Changed the naming convention of the setup wizard filename
[citadel.git] / webcit / webserver.c
index 64d63d27a14f178c1373f93ab7bbb751b1b21e9f..612ac5d086507408efc3119001df8b84115bc917 100644 (file)
 /*
- * $Id$
- */
-/**
- * \defgroup Webserver This contains a simple multithreaded TCP server manager.  It sits around
+ * This contains a simple multithreaded TCP server manager.  It sits around
  * waiting on the specified port for incoming HTTP connections.  When a
  * connection is established, it calls context_loop() from context_loop.c.
- * \ingroup WebcitHttpServer
+ *
+ * Copyright (c) 1996-2011 by the citadel.org developers.
+ * This program is released under the terms of the GNU General Public License v3.
+ *
  */
 
-/*@{*/
 #include "webcit.h"
 #include "webserver.h"
 
-#if HAVE_BACKTRACE
-#include <execinfo.h>
-#endif
-
+#include "modules_init.h"
 #ifndef HAVE_SNPRINTF
 int vsnprintf(char *buf, size_t max, const char *fmt, va_list argp);
 #endif
 
-int verbosity = 9;             /**< Logging level */
-int msock;                         /**< master listening socket */
-int is_https = 0;              /**< Nonzero if I am an HTTPS service */
-int follow_xff = 0;            /**< Follow X-Forwarded-For: header */
-int home_specified = 0; /**< did the user specify a homedir? */
-extern void *context_loop(int);
-extern void *housekeeping_loop(void);
+
+extern int msock;                      /* master listening socket */
+extern int verbosity;          /* Logging level */
+extern char static_icon_dir[PATH_MAX];          /* where should we find our mime icons */
+int is_https = 0;              /* Nonzero if I am an HTTPS service */
+int follow_xff = 0;            /* Follow X-Forwarded-For: header */
+int DisableGzip = 0;
+struct redirector *redir = NULL;
+char *default_landing_page = NULL;
+int num_redir = 0;
 extern pthread_mutex_t SessionListMutex;
 extern pthread_key_t MyConKey;
 
-char socket_dir[PATH_MAX];      /**< where to talk to our citadel server */
-static const char editor_absolut_dir[PATH_MAX]=EDITORDIR; /**< nailed to what configure gives us. */
-static char static_dir[PATH_MAX]; /**< calculated on startup */
-char  *static_dirs[]={ /**< needs same sort order as the web mapping */
-       (char*)static_dir,                  /** our templates on disk */
-       (char*)static_dir,                  /** our templates on disk */
-       (char*)editor_absolut_dir           /** the editor on disk */
-};
-
-/**
- * Subdirectories from which the client may request static content
- *
- * (If you add more, remember to increment 'ndirs' below)
- */
-char *static_content_dirs[] = {
-       "static",                     /** static templates */
-       "static.local",               /** site local static templates */
-       "tiny_mce"                    /** the JS editor */
-};
-
-int ndirs=3;
-
-
-char *server_cookie = NULL; /**< our Cookie connection to the client */
-
-int http_port = PORT_NUM;      /**< Port to listen on */
-
-char *ctdlhost = DEFAULT_HOST; /**< our name */
-char *ctdlport = DEFAULT_PORT; /**< our Port */
-int setup_wizard = 0;          /**< should we run the setup wizard? \todo */
-char wizard_filename[PATH_MAX];/**< where's the setup wizard? */
-int running_as_daemon = 0;     /**< should we deamonize on startup? */
-
-
-/** 
- * \brief This is a generic function to set up a master socket for listening on
- * a TCP port.  The server shuts down if the bind fails.
- * \param ip_addr ip to bind to
- * \param port_number the port to bind to 
- * \param queue_len the size of the input queue ????
- */
-int ig_tcp_server(char *ip_addr, int port_number, int queue_len)
-{
-       struct sockaddr_in sin;
-       int s, i;
-
-       memset(&sin, 0, sizeof(sin));
-       sin.sin_family = AF_INET;
-       if (ip_addr == NULL) {
-               sin.sin_addr.s_addr = INADDR_ANY;
-       } else {
-               sin.sin_addr.s_addr = inet_addr(ip_addr);
-       }
-
-       if (sin.sin_addr.s_addr == INADDR_NONE) {
-               sin.sin_addr.s_addr = INADDR_ANY;
-       }
-
-       if (port_number == 0) {
-               lprintf(1, "Cannot start: no port number specified.\n");
-               exit(WC_EXIT_BIND);
-       }
-       sin.sin_port = htons((u_short) port_number);
-
-       s = socket(PF_INET, SOCK_STREAM, (getprotobyname("tcp")->p_proto));
-       if (s < 0) {
-               lprintf(1, "Can't create a socket: %s\n", strerror(errno));
-               exit(WC_EXIT_BIND);
-       }
-       /** Set some socket options that make sense. */
-       i = 1;
-       setsockopt(s, SOL_SOCKET, SO_REUSEADDR, &i, sizeof(i));
-
-       if (bind(s, (struct sockaddr *) &sin, sizeof(sin)) < 0) {
-               lprintf(1, "Can't bind: %s\n", strerror(errno));
-               exit(WC_EXIT_BIND);
-       }
-       if (listen(s, queue_len) < 0) {
-               lprintf(1, "Can't listen: %s\n", strerror(errno));
-               exit(WC_EXIT_BIND);
-       }
-       return (s);
-}
-
-
-
-/**
- * \brief Create a Unix domain socket and listen on it
- * \param sockpath file name of the unix domain socket
- * \param queue_len queue size of the kernel fifo????
- */
-int ig_uds_server(char *sockpath, int queue_len)
-{
-       struct sockaddr_un addr;
-       int s;
-       int i;
-       int actual_queue_len;
-
-       actual_queue_len = queue_len;
-       if (actual_queue_len < 5) actual_queue_len = 5;
-
-       i = unlink(sockpath);
-       if (i != 0) if (errno != ENOENT) {
-               lprintf(1, "citserver: can't unlink %s: %s\n",
-                       sockpath, strerror(errno));
-               exit(WC_EXIT_BIND);
-       }
-
-       memset(&addr, 0, sizeof(addr));
-       addr.sun_family = AF_UNIX;
-       safestrncpy(addr.sun_path, sockpath, sizeof addr.sun_path);
-
-       s = socket(AF_UNIX, SOCK_STREAM, 0);
-       if (s < 0) {
-               lprintf(1, "citserver: Can't create a socket: %s\n",
-                       strerror(errno));
-               exit(WC_EXIT_BIND);
-       }
-
-       if (bind(s, (struct sockaddr *)&addr, sizeof(addr)) < 0) {
-               lprintf(1, "citserver: Can't bind: %s\n",
-                       strerror(errno));
-               exit(WC_EXIT_BIND);
-       }
-
-       if (listen(s, actual_queue_len) < 0) {
-               lprintf(1, "citserver: Can't listen: %s\n",
-                       strerror(errno));
-               exit(WC_EXIT_BIND);
-       }
+extern void *housekeeping_loop(void);
+extern int webcit_tcp_server(char *ip_addr, int port_number, int queue_len);
+extern int webcit_uds_server(char *sockpath, int queue_len);
+extern void graceful_shutdown_watcher(int signum);
+extern void graceful_shutdown(int signum);
+extern void start_daemon(char *pid_file);
+extern void webcit_calc_dirs_n_files(int relh, const char *basedir, int home, char *webcitdir, char *relhome);
+extern void worker_entry(void);
+extern void drop_root(uid_t UID);
+
+char socket_dir[PATH_MAX];     /* where to talk to our citadel server */
+char *server_cookie = NULL;    /* our Cookie connection to the client */
+int http_port = PORT_NUM;      /* Port to listen on */
+char *ctdlhost = DEFAULT_HOST; /* Host name or IP address of Citadel server */
+char *ctdlport = DEFAULT_PORT; /* Port number of Citadel server */
+int setup_wizard = 0;          /* should we run the setup wizard? */
+char wizard_filename[PATH_MAX];        /* location of file containing the last webcit version against which we ran setup wizard */
+int running_as_daemon = 0;     /* should we deamonize on startup? */
+
+
+/* #define DBG_PRINNT_HOOKS_AT_START */
+#ifdef DBG_PRINNT_HOOKS_AT_START
+extern HashList *HandlerHash;
+const char foobuf[32];
+const char *nix(void *vptr) {snprintf(foobuf, 32, "%0x", (long) vptr); return foobuf;}
+#endif 
+extern int dbg_analyze_msg;
+extern int dbg_backtrace_template_errors;
+extern int DumpTemplateI18NStrings;
+extern StrBuf *I18nDump;
+void InitTemplateCache(void);
+extern int LoadTemplates;
 
-       chmod(sockpath, 0777);
-       return(s);
-}
 
 
 
 
-/**
- * \brief Read data from the client socket.
- * \param sock socket fd to read from ???
- * \param buf buffer to read into 
- * \param bytes how large is the read buffer?
- * \param timeout how long should we wait for input?
- * \return values are\
- *      1       Requested number of bytes has been read.\
- *      0       Request timed out.\
- *        -1           Connection is broken, or other error.
+/*
+ * Handle redirects to legacy web servers
  */
-int client_read_to(int sock, char *buf, int bytes, int timeout)
-{
-       int len, rlen;
-       fd_set rfds;
-       struct timeval tv;
-       int retval;
-
-
-#ifdef HAVE_OPENSSL
-       if (is_https) {
-               return (client_read_ssl(buf, bytes, timeout));
-       }
-#endif
-
-       len = 0;
-       while (len < bytes) {
-               FD_ZERO(&rfds);
-               FD_SET(sock, &rfds);
-               tv.tv_sec = timeout;
-               tv.tv_usec = 0;
-
-               retval = select((sock) + 1, &rfds, NULL, NULL, &tv);
-               if (FD_ISSET(sock, &rfds) == 0) {
-                       return (0);
-               }
-
-               rlen = read(sock, &buf[len], bytes - len);
-
-               if (rlen < 1) {
-                       lprintf(2, "client_read() failed: %s\n",
-                               strerror(errno));
-                       return (-1);
+void handle_redir(void) {
+       if (num_redir > 0) {
+               int i;
+               const char *req = ChrPtr(WC->Hdr->this_page);
+               if (!req) {
+                       do_404();
+                       return;
                }
-               len = len + rlen;
-       }
-
-#ifdef HTTP_TRACING
-       write(2, "\033[32m", 5);
-       write(2, buf, bytes);
-       write(2, "\033[30m", 5);
-#endif
-       return (1);
-}
-
-/**
- * \brief write data to the client
- * \param buf data to write to the client
- * \param count size of buffer
- */
-ssize_t client_write(const void *buf, size_t count)
-{
-       char *newptr;
-       size_t newalloc;
-
-       if (WC->burst != NULL) {
-               if ((WC->burst_len + count) >= WC->burst_alloc) {
-                       newalloc = (WC->burst_alloc * 2);
-                       if ((WC->burst_len + count) >= newalloc) {
-                               newalloc += count;
+               if (req[0] == '/') ++req;
+               syslog(9, "handle_redir() called; redirect this: %s", req);
+               for (i=0; i<num_redir; ++i) {
+                       if (!strncmp(redir[i].urlpart, req, strlen(redir[i].urlpart))) {
+                               char go_here[1024];
+                               snprintf(go_here, sizeof go_here, redir[i].redirect_to, req);
+                               syslog(9, "redirecting to: %s", go_here);
+                               http_redirect(go_here);
+                               return;
                        }
-                       newptr = realloc(WC->burst, newalloc);
-                       if (newptr != NULL) {
-                               WC->burst = newptr;
-                               WC->burst_alloc = newalloc;
-                       }
-               }
-               if ((WC->burst_len + count) < WC->burst_alloc) {
-                       memcpy(&WC->burst[WC->burst_len], buf, count);
-                       WC->burst_len += count;
-                       return (count);
                }
-               else {
-                       return(-1);
-               }
-       }
-#ifdef HAVE_OPENSSL
-       if (is_https) {
-               client_write_ssl((char *) buf, count);
-               return (count);
        }
-#endif
-#ifdef HTTP_TRACING
-       write(2, "\033[34m", 5);
-       write(2, buf, count);
-       write(2, "\033[30m", 5);
-#endif
-       return (write(WC->http_sock, buf, count));
+       do_404();
 }
 
-/**
- * \brief what burst???
- */
-void begin_burst(void)
-{
-       if (WC->burst != NULL) {
-               free(WC->burst);
-               WC->burst = NULL;
-       }
-       WC->burst_len = 0;
-       WC->burst_alloc = 32768;
-       WC->burst = malloc(WC->burst_alloc);
-}
 
 
-/**
- * \brief uses the same calling syntax as compress2(), but it
- * creates a stream compatible with HTTP "Content-encoding: gzip"
- */
-#ifdef HAVE_ZLIB
-#define DEF_MEM_LEVEL 8 /**< memlevel??? */
-#define OS_CODE 0x03   /**< unix */
-int ZEXPORT compress_gzip(Bytef * dest,         /**< compressed buffer*/
-                                                 uLongf * destLen,     /**< length of the compresed data */
-                                                 const Bytef * source, /**< source to encode */
-                                                 uLong sourceLen,      /**< length of the source to encode */
-                                                 int level)            /**< what level??? */
-{
-       const int gz_magic[2] = { 0x1f, 0x8b }; /** gzip magic header */
-
-       /** write gzip header */
-       sprintf((char *) dest, "%c%c%c%c%c%c%c%c%c%c",
-               gz_magic[0], gz_magic[1], Z_DEFLATED,
-               0 /*flags */ , 0, 0, 0, 0 /*time */ , 0 /** xflags */ ,
-               OS_CODE);
-
-       /* normal deflate */
-       z_stream stream;
-       int err;
-       stream.next_in = (Bytef *) source;
-       stream.avail_in = (uInt) sourceLen;
-       stream.next_out = dest + 10L;   // after header
-       stream.avail_out = (uInt) * destLen;
-       if ((uLong) stream.avail_out != *destLen)
-               return Z_BUF_ERROR;
-
-       stream.zalloc = (alloc_func) 0;
-       stream.zfree = (free_func) 0;
-       stream.opaque = (voidpf) 0;
-
-       err = deflateInit2(&stream, level, Z_DEFLATED, -MAX_WBITS,
-                          DEF_MEM_LEVEL, Z_DEFAULT_STRATEGY);
-       if (err != Z_OK)
-               return err;
-
-       err = deflate(&stream, Z_FINISH);
-       if (err != Z_STREAM_END) {
-               deflateEnd(&stream);
-               return err == Z_OK ? Z_BUF_ERROR : err;
-       }
-       *destLen = stream.total_out + 10L;
-
-       /* write CRC and Length */
-       uLong crc = crc32(0L, source, sourceLen);
-       int n;
-       for (n = 0; n < 4; ++n, ++*destLen) {
-               dest[*destLen] = (int) (crc & 0xff);
-               crc >>= 8;
-       }
-       uLong len = stream.total_in;
-       for (n = 0; n < 4; ++n, ++*destLen) {
-               dest[*destLen] = (int) (len & 0xff);
-               len >>= 8;
-       }
-       err = deflateEnd(&stream);
-       return err;
-}
-#endif
-
-/**
- * \brief what burst???
+/*
+ * load redirect strings (for supporting transition of legacy web servers to citadel on the same host)
  */
-void end_burst(void)
-{
-       size_t the_len;
-       char *the_data;
-
-       if (WC->burst == NULL)
+void load_redirs(char *filename) {
+       char buf[1024];
+       int num_redir_alloc = num_redir;
+       FILE *fp = fopen(filename, "r");
+       if (!fp) {
+               syslog(1, "Cannot open %s: %s", filename, strerror(errno));
                return;
-
-       the_len = WC->burst_len;
-       the_data = WC->burst;
-
-       WC->burst_len = 0;
-       WC->burst_alloc = 0;
-       WC->burst = NULL;
-
-#ifdef HAVE_ZLIB
-       /* Handle gzip compression */
-       if (WC->gzip_ok) {
-               char *compressed_data = NULL;
-               uLongf compressed_len;
-
-               compressed_len = (uLongf) ((the_len * 101) / 100) + 100;
-               compressed_data = malloc(compressed_len);
-
-               if (compress_gzip((Bytef *) compressed_data,
-                                 &compressed_len,
-                                 (Bytef *) the_data,
-                                 (uLongf) the_len, Z_BEST_SPEED) == Z_OK) {
-                       wprintf("Content-encoding: gzip\r\n");
-                       free(the_data);
-                       the_data = compressed_data;
-                       the_len = compressed_len;
-               } else {
-                       free(compressed_data);
-               }
        }
-#endif                         /* HAVE_ZLIB */
-
-       wprintf("Content-length: %d\r\n\r\n", the_len);
-       client_write(the_data, the_len);
-       free(the_data);
-       return;
-}
-
-
-
-/**
- * \brief Read data from the client socket with default timeout.
- * (This is implemented in terms of client_read_to() and could be
- * justifiably moved out of sysdep.c)
- * \param sock the socket fd to read from???
- * \param buf the buffer to write to
- * \param bytes how large is the buffer
- */
-int client_read(int sock, char *buf, int bytes)
-{
-       return (client_read_to(sock, buf, bytes, SLEEPING));
-}
-
-
-/**
- * \brief Get a LF-terminated line of text from the client.
- * (This is implemented in terms of client_read() and could be
- * justifiably moved out of sysdep.c)
- * \param sock socket fd to get client line from???
- * \param buf buffer to write read data to
- * \param bufsiz how many bytes to read
- * \return  numer of bytes read???
- */
-int client_getln(int sock, char *buf, int bufsiz)
-{
-       int i, retval;
-
-       /** Read one character at a time.*/
-       for (i = 0;; i++) {
-               retval = client_read(sock, &buf[i], 1);
-               if (retval != 1 || buf[i] == '\n' || i == (bufsiz-1))
-                       break;
-               if ( (!isspace(buf[i])) && (!isprint(buf[i])) ) {
-                       /** Non printable character recieved from client */
-                       return(-1);
-               }
-       }
-
-       /** If we got a long line, discard characters until the newline. */
-       if (i == (bufsiz-1))
-               while (buf[i] != '\n' && retval == 1)
-                       retval = client_read(sock, &buf[i], 1);
-
-       /**
-        * Strip any trailing non-printable characters.
-        */
-       buf[i] = 0;
-       while ((strlen(buf) > 0) && (!isprint(buf[strlen(buf) - 1]))) {
-               buf[strlen(buf) - 1] = 0;
-       }
-       return (retval);
-}
 
-/**
- * \brief shut us down the regular way.
- * param signum the signal we want to forward
- */
-pid_t current_child;
-void graceful_shutdown(int signum) {
-       kill(current_child, signum);
-       exit(0);
-}
-
-
-/**
- * \brief      Start running as a daemon.  
- *
- * param       do_close_stdio          Only close stdio if set.
- */
-
-/*
- * Start running as a daemon.
- */
-void start_daemon(char *pid_file) 
-{
-       int status = 0;
-       pid_t child = 0;
-       FILE *fp;
-       int do_restart = 0;
-
-       current_child = 0;
-
-       /* Close stdin/stdout/stderr and replace them with /dev/null.
-        * We don't just call close() because we don't want these fd's
-        * to be reused for other files.
-        */
-       chdir("/");
-
-       signal(SIGHUP, SIG_IGN);
-       signal(SIGINT, SIG_IGN);
-       signal(SIGQUIT, SIG_IGN);
+       while (fgets(buf, sizeof buf, fp) != NULL) {
+               char *ch;
 
-       child = fork();
-       if (child != 0) {
-               exit(0);
-       }
-
-       setsid();
-       umask(0);
-       freopen("/dev/null", "r", stdin);
-       freopen("/dev/null", "w", stdout);
-       freopen("/dev/null", "w", stderr);
+               buf[strlen(buf)-1] = 0;
 
-       do {
-               current_child = fork();
+               ch = strchr(buf, '#');
+               if (ch) strcpy(ch, "");
+               striplt(buf);
+               if (!IsEmptyStr(buf)) {
 
-       
-               if (current_child < 0) {
-                       perror("fork");
-                       exit(errno);
-               }
-       
-               else if (current_child == 0) {
-                       signal(SIGTERM, graceful_shutdown);
-                       return; /* continue starting citadel. */
-               }
-       
-               else {
-                       signal(SIGTERM, SIG_IGN);
-                       if (pid_file) {
-                               fp = fopen(pid_file, "w");
-                               if (fp != NULL) {
-                                       fprintf(fp, "%d\n", current_child);
-                                       fclose(fp);
+                       if (num_redir >= num_redir_alloc) {
+                               if (num_redir_alloc == 0) {
+                                       num_redir_alloc = 10;
                                }
+                               else {
+                                       num_redir_alloc = num_redir_alloc * 2;
+                               }
+                               redir = realloc(redir, sizeof(struct redirector) * num_redir_alloc );
                        }
-                       waitpid(current_child, &status, 0);
-               }
-
-               do_restart = 0;
-
-               /* Did the main process exit with an actual exit code? */
-               if (WIFEXITED(status)) {
-
-                       /* Exit code 0 means the watcher should exit */
-                       if (WEXITSTATUS(status) == 0) {
-                               do_restart = 0;
-                       }
-
-                       /* Exit code 101-109 means the watcher should exit */
-                       else if ( (WEXITSTATUS(status) >= 101) && (WEXITSTATUS(status) <= 109) ) {
-                               do_restart = 0;
-                       }
-
-                       /* Any other exit code means we should restart. */
-                       else {
-                               do_restart = 1;
+       
+                       extract_token(redir[num_redir].urlpart, buf, 0, '|', sizeof(redir[num_redir].urlpart));
+                       extract_token(redir[num_redir].redirect_to, buf, 1, '|', sizeof(redir[num_redir].redirect_to));
+                       WebcitAddUrlHandler(redir[num_redir].urlpart, strlen(redir[num_redir].urlpart), "", 0, handle_redir, ANONYMOUS|COOKIEUNNEEDED|ISSTATIC);
+                       if (!strcasecmp(redir[num_redir].urlpart, "home")) {
+                               default_landing_page = redir[num_redir].redirect_to ;
                        }
+                       ++num_redir;
                }
 
-               /* Any other type of termination (signals, etc.) should also restart. */
-               else {
-                       do_restart = 1;
-               }
-
-       } while (do_restart);
-
-       if (pid_file) {
-               unlink(pid_file);
        }
-       exit(WEXITSTATUS(status));
+       fclose(fp);
 }
 
-/**
- * \brief      Spawn an additional worker thread into the pool.
- */
-void spawn_another_worker_thread()
-{
-       pthread_t SessThread;   /**< Thread descriptor */
-       pthread_attr_t attr;    /**< Thread attributes */
-       int ret;
 
-       lprintf(3, "Creating a new thread\n");
 
-       /** set attributes for the new thread */
-       pthread_attr_init(&attr);
-       pthread_attr_setdetachstate(&attr, PTHREAD_CREATE_DETACHED);
-
-       /**
-        * Our per-thread stacks need to be bigger than the default size, otherwise
-        * the MIME parser crashes on FreeBSD, and the IMAP service crashes on
-        * 64-bit Linux.
-        */
-       if ((ret = pthread_attr_setstacksize(&attr, 1024 * 1024))) {
-               lprintf(1, "pthread_attr_setstacksize: %s\n",
-                       strerror(ret));
-               pthread_attr_destroy(&attr);
-       }
-
-       /** now create the thread */
-       if (pthread_create(&SessThread, &attr,
-                          (void *(*)(void *)) worker_entry, NULL)
-           != 0) {
-               lprintf(1, "Can't create thread: %s\n", strerror(errno));
-       }
-
-       /** free up the attributes */
-       pthread_attr_destroy(&attr);
-}
-
-/**
- * \brief Here's where it all begins.
- * \param argc number of commandline args
- * \param argv the commandline arguments
+/*
+ * Here's where it all begins.
  */
 int main(int argc, char **argv)
 {
-       pthread_t SessThread;   /**< Thread descriptor */
-       pthread_attr_t attr;    /**< Thread attributes */
-       int a, i;                       /**< General-purpose variables */
+       uid_t UID = -1;
+       size_t basesize = 2;            /* how big should strbufs be on creation? */
+       pthread_t SessThread;           /* Thread descriptor */
+       pthread_attr_t attr;            /* Thread attributes */
+       int a;                          /* General-purpose variable */
        char tracefile[PATH_MAX];
-       char ip_addr[256];
-       char dirbuffer[PATH_MAX]="";
+       char ip_addr[256]="*";
        int relh=0;
        int home=0;
-       int home_specified=0;
        char relhome[PATH_MAX]="";
        char webcitdir[PATH_MAX] = DATADIR;
        char *pidfile = NULL;
        char *hdir;
-       const char *basedir;
-#ifdef ENABLE_NLS
-       char *locale = NULL;
-       char *mo = NULL;
-#endif /* ENABLE_NLS */
-       char uds_listen_path[PATH_MAX]; /**< listen on a unix domain socket? */
+       const char *basedir = NULL;
+       char uds_listen_path[PATH_MAX]; /* listen on a unix domain socket? */
+       const char *I18nDumpFile = NULL;
+       FILE *rvfp = NULL;
+       int rv = 0;
+
+       WildFireInitBacktrace(argv[0], 2);
+
+       start_modules ();
+
+#ifdef DBG_PRINNT_HOOKS_AT_START
+/*     dbg_PrintHash(HandlerHash, nix, NULL);*/
+#endif
+
+       /* Ensure that we are linked to the correct version of libcitadel */
+       if (libcitadel_version_number() < LIBCITADEL_VERSION_NUMBER) {
+               fprintf(stderr, " You are running libcitadel version %d.%02d\n",
+                       (libcitadel_version_number() / 100), (libcitadel_version_number() % 100));
+               fprintf(stderr, "WebCit was compiled against version %d.%02d\n",
+                       (LIBCITADEL_VERSION_NUMBER / 100), (LIBCITADEL_VERSION_NUMBER % 100));
+               return(1);
+       }
 
        strcpy(uds_listen_path, "");
 
-       /** Parse command line */
+       /* Parse command line */
 #ifdef HAVE_OPENSSL
-       while ((a = getopt(argc, argv, "h:i:p:t:x:dD:cfs")) != EOF)
+       while ((a = getopt(argc, argv, "u:h:i:p:t:T:B:x:dD:G:r:cfsS:Z")) != EOF)
 #else
-       while ((a = getopt(argc, argv, "h:i:p:t:x:dD:cf")) != EOF)
+       while ((a = getopt(argc, argv, "u:h:i:p:t:T:B:x:dD:G:r:cfZ")) != EOF)
 #endif
                switch (a) {
+               case 'u':
+                       UID = atol(optarg);
+                       break;
+               case 'r':
+                       load_redirs(optarg);
+                       break;
                case 'h':
                        hdir = strdup(optarg);
                        relh=hdir[0]!='/';
-                       if (!relh) safestrncpy(webcitdir, hdir,
-                                                                  sizeof webcitdir);
-                       else
-                               safestrncpy(relhome, relhome,
-                                                       sizeof relhome);
+                       if (!relh) {
+                               safestrncpy(webcitdir, hdir, sizeof webcitdir);
+                       }
+                       else {
+                               safestrncpy(relhome, relhome, sizeof relhome);
+                       }
                        /* free(hdir); TODO: SHOULD WE DO THIS? */
-                       home_specified = 1;
                        home=1;
                        break;
                case 'd':
@@ -651,6 +216,11 @@ int main(int argc, char **argv)
                        pidfile = strdup(optarg);
                        running_as_daemon = 1;
                        break;
+               case 'B': /* Basesize */
+                       basesize = atoi(optarg);
+                       if (basesize > 2)
+                               StartLibCitadel(basesize);
+                       break;
                case 'i':
                        safestrncpy(ip_addr, optarg, sizeof ip_addr);
                        break;
@@ -662,9 +232,17 @@ int main(int argc, char **argv)
                        break;
                case 't':
                        safestrncpy(tracefile, optarg, sizeof tracefile);
-                       freopen(tracefile, "w", stdout);
-                       freopen(tracefile, "w", stderr);
-                       freopen(tracefile, "r", stdin);
+                       rvfp = freopen(tracefile, "w", stdout);
+                       rvfp = freopen(tracefile, "w", stderr);
+                       rvfp = freopen(tracefile, "r", stdin);
+                       break;
+               case 'T':
+                       LoadTemplates = atoi(optarg);
+                       dbg_analyze_msg = (LoadTemplates && (1<<1)) != 0;
+                       dbg_backtrace_template_errors = (LoadTemplates && (1<<2)) != 0;
+                       break;
+               case 'Z':
+                       DisableGzip = 1;
                        break;
                case 'x':
                        verbosity = atoi(optarg);
@@ -681,27 +259,44 @@ int main(int argc, char **argv)
                                if (gethostname
                                    (&server_cookie[strlen(server_cookie)],
                                     200) != 0) {
-                                       lprintf(2, "gethostname: %s\n",
-                                               strerror(errno));
+                                       syslog(2, "gethostname: %s", strerror(errno));
                                        free(server_cookie);
                                }
                        }
                        break;
+#ifdef HAVE_OPENSSL
                case 's':
                        is_https = 1;
                        break;
+               case 'S':
+                       is_https = 1;
+                       ssl_cipher_list = strdup(optarg);
+                       break;
+#endif
+               case 'G':
+                       DumpTemplateI18NStrings = 1;
+                       I18nDump = NewStrBufPlain(HKEY("int templatestrings(void)\n{\n"));
+                       I18nDumpFile = optarg;
+                       break;
                default:
-                       fprintf(stderr, "usage: webserver "
+                       fprintf(stderr, "usage: webcit "
                                "[-i ip_addr] [-p http_port] "
                                "[-t tracefile] [-c] [-f] "
-                               "[-d] "
+                               "[-T Templatedebuglevel] "
+                               "[-d] [-Z] [-G i18ndumpfile] "
 #ifdef HAVE_OPENSSL
-                               "[-s] "
+                               "[-s] [-S cipher_suites]"
 #endif
                                "[remotehost [remoteport]]\n");
                        return 1;
                }
 
+       /* Start the logger */
+       openlog("webcit",
+               ( running_as_daemon ? (LOG_PID) : (LOG_PID | LOG_PERROR) ),
+               LOG_DAEMON
+       );
+
        if (optind < argc) {
                ctdlhost = argv[optind];
                if (++optind < argc)
@@ -709,64 +304,79 @@ int main(int argc, char **argv)
        }
 
        /* daemonize, if we were asked to */
-       if (running_as_daemon) {
+       if (!DumpTemplateI18NStrings && running_as_daemon) {
                start_daemon(pidfile);
        }
+       else {
+               signal(SIGINT, graceful_shutdown);
+               signal(SIGHUP, graceful_shutdown);
+       }
+
+       webcit_calc_dirs_n_files(relh, basedir, home, webcitdir, relhome);
+       LoadIconDir(static_icon_dir);
+
+       /* Tell 'em who's in da house */
+       syslog(1, "%s", PACKAGE_STRING);
+       syslog(1, "Copyright (C) 1996-2011 by the citadel.org team");
+       syslog(1, " ");
+       syslog(1, "This program is open source software: you can redistribute it and/or");
+       syslog(1, "modify it under the terms of the GNU General Public License as published");
+       syslog(1, "by the Free Software Foundation, either version 3 of the License, or");
+       syslog(1, "(at your option) any later version.");
+       syslog(1, " ");
+       syslog(1, "This program is distributed in the hope that it will be useful,");
+       syslog(1, "but WITHOUT ANY WARRANTY; without even the implied warranty of");
+       syslog(1, "MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the");
+       syslog(1, "GNU General Public License for more details.");
+       syslog(1, " ");
+       syslog(1, "You should have received a copy of the GNU General Public License");
+       syslog(1, "along with this program.  If not, see <http://www.gnu.org/licenses/>.");
+       syslog(1, " ");
+
+
+       /* initialize various subsystems */
+
+       initialise_modules();
+       InitTemplateCache();
+       if (DumpTemplateI18NStrings) {
+               FILE *fd;
+               StrBufAppendBufPlain(I18nDump, HKEY("}\n"), 0);
+               if (StrLength(I18nDump) < 50) {
+                       syslog(1, "********************************************************************************\n");
+                       syslog(1, "*        No strings found in templates!  Are you sure they're there?           *\n");
+                       syslog(1, "********************************************************************************\n");
+                       return -1;
+               }
+               fd = fopen(I18nDumpFile, "w");
+               if (fd == NULL) {
+                       syslog(1, "********************************************************************************\n");
+                       syslog(1, "*                  unable to open I18N dumpfile [%s]         *\n", I18nDumpFile);
+                       syslog(1, "********************************************************************************\n");
+                       return -1;
+               }
+               rv = fwrite(ChrPtr(I18nDump), 1, StrLength(I18nDump), fd);
+               fclose(fd);
+               return 0;
+       }
 
-       /** Tell 'em who's in da house */
-       lprintf(1, SERVER "\n");
-       lprintf(1, "Copyright (C) 1996-2007 by the Citadel development team.\n"
-               "This software is distributed under the terms of the "
-               "GNU General Public License.\n\n"
-       );
-
-
-       /** initialize the International Bright Young Thing */
-#ifdef ENABLE_NLS
-       initialize_locales();
-       locale = setlocale(LC_ALL, "");
-       mo = malloc(strlen(webcitdir) + 20);
-       lprintf(9, "Message catalog directory: %s\n", bindtextdomain("webcit", LOCALEDIR"/locale"));
-       free(mo);
-       lprintf(9, "Text domain: %s\n", textdomain("webcit"));
-       lprintf(9, "Text domain Charset: %s\n", bind_textdomain_codeset("webcit","UTF8"));
-#endif
 
+       /* Tell libical to return an error instead of aborting if it sees badly formed iCalendar data. */
+       icalerror_errors_are_fatal = 0;
 
-       /* calculate all our path on a central place */
-    /* where to keep our config */
-       
-#define COMPUTE_DIRECTORY(SUBDIR) memcpy(dirbuffer,SUBDIR, sizeof dirbuffer);\
-       snprintf(SUBDIR,sizeof SUBDIR,  "%s%s%s%s%s%s%s", \
-                        (home&!relh)?webcitdir:basedir, \
-             ((basedir!=webcitdir)&(home&!relh))?basedir:"/", \
-             ((basedir!=webcitdir)&(home&!relh))?"/":"", \
-                        relhome, \
-             (relhome[0]!='\0')?"/":"",\
-                        dirbuffer,\
-                        (dirbuffer[0]!='\0')?"/":"");
-       basedir=RUNDIR;
-       COMPUTE_DIRECTORY(socket_dir);
-       basedir=DATADIR;
-       COMPUTE_DIRECTORY(static_dir);
-       /** we should go somewhere we can leave our coredump, if enabled... */
-       lprintf(9, "Changing directory to %s\n", socket_dir);
-       if (chdir(webcitdir) != 0) {
-               perror("chdir");
-       }
-       initialize_viewdefs();
-       initialize_axdefs();
+       /* Use our own prefix on tzid's generated from system tzdata */
+       icaltimezone_set_tzid_prefix("/citadel.org/");
 
-       /**
+       /*
         * Set up a place to put thread-specific data.
         * We only need a single pointer per thread - it points to the
         * wcsession struct to which the thread is currently bound.
         */
        if (pthread_key_create(&MyConKey, NULL) != 0) {
-               lprintf(1, "Can't create TSD key: %s\n", strerror(errno));
+               syslog(1, "Can't create TSD key: %s\n", strerror(errno));
        }
+       InitialiseSemaphores ();
 
-       /**
+       /*
         * Set up a place to put thread-specific SSL data.
         * We don't stick this in the wcsession struct because SSL starts
         * up before the session is bound, and it gets torn down between
@@ -774,31 +384,36 @@ int main(int argc, char **argv)
         */
 #ifdef HAVE_OPENSSL
        if (pthread_key_create(&ThreadSSL, NULL) != 0) {
-               lprintf(1, "Can't create TSD key: %s\n", strerror(errno));
+               syslog(1, "Can't create TSD key: %s\n", strerror(errno));
        }
 #endif
 
-       /**
+       /*
         * Bind the server to our favorite port.
-        * There is no need to check for errors, because ig_tcp_server()
+        * There is no need to check for errors, because webcit_tcp_server()
         * exits if it doesn't succeed.
         */
 
-       if (strlen(uds_listen_path) > 0) {
-               lprintf(2, "Attempting to create listener socket at %s...\n", uds_listen_path);
-               msock = ig_uds_server(uds_listen_path, LISTEN_QUEUE_LENGTH);
+       if (!IsEmptyStr(uds_listen_path)) {
+               syslog(2, "Attempting to create listener socket at %s...\n", uds_listen_path);
+               msock = webcit_uds_server(uds_listen_path, LISTEN_QUEUE_LENGTH);
        }
        else {
-               lprintf(2, "Attempting to bind to port %d...\n", http_port);
-               msock = ig_tcp_server(ip_addr, http_port, LISTEN_QUEUE_LENGTH);
+               syslog(2, "Attempting to bind to port %d...\n", http_port);
+               msock = webcit_tcp_server(ip_addr, http_port, LISTEN_QUEUE_LENGTH);
+       }
+       if (msock < 0)
+       {
+               ShutDownWebcit();
+               return -msock;
        }
 
-       lprintf(2, "Listening on socket %d\n", msock);
+       syslog(2, "Listening on socket %d\n", msock);
        signal(SIGPIPE, SIG_IGN);
 
        pthread_mutex_init(&SessionListMutex, NULL);
 
-       /**
+       /*
         * Start up the housekeeping thread
         */
        pthread_attr_init(&attr);
@@ -807,7 +422,7 @@ int main(int argc, char **argv)
                       (void *(*)(void *)) housekeeping_loop, NULL);
 
 
-       /**
+       /*
         * If this is an HTTPS server, fire up SSL
         */
 #ifdef HAVE_OPENSSL
@@ -815,116 +430,17 @@ int main(int argc, char **argv)
                init_ssl();
        }
 #endif
+       drop_root(UID);
 
-       /** Start a few initial worker threads */
-       for (i = 0; i < (MIN_WORKER_THREADS); ++i) {
-               spawn_another_worker_thread();
-       }
-
-       /* now the original thread becomes another worker */
+       /* Become a worker thread.  More worker threads will be spawned as they are needed. */
        worker_entry();
+       ShutDownLibCitadel();
        return 0;
 }
 
 
-/**
- * Entry point for worker threads
- */
-void worker_entry(void)
-{
-       int ssock;
-       int i = 0;
-       int time_to_die = 0;
-       int fail_this_transaction = 0;
-
-       do {
-               /** Only one thread can accept at a time */
-               fail_this_transaction = 0;
-               ssock = accept(msock, NULL, 0);
-               if (ssock < 0) {
-                       lprintf(2, "accept() failed: %s\n",
-                               strerror(errno));
-               } else {
-                       /** Set the SO_REUSEADDR socket option */
-                       i = 1;
-                       setsockopt(ssock, SOL_SOCKET, SO_REUSEADDR,
-                                  &i, sizeof(i));
-
-                       /** If we are an HTTPS server, go crypto now. */
-#ifdef HAVE_OPENSSL
-                       if (is_https) {
-                               if (starttls(ssock) != 0) {
-                                       fail_this_transaction = 1;
-                                       close(ssock);
-                               }
-                       }
-#endif
-
-                       if (fail_this_transaction == 0) {
-
-                               /** Perform an HTTP transaction... */
-                               context_loop(ssock);
 
-                               /** Shut down SSL/TLS if required... */
-#ifdef HAVE_OPENSSL
-                               if (is_https) {
-                                       endtls();
-                               }
-#endif
 
-                               /** ...and close the socket. */
-                               lingering_close(ssock);
-                       }
 
-               }
-
-       } while (!time_to_die);
 
-       pthread_exit(NULL);
-}
-
-/**
- * \brief logprintf. log messages 
- * logs to stderr if loglevel is lower than the verbosity set at startup
- * \param loglevel level of the message
- * \param format the printf like format string
- * \param ... the strings to put into format
- */
-int lprintf(int loglevel, const char *format, ...)
-{
-       va_list ap;
-
-       if (loglevel <= verbosity) {
-               va_start(ap, format);
-               vfprintf(stderr, format, ap);
-               va_end(ap);
-               fflush(stderr);
-       }
-       return 1;
-}
-
-
-/**
- * \brief print the actual stack frame.
- */
-void wc_backtrace(void)
-{
-#ifdef HAVE_BACKTRACE
-       void *stack_frames[50];
-       size_t size, i;
-       char **strings;
-
-
-       size = backtrace(stack_frames, sizeof(stack_frames) / sizeof(void*));
-       strings = backtrace_symbols(stack_frames, size);
-       for (i = 0; i < size; i++) {
-               if (strings != NULL)
-                       lprintf(1, "%s\n", strings[i]);
-               else
-                       lprintf(1, "%p\n", stack_frames[i]);
-       }
-       free(strings);
-#endif
-}
 
-/*@}*/