]> git.sur5r.net Git - openldap/blob - servers/slapd/back-bdb/modrdn.c
(Partial) Sync with HEAD
[openldap] / servers / slapd / back-bdb / modrdn.c
1 /* modrdn.c - bdb backend modrdn routine */
2 /* $OpenLDAP$ */
3 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
4  *
5  * Copyright 2000-2003 The OpenLDAP Foundation.
6  * All rights reserved.
7  *
8  * Redistribution and use in source and binary forms, with or without
9  * modification, are permitted only as authorized by the OpenLDAP
10  * Public License.
11  *
12  * A copy of this license is available in the file LICENSE in the
13  * top-level directory of the distribution or, alternatively, at
14  * <http://www.OpenLDAP.org/license.html>.
15  */
16
17 #include "portable.h"
18
19 #include <stdio.h>
20 #include <ac/string.h>
21
22 #include "back-bdb.h"
23 #include "external.h"
24
25 int
26 bdb_modrdn( Operation   *op, SlapReply *rs )
27 {
28         struct bdb_info *bdb = (struct bdb_info *) op->o_bd->be_private;
29         AttributeDescription *children = slap_schema.si_ad_children;
30         AttributeDescription *entry = slap_schema.si_ad_entry;
31         struct berval   p_dn, p_ndn;
32         struct berval   new_dn = {0, NULL}, new_ndn = {0, NULL};
33         int             isroot = -1;
34         Entry           *e = NULL;
35         Entry           *p = NULL;
36         EntryInfo       *ei = NULL, *eip = NULL, *nei = NULL, *neip = NULL;
37         /* LDAP v2 supporting correct attribute handling. */
38         LDAPRDN         new_rdn = NULL;
39         LDAPRDN         old_rdn = NULL;
40         char textbuf[SLAP_TEXT_BUFLEN];
41         size_t textlen = sizeof textbuf;
42         DB_TXN          *ltid = NULL, *lt2;
43         struct bdb_op_info opinfo;
44         Entry dummy, *save;
45
46         ID                      id;
47
48         Entry           *np = NULL;                     /* newSuperior Entry */
49         struct berval   *np_dn = NULL;                  /* newSuperior dn */
50         struct berval   *np_ndn = NULL;                 /* newSuperior ndn */
51         struct berval   *new_parent_dn = NULL;  /* np_dn, p_dn, or NULL */
52
53         /* Used to interface with bdb_modify_internal() */
54         Modifications   *mod = NULL;            /* Used to delete old rdn */
55
56         int             manageDSAit = get_manageDSAit( op );
57
58         u_int32_t       locker = 0;
59         DB_LOCK         lock, plock, nplock;
60
61         int             noop = 0;
62
63         int             num_retries = 0;
64
65         LDAPControl *ctrls[SLAP_MAX_RESPONSE_CONTROLS];
66         int num_ctrls = 0;
67
68         Operation *ps_list;
69         struct psid_entry *pm_list, *pm_prev;
70         int     rc;
71         EntryInfo       *suffix_ei;
72         Entry           *ctxcsn_e;
73         int                     ctxcsn_added = 0;
74
75 #ifdef NEW_LOGGING
76         LDAP_LOG ( OPERATION, ENTRY, "==>bdb_modrdn(%s,%s,%s)\n", 
77                 op->o_req_dn.bv_val,op->oq_modrdn.rs_newrdn.bv_val,
78                 op->oq_modrdn.rs_newSup ? op->oq_modrdn.rs_newSup->bv_val : "NULL" );
79 #else
80         Debug( LDAP_DEBUG_TRACE, "==>bdb_modrdn(%s,%s,%s)\n",
81                 op->o_req_dn.bv_val,op->oq_modrdn.rs_newrdn.bv_val,
82                 op->oq_modrdn.rs_newSup ? op->oq_modrdn.rs_newSup->bv_val : "NULL" );
83 #endif
84
85         if( 0 ) {
86 retry:  /* transaction retry */
87                 if (e != NULL) {
88                         bdb_unlocked_cache_return_entry_w(&bdb->bi_cache, e);
89                         e = NULL;
90                 }
91                 if (p != NULL) {
92                         bdb_unlocked_cache_return_entry_r(&bdb->bi_cache, p);
93                         p = NULL;
94                 }
95                 if (np != NULL) {
96                         bdb_unlocked_cache_return_entry_r(&bdb->bi_cache, np);
97                         np = NULL;
98                 }
99 #ifdef NEW_LOGGING
100                 LDAP_LOG ( OPERATION, DETAIL1, "==>bdb_modrdn: retrying...\n", 0, 0, 0);
101 #else
102                 Debug( LDAP_DEBUG_TRACE, "==>bdb_modrdn: retrying...\n", 0, 0, 0 );
103 #endif
104                 pm_list = LDAP_LIST_FIRST(&op->o_pm_list);
105                 while ( pm_list != NULL ) {
106                         LDAP_LIST_REMOVE ( pm_list, ps_link );
107                         pm_prev = pm_list;
108                         pm_list = LDAP_LIST_NEXT ( pm_list, ps_link );
109                         ch_free( pm_prev );
110                 }
111
112                 rs->sr_err = TXN_ABORT( ltid );
113                 ltid = NULL;
114                 op->o_private = NULL;
115                 op->o_do_not_cache = opinfo.boi_acl_cache;
116                 if( rs->sr_err != 0 ) {
117                         rs->sr_err = LDAP_OTHER;
118                         rs->sr_text = "internal error";
119                         goto return_results;
120                 }
121                 ldap_pvt_thread_yield();
122                 bdb_trans_backoff( ++num_retries );
123         }
124
125         /* begin transaction */
126         rs->sr_err = TXN_BEGIN( bdb->bi_dbenv, NULL, &ltid, 
127                 bdb->bi_db_opflags );
128         rs->sr_text = NULL;
129         if( rs->sr_err != 0 ) {
130 #ifdef NEW_LOGGING
131                 LDAP_LOG ( OPERATION, ERR, 
132                         "==>bdb_modrdn: txn_begin failed: %s (%d)\n", 
133                         db_strerror(rs->sr_err), rs->sr_err, 0 );
134 #else
135                 Debug( LDAP_DEBUG_TRACE,
136                         "bdb_delete: txn_begin failed: %s (%d)\n",
137                         db_strerror(rs->sr_err), rs->sr_err, 0 );
138 #endif
139                 rs->sr_err = LDAP_OTHER;
140                 rs->sr_text = "internal error";
141                 goto return_results;
142         }
143
144         locker = TXN_ID ( ltid );
145
146         opinfo.boi_bdb = op->o_bd;
147         opinfo.boi_txn = ltid;
148         opinfo.boi_locker = locker;
149         opinfo.boi_err = 0;
150         opinfo.boi_acl_cache = op->o_do_not_cache;
151         op->o_private = &opinfo;
152
153         /* get entry */
154         rs->sr_err = bdb_dn2entry( op, ltid, &op->o_req_ndn, &ei, 1,
155                 locker, &lock );
156
157         switch( rs->sr_err ) {
158         case 0:
159         case DB_NOTFOUND:
160                 break;
161         case DB_LOCK_DEADLOCK:
162         case DB_LOCK_NOTGRANTED:
163                 goto retry;
164         case LDAP_BUSY:
165                 rs->sr_text = "ldap server busy";
166                 goto return_results;
167         default:
168                 rs->sr_err = LDAP_OTHER;
169                 rs->sr_text = "internal error";
170                 goto return_results;
171         }
172
173         e = ei->bei_e;
174         /* FIXME: dn2entry() should return non-glue entry */
175         if (( rs->sr_err == DB_NOTFOUND ) || ( !manageDSAit && e && is_entry_glue( e ))) {
176                 if( e != NULL ) {
177                         rs->sr_matched = ch_strdup( e->e_dn );
178                         rs->sr_ref = is_entry_referral( e )
179                                 ? get_entry_referrals( op, e )
180                                 : NULL;
181                         bdb_unlocked_cache_return_entry_r( &bdb->bi_cache, e);
182                         e = NULL;
183
184                 } else {
185                         BerVarray deref = NULL;
186                         if ( !LDAP_STAILQ_EMPTY( &op->o_bd->be_syncinfo )) {
187                                 syncinfo_t *si;
188                                 LDAP_STAILQ_FOREACH( si, &op->o_bd->be_syncinfo, si_next ) {
189                                         struct berval tmpbv;
190                                         ber_dupbv( &tmpbv, &si->si_provideruri_bv[0] );
191                                         ber_bvarray_add( &deref, &tmpbv );
192                 }
193                         } else {
194                                 deref = default_referral;
195                         }
196                         rs->sr_ref = referral_rewrite( deref, NULL, &op->o_req_dn,
197                                 LDAP_SCOPE_DEFAULT );
198                 }
199
200                 rs->sr_err = LDAP_REFERRAL;
201                 send_ldap_result( op, rs );
202
203                 ber_bvarray_free( rs->sr_ref );
204                 free( (char *)rs->sr_matched );
205                 rs->sr_ref = NULL;
206                 rs->sr_matched = NULL;
207
208                 goto done;
209         }
210
211         if ( get_assert( op ) &&
212                 ( test_filter( op, e, get_assertion( op )) != LDAP_COMPARE_TRUE ))
213         {
214                 rs->sr_err = LDAP_ASSERTION_FAILED;
215                 goto return_results;
216         }
217
218         /* check write on old entry */
219         rs->sr_err = access_allowed( op, e, entry, NULL, ACL_WRITE, NULL );
220         if ( ! rs->sr_err ) {
221                 switch( opinfo.boi_err ) {
222                 case DB_LOCK_DEADLOCK:
223                 case DB_LOCK_NOTGRANTED:
224                         goto retry;
225                 }
226
227 #ifdef NEW_LOGGING
228                 LDAP_LOG ( OPERATION, ERR, 
229                         "==>bdb_modrdn: no access to entry\n", 0, 0, 0 );
230 #else
231                 Debug( LDAP_DEBUG_TRACE, "no access to entry\n", 0,
232                         0, 0 );
233 #endif
234                 rs->sr_text = "no write access to old entry";
235                 rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
236                 goto return_results;
237         }
238
239 #ifndef BDB_HIER
240         rs->sr_err = bdb_cache_children( op, ltid, e );
241         if ( rs->sr_err != DB_NOTFOUND ) {
242                 switch( rs->sr_err ) {
243                 case DB_LOCK_DEADLOCK:
244                 case DB_LOCK_NOTGRANTED:
245                         goto retry;
246                 case 0:
247 #ifdef NEW_LOGGING
248                         LDAP_LOG ( OPERATION, DETAIL1, 
249                                 "<=- bdb_modrdn: non-leaf %s\n", op->o_req_dn.bv_val, 0, 0 );
250 #else
251                         Debug(LDAP_DEBUG_ARGS,
252                                 "<=- bdb_modrdn: non-leaf %s\n",
253                                 op->o_req_dn.bv_val, 0, 0);
254 #endif
255                         rs->sr_err = LDAP_NOT_ALLOWED_ON_NONLEAF;
256                         rs->sr_text = "subtree rename not supported";
257                         break;
258                 default:
259 #ifdef NEW_LOGGING
260                         LDAP_LOG ( OPERATION, ERR, 
261                                 "<=- bdb_modrdn: has_children failed %s (%d)\n",
262                                 db_strerror(rs->sr_err), rs->sr_err, 0 );
263 #else
264                         Debug(LDAP_DEBUG_ARGS,
265                                 "<=- bdb_modrdn: has_children failed: %s (%d)\n",
266                                 db_strerror(rs->sr_err), rs->sr_err, 0 );
267 #endif
268                         rs->sr_err = LDAP_OTHER;
269                         rs->sr_text = "internal error";
270                 }
271                 goto return_results;
272         }
273         ei->bei_state |= CACHE_ENTRY_NO_KIDS;
274 #endif
275         if (!manageDSAit && is_entry_referral( e ) ) {
276                 /* parent is a referral, don't allow add */
277                 rs->sr_ref = get_entry_referrals( op, e );
278
279 #ifdef NEW_LOGGING
280                 LDAP_LOG ( OPERATION, DETAIL1, 
281                         "==>bdb_modrdn: entry %s is referral \n", e->e_dn, 0, 0 );
282 #else
283                 Debug( LDAP_DEBUG_TRACE, "bdb_modrdn: entry %s is referral\n",
284                         e->e_dn, 0, 0 );
285 #endif
286
287                 rs->sr_err = LDAP_REFERRAL,
288                 rs->sr_matched = e->e_name.bv_val;
289                 send_ldap_result( op, rs );
290
291                 ber_bvarray_free( rs->sr_ref );
292                 rs->sr_ref = NULL;
293                 rs->sr_matched = NULL;
294                 goto done;
295         }
296
297         if ( be_issuffix( op->o_bd, &e->e_nname ) ) {
298                 p_ndn = slap_empty_bv;
299         } else {
300                 dnParent( &e->e_nname, &p_ndn );
301         }
302         np_ndn = &p_ndn;
303         if ( p_ndn.bv_len != 0 ) {
304                 /* Make sure parent entry exist and we can write its 
305                  * children.
306                  */
307                 eip = ei->bei_parent;
308                 rs->sr_err = bdb_cache_find_id( op, ltid,
309                         eip->bei_id, &eip, 0, locker, &plock );
310
311                 switch( rs->sr_err ) {
312                 case 0:
313                 case DB_NOTFOUND:
314                         break;
315                 case DB_LOCK_DEADLOCK:
316                 case DB_LOCK_NOTGRANTED:
317                         goto retry;
318                 case LDAP_BUSY:
319                         rs->sr_text = "ldap server busy";
320                         goto return_results;
321                 default:
322                         rs->sr_err = LDAP_OTHER;
323                         rs->sr_text = "internal error";
324                         goto return_results;
325                 }
326
327                 p = eip->bei_e;
328                 if( p == NULL) {
329 #ifdef NEW_LOGGING
330                         LDAP_LOG ( OPERATION, ERR, 
331                                 "==>bdb_modrdn: parent does not exist\n", 0, 0, 0 );
332 #else
333                         Debug( LDAP_DEBUG_TRACE, "bdb_modrdn: parent does not exist\n",
334                                 0, 0, 0);
335 #endif
336                         rs->sr_err = LDAP_OTHER;
337                         rs->sr_text = "old entry's parent does not exist";
338                         goto return_results;
339                 }
340
341                 /* check parent for "children" acl */
342                 rs->sr_err = access_allowed( op, p,
343                         children, NULL, ACL_WRITE, NULL );
344
345                 if ( ! rs->sr_err ) {
346                         switch( opinfo.boi_err ) {
347                         case DB_LOCK_DEADLOCK:
348                         case DB_LOCK_NOTGRANTED:
349                                 goto retry;
350                         }
351
352                         rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
353 #ifdef NEW_LOGGING
354                         LDAP_LOG ( OPERATION, ERR, 
355                                 "==>bdb_modrdn: no access to parent\n", 0, 0, 0 );
356 #else
357                         Debug( LDAP_DEBUG_TRACE, "no access to parent\n", 0,
358                                 0, 0 );
359 #endif
360                         rs->sr_text = "no write access to old parent's children";
361                         goto return_results;
362                 }
363
364 #ifdef NEW_LOGGING
365                 LDAP_LOG ( OPERATION, DETAIL1, 
366                         "==>bdb_modrdn: wr to children %s is OK\n", p_ndn.bv_val, 0, 0 );
367 #else
368                 Debug( LDAP_DEBUG_TRACE,
369                         "bdb_modrdn: wr to children of entry %s OK\n",
370                         p_ndn.bv_val, 0, 0 );
371 #endif
372                 
373                 if ( p_ndn.bv_val == slap_empty_bv.bv_val ) {
374                         p_dn = slap_empty_bv;
375                 } else {
376                         dnParent( &e->e_name, &p_dn );
377                 }
378
379 #ifdef NEW_LOGGING
380                 LDAP_LOG ( OPERATION, DETAIL1, 
381                         "==>bdb_modrdn: parent dn=%s\n", p_dn.bv_val, 0, 0 );
382 #else
383                 Debug( LDAP_DEBUG_TRACE,
384                         "bdb_modrdn: parent dn=%s\n",
385                         p_dn.bv_val, 0, 0 );
386 #endif
387
388         } else {
389                 /* no parent, modrdn entry directly under root */
390                 isroot = be_isroot( op->o_bd, &op->o_ndn );
391                 if ( ! isroot ) {
392                         if ( be_issuffix( op->o_bd, (struct berval *)&slap_empty_bv )
393                                 || be_isupdate( op->o_bd, &op->o_ndn ) ) {
394
395                                 p = (Entry *)&slap_entry_root;
396
397                                 /* check parent for "children" acl */
398                                 rs->sr_err = access_allowed( op, p,
399                                         children, NULL, ACL_WRITE, NULL );
400
401                                 p = NULL;
402
403                                 if ( ! rs->sr_err ) {
404                                         switch( opinfo.boi_err ) {
405                                         case DB_LOCK_DEADLOCK:
406                                         case DB_LOCK_NOTGRANTED:
407                                                 goto retry;
408                                         }
409
410                                         rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
411 #ifdef NEW_LOGGING
412                                         LDAP_LOG ( OPERATION, ERR, 
413                                                 "==>bdb_modrdn: no access to parent\n", 0, 0, 0 );
414 #else
415                                         Debug( LDAP_DEBUG_TRACE, 
416                                                 "no access to parent\n", 
417                                                 0, 0, 0 );
418 #endif
419                                         rs->sr_text = "no write access to old parent";
420                                         goto return_results;
421                                 }
422
423 #ifdef NEW_LOGGING
424                                 LDAP_LOG ( OPERATION, DETAIL1, 
425                                         "==>bdb_modrdn: wr to children of entry \"%s\" OK\n", 
426                                         p_dn.bv_val, 0, 0 );
427 #else
428                                 Debug( LDAP_DEBUG_TRACE,
429                                         "bdb_modrdn: wr to children of entry \"\" OK\n",
430                                         0, 0, 0 );
431 #endif
432                 
433                                 p_dn.bv_val = "";
434                                 p_dn.bv_len = 0;
435
436 #ifdef NEW_LOGGING
437                                 LDAP_LOG ( OPERATION, DETAIL1, 
438                                         "==>bdb_modrdn: parent dn=\"\" \n", 0, 0, 0 );
439 #else
440                                 Debug( LDAP_DEBUG_TRACE,
441                                         "bdb_modrdn: parent dn=\"\"\n",
442                                         0, 0, 0 );
443 #endif
444
445                         } else {
446 #ifdef NEW_LOGGING
447                                 LDAP_LOG ( OPERATION, ERR, 
448                                         "==>bdb_modrdn: no parent, not root &\"\" is not "
449                                         "suffix\n", 0, 0, 0 );
450 #else
451                                 Debug( LDAP_DEBUG_TRACE,
452                                         "bdb_modrdn: no parent, not root "
453                                         "& \"\" is not suffix\n",
454                                         0, 0, 0);
455 #endif
456                                 rs->sr_text = "no write access to old parent";
457                                 rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
458                                 goto return_results;
459                         }
460                 }
461         }
462
463         new_parent_dn = &p_dn;  /* New Parent unless newSuperior given */
464
465         if ( op->oq_modrdn.rs_newSup != NULL ) {
466 #ifdef NEW_LOGGING
467                 LDAP_LOG ( OPERATION, DETAIL1, 
468                         "==>bdb_modrdn: new parent \"%s\" requested...\n", 
469                         op->oq_modrdn.rs_newSup->bv_val, 0, 0 );
470 #else
471                 Debug( LDAP_DEBUG_TRACE, 
472                         "bdb_modrdn: new parent \"%s\" requested...\n",
473                         op->oq_modrdn.rs_newSup->bv_val, 0, 0 );
474 #endif
475
476                 /*  newSuperior == oldParent? */
477                 if( dn_match( &p_ndn, op->oq_modrdn.rs_nnewSup ) ) {
478 #ifdef NEW_LOGGING
479                         LDAP_LOG( BACK_BDB, INFO, "bdb_back_modrdn: "
480                                 "new parent \"%s\" same as the old parent \"%s\"\n",
481                                 op->oq_modrdn.rs_newSup->bv_val, p_dn.bv_val, 0 );
482 #else
483                         Debug( LDAP_DEBUG_TRACE, "bdb_back_modrdn: "
484                                 "new parent \"%s\" same as the old parent \"%s\"\n",
485                                 op->oq_modrdn.rs_newSup->bv_val, p_dn.bv_val, 0 );
486 #endif      
487                         op->oq_modrdn.rs_newSup = NULL; /* ignore newSuperior */
488                 }
489         }
490
491         if ( op->oq_modrdn.rs_newSup != NULL ) {
492                 if ( op->oq_modrdn.rs_newSup->bv_len ) {
493                         np_dn = op->oq_modrdn.rs_newSup;
494                         np_ndn = op->oq_modrdn.rs_nnewSup;
495
496                         /* newSuperior == oldParent?, if so ==> ERROR */
497                         /* newSuperior == entry being moved?, if so ==> ERROR */
498                         /* Get Entry with dn=newSuperior. Does newSuperior exist? */
499
500                         rs->sr_err = bdb_dn2entry( op, ltid, np_ndn,
501                                 &neip, 0, locker, &nplock );
502
503                         switch( rs->sr_err ) {
504                         case 0: np = neip->bei_e;
505                         case DB_NOTFOUND:
506                                 break;
507                         case DB_LOCK_DEADLOCK:
508                         case DB_LOCK_NOTGRANTED:
509                                 goto retry;
510                         case LDAP_BUSY:
511                                 rs->sr_text = "ldap server busy";
512                                 goto return_results;
513                         default:
514                                 rs->sr_err = LDAP_OTHER;
515                                 rs->sr_text = "internal error";
516                                 goto return_results;
517                         }
518
519                         if( np == NULL) {
520 #ifdef NEW_LOGGING
521                                 LDAP_LOG ( OPERATION, DETAIL1, 
522                                         "==>bdb_modrdn: newSup(ndn=%s) not here!\n", 
523                                         np_ndn->bv_val, 0, 0 );
524 #else
525                                 Debug( LDAP_DEBUG_TRACE,
526                                         "bdb_modrdn: newSup(ndn=%s) not here!\n",
527                                         np_ndn->bv_val, 0, 0);
528 #endif
529                                 rs->sr_text = "new superior not found";
530                                 rs->sr_err = LDAP_OTHER;
531                                 goto return_results;
532                         }
533
534 #ifdef NEW_LOGGING
535                         LDAP_LOG ( OPERATION, DETAIL1, 
536                                 "==>bdb_modrdn: wr to new parent OK np=%p, id=%ld\n", 
537                                 (void *) np, (long) np->e_id, 0 );
538 #else
539                         Debug( LDAP_DEBUG_TRACE,
540                                 "bdb_modrdn: wr to new parent OK np=%p, id=%ld\n",
541                                 (void *) np, (long) np->e_id, 0 );
542 #endif
543
544                         /* check newSuperior for "children" acl */
545                         rs->sr_err = access_allowed( op, np, children,
546                                 NULL, ACL_WRITE, NULL );
547
548                         if( ! rs->sr_err ) {
549                                 switch( opinfo.boi_err ) {
550                                 case DB_LOCK_DEADLOCK:
551                                 case DB_LOCK_NOTGRANTED:
552                                         goto retry;
553                                 }
554
555 #ifdef NEW_LOGGING
556                                 LDAP_LOG ( OPERATION, DETAIL1, 
557                                         "==>bdb_modrdn: no wr to newSup children\n", 0, 0, 0 );
558 #else
559                                 Debug( LDAP_DEBUG_TRACE,
560                                         "bdb_modrdn: no wr to newSup children\n",
561                                         0, 0, 0 );
562 #endif
563                                 rs->sr_text = "no write access to new superior's children";
564                                 rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
565                                 goto return_results;
566                         }
567
568 #ifdef BDB_ALIASES
569                         if ( is_entry_alias( np ) ) {
570                                 /* parent is an alias, don't allow add */
571 #ifdef NEW_LOGGING
572                                 LDAP_LOG ( OPERATION, DETAIL1, 
573                                         "==>bdb_modrdn: entry is alias\n", 0, 0, 0 );
574 #else
575                                 Debug( LDAP_DEBUG_TRACE, "bdb_modrdn: entry is alias\n",
576                                         0, 0, 0 );
577 #endif
578                                 rs->sr_text = "new superior is an alias";
579                                 rs->sr_err = LDAP_ALIAS_PROBLEM;
580                                 goto return_results;
581                         }
582 #endif
583
584                         if ( is_entry_referral( np ) ) {
585                                 /* parent is a referral, don't allow add */
586 #ifdef NEW_LOGGING
587                                 LDAP_LOG ( OPERATION, DETAIL1, 
588                                         "==>bdb_modrdn: entry is referral\n", 0, 0, 0 );
589 #else
590                                 Debug( LDAP_DEBUG_TRACE, "bdb_modrdn: entry is referral\n",
591                                         0, 0, 0 );
592 #endif
593                                 rs->sr_text = "new superior is a referral";
594                                 rs->sr_err = LDAP_OTHER;
595                                 goto return_results;
596                         }
597
598                 } else {
599                         if ( isroot == -1 ) {
600                                 isroot = be_isroot( op->o_bd, &op->o_ndn );
601                         }
602                         
603                         np_dn = NULL;
604
605                         /* no parent, modrdn entry directly under root */
606                         if ( ! isroot ) {
607                                 if ( be_issuffix( op->o_bd, (struct berval *)&slap_empty_bv )
608                                         || be_isupdate( op->o_bd, &op->o_ndn ) ) {
609                                         np = (Entry *)&slap_entry_root;
610
611                                         /* check parent for "children" acl */
612                                         rs->sr_err = access_allowed( op, np,
613                                                 children, NULL, ACL_WRITE, NULL );
614
615                                         np = NULL;
616
617                                         if ( ! rs->sr_err ) {
618                                                 switch( opinfo.boi_err ) {
619                                                 case DB_LOCK_DEADLOCK:
620                                                 case DB_LOCK_NOTGRANTED:
621                                                         goto retry;
622                                                 }
623
624                                                 rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
625 #ifdef NEW_LOGGING
626                                                 LDAP_LOG ( OPERATION, ERR, 
627                                                         "==>bdb_modrdn: no access to superior\n", 0, 0, 0 );
628 #else
629                                                 Debug( LDAP_DEBUG_TRACE, 
630                                                         "no access to new superior\n", 
631                                                         0, 0, 0 );
632 #endif
633                                                 rs->sr_text = "no write access to new superior's children";
634                                                 goto return_results;
635                                         }
636
637 #ifdef NEW_LOGGING
638                                         LDAP_LOG ( OPERATION, DETAIL1, 
639                                                 "bdb_modrdn: wr to children entry \"\" OK\n", 0, 0, 0 );
640 #else
641                                         Debug( LDAP_DEBUG_TRACE,
642                                                 "bdb_modrdn: wr to children of entry \"\" OK\n",
643                                                 0, 0, 0 );
644 #endif
645                 
646                                 } else {
647 #ifdef NEW_LOGGING
648                                         LDAP_LOG ( OPERATION, ERR, 
649                                                 "bdb_modrdn: new superior=\"\", not root & \"\" "
650                                                 "is not suffix\n", 0, 0, 0 );
651 #else
652                                         Debug( LDAP_DEBUG_TRACE,
653                                                 "bdb_modrdn: new superior=\"\", not root "
654                                                 "& \"\" is not suffix\n",
655                                                 0, 0, 0);
656 #endif
657                                         rs->sr_text = "no write access to new superior's children";
658                                         rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
659                                         goto return_results;
660                                 }
661                         }
662
663 #ifdef NEW_LOGGING
664                         LDAP_LOG ( OPERATION, DETAIL1, 
665                                 "bdb_modrdn: new superior=\"\"\n", 0, 0, 0 );
666 #else
667                         Debug( LDAP_DEBUG_TRACE,
668                                 "bdb_modrdn: new superior=\"\"\n",
669                                 0, 0, 0 );
670 #endif
671                 }
672
673 #ifdef NEW_LOGGING
674                 LDAP_LOG ( OPERATION, DETAIL1, 
675                         "bdb_modrdn: wr to new parent's children OK\n", 0, 0, 0 );
676 #else
677                 Debug( LDAP_DEBUG_TRACE,
678                         "bdb_modrdn: wr to new parent's children OK\n",
679                         0, 0, 0 );
680 #endif
681
682                 new_parent_dn = np_dn;
683         }
684
685         /* Build target dn and make sure target entry doesn't exist already. */
686         if (!new_dn.bv_val) build_new_dn( &new_dn, new_parent_dn, &op->oq_modrdn.rs_newrdn, NULL ); 
687
688         if (!new_ndn.bv_val) {
689                 struct berval bv = {0, NULL};
690                 dnNormalize( 0, NULL, NULL, &new_dn, &bv, op->o_tmpmemctx );
691                 ber_dupbv( &new_ndn, &bv );
692         }
693
694 #ifdef NEW_LOGGING
695         LDAP_LOG ( OPERATION, RESULTS, 
696                 "bdb_modrdn: new ndn=%s\n", new_ndn.bv_val, 0, 0 );
697 #else
698         Debug( LDAP_DEBUG_TRACE, "bdb_modrdn: new ndn=%s\n",
699                 new_ndn.bv_val, 0, 0 );
700 #endif
701
702
703         /* Shortcut the search */
704         nei = neip ? neip : eip;
705         rs->sr_err = bdb_cache_find_ndn ( op, ltid, &new_ndn, &nei );
706         if ( nei ) bdb_cache_entryinfo_unlock( nei );
707         switch( rs->sr_err ) {
708         case DB_LOCK_DEADLOCK:
709         case DB_LOCK_NOTGRANTED:
710                 goto retry;
711         case DB_NOTFOUND:
712                 break;
713         case 0:
714                 rs->sr_err = LDAP_ALREADY_EXISTS;
715                 goto return_results;
716         default:
717                 rs->sr_err = LDAP_OTHER;
718                 rs->sr_text = "internal error";
719                 goto return_results;
720         }
721
722         /* Get attribute type and attribute value of our new rdn, we will
723          * need to add that to our new entry
724          */
725         if ( !new_rdn && ldap_bv2rdn_x( &op->oq_modrdn.rs_newrdn, &new_rdn, (char **)&rs->sr_text,
726                 LDAP_DN_FORMAT_LDAP, op->o_tmpmemctx ) )
727         {
728 #ifdef NEW_LOGGING
729                 LDAP_LOG ( OPERATION, ERR, 
730                         "bdb_modrdn: can't figure out "
731                         "type(s)/values(s) of newrdn\n", 
732                         0, 0, 0 );
733 #else
734                 Debug( LDAP_DEBUG_TRACE,
735                         "bdb_modrdn: can't figure out "
736                         "type(s)/values(s) of newrdn\n", 
737                         0, 0, 0 );
738 #endif
739                 rs->sr_err = LDAP_INVALID_DN_SYNTAX;
740                 rs->sr_text = "unknown type(s) used in RDN";
741                 goto return_results;
742         }
743
744 #ifdef NEW_LOGGING
745         LDAP_LOG ( OPERATION, RESULTS, 
746                 "bdb_modrdn: new_rdn_type=\"%s\", "
747                 "new_rdn_val=\"%s\"\n",
748                 new_rdn[ 0 ]->la_attr.bv_val, 
749                 new_rdn[ 0 ]->la_value.bv_val, 0 );
750 #else
751         Debug( LDAP_DEBUG_TRACE,
752                 "bdb_modrdn: new_rdn_type=\"%s\", "
753                 "new_rdn_val=\"%s\"\n",
754                 new_rdn[ 0 ]->la_attr.bv_val,
755                 new_rdn[ 0 ]->la_value.bv_val, 0 );
756 #endif
757
758         if ( op->oq_modrdn.rs_deleteoldrdn ) {
759                 if ( !old_rdn && ldap_bv2rdn_x( &op->o_req_dn, &old_rdn, (char **)&rs->sr_text,
760                         LDAP_DN_FORMAT_LDAP, op->o_tmpmemctx ) )
761                 {
762 #ifdef NEW_LOGGING
763                         LDAP_LOG ( OPERATION, ERR, 
764                                 "bdb_modrdn: can't figure out "
765                                 "type(s)/values(s) of old_rdn\n", 
766                                 0, 0, 0 );
767 #else
768                         Debug( LDAP_DEBUG_TRACE,
769                                 "bdb_modrdn: can't figure out "
770                                 "the old_rdn type(s)/value(s)\n", 
771                                 0, 0, 0 );
772 #endif
773                         rs->sr_err = LDAP_OTHER;
774                         rs->sr_text = "cannot parse RDN from old DN";
775                         goto return_results;            
776                 }
777         }
778
779         /* prepare modlist of modifications from old/new rdn */
780         if (!mod) {
781                 rs->sr_err = slap_modrdn2mods( op, rs, e, old_rdn, new_rdn, &mod );
782                 if ( rs->sr_err != LDAP_SUCCESS ) {
783                         goto return_results;
784                 }
785         }
786
787         if( op->o_preread ) {
788                 if( slap_read_controls( op, rs, e,
789                         &slap_pre_read_bv, &ctrls[num_ctrls] ) )
790                 {
791 #ifdef NEW_LOGGING                                   
792                         LDAP_LOG ( OPERATION, DETAIL1,
793                                 "<=- bdb_modrdn: post-read failed!\n", 0, 0, 0 );
794 #else
795                         Debug( LDAP_DEBUG_TRACE,        
796                                 "<=- bdb_modrdn: post-read failed!\n", 0, 0, 0 );
797 #endif
798                         goto return_results;
799                 }                   
800                 ctrls[++num_ctrls] = NULL;
801                 op->o_preread = 0;  /* prevent redo on retry */
802         }
803
804         /* nested transaction */
805         rs->sr_err = TXN_BEGIN( bdb->bi_dbenv, ltid, &lt2, 
806                 bdb->bi_db_opflags );
807         rs->sr_text = NULL;
808         if( rs->sr_err != 0 ) {
809 #ifdef NEW_LOGGING
810                 LDAP_LOG ( OPERATION, ERR, 
811                         "bdb_modrdn: txn_begin(2) failed: %s (%d)\n", db_strerror(rs->sr_err), rs->sr_err, 0 );
812 #else
813                 Debug( LDAP_DEBUG_TRACE,
814                         "bdb_modrdn: txn_begin(2) failed: %s (%d)\n",
815                         db_strerror(rs->sr_err), rs->sr_err, 0 );
816 #endif
817                 rs->sr_err = LDAP_OTHER;
818                 rs->sr_text = "internal error";
819                 goto return_results;
820         }
821
822         dummy = *e;
823         save = e;
824         e = &dummy;
825
826         /* delete old one */
827         rs->sr_err = bdb_dn2id_delete( op, lt2, eip, e );
828         if ( rs->sr_err != 0 ) {
829 #ifdef NEW_LOGGING
830                 LDAP_LOG ( OPERATION, ERR, 
831                         "<=- bdb_modrdn: dn2id del failed: %s (%d)\n",
832                         db_strerror(rs->sr_err), rs->sr_err, 0 );
833 #else
834                 Debug(LDAP_DEBUG_TRACE,
835                         "<=- bdb_modrdn: dn2id del failed: %s (%d)\n",
836                         db_strerror(rs->sr_err), rs->sr_err, 0 );
837 #endif
838                 switch( rs->sr_err ) {
839                 case DB_LOCK_DEADLOCK:
840                 case DB_LOCK_NOTGRANTED:
841                         goto retry;
842                 }
843                 rs->sr_err = LDAP_OTHER;
844                 rs->sr_text = "DN index delete fail";
845                 goto return_results;
846         }
847
848         /* Binary format uses a single contiguous block, cannot
849          * free individual fields. But if a previous modrdn has
850          * already happened, must free the names. The frees are
851          * done in bdb_cache_modrdn().
852          */
853         if( e->e_nname.bv_val < e->e_bv.bv_val || e->e_nname.bv_val >
854                 e->e_bv.bv_val + e->e_bv.bv_len ) {
855                 e->e_name.bv_val = NULL;
856                 e->e_nname.bv_val = NULL;
857         }
858         e->e_name = new_dn;
859         e->e_nname = new_ndn;
860         new_dn.bv_val = NULL;
861         new_ndn.bv_val = NULL;
862
863         /* add new one */
864         rs->sr_err = bdb_dn2id_add( op, lt2, neip ? neip : eip, e );
865         if ( rs->sr_err != 0 ) {
866 #ifdef NEW_LOGGING
867                 LDAP_LOG ( OPERATION, ERR, 
868                         "<=- bdb_modrdn: dn2id add failed: %s (%d)\n",
869                         db_strerror(rs->sr_err), rs->sr_err, 0 );
870 #else
871                 Debug(LDAP_DEBUG_TRACE,
872                         "<=- bdb_modrdn: dn2id add failed: %s (%d)\n",
873                         db_strerror(rs->sr_err), rs->sr_err, 0 );
874 #endif
875                 switch( rs->sr_err ) {
876                 case DB_LOCK_DEADLOCK:
877                 case DB_LOCK_NOTGRANTED:
878                         goto retry;
879                 }
880                 rs->sr_err = LDAP_OTHER;
881                 rs->sr_text = "DN index add failed";
882                 goto return_results;
883         }
884
885         if ( rs->sr_err == LDAP_SUCCESS && !op->o_noop && !op->o_no_psearch ) {
886                 ldap_pvt_thread_rdwr_rlock( &bdb->bi_pslist_rwlock );
887                 LDAP_LIST_FOREACH ( ps_list, &bdb->bi_psearch_list, o_ps_link ) {
888                         bdb_psearch( op, rs, ps_list, e, LDAP_PSEARCH_BY_PREMODIFY );
889                 }
890                 ldap_pvt_thread_rdwr_runlock( &bdb->bi_pslist_rwlock );
891         }
892
893         /* modify entry */
894         rs->sr_err = bdb_modify_internal( op, lt2, &mod[0], e,
895                 &rs->sr_text, textbuf, textlen );
896
897         if( rs->sr_err != LDAP_SUCCESS ) {
898 #ifdef NEW_LOGGING
899                 LDAP_LOG ( OPERATION, ERR, 
900                         "<=- bdb_modrdn: modify failed: %s (%d)\n",
901                         db_strerror(rs->sr_err), rs->sr_err, 0 );
902 #else
903                 Debug(LDAP_DEBUG_TRACE,
904                         "<=- bdb_modrdn: modify failed: %s (%d)\n",
905                         db_strerror(rs->sr_err), rs->sr_err, 0 );
906 #endif
907                 if ( ( rs->sr_err == LDAP_INSUFFICIENT_ACCESS ) && opinfo.boi_err ) {
908                         rs->sr_err = opinfo.boi_err;
909                 }
910                 switch( rs->sr_err ) {
911                 case DB_LOCK_DEADLOCK:
912                 case DB_LOCK_NOTGRANTED:
913                         goto retry;
914                 }
915                 goto return_results;
916         }
917
918         if( op->o_postread ) {
919                 if( slap_read_controls( op, rs, e,
920                         &slap_post_read_bv, &ctrls[num_ctrls] ) )
921                 {
922 #ifdef NEW_LOGGING                                   
923                         LDAP_LOG ( OPERATION, DETAIL1,
924                                 "<=- bdb_modrdn: post-read failed!\n", 0, 0, 0 );
925 #else
926                         Debug( LDAP_DEBUG_TRACE,        
927                                 "<=- bdb_modrdn: post-read failed!\n", 0, 0, 0 );
928 #endif
929                         goto return_results;
930                 }                   
931                 ctrls[++num_ctrls] = NULL;
932                 op->o_postread = 0;  /* prevent redo on retry */
933                 /* FIXME: should read entry on the last retry */
934         }
935
936         /* id2entry index */
937         rs->sr_err = bdb_id2entry_update( op->o_bd, lt2, e );
938         if ( rs->sr_err != 0 ) {
939 #ifdef NEW_LOGGING
940                 LDAP_LOG ( OPERATION, ERR, 
941                         "<=- bdb_modrdn: id2entry failed: %s (%d)\n",
942                         db_strerror(rs->sr_err), rs->sr_err, 0 );
943 #else
944                 Debug(LDAP_DEBUG_TRACE,
945                         "<=- bdb_modrdn: id2entry failed: %s (%d)\n",
946                         db_strerror(rs->sr_err), rs->sr_err, 0 );
947 #endif
948                 switch( rs->sr_err ) {
949                 case DB_LOCK_DEADLOCK:
950                 case DB_LOCK_NOTGRANTED:
951                         goto retry;
952                 }
953                 rs->sr_err = LDAP_OTHER;
954                 rs->sr_text = "entry update failed";
955                 goto return_results;
956         }
957         if ( TXN_COMMIT( lt2, 0 ) != 0 ) {
958                 rs->sr_err = LDAP_OTHER;
959                 rs->sr_text = "txn_commit(2) failed";
960                 goto return_results;
961         }
962
963         if ( LDAP_STAILQ_EMPTY( &op->o_bd->be_syncinfo )) {
964                 rc = bdb_csn_commit( op, rs, ltid, ei, &suffix_ei,
965                         &ctxcsn_e, &ctxcsn_added, locker );
966                 switch ( rc ) {
967                 case BDB_CSN_ABORT :
968                         goto return_results;
969                 case BDB_CSN_RETRY :
970                         goto retry;
971                 }
972         }
973
974         if( op->o_noop ) {
975                 if(( rs->sr_err=TXN_ABORT( ltid )) != 0 ) {
976                         rs->sr_text = "txn_abort (no-op) failed";
977                 } else {
978                         noop = 1;
979                         rs->sr_err = LDAP_SUCCESS;
980                 }
981
982         } else {
983                 bdb_cache_modrdn( save, &op->orr_nnewrdn, e, neip,
984                         bdb->bi_dbenv, locker, &lock );
985
986                 if ( LDAP_STAILQ_EMPTY( &op->o_bd->be_syncinfo )) {
987                         if ( ctxcsn_added ) {
988                                 bdb_cache_add( bdb, suffix_ei, ctxcsn_e,
989                                         (struct berval *)&slap_ldapsync_cn_bv, locker );
990                         }
991                 }
992
993                 if ( rs->sr_err == LDAP_SUCCESS && !op->o_noop ) {
994                         /* Loop through in-scope entries for each psearch spec */
995                         ldap_pvt_thread_rdwr_rlock( &bdb->bi_pslist_rwlock );
996                         LDAP_LIST_FOREACH ( ps_list, &bdb->bi_psearch_list, o_ps_link ) {
997                                 bdb_psearch( op, rs, ps_list, e, LDAP_PSEARCH_BY_MODIFY );
998                         }
999                         ldap_pvt_thread_rdwr_runlock( &bdb->bi_pslist_rwlock );
1000                         pm_list = LDAP_LIST_FIRST(&op->o_pm_list);
1001                         while ( pm_list != NULL ) {
1002                                 bdb_psearch(op, rs, pm_list->ps_op,
1003                                                         e, LDAP_PSEARCH_BY_SCOPEOUT);
1004                                 pm_prev = pm_list;
1005                                 LDAP_LIST_REMOVE ( pm_list, ps_link );
1006                                 pm_list = LDAP_LIST_NEXT ( pm_list, ps_link );
1007                                 ch_free( pm_prev );
1008                         }
1009                 }
1010
1011                 if(( rs->sr_err=TXN_COMMIT( ltid, 0 )) != 0 ) {
1012                         rs->sr_text = "txn_commit failed";
1013                 } else {
1014                         rs->sr_err = LDAP_SUCCESS;
1015                 }
1016         }
1017  
1018         ltid = NULL;
1019         op->o_private = NULL;
1020  
1021         if( rs->sr_err != LDAP_SUCCESS ) {
1022 #ifdef NEW_LOGGING
1023                 LDAP_LOG ( OPERATION, RESULTS, "bdb_modrdn: %s : %s (%d)\n", 
1024                         rs->sr_text, db_strerror(rs->sr_err), rs->sr_err );
1025 #else
1026                 Debug( LDAP_DEBUG_TRACE, "bdb_add: %s : %s (%d)\n",
1027                         rs->sr_text, db_strerror(rs->sr_err), rs->sr_err );
1028 #endif
1029                 rs->sr_err = LDAP_OTHER;
1030
1031                 goto return_results;
1032         }
1033
1034 #ifdef NEW_LOGGING
1035         LDAP_LOG ( OPERATION, RESULTS, 
1036                 "bdb_modrdn: rdn modified%s id=%08lx dn=\"%s\"\n", 
1037                 op->o_noop ? " (no-op)" : "", e->e_id, e->e_dn );
1038 #else
1039         Debug(LDAP_DEBUG_TRACE,
1040                 "bdb_modrdn: rdn modified%s id=%08lx dn=\"%s\"\n",
1041                 op->o_noop ? " (no-op)" : "", e->e_id, e->e_dn );
1042 #endif
1043         rs->sr_text = NULL;
1044         if( num_ctrls ) rs->sr_ctrls = ctrls;
1045
1046 return_results:
1047         send_ldap_result( op, rs );
1048
1049         if( rs->sr_err == LDAP_SUCCESS && bdb->bi_txn_cp ) {
1050                 ldap_pvt_thread_yield();
1051                 TXN_CHECKPOINT( bdb->bi_dbenv,
1052                         bdb->bi_txn_cp_kbyte, bdb->bi_txn_cp_min, 0 );
1053         }
1054
1055 done:
1056         if( new_dn.bv_val != NULL ) free( new_dn.bv_val );
1057         if( new_ndn.bv_val != NULL ) free( new_ndn.bv_val );
1058
1059         /* LDAP v2 supporting correct attribute handling. */
1060         if ( new_rdn != NULL ) {
1061                 ldap_rdnfree_x( new_rdn, op->o_tmpmemctx );
1062         }
1063         if ( old_rdn != NULL ) {
1064                 ldap_rdnfree_x( old_rdn, op->o_tmpmemctx );
1065         }
1066         if( mod != NULL ) {
1067                 Modifications *tmp;
1068                 for (; mod; mod=tmp ) {
1069                         tmp = mod->sml_next;
1070                         /* slap_modrdn2mods does things one way,
1071                          * slap_mods_opattrs does it differently
1072                          */
1073                         if ( mod->sml_op != SLAP_MOD_SOFTADD &&
1074                                 mod->sml_op != LDAP_MOD_DELETE ) break;
1075                         if ( mod->sml_nvalues ) free( mod->sml_nvalues[0].bv_val );
1076                         free( mod );
1077                 }
1078                 slap_mods_free( mod );
1079         }
1080
1081         /* LDAP v3 Support */
1082         if( np != NULL ) {
1083                 /* free new parent and reader lock */
1084                 bdb_unlocked_cache_return_entry_r(&bdb->bi_cache, np);
1085         }
1086
1087         if( p != NULL ) {
1088                 /* free parent and reader lock */
1089                 bdb_unlocked_cache_return_entry_r(&bdb->bi_cache, p);
1090         }
1091
1092         /* free entry */
1093         if( e != NULL ) {
1094                 bdb_unlocked_cache_return_entry_w( &bdb->bi_cache, e);
1095         }
1096
1097         if( ltid != NULL ) {
1098                 pm_list = LDAP_LIST_FIRST(&op->o_pm_list);
1099                 while ( pm_list != NULL ) {
1100                         LDAP_LIST_REMOVE ( pm_list, ps_link );
1101                         pm_prev = pm_list;
1102                         pm_list = LDAP_LIST_NEXT ( pm_list, ps_link );
1103                         ch_free( pm_prev );
1104                 }
1105                 TXN_ABORT( ltid );
1106                 op->o_private = NULL;
1107         }
1108
1109         return ( ( rs->sr_err == LDAP_SUCCESS ) ? noop : rs->sr_err );
1110 }