corosync-qnetd.c 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662
  1. /*
  2. * Copyright (c) 2015-2016 Red Hat, Inc.
  3. *
  4. * All rights reserved.
  5. *
  6. * Author: Jan Friesse (jfriesse@redhat.com)
  7. *
  8. * This software licensed under BSD license, the text of which follows:
  9. *
  10. * Redistribution and use in source and binary forms, with or without
  11. * modification, are permitted provided that the following conditions are met:
  12. *
  13. * - Redistributions of source code must retain the above copyright notice,
  14. * this list of conditions and the following disclaimer.
  15. * - Redistributions in binary form must reproduce the above copyright notice,
  16. * this list of conditions and the following disclaimer in the documentation
  17. * and/or other materials provided with the distribution.
  18. * - Neither the name of the Red Hat, Inc. nor the names of its
  19. * contributors may be used to endorse or promote products derived from this
  20. * software without specific prior written permission.
  21. *
  22. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
  23. * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
  24. * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
  25. * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
  26. * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
  27. * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
  28. * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
  29. * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
  30. * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
  31. * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
  32. * THE POSSIBILITY OF SUCH DAMAGE.
  33. */
  34. #include <err.h>
  35. #include <errno.h>
  36. #include <getopt.h>
  37. #include <signal.h>
  38. #include <unistd.h>
  39. #include "qnet-config.h"
  40. #include "dynar.h"
  41. #include "dynar-str.h"
  42. #include "dynar-getopt-lex.h"
  43. #include "nss-sock.h"
  44. #include "pr-poll-array.h"
  45. #include "qnetd-advanced-settings.h"
  46. #include "qnetd-algorithm.h"
  47. #include "qnetd-instance.h"
  48. #include "qnetd-ipc.h"
  49. #include "qnetd-log.h"
  50. #include "qnetd-client-net.h"
  51. #include "qnetd-client-msg-received.h"
  52. #include "qnetd-poll-array-user-data.h"
  53. #include "utils.h"
  54. #include "msg.h"
  55. #ifdef HAVE_LIBSYSTEMD
  56. #include <systemd/sd-daemon.h>
  57. #endif
  58. /*
  59. * This is global variable used for comunication with main loop and signal (calls close)
  60. */
  61. struct qnetd_instance *global_instance;
  62. enum tlv_decision_algorithm_type
  63. qnetd_static_supported_decision_algorithms[QNETD_STATIC_SUPPORTED_DECISION_ALGORITHMS_SIZE] = {
  64. TLV_DECISION_ALGORITHM_TYPE_TEST,
  65. TLV_DECISION_ALGORITHM_TYPE_FFSPLIT,
  66. TLV_DECISION_ALGORITHM_TYPE_2NODELMS,
  67. TLV_DECISION_ALGORITHM_TYPE_LMS,
  68. };
  69. static void
  70. qnetd_err_nss(void)
  71. {
  72. qnetd_log_nss(LOG_CRIT, "NSS error");
  73. exit(1);
  74. }
  75. static void
  76. qnetd_warn_nss(void)
  77. {
  78. qnetd_log_nss(LOG_WARNING, "NSS warning");
  79. }
  80. static PRPollDesc *
  81. qnetd_pr_poll_array_create(struct qnetd_instance *instance)
  82. {
  83. struct pr_poll_array *poll_array;
  84. const struct qnetd_client_list *client_list;
  85. struct qnetd_client *client;
  86. PRPollDesc *poll_desc;
  87. struct qnetd_poll_array_user_data *user_data;
  88. const struct unix_socket_client_list *ipc_client_list;
  89. struct unix_socket_client *ipc_client;
  90. poll_array = &instance->poll_array;
  91. client_list = &instance->clients;
  92. ipc_client_list = &instance->local_ipc.clients;
  93. pr_poll_array_clean(poll_array);
  94. if (pr_poll_array_add(poll_array, &poll_desc, (void **)&user_data) < 0) {
  95. return (NULL);
  96. }
  97. poll_desc->fd = instance->server.socket;
  98. poll_desc->in_flags = PR_POLL_READ;
  99. user_data->type = QNETD_POLL_ARRAY_USER_DATA_TYPE_SOCKET;
  100. if (qnetd_ipc_is_closed(instance)) {
  101. qnetd_log(LOG_DEBUG, "Listening socket is closed");
  102. return (NULL);
  103. }
  104. if (pr_poll_array_add(poll_array, &poll_desc, (void **)&user_data) < 0) {
  105. return (NULL);
  106. }
  107. poll_desc->fd = instance->ipc_socket_poll_fd;
  108. poll_desc->in_flags = PR_POLL_READ;
  109. user_data->type = QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_SOCKET;
  110. TAILQ_FOREACH(client, client_list, entries) {
  111. if (pr_poll_array_add(poll_array, &poll_desc, (void **)&user_data) < 0) {
  112. return (NULL);
  113. }
  114. poll_desc->fd = client->socket;
  115. poll_desc->in_flags = PR_POLL_READ;
  116. if (!send_buffer_list_empty(&client->send_buffer_list)) {
  117. poll_desc->in_flags |= PR_POLL_WRITE;
  118. }
  119. user_data->type = QNETD_POLL_ARRAY_USER_DATA_TYPE_CLIENT;
  120. user_data->client = client;
  121. }
  122. TAILQ_FOREACH(ipc_client, ipc_client_list, entries) {
  123. if (!ipc_client->reading_line && !ipc_client->writing_buffer) {
  124. continue;
  125. }
  126. if (pr_poll_array_add(poll_array, &poll_desc, (void **)&user_data) < 0) {
  127. return (NULL);
  128. }
  129. poll_desc->fd = ((struct qnetd_ipc_user_data *)ipc_client->user_data)->nspr_poll_fd;
  130. if (ipc_client->reading_line) {
  131. poll_desc->in_flags |= PR_POLL_READ;
  132. }
  133. if (ipc_client->writing_buffer) {
  134. poll_desc->in_flags |= PR_POLL_WRITE;
  135. }
  136. user_data->type = QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_CLIENT;
  137. user_data->ipc_client = ipc_client;
  138. }
  139. pr_poll_array_gc(poll_array);
  140. return (poll_array->array);
  141. }
  142. static int
  143. qnetd_poll(struct qnetd_instance *instance)
  144. {
  145. struct qnetd_client *client;
  146. PRPollDesc *pfds;
  147. PRInt32 poll_res;
  148. ssize_t i;
  149. int client_disconnect;
  150. struct qnetd_poll_array_user_data *user_data;
  151. struct unix_socket_client *ipc_client;
  152. client = NULL;
  153. client_disconnect = 0;
  154. pfds = qnetd_pr_poll_array_create(instance);
  155. if (pfds == NULL) {
  156. return (-1);
  157. }
  158. if ((poll_res = PR_Poll(pfds, pr_poll_array_size(&instance->poll_array),
  159. timer_list_time_to_expire(&instance->main_timer_list))) >= 0) {
  160. timer_list_expire(&instance->main_timer_list);
  161. /*
  162. * Walk thru pfds array and process events
  163. */
  164. for (i = 0; i < pr_poll_array_size(&instance->poll_array); i++) {
  165. user_data = pr_poll_array_get_user_data(&instance->poll_array, i);
  166. client = NULL;
  167. ipc_client = NULL;
  168. client_disconnect = 0;
  169. switch (user_data->type) {
  170. case QNETD_POLL_ARRAY_USER_DATA_TYPE_SOCKET:
  171. break;
  172. case QNETD_POLL_ARRAY_USER_DATA_TYPE_CLIENT:
  173. client = user_data->client;
  174. client_disconnect = client->schedule_disconnect;
  175. break;
  176. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_SOCKET:
  177. break;
  178. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_CLIENT:
  179. ipc_client = user_data->ipc_client;
  180. client_disconnect = ipc_client->schedule_disconnect;
  181. }
  182. if (!client_disconnect && poll_res > 0 &&
  183. pfds[i].out_flags & PR_POLL_READ) {
  184. switch (user_data->type) {
  185. case QNETD_POLL_ARRAY_USER_DATA_TYPE_SOCKET:
  186. qnetd_client_net_accept(instance);
  187. break;
  188. case QNETD_POLL_ARRAY_USER_DATA_TYPE_CLIENT:
  189. if (qnetd_client_net_read(instance, client) == -1) {
  190. client_disconnect = 1;
  191. }
  192. break;
  193. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_SOCKET:
  194. qnetd_ipc_accept(instance, &ipc_client);
  195. break;
  196. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_CLIENT:
  197. qnetd_ipc_io_read(instance, ipc_client);
  198. break;
  199. }
  200. }
  201. if (!client_disconnect && poll_res > 0 &&
  202. pfds[i].out_flags & PR_POLL_WRITE) {
  203. switch (user_data->type) {
  204. case QNETD_POLL_ARRAY_USER_DATA_TYPE_SOCKET:
  205. /*
  206. * Poll write on listen socket -> fatal error
  207. */
  208. qnetd_log(LOG_CRIT, "POLL_WRITE on listening socket");
  209. return (-1);
  210. break;
  211. case QNETD_POLL_ARRAY_USER_DATA_TYPE_CLIENT:
  212. if (qnetd_client_net_write(instance, client) == -1) {
  213. client_disconnect = 1;
  214. }
  215. break;
  216. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_SOCKET:
  217. qnetd_log(LOG_CRIT, "POLL_WRITE on listening IPC socket");
  218. return (-1);
  219. break;
  220. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_CLIENT:
  221. qnetd_ipc_io_write(instance, ipc_client);
  222. break;
  223. }
  224. }
  225. if (!client_disconnect && poll_res > 0 &&
  226. (pfds[i].out_flags & (PR_POLL_ERR|PR_POLL_NVAL|PR_POLL_HUP|PR_POLL_EXCEPT)) &&
  227. !(pfds[i].out_flags & (PR_POLL_READ|PR_POLL_WRITE))) {
  228. switch (user_data->type) {
  229. case QNETD_POLL_ARRAY_USER_DATA_TYPE_SOCKET:
  230. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_SOCKET:
  231. if (pfds[i].out_flags != PR_POLL_NVAL) {
  232. /*
  233. * Poll ERR on listening socket is fatal error.
  234. * POLL_NVAL is used as a signal to quit poll loop.
  235. */
  236. qnetd_log(LOG_CRIT, "POLL_ERR (%u) on listening "
  237. "socket", pfds[i].out_flags);
  238. } else {
  239. qnetd_log(LOG_DEBUG, "Listening socket is closed");
  240. }
  241. return (-1);
  242. break;
  243. case QNETD_POLL_ARRAY_USER_DATA_TYPE_CLIENT:
  244. qnetd_log(LOG_DEBUG, "POLL_ERR (%u) on client socket. "
  245. "Disconnecting.", pfds[i].out_flags);
  246. client_disconnect = 1;
  247. break;
  248. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_CLIENT:
  249. qnetd_log(LOG_DEBUG, "POLL_ERR (%u) on ipc client socket."
  250. " Disconnecting.", pfds[i].out_flags);
  251. client_disconnect = 1;
  252. break;
  253. }
  254. }
  255. /*
  256. * If client is scheduled for disconnect, disconnect it
  257. */
  258. if (user_data->type == QNETD_POLL_ARRAY_USER_DATA_TYPE_CLIENT &&
  259. client_disconnect) {
  260. qnetd_instance_client_disconnect(instance, client, 0);
  261. } else if (user_data->type == QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_CLIENT &&
  262. (client_disconnect || ipc_client->schedule_disconnect)) {
  263. qnetd_ipc_client_disconnect(instance, ipc_client);
  264. }
  265. }
  266. }
  267. return (0);
  268. }
  269. static void
  270. signal_int_handler(int sig)
  271. {
  272. qnetd_log(LOG_DEBUG, "SIGINT received - closing server IPC socket");
  273. qnetd_ipc_close(global_instance);
  274. }
  275. static void
  276. signal_term_handler(int sig)
  277. {
  278. qnetd_log(LOG_DEBUG, "SIGTERM received - closing server IPC socket");
  279. qnetd_ipc_close(global_instance);
  280. }
  281. static void
  282. signal_handlers_register(void)
  283. {
  284. struct sigaction act;
  285. act.sa_handler = signal_int_handler;
  286. sigemptyset(&act.sa_mask);
  287. act.sa_flags = SA_RESTART;
  288. sigaction(SIGINT, &act, NULL);
  289. act.sa_handler = signal_term_handler;
  290. sigemptyset(&act.sa_mask);
  291. act.sa_flags = SA_RESTART;
  292. sigaction(SIGTERM, &act, NULL);
  293. }
  294. static void
  295. usage(void)
  296. {
  297. printf("usage: %s [-46dfhv] [-l listen_addr] [-p listen_port] [-s tls]\n", QNETD_PROGRAM_NAME);
  298. printf("%14s[-c client_cert_required] [-m max_clients] [-S option=value[,option2=value2,...]]\n", "");
  299. }
  300. static void
  301. display_version(void)
  302. {
  303. enum msg_type *supported_messages;
  304. size_t no_supported_messages;
  305. size_t zi;
  306. msg_get_supported_messages(&supported_messages, &no_supported_messages);
  307. printf("Corosync Qdevice Network Daemon, version '%s'\n\n", VERSION);
  308. printf("Supported algorithms: ");
  309. for (zi = 0; zi < QNETD_STATIC_SUPPORTED_DECISION_ALGORITHMS_SIZE; zi++) {
  310. if (zi != 0) {
  311. printf(", ");
  312. }
  313. printf("%s (%u)",
  314. tlv_decision_algorithm_type_to_str(qnetd_static_supported_decision_algorithms[zi]),
  315. qnetd_static_supported_decision_algorithms[zi]);
  316. }
  317. printf("\n");
  318. printf("Supported message types: ");
  319. for (zi = 0; zi < no_supported_messages; zi++) {
  320. if (zi != 0) {
  321. printf(", ");
  322. }
  323. printf("%s (%u)", msg_type_to_str(supported_messages[zi]), supported_messages[zi]);
  324. }
  325. printf("\n");
  326. }
  327. static void
  328. cli_parse_long_opt(struct qnetd_advanced_settings *advanced_settings, const char *long_opt)
  329. {
  330. struct dynar_getopt_lex lex;
  331. struct dynar dynar_long_opt;
  332. const char *opt;
  333. const char *val;
  334. int res;
  335. dynar_init(&dynar_long_opt, strlen(long_opt) + 1);
  336. if (dynar_str_cpy(&dynar_long_opt, long_opt) != 0) {
  337. errx(1, "Can't alloc memory for long option");
  338. }
  339. dynar_getopt_lex_init(&lex, &dynar_long_opt);
  340. while (dynar_getopt_lex_token_next(&lex) == 0 && strcmp(dynar_data(&lex.option), "") != 0) {
  341. opt = dynar_data(&lex.option);
  342. val = dynar_data(&lex.value);
  343. res = qnetd_advanced_settings_set(advanced_settings, opt, val);
  344. switch (res) {
  345. case -1:
  346. errx(1, "Unknown option '%s'", opt);
  347. break;
  348. case -2:
  349. errx(1, "Invalid value '%s' for option '%s'", val, opt);
  350. break;
  351. }
  352. }
  353. dynar_getopt_lex_destroy(&lex);
  354. dynar_destroy(&dynar_long_opt);
  355. }
  356. static void
  357. cli_parse(int argc, char * const argv[], char **host_addr, uint16_t *host_port, int *foreground,
  358. int *debug_log, int *bump_log_priority, enum tlv_tls_supported *tls_supported,
  359. int *client_cert_required, size_t *max_clients, PRIntn *address_family,
  360. struct qnetd_advanced_settings *advanced_settings)
  361. {
  362. int ch;
  363. char *ep;
  364. long long int tmpll;
  365. *host_addr = NULL;
  366. *host_port = QNETD_DEFAULT_HOST_PORT;
  367. *foreground = 0;
  368. *debug_log = 0;
  369. *bump_log_priority = 0;
  370. *tls_supported = QNETD_DEFAULT_TLS_SUPPORTED;
  371. *client_cert_required = QNETD_DEFAULT_TLS_CLIENT_CERT_REQUIRED;
  372. *max_clients = QNETD_DEFAULT_MAX_CLIENTS;
  373. *address_family = PR_AF_UNSPEC;
  374. while ((ch = getopt(argc, argv, "46dfhvc:l:m:p:S:s:")) != -1) {
  375. switch (ch) {
  376. case '4':
  377. *address_family = PR_AF_INET;
  378. break;
  379. case '6':
  380. *address_family = PR_AF_INET6;
  381. break;
  382. case 'f':
  383. *foreground = 1;
  384. break;
  385. case 'd':
  386. if (*debug_log) {
  387. *bump_log_priority = 1;
  388. }
  389. *debug_log = 1;
  390. break;
  391. case 'c':
  392. if ((*client_cert_required = utils_parse_bool_str(optarg)) == -1) {
  393. errx(1, "client_cert_required should be on/yes/1, off/no/0");
  394. }
  395. break;
  396. case 'l':
  397. free(*host_addr);
  398. *host_addr = strdup(optarg);
  399. if (*host_addr == NULL) {
  400. errx(1, "Can't alloc memory for host addr string");
  401. }
  402. break;
  403. case 'm':
  404. errno = 0;
  405. tmpll = strtoll(optarg, &ep, 10);
  406. if (tmpll < 0 || errno != 0 || *ep != '\0') {
  407. errx(1, "max clients value %s is invalid", optarg);
  408. }
  409. *max_clients = (size_t)tmpll;
  410. break;
  411. case 'p':
  412. *host_port = strtol(optarg, &ep, 10);
  413. if (*host_port <= 0 || *host_port > ((uint16_t)~0) || *ep != '\0') {
  414. errx(1, "host port must be in range 0-65535");
  415. }
  416. break;
  417. case 'S':
  418. cli_parse_long_opt(advanced_settings, optarg);
  419. break;
  420. case 's':
  421. if (strcasecmp(optarg, "on") == 0) {
  422. *tls_supported = QNETD_DEFAULT_TLS_SUPPORTED;
  423. } else if (strcasecmp(optarg, "off") == 0) {
  424. *tls_supported = TLV_TLS_UNSUPPORTED;
  425. } else if (strcasecmp(optarg, "req") == 0) {
  426. *tls_supported = TLV_TLS_REQUIRED;
  427. } else {
  428. errx(1, "tls must be one of on, off, req");
  429. }
  430. break;
  431. case 'v':
  432. display_version();
  433. exit(1);
  434. break;
  435. case 'h':
  436. case '?':
  437. usage();
  438. exit(1);
  439. break;
  440. }
  441. }
  442. }
  443. int
  444. main(int argc, char * const argv[])
  445. {
  446. struct qnetd_instance instance;
  447. struct qnetd_advanced_settings advanced_settings;
  448. char *host_addr;
  449. uint16_t host_port;
  450. int foreground;
  451. int debug_log;
  452. int bump_log_priority;
  453. enum tlv_tls_supported tls_supported;
  454. int client_cert_required;
  455. size_t max_clients;
  456. PRIntn address_family;
  457. int lock_file;
  458. int another_instance_running;
  459. if (qnetd_advanced_settings_init(&advanced_settings) != 0) {
  460. errx(1, "Can't alloc memory for advanced settings");
  461. }
  462. cli_parse(argc, argv, &host_addr, &host_port, &foreground, &debug_log, &bump_log_priority,
  463. &tls_supported, &client_cert_required, &max_clients, &address_family, &advanced_settings);
  464. if (foreground) {
  465. qnetd_log_init(QNETD_LOG_TARGET_STDERR);
  466. } else {
  467. qnetd_log_init(QNETD_LOG_TARGET_SYSLOG);
  468. }
  469. qnetd_log_set_debug(debug_log);
  470. qnetd_log_set_priority_bump(bump_log_priority);
  471. /*
  472. * Daemonize
  473. */
  474. if (!foreground) {
  475. utils_tty_detach();
  476. }
  477. if ((lock_file = utils_flock(advanced_settings.lock_file, getpid(),
  478. &another_instance_running)) == -1) {
  479. if (another_instance_running) {
  480. qnetd_log(LOG_ERR, "Another instance is running");
  481. } else {
  482. qnetd_log_err(LOG_ERR, "Can't acquire lock");
  483. }
  484. exit(1);
  485. }
  486. qnetd_log(LOG_DEBUG, "Initializing nss");
  487. if (nss_sock_init_nss((tls_supported != TLV_TLS_UNSUPPORTED ?
  488. advanced_settings.nss_db_dir : NULL)) != 0) {
  489. qnetd_err_nss();
  490. }
  491. if (SSL_ConfigServerSessionIDCache(0, 0, 0, NULL) != SECSuccess) {
  492. qnetd_err_nss();
  493. }
  494. if (qnetd_instance_init(&instance, tls_supported, client_cert_required,
  495. max_clients, &advanced_settings) == -1) {
  496. qnetd_log(LOG_ERR, "Can't initialize qnetd");
  497. exit(1);
  498. }
  499. instance.host_addr = host_addr;
  500. instance.host_port = host_port;
  501. if (tls_supported != TLV_TLS_UNSUPPORTED && qnetd_instance_init_certs(&instance) == -1) {
  502. qnetd_err_nss();
  503. }
  504. qnetd_log(LOG_DEBUG, "Initializing local socket");
  505. if (qnetd_ipc_init(&instance) != 0) {
  506. return (1);
  507. }
  508. qnetd_log(LOG_DEBUG, "Creating listening socket");
  509. instance.server.socket = nss_sock_create_listen_socket(instance.host_addr,
  510. instance.host_port, address_family);
  511. if (instance.server.socket == NULL) {
  512. qnetd_err_nss();
  513. }
  514. if (nss_sock_set_non_blocking(instance.server.socket) != 0) {
  515. qnetd_err_nss();
  516. }
  517. if (PR_Listen(instance.server.socket, instance.advanced_settings->listen_backlog) !=
  518. PR_SUCCESS) {
  519. qnetd_err_nss();
  520. }
  521. global_instance = &instance;
  522. signal_handlers_register();
  523. qnetd_log(LOG_DEBUG, "Registering algorithms");
  524. if (qnetd_algorithm_register_all() != 0) {
  525. exit(1);
  526. }
  527. qnetd_log(LOG_DEBUG, "QNetd ready to provide service");
  528. #ifdef HAVE_LIBSYSTEMD
  529. sd_notify(0, "READY=1");
  530. #endif
  531. /*
  532. * MAIN LOOP
  533. */
  534. while (qnetd_poll(&instance) == 0) {
  535. }
  536. /*
  537. * Cleanup
  538. */
  539. qnetd_ipc_destroy(&instance);
  540. if (PR_Close(instance.server.socket) != PR_SUCCESS) {
  541. qnetd_warn_nss();
  542. }
  543. CERT_DestroyCertificate(instance.server.cert);
  544. SECKEY_DestroyPrivateKey(instance.server.private_key);
  545. SSL_ClearSessionCache();
  546. SSL_ShutdownServerSessionIDCache();
  547. qnetd_instance_destroy(&instance);
  548. qnetd_advanced_settings_destroy(&advanced_settings);
  549. if (NSS_Shutdown() != SECSuccess) {
  550. qnetd_warn_nss();
  551. }
  552. if (PR_Cleanup() != PR_SUCCESS) {
  553. qnetd_warn_nss();
  554. }
  555. qnetd_log_close();
  556. return (0);
  557. }