]> git.sur5r.net Git - openldap/blob - servers/slapd/back-bdb/modrdn.c
condition compilation of DISCLOSE checking
[openldap] / servers / slapd / back-bdb / modrdn.c
1 /* modrdn.c - bdb backend modrdn routine */
2 /* $OpenLDAP$ */
3 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
4  *
5  * Copyright 2000-2005 The OpenLDAP Foundation.
6  * All rights reserved.
7  *
8  * Redistribution and use in source and binary forms, with or without
9  * modification, are permitted only as authorized by the OpenLDAP
10  * Public License.
11  *
12  * A copy of this license is available in the file LICENSE in the
13  * top-level directory of the distribution or, alternatively, at
14  * <http://www.OpenLDAP.org/license.html>.
15  */
16
17 #include "portable.h"
18
19 #include <stdio.h>
20 #include <ac/string.h>
21
22 #include "back-bdb.h"
23
24 int
25 bdb_modrdn( Operation   *op, SlapReply *rs )
26 {
27         struct bdb_info *bdb = (struct bdb_info *) op->o_bd->be_private;
28         AttributeDescription *children = slap_schema.si_ad_children;
29         AttributeDescription *entry = slap_schema.si_ad_entry;
30         struct berval   p_dn, p_ndn;
31         struct berval   new_dn = {0, NULL}, new_ndn = {0, NULL};
32         int             isroot = -1;
33         Entry           *e = NULL;
34         Entry           *p = NULL;
35         EntryInfo       *ei = NULL, *eip = NULL, *nei = NULL, *neip = NULL;
36         /* LDAP v2 supporting correct attribute handling. */
37         LDAPRDN         new_rdn = NULL;
38         LDAPRDN         old_rdn = NULL;
39         char textbuf[SLAP_TEXT_BUFLEN];
40         size_t textlen = sizeof textbuf;
41         DB_TXN          *ltid = NULL, *lt2;
42         struct bdb_op_info opinfo = {0};
43         Entry dummy = {0};
44
45         ID                      id;
46
47         Entry           *np = NULL;                     /* newSuperior Entry */
48         struct berval   *np_dn = NULL;                  /* newSuperior dn */
49         struct berval   *np_ndn = NULL;                 /* newSuperior ndn */
50         struct berval   *new_parent_dn = NULL;  /* np_dn, p_dn, or NULL */
51
52         /* Used to interface with bdb_modify_internal() */
53         Modifications   *mod = NULL;            /* Used to delete old rdn */
54
55         int             manageDSAit = get_manageDSAit( op );
56
57         u_int32_t       locker = 0;
58         DB_LOCK         lock, plock, nplock;
59
60         int             num_retries = 0;
61
62         LDAPControl **preread_ctrl = NULL;
63         LDAPControl **postread_ctrl = NULL;
64         LDAPControl *ctrls[SLAP_MAX_RESPONSE_CONTROLS];
65         int num_ctrls = 0;
66
67         Operation *ps_list;
68         struct psid_entry *pm_list, *pm_prev;
69         int     rc;
70         EntryInfo       *suffix_ei;
71         Entry           *ctxcsn_e;
72         int                     ctxcsn_added = 0;
73
74         int parent_is_glue = 0;
75         int parent_is_leaf = 0;
76
77         ctrls[num_ctrls] = NULL;
78
79         Debug( LDAP_DEBUG_TRACE, "==>" LDAP_XSTRING(bdb_modrdn) "(%s,%s,%s)\n",
80                 op->o_req_dn.bv_val,op->oq_modrdn.rs_newrdn.bv_val,
81                 op->oq_modrdn.rs_newSup ? op->oq_modrdn.rs_newSup->bv_val : "NULL" );
82
83         if( 0 ) {
84 retry:  /* transaction retry */
85                 if ( dummy.e_attrs ) {
86                         attrs_free( dummy.e_attrs );
87                         dummy.e_attrs = NULL;
88                 }
89                 if (e != NULL) {
90                         bdb_unlocked_cache_return_entry_w(&bdb->bi_cache, e);
91                         e = NULL;
92                 }
93                 if (p != NULL) {
94                         bdb_unlocked_cache_return_entry_r(&bdb->bi_cache, p);
95                         p = NULL;
96                 }
97                 if (np != NULL) {
98                         bdb_unlocked_cache_return_entry_r(&bdb->bi_cache, np);
99                         np = NULL;
100                 }
101                 Debug( LDAP_DEBUG_TRACE, "==>" LDAP_XSTRING(bdb_modrdn)
102                                 ": retrying...\n", 0, 0, 0 );
103
104                 rs->sr_err = TXN_ABORT( ltid );
105                 ltid = NULL;
106                 op->o_private = NULL;
107                 op->o_do_not_cache = opinfo.boi_acl_cache;
108                 if( rs->sr_err != 0 ) {
109                         rs->sr_err = LDAP_OTHER;
110                         rs->sr_text = "internal error";
111                         goto return_results;
112                 }
113                 parent_is_glue = 0;
114                 parent_is_leaf = 0;
115                 ldap_pvt_thread_yield();
116                 bdb_trans_backoff( ++num_retries );
117         }
118
119         /* begin transaction */
120         rs->sr_err = TXN_BEGIN( bdb->bi_dbenv, NULL, &ltid, 
121                 bdb->bi_db_opflags );
122         rs->sr_text = NULL;
123         if( rs->sr_err != 0 ) {
124                 Debug( LDAP_DEBUG_TRACE,
125                         LDAP_XSTRING(bdb_modrdn) ": txn_begin failed: "
126                         "%s (%d)\n", db_strerror(rs->sr_err), rs->sr_err, 0 );
127                 rs->sr_err = LDAP_OTHER;
128                 rs->sr_text = "internal error";
129                 goto return_results;
130         }
131
132         locker = TXN_ID ( ltid );
133
134         opinfo.boi_bdb = op->o_bd;
135         opinfo.boi_txn = ltid;
136         opinfo.boi_locker = locker;
137         opinfo.boi_err = 0;
138         opinfo.boi_acl_cache = op->o_do_not_cache;
139         op->o_private = &opinfo;
140
141         /* get entry */
142         rs->sr_err = bdb_dn2entry( op, ltid, &op->o_req_ndn, &ei, 1,
143                 locker, &lock );
144
145         switch( rs->sr_err ) {
146         case 0:
147         case DB_NOTFOUND:
148                 break;
149         case DB_LOCK_DEADLOCK:
150         case DB_LOCK_NOTGRANTED:
151                 goto retry;
152         case LDAP_BUSY:
153                 rs->sr_text = "ldap server busy";
154                 goto return_results;
155         default:
156                 rs->sr_err = LDAP_OTHER;
157                 rs->sr_text = "internal error";
158                 goto return_results;
159         }
160
161         e = ei->bei_e;
162         /* FIXME: dn2entry() should return non-glue entry */
163         if (( rs->sr_err == DB_NOTFOUND ) ||
164                 ( !manageDSAit && e && is_entry_glue( e )))
165         {
166                 BerVarray deref = NULL;
167                 if( e != NULL ) {
168                         rs->sr_matched = ch_strdup( e->e_dn );
169                         rs->sr_ref = is_entry_referral( e )
170                                 ? get_entry_referrals( op, e )
171                                 : NULL;
172                         bdb_unlocked_cache_return_entry_r( &bdb->bi_cache, e);
173                         e = NULL;
174
175                 } else {
176                         if ( op->o_bd->be_syncinfo ) {
177                                 syncinfo_t *si = op->o_bd->be_syncinfo;
178                                 {
179                                         struct berval tmpbv;
180                                         ber_dupbv( &tmpbv, &si->si_provideruri_bv[0] );
181                                         ber_bvarray_add( &deref, &tmpbv );
182                 }
183                         } else {
184                                 deref = default_referral;
185                         }
186                         rs->sr_ref = referral_rewrite( deref, NULL, &op->o_req_dn,
187                                         LDAP_SCOPE_DEFAULT );
188                 }
189
190                 rs->sr_err = LDAP_REFERRAL;
191                 send_ldap_result( op, rs );
192
193                 ber_bvarray_free( rs->sr_ref );
194                 if ( deref != default_referral ) {
195                         ber_bvarray_free( deref );
196                 }
197                 free( (char *)rs->sr_matched );
198                 rs->sr_ref = NULL;
199                 rs->sr_matched = NULL;
200
201                 goto done;
202         }
203
204         if ( get_assert( op ) &&
205                 ( test_filter( op, e, get_assertion( op )) != LDAP_COMPARE_TRUE ))
206         {
207                 rs->sr_err = LDAP_ASSERTION_FAILED;
208                 goto return_results;
209         }
210
211         /* check write on old entry */
212         rs->sr_err = access_allowed( op, e, entry, NULL, ACL_WRITE, NULL );
213         if ( ! rs->sr_err ) {
214                 switch( opinfo.boi_err ) {
215                 case DB_LOCK_DEADLOCK:
216                 case DB_LOCK_NOTGRANTED:
217                         goto retry;
218                 }
219
220                 Debug( LDAP_DEBUG_TRACE, "no access to entry\n", 0,
221                         0, 0 );
222                 rs->sr_text = "no write access to old entry";
223                 rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
224                 goto return_results;
225         }
226
227 #ifndef BDB_HIER
228         rs->sr_err = bdb_cache_children( op, ltid, e );
229         if ( rs->sr_err != DB_NOTFOUND ) {
230                 switch( rs->sr_err ) {
231                 case DB_LOCK_DEADLOCK:
232                 case DB_LOCK_NOTGRANTED:
233                         goto retry;
234                 case 0:
235                         Debug(LDAP_DEBUG_ARGS,
236                                 "<=- " LDAP_XSTRING(bdb_modrdn)
237                                 ": non-leaf %s\n",
238                                 op->o_req_dn.bv_val, 0, 0);
239                         rs->sr_err = LDAP_NOT_ALLOWED_ON_NONLEAF;
240                         rs->sr_text = "subtree rename not supported";
241                         break;
242                 default:
243                         Debug(LDAP_DEBUG_ARGS,
244                                 "<=- " LDAP_XSTRING(bdb_modrdn)
245                                 ": has_children failed: %s (%d)\n",
246                                 db_strerror(rs->sr_err), rs->sr_err, 0 );
247                         rs->sr_err = LDAP_OTHER;
248                         rs->sr_text = "internal error";
249                 }
250                 goto return_results;
251         }
252         ei->bei_state |= CACHE_ENTRY_NO_KIDS;
253 #endif
254
255         if (!manageDSAit && is_entry_referral( e ) ) {
256                 /* parent is a referral, don't allow add */
257                 rs->sr_ref = get_entry_referrals( op, e );
258
259                 Debug( LDAP_DEBUG_TRACE, LDAP_XSTRING(bdb_modrdn)
260                         ": entry %s is referral\n", e->e_dn, 0, 0 );
261
262                 rs->sr_err = LDAP_REFERRAL,
263                 rs->sr_matched = e->e_name.bv_val;
264                 send_ldap_result( op, rs );
265
266                 ber_bvarray_free( rs->sr_ref );
267                 rs->sr_ref = NULL;
268                 rs->sr_matched = NULL;
269                 goto done;
270         }
271
272         if ( be_issuffix( op->o_bd, &e->e_nname ) ) {
273                 p_ndn = slap_empty_bv;
274         } else {
275                 dnParent( &e->e_nname, &p_ndn );
276         }
277         np_ndn = &p_ndn;
278         if ( p_ndn.bv_len != 0 ) {
279                 /* Make sure parent entry exist and we can write its 
280                  * children.
281                  */
282                 eip = ei->bei_parent;
283                 rs->sr_err = bdb_cache_find_id( op, ltid,
284                         eip->bei_id, &eip, 0, locker, &plock );
285
286                 switch( rs->sr_err ) {
287                 case 0:
288                 case DB_NOTFOUND:
289                         break;
290                 case DB_LOCK_DEADLOCK:
291                 case DB_LOCK_NOTGRANTED:
292                         goto retry;
293                 case LDAP_BUSY:
294                         rs->sr_text = "ldap server busy";
295                         goto return_results;
296                 default:
297                         rs->sr_err = LDAP_OTHER;
298                         rs->sr_text = "internal error";
299                         goto return_results;
300                 }
301
302                 p = eip->bei_e;
303                 if( p == NULL) {
304                         Debug( LDAP_DEBUG_TRACE, LDAP_XSTRING(bdb_modrdn)
305                                 ": parent does not exist\n", 0, 0, 0);
306                         rs->sr_err = LDAP_OTHER;
307                         rs->sr_text = "old entry's parent does not exist";
308                         goto return_results;
309                 }
310
311                 /* check parent for "children" acl */
312                 rs->sr_err = access_allowed( op, p,
313                         children, NULL, ACL_WRITE, NULL );
314
315                 if ( ! rs->sr_err ) {
316                         switch( opinfo.boi_err ) {
317                         case DB_LOCK_DEADLOCK:
318                         case DB_LOCK_NOTGRANTED:
319                                 goto retry;
320                         }
321
322                         rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
323                         Debug( LDAP_DEBUG_TRACE, "no access to parent\n", 0,
324                                 0, 0 );
325                         rs->sr_text = "no write access to old parent's children";
326                         goto return_results;
327                 }
328
329                 Debug( LDAP_DEBUG_TRACE,
330                         LDAP_XSTRING(bdb_modrdn) ": wr to children "
331                         "of entry %s OK\n", p_ndn.bv_val, 0, 0 );
332                 
333                 if ( p_ndn.bv_val == slap_empty_bv.bv_val ) {
334                         p_dn = slap_empty_bv;
335                 } else {
336                         dnParent( &e->e_name, &p_dn );
337                 }
338
339                 Debug( LDAP_DEBUG_TRACE,
340                         LDAP_XSTRING(bdb_modrdn) ": parent dn=%s\n",
341                         p_dn.bv_val, 0, 0 );
342
343         } else {
344                 /* no parent, modrdn entry directly under root */
345                 isroot = be_isroot( op );
346                 if ( ! isroot ) {
347                         if ( be_issuffix( op->o_bd, (struct berval *)&slap_empty_bv )
348                                 || be_shadow_update( op ) ) {
349
350                                 p = (Entry *)&slap_entry_root;
351
352                                 /* check parent for "children" acl */
353                                 rs->sr_err = access_allowed( op, p,
354                                         children, NULL, ACL_WRITE, NULL );
355
356                                 p = NULL;
357
358                                 if ( ! rs->sr_err ) {
359                                         switch( opinfo.boi_err ) {
360                                         case DB_LOCK_DEADLOCK:
361                                         case DB_LOCK_NOTGRANTED:
362                                                 goto retry;
363                                         }
364
365                                         rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
366                                         Debug( LDAP_DEBUG_TRACE, 
367                                                 "no access to parent\n", 
368                                                 0, 0, 0 );
369                                         rs->sr_text = "no write access to old parent";
370                                         goto return_results;
371                                 }
372
373                                 Debug( LDAP_DEBUG_TRACE,
374                                         LDAP_XSTRING(bdb_modrdn)
375                                         ": wr to children of entry \"\" OK\n",
376                                         0, 0, 0 );
377                 
378                                 p_dn.bv_val = "";
379                                 p_dn.bv_len = 0;
380
381                                 Debug( LDAP_DEBUG_TRACE,
382                                         LDAP_XSTRING(bdb_modrdn)
383                                         ": parent dn=\"\"\n",
384                                         0, 0, 0 );
385
386                         } else {
387                                 Debug( LDAP_DEBUG_TRACE,
388                                         LDAP_XSTRING(bdb_modrdn)
389                                         ": no parent, not root "
390                                         "& \"\" is not suffix\n",
391                                         0, 0, 0);
392                                 rs->sr_text = "no write access to old parent";
393                                 rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
394                                 goto return_results;
395                         }
396                 }
397         }
398
399         new_parent_dn = &p_dn;  /* New Parent unless newSuperior given */
400
401         if ( op->oq_modrdn.rs_newSup != NULL ) {
402                 Debug( LDAP_DEBUG_TRACE, 
403                         LDAP_XSTRING(bdb_modrdn)
404                         ": new parent \"%s\" requested...\n",
405                         op->oq_modrdn.rs_newSup->bv_val, 0, 0 );
406
407                 /*  newSuperior == oldParent? */
408                 if( dn_match( &p_ndn, op->oq_modrdn.rs_nnewSup ) ) {
409                         Debug( LDAP_DEBUG_TRACE, "bdb_back_modrdn: "
410                                 "new parent \"%s\" same as the old parent \"%s\"\n",
411                                 op->oq_modrdn.rs_newSup->bv_val, p_dn.bv_val, 0 );
412                         op->oq_modrdn.rs_newSup = NULL; /* ignore newSuperior */
413                 }
414         }
415
416         if ( op->oq_modrdn.rs_newSup != NULL ) {
417                 if ( op->oq_modrdn.rs_newSup->bv_len ) {
418                         np_dn = op->oq_modrdn.rs_newSup;
419                         np_ndn = op->oq_modrdn.rs_nnewSup;
420
421                         /* newSuperior == oldParent?, if so ==> ERROR */
422                         /* newSuperior == entry being moved?, if so ==> ERROR */
423                         /* Get Entry with dn=newSuperior. Does newSuperior exist? */
424
425                         rs->sr_err = bdb_dn2entry( op, ltid, np_ndn,
426                                 &neip, 0, locker, &nplock );
427
428                         switch( rs->sr_err ) {
429                         case 0: np = neip->bei_e;
430                         case DB_NOTFOUND:
431                                 break;
432                         case DB_LOCK_DEADLOCK:
433                         case DB_LOCK_NOTGRANTED:
434                                 goto retry;
435                         case LDAP_BUSY:
436                                 rs->sr_text = "ldap server busy";
437                                 goto return_results;
438                         default:
439                                 rs->sr_err = LDAP_OTHER;
440                                 rs->sr_text = "internal error";
441                                 goto return_results;
442                         }
443
444                         if( np == NULL) {
445                                 Debug( LDAP_DEBUG_TRACE,
446                                         LDAP_XSTRING(bdb_modrdn)
447                                         ": newSup(ndn=%s) not here!\n",
448                                         np_ndn->bv_val, 0, 0);
449                                 rs->sr_text = "new superior not found";
450                                 rs->sr_err = LDAP_OTHER;
451                                 goto return_results;
452                         }
453
454                         Debug( LDAP_DEBUG_TRACE,
455                                 LDAP_XSTRING(bdb_modrdn)
456                                 ": wr to new parent OK np=%p, id=%ld\n",
457                                 (void *) np, (long) np->e_id, 0 );
458
459                         /* check newSuperior for "children" acl */
460                         rs->sr_err = access_allowed( op, np, children,
461                                 NULL, ACL_WRITE, NULL );
462
463                         if( ! rs->sr_err ) {
464                                 switch( opinfo.boi_err ) {
465                                 case DB_LOCK_DEADLOCK:
466                                 case DB_LOCK_NOTGRANTED:
467                                         goto retry;
468                                 }
469
470                                 Debug( LDAP_DEBUG_TRACE,
471                                         LDAP_XSTRING(bdb_modrdn)
472                                         ": no wr to newSup children\n",
473                                         0, 0, 0 );
474                                 rs->sr_text = "no write access to new superior's children";
475                                 rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
476                                 goto return_results;
477                         }
478
479                         if ( is_entry_alias( np ) ) {
480                                 /* parent is an alias, don't allow add */
481                                 Debug( LDAP_DEBUG_TRACE,
482                                         LDAP_XSTRING(bdb_modrdn)
483                                         ": entry is alias\n",
484                                         0, 0, 0 );
485                                 rs->sr_text = "new superior is an alias";
486                                 rs->sr_err = LDAP_ALIAS_PROBLEM;
487                                 goto return_results;
488                         }
489
490                         if ( is_entry_referral( np ) ) {
491                                 /* parent is a referral, don't allow add */
492                                 Debug( LDAP_DEBUG_TRACE,
493                                         LDAP_XSTRING(bdb_modrdn)
494                                         ": entry is referral\n",
495                                         0, 0, 0 );
496                                 rs->sr_text = "new superior is a referral";
497                                 rs->sr_err = LDAP_OTHER;
498                                 goto return_results;
499                         }
500
501                 } else {
502                         if ( isroot == -1 ) {
503                                 isroot = be_isroot( op );
504                         }
505                         
506                         np_dn = NULL;
507
508                         /* no parent, modrdn entry directly under root */
509                         if ( ! isroot ) {
510                                 if ( be_issuffix( op->o_bd, (struct berval *)&slap_empty_bv )
511                                         || be_isupdate( op ) ) {
512                                         np = (Entry *)&slap_entry_root;
513
514                                         /* check parent for "children" acl */
515                                         rs->sr_err = access_allowed( op, np,
516                                                 children, NULL, ACL_WRITE, NULL );
517
518                                         np = NULL;
519
520                                         if ( ! rs->sr_err ) {
521                                                 switch( opinfo.boi_err ) {
522                                                 case DB_LOCK_DEADLOCK:
523                                                 case DB_LOCK_NOTGRANTED:
524                                                         goto retry;
525                                                 }
526
527                                                 rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
528                                                 Debug( LDAP_DEBUG_TRACE, 
529                                                         "no access to new superior\n", 
530                                                         0, 0, 0 );
531                                                 rs->sr_text =
532                                                         "no write access to new superior's children";
533                                                 goto return_results;
534                                         }
535
536                                         Debug( LDAP_DEBUG_TRACE,
537                                                 LDAP_XSTRING(bdb_modrdn)
538                                                 ": wr to children "
539                                                 "of entry \"\" OK\n",
540                                                 0, 0, 0 );
541                 
542                                 } else {
543                                         Debug( LDAP_DEBUG_TRACE,
544                                                 LDAP_XSTRING(bdb_modrdn)
545                                                 ": new superior=\"\", not root "
546                                                 "& \"\" is not suffix\n",
547                                                 0, 0, 0 );
548                                         rs->sr_text = "no write access to new superior's children";
549                                         rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
550                                         goto return_results;
551                                 }
552                         }
553
554                         Debug( LDAP_DEBUG_TRACE,
555                                 LDAP_XSTRING(bdb_modrdn)
556                                 ": new superior=\"\"\n",
557                                 0, 0, 0 );
558                 }
559
560                 Debug( LDAP_DEBUG_TRACE,
561                         LDAP_XSTRING(bdb_modrdn)
562                         ": wr to new parent's children OK\n",
563                         0, 0, 0 );
564
565                 new_parent_dn = np_dn;
566         }
567
568         /* Build target dn and make sure target entry doesn't exist already. */
569         if (!new_dn.bv_val) {
570                 build_new_dn( &new_dn, new_parent_dn, &op->oq_modrdn.rs_newrdn, NULL ); 
571         }
572
573         if (!new_ndn.bv_val) {
574                 struct berval bv = {0, NULL};
575                 dnNormalize( 0, NULL, NULL, &new_dn, &bv, op->o_tmpmemctx );
576                 ber_dupbv( &new_ndn, &bv );
577         }
578
579         Debug( LDAP_DEBUG_TRACE, LDAP_XSTRING(bdb_modrdn) ": new ndn=%s\n",
580                 new_ndn.bv_val, 0, 0 );
581
582         /* Shortcut the search */
583         nei = neip ? neip : eip;
584         rs->sr_err = bdb_cache_find_ndn ( op, ltid, &new_ndn, &nei );
585         if ( nei ) bdb_cache_entryinfo_unlock( nei );
586         switch( rs->sr_err ) {
587         case DB_LOCK_DEADLOCK:
588         case DB_LOCK_NOTGRANTED:
589                 goto retry;
590         case DB_NOTFOUND:
591                 break;
592         case 0:
593                 rs->sr_err = LDAP_ALREADY_EXISTS;
594                 goto return_results;
595         default:
596                 rs->sr_err = LDAP_OTHER;
597                 rs->sr_text = "internal error";
598                 goto return_results;
599         }
600
601         /* Get attribute type and attribute value of our new rdn, we will
602          * need to add that to our new entry
603          */
604         if ( !new_rdn && ldap_bv2rdn_x( &op->oq_modrdn.rs_newrdn, &new_rdn,
605                 (char **)&rs->sr_text, LDAP_DN_FORMAT_LDAP, op->o_tmpmemctx ) )
606         {
607                 Debug( LDAP_DEBUG_TRACE,
608                         LDAP_XSTRING(bdb_modrdn) ": can't figure out "
609                         "type(s)/values(s) of newrdn\n", 
610                         0, 0, 0 );
611                 rs->sr_err = LDAP_INVALID_DN_SYNTAX;
612                 rs->sr_text = "unknown type(s) used in RDN";
613                 goto return_results;
614         }
615
616         Debug( LDAP_DEBUG_TRACE,
617                 LDAP_XSTRING(bdb_modrdn)
618                 ": new_rdn_type=\"%s\", new_rdn_val=\"%s\"\n",
619                 new_rdn[ 0 ]->la_attr.bv_val,
620                 new_rdn[ 0 ]->la_value.bv_val, 0 );
621
622         if ( op->oq_modrdn.rs_deleteoldrdn ) {
623                 if ( !old_rdn && ldap_bv2rdn_x( &op->o_req_dn, &old_rdn,
624                         (char **)&rs->sr_text, LDAP_DN_FORMAT_LDAP, op->o_tmpmemctx ) )
625                 {
626                         Debug( LDAP_DEBUG_TRACE,
627                                 LDAP_XSTRING(bdb_modrdn) ": can't figure out "
628                                 "the old_rdn type(s)/value(s)\n", 
629                                 0, 0, 0 );
630                         rs->sr_err = LDAP_OTHER;
631                         rs->sr_text = "cannot parse RDN from old DN";
632                         goto return_results;            
633                 }
634         }
635
636         /* prepare modlist of modifications from old/new rdn */
637         if (!mod) {
638                 rs->sr_err = slap_modrdn2mods( op, rs, e, old_rdn, new_rdn, &mod );
639                 if ( rs->sr_err != LDAP_SUCCESS ) {
640                         goto return_results;
641                 }
642         }
643
644         if( op->o_preread ) {
645                 if( preread_ctrl == NULL ) {
646                         preread_ctrl = &ctrls[num_ctrls++];
647                         ctrls[num_ctrls] = NULL;
648                 }
649                 if( slap_read_controls( op, rs, e,
650                         &slap_pre_read_bv, preread_ctrl ) )
651                 {
652                         Debug( LDAP_DEBUG_TRACE,        
653                                 "<=- " LDAP_XSTRING(bdb_modrdn)
654                                 ": post-read failed!\n", 0, 0, 0 );
655                         goto return_results;
656                 }                   
657         }
658
659         /* nested transaction */
660         rs->sr_err = TXN_BEGIN( bdb->bi_dbenv, ltid, &lt2, bdb->bi_db_opflags );
661         rs->sr_text = NULL;
662         if( rs->sr_err != 0 ) {
663                 Debug( LDAP_DEBUG_TRACE,
664                         LDAP_XSTRING(bdb_modrdn)
665                         ": txn_begin(2) failed: %s (%d)\n",
666                         db_strerror(rs->sr_err), rs->sr_err, 0 );
667                 rs->sr_err = LDAP_OTHER;
668                 rs->sr_text = "internal error";
669                 goto return_results;
670         }
671
672         /* delete old DN */
673         rs->sr_err = bdb_dn2id_delete( op, lt2, eip, e );
674         if ( rs->sr_err != 0 ) {
675                 Debug(LDAP_DEBUG_TRACE,
676                         "<=- " LDAP_XSTRING(bdb_modrdn)
677                         ": dn2id del failed: %s (%d)\n",
678                         db_strerror(rs->sr_err), rs->sr_err, 0 );
679                 switch( rs->sr_err ) {
680                 case DB_LOCK_DEADLOCK:
681                 case DB_LOCK_NOTGRANTED:
682                         goto retry;
683                 }
684                 rs->sr_err = LDAP_OTHER;
685                 rs->sr_text = "DN index delete fail";
686                 goto return_results;
687         }
688
689         /* copy the entry, then override some fields */
690         dummy = *e;
691         dummy.e_name = new_dn;
692         dummy.e_nname = new_ndn;
693         dummy.e_attrs = NULL;
694
695         /* add new DN */
696         rs->sr_err = bdb_dn2id_add( op, lt2, neip ? neip : eip, &dummy );
697         if ( rs->sr_err != 0 ) {
698                 Debug(LDAP_DEBUG_TRACE,
699                         "<=- " LDAP_XSTRING(bdb_modrdn)
700                         ": dn2id add failed: %s (%d)\n",
701                         db_strerror(rs->sr_err), rs->sr_err, 0 );
702                 switch( rs->sr_err ) {
703                 case DB_LOCK_DEADLOCK:
704                 case DB_LOCK_NOTGRANTED:
705                         goto retry;
706                 }
707                 rs->sr_err = LDAP_OTHER;
708                 rs->sr_text = "DN index add failed";
709                 goto return_results;
710         }
711
712         dummy.e_attrs = e->e_attrs;
713
714         /* modify entry */
715         rs->sr_err = bdb_modify_internal( op, lt2, &mod[0], &dummy,
716                 &rs->sr_text, textbuf, textlen );
717         if( rs->sr_err != LDAP_SUCCESS ) {
718                 Debug(LDAP_DEBUG_TRACE,
719                         "<=- " LDAP_XSTRING(bdb_modrdn)
720                         ": modify failed: %s (%d)\n",
721                         db_strerror(rs->sr_err), rs->sr_err, 0 );
722                 if ( ( rs->sr_err == LDAP_INSUFFICIENT_ACCESS ) && opinfo.boi_err ) {
723                         rs->sr_err = opinfo.boi_err;
724                 }
725                 if ( dummy.e_attrs == e->e_attrs ) dummy.e_attrs = NULL;
726                 switch( rs->sr_err ) {
727                 case DB_LOCK_DEADLOCK:
728                 case DB_LOCK_NOTGRANTED:
729                         goto retry;
730                 }
731                 goto return_results;
732         }
733
734         /* id2entry index */
735         rs->sr_err = bdb_id2entry_update( op->o_bd, lt2, &dummy );
736         if ( rs->sr_err != 0 ) {
737                 Debug(LDAP_DEBUG_TRACE,
738                         "<=- " LDAP_XSTRING(bdb_modrdn)
739                         ": id2entry failed: %s (%d)\n",
740                         db_strerror(rs->sr_err), rs->sr_err, 0 );
741                 switch( rs->sr_err ) {
742                 case DB_LOCK_DEADLOCK:
743                 case DB_LOCK_NOTGRANTED:
744                         goto retry;
745                 }
746                 rs->sr_err = LDAP_OTHER;
747                 rs->sr_text = "entry update failed";
748                 goto return_results;
749         }
750
751         if ( p_ndn.bv_len != 0 ) {
752                 parent_is_glue = is_entry_glue(p);
753                 rs->sr_err = bdb_cache_children( op, lt2, p );
754                 if ( rs->sr_err != DB_NOTFOUND ) {
755                         switch( rs->sr_err ) {
756                         case DB_LOCK_DEADLOCK:
757                         case DB_LOCK_NOTGRANTED:
758                                 goto retry;
759                         case 0:
760                                 break;
761                         default:
762                                 Debug(LDAP_DEBUG_ARGS,
763                                         "<=- " LDAP_XSTRING(bdb_modrdn)
764                                         ": has_children failed: %s (%d)\n",
765                                         db_strerror(rs->sr_err), rs->sr_err, 0 );
766                                 rs->sr_err = LDAP_OTHER;
767                                 rs->sr_text = "internal error";
768                                 goto return_results;
769                         }
770                         parent_is_leaf = 1;
771                 }
772                 bdb_unlocked_cache_return_entry_r(&bdb->bi_cache, p);
773                 p = NULL;
774         }
775
776         if ( TXN_COMMIT( lt2, 0 ) != 0 ) {
777                 rs->sr_err = LDAP_OTHER;
778                 rs->sr_text = "txn_commit(2) failed";
779                 goto return_results;
780         }
781
782         if( op->o_postread ) {
783                 if( postread_ctrl == NULL ) {
784                         postread_ctrl = &ctrls[num_ctrls++];
785                         ctrls[num_ctrls] = NULL;
786                 }
787                 if( slap_read_controls( op, rs, &dummy,
788                         &slap_post_read_bv, postread_ctrl ) )
789                 {
790                         Debug( LDAP_DEBUG_TRACE,        
791                                 "<=- " LDAP_XSTRING(bdb_modrdn)
792                                 ": post-read failed!\n", 0, 0, 0 );
793                         goto return_results;
794                 }                   
795         }
796
797         if( op->o_noop ) {
798                 if(( rs->sr_err=TXN_ABORT( ltid )) != 0 ) {
799                         rs->sr_text = "txn_abort (no-op) failed";
800                 } else {
801                         rs->sr_err = LDAP_SUCCESS;
802                         goto return_results;
803                 }
804
805         } else {
806                 rc = bdb_cache_modrdn( e, &op->orr_nnewrdn, &dummy, neip,
807                         bdb->bi_dbenv, locker, &lock );
808                 switch( rc ) {
809                 case DB_LOCK_DEADLOCK:
810                 case DB_LOCK_NOTGRANTED:
811                         goto retry;
812                 }
813                 dummy.e_attrs = NULL;
814                 new_dn.bv_val = NULL;
815                 new_ndn.bv_val = NULL;
816
817                 if(( rs->sr_err=TXN_COMMIT( ltid, 0 )) != 0 ) {
818                         rs->sr_text = "txn_commit failed";
819                 } else {
820                         rs->sr_err = LDAP_SUCCESS;
821                 }
822         }
823  
824         ltid = NULL;
825         op->o_private = NULL;
826  
827         if( rs->sr_err != LDAP_SUCCESS ) {
828                 Debug( LDAP_DEBUG_TRACE,
829                         LDAP_XSTRING(bdb_modrdn) ": %s : %s (%d)\n",
830                         rs->sr_text, db_strerror(rs->sr_err), rs->sr_err );
831                 rs->sr_err = LDAP_OTHER;
832
833                 goto return_results;
834         }
835
836         Debug(LDAP_DEBUG_TRACE,
837                 LDAP_XSTRING(bdb_modrdn)
838                 ": rdn modified%s id=%08lx dn=\"%s\"\n",
839                 op->o_noop ? " (no-op)" : "",
840                 dummy.e_id, op->o_req_dn.bv_val );
841         rs->sr_text = NULL;
842         if( num_ctrls ) rs->sr_ctrls = ctrls;
843
844 return_results:
845         if ( dummy.e_attrs ) {
846                 attrs_free( dummy.e_attrs );
847         }
848         send_ldap_result( op, rs );
849
850         if( rs->sr_err == LDAP_SUCCESS && bdb->bi_txn_cp ) {
851                 ldap_pvt_thread_yield();
852                 TXN_CHECKPOINT( bdb->bi_dbenv,
853                         bdb->bi_txn_cp_kbyte, bdb->bi_txn_cp_min, 0 );
854         }
855         
856         if ( rs->sr_err == LDAP_SUCCESS && parent_is_glue && parent_is_leaf ) {
857                 op->o_delete_glue_parent = 1;
858         }
859
860 done:
861         if( new_dn.bv_val != NULL ) free( new_dn.bv_val );
862         if( new_ndn.bv_val != NULL ) free( new_ndn.bv_val );
863
864         /* LDAP v2 supporting correct attribute handling. */
865         if ( new_rdn != NULL ) {
866                 ldap_rdnfree_x( new_rdn, op->o_tmpmemctx );
867         }
868         if ( old_rdn != NULL ) {
869                 ldap_rdnfree_x( old_rdn, op->o_tmpmemctx );
870         }
871         if( mod != NULL ) {
872                 Modifications *tmp;
873                 for (; mod; mod=tmp ) {
874                         tmp = mod->sml_next;
875                         /* slap_modrdn2mods does things one way,
876                          * slap_mods_opattrs does it differently
877                          */
878                         if ( mod->sml_op != SLAP_MOD_SOFTADD &&
879                                 mod->sml_op != LDAP_MOD_DELETE ) break;
880                         if ( mod->sml_nvalues ) free( mod->sml_nvalues[0].bv_val );
881                         free( mod );
882                 }
883                 slap_mods_free( mod );
884         }
885
886         /* LDAP v3 Support */
887         if( np != NULL ) {
888                 /* free new parent and reader lock */
889                 bdb_unlocked_cache_return_entry_r(&bdb->bi_cache, np);
890         }
891
892         if( p != NULL ) {
893                 /* free parent and reader lock */
894                 bdb_unlocked_cache_return_entry_r(&bdb->bi_cache, p);
895         }
896
897         /* free entry */
898         if( e != NULL ) {
899                 bdb_unlocked_cache_return_entry_w( &bdb->bi_cache, e);
900         }
901
902         if( ltid != NULL ) {
903                 TXN_ABORT( ltid );
904                 op->o_private = NULL;
905         }
906
907         if( preread_ctrl != NULL ) {
908                 slap_sl_free( (*preread_ctrl)->ldctl_value.bv_val, op->o_tmpmemctx );
909                 slap_sl_free( *preread_ctrl, op->o_tmpmemctx );
910         }
911         if( postread_ctrl != NULL ) {
912                 slap_sl_free( (*postread_ctrl)->ldctl_value.bv_val, op->o_tmpmemctx );
913                 slap_sl_free( *postread_ctrl, op->o_tmpmemctx );
914         }
915         return rs->sr_err;
916 }