]> git.sur5r.net Git - openldap/blob - servers/slapd/daemon.c
First rounded of changes in prep for 2.2.beta3
[openldap] / servers / slapd / daemon.c
1 /* $OpenLDAP$ */
2 /*
3  * Copyright 1998-2003 The OpenLDAP Foundation, All Rights Reserved.
4  * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
5  */
6
7 #include "portable.h"
8
9 #include <stdio.h>
10
11 #include <ac/ctype.h>
12 #include <ac/errno.h>
13 #include <ac/socket.h>
14 #include <ac/string.h>
15 #include <ac/time.h>
16 #include <ac/unistd.h>
17
18 #include "ldap_pvt.h"
19 #include "ldap_pvt_thread.h"
20 #include "lutil.h"
21 #include "slap.h"
22
23 #include "ldap_rq.h"
24
25 #ifdef HAVE_TCPD
26 #include <tcpd.h>
27 #define SLAP_STRING_UNKNOWN     STRING_UNKNOWN
28
29 int allow_severity = LOG_INFO;
30 int deny_severity = LOG_NOTICE;
31 #else /* ! TCP Wrappers */
32 #define SLAP_STRING_UNKNOWN     "unknown"
33 #endif /* ! TCP Wrappers */
34
35 #ifdef LDAP_PF_LOCAL
36 #include <sys/stat.h>
37 /* this should go in <ldap.h> as soon as it is accepted */
38 #define LDAPI_MOD_URLEXT                "x-mod"
39 #endif /* LDAP_PF_LOCAL */
40
41 #ifdef LDAP_PF_INET6
42 int slap_inet4or6 = AF_UNSPEC;
43 #else
44 int slap_inet4or6 = AF_INET;
45 #endif
46
47 /* globals */
48 time_t starttime;
49 ber_socket_t dtblsize;
50
51 Listener **slap_listeners = NULL;
52
53 #define SLAPD_LISTEN 10
54
55 static ber_socket_t wake_sds[2];
56 static int emfile;
57
58 #if defined(NO_THREADS) || defined(HAVE_GNU_PTH)
59 static int waking;
60 #define WAKE_LISTENER(w) \
61 ((w && !waking) ? tcp_write( wake_sds[1], "0", 1 ), waking=1 : 0)
62 #else
63 #define WAKE_LISTENER(w) \
64 do { if (w) tcp_write( wake_sds[1], "0", 1 ); } while(0)
65 #endif
66
67 #ifndef HAVE_WINSOCK
68 static
69 #endif
70 volatile sig_atomic_t slapd_shutdown = 0, slapd_gentle_shutdown = 0;
71 volatile sig_atomic_t slapd_abrupt_shutdown = 0;
72
73 static struct slap_daemon {
74         ldap_pvt_thread_mutex_t sd_mutex;
75
76         ber_socket_t sd_nactives;
77
78 #ifndef HAVE_WINSOCK
79         /* In winsock, accept() returns values higher than dtblsize
80                 so don't bother with this optimization */
81         int sd_nfds;
82 #endif
83
84         fd_set sd_actives;
85         fd_set sd_readers;
86         fd_set sd_writers;
87 } slap_daemon;
88
89
90
91 #ifdef HAVE_SLP
92 /*
93  * SLP related functions
94  */
95 #include <slp.h>
96
97 #define LDAP_SRVTYPE_PREFIX "service:ldap://"
98 #define LDAPS_SRVTYPE_PREFIX "service:ldaps://"
99 static char** slapd_srvurls = NULL;
100 static SLPHandle slapd_hslp = 0;
101
102 void slapd_slp_init( const char* urls ) {
103         int i;
104
105         slapd_srvurls = ldap_str2charray( urls, " " );
106
107         if( slapd_srvurls == NULL ) return;
108
109         /* find and expand INADDR_ANY URLs */
110         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
111                 if( strcmp( slapd_srvurls[i], "ldap:///" ) == 0) {
112                         char *host = ldap_pvt_get_fqdn( NULL );
113                         if ( host != NULL ) {
114                                 slapd_srvurls[i] = (char *) ch_realloc( slapd_srvurls[i],
115                                         strlen( host ) +
116                                         sizeof( LDAP_SRVTYPE_PREFIX ) );
117                                 strcpy( lutil_strcopy(slapd_srvurls[i],
118                                         LDAP_SRVTYPE_PREFIX ), host );
119
120                                 ch_free( host );
121                         }
122
123                 } else if ( strcmp( slapd_srvurls[i], "ldaps:///" ) == 0) {
124                         char *host = ldap_pvt_get_fqdn( NULL );
125                         if ( host != NULL ) {
126                                 slapd_srvurls[i] = (char *) ch_realloc( slapd_srvurls[i],
127                                         strlen( host ) +
128                                         sizeof( LDAPS_SRVTYPE_PREFIX ) );
129                                 strcpy( lutil_strcopy(slapd_srvurls[i],
130                                         LDAPS_SRVTYPE_PREFIX ), host );
131
132                                 ch_free( host );
133                         }
134                 }
135         }
136
137         /* open the SLP handle */
138         SLPOpen( "en", 0, &slapd_hslp );
139 }
140
141 void slapd_slp_deinit() {
142         if( slapd_srvurls == NULL ) return;
143
144         ldap_charray_free( slapd_srvurls );
145         slapd_srvurls = NULL;
146
147         /* close the SLP handle */
148         SLPClose( slapd_hslp );
149 }
150
151 void slapd_slp_regreport(
152         SLPHandle hslp,
153         SLPError errcode,
154         void* cookie )
155 {
156         /* empty report */
157 }
158
159 void slapd_slp_reg() {
160         int i;
161
162         if( slapd_srvurls == NULL ) return;
163
164         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
165                 if( strncmp( slapd_srvurls[i], LDAP_SRVTYPE_PREFIX,
166                                 sizeof( LDAP_SRVTYPE_PREFIX ) - 1 ) == 0 ||
167                     strncmp( slapd_srvurls[i], LDAPS_SRVTYPE_PREFIX,
168                                 sizeof( LDAPS_SRVTYPE_PREFIX ) - 1 ) == 0 )
169                 {
170                         SLPReg( slapd_hslp,
171                                 slapd_srvurls[i],
172                                 SLP_LIFETIME_MAXIMUM,
173                                 "ldap",
174                                 "",
175                                 1,
176                                 slapd_slp_regreport,
177                                 NULL );
178                 }
179         }
180 }
181
182 void slapd_slp_dereg() {
183         int i;
184
185         if( slapd_srvurls == NULL ) return;
186
187         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
188                 SLPDereg( slapd_hslp,
189                         slapd_srvurls[i],
190                         slapd_slp_regreport,
191                         NULL );
192         }
193 }
194 #endif /* HAVE_SLP */
195
196 /*
197  * Add a descriptor to daemon control
198  *
199  * If isactive, the descriptor is a live server session and is subject
200  * to idletimeout control. Otherwise, the descriptor is a passive
201  * listener or an outbound client session, and not subject to
202  * idletimeout.
203  */
204 static void slapd_add(ber_socket_t s, int isactive) {
205         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
206
207         assert( !FD_ISSET( s, &slap_daemon.sd_actives ));
208         assert( !FD_ISSET( s, &slap_daemon.sd_readers ));
209         assert( !FD_ISSET( s, &slap_daemon.sd_writers ));
210
211 #ifndef HAVE_WINSOCK
212         if (s >= slap_daemon.sd_nfds) {
213                 slap_daemon.sd_nfds = s + 1;
214         }
215 #endif
216
217         if ( isactive ) {
218                 slap_daemon.sd_nactives++;
219         }
220
221         FD_SET( s, &slap_daemon.sd_actives );
222         FD_SET( s, &slap_daemon.sd_readers );
223
224 #ifdef NEW_LOGGING
225         LDAP_LOG( CONNECTION, DETAIL1, 
226                 "slapd_add: added %ld%s%s\n", (long)s,
227                 FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
228                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : "" );
229 #else
230         Debug( LDAP_DEBUG_CONNS, "daemon: added %ld%s%s\n",
231                 (long) s,
232             FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
233                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : "" );
234 #endif
235         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
236 }
237
238 /*
239  * Remove the descriptor from daemon control
240  */
241 void slapd_remove(ber_socket_t s, int wasactive, int wake) {
242         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
243
244         if ( wasactive ) {
245                 slap_daemon.sd_nactives--;
246         }
247
248 #ifdef NEW_LOGGING
249         LDAP_LOG( CONNECTION, DETAIL1, 
250                 "slapd_remove: removing %ld%s%s\n", (long) s,
251                 FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
252                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : ""  );
253 #else
254         Debug( LDAP_DEBUG_CONNS, "daemon: removing %ld%s%s\n",
255                 (long) s,
256             FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
257                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : "" );
258 #endif
259         FD_CLR( s, &slap_daemon.sd_actives );
260         FD_CLR( s, &slap_daemon.sd_readers );
261         FD_CLR( s, &slap_daemon.sd_writers );
262
263         /* If we ran out of file descriptors, we dropped a listener from
264          * the select() loop. Now that we're removing a session from our
265          * control, we can try to resume a dropped listener to use.
266          */
267         if ( emfile ) {
268                 int i;
269                 for ( i = 0; slap_listeners[i] != NULL; i++ ) {
270                         if ( slap_listeners[i]->sl_sd != AC_SOCKET_INVALID ) {
271                                 if ( slap_listeners[i]->sl_sd == s ) continue;
272                                 if ( slap_listeners[i]->sl_is_mute ) {
273                                         slap_listeners[i]->sl_is_mute = 0;
274                                         emfile--;
275                                         break;
276                                 }
277                         }
278                 }
279                 /* Walked the entire list without enabling anything; emfile
280                  * counter is stale. Reset it.
281                  */
282                 if ( slap_listeners[i] == NULL )
283                         emfile = 0;
284         }
285         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
286         WAKE_LISTENER(wake || slapd_gentle_shutdown == 2);
287 }
288
289 void slapd_clr_write(ber_socket_t s, int wake) {
290         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
291
292         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
293         FD_CLR( s, &slap_daemon.sd_writers );
294
295         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
296         WAKE_LISTENER(wake);
297 }
298
299 void slapd_set_write(ber_socket_t s, int wake) {
300         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
301
302         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
303         if (!FD_ISSET(s, &slap_daemon.sd_writers))
304             FD_SET( (unsigned) s, &slap_daemon.sd_writers );
305
306         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
307         WAKE_LISTENER(wake);
308 }
309
310 void slapd_clr_read(ber_socket_t s, int wake) {
311         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
312
313         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
314         FD_CLR( s, &slap_daemon.sd_readers );
315
316         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
317         WAKE_LISTENER(wake);
318 }
319
320 void slapd_set_read(ber_socket_t s, int wake) {
321         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
322
323         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
324         if (!FD_ISSET(s, &slap_daemon.sd_readers))
325             FD_SET( s, &slap_daemon.sd_readers );
326
327         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
328         WAKE_LISTENER(wake);
329 }
330
331 static void slapd_close(ber_socket_t s) {
332 #ifdef NEW_LOGGING
333         LDAP_LOG( CONNECTION, DETAIL1, "slapd_close: closing %ld\n", (long)s, 0, 0);
334 #else
335         Debug( LDAP_DEBUG_CONNS, "daemon: closing %ld\n",
336                 (long) s, 0, 0 );
337 #endif
338         tcp_close(s);
339 }
340
341 static void slap_free_listener_addresses(struct sockaddr **sal)
342 {
343         struct sockaddr **sap;
344
345         if (sal == NULL) {
346                 return;
347         }
348
349         for (sap = sal; *sap != NULL; sap++) {
350                 ch_free(*sap);
351         }
352
353         ch_free(sal);
354 }
355
356 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
357 static int get_url_perms(
358         char    **exts,
359         mode_t  *perms,
360         int     *crit )
361 {
362         int     i;
363
364         assert( exts );
365         assert( perms );
366         assert( crit );
367
368         *crit = 0;
369         for ( i = 0; exts[ i ]; i++ ) {
370                 char    *type = exts[ i ];
371                 int     c = 0;
372
373                 if ( type[ 0 ] == '!' ) {
374                         c = 1;
375                         type++;
376                 }
377
378                 if ( strncasecmp( type, LDAPI_MOD_URLEXT "=", sizeof(LDAPI_MOD_URLEXT "=") - 1 ) == 0 ) {
379                         char    *value = type
380                                 + ( sizeof(LDAPI_MOD_URLEXT "=") - 1 );
381                         mode_t  p = 0;
382                         int     j;
383
384                         switch (strlen(value)) {
385                         case 4:
386                                 /* skip leading '0' */
387                                 if ( value[ 0 ] != '0' ) {
388                                         return LDAP_OTHER;
389                                 }
390                                 value++;
391
392                         case 3:
393                                 for ( j = 0; j < 3; j++) {
394                                         int     v;
395
396                                         v = value[ j ] - '0';
397
398                                         if ( v < 0 || v > 7 ) {
399                                                 return LDAP_OTHER;
400                                         }
401
402                                         p |= v << 3*(2-j);
403                                 }
404                                 break;
405
406                         case 10:
407                                 for ( j = 1; j < 10; j++ ) {
408                                         static mode_t   m[] = { 0, 
409                                                 S_IRUSR, S_IWUSR, S_IXUSR,
410                                                 S_IRGRP, S_IWGRP, S_IXGRP,
411                                                 S_IROTH, S_IWOTH, S_IXOTH
412                                         };
413                                         static char     c[] = "-rwxrwxrwx"; 
414
415                                         if ( value[ j ] == c[ j ] ) {
416                                                 p |= m[ j ];
417         
418                                         } else if ( value[ j ] != '-' ) {
419                                                 return LDAP_OTHER;
420                                         }
421                                 }
422                                 break;
423
424                         default:
425                                 return LDAP_OTHER;
426                         } 
427
428                         *crit = c;
429                         *perms = p;
430
431                         return LDAP_SUCCESS;
432                 }
433         }
434
435         return LDAP_OTHER;
436 }
437 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
438
439 /* port = 0 indicates AF_LOCAL */
440 static int slap_get_listener_addresses(
441         const char *host,
442         unsigned short port,
443         struct sockaddr ***sal)
444 {
445         struct sockaddr **sap;
446
447 #ifdef LDAP_PF_LOCAL
448         if ( port == 0 ) {
449                 *sal = ch_malloc(2 * sizeof(void *));
450                 if (*sal == NULL) {
451                         return -1;
452                 }
453
454                 sap = *sal;
455                 *sap = ch_malloc(sizeof(struct sockaddr_un));
456                 if (*sap == NULL)
457                         goto errexit;
458                 sap[1] = NULL;
459
460                 if ( strlen(host) >
461                      (sizeof(((struct sockaddr_un *)*sap)->sun_path) - 1) ) {
462 #ifdef NEW_LOGGING
463                         LDAP_LOG( CONNECTION, INFO, 
464                                 "slap_get_listener_addresses: domain socket path (%s) "
465                                 "too long in URL\n", host, 0, 0 );
466 #else
467                         Debug( LDAP_DEBUG_ANY,
468                                "daemon: domain socket path (%s) too long in URL",
469                                host, 0, 0);
470 #endif
471                         goto errexit;
472                 }
473
474                 (void)memset( (void *)*sap, '\0', sizeof(struct sockaddr_un) );
475                 (*sap)->sa_family = AF_LOCAL;
476                 strcpy( ((struct sockaddr_un *)*sap)->sun_path, host );
477         } else
478 #endif
479         {
480 #ifdef HAVE_GETADDRINFO
481                 struct addrinfo hints, *res, *sai;
482                 int n, err;
483                 char serv[7];
484
485                 memset( &hints, '\0', sizeof(hints) );
486                 hints.ai_flags = AI_PASSIVE;
487                 hints.ai_socktype = SOCK_STREAM;
488                 hints.ai_family = slap_inet4or6;
489                 snprintf(serv, sizeof serv, "%d", port);
490
491                 if ( (err = getaddrinfo(host, serv, &hints, &res)) ) {
492 #ifdef NEW_LOGGING
493                         LDAP_LOG( CONNECTION, INFO, 
494                                    "slap_get_listener_addresses: getaddrinfo failed: %s\n",
495                                    AC_GAI_STRERROR(err), 0, 0 );
496 #else
497                         Debug( LDAP_DEBUG_ANY, "daemon: getaddrinfo failed: %s\n",
498                                 AC_GAI_STRERROR(err), 0, 0);
499 #endif
500                         return -1;
501                 }
502
503                 sai = res;
504                 for (n=2; (sai = sai->ai_next) != NULL; n++) {
505                         /* EMPTY */ ;
506                 }
507                 *sal = ch_calloc(n, sizeof(void *));
508                 if (*sal == NULL) {
509                         return -1;
510                 }
511
512                 sap = *sal;
513                 *sap = NULL;
514
515                 for ( sai=res; sai; sai=sai->ai_next ) {
516                         if( sai->ai_addr == NULL ) {
517 #ifdef NEW_LOGGING
518                                 LDAP_LOG( CONNECTION, INFO,
519                                         "slap_get_listener_addresses: "
520                                         "getaddrinfo ai_addr is NULL?\n", 0, 0, 0 );
521 #else
522                                 Debug( LDAP_DEBUG_ANY, "slap_get_listener_addresses: "
523                                         "getaddrinfo ai_addr is NULL?\n", 0, 0, 0 );
524 #endif
525                                 freeaddrinfo(res);
526                                 goto errexit;
527                         }
528
529                         switch (sai->ai_family) {
530 #  ifdef LDAP_PF_INET6
531                         case AF_INET6:
532                                 *sap = ch_malloc(sizeof(struct sockaddr_in6));
533                                 if (*sap == NULL) {
534                                         freeaddrinfo(res);
535                                         goto errexit;
536                                 }
537                                 *(struct sockaddr_in6 *)*sap =
538                                         *((struct sockaddr_in6 *)sai->ai_addr);
539                                 break;
540 #  endif
541                         case AF_INET:
542                                 *sap = ch_malloc(sizeof(struct sockaddr_in));
543                                 if (*sap == NULL) {
544                                         freeaddrinfo(res);
545                                         goto errexit;
546                                 }
547                                 *(struct sockaddr_in *)*sap =
548                                         *((struct sockaddr_in *)sai->ai_addr);
549                                 break;
550                         default:
551                                 *sap = NULL;
552                                 break;
553                         }
554
555                         if (*sap != NULL) {
556                                 (*sap)->sa_family = sai->ai_family;
557                                 sap++;
558                                 *sap = NULL;
559                         }
560                 }
561
562                 freeaddrinfo(res);
563 #else
564                 int i, n = 1;
565                 struct in_addr in;
566                 struct hostent *he = NULL;
567
568                 if ( host == NULL ) {
569                         in.s_addr = htonl(INADDR_ANY);
570
571                 } else if ( !inet_aton( host, &in ) ) {
572                         he = gethostbyname( host );
573                         if( he == NULL ) {
574 #ifdef NEW_LOGGING
575                                 LDAP_LOG( CONNECTION, INFO, 
576                                         "slap_get_listener_addresses: invalid host %s\n", host, 0, 0 );
577 #else
578                                 Debug( LDAP_DEBUG_ANY,
579                                        "daemon: invalid host %s", host, 0, 0);
580 #endif
581                                 return -1;
582                         }
583                         for (n = 0; he->h_addr_list[n]; n++) ;
584                 }
585
586                 *sal = ch_malloc((n+1) * sizeof(void *));
587                 if (*sal == NULL) {
588                         return -1;
589                 }
590
591                 sap = *sal;
592                 for ( i = 0; i<n; i++ ) {
593                         sap[i] = ch_malloc(sizeof(struct sockaddr_in));
594                         if (*sap == NULL) {
595                                 goto errexit;
596                         }
597                         (void)memset( (void *)sap[i], '\0', sizeof(struct sockaddr_in) );
598                         sap[i]->sa_family = AF_INET;
599                         ((struct sockaddr_in *)sap[i])->sin_port = htons(port);
600                         if (he) {
601                                 AC_MEMCPY( &((struct sockaddr_in *)sap[i])->sin_addr, he->h_addr_list[i], sizeof(struct in_addr) );
602                         } else {
603                                 AC_MEMCPY( &((struct sockaddr_in *)sap[i])->sin_addr, &in, sizeof(struct in_addr) );
604                         }
605                 }
606                 sap[i] = NULL;
607 #endif
608         }
609
610         return 0;
611
612 errexit:
613         slap_free_listener_addresses(*sal);
614         return -1;
615 }
616
617 static int slap_open_listener(
618         const char* url,
619         int *listeners,
620         int *cur
621         )
622 {
623         int     num, tmp, rc;
624         Listener l;
625         Listener *li;
626         LDAPURLDesc *lud;
627         unsigned short port;
628         int err, addrlen = 0;
629         struct sockaddr **sal, **psal;
630         int socktype = SOCK_STREAM;     /* default to COTS */
631
632 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
633         /*
634          * use safe defaults
635          */
636         int     crit = 1;
637 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
638
639         rc = ldap_url_parse( url, &lud );
640
641         if( rc != LDAP_URL_SUCCESS ) {
642 #ifdef NEW_LOGGING
643                 LDAP_LOG( CONNECTION, ERR, 
644                         "slap_open_listener: listen URL \"%s\" parse error %d\n",
645                         url, rc , 0 );
646 #else
647                 Debug( LDAP_DEBUG_ANY,
648                         "daemon: listen URL \"%s\" parse error=%d\n",
649                         url, rc, 0 );
650 #endif
651                 return rc;
652         }
653
654         l.sl_url.bv_val = NULL;
655         l.sl_is_mute = 0;
656
657 #ifndef HAVE_TLS
658         if( ldap_pvt_url_scheme2tls( lud->lud_scheme ) ) {
659 #ifdef NEW_LOGGING
660                 LDAP_LOG( CONNECTION, INFO, 
661                            "slap_open_listener: TLS is not supported (%s)\n", url, 0, 0 );
662 #else
663                 Debug( LDAP_DEBUG_ANY,
664                         "daemon: TLS not supported (%s)\n",
665                         url, 0, 0 );
666 #endif
667                 ldap_free_urldesc( lud );
668                 return -1;
669         }
670
671         if(! lud->lud_port ) {
672                 lud->lud_port = LDAP_PORT;
673         }
674
675 #else
676         l.sl_is_tls = ldap_pvt_url_scheme2tls( lud->lud_scheme );
677
678         if(! lud->lud_port ) {
679                 lud->lud_port = l.sl_is_tls ? LDAPS_PORT : LDAP_PORT;
680         }
681 #endif
682
683         port = (unsigned short) lud->lud_port;
684
685         tmp = ldap_pvt_url_scheme2proto(lud->lud_scheme);
686         if ( tmp == LDAP_PROTO_IPC ) {
687 #ifdef LDAP_PF_LOCAL
688                 if ( lud->lud_host == NULL || lud->lud_host[0] == '\0' ) {
689                         err = slap_get_listener_addresses(LDAPI_SOCK, 0, &sal);
690                 } else {
691                         err = slap_get_listener_addresses(lud->lud_host, 0, &sal);
692                 }
693 #else
694
695 #ifdef NEW_LOGGING
696                 LDAP_LOG( CONNECTION, INFO, 
697                         "slap_open_listener: URL scheme is not supported: %s\n", url, 0, 0 );
698 #else
699                 Debug( LDAP_DEBUG_ANY, "daemon: URL scheme not supported: %s",
700                         url, 0, 0);
701 #endif
702                 ldap_free_urldesc( lud );
703                 return -1;
704 #endif
705         } else {
706                 if( lud->lud_host == NULL || lud->lud_host[0] == '\0'
707                         || strcmp(lud->lud_host, "*") == 0 )
708                 {
709                         err = slap_get_listener_addresses(NULL, port, &sal);
710                 } else {
711                         err = slap_get_listener_addresses(lud->lud_host, port, &sal);
712                 }
713         }
714 #ifdef LDAP_CONNECTIONLESS
715         l.sl_is_udp = ( tmp == LDAP_PROTO_UDP );
716 #endif
717
718 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
719         if ( lud->lud_exts ) {
720                 err = get_url_perms( lud->lud_exts, &l.sl_perms, &crit );
721         } else {
722                 l.sl_perms = S_IRWXU | S_IRWXO;
723         }
724 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
725
726         ldap_free_urldesc( lud );
727         if ( err ) {
728                 return -1;
729         }
730
731         /* If we got more than one address returned, we need to make space
732          * for it in the slap_listeners array.
733          */
734         for ( num=0; sal[num]; num++ );
735         if ( num > 1 ) {
736                 *listeners += num-1;
737                 slap_listeners = ch_realloc( slap_listeners, (*listeners + 1) * sizeof(Listener *) );
738         }
739
740         psal = sal;
741         while ( *sal != NULL ) {
742                 char *af;
743                 switch( (*sal)->sa_family ) {
744                 case AF_INET:
745                         af = "IPv4";
746                         break;
747 #ifdef LDAP_PF_INET6
748                 case AF_INET6:
749                         af = "IPv6";
750                         break;
751 #endif
752 #ifdef LDAP_PF_LOCAL
753                 case AF_LOCAL:
754                         af = "Local";
755                         break;
756 #endif
757                 default:
758                         sal++;
759                         continue;
760                 }
761 #ifdef LDAP_CONNECTIONLESS
762                 if( l.sl_is_udp ) socktype = SOCK_DGRAM;
763 #endif
764                 l.sl_sd = socket( (*sal)->sa_family, socktype, 0);
765                 if ( l.sl_sd == AC_SOCKET_INVALID ) {
766                         int err = sock_errno();
767 #ifdef NEW_LOGGING
768                         LDAP_LOG( CONNECTION, ERR, 
769                                 "slap_open_listener: %s socket() failed errno=%d (%s)\n",
770                                 af, err, sock_errstr(err) );
771 #else
772                         Debug( LDAP_DEBUG_ANY,
773                                 "daemon: %s socket() failed errno=%d (%s)\n",
774                                 af, err, sock_errstr(err) );
775 #endif
776                         sal++;
777                         continue;
778                 }
779 #ifndef HAVE_WINSOCK
780                 if ( l.sl_sd >= dtblsize ) {
781 #ifdef NEW_LOGGING
782                         LDAP_LOG( CONNECTION, ERR, 
783                                 "slap_open_listener: listener descriptor %ld is too "
784                                 "great %ld\n", (long)l.sl_sd, (long)dtblsize, 0 );
785 #else
786                         Debug( LDAP_DEBUG_ANY,
787                                 "daemon: listener descriptor %ld is too great %ld\n",
788                                 (long) l.sl_sd, (long) dtblsize, 0 );
789 #endif
790                         tcp_close( l.sl_sd );
791                         sal++;
792                         continue;
793                 }
794 #endif
795 #ifdef LDAP_PF_LOCAL
796                 if ( (*sal)->sa_family == AF_LOCAL ) {
797                         unlink ( ((struct sockaddr_un *)*sal)->sun_path );
798                 } else
799 #endif
800                 {
801 #ifdef SO_REUSEADDR
802                         /* enable address reuse */
803                         tmp = 1;
804                         rc = setsockopt( l.sl_sd, SOL_SOCKET, SO_REUSEADDR,
805                                 (char *) &tmp, sizeof(tmp) );
806                         if ( rc == AC_SOCKET_ERROR ) {
807                                 int err = sock_errno();
808 #ifdef NEW_LOGGING
809                                 LDAP_LOG( CONNECTION, INFO, 
810                                         "slap_open_listener: setsockopt( %ld, SO_REUSEADDR ) "
811                                         "failed errno %d (%s)\n", (long)l.sl_sd, err, 
812                                         sock_errstr(err) );
813 #else
814                                 Debug( LDAP_DEBUG_ANY,
815                                        "slapd(%ld): setsockopt(SO_REUSEADDR) failed errno=%d (%s)\n",
816                                        (long) l.sl_sd, err, sock_errstr(err) );
817 #endif
818                         }
819 #endif
820                 }
821
822                 switch( (*sal)->sa_family ) {
823                 case AF_INET:
824                         addrlen = sizeof(struct sockaddr_in);
825                         break;
826 #ifdef LDAP_PF_INET6
827                 case AF_INET6:
828 #ifdef IPV6_V6ONLY
829                         /* Try to use IPv6 sockets for IPv6 only */
830                         tmp = 1;
831                         rc = setsockopt( l.sl_sd, IPPROTO_IPV6, IPV6_V6ONLY,
832                                          (char *) &tmp, sizeof(tmp) );
833                         if ( rc == AC_SOCKET_ERROR ) {
834                                 int err = sock_errno();
835 #ifdef NEW_LOGGING
836                                 LDAP_LOG( CONNECTION, INFO,
837                                            "slap_open_listener: setsockopt( %ld, IPV6_V6ONLY ) failed errno %d (%s)\n",
838                                            (long)l.sl_sd, err, sock_errstr(err) );
839 #else
840                                 Debug( LDAP_DEBUG_ANY,
841                                        "slapd(%ld): setsockopt(IPV6_V6ONLY) failed errno=%d (%s)\n",
842                                        (long) l.sl_sd, err, sock_errstr(err) );
843 #endif
844                         }
845 #endif
846                         addrlen = sizeof(struct sockaddr_in6);
847                         break;
848 #endif
849 #ifdef LDAP_PF_LOCAL
850                 case AF_LOCAL:
851                         addrlen = sizeof(struct sockaddr_un);
852                         break;
853 #endif
854                 }
855
856                 if (bind(l.sl_sd, *sal, addrlen)) {
857                         err = sock_errno();
858 #ifdef NEW_LOGGING
859                 LDAP_LOG( CONNECTION, INFO, 
860                         "slap_open_listener: bind(%ld) failed errno=%d (%s)\n",
861                         (long)l.sl_sd, err, sock_errstr(err) );
862 #else
863                 Debug( LDAP_DEBUG_ANY, "daemon: bind(%ld) failed errno=%d (%s)\n",
864                        (long) l.sl_sd, err, sock_errstr(err) );
865 #endif
866                         tcp_close( l.sl_sd );
867                         sal++;
868                         continue;
869                 }
870
871         switch ( (*sal)->sa_family ) {
872 #ifdef LDAP_PF_LOCAL
873         case AF_LOCAL: {
874                 char *addr = ((struct sockaddr_un *)*sal)->sun_path;
875 #if 0 /* don't muck with socket perms */
876                 if ( chmod( addr, l.sl_perms ) < 0 && crit ) {
877                         int err = sock_errno();
878 #ifdef NEW_LOGGING
879                         LDAP_LOG( CONNECTION, INFO, 
880                                 "slap_open_listener: fchmod(%ld) failed errno=%d (%s)\n",
881                                 (long)l.sl_sd, err, sock_errstr(err) );
882 #else
883                         Debug( LDAP_DEBUG_ANY, "daemon: fchmod(%ld) failed errno=%d (%s)",
884                                (long) l.sl_sd, err, sock_errstr(err) );
885 #endif
886                         tcp_close( l.sl_sd );
887                         slap_free_listener_addresses(psal);
888                         return -1;
889                 }
890 #endif
891                 l.sl_name.bv_len = strlen(addr) + sizeof("PATH=") - 1;
892                 l.sl_name.bv_val = ber_memalloc( l.sl_name.bv_len + 1 );
893                 snprintf( l.sl_name.bv_val, l.sl_name.bv_len + 1, 
894                                 "PATH=%s", addr );
895         } break;
896 #endif /* LDAP_PF_LOCAL */
897
898         case AF_INET: {
899                 char *s;
900 #if defined( HAVE_GETADDRINFO ) && defined( HAVE_INET_NTOP )
901                 char addr[INET_ADDRSTRLEN];
902                 inet_ntop( AF_INET, &((struct sockaddr_in *)*sal)->sin_addr,
903                            addr, sizeof(addr) );
904                 s = addr;
905 #else
906                 s = inet_ntoa( ((struct sockaddr_in *) *sal)->sin_addr );
907 #endif
908                 port = ntohs( ((struct sockaddr_in *)*sal) ->sin_port );
909                 l.sl_name.bv_val = ber_memalloc( sizeof("IP=255.255.255.255:65535") );
910                 snprintf( l.sl_name.bv_val, sizeof("IP=255.255.255.255:65535"),
911                         "IP=%s:%d",
912                          s != NULL ? s : SLAP_STRING_UNKNOWN, port );
913                 l.sl_name.bv_len = strlen( l.sl_name.bv_val );
914         } break;
915
916 #ifdef LDAP_PF_INET6
917         case AF_INET6: {
918                 char addr[INET6_ADDRSTRLEN];
919                 inet_ntop( AF_INET6, &((struct sockaddr_in6 *)*sal)->sin6_addr,
920                            addr, sizeof addr);
921                 port = ntohs( ((struct sockaddr_in6 *)*sal)->sin6_port );
922                 l.sl_name.bv_len = strlen(addr) + sizeof("IP= 65535");
923                 l.sl_name.bv_val = ber_memalloc( l.sl_name.bv_len );
924                 snprintf( l.sl_name.bv_val, l.sl_name.bv_len, "IP=%s %d", 
925                                 addr, port );
926                 l.sl_name.bv_len = strlen( l.sl_name.bv_val );
927         } break;
928 #endif /* LDAP_PF_INET6 */
929
930         default:
931 #ifdef NEW_LOGGING
932                 LDAP_LOG( CONNECTION, INFO, 
933                         "slap_open_listener: unsupported address family (%d)\n",
934                         (int)(*sal)->sa_family, 0, 0 );
935 #else
936                 Debug( LDAP_DEBUG_ANY, "daemon: unsupported address family (%d)\n",
937                         (int) (*sal)->sa_family, 0, 0 );
938 #endif
939                 break;
940         }
941
942         AC_MEMCPY(&l.sl_sa, *sal, addrlen);
943         ber_str2bv( url, 0, 1, &l.sl_url);
944         li = ch_malloc( sizeof( Listener ) );
945         *li = l;
946         slap_listeners[*cur] = li;
947         (*cur)++;
948         sal++;
949
950         } /* while ( *sal != NULL ) */
951
952         slap_free_listener_addresses(psal);
953
954         if ( l.sl_url.bv_val == NULL )
955         {
956 #ifdef NEW_LOGGING
957                 LDAP_LOG( CONNECTION, RESULTS, 
958                         "slap_open_listener: failed on %s\n", url, 0, 0 );
959 #else
960                 Debug( LDAP_DEBUG_TRACE,
961                         "slap_open_listener: failed on %s\n", url, 0, 0 );
962 #endif
963                 return -1;
964         }
965
966 #ifdef NEW_LOGGING
967         LDAP_LOG( CONNECTION, RESULTS, 
968                 "slap_open_listener: daemon initialized %s\n",
969                 l.sl_url.bv_val, 0, 0 );
970 #else
971         Debug( LDAP_DEBUG_TRACE, "daemon: initialized %s\n",
972                 l.sl_url.bv_val, 0, 0 );
973 #endif
974         return 0;
975 }
976
977 static int sockinit(void);
978 static int sockdestroy(void);
979
980 int slapd_daemon_init( const char *urls )
981 {
982         int i, j, n, rc;
983         char **u;
984
985 #ifdef NEW_LOGGING
986         LDAP_LOG( CONNECTION, ARGS, 
987                 "slapd_daemon_init: %s\n", urls ? urls : "<null>", 0, 0 );
988 #else
989         Debug( LDAP_DEBUG_ARGS, "daemon_init: %s\n",
990                 urls ? urls : "<null>", 0, 0 );
991 #endif
992         if( (rc = sockinit()) != 0 ) {
993                 return rc;
994         }
995
996 #ifdef HAVE_SYSCONF
997         dtblsize = sysconf( _SC_OPEN_MAX );
998 #elif HAVE_GETDTABLESIZE
999         dtblsize = getdtablesize();
1000 #else
1001         dtblsize = FD_SETSIZE;
1002 #endif
1003
1004 #ifdef FD_SETSIZE
1005         if(dtblsize > FD_SETSIZE) {
1006                 dtblsize = FD_SETSIZE;
1007         }
1008 #endif  /* !FD_SETSIZE */
1009
1010         /* open a pipe (or something equivalent connected to itself).
1011          * we write a byte on this fd whenever we catch a signal. The main
1012          * loop will be select'ing on this socket, and will wake up when
1013          * this byte arrives.
1014          */
1015         if( (rc = lutil_pair( wake_sds )) < 0 ) {
1016 #ifdef NEW_LOGGING
1017                 LDAP_LOG( CONNECTION, ERR, 
1018                         "slap_daemon_init: lutil_pair() failed rc=%d\n", rc, 0, 0);
1019 #else
1020                 Debug( LDAP_DEBUG_ANY,
1021                         "daemon: lutil_pair() failed rc=%d\n", rc, 0, 0 );
1022 #endif
1023                 return rc;
1024         }
1025
1026         FD_ZERO( &slap_daemon.sd_readers );
1027         FD_ZERO( &slap_daemon.sd_writers );
1028
1029         if( urls == NULL ) {
1030                 urls = "ldap:///";
1031         }
1032
1033         u = ldap_str2charray( urls, " " );
1034
1035         if( u == NULL || u[0] == NULL ) {
1036 #ifdef NEW_LOGGING
1037                 LDAP_LOG( CONNECTION, ERR, 
1038                         "slap_daemon_init: no urls (%s) provided.\n", urls, 0, 0 );
1039 #else
1040                 Debug( LDAP_DEBUG_ANY, "daemon_init: no urls (%s) provided.\n",
1041                         urls, 0, 0 );
1042 #endif
1043                 return -1;
1044         }
1045
1046         for( i=0; u[i] != NULL; i++ ) {
1047 #ifdef NEW_LOGGING
1048                 LDAP_LOG( CONNECTION, DETAIL1, 
1049                         "slap_daemon_init: listen on %s\n", u[i], 0, 0 );
1050 #else
1051                 Debug( LDAP_DEBUG_TRACE, "daemon_init: listen on %s\n",
1052                         u[i], 0, 0 );
1053 #endif
1054         }
1055
1056         if( i == 0 ) {
1057 #ifdef NEW_LOGGING
1058                 LDAP_LOG( CONNECTION, INFO, 
1059                          "slap_daemon_init: no listeners to open (%s)\n", urls, 0, 0 );
1060 #else
1061                 Debug( LDAP_DEBUG_ANY, "daemon_init: no listeners to open (%s)\n",
1062                         urls, 0, 0 );
1063 #endif
1064                 ldap_charray_free( u );
1065                 return -1;
1066         }
1067
1068 #ifdef NEW_LOGGING
1069         LDAP_LOG( CONNECTION, INFO, 
1070                 "slap_daemon_init: %d listeners to open...\n", i, 0, 0 );
1071 #else
1072         Debug( LDAP_DEBUG_TRACE, "daemon_init: %d listeners to open...\n",
1073                 i, 0, 0 );
1074 #endif
1075         slap_listeners = ch_malloc( (i+1)*sizeof(Listener *) );
1076
1077         for(n = 0, j = 0; u[n]; n++ ) {
1078                 if ( slap_open_listener( u[n], &i, &j ) ) {
1079                         ldap_charray_free( u );
1080                         return -1;
1081                 }
1082         }
1083         slap_listeners[j] = NULL;
1084
1085 #ifdef NEW_LOGGING
1086         LDAP_LOG( CONNECTION, DETAIL1, 
1087                 "slap_daemon_init: %d listeners opened\n", i, 0, 0 );
1088 #else
1089         Debug( LDAP_DEBUG_TRACE, "daemon_init: %d listeners opened\n",
1090                 i, 0, 0 );
1091 #endif
1092
1093 #ifdef HAVE_SLP
1094         slapd_slp_init( urls );
1095         slapd_slp_reg();
1096 #endif
1097
1098         ldap_charray_free( u );
1099         ldap_pvt_thread_mutex_init( &slap_daemon.sd_mutex );
1100         return !i;
1101 }
1102
1103
1104 int
1105 slapd_daemon_destroy(void)
1106 {
1107         connections_destroy();
1108         tcp_close( wake_sds[1] );
1109         tcp_close( wake_sds[0] );
1110         sockdestroy();
1111
1112 #ifdef HAVE_SLP
1113         slapd_slp_dereg();
1114         slapd_slp_deinit();
1115 #endif
1116
1117         return 0;
1118 }
1119
1120
1121 static void
1122 close_listeners(
1123         int remove
1124 )
1125 {
1126         int l;
1127
1128         for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1129                 if ( slap_listeners[l]->sl_sd != AC_SOCKET_INVALID ) {
1130                         if ( remove )
1131                                 slapd_remove( slap_listeners[l]->sl_sd, 0, 0 );
1132 #ifdef LDAP_PF_LOCAL
1133                         if ( slap_listeners[l]->sl_sa.sa_addr.sa_family == AF_LOCAL ) {
1134                                 unlink( slap_listeners[l]->sl_sa.sa_un_addr.sun_path );
1135                         }
1136 #endif /* LDAP_PF_LOCAL */
1137                         slapd_close( slap_listeners[l]->sl_sd );
1138                 }
1139                 if ( slap_listeners[l]->sl_url.bv_val )
1140                         ber_memfree( slap_listeners[l]->sl_url.bv_val );
1141                 if ( slap_listeners[l]->sl_name.bv_val )
1142                         ber_memfree( slap_listeners[l]->sl_name.bv_val );
1143                 free ( slap_listeners[l] );
1144                 slap_listeners[l] = NULL;
1145         }
1146 }
1147
1148
1149 static void *
1150 slapd_daemon_task(
1151         void *ptr
1152 )
1153 {
1154         int l;
1155         time_t  last_idle_check = 0;
1156         struct timeval idle;
1157
1158 #define SLAPD_IDLE_CHECK_LIMIT 4
1159
1160         if ( global_idletimeout > 0 ) {
1161                 last_idle_check = slap_get_time();
1162                 /* Set the select timeout.
1163                  * Don't just truncate, preserve the fractions of
1164                  * seconds to prevent sleeping for zero time.
1165                  */
1166                 idle.tv_sec = global_idletimeout/SLAPD_IDLE_CHECK_LIMIT;
1167                 idle.tv_usec = global_idletimeout - idle.tv_sec * SLAPD_IDLE_CHECK_LIMIT;
1168                 idle.tv_usec *= 1000000 / SLAPD_IDLE_CHECK_LIMIT;
1169         } else {
1170                 idle.tv_sec = 0;
1171                 idle.tv_usec = 0;
1172         }
1173
1174         for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1175                 if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1176                         continue;
1177 #ifdef LDAP_CONNECTIONLESS
1178                 /* Since this is connectionless, the data port is the
1179                  * listening port. The listen() and accept() calls
1180                  * are unnecessary.
1181                  */
1182                 if ( slap_listeners[l]->sl_is_udp ) {
1183                         slapd_add( slap_listeners[l]->sl_sd, 1 );
1184                         continue;
1185                 }
1186 #endif
1187
1188                 if ( listen( slap_listeners[l]->sl_sd, SLAPD_LISTEN ) == -1 ) {
1189                         int err = sock_errno();
1190
1191 #ifdef LDAP_PF_INET6
1192                         /* If error is EADDRINUSE, we are trying to listen to INADDR_ANY and
1193                          * we are already listening to in6addr_any, then we want to ignore
1194                          * this and continue.
1195                          */
1196                         if ( err == EADDRINUSE ) {
1197                                 int i;
1198                                 struct sockaddr_in sa = slap_listeners[l]->sl_sa.sa_in_addr;
1199                                 struct sockaddr_in6 sa6;
1200                                 
1201                                 if ( sa.sin_family == AF_INET &&
1202                                      sa.sin_addr.s_addr == htonl(INADDR_ANY) ) {
1203                                         for ( i = 0 ; i < l; i++ ) {
1204                                                 sa6 = slap_listeners[i]->sl_sa.sa_in6_addr;
1205                                                 if ( sa6.sin6_family == AF_INET6 &&
1206                                                      !memcmp( &sa6.sin6_addr, &in6addr_any, sizeof(struct in6_addr) ) )
1207                                                         break;
1208                                         }
1209
1210                                         if ( i < l ) {
1211                                                 /* We are already listening to in6addr_any */
1212 #ifdef NEW_LOGGING
1213                                                 LDAP_LOG(CONNECTION, WARNING,
1214                                                            "slapd_daemon_task: Attempt to listen to 0.0.0.0 failed, already listening on ::, assuming IPv4 included\n", 0, 0, 0 );
1215 #else
1216                                                 Debug( LDAP_DEBUG_CONNS,
1217                                                        "daemon: Attempt to listen to 0.0.0.0 failed, already listening on ::, assuming IPv4 included\n",
1218                                                        0, 0, 0 );
1219 #endif
1220                                                 slapd_close( slap_listeners[l]->sl_sd );
1221                                                 slap_listeners[l]->sl_sd = AC_SOCKET_INVALID;
1222                                                 continue;
1223                                         }
1224                                 }
1225                         }
1226 #endif                          
1227 #ifdef NEW_LOGGING
1228                         LDAP_LOG( CONNECTION, ERR, 
1229                                 "slapd_daemon_task: listen( %s, 5 ) failed errno=%d (%s)\n",
1230                                 slap_listeners[l]->sl_url.bv_val, err, sock_errstr(err) );
1231 #else
1232                         Debug( LDAP_DEBUG_ANY,
1233                                 "daemon: listen(%s, 5) failed errno=%d (%s)\n",
1234                                         slap_listeners[l]->sl_url.bv_val, err,
1235                                         sock_errstr(err) );
1236 #endif
1237                         return( (void*)-1 );
1238                 }
1239
1240                 slapd_add( slap_listeners[l]->sl_sd, 0 );
1241         }
1242
1243 #ifdef HAVE_NT_SERVICE_MANAGER
1244         if ( started_event != NULL ) {
1245                 ldap_pvt_thread_cond_signal( &started_event );
1246         }
1247 #endif
1248         /* initialization complete. Here comes the loop. */
1249
1250         while ( !slapd_shutdown ) {
1251                 ber_socket_t i;
1252                 int ns;
1253                 int at;
1254                 ber_socket_t nfds;
1255 #define SLAPD_EBADF_LIMIT 16
1256                 int ebadf = 0;
1257
1258                 time_t  now;
1259
1260                 fd_set                  readfds;
1261                 fd_set                  writefds;
1262                 Sockaddr                from;
1263
1264                 struct timeval          tv;
1265                 struct timeval          *tvp;
1266
1267                 struct timeval          *cat;
1268                 time_t                          tdelta = 1;
1269                 struct re_s*            rtask;
1270                 now = slap_get_time();
1271
1272                 if( ( global_idletimeout > 0 ) &&
1273                         difftime( last_idle_check +
1274                         global_idletimeout/SLAPD_IDLE_CHECK_LIMIT, now ) < 0 ) {
1275                         connections_timeout_idle( now );
1276                         last_idle_check = now;
1277                 }
1278                 tv = idle;
1279
1280 #ifdef SIGHUP
1281                 if( slapd_gentle_shutdown ) {
1282                         ber_socket_t active;
1283
1284                         if( slapd_gentle_shutdown == 1 ) {
1285                                 Debug( LDAP_DEBUG_ANY, "slapd gentle shutdown\n", 0, 0, 0 );
1286                                 close_listeners( 1 );
1287                                 global_restrictops |= SLAP_RESTRICT_OP_WRITES;
1288                                 slapd_gentle_shutdown = 2;
1289                         }
1290
1291                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1292                         active = slap_daemon.sd_nactives;
1293                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1294                         if( active == 0 ) {
1295                                 slapd_shutdown = 2;
1296                                 break;
1297                         }
1298                 }
1299 #endif
1300
1301                 FD_ZERO( &writefds );
1302                 FD_ZERO( &readfds );
1303
1304                 at = 0;
1305
1306                 ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1307
1308 #ifdef FD_SET_MANUAL_COPY
1309                 for( s = 0; s < nfds; s++ ) {
1310                         if(FD_ISSET( &slap_sd_readers, s )) {
1311                                 FD_SET( s, &readfds );
1312                         }
1313                         if(FD_ISSET( &slap_sd_writers, s )) {
1314                                 FD_SET( s, &writefds );
1315                         }
1316                 }
1317 #else
1318                 AC_MEMCPY( &readfds, &slap_daemon.sd_readers, sizeof(fd_set) );
1319                 AC_MEMCPY( &writefds, &slap_daemon.sd_writers, sizeof(fd_set) );
1320 #endif
1321                 assert(!FD_ISSET(wake_sds[0], &readfds));
1322                 FD_SET( wake_sds[0], &readfds );
1323
1324                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1325                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1326                                 continue;
1327                         if ( slap_listeners[l]->sl_is_mute )
1328                                 FD_CLR( slap_listeners[l]->sl_sd, &readfds );
1329                         else
1330                         if (!FD_ISSET(slap_listeners[l]->sl_sd, &readfds))
1331                             FD_SET( slap_listeners[l]->sl_sd, &readfds );
1332                 }
1333
1334 #ifndef HAVE_WINSOCK
1335                 nfds = slap_daemon.sd_nfds;
1336 #else
1337                 nfds = dtblsize;
1338 #endif
1339                 if ( global_idletimeout && slap_daemon.sd_nactives )
1340                         at = 1;
1341
1342                 ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1343
1344                 if ( at 
1345 #if defined(HAVE_YIELDING_SELECT) || defined(NO_THREADS)
1346                         &&  ( tv.tv_sec || tv.tv_usec )
1347 #endif
1348                         )
1349                         tvp = &tv;
1350                 else
1351                         tvp = NULL;
1352
1353                 ldap_pvt_thread_mutex_lock( &syncrepl_rq.rq_mutex );
1354                 rtask = ldap_pvt_runqueue_next_sched( &syncrepl_rq, &cat );
1355                 while ( cat && cat->tv_sec && cat->tv_sec <= now ) {
1356                         if ( ldap_pvt_runqueue_isrunning( &syncrepl_rq, rtask )) {
1357                                 ldap_pvt_runqueue_resched( &syncrepl_rq, rtask, 0 );
1358                         } else {
1359                                 ldap_pvt_runqueue_runtask( &syncrepl_rq, rtask );
1360                                 ldap_pvt_runqueue_resched( &syncrepl_rq, rtask, 0 );
1361                                 ldap_pvt_thread_mutex_unlock( &syncrepl_rq.rq_mutex );
1362                                 ldap_pvt_thread_pool_submit( &connection_pool,
1363                                                                                         rtask->routine, (void *) rtask );
1364                                 ldap_pvt_thread_mutex_lock( &syncrepl_rq.rq_mutex );
1365                         }
1366                         rtask = ldap_pvt_runqueue_next_sched( &syncrepl_rq, &cat );
1367                 }
1368                 ldap_pvt_thread_mutex_unlock( &syncrepl_rq.rq_mutex );
1369
1370                 if ( cat != NULL ) {
1371                         time_t diff = difftime( cat->tv_sec, now );
1372                         if ( diff == 0 )
1373                                 diff = tdelta;
1374                         if ( tvp == NULL || diff < tv.tv_sec ) {
1375                                 tv.tv_sec = diff;
1376                                 tv.tv_usec = 0;
1377                                 tvp = &tv;
1378                         }
1379                 }
1380
1381                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1382                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID ||
1383                             slap_listeners[l]->sl_is_mute )
1384                                 continue;
1385
1386 #ifdef NEW_LOGGING
1387                         LDAP_LOG( CONNECTION, DETAIL1, 
1388                                 "slapd_daemon_task: select: listen=%d "
1389                                 "active_threads=%d tvp=%s\n",
1390                                 slap_listeners[l]->sl_sd, at, tvp == NULL ? "NULL" : "zero" );
1391 #else
1392                         Debug( LDAP_DEBUG_CONNS,
1393                                 "daemon: select: listen=%d active_threads=%d tvp=%s\n",
1394                                         slap_listeners[l]->sl_sd, at,
1395                                         tvp == NULL ? "NULL" : "zero" );
1396 #endif
1397                 }
1398
1399                 switch(ns = select( nfds, &readfds,
1400 #ifdef HAVE_WINSOCK
1401                         /* don't pass empty fd_set */
1402                         ( writefds.fd_count > 0 ? &writefds : NULL ),
1403 #else
1404                         &writefds,
1405 #endif
1406                         NULL, tvp ))
1407                 {
1408                 case -1: {      /* failure - try again */
1409                                 int err = sock_errno();
1410
1411                                 if( err == EBADF
1412 #ifdef WSAENOTSOCK
1413                                         /* you'd think this would be EBADF */
1414                                         || err == WSAENOTSOCK
1415 #endif
1416                                 ) {
1417                                         if (++ebadf < SLAPD_EBADF_LIMIT)
1418                                                 continue;
1419                                 }
1420
1421                                 if( err != EINTR ) {
1422 #ifdef NEW_LOGGING
1423                                         LDAP_LOG( CONNECTION, INFO, 
1424                                                 "slapd_daemon_task: select failed (%d): %s\n",
1425                                                 err, sock_errstr(err), 0 );
1426 #else
1427                                         Debug( LDAP_DEBUG_CONNS,
1428                                                 "daemon: select failed (%d): %s\n",
1429                                                 err, sock_errstr(err), 0 );
1430 #endif
1431                                         slapd_shutdown = 2;
1432                                 }
1433                         }
1434                         continue;
1435
1436                 case 0:         /* timeout - let threads run */
1437                         ebadf = 0;
1438 #ifdef NEW_LOGGING
1439                         LDAP_LOG( CONNECTION, DETAIL2,
1440                                    "slapd_daemon_task: select timeout - yielding\n", 0, 0, 0 );
1441 #else
1442                         Debug( LDAP_DEBUG_CONNS, "daemon: select timeout - yielding\n",
1443                             0, 0, 0 );
1444 #endif
1445
1446                         ldap_pvt_thread_yield();
1447                         continue;
1448
1449                 default:        /* something happened - deal with it */
1450                         if( slapd_shutdown ) continue;
1451
1452                         ebadf = 0;
1453 #ifdef NEW_LOGGING
1454                         LDAP_LOG( CONNECTION, DETAIL2, 
1455                                    "slapd_daemon_task: activity on %d descriptors\n", ns, 0, 0 );
1456 #else
1457                         Debug( LDAP_DEBUG_CONNS, "daemon: activity on %d descriptors\n",
1458                                 ns, 0, 0 );
1459 #endif
1460                         /* FALL THRU */
1461                 }
1462
1463                 if( FD_ISSET( wake_sds[0], &readfds ) ) {
1464                         char c[BUFSIZ];
1465                         tcp_read( wake_sds[0], c, sizeof(c) );
1466 #if defined(NO_THREADS) || defined(HAVE_GNU_PTH)
1467                         waking = 0;
1468 #endif
1469                         continue;
1470                 }
1471
1472                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1473                         ber_socket_t s;
1474                         socklen_t len = sizeof(from);
1475                         long id;
1476                         slap_ssf_t ssf = 0;
1477                         char *authid = NULL;
1478 #ifdef SLAPD_RLOOKUPS
1479                         char hbuf[NI_MAXHOST];
1480 #endif
1481
1482                         char    *dnsname = NULL;
1483                         char    *peeraddr = NULL;
1484 #ifdef LDAP_PF_LOCAL
1485                         char    peername[MAXPATHLEN + sizeof("PATH=")];
1486 #elif defined(LDAP_PF_INET6)
1487                         char    peername[sizeof("IP=ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff 65535")];
1488 #else
1489                         char    peername[sizeof("IP=255.255.255.255:65336")];
1490 #endif /* LDAP_PF_LOCAL */
1491
1492                         peername[0] = '\0';
1493
1494                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1495                                 continue;
1496
1497                         if ( !FD_ISSET( slap_listeners[l]->sl_sd, &readfds ) )
1498                                 continue;
1499                         
1500 #ifdef LDAP_CONNECTIONLESS
1501                         if ( slap_listeners[l]->sl_is_udp ) {
1502                                 /* The first time we receive a query, we set this
1503                                  * up as a "connection". It remains open for the life
1504                                  * of the slapd.
1505                                  */
1506                                 if ( slap_listeners[l]->sl_is_udp < 2 ) {
1507                                     id = connection_init(
1508                                         slap_listeners[l]->sl_sd,
1509                                         slap_listeners[l], "", "",
1510                                         CONN_IS_UDP, ssf, authid );
1511                                     slap_listeners[l]->sl_is_udp++;
1512                                 }
1513                                 continue;
1514                         }
1515 #endif
1516
1517                         /* Don't need to look at this in the data loops */
1518                         FD_CLR( slap_listeners[l]->sl_sd, &readfds );
1519                         FD_CLR( slap_listeners[l]->sl_sd, &writefds );
1520
1521                         s = accept( slap_listeners[l]->sl_sd,
1522                                 (struct sockaddr *) &from, &len );
1523                         if ( s == AC_SOCKET_INVALID ) {
1524                                 int err = sock_errno();
1525
1526                                 if(
1527 #ifdef EMFILE
1528                                     err == EMFILE ||
1529 #endif
1530 #ifdef ENFILE
1531                                     err == ENFILE ||
1532 #endif
1533                                     0 )
1534                                 {
1535                                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1536                                         emfile++;
1537                                         /* Stop listening until an existing session closes */
1538                                         slap_listeners[l]->sl_is_mute = 1;
1539                                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1540                                 }
1541
1542 #ifdef NEW_LOGGING
1543                                 LDAP_LOG( CONNECTION, ERR, 
1544                                         "slapd_daemon_task: accept(%ld) failed errno=%d (%s)\n",
1545                                         (long)slap_listeners[l]->sl_sd, 
1546                                         err, sock_errstr(err) );
1547 #else
1548                                 Debug( LDAP_DEBUG_ANY,
1549                                         "daemon: accept(%ld) failed errno=%d (%s)\n",
1550                                         (long) slap_listeners[l]->sl_sd, err,
1551                                         sock_errstr(err) );
1552 #endif
1553                                 ldap_pvt_thread_yield();
1554                                 continue;
1555                         }
1556
1557 #ifndef HAVE_WINSOCK
1558                         /* make sure descriptor number isn't too great */
1559                         if ( s >= dtblsize ) {
1560 #ifdef NEW_LOGGING
1561                                 LDAP_LOG( CONNECTION, ERR, 
1562                                    "slapd_daemon_task: %ld beyond descriptor table size %ld\n",
1563                                    (long)s, (long)dtblsize, 0 );
1564 #else
1565                                 Debug( LDAP_DEBUG_ANY,
1566                                         "daemon: %ld beyond descriptor table size %ld\n",
1567                                         (long) s, (long) dtblsize, 0 );
1568 #endif
1569
1570                                 slapd_close(s);
1571                                 ldap_pvt_thread_yield();
1572                                 continue;
1573                         }
1574 #endif
1575
1576 #ifdef LDAP_DEBUG
1577                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1578
1579                         /* newly accepted stream should not be in any of the FD SETS */
1580                         assert( !FD_ISSET( s, &slap_daemon.sd_actives) );
1581                         assert( !FD_ISSET( s, &slap_daemon.sd_readers) );
1582                         assert( !FD_ISSET( s, &slap_daemon.sd_writers) );
1583
1584                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1585 #endif
1586
1587 #if defined( SO_KEEPALIVE ) || defined( TCP_NODELAY )
1588 #ifdef LDAP_PF_LOCAL
1589                         /* for IPv4 and IPv6 sockets only */
1590                         if ( from.sa_addr.sa_family != AF_LOCAL )
1591 #endif /* LDAP_PF_LOCAL */
1592                         {
1593                                 int rc;
1594                                 int tmp;
1595 #ifdef SO_KEEPALIVE
1596                                 /* enable keep alives */
1597                                 tmp = 1;
1598                                 rc = setsockopt( s, SOL_SOCKET, SO_KEEPALIVE,
1599                                         (char *) &tmp, sizeof(tmp) );
1600                                 if ( rc == AC_SOCKET_ERROR ) {
1601                                         int err = sock_errno();
1602 #ifdef NEW_LOGGING
1603                                         LDAP_LOG( CONNECTION, ERR, 
1604                                                 "slapd_daemon_task: setsockopt( %ld, SO_KEEPALIVE)"
1605                                            " failed errno=%d (%s)\n",
1606                                                 (long)s, err, sock_errstr(err) );
1607 #else
1608                                         Debug( LDAP_DEBUG_ANY,
1609                                                 "slapd(%ld): setsockopt(SO_KEEPALIVE) failed "
1610                                                 "errno=%d (%s)\n", (long) s, err, sock_errstr(err) );
1611 #endif
1612                                 }
1613 #endif
1614 #ifdef TCP_NODELAY
1615                                 /* enable no delay */
1616                                 tmp = 1;
1617                                 rc = setsockopt( s, IPPROTO_TCP, TCP_NODELAY,
1618                                         (char *)&tmp, sizeof(tmp) );
1619                                 if ( rc == AC_SOCKET_ERROR ) {
1620                                         int err = sock_errno();
1621 #ifdef NEW_LOGGING
1622                                         LDAP_LOG( CONNECTION, ERR, 
1623                                                 "slapd_daemon_task: setsockopt( %ld, "
1624                                                 "TCP_NODELAY) failed errno=%d (%s)\n",
1625                                                 (long)s, err, sock_errstr(err) );
1626 #else
1627                                         Debug( LDAP_DEBUG_ANY,
1628                                                 "slapd(%ld): setsockopt(TCP_NODELAY) failed "
1629                                                 "errno=%d (%s)\n", (long) s, err, sock_errstr(err) );
1630 #endif
1631                                 }
1632 #endif
1633                         }
1634 #endif
1635
1636 #ifdef NEW_LOGGING
1637                         LDAP_LOG( CONNECTION, DETAIL1, 
1638                                 "slapd_daemon_task: new connection on %ld\n", (long)s, 0, 0 );
1639 #else
1640                         Debug( LDAP_DEBUG_CONNS, "daemon: new connection on %ld\n",
1641                                 (long) s, 0, 0 );
1642 #endif
1643                         switch ( from.sa_addr.sa_family ) {
1644 #  ifdef LDAP_PF_LOCAL
1645                         case AF_LOCAL:
1646                                 sprintf( peername, "PATH=%s", from.sa_un_addr.sun_path );
1647                                 ssf = LDAP_PVT_SASL_LOCAL_SSF;
1648                                 {
1649                                         uid_t uid;
1650                                         gid_t gid;
1651
1652                                         if( getpeereid( s, &uid, &gid ) == 0 ) {
1653                                                 authid = ch_malloc(
1654                                                         sizeof("uidnumber=4294967295+gidnumber=4294967295,"
1655                                                                 "cn=peercred,cn=external,cn=auth"));
1656                                                 sprintf(authid, "uidnumber=%d+gidnumber=%d,"
1657                                                         "cn=peercred,cn=external,cn=auth",
1658                                                         (int) uid, (int) gid);
1659                                         }
1660                                 }
1661                                 dnsname = "local";
1662                                 break;
1663 #endif /* LDAP_PF_LOCAL */
1664
1665 #  ifdef LDAP_PF_INET6
1666                         case AF_INET6:
1667                         if ( IN6_IS_ADDR_V4MAPPED(&from.sa_in6_addr.sin6_addr) ) {
1668                                 peeraddr = inet_ntoa( *((struct in_addr *)
1669                                                         &from.sa_in6_addr.sin6_addr.s6_addr[12]) );
1670                                 sprintf( peername, "IP=%s:%d",
1671                                          peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1672                                          (unsigned) ntohs( from.sa_in6_addr.sin6_port ) );
1673                         } else {
1674                                 char addr[INET6_ADDRSTRLEN];
1675
1676                                 peeraddr = (char *) inet_ntop( AF_INET6,
1677                                                       &from.sa_in6_addr.sin6_addr,
1678                                                       addr, sizeof addr );
1679                                 sprintf( peername, "IP=%s %d",
1680                                          peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1681                                          (unsigned) ntohs( from.sa_in6_addr.sin6_port ) );
1682                         }
1683                         break;
1684 #  endif /* LDAP_PF_INET6 */
1685
1686                         case AF_INET:
1687                         peeraddr = inet_ntoa( from.sa_in_addr.sin_addr );
1688                         sprintf( peername, "IP=%s:%d",
1689                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1690                                 (unsigned) ntohs( from.sa_in_addr.sin_port ) );
1691                                 break;
1692
1693                         default:
1694                                 slapd_close(s);
1695                                 continue;
1696                         }
1697
1698                         if ( ( from.sa_addr.sa_family == AF_INET )
1699 #ifdef LDAP_PF_INET6
1700                                 || ( from.sa_addr.sa_family == AF_INET6 )
1701 #endif
1702                         ) {
1703 #ifdef SLAPD_RLOOKUPS
1704                                 if ( use_reverse_lookup ) {
1705                                         char *herr;
1706                                         if (ldap_pvt_get_hname( (const struct sockaddr *)&from, len, hbuf,
1707                                                 sizeof(hbuf), &herr ) == 0) {
1708                                                 ldap_pvt_str2lower( hbuf );
1709                                                 dnsname = hbuf;
1710                                         }
1711                                 }
1712 #else
1713                                 dnsname = NULL;
1714 #endif /* SLAPD_RLOOKUPS */
1715
1716 #ifdef HAVE_TCPD
1717                                 if ( !hosts_ctl("slapd",
1718                                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1719                                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1720                                                 SLAP_STRING_UNKNOWN ))
1721                                 {
1722                                         /* DENY ACCESS */
1723                                         Statslog( LDAP_DEBUG_STATS,
1724                                                 "fd=%ld DENIED from %s (%s)\n",
1725                                                 (long) s,
1726                                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1727                                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1728                                                 0, 0 );
1729                                         slapd_close(s);
1730                                         continue;
1731                                 }
1732 #endif /* HAVE_TCPD */
1733                         }
1734
1735                         id = connection_init(s,
1736                                 slap_listeners[l],
1737                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1738                                 peername,
1739 #ifdef HAVE_TLS
1740                                 slap_listeners[l]->sl_is_tls ? CONN_IS_TLS : 0,
1741 #else
1742                                 0,
1743 #endif
1744                                 ssf,
1745                                 authid );
1746
1747                         if( authid ) ch_free(authid);
1748
1749                         if( id < 0 ) {
1750 #ifdef NEW_LOGGING
1751                                 LDAP_LOG( CONNECTION, INFO, 
1752                                         "slapd_daemon_task: "
1753                                         "connection_init(%ld, %s, %s) "
1754                                         "failed.\n",
1755                                         (long)s, peername, 
1756                                         slap_listeners[l]->sl_name.bv_val );
1757 #else
1758                                 Debug( LDAP_DEBUG_ANY,
1759                                         "daemon: connection_init(%ld, %s, %s) "
1760                                         "failed.\n",
1761                                         (long) s,
1762                                         peername,
1763                                         slap_listeners[l]->sl_name.bv_val );
1764 #endif
1765                                 slapd_close(s);
1766                                 continue;
1767                         }
1768
1769                         Statslog( LDAP_DEBUG_STATS,
1770                                 "conn=%ld fd=%ld ACCEPT from %s (%s)\n",
1771                                 id, (long) s,
1772                                 peername,
1773                                 slap_listeners[l]->sl_name.bv_val,
1774                                 0 );
1775
1776                         slapd_add( s, 1 );
1777                         continue;
1778                 }
1779
1780 #ifdef LDAP_DEBUG
1781 #ifdef NEW_LOGGING
1782                 LDAP_LOG( CONNECTION, DETAIL2,
1783                            "slapd_daemon_task: activity on ", 0, 0, 0 );
1784 #else
1785                 Debug( LDAP_DEBUG_CONNS, "daemon: activity on:", 0, 0, 0 );
1786 #endif
1787 #ifdef HAVE_WINSOCK
1788                 for ( i = 0; i < readfds.fd_count; i++ ) {
1789 #ifdef NEW_LOGGING
1790                         LDAP_LOG( CONNECTION, DETAIL2, 
1791                                 " %d%s", readfds.fd_array[i], "r", 0, 0 );
1792 #else
1793                         Debug( LDAP_DEBUG_CONNS, " %d%s",
1794                                 readfds.fd_array[i], "r", 0 );
1795 #endif
1796                 }
1797                 for ( i = 0; i < writefds.fd_count; i++ ) {
1798 #ifdef NEW_LOGGING
1799                         LDAP_LOG( CONNECTION, DETAIL2, 
1800                                 " %d%s", writefds.fd_array[i], "w" , 0 );
1801 #else
1802                         Debug( LDAP_DEBUG_CONNS, " %d%s",
1803                                 writefds.fd_array[i], "w", 0 );
1804 #endif
1805                 }
1806
1807 #else
1808                 for ( i = 0; i < nfds; i++ ) {
1809                         int     r, w;
1810
1811                         r = FD_ISSET( i, &readfds );
1812                         w = FD_ISSET( i, &writefds );
1813                         if ( r || w ) {
1814 #ifdef NEW_LOGGING
1815                                 LDAP_LOG( CONNECTION, DETAIL2, 
1816                                         " %d%s%s", i, r ? "r" : "", w ? "w" : "" );
1817 #else
1818                                 Debug( LDAP_DEBUG_CONNS, " %d%s%s", i,
1819                                     r ? "r" : "", w ? "w" : "" );
1820 #endif
1821                         }
1822                 }
1823 #endif
1824 #ifdef NEW_LOGGING
1825                 LDAP_LOG( CONNECTION, DETAIL2, "\n", 0, 0, 0 );
1826 #else
1827                 Debug( LDAP_DEBUG_CONNS, "\n", 0, 0, 0 );
1828 #endif
1829
1830 #endif
1831
1832                 /* loop through the writers */
1833 #ifdef HAVE_WINSOCK
1834                 for ( i = 0; i < writefds.fd_count; i++ )
1835 #else
1836                 for ( i = 0; i < nfds; i++ )
1837 #endif
1838                 {
1839                         ber_socket_t wd;
1840 #ifdef HAVE_WINSOCK
1841                         wd = writefds.fd_array[i];
1842 #else
1843                         if( ! FD_ISSET( i, &writefds ) ) {
1844                                 continue;
1845                         }
1846                         wd = i;
1847 #endif
1848
1849 #ifdef NEW_LOGGING
1850                         LDAP_LOG( CONNECTION, DETAIL2, 
1851                                 "slapd_daemon_task: write active on %d\n", wd, 0, 0 );
1852 #else
1853                         Debug( LDAP_DEBUG_CONNS,
1854                                 "daemon: write active on %d\n",
1855                                 wd, 0, 0 );
1856 #endif
1857                         /*
1858                          * NOTE: it is possible that the connection was closed
1859                          * and that the stream is now inactive.
1860                          * connection_write() must valid the stream is still
1861                          * active.
1862                          */
1863
1864                         if ( connection_write( wd ) < 0 ) {
1865                                 FD_CLR( (unsigned) wd, &readfds );
1866                                 slapd_close( wd );
1867                         }
1868                 }
1869
1870 #ifdef HAVE_WINSOCK
1871                 for ( i = 0; i < readfds.fd_count; i++ )
1872 #else
1873                 for ( i = 0; i < nfds; i++ )
1874 #endif
1875                 {
1876                         ber_socket_t rd;
1877 #ifdef HAVE_WINSOCK
1878                         rd = readfds.fd_array[i];
1879 #else
1880                         if( ! FD_ISSET( i, &readfds ) ) {
1881                                 continue;
1882                         }
1883                         rd = i;
1884 #endif
1885
1886 #ifdef NEW_LOGGING
1887                         LDAP_LOG( CONNECTION, DETAIL2, 
1888                                 "slapd_daemon_task: read activity on %d\n", rd, 0, 0 );
1889 #else
1890                         Debug ( LDAP_DEBUG_CONNS,
1891                                 "daemon: read activity on %d\n", rd, 0, 0 );
1892 #endif
1893                         /*
1894                          * NOTE: it is possible that the connection was closed
1895                          * and that the stream is now inactive.
1896                          * connection_read() must valid the stream is still
1897                          * active.
1898                          */
1899
1900                         if ( connection_read( rd ) < 0 ) {
1901                                 slapd_close( rd );
1902                         }
1903                 }
1904                 ldap_pvt_thread_yield();
1905         }
1906
1907         if( slapd_shutdown == 1 ) {
1908 #ifdef NEW_LOGGING
1909                 LDAP_LOG( CONNECTION, CRIT,
1910                    "slapd_daemon_task: shutdown requested and initiated.\n", 0, 0, 0 );
1911 #else
1912                 Debug( LDAP_DEBUG_TRACE,
1913                         "daemon: shutdown requested and initiated.\n",
1914                         0, 0, 0 );
1915 #endif
1916
1917         } else if ( slapd_shutdown == 2 ) {
1918 #ifdef HAVE_NT_SERVICE_MANAGER
1919 #ifdef NEW_LOGGING
1920                         LDAP_LOG( CONNECTION, CRIT,
1921                            "slapd_daemon_task: shutdown initiated by Service Manager.\n",
1922                            0, 0, 0);
1923 #else
1924                         Debug( LDAP_DEBUG_TRACE,
1925                                "daemon: shutdown initiated by Service Manager.\n",
1926                                0, 0, 0);
1927 #endif
1928 #else /* !HAVE_NT_SERVICE_MANAGER */
1929 #ifdef NEW_LOGGING
1930                         LDAP_LOG( CONNECTION, CRIT,
1931                            "slapd_daemon_task: abnormal condition, "
1932                            "shutdown initiated.\n", 0, 0, 0 );
1933 #else
1934                         Debug( LDAP_DEBUG_TRACE,
1935                                "daemon: abnormal condition, shutdown initiated.\n",
1936                                0, 0, 0 );
1937 #endif
1938 #endif /* !HAVE_NT_SERVICE_MANAGER */
1939         } else {
1940 #ifdef NEW_LOGGING
1941                 LDAP_LOG( CONNECTION, CRIT,
1942                    "slapd_daemon_task: no active streams, shutdown initiated.\n", 
1943                    0, 0, 0 );
1944 #else
1945                 Debug( LDAP_DEBUG_TRACE,
1946                        "daemon: no active streams, shutdown initiated.\n",
1947                        0, 0, 0 );
1948 #endif
1949         }
1950
1951         if( slapd_gentle_shutdown != 2 ) {
1952                 close_listeners ( 0 );
1953         }
1954
1955         free ( slap_listeners );
1956         slap_listeners = NULL;
1957
1958         if( !slapd_gentle_shutdown ) {
1959                 slapd_abrupt_shutdown = 1;
1960                 connections_shutdown();
1961         }
1962
1963 #ifdef NEW_LOGGING
1964         LDAP_LOG( CONNECTION, CRIT, 
1965                 "slapd_daemon_task: shutdown waiting for %d threads to terminate.\n",
1966                 ldap_pvt_thread_pool_backload(&connection_pool), 0, 0 );
1967 #else
1968         Debug( LDAP_DEBUG_ANY,
1969             "slapd shutdown: waiting for %d threads to terminate\n",
1970             ldap_pvt_thread_pool_backload(&connection_pool), 0, 0 );
1971 #endif
1972         ldap_pvt_thread_pool_destroy(&connection_pool, 1);
1973
1974         return NULL;
1975 }
1976
1977
1978 int slapd_daemon( void )
1979 {
1980         int rc;
1981
1982         connections_init();
1983
1984 #define SLAPD_LISTENER_THREAD 1
1985 #if defined( SLAPD_LISTENER_THREAD )
1986         {
1987                 ldap_pvt_thread_t       listener_tid;
1988
1989                 /* listener as a separate THREAD */
1990                 rc = ldap_pvt_thread_create( &listener_tid,
1991                         0, slapd_daemon_task, NULL );
1992
1993                 if ( rc != 0 ) {
1994 #ifdef NEW_LOGGING
1995                         LDAP_LOG( CONNECTION, ERR, 
1996                                 "slapd_daemon: listener ldap_pvt_thread_create failed (%d).\n",
1997                                 rc, 0, 0 );
1998 #else
1999                         Debug( LDAP_DEBUG_ANY,
2000                         "listener ldap_pvt_thread_create failed (%d)\n", rc, 0, 0 );
2001 #endif
2002                         return rc;
2003                 }
2004  
2005                 /* wait for the listener thread to complete */
2006                 ldap_pvt_thread_join( listener_tid, (void *) NULL );
2007         }
2008 #else
2009         /* experimental code */
2010         slapd_daemon_task( NULL );
2011 #endif
2012
2013         return 0;
2014
2015 }
2016
2017 int sockinit(void)
2018 {
2019 #if defined( HAVE_WINSOCK2 )
2020     WORD wVersionRequested;
2021         WSADATA wsaData;
2022         int err;
2023
2024         wVersionRequested = MAKEWORD( 2, 0 );
2025
2026         err = WSAStartup( wVersionRequested, &wsaData );
2027         if ( err != 0 ) {
2028                 /* Tell the user that we couldn't find a usable */
2029                 /* WinSock DLL.                                  */
2030                 return -1;
2031         }
2032
2033         /* Confirm that the WinSock DLL supports 2.0.*/
2034         /* Note that if the DLL supports versions greater    */
2035         /* than 2.0 in addition to 2.0, it will still return */
2036         /* 2.0 in wVersion since that is the version we      */
2037         /* requested.                                        */
2038
2039         if ( LOBYTE( wsaData.wVersion ) != 2 ||
2040                 HIBYTE( wsaData.wVersion ) != 0 )
2041         {
2042             /* Tell the user that we couldn't find a usable */
2043             /* WinSock DLL.                                  */
2044             WSACleanup();
2045             return -1;
2046         }
2047
2048         /* The WinSock DLL is acceptable. Proceed. */
2049 #elif defined( HAVE_WINSOCK )
2050         WSADATA wsaData;
2051         if ( WSAStartup( 0x0101, &wsaData ) != 0 ) {
2052             return -1;
2053         }
2054 #endif
2055         return 0;
2056 }
2057
2058 int sockdestroy(void)
2059 {
2060 #if defined( HAVE_WINSOCK2 ) || defined( HAVE_WINSOCK )
2061         WSACleanup();
2062 #endif
2063         return 0;
2064 }
2065
2066 RETSIGTYPE
2067 slap_sig_shutdown( int sig )
2068 {
2069 #if 0
2070 #ifdef NEW_LOGGING
2071         LDAP_LOG( CONNECTION, CRIT, 
2072                 "slap_sig_shutdown: signal %d\n", sig, 0, 0 );
2073 #else
2074         Debug(LDAP_DEBUG_TRACE, "slap_sig_shutdown: signal %d\n", sig, 0, 0);
2075 #endif
2076 #endif
2077
2078         /*
2079          * If the NT Service Manager is controlling the server, we don't
2080          * want SIGBREAK to kill the server. For some strange reason,
2081          * SIGBREAK is generated when a user logs out.
2082          */
2083
2084 #if HAVE_NT_SERVICE_MANAGER && SIGBREAK
2085         if (is_NT_Service && sig == SIGBREAK)
2086                 ;
2087         else
2088 #endif
2089 #ifdef SIGHUP
2090         if (sig == SIGHUP && global_gentlehup && slapd_gentle_shutdown == 0)
2091                 slapd_gentle_shutdown = 1;
2092         else
2093 #endif
2094         slapd_shutdown = 1;
2095
2096         WAKE_LISTENER(1);
2097
2098         /* reinstall self */
2099         (void) SIGNAL_REINSTALL( sig, slap_sig_shutdown );
2100 }
2101
2102 RETSIGTYPE
2103 slap_sig_wake( int sig )
2104 {
2105         WAKE_LISTENER(1);
2106
2107         /* reinstall self */
2108         (void) SIGNAL_REINSTALL( sig, slap_sig_wake );
2109 }
2110
2111
2112 void slapd_add_internal(ber_socket_t s, int isactive) {
2113         slapd_add(s, isactive);
2114 }
2115
2116 Listener ** slapd_get_listeners(void) {
2117         return slap_listeners;
2118 }