New server option -b to specify the name of a file to which backtrace should be writt...
[citadel.git] / citadel / sysdep.c
index f8a3207094fb0626cac2a1d2be06ac97445476e3..3caa2dcfc004dfa3573ba19c30f2844ce70dfeb4 100644 (file)
-/*
- * $Id$
- *
- * Citadel "system dependent" stuff.
- * See COPYING for copyright information.
- *
- * Here's where we (hopefully) have most parts of the Citadel server that
- * would need to be altered to run the server in a non-POSIX environment.
- * 
- * If we ever port to a different platform and either have multiple
- * variants of this file or simply load it up with #ifdefs.
- *
- */
+// Citadel "system dependent" stuff.
+//
+// Here's where we (hopefully) have most parts of the Citadel server that
+// might need tweaking when run on different operating system variants.
+//
+// Copyright (c) 1987-2021 by the citadel.org team
+//
+// This program is open source software; you can redistribute it and/or modify
+// it under the terms of the GNU General Public License, version 3.
+//
+// This program is distributed in the hope that it will be useful,
+// but WITHOUT ANY WARRANTY; without even the implied warranty of
+// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+// GNU General Public License for more details.
 
 #include "sysdep.h"
 #include <stdlib.h>
 #include <unistd.h>
-#include <stdio.h>
-#include <fcntl.h>
-#include <ctype.h>
-#include <signal.h>
-#include <sys/types.h>
 #include <sys/stat.h>
-#include <sys/wait.h>
-#include <sys/socket.h>
+#include <errno.h>
+#include <signal.h>
+#include <stdio.h>
 #include <syslog.h>
 #include <sys/syslog.h>
-
-#if TIME_WITH_SYS_TIME
-# include <sys/time.h>
-# include <time.h>
-#else
-# if HAVE_SYS_TIME_H
-#  include <sys/time.h>
-# else
-#  include <time.h>
-# endif
-#endif
-
-#include <limits.h>
-#include <sys/resource.h>
+#include <execinfo.h>
+#include <netdb.h>
+#include <sys/un.h>
+#include <sys/types.h>
+#include <sys/socket.h>
 #include <netinet/in.h>
+#include <arpa/inet.h>
 #include <netinet/tcp.h>
 #include <arpa/inet.h>
-#include <netdb.h>
-#include <sys/un.h>
-#include <string.h>
-#include <pwd.h>
-#include <errno.h>
-#include <stdarg.h>
-#include <grp.h>
+#define SHOW_ME_VAPPEND_PRINTF
 #include <libcitadel.h>
-#include "citadel.h"
-#include "server.h"
-#include "sysdep_decls.h"
 #include "citserver.h"
-#include "support.h"
 #include "config.h"
-#include "database.h"
+#include "ctdl_module.h"
+#include "sysdep_decls.h"
+#include "modules/crypto/serv_crypto.h"        // Needed for init_ssl, client_write_ssl, client_read_ssl, destruct_ssl
 #include "housekeeping.h"
-#include "modules/crypto/serv_crypto.h"        /* Needed for init_ssl, client_write_ssl, client_read_ssl, destruct_ssl */
-#include "ecrash.h"
 #include "context.h"
 
-#ifdef HAVE_SYS_SELECT_H
-#include <sys/select.h>
-#endif
-
-#ifndef HAVE_SNPRINTF
-#include "snprintf.h"
-#endif
-
-#include "ctdl_module.h"
-#include "threads.h"
-#include "user_ops.h"
-#include "control.h"
-
-
-#ifdef DEBUG_MEMORY_LEAKS
-struct igheap {
-       struct igheap *next;
-       char file[32];
-       int line;
-       void *block;
-};
-
-struct igheap *igheap = NULL;
-#endif
-
-
-int verbosity = DEFAULT_VERBOSITY;             /* Logging level */
-
-int syslog_facility = LOG_DAEMON;
-int enable_syslog = 0;
+// Signal handler to shut down the server.
+volatile int exit_signal = 0;
+volatile int shutdown_and_halt = 0;
+volatile int restart_server = 0;
+volatile int running_as_daemon = 0;
 
 
-/*
- * CtdlLogPrintf()  ...   Write logging information
- */
-void CtdlLogPrintf(enum LogLevel loglevel, const char *format, ...) {   
-       va_list arg_ptr;
-       va_start(arg_ptr, format);
-       vCtdlLogPrintf(loglevel, format, arg_ptr);
-       va_end(arg_ptr);
-}
+static RETSIGTYPE signal_cleanup(int signum) {
+       syslog(LOG_DEBUG, "sysdep: caught signal %d - backtrace follows:", signum);
 
-void vCtdlLogPrintf(enum LogLevel loglevel, const char *format, va_list arg_ptr)
-{
-       char buf[SIZ], buf2[SIZ];
+       void *bt[1024];
+       int bt_size;
+       char **bt_syms;
+       int i;
+       FILE *backtrace_fp = NULL;
 
-       if (enable_syslog) {
-               vsyslog((syslog_facility | loglevel), format, arg_ptr);
+       if (backtrace_filename != NULL) {
+               backtrace_fp = fopen(backtrace_filename, "w");
        }
 
-       /* stderr output code */
-       if (enable_syslog || running_as_daemon) return;
-
-       /* if we run in forground and syslog is disabled, log to terminal */
-       if (loglevel <= verbosity) { 
-               struct timeval tv;
-               struct tm tim;
-               time_t unixtime;
-               CitContext *CCC = CC;
-
-               gettimeofday(&tv, NULL);
-               /* Promote to time_t; types differ on some OSes (like darwin) */
-               unixtime = tv.tv_sec;
-               localtime_r(&unixtime, &tim);
-               if ((CCC != NULL) && (CCC->cs_pid != 0)) {
-                       sprintf(buf,
-                               "%04d/%02d/%02d %2d:%02d:%02d.%06ld [%3d] ",
-                               tim.tm_year + 1900, tim.tm_mon + 1,
-                               tim.tm_mday, tim.tm_hour, tim.tm_min,
-                               tim.tm_sec, (long)tv.tv_usec,
-                               CCC->cs_pid);
-               } else {
-                       sprintf(buf,
-                               "%04d/%02d/%02d %2d:%02d:%02d.%06ld ",
-                               tim.tm_year + 1900, tim.tm_mon + 1,
-                               tim.tm_mday, tim.tm_hour, tim.tm_min,
-                               tim.tm_sec, (long)tv.tv_usec);
+       bt_size = backtrace(bt, 1024);
+       bt_syms = backtrace_symbols(bt, bt_size);
+       for (i = 1; i < bt_size; i++) {
+               syslog(LOG_DEBUG, "%s", bt_syms[i]);
+               if (backtrace_fp) {
+                       fprintf(backtrace_fp, "%s\n", bt_syms[i]);
                }
-               vsnprintf(buf2, SIZ, format, arg_ptr);   
-
-               fprintf(stderr, "%s%s", buf, buf2);
-               fflush(stderr);
        }
-}   
-
-
-
-/*
- * Signal handler to shut down the server.
- */
-
-volatile int exit_signal = 0;
-volatile int shutdown_and_halt = 0;
-volatile int restart_server = 0;
-volatile int running_as_daemon = 0;
+       free(bt_syms);
 
-static RETSIGTYPE signal_cleanup(int signum) {
-
-       if (CT)
-               CT->signal = signum;
-       else
-       {
-               CtdlLogPrintf(CTDL_DEBUG, "Caught signal %d; shutting down.\n", signum);
-               exit_signal = signum;
+       if (backtrace_fp) {
+               fclose(backtrace_fp);
        }
-}
 
-static RETSIGTYPE signal_exit(int signum) {
-       exit(1);
+       exit_signal = signum;
+       server_shutting_down = 1;
 }
 
 
-
-/*
- * Some initialization stuff...
- */
+// Some initialization stuff...
 void init_sysdep(void) {
        sigset_t set;
 
-       /* Avoid vulnerabilities related to FD_SETSIZE if we can. */
+       // Avoid vulnerabilities related to FD_SETSIZE if we can.
 #ifdef FD_SETSIZE
 #ifdef RLIMIT_NOFILE
        struct rlimit rl;
@@ -192,139 +95,134 @@ void init_sysdep(void) {
 #endif
 #endif
 
-       /* If we've got OpenSSL, we're going to use it. */
+       // If we've got OpenSSL, we're going to use it.
 #ifdef HAVE_OPENSSL
        init_ssl();
 #endif
 
-       /*
-        * Set up a place to put thread-specific data.
-        * We only need a single pointer per thread - it points to the
-        * CitContext structure (in the ContextList linked list) of the
-        * session to which the calling thread is currently bound.
-        */
-       if (citthread_key_create(&MyConKey, NULL) != 0) {
-               CtdlLogPrintf(CTDL_CRIT, "Can't create TSD key: %s\n",
-                       strerror(errno));
+       if (pthread_key_create(&ThreadKey, NULL) != 0) {                        // TSD for threads
+               syslog(LOG_ERR, "pthread_key_create() : %m");
+               abort();
+       }
+       
+       if (pthread_key_create(&MyConKey, NULL) != 0) {                         // TSD for sessions
+               syslog(LOG_CRIT, "sysdep: can't create TSD key: %m");
+               abort();
        }
 
-       /*
-        * The action for unexpected signals and exceptions should be to
-        * call signal_cleanup() to gracefully shut down the server.
-        */
+       // Interript, hangup, and terminate signals should cause the server to shut down.
        sigemptyset(&set);
        sigaddset(&set, SIGINT);
-       sigaddset(&set, SIGQUIT);
        sigaddset(&set, SIGHUP);
        sigaddset(&set, SIGTERM);
-       // sigaddset(&set, SIGSEGV);    commented out because
-       // sigaddset(&set, SIGILL);     we want core dumps
-       // sigaddset(&set, SIGBUS);
+       sigaddset(&set, SIGSEGV);
        sigprocmask(SIG_UNBLOCK, &set, NULL);
 
        signal(SIGINT, signal_cleanup);
-       signal(SIGQUIT, signal_cleanup);
        signal(SIGHUP, signal_cleanup);
        signal(SIGTERM, signal_cleanup);
-       signal(SIGUSR2, signal_exit);
-       // signal(SIGSEGV, signal_cleanup);     commented out because
-       // signal(SIGILL, signal_cleanup);      we want core dumps
-       // signal(SIGBUS, signal_cleanup);
-
-       /*
-        * Do not shut down the server on broken pipe signals, otherwise the
-        * whole Citadel service would come down whenever a single client
-        * socket breaks.
-        */
+       signal(SIGSEGV, signal_cleanup);
+
+       // Do not shut down the server on broken pipe signals, otherwise the
+       // whole Citadel service would come down whenever a single client
+       // socket breaks.
        signal(SIGPIPE, SIG_IGN);
 }
 
 
-
-
-/*
- * This is a generic function to set up a master socket for listening on
- * a TCP port.  The server shuts down if the bind fails.
- *
- */
-int ig_tcp_server(char *ip_addr, int port_number, int queue_len, char **errormessage)
-{
-       struct sockaddr_in sin;
-       int s, i;
-       int actual_queue_len;
-
-       actual_queue_len = queue_len;
-       if (actual_queue_len < 5) actual_queue_len = 5;
-
-       memset(&sin, 0, sizeof(sin));
-       sin.sin_family = AF_INET;
-       sin.sin_port = htons((u_short)port_number);
-       if (ip_addr == NULL) {
-               sin.sin_addr.s_addr = INADDR_ANY;
+// This is a generic function to set up a master socket for listening on
+// a TCP port.  The server shuts down if the bind fails.  (IPv4/IPv6 version)
+//
+// ip_addr     IP address to bind
+// port_number port number to bind
+// queue_len   number of incoming connections to allow in the queue
+int ctdl_tcp_server(char *ip_addr, int port_number, int queue_len) {
+       struct protoent *p;
+       struct sockaddr_in6 sin6;
+       struct sockaddr_in sin4;
+       int s, i, b;
+       int ip_version = 6;
+
+       memset(&sin6, 0, sizeof(sin6));
+       memset(&sin4, 0, sizeof(sin4));
+       sin6.sin6_family = AF_INET6;
+       sin4.sin_family = AF_INET;
+
+       if (    (ip_addr == NULL)                                                       // any IPv6
+               || (IsEmptyStr(ip_addr))
+               || (!strcmp(ip_addr, "*"))
+       ) {
+               ip_version = 6;
+               sin6.sin6_addr = in6addr_any;
        }
-       else {
-               sin.sin_addr.s_addr = inet_addr(ip_addr);
+       else if (!strcmp(ip_addr, "0.0.0.0"))                                           // any IPv4
+       {
+               ip_version = 4;
+               sin4.sin_addr.s_addr = INADDR_ANY;
        }
-                                                                               
-       if (sin.sin_addr.s_addr == !INADDR_ANY) {
-               sin.sin_addr.s_addr = INADDR_ANY;
+       else if ((strchr(ip_addr, '.')) && (!strchr(ip_addr, ':')))                     // specific IPv4
+       {
+               ip_version = 4;
+               if (inet_pton(AF_INET, ip_addr, &sin4.sin_addr) <= 0) {
+                       syslog(LOG_ALERT, "tcpserver: inet_pton: %m");
+                       return (-1);
+               }
+       }
+       else                                                                            // specific IPv6
+       {
+               ip_version = 6;
+               if (inet_pton(AF_INET6, ip_addr, &sin6.sin6_addr) <= 0) {
+                       syslog(LOG_ALERT, "tcpserver: inet_pton: %m");
+                       return (-1);
+               }
        }
 
-       s = socket(PF_INET, SOCK_STREAM, IPPROTO_TCP);
+       if (port_number == 0) {
+               syslog(LOG_ALERT, "tcpserver: no port number was specified");
+               return (-1);
+       }
+       sin6.sin6_port = htons((u_short) port_number);
+       sin4.sin_port = htons((u_short) port_number);
 
-       if (s < 0) {
-               *errormessage = (char*) malloc(SIZ + 1);
-               snprintf(*errormessage, SIZ, 
-                                "citserver: Can't create a socket: %s",
-                                strerror(errno));
-               CtdlLogPrintf(CTDL_EMERG, "%s\n", *errormessage);
-               return(-1);
+       p = getprotobyname("tcp");
+       if (p == NULL) {
+               syslog(LOG_ALERT, "tcpserver: getprotobyname: %m");
+               return (-1);
        }
 
+       s = socket( ((ip_version == 6) ? PF_INET6 : PF_INET), SOCK_STREAM, (p->p_proto));
+       if (s < 0) {
+               syslog(LOG_ALERT, "tcpserver: socket: %m");
+               return (-1);
+       }
+       // Set some socket options that make sense.
        i = 1;
        setsockopt(s, SOL_SOCKET, SO_REUSEADDR, &i, sizeof(i));
 
-       if (bind(s, (struct sockaddr *)&sin, sizeof(sin)) < 0) {
-               *errormessage = (char*) malloc(SIZ + 1);
-               snprintf(*errormessage, SIZ, 
-                                "citserver: Can't bind: %s",
-                                strerror(errno));
-               CtdlLogPrintf(CTDL_EMERG, "%s\n", *errormessage);
-               close(s);
-               return(-1);
+       if (ip_version == 6) {
+               b = bind(s, (struct sockaddr *) &sin6, sizeof(sin6));
        }
-
-       /* set to nonblock - we need this for some obscure situations */
-       if (fcntl(s, F_SETFL, O_NONBLOCK) < 0) {
-               *errormessage = (char*) malloc(SIZ + 1);
-               snprintf(*errormessage, SIZ, 
-                                "citserver: Can't set socket to non-blocking: %s",
-                                strerror(errno));
-               CtdlLogPrintf(CTDL_EMERG, "%s\n", *errormessage);
-               close(s);
-               return(-1);
+       else {
+               b = bind(s, (struct sockaddr *) &sin4, sizeof(sin4));
        }
 
-       if (listen(s, actual_queue_len) < 0) {
-               *errormessage = (char*) malloc(SIZ + 1);
-               snprintf(*errormessage, SIZ, 
-                                "citserver: Can't listen: %s",
-                                strerror(errno));
-               CtdlLogPrintf(CTDL_EMERG, "%s\n", *errormessage);
-               close(s);
-               return(-1);
+       if (b < 0) {
+               syslog(LOG_ALERT, "tcpserver: bind: %m");
+               return (-1);
        }
 
-       return(s);
-}
+       fcntl(s, F_SETFL, O_NONBLOCK);
 
+       if (listen(s, ((queue_len >= 5) ? queue_len : 5) ) < 0) {
+               syslog(LOG_ALERT, "tcpserver: listen: %m");
+               return (-1);
+       }
+       return (s);
+}
 
 
-/*
- * Create a Unix domain socket and listen on it
- */
-int ig_uds_server(char *sockpath, int queue_len, char **errormessage)
-{
+// Create a Unix domain socket and listen on it
+int ctdl_uds_server(char *sockpath, int queue_len) {
        struct sockaddr_un addr;
        int s;
        int i;
@@ -338,10 +236,7 @@ int ig_uds_server(char *sockpath, int queue_len, char **errormessage)
 
        i = unlink(sockpath);
        if ((i != 0) && (errno != ENOENT)) {
-               *errormessage = (char*) malloc(SIZ + 1);
-               snprintf(*errormessage, SIZ, "citserver: can't unlink %s: %s",
-                       sockpath, strerror(errno));
-               CtdlLogPrintf(CTDL_EMERG, "%s\n", *errormessage);
+               syslog(LOG_ERR, "udsserver: %m");
                return(-1);
        }
 
@@ -351,40 +246,24 @@ int ig_uds_server(char *sockpath, int queue_len, char **errormessage)
 
        s = socket(AF_UNIX, SOCK_STREAM, 0);
        if (s < 0) {
-               *errormessage = (char*) malloc(SIZ + 1);
-               snprintf(*errormessage, SIZ, 
-                        "citserver: Can't create a socket: %s",
-                        strerror(errno));
-               CtdlLogPrintf(CTDL_EMERG, "%s\n", *errormessage);
+               syslog(LOG_ERR, "udsserver: socket: %m");
                return(-1);
        }
 
        if (bind(s, (struct sockaddr *)&addr, sizeof(addr)) < 0) {
-               *errormessage = (char*) malloc(SIZ + 1);
-               snprintf(*errormessage, SIZ, 
-                        "citserver: Can't bind: %s",
-                        strerror(errno));
-               CtdlLogPrintf(CTDL_EMERG, "%s\n", *errormessage);
+               syslog(LOG_ERR, "udsserver: bind: %m");
                return(-1);
        }
 
-       /* set to nonblock - we need this for some obscure situations */
+       // set to nonblock - we need this for some obscure situations
        if (fcntl(s, F_SETFL, O_NONBLOCK) < 0) {
-               *errormessage = (char*) malloc(SIZ + 1);
-               snprintf(*errormessage, SIZ, 
-                        "citserver: Can't set socket to non-blocking: %s",
-                        strerror(errno));
-               CtdlLogPrintf(CTDL_EMERG, "%s\n", *errormessage);
+               syslog(LOG_ERR, "udsserver: fcntl: %m");
                close(s);
                return(-1);
        }
 
        if (listen(s, actual_queue_len) < 0) {
-               *errormessage = (char*) malloc(SIZ + 1);
-               snprintf(*errormessage, SIZ, 
-                        "citserver: Can't listen: %s",
-                        strerror(errno));
-               CtdlLogPrintf(CTDL_EMERG, "%s\n", *errormessage);
+               syslog(LOG_ERR, "udsserver: listen: %m");
                return(-1);
        }
 
@@ -397,11 +276,8 @@ int ig_uds_server(char *sockpath, int queue_len, char **errormessage)
 }
 
 
-
-/*
- * The following functions implement output buffering on operating systems which
- * support it (such as Linux and various BSD flavors).
- */
+// The following functions implement output buffering on operating systems which
+// support it (such as Linux and various BSD flavors).
 #ifndef HAVE_DARWIN
 #ifdef TCP_CORK
 #      define HAVE_TCP_BUFFERING
@@ -410,8 +286,8 @@ int ig_uds_server(char *sockpath, int queue_len, char **errormessage)
 #              define HAVE_TCP_BUFFERING
 #              define TCP_CORK TCP_NOPUSH
 #      endif
-#endif /* TCP_CORK */
-#endif /* HAVE_DARWIN */
+#endif // TCP_CORK
+#endif // HAVE_DARWIN
 
 static unsigned on = 1, off = 0;
 
@@ -441,20 +317,20 @@ void flush_output(void) {
 #endif
 }
 
-/*
-static void flush_client_inbuf(void)
-{
-       CitContext *CCC=CC;
 
-       FlushStrBuf(CCC->ReadBuf);
-       CCC->Pos = NULL;
+// close the client socket
+void client_close(void) {
+       CitContext *CCC = CC;
 
+       if (!CCC) return;
+       if (CCC->client_socket <= 0) return;
+       syslog(LOG_DEBUG, "sysdep: closing socket %d", CCC->client_socket);
+       close(CCC->client_socket);
+       CCC->client_socket = -1 ;
 }
-*/
 
-/*
- * client_write()   ...    Send binary data to the client.
- */
+
+// Send binary data to the client.
 int client_write(const char *buf, int nbytes)
 {
        int bytes_written = 0;
@@ -468,8 +344,8 @@ int client_write(const char *buf, int nbytes)
 
        if (nbytes < 1) return(0);
 
-//     flush_client_inbuf();
        Ctx = CC;
+
        if (Ctx->redirect_buffer != NULL) {
                StrBufAppendBufPlain(Ctx->redirect_buffer,
                                     buf, nbytes, 0);
@@ -493,36 +369,28 @@ int client_write(const char *buf, int nbytes)
                        if (select(1, NULL, &wset, NULL, NULL) == -1) {
                                if (errno == EINTR)
                                {
-                                       CtdlLogPrintf(CTDL_DEBUG, "client_write(%d bytes) select() interrupted.\n", nbytes-bytes_written);
-                                       if (CtdlThreadCheckStop()) {
-                                               CC->kill_me = 1;
+                                       syslog(LOG_DEBUG, "sysdep: client_write(%d bytes) select() interrupted.", nbytes-bytes_written);
+                                       if (server_shutting_down) {
+                                               CC->kill_me = KILLME_SELECT_INTERRUPTED;
                                                return (-1);
                                        } else {
-                                               /* can't trust fd's and stuff so we need to re-create them */
+                                               // can't trust fd's and stuff so we need to re-create them
                                                continue;
                                        }
                                } else {
-                                       CtdlLogPrintf(CTDL_ERR,
-                                               "client_write(%d bytes) select failed: %s (%d)\n",
-                                               nbytes - bytes_written,
-                                               strerror(errno), errno);
-                                       cit_backtrace();
-                                       Ctx->kill_me = 1;
+                                       syslog(LOG_ERR, "sysdep: client_write(%d bytes) select failed: %m", nbytes - bytes_written);
+                                       client_close();
+                                       Ctx->kill_me = KILLME_SELECT_FAILED;
                                        return -1;
                                }
                        }
                }
 
-               retval = write(Ctx->client_socket, &buf[bytes_written],
-                       nbytes - bytes_written);
+               retval = write(Ctx->client_socket, &buf[bytes_written], nbytes - bytes_written);
                if (retval < 1) {
-                       CtdlLogPrintf(CTDL_ERR,
-                               "client_write(%d bytes) failed: %s (%d)\n",
-                               nbytes - bytes_written,
-                               strerror(errno), errno);
-                       cit_backtrace();
-                       // CtdlLogPrintf(CTDL_DEBUG, "Tried to send: %s",  &buf[bytes_written]);
-                       Ctx->kill_me = 1;
+                       syslog(LOG_ERR, "sysdep: client_write(%d bytes) failed: %m", nbytes - bytes_written);
+                       client_close();
+                       Ctx->kill_me = KILLME_WRITE_FAILED;
                        return -1;
                }
                bytes_written = bytes_written + retval;
@@ -535,10 +403,8 @@ void cputbuf(const StrBuf *Buf) {
 }   
 
 
-/*
- * cprintf()   Send formatted printable data to the client.
- *             Implemented in terms of client_write() so it's technically not sysdep...
- */
+// Send formatted printable data to the client.
+// Implemented in terms of client_write() so it's technically not sysdep...
 void cprintf(const char *format, ...) {   
        va_list arg_ptr;   
        char buf[1024];
@@ -548,24 +414,21 @@ void cprintf(const char *format, ...) {
                buf[sizeof buf - 2] = '\n';
        client_write(buf, strlen(buf)); 
        va_end(arg_ptr);
-}   
+}
 
 
-/*
- * Read data from the client socket.
- *
- * sock                socket fd to read from
- * buf         buffer to read into 
- * bytes       number of bytes to read
- * timeout     Number of seconds to wait before timing out
- *
- * Possible return values:
- *      1       Requested number of bytes has been read.
- *      0       Request timed out.
- *     -1      Connection is broken, or other error.
- */
-int client_read_blob(StrBuf *Target, int bytes, int timeout)
-{
+// Read data from the client socket.
+//
+// sock                socket fd to read from
+// buf         buffer to read into 
+// bytes       number of bytes to read
+// timeout     Number of seconds to wait before timing out
+//
+// Possible return values:
+//      1       Requested number of bytes has been read.
+//      0       Request timed out.
+//     -1      Connection is broken, or other error.
+int client_read_blob(StrBuf *Target, int bytes, int timeout) {
        CitContext *CCC=CC;
        const char *Error;
        int retval = 0;
@@ -573,45 +436,70 @@ int client_read_blob(StrBuf *Target, int bytes, int timeout)
 #ifdef HAVE_OPENSSL
        if (CCC->redirect_ssl) {
                retval = client_read_sslblob(Target, bytes, timeout);
+               if (retval < 0) {
+                       syslog(LOG_ERR, "sysdep: client_read_blob() failed");
+               }
        }
        else 
 #endif
-
+       {
                retval = StrBufReadBLOBBuffered(Target, 
-                                               CCC->ReadBuf,
-                                               &CCC->Pos,
+                                               CCC->RecvBuf.Buf,
+                                               &CCC->RecvBuf.ReadWritePointer,
                                                &CCC->client_socket,
                                                1, 
                                                bytes,
                                                O_TERM,
-                                               &Error);
-       if (retval < 0) {
-               CtdlLogPrintf(CTDL_CRIT, 
-                             "%s failed: %s\n",
-                             __FUNCTION__,
-                             Error);
+                                               &Error
+               );
+               if (retval < 0) {
+                       syslog(LOG_ERR, "sysdep: client_read_blob() failed: %s", Error);
+                       client_close();
+                       return retval;
+               }
        }
-       else
+       return retval;
+}
+
+
+// to make client_read_random_blob() more efficient, increase buffer size.
+// just use in greeting function, else your buffer may be flushed
+void client_set_inbound_buf(long N)
+{
+       CitContext *CCC=CC;
+       FlushStrBuf(CCC->RecvBuf.Buf);
+       ReAdjustEmptyBuf(CCC->RecvBuf.Buf, N * SIZ, N * SIZ);
+}
+
+int client_read_random_blob(StrBuf *Target, int timeout)
+{
+       CitContext *CCC=CC;
+       int rc;
+
+       rc =  client_read_blob(Target, 1, timeout);
+       if (rc > 0)
        {
-#ifdef BIGBAD_IODBG
-               int rv = 0;
-               char fn [SIZ];
-               FILE *fd;
-
-               snprintf(fn, SIZ, "/tmp/foolog_%s.%d", CCC->ServiceName, CCC->cs_pid);
-
-               fd = fopen(fn, "a+");
-                fprintf(fd, "Read: BufSize: %d BufContent: [",
-                        StrLength(Target));
-               rv = fwrite(ChrPtr(Target), StrLength(Target), 1, fd);
-                fprintf(fd, "]\n");
+               long len;
+               const char *pch;
                
-                       
-                fclose(fd);
-#endif
+               len = StrLength(CCC->RecvBuf.Buf);
+               pch = ChrPtr(CCC->RecvBuf.Buf);
 
+               if (len > 0)
+               {
+                       if (CCC->RecvBuf.ReadWritePointer != NULL) {
+                               len -= CCC->RecvBuf.ReadWritePointer - pch;
+                               pch = CCC->RecvBuf.ReadWritePointer;
+                       }
+                       StrBufAppendBufPlain(Target, pch, len, 0);
+                       FlushStrBuf(CCC->RecvBuf.Buf);
+                       CCC->RecvBuf.ReadWritePointer = NULL;
+                       return StrLength(Target);
+               }
+               return rc;
        }
-       return retval == bytes;
+       else
+               return rc;
 }
 
 int client_read_to(char *buf, int bytes, int timeout)
@@ -636,30 +524,25 @@ int client_read_to(char *buf, int bytes, int timeout)
 }
 
 
-int HaveMoreLinesWaiting(CitContext *CCC)
-{
-       if ((CCC->kill_me == 1) || (
-           (CCC->Pos == NULL) && 
-           (StrLength(CCC->ReadBuf) == 0) && 
-           (CCC->client_socket != -1)) )
+int HaveMoreLinesWaiting(CitContext *CCC) {
+       if ((CCC->kill_me != 0) ||
+           ( (CCC->RecvBuf.ReadWritePointer == NULL) && 
+             (StrLength(CCC->RecvBuf.Buf) == 0) && 
+             (CCC->client_socket != -1)) )
                return 0;
        else
                return 1;
 }
 
 
-/*
- * Read data from the client socket with default timeout.
- * (This is implemented in terms of client_read_to() and could be
- * justifiably moved out of sysdep.c)
- */
-INLINE int client_read(char *buf, int bytes)
-{
-       return(client_read_to(buf, bytes, config.c_sleeping));
+// Read data from the client socket with default timeout.
+// (This is implemented in terms of client_read_to() and could be
+// justifiably moved out of sysdep.c)
+INLINE int client_read(char *buf, int bytes) {
+       return(client_read_to(buf, bytes, CtdlGetConfigInt("c_sleeping")));
 }
 
-int CtdlClientGetLine(StrBuf *Target)
-{
+int CtdlClientGetLine(StrBuf *Target) {
        CitContext *CCC=CC;
        const char *Error;
        int rc;
@@ -667,129 +550,29 @@ int CtdlClientGetLine(StrBuf *Target)
        FlushStrBuf(Target);
 #ifdef HAVE_OPENSSL
        if (CCC->redirect_ssl) {
-#ifdef BIGBAD_IODBG
-               char fn [SIZ];
-               FILE *fd;
-               int len = 0;
-               int rlen = 0;
-               int  nlen = 0;
-               int nrlen = 0;
-               const char *pch;
-
-               snprintf(fn, SIZ, "/tmp/foolog_%s.%d", CCC->ServiceName, CCC->cs_pid);
-
-               fd = fopen(fn, "a+");
-               pch = ChrPtr(CCC->ReadBuf);
-               len = StrLength(CCC->ReadBuf);
-               if (CCC->Pos != NULL)
-                       rlen = CC->Pos - pch;
-               else
-                       rlen = 0;
-
-/*             fprintf(fd, "\n\n\nBufSize: %d BufPos: %d \nBufContent: [%s]\n\n_____________________\n",
-                       len, rlen, pch);
-*/
-               fprintf(fd, "\n\n\nSSL1: BufSize: %d BufPos: %d \n_____________________\n",
-                       len, rlen);
-#endif
-               rc = client_readline_sslbuffer(Target,
-                                              CCC->ReadBuf,
-                                              1);
-#ifdef BIGBAD_IODBG
-                pch = ChrPtr(CCC->ReadBuf);
-                nlen = StrLength(CCC->ReadBuf);
-                if (CCC->Pos != NULL)
-                        nrlen = CC->Pos - pch;
-                else
-                        nrlen = 0;
-/*
-                fprintf(fd, "\n\n\nBufSize: was: %d is: %d BufPos: was: %d is: %d \nBufContent: [%s]\n\n_____________________\n",
-                        len, nlen, rlen, nrlen, pch);
-*/
-                fprintf(fd, "\n\n\nSSL2: BufSize: was: %d is: %d BufPos: was: %d is: %d \n",
-                        len, nlen, rlen, nrlen);
-
-                fprintf(fd, "SSL3: Read: BufSize: %d BufContent: [%s]\n\n*************\n",
-                        StrLength(Target), ChrPtr(Target));
-                fclose(fd);
-
-               if ((rc < 0) && (Error != NULL))
-                       CtdlLogPrintf(CTDL_CRIT, 
-                                     "%s failed: %s\n",
-                                     __FUNCTION__,
-                                     Error);
-#endif
+               rc = client_readline_sslbuffer(Target, CCC->RecvBuf.Buf, &CCC->RecvBuf.ReadWritePointer, 1);
                return rc;
        }
        else 
 #endif
        {
-#ifdef BIGBAD_IODBG
-               char fn [SIZ];
-               FILE *fd;
-               int len, rlen, nlen, nrlen;
-               const char *pch;
-
-               snprintf(fn, SIZ, "/tmp/foolog_%s.%d", CCC->ServiceName, CCC->cs_pid);
-
-               fd = fopen(fn, "a+");
-               pch = ChrPtr(CCC->ReadBuf);
-               len = StrLength(CCC->ReadBuf);
-               if (CCC->Pos != NULL)
-                       rlen = CC->Pos - pch;
-               else
-                       rlen = 0;
-
-/*             fprintf(fd, "\n\n\nBufSize: %d BufPos: %d \nBufContent: [%s]\n\n_____________________\n",
-                       len, rlen, pch);
-*/
-               fprintf(fd, "\n\n\nBufSize: %d BufPos: %d \n_____________________\n",
-                       len, rlen);
-#endif
                rc = StrBufTCP_read_buffered_line_fast(Target, 
-                                                      CCC->ReadBuf,
-                                                      &CCC->Pos,
+                                                      CCC->RecvBuf.Buf,
+                                                      &CCC->RecvBuf.ReadWritePointer,
                                                       &CCC->client_socket,
                                                       5,
                                                       1,
-                                                      &Error);
-
-#ifdef BIGBAD_IODBG
-                pch = ChrPtr(CCC->ReadBuf);
-                nlen = StrLength(CCC->ReadBuf);
-                if (CCC->Pos != NULL)
-                        nrlen = CC->Pos - pch;
-                else
-                        nrlen = 0;
-/*
-                fprintf(fd, "\n\n\nBufSize: was: %d is: %d BufPos: was: %d is: %d \nBufContent: [%s]\n\n_____________________\n",
-                        len, nlen, rlen, nrlen, pch);
-*/
-                fprintf(fd, "\n\n\nBufSize: was: %d is: %d BufPos: was: %d is: %d \n",
-                        len, nlen, rlen, nrlen);
-
-                fprintf(fd, "Read: BufSize: %d BufContent: [%s]\n\n*************\n",
-                        StrLength(Target), ChrPtr(Target));
-                fclose(fd);
-
-               if ((rc < 0) && (Error != NULL))
-                       CtdlLogPrintf(CTDL_CRIT, 
-                                     "%s failed: %s\n",
-                                     __FUNCTION__,
-                                     Error);
-#endif
+                                                      &Error
+               );
                return rc;
        }
 }
 
 
-/*
- * client_getln()   ...   Get a LF-terminated line of text from the client.
- * (This is implemented in terms of client_read() and could be
- * justifiably moved out of sysdep.c)
- */
-int client_getln(char *buf, int bufsize)
-{
+// Get a LF-terminated line of text from the client.
+// (This is implemented in terms of client_read() and could be
+// justifiably moved out of sysdep.c)
+int client_getln(char *buf, int bufsize) {
        int i, retval;
        CitContext *CCC=CC;
        const char *pCh;
@@ -801,8 +584,7 @@ int client_getln(char *buf, int bufsize)
 
        i = StrLength(CCC->MigrateBuf);
        pCh = ChrPtr(CCC->MigrateBuf);
-       /* Strip the trailing LF, and the trailing CR if present.
-        */
+       // Strip the trailing LF, and the trailing CR if present.
        if (bufsize <= i)
                i = bufsize - 1;
        while ( (i > 0)
@@ -821,34 +603,50 @@ int client_getln(char *buf, int bufsize)
 }
 
 
-/*
- * Cleanup any contexts that are left lying around
- */
-
-
-void close_masters (void)
-{
+// Cleanup any contexts that are left lying around
+void close_masters(void) {
        struct ServiceFunctionHook *serviceptr;
-       
-       /*
-        * close all protocol master sockets
-        */
+       const char *Text;
+
+       // close all protocol master sockets
        for (serviceptr = ServiceHookTable; serviceptr != NULL;
            serviceptr = serviceptr->next ) {
 
-               if (serviceptr->tcp_port > 0)
-               {
-                       CtdlLogPrintf(CTDL_INFO, "Closing listener on port %d\n",
-                               serviceptr->tcp_port);
+               if (serviceptr->tcp_port > 0) {
+                       if (serviceptr->msock == -1) {
+                               Text = "not closing again";
+                       }
+                       else {
+                               Text = "Closing";
+                       }
+                       syslog(LOG_INFO, "sysdep: %s %d listener on port %d",
+                              Text,
+                              serviceptr->msock,
+                              serviceptr->tcp_port
+                       );
                        serviceptr->tcp_port = 0;
                }
                
-               if (serviceptr->sockpath != NULL)
-                       CtdlLogPrintf(CTDL_INFO, "Closing listener on '%s'\n",
-                               serviceptr->sockpath);
+               if (serviceptr->sockpath != NULL) {
+                       if (serviceptr->msock == -1) {
+                               Text = "not closing again";
+                       }
+                       else {
+                               Text = "Closing";
+                       }
+                       syslog(LOG_INFO, "sysdep: %s %d listener on '%s'",
+                              Text,
+                              serviceptr->msock,
+                              serviceptr->sockpath
+                       );
+               }
 
-               close(serviceptr->msock);
-               /* If it's a Unix domain socket, remove the file. */
+               if (serviceptr->msock != -1) {
+                       close(serviceptr->msock);
+                       serviceptr->msock = -1;
+               }
+
+               // If it's a Unix domain socket, remove the file.
                if (serviceptr->sockpath != NULL) {
                        unlink(serviceptr->sockpath);
                        serviceptr->sockpath = NULL;
@@ -857,32 +655,13 @@ void close_masters (void)
 }
 
 
-/*
- * The system-dependent part of master_cleanup() - close the master socket.
- */
+// The system-dependent part of master_cleanup() - close the master socket.
 void sysdep_master_cleanup(void) {
-       
        close_masters();
-       
        context_cleanup();
-       
 #ifdef HAVE_OPENSSL
        destruct_ssl();
 #endif
-       CtdlDestroyProtoHooks();
-       CtdlDestroyDeleteHooks();
-       CtdlDestroyXmsgHooks();
-       CtdlDestroyNetprocHooks();
-       CtdlDestroyUserHooks();
-       CtdlDestroyMessageHook();
-       CtdlDestroyCleanupHooks();
-       CtdlDestroyFixedOutputHooks();  
-       CtdlDestroySessionHooks();
-       CtdlDestroyServiceHook();
-       CtdlDestroyRoomHooks();
-       #ifdef HAVE_BACKTRACE
-///    eCrash_Uninit();
-       #endif
 }
 
 
@@ -898,26 +677,17 @@ int nFireUps = 0;
 int nFireUpsNonRestart = 0;
 pid_t ForkedPid = 1;
 
-/*
- * Start running as a daemon.
- */
+// Start running as a daemon.
 void start_daemon(int unused) {
        int status = 0;
        pid_t child = 0;
        FILE *fp;
        int do_restart = 0;
-
        current_child = 0;
 
-       /* Close stdin/stdout/stderr and replace them with /dev/null.
-        * We don't just call close() because we don't want these fd's
-        * to be reused for other files.
-        */
-       if (chdir(ctdl_run_dir) != 0)
-               CtdlLogPrintf(CTDL_EMERG, 
-                             "unable to change into directory [%s]: %s", 
-                             ctdl_run_dir, strerror(errno));
-
+       // Close stdin/stdout/stderr and replace them with /dev/null.
+       // We don't just call close() because we don't want these fd's
+       // to be reused for other files.
        child = fork();
        if (child != 0) {
                exit(0);
@@ -929,28 +699,23 @@ void start_daemon(int unused) {
 
        setsid();
        umask(0);
-        if ((freopen("/dev/null", "r", stdin) != stdin) || 
-           (freopen("/dev/null", "w", stdout) != stdout) || 
-           (freopen("/dev/null", "w", stderr) != stderr))
-               CtdlLogPrintf(CTDL_EMERG, 
-                             "unable to reopen stdin/out/err %s", 
-                             strerror(errno));
-               
+       if (    (freopen("/dev/null", "r", stdin) != stdin) || 
+               (freopen("/dev/null", "w", stdout) != stdout) || 
+               (freopen("/dev/null", "w", stderr) != stderr)
+       ) {
+               syslog(LOG_ERR, "sysdep: unable to reopen stdio: %m");
+       }
 
        do {
                current_child = fork();
-
                signal(SIGTERM, graceful_shutdown);
-       
                if (current_child < 0) {
                        perror("fork");
                        exit(errno);
                }
-       
                else if (current_child == 0) {
-                       return; /* continue starting citadel. */
+                       return; // continue starting citadel.
                }
-       
                else {
                        fp = fopen(file_pid_file, "w");
                        if (fp != NULL) {
@@ -959,20 +724,19 @@ void start_daemon(int unused) {
                        }
                        waitpid(current_child, &status, 0);
                }
-               do_restart = 0;
                nFireUpsNonRestart = nFireUps;
                
-               /* Exit code 0 means the watcher should exit */
+               // Exit code 0 means the watcher should exit
                if (WIFEXITED(status) && (WEXITSTATUS(status) == CTDLEXIT_SHUTDOWN)) {
                        do_restart = 0;
                }
 
-               /* Exit code 101-109 means the watcher should exit */
+               // Exit code 101-109 means the watcher should exit
                else if (WIFEXITED(status) && (WEXITSTATUS(status) >= 101) && (WEXITSTATUS(status) <= 109)) {
                        do_restart = 0;
                }
 
-               /* Any other exit code, or no exit code, means we should restart. */
+               // Any other exit code, or no exit code, means we should restart.
                else {
                        do_restart = 1;
                        nFireUps++;
@@ -986,15 +750,11 @@ void start_daemon(int unused) {
 }
 
 
-
-void checkcrash(void)
-{
-       if (nFireUpsNonRestart != nFireUps)
-       {
+void checkcrash(void) {
+       if (nFireUpsNonRestart != nFireUps) {
                StrBuf *CrashMail;
-
                CrashMail = NewStrBuf();
-               CtdlLogPrintf(CTDL_ALERT, "Posting crash message\n");
+               syslog(LOG_ALERT, "sysdep: posting crash message");
                StrBufPrintf(CrashMail, 
                        " \n"
                        " The Citadel server process (citserver) terminated unexpectedly."
@@ -1003,7 +763,7 @@ void checkcrash(void)
                        "factor.\n \n"
                        " You can obtain more information about this by enabling core dumps.\n \n"
                        " For more information, please see:\n \n"
-                       " http://citadel.org/doku.php/faq:mastering_your_os:gdb#how.do.i.make.my.system.produce.core-files"
+                       " http://citadel.org/doku.php?id=faq:mastering_your_os:gdb#how.do.i.make.my.system.produce.core-files"
                        "\n \n"
 
                        " If you have already done this, the core dump is likely to be found at %score.%d\n"
@@ -1015,13 +775,11 @@ void checkcrash(void)
 }
 
 
-/*
- * Generic routine to convert a login name to a full name (gecos)
- * Returns nonzero if a conversion took place
- */
+// Generic routine to convert a login name to a full name (gecos)
+// Returns nonzero if a conversion took place
 int convert_login(char NameToConvert[]) {
        struct passwd *pw;
-       int a;
+       unsigned int a;
 
        pw = getpwnam(NameToConvert);
        if (pw == NULL) {
@@ -1037,36 +795,78 @@ int convert_login(char NameToConvert[]) {
 }
 
 
+void HuntBadSession(void) {
+       int highest;
+       CitContext *ptr;
+       fd_set readfds;
+       struct timeval tv;
+       struct ServiceFunctionHook *serviceptr;
+
+       // Next, add all of the client sockets
+       begin_critical_section(S_SESSION_TABLE);
+       for (ptr = ContextList; ptr != NULL; ptr = ptr->next) {
+               if ((ptr->state == CON_SYS) && (ptr->client_socket == 0))
+                       continue;
+               // Initialize the fdset.
+               FD_ZERO(&readfds);
+               highest = 0;
+               tv.tv_sec = 0;          // wake up every second if no input
+               tv.tv_usec = 0;
+
+               // Don't select on dead sessions, only truly idle ones
+               if (    (ptr->state == CON_IDLE)
+                       && (ptr->kill_me == 0)
+                       && (ptr->client_socket > 0)
+               ) {
+                       FD_SET(ptr->client_socket, &readfds);
+                       if (ptr->client_socket > highest)
+                               highest = ptr->client_socket;
+                       
+                       if ((select(highest + 1, &readfds, NULL, NULL, &tv) < 0) && (errno == EBADF))
+                       {
+                               // Gotcha!
+                               syslog(LOG_ERR,
+                                      "sysdep: killing session CC[%d] bad FD: [%d] User[%s] Host[%s:%s]",
+                                       ptr->cs_pid,
+                                       ptr->client_socket,
+                                       ptr->curr_user,
+                                       ptr->cs_host,
+                                       ptr->cs_addr
+                               );
+                               ptr->kill_me = 1;
+                               ptr->client_socket = -1;
+                               break;
+                       }
+               }
+       }
+       end_critical_section(S_SESSION_TABLE);
+
+       // First, add the various master sockets to the fdset.
+       for (serviceptr = ServiceHookTable; serviceptr != NULL; serviceptr = serviceptr->next ) {
+
+               // Initialize the fdset.
+               highest = 0;
+               tv.tv_sec = 0;          // wake up every second if no input
+               tv.tv_usec = 0;
 
-/* 
- * This loop just keeps going and going and going...
- */
-/*
- * FIXME:
- * This current implimentation of worker_thread creates a bottle neck in several situations
- * The first thing to remember is that a single thread can handle more than one connection at a time.
- * More threads mean less memory for the system to run in.
- * So for efficiency we want every thread to be doing something useful or waiting in the main loop for
- * something to happen anywhere.
- * This current implimentation requires worker threads to wait in other locations, after it has
- * been committed to a single connection which is very wasteful.
- * As an extreme case consider this:
- * A slow client connects and this slow client sends only one character each second.
- * With this current implimentation a single worker thread is dispatched to handle that connection
- * until such times as the client timeout expires, an error occurs on the socket or the client
- * completes its transmission.
- * THIS IS VERY BAD since that thread could have handled a read from many more clients in each one
- * second interval between chars.
- *
- * It is my intention to re-write this code and the associated client_getln, client_read functions
- * to allow any thread to read data on behalf of any connection (context).
- * To do this I intend to have this main loop read chars into a buffer stored in the context.
- * Once the correct criteria for a full buffer is met then we will dispatch a thread to 
- * process it.
- * This worker thread loop also needs to be able to handle binary data.
- */
-void *worker_thread(void *arg) {
+               FD_SET(serviceptr->msock, &readfds);
+               if (serviceptr->msock > highest) {
+                       highest = serviceptr->msock;
+               }
+               if ((select(highest + 1, &readfds, NULL, NULL, &tv) < 0) &&
+                   (errno == EBADF))
+               {
+                       // Gotcha! server socket dead? commit suicide!
+                       syslog(LOG_ERR, "sysdep: found bad FD: %d and its a server socket! Shutting Down!", serviceptr->msock);
+                       server_shutting_down = 1;
+                       break;
+               }
+       }
+}
+
+
+// This loop just keeps going and going and going...
+void *worker_thread(void *blah) {
        int highest;
        CitContext *ptr;
        CitContext *bind_me = NULL;
@@ -1074,33 +874,48 @@ void *worker_thread(void *arg) {
        int retval = 0;
        struct timeval tv;
        int force_purge = 0;
-       
+       struct ServiceFunctionHook *serviceptr;
+       int ssock;                      // Descriptor for client socket
+       CitContext *con = NULL;         // Temporary context pointer
+       int i;
+
+       pthread_mutex_lock(&ThreadCountMutex);
+       ++num_workers;
+       pthread_mutex_unlock(&ThreadCountMutex);
 
-       while (!CtdlThreadCheckStop()) {
+       while (!server_shutting_down) {
 
-               /* make doubly sure we're not holding any stale db handles
-                * which might cause a deadlock.
-                */
+               // make doubly sure we're not holding any stale db handles which might cause a deadlock
                cdb_check_handles();
 do_select:     force_purge = 0;
-               bind_me = NULL;         /* Which session shall we handle? */
+               bind_me = NULL;         // Which session shall we handle?
 
-               /* Initialize the fdset. */
+               // Initialize the fdset
                FD_ZERO(&readfds);
                highest = 0;
 
+               // First, add the various master sockets to the fdset.
+               for (serviceptr = ServiceHookTable; serviceptr != NULL; serviceptr = serviceptr->next ) {
+                       FD_SET(serviceptr->msock, &readfds);
+                       if (serviceptr->msock > highest) {
+                               highest = serviceptr->msock;
+                       }
+               }
+
+               // Next, add all of the client sockets.
                begin_critical_section(S_SESSION_TABLE);
                for (ptr = ContextList; ptr != NULL; ptr = ptr->next) {
-                       int client_socket;
-                       client_socket = ptr->client_socket;
-                       /* Dont select on dead sessions only truly idle ones */
-                       if ((ptr->state == CON_IDLE) && 
-                           (CC->kill_me == 0) &&
-                           (client_socket != -1))
-                       {
-                               FD_SET(client_socket, &readfds);
-                               if (client_socket > highest)
-                                       highest = client_socket;
+                       if ((ptr->state == CON_SYS) && (ptr->client_socket == 0))
+                           continue;
+
+                       // Don't select on dead sessions, only truly idle ones
+                       if (    (ptr->state == CON_IDLE)
+                               && (ptr->kill_me == 0)
+                               && (ptr->client_socket > 0)
+                       ) {
+                               FD_SET(ptr->client_socket, &readfds);
+                               if (ptr->client_socket > highest)
+                                       highest = ptr->client_socket;
                        }
                        if ((bind_me == NULL) && (ptr->state == CON_READY)) {
                                bind_me = ptr;
@@ -1119,48 +934,96 @@ do_select:       force_purge = 0;
                        goto SKIP_SELECT;
                }
 
-               /* If we got this far, it means that there are no sessions
-                * which a previous thread marked for attention, so we go
-                * ahead and get ready to select().
-                */
+               // If we got this far, it means that there are no sessions
+               // which a previous thread marked for attention, so we go
+               // ahead and get ready to select().
 
-               if (!CtdlThreadCheckStop()) {
-                       tv.tv_sec = 1;          /* wake up every second if no input */
+               if (!server_shutting_down) {
+                       tv.tv_sec = 1;          // wake up every second if no input
                        tv.tv_usec = 0;
-                       retval = CtdlThreadSelect(highest + 1, &readfds, NULL, NULL, &tv);
+                       retval = select(highest + 1, &readfds, NULL, NULL, &tv);
                }
-               else
+               else {
+                       --num_workers;
                        return NULL;
+               }
 
-               /* Now figure out who made this select() unblock.
-                * First, check for an error or exit condition.
-                */
+               // Now figure out who made this select() unblock.
+               // First, check for an error or exit condition.
                if (retval < 0) {
                        if (errno == EBADF) {
-                               CtdlLogPrintf(CTDL_NOTICE, "select() failed: (%s)\n",
-                                       strerror(errno));
+                               syslog(LOG_ERR, "sysdep: select() failed: %m");
+                               HuntBadSession();
                                goto do_select;
                        }
                        if (errno != EINTR) {
-                               CtdlLogPrintf(CTDL_EMERG, "Exiting (%s)\n", strerror(errno));
-                               CtdlThreadStopAll();
+                               syslog(LOG_ERR, "sysdep: exiting: %m");
+                               server_shutting_down = 1;
                                continue;
                        } else {
-                               CtdlLogPrintf(CTDL_DEBUG, "Interrupted CtdlThreadSelect.\n");
-                               if (CtdlThreadCheckStop()) return(NULL);
+                               if (server_shutting_down) {
+                                       --num_workers;
+                                       return(NULL);
+                               }
                                goto do_select;
                        }
                }
-               else if(retval == 0) {
-                       if (CtdlThreadCheckStop()) return(NULL);
+               else if (retval == 0) {
+                       if (server_shutting_down) {
+                               --num_workers;
+                               return(NULL);
+                       }
+               }
+
+               // Next, check to see if it's a new client connecting on a master socket.
+
+               else if ((retval > 0) && (!server_shutting_down)) for (serviceptr = ServiceHookTable; serviceptr != NULL; serviceptr = serviceptr->next) {
+
+                       if (FD_ISSET(serviceptr->msock, &readfds)) {
+                               ssock = accept(serviceptr->msock, NULL, 0);
+                               if (ssock >= 0) {
+                                       syslog(LOG_DEBUG, "sysdep: new client socket %d", ssock);
+
+                                       // The master socket is non-blocking but the client
+                                       // sockets need to be blocking, otherwise certain
+                                       // operations barf on FreeBSD.  Not a fatal error.
+                                       if (fcntl(ssock, F_SETFL, 0) < 0) {
+                                               syslog(LOG_ERR, "sysdep: Can't set socket to blocking: %m");
+                                       }
+
+                                       // New context will be created already
+                                       // set up in the CON_EXECUTING state.
+                                       con = CreateNewContext();
+
+                                       // Assign our new socket number to it.
+                                       con->tcp_port = serviceptr->tcp_port;
+                                       con->client_socket = ssock;
+                                       con->h_command_function = serviceptr->h_command_function;
+                                       con->h_async_function = serviceptr->h_async_function;
+                                       con->h_greeting_function = serviceptr->h_greeting_function;
+                                       con->ServiceName = serviceptr->ServiceName;
+                                       
+                                       // Connections on a local client are always from the same host
+                                       if (serviceptr->sockpath != NULL) {
+                                               con->is_local_client = 1;
+                                       }
+       
+                                       // Set the SO_REUSEADDR socket option
+                                       i = 1;
+                                       setsockopt(ssock, SOL_SOCKET, SO_REUSEADDR, &i, sizeof(i));
+                                       con->state = CON_GREETING;
+                                       retval--;
+                                       if (retval == 0)
+                                               break;
+                               }
+                       }
                }
 
-               /* It must be a client socket.  Find a context that has data
-                * waiting on its socket *and* is in the CON_IDLE state.  Any
-                * active sockets other than our chosen one are marked as
-                * CON_READY so the next thread that comes around can just bind
-                * to one without having to select() again.
-                */
+               // It must be a client socket.  Find a context that has data
+               // waiting on its socket *and* is in the CON_IDLE state.  Any
+               // active sockets other than our chosen one are marked as
+               // CON_READY so the next thread that comes around can just bind
+               // to one without having to select() again.
                begin_critical_section(S_SESSION_TABLE);
                for (ptr = ContextList; ptr != NULL; ptr = ptr->next) {
                        int checkfd = ptr->client_socket;
@@ -1168,7 +1031,7 @@ do_select:        force_purge = 0;
                                if (FD_ISSET(checkfd, &readfds)) {
                                        ptr->input_waiting = 1;
                                        if (!bind_me) {
-                                               bind_me = ptr;  /* I choose you! */
+                                               bind_me = ptr;  // I choose you!
                                                bind_me->state = CON_EXECUTING;
                                        }
                                        else {
@@ -1176,7 +1039,7 @@ do_select:        force_purge = 0;
                                        }
                                } else if ((ptr->is_async) && (ptr->async_waiting) && (ptr->h_async_function)) {
                                        if (!bind_me) {
-                                               bind_me = ptr;  /* I choose you! */
+                                               bind_me = ptr;  // I choose you!
                                                bind_me->state = CON_EXECUTING;
                                        }
                                        else {
@@ -1188,7 +1051,11 @@ do_select:       force_purge = 0;
                end_critical_section(S_SESSION_TABLE);
 
 SKIP_SELECT:
-               /* We're bound to a session */
+               // We're bound to a session
+               pthread_mutex_lock(&ThreadCountMutex);
+               ++active_workers;
+               pthread_mutex_unlock(&ThreadCountMutex);
+
                if (bind_me != NULL) {
                        become_session(bind_me);
 
@@ -1197,7 +1064,7 @@ SKIP_SELECT:
                                begin_session(bind_me);
                                bind_me->h_greeting_function();
                        }
-                       /* If the client has sent a command, execute it. */
+                       // If the client has sent a command, execute it.
                        if (CC->input_waiting) {
                                CC->h_command_function();
 
@@ -1207,14 +1074,12 @@ SKIP_SELECT:
                                CC->input_waiting = 0;
                        }
 
-                       /* If there are asynchronous messages waiting and the
-                        * client supports it, do those now */
-                       if ((CC->is_async) && (CC->async_waiting)
-                          && (CC->h_async_function != NULL)) {
+                       // If there are asynchronous messages waiting and the client supports it, do those now
+                       if ((CC->is_async) && (CC->async_waiting) && (CC->h_async_function != NULL)) {
                                CC->h_async_function();
                                CC->async_waiting = 0;
                        }
-                       
+
                        force_purge = CC->kill_me;
                        become_session(NULL);
                        bind_me->state = CON_IDLE;
@@ -1222,142 +1087,29 @@ SKIP_SELECT:
 
                dead_session_purge(force_purge);
                do_housekeeping();
-       }
-       /* If control reaches this point, the server is shutting down */        
-       return(NULL);
-}
-
 
-
-
-/*
- * A function to handle selecting on master sockets.
- * In other words it handles new connections.
- * It is a thread.
- */
-void *select_on_master (void *arg)
-{
-       struct ServiceFunctionHook *serviceptr;
-       fd_set master_fds;
-       int highest;
-       struct timeval tv;
-       int ssock;                      /* Descriptor for client socket */
-       CitContext *con= NULL;  /* Temporary context pointer */
-       int m;
-       int i;
-       int retval;
-
-       while (!CtdlThreadCheckStop()) {
-               /* Initialize the fdset. */
-               FD_ZERO(&master_fds);
-               highest = 0;
-
-               /* First, add the various master sockets to the fdset. */
-               for (serviceptr = ServiceHookTable; serviceptr != NULL;
-               serviceptr = serviceptr->next ) {
-                       m = serviceptr->msock;
-                       FD_SET(m, &master_fds);
-                       if (m > highest) {
-                               highest = m;
-                       }
-               }
-
-               if (!CtdlThreadCheckStop()) {
-                       tv.tv_sec = 60;         /* wake up every second if no input */
-                       tv.tv_usec = 0;
-                       retval = CtdlThreadSelect(highest + 1, &master_fds, NULL, NULL, &tv);
-               }
-               else
-                       return NULL;
-
-               /* Now figure out who made this select() unblock.
-                * First, check for an error or exit condition.
-                */
-               if (retval < 0) {
-                       if (errno == EBADF) {
-                               CtdlLogPrintf(CTDL_NOTICE, "select() failed: (%s)\n",
-                                       strerror(errno));
-                               continue;
-                       }
-                       if (errno != EINTR) {
-                               CtdlLogPrintf(CTDL_EMERG, "Exiting (%s)\n", strerror(errno));
-                               CtdlThreadStopAll();
-                       } else {
-                               CtdlLogPrintf(CTDL_DEBUG, "Interrupted CtdlThreadSelect.\n");
-                               if (CtdlThreadCheckStop()) return(NULL);
-                               continue;
-                       }
-               }
-               else if(retval == 0) {
-                       if (CtdlThreadCheckStop()) return(NULL);
-                       continue;
-               }
-               /* Next, check to see if it's a new client connecting
-                * on a master socket.
-                */
-               else for (serviceptr = ServiceHookTable; serviceptr != NULL;
-                    serviceptr = serviceptr->next ) {
-
-                       if (FD_ISSET(serviceptr->msock, &master_fds)) {
-                               ssock = accept(serviceptr->msock, NULL, 0);
-                               if (ssock >= 0) {
-                                       CtdlLogPrintf(CTDL_DEBUG,
-                                               "New client socket %d\n",
-                                               ssock);
-
-                                       /* The master socket is non-blocking but the client
-                                        * sockets need to be blocking, otherwise certain
-                                        * operations barf on FreeBSD.  Not a fatal error.
-                                        */
-                                       if (fcntl(ssock, F_SETFL, 0) < 0) {
-                                               CtdlLogPrintf(CTDL_EMERG,
-                                                       "citserver: Can't set socket to blocking: %s\n",
-                                                       strerror(errno));
-                                       }
-
-                                       /* New context will be created already
-                                        * set up in the CON_EXECUTING state.
-                                        */
-                                       con = CreateNewContext();
-
-                                       /* Assign our new socket number to it. */
-                                       con->client_socket = ssock;
-                                       con->h_command_function =
-                                               serviceptr->h_command_function;
-                                       con->h_async_function =
-                                               serviceptr->h_async_function;
-                                       con->h_greeting_function = serviceptr->h_greeting_function;
-                                       con->ServiceName =
-                                               serviceptr->ServiceName;
-                                       
-                                       /* Determine whether it's a local socket */
-                                       if (serviceptr->sockpath != NULL)
-                                               con->is_local_socket = 1;
-       
-                                       /* Set the SO_REUSEADDR socket option */
-                                       i = 1;
-                                       setsockopt(ssock, SOL_SOCKET,
-                                               SO_REUSEADDR,
-                                               &i, sizeof(i));
-
-                                       con->state = CON_GREETING;
-
-                                       retval--;
-                                       if (retval == 0)
-                                               break;
-                               }
-                       }
+               pthread_mutex_lock(&ThreadCountMutex);
+               --active_workers;
+               if ((active_workers + CtdlGetConfigInt("c_min_workers") < num_workers) &&
+                   (num_workers > CtdlGetConfigInt("c_min_workers")))
+               {
+                       num_workers--;
+                       pthread_mutex_unlock(&ThreadCountMutex);
+                       return (NULL);
                }
+               pthread_mutex_unlock(&ThreadCountMutex);
        }
-       return NULL;
-}
 
+       // If control reaches this point, the server is shutting down
+       pthread_mutex_lock(&ThreadCountMutex);
+       --num_workers;
+       pthread_mutex_unlock(&ThreadCountMutex);
+       return(NULL);
+}
 
 
-/*
- * SyslogFacility()
- * Translate text facility name to syslog.h defined value.
- */
+// SyslogFacility()
+// Translate text facility name to syslog.h defined value.
 int SyslogFacility(char *name)
 {
        int i;
@@ -1390,115 +1142,5 @@ int SyslogFacility(char *name)
                if(!strcasecmp(name, facTbl[i].name))
                        return facTbl[i].facility;
        }
-       enable_syslog = 0;
        return LOG_DAEMON;
 }
-
-
-/********** MEM CHEQQER ***********/
-
-#ifdef DEBUG_MEMORY_LEAKS
-
-#undef malloc
-#undef realloc
-#undef strdup
-#undef free
-
-void *tracked_malloc(size_t size, char *file, int line) {
-       struct igheap *thisheap;
-       void *block;
-
-       block = malloc(size);
-       if (block == NULL) return(block);
-
-       thisheap = malloc(sizeof(struct igheap));
-       if (thisheap == NULL) {
-               free(block);
-               return(NULL);
-       }
-
-       thisheap->block = block;
-       strcpy(thisheap->file, file);
-       thisheap->line = line;
-       
-       begin_critical_section(S_DEBUGMEMLEAKS);
-       thisheap->next = igheap;
-       igheap = thisheap;
-       end_critical_section(S_DEBUGMEMLEAKS);
-
-       return(block);
-}
-
-
-void *tracked_realloc(void *ptr, size_t size, char *file, int line) {
-       struct igheap *thisheap;
-       void *block;
-
-       block = realloc(ptr, size);
-       if (block == NULL) return(block);
-
-       thisheap = malloc(sizeof(struct igheap));
-       if (thisheap == NULL) {
-               free(block);
-               return(NULL);
-       }
-
-       thisheap->block = block;
-       strcpy(thisheap->file, file);
-       thisheap->line = line;
-       
-       begin_critical_section(S_DEBUGMEMLEAKS);
-       thisheap->next = igheap;
-       igheap = thisheap;
-       end_critical_section(S_DEBUGMEMLEAKS);
-
-       return(block);
-}
-
-
-
-void tracked_free(void *ptr) {
-       struct igheap *thisheap;
-       struct igheap *trash;
-
-       free(ptr);
-
-       if (igheap == NULL) return;
-       begin_critical_section(S_DEBUGMEMLEAKS);
-       for (thisheap = igheap; thisheap != NULL; thisheap = thisheap->next) {
-               if (thisheap->next != NULL) {
-                       if (thisheap->next->block == ptr) {
-                               trash = thisheap->next;
-                               thisheap->next = thisheap->next->next;
-                               free(trash);
-                       }
-               }
-       }
-       if (igheap->block == ptr) {
-               trash = igheap;
-               igheap = igheap->next;
-               free(trash);
-       }
-       end_critical_section(S_DEBUGMEMLEAKS);
-}
-
-char *tracked_strdup(const char *s, char *file, int line) {
-       char *ptr;
-
-       if (s == NULL) return(NULL);
-       ptr = tracked_malloc(strlen(s) + 1, file, line);
-       if (ptr == NULL) return(NULL);
-       strncpy(ptr, s, strlen(s));
-       return(ptr);
-}
-
-void dump_heap(void) {
-       struct igheap *thisheap;
-
-       for (thisheap = igheap; thisheap != NULL; thisheap = thisheap->next) {
-               CtdlLogPrintf(CTDL_CRIT, "UNFREED: %30s : %d\n",
-                       thisheap->file, thisheap->line);
-       }
-}
-
-#endif /*  DEBUG_MEMORY_LEAKS */