[package] uhttpd:
[openwrt.git] / package / uhttpd / src / uhttpd.c
1 /*
2  * uhttpd - Tiny single-threaded httpd - Main component
3  *
4  *   Copyright (C) 2010 Jo-Philipp Wich <xm@subsignal.org>
5  *
6  *  Licensed under the Apache License, Version 2.0 (the "License");
7  *  you may not use this file except in compliance with the License.
8  *  You may obtain a copy of the License at
9  *
10  *      http://www.apache.org/licenses/LICENSE-2.0
11  *
12  *  Unless required by applicable law or agreed to in writing, software
13  *  distributed under the License is distributed on an "AS IS" BASIS,
14  *  WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15  *  See the License for the specific language governing permissions and
16  *  limitations under the License.
17  */
18
19 #define _XOPEN_SOURCE 500       /* crypt() */
20
21 #include "uhttpd.h"
22 #include "uhttpd-utils.h"
23 #include "uhttpd-file.h"
24
25 #ifdef HAVE_CGI
26 #include "uhttpd-cgi.h"
27 #endif
28
29 #ifdef HAVE_LUA
30 #include "uhttpd-lua.h"
31 #endif
32
33 #ifdef HAVE_TLS
34 #include "uhttpd-tls.h"
35 #endif
36
37
38 static int run = 1;
39
40 static void uh_sigterm(int sig)
41 {
42         run = 0;
43 }
44
45 static void uh_sigchld(int sig)
46 {
47         while( waitpid(-1, NULL, WNOHANG) > 0 ) { }
48 }
49
50 static void uh_config_parse(const char *path)
51 {
52         FILE *c;
53         char line[512];
54         char *user = NULL;
55         char *pass = NULL;
56         char *eol  = NULL;
57
58         if( (c = fopen(path ? path : "/etc/httpd.conf", "r")) != NULL )
59         {
60                 memset(line, 0, sizeof(line));
61
62                 while( fgets(line, sizeof(line) - 1, c) )
63                 {
64                         if( (line[0] == '/') && (strchr(line, ':') != NULL) )
65                         {
66                                 if( !(user = strchr(line, ':')) || (*user++ = 0) ||
67                                     !(pass = strchr(user, ':')) || (*pass++ = 0) ||
68                                         !(eol = strchr(pass, '\n')) || (*eol++  = 0) )
69                                                 continue;
70
71                                 if( !uh_auth_add(line, user, pass) )
72                                 {
73                                         fprintf(stderr,
74                                                 "Can not manage more than %i basic auth realms, "
75                                                 "will skip the rest\n", UH_LIMIT_AUTHREALMS
76                                         );
77
78                                         break;
79                                 } 
80                         }
81                 }
82
83                 fclose(c);
84         }
85 }
86
87 static int uh_socket_bind(
88         fd_set *serv_fds, int *max_fd, const char *host, const char *port,
89         struct addrinfo *hints, int do_tls, struct config *conf
90 ) {
91         int sock = -1;
92         int yes = 1;
93         int status;
94         int bound = 0;
95
96         struct listener *l = NULL;
97         struct addrinfo *addrs = NULL, *p = NULL;
98
99         if( (status = getaddrinfo(host, port, hints, &addrs)) != 0 )
100         {
101                 fprintf(stderr, "getaddrinfo(): %s\n", gai_strerror(status));
102         }
103
104         /* try to bind a new socket to each found address */
105         for( p = addrs; p; p = p->ai_next )
106         {
107                 /* get the socket */
108                 if( (sock = socket(p->ai_family, p->ai_socktype, p->ai_protocol)) == -1 )
109                 {
110                         perror("socket()");
111                         goto error;
112                 }
113
114                 /* "address already in use" */
115                 if( setsockopt(sock, SOL_SOCKET, SO_REUSEADDR, &yes, sizeof(yes)) == -1 )
116                 {
117                         perror("setsockopt()");
118                         goto error;
119                 }
120
121                 /* required to get parallel v4 + v6 working */
122                 if( p->ai_family == AF_INET6 )
123                 {
124                         if( setsockopt(sock, IPPROTO_IPV6, IPV6_V6ONLY, &yes, sizeof(yes)) == -1 )
125                         {
126                                 perror("setsockopt()");
127                                 goto error;
128                         }
129                 }
130
131                 /* bind */
132                 if( bind(sock, p->ai_addr, p->ai_addrlen) == -1 )
133                 {
134                         perror("bind()");
135                         goto error;
136                 }
137
138                 /* listen */
139                 if( listen(sock, UH_LIMIT_CLIENTS) == -1 )
140                 {
141                         perror("listen()");
142                         goto error;
143                 }
144
145                 /* add listener to global list */
146                 if( ! (l = uh_listener_add(sock, conf)) )
147                 {
148                         fprintf(stderr,
149                                 "uh_listener_add(): Can not create more than "
150                                 "%i listen sockets\n", UH_LIMIT_LISTENERS
151                         );
152
153                         goto error;
154                 }
155
156 #ifdef HAVE_TLS
157                 /* init TLS */
158                 l->tls = do_tls ? conf->tls : NULL;
159 #endif
160
161                 /* add socket to server fd set */
162                 FD_SET(sock, serv_fds);
163                 fd_cloexec(sock);
164                 *max_fd = max(*max_fd, sock);
165
166                 bound++;
167                 continue;
168
169                 error:
170                 if( sock > 0 )
171                         close(sock);
172         }
173
174         freeaddrinfo(addrs);
175
176         return bound;
177 }
178
179 static struct http_request * uh_http_header_parse(struct client *cl, char *buffer, int buflen)
180 {
181         char *method  = &buffer[0];
182         char *path    = NULL;
183         char *version = NULL;
184
185         char *headers = NULL;
186         char *hdrname = NULL;
187         char *hdrdata = NULL;
188
189         int i;
190         int hdrcount = 0;
191
192         static struct http_request req;
193
194         memset(&req, 0, sizeof(req));
195
196
197         /* terminate initial header line */
198         if( (headers = strfind(buffer, buflen, "\r\n", 2)) != NULL )
199         {
200                 buffer[buflen-1] = 0;
201
202                 *headers++ = 0;
203                 *headers++ = 0;
204
205                 /* find request path */
206                 if( (path = strchr(buffer, ' ')) != NULL )
207                         *path++ = 0;
208
209                 /* find http version */
210                 if( (path != NULL) && ((version = strchr(path, ' ')) != NULL) )
211                         *version++ = 0;
212
213
214                 /* check method */
215                 if( strcmp(method, "GET") && strcmp(method, "HEAD") && strcmp(method, "POST") )
216                 {
217                         /* invalid method */
218                         uh_http_response(cl, 405, "Method Not Allowed");
219                         return NULL;
220                 }
221                 else
222                 {
223                         switch(method[0])
224                         {
225                                 case 'G':
226                                         req.method = UH_HTTP_MSG_GET;
227                                         break;
228
229                                 case 'H':
230                                         req.method = UH_HTTP_MSG_HEAD;
231                                         break;
232
233                                 case 'P':
234                                         req.method = UH_HTTP_MSG_POST;
235                                         break;
236                         }
237                 }
238
239                 /* check path */
240                 if( !path || !strlen(path) )
241                 {
242                         /* malformed request */
243                         uh_http_response(cl, 400, "Bad Request");
244                         return NULL;
245                 }
246                 else
247                 {
248                         req.url = path;
249                 }
250
251                 /* check version */
252                 if( strcmp(version, "HTTP/0.9") && strcmp(version, "HTTP/1.0") && strcmp(version, "HTTP/1.1") )
253                 {
254                         /* unsupported version */
255                         uh_http_response(cl, 400, "Bad Request");
256                         return NULL;
257                 }
258                 else
259                 {
260                         req.version = strtof(&version[5], NULL);
261                 }
262
263
264                 /* process header fields */
265                 for( i = (int)(headers - buffer); i < buflen; i++ )
266                 {
267                         /* found eol and have name + value, push out header tuple */
268                         if( hdrname && hdrdata && (buffer[i] == '\r' || buffer[i] == '\n') )
269                         {
270                                 buffer[i] = 0;
271
272                                 /* store */
273                                 if( (hdrcount + 1) < array_size(req.headers) )
274                                 {
275                                         req.headers[hdrcount++] = hdrname;
276                                         req.headers[hdrcount++] = hdrdata;
277
278                                         hdrname = hdrdata = NULL;
279                                 }
280
281                                 /* too large */
282                                 else
283                                 {
284                                         uh_http_response(cl, 413, "Request Entity Too Large");
285                                         return NULL;
286                                 }
287                         }
288
289                         /* have name but no value and found a colon, start of value */
290                         else if( hdrname && !hdrdata && ((i+2) < buflen) &&
291                                 (buffer[i] == ':') && (buffer[i+1] == ' ')
292                         ) {
293                                 buffer[i] = 0;
294                                 hdrdata = &buffer[i+2];
295                         }
296
297                         /* have no name and found [A-Z], start of name */
298                         else if( !hdrname && isalpha(buffer[i]) && isupper(buffer[i]) )
299                         {
300                                 hdrname = &buffer[i];
301                         }
302                 }
303
304                 /* valid enough */
305                 return &req;
306         }
307
308         /* Malformed request */
309         uh_http_response(cl, 400, "Bad Request");
310         return NULL;
311 }
312
313
314 static struct http_request * uh_http_header_recv(struct client *cl)
315 {
316         static char buffer[UH_LIMIT_MSGHEAD];
317         char *bufptr = &buffer[0];
318         char *idxptr = NULL;
319
320         struct timeval timeout;
321
322         fd_set reader;
323
324         ssize_t blen = sizeof(buffer)-1;
325         ssize_t rlen = 0;
326
327
328         memset(buffer, 0, sizeof(buffer));
329
330         while( blen > 0 )
331         {
332                 FD_ZERO(&reader);
333                 FD_SET(cl->socket, &reader);
334
335                 /* fail after 0.1s */
336                 timeout.tv_sec  = 0;
337                 timeout.tv_usec = 100000;
338
339                 /* check whether fd is readable */
340                 if( select(cl->socket + 1, &reader, NULL, NULL, &timeout) > 0 )
341                 {
342                         /* receive data */
343                         rlen = uh_tcp_peek(cl, bufptr, blen);
344
345                         if( rlen > 0 )
346                         {
347                                 if( (idxptr = strfind(buffer, sizeof(buffer), "\r\n\r\n", 4)) )
348                                 {
349                                         blen -= uh_tcp_recv(cl, bufptr, (int)(idxptr - bufptr) + 4);
350
351                                         /* header read complete ... */
352                                         return uh_http_header_parse(cl, buffer, sizeof(buffer) - blen - 1);
353                                 }
354                                 else
355                                 {
356                                         rlen = uh_tcp_recv(cl, bufptr, rlen);
357                                         blen -= rlen;
358                                         bufptr += rlen;
359                                 }
360                         }
361                         else
362                         {
363                                 /* invalid request (unexpected eof/timeout) */
364                                 uh_http_response(cl, 408, "Request Timeout");
365                                 return NULL;
366                         }
367                 }
368                 else
369                 {
370                         /* invalid request (unexpected eof/timeout) */
371                         uh_http_response(cl, 408, "Request Timeout");
372                         return NULL;
373                 }
374         }
375
376         /* request entity too large */
377         uh_http_response(cl, 413, "Request Entity Too Large");
378         return NULL;
379 }
380
381 static int uh_path_match(const char *prefix, const char *url)
382 {
383         if( (strstr(url, prefix) == url) &&
384             ((prefix[strlen(prefix)-1] == '/') ||
385                  (strlen(url) == strlen(prefix))   ||
386                  (url[strlen(prefix)] == '/'))
387         ) {
388                 return 1;
389         }
390
391         return 0;
392 }
393
394
395 int main (int argc, char **argv)
396 {
397 #ifdef HAVE_LUA
398         /* Lua runtime */
399         lua_State *L = NULL;
400 #endif
401
402         /* master file descriptor list */
403         fd_set used_fds, serv_fds, read_fds;
404
405         /* working structs */
406         struct addrinfo hints;
407         struct http_request *req;
408         struct path_info *pin;
409         struct client *cl;
410         struct sigaction sa;
411         struct config conf;
412
413         /* maximum file descriptor number */
414         int new_fd, cur_fd, max_fd = 0;
415
416         int tls = 0;
417         int keys = 0;
418         int bound = 0;
419         int nofork = 0;
420
421         /* args */
422         char opt;
423         char bind[128];
424         char *port = NULL;
425
426         /* library handles */
427         void *tls_lib;
428         void *lua_lib;
429
430         /* clear the master and temp sets */
431         FD_ZERO(&used_fds);
432         FD_ZERO(&serv_fds);
433         FD_ZERO(&read_fds);
434
435         /* handle SIGPIPE, SIGCHILD */
436         sa.sa_flags = 0;
437         sigemptyset(&sa.sa_mask);
438
439         sa.sa_handler = SIG_IGN;
440         sigaction(SIGPIPE, &sa, NULL);
441
442         sa.sa_handler = uh_sigchld;
443         sigaction(SIGCHLD, &sa, NULL);
444
445         sa.sa_handler = uh_sigterm;
446         sigaction(SIGINT,  &sa, NULL);
447         sigaction(SIGTERM, &sa, NULL);
448
449         /* prepare addrinfo hints */
450         memset(&hints, 0, sizeof(hints));
451         hints.ai_family   = AF_UNSPEC;
452         hints.ai_socktype = SOCK_STREAM;
453         hints.ai_flags    = AI_PASSIVE;
454
455         /* parse args */
456         memset(&conf, 0, sizeof(conf));
457         memset(bind, 0, sizeof(bind));
458
459 #ifdef HAVE_TLS
460         /* load TLS plugin */
461         if( ! (tls_lib = dlopen("uhttpd_tls.so", RTLD_LAZY | RTLD_GLOBAL)) )
462         {
463                 fprintf(stderr,
464                         "Notice: Unable to load TLS plugin - disabling SSL support! "
465                         "(Reason: %s)\n", dlerror()
466                 );
467         }
468         else
469         {
470                 /* resolve functions */
471                 if( !(conf.tls_init   = dlsym(tls_lib, "uh_tls_ctx_init"))      ||
472                     !(conf.tls_cert   = dlsym(tls_lib, "uh_tls_ctx_cert"))      ||
473                     !(conf.tls_key    = dlsym(tls_lib, "uh_tls_ctx_key"))       ||
474                     !(conf.tls_free   = dlsym(tls_lib, "uh_tls_ctx_free"))      ||
475                         !(conf.tls_accept = dlsym(tls_lib, "uh_tls_client_accept")) ||
476                         !(conf.tls_close  = dlsym(tls_lib, "uh_tls_client_close"))  ||
477                         !(conf.tls_recv   = dlsym(tls_lib, "uh_tls_client_recv"))   ||
478                         !(conf.tls_send   = dlsym(tls_lib, "uh_tls_client_send"))
479                 ) {
480                         fprintf(stderr,
481                                 "Error: Failed to lookup required symbols "
482                                 "in TLS plugin: %s\n", dlerror()
483                         );
484                         exit(1);
485                 }
486
487                 /* init SSL context */
488                 if( ! (conf.tls = conf.tls_init()) )
489                 {
490                         fprintf(stderr, "Error: Failed to initalize SSL context\n");
491                         exit(1);
492                 }
493         }
494 #endif
495
496         while( (opt = getopt(argc, argv, "fC:K:p:s:h:c:l:L:d:r:m:x:t:")) > 0 )
497         {
498                 switch(opt)
499                 {
500                         /* [addr:]port */
501                         case 'p':
502                         case 's':
503                                 if( (port = strrchr(optarg, ':')) != NULL )
504                                 {
505                                         if( (optarg[0] == '[') && (port > optarg) && (port[-1] == ']') )
506                                                 memcpy(bind, optarg + 1,
507                                                         min(sizeof(bind), (int)(port - optarg) - 2));
508                                         else
509                                                 memcpy(bind, optarg,
510                                                         min(sizeof(bind), (int)(port - optarg)));
511
512                                         port++;
513                                 }
514                                 else
515                                 {
516                                         port = optarg;
517                                 }
518
519                                 if( opt == 's' )
520                                 {
521                                         if( !conf.tls )
522                                         {
523                                                 fprintf(stderr,
524                                                         "Notice: TLS support is disabled, "
525                                                         "ignoring '-s %s'\n", optarg
526                                                 );
527                                                 continue;
528                                         }
529
530                                         tls = 1;
531                                 }
532
533                                 /* bind sockets */
534                                 bound += uh_socket_bind(
535                                         &serv_fds, &max_fd, bind[0] ? bind : NULL, port,
536                                         &hints, (opt == 's'), &conf
537                                 );
538
539                                 break;
540
541 #ifdef HAVE_TLS
542                         /* certificate */
543                         case 'C':
544                                 if( conf.tls )
545                                 {
546                                         if( conf.tls_cert(conf.tls, optarg) < 1 )
547                                         {
548                                                 fprintf(stderr,
549                                                         "Error: Invalid certificate file given\n");
550                                                 exit(1);
551                                         }
552
553                                         keys++;
554                                 }
555
556                                 break;
557
558                         /* key */
559                         case 'K':
560                                 if( conf.tls )
561                                 {
562                                         if( conf.tls_key(conf.tls, optarg) < 1 )
563                                         {
564                                                 fprintf(stderr,
565                                                         "Error: Invalid private key file given\n");
566                                                 exit(1);
567                                         }
568
569                                         keys++;
570                                 }
571
572                                 break;
573 #endif
574
575                         /* docroot */
576                         case 'h':
577                                 if( ! realpath(optarg, conf.docroot) )
578                                 {
579                                         fprintf(stderr, "Error: Invalid directory %s: %s\n",
580                                                 optarg, strerror(errno));
581                                         exit(1);
582                                 }
583                                 break;
584
585 #ifdef HAVE_CGI
586                         /* cgi prefix */
587                         case 'x':
588                                 conf.cgi_prefix = optarg;
589                                 break;
590 #endif
591
592 #ifdef HAVE_LUA
593                         /* lua prefix */
594                         case 'l':
595                                 conf.lua_prefix = optarg;
596                                 break;
597
598                         /* lua handler */
599                         case 'L':
600                                 conf.lua_handler = optarg;
601                                 break;
602 #endif
603
604 #if defined(HAVE_CGI) || defined(HAVE_LUA)
605                         /* script timeout */
606                         case 't':
607                                 conf.script_timeout = atoi(optarg);
608                                 break;
609 #endif
610
611                         /* no fork */
612                         case 'f':
613                                 nofork = 1;
614                                 break;
615
616                         /* urldecode */
617                         case 'd':
618                                 if( (port = malloc(strlen(optarg)+1)) != NULL )
619                                 {
620                                         memset(port, 0, strlen(optarg)+1);
621                                         uh_urldecode(port, strlen(optarg), optarg, strlen(optarg));
622                                         printf("%s", port);
623                                         free(port);
624                                         exit(0);
625                                 }
626                                 break;
627
628                         /* basic auth realm */
629                         case 'r':
630                                 conf.realm = optarg;
631                                 break;
632
633                         /* md5 crypt */
634                         case 'm':
635                                 printf("%s\n", crypt(optarg, "$1$"));
636                                 exit(0);
637                                 break;
638
639                         /* config file */
640                         case 'c':
641                                 conf.file = optarg;
642                                 break;
643
644                         default:
645                                 fprintf(stderr,
646                                         "Usage: %s -p [addr:]port [-h docroot]\n"
647                                         "       -f              Do not fork to background\n"
648                                         "       -c file         Configuration file, default is '/etc/httpd.conf'\n"
649                                         "       -p [addr:]port  Bind to specified address and port, multiple allowed\n"
650 #ifdef HAVE_TLS
651                                         "       -s [addr:]port  Like -p but provide HTTPS on this port\n"
652                                         "       -C file         ASN.1 server certificate file\n"
653                                         "       -K file         ASN.1 server private key file\n"
654 #endif
655                                         "       -h directory    Specify the document root, default is '.'\n"
656 #ifdef HAVE_LUA
657                                         "       -l string       URL prefix for Lua handler, default is '/lua'\n"
658                                         "       -L file         Lua handler script, omit to disable Lua\n"
659 #endif
660 #ifdef HAVE_CGI
661                                         "       -x string       URL prefix for CGI handler, default is '/cgi-bin'\n"
662 #endif
663 #if defined(HAVE_CGI) || defined(HAVE_LUA)
664                                         "       -t seconds      CGI and Lua script timeout in seconds, default is 60\n"
665 #endif
666                                         "       -d string       URL decode given string\n"
667                                         "       -r string       Specify basic auth realm\n"
668                                         "       -m string       MD5 crypt given string\n"
669                                         "\n", argv[0]
670                                 );
671
672                                 exit(1);
673                 }
674         }
675
676 #ifdef HAVE_TLS
677         if( (tls == 1) && (keys < 2) )
678         {
679                 fprintf(stderr, "Error: Missing private key or certificate file\n");
680                 exit(1);
681         }
682 #endif
683
684         if( bound < 1 )
685         {
686                 fprintf(stderr, "Error: No sockets bound, unable to continue\n");
687                 exit(1);
688         }
689
690         /* default docroot */
691         if( !conf.docroot[0] && !realpath(".", conf.docroot) )
692         {
693                 fprintf(stderr, "Error: Can not determine default document root: %s\n",
694                         strerror(errno));
695                 exit(1);
696         }
697
698         /* default realm */
699         if( ! conf.realm )
700                 conf.realm = "Protected Area";
701
702         /* config file */
703         uh_config_parse(conf.file);
704
705 #if defined(HAVE_CGI) || defined(HAVE_LUA)
706         /* default script timeout */
707         if( conf.script_timeout <= 0 )
708                 conf.script_timeout = 60;
709 #endif
710
711 #ifdef HAVE_CGI
712         /* default cgi prefix */
713         if( ! conf.cgi_prefix )
714                 conf.cgi_prefix = "/cgi-bin";
715 #endif
716
717 #ifdef HAVE_LUA
718         /* load Lua plugin */
719         if( ! (lua_lib = dlopen("uhttpd_lua.so", RTLD_LAZY | RTLD_GLOBAL)) )
720         {
721                 fprintf(stderr,
722                         "Notice: Unable to load Lua plugin - disabling Lua support! "
723                         "(Reason: %s)\n", dlerror()
724                 );
725         }
726         else
727         {
728                 /* resolve functions */
729                 if( !(conf.lua_init    = dlsym(lua_lib, "uh_lua_init"))    ||
730                     !(conf.lua_close   = dlsym(lua_lib, "uh_lua_close"))   ||
731                     !(conf.lua_request = dlsym(lua_lib, "uh_lua_request"))
732                 ) {
733                         fprintf(stderr,
734                                 "Error: Failed to lookup required symbols "
735                                 "in Lua plugin: %s\n", dlerror()
736                         );
737                         exit(1);
738                 }
739
740                 /* init Lua runtime if handler is specified */
741                 if( conf.lua_handler )
742                 {
743                         /* default lua prefix */
744                         if( ! conf.lua_prefix )
745                                 conf.lua_prefix = "/lua";
746
747                         L = conf.lua_init(conf.lua_handler);
748                 }
749         }
750 #endif
751
752         /* fork (if not disabled) */
753         if( ! nofork )
754         {
755                 switch( fork() )
756                 {
757                         case -1:
758                                 perror("fork()");
759                                 exit(1);
760
761                         case 0:
762                                 /* daemon setup */
763                                 if( chdir("/") )
764                                         perror("chdir()");
765
766                                 if( (cur_fd = open("/dev/null", O_WRONLY)) > -1 )
767                                         dup2(cur_fd, 0);
768
769                                 if( (cur_fd = open("/dev/null", O_RDONLY)) > -1 )
770                                         dup2(cur_fd, 1);
771
772                                 if( (cur_fd = open("/dev/null", O_RDONLY)) > -1 )
773                                         dup2(cur_fd, 2);
774
775                                 break;
776
777                         default:
778                                 exit(0);
779                 }
780         }
781
782         /* backup server descriptor set */
783         used_fds = serv_fds;
784
785         /* loop */
786         while(run)
787         {
788                 /* create a working copy of the used fd set */
789                 read_fds = used_fds;
790
791                 /* sleep until socket activity */
792                 if( select(max_fd + 1, &read_fds, NULL, NULL, NULL) == -1 )
793                 {
794                         perror("select()");
795                         exit(1);
796                 }
797
798                 /* run through the existing connections looking for data to be read */
799                 for( cur_fd = 0; cur_fd <= max_fd; cur_fd++ )
800                 {
801                         /* is a socket managed by us */
802                         if( FD_ISSET(cur_fd, &read_fds) )
803                         {
804                                 /* is one of our listen sockets */
805                                 if( FD_ISSET(cur_fd, &serv_fds) )
806                                 {
807                                         /* handle new connections */
808                                         if( (new_fd = accept(cur_fd, NULL, 0)) != -1 )
809                                         {
810                                                 /* add to global client list */
811                                                 if( (cl = uh_client_add(new_fd, uh_listener_lookup(cur_fd))) != NULL )
812                                                 {
813 #ifdef HAVE_TLS
814                                                         /* setup client tls context */
815                                                         if( conf.tls )
816                                                                 conf.tls_accept(cl);
817 #endif
818
819                                                         /* add client socket to global fdset */
820                                                         FD_SET(new_fd, &used_fds);
821                                                         fd_cloexec(new_fd);
822                                                         max_fd = max(max_fd, new_fd);
823                                                 }
824
825                                                 /* insufficient resources */
826                                                 else
827                                                 {
828                                                         fprintf(stderr,
829                                                                 "uh_client_add(): Can not manage more than "
830                                                                 "%i client sockets, connection dropped\n",
831                                                                 UH_LIMIT_CLIENTS
832                                                         );
833
834                                                         close(new_fd);
835                                                 }
836                                         }
837                                 }
838
839                                 /* is a client socket */
840                                 else
841                                 {
842                                         if( ! (cl = uh_client_lookup(cur_fd)) )
843                                         {
844                                                 /* this should not happen! */
845                                                 fprintf(stderr,
846                                                         "uh_client_lookup(): No entry for fd %i!\n",
847                                                         cur_fd);
848
849                                                 goto cleanup;
850                                         }
851
852                                         /* parse message header */
853                                         if( (req = uh_http_header_recv(cl)) != NULL )
854                                         {
855 #ifdef HAVE_LUA
856                                                 /* Lua request? */
857                                                 if( L && uh_path_match(conf.lua_prefix, req->url) )
858                                                 {
859                                                         conf.lua_request(cl, req, L);
860                                                 }
861                                                 else
862 #endif
863                                                 /* dispatch request */
864                                                 if( (pin = uh_path_lookup(cl, req->url)) != NULL )
865                                                 {
866                                                         /* auth ok? */
867                                                         if( uh_auth_check(cl, req, pin) )
868                                                         {
869 #ifdef HAVE_CGI
870                                                                 if( uh_path_match(conf.cgi_prefix, pin->name) )
871                                                                 {
872                                                                         uh_cgi_request(cl, req, pin);
873                                                                 }
874                                                                 else
875 #endif
876                                                                 {
877                                                                         uh_file_request(cl, req, pin);
878                                                                 }
879                                                         }
880                                                 }
881
882                                                 /* 404 */
883                                                 else
884                                                 {
885                                                         uh_http_sendhf(cl, 404, "Not Found",
886                                                                 "No such file or directory");
887                                                 }
888                                         }
889
890                                         /* 400 */
891                                         else
892                                         {
893                                                 uh_http_sendhf(cl, 400, "Bad Request",
894                                                         "Malformed request received");
895                                         }
896
897 #ifdef HAVE_TLS
898                                         /* free client tls context */
899                                         if( conf.tls )
900                                                 conf.tls_close(cl);
901 #endif
902
903                                         cleanup:
904
905                                         /* close client socket */
906                                         close(cur_fd);
907                                         FD_CLR(cur_fd, &used_fds);
908
909                                         /* remove from global client list */
910                                         uh_client_remove(cur_fd);
911                                 }
912                         }
913                 }
914         }
915
916 #ifdef HAVE_LUA
917         /* destroy the Lua state */
918         if( L != NULL )
919                 conf.lua_close(L);
920 #endif
921
922         return 0;
923 }
924