s3/packaging: Add keyutils-devel to build requires.
[Samba/bb.git] / source / smbd / server.c
blobb05758ea4ebba1b5b70f36fda4b2778a75864948
1 /*
2 Unix SMB/CIFS implementation.
3 Main SMB server routines
4 Copyright (C) Andrew Tridgell 1992-1998
5 Copyright (C) Martin Pool 2002
6 Copyright (C) Jelmer Vernooij 2002-2003
7 Copyright (C) Volker Lendecke 1993-2007
8 Copyright (C) Jeremy Allison 1993-2007
10 This program is free software; you can redistribute it and/or modify
11 it under the terms of the GNU General Public License as published by
12 the Free Software Foundation; either version 3 of the License, or
13 (at your option) any later version.
15 This program is distributed in the hope that it will be useful,
16 but WITHOUT ANY WARRANTY; without even the implied warranty of
17 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
18 GNU General Public License for more details.
20 You should have received a copy of the GNU General Public License
21 along with this program. If not, see <http://www.gnu.org/licenses/>.
24 #include "includes.h"
26 static_decl_rpc;
28 static int am_parent = 1;
30 extern struct auth_context *negprot_global_auth_context;
31 extern SIG_ATOMIC_T got_sig_term;
32 extern SIG_ATOMIC_T reload_after_sighup;
33 static SIG_ATOMIC_T got_sig_cld;
35 #ifdef WITH_DFS
36 extern int dcelogin_atmost_once;
37 #endif /* WITH_DFS */
39 /* really we should have a top level context structure that has the
40 client file descriptor as an element. That would require a major rewrite :(
42 the following 2 functions are an alternative - they make the file
43 descriptor private to smbd
45 static int server_fd = -1;
47 int smbd_server_fd(void)
49 return server_fd;
52 static void smbd_set_server_fd(int fd)
54 server_fd = fd;
57 int get_client_fd(void)
59 return server_fd;
62 #ifdef CLUSTER_SUPPORT
63 static int client_get_tcp_info(struct sockaddr_storage *server,
64 struct sockaddr_storage *client)
66 socklen_t length;
67 if (server_fd == -1) {
68 return -1;
70 length = sizeof(*server);
71 if (getsockname(server_fd, (struct sockaddr *)server, &length) != 0) {
72 return -1;
74 length = sizeof(*client);
75 if (getpeername(server_fd, (struct sockaddr *)client, &length) != 0) {
76 return -1;
78 return 0;
80 #endif
82 struct event_context *smbd_event_context(void)
84 static struct event_context *ctx;
86 if (!ctx && !(ctx = event_context_init(talloc_autofree_context()))) {
87 smb_panic("Could not init smbd event context");
89 return ctx;
92 struct messaging_context *smbd_messaging_context(void)
94 static struct messaging_context *ctx;
96 if (ctx == NULL) {
97 ctx = messaging_init(talloc_autofree_context(), server_id_self(),
98 smbd_event_context());
100 if (ctx == NULL) {
101 DEBUG(0, ("Could not init smbd messaging context.\n"));
103 return ctx;
106 struct memcache *smbd_memcache(void)
108 static struct memcache *cache;
110 if (!cache
111 && !(cache = memcache_init(talloc_autofree_context(),
112 lp_max_stat_cache_size()*1024))) {
114 smb_panic("Could not init smbd memcache");
116 return cache;
119 /*******************************************************************
120 What to do when smb.conf is updated.
121 ********************************************************************/
123 static void smb_conf_updated(struct messaging_context *msg,
124 void *private_data,
125 uint32_t msg_type,
126 struct server_id server_id,
127 DATA_BLOB *data)
129 DEBUG(10,("smb_conf_updated: Got message saying smb.conf was "
130 "updated. Reloading.\n"));
131 reload_services(False);
135 /*******************************************************************
136 Delete a statcache entry.
137 ********************************************************************/
139 static void smb_stat_cache_delete(struct messaging_context *msg,
140 void *private_data,
141 uint32_t msg_tnype,
142 struct server_id server_id,
143 DATA_BLOB *data)
145 const char *name = (const char *)data->data;
146 DEBUG(10,("smb_stat_cache_delete: delete name %s\n", name));
147 stat_cache_delete(name);
150 /****************************************************************************
151 Terminate signal.
152 ****************************************************************************/
154 static void sig_term(void)
156 got_sig_term = 1;
157 sys_select_signal(SIGTERM);
160 /****************************************************************************
161 Catch a sighup.
162 ****************************************************************************/
164 static void sig_hup(int sig)
166 reload_after_sighup = 1;
167 sys_select_signal(SIGHUP);
170 /****************************************************************************
171 Catch a sigcld
172 ****************************************************************************/
173 static void sig_cld(int sig)
175 got_sig_cld = 1;
176 sys_select_signal(SIGCLD);
179 /****************************************************************************
180 Send a SIGTERM to our process group.
181 *****************************************************************************/
183 static void killkids(void)
185 if(am_parent) kill(0,SIGTERM);
188 /****************************************************************************
189 Process a sam sync message - not sure whether to do this here or
190 somewhere else.
191 ****************************************************************************/
193 static void msg_sam_sync(struct messaging_context *msg,
194 void *private_data,
195 uint32_t msg_type,
196 struct server_id server_id,
197 DATA_BLOB *data)
199 DEBUG(10, ("** sam sync message received, ignoring\n"));
203 /****************************************************************************
204 Open the socket communication - inetd.
205 ****************************************************************************/
207 static bool open_sockets_inetd(void)
209 /* Started from inetd. fd 0 is the socket. */
210 /* We will abort gracefully when the client or remote system
211 goes away */
212 smbd_set_server_fd(dup(0));
214 /* close our standard file descriptors */
215 close_low_fds(False); /* Don't close stderr */
217 set_socket_options(smbd_server_fd(),"SO_KEEPALIVE");
218 set_socket_options(smbd_server_fd(), lp_socket_options());
220 return True;
223 static void msg_exit_server(struct messaging_context *msg,
224 void *private_data,
225 uint32_t msg_type,
226 struct server_id server_id,
227 DATA_BLOB *data)
229 DEBUG(3, ("got a SHUTDOWN message\n"));
230 exit_server_cleanly(NULL);
233 #ifdef DEVELOPER
234 static void msg_inject_fault(struct messaging_context *msg,
235 void *private_data,
236 uint32_t msg_type,
237 struct server_id src,
238 DATA_BLOB *data)
240 int sig;
242 if (data->length != sizeof(sig)) {
244 DEBUG(0, ("Process %s sent bogus signal injection request\n",
245 procid_str_static(&src)));
246 return;
249 sig = *(int *)data->data;
250 if (sig == -1) {
251 exit_server("internal error injected");
252 return;
255 #if HAVE_STRSIGNAL
256 DEBUG(0, ("Process %s requested injection of signal %d (%s)\n",
257 procid_str_static(&src), sig, strsignal(sig)));
258 #else
259 DEBUG(0, ("Process %s requested injection of signal %d\n",
260 procid_str_static(&src), sig));
261 #endif
263 kill(sys_getpid(), sig);
265 #endif /* DEVELOPER */
267 struct child_pid {
268 struct child_pid *prev, *next;
269 pid_t pid;
272 static struct child_pid *children;
273 static int num_children;
275 static void add_child_pid(pid_t pid)
277 struct child_pid *child;
279 if (lp_max_smbd_processes() == 0) {
280 /* Don't bother with the child list if we don't care anyway */
281 return;
284 child = SMB_MALLOC_P(struct child_pid);
285 if (child == NULL) {
286 DEBUG(0, ("Could not add child struct -- malloc failed\n"));
287 return;
289 child->pid = pid;
290 DLIST_ADD(children, child);
291 num_children += 1;
294 static void remove_child_pid(pid_t pid, bool unclean_shutdown)
296 struct child_pid *child;
298 if (unclean_shutdown) {
299 /* a child terminated uncleanly so tickle all processes to see
300 if they can grab any of the pending locks
302 DEBUG(3,(__location__ " Unclean shutdown of pid %u\n", (unsigned int)pid));
303 messaging_send_buf(smbd_messaging_context(), procid_self(),
304 MSG_SMB_BRL_VALIDATE, NULL, 0);
305 message_send_all(smbd_messaging_context(),
306 MSG_SMB_UNLOCK, NULL, 0, NULL);
309 if (lp_max_smbd_processes() == 0) {
310 /* Don't bother with the child list if we don't care anyway */
311 return;
314 for (child = children; child != NULL; child = child->next) {
315 if (child->pid == pid) {
316 struct child_pid *tmp = child;
317 DLIST_REMOVE(children, child);
318 SAFE_FREE(tmp);
319 num_children -= 1;
320 return;
324 DEBUG(0, ("Could not find child %d -- ignoring\n", (int)pid));
327 /****************************************************************************
328 Have we reached the process limit ?
329 ****************************************************************************/
331 static bool allowable_number_of_smbd_processes(void)
333 int max_processes = lp_max_smbd_processes();
335 if (!max_processes)
336 return True;
338 return num_children < max_processes;
341 /****************************************************************************
342 Open the socket communication.
343 ****************************************************************************/
345 static bool open_sockets_smbd(bool is_daemon, bool interactive, const char *smb_ports)
347 int num_interfaces = iface_count();
348 int num_sockets = 0;
349 int fd_listenset[FD_SETSIZE];
350 fd_set listen_set;
351 int s;
352 int maxfd = 0;
353 int i;
354 char *ports;
355 struct dns_reg_state * dns_reg = NULL;
356 unsigned dns_port = 0;
358 if (!is_daemon) {
359 return open_sockets_inetd();
362 #ifdef HAVE_ATEXIT
364 static int atexit_set;
365 if(atexit_set == 0) {
366 atexit_set=1;
367 atexit(killkids);
370 #endif
372 /* Stop zombies */
373 CatchSignal(SIGCLD, sig_cld);
375 FD_ZERO(&listen_set);
377 /* use a reasonable default set of ports - listing on 445 and 139 */
378 if (!smb_ports) {
379 ports = lp_smb_ports();
380 if (!ports || !*ports) {
381 ports = smb_xstrdup(SMB_PORTS);
382 } else {
383 ports = smb_xstrdup(ports);
385 } else {
386 ports = smb_xstrdup(smb_ports);
389 if (lp_interfaces() && lp_bind_interfaces_only()) {
390 /* We have been given an interfaces line, and been
391 told to only bind to those interfaces. Create a
392 socket per interface and bind to only these.
395 /* Now open a listen socket for each of the
396 interfaces. */
397 for(i = 0; i < num_interfaces; i++) {
398 TALLOC_CTX *frame = NULL;
399 const struct sockaddr_storage *ifss =
400 iface_n_sockaddr_storage(i);
401 char *tok;
402 const char *ptr;
404 if (ifss == NULL) {
405 DEBUG(0,("open_sockets_smbd: "
406 "interface %d has NULL IP address !\n",
407 i));
408 continue;
411 frame = talloc_stackframe();
412 for (ptr=ports;
413 next_token_talloc(frame,&ptr, &tok, " \t,");) {
414 unsigned port = atoi(tok);
415 if (port == 0 || port > 0xffff) {
416 continue;
419 /* Keep the first port for mDNS service
420 * registration.
422 if (dns_port == 0) {
423 dns_port = port;
426 s = fd_listenset[num_sockets] =
427 open_socket_in(SOCK_STREAM,
428 port,
429 num_sockets == 0 ? 0 : 2,
430 ifss,
431 true);
432 if(s == -1) {
433 continue;
436 /* ready to listen */
437 set_socket_options(s,"SO_KEEPALIVE");
438 set_socket_options(s,lp_socket_options());
440 /* Set server socket to
441 * non-blocking for the accept. */
442 set_blocking(s,False);
444 if (listen(s, SMBD_LISTEN_BACKLOG) == -1) {
445 DEBUG(0,("open_sockets_smbd: listen: "
446 "%s\n", strerror(errno)));
447 close(s);
448 TALLOC_FREE(frame);
449 return False;
451 FD_SET(s,&listen_set);
452 maxfd = MAX( maxfd, s);
454 num_sockets++;
455 if (num_sockets >= FD_SETSIZE) {
456 DEBUG(0,("open_sockets_smbd: Too "
457 "many sockets to bind to\n"));
458 TALLOC_FREE(frame);
459 return False;
462 TALLOC_FREE(frame);
464 } else {
465 /* Just bind to 0.0.0.0 - accept connections
466 from anywhere. */
468 TALLOC_CTX *frame = talloc_stackframe();
469 char *tok;
470 const char *ptr;
471 const char *sock_addr = lp_socket_address();
472 char *sock_tok;
473 const char *sock_ptr;
475 if (strequal(sock_addr, "0.0.0.0") ||
476 strequal(sock_addr, "::")) {
477 #if HAVE_IPV6
478 sock_addr = "::,0.0.0.0";
479 #else
480 sock_addr = "0.0.0.0";
481 #endif
484 for (sock_ptr=sock_addr;
485 next_token_talloc(frame, &sock_ptr, &sock_tok, " \t,"); ) {
486 for (ptr=ports; next_token_talloc(frame, &ptr, &tok, " \t,"); ) {
487 struct sockaddr_storage ss;
489 unsigned port = atoi(tok);
490 if (port == 0 || port > 0xffff) {
491 continue;
494 /* Keep the first port for mDNS service
495 * registration.
497 if (dns_port == 0) {
498 dns_port = port;
501 /* open an incoming socket */
502 if (!interpret_string_addr(&ss, sock_tok,
503 AI_NUMERICHOST|AI_PASSIVE)) {
504 continue;
507 s = open_socket_in(SOCK_STREAM,
508 port,
509 num_sockets == 0 ? 0 : 2,
510 &ss,
511 true);
512 if (s == -1) {
513 continue;
516 /* ready to listen */
517 set_socket_options(s,"SO_KEEPALIVE");
518 set_socket_options(s,lp_socket_options());
520 /* Set server socket to non-blocking
521 * for the accept. */
522 set_blocking(s,False);
524 if (listen(s, SMBD_LISTEN_BACKLOG) == -1) {
525 DEBUG(0,("open_sockets_smbd: "
526 "listen: %s\n",
527 strerror(errno)));
528 close(s);
529 TALLOC_FREE(frame);
530 return False;
533 fd_listenset[num_sockets] = s;
534 FD_SET(s,&listen_set);
535 maxfd = MAX( maxfd, s);
537 num_sockets++;
539 if (num_sockets >= FD_SETSIZE) {
540 DEBUG(0,("open_sockets_smbd: Too "
541 "many sockets to bind to\n"));
542 TALLOC_FREE(frame);
543 return False;
547 TALLOC_FREE(frame);
550 SAFE_FREE(ports);
552 if (num_sockets == 0) {
553 DEBUG(0,("open_sockets_smbd: No "
554 "sockets available to bind to.\n"));
555 return false;
558 /* Setup the main smbd so that we can get messages. Note that
559 do this after starting listening. This is needed as when in
560 clustered mode, ctdb won't allow us to start doing database
561 operations until it has gone thru a full startup, which
562 includes checking to see that smbd is listening. */
563 claim_connection(NULL,"",
564 FLAG_MSG_GENERAL|FLAG_MSG_SMBD|FLAG_MSG_DBWRAP);
566 /* Listen to messages */
568 messaging_register(smbd_messaging_context(), NULL,
569 MSG_SMB_SAM_SYNC, msg_sam_sync);
570 messaging_register(smbd_messaging_context(), NULL,
571 MSG_SHUTDOWN, msg_exit_server);
572 messaging_register(smbd_messaging_context(), NULL,
573 MSG_SMB_FILE_RENAME, msg_file_was_renamed);
574 messaging_register(smbd_messaging_context(), NULL,
575 MSG_SMB_CONF_UPDATED, smb_conf_updated);
576 messaging_register(smbd_messaging_context(), NULL,
577 MSG_SMB_STAT_CACHE_DELETE, smb_stat_cache_delete);
578 brl_register_msgs(smbd_messaging_context());
580 #ifdef CLUSTER_SUPPORT
581 if (lp_clustering()) {
582 ctdbd_register_reconfigure(messaging_ctdbd_connection());
584 #endif
586 #ifdef DEVELOPER
587 messaging_register(smbd_messaging_context(), NULL,
588 MSG_SMB_INJECT_FAULT, msg_inject_fault);
589 #endif
591 /* Kick off our mDNS registration. */
592 if (dns_port != 0) {
593 #ifdef WITH_DNSSD_SUPPORT
594 dns_register_smbd(&dns_reg, dns_port, &maxfd,
595 &r_fds, &idle_timeout);
596 #endif
597 #ifdef WITH_AVAHI_SUPPORT
598 void *avahi_conn;
599 avahi_conn = avahi_start_register(
600 smbd_event_context(), smbd_event_context(),
601 dns_port);
602 if (avahi_conn == NULL) {
603 DEBUG(10, ("avahi_start_register failed\n"));
605 #endif
608 /* now accept incoming connections - forking a new process
609 for each incoming connection */
610 DEBUG(2,("waiting for a connection\n"));
611 while (1) {
612 struct timeval now, idle_timeout;
613 fd_set r_fds, w_fds;
614 int num;
616 /* Ensure we respond to PING and DEBUG messages from the main smbd. */
617 message_dispatch(smbd_messaging_context());
619 if (got_sig_cld) {
620 pid_t pid;
621 int status;
623 got_sig_cld = False;
625 while ((pid = sys_waitpid(-1, &status, WNOHANG)) > 0) {
626 bool unclean_shutdown = False;
628 /* If the child terminated normally, assume
629 it was an unclean shutdown unless the
630 status is 0
632 if (WIFEXITED(status)) {
633 unclean_shutdown = WEXITSTATUS(status);
635 /* If the child terminated due to a signal
636 we always assume it was unclean.
638 if (WIFSIGNALED(status)) {
639 unclean_shutdown = True;
641 remove_child_pid(pid, unclean_shutdown);
645 idle_timeout = timeval_zero();
647 memcpy((char *)&r_fds, (char *)&listen_set,
648 sizeof(listen_set));
649 FD_ZERO(&w_fds);
650 GetTimeOfDay(&now);
652 event_add_to_select_args(smbd_event_context(), &now,
653 &r_fds, &w_fds, &idle_timeout,
654 &maxfd);
656 num = sys_select(maxfd+1,&r_fds,&w_fds,NULL,
657 timeval_is_zero(&idle_timeout) ?
658 NULL : &idle_timeout);
660 if (num == -1 && errno == EINTR) {
661 if (got_sig_term) {
662 exit_server_cleanly(NULL);
665 /* check for sighup processing */
666 if (reload_after_sighup) {
667 change_to_root_user();
668 DEBUG(1,("Reloading services after SIGHUP\n"));
669 reload_services(False);
670 reload_after_sighup = 0;
673 continue;
677 /* If the idle timeout fired and we don't have any connected
678 * users, exit gracefully. We should be running under a process
679 * controller that will restart us if necessry.
681 if (num == 0 && count_all_current_connections() == 0) {
682 exit_server_cleanly("idle timeout");
685 /* process pending nDNS responses */
686 if (dns_register_smbd_reply(dns_reg, &r_fds, &idle_timeout)) {
687 --num;
690 if (run_events(smbd_event_context(), num, &r_fds, &w_fds)) {
691 continue;
694 /* check if we need to reload services */
695 check_reload(time(NULL));
697 /* Find the sockets that are read-ready -
698 accept on these. */
699 for( ; num > 0; num--) {
700 struct sockaddr addr;
701 socklen_t in_addrlen = sizeof(addr);
702 pid_t child = 0;
704 s = -1;
705 for(i = 0; i < num_sockets; i++) {
706 if(FD_ISSET(fd_listenset[i],&r_fds)) {
707 s = fd_listenset[i];
708 /* Clear this so we don't look
709 at it again. */
710 FD_CLR(fd_listenset[i],&r_fds);
711 break;
715 smbd_set_server_fd(accept(s,&addr,&in_addrlen));
717 if (smbd_server_fd() == -1 && errno == EINTR)
718 continue;
720 if (smbd_server_fd() == -1) {
721 DEBUG(2,("open_sockets_smbd: accept: %s\n",
722 strerror(errno)));
723 continue;
726 /* Ensure child is set to blocking mode */
727 set_blocking(smbd_server_fd(),True);
729 if (smbd_server_fd() != -1 && interactive)
730 return True;
732 if (allowable_number_of_smbd_processes() &&
733 smbd_server_fd() != -1 &&
734 ((child = sys_fork())==0)) {
735 char remaddr[INET6_ADDRSTRLEN];
737 /* Child code ... */
739 /* Stop zombies, the parent explicitly handles
740 * them, counting worker smbds. */
741 CatchChild();
743 /* close the listening socket(s) */
744 for(i = 0; i < num_sockets; i++)
745 close(fd_listenset[i]);
747 /* close our mDNS daemon handle */
748 dns_register_close(&dns_reg);
750 /* close our standard file
751 descriptors */
752 close_low_fds(False);
753 am_parent = 0;
755 set_socket_options(smbd_server_fd(),"SO_KEEPALIVE");
756 set_socket_options(smbd_server_fd(),
757 lp_socket_options());
759 /* this is needed so that we get decent entries
760 in smbstatus for port 445 connects */
761 set_remote_machine_name(get_peer_addr(smbd_server_fd(),
762 remaddr,
763 sizeof(remaddr)),
764 false);
766 if (!reinit_after_fork(
767 smbd_messaging_context(),
768 smbd_event_context(),
769 true)) {
770 DEBUG(0,("reinit_after_fork() failed\n"));
771 smb_panic("reinit_after_fork() failed");
774 return True;
776 /* The parent doesn't need this socket */
777 close(smbd_server_fd());
779 /* Sun May 6 18:56:14 2001 ackley@cs.unm.edu:
780 Clear the closed fd info out of server_fd --
781 and more importantly, out of client_fd in
782 util_sock.c, to avoid a possible
783 getpeername failure if we reopen the logs
784 and use %I in the filename.
787 smbd_set_server_fd(-1);
789 if (child != 0) {
790 add_child_pid(child);
793 /* Force parent to check log size after
794 * spawning child. Fix from
795 * klausr@ITAP.Physik.Uni-Stuttgart.De. The
796 * parent smbd will log to logserver.smb. It
797 * writes only two messages for each child
798 * started/finished. But each child writes,
799 * say, 50 messages also in logserver.smb,
800 * begining with the debug_count of the
801 * parent, before the child opens its own log
802 * file logserver.client. In a worst case
803 * scenario the size of logserver.smb would be
804 * checked after about 50*50=2500 messages
805 * (ca. 100kb).
806 * */
807 force_check_log_size();
809 } /* end for num */
810 } /* end while 1 */
812 /* NOTREACHED return True; */
815 /****************************************************************************
816 Reload printers
817 **************************************************************************/
818 void reload_printers(void)
820 int snum;
821 int n_services = lp_numservices();
822 int pnum = lp_servicenumber(PRINTERS_NAME);
823 const char *pname;
825 pcap_cache_reload();
827 /* remove stale printers */
828 for (snum = 0; snum < n_services; snum++) {
829 /* avoid removing PRINTERS_NAME or non-autoloaded printers */
830 if (snum == pnum || !(lp_snum_ok(snum) && lp_print_ok(snum) &&
831 lp_autoloaded(snum)))
832 continue;
834 pname = lp_printername(snum);
835 if (!pcap_printername_ok(pname)) {
836 DEBUG(3, ("removing stale printer %s\n", pname));
838 if (is_printer_published(NULL, snum, NULL))
839 nt_printer_publish(NULL, snum, SPOOL_DS_UNPUBLISH);
840 del_a_printer(pname);
841 lp_killservice(snum);
845 load_printers();
848 /****************************************************************************
849 Reload the services file.
850 **************************************************************************/
852 bool reload_services(bool test)
854 bool ret;
856 if (lp_loaded()) {
857 char *fname = lp_configfile();
858 if (file_exist(fname, NULL) &&
859 !strcsequal(fname, get_dyn_CONFIGFILE())) {
860 set_dyn_CONFIGFILE(fname);
861 test = False;
865 reopen_logs();
867 if (test && !lp_file_list_changed())
868 return(True);
870 lp_killunused(conn_snum_used);
872 ret = lp_load(get_dyn_CONFIGFILE(), False, False, True, True);
874 reload_printers();
876 /* perhaps the config filename is now set */
877 if (!test)
878 reload_services(True);
880 reopen_logs();
882 load_interfaces();
884 if (smbd_server_fd() != -1) {
885 set_socket_options(smbd_server_fd(),"SO_KEEPALIVE");
886 set_socket_options(smbd_server_fd(), lp_socket_options());
889 mangle_reset_cache();
890 reset_stat_cache();
892 /* this forces service parameters to be flushed */
893 set_current_service(NULL,0,True);
895 return(ret);
898 /****************************************************************************
899 Exit the server.
900 ****************************************************************************/
902 /* Reasons for shutting down a server process. */
903 enum server_exit_reason { SERVER_EXIT_NORMAL, SERVER_EXIT_ABNORMAL };
905 static void exit_server_common(enum server_exit_reason how,
906 const char *const reason) NORETURN_ATTRIBUTE;
908 static void exit_server_common(enum server_exit_reason how,
909 const char *const reason)
911 static int firsttime=1;
912 bool had_open_conn;
914 if (!firsttime)
915 exit(0);
916 firsttime = 0;
918 change_to_root_user();
920 if (negprot_global_auth_context) {
921 (negprot_global_auth_context->free)(&negprot_global_auth_context);
924 had_open_conn = conn_close_all();
926 invalidate_all_vuids();
928 /* 3 second timeout. */
929 print_notify_send_messages(smbd_messaging_context(), 3);
931 /* delete our entry in the connections database. */
932 yield_connection(NULL,"");
934 respond_to_all_remaining_local_messages();
936 #ifdef WITH_DFS
937 if (dcelogin_atmost_once) {
938 dfs_unlogin();
940 #endif
942 #ifdef USE_DMAPI
943 /* Destroy Samba DMAPI session only if we are master smbd process */
944 if (am_parent) {
945 if (!dmapi_destroy_session()) {
946 DEBUG(0,("Unable to close Samba DMAPI session\n"));
949 #endif
951 locking_end();
952 printing_end();
954 if (how != SERVER_EXIT_NORMAL) {
955 int oldlevel = DEBUGLEVEL;
957 DEBUGLEVEL = 10;
959 DEBUGSEP(0);
960 DEBUG(0,("Abnormal server exit: %s\n",
961 reason ? reason : "no explanation provided"));
962 DEBUGSEP(0);
964 log_stack_trace();
966 DEBUGLEVEL = oldlevel;
967 dump_core();
969 } else {
970 DEBUG(3,("Server exit (%s)\n",
971 (reason ? reason : "normal exit")));
974 /* if we had any open SMB connections when we exited then we
975 need to tell the parent smbd so that it can trigger a retry
976 of any locks we may have been holding or open files we were
977 blocking */
978 if (had_open_conn) {
979 exit(1);
980 } else {
981 exit(0);
985 void exit_server(const char *const explanation)
987 exit_server_common(SERVER_EXIT_ABNORMAL, explanation);
990 void exit_server_cleanly(const char *const explanation)
992 exit_server_common(SERVER_EXIT_NORMAL, explanation);
995 void exit_server_fault(void)
997 exit_server("critical server fault");
1001 /****************************************************************************
1002 received when we should release a specific IP
1003 ****************************************************************************/
1004 static void release_ip(const char *ip, void *priv)
1006 char addr[INET6_ADDRSTRLEN];
1008 if (strcmp(client_socket_addr(get_client_fd(),addr,sizeof(addr)), ip) == 0) {
1009 /* we can't afford to do a clean exit - that involves
1010 database writes, which would potentially mean we
1011 are still running after the failover has finished -
1012 we have to get rid of this process ID straight
1013 away */
1014 DEBUG(0,("Got release IP message for our IP %s - exiting immediately\n",
1015 ip));
1016 /* note we must exit with non-zero status so the unclean handler gets
1017 called in the parent, so that the brl database is tickled */
1018 _exit(1);
1022 static void msg_release_ip(struct messaging_context *msg_ctx, void *private_data,
1023 uint32_t msg_type, struct server_id server_id, DATA_BLOB *data)
1025 release_ip((char *)data->data, NULL);
1028 /****************************************************************************
1029 Initialise connect, service and file structs.
1030 ****************************************************************************/
1032 static bool init_structs(void )
1035 * Set the machine NETBIOS name if not already
1036 * set from the config file.
1039 if (!init_names())
1040 return False;
1042 conn_init();
1044 file_init();
1046 /* for RPC pipes */
1047 init_rpc_pipe_hnd();
1049 init_dptrs();
1051 if (!secrets_init())
1052 return False;
1054 return True;
1058 * Send keepalive packets to our client
1060 static bool keepalive_fn(const struct timeval *now, void *private_data)
1062 if (!send_keepalive(smbd_server_fd())) {
1063 DEBUG( 2, ( "Keepalive failed - exiting.\n" ) );
1064 return False;
1066 return True;
1070 * Do the recurring check if we're idle
1072 static bool deadtime_fn(const struct timeval *now, void *private_data)
1074 if ((conn_num_open() == 0)
1075 || (conn_idle_all(now->tv_sec))) {
1076 DEBUG( 2, ( "Closing idle connection\n" ) );
1077 messaging_send(smbd_messaging_context(), procid_self(),
1078 MSG_SHUTDOWN, &data_blob_null);
1079 return False;
1082 return True;
1086 * Do the recurring log file and smb.conf reload checks.
1089 static bool housekeeping_fn(const struct timeval *now, void *private_data)
1091 change_to_root_user();
1093 /* update printer queue caches if necessary */
1094 update_monitored_printq_cache();
1096 /* check if we need to reload services */
1097 check_reload(time(NULL));
1099 /* Change machine password if neccessary. */
1100 attempt_machine_password_change();
1103 * Force a log file check.
1105 force_check_log_size();
1106 check_log_size();
1107 return true;
1110 /****************************************************************************
1111 main program.
1112 ****************************************************************************/
1114 /* Declare prototype for build_options() to avoid having to run it through
1115 mkproto.h. Mixing $(builddir) and $(srcdir) source files in the current
1116 prototype generation system is too complicated. */
1118 extern void build_options(bool screen);
1120 int main(int argc,const char *argv[])
1122 /* shall I run as a daemon */
1123 static bool is_daemon = False;
1124 static bool interactive = False;
1125 static bool Fork = True;
1126 static bool no_process_group = False;
1127 static bool log_stdout = False;
1128 static char *ports = NULL;
1129 static char *profile_level = NULL;
1130 int opt;
1131 poptContext pc;
1132 bool print_build_options = False;
1133 enum {
1134 OPT_DAEMON = 1000,
1135 OPT_INTERACTIVE,
1136 OPT_FORK,
1137 OPT_NO_PROCESS_GROUP,
1138 OPT_LOG_STDOUT
1140 struct poptOption long_options[] = {
1141 POPT_AUTOHELP
1142 {"daemon", 'D', POPT_ARG_NONE, NULL, OPT_DAEMON, "Become a daemon (default)" },
1143 {"interactive", 'i', POPT_ARG_NONE, NULL, OPT_INTERACTIVE, "Run interactive (not a daemon)"},
1144 {"foreground", 'F', POPT_ARG_NONE, NULL, OPT_FORK, "Run daemon in foreground (for daemontools, etc.)" },
1145 {"no-process-group", '\0', POPT_ARG_NONE, NULL, OPT_NO_PROCESS_GROUP, "Don't create a new process group" },
1146 {"log-stdout", 'S', POPT_ARG_NONE, NULL, OPT_LOG_STDOUT, "Log to stdout" },
1147 {"build-options", 'b', POPT_ARG_NONE, NULL, 'b', "Print build options" },
1148 {"port", 'p', POPT_ARG_STRING, &ports, 0, "Listen on the specified ports"},
1149 {"profiling-level", 'P', POPT_ARG_STRING, &profile_level, 0, "Set profiling level","PROFILE_LEVEL"},
1150 POPT_COMMON_SAMBA
1151 POPT_COMMON_DYNCONFIG
1152 POPT_TABLEEND
1154 TALLOC_CTX *frame = talloc_stackframe(); /* Setup tos. */
1156 TimeInit();
1158 #ifdef HAVE_SET_AUTH_PARAMETERS
1159 set_auth_parameters(argc,argv);
1160 #endif
1162 pc = poptGetContext("smbd", argc, argv, long_options, 0);
1163 while((opt = poptGetNextOpt(pc)) != -1) {
1164 switch (opt) {
1165 case OPT_DAEMON:
1166 is_daemon = true;
1167 break;
1168 case OPT_INTERACTIVE:
1169 interactive = true;
1170 break;
1171 case OPT_FORK:
1172 Fork = false;
1173 break;
1174 case OPT_NO_PROCESS_GROUP:
1175 no_process_group = true;
1176 break;
1177 case OPT_LOG_STDOUT:
1178 log_stdout = true;
1179 break;
1180 case 'b':
1181 print_build_options = True;
1182 break;
1183 default:
1184 d_fprintf(stderr, "\nInvalid option %s: %s\n\n",
1185 poptBadOption(pc, 0), poptStrerror(opt));
1186 poptPrintUsage(pc, stderr, 0);
1187 exit(1);
1190 poptFreeContext(pc);
1192 if (interactive) {
1193 Fork = False;
1194 log_stdout = True;
1197 setup_logging(argv[0],log_stdout);
1199 if (print_build_options) {
1200 build_options(True); /* Display output to screen as well as debug */
1201 exit(0);
1204 load_case_tables();
1206 #ifdef HAVE_SETLUID
1207 /* needed for SecureWare on SCO */
1208 setluid(0);
1209 #endif
1211 sec_init();
1213 set_remote_machine_name("smbd", False);
1215 if (interactive && (DEBUGLEVEL >= 9)) {
1216 talloc_enable_leak_report();
1219 if (log_stdout && Fork) {
1220 DEBUG(0,("ERROR: Can't log to stdout (-S) unless daemon is in foreground (-F) or interactive (-i)\n"));
1221 exit(1);
1224 /* we want to re-seed early to prevent time delays causing
1225 client problems at a later date. (tridge) */
1226 generate_random_buffer(NULL, 0);
1228 /* make absolutely sure we run as root - to handle cases where people
1229 are crazy enough to have it setuid */
1231 gain_root_privilege();
1232 gain_root_group_privilege();
1234 fault_setup((void (*)(void *))exit_server_fault);
1235 dump_core_setup("smbd");
1237 CatchSignal(SIGTERM , SIGNAL_CAST sig_term);
1238 CatchSignal(SIGHUP,SIGNAL_CAST sig_hup);
1240 /* we are never interested in SIGPIPE */
1241 BlockSignals(True,SIGPIPE);
1243 #if defined(SIGFPE)
1244 /* we are never interested in SIGFPE */
1245 BlockSignals(True,SIGFPE);
1246 #endif
1248 #if defined(SIGUSR2)
1249 /* We are no longer interested in USR2 */
1250 BlockSignals(True,SIGUSR2);
1251 #endif
1253 /* POSIX demands that signals are inherited. If the invoking process has
1254 * these signals masked, we will have problems, as we won't recieve them. */
1255 BlockSignals(False, SIGHUP);
1256 BlockSignals(False, SIGUSR1);
1257 BlockSignals(False, SIGTERM);
1259 /* we want total control over the permissions on created files,
1260 so set our umask to 0 */
1261 umask(0);
1263 init_sec_ctx();
1265 reopen_logs();
1267 DEBUG(0,("smbd version %s started.\n", SAMBA_VERSION_STRING));
1268 DEBUGADD(0,("%s\n", COPYRIGHT_STARTUP_MESSAGE));
1270 DEBUG(2,("uid=%d gid=%d euid=%d egid=%d\n",
1271 (int)getuid(),(int)getgid(),(int)geteuid(),(int)getegid()));
1273 /* Output the build options to the debug log */
1274 build_options(False);
1276 if (sizeof(uint16) < 2 || sizeof(uint32) < 4) {
1277 DEBUG(0,("ERROR: Samba is not configured correctly for the word size on your machine\n"));
1278 exit(1);
1281 if (!lp_load_initial_only(get_dyn_CONFIGFILE())) {
1282 DEBUG(0, ("error opening config file\n"));
1283 exit(1);
1286 if (smbd_messaging_context() == NULL)
1287 exit(1);
1289 if (!reload_services(False))
1290 return(-1);
1292 init_structs();
1294 #ifdef WITH_PROFILE
1295 if (!profile_setup(smbd_messaging_context(), False)) {
1296 DEBUG(0,("ERROR: failed to setup profiling\n"));
1297 return -1;
1299 if (profile_level != NULL) {
1300 int pl = atoi(profile_level);
1301 struct server_id src;
1303 DEBUG(1, ("setting profiling level: %s\n",profile_level));
1304 src.pid = getpid();
1305 set_profile_level(pl, src);
1307 #endif
1309 DEBUG(3,( "loaded services\n"));
1311 if (!is_daemon && !is_a_socket(0)) {
1312 if (!interactive)
1313 DEBUG(0,("standard input is not a socket, assuming -D option\n"));
1316 * Setting is_daemon here prevents us from eventually calling
1317 * the open_sockets_inetd()
1320 is_daemon = True;
1323 if (is_daemon && !interactive) {
1324 DEBUG( 3, ( "Becoming a daemon.\n" ) );
1325 become_daemon(Fork, no_process_group);
1328 #if HAVE_SETPGID
1330 * If we're interactive we want to set our own process group for
1331 * signal management.
1333 if (interactive && !no_process_group)
1334 setpgid( (pid_t)0, (pid_t)0);
1335 #endif
1337 if (!directory_exist(lp_lockdir(), NULL))
1338 mkdir(lp_lockdir(), 0755);
1340 if (is_daemon)
1341 pidfile_create("smbd");
1343 if (!reinit_after_fork(smbd_messaging_context(),
1344 smbd_event_context(), false)) {
1345 DEBUG(0,("reinit_after_fork() failed\n"));
1346 exit(1);
1349 /* Setup all the TDB's - including CLEAR_IF_FIRST tdb's. */
1351 if (smbd_memcache() == NULL) {
1352 exit(1);
1355 memcache_set_global(smbd_memcache());
1357 /* Initialise the password backed before the global_sam_sid
1358 to ensure that we fetch from ldap before we make a domain sid up */
1360 if(!initialize_password_db(False, smbd_event_context()))
1361 exit(1);
1363 if (!secrets_init()) {
1364 DEBUG(0, ("ERROR: smbd can not open secrets.tdb\n"));
1365 exit(1);
1368 if(!get_global_sam_sid()) {
1369 DEBUG(0,("ERROR: Samba cannot create a SAM SID.\n"));
1370 exit(1);
1373 if (!session_init())
1374 exit(1);
1376 if (!connections_init(True))
1377 exit(1);
1379 if (!locking_init())
1380 exit(1);
1382 namecache_enable();
1384 if (!W_ERROR_IS_OK(registry_init_full()))
1385 exit(1);
1387 #if 0
1388 if (!init_svcctl_db())
1389 exit(1);
1390 #endif
1392 if (!print_backend_init(smbd_messaging_context()))
1393 exit(1);
1395 if (!init_guest_info()) {
1396 DEBUG(0,("ERROR: failed to setup guest info.\n"));
1397 return -1;
1400 /* only start the background queue daemon if we are
1401 running as a daemon -- bad things will happen if
1402 smbd is launched via inetd and we fork a copy of
1403 ourselves here */
1405 if (is_daemon && !interactive
1406 && lp_parm_bool(-1, "smbd", "backgroundqueue", true)) {
1407 start_background_queue();
1410 if (!open_sockets_smbd(is_daemon, interactive, ports))
1411 exit(1);
1414 * everything after this point is run after the fork()
1417 static_init_rpc;
1419 init_modules();
1421 /* Possibly reload the services file. Only worth doing in
1422 * daemon mode. In inetd mode, we know we only just loaded this.
1424 if (is_daemon) {
1425 reload_services(True);
1428 if (!init_account_policy()) {
1429 DEBUG(0,("Could not open account policy tdb.\n"));
1430 exit(1);
1433 if (*lp_rootdir()) {
1434 if (sys_chroot(lp_rootdir()) != 0) {
1435 DEBUG(0,("Failed to change root to %s\n", lp_rootdir()));
1436 exit(1);
1438 if (chdir("/") == -1) {
1439 DEBUG(0,("Failed to chdir to / on chroot to %s\n", lp_rootdir()));
1440 exit(1);
1442 DEBUG(0,("Changed root to %s\n", lp_rootdir()));
1445 /* Setup oplocks */
1446 if (!init_oplocks(smbd_messaging_context()))
1447 exit(1);
1449 /* Setup aio signal handler. */
1450 initialize_async_io_handler();
1452 /* register our message handlers */
1453 messaging_register(smbd_messaging_context(), NULL,
1454 MSG_SMB_FORCE_TDIS, msg_force_tdis);
1455 messaging_register(smbd_messaging_context(), NULL,
1456 MSG_SMB_RELEASE_IP, msg_release_ip);
1457 messaging_register(smbd_messaging_context(), NULL,
1458 MSG_SMB_CLOSE_FILE, msg_close_file);
1460 if ((lp_keepalive() != 0)
1461 && !(event_add_idle(smbd_event_context(), NULL,
1462 timeval_set(lp_keepalive(), 0),
1463 "keepalive", keepalive_fn,
1464 NULL))) {
1465 DEBUG(0, ("Could not add keepalive event\n"));
1466 exit(1);
1469 if (!(event_add_idle(smbd_event_context(), NULL,
1470 timeval_set(IDLE_CLOSED_TIMEOUT, 0),
1471 "deadtime", deadtime_fn, NULL))) {
1472 DEBUG(0, ("Could not add deadtime event\n"));
1473 exit(1);
1476 if (!(event_add_idle(smbd_event_context(), NULL,
1477 timeval_set(SMBD_SELECT_TIMEOUT, 0),
1478 "housekeeping", housekeeping_fn, NULL))) {
1479 DEBUG(0, ("Could not add housekeeping event\n"));
1480 exit(1);
1483 #ifdef CLUSTER_SUPPORT
1485 if (lp_clustering()) {
1487 * We need to tell ctdb about our client's TCP
1488 * connection, so that for failover ctdbd can send
1489 * tickle acks, triggering a reconnection by the
1490 * client.
1493 struct sockaddr_storage srv, clnt;
1495 if (client_get_tcp_info(&srv, &clnt) == 0) {
1497 NTSTATUS status;
1499 status = ctdbd_register_ips(
1500 messaging_ctdbd_connection(),
1501 &srv, &clnt, release_ip, NULL);
1503 if (!NT_STATUS_IS_OK(status)) {
1504 DEBUG(0, ("ctdbd_register_ips failed: %s\n",
1505 nt_errstr(status)));
1507 } else
1509 DEBUG(0,("Unable to get tcp info for "
1510 "CTDB_CONTROL_TCP_CLIENT: %s\n",
1511 strerror(errno)));
1515 #endif
1517 TALLOC_FREE(frame);
1519 smbd_process();
1521 namecache_shutdown();
1523 exit_server_cleanly(NULL);
1524 return(0);