]> git.sur5r.net Git - openldap/blob - libraries/libldap/request.c
Fix up referral commit.
[openldap] / libraries / libldap / request.c
1 /* $OpenLDAP$ */
2 /*
3  * Copyright 1998-2000 The OpenLDAP Foundation, All Rights Reserved.
4  * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
5  */
6 /*  Portions
7  *  Copyright (c) 1995 Regents of the University of Michigan.
8  *  All rights reserved.
9  */
10 /*---
11  * This notice applies to changes, created by or for Novell, Inc.,
12  * to preexisting works for which notices appear elsewhere in this file.
13  *
14  * Copyright (C) 1999, 2000 Novell, Inc. All Rights Reserved.
15  *
16  * THIS WORK IS SUBJECT TO U.S. AND INTERNATIONAL COPYRIGHT LAWS AND TREATIES.
17  * USE, MODIFICATION, AND REDISTRIBUTION OF THIS WORK IS SUBJECT TO VERSION
18  * 2.0.1 OF THE OPENLDAP PUBLIC LICENSE, A COPY OF WHICH IS AVAILABLE AT
19  * HTTP://WWW.OPENLDAP.ORG/LICENSE.HTML OR IN THE FILE "LICENSE" IN THE
20  * TOP-LEVEL DIRECTORY OF THE DISTRIBUTION. ANY USE OR EXPLOITATION OF THIS
21  * WORK OTHER THAN AS AUTHORIZED IN VERSION 2.0.1 OF THE OPENLDAP PUBLIC
22  * LICENSE, OR OTHER PRIOR WRITTEN CONSENT FROM NOVELL, COULD SUBJECT THE
23  * PERPETRATOR TO CRIMINAL AND CIVIL LIABILITY. 
24  *---
25  * Modification to OpenLDAP source by Novell, Inc.
26  * April 2000 sfs  Added code to chase V3 referrals
27  *  request.c - sending of ldap requests; handling of referrals
28  */
29
30 #include "portable.h"
31
32 #include <stdio.h>
33
34 #include <ac/stdlib.h>
35
36 #include <ac/errno.h>
37 #include <ac/socket.h>
38 #include <ac/string.h>
39 #include <ac/time.h>
40 #include <ac/unistd.h>
41
42 #include "ldap-int.h"
43 #include "lber.h"
44
45 static LDAPConn *find_connection LDAP_P(( LDAP *ld, LDAPURLDesc *srv, int any ));
46 static void use_connection LDAP_P(( LDAP *ld, LDAPConn *lc ));
47
48 #ifdef LDAP_API_FEATURE_X_OPENLDAP_V2_DNS
49 static LDAPURLDesc *dn2servers LDAP_P(( LDAP *ld, const char *dn ));
50 #endif /* LDAP_API_FEATURE_X_OPENLDAP_V2_DNS */
51
52 static BerElement *re_encode_request LDAP_P((
53         LDAP *ld,
54         BerElement *origber,
55     ber_int_t msgid,
56         char **dnp,
57         int      *type));
58
59
60 BerElement *
61 ldap_alloc_ber_with_options( LDAP *ld )
62 {
63         BerElement      *ber;
64
65     if (( ber = ber_alloc_t( ld->ld_lberoptions )) == NULL ) {
66                 ld->ld_errno = LDAP_NO_MEMORY;
67 #ifdef STR_TRANSLATION
68         } else {
69                 ldap_set_ber_options( ld, ber );
70 #endif /* STR_TRANSLATION */
71         }
72
73         return( ber );
74 }
75
76
77 void
78 ldap_set_ber_options( LDAP *ld, BerElement *ber )
79 {
80         ber->ber_options = ld->ld_lberoptions;
81 #ifdef STR_TRANSLATION
82         if (( ld->ld_lberoptions & LBER_TRANSLATE_STRINGS ) != 0 ) {
83                 ber_set_string_translators( ber,
84                     ld->ld_lber_encode_translate_proc,
85                     ld->ld_lber_decode_translate_proc );
86         }
87 #endif /* STR_TRANSLATION */
88 }
89
90
91 ber_int_t
92 ldap_send_initial_request(
93         LDAP *ld,
94         ber_tag_t msgtype,
95         const char *dn,
96         BerElement *ber )
97 {
98         LDAPURLDesc     *servers;
99         int rc;
100
101         Debug( LDAP_DEBUG_TRACE, "ldap_send_initial_request\n", 0, 0, 0 );
102
103         if ( ! ber_pvt_sb_in_use(&ld->ld_sb ) ) {
104                 /* not connected yet */
105                 int rc = ldap_open_defconn( ld );
106
107                 if( rc < 0 ) {
108                         ber_free( ber, 1 );
109                         return( -1 );
110                 }
111
112                 Debug( LDAP_DEBUG_TRACE,
113                         "ldap_delayed_open successful, ld_host is %s\n",
114                         ( ld->ld_host == NULL ) ? "(null)" : ld->ld_host, 0, 0 );
115         }
116
117 #ifdef LDAP_API_FEATURE_X_OPENLDAP_V2_DNS
118         if ( LDAP_BOOL_GET(&ld->ld_options, LDAP_BOOL_DNS )
119                 && ldap_is_dns_dn( dn ) )
120         {
121                 if (( servers = dn2servers( ld, dn )) == NULL ) {
122                         ber_free( ber, 1 );
123                         return( -1 );
124                 }
125
126 #ifdef LDAP_DEBUG
127                 if ( ldap_debug & LDAP_DEBUG_TRACE ) {
128                         LDAPURLDesc     *srv;
129
130                         for (   srv = servers;
131                                         srv != NULL;
132                                 srv = srv->lud_next )
133                         {
134                                 fprintf( stderr,
135                                     "LDAP server %s:  dn %s, port %d\n",
136                                     srv->lud_host, ( srv->lud_dn == NULL ) ?
137                                     "(default)" : srv->lud_dn,
138                                     srv->lud_port );
139                         }
140                 }
141 #endif /* LDAP_DEBUG */
142         } else
143 #endif /* LDAP_API_FEATURE_X_OPENLDAP_V2_DNS */
144         {
145                 /*
146                  * use of DNS is turned off or this is an X.500 DN...
147                  * use our default connection
148                  */
149                 servers = NULL;
150         }       
151
152         rc = ldap_send_server_request( ld, ber, ld->ld_msgid, NULL,
153                                                                         servers, NULL, NULL );
154         if (servers)
155                 ldap_free_urllist(servers);
156         return(rc);
157 }
158
159
160
161 int
162 ldap_send_server_request(
163         LDAP *ld,
164         BerElement *ber,
165         ber_int_t msgid,
166         LDAPRequest *parentreq,
167         LDAPURLDesc *srvlist,
168         LDAPConn *lc,
169         LDAPreqinfo *bind )
170 {
171         LDAPRequest     *lr;
172         int incparent;
173
174         Debug( LDAP_DEBUG_TRACE, "ldap_send_server_request\n", 0, 0, 0 );
175
176         incparent = 0;
177         ld->ld_errno = LDAP_SUCCESS;    /* optimistic */
178
179         if ( lc == NULL ) {
180                 if ( srvlist == NULL ) {
181                         lc = ld->ld_defconn;
182                 } else {
183                         if (( lc = find_connection( ld, srvlist, 1 )) ==
184                             NULL ) {
185                                 if ( (bind != NULL) && (parentreq != NULL) ) {
186                                         /* Remember the bind in the parent */
187                                         incparent = 1;
188                                         ++parentreq->lr_outrefcnt;
189                                 }
190                                 lc = ldap_new_connection( ld, srvlist, 0, 1, bind );
191                         }
192                 }
193         }
194
195         if ( lc == NULL || lc->lconn_status != LDAP_CONNST_CONNECTED ) {
196                 ber_free( ber, 1 );
197                 if ( ld->ld_errno == LDAP_SUCCESS ) {
198                         ld->ld_errno = LDAP_SERVER_DOWN;
199                 }
200                 if ( incparent ) {
201                         /* Forget about the bind */
202                         --parentreq->lr_outrefcnt; 
203                 }
204                 return( -1 );
205         }
206
207         use_connection( ld, lc );
208         if (( lr = (LDAPRequest *)LDAP_CALLOC( 1, sizeof( LDAPRequest ))) ==
209             NULL ) {
210                 ld->ld_errno = LDAP_NO_MEMORY;
211                 ldap_free_connection( ld, lc, 0, 0 );
212                 ber_free( ber, 1 );
213                 if ( incparent ) {
214                         /* Forget about the bind */
215                         --parentreq->lr_outrefcnt; 
216                 }
217                 return( -1 );
218         } 
219         lr->lr_msgid = msgid;
220         lr->lr_status = LDAP_REQST_INPROGRESS;
221         lr->lr_res_errno = LDAP_SUCCESS;        /* optimistic */
222         lr->lr_ber = ber;
223         lr->lr_conn = lc;
224         if ( parentreq != NULL ) {      /* sub-request */
225                 if ( !incparent ) { 
226                         /* Increment if we didn't do it before the bind */
227                         ++parentreq->lr_outrefcnt;
228                 }
229                 lr->lr_origid = parentreq->lr_origid;
230                 lr->lr_parentcnt = parentreq->lr_parentcnt + 1;
231                 lr->lr_parent = parentreq;
232                 lr->lr_refnext = parentreq->lr_refnext;
233                 parentreq->lr_refnext = lr;
234         } else {                        /* original request */
235                 lr->lr_origid = lr->lr_msgid;
236         }
237
238         if (( lr->lr_next = ld->ld_requests ) != NULL ) {
239                 lr->lr_next->lr_prev = lr;
240         }
241         ld->ld_requests = lr;
242         lr->lr_prev = NULL;
243
244         if ( ber_flush( lc->lconn_sb, ber, 0 ) != 0 ) {
245 #ifdef notyet
246                 if ( errno == EWOULDBLOCK ) {
247                         /* need to continue write later */
248                         lr->lr_status = LDAP_REQST_WRITING;
249                         ldap_mark_select_write( ld, lc->lconn_sb );
250                 } else {
251 #else /* notyet */
252                         ld->ld_errno = LDAP_SERVER_DOWN;
253                         ldap_free_request( ld, lr );
254                         ldap_free_connection( ld, lc, 0, 0 );
255                         return( -1 );
256 #endif /* notyet */
257 #ifdef notyet
258                 }
259 #endif /* notyet */
260         } else {
261                 if ( parentreq == NULL ) {
262                         ber->ber_end = ber->ber_ptr;
263                         ber->ber_ptr = ber->ber_buf;
264                 }
265
266                 /* sent -- waiting for a response */
267                 ldap_mark_select_read( ld, lc->lconn_sb );
268         }
269
270         ld->ld_errno = LDAP_SUCCESS;
271         return( msgid );
272 }
273
274 LDAPConn *
275 ldap_new_connection( LDAP *ld, LDAPURLDesc *srvlist, int use_ldsb,
276         int connect, LDAPreqinfo *bind )
277 {
278         LDAPConn        *lc;
279         LDAPURLDesc     *srv;
280         Sockbuf         *sb;
281
282         Debug( LDAP_DEBUG_TRACE, "ldap_new_connection\n", 0, 0, 0 );
283         /*
284          * make a new LDAP server connection
285          * XXX open connection synchronously for now
286          */
287         if (( lc = (LDAPConn *)LDAP_CALLOC( 1, sizeof( LDAPConn ))) == NULL ||
288             ( !use_ldsb && ( (sb = ber_sockbuf_alloc()) == NULL ))) {
289                 if ( lc != NULL ) {
290                         LDAP_FREE( (char *)lc );
291                 }
292                 ld->ld_errno = LDAP_NO_MEMORY;
293                 return( NULL );
294         }
295
296         lc->lconn_sb = ( use_ldsb ) ? &ld->ld_sb : sb;
297
298         if ( connect ) {
299                 for ( srv = srvlist; srv != NULL; srv = srv->lud_next ) {
300                         if ( open_ldap_connection( ld, lc->lconn_sb,
301                                         srv, &lc->lconn_krbinstance, 0 ) != -1 )
302                         {
303                                 break;
304                         }
305                 }
306
307                 if ( srv == NULL ) {
308                         if ( !use_ldsb ) {
309                                 ber_sockbuf_free( lc->lconn_sb );
310                         }
311                     LDAP_FREE( (char *)lc );
312                     ld->ld_errno = LDAP_SERVER_DOWN;
313                     return( NULL );
314                 }
315
316                 lc->lconn_server = ldap_url_dup(srv);
317         }
318
319         lc->lconn_status = LDAP_CONNST_CONNECTED;
320         lc->lconn_next = ld->ld_conns;
321         ld->ld_conns = lc;
322
323         /*
324          * XXX for now, we always do a synchronous bind.  This will have
325          * to change in the long run...
326          */
327         if ( bind != NULL) {
328                 int             err = 0;
329                 LDAPConn        *savedefconn;
330
331                 /* Set flag to prevent additional referrals from being processed on this
332                  * connection until the bind has completed
333                  */
334                 lc->lconn_rebind_inprogress = 1;
335                 /* V3 rebind function */
336                 if ( ld->ld_rebindproc != NULL) {
337                         LDAPURLDesc     *srvfunc;
338                         if( ( srvfunc = ldap_url_dup( srvlist)) == NULL) {
339                                 ld->ld_errno = LDAP_NO_MEMORY;
340                                 err = -1;
341                         } else {
342                                 savedefconn = ld->ld_defconn;
343                                 ++lc->lconn_refcnt;     /* avoid premature free */
344                                 ld->ld_defconn = lc;
345
346                                 Debug( LDAP_DEBUG_TRACE, "Call application rebindproc\n", 0, 0, 0);
347                                 err = (*ld->ld_rebindproc)( ld, bind->ri_url, bind->ri_request, bind->ri_msgid);
348
349                                 ld->ld_defconn = savedefconn;
350                                 --lc->lconn_refcnt;
351
352                                 if( err != 0) {
353                                 err = -1;
354                                         ldap_free_connection( ld, lc, 1, 0 );
355                                         lc = NULL;
356                         }
357                                 ldap_free_urldesc( srvfunc);
358                 }
359                 } else {
360                         savedefconn = ld->ld_defconn;
361                         ++lc->lconn_refcnt;     /* avoid premature free */
362                         ld->ld_defconn = lc;
363
364                         Debug( LDAP_DEBUG_TRACE, "anonymous rebind via ldap_bind_s\n", 0, 0, 0);
365                         if ( ldap_bind_s( ld, "", "", LDAP_AUTH_SIMPLE ) != LDAP_SUCCESS ) {
366                                 err = -1;
367                         }
368                         ld->ld_defconn = savedefconn;
369                         --lc->lconn_refcnt;
370
371                 if ( err != 0 ) {
372                         ldap_free_connection( ld, lc, 1, 0 );
373                         lc = NULL;
374                 }
375         }
376                 if( lc != NULL)
377                         lc->lconn_rebind_inprogress = 0;
378         }
379
380         return( lc );
381 }
382
383
384 static LDAPConn *
385 find_connection( LDAP *ld, LDAPURLDesc *srv, int any )
386 /*
387  * return an existing connection (if any) to the server srv
388  * if "any" is non-zero, check for any server in the "srv" chain
389  */
390 {
391         LDAPConn        *lc;
392         LDAPURLDesc     *ls;
393
394         for ( lc = ld->ld_conns; lc != NULL; lc = lc->lconn_next ) {
395                 for ( ls = srv; ls != NULL; ls = ls->lud_next ) {
396                         if ( lc->lconn_server->lud_host != NULL &&
397                             ls->lud_host != NULL && strcasecmp(
398                             ls->lud_host, lc->lconn_server->lud_host ) == 0
399                             && ls->lud_port == lc->lconn_server->lud_port ) {
400                                 return( lc );
401                         }
402                         if ( !any ) {
403                                 break;
404                         }
405                 }
406         }
407
408         return( NULL );
409 }
410
411
412
413 static void
414 use_connection( LDAP *ld, LDAPConn *lc )
415 {
416         ++lc->lconn_refcnt;
417         lc->lconn_lastused = time( NULL );
418 }
419
420
421 void
422 ldap_free_connection( LDAP *ld, LDAPConn *lc, int force, int unbind )
423 {
424         LDAPConn        *tmplc, *prevlc;
425
426         Debug( LDAP_DEBUG_TRACE, "ldap_free_connection\n", 0, 0, 0 );
427
428         if ( force || --lc->lconn_refcnt <= 0 ) {
429                 if ( lc->lconn_status == LDAP_CONNST_CONNECTED ) {
430                         ldap_mark_select_clear( ld, lc->lconn_sb );
431                         if ( unbind ) {
432                                 ldap_send_unbind( ld, lc->lconn_sb, NULL, NULL );
433                         }
434                 }
435
436                 /* force closure */
437                 ldap_close_connection( lc->lconn_sb );
438                 ber_pvt_sb_destroy( lc->lconn_sb );
439
440                 if( lc->lconn_ber != NULL ) {
441                         ber_free( lc->lconn_ber, 1 );
442                 }
443
444                 prevlc = NULL;
445                 for ( tmplc = ld->ld_conns; tmplc != NULL;
446                     tmplc = tmplc->lconn_next ) {
447                         if ( tmplc == lc ) {
448                                 if ( prevlc == NULL ) {
449                                     ld->ld_conns = tmplc->lconn_next;
450                                 } else {
451                                     prevlc->lconn_next = tmplc->lconn_next;
452                                 }
453                                 break;
454                         }
455                         prevlc = tmplc;
456                 }
457                 ldap_free_urllist( lc->lconn_server );
458                 if ( lc->lconn_krbinstance != NULL ) {
459                         LDAP_FREE( lc->lconn_krbinstance );
460                 }
461                 if ( lc->lconn_sb != &ld->ld_sb ) {
462                         ber_sockbuf_free( lc->lconn_sb );
463                 }
464                 if( lc->lconn_rebind_queue != NULL) {
465                         int i;
466                         for( i = 0; lc->lconn_rebind_queue[i] != NULL; i++) {
467                                 free_strarray(lc->lconn_rebind_queue[i]);
468                         }
469                         LDAP_FREE( lc->lconn_rebind_queue);
470                 }
471                 LDAP_FREE( lc );
472                 Debug( LDAP_DEBUG_TRACE, "ldap_free_connection: actually freed\n",
473                     0, 0, 0 );
474         } else {
475                 lc->lconn_lastused = time( NULL );
476                 Debug( LDAP_DEBUG_TRACE, "ldap_free_connection: refcnt %d\n",
477                     lc->lconn_refcnt, 0, 0 );
478         }
479 }
480
481
482 #ifdef LDAP_DEBUG
483 void
484 ldap_dump_connection( LDAP *ld, LDAPConn *lconns, int all )
485 {
486         LDAPConn        *lc;
487         char            timebuf[32];
488
489         fprintf( stderr, "** Connection%s:\n", all ? "s" : "" );
490         for ( lc = lconns; lc != NULL; lc = lc->lconn_next ) {
491                 if ( lc->lconn_server != NULL ) {
492                         fprintf( stderr, "* host: %s  port: %d%s\n",
493                             ( lc->lconn_server->lud_host == NULL ) ? "(null)"
494                             : lc->lconn_server->lud_host,
495                             lc->lconn_server->lud_port, ( lc->lconn_sb ==
496                             &ld->ld_sb ) ? "  (default)" : "" );
497                 }
498                 fprintf( stderr, "  refcnt: %d  status: %s\n", lc->lconn_refcnt,
499                     ( lc->lconn_status == LDAP_CONNST_NEEDSOCKET ) ?
500                     "NeedSocket" : ( lc->lconn_status ==
501                     LDAP_CONNST_CONNECTING ) ? "Connecting" : "Connected" );
502                 fprintf( stderr, "  last used: %s",
503                     ldap_pvt_ctime( &lc->lconn_lastused, timebuf ));
504                 if( lc->lconn_rebind_inprogress ) {
505                         fprintf( stderr, "  rebind in progress\n");
506                         if( lc->lconn_rebind_queue != NULL) {
507                                 int i = 0;
508                                 for( ;lc->lconn_rebind_queue[i] != NULL; i++) {
509                                         int j = 0;
510                                         for( ;lc->lconn_rebind_queue[i][j] != 0; j++) {
511                                                 fprintf( stderr, "    queue %d entry %d - %s\n",
512                                                         i, j, lc->lconn_rebind_queue[i][j]);
513                                         }
514                                 }
515                         } else {
516                                 fprintf( stderr, "    queue is empty\n");
517                         }
518                 }
519                 fprintf(stderr, "\n");
520                 if ( !all ) {
521                         break;
522                 }
523         }
524 }
525
526
527 void
528 ldap_dump_requests_and_responses( LDAP *ld )
529 {
530         LDAPRequest     *lr;
531         LDAPMessage     *lm, *l;
532
533         fprintf( stderr, "** Outstanding Requests:\n" );
534         if (( lr = ld->ld_requests ) == NULL ) {
535                 fprintf( stderr, "   Empty\n" );
536         }
537         for ( ; lr != NULL; lr = lr->lr_next ) {
538             fprintf( stderr, " * msgid %d,  origid %d, status %s\n",
539                 lr->lr_msgid, lr->lr_origid,
540                 ( lr->lr_status == LDAP_REQST_INPROGRESS ) ? "InProgress" :
541                 ( lr->lr_status == LDAP_REQST_CHASINGREFS ) ? "ChasingRefs" :
542                 ( lr->lr_status == LDAP_REQST_NOTCONNECTED ) ? "NotConnected" :
543                 ( lr->lr_status == LDAP_REQST_WRITING) ? "Writing" :
544                 ( lr->lr_status == LDAP_REQST_COMPLETED ? "Request Completed" : "Invalid Status"));
545             fprintf( stderr, "   outstanding referrals %d, parent count %d\n",
546                     lr->lr_outrefcnt, lr->lr_parentcnt );
547         }
548
549         fprintf( stderr, "** Response Queue:\n" );
550         if (( lm = ld->ld_responses ) == NULL ) {
551                 fprintf( stderr, "   Empty\n" );
552         }
553         for ( ; lm != NULL; lm = lm->lm_next ) {
554                 fprintf( stderr, " * msgid %d,  type %lu\n",
555                     lm->lm_msgid, (unsigned long) lm->lm_msgtype );
556                 if (( l = lm->lm_chain ) != NULL ) {
557                         fprintf( stderr, "   chained responses:\n" );
558                         for ( ; l != NULL; l = l->lm_chain ) {
559                                 fprintf( stderr,
560                                     "  * msgid %d,  type %lu\n",
561                                     l->lm_msgid,
562                                     (unsigned long) l->lm_msgtype );
563                         }
564                 }
565         }
566 }
567 #endif /* LDAP_DEBUG */
568
569
570 void
571 ldap_free_request( LDAP *ld, LDAPRequest *lr )
572 {
573         LDAPRequest     *tmplr, *nextlr;
574
575         Debug( LDAP_DEBUG_TRACE, "ldap_free_request (origid %d, msgid %d)\n",
576                 lr->lr_origid, lr->lr_msgid, 0 );
577
578         if ( lr->lr_parent != NULL ) {
579                 --lr->lr_parent->lr_outrefcnt;
580         } else {
581                 /* free all referrals (child requests) */
582                 for ( tmplr = lr->lr_refnext; tmplr != NULL; tmplr = nextlr ) {
583                         nextlr = tmplr->lr_refnext;
584                         ldap_free_request( ld, tmplr );
585                 }
586         }
587
588         if ( lr->lr_prev == NULL ) {
589                 ld->ld_requests = lr->lr_next;
590         } else {
591                 lr->lr_prev->lr_next = lr->lr_next;
592         }
593
594         if ( lr->lr_next != NULL ) {
595                 lr->lr_next->lr_prev = lr->lr_prev;
596         }
597
598         if ( lr->lr_ber != NULL ) {
599                 ber_free( lr->lr_ber, 1 );
600         }
601
602         if ( lr->lr_res_error != NULL ) {
603                 LDAP_FREE( lr->lr_res_error );
604         }
605
606         if ( lr->lr_res_matched != NULL ) {
607                 LDAP_FREE( lr->lr_res_matched );
608         }
609
610         LDAP_FREE( lr );
611 }
612
613 /*
614  * Chase v3 referrals
615  *
616  * Parameters:
617  *  (IN) ld = LDAP connection handle
618  *  (IN) lr = LDAP Request structure
619  *  (IN) refs = array of pointers to referral strings that we will chase
620  *              The array will be free'd by this function when no longer needed
621  *  (OUT) errstrp = Place to return a string of referrals which could not be followed
622  *  (OUT) hadrefp = 1 if sucessfully followed referral
623  *
624  * Return value - number of referrals followed
625  */
626 LIBLDAP_F(int)
627 ldap_chase_v3referrals( LDAP *ld, LDAPRequest *lr, char **refs, char **errstrp, int *hadrefp )
628 {
629         char            *unfollowed;
630         int                      unfollowedcnt = 0;
631         LDAPRequest     *origreq;
632         LDAPURLDesc     *srv = NULL;
633         BerElement      *ber;
634         char            **refarray = NULL;
635         LDAPConn        *lc;
636         int                      rc, count, i, j;
637         LDAPreqinfo  rinfo;
638
639         ld->ld_errno = LDAP_SUCCESS;    /* optimistic */
640         *hadrefp = 0;
641
642         Debug( LDAP_DEBUG_TRACE, "ldap_chase_v3referrals\n", 0, 0, 0 );
643
644         unfollowed = NULL;
645         rc = count = 0;
646
647         /* If no referrals in array, return */
648         if ( (refs == NULL) || ( (refs)[0] == NULL) ) {
649                 rc = 0;
650                 goto done;
651         }
652
653         /* Check for hop limit exceeded */
654         if ( lr->lr_parentcnt >= ld->ld_refhoplimit ) {
655                 Debug( LDAP_DEBUG_ANY,
656                     "more than %d referral hops (dropping)\n", ld->ld_refhoplimit, 0, 0 );
657                 ld->ld_errno = LDAP_REFERRAL_LIMIT_EXCEEDED;
658             rc = -1;
659                 goto done;
660         }
661
662         /* find original request */
663         for ( origreq = lr; origreq->lr_parent != NULL; origreq = origreq->lr_parent ) {
664                 ;
665         }
666
667         refarray = refs;
668         refs = NULL;
669         /* parse out & follow referrals */
670         for( i=0; refarray[i] != NULL; i++) {
671                 /* Parse the referral URL */
672                 if (( rc = ldap_url_parse( refarray[i], &srv)) != LDAP_SUCCESS) {
673                         ld->ld_errno = rc;
674                         rc = -1;
675                         goto done;
676                 }
677
678                 /* treat ldap://hostpart and ldap://hostpart/ the same */
679                 if ( srv->lud_dn && srv->lud_dn[0] == '\0' ) {
680                         LDAP_FREE( srv->lud_dn );
681                         srv->lud_dn = NULL;
682                 }
683
684                 /* check connection for re-bind in progress */
685                 if (( lc = find_connection( ld, srv, 1 )) != NULL ) {
686                         if( lc->lconn_rebind_inprogress) {
687                                 /* We are already chasing a referral or search reference and a
688                                  * bind on that connection is in progress.  We must queue
689                                  * referrals on that connection, so we don't get a request
690                                  * going out before the bind operation completes. This happens
691                                  * if two search references come in one behind the other
692                                  * for the same server with different contexts.
693                                  */
694                                 Debug( LDAP_DEBUG_TRACE, "ldap_chase_v3referrals: queue referral \"%s\"\n",
695                                         refarray[i], 0, 0);
696                                 if( lc->lconn_rebind_queue == NULL ) {
697                                         /* Create a referral list */
698                                         if( (lc->lconn_rebind_queue = (char ***)LDAP_MALLOC( sizeof(void *) * 2)) == NULL) {
699                                                 ld->ld_errno = LDAP_NO_MEMORY;
700                                                 rc = -1;
701                                                 goto done;
702                                         }
703                                         lc->lconn_rebind_queue[0] = refarray;
704                                         lc->lconn_rebind_queue[1] = NULL;
705                                         refarray = NULL;
706                                 } else {
707                                         /* Count how many referral arrays we already have */
708                                         for( j = 0; lc->lconn_rebind_queue[j] != NULL; j++) {
709                                                 ;
710                                         }
711                                         /* Add the new referral to the list */
712                                         if( (lc->lconn_rebind_queue = (char ***)LDAP_REALLOC(
713                                                         lc->lconn_rebind_queue, sizeof(void *) * (j + 2))) == NULL) {
714                                                 ld->ld_errno = LDAP_NO_MEMORY;
715                                                 rc = -1;
716                                                 goto done;
717                                         }
718                                         lc->lconn_rebind_queue[j] = refarray;
719                                         lc->lconn_rebind_queue[j+1] = NULL;
720                                         refarray = NULL;
721                                 }
722                                 /* We have queued the referral/reference, now just return */
723                                 rc = 0;
724                                 *hadrefp = 1;
725                                 count = 1; /* Pretend we already followed referral */
726                                 goto done;
727                         }
728                 } 
729                 /* Re-encode the request with the new starting point of the search.
730                  * Note: In the future we also need to replace the filter if one
731                  * was provided with the search reference
732                  */
733                 if (( ber = re_encode_request( ld, origreq->lr_ber,
734                             ++ld->ld_msgid, &srv->lud_dn, &rinfo.ri_request )) == NULL ) {
735                         ld->ld_errno = LDAP_ENCODING_ERROR;
736                         rc = -1;
737                         goto done;
738                 }
739
740                 Debug( LDAP_DEBUG_TRACE, "ldap_chase_v3referral: msgid %d, url \"%s\"\n",
741                         lr->lr_msgid, refarray[i], 0);
742
743                 /* Send the new request to the server - may require a bind */
744                 rinfo.ri_msgid = origreq->lr_origid;
745                 rinfo.ri_url = refarray[i];
746                 if ( (rc = ldap_send_server_request( ld, ber, ld->ld_msgid,
747                         origreq, srv, NULL, &rinfo )) < 0 ) {
748                         /* Failure, try next referral in the list */
749                         Debug( LDAP_DEBUG_ANY, "Unable to chase referral \"%s\" (%s)\n", 
750                                 refarray[i], ldap_err2string( ld->ld_errno ), 0);
751                         unfollowedcnt += ldap_append_referral( ld, &unfollowed, refarray[i]);
752                         ldap_free_urllist(srv);
753                         srv = NULL;
754                 } else {
755                         /* Success, no need to try this referral list further */
756                         rc = 0;
757                         ++count;
758                         *hadrefp = 1;
759
760                         /* check if there is a queue of referrals that came in during bind */
761                         if( lc == NULL) {
762                                 if (( lc = find_connection( ld, srv, 1 )) == NULL ) {
763                                         ld->ld_errno = LDAP_OPERATIONS_ERROR;
764                                         rc = -1;
765                                         goto done;
766                                 }
767                         }
768
769                         if( lc->lconn_rebind_queue != NULL) {
770                                 /* Release resources of previous list */
771                                 free_strarray(refarray);
772                                 refarray = NULL;
773                                 ldap_free_urllist(srv);
774                                 srv = NULL;
775
776                                 /* Pull entries off end of queue so list always null terminated */
777                                 for( j = 0; lc->lconn_rebind_queue[j] != NULL; j++) {
778                                         ;
779                                 }
780                                 refarray = lc->lconn_rebind_queue[j-1];
781                                 lc->lconn_rebind_queue[j-1] = NULL;
782                                 /* we pulled off last entry from queue, free queue */
783                                 if ( j == 1 ) {
784                                         LDAP_FREE( lc->lconn_rebind_queue);
785                                         lc->lconn_rebind_queue = NULL;
786                                 }
787                                 /* restart the loop the with new referral list */
788                                 i = -1;
789                                 continue;
790                         }
791                         break; /* referral followed, break out of for loop */
792                 }
793         } /* end for loop */
794 done:
795         free_strarray(refarray);
796         ldap_free_urllist(srv);
797         LDAP_FREE( *errstrp );
798         
799         if( rc == 0) {
800                 *errstrp = NULL;
801                 LDAP_FREE( unfollowed );
802                 return count;
803         } else {
804                 ld->ld_errno = LDAP_REFERRAL;
805                 *errstrp = unfollowed;
806                 return rc;
807         }
808 }
809
810 /*
811  * XXX merging of errors in this routine needs to be improved
812  */
813 int
814 ldap_chase_referrals( LDAP *ld, LDAPRequest *lr, char **errstrp, int *hadrefp )
815 {
816         int             rc, count, len, newdn;
817 #ifdef LDAP_API_FEATURE_X_OPENLDAP_V2_DNS
818         int             ldapref;
819 #endif /* LDAP_API_FEATURE_X_OPENLDAP_V2_DNS */
820         char            *p, *ports, *ref, *tmpref, *refdn, *unfollowed;
821         LDAPRequest     *origreq;
822         LDAPURLDesc     *srv;
823         BerElement      *ber;
824         LDAPreqinfo  rinfo;
825
826         Debug( LDAP_DEBUG_TRACE, "ldap_chase_referrals\n", 0, 0, 0 );
827
828         ld->ld_errno = LDAP_SUCCESS;    /* optimistic */
829         *hadrefp = 0;
830
831         if ( *errstrp == NULL ) {
832                 return( 0 );
833         }
834
835         len = strlen( *errstrp );
836         for ( p = *errstrp; len >= LDAP_REF_STR_LEN; ++p, --len ) {
837                 if (( *p == 'R' || *p == 'r' ) && strncasecmp( p,
838                     LDAP_REF_STR, LDAP_REF_STR_LEN ) == 0 ) {
839                         *p = '\0';
840                         p += LDAP_REF_STR_LEN;
841                         break;
842                 }
843         }
844
845         if ( len < LDAP_REF_STR_LEN ) {
846                 return( 0 );
847         }
848
849         if ( lr->lr_parentcnt >= ld->ld_refhoplimit ) {
850                 Debug( LDAP_DEBUG_ANY,
851                     "more than %d referral hops (dropping)\n",
852                     ld->ld_refhoplimit, 0, 0 );
853                     /* XXX report as error in ld->ld_errno? */
854                     return( 0 );
855         }
856
857         /* find original request */
858         for ( origreq = lr; origreq->lr_parent != NULL;
859              origreq = origreq->lr_parent ) {
860                 ;
861         }
862
863         unfollowed = NULL;
864         rc = count = 0;
865
866         /* parse out & follow referrals */
867         for ( ref = p; rc == 0 && ref != NULL; ref = p ) {
868 #ifdef LDAP_API_FEATURE_X_OPENLDAP_V2_DNS
869                 ldapref = 0;
870 #endif /* LDAP_API_FEATURE_X_OPENLDAP_V2_DNS */
871
872                 if (( p = strchr( ref, '\n' )) != NULL ) {
873                         *p++ = '\0';
874                 } else {
875                         p = NULL;
876                 }
877
878                 ldap_pvt_hex_unescape( ref );
879                 len = strlen( ref );
880
881                 if ( len > LDAP_LDAP_REF_STR_LEN && strncasecmp( ref,
882                     LDAP_LDAP_REF_STR, LDAP_LDAP_REF_STR_LEN ) == 0 ) {
883                         Debug( LDAP_DEBUG_TRACE,
884                             "chasing LDAP referral: <%s>\n", ref, 0, 0 );
885 #ifdef LDAP_API_FEATURE_X_OPENLDAP_V2_DNS
886                         ldapref = 1;
887 #endif /* LDAP_API_FEATURE_X_OPENLDAP_V2_DNS */
888                         tmpref = ref + LDAP_LDAP_REF_STR_LEN;
889 #ifdef LDAP_API_FEATURE_X_OPENLDAP_V2_DNS
890                 } else if ( len > LDAP_DX_REF_STR_LEN && strncasecmp( ref,
891                     LDAP_DX_REF_STR, LDAP_DX_REF_STR_LEN ) == 0 ) {
892                         Debug( LDAP_DEBUG_TRACE,
893                             "chasing DX referral: <%s>\n", ref, 0, 0 );
894                         tmpref = ref + LDAP_DX_REF_STR_LEN;
895 #endif /* LDAP_API_FEATURE_X_OPENLDAP_V2_DNS */
896                 } else {
897                         Debug( LDAP_DEBUG_TRACE,
898                             "ignoring unknown referral <%s>\n", ref, 0, 0 );
899                         rc = ldap_append_referral( ld, &unfollowed, ref );
900                         *hadrefp = 1;
901                         continue;
902                 }
903
904                 /* copy the complete referral for rebind process */
905                 rinfo.ri_url = LDAP_STRDUP( ref );
906
907                 *hadrefp = 1;
908
909                 if (( refdn = strchr( tmpref, '/' )) != NULL ) {
910                         *refdn++ = '\0';
911                         newdn = refdn[0] != '?' && refdn[0] != '\0';
912                         if( !newdn ) refdn = NULL;
913                 } else {
914                         newdn = 0;
915                 }
916
917                 if (( ber = re_encode_request( ld, origreq->lr_ber,
918                     ++ld->ld_msgid, &refdn, &rinfo.ri_request )) == NULL ) {
919                         return( -1 );
920                 }
921
922 #ifdef LDAP_API_FEATURE_X_OPENLDAP_V2_DNS
923                 if ( ldapref ) {
924 #endif /* LDAP_API_FEATURE_X_OPENLDAP_V2_DNS */
925                         if (( srv = (LDAPURLDesc *)LDAP_CALLOC( 1,
926                             sizeof( LDAPURLDesc ))) == NULL ) {
927                                 ber_free( ber, 1 );
928                                 ld->ld_errno = LDAP_NO_MEMORY;
929                                 return( -1 );
930                         }
931
932                         if (( srv->lud_host = LDAP_STRDUP( tmpref )) == NULL ) {
933                                 LDAP_FREE( (char *)srv );
934                                 ber_free( ber, 1 );
935                                 ld->ld_errno = LDAP_NO_MEMORY;
936                                 return( -1 );
937                         }
938
939                         if (( ports = strchr( srv->lud_host, ':' )) != NULL ) {
940                                 *ports++ = '\0';
941                                 srv->lud_port = atoi( ports );
942                         } else {
943                                 srv->lud_port = ldap_int_global_options.ldo_defport;
944                         }
945 #ifdef LDAP_API_FEATURE_X_OPENLDAP_V2_DNS
946                 } else {
947                         srv = dn2servers( ld, tmpref );
948                 }
949 #endif /* LDAP_API_FEATURE_X_OPENLDAP_V2_DNS */
950
951                 rinfo.ri_msgid = origreq->lr_origid;
952                 if ( srv != NULL && ldap_send_server_request( ld, ber, ld->ld_msgid,
953                     lr, srv, NULL, &rinfo ) >= 0 ) {
954                         ++count;
955                 } else {
956                         Debug( LDAP_DEBUG_ANY,
957                             "Unable to chase referral (%s)\n", 
958                             ldap_err2string( ld->ld_errno ), 0, 0 );
959                         rc = ldap_append_referral( ld, &unfollowed, ref );
960                 }
961                 LDAP_FREE( rinfo.ri_url);
962
963                 if (srv != NULL)
964                         ldap_free_urllist(srv);
965
966                 if ( !newdn && refdn != NULL ) {
967                         LDAP_FREE( refdn );
968                 }
969         }
970
971         LDAP_FREE( *errstrp );
972         *errstrp = unfollowed;
973
974         return(( rc == 0 ) ? count : rc );
975 }
976
977
978 int
979 ldap_append_referral( LDAP *ld, char **referralsp, char *s )
980 {
981         int     first;
982
983         if ( *referralsp == NULL ) {
984                 first = 1;
985                 *referralsp = (char *)LDAP_MALLOC( strlen( s ) + LDAP_REF_STR_LEN
986                     + 1 );
987         } else {
988                 first = 0;
989                 *referralsp = (char *)LDAP_REALLOC( *referralsp,
990                     strlen( *referralsp ) + strlen( s ) + 2 );
991         }
992
993         if ( *referralsp == NULL ) {
994                 ld->ld_errno = LDAP_NO_MEMORY;
995                 return( -1 );
996         }
997
998         if ( first ) {
999                 strcpy( *referralsp, LDAP_REF_STR );
1000         } else {
1001                 strcat( *referralsp, "\n" );
1002         }
1003         strcat( *referralsp, s );
1004
1005         return( 0 );
1006 }
1007
1008
1009
1010 static BerElement *
1011 re_encode_request( LDAP *ld, BerElement *origber, ber_int_t msgid, char **dnp, int *type )
1012 {
1013 /*
1014  * XXX this routine knows way too much about how the lber library works!
1015  */
1016         ber_int_t       along;
1017         ber_tag_t       tag;
1018         ber_int_t       ver;
1019         int             rc;
1020         BerElement      tmpber, *ber;
1021         char            *orig_dn;
1022
1023         Debug( LDAP_DEBUG_TRACE,
1024             "re_encode_request: new msgid %ld, new dn <%s>\n",
1025             (long) msgid, ( *dnp == NULL ) ? "NONE" : *dnp, 0 );
1026
1027         tmpber = *origber;
1028
1029         /*
1030          * all LDAP requests are sequences that start with a message id.
1031          * For all except delete, this is followed by a sequence that is
1032          * tagged with the operation code.  For delete, the provided DN
1033          * is not wrapped by a sequence.
1034          */
1035         rc = ber_scanf( &tmpber, "{it", /*}*/ &along, &tag );
1036
1037         if ( rc == LBER_ERROR ) {
1038                 ld->ld_errno = LDAP_DECODING_ERROR;
1039                 return( NULL );
1040         }
1041
1042         assert( tag != 0);
1043         if ( tag == LDAP_REQ_BIND ) {
1044                 /* bind requests have a version number before the DN & other stuff */
1045                 rc = ber_scanf( &tmpber, "{ia" /*}*/, &ver, &orig_dn );
1046
1047         } else if ( tag == LDAP_REQ_DELETE ) {
1048                 /* delete requests don't have a DN wrapping sequence */
1049                 rc = ber_scanf( &tmpber, "a", &orig_dn );
1050
1051         } else {
1052                 rc = ber_scanf( &tmpber, "{a" /*}*/, &orig_dn );
1053         }
1054
1055         if( rc == LBER_ERROR ) {
1056                 ld->ld_errno = LDAP_DECODING_ERROR;
1057                 return NULL;
1058         }
1059
1060         if ( *dnp == NULL ) {
1061                 *dnp = orig_dn;
1062         } else {
1063                 LDAP_FREE( orig_dn );
1064         }
1065
1066         if (( ber = ldap_alloc_ber_with_options( ld )) == NULL ) {
1067                 return( NULL );
1068         }
1069
1070         if ( tag == LDAP_REQ_BIND ) {
1071                 rc = ber_printf( ber, "{it{is" /*}}*/, msgid, tag, ver, *dnp );
1072         } else if ( tag == LDAP_REQ_DELETE ) {
1073                 rc = ber_printf( ber, "{its}", msgid, tag, *dnp );
1074         } else {
1075                 rc = ber_printf( ber, "{it{s" /*}}*/, msgid, tag, *dnp );
1076         }
1077
1078         if ( rc == -1 ) {
1079                 ld->ld_errno = LDAP_ENCODING_ERROR;
1080                 ber_free( ber, 1 );
1081                 return( NULL );
1082         }
1083
1084         if ( tag != LDAP_REQ_DELETE && (
1085                 ber_write(ber, tmpber.ber_ptr, ( tmpber.ber_end - tmpber.ber_ptr ), 0)
1086                 != ( tmpber.ber_end - tmpber.ber_ptr ) ||
1087             ber_printf( ber, /*{{*/ "}}" ) == -1 ) )
1088         {
1089                 ld->ld_errno = LDAP_ENCODING_ERROR;
1090                 ber_free( ber, 1 );
1091                 return( NULL );
1092         }
1093
1094 #ifdef LDAP_DEBUG
1095         if ( ldap_debug & LDAP_DEBUG_PACKETS ) {
1096                 Debug( LDAP_DEBUG_ANY, "re_encode_request new request is:\n",
1097                     0, 0, 0 );
1098                 ber_log_dump( LDAP_DEBUG_BER, ldap_debug, ber, 0 );
1099         }
1100 #endif /* LDAP_DEBUG */
1101
1102         *type = tag;    /* return request type */
1103         return( ber );
1104 }
1105
1106
1107 LDAPRequest *
1108 ldap_find_request_by_msgid( LDAP *ld, ber_int_t msgid )
1109 {
1110         LDAPRequest     *lr;
1111
1112         for ( lr = ld->ld_requests; lr != NULL; lr = lr->lr_next ) {
1113                 if( lr->lr_status == LDAP_REQST_COMPLETED ) {
1114                         continue;       /* Skip completed requests */
1115                 }
1116                 if ( msgid == lr->lr_msgid ) {
1117                         break;
1118                 }
1119         }
1120
1121         return( lr );
1122 }
1123
1124
1125 #ifdef LDAP_API_FEATURE_X_OPENLDAP_V2_DNS
1126 static LDAPURLDesc *
1127 dn2servers( LDAP *ld, const char *dn )  /* dn can also be a domain.... */
1128 {
1129         char            *p, *host, *server_dn, **dxs;
1130         const char *domain;
1131         int             i, port;
1132         LDAPURLDesc     *srvlist, *prevsrv, *srv;
1133
1134         if (( domain = strrchr( dn, '@' )) != NULL ) {
1135                 ++domain;
1136         } else {
1137                 domain = dn;
1138         }
1139
1140         if (( dxs = ldap_getdxbyname( domain )) == NULL ) {
1141                 ld->ld_errno = LDAP_NO_MEMORY;
1142                 return( NULL );
1143         }
1144
1145         srvlist = NULL;
1146         for ( i = 0; dxs[ i ] != NULL; ++i ) {
1147                 if (ldap_url_parselist(&srv, dxs[i]) == LDAP_SUCCESS
1148                         || ldap_url_parsehosts(&srv, dxs[i]) == LDAP_SUCCESS)
1149                 {
1150                         /* add to end of list of servers */
1151                         if ( srvlist == NULL ) {
1152                                 srvlist = srv;
1153                         } else {
1154                                 prevsrv->lud_next = srv;
1155                         }
1156                         prevsrv = srv;
1157                 }
1158         }
1159
1160         ldap_value_free( dxs );
1161
1162         if ( srvlist == NULL ) {
1163                 ld->ld_errno = LDAP_SERVER_DOWN;
1164         }
1165
1166         return( srvlist );
1167 }
1168 #endif /* LDAP_API_FEATURE_X_OPENLDAP_V2_DNS */