]> git.saurik.com Git - apple/mdnsresponder.git/blobdiff - mDNSShared/uds_daemon.c
mDNSResponder-161.1.tar.gz
[apple/mdnsresponder.git] / mDNSShared / uds_daemon.c
index 3a0842f5bc0e4cc1abb1f070d1173ff0e341af5f..604f39b7b094217e20981b2c540f19bf75663e24 100644 (file)
  *
  * Copyright (c) 2003-2006 Apple Computer, Inc. All rights reserved.
  *
- * @APPLE_LICENSE_HEADER_START@
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
  * 
- * This file contains Original Code and/or Modifications of Original Code
- * as defined in and that are subject to the Apple Public Source License
- * Version 2.0 (the 'License'). You may not use this file except in
- * compliance with the License. Please obtain a copy of the License at
- * http://www.opensource.apple.com/apsl/ and read it before using this
- * file.
+ *     http://www.apache.org/licenses/LICENSE-2.0
  * 
- * The Original Code and all software distributed under the License are
- * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
- * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
- * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
- * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
- * Please see the License for the specific language governing rights and
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
  * limitations under the License.
- * 
- * @APPLE_LICENSE_HEADER_END@
 
-    Change History (most recent first):
+       Change History (most recent first):
 
 $Log: uds_daemon.c,v $
-Revision 1.199.2.1  2007/01/06 03:22:03  cheshire
-<rdar://problem/4912058> Crash at resolve_result_callback + 192
-
-Revision 1.199  2006/06/28 08:53:39  cheshire
-Added (commented out) debugging messages
-
-Revision 1.198  2006/06/27 20:16:07  cheshire
-Fix code layout
-
-Revision 1.197  2006/05/18 01:32:35  cheshire
-<rdar://problem/4472706> iChat: Lost connection with Bonjour
-(mDNSResponder insufficiently defensive against malformed browsing PTR responses)
-
-Revision 1.196  2006/05/05 07:07:13  cheshire
-<rdar://problem/4538206> mDNSResponder fails when UDS reads deliver partial data
-
-Revision 1.195  2006/04/25 20:56:28  mkrochma
-Added comment about previous checkin
-
-Revision 1.194  2006/04/25 18:29:36  mkrochma
-Workaround for warning: unused variable 'status' when building mDNSPosix
-
-Revision 1.193  2006/03/19 17:14:38  cheshire
-<rdar://problem/4483117> Need faster purging of stale records
-read_rr_from_ipc_msg was not setting namehash and rdatahash
-
-Revision 1.192  2006/03/18 20:58:32  cheshire
-Misplaced curly brace
-
-Revision 1.191  2006/03/10 22:19:43  cheshire
-Update debugging message in resolve_result_callback() to indicate whether event is ADD or RMV
-
-Revision 1.190  2006/03/10 21:56:12  cheshire
-<rdar://problem/4111464> After record update, old record sometimes remains in cache
-When service TXT and SRV record both change, clients with active resolve calls get *two* callbacks, one
-when the TXT data changes, and then immediately afterwards a second callback with the new port number
-This change suppresses the first unneccessary (and confusing) callback
+Revision 1.366  2007/10/10 00:48:54  cheshire
+<rdar://problem/5526379> Daemon spins in an infinite loop when it doesn't get the control message it's expecting
 
-Revision 1.189  2006/01/06 00:56:31  cheshire
-<rdar://problem/4400573> Should remove PID file on exit
+Revision 1.365  2007/10/06 03:25:23  cheshire
+<rdar://problem/5525267> MacBuddy exits abnormally when clicking "Continue" in AppleConnect pane
 
-Revision 1.188  2005/10/11 22:15:03  cheshire
-<rdar://problem/4296042> Add memory corruption safeguards to uds_daemon.c
-Only compile uds_validatelists() when building for Mac OS X
+Revision 1.364  2007/10/06 03:20:16  cheshire
+Improved LogOperation debugging messages
 
-Revision 1.187  2005/10/11 20:30:27  cheshire
-<rdar://problem/4296042> Add memory corruption safeguards to uds_daemon.c
+Revision 1.363  2007/10/05 23:24:52  cheshire
+Improved LogOperation messages about separate error return socket
 
-Revision 1.186  2005/09/12 07:11:53  herscher
-<rdar://problem/4248878> Lazily call RegisterSearchDomains to workaround crashes of several routers. This code is conditionally compiled, and currently is only enabled on Windows platforms.
+Revision 1.362  2007/10/05 22:11:58  cheshire
+Improved "send_msg ERROR" debugging message
 
-Revision 1.185  2005/07/29 00:55:10  ksekar
-Removed validation check in uds_validatelists which generated false alarms
+Revision 1.361  2007/10/04 20:45:18  cheshire
+<rdar://problem/5518381> Race condition in kDNSServiceFlagsShareConnection-mode call handling
 
-Revision 1.184  2005/07/04 22:40:26  cheshire
-Additional debugging code to help catch memory corruption
+Revision 1.360  2007/10/01 23:24:46  cheshire
+SIGINFO output was mislabeling mDNSInterface_Any queries as unicast queries
 
-Revision 1.183  2005/06/13 22:39:11  cheshire
-<rdar://problem/4144870> Missing return statement in handle_enum_request() error handling
+Revision 1.359  2007/09/30 00:09:27  cheshire
+<rdar://problem/5492315> Pass socket fd via SCM_RIGHTS sendmsg instead of using named UDS in the filesystem
 
-Revision 1.182  2005/03/21 00:39:31  shersche
-<rdar://problem/4021486> Fix build warnings on Win32 platform
+Revision 1.358  2007/09/29 20:08:06  cheshire
+Fixed typo in comment
 
-Revision 1.181  2005/03/20 20:21:32  shersche
-<rdar://problem/4056827> mDNSResponder crashes when incorrect interface index is passed to DNSServiceRegister()
-Text record length and data parameters must be initialized to 0 and NULL to ensure that the service request
-object is cleaned up correctly when encountering an interface index error.
+Revision 1.357  2007/09/27 22:10:04  cheshire
+Add LogOperation line for DNSServiceRegisterRecord callbacks
 
-Revision 1.180  2005/03/10 00:13:12  cheshire
-<rdar://problem/4043098> DNSServiceBrowse no longer returning error codes for invalid types
-In handle_browse_request(), mStatus err was being set correctly if an error occurred,
-but the end of the function returned mStatus_NoError intead of err.
+Revision 1.356  2007/09/26 21:29:30  cheshire
+Improved question list SIGINFO output
 
-Revision 1.179  2005/03/04 02:47:26  ksekar
-<rdar://problem/4026393> SCPreference domains disappear from enumeration when moving out from firewall
+Revision 1.355  2007/09/26 01:54:34  mcguire
+Debugging: In SIGINFO output, show ClientTunnel query interval, which is how we determine whether a query is still active
 
-Revision 1.178  2005/02/25 19:35:38  ksekar
-<rdar://problem/4023750> Non-local empty string registration failures should not return errors to caller
+Revision 1.354  2007/09/26 01:26:31  cheshire
+<rdar://problem/5501567> BTMM: mDNSResponder crashes in free_service_instance enabling/disabling BTMM
+Need to call SendServiceRemovalNotification *before* backpointer is cleared
 
-Revision 1.177  2005/02/25 03:05:41  cheshire
-Change "broken pipe" message to debugf()
+Revision 1.353  2007/09/25 20:46:33  cheshire
+Include DNSServiceRegisterRecord operations in SIGINFO output
 
-Revision 1.176  2005/02/24 18:44:45  ksekar
-<rdar://problem/4018516> Printer Sharing does not get re-registered with wide-area
+Revision 1.352  2007/09/25 20:23:40  cheshire
+<rdar://problem/5501567> BTMM: mDNSResponder crashes in free_service_instance enabling/disabling BTMM
+Need to clear si->request backpointer before calling mDNS_DeregisterService(&mDNSStorage, &si->srs);
 
-Revision 1.175  2005/02/21 21:31:25  ksekar
-<rdar://problem/4015162> changed LogMsg to debugf
+Revision 1.351  2007/09/25 18:20:34  cheshire
+Changed name of "free_service_instance" to more accurate "unlink_and_free_service_instance"
 
-Revision 1.174  2005/02/20 01:41:17  cheshire
-Fix compiler signed/unsigned warning
+Revision 1.350  2007/09/24 23:54:52  mcguire
+Additional list checking in uds_validatelists()
 
-Revision 1.173  2005/02/18 01:26:42  cheshire
-<rdar://problem/4012162> "Could not write data to client after 60 seconds" message could be more helpful
-Log additional information about failed client
+Revision 1.349  2007/09/24 06:01:00  cheshire
+Debugging: In SIGINFO output, show NAT Traversal time values in seconds rather than platform ticks
 
-Revision 1.172  2005/02/18 00:58:35  cheshire
-<rdar://problem/4012162> "Could not write data to client after 60 seconds" message could be more helpful
+Revision 1.348  2007/09/24 05:02:41  cheshire
+Debugging: In SIGINFO output, indicate explicitly when a given section is empty
 
-Revision 1.171  2005/02/18 00:43:12  cheshire
-<rdar://problem/4010245> mDNSResponder should auto-truncate service names that are too long
+Revision 1.347  2007/09/21 02:04:33  cheshire
+<rdar://problem/5440831> BTMM: mDNSResponder crashes in free_service_instance enabling/disabling BTMM
 
-Revision 1.170  2005/02/16 01:15:02  cheshire
-Improve LogOperation() debugging messages for DNSServiceBrowse and DNSServiceRegister
+Revision 1.346  2007/09/19 22:47:25  cheshire
+<rdar://problem/5490182> Memory corruption freeing a "no such service" service record
 
-Revision 1.169  2005/02/08 01:57:14  cheshire
-More detailed error reporting in udsserver_init()
+Revision 1.345  2007/09/19 20:32:29  cheshire
+<rdar://problem/5482322> BTMM: Don't advertise SMB with BTMM because it doesn't support IPv6
 
-Revision 1.168  2005/02/03 00:44:37  cheshire
-<rdar://problem/3986663> DNSServiceUpdateRecord returns kDNSServiceErr_Invalid when rdlen=0, rdata=NULL
+Revision 1.344  2007/09/19 19:27:50  cheshire
+<rdar://problem/5492182> Improved diagnostics when daemon can't connect to error return path socket
 
-Revision 1.167  2005/02/02 02:19:32  cheshire
-Add comment explaining why unlink(MDNS_UDS_SERVERPATH); fails
+Revision 1.343  2007/09/18 21:42:30  cheshire
+To reduce programming mistakes, renamed ExtPort to RequestedPort
 
-Revision 1.166  2005/02/01 19:58:52  ksekar
-Shortened cryptic "broken pipe" syslog message
+Revision 1.342  2007/09/14 22:38:20  cheshire
+Additional list checking in uds_validatelists()
 
-Revision 1.165  2005/02/01 19:56:47  ksekar
-Moved LogMsg from daemon.c to uds_daemon.c, cleaned up wording
+Revision 1.341  2007/09/13 00:16:43  cheshire
+<rdar://problem/5468706> Miscellaneous NAT Traversal improvements
 
-Revision 1.164  2005/01/28 06:07:55  cheshire
-Don't use deliver_error() from within handle_regrecord_request()
+Revision 1.340  2007/09/12 23:03:08  cheshire
+<rdar://problem/5476978> DNSServiceNATPortMappingCreate callback not giving correct interface index
 
-Revision 1.163  2005/01/28 01:39:16  cheshire
-Include file descriptor number in "broken pipe" message
+Revision 1.339  2007/09/12 19:22:21  cheshire
+Variable renaming in preparation for upcoming fixes e.g. priv/pub renamed to intport/extport
+Made NAT Traversal packet handlers take typed data instead of anonymous "mDNSu8 *" byte pointers
 
-Revision 1.162  2005/01/27 23:59:20  cheshire
-Remove extraneous LogMsg
+Revision 1.338  2007/09/12 01:22:13  cheshire
+Improve validatelists() checking to detect when 'next' pointer gets smashed to ~0
 
-Revision 1.161  2005/01/27 22:57:56  cheshire
-Fix compile errors on gcc4
+Revision 1.337  2007/09/07 23:05:04  cheshire
+Add display of client_context field in handle_cancel_request() LogOperation message
+While loop was checking client_context.u32[2] instead of client_context.u32[1]
 
-Revision 1.160  2005/01/27 20:52:11  cheshire
-<rdar://problem/3972566> mDNSResponder leaks sockets for add/update/remove record calls
+Revision 1.336  2007/09/07 20:56:03  cheshire
+Renamed uint32_t field in client_context_t from "ptr64" to more accurate name "u32"
 
-Revision 1.159  2005/01/27 01:45:25  cheshire
-<rdar://problem/3976147> mDNSResponder should never call exit(1);
+Revision 1.335  2007/09/05 22:25:01  vazquez
+<rdar://problem/5400521> update_record mDNSResponder leak
 
-Revision 1.158  2005/01/25 17:28:07  ksekar
-<rdar://problem/3971467> Should not return "local" twice for domain enumeration
+Revision 1.334  2007/09/05 20:43:57  cheshire
+Added LogOperation message showing fd of socket listening for incoming Unix Domain Socket client requests
 
-Revision 1.157  2005/01/21 02:20:39  cheshire
-Fix mistake in LogOperation() format string
+Revision 1.333  2007/08/28 23:32:35  cheshire
+Added LogOperation messages for DNSServiceNATPortMappingCreate() operations
 
-Revision 1.156  2005/01/19 19:15:36  ksekar
-Refinement to <rdar://problem/3954575> - Simplify mDNS_PurgeResultsForDomain logic and move into daemon layer
+Revision 1.332  2007/08/27 22:59:31  cheshire
+Show reg_index in DNSServiceRegisterRecord/DNSServiceRemoveRecord messages
 
-Revision 1.155  2005/01/19 03:00:47  cheshire
-Show Add/Rmv in DNSServiceBrowse LogOperation() message
+Revision 1.331  2007/08/27 20:29:57  cheshire
+Added SIGINFO listing of TunnelClients
 
-Revision 1.154  2005/01/15 00:56:42  ksekar
-<rdar://problem/3954575> Unicast services don't disappear when logging
-out of VPN
+Revision 1.330  2007/08/24 23:46:50  cheshire
+Added debugging messages and SIGINFO listing of DomainAuthInfo records
 
-Revision 1.153  2005/01/14 18:44:28  ksekar
-<rdar://problem/3954609> mDNSResponder is crashing when changing domains
+Revision 1.329  2007/08/18 01:02:04  mcguire
+<rdar://problem/5415593> No Bonjour services are getting registered at boot
 
-Revision 1.152  2005/01/13 17:16:38  ksekar
-Back out checkin 1.150 - correct fix is on clientstub side
+Revision 1.328  2007/08/15 20:18:28  vazquez
+<rdar://problem/5400521> update_record mDNSResponder leak
+Make sure we free all ExtraResourceRecords
 
-Revision 1.151  2005/01/11 21:06:29  ksekar
-Changed now-benign LogMsg to debugf
+Revision 1.327  2007/08/08 22:34:59  mcguire
+<rdar://problem/5197869> Security: Run mDNSResponder as user id mdnsresponder instead of root
 
-Revision 1.150  2005/01/07 23:59:15  ksekar
-<rdar://problem/3942900> dnd-sd shows the wrong port numbers
+Revision 1.326  2007/08/01 16:09:14  cheshire
+Removed unused NATTraversalInfo substructure from AuthRecord; reduced structure sizecheck values accordingly
 
-Revision 1.149  2004/12/20 23:20:35  cheshire
-<rdar://problem/3928361> mDNSResponder crashes repeatedly when printer sharing is enabled
-Make sure to call mDNS_SetupResourceRecord() for all newly created AuthRecords
+Revision 1.325  2007/07/31 21:29:41  cheshire
+<rdar://problem/5372207> System Default registration domain(s) not listed in Domain Enumeration ("dns-sd -E")
 
-Revision 1.148  2004/12/20 20:37:35  cheshire
-AllowRemoteQuery not set for the extras in a ServiceRecordSet
+Revision 1.324  2007/07/31 01:56:21  cheshire
+Corrected function name in log message
 
-Revision 1.147  2004/12/20 00:15:41  cheshire
-Include client file descriptor numbers in udsserver_info() output
+Revision 1.323  2007/07/27 23:57:23  cheshire
+Added compile-time structure size checks
 
-Revision 1.146  2004/12/17 05:25:47  cheshire
-<rdar://problem/3925163> Shorten DNS-SD queries to avoid NAT bugs
+Revision 1.322  2007/07/27 19:37:19  cheshire
+Moved AutomaticBrowseDomainQ into main mDNS object
 
-Revision 1.145  2004/12/16 21:39:46  cheshire
-Include CacheGroup objects in CacheUsed count
+Revision 1.321  2007/07/27 19:30:41  cheshire
+Changed mDNSQuestionCallback parameter from mDNSBool to QC_result,
+to properly reflect tri-state nature of the possible responses
 
-Revision 1.144  2004/12/16 21:27:38  ksekar
-Fixed build failures when compiled with verbose debugging messages
+Revision 1.320  2007/07/27 00:48:27  cheshire
+<rdar://problem/4700198> BTMM: Services should only get registered in .Mac domain of current user
+<rdar://problem/4731180> BTMM: Only browse in the current user's .Mac domain by default
 
-Revision 1.143  2004/12/16 20:13:02  cheshire
-<rdar://problem/3324626> Cache memory management improvements
+Revision 1.319  2007/07/24 17:23:33  cheshire
+<rdar://problem/5357133> Add list validation checks for debugging
 
-Revision 1.142  2004/12/16 08:07:33  shersche
-Fix compiler error (mixed declarations and code) on Windows
+Revision 1.318  2007/07/23 23:09:51  cheshire
+<rdar://problem/5351997> Reject oversized client requests
 
-Revision 1.141  2004/12/16 01:56:21  cheshire
-Improve DNSServiceEnumerateDomains syslog message
+Revision 1.317  2007/07/23 22:24:47  cheshire
+<rdar://problem/5352299> Make mDNSResponder more defensive against malicious local clients
+Additional refinements
 
-Revision 1.140  2004/12/14 03:02:10  ksekar
-<rdar://problem/3919016> Rare race condition can cause crash
+Revision 1.316  2007/07/23 22:12:53  cheshire
+<rdar://problem/5352299> Make mDNSResponder more defensive against malicious local clients
 
-Revision 1.139  2004/12/13 21:18:45  ksekar
-Include uDNS registrations in CountPeerRegistrations
+Revision 1.315  2007/07/21 01:36:13  cheshire
+Need to also add ".local" as automatic browsing domain
 
-Revision 1.138  2004/12/13 18:23:18  ksekar
-<rdar://problem/3915805> mDNSResponder error when quitting iChat -
-don't close sockets delivering errors to blocked clients
+Revision 1.314  2007/07/20 20:12:37  cheshire
+Rename "mDNS_DomainTypeBrowseLegacy" as "mDNS_DomainTypeBrowseAutomatic"
 
-Revision 1.137  2004/12/13 00:09:22  ksekar
-<rdar://problem/3915805> mDNSResponder error when quitting iChat
+Revision 1.313  2007/07/20 00:54:21  cheshire
+<rdar://problem/4641118> Need separate SCPreferences for per-user .Mac settings
 
-Revision 1.136  2004/12/11 01:52:10  cheshire
-<rdar://problem/3785820> Support kDNSServiceFlagsAllowRemoteQuery for registering services too
+Revision 1.312  2007/07/11 03:06:43  cheshire
+<rdar://problem/5303807> Register IPv6-only hostname and don't create port mappings for AutoTunnel services
 
-Revision 1.135  2004/12/10 20:46:37  cheshire
-Change LogOperation message to debugf
+Revision 1.311  2007/07/06 21:19:18  cheshire
+Add list of NAT traversals to SIGINFO output
 
-Revision 1.134  2004/12/10 13:19:37  cheshire
-Add verbosedebugf() logging message in CountPeerRegistrations()
+Revision 1.310  2007/07/03 19:56:50  cheshire
+Add LogOperation message for DNSServiceSetDefaultDomainForUser
 
-Revision 1.133  2004/12/10 05:27:26  cheshire
-<rdar://problem/3909147> Guard against multiple autoname services of the same type on the same machine
+Revision 1.309  2007/06/29 23:12:49  vazquez
+<rdar://problem/5294103> Stop using generate_final_fatal_reply_with_garbage
 
-Revision 1.132  2004/12/10 04:28:28  cheshire
-<rdar://problem/3914406> User not notified of name changes for services using new UDS API
+Revision 1.308  2007/06/29 00:10:07  vazquez
+<rdar://problem/5301908> Clean up NAT state machine (necessary for 6 other fixes)
 
-Revision 1.131  2004/12/10 02:09:25  cheshire
-<rdar://problem/3898376> Modify default TTLs
+Revision 1.307  2007/05/25 00:25:44  cheshire
+<rdar://problem/5227737> Need to enhance putRData to output all current known types
 
-Revision 1.130  2004/12/10 00:55:24  cheshire
-Add full name and type to LogOperation messages for DNSServiceAddRecord/UpdateRecord/RemoveRecord
+Revision 1.306  2007/05/24 22:31:35  vazquez
+Bug #: 4272956
+Reviewed by: Stuart Cheshire
+<rdar://problem/4272956> WWDC API: Return ADD/REMOVE events in registration callback
 
-Revision 1.129  2004/12/09 03:17:23  ksekar
-<rdar://problem/3910435> DomainEnumeration interface index should be zero
+Revision 1.305  2007/05/23 18:59:22  cheshire
+Remove unnecessary IPC_FLAGS_REUSE_SOCKET
 
-Revision 1.128  2004/12/07 21:26:05  ksekar
-<rdar://problem/3908336> DNSServiceRegisterRecord() can crash on deregistration
+Revision 1.304  2007/05/22 01:07:42  cheshire
+<rdar://problem/3563675> API: Need a way to get version/feature information
 
-Revision 1.127  2004/12/07 20:42:34  cheshire
-Add explicit context parameter to mDNS_RemoveRecordFromService()
+Revision 1.303  2007/05/22 00:32:58  cheshire
+Make a send_all() subroutine -- will be helpful for implementing DNSServiceGetProperty(DaemonVersion)
 
-Revision 1.126  2004/12/07 17:23:55  ksekar
-Fixed LogOperation
+Revision 1.302  2007/05/21 18:54:54  cheshire
+Add "Cancel" LogOperation message when we get a cancel_request command over the UDS
 
-Revision 1.125  2004/12/06 21:15:23  ksekar
-<rdar://problem/3884386> mDNSResponder crashed in CheckServiceRegistrations
+Revision 1.301  2007/05/18 23:55:22  cheshire
+<rdar://problem/4454655> Allow multiple register/browse/resolve operations to share single Unix Domain Socket
 
-Revision 1.124  2004/11/30 02:19:14  cheshire
-<rdar://problem/3827971> Raise maxfds.rlim_cur for mDNSResponder
+Revision 1.300  2007/05/18 21:27:11  cheshire
+Rename connected_registration_termination to connection_termination
 
-Revision 1.123  2004/11/29 23:50:57  cheshire
-Checkin 1.122 not necessary
+Revision 1.299  2007/05/18 21:24:34  cheshire
+Rename rstate to request
 
-Revision 1.122  2004/11/24 17:55:01  ksekar
-Added log message clarifying <rdar://problem/3869241> For unicast operations, verify that service types are legal
+Revision 1.298  2007/05/18 21:22:35  cheshire
+Convert uint16_t etc. to their locally-defined equivalents, like the rest of the core code
 
-Revision 1.121  2004/11/24 04:45:52  cheshire
-Spelling mistake
+Revision 1.297  2007/05/18 20:33:11  cheshire
+Avoid declaring lots of uninitialized variables in read_rr_from_ipc_msg
 
-Revision 1.120  2004/11/24 00:10:44  cheshire
-<rdar://problem/3869241> For unicast operations, verify that service types are legal
+Revision 1.296  2007/05/18 19:04:19  cheshire
+Rename msgdata to msgptr (may be modified); rename (currently unused) bufsize to msgend
 
-Revision 1.119  2004/11/23 23:54:17  ksekar
-<rdar://problem/3890318> Wide-Area DNSServiceRegisterRecord() failures
-can crash mDNSResponder
+Revision 1.295  2007/05/18 17:57:13  cheshire
+Reorder functions in file to arrange them in logical groups; added "#pragma mark" headers for each group
 
-Revision 1.118  2004/11/23 22:33:01  cheshire
-<rdar://problem/3654910> Remove temporary workaround code for iChat
+Revision 1.294  2007/05/17 20:58:22  cheshire
+<rdar://problem/4647145> DNSServiceQueryRecord should return useful information with NXDOMAIN
 
-Revision 1.117  2004/11/23 20:23:10  ksekar
-Fixed LogOperation that causes crash on connected service deregistrations
+Revision 1.293  2007/05/17 19:46:20  cheshire
+Routine name deliver_async_error() is misleading. What it actually does is write a message header
+(containing an error code) followed by 256 bytes of garbage zeroes onto a client connection,
+thereby trashing it and making it useless for any subsequent communication. It's destructive,
+and not very useful. Changing name to generate_final_fatal_reply_with_garbage().
 
-Revision 1.116  2004/11/23 03:39:47  cheshire
-Let interface name/index mapping capability live directly in JNISupport.c,
-instead of having to call through to the daemon via IPC to get this information.
+Revision 1.292  2007/05/16 01:06:52  cheshire
+<rdar://problem/4471320> Improve reliability of kDNSServiceFlagsMoreComing flag on multiprocessor machines
 
-Revision 1.115  2004/11/13 00:12:53  ksekar
-Fixed some LogOperation printf converstions for debug builds.
+Revision 1.291  2007/05/15 21:57:16  cheshire
+<rdar://problem/4608220> Use dnssd_SocketValid(x) macro instead of just
+assuming that all negative values (or zero!) are invalid socket numbers
 
-Revision 1.114  2004/11/12 18:25:45  shersche
-Tidy up cross platform usleep code fragment.
+Revision 1.290  2007/05/10 23:30:57  cheshire
+<rdar://problem/4084490> Only one browse gets remove events when disabling browse domain
 
-Revision 1.113  2004/11/12 03:21:41  rpantos
-rdar://problem/3809541 Add DNSSDMapIfIndexToName, DNSSDMapNameToIfIndex.
+Revision 1.289  2007/05/02 22:18:08  cheshire
+Renamed NATTraversalInfo_struct context to NATTraversalContext
 
-Revision 1.112  2004/11/11 16:58:32  ksekar
-Removed unused code (previously wrapped in #if 0)
+Revision 1.288  2007/04/30 21:33:39  cheshire
+Fix crash when a callback unregisters a service while the UpdateSRVRecords() loop
+is iterating through the m->ServiceRegistrations list
 
-Revision 1.111  2004/11/05 22:47:37  shersche
-Conditionally compile usleep(1000) to be Sleep(1) on Windows
-Submitted by: Pavel Repin <prepin@gmail.com>
+Revision 1.287  2007/04/27 19:03:22  cheshire
+Check q->LongLived not q->llq to tell if a query is LongLived
 
-Revision 1.110  2004/11/05 19:56:56  ksekar
-<rdar://problem/3862646> We no longer need to browse .Mac domains by
-default - changed #if 0 to more descriptive #ifdef _HAVE_SETDOMAIN_SUPPORT_
+Revision 1.286  2007/04/26 16:00:01  cheshire
+Show interface number in DNSServiceBrowse RESULT output
 
-Revision 1.109  2004/11/04 03:40:45  cheshire
-More debugging messages
+Revision 1.285  2007/04/22 19:03:39  cheshire
+Minor code tidying
 
-Revision 1.108  2004/11/03 02:25:51  cheshire
-<rdar://problem/3324137> Conflict for Computer Name should update *all* empty string services, not just the one with the conflict
+Revision 1.284  2007/04/22 06:02:03  cheshire
+<rdar://problem/4615977> Query should immediately return failure when no server
 
-Revision 1.107  2004/11/02 19:39:23  ksekar
-<rdar://problem/3862646> We no longer need to browse .Mac domains by default
+Revision 1.283  2007/04/21 21:47:47  cheshire
+<rdar://problem/4376383> Daemon: Add watchdog timer
 
-Revision 1.106  2004/11/02 02:12:21  cheshire
-<rdar://problem/3839111> Remove unnecessary memory allocations
+Revision 1.282  2007/04/20 21:17:24  cheshire
+For naming consistency, kDNSRecordTypeNegative should be kDNSRecordTypePacketNegative
 
-Revision 1.105  2004/10/28 19:07:19  cheshire
-Add some more debugging checks and improved LogOperation() messages
+Revision 1.281  2007/04/19 23:25:20  cheshire
+Added debugging message
 
-Revision 1.104  2004/10/26 18:53:15  cheshire
-Avoid unused variable warning
+Revision 1.280  2007/04/17 19:21:29  cheshire
+<rdar://problem/5140339> Domain discovery not working over VPN
 
-Revision 1.103  2004/10/26 07:15:55  cheshire
-Add file descriptor number to all LogOperation messages
+Revision 1.279  2007/04/16 21:53:49  cheshire
+Improve display of negative cache entries
 
-Revision 1.102  2004/10/26 06:11:42  cheshire
-Add improved logging to aid in diagnosis of <rdar://problem/3842714> mDNSResponder crashed
+Revision 1.278  2007/04/16 20:49:40  cheshire
+Fix compile errors for mDNSPosix build
 
-Revision 1.101  2004/10/26 04:31:44  cheshire
-Rename CountSubTypes() as ChopSubTypes()
+Revision 1.277  2007/04/05 22:55:36  cheshire
+<rdar://problem/5077076> Records are ending up in Lighthouse without expiry information
 
-Revision 1.100  2004/10/26 01:17:48  cheshire
-Use "#if 0" instead of commenting out code
+Revision 1.276  2007/04/05 19:20:13  cheshire
+Non-blocking mode not being set correctly -- was clobbering other flags
 
-Revision 1.99  2004/10/19 21:33:22  cheshire
-<rdar://problem/3844991> Cannot resolve non-local registrations using the mach API
-Added flag 'kDNSServiceFlagsForceMulticast'. Passing through an interface id for a unicast name
-doesn't force multicast unless you set this flag to indicate explicitly that this is what you want
+Revision 1.275  2007/04/04 21:21:25  cheshire
+<rdar://problem/4546810> Fix crash: In regservice_callback service_instance was being referenced after being freed
 
-Revision 1.98  2004/10/14 01:59:33  cheshire
-<rdar://problem/3839208> UDS resolves don't work for uDNS services
+Revision 1.274  2007/04/04 01:30:42  cheshire
+<rdar://problem/5075200> DNSServiceAddRecord is failing to advertise NULL record
+Add SIGINFO output lising our advertised Authoritative Records
 
-Revision 1.97  2004/10/13 00:58:35  cheshire
-<rdar://problem/3832738> Registering a proxy doesn't work
+Revision 1.273  2007/04/04 00:03:27  cheshire
+<rdar://problem/5089862> DNSServiceQueryRecord is returning kDNSServiceErr_NoSuchRecord for empty rdata
 
-Revision 1.96  2004/09/30 00:25:00  ksekar
-<rdar://problem/3695802> Dynamically update default registration domains on config change
+Revision 1.272  2007/04/03 20:10:32  cheshire
+Show ADD/RMV in DNSServiceQueryRecord log message instead of just "RESULT"
 
-Revision 1.95  2004/09/26 23:20:36  ksekar
-<rdar://problem/3813108> Allow default registrations in multiple wide-area domains
+Revision 1.271  2007/04/03 19:22:32  cheshire
+Use mDNSSameIPv4Address (and similar) instead of accessing internal fields directly
 
-Revision 1.94  2004/09/22 18:27:06  ksekar
-<rdar://problem/3811427> allow DNSServiceAddRecord to pass zero to get
-default record TTL
+Revision 1.270  2007/03/30 21:55:30  cheshire
+Added comments
 
-Revision 1.93  2004/09/22 02:39:44  cheshire
-<rdar://problem/3810757> Allow DNSServiceRegisterRecord to pass zero to get default record TTL
+Revision 1.269  2007/03/29 01:31:44  cheshire
+Faulty logic was incorrectly suppressing some NAT port mapping callbacks
 
-Revision 1.92  2004/09/22 02:34:04  cheshire
-Rename parameter "ttl" to "GetTTL" for clarity
+Revision 1.268  2007/03/29 00:13:58  cheshire
+Remove unnecessary fields from service_instance structure: autoname, autorename, allowremotequery, name
 
-Revision 1.91  2004/09/22 02:25:43  cheshire
-Fix spelling errors
+Revision 1.267  2007/03/28 20:59:27  cheshire
+<rdar://problem/4743285> Remove inappropriate use of IsPrivateV4Addr()
 
-Revision 1.90  2004/09/21 23:40:12  ksekar
-<rdar://problem/3810349> mDNSResponder to return errors on NAT traversal failure
+Revision 1.266  2007/03/28 15:56:37  cheshire
+<rdar://problem/5085774> Add listing of NAT port mapping and GetAddrInfo requests in SIGINFO output
 
-Revision 1.89  2004/09/21 23:29:51  cheshire
-<rdar://problem/3680045> DNSServiceResolve should delay sending packets
+Revision 1.265  2007/03/27 22:52:07  cheshire
+Fix crash in udsserver_automatic_browse_domain_changed
 
-Revision 1.88  2004/09/21 23:12:46  cheshire
-Reorder initialization of question fields to match structure order
+Revision 1.264  2007/03/27 00:49:40  cheshire
+Should use mallocL, not plain malloc
 
-Revision 1.87  2004/09/21 22:18:33  cheshire
-In SIGINFO output, display a '-' next to records that have the Unique bit set
+Revision 1.263  2007/03/27 00:45:01  cheshire
+Removed unnecessary "void *termination_context" pointer
 
-Revision 1.86  2004/09/21 21:05:11  cheshire
-Move duplicate code out of mDNSMacOSX/daemon.c and mDNSPosix/PosixDaemon.c,
-into mDNSShared/uds_daemon.c
+Revision 1.262  2007/03/27 00:40:43  cheshire
+Eliminate resolve_termination_t as a separately-allocated structure, and make it part of the request_state union
 
-Revision 1.85  2004/09/18 01:11:58  ksekar
-<rdar://problem/3806734> Add a user's default domain to empty-string browse list
+Revision 1.261  2007/03/27 00:29:00  cheshire
+Eliminate queryrecord_request data as a separately-allocated structure, and make it part of the request_state union
 
-Revision 1.84  2004/09/17 01:08:55  cheshire
-Renamed mDNSClientAPI.h to mDNSEmbeddedAPI.h
-  The name "mDNSClientAPI.h" is misleading to new developers looking at this code. The interfaces
-  declared in that file are ONLY appropriate to single-address-space embedded applications.
-  For clients on general-purpose computers, the interfaces defined in dns_sd.h should be used.
+Revision 1.260  2007/03/27 00:18:42  cheshire
+Eliminate enum_termination_t and domain_enum_t as separately-allocated structures,
+and make them part of the request_state union
 
-Revision 1.83  2004/09/16 23:26:33  cheshire
-Move version check inside preceeding "if" that checks we have a complete header
+Revision 1.259  2007/03/26 23:48:16  cheshire
+<rdar://problem/4848295> Advertise model information via Bonjour
+Refinements to reduce unnecessary transmissions of the DeviceInfo TXT record
 
-Revision 1.82  2004/09/16 23:14:25  cheshire
-Changes for Windows compatibility
+Revision 1.258  2007/03/24 00:40:04  cheshire
+Minor code cleanup
 
-Revision 1.81  2004/09/16 21:46:38  ksekar
-<rdar://problem/3665304> Need SPI for LoginWindow to associate a UID with a Wide Area domain
+Revision 1.257  2007/03/24 00:23:12  cheshire
+Eliminate port_mapping_info_t as a separately-allocated structure, and make it part of the request_state union
 
-Revision 1.80  2004/09/16 01:58:23  cheshire
-Fix compiler warnings
+Revision 1.256  2007/03/24 00:07:18  cheshire
+Eliminate addrinfo_info_t as a separately-allocated structure, and make it part of the request_state union
 
-Revision 1.79  2004/09/16 00:24:49  cheshire
-<rdar://problem/3803162> Fix unsafe use of mDNSPlatformTimeNow()
+Revision 1.255  2007/03/23 23:56:14  cheshire
+Move list of record registrations into the request_state union
 
-Revision 1.78  2004/09/15 21:44:20  cheshire
-<rdar://problem/3681031> Randomize initial timenow_adjust value in mDNS_Init
-Show time value in log to help diagnose errors
+Revision 1.254  2007/03/23 23:48:56  cheshire
+Eliminate service_info as a separately-allocated structure, and make it part of the request_state union
 
-Revision 1.77  2004/09/15 00:19:18  cheshire
-<rdar://problem/3785823> read_rr_from_ipc_msg should use mDNS_SetupResourceRecord()
+Revision 1.253  2007/03/23 23:04:29  cheshire
+Eliminate browser_info_t as a separately-allocated structure, and make it part of request_state
 
-Revision 1.76  2004/09/02 06:39:52  cheshire
-Minor textual cleanup for clarity
+Revision 1.252  2007/03/23 22:59:58  cheshire
+<rdar://problem/4848295> Advertise model information via Bonjour
+Use kStandardTTL, not kHostNameTTL
 
-Revision 1.75  2004/09/02 03:48:47  cheshire
-<rdar://problem/3709039> Disable targeted unicast query support by default
-1. New flag kDNSServiceFlagsAllowRemoteQuery to indicate we want to allow remote queries for this record
-2. New field AllowRemoteQuery in AuthRecord structure
-3. uds_daemon.c sets AllowRemoteQuery if kDNSServiceFlagsAllowRemoteQuery is set
-4. mDNS.c only answers remote queries if AllowRemoteQuery is set
+Revision 1.251  2007/03/23 22:44:07  cheshire
+Instead of calling AbortUnlinkAndFree() haphazardly all over the place, make the handle* routines
+return an error code, and then request_callback() does all necessary cleanup in one place.
 
-Revision 1.74  2004/08/25 02:32:47  cheshire
-Minor cleanup: replace "&regtype[0]" with "regtype"
+Revision 1.250  2007/03/22 20:30:07  cheshire
+Remove pointless "if (request->ts != t_complete) ..." checks
 
-Revision 1.73  2004/08/25 02:30:40  cheshire
-<rdar://problem/3588761> Current method of doing subtypes causes name collisions
+Revision 1.249  2007/03/22 20:13:27  cheshire
+Delete unused client_context field
 
-Revision 1.72  2004/08/14 03:22:42  cheshire
-<rdar://problem/3762579> Dynamic DNS UI <-> mDNSResponder glue
-Add GetUserSpecifiedDDNSName() routine
-Convert ServiceRegDomain to domainname instead of C string
-Replace mDNS_GenerateFQDN/mDNS_GenerateGlobalFQDN with mDNS_SetFQDNs
+Revision 1.248  2007/03/22 20:03:37  cheshire
+Rename variables for clarity: instead of using variable rs for both request_state
+and reply_state, use req for request_state and rep for reply_state
 
-Revision 1.71  2004/08/11 04:21:21  rpantos
-Fix Windows build.
+Revision 1.247  2007/03/22 19:31:42  cheshire
+<rdar://problem/4848295> Advertise model information via Bonjour
+Add missing "model=" at start of DeviceInfo data
 
-Revision 1.70  2004/08/11 02:07:00  cheshire
-Remove "mDNS *globalInstance" parameter from udsserver_init()
-Move CheckForDuplicateRegistrations from daemon.c
-<rdar://problem/3501938> No warning when accidentally registering the same service multiple times using socket API
+Revision 1.246  2007/03/22 18:31:48  cheshire
+Put dst parameter first in mDNSPlatformStrCopy/mDNSPlatformMemCopy, like conventional Posix strcpy/memcpy
 
-Revision 1.69  2004/08/10 16:14:48  cheshire
-Fix debug builds (oops)
+Revision 1.245  2007/03/22 00:49:20  cheshire
+<rdar://problem/4848295> Advertise model information via Bonjour
 
-Revision 1.68  2004/08/10 06:24:56  cheshire
-Use types with precisely defined sizes for 'op' and 'reg_index', for better
-compatibility if the daemon and the client stub are built using different compilers
+Revision 1.244  2007/03/21 21:01:48  cheshire
+<rdar://problem/4789793> Leak on error path in regrecord_callback, uds_daemon.c
 
-Revision 1.67  2004/07/27 07:14:16  shersche
-make error socket non-blocking after call to connect()
+Revision 1.243  2007/03/21 19:01:57  cheshire
+<rdar://problem/5078494> IPC code not 64-bit-savvy: assumes long=32bits, and short=16bits
 
-Revision 1.66  2004/07/13 21:24:25  rpantos
-Fix for <rdar://problem/3701120>.
+Revision 1.242  2007/03/21 18:51:21  cheshire
+<rdar://problem/4549320> Code in uds_daemon.c passes function name instead of type name to mallocL/freeL
 
-Revision 1.65  2004/06/26 03:17:14  shersche
-implement cross-platform strerror function
+Revision 1.241  2007/03/20 00:04:50  cheshire
+<rdar://problem/4837929> Should allow "udp" or "tcp" for protocol command-line arg
+Fix LogOperation("DNSServiceNATPortMappingCreate(...)") message to actually show client arguments
 
-Submitted by: herscher
+Revision 1.240  2007/03/16 23:25:35  cheshire
+<rdar://problem/5067001> NAT-PMP: Parameter validation not working correctly
 
-Revision 1.64  2004/06/25 00:26:27  rpantos
-Changes to fix the Posix build on Solaris.
+Revision 1.239  2007/03/10 02:29:36  cheshire
+Added comment about port_mapping_create_reply()
 
-Revision 1.63  2004/06/24 03:43:44  rpantos
-Fix previous checkin so it builds on Windows.
+Revision 1.238  2007/03/07 00:26:48  cheshire
+<rdar://problem/4426754> DNSServiceRemoveRecord log message should include record type
 
-Revision 1.62  2004/06/24 00:57:08  ksekar
-Replaced code acccidentally removed in checkin 1.59.
+Revision 1.237  2007/02/28 01:44:29  cheshire
+<rdar://problem/5027863> Byte order bugs in uDNS.c, uds_daemon.c, dnssd_clientstub.c
 
-Revision 1.61  2004/06/19 00:09:39  cheshire
-Remove unused strsep() implementation
+Revision 1.236  2007/02/14 01:58:19  cheshire
+<rdar://problem/4995831> Don't delete Unix Domain Socket on exit if we didn't create it on startup
 
-Revision 1.60  2004/06/18 19:10:00  cheshire
-<rdar://problem/3588761> Current method of doing subtypes causes name collisions
+Revision 1.235  2007/02/08 21:12:28  cheshire
+<rdar://problem/4386497> Stop reading /etc/mDNSResponder.conf on every sleep/wake
 
-Revision 1.59  2004/06/18 05:10:31  rpantos
-Changes to allow code to be used on Windows
+Revision 1.234  2007/02/06 19:06:49  cheshire
+<rdar://problem/3956518> Need to go native with launchd
 
-Revision 1.58  2004/06/15 03:54:08  cheshire
-Include mDNS_TimeNow(&mDNSStorage) in SIGINFO output
+Revision 1.233  2007/01/10 20:49:37  cheshire
+Remove unnecessary setting of q->Private fields
 
-Revision 1.57  2004/06/12 01:47:27  ksekar
-<rdar://problem/3690241>: BBEdit crashes when trying to check for newer version
-udsserver_idle compared time in ticks to interval in seconds.
+Revision 1.232  2007/01/09 00:03:23  cheshire
+Call udsserver_handle_configchange() once at the end of udsserver_init()
+to set up the automatic registration and browsing domains.
 
-Revision 1.56  2004/06/12 01:35:47  cheshire
-Changes for Windows compatibility
+Revision 1.231  2007/01/06 02:50:19  cheshire
+<rdar://problem/4632919> Instead of copying SRV and TXT record data, just store pointers to cache entities
 
-Revision 1.55  2004/06/05 00:04:27  cheshire
-<rdar://problem/3668639>: wide-area domains should be returned in reg. domain enumeration
+Revision 1.230  2007/01/06 01:00:35  cheshire
+Improved SIGINFO output
 
-Revision 1.54  2004/06/01 22:22:52  ksekar
-<rdar://problem/3668635>: wide-area default registrations should be in
-.local too
+Revision 1.229  2007/01/05 08:30:56  cheshire
+Trim excessive "$Log" checkin history from before 2006
+(checkin history still available via "cvs log ..." of course)
 
-Revision 1.53  2004/05/28 23:42:37  ksekar
-<rdar://problem/3258021>: Feature: DNS server->client notification on record changes (#7805)
+Revision 1.228  2007/01/05 08:09:05  cheshire
+Reorder code into functional sections, with "#pragma mark" headers
 
-Revision 1.52  2004/05/26 00:39:49  ksekar
-<rdar://problem/3667105>: wide-area DNS-SD servers don't appear in
-Finder
-Use local-only InterfaceID for GetDomains calls for sockets-API
+Revision 1.227  2007/01/05 07:04:24  cheshire
+Minor code tidying
 
-Revision 1.51  2004/05/18 23:51:27  cheshire
-Tidy up all checkin comments to use consistent "<rdar://problem/xxxxxxx>" format for bug numbers
+Revision 1.226  2007/01/05 05:44:35  cheshire
+Move automatic browse/registration management from uDNS.c to mDNSShared/uds_daemon.c,
+so that mDNSPosix embedded clients will compile again
 
-Revision 1.50  2004/05/14 16:39:47  ksekar
-Browse for iChat locally for now.
+Revision 1.225  2007/01/04 23:11:15  cheshire
+<rdar://problem/4720673> uDNS: Need to start caching unicast records
+When an automatic browsing domain is removed, generate appropriate "remove" events for legacy queries
 
-Revision 1.49  2004/05/13 21:33:52  ksekar
-Clean up non-local registration control via config file.  Force iChat
-registrations to be local for now.
+Revision 1.224  2007/01/04 20:57:49  cheshire
+Rename ReturnCNAME to ReturnIntermed (for ReturnIntermediates)
 
-Revision 1.48  2004/05/13 04:13:19  ksekar
-Updated SIGINFO handler for multi-domain browses
+Revision 1.223  2006/12/21 01:25:49  cheshire
+Tidy up SIGINFO state log
 
-Revision 1.47  2004/05/12 22:04:01  ksekar
-Implemented multi-domain browsing by default for uds_daemon.
+Revision 1.222  2006/12/21 00:15:22  cheshire
+Get rid of gmDNS macro; fixed a crash in udsserver_info()
 
-Revision 1.46  2004/05/06 18:42:58  ksekar
-General dns_sd.h API cleanup, including the following radars:
-<rdar://problem/3592068>: Remove flags with zero value
-<rdar://problem/3479569>: Passing in NULL causes a crash.
+Revision 1.221  2006/12/20 04:07:38  cheshire
+Remove uDNS_info substructure from AuthRecord_struct
 
-Revision 1.45  2004/03/12 08:49:28  cheshire
-#include <sys/socket.h>
+Revision 1.220  2006/12/19 22:49:25  cheshire
+Remove uDNS_info substructure from ServiceRecordSet_struct
 
-Revision 1.44  2004/02/25 01:25:27  ksekar
-<rdar://problem/3569212>: DNSServiceRegisterRecord flags not error-checked
+Revision 1.219  2006/12/14 03:02:38  cheshire
+<rdar://problem/4838433> Tools: dns-sd -G 0 only returns IPv6 when you have a routable IPv6 address
 
-Revision 1.43  2004/02/24 01:46:40  cheshire
-Manually reinstate lost checkin 1.36
+Revision 1.218  2006/11/18 05:01:33  cheshire
+Preliminary support for unifying the uDNS and mDNS code,
+including caching of uDNS answers
 
-Revision 1.42  2004/02/05 19:39:29  cheshire
-Move creation of /var/run/mDNSResponder.pid to uds_daemon.c,
-so that all platforms get this functionality
+Revision 1.217  2006/11/15 19:27:53  mkrochma
+<rdar://problem/4838433> Tools: dns-sd -G 0 only returns IPv6 when you have a routable IPv6 address
 
-Revision 1.41  2004/02/03 18:59:02  cheshire
-Change "char *domain" parameter for format_enumeration_reply to "const char *domain"
+Revision 1.216  2006/11/10 00:54:16  cheshire
+<rdar://problem/4816598> Changing case of Computer Name doesn't work
 
-Revision 1.40  2004/01/28 03:41:00  cheshire
-<rdar://problem/3541946>: Need ability to do targeted queries as well as multicast queries
+Revision 1.215  2006/10/27 01:30:23  cheshire
+Need explicitly to set ReturnIntermed = mDNSfalse
 
-Revision 1.39  2004/01/25 00:03:21  cheshire
-Change to use mDNSVal16() instead of private PORT_AS_NUM() macro
+Revision 1.214  2006/10/20 05:37:23  herscher
+Display question list information in udsserver_info()
 
-Revision 1.38  2004/01/19 19:51:46  cheshire
-Fix compiler error (mixed declarations and code) on some versions of Linux
+Revision 1.213  2006/10/05 03:54:31  herscher
+Remove embedded uDNS_info struct from DNSQuestion_struct
 
-Revision 1.37  2003/12/08 21:11:42  rpantos
-Changes necessary to support mDNSResponder on Linux.
+Revision 1.212  2006/09/30 01:22:35  cheshire
+Put back UTF-8 curly quotes in log messages
 
-Revision 1.36  2003/12/04 23:40:57  cheshire
-<rdar://problem/3484766>: Security: Crashing bug in mDNSResponder
-Fix some more code that should use buffer size MAX_ESCAPED_DOMAIN_NAME (1005) instead of 256-byte buffers.
+Revision 1.211  2006/09/27 00:44:55  herscher
+<rdar://problem/4249761> API: Need DNSServiceGetAddrInfo()
 
-Revision 1.35  2003/12/03 19:10:22  ksekar
-<rdar://problem/3498644>: malloc'd data not zero'd
+Revision 1.210  2006/09/26 01:52:41  herscher
+<rdar://problem/4245016> NAT Port Mapping API (for both NAT-PMP and UPnP Gateway Protocol)
 
-Revision 1.34  2003/12/03 02:00:01  ksekar
-<rdar://problem/3498644>: malloc'd data not zero'd
+Revision 1.209  2006/09/21 21:34:09  cheshire
+<rdar://problem/4100000> Allow empty string name when using kDNSServiceFlagsNoAutoRename
 
-Revision 1.33  2003/11/22 01:18:46  ksekar
-<rdar://problem/3486646>: config change handler not called for dns-sd services
+Revision 1.208  2006/09/21 21:28:24  cheshire
+Code cleanup to make it consistent with daemon.c: change rename_on_memfree to renameonmemfree
 
-Revision 1.32  2003/11/20 21:46:12  ksekar
-<rdar://problem/3486635>: leak: DNSServiceRegisterRecord
+Revision 1.207  2006/09/15 21:20:16  cheshire
+Remove uDNS_info substructure from mDNS_struct
 
-Revision 1.31  2003/11/20 20:33:05  ksekar
-<rdar://problem/3486635>: leak: DNSServiceRegisterRecord
+Revision 1.206  2006/08/14 23:24:56  cheshire
+Re-licensed mDNSResponder daemon source code under Apache License, Version 2.0
 
-Revision 1.30  2003/11/20 02:10:55  ksekar
-<rdar://problem/3486643>: cleanup DNSServiceAdd/RemoveRecord
+Revision 1.205  2006/07/20 22:07:30  mkrochma
+<rdar://problem/4633196> Wide-area browsing is currently broken in TOT
+More fixes for uninitialized variables
 
-Revision 1.29  2003/11/14 21:18:32  cheshire
-<rdar://problem/3484766>: Security: Crashing bug in mDNSResponder
-Fix code that should use buffer size MAX_ESCAPED_DOMAIN_NAME (1005) instead of 256-byte buffers.
+Revision 1.204  2006/07/15 02:01:33  cheshire
+<rdar://problem/4472014> Add Private DNS client functionality to mDNSResponder
+Fix broken "empty string" browsing
 
-Revision 1.28  2003/11/08 22:18:29  cheshire
-<rdar://problem/3477870>: Don't need to show process ID in *every* mDNSResponder syslog message
+Revision 1.203  2006/07/07 01:09:13  cheshire
+<rdar://problem/4472013> Add Private DNS server functionality to dnsextd
+Only use mallocL/freeL debugging routines when building mDNSResponder, not dnsextd
 
-Revision 1.27  2003/11/05 22:44:57  ksekar
-<rdar://problem/3335230>: No bounds checking when reading data from client
-Reviewed by: Stuart Cheshire
+Revision 1.202  2006/07/05 22:00:10  cheshire
+Wide-area cleanup: Rename mDNSPlatformGetRegDomainList() to uDNS_GetDefaultRegDomainList()
 
-Revision 1.26  2003/10/23 17:51:04  ksekar
-<rdar://problem/3335216>: handle blocked clients more efficiently
-Changed gettimeofday() to mDNS_TimeNow(&mDNSStorage);
+Revision 1.201  2006/06/29 03:02:47  cheshire
+<rdar://problem/4607042> mDNSResponder NXDOMAIN and CNAME support
 
-Revision 1.25  2003/10/22 23:37:49  ksekar
-<rdar://problem/3459141>: crash/hang in abort_client
+Revision 1.200  2006/06/28 08:56:26  cheshire
+Added "_op" to the end of the operation code enum values,
+to differentiate them from the routines with the same names
 
-Revision 1.24  2003/10/21 20:59:40  ksekar
-<rdar://problem/3335216>: handle blocked clients more efficiently
+Revision 1.199  2006/06/28 08:53:39  cheshire
+Added (commented out) debugging messages
 
-Revision 1.23  2003/09/23 02:12:43  cheshire
-Also include port number in list of services registered via new UDS API
+Revision 1.198  2006/06/27 20:16:07  cheshire
+Fix code layout
 
-Revision 1.22  2003/08/19 16:03:55  ksekar
-<rdar://problem/3380097>: ER: SIGINFO dump should include resolves started by DNSServiceQueryRecord
-Check termination_context for NULL before dereferencing.
+Revision 1.197  2006/05/18 01:32:35  cheshire
+<rdar://problem/4472706> iChat: Lost connection with Bonjour
+(mDNSResponder insufficiently defensive against malformed browsing PTR responses)
 
-Revision 1.21  2003/08/19 05:39:43  cheshire
-<rdar://problem/3380097> SIGINFO dump should include resolves started by DNSServiceQueryRecord
+Revision 1.196  2006/05/05 07:07:13  cheshire
+<rdar://problem/4538206> mDNSResponder fails when UDS reads deliver partial data
 
-Revision 1.20  2003/08/16 03:39:01  cheshire
-<rdar://problem/3338440> InterfaceID -1 indicates "local only"
+Revision 1.195  2006/04/25 20:56:28  mkrochma
+Added comment about previous checkin
 
-Revision 1.19  2003/08/15 20:16:03  cheshire
-<rdar://problem/3366590> mDNSResponder takes too much RPRVT
-We want to avoid touching the rdata pages, so we don't page them in.
-1. RDLength was stored with the rdata, which meant touching the page just to find the length.
-   Moved this from the RData to the ResourceRecord object.
-2. To avoid unnecessarily touching the rdata just to compare it,
-   compute a hash of the rdata and store the hash in the ResourceRecord object.
+Revision 1.194  2006/04/25 18:29:36  mkrochma
+Workaround for warning: unused variable 'status' when building mDNSPosix
 
-Revision 1.18  2003/08/15 00:38:00  ksekar
-<rdar://problem/3377005>: Bug: buffer overrun when reading long rdata from client
+Revision 1.193  2006/03/19 17:14:38  cheshire
+<rdar://problem/4483117> Need faster purging of stale records
+read_rr_from_ipc_msg was not setting namehash and rdatahash
 
-Revision 1.17  2003/08/14 02:18:21  cheshire
-<rdar://problem/3375491> Split generic ResourceRecord type into two separate types: AuthRecord and CacheRecord
+Revision 1.192  2006/03/18 20:58:32  cheshire
+Misplaced curly brace
 
-Revision 1.16  2003/08/13 23:58:52  ksekar
-<rdar://problem/3374911>: Bug: UDS Sub-type browsing works, but not sub-type registration
-Fixed pointer increment error, moved subtype reading for-loop for easier error bailout.
+Revision 1.191  2006/03/10 22:19:43  cheshire
+Update debugging message in resolve_result_callback() to indicate whether event is ADD or RMV
 
-Revision 1.15  2003/08/13 17:30:33  ksekar
-<rdar://problem/3374671>: DNSServiceAddRecord doesn't work
-Fixed various problems with handling the AddRecord request and freeing the ExtraResourceRecords.
+Revision 1.190  2006/03/10 21:56:12  cheshire
+<rdar://problem/4111464> After record update, old record sometimes remains in cache
+When service TXT and SRV record both change, clients with active resolve calls get *two* callbacks, one
+when the TXT data changes, and then immediately afterwards a second callback with the new port number
+This change suppresses the first unneccessary (and confusing) callback
 
-Revision 1.14  2003/08/12 19:56:25  cheshire
-Update to APSL 2.0
+Revision 1.189  2006/01/06 00:56:31  cheshire
+<rdar://problem/4400573> Should remove PID file on exit
 
- */
+*/
 
 #if defined(_WIN32)
 #include <process.h>
-#define MDNS_LAZY_REGISTER_SEARCH_DOMAINS
-#define dnssd_strerror(X)      win32_strerror(X)
-#define usleep(X)                              Sleep(((X)+999)/1000)
-static char *  win32_strerror(int inErrorCode);
+#define dnssd_strerror(X) win32_strerror(X)
+#define usleep(X) Sleep(((X)+999)/1000)
+mDNSlocal char *win32_strerror(int inErrorCode)
+       {
+       static char buffer[1024];
+       DWORD       n;
+       memset(buffer, 0, sizeof(buffer));
+       n = FormatMessageA(
+                       FORMAT_MESSAGE_FROM_SYSTEM | FORMAT_MESSAGE_IGNORE_INSERTS,
+                       NULL,
+                       (DWORD) inErrorCode,
+                       MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT),
+                       buffer,
+                       sizeof(buffer),
+                       NULL);
+       if (n > 0)
+               {
+               // Remove any trailing CR's or LF's since some messages have them.
+               while ((n > 0) && isspace(((unsigned char *) buffer)[n - 1]))
+                       buffer[--n] = '\0';
+               }
+       return buffer;
+       }
 #else
 #include <fcntl.h>
 #include <errno.h>
@@ -658,273 +622,210 @@ static char *   win32_strerror(int inErrorCode);
 #include <sys/types.h>
 #include <sys/time.h>
 #include <sys/resource.h>
-#define dnssd_strerror(X)      strerror(X)
+#define dnssd_strerror(X) strerror(X)
 #endif
 
 #include <stdlib.h>
 #include <stdio.h>
 #include "mDNSEmbeddedAPI.h"
 #include "DNSCommon.h"
+#include "uDNS.h"
 #include "uds_daemon.h"
-#include "dns_sd.h"
-#include "dnssd_ipc.h"
 
-// Apple specific configuration functionality, not required for other platforms
-#ifdef __MACOSX__
+// Apple-specific functionality, not required for other platforms
+#if APPLE_OSX_mDNSResponder
 #include <sys/ucred.h>
-#ifndef LOCAL_PEERCRED
-#define LOCAL_PEERCRED 0x001 /* retrieve peer credentials */
-#endif // LOCAL_PEERCRED
-#endif //__MACOSX__
-
-#if defined(MDNS_LAZY_REGISTER_SEARCH_DOMAINS)
-extern mStatus dDNS_RegisterSearchDomains( mDNS * const m );
+#ifndef PID_FILE
+#define PID_FILE ""
+#endif
 #endif
 
-// Types and Data Structures
-// ----------------------------------------------------------------------
+// User IDs 0-500 are system-wide processes, not actual users in the usual sense
+// User IDs for real user accounts start at 501 and count up from there
+#define SystemUID(X) ((X) <= 500)
+
+// ***************************************************************************
+#if COMPILER_LIKES_PRAGMA_MARK
+#pragma mark -
+#pragma mark - Types and Data Structures
+#endif
 
 typedef enum
-    {
-    t_uninitialized,
-    t_morecoming,
-    t_complete,
-    t_error,
-    t_terminated
-    } transfer_state;
+       {
+       t_uninitialized,
+       t_morecoming,
+       t_complete,
+       t_error,
+       t_terminated
+       } transfer_state;
+
+typedef struct request_state request_state;
 
-typedef void (*req_termination_fn)(void *);
+typedef void (*req_termination_fn)(request_state *request);
 
 typedef struct registered_record_entry
-    {
-    uint32_t key;
-    AuthRecord *rr;
-    struct registered_record_entry *next;
-    client_context_t client_context;
-    struct request_state *rstate;
-    } registered_record_entry;
+       {
+       struct registered_record_entry *next;
+       mDNSu32 key;
+       AuthRecord *rr;         // Variable-sized AuthRecord
+       client_context_t client_context;
+       request_state *request;
+       } registered_record_entry;
 
 // A single registered service: ServiceRecordSet + bookkeeping
 // Note that we duplicate some fields from parent service_info object
 // to facilitate cleanup, when instances and parent may be deallocated at different times.
 typedef struct service_instance
-    {
-    struct service_instance *next;
-    mDNSBool autoname;                         // Set if this name is tied to the Computer Name
-    mDNSBool autorename;                       // Set if this client wants us to automatically rename on conflict
-    mDNSBool allowremotequery;         // Respond to unicast queries from outside the local link?
-    mDNSBool rename_on_memfree;        // Set on config change when we deregister original name
-    domainlabel name;
-    domainname domain;
-    mDNSBool default_local;                    // is this the "local." from an empty-string registration?
-    struct request_state *request;
-    dnssd_sock_t sd;
-    AuthRecord *subtypes;
-    ServiceRecordSet srs; // note - must be last field in struct
-    } service_instance;
-
-// A client-created service.  May reference several service_info objects if default
-// settings cause registration in multiple domains.
-typedef struct
        {
-    uint16_t txtlen;
-    void *txtdata;
-    mDNSIPPort port;
-    domainlabel name;
-    char type_as_string[MAX_ESCAPED_DOMAIN_NAME];
-    domainname type;
-    mDNSBool default_domain;
-    domainname host;
-    mDNSBool autoname;                         // Set if this name is tied to the Computer Name
-    mDNSBool autorename;                       // Set if this client wants us to automatically rename on conflict
-    mDNSBool allowremotequery;         // Respond to unicast queries from outside the local link?
-    int num_subtypes;
-    mDNSInterfaceID InterfaceID;
-    service_instance *instances;
-    struct request_state *request;
-       } service_info;
+       struct service_instance *next;
+       request_state *request;
+       dnssd_sock_t sd;
+       AuthRecord *subtypes;
+       mDNSBool renameonmemfree;               // Set on config change when we deregister original name
+    mDNSBool clientnotified;           // Has client been notified of successful registration yet?
+       mDNSBool default_local;                 // is this the "local." from an empty-string registration?
+       domainname domain;
+       ServiceRecordSet srs;                   // note - must be last field in struct
+       } service_instance;
 
 // for multi-domain default browsing
 typedef struct browser_t
        {
-    DNSQuestion q;
-    domainname domain;
-    struct browser_t *next;
+       struct browser_t *next;
+       domainname domain;
+       DNSQuestion q;
        } browser_t;
 
-// parent struct for browser instances: list pointer plus metadata
-typedef struct
+struct request_state
        {
-    mDNSBool default_domain;
-    mDNSBool ForceMCast;
-    domainname regtype;
-    mDNSInterfaceID interface_id;
-    struct request_state *rstate;
-    browser_t *browsers;
-       } browser_info_t;
-
-typedef struct
-    {
-    mStatus err;               // Note: This field is in NETWORK byte order
-    int nwritten;
-    dnssd_sock_t sd;
-    } undelivered_error_t;
-
-typedef struct request_state
-    {
-    // connection structures
-    dnssd_sock_t sd;
-
-    // state of read (in case message is read over several recv() calls)
-    transfer_state ts;
-    uint32_t hdr_bytes;                // bytes of header already read
-    ipc_msg_hdr hdr;
-    uint32_t data_bytes;       // bytes of message data already read
-    char *msgbuf;              // pointer to data storage to pass to free()
-    char *msgdata;             // pointer to data to be read from (may be modified)
-    int bufsize;               // size of data storage
-
-    // reply, termination, error, and client context info
-    int no_reply;              // don't send asynchronous replies to client
-    int time_blocked;           // record time of a blocked client
-    void *client_context;      // don't touch this - pointer only valid in client's addr space
-    struct reply_state *replies;  // corresponding (active) reply list
-    undelivered_error_t *u_err;
-    void *termination_context;
-    req_termination_fn terminate;
-
-    //!!!KRS toss these pointers in a union
-    // registration context associated with this request (null if not applicable)
-    registered_record_entry *reg_recs;  // muliple registrations for a connection-oriented request
-    service_info *service_registration;
-    browser_info_t *browser_info;
-    struct request_state *next;
-    } request_state;
+       request_state *next;
+       request_state *primary;                 // If this operation is on a shared socket, pointer to
+                                                                       // primary request_state for the original DNSServiceConnect() operation
+       dnssd_sock_t sd;
+       dnssd_sock_t errsd;
+       mDNSu32 uid;
+
+       // NOTE: On a shared connection these fields in the primary structure, including hdr, are re-used
+       // for each new request. This is because, until we've read the ipc_msg_hdr to find out what the
+       // operation is, we don't know if we're going to need to allocate a new request_state or not.
+       transfer_state ts;
+       mDNSu32 hdr_bytes;                              // bytes of header already read
+       ipc_msg_hdr hdr;
+       mDNSu32 data_bytes;                     // bytes of message data already read
+       char *msgbuf;                                   // pointer to data storage to pass to free()
+       char *msgptr;                                   // pointer to data to be read from (may be modified)
+       char *msgend;                                   // pointer to byte after last byte of message
+
+       // reply, termination, error, and client context info
+       int no_reply;                                   // don't send asynchronous replies to client
+       int time_blocked;                               // record time of a blocked client
+       struct reply_state *replies;    // corresponding (active) reply list
+       req_termination_fn terminate;
+
+       union
+               {
+               registered_record_entry *reg_recs;  // list of registrations for a connection-oriented request
+               struct
+                       {
+                       mDNSInterfaceID interface_id;
+                       mDNSBool default_domain;
+                       mDNSBool ForceMCast;
+                       domainname regtype;
+                       browser_t *browsers;
+                       } browser;
+               struct
+                       {
+                       mDNSInterfaceID InterfaceID;
+                       mDNSu16 txtlen;
+                       void *txtdata;
+                       mDNSIPPort port;
+                       domainlabel name;
+                       char type_as_string[MAX_ESCAPED_DOMAIN_NAME];
+                       domainname type;
+                       mDNSBool default_domain;
+                       domainname host;
+                       mDNSBool autoname;                              // Set if this name is tied to the Computer Name
+                       mDNSBool autorename;                    // Set if this client wants us to automatically rename on conflict
+                       mDNSBool allowremotequery;              // Respond to unicast queries from outside the local link?
+                       int num_subtypes;
+                       service_instance *instances;
+                       } servicereg;
+               struct
+                       {
+                       mDNSInterfaceID      interface_id;
+                       mDNSu32              flags;
+                       mDNSu32              protocol;
+                       DNSQuestion          q4;
+                       DNSQuestion          q6;
+                       } addrinfo;
+               struct
+                       {
+                       mDNSIPPort           ReqExt;    // External port we originally requested, for logging purposes
+                       NATTraversalInfo     NATinfo;
+                       } pm;
+               struct
+                       {
+                       DNSQuestion q_all;
+                       DNSQuestion q_default;
+                       } enumeration;
+               struct
+                       {
+                       DNSQuestion q;
+                       } queryrecord;
+               struct
+                       {
+                       DNSQuestion qtxt;
+                       DNSQuestion qsrv;
+                       const ResourceRecord *txt;
+                       const ResourceRecord *srv;
+                       } resolve;
+                ;
+               } u;
+       };
 
 // struct physically sits between ipc message header and call-specific fields in the message buffer
 typedef struct
-    {
-    DNSServiceFlags flags;                     // Note: This field is in NETWORK byte order
-    uint32_t ifi;                                      // Note: This field is in NETWORK byte order
-    DNSServiceErrorType error;         // Note: This field is in NETWORK byte order
-    } reply_hdr;
+       {
+       DNSServiceFlags flags;                  // Note: This field is in NETWORK byte order
+       mDNSu32 ifi;                                    // Note: This field is in NETWORK byte order
+       DNSServiceErrorType error;              // Note: This field is in NETWORK byte order
+       } reply_hdr;
 
 typedef struct reply_state
-    {
-    // state of the transmission
-    dnssd_sock_t sd;
-    transfer_state ts;
-    uint32_t nwriten;
-    uint32_t len;
-    // context of the reply
-    struct request_state *request;  // the request that this answers
-    struct reply_state *next;   // if there are multiple unsent replies
-    // pointer into message buffer - allows fields to be changed after message is formatted
-    ipc_msg_hdr *mhdr;
-    reply_hdr *rhdr;
-    char *sdata;  // pointer to start of call-specific data
-    // pointer to malloc'd buffer
-    char *msgbuf;
-    } reply_state;
-
-// domain enumeration and resolv calls require 2 mDNSCore calls, so we need separate interconnected
-// structures to handle callbacks
-typedef struct
-    {
-    DNSQuestion question;
-    mDNS_DomainType type;
-    request_state *rstate;
-    } domain_enum_t;
-
-typedef struct
-    {
-    domain_enum_t *all;
-    domain_enum_t *def;
-    request_state *rstate;
-    } enum_termination_t;
-
-typedef struct
-    {
-    request_state *rstate;
-    DNSQuestion qtxt;
-    DNSQuestion qsrv;
-    // const ResourceRecord *txt;
-    // const ResourceRecord *srv;
-    mDNSBool   srv;
-    mDNSBool   txt;
-    rdataSRV   srvdata;
-    mDNSu16    txtlen;
-    mDNSu8     txtdata[AbsoluteMaxDNSMessageData];
-    } resolve_termination_t;
-
-#ifdef _HAVE_SETDOMAIN_SUPPORT_
-typedef struct default_browse_list_t
-       {
-    struct default_browse_list_t *next;
-    uid_t uid;
-    AuthRecord ptr_rec;
-       } default_browse_list_t;
-
-static default_browse_list_t *default_browse_list = NULL;
-#endif // _HAVE_SETDOMAIN_SUPPORT_
+       {
+       dnssd_sock_t sd;
+       transfer_state ts;
+       mDNSu32 nwriten;
+       mDNSu32 len;
+       request_state *request;         // the request that this answers
+       struct reply_state *next;       // if there are multiple unsent replies
+       char *msgbuf;                           // pointer to malloc'd buffer
+       ipc_msg_hdr *mhdr;                      // pointer into message buffer - allows fields to be changed after message is formatted
+       reply_hdr *rhdr;
+       char *sdata;                            // pointer to start of call-specific data
+       } reply_state;
+
+// ***************************************************************************
+#if COMPILER_LIKES_PRAGMA_MARK
+#pragma mark -
+#pragma mark - Globals
+#endif
 
 // globals
 mDNSexport mDNS mDNSStorage;
-#define gmDNS (&mDNSStorage)
-
-static dnssd_sock_t                    listenfd                =       dnssd_InvalidSocket;
-static request_state   *       all_requests    =       NULL;
-
-#define MAX_TIME_BLOCKED 60 * mDNSPlatformOneSecond  // try to send data to a blocked client for 60 seconds before
-                                                     // terminating connection
-#define MSG_PAD_BYTES 5                              // pad message buffer (read from client) with n zero'd bytes to guarantee
-                                                     // n get_string() calls w/o buffer overrun
-// private function prototypes
-mDNSlocal void connect_callback(void *info);
-mDNSlocal int read_msg(request_state *rs);
-mDNSlocal int send_msg(reply_state *rs);
-mDNSlocal void abort_request(request_state *rs);
-mDNSlocal void request_callback(void *info);
-mDNSlocal void handle_resolve_request(request_state *rstate);
-mDNSlocal void question_result_callback(mDNS *const m, DNSQuestion *question, const ResourceRecord *const answer, mDNSBool AddRecord);
-mDNSlocal void question_termination_callback(void *context);
-mDNSlocal void handle_browse_request(request_state *request);
-mDNSlocal void browse_termination_callback(void *context);
-mDNSlocal void handle_regservice_request(request_state *request);
-mDNSlocal void regservice_termination_callback(void *context);
-mDNSlocal void regservice_callback(mDNS *const m, ServiceRecordSet *const srs, mStatus result);
-mDNSlocal mStatus handle_add_request(request_state *rstate);
-mDNSlocal mStatus handle_update_request(request_state *rstate);
-mDNSlocal void append_reply(request_state *req, reply_state *rep);
-mDNSlocal int build_domainname_from_strings(domainname *srv, char *name, char *regtype, char *domain);
-mDNSlocal void enum_termination_callback(void *context);
-mDNSlocal void enum_result_callback(mDNS *const m, DNSQuestion *question, const ResourceRecord *const answer, mDNSBool AddRecord);
-mDNSlocal void handle_query_request(request_state *rstate);
-mDNSlocal reply_state *format_enumeration_reply(request_state *rstate, const char *domain, DNSServiceFlags flags, uint32_t ifi, DNSServiceErrorType err);
-mDNSlocal void handle_enum_request(request_state *rstate);
-mDNSlocal mStatus handle_regrecord_request(request_state *rstate);
-mDNSlocal void regrecord_callback(mDNS *const m, AuthRecord * rr, mStatus result);
-mDNSlocal void connected_registration_termination(void *context);
-mDNSlocal void handle_reconfirm_request(request_state *rstate);
-mDNSlocal AuthRecord *read_rr_from_ipc_msg(char *msgbuf, int ttl, int validate_flags);
-mDNSlocal mStatus handle_removerecord_request(request_state *rstate);
-mDNSlocal void reset_connected_rstate(request_state *rstate);
-mDNSlocal int deliver_error(request_state *rstate, mStatus err);
-mDNSlocal int deliver_async_error(request_state *rs, reply_op_t op, mStatus err);
-mDNSlocal transfer_state send_undelivered_error(request_state *rs);
-mDNSlocal reply_state *create_reply(reply_op_t op, size_t datalen, request_state *request);
-mDNSlocal void update_callback(mDNS *const m, AuthRecord *const rr, RData *oldrd);
-mDNSlocal void my_perror(char *errmsg);
-mDNSlocal void unlink_request(request_state *rs);
-mDNSlocal void resolve_result_callback(mDNS *const m, DNSQuestion *question, const ResourceRecord *const answer, mDNSBool AddRecord);
-mDNSlocal void resolve_termination_callback(void *context);
-mDNSlocal int validate_message(request_state *rstate);
-mDNSlocal mStatus remove_extra(request_state *rstate, service_instance *serv);
-mDNSlocal mStatus remove_record(request_state *rstate);
-mDNSlocal void free_service_instance(service_instance *srv);
-mDNSlocal uint32_t dnssd_htonl(uint32_t l);
-mDNSlocal void handle_setdomain_request(request_state *rstate);
+mDNSexport const char ProgramName[] = "mDNSResponder";
+
+static dnssd_sock_t listenfd = dnssd_InvalidSocket;
+static request_state *all_requests = NULL;
 
+static DNameListElem *SCPrefBrowseDomains;                     // List of automatic browsing domains read from SCPreferences for "empty string" browsing
+static ARListElem    *LocalDomainEnumRecords;          // List of locally-generated PTR records to augment those we learn from the network
+mDNSexport DNameListElem *AutoBrowseDomains;           // List created from those local-only PTR records plus records we get from the network
+
+mDNSexport DNameListElem *AutoRegistrationDomains;     // Domains where we automatically register for empty-string registrations
+
+#define MSG_PAD_BYTES 5                // pad message buffer (read from client) with n zero'd bytes to guarantee
+                                                       // n get_string() calls w/o buffer overrun
 // initialization, setup/teardown functions
 
 // If a platform specifies its own PID file name, we use that
@@ -932,31 +833,11 @@ mDNSlocal void handle_setdomain_request(request_state *rstate);
 #define PID_FILE "/var/run/mDNSResponder.pid"
 #endif
 
-mDNSlocal void LogClientInfo(request_state *req)
-       {
-       void *t = req->termination_context;
-       if (t)
-               {
-               if (req->terminate == regservice_termination_callback)
-                       {
-                       service_instance *ptr;
-                       for (ptr = ((service_info *)t)->instances; ptr; ptr = ptr->next)
-                               LogMsgNoIdent("%3d: DNSServiceRegister         %##s %u", req->sd, ptr->srs.RR_SRV.resrec.name->c, SRS_PORT(&ptr->srs));
-                       }
-               else if (req->terminate == browse_termination_callback)
-                       {
-                       browser_t *blist;
-                       for (blist = req->browser_info->browsers; blist; blist = blist->next)
-                               LogMsgNoIdent("%3d: DNSServiceBrowse           %##s", req->sd, blist->q.qname.c);
-                       }
-               else if (req->terminate == resolve_termination_callback)
-                       LogMsgNoIdent("%3d: DNSServiceResolve          %##s", req->sd, ((resolve_termination_t *)t)->qsrv.qname.c);
-               else if (req->terminate == question_termination_callback)
-                       LogMsgNoIdent("%3d: DNSServiceQueryRecord      %##s", req->sd, ((DNSQuestion *)          t)->qname.c);
-               else if (req->terminate == enum_termination_callback)
-                       LogMsgNoIdent("%3d: DNSServiceEnumerateDomains %##s", req->sd, ((enum_termination_t *)   t)->all->question.qname.c);
-               }
-       }
+// ***************************************************************************
+#if COMPILER_LIKES_PRAGMA_MARK
+#pragma mark -
+#pragma mark - General Utility Functions
+#endif
 
 mDNSlocal void FatalError(char *errmsg)
        {
@@ -965,495 +846,1639 @@ mDNSlocal void FatalError(char *errmsg)
        abort();                // On platforms where writing to zero doesn't generate an exception, abort instead
        }
 
-int udsserver_init(void)
+mDNSlocal mDNSu32 dnssd_htonl(mDNSu32 l)
        {
-       dnssd_sockaddr_t laddr;
-       int                              ret;
-#if defined(_WIN32)
-       u_long opt = 1;
-#endif
+       mDNSu32 ret;
+       char *data = (char*) &ret;
+       put_uint32(l, &data);
+       return ret;
+       }
 
-       // If a particular platform wants to opt out of having a PID file, define PID_FILE to be ""
-       if (PID_FILE[0])
+// hack to search-replace perror's to LogMsg's
+mDNSlocal void my_perror(char *errmsg)
+       {
+       LogMsg("%s: %s", errmsg, dnssd_strerror(dnssd_errno()));
+       }
+
+mDNSlocal void abort_request(request_state *req)
+       {
+       // First stop whatever mDNSCore operation we were doing
+       if (req->terminate) req->terminate(req);
+
+       // Now, if this request_state is not subbordinate to some other primary, close file descriptor and discard replies
+       if (!req->primary)
                {
-               FILE *fp = fopen(PID_FILE, "w");
-               if (fp != NULL)
+               if (req->errsd != req->sd) LogOperation("%3d: Removing FD and closing errsd %d", req->sd, req->errsd);
+               else                       LogOperation("%3d: Removing FD", req->sd);
+               udsSupportRemoveFDFromEventLoop(req->sd);               // Note: This also closes file descriptor req->sd for us
+               if (req->errsd != req->sd) { dnssd_close(req->errsd); req->errsd = req->sd; }
+
+               while (req->replies)    // free pending replies
                        {
-                       fprintf(fp, "%d\n", getpid());
-                       fclose(fp);
+                       reply_state *ptr = req->replies;
+                       req->replies = req->replies->next;
+                       if (ptr->msgbuf) freeL("reply_state msgbuf (abort)", ptr->msgbuf);
+                       freeL("reply_state (abort)", ptr);
                        }
                }
 
-       if ((listenfd = socket(AF_DNSSD, SOCK_STREAM, 0)) == dnssd_InvalidSocket)
-               {
-               my_perror("ERROR: socket(AF_DNSSD, SOCK_STREAM, 0); failed");
-               goto error;
-               }
+// Set req->sd to something invalid, so that udsserver_idle knows to unlink and free this structure
+#if APPLE_OSX_mDNSResponder && MACOSX_MDNS_MALLOC_DEBUGGING
+       // Don't use dnssd_InvalidSocket (-1) because that's the sentinel value MACOSX_MDNS_MALLOC_DEBUGGING uses
+       // for detecting when the memory for an object is inadvertently freed while the object is still on some list
+       req->sd = -2;
+#else
+       req->sd = dnssd_InvalidSocket;
+#endif
+       }
+
+mDNSlocal void AbortUnlinkAndFree(request_state *req)
+       {
+       request_state **p = &all_requests;
+       abort_request(req);
+       while (*p && *p != req) p=&(*p)->next;
+       if (*p) { *p = req->next; freeL("request_state/AbortUnlinkAndFree", req); }
+       }
 
-    bzero(&laddr, sizeof(laddr));
+mDNSlocal reply_state *create_reply(const reply_op_t op, const size_t datalen, request_state *const request)
+       {
+       reply_state *reply;
+       int totallen = (int) (datalen + sizeof(ipc_msg_hdr));
 
-       #if defined(USE_TCP_LOOPBACK)
+       if ((unsigned)datalen < sizeof(reply_hdr))
                {
-               laddr.sin_family                =       AF_INET;
-               laddr.sin_port                  =       htons(MDNS_TCP_SERVERPORT);
-               laddr.sin_addr.s_addr   =       inet_addr(MDNS_TCP_SERVERADDR);
-       ret = bind(listenfd, (struct sockaddr *) &laddr, sizeof(laddr));
-               if (ret < 0)
-                       {
-                       my_perror("ERROR: bind(listenfd, (struct sockaddr *) &laddr, sizeof(laddr)); failed");
-                       goto error;
-                       }
+               LogMsg("ERROR: create_reply - data length less than lenght of required fields");
+               return NULL;
                }
-       #else
+
+       reply = mallocL("reply_state", sizeof(reply_state));
+       if (!reply) FatalError("ERROR: malloc");
+       mDNSPlatformMemZero(reply, sizeof(reply_state));
+       reply->ts      = t_morecoming;
+       reply->sd      = request->sd;
+       reply->request = request;
+       reply->len     = totallen;
+       reply->msgbuf  = mallocL("reply_state msgbuf", totallen);
+       if (!reply->msgbuf) FatalError("ERROR: malloc");
+       mDNSPlatformMemZero(reply->msgbuf, totallen);
+       reply->mhdr    = (ipc_msg_hdr *)reply->msgbuf;
+       reply->rhdr    = (reply_hdr *)(reply->msgbuf + sizeof(ipc_msg_hdr));
+       reply->sdata   = reply->msgbuf + sizeof(ipc_msg_hdr) + sizeof(reply_hdr);
+       reply->mhdr->version   = VERSION;
+       reply->mhdr->datalen   = datalen;
+       reply->mhdr->ipc_flags = 0;
+       reply->mhdr->op        = op;
+       reply->mhdr->client_context = request->hdr.client_context;
+       reply->mhdr->reg_index = 0;
+       return reply;
+       }
+
+// Append a reply to the list in a request object
+// If our request is sharing a connection, then we append our reply_state onto the primary's list
+mDNSlocal void append_reply(request_state *req, reply_state *rep)
+       {
+       request_state *r = req->primary ? req->primary : req;
+       reply_state **ptr = &r->replies;
+       while (*ptr) ptr = &(*ptr)->next;
+       *ptr = rep;
+       rep->next = NULL;
+       }
+
+// Generates a response message giving name, type, domain, plus interface index,
+// suitable for a browse result or service registration result.
+// On successful completion rep is set to point to a malloc'd reply_state struct
+mDNSlocal mStatus GenerateNTDResponse(const domainname *const servicename, const mDNSInterfaceID id,
+       request_state *const request, reply_state **const rep, reply_op_t op, DNSServiceFlags flags, mStatus err)
+       {
+       domainlabel name;
+       domainname type, dom;
+       *rep = NULL;
+       if (!DeconstructServiceName(servicename, &name, &type, &dom))
+               return kDNSServiceErr_Invalid;
+       else
                {
-       mode_t mask = umask(0);
-       unlink(MDNS_UDS_SERVERPATH);  //OK if this fails
-       laddr.sun_family = AF_LOCAL;
-       #ifndef NOT_HAVE_SA_LEN
-       // According to Stevens (section 3.2), there is no portable way to
-       // determine whether sa_len is defined on a particular platform.
-       laddr.sun_len = sizeof(struct sockaddr_un);
-       #endif
-       strcpy(laddr.sun_path, MDNS_UDS_SERVERPATH);
-               ret = bind(listenfd, (struct sockaddr *) &laddr, sizeof(laddr));
-               umask(mask);
-               if (ret < 0)
-                       {
-                       my_perror("ERROR: bind(listenfd, (struct sockaddr *) &laddr, sizeof(laddr)); failed");
-                       goto error;
-                       }
+               char namestr[MAX_DOMAIN_LABEL+1];
+               char typestr[MAX_ESCAPED_DOMAIN_NAME];
+               char domstr [MAX_ESCAPED_DOMAIN_NAME];
+               int len;
+               char *data;
+
+               ConvertDomainLabelToCString_unescaped(&name, namestr);
+               ConvertDomainNameToCString(&type, typestr);
+               ConvertDomainNameToCString(&dom, domstr);
+
+               // Calculate reply data length
+               len = sizeof(DNSServiceFlags);
+               len += sizeof(mDNSu32);  // if index
+               len += sizeof(DNSServiceErrorType);
+               len += (int) (strlen(namestr) + 1);
+               len += (int) (strlen(typestr) + 1);
+               len += (int) (strlen(domstr) + 1);
+
+               // Build reply header
+               *rep = create_reply(op, len, request);
+               (*rep)->rhdr->flags = dnssd_htonl(flags);
+               (*rep)->rhdr->ifi   = dnssd_htonl(mDNSPlatformInterfaceIndexfromInterfaceID(&mDNSStorage, id));
+               (*rep)->rhdr->error = dnssd_htonl(err);
+
+               // Build reply body
+               data = (*rep)->sdata;
+               put_string(namestr, &data);
+               put_string(typestr, &data);
+               put_string(domstr, &data);
+
+               return mStatus_NoError;
                }
-       #endif
+       }
 
-       #if defined(_WIN32)
-       //
-       // SEH: do we even need to do this on windows?  this socket
-       // will be given to WSAEventSelect which will automatically
-       // set it to non-blocking
-       //
-       if (ioctlsocket(listenfd, FIONBIO, &opt) != 0)
-       #else
-    if (fcntl(listenfd, F_SETFL, O_NONBLOCK) != 0)
-       #endif
+// Returns a resource record (allocated w/ malloc) containing the data found in an IPC message
+// Data must be in the following format: flags, interfaceIndex, name, rrtype, rrclass, rdlen, rdata, (optional) ttl
+// (ttl only extracted/set if ttl argument is non-zero). Returns NULL for a bad-parameter error
+mDNSlocal AuthRecord *read_rr_from_ipc_msg(request_state *request, int GetTTL, int validate_flags)
+       {
+       DNSServiceFlags flags  = get_flags(&request->msgptr, request->msgend);
+       mDNSu32 interfaceIndex = get_uint32(&request->msgptr, request->msgend);
+       char name[256];
+       int str_err   = get_string(&request->msgptr, request->msgend, name, sizeof(name));
+       mDNSu16 type  = get_uint16(&request->msgptr, request->msgend);
+       mDNSu16 class = get_uint16(&request->msgptr, request->msgend);
+       mDNSu16 rdlen = get_uint16(&request->msgptr, request->msgend);
+       char *rdata   = get_rdata(&request->msgptr, request->msgend, rdlen);
+       mDNSu32 ttl   = GetTTL ? get_uint32(&request->msgptr, request->msgend) : 0;
+       int storage_size = rdlen > sizeof(RDataBody) ? rdlen : sizeof(RDataBody);
+       AuthRecord *rr;
+
+       if (str_err) { LogMsg("ERROR: read_rr_from_ipc_msg - get_string"); return NULL; }
+
+       if (!request->msgptr) { LogMsg("Error reading Resource Record from client"); return NULL; }
+
+       if (validate_flags &&
+               !((flags & kDNSServiceFlagsShared) == kDNSServiceFlagsShared) &&
+               !((flags & kDNSServiceFlagsUnique) == kDNSServiceFlagsUnique))
                {
-               my_perror("ERROR: could not set listen socket to non-blocking mode");
-               goto error;
+               LogMsg("ERROR: Bad resource record flags (must be kDNSServiceFlagsShared or kDNSServiceFlagsUnique)");
+               return NULL;
                }
 
-       if (listen(listenfd, LISTENQ) != 0)
+       rr = mallocL("AuthRecord/read_rr_from_ipc_msg", sizeof(AuthRecord) - sizeof(RDataBody) + storage_size);
+       if (!rr) FatalError("ERROR: malloc");
+       mDNS_SetupResourceRecord(rr, mDNSNULL, mDNSPlatformInterfaceIDfromInterfaceIndex(&mDNSStorage, interfaceIndex),
+               type, 0, (mDNSu8) ((flags & kDNSServiceFlagsShared) ? kDNSRecordTypeShared : kDNSRecordTypeUnique), mDNSNULL, mDNSNULL);
+
+       if (!MakeDomainNameFromDNSNameString(&rr->namestorage, name))
                {
-               my_perror("ERROR: could not listen on listen socket");
-               goto error;
+               LogMsg("ERROR: bad name: %s", name);
+               freeL("AuthRecord/read_rr_from_ipc_msg", rr);
+               return NULL;
                }
 
-    if (mStatus_NoError != udsSupportAddFDToEventLoop(listenfd, connect_callback, (void *) NULL))
-        {
-        my_perror("ERROR: could not add listen socket to event loop");
-        goto error;
-        }
+       if (flags & kDNSServiceFlagsAllowRemoteQuery) rr->AllowRemoteQuery = mDNStrue;
+       rr->resrec.rrclass = class;
+       rr->resrec.rdlength = rdlen;
+       rr->resrec.rdata->MaxRDLength = rdlen;
+       mDNSPlatformMemCopy(rr->resrec.rdata->u.data, rdata, rdlen);
+       if (GetTTL) rr->resrec.rroriginalttl = ttl;
+       rr->resrec.namehash = DomainNameHashValue(rr->resrec.name);
+       SetNewRData(&rr->resrec, mDNSNULL, 0);  // Sets rr->rdatahash for us
+       return rr;
+       }
 
-#if !defined(PLATFORM_NO_RLIMIT)
+mDNSlocal int build_domainname_from_strings(domainname *srv, char *name, char *regtype, char *domain)
        {
-       // Set maximum number of open file descriptors
-       #define MIN_OPENFILES 10240
-       struct rlimit maxfds, newfds;
-
-       // Due to bugs in OS X (<rdar://problem/2941095>, <rdar://problem/3342704>, <rdar://problem/3839173>)
-       // you have to get and set rlimits once before getrlimit will return sensible values
-       if (getrlimit(RLIMIT_NOFILE, &maxfds) < 0) { my_perror("ERROR: Unable to get file descriptor limit"); return 0; }
-       if (setrlimit(RLIMIT_NOFILE, &maxfds) < 0) my_perror("ERROR: Unable to set maximum file descriptor limit");
+       domainlabel n;
+       domainname d, t;
 
-       if (getrlimit(RLIMIT_NOFILE, &maxfds) < 0) { my_perror("ERROR: Unable to get file descriptor limit"); return 0; }
-       newfds.rlim_max = (maxfds.rlim_max > MIN_OPENFILES) ? maxfds.rlim_max : MIN_OPENFILES;
-       newfds.rlim_cur = (maxfds.rlim_cur > MIN_OPENFILES) ? maxfds.rlim_cur : MIN_OPENFILES;
-       if (newfds.rlim_max != maxfds.rlim_max || newfds.rlim_cur != maxfds.rlim_cur)
-               if (setrlimit(RLIMIT_NOFILE, &newfds) < 0) my_perror("ERROR: Unable to set maximum file descriptor limit");
+       if (!MakeDomainLabelFromLiteralString(&n, name)) return -1;
+       if (!MakeDomainNameFromDNSNameString(&t, regtype)) return -1;
+       if (!MakeDomainNameFromDNSNameString(&d, domain)) return -1;
+       if (!ConstructServiceName(srv, &n, &t, &d)) return -1;
+       return 0;
+       }
 
-       if (getrlimit(RLIMIT_NOFILE, &maxfds) < 0) { my_perror("ERROR: Unable to get file descriptor limit"); return 0; }
-       debugf("maxfds.rlim_max %d", (long)maxfds.rlim_max);
-       debugf("maxfds.rlim_cur %d", (long)maxfds.rlim_cur);
+mDNSlocal void send_all(dnssd_sock_t s, const char *ptr, int len)
+       {
+       int n = send(s, ptr, len, 0);
+       // On a freshly-created Unix Domain Socket, the kernel should *never* fail to buffer a small write for us
+       // (four bytes for a typical error code return, 12 bytes for DNSServiceGetProperty(DaemonVersion)).
+       // If it does fail, we don't attempt to handle this failure, but we do log it so we know something is wrong.
+       if (n < len)
+               LogMsg("ERROR: send_all(%d) wrote %d of %d errno %d %s",
+                       s, n, len, dnssd_errno(), dnssd_strerror(dnssd_errno()));
        }
+
+// ***************************************************************************
+#if COMPILER_LIKES_PRAGMA_MARK
+#pragma mark -
+#pragma mark - DNSServiceRegister
 #endif
-       
-    return 0;
-       
-error:
 
-    my_perror("ERROR: udsserver_init");
-    return -1;
-    }
+mDNSexport void FreeExtraRR(mDNS *const m, AuthRecord *const rr, mStatus result)
+       {
+       ExtraResourceRecord *extra = (ExtraResourceRecord *)rr->RecordContext;
+       (void)m;  //unused
+
+       if (result != mStatus_MemFree) { LogMsg("Error: FreeExtraRR invoked with unexpected error %d", result); return; }
+
+       LogOperation("     FreeExtraRR %s", RRDisplayString(m, &rr->resrec));
+
+       if (rr->resrec.rdata != &rr->rdatastorage)
+               freeL("Extra RData", rr->resrec.rdata);
+       freeL("ExtraResourceRecord/FreeExtraRR", extra);
+       }
+
+mDNSlocal void unlink_and_free_service_instance(service_instance *srv)
+       {
+       ExtraResourceRecord *e = srv->srs.Extras, *tmp;
+
+       // clear pointers from parent struct
+       if (srv->request)
+               {
+               service_instance **p = &srv->request->u.servicereg.instances;
+               while (*p)
+                       {
+                       if (*p == srv) { *p = (*p)->next; break; }
+                       p = &(*p)->next;
+                       }
+               }
+
+       while (e)
+               {
+               e->r.RecordContext = e;
+               tmp = e;
+               e = e->next;
+               FreeExtraRR(&mDNSStorage, &tmp->r, mStatus_MemFree);
+               }
+
+       if (srv->srs.RR_TXT.resrec.rdata != &srv->srs.RR_TXT.rdatastorage)
+               freeL("TXT RData", srv->srs.RR_TXT.resrec.rdata);
+
+       if (srv->subtypes) { freeL("ServiceSubTypes", srv->subtypes); srv->subtypes = NULL; }
+       freeL("service_instance", srv);
+       }
+
+// Count how many other service records we have locally with the same name, but different rdata.
+// For auto-named services, we can have at most one per machine -- if we allowed two auto-named services of
+// the same type on the same machine, we'd get into an infinite autoimmune-response loop of continuous renaming.
+mDNSexport int CountPeerRegistrations(mDNS *const m, ServiceRecordSet *const srs)
+       {
+       int count = 0;
+       ResourceRecord *r = &srs->RR_SRV.resrec;
+       AuthRecord *rr;
+       ServiceRecordSet *s;
+
+       for (rr = m->ResourceRecords; rr; rr=rr->next)
+               if (rr->resrec.rrtype == kDNSType_SRV && SameDomainName(rr->resrec.name, r->name) && !SameRData(&rr->resrec, r))
+                       count++;
+
+       for (s = m->ServiceRegistrations; s; s = s->uDNS_next)
+               if (s->state != regState_Unregistered && SameDomainName(s->RR_SRV.resrec.name, r->name) && !SameRData(&s->RR_SRV.resrec, r))
+                       count++;
+
+       verbosedebugf("%d peer registrations for %##s", count, r->name->c);
+       return(count);
+       }
+
+mDNSexport int CountExistingRegistrations(domainname *srv, mDNSIPPort port)
+       {
+       int count = 0;
+       AuthRecord *rr;
+       for (rr = mDNSStorage.ResourceRecords; rr; rr=rr->next)
+               if (rr->resrec.rrtype == kDNSType_SRV &&
+                       mDNSSameIPPort(rr->resrec.rdata->u.srv.port, port) &&
+                       SameDomainName(rr->resrec.name, srv))
+                       count++;
+       return(count);
+       }
+
+mDNSlocal void SendServiceRemovalNotification(ServiceRecordSet *const srs)
+       {
+       reply_state *rep;
+       service_instance *instance = srs->ServiceContext;
+       if (GenerateNTDResponse(srs->RR_SRV.resrec.name, srs->RR_SRV.resrec.InterfaceID, instance->request, &rep, reg_service_reply_op, 0, mStatus_NoError) != mStatus_NoError)
+               LogMsg("%3d: SendServiceRemovalNotification: %##s is not valid DNS-SD SRV name", instance->sd, srs->RR_SRV.resrec.name->c);
+       else { append_reply(instance->request, rep); instance->clientnotified = mDNSfalse; }
+       }
+
+// service registration callback performs three duties - frees memory for deregistered services,
+// handles name conflicts, and delivers completed registration information to the client (via
+// process_service_registraion())
+mDNSlocal void regservice_callback(mDNS *const m, ServiceRecordSet *const srs, mStatus result)
+       {
+       mStatus err;
+       mDNSBool SuppressError = mDNSfalse;
+       service_instance *instance = srs->ServiceContext;
+       reply_state         *rep;
+       (void)m; // Unused
+       if (!srs)      { LogMsg("regservice_callback: srs is NULL %d",                 result); return; }
+       if (!instance) { LogMsg("regservice_callback: srs->ServiceContext is NULL %d", result); return; }
+
+       // don't send errors up to client for wide-area, empty-string registrations
+       if (instance->request &&
+               instance->request->u.servicereg.default_domain &&
+               !instance->default_local)
+               SuppressError = mDNStrue;
+
+       if (result == mStatus_NoError)
+               LogOperation("%3d: DNSServiceRegister(%##s, %u) REGISTERED",    instance->sd, srs->RR_SRV.resrec.name->c, mDNSVal16(srs->RR_SRV.resrec.rdata->u.srv.port));
+       else if (result == mStatus_MemFree)
+               LogOperation("%3d: DNSServiceRegister(%##s, %u) DEREGISTERED",  instance->sd, srs->RR_SRV.resrec.name->c, mDNSVal16(srs->RR_SRV.resrec.rdata->u.srv.port));
+       else if (result == mStatus_NameConflict)
+               LogOperation("%3d: DNSServiceRegister(%##s, %u) NAME CONFLICT", instance->sd, srs->RR_SRV.resrec.name->c, mDNSVal16(srs->RR_SRV.resrec.rdata->u.srv.port));
+       else
+               LogOperation("%3d: DNSServiceRegister(%##s, %u) CALLBACK %d",   instance->sd, srs->RR_SRV.resrec.name->c, mDNSVal16(srs->RR_SRV.resrec.rdata->u.srv.port), result);
+
+       if (!instance->request && result != mStatus_MemFree) { LogMsg("regservice_callback: instance->request is NULL %d", result); return; }
+
+       if (result == mStatus_NoError)
+               {
+               if (instance->request->u.servicereg.allowremotequery)
+                       {
+                       ExtraResourceRecord *e;
+                       srs->RR_ADV.AllowRemoteQuery = mDNStrue;
+                       srs->RR_PTR.AllowRemoteQuery = mDNStrue;
+                       srs->RR_SRV.AllowRemoteQuery = mDNStrue;
+                       srs->RR_TXT.AllowRemoteQuery = mDNStrue;
+                       for (e = instance->srs.Extras; e; e = e->next) e->r.AllowRemoteQuery = mDNStrue;
+                       }
+
+               if (GenerateNTDResponse(srs->RR_SRV.resrec.name, srs->RR_SRV.resrec.InterfaceID, instance->request, &rep, reg_service_reply_op, kDNSServiceFlagsAdd, result) != mStatus_NoError)
+                       LogMsg("%3d: regservice_callback: %##s is not valid DNS-SD SRV name", instance->sd, srs->RR_SRV.resrec.name->c);
+               else { append_reply(instance->request, rep); instance->clientnotified = mDNStrue; }
+
+               if (instance->request->u.servicereg.autoname && CountPeerRegistrations(m, srs) == 0)
+                       RecordUpdatedNiceLabel(m, 0);   // Successfully got new name, tell user immediately
+               }
+       else if (result == mStatus_MemFree)
+               {
+               if (instance->request && instance->renameonmemfree)
+                       {
+                       instance->renameonmemfree = 0;
+                       err = mDNS_RenameAndReregisterService(m, srs, &instance->request->u.servicereg.name);
+                       if (err) LogMsg("ERROR: regservice_callback - RenameAndReregisterService returned %ld", err);
+                       // error should never happen - safest to log and continue
+                       }
+               else
+                       unlink_and_free_service_instance(instance);
+               }
+       else if (result == mStatus_NameConflict)
+               {
+               if (instance->request->u.servicereg.autorename)
+                       {
+                       if (instance->request->u.servicereg.autoname && CountPeerRegistrations(m, srs) == 0)
+                               {
+                               // On conflict for an autoname service, rename and reregister *all* autoname services
+                               IncrementLabelSuffix(&m->nicelabel, mDNStrue);
+                               m->MainCallback(m, mStatus_ConfigChanged);      // will call back into udsserver_handle_configchange()
+                               }
+                       else    // On conflict for a non-autoname service, rename and reregister just that one service
+                               {
+                               if (instance->clientnotified) SendServiceRemovalNotification(srs);
+                               mDNS_RenameAndReregisterService(m, srs, mDNSNULL);
+                               }
+                       }
+               else
+                       {
+                       if (!SuppressError) 
+                               {
+                               if (GenerateNTDResponse(srs->RR_SRV.resrec.name, srs->RR_SRV.resrec.InterfaceID, instance->request, &rep, reg_service_reply_op, kDNSServiceFlagsAdd, result) != mStatus_NoError)
+                                       LogMsg("%3d: regservice_callback: %##s is not valid DNS-SD SRV name", instance->sd, srs->RR_SRV.resrec.name->c);
+                               else { append_reply(instance->request, rep); instance->clientnotified = mDNStrue; }
+                               }
+                       unlink_and_free_service_instance(instance);
+                       }
+               }
+       else
+               {
+               if (result != mStatus_NATTraversal)
+                       LogMsg("regservice_callback: Error %d%s for %s", result, SuppressError ? " (suppressed)" : "", ARDisplayString(m, &srs->RR_SRV));
+               if (!SuppressError) 
+                       {
+                       if (GenerateNTDResponse(srs->RR_SRV.resrec.name, srs->RR_SRV.resrec.InterfaceID, instance->request, &rep, reg_service_reply_op, kDNSServiceFlagsAdd, result) != mStatus_NoError)
+                               LogMsg("%3d: regservice_callback: %##s is not valid DNS-SD SRV name", instance->sd, srs->RR_SRV.resrec.name->c);
+                       else { append_reply(instance->request, rep); instance->clientnotified = mDNStrue; }
+                       }
+               unlink_and_free_service_instance(instance);
+               }
+       }
+
+mDNSlocal void regrecord_callback(mDNS *const m, AuthRecord *rr, mStatus result)
+       {
+       (void)m; // Unused
+       if (!rr->RecordContext)         // parent struct already freed by termination callback
+               {
+               if (result == mStatus_NoError)
+                       LogMsg("Error: regrecord_callback: successful registration of orphaned record");
+               else
+                       {
+                       if (result != mStatus_MemFree) LogMsg("regrecord_callback: error %d received after parent termination", result);
+                       freeL("AuthRecord/regrecord_callback", rr);
+                       }
+               }
+       else
+               {
+               registered_record_entry *re = rr->RecordContext;
+               request_state *request = re->request;
+               int len = sizeof(DNSServiceFlags) + sizeof(mDNSu32) + sizeof(DNSServiceErrorType);
+               reply_state *reply = create_reply(reg_record_reply_op, len, request);
+               reply->mhdr->client_context = re->client_context;
+               reply->rhdr->flags = dnssd_htonl(0);
+               reply->rhdr->ifi   = dnssd_htonl(mDNSPlatformInterfaceIndexfromInterfaceID(m, rr->resrec.InterfaceID));
+               reply->rhdr->error = dnssd_htonl(result);
+
+               LogOperation("%3d: DNSServiceRegisterRecord(%u) result %d", request->sd, request->hdr.reg_index, result);
+               if (result)
+                       {
+                       // unlink from list, free memory
+                       registered_record_entry **ptr = &request->u.reg_recs;
+                       while (*ptr && (*ptr) != re) ptr = &(*ptr)->next;
+                       if (!*ptr) { LogMsg("regrecord_callback - record not in list!"); return; }
+                       *ptr = (*ptr)->next;
+                       freeL("registered_record_entry AuthRecord regrecord_callback", re->rr);
+                       freeL("registered_record_entry regrecord_callback", re);
+                       }
+               append_reply(request, reply);
+               }
+       }
+
+mDNSlocal void connection_termination(request_state *request)
+       {
+       request_state **req = &all_requests;
+       while (*req)
+               {
+               if ((*req)->primary == request)
+                       {
+                       // Since we're already doing a list traversal, we unlink the request directly instead of using AbortUnlinkAndFree()
+                       request_state *tmp = *req;
+                       abort_request(tmp);
+                       *req = tmp->next;
+                       freeL("request_state/connection_termination", tmp);
+                       }
+               else
+                       req = &(*req)->next;
+               }
+
+       while (request->u.reg_recs)
+               {
+               registered_record_entry *ptr = request->u.reg_recs;
+               request->u.reg_recs = request->u.reg_recs->next;
+               ptr->rr->RecordContext = NULL;
+               mDNS_Deregister(&mDNSStorage, ptr->rr);         // Will free ptr->rr for us
+               freeL("registered_record_entry/connection_termination", ptr);
+               }
+       }
+
+mDNSlocal void handle_cancel_request(request_state *request)
+       {
+       request_state **req = &all_requests;
+       LogOperation("%3d: Cancel %X%08X", request->sd, request->hdr.client_context.u32[1], request->hdr.client_context.u32[0]);
+       while (*req)
+               {
+               if ((*req)->primary == request &&
+                       (*req)->hdr.client_context.u32[0] == request->hdr.client_context.u32[0] &&
+                       (*req)->hdr.client_context.u32[1] == request->hdr.client_context.u32[1])
+                       {
+                       // Since we're already doing a list traversal, we unlink the request directly instead of using AbortUnlinkAndFree()
+                       request_state *tmp = *req;
+                       abort_request(tmp);
+                       *req = tmp->next;
+                       freeL("request_state/handle_cancel_request", tmp);
+                       }
+               else
+                       req = &(*req)->next;
+               }
+       }
+
+mDNSlocal mStatus handle_regrecord_request(request_state *request)
+       {
+       mStatus err = mStatus_BadParamErr;
+       AuthRecord *rr = read_rr_from_ipc_msg(request, 1, 1);
+       if (rr)
+               {
+               // allocate registration entry, link into list
+               registered_record_entry *re = mallocL("registered_record_entry", sizeof(registered_record_entry));
+               if (!re) FatalError("ERROR: malloc");
+               re->key = request->hdr.reg_index;
+               re->rr = rr;
+               re->request = request;
+               re->client_context = request->hdr.client_context;
+               rr->RecordContext = re;
+               rr->RecordCallback = regrecord_callback;
+               re->next = request->u.reg_recs;
+               request->u.reg_recs = re;
+       
+               if (rr->resrec.rroriginalttl == 0)
+                       rr->resrec.rroriginalttl = DefaultTTLforRRType(rr->resrec.rrtype);
+       
+               LogOperation("%3d: DNSServiceRegisterRecord(%u %s)", request->sd, request->hdr.reg_index, RRDisplayString(&mDNSStorage, &rr->resrec));
+               err = mDNS_Register(&mDNSStorage, rr);
+               }
+       return(err);
+       }
+
+mDNSlocal mStatus add_record_to_service(request_state *request, service_instance *instance, mDNSu16 rrtype, mDNSu16 rdlen, char *rdata, mDNSu32 ttl)
+       {
+       ServiceRecordSet *srs = &instance->srs;
+       mStatus result;
+       int size = rdlen > sizeof(RDataBody) ? rdlen : sizeof(RDataBody);
+       ExtraResourceRecord *extra = mallocL("ExtraResourceRecord", sizeof(*extra) - sizeof(RDataBody) + size);
+       if (!extra) { my_perror("ERROR: malloc"); return mStatus_NoMemoryErr; }
+
+       mDNSPlatformMemZero(extra, sizeof(ExtraResourceRecord));  // OK if oversized rdata not zero'd
+       extra->r.resrec.rrtype = rrtype;
+       extra->r.rdatastorage.MaxRDLength = (mDNSu16) size;
+       extra->r.resrec.rdlength = rdlen;
+       mDNSPlatformMemCopy(&extra->r.rdatastorage.u.data, rdata, rdlen);
+
+       result = mDNS_AddRecordToService(&mDNSStorage, srs, extra, &extra->r.rdatastorage, ttl);
+       if (result) { freeL("ExtraResourceRecord/add_record_to_service", extra); return result; }
+
+       extra->ClientID = request->hdr.reg_index;
+       return result;
+       }
+
+mDNSlocal mStatus handle_add_request(request_state *request)
+       {
+       service_instance *i;
+       mStatus result = mStatus_UnknownErr;
+       DNSServiceFlags flags = get_flags(&request->msgptr, request->msgend);
+       mDNSu16        rrtype = get_uint16(&request->msgptr, request->msgend);
+       mDNSu16        rdlen  = get_uint16(&request->msgptr, request->msgend);
+       char           *rdata = get_rdata(&request->msgptr, request->msgend, rdlen);
+       mDNSu32        ttl    = get_uint32(&request->msgptr, request->msgend);
+       if (!ttl) ttl = DefaultTTLforRRType(rrtype);
+       (void)flags; // Unused
+
+       if (!request->msgptr) { LogMsg("%3d: DNSServiceAddRecord(unreadable parameters)", request->sd); return(mStatus_BadParamErr); }
+
+       LogOperation("%3d: DNSServiceAddRecord(%##s, %s, %d)", request->sd,
+               (request->u.servicereg.instances) ? request->u.servicereg.instances->srs.RR_SRV.resrec.name->c : NULL, DNSTypeName(rrtype), rdlen);
+
+       for (i = request->u.servicereg.instances; i; i = i->next)
+               {
+               result = add_record_to_service(request, i, rrtype, rdlen, rdata, ttl);
+               if (result && i->default_local) break;
+               else result = mStatus_NoError;  // suppress non-local default errors
+               }
+
+       return(result);
+       }
+
+mDNSlocal void update_callback(mDNS *const m, AuthRecord *const rr, RData *oldrd)
+       {
+       (void)m; // Unused
+       if (oldrd != &rr->rdatastorage) freeL("RData/update_callback", oldrd);
+       }
+
+mDNSlocal mStatus update_record(AuthRecord *rr, mDNSu16 rdlen, char *rdata, mDNSu32 ttl)
+       {
+       int rdsize;
+       RData *newrd;
+       mStatus result;
+
+       if (rdlen > sizeof(RDataBody)) rdsize = rdlen;
+       else rdsize = sizeof(RDataBody);
+       newrd = mallocL("RData/update_record", sizeof(RData) - sizeof(RDataBody) + rdsize);
+       if (!newrd) FatalError("ERROR: malloc");
+       newrd->MaxRDLength = (mDNSu16) rdsize;
+       mDNSPlatformMemCopy(&newrd->u, rdata, rdlen);
+
+       // BIND named (name daemon) doesn't allow TXT records with zero-length rdata. This is strictly speaking correct,
+       // since RFC 1035 specifies a TXT record as "One or more <character-string>s", not "Zero or more <character-string>s".
+       // Since some legacy apps try to create zero-length TXT records, we'll silently correct it here.
+       if (rr->resrec.rrtype == kDNSType_TXT && rdlen == 0) { rdlen = 1; newrd->u.txt.c[0] = 0; }
+
+       result = mDNS_Update(&mDNSStorage, rr, ttl, rdlen, newrd, update_callback);
+       if (result) { LogMsg("ERROR: mDNS_Update - %ld", result); freeL("RData/update_record", newrd); }
+       return result;
+       }
+
+mDNSlocal mStatus handle_update_request(request_state *request)
+       {
+       mStatus result = mStatus_BadReferenceErr;
+       service_instance *i;
+       AuthRecord *rr = NULL;
+
+       // get the message data
+       DNSServiceFlags flags = get_flags(&request->msgptr, request->msgend);   // flags unused
+       mDNSu16 rdlen = get_uint16(&request->msgptr, request->msgend);
+       char *rdata = get_rdata(&request->msgptr, request->msgend, rdlen);
+       mDNSu32 ttl = get_uint32(&request->msgptr, request->msgend);
+       (void)flags; // Unused
+
+       if (!request->msgptr) { LogMsg("%3d: DNSServiceUpdateRecord(unreadable parameters)", request->sd); return(mStatus_BadParamErr); }
+
+       if (request->terminate == connection_termination)
+               {
+               // update an individually registered record
+               registered_record_entry *reptr;
+               for (reptr = request->u.reg_recs; reptr; reptr = reptr->next)
+                       {
+                       if (reptr->key == request->hdr.reg_index)
+                               {
+                               result = update_record(reptr->rr, rdlen, rdata, ttl);
+                               goto end;
+                               }
+                       }
+               result = mStatus_BadReferenceErr;
+               goto end;
+               }
+
+       // update a record from a service record set
+       for (i = request->u.servicereg.instances; i; i = i->next)
+               {
+               if (request->hdr.reg_index == TXT_RECORD_INDEX) rr = &i->srs.RR_TXT;
+               else
+                       {
+                       ExtraResourceRecord *e;
+                       for (e = i->srs.Extras; e; e = e->next)
+                               if (e->ClientID == request->hdr.reg_index) { rr = &e->r; break; }
+                       }
+
+               if (!rr) { result = mStatus_BadReferenceErr; goto end; }
+               result = update_record(rr, rdlen, rdata, ttl);
+               if (result && i->default_local) goto end;
+               else result = mStatus_NoError;  // suppress non-local default errors
+               }
+
+end:
+       LogOperation("%3d: DNSServiceUpdateRecord(%##s, %s)", request->sd,
+               (request->u.servicereg.instances) ? request->u.servicereg.instances->srs.RR_SRV.resrec.name->c : NULL,
+               rr ? DNSTypeName(rr->resrec.rrtype) : "<NONE>");
+
+       return(result);
+       }
+
+// remove a resource record registered via DNSServiceRegisterRecord()
+mDNSlocal mStatus remove_record(request_state *request)
+       {
+       mStatus err = mStatus_UnknownErr;
+       registered_record_entry *e, **ptr = &request->u.reg_recs;
+
+       while (*ptr && (*ptr)->key != request->hdr.reg_index) ptr = &(*ptr)->next;
+       if (!*ptr) { LogMsg("%3d: DNSServiceRemoveRecord(%u) not found", request->sd, request->hdr.reg_index); return mStatus_BadReferenceErr; }
+       e = *ptr;
+       *ptr = e->next; // unlink
+
+       LogOperation("%3d: DNSServiceRemoveRecord(%u %s)", request->sd, request->hdr.reg_index, RRDisplayString(&mDNSStorage, &e->rr->resrec));
+       e->rr->RecordContext = NULL;
+       err = mDNS_Deregister(&mDNSStorage, e->rr);
+       if (err)
+               {
+               LogMsg("ERROR: remove_record, mDNS_Deregister: %ld", err);
+               freeL("registered_record_entry AuthRecord remove_record", e->rr);
+               }
+       freeL("registered_record_entry remove_record", e);
+       return err;
+       }
+
+mDNSlocal mStatus remove_extra(const request_state *const request, service_instance *const serv, mDNSu16 *const rrtype)
+       {
+       mStatus err = mStatus_BadReferenceErr;
+       ExtraResourceRecord *ptr;
+
+       for (ptr = serv->srs.Extras; ptr; ptr = ptr->next)              
+               {
+               if (ptr->ClientID == request->hdr.reg_index) // found match
+                       {
+                       *rrtype = ptr->r.resrec.rrtype;
+                       return mDNS_RemoveRecordFromService(&mDNSStorage, &serv->srs, ptr, FreeExtraRR, ptr);
+                       }
+               }
+       return err;
+       }
+
+mDNSlocal mStatus handle_removerecord_request(request_state *request)
+       {
+       mStatus err = mStatus_BadReferenceErr;
+       get_flags(&request->msgptr, request->msgend);   // flags unused
+
+       if (!request->msgptr) { LogMsg("%3d: DNSServiceRemoveRecord(unreadable parameters)", request->sd); return(mStatus_BadParamErr); }
+
+       if (request->terminate == connection_termination)
+               err = remove_record(request);  // remove individually registered record
+       else
+               {
+               service_instance *i;
+               mDNSu16 rrtype = 0;
+               LogOperation("%3d: DNSServiceRemoveRecord(%##s, %s)", request->sd,
+                       (request->u.servicereg.instances) ? request->u.servicereg.instances->srs.RR_SRV.resrec.name->c : NULL,
+                       rrtype ? DNSTypeName(rrtype) : "<NONE>");
+               for (i = request->u.servicereg.instances; i; i = i->next)
+                       {
+                       err = remove_extra(request, i, &rrtype);
+                       if (err && i->default_local) break;
+                       else err = mStatus_NoError;  // suppress non-local default errors
+                       }
+               }
+
+       return(err);
+       }
+
+// If there's a comma followed by another character,
+// FindFirstSubType overwrites the comma with a nul and returns the pointer to the next character.
+// Otherwise, it returns a pointer to the final nul at the end of the string
+mDNSlocal char *FindFirstSubType(char *p)
+       {
+       while (*p)
+               {
+               if (p[0] == '\\' && p[1]) p += 2;
+               else if (p[0] == ',' && p[1]) { *p++ = 0; return(p); }
+               else p++;
+               }
+       return(p);
+       }
+
+// If there's a comma followed by another character,
+// FindNextSubType overwrites the comma with a nul and returns the pointer to the next character.
+// If it finds an illegal unescaped dot in the subtype name, it returns mDNSNULL
+// Otherwise, it returns a pointer to the final nul at the end of the string
+mDNSlocal char *FindNextSubType(char *p)
+       {
+       while (*p)
+               {
+               if (p[0] == '\\' && p[1])               // If escape character
+                       p += 2;                                         // ignore following character
+               else if (p[0] == ',')                   // If we found a comma
+                       {
+                       if (p[1]) *p++ = 0;
+                       return(p);
+                       }
+               else if (p[0] == '.')
+                       return(mDNSNULL);
+               else p++;
+               }
+       return(p);
+       }
+
+// Returns -1 if illegal subtype found
+mDNSexport mDNSs32 ChopSubTypes(char *regtype)
+       {
+       mDNSs32 NumSubTypes = 0;
+       char *stp = FindFirstSubType(regtype);
+       while (stp && *stp)                                     // If we found a comma...
+               {
+               if (*stp == ',') return(-1);
+               NumSubTypes++;
+               stp = FindNextSubType(stp);
+               }
+       if (!stp) return(-1);
+       return(NumSubTypes);
+       }
+
+mDNSexport AuthRecord *AllocateSubTypes(mDNSs32 NumSubTypes, char *p)
+       {
+       AuthRecord *st = mDNSNULL;
+       if (NumSubTypes)
+               {
+               mDNSs32 i;
+               st = mallocL("ServiceSubTypes", NumSubTypes * sizeof(AuthRecord));
+               if (!st) return(mDNSNULL);
+               for (i = 0; i < NumSubTypes; i++)
+                       {
+                       mDNS_SetupResourceRecord(&st[i], mDNSNULL, mDNSInterface_Any, kDNSQType_ANY, kStandardTTL, 0, mDNSNULL, mDNSNULL);
+                       while (*p) p++;
+                       p++;
+                       if (!MakeDomainNameFromDNSNameString(&st[i].namestorage, p))
+                               { freeL("ServiceSubTypes", st); return(mDNSNULL); }
+                       }
+               }
+       return(st);
+       }
+
+mDNSlocal mStatus register_service_instance(request_state *request, const domainname *domain)
+       {
+       service_instance **ptr, *instance;
+       int instance_size;
+       mStatus result;
+
+       for (ptr = &request->u.servicereg.instances; *ptr; ptr = &(*ptr)->next)
+               {
+               if (SameDomainName(&(*ptr)->domain, domain))
+                       { LogMsg("register_service_instance: domain %##s already registered", domain->c); return mStatus_AlreadyRegistered; }
+               }
+
+       // Special-case hack: We don't advertise SMB service in AutoTunnel domains, because AutoTunnel services have to support IPv6, and our SMB server does not
+       // <rdar://problem/5482322> BTMM: Don't advertise SMB with BTMM because it doesn't support IPv6
+       if (SameDomainName(&request->u.servicereg.type, (const domainname *) "\x4" "_smb" "\x4" "_tcp"))
+               {
+               DomainAuthInfo *AuthInfo = GetAuthInfoForName(&mDNSStorage, domain);
+               if (AuthInfo && AuthInfo->AutoTunnel) return(kDNSServiceErr_Unsupported);
+               }
+
+       instance_size = sizeof(*instance);
+       if (request->u.servicereg.txtlen > sizeof(RDataBody)) instance_size += (request->u.servicereg.txtlen - sizeof(RDataBody));
+       instance = mallocL("service_instance", instance_size);
+       if (!instance) { my_perror("ERROR: malloc"); return mStatus_NoMemoryErr; }
+
+       instance->next            = mDNSNULL;
+       instance->request         = request;
+       instance->sd              = request->sd;
+       instance->subtypes        = AllocateSubTypes(request->u.servicereg.num_subtypes, request->u.servicereg.type_as_string);
+       instance->renameonmemfree = 0;
+       instance->clientnotified  = mDNSfalse;
+       instance->default_local   = (request->u.servicereg.default_domain && SameDomainName(domain, &localdomain));
+       AssignDomainName(&instance->domain, domain);
+
+       if (request->u.servicereg.num_subtypes && !instance->subtypes)
+               { unlink_and_free_service_instance(instance); instance = NULL; FatalError("ERROR: malloc"); }
+
+       LogOperation("%3d: DNSServiceRegister(%#s.%##s%##s, %u) ADDING",
+               instance->sd, &request->u.servicereg.name, &request->u.servicereg.type, domain->c, mDNSVal16(request->u.servicereg.port));
+
+       result = mDNS_RegisterService(&mDNSStorage, &instance->srs,
+               &request->u.servicereg.name, &request->u.servicereg.type, domain,
+               request->u.servicereg.host.c[0] ? &request->u.servicereg.host : NULL,
+               request->u.servicereg.port,
+               request->u.servicereg.txtdata, request->u.servicereg.txtlen,
+               instance->subtypes, request->u.servicereg.num_subtypes,
+               request->u.servicereg.InterfaceID, regservice_callback, instance);
+
+       if (!result) *ptr = instance;           // Append this to the end of our request->u.servicereg.instances list
+       else
+               {
+               LogMsg("register_service_instance %#s.%##s%##s error %d",
+                       &request->u.servicereg.name, &request->u.servicereg.type, domain->c, result);
+               unlink_and_free_service_instance(instance);
+               }
+
+       return result;
+       }
+
+mDNSlocal void UpdateDeviceInfoRecord(mDNS *const m);
+
+mDNSlocal void regservice_termination_callback(request_state *request)
+       {
+       if (!request) { LogMsg("regservice_termination_callback context is NULL"); return; }
+       while (request->u.servicereg.instances)
+               {
+               service_instance *p = request->u.servicereg.instances;
+               request->u.servicereg.instances = request->u.servicereg.instances->next;
+               // only safe to free memory if registration is not valid, i.e. deregister fails (which invalidates p)
+               LogOperation("%3d: DNSServiceRegister(%##s, %u) STOP",
+                       request->sd, p->srs.RR_SRV.resrec.name->c, mDNSVal16(p->srs.RR_SRV.resrec.rdata->u.srv.port));
+
+               // Clear backpointer *before* calling mDNS_DeregisterService/unlink_and_free_service_instance
+               // We don't need unlink_and_free_service_instance to cut its element from the list, because we're already advancing
+               // request->u.servicereg.instances as we work our way through the list, implicitly cutting one element at a time
+               // We can't clear p->request *after* the calling mDNS_DeregisterService/unlink_and_free_service_instance
+               // because by then we might have already freed p
+               p->request = NULL;
+               if (mDNS_DeregisterService(&mDNSStorage, &p->srs)) unlink_and_free_service_instance(p);
+               // Don't touch service_instance *p after this -- it's likely to have been freed already
+               }
+       if (request->u.servicereg.txtdata)
+               { freeL("service_info txtdata", request->u.servicereg.txtdata); request->u.servicereg.txtdata = NULL; }
+       if (request->u.servicereg.autoname) UpdateDeviceInfoRecord(&mDNSStorage);
+       }
+
+mDNSlocal void udsserver_default_reg_domain_changed(const DNameListElem *const d, const mDNSBool add)
+       {
+       request_state *request;
+
+#if APPLE_OSX_mDNSResponder
+       machserver_automatic_registration_domain_changed(&d->name, add);
+#endif // APPLE_OSX_mDNSResponder
+
+       LogMsg("%s registration domain %##s", add ? "Adding" : "Removing", d->name.c);
+       for (request = all_requests; request; request = request->next)
+               {
+               if (request->terminate != regservice_termination_callback) continue;
+               if (!request->u.servicereg.default_domain) continue;
+               if (!d->uid || SystemUID(request->uid) || request->uid == d->uid)
+                       {
+                       service_instance **ptr = &request->u.servicereg.instances;
+                       while (*ptr && !SameDomainName(&(*ptr)->domain, &d->name)) ptr = &(*ptr)->next;
+                       if (add)
+                               {
+                               // If we don't already have this domain in our list for this registration, add it now
+                               if (!*ptr) register_service_instance(request, &d->name);
+                               else debugf("udsserver_default_reg_domain_changed %##s already in list, not re-adding", &d->name);
+                               }
+                       else
+                               {
+                               // Normally we should not fail to find the specified instance
+                               // One case where this can happen is if a uDNS update fails for some reason,
+                               // and regservice_callback then calls unlink_and_free_service_instance and disposes of that instance.
+                               if (!*ptr)
+                                       LogMsg("udsserver_default_reg_domain_changed domain %##s not found for service %#s type %s",
+                                               &d->name, request->u.servicereg.name.c, request->u.servicereg.type_as_string);
+                               else
+                                       {
+                                       DNameListElem *p;
+                                       for (p = AutoRegistrationDomains; p; p=p->next)
+                                               if (!p->uid || SystemUID(request->uid) || request->uid == p->uid)
+                                                       if (SameDomainName(&d->name, &p->name)) break;
+                                       if (p) debugf("udsserver_default_reg_domain_changed %##s still in list, not removing", &d->name);
+                                       else
+                                               {
+                                               mStatus err;
+                                               service_instance *si = *ptr;
+                                               *ptr = si->next;
+                                               if (si->clientnotified) SendServiceRemovalNotification(&si->srs); // Do this *before* clearing si->request backpointer
+                                               // Now that we've cut this service_instance from the list, we MUST clear the si->request backpointer.
+                                               // Otherwise what can happen is this: While our mDNS_DeregisterService is in the
+                                               // process of completing asynchronously, the client cancels the entire operation, so
+                                               // regservice_termination_callback then runs through the whole list deregistering each
+                                               // instance, clearing the backpointers, and then disposing the parent request_state object.
+                                               // However, because this service_instance isn't in the list any more, regservice_termination_callback
+                                               // has no way to find it and clear its backpointer, and then when our mDNS_DeregisterService finally
+                                               // completes later with a mStatus_MemFree message, it calls unlink_and_free_service_instance() with
+                                               // a service_instance with a stale si->request backpointer pointing to memory that's already been freed.
+                                               si->request = NULL;
+                                               err = mDNS_DeregisterService(&mDNSStorage, &si->srs);
+                                               if (err) { LogMsg("udsserver_default_reg_domain_changed err %d", err); unlink_and_free_service_instance(si); }
+                                               }
+                                       }
+                               }
+                       }
+               }
+       }
+
+mDNSlocal mStatus handle_regservice_request(request_state *request)
+       {
+       char name[256]; // Lots of spare space for extra-long names that we'll auto-truncate down to 63 bytes
+       char domain[MAX_ESCAPED_DOMAIN_NAME], host[MAX_ESCAPED_DOMAIN_NAME];
+       char type_as_string[MAX_ESCAPED_DOMAIN_NAME];
+       domainname d, srv;
+       mStatus err;
+
+       DNSServiceFlags flags = get_flags(&request->msgptr, request->msgend);
+       mDNSu32 interfaceIndex = get_uint32(&request->msgptr, request->msgend);
+       mDNSInterfaceID InterfaceID = mDNSPlatformInterfaceIDfromInterfaceIndex(&mDNSStorage, interfaceIndex);
+       if (interfaceIndex && !InterfaceID)
+               { LogMsg("ERROR: handle_regservice_request - Couldn't find interfaceIndex %d", interfaceIndex); return(mStatus_BadParamErr); }
+
+       if (get_string(&request->msgptr, request->msgend, name, sizeof(name)) < 0 ||
+               get_string(&request->msgptr, request->msgend, type_as_string, MAX_ESCAPED_DOMAIN_NAME) < 0 ||
+               get_string(&request->msgptr, request->msgend, domain, MAX_ESCAPED_DOMAIN_NAME) < 0 ||
+               get_string(&request->msgptr, request->msgend, host, MAX_ESCAPED_DOMAIN_NAME) < 0)
+               { LogMsg("ERROR: handle_regservice_request - Couldn't read name/regtype/domain"); return(mStatus_BadParamErr); }
+
+       request->u.servicereg.InterfaceID = InterfaceID;
+       request->u.servicereg.instances = NULL;
+       request->u.servicereg.txtlen  = 0;
+       request->u.servicereg.txtdata = NULL;
+       mDNSPlatformStrCopy(request->u.servicereg.type_as_string, type_as_string);
+
+       if (request->msgptr + 2 > request->msgend) request->msgptr = NULL;
+       else
+               {
+               request->u.servicereg.port.b[0] = *request->msgptr++;
+               request->u.servicereg.port.b[1] = *request->msgptr++;
+               }
+
+       request->u.servicereg.txtlen = get_uint16(&request->msgptr, request->msgend);
+       if (request->u.servicereg.txtlen)
+               {
+               request->u.servicereg.txtdata = mallocL("service_info txtdata", request->u.servicereg.txtlen);
+               if (!request->u.servicereg.txtdata) FatalError("ERROR: handle_regservice_request - malloc");
+               mDNSPlatformMemCopy(request->u.servicereg.txtdata, get_rdata(&request->msgptr, request->msgend, request->u.servicereg.txtlen), request->u.servicereg.txtlen);
+               }
+       else request->u.servicereg.txtdata = NULL;
 
-int udsserver_exit(void)
-    {
-       dnssd_close(listenfd);
+       if (!request->msgptr) { LogMsg("%3d: DNSServiceRegister(unreadable parameters)", request->sd); return(mStatus_BadParamErr); }
 
-#if !defined(USE_TCP_LOOPBACK)
-       // Currently, we're unable to remove /var/run/mdnsd because we've changed to userid "nobody"
-       // to give up unnecessary privilege, but we need to be root to remove this Unix Domain Socket.
-       // It would be nice if we could find a solution to this problem
-       if (unlink(MDNS_UDS_SERVERPATH))
-               debugf("Unable to remove %s", MDNS_UDS_SERVERPATH);
-#endif
+       // Check for sub-types after the service type
+       request->u.servicereg.num_subtypes = ChopSubTypes(request->u.servicereg.type_as_string);        // Note: Modifies regtype string to remove trailing subtypes
+       if (request->u.servicereg.num_subtypes < 0)
+               { LogMsg("ERROR: handle_regservice_request - ChopSubTypes failed %s", request->u.servicereg.type_as_string); return(mStatus_BadParamErr); }
 
-       if (PID_FILE[0]) unlink(PID_FILE);
+       // Don't try to construct "domainname t" until *after* ChopSubTypes has worked its magic
+       if (!*request->u.servicereg.type_as_string || !MakeDomainNameFromDNSNameString(&request->u.servicereg.type, request->u.servicereg.type_as_string))
+               { LogMsg("ERROR: handle_regservice_request - type_as_string bad %s", request->u.servicereg.type_as_string); return(mStatus_BadParamErr); }
 
-    return 0;
-    }
-
-mDNSs32 udsserver_idle(mDNSs32 nextevent)
-    {
-    request_state *req = all_requests, *tmp, *prev = NULL;
-    reply_state *fptr;
-    transfer_state result;
-    mDNSs32 now = mDNS_TimeNow(&mDNSStorage);
-
-    while(req)
-        {
-        result = t_uninitialized;
-        if (req->u_err)
-            result = send_undelivered_error(req);
-        if (result != t_error && result != t_morecoming &&             // don't try to send msg if send_error failed
-            (req->ts == t_complete || req->ts == t_morecoming))
-            {
-            while(req->replies)
-                {
-                if (req->replies->next) req->replies->rhdr->flags |= dnssd_htonl(kDNSServiceFlagsMoreComing);
-                result = send_msg(req->replies);
-                if (result == t_complete)
-                    {
-                    fptr = req->replies;
-                    req->replies = req->replies->next;
-                    freeL("udsserver_idle", fptr);
-                    req->time_blocked = 0;                              // reset failure counter after successful send
-                    }
-                else if (result == t_terminated || result == t_error)
-                    {
-                    abort_request(req);
-                    break;
-                    }
-                else if (result == t_morecoming) break;                        // client's queues are full, move to next
-                }
-            }
-        if (result == t_morecoming)
+       if (!name[0])
+               {
+               request->u.servicereg.name = mDNSStorage.nicelabel;
+               request->u.servicereg.autoname = mDNStrue;
+               }
+       else
+               {
+               // If the client is allowing AutoRename, then truncate name to legal length before converting it to a DomainLabel
+               if ((flags & kDNSServiceFlagsNoAutoRename) == 0)
                        {
-                       if (!req->time_blocked) req->time_blocked = now;
-                       debugf("udsserver_idle: client has been blocked for %ld seconds", (now - req->time_blocked) / mDNSPlatformOneSecond);
-                       if (now - req->time_blocked >= MAX_TIME_BLOCKED)
-                               {
-                               LogMsg("Could not write data to client %d after %ld seconds - aborting connection", req->sd, MAX_TIME_BLOCKED / mDNSPlatformOneSecond);
-                               LogClientInfo(req);
-                               abort_request(req);
-                               result = t_terminated;
-                               }
-                       else if (nextevent - now > mDNSPlatformOneSecond) nextevent = now + mDNSPlatformOneSecond;  // try again in a second
+                       int newlen = TruncateUTF8ToLength((mDNSu8*)name, mDNSPlatformStrLen(name), MAX_DOMAIN_LABEL);
+                       name[newlen] = 0;
                        }
-        if (result == t_terminated || result == t_error)
-        //since we're already doing a list traversal, we unlink the request manually instead of calling unlink_request()
-            {
-            tmp = req;
-            if (prev) prev->next = req->next;
-            if (req == all_requests) all_requests = all_requests->next;
-            req = req->next;
-            freeL("udsserver_idle", tmp);
-            }
-        else
-            {
-            prev = req;
-            req = req->next;
-            }
-        }
-    return nextevent;
-    }
+               if (!MakeDomainLabelFromLiteralString(&request->u.servicereg.name, name))
+                       { LogMsg("ERROR: handle_regservice_request - name bad %s", name); return(mStatus_BadParamErr); }
+               request->u.servicereg.autoname = mDNSfalse;
+               }
 
-mDNSexport void udsserver_info(mDNS *const m)
-    {
-       mDNSs32 now = mDNS_TimeNow(m);
-       mDNSu32 CacheUsed = 0, CacheActive = 0;
-       mDNSu32 slot;
-       CacheGroup *cg;
-       CacheRecord *rr;
-    request_state *req;
+       if (*domain)
+               {
+               request->u.servicereg.default_domain = mDNSfalse;
+               if (!MakeDomainNameFromDNSNameString(&d, domain))
+                       { LogMsg("ERROR: handle_regservice_request - domain bad %s", domain); return(mStatus_BadParamErr); }
+               }
+       else
+               {
+               request->u.servicereg.default_domain = mDNStrue;
+               MakeDomainNameFromDNSNameString(&d, "local.");
+               }
+
+       if (!ConstructServiceName(&srv, &request->u.servicereg.name, &request->u.servicereg.type, &d))
+               {
+               LogMsg("ERROR: handle_regservice_request - Couldn't ConstructServiceName from, “%#s” “%##s” “%##s”",
+                       request->u.servicereg.name.c, request->u.servicereg.type.c, d.c); return(mStatus_BadParamErr);
+               }
 
-    LogMsgNoIdent("Timenow 0x%08lX (%ld)", (mDNSu32)now, now);
+       if (!MakeDomainNameFromDNSNameString(&request->u.servicereg.host, host))
+               { LogMsg("ERROR: handle_regservice_request - host bad %s", host); return(mStatus_BadParamErr); }
+       request->u.servicereg.autorename       = (flags & kDNSServiceFlagsNoAutoRename    ) == 0;
+       request->u.servicereg.allowremotequery = (flags & kDNSServiceFlagsAllowRemoteQuery) != 0;
 
-    LogMsgNoIdent("Slt Q   TTL U Type  if     len rdata");
-       for (slot = 0; slot < CACHE_HASH_SLOTS; slot++)
-               for(cg = m->rrcache_hash[slot]; cg; cg=cg->next)
-                       {
-                       CacheUsed++;    // Count one cache entity for the CacheGroup object
-                       for (rr = cg->members; rr; rr=rr->next)
-                               {
-                               mDNSs32 remain = rr->resrec.rroriginalttl - (now - rr->TimeRcvd) / mDNSPlatformOneSecond;
-                               CacheUsed++;
-                               if (rr->CRActiveQuestion) CacheActive++;
-                               LogMsgNoIdent("%3d %s%6ld %s %-6s%-6s%s",
-                                       slot,
-                                       rr->CRActiveQuestion ? "*" : " ",
-                                       remain,
-                                       (rr->resrec.RecordType & kDNSRecordTypePacketUniqueMask) ? "-" : " ",
-                                       DNSTypeName(rr->resrec.rrtype),
-                                       ((NetworkInterfaceInfo *)rr->resrec.InterfaceID)->ifname,
-                                       CRDisplayString(m, rr));
-                               usleep(1000);   // Limit rate a little so we don't flood syslog too fast
-                               }
-                       }
+       // Some clients use mDNS for lightweight copy protection, registering a pseudo-service with
+       // a port number of zero. When two instances of the protected client are allowed to run on one
+       // machine, we don't want to see misleading "Bogus client" messages in syslog and the console.
+       if (!mDNSIPPortIsZero(request->u.servicereg.port))
+               {
+               int count = CountExistingRegistrations(&srv, request->u.servicereg.port);
+               if (count)
+                       LogMsg("Client application registered %d identical instances of service %##s port %u.",
+                               count+1, srv.c, mDNSVal16(request->u.servicereg.port));
+               }
 
-       if (m->rrcache_totalused != CacheUsed)
-               LogMsgNoIdent("Cache use mismatch: rrcache_totalused is %lu, true count %lu", m->rrcache_totalused, CacheUsed);
-       if (m->rrcache_active != CacheActive)
-               LogMsgNoIdent("Cache use mismatch: rrcache_active is %lu, true count %lu", m->rrcache_active, CacheActive);
-       LogMsgNoIdent("Cache currently contains %lu records; %lu referenced by active questions", CacheUsed, CacheActive);
+       LogOperation("%3d: DNSServiceRegister(\"%s\", \"%s\", \"%s\", \"%s\", %u) START",
+               request->sd, name, request->u.servicereg.type_as_string, domain, host, mDNSVal16(request->u.servicereg.port));
+       err = register_service_instance(request, &d);
 
-    for (req = all_requests; req; req=req->next)
-               LogClientInfo(req);
+       // Set request->terminate first, before adding additional service instances, because the
+       // uds_validatelists uses the request->terminate function pointer to determine what kind
+       // of request this is, and therefore what kind of list validation is required.
+       if (!err)
+               {
+               request->terminate = regservice_termination_callback;
+               if (request->u.servicereg.autoname) UpdateDeviceInfoRecord(&mDNSStorage);
+               }
 
-    now = mDNS_TimeNow(m);
-    LogMsgNoIdent("Timenow 0x%08lX (%ld)", (mDNSu32)now, now);
-    }
+       if (!err && !*domain)
+               {
+               DNameListElem *ptr;
+               // note that we don't report errors for non-local, non-explicit domains
+               for (ptr = AutoRegistrationDomains; ptr; ptr = ptr->next)
+                       if (!ptr->uid || SystemUID(request->uid) || request->uid == ptr->uid)
+                               register_service_instance(request, &ptr->name);
+               }
 
-#if __MACOSX__ && MACOSX_MDNS_MALLOC_DEBUGGING
-mDNSexport void uds_validatelists(void)
-       {
-       request_state *req;
-       for (req = all_requests; req; req=req->next)
-               if (req->sd < 0 && req->sd != -2)
-                       LogMemCorruption("UDS request list: %p is garbage (%X)", req, req->sd);
+       return(err);
        }
+
+// ***************************************************************************
+#if COMPILER_LIKES_PRAGMA_MARK
+#pragma mark -
+#pragma mark - DNSServiceBrowse
 #endif
 
-mDNSlocal void rename_service(service_instance *srv)
+mDNSlocal void FoundInstance(mDNS *const m, DNSQuestion *question, const ResourceRecord *const answer, QC_result AddRecord)
        {
-       if (srv->autoname && !SameDomainLabel(srv->name.c, gmDNS->nicelabel.c))
+       const DNSServiceFlags flags = AddRecord ? kDNSServiceFlagsAdd : 0;
+       request_state *req = question->QuestionContext;
+       reply_state *rep;
+       (void)m; // Unused
+
+       if (answer->rrtype != kDNSType_PTR)
+               { LogMsg("%3d: FoundInstance: Should not be called with rrtype %d (not a PTR record)", req->sd, answer->rrtype); return; }
+
+       if (GenerateNTDResponse(&answer->rdata->u.name, answer->InterfaceID, req, &rep, browse_reply_op, flags, mStatus_NoError) != mStatus_NoError)
                {
-               srv->rename_on_memfree = 1;
-               if (mDNS_DeregisterService(gmDNS, &srv->srs))   // If service deregistered already, we can re-register immediately
-                       regservice_callback(gmDNS, &srv->srs, mStatus_MemFree);
+               LogMsg("%3d: FoundInstance: %##s PTR %##s received from network is not valid DNS-SD service pointer",
+                       req->sd, answer->name->c, answer->rdata->u.name.c);
+               return;
                }
+
+       LogOperation("%3d: DNSServiceBrowse(%##s, %s) RESULT %s %d: %s",
+               req->sd, question->qname.c, DNSTypeName(question->qtype), AddRecord ? "Add" : "Rmv",
+               mDNSPlatformInterfaceIndexfromInterfaceID(m, answer->InterfaceID), RRDisplayString(m, answer));
+
+       append_reply(req, rep);
        }
 
-mDNSexport void udsserver_handle_configchange(void)
-    {
-    request_state *req;
+mDNSlocal mStatus add_domain_to_browser(request_state *info, const domainname *d)
+       {
+       browser_t *b, *p;
+       mStatus err;
 
-    for (req = all_requests; req; req = req->next)
-        {
-               if (req->service_registration)
-                       {
-                       service_instance *ptr;
-                       for (ptr = req->service_registration->instances; ptr; ptr = ptr->next)
-                               rename_service(ptr);
-                       }
+       for (p = info->u.browser.browsers; p; p = p->next)
+               {
+               if (SameDomainName(&p->domain, d))
+                       { debugf("add_domain_to_browser %##s already in list", d->c); return mStatus_AlreadyRegistered; }
                }
-    }
-
-mDNSlocal void connect_callback(void *info)
-    {
-    dnssd_sock_t sd;
-       dnssd_socklen_t len;
-       unsigned long optval;
-    dnssd_sockaddr_t cliaddr;
-    request_state *rstate;
-    (void)info; // Unused
-
-       len = (dnssd_socklen_t) sizeof(cliaddr);
-    
-       sd = accept(listenfd, (struct sockaddr*) &cliaddr, &len);
-
-    if (sd == dnssd_InvalidSocket)
-        {
-        if (dnssd_errno() == dnssd_EWOULDBLOCK) return;
-        my_perror("ERROR: accept");
-        return;
-       }
-    optval = 1;
-
-#ifdef SO_NOSIGPIPE
-       // Some environments (e.g. OS X) support turning off SIGPIPE for a socket
-    if (setsockopt(sd, SOL_SOCKET, SO_NOSIGPIPE, &optval, sizeof(optval)) < 0)
-       {
-        my_perror("ERROR: setsockopt - SO_NOSIGPIPE - aborting client");
-        dnssd_close(sd);
-        return;
-       }
-#endif
 
-#if defined(_WIN32)
-       if (ioctlsocket(sd, FIONBIO, &optval) != 0)
-#else
-       if (fcntl(sd, F_SETFL, O_NONBLOCK) != 0)
-#endif
-        {
-               my_perror("ERROR: fcntl(sd, F_SETFL, O_NONBLOCK) - aborting client");
-               dnssd_close(sd);
-               return;
+       b = mallocL("browser_t", sizeof(*b));
+       if (!b) return mStatus_NoMemoryErr;
+       AssignDomainName(&b->domain, d);
+       err = mDNS_StartBrowse(&mDNSStorage, &b->q,
+               &info->u.browser.regtype, d, info->u.browser.interface_id, info->u.browser.ForceMCast, FoundInstance, info);
+       if (err)
+               {
+               LogMsg("mDNS_StartBrowse returned %d for type %##s domain %##s", err, info->u.browser.regtype.c, d->c);
+               freeL("browser_t/add_domain_to_browser", b);
                }
-       
-       // allocate a request_state struct that will live with the socket
-    rstate = mallocL("connect_callback", sizeof(request_state));
-    if (!rstate) FatalError("ERROR: malloc");
-    bzero(rstate, sizeof(request_state));
-    rstate->ts = t_morecoming;
-    rstate->sd = sd;
-    
-       LogOperation("%3d: Adding FD", rstate->sd);
-    if ( mStatus_NoError != udsSupportAddFDToEventLoop( sd, request_callback, rstate))
-        return;
-    rstate->next = all_requests;
-    all_requests = rstate;
-    }
-
-// handler
-mDNSlocal void request_callback(void *info)
-       {
-       request_state *rstate = info;
-       transfer_state result;
-       dnssd_sockaddr_t cliaddr;
-       int dedicated_error_socket;
-#if defined(_WIN32)
-       u_long opt = 1;
-#endif
-       
-       result = read_msg(rstate);
-       if (result == t_morecoming)
+       else
                {
-               return;
+               b->next = info->u.browser.browsers;
+               info->u.browser.browsers = b;
                }
-       if (result == t_terminated)
+               return err;
+       }
+
+mDNSlocal void browse_termination_callback(request_state *info)
+       {
+       while (info->u.browser.browsers)
                {
-               abort_request(rstate);
-               unlink_request(rstate);
-               return;
+               browser_t *ptr = info->u.browser.browsers;
+               info->u.browser.browsers = ptr->next;
+               LogOperation("%3d: DNSServiceBrowse(%##s) STOP", info->sd, ptr->q.qname.c);
+               mDNS_StopBrowse(&mDNSStorage, &ptr->q);  // no need to error-check result
+               freeL("browser_t/browse_termination_callback", ptr);
                }
-       if (result == t_error)
+       }
+
+mDNSlocal void udsserver_automatic_browse_domain_changed(const DNameListElem *const d, const mDNSBool add)
+       {
+       request_state *request;
+       debugf("udsserver_automatic_browse_domain_changed: %s default browse domain %##s", add ? "Adding" : "Removing", d->name.c);
+
+#if APPLE_OSX_mDNSResponder
+       machserver_automatic_browse_domain_changed(&d->name, add);
+#endif // APPLE_OSX_mDNSResponder
+
+       for (request = all_requests; request; request = request->next)
                {
-               abort_request(rstate);
-               unlink_request(rstate);
-               return;
+               if (request->terminate != browse_termination_callback) continue;        // Not a browse operation
+               if (!request->u.browser.default_domain) continue;                                       // Not an auto-browse operation
+               if (!d->uid || SystemUID(request->uid) || request->uid == d->uid)
+                       {
+                       browser_t **ptr = &request->u.browser.browsers;
+                       while (*ptr && !SameDomainName(&(*ptr)->domain, &d->name)) ptr = &(*ptr)->next;
+                       if (add)
+                               {
+                               // If we don't already have this domain in our list for this browse operation, add it now
+                               if (!*ptr) add_domain_to_browser(request, &d->name);
+                               else debugf("udsserver_automatic_browse_domain_changed %##s already in list, not re-adding", &d->name);
+                               }
+                       else
+                               {
+                               if (!*ptr) LogMsg("udsserver_automatic_browse_domain_changed ERROR %##s not found", &d->name);
+                               else
+                                       {
+                                       DNameListElem *p;
+                                       for (p = AutoBrowseDomains; p; p=p->next)
+                                               if (!p->uid || SystemUID(request->uid) || request->uid == p->uid)
+                                                       if (SameDomainName(&d->name, &p->name)) break;
+                                       if (p) debugf("udsserver_automatic_browse_domain_changed %##s still in list, not removing", &d->name);
+                                       else
+                                               {
+                                               browser_t *remove = *ptr;
+                                               *ptr = (*ptr)->next;
+                                               mDNS_StopQueryWithRemoves(&mDNSStorage, &remove->q);
+                                               freeL("browser_t/udsserver_automatic_browse_domain_changed", remove);
+                                               }
+                                       }
+                               }
+                       }
                }
+       }
+
+mDNSlocal void FreeARElemCallback(mDNS *const m, AuthRecord *const rr, mStatus result)
+       {
+       (void)m;  // unused
+       if (result == mStatus_MemFree) mDNSPlatformMemFree(rr->RecordContext);
+       }
 
-       if (rstate->hdr.version != VERSION)
+mDNSlocal void RegisterLocalOnlyDomainEnumPTR(mDNS *m, const domainname *d, int type)
+       {
+       // allocate/register legacy and non-legacy _browse PTR record
+       mStatus err;
+       ARListElem *ptr = mDNSPlatformMemAllocate(sizeof(*ptr));
+
+       LogOperation("Incrementing %s refcount for %##s",
+               (type == mDNS_DomainTypeBrowse         ) ? "browse domain   " :
+               (type == mDNS_DomainTypeRegistration   ) ? "registration dom" :
+               (type == mDNS_DomainTypeBrowseAutomatic) ? "automatic browse" : "?", d->c);
+
+       mDNS_SetupResourceRecord(&ptr->ar, mDNSNULL, mDNSInterface_LocalOnly, kDNSType_PTR, 7200, kDNSRecordTypeShared, FreeARElemCallback, ptr);
+       MakeDomainNameFromDNSNameString(&ptr->ar.namestorage, mDNS_DomainTypeNames[type]);
+       AppendDNSNameString            (&ptr->ar.namestorage, "local");
+       AssignDomainName(&ptr->ar.resrec.rdata->u.name, d);
+       err = mDNS_Register(m, &ptr->ar);
+       if (err)
                {
-               LogMsg("ERROR: client incompatible with daemon (client version = %d, "
-                      "daemon version = %d)\n", rstate->hdr.version, VERSION);
-               abort_request(rstate);
-               unlink_request(rstate);
-               return;
+               LogMsg("SetSCPrefsBrowseDomain: mDNS_Register returned error %d", err);
+               mDNSPlatformMemFree(ptr);
                }
-       
-       if (validate_message(rstate) < 0)
+       else
                {
-               // note that we cannot deliver an error message if validation fails, since the path to the error socket
-               // may be contained in the (invalid) message body for some message types
-               abort_request(rstate);
-               unlink_request(rstate);
-               LogMsg("Invalid message sent by client - may indicate a malicious program running on this machine!");
-               return;
+               ptr->next = LocalDomainEnumRecords;
+               LocalDomainEnumRecords = ptr;
                }
-       
-       // check if client wants silent operation
-       if (rstate->hdr.flags & IPC_FLAGS_NOREPLY) rstate->no_reply = 1;
+       }
 
-       dedicated_error_socket = (rstate->hdr.op == reg_record_request    || rstate->hdr.op == add_record_request ||
-                                 rstate->hdr.op == update_record_request || rstate->hdr.op == remove_record_request);
-       
-       if (((rstate->hdr.flags & IPC_FLAGS_REUSE_SOCKET) == 0) != dedicated_error_socket)
-               LogMsg("WARNING: client request %d with incorrect flags setting 0x%X", rstate->hdr.op, rstate->hdr.flags);
+mDNSlocal void DeregisterLocalOnlyDomainEnumPTR(mDNS *m, const domainname *d, int type)
+       {
+       ARListElem **ptr = &LocalDomainEnumRecords;
+       domainname lhs; // left-hand side of PTR, for comparison
 
-       // check if primary socket is to be used for synchronous errors, else open new socket
-       if (dedicated_error_socket)
+       LogOperation("Decrementing %s refcount for %##s",
+               (type == mDNS_DomainTypeBrowse         ) ? "browse domain   " :
+               (type == mDNS_DomainTypeRegistration   ) ? "registration dom" :
+               (type == mDNS_DomainTypeBrowseAutomatic) ? "automatic browse" : "?", d->c);
+
+       MakeDomainNameFromDNSNameString(&lhs, mDNS_DomainTypeNames[type]);
+       AppendDNSNameString            (&lhs, "local");
+
+       while (*ptr)
                {
-               mStatus err = 0;
-               int nwritten;
-               dnssd_sock_t errfd = socket(AF_DNSSD, SOCK_STREAM, 0);
-               if (errfd == dnssd_InvalidSocket)
+               if (SameDomainName(&(*ptr)->ar.resrec.rdata->u.name, d) && SameDomainName((*ptr)->ar.resrec.name, &lhs))
                        {
-                       my_perror("ERROR: socket");
-                       abort_request(rstate);
-                       unlink_request(rstate);
+                       ARListElem *remove = *ptr;
+                       *ptr = (*ptr)->next;
+                       mDNS_Deregister(m, &remove->ar);
                        return;
                        }
+               else ptr = &(*ptr)->next;
+               }
+       }
 
-               //LogOperation("request_callback: Opened dedicated errfd %d", errfd);
+mDNSlocal void AddAutoBrowseDomain(const mDNSu32 uid, const domainname *const name)
+       {
+       DNameListElem *new = mDNSPlatformMemAllocate(sizeof(DNameListElem));
+       if (!new) { LogMsg("ERROR: malloc"); return; }
+       AssignDomainName(&new->name, name);
+       new->uid = uid;
+       new->next = AutoBrowseDomains;
+       AutoBrowseDomains = new;
+       udsserver_automatic_browse_domain_changed(new, mDNStrue);
+       }
 
-               #if defined(USE_TCP_LOOPBACK)
+mDNSlocal void RmvAutoBrowseDomain(const mDNSu32 uid, const domainname *const name)
+       {
+       DNameListElem **p = &AutoBrowseDomains;
+       while (*p && (!SameDomainName(&(*p)->name, name) || (*p)->uid != uid)) p = &(*p)->next;
+       if (!*p) LogMsg("RmvAutoBrowseDomain: Got remove event for domain %##s not in list", name->c);
+       else
+               {
+               DNameListElem *ptr = *p;
+               *p = ptr->next;
+               udsserver_automatic_browse_domain_changed(ptr, mDNSfalse);
+               mDNSPlatformMemFree(ptr);
+               }
+       }
+
+mDNSlocal void SetPrefsBrowseDomains(mDNS *m, DNameListElem *browseDomains, mDNSBool add)
+       {
+       DNameListElem *d;
+       for (d = browseDomains; d; d = d->next)
+               {
+               if (add)
                        {
-                       mDNSOpaque16 port;
-                       port.b[0] = rstate->msgdata[0];
-                       port.b[1] = rstate->msgdata[1];
-                       rstate->msgdata += 2;
-                       cliaddr.sin_family      = AF_INET;
-                       cliaddr.sin_port        = port.NotAnInteger;
-                       cliaddr.sin_addr.s_addr = inet_addr(MDNS_TCP_SERVERADDR);
+                       RegisterLocalOnlyDomainEnumPTR(m, &d->name, mDNS_DomainTypeBrowse);
+                       AddAutoBrowseDomain(d->uid, &d->name);
                        }
-               #else
+               else
                        {
-                       char ctrl_path[MAX_CTLPATH];
-                       get_string(&rstate->msgdata, ctrl_path, 256);   // path is first element in message buffer
-                       bzero(&cliaddr, sizeof(cliaddr));
-                       cliaddr.sun_family = AF_LOCAL;
-                       strcpy(cliaddr.sun_path, ctrl_path);
+                       DeregisterLocalOnlyDomainEnumPTR(m, &d->name, mDNS_DomainTypeBrowse);
+                       RmvAutoBrowseDomain(d->uid, &d->name);
                        }
-               #endif
-               //LogOperation("request_callback: Connecting to “%s”", cliaddr.sun_path);
-               if (connect(errfd, (struct sockaddr *)&cliaddr, sizeof(cliaddr)) < 0)
+               }
+       }
+
+mDNSlocal void UpdateDeviceInfoRecord(mDNS *const m)
+       {
+       int num_autoname = 0;
+       request_state *req;
+       for (req = all_requests; req; req = req->next)
+               if (req->terminate == regservice_termination_callback && req->u.servicereg.autoname)
+                       num_autoname++;
+
+       // If DeviceInfo record is currently registered, see if we need to deregister it
+       if (m->DeviceInfo.resrec.RecordType != kDNSRecordTypeUnregistered)
+               if (num_autoname == 0 || !SameDomainLabelCS(m->DeviceInfo.resrec.name->c, m->nicelabel.c))
                        {
-                       //LogOperation("request_callback: Couldn't connect to “%s”", cliaddr.sun_path);
-                       my_perror("ERROR: connect");
-                       abort_request(rstate);
-                       unlink_request(rstate);
-                       return;
+                       LogOperation("UpdateDeviceInfoRecord Deregister %##s", m->DeviceInfo.resrec.name);
+                       mDNS_Deregister(m, &m->DeviceInfo);
                        }
-#if defined(_WIN32)
-               if (ioctlsocket(errfd, FIONBIO, &opt) != 0)
-#else
-               if (fcntl(errfd, F_SETFL, O_NONBLOCK) != 0)
-#endif
+
+       // If DeviceInfo record is not currently registered, see if we need to register it
+       if (m->DeviceInfo.resrec.RecordType == kDNSRecordTypeUnregistered)
+               if (num_autoname > 0)
                        {
-                       my_perror("ERROR: could not set control socket to non-blocking mode");
-                       abort_request(rstate);
-                       unlink_request(rstate);
-                       return;
+                       mDNSu8 len = m->HIHardware.c[0] < 255 - 6 ? m->HIHardware.c[0] : 255 - 6;
+                       mDNS_SetupResourceRecord(&m->DeviceInfo, mDNSNULL, mDNSNULL, kDNSType_TXT, kStandardTTL, kDNSRecordTypeAdvisory, mDNSNULL, mDNSNULL);
+                       ConstructServiceName(&m->DeviceInfo.namestorage, &m->nicelabel, &DeviceInfoName, &localdomain);
+                       mDNSPlatformMemCopy(m->DeviceInfo.resrec.rdata->u.data + 1, "model=", 6);
+                       mDNSPlatformMemCopy(m->DeviceInfo.resrec.rdata->u.data + 7, m->HIHardware.c + 1, len);
+                       m->DeviceInfo.resrec.rdata->u.data[0] = 6 + len;        // "model=" plus the device string
+                       m->DeviceInfo.resrec.rdlength         = 7 + len;        // One extra for the length byte at the start of the string
+                       LogOperation("UpdateDeviceInfoRecord   Register %##s", m->DeviceInfo.resrec.name);
+                       mDNS_Register(m, &m->DeviceInfo);
+                       }
+       }
+
+mDNSexport void udsserver_handle_configchange(mDNS *const m)
+       {
+       request_state *req;
+       service_instance *ptr;
+       DNameListElem *RegDomains;
+       DNameListElem *BrowseDomains;
+       DNameListElem *p;
+
+       UpdateDeviceInfoRecord(m);
+
+       // For autoname services, see if the default service name has changed, necessitating an automatic update
+       for (req = all_requests; req; req = req->next)
+               if (req->terminate == regservice_termination_callback)
+                       if (req->u.servicereg.autoname && !SameDomainLabelCS(req->u.servicereg.name.c, m->nicelabel.c))
+                               {
+                               req->u.servicereg.name = m->nicelabel;
+                               for (ptr = req->u.servicereg.instances; ptr; ptr = ptr->next)
+                                       {
+                                       ptr->renameonmemfree = 1;
+                                       if (ptr->clientnotified) SendServiceRemovalNotification(&ptr->srs);
+                                       if (mDNS_DeregisterService(m, &ptr->srs)) // If service was deregistered already
+                                               regservice_callback(m, &ptr->srs, mStatus_MemFree); // we can re-register immediately
+                                       }
+                               }
+
+       // Let the platform layer get the current DNS information
+       mDNS_Lock(m);
+       mDNSPlatformSetDNSConfig(m, mDNSfalse, mDNSfalse, mDNSNULL, &RegDomains, &BrowseDomains);
+       mDNS_Unlock(m);
+
+       // Any automatic registration domains are also implicitly automatic browsing domains
+       if (RegDomains) SetPrefsBrowseDomains(m, RegDomains, mDNStrue);                                                         // Add the new list first
+       if (AutoRegistrationDomains) SetPrefsBrowseDomains(m, AutoRegistrationDomains, mDNSfalse);      // Then clear the old list
+
+       // Add any new domains not already in our AutoRegistrationDomains list
+       for (p=RegDomains; p; p=p->next)
+               {
+               DNameListElem **pp = &AutoRegistrationDomains;
+               while (*pp && ((*pp)->uid != p->uid || !SameDomainName(&(*pp)->name, &p->name))) pp = &(*pp)->next;
+               if (!*pp)               // If not found in our existing list, this is a new default registration domain
+                       {
+                       RegisterLocalOnlyDomainEnumPTR(m, &p->name, mDNS_DomainTypeRegistration);
+                       udsserver_default_reg_domain_changed(p, mDNStrue);
+                       }
+               else                    // else found same domainname in both old and new lists, so no change, just delete old copy
+                       {
+                       DNameListElem *del = *pp;
+                       *pp = (*pp)->next;
+                       mDNSPlatformMemFree(del);
                        }
+               }
+
+       // Delete any domains in our old AutoRegistrationDomains list that are now gone
+       while (AutoRegistrationDomains)
+               {
+               DNameListElem *del = AutoRegistrationDomains;
+               AutoRegistrationDomains = AutoRegistrationDomains->next;                // Cut record from list FIRST,
+               DeregisterLocalOnlyDomainEnumPTR(m, &del->name, mDNS_DomainTypeRegistration);
+               udsserver_default_reg_domain_changed(del, mDNSfalse);                   // before calling udsserver_default_reg_domain_changed()
+               mDNSPlatformMemFree(del);
+               }
+
+       // Now we have our new updated automatic registration domain list
+       AutoRegistrationDomains = RegDomains;
 
-               switch(rstate->hdr.op)
+       // Add new browse domains to internal list
+       if (BrowseDomains) SetPrefsBrowseDomains(m, BrowseDomains, mDNStrue);
+
+       // Remove old browse domains from internal list
+       if (SCPrefBrowseDomains)
+               {
+               SetPrefsBrowseDomains(m, SCPrefBrowseDomains, mDNSfalse);
+               while (SCPrefBrowseDomains)
                        {
-                       case reg_record_request:    err = handle_regrecord_request   (rstate); break;
-                       case add_record_request:    err = handle_add_request         (rstate); break;
-                       case update_record_request: err = handle_update_request      (rstate); break;
-                       case remove_record_request: err = handle_removerecord_request(rstate); break;
-                       default: LogMsg("%3d: ERROR: udsserver_recv_request - unsupported request type: %d", rstate->sd, rstate->hdr.op);
+                       DNameListElem *fptr = SCPrefBrowseDomains;
+                       SCPrefBrowseDomains = SCPrefBrowseDomains->next;
+                       mDNSPlatformMemFree(fptr);
                        }
+               }
+
+       // Replace the old browse domains array with the new array
+       SCPrefBrowseDomains = BrowseDomains;
+       }
+
+mDNSlocal void AutomaticBrowseDomainChange(mDNS *const m, DNSQuestion *q, const ResourceRecord *const answer, QC_result AddRecord)
+       {
+       (void)m; // unused;
+       (void)q; // unused
+
+       LogOperation("AutomaticBrowseDomainChange: %s automatic browse domain %##s",
+               AddRecord ? "Adding" : "Removing", answer->rdata->u.name.c);
+
+       if (AddRecord) AddAutoBrowseDomain(0, &answer->rdata->u.name);
+       else           RmvAutoBrowseDomain(0, &answer->rdata->u.name);
+       }
+
+mDNSlocal mStatus handle_browse_request(request_state *request)
+       {
+       char regtype[MAX_ESCAPED_DOMAIN_NAME], domain[MAX_ESCAPED_DOMAIN_NAME];
+       domainname typedn, d, temp;
+       mDNSs32 NumSubTypes;
+       mStatus err = mStatus_NoError;
+
+       DNSServiceFlags flags = get_flags(&request->msgptr, request->msgend);
+       mDNSu32 interfaceIndex = get_uint32(&request->msgptr, request->msgend);
+       mDNSInterfaceID InterfaceID = mDNSPlatformInterfaceIDfromInterfaceIndex(&mDNSStorage, interfaceIndex);
+       if (interfaceIndex && !InterfaceID) return(mStatus_BadParamErr);
+
+       if (get_string(&request->msgptr, request->msgend, regtype, MAX_ESCAPED_DOMAIN_NAME) < 0 ||
+               get_string(&request->msgptr, request->msgend, domain, MAX_ESCAPED_DOMAIN_NAME) < 0) return(mStatus_BadParamErr);
+
+       if (!request->msgptr) { LogMsg("%3d: DNSServiceBrowse(unreadable parameters)", request->sd); return(mStatus_BadParamErr); }
+
+       if (!domain || (domain[0] == '\0')) uDNS_RegisterSearchDomains(&mDNSStorage);
+
+       typedn.c[0] = 0;
+       NumSubTypes = ChopSubTypes(regtype);    // Note: Modifies regtype string to remove trailing subtypes
+       if (NumSubTypes < 0 || NumSubTypes > 1) return(mStatus_BadParamErr);
+       if (NumSubTypes == 1 && !AppendDNSNameString(&typedn, regtype + strlen(regtype) + 1)) return(mStatus_BadParamErr);
+
+       if (!regtype[0] || !AppendDNSNameString(&typedn, regtype)) return(mStatus_BadParamErr);
+
+       if (!MakeDomainNameFromDNSNameString(&temp, regtype)) return(mStatus_BadParamErr);
+       // For over-long service types, we only allow domain "local"
+       if (temp.c[0] > 15 && domain[0] == 0) mDNSPlatformStrCopy(domain, "local.");
+
+       // Set up browser info
+       request->u.browser.ForceMCast = (flags & kDNSServiceFlagsForceMulticast) != 0;
+       request->u.browser.interface_id = InterfaceID;
+       AssignDomainName(&request->u.browser.regtype, &typedn);
+       request->u.browser.default_domain = !domain[0];
+       request->u.browser.browsers = NULL;
+
+       LogOperation("%3d: DNSServiceBrowse(\"%##s\", \"%s\") START", request->sd, request->u.browser.regtype.c, domain);
+       if (domain[0])
+               {
+               if (!MakeDomainNameFromDNSNameString(&d, domain)) return(mStatus_BadParamErr);
+               err = add_domain_to_browser(request, &d);
+               }
+
+       else
+               {
+               DNameListElem *sdom;
+               for (sdom = AutoBrowseDomains; sdom; sdom = sdom->next)
+                       if (!sdom->uid || SystemUID(request->uid) || request->uid == sdom->uid)
+                               {
+                               err = add_domain_to_browser(request, &sdom->name);
+                               if (err)
+                                       {
+                                       if (SameDomainName(&sdom->name, &localdomain)) break;
+                                       else err = mStatus_NoError;  // suppress errors for non-local "default" domains
+                                       }
+                               }
+               }
+
+       if (!err) request->terminate = browse_termination_callback;
+
+       return(err);
+       }
+
+// ***************************************************************************
+#if COMPILER_LIKES_PRAGMA_MARK
+#pragma mark -
+#pragma mark - DNSServiceResolve
+#endif
+
+mDNSlocal void resolve_result_callback(mDNS *const m, DNSQuestion *question, const ResourceRecord *const answer, QC_result AddRecord)
+       {
+       size_t len = 0;
+       char fullname[MAX_ESCAPED_DOMAIN_NAME], target[MAX_ESCAPED_DOMAIN_NAME];
+       char *data;
+       reply_state *rep;
+       request_state *req = question->QuestionContext;
+       (void)m; // Unused
+
+       LogOperation("%3d: DNSServiceResolve(%##s, %s) %s %s",
+               req->sd, question->qname.c, DNSTypeName(question->qtype), AddRecord ? "ADD" : "RMV", RRDisplayString(m, answer));
+
+       // This code used to do this trick of just keeping a copy of the pointer to
+       // the answer record in the cache, but the unicast query code doesn't currently
+       // put its answer records in the cache, so for now we can't do this.
 
-               //LogOperation("request_callback: Returning error code %d on socket %d", err, errfd);
-               err = dnssd_htonl(err);
-               nwritten = send(errfd, (dnssd_sockbuf_t) &err, sizeof(err), 0);
-               // On a freshly-created Unix Domain Socket, the kernel should *never* fail to buffer a four-byte write for us.
-               // If not, we don't attempt to handle this failure, but we do log it.
-               if (nwritten < (int)sizeof(err))
-                       LogMsg("ERROR: failed to write error response back to caller: %d %d %s",
-                               nwritten, dnssd_errno(), dnssd_strerror(dnssd_errno()));
-               //else LogOperation("request_callback: Returned  error code %d on socket %d", err, errfd);
-               dnssd_close(errfd);
-               //LogOperation("request_callback: Closed errfd %d", errfd);
-               reset_connected_rstate(rstate);         // Reset ready to accept the next request on this pipe
+       if (!AddRecord)
+               {
+               if (answer->rrtype == kDNSType_SRV && req->u.resolve.srv == answer) req->u.resolve.srv = mDNSNULL;
+               if (answer->rrtype == kDNSType_TXT && req->u.resolve.txt == answer) req->u.resolve.txt = mDNSNULL;
+               return;
                }
-       else
+
+       if (answer->rrtype == kDNSType_SRV) req->u.resolve.srv = answer;
+       if (answer->rrtype == kDNSType_TXT) req->u.resolve.txt = answer;
+
+       if (!req->u.resolve.txt || !req->u.resolve.srv) return;         // only deliver result to client if we have both answers
+
+       ConvertDomainNameToCString(answer->name, fullname);
+       ConvertDomainNameToCString(&req->u.resolve.srv->rdata->u.srv.target, target);
+
+       // calculate reply length
+       len += sizeof(DNSServiceFlags);
+       len += sizeof(mDNSu32);  // interface index
+       len += sizeof(DNSServiceErrorType);
+       len += strlen(fullname) + 1;
+       len += strlen(target) + 1;
+       len += 2 * sizeof(mDNSu16);  // port, txtLen
+       len += req->u.resolve.txt->rdlength;
+
+       // allocate/init reply header
+       rep = create_reply(resolve_reply_op, len, req);
+       rep->rhdr->flags = dnssd_htonl(0);
+       rep->rhdr->ifi   = dnssd_htonl(mDNSPlatformInterfaceIndexfromInterfaceID(m, answer->InterfaceID));
+       rep->rhdr->error = dnssd_htonl(kDNSServiceErr_NoError);
+
+       data = rep->sdata;
+
+       // write reply data to message
+       put_string(fullname, &data);
+       put_string(target, &data);
+       *data++ = req->u.resolve.srv->rdata->u.srv.port.b[0];
+       *data++ = req->u.resolve.srv->rdata->u.srv.port.b[1];
+       put_uint16(req->u.resolve.txt->rdlength, &data);
+       put_rdata(req->u.resolve.txt->rdlength, req->u.resolve.txt->rdata->u.data, &data);
+
+       append_reply(req, rep);
+       }
+
+mDNSlocal void resolve_termination_callback(request_state *request)
+       {
+       LogOperation("%3d: DNSServiceResolve(%##s) STOP", request->sd, request->u.resolve.qtxt.qname.c);
+       mDNS_StopQuery(&mDNSStorage, &request->u.resolve.qtxt);
+       mDNS_StopQuery(&mDNSStorage, &request->u.resolve.qsrv);
+       }
+
+mDNSlocal mStatus handle_resolve_request(request_state *request)
+       {
+       char name[256], regtype[MAX_ESCAPED_DOMAIN_NAME], domain[MAX_ESCAPED_DOMAIN_NAME];
+       domainname fqdn;
+       mStatus err;
+
+       // extract the data from the message
+       DNSServiceFlags flags = get_flags(&request->msgptr, request->msgend);
+       mDNSu32 interfaceIndex = get_uint32(&request->msgptr, request->msgend);
+       mDNSInterfaceID InterfaceID = mDNSPlatformInterfaceIDfromInterfaceIndex(&mDNSStorage, interfaceIndex);
+       if (interfaceIndex && !InterfaceID)
+               { LogMsg("ERROR: handle_resolve_request bad interfaceIndex %d", interfaceIndex); return(mStatus_BadParamErr); }
+
+       if (get_string(&request->msgptr, request->msgend, name, 256) < 0 ||
+               get_string(&request->msgptr, request->msgend, regtype, MAX_ESCAPED_DOMAIN_NAME) < 0 ||
+               get_string(&request->msgptr, request->msgend, domain, MAX_ESCAPED_DOMAIN_NAME) < 0)
+               { LogMsg("ERROR: handle_resolve_request - Couldn't read name/regtype/domain"); return(mStatus_BadParamErr); }
+
+       if (!request->msgptr) { LogMsg("%3d: DNSServiceResolve(unreadable parameters)", request->sd); return(mStatus_BadParamErr); }
+
+       if (build_domainname_from_strings(&fqdn, name, regtype, domain) < 0)
+               { LogMsg("ERROR: handle_resolve_request bad “%s” “%s” “%s”", name, regtype, domain); return(mStatus_BadParamErr); }
+
+       mDNSPlatformMemZero(&request->u.resolve, sizeof(request->u.resolve));
+
+       // format questions
+       request->u.resolve.qsrv.InterfaceID      = InterfaceID;
+       request->u.resolve.qsrv.Target           = zeroAddr;
+       AssignDomainName(&request->u.resolve.qsrv.qname, &fqdn);
+       request->u.resolve.qsrv.qtype            = kDNSType_SRV;
+       request->u.resolve.qsrv.qclass           = kDNSClass_IN;
+       request->u.resolve.qsrv.LongLived        = (flags & kDNSServiceFlagsLongLivedQuery     ) != 0;
+       request->u.resolve.qsrv.ExpectUnique     = mDNStrue;
+       request->u.resolve.qsrv.ForceMCast       = (flags & kDNSServiceFlagsForceMulticast     ) != 0;
+       request->u.resolve.qsrv.ReturnIntermed   = (flags & kDNSServiceFlagsReturnIntermediates) != 0;
+       request->u.resolve.qsrv.QuestionCallback = resolve_result_callback;
+       request->u.resolve.qsrv.QuestionContext  = request;
+
+       request->u.resolve.qtxt.InterfaceID      = InterfaceID;
+       request->u.resolve.qtxt.Target           = zeroAddr;
+       AssignDomainName(&request->u.resolve.qtxt.qname, &fqdn);
+       request->u.resolve.qtxt.qtype            = kDNSType_TXT;
+       request->u.resolve.qtxt.qclass           = kDNSClass_IN;
+       request->u.resolve.qtxt.LongLived        = (flags & kDNSServiceFlagsLongLivedQuery     ) != 0;
+       request->u.resolve.qtxt.ExpectUnique     = mDNStrue;
+       request->u.resolve.qtxt.ForceMCast       = (flags & kDNSServiceFlagsForceMulticast     ) != 0;
+       request->u.resolve.qtxt.ReturnIntermed   = (flags & kDNSServiceFlagsReturnIntermediates) != 0;
+       request->u.resolve.qtxt.QuestionCallback = resolve_result_callback;
+       request->u.resolve.qtxt.QuestionContext  = request;
+
+       // ask the questions
+       LogOperation("%3d: DNSServiceResolve(%##s) START", request->sd, request->u.resolve.qsrv.qname.c);
+       err = mDNS_StartQuery(&mDNSStorage, &request->u.resolve.qsrv);
+       if (!err)
                {
-               switch(rstate->hdr.op)
-                       {
-                       case resolve_request:          handle_resolve_request   (rstate); break;
-                       case query_request:            handle_query_request     (rstate); break;
-                       case browse_request:           handle_browse_request    (rstate); break;
-                       case reg_service_request:      handle_regservice_request(rstate); break;
-                       case enumeration_request:      handle_enum_request      (rstate); break;
-                       case reconfirm_record_request: handle_reconfirm_request (rstate); break;
-                       case setdomain_request:        handle_setdomain_request (rstate); break;
-                       default: LogMsg("%3d: ERROR: udsserver_recv_request - unsupported request type: %d", rstate->sd, rstate->hdr.op);
-                       }
+               err = mDNS_StartQuery(&mDNSStorage, &request->u.resolve.qtxt);
+               if (err) mDNS_StopQuery(&mDNSStorage, &request->u.resolve.qsrv);
                }
+
+       if (!err) request->terminate = resolve_termination_callback;
+
+       return(err);
        }
 
-// mDNS operation functions.  Each operation has 3 associated functions - a request handler that parses
+// ***************************************************************************
+#if COMPILER_LIKES_PRAGMA_MARK
+#pragma mark -
+#pragma mark - DNSServiceQueryRecord
+#endif
+
+// mDNS operation functions. Each operation has 3 associated functions - a request handler that parses
 // the client's request and makes the appropriate mDNSCore call, a result handler (passed as a callback
 // to the mDNSCore routine) that sends results back to the client, and a termination routine that aborts
 // the mDNSCore operation if the client dies or closes its socket.
@@ -1462,2229 +2487,1378 @@ mDNSlocal void request_callback(void *info)
 // massage the name parameters appropriately, but the rest of the operations (making the query call,
 // delivering the result to the client, and termination) are identical.
 
-mDNSlocal void handle_query_request(request_state *rstate)
-    {
-    DNSServiceFlags flags;
-    uint32_t ifi;
-    char name[256];
-    uint16_t rrtype, rrclass;
-    char *ptr;
-    mStatus result;
-    mDNSInterfaceID InterfaceID;
-       DNSQuestion *q;
-       
-    if (rstate->ts != t_complete)
-        {
-        LogMsg("ERROR: handle_query_request - transfer state != t_complete");
-        goto error;
-        }
-    ptr = rstate->msgdata;
-    if (!ptr)
-        {
-        LogMsg("ERROR: handle_query_request - NULL msgdata");
-        goto error;
-        }
-       
-    flags = get_flags(&ptr);
-    ifi = get_long(&ptr);
-    if (get_string(&ptr, name, 256) < 0) goto bad_param;
-    rrtype = get_short(&ptr);
-    rrclass = get_short(&ptr);
-       InterfaceID = mDNSPlatformInterfaceIDfromInterfaceIndex(gmDNS, ifi);
-    if (ifi && !InterfaceID) goto bad_param;
-
-    q = mallocL("DNSQuestion", sizeof(DNSQuestion));
-    if (!q) FatalError("ERROR: handle_query - malloc");
-    bzero(q, sizeof(DNSQuestion));
-
-    q->InterfaceID      = InterfaceID;
-    q->Target           = zeroAddr;
-    if (!MakeDomainNameFromDNSNameString(&q->qname, name)) { freeL("DNSQuestion", q); goto bad_param; }
-    q->qtype            = rrtype;
-    q->qclass           = rrclass;
-    q->LongLived        = (flags & kDNSServiceFlagsLongLivedQuery) != 0;
-    q->ExpectUnique     = mDNSfalse;
-    q->ForceMCast       = (flags & kDNSServiceFlagsForceMulticast) != 0;
-    q->QuestionCallback = question_result_callback;
-    q->QuestionContext  = rstate;
-
-    rstate->termination_context = q;
-    rstate->terminate = question_termination_callback;
-
-       LogOperation("%3d: DNSServiceQueryRecord(%##s, %s) START", rstate->sd, q->qname.c, DNSTypeName(q->qtype));
-    result = mDNS_StartQuery(gmDNS, q);
-    if (result != mStatus_NoError) LogMsg("ERROR: mDNS_StartQuery: %d", (int)result);
-       
-    if (result) rstate->terminate = NULL;
-    if (deliver_error(rstate, result) < 0) goto error;
-    return;
-    
-bad_param:
-    deliver_error(rstate, mStatus_BadParamErr);
-    rstate->terminate = NULL;  // don't try to terminate insuccessful Core calls
-error:
-    abort_request(rstate);
-    unlink_request(rstate);
-    return;
-    }
-
-mDNSlocal void handle_resolve_request(request_state *rstate)
-    {
-    DNSServiceFlags flags;
-    uint32_t interfaceIndex;
-    mDNSInterfaceID InterfaceID;
-    char name[256], regtype[MAX_ESCAPED_DOMAIN_NAME], domain[MAX_ESCAPED_DOMAIN_NAME];
-    char *ptr;  // message data pointer
-    domainname fqdn;
-    resolve_termination_t *term;
-    mStatus err;
-    
-    if (rstate->ts != t_complete)
-        {
-        LogMsg("ERROR: handle_resolve_request - transfer state != t_complete");
-        abort_request(rstate);
-        unlink_request(rstate);
-        return;
-        }
-        
-    // extract the data from the message
-    ptr = rstate->msgdata;
-    if (!ptr)
-        {
-        LogMsg("ERROR: handle_resolve_request - NULL msgdata");
-        abort_request(rstate);
-        unlink_request(rstate);
-        return;
-        }
-    flags = get_flags(&ptr);
-    interfaceIndex = get_long(&ptr);
-    InterfaceID = mDNSPlatformInterfaceIDfromInterfaceIndex(gmDNS, interfaceIndex);
-    if (interfaceIndex && !InterfaceID)
-       { LogMsg("ERROR: handle_resolve_request - Couldn't find InterfaceID for interfaceIndex %d", interfaceIndex); goto bad_param; }
-    if (get_string(&ptr, name, 256) < 0 ||
-        get_string(&ptr, regtype, MAX_ESCAPED_DOMAIN_NAME) < 0 ||
-        get_string(&ptr, domain, MAX_ESCAPED_DOMAIN_NAME) < 0)
-       { LogMsg("ERROR: handle_resolve_request - Couldn't read name/regtype/domain"); goto bad_param; }
-
-    // free memory in rstate since we don't need it anymore
-    freeL("handle_resolve_request", rstate->msgbuf);
-    rstate->msgbuf = NULL;
-
-    if (build_domainname_from_strings(&fqdn, name, regtype, domain) < 0)
-       { LogMsg("ERROR: handle_resolve_request - Couldn't build_domainname_from_strings “%s” “%s” “%s”", name, regtype, domain); goto bad_param; }
-
-    // set up termination info
-    term = mallocL("handle_resolve_request", sizeof(resolve_termination_t));
-    bzero(term, sizeof(*term));
-    if (!term) FatalError("ERROR: malloc");
-
-    // format questions
-    term->qsrv.InterfaceID      = InterfaceID;
-    term->qsrv.Target           = zeroAddr;
-    memcpy(&term->qsrv.qname, &fqdn, MAX_DOMAIN_NAME);
-    term->qsrv.qtype            = kDNSType_SRV;
-    term->qsrv.qclass           = kDNSClass_IN;
-    term->qsrv.LongLived        = mDNSfalse;
-    term->qsrv.ExpectUnique     = mDNStrue;
-       term->qsrv.ForceMCast       = mDNSfalse;
-    term->qsrv.QuestionCallback = resolve_result_callback;
-    term->qsrv.QuestionContext  = rstate;
-    
-    term->qtxt.InterfaceID      = InterfaceID;
-    term->qtxt.Target           = zeroAddr;
-    memcpy(&term->qtxt.qname, &fqdn, MAX_DOMAIN_NAME);
-    term->qtxt.qtype            = kDNSType_TXT;
-    term->qtxt.qclass           = kDNSClass_IN;
-    term->qtxt.LongLived        = mDNSfalse;
-    term->qtxt.ExpectUnique     = mDNStrue;
-       term->qtxt.ForceMCast       = mDNSfalse;
-    term->qtxt.QuestionCallback = resolve_result_callback;
-    term->qtxt.QuestionContext  = rstate;
-
-    term->rstate = rstate;
-    rstate->termination_context = term;
-    rstate->terminate = resolve_termination_callback;
-    
-    // ask the questions
-       LogOperation("%3d: DNSServiceResolve(%##s) START", rstate->sd, term->qsrv.qname.c);
-    err = mDNS_StartQuery(gmDNS, &term->qsrv);
-    if (!err) err = mDNS_StartQuery(gmDNS, &term->qtxt);
-
-    if (err)
-        {
-        freeL("handle_resolve_request", term);
-        rstate->terminate = NULL;  // prevent abort_request() from invoking termination callback
-        }
-    if (deliver_error(rstate, err) < 0 || err)
-        {
-        abort_request(rstate);
-        unlink_request(rstate);
-        }
-    return;
-
-bad_param:
-    deliver_error(rstate, mStatus_BadParamErr);
-    abort_request(rstate);
-    unlink_request(rstate);
-    }
-    
-mDNSlocal void resolve_termination_callback(void *context)
-    {
-    resolve_termination_t *term = context;
-    request_state *rs;
-    
-    if (!term)
-        {
-        LogMsg("ERROR: resolve_termination_callback: double termination");
-        return;
-        }
-    rs = term->rstate;
-       LogOperation("%3d: DNSServiceResolve(%##s) STOP", rs->sd, term->qtxt.qname.c);
-    
-    mDNS_StopQuery(gmDNS, &term->qtxt);
-    mDNS_StopQuery(gmDNS, &term->qsrv);
-    
-    freeL("resolve_termination_callback", term);
-    rs->termination_context = NULL;
-    }
-
-mDNSlocal void resolve_result_callback(mDNS *const m, DNSQuestion *question, const ResourceRecord *const answer, mDNSBool AddRecord)
-       {
-    size_t len = 0;
-    char fullname[MAX_ESCAPED_DOMAIN_NAME], target[MAX_ESCAPED_DOMAIN_NAME];
-    char *data;
-    transfer_state result;
-    reply_state *rep;
-    request_state *rs = question->QuestionContext;
-    resolve_termination_t *res = rs->termination_context;
-    (void)m; // Unused
+// what gets called when a resolve is completed and we need to send the data back to the client
+mDNSlocal void queryrecord_result_callback(mDNS *const m, DNSQuestion *question, const ResourceRecord *const answer, QC_result AddRecord)
+       {
+       char name[MAX_ESCAPED_DOMAIN_NAME];
+       request_state *req = question->QuestionContext;
+       reply_state *rep;
+       char *data;
+       size_t len;
+       DNSServiceErrorType error = kDNSServiceErr_NoError;
+       (void)m; // Unused
 
-       LogOperation("%3d: DNSServiceResolve(%##s, %s) %s %s",
-               rs->sd, question->qname.c, DNSTypeName(question->qtype), AddRecord ? "ADD" : "RMV", RRDisplayString(m, answer));
-    
-    // This code used to do this trick of just keeping a copy of the pointer to
-    // the answer record in the cache, but the unicast query code doesn't currently
-    // put its answer records in the cache, so for now we can't do this.
-    
-       if (!AddRecord)
+       LogOperation("%3d: %s(%##s, %s) %s %s", req->sd,
+               req->hdr.op == query_request ? "DNSServiceQueryRecord" : "DNSServiceGetAddrInfo",
+               question->qname.c, DNSTypeName(question->qtype), AddRecord ? "ADD" : "RMV", RRDisplayString(m, answer));
+
+       if (answer->RecordType == kDNSRecordTypePacketNegative)
                {
-               // After unicast query code is updated to store its records in the common cache, use this...
-               // if (answer->rrtype == kDNSType_SRV && res->srv == answer) res->srv = mDNSNULL;
-               // if (answer->rrtype == kDNSType_TXT && res->txt == answer) res->txt = mDNSNULL;
-               // intead of this...
-               if (answer->rrtype == kDNSType_SRV && res->srv &&                                    SameRDataBody(answer, (RDataBody *)&res->srvdata))
-                       res->srv = mDNSfalse;
-               if (answer->rrtype == kDNSType_TXT && res->txt && answer->rdlength == res->txtlen && SameRDataBody(answer, (RDataBody *)&res->txtdata))
-                       res->txt = mDNSfalse;
-               return;
+               error = kDNSServiceErr_NoSuchRecord;
+               ConvertDomainNameToCString(&question->qname, name);
+               AddRecord = mDNStrue;
                }
+       else
+               ConvertDomainNameToCString(answer->name, name);
 
-       // After unicast query code is updated to store its records in the common cache, use this...
-    // if (answer->rrtype == kDNSType_SRV) res->srv = answer;
-    // if (answer->rrtype == kDNSType_TXT) res->txt = answer;
-       // intead of this...
-    if (answer->rrtype == kDNSType_SRV)
-               {
-               // Don't copy structure in its entirety, because the CacheEntity may be an intentionally truncated object
-               // (to economize on space) and reading past the end may run into unmapped memory, causing a crash.
-               //res->srvdata = answer->rdata->u.srv;
-               // The AssignDomainName() macro is smart enough to only copy the valid part of the name, and not
-               // try to copy the full 255 bytes which may not all be there.
-               AssignDomainName(&res->srvdata.target, &answer->rdata->u.srv.target);
-               res->srvdata.port = answer->rdata->u.srv.port;
-               res->srv = mDNStrue;
-               }
-    if (answer->rrtype == kDNSType_TXT)
-       {
-       if (answer->rdlength > AbsoluteMaxDNSMessageData) return;
-       res->txtlen = answer->rdlength;
-       mDNSPlatformMemCopy(answer->rdata->u.data, res->txtdata, res->txtlen);
-       res->txt = mDNStrue;
-       }
-
-    if (!res->txt || !res->srv) return;                // only deliver result to client if we have both answers
-    
-    ConvertDomainNameToCString(answer->name, fullname);
-    ConvertDomainNameToCString(&res->srvdata.target, target);
-
-    // calculate reply length
-    len += sizeof(DNSServiceFlags);
-    len += sizeof(uint32_t);  // interface index
-    len += sizeof(DNSServiceErrorType);
-    len += strlen(fullname) + 1;
-    len += strlen(target) + 1;
-    len += 2 * sizeof(uint16_t);  // port, txtLen
-    len += res->txtlen;
-    
-    // allocate/init reply header
-    rep =  create_reply(resolve_reply, len, rs);
-    rep->rhdr->flags = dnssd_htonl(0);
-    rep->rhdr->ifi   = dnssd_htonl(mDNSPlatformInterfaceIndexfromInterfaceID(gmDNS, answer->InterfaceID));
-    rep->rhdr->error = dnssd_htonl(kDNSServiceErr_NoError);
-
-    data = rep->sdata;
-    
-    // write reply data to message
-    put_string(fullname, &data);
-    put_string(target, &data);
-       *data++ = res->srvdata.port.b[0];
-       *data++ = res->srvdata.port.b[1];
-    put_short(res->txtlen, &data);
-    put_rdata(res->txtlen, res->txtdata, &data);
-    
-    result = send_msg(rep);
-    if (result == t_error || result == t_terminated)
-        {
-        abort_request(rs);
-        unlink_request(rs);
-        freeL("resolve_result_callback", rep);
-        }
-    else if (result == t_complete) freeL("resolve_result_callback", rep);
-    else append_reply(rs, rep);
-    }
+       len = sizeof(DNSServiceFlags);  // calculate reply data length
+       len += sizeof(mDNSu32);         // interface index
+       len += sizeof(DNSServiceErrorType);
+       len += strlen(name) + 1;
+       len += 3 * sizeof(mDNSu16);     // type, class, rdlen
+       len += answer->rdlength;
+       len += sizeof(mDNSu32);         // TTL
 
-// what gets called when a resolve is completed and we need to send the data back to the client
-mDNSlocal void question_result_callback(mDNS *const m, DNSQuestion *question, const ResourceRecord *const answer, mDNSBool AddRecord)
-    {
-    char *data;
-    char name[MAX_ESCAPED_DOMAIN_NAME];
-    request_state *req = question->QuestionContext;
-    reply_state *rep;
-    size_t len;
-    (void)m; // Unused
-
-       LogOperation("%3d: DNSServiceQueryRecord(%##s, %s) RESULT %s", req->sd, question->qname.c, DNSTypeName(question->qtype), RRDisplayString(m, answer));
-    //mDNS_StopQuery(m, question);
-    
-    // calculate reply data length
-    len = sizeof(DNSServiceFlags);
-    len += 2 * sizeof(uint32_t);  // if index + ttl
-    len += sizeof(DNSServiceErrorType);
-    len += 3 * sizeof(uint16_t); // type, class, rdlen
-    len += answer->rdlength;
-    ConvertDomainNameToCString(answer->name, name);
-    len += strlen(name) + 1;
-    
-    rep =  create_reply(query_reply, len, req);
-
-    rep->rhdr->flags = dnssd_htonl(AddRecord ? kDNSServiceFlagsAdd : 0);
-    rep->rhdr->ifi   = dnssd_htonl(mDNSPlatformInterfaceIndexfromInterfaceID(gmDNS, answer->InterfaceID));
-    rep->rhdr->error = dnssd_htonl(kDNSServiceErr_NoError);
-
-    data = rep->sdata;
-    
-    put_string(name, &data);
-    put_short(answer->rrtype, &data);
-    put_short(answer->rrclass, &data);
-    put_short(answer->rdlength, &data);
-    put_rdata(answer->rdlength, answer->rdata->u.data, &data);
-    put_long(AddRecord ? answer->rroriginalttl : 0, &data);
-
-    append_reply(req, rep);
-    return;
-    }
-
-mDNSlocal void question_termination_callback(void *context)
-    {
-    DNSQuestion *q = context;
-       LogOperation("%3d: DNSServiceQueryRecord(%##s, %s) STOP", ((request_state *)q->QuestionContext)->sd, q->qname.c, DNSTypeName(q->qtype));
-    mDNS_StopQuery(gmDNS, q);  // no need to error check
-    freeL("question_termination_callback", q);
-    }
+       rep = create_reply(req->hdr.op == query_request ? query_reply_op : addrinfo_reply_op, len, req);
 
-// If there's a comma followed by another character,
-// FindFirstSubType overwrites the comma with a nul and returns the pointer to the next character.
-// Otherwise, it returns a pointer to the final nul at the end of the string
-mDNSlocal char *FindFirstSubType(char *p)
-       {
-       while (*p)
+       rep->rhdr->flags = dnssd_htonl(AddRecord ? kDNSServiceFlagsAdd : 0);
+       rep->rhdr->ifi   = dnssd_htonl(mDNSPlatformInterfaceIndexfromInterfaceID(m, answer->InterfaceID));
+       rep->rhdr->error = dnssd_htonl(error);
+
+       data = rep->sdata;
+
+       put_string(name, &data);
+
+       if (answer->RecordType == kDNSRecordTypePacketNegative)
                {
-               if (p[0] == '\\' && p[1]) p += 2;
-               else if (p[0] == ',' && p[1]) { *p++ = 0; return(p); }
-               else p++;
+               put_uint16(question->qtype, &data);
+               put_uint16(question->qclass, &data);
+               put_uint16(0, &data);
+               put_rdata(0, mDNSNULL, &data);
+               put_uint32(0, &data);
                }
-       return(p);
+       else
+               {
+               put_uint16(answer->rrtype, &data);
+               put_uint16(answer->rrclass, &data);
+               put_uint16(answer->rdlength, &data);
+               //put_rdata(answer->rdlength, answer->rdata->u.data, &data);
+               if (!putRData(mDNSNULL, (mDNSu8 *)data, (mDNSu8 *)rep->rhdr + len, answer))
+                       LogMsg("queryrecord_result_callback putRData failed %d", (mDNSu8 *)rep->rhdr + len - (mDNSu8 *)data);
+               data += answer->rdlength;
+               put_uint32(AddRecord ? answer->rroriginalttl : 0, &data);
+               }
+
+       append_reply(req, rep);
        }
 
-// If there's a comma followed by another character,
-// FindNextSubType overwrites the comma with a nul and returns the pointer to the next character.
-// If it finds an illegal unescaped dot in the subtype name, it returns mDNSNULL
-// Otherwise, it returns a pointer to the final nul at the end of the string
-mDNSlocal char *FindNextSubType(char *p)
+mDNSlocal void queryrecord_termination_callback(request_state *request)
        {
-       while (*p)
-               {
-               if (p[0] == '\\' && p[1])               // If escape character
-                       p += 2;                                         // ignore following character
-               else if (p[0] == ',')                   // If we found a comma
-                       {
-                       if (p[1]) *p++ = 0;
-                       return(p);
-                       }
-               else if (p[0] == '.')
-                       return(mDNSNULL);
-               else p++;
-               }
-       return(p);
+       LogOperation("%3d: DNSServiceQueryRecord(%##s, %s) STOP",
+               request->sd, request->u.queryrecord.q.qname.c, DNSTypeName(request->u.queryrecord.q.qtype));
+       mDNS_StopQuery(&mDNSStorage, &request->u.queryrecord.q);  // no need to error check
        }
 
-// Returns -1 if illegal subtype found
-mDNSexport mDNSs32 ChopSubTypes(char *regtype)
+mDNSlocal mStatus handle_queryrecord_request(request_state *request)
        {
-       mDNSs32 NumSubTypes = 0;
-       char *stp = FindFirstSubType(regtype);
-       while (stp && *stp)                                     // If we found a comma...
-               {
-               if (*stp == ',') return(-1);
-               NumSubTypes++;
-               stp = FindNextSubType(stp);
-               }
-       if (!stp) return(-1);
-       return(NumSubTypes);
+       char name[256];
+       mDNSu16 rrtype, rrclass;
+       mStatus err;
+
+       DNSServiceFlags flags = get_flags(&request->msgptr, request->msgend);
+       mDNSu32 interfaceIndex = get_uint32(&request->msgptr, request->msgend);
+       mDNSInterfaceID InterfaceID = mDNSPlatformInterfaceIDfromInterfaceIndex(&mDNSStorage, interfaceIndex);
+       if (interfaceIndex && !InterfaceID) return(mStatus_BadParamErr);
+
+       if (get_string(&request->msgptr, request->msgend, name, 256) < 0) return(mStatus_BadParamErr);
+       rrtype  = get_uint16(&request->msgptr, request->msgend);
+       rrclass = get_uint16(&request->msgptr, request->msgend);
+
+       if (!request->msgptr) { LogMsg("%3d: DNSServiceQueryRecord(unreadable parameters)", request->sd); return(mStatus_BadParamErr); }
+
+       mDNSPlatformMemZero(&request->u.queryrecord.q, sizeof(&request->u.queryrecord.q));
+
+       request->u.queryrecord.q.InterfaceID      = InterfaceID;
+       request->u.queryrecord.q.Target           = zeroAddr;
+       if (!MakeDomainNameFromDNSNameString(&request->u.queryrecord.q.qname, name)) return(mStatus_BadParamErr);
+       request->u.queryrecord.q.qtype            = rrtype;
+       request->u.queryrecord.q.qclass           = rrclass;
+       request->u.queryrecord.q.LongLived        = (flags & kDNSServiceFlagsLongLivedQuery     ) != 0;
+       request->u.queryrecord.q.ExpectUnique     = mDNSfalse;
+       request->u.queryrecord.q.ForceMCast       = (flags & kDNSServiceFlagsForceMulticast     ) != 0;
+       request->u.queryrecord.q.ReturnIntermed   = (flags & kDNSServiceFlagsReturnIntermediates) != 0;
+       request->u.queryrecord.q.QuestionCallback = queryrecord_result_callback;
+       request->u.queryrecord.q.QuestionContext  = request;
+
+       LogOperation("%3d: DNSServiceQueryRecord(%##s, %s, %X) START",
+               request->sd, request->u.queryrecord.q.qname.c, DNSTypeName(request->u.queryrecord.q.qtype), flags);
+       err = mDNS_StartQuery(&mDNSStorage, &request->u.queryrecord.q);
+       if (err) LogMsg("ERROR: mDNS_StartQuery: %d", (int)err);
+
+       if (!err) request->terminate = queryrecord_termination_callback;
+
+       return(err);
        }
 
-mDNSexport AuthRecord *AllocateSubTypes(mDNSs32 NumSubTypes, char *p)
+// ***************************************************************************
+#if COMPILER_LIKES_PRAGMA_MARK
+#pragma mark -
+#pragma mark - DNSServiceEnumerateDomains
+#endif
+
+mDNSlocal reply_state *format_enumeration_reply(request_state *request,
+       const char *domain, DNSServiceFlags flags, mDNSu32 ifi, DNSServiceErrorType err)
        {
-       AuthRecord *st = mDNSNULL;
-       if (NumSubTypes)
-               {
-               mDNSs32 i;
-               st = mallocL("ServiceSubTypes", NumSubTypes * sizeof(AuthRecord));
-               if (!st) return(mDNSNULL);
-               for (i = 0; i < NumSubTypes; i++)
-                       {
-                       mDNS_SetupResourceRecord(&st[i], mDNSNULL, mDNSInterface_Any, kDNSQType_ANY, kStandardTTL, 0, mDNSNULL, mDNSNULL);
-                       while (*p) p++;
-                       p++;
-                       if (!MakeDomainNameFromDNSNameString(st[i].resrec.name, p))
-                               { freeL("ServiceSubTypes", st); return(mDNSNULL); }
-                       }
-               }
-       return(st);
+       size_t len;
+       reply_state *reply;
+       char *data;
+
+       len = sizeof(DNSServiceFlags);
+       len += sizeof(mDNSu32);
+       len += sizeof(DNSServiceErrorType);
+       len += strlen(domain) + 1;
+
+       reply = create_reply(enumeration_reply_op, len, request);
+       reply->rhdr->flags = dnssd_htonl(flags);
+       reply->rhdr->ifi = dnssd_htonl(ifi);
+       reply->rhdr->error = dnssd_htonl(err);
+       data = reply->sdata;
+       put_string(domain, &data);
+       return reply;
        }
 
-#ifdef _HAVE_SETDOMAIN_SUPPORT_
-mDNSlocal void free_defdomain(mDNS *const m, AuthRecord *const rr, mStatus result)
+mDNSlocal void enum_termination_callback(request_state *request)
        {
-       (void)m;  // unused
-       if (result == mStatus_MemFree) free(rr->RecordContext);  // context is the enclosing list structure
+       mDNS_StopGetDomains(&mDNSStorage, &request->u.enumeration.q_all);
+       mDNS_StopGetDomains(&mDNSStorage, &request->u.enumeration.q_default);
        }
-#endif
 
-mDNSlocal void handle_setdomain_request(request_state *request)
+mDNSlocal void enum_result_callback(mDNS *const m,
+       DNSQuestion *const question, const ResourceRecord *const answer, QC_result AddRecord)
        {
-       mStatus err = mStatus_NoError;
-       char *ptr;
-       char domainstr[MAX_ESCAPED_DOMAIN_NAME];
-       domainname domain;
-       DNSServiceFlags flags;
-#ifdef _HAVE_SETDOMAIN_SUPPORT_
-       struct xucred xuc;
-       socklen_t xuclen;
-#endif
+       char domain[MAX_ESCAPED_DOMAIN_NAME];
+       request_state *request = question->QuestionContext;
+       DNSServiceFlags flags = 0;
+       reply_state *reply;
+       (void)m; // Unused
+
+       if (answer->rrtype != kDNSType_PTR) return;
        
-       if (request->ts != t_complete)
-        {
-        LogMsg("ERROR: handle_setdomain_request - transfer state != t_complete");
-        abort_request(request);
-        unlink_request(request);
-        return;
-        }
-
-    // extract flags/domain from message
-    ptr = request->msgdata;
-    flags = get_flags(&ptr);
-    if (get_string(&ptr, domainstr, MAX_ESCAPED_DOMAIN_NAME) < 0 ||
-               !MakeDomainNameFromDNSNameString(&domain, domainstr))
-               { err = mStatus_BadParamErr; goto end; }
-
-       freeL("handle_setdomain_request", request->msgbuf);
-    request->msgbuf = NULL;
-
-       debugf("%3d: DNSServiceSetDefaultDomainForUser(%##s)", request->sd, domain.c);
-
-#ifdef _HAVE_SETDOMAIN_SUPPORT_
-    // this functionality currently only used for Apple-specific configuration, so we don't burned other platforms by mandating
-       // the existence of this socket option
-       xuclen = sizeof(xuc);
-       if (getsockopt(request->sd, 0, LOCAL_PEERCRED, &xuc, &xuclen))
-               { my_perror("ERROR: getsockopt, LOCAL_PEERCRED"); err = mStatus_UnknownErr; goto end; }
-       if (xuc.cr_version != XUCRED_VERSION) { LogMsg("getsockopt, LOCAL_PEERCRED - bad version"); err = mStatus_UnknownErr; goto end; }
-       LogMsg("Default domain %s %s for UID %d", domainstr, flags & kDNSServiceFlagsAdd ? "set" : "removed", xuc.cr_uid);
-
-       if (flags & kDNSServiceFlagsAdd)
-               {
-               // register a local-only PRT record
-               default_browse_list_t *newelem = malloc(sizeof(default_browse_list_t));
-               if (!newelem) { LogMsg("ERROR: malloc"); err = mStatus_NoMemoryErr; goto end; }
-               mDNS_SetupResourceRecord(&newelem->ptr_rec, mDNSNULL, mDNSInterface_LocalOnly, kDNSType_PTR, 7200,  kDNSRecordTypeShared, free_defdomain, newelem);
-               MakeDomainNameFromDNSNameString(&newelem->ptr_rec.resrec.name, mDNS_DomainTypeNames[mDNS_DomainTypeBrowseDefault]);
-               AppendDNSNameString            (&newelem->ptr_rec.resrec.name, "local");
-               AssignDomainName(&newelem->ptr_rec.resrec.rdata->u.name, &domain);
-               newelem->uid = xuc.cr_uid;
-               err = mDNS_Register(gmDNS, &newelem->ptr_rec);
-               if (err) free(newelem);
-               else
-                       {
-                       // link into list
-                       newelem->next = default_browse_list;
-                       default_browse_list = newelem;
-                       }
-               
-               }
-       else
+       // We only return add/remove events for the browse and registration lists
+       // For the default browse and registration answers, we only give an "ADD" event
+       if (question == &request->u.enumeration.q_default && !AddRecord) return;
+
+       if (AddRecord)
                {
-               // remove - find in list, deregister
-               default_browse_list_t *ptr = default_browse_list, *prev = NULL;
-               while (ptr)
-                       {
-                       if (SameDomainName(&ptr->ptr_rec.resrec.rdata->u.name, &domain))
-                               {
-                               if (prev) prev->next = ptr->next;
-                               else default_browse_list = ptr->next;
-                               err = mDNS_Deregister(gmDNS, &ptr->ptr_rec);
-                               break;
-                               }
-                       prev = ptr;
-                       ptr = ptr->next;
-                       }
-               if (!ptr) { LogMsg("Attempt to remove nonexistent domain %s for UID %d", domainstr, xuc.cr_uid); err = mStatus_Invalid; }
+               flags |= kDNSServiceFlagsAdd;
+               if (question == &request->u.enumeration.q_default) flags |= kDNSServiceFlagsDefault;
                }
-#else
-       err = mStatus_NoError;
-#endif // _HAVE_SETDOMAIN_SUPPORT_
-       
-       end:
-    deliver_error(request, err);
-    abort_request(request);
-    unlink_request(request);
-    }
 
-// Generates a response message giving name, type, domain, plus interface index,
-// suitable for a browse result or service registration result.
-// On successful completion rep is set to point to a malloc'd reply_state struct
-mDNSlocal mStatus GenerateNTDResponse(domainname *servicename, mDNSInterfaceID id, request_state *request, reply_state **rep)
+       ConvertDomainNameToCString(&answer->rdata->u.name, domain);
+       // Note that we do NOT propagate specific interface indexes to the client - for example, a domain we learn from
+       // a machine's system preferences may be discovered on the LocalOnly interface, but should be browsed on the
+       // network, so we just pass kDNSServiceInterfaceIndexAny
+       reply = format_enumeration_reply(request, domain, flags, kDNSServiceInterfaceIndexAny, kDNSServiceErr_NoError);
+       if (!reply) { LogMsg("ERROR: enum_result_callback, format_enumeration_reply"); return; }
+       append_reply(request, reply);
+       }
+
+mDNSlocal mStatus handle_enum_request(request_state *request)
        {
-       domainlabel name;
-       domainname type, dom;
-       *rep = NULL;
-       if (!DeconstructServiceName(servicename, &name, &type, &dom))
-               return kDNSServiceErr_Invalid;
-       else
-               {
-               char namestr[MAX_DOMAIN_LABEL+1];
-               char typestr[MAX_ESCAPED_DOMAIN_NAME];
-               char domstr [MAX_ESCAPED_DOMAIN_NAME];
-               int len;
-               char *data;
+       mStatus err;
+       DNSServiceFlags flags = get_flags(&request->msgptr, request->msgend);
+       DNSServiceFlags reg = flags & kDNSServiceFlagsRegistrationDomains;
+       mDNS_DomainType t_all     = reg ? mDNS_DomainTypeRegistration        : mDNS_DomainTypeBrowse;
+       mDNS_DomainType t_default = reg ? mDNS_DomainTypeRegistrationDefault : mDNS_DomainTypeBrowseDefault;
+       mDNSu32 interfaceIndex = get_uint32(&request->msgptr, request->msgend);
+       mDNSInterfaceID InterfaceID = mDNSPlatformInterfaceIDfromInterfaceIndex(&mDNSStorage, interfaceIndex);
+       if (interfaceIndex && !InterfaceID) return(mStatus_BadParamErr);
+
+       if (!request->msgptr) { LogMsg("%3d: DNSServiceEnumerateDomains(unreadable parameters)", request->sd); return(mStatus_BadParamErr); }
+
+       // allocate context structures
+       uDNS_RegisterSearchDomains(&mDNSStorage);
+
+       // enumeration requires multiple questions, so we must link all the context pointers so that
+       // necessary context can be reached from the callbacks
+       request->u.enumeration.q_all    .QuestionContext = request;
+       request->u.enumeration.q_default.QuestionContext = request;
        
-               ConvertDomainLabelToCString_unescaped(&name, namestr);
-               ConvertDomainNameToCString(&type, typestr);
-               ConvertDomainNameToCString(&dom, domstr);
-               
-               // Calculate reply data length
-               len = sizeof(DNSServiceFlags);
-               len += sizeof(uint32_t);  // if index
-               len += sizeof(DNSServiceErrorType);
-               len += (int) (strlen(namestr) + 1);
-               len += (int) (strlen(typestr) + 1);
-               len += (int) (strlen(domstr) + 1);
-               
-               // Build reply header
-               *rep = create_reply(query_reply, len, request);
-               (*rep)->rhdr->flags = dnssd_htonl(0);
-               (*rep)->rhdr->ifi   = dnssd_htonl(mDNSPlatformInterfaceIndexfromInterfaceID(gmDNS, id));
-               (*rep)->rhdr->error = dnssd_htonl(kDNSServiceErr_NoError);
-               
-               // Build reply body
-               data = (*rep)->sdata;
-               put_string(namestr, &data);
-               put_string(typestr, &data);
-               put_string(domstr, &data);
+       // if the caller hasn't specified an explicit interface, we use local-only to get the system-wide list.
+       if (!InterfaceID) InterfaceID = mDNSInterface_LocalOnly;
 
-               return mStatus_NoError;
+       // make the calls
+       LogOperation("%3d: DNSServiceEnumerateDomains(%X=%s)", request->sd, flags,
+               (flags & kDNSServiceFlagsBrowseDomains      ) ? "kDNSServiceFlagsBrowseDomains" :
+               (flags & kDNSServiceFlagsRegistrationDomains) ? "kDNSServiceFlagsRegistrationDomains" : "<<Unknown>>");
+       err = mDNS_GetDomains(&mDNSStorage, &request->u.enumeration.q_all, t_all, NULL, InterfaceID, enum_result_callback, request);
+       if (!err)
+               {
+               err = mDNS_GetDomains(&mDNSStorage, &request->u.enumeration.q_default, t_default, NULL, InterfaceID, enum_result_callback, request);
+               if (err) mDNS_StopGetDomains(&mDNSStorage, &request->u.enumeration.q_all);
                }
+       if (!err) request->terminate = enum_termination_callback;
+
+       return(err);
        }
 
-mDNSlocal void FoundInstance(mDNS *const m, DNSQuestion *question, const ResourceRecord *const answer, mDNSBool AddRecord)
+// ***************************************************************************
+#if COMPILER_LIKES_PRAGMA_MARK
+#pragma mark -
+#pragma mark - DNSServiceReconfirmRecord & Misc
+#endif
+
+mDNSlocal mStatus handle_reconfirm_request(request_state *request)
        {
-       request_state *req = question->QuestionContext;
-       reply_state *rep;
-       (void)m; // Unused
+       mStatus status = mStatus_BadParamErr;
+       AuthRecord *rr = read_rr_from_ipc_msg(request, 0, 0);
+       if (rr)
+               {
+               status = mDNS_ReconfirmByValue(&mDNSStorage, &rr->resrec);
+               LogOperation(
+                       (status == mStatus_NoError) ?
+                       "%3d: DNSServiceReconfirmRecord(%s) interface %d initiated" :
+                       "%3d: DNSServiceReconfirmRecord(%s) interface %d failed: %d",
+                       request->sd, RRDisplayString(&mDNSStorage, &rr->resrec),
+                       mDNSPlatformInterfaceIndexfromInterfaceID(&mDNSStorage, rr->resrec.InterfaceID), status);
+               freeL("AuthRecord/handle_reconfirm_request", rr);
+               }
+       return(status);
+       }
 
-       if (answer->rrtype != kDNSType_PTR)
-               { LogMsg("%3d: FoundInstance: Should not be called with rrtype %d (not a PTR record)", req->sd, answer->rrtype); return; }
+mDNSlocal mStatus handle_setdomain_request(request_state *request)
+       {
+       char domainstr[MAX_ESCAPED_DOMAIN_NAME];
+       domainname domain;
+       DNSServiceFlags flags = get_flags(&request->msgptr, request->msgend);
+       (void)flags; // Unused
+       if (get_string(&request->msgptr, request->msgend, domainstr, MAX_ESCAPED_DOMAIN_NAME) < 0 ||
+               !MakeDomainNameFromDNSNameString(&domain, domainstr))
+               { LogMsg("%3d: DNSServiceSetDefaultDomainForUser(unreadable parameters)", request->sd); return(mStatus_BadParamErr); }
+
+       LogOperation("%3d: DNSServiceSetDefaultDomainForUser(%##s)", request->sd, domain.c);
+       return(mStatus_NoError);
+       }
+
+typedef packedstruct
+       {
+       mStatus err;
+       mDNSu32 len;
+       mDNSu32 vers;
+       } DaemonVersionReply;
 
-       if (GenerateNTDResponse(&answer->rdata->u.name, answer->InterfaceID, req, &rep) != mStatus_NoError)
+mDNSlocal void handle_getproperty_request(request_state *request)
+       {
+       const mStatus BadParamErr = dnssd_htonl(mStatus_BadParamErr);
+       char prop[256];
+       if (get_string(&request->msgptr, request->msgend, prop, sizeof(prop)) >= 0)
                {
-               LogMsg("%3d: FoundInstance: %##s PTR %##s received from network is not valid DNS-SD service pointer",
-                       req->sd, answer->name->c, answer->rdata->u.name.c);
-               return;
+               LogOperation("%3d: DNSServiceGetProperty(%s)", request->sd, prop);
+               if (!strcmp(prop, kDNSServiceProperty_DaemonVersion))
+                       {
+                       DaemonVersionReply x = { 0, dnssd_htonl(4), dnssd_htonl(_DNS_SD_H) };
+                       send_all(request->sd, (const char *)&x, sizeof(x));
+                       return;
+                       }
                }
 
-       LogOperation("%3d: DNSServiceBrowse(%##s, %s) RESULT %s %s",
-               req->sd, question->qname.c, DNSTypeName(question->qtype), AddRecord ? "Add" : "Rmv", RRDisplayString(m, answer));
+       // If we didn't recogize the requested property name, return BadParamErr
+       send_all(request->sd, (const char *)&BadParamErr, sizeof(BadParamErr));
+       }
 
-       if (AddRecord) rep->rhdr->flags |= dnssd_htonl(kDNSServiceFlagsAdd);
-       append_reply(req, rep);
+// ***************************************************************************
+#if COMPILER_LIKES_PRAGMA_MARK
+#pragma mark -
+#pragma mark - DNSServiceNATPortMappingCreate
+#endif
+
+#define DNSServiceProtocol(X) ((X) == NATOp_AddrRequest ? 0 : (X) == NATOp_MapUDP ? kDNSServiceProtocol_UDP : kDNSServiceProtocol_TCP)
+
+mDNSlocal void port_mapping_termination_callback(request_state *request)
+       {
+       LogOperation("%3d: DNSServiceNATPortMappingCreate(%X, %u, %u, %d) STOP", request->sd,
+               DNSServiceProtocol(request->u.pm.NATinfo.Protocol),
+               mDNSVal16(request->u.pm.NATinfo.IntPort), mDNSVal16(request->u.pm.ReqExt), request->u.pm.NATinfo.NATLease);
+       mDNS_StopNATOperation(&mDNSStorage, &request->u.pm.NATinfo);
        }
 
-mDNSlocal mStatus add_domain_to_browser(browser_info_t *info, const domainname *d)
+// Called via function pointer when we get a NAT-PMP address request or port mapping response
+mDNSlocal void port_mapping_create_request_callback(mDNS *m, NATTraversalInfo *n)
        {
-       browser_t *b, *p;
-       mStatus err;
+       request_state *request = (request_state *)n->clientContext;
+       reply_state *rep;
+       int replyLen;
+       char *data;
+
+       if (!request) { LogMsg("port_mapping_create_request_callback called with unknown request_state object"); return; }
+
+       // calculate reply data length
+       replyLen = sizeof(DNSServiceFlags);
+       replyLen += 3 * sizeof(mDNSu32);  // if index + addr + ttl
+       replyLen += sizeof(DNSServiceErrorType);
+       replyLen += 2 * sizeof(mDNSu16);  // Internal Port + External Port
+       replyLen += sizeof(mDNSu8);       // protocol
+
+       rep = create_reply(port_mapping_reply_op, replyLen, request);
+
+       rep->rhdr->flags = dnssd_htonl(0);
+       rep->rhdr->ifi   = dnssd_htonl(mDNSPlatformInterfaceIndexfromInterfaceID(m, n->InterfaceID));
+       rep->rhdr->error = dnssd_htonl(n->Result);
+
+       data = rep->sdata;
+
+       *data++ = request->u.pm.NATinfo.ExternalAddress.b[0];
+       *data++ = request->u.pm.NATinfo.ExternalAddress.b[1];
+       *data++ = request->u.pm.NATinfo.ExternalAddress.b[2];
+       *data++ = request->u.pm.NATinfo.ExternalAddress.b[3];
+       *data++ = DNSServiceProtocol(request->u.pm.NATinfo.Protocol);
+       *data++ = request->u.pm.NATinfo.IntPort.b[0];
+       *data++ = request->u.pm.NATinfo.IntPort.b[1];
+       *data++ = request->u.pm.NATinfo.ExternalPort.b[0];
+       *data++ = request->u.pm.NATinfo.ExternalPort.b[1];
+       put_uint32(request->u.pm.NATinfo.Lifetime, &data);
+
+       LogOperation("%3d: DNSServiceNATPortMappingCreate(%X, %u, %u, %d) RESULT %.4a:%u TTL %u", request->sd,
+               DNSServiceProtocol(request->u.pm.NATinfo.Protocol),
+               mDNSVal16(request->u.pm.NATinfo.IntPort), mDNSVal16(request->u.pm.ReqExt), request->u.pm.NATinfo.NATLease,
+               &request->u.pm.NATinfo.ExternalAddress, mDNSVal16(request->u.pm.NATinfo.ExternalPort), request->u.pm.NATinfo.Lifetime);
+
+       append_reply(request, rep);
+       }
+
+mDNSlocal mStatus handle_port_mapping_request(request_state *request)
+       {
+       mDNSu32 ttl = 0;
+       mStatus err = mStatus_NoError;
 
-       for (p = info->browsers; p; p = p->next)
+       DNSServiceFlags flags          = get_flags(&request->msgptr, request->msgend);
+       mDNSu32         interfaceIndex = get_uint32(&request->msgptr, request->msgend);
+       mDNSInterfaceID InterfaceID    = mDNSPlatformInterfaceIDfromInterfaceIndex(&mDNSStorage, interfaceIndex);
+       mDNSu8          protocol       = get_uint32(&request->msgptr, request->msgend);
+       (void)flags; // Unused
+       if (interfaceIndex && !InterfaceID) return(mStatus_BadParamErr);
+       if (request->msgptr + 8 > request->msgend) request->msgptr = NULL;
+       else
                {
-               if (SameDomainName(&p->domain, d))
-                       { debugf("add_domain_to_browser - attempt to add domain %##d already in list", d->c); return mStatus_AlreadyRegistered; }
+               request->u.pm.NATinfo.IntPort.b[0] = *request->msgptr++;
+               request->u.pm.NATinfo.IntPort.b[1] = *request->msgptr++;
+               request->u.pm.ReqExt.b[0]          = *request->msgptr++;
+               request->u.pm.ReqExt.b[1]          = *request->msgptr++;
+               ttl = get_uint32(&request->msgptr, request->msgend);
                }
 
-       b = mallocL("browser_t", sizeof(*b));
-       if (!b) return mStatus_NoMemoryErr;
-       AssignDomainName(&b->domain, d);
-       err = mDNS_StartBrowse(gmDNS, &b->q, &info->regtype, d, info->interface_id, info->ForceMCast, FoundInstance, info->rstate);
-       if (err)
+       if (!request->msgptr) { LogMsg("%3d: DNSServiceNATPortMappingCreate(unreadable parameters)", request->sd); return(mStatus_BadParamErr); }
+
+       if (protocol == 0)      // If protocol == 0 (i.e. just request public address) then IntPort, ExtPort, ttl must be zero too
                {
-               LogMsg("mDNS_StartBrowse returned %d for type %##s domain %##s", err, info->regtype.c, d->c);
-               freeL("browser_t", b);
+               if (!mDNSIPPortIsZero(request->u.pm.NATinfo.IntPort) || !mDNSIPPortIsZero(request->u.pm.ReqExt) || ttl) return(mStatus_BadParamErr);
                }
        else
                {
-               b->next = info->browsers;
-               info->browsers = b;
+               if (mDNSIPPortIsZero(request->u.pm.NATinfo.IntPort)) return(mStatus_BadParamErr);
+               if (!(protocol & (kDNSServiceProtocol_UDP | kDNSServiceProtocol_TCP))) return(mStatus_BadParamErr);
                }
-               return err;
+
+       request->u.pm.NATinfo.Protocol       = !protocol ? NATOp_AddrRequest : (protocol == kDNSServiceProtocol_UDP) ? NATOp_MapUDP : NATOp_MapTCP;
+       //       u.pm.NATinfo.IntPort        = already set above
+       request->u.pm.NATinfo.RequestedPort  = request->u.pm.ReqExt;
+       request->u.pm.NATinfo.NATLease       = ttl;
+       request->u.pm.NATinfo.clientCallback = port_mapping_create_request_callback;
+       request->u.pm.NATinfo.clientContext  = request;
+
+       LogOperation("%3d: DNSServiceNATPortMappingCreate(%X, %u, %u, %d) START", request->sd,
+               protocol, mDNSVal16(request->u.pm.NATinfo.IntPort), mDNSVal16(request->u.pm.ReqExt), request->u.pm.NATinfo.NATLease);
+       err = mDNS_StartNATOperation(&mDNSStorage, &request->u.pm.NATinfo);
+       if (!err) request->terminate = port_mapping_termination_callback;
+
+       return(err);
        }
 
-mDNSlocal void handle_browse_request(request_state *request)
-    {
-    DNSServiceFlags flags;
-    uint32_t interfaceIndex;
-    mDNSInterfaceID InterfaceID;
-    char regtype[MAX_ESCAPED_DOMAIN_NAME], domain[MAX_ESCAPED_DOMAIN_NAME];
-    domainname typedn, d, temp;
-    mDNSs32 NumSubTypes;
-    char *ptr;
-    mStatus err = mStatus_NoError;
-       DNameListElem *search_domain_list, *sdom;
-       browser_info_t *info = NULL;
-       
-    if (request->ts != t_complete)
-        {
-        LogMsg("ERROR: handle_browse_request - transfer state != t_complete");
-        abort_request(request);
-        unlink_request(request);
-        return;
-        }
-
-    // extract data from message
-    ptr = request->msgdata;
-    flags = get_flags(&ptr);
-    interfaceIndex = get_long(&ptr);
-    if (get_string(&ptr, regtype, MAX_ESCAPED_DOMAIN_NAME) < 0 ||
-        get_string(&ptr, domain, MAX_ESCAPED_DOMAIN_NAME) < 0)
-               { err = mStatus_BadParamErr;  goto error; }
-    freeL("handle_browse_request", request->msgbuf);
-    request->msgbuf = NULL;
-
-    InterfaceID = mDNSPlatformInterfaceIDfromInterfaceIndex(gmDNS, interfaceIndex);
-    if (interfaceIndex && !InterfaceID) { err = mStatus_BadParamErr;  goto error; }
-
-#if defined(MDNS_LAZY_REGISTER_SEARCH_DOMAINS)
-       if ( !domain || ( domain[0] == '\0' ) )
-               {
-               dDNS_RegisterSearchDomains( gmDNS );
-               }
+// ***************************************************************************
+#if COMPILER_LIKES_PRAGMA_MARK
+#pragma mark -
+#pragma mark - DNSServiceGetAddrInfo
 #endif
-               
-       typedn.c[0] = 0;
-       NumSubTypes = ChopSubTypes(regtype);    // Note: Modifies regtype string to remove trailing subtypes
-       if (NumSubTypes < 0 || NumSubTypes > 1) { err = mStatus_BadParamErr;  goto error; }
-       if (NumSubTypes == 1 && !AppendDNSNameString(&typedn, regtype + strlen(regtype) + 1))
-               { err = mStatus_BadParamErr;  goto error; }
-
-    if (!regtype[0] || !AppendDNSNameString(&typedn, regtype)) { err = mStatus_BadParamErr;  goto error; }
-
-       if (!MakeDomainNameFromDNSNameString(&temp, regtype)) { err = mStatus_BadParamErr;  goto error; }
-       if (temp.c[0] > 15 && domain[0] == 0) strcpy(domain, "local."); // For over-long service types, we only allow domain "local"
-
-       // allocate and set up browser info
-       info = mallocL("browser_info_t", sizeof(*info));
-       if (!info) { err = mStatus_NoMemoryErr; goto error; }
-
-       request->browser_info = info;
-       info->ForceMCast = (flags & kDNSServiceFlagsForceMulticast) != 0;
-       info->interface_id = InterfaceID;
-       AssignDomainName(&info->regtype, &typedn);
-       info->rstate = request;
-       info->default_domain = !domain[0];
-       info->browsers = NULL;
-
-       // setup termination context
-       request->termination_context = info;
-    request->terminate = browse_termination_callback;
-       
-       LogOperation("%3d: DNSServiceBrowse(\"%##s\", \"%s\") START", request->sd, info->regtype.c, domain);
-       if (domain[0])
-               {
-               if (!MakeDomainNameFromDNSNameString(&d, domain)) { err = mStatus_BadParamErr;  goto error; }
-               err = add_domain_to_browser(info, &d);
-               }
 
-       else
+mDNSlocal void addrinfo_termination_callback(request_state *request)
+       {
+       if (request->u.addrinfo.q4.QuestionContext)
                {
-               search_domain_list = mDNSPlatformGetSearchDomainList();
-               for (sdom = search_domain_list; sdom; sdom = sdom->next)
-                       {
-                       err = add_domain_to_browser(info, &sdom->name);
-                       if (err)
-                               {
-                               if (SameDomainName(&sdom->name, &localdomain)) break;
-                               else err = mStatus_NoError;  // suppress errors for non-local "default" domains
-                               }
-
-                       }
-               mDNS_FreeDNameList(search_domain_list);
+               mDNS_StopQuery(&mDNSStorage, &request->u.addrinfo.q4);
+               request->u.addrinfo.q4.QuestionContext = mDNSNULL;
                }
-               
-       deliver_error(request, err);
-       return;
-    
-error:
-       if (info) freeL("browser_info_t", info);
-       if (request->termination_context) request->termination_context = NULL;
-    deliver_error(request, err);
-    abort_request(request);
-    unlink_request(request);
-    }
-
-mDNSlocal void browse_termination_callback(void *context)
-    {
-       browser_info_t *info = context;
-       browser_t *ptr;
-       
-       if (!info) return;
 
-       while(info->browsers)
+       if (request->u.addrinfo.q6.QuestionContext)
                {
-               ptr = info->browsers;
-               info->browsers = ptr->next;
-               LogOperation("%3d: DNSServiceBrowse(%##s) STOP", info->rstate->sd, ptr->q.qname.c);
-               mDNS_StopBrowse(gmDNS, &ptr->q);  // no need to error-check result
-               freeL("browse_termination_callback", ptr);
+               mDNS_StopQuery(&mDNSStorage, &request->u.addrinfo.q6);
+               request->u.addrinfo.q6.QuestionContext = mDNSNULL;
                }
-       
-       info->rstate->termination_context = NULL;
-       freeL("browser_info", info);
        }
 
-mDNSexport void udsserver_default_browse_domain_changed(const domainname *d, mDNSBool add)
+mDNSlocal mStatus handle_addrinfo_request(request_state *request)
        {
-       request_state *r;
+       char hostname[256];
+       domainname d;
+       mStatus err = 0;
+
+       DNSServiceFlags flags = get_flags(&request->msgptr, request->msgend);
+       mDNSu32 interfaceIndex = get_uint32(&request->msgptr, request->msgend);
+       request->u.addrinfo.interface_id = mDNSPlatformInterfaceIDfromInterfaceIndex(&mDNSStorage, interfaceIndex);
+       if (interfaceIndex && !request->u.addrinfo.interface_id) return(mStatus_BadParamErr);
+       request->u.addrinfo.flags = flags;
+       request->u.addrinfo.protocol = get_uint32(&request->msgptr, request->msgend);
+       if (request->u.addrinfo.protocol > (kDNSServiceProtocol_IPv4|kDNSServiceProtocol_IPv6))
+               return(mStatus_BadParamErr);
+
+       if (get_string(&request->msgptr, request->msgend, hostname, 256) < 0) return(mStatus_BadParamErr);
+
+       if (!request->msgptr) { LogMsg("%3d: DNSServiceGetAddrInfo(unreadable parameters)", request->sd); return(mStatus_BadParamErr); }
+
+       if (!MakeDomainNameFromDNSNameString(&d, hostname))
+               { LogMsg("ERROR: handle_addrinfo_request: bad hostname: %s", hostname); return(mStatus_BadParamErr); }
 
-       for (r = all_requests; r; r = r->next)
+       if (!request->u.addrinfo.protocol)
                {
-               browser_info_t *info = r->browser_info;
-               
-               if (!info || !info->default_domain) continue;
-               if (add) add_domain_to_browser(info, d);
+               NetworkInterfaceInfo *i;
+               if (IsLocalDomain(&d))
+                       {
+                       for (i = mDNSStorage.HostInterfaces; i; i = i->next)
+                               {
+                               if      ((i->ip.type == mDNSAddrType_IPv4) && !mDNSIPv4AddressIsZero(i->ip.ip.v4)) request->u.addrinfo.protocol |= kDNSServiceProtocol_IPv4;
+                               else if ((i->ip.type == mDNSAddrType_IPv6) && !mDNSIPv6AddressIsZero(i->ip.ip.v6)) request->u.addrinfo.protocol |= kDNSServiceProtocol_IPv6;
+                               }
+                       }
                else
                        {
-                       browser_t **ptr = &info->browsers;
-                       while (*ptr)
+                       for (i = mDNSStorage.HostInterfaces; i; i = i->next)
                                {
-                               if (SameDomainName(&(*ptr)->domain, d))
-                                       {
-                                       browser_t *remove = *ptr;
-                                       *ptr = (*ptr)->next;
-                                       if (remove->q.LongLived)
-                                               {
-                                               // give goodbyes for known answers.
-                                               // note that since events are sent to client via udsserver_idle(), we don't need to worry about the question being cancelled mid-loop
-                                               CacheRecord *ka = remove->q.uDNS_info.knownAnswers;
-                                               while (ka) { remove->q.QuestionCallback(gmDNS, &remove->q, &ka->resrec, mDNSfalse); ka = ka->next; }
-                                               }
-                                       mDNS_StopBrowse(gmDNS, &remove->q);
-                                       freeL("browser_t", remove);
-                                       return;
-                                       }
-                               ptr = &(*ptr)->next;
+                               if      ((i->ip.type == mDNSAddrType_IPv4) && !mDNSv4AddressIsLinkLocal(&i->ip.ip.v4)) request->u.addrinfo.protocol |= kDNSServiceProtocol_IPv4;
+                               else if ((i->ip.type == mDNSAddrType_IPv6) && !mDNSv4AddressIsLinkLocal(&i->ip.ip.v6)) request->u.addrinfo.protocol |= kDNSServiceProtocol_IPv6;
                                }
-                       LogMsg("Requested removal of default domain %##s not in list for sd %d", d->c, r->sd);
                        }
                }
-       }
 
-// Count how many other service records we have locally with the same name, but different rdata.
-// For auto-named services, we can have at most one per machine -- if we allowed two auto-named services of
-// the same type on the same machine, we'd get into an infinite autoimmune-response loop of continuous renaming.
-mDNSexport int CountPeerRegistrations(mDNS *const m, ServiceRecordSet *const srs)
-       {
-       int count = 0;
-       ResourceRecord *r = &srs->RR_SRV.resrec;
-       AuthRecord *rr;
-       ServiceRecordSet *s;
-       
-       for (rr = m->ResourceRecords; rr; rr=rr->next)
-               if (rr->resrec.rrtype == kDNSType_SRV && SameDomainName(rr->resrec.name, r->name) && !SameRData(&rr->resrec, r))
-                       count++;
+       if (request->u.addrinfo.protocol & kDNSServiceProtocol_IPv4)
+               {
+               request->u.addrinfo.q4.InterfaceID      = request->u.addrinfo.interface_id;
+               request->u.addrinfo.q4.Target           = zeroAddr;
+               request->u.addrinfo.q4.qname            = d;
+               request->u.addrinfo.q4.qtype            = kDNSServiceType_A;
+               request->u.addrinfo.q4.qclass           = kDNSServiceClass_IN;
+               request->u.addrinfo.q4.LongLived        = (flags & kDNSServiceFlagsLongLivedQuery     ) != 0;
+               request->u.addrinfo.q4.ExpectUnique     = mDNSfalse;
+               request->u.addrinfo.q4.ForceMCast       = (flags & kDNSServiceFlagsForceMulticast     ) != 0;
+               request->u.addrinfo.q4.ReturnIntermed   = (flags & kDNSServiceFlagsReturnIntermediates) != 0;
+               request->u.addrinfo.q4.QuestionCallback = queryrecord_result_callback;
+               request->u.addrinfo.q4.QuestionContext  = request;
+
+               err = mDNS_StartQuery(&mDNSStorage, &request->u.addrinfo.q4);
+               if (err != mStatus_NoError)
+                       {
+                       LogMsg("ERROR: mDNS_StartQuery: %d", (int)err);
+                       request->u.addrinfo.q4.QuestionContext = mDNSNULL;
+                       }
+               }
 
-       for (rr = m->uDNS_info.RecordRegistrations; rr; rr=rr->next)
-               if (rr->uDNS_info.state != regState_Unregistered && rr->resrec.rrtype == kDNSType_SRV && SameDomainName(rr->resrec.name, r->name) && !SameRData(&rr->resrec, r))
-                       count++;
+       if (!err && (request->u.addrinfo.protocol & kDNSServiceProtocol_IPv6))
+               {
+               request->u.addrinfo.q6.InterfaceID      = request->u.addrinfo.interface_id;
+               request->u.addrinfo.q6.Target           = zeroAddr;
+               request->u.addrinfo.q6.qname            = d;
+               request->u.addrinfo.q6.qtype            = kDNSServiceType_AAAA;
+               request->u.addrinfo.q6.qclass           = kDNSServiceClass_IN;
+               request->u.addrinfo.q6.LongLived        = (flags & kDNSServiceFlagsLongLivedQuery     ) != 0;
+               request->u.addrinfo.q6.ExpectUnique     = mDNSfalse;
+               request->u.addrinfo.q6.ForceMCast       = (flags & kDNSServiceFlagsForceMulticast     ) != 0;
+               request->u.addrinfo.q6.ReturnIntermed   = (flags & kDNSServiceFlagsReturnIntermediates) != 0;
+               request->u.addrinfo.q6.QuestionCallback = queryrecord_result_callback;
+               request->u.addrinfo.q6.QuestionContext  = request;
+
+               err = mDNS_StartQuery(&mDNSStorage, &request->u.addrinfo.q6);
+               if (err != mStatus_NoError)
+                       {
+                       LogMsg("ERROR: mDNS_StartQuery: %d", (int)err);
+                       request->u.addrinfo.q6.QuestionContext = mDNSNULL;
+                       }
+               }
 
-       for (s = m->uDNS_info.ServiceRegistrations; s; s = s->next)
-               if (s->uDNS_info.state != regState_Unregistered && SameDomainName(s->RR_SRV.resrec.name, r->name) && !SameRData(&s->RR_SRV.resrec, r))
-                       count++;
-               
-       verbosedebugf("%d peer registrations for %##s", count, r->name->c);
-       return(count);
+       LogOperation("%3d: DNSServiceGetAddrInfo(%##s) START", request->sd, d.c);
+
+       if (!err) request->terminate = addrinfo_termination_callback;
+
+       return(err);
        }
 
-mDNSexport int CountExistingRegistrations(domainname *srv, mDNSIPPort port)
+// ***************************************************************************
+#if COMPILER_LIKES_PRAGMA_MARK
+#pragma mark -
+#pragma mark - Main Request Handler etc.
+#endif
+
+mDNSlocal request_state *NewRequest(void)
        {
-       int count = 0;
-       AuthRecord *rr;
-       for (rr = gmDNS->ResourceRecords; rr; rr=rr->next)
-               if (rr->resrec.rrtype == kDNSType_SRV &&
-                       rr->resrec.rdata->u.srv.port.NotAnInteger == port.NotAnInteger &&
-                       SameDomainName(rr->resrec.name, srv))
-                       count++;
-       return(count);
+       request_state **p = &all_requests;
+       while (*p) p=&(*p)->next;
+       *p = mallocL("request_state", sizeof(request_state));
+       if (!*p) FatalError("ERROR: malloc");
+       mDNSPlatformMemZero(*p, sizeof(request_state));
+       return(*p);
        }
 
-mDNSlocal mStatus register_service_instance(request_state *request, const domainname *domain)
+// read_msg may be called any time when the transfer state (req->ts) is t_morecoming.
+// returns the current state of the request (morecoming, error, complete, terminated.)
+// if there is no data on the socket, the socket will be closed and t_terminated will be returned
+// *** NOTE return value is actually ignored -- should change return type to void ***
+mDNSlocal int read_msg(request_state *req)
        {
-       service_info *info = request->service_registration;
-       service_instance *ptr, *instance;
-    int instance_size;
-       mStatus result;
+       mDNSu32 nleft;
+       int nread;
 
-       for (ptr = info->instances; ptr; ptr = ptr->next)
+       if (req->ts == t_terminated || req->ts == t_error)
                {
-               if (SameDomainName(&ptr->domain, domain))
-                       { LogMsg("register_service_instance: domain %##s already registered", domain->c); return mStatus_AlreadyRegistered; }
+               LogMsg("ERROR: read_msg called with transfer state terminated or error");
+               req->ts = t_error;
+               return t_error;
                }
-       
-       instance_size = sizeof(*instance);
-       if (info->txtlen > sizeof(RDataBody)) instance_size += (info->txtlen - sizeof(RDataBody));
-       instance = mallocL("service_instance", instance_size);
-       if (!instance) { my_perror("ERROR: malloc"); return mStatus_NoMemoryErr; }
 
-       instance->subtypes = AllocateSubTypes(info->num_subtypes, info->type_as_string);
-       if (info->num_subtypes && !instance->subtypes)
-               { free_service_instance(instance); instance = NULL; FatalError("ERROR: malloc"); }
-    instance->request           = request;
-       instance->sd                = request->sd;
-    instance->autoname          = info->autoname;
-    instance->autorename        = info->autorename;
-    instance->allowremotequery  = info->allowremotequery;
-    instance->rename_on_memfree = 0;
-       instance->name              = info->name;
-       AssignDomainName(&instance->domain, domain);
-       instance->default_local = (info->default_domain && SameDomainName(domain, &localdomain));
-    result = mDNS_RegisterService(gmDNS, &instance->srs, &instance->name, &info->type, domain, info->host.c[0] ? &info->host : NULL, info->port,
-                                                                 info->txtdata, info->txtlen, instance->subtypes, info->num_subtypes, info->InterfaceID, regservice_callback, instance);
-
-       if (result) free_service_instance(instance);
-       else
+       if (req->ts == t_complete)      // this must be death or something is wrong
                {
-               instance->next = info->instances;
-               info->instances = instance;
+               char buf[4];    // dummy for death notification
+               nread = recv(req->sd, buf, 4, 0);
+               if (!nread) { req->ts = t_terminated; return t_terminated; }
+               if (nread < 0) goto rerror;
+               LogMsg("ERROR: read data from a completed request.");
+               req->ts = t_error;
+               return t_error;
                }
-       return result;
-       }
 
-mDNSexport void udsserver_default_reg_domain_changed(const domainname *d, mDNSBool add)
-       {
-       request_state *rstate;
-       service_info *info;
+       if (req->ts != t_morecoming)
+               {
+               LogMsg("ERROR: read_msg called with invalid transfer state (%d)", req->ts);
+               req->ts = t_error;
+               return t_error;
+               }
 
-       LogMsg("%s registration domain %##s", add ? "Adding" : "Removing", d->c);
-       for (rstate = all_requests; rstate; rstate = rstate->next)
+       if (req->hdr_bytes < sizeof(ipc_msg_hdr))
                {
-               if (rstate->terminate != regservice_termination_callback) continue;
-               info = rstate->service_registration;
-               if (!info) { LogMsg("udsserver_default_reg_domain_changed - NULL service info"); continue; } // this should never happen
-               if (!info->default_domain)  continue;
+               nleft = sizeof(ipc_msg_hdr) - req->hdr_bytes;
+               nread = recv(req->sd, (char *)&req->hdr + req->hdr_bytes, nleft, 0);
+               if (nread == 0) { req->ts = t_terminated; return t_terminated; }
+               if (nread < 0) goto rerror;
+               req->hdr_bytes += nread;
+               if (req->hdr_bytes > sizeof(ipc_msg_hdr))
+                       {
+                       LogMsg("ERROR: read_msg - read too many header bytes");
+                       req->ts = t_error;
+                       return t_error;
+                       }
 
-               // valid default registration
-               if (add) register_service_instance(rstate, d);
-               else
+               // only read data if header is complete
+               if (req->hdr_bytes == sizeof(ipc_msg_hdr))
                        {
-                       // find the instance to remove
-                       service_instance *si = rstate->service_registration->instances, *prev = NULL;
-                       while (si)
+                       ConvertHeaderBytes(&req->hdr);
+                       if (req->hdr.version != VERSION)
+                               { LogMsg("ERROR: client version 0x%08X daemon version 0x%08X", req->hdr.version, VERSION); req->ts = t_error; return t_error; }
+
+                       // Largest conceivable single request is a DNSServiceRegisterRecord() or DNSServiceAddRecord()
+                       // with 64kB of rdata. Adding 1005 byte for a maximal domain name, plus a safety margin
+                       // for other overhead, this means any message above 70kB is definitely bogus.
+                       if (req->hdr.datalen > 70000)
                                {
-                               if (SameDomainName(&si->domain, d))
-                                       {
-                                       mStatus err;
-                                       if (prev) prev->next = si->next;
-                                       else info->instances = si->next;
-                                       err = mDNS_DeregisterService(gmDNS, &si->srs);
-                                       if (err)
-                                               {
-                                               LogMsg("udsserver_default_reg_domain_changed - mDNS_DeregisterService err %d", err);
-                                               free_service_instance(si);
-                                               }
-                                       break;
-                                       }
-                               prev = si;
-                               si = si->next;
+                               LogMsg("ERROR: read_msg - hdr.datalen %lu (%X) > 70000", req->hdr.datalen, req->hdr.datalen);
+                               req->ts = t_error;
+                               return t_error;
+                               }
+                       req->msgbuf = mallocL("request_state msgbuf", req->hdr.datalen + MSG_PAD_BYTES);
+                       if (!req->msgbuf) { my_perror("ERROR: malloc"); req->ts = t_error; return t_error; }
+                       req->msgptr = req->msgbuf;
+                       req->msgend = req->msgbuf + req->hdr.datalen;
+                       mDNSPlatformMemZero(req->msgbuf, req->hdr.datalen + MSG_PAD_BYTES);
+                       }
+               }
+
+       // If our header is complete, but we're still needing more body data, then try to read it now
+       // Note: For cancel_request req->hdr.datalen == 0, but there's no error return socket for cancel_request
+       // Any time we need to get the error return socket we know we'll have at least one data byte
+       // (even if only the one-byte empty C string placeholder for the old ctrl_path parameter)
+       if (req->hdr_bytes == sizeof(ipc_msg_hdr) && req->data_bytes < req->hdr.datalen)
+               {
+               nleft = req->hdr.datalen - req->data_bytes;
+               struct iovec vec = { req->msgbuf + req->data_bytes, nleft };    // Tell recvmsg where we want the bytes put
+               struct msghdr msg;
+               struct cmsghdr *cmsg;
+               char cbuf[sizeof(struct cmsghdr) + sizeof(dnssd_sock_t)];
+               msg.msg_name       = 0;
+               msg.msg_namelen    = 0;
+               msg.msg_iov        = &vec;
+               msg.msg_iovlen     = 1;
+               msg.msg_control    = cbuf;
+               msg.msg_controllen = sizeof(cbuf);
+               msg.msg_flags      = 0;
+               nread = recvmsg(req->sd, &msg, 0);
+               if (nread == 0) { req->ts = t_terminated; return t_terminated; }
+               if (nread < 0) goto rerror;
+               req->data_bytes += nread;
+               if (req->data_bytes > req->hdr.datalen)
+                       {
+                       LogMsg("ERROR: read_msg - read too many data bytes");
+                       req->ts = t_error;
+                       return t_error;
+                       }
+               cmsg = CMSG_FIRSTHDR(&msg);
+               if (msg.msg_controllen == sizeof(cbuf) &&
+                       cmsg->cmsg_len     == sizeof(cbuf) &&
+                       cmsg->cmsg_level   == SOL_SOCKET   &&
+                       cmsg->cmsg_type    == SCM_RIGHTS)
+                       {
+                       req->errsd = *(dnssd_sock_t *)CMSG_DATA(cmsg);
+                       if (req->data_bytes < req->hdr.datalen)
+                               {
+                               LogMsg("%3d: Client sent error socket %d via SCM_RIGHTS with req->data_bytes %d < req->hdr.datalen %d",
+                                       req->sd, req->errsd, req->data_bytes, req->hdr.datalen);
+                               req->ts = t_error;
+                               return t_error;
                                }
-                       if (!si) debugf("udsserver_default_reg_domain_changed - domain %##s not registered", d->c); // normal if registration failed
                        }
                }
-       }
 
-// service registration
-mDNSlocal void handle_regservice_request(request_state *request)
-    {
-    DNSServiceFlags flags;
-    uint32_t ifi;
-    char name[1024];   // Lots of spare space for extra-long names that we'll auto-truncate down to 63 bytes
-    char domain[MAX_ESCAPED_DOMAIN_NAME], host[MAX_ESCAPED_DOMAIN_NAME];
-    char *ptr;
-    domainname d, srv;
-    mStatus result;
-       service_info *service = NULL;
+       // If our header and data are both complete, see if we need to make our separate error return socket
+       if (req->hdr_bytes == sizeof(ipc_msg_hdr) && req->data_bytes == req->hdr.datalen)
+               {
+               if (req->terminate && req->hdr.op != cancel_request)
+                       {
+                       dnssd_sockaddr_t cliaddr;
+#if defined(USE_TCP_LOOPBACK)
+                       mDNSOpaque16 port;
+                       port.b[0] = req->msgptr[0];
+                       port.b[1] = req->msgptr[1];
+                       req->msgptr += 2;
+                       cliaddr.sin_family      = AF_INET;
+                       cliaddr.sin_port        = port.NotAnInteger;
+                       cliaddr.sin_addr.s_addr = inet_addr(MDNS_TCP_SERVERADDR);
+#else
+                       char ctrl_path[MAX_CTLPATH];
+                       get_string(&req->msgptr, req->msgend, ctrl_path, MAX_CTLPATH);  // path is first element in message buffer
+                       mDNSPlatformMemZero(&cliaddr, sizeof(cliaddr));
+                       cliaddr.sun_family = AF_LOCAL;
+                       mDNSPlatformStrCopy(cliaddr.sun_path, ctrl_path);
+                       // If the error return path UDS name is empty string, that tells us
+                       // that this is a new version of the library that's going to pass us
+                       // the error return path socket via sendmsg/recvmsg
+                       if (ctrl_path[0] == 0)
+                               {
+                               if (req->errsd == req->sd)
+                                       { LogMsg("%3d: request_callback: ERROR failed to get errsd via SCM_RIGHTS", req->sd); req->ts = t_error; return t_error; }
+                               goto got_errfd;
+                               }
+#endif
+       
+                       req->errsd = socket(AF_DNSSD, SOCK_STREAM, 0);
+                       if (!dnssd_SocketValid(req->errsd)) { my_perror("ERROR: socket"); req->ts = t_error; return t_error; }
        
-       if (request->ts != t_complete)
-        {
-        LogMsg("ERROR: handle_regservice_request - transfer state != t_complete");
-        abort_request(request);
-        unlink_request(request);
-        return;
-        }
-
-       service = mallocL("service_info", sizeof(*service));
-       if (!service) { my_perror("ERROR: malloc"); result = mStatus_NoMemoryErr; goto finish; }
-
-       service->instances = NULL;
-       service->request = request;
-       service->txtlen  = 0;
-       service->txtdata = NULL;
-       request->service_registration = service;
-    request->termination_context = request->service_registration;
-    request->terminate = regservice_termination_callback;
+                       if (connect(req->errsd, (struct sockaddr *)&cliaddr, sizeof(cliaddr)) < 0)
+                               {
+#if !defined(USE_TCP_LOOPBACK)
+                               struct stat sb;
+                               LogMsg("request_callback: Couldn't connect to error return path socket “%s” errno %d %s",
+                                       cliaddr.sun_path, dnssd_errno(), dnssd_strerror(dnssd_errno()));
+                               if (stat(cliaddr.sun_path, &sb) < 0)
+                                       LogMsg("request_callback: stat failed “%s” errno %d %s", cliaddr.sun_path, dnssd_errno(), dnssd_strerror(dnssd_errno()));
+                               else
+                                       LogMsg("request_callback: file “%s” mode %o (octal) uid %d gid %d", cliaddr.sun_path, sb.st_mode, sb.st_uid, sb.st_gid);
+#endif
+                               req->ts = t_error;
+                               return t_error;
+                               }
        
-    // extract data from message
-    ptr = request->msgdata;
-    flags = get_flags(&ptr);
-    ifi = get_long(&ptr);
-    service->InterfaceID = mDNSPlatformInterfaceIDfromInterfaceIndex(gmDNS, ifi);
-    if (ifi && !service->InterfaceID)
-       { LogMsg("ERROR: handle_regservice_request - Couldn't find InterfaceID for interfaceIndex %d", ifi); goto bad_param; }
-    if (get_string(&ptr, name, sizeof(name)) < 0 ||
-        get_string(&ptr, service->type_as_string, MAX_ESCAPED_DOMAIN_NAME) < 0 ||
-        get_string(&ptr, domain, MAX_ESCAPED_DOMAIN_NAME) < 0 ||
-        get_string(&ptr, host, MAX_ESCAPED_DOMAIN_NAME) < 0)
-       { LogMsg("ERROR: handle_regservice_request - Couldn't read name/regtype/domain"); goto bad_param; }
-        
-       service->port.b[0] = *ptr++;
-       service->port.b[1] = *ptr++;
-
-    service->txtlen  = get_short(&ptr);
-       if (service->txtlen)
-               {
-               service->txtdata = mallocL("txtdata", service->txtlen);
-               if (!service->txtdata) { my_perror("ERROR: malloc"); result = mStatus_NoMemoryErr; goto finish; }
-               memcpy(service->txtdata, get_rdata(&ptr, service->txtlen), service->txtlen);
-               }
-       else service->txtdata = NULL;
+got_errfd:
+                       LogOperation("%3d: Using separate error socket %d", req->sd, req->errsd);
+#if defined(_WIN32)
+                       if (ioctlsocket(req->errsd, FIONBIO, &opt) != 0)
+#else
+                       if (fcntl(req->errsd, F_SETFL, fcntl(req->errsd, F_GETFL, 0) | O_NONBLOCK) != 0)
+#endif
+                               { my_perror("ERROR: could not set control socket to non-blocking mode"); req->ts = t_error; return t_error; }
+                       }
+               
+               req->ts = t_complete;
+               }
 
-       // Check for sub-types after the service type
-       service->num_subtypes = ChopSubTypes(service->type_as_string);  // Note: Modifies regtype string to remove trailing subtypes
-       if (service->num_subtypes < 0)
-       { LogMsg("ERROR: handle_regservice_request - ChopSubTypes failed %s", service->type_as_string); goto bad_param; }
+       return req->ts;
 
-       // Don't try to construct "domainname t" until *after* ChopSubTypes has worked its magic
-    if (!*service->type_as_string || !MakeDomainNameFromDNSNameString(&service->type, service->type_as_string))
-       { LogMsg("ERROR: handle_regservice_request - service->type_as_string bad %s", service->type_as_string); goto bad_param; }
+rerror:
+       if (dnssd_errno() == dnssd_EWOULDBLOCK || dnssd_errno() == dnssd_EINTR) return t_morecoming;
+       my_perror("ERROR: read_msg");
+       req->ts = t_error;
+       return t_error;
+       }
+
+#define RecordOrientedOp(X) \
+       ((X) == reg_record_request || (X) == add_record_request || (X) == update_record_request || (X) == remove_record_request)
+
+// The lightweight operations are the ones that don't need a dedicated request_state structure allocated for them
+#define LightweightOp(X) (RecordOrientedOp(X) || (X) == cancel_request)
+
+mDNSlocal void request_callback(int fd, short filter, void *info)
+       {
+       mStatus err = 0;
+       request_state *req = info;
+#if defined(_WIN32)
+       u_long opt = 1;
+#endif
+       mDNSs32 min_size = sizeof(DNSServiceFlags);
+       (void)fd; // Unused
+       (void)filter; // Unused
 
-    if (!name[0])
+       read_msg(req);
+       if (req->ts == t_morecoming) return;
+       if (req->ts == t_terminated || req->ts == t_error) { AbortUnlinkAndFree(req); return; }
+
+       if (req->hdr.version != VERSION)
                {
-               service->name = (gmDNS)->nicelabel;
-               service->autoname = mDNStrue;
+               LogMsg("ERROR: client incompatible with daemon (client version = %d, "
+                          "daemon version = %d)\n", req->hdr.version, VERSION);
+               AbortUnlinkAndFree(req);
+               return;
                }
-    else
+
+       switch(req->hdr.op)            //          Interface       + other data
                {
-               // If the client is allowing AutoRename, then truncate name to legal length before converting it to a DomainLabel
-               if ((flags & kDNSServiceFlagsNoAutoRename) == 0)
+               case connection_request:       min_size = 0;                                                                           break;
+               case reg_service_request:      min_size += sizeof(mDNSu32) + 4 /* name, type, domain, host */ + 4 /* port, textlen */; break;
+               case add_record_request:       min_size +=                   4 /* type, rdlen */              + 4 /* ttl */;           break;
+               case update_record_request:    min_size +=                   2 /* rdlen */                    + 4 /* ttl */;           break;
+               case remove_record_request:                                                                                            break;
+               case browse_request:           min_size += sizeof(mDNSu32) + 2 /* type, domain */;                                     break;
+               case resolve_request:          min_size += sizeof(mDNSu32) + 3 /* type, type, domain */;                               break;
+               case query_request:            min_size += sizeof(mDNSu32) + 1 /* name */                     + 4 /* type, class*/;    break;
+               case enumeration_request:      min_size += sizeof(mDNSu32);                                                            break;
+               case reg_record_request:       min_size += sizeof(mDNSu32) + 1 /* name */ + 6 /* type, class, rdlen */ + 4 /* ttl */;  break;
+               case reconfirm_record_request: min_size += sizeof(mDNSu32) + 1 /* name */ + 6 /* type, class, rdlen */;                break;
+               case setdomain_request:        min_size +=                   1 /* domain */;                                           break;
+               case getproperty_request:      min_size = 2;                                                                           break;
+               case port_mapping_request:     min_size += sizeof(mDNSu32) + 4 /* udp/tcp */ + 4 /* int/ext port */    + 4 /* ttl */;  break;
+               case addrinfo_request:         min_size += sizeof(mDNSu32) + 4 /* v4/v6 */   + 1 /* hostname */;                       break;
+               case cancel_request:           min_size = 0;                                                                           break;
+               default: LogMsg("ERROR: validate_message - unsupported req type: %d", req->hdr.op); min_size = -1;                     break;
+               }
+
+       if ((mDNSs32)req->data_bytes < min_size)
+               { LogMsg("Invalid message %d bytes; min for %d is %d", req->data_bytes, req->hdr.op, min_size); AbortUnlinkAndFree(req); return; }
+
+       if (LightweightOp(req->hdr.op) && !req->terminate)
+               { LogMsg("Reg/Add/Update/Remove %d require existing connection", req->hdr.op);                  AbortUnlinkAndFree(req); return; }
+
+       // check if client wants silent operation
+       if (req->hdr.ipc_flags & IPC_FLAGS_NOREPLY) req->no_reply = 1;
+
+       // If req->terminate is already set, this means this operation is sharing an existing connection
+       if (req->terminate && !LightweightOp(req->hdr.op))
+               {
+               request_state *newreq = NewRequest();
+               newreq->primary = req;
+               newreq->sd      = req->sd;
+               newreq->errsd   = req->errsd;
+               newreq->uid     = req->uid;
+               newreq->hdr     = req->hdr;
+               newreq->msgbuf  = req->msgbuf;
+               newreq->msgptr  = req->msgptr;
+               newreq->msgend  = req->msgend;
+               req = newreq;
+               }
+
+       switch(req->hdr.op)
+               {
+               // These are all operations that have their own first-class request_state object
+               case connection_request:
+                       LogOperation("%3d: DNSServiceCreateConnection START", req->sd);
+                       req->terminate = connection_termination;
+                       break;
+               case resolve_request:              err = handle_resolve_request     (req); break;
+               case query_request:                err = handle_queryrecord_request (req); break;
+               case browse_request:               err = handle_browse_request      (req); break;
+               case reg_service_request:          err = handle_regservice_request  (req); break;
+               case enumeration_request:          err = handle_enum_request        (req); break;
+               case reconfirm_record_request:     err = handle_reconfirm_request   (req); break;
+               case setdomain_request:            err = handle_setdomain_request   (req); break;
+               case getproperty_request:                handle_getproperty_request (req); break;
+               case port_mapping_request:         err = handle_port_mapping_request(req); break;
+               case addrinfo_request:             err = handle_addrinfo_request    (req); break;
+
+               // These are all operations that work with an existing request_state object
+               case reg_record_request:           err = handle_regrecord_request   (req); break;
+               case add_record_request:           err = handle_add_request         (req); break;
+               case update_record_request:        err = handle_update_request      (req); break;
+               case remove_record_request:        err = handle_removerecord_request(req); break;
+               case cancel_request:                     handle_cancel_request      (req); break;
+               default: LogMsg("%3d: ERROR: Unsupported UDS req: %d", req->sd, req->hdr.op);
+               }
+
+       // req->msgbuf may be NULL, e.g. for connection_request or remove_record_request
+       if (req->msgbuf) freeL("request_state msgbuf", req->msgbuf);
+
+       // There's no return data for a cancel request (DNSServiceRefDeallocate returns no result)
+       // For a DNSServiceGetProperty call, the handler already generated the response,
+       // so no need to do it again here
+       if (req->hdr.op != cancel_request && req->hdr.op != getproperty_request)
+               {
+               err = dnssd_htonl(err);
+               send_all(req->errsd, (const char *)&err, sizeof(err));
+               if (req->errsd != req->sd)
                        {
-                       int newlen = TruncateUTF8ToLength((mDNSu8*)name, mDNSPlatformStrLen(name), MAX_DOMAIN_LABEL);
-                       name[newlen] = 0;
+                       LogOperation("%3d: Closing error socket %d", req->sd, req->errsd);
+                       dnssd_close(req->errsd);
+                       req->errsd = req->sd;
+                       // Also need to reset the parent's errsd, if this is a subbordinate operation
+                       if (req->primary) req->primary->errsd = req->primary->sd;
                        }
-               if (!MakeDomainLabelFromLiteralString(&service->name, name))
-                       { LogMsg("ERROR: handle_regservice_request - name bad %s", name); goto bad_param; }
-               service->autoname = mDNSfalse;
                }
-               
-       if (*domain)
+
+       // Reset ready to accept the next req on this pipe
+       if (req->primary) req = req->primary;
+       req->ts         = t_morecoming;
+       req->hdr_bytes  = 0;
+       req->data_bytes = 0;
+       req->msgbuf     = mDNSNULL;
+       req->msgptr     = mDNSNULL;
+       req->msgend     = 0;
+       }
+
+mDNSlocal void connect_callback(int fd, short filter, void *info)
+       {
+       dnssd_sockaddr_t cliaddr;
+       dnssd_socklen_t len = (dnssd_socklen_t) sizeof(cliaddr);
+       dnssd_sock_t sd = accept(listenfd, (struct sockaddr*) &cliaddr, &len);
+       const unsigned long optval = 1;
+
+       (void)fd; // Unused
+       (void)filter; // Unused
+       (void)info; // Unused
+
+       if (!dnssd_SocketValid(sd))
                {
-               service->default_domain = mDNSfalse;
-               if (!MakeDomainNameFromDNSNameString(&d, domain))
-                       { LogMsg("ERROR: handle_regservice_request - domain bad %s", domain); goto bad_param; }
+               if (dnssd_errno() != dnssd_EWOULDBLOCK) my_perror("ERROR: accept");
+               return;
                }
-       else
+
+#ifdef SO_NOSIGPIPE
+       // Some environments (e.g. OS X) support turning off SIGPIPE for a socket
+       if (setsockopt(sd, SOL_SOCKET, SO_NOSIGPIPE, &optval, sizeof(optval)) < 0)
                {
-               service->default_domain = mDNStrue;
-               MakeDomainNameFromDNSNameString(&d, "local.");
+               my_perror("ERROR: setsockopt - SO_NOSIGPIPE - aborting client");
+               dnssd_close(sd);
+               return;
                }
-       
-       if (!ConstructServiceName(&srv, &service->name, &service->type, &d))
-               { LogMsg("ERROR: handle_regservice_request - Couldn't ConstructServiceName from, “%#s” “%##s” “%##s”", service->name.c, service->type.c, d.c); goto bad_param; }
-               
-       if (!MakeDomainNameFromDNSNameString(&service->host, host))
-               { LogMsg("ERROR: handle_regservice_request - host bad %s", host); goto bad_param; }
-       service->autorename       = (flags & kDNSServiceFlagsNoAutoRename    ) == 0;
-       service->allowremotequery = (flags & kDNSServiceFlagsAllowRemoteQuery) != 0;
-       
-       // Some clients use mDNS for lightweight copy protection, registering a pseudo-service with
-       // a port number of zero. When two instances of the protected client are allowed to run on one
-       // machine, we don't want to see misleading "Bogus client" messages in syslog and the console.
-       if (service->port.NotAnInteger)
+#endif
+
+#if defined(_WIN32)
+       if (ioctlsocket(sd, FIONBIO, &optval) != 0)
+#else
+       if (fcntl(sd, F_SETFL, fcntl(sd, F_GETFL, 0) | O_NONBLOCK) != 0)
+#endif
                {
-               int count = CountExistingRegistrations(&srv, service->port);
-               if (count)
-                       LogMsg("Client application registered %d identical instances of service %##s port %u.",
-                               count+1, srv.c, mDNSVal16(service->port));
+               my_perror("ERROR: fcntl(sd, F_SETFL, O_NONBLOCK) - aborting client");
+               dnssd_close(sd);
+               return;
                }
-
-       LogOperation("%3d: DNSServiceRegister(\"%s\", \"%s\", \"%s\", \"%s\", %u) START",
-               request->sd, name, service->type_as_string, domain, host, mDNSVal16(service->port));
-       result = register_service_instance(request, &d);
-       
-       if (!result && !*domain)
+       else
                {
-               DNameListElem *ptr, *def_domains = mDNSPlatformGetRegDomainList();
-               for (ptr = def_domains; ptr; ptr = ptr->next)
-                       register_service_instance(request, &ptr->name);
-                   // note that we don't report errors for non-local, non-explicit domains
-               mDNS_FreeDNameList(def_domains);
+               request_state *request = NewRequest();
+               request->ts    = t_morecoming;
+               request->sd    = sd;
+               request->errsd = sd;
+#if APPLE_OSX_mDNSResponder
+       struct xucred x;
+       socklen_t len = sizeof(x);
+       if (getsockopt(sd, 0, LOCAL_PEERCRED, &x, &len) >= 0 && x.cr_version == XUCRED_VERSION) request->uid = x.cr_uid;
+       else my_perror("ERROR: getsockopt, LOCAL_PEERCRED");
+       debugf("LOCAL_PEERCRED %d %u %u %d", len, x.cr_version, x.cr_uid, x.cr_ngroups);
+#endif APPLE_OSX_mDNSResponder
+               LogOperation("%3d: Adding FD for uid %u", request->sd, request->uid);
+               udsSupportAddFDToEventLoop(sd, request_callback, request);
                }
-       
-finish:
-    deliver_error(request, result);
-    if (result != mStatus_NoError)
-        {
-        abort_request(request);
-        unlink_request(request);
-        }
-    else
-        reset_connected_rstate(request);  // prepare to receive add/remove messages
-
-    return;
-
-bad_param:
-       //if (service) freeL("service_info", service);  Don't think we should do this -- abort_request will free it a second time and crash
-    deliver_error(request, mStatus_BadParamErr);
-    abort_request(request);
-    unlink_request(request);
-    }
+       }
 
-// service registration callback performs three duties - frees memory for deregistered services,
-// handles name conflicts, and delivers completed registration information to the client (via
-// process_service_registraion())
+mDNSexport int udsserver_init(dnssd_sock_t skt)
+       {
+       dnssd_sockaddr_t laddr;
+       int ret;
+#if defined(_WIN32)
+       u_long opt = 1;
+#endif
 
-mDNSlocal void regservice_callback(mDNS *const m, ServiceRecordSet *const srs, mStatus result)
-    {
-    mStatus err;
-       mDNSBool SuppressError = mDNSfalse;
-    service_instance *instance = srs->ServiceContext;
-    (void)m; // Unused
-    if (!srs)      { LogMsg("regservice_callback: srs is NULL %d",                 result); return; }
-    if (!instance) { LogMsg("regservice_callback: srs->ServiceContext is NULL %d", result); return; }
+       LogOperation("udsserver_init");
 
-       if (instance->request && instance->request->service_registration)
+       // If a particular platform wants to opt out of having a PID file, define PID_FILE to be ""
+       if (PID_FILE[0])
                {
-               service_info *info = instance->request->service_registration;
-               if (info->default_domain && !instance->default_local) SuppressError = mDNStrue;
-        // don't send errors up to client for wide-area, empty-string registrations
+               FILE *fp = fopen(PID_FILE, "w");
+               if (fp != NULL)
+                       {
+                       fprintf(fp, "%d\n", getpid());
+                       fclose(fp);
+                       }
                }
-       
-    if (result == mStatus_NoError)
-               LogOperation("%3d: DNSServiceRegister(%##s, %u) REGISTERED  ",  instance->sd, srs->RR_SRV.resrec.name->c, mDNSVal16(srs->RR_SRV.resrec.rdata->u.srv.port));
-       else if (result == mStatus_MemFree)
-               LogOperation("%3d: DNSServiceRegister(%##s, %u) DEREGISTERED",  instance->sd, srs->RR_SRV.resrec.name->c, mDNSVal16(srs->RR_SRV.resrec.rdata->u.srv.port));
-       else if (result == mStatus_NameConflict)
-               LogOperation("%3d: DNSServiceRegister(%##s, %u) NAME CONFLICT", instance->sd, srs->RR_SRV.resrec.name->c, mDNSVal16(srs->RR_SRV.resrec.rdata->u.srv.port));
-       else
-               LogOperation("%3d: DNSServiceRegister(%##s, %u) CALLBACK %d",   instance->sd, srs->RR_SRV.resrec.name->c, mDNSVal16(srs->RR_SRV.resrec.rdata->u.srv.port), result);
 
-    if (result == mStatus_NoError)
+       if (dnssd_SocketValid(skt))
+               listenfd = skt;
+       else
                {
-               request_state *req = instance->request;
-               if (instance->allowremotequery)
+               listenfd = socket(AF_DNSSD, SOCK_STREAM, 0);
+               if (!dnssd_SocketValid(listenfd))
                        {
-                       ExtraResourceRecord *e;
-                       srs->RR_ADV.AllowRemoteQuery = mDNStrue;
-                       srs->RR_PTR.AllowRemoteQuery = mDNStrue;
-                       srs->RR_SRV.AllowRemoteQuery = mDNStrue;
-                       srs->RR_TXT.AllowRemoteQuery = mDNStrue;
-                       for (e = instance->srs.Extras; e; e = e->next) e->r.AllowRemoteQuery = mDNStrue;
+                       my_perror("ERROR: socket(AF_DNSSD, SOCK_STREAM, 0); failed");
+                       goto error;
                        }
-        
-               if (!req) LogMsg("ERROR: regservice_callback - null request object");
-               else
+
+               mDNSPlatformMemZero(&laddr, sizeof(laddr));
+
+               #if defined(USE_TCP_LOOPBACK)
                        {
-                       reply_state *rep;
-                       if (GenerateNTDResponse(srs->RR_SRV.resrec.name, srs->RR_SRV.resrec.InterfaceID, req, &rep) != mStatus_NoError)
-                               LogMsg("%3d: regservice_callback: %##s is not valid DNS-SD SRV name", req->sd, srs->RR_SRV.resrec.name->c);
-                       else
+                       laddr.sin_family = AF_INET;
+                       laddr.sin_port = htons(MDNS_TCP_SERVERPORT);
+                       laddr.sin_addr.s_addr = inet_addr(MDNS_TCP_SERVERADDR);
+                       ret = bind(listenfd, (struct sockaddr *) &laddr, sizeof(laddr));
+                       if (ret < 0)
                                {
-                               transfer_state send_result = send_msg(rep);
-                               if (send_result == t_error || send_result == t_terminated)
-                                       { abort_request(req); unlink_request(req); freeL("reply_state", rep); }
-                               else if (send_result == t_complete) freeL("regservice_callback", rep);
-                               else append_reply(req, rep);
+                               my_perror("ERROR: bind(listenfd, (struct sockaddr *) &laddr, sizeof(laddr)); failed");
+                               goto error;
                                }
                        }
-        if (instance->autoname && CountPeerRegistrations(m, srs) == 0)
-               RecordUpdatedNiceLabel(m, 0);   // Successfully got new name, tell user immediately
-               return;
+               #else
+                       {
+                       mode_t mask = umask(0);
+                       unlink(MDNS_UDS_SERVERPATH);  //OK if this fails
+                       laddr.sun_family = AF_LOCAL;
+                       #ifndef NOT_HAVE_SA_LEN
+                       // According to Stevens (section 3.2), there is no portable way to
+                       // determine whether sa_len is defined on a particular platform.
+                       laddr.sun_len = sizeof(struct sockaddr_un);
+                       #endif
+                       mDNSPlatformStrCopy(laddr.sun_path, MDNS_UDS_SERVERPATH);
+                       ret = bind(listenfd, (struct sockaddr *) &laddr, sizeof(laddr));
+                       umask(mask);
+                       if (ret < 0)
+                               {
+                               my_perror("ERROR: bind(listenfd, (struct sockaddr *) &laddr, sizeof(laddr)); failed");
+                               goto error;
+                               }
+                       }
+               #endif
                }
-    else if (result == mStatus_MemFree)
-        {
-        if (instance->rename_on_memfree)
-            {
-            instance->rename_on_memfree = 0;
-            instance->name = gmDNS->nicelabel;
-            err = mDNS_RenameAndReregisterService(gmDNS, srs, &instance->name);
-            if (err) LogMsg("ERROR: regservice_callback - RenameAndReregisterService returned %ld", err);
-            // error should never happen - safest to log and continue
-            }
-        else
-            {
-                       free_service_instance(instance);
-            return;
-            }
-        }
-    else if (result == mStatus_NameConflict)
-       {
-        if (instance->autoname && CountPeerRegistrations(m, srs) == 0)
-               {
-               // On conflict for an autoname service, rename and reregister *all* autoname services
-                       IncrementLabelSuffix(&m->nicelabel, mDNStrue);
-                       m->MainCallback(m, mStatus_ConfigChanged);
-               }
-        else if (instance->autoname || instance->autorename)
-            {
-            mDNS_RenameAndReregisterService(gmDNS, srs, mDNSNULL);
-            return;
-            }
-        else
-            {
-                   request_state *rs = instance->request;
-                       if (!rs) { LogMsg("ERROR: regservice_callback: received result %ld with a NULL request pointer", result); return; }
-                       free_service_instance(instance);
-                       if (!SuppressError && deliver_async_error(rs, reg_service_reply, result) < 0)
-                {
-                abort_request(rs);
-                unlink_request(rs);
-                }
-            return;
-            }
-       }
-    else
-        {
-               request_state *rs = instance->request;
-               if (!rs) { LogMsg("ERROR: regservice_callback: received result %ld with a NULL request pointer", result); return; }
-        if (result != mStatus_NATTraversal) LogMsg("ERROR: unknown result in regservice_callback: %ld", result);
-               free_service_instance(instance);
-        if (!SuppressError && deliver_async_error(rs, reg_service_reply, result) < 0)
-            {
-            abort_request(rs);
-            unlink_request(rs);
-            }
-        return;
-        }
-    }
 
-mDNSexport void FreeExtraRR(mDNS *const m, AuthRecord *const rr, mStatus result)
-       {
-       ExtraResourceRecord *extra = (ExtraResourceRecord *)rr->RecordContext;
-       (void)m;  //unused
-       
-       if (result != mStatus_MemFree) { LogMsg("Error: FreeExtraRR invoked with unexpected error %d", result); return; }
-       
-       debugf("%##s: MemFree", rr->resrec.name->c);
-       if (rr->resrec.rdata != &rr->rdatastorage)
-               freeL("Extra RData", rr->resrec.rdata);
-       freeL("ExtraResourceRecord", extra);
-       }
+#if defined(_WIN32)
+       // SEH: do we even need to do this on windows?
+       // This socket will be given to WSAEventSelect which will automatically set it to non-blocking
+       if (ioctlsocket(listenfd, FIONBIO, &opt) != 0)
+#else
+       if (fcntl(listenfd, F_SETFL, fcntl(listenfd, F_GETFL, 0) | O_NONBLOCK) != 0)
+#endif
+               {
+               my_perror("ERROR: could not set listen socket to non-blocking mode");
+               goto error;
+               }
+
+       if (listen(listenfd, LISTENQ) != 0)
+               {
+               my_perror("ERROR: could not listen on listen socket");
+               goto error;
+               }
+
+       if (mStatus_NoError != udsSupportAddFDToEventLoop(listenfd, connect_callback, (void *) NULL))
+               {
+               my_perror("ERROR: could not add listen socket to event loop");
+               goto error;
+               }
+       else LogOperation("%3d: Listening for incoming Unix Domain Socket client requests", listenfd);
 
-mDNSlocal mStatus add_record_to_service(request_state *rstate, service_instance *instance, uint16_t rrtype, uint16_t rdlen, char *rdata, uint32_t ttl)
+#if !defined(PLATFORM_NO_RLIMIT)
        {
-       ServiceRecordSet *srs = &instance->srs;
-    ExtraResourceRecord *extra;
-       mStatus result;
-       int size;
-       
-       if (rdlen > sizeof(RDataBody)) size = rdlen;
-    else size = sizeof(RDataBody);
-       
-    extra = mallocL("ExtraResourceRecord", sizeof(*extra) - sizeof(RDataBody) + size);
-    if (!extra)
-        {
-        my_perror("ERROR: malloc");
-               return mStatus_NoMemoryErr;
-        }
-        
-    bzero(extra, sizeof(ExtraResourceRecord));  // OK if oversized rdata not zero'd
-    extra->r.resrec.rrtype = rrtype;
-    extra->r.rdatastorage.MaxRDLength = (mDNSu16) size;
-    extra->r.resrec.rdlength = rdlen;
-    memcpy(&extra->r.rdatastorage.u.data, rdata, rdlen);
-       
-    result =  mDNS_AddRecordToService(gmDNS, srs , extra, &extra->r.rdatastorage, ttl);
-       if (result) { freeL("ExtraResourceRecord", extra); return result; }
+       // Set maximum number of open file descriptors
+       #define MIN_OPENFILES 10240
+       struct rlimit maxfds, newfds;
 
-    extra->ClientID = rstate->hdr.reg_index;
-       return result;
+       // Due to bugs in OS X (<rdar://problem/2941095>, <rdar://problem/3342704>, <rdar://problem/3839173>)
+       // you have to get and set rlimits once before getrlimit will return sensible values
+       if (getrlimit(RLIMIT_NOFILE, &maxfds) < 0) { my_perror("ERROR: Unable to get file descriptor limit"); return 0; }
+       if (setrlimit(RLIMIT_NOFILE, &maxfds) < 0) my_perror("ERROR: Unable to set maximum file descriptor limit");
+
+       if (getrlimit(RLIMIT_NOFILE, &maxfds) < 0) { my_perror("ERROR: Unable to get file descriptor limit"); return 0; }
+       newfds.rlim_max = (maxfds.rlim_max > MIN_OPENFILES) ? maxfds.rlim_max : MIN_OPENFILES;
+       newfds.rlim_cur = (maxfds.rlim_cur > MIN_OPENFILES) ? maxfds.rlim_cur : MIN_OPENFILES;
+       if (newfds.rlim_max != maxfds.rlim_max || newfds.rlim_cur != maxfds.rlim_cur)
+               if (setrlimit(RLIMIT_NOFILE, &newfds) < 0) my_perror("ERROR: Unable to set maximum file descriptor limit");
+
+       if (getrlimit(RLIMIT_NOFILE, &maxfds) < 0) { my_perror("ERROR: Unable to get file descriptor limit"); return 0; }
+       debugf("maxfds.rlim_max %d", (long)maxfds.rlim_max);
+       debugf("maxfds.rlim_cur %d", (long)maxfds.rlim_cur);
        }
+#endif
 
-mDNSlocal mStatus handle_add_request(request_state *rstate)
-    {
-    uint32_t ttl;
-    uint16_t rrtype, rdlen;
-    char *ptr, *rdata;
-    mStatus result = mStatus_UnknownErr;
-    DNSServiceFlags flags;
-       service_info *srvinfo = rstate->service_registration;
-       service_instance *i;
+       // We start a "LocalOnly" query looking for Automatic Browse Domain records.
+       // When Domain Enumeration in uDNS.c finds an "lb" record from the network, it creates a
+       // "LocalOnly" record, which results in our AutomaticBrowseDomainChange callback being invoked
+       mDNS_GetDomains(&mDNSStorage, &mDNSStorage.AutomaticBrowseDomainQ, mDNS_DomainTypeBrowseAutomatic,
+               mDNSNULL, mDNSInterface_LocalOnly, AutomaticBrowseDomainChange, mDNSNULL);
 
-       if (!srvinfo) { LogMsg("handle_add_request called with NULL service_registration"); return(-1); }
+       RegisterLocalOnlyDomainEnumPTR(&mDNSStorage, &localdomain, mDNS_DomainTypeRegistration);                // Add "local" as recommended registration domain ("dns-sd -E")
+       RegisterLocalOnlyDomainEnumPTR(&mDNSStorage, &localdomain, mDNS_DomainTypeBrowse);                              // Add "local" as recommended browsing domain ("dns-sd -F")
+       AddAutoBrowseDomain(0, &localdomain);                                                                                                                   // Add "local" as automatic browsing domain
 
-       ptr = rstate->msgdata;
-    flags = get_flags(&ptr);
-    rrtype = get_short(&ptr);
-    rdlen = get_short(&ptr);
-    rdata = get_rdata(&ptr, rdlen);
-    ttl = get_long(&ptr);
-       
-    if (!ttl) ttl = DefaultTTLforRRType(rrtype);
+       udsserver_handle_configchange(&mDNSStorage);
+       return 0;
 
-       LogOperation("%3d: DNSServiceAddRecord(%##s, %s)", rstate->sd,
-               (srvinfo->instances) ? srvinfo->instances->srs.RR_SRV.resrec.name->c : NULL, DNSTypeName(rrtype));
+error:
 
-       for (i = srvinfo->instances; i; i = i->next)
-               {
-               result = add_record_to_service(rstate, i, rrtype, rdlen, rdata, ttl);
-               if (result && i->default_local) break;
-               else result = mStatus_NoError;  // suppress non-local default errors
-               }
-       
-       return(result);
-    }
+       my_perror("ERROR: udsserver_init");
+       return -1;
+       }
 
-mDNSlocal mStatus update_record(AuthRecord *rr, uint16_t rdlen, char *rdata, uint32_t ttl)
+mDNSexport int udsserver_exit(dnssd_sock_t skt)
        {
-       int rdsize;
-       RData *newrd;
-       mStatus result;
-       
-       if (rdlen > sizeof(RDataBody)) rdsize = rdlen;
-    else rdsize = sizeof(RDataBody);
-    newrd = mallocL("handle_update_request", sizeof(RData) - sizeof(RDataBody) + rdsize);
-    if (!newrd) FatalError("ERROR: malloc");
-    newrd->MaxRDLength = (mDNSu16) rdsize;
-    memcpy(&newrd->u, rdata, rdlen);
+       // If the launching environment created no listening socket,
+       // that means we created it ourselves, so we should clean it up on exit
+       if (!dnssd_SocketValid(skt))
+               {
+               dnssd_close(listenfd);
+#if !defined(USE_TCP_LOOPBACK)
+               // Currently, we're unable to remove /var/run/mdnsd because we've changed to userid "nobody"
+               // to give up unnecessary privilege, but we need to be root to remove this Unix Domain Socket.
+               // It would be nice if we could find a solution to this problem
+               if (unlink(MDNS_UDS_SERVERPATH))
+                       debugf("Unable to remove %s", MDNS_UDS_SERVERPATH);
+#endif
+               }
 
-       // BIND named (name daemon) doesn't allow TXT records with zero-length rdata. This is strictly speaking correct,
-       // since RFC 1035 specifies a TXT record as "One or more <character-string>s", not "Zero or more <character-string>s".
-       // Since some legacy apps try to create zero-length TXT records, we'll silently correct it here.
-       if (rr->resrec.rrtype == kDNSType_TXT && rdlen == 0) { rdlen = 1; newrd->u.txt.c[0] = 0; }
+       if (PID_FILE[0]) unlink(PID_FILE);
 
-    result = mDNS_Update(gmDNS, rr, ttl, rdlen, newrd, update_callback);
-       if (result) { LogMsg("ERROR: mDNS_Update - %ld", result); freeL("handle_update_request", newrd); }
-       return result;
+       return 0;
        }
 
-mDNSlocal mStatus handle_update_request(request_state *rstate)
-    {
-       uint16_t rdlen;
-    char *ptr, *rdata;
-    uint32_t ttl;
-    mStatus result = mStatus_BadReferenceErr;
-       service_info *srvinfo = rstate->service_registration;
-       service_instance *i;
-       AuthRecord *rr = NULL;
-
-       // get the message data
-       ptr = rstate->msgdata;
-    get_flags(&ptr);   // flags unused
-    rdlen = get_short(&ptr);
-    rdata = get_rdata(&ptr, rdlen);
-    ttl = get_long(&ptr);
-
-       if (rstate->reg_recs)
+mDNSlocal void LogClientInfo(mDNS *const m, request_state *req)
+       {
+       if (!req->terminate)
+               LogMsgNoIdent("%3d: No operation yet on this socket", req->sd);
+       else if (req->terminate == connection_termination)
                {
-               // update an individually registered record
-               registered_record_entry *reptr;
-               for (reptr = rstate->reg_recs; reptr; reptr = reptr->next)
-                       {
-                       if (reptr->key == rstate->hdr.reg_index)
-                               {
-                               result = update_record(reptr->rr, rdlen, rdata, ttl);
-                               goto end;
-                               }
-                       }
-               result = mStatus_BadReferenceErr;
-               goto end;
+               registered_record_entry *p;
+               LogMsgNoIdent("%3d: DNSServiceCreateConnection", req->sd);
+               for (p = req->u.reg_recs; p; p=p->next)
+                       LogMsgNoIdent(" ->  DNSServiceRegisterRecord %3d %s", p->key, ARDisplayString(m, p->rr));
                }
-
-       // update a record from a service record set
-       if (!srvinfo) { result = mStatus_BadReferenceErr;  goto end; }
-       for (i = srvinfo->instances; i; i = i->next)
+       else if (req->terminate == regservice_termination_callback)
                {
-               if (rstate->hdr.reg_index == TXT_RECORD_INDEX) rr = &i->srs.RR_TXT;
-               else
-                       {
-                       ExtraResourceRecord *e;
-                       for (e = i->srs.Extras; e; e = e->next)
-                               if (e->ClientID == rstate->hdr.reg_index) { rr = &e->r; break; }
-                       }
-
-               if (!rr) { result = mStatus_BadReferenceErr; goto end; }
-               result = update_record(rr, rdlen, rdata, ttl);
-               if (result && i->default_local) goto end;
-               else result = mStatus_NoError;  // suppress non-local default errors
+               service_instance *ptr;
+               for (ptr = req->u.servicereg.instances; ptr; ptr = ptr->next)
+                       LogMsgNoIdent("%3d: DNSServiceRegister         %##s %u", req->sd, ptr->srs.RR_SRV.resrec.name->c, SRS_PORT(&ptr->srs));
                }
+       else if (req->terminate == browse_termination_callback)
+               {
+               browser_t *blist;
+               for (blist = req->u.browser.browsers; blist; blist = blist->next)
+                       LogMsgNoIdent("%3d: DNSServiceBrowse           %##s", req->sd, blist->q.qname.c);
+               }
+       else if (req->terminate == resolve_termination_callback)
+               LogMsgNoIdent("%3d: DNSServiceResolve          %##s", req->sd, req->u.resolve.qsrv.qname.c);
+       else if (req->terminate == queryrecord_termination_callback)
+               LogMsgNoIdent("%3d: DNSServiceQueryRecord      %##s (%s)", req->sd, req->u.queryrecord.q.qname.c, DNSTypeName(req->u.queryrecord.q.qtype));
+       else if (req->terminate == enum_termination_callback)
+               LogMsgNoIdent("%3d: DNSServiceEnumerateDomains %##s", req->sd, req->u.enumeration.q_all.qname.c);
+       else if (req->terminate == port_mapping_termination_callback)
+               LogMsgNoIdent("%3d: DNSServiceNATPortMapping   %.4a %s%s Int %d Req %d Ext %d Req TTL %d Granted TTL %d",
+                       req->sd,
+                       &req->u.pm.NATinfo.ExternalAddress,
+                       req->u.pm.NATinfo.Protocol & NATOp_MapTCP ? "TCP" : "   ",
+                       req->u.pm.NATinfo.Protocol & NATOp_MapUDP ? "UDP" : "   ",
+                       mDNSVal16(req->u.pm.NATinfo.IntPort),
+                       mDNSVal16(req->u.pm.ReqExt),
+                       mDNSVal16(req->u.pm.NATinfo.ExternalPort),
+                       req->u.pm.NATinfo.NATLease,
+                       req->u.pm.NATinfo.Lifetime);
+       else if (req->terminate == addrinfo_termination_callback)
+               LogMsgNoIdent("%3d: DNSServiceGetAddrInfo      %s%s %##s", req->sd,
+                       req->u.addrinfo.protocol & kDNSServiceProtocol_IPv4 ? "v4" : "  ",
+                       req->u.addrinfo.protocol & kDNSServiceProtocol_IPv6 ? "v6" : "  ",
+                       req->u.addrinfo.q4.qname.c);
+       else
+               LogMsgNoIdent("%3d: Unrecognized operation %p", req->sd, req->terminate);
+       }
 
-end:
-       LogOperation("%3d: DNSServiceUpdateRecord(%##s, %s)", rstate->sd,
-               (srvinfo->instances) ? srvinfo->instances->srs.RR_SRV.resrec.name->c : NULL,
-               rr ? DNSTypeName(rr->resrec.rrtype) : "<NONE>");
+mDNSexport void udsserver_info(mDNS *const m)
+       {
+       mDNSs32 now = mDNS_TimeNow(m);
+       mDNSu32 CacheUsed = 0, CacheActive = 0;
+       mDNSu32 slot;
+       CacheGroup *cg;
+       CacheRecord *cr;
 
-    return(result);
-    }
-    
-mDNSlocal void update_callback(mDNS *const m, AuthRecord *const rr, RData *oldrd)
-    {
-    (void)m; // Unused
-    if (oldrd != &rr->rdatastorage) freeL("update_callback", oldrd);
-    }
+       LogMsgNoIdent("Timenow 0x%08lX (%ld)", (mDNSu32)now, now);
+       LogMsgNoIdent("------------ Cache -------------");
 
-mDNSlocal void free_service_instance(service_instance *srv)
-       {
-       request_state *rstate = srv->request;
-       ExtraResourceRecord *e = srv->srs.Extras, *tmp;
-       
-       // clear pointers from parent struct
-       if (rstate)
-               {
-               service_instance *ptr = rstate->service_registration->instances, *prev = NULL;
-               while (ptr)
+       LogMsgNoIdent("Slt Q     TTL if    U Type rdlen");
+       for (slot = 0; slot < CACHE_HASH_SLOTS; slot++)
+               for (cg = m->rrcache_hash[slot]; cg; cg=cg->next)
                        {
-                       if (ptr == srv)
+                       CacheUsed++;    // Count one cache entity for the CacheGroup object
+                       for (cr = cg->members; cr; cr=cr->next)
                                {
-                               if (prev) prev->next = ptr->next;
-                               else rstate->service_registration->instances = ptr->next;
-                               break;
+                               mDNSs32 remain = cr->resrec.rroriginalttl - (now - cr->TimeRcvd) / mDNSPlatformOneSecond;
+                               NetworkInterfaceInfo *info = (NetworkInterfaceInfo *)cr->resrec.InterfaceID;
+                               CacheUsed++;
+                               if (cr->CRActiveQuestion) CacheActive++;
+                               LogMsgNoIdent("%3d %s%8ld %-6s%s %-6s%s",
+                                       slot,
+                                       cr->CRActiveQuestion ? "*" : " ",
+                                       remain,
+                                       info ? info->ifname : "-U-",
+                                       (cr->resrec.RecordType == kDNSRecordTypePacketNegative)  ? "-" :
+                                       (cr->resrec.RecordType & kDNSRecordTypePacketUniqueMask) ? " " : "+",
+                                       DNSTypeName(cr->resrec.rrtype),
+                                       CRDisplayString(m, cr));
+                               usleep(1000);   // Limit rate a little so we don't flood syslog too fast
                                }
-                       prev = ptr;
-                       ptr = ptr->next;
                        }
-               }
-       
-       while(e)
+
+       if (m->rrcache_totalused != CacheUsed)
+               LogMsgNoIdent("Cache use mismatch: rrcache_totalused is %lu, true count %lu", m->rrcache_totalused, CacheUsed);
+       if (m->rrcache_active != CacheActive)
+               LogMsgNoIdent("Cache use mismatch: rrcache_active is %lu, true count %lu", m->rrcache_active, CacheActive);
+       LogMsgNoIdent("Cache currently contains %lu entities; %lu referenced by active questions", CacheUsed, CacheActive);
+
+       LogMsgNoIdent("--------- Auth Records ---------");
+       if (!m->ResourceRecords) LogMsgNoIdent("<None>");
+       else
                {
-               e->r.RecordContext = e;
-               tmp = e;
-               e = e->next;
-               FreeExtraRR(gmDNS, &tmp->r, mStatus_MemFree);
+               AuthRecord *ar;
+               for (ar = m->ResourceRecords; ar; ar=ar->next)
+                       LogMsgNoIdent("%s", ARDisplayString(m, ar));
                }
-       
-       if (srv->subtypes) { freeL("regservice_callback", srv->subtypes); srv->subtypes = NULL; }
-       freeL("regservice_callback", srv);
-       }
-
-mDNSlocal void regservice_termination_callback(void *context)
-    {
-       service_info *info = context;
-       service_instance *i, *p;
-       if (!info) { LogMsg("regservice_termination_callback context is NULL"); return; }
-       if (!info->request) { LogMsg("regservice_termination_callback info->request is NULL"); return; }
-       i = info->instances;
-       while (i)
-               {
-               p = i;
-               i = i->next;
-               p->request = NULL;  // clear back pointer
-               // only safe to free memory if registration is not valid, i.e. deregister fails (which invalidates p)
-               LogOperation("%3d: DNSServiceRegister(%##s, %u) STOP", info->request->sd, p->srs.RR_SRV.resrec.name->c, mDNSVal16(p->srs.RR_SRV.resrec.rdata->u.srv.port));
-               if (mDNS_DeregisterService(gmDNS, &p->srs)) free_service_instance(p);
-               }
-       info->request->service_registration = NULL; // clear pointer from request back to info
-       if (info->txtdata) { freeL("txtdata", info->txtdata); info->txtdata = NULL; }
-       freeL("service_info", info);
-       }
-
-mDNSlocal mStatus handle_regrecord_request(request_state *rstate)
-    {
-    AuthRecord *rr;
-    registered_record_entry *re;
-    mStatus result;
-    
-    if (rstate->ts != t_complete)
-        {
-        LogMsg("ERROR: handle_regrecord_request - transfer state != t_complete");
-        abort_request(rstate);
-        unlink_request(rstate);
-        return(-1);
-        }
-        
-    rr = read_rr_from_ipc_msg(rstate->msgdata, 1, 1);
-    if (!rr) return(mStatus_BadParamErr);
-
-    // allocate registration entry, link into list
-    re = mallocL("handle_regrecord_request", sizeof(registered_record_entry));
-    if (!re) FatalError("ERROR: malloc");
-    re->key = rstate->hdr.reg_index;
-    re->rr = rr;
-    re->rstate = rstate;
-    re->client_context = rstate->hdr.client_context;
-    rr->RecordContext = re;
-    rr->RecordCallback = regrecord_callback;
-    re->next = rstate->reg_recs;
-    rstate->reg_recs = re;
-
-    if (!rstate->terminate)
-       {
-        rstate->terminate = connected_registration_termination;
-        rstate->termination_context = rstate;
-       }
-    
-    if (rr->resrec.rroriginalttl == 0)
-        rr->resrec.rroriginalttl = DefaultTTLforRRType(rr->resrec.rrtype);
-    
-       LogOperation("%3d: DNSServiceRegisterRecord %s", rstate->sd, RRDisplayString(gmDNS, &rr->resrec));
-    result = mDNS_Register(gmDNS, rr);
-    return(result);
-    }
-
-mDNSlocal void regrecord_callback(mDNS *const m, AuthRecord * rr, mStatus result)
-    {
-    registered_record_entry *re = rr->RecordContext;
-       request_state *rstate = re ? re->rstate : NULL;
-    int len;
-    reply_state *reply;
-    transfer_state ts;
-    (void)m; // Unused
-
-       if (!re)
-               {
-               // parent struct alreadt freed by termination callback
-               if (!result) LogMsg("Error: regrecord_callback: successful registration of orphaned record");
-               else
+
+       LogMsgNoIdent("---------- Questions -----------");
+       if (!m->Questions) LogMsgNoIdent("<None>");
+       else
+               {
+               DNSQuestion *q;
+               CacheUsed = 0;
+               CacheActive = 0;
+               LogMsgNoIdent("   Int  Next if    T NumAns Type  Name");
+               for (q = m->Questions; q; q=q->next)
                        {
-                       if (result != mStatus_MemFree) LogMsg("regrecord_callback: error %d received after parent termination", result);
-                       freeL("regrecord_callback", rr);
+                       mDNSs32 i = q->ThisQInterval / mDNSPlatformOneSecond;
+                       mDNSs32 n = (q->LastQTime + q->ThisQInterval - now) / mDNSPlatformOneSecond;
+                       NetworkInterfaceInfo *info = (NetworkInterfaceInfo *)q->InterfaceID;
+                       CacheUsed++;
+                       if (q->ThisQInterval) CacheActive++;
+                       LogMsgNoIdent("%6d%6d %-6s%s %5d  %-6s%##s%s",
+                               i, n,
+                               info ? info->ifname : mDNSOpaque16IsZero(q->TargetQID) ? "" : "-U-",
+                               mDNSOpaque16IsZero(q->TargetQID) ? " " : q->LongLived ? "L" : "O", // mDNS, long-lived, or one-shot query?
+                               q->CurrentAnswers,
+                               DNSTypeName(q->qtype), q->qname.c, q->DuplicateOf ? " (dup)" : "");
+                       usleep(1000);   // Limit rate a little so we don't flood syslog too fast
                        }
-               return;
+               LogMsgNoIdent("%lu question%s; %lu active", CacheUsed, CacheUsed > 1 ? "s" : "", CacheActive);
                }
-       
-    // format result, add to the list for the request, including the client context in the header
-    len = sizeof(DNSServiceFlags);
-    len += sizeof(uint32_t);                //interfaceIndex
-    len += sizeof(DNSServiceErrorType);
-    
-    reply = create_reply(reg_record_reply, len, rstate);
-    reply->mhdr->client_context = re->client_context;
-    reply->rhdr->flags = dnssd_htonl(0);
-    reply->rhdr->ifi = dnssd_htonl(mDNSPlatformInterfaceIndexfromInterfaceID(gmDNS, rr->resrec.InterfaceID));
-    reply->rhdr->error = dnssd_htonl(result);
-
-       if (result)
-               {
-               // unlink from list, free memory
-               registered_record_entry **ptr = &re->rstate->reg_recs;
-               while (*ptr && (*ptr) != re) ptr = &(*ptr)->next;
-               if (!*ptr) { LogMsg("regrecord_callback - record not in list!"); return; }
-               *ptr = (*ptr)->next;
-               freeL("regrecord_callback", re->rr);
-               re->rr = rr = NULL;
-               freeL("regrecord_callback", re);
-               re = NULL;
+
+       LogMsgNoIdent("---- Active Client Requests ----");
+       if (!all_requests) LogMsgNoIdent("<None>");
+       else
+               {
+               request_state *req;
+               for (req = all_requests; req; req=req->next)
+                       LogClientInfo(m, req);
                }
-       
-    ts = send_msg(reply);
-       
-    if (ts == t_error || ts == t_terminated) { abort_request(rstate); unlink_request(rstate); }
-    else if (ts == t_complete) freeL("regrecord_callback", reply);
-    else if (ts == t_morecoming) append_reply(rstate, reply);   // client is blocked, link reply into list
-       }
-
-mDNSlocal void connected_registration_termination(void *context)
-    {
-    int shared;
-    registered_record_entry *fptr, *ptr = ((request_state *)context)->reg_recs;
-    while(ptr)
-        {
-        fptr = ptr;
-        ptr = ptr->next;
-        shared = fptr->rr->resrec.RecordType == kDNSRecordTypeShared;
-               fptr->rr->RecordContext = NULL;
-        mDNS_Deregister(gmDNS, fptr->rr);
-        freeL("connected_registration_termination", fptr);
-               }
-       }
-    
-mDNSlocal mStatus handle_removerecord_request(request_state *rstate)
-    {
-    mStatus err = mStatus_BadReferenceErr;
-    char *ptr;
-       service_info *srvinfo = rstate->service_registration;
-
-    ptr = rstate->msgdata;
-    get_flags(&ptr);   // flags unused
-
-       if (rstate->reg_recs)  err = remove_record(rstate);  // remove individually registered record
-       else if (!srvinfo) LogOperation("%3d: DNSServiceRemoveRecord (bad ref)", rstate->sd);
-    else
+
+       LogMsgNoIdent("-------- NAT Traversals --------");
+       if (!m->NATTraversals) LogMsgNoIdent("<None>");
+       else
                {
-               service_instance *i;
-               LogOperation("%3d: DNSServiceRemoveRecord(%##s)", rstate->sd,
-                       (srvinfo->instances) ? srvinfo->instances->srs.RR_SRV.resrec.name->c : NULL);
-               for (i = srvinfo->instances; i; i = i->next)
+               NATTraversalInfo *nat;
+               for (nat = m->NATTraversals; nat; nat=nat->next)
                        {
-                       err = remove_extra(rstate, i);
-                       if (err && i->default_local) break;
-                       else err = mStatus_NoError;  // suppress non-local default errors
+                       if (nat->Protocol)
+                               LogMsgNoIdent("%p %s Int %5d Ext %5d Err %d Retry %d Interval %d Expire %d",
+                                       nat, nat->Protocol == NATOp_MapTCP ? "TCP" : "UDP",
+                                       mDNSVal16(nat->IntPort), mDNSVal16(nat->ExternalPort), nat->Result,
+                                       nat->retryPortMap ? (nat->retryPortMap - now) / mDNSPlatformOneSecond : 0,
+                                       nat->retryInterval / mDNSPlatformOneSecond,
+                                       nat->ExpiryTime ? (nat->ExpiryTime - now) / mDNSPlatformOneSecond : 0);
+                       else
+                               LogMsgNoIdent("%p Address Request Retry %d Interval %d", nat,
+                                       (m->retryGetAddr - now) / mDNSPlatformOneSecond,
+                                       m->retryIntervalGetAddr / mDNSPlatformOneSecond);
                        }
                }
-       
-    return(err);
-    }
 
-// remove a resource record registered via DNSServiceRegisterRecord()
-mDNSlocal mStatus remove_record(request_state *rstate)
-    {
-    int shared;
-    mStatus err = mStatus_UnknownErr;
-    registered_record_entry *e, **ptr = &rstate->reg_recs;
-       
-    while(*ptr && (*ptr)->key != rstate->hdr.reg_index) ptr = &(*ptr)->next;
-       if (!*ptr) { LogMsg("DNSServiceRemoveRecord - bad reference"); return mStatus_BadReferenceErr; }
-       e = *ptr;
-       *ptr = e->next; // unlink
-       
-       LogOperation("%3d: DNSServiceRemoveRecord(%#s)", rstate->sd, e->rr->resrec.name->c);
-       shared = e->rr->resrec.RecordType == kDNSRecordTypeShared;
-       e->rr->RecordContext = NULL;
-       err = mDNS_Deregister(gmDNS, e->rr);
-       if (err)
+       LogMsgNoIdent("--------- AuthInfoList ---------");
+       if (!m->AuthInfoList) LogMsgNoIdent("<None>");
+       else
                {
-               LogMsg("ERROR: remove_record, mDNS_Deregister: %ld", err);
-               freeL("remove_record", e->rr);
-               freeL("remove_record", e);
+               DomainAuthInfo *a;
+               for (a = m->AuthInfoList; a; a = a->next)
+                       LogMsgNoIdent("%##s %##s%s", a->domain.c, a->keyname.c, a->AutoTunnel ? " AutoTunnel" : "");
                }
-       return err;
-    }
-
-mDNSlocal mStatus remove_extra(request_state *rstate, service_instance *serv)
-       {
-       mStatus err = mStatus_BadReferenceErr;
-       ExtraResourceRecord *ptr;
 
-       for (ptr = serv->srs.Extras; ptr; ptr = ptr->next)
+       #if APPLE_OSX_mDNSResponder
+       LogMsgNoIdent("--------- TunnelClients ---------");
+       if (!m->TunnelClients) LogMsgNoIdent("<None>");
+       else
                {
-               if (ptr->ClientID == rstate->hdr.reg_index) // found match
-                       return mDNS_RemoveRecordFromService(gmDNS, &serv->srs, ptr, FreeExtraRR, ptr);
+               ClientTunnel *c;
+               for (c = m->TunnelClients; c; c = c->next)
+                       LogMsgNoIdent("%##s local %.16a %.4a remote %.16a %.4a %5d interval %d", c->dstname.c, &c->loc_inner, &c->loc_outer, &c->rmt_inner, &c->rmt_outer, mDNSVal16(c->rmt_outer_port), c->q.ThisQInterval);
                }
-       return err;
+       #endif
        }
 
-// domain enumeration
-mDNSlocal void handle_enum_request(request_state *rstate)
-    {
-    DNSServiceFlags flags;
-    uint32_t ifi;
-    mDNSInterfaceID InterfaceID;
-    char *ptr = rstate->msgdata;
-    domain_enum_t *def, *all;
-    enum_termination_t *term;
-    mStatus err;
-    int result;
-    
-    if (rstate->ts != t_complete)
-        {
-        LogMsg("ERROR: handle_enum_request - transfer state != t_complete");
-        abort_request(rstate);
-        unlink_request(rstate);
-        return;
-        }
-        
-    flags = get_flags(&ptr);
-    ifi = get_long(&ptr);
-    InterfaceID = mDNSPlatformInterfaceIDfromInterfaceIndex(gmDNS, ifi);
-    if (ifi && !InterfaceID)
-       {
-               deliver_error(rstate, mStatus_BadParamErr);
-               abort_request(rstate);
-               unlink_request(rstate);
-               return;
-       }
-
-    // allocate context structures
-    def = mallocL("handle_enum_request", sizeof(domain_enum_t));
-    all = mallocL("handle_enum_request", sizeof(domain_enum_t));
-    term = mallocL("handle_enum_request", sizeof(enum_termination_t));
-    if (!def || !all || !term) FatalError("ERROR: malloc");
-
-#if defined(MDNS_LAZY_REGISTER_SEARCH_DOMAINS)
-       dDNS_RegisterSearchDomains( gmDNS );
-#endif
-               
-    // enumeration requires multiple questions, so we must link all the context pointers so that
-    // necessary context can be reached from the callbacks
-    def->rstate = rstate;
-    all->rstate = rstate;
-    term->def = def;
-    term->all = all;
-    term->rstate = rstate;
-    rstate->termination_context = term;
-    rstate->terminate = enum_termination_callback;
-    def->question.QuestionContext = def;
-    def->type = (flags & kDNSServiceFlagsRegistrationDomains) ?
-        mDNS_DomainTypeRegistrationDefault: mDNS_DomainTypeBrowseDefault;
-    all->question.QuestionContext = all;
-    all->type = (flags & kDNSServiceFlagsRegistrationDomains) ?
-        mDNS_DomainTypeRegistration : mDNS_DomainTypeBrowse;
-
-       // if the caller hasn't specified an explicit interface, we use local-only to get the system-wide list.
-       if (!InterfaceID) InterfaceID = mDNSInterface_LocalOnly;
-       
-    // make the calls
-       LogOperation("%3d: DNSServiceEnumerateDomains(%X=%s)", rstate->sd, flags,
-               (flags & kDNSServiceFlagsBrowseDomains      ) ? "kDNSServiceFlagsBrowseDomains" :
-               (flags & kDNSServiceFlagsRegistrationDomains) ? "kDNSServiceFlagsRegistrationDomains" : "<<Unknown>>");
-    err = mDNS_GetDomains(gmDNS, &all->question, all->type, NULL, InterfaceID, enum_result_callback, all);
-    if (err == mStatus_NoError)
-        err = mDNS_GetDomains(gmDNS, &def->question, def->type, NULL, InterfaceID, enum_result_callback, def);
-    result = deliver_error(rstate, err);  // send error *before* returning local domain
-    
-    if (result < 0 || err)
-        {
-        abort_request(rstate);
-        unlink_request(rstate);
-        return;
-        }
-    }
-
-mDNSlocal void enum_result_callback(mDNS *const m, DNSQuestion *question, const ResourceRecord *const answer, mDNSBool AddRecord)
-    {
-    char domain[MAX_ESCAPED_DOMAIN_NAME];
-    domain_enum_t *de = question->QuestionContext;
-    DNSServiceFlags flags = 0;
-    reply_state *reply;
-    (void)m; // Unused
-
-    if (answer->rrtype != kDNSType_PTR) return;
-       if (!AddRecord && de->type != mDNS_DomainTypeBrowse) return;
-       
-    if (AddRecord)
-       {
-        flags |= kDNSServiceFlagsAdd;
-        if (de->type == mDNS_DomainTypeRegistrationDefault || de->type == mDNS_DomainTypeBrowseDefault)
-            flags |= kDNSServiceFlagsDefault;
-       }
-    ConvertDomainNameToCString(&answer->rdata->u.name, domain);
-       // note that we do NOT propagate specific interface indexes to the client - for example, a domain we learn from
-       // a machine's system preferences may be discovered on the LocalOnly interface, but should be browsed on the
-       // network, so we just pass kDNSServiceInterfaceIndexAny
-    reply = format_enumeration_reply(de->rstate, domain, flags, kDNSServiceInterfaceIndexAny, kDNSServiceErr_NoError);
-    if (!reply)
-       {
-        LogMsg("ERROR: enum_result_callback, format_enumeration_reply");
-        return;
-       }
-    reply->next = NULL;
-    append_reply(de->rstate, reply);
-    return;
-    }
-
-mDNSlocal reply_state *format_enumeration_reply(request_state *rstate, const char *domain, DNSServiceFlags flags, uint32_t ifi, DNSServiceErrorType err)
-    {
-    size_t len;
-    reply_state *reply;
-    char *data;
-
-    len = sizeof(DNSServiceFlags);
-    len += sizeof(uint32_t);
-    len += sizeof(DNSServiceErrorType);
-    len += strlen(domain) + 1;
-
-    reply = create_reply(enumeration_reply, len, rstate);
-    reply->rhdr->flags = dnssd_htonl(flags);
-    reply->rhdr->ifi = dnssd_htonl(ifi);
-    reply->rhdr->error = dnssd_htonl(err);
-    data = reply->sdata;
-    put_string(domain, &data);
-    return reply;
-    }
-
-mDNSlocal void enum_termination_callback(void *context)
-    {
-    enum_termination_t *t = context;
-    mDNS *coredata = gmDNS;
-
-    mDNS_StopGetDomains(coredata, &t->all->question);
-    mDNS_StopGetDomains(coredata, &t->def->question);
-    freeL("enum_termination_callback", t->all);
-    freeL("enum_termination_callback", t->def);
-    t->rstate->termination_context = NULL;
-    freeL("enum_termination_callback", t);
-    }
-
-mDNSlocal void handle_reconfirm_request(request_state *rstate)
-    {
-    AuthRecord *rr = read_rr_from_ipc_msg(rstate->msgdata, 0, 0);
-    if (rr)
-               {
-               mStatus status = mDNS_ReconfirmByValue(gmDNS, &rr->resrec);
-               LogOperation(
-                       (status == mStatus_NoError) ?
-                       "%3d: DNSServiceReconfirmRecord(%s) interface %d initiated" :
-                       "%3d: DNSServiceReconfirmRecord(%s) interface %d failed: %d",
-                       rstate->sd, RRDisplayString(gmDNS, &rr->resrec),
-                       mDNSPlatformInterfaceIndexfromInterfaceID(gmDNS, rr->resrec.InterfaceID), status);
-               status = 0;  // Adding this line eliminates a build failure when building mDNSPosix on Tiger
-               }
-       abort_request(rstate);
-       unlink_request(rstate);
-       freeL("handle_reconfirm_request", rr);
-       }
-
-// setup rstate to accept new reg/dereg requests
-mDNSlocal void reset_connected_rstate(request_state *rstate)
-    {
-    rstate->ts = t_morecoming;
-    rstate->hdr_bytes = 0;
-    rstate->data_bytes = 0;
-    if (rstate->msgbuf) freeL("reset_connected_rstate", rstate->msgbuf);
-    rstate->msgbuf = NULL;
-    rstate->bufsize = 0;
-    }
-
-// returns a resource record (allocated w/ malloc) containing the data found in an IPC message
-// data must be in format flags, interfaceIndex, name, rrtype, rrclass, rdlen, rdata, (optional)ttl
-// (ttl only extracted/set if ttl argument is non-zero).  returns NULL for a bad-parameter error
-mDNSlocal AuthRecord *read_rr_from_ipc_msg(char *msgbuf, int GetTTL, int validate_flags)
-    {
-    char *rdata, name[256];
-    AuthRecord *rr;
-    DNSServiceFlags flags;
-    uint32_t interfaceIndex;
-    uint16_t type, class, rdlen;
-    int storage_size;
-
-    flags = get_flags(&msgbuf);
-       if (validate_flags &&
-               !((flags & kDNSServiceFlagsShared) == kDNSServiceFlagsShared) &&
-               !((flags & kDNSServiceFlagsUnique) == kDNSServiceFlagsUnique))
+#if APPLE_OSX_mDNSResponder && MACOSX_MDNS_MALLOC_DEBUGGING
+mDNSexport void uds_validatelists(void)
+       {
+       request_state *req;
+       for (req = all_requests; req; req=req->next)
                {
-               LogMsg("ERROR: Bad resource record flags (must be kDNSServiceFlagsShared or kDNSServiceFlagsUnique)");
-               return NULL;
-               }
-       
-       interfaceIndex = get_long(&msgbuf);
-    if (get_string(&msgbuf, name, 256) < 0)
-        {
-        LogMsg("ERROR: read_rr_from_ipc_msg - get_string");
-        return NULL;
-        }
-    type = get_short(&msgbuf);
-    class = get_short(&msgbuf);
-    rdlen = get_short(&msgbuf);
-
-    if (rdlen > sizeof(RDataBody)) storage_size = rdlen;
-    else storage_size = sizeof(RDataBody);
-    
-    rr = mallocL("read_rr_from_ipc_msg", sizeof(AuthRecord) - sizeof(RDataBody) + storage_size);
-    if (!rr) FatalError("ERROR: malloc");
-    bzero(rr, sizeof(AuthRecord));  // ok if oversized rdata not zero'd
-    
-    mDNS_SetupResourceRecord(rr, mDNSNULL, mDNSPlatformInterfaceIDfromInterfaceIndex(gmDNS, interfaceIndex),
-               type, 0, (mDNSu8) ((flags & kDNSServiceFlagsShared) ? kDNSRecordTypeShared : kDNSRecordTypeUnique), mDNSNULL, mDNSNULL);
-    
-    if (!MakeDomainNameFromDNSNameString(rr->resrec.name, name))
-       {
-        LogMsg("ERROR: bad name: %s", name);
-        freeL("read_rr_from_ipc_msg", rr);
-        return NULL;
-       }
-    
-    if (flags & kDNSServiceFlagsAllowRemoteQuery) rr->AllowRemoteQuery  = mDNStrue;
-    rr->resrec.rrclass = class;
-    rr->resrec.rdlength = rdlen;
-    rr->resrec.rdata->MaxRDLength = rdlen;
-    rdata = get_rdata(&msgbuf, rdlen);
-    memcpy(rr->resrec.rdata->u.data, rdata, rdlen);
-    if (GetTTL) rr->resrec.rroriginalttl = get_long(&msgbuf);
-    rr->resrec.namehash = DomainNameHashValue(rr->resrec.name);
-    SetNewRData(&rr->resrec, mDNSNULL, 0);     // Sets rr->rdatahash for us
-    return rr;
-    }
+               if (req->next == (request_state *)~0 || (req->sd < 0 && req->sd != -2))
+                       LogMemCorruption("UDS request list: %p is garbage (%d)", req, req->sd);
 
-mDNSlocal int build_domainname_from_strings(domainname *srv, char *name, char *regtype, char *domain)
-    {
-    domainlabel n;
-    domainname d, t;
-
-    if (!MakeDomainLabelFromLiteralString(&n, name)) return -1;
-    if (!MakeDomainNameFromDNSNameString(&t, regtype)) return -1;
-    if (!MakeDomainNameFromDNSNameString(&d, domain)) return -1;
-    if (!ConstructServiceName(srv, &n, &t, &d)) return -1;
-    return 0;
-    }
-
-// append a reply to the list in a request object
-mDNSlocal void append_reply(request_state *req, reply_state *rep)
-    {
-    reply_state *ptr;
-
-    if (!req->replies) req->replies = rep;
-    else
-       {
-        ptr = req->replies;
-        while (ptr->next) ptr = ptr->next;
-        ptr->next = rep;
-       }
-    rep->next = NULL;
-    }
-
-// read_msg may be called any time when the transfer state (rs->ts) is t_morecoming.
-// returns the current state of the request (morecoming, error, complete, terminated.)
-// if there is no data on the socket, the socket will be closed and t_terminated will be returned
-mDNSlocal int read_msg(request_state *rs)
-    {
-    uint32_t nleft;
-    int nread;
-    char buf[4];   // dummy for death notification
-    
-    if (rs->ts == t_terminated || rs->ts == t_error)
-        {
-        LogMsg("ERROR: read_msg called with transfer state terminated or error");
-        rs->ts = t_error;
-        return t_error;
-        }
-        
-    if (rs->ts == t_complete)
-       {  // this must be death or something is wrong
-        nread = recv(rs->sd, buf, 4, 0);
-        if (!nread)    {  rs->ts = t_terminated;  return t_terminated;         }
-        if (nread < 0) goto rerror;
-        LogMsg("ERROR: read data from a completed request.");
-        rs->ts = t_error;
-        return t_error;
-       }
-
-    if (rs->ts != t_morecoming)
-        {
-        LogMsg("ERROR: read_msg called with invalid transfer state (%d)", rs->ts);
-        rs->ts = t_error;
-        return t_error;
-        }
-        
-    if (rs->hdr_bytes < sizeof(ipc_msg_hdr))
-       {
-        nleft = sizeof(ipc_msg_hdr) - rs->hdr_bytes;
-        nread = recv(rs->sd, (char *)&rs->hdr + rs->hdr_bytes, nleft, 0);
-        if (nread == 0)        { rs->ts = t_terminated;  return t_terminated;          }
-        if (nread < 0) goto rerror;
-        rs->hdr_bytes += nread;
-        if (rs->hdr_bytes == sizeof(ipc_msg_hdr))
-               {
-               ConvertHeaderBytes(&rs->hdr);
-                       if (rs->hdr.version != VERSION)
-                               {
-                               LogMsg("ERROR: read_msg - client version 0x%08X does not match daemon version 0x%08X", rs->hdr.version, VERSION);
-                               rs->ts = t_error;
-                               return t_error;
-                               }
-                       }
-        if (rs->hdr_bytes > sizeof(ipc_msg_hdr))
-            {
-            LogMsg("ERROR: read_msg - read too many header bytes");
-            rs->ts = t_error;
-            return t_error;
-            }
-       }
-
-    // only read data if header is complete
-    if (rs->hdr_bytes == sizeof(ipc_msg_hdr))
-       {
-        if (rs->hdr.datalen == 0)  // ok in removerecord requests
-            {
-            rs->ts = t_complete;
-            rs->msgbuf = NULL;
-            return t_complete;
-            }
-        
-        if (!rs->msgbuf)  // allocate the buffer first time through
-            {
-            rs->msgbuf = mallocL("read_msg", rs->hdr.datalen + MSG_PAD_BYTES);
-            if (!rs->msgbuf)
-               {
-                my_perror("ERROR: malloc");
-                rs->ts = t_error;
-                return t_error;
-               }
-            rs->msgdata = rs->msgbuf;
-            bzero(rs->msgbuf, rs->hdr.datalen + MSG_PAD_BYTES);
-            }
-        nleft = rs->hdr.datalen - rs->data_bytes;
-        nread = recv(rs->sd, rs->msgbuf + rs->data_bytes, nleft, 0);
-        if (nread == 0)        { rs->ts = t_terminated;  return t_terminated;  }
-        if (nread < 0) goto rerror;
-        rs->data_bytes += nread;
-        if (rs->data_bytes > rs->hdr.datalen)
-            {
-            LogMsg("ERROR: read_msg - read too many data bytes");
-            rs->ts = t_error;
-            return t_error;
-            }
-        }
-
-    if (rs->hdr_bytes == sizeof(ipc_msg_hdr) && rs->data_bytes == rs->hdr.datalen)
-        rs->ts = t_complete;
-    else rs->ts = t_morecoming;
-
-    return rs->ts;
+               reply_state *rep;
+               for (rep = req->replies; rep; rep=rep->next)
+                 if (rep->next == (reply_state *)~0)
+                       LogMemCorruption("UDS req->replies: %p is garbage", rep);
 
-rerror:
-    if (dnssd_errno() == dnssd_EWOULDBLOCK || dnssd_errno() == dnssd_EINTR) return t_morecoming;
-    my_perror("ERROR: read_msg");
-    rs->ts = t_error;
-    return t_error;
-    }
-
-mDNSlocal int send_msg(reply_state *rs)
-    {
-    ssize_t nwriten;
-    
-    if (!rs->msgbuf)
-        {
-        LogMsg("ERROR: send_msg called with NULL message buffer");
-        return t_error;
-        }
-    
-    if (rs->request->no_reply) //!!!KRS this behavior should be optimized if it becomes more common
-        {
-        rs->ts = t_complete;
-        freeL("send_msg", rs->msgbuf);
-        return t_complete;
-        }
-
-       ConvertHeaderBytes(rs->mhdr);
-    nwriten = send(rs->sd, rs->msgbuf + rs->nwriten, rs->len - rs->nwriten, 0);
-       ConvertHeaderBytes(rs->mhdr);
-    if (nwriten < 0)
-       {
-        if (dnssd_errno() == dnssd_EINTR || dnssd_errno() == dnssd_EWOULDBLOCK) nwriten = 0;
-        else
-            {
-#if !defined(PLATFORM_NO_EPIPE)
-            if (dnssd_errno() == EPIPE)
-               {
-                debugf("%3d: broken pipe", rs->sd);
-                rs->ts = t_terminated;
-                rs->request->ts = t_terminated;
-                return t_terminated;
-               }
-            else
-#endif
-               {
-                my_perror("ERROR: send\n");
-                rs->ts = t_error;
-                return t_error;
-               }
-            }
-        }
-    rs->nwriten += nwriten;
-
-    if (rs->nwriten == rs->len)
-       {
-        rs->ts = t_complete;
-        freeL("send_msg", rs->msgbuf);
-       }
-    return rs->ts;
-    }
-
-mDNSlocal reply_state *create_reply(reply_op_t op, size_t datalen, request_state *request)
-       {
-    reply_state *reply;
-    int totallen;
-
-    if ((unsigned)datalen < sizeof(reply_hdr))
-        {
-        LogMsg("ERROR: create_reply - data length less than lenght of required fields");
-        return NULL;
-        }
-    
-    totallen = (int) (datalen + sizeof(ipc_msg_hdr));
-    reply = mallocL("create_reply", sizeof(reply_state));
-    if (!reply) FatalError("ERROR: malloc");
-    bzero(reply, sizeof(reply_state));
-    reply->ts = t_morecoming;
-    reply->sd = request->sd;
-    reply->request = request;
-    reply->len = totallen;
-    reply->msgbuf = mallocL("create_reply", totallen);
-    if (!reply->msgbuf) FatalError("ERROR: malloc");
-    bzero(reply->msgbuf, totallen);
-    reply->mhdr = (ipc_msg_hdr *)reply->msgbuf;
-    reply->rhdr = (reply_hdr *)(reply->msgbuf + sizeof(ipc_msg_hdr));
-    reply->sdata = reply->msgbuf + sizeof(ipc_msg_hdr) + sizeof(reply_hdr);
-    reply->mhdr->version = VERSION;
-    reply->mhdr->op = op;
-    reply->mhdr->datalen = totallen - sizeof(ipc_msg_hdr);
-    return reply;
-    }
-
-mDNSlocal int deliver_error(request_state *rstate, mStatus err)
-       {
-       int nwritten = -1;
-       undelivered_error_t *undeliv;
-       
-       err = dnssd_htonl(err);
-       nwritten = send(rstate->sd, (dnssd_sockbuf_t) &err, sizeof(mStatus), 0);
-       if (nwritten < (int)sizeof(mStatus))
-               {
-               if (dnssd_errno() == dnssd_EINTR || dnssd_errno() == dnssd_EWOULDBLOCK)
-                       nwritten = 0;
-               if (nwritten < 0)
+               if (req->terminate == connection_termination)
                        {
-                       my_perror("ERROR: send - unable to deliver error to client");
-                       return(-1);
+                       registered_record_entry *p;
+                       for (p = req->u.reg_recs; p; p=p->next)
+                               if (p->next == (registered_record_entry *)~0)
+                                       LogMemCorruption("UDS req->u.reg_recs: %p is garbage", p);
                        }
-               else
+               else if (req->terminate == regservice_termination_callback)
                        {
-                       //client blocked - store result and come backr
-                       undeliv = mallocL("deliver_error", sizeof(undelivered_error_t));
-                       if (!undeliv) FatalError("ERROR: malloc");
-                       undeliv->err      = err;
-                       undeliv->nwritten = nwritten;
-                       undeliv->sd       = rstate->sd;
-                       rstate->u_err     = undeliv;
-                       return 0;
+                       service_instance *p;
+                       for (p = req->u.servicereg.instances; p; p=p->next)
+                               if (p->next == (service_instance *)~0)
+                                       LogMemCorruption("UDS req->u.servicereg.instances: %p is garbage", p);
                        }
-               }
-       return 0;
-       }
-
-// returns 0 on success, -1 if send is incomplete, or on terminal failure (request is aborted)
-mDNSlocal transfer_state send_undelivered_error(request_state *rs)
-       {
-       int nwritten;
-       
-       nwritten = send(rs->u_err->sd, (char *)(&rs->u_err->err) + rs->u_err->nwritten, sizeof(mStatus) - rs->u_err->nwritten, 0);
-       if (nwritten < 0)
-               {
-               if (dnssd_errno() == dnssd_EINTR || dnssd_errno() == dnssd_EWOULDBLOCK)
-                       nwritten = 0;
-               else
+               else if (req->terminate == browse_termination_callback)
                        {
-                       my_perror("ERROR: send - unable to deliver error to client\n");
-                       return t_error;
+                       browser_t *p;
+                       for (p = req->u.browser.browsers; p; p=p->next)
+                               if (p->next == (browser_t *)~0)
+                                       LogMemCorruption("UDS req->u.browser.browsers: %p is garbage", p);
                        }
                }
-       if ((unsigned int)(nwritten + rs->u_err->nwritten) >= sizeof(mStatus))
-               {
-               freeL("send_undelivered_error", rs->u_err);
-               rs->u_err = NULL;
-               return t_complete;
-               }
-       rs->u_err->nwritten += nwritten;
-       return t_morecoming;
-       }
-
-// send bogus data along with an error code to the app callback
-// returns 0 on success (linking reply into list of not fully delivered),
-// -1 on failure (request should be aborted)
-mDNSlocal int deliver_async_error(request_state *rs, reply_op_t op, mStatus err)
-    {
-    int len;
-    reply_state *reply;
-    transfer_state ts;
-    
-    if (rs->no_reply) return 0;
-    len = 256;         // long enough for any reply handler to read all args w/o buffer overrun
-    reply = create_reply(op, len, rs);
-    reply->rhdr->error = dnssd_htonl(err);
-    ts = send_msg(reply);
-    if (ts == t_error || ts == t_terminated)
-        {
-        freeL("deliver_async_error", reply);
-        return -1;
-        }
-    else if (ts == t_complete) freeL("deliver_async_error", reply);
-    else if (ts == t_morecoming) append_reply(rs, reply);   // client is blocked, link reply into list
-    return 0;
-    }
-
-mDNSlocal void abort_request(request_state *rs)
-    {
-    reply_state *rep, *ptr;
-
-    if (rs->terminate) rs->terminate(rs->termination_context);  // terminate field may not be set yet
-    if (rs->msgbuf) freeL("abort_request", rs->msgbuf);
-       LogOperation("%3d: Removing FD", rs->sd);
-    udsSupportRemoveFDFromEventLoop(rs->sd);                                   // Note: This also closes file descriptor rs->sd for us
 
-       // Don't use dnssd_InvalidSocket (-1) because that's the sentinel value MACOSX_MDNS_MALLOC_DEBUGGING uses
-       // for detecting when the memory for an object is inadvertently freed while the object is still on some list
-    rs->sd = -2;
-
-    // free pending replies
-    rep = rs->replies;
-    while(rep)
-       {
-        if (rep->msgbuf) freeL("abort_request", rep->msgbuf);
-        ptr = rep;
-        rep = rep->next;
-        freeL("abort_request", ptr);
-       }
-    
-    if (rs->u_err)
-        {
-        freeL("abort_request", rs->u_err);
-        rs->u_err = NULL;
-        }
-    }
-
-mDNSlocal void unlink_request(request_state *rs)
-    {
-    request_state *ptr;
-    
-    if (rs == all_requests)
-        {
-        all_requests = all_requests->next;
-        freeL("unlink_request", rs);
-        return;
-        }
-    for(ptr = all_requests; ptr->next; ptr = ptr->next)
-        if (ptr->next == rs)
-            {
-            ptr->next = rs->next;
-            freeL("unlink_request", rs);
-            return;
-        }
-    }
-
-//hack to search-replace perror's to LogMsg's
-mDNSlocal void my_perror(char *errmsg)
-    {
-    LogMsg("%s: %s", errmsg, dnssd_strerror(dnssd_errno()));
-    }
-
-// check that the message delivered by the client is sufficiently long to extract the required data from the buffer
-// without overrunning it.
-// returns 0 on success, -1 on error.
-
-mDNSlocal int validate_message(request_state *rstate)
-    {
-    uint32_t min_size;
-    
-    switch(rstate->hdr.op)
-       {
-        case resolve_request: min_size =       sizeof(DNSServiceFlags) +       // flags
-                                               sizeof(uint32_t) +              // interface
-                                               (3 * sizeof(char));             // name, regtype, domain
-                                               break;
-        case query_request: min_size =                 sizeof(DNSServiceFlags) +       // flags
-                                               sizeof(uint32_t) +              // interface
-                                               sizeof(char) +                  // fullname
-                                               (2 * sizeof(uint16_t));         // type, class
-                                               break;
-        case browse_request: min_size =        sizeof(DNSServiceFlags) +       // flags
-                                               sizeof(uint32_t) +              // interface
-                                               (2 * sizeof(char));             // regtype, domain
-                                               break;
-        case reg_service_request: min_size =   sizeof(DNSServiceFlags) +       // flags
-                                               sizeof(uint32_t) +              // interface
-                                               (4 * sizeof(char)) +            // name, type, domain, host
-                                               (2 * sizeof(uint16_t));         // port, textlen
-                                               break;
-        case enumeration_request: min_size =   sizeof(DNSServiceFlags) +       // flags
-                                               sizeof(uint32_t);               // interface
-                                               break;
-        case reg_record_request: min_size =    sizeof(DNSServiceFlags) +       // flags
-                                               sizeof(uint32_t) +              // interface
-                                               sizeof(char) +                  // fullname
-                                               (3 * sizeof(uint16_t)) +        // type, class, rdlen
-                                               sizeof(uint32_t);               // ttl
-                                               break;
-        case add_record_request: min_size =    sizeof(DNSServiceFlags) +       // flags
-                                               (2 * sizeof(uint16_t)) +        // type, rdlen
-                                               sizeof(uint32_t);               // ttl
-                                               break;
-        case update_record_request: min_size = sizeof(DNSServiceFlags) +       // flags
-                                               sizeof(uint16_t) +              // rdlen
-                                               sizeof(uint32_t);               // ttl
-                                               break;
-        case remove_record_request: min_size = sizeof(DNSServiceFlags);        // flags
-                                               break;
-        case reconfirm_record_request: min_size=sizeof(DNSServiceFlags) +      // flags
-                                               sizeof(uint32_t) +              // interface
-                                               sizeof(char) +                  // fullname
-                                               (3 * sizeof(uint16_t));         // type, class, rdlen
-                                   break;
-               case setdomain_request: min_size = sizeof(DNSServiceFlags) + sizeof(char);  // flags + domain
-                       break;
-               default:
-            LogMsg("ERROR: validate_message - unsupported request type: %d", rstate->hdr.op);
-           return -1;
-       }
-    
-       return (rstate->data_bytes >= min_size ? 0 : -1);
-    
-    }
-
-mDNSlocal uint32_t dnssd_htonl(uint32_t l)
-       {
-       uint32_t        ret;
-       char    *       data;
+       DNameListElem *d;
+       for (d = SCPrefBrowseDomains; d; d=d->next)
+               if (d->next == (DNameListElem *)~0 || d->name.c[0] > 63)
+                       LogMemCorruption("SCPrefBrowseDomains: %p is garbage (%d)", d, d->name.c[0]);
 
-       data = (char*) &ret;
+       ARListElem *b;
+       for (b = LocalDomainEnumRecords; b; b=b->next)
+               if (b->next == (ARListElem *)~0 || b->ar.resrec.name->c[0] > 63)
+                       LogMemCorruption("LocalDomainEnumRecords: %p is garbage (%d)", b, b->ar.resrec.name->c[0]);
 
-       put_long(l, &data);
+       for (d = AutoBrowseDomains; d; d=d->next)
+               if (d->next == (DNameListElem *)~0 || d->name.c[0] > 63)
+                       LogMemCorruption("AutoBrowseDomains: %p is garbage (%d)", d, d->name.c[0]);
 
-       return ret;
+       for (d = AutoRegistrationDomains; d; d=d->next)
+               if (d->next == (DNameListElem *)~0 || d->name.c[0] > 63)
+                       LogMemCorruption("AutoRegistrationDomains: %p is garbage (%d)", d, d->name.c[0]);
        }
+#endif
 
-#if defined(_WIN32)
-
-mDNSlocal char * win32_strerror(int inErrorCode)
+mDNSlocal int send_msg(reply_state *rep)
        {
-       static char buffer[1024];
-       DWORD       n;
+       ssize_t nwriten;
+       if (!rep->msgbuf) { LogMsg("ERROR: send_msg called with NULL message buffer"); return(rep->ts = t_error); }
+       if (rep->request->no_reply) { freeL("reply_state msgbuf (no_reply)", rep->msgbuf); return(rep->ts = t_complete); }
 
-       memset(buffer, 0, sizeof(buffer));
+       ConvertHeaderBytes(rep->mhdr);
+       nwriten = send(rep->sd, rep->msgbuf + rep->nwriten, rep->len - rep->nwriten, 0);
+       ConvertHeaderBytes(rep->mhdr);
 
-       n = FormatMessageA(
-                       FORMAT_MESSAGE_FROM_SYSTEM | FORMAT_MESSAGE_IGNORE_INSERTS,
-                       NULL,
-                       (DWORD) inErrorCode,
-                       MAKELANGID( LANG_NEUTRAL, SUBLANG_DEFAULT ),
-                       buffer,
-                       sizeof( buffer ),
-                       NULL );
+       if (nwriten < 0)
+               {
+               if (dnssd_errno() == dnssd_EINTR || dnssd_errno() == dnssd_EWOULDBLOCK) nwriten = 0;
+               else
+                       {
+#if !defined(PLATFORM_NO_EPIPE)
+                       if (dnssd_errno() == EPIPE)
+                               return(rep->request->ts = rep->ts = t_terminated);
+                       else
+#endif
+                               {
+                               LogMsg("send_msg ERROR: failed to write %d bytes to fd %d errno %d %s",
+                                       rep->len - rep->nwriten, rep->sd, dnssd_errno(), dnssd_strerror(dnssd_errno()));
+                               return(rep->ts = t_error);
+                               }
+                       }
+               }
+       rep->nwriten += nwriten;
+       if (rep->nwriten == rep->len) { freeL("reply_state msgbuf (t_complete)", rep->msgbuf); rep->ts = t_complete; }
+       return rep->ts;
+       }
+
+mDNSexport mDNSs32 udsserver_idle(mDNSs32 nextevent)
+       {
+       mDNSs32 now = mDNS_TimeNow(&mDNSStorage);
+       request_state **req = &all_requests;
 
-       if( n > 0 )
+       while (*req)
                {
-               // Remove any trailing CR's or LF's since some messages have them.
+               while ((*req)->replies)         // Send queued replies
+                       {
+                       transfer_state result;
+                       if ((*req)->replies->next) (*req)->replies->rhdr->flags |= dnssd_htonl(kDNSServiceFlagsMoreComing);
+                       result = send_msg((*req)->replies);     // Returns t_morecoming if buffer full because client is not reading
+                       if (result == t_complete)
+                               {
+                               reply_state *fptr = (*req)->replies;
+                               (*req)->replies = (*req)->replies->next;
+                               freeL("reply_state/udsserver_idle", fptr);
+                               (*req)->time_blocked = 0; // reset failure counter after successful send
+                               continue;
+                               }
+                       else if (result == t_terminated || result == t_error) abort_request(*req);
+                       break;
+                       }
+
+               if ((*req)->replies)            // If we failed to send everything, check our time_blocked timer
+                       {
+                       if (!(*req)->time_blocked) (*req)->time_blocked = NonZeroTime(now);
+                       if (now - (*req)->time_blocked >= 60 * mDNSPlatformOneSecond)
+                               {
+                               LogMsg("Could not write data to client %d after %ld seconds - aborting connection",
+                                       (*req)->sd, (now - (*req)->time_blocked) / mDNSPlatformOneSecond);
+                               LogClientInfo(&mDNSStorage, *req);
+                               abort_request(*req);
+                               }
+                       else if (nextevent - now > mDNSPlatformOneSecond) nextevent = now + mDNSPlatformOneSecond;
+                       }
 
-               while( ( n > 0 ) && isspace( ( (unsigned char *) buffer)[ n - 1 ] ) )
+               if (!dnssd_SocketValid((*req)->sd)) // If this request is finished, unlink it from the list and free the memory
                        {
-                       buffer[ --n ] = '\0';
+                       // Since we're already doing a list traversal, we unlink the request directly instead of using AbortUnlinkAndFree()
+                       request_state *tmp = *req;
+                       *req = tmp->next;
+                       freeL("request_state/udsserver_idle", tmp);
                        }
+               else
+                       req = &(*req)->next;
                }
-
-       return buffer;
+       return nextevent;
        }
 
-#endif
+struct CompileTimeAssertionChecks_uds_daemon
+       {
+       // Check our structures are reasonable sizes. Including overly-large buffers, or embedding
+       // other overly-large structures instead of having a pointer to them, can inadvertently
+       // cause structure sizes (and therefore memory usage) to balloon unreasonably.
+       char sizecheck_request_state          [(sizeof(request_state)           <= 1800) ? 1 : -1];
+       char sizecheck_registered_record_entry[(sizeof(registered_record_entry) <=   30) ? 1 : -1];
+       char sizecheck_service_instance       [(sizeof(service_instance)        <= 6000) ? 1 : -1];
+       char sizecheck_browser_t              [(sizeof(browser_t)               <= 1000) ? 1 : -1];
+       char sizecheck_reply_hdr              [(sizeof(reply_hdr)               <=   20) ? 1 : -1];
+       char sizecheck_reply_state            [(sizeof(reply_state)             <=   40) ? 1 : -1];
+       };