This library is free software; you can redistribute it and/or
modify it under the terms of the GNU Lesser General Public
License as published by the Free Software Foundation; either
- version 2 of the License, or (at your option) any later version.
+ version 3 of the License, or (at your option) any later version.
This library is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
Lesser General Public License for more details.
You should have received a copy of the GNU Lesser General Public
- License along with this library; if not, write to the Free Software
- Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
+ License along with this library; if not, see <http://www.gnu.org/licenses/>.
*/
/*
* Author: Andrew Tridgell
*/
-#include "includes.h"
-#include "ldb/ldb_tdb/ldb_tdb.h"
-
-/*
- free a message that has all parts separately allocated
-*/
-static void msg_free_all_parts(struct ldb_context *ldb, struct ldb_message *msg)
-{
- int i, j;
- ldb_free(ldb, msg->dn);
- for (i=0;i<msg->num_elements;i++) {
- ldb_free(ldb, msg->elements[i].name);
- for (j=0;j<msg->elements[i].num_values;j++) {
- ldb_free(ldb, msg->elements[i].values[j].data);
- }
- ldb_free(ldb, msg->elements[i].values);
- }
- ldb_free(ldb, msg->elements);
- ldb_free(ldb, msg);
-}
-
-
-/*
- duplicate a ldb_val structure
-*/
-struct ldb_val ldb_val_dup(struct ldb_context *ldb,
- const struct ldb_val *v)
-{
- struct ldb_val v2;
- v2.length = v->length;
- if (v->length == 0) {
- v2.data = NULL;
- return v2;
- }
-
- /* the +1 is to cope with buggy C library routines like strndup
- that look one byte beyond */
- v2.data = ldb_malloc(ldb, v->length+1);
- if (!v2.data) {
- v2.length = 0;
- return v2;
- }
-
- memcpy(v2.data, v->data, v->length);
- ((char *)v2.data)[v->length] = 0;
- return v2;
-}
-
+#include "ldb_includes.h"
+#include "ldb_tdb.h"
/*
add one element to a message
*/
-static int msg_add_element(struct ldb_context *ldb,
- struct ldb_message *ret, const struct ldb_message_element *el)
+static int msg_add_element(struct ldb_message *ret,
+ const struct ldb_message_element *el,
+ int check_duplicates)
{
- int i;
+ unsigned int i;
struct ldb_message_element *e2, *elnew;
- e2 = ldb_realloc_p(ldb, ret->elements, struct ldb_message_element, ret->num_elements+1);
+ if (check_duplicates && ldb_msg_find_element(ret, el->name)) {
+ /* its already there */
+ return 0;
+ }
+
+ e2 = talloc_realloc(ret, ret->elements, struct ldb_message_element, ret->num_elements+1);
if (!e2) {
return -1;
}
elnew = &e2[ret->num_elements];
- elnew->name = ldb_strdup(ldb, el->name);
+ elnew->name = talloc_strdup(ret->elements, el->name);
if (!elnew->name) {
return -1;
}
if (el->num_values) {
- elnew->values = ldb_malloc_array_p(ldb, struct ldb_val, el->num_values);
+ elnew->values = talloc_array(ret->elements, struct ldb_val, el->num_values);
if (!elnew->values) {
return -1;
}
}
for (i=0;i<el->num_values;i++) {
- elnew->values[i] = ldb_val_dup(ldb, &el->values[i]);
+ elnew->values[i] = ldb_val_dup(elnew->values, &el->values[i]);
if (elnew->values[i].length != el->values[i].length) {
return -1;
}
return 0;
}
+/*
+ add the special distinguishedName element
+*/
+static int msg_add_distinguished_name(struct ldb_message *msg)
+{
+ struct ldb_message_element el;
+ struct ldb_val val;
+ int ret;
+
+ el.flags = 0;
+ el.name = "distinguishedName";
+ el.num_values = 1;
+ el.values = &val;
+ val.data = (uint8_t *)ldb_dn_alloc_linearized(msg, msg->dn);
+ val.length = strlen((char *)val.data);
+
+ ret = msg_add_element(msg, &el, 1);
+ return ret;
+}
+
/*
add all elements from one message into another
*/
-static int msg_add_all_elements(struct ldb_context *ldb, struct ldb_message *ret,
+static int msg_add_all_elements(struct ldb_module *module, struct ldb_message *ret,
const struct ldb_message *msg)
{
- int i;
+ struct ldb_context *ldb = module->ldb;
+ unsigned int i;
+ int check_duplicates = (ret->num_elements != 0);
+
+ if (msg_add_distinguished_name(ret) != 0) {
+ return -1;
+ }
+
for (i=0;i<msg->num_elements;i++) {
- int flags = ltdb_attribute_flags(ldb, msg->elements[i].name);
- if (flags & LTDB_FLAG_HIDDEN) {
+ const struct ldb_schema_attribute *a;
+ a = ldb_schema_attribute_by_name(ldb, msg->elements[i].name);
+ if (a->flags & LDB_ATTR_FLAG_HIDDEN) {
continue;
}
- if (msg_add_element(ldb, ret, &msg->elements[i]) != 0) {
+ if (msg_add_element(ret, &msg->elements[i],
+ check_duplicates) != 0) {
return -1;
}
}
/*
pull the specified list of attributes from a message
*/
-static struct ldb_message *ltdb_pull_attrs(struct ldb_context *ldb,
+static struct ldb_message *ltdb_pull_attrs(struct ldb_module *module,
+ TALLOC_CTX *mem_ctx,
const struct ldb_message *msg,
const char * const *attrs)
{
struct ldb_message *ret;
int i;
- ret = ldb_malloc_p(ldb, struct ldb_message);
+ ret = talloc(mem_ctx, struct ldb_message);
if (!ret) {
return NULL;
}
- ret->dn = ldb_strdup(ldb, msg->dn);
+ ret->dn = ldb_dn_copy(ret, msg->dn);
if (!ret->dn) {
- ldb_free(ldb, ret);
+ talloc_free(ret);
return NULL;
}
ret->num_elements = 0;
ret->elements = NULL;
- ret->private_data = NULL;
if (!attrs) {
- if (msg_add_all_elements(ldb, ret, msg) != 0) {
- msg_free_all_parts(ldb, ret);
+ if (msg_add_all_elements(module, ret, msg) != 0) {
+ talloc_free(ret);
return NULL;
}
return ret;
struct ldb_message_element *el;
if (strcmp(attrs[i], "*") == 0) {
- if (msg_add_all_elements(ldb, ret, msg) != 0) {
- msg_free_all_parts(ldb, ret);
+ if (msg_add_all_elements(module, ret, msg) != 0) {
+ talloc_free(ret);
+ return NULL;
+ }
+ continue;
+ }
+
+ if (ldb_attr_cmp(attrs[i], "distinguishedName") == 0) {
+ if (msg_add_distinguished_name(ret) != 0) {
return NULL;
}
continue;
if (!el) {
continue;
}
- if (msg_add_element(ldb, ret, el) != 0) {
- msg_free_all_parts(ldb, ret);
+ if (msg_add_element(ret, el, 1) != 0) {
+ talloc_free(ret);
return NULL;
}
}
return ret;
}
-
-
/*
- see if a ldb_val is a wildcard
- return 1 if yes, 0 if no
+ search the database for a single simple dn.
+ return LDB_ERR_NO_SUCH_OBJECT on record-not-found
+ and LDB_SUCCESS on success
*/
-int ltdb_has_wildcard(struct ldb_context *ldb, const char *attr_name,
- const struct ldb_val *val)
+static int ltdb_search_base(struct ldb_module *module, struct ldb_dn *dn)
{
- int flags;
-
- /* all attribute types recognise the "*" wildcard */
- if (val->length == 1 && strncmp((char *)val->data, "*", 1) == 0) {
- return 1;
- }
+ struct ltdb_private *ltdb = (struct ltdb_private *)module->private_data;
+ TDB_DATA tdb_key, tdb_data;
- if (strpbrk(val->data, "*?") == NULL) {
- return 0;
+ if (ldb_dn_is_null(dn)) {
+ return LDB_ERR_NO_SUCH_OBJECT;
}
- flags = ltdb_attribute_flags(ldb, attr_name);
- if (flags & LTDB_FLAG_WILDCARD) {
- return 1;
+ /* form the key */
+ tdb_key = ltdb_key(module, dn);
+ if (!tdb_key.dptr) {
+ return LDB_ERR_OPERATIONS_ERROR;
}
- return 0;
-}
-
-
-/*
- free the results of a ltdb_search_dn1 search
-*/
-void ltdb_search_dn1_free(struct ldb_context *ldb, struct ldb_message *msg)
-{
- int i;
- ldb_free(ldb, msg->private_data);
- for (i=0;i<msg->num_elements;i++) {
- ldb_free(ldb, msg->elements[i].values);
+ tdb_data = tdb_fetch(ltdb->tdb, tdb_key);
+ talloc_free(tdb_key.dptr);
+ if (!tdb_data.dptr) {
+ return LDB_ERR_NO_SUCH_OBJECT;
}
- ldb_free(ldb, msg->elements);
- memset(msg, 0, sizeof(*msg));
+
+ free(tdb_data.dptr);
+ return LDB_SUCCESS;
}
-
/*
search the database for a single simple dn, returning all attributes
in a single message
- return 1 on success, 0 on record-not-found and -1 on error
+ return LDB_ERR_NO_SUCH_OBJECT on record-not-found
+ and LDB_SUCCESS on success
*/
-int ltdb_search_dn1(struct ldb_context *ldb, const char *dn, struct ldb_message *msg)
+int ltdb_search_dn1(struct ldb_module *module, struct ldb_dn *dn, struct ldb_message *msg)
{
- struct ltdb_private *ltdb = ldb->private_data;
+ struct ltdb_private *ltdb = (struct ltdb_private *)module->private_data;
int ret;
- TDB_DATA tdb_key, tdb_data, tdb_data2;
+ TDB_DATA tdb_key, tdb_data;
memset(msg, 0, sizeof(*msg));
/* form the key */
- tdb_key = ltdb_key(ldb, dn);
+ tdb_key = ltdb_key(module, dn);
if (!tdb_key.dptr) {
- return -1;
+ return LDB_ERR_OPERATIONS_ERROR;
}
tdb_data = tdb_fetch(ltdb->tdb, tdb_key);
- ldb_free(ldb, tdb_key.dptr);
+ talloc_free(tdb_key.dptr);
if (!tdb_data.dptr) {
- return 0;
+ return LDB_ERR_NO_SUCH_OBJECT;
}
-
- tdb_data2.dptr = ldb_malloc(ldb, tdb_data.dsize);
- if (!tdb_data2.dptr) {
- free(tdb_data.dptr);
- return -1;
- }
- memcpy(tdb_data2.dptr, tdb_data.dptr, tdb_data.dsize);
- free(tdb_data.dptr);
- tdb_data2.dsize = tdb_data.dsize;
-
- msg->private_data = tdb_data2.dptr;
+
msg->num_elements = 0;
msg->elements = NULL;
- ret = ltdb_unpack_data(ldb, &tdb_data2, msg);
+ ret = ltdb_unpack_data(module, &tdb_data, msg);
+ free(tdb_data.dptr);
if (ret == -1) {
- free(tdb_data2.dptr);
- return -1;
+ return LDB_ERR_OPERATIONS_ERROR;
}
if (!msg->dn) {
- msg->dn = ldb_strdup(ldb, dn);
+ msg->dn = ldb_dn_copy(msg, dn);
}
if (!msg->dn) {
- ldb_free(ldb, tdb_data2.dptr);
- return -1;
+ return LDB_ERR_OPERATIONS_ERROR;
}
- return 1;
+ return LDB_SUCCESS;
}
-
-/*
- search the database for a single simple dn
-*/
-int ltdb_search_dn(struct ldb_context *ldb, char *dn,
- const char * const attrs[], struct ldb_message ***res)
-{
- int ret;
- struct ldb_message msg, *msg2;
-
- ret = ltdb_search_dn1(ldb, dn, &msg);
- if (ret != 1) {
- return ret;
- }
-
- msg2 = ltdb_pull_attrs(ldb, &msg, attrs);
-
- ltdb_search_dn1_free(ldb, &msg);
-
- if (!msg2) {
- return -1;
- }
-
- *res = ldb_malloc_array_p(ldb, struct ldb_message *, 2);
- if (! *res) {
- msg_free_all_parts(ldb, msg2);
- return -1;
- }
-
- (*res)[0] = msg2;
- (*res)[1] = NULL;
-
- return 1;
-}
-
-
/*
add a set of attributes from a record to a set of results
return 0 on success, -1 on failure
*/
-int ltdb_add_attr_results(struct ldb_context *ldb, struct ldb_message *msg,
+int ltdb_add_attr_results(struct ldb_module *module,
+ TALLOC_CTX *mem_ctx,
+ struct ldb_message *msg,
const char * const attrs[],
unsigned int *count,
struct ldb_message ***res)
struct ldb_message **res2;
/* pull the attributes that the user wants */
- msg2 = ltdb_pull_attrs(ldb, msg, attrs);
+ msg2 = ltdb_pull_attrs(module, mem_ctx, msg, attrs);
if (!msg2) {
return -1;
}
/* add to the results list */
- res2 = ldb_realloc_p(ldb, *res, struct ldb_message *, (*count)+2);
+ res2 = talloc_realloc(mem_ctx, *res, struct ldb_message *, (*count)+2);
if (!res2) {
- msg_free_all_parts(ldb, msg2);
+ talloc_free(msg2);
return -1;
}
(*res) = res2;
- (*res)[*count] = msg2;
+ (*res)[*count] = talloc_move(*res, &msg2);
(*res)[(*count)+1] = NULL;
(*count)++;
}
+
/*
- internal search state during a full db search
-*/
-struct ltdb_search_info {
- struct ldb_context *ldb;
- struct ldb_parse_tree *tree;
- const char *base;
- enum ldb_scope scope;
- const char * const *attrs;
- struct ldb_message **msgs;
- int failures;
- int count;
-};
+ filter the specified list of attributes from a message
+ removing not requested attrs.
+ */
+int ltdb_filter_attrs(struct ldb_message *msg, const char * const *attrs)
+{
+ int i, keep_all = 0;
+
+ if (attrs) {
+ /* check for special attrs */
+ for (i = 0; attrs[i]; i++) {
+ if (strcmp(attrs[i], "*") == 0) {
+ keep_all = 1;
+ break;
+ }
+
+ if (ldb_attr_cmp(attrs[i], "distinguishedName") == 0) {
+ if (msg_add_distinguished_name(msg) != 0) {
+ return -1;
+ }
+ }
+ }
+ } else {
+ keep_all = 1;
+ }
+
+ if (keep_all) {
+ if (msg_add_distinguished_name(msg) != 0) {
+ return -1;
+ }
+ return 0;
+ }
+
+ for (i = 0; i < msg->num_elements; i++) {
+ int j, found;
+
+ for (j = 0, found = 0; attrs[j]; j++) {
+ if (ldb_attr_cmp(msg->elements[i].name, attrs[j]) == 0) {
+ found = 1;
+ break;
+ }
+ }
+
+ if (!found) {
+ ldb_msg_remove_attr(msg, msg->elements[i].name);
+ i--;
+ }
+ }
+ return 0;
+}
/*
search function for a non-indexed search
*/
static int search_func(struct tdb_context *tdb, TDB_DATA key, TDB_DATA data, void *state)
{
- struct ltdb_search_info *sinfo = state;
- struct ldb_message msg;
+ struct ltdb_context *ac;
+ struct ldb_message *msg;
int ret;
+ ac = talloc_get_type(state, struct ltdb_context);
+
if (key.dsize < 4 ||
- strncmp(key.dptr, "DN=", 3) != 0) {
+ strncmp((char *)key.dptr, "DN=", 3) != 0) {
return 0;
}
+ msg = ldb_msg_new(ac);
+ if (!msg) {
+ return -1;
+ }
+
/* unpack the record */
- ret = ltdb_unpack_data(sinfo->ldb, &data, &msg);
+ ret = ltdb_unpack_data(ac->module, &data, msg);
if (ret == -1) {
- sinfo->failures++;
- return 0;
+ talloc_free(msg);
+ return -1;
}
- if (!msg.dn) {
- msg.dn = key.dptr + 3;
+ if (!msg->dn) {
+ msg->dn = ldb_dn_new(msg, ac->module->ldb,
+ (char *)key.dptr + 3);
+ if (msg->dn == NULL) {
+ talloc_free(msg);
+ return -1;
+ }
}
/* see if it matches the given expression */
- if (!ldb_message_match(sinfo->ldb, &msg, sinfo->tree,
- sinfo->base, sinfo->scope)) {
- ltdb_unpack_data_free(sinfo->ldb, &msg);
+ if (!ldb_match_msg(ac->module->ldb, msg,
+ ac->tree, ac->base, ac->scope)) {
+ talloc_free(msg);
return 0;
}
- ret = ltdb_add_attr_results(sinfo->ldb, &msg, sinfo->attrs, &sinfo->count, &sinfo->msgs);
+ /* filter the attributes that the user wants */
+ ret = ltdb_filter_attrs(msg, ac->attrs);
if (ret == -1) {
- sinfo->failures++;
- }
-
- ltdb_unpack_data_free(sinfo->ldb, &msg);
-
- return ret;
-}
-
-
-/*
- free a set of search results
-*/
-int ltdb_search_free(struct ldb_context *ldb, struct ldb_message **msgs)
-{
- struct ltdb_private *ltdb = ldb->private_data;
- int i;
-
- ltdb->last_err_string = NULL;
-
- if (!msgs) return 0;
-
- for (i=0;msgs[i];i++) {
- msg_free_all_parts(ldb, msgs[i]);
+ talloc_free(msg);
+ return -1;
}
- ldb_free(ldb, msgs);
+ ret = ldb_module_send_entry(ac->req, msg, NULL);
+ if (ret != LDB_SUCCESS) {
+ ac->callback_failed = true;
+ /* the callback failed, abort the operation */
+ return -1;
+ }
return 0;
}
+
/*
search the database with a LDAP-like expression.
- this is the "full search" non-indexed varient
+ this is the "full search" non-indexed variant
*/
-static int ltdb_search_full(struct ldb_context *ldb,
- const char *base,
- enum ldb_scope scope,
- struct ldb_parse_tree *tree,
- const char * const attrs[], struct ldb_message ***res)
+static int ltdb_search_full(struct ltdb_context *ctx)
{
- struct ltdb_private *ltdb = ldb->private_data;
+ struct ltdb_private *ltdb = talloc_get_type(ctx->module->private_data, struct ltdb_private);
int ret;
- struct ltdb_search_info sinfo;
- sinfo.tree = tree;
- sinfo.ldb = ldb;
- sinfo.scope = scope;
- sinfo.base = base;
- sinfo.attrs = attrs;
- sinfo.msgs = NULL;
- sinfo.count = 0;
- sinfo.failures = 0;
-
- ret = tdb_traverse(ltdb->tdb, search_func, &sinfo);
+ if (ltdb->in_transaction != 0) {
+ ret = tdb_traverse(ltdb->tdb, search_func, ctx);
+ } else {
+ ret = tdb_traverse_read(ltdb->tdb, search_func, ctx);
+ }
if (ret == -1) {
- ltdb_search_free(ldb, sinfo.msgs);
- return -1;
+ return LDB_ERR_OPERATIONS_ERROR;
}
- *res = sinfo.msgs;
- return sinfo.count;
+ return LDB_SUCCESS;
}
-
/*
search the database with a LDAP-like expression.
choses a search method
*/
-int ltdb_search(struct ldb_context *ldb, const char *base,
- enum ldb_scope scope, const char *expression,
- const char * const attrs[], struct ldb_message ***res)
+int ltdb_search(struct ltdb_context *ctx)
{
- struct ltdb_private *ltdb = ldb->private_data;
- struct ldb_parse_tree *tree;
+ struct ldb_module *module = ctx->module;
+ struct ldb_request *req = ctx->req;
+ struct ltdb_private *ltdb = talloc_get_type(module->private_data, struct ltdb_private);
int ret;
- ltdb->last_err_string = NULL;
+ req->handle->state = LDB_ASYNC_PENDING;
- if (ltdb_cache_load(ldb) != 0) {
- return -1;
+ if (ltdb_lock_read(module) != 0) {
+ return LDB_ERR_OPERATIONS_ERROR;
}
- *res = NULL;
+ if (ltdb_cache_load(module) != 0) {
+ ltdb_unlock_read(module);
+ return LDB_ERR_OPERATIONS_ERROR;
+ }
- /* form a parse tree for the expression */
- tree = ldb_parse_tree(ldb, expression);
- if (!tree) {
- ltdb->last_err_string = "expression parse failed";
- return -1;
+ if (req->op.search.tree == NULL) {
+ ltdb_unlock_read(module);
+ return LDB_ERR_OPERATIONS_ERROR;
}
- if (tree->operation == LDB_OP_SIMPLE &&
- ldb_attr_cmp(tree->u.simple.attr, "dn") == 0 &&
- !ltdb_has_wildcard(ldb, tree->u.simple.attr, &tree->u.simple.value)) {
- /* yay! its a nice simple one */
- ret = ltdb_search_dn(ldb, tree->u.simple.value.data, attrs, res);
+ if ((req->op.search.base == NULL) || (ldb_dn_is_null(req->op.search.base) == true)) {
+
+ /* Check what we should do with a NULL dn */
+ switch (req->op.search.scope) {
+ case LDB_SCOPE_BASE:
+ ldb_asprintf_errstring(module->ldb,
+ "NULL Base DN invalid for a base search");
+ ret = LDB_ERR_INVALID_DN_SYNTAX;
+ break;
+ case LDB_SCOPE_ONELEVEL:
+ ldb_asprintf_errstring(module->ldb,
+ "NULL Base DN invalid for a one-level search");
+ ret = LDB_ERR_INVALID_DN_SYNTAX;
+ break;
+ case LDB_SCOPE_SUBTREE:
+ default:
+ /* We accept subtree searches from a NULL base DN, ie over the whole DB */
+ ret = LDB_SUCCESS;
+ }
+ } else if (ldb_dn_is_valid(req->op.search.base) == false) {
+
+ /* We don't want invalid base DNs here */
+ ldb_asprintf_errstring(module->ldb,
+ "Invalid Base DN: %s",
+ ldb_dn_get_linearized(req->op.search.base));
+ ret = LDB_ERR_INVALID_DN_SYNTAX;
+
+ } else if (ltdb->check_base) {
+ /* This database has been marked as 'checkBaseOnSearch', so do a spot check of the base dn */
+ ret = ltdb_search_base(module, req->op.search.base);
+
+ if (ret == LDB_ERR_NO_SUCH_OBJECT) {
+ ldb_asprintf_errstring(module->ldb,
+ "No such Base DN: %s",
+ ldb_dn_get_linearized(req->op.search.base));
+ }
+
} else {
- ret = ltdb_search_indexed(ldb, base, scope, tree, attrs, res);
- if (ret == -1) {
- ret = ltdb_search_full(ldb, base, scope, tree, attrs, res);
+ /* If we are not checking the base DN life is easy */
+ ret = LDB_SUCCESS;
+ }
+
+ ctx->tree = req->op.search.tree;
+ ctx->scope = req->op.search.scope;
+ ctx->base = req->op.search.base;
+ ctx->attrs = req->op.search.attrs;
+
+ if (ret == LDB_SUCCESS) {
+ ret = ltdb_search_indexed(ctx);
+ if (ret == LDB_ERR_NO_SUCH_OBJECT) {
+ /* Not in the index, therefore OK! */
+ ret = LDB_SUCCESS;
+
+ }
+ /* Check if we got just a normal error.
+ * In that case proceed to a full search unless we got a
+ * callback error */
+ if ( ! ctx->callback_failed && ret != LDB_SUCCESS) {
+ /* Not indexed, so we need to do a full scan */
+ ret = ltdb_search_full(ctx);
+ if (ret != LDB_SUCCESS) {
+ ldb_set_errstring(module->ldb, "Indexed and full searches both failed!\n");
+ }
}
}
- ldb_parse_tree_free(ldb, tree);
+ ltdb_unlock_read(module);
return ret;
}