]> git.sur5r.net Git - openldap/blob - servers/slapd/daemon.c
safer defaults ...
[openldap] / servers / slapd / daemon.c
1 /* $OpenLDAP$ */
2 /*
3  * Copyright 1998-2003 The OpenLDAP Foundation, All Rights Reserved.
4  * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
5  */
6
7 #include "portable.h"
8
9 #include <stdio.h>
10
11 #include <ac/ctype.h>
12 #include <ac/errno.h>
13 #include <ac/socket.h>
14 #include <ac/string.h>
15 #include <ac/time.h>
16 #include <ac/unistd.h>
17
18 #include "ldap_pvt.h"
19 #include "ldap_pvt_thread.h"
20 #include "lutil.h"
21 #include "slap.h"
22
23 #ifdef HAVE_TCPD
24 #include <tcpd.h>
25 #define SLAP_STRING_UNKNOWN     STRING_UNKNOWN
26
27 int allow_severity = LOG_INFO;
28 int deny_severity = LOG_NOTICE;
29 #else /* ! TCP Wrappers */
30 #define SLAP_STRING_UNKNOWN     "unknown"
31 #endif /* ! TCP Wrappers */
32
33 #ifdef LDAP_PF_LOCAL
34 #include <sys/stat.h>
35 /* this should go in <ldap.h> as soon as it is accepted */
36 #define LDAPI_MOD_URLEXT                "x-mod"
37 #endif /* LDAP_PF_LOCAL */
38
39 #ifdef LDAP_PF_INET6
40 int slap_inet4or6 = AF_UNSPEC;
41 #else
42 int slap_inet4or6 = AF_INET;
43 #endif
44
45 /* globals */
46 time_t starttime;
47 ber_socket_t dtblsize;
48
49 Listener **slap_listeners = NULL;
50
51 #define SLAPD_LISTEN 10
52
53 static ber_socket_t wake_sds[2];
54
55 #if defined(NO_THREADS) || defined(HAVE_GNU_PTH)
56 static int waking;
57 #define WAKE_LISTENER(w) \
58 ((w && !waking) ? tcp_write( wake_sds[1], "0", 1 ), waking=1 : 0)
59 #else
60 #define WAKE_LISTENER(w) \
61 do { if (w) tcp_write( wake_sds[1], "0", 1 ); } while(0)
62 #endif
63
64 #ifndef HAVE_WINSOCK
65 static
66 #endif
67 volatile sig_atomic_t slapd_shutdown = 0, slapd_gentle_shutdown = 0;
68
69 static struct slap_daemon {
70         ldap_pvt_thread_mutex_t sd_mutex;
71
72         ber_socket_t sd_nactives;
73
74 #ifndef HAVE_WINSOCK
75         /* In winsock, accept() returns values higher than dtblsize
76                 so don't bother with this optimization */
77         int sd_nfds;
78 #endif
79
80         fd_set sd_actives;
81         fd_set sd_readers;
82         fd_set sd_writers;
83 } slap_daemon;
84
85
86
87 #ifdef HAVE_SLP
88 /*
89  * SLP related functions
90  */
91 #include <slp.h>
92
93 #define LDAP_SRVTYPE_PREFIX "service:ldap://"
94 #define LDAPS_SRVTYPE_PREFIX "service:ldaps://"
95 static char** slapd_srvurls = NULL;
96 static SLPHandle slapd_hslp = 0;
97
98 void slapd_slp_init( const char* urls ) {
99         int i;
100
101         slapd_srvurls = ldap_str2charray( urls, " " );
102
103         if( slapd_srvurls == NULL ) return;
104
105         /* find and expand INADDR_ANY URLs */
106         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
107                 if( strcmp( slapd_srvurls[i], "ldap:///" ) == 0) {
108                         char *host = ldap_pvt_get_fqdn( NULL );
109                         if ( host != NULL ) {
110                                 slapd_srvurls[i] = (char *) ch_realloc( slapd_srvurls[i],
111                                         strlen( host ) +
112                                         sizeof( LDAP_SRVTYPE_PREFIX ) );
113                                 strcpy( lutil_strcopy(slapd_srvurls[i],
114                                         LDAP_SRVTYPE_PREFIX ), host );
115
116                                 ch_free( host );
117                         }
118
119                 } else if ( strcmp( slapd_srvurls[i], "ldaps:///" ) == 0) {
120                         char *host = ldap_pvt_get_fqdn( NULL );
121                         if ( host != NULL ) {
122                                 slapd_srvurls[i] = (char *) ch_realloc( slapd_srvurls[i],
123                                         strlen( host ) +
124                                         sizeof( LDAPS_SRVTYPE_PREFIX ) );
125                                 strcpy( lutil_strcopy(slapd_srvurls[i],
126                                         LDAPS_SRVTYPE_PREFIX ), host );
127
128                                 ch_free( host );
129                         }
130                 }
131         }
132
133         /* open the SLP handle */
134         SLPOpen( "en", 0, &slapd_hslp );
135 }
136
137 void slapd_slp_deinit() {
138         if( slapd_srvurls == NULL ) return;
139
140         ldap_charray_free( slapd_srvurls );
141         slapd_srvurls = NULL;
142
143         /* close the SLP handle */
144         SLPClose( slapd_hslp );
145 }
146
147 void slapd_slp_regreport(
148         SLPHandle hslp,
149         SLPError errcode,
150         void* cookie )
151 {
152         /* empty report */
153 }
154
155 void slapd_slp_reg() {
156         int i;
157
158         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
159                 if( strncmp( slapd_srvurls[i], LDAP_SRVTYPE_PREFIX,
160                                 sizeof( LDAP_SRVTYPE_PREFIX ) - 1 ) == 0 ||
161                     strncmp( slapd_srvurls[i], LDAPS_SRVTYPE_PREFIX,
162                                 sizeof( LDAPS_SRVTYPE_PREFIX ) - 1 ) == 0 )
163                 {
164                         SLPReg( slapd_hslp,
165                                 slapd_srvurls[i],
166                                 SLP_LIFETIME_MAXIMUM,
167                                 "ldap",
168                                 "",
169                                 1,
170                                 slapd_slp_regreport,
171                                 NULL );
172                 }
173         }
174 }
175
176 void slapd_slp_dereg() {
177         int i;
178
179         for( i=0; slapd_srvurls[i] != NULL; i++ ) {
180                 SLPDereg( slapd_hslp,
181                         slapd_srvurls[i],
182                         slapd_slp_regreport,
183                         NULL );
184         }
185 }
186 #endif /* HAVE_SLP */
187
188 /*
189  * Add a descriptor to daemon control
190  */
191 static void slapd_add(ber_socket_t s) {
192         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
193
194         assert( !FD_ISSET( s, &slap_daemon.sd_actives ));
195         assert( !FD_ISSET( s, &slap_daemon.sd_readers ));
196         assert( !FD_ISSET( s, &slap_daemon.sd_writers ));
197
198 #ifndef HAVE_WINSOCK
199         if (s >= slap_daemon.sd_nfds) {
200                 slap_daemon.sd_nfds = s + 1;
201         }
202 #endif
203
204         slap_daemon.sd_nactives++;
205
206         FD_SET( s, &slap_daemon.sd_actives );
207         FD_SET( s, &slap_daemon.sd_readers );
208
209 #ifdef NEW_LOGGING
210         LDAP_LOG( CONNECTION, DETAIL1, 
211                 "slapd_add: added %ld%s%s\n", (long)s,
212                 FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
213                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : "" );
214 #else
215         Debug( LDAP_DEBUG_CONNS, "daemon: added %ld%s%s\n",
216                 (long) s,
217             FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
218                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : "" );
219 #endif
220         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
221 }
222
223 /*
224  * Remove the descriptor from daemon control
225  */
226 void slapd_remove(ber_socket_t s, int wake) {
227         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
228
229         slap_daemon.sd_nactives--;
230
231 #ifdef NEW_LOGGING
232         LDAP_LOG( CONNECTION, DETAIL1, 
233                 "slapd_remove: removing %ld%s%s\n", (long) s,
234                 FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
235                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : ""  );
236 #else
237         Debug( LDAP_DEBUG_CONNS, "daemon: removing %ld%s%s\n",
238                 (long) s,
239             FD_ISSET(s, &slap_daemon.sd_readers) ? "r" : "",
240                 FD_ISSET(s, &slap_daemon.sd_writers) ? "w" : "" );
241 #endif
242         FD_CLR( s, &slap_daemon.sd_actives );
243         FD_CLR( s, &slap_daemon.sd_readers );
244         FD_CLR( s, &slap_daemon.sd_writers );
245
246         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
247         WAKE_LISTENER(wake || slapd_gentle_shutdown == 2);
248 }
249
250 void slapd_clr_write(ber_socket_t s, int wake) {
251         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
252
253         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
254         FD_CLR( s, &slap_daemon.sd_writers );
255
256         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
257         WAKE_LISTENER(wake);
258 }
259
260 void slapd_set_write(ber_socket_t s, int wake) {
261         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
262
263         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
264         if (!FD_ISSET(s, &slap_daemon.sd_writers))
265             FD_SET( (unsigned) s, &slap_daemon.sd_writers );
266
267         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
268         WAKE_LISTENER(wake);
269 }
270
271 void slapd_clr_read(ber_socket_t s, int wake) {
272         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
273
274         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
275         FD_CLR( s, &slap_daemon.sd_readers );
276
277         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
278         WAKE_LISTENER(wake);
279 }
280
281 void slapd_set_read(ber_socket_t s, int wake) {
282         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
283
284         assert( FD_ISSET( s, &slap_daemon.sd_actives) );
285         if (!FD_ISSET(s, &slap_daemon.sd_readers))
286             FD_SET( s, &slap_daemon.sd_readers );
287
288         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
289         WAKE_LISTENER(wake);
290 }
291
292 static void slapd_close(ber_socket_t s) {
293 #ifdef NEW_LOGGING
294         LDAP_LOG( CONNECTION, DETAIL1, "slapd_close: closing %ld\n", (long)s, 0, 0);
295 #else
296         Debug( LDAP_DEBUG_CONNS, "daemon: closing %ld\n",
297                 (long) s, 0, 0 );
298 #endif
299         tcp_close(s);
300 }
301
302 static void slap_free_listener_addresses(struct sockaddr **sal)
303 {
304         struct sockaddr **sap;
305
306         if (sal == NULL) {
307                 return;
308         }
309
310         for (sap = sal; *sap != NULL; sap++) {
311                 ch_free(*sap);
312         }
313
314         ch_free(sal);
315 }
316
317 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
318 static int get_url_perms(
319         char    **exts,
320         mode_t  *perms,
321         int     *crit )
322 {
323         int     i;
324
325         assert( exts );
326         assert( perms );
327         assert( crit );
328
329         *crit = 0;
330         for ( i = 0; exts[ i ]; i++ ) {
331                 char    *type = exts[ i ];
332                 int     c = 0;
333
334                 if ( type[ 0 ] == '!' ) {
335                         c = 1;
336                         type++;
337                 }
338
339                 if ( strncasecmp( type, LDAPI_MOD_URLEXT "=", sizeof(LDAPI_MOD_URLEXT "=") - 1 ) == 0 ) {
340                         char    *value = type
341                                 + ( sizeof(LDAPI_MOD_URLEXT "=") - 1 );
342                         mode_t  p = 0;
343                         int     j;
344
345                         switch (strlen(value)) {
346                         case 4:
347                                 /* skip leading '0' */
348                                 if ( value[ 0 ] != '0' ) {
349                                         return LDAP_OTHER;
350                                 }
351                                 value++;
352
353                         case 3:
354                                 for ( j = 0; j < 3; j++) {
355                                         int     v;
356
357                                         v = value[ j ] - '0';
358
359                                         if ( v < 0 || v > 7 ) {
360                                                 return LDAP_OTHER;
361                                         }
362
363                                         p |= v << 3*(2-j);
364                                 }
365                                 break;
366
367                         case 10:
368                                 for ( j = 1; j < 10; j++ ) {
369                                         static mode_t   m[] = { 0, 
370                                                 S_IRUSR, S_IWUSR, S_IXUSR,
371                                                 S_IRGRP, S_IWGRP, S_IXGRP,
372                                                 S_IROTH, S_IWOTH, S_IXOTH
373                                         };
374                                         static char     c[] = "-rwxrwxrwx"; 
375
376                                         if ( value[ j ] == c[ j ] ) {
377                                                 p |= m[ j ];
378         
379                                         } else if ( value[ j ] != '-' ) {
380                                                 return LDAP_OTHER;
381                                         }
382                                 }
383                                 break;
384
385                         default:
386                                 return LDAP_OTHER;
387                         } 
388
389                         *crit = c;
390                         *perms = p;
391
392                         return LDAP_SUCCESS;
393                 }
394         }
395
396         return LDAP_OTHER;
397 }
398 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
399
400 /* port = 0 indicates AF_LOCAL */
401 static int slap_get_listener_addresses(
402         const char *host,
403         unsigned short port,
404         struct sockaddr ***sal)
405 {
406         struct sockaddr **sap;
407
408 #ifdef LDAP_PF_LOCAL
409         if ( port == 0 ) {
410                 *sal = ch_malloc(2 * sizeof(void *));
411                 if (*sal == NULL) {
412                         return -1;
413                 }
414
415                 sap = *sal;
416                 *sap = ch_malloc(sizeof(struct sockaddr_un));
417                 if (*sap == NULL)
418                         goto errexit;
419                 sap[1] = NULL;
420
421                 if ( strlen(host) >
422                      (sizeof(((struct sockaddr_un *)*sap)->sun_path) - 1) ) {
423 #ifdef NEW_LOGGING
424                         LDAP_LOG( CONNECTION, INFO, 
425                                 "slap_get_listener_addresses: domain socket path (%s) "
426                                 "too long in URL\n", host, 0, 0 );
427 #else
428                         Debug( LDAP_DEBUG_ANY,
429                                "daemon: domain socket path (%s) too long in URL",
430                                host, 0, 0);
431 #endif
432                         goto errexit;
433                 }
434
435                 (void)memset( (void *)*sap, '\0', sizeof(struct sockaddr_un) );
436                 (*sap)->sa_family = AF_LOCAL;
437                 strcpy( ((struct sockaddr_un *)*sap)->sun_path, host );
438         } else
439 #endif
440         {
441 #ifdef HAVE_GETADDRINFO
442                 struct addrinfo hints, *res, *sai;
443                 int n, err;
444                 char serv[7];
445
446                 memset( &hints, '\0', sizeof(hints) );
447                 hints.ai_flags = AI_PASSIVE;
448                 hints.ai_socktype = SOCK_STREAM;
449                 hints.ai_family = slap_inet4or6;
450                 snprintf(serv, sizeof serv, "%d", port);
451
452                 if ( (err = getaddrinfo(host, serv, &hints, &res)) ) {
453 #ifdef NEW_LOGGING
454                         LDAP_LOG( CONNECTION, INFO, 
455                                    "slap_get_listener_addresses: getaddrinfo failed: %s\n",
456                                    AC_GAI_STRERROR(err), 0, 0 );
457 #else
458                         Debug( LDAP_DEBUG_ANY, "daemon: getaddrinfo failed: %s\n",
459                                 AC_GAI_STRERROR(err), 0, 0);
460 #endif
461                         return -1;
462                 }
463
464                 sai = res;
465                 for (n=2; (sai = sai->ai_next) != NULL; n++) {
466                         /* EMPTY */ ;
467                 }
468                 *sal = ch_calloc(n, sizeof(void *));
469                 if (*sal == NULL) {
470                         return -1;
471                 }
472
473                 sap = *sal;
474                 *sap = NULL;
475
476                 for ( sai=res; sai; sai=sai->ai_next ) {
477                         if( sai->ai_addr == NULL ) {
478 #ifdef NEW_LOGGING
479                                 LDAP_LOG( CONNECTION, INFO,
480                                         "slap_get_listener_addresses: "
481                                         "getaddrinfo ai_addr is NULL?\n", 0, 0, 0 );
482 #else
483                                 Debug( LDAP_DEBUG_ANY, "slap_get_listener_addresses: "
484                                         "getaddrinfo ai_addr is NULL?\n", 0, 0, 0 );
485 #endif
486                                 freeaddrinfo(res);
487                                 goto errexit;
488                         }
489
490                         switch (sai->ai_family) {
491 #  ifdef LDAP_PF_INET6
492                         case AF_INET6:
493                                 *sap = ch_malloc(sizeof(struct sockaddr_in6));
494                                 if (*sap == NULL) {
495                                         freeaddrinfo(res);
496                                         goto errexit;
497                                 }
498                                 *(struct sockaddr_in6 *)*sap =
499                                         *((struct sockaddr_in6 *)sai->ai_addr);
500                                 break;
501 #  endif
502                         case AF_INET:
503                                 *sap = ch_malloc(sizeof(struct sockaddr_in));
504                                 if (*sap == NULL) {
505                                         freeaddrinfo(res);
506                                         goto errexit;
507                                 }
508                                 *(struct sockaddr_in *)*sap =
509                                         *((struct sockaddr_in *)sai->ai_addr);
510                                 break;
511                         default:
512                                 *sap = NULL;
513                                 break;
514                         }
515
516                         if (*sap != NULL) {
517                                 (*sap)->sa_family = sai->ai_family;
518                                 sap++;
519                                 *sap = NULL;
520                         }
521                 }
522
523                 freeaddrinfo(res);
524 #else
525                 int i, n = 1;
526                 struct in_addr in;
527                 struct hostent *he = NULL;
528
529                 if ( host == NULL ) {
530                         in.s_addr = htonl(INADDR_ANY);
531
532                 } else if ( !inet_aton( host, &in ) ) {
533                         he = gethostbyname( host );
534                         if( he == NULL ) {
535 #ifdef NEW_LOGGING
536                                 LDAP_LOG( CONNECTION, INFO, 
537                                         "slap_get_listener_addresses: invalid host %s\n", host, 0, 0 );
538 #else
539                                 Debug( LDAP_DEBUG_ANY,
540                                        "daemon: invalid host %s", host, 0, 0);
541 #endif
542                                 return -1;
543                         }
544                         for (n = 0; he->h_addr_list[n]; n++) ;
545                 }
546
547                 *sal = ch_malloc((n+1) * sizeof(void *));
548                 if (*sal == NULL) {
549                         return -1;
550                 }
551
552                 sap = *sal;
553                 for ( i = 0; i<n; i++ ) {
554                         sap[i] = ch_malloc(sizeof(struct sockaddr_in));
555                         if (*sap == NULL) {
556                                 goto errexit;
557                         }
558                         (void)memset( (void *)sap[i], '\0', sizeof(struct sockaddr_in) );
559                         sap[i]->sa_family = AF_INET;
560                         ((struct sockaddr_in *)sap[i])->sin_port = htons(port);
561                         if (he) {
562                                 AC_MEMCPY( &((struct sockaddr_in *)sap[i])->sin_addr, he->h_addr_list[i], sizeof(struct in_addr) );
563                         } else {
564                                 AC_MEMCPY( &((struct sockaddr_in *)sap[i])->sin_addr, &in, sizeof(struct in_addr) );
565                         }
566                 }
567                 sap[i] = NULL;
568 #endif
569         }
570
571         return 0;
572
573 errexit:
574         slap_free_listener_addresses(*sal);
575         return -1;
576 }
577
578 static int slap_open_listener(
579         const char* url,
580         int *listeners,
581         int *cur
582         )
583 {
584         int     num, tmp, rc;
585         Listener l;
586         Listener *li;
587         LDAPURLDesc *lud;
588         unsigned short port;
589         int err, addrlen = 0;
590         struct sockaddr **sal, **psal;
591         int socktype = SOCK_STREAM;     /* default to COTS */
592
593 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
594         /*
595          * use safe defaults
596          */
597         int     crit = 1;
598 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
599
600         rc = ldap_url_parse( url, &lud );
601
602         if( rc != LDAP_URL_SUCCESS ) {
603 #ifdef NEW_LOGGING
604                 LDAP_LOG( CONNECTION, ERR, 
605                         "slap_open_listener: listen URL \"%s\" parse error %d\n",
606                         url, rc , 0 );
607 #else
608                 Debug( LDAP_DEBUG_ANY,
609                         "daemon: listen URL \"%s\" parse error=%d\n",
610                         url, rc, 0 );
611 #endif
612                 return rc;
613         }
614
615         l.sl_url.bv_val = NULL;
616
617 #ifndef HAVE_TLS
618         if( ldap_pvt_url_scheme2tls( lud->lud_scheme ) ) {
619 #ifdef NEW_LOGGING
620                 LDAP_LOG( CONNECTION, INFO, 
621                            "slap_open_listener: TLS is not supported (%s)\n", url, 0, 0 );
622 #else
623                 Debug( LDAP_DEBUG_ANY,
624                         "daemon: TLS not supported (%s)\n",
625                         url, 0, 0 );
626 #endif
627                 ldap_free_urldesc( lud );
628                 return -1;
629         }
630
631         if(! lud->lud_port ) {
632                 lud->lud_port = LDAP_PORT;
633         }
634
635 #else
636         l.sl_is_tls = ldap_pvt_url_scheme2tls( lud->lud_scheme );
637
638         if(! lud->lud_port ) {
639                 lud->lud_port = l.sl_is_tls ? LDAPS_PORT : LDAP_PORT;
640         }
641 #endif
642
643         port = (unsigned short) lud->lud_port;
644
645         tmp = ldap_pvt_url_scheme2proto(lud->lud_scheme);
646         if ( tmp == LDAP_PROTO_IPC ) {
647 #ifdef LDAP_PF_LOCAL
648                 if ( lud->lud_host == NULL || lud->lud_host[0] == '\0' ) {
649                         err = slap_get_listener_addresses(LDAPI_SOCK, 0, &sal);
650                 } else {
651                         err = slap_get_listener_addresses(lud->lud_host, 0, &sal);
652                 }
653 #else
654
655 #ifdef NEW_LOGGING
656                 LDAP_LOG( CONNECTION, INFO, 
657                         "slap_open_listener: URL scheme is not supported: %s\n", url, 0, 0 );
658 #else
659                 Debug( LDAP_DEBUG_ANY, "daemon: URL scheme not supported: %s",
660                         url, 0, 0);
661 #endif
662                 ldap_free_urldesc( lud );
663                 return -1;
664 #endif
665         } else {
666                 if( lud->lud_host == NULL || lud->lud_host[0] == '\0'
667                         || strcmp(lud->lud_host, "*") == 0 )
668                 {
669                         err = slap_get_listener_addresses(NULL, port, &sal);
670                 } else {
671                         err = slap_get_listener_addresses(lud->lud_host, port, &sal);
672                 }
673         }
674 #ifdef LDAP_CONNECTIONLESS
675         l.sl_is_udp = ( tmp == LDAP_PROTO_UDP );
676 #endif
677
678 #if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
679         if ( lud->lud_exts ) {
680                 err = get_url_perms( lud->lud_exts, &l.sl_perms, &crit );
681         } else {
682                 l.sl_perms = S_IRWXU | S_IRWXO;
683         }
684 #endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
685
686         ldap_free_urldesc( lud );
687         if ( err ) {
688                 return -1;
689         }
690
691         /* If we got more than one address returned, we need to make space
692          * for it in the slap_listeners array.
693          */
694         for ( num=0; sal[num]; num++ );
695         if ( num > 1 ) {
696                 *listeners += num-1;
697                 slap_listeners = ch_realloc( slap_listeners, (*listeners + 1) * sizeof(Listener *) );
698         }
699
700         psal = sal;
701         while ( *sal != NULL ) {
702                 switch( (*sal)->sa_family ) {
703                 case AF_INET:
704 #ifdef LDAP_PF_INET6
705                 case AF_INET6:
706 #endif
707 #ifdef LDAP_PF_LOCAL
708                 case AF_LOCAL:
709 #endif
710                         break;
711                 default:
712                         sal++;
713                         continue;
714                 }
715 #ifdef LDAP_CONNECTIONLESS
716                 if( l.sl_is_udp ) socktype = SOCK_DGRAM;
717 #endif
718                 l.sl_sd = socket( (*sal)->sa_family, socktype, 0);
719                 if ( l.sl_sd == AC_SOCKET_INVALID ) {
720                         int err = sock_errno();
721 #ifdef NEW_LOGGING
722                         LDAP_LOG( CONNECTION, ERR, 
723                                 "slap_open_listener: socket() failed errno=%d (%s)\n",
724                                 err, sock_errstr(err), 0 );
725 #else
726                         Debug( LDAP_DEBUG_ANY,
727                                 "daemon: socket() failed errno=%d (%s)\n", err,
728                                 sock_errstr(err), 0 );
729 #endif
730                         sal++;
731                         continue;
732                 }
733 #ifndef HAVE_WINSOCK
734                 if ( l.sl_sd >= dtblsize ) {
735 #ifdef NEW_LOGGING
736                         LDAP_LOG( CONNECTION, ERR, 
737                                 "slap_open_listener: listener descriptor %ld is too "
738                                 "great %ld\n", (long)l.sl_sd, (long)dtblsize, 0 );
739 #else
740                         Debug( LDAP_DEBUG_ANY,
741                                "daemon: listener descriptor %ld is too great %ld\n",
742                                (long) l.sl_sd, (long) dtblsize, 0 );
743 #endif
744                         tcp_close( l.sl_sd );
745                         sal++;
746                         continue;
747                 }
748 #endif
749 #ifdef LDAP_PF_LOCAL
750                 if ( (*sal)->sa_family == AF_LOCAL ) {
751                         unlink ( ((struct sockaddr_un *)*sal)->sun_path );
752                 } else
753 #endif
754                 {
755 #ifdef SO_REUSEADDR
756                         /* enable address reuse */
757                         tmp = 1;
758                         rc = setsockopt( l.sl_sd, SOL_SOCKET, SO_REUSEADDR,
759                                          (char *) &tmp, sizeof(tmp) );
760                         if ( rc == AC_SOCKET_ERROR ) {
761                                 int err = sock_errno();
762 #ifdef NEW_LOGGING
763                                 LDAP_LOG( CONNECTION, INFO, 
764                                         "slap_open_listener: setsockopt( %ld, SO_REUSEADDR ) "
765                                         "failed errno %d (%s)\n", (long)l.sl_sd, err, 
766                                         sock_errstr(err) );
767 #else
768                                 Debug( LDAP_DEBUG_ANY,
769                                        "slapd(%ld): setsockopt(SO_REUSEADDR) failed errno=%d (%s)\n",
770                                        (long) l.sl_sd, err, sock_errstr(err) );
771 #endif
772                         }
773 #endif
774                 }
775
776                 switch( (*sal)->sa_family ) {
777                 case AF_INET:
778                         addrlen = sizeof(struct sockaddr_in);
779                         break;
780 #ifdef LDAP_PF_INET6
781                 case AF_INET6:
782 #ifdef IPV6_V6ONLY
783                         /* Try to use IPv6 sockets for IPv6 only */
784                         tmp = 1;
785                         rc = setsockopt( l.sl_sd, IPPROTO_IPV6, IPV6_V6ONLY,
786                                          (char *) &tmp, sizeof(tmp) );
787                         if ( rc == AC_SOCKET_ERROR ) {
788                                 int err = sock_errno();
789 #ifdef NEW_LOGGING
790                                 LDAP_LOG( CONNECTION, INFO,
791                                            "slap_open_listener: setsockopt( %ld, IPV6_V6ONLY ) failed errno %d (%s)\n",
792                                            (long)l.sl_sd, err, sock_errstr(err) );
793 #else
794                                 Debug( LDAP_DEBUG_ANY,
795                                        "slapd(%ld): setsockopt(IPV6_V6ONLY) failed errno=%d (%s)\n",
796                                        (long) l.sl_sd, err, sock_errstr(err) );
797 #endif
798                         }
799 #endif
800                         addrlen = sizeof(struct sockaddr_in6);
801                         break;
802 #endif
803 #ifdef LDAP_PF_LOCAL
804                 case AF_LOCAL:
805                         addrlen = sizeof(struct sockaddr_un);
806                         break;
807 #endif
808                 }
809
810                 if (bind(l.sl_sd, *sal, addrlen)) {
811                         err = sock_errno();
812 #ifdef NEW_LOGGING
813                 LDAP_LOG( CONNECTION, INFO, 
814                         "slap_open_listener: bind(%ld) failed errno=%d (%s)\n",
815                         (long)l.sl_sd, err, sock_errstr(err) );
816 #else
817                 Debug( LDAP_DEBUG_ANY, "daemon: bind(%ld) failed errno=%d (%s)\n",
818                        (long) l.sl_sd, err, sock_errstr(err) );
819 #endif
820                         tcp_close( l.sl_sd );
821                         sal++;
822                         continue;
823                 }
824
825         switch ( (*sal)->sa_family ) {
826 #ifdef LDAP_PF_LOCAL
827         case AF_LOCAL: {
828                 char *addr = ((struct sockaddr_un *)*sal)->sun_path;
829 #if 0 /* don't muck with socket perms */
830                 if ( chmod( addr, l.sl_perms ) < 0 && crit ) {
831                         int err = sock_errno();
832 #ifdef NEW_LOGGING
833                         LDAP_LOG( CONNECTION, INFO, 
834                                 "slap_open_listener: fchmod(%ld) failed errno=%d (%s)\n",
835                                 (long)l.sl_sd, err, sock_errstr(err) );
836 #else
837                         Debug( LDAP_DEBUG_ANY, "daemon: fchmod(%ld) failed errno=%d (%s)",
838                                (long) l.sl_sd, err, sock_errstr(err) );
839 #endif
840                         tcp_close( l.sl_sd );
841                         slap_free_listener_addresses(psal);
842                         return -1;
843                 }
844 #endif
845                 l.sl_name.bv_len = strlen(addr) + sizeof("PATH=") - 1;
846                 l.sl_name.bv_val = ber_memalloc( l.sl_name.bv_len + 1 );
847                 snprintf( l.sl_name.bv_val, l.sl_name.bv_len + 1, 
848                                 "PATH=%s", addr );
849         } break;
850 #endif /* LDAP_PF_LOCAL */
851
852         case AF_INET: {
853                 char *s;
854 #if defined( HAVE_GETADDRINFO ) && defined( HAVE_INET_NTOP )
855                 char addr[INET_ADDRSTRLEN];
856                 inet_ntop( AF_INET, &((struct sockaddr_in *)*sal)->sin_addr,
857                            addr, sizeof(addr) );
858                 s = addr;
859 #else
860                 s = inet_ntoa( ((struct sockaddr_in *) *sal)->sin_addr );
861 #endif
862                 port = ntohs( ((struct sockaddr_in *)*sal) ->sin_port );
863                 l.sl_name.bv_val = ber_memalloc( sizeof("IP=255.255.255.255:65535") );
864                 snprintf( l.sl_name.bv_val, sizeof("IP=255.255.255.255:65535"),
865                         "IP=%s:%d",
866                          s != NULL ? s : SLAP_STRING_UNKNOWN, port );
867                 l.sl_name.bv_len = strlen( l.sl_name.bv_val );
868         } break;
869
870 #ifdef LDAP_PF_INET6
871         case AF_INET6: {
872                 char addr[INET6_ADDRSTRLEN];
873                 inet_ntop( AF_INET6, &((struct sockaddr_in6 *)*sal)->sin6_addr,
874                            addr, sizeof addr);
875                 port = ntohs( ((struct sockaddr_in6 *)*sal)->sin6_port );
876                 l.sl_name.bv_len = strlen(addr) + sizeof("IP= 65535");
877                 l.sl_name.bv_val = ber_memalloc( l.sl_name.bv_len );
878                 snprintf( l.sl_name.bv_val, l.sl_name.bv_len, "IP=%s %d", 
879                                 addr, port );
880                 l.sl_name.bv_len = strlen( l.sl_name.bv_val );
881         } break;
882 #endif /* LDAP_PF_INET6 */
883
884         default:
885 #ifdef NEW_LOGGING
886                 LDAP_LOG( CONNECTION, INFO, 
887                         "slap_open_listener: unsupported address family (%d)\n",
888                         (int)(*sal)->sa_family, 0, 0 );
889 #else
890                 Debug( LDAP_DEBUG_ANY, "daemon: unsupported address family (%d)\n",
891                         (int) (*sal)->sa_family, 0, 0 );
892 #endif
893                 break;
894         }
895
896         AC_MEMCPY(&l.sl_sa, *sal, addrlen);
897         ber_str2bv( url, 0, 1, &l.sl_url);
898         li = ch_malloc( sizeof( Listener ) );
899         *li = l;
900         slap_listeners[*cur] = li;
901         (*cur)++;
902         sal++;
903
904         } /* while ( *sal != NULL ) */
905
906         slap_free_listener_addresses(psal);
907
908         if ( l.sl_url.bv_val == NULL )
909         {
910 #ifdef NEW_LOGGING
911                 LDAP_LOG( CONNECTION, RESULTS, 
912                         "slap_open_listener: failed on %s\n", url, 0, 0 );
913 #else
914                 Debug( LDAP_DEBUG_TRACE,
915                         "slap_open_listener: failed on %s\n", url, 0, 0 );
916 #endif
917                 return -1;
918         }
919
920 #ifdef NEW_LOGGING
921         LDAP_LOG( CONNECTION, RESULTS, 
922                 "slap_open_listener: daemon initialized %s\n",
923                 l.sl_url.bv_val, 0, 0 );
924 #else
925         Debug( LDAP_DEBUG_TRACE, "daemon: initialized %s\n",
926                 l.sl_url.bv_val, 0, 0 );
927 #endif
928         return 0;
929 }
930
931 static int sockinit(void);
932 static int sockdestroy(void);
933
934 int slapd_daemon_init( const char *urls )
935 {
936         int i, j, n, rc;
937         char **u;
938
939 #ifdef NEW_LOGGING
940         LDAP_LOG( CONNECTION, ARGS, 
941                 "slapd_daemon_init: %s\n", urls ? urls : "<null>", 0, 0 );
942 #else
943         Debug( LDAP_DEBUG_ARGS, "daemon_init: %s\n",
944                 urls ? urls : "<null>", 0, 0 );
945 #endif
946         if( (rc = sockinit()) != 0 ) {
947                 return rc;
948         }
949
950 #ifdef HAVE_SYSCONF
951         dtblsize = sysconf( _SC_OPEN_MAX );
952 #elif HAVE_GETDTABLESIZE
953         dtblsize = getdtablesize();
954 #else
955         dtblsize = FD_SETSIZE;
956 #endif
957
958 #ifdef FD_SETSIZE
959         if(dtblsize > FD_SETSIZE) {
960                 dtblsize = FD_SETSIZE;
961         }
962 #endif  /* !FD_SETSIZE */
963
964         /* open a pipe (or something equivalent connected to itself).
965          * we write a byte on this fd whenever we catch a signal. The main
966          * loop will be select'ing on this socket, and will wake up when
967          * this byte arrives.
968          */
969         if( (rc = lutil_pair( wake_sds )) < 0 ) {
970 #ifdef NEW_LOGGING
971                 LDAP_LOG( CONNECTION, ERR, 
972                         "slap_daemon_init: lutil_pair() failed rc=%d\n", rc, 0, 0);
973 #else
974                 Debug( LDAP_DEBUG_ANY,
975                         "daemon: lutil_pair() failed rc=%d\n", rc, 0, 0 );
976 #endif
977                 return rc;
978         }
979
980         FD_ZERO( &slap_daemon.sd_readers );
981         FD_ZERO( &slap_daemon.sd_writers );
982
983         if( urls == NULL ) {
984                 urls = "ldap:///";
985         }
986
987         u = ldap_str2charray( urls, " " );
988
989         if( u == NULL || u[0] == NULL ) {
990 #ifdef NEW_LOGGING
991                 LDAP_LOG( CONNECTION, ERR, 
992                         "slap_daemon_init: no urls (%s) provided.\n", urls, 0, 0 );
993 #else
994                 Debug( LDAP_DEBUG_ANY, "daemon_init: no urls (%s) provided.\n",
995                         urls, 0, 0 );
996 #endif
997                 return -1;
998         }
999
1000         for( i=0; u[i] != NULL; i++ ) {
1001 #ifdef NEW_LOGGING
1002                 LDAP_LOG( CONNECTION, DETAIL1, 
1003                         "slap_daemon_init: listen on %s\n.", u[i], 0, 0 );
1004 #else
1005                 Debug( LDAP_DEBUG_TRACE, "daemon_init: listen on %s\n",
1006                         u[i], 0, 0 );
1007 #endif
1008         }
1009
1010         if( i == 0 ) {
1011 #ifdef NEW_LOGGING
1012                 LDAP_LOG( CONNECTION, INFO, 
1013                          "slap_daemon_init: no listeners to open (%s)\n", urls, 0, 0 );
1014 #else
1015                 Debug( LDAP_DEBUG_ANY, "daemon_init: no listeners to open (%s)\n",
1016                         urls, 0, 0 );
1017 #endif
1018                 ldap_charray_free( u );
1019                 return -1;
1020         }
1021
1022 #ifdef NEW_LOGGING
1023         LDAP_LOG( CONNECTION, INFO, 
1024                 "slap_daemon_init: %d listeners to open...\n", i, 0, 0 );
1025 #else
1026         Debug( LDAP_DEBUG_TRACE, "daemon_init: %d listeners to open...\n",
1027                 i, 0, 0 );
1028 #endif
1029         slap_listeners = ch_malloc( (i+1)*sizeof(Listener *) );
1030
1031         for(n = 0, j = 0; u[n]; n++ ) {
1032                 if ( slap_open_listener( u[n], &i, &j ) ) {
1033                         ldap_charray_free( u );
1034                         return -1;
1035                 }
1036         }
1037         slap_listeners[j] = NULL;
1038
1039 #ifdef NEW_LOGGING
1040         LDAP_LOG( CONNECTION, DETAIL1, 
1041                 "slap_daemon_init: %d listeners opened\n", i, 0, 0 );
1042 #else
1043         Debug( LDAP_DEBUG_TRACE, "daemon_init: %d listeners opened\n",
1044                 i, 0, 0 );
1045 #endif
1046
1047 #ifdef HAVE_SLP
1048         slapd_slp_init( urls );
1049         slapd_slp_reg();
1050 #endif
1051
1052         ldap_charray_free( u );
1053         ldap_pvt_thread_mutex_init( &slap_daemon.sd_mutex );
1054         return !i;
1055 }
1056
1057
1058 int
1059 slapd_daemon_destroy(void)
1060 {
1061         connections_destroy();
1062         tcp_close( wake_sds[1] );
1063         tcp_close( wake_sds[0] );
1064         sockdestroy();
1065
1066 #ifdef HAVE_SLP
1067         slapd_slp_dereg();
1068         slapd_slp_deinit();
1069 #endif
1070
1071         return 0;
1072 }
1073
1074
1075 static void
1076 close_listeners(
1077         int remove
1078 )
1079 {
1080         int l;
1081
1082         for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1083                 if ( slap_listeners[l]->sl_sd != AC_SOCKET_INVALID ) {
1084                         if ( remove )
1085                                 slapd_remove( slap_listeners[l]->sl_sd, 0 );
1086 #ifdef LDAP_PF_LOCAL
1087                         if ( slap_listeners[l]->sl_sa.sa_addr.sa_family == AF_LOCAL ) {
1088                                 unlink( slap_listeners[l]->sl_sa.sa_un_addr.sun_path );
1089                         }
1090 #endif /* LDAP_PF_LOCAL */
1091                         slapd_close( slap_listeners[l]->sl_sd );
1092                 }
1093                 if ( slap_listeners[l]->sl_url.bv_val )
1094                         ber_memfree( slap_listeners[l]->sl_url.bv_val );
1095                 if ( slap_listeners[l]->sl_name.bv_val )
1096                         ber_memfree( slap_listeners[l]->sl_name.bv_val );
1097                 free ( slap_listeners[l] );
1098                 slap_listeners[l] = NULL;
1099         }
1100 }
1101
1102
1103 static void *
1104 slapd_daemon_task(
1105         void *ptr
1106 )
1107 {
1108         int l;
1109         time_t  last_idle_check = 0;
1110         time( &starttime );
1111
1112         if ( global_idletimeout > 0 ) {
1113                 last_idle_check = slap_get_time();
1114         }
1115         for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1116                 if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1117                         continue;
1118 #ifdef LDAP_CONNECTIONLESS
1119                 /* Since this is connectionless, the data port is the
1120                  * listening port. The listen() and accept() calls
1121                  * are unnecessary.
1122                  */
1123                 if ( slap_listeners[l]->sl_is_udp ) {
1124                         slapd_add( slap_listeners[l]->sl_sd );
1125                         continue;
1126                 }
1127 #endif
1128
1129                 if ( listen( slap_listeners[l]->sl_sd, SLAPD_LISTEN ) == -1 ) {
1130                         int err = sock_errno();
1131
1132 #ifdef LDAP_PF_INET6
1133                         /* If error is EADDRINUSE, we are trying to listen to INADDR_ANY and
1134                          * we are already listening to in6addr_any, then we want to ignore
1135                          * this and continue.
1136                          */
1137                         if ( err == EADDRINUSE ) {
1138                                 int i;
1139                                 struct sockaddr_in sa = slap_listeners[l]->sl_sa.sa_in_addr;
1140                                 struct sockaddr_in6 sa6;
1141                                 
1142                                 if ( sa.sin_family == AF_INET &&
1143                                      sa.sin_addr.s_addr == htonl(INADDR_ANY) ) {
1144                                         for ( i = 0 ; i < l; i++ ) {
1145                                                 sa6 = slap_listeners[i]->sl_sa.sa_in6_addr;
1146                                                 if ( sa6.sin6_family == AF_INET6 &&
1147                                                      !memcmp( &sa6.sin6_addr, &in6addr_any, sizeof(struct in6_addr) ) )
1148                                                         break;
1149                                         }
1150
1151                                         if ( i < l ) {
1152                                                 /* We are already listening to in6addr_any */
1153 #ifdef NEW_LOGGING
1154                                                 LDAP_LOG(CONNECTION, WARNING,
1155                                                            "slapd_daemon_task: Attempt to listen to 0.0.0.0 failed, already listening on ::, assuming IPv4 included\n", 0, 0, 0 );
1156 #else
1157                                                 Debug( LDAP_DEBUG_CONNS,
1158                                                        "daemon: Attempt to listen to 0.0.0.0 failed, already listening on ::, assuming IPv4 included\n",
1159                                                        0, 0, 0 );
1160 #endif
1161                                                 slapd_close( slap_listeners[l]->sl_sd );
1162                                                 slap_listeners[l]->sl_sd = AC_SOCKET_INVALID;
1163                                                 continue;
1164                                         }
1165                                 }
1166                         }
1167 #endif                          
1168 #ifdef NEW_LOGGING
1169                         LDAP_LOG( CONNECTION, ERR, 
1170                                 "slapd_daemon_task: listen( %s, 5 ) failed errno=%d (%s)\n",
1171                                 slap_listeners[l]->sl_url.bv_val, err, sock_errstr(err) );
1172 #else
1173                         Debug( LDAP_DEBUG_ANY,
1174                                 "daemon: listen(%s, 5) failed errno=%d (%s)\n",
1175                                         slap_listeners[l]->sl_url.bv_val, err,
1176                                         sock_errstr(err) );
1177 #endif
1178                         return( (void*)-1 );
1179                 }
1180
1181                 slapd_add( slap_listeners[l]->sl_sd );
1182         }
1183
1184 #ifdef HAVE_NT_SERVICE_MANAGER
1185         if ( started_event != NULL ) {
1186                 ldap_pvt_thread_cond_signal( &started_event );
1187         }
1188 #endif
1189         /* initialization complete. Here comes the loop. */
1190
1191         while ( !slapd_shutdown ) {
1192                 ber_socket_t i;
1193                 int ns;
1194                 int at;
1195                 ber_socket_t nfds;
1196 #define SLAPD_EBADF_LIMIT 16
1197                 int ebadf = 0;
1198                 int emfile = 0;
1199
1200 #define SLAPD_IDLE_CHECK_LIMIT 4
1201                 time_t  now;
1202
1203
1204                 fd_set                  readfds;
1205                 fd_set                  writefds;
1206                 Sockaddr                from;
1207
1208                 struct timeval          zero;
1209                 struct timeval          *tvp;
1210
1211                 if( emfile ) {
1212                         now = slap_get_time();
1213                         connections_timeout_idle( now );
1214                 }
1215                 else if ( global_idletimeout > 0 ) {
1216                         now = slap_get_time();
1217                         if ( difftime( last_idle_check+global_idletimeout/SLAPD_IDLE_CHECK_LIMIT, now ) < 0 ) {
1218                                 connections_timeout_idle( now );
1219                         }
1220                 }
1221
1222 #ifdef SIGHUP
1223                 if( slapd_gentle_shutdown ) {
1224                         ber_socket_t active;
1225
1226                         if( slapd_gentle_shutdown == 1 ) {
1227                                 Debug( LDAP_DEBUG_ANY, "slapd gentle shutdown\n", 0, 0, 0 );
1228                                 close_listeners( 1 );
1229                                 global_restrictops |= SLAP_RESTRICT_OP_WRITES;
1230                                 slapd_gentle_shutdown = 2;
1231                         }
1232
1233                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1234                         active = slap_daemon.sd_nactives;
1235                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1236                         if( active == 0 ) {
1237                                 slapd_shutdown = 2;
1238                                 break;
1239                         }
1240                 }
1241 #endif
1242
1243                 FD_ZERO( &writefds );
1244                 FD_ZERO( &readfds );
1245
1246                 zero.tv_sec = 0;
1247                 zero.tv_usec = 0;
1248
1249                 ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1250
1251 #ifdef FD_SET_MANUAL_COPY
1252                 for( s = 0; s < nfds; s++ ) {
1253                         if(FD_ISSET( &slap_sd_readers, s )) {
1254                                 FD_SET( s, &readfds );
1255                         }
1256                         if(FD_ISSET( &slap_sd_writers, s )) {
1257                                 FD_SET( s, &writefds );
1258                         }
1259                 }
1260 #else
1261                 AC_MEMCPY( &readfds, &slap_daemon.sd_readers, sizeof(fd_set) );
1262                 AC_MEMCPY( &writefds, &slap_daemon.sd_writers, sizeof(fd_set) );
1263 #endif
1264                 assert(!FD_ISSET(wake_sds[0], &readfds));
1265                 FD_SET( wake_sds[0], &readfds );
1266
1267                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1268                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1269                                 continue;
1270                         if (!FD_ISSET(slap_listeners[l]->sl_sd, &readfds))
1271                             FD_SET( slap_listeners[l]->sl_sd, &readfds );
1272                 }
1273
1274 #ifndef HAVE_WINSOCK
1275                 nfds = slap_daemon.sd_nfds;
1276 #else
1277                 nfds = dtblsize;
1278 #endif
1279
1280                 ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1281
1282                 at = ldap_pvt_thread_pool_backload(&connection_pool);
1283
1284 #if defined( HAVE_YIELDING_SELECT ) || defined( NO_THREADS )
1285                 tvp = NULL;
1286 #else
1287                 tvp = at ? &zero : NULL;
1288 #endif
1289
1290                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1291                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1292                                 continue;
1293
1294 #ifdef NEW_LOGGING
1295                         LDAP_LOG( CONNECTION, DETAIL1, 
1296                                 "slapd_daemon_task: select: listen=%d "
1297                                 "active_threads=%d tvp=%s\n",
1298                                 slap_listeners[l]->sl_sd, at, tvp == NULL ? "NULL" : "zero" );
1299 #else
1300                         Debug( LDAP_DEBUG_CONNS,
1301                                 "daemon: select: listen=%d active_threads=%d tvp=%s\n",
1302                                         slap_listeners[l]->sl_sd, at,
1303                                         tvp == NULL ? "NULL" : "zero" );
1304 #endif
1305                 }
1306
1307                 switch(ns = select( nfds, &readfds,
1308 #ifdef HAVE_WINSOCK
1309                         /* don't pass empty fd_set */
1310                         ( writefds.fd_count > 0 ? &writefds : NULL ),
1311 #else
1312                         &writefds,
1313 #endif
1314                         NULL, tvp ))
1315                 {
1316                 case -1: {      /* failure - try again */
1317                                 int err = sock_errno();
1318
1319                                 if( err == EBADF
1320 #ifdef WSAENOTSOCK
1321                                         /* you'd think this would be EBADF */
1322                                         || err == WSAENOTSOCK
1323 #endif
1324                                 ) {
1325                                         if (++ebadf < SLAPD_EBADF_LIMIT)
1326                                                 continue;
1327                                 }
1328
1329                                 if( err != EINTR ) {
1330 #ifdef NEW_LOGGING
1331                                         LDAP_LOG( CONNECTION, INFO, 
1332                                                 "slapd_daemon_task: select failed (%d): %s\n",
1333                                                 err, sock_errstr(err), 0 );
1334 #else
1335                                         Debug( LDAP_DEBUG_CONNS,
1336                                                 "daemon: select failed (%d): %s\n",
1337                                                 err, sock_errstr(err), 0 );
1338 #endif
1339                                         slapd_shutdown = 2;
1340                                 }
1341                         }
1342                         continue;
1343
1344                 case 0:         /* timeout - let threads run */
1345                         ebadf = 0;
1346 #ifdef NEW_LOGGING
1347                         LDAP_LOG( CONNECTION, DETAIL2,
1348                                    "slapd_daemon_task: select timeout - yielding\n", 0, 0, 0 );
1349 #else
1350                         Debug( LDAP_DEBUG_CONNS, "daemon: select timeout - yielding\n",
1351                             0, 0, 0 );
1352 #endif
1353                         ldap_pvt_thread_yield();
1354                         continue;
1355
1356                 default:        /* something happened - deal with it */
1357                         if( slapd_shutdown ) continue;
1358
1359                         ebadf = 0;
1360 #ifdef NEW_LOGGING
1361                         LDAP_LOG( CONNECTION, DETAIL2, 
1362                                    "slapd_daemon_task: activity on %d descriptors\n", ns, 0, 0 );
1363 #else
1364                         Debug( LDAP_DEBUG_CONNS, "daemon: activity on %d descriptors\n",
1365                                 ns, 0, 0 );
1366 #endif
1367                         /* FALL THRU */
1368                 }
1369
1370                 if( FD_ISSET( wake_sds[0], &readfds ) ) {
1371                         char c[BUFSIZ];
1372                         tcp_read( wake_sds[0], c, sizeof(c) );
1373 #if defined(NO_THREADS) || defined(HAVE_GNU_PTH)
1374                         waking = 0;
1375 #endif
1376                         continue;
1377                 }
1378
1379                 for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1380                         ber_socket_t s;
1381                         socklen_t len = sizeof(from);
1382                         long id;
1383                         slap_ssf_t ssf = 0;
1384                         char *authid = NULL;
1385 #ifdef SLAPD_RLOOKUPS
1386                         char hbuf[NI_MAXHOST];
1387 #endif
1388
1389                         char    *dnsname = NULL;
1390                         char    *peeraddr = NULL;
1391 #ifdef LDAP_PF_LOCAL
1392                         char    peername[MAXPATHLEN + sizeof("PATH=")];
1393 #elif defined(LDAP_PF_INET6)
1394                         char    peername[sizeof("IP=ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff 65535")];
1395 #else
1396                         char    peername[sizeof("IP=255.255.255.255:65336")];
1397 #endif /* LDAP_PF_LOCAL */
1398
1399                         peername[0] = '\0';
1400
1401                         if ( slap_listeners[l]->sl_sd == AC_SOCKET_INVALID )
1402                                 continue;
1403
1404                         if ( !FD_ISSET( slap_listeners[l]->sl_sd, &readfds ) )
1405                                 continue;
1406
1407 #ifdef LDAP_CONNECTIONLESS
1408                         if ( slap_listeners[l]->sl_is_udp ) {
1409                                 /* The first time we receive a query, we set this
1410                                  * up as a "connection". It remains open for the life
1411                                  * of the slapd.
1412                                  */
1413                                 if ( slap_listeners[l]->sl_is_udp < 2 ) {
1414                                     id = connection_init(
1415                                         slap_listeners[l]->sl_sd,
1416                                         slap_listeners[l], "", "",
1417                                         2, ssf, authid );
1418                                     slap_listeners[l]->sl_is_udp++;
1419                                 }
1420                                 continue;
1421                         }
1422 #endif
1423
1424                         s = accept( slap_listeners[l]->sl_sd,
1425                                 (struct sockaddr *) &from, &len );
1426                         if ( s == AC_SOCKET_INVALID ) {
1427                                 int err = sock_errno();
1428
1429 #ifdef EMFILE
1430                                 if( err == EMFILE ) {
1431                                         emfile++;
1432                                 } else
1433 #endif
1434 #ifdef ENFILE
1435                                 if( err == ENFILE ) {
1436                                         emfile++;
1437                                 } else 
1438 #endif
1439                                 {
1440                                         emfile=0;
1441                                 }
1442
1443                                 if( emfile < 3 ) {
1444 #ifdef NEW_LOGGING
1445                                         LDAP_LOG( CONNECTION, ERR, 
1446                                                 "slapd_daemon_task: accept(%ld) failed errno=%d (%s)\n",
1447                                                 (long)slap_listeners[l]->sl_sd, 
1448                                                 err, sock_errstr(err) );
1449 #else
1450                                         Debug( LDAP_DEBUG_ANY,
1451                                             "daemon: accept(%ld) failed errno=%d (%s)\n",
1452                                             (long) slap_listeners[l]->sl_sd, err,
1453                                             sock_errstr(err) );
1454 #endif
1455                                 } else {
1456                                         /* prevent busy loop */
1457 #  ifdef HAVE_USLEEP
1458                                         if( emfile % 4 == 3 ) usleep( 250 );
1459 #  else
1460                                         if( emfile % 8 == 7 ) sleep( 1 );
1461 #  endif
1462                                 }
1463
1464                                 ldap_pvt_thread_yield();
1465                                 continue;
1466                         }
1467                         emfile = 0;
1468
1469 #ifndef HAVE_WINSOCK
1470                         /* make sure descriptor number isn't too great */
1471                         if ( s >= dtblsize ) {
1472 #ifdef NEW_LOGGING
1473                                 LDAP_LOG( CONNECTION, ERR, 
1474                                    "slapd_daemon_task: %ld beyond descriptor table size %ld\n",
1475                                    (long)s, (long)dtblsize, 0 );
1476 #else
1477                                 Debug( LDAP_DEBUG_ANY,
1478                                         "daemon: %ld beyond descriptor table size %ld\n",
1479                                         (long) s, (long) dtblsize, 0 );
1480 #endif
1481
1482                                 slapd_close(s);
1483                                 ldap_pvt_thread_yield();
1484                                 continue;
1485                         }
1486 #endif
1487
1488 #ifdef LDAP_DEBUG
1489                         ldap_pvt_thread_mutex_lock( &slap_daemon.sd_mutex );
1490
1491                         /* newly accepted stream should not be in any of the FD SETS */
1492                         assert( !FD_ISSET( s, &slap_daemon.sd_actives) );
1493                         assert( !FD_ISSET( s, &slap_daemon.sd_readers) );
1494                         assert( !FD_ISSET( s, &slap_daemon.sd_writers) );
1495
1496                         ldap_pvt_thread_mutex_unlock( &slap_daemon.sd_mutex );
1497 #endif
1498
1499 #if defined( SO_KEEPALIVE ) || defined( TCP_NODELAY )
1500 #ifdef LDAP_PF_LOCAL
1501                         /* for IPv4 and IPv6 sockets only */
1502                         if ( from.sa_addr.sa_family != AF_LOCAL )
1503 #endif /* LDAP_PF_LOCAL */
1504                         {
1505                                 int rc;
1506                                 int tmp;
1507 #ifdef SO_KEEPALIVE
1508                                 /* enable keep alives */
1509                                 tmp = 1;
1510                                 rc = setsockopt( s, SOL_SOCKET, SO_KEEPALIVE,
1511                                         (char *) &tmp, sizeof(tmp) );
1512                                 if ( rc == AC_SOCKET_ERROR ) {
1513                                         int err = sock_errno();
1514 #ifdef NEW_LOGGING
1515                                         LDAP_LOG( CONNECTION, ERR, 
1516                                                 "slapd_daemon_task: setsockopt( %ld, SO_KEEPALIVE)"
1517                                            " failed errno=%d (%s)\n",
1518                                                 (long)s, err, sock_errstr(err) );
1519 #else
1520                                         Debug( LDAP_DEBUG_ANY,
1521                                                 "slapd(%ld): setsockopt(SO_KEEPALIVE) failed "
1522                                                 "errno=%d (%s)\n", (long) s, err, sock_errstr(err) );
1523 #endif
1524                                 }
1525 #endif
1526 #ifdef TCP_NODELAY
1527                                 /* enable no delay */
1528                                 tmp = 1;
1529                                 rc = setsockopt( s, IPPROTO_TCP, TCP_NODELAY,
1530                                         (char *)&tmp, sizeof(tmp) );
1531                                 if ( rc == AC_SOCKET_ERROR ) {
1532                                         int err = sock_errno();
1533 #ifdef NEW_LOGGING
1534                                         LDAP_LOG( CONNECTION, ERR, 
1535                                                 "slapd_daemon_task: setsockopt( %ld, "
1536                                                 "TCP_NODELAY) failed errno=%d (%s)\n",
1537                                                 (long)s, err, sock_errstr(err) );
1538 #else
1539                                         Debug( LDAP_DEBUG_ANY,
1540                                                 "slapd(%ld): setsockopt(TCP_NODELAY) failed "
1541                                                 "errno=%d (%s)\n", (long) s, err, sock_errstr(err) );
1542 #endif
1543                                 }
1544 #endif
1545                         }
1546 #endif
1547
1548 #ifdef NEW_LOGGING
1549                         LDAP_LOG( CONNECTION, DETAIL1, 
1550                                 "slapd_daemon_task: new connection on %ld\n", (long)s, 0, 0 );
1551 #else
1552                         Debug( LDAP_DEBUG_CONNS, "daemon: new connection on %ld\n",
1553                                 (long) s, 0, 0 );
1554 #endif
1555                         switch ( from.sa_addr.sa_family ) {
1556 #  ifdef LDAP_PF_LOCAL
1557                         case AF_LOCAL:
1558                                 sprintf( peername, "PATH=%s", from.sa_un_addr.sun_path );
1559                                 ssf = LDAP_PVT_SASL_LOCAL_SSF;
1560                                 {
1561                                         uid_t uid;
1562                                         gid_t gid;
1563
1564                                         if( getpeereid( s, &uid, &gid ) == 0 ) {
1565                                                 authid = ch_malloc(
1566                                                         sizeof("uidnumber=4294967295+gidnumber=4294967295,"
1567                                                                 "cn=peercred,cn=external,cn=auth"));
1568                                                 sprintf(authid, "uidnumber=%d+gidnumber=%d,"
1569                                                         "cn=peercred,cn=external,cn=auth",
1570                                                         (int) uid, (int) gid);
1571                                         }
1572                                 }
1573                                 dnsname = "local";
1574                                 break;
1575 #endif /* LDAP_PF_LOCAL */
1576
1577 #  ifdef LDAP_PF_INET6
1578                         case AF_INET6:
1579                         if ( IN6_IS_ADDR_V4MAPPED(&from.sa_in6_addr.sin6_addr) ) {
1580                                 peeraddr = inet_ntoa( *((struct in_addr *)
1581                                                         &from.sa_in6_addr.sin6_addr.s6_addr[12]) );
1582                                 sprintf( peername, "IP=%s:%d",
1583                                          peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1584                                          (unsigned) ntohs( from.sa_in6_addr.sin6_port ) );
1585                         } else {
1586                                 char addr[INET6_ADDRSTRLEN];
1587
1588                                 peeraddr = (char *) inet_ntop( AF_INET6,
1589                                                       &from.sa_in6_addr.sin6_addr,
1590                                                       addr, sizeof addr );
1591                                 sprintf( peername, "IP=%s %d",
1592                                          peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1593                                          (unsigned) ntohs( from.sa_in6_addr.sin6_port ) );
1594                         }
1595                         break;
1596 #  endif /* LDAP_PF_INET6 */
1597
1598                         case AF_INET:
1599                         peeraddr = inet_ntoa( from.sa_in_addr.sin_addr );
1600                         sprintf( peername, "IP=%s:%d",
1601                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1602                                 (unsigned) ntohs( from.sa_in_addr.sin_port ) );
1603                                 break;
1604
1605                         default:
1606                                 slapd_close(s);
1607                                 continue;
1608                         }
1609
1610                         if ( ( from.sa_addr.sa_family == AF_INET )
1611 #ifdef LDAP_PF_INET6
1612                                 || ( from.sa_addr.sa_family == AF_INET6 )
1613 #endif
1614                         ) {
1615 #ifdef SLAPD_RLOOKUPS
1616                                 if ( use_reverse_lookup ) {
1617                                         char *herr;
1618                                         if (ldap_pvt_get_hname( (const struct sockaddr *)&from, len, hbuf,
1619                                                 sizeof(hbuf), &herr ) == 0) {
1620                                                 ldap_pvt_str2lower( hbuf );
1621                                                 dnsname = hbuf;
1622                                         }
1623                                 }
1624 #else
1625                                 dnsname = NULL;
1626 #endif /* SLAPD_RLOOKUPS */
1627
1628 #ifdef HAVE_TCPD
1629                                 if ( !hosts_ctl("slapd",
1630                                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1631                                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1632                                                 SLAP_STRING_UNKNOWN ))
1633                                 {
1634                                         /* DENY ACCESS */
1635                                         Statslog( LDAP_DEBUG_STATS,
1636                                                 "fd=%ld DENIED from %s (%s)",
1637                                                 (long) s,
1638                                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1639                                                 peeraddr != NULL ? peeraddr : SLAP_STRING_UNKNOWN,
1640                                                 0, 0 );
1641                                         slapd_close(s);
1642                                         continue;
1643                                 }
1644 #endif /* HAVE_TCPD */
1645                         }
1646
1647                         id = connection_init(s,
1648                                 slap_listeners[l],
1649                                 dnsname != NULL ? dnsname : SLAP_STRING_UNKNOWN,
1650                                 peername,
1651 #ifdef HAVE_TLS
1652                                 slap_listeners[l]->sl_is_tls,
1653 #else
1654                                 0,
1655 #endif
1656                                 ssf,
1657                                 authid );
1658
1659                         if( authid ) ch_free(authid);
1660
1661                         if( id < 0 ) {
1662 #ifdef NEW_LOGGING
1663                                 LDAP_LOG( CONNECTION, INFO, 
1664                                         "slapd_daemon_task: "
1665                                         "connection_init(%ld, %s, %s) "
1666                                         "failed.\n",
1667                                         (long)s, peername, 
1668                                         slap_listeners[l]->sl_name.bv_val );
1669 #else
1670                                 Debug( LDAP_DEBUG_ANY,
1671                                         "daemon: connection_init(%ld, %s, %s) "
1672                                         "failed.\n",
1673                                         (long) s,
1674                                         peername,
1675                                         slap_listeners[l]->sl_name.bv_val );
1676 #endif
1677                                 slapd_close(s);
1678                                 continue;
1679                         }
1680
1681                         Statslog( LDAP_DEBUG_STATS,
1682                                 "conn=%ld fd=%ld ACCEPT from %s (%s)\n",
1683                                 id, (long) s,
1684                                 peername,
1685                                 slap_listeners[l]->sl_name.bv_val,
1686                                 0 );
1687
1688                         slapd_add( s );
1689                         continue;
1690                 }
1691
1692 #ifdef LDAP_DEBUG
1693 #ifdef NEW_LOGGING
1694                 LDAP_LOG( CONNECTION, DETAIL2,
1695                            "slapd_daemon_task: activity on ", 0, 0, 0 );
1696 #else
1697                 Debug( LDAP_DEBUG_CONNS, "daemon: activity on:", 0, 0, 0 );
1698 #endif
1699 #ifdef HAVE_WINSOCK
1700                 for ( i = 0; i < readfds.fd_count; i++ ) {
1701 #ifdef NEW_LOGGING
1702                         LDAP_LOG( CONNECTION, DETAIL2, 
1703                                 " %d%s", readfds.fd_array[i], "r", 0, 0 );
1704 #else
1705                         Debug( LDAP_DEBUG_CONNS, " %d%s",
1706                                 readfds.fd_array[i], "r", 0 );
1707 #endif
1708                 }
1709                 for ( i = 0; i < writefds.fd_count; i++ ) {
1710 #ifdef NEW_LOGGING
1711                         LDAP_LOG( CONNECTION, DETAIL2, 
1712                                 " %d%s", writefds.fd_array[i], "w" , 0 );
1713 #else
1714                         Debug( LDAP_DEBUG_CONNS, " %d%s",
1715                                 writefds.fd_array[i], "w", 0 );
1716 #endif
1717                 }
1718
1719 #else
1720                 for ( i = 0; i < nfds; i++ ) {
1721                         int     r, w;
1722                         int     is_listener = 0;
1723
1724                         for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1725                                 if ( i == slap_listeners[l]->sl_sd ) {
1726 #ifdef LDAP_CONNECTIONLESS
1727                                 /* The listener is the data port. Don't
1728                                  * skip it.
1729                                  */
1730                                         if (slap_listeners[l]->sl_is_udp) continue;
1731 #endif
1732                                         is_listener = 1;
1733                                         break;
1734                                 }
1735                         }
1736                         if ( is_listener ) {
1737                                 continue;
1738                         }
1739                         r = FD_ISSET( i, &readfds );
1740                         w = FD_ISSET( i, &writefds );
1741                         if ( r || w ) {
1742 #ifdef NEW_LOGGING
1743                                 LDAP_LOG( CONNECTION, DETAIL2, 
1744                                         " %d%s%s", i, r ? "r" : "", w ? "w" : "" );
1745 #else
1746                                 Debug( LDAP_DEBUG_CONNS, " %d%s%s", i,
1747                                     r ? "r" : "", w ? "w" : "" );
1748 #endif
1749                         }
1750                 }
1751 #endif
1752 #ifdef NEW_LOGGING
1753                 LDAP_LOG( CONNECTION, DETAIL2, "\n", 0, 0, 0 );
1754 #else
1755                 Debug( LDAP_DEBUG_CONNS, "\n", 0, 0, 0 );
1756 #endif
1757
1758 #endif
1759
1760                 /* loop through the writers */
1761 #ifdef HAVE_WINSOCK
1762                 for ( i = 0; i < writefds.fd_count; i++ )
1763 #else
1764                 for ( i = 0; i < nfds; i++ )
1765 #endif
1766                 {
1767                         ber_socket_t wd;
1768                         int is_listener = 0;
1769 #ifdef HAVE_WINSOCK
1770                         wd = writefds.fd_array[i];
1771 #else
1772                         if( ! FD_ISSET( i, &writefds ) ) {
1773                                 continue;
1774                         }
1775                         wd = i;
1776 #endif
1777
1778                         for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1779                                 if ( i == slap_listeners[l]->sl_sd ) {
1780 #ifdef LDAP_CONNECTIONLESS
1781                                         if (slap_listeners[l]->sl_is_udp) continue;
1782 #endif
1783                                         is_listener = 1;
1784                                         break;
1785                                 }
1786                         }
1787                         if ( is_listener ) {
1788                                 continue;
1789                         }
1790 #ifdef NEW_LOGGING
1791                         LDAP_LOG( CONNECTION, DETAIL2, 
1792                                 "slapd_daemon_task: write active on %d\n", wd, 0, 0 );
1793 #else
1794                         Debug( LDAP_DEBUG_CONNS,
1795                                 "daemon: write active on %d\n",
1796                                 wd, 0, 0 );
1797 #endif
1798                         /*
1799                          * NOTE: it is possible that the connection was closed
1800                          * and that the stream is now inactive.
1801                          * connection_write() must valid the stream is still
1802                          * active.
1803                          */
1804
1805                         if ( connection_write( wd ) < 0 ) {
1806                                 FD_CLR( (unsigned) wd, &readfds );
1807                                 slapd_close( wd );
1808                         }
1809                 }
1810
1811 #ifdef HAVE_WINSOCK
1812                 for ( i = 0; i < readfds.fd_count; i++ )
1813 #else
1814                 for ( i = 0; i < nfds; i++ )
1815 #endif
1816                 {
1817                         ber_socket_t rd;
1818                         int is_listener = 0;
1819
1820 #ifdef HAVE_WINSOCK
1821                         rd = readfds.fd_array[i];
1822 #else
1823                         if( ! FD_ISSET( i, &readfds ) ) {
1824                                 continue;
1825                         }
1826                         rd = i;
1827 #endif
1828
1829                         for ( l = 0; slap_listeners[l] != NULL; l++ ) {
1830                                 if ( rd == slap_listeners[l]->sl_sd ) {
1831 #ifdef LDAP_CONNECTIONLESS
1832                                         if (slap_listeners[l]->sl_is_udp) continue;
1833 #endif
1834                                         is_listener = 1;
1835                                         break;
1836                                 }
1837                         }
1838                         if ( is_listener ) {
1839                                 continue;
1840                         }
1841
1842 #ifdef NEW_LOGGING
1843                         LDAP_LOG( CONNECTION, DETAIL2, 
1844                                 "slapd_daemon_task: read activity on %d\n", rd, 0, 0 );
1845 #else
1846                         Debug ( LDAP_DEBUG_CONNS,
1847                                 "daemon: read activity on %d\n", rd, 0, 0 );
1848 #endif
1849                         /*
1850                          * NOTE: it is possible that the connection was closed
1851                          * and that the stream is now inactive.
1852                          * connection_read() must valid the stream is still
1853                          * active.
1854                          */
1855
1856                         if ( connection_read( rd ) < 0 ) {
1857                                 slapd_close( rd );
1858                         }
1859                 }
1860                 ldap_pvt_thread_yield();
1861         }
1862
1863         if( slapd_shutdown == 1 ) {
1864 #ifdef NEW_LOGGING
1865                 LDAP_LOG( CONNECTION, CRIT,
1866                    "slapd_daemon_task: shutdown requested and initiated.\n", 0, 0, 0 );
1867 #else
1868                 Debug( LDAP_DEBUG_TRACE,
1869                         "daemon: shutdown requested and initiated.\n",
1870                         0, 0, 0 );
1871 #endif
1872
1873         } else if ( slapd_shutdown == 2 ) {
1874 #ifdef HAVE_NT_SERVICE_MANAGER
1875 #ifdef NEW_LOGGING
1876                         LDAP_LOG( CONNECTION, CRIT,
1877                            "slapd_daemon_task: shutdown initiated by Service Manager.\n",
1878                            0, 0, 0);
1879 #else
1880                         Debug( LDAP_DEBUG_TRACE,
1881                                "daemon: shutdown initiated by Service Manager.\n",
1882                                0, 0, 0);
1883 #endif
1884 #else /* !HAVE_NT_SERVICE_MANAGER */
1885 #ifdef NEW_LOGGING
1886                         LDAP_LOG( CONNECTION, CRIT,
1887                            "slapd_daemon_task: abnormal condition, "
1888                            "shutdown initiated.\n", 0, 0, 0 );
1889 #else
1890                         Debug( LDAP_DEBUG_TRACE,
1891                                "daemon: abnormal condition, shutdown initiated.\n",
1892                                0, 0, 0 );
1893 #endif
1894 #endif /* !HAVE_NT_SERVICE_MANAGER */
1895         } else {
1896 #ifdef NEW_LOGGING
1897                 LDAP_LOG( CONNECTION, CRIT,
1898                    "slapd_daemon_task: no active streams, shutdown initiated.\n", 
1899                    0, 0, 0 );
1900 #else
1901                 Debug( LDAP_DEBUG_TRACE,
1902                        "daemon: no active streams, shutdown initiated.\n",
1903                        0, 0, 0 );
1904 #endif
1905         }
1906
1907         if( slapd_gentle_shutdown != 2 ) {
1908                 close_listeners ( 0 );
1909         }
1910
1911         free ( slap_listeners );
1912         slap_listeners = NULL;
1913
1914         if( !slapd_gentle_shutdown ) {
1915                 connections_shutdown();
1916         }
1917
1918 #ifdef NEW_LOGGING
1919         LDAP_LOG( CONNECTION, CRIT, 
1920                 "slapd_daemon_task: shutdown waiting for %d threads to terminate.\n",
1921                 ldap_pvt_thread_pool_backload(&connection_pool), 0, 0 );
1922 #else
1923         Debug( LDAP_DEBUG_ANY,
1924             "slapd shutdown: waiting for %d threads to terminate\n",
1925             ldap_pvt_thread_pool_backload(&connection_pool), 0, 0 );
1926 #endif
1927         ldap_pvt_thread_pool_destroy(&connection_pool, 1);
1928
1929         return NULL;
1930 }
1931
1932
1933 int slapd_daemon( void )
1934 {
1935         int rc;
1936
1937         connections_init();
1938
1939 #define SLAPD_LISTENER_THREAD 1
1940 #if defined( SLAPD_LISTENER_THREAD )
1941         {
1942                 ldap_pvt_thread_t       listener_tid;
1943
1944                 /* listener as a separate THREAD */
1945                 rc = ldap_pvt_thread_create( &listener_tid,
1946                         0, slapd_daemon_task, NULL );
1947
1948                 if ( rc != 0 ) {
1949 #ifdef NEW_LOGGING
1950                         LDAP_LOG( CONNECTION, ERR, 
1951                                 "slapd_daemon: listener ldap_pvt_thread_create failed (%d).\n",
1952                                 rc, 0, 0 );
1953 #else
1954                         Debug( LDAP_DEBUG_ANY,
1955                         "listener ldap_pvt_thread_create failed (%d)\n", rc, 0, 0 );
1956 #endif
1957                         return rc;
1958                 }
1959  
1960                 /* wait for the listener thread to complete */
1961                 ldap_pvt_thread_join( listener_tid, (void *) NULL );
1962         }
1963 #else
1964         /* experimental code */
1965         slapd_daemon_task( NULL );
1966 #endif
1967
1968         return 0;
1969
1970 }
1971
1972 int sockinit(void)
1973 {
1974 #if defined( HAVE_WINSOCK2 )
1975     WORD wVersionRequested;
1976         WSADATA wsaData;
1977         int err;
1978
1979         wVersionRequested = MAKEWORD( 2, 0 );
1980
1981         err = WSAStartup( wVersionRequested, &wsaData );
1982         if ( err != 0 ) {
1983                 /* Tell the user that we couldn't find a usable */
1984                 /* WinSock DLL.                                  */
1985                 return -1;
1986         }
1987
1988         /* Confirm that the WinSock DLL supports 2.0.*/
1989         /* Note that if the DLL supports versions greater    */
1990         /* than 2.0 in addition to 2.0, it will still return */
1991         /* 2.0 in wVersion since that is the version we      */
1992         /* requested.                                        */
1993
1994         if ( LOBYTE( wsaData.wVersion ) != 2 ||
1995                 HIBYTE( wsaData.wVersion ) != 0 )
1996         {
1997             /* Tell the user that we couldn't find a usable */
1998             /* WinSock DLL.                                  */
1999             WSACleanup();
2000             return -1;
2001         }
2002
2003         /* The WinSock DLL is acceptable. Proceed. */
2004 #elif defined( HAVE_WINSOCK )
2005         WSADATA wsaData;
2006         if ( WSAStartup( 0x0101, &wsaData ) != 0 ) {
2007             return -1;
2008         }
2009 #endif
2010         return 0;
2011 }
2012
2013 int sockdestroy(void)
2014 {
2015 #if defined( HAVE_WINSOCK2 ) || defined( HAVE_WINSOCK )
2016         WSACleanup();
2017 #endif
2018         return 0;
2019 }
2020
2021 RETSIGTYPE
2022 slap_sig_shutdown( int sig )
2023 {
2024 #ifdef NEW_LOGGING
2025         LDAP_LOG( CONNECTION, CRIT, 
2026                 "slap_sig_shutdown: signal %d\n", sig, 0, 0 );
2027 #else
2028         Debug(LDAP_DEBUG_TRACE, "slap_sig_shutdown: signal %d\n", sig, 0, 0);
2029 #endif
2030
2031         /*
2032          * If the NT Service Manager is controlling the server, we don't
2033          * want SIGBREAK to kill the server. For some strange reason,
2034          * SIGBREAK is generated when a user logs out.
2035          */
2036
2037 #if HAVE_NT_SERVICE_MANAGER && SIGBREAK
2038         if (is_NT_Service && sig == SIGBREAK)
2039 #ifdef NEW_LOGGING
2040             LDAP_LOG( CONNECTION, CRIT,
2041                     "slap_sig_shutdown: SIGBREAK ignored.\n", 0, 0, 0 );
2042 #else
2043             Debug(LDAP_DEBUG_TRACE, "slap_sig_shutdown: SIGBREAK ignored.\n",
2044                   0, 0, 0);
2045 #endif
2046         else
2047 #endif
2048 #ifdef SIGHUP
2049         if (sig == SIGHUP && global_gentlehup && slapd_gentle_shutdown == 0)
2050                 slapd_gentle_shutdown = 1;
2051         else
2052 #endif
2053         slapd_shutdown = 1;
2054
2055         WAKE_LISTENER(1);
2056
2057         /* reinstall self */
2058         (void) SIGNAL_REINSTALL( sig, slap_sig_shutdown );
2059 }
2060
2061 RETSIGTYPE
2062 slap_sig_wake( int sig )
2063 {
2064         WAKE_LISTENER(1);
2065
2066         /* reinstall self */
2067         (void) SIGNAL_REINSTALL( sig, slap_sig_wake );
2068 }
2069
2070
2071 void slapd_add_internal(ber_socket_t s) {
2072         slapd_add(s);
2073 }
2074
2075 Listener ** slapd_get_listeners(void) {
2076         return slap_listeners;
2077 }