1 /* ldap-int.h - defines & prototypes internal to the LDAP library */
3 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
5 * Copyright 1998-2009 The OpenLDAP Foundation.
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted only as authorized by the OpenLDAP
12 * A copy of this license is available in the file LICENSE in the
13 * top-level directory of the distribution or, alternatively, at
14 * <http://www.OpenLDAP.org/license.html>.
16 /* Portions Copyright (c) 1995 Regents of the University of Michigan.
17 * All rights reserved.
24 #define LDAP_THREAD_SAFE 1
27 #include "../liblber/lber-int.h"
30 #include <ldap_pvt_thread.h>
33 #ifdef HAVE_CYRUS_SASL
34 /* the need for this should be removed */
35 #ifdef HAVE_SASL_SASL_H
36 #include <sasl/sasl.h>
41 #define SASL_MAX_BUFF_SIZE (0xffffff)
42 #define SASL_MIN_BUFF_SIZE 4096
45 /* for struct timeval */
49 #define TV2MILLISEC(tv) (((tv)->tv_sec * 1000) + ((tv)->tv_usec/1000))
52 * Support needed if the library is running in the kernel
54 #if LDAP_INT_IN_KERNEL
56 * Platform specific function to return a pointer to the
57 * process-specific global options.
59 * This function should perform the following functions:
60 * Allocate and initialize a global options struct on a per process basis
61 * Use callers process identifier to return its global options struct
62 * Note: Deallocate structure when the process exits
64 # define LDAP_INT_GLOBAL_OPT() ldap_int_global_opt()
65 struct ldapoptions *ldap_int_global_opt(void);
67 # define LDAP_INT_GLOBAL_OPT() (&ldap_int_global_options)
70 #define ldap_debug ((LDAP_INT_GLOBAL_OPT())->ldo_debug)
78 #define Debug( level, fmt, arg1, arg2, arg3 ) \
79 do { if ( ldap_debug & level ) \
80 ldap_log_printf( NULL, (level), (fmt), (arg1), (arg2), (arg3) ); \
83 #define LDAP_Debug( subsystem, level, fmt, arg1, arg2, arg3 )\
84 ldap_log_printf( NULL, (level), (fmt), (arg1), (arg2), (arg3) )
88 #define Debug( level, fmt, arg1, arg2, arg3 ) ((void)0)
89 #define LDAP_Debug( subsystem, level, fmt, arg1, arg2, arg3 ) ((void)0)
91 #endif /* LDAP_DEBUG */
93 #define LDAP_DEPRECATED 1
100 #define LDAP_URL_PREFIX "ldap://"
101 #define LDAP_URL_PREFIX_LEN STRLENOF(LDAP_URL_PREFIX)
102 #define LDAPS_URL_PREFIX "ldaps://"
103 #define LDAPS_URL_PREFIX_LEN STRLENOF(LDAPS_URL_PREFIX)
104 #define LDAPI_URL_PREFIX "ldapi://"
105 #define LDAPI_URL_PREFIX_LEN STRLENOF(LDAPI_URL_PREFIX)
106 #ifdef LDAP_CONNECTIONLESS
107 #define LDAPC_URL_PREFIX "cldap://"
108 #define LDAPC_URL_PREFIX_LEN STRLENOF(LDAPC_URL_PREFIX)
110 #define LDAP_URL_URLCOLON "URL:"
111 #define LDAP_URL_URLCOLON_LEN STRLENOF(LDAP_URL_URLCOLON)
113 #define LDAP_REF_STR "Referral:\n"
114 #define LDAP_REF_STR_LEN STRLENOF(LDAP_REF_STR)
115 #define LDAP_LDAP_REF_STR LDAP_URL_PREFIX
116 #define LDAP_LDAP_REF_STR_LEN LDAP_URL_PREFIX_LEN
118 #define LDAP_DEFAULT_REFHOPLIMIT 5
120 #define LDAP_BOOL_REFERRALS 0
121 #define LDAP_BOOL_RESTART 1
122 #define LDAP_BOOL_TLS 3
123 #define LDAP_BOOL_CONNECT_ASYNC 4
124 #define LDAP_BOOL_SASL_NOCANON 5
126 #define LDAP_BOOLEANS unsigned long
127 #define LDAP_BOOL(n) ((LDAP_BOOLEANS)1 << (n))
128 #define LDAP_BOOL_GET(lo, bool) \
129 ((lo)->ldo_booleans & LDAP_BOOL(bool) ? -1 : 0)
130 #define LDAP_BOOL_SET(lo, bool) ((lo)->ldo_booleans |= LDAP_BOOL(bool))
131 #define LDAP_BOOL_CLR(lo, bool) ((lo)->ldo_booleans &= ~LDAP_BOOL(bool))
132 #define LDAP_BOOL_ZERO(lo) ((lo)->ldo_booleans = 0)
135 * This structure represents both ldap messages and ldap responses.
136 * These are really the same, except in the case of search responses,
137 * where a response has multiple messages.
141 ber_int_t lm_msgid; /* the message id */
142 ber_tag_t lm_msgtype; /* the message type */
143 BerElement *lm_ber; /* the ber encoded message contents */
144 struct ldapmsg *lm_chain; /* for search - next msg in the resp */
145 struct ldapmsg *lm_chain_tail;
146 struct ldapmsg *lm_next; /* next response */
147 time_t lm_time; /* used to maintain cache */
157 char *lt_ciphersuite;
164 typedef struct ldaplist {
165 struct ldaplist *ll_next;
170 * structure representing get/set'able options
171 * which have global defaults.
175 #define LDAP_UNINITIALIZED 0x0
176 #define LDAP_INITIALIZED 0x1
177 #define LDAP_VALID_SESSION 0x2
178 #define LDAP_TRASHED_SESSION 0xFF
180 #ifdef LDAP_CONNECTIONLESS
181 #define LDAP_IS_UDP(ld) ((ld)->ld_options.ldo_is_udp)
182 void* ldo_peer; /* struct sockaddr* */
187 /* per API call timeout */
188 struct timeval ldo_tm_api;
189 struct timeval ldo_tm_net;
191 ber_int_t ldo_version;
193 ber_int_t ldo_timelimit;
194 ber_int_t ldo_sizelimit;
199 LDAP_TLS_CONNECT_CB *ldo_tls_connect_cb;
200 void* ldo_tls_connect_arg;
201 struct ldaptls ldo_tls_info;
202 #define ldo_tls_certfile ldo_tls_info.lt_certfile
203 #define ldo_tls_keyfile ldo_tls_info.lt_keyfile
204 #define ldo_tls_dhfile ldo_tls_info.lt_dhfile
205 #define ldo_tls_cacertfile ldo_tls_info.lt_cacertfile
206 #define ldo_tls_cacertdir ldo_tls_info.lt_cacertdir
207 #define ldo_tls_ciphersuite ldo_tls_info.lt_ciphersuite
208 #define ldo_tls_crlfile ldo_tls_info.lt_crlfile
210 int ldo_tls_require_cert;
211 #ifdef HAVE_OPENSSL_CRL
212 int ldo_tls_crlcheck;
216 LDAPURLDesc *ldo_defludp;
219 char* ldo_defbinddn; /* bind dn */
221 #ifdef HAVE_CYRUS_SASL
222 char* ldo_def_sasl_mech; /* SASL Mechanism(s) */
223 char* ldo_def_sasl_realm; /* SASL realm */
224 char* ldo_def_sasl_authcid; /* SASL authentication identity */
225 char* ldo_def_sasl_authzid; /* SASL authorization identity */
227 /* SASL Security Properties */
228 struct sasl_security_properties ldo_sasl_secprops;
232 unsigned gssapi_flags;
234 unsigned ldo_gssapi_flags;
235 #define LDAP_GSSAPI_OPT_DO_NOT_FREE_GSS_CONTEXT 0x0001
236 #define LDAP_GSSAPI_OPT_ALLOW_REMOTE_PRINCIPAL 0x0002
237 unsigned ldo_gssapi_options;
240 int ldo_refhoplimit; /* limit on referral nesting */
242 /* LDAPv3 server and client controls */
243 LDAPControl **ldo_sctrls;
244 LDAPControl **ldo_cctrls;
246 /* LDAP rebind callback function */
247 LDAP_REBIND_PROC *ldo_rebind_proc;
248 void *ldo_rebind_params;
249 LDAP_NEXTREF_PROC *ldo_nextref_proc;
250 void *ldo_nextref_params;
251 LDAP_URLLIST_PROC *ldo_urllist_proc;
252 void *ldo_urllist_params;
254 /* LDAP connection callback stack */
255 ldaplist *ldo_conn_cbs;
257 LDAP_BOOLEANS ldo_booleans; /* boolean options */
262 * structure for representing an LDAP server connection
264 typedef struct ldap_conn {
266 #ifdef HAVE_CYRUS_SASL
267 void *lconn_sasl_authctx; /* context for bind */
268 void *lconn_sasl_sockctx; /* for security layer */
271 void *lconn_gss_ctx; /* gss_ctx_id_t */
274 time_t lconn_created; /* time */
275 time_t lconn_lastused; /* time */
276 int lconn_rebind_inprogress; /* set if rebind in progress */
277 char ***lconn_rebind_queue; /* used if rebind in progress */
279 #define LDAP_CONNST_NEEDSOCKET 1
280 #define LDAP_CONNST_CONNECTING 2
281 #define LDAP_CONNST_CONNECTED 3
282 LDAPURLDesc *lconn_server;
283 BerElement *lconn_ber; /* ber receiving on this conn. */
285 struct ldap_conn *lconn_next;
290 * structure used to track outstanding requests
292 typedef struct ldapreq {
293 ber_int_t lr_msgid; /* the message id */
294 int lr_status; /* status of request */
295 #define LDAP_REQST_COMPLETED 0
296 #define LDAP_REQST_INPROGRESS 1
297 #define LDAP_REQST_CHASINGREFS 2
298 #define LDAP_REQST_NOTCONNECTED 3
299 #define LDAP_REQST_WRITING 4
300 int lr_refcnt; /* count of references */
301 int lr_outrefcnt; /* count of outstanding referrals */
302 int lr_abandoned; /* the request has been abandoned */
303 ber_int_t lr_origid; /* original request's message id */
304 int lr_parentcnt; /* count of parent requests */
305 ber_tag_t lr_res_msgtype; /* result message type */
306 ber_int_t lr_res_errno; /* result LDAP errno */
307 char *lr_res_error; /* result error string */
308 char *lr_res_matched;/* result matched DN string */
309 BerElement *lr_ber; /* ber encoded request contents */
310 LDAPConn *lr_conn; /* connection used to send request */
311 struct berval lr_dn; /* DN of request, in lr_ber */
312 struct ldapreq *lr_parent; /* request that spawned this referral */
313 struct ldapreq *lr_child; /* first child request */
314 struct ldapreq *lr_refnext; /* next referral spawned */
315 struct ldapreq *lr_prev; /* previous request */
316 struct ldapreq *lr_next; /* next request */
320 * structure for client cache
322 #define LDAP_CACHE_BUCKETS 31 /* cache hash table size */
323 typedef struct ldapcache {
324 LDAPMessage *lc_buckets[LDAP_CACHE_BUCKETS];/* hash table */
325 LDAPMessage *lc_requests; /* unfulfilled reqs */
326 long lc_timeout; /* request timeout */
327 ber_len_t lc_maxmem; /* memory to use */
328 ber_len_t lc_memused; /* memory in use */
329 int lc_enabled; /* enabled? */
330 unsigned long lc_options; /* options */
331 #define LDAP_CACHE_OPT_CACHENOERRS 0x00000001
332 #define LDAP_CACHE_OPT_CACHEALLERRS 0x00000002
336 * structure containing referral request info for rebind procedure
338 typedef struct ldapreqinfo {
345 * structure representing an ldap connection
349 Sockbuf *ld_sb; /* socket descriptor & buffer */
351 struct ldapoptions ld_options;
353 #define ld_valid ld_options.ldo_valid
354 #define ld_debug ld_options.ldo_debug
356 #define ld_deref ld_options.ldo_deref
357 #define ld_timelimit ld_options.ldo_timelimit
358 #define ld_sizelimit ld_options.ldo_sizelimit
360 #define ld_defbinddn ld_options.ldo_defbinddn
361 #define ld_defbase ld_options.ldo_defbase
362 #define ld_defhost ld_options.ldo_defhost
363 #define ld_defport ld_options.ldo_defport
365 #define ld_refhoplimit ld_options.ldo_refhoplimit
367 #define ld_sctrls ld_options.ldo_sctrls
368 #define ld_cctrls ld_options.ldo_cctrls
369 #define ld_rebind_proc ld_options.ldo_rebind_proc
370 #define ld_rebind_params ld_options.ldo_rebind_params
371 #define ld_nextref_proc ld_options.ldo_nextref_proc
372 #define ld_nextref_params ld_options.ldo_nextref_params
373 #define ld_urllist_proc ld_options.ldo_urllist_proc
374 #define ld_urllist_params ld_options.ldo_urllist_params
376 #define ld_version ld_options.ldo_version
378 unsigned short ld_lberoptions;
386 /* do not mess with these */
387 LDAPRequest *ld_requests; /* list of outstanding requests */
388 LDAPMessage *ld_responses; /* list of outstanding responses */
390 #ifdef LDAP_R_COMPILE
391 ldap_pvt_thread_mutex_t ld_conn_mutex;
392 ldap_pvt_thread_mutex_t ld_req_mutex;
393 ldap_pvt_thread_mutex_t ld_res_mutex;
396 ber_len_t ld_nabandoned;
397 ber_int_t *ld_abandoned; /* array of abandoned requests */
399 LDAPCache *ld_cache; /* non-null if cache is initialized */
401 /* do not mess with the rest though */
403 LDAPConn *ld_defconn; /* default connection */
404 LDAPConn *ld_conns; /* list of server connections */
405 void *ld_selectinfo; /* platform specifics for select */
407 #define LDAP_VALID(ld) ( (ld)->ld_valid == LDAP_VALID_SESSION )
408 #define LDAP_TRASHED(ld) ( (ld)->ld_valid == LDAP_TRASHED_SESSION )
409 #define LDAP_TRASH(ld) ( (ld)->ld_valid = LDAP_TRASHED_SESSION )
411 #ifdef LDAP_R_COMPILE
412 LDAP_V ( ldap_pvt_thread_mutex_t ) ldap_int_resolv_mutex;
414 #ifdef HAVE_CYRUS_SASL
415 LDAP_V( ldap_pvt_thread_mutex_t ) ldap_int_sasl_mutex;
418 LDAP_V( ldap_pvt_thread_mutex_t ) ldap_int_gssapi_mutex;
422 #ifdef LDAP_R_COMPILE
423 #define LDAP_NEXT_MSGID(ld, id) \
424 ldap_pvt_thread_mutex_lock( &(ld)->ld_req_mutex ); \
425 id = ++(ld)->ld_msgid; \
426 ldap_pvt_thread_mutex_unlock( &(ld)->ld_req_mutex )
428 #define LDAP_NEXT_MSGID(ld, id) id = ++(ld)->ld_msgid
436 ldap_int_bisect_find( ber_int_t *v, ber_len_t n, ber_int_t id, int *idxp );
438 ldap_int_bisect_insert( ber_int_t **vp, ber_len_t *np, int id, int idx );
440 ldap_int_bisect_delete( ber_int_t **vp, ber_len_t *np, int id, int idx );
446 LDAP_V ( struct ldapoptions ) ldap_int_global_options;
448 LDAP_F ( void ) ldap_int_initialize LDAP_P((struct ldapoptions *, int *));
449 LDAP_F ( void ) ldap_int_initialize_global_options LDAP_P((
450 struct ldapoptions *, int *));
453 /* simple macros to realloc for now */
454 #define LDAP_MALLOC(s) (ber_memalloc_x((s),NULL))
455 #define LDAP_CALLOC(n,s) (ber_memcalloc_x((n),(s),NULL))
456 #define LDAP_REALLOC(p,s) (ber_memrealloc_x((p),(s),NULL))
457 #define LDAP_FREE(p) (ber_memfree_x((p),NULL))
458 #define LDAP_VFREE(v) (ber_memvfree_x((void **)(v),NULL))
459 #define LDAP_STRDUP(s) (ber_strdup_x((s),NULL))
460 #define LDAP_STRNDUP(s,l) (ber_strndup_x((s),(l),NULL))
462 #define LDAP_MALLOCX(s,x) (ber_memalloc_x((s),(x)))
463 #define LDAP_CALLOCX(n,s,x) (ber_memcalloc_x((n),(s),(x)))
464 #define LDAP_REALLOCX(p,s,x) (ber_memrealloc_x((p),(s),(x)))
465 #define LDAP_FREEX(p,x) (ber_memfree_x((p),(x)))
466 #define LDAP_VFREEX(v,x) (ber_memvfree_x((void **)(v),(x)))
467 #define LDAP_STRDUPX(s,x) (ber_strdup_x((s),(x)))
468 #define LDAP_STRNDUPX(s,l,x) (ber_strndup_x((s),(l),(x)))
473 LDAP_F (void) ldap_int_error_init( void );
478 LDAP_F (void) ldap_int_utils_init LDAP_P(( void ));
484 LDAP_F (int) ldap_log_printf LDAP_P((LDAP *ld, int level, const char *fmt, ...)) LDAP_GCCATTR((format(printf, 3, 4)));
489 LDAP_F (void) ldap_add_request_to_cache LDAP_P(( LDAP *ld, ber_tag_t msgtype,
490 BerElement *request ));
491 LDAP_F (void) ldap_add_result_to_cache LDAP_P(( LDAP *ld, LDAPMessage *result ));
492 LDAP_F (int) ldap_check_cache LDAP_P(( LDAP *ld, ber_tag_t msgtype, BerElement *request ));
497 LDAP_F (int) ldap_int_put_controls LDAP_P((
499 LDAPControl *const *ctrls,
502 LDAP_F (int) ldap_int_client_controls LDAP_P((
504 LDAPControl **ctrlp ));
509 LDAP_F (int) ldap_int_next_line_tokens LDAP_P(( char **bufp, ber_len_t *blenp, char ***toksp ));
515 LDAP_F (int) ldap_open_defconn( LDAP *ld );
516 LDAP_F (int) ldap_int_open_connection( LDAP *ld,
517 LDAPConn *conn, LDAPURLDesc *srvlist, int async );
523 LDAP_V (int) ldap_int_tblsize;
524 LDAP_F (void) ldap_int_ip_init( void );
527 LDAP_F (int) ldap_int_timeval_dup( struct timeval **dest,
528 const struct timeval *tm );
529 LDAP_F (int) ldap_connect_to_host( LDAP *ld, Sockbuf *sb,
530 int proto, LDAPURLDesc *srv, int async );
531 LDAP_F (int) ldap_int_poll( LDAP *ld, ber_socket_t s,
532 struct timeval *tvp );
534 #if defined(HAVE_TLS) || defined(HAVE_CYRUS_SASL)
535 LDAP_V (char *) ldap_int_hostname;
536 LDAP_F (char *) ldap_host_connected_to( Sockbuf *sb,
540 LDAP_F (int) ldap_int_select( LDAP *ld, struct timeval *timeout );
541 LDAP_F (void *) ldap_new_select_info( void );
542 LDAP_F (void) ldap_free_select_info( void *sip );
543 LDAP_F (void) ldap_mark_select_write( LDAP *ld, Sockbuf *sb );
544 LDAP_F (void) ldap_mark_select_read( LDAP *ld, Sockbuf *sb );
545 LDAP_F (void) ldap_mark_select_clear( LDAP *ld, Sockbuf *sb );
546 LDAP_F (int) ldap_is_read_ready( LDAP *ld, Sockbuf *sb );
547 LDAP_F (int) ldap_is_write_ready( LDAP *ld, Sockbuf *sb );
549 LDAP_F (int) ldap_int_connect_cbs( LDAP *ld, Sockbuf *sb,
550 ber_socket_t *s, LDAPURLDesc *srv, struct sockaddr *addr );
556 LDAP_F (int) ldap_connect_to_path( LDAP *ld, Sockbuf *sb,
557 LDAPURLDesc *srv, int async );
558 #endif /* LDAP_PF_LOCAL */
563 LDAP_F (ber_int_t) ldap_send_initial_request( LDAP *ld, ber_tag_t msgtype,
564 const char *dn, BerElement *ber, ber_int_t msgid );
565 LDAP_F (BerElement *) ldap_alloc_ber_with_options( LDAP *ld );
566 LDAP_F (void) ldap_set_ber_options( LDAP *ld, BerElement *ber );
568 LDAP_F (int) ldap_send_server_request( LDAP *ld, BerElement *ber, ber_int_t msgid, LDAPRequest *parentreq, LDAPURLDesc **srvlist, LDAPConn *lc, LDAPreqinfo *bind );
569 LDAP_F (LDAPConn *) ldap_new_connection( LDAP *ld, LDAPURLDesc **srvlist, int use_ldsb, int connect, LDAPreqinfo *bind );
570 LDAP_F (LDAPRequest *) ldap_find_request_by_msgid( LDAP *ld, ber_int_t msgid );
571 LDAP_F (void) ldap_return_request( LDAP *ld, LDAPRequest *lr, int freeit );
572 LDAP_F (void) ldap_free_request( LDAP *ld, LDAPRequest *lr );
573 LDAP_F (void) ldap_free_connection( LDAP *ld, LDAPConn *lc, int force, int unbind );
574 LDAP_F (void) ldap_dump_connection( LDAP *ld, LDAPConn *lconns, int all );
575 LDAP_F (void) ldap_dump_requests_and_responses( LDAP *ld );
576 LDAP_F (int) ldap_chase_referrals( LDAP *ld, LDAPRequest *lr,
577 char **errstrp, int sref, int *hadrefp );
578 LDAP_F (int) ldap_chase_v3referrals( LDAP *ld, LDAPRequest *lr,
579 char **refs, int sref, char **referralsp, int *hadrefp );
580 LDAP_F (int) ldap_append_referral( LDAP *ld, char **referralsp, char *s );
581 LDAP_F (int) ldap_int_flush_request( LDAP *ld, LDAPRequest *lr );
586 LDAP_F (const char *) ldap_int_msgtype2str( ber_tag_t tag );
591 LDAP_F (BerElement *) ldap_build_search_req LDAP_P((
598 LDAPControl **sctrls,
599 LDAPControl **cctrls,
608 LDAP_F (int) ldap_ld_free LDAP_P((
611 LDAPControl **sctrls,
612 LDAPControl **cctrls ));
614 LDAP_F (int) ldap_send_unbind LDAP_P((
617 LDAPControl **sctrls,
618 LDAPControl **cctrls ));
623 LDAP_F (LDAPURLDesc *) ldap_url_dup LDAP_P((
624 LDAPURLDesc *ludp ));
626 LDAP_F (LDAPURLDesc *) ldap_url_duplist LDAP_P((
627 LDAPURLDesc *ludlist ));
629 LDAP_F (int) ldap_url_parsehosts LDAP_P((
630 LDAPURLDesc **ludlist,
634 LDAP_F (char *) ldap_url_list2hosts LDAP_P((
635 LDAPURLDesc *ludlist ));
641 LDAP_F (int) ldap_int_sasl_init LDAP_P(( void ));
643 LDAP_F (int) ldap_int_sasl_open LDAP_P((
644 LDAP *ld, LDAPConn *conn,
646 LDAP_F (int) ldap_int_sasl_close LDAP_P(( LDAP *ld, LDAPConn *conn ));
648 LDAP_F (int) ldap_int_sasl_external LDAP_P((
649 LDAP *ld, LDAPConn *conn,
650 const char* authid, ber_len_t ssf ));
652 LDAP_F (int) ldap_int_sasl_get_option LDAP_P(( LDAP *ld,
653 int option, void *arg ));
654 LDAP_F (int) ldap_int_sasl_set_option LDAP_P(( LDAP *ld,
655 int option, void *arg ));
656 LDAP_F (int) ldap_int_sasl_config LDAP_P(( struct ldapoptions *lo,
657 int option, const char *arg ));
659 LDAP_F (int) ldap_int_sasl_bind LDAP_P((
663 LDAPControl **, LDAPControl **,
665 /* should be passed in client controls */
667 LDAP_SASL_INTERACT_PROC *interact,
671 LDAP_F (char *) ldap_int_parse_numericoid LDAP_P((
679 LDAP_F (int) ldap_int_tls_config LDAP_P(( LDAP *ld,
680 int option, const char *arg ));
682 LDAP_F (int) ldap_int_tls_start LDAP_P(( LDAP *ld,
683 LDAPConn *conn, LDAPURLDesc *srv ));
685 LDAP_F (void) ldap_int_tls_destroy LDAP_P(( struct ldapoptions *lo ));
690 LDAP_F (char **) ldap_value_dup LDAP_P((
691 char *const *vals ));
695 #endif /* _LDAP_INT_H */