/*
- * $Id$
+ * Copyright (c) 1996-2020 by the citadel.org team
*
- * This contains a simple multithreaded TCP server manager. It sits around
- * waiting on the specified port for incoming HTTP connections. When a
- * connection is established, it calls context_loop() from context_loop.c.
+ * This program is open source software. You can redistribute it and/or
+ * modify it under the terms of the GNU General Public License version 3.
*
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU General Public License for more details.
*/
-
#include "webcit.h"
#include "webserver.h"
-#ifndef HAVE_SNPRINTF
-int vsnprintf(char *buf, size_t max, const char *fmt, va_list argp);
-#endif
+#include "modules_init.h"
-int verbosity = 9; /* Logging level */
-int msock; /* master listening socket */
-int is_https = 0; /* Nonzero if I am an HTTPS service */
-int follow_xff = 0; /* Follow X-Forwarded-For: header */
-extern void *context_loop(int);
-extern void *housekeeping_loop(void);
+extern int msock; /* master listening socket */
+extern char static_icon_dir[PATH_MAX]; /* where should we find our mime icons */
+int is_https = 0; /* Nonzero if I am an HTTPS service */
+int follow_xff = 0; /* Follow X-Forwarded-For: header? */
+int DisableGzip = 0;
+char *default_landing_page = NULL;
extern pthread_mutex_t SessionListMutex;
extern pthread_key_t MyConKey;
-
-char *server_cookie = NULL;
-
-
-char *ctdlhost = DEFAULT_HOST;
-char *ctdlport = DEFAULT_PORT;
-int setup_wizard = 0;
-char wizard_filename[PATH_MAX];
-
-/*
- * This is a generic function to set up a master socket for listening on
- * a TCP port. The server shuts down if the bind fails.
- */
-int ig_tcp_server(char *ip_addr, int port_number, int queue_len)
-{
- struct sockaddr_in sin;
- int s, i;
-
- memset(&sin, 0, sizeof(sin));
- sin.sin_family = AF_INET;
- if (ip_addr == NULL) {
- sin.sin_addr.s_addr = INADDR_ANY;
- } else {
- sin.sin_addr.s_addr = inet_addr(ip_addr);
- }
-
- if (sin.sin_addr.s_addr == INADDR_NONE) {
- sin.sin_addr.s_addr = INADDR_ANY;
- }
-
- if (port_number == 0) {
- lprintf(1, "Cannot start: no port number specified.\n");
- exit(1);
- }
- sin.sin_port = htons((u_short) port_number);
-
- s = socket(PF_INET, SOCK_STREAM, (getprotobyname("tcp")->p_proto));
- if (s < 0) {
- lprintf(1, "Can't create a socket: %s\n", strerror(errno));
- exit(errno);
- }
- /* Set some socket options that make sense. */
- i = 1;
- setsockopt(s, SOL_SOCKET, SO_REUSEADDR, &i, sizeof(i));
-
- if (bind(s, (struct sockaddr *) &sin, sizeof(sin)) < 0) {
- lprintf(1, "Can't bind: %s\n", strerror(errno));
- exit(errno);
- }
- if (listen(s, queue_len) < 0) {
- lprintf(1, "Can't listen: %s\n", strerror(errno));
- exit(errno);
- }
- return (s);
-}
-
-
-/*
- * Read data from the client socket.
- * Return values are:
- * 1 Requested number of bytes has been read.
- * 0 Request timed out.
- * -1 Connection is broken, or other error.
- */
-int client_read_to(int sock, char *buf, int bytes, int timeout)
-{
- int len, rlen;
- fd_set rfds;
- struct timeval tv;
- int retval;
-
-
-#ifdef HAVE_OPENSSL
- if (is_https) {
- return (client_read_ssl(buf, bytes, timeout));
- }
-#endif
-
- len = 0;
- while (len < bytes) {
- FD_ZERO(&rfds);
- FD_SET(sock, &rfds);
- tv.tv_sec = timeout;
- tv.tv_usec = 0;
-
- retval = select((sock) + 1, &rfds, NULL, NULL, &tv);
- if (FD_ISSET(sock, &rfds) == 0) {
- return (0);
- }
-
- rlen = read(sock, &buf[len], bytes - len);
-
- if (rlen < 1) {
- lprintf(2, "client_read() failed: %s\n",
- strerror(errno));
- return (-1);
- }
- len = len + rlen;
- }
-
-#ifdef HTTP_TRACING
- write(2, "\033[32m", 5);
- write(2, buf, bytes);
- write(2, "\033[30m", 5);
-#endif
- return (1);
-}
-
-
-ssize_t client_write(const void *buf, size_t count)
-{
-
- if (WC->burst != NULL) {
- WC->burst =
- realloc(WC->burst, (WC->burst_len + count + 2));
- memcpy(&WC->burst[WC->burst_len], buf, count);
- WC->burst_len += count;
- return (count);
- }
-#ifdef HAVE_OPENSSL
- if (is_https) {
- client_write_ssl((char *) buf, count);
- return (count);
- }
-#endif
-#ifdef HTTP_TRACING
- write(2, "\033[34m", 5);
- write(2, buf, count);
- write(2, "\033[30m", 5);
-#endif
- return (write(WC->http_sock, buf, count));
-}
-
-
-void begin_burst(void)
-{
- if (WC->burst != NULL) {
- free(WC->burst);
- WC->burst = NULL;
- }
- WC->burst_len = 0;
- WC->burst = malloc(SIZ);
-}
-
+extern void *housekeeping_loop(void);
+extern int webcit_tcp_server(char *ip_addr, int port_number, int queue_len);
+extern int webcit_uds_server(char *sockpath, int queue_len);
+extern void graceful_shutdown_watcher(int signum);
+extern void graceful_shutdown(int signum);
+extern void start_daemon(char *pid_file);
+extern void webcit_calc_dirs_n_files(int relh, const char *basedir, int home, char *webcitdir, char *relhome);
+extern void worker_entry(void);
+extern void drop_root(uid_t UID);
+
+char socket_dir[PATH_MAX]; /* where to talk to our citadel server */
+char *server_cookie = NULL; /* our Cookie connection to the client */
+int http_port = PORT_NUM; /* Port to listen on */
+char *ctdlhost = DEFAULT_HOST; /* Host name or IP address of Citadel server */
+char *ctdlport = DEFAULT_PORT; /* Port number of Citadel server */
+int setup_wizard = 0; /* should we run the setup wizard? */
+char wizard_filename[PATH_MAX]; /* location of file containing the last webcit version against which we ran setup wizard */
+int running_as_daemon = 0; /* should we deamonize on startup? */
+
+/* #define DBG_PRINNT_HOOKS_AT_START */
+#ifdef DBG_PRINNT_HOOKS_AT_START
+extern HashList *HandlerHash;
+const char foobuf[32];
+const char *nix(void *vptr) {snprintf(foobuf, 32, "%0x", (long) vptr); return foobuf;}
+#endif
+extern int verbose;
+extern int dbg_analyze_msg;
+extern int dbg_backtrace_template_errors;
+extern int DumpTemplateI18NStrings;
+extern StrBuf *I18nDump;
+void InitTemplateCache(void);
+extern int LoadTemplates;
+
+void LoadMimeBlacklist(void);
/*
- * compress_gzip() uses the same calling syntax as compress2(), but it
- * creates a stream compatible with HTTP "Content-encoding: gzip"
+ * Here's where it all begins.
*/
-#ifdef HAVE_ZLIB
-#define DEF_MEM_LEVEL 8
-#define OS_CODE 0x03 /* unix */
-int ZEXPORT compress_gzip(Bytef * dest, uLongf * destLen,
- const Bytef * source, uLong sourceLen, int level)
+int main(int argc, char **argv)
{
- const int gz_magic[2] = { 0x1f, 0x8b }; /* gzip magic header */
-
- /* write gzip header */
- sprintf((char *) dest, "%c%c%c%c%c%c%c%c%c%c",
- gz_magic[0], gz_magic[1], Z_DEFLATED,
- 0 /*flags */ , 0, 0, 0, 0 /*time */ , 0 /*xflags */ ,
- OS_CODE);
-
- /* normal deflate */
- z_stream stream;
- int err;
- stream.next_in = (Bytef *) source;
- stream.avail_in = (uInt) sourceLen;
- stream.next_out = dest + 10L; // after header
- stream.avail_out = (uInt) * destLen;
- if ((uLong) stream.avail_out != *destLen)
- return Z_BUF_ERROR;
-
- stream.zalloc = (alloc_func) 0;
- stream.zfree = (free_func) 0;
- stream.opaque = (voidpf) 0;
-
- err = deflateInit2(&stream, level, Z_DEFLATED, -MAX_WBITS,
- DEF_MEM_LEVEL, Z_DEFAULT_STRATEGY);
- if (err != Z_OK)
- return err;
-
- err = deflate(&stream, Z_FINISH);
- if (err != Z_STREAM_END) {
- deflateEnd(&stream);
- return err == Z_OK ? Z_BUF_ERROR : err;
- }
- *destLen = stream.total_out + 10L;
-
- /* write CRC and Length */
- uLong crc = crc32(0L, source, sourceLen);
- int n;
- for (n = 0; n < 4; ++n, ++*destLen) {
- dest[*destLen] = (int) (crc & 0xff);
- crc >>= 8;
- }
- uLong len = stream.total_in;
- for (n = 0; n < 4; ++n, ++*destLen) {
- dest[*destLen] = (int) (len & 0xff);
- len >>= 8;
- }
- err = deflateEnd(&stream);
- return err;
-}
+ uid_t UID = -1;
+ size_t basesize = 2; /* how big should strbufs be on creation? */
+ pthread_t SessThread; /* Thread descriptor */
+ pthread_attr_t attr; /* Thread attributes */
+ int a; /* General-purpose variable */
+ char ip_addr[256]="*";
+ int relh=0;
+ int home=0;
+ char relhome[PATH_MAX]="";
+ char webcitdir[PATH_MAX] = DATADIR;
+ char *pidfile = NULL;
+ char *hdir;
+ const char *basedir = NULL;
+ char uds_listen_path[PATH_MAX]; /* listen on a unix domain socket? */
+ const char *I18nDumpFile = NULL;
+
+ WildFireInitBacktrace(argv[0], 2);
+
+ start_modules();
+
+#ifdef DBG_PRINNT_HOOKS_AT_START
+/* dbg_PrintHash(HandlerHash, nix, NULL);*/
#endif
-void end_burst(void)
-{
- size_t the_len;
- char *the_data;
-
- if (WC->burst == NULL)
- return;
-
- the_len = WC->burst_len;
- the_data = WC->burst;
-
- WC->burst_len = 0;
- WC->burst = NULL;
-
-#ifdef HAVE_ZLIB
- /* Handle gzip compression */
- if (WC->gzip_ok) {
- char *compressed_data = NULL;
- uLongf compressed_len;
-
- compressed_len = (uLongf) ((the_len * 101) / 100) + 100;
- compressed_data = malloc(compressed_len);
-
- if (compress_gzip((Bytef *) compressed_data,
- &compressed_len,
- (Bytef *) the_data,
- (uLongf) the_len, Z_BEST_SPEED) == Z_OK) {
- wprintf("Content-encoding: gzip\r\n");
- free(the_data);
- the_data = compressed_data;
- the_len = compressed_len;
- } else {
- free(compressed_data);
- }
- }
-#endif /* HAVE_ZLIB */
-
- wprintf("Content-length: %d\r\n\r\n", the_len);
- client_write(the_data, the_len);
- free(the_data);
- return;
-}
-
-
-
-/*
- * Read data from the client socket with default timeout.
- * (This is implemented in terms of client_read_to() and could be
- * justifiably moved out of sysdep.c)
- */
-int client_read(int sock, char *buf, int bytes)
-{
- return (client_read_to(sock, buf, bytes, SLEEPING));
-}
-
-
-/*
- * client_getln() ... Get a LF-terminated line of text from the client.
- * (This is implemented in terms of client_read() and could be
- * justifiably moved out of sysdep.c)
- */
-int client_getln(int sock, char *buf, int bufsiz)
-{
- int i, retval;
-
- /* Read one character at a time.
- */
- for (i = 0;; i++) {
- retval = client_read(sock, &buf[i], 1);
- if (retval != 1 || buf[i] == '\n' || i == (bufsiz-1))
- break;
- }
-
- /* If we got a long line, discard characters until the newline.
- */
- if (i == (bufsiz-1))
- while (buf[i] != '\n' && retval == 1)
- retval = client_read(sock, &buf[i], 1);
-
- /*
- * Strip any trailing non-printable characters.
- */
- buf[i] = 0;
- while ((strlen(buf) > 0) && (!isprint(buf[strlen(buf) - 1]))) {
- buf[strlen(buf) - 1] = 0;
- }
- return (retval);
-}
-
-
-/*
- * Start running as a daemon. Only close stdio if do_close_stdio is set.
- */
-void start_daemon(int do_close_stdio)
-{
- if (do_close_stdio) {
- /* close(0); */
- close(1);
- close(2);
+ /* Ensure that we are linked to the correct version of libcitadel */
+ if (libcitadel_version_number() < LIBCITADEL_VERSION_NUMBER) {
+ fprintf(stderr, " You are running libcitadel version %d\n", libcitadel_version_number() );
+ fprintf(stderr, "WebCit was compiled against version %d\n", LIBCITADEL_VERSION_NUMBER );
+ return(1);
}
- signal(SIGHUP, SIG_IGN);
- signal(SIGINT, SIG_IGN);
- signal(SIGQUIT, SIG_IGN);
- if (fork() != 0)
- exit(0);
-}
-
-void spawn_another_worker_thread()
-{
- pthread_t SessThread; /* Thread descriptor */
- pthread_attr_t attr; /* Thread attributes */
- int ret;
- lprintf(3, "Creating a new thread\n");
-
- /* set attributes for the new thread */
- pthread_attr_init(&attr);
- pthread_attr_setdetachstate(&attr, PTHREAD_CREATE_DETACHED);
-
- /* Our per-thread stacks need to be bigger than the default size, otherwise
- * the MIME parser crashes on FreeBSD, and the IMAP service crashes on
- * 64-bit Linux.
- */
- if ((ret = pthread_attr_setstacksize(&attr, 1024 * 1024))) {
- lprintf(1, "pthread_attr_setstacksize: %s\n",
- strerror(ret));
- pthread_attr_destroy(&attr);
- }
-
- /* now create the thread */
- if (pthread_create(&SessThread, &attr,
- (void *(*)(void *)) worker_entry, NULL)
- != 0) {
- lprintf(1, "Can't create thread: %s\n", strerror(errno));
- }
-
- /* free up the attributes */
- pthread_attr_destroy(&attr);
-}
-
-/*
- * Here's where it all begins.
- */
-int main(int argc, char **argv)
-{
- pthread_t SessThread; /* Thread descriptor */
- pthread_attr_t attr; /* Thread attributes */
- int a, i; /* General-purpose variables */
- int port = PORT_NUM; /* Port to listen on */
- char tracefile[PATH_MAX];
- char ip_addr[256];
- char *webcitdir = WEBCITDIR;
-#ifdef ENABLE_NLS
- char *locale = NULL;
- char *mo = NULL;
-#endif /* ENABLE_NLS */
+ strcpy(uds_listen_path, "");
/* Parse command line */
#ifdef HAVE_OPENSSL
- while ((a = getopt(argc, argv, "h:i:p:t:x:cfs")) != EOF)
+ while ((a = getopt(argc, argv, "u:h:i:p:t:T:B:x:g:dD:G:cfsS:Z:v:")) != EOF)
#else
- while ((a = getopt(argc, argv, "h:i:p:t:x:cf")) != EOF)
+ while ((a = getopt(argc, argv, "u:h:i:p:t:T:B:x:g:dD:G:cfZ:v:")) != EOF)
#endif
switch (a) {
+ case 'u':
+ UID = atol(optarg);
+ break;
case 'h':
- webcitdir = strdup(optarg);
+ hdir = strdup(optarg);
+ relh=hdir[0]!='/';
+ if (!relh) {
+ safestrncpy(webcitdir, hdir, sizeof webcitdir);
+ }
+ else {
+ safestrncpy(relhome, relhome, sizeof relhome);
+ }
+ /* free(hdir); TODO: SHOULD WE DO THIS? */
+ home=1;
+ break;
+ case 'd':
+ running_as_daemon = 1;
+ break;
+ case 'D':
+ pidfile = strdup(optarg);
+ running_as_daemon = 1;
+ break;
+ case 'g':
+ default_landing_page = strdup(optarg);
+ break;
+ case 'B': /* Basesize */
+ basesize = atoi(optarg);
+ if (basesize > 2)
+ StartLibCitadel(basesize);
break;
case 'i':
safestrncpy(ip_addr, optarg, sizeof ip_addr);
break;
case 'p':
- port = atoi(optarg);
+ http_port = atoi(optarg);
+ if (http_port == 0) {
+ safestrncpy(uds_listen_path, optarg, sizeof uds_listen_path);
+ }
break;
case 't':
- safestrncpy(tracefile, optarg, sizeof tracefile);
- freopen(tracefile, "w", stdout);
- freopen(tracefile, "w", stderr);
- freopen(tracefile, "r", stdin);
+ /* no longer used, but ignored so old scripts don't break */
+ break;
+ case 'T':
+ LoadTemplates = atoi(optarg);
+ dbg_analyze_msg = (LoadTemplates & (1<<1)) != 0;
+ dbg_backtrace_template_errors = (LoadTemplates & (1<<2)) != 0;
+ break;
+ case 'Z':
+ DisableGzip = 1;
break;
case 'x':
- verbosity = atoi(optarg);
+ /* no longer used, but ignored so old scripts don't break */
break;
case 'f':
follow_xff = 1;
if (gethostname
(&server_cookie[strlen(server_cookie)],
200) != 0) {
- lprintf(2, "gethostname: %s\n",
- strerror(errno));
+ syslog(LOG_INFO, "gethostname: %s", strerror(errno));
free(server_cookie);
}
}
break;
+#ifdef HAVE_OPENSSL
case 's':
is_https = 1;
break;
+ case 'S':
+ is_https = 1;
+ ssl_cipher_list = strdup(optarg);
+ break;
+#endif
+ case 'G':
+ DumpTemplateI18NStrings = 1;
+ I18nDump = NewStrBufPlain(HKEY("int templatestrings(void)\n{\n"));
+ I18nDumpFile = optarg;
+ break;
+ case 'v':
+ verbose=1;
+ break;
default:
- fprintf(stderr, "usage: webserver "
+ fprintf(stderr, "usage:\nwebcit "
"[-i ip_addr] [-p http_port] "
- "[-t tracefile] [-c] [-f] "
+ "[-c] [-f] "
+ "[-T Templatedebuglevel] "
+ "[-d] [-Z] [-G i18ndumpfile] "
+ "[-u uid] [-h homedirectory] "
+ "[-D daemonizepid] [-v] "
+ "[-g defaultlandingpage] [-B basesize] "
#ifdef HAVE_OPENSSL
- "[-s] "
+ "[-s] [-S cipher_suites]"
#endif
"[remotehost [remoteport]]\n");
return 1;
}
+ /* Start the logger */
+ openlog("webcit",
+ ( running_as_daemon ? (LOG_PID) : (LOG_PID | LOG_PERROR) ),
+ LOG_DAEMON
+ );
+
if (optind < argc) {
ctdlhost = argv[optind];
if (++optind < argc)
ctdlport = argv[optind];
}
- /* Tell 'em who's in da house */
- lprintf(1, SERVER "\n");
- lprintf(1, "Copyright (C) 1996-2005 by the Citadel development team.\n"
- "This software is distributed under the terms of the "
- "GNU General Public License.\n\n"
- );
- lprintf(9, "Changing directory to %s\n", webcitdir);
- if (chdir(webcitdir) != 0) {
- perror("chdir");
+ /* daemonize, if we were asked to */
+ if (!DumpTemplateI18NStrings && running_as_daemon) {
+ start_daemon(pidfile);
+ }
+ else {
+ signal(SIGINT, graceful_shutdown);
+ signal(SIGHUP, graceful_shutdown);
}
- /* initialize the International Bright Young Thing */
-#ifdef ENABLE_NLS
+ webcit_calc_dirs_n_files(relh, basedir, home, webcitdir, relhome);
+ LoadMimeBlacklist();
+ LoadIconDir(static_icon_dir);
- initialize_locales();
+ /* Tell 'em who's in da house */
+ syslog(LOG_NOTICE, "%s", PACKAGE_STRING);
+ syslog(LOG_NOTICE, "Copyright (C) 1996-2020 by the citadel.org team");
+ syslog(LOG_NOTICE, " ");
+ syslog(LOG_NOTICE, "This program is open source software: you can redistribute it and/or");
+ syslog(LOG_NOTICE, "modify it under the terms of the GNU General Public License, version 3.");
+ syslog(LOG_NOTICE, " ");
+ syslog(LOG_NOTICE, "This program is distributed in the hope that it will be useful,");
+ syslog(LOG_NOTICE, "but WITHOUT ANY WARRANTY; without even the implied warranty of");
+ syslog(LOG_NOTICE, "MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the");
+ syslog(LOG_NOTICE, "GNU General Public License for more details.");
+ syslog(LOG_NOTICE, " ");
+
+ /* initialize various subsystems */
+
+ initialise_modules();
+ initialise2_modules();
+ InitTemplateCache();
+ if (DumpTemplateI18NStrings) {
+ FILE *fd;
+ StrBufAppendBufPlain(I18nDump, HKEY("}\n"), 0);
+ if (StrLength(I18nDump) < 50) {
+ syslog(LOG_INFO, "*******************************************************************\n");
+ syslog(LOG_INFO, "* No strings found in templates! Are you sure they're there? *\n");
+ syslog(LOG_INFO, "*******************************************************************\n");
+ return -1;
+ }
+ fd = fopen(I18nDumpFile, "w");
+ if (fd == NULL) {
+ syslog(LOG_INFO, "***********************************************\n");
+ syslog(LOG_INFO, "* unable to open I18N dumpfile [%s] *\n", I18nDumpFile);
+ syslog(LOG_INFO, "***********************************************\n");
+ return -1;
+ }
+ fwrite(ChrPtr(I18nDump), 1, StrLength(I18nDump), fd);
+ fclose(fd);
+ return 0;
+ }
- locale = setlocale(LC_ALL, "");
+ /* Tell libical to return an error instead of aborting if it sees badly formed iCalendar data. */
- mo = malloc(strlen(webcitdir) + 20);
- sprintf(mo, "%s/locale", webcitdir);
- lprintf(9, "Message catalog directory: %s\n",
- bindtextdomain("webcit", mo)
- );
- free(mo);
- lprintf(9, "Text domain: %s\n",
- textdomain("webcit")
- );
- lprintf(9, "Text domain Charset: %s\n",
- bind_textdomain_codeset("webcit","UTF8")
- );
+#ifdef LIBICAL_ICAL_EXPORT // cheap and sleazy way to detect libical >=2.0
+ icalerror_set_errors_are_fatal(0);
+#else
+ icalerror_errors_are_fatal = 0;
#endif
- initialize_viewdefs();
- initialize_axdefs();
+ /* Use our own prefix on tzid's generated from system tzdata */
+ icaltimezone_set_tzid_prefix("/citadel.org/");
/*
* Set up a place to put thread-specific data.
* wcsession struct to which the thread is currently bound.
*/
if (pthread_key_create(&MyConKey, NULL) != 0) {
- lprintf(1, "Can't create TSD key: %s\n", strerror(errno));
+ syslog(LOG_ERR, "Can't create TSD key: %s", strerror(errno));
}
+ InitialiseSemaphores();
/*
* Set up a place to put thread-specific SSL data.
*/
#ifdef HAVE_OPENSSL
if (pthread_key_create(&ThreadSSL, NULL) != 0) {
- lprintf(1, "Can't create TSD key: %s\n", strerror(errno));
+ syslog(LOG_ERR, "Can't create TSD key: %s", strerror(errno));
}
#endif
/*
* Bind the server to our favorite port.
- * There is no need to check for errors, because ig_tcp_server()
+ * There is no need to check for errors, because webcit_tcp_server()
* exits if it doesn't succeed.
*/
- lprintf(2, "Attempting to bind to port %d...\n", port);
- msock = ig_tcp_server(ip_addr, port, LISTEN_QUEUE_LENGTH);
- lprintf(2, "Listening on socket %d\n", msock);
+
+ if (!IsEmptyStr(uds_listen_path)) {
+ syslog(LOG_DEBUG, "Attempting to create listener socket at %s...", uds_listen_path);
+ msock = webcit_uds_server(uds_listen_path, LISTEN_QUEUE_LENGTH);
+ }
+ else {
+ syslog(LOG_DEBUG, "Attempting to bind to port %d...", http_port);
+ msock = webcit_tcp_server(ip_addr, http_port, LISTEN_QUEUE_LENGTH);
+ }
+ if (msock < 0)
+ {
+ ShutDownWebcit();
+ return -msock;
+ }
+
+ syslog(LOG_INFO, "Listening on socket %d", msock);
signal(SIGPIPE, SIG_IGN);
pthread_mutex_init(&SessionListMutex, NULL);
*/
pthread_attr_init(&attr);
pthread_attr_setdetachstate(&attr, PTHREAD_CREATE_DETACHED);
- pthread_create(&SessThread, &attr,
- (void *(*)(void *)) housekeeping_loop, NULL);
-
+ pthread_create(&SessThread, &attr, (void *(*)(void *)) housekeeping_loop, NULL);
/*
* If this is an HTTPS server, fire up SSL
init_ssl();
}
#endif
+ drop_root(UID);
- /* Start a few initial worker threads */
- for (i = 0; i < (MIN_WORKER_THREADS); ++i) {
- spawn_another_worker_thread();
- }
-
- /* now the original thread becomes another worker */
+ /* Become a worker thread. More worker threads will be spawned as they are needed. */
worker_entry();
+ ShutDownLibCitadel();
return 0;
}
-/*
- * Entry point for worker threads
- */
-void worker_entry(void)
-{
- int ssock;
- int i = 0;
- int time_to_die = 0;
- int fail_this_transaction = 0;
-
- do {
- /* Only one thread can accept at a time */
- fail_this_transaction = 0;
- ssock = accept(msock, NULL, 0);
- if (ssock < 0) {
- lprintf(2, "accept() failed: %s\n",
- strerror(errno));
- } else {
- /* Set the SO_REUSEADDR socket option */
- i = 1;
- setsockopt(ssock, SOL_SOCKET, SO_REUSEADDR,
- &i, sizeof(i));
-
- /* If we are an HTTPS server, go crypto now. */
-#ifdef HAVE_OPENSSL
- if (is_https) {
- if (starttls(ssock) != 0) {
- fail_this_transaction = 1;
- close(ssock);
- }
- }
-#endif
-
- if (fail_this_transaction == 0) {
- /* Perform an HTTP transaction... */
- context_loop(ssock);
- /* ...and close the socket. */
- lingering_close(ssock);
- }
-
- }
- } while (!time_to_die);
- pthread_exit(NULL);
-}
-int lprintf(int loglevel, const char *format, ...)
-{
- va_list ap;
- if (loglevel <= verbosity) {
- va_start(ap, format);
- vfprintf(stderr, format, ap);
- va_end(ap);
- fflush(stderr);
- }
- return 1;
-}