client.c 16.3 KB
Newer Older
Ondřej Kuzník's avatar
Ondřej Kuzník committed
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
/* $OpenLDAP$ */
/* This work is part of OpenLDAP Software <http://www.openldap.org/>.
 *
 * Copyright 1998-2020 The OpenLDAP Foundation.
 * All rights reserved.
 *
 * Redistribution and use in source and binary forms, with or without
 * modification, are permitted only as authorized by the OpenLDAP
 * Public License.
 *
 * A copy of this license is available in the file LICENSE in the
 * top-level directory of the distribution or, alternatively, at
 * <http://www.OpenLDAP.org/license.html>.
 */

#include "portable.h"

#include <ac/socket.h>
#include <ac/errno.h>
#include <ac/string.h>
#include <ac/time.h>
#include <ac/unistd.h>

#include "lutil.h"
25
#include "lload.h"
Ondřej Kuzník's avatar
Ondřej Kuzník committed
26

27
28
long lload_client_max_pending = 0;

29
lload_c_head clients = LDAP_CIRCLEQ_HEAD_INITIALIZER( clients );
30
31
32

ldap_pvt_thread_mutex_t clients_mutex;

33
34
static void client_unlink( LloadConnection *upstream );

35
int
36
request_abandon( LloadConnection *c, LloadOperation *op )
37
{
38
    LloadOperation *request, needle = { .o_client_connid = c->c_connid };
39
40
    int rc = LDAP_SUCCESS;

41
42
    op->o_res = LLOAD_OP_COMPLETED;

43
44
45
46
47
    if ( ber_decode_int( &op->o_request, &needle.o_client_msgid ) ) {
        Debug( LDAP_DEBUG_STATS, "request_abandon: "
                "connid=%lu msgid=%d invalid integer sent in abandon request\n",
                c->c_connid, op->o_client_msgid );

48
49
        operation_unlink( op );
        CONNECTION_LOCK_DESTROY(c);
50
51
52
        return -1;
    }

53
    CONNECTION_LOCK(c);
54
55
56
57
58
59
    request = tavl_find( c->c_ops, &needle, operation_client_cmp );
    if ( !request ) {
        Debug( LDAP_DEBUG_STATS, "request_abandon: "
                "connid=%lu msgid=%d requests abandon of an operation "
                "msgid=%d not being processed anymore\n",
                c->c_connid, op->o_client_msgid, needle.o_client_msgid );
60
        CONNECTION_UNLOCK(c);
61
62
63
64
65
66
67
        goto done;
    } else if ( request->o_tag == LDAP_REQ_BIND ) {
        /* RFC 4511 states we must not allow Abandon on Binds */
        Debug( LDAP_DEBUG_STATS, "request_abandon: "
                "connid=%lu msgid=%d requests abandon of a bind operation "
                "msgid=%d\n",
                c->c_connid, op->o_client_msgid, needle.o_client_msgid );
68
        CONNECTION_UNLOCK(c);
69
70
71
72
        goto done;
    }
    Debug( LDAP_DEBUG_STATS, "request_abandon: "
            "connid=%lu msgid=%d abandoning %s msgid=%d\n",
73
74
            c->c_connid, op->o_client_msgid,
            lload_msgtype2str( request->o_tag ), needle.o_client_msgid );
75
76

    if ( c->c_state == LLOAD_C_BINDING ) {
77
        assert(0);
78
79
    }

80
    CONNECTION_UNLOCK(c);
81
82
83
    operation_abandon( request );

done:
84
    operation_unlink( op );
85
86
87
88
    return rc;
}

int
89
request_process( LloadConnection *client, LloadOperation *op )
90
91
{
    BerElement *output;
92
    LloadConnection *upstream;
93
    ber_int_t msgid;
94
    int res, rc = LDAP_SUCCESS;
95

96
    upstream = backend_select( op, &res );
97
98
99
100
101
    if ( !upstream ) {
        Debug( LDAP_DEBUG_STATS, "request_process: "
                "connid=%lu, msgid=%d no available connection found\n",
                op->o_client_connid, op->o_client_msgid );

102
        operation_send_reject( op, res, "no connections available", 1 );
103
104
105
106
        goto fail;
    }
    op->o_upstream = upstream;
    op->o_upstream_connid = upstream->c_connid;
107
    op->o_res = LLOAD_OP_FAILED;
108

109
110
111
112
113
114
    /* Was it unlinked in the meantime? No need to send a response since the
     * client is dead */
    if ( !IS_ALIVE( op, o_refcnt ) ) {
        LloadBackend *b = upstream->c_private;

        upstream->c_n_ops_executing--;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
115
        checked_unlock( &upstream->c_io_mutex );
116
117
        CONNECTION_UNLOCK(upstream);

Ondřej Kuzník's avatar
Ondřej Kuzník committed
118
        checked_lock( &b->b_mutex );
119
        b->b_n_ops_executing--;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
120
        checked_unlock( &b->b_mutex );
121
122

        assert( !IS_ALIVE( client, c_live ) );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
123
        checked_lock( &op->o_link_mutex );
124
125
126
        if ( op->o_upstream ) {
            op->o_upstream = NULL;
        }
Ondřej Kuzník's avatar
Ondřej Kuzník committed
127
        checked_unlock( &op->o_link_mutex );
128
129
130
        return -1;
    }

131
132
    output = upstream->c_pendingber;
    if ( output == NULL && (output = ber_alloc()) == NULL ) {
133
134
135
136
        LloadBackend *b = upstream->c_private;

        upstream->c_n_ops_executing--;
        CONNECTION_UNLOCK(upstream);
Ondřej Kuzník's avatar
Ondřej Kuzník committed
137
        checked_unlock( &upstream->c_io_mutex );
138

Ondřej Kuzník's avatar
Ondřej Kuzník committed
139
        checked_lock( &b->b_mutex );
140
141
        b->b_n_ops_executing--;
        operation_update_backend_counters( op, b );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
142
        checked_unlock( &b->b_mutex );
143
144
145
146

        Debug( LDAP_DEBUG_ANY, "request_process: "
                "ber_alloc failed\n" );

147
148
149
150
151
152
153
154
        rc = -1;
        goto fail;
    }
    upstream->c_pendingber = output;

    op->o_upstream_msgid = msgid = upstream->c_next_msgid++;
    rc = tavl_insert(
            &upstream->c_ops, op, operation_upstream_cmp, avl_dup_error );
155
    CONNECTION_UNLOCK(upstream);
156
157
158
159

    Debug( LDAP_DEBUG_TRACE, "request_process: "
            "client connid=%lu added %s msgid=%d to upstream connid=%lu as "
            "msgid=%d\n",
160
            op->o_client_connid, lload_msgtype2str( op->o_tag ),
161
162
163
            op->o_client_msgid, op->o_upstream_connid, op->o_upstream_msgid );
    assert( rc == LDAP_SUCCESS );

164
165
    lload_stats.counters[LLOAD_STATS_OPS_OTHER].lc_ops_forwarded++;

166
167
    if ( (lload_features & LLOAD_FEATURE_PROXYAUTHZ) &&
            client->c_type != LLOAD_C_PRIVILEGED ) {
168
        CONNECTION_LOCK(client);
169
170
171
172
173
174
175
176
        Debug( LDAP_DEBUG_TRACE, "request_process: "
                "proxying identity %s to upstream\n",
                client->c_auth.bv_val );
        ber_printf( output, "t{titOt{{sbO}" /* "}}" */, LDAP_TAG_MESSAGE,
                LDAP_TAG_MSGID, msgid,
                op->o_tag, &op->o_request,
                LDAP_TAG_CONTROLS,
                LDAP_CONTROL_PROXY_AUTHZ, 1, &client->c_auth );
177
        CONNECTION_UNLOCK(client);
178
179
180
181
182
183
184
185
186
187
188
189

        if ( !BER_BVISNULL( &op->o_ctrls ) ) {
            ber_write( output, op->o_ctrls.bv_val, op->o_ctrls.bv_len, 0 );
        }

        ber_printf( output, /* "{{" */ "}}" );
    } else {
        ber_printf( output, "t{titOtO}", LDAP_TAG_MESSAGE,
                LDAP_TAG_MSGID, msgid,
                op->o_tag, &op->o_request,
                LDAP_TAG_CONTROLS, BER_BV_OPTIONAL( &op->o_ctrls ) );
    }
Ondřej Kuzník's avatar
Ondřej Kuzník committed
190
    checked_unlock( &upstream->c_io_mutex );
191
192
193
194
195
196

    connection_write_cb( -1, 0, upstream );
    return rc;

fail:
    if ( upstream ) {
197
        CONNECTION_LOCK_DESTROY(upstream);
198
199
200

        operation_send_reject( op, LDAP_OTHER, "internal error", 0 );
    }
201
202

    operation_unlink( op );
203
    if ( rc ) {
204
        CONNECTION_LOCK_DESTROY(client);
205
206
207
208
    }
    return rc;
}

209
int
210
handle_one_request( LloadConnection *c )
211
212
{
    BerElement *ber;
213
    LloadOperation *op = NULL;
214
    RequestHandler handler = NULL;
215
    int over_limit = 0;
216
217

    ber = c->c_currentber;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
218
219
    c->c_currentber = NULL;

220
    CONNECTION_LOCK(c);
Ondřej Kuzník's avatar
Ondřej Kuzník committed
221
222
    op = operation_init( c, ber );
    if ( !op ) {
223
        Debug( LDAP_DEBUG_ANY, "handle_one_request: "
Ondřej Kuzník's avatar
Ondřej Kuzník committed
224
225
                "connid=%lu, operation_init failed\n",
                c->c_connid );
226
        CONNECTION_DESTROY(c);
227
228
        ber_free( ber, 1 );
        return -1;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
229
    }
230
231
232
233
    if ( lload_client_max_pending &&
            c->c_n_ops_executing >= lload_client_max_pending ) {
        over_limit = 1;
    }
234
    CONNECTION_UNLOCK(c);
Ondřej Kuzník's avatar
Ondřej Kuzník committed
235

Ondřej Kuzník's avatar
Ondřej Kuzník committed
236
237
    switch ( op->o_tag ) {
        case LDAP_REQ_UNBIND:
238
            /* There is never a response for this operation */
239
            op->o_res = LLOAD_OP_COMPLETED;
240
241
            operation_unlink( op );

Ondřej Kuzník's avatar
Ondřej Kuzník committed
242
243
244
            Debug( LDAP_DEBUG_STATS, "handle_one_request: "
                    "received unbind, closing client connid=%lu\n",
                    c->c_connid );
245
            CONNECTION_LOCK_DESTROY(c);
246
            return -1;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
247
        case LDAP_REQ_BIND:
Ondřej Kuzník's avatar
Ondřej Kuzník committed
248
            handler = request_bind;
249
250
            break;
        case LDAP_REQ_ABANDON:
251
252
            /* We can't send a response to abandon requests even if a bind is
             * currently in progress */
253
            return request_abandon( c, op );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
254
        case LDAP_REQ_EXTENDED:
Ondřej Kuzník's avatar
Ondřej Kuzník committed
255
        default:
256
            if ( c->c_state == LLOAD_C_BINDING ) {
257
                operation_send_reject(
258
                        op, LDAP_PROTOCOL_ERROR, "bind in progress", 0 );
259
                return LDAP_SUCCESS;
260
            }
261
262
263
264
265
266
267
268
269
270
271
            if ( over_limit ) {
                operation_send_reject( op, LDAP_BUSY,
                        "pending operation limit reached on this connection",
                        0 );
                return LDAP_SUCCESS;
            }
            if ( op->o_tag == LDAP_REQ_EXTENDED ) {
                handler = request_extended;
            } else {
                handler = request_process;
            }
Ondřej Kuzník's avatar
Ondřej Kuzník committed
272
273
274
            break;
    }

275
    if ( c->c_state == LLOAD_C_CLOSING ) {
276
        operation_send_reject(
277
                op, LDAP_UNAVAILABLE, "connection is shutting down", 0 );
278
        return LDAP_SUCCESS;
279
280
    }

281
    return handler( c, op );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
282
283
}

Ondřej Kuzník's avatar
Ondřej Kuzník committed
284
285
286
287
288
289
/*
 * The connection has a token assigned to it when the callback is set up.
 */
void
client_tls_handshake_cb( evutil_socket_t s, short what, void *arg )
{
290
    LloadConnection *c = arg;
291
    epoch_t epoch;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
292
293
294
295
296
297
298
299
300
301
302
303
304
305
    int rc = 0;

    if ( what & EV_TIMEOUT ) {
        Debug( LDAP_DEBUG_CONNS, "client_tls_handshake_cb: "
                "connid=%lu, timeout reached, destroying\n",
                c->c_connid );
        goto fail;
    }

    /*
     * In case of StartTLS, make sure we flush the response first.
     * Also before we try to read anything from the connection, it isn't
     * permitted to Abandon a StartTLS exop per RFC4511 anyway.
     */
Ondřej Kuzník's avatar
Ondřej Kuzník committed
306
    checked_lock( &c->c_io_mutex );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
307
    if ( c->c_pendingber ) {
Ondřej Kuzník's avatar
Ondřej Kuzník committed
308
        checked_unlock( &c->c_io_mutex );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
309
310
        connection_write_cb( s, what, arg );

311
        if ( !IS_ALIVE( c, c_live ) ) {
Ondřej Kuzník's avatar
Ondřej Kuzník committed
312
313
314
315
316
            goto fail;
        }

        /* Do we still have data pending? If so, connection_write_cb would
         * already have arranged the write callback to trigger again */
Ondřej Kuzník's avatar
Ondřej Kuzník committed
317
        checked_lock( &c->c_io_mutex );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
318
        if ( c->c_pendingber ) {
Ondřej Kuzník's avatar
Ondřej Kuzník committed
319
            checked_unlock( &c->c_io_mutex );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
320
321
322
323
            return;
        }
    }

324
    rc = ldap_pvt_tls_accept( c->c_sb, LLOAD_TLS_CTX );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
325
    checked_unlock( &c->c_io_mutex );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
326
327
328
329
330
331
332
333
334
335
336
337
338
    if ( rc < 0 ) {
        goto fail;
    }

    if ( rc == 0 ) {
        struct event_base *base = event_get_base( c->c_read_event );

        /*
         * We're finished, replace the callbacks
         *
         * This is deadlock-safe, since both share the same base - the one
         * that's just running us.
         */
339
        CONNECTION_LOCK(c);
Ondřej Kuzník's avatar
Ondřej Kuzník committed
340
341
342
        event_del( c->c_read_event );
        event_del( c->c_write_event );

343
        c->c_read_timeout = NULL;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
344
345
        event_assign( c->c_read_event, base, c->c_fd, EV_READ|EV_PERSIST,
                connection_read_cb, c );
346
        if ( IS_ALIVE( c, c_live ) ) {
347
348
            event_add( c->c_read_event, c->c_read_timeout );
        }
Ondřej Kuzník's avatar
Ondřej Kuzník committed
349
350
351
352
353
354
355
356

        event_assign( c->c_write_event, base, c->c_fd, EV_WRITE,
                connection_write_cb, c );
        Debug( LDAP_DEBUG_CONNS, "client_tls_handshake_cb: "
                "connid=%lu finished\n",
                c->c_connid );

        c->c_is_tls = LLOAD_TLS_ESTABLISHED;
357
        CONNECTION_UNLOCK(c);
Ondřej Kuzník's avatar
Ondřej Kuzník committed
358
359
        return;
    } else if ( ber_sockbuf_ctrl( c->c_sb, LBER_SB_OPT_NEEDS_WRITE, NULL ) ) {
360
361
        if ( IS_ALIVE( c, c_live ) ) {
            CONNECTION_LOCK(c);
362
            event_add( c->c_write_event, lload_write_timeout );
363
            CONNECTION_UNLOCK(c);
364
        }
Ondřej Kuzník's avatar
Ondřej Kuzník committed
365
366
367
368
369
370
371
372
373
374
        Debug( LDAP_DEBUG_CONNS, "client_tls_handshake_cb: "
                "connid=%lu need write rc=%d\n",
                c->c_connid, rc );
    }
    return;

fail:
    Debug( LDAP_DEBUG_CONNS, "client_tls_handshake_cb: "
            "connid=%lu failed rc=%d\n",
            c->c_connid, rc );
375
376
377
378
379

    assert( c->c_ops == NULL );
    epoch = epoch_join();
    CONNECTION_LOCK_DESTROY(c);
    epoch_leave( epoch );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
380
381
}

382
LloadConnection *
Ondřej Kuzník's avatar
Ondřej Kuzník committed
383
384
client_init(
        ber_socket_t s,
385
        LloadListener *listener,
Ondřej Kuzník's avatar
Ondřej Kuzník committed
386
387
388
389
        const char *peername,
        struct event_base *base,
        int flags )
{
390
    LloadConnection *c;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
391
    struct event *event;
392
393
    event_callback_fn read_cb = connection_read_cb,
                      write_cb = connection_write_cb;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
394
395
396

    assert( listener != NULL );

397
    if ( (c = lload_connection_init( s, peername, flags) ) == NULL ) {
398
399
        return NULL;
    }
Ondřej Kuzník's avatar
Ondřej Kuzník committed
400

401
402
403
404
405
    {
        ber_len_t max = sockbuf_max_incoming_client;
        ber_sockbuf_ctrl( c->c_sb, LBER_SB_OPT_SET_MAX_INCOMING, &max );
    }

406
    c->c_state = LLOAD_C_READY;
407

Ondřej Kuzník's avatar
Ondřej Kuzník committed
408
409
410
411
412
    if ( flags & CONN_IS_TLS ) {
        int rc;

        c->c_is_tls = LLOAD_LDAPS;

413
        rc = ldap_pvt_tls_accept( c->c_sb, LLOAD_TLS_CTX );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
414
415
416
417
        if ( rc < 0 ) {
            Debug( LDAP_DEBUG_CONNS, "client_init: "
                    "connid=%lu failed initial TLS accept rc=%d\n",
                    c->c_connid, rc );
418
            CONNECTION_LOCK(c);
Ondřej Kuzník's avatar
Ondřej Kuzník committed
419
420
421
422
            goto fail;
        }

        if ( rc ) {
423
            c->c_read_timeout = lload_timeout_net;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
424
425
426
427
            read_cb = write_cb = client_tls_handshake_cb;
        }
    }

428
    event = event_new( base, s, EV_READ|EV_PERSIST, read_cb, c );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
429
    if ( !event ) {
Ondřej Kuzník's avatar
Ondřej Kuzník committed
430
431
        Debug( LDAP_DEBUG_ANY, "client_init: "
                "Read event could not be allocated\n" );
432
        CONNECTION_LOCK(c);
Ondřej Kuzník's avatar
Ondřej Kuzník committed
433
434
435
436
        goto fail;
    }
    c->c_read_event = event;

437
    event = event_new( base, s, EV_WRITE, write_cb, c );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
438
    if ( !event ) {
Ondřej Kuzník's avatar
Ondřej Kuzník committed
439
440
        Debug( LDAP_DEBUG_ANY, "client_init: "
                "Write event could not be allocated\n" );
441
        CONNECTION_LOCK(c);
Ondřej Kuzník's avatar
Ondřej Kuzník committed
442
443
444
445
446
        goto fail;
    }
    c->c_write_event = event;

    c->c_private = listener;
447
    c->c_destroy = client_destroy;
448
    c->c_unlink = client_unlink;
449
    c->c_pdu_cb = handle_one_request;
450

451
452
453
454
    CONNECTION_LOCK(c);
    /* We only register the write event when we have data pending */
    event_add( c->c_read_event, c->c_read_timeout );

Ondřej Kuzník's avatar
Ondřej Kuzník committed
455
    checked_lock( &clients_mutex );
456
    LDAP_CIRCLEQ_INSERT_TAIL( &clients, c, c_next );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
457
    checked_unlock( &clients_mutex );
458
    CONNECTION_UNLOCK(c);
Ondřej Kuzník's avatar
Ondřej Kuzník committed
459
460
461
462
463

    return c;
fail:
    if ( c->c_write_event ) {
        event_free( c->c_write_event );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
464
        c->c_write_event = NULL;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
465
466
467
    }
    if ( c->c_read_event ) {
        event_free( c->c_read_event );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
468
        c->c_read_event = NULL;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
469
    }
470

471
    c->c_state = LLOAD_C_INVALID;
472
473
474
    c->c_live--;
    c->c_refcnt--;
    connection_destroy( c );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
475
476
477
    return NULL;
}

478
void
479
client_reset( LloadConnection *c )
480
481
{
    TAvlnode *root;
482
    long freed = 0, executing;
483
484
485

    root = c->c_ops;
    c->c_ops = NULL;
486
487
    executing = c->c_n_ops_executing;
    c->c_n_ops_executing = 0;
488
489
490
491
492
493
494
495
496

    if ( !BER_BVISNULL( &c->c_auth ) ) {
        ch_free( c->c_auth.bv_val );
        BER_BVZERO( &c->c_auth );
    }
    if ( !BER_BVISNULL( &c->c_sasl_bind_mech ) ) {
        ch_free( c->c_sasl_bind_mech.bv_val );
        BER_BVZERO( &c->c_sasl_bind_mech );
    }
497
    CONNECTION_UNLOCK(c);
498
499
500
501

    if ( root ) {
        freed = tavl_free( root, (AVL_FREE)operation_abandon );
        Debug( LDAP_DEBUG_TRACE, "client_reset: "
502
                "dropped %ld operations\n",
503
504
                freed );
    }
505
    assert( freed == executing );
506

507
    CONNECTION_LOCK(c);
508
509
}

Ondřej Kuzník's avatar
Ondřej Kuzník committed
510
void
511
client_unlink( LloadConnection *c )
Ondřej Kuzník's avatar
Ondřej Kuzník committed
512
{
513
    enum sc_state state;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
514
    struct event *read_event, *write_event;
515

516
517
    Debug( LDAP_DEBUG_CONNS, "client_unlink: "
            "removing client connid=%lu\n",
518
519
            c->c_connid );

520
    assert( c->c_state != LLOAD_C_INVALID );
521
522
    assert( c->c_state != LLOAD_C_DYING );

523
    state = c->c_state;
524
    c->c_state = LLOAD_C_DYING;
525

Ondřej Kuzník's avatar
Ondřej Kuzník committed
526
527
    read_event = c->c_read_event;
    write_event = c->c_write_event;
528
    CONNECTION_UNLOCK(c);
Ondřej Kuzník's avatar
Ondřej Kuzník committed
529
530
531

    if ( read_event ) {
        event_del( read_event );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
532
    }
533

Ondřej Kuzník's avatar
Ondřej Kuzník committed
534
535
    if ( write_event ) {
        event_del( write_event );
536
537
    }

538
    if ( state != LLOAD_C_DYING ) {
Ondřej Kuzník's avatar
Ondřej Kuzník committed
539
        checked_lock( &clients_mutex );
540
        LDAP_CIRCLEQ_REMOVE( &clients, c, c_next );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
541
        checked_unlock( &clients_mutex );
542
543
    }

544
545
546
547
548
549
550
551
552
553
554
555
556
557
    CONNECTION_LOCK(c);
    client_reset( c );
}

void
client_destroy( LloadConnection *c )
{
    Debug( LDAP_DEBUG_CONNS, "client_destroy: "
            "destroying client connid=%lu\n",
            c->c_connid );

    CONNECTION_LOCK(c);
    assert( c->c_state == LLOAD_C_DYING );
    c->c_state = LLOAD_C_INVALID;
Ondřej Kuzník's avatar
Ondřej Kuzník committed
558

559
560
    assert( c->c_ops == NULL );

Ondřej Kuzník's avatar
Ondřej Kuzník committed
561
562
563
564
565
566
567
568
569
570
    if ( c->c_read_event ) {
        event_free( c->c_read_event );
        c->c_read_event = NULL;
    }

    if ( c->c_write_event ) {
        event_free( c->c_write_event );
        c->c_write_event = NULL;
    }

571
    assert( c->c_refcnt == 0 );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
572
573
    connection_destroy( c );
}
574
575

void
576
clients_destroy( int gentle )
577
{
Ondřej Kuzník's avatar
Ondřej Kuzník committed
578
    checked_lock( &clients_mutex );
579
580
    connections_walk(
            &clients_mutex, &clients, lload_connection_close, &gentle );
Ondřej Kuzník's avatar
Ondřej Kuzník committed
581
    checked_unlock( &clients_mutex );
582
}