]> git.sur5r.net Git - openldap/blob - servers/slapd/daemon.c
Allow a small number of waking events to be outstanding, not just 1
[openldap] / servers / slapd / daemon.c
1 /* $OpenLDAP$ */
2 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
3  *
4  * Copyright 1998-2004 The OpenLDAP Foundation.
5  * All rights reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted only as authorized by the OpenLDAP
9  * Public License.
10  *
11  * A copy of this license is available in the file LICENSE in the
12  * top-level directory of the distribution or, alternatively, at
13  * <http://www.OpenLDAP.org/license.html>.
14  */
15 /* Portions Copyright (c) 1995 Regents of the University of Michigan.
16  * All rights reserved.
17  *
18  * Redistribution and use in source and binary forms are permitted
19  * provided that this notice is preserved and that due credit is given
20  * to the University of Michigan at Ann Arbor. The name of the University
21  * may not be used to endorse or promote products derived from this
22  * software without specific prior written permission. This software
23  * is provided ``as is'' without express or implied warranty.
24  */
25
26 #include "portable.h"
27
28 #include <stdio.h>
29
30 #include <ac/ctype.h>
31 #include <ac/errno.h>
32 #include <ac/socket.h>
33 #include <ac/string.h>
34 #include <ac/time.h>
35 #include <ac/unistd.h>
36
37 #include "slap.h"
38 #include "ldap_pvt_thread.h"
39 #include "lutil.h"
40
41 #include "ldap_rq.h"
42
43 #ifdef HAVE_TCPD
44 #include <tcpd.h>
45 #define SLAP_STRING_UNKNOWN     STRING_UNKNOWN
46
47 int allow_severity = LOG_INFO;
48 int deny_severity = LOG_NOTICE;
49 #else /* ! TCP Wrappers */
50 #define SLAP_STRING_UNKNOWN     "unknown"
51 #endif /* ! TCP Wrappers */
52
53 #ifdef LDAP_PF_LOCAL
54 #include <sys/stat.h>
55 /* this should go in <ldap.h> as soon as it is accepted */
56 #define LDAPI_MOD_URLEXT                "x-mod"
57 #endif /* LDAP_PF_LOCAL */
58
59 #ifdef LDAP_PF_INET6
60 int slap_inet4or6 = AF_UNSPEC;
61 #else
62 int slap_inet4or6 = AF_INET;
63 #endif
64
65 /* globals */
66 time_t starttime;
67 ber_socket_t dtblsize;
68 slap_ssf_t local_ssf = LDAP_PVT_SASL_LOCAL_SSF;
69
70 Listener **slap_listeners = NULL;
71
72 #define SLAPD_LISTEN 10
73
74 static ber_socket_t wake_sds[2];
75 static int emfile;
76
77 static int waking;
78 #define WAKE_LISTENER(w) \
79 do { if (w && waking < 5) { tcp_write( wake_sds[1], "0", 1 ); waking++;} } while(0)
80
81 volatile sig_atomic_t slapd_shutdown = 0, slapd_gentle_shutdown = 0;
82 volatile sig_atomic_t slapd_abrupt_shutdown = 0;
83
84 static struct slap_daemon {
85         ldap_pvt_thread_mutex_t sd_mutex;
86
87         ber_socket_t sd_nactives;
88
89 #ifndef HAVE_WINSOCK
90         /* In winsock, accept() returns values higher than dtblsize
91                 so don't bother with this optimization */
92         int sd_nfds;
93 #endif
94         int sd_nwriters;
95
96         fd_set sd_actives;
97         fd_set sd_readers;
98         fd_set sd_writers;
99 } slap_daemon;
100
101
102
103 #ifdef HAVE_SLP
104 /*
105  * SLP related functions
106  */
107 #include <slp.h>
108
109 #define LDAP_SRVTYPE_PREFIX "service:ldap://"
110 #define LDAPS_SRVTYPE_PREFIX "service:ldaps://"
111 static char** slapd_srvurls = NULL;
112 static SLPHandle slapd_hslp = 0;
113 int slapd_register_slp = 0;
114
115 void slapd_slp_init( const char* urls ) {
116         int i;
117
118         slapd_srvurls = ldap_str2charray( urls, " " );
119
120         if( slapd_srvurls == NULL ) return;
121
122         /* find and expand INADDR_ANY URLs */
123         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
124                 if( strcmp( slapd_srvurls[i], "ldap:///" ) == 0) {
125                         char *host = ldap_pvt_get_fqdn( NULL );
126                         if ( host != NULL ) {
127                                 slapd_srvurls[i] = (char *) ch_realloc( slapd_srvurls[i],
128                                         strlen( host ) +
129                                         sizeof( LDAP_SRVTYPE_PREFIX ) );
130                                 strcpy( lutil_strcopy(slapd_srvurls[i],
131                                         LDAP_SRVTYPE_PREFIX ), host );
132
133                                 ch_free( host );
134                         }
135
136                 } else if ( strcmp( slapd_srvurls[i], "ldaps:///" ) == 0) {
137                         char *host = ldap_pvt_get_fqdn( NULL );
138                         if ( host != NULL ) {
139                                 slapd_srvurls[i] = (char *) ch_realloc( slapd_srvurls[i],
140                                         strlen( host ) +
141                                         sizeof( LDAPS_SRVTYPE_PREFIX ) );
142                                 strcpy( lutil_strcopy(slapd_srvurls[i],
143                                         LDAPS_SRVTYPE_PREFIX ), host );
144
145                                 ch_free( host );
146                         }
147                 }
148         }
149
150         /* open the SLP handle */
151         SLPOpen( "en", 0, &slapd_hslp );
152 }
153
154 void slapd_slp_deinit() {
155         if( slapd_srvurls == NULL ) return;
156
157         ldap_charray_free( slapd_srvurls );
158         slapd_srvurls = NULL;
159
160         /* close the SLP handle */
161         SLPClose( slapd_hslp );
162 }
163
164 void slapd_slp_regreport(
165         SLPHandle hslp,
166         SLPError errcode,
167         void* cookie )
168 {
169         /* empty report */
170 }
171
172 void slapd_slp_reg() {
173         int i;
174
175         if( slapd_srvurls == NULL ) return;
176
177         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
178                 if( strncmp( slapd_srvurls[i], LDAP_SRVTYPE_PREFIX,
179                                 sizeof( LDAP_SRVTYPE_PREFIX ) - 1 ) == 0 ||
180                     strncmp( slapd_srvurls[i], LDAPS_SRVTYPE_PREFIX,
181                                 sizeof( LDAPS_SRVTYPE_PREFIX ) - 1 ) == 0 )
182                 {
183                         SLPReg( slapd_hslp,
184                                 slapd_srvurls[i],
185                                 SLP_LIFETIME_MAXIMUM,
186                                 "ldap",
187                                 "",
188                                 1,
189                                 slapd_slp_regreport,
190                                 NULL );
191                 }
192         }
193 }
194
195 void slapd_slp_dereg() {
196         int i;
197
198         if( slapd_srvurls == NULL ) return;
199
200         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
201                 SLPDereg( slapd_hslp,
202                         slapd_srvurls[i],
203                         slapd_slp_regreport,
204                         NULL );
205         }
206 }
207 #endif /* HAVE_SLP */
208
209 /*
210  * Add a descriptor to daemon control
211  *
212  * If isactive, the descriptor is a live server session and is subject
213  * to idletimeout control. Otherwise, the descriptor is a passive
214  * listener or an outbound client session, and not subject to
215  * idletimeout.
216  */
217 static void slapd_add(ber_socket_t s, int isactive) {
218         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
219
220         assert( !FD_ISSET( s, &slap_daemon.sd_actives ));
221         assert( !FD_ISSET( s, &slap_daemon.sd_readers ));
222         assert( !FD_ISSET( s, &slap_daemon.sd_writers ));
223
224 #ifndef HAVE_WINSOCK
225         if (s >= slap_daemon.sd_nfds) {
226                 slap_daemon.sd_nfds = s + 1;
227         }
228 #endif
229
230         if ( isactive ) {
231                 slap_daemon.sd_nactives++;
232         }
233
234         FD_SET( s, &slap_daemon.sd_actives );
235         FD_SET( s, &slap_daemon.sd_readers );
236
237         Debug( LDAP_DEBUG_CONNS, "daemon: added %ld%s%s\n",
238                 (long) s,
239             FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
240                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : "" );
241         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
242 }
243
244 /*
245  * Remove the descriptor from daemon control
246  */
247 void slapd_remove(ber_socket_t s, int wasactive, int wake) {
248         int waswriter;
249         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
250
251         if ( wasactive ) {
252                 slap_daemon.sd_nactives--;
253         }
254         waswriter = FD_ISSET(s, &slap_daemon.sd_writers);
255
256         Debug( LDAP_DEBUG_CONNS, "daemon: removing %ld%s%s\n",
257                 (long) s,
258             FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
259                 waswriter ? "w" : "" );
260         if ( waswriter ) slap_daemon.sd_nwriters--;
261         FD_CLR( s, &slap_daemon.sd_actives );
262         FD_CLR( s, &slap_daemon.sd_readers );
263         FD_CLR( s, &slap_daemon.sd_writers );
264
265         /* If we ran out of file descriptors, we dropped a listener from
266          * the select() loop. Now that we're removing a session from our
267          * control, we can try to resume a dropped listener to use.
268          */
269         if ( emfile ) {
270                 int i;
271                 for ( i = 0; slap_listeners[i] != NULL; i++ ) {
272                         if ( slap_listeners[i]->sl_sd != AC_SOCKET_INVALID ) {
273                                 if ( slap_listeners[i]->sl_sd == s ) continue;
274                                 if ( slap_listeners[i]->sl_is_mute ) {
275                                         slap_listeners[i]->sl_is_mute = 0;
276                                         emfile--;
277                                         break;
278                                 }
279                         }
280                 }
281                 /* Walked the entire list without enabling anything; emfile
282                  * counter is stale. Reset it.
283                  */
284                 if ( slap_listeners[i] == NULL )
285                         emfile = 0;
286         }
287         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
288         WAKE_LISTENER(wake || slapd_gentle_shutdown == 2);
289 }
290
291 void slapd_clr_write(ber_socket_t s, int wake) {
292         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
293
294         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
295         if ( FD_ISSET( s, &slap_daemon.sd_writers )) {
296                 FD_CLR( s, &slap_daemon.sd_writers );
297                 slap_daemon.sd_nwriters--;
298         }
299
300         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
301         WAKE_LISTENER(wake);
302 }
303
304 void slapd_set_write(ber_socket_t s, int wake) {
305         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
306
307         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
308         if (!FD_ISSET(s, &slap_daemon.sd_writers)) {
309                 FD_SET( (unsigned) s, &slap_daemon.sd_writers );
310                 slap_daemon.sd_nwriters++;
311         }
312
313         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
314         WAKE_LISTENER(wake);
315 }
316
317 void slapd_clr_read(ber_socket_t s, int wake) {
318         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
319
320         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
321         FD_CLR( s, &slap_daemon.sd_readers );
322
323         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
324         WAKE_LISTENER(wake);
325 }
326
327 void slapd_set_read(ber_socket_t s, int wake) {
328         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
329
330         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
331         if (!FD_ISSET(s, &slap_daemon.sd_readers))
332             FD_SET( s, &slap_daemon.sd_readers );
333
334         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
335         WAKE_LISTENER(wake);
336 }
337
338 static void slapd_close(ber_socket_t s) {
339         Debug( LDAP_DEBUG_CONNS, "daemon: closing %ld\n",
340                 (long) s, 0, 0 );
341         tcp_close(s);
342 }
343
344 static void slap_free_listener_addresses(struct sockaddr **sal)
345 {
346         struct sockaddr **sap;
347
348         if (sal == NULL) {
349                 return;
350         }
351
352         for (sap = sal; *sap != NULL; sap++) {
353                 ch_free(*sap);
354         }
355
356         ch_free(sal);
357 }
358
359 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
360 static int get_url_perms(
361         char    **exts,
362         mode_t  *perms,
363         int     *crit )
364 {
365         int     i;
366
367         assert( exts );
368         assert( perms );
369         assert( crit );
370
371         *crit = 0;
372         for ( i = 0; exts[ i ]; i++ ) {
373                 char    *type = exts[ i ];
374                 int     c = 0;
375
376                 if ( type[ 0 ] == '!' ) {
377                         c = 1;
378                         type++;
379                 }
380
381                 if ( strncasecmp( type, LDAPI_MOD_URLEXT "=", sizeof(LDAPI_MOD_URLEXT "=") - 1 ) == 0 ) {
382                         char    *value = type
383                                 + ( sizeof(LDAPI_MOD_URLEXT "=") - 1 );
384                         mode_t  p = 0;
385                         int     j;
386
387                         switch (strlen(value)) {
388                         case 4:
389                                 /* skip leading '0' */
390                                 if ( value[ 0 ] != '0' ) {
391                                         return LDAP_OTHER;
392                                 }
393                                 value++;
394
395                         case 3:
396                                 for ( j = 0; j < 3; j++) {
397                                         int     v;
398
399                                         v = value[ j ] - '0';
400
401                                         if ( v < 0 || v > 7 ) {
402                                                 return LDAP_OTHER;
403                                         }
404
405                                         p |= v << 3*(2-j);
406                                 }
407                                 break;
408
409                         case 10:
410                                 for ( j = 1; j < 10; j++ ) {
411                                         static mode_t   m[] = { 0, 
412                                                 S_IRUSR, S_IWUSR, S_IXUSR,
413                                                 S_IRGRP, S_IWGRP, S_IXGRP,
414                                                 S_IROTH, S_IWOTH, S_IXOTH
415                                         };
416                                         static char     c[] = "-rwxrwxrwx"; 
417
418                                         if ( value[ j ] == c[ j ] ) {
419                                                 p |= m[ j ];
420         
421                                         } else if ( value[ j ] != '-' ) {
422                                                 return LDAP_OTHER;
423                                         }
424                                 }
425                                 break;
426
427                         default:
428                                 return LDAP_OTHER;
429                         } 
430
431                         *crit = c;
432                         *perms = p;
433
434                         return LDAP_SUCCESS;
435                 }
436         }
437
438         return LDAP_OTHER;
439 }
440 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
441
442 /* port = 0 indicates AF_LOCAL */
443 static int slap_get_listener_addresses(
444         const char *host,
445         unsigned short port,
446         struct sockaddr ***sal)
447 {
448         struct sockaddr **sap;
449
450 #ifdef LDAP_PF_LOCAL
451         if ( port == 0 ) {
452                 *sal = ch_malloc(2 * sizeof(void *));
453                 if (*sal == NULL) {
454                         return -1;
455                 }
456
457                 sap = *sal;
458                 *sap = ch_malloc(sizeof(struct sockaddr_un));
459                 if (*sap == NULL)
460                         goto errexit;
461                 sap[1] = NULL;
462
463                 if ( strlen(host) >
464                      (sizeof(((struct sockaddr_un *)*sap)->sun_path) - 1) ) {
465                         Debug( LDAP_DEBUG_ANY,
466                                "daemon: domain socket path (%s) too long in URL",
467                                host, 0, 0);
468                         goto errexit;
469                 }
470
471                 (void)memset( (void *)*sap, '\0', sizeof(struct sockaddr_un) );
472                 (*sap)->sa_family = AF_LOCAL;
473                 strcpy( ((struct sockaddr_un *)*sap)->sun_path, host );
474         } else
475 #endif
476         {
477 #ifdef HAVE_GETADDRINFO
478                 struct addrinfo hints, *res, *sai;
479                 int n, err;
480                 char serv[7];
481
482                 memset( &hints, '\0', sizeof(hints) );
483                 hints.ai_flags = AI_PASSIVE;
484                 hints.ai_socktype = SOCK_STREAM;
485                 hints.ai_family = slap_inet4or6;
486                 snprintf(serv, sizeof serv, "%d", port);
487
488                 if ( (err = getaddrinfo(host, serv, &hints, &res)) ) {
489                         Debug( LDAP_DEBUG_ANY, "daemon: getaddrinfo failed: %s\n",
490                                 AC_GAI_STRERROR(err), 0, 0);
491                         return -1;
492                 }
493
494                 sai = res;
495                 for (n=2; (sai = sai->ai_next) != NULL; n++) {
496                         /* EMPTY */ ;
497                 }
498                 *sal = ch_calloc(n, sizeof(void *));
499                 if (*sal == NULL) {
500                         return -1;
501                 }
502
503                 sap = *sal;
504                 *sap = NULL;
505
506                 for ( sai=res; sai; sai=sai->ai_next ) {
507                         if( sai->ai_addr == NULL ) {
508                                 Debug( LDAP_DEBUG_ANY, "slap_get_listener_addresses: "
509                                         "getaddrinfo ai_addr is NULL?\n", 0, 0, 0 );
510                                 freeaddrinfo(res);
511                                 goto errexit;
512                         }
513
514                         switch (sai->ai_family) {
515 #  ifdef LDAP_PF_INET6
516                         case AF_INET6:
517                                 *sap = ch_malloc(sizeof(struct sockaddr_in6));
518                                 if (*sap == NULL) {
519                                         freeaddrinfo(res);
520                                         goto errexit;
521                                 }
522                                 *(struct sockaddr_in6 *)*sap =
523                                         *((struct sockaddr_in6 *)sai->ai_addr);
524                                 break;
525 #  endif
526                         case AF_INET:
527                                 *sap = ch_malloc(sizeof(struct sockaddr_in));
528                                 if (*sap == NULL) {
529                                         freeaddrinfo(res);
530                                         goto errexit;
531                                 }
532                                 *(struct sockaddr_in *)*sap =
533                                         *((struct sockaddr_in *)sai->ai_addr);
534                                 break;
535                         default:
536                                 *sap = NULL;
537                                 break;
538                         }
539
540                         if (*sap != NULL) {
541                                 (*sap)->sa_family = sai->ai_family;
542                                 sap++;
543                                 *sap = NULL;
544                         }
545                 }
546
547                 freeaddrinfo(res);
548 #else
549                 int i, n = 1;
550                 struct in_addr in;
551                 struct hostent *he = NULL;
552
553                 if ( host == NULL ) {
554                         in.s_addr = htonl(INADDR_ANY);
555
556                 } else if ( !inet_aton( host, &in ) ) {
557                         he = gethostbyname( host );
558                         if( he == NULL ) {
559                                 Debug( LDAP_DEBUG_ANY,
560                                        "daemon: invalid host %s", host, 0, 0);
561                                 return -1;
562                         }
563                         for (n = 0; he->h_addr_list[n]; n++) ;
564                 }
565
566                 *sal = ch_malloc((n+1) * sizeof(void *));
567                 if (*sal == NULL) {
568                         return -1;
569                 }
570
571                 sap = *sal;
572                 for ( i = 0; i<n; i++ ) {
573                         sap[i] = ch_malloc(sizeof(struct sockaddr_in));
574                         if (*sap == NULL) {
575                                 goto errexit;
576                         }
577                         (void)memset( (void *)sap[i], '\0', sizeof(struct sockaddr_in) );
578                         sap[i]->sa_family = AF_INET;
579                         ((struct sockaddr_in *)sap[i])->sin_port = htons(port);
580                         if (he) {
581                                 AC_MEMCPY( &((struct sockaddr_in *)sap[i])->sin_addr, he->h_addr_list[i], sizeof(struct in_addr) );
582                         } else {
583                                 AC_MEMCPY( &((struct sockaddr_in *)sap[i])->sin_addr, &in, sizeof(struct in_addr) );
584                         }
585                 }
586                 sap[i] = NULL;
587 #endif
588         }
589
590         return 0;
591
592 errexit:
593         slap_free_listener_addresses(*sal);
594         return -1;
595 }
596
597 static int slap_open_listener(
598         const char* url,
599         int *listeners,
600         int *cur
601         )
602 {
603         int     num, tmp, rc;
604         Listener l;
605         Listener *li;
606         LDAPURLDesc *lud;
607         unsigned short port;
608         int err, addrlen = 0;
609         struct sockaddr **sal, **psal;
610         int socktype = SOCK_STREAM;     /* default to COTS */
611
612 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
613         /*
614          * use safe defaults
615          */
616         int     crit = 1;
617 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
618
619         rc = ldap_url_parse( url, &lud );
620
621         if( rc != LDAP_URL_SUCCESS ) {
622                 Debug( LDAP_DEBUG_ANY,
623                         "daemon: listen URL \"%s\" parse error=%d\n",
624                         url, rc, 0 );
625                 return rc;
626         }
627
628         l.sl_url.bv_val = NULL;
629         l.sl_is_mute = 0;
630
631 #ifndef HAVE_TLS
632         if( ldap_pvt_url_scheme2tls( lud->lud_scheme ) ) {
633                 Debug( LDAP_DEBUG_ANY,
634                         "daemon: TLS not supported (%s)\n",
635                         url, 0, 0 );
636                 ldap_free_urldesc( lud );
637                 return -1;
638         }
639
640         if(! lud->lud_port ) {
641                 lud->lud_port = LDAP_PORT;
642         }
643
644 #else
645         l.sl_is_tls = ldap_pvt_url_scheme2tls( lud->lud_scheme );
646
647         if(! lud->lud_port ) {
648                 lud->lud_port = l.sl_is_tls ? LDAPS_PORT : LDAP_PORT;
649         }
650 #endif
651
652         port = (unsigned short) lud->lud_port;
653
654         tmp = ldap_pvt_url_scheme2proto(lud->lud_scheme);
655         if ( tmp == LDAP_PROTO_IPC ) {
656 #ifdef LDAP_PF_LOCAL
657                 if ( lud->lud_host == NULL || lud->lud_host[0] == '\0' ) {
658                         err = slap_get_listener_addresses(LDAPI_SOCK, 0, &sal);
659                 } else {
660                         err = slap_get_listener_addresses(lud->lud_host, 0, &sal);
661                 }
662 #else
663
664                 Debug( LDAP_DEBUG_ANY, "daemon: URL scheme not supported: %s",
665                         url, 0, 0);
666                 ldap_free_urldesc( lud );
667                 return -1;
668 #endif
669         } else {
670                 if( lud->lud_host == NULL || lud->lud_host[0] == '\0'
671                         || strcmp(lud->lud_host, "*") == 0 )
672                 {
673                         err = slap_get_listener_addresses(NULL, port, &sal);
674                 } else {
675                         err = slap_get_listener_addresses(lud->lud_host, port, &sal);
676                 }
677         }
678 #ifdef LDAP_CONNECTIONLESS
679         l.sl_is_udp = ( tmp == LDAP_PROTO_UDP );
680 #endif
681
682 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
683         if ( lud->lud_exts ) {
684                 err = get_url_perms( lud->lud_exts, &l.sl_perms, &crit );
685         } else {
686                 l.sl_perms = S_IRWXU | S_IRWXO;
687         }
688 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
689
690         ldap_free_urldesc( lud );
691         if ( err ) {
692                 return -1;
693         }
694
695         /* If we got more than one address returned, we need to make space
696          * for it in the slap_listeners array.
697          */
698         for ( num=0; sal[num]; num++ );
699         if ( num > 1 ) {
700                 *listeners += num-1;
701                 slap_listeners = ch_realloc( slap_listeners, (*listeners + 1) * sizeof(Listener *) );
702         }
703
704         psal = sal;
705         while ( *sal != NULL ) {
706                 char *af;
707                 switch( (*sal)->sa_family ) {
708                 case AF_INET:
709                         af = "IPv4";
710                         break;
711 #ifdef LDAP_PF_INET6
712                 case AF_INET6:
713                         af = "IPv6";
714                         break;
715 #endif
716 #ifdef LDAP_PF_LOCAL
717                 case AF_LOCAL:
718                         af = "Local";
719                         break;
720 #endif
721                 default:
722                         sal++;
723                         continue;
724                 }
725 #ifdef LDAP_CONNECTIONLESS
726                 if( l.sl_is_udp ) socktype = SOCK_DGRAM;
727 #endif
728                 l.sl_sd = socket( (*sal)->sa_family, socktype, 0);
729                 if ( l.sl_sd == AC_SOCKET_INVALID ) {
730                         int err = sock_errno();
731                         Debug( LDAP_DEBUG_ANY,
732                                 "daemon: %s socket() failed errno=%d (%s)\n",
733                                 af, err, sock_errstr(err) );
734                         sal++;
735                         continue;
736                 }
737 #ifndef HAVE_WINSOCK
738                 if ( l.sl_sd >= dtblsize ) {
739                         Debug( LDAP_DEBUG_ANY,
740                                 "daemon: listener descriptor %ld is too great %ld\n",
741                                 (long) l.sl_sd, (long) dtblsize, 0 );
742                         tcp_close( l.sl_sd );
743                         sal++;
744                         continue;
745                 }
746 #endif
747 #ifdef LDAP_PF_LOCAL
748                 if ( (*sal)->sa_family == AF_LOCAL ) {
749                         unlink ( ((struct sockaddr_un *)*sal)->sun_path );
750                 } else
751 #endif
752                 {
753 #ifdef SO_REUSEADDR
754                         /* enable address reuse */
755                         tmp = 1;
756                         rc = setsockopt( l.sl_sd, SOL_SOCKET, SO_REUSEADDR,
757                                 (char *) &tmp, sizeof(tmp) );
758                         if ( rc == AC_SOCKET_ERROR ) {
759                                 int err = sock_errno();
760                                 Debug( LDAP_DEBUG_ANY,
761                                        "slapd(%ld): setsockopt(SO_REUSEADDR) failed errno=%d (%s)\n",
762                                        (long) l.sl_sd, err, sock_errstr(err) );
763                         }
764 #endif
765                 }
766
767                 switch( (*sal)->sa_family ) {
768                 case AF_INET:
769                         addrlen = sizeof(struct sockaddr_in);
770                         break;
771 #ifdef LDAP_PF_INET6
772                 case AF_INET6:
773 #ifdef IPV6_V6ONLY
774                         /* Try to use IPv6 sockets for IPv6 only */
775                         tmp = 1;
776                         rc = setsockopt( l.sl_sd, IPPROTO_IPV6, IPV6_V6ONLY,
777                                          (char *) &tmp, sizeof(tmp) );
778                         if ( rc == AC_SOCKET_ERROR ) {
779                                 int err = sock_errno();
780                                 Debug( LDAP_DEBUG_ANY,
781                                        "slapd(%ld): setsockopt(IPV6_V6ONLY) failed errno=%d (%s)\n",
782                                        (long) l.sl_sd, err, sock_errstr(err) );
783                         }
784 #endif
785                         addrlen = sizeof(struct sockaddr_in6);
786                         break;
787 #endif
788 #ifdef LDAP_PF_LOCAL
789                 case AF_LOCAL:
790                         addrlen = sizeof(struct sockaddr_un);
791                         break;
792 #endif
793                 }
794
795                 if (bind(l.sl_sd, *sal, addrlen)) {
796                         err = sock_errno();
797                 Debug( LDAP_DEBUG_ANY, "daemon: bind(%ld) failed errno=%d (%s)\n",
798                        (long) l.sl_sd, err, sock_errstr(err) );
799                         tcp_close( l.sl_sd );
800                         sal++;
801                         continue;
802                 }
803
804         switch ( (*sal)->sa_family ) {
805 #ifdef LDAP_PF_LOCAL
806         case AF_LOCAL: {
807                 char *addr = ((struct sockaddr_un *)*sal)->sun_path;
808 #if 0 /* don't muck with socket perms */
809                 if ( chmod( addr, l.sl_perms ) < 0 && crit ) {
810                         int err = sock_errno();
811                         Debug( LDAP_DEBUG_ANY, "daemon: fchmod(%ld) failed errno=%d (%s)",
812                                (long) l.sl_sd, err, sock_errstr(err) );
813                         tcp_close( l.sl_sd );
814                         slap_free_listener_addresses(psal);
815                         return -1;
816                 }
817 #endif
818                 l.sl_name.bv_len = strlen(addr) + sizeof("PATH=") - 1;
819                 l.sl_name.bv_val = ber_memalloc( l.sl_name.bv_len + 1 );
820                 snprintf( l.sl_name.bv_val, l.sl_name.bv_len + 1, 
821                                 "PATH=%s", addr );
822         } break;
823 #endif /* LDAP_PF_LOCAL */
824
825         case AF_INET: {
826                 char *s;
827 #if defined( HAVE_GETADDRINFO ) && defined( HAVE_INET_NTOP )
828                 char addr[INET_ADDRSTRLEN];
829                 inet_ntop( AF_INET, &((struct sockaddr_in *)*sal)->sin_addr,
830                            addr, sizeof(addr) );
831                 s = addr;
832 #else
833                 s = inet_ntoa( ((struct sockaddr_in *) *sal)->sin_addr );
834 #endif
835                 port = ntohs( ((struct sockaddr_in *)*sal) ->sin_port );
836                 l.sl_name.bv_val = ber_memalloc( sizeof("IP=255.255.255.255:65535") );
837                 snprintf( l.sl_name.bv_val, sizeof("IP=255.255.255.255:65535"),
838                         "IP=%s:%d",
839                          s != NULL ? s : SLAP_STRING_UNKNOWN, port );
840                 l.sl_name.bv_len = strlen( l.sl_name.bv_val );
841         } break;
842
843 #ifdef LDAP_PF_INET6
844         case AF_INET6: {
845                 char addr[INET6_ADDRSTRLEN];
846                 inet_ntop( AF_INET6, &((struct sockaddr_in6 *)*sal)->sin6_addr,
847                            addr, sizeof addr);
848                 port = ntohs( ((struct sockaddr_in6 *)*sal)->sin6_port );
849                 l.sl_name.bv_len = strlen(addr) + sizeof("IP= 65535");
850                 l.sl_name.bv_val = ber_memalloc( l.sl_name.bv_len );
851                 snprintf( l.sl_name.bv_val, l.sl_name.bv_len, "IP=%s %d", 
852                                 addr, port );
853                 l.sl_name.bv_len = strlen( l.sl_name.bv_val );
854         } break;
855 #endif /* LDAP_PF_INET6 */
856
857         default:
858                 Debug( LDAP_DEBUG_ANY, "daemon: unsupported address family (%d)\n",
859                         (int) (*sal)->sa_family, 0, 0 );
860                 break;
861         }
862
863         AC_MEMCPY(&l.sl_sa, *sal, addrlen);
864         ber_str2bv( url, 0, 1, &l.sl_url);
865         li = ch_malloc( sizeof( Listener ) );
866         *li = l;
867         slap_listeners[*cur] = li;
868         (*cur)++;
869         sal++;
870
871         } /* while ( *sal != NULL ) */
872
873         slap_free_listener_addresses(psal);
874
875         if ( l.sl_url.bv_val == NULL )
876         {
877                 Debug( LDAP_DEBUG_TRACE,
878                         "slap_open_listener: failed on %s\n", url, 0, 0 );
879                 return -1;
880         }
881
882         Debug( LDAP_DEBUG_TRACE, "daemon: initialized %s\n",
883                 l.sl_url.bv_val, 0, 0 );
884         return 0;
885 }
886
887 static int sockinit(void);
888 static int sockdestroy(void);
889
890 int slapd_daemon_init( const char *urls )
891 {
892         int i, j, n, rc;
893         char **u;
894
895         Debug( LDAP_DEBUG_ARGS, "daemon_init: %s\n",
896                 urls ? urls : "<null>", 0, 0 );
897         if( (rc = sockinit()) != 0 ) {
898                 return rc;
899         }
900
901 #ifdef HAVE_SYSCONF
902         dtblsize = sysconf( _SC_OPEN_MAX );
903 #elif HAVE_GETDTABLESIZE
904         dtblsize = getdtablesize();
905 #else
906         dtblsize = FD_SETSIZE;
907 #endif
908
909 #ifdef FD_SETSIZE
910         if(dtblsize > FD_SETSIZE) {
911                 dtblsize = FD_SETSIZE;
912         }
913 #endif  /* !FD_SETSIZE */
914
915         /* open a pipe (or something equivalent connected to itself).
916          * we write a byte on this fd whenever we catch a signal. The main
917          * loop will be select'ing on this socket, and will wake up when
918          * this byte arrives.
919          */
920         if( (rc = lutil_pair( wake_sds )) < 0 ) {
921                 Debug( LDAP_DEBUG_ANY,
922                         "daemon: lutil_pair() failed rc=%d\n", rc, 0, 0 );
923                 return rc;
924         }
925
926         FD_ZERO( &slap_daemon.sd_readers );
927         FD_ZERO( &slap_daemon.sd_writers );
928
929         if( urls == NULL ) {
930                 urls = "ldap:///";
931         }
932
933         u = ldap_str2charray( urls, " " );
934
935         if( u == NULL || u[0] == NULL ) {
936                 Debug( LDAP_DEBUG_ANY, "daemon_init: no urls (%s) provided.\n",
937                         urls, 0, 0 );
938                 return -1;
939         }
940
941         for( i=0; u[i] != NULL; i++ ) {
942                 Debug( LDAP_DEBUG_TRACE, "daemon_init: listen on %s\n",
943                         u[i], 0, 0 );
944         }
945
946         if( i == 0 ) {
947                 Debug( LDAP_DEBUG_ANY, "daemon_init: no listeners to open (%s)\n",
948                         urls, 0, 0 );
949                 ldap_charray_free( u );
950                 return -1;
951         }
952
953         Debug( LDAP_DEBUG_TRACE, "daemon_init: %d listeners to open...\n",
954                 i, 0, 0 );
955         slap_listeners = ch_malloc( (i+1)*sizeof(Listener *) );
956
957         for(n = 0, j = 0; u[n]; n++ ) {
958                 if ( slap_open_listener( u[n], &i, &j ) ) {
959                         ldap_charray_free( u );
960                         return -1;
961                 }
962         }
963         slap_listeners[j] = NULL;
964
965         Debug( LDAP_DEBUG_TRACE, "daemon_init: %d listeners opened\n",
966                 i, 0, 0 );
967
968 #ifdef HAVE_SLP
969         if( slapd_register_slp ) {
970                 slapd_slp_init( urls );
971                 slapd_slp_reg();
972         }
973 #endif
974
975         ldap_charray_free( u );
976         ldap_pvt_thread_mutex_init( &slap_daemon.sd_mutex );
977         return !i;
978 }
979
980
981 int
982 slapd_daemon_destroy(void)
983 {
984         connections_destroy();
985         tcp_close( wake_sds[1] );
986         tcp_close( wake_sds[0] );
987         sockdestroy();
988
989 #ifdef HAVE_SLP
990         if( slapd_register_slp ) {
991                 slapd_slp_dereg();
992                 slapd_slp_deinit();
993         }
994 #endif
995
996         return 0;
997 }
998
999
1000 static void
1001 close_listeners(
1002         int remove
1003 )
1004 {
1005         int l;
1006
1007         for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1008                 if ( slap_listeners[l]->sl_sd != AC_SOCKET_INVALID ) {
1009                         if ( remove )
1010                                 slapd_remove( slap_listeners[l]->sl_sd, 0, 0 );
1011 #ifdef LDAP_PF_LOCAL
1012                         if ( slap_listeners[l]->sl_sa.sa_addr.sa_family == AF_LOCAL ) {
1013                                 unlink( slap_listeners[l]->sl_sa.sa_un_addr.sun_path );
1014                         }
1015 #endif /* LDAP_PF_LOCAL */
1016                         slapd_close( slap_listeners[l]->sl_sd );
1017                 }
1018                 if ( slap_listeners[l]->sl_url.bv_val )
1019                         ber_memfree( slap_listeners[l]->sl_url.bv_val );
1020                 if ( slap_listeners[l]->sl_name.bv_val )
1021                         ber_memfree( slap_listeners[l]->sl_name.bv_val );
1022                 free ( slap_listeners[l] );
1023                 slap_listeners[l] = NULL;
1024         }
1025 }
1026
1027
1028 static void *
1029 slapd_daemon_task(
1030         void *ptr
1031 )
1032 {
1033         int l;
1034         time_t  last_idle_check = 0;
1035         struct timeval idle;
1036
1037 #define SLAPD_IDLE_CHECK_LIMIT 4
1038
1039         if ( global_idletimeout > 0 ) {
1040                 last_idle_check = slap_get_time();
1041                 /* Set the select timeout.
1042                  * Don't just truncate, preserve the fractions of
1043                  * seconds to prevent sleeping for zero time.
1044                  */
1045                 idle.tv_sec = global_idletimeout/SLAPD_IDLE_CHECK_LIMIT;
1046                 idle.tv_usec = global_idletimeout - idle.tv_sec * SLAPD_IDLE_CHECK_LIMIT;
1047                 idle.tv_usec *= 1000000 / SLAPD_IDLE_CHECK_LIMIT;
1048         } else {
1049                 idle.tv_sec = 0;
1050                 idle.tv_usec = 0;
1051         }
1052
1053         for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1054                 if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1055                         continue;
1056 #ifdef LDAP_CONNECTIONLESS
1057                 /* Since this is connectionless, the data port is the
1058                  * listening port. The listen() and accept() calls
1059                  * are unnecessary.
1060                  */
1061                 if ( slap_listeners[l]->sl_is_udp ) {
1062                         slapd_add( slap_listeners[l]->sl_sd, 1 );
1063                         continue;
1064                 }
1065 #endif
1066
1067                 if ( listen( slap_listeners[l]->sl_sd, SLAPD_LISTEN ) == -1 ) {
1068                         int err = sock_errno();
1069
1070 #ifdef LDAP_PF_INET6
1071                         /* If error is EADDRINUSE, we are trying to listen to INADDR_ANY and
1072                          * we are already listening to in6addr_any, then we want to ignore
1073                          * this and continue.
1074                          */
1075                         if ( err == EADDRINUSE ) {
1076                                 int i;
1077                                 struct sockaddr_in sa = slap_listeners[l]->sl_sa.sa_in_addr;
1078                                 struct sockaddr_in6 sa6;
1079                                 
1080                                 if ( sa.sin_family == AF_INET &&
1081                                      sa.sin_addr.s_addr == htonl(INADDR_ANY) ) {
1082                                         for ( i = 0 ; i < l; i++ ) {
1083                                                 sa6 = slap_listeners[i]->sl_sa.sa_in6_addr;
1084                                                 if ( sa6.sin6_family == AF_INET6 &&
1085                                                      !memcmp( &sa6.sin6_addr, &in6addr_any, sizeof(struct in6_addr) ) )
1086                                                         break;
1087                                         }
1088
1089                                         if ( i < l ) {
1090                                                 /* We are already listening to in6addr_any */
1091                                                 Debug( LDAP_DEBUG_CONNS,
1092                                                        "daemon: Attempt to listen to 0.0.0.0 failed, already listening on ::, assuming IPv4 included\n",
1093                                                        0, 0, 0 );
1094                                                 slapd_close( slap_listeners[l]->sl_sd );
1095                                                 slap_listeners[l]->sl_sd = AC_SOCKET_INVALID;
1096                                                 continue;
1097                                         }
1098                                 }
1099                         }
1100 #endif                          
1101                         Debug( LDAP_DEBUG_ANY,
1102                                 "daemon: listen(%s, 5) failed errno=%d (%s)\n",
1103                                         slap_listeners[l]->sl_url.bv_val, err,
1104                                         sock_errstr(err) );
1105                         return( (void*)-1 );
1106                 }
1107
1108                 slapd_add( slap_listeners[l]->sl_sd, 0 );
1109         }
1110
1111 #ifdef HAVE_NT_SERVICE_MANAGER
1112         if ( started_event != NULL ) {
1113                 ldap_pvt_thread_cond_signal( &started_event );
1114         }
1115 #endif
1116         /* initialization complete. Here comes the loop. */
1117
1118         while ( !slapd_shutdown ) {
1119                 ber_socket_t i;
1120                 int ns, nwriters;
1121                 int at;
1122                 ber_socket_t nfds, nrfds, nwfds;
1123 #define SLAPD_EBADF_LIMIT 16
1124                 int ebadf = 0;
1125
1126                 time_t  now;
1127
1128                 fd_set                  readfds;
1129                 fd_set                  writefds;
1130                 Sockaddr                from;
1131
1132                 struct timeval          tv;
1133                 struct timeval          *tvp;
1134
1135                 struct timeval          *cat;
1136                 time_t                          tdelta = 1;
1137                 struct re_s*            rtask;
1138                 now = slap_get_time();
1139
1140                 if( ( global_idletimeout > 0 ) &&
1141                         difftime( last_idle_check +
1142                         global_idletimeout/SLAPD_IDLE_CHECK_LIMIT, now ) < 0 ) {
1143                         connections_timeout_idle( now );
1144                         last_idle_check = now;
1145                 }
1146                 tv = idle;
1147
1148 #ifdef SIGHUP
1149                 if( slapd_gentle_shutdown ) {
1150                         ber_socket_t active;
1151
1152                         if( slapd_gentle_shutdown == 1 ) {
1153                                 Debug( LDAP_DEBUG_ANY, "slapd gentle shutdown\n", 0, 0, 0 );
1154                                 close_listeners( 1 );
1155                                 frontendDB->be_restrictops |= SLAP_RESTRICT_OP_WRITES;
1156                                 slapd_gentle_shutdown = 2;
1157                         }
1158
1159                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1160                         active = slap_daemon.sd_nactives;
1161                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1162                         if( active == 0 ) {
1163                                 slapd_shutdown = 2;
1164                                 break;
1165                         }
1166                 }
1167 #endif
1168
1169                 at = 0;
1170
1171                 ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1172
1173                 nwriters = slap_daemon.sd_nwriters;
1174                 AC_MEMCPY( &readfds, &slap_daemon.sd_readers, sizeof(fd_set) );
1175                 if ( nwriters )
1176                         AC_MEMCPY( &writefds, &slap_daemon.sd_writers, sizeof(fd_set) );
1177                 assert(!FD_ISSET(wake_sds[0], &readfds));
1178                 FD_SET( wake_sds[0], &readfds );
1179
1180                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1181                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1182                                 continue;
1183                         if ( slap_listeners[l]->sl_is_mute )
1184                                 FD_CLR( slap_listeners[l]->sl_sd, &readfds );
1185                         else
1186                         if (!FD_ISSET(slap_listeners[l]->sl_sd, &readfds))
1187                             FD_SET( slap_listeners[l]->sl_sd, &readfds );
1188                 }
1189
1190 #ifndef HAVE_WINSOCK
1191                 nfds = slap_daemon.sd_nfds;
1192 #else
1193                 nfds = dtblsize;
1194 #endif
1195                 if ( global_idletimeout && slap_daemon.sd_nactives )
1196                         at = 1;
1197
1198                 ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1199
1200                 if ( at 
1201 #if defined(HAVE_YIELDING_SELECT) || defined(NO_THREADS)
1202                         &&  ( tv.tv_sec || tv.tv_usec )
1203 #endif
1204                         )
1205                         tvp = &tv;
1206                 else
1207                         tvp = NULL;
1208
1209                 ldap_pvt_thread_mutex_lock( &syncrepl_rq.rq_mutex );
1210                 rtask = ldap_pvt_runqueue_next_sched( &syncrepl_rq, &cat );
1211                 while ( cat && cat->tv_sec && cat->tv_sec <= now ) {
1212                         if ( ldap_pvt_runqueue_isrunning( &syncrepl_rq, rtask )) {
1213                                 ldap_pvt_runqueue_resched( &syncrepl_rq, rtask, 0 );
1214                         } else {
1215                                 ldap_pvt_runqueue_runtask( &syncrepl_rq, rtask );
1216                                 ldap_pvt_runqueue_resched( &syncrepl_rq, rtask, 0 );
1217                                 ldap_pvt_thread_mutex_unlock( &syncrepl_rq.rq_mutex );
1218                                 ldap_pvt_thread_pool_submit( &connection_pool,
1219                                                                                         rtask->routine, (void *) rtask );
1220                                 ldap_pvt_thread_mutex_lock( &syncrepl_rq.rq_mutex );
1221                         }
1222                         rtask = ldap_pvt_runqueue_next_sched( &syncrepl_rq, &cat );
1223                 }
1224                 ldap_pvt_thread_mutex_unlock( &syncrepl_rq.rq_mutex );
1225
1226                 if ( cat != NULL ) {
1227                         time_t diff = difftime( cat->tv_sec, now );
1228                         if ( diff == 0 )
1229                                 diff = tdelta;
1230                         if ( tvp == NULL || diff < tv.tv_sec ) {
1231                                 tv.tv_sec = diff;
1232                                 tv.tv_usec = 0;
1233                                 tvp = &tv;
1234                         }
1235                 }
1236
1237                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1238                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID ||
1239                             slap_listeners[l]->sl_is_mute )
1240                                 continue;
1241
1242                         Debug( LDAP_DEBUG_CONNS,
1243                                 "daemon: select: listen=%d active_threads=%d tvp=%s\n",
1244                                         slap_listeners[l]->sl_sd, at,
1245                                         tvp == NULL ? "NULL" : "zero" );
1246                 }
1247
1248                 switch(ns = select( nfds, &readfds, nwriters > 0 ? &writefds : NULL,
1249                         NULL, tvp ))
1250                 {
1251                 case -1: {      /* failure - try again */
1252                                 int err = sock_errno();
1253
1254                                 if( err == EBADF
1255 #ifdef WSAENOTSOCK
1256                                         /* you'd think this would be EBADF */
1257                                         || err == WSAENOTSOCK
1258 #endif
1259                                 ) {
1260                                         if (++ebadf < SLAPD_EBADF_LIMIT)
1261                                                 continue;
1262                                 }
1263
1264                                 if( err != EINTR ) {
1265                                         Debug( LDAP_DEBUG_CONNS,
1266                                                 "daemon: select failed (%d): %s\n",
1267                                                 err, sock_errstr(err), 0 );
1268                                         slapd_shutdown = 2;
1269                                 }
1270                         }
1271                         continue;
1272
1273                 case 0:         /* timeout - let threads run */
1274                         ebadf = 0;
1275                         Debug( LDAP_DEBUG_CONNS, "daemon: select timeout - yielding\n",
1276                             0, 0, 0 );
1277
1278                         ldap_pvt_thread_yield();
1279                         continue;
1280
1281                 default:        /* something happened - deal with it */
1282                         if( slapd_shutdown ) continue;
1283
1284                         ebadf = 0;
1285                         Debug( LDAP_DEBUG_CONNS, "daemon: activity on %d descriptors\n",
1286                                 ns, 0, 0 );
1287                         /* FALL THRU */
1288                 }
1289
1290                 if( FD_ISSET( wake_sds[0], &readfds ) ) {
1291                         char c[BUFSIZ];
1292                         tcp_read( wake_sds[0], c, sizeof(c) );
1293                         waking = 0;
1294                         ns--;
1295                         continue;
1296                 }
1297
1298                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1299                         ber_socket_t s;
1300                         socklen_t len = sizeof(from);
1301                         long id;
1302                         slap_ssf_t ssf = 0;
1303                         struct berval authid = BER_BVNULL;
1304 #ifdef SLAPD_RLOOKUPS
1305                         char hbuf[NI_MAXHOST];
1306 #endif
1307
1308                         char    *dnsname = NULL;
1309                         char    *peeraddr = NULL;
1310 #ifdef LDAP_PF_LOCAL
1311                         char peername[MAXPATHLEN + sizeof("PATH=")];
1312 #elif defined(LDAP_PF_INET6)
1313                         char peername[sizeof(
1314                                 "IP=ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff 65535")];
1315 #else
1316                         char peername[sizeof("IP=255.255.255.255:65336")];
1317 #endif /* LDAP_PF_LOCAL */
1318
1319                         peername[0] = '\0';
1320
1321                         if ( ns <= 0 ) break;
1322
1323                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1324                                 continue;
1325
1326                         if ( !FD_ISSET( slap_listeners[l]->sl_sd, &readfds ) )
1327                                 continue;
1328                         
1329                         ns--;
1330
1331 #ifdef LDAP_CONNECTIONLESS
1332                         if ( slap_listeners[l]->sl_is_udp ) {
1333                                 /* The first time we receive a query, we set this
1334                                  * up as a "connection". It remains open for the life
1335                                  * of the slapd.
1336                                  */
1337                                 if ( slap_listeners[l]->sl_is_udp < 2 ) {
1338                                         id = connection_init(
1339                                                 slap_listeners[l]->sl_sd,
1340                                                 slap_listeners[l], "", "",
1341                                                 CONN_IS_UDP, ssf, NULL );
1342                                     slap_listeners[l]->sl_is_udp++;
1343                                 }
1344                                 continue;
1345                         }
1346 #endif
1347
1348                         /* Don't need to look at this in the data loops */
1349                         FD_CLR( slap_listeners[l]->sl_sd, &readfds );
1350                         FD_CLR( slap_listeners[l]->sl_sd, &writefds );
1351
1352 #  ifdef LDAP_PF_LOCAL
1353                         /* FIXME: apparently accept doesn't fill
1354                          * the sun_path sun_path member */
1355                         from.sa_un_addr.sun_path[0] = '\0';
1356 #  endif /* LDAP_PF_LOCAL */
1357                         s = accept( slap_listeners[l]->sl_sd,
1358                                 (struct sockaddr *) &from, &len );
1359                         if ( s == AC_SOCKET_INVALID ) {
1360                                 int err = sock_errno();
1361
1362                                 if(
1363 #ifdef EMFILE
1364                                     err == EMFILE ||
1365 #endif
1366 #ifdef ENFILE
1367                                     err == ENFILE ||
1368 #endif
1369                                     0 )
1370                                 {
1371                                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1372                                         emfile++;
1373                                         /* Stop listening until an existing session closes */
1374                                         slap_listeners[l]->sl_is_mute = 1;
1375                                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1376                                 }
1377
1378                                 Debug( LDAP_DEBUG_ANY,
1379                                         "daemon: accept(%ld) failed errno=%d (%s)\n",
1380                                         (long) slap_listeners[l]->sl_sd, err,
1381                                         sock_errstr(err) );
1382                                 ldap_pvt_thread_yield();
1383                                 continue;
1384                         }
1385
1386 #ifndef HAVE_WINSOCK
1387                         /* make sure descriptor number isn't too great */
1388                         if ( s >= dtblsize ) {
1389                                 Debug( LDAP_DEBUG_ANY,
1390                                         "daemon: %ld beyond descriptor table size %ld\n",
1391                                         (long) s, (long) dtblsize, 0 );
1392
1393                                 slapd_close(s);
1394                                 ldap_pvt_thread_yield();
1395                                 continue;
1396                         }
1397 #endif
1398
1399 #ifdef LDAP_DEBUG
1400                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1401
1402                         /* newly accepted stream should not be in any of the FD SETS */
1403                         assert( !FD_ISSET( s, &slap_daemon.sd_actives) );
1404                         assert( !FD_ISSET( s, &slap_daemon.sd_readers) );
1405                         assert( !FD_ISSET( s, &slap_daemon.sd_writers) );
1406
1407                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1408 #endif
1409
1410 #if defined( SO_KEEPALIVE ) || defined( TCP_NODELAY )
1411 #ifdef LDAP_PF_LOCAL
1412                         /* for IPv4 and IPv6 sockets only */
1413                         if ( from.sa_addr.sa_family != AF_LOCAL )
1414 #endif /* LDAP_PF_LOCAL */
1415                         {
1416                                 int rc;
1417                                 int tmp;
1418 #ifdef SO_KEEPALIVE
1419                                 /* enable keep alives */
1420                                 tmp = 1;
1421                                 rc = setsockopt( s, SOL_SOCKET, SO_KEEPALIVE,
1422                                         (char *) &tmp, sizeof(tmp) );
1423                                 if ( rc == AC_SOCKET_ERROR ) {
1424                                         int err = sock_errno();
1425                                         Debug( LDAP_DEBUG_ANY,
1426                                                 "slapd(%ld): setsockopt(SO_KEEPALIVE) failed "
1427                                                 "errno=%d (%s)\n", (long) s, err, sock_errstr(err) );
1428                                 }
1429 #endif
1430 #ifdef TCP_NODELAY
1431                                 /* enable no delay */
1432                                 tmp = 1;
1433                                 rc = setsockopt( s, IPPROTO_TCP, TCP_NODELAY,
1434                                         (char *)&tmp, sizeof(tmp) );
1435                                 if ( rc == AC_SOCKET_ERROR ) {
1436                                         int err = sock_errno();
1437                                         Debug( LDAP_DEBUG_ANY,
1438                                                 "slapd(%ld): setsockopt(TCP_NODELAY) failed "
1439                                                 "errno=%d (%s)\n", (long) s, err, sock_errstr(err) );
1440                                 }
1441 #endif
1442                         }
1443 #endif
1444
1445                         Debug( LDAP_DEBUG_CONNS, "daemon: new connection on %ld\n",
1446                                 (long) s, 0, 0 );
1447                         switch ( from.sa_addr.sa_family ) {
1448 #  ifdef LDAP_PF_LOCAL
1449                         case AF_LOCAL:
1450                                 /* FIXME: apparently accept doesn't fill
1451                                  * the sun_path sun_path member */
1452                                 if ( from.sa_un_addr.sun_path[0] == '\0' ) {
1453                                         AC_MEMCPY( from.sa_un_addr.sun_path,
1454                                                         slap_listeners[l]->sl_sa.sa_un_addr.sun_path,
1455                                                         sizeof( from.sa_un_addr.sun_path ) );
1456                                 }
1457
1458                                 sprintf( peername, "PATH=%s", from.sa_un_addr.sun_path );
1459                                 ssf = local_ssf;
1460                                 {
1461                                         uid_t uid;
1462                                         gid_t gid;
1463
1464                                         if( getpeereid( s, &uid, &gid ) == 0 ) {
1465                                                 authid.bv_val = ch_malloc(
1466                                                         sizeof("uidnumber=4294967295+gidnumber=4294967295,"
1467                                                         "cn=peercred,cn=external,cn=auth"));
1468                                                 authid.bv_len = sprintf( authid.bv_val,
1469                                                         "uidnumber=%d+gidnumber=%d,"
1470                                                         "cn=peercred,cn=external,cn=auth",
1471                                                         (int) uid, (int) gid);
1472                                         }
1473                                 }
1474                                 dnsname = "local";
1475                                 break;
1476 #endif /* LDAP_PF_LOCAL */
1477
1478 #  ifdef LDAP_PF_INET6
1479                         case AF_INET6:
1480                         if ( IN6_IS_ADDR_V4MAPPED(&from.sa_in6_addr.sin6_addr) ) {
1481                                 peeraddr = inet_ntoa( *((struct in_addr *)
1482                                                         &from.sa_in6_addr.sin6_addr.s6_addr[12]) );
1483                                 sprintf( peername, "IP=%s:%d",
1484                                          peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1485                                          (unsigned) ntohs( from.sa_in6_addr.sin6_port ) );
1486                         } else {
1487                                 char addr[INET6_ADDRSTRLEN];
1488
1489                                 peeraddr = (char *) inet_ntop( AF_INET6,
1490                                                       &from.sa_in6_addr.sin6_addr,
1491                                                       addr, sizeof addr );
1492                                 sprintf( peername, "IP=%s %d",
1493                                          peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1494                                          (unsigned) ntohs( from.sa_in6_addr.sin6_port ) );
1495                         }
1496                         break;
1497 #  endif /* LDAP_PF_INET6 */
1498
1499                         case AF_INET:
1500                         peeraddr = inet_ntoa( from.sa_in_addr.sin_addr );
1501                         sprintf( peername, "IP=%s:%d",
1502                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1503                                 (unsigned) ntohs( from.sa_in_addr.sin_port ) );
1504                                 break;
1505
1506                         default:
1507                                 slapd_close(s);
1508                                 continue;
1509                         }
1510
1511                         if ( ( from.sa_addr.sa_family == AF_INET )
1512 #ifdef LDAP_PF_INET6
1513                                 || ( from.sa_addr.sa_family == AF_INET6 )
1514 #endif
1515                         ) {
1516 #ifdef SLAPD_RLOOKUPS
1517                                 if ( use_reverse_lookup ) {
1518                                         char *herr;
1519                                         if (ldap_pvt_get_hname( (const struct sockaddr *)&from, len, hbuf,
1520                                                 sizeof(hbuf), &herr ) == 0) {
1521                                                 ldap_pvt_str2lower( hbuf );
1522                                                 dnsname = hbuf;
1523                                         }
1524                                 }
1525 #else
1526                                 dnsname = NULL;
1527 #endif /* SLAPD_RLOOKUPS */
1528
1529 #ifdef HAVE_TCPD
1530                                 if ( !hosts_ctl("slapd",
1531                                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1532                                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1533                                                 SLAP_STRING_UNKNOWN ))
1534                                 {
1535                                         /* DENY ACCESS */
1536                                         Statslog( LDAP_DEBUG_STATS,
1537                                                 "fd=%ld DENIED from %s (%s)\n",
1538                                                 (long) s,
1539                                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1540                                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1541                                                 0, 0 );
1542                                         slapd_close(s);
1543                                         continue;
1544                                 }
1545 #endif /* HAVE_TCPD */
1546                         }
1547
1548                         id = connection_init(s,
1549                                 slap_listeners[l],
1550                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1551                                 peername,
1552 #ifdef HAVE_TLS
1553                                 slap_listeners[l]->sl_is_tls ? CONN_IS_TLS : 0,
1554 #else
1555                                 0,
1556 #endif
1557                                 ssf,
1558                                 authid.bv_val ? &authid : NULL );
1559
1560                         if( authid.bv_val ) ch_free(authid.bv_val);
1561
1562                         if( id < 0 ) {
1563                                 Debug( LDAP_DEBUG_ANY,
1564                                         "daemon: connection_init(%ld, %s, %s) "
1565                                         "failed.\n",
1566                                         (long) s,
1567                                         peername,
1568                                         slap_listeners[l]->sl_name.bv_val );
1569                                 slapd_close(s);
1570                                 continue;
1571                         }
1572
1573                         Statslog( LDAP_DEBUG_STATS,
1574                                 "conn=%ld fd=%ld ACCEPT from %s (%s)\n",
1575                                 id, (long) s,
1576                                 peername,
1577                                 slap_listeners[l]->sl_name.bv_val,
1578                                 0 );
1579
1580                         slapd_add( s, 1 );
1581                         continue;
1582                 }
1583
1584                 /* bypass the following tests if no descriptors left */
1585                 if ( ns <= 0 ) {
1586                         ldap_pvt_thread_yield();
1587                         continue;
1588                 }
1589
1590                 Debug( LDAP_DEBUG_CONNS, "daemon: activity on:", 0, 0, 0 );
1591 #ifdef HAVE_WINSOCK
1592                 nrfds = readfds.fd_count;
1593                 nwfds = writefds.fd_count;
1594                 for ( i = 0; i < readfds.fd_count; i++ ) {
1595                         Debug( LDAP_DEBUG_CONNS, " %d%s",
1596                                 readfds.fd_array[i], "r", 0 );
1597                 }
1598                 for ( i = 0; i < writefds.fd_count; i++ ) {
1599                         Debug( LDAP_DEBUG_CONNS, " %d%s",
1600                                 writefds.fd_array[i], "w", 0 );
1601                 }
1602
1603 #else
1604                 nrfds = 0;
1605                 nwfds = 0;
1606                 for ( i = 0; i < nfds; i++ ) {
1607                         int     r, w;
1608
1609                         r = FD_ISSET( i, &readfds );
1610                         w = FD_ISSET( i, &writefds );
1611                         if ( r || w ) {
1612                                 Debug( LDAP_DEBUG_CONNS, " %d%s%s", i,
1613                                     r ? "r" : "", w ? "w" : "" );
1614                                 if ( r ) {
1615                                         nrfds++;
1616                                         ns--;
1617                                 }
1618                                 if ( w ) {
1619                                         nwfds++;
1620                                         ns--;
1621                                 }
1622                         }
1623                         if ( ns <= 0 ) break;
1624                 }
1625 #endif
1626                 Debug( LDAP_DEBUG_CONNS, "\n", 0, 0, 0 );
1627
1628
1629                 /* loop through the writers */
1630                 for ( i = 0; nwfds > 0; i++ )
1631                 {
1632                         ber_socket_t wd;
1633 #ifdef HAVE_WINSOCK
1634                         wd = writefds.fd_array[i];
1635 #else
1636                         if( ! FD_ISSET( i, &writefds ) ) {
1637                                 continue;
1638                         }
1639                         wd = i;
1640 #endif
1641                         nwfds--;
1642
1643                         Debug( LDAP_DEBUG_CONNS,
1644                                 "daemon: write active on %d\n",
1645                                 wd, 0, 0 );
1646                         /*
1647                          * NOTE: it is possible that the connection was closed
1648                          * and that the stream is now inactive.
1649                          * connection_write() must valid the stream is still
1650                          * active.
1651                          */
1652
1653                         if ( connection_write( wd ) < 0 ) {
1654                                 if ( FD_ISSET( wd, &readfds )) {
1655                                         FD_CLR( (unsigned) wd, &readfds );
1656                                         nrfds--;
1657                                 }
1658                                 slapd_close( wd );
1659                         }
1660                 }
1661
1662                 for ( i = 0; nrfds > 0; i++ )
1663                 {
1664                         ber_socket_t rd;
1665 #ifdef HAVE_WINSOCK
1666                         rd = readfds.fd_array[i];
1667 #else
1668                         if( ! FD_ISSET( i, &readfds ) ) {
1669                                 continue;
1670                         }
1671                         rd = i;
1672 #endif
1673                         nrfds--;
1674
1675                         Debug ( LDAP_DEBUG_CONNS,
1676                                 "daemon: read activity on %d\n", rd, 0, 0 );
1677                         /*
1678                          * NOTE: it is possible that the connection was closed
1679                          * and that the stream is now inactive.
1680                          * connection_read() must valid the stream is still
1681                          * active.
1682                          */
1683
1684                         if ( connection_read( rd ) < 0 ) {
1685                                 slapd_close( rd );
1686                         }
1687                 }
1688                 ldap_pvt_thread_yield();
1689         }
1690
1691         if( slapd_shutdown == 1 ) {
1692                 Debug( LDAP_DEBUG_TRACE,
1693                         "daemon: shutdown requested and initiated.\n",
1694                         0, 0, 0 );
1695
1696         } else if ( slapd_shutdown == 2 ) {
1697 #ifdef HAVE_NT_SERVICE_MANAGER
1698                         Debug( LDAP_DEBUG_TRACE,
1699                                "daemon: shutdown initiated by Service Manager.\n",
1700                                0, 0, 0);
1701 #else /* !HAVE_NT_SERVICE_MANAGER */
1702                         Debug( LDAP_DEBUG_TRACE,
1703                                "daemon: abnormal condition, shutdown initiated.\n",
1704                                0, 0, 0 );
1705 #endif /* !HAVE_NT_SERVICE_MANAGER */
1706         } else {
1707                 Debug( LDAP_DEBUG_TRACE,
1708                        "daemon: no active streams, shutdown initiated.\n",
1709                        0, 0, 0 );
1710         }
1711
1712         if( slapd_gentle_shutdown != 2 ) {
1713                 close_listeners ( 0 );
1714         }
1715
1716         free ( slap_listeners );
1717         slap_listeners = NULL;
1718
1719         if( !slapd_gentle_shutdown ) {
1720                 slapd_abrupt_shutdown = 1;
1721                 connections_shutdown();
1722         }
1723
1724         Debug( LDAP_DEBUG_ANY,
1725             "slapd shutdown: waiting for %d threads to terminate\n",
1726             ldap_pvt_thread_pool_backload(&connection_pool), 0, 0 );
1727         ldap_pvt_thread_pool_destroy(&connection_pool, 1);
1728
1729         return NULL;
1730 }
1731
1732
1733 int slapd_daemon( void )
1734 {
1735         int rc;
1736
1737         connections_init();
1738
1739 #define SLAPD_LISTENER_THREAD 1
1740 #if defined( SLAPD_LISTENER_THREAD )
1741         {
1742                 ldap_pvt_thread_t       listener_tid;
1743
1744                 /* listener as a separate THREAD */
1745                 rc = ldap_pvt_thread_create( &listener_tid,
1746                         0, slapd_daemon_task, NULL );
1747
1748                 if ( rc != 0 ) {
1749                         Debug( LDAP_DEBUG_ANY,
1750                         "listener ldap_pvt_thread_create failed (%d)\n", rc, 0, 0 );
1751                         return rc;
1752                 }
1753  
1754                 /* wait for the listener thread to complete */
1755                 ldap_pvt_thread_join( listener_tid, (void *) NULL );
1756         }
1757 #else
1758         /* experimental code */
1759         slapd_daemon_task( NULL );
1760 #endif
1761
1762         return 0;
1763
1764 }
1765
1766 int sockinit(void)
1767 {
1768 #if defined( HAVE_WINSOCK2 )
1769     WORD wVersionRequested;
1770         WSADATA wsaData;
1771         int err;
1772
1773         wVersionRequested = MAKEWORD( 2, 0 );
1774
1775         err = WSAStartup( wVersionRequested, &wsaData );
1776         if ( err != 0 ) {
1777                 /* Tell the user that we couldn't find a usable */
1778                 /* WinSock DLL.                                  */
1779                 return -1;
1780         }
1781
1782         /* Confirm that the WinSock DLL supports 2.0.*/
1783         /* Note that if the DLL supports versions greater    */
1784         /* than 2.0 in addition to 2.0, it will still return */
1785         /* 2.0 in wVersion since that is the version we      */
1786         /* requested.                                        */
1787
1788         if ( LOBYTE( wsaData.wVersion ) != 2 ||
1789                 HIBYTE( wsaData.wVersion ) != 0 )
1790         {
1791             /* Tell the user that we couldn't find a usable */
1792             /* WinSock DLL.                                  */
1793             WSACleanup();
1794             return -1;
1795         }
1796
1797         /* The WinSock DLL is acceptable. Proceed. */
1798 #elif defined( HAVE_WINSOCK )
1799         WSADATA wsaData;
1800         if ( WSAStartup( 0x0101, &wsaData ) != 0 ) {
1801             return -1;
1802         }
1803 #endif
1804         return 0;
1805 }
1806
1807 int sockdestroy(void)
1808 {
1809 #if defined( HAVE_WINSOCK2 ) || defined( HAVE_WINSOCK )
1810         WSACleanup();
1811 #endif
1812         return 0;
1813 }
1814
1815 RETSIGTYPE
1816 slap_sig_shutdown( int sig )
1817 {
1818 #if 0
1819         Debug(LDAP_DEBUG_TRACE, "slap_sig_shutdown: signal %d\n", sig, 0, 0);
1820 #endif
1821
1822         /*
1823          * If the NT Service Manager is controlling the server, we don't
1824          * want SIGBREAK to kill the server. For some strange reason,
1825          * SIGBREAK is generated when a user logs out.
1826          */
1827
1828 #if HAVE_NT_SERVICE_MANAGER && SIGBREAK
1829         if (is_NT_Service && sig == SIGBREAK)
1830                 ;
1831         else
1832 #endif
1833 #ifdef SIGHUP
1834         if (sig == SIGHUP && global_gentlehup && slapd_gentle_shutdown == 0)
1835                 slapd_gentle_shutdown = 1;
1836         else
1837 #endif
1838         slapd_shutdown = 1;
1839         WAKE_LISTENER(1);
1840
1841         /* reinstall self */
1842         (void) SIGNAL_REINSTALL( sig, slap_sig_shutdown );
1843 }
1844
1845 RETSIGTYPE
1846 slap_sig_wake( int sig )
1847 {
1848         WAKE_LISTENER(1);
1849
1850         /* reinstall self */
1851         (void) SIGNAL_REINSTALL( sig, slap_sig_wake );
1852 }
1853
1854
1855 void slapd_add_internal(ber_socket_t s, int isactive) {
1856         slapd_add(s, isactive);
1857 }
1858
1859 Listener ** slapd_get_listeners(void) {
1860         return slap_listeners;
1861 }
1862
1863 void slap_wake_listener()
1864 {
1865         WAKE_LISTENER(1);
1866 }