]> arthur.barton.de Git - ngircd-alex.git/blobdiff - src/ngircd/ngircd.c
Make setgroups(3) function optional
[ngircd-alex.git] / src / ngircd / ngircd.c
index 113cecabf848cda2246ff08c278fd69c7b50edda..0e8acb54213e3a3c6e54e99affdf0b9bfed22871 100644 (file)
 /*
  * ngIRCd -- The Next Generation IRC Daemon
- * Copyright (c)2001,2002 by Alexander Barton (alex@barton.de)
+ * Copyright (c)2001-2014 Alexander Barton (alex@barton.de) and Contributors.
  *
- * Dieses Programm ist freie Software. Sie koennen es unter den Bedingungen
- * der GNU General Public License (GPL), wie von der Free Software Foundation
- * herausgegeben, weitergeben und/oder modifizieren, entweder unter Version 2
- * der Lizenz oder (wenn Sie es wuenschen) jeder spaeteren Version.
- * Naehere Informationen entnehmen Sie bitter der Datei COPYING. Eine Liste
- * der an ngIRCd beteiligten Autoren finden Sie in der Datei AUTHORS.
- *
- * $Id: ngircd.c,v 1.31 2002/03/10 17:50:48 alex Exp $
- *
- * ngircd.c: Hier beginnt alles ;-)
- *
- * $Log: ngircd.c,v $
- * Revision 1.31  2002/03/10 17:50:48  alex
- * - Handling von "--version" und "--help" nochmal geaendert ...
- *
- * Revision 1.30  2002/03/10 17:45:41  alex
- * - bei "ngircd --version" werden nun die eincompilierten Pfade angezeigt.
- *
- * Revision 1.29  2002/03/06 15:36:04  alex
- * - stderr wird nun in eine Datei umgelenkt (ngircd.err). Wenn der Server
- *   nicht im Debug-Modus laeuft, so wird diese bei Programmende geloescht.
- *
- * Revision 1.28  2002/02/27 23:24:29  alex
- * - ueberfluessige Init- und Exit-Funktionen entfernt.
- *
- * Revision 1.27  2002/02/25 11:42:47  alex
- * - wenn ein System sigaction() nicht kennt, so wird nun signal() verwendet.
- *
- * Revision 1.26  2002/02/23 19:06:47  alex
- * - fuer SIGCHLD wird nun auch SA_NOCLDWAIT gesetzt, wenn vorhanden.
- *
- * Revision 1.25  2002/02/19 20:30:47  alex
- * - SA_RESTART wird fuer Signale nur noch gesetzt, wenn es definiert ist.
- *
- * Revision 1.24  2002/02/19 20:08:24  alex
- * - "Passive-Mode" implementiert: kein Auto-Conect zu anderen Servern.
- * - NGIRCd_DebugLevel wird (fuer VERSION-Befehl) ermittelt.
- *
- * Revision 1.23  2002/02/17 23:40:21  alex
- * - neue Funktion NGIRCd_VersionAddition(). NGIRCd_Version() aufgespaltet.
- *
- * Revision 1.22  2002/01/22 17:15:39  alex
- * - die Fehlermeldung "interrupted system call" sollte nicht mehr auftreten.
- *
- * Revision 1.21  2002/01/21 00:02:11  alex
- * - Hilfetexte korrigiert und ergaenzt (Sniffer).
- *
- * Revision 1.20  2002/01/18 11:12:11  alex
- * - der Sniffer wird nun nur noch aktiviert, wenn auf Kommandozeile angegeben.
- *
- * Revision 1.19  2002/01/12 00:17:28  alex
- * - ngIRCd wandelt sich nun selber in einen Daemon (Hintergrundprozess) um.
- *
- * Revision 1.18  2002/01/11 14:45:18  alex
- * - Kommandozeilen-Parser implementiert: Debug- und No-Daemon-Modus, Hilfe.
- *
- * Revision 1.17  2002/01/02 02:51:16  alex
- * - Signal-Handler fuer SIGCHLD: so sollten Zombies nicht mehr vorkommen.
- *
- * Revision 1.15  2001/12/31 02:18:51  alex
- * - viele neue Befehle (WHOIS, ISON, OPER, DIE, RESTART),
- * - neuen Header "defines.h" mit (fast) allen Konstanten.
- * - Code Cleanups und viele "kleine" Aenderungen & Bugfixes.
- *
- * Revision 1.14  2001/12/30 19:26:12  alex
- * - Unterstuetzung fuer die Konfigurationsdatei eingebaut.
- *
- * Revision 1.13  2001/12/30 11:42:00  alex
- * - der Server meldet nun eine ordentliche "Start-Zeit".
- *
- * Revision 1.12  2001/12/29 03:07:36  alex
- * - einige Loglevel geaendert.
- *
- * Revision 1.11  2001/12/26 14:45:37  alex
- * - "Code Cleanups".
- *
- * Revision 1.10  2001/12/24 01:34:38  alex
- * - Signal-Handler aufgeraeumt; u.a. SIGPIPE wird nun korrekt ignoriert.
- *
- * Revision 1.9  2001/12/21 22:24:50  alex
- * - neues Modul "parse" wird initialisiert und abgemeldet.
- *
- * Revision 1.8  2001/12/14 08:15:26  alex
- * - neue Module (irc, client, channel) werden an- und abgemeldet.
- * - zweiter Listen-Socket wird zu Testzwecken konfiguriert.
- *
- * Revision 1.7  2001/12/13 01:31:46  alex
- * - Conn_Handler() wird nun mit einem Timeout aufgerufen.
- *
- * Revision 1.6  2001/12/12 23:30:42  alex
- * - Log-Meldungen an syslog angepasst.
- * - NGIRCd_Quit ist nun das Flag zum Beenden des ngircd.
- *
- * Revision 1.5  2001/12/12 17:21:21  alex
- * - mehr Unterfunktionen eingebaut, Modul besser strukturiert & dokumentiert.
- * - Anpassungen an neue Module.
- *
- * Revision 1.4  2001/12/12 01:58:53  alex
- * - Test auf socklen_t verbessert.
- *
- * Revision 1.3  2001/12/12 01:40:39  alex
- * - ein paar mehr Kommentare; Variablennamen verstaendlicher gemacht.
- * - fehlenden Header <arpa/inet.h> ergaenz.
- * - SIGINT und SIGQUIT werden nun ebenfalls behandelt.
- *
- * Revision 1.2  2001/12/11 22:04:21  alex
- * - Test auf stdint.h (HAVE_STDINT_H) hinzugefuegt.
- *
- * Revision 1.1.1.1  2001/12/11 21:53:04  alex
- * - Imported sources to CVS.
+ * This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; either version 2 of the License, or
+ * (at your option) any later version.
+ * Please read the file COPYING, README and AUTHORS for more information.
  */
 
+#include "portab.h"
 
-#define PORTAB_CHECK_TYPES             /* Prueffunktion einbinden, s.u. */
-
-
-#include <portab.h>
-#include "global.h"
-
-#include <imp.h>
+/**
+ * @file
+ * The main program, including the C function main() which is called
+ * by the loader of the operating system.
+ */
 
 #include <assert.h>
 #include <errno.h>
 #include <stdio.h>
-#include <signal.h>
+#include <stdlib.h>
 #include <string.h>
 #include <unistd.h>
-#include <sys/types.h>
-#include <sys/wait.h>
 #include <time.h>
+#include <sys/types.h>
+#include <sys/stat.h>
+#include <fcntl.h>
+#include <pwd.h>
+#include <grp.h>
 
+#if defined(DEBUG) && defined(HAVE_MTRACE)
+#include <mcheck.h>
+#endif
+
+#include "conn.h"
+#include "class.h"
 #include "channel.h"
-#include "client.h"
 #include "conf.h"
-#include "conn.h"
-#include "irc.h"
 #include "log.h"
-#include "parse.h"
+#include "sighandlers.h"
+#include "io.h"
 
-#include <exp.h>
 #include "ngircd.h"
 
+static void Show_Version PARAMS(( void ));
+static void Show_Help PARAMS(( void ));
+
+static void Pidfile_Create PARAMS(( pid_t pid ));
+static void Pidfile_Delete PARAMS(( void ));
+
+static void Fill_Version PARAMS(( void ));
 
-LOCAL VOID Initialize_Signal_Handler( VOID );
-LOCAL VOID Signal_Handler( INT Signal );
+static void Random_Init PARAMS(( void ));
 
-LOCAL VOID Initialize_Listen_Ports( VOID );
+static void Setup_FDStreams PARAMS(( int fd ));
 
-LOCAL VOID Show_Version( VOID );
-LOCAL VOID Show_Help( VOID );
+static bool NGIRCd_Init PARAMS(( bool ));
 
 
-GLOBAL INT main( INT argc, CONST CHAR *argv[] )
+/**
+ * The main() function of ngIRCd.
+ *
+ * Here all starts: this function is called by the operating system loader,
+ * it is the first portion of code executed of ngIRCd.
+ *
+ * @param argc The number of arguments passed to ngIRCd on the command line.
+ * @param argv An array containing all the arguments passed to ngIRCd.
+ * @return Global exit code of ngIRCd, zero on success.
+ */
+GLOBAL int
+main(int argc, const char *argv[])
 {
-       BOOLEAN ok;
-       INT pid, i, n;
+       bool ok, configtest = false;
+       bool NGIRCd_NoDaemon = false;
+       int i;
+       size_t n;
+
+#if defined(DEBUG) && defined(HAVE_MTRACE)
+       /* enable GNU libc memory tracing when running in debug mode
+        * and functionality available */
+       mtrace();
+#endif
 
-       /* Datentypen der portab-Library ueberpruefen */
-       portab_check_types( );
+       umask(0077);
 
-       NGIRCd_Restart = FALSE;
-       NGIRCd_Quit = FALSE;
-       NGIRCd_NoDaemon = FALSE;
-       NGIRCd_Passive = FALSE;
+       NGIRCd_SignalQuit = NGIRCd_SignalRestart = false;
+       NGIRCd_Passive = false;
 #ifdef DEBUG
-       NGIRCd_Debug = FALSE;
+       NGIRCd_Debug = false;
 #endif
 #ifdef SNIFFER
-       NGIRCd_Sniffer = FALSE;
+       NGIRCd_Sniffer = false;
 #endif
-
-       /* Kommandozeile parsen */
-       for( i = 1; i < argc; i++ )
-       {
-               ok = FALSE;
-               if(( argv[i][0] == '-' ) && ( argv[i][1] == '-' ))
-               {
-                       /* Lange Option */
-
+       strlcpy(NGIRCd_ConfFile, SYSCONFDIR, sizeof(NGIRCd_ConfFile));
+       strlcat(NGIRCd_ConfFile, CONFIG_FILE, sizeof(NGIRCd_ConfFile));
+
+       Fill_Version();
+
+       /* parse conmmand line */
+       for (i = 1; i < argc; i++) {
+               ok = false;
+               if (argv[i][0] == '-' && argv[i][1] == '-') {
+                       /* long option */
+                       if (strcmp(argv[i], "--config") == 0) {
+                               if (i + 1 < argc) {
+                                       /* Ok, there's an parameter left */
+                                       strlcpy(NGIRCd_ConfFile, argv[i+1],
+                                               sizeof(NGIRCd_ConfFile));
+                                       /* next parameter */
+                                       i++; ok = true;
+                               }
+                       }
+                       if (strcmp(argv[i], "--configtest") == 0) {
+                               configtest = true;
+                               ok = true;
+                       }
 #ifdef DEBUG
-                       if( strcmp( argv[i], "--debug" ) == 0 )
-                       {
-                               NGIRCd_Debug = TRUE;
-                               ok = TRUE;
+                       if (strcmp(argv[i], "--debug") == 0) {
+                               NGIRCd_Debug = true;
+                               ok = true;
                        }
 #endif
-                       if( strcmp( argv[i], "--help" ) == 0 )
-                       {
-                               Show_Version( ); puts( "" );
-                               Show_Help( ); puts( "" );
-                               exit( 1 );
+                       if (strcmp(argv[i], "--help") == 0) {
+                               Show_Version();
+                               puts(""); Show_Help( ); puts( "" );
+                               exit(1);
                        }
-                       if( strcmp( argv[i], "--nodaemon" ) == 0 )
-                       {
-                               NGIRCd_NoDaemon = TRUE;
-                               ok = TRUE;
+                       if (strcmp(argv[i], "--nodaemon") == 0) {
+                               NGIRCd_NoDaemon = true;
+                               ok = true;
                        }
-                       if( strcmp( argv[i], "--passive" ) == 0 )
-                       {
-                               NGIRCd_Passive = TRUE;
-                               ok = TRUE;
+                       if (strcmp(argv[i], "--passive") == 0) {
+                               NGIRCd_Passive = true;
+                               ok = true;
                        }
 #ifdef SNIFFER
-                       if( strcmp( argv[i], "--sniffer" ) == 0 )
-                       {
-                               NGIRCd_Sniffer = TRUE;
-                               ok = TRUE;
+                       if (strcmp(argv[i], "--sniffer") == 0) {
+                               NGIRCd_Sniffer = true;
+                               ok = true;
                        }
 #endif
-                       if( strcmp( argv[i], "--version" ) == 0 )
-                       {
-                               Show_Version( );
-                               exit( 1 );
+                       if (strcmp(argv[i], "--version") == 0) {
+                               Show_Version();
+                               exit(1);
                        }
                }
-               else if(( argv[i][0] == '-' ) && ( argv[i][1] != '-' ))
-               {
-                       /* Kurze Option */
-                       
-                       for( n = 1; n < strlen( argv[i] ); n++ )
-                       {
-                               ok = FALSE;
+               else if(argv[i][0] == '-' && argv[i][1] != '-') {
+                       /* short option */
+                       for (n = 1; n < strlen(argv[i]); n++) {
+                               ok = false;
 #ifdef DEBUG
-                               if( argv[i][n] == 'd' )
-                               {
-                                       NGIRCd_Debug = TRUE;
-                                       ok = TRUE;
+                               if (argv[i][n] == 'd') {
+                                       NGIRCd_Debug = true;
+                                       ok = true;
                                }
 #endif
-                               if( argv[i][n] == 'n' )
-                               {
-                                       NGIRCd_NoDaemon = TRUE;
-                                       ok = TRUE;
+                               if (argv[i][n] == 'f') {
+                                       if (!argv[i][n+1] && i+1 < argc) {
+                                               /* Ok, next character is a blank */
+                                               strlcpy(NGIRCd_ConfFile, argv[i+1],
+                                                       sizeof(NGIRCd_ConfFile));
+
+                                               /* go to the following parameter */
+                                               i++;
+                                               n = strlen(argv[i]);
+                                               ok = true;
+                                       }
+                               }
+
+                               if (argv[i][n] == 'h') {
+                                       Show_Version();
+                                       puts(""); Show_Help(); puts("");
+                                       exit(1);
                                }
-                               if( argv[i][n] == 'p' )
-                               {
-                                       NGIRCd_Passive = TRUE;
-                                       ok = TRUE;
+
+                               if (argv[i][n] == 'n') {
+                                       NGIRCd_NoDaemon = true;
+                                       ok = true;
+                               }
+                               if (argv[i][n] == 'p') {
+                                       NGIRCd_Passive = true;
+                                       ok = true;
                                }
 #ifdef SNIFFER
-                               if( argv[i][n] == 's' )
-                               {
-                                       NGIRCd_Sniffer = TRUE;
-                                       ok = TRUE;
+                               if (argv[i][n] == 's') {
+                                       NGIRCd_Sniffer = true;
+                                       ok = true;
                                }
 #endif
+                               if (argv[i][n] == 't') {
+                                       configtest = true;
+                                       ok = true;
+                               }
 
-                               if( ! ok )
-                               {
-                                       printf( PACKAGE": invalid option \"-%c\"!\n", argv[i][n] );
-                                       puts( "Try \""PACKAGE" --help\" for more information." );
-                                       exit( 1 );
+                               if (argv[i][n] == 'V') {
+                                       Show_Version();
+                                       exit(1);
+                               }
+
+                               if (!ok) {
+                                       printf("%s: invalid option \"-%c\"!\n",
+                                              PACKAGE_NAME, argv[i][n]);
+                                       printf("Try \"%s --help\" for more information.\n",
+                                              PACKAGE_NAME);
+                                       exit(1);
                                }
                        }
 
                }
-               if( ! ok )
-               {
-                       printf( PACKAGE": invalid option \"%s\"!\n", argv[i] );
-                       puts( "Try \""PACKAGE" --help\" for more information." );
-                       exit( 1 );
+               if (!ok) {
+                       printf("%s: invalid option \"%s\"!\n",
+                              PACKAGE_NAME, argv[i]);
+                       printf("Try \"%s --help\" for more information.\n",
+                              PACKAGE_NAME);
+                       exit(1);
                }
        }
 
-       /* Debug-Level (fuer IRC-Befehl "VERSION") ermitteln */
-       strcpy( NGIRCd_DebugLevel, "" );
+       /* Debug level for "VERSION" command */
+       NGIRCd_DebugLevel[0] = '\0';
 #ifdef DEBUG
-       if( NGIRCd_Debug ) strcpy( NGIRCd_DebugLevel, "1" );
+       if (NGIRCd_Debug)
+               strcpy(NGIRCd_DebugLevel, "1");
 #endif
 #ifdef SNIFFER
-       if( NGIRCd_Sniffer ) strcpy( NGIRCd_DebugLevel, "2" );
+       if (NGIRCd_Sniffer) {
+               NGIRCd_Debug = true;
+               strcpy(NGIRCd_DebugLevel, "2");
+       }
 #endif
-       
-       while( ! NGIRCd_Quit )
-       {
-               /* In der Regel wird ein Sub-Prozess ge-fork()'t, der
-                * nicht mehr mit dem Terminal verbunden ist. Mit der
-                * Option "--nodaemon" kann dies (z.B. zum Debuggen)
-                * verhindert werden. */
-               if( ! NGIRCd_NoDaemon )
-               {
-                       /* Daemon im Hintergrund erzeugen */
-                       pid = fork( );
-                       if( pid > 0 )
-                       {
-                               /* "alter" Prozess */
-                               exit( 0 );
-                       }
-                       if( pid < 0 )
-                       {
-                               /* Fehler */
-                               printf( PACKAGE": Can't fork: %s!\nFatal error, exiting now ...", strerror( errno ));
-                               exit( 1 );
-                       }
 
-                       /* Child-Prozess initialisieren */
-                       setsid( );
-                       chdir( "/" );
+       if (configtest) {
+               Show_Version(); puts("");
+               exit(Conf_Test());
+       }
+
+       while (!NGIRCd_SignalQuit) {
+               /* Initialize global variables */
+               NGIRCd_Start = time(NULL);
+               (void)strftime(NGIRCd_StartStr, 64,
+                              "%a %b %d %Y at %H:%M:%S (%Z)",
+                              localtime(&NGIRCd_Start));
+
+               NGIRCd_SignalRestart = false;
+               NGIRCd_SignalQuit = false;
+
+               /* Initialize modules, part I */
+               Log_Init(!NGIRCd_NoDaemon);
+               Random_Init();
+               Conf_Init();
+               Log_ReInit();
+
+               /* Initialize the "main program": chroot environment, user and
+                * group ID, ... */
+               if (!NGIRCd_Init(NGIRCd_NoDaemon)) {
+                       Log(LOG_ALERT, "Fatal: Initialization failed, exiting!");
+                       exit(1);
                }
-       
-               /* Globale Variablen initialisieren */
-               NGIRCd_Start = time( NULL );
-               strftime( NGIRCd_StartStr, 64, "%a %b %d %Y at %H:%M:%S (%Z)", localtime( &NGIRCd_Start ));
-               NGIRCd_Restart = FALSE;
-               NGIRCd_Quit = FALSE;
-
-               /* Module initialisieren */
-               Log_Init( );
-               Conf_Init( );
-               Channel_Init( );
-               Client_Init( );
-               Conn_Init( );
-
-               /* Signal-Handler initialisieren */
-               Initialize_Signal_Handler( );
-
-               /* Listen-Ports initialisieren */
-               Initialize_Listen_Ports( );
-
-               /* Hauptschleife */
-               while( TRUE )
-               {
-                       if( NGIRCd_Quit || NGIRCd_Restart ) break;
-                       Conn_Handler( 5 );
+
+               /* Initialize modules, part II: these functions are eventually
+                * called with already dropped privileges ... */
+               Channel_Init();
+               Client_Init();
+               Conn_Init();
+               Class_Init();
+
+               if (!io_library_init(CONNECTION_POOL)) {
+                       Log(LOG_ALERT,
+                           "Fatal: Could not initialize IO routines: %s",
+                           strerror(errno));
+                       exit(1);
                }
 
-               /* Alles abmelden */
-               Conn_Exit( );
-               Client_Exit( );
-               Channel_Exit( );
-               Conf_Exit( );
-               Log_Exit( );
-       }
+               if (!Signals_Init()) {
+                       Log(LOG_ALERT,
+                           "Fatal: Could not set up signal handlers: %s",
+                           strerror(errno));
+                       exit(1);
+               }
 
-#ifndef DEBUG
-       /* aufraeumen */
-       if( unlink( ERROR_FILE ) != 0 ) Log( LOG_ERR, "Can't delete \""ERROR_FILE"\": %s", strerror( errno ));
+               /* Create protocol and server identification. The syntax
+                * used by ngIRCd in PASS commands and the known "extended
+                * flags" are described in doc/Protocol.txt. */
+#ifdef IRCPLUS
+               snprintf(NGIRCd_ProtoID, sizeof NGIRCd_ProtoID, "%s%s %s|%s:%s",
+                        PROTOVER, PROTOIRCPLUS, PACKAGE_NAME, PACKAGE_VERSION,
+                        IRCPLUSFLAGS);
+#ifdef ZLIB
+               strlcat(NGIRCd_ProtoID, "Z", sizeof NGIRCd_ProtoID);
 #endif
+               if (Conf_OperCanMode)
+                       strlcat(NGIRCd_ProtoID, "o", sizeof NGIRCd_ProtoID);
+#else /* IRCPLUS */
+               snprintf(NGIRCd_ProtoID, sizeof NGIRCd_ProtoID, "%s%s %s|%s",
+                        PROTOVER, PROTOIRC, PACKAGE_NAME, PACKAGE_VERSION);
+#endif /* IRCPLUS */
+               strlcat(NGIRCd_ProtoID, " P", sizeof NGIRCd_ProtoID);
+#ifdef ZLIB
+               strlcat(NGIRCd_ProtoID, "Z", sizeof NGIRCd_ProtoID);
+#endif
+               LogDebug("Protocol and server ID is \"%s\".", NGIRCd_ProtoID);
 
-       return 0;
-} /* main */
-
+               Channel_InitPredefined();
 
-GLOBAL CHAR *NGIRCd_Version( VOID )
-{
-       STATIC CHAR version[126];
+               if (Conn_InitListeners() < 1) {
+                       Log(LOG_ALERT,
+                           "Server isn't listening on a single port!" );
+                       Log(LOG_ALERT,
+                           "%s exiting due to fatal errors!", PACKAGE_NAME);
+                       Pidfile_Delete();
+                       exit(1);
+               }
 
-       sprintf( version, PACKAGE" version "VERSION"-%s", NGIRCd_VersionAddition( ));
-       return version;
-} /* NGIRCd_Version */
+               /* Main Run Loop */
+               Conn_Handler();
 
+               Conn_Exit();
+               Client_Exit();
+               Channel_Exit();
+               Class_Exit();
+               Log_Exit();
+               Signals_Exit();
+       }
+       Pidfile_Delete();
 
-GLOBAL CHAR *NGIRCd_VersionAddition( VOID )
-{
-       STATIC CHAR txt[64];
+       return 0;
+} /* main */
 
-       strcpy( txt, "" );
 
-#ifdef USE_SYSLOG
-       if( txt[0] ) strcat( txt, "+" );
-       strcat( txt, "SYSLOG" );
+/**
+ * Generate ngIRCd "version strings".
+ *
+ * The ngIRCd version information is generated once and then stored in the
+ * NGIRCd_Version and NGIRCd_VersionAddition string variables for further
+ * usage, for example by the IRC command "VERSION" and the --version command
+ * line switch.
+ */
+static void
+Fill_Version(void)
+{
+       NGIRCd_VersionAddition[0] = '\0';
+
+#ifdef ICONV
+       if (NGIRCd_VersionAddition[0])
+               strlcat(NGIRCd_VersionAddition, "+",
+                       sizeof NGIRCd_VersionAddition);
+       strlcat(NGIRCd_VersionAddition, "CHARCONV",
+               sizeof NGIRCd_VersionAddition);
+#endif
+#ifdef DEBUG
+       if (NGIRCd_VersionAddition[0])
+               strlcat(NGIRCd_VersionAddition, "+",
+                       sizeof NGIRCd_VersionAddition);
+       strlcat(NGIRCd_VersionAddition, "DEBUG",
+               sizeof NGIRCd_VersionAddition);
+#endif
+#ifdef IDENTAUTH
+       if (NGIRCd_VersionAddition[0])
+               strlcat(NGIRCd_VersionAddition, "+",
+                       sizeof NGIRCd_VersionAddition);
+       strlcat(NGIRCd_VersionAddition, "IDENT",
+               sizeof NGIRCd_VersionAddition);
+#endif
+#ifdef WANT_IPV6
+       if (NGIRCd_VersionAddition[0])
+               strlcat(NGIRCd_VersionAddition, "+",
+                       sizeof(NGIRCd_VersionAddition));
+       strlcat(NGIRCd_VersionAddition, "IPv6",
+               sizeof(NGIRCd_VersionAddition));
+#endif
+#ifdef IRCPLUS
+       if (NGIRCd_VersionAddition[0])
+               strlcat(NGIRCd_VersionAddition, "+",
+                       sizeof NGIRCd_VersionAddition);
+       strlcat(NGIRCd_VersionAddition, "IRCPLUS",
+               sizeof NGIRCd_VersionAddition);
+#endif
+#ifdef PAM
+       if (NGIRCd_VersionAddition[0])
+               strlcat(NGIRCd_VersionAddition, "+",
+                       sizeof NGIRCd_VersionAddition);
+       strlcat(NGIRCd_VersionAddition, "PAM",
+               sizeof NGIRCd_VersionAddition);
 #endif
 #ifdef STRICT_RFC
-       if( txt[0] ) strcat( txt, "+" );
-       strcat( txt, "RFC" );
+       if (NGIRCd_VersionAddition[0])
+               strlcat(NGIRCd_VersionAddition, "+",
+                       sizeof NGIRCd_VersionAddition);
+       strlcat(NGIRCd_VersionAddition, "RFC",
+               sizeof NGIRCd_VersionAddition);
+#endif
+#ifdef SNIFFER
+       if (NGIRCd_VersionAddition[0])
+               strlcat(NGIRCd_VersionAddition, "+",
+                       sizeof NGIRCd_VersionAddition);
+       strlcat(NGIRCd_VersionAddition, "SNIFFER",
+               sizeof NGIRCd_VersionAddition);
+#endif
+#ifdef SSL_SUPPORT
+       if (NGIRCd_VersionAddition[0])
+               strlcat(NGIRCd_VersionAddition, "+",
+                       sizeof NGIRCd_VersionAddition);
+       strlcat(NGIRCd_VersionAddition, "SSL",
+               sizeof NGIRCd_VersionAddition);
+#endif
+#ifdef SYSLOG
+       if (NGIRCd_VersionAddition[0])
+               strlcat(NGIRCd_VersionAddition, "+",
+                       sizeof NGIRCd_VersionAddition);
+       strlcat(NGIRCd_VersionAddition, "SYSLOG",
+               sizeof NGIRCd_VersionAddition);
+#endif
+#ifdef TCPWRAP
+       if (NGIRCd_VersionAddition[0])
+               strlcat(NGIRCd_VersionAddition, "+",
+                       sizeof NGIRCd_VersionAddition);
+       strlcat(NGIRCd_VersionAddition, "TCPWRAP",
+               sizeof NGIRCd_VersionAddition);
 #endif
+#ifdef ZLIB
+       if (NGIRCd_VersionAddition[0])
+               strlcat(NGIRCd_VersionAddition, "+",
+                       sizeof NGIRCd_VersionAddition);
+       strlcat(NGIRCd_VersionAddition, "ZLIB",
+               sizeof NGIRCd_VersionAddition);
+#endif
+       if (NGIRCd_VersionAddition[0])
+               strlcat(NGIRCd_VersionAddition, "-",
+                       sizeof(NGIRCd_VersionAddition));
+
+       strlcat(NGIRCd_VersionAddition, HOST_CPU,
+               sizeof(NGIRCd_VersionAddition));
+       strlcat(NGIRCd_VersionAddition, "/", sizeof(NGIRCd_VersionAddition));
+       strlcat(NGIRCd_VersionAddition, HOST_VENDOR,
+               sizeof(NGIRCd_VersionAddition));
+       strlcat(NGIRCd_VersionAddition, "/", sizeof(NGIRCd_VersionAddition));
+       strlcat(NGIRCd_VersionAddition, HOST_OS,
+               sizeof(NGIRCd_VersionAddition));
+
+       snprintf(NGIRCd_Version, sizeof NGIRCd_Version, "%s %s-%s",
+                PACKAGE_NAME, PACKAGE_VERSION, NGIRCd_VersionAddition);
+} /* Fill_Version */
+
+
+/**
+ * Display copyright and version information of ngIRCd on the console.
+ */
+static void
+Show_Version( void )
+{
+       puts( NGIRCd_Version );
+       puts( "Copyright (c)2001-2014 Alexander Barton (<alex@barton.de>) and Contributors." );
+       puts( "Homepage: <http://ngircd.barton.de/>\n" );
+       puts( "This is free software; see the source for copying conditions. There is NO" );
+       puts( "warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE." );
+} /* Show_Version */
+
+
+/**
+ * Display a short help text on the console.
+ * This help depends on the configuration of the executable and only shows
+ * options that are actually enabled.
+ */
+static void
+Show_Help( void )
+{
 #ifdef DEBUG
-       if( txt[0] ) strcat( txt, "+" );
-       strcat( txt, "DEBUG" );
+       puts( "  -d, --debug        log extra debug messages" );
 #endif
+       puts( "  -f, --config <f>   use file <f> as configuration file" );
+       puts( "  -n, --nodaemon     don't fork and don't detach from controlling terminal" );
+       puts( "  -p, --passive      disable automatic connections to other servers" );
 #ifdef SNIFFER
-       if( txt[0] ) strcat( txt, "+" );
-       strcat( txt, "SNIFFER" );
+       puts( "  -s, --sniffer      enable network sniffer and display all IRC traffic" );
 #endif
+       puts( "  -t, --configtest   read, validate and display configuration; then exit" );
+       puts( "  -V, --version      output version information and exit" );
+       puts( "  -h, --help         display this help and exit" );
+} /* Show_Help */
 
-       if( txt[0] ) strcat( txt, "-" );
-       strcat( txt, P_OSNAME"/"P_ARCHNAME );
 
-       return txt;
-} /* NGIRCd_VersionAddition */
+/**
+ * Delete the file containing the process ID (PID).
+ */
+static void
+Pidfile_Delete( void )
+{
+       /* Pidfile configured? */
+       if( ! Conf_PidFile[0] ) return;
 
+#ifdef DEBUG
+       Log( LOG_DEBUG, "Removing PID file (%s) ...", Conf_PidFile );
+#endif
 
-LOCAL VOID Initialize_Signal_Handler( VOID )
-{
-       /* Signal-Handler initialisieren: einige Signale
-        * werden ignoriert, andere speziell behandelt. */
+       if( unlink( Conf_PidFile ))
+               Log( LOG_ERR, "Error unlinking PID file (%s): %s", Conf_PidFile, strerror( errno ));
+} /* Pidfile_Delete */
 
-#ifdef HAVE_SIGACTION
-       /* sigaction() ist vorhanden */
 
-       struct sigaction saction;
+/**
+ * Create the file containing the process ID of ngIRCd ("PID file").
+ *
+ * @param pid  The process ID to be stored in this file.
+ */
+static void
+Pidfile_Create(pid_t pid)
+{
+       int pidfd;
+       char pidbuf[64];
+       int len;
 
-       /* Signal-Struktur initialisieren */
-       memset( &saction, 0, sizeof( saction ));
-       saction.sa_handler = Signal_Handler;
-#ifdef SA_RESTART
-       saction.sa_flags |= SA_RESTART;
+       /* Pidfile configured? */
+       if( ! Conf_PidFile[0] ) return;
+
+#ifdef DEBUG
+       Log( LOG_DEBUG, "Creating PID file (%s) ...", Conf_PidFile );
 #endif
-#ifdef SA_NOCLDWAIT
-       saction.sa_flags |= SA_NOCLDWAIT;
+
+       pidfd = open( Conf_PidFile, O_RDWR|O_CREAT|O_EXCL, S_IRUSR|S_IWUSR|S_IRGRP|S_IROTH);
+       if ( pidfd < 0 ) {
+               Log( LOG_ERR, "Error writing PID file (%s): %s", Conf_PidFile, strerror( errno ));
+               return;
+       }
+
+       len = snprintf(pidbuf, sizeof pidbuf, "%ld\n", (long)pid);
+       if (len < 0 || len >= (int)sizeof pidbuf) {
+               Log(LOG_ERR, "Error converting process ID!");
+               close(pidfd);
+               return;
+       }
+       
+       if (write(pidfd, pidbuf, (size_t)len) != (ssize_t)len)
+               Log(LOG_ERR, "Can't write PID file (%s): %s!", Conf_PidFile,
+                   strerror(errno));
+
+       if (close(pidfd) != 0)
+               Log(LOG_ERR, "Error closing PID file (%s): %s!", Conf_PidFile,
+                   strerror(errno));
+} /* Pidfile_Create */
+
+
+/**
+ * Redirect stdin, stdout and stderr to appropriate file handles.
+ *
+ * @param fd   The file handle stdin, stdout and stderr should be redirected to.
+ */
+static void
+Setup_FDStreams(int fd)
+{
+       if (fd < 0)
+               return;
+
+       fflush(stdout);
+       fflush(stderr);
+
+       /* Create new stdin(0), stdout(1) and stderr(2) descriptors */
+       dup2( fd, 0 ); dup2( fd, 1 ); dup2( fd, 2 );
+} /* Setup_FDStreams */
+
+
+#if !defined(SINGLE_USER_OS)
+
+/**
+ * Get user and group ID of unprivileged "nobody" user.
+ *
+ * @param uid  User ID
+ * @param gid  Group ID
+ * @return     true on success.
+ */
+static bool
+NGIRCd_getNobodyID(uid_t *uid, gid_t *gid )
+{
+       struct passwd *pwd;
+
+#ifdef __CYGWIN__
+       /* Cygwin kludge.
+        * It can return EINVAL instead of EPERM
+        * so, if we are already unprivileged,
+        * use id of current user.
+        */
+       if (geteuid() && getuid()) {
+               *uid = getuid();
+               *gid = getgid();
+               return true;
+       }
 #endif
 
-       /* Signal-Handler einhaengen */
-       sigaction( SIGINT, &saction, NULL );
-       sigaction( SIGQUIT, &saction, NULL );
-       sigaction( SIGTERM, &saction, NULL);
-       sigaction( SIGHUP, &saction, NULL);
-       sigaction( SIGCHLD, &saction, NULL);
+       pwd = getpwnam("nobody");
+       if (!pwd)
+               return false;
 
-       /* einige Signale ignorieren */
-       saction.sa_handler = SIG_IGN;
-       sigaction( SIGPIPE, &saction, NULL );
-#else
-       /* kein sigaction() vorhanden */
+       if (!pwd->pw_uid || !pwd->pw_gid)
+               return false;
+
+       *uid = pwd->pw_uid;
+       *gid = pwd->pw_gid;
+       endpwent();
 
-       /* Signal-Handler einhaengen */
-       signal( SIGINT, Signal_Handler );
-       signal( SIGQUIT, Signal_Handler );
-       signal( SIGTERM, Signal_Handler );
-       signal( SIGHUP, Signal_Handler );
-       signal( SIGCHLD, Signal_Handler );
+       return true;
+} /* NGIRCd_getNobodyID */
 
-       /* einige Signale ignorieren */
-       signal( SIGPIPE, SIG_IGN );
 #endif
-} /* Initialize_Signal_Handler */
 
 
-LOCAL VOID Signal_Handler( INT Signal )
+#ifdef HAVE_ARC4RANDOM
+static void
+Random_Init(void)
 {
-       /* Signal-Handler. Dieser wird aufgerufen, wenn eines der Signale eintrifft,
-        * fuer das wir uns registriert haben (vgl. Initialize_Signal_Handler). Die
-        * Nummer des eingetroffenen Signals wird der Funktion uebergeben. */
-
-       switch( Signal )
-       {
-               case SIGTERM:
-               case SIGINT:
-               case SIGQUIT:
-                       /* wir soll(t)en uns wohl beenden ... */
-                       if( Signal == SIGTERM ) Log( LOG_WARNING, "Got TERM signal, terminating now ..." );
-                       else if( Signal == SIGINT ) Log( LOG_WARNING, "Got INT signal, terminating now ..." );
-                       else if( Signal == SIGQUIT ) Log( LOG_WARNING, "Got QUIT signal, terminating now ..." );
-                       NGIRCd_Quit = TRUE;
-                       break;
-               case SIGHUP:
-                       /* neu starten */
-                       Log( LOG_WARNING, "Got HUP signal, restarting now ..." );
-                       NGIRCd_Restart = TRUE;
-                       break;
-               case SIGCHLD:
-                       /* Child-Prozess wurde beendet. Zombies vermeiden: */
-                       while( waitpid( -1, NULL, WNOHANG ) > 0);
-                       break;
-               default:
-                       /* unbekanntes bzw. unbehandeltes Signal */
-                       Log( LOG_NOTICE, "Got signal %d! Ignored.", Signal );
-       }
-} /* Signal_Handler */
 
+}
+#else
+static bool
+Random_Init_Kern(const char *file)
+{
+       unsigned int seed;
+       bool ret = false;
+       int fd = open(file, O_RDONLY);
+       if (fd >= 0) {
+               if (read(fd, &seed, sizeof(seed)) == sizeof(seed))
+                       ret = true;
+               close(fd);
+               srand(seed);
+       }
+       return ret;
+}
 
-LOCAL VOID Initialize_Listen_Ports( VOID )
+/**
+ * Initialize libc rand(3) number generator
+ */
+static void
+Random_Init(void)
 {
-       /* Ports, auf denen der Server Verbindungen entgegennehmen
-        * soll, initialisieren */
-       
-       INT created, i;
+       if (Random_Init_Kern("/dev/urandom"))
+               return;
+       if (Random_Init_Kern("/dev/random"))
+               return;
+       if (Random_Init_Kern("/dev/arandom"))
+               return;
+       srand(rand() ^ (unsigned)getpid() ^ (unsigned)time(NULL));
+}
+#endif
+
 
-       created = 0;
-       for( i = 0; i < Conf_ListenPorts_Count; i++ )
-       {
-               if( Conn_NewListener( Conf_ListenPorts[i] )) created++;
-               else Log( LOG_ERR, "Can't listen on port %d!", Conf_ListenPorts[i] );
+/**
+ * Initialize ngIRCd daemon.
+ *
+ * @param NGIRCd_NoDaemon Set to true if ngIRCd should run in the
+ *             foreground (and not as a daemon).
+ * @return true on success.
+ */
+static bool
+NGIRCd_Init(bool NGIRCd_NoDaemon)
+{
+       static bool initialized;
+       bool chrooted = false;
+       struct passwd *pwd;
+       struct group *grp;
+       int real_errno, fd = -1;
+       pid_t pid;
+
+       if (initialized)
+               return true;
+
+       if (!NGIRCd_NoDaemon) {
+               /* open /dev/null before chroot() */
+               fd = open( "/dev/null", O_RDWR);
+               if (fd < 0)
+                       Log(LOG_WARNING, "Could not open /dev/null: %s",
+                           strerror(errno));
        }
 
-       if( created < 1 )
-       {
-               Log( LOG_ALERT, "Server isn't listening on a single port!" );
-               Log( LOG_ALERT, PACKAGE" exiting due to fatal errors!" );
-               exit( 1 );
+       /* SSL initialization */
+       if (!ConnSSL_InitLibrary()) {
+               Log(LOG_ERR, "Error during SSL initialization!");
+               goto out;
        }
-} /* Initialize_Listen_Ports */
 
+       /* Change root */
+       if (Conf_Chroot[0]) {
+               if (chdir(Conf_Chroot) != 0) {
+                       Log(LOG_ERR, "Can't chdir() in ChrootDir (%s): %s!",
+                           Conf_Chroot, strerror(errno));
+                       goto out;
+               }
 
-LOCAL VOID Show_Version( VOID )
-{
-       puts( NGIRCd_Version( ));
-       puts( "Copyright (c)2001,2002 by Alexander Barton (alex@barton.de).\n" );
-       puts( "This is free software; see the source for copying conditions. There is NO" );
-       puts( "warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE." );
-} /* Show_Version */
+               if (chroot(Conf_Chroot) != 0) {
+                       Log(LOG_ERR,
+                           "Can't change root directory to \"%s\": %s!",
+                           Conf_Chroot, strerror(errno));
+                       goto out;
+               } else {
+                       chrooted = true;
+                       Log(LOG_INFO,
+                           "Changed root and working directory to \"%s\".",
+                           Conf_Chroot);
+               }
+       }
 
+#if !defined(SINGLE_USER_OS)
+       /* Check user ID */
+       if (Conf_UID == 0) {
+               pwd = getpwuid(0);
+               Log(LOG_INFO,
+                   "ServerUID must not be %s(0), using \"nobody\" instead.",
+                   pwd ? pwd->pw_name : "?");
+               if (!NGIRCd_getNobodyID(&Conf_UID, &Conf_GID)) {
+                       Log(LOG_WARNING,
+                           "Could not get user/group ID of user \"nobody\": %s",
+                           errno ? strerror(errno) : "not found" );
+                       goto out;
+               }
+       }
 
-LOCAL VOID Show_Help( VOID )
-{
-       puts( "Compile-time defaults:\n" );
-       puts( "  - configuration: "CONFIG_FILE );
-       puts( "  - MOTD file: "MOTD_FILE );
-       puts( "  - server error log: "ERROR_FILE"\n" );
-       puts( "Run-time options:\n" );
-#ifdef DEBUG
-       puts( "  -d, --debug       log extra debug messages" );
+       /* Change group ID */
+       if (getgid() != Conf_GID) {
+               if (setgid(Conf_GID) != 0) {
+                       real_errno = errno;
+                       grp = getgrgid(Conf_GID);
+                       Log(LOG_ERR, "Can't change group ID to %s(%u): %s!",
+                           grp ? grp->gr_name : "?", Conf_GID,
+                           strerror(real_errno));
+                       if (real_errno != EPERM) 
+                               goto out;
+               }
+#ifdef HAVE_SETGROUPS
+               if (setgroups(0, NULL) != 0) {
+                       real_errno = errno;
+                       Log(LOG_ERR, "Can't drop supplementary group IDs: %s!",
+                                       strerror(errno));
+                       if (real_errno != EPERM)
+                               goto out;
+               }
+#else
+               Log(LOG_WARNING,
+                   "Can't drop supplementary group IDs: setgroups(3) missing!");
 #endif
-        puts( "  -n, --nodaemon    don't fork and don't detatch from controlling terminal" );
-        puts( "  -p, --passive     disable automatic connections to other servers" );
-#ifdef SNIFFER
-       puts( "  -s, --sniffer     enable network sniffer and display all IRC traffic" );
+       }
 #endif
-       puts( "      --version     output version information and exit" );
-       puts( "      --help        display this help and exit" );
-} /* Show_Help */
+
+       /* Change user ID */
+       if (getuid() != Conf_UID) {
+               if (setuid(Conf_UID) != 0) {
+                       real_errno = errno;
+                       pwd = getpwuid(Conf_UID);
+                       Log(LOG_ERR, "Can't change user ID to %s(%u): %s!",
+                           pwd ? pwd->pw_name : "?", Conf_UID,
+                           strerror(real_errno));
+                       if (real_errno != EPERM)
+                               goto out;
+               }
+       }
+
+       initialized = true;
+
+       /* Normally a child process is forked which isn't any longer
+        * connected to ther controlling terminal. Use "--nodaemon"
+        * to disable this "daemon mode" (useful for debugging). */
+       if (!NGIRCd_NoDaemon) {
+               pid = fork();
+               if (pid > 0) {
+                       /* "Old" process: exit. */
+                       exit(0);
+               }
+               if (pid < 0) {
+                       /* Error!? */
+                       fprintf(stderr,
+                               "%s: Can't fork: %s!\nFatal error, exiting now ...\n",
+                               PACKAGE_NAME, strerror(errno));
+                       exit(1);
+               }
+
+               /* New child process */
+#ifdef HAVE_SETSID
+               (void)setsid();
+#else
+               setpgrp(0, getpid());
+#endif
+               if (chdir("/") != 0)
+                       Log(LOG_ERR, "Can't change directory to '/': %s!",
+                                    strerror(errno));
+
+               /* Detach stdin, stdout and stderr */
+               Setup_FDStreams(fd);
+               if (fd > 2)
+                       close(fd);
+       }
+       pid = getpid();
+
+       Pidfile_Create(pid);
+
+       /* Check UID/GID we are running as, can be different from values
+        * configured (e. g. if we were already started with a UID>0. */
+       Conf_UID = getuid();
+       Conf_GID = getgid();
+
+       pwd = getpwuid(Conf_UID);
+       grp = getgrgid(Conf_GID);
+
+       Log(LOG_INFO, "Running as user %s(%ld), group %s(%ld), with PID %ld.",
+           pwd ? pwd->pw_name : "unknown", (long)Conf_UID,
+           grp ? grp->gr_name : "unknown", (long)Conf_GID, (long)pid);
+
+       if (chrooted) {
+               Log(LOG_INFO, "Running with root directory \"%s\".",
+                   Conf_Chroot );
+               return true;
+       } else
+               Log(LOG_INFO, "Not running with changed root directory.");
+
+       /* Change working directory to home directory of the user we are
+        * running as (only when running in daemon mode and not in chroot) */
+
+       if (NGIRCd_NoDaemon)
+               return true;
+
+       if (pwd) {
+               if (chdir(pwd->pw_dir) == 0)
+                       Log(LOG_DEBUG,
+                           "Changed working directory to \"%s\" ...",
+                           pwd->pw_dir);
+               else
+                       Log(LOG_ERR,
+                           "Can't change working directory to \"%s\": %s!",
+                           pwd->pw_dir, strerror(errno));
+       } else
+               Log(LOG_ERR, "Can't get user informaton for UID %d!?", Conf_UID);
+
+       return true;
+ out:
+       if (fd > 2)
+               close(fd);
+       return false;
+} /* NGIRCd_Init */
 
 
 /* -eof- */