULL )
275                         emfile = 0;
276         }
277         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
278         WAKE_LISTENER(wake || slapd_gentle_shutdown == 2);
279 }
280
281 void slapd_clr_write(ber_socket_t s, int wake) {
282         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
283
284         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
285         FD_CLR( s, &slap_daemon.sd_writers );
286
287         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
288         WAKE_LISTENER(wake);
289 }
290
291 void slapd_set_write(ber_socket_t s, int wake) {
292         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
293
294         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
295         if (!FD_ISSET(s, &slap_daemon.sd_writers))
296             FD_SET( (unsigned) s, &slap_daemon.sd_writers );
297
298         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
299         WAKE_LISTENER(wake);
300 }
301
302 void slapd_clr_read(ber_socket_t s, int wake) {
303         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
304
305         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
306         FD_CLR( s, &slap_daemon.sd_readers );
307
308         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
309         WAKE_LISTENER(wake);
310 }
311
312 void slapd_set_read(ber_socket_t s, int wake) {
313         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
314
315         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
316         if (!FD_ISSET(s, &slap_daemon.sd_readers))
317             FD_SET( s, &slap_daemon.sd_readers );
318
319         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
320         WAKE_LISTENER(wake);
321 }
322
323 static void slapd_close(ber_socket_t s) {
324 #ifdef NEW_LOGGING
325         LDAP_LOG( CONNECTION, DETAIL1, "slapd_close: closing %ld\n", (long)s, 0, 0);
326 #else
327         Debug( LDAP_DEBUG_CONNS, "daemon: closing %ld\n",
328                 (long) s, 0, 0 );
329 #endif
330         tcp_close(s);
331 }
332
333 static void slap_free_listener_addresses(struct sockaddr **sal)
334 {
335         struct sockaddr **sap;
336
337         if (sal == NULL) {
338                 return;
339         }
340
341         for (sap = sal; *sap != NULL; sap++) {
342                 ch_free(*sap);
343         }
344
345         ch_free(sal);
346 }
347
348 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
349 static int get_url_perms(
350         char    **exts,
351         mode_t  *perms,
352         int     *crit )
353 {
354         int     i;
355
356         assert( exts );
357         assert( perms );
358         assert( crit );
359
360         *crit = 0;
361         for ( i = 0; exts[ i ]; i++ ) {
362                 char    *type = exts[ i ];
363                 int     c = 0;
364
365                 if ( type[ 0 ] == '!' ) {
366                         c = 1;
367                         type++;
368                 }
369
370                 if ( strncasecmp( type, LDAPI_MOD_URLEXT "=", sizeof(LDAPI_MOD_URLEXT "=") - 1 ) == 0 ) {
371                         char    *value = type
372                                 + ( sizeof(LDAPI_MOD_URLEXT "=") - 1 );
373                         mode_t  p = 0;
374                         int     j;
375
376                         switch (strlen(value)) {
377                         case 4:
378                                 /* skip leading '0' */
379                                 if ( value[ 0 ] != '0' ) {
380                                         return LDAP_OTHER;
381                                 }
382                                 value++;
383
384                         case 3:
385                                 for ( j = 0; j < 3; j++) {
386                                         int     v;
387
388                                         v = value[ j ] - '0';
389
390                                         if ( v < 0 || v > 7 ) {
391                                                 return LDAP_OTHER;
392                                         }
393
394                                         p |= v << 3*(2-j);
395                                 }
396                                 break;
397
398                         case 10:
399                                 for ( j = 1; j < 10; j++ ) {
400                                         static mode_t   m[] = { 0, 
401                                                 S_IRUSR, S_IWUSR, S_IXUSR,
402                                                 S_IRGRP, S_IWGRP, S_IXGRP,
403                                                 S_IROTH, S_IWOTH, S_IXOTH
404                                         };
405                                         static char     c[] = "-rwxrwxrwx"; 
406
407                                         if ( value[ j ] == c[ j ] ) {
408                                                 p |= m[ j ];
409         
410                                         } else if ( value[ j ] != '-' ) {
411                                                 return LDAP_OTHER;
412                                         }
413                                 }
414                                 break;
415
416                         default:
417                                 return LDAP_OTHER;
418                         } 
419
420                         *crit = c;
421                         *perms = p;
422
423                         return LDAP_SUCCESS;
424                 }
425         }
426
427         return LDAP_OTHER;
428 }
429 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
430
431 /* port = 0 indicates AF_LOCAL */
432 static int slap_get_listener_addresses(
433         const char *host,
434         unsigned short port,
435         struct sockaddr ***sal)
436 {
437         struct sockaddr **sap;
438
439 #ifdef LDAP_PF_LOCAL
440         if ( port == 0 ) {
441                 *sal = ch_malloc(2 * sizeof(void *));
442                 if (*sal == NULL) {
443                         return -1;
444                 }
445
446                 sap = *sal;
447                 *sap = ch_malloc(sizeof(struct sockaddr_un));
448                 if (*sap == NULL)
449                         goto errexit;
450                 sap[1] = NULL;
451
452                 if ( strlen(host) >
453                      (sizeof(((struct sockaddr_un *)*sap)->sun_path) - 1) ) {
454 #ifdef NEW_LOGGING
455                         LDAP_LOG( CONNECTION, INFO, 
456                                 "slap_get_listener_addresses: domain socket path (%s) "
457                                 "too long in URL\n", host, 0, 0 );
458 #else
459                         Debug( LDAP_DEBUG_ANY,
460                                "daemon: domain socket path (%s) too long in URL",
461                                host, 0, 0);
462 #endif
463                         goto errexit;
464                 }
465
466                 (void)memset( (void *)*sap, '\0', sizeof(struct sockaddr_un) );
467                 (*sap)->sa_family = AF_LOCAL;
468                 strcpy( ((struct sockaddr_un *)*sap)->sun_path, host );
469         } else
470 #endif
471         {
472 #ifdef HAVE_GETADDRINFO
473                 struct addrinfo hints, *res, *sai;
474                 int n, err;
475                 char serv[7];
476
477                 memset( &hints, '\0', sizeof(hints) );
478                 hints.ai_flags = AI_PASSIVE;
479                 hints.ai_socktype = SOCK_STREAM;
480                 hints.ai_family = slap_inet4or6;
481                 snprintf(serv, sizeof serv, "%d", port);
482
483                 if ( (err = getaddrinfo(host, serv, &hints, &res)) ) {
484 #ifdef NEW_LOGGING
485                         LDAP_LOG( CONNECTION, INFO, 
486                                    "slap_get_listener_addresses: getaddrinfo failed: %s\n",
487                                    AC_GAI_STRERROR(err), 0, 0 );
488 #else
489                         Debug( LDAP_DEBUG_ANY, "daemon: getaddrinfo failed: %s\n",
490                                 AC_GAI_STRERROR(err), 0, 0);
491 #endif
492                         return -1;
493                 }
494
495                 sai = res;
496                 for (n=2; (sai = sai->ai_next) != NULL; n++) {
497                         /* EMPTY */ ;
498                 }
499                 *sal = ch_calloc(n, sizeof(void *));
500                 if (*sal == NULL) {
501                         return -1;
502                 }
503
504                 sap = *sal;
505                 *sap = NULL;
506
507                 for ( sai=res; sai; sai=sai->ai_next ) {
508                         if( sai->ai_addr == NULL ) {
509 #ifdef NEW_LOGGING
510                                 LDAP_LOG( CONNECTION, INFO,
511                                         "slap_get_listener_addresses: "
512                                         "getaddrinfo ai_addr is NULL?\n", 0, 0, 0 );
513 #else
514                                 Debug( LDAP_DEBUG_ANY, "slap_get_listener_addresses: "
515                                         "getaddrinfo ai_addr is NULL?\n", 0, 0, 0 );
516 #endif
517                                 freeaddrinfo(res);
518                                 goto errexit;
519                         }
520
521                         switch (sai->ai_family) {
522 #  ifdef LDAP_PF_INET6
523                         case AF_INET6:
524                                 *sap = ch_malloc(sizeof(struct sockaddr_in6));
525                                 if (*sap == NULL) {
526                                         freeaddrinfo(res);
527                                         goto errexit;
528                                 }
529                                 *(struct sockaddr_in6 *)*sap =
530                                         *((struct sockaddr_in6 *)sai->ai_addr);
531                                 break;
532 #  endif
533                         case AF_INET:
534                                 *sap = ch_malloc(sizeof(struct sockaddr_in));
535                                 if (*sap == NULL) {
536                                         freeaddrinfo(res);
537                                         goto errexit;
538                                 }
539                                 *(struct sockaddr_in *)*sap =
540                                         *((struct sockaddr_in *)sai->ai_addr);
541                                 break;
542                         default:
543                                 *sap = NULL;
544                                 break;
545                         }
546
547                         if (*sap != NULL) {
548                                 (*sap)->sa_family = sai->ai_family;
549                                 sap++;
550                                 *sap = NULL;
551                         }
552                 }
553
554                 freeaddrinfo(res);
555 #else
556                 int i, n = 1;
557                 struct in_addr in;
558                 struct hostent *he = NULL;
559
560                 if ( host == NULL ) {
561                         in.s_addr = htonl(INADDR_ANY);
562
563                 } else if ( !inet_aton( host, &in ) ) {
564                         he = gethostbyname( host );
565                         if( he == NULL ) {
566 #ifdef NEW_LOGGING
567                                 LDAP_LOG( CONNECTION, INFO, 
568                                         "slap_get_listener_addresses: invalid host %s\n", host, 0, 0 );
569 #else
570                                 Debug( LDAP_DEBUG_ANY,
571                                        "daemon: invalid host %s", host, 0, 0);
572 #endif
573                                 return -1;
574                         }
575                         for (n = 0; he->h_addr_list[n]; n++) ;
576                 }
577
578                 *sal = ch_malloc((n+1) * sizeof(void *));
579                 if (*sal == NULL) {
580                         return -1;
581                 }
582
583                 sap = *sal;
584                 for ( i = 0; i<n; i++ ) {
585                         sap[i] = ch_malloc(sizeof(struct sockaddr_in));
586                         if (*sap == NULL) {
587                                 goto errexit;
588                         }
589                         (void)memset( (void *)sap[i], '\0', sizeof(struct sockaddr_in) );
590                         sap[i]->sa_family = AF_INET;
591                         ((struct sockaddr_in *)sap[i])->sin_port = htons(port);
592                         if (he) {
593                                 AC_MEMCPY( &((struct sockaddr_in *)sap[i])->sin_addr, he->h_addr_list[i], sizeof(struct in_addr) );
594                         } else {
595                                 AC_MEMCPY( &((struct sockaddr_in *)sap[i])->sin_addr, &in, sizeof(struct in_addr) );
596                         }
597                 }
598                 sap[i] = NULL;
599 #endif
600         }
601
602         return 0;
603
604 errexit:
605         slap_free_listener_addresses(*sal);
606         return -1;
607 }
608
609 static int slap_open_listener(
610         const char* url,
611         int *listeners,
612         int *cur
613         )
614 {
615         int     num, tmp, rc;
616         Listener l;
617         Listener *li;
618         LDAPURLDesc *lud;
619         unsigned short port;
620         int err, addrlen = 0;
621         struct sockaddr **sal, **psal;
622         int socktype = SOCK_STREAM;     /* default to COTS */
623
624 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
625         /*
626          * use safe defaults
627          */
628         int     crit = 1;
629 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
630
631         rc = ldap_url_parse( url, &lud );
632
633         if( rc != LDAP_URL_SUCCESS ) {
634 #ifdef NEW_LOGGING
635                 LDAP_LOG( CONNECTION, ERR, 
636                         "slap_open_listener: listen URL \"%s\" parse error %d\n",
637                         url, rc , 0 );
638 #else
639                 Debug( LDAP_DEBUG_ANY,
640                         "daemon: listen URL \"%s\" parse error=%d\n",
641                         url, rc, 0 );
642 #endif
643                 return rc;
644         }
645
646         l.sl_url.bv_val = NULL;
647         l.sl_is_mute = 0;
648
649 #ifndef HAVE_TLS
650         if( ldap_pvt_url_scheme2tls( lud->lud_scheme ) ) {
651 #ifdef NEW_LOGGING
652                 LDAP_LOG( CONNECTION, INFO, 
653                            "slap_open_listener: TLS is not supported (%s)\n", url, 0, 0 );
654 #else
655                 Debug( LDAP_DEBUG_ANY,
656                         "daemon: TLS not supported (%s)\n",
657                         url, 0, 0 );
658 #endif
659                 ldap_free_urldesc( lud );
660                 return -1;
661         }
662
663         if(! lud->lud_port ) {
664                 lud->lud_port = LDAP_PORT;
665         }
666
667 #else
668         l.sl_is_tls = ldap_pvt_url_scheme2tls( lud->lud_scheme );
669
670         if(! lud->lud_port ) {
671                 lud->lud_port = l.sl_is_tls ? LDAPS_PORT : LDAP_PORT;
672         }
673 #endif
674
675         port = (unsigned short) lud->lud_port;
676
677         tmp = ldap_pvt_url_scheme2proto(lud->lud_scheme);
678         if ( tmp == LDAP_PROTO_IPC ) {
679 #ifdef LDAP_PF_LOCAL
680                 if ( lud->lud_host == NULL || lud->lud_host[0] == '\0' ) {
681                         err = slap_get_listener_addresses(LDAPI_SOCK, 0, &sal);
682                 } else {
683                         err = slap_get_listener_addresses(lud->lud_host, 0, &sal);
684                 }
685 #else
686
687 #ifdef NEW_LOGGING
688                 LDAP_LOG( CONNECTION, INFO, 
689                         "slap_open_listener: URL scheme is not supported: %s\n", url, 0, 0 );
690 #else
691                 Debug( LDAP_DEBUG_ANY, "daemon: URL scheme not supported: %s",
692                         url, 0, 0);
693 #endif
694                 ldap_free_urldesc( lud );
695                 return -1;
696 #endif
697         } else {
698                 if( lud->lud_host == NULL || lud->lud_host[0] == '\0'
699                         || strcmp(lud->lud_host, "*") == 0 )
700                 {
701                         err = slap_get_listener_addresses(NULL, port, &sal);
702                 } else {
703                         err = slap_get_listener_addresses(lud->lud_host, port, &sal);
704                 }
705         }
706 #ifdef LDAP_CONNECTIONLESS
707         l.sl_is_udp = ( tmp == LDAP_PROTO_UDP );
708 #endif
709
710 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
711         if ( lud->lud_exts ) {
712                 err = get_url_perms( lud->lud_exts, &l.sl_perms, &crit );
713         } else {
714                 l.sl_perms = S_IRWXU | S_IRWXO;
715         }
716 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
717
718         ldap_free_urldesc( lud );
719         if ( err ) {
720                 return -1;
721         }
722
723         /* If we got more than one address returned, we need to make space
724          * for it in the slap_listeners array.
725          */
726         for ( num=0; sal[num]; num++ );
727         if ( num > 1 ) {
728                 *listeners += num-1;
729                 slap_listeners = ch_realloc( slap_listeners, (*listeners + 1) * sizeof(Listener *) );
730         }
731
732         psal = sal;
733         while ( *sal != NULL ) {
734                 char *af;
735                 switch( (*sal)->sa_family ) {
736                 case AF_INET:
737                         af = "IPv4";
738                         break;
739 #ifdef LDAP_PF_INET6
740                 case AF_INET6:
741                         af = "IPv6";
742                         break;
743 #endif
744 #ifdef LDAP_PF_LOCAL
745                 case AF_LOCAL:
746                         af = "Local";
747                         break;
748 #endif
749                 default:
750                         sal++;
751                         continue;
752                 }
753 #ifdef LDAP_CONNECTIONLESS
754                 if( l.sl_is_udp ) socktype = SOCK_DGRAM;
755 #endif
756                 l.sl_sd = socket( (*sal)->sa_family, socktype, 0);
757                 if ( l.sl_sd == AC_SOCKET_INVALID ) {
758                         int err = sock_errno();
759 #ifdef NEW_LOGGING
760                         LDAP_LOG( CONNECTION, ERR, 
761                                 "slap_open_listener: %s socket() failed errno=%d (%s)\n",
762                                 af, err, sock_errstr(err) );
763 #else
764                         Debug( LDAP_DEBUG_ANY,
765                                 "daemon: %s socket() failed errno=%d (%s)\n",
766                                 af, err, sock_errstr(err) );
767 #endif
768                         sal++;
769                         continue;
770                 }
771 #ifndef HAVE_WINSOCK
772                 if ( l.sl_sd >= dtblsize ) {
773 #ifdef NEW_LOGGING
774                         LDAP_LOG( CONNECTION, ERR, 
775                                 "slap_open_listener: listener descriptor %ld is too "
776                                 "great %ld\n", (long)l.sl_sd, (long)dtblsize, 0 );
777 #else
778                         Debug( LDAP_DEBUG_ANY,
779                                 "daemon: listener descriptor %ld is too great %ld\n",
780                                 (long) l.sl_sd, (long) dtblsize, 0 );
781 #endif
782                         tcp_close( l.sl_sd );
783                         sal++;
784                         continue;
785                 }
786 #endif
787 #ifdef LDAP_PF_LOCAL
788                 if ( (*sal)->sa_family == AF_LOCAL ) {
789                         unlink ( ((struct sockaddr_un *)*sal)->sun_path );
790                 } else
791 #endif
792                 {
793 #ifdef SO_REUSEADDR
794                         /* enable address reuse */
795                         tmp = 1;
796                         rc = setsockopt( l.sl_sd, SOL_SOCKET, SO_REUSEADDR,
797                                 (char *) &tmp, sizeof(tmp) );
798                         if ( rc == AC_SOCKET_ERROR ) {
799                                 int err = sock_errno();
800 #ifdef NEW_LOGGING
801                                 LDAP_LOG( CONNECTION, INFO, 
802                                         "slap_open_listener: setsockopt( %ld, SO_REUSEADDR ) "
803                                         "failed errno %d (%s)\n", (long)l.sl_sd, err, 
804                                         sock_errstr(err) );
805 #else
806                                 Debug( LDAP_DEBUG_ANY,
807                                        "slapd(%ld): setsockopt(SO_REUSEADDR) failed errno=%d (%s)\n",
808                                        (long) l.sl_sd, err, sock_errstr(err) );
809 #endif
810                         }
811 #endif
812                 }
813
814                 switch( (*sal)->sa_family ) {
815                 case AF_INET:
816                         addrlen = sizeof(struct sockaddr_in);
817                         break;
818 #ifdef LDAP_PF_INET6
819                 case AF_INET6:
820 #ifdef IPV6_V6ONLY
821                         /* Try to use IPv6 sockets for IPv6 only */
822                         tmp = 1;
823                         rc = setsockopt( l.sl_sd, IPPROTO_IPV6, IPV6_V6ONLY,
824                                          (char *) &tmp, sizeof(tmp) );
825                         if ( rc == AC_SOCKET_ERROR ) {
826                                 int err = sock_errno();
827 #ifdef NEW_LOGGING
828                                 LDAP_LOG( CONNECTION, INFO,
829                                            "slap_open_listener: setsockopt( %ld, IPV6_V6ONLY ) failed errno %d (%s)\n",
830                                            (long)l.sl_sd, err, sock_errstr(err) );
831 #else
832                                 Debug( LDAP_DEBUG_ANY,
833                                        "slapd(%ld): setsockopt(IPV6_V6ONLY) failed errno=%d (%s)\n",
834                                        (long) l.sl_sd, err, sock_errstr(err) );
835 #endif
836                         }
837 #endif
838                         addrlen = sizeof(struct sockaddr_in6);
839                         break;
840 #endif
841 #ifdef LDAP_PF_LOCAL
842                 case AF_LOCAL:
843                         addrlen = sizeof(struct sockaddr_un);
844                         break;
845 #endif
846                 }
847
848                 if (bind(l.sl_sd, *sal, addrlen)) {
849                         err = sock_errno();
850 #ifdef NEW_LOGGING
851                 LDAP_LOG( CONNECTION, INFO, 
852                         "slap_open_listener: bind(%ld) failed errno=%d (%s)\n",
853                         (long)l.sl_sd, err, sock_errstr(err) );
854 #else
855                 Debug( LDAP_DEBUG_ANY, "daemon: bind(%ld) failed errno=%d (%s)\n",
856                        (long) l.sl_sd, err, sock_errstr(err) );
857 #endif
858                         tcp_close( l.sl_sd );
859                         sal++;
860                         continue;
861                 }
862
863         switch ( (*sal)->sa_family ) {
864 #ifdef LDAP_PF_LOCAL
865         case AF_LOCAL: {
866                 char *addr = ((struct sockaddr_un *)*sal)->sun_path;
867 #if 0 /* don't muck with socket perms */
868                 if ( chmod( addr, l.sl_perms ) < 0 && crit ) {
869                         int err = sock_errno();
870 #ifdef NEW_LOGGING
871                         LDAP_LOG( CONNECTION, INFO, 
872                                 "slap_open_listener: fchmod(%ld) failed errno=%d (%s)\n",
873                                 (long)l.sl_sd, err, sock_errstr(err) );
874 #else
875                         Debug( LDAP_DEBUG_ANY, "daemon: fchmod(%ld) failed errno=%d (%s)",
876                                (long) l.sl_sd, err, sock_errstr(err) );
877 #endif
878                         tcp_close( l.sl_sd );
879                         slap_free_listener_addresses(psal);
880                         return -1;
881                 }
882 #endif
883                 l.sl_name.bv_len = strlen(addr) + sizeof("PATH=") - 1;
884                 l.sl_name.bv_val = ber_memalloc( l.sl_name.bv_len + 1 );
885                 snprintf( l.sl_name.bv_val, l.sl_name.bv_len + 1, 
886                                 "PATH=%s", addr );
887         } break;
888 #endif /* LDAP_PF_LOCAL */
889
890         case AF_INET: {
891                 char *s;
892 #if defined( HAVE_GETADDRINFO ) && defined( HAVE_INET_NTOP )
893                 char addr[INET_ADDRSTRLEN];
894                 inet_ntop( AF_INET, &((struct sockaddr_in *)*sal)->sin_addr,
895                            addr, sizeof(addr) );
896                 s = addr;
897 #else
898                 s = inet_ntoa( ((struct sockaddr_in *) *sal)->sin_addr );
899 #endif
900                 port = ntohs( ((struct sockaddr_in *)*sal) ->sin_port );
901                 l.sl_name.bv_val = ber_memalloc( sizeof("IP=255.255.255.255:65535") );
902                 snprintf( l.sl_name.bv_val, sizeof("IP=255.255.255.255:65535"),
903                         "IP=%s:%d",
904                          s != NULL ? s : SLAP_STRING_UNKNOWN, port );
905                 l.sl_name.bv_len = strlen( l.sl_name.bv_val );
906         } break;
907
908 #ifdef LDAP_PF_INET6
909         case AF_INET6: {
910                 char addr[INET6_ADDRSTRLEN];
911                 inet_ntop( AF_INET6, &((struct sockaddr_in6 *)*sal)->sin6_addr,
912                            addr, sizeof addr);
913                 port = ntohs( ((struct sockaddr_in6 *)*sal)->sin6_port );
914                 l.sl_name.bv_len = strlen(addr) + sizeof("IP= 65535");
915                 l.sl_name.bv_val = ber_memalloc( l.sl_name.bv_len );
916                 snprintf( l.sl_name.bv_val, l.sl_name.bv_len, "IP=%s %d", 
917                                 addr, port );
918                 l.sl_name.bv_len = strlen( l.sl_name.bv_val );
919         } break;
920 #endif /* LDAP_PF_INET6 */
921
922         default:
923 #ifdef NEW_LOGGING
924                 LDAP_LOG( CONNECTION, INFO, 
925                         "slap_open_listener: unsupported address family (%d)\n",
926                         (int)(*sal)->sa_family, 0, 0 );
927 #else
928                 Debug( LDAP_DEBUG_ANY, "daemon: unsupported address family (%d)\n",
929                         (int) (*sal)->sa_family, 0, 0 );
930 #endif
931                 break;
932         }
933
934         AC_MEMCPY(&l.sl_sa, *sal, addrlen);
935         ber_str2bv( url, 0, 1, &l.sl_url);
936         li = ch_malloc( sizeof( Listener ) );
937         *li = l;
938         slap_listeners[*cur] = li;
939         (*cur)++;
940         sal++;
941
942         } /* while ( *sal != NULL ) */
943
944         slap_free_listener_addresses(psal);
945
946         if ( l.sl_url.bv_val == NULL )
947         {
948 #ifdef NEW_LOGGING
949                 LDAP_LOG( CONNECTION, RESULTS, 
950                         "slap_open_listener: failed on %s\n", url, 0, 0 );
951 #else
952                 Debug( LDAP_DEBUG_TRACE,
953                         "slap_open_listener: failed on %s\n", url, 0, 0 );
954 #endif
955                 return -1;
956         }
957
958 #ifdef NEW_LOGGING
959         LDAP_LOG( CONNECTION, RESULTS, 
960                 "slap_open_listener: daemon initialized %s\n",
961                 l.sl_url.bv_val, 0, 0 );
962 #else
963         Debug( LDAP_DEBUG_TRACE, "daemon: initialized %s\n",
964                 l.sl_url.bv_val, 0, 0 );
965 #endif
966         return 0;
967 }
968
969 static int sockinit(void);
970 static int sockdestroy(void);
971
972 int slapd_daemon_init( const char *urls )
973 {
974         int i, j, n, rc;
975         char **u;
976
977 #ifdef NEW_LOGGING
978         LDAP_LOG( CONNECTION, ARGS, 
979                 "slapd_daemon_init: %s\n", urls ? urls : "<null>", 0, 0 );
980 #else
981         Debug( LDAP_DEBUG_ARGS, "daemon_init: %s\n",
982                 urls ? urls : "<null>", 0, 0 );
983 #endif
984         if( (rc = sockinit()) != 0 ) {
985                 return rc;
986         }
987
988 #ifdef HAVE_SYSCONF
989         dtblsize = sysconf( _SC_OPEN_MAX );
990 #elif HAVE_GETDTABLESIZE
991         dtblsize = getdtablesize();
992 #else
993         dtblsize = FD_SETSIZE;
994 #endif
995
996 #ifdef FD_SETSIZE
997         if(dtblsize > FD_SETSIZE) {
998                 dtblsize = FD_SETSIZE;
999         }
1000 #endif  /* !FD_SETSIZE */
1001
1002         /* open a pipe (or something equivalent connected to itself).
1003          * we write a byte on this fd whenever we catch a signal. The main
1004          * loop will be select'ing on this socket, and will wake up when
1005          * this byte arrives.
1006          */
1007         if( (rc = lutil_pair( wake_sds )) < 0 ) {
1008 #ifdef NEW_LOGGING
1009                 LDAP_LOG( CONNECTION, ERR, 
1010                         "slap_daemon_init: lutil_pair() failed rc=%d\n", rc, 0, 0);
1011 #else
1012                 Debug( LDAP_DEBUG_ANY,
1013                         "daemon: lutil_pair() failed rc=%d\n", rc, 0, 0 );
1014 #endif
1015                 return rc;
1016         }
1017
1018         FD_ZERO( &slap_daemon.sd_readers );
1019         FD_ZERO( &slap_daemon.sd_writers );
1020
1021         if( urls == NULL ) {
1022                 urls = "ldap:///";
1023         }
1024
1025         u = ldap_str2charray( urls, " " );
1026
1027         if( u == NULL || u[0] == NULL ) {
1028 #ifdef NEW_LOGGING
1029                 LDAP_LOG( CONNECTION, ERR, 
1030                         "slap_daemon_init: no urls (%s) provided.\n", urls, 0, 0 );
1031 #else
1032                 Debug( LDAP_DEBUG_ANY, "daemon_init: no urls (%s) provided.\n",
1033                         urls, 0, 0 );
1034 #endif
1035                 return -1;
1036         }
1037
1038         for( i=0; u[i] != NULL; i++ ) {
1039 #ifdef NEW_LOGGING
1040                 LDAP_LOG( CONNECTION, DETAIL1, 
1041                         "slap_daemon_init: listen on %s\n", u[i], 0, 0 );
1042 #else
1043                 Debug( LDAP_DEBUG_TRACE, "daemon_init: listen on %s\n",
1044                         u[i], 0, 0 );
1045 #endif
1046         }
1047
1048         if( i == 0 ) {
1049 #ifdef NEW_LOGGING
1050                 LDAP_LOG( CONNECTION, INFO, 
1051                          "slap_daemon_init: no listeners to open (%s)\n", urls, 0, 0 );
1052 #else
1053                 Debug( LDAP_DEBUG_ANY, "daemon_init: no listeners to open (%s)\n",
1054                         urls, 0, 0 );
1055 #endif
1056                 ldap_charray_free( u );
1057                 return -1;
1058         }
1059
1060 #ifdef NEW_LOGGING
1061         LDAP_LOG( CONNECTION, INFO, 
1062                 "slap_daemon_init: %d listeners to open...\n", i, 0, 0 );
1063 #else
1064         Debug( LDAP_DEBUG_TRACE, "daemon_init: %d listeners to open...\n",
1065                 i, 0, 0 );
1066 #endif
1067         slap_listeners = ch_malloc( (i+1)*sizeof(Listener *) );
1068
1069         for(n = 0, j = 0; u[n]; n++ ) {
1070                 if ( slap_open_listener( u[n], &i, &j ) ) {
1071                         ldap_charray_free( u );
1072                         return -1;
1073                 }
1074         }
1075         slap_listeners[j] = NULL;
1076
1077 #ifdef NEW_LOGGING
1078         LDAP_LOG( CONNECTION, DETAIL1, 
1079                 "slap_daemon_init: %d listeners opened\n", i, 0, 0 );
1080 #else
1081         Debug( LDAP_DEBUG_TRACE, "daemon_init: %d listeners opened\n",
1082                 i, 0, 0 );
1083 #endif
1084
1085 #ifdef HAVE_SLP
1086         slapd_slp_init( urls );
1087         slapd_slp_reg();
1088 #endif
1089
1090         ldap_charray_free( u );
1091         ldap_pvt_thread_mutex_init( &slap_daemon.sd_mutex );
1092         return !i;
1093 }
1094
1095
1096 int
1097 slapd_daemon_destroy(void)
1098 {
1099         connections_destroy();
1100         tcp_close( wake_sds[1] );
1101         tcp_close( wake_sds[0] );
1102         sockdestroy();
1103
1104 #ifdef HAVE_SLP
1105         slapd_slp_dereg();
1106         slapd_slp_deinit();
1107 #endif
1108
1109         return 0;
1110 }
1111
1112
1113 static void
1114 close_listeners(
1115         int remove
1116 )
1117 {
1118         int l;
1119
1120         for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1121                 if ( slap_listeners[l]->sl_sd != AC_SOCKET_INVALID ) {
1122                         if ( remove )
1123                                 slapd_remove( slap_listeners[l]->sl_sd, 0 );
1124 #ifdef LDAP_PF_LOCAL
1125                         if ( slap_listeners[l]->sl_sa.sa_addr.sa_family == AF_LOCAL ) {
1126                                 unlink( slap_listeners[l]->sl_sa.sa_un_addr.sun_path );
1127                         }
1128 #endif /* LDAP_PF_LOCAL */
1129                         slapd_close( slap_listeners[l]->sl_sd );
1130                 }
1131                 if ( slap_listeners[l]->sl_url.bv_val )
1132                         ber_memfree( slap_listeners[l]->sl_url.bv_val );
1133                 if ( slap_listeners[l]->sl_name.bv_val )
1134                         ber_memfree( slap_listeners[l]->sl_name.bv_val );
1135                 free ( slap_listeners[l] );
1136                 slap_listeners[l] = NULL;
1137         }
1138 }
1139
1140
1141 static void *
1142 slapd_daemon_task(
1143         void *ptr
1144 )
1145 {
1146         int l;
1147         time_t  last_idle_check = 0;
1148         struct timeval idle;
1149
1150 #define SLAPD_IDLE_CHECK_LIMIT 4
1151
1152         if ( global_idletimeout > 0 ) {
1153                 last_idle_check = slap_get_time();
1154                 /* Set the select timeout.
1155                  * Don't just truncate, preserve the fractions of
1156                  * seconds to prevent sleeping for zero time.
1157                  */
1158                 idle.tv_sec = global_idletimeout/SLAPD_IDLE_CHECK_LIMIT;
1159                 idle.tv_usec = global_idletimeout - idle.tv_sec * SLAPD_IDLE_CHECK_LIMIT;
1160                 idle.tv_usec *= 1000000 / SLAPD_IDLE_CHECK_LIMIT;
1161         } else {
1162                 idle.tv_sec = 0;
1163                 idle.tv_usec = 0;
1164         }
1165
1166         for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1167                 if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1168                         continue;
1169 #ifdef LDAP_CONNECTIONLESS
1170                 /* Since this is connectionless, the data port is the
1171                  * listening port. The listen() and accept() calls
1172                  * are unnecessary.
1173                  */
1174                 if ( slap_listeners[l]->sl_is_udp ) {
1175                         slapd_add( slap_listeners[l]->sl_sd );
1176                         continue;
1177                 }
1178 #endif
1179
1180                 if ( listen( slap_listeners[l]->sl_sd, SLAPD_LISTEN ) == -1 ) {
1181                         int err = sock_errno();
1182
1183 #ifdef LDAP_PF_INET6
1184                         /* If error is EADDRINUSE, we are trying to listen to INADDR_ANY and
1185                          * we are already listening to in6addr_any, then we want to ignore
1186                          * this and continue.
1187                          */
1188                         if ( err == EADDRINUSE ) {
1189                                 int i;
1190                                 struct sockaddr_in sa = slap_listeners[l]->sl_sa.sa_in_addr;
1191                                 struct sockaddr_in6 sa6;
1192                                 
1193                                 if ( sa.sin_family == AF_INET &&
1194                                      sa.sin_addr.s_addr == htonl(INADDR_ANY) ) {
1195                                         for ( i = 0 ; i < l; i++ ) {
1196                                                 sa6 = slap_listeners[i]->sl_sa.sa_in6_addr;
1197                                                 if ( sa6.sin6_family == AF_INET6 &&
1198                                                      !memcmp( &sa6.sin6_addr, &in6addr_any, sizeof(struct in6_addr) ) )
1199                                                         break;
1200                                         }
1201
1202                                         if ( i < l ) {
1203                                                 /* We are already listening to in6addr_any */
1204 #ifdef NEW_LOGGING
1205                                                 LDAP_LOG(CONNECTION, WARNING,
1206                                                            "slapd_daemon_task: Attempt to listen to 0.0.0.0 failed, already listening on ::, assuming IPv4 included\n", 0, 0, 0 );
1207 #else
1208                                                 Debug( LDAP_DEBUG_CONNS,
1209                                                        "daemon: Attempt to listen to 0.0.0.0 failed, already listening on ::, assuming IPv4 included\n",
1210                                                        0, 0, 0 );
1211 #endif
1212                                                 slapd_close( slap_listeners[l]->sl_sd );
1213                                                 slap_listeners[l]->sl_sd = AC_SOCKET_INVALID;
1214                                                 continue;
1215                                         }
1216                                 }
1217                         }
1218 #endif                          
1219 #ifdef NEW_LOGGING
1220                         LDAP_LOG( CONNECTION, ERR, 
1221                                 "slapd_daemon_task: listen( %s, 5 ) failed errno=%d (%s)\n",
1222                                 slap_listeners[l]->sl_url.bv_val, err, sock_errstr(err) );
1223 #else
1224                         Debug( LDAP_DEBUG_ANY,
1225                                 "daemon: listen(%s, 5) failed errno=%d (%s)\n",
1226                                         slap_listeners[l]->sl_url.bv_val, err,
1227                                         sock_errstr(err) );
1228 #endif
1229                         return( (void*)-1 );
1230                 }
1231
1232                 slapd_add( slap_listeners[l]->sl_sd );
1233         }
1234
1235 #ifdef HAVE_NT_SERVICE_MANAGER
1236         if ( started_event != NULL ) {
1237                 ldap_pvt_thread_cond_signal( &started_event );
1238         }
1239 #endif
1240         /* initialization complete. Here comes the loop. */
1241
1242         while ( !slapd_shutdown ) {
1243                 ber_socket_t i;
1244                 int ns;
1245                 int at;
1246                 ber_socket_t nfds;
1247 #define SLAPD_EBADF_LIMIT 16
1248                 int ebadf = 0;
1249
1250                 time_t  now;
1251
1252                 fd_set                  readfds;
1253                 fd_set                  writefds;
1254                 Sockaddr                from;
1255
1256                 struct timeval          tv;
1257                 struct timeval          *tvp;
1258
1259 #ifdef LDAP_SYNCREPL
1260                 struct timeval          *cat;
1261                 time_t                          tdelta = 1;
1262                 struct re_s*            rtask;
1263 #endif
1264                 now = slap_get_time();
1265
1266                 if( ( global_idletimeout > 0 ) &&
1267                         difftime( last_idle_check +
1268                         global_idletimeout/SLAPD_IDLE_CHECK_LIMIT, now ) < 0 ) {
1269                         connections_timeout_idle( now );
1270                         last_idle_check = now;
1271                 }
1272                 tv = idle;
1273
1274 #ifdef SIGHUP
1275                 if( slapd_gentle_shutdown ) {
1276                         ber_socket_t active;
1277
1278                         if( slapd_gentle_shutdown == 1 ) {
1279                                 Debug( LDAP_DEBUG_ANY, "slapd gentle shutdown\n", 0, 0, 0 );
1280                                 close_listeners( 1 );
1281                                 global_restrictops |= SLAP_RESTRICT_OP_WRITES;
1282                                 slapd_gentle_shutdown = 2;
1283                         }
1284
1285                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1286                         active = slap_daemon.sd_nactives;
1287                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1288                         if( active == 0 ) {
1289                                 slapd_shutdown = 2;
1290                                 break;
1291                         }
1292                 }
1293 #endif
1294
1295                 FD_ZERO( &writefds );
1296                 FD_ZERO( &readfds );
1297
1298                 at = 0;
1299
1300                 ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1301
1302 #ifdef FD_SET_MANUAL_COPY
1303                 for( s = 0; s < nfds; s++ ) {
1304                         if(FD_ISSET( &slap_sd_readers, s )) {
1305                                 FD_SET( s, &readfds );
1306                         }
1307                         if(FD_ISSET( &slap_sd_writers, s )) {
1308                                 FD_SET( s, &writefds );
1309                         }
1310                 }
1311 #else
1312                 AC_MEMCPY( &readfds, &slap_daemon.sd_readers, sizeof(fd_set) );
1313                 AC_MEMCPY( &writefds, &slap_daemon.sd_writers, sizeof(fd_set) );
1314 #endif
1315                 assert(!FD_ISSET(wake_sds[0], &readfds));
1316                 FD_SET( wake_sds[0], &readfds );
1317
1318                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1319                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1320                                 continue;
1321                         if ( slap_listeners[l]->sl_is_mute )
1322                                 FD_CLR( slap_listeners[l]->sl_sd, &readfds );
1323                         else
1324                         if (!FD_ISSET(slap_listeners[l]->sl_sd, &readfds))
1325                             FD_SET( slap_listeners[l]->sl_sd, &readfds );
1326                 }
1327
1328 #ifndef HAVE_WINSOCK
1329                 nfds = slap_daemon.sd_nfds;
1330 #else
1331                 nfds = dtblsize;
1332 #endif
1333                 if ( global_idletimeout && slap_daemon.sd_nactives )
1334                         at = 1;
1335
1336                 ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1337
1338                 if ( !at ) {
1339                         at = ldap_pvt_thread_pool_backload(&connection_pool) -
1340                                  ldap_pvt_runqueue_persistent_backload( &syncrepl_rq );
1341                 }
1342
1343                 if ( at 
1344 #if defined(HAVE_YIELDING_SELECT) || defined(NO_THREADS)
1345                         &&  ( tv.tv_sec || tv.tv_usec )
1346 #endif
1347                         )
1348                         tvp = &tv;
1349                 else
1350                         tvp = NULL;
1351
1352 #ifdef LDAP_SYNCREPL
1353                 ldap_pvt_thread_mutex_lock( &syncrepl_rq.rq_mutex );
1354                 rtask = ldap_pvt_runqueue_next_sched( &syncrepl_rq, &cat );
1355                 while ( cat && cat->tv_sec && cat->tv_sec <= now ) {
1356                         if ( ldap_pvt_runqueue_isrunning( &syncrepl_rq, rtask )) {
1357                                 ldap_pvt_runqueue_resched( &syncrepl_rq, rtask );
1358                         } else {
1359                                 ldap_pvt_runqueue_runtask( &syncrepl_rq, rtask );
1360                                 ldap_pvt_runqueue_resched( &syncrepl_rq, rtask );
1361                                 ldap_pvt_thread_mutex_unlock( &syncrepl_rq.rq_mutex );
1362                                 ldap_pvt_thread_pool_submit( &connection_pool,
1363                                                                                         rtask->routine, (void *) rtask );
1364                         }
1365                         rtask = ldap_pvt_runqueue_next_sched( &syncrepl_rq, &cat );
1366                 }
1367                 rtask = ldap_pvt_runqueue_next_sched( &syncrepl_rq, &cat );
1368                 ldap_pvt_thread_mutex_unlock( &syncrepl_rq.rq_mutex );
1369
1370                 if ( cat != NULL ) {
1371                         time_t diff = difftime( cat->tv_sec, now );
1372                         if ( diff == 0 )
1373                                 diff = tdelta;
1374                         if ( tvp == NULL || diff < tv.tv_sec ) {
1375                                 tv.tv_sec = diff;
1376                                 tv.tv_usec = 0;
1377                                 tvp = &tv;
1378                         }
1379                 }
1380 #endif
1381
1382                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1383                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID ||
1384                             slap_listeners[l]->sl_is_mute )
1385                                 continue;
1386
1387 #ifdef NEW_LOGGING
1388                         LDAP_LOG( CONNECTION, DETAIL1, 
1389                                 "slapd_daemon_task: select: listen=%d "
1390                                 "active_threads=%d tvp=%s\n",
1391                                 slap_listeners[l]->sl_sd, at, tvp == NULL ? "NULL" : "zero" );
1392 #else
1393                         Debug( LDAP_DEBUG_CONNS,
1394                                 "daemon: select: listen=%d active_threads=%d tvp=%s\n",
1395                                         slap_listeners[l]->sl_sd, at,
1396                                         tvp == NULL ? "NULL" : "zero" );
1397 #endif
1398                 }
1399
1400                 switch(ns = select( nfds, &readfds,
1401 #ifdef HAVE_WINSOCK
1402                         /* don't pass empty fd_set */
1403                         ( writefds.fd_count > 0 ? &writefds : NULL ),
1404 #else
1405                         &writefds,
1406 #endif
1407                         NULL, tvp ))
1408                 {
1409                 case -1: {      /* failure - try again */
1410                                 int err = sock_errno();
1411
1412                                 if( err == EBADF
1413 #ifdef WSAENOTSOCK
1414                                         /* you'd think this would be EBADF */
1415                                         || err == WSAENOTSOCK
1416 #endif
1417                                 ) {
1418                                         if (++ebadf < SLAPD_EBADF_LIMIT)
1419                                                 continue;
1420                                 }
1421
1422                                 if( err != EINTR ) {
1423 #ifdef NEW_LOGGING
1424                                         LDAP_LOG( CONNECTION, INFO, 
1425                                                 "slapd_daemon_task: select failed (%d): %s\n",
1426                                                 err, sock_errstr(err), 0 );
1427 #else
1428                                         Debug( LDAP_DEBUG_CONNS,
1429                                                 "daemon: select failed (%d): %s\n",
1430                                                 err, sock_errstr(err), 0 );
1431 #endif
1432                                         slapd_shutdown = 2;
1433                                 }
1434                         }
1435                         continue;
1436
1437                 case 0:         /* timeout - let threads run */
1438                         ebadf = 0;
1439 #ifdef NEW_LOGGING
1440                         LDAP_LOG( CONNECTION, DETAIL2,
1441                                    "slapd_daemon_task: select timeout - yielding\n", 0, 0, 0 );
1442 #else
1443                         Debug( LDAP_DEBUG_CONNS, "daemon: select timeout - yielding\n",
1444                             0, 0, 0 );
1445 #endif
1446
1447                         ldap_pvt_thread_yield();
1448                         continue;
1449
1450                 default:        /* something happened - deal with it */
1451                         if( slapd_shutdown ) continue;
1452
1453                         ebadf = 0;
1454 #ifdef NEW_LOGGING
1455                         LDAP_LOG( CONNECTION, DETAIL2, 
1456                                    "slapd_daemon_task: activity on %d descriptors\n", ns, 0, 0 );
1457 #else
1458                         Debug( LDAP_DEBUG_CONNS, "daemon: activity on %d descriptors\n",
1459                                 ns, 0, 0 );
1460 #endif
1461                         /* FALL THRU */
1462                 }
1463
1464                 if( FD_ISSET( wake_sds[0], &readfds ) ) {
1465                         char c[BUFSIZ];
1466                         tcp_read( wake_sds[0], c, sizeof(c) );
1467 #if defined(NO_THREADS) || defined(HAVE_GNU_PTH)
1468                         waking = 0;
1469 #endif
1470                         continue;
1471                 }
1472
1473                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1474                         ber_socket_t s;
1475                         socklen_t len = sizeof(from);
1476                         long id;
1477                         slap_ssf_t ssf = 0;
1478                         char *authid = NULL;
1479 #ifdef SLAPD_RLOOKUPS
1480                         char hbuf[NI_MAXHOST];
1481 #endif
1482
1483                         char    *dnsname = NULL;
1484                         char    *peeraddr = NULL;
1485 #ifdef LDAP_PF_LOCAL
1486                         char    peername[MAXPATHLEN + sizeof("PATH=")];
1487 #elif defined(LDAP_PF_INET6)
1488                         char    peername[sizeof("IP=ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff 65535")];
1489 #else
1490                         char    peername[sizeof("IP=255.255.255.255:65336")];
1491 #endif /* LDAP_PF_LOCAL */
1492
1493                         peername[0] = '\0';
1494
1495                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1496                                 continue;
1497
1498                         if ( !FD_ISSET( slap_listeners[l]->sl_sd, &readfds ) )
1499                                 continue;
1500                         
1501 #ifdef LDAP_CONNECTIONLESS
1502                         if ( slap_listeners[l]->sl_is_udp ) {
1503                                 /* The first time we receive a query, we set this
1504                                  * up as a "connection". It remains open for the life
1505                                  * of the slapd.
1506                                  */
1507                                 if ( slap_listeners[l]->sl_is_udp < 2 ) {
1508                                     id = connection_init(
1509                                         slap_listeners[l]->sl_sd,
1510                                         slap_listeners[l], "", "",
1511                                         2, ssf, authid );
1512                                     slap_listeners[l]->sl_is_udp++;
1513                                 }
1514                                 continue;
1515                         }
1516 #endif
1517
1518                         /* Don't need to look at this in the data loops */
1519                         FD_CLR( slap_listeners[l]->sl_sd, &readfds );
1520                         FD_CLR( slap_listeners[l]->sl_sd, &writefds );
1521
1522                         s = accept( slap_listeners[l]->sl_sd,
1523                                 (struct sockaddr *) &from, &len );
1524                         if ( s == AC_SOCKET_INVALID ) {
1525                                 int err = sock_errno();
1526
1527                                 if(
1528 #ifdef EMFILE
1529                                     err == EMFILE ||
1530 #endif
1531 #ifdef ENFILE
1532                                     err == ENFILE ||
1533 #endif
1534                                     0 )
1535                                 {
1536                                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1537                                         emfile++;
1538                                         /* Stop listening until an existing session closes */
1539                                         slap_listeners[l]->sl_is_mute = 1;
1540                                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1541                                 }
1542
1543 #ifdef NEW_LOGGING
1544                                 LDAP_LOG( CONNECTION, ERR, 
1545                                         "slapd_daemon_task: accept(%ld) failed errno=%d (%s)\n",
1546                                         (long)slap_listeners[l]->sl_sd, 
1547                                         err, sock_errstr(err) );
1548 #else
1549                                 Debug( LDAP_DEBUG_ANY,
1550                                         "daemon: accept(%ld) failed errno=%d (%s)\n",
1551                                         (long) slap_listeners[l]->sl_sd, err,
1552                                         sock_errstr(err) );
1553 #endif
1554                                 ldap_pvt_thread_yield();
1555                                 continue;
1556                         }
1557
1558 #ifndef HAVE_WINSOCK
1559                         /* make sure descriptor number isn't too great */
1560                         if ( s >= dtblsize ) {
1561 #ifdef NEW_LOGGING
1562                                 LDAP_LOG( CONNECTION, ERR, 
1563                                    "slapd_daemon_task: %ld beyond descriptor table size %ld\n",
1564                                    (long)s, (long)dtblsize, 0 );
1565 #else
1566                                 Debug( LDAP_DEBUG_ANY,
1567                                         "daemon: %ld beyond descriptor table size %ld\n",
1568                                         (long) s, (long) dtblsize, 0 );
1569 #endif
1570
1571                                 slapd_close(s);
1572                                 ldap_pvt_thread_yield();
1573                                 continue;
1574                         }
1575 #endif
1576
1577 #ifdef LDAP_DEBUG
1578                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1579
1580                         /* newly accepted stream should not be in any of the FD SETS */
1581                         assert( !FD_ISSET( s, &slap_daemon.sd_actives) );
1582                         assert( !FD_ISSET( s, &slap_daemon.sd_readers) );
1583                         assert( !FD_ISSET( s, &slap_daemon.sd_writers) );
1584
1585                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1586 #endif
1587
1588 #if defined( SO_KEEPALIVE ) || defined( TCP_NODELAY )
1589 #ifdef LDAP_PF_LOCAL
1590                         /* for IPv4 and IPv6 sockets only */
1591                         if ( from.sa_addr.sa_family != AF_LOCAL )
1592 #endif /* LDAP_PF_LOCAL */
1593                         {
1594                                 int rc;
1595                                 int tmp;
1596 #ifdef SO_KEEPALIVE
1597                                 /* enable keep alives */
1598                                 tmp = 1;
1599                                 rc = setsockopt( s, SOL_SOCKET, SO_KEEPALIVE,
1600                                         (char *) &tmp, sizeof(tmp) );
1601                                 if ( rc == AC_SOCKET_ERROR ) {
1602                                         int err = sock_errno();
1603 #ifdef NEW_LOGGING
1604                                         LDAP_LOG( CONNECTION, ERR, 
1605                                                 "slapd_daemon_task: setsockopt( %ld, SO_KEEPALIVE)"
1606                                            " failed errno=%d (%s)\n",
1607                                                 (long)s, err, sock_errstr(err) );
1608 #else
1609                                         Debug( LDAP_DEBUG_ANY,
1610                                                 "slapd(%ld): setsockopt(SO_KEEPALIVE) failed "
1611                                                 "errno=%d (%s)\n", (long) s, err, sock_errstr(err) );
1612 #endif
1613                                 }
1614 #endif
1615 #ifdef TCP_NODELAY
1616                                 /* enable no delay */
1617                                 tmp = 1;
1618                                 rc = setsockopt( s, IPPROTO_TCP, TCP_NODELAY,
1619                                         (char *)&tmp, sizeof(tmp) );
1620                                 if ( rc == AC_SOCKET_ERROR ) {
1621                                         int err = sock_errno();
1622 #ifdef NEW_LOGGING
1623                                         LDAP_LOG( CONNECTION, ERR, 
1624                                                 "slapd_daemon_task: setsockopt( %ld, "
1625                                                 "TCP_NODELAY) failed errno=%d (%s)\n",
1626                                                 (long)s, err, sock_errstr(err) );
1627 #else
1628                                         Debug( LDAP_DEBUG_ANY,
1629                                                 "slapd(%ld): setsockopt(TCP_NODELAY) failed "
1630                                                 "errno=%d (%s)\n", (long) s, err, sock_errstr(err) );
1631 #endif
1632                                 }
1633 #endif
1634                         }
1635 #endif
1636
1637 #ifdef NEW_LOGGING
1638                         LDAP_LOG( CONNECTION, DETAIL1, 
1639                                 "slapd_daemon_task: new connection on %ld\n", (long)s, 0, 0 );
1640 #else
1641                         Debug( LDAP_DEBUG_CONNS, "daemon: new connection on %ld\n",
1642                                 (long) s, 0, 0 );
1643 #endif
1644                         switch ( from.sa_addr.sa_family ) {
1645 #  ifdef LDAP_PF_LOCAL
1646                         case AF_LOCAL:
1647                                 sprintf( peername, "PATH=%s", from.sa_un_addr.sun_path );
1648                                 ssf = LDAP_PVT_SASL_LOCAL_SSF;
1649                                 {
1650                                         uid_t uid;
1651                                         gid_t gid;
1652
1653                                         if( getpeereid( s, &uid, &gid ) == 0 ) {
1654                                                 authid = ch_malloc(
1655                                                         sizeof("uidnumber=4294967295+gidnumber=4294967295,"
1656                                                                 "cn=peercred,cn=external,cn=auth"));
1657                                                 sprintf(authid, "uidnumber=%d+gidnumber=%d,"
1658                                                         "cn=peercred,cn=external,cn=auth",
1659                                                         (int) uid, (int) gid);
1660                                         }
1661                                 }
1662                                 dnsname = "local";
1663                                 break;
1664 #endif /* LDAP_PF_LOCAL */
1665
1666 #  ifdef LDAP_PF_INET6
1667                         case AF_INET6:
1668                         if ( IN6_IS_ADDR_V4MAPPED(&from.sa_in6_addr.sin6_addr) ) {
1669                                 peeraddr = inet_ntoa( *((struct in_addr *)
1670                                                         &from.sa_in6_addr.sin6_addr.s6_addr[12]) );
1671                                 sprintf( peername, "IP=%s:%d",
1672                                          peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1673                                          (unsigned) ntohs( from.sa_in6_addr.sin6_port ) );
1674                         } else {
1675                                 char addr[INET6_ADDRSTRLEN];
1676
1677                                 peeraddr = (char *) inet_ntop( AF_INET6,
1678                                                       &from.sa_in6_addr.sin6_addr,
1679                                                       addr, sizeof addr );
1680                                 sprintf( peername, "IP=%s %d",
1681                                          peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1682                                          (unsigned) ntohs( from.sa_in6_addr.sin6_port ) );
1683                         }
1684                         break;
1685 #  endif /* LDAP_PF_INET6 */
1686
1687                         case AF_INET:
1688                         peeraddr = inet_ntoa( from.sa_in_addr.sin_addr );
1689                         sprintf( peername, "IP=%s:%d",
1690                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1691                                 (unsigned) ntohs( from.sa_in_addr.sin_port ) );
1692                                 break;
1693
1694                         default:
1695                                 slapd_close(s);
1696                                 continue;
1697                         }
1698
1699                         if ( ( from.sa_addr.sa_family == AF_INET )
1700 #ifdef LDAP_PF_INET6
1701                                 || ( from.sa_addr.sa_family == AF_INET6 )
1702 #endif
1703                         ) {
1704 #ifdef SLAPD_RLOOKUPS
1705                                 if ( use_reverse_lookup ) {
1706                                         char *herr;
1707                                         if (ldap_pvt_get_hname( (const struct sockaddr *)&from, len, hbuf,
1708                                                 sizeof(hbuf), &herr ) == 0) {
1709                                                 ldap_pvt_str2lower( hbuf );
1710                                                 dnsname = hbuf;
1711                                         }
1712                                 }
1713 #else
1714                                 dnsname = NULL;
1715 #endif /* SLAPD_RLOOKUPS */
1716
1717 #ifdef HAVE_TCPD
1718                                 if ( !hosts_ctl("slapd",
1719                                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1720                                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1721                                                 SLAP_STRING_UNKNOWN ))
1722                                 {
1723                                         /* DENY ACCESS */
1724                                         Statslog( LDAP_DEBUG_STATS,
1725                                                 "fd=%ld DENIED from %s (%s)\n",
1726                                                 (long) s,
1727                                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1728                                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1729                                                 0, 0 );
1730                                         slapd_close(s);
1731                                         continue;
1732                                 }
1733 #endif /* HAVE_TCPD */
1734                         }
1735
1736                         id = connection_init(s,
1737                                 slap_listeners[l],
1738                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1739                                 peername,
1740 #ifdef HAVE_TLS
1741                                 slap_listeners[l]->sl_is_tls,
1742 #else
1743                                 0,
1744 #endif
1745                                 ssf,
1746                                 authid );
1747
1748                         if( authid ) ch_free(authid);
1749
1750                         if( id < 0 ) {
1751 #ifdef NEW_LOGGING
1752                                 LDAP_LOG( CONNECTION, INFO, 
1753                                         "slapd_daemon_task: "
1754                                         "connection_init(%ld, %s, %s) "
1755                                         "failed.\n",
1756                                         (long)s, peername, 
1757                                         slap_listeners[l]->sl_name.bv_val );
1758 #else
1759                                 Debug( LDAP_DEBUG_ANY,
1760                                         "daemon: connection_init(%ld, %s, %s) "
1761                                         "failed.\n",
1762                                         (long) s,
1763                                         peername,
1764                                         slap_listeners[l]->sl_name.bv_val );
1765 #endif
1766                                 slapd_close(s);
1767                                 continue;
1768                         }
1769
1770                         Statslog( LDAP_DEBUG_STATS,
1771                                 "conn=%ld fd=%ld ACCEPT from %s (%s)\n",
1772                                 id, (long) s,
1773                                 peername,
1774                                 slap_listeners[l]->sl_name.bv_val,
1775                                 0 );
1776
1777                         slapd_add( s );
1778                         continue;
1779                 }
1780
1781 #ifdef LDAP_DEBUG
1782 #ifdef NEW_LOGGING
1783                 LDAP_LOG( CONNECTION, DETAIL2,
1784                            "slapd_daemon_task: activity on ", 0, 0, 0 );
1785 #else
1786                 Debug( LDAP_DEBUG_CONNS, "daemon: activity on:", 0, 0, 0 );
1787 #endif
1788 #ifdef HAVE_WINSOCK
1789                 for ( i = 0; i < readfds.fd_count; i++ ) {
1790 #ifdef NEW_LOGGING
1791                         LDAP_LOG( CONNECTION, DETAIL2, 
1792                                 " %d%s", readfds.fd_array[i], "r", 0, 0 );
1793 #else
1794                         Debug( LDAP_DEBUG_CONNS, " %d%s",
1795                                 readfds.fd_array[i], "r", 0 );
1796 #endif
1797                 }
1798                 for ( i = 0; i < writefds.fd_count; i++ ) {
1799 #ifdef NEW_LOGGING
1800                         LDAP_LOG( CONNECTION, DETAIL2, 
1801                                 " %d%s", writefds.fd_array[i], "w" , 0 );
1802 #else
1803                         Debug( LDAP_DEBUG_CONNS, " %d%s",
1804                                 writefds.fd_array[i], "w", 0 );
1805 #endif
1806                 }
1807
1808 #else
1809                 for ( i = 0; i < nfds; i++ ) {
1810                         int     r, w;
1811
1812                         r = FD_ISSET( i, &readfds );
1813                         w = FD_ISSET( i, &writefds );
1814                         if ( r || w ) {
1815 #ifdef NEW_LOGGING
1816                                 LDAP_LOG( CONNECTION, DETAIL2, 
1817                                         " %d%s%s", i, r ? "r" : "", w ? "w" : "" );
1818 #else
1819                                 Debug( LDAP_DEBUG_CONNS, " %d%s%s", i,
1820                                     r ? "r" : "", w ? "w" : "" );
1821 #endif
1822                         }
1823                 }
1824 #endif
1825 #ifdef NEW_LOGGING
1826                 LDAP_LOG( CONNECTION, DETAIL2, "\n", 0, 0, 0 );
1827 #else
1828                 Debug( LDAP_DEBUG_CONNS, "\n", 0, 0, 0 );
1829 #endif
1830
1831 #endif
1832
1833                 /* loop through the writers */
1834 #ifdef HAVE_WINSOCK
1835                 for ( i = 0; i < writefds.fd_count; i++ )
1836 #else
1837                 for ( i = 0; i < nfds; i++ )
1838 #endif
1839                 {
1840                         ber_socket_t wd;
1841 #ifdef HAVE_WINSOCK
1842                         wd = writefds.fd_array[i];
1843 #else
1844                         if( ! FD_ISSET( i, &writefds ) ) {
1845                                 continue;
1846                         }
1847                         wd = i;
1848 #endif
1849
1850 #ifdef NEW_LOGGING
1851                         LDAP_LOG( CONNECTION, DETAIL2, 
1852                                 "slapd_daemon_task: write active on %d\n", wd, 0, 0 );
1853 #else
1854                         Debug( LDAP_DEBUG_CONNS,
1855                                 "daemon: write active on %d\n",
1856                                 wd, 0, 0 );
1857 #endif
1858                         /*
1859                          * NOTE: it is possible that the connection was closed
1860                          * and that the stream is now inactive.
1861                          * connection_write() must valid the stream is still
1862                          * active.
1863                          */
1864
1865                         if ( connection_write( wd ) < 0 ) {
1866                                 FD_CLR( (unsigned) wd, &readfds );
1867                                 slapd_close( wd );
1868                         }
1869                 }
1870
1871 #ifdef HAVE_WINSOCK
1872                 for ( i = 0; i < readfds.fd_count; i++ )
1873 #else
1874                 for ( i = 0; i < nfds; i++ )
1875 #endif
1876                 {
1877                         ber_socket_t rd;
1878 #ifdef HAVE_WINSOCK
1879                         rd = readfds.fd_array[i];
1880 #else
1881                         if( ! FD_ISSET( i, &readfds ) ) {
1882                                 continue;
1883                         }
1884                         rd = i;
1885 #endif
1886
1887 #ifdef NEW_LOGGING
1888                         LDAP_LOG( CONNECTION, DETAIL2, 
1889                                 "slapd_daemon_task: read activity on %d\n", rd, 0, 0 );
1890 #else
1891                         Debug ( LDAP_DEBUG_CONNS,
1892                                 "daemon: read activity on %d\n", rd, 0, 0 );
1893 #endif
1894                         /*
1895                          * NOTE: it is possible that the connection was closed
1896                          * and that the stream is now inactive.
1897                          * connection_read() must valid the stream is still
1898                          * active.
1899                          */
1900
1901                         if ( connection_read( rd ) < 0 ) {
1902                                 slapd_close( rd );
1903                         }
1904                 }
1905                 ldap_pvt_thread_yield();
1906         }
1907
1908         if( slapd_shutdown == 1 ) {
1909 #ifdef NEW_LOGGING
1910                 LDAP_LOG( CONNECTION, CRIT,
1911                    "slapd_daemon_task: shutdown requested and initiated.\n", 0, 0, 0 );
1912 #else
1913                 Debug( LDAP_DEBUG_TRACE,
1914                         "daemon: shutdown requested and initiated.\n",
1915                         0, 0, 0 );
1916 #endif
1917
1918         } else if ( slapd_shutdown == 2 ) {
1919 #ifdef HAVE_NT_SERVICE_MANAGER
1920 #ifdef NEW_LOGGING
1921                         LDAP_LOG( CONNECTION, CRIT,
1922                            "slapd_daemon_task: shutdown initiated by Service Manager.\n",
1923                            0, 0, 0);
1924 #else
1925                         Debug( LDAP_DEBUG_TRACE,
1926                                "daemon: shutdown initiated by Service Manager.\n",
1927                                0, 0, 0);
1928 #endif
1929 #else /* !HAVE_NT_SERVICE_MANAGER */
1930 #ifdef NEW_LOGGING
1931                         LDAP_LOG( CONNECTION, CRIT,
1932                            "slapd_daemon_task: abnormal condition, "
1933                            "shutdown initiated.\n", 0, 0, 0 );
1934 #else
1935                         Debug( LDAP_DEBUG_TRACE,
1936                                "daemon: abnormal condition, shutdown initiated.\n",
1937                                0, 0, 0 );
1938 #endif
1939 #endif /* !HAVE_NT_SERVICE_MANAGER */
1940         } else {
1941 #ifdef NEW_LOGGING
1942                 LDAP_LOG( CONNECTION, CRIT,
1943                    "slapd_daemon_task: no active streams, shutdown initiated.\n", 
1944                    0, 0, 0 );
1945 #else
1946                 Debug( LDAP_DEBUG_TRACE,
1947                        "daemon: no active streams, shutdown initiated.\n",
1948                        0, 0, 0 );
1949 #endif
1950         }
1951
1952         if( slapd_gentle_shutdown != 2 ) {
1953                 close_listeners ( 0 );
1954         }
1955
1956         free ( slap_listeners );
1957         slap_listeners = NULL;
1958
1959         if( !slapd_gentle_shutdown ) {
1960                 connections_shutdown();
1961         }
1962
1963 #ifdef NEW_LOGGING
1964         LDAP_LOG( CONNECTION, CRIT, 
1965                 "slapd_daemon_task: shutdown waiting for %d threads to terminate.\n",
1966                 ldap_pvt_thread_pool_backload(&connection_pool), 0, 0 );
1967 #else
1968         Debug( LDAP_DEBUG_ANY,
1969             "slapd shutdown: waiting for %d threads to terminate\n",
1970             ldap_pvt_thread_pool_backload(&connection_pool), 0, 0 );
1971 #endif
1972         ldap_pvt_thread_pool_destroy(&connection_pool, 1);
1973
1974         return NULL;
1975 }
1976
1977
1978 int slapd_daemon( void )
1979 {
1980         int rc;
1981
1982         connections_init();
1983
1984 #define SLAPD_LISTENER_THREAD 1
1985 #if defined( SLAPD_LISTENER_THREAD )
1986         {
1987                 ldap_pvt_thread_t       listener_tid;
1988
1989                 /* listener as a separate THREAD */
1990                 rc = ldap_pvt_thread_create( &listener_tid,
1991                         0, slapd_daemon_task, NULL );
1992
1993                 if ( rc != 0 ) {
1994 #ifdef NEW_LOGGING
1995                         LDAP_LOG( CONNECTION, ERR, 
1996                                 "slapd_daemon: listener ldap_pvt_thread_create failed (%d).\n",
1997                                 rc, 0, 0 );
1998 #else
1999                         Debug( LDAP_DEBUG_ANY,
2000                         "listener ldap_pvt_thread_create failed (%d)\n", rc, 0, 0 );
2001 #endif
2002                         return rc;
2003                 }
2004  
2005                 /* wait for the listener thread to complete */
2006                 ldap_pvt_thread_join( listener_tid, (void *) NULL );
2007         }
2008 #else
2009         /* experimental code */
2010         slapd_daemon_task( NULL );
2011 #endif
2012
2013         return 0;
2014
2015 }
2016
2017 int sockinit(void)
2018 {
2019 #if defined( HAVE_WINSOCK2 )
2020     WORD wVersionRequested;
2021         WSADATA wsaData;
2022         int err;
2023
2024         wVersionRequested = MAKEWORD( 2, 0 );
2025
2026         err = WSAStartup( wVersionRequested, &wsaData );
2027         if ( err != 0 ) {
2028                 /* Tell the user that we couldn't find a usable */
2029                 /* WinSock DLL.                                  */
2030                 return -1;
2031         }
2032
2033         /* Confirm that the WinSock DLL supports 2.0.*/
2034         /* Note that if the DLL supports versions greater    */
2035         /* than 2.0 in addition to 2.0, it will still return */
2036         /* 2.0 in wVersion since that is the version we      */
2037         /* requested.                                        */
2038
2039         if ( LOBYTE( wsaData.wVersion ) != 2 ||
2040                 HIBYTE( wsaData.wVersion ) != 0 )
2041         {
2042             /* Tell the user that we couldn't find a usable */
2043             /* WinSock DLL.                                  */
2044             WSACleanup();
2045             return -1;
2046         }
2047
2048         /* The WinSock DLL is acceptable. Proceed. */
2049 #elif defined( HAVE_WINSOCK )
2050         WSADATA wsaData;
2051         if ( WSAStartup( 0x0101, &wsaData ) != 0 ) {
2052             return -1;
2053         }
2054 #endif
2055         return 0;
2056 }
2057
2058 int sockdestroy(void)
2059 {
2060 #if defined( HAVE_WINSOCK2 ) || defined( HAVE_WINSOCK )
2061         WSACleanup();
2062 #endif
2063         return 0;
2064 }
2065
2066 RETSIGTYPE
2067 slap_sig_shutdown( int sig )
2068 {
2069 #if 0
2070 #ifdef NEW_LOGGING
2071         LDAP_LOG( CONNECTION, CRIT, 
2072                 "slap_sig_shutdown: signal %d\n", sig, 0, 0 );
2073 #else
2074         Debug(LDAP_DEBUG_TRACE, "slap_sig_shutdown: signal %d\n", sig, 0, 0);
2075 #endif
2076 #endif
2077
2078         /*
2079          * If the NT Service Manager is controlling the server, we don't
2080          * want SIGBREAK to kill the server. For some strange reason,
2081          * SIGBREAK is generated when a user logs out.
2082          */
2083
2084 #if 0
2085 #if HAVE_NT_SERVICE_MANAGER && SIGBREAK
2086         if (is_NT_Service && sig == SIGBREAK)
2087 #ifdef NEW_LOGGING
2088             LDAP_LOG( CONNECTION, CRIT,
2089                     "slap_sig_shutdown: SIGBREAK ignored.\n", 0, 0, 0 );
2090 #else
2091             Debug(LDAP_DEBUG_TRACE, "slap_sig_shutdown: SIGBREAK ignored.\n",
2092                   0, 0, 0);
2093 #endif
2094         else
2095 #endif
2096 #endif
2097 #ifdef SIGHUP
2098         if (sig == SIGHUP && global_gentlehup && slapd_gentle_shutdown == 0)
2099                 slapd_gentle_shutdown = 1;
2100         else
2101 #endif
2102         slapd_shutdown = 1;
2103
2104         WAKE_LISTENER(1);
2105
2106         /* reinstall self */
2107         (void) SIGNAL_REINSTALL( sig, slap_sig_shutdown );
2108 }
2109
2110 RETSIGTYPE
2111 slap_sig_wake( int sig )
2112 {
2113         WAKE_LISTENER(1);
2114
2115         /* reinstall self */
2116         (void) SIGNAL_REINSTALL( sig, slap_sig_wake );
2117 }
2118
2119
2120 void slapd_add_internal(ber_socket_t s) {
2121         slapd_add(s);
2122 }
2123
2124 Listener ** slapd_get_listeners(void) {
2125         return slap_listeners;
2126 }