2017-03-09 06:59:57 +08:00
|
|
|
/* $OpenLDAP$ */
|
|
|
|
/* This work is part of OpenLDAP Software <http://www.openldap.org/>.
|
|
|
|
*
|
|
|
|
* Copyright 1998-2015 The OpenLDAP Foundation.
|
|
|
|
* Portions Copyright 2007 by Howard Chu, Symas Corporation.
|
|
|
|
* All rights reserved.
|
|
|
|
*
|
|
|
|
* Redistribution and use in source and binary forms, with or without
|
|
|
|
* modification, are permitted only as authorized by the OpenLDAP
|
|
|
|
* Public License.
|
|
|
|
*
|
|
|
|
* A copy of this license is available in the file LICENSE in the
|
|
|
|
* top-level directory of the distribution or, alternatively, at
|
|
|
|
* <http://www.OpenLDAP.org/license.html>.
|
|
|
|
*/
|
|
|
|
/* Portions Copyright (c) 1995 Regents of the University of Michigan.
|
|
|
|
* All rights reserved.
|
|
|
|
*
|
|
|
|
* Redistribution and use in source and binary forms are permitted
|
|
|
|
* provided that this notice is preserved and that due credit is given
|
|
|
|
* to the University of Michigan at Ann Arbor. The name of the University
|
|
|
|
* may not be used to endorse or promote products derived from this
|
|
|
|
* software without specific prior written permission. This software
|
|
|
|
* is provided ``as is'' without express or implied warranty.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include "portable.h"
|
|
|
|
|
|
|
|
#include <stdio.h>
|
|
|
|
|
|
|
|
#include <ac/ctype.h>
|
|
|
|
#include <ac/errno.h>
|
|
|
|
#include <ac/socket.h>
|
|
|
|
#include <ac/string.h>
|
|
|
|
#include <ac/time.h>
|
|
|
|
#include <ac/unistd.h>
|
|
|
|
|
|
|
|
#include <event2/event.h>
|
2017-03-14 18:42:58 +08:00
|
|
|
#include <event2/dns.h>
|
2017-03-09 06:59:57 +08:00
|
|
|
#include <event2/listener.h>
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
#include "lload.h"
|
2017-03-09 06:59:57 +08:00
|
|
|
#include "ldap_pvt_thread.h"
|
|
|
|
#include "lutil.h"
|
|
|
|
|
|
|
|
#include "ldap_rq.h"
|
|
|
|
|
|
|
|
#ifdef LDAP_PF_LOCAL
|
|
|
|
#include <sys/stat.h>
|
|
|
|
/* this should go in <ldap.h> as soon as it is accepted */
|
|
|
|
#define LDAPI_MOD_URLEXT "x-mod"
|
|
|
|
#endif /* LDAP_PF_LOCAL */
|
|
|
|
|
2018-02-05 17:04:02 +08:00
|
|
|
#ifndef BALANCER_MODULE
|
2017-03-09 06:59:57 +08:00
|
|
|
#ifdef LDAP_PF_INET6
|
|
|
|
int slap_inet4or6 = AF_UNSPEC;
|
|
|
|
#else /* ! INETv6 */
|
|
|
|
int slap_inet4or6 = AF_INET;
|
|
|
|
#endif /* ! INETv6 */
|
|
|
|
|
|
|
|
/* globals */
|
|
|
|
time_t starttime;
|
|
|
|
struct runqueue_s slapd_rq;
|
|
|
|
|
2018-02-05 17:04:02 +08:00
|
|
|
#ifdef LDAP_TCP_BUFFER
|
|
|
|
int slapd_tcp_rmem;
|
|
|
|
int slapd_tcp_wmem;
|
|
|
|
#endif /* LDAP_TCP_BUFFER */
|
|
|
|
|
|
|
|
volatile sig_atomic_t slapd_shutdown = 0;
|
|
|
|
volatile sig_atomic_t slapd_gentle_shutdown = 0;
|
|
|
|
volatile sig_atomic_t slapd_abrupt_shutdown = 0;
|
|
|
|
#endif /* !BALANCER_MODULE */
|
|
|
|
|
|
|
|
static int emfile;
|
|
|
|
|
2018-02-07 20:38:40 +08:00
|
|
|
ldap_pvt_thread_mutex_t lload_wait_mutex;
|
|
|
|
ldap_pvt_thread_cond_t lload_wait_cond;
|
|
|
|
ldap_pvt_thread_cond_t lload_pause_cond;
|
|
|
|
|
2017-03-09 06:59:57 +08:00
|
|
|
#ifndef SLAPD_MAX_DAEMON_THREADS
|
|
|
|
#define SLAPD_MAX_DAEMON_THREADS 16
|
|
|
|
#endif
|
2017-12-18 18:53:39 +08:00
|
|
|
int lload_daemon_threads = 1;
|
|
|
|
int lload_daemon_mask;
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
struct event_base *listener_base = NULL;
|
2017-12-18 18:53:39 +08:00
|
|
|
LloadListener **lload_listeners = NULL;
|
2017-03-09 06:59:57 +08:00
|
|
|
static ldap_pvt_thread_t listener_tid, *daemon_tid;
|
|
|
|
|
2018-02-07 20:30:58 +08:00
|
|
|
struct event_base *daemon_base = NULL;
|
2017-03-14 18:42:58 +08:00
|
|
|
struct evdns_base *dnsbase;
|
|
|
|
|
2017-11-22 21:05:11 +08:00
|
|
|
struct event *lload_timeout_event;
|
|
|
|
|
2018-01-25 19:19:05 +08:00
|
|
|
/*
|
|
|
|
* global lload statistics. Not mutex protected to preserve performance -
|
|
|
|
* increment is atomic, at most we risk a bit of inconsistency
|
|
|
|
*/
|
2018-02-07 18:29:20 +08:00
|
|
|
lload_global_stats_t lload_stats = {};
|
2018-01-25 19:19:05 +08:00
|
|
|
|
2017-03-09 06:59:57 +08:00
|
|
|
#ifndef SLAPD_LISTEN_BACKLOG
|
|
|
|
#define SLAPD_LISTEN_BACKLOG 1024
|
|
|
|
#endif /* ! SLAPD_LISTEN_BACKLOG */
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
#define DAEMON_ID(fd) ( fd & lload_daemon_mask )
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
#ifdef HAVE_WINSOCK
|
|
|
|
ldap_pvt_thread_mutex_t slapd_ws_mutex;
|
|
|
|
SOCKET *slapd_ws_sockets;
|
|
|
|
#define SD_READ 1
|
|
|
|
#define SD_WRITE 2
|
|
|
|
#define SD_ACTIVE 4
|
|
|
|
#define SD_LISTENER 8
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#ifdef HAVE_TCPD
|
|
|
|
static ldap_pvt_thread_mutex_t sd_tcpd_mutex;
|
|
|
|
#endif /* TCP Wrappers */
|
|
|
|
|
|
|
|
typedef struct listener_item {
|
|
|
|
struct evconnlistener *listener;
|
|
|
|
ber_socket_t fd;
|
|
|
|
} listener_item;
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
typedef struct lload_daemon_st {
|
2017-03-09 06:59:57 +08:00
|
|
|
ldap_pvt_thread_mutex_t sd_mutex;
|
|
|
|
|
|
|
|
struct event_base *base;
|
|
|
|
struct event *wakeup_event;
|
2017-12-18 18:53:39 +08:00
|
|
|
} lload_daemon_st;
|
2017-03-09 06:59:57 +08:00
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
static lload_daemon_st lload_daemon[SLAPD_MAX_DAEMON_THREADS];
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
static void daemon_wakeup_cb( evutil_socket_t sig, short what, void *arg );
|
|
|
|
|
|
|
|
static void
|
2017-12-18 18:53:39 +08:00
|
|
|
lloadd_close( ber_socket_t s )
|
2017-03-09 06:59:57 +08:00
|
|
|
{
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_CONNS, "lloadd_close: "
|
2017-06-30 17:10:21 +08:00
|
|
|
"closing fd=%ld\n",
|
2017-03-09 06:59:57 +08:00
|
|
|
(long)s );
|
|
|
|
tcp_close( s );
|
|
|
|
}
|
|
|
|
|
2018-02-07 20:38:40 +08:00
|
|
|
static int
|
|
|
|
lload_base_dispatch( struct event_base *base )
|
|
|
|
{
|
|
|
|
int rc;
|
|
|
|
|
|
|
|
while ( (rc = event_base_dispatch( base )) == 0 ) {
|
|
|
|
if ( event_base_got_exit( base ) ) {
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
Debug( LDAP_DEBUG_TRACE, "lload_base_dispatch: "
|
|
|
|
"handling pause\n" );
|
|
|
|
/*
|
|
|
|
* We are pausing, signal the pausing thread we've finished and
|
|
|
|
* wait until the thread pool resumes operation.
|
|
|
|
*
|
|
|
|
* Do this in lockstep with the pausing thread.
|
|
|
|
*/
|
|
|
|
ldap_pvt_thread_mutex_lock( &lload_wait_mutex );
|
|
|
|
ldap_pvt_thread_cond_signal( &lload_wait_cond );
|
|
|
|
|
|
|
|
/* Now wait until we resume */
|
|
|
|
ldap_pvt_thread_cond_wait( &lload_pause_cond, &lload_wait_mutex );
|
|
|
|
ldap_pvt_thread_mutex_unlock( &lload_wait_mutex );
|
|
|
|
|
|
|
|
Debug( LDAP_DEBUG_TRACE, "lload_base_dispatch: "
|
|
|
|
"resuming\n" );
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( rc ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_base_dispatch: "
|
|
|
|
"event_base_dispatch() returned an error rc=%d\n",
|
|
|
|
rc );
|
|
|
|
}
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2017-03-09 06:59:57 +08:00
|
|
|
static void
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_free_listener_addresses( struct sockaddr **sal )
|
2017-03-09 06:59:57 +08:00
|
|
|
{
|
|
|
|
struct sockaddr **sap;
|
|
|
|
if ( sal == NULL ) return;
|
|
|
|
for ( sap = sal; *sap != NULL; sap++ )
|
|
|
|
ch_free(*sap);
|
|
|
|
ch_free( sal );
|
|
|
|
}
|
|
|
|
|
|
|
|
#if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
|
|
|
|
static int
|
|
|
|
get_url_perms( char **exts, mode_t *perms, int *crit )
|
|
|
|
{
|
|
|
|
int i;
|
|
|
|
|
|
|
|
assert( exts != NULL );
|
|
|
|
assert( perms != NULL );
|
|
|
|
assert( crit != NULL );
|
|
|
|
|
|
|
|
*crit = 0;
|
|
|
|
for ( i = 0; exts[i]; i++ ) {
|
|
|
|
char *type = exts[i];
|
|
|
|
int c = 0;
|
|
|
|
|
|
|
|
if ( type[0] == '!' ) {
|
|
|
|
c = 1;
|
|
|
|
type++;
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( strncasecmp( type, LDAPI_MOD_URLEXT "=",
|
|
|
|
sizeof(LDAPI_MOD_URLEXT "=") - 1 ) == 0 ) {
|
|
|
|
char *value = type + ( sizeof(LDAPI_MOD_URLEXT "=") - 1 );
|
|
|
|
mode_t p = 0;
|
|
|
|
int j;
|
|
|
|
|
|
|
|
switch ( strlen( value ) ) {
|
|
|
|
case 4:
|
|
|
|
/* skip leading '0' */
|
|
|
|
if ( value[0] != '0' ) return LDAP_OTHER;
|
|
|
|
value++;
|
|
|
|
|
|
|
|
case 3:
|
|
|
|
for ( j = 0; j < 3; j++ ) {
|
|
|
|
int v;
|
|
|
|
|
|
|
|
v = value[j] - '0';
|
|
|
|
|
|
|
|
if ( v < 0 || v > 7 ) return LDAP_OTHER;
|
|
|
|
|
|
|
|
p |= v << 3 * ( 2 - j );
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
|
|
|
|
case 10:
|
|
|
|
for ( j = 1; j < 10; j++ ) {
|
|
|
|
static mode_t m[] = { 0, S_IRUSR, S_IWUSR, S_IXUSR,
|
|
|
|
S_IRGRP, S_IWGRP, S_IXGRP, S_IROTH, S_IWOTH,
|
|
|
|
S_IXOTH };
|
|
|
|
static const char c[] = "-rwxrwxrwx";
|
|
|
|
|
|
|
|
if ( value[j] == c[j] ) {
|
|
|
|
p |= m[j];
|
|
|
|
|
|
|
|
} else if ( value[j] != '-' ) {
|
|
|
|
return LDAP_OTHER;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
|
|
|
|
default:
|
|
|
|
return LDAP_OTHER;
|
|
|
|
}
|
|
|
|
|
|
|
|
*crit = c;
|
|
|
|
*perms = p;
|
|
|
|
|
|
|
|
return LDAP_SUCCESS;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return LDAP_OTHER;
|
|
|
|
}
|
|
|
|
#endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
|
|
|
|
|
|
|
|
/* port = 0 indicates AF_LOCAL */
|
|
|
|
static int
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_get_listener_addresses(
|
2017-03-09 06:59:57 +08:00
|
|
|
const char *host,
|
|
|
|
unsigned short port,
|
|
|
|
struct sockaddr ***sal )
|
|
|
|
{
|
|
|
|
struct sockaddr **sap;
|
|
|
|
|
|
|
|
#ifdef LDAP_PF_LOCAL
|
|
|
|
if ( port == 0 ) {
|
|
|
|
sap = *sal = ch_malloc( 2 * sizeof(void *) );
|
|
|
|
|
|
|
|
*sap = ch_calloc( 1, sizeof(struct sockaddr_un) );
|
|
|
|
sap[1] = NULL;
|
|
|
|
|
|
|
|
if ( strlen( host ) >
|
|
|
|
( sizeof( ((struct sockaddr_un *)*sap)->sun_path ) - 1 ) ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_get_listener_addresses: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"domain socket path (%s) too long in URL\n",
|
|
|
|
host );
|
|
|
|
goto errexit;
|
|
|
|
}
|
|
|
|
|
|
|
|
(*sap)->sa_family = AF_LOCAL;
|
|
|
|
strcpy( ((struct sockaddr_un *)*sap)->sun_path, host );
|
|
|
|
} else
|
|
|
|
#endif /* LDAP_PF_LOCAL */
|
|
|
|
{
|
|
|
|
#ifdef HAVE_GETADDRINFO
|
|
|
|
struct addrinfo hints, *res, *sai;
|
|
|
|
int n, err;
|
|
|
|
char serv[7];
|
|
|
|
|
|
|
|
memset( &hints, '\0', sizeof(hints) );
|
|
|
|
hints.ai_flags = AI_PASSIVE;
|
|
|
|
hints.ai_socktype = SOCK_STREAM;
|
|
|
|
hints.ai_family = slap_inet4or6;
|
|
|
|
snprintf( serv, sizeof(serv), "%d", port );
|
|
|
|
|
|
|
|
if ( (err = getaddrinfo( host, serv, &hints, &res )) ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_get_listener_addresses: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"getaddrinfo() failed: %s\n",
|
|
|
|
AC_GAI_STRERROR(err) );
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
sai = res;
|
|
|
|
for ( n = 2; ( sai = sai->ai_next ) != NULL; n++ ) {
|
|
|
|
/* EMPTY */;
|
|
|
|
}
|
|
|
|
sap = *sal = ch_calloc( n, sizeof(void *) );
|
|
|
|
|
|
|
|
*sap = NULL;
|
|
|
|
|
|
|
|
for ( sai = res; sai; sai = sai->ai_next ) {
|
|
|
|
if ( sai->ai_addr == NULL ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_get_listener_addresses: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"getaddrinfo ai_addr is NULL?\n" );
|
|
|
|
freeaddrinfo( res );
|
|
|
|
goto errexit;
|
|
|
|
}
|
|
|
|
|
|
|
|
switch ( sai->ai_family ) {
|
|
|
|
#ifdef LDAP_PF_INET6
|
|
|
|
case AF_INET6:
|
|
|
|
*sap = ch_malloc( sizeof(struct sockaddr_in6) );
|
|
|
|
*(struct sockaddr_in6 *)*sap =
|
|
|
|
*((struct sockaddr_in6 *)sai->ai_addr);
|
|
|
|
break;
|
|
|
|
#endif /* LDAP_PF_INET6 */
|
|
|
|
case AF_INET:
|
|
|
|
*sap = ch_malloc( sizeof(struct sockaddr_in) );
|
|
|
|
*(struct sockaddr_in *)*sap =
|
|
|
|
*((struct sockaddr_in *)sai->ai_addr);
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
*sap = NULL;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( *sap != NULL ) {
|
|
|
|
(*sap)->sa_family = sai->ai_family;
|
|
|
|
sap++;
|
|
|
|
*sap = NULL;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
freeaddrinfo( res );
|
|
|
|
|
|
|
|
#else /* ! HAVE_GETADDRINFO */
|
|
|
|
int i, n = 1;
|
|
|
|
struct in_addr in;
|
|
|
|
struct hostent *he = NULL;
|
|
|
|
|
|
|
|
if ( host == NULL ) {
|
|
|
|
in.s_addr = htonl( INADDR_ANY );
|
|
|
|
|
|
|
|
} else if ( !inet_aton( host, &in ) ) {
|
|
|
|
he = gethostbyname( host );
|
|
|
|
if ( he == NULL ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_get_listener_addresses: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"invalid host %s\n",
|
|
|
|
host );
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
for ( n = 0; he->h_addr_list[n]; n++ ) /* empty */;
|
|
|
|
}
|
|
|
|
|
|
|
|
sap = *sal = ch_malloc( ( n + 1 ) * sizeof(void *) );
|
|
|
|
|
|
|
|
for ( i = 0; i < n; i++ ) {
|
|
|
|
sap[i] = ch_calloc( 1, sizeof(struct sockaddr_in) );
|
|
|
|
sap[i]->sa_family = AF_INET;
|
|
|
|
((struct sockaddr_in *)sap[i])->sin_port = htons( port );
|
|
|
|
AC_MEMCPY( &((struct sockaddr_in *)sap[i])->sin_addr,
|
|
|
|
he ? (struct in_addr *)he->h_addr_list[i] : &in,
|
|
|
|
sizeof(struct in_addr) );
|
|
|
|
}
|
|
|
|
sap[i] = NULL;
|
|
|
|
#endif /* ! HAVE_GETADDRINFO */
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
|
|
|
|
errexit:
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_free_listener_addresses(*sal);
|
2017-03-09 06:59:57 +08:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
static int
|
2018-04-04 23:29:36 +08:00
|
|
|
lload_open_listener(
|
|
|
|
const char *url,
|
|
|
|
LDAPURLDesc *lud,
|
|
|
|
int *listeners,
|
|
|
|
int *cur )
|
2017-03-09 06:59:57 +08:00
|
|
|
{
|
|
|
|
int num, tmp, rc;
|
2017-12-18 18:53:39 +08:00
|
|
|
LloadListener l;
|
|
|
|
LloadListener *li;
|
2017-03-09 06:59:57 +08:00
|
|
|
unsigned short port;
|
|
|
|
int err, addrlen = 0;
|
|
|
|
struct sockaddr **sal = NULL, **psal;
|
|
|
|
int socktype = SOCK_STREAM; /* default to COTS */
|
|
|
|
ber_socket_t s;
|
|
|
|
char ebuf[128];
|
|
|
|
|
|
|
|
#if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
|
|
|
|
/*
|
|
|
|
* use safe defaults
|
|
|
|
*/
|
|
|
|
int crit = 1;
|
|
|
|
#endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
|
|
|
|
|
2018-04-04 23:29:36 +08:00
|
|
|
assert( url );
|
|
|
|
assert( lud );
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
l.sl_url.bv_val = NULL;
|
|
|
|
l.sl_mute = 0;
|
|
|
|
l.sl_busy = 0;
|
|
|
|
|
|
|
|
#ifndef HAVE_TLS
|
|
|
|
if ( ldap_pvt_url_scheme2tls( lud->lud_scheme ) ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_open_listener: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"TLS not supported (%s)\n",
|
|
|
|
url );
|
|
|
|
ldap_free_urldesc( lud );
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( !lud->lud_port ) lud->lud_port = LDAP_PORT;
|
|
|
|
|
|
|
|
#else /* HAVE_TLS */
|
|
|
|
l.sl_is_tls = ldap_pvt_url_scheme2tls( lud->lud_scheme );
|
|
|
|
#endif /* HAVE_TLS */
|
|
|
|
|
|
|
|
#ifdef LDAP_TCP_BUFFER
|
|
|
|
l.sl_tcp_rmem = 0;
|
|
|
|
l.sl_tcp_wmem = 0;
|
|
|
|
#endif /* LDAP_TCP_BUFFER */
|
|
|
|
|
|
|
|
port = (unsigned short)lud->lud_port;
|
|
|
|
|
|
|
|
tmp = ldap_pvt_url_scheme2proto( lud->lud_scheme );
|
|
|
|
if ( tmp == LDAP_PROTO_IPC ) {
|
|
|
|
#ifdef LDAP_PF_LOCAL
|
|
|
|
if ( lud->lud_host == NULL || lud->lud_host[0] == '\0' ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
err = lload_get_listener_addresses( LDAPI_SOCK, 0, &sal );
|
2017-03-09 06:59:57 +08:00
|
|
|
} else {
|
2017-12-18 18:53:39 +08:00
|
|
|
err = lload_get_listener_addresses( lud->lud_host, 0, &sal );
|
2017-03-09 06:59:57 +08:00
|
|
|
}
|
|
|
|
#else /* ! LDAP_PF_LOCAL */
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_open_listener: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"URL scheme not supported: %s\n",
|
|
|
|
url );
|
|
|
|
ldap_free_urldesc( lud );
|
|
|
|
return -1;
|
|
|
|
#endif /* ! LDAP_PF_LOCAL */
|
|
|
|
} else {
|
|
|
|
if ( lud->lud_host == NULL || lud->lud_host[0] == '\0' ||
|
|
|
|
strcmp( lud->lud_host, "*" ) == 0 ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
err = lload_get_listener_addresses( NULL, port, &sal );
|
2017-03-09 06:59:57 +08:00
|
|
|
} else {
|
2017-12-18 18:53:39 +08:00
|
|
|
err = lload_get_listener_addresses( lud->lud_host, port, &sal );
|
2017-03-09 06:59:57 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
#if defined(LDAP_PF_LOCAL) || defined(SLAP_X_LISTENER_MOD)
|
|
|
|
if ( lud->lud_exts ) {
|
|
|
|
err = get_url_perms( lud->lud_exts, &l.sl_perms, &crit );
|
|
|
|
} else {
|
|
|
|
l.sl_perms = S_IRWXU | S_IRWXO;
|
|
|
|
}
|
|
|
|
#endif /* LDAP_PF_LOCAL || SLAP_X_LISTENER_MOD */
|
|
|
|
|
|
|
|
ldap_free_urldesc( lud );
|
|
|
|
if ( err ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_free_listener_addresses( sal );
|
2017-03-09 06:59:57 +08:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* If we got more than one address returned, we need to make space
|
2017-12-18 18:53:39 +08:00
|
|
|
* for it in the lload_listeners array.
|
2017-03-09 06:59:57 +08:00
|
|
|
*/
|
|
|
|
for ( num = 0; sal[num]; num++ ) /* empty */;
|
|
|
|
if ( num > 1 ) {
|
|
|
|
*listeners += num - 1;
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_listeners = ch_realloc( lload_listeners,
|
|
|
|
( *listeners + 1 ) * sizeof(LloadListener *) );
|
2017-03-09 06:59:57 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
psal = sal;
|
|
|
|
while ( *sal != NULL ) {
|
|
|
|
char *af;
|
|
|
|
switch ( (*sal)->sa_family ) {
|
|
|
|
case AF_INET:
|
|
|
|
af = "IPv4";
|
|
|
|
break;
|
|
|
|
#ifdef LDAP_PF_INET6
|
|
|
|
case AF_INET6:
|
|
|
|
af = "IPv6";
|
|
|
|
break;
|
|
|
|
#endif /* LDAP_PF_INET6 */
|
|
|
|
#ifdef LDAP_PF_LOCAL
|
|
|
|
case AF_LOCAL:
|
|
|
|
af = "Local";
|
|
|
|
break;
|
|
|
|
#endif /* LDAP_PF_LOCAL */
|
|
|
|
default:
|
|
|
|
sal++;
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
|
|
|
s = socket( (*sal)->sa_family, socktype, 0 );
|
|
|
|
if ( s == AC_SOCKET_INVALID ) {
|
|
|
|
int err = sock_errno();
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_open_listener: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"%s socket() failed errno=%d (%s)\n",
|
|
|
|
af, err, sock_errstr( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
sal++;
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
ber_pvt_socket_set_nonblock( s, 1 );
|
|
|
|
l.sl_sd = s;
|
|
|
|
|
|
|
|
#ifdef LDAP_PF_LOCAL
|
|
|
|
if ( (*sal)->sa_family == AF_LOCAL ) {
|
|
|
|
unlink( ((struct sockaddr_un *)*sal)->sun_path );
|
|
|
|
} else
|
|
|
|
#endif /* LDAP_PF_LOCAL */
|
|
|
|
{
|
|
|
|
#ifdef SO_REUSEADDR
|
|
|
|
/* enable address reuse */
|
|
|
|
tmp = 1;
|
|
|
|
rc = setsockopt(
|
|
|
|
s, SOL_SOCKET, SO_REUSEADDR, (char *)&tmp, sizeof(tmp) );
|
|
|
|
if ( rc == AC_SOCKET_ERROR ) {
|
|
|
|
int err = sock_errno();
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_open_listener(%ld): "
|
2017-03-09 06:59:57 +08:00
|
|
|
"setsockopt(SO_REUSEADDR) failed errno=%d (%s)\n",
|
|
|
|
(long)l.sl_sd, err,
|
|
|
|
sock_errstr( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
}
|
|
|
|
#endif /* SO_REUSEADDR */
|
|
|
|
}
|
|
|
|
|
|
|
|
switch ( (*sal)->sa_family ) {
|
|
|
|
case AF_INET:
|
|
|
|
addrlen = sizeof(struct sockaddr_in);
|
|
|
|
break;
|
|
|
|
#ifdef LDAP_PF_INET6
|
|
|
|
case AF_INET6:
|
|
|
|
#ifdef IPV6_V6ONLY
|
|
|
|
/* Try to use IPv6 sockets for IPv6 only */
|
|
|
|
tmp = 1;
|
|
|
|
rc = setsockopt( s, IPPROTO_IPV6, IPV6_V6ONLY, (char *)&tmp,
|
|
|
|
sizeof(tmp) );
|
|
|
|
if ( rc == AC_SOCKET_ERROR ) {
|
|
|
|
int err = sock_errno();
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_open_listener(%ld): "
|
2017-03-09 06:59:57 +08:00
|
|
|
"setsockopt(IPV6_V6ONLY) failed errno=%d (%s)\n",
|
|
|
|
(long)l.sl_sd, err,
|
|
|
|
sock_errstr( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
}
|
|
|
|
#endif /* IPV6_V6ONLY */
|
|
|
|
addrlen = sizeof(struct sockaddr_in6);
|
|
|
|
break;
|
|
|
|
#endif /* LDAP_PF_INET6 */
|
|
|
|
|
|
|
|
#ifdef LDAP_PF_LOCAL
|
|
|
|
case AF_LOCAL:
|
|
|
|
#ifdef LOCAL_CREDS
|
|
|
|
{
|
|
|
|
int one = 1;
|
|
|
|
setsockopt( s, 0, LOCAL_CREDS, &one, sizeof(one) );
|
|
|
|
}
|
|
|
|
#endif /* LOCAL_CREDS */
|
|
|
|
|
|
|
|
addrlen = sizeof(struct sockaddr_un);
|
|
|
|
break;
|
|
|
|
#endif /* LDAP_PF_LOCAL */
|
|
|
|
}
|
|
|
|
|
|
|
|
#ifdef LDAP_PF_LOCAL
|
|
|
|
/* create socket with all permissions set for those systems
|
|
|
|
* that honor permissions on sockets (e.g. Linux); typically,
|
|
|
|
* only write is required. To exploit filesystem permissions,
|
|
|
|
* place the socket in a directory and use directory's
|
|
|
|
* permissions. Need write perms to the directory to
|
|
|
|
* create/unlink the socket; likely need exec perms to access
|
|
|
|
* the socket (ITS#4709) */
|
|
|
|
{
|
|
|
|
mode_t old_umask = 0;
|
|
|
|
|
|
|
|
if ( (*sal)->sa_family == AF_LOCAL ) {
|
|
|
|
old_umask = umask( 0 );
|
|
|
|
}
|
|
|
|
#endif /* LDAP_PF_LOCAL */
|
|
|
|
rc = bind( s, *sal, addrlen );
|
|
|
|
#ifdef LDAP_PF_LOCAL
|
|
|
|
if ( old_umask != 0 ) {
|
|
|
|
umask( old_umask );
|
|
|
|
}
|
|
|
|
}
|
|
|
|
#endif /* LDAP_PF_LOCAL */
|
|
|
|
if ( rc ) {
|
|
|
|
err = sock_errno();
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_open_listener: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"bind(%ld) failed errno=%d (%s)\n",
|
|
|
|
(long)l.sl_sd, err,
|
|
|
|
sock_errstr( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
tcp_close( s );
|
|
|
|
sal++;
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
|
|
|
switch ( (*sal)->sa_family ) {
|
|
|
|
#ifdef LDAP_PF_LOCAL
|
|
|
|
case AF_LOCAL: {
|
|
|
|
char *path = ((struct sockaddr_un *)*sal)->sun_path;
|
|
|
|
l.sl_name.bv_len = strlen( path ) + STRLENOF("PATH=");
|
|
|
|
l.sl_name.bv_val = ch_malloc( l.sl_name.bv_len + 1 );
|
|
|
|
snprintf( l.sl_name.bv_val, l.sl_name.bv_len + 1, "PATH=%s",
|
|
|
|
path );
|
|
|
|
} break;
|
|
|
|
#endif /* LDAP_PF_LOCAL */
|
|
|
|
|
|
|
|
case AF_INET: {
|
|
|
|
char addr[INET_ADDRSTRLEN];
|
|
|
|
const char *s;
|
|
|
|
#if defined(HAVE_GETADDRINFO) && defined(HAVE_INET_NTOP)
|
|
|
|
s = inet_ntop( AF_INET,
|
|
|
|
&((struct sockaddr_in *)*sal)->sin_addr, addr,
|
|
|
|
sizeof(addr) );
|
|
|
|
#else /* ! HAVE_GETADDRINFO || ! HAVE_INET_NTOP */
|
|
|
|
s = inet_ntoa( ((struct sockaddr_in *)*sal)->sin_addr );
|
|
|
|
#endif /* ! HAVE_GETADDRINFO || ! HAVE_INET_NTOP */
|
|
|
|
if ( !s ) s = SLAP_STRING_UNKNOWN;
|
|
|
|
port = ntohs( ((struct sockaddr_in *)*sal)->sin_port );
|
|
|
|
l.sl_name.bv_val =
|
|
|
|
ch_malloc( sizeof("IP=255.255.255.255:65535") );
|
|
|
|
snprintf( l.sl_name.bv_val,
|
|
|
|
sizeof("IP=255.255.255.255:65535"), "IP=%s:%d", s,
|
|
|
|
port );
|
|
|
|
l.sl_name.bv_len = strlen( l.sl_name.bv_val );
|
|
|
|
} break;
|
|
|
|
|
|
|
|
#ifdef LDAP_PF_INET6
|
|
|
|
case AF_INET6: {
|
|
|
|
char addr[INET6_ADDRSTRLEN];
|
|
|
|
const char *s;
|
|
|
|
s = inet_ntop( AF_INET6,
|
|
|
|
&((struct sockaddr_in6 *)*sal)->sin6_addr, addr,
|
|
|
|
sizeof(addr) );
|
|
|
|
if ( !s ) s = SLAP_STRING_UNKNOWN;
|
|
|
|
port = ntohs( ((struct sockaddr_in6 *)*sal)->sin6_port );
|
|
|
|
l.sl_name.bv_len = strlen( s ) + sizeof("IP=[]:65535");
|
|
|
|
l.sl_name.bv_val = ch_malloc( l.sl_name.bv_len );
|
|
|
|
snprintf( l.sl_name.bv_val, l.sl_name.bv_len, "IP=[%s]:%d", s,
|
|
|
|
port );
|
|
|
|
l.sl_name.bv_len = strlen( l.sl_name.bv_val );
|
|
|
|
} break;
|
|
|
|
#endif /* LDAP_PF_INET6 */
|
|
|
|
|
|
|
|
default:
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_open_listener: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"unsupported address family (%d)\n",
|
|
|
|
(int)(*sal)->sa_family );
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
AC_MEMCPY( &l.sl_sa, *sal, addrlen );
|
|
|
|
ber_str2bv( url, 0, 1, &l.sl_url );
|
2017-12-18 18:53:39 +08:00
|
|
|
li = ch_malloc( sizeof(LloadListener) );
|
2017-03-09 06:59:57 +08:00
|
|
|
*li = l;
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_listeners[*cur] = li;
|
2017-03-09 06:59:57 +08:00
|
|
|
(*cur)++;
|
|
|
|
sal++;
|
|
|
|
}
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_free_listener_addresses( psal );
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
if ( l.sl_url.bv_val == NULL ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_open_listener: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"failed on %s\n",
|
|
|
|
url );
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_TRACE, "lload_open_listener: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"listener initialized %s\n",
|
|
|
|
l.sl_url.bv_val );
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2018-04-04 23:32:53 +08:00
|
|
|
int
|
|
|
|
lload_open_new_listener( const char *url, LDAPURLDesc *lud )
|
|
|
|
{
|
|
|
|
int rc, i, j = 0;
|
|
|
|
|
|
|
|
for ( i = 0; lload_listeners && lload_listeners[i] != NULL;
|
|
|
|
i++ ) /* count */
|
|
|
|
;
|
|
|
|
j = i;
|
|
|
|
|
|
|
|
i++;
|
|
|
|
lload_listeners = ch_realloc(
|
|
|
|
lload_listeners, ( i + 1 ) * sizeof(LloadListener *) );
|
|
|
|
|
|
|
|
rc = lload_open_listener( url, lud, &i, &j );
|
|
|
|
lload_listeners[j] = NULL;
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2017-03-09 06:59:57 +08:00
|
|
|
int lloadd_inited = 0;
|
|
|
|
|
|
|
|
int
|
2018-04-04 23:29:36 +08:00
|
|
|
lloadd_listeners_init( const char *urls )
|
2017-03-09 06:59:57 +08:00
|
|
|
{
|
|
|
|
int i, j, n;
|
|
|
|
char **u;
|
2018-04-04 23:29:36 +08:00
|
|
|
LDAPURLDesc *lud;
|
2017-03-09 06:59:57 +08:00
|
|
|
|
2018-04-04 23:29:36 +08:00
|
|
|
Debug( LDAP_DEBUG_ARGS, "lloadd_listeners_init: %s\n",
|
2017-03-09 06:59:57 +08:00
|
|
|
urls ? urls : "<null>" );
|
|
|
|
|
|
|
|
#ifdef HAVE_TCPD
|
|
|
|
ldap_pvt_thread_mutex_init( &sd_tcpd_mutex );
|
|
|
|
#endif /* TCP Wrappers */
|
|
|
|
|
|
|
|
if ( urls == NULL ) urls = "ldap:///";
|
|
|
|
|
|
|
|
u = ldap_str2charray( urls, " " );
|
|
|
|
|
|
|
|
if ( u == NULL || u[0] == NULL ) {
|
2018-04-04 23:29:36 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lloadd_listeners_init: "
|
2017-06-20 20:00:31 +08:00
|
|
|
"no urls (%s) provided\n",
|
2017-03-09 06:59:57 +08:00
|
|
|
urls );
|
|
|
|
if ( u ) ldap_charray_free( u );
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
for ( i = 0; u[i] != NULL; i++ ) {
|
2018-04-04 23:29:36 +08:00
|
|
|
Debug( LDAP_DEBUG_TRACE, "lloadd_listeners_init: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"listen on %s\n",
|
|
|
|
u[i] );
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( i == 0 ) {
|
2018-04-04 23:29:36 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lloadd_listeners_init: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"no listeners to open (%s)\n",
|
|
|
|
urls );
|
|
|
|
ldap_charray_free( u );
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2018-04-04 23:29:36 +08:00
|
|
|
Debug( LDAP_DEBUG_TRACE, "lloadd_listeners_init: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"%d listeners to open...\n",
|
|
|
|
i );
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_listeners = ch_malloc( ( i + 1 ) * sizeof(LloadListener *) );
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
for ( n = 0, j = 0; u[n]; n++ ) {
|
2018-04-04 23:29:36 +08:00
|
|
|
if ( ldap_url_parse_ext( u[n], &lud, LDAP_PVT_URL_PARSE_DEF_PORT ) ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "lloadd_listeners_init: "
|
|
|
|
"could not parse url %s\n",
|
|
|
|
u[n] );
|
|
|
|
ldap_charray_free( u );
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( lload_open_listener( u[n], lud, &i, &j ) ) {
|
2017-03-09 06:59:57 +08:00
|
|
|
ldap_charray_free( u );
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
}
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_listeners[j] = NULL;
|
2017-03-09 06:59:57 +08:00
|
|
|
|
2018-04-04 23:29:36 +08:00
|
|
|
Debug( LDAP_DEBUG_TRACE, "lloadd_listeners_init: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"%d listeners opened\n",
|
|
|
|
i );
|
|
|
|
|
|
|
|
ldap_charray_free( u );
|
|
|
|
|
|
|
|
return !i;
|
|
|
|
}
|
|
|
|
|
|
|
|
int
|
2017-12-18 18:53:39 +08:00
|
|
|
lloadd_daemon_destroy( void )
|
2017-03-09 06:59:57 +08:00
|
|
|
{
|
|
|
|
if ( lloadd_inited ) {
|
|
|
|
int i;
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
for ( i = 0; i < lload_daemon_threads; i++ ) {
|
|
|
|
ldap_pvt_thread_mutex_destroy( &lload_daemon[i].sd_mutex );
|
|
|
|
if ( lload_daemon[i].wakeup_event ) {
|
|
|
|
event_free( lload_daemon[i].wakeup_event );
|
2017-05-03 18:07:35 +08:00
|
|
|
}
|
2017-12-18 18:53:39 +08:00
|
|
|
if ( lload_daemon[i].base ) {
|
|
|
|
event_base_free( lload_daemon[i].base );
|
2017-05-03 18:07:35 +08:00
|
|
|
}
|
2017-03-09 06:59:57 +08:00
|
|
|
}
|
2018-03-21 01:21:22 +08:00
|
|
|
|
|
|
|
event_base_free( daemon_base );
|
|
|
|
daemon_base = NULL;
|
|
|
|
|
2017-03-09 06:59:57 +08:00
|
|
|
lloadd_inited = 0;
|
|
|
|
#ifdef HAVE_TCPD
|
|
|
|
ldap_pvt_thread_mutex_destroy( &sd_tcpd_mutex );
|
|
|
|
#endif /* TCP Wrappers */
|
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void
|
|
|
|
destroy_listeners( void )
|
|
|
|
{
|
2017-12-18 18:53:39 +08:00
|
|
|
LloadListener *lr, **ll = lload_listeners;
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
if ( ll == NULL ) return;
|
|
|
|
|
|
|
|
ldap_pvt_thread_join( listener_tid, (void *)NULL );
|
|
|
|
|
|
|
|
while ( (lr = *ll++) != NULL ) {
|
|
|
|
if ( lr->sl_url.bv_val ) {
|
|
|
|
ber_memfree( lr->sl_url.bv_val );
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( lr->sl_name.bv_val ) {
|
|
|
|
ber_memfree( lr->sl_name.bv_val );
|
|
|
|
}
|
|
|
|
|
2017-06-27 23:37:59 +08:00
|
|
|
#ifdef LDAP_PF_LOCAL
|
|
|
|
if ( lr->sl_sa.sa_addr.sa_family == AF_LOCAL ) {
|
|
|
|
unlink( lr->sl_sa.sa_un_addr.sun_path );
|
|
|
|
}
|
|
|
|
#endif /* LDAP_PF_LOCAL */
|
|
|
|
|
2017-03-09 06:59:57 +08:00
|
|
|
evconnlistener_free( lr->listener );
|
|
|
|
|
|
|
|
free( lr );
|
|
|
|
}
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
free( lload_listeners );
|
|
|
|
lload_listeners = NULL;
|
2017-05-03 18:07:35 +08:00
|
|
|
|
|
|
|
if ( listener_base ) {
|
|
|
|
event_base_free( listener_base );
|
|
|
|
}
|
2017-03-09 06:59:57 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
static void
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_listener(
|
2017-03-09 06:59:57 +08:00
|
|
|
struct evconnlistener *listener,
|
|
|
|
ber_socket_t s,
|
|
|
|
struct sockaddr *a,
|
|
|
|
int len,
|
|
|
|
void *arg )
|
|
|
|
{
|
2017-12-18 18:53:39 +08:00
|
|
|
LloadListener *sl = arg;
|
|
|
|
LloadConnection *c;
|
2017-03-09 06:59:57 +08:00
|
|
|
Sockaddr *from = (Sockaddr *)a;
|
|
|
|
#ifdef SLAPD_RLOOKUPS
|
|
|
|
char hbuf[NI_MAXHOST];
|
|
|
|
#endif /* SLAPD_RLOOKUPS */
|
|
|
|
|
|
|
|
const char *peeraddr = NULL;
|
|
|
|
/* we assume INET6_ADDRSTRLEN > INET_ADDRSTRLEN */
|
|
|
|
char addr[INET6_ADDRSTRLEN];
|
|
|
|
#ifdef LDAP_PF_LOCAL
|
|
|
|
char peername[MAXPATHLEN + sizeof("PATH=")];
|
|
|
|
#ifdef LDAP_PF_LOCAL_SENDMSG
|
|
|
|
char peerbuf[8];
|
|
|
|
struct berval peerbv = BER_BVNULL;
|
|
|
|
#endif
|
|
|
|
#elif defined(LDAP_PF_INET6)
|
|
|
|
char peername[sizeof("IP=[ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff]:65535")];
|
|
|
|
#else /* ! LDAP_PF_LOCAL && ! LDAP_PF_INET6 */
|
|
|
|
char peername[sizeof("IP=255.255.255.255:65336")];
|
|
|
|
#endif /* LDAP_PF_LOCAL */
|
|
|
|
int cflag;
|
|
|
|
int tid;
|
|
|
|
char ebuf[128];
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_TRACE, ">>> lload_listener(%s)\n", sl->sl_url.bv_val );
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
peername[0] = '\0';
|
|
|
|
|
|
|
|
/* Resume the listener FD to allow concurrent-processing of
|
|
|
|
* additional incoming connections.
|
|
|
|
*/
|
|
|
|
sl->sl_busy = 0;
|
|
|
|
|
|
|
|
tid = DAEMON_ID(s);
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_CONNS, "lload_listener: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"listen=%ld, new connection fd=%ld\n",
|
|
|
|
(long)sl->sl_sd, (long)s );
|
|
|
|
|
|
|
|
#if defined(SO_KEEPALIVE) || defined(TCP_NODELAY)
|
|
|
|
#ifdef LDAP_PF_LOCAL
|
|
|
|
/* for IPv4 and IPv6 sockets only */
|
|
|
|
if ( from->sa_addr.sa_family != AF_LOCAL )
|
|
|
|
#endif /* LDAP_PF_LOCAL */
|
|
|
|
{
|
|
|
|
int rc;
|
|
|
|
int tmp;
|
|
|
|
#ifdef SO_KEEPALIVE
|
|
|
|
/* enable keep alives */
|
|
|
|
tmp = 1;
|
|
|
|
rc = setsockopt(
|
|
|
|
s, SOL_SOCKET, SO_KEEPALIVE, (char *)&tmp, sizeof(tmp) );
|
|
|
|
if ( rc == AC_SOCKET_ERROR ) {
|
|
|
|
int err = sock_errno();
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener(%ld): "
|
2017-03-09 06:59:57 +08:00
|
|
|
"setsockopt(SO_KEEPALIVE) failed errno=%d (%s)\n",
|
|
|
|
(long)s, err, sock_errstr( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
}
|
|
|
|
#endif /* SO_KEEPALIVE */
|
|
|
|
#ifdef TCP_NODELAY
|
|
|
|
/* enable no delay */
|
|
|
|
tmp = 1;
|
|
|
|
rc = setsockopt(
|
|
|
|
s, IPPROTO_TCP, TCP_NODELAY, (char *)&tmp, sizeof(tmp) );
|
|
|
|
if ( rc == AC_SOCKET_ERROR ) {
|
|
|
|
int err = sock_errno();
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener(%ld): "
|
2017-03-09 06:59:57 +08:00
|
|
|
"setsockopt(TCP_NODELAY) failed errno=%d (%s)\n",
|
|
|
|
(long)s, err, sock_errstr( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
}
|
|
|
|
#endif /* TCP_NODELAY */
|
|
|
|
}
|
|
|
|
#endif /* SO_KEEPALIVE || TCP_NODELAY */
|
|
|
|
|
|
|
|
cflag = 0;
|
|
|
|
switch ( from->sa_addr.sa_family ) {
|
|
|
|
#ifdef LDAP_PF_LOCAL
|
|
|
|
case AF_LOCAL:
|
|
|
|
cflag |= CONN_IS_IPC;
|
|
|
|
|
|
|
|
/* FIXME: apparently accept doesn't fill the sun_path member */
|
|
|
|
sprintf( peername, "PATH=%s", sl->sl_sa.sa_un_addr.sun_path );
|
|
|
|
break;
|
|
|
|
#endif /* LDAP_PF_LOCAL */
|
|
|
|
|
|
|
|
#ifdef LDAP_PF_INET6
|
|
|
|
case AF_INET6:
|
|
|
|
if ( IN6_IS_ADDR_V4MAPPED( &from->sa_in6_addr.sin6_addr ) ) {
|
|
|
|
#if defined(HAVE_GETADDRINFO) && defined(HAVE_INET_NTOP)
|
|
|
|
peeraddr = inet_ntop( AF_INET,
|
|
|
|
( (struct in_addr *)&from->sa_in6_addr.sin6_addr
|
|
|
|
.s6_addr[12] ),
|
|
|
|
addr, sizeof(addr) );
|
|
|
|
#else /* ! HAVE_GETADDRINFO || ! HAVE_INET_NTOP */
|
|
|
|
peeraddr = inet_ntoa( *( (struct in_addr *)&from->sa_in6_addr
|
|
|
|
.sin6_addr.s6_addr[12] ) );
|
|
|
|
#endif /* ! HAVE_GETADDRINFO || ! HAVE_INET_NTOP */
|
|
|
|
if ( !peeraddr ) peeraddr = SLAP_STRING_UNKNOWN;
|
|
|
|
sprintf( peername, "IP=%s:%d", peeraddr,
|
|
|
|
(unsigned)ntohs( from->sa_in6_addr.sin6_port ) );
|
|
|
|
} else {
|
|
|
|
peeraddr = inet_ntop( AF_INET6, &from->sa_in6_addr.sin6_addr,
|
|
|
|
addr, sizeof(addr) );
|
|
|
|
if ( !peeraddr ) peeraddr = SLAP_STRING_UNKNOWN;
|
|
|
|
sprintf( peername, "IP=[%s]:%d", peeraddr,
|
|
|
|
(unsigned)ntohs( from->sa_in6_addr.sin6_port ) );
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
#endif /* LDAP_PF_INET6 */
|
|
|
|
|
|
|
|
case AF_INET: {
|
|
|
|
#if defined(HAVE_GETADDRINFO) && defined(HAVE_INET_NTOP)
|
|
|
|
peeraddr = inet_ntop(
|
|
|
|
AF_INET, &from->sa_in_addr.sin_addr, addr, sizeof(addr) );
|
|
|
|
#else /* ! HAVE_GETADDRINFO || ! HAVE_INET_NTOP */
|
|
|
|
peeraddr = inet_ntoa( from->sa_in_addr.sin_addr );
|
|
|
|
#endif /* ! HAVE_GETADDRINFO || ! HAVE_INET_NTOP */
|
|
|
|
if ( !peeraddr ) peeraddr = SLAP_STRING_UNKNOWN;
|
|
|
|
sprintf( peername, "IP=%s:%d", peeraddr,
|
|
|
|
(unsigned)ntohs( from->sa_in_addr.sin_port ) );
|
|
|
|
} break;
|
|
|
|
|
|
|
|
default:
|
2017-12-18 18:53:39 +08:00
|
|
|
lloadd_close( s );
|
2017-03-09 06:59:57 +08:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
#ifdef HAVE_TLS
|
|
|
|
if ( sl->sl_is_tls ) cflag |= CONN_IS_TLS;
|
|
|
|
#endif
|
2017-12-18 18:53:39 +08:00
|
|
|
c = client_init( s, sl, peername, lload_daemon[tid].base, cflag );
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
if ( !c ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener: "
|
2017-06-20 20:00:31 +08:00
|
|
|
"client_init(%ld, %s, %s) failed\n",
|
2017-03-09 06:59:57 +08:00
|
|
|
(long)s, peername, sl->sl_name.bv_val );
|
2017-12-18 18:53:39 +08:00
|
|
|
lloadd_close( s );
|
2017-03-09 06:59:57 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void *
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_listener_thread( void *ctx )
|
2017-03-09 06:59:57 +08:00
|
|
|
{
|
2018-02-07 20:38:40 +08:00
|
|
|
int rc = lload_base_dispatch( listener_base );
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener_thread: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"event loop finished: rc=%d\n",
|
|
|
|
rc );
|
|
|
|
|
|
|
|
return (void *)NULL;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void
|
|
|
|
listener_error_cb( struct evconnlistener *lev, void *arg )
|
|
|
|
{
|
2017-12-18 18:53:39 +08:00
|
|
|
LloadListener *l = arg;
|
2017-03-09 06:59:57 +08:00
|
|
|
int err = EVUTIL_SOCKET_ERROR();
|
|
|
|
|
|
|
|
assert( l->listener == lev );
|
|
|
|
if (
|
|
|
|
#ifdef EMFILE
|
|
|
|
err == EMFILE ||
|
|
|
|
#endif /* EMFILE */
|
|
|
|
#ifdef ENFILE
|
|
|
|
err == ENFILE ||
|
|
|
|
#endif /* ENFILE */
|
|
|
|
0 ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
ldap_pvt_thread_mutex_lock( &lload_daemon[0].sd_mutex );
|
2017-03-09 06:59:57 +08:00
|
|
|
emfile++;
|
|
|
|
/* Stop listening until an existing session closes */
|
|
|
|
l->sl_mute = 1;
|
|
|
|
evconnlistener_disable( lev );
|
2017-12-18 18:53:39 +08:00
|
|
|
ldap_pvt_thread_mutex_unlock( &lload_daemon[0].sd_mutex );
|
2017-06-27 23:37:59 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "listener_error_cb: "
|
|
|
|
"too many open files, cannot accept new connections on "
|
|
|
|
"url=%s\n",
|
|
|
|
l->sl_url.bv_val );
|
2017-03-09 06:59:57 +08:00
|
|
|
} else {
|
|
|
|
char ebuf[128];
|
|
|
|
Debug( LDAP_DEBUG_ANY, "listener_error_cb: "
|
|
|
|
"received an error on a listener, shutting down: '%s'\n",
|
|
|
|
sock_errstr( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
event_base_loopexit( l->base, NULL );
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2017-06-27 23:37:59 +08:00
|
|
|
void
|
|
|
|
listeners_reactivate( void )
|
|
|
|
{
|
|
|
|
int i;
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
ldap_pvt_thread_mutex_lock( &lload_daemon[0].sd_mutex );
|
|
|
|
for ( i = 0; emfile && lload_listeners[i] != NULL; i++ ) {
|
|
|
|
LloadListener *lr = lload_listeners[i];
|
2017-06-27 23:37:59 +08:00
|
|
|
|
|
|
|
if ( lr->sl_sd == AC_SOCKET_INVALID ) continue;
|
|
|
|
if ( lr->sl_mute ) {
|
|
|
|
emfile--;
|
|
|
|
evconnlistener_enable( lr->listener );
|
|
|
|
lr->sl_mute = 0;
|
|
|
|
Debug( LDAP_DEBUG_CONNS, "listeners_reactivate: "
|
|
|
|
"reactivated listener url=%s\n",
|
|
|
|
lr->sl_url.bv_val );
|
|
|
|
}
|
|
|
|
}
|
2017-12-18 18:53:39 +08:00
|
|
|
if ( emfile && lload_listeners[i] == NULL ) {
|
2017-06-27 23:37:59 +08:00
|
|
|
/* Walked the entire list without enabling anything; emfile
|
|
|
|
* counter is stale. Reset it. */
|
|
|
|
emfile = 0;
|
|
|
|
}
|
2017-12-18 18:53:39 +08:00
|
|
|
ldap_pvt_thread_mutex_unlock( &lload_daemon[0].sd_mutex );
|
2017-06-27 23:37:59 +08:00
|
|
|
}
|
|
|
|
|
2017-03-09 06:59:57 +08:00
|
|
|
static int
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_listener_activate( void )
|
2017-03-09 06:59:57 +08:00
|
|
|
{
|
|
|
|
struct evconnlistener *listener;
|
|
|
|
int l, rc;
|
|
|
|
char ebuf[128];
|
|
|
|
|
|
|
|
listener_base = event_base_new();
|
|
|
|
if ( !listener_base ) return -1;
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
for ( l = 0; lload_listeners[l] != NULL; l++ ) {
|
|
|
|
if ( lload_listeners[l]->sl_sd == AC_SOCKET_INVALID ) continue;
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
/* FIXME: TCP-only! */
|
|
|
|
#ifdef LDAP_TCP_BUFFER
|
|
|
|
if ( 1 ) {
|
|
|
|
int origsize, size, realsize, rc;
|
|
|
|
socklen_t optlen;
|
|
|
|
|
|
|
|
size = 0;
|
2017-12-18 18:53:39 +08:00
|
|
|
if ( lload_listeners[l]->sl_tcp_rmem > 0 ) {
|
|
|
|
size = lload_listeners[l]->sl_tcp_rmem;
|
2017-03-09 06:59:57 +08:00
|
|
|
} else if ( slapd_tcp_rmem > 0 ) {
|
|
|
|
size = slapd_tcp_rmem;
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( size > 0 ) {
|
|
|
|
optlen = sizeof(origsize);
|
2017-12-18 18:53:39 +08:00
|
|
|
rc = getsockopt( lload_listeners[l]->sl_sd, SOL_SOCKET,
|
2017-03-09 06:59:57 +08:00
|
|
|
SO_RCVBUF, (void *)&origsize, &optlen );
|
|
|
|
|
|
|
|
if ( rc ) {
|
|
|
|
int err = sock_errno();
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener_activate: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"getsockopt(SO_RCVBUF) failed errno=%d (%s)\n",
|
|
|
|
err, AC_STRERROR_R( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
}
|
|
|
|
|
|
|
|
optlen = sizeof(size);
|
2017-12-18 18:53:39 +08:00
|
|
|
rc = setsockopt( lload_listeners[l]->sl_sd, SOL_SOCKET,
|
2017-03-09 06:59:57 +08:00
|
|
|
SO_RCVBUF, (const void *)&size, optlen );
|
|
|
|
|
|
|
|
if ( rc ) {
|
|
|
|
int err = sock_errno();
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener_activate: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"setsockopt(SO_RCVBUF) failed errno=%d (%s)\n",
|
|
|
|
err, sock_errstr( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
}
|
|
|
|
|
|
|
|
optlen = sizeof(realsize);
|
2017-12-18 18:53:39 +08:00
|
|
|
rc = getsockopt( lload_listeners[l]->sl_sd, SOL_SOCKET,
|
2017-03-09 06:59:57 +08:00
|
|
|
SO_RCVBUF, (void *)&realsize, &optlen );
|
|
|
|
|
|
|
|
if ( rc ) {
|
|
|
|
int err = sock_errno();
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener_activate: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"getsockopt(SO_RCVBUF) failed errno=%d (%s)\n",
|
|
|
|
err, sock_errstr( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
}
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener_activate: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"url=%s (#%d) RCVBUF original size=%d requested "
|
|
|
|
"size=%d real size=%d\n",
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_listeners[l]->sl_url.bv_val, l, origsize, size,
|
2017-03-09 06:59:57 +08:00
|
|
|
realsize );
|
|
|
|
}
|
|
|
|
|
|
|
|
size = 0;
|
2017-12-18 18:53:39 +08:00
|
|
|
if ( lload_listeners[l]->sl_tcp_wmem > 0 ) {
|
|
|
|
size = lload_listeners[l]->sl_tcp_wmem;
|
2017-03-09 06:59:57 +08:00
|
|
|
} else if ( slapd_tcp_wmem > 0 ) {
|
|
|
|
size = slapd_tcp_wmem;
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( size > 0 ) {
|
|
|
|
optlen = sizeof(origsize);
|
2017-12-18 18:53:39 +08:00
|
|
|
rc = getsockopt( lload_listeners[l]->sl_sd, SOL_SOCKET,
|
2017-03-09 06:59:57 +08:00
|
|
|
SO_SNDBUF, (void *)&origsize, &optlen );
|
|
|
|
|
|
|
|
if ( rc ) {
|
|
|
|
int err = sock_errno();
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener_activate: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"getsockopt(SO_SNDBUF) failed errno=%d (%s)\n",
|
|
|
|
err, sock_errstr( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
}
|
|
|
|
|
|
|
|
optlen = sizeof(size);
|
2017-12-18 18:53:39 +08:00
|
|
|
rc = setsockopt( lload_listeners[l]->sl_sd, SOL_SOCKET,
|
2017-03-09 06:59:57 +08:00
|
|
|
SO_SNDBUF, (const void *)&size, optlen );
|
|
|
|
|
|
|
|
if ( rc ) {
|
|
|
|
int err = sock_errno();
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener_activate: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"setsockopt(SO_SNDBUF) failed errno=%d (%s)\n",
|
|
|
|
err, sock_errstr( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
}
|
|
|
|
|
|
|
|
optlen = sizeof(realsize);
|
2017-12-18 18:53:39 +08:00
|
|
|
rc = getsockopt( lload_listeners[l]->sl_sd, SOL_SOCKET,
|
2017-03-09 06:59:57 +08:00
|
|
|
SO_SNDBUF, (void *)&realsize, &optlen );
|
|
|
|
|
|
|
|
if ( rc ) {
|
|
|
|
int err = sock_errno();
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener_activate: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"getsockopt(SO_SNDBUF) failed errno=%d (%s)\n",
|
|
|
|
err, sock_errstr( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
}
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener_activate: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"url=%s (#%d) SNDBUF original size=%d requested "
|
|
|
|
"size=%d real size=%d\n",
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_listeners[l]->sl_url.bv_val, l, origsize, size,
|
2017-03-09 06:59:57 +08:00
|
|
|
realsize );
|
|
|
|
}
|
|
|
|
}
|
|
|
|
#endif /* LDAP_TCP_BUFFER */
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_listeners[l]->sl_busy = 1;
|
|
|
|
listener = evconnlistener_new( listener_base, lload_listener,
|
|
|
|
lload_listeners[l], LEV_OPT_THREADSAFE, SLAPD_LISTEN_BACKLOG,
|
|
|
|
lload_listeners[l]->sl_sd );
|
2017-03-09 06:59:57 +08:00
|
|
|
if ( !listener ) {
|
|
|
|
int err = sock_errno();
|
|
|
|
|
|
|
|
#ifdef LDAP_PF_INET6
|
|
|
|
/* If error is EADDRINUSE, we are trying to listen to INADDR_ANY and
|
|
|
|
* we are already listening to in6addr_any, then we want to ignore
|
|
|
|
* this and continue.
|
|
|
|
*/
|
|
|
|
if ( err == EADDRINUSE ) {
|
|
|
|
int i;
|
2017-12-18 18:53:39 +08:00
|
|
|
struct sockaddr_in sa = lload_listeners[l]->sl_sa.sa_in_addr;
|
2017-03-09 06:59:57 +08:00
|
|
|
struct sockaddr_in6 sa6;
|
|
|
|
|
|
|
|
if ( sa.sin_family == AF_INET &&
|
|
|
|
sa.sin_addr.s_addr == htonl( INADDR_ANY ) ) {
|
|
|
|
for ( i = 0; i < l; i++ ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
sa6 = lload_listeners[i]->sl_sa.sa_in6_addr;
|
2017-03-09 06:59:57 +08:00
|
|
|
if ( sa6.sin6_family == AF_INET6 &&
|
|
|
|
!memcmp( &sa6.sin6_addr, &in6addr_any,
|
|
|
|
sizeof(struct in6_addr) ) ) {
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( i < l ) {
|
|
|
|
/* We are already listening to in6addr_any */
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_CONNS, "lload_listener_activate: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"Attempt to listen to 0.0.0.0 failed, "
|
|
|
|
"already listening on ::, assuming IPv4 "
|
|
|
|
"included\n" );
|
2017-12-18 18:53:39 +08:00
|
|
|
lloadd_close( lload_listeners[l]->sl_sd );
|
|
|
|
lload_listeners[l]->sl_sd = AC_SOCKET_INVALID;
|
2017-03-09 06:59:57 +08:00
|
|
|
continue;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
#endif /* LDAP_PF_INET6 */
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener_activate: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"listen(%s, 5) failed errno=%d (%s)\n",
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_listeners[l]->sl_url.bv_val, err,
|
2017-03-09 06:59:57 +08:00
|
|
|
sock_errstr( err, ebuf, sizeof(ebuf) ) );
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_listeners[l]->base = listener_base;
|
|
|
|
lload_listeners[l]->listener = listener;
|
2017-03-09 06:59:57 +08:00
|
|
|
evconnlistener_set_error_cb( listener, listener_error_cb );
|
|
|
|
}
|
|
|
|
|
|
|
|
rc = ldap_pvt_thread_create(
|
2017-12-18 18:53:39 +08:00
|
|
|
&listener_tid, 0, lload_listener_thread, lload_listeners[l] );
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
if ( rc != 0 ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_listener_activate(%d): "
|
2017-03-09 06:59:57 +08:00
|
|
|
"submit failed (%d)\n",
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_listeners[l]->sl_sd, rc );
|
2017-03-09 06:59:57 +08:00
|
|
|
}
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void *
|
2017-12-18 18:53:39 +08:00
|
|
|
lloadd_io_task( void *ptr )
|
2017-03-09 06:59:57 +08:00
|
|
|
{
|
|
|
|
int rc;
|
|
|
|
int tid = (ldap_pvt_thread_t *)ptr - daemon_tid;
|
2017-12-18 18:53:39 +08:00
|
|
|
struct event_base *base = lload_daemon[tid].base;
|
2017-03-09 06:59:57 +08:00
|
|
|
struct event *event;
|
|
|
|
|
|
|
|
event = event_new( base, -1, EV_WRITE, daemon_wakeup_cb, ptr );
|
|
|
|
if ( !event ) {
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lloadd_io_task: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"failed to set up the wakeup event\n" );
|
|
|
|
return (void *)-1;
|
|
|
|
}
|
|
|
|
event_add( event, NULL );
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_daemon[tid].wakeup_event = event;
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
/* run */
|
2018-02-07 20:38:40 +08:00
|
|
|
rc = lload_base_dispatch( base );
|
2017-12-18 18:53:39 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lloadd_io_task: "
|
2017-03-09 06:59:57 +08:00
|
|
|
"Daemon %d, event loop finished: rc=%d\n",
|
|
|
|
tid, rc );
|
|
|
|
|
|
|
|
if ( !slapd_gentle_shutdown ) {
|
|
|
|
slapd_abrupt_shutdown = 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
|
|
|
|
int
|
2017-12-18 18:53:39 +08:00
|
|
|
lloadd_daemon( struct event_base *daemon_base )
|
2017-03-09 06:59:57 +08:00
|
|
|
{
|
|
|
|
int i, rc;
|
2017-12-18 18:53:39 +08:00
|
|
|
LloadBackend *b;
|
2017-03-14 18:42:58 +08:00
|
|
|
struct event_base *base;
|
2017-11-22 21:05:11 +08:00
|
|
|
struct event *event;
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
assert( daemon_base != NULL );
|
|
|
|
|
2018-04-10 16:26:56 +08:00
|
|
|
#ifndef EVDNS_BASE_INITIALIZE_NAMESERVERS /* libevent 2.0 support */
|
|
|
|
#define EVDNS_BASE_INITIALIZE_NAMESERVERS 1
|
|
|
|
#endif /* !EVDNS_BASE_INITIALIZE_NAMESERVERS */
|
|
|
|
|
|
|
|
dnsbase = evdns_base_new( daemon_base, EVDNS_BASE_INITIALIZE_NAMESERVERS );
|
2017-03-14 18:42:58 +08:00
|
|
|
if ( !dnsbase ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "lloadd startup: "
|
|
|
|
"failed to set up for async name resolution\n" );
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
if ( lload_daemon_threads > SLAPD_MAX_DAEMON_THREADS )
|
|
|
|
lload_daemon_threads = SLAPD_MAX_DAEMON_THREADS;
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
daemon_tid =
|
2017-12-18 18:53:39 +08:00
|
|
|
ch_malloc( lload_daemon_threads * sizeof(ldap_pvt_thread_t) );
|
2017-03-09 06:59:57 +08:00
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
for ( i = 0; i < lload_daemon_threads; i++ ) {
|
2017-03-14 18:42:58 +08:00
|
|
|
base = event_base_new();
|
|
|
|
if ( !base ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "lloadd startup: "
|
|
|
|
"failed to acquire event base for an I/O thread\n" );
|
|
|
|
return -1;
|
|
|
|
}
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_daemon[i].base = base;
|
2017-03-14 18:42:58 +08:00
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
ldap_pvt_thread_mutex_init( &lload_daemon[i].sd_mutex );
|
2017-03-09 06:59:57 +08:00
|
|
|
/* threads that handle client and upstream sockets */
|
|
|
|
rc = ldap_pvt_thread_create(
|
2017-12-18 18:53:39 +08:00
|
|
|
&daemon_tid[i], 0, lloadd_io_task, &daemon_tid[i] );
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
if ( rc != 0 ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "lloadd startup: "
|
|
|
|
"listener ldap_pvt_thread_create failed (%d)\n",
|
|
|
|
rc );
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
if ( (rc = lload_listener_activate()) != 0 ) {
|
2017-05-18 23:15:26 +08:00
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
2018-03-16 21:05:21 +08:00
|
|
|
if ( !LDAP_CIRCLEQ_EMPTY( &backend ) ) {
|
|
|
|
current_backend = LDAP_CIRCLEQ_FIRST( &backend );
|
|
|
|
LDAP_CIRCLEQ_FOREACH ( b, &backend, b_next ) {
|
|
|
|
event = evtimer_new( daemon_base, backend_connect, b );
|
|
|
|
if ( !event ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "lloadd: "
|
|
|
|
"failed to allocate retry event\n" );
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
b->b_retry_event = event;
|
2017-04-12 23:02:35 +08:00
|
|
|
|
2018-03-16 21:05:21 +08:00
|
|
|
backend_retry( b );
|
|
|
|
}
|
2017-03-14 18:42:58 +08:00
|
|
|
}
|
|
|
|
|
2018-04-10 16:26:56 +08:00
|
|
|
event = evtimer_new( daemon_base, operations_timeout, NULL );
|
2017-11-22 21:05:11 +08:00
|
|
|
if ( !event ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "lloadd: "
|
|
|
|
"failed to allocate timeout event\n" );
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
lload_timeout_event = event;
|
|
|
|
|
|
|
|
/* TODO: should we just add it with any timeout and re-add when the timeout
|
|
|
|
* changes? */
|
|
|
|
if ( lload_timeout_api ) {
|
|
|
|
event_add( event, lload_timeout_api );
|
|
|
|
}
|
|
|
|
|
2017-03-09 06:59:57 +08:00
|
|
|
lloadd_inited = 1;
|
2018-02-07 20:38:40 +08:00
|
|
|
rc = lload_base_dispatch( daemon_base );
|
2017-03-09 06:59:57 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "lloadd shutdown: "
|
|
|
|
"Main event loop finished: rc=%d\n",
|
|
|
|
rc );
|
|
|
|
|
|
|
|
/* shutdown */
|
|
|
|
event_base_loopexit( listener_base, 0 );
|
|
|
|
|
|
|
|
/* wait for the listener threads to complete */
|
|
|
|
destroy_listeners();
|
|
|
|
|
2018-03-26 20:28:38 +08:00
|
|
|
/* TODO: Mark upstream connections closing */
|
|
|
|
|
|
|
|
for ( i = 0; i < lload_daemon_threads; i++ ) {
|
|
|
|
/*
|
|
|
|
* https://github.com/libevent/libevent/issues/623
|
|
|
|
* deleting the event doesn't notify the base, just activate it and
|
|
|
|
* let it delete itself
|
|
|
|
*/
|
|
|
|
event_active( lload_daemon[i].wakeup_event, EV_READ, 0 );
|
|
|
|
}
|
|
|
|
|
2018-03-21 01:21:22 +08:00
|
|
|
for ( i = 0; i < lload_daemon_threads; i++ ) {
|
2018-03-26 20:28:38 +08:00
|
|
|
ldap_pvt_thread_join( daemon_tid[i], (void *)NULL );
|
2018-03-21 01:21:22 +08:00
|
|
|
}
|
2017-03-09 06:59:57 +08:00
|
|
|
|
2018-03-21 01:21:22 +08:00
|
|
|
#ifndef BALANCER_MODULE
|
2017-03-09 06:59:57 +08:00
|
|
|
if ( LogTest( LDAP_DEBUG_ANY ) ) {
|
|
|
|
int t = ldap_pvt_thread_pool_backload( &connection_pool );
|
|
|
|
Debug( LDAP_DEBUG_ANY, "lloadd shutdown: "
|
|
|
|
"waiting for %d operations/tasks to finish\n",
|
|
|
|
t );
|
|
|
|
}
|
|
|
|
ldap_pvt_thread_pool_close( &connection_pool, 1 );
|
2018-03-21 01:21:22 +08:00
|
|
|
#endif
|
|
|
|
|
2018-02-19 22:22:40 +08:00
|
|
|
lload_backends_destroy();
|
2017-05-25 22:04:08 +08:00
|
|
|
clients_destroy();
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_bindconf_free( &bindconf );
|
2017-05-03 18:07:35 +08:00
|
|
|
evdns_base_free( dnsbase, 0 );
|
2017-03-09 06:59:57 +08:00
|
|
|
|
|
|
|
ch_free( daemon_tid );
|
|
|
|
daemon_tid = NULL;
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
lloadd_daemon_destroy();
|
2017-03-09 06:59:57 +08:00
|
|
|
|
2018-03-21 01:21:22 +08:00
|
|
|
/* If we're a slapd module, let the thread that initiated the shut down
|
|
|
|
* know we've finished */
|
|
|
|
ldap_pvt_thread_cond_signal( &lload_wait_cond );
|
|
|
|
|
2017-03-09 06:59:57 +08:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
static void
|
|
|
|
daemon_wakeup_cb( evutil_socket_t sig, short what, void *arg )
|
|
|
|
{
|
|
|
|
int tid = (ldap_pvt_thread_t *)arg - daemon_tid;
|
|
|
|
|
|
|
|
Debug( LDAP_DEBUG_TRACE, "daemon_wakeup_cb: "
|
|
|
|
"Daemon thread %d woken up\n",
|
|
|
|
tid );
|
2018-03-26 20:28:38 +08:00
|
|
|
event_del( lload_daemon[tid].wakeup_event );
|
2017-03-09 06:59:57 +08:00
|
|
|
}
|
|
|
|
|
2018-02-21 17:27:33 +08:00
|
|
|
LloadChange lload_change = { .type = LLOAD_UNDEFINED };
|
|
|
|
|
2018-02-07 20:38:40 +08:00
|
|
|
#ifdef BALANCER_MODULE
|
2018-02-20 23:45:35 +08:00
|
|
|
int
|
|
|
|
backend_conn_cb( ldap_pvt_thread_start_t *start, void *startarg, void *arg )
|
|
|
|
{
|
|
|
|
LloadConnection *c = startarg;
|
|
|
|
LloadBackend *b = arg;
|
|
|
|
|
|
|
|
if ( b == NULL || c->c_private == b ) {
|
2018-03-28 17:16:24 +08:00
|
|
|
CONNECTION_LOCK_DESTROY(c);
|
2018-02-20 23:45:35 +08:00
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
int
|
|
|
|
client_tls_cb( ldap_pvt_thread_start_t *start, void *startarg, void *arg )
|
|
|
|
{
|
|
|
|
LloadConnection *c = startarg;
|
|
|
|
|
|
|
|
if ( c->c_destroy == client_destroy &&
|
|
|
|
c->c_is_tls == LLOAD_TLS_ESTABLISHED ) {
|
|
|
|
CONNECTION_LOCK_DESTROY(c);
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
void
|
|
|
|
lload_handle_backend_invalidation( LloadChange *change )
|
|
|
|
{
|
|
|
|
LloadBackend *b = change->target;
|
|
|
|
|
|
|
|
assert( change->object == LLOAD_BACKEND );
|
|
|
|
|
|
|
|
if ( change->type == LDAP_REQ_ADD ) {
|
2018-03-24 00:16:44 +08:00
|
|
|
BackendInfo *mi = backend_info( "monitor" );
|
|
|
|
|
|
|
|
if ( mi ) {
|
|
|
|
monitor_extra_t *mbe = mi->bi_extra;
|
|
|
|
if ( mbe->is_configured() ) {
|
|
|
|
lload_monitor_backend_init( mi, b );
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-02-21 17:27:33 +08:00
|
|
|
if ( !current_backend ) {
|
|
|
|
current_backend = b;
|
|
|
|
}
|
2018-02-20 23:45:35 +08:00
|
|
|
backend_retry( b );
|
|
|
|
return;
|
|
|
|
} else if ( change->type == LDAP_REQ_DELETE ) {
|
2018-02-21 17:27:33 +08:00
|
|
|
ldap_pvt_thread_pool_walk(
|
|
|
|
&connection_pool, handle_pdus, backend_conn_cb, b );
|
|
|
|
ldap_pvt_thread_pool_walk(
|
|
|
|
&connection_pool, upstream_bind, backend_conn_cb, b );
|
2018-03-28 17:29:42 +08:00
|
|
|
/* Drop the connection task if it's queued */
|
|
|
|
if ( b->b_cookie ) {
|
|
|
|
int rc = ldap_pvt_thread_pool_retract( b->b_cookie );
|
|
|
|
assert( rc == 1 );
|
|
|
|
b->b_opening--;
|
|
|
|
}
|
2018-02-20 23:45:35 +08:00
|
|
|
lload_backend_destroy( b );
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
assert( change->type == LDAP_REQ_MODIFY );
|
|
|
|
assert( change->flags.generic != 0 );
|
|
|
|
|
|
|
|
/*
|
|
|
|
* A change that can't be handled gracefully, terminate all connections and
|
|
|
|
* start over.
|
|
|
|
*/
|
|
|
|
if ( change->flags.backend & LLOAD_BACKEND_MOD_OTHER ) {
|
|
|
|
ldap_pvt_thread_pool_walk(
|
|
|
|
&connection_pool, handle_pdus, backend_conn_cb, b );
|
|
|
|
ldap_pvt_thread_pool_walk(
|
|
|
|
&connection_pool, upstream_bind, backend_conn_cb, b );
|
|
|
|
backend_reset( b );
|
|
|
|
backend_retry( b );
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Handle changes to number of connections:
|
|
|
|
* - a change might get the connection limit above the pool size:
|
|
|
|
* - consider closing (in order of priority?):
|
|
|
|
* - connections awaiting connect() completion
|
|
|
|
* - connections currently preparing
|
|
|
|
* - bind connections over limit (which is 0 if 'feature vc' is on
|
|
|
|
* - regular connections over limit
|
|
|
|
* - below pool size
|
|
|
|
* - call backend_retry if there are no opening connections
|
|
|
|
* - one pool size above and one below the configured size
|
|
|
|
* - still close the ones above limit, it should sort itself out
|
|
|
|
* the only issue is if a closing connection isn't guaranteed to do
|
|
|
|
* that at some point
|
|
|
|
*/
|
|
|
|
if ( change->flags.backend & LLOAD_BACKEND_MOD_CONNS ) {
|
|
|
|
int bind_requested = 0, need_close = 0, need_open = 0;
|
|
|
|
LloadConnection *c;
|
|
|
|
|
|
|
|
bind_requested =
|
|
|
|
#ifdef LDAP_API_FEATURE_VERIFY_CREDENTIALS
|
|
|
|
(lload_features & LLOAD_FEATURE_VC) ? 0 :
|
|
|
|
#endif /* LDAP_API_FEATURE_VERIFY_CREDENTIALS */
|
|
|
|
b->b_numbindconns;
|
|
|
|
|
|
|
|
if ( b->b_bindavail > bind_requested ) {
|
|
|
|
need_close += b->b_bindavail - bind_requested;
|
|
|
|
} else if ( b->b_bindavail < bind_requested ) {
|
|
|
|
need_open = 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( b->b_active > b->b_numconns ) {
|
|
|
|
need_close += b->b_active - b->b_numconns;
|
|
|
|
} else if ( b->b_active < b->b_numconns ) {
|
|
|
|
need_open = 1;
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( !need_open ) {
|
|
|
|
need_close += b->b_opening;
|
|
|
|
|
|
|
|
while ( !LDAP_LIST_EMPTY( &b->b_connecting ) ) {
|
|
|
|
LloadPendingConnection *p = LDAP_LIST_FIRST( &b->b_connecting );
|
|
|
|
|
|
|
|
LDAP_LIST_REMOVE( p, next );
|
|
|
|
event_free( p->event );
|
|
|
|
evutil_closesocket( p->fd );
|
|
|
|
ch_free( p );
|
|
|
|
b->b_opening--;
|
|
|
|
need_close--;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( need_close || !need_open ) {
|
|
|
|
/* It might be too late to repurpose a preparing connection, just
|
|
|
|
* close them all */
|
|
|
|
while ( !LDAP_CIRCLEQ_EMPTY( &b->b_preparing ) ) {
|
|
|
|
c = LDAP_CIRCLEQ_FIRST( &b->b_preparing );
|
|
|
|
|
|
|
|
event_del( c->c_read_event );
|
|
|
|
CONNECTION_LOCK_DESTROY(c);
|
|
|
|
assert( c == NULL );
|
|
|
|
b->b_opening--;
|
|
|
|
need_close--;
|
|
|
|
}
|
|
|
|
event_del( b->b_retry_event );
|
|
|
|
assert( b->b_opening == 0 );
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( b->b_bindavail > bind_requested ) {
|
|
|
|
int diff = b->b_bindavail - bind_requested;
|
|
|
|
|
|
|
|
assert( need_close >= diff );
|
|
|
|
|
|
|
|
LDAP_CIRCLEQ_FOREACH ( c, &b->b_bindconns, c_next ) {
|
|
|
|
lload_connection_close( c );
|
|
|
|
need_close--;
|
|
|
|
diff--;
|
|
|
|
if ( !diff ) {
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
assert( diff == 0 );
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( b->b_active > b->b_numconns ) {
|
|
|
|
int diff = b->b_active - b->b_numconns;
|
|
|
|
|
|
|
|
assert( need_close >= diff );
|
|
|
|
|
|
|
|
LDAP_CIRCLEQ_FOREACH ( c, &b->b_conns, c_next ) {
|
|
|
|
lload_connection_close( c );
|
|
|
|
need_close--;
|
|
|
|
diff--;
|
|
|
|
if ( !diff ) {
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
assert( diff == 0 );
|
|
|
|
}
|
|
|
|
assert( need_close == 0 );
|
|
|
|
|
|
|
|
if ( need_open ) {
|
|
|
|
backend_retry( b );
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
void
|
|
|
|
lload_handle_bindconf_invalidation( LloadChange *change )
|
|
|
|
{
|
|
|
|
LloadBackend *b;
|
|
|
|
LloadConnection *c;
|
|
|
|
|
|
|
|
assert( change->type == LDAP_REQ_MODIFY );
|
|
|
|
assert( change->object == LLOAD_BINDCONF );
|
|
|
|
|
2018-02-21 17:27:33 +08:00
|
|
|
change->flags.bindconf &= ~LLOAD_BINDCONF_MOD_TIMEOUTS;
|
|
|
|
|
|
|
|
if ( !change->flags.bindconf ) {
|
2018-02-20 23:45:35 +08:00
|
|
|
/* Nothing needs doing, things will generally fall into place */
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Only timeout changes can be handled gracefully, terminate all
|
|
|
|
* connections and start over.
|
|
|
|
*/
|
|
|
|
ldap_pvt_thread_pool_walk(
|
|
|
|
&connection_pool, handle_pdus, backend_conn_cb, NULL );
|
|
|
|
ldap_pvt_thread_pool_walk(
|
|
|
|
&connection_pool, upstream_bind, backend_conn_cb, NULL );
|
|
|
|
|
|
|
|
LDAP_CIRCLEQ_FOREACH ( b, &backend, b_next ) {
|
|
|
|
backend_reset( b );
|
|
|
|
backend_retry( b );
|
|
|
|
}
|
|
|
|
|
2018-02-21 17:27:33 +08:00
|
|
|
/* Reconsider the PRIVILEGED flag on all clients */
|
2018-02-20 23:45:35 +08:00
|
|
|
LDAP_CIRCLEQ_FOREACH ( c, &clients, c_next ) {
|
|
|
|
int privileged = ber_bvstrcasecmp( &c->c_auth, &lloadd_identity );
|
|
|
|
|
2018-02-21 17:27:33 +08:00
|
|
|
/* We have just terminated all pending operations (even pins), there
|
|
|
|
* should be no connections still binding/closing */
|
2018-02-20 23:45:35 +08:00
|
|
|
assert( c->c_state == LLOAD_C_READY );
|
|
|
|
|
|
|
|
c->c_type = privileged ? LLOAD_C_PRIVILEGED : LLOAD_C_OPEN;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
void
|
|
|
|
lload_handle_global_invalidation( LloadChange *change )
|
|
|
|
{
|
|
|
|
assert( change->type == LDAP_REQ_MODIFY );
|
|
|
|
assert( change->object == LLOAD_DAEMON );
|
|
|
|
|
|
|
|
if ( change->flags.daemon & LLOAD_DAEMON_MOD_THREADS ) {
|
|
|
|
/* walk the task queue to remove any tasks belonging to us. */
|
|
|
|
/* TODO: initiate a full module restart, everything will fall into
|
|
|
|
* place at that point */
|
|
|
|
ldap_pvt_thread_pool_walk(
|
|
|
|
&connection_pool, handle_pdus, backend_conn_cb, NULL );
|
|
|
|
ldap_pvt_thread_pool_walk(
|
|
|
|
&connection_pool, upstream_bind, backend_conn_cb, NULL );
|
|
|
|
assert(0);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( change->flags.daemon & LLOAD_DAEMON_MOD_FEATURES ) {
|
2018-02-21 17:27:33 +08:00
|
|
|
lload_features_t feature_diff =
|
|
|
|
lload_features ^ ( ~(uintptr_t)change->target );
|
|
|
|
/* Feature change handling:
|
|
|
|
* - VC (TODO):
|
2018-02-20 23:45:35 +08:00
|
|
|
* - on: terminate all bind connections
|
|
|
|
* - off: cancel all bind operations in progress, reopen bind connections
|
2018-02-21 17:27:33 +08:00
|
|
|
* - ProxyAuthz:
|
|
|
|
* - on: nothing needed
|
|
|
|
* - off: clear c_auth/privileged on each client
|
2018-02-20 23:45:35 +08:00
|
|
|
*/
|
2018-02-21 17:27:33 +08:00
|
|
|
|
|
|
|
assert( change->target );
|
|
|
|
if ( feature_diff & LLOAD_FEATURE_VC ) {
|
|
|
|
assert(0);
|
|
|
|
feature_diff &= ~LLOAD_FEATURE_VC;
|
|
|
|
}
|
|
|
|
if ( feature_diff & LLOAD_FEATURE_PROXYAUTHZ ) {
|
|
|
|
if ( !(lload_features & LLOAD_FEATURE_PROXYAUTHZ) ) {
|
|
|
|
LloadConnection *c;
|
|
|
|
/* We switched proxyauthz off */
|
|
|
|
LDAP_CIRCLEQ_FOREACH ( c, &clients, c_next ) {
|
|
|
|
if ( !BER_BVISNULL( &c->c_auth ) ) {
|
|
|
|
ber_memfree( c->c_auth.bv_val );
|
|
|
|
BER_BVZERO( &c->c_auth );
|
|
|
|
}
|
|
|
|
if ( c->c_type == LLOAD_C_PRIVILEGED ) {
|
|
|
|
c->c_type = LLOAD_C_OPEN;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
feature_diff &= ~LLOAD_FEATURE_PROXYAUTHZ;
|
|
|
|
}
|
|
|
|
assert( !feature_diff );
|
2018-02-20 23:45:35 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
if ( change->flags.daemon & LLOAD_DAEMON_MOD_TLS ) {
|
|
|
|
/* terminate all clients with TLS set up */
|
|
|
|
ldap_pvt_thread_pool_walk(
|
|
|
|
&connection_pool, handle_pdus, client_tls_cb, NULL );
|
|
|
|
if ( !LDAP_CIRCLEQ_EMPTY( &clients ) ) {
|
|
|
|
LloadConnection *c = LDAP_CIRCLEQ_FIRST( &clients );
|
|
|
|
unsigned long first_connid = c->c_connid;
|
|
|
|
|
|
|
|
while ( c ) {
|
|
|
|
LloadConnection *next =
|
|
|
|
LDAP_CIRCLEQ_LOOP_NEXT( &clients, c, c_next );
|
|
|
|
if ( c->c_is_tls ) {
|
|
|
|
CONNECTION_LOCK(c);
|
|
|
|
CONNECTION_DESTROY(c);
|
|
|
|
assert( c == NULL );
|
|
|
|
}
|
|
|
|
c = next;
|
|
|
|
if ( c->c_connid <= first_connid ) {
|
|
|
|
c = NULL;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
int
|
|
|
|
lload_handle_invalidation( LloadChange *change )
|
|
|
|
{
|
|
|
|
if ( change->type == LDAP_REQ_MODIFY && change->flags.generic == 0 ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_handle_invalidation: "
|
|
|
|
"a modify where apparently nothing changed\n" );
|
|
|
|
}
|
|
|
|
|
|
|
|
switch ( change->object ) {
|
|
|
|
case LLOAD_BACKEND:
|
|
|
|
lload_handle_backend_invalidation( change );
|
|
|
|
break;
|
|
|
|
case LLOAD_DAEMON:
|
|
|
|
lload_handle_global_invalidation( change );
|
|
|
|
break;
|
|
|
|
case LLOAD_BINDCONF:
|
|
|
|
lload_handle_bindconf_invalidation( change );
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
Debug( LDAP_DEBUG_ANY, "lload_handle_invalidation: "
|
|
|
|
"unrecognised change\n" );
|
|
|
|
assert(0);
|
|
|
|
}
|
|
|
|
|
|
|
|
return LDAP_SUCCESS;
|
|
|
|
}
|
|
|
|
|
2018-02-07 20:38:40 +08:00
|
|
|
/*
|
|
|
|
* Signal the event base to terminate processing as soon as it can and wait for
|
|
|
|
* lload_base_dispatch to notify us this has happened.
|
|
|
|
*/
|
|
|
|
static int
|
|
|
|
lload_pause_base( struct event_base *base )
|
|
|
|
{
|
|
|
|
int rc;
|
|
|
|
|
|
|
|
ldap_pvt_thread_mutex_lock( &lload_wait_mutex );
|
|
|
|
event_base_loopbreak( base );
|
|
|
|
rc = ldap_pvt_thread_cond_wait( &lload_wait_cond, &lload_wait_mutex );
|
|
|
|
ldap_pvt_thread_mutex_unlock( &lload_wait_mutex );
|
|
|
|
|
|
|
|
return rc;
|
|
|
|
}
|
|
|
|
|
|
|
|
void
|
|
|
|
lload_pause_server( void )
|
|
|
|
{
|
2018-02-21 17:27:33 +08:00
|
|
|
LloadChange ch = { .type = LLOAD_UNDEFINED };
|
2018-02-07 20:38:40 +08:00
|
|
|
int i;
|
|
|
|
|
|
|
|
lload_pause_base( listener_base );
|
|
|
|
lload_pause_base( daemon_base );
|
|
|
|
|
|
|
|
for ( i = 0; i < lload_daemon_threads; i++ ) {
|
|
|
|
lload_pause_base( lload_daemon[i].base );
|
|
|
|
}
|
2018-02-21 17:27:33 +08:00
|
|
|
|
|
|
|
lload_change = ch;
|
2018-02-07 20:38:40 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
void
|
|
|
|
lload_unpause_server( void )
|
|
|
|
{
|
2018-02-21 17:27:33 +08:00
|
|
|
if ( lload_change.type != LLOAD_UNDEFINED ) {
|
|
|
|
lload_handle_invalidation( &lload_change );
|
|
|
|
}
|
|
|
|
|
2018-02-07 20:38:40 +08:00
|
|
|
/*
|
|
|
|
* Make sure lloadd is completely ready to unpause by now:
|
|
|
|
*
|
|
|
|
* After the broadcast, we handle I/O and begin filling the thread pool, in
|
|
|
|
* high load conditions, we might hit the pool limits and start processing
|
|
|
|
* operations in the I/O threads (one PDU per socket at a time for fairness
|
|
|
|
* sake) even before a pause has finished from slapd's point of view!
|
|
|
|
*
|
|
|
|
* When (max_pdus_per_cycle == 0) we don't use the pool for these at all and
|
|
|
|
* most lload processing starts immediately making this even more prominent.
|
|
|
|
*/
|
|
|
|
ldap_pvt_thread_cond_broadcast( &lload_pause_cond );
|
|
|
|
}
|
|
|
|
#endif /* BALANCER_MODULE */
|
|
|
|
|
2017-03-09 06:59:57 +08:00
|
|
|
void
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_sig_shutdown( evutil_socket_t sig, short what, void *arg )
|
2017-03-09 06:59:57 +08:00
|
|
|
{
|
|
|
|
struct event_base *daemon_base = arg;
|
|
|
|
int save_errno = errno;
|
|
|
|
int i;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* If the NT Service Manager is controlling the server, we don't
|
|
|
|
* want SIGBREAK to kill the server. For some strange reason,
|
|
|
|
* SIGBREAK is generated when a user logs out.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#if defined(HAVE_NT_SERVICE_MANAGER) && defined(SIGBREAK)
|
|
|
|
if ( is_NT_Service && sig == SIGBREAK ) {
|
|
|
|
/* empty */;
|
|
|
|
} else
|
|
|
|
#endif /* HAVE_NT_SERVICE_MANAGER && SIGBREAK */
|
|
|
|
#ifdef SIGHUP
|
|
|
|
if ( sig == SIGHUP && global_gentlehup && slapd_gentle_shutdown == 0 ) {
|
|
|
|
slapd_gentle_shutdown = 1;
|
|
|
|
} else
|
|
|
|
#endif /* SIGHUP */
|
|
|
|
{
|
|
|
|
slapd_shutdown = 1;
|
|
|
|
}
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
for ( i = 0; i < lload_daemon_threads; i++ ) {
|
2018-02-05 17:04:02 +08:00
|
|
|
event_base_loopexit( lload_daemon[i].base, NULL );
|
2017-03-09 06:59:57 +08:00
|
|
|
}
|
|
|
|
event_base_loopexit( daemon_base, NULL );
|
|
|
|
|
|
|
|
errno = save_errno;
|
|
|
|
}
|
|
|
|
|
2017-03-14 18:42:58 +08:00
|
|
|
struct event_base *
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_get_base( ber_socket_t s )
|
2017-03-14 18:42:58 +08:00
|
|
|
{
|
|
|
|
int tid = DAEMON_ID(s);
|
2017-12-18 18:53:39 +08:00
|
|
|
return lload_daemon[tid].base;
|
2017-03-14 18:42:58 +08:00
|
|
|
}
|
|
|
|
|
2017-12-18 18:53:39 +08:00
|
|
|
LloadListener **
|
|
|
|
lloadd_get_listeners( void )
|
2017-03-09 06:59:57 +08:00
|
|
|
{
|
|
|
|
/* Could return array with no listeners if !listening, but current
|
|
|
|
* callers mostly look at the URLs. E.g. syncrepl uses this to
|
|
|
|
* identify the server, which means it wants the startup arguments.
|
|
|
|
*/
|
2017-12-18 18:53:39 +08:00
|
|
|
return lload_listeners;
|
2017-03-09 06:59:57 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
/* Reject all incoming requests */
|
|
|
|
void
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_suspend_listeners( void )
|
2017-03-09 06:59:57 +08:00
|
|
|
{
|
|
|
|
int i;
|
2017-12-18 18:53:39 +08:00
|
|
|
for ( i = 0; lload_listeners[i]; i++ ) {
|
|
|
|
lload_listeners[i]->sl_mute = 1;
|
|
|
|
evconnlistener_disable( lload_listeners[i]->listener );
|
|
|
|
listen( lload_listeners[i]->sl_sd, 0 );
|
2017-03-09 06:59:57 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Resume after a suspend */
|
|
|
|
void
|
2017-12-18 18:53:39 +08:00
|
|
|
lload_resume_listeners( void )
|
2017-03-09 06:59:57 +08:00
|
|
|
{
|
|
|
|
int i;
|
2017-12-18 18:53:39 +08:00
|
|
|
for ( i = 0; lload_listeners[i]; i++ ) {
|
|
|
|
lload_listeners[i]->sl_mute = 0;
|
|
|
|
listen( lload_listeners[i]->sl_sd, SLAPD_LISTEN_BACKLOG );
|
|
|
|
evconnlistener_enable( lload_listeners[i]->listener );
|
2017-03-09 06:59:57 +08:00
|
|
|
}
|
|
|
|
}
|