corosync-qnetd.c 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666
  1. /*
  2. * Copyright (c) 2015-2019 Red Hat, Inc.
  3. *
  4. * All rights reserved.
  5. *
  6. * Author: Jan Friesse (jfriesse@redhat.com)
  7. *
  8. * This software licensed under BSD license, the text of which follows:
  9. *
  10. * Redistribution and use in source and binary forms, with or without
  11. * modification, are permitted provided that the following conditions are met:
  12. *
  13. * - Redistributions of source code must retain the above copyright notice,
  14. * this list of conditions and the following disclaimer.
  15. * - Redistributions in binary form must reproduce the above copyright notice,
  16. * this list of conditions and the following disclaimer in the documentation
  17. * and/or other materials provided with the distribution.
  18. * - Neither the name of the Red Hat, Inc. nor the names of its
  19. * contributors may be used to endorse or promote products derived from this
  20. * software without specific prior written permission.
  21. *
  22. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS"
  23. * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
  24. * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
  25. * ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE
  26. * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
  27. * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
  28. * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
  29. * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
  30. * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
  31. * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
  32. * THE POSSIBILITY OF SUCH DAMAGE.
  33. */
  34. #include <err.h>
  35. #include <errno.h>
  36. #include <getopt.h>
  37. #include <limits.h>
  38. #include <signal.h>
  39. #include <unistd.h>
  40. #include "qnet-config.h"
  41. #include "dynar.h"
  42. #include "dynar-str.h"
  43. #include "dynar-getopt-lex.h"
  44. #include "log.h"
  45. #include "nss-sock.h"
  46. #include "pr-poll-array.h"
  47. #include "qnetd-advanced-settings.h"
  48. #include "qnetd-algorithm.h"
  49. #include "qnetd-instance.h"
  50. #include "qnetd-ipc.h"
  51. #include "qnetd-client-net.h"
  52. #include "qnetd-client-msg-received.h"
  53. #include "qnetd-poll-array-user-data.h"
  54. #include "utils.h"
  55. #include "msg.h"
  56. /*
  57. * This is global variable used for comunication with main loop and signal (calls close)
  58. */
  59. struct qnetd_instance *global_instance;
  60. enum tlv_decision_algorithm_type
  61. qnetd_static_supported_decision_algorithms[QNETD_STATIC_SUPPORTED_DECISION_ALGORITHMS_SIZE] = {
  62. TLV_DECISION_ALGORITHM_TYPE_TEST,
  63. TLV_DECISION_ALGORITHM_TYPE_FFSPLIT,
  64. TLV_DECISION_ALGORITHM_TYPE_2NODELMS,
  65. TLV_DECISION_ALGORITHM_TYPE_LMS,
  66. };
  67. static void
  68. qnetd_err_nss(void)
  69. {
  70. log_nss(LOG_CRIT, "NSS error");
  71. exit(1);
  72. }
  73. static void
  74. qnetd_warn_nss(void)
  75. {
  76. log_nss(LOG_WARNING, "NSS warning");
  77. }
  78. static PRPollDesc *
  79. qnetd_pr_poll_array_create(struct qnetd_instance *instance)
  80. {
  81. struct pr_poll_array *poll_array;
  82. const struct qnetd_client_list *client_list;
  83. struct qnetd_client *client;
  84. PRPollDesc *poll_desc;
  85. struct qnetd_poll_array_user_data *user_data;
  86. const struct unix_socket_client_list *ipc_client_list;
  87. struct unix_socket_client *ipc_client;
  88. poll_array = &instance->poll_array;
  89. client_list = &instance->clients;
  90. ipc_client_list = &instance->local_ipc.clients;
  91. pr_poll_array_clean(poll_array);
  92. if (pr_poll_array_add(poll_array, &poll_desc, (void **)&user_data) < 0) {
  93. return (NULL);
  94. }
  95. poll_desc->fd = instance->server.socket;
  96. poll_desc->in_flags = PR_POLL_READ;
  97. user_data->type = QNETD_POLL_ARRAY_USER_DATA_TYPE_SOCKET;
  98. if (qnetd_ipc_is_closed(instance)) {
  99. log(LOG_DEBUG, "Listening socket is closed");
  100. return (NULL);
  101. }
  102. if (pr_poll_array_add(poll_array, &poll_desc, (void **)&user_data) < 0) {
  103. return (NULL);
  104. }
  105. poll_desc->fd = instance->ipc_socket_poll_fd;
  106. poll_desc->in_flags = PR_POLL_READ;
  107. user_data->type = QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_SOCKET;
  108. TAILQ_FOREACH(client, client_list, entries) {
  109. if (pr_poll_array_add(poll_array, &poll_desc, (void **)&user_data) < 0) {
  110. return (NULL);
  111. }
  112. poll_desc->fd = client->socket;
  113. poll_desc->in_flags = PR_POLL_READ;
  114. if (!send_buffer_list_empty(&client->send_buffer_list)) {
  115. poll_desc->in_flags |= PR_POLL_WRITE;
  116. }
  117. user_data->type = QNETD_POLL_ARRAY_USER_DATA_TYPE_CLIENT;
  118. user_data->client = client;
  119. }
  120. TAILQ_FOREACH(ipc_client, ipc_client_list, entries) {
  121. if (!ipc_client->reading_line && !ipc_client->writing_buffer) {
  122. continue;
  123. }
  124. if (pr_poll_array_add(poll_array, &poll_desc, (void **)&user_data) < 0) {
  125. return (NULL);
  126. }
  127. poll_desc->fd = ((struct qnetd_ipc_user_data *)ipc_client->user_data)->nspr_poll_fd;
  128. if (ipc_client->reading_line) {
  129. poll_desc->in_flags |= PR_POLL_READ;
  130. }
  131. if (ipc_client->writing_buffer) {
  132. poll_desc->in_flags |= PR_POLL_WRITE;
  133. }
  134. user_data->type = QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_CLIENT;
  135. user_data->ipc_client = ipc_client;
  136. }
  137. pr_poll_array_gc(poll_array);
  138. return (poll_array->array);
  139. }
  140. static int
  141. qnetd_poll(struct qnetd_instance *instance)
  142. {
  143. struct qnetd_client *client;
  144. PRPollDesc *pfds;
  145. PRInt32 poll_res;
  146. ssize_t i;
  147. int client_disconnect;
  148. struct qnetd_poll_array_user_data *user_data;
  149. struct unix_socket_client *ipc_client;
  150. client = NULL;
  151. client_disconnect = 0;
  152. pfds = qnetd_pr_poll_array_create(instance);
  153. if (pfds == NULL) {
  154. return (-1);
  155. }
  156. if ((poll_res = PR_Poll(pfds, pr_poll_array_size(&instance->poll_array),
  157. timer_list_time_to_expire(&instance->main_timer_list))) >= 0) {
  158. timer_list_expire(&instance->main_timer_list);
  159. /*
  160. * Walk thru pfds array and process events
  161. */
  162. for (i = 0; i < pr_poll_array_size(&instance->poll_array); i++) {
  163. user_data = pr_poll_array_get_user_data(&instance->poll_array, i);
  164. client = NULL;
  165. ipc_client = NULL;
  166. client_disconnect = 0;
  167. switch (user_data->type) {
  168. case QNETD_POLL_ARRAY_USER_DATA_TYPE_SOCKET:
  169. break;
  170. case QNETD_POLL_ARRAY_USER_DATA_TYPE_CLIENT:
  171. client = user_data->client;
  172. client_disconnect = client->schedule_disconnect;
  173. break;
  174. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_SOCKET:
  175. break;
  176. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_CLIENT:
  177. ipc_client = user_data->ipc_client;
  178. client_disconnect = ipc_client->schedule_disconnect;
  179. }
  180. if (!client_disconnect && poll_res > 0 &&
  181. pfds[i].out_flags & PR_POLL_READ) {
  182. switch (user_data->type) {
  183. case QNETD_POLL_ARRAY_USER_DATA_TYPE_SOCKET:
  184. qnetd_client_net_accept(instance);
  185. break;
  186. case QNETD_POLL_ARRAY_USER_DATA_TYPE_CLIENT:
  187. if (qnetd_client_net_read(instance, client) == -1) {
  188. client_disconnect = 1;
  189. }
  190. break;
  191. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_SOCKET:
  192. qnetd_ipc_accept(instance, &ipc_client);
  193. break;
  194. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_CLIENT:
  195. qnetd_ipc_io_read(instance, ipc_client);
  196. break;
  197. }
  198. }
  199. if (!client_disconnect && poll_res > 0 &&
  200. pfds[i].out_flags & PR_POLL_WRITE) {
  201. switch (user_data->type) {
  202. case QNETD_POLL_ARRAY_USER_DATA_TYPE_SOCKET:
  203. /*
  204. * Poll write on listen socket -> fatal error
  205. */
  206. log(LOG_CRIT, "POLL_WRITE on listening socket");
  207. return (-1);
  208. break;
  209. case QNETD_POLL_ARRAY_USER_DATA_TYPE_CLIENT:
  210. if (qnetd_client_net_write(instance, client) == -1) {
  211. client_disconnect = 1;
  212. }
  213. break;
  214. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_SOCKET:
  215. log(LOG_CRIT, "POLL_WRITE on listening IPC socket");
  216. return (-1);
  217. break;
  218. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_CLIENT:
  219. qnetd_ipc_io_write(instance, ipc_client);
  220. break;
  221. }
  222. }
  223. if (!client_disconnect && poll_res > 0 &&
  224. (pfds[i].out_flags & (PR_POLL_ERR|PR_POLL_NVAL|PR_POLL_HUP|PR_POLL_EXCEPT)) &&
  225. !(pfds[i].out_flags & (PR_POLL_READ|PR_POLL_WRITE))) {
  226. switch (user_data->type) {
  227. case QNETD_POLL_ARRAY_USER_DATA_TYPE_SOCKET:
  228. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_SOCKET:
  229. if (pfds[i].out_flags != PR_POLL_NVAL) {
  230. /*
  231. * Poll ERR on listening socket is fatal error.
  232. * POLL_NVAL is used as a signal to quit poll loop.
  233. */
  234. log(LOG_CRIT, "POLL_ERR (%u) on listening "
  235. "socket", pfds[i].out_flags);
  236. } else {
  237. log(LOG_DEBUG, "Listening socket is closed");
  238. }
  239. return (-1);
  240. break;
  241. case QNETD_POLL_ARRAY_USER_DATA_TYPE_CLIENT:
  242. log(LOG_DEBUG, "POLL_ERR (%u) on client socket. "
  243. "Disconnecting.", pfds[i].out_flags);
  244. client_disconnect = 1;
  245. break;
  246. case QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_CLIENT:
  247. log(LOG_DEBUG, "POLL_ERR (%u) on ipc client socket."
  248. " Disconnecting.", pfds[i].out_flags);
  249. client_disconnect = 1;
  250. break;
  251. }
  252. }
  253. /*
  254. * If client is scheduled for disconnect, disconnect it
  255. */
  256. if (user_data->type == QNETD_POLL_ARRAY_USER_DATA_TYPE_CLIENT &&
  257. client_disconnect) {
  258. qnetd_instance_client_disconnect(instance, client, 0);
  259. } else if (user_data->type == QNETD_POLL_ARRAY_USER_DATA_TYPE_IPC_CLIENT &&
  260. (client_disconnect || ipc_client->schedule_disconnect)) {
  261. qnetd_ipc_client_disconnect(instance, ipc_client);
  262. }
  263. }
  264. }
  265. return (0);
  266. }
  267. static void
  268. signal_int_handler(int sig)
  269. {
  270. log(LOG_DEBUG, "SIGINT received - closing server IPC socket");
  271. qnetd_ipc_close(global_instance);
  272. }
  273. static void
  274. signal_term_handler(int sig)
  275. {
  276. log(LOG_DEBUG, "SIGTERM received - closing server IPC socket");
  277. qnetd_ipc_close(global_instance);
  278. }
  279. static void
  280. signal_handlers_register(void)
  281. {
  282. struct sigaction act;
  283. act.sa_handler = signal_int_handler;
  284. sigemptyset(&act.sa_mask);
  285. act.sa_flags = SA_RESTART;
  286. sigaction(SIGINT, &act, NULL);
  287. act.sa_handler = signal_term_handler;
  288. sigemptyset(&act.sa_mask);
  289. act.sa_flags = SA_RESTART;
  290. sigaction(SIGTERM, &act, NULL);
  291. }
  292. static void
  293. usage(void)
  294. {
  295. printf("usage: %s [-46dfhv] [-l listen_addr] [-p listen_port] [-s tls]\n", QNETD_PROGRAM_NAME);
  296. printf("%14s[-c client_cert_required] [-m max_clients] [-S option=value[,option2=value2,...]]\n", "");
  297. }
  298. static void
  299. display_version(void)
  300. {
  301. enum msg_type *supported_messages;
  302. size_t no_supported_messages;
  303. size_t zi;
  304. msg_get_supported_messages(&supported_messages, &no_supported_messages);
  305. printf("Corosync Qdevice Network Daemon, version '%s'\n\n", VERSION);
  306. printf("Supported algorithms: ");
  307. for (zi = 0; zi < QNETD_STATIC_SUPPORTED_DECISION_ALGORITHMS_SIZE; zi++) {
  308. if (zi != 0) {
  309. printf(", ");
  310. }
  311. printf("%s (%u)",
  312. tlv_decision_algorithm_type_to_str(qnetd_static_supported_decision_algorithms[zi]),
  313. qnetd_static_supported_decision_algorithms[zi]);
  314. }
  315. printf("\n");
  316. printf("Supported message types: ");
  317. for (zi = 0; zi < no_supported_messages; zi++) {
  318. if (zi != 0) {
  319. printf(", ");
  320. }
  321. printf("%s (%u)", msg_type_to_str(supported_messages[zi]), supported_messages[zi]);
  322. }
  323. printf("\n");
  324. }
  325. static void
  326. cli_parse_long_opt(struct qnetd_advanced_settings *advanced_settings, const char *long_opt)
  327. {
  328. struct dynar_getopt_lex lex;
  329. struct dynar dynar_long_opt;
  330. const char *opt;
  331. const char *val;
  332. int res;
  333. dynar_init(&dynar_long_opt, strlen(long_opt) + 1);
  334. if (dynar_str_cpy(&dynar_long_opt, long_opt) != 0) {
  335. errx(1, "Can't alloc memory for long option");
  336. }
  337. dynar_getopt_lex_init(&lex, &dynar_long_opt);
  338. while (dynar_getopt_lex_token_next(&lex) == 0 && strcmp(dynar_data(&lex.option), "") != 0) {
  339. opt = dynar_data(&lex.option);
  340. val = dynar_data(&lex.value);
  341. res = qnetd_advanced_settings_set(advanced_settings, opt, val);
  342. switch (res) {
  343. case -1:
  344. errx(1, "Unknown option '%s'", opt);
  345. break;
  346. case -2:
  347. errx(1, "Invalid value '%s' for option '%s'", val, opt);
  348. break;
  349. }
  350. }
  351. dynar_getopt_lex_destroy(&lex);
  352. dynar_destroy(&dynar_long_opt);
  353. }
  354. static void
  355. cli_parse(int argc, char * const argv[], char **host_addr, uint16_t *host_port, int *foreground,
  356. int *debug_log, int *bump_log_priority, enum tlv_tls_supported *tls_supported,
  357. int *client_cert_required, size_t *max_clients, PRIntn *address_family,
  358. struct qnetd_advanced_settings *advanced_settings)
  359. {
  360. int ch;
  361. long long int tmpll;
  362. *host_addr = NULL;
  363. *host_port = QNETD_DEFAULT_HOST_PORT;
  364. *foreground = 0;
  365. *debug_log = 0;
  366. *bump_log_priority = 0;
  367. *tls_supported = QNETD_DEFAULT_TLS_SUPPORTED;
  368. *client_cert_required = QNETD_DEFAULT_TLS_CLIENT_CERT_REQUIRED;
  369. *max_clients = QNETD_DEFAULT_MAX_CLIENTS;
  370. *address_family = PR_AF_UNSPEC;
  371. while ((ch = getopt(argc, argv, "46dfhvc:l:m:p:S:s:")) != -1) {
  372. switch (ch) {
  373. case '4':
  374. *address_family = PR_AF_INET;
  375. break;
  376. case '6':
  377. *address_family = PR_AF_INET6;
  378. break;
  379. case 'f':
  380. *foreground = 1;
  381. break;
  382. case 'd':
  383. if (*debug_log) {
  384. *bump_log_priority = 1;
  385. }
  386. *debug_log = 1;
  387. break;
  388. case 'c':
  389. if ((*client_cert_required = utils_parse_bool_str(optarg)) == -1) {
  390. errx(1, "client_cert_required should be on/yes/1, off/no/0");
  391. }
  392. break;
  393. case 'l':
  394. free(*host_addr);
  395. *host_addr = strdup(optarg);
  396. if (*host_addr == NULL) {
  397. errx(1, "Can't alloc memory for host addr string");
  398. }
  399. break;
  400. case 'm':
  401. if (utils_strtonum(optarg, 0, LLONG_MAX, &tmpll) == -1) {
  402. errx(1, "max clients value %s is invalid", optarg);
  403. }
  404. *max_clients = (size_t)tmpll;
  405. break;
  406. case 'p':
  407. if (utils_strtonum(optarg, 1, UINT16_MAX, &tmpll) == -1) {
  408. errx(1, "host port must be in range 1-%u", UINT16_MAX);
  409. }
  410. *host_port = tmpll;
  411. break;
  412. case 'S':
  413. cli_parse_long_opt(advanced_settings, optarg);
  414. break;
  415. case 's':
  416. if (strcasecmp(optarg, "on") == 0) {
  417. *tls_supported = QNETD_DEFAULT_TLS_SUPPORTED;
  418. } else if (strcasecmp(optarg, "off") == 0) {
  419. *tls_supported = TLV_TLS_UNSUPPORTED;
  420. } else if (strcasecmp(optarg, "req") == 0) {
  421. *tls_supported = TLV_TLS_REQUIRED;
  422. } else {
  423. errx(1, "tls must be one of on, off, req");
  424. }
  425. break;
  426. case 'v':
  427. display_version();
  428. exit(1);
  429. break;
  430. case 'h':
  431. case '?':
  432. usage();
  433. exit(1);
  434. break;
  435. }
  436. }
  437. }
  438. int
  439. main(int argc, char * const argv[])
  440. {
  441. struct qnetd_instance instance;
  442. struct qnetd_advanced_settings advanced_settings;
  443. char *host_addr;
  444. uint16_t host_port;
  445. int foreground;
  446. int debug_log;
  447. int bump_log_priority;
  448. enum tlv_tls_supported tls_supported;
  449. int client_cert_required;
  450. size_t max_clients;
  451. PRIntn address_family;
  452. int lock_file;
  453. int another_instance_running;
  454. int log_target;
  455. if (qnetd_advanced_settings_init(&advanced_settings) != 0) {
  456. errx(1, "Can't alloc memory for advanced settings");
  457. }
  458. cli_parse(argc, argv, &host_addr, &host_port, &foreground, &debug_log, &bump_log_priority,
  459. &tls_supported, &client_cert_required, &max_clients, &address_family, &advanced_settings);
  460. log_target = LOG_TARGET_SYSLOG;
  461. if (foreground) {
  462. log_target |= LOG_TARGET_STDERR;
  463. }
  464. if (log_init(QNETD_PROGRAM_NAME, log_target, LOG_DAEMON) == -1) {
  465. errx(1, "Can't initialize logging");
  466. }
  467. log_set_debug(debug_log);
  468. log_set_priority_bump(bump_log_priority);
  469. /*
  470. * Check that it's possible to open NSS dir if needed
  471. */
  472. if (nss_sock_check_db_dir((tls_supported != TLV_TLS_UNSUPPORTED ?
  473. advanced_settings.nss_db_dir : NULL)) != 0) {
  474. log_err(LOG_ERR, "Can't open NSS DB directory");
  475. exit (1);
  476. }
  477. /*
  478. * Daemonize
  479. */
  480. if (!foreground) {
  481. utils_tty_detach();
  482. }
  483. if ((lock_file = utils_flock(advanced_settings.lock_file, getpid(),
  484. &another_instance_running)) == -1) {
  485. if (another_instance_running) {
  486. log(LOG_ERR, "Another instance is running");
  487. } else {
  488. log_err(LOG_ERR, "Can't acquire lock");
  489. }
  490. exit(1);
  491. }
  492. log(LOG_DEBUG, "Initializing nss");
  493. if (nss_sock_init_nss((tls_supported != TLV_TLS_UNSUPPORTED ?
  494. advanced_settings.nss_db_dir : NULL)) != 0) {
  495. qnetd_err_nss();
  496. }
  497. if (SSL_ConfigServerSessionIDCache(0, 0, 0, NULL) != SECSuccess) {
  498. qnetd_err_nss();
  499. }
  500. if (qnetd_instance_init(&instance, tls_supported, client_cert_required,
  501. max_clients, &advanced_settings) == -1) {
  502. log(LOG_ERR, "Can't initialize qnetd");
  503. exit(1);
  504. }
  505. instance.host_addr = host_addr;
  506. instance.host_port = host_port;
  507. if (tls_supported != TLV_TLS_UNSUPPORTED && qnetd_instance_init_certs(&instance) == -1) {
  508. qnetd_err_nss();
  509. }
  510. log(LOG_DEBUG, "Initializing local socket");
  511. if (qnetd_ipc_init(&instance) != 0) {
  512. return (1);
  513. }
  514. log(LOG_DEBUG, "Creating listening socket");
  515. instance.server.socket = nss_sock_create_listen_socket(instance.host_addr,
  516. instance.host_port, address_family);
  517. if (instance.server.socket == NULL) {
  518. qnetd_err_nss();
  519. }
  520. if (nss_sock_set_non_blocking(instance.server.socket) != 0) {
  521. qnetd_err_nss();
  522. }
  523. if (PR_Listen(instance.server.socket, instance.advanced_settings->listen_backlog) !=
  524. PR_SUCCESS) {
  525. qnetd_err_nss();
  526. }
  527. global_instance = &instance;
  528. signal_handlers_register();
  529. log(LOG_DEBUG, "Registering algorithms");
  530. if (qnetd_algorithm_register_all() != 0) {
  531. exit(1);
  532. }
  533. log(LOG_DEBUG, "QNetd ready to provide service");
  534. /*
  535. * MAIN LOOP
  536. */
  537. while (qnetd_poll(&instance) == 0) {
  538. }
  539. /*
  540. * Cleanup
  541. */
  542. qnetd_ipc_destroy(&instance);
  543. if (PR_Close(instance.server.socket) != PR_SUCCESS) {
  544. qnetd_warn_nss();
  545. }
  546. CERT_DestroyCertificate(instance.server.cert);
  547. SECKEY_DestroyPrivateKey(instance.server.private_key);
  548. SSL_ClearSessionCache();
  549. SSL_ShutdownServerSessionIDCache();
  550. qnetd_instance_destroy(&instance);
  551. qnetd_advanced_settings_destroy(&advanced_settings);
  552. if (NSS_Shutdown() != SECSuccess) {
  553. qnetd_warn_nss();
  554. }
  555. if (PR_Cleanup() != PR_SUCCESS) {
  556. qnetd_warn_nss();
  557. }
  558. log_close();
  559. return (0);
  560. }