uhttpd: block SIGCHLD until it is expected (#6957)
[oweals/openwrt.git] / package / uhttpd / src / uhttpd.c
1 /*
2  * uhttpd - Tiny single-threaded httpd - Main component
3  *
4  *   Copyright (C) 2010 Jo-Philipp Wich <xm@subsignal.org>
5  *
6  *  Licensed under the Apache License, Version 2.0 (the "License");
7  *  you may not use this file except in compliance with the License.
8  *  You may obtain a copy of the License at
9  *
10  *      http://www.apache.org/licenses/LICENSE-2.0
11  *
12  *  Unless required by applicable law or agreed to in writing, software
13  *  distributed under the License is distributed on an "AS IS" BASIS,
14  *  WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15  *  See the License for the specific language governing permissions and
16  *  limitations under the License.
17  */
18
19 #define _XOPEN_SOURCE 500       /* crypt() */
20
21 #include "uhttpd.h"
22 #include "uhttpd-utils.h"
23 #include "uhttpd-file.h"
24
25 #ifdef HAVE_CGI
26 #include "uhttpd-cgi.h"
27 #endif
28
29 #ifdef HAVE_LUA
30 #include "uhttpd-lua.h"
31 #endif
32
33 #ifdef HAVE_TLS
34 #include "uhttpd-tls.h"
35 #endif
36
37
38 static int run = 1;
39
40 static void uh_sigterm(int sig)
41 {
42         run = 0;
43 }
44
45 static void uh_sigchld(int sig)
46 {
47         while( waitpid(-1, NULL, WNOHANG) > 0 ) { }
48 }
49
50 static void uh_config_parse(const char *path)
51 {
52         FILE *c;
53         char line[512];
54         char *user = NULL;
55         char *pass = NULL;
56         char *eol  = NULL;
57
58         if( (c = fopen(path ? path : "/etc/httpd.conf", "r")) != NULL )
59         {
60                 memset(line, 0, sizeof(line));
61
62                 while( fgets(line, sizeof(line) - 1, c) )
63                 {
64                         if( (line[0] == '/') && (strchr(line, ':') != NULL) )
65                         {
66                                 if( !(user = strchr(line, ':')) || (*user++ = 0) ||
67                                     !(pass = strchr(user, ':')) || (*pass++ = 0) ||
68                                         !(eol = strchr(pass, '\n')) || (*eol++  = 0) )
69                                                 continue;
70
71                                 if( !uh_auth_add(line, user, pass) )
72                                 {
73                                         fprintf(stderr,
74                                                 "Can not manage more than %i basic auth realms, "
75                                                 "will skip the rest\n", UH_LIMIT_AUTHREALMS
76                                         );
77
78                                         break;
79                                 } 
80                         }
81                 }
82
83                 fclose(c);
84         }
85 }
86
87 static int uh_socket_bind(
88         fd_set *serv_fds, int *max_fd, const char *host, const char *port,
89         struct addrinfo *hints, int do_tls, struct config *conf
90 ) {
91         int sock = -1;
92         int yes = 1;
93         int status;
94         int bound = 0;
95
96         struct listener *l = NULL;
97         struct addrinfo *addrs = NULL, *p = NULL;
98
99         if( (status = getaddrinfo(host, port, hints, &addrs)) != 0 )
100         {
101                 fprintf(stderr, "getaddrinfo(): %s\n", gai_strerror(status));
102         }
103
104         /* try to bind a new socket to each found address */
105         for( p = addrs; p; p = p->ai_next )
106         {
107                 /* get the socket */
108                 if( (sock = socket(p->ai_family, p->ai_socktype, p->ai_protocol)) == -1 )
109                 {
110                         perror("socket()");
111                         goto error;
112                 }
113
114                 /* "address already in use" */
115                 if( setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, &yes, sizeof(yes)) == -1 )
116                 {
117                         perror("setsockopt()");
118                         goto error;
119                 }
120
121                 /* required to get parallel v4 + v6 working */
122                 if( p->ai_family == AF_INET6 )
123                 {
124                         if( setsockopt(sock, IPPROTO_IPV6, IPV6_V6ONLY, &yes, sizeof(yes)) == -1 )
125                         {
126                                 perror("setsockopt()");
127                                 goto error;
128                         }
129                 }
130
131                 /* bind */
132                 if( bind(sock, p->ai_addr, p->ai_addrlen) == -1 )
133                 {
134                         perror("bind()");
135                         goto error;
136                 }
137
138                 /* listen */
139                 if( listen(sock, UH_LIMIT_CLIENTS) == -1 )
140                 {
141                         perror("listen()");
142                         goto error;
143                 }
144
145                 /* add listener to global list */
146                 if( ! (l = uh_listener_add(sock, conf)) )
147                 {
148                         fprintf(stderr,
149                                 "uh_listener_add(): Can not create more than "
150                                 "%i listen sockets\n", UH_LIMIT_LISTENERS
151                         );
152
153                         goto error;
154                 }
155
156 #ifdef HAVE_TLS
157                 /* init TLS */
158                 l->tls = do_tls ? conf->tls : NULL;
159 #endif
160
161                 /* add socket to server fd set */
162                 FD_SET(sock, serv_fds);
163                 fd_cloexec(sock);
164                 *max_fd = max(*max_fd, sock);
165
166                 bound++;
167                 continue;
168
169                 error:
170                 if( sock > 0 )
171                         close(sock);
172         }
173
174         freeaddrinfo(addrs);
175
176         return bound;
177 }
178
179 static struct http_request * uh_http_header_parse(struct client *cl, char *buffer, int buflen)
180 {
181         char *method  = &buffer[0];
182         char *path    = NULL;
183         char *version = NULL;
184
185         char *headers = NULL;
186         char *hdrname = NULL;
187         char *hdrdata = NULL;
188
189         int i;
190         int hdrcount = 0;
191
192         static struct http_request req;
193
194         memset(&req, 0, sizeof(req));
195
196
197         /* terminate initial header line */
198         if( (headers = strfind(buffer, buflen, "\r\n", 2)) != NULL )
199         {
200                 buffer[buflen-1] = 0;
201
202                 *headers++ = 0;
203                 *headers++ = 0;
204
205                 /* find request path */
206                 if( (path = strchr(buffer, ' ')) != NULL )
207                         *path++ = 0;
208
209                 /* find http version */
210                 if( (path != NULL) && ((version = strchr(path, ' ')) != NULL) )
211                         *version++ = 0;
212
213
214                 /* check method */
215                 if( strcmp(method, "GET") && strcmp(method, "HEAD") && strcmp(method, "POST") )
216                 {
217                         /* invalid method */
218                         uh_http_response(cl, 405, "Method Not Allowed");
219                         return NULL;
220                 }
221                 else
222                 {
223                         switch(method[0])
224                         {
225                                 case 'G':
226                                         req.method = UH_HTTP_MSG_GET;
227                                         break;
228
229                                 case 'H':
230                                         req.method = UH_HTTP_MSG_HEAD;
231                                         break;
232
233                                 case 'P':
234                                         req.method = UH_HTTP_MSG_POST;
235                                         break;
236                         }
237                 }
238
239                 /* check path */
240                 if( !path || !strlen(path) )
241                 {
242                         /* malformed request */
243                         uh_http_response(cl, 400, "Bad Request");
244                         return NULL;
245                 }
246                 else
247                 {
248                         req.url = path;
249                 }
250
251                 /* check version */
252                 if( strcmp(version, "HTTP/0.9") && strcmp(version, "HTTP/1.0") && strcmp(version, "HTTP/1.1") )
253                 {
254                         /* unsupported version */
255                         uh_http_response(cl, 400, "Bad Request");
256                         return NULL;
257                 }
258                 else
259                 {
260                         req.version = strtof(&version[5], NULL);
261                 }
262
263
264                 /* process header fields */
265                 for( i = (int)(headers - buffer); i < buflen; i++ )
266                 {
267                         /* found eol and have name + value, push out header tuple */
268                         if( hdrname && hdrdata && (buffer[i] == '\r' || buffer[i] == '\n') )
269                         {
270                                 buffer[i] = 0;
271
272                                 /* store */
273                                 if( (hdrcount + 1) < array_size(req.headers) )
274                                 {
275                                         req.headers[hdrcount++] = hdrname;
276                                         req.headers[hdrcount++] = hdrdata;
277
278                                         hdrname = hdrdata = NULL;
279                                 }
280
281                                 /* too large */
282                                 else
283                                 {
284                                         uh_http_response(cl, 413, "Request Entity Too Large");
285                                         return NULL;
286                                 }
287                         }
288
289                         /* have name but no value and found a colon, start of value */
290                         else if( hdrname && !hdrdata && ((i+2) < buflen) &&
291                                 (buffer[i] == ':') && (buffer[i+1] == ' ')
292                         ) {
293                                 buffer[i] = 0;
294                                 hdrdata = &buffer[i+2];
295                         }
296
297                         /* have no name and found [A-Z], start of name */
298                         else if( !hdrname && isalpha(buffer[i]) && isupper(buffer[i]) )
299                         {
300                                 hdrname = &buffer[i];
301                         }
302                 }
303
304                 /* valid enough */
305                 return &req;
306         }
307
308         /* Malformed request */
309         uh_http_response(cl, 400, "Bad Request");
310         return NULL;
311 }
312
313
314 static struct http_request * uh_http_header_recv(struct client *cl)
315 {
316         static char buffer[UH_LIMIT_MSGHEAD];
317         char *bufptr = &buffer[0];
318         char *idxptr = NULL;
319
320         struct timeval timeout;
321
322         fd_set reader;
323
324         ssize_t blen = sizeof(buffer)-1;
325         ssize_t rlen = 0;
326
327
328         memset(buffer, 0, sizeof(buffer));
329
330         while( blen > 0 )
331         {
332                 FD_ZERO(&reader);
333                 FD_SET(cl->socket, &reader);
334
335                 /* fail after 0.1s */
336                 timeout.tv_sec  = 0;
337                 timeout.tv_usec = 100000;
338
339                 /* check whether fd is readable */
340                 if( select(cl->socket + 1, &reader, NULL, NULL, &timeout) > 0 )
341                 {
342                         /* receive data */
343                         rlen = uh_tcp_peek(cl, bufptr, blen);
344
345                         if( rlen > 0 )
346                         {
347                                 if( (idxptr = strfind(buffer, sizeof(buffer), "\r\n\r\n", 4)) )
348                                 {
349                                         blen -= uh_tcp_recv(cl, bufptr, (int)(idxptr - bufptr) + 4);
350
351                                         /* header read complete ... */
352                                         return uh_http_header_parse(cl, buffer, sizeof(buffer) - blen - 1);
353                                 }
354                                 else
355                                 {
356                                         rlen = uh_tcp_recv(cl, bufptr, rlen);
357                                         blen -= rlen;
358                                         bufptr += rlen;
359                                 }
360                         }
361                         else
362                         {
363                                 /* invalid request (unexpected eof/timeout) */
364                                 uh_http_response(cl, 408, "Request Timeout");
365                                 return NULL;
366                         }
367                 }
368                 else
369                 {
370                         /* invalid request (unexpected eof/timeout) */
371                         uh_http_response(cl, 408, "Request Timeout");
372                         return NULL;
373                 }
374         }
375
376         /* request entity too large */
377         uh_http_response(cl, 413, "Request Entity Too Large");
378         return NULL;
379 }
380
381 static int uh_path_match(const char *prefix, const char *url)
382 {
383         if( (strstr(url, prefix) == url) &&
384             ((prefix[strlen(prefix)-1] == '/') ||
385                  (strlen(url) == strlen(prefix))   ||
386                  (url[strlen(prefix)] == '/'))
387         ) {
388                 return 1;
389         }
390
391         return 0;
392 }
393
394
395 int main (int argc, char **argv)
396 {
397 #ifdef HAVE_LUA
398         /* Lua runtime */
399         lua_State *L = NULL;
400 #endif
401
402         /* master file descriptor list */
403         fd_set used_fds, serv_fds, read_fds;
404
405         /* working structs */
406         struct addrinfo hints;
407         struct http_request *req;
408         struct path_info *pin;
409         struct client *cl;
410         struct sigaction sa;
411         struct config conf;
412
413         /* signal mask */
414         sigset_t ss;
415
416         /* maximum file descriptor number */
417         int new_fd, cur_fd, max_fd = 0;
418
419         int tls = 0;
420         int keys = 0;
421         int bound = 0;
422         int nofork = 0;
423
424         /* args */
425         char opt;
426         char bind[128];
427         char *port = NULL;
428
429         /* library handles */
430         void *tls_lib;
431         void *lua_lib;
432
433         /* clear the master and temp sets */
434         FD_ZERO(&used_fds);
435         FD_ZERO(&serv_fds);
436         FD_ZERO(&read_fds);
437
438         /* handle SIGPIPE, SIGINT, SIGTERM, SIGCHLD */
439         sa.sa_flags = 0;
440         sigemptyset(&sa.sa_mask);
441
442         sa.sa_handler = SIG_IGN;
443         sigaction(SIGPIPE, &sa, NULL);
444
445         sa.sa_handler = uh_sigchld;
446         sigaction(SIGCHLD, &sa, NULL);
447
448         sa.sa_handler = uh_sigterm;
449         sigaction(SIGINT,  &sa, NULL);
450         sigaction(SIGTERM, &sa, NULL);
451
452         /* defer SIGCHLD */
453         sigemptyset(&ss);
454         sigaddset(&ss, SIGCHLD);
455         sigprocmask(SIG_BLOCK, &ss, NULL);
456
457         /* prepare addrinfo hints */
458         memset(&hints, 0, sizeof(hints));
459         hints.ai_family   = AF_UNSPEC;
460         hints.ai_socktype = SOCK_STREAM;
461         hints.ai_flags    = AI_PASSIVE;
462
463         /* parse args */
464         memset(&conf, 0, sizeof(conf));
465         memset(bind, 0, sizeof(bind));
466
467 #ifdef HAVE_TLS
468         /* load TLS plugin */
469         if( ! (tls_lib = dlopen("uhttpd_tls.so", RTLD_LAZY | RTLD_GLOBAL)) )
470         {
471                 fprintf(stderr,
472                         "Notice: Unable to load TLS plugin - disabling SSL support! "
473                         "(Reason: %s)\n", dlerror()
474                 );
475         }
476         else
477         {
478                 /* resolve functions */
479                 if( !(conf.tls_init   = dlsym(tls_lib, "uh_tls_ctx_init"))      ||
480                     !(conf.tls_cert   = dlsym(tls_lib, "uh_tls_ctx_cert"))      ||
481                     !(conf.tls_key    = dlsym(tls_lib, "uh_tls_ctx_key"))       ||
482                     !(conf.tls_free   = dlsym(tls_lib, "uh_tls_ctx_free"))      ||
483                         !(conf.tls_accept = dlsym(tls_lib, "uh_tls_client_accept")) ||
484                         !(conf.tls_close  = dlsym(tls_lib, "uh_tls_client_close"))  ||
485                         !(conf.tls_recv   = dlsym(tls_lib, "uh_tls_client_recv"))   ||
486                         !(conf.tls_send   = dlsym(tls_lib, "uh_tls_client_send"))
487                 ) {
488                         fprintf(stderr,
489                                 "Error: Failed to lookup required symbols "
490                                 "in TLS plugin: %s\n", dlerror()
491                         );
492                         exit(1);
493                 }
494
495                 /* init SSL context */
496                 if( ! (conf.tls = conf.tls_init()) )
497                 {
498                         fprintf(stderr, "Error: Failed to initalize SSL context\n");
499                         exit(1);
500                 }
501         }
502 #endif
503
504         while( (opt = getopt(argc, argv, "fC:K:p:s:h:c:l:L:d:r:m:x:t:")) > 0 )
505         {
506                 switch(opt)
507                 {
508                         /* [addr:]port */
509                         case 'p':
510                         case 's':
511                                 if( (port = strrchr(optarg, ':')) != NULL )
512                                 {
513                                         if( (optarg[0] == '[') && (port > optarg) && (port[-1] == ']') )
514                                                 memcpy(bind, optarg + 1,
515                                                         min(sizeof(bind), (int)(port - optarg) - 2));
516                                         else
517                                                 memcpy(bind, optarg,
518                                                         min(sizeof(bind), (int)(port - optarg)));
519
520                                         port++;
521                                 }
522                                 else
523                                 {
524                                         port = optarg;
525                                 }
526
527                                 if( opt == 's' )
528                                 {
529                                         if( !conf.tls )
530                                         {
531                                                 fprintf(stderr,
532                                                         "Notice: TLS support is disabled, "
533                                                         "ignoring '-s %s'\n", optarg
534                                                 );
535                                                 continue;
536                                         }
537
538                                         tls = 1;
539                                 }
540
541                                 /* bind sockets */
542                                 bound += uh_socket_bind(
543                                         &serv_fds, &max_fd, bind[0] ? bind : NULL, port,
544                                         &hints, (opt == 's'), &conf
545                                 );
546
547                                 break;
548
549 #ifdef HAVE_TLS
550                         /* certificate */
551                         case 'C':
552                                 if( conf.tls )
553                                 {
554                                         if( conf.tls_cert(conf.tls, optarg) < 1 )
555                                         {
556                                                 fprintf(stderr,
557                                                         "Error: Invalid certificate file given\n");
558                                                 exit(1);
559                                         }
560
561                                         keys++;
562                                 }
563
564                                 break;
565
566                         /* key */
567                         case 'K':
568                                 if( conf.tls )
569                                 {
570                                         if( conf.tls_key(conf.tls, optarg) < 1 )
571                                         {
572                                                 fprintf(stderr,
573                                                         "Error: Invalid private key file given\n");
574                                                 exit(1);
575                                         }
576
577                                         keys++;
578                                 }
579
580                                 break;
581 #endif
582
583                         /* docroot */
584                         case 'h':
585                                 if( ! realpath(optarg, conf.docroot) )
586                                 {
587                                         fprintf(stderr, "Error: Invalid directory %s: %s\n",
588                                                 optarg, strerror(errno));
589                                         exit(1);
590                                 }
591                                 break;
592
593 #ifdef HAVE_CGI
594                         /* cgi prefix */
595                         case 'x':
596                                 conf.cgi_prefix = optarg;
597                                 break;
598 #endif
599
600 #ifdef HAVE_LUA
601                         /* lua prefix */
602                         case 'l':
603                                 conf.lua_prefix = optarg;
604                                 break;
605
606                         /* lua handler */
607                         case 'L':
608                                 conf.lua_handler = optarg;
609                                 break;
610 #endif
611
612 #if defined(HAVE_CGI) || defined(HAVE_LUA)
613                         /* script timeout */
614                         case 't':
615                                 conf.script_timeout = atoi(optarg);
616                                 break;
617 #endif
618
619                         /* no fork */
620                         case 'f':
621                                 nofork = 1;
622                                 break;
623
624                         /* urldecode */
625                         case 'd':
626                                 if( (port = malloc(strlen(optarg)+1)) != NULL )
627                                 {
628                                         memset(port, 0, strlen(optarg)+1);
629                                         uh_urldecode(port, strlen(optarg), optarg, strlen(optarg));
630                                         printf("%s", port);
631                                         free(port);
632                                         exit(0);
633                                 }
634                                 break;
635
636                         /* basic auth realm */
637                         case 'r':
638                                 conf.realm = optarg;
639                                 break;
640
641                         /* md5 crypt */
642                         case 'm':
643                                 printf("%s\n", crypt(optarg, "$1$"));
644                                 exit(0);
645                                 break;
646
647                         /* config file */
648                         case 'c':
649                                 conf.file = optarg;
650                                 break;
651
652                         default:
653                                 fprintf(stderr,
654                                         "Usage: %s -p [addr:]port [-h docroot]\n"
655                                         "       -f              Do not fork to background\n"
656                                         "       -c file         Configuration file, default is '/etc/httpd.conf'\n"
657                                         "       -p [addr:]port  Bind to specified address and port, multiple allowed\n"
658 #ifdef HAVE_TLS
659                                         "       -s [addr:]port  Like -p but provide HTTPS on this port\n"
660                                         "       -C file         ASN.1 server certificate file\n"
661                                         "       -K file         ASN.1 server private key file\n"
662 #endif
663                                         "       -h directory    Specify the document root, default is '.'\n"
664 #ifdef HAVE_LUA
665                                         "       -l string       URL prefix for Lua handler, default is '/lua'\n"
666                                         "       -L file         Lua handler script, omit to disable Lua\n"
667 #endif
668 #ifdef HAVE_CGI
669                                         "       -x string       URL prefix for CGI handler, default is '/cgi-bin'\n"
670 #endif
671 #if defined(HAVE_CGI) || defined(HAVE_LUA)
672                                         "       -t seconds      CGI and Lua script timeout in seconds, default is 60\n"
673 #endif
674                                         "       -d string       URL decode given string\n"
675                                         "       -r string       Specify basic auth realm\n"
676                                         "       -m string       MD5 crypt given string\n"
677                                         "\n", argv[0]
678                                 );
679
680                                 exit(1);
681                 }
682         }
683
684 #ifdef HAVE_TLS
685         if( (tls == 1) && (keys < 2) )
686         {
687                 fprintf(stderr, "Error: Missing private key or certificate file\n");
688                 exit(1);
689         }
690 #endif
691
692         if( bound < 1 )
693         {
694                 fprintf(stderr, "Error: No sockets bound, unable to continue\n");
695                 exit(1);
696         }
697
698         /* default docroot */
699         if( !conf.docroot[0] && !realpath(".", conf.docroot) )
700         {
701                 fprintf(stderr, "Error: Can not determine default document root: %s\n",
702                         strerror(errno));
703                 exit(1);
704         }
705
706         /* default realm */
707         if( ! conf.realm )
708                 conf.realm = "Protected Area";
709
710         /* config file */
711         uh_config_parse(conf.file);
712
713 #if defined(HAVE_CGI) || defined(HAVE_LUA)
714         /* default script timeout */
715         if( conf.script_timeout <= 0 )
716                 conf.script_timeout = 60;
717 #endif
718
719 #ifdef HAVE_CGI
720         /* default cgi prefix */
721         if( ! conf.cgi_prefix )
722                 conf.cgi_prefix = "/cgi-bin";
723 #endif
724
725 #ifdef HAVE_LUA
726         /* load Lua plugin */
727         if( ! (lua_lib = dlopen("uhttpd_lua.so", RTLD_LAZY | RTLD_GLOBAL)) )
728         {
729                 fprintf(stderr,
730                         "Notice: Unable to load Lua plugin - disabling Lua support! "
731                         "(Reason: %s)\n", dlerror()
732                 );
733         }
734         else
735         {
736                 /* resolve functions */
737                 if( !(conf.lua_init    = dlsym(lua_lib, "uh_lua_init"))    ||
738                     !(conf.lua_close   = dlsym(lua_lib, "uh_lua_close"))   ||
739                     !(conf.lua_request = dlsym(lua_lib, "uh_lua_request"))
740                 ) {
741                         fprintf(stderr,
742                                 "Error: Failed to lookup required symbols "
743                                 "in Lua plugin: %s\n", dlerror()
744                         );
745                         exit(1);
746                 }
747
748                 /* init Lua runtime if handler is specified */
749                 if( conf.lua_handler )
750                 {
751                         /* default lua prefix */
752                         if( ! conf.lua_prefix )
753                                 conf.lua_prefix = "/lua";
754
755                         L = conf.lua_init(conf.lua_handler);
756                 }
757         }
758 #endif
759
760         /* fork (if not disabled) */
761         if( ! nofork )
762         {
763                 switch( fork() )
764                 {
765                         case -1:
766                                 perror("fork()");
767                                 exit(1);
768
769                         case 0:
770                                 /* daemon setup */
771                                 if( chdir("/") )
772                                         perror("chdir()");
773
774                                 if( (cur_fd = open("/dev/null", O_WRONLY)) > -1 )
775                                         dup2(cur_fd, 0);
776
777                                 if( (cur_fd = open("/dev/null", O_RDONLY)) > -1 )
778                                         dup2(cur_fd, 1);
779
780                                 if( (cur_fd = open("/dev/null", O_RDONLY)) > -1 )
781                                         dup2(cur_fd, 2);
782
783                                 break;
784
785                         default:
786                                 exit(0);
787                 }
788         }
789
790         /* backup server descriptor set */
791         used_fds = serv_fds;
792
793         /* loop */
794         while(run)
795         {
796                 /* create a working copy of the used fd set */
797                 read_fds = used_fds;
798
799                 /* sleep until socket activity */
800                 if( select(max_fd + 1, &read_fds, NULL, NULL, NULL) == -1 )
801                 {
802                         perror("select()");
803                         exit(1);
804                 }
805
806                 /* run through the existing connections looking for data to be read */
807                 for( cur_fd = 0; cur_fd <= max_fd; cur_fd++ )
808                 {
809                         /* is a socket managed by us */
810                         if( FD_ISSET(cur_fd, &read_fds) )
811                         {
812                                 /* is one of our listen sockets */
813                                 if( FD_ISSET(cur_fd, &serv_fds) )
814                                 {
815                                         /* handle new connections */
816                                         if( (new_fd = accept(cur_fd, NULL, 0)) != -1 )
817                                         {
818                                                 /* add to global client list */
819                                                 if( (cl = uh_client_add(new_fd, uh_listener_lookup(cur_fd))) != NULL )
820                                                 {
821 #ifdef HAVE_TLS
822                                                         /* setup client tls context */
823                                                         if( conf.tls )
824                                                                 conf.tls_accept(cl);
825 #endif
826
827                                                         /* add client socket to global fdset */
828                                                         FD_SET(new_fd, &used_fds);
829                                                         fd_cloexec(new_fd);
830                                                         max_fd = max(max_fd, new_fd);
831                                                 }
832
833                                                 /* insufficient resources */
834                                                 else
835                                                 {
836                                                         fprintf(stderr,
837                                                                 "uh_client_add(): Can not manage more than "
838                                                                 "%i client sockets, connection dropped\n",
839                                                                 UH_LIMIT_CLIENTS
840                                                         );
841
842                                                         close(new_fd);
843                                                 }
844                                         }
845                                 }
846
847                                 /* is a client socket */
848                                 else
849                                 {
850                                         if( ! (cl = uh_client_lookup(cur_fd)) )
851                                         {
852                                                 /* this should not happen! */
853                                                 fprintf(stderr,
854                                                         "uh_client_lookup(): No entry for fd %i!\n",
855                                                         cur_fd);
856
857                                                 goto cleanup;
858                                         }
859
860                                         /* parse message header */
861                                         if( (req = uh_http_header_recv(cl)) != NULL )
862                                         {
863 #ifdef HAVE_LUA
864                                                 /* Lua request? */
865                                                 if( L && uh_path_match(conf.lua_prefix, req->url) )
866                                                 {
867                                                         conf.lua_request(cl, req, L);
868                                                 }
869                                                 else
870 #endif
871                                                 /* dispatch request */
872                                                 if( (pin = uh_path_lookup(cl, req->url)) != NULL )
873                                                 {
874                                                         /* auth ok? */
875                                                         if( uh_auth_check(cl, req, pin) )
876                                                         {
877 #ifdef HAVE_CGI
878                                                                 if( uh_path_match(conf.cgi_prefix, pin->name) )
879                                                                 {
880                                                                         uh_cgi_request(cl, req, pin);
881                                                                 }
882                                                                 else
883 #endif
884                                                                 {
885                                                                         uh_file_request(cl, req, pin);
886                                                                 }
887                                                         }
888                                                 }
889
890                                                 /* 404 */
891                                                 else
892                                                 {
893                                                         uh_http_sendhf(cl, 404, "Not Found",
894                                                                 "No such file or directory");
895                                                 }
896                                         }
897
898                                         /* 400 */
899                                         else
900                                         {
901                                                 uh_http_sendhf(cl, 400, "Bad Request",
902                                                         "Malformed request received");
903                                         }
904
905 #ifdef HAVE_TLS
906                                         /* free client tls context */
907                                         if( conf.tls )
908                                                 conf.tls_close(cl);
909 #endif
910
911                                         cleanup:
912
913                                         /* close client socket */
914                                         close(cur_fd);
915                                         FD_CLR(cur_fd, &used_fds);
916
917                                         /* remove from global client list */
918                                         uh_client_remove(cur_fd);
919                                 }
920                         }
921                 }
922         }
923
924 #ifdef HAVE_LUA
925         /* destroy the Lua state */
926         if( L != NULL )
927                 conf.lua_close(L);
928 #endif
929
930         return 0;
931 }
932