2 * Copyright 1998-2002 The OpenLDAP Foundation, All Rights Reserved.
3 * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
5 * Copyright 2001, Pierangelo Masarati, All rights reserved. <ando@sys-net.it>
7 * This work has been developed to fulfill the requirements
8 * of SysNet s.n.c. <http:www.sys-net.it> and it has been donated
9 * to the OpenLDAP Foundation in the hope that it may be useful
10 * to the Open Source community, but WITHOUT ANY WARRANTY.
12 * Permission is granted to anyone to use this software for any purpose
13 * on any computer system, and to alter it and redistribute it, subject
14 * to the following restrictions:
16 * 1. The author and SysNet s.n.c. are not responsible for the consequences
17 * of use of this software, no matter how awful, even if they arise from
20 * 2. The origin of this software must not be misrepresented, either by
21 * explicit claim or by omission. Since few users ever read sources,
22 * credits should appear in the documentation.
24 * 3. Altered versions must be plainly marked as such, and must not be
25 * misrepresented as being the original software. Since few users
26 * ever read sources, credits should appear in the documentation.
27 * SysNet s.n.c. cannot be responsible for the consequences of the
30 * 4. This notice may not be removed or altered.
33 * This software is based on the backend back-ldap, implemented
34 * by Howard Chu <hyc@highlandsun.com>, and modified by Mark Valence
35 * <kurash@sassafras.com>, Pierangelo Masarati <ando@sys-net.it> and other
36 * contributors. The contribution of the original software to the present
37 * implementation is acknowledged in this copyright statement.
39 * A special acknowledgement goes to Howard for the overall architecture
40 * (and for borrowing large pieces of code), and to Mark, who implemented
41 * from scratch the attribute/objectclass mapping.
43 * The original copyright statement follows.
45 * Copyright 1999, Howard Chu, All rights reserved. <hyc@highlandsun.com>
47 * Permission is granted to anyone to use this software for any purpose
48 * on any computer system, and to alter it and redistribute it, subject
49 * to the following restrictions:
51 * 1. The author is not responsible for the consequences of use of this
52 * software, no matter how awful, even if they arise from flaws in it.
54 * 2. The origin of this software must not be misrepresented, either by
55 * explicit claim or by omission. Since few users ever read sources,
56 * credits should appear in the documentation.
58 * 3. Altered versions must be plainly marked as such, and must not be
59 * misrepresented as being the original software. Since few users
60 * ever read sources, credits should appear in the
63 * 4. This notice may not be removed or altered.
71 #include <ac/socket.h>
72 #include <ac/string.h>
77 #include "../back-ldap/back-ldap.h"
78 #include "back-meta.h"
81 * Set PRINT_CONNTREE larger than 0 to dump the connection tree (debug only)
83 #define PRINT_CONNTREE 0
88 * compares two struct metaconn based on the value of the conn pointer;
97 struct metaconn *lc1 = ( struct metaconn * )c1;
98 struct metaconn *lc2 = ( struct metaconn * )c2;
100 return ( ( lc1->conn < lc2->conn ) ? -1 :
101 ( ( lc1->conn > lc2-> conn ) ? 1 : 0 ) );
107 * returns -1 in case a duplicate struct metaconn has been inserted;
116 struct metaconn *lc1 = ( struct metaconn * )c1;
117 struct metaconn *lc2 = ( struct metaconn * )c2;
119 return( ( lc1->conn == lc2->conn ) ? -1 : 0 );
123 * Debug stuff (got it from libavl)
125 #if PRINT_CONNTREE > 0
127 ravl_print( Avlnode *root, int depth )
135 ravl_print( root->avl_right, depth+1 );
137 for ( i = 0; i < depth; i++ ) {
141 printf( "c(%d) %d\n", ( ( struct metaconn * )root->avl_data )->conn->c_connid, root->avl_bf );
143 ravl_print( root->avl_left, depth+1 );
147 myprint( Avlnode *root )
149 printf( "********\n" );
152 printf( "\tNULL\n" );
154 ravl_print( root, 0 );
157 printf( "********\n" );
159 #endif /* PRINT_CONNTREE */
167 * Allocates a connection structure, making room for all the referenced targets
169 static struct metaconn *
170 metaconn_alloc( int ntargets )
175 assert( ntargets > 0 );
177 lc = ch_calloc( sizeof( struct metaconn ), 1 );
183 * make it a null-terminated array ...
185 lc->conns = ch_calloc( sizeof( struct metasingleconn * ), ntargets+1 );
186 if ( lc->conns == NULL ) {
191 for ( i = 0; i < ntargets; i++ ) {
193 ch_calloc( sizeof( struct metasingleconn ), 1 );
194 if ( lc->conns[ i ] == NULL ) {
195 charray_free( ( char ** )lc->conns );
202 lc->bound_target = META_BOUND_NONE;
224 for ( i = 0; lc->conns[ i ] != NULL; ++i ) {
225 free( lc->conns[ i ] );
227 charray_free( ( char ** )lc->conns );
236 * Initializes one connection
242 struct metatarget *lt,
244 struct metasingleconn *lsc
252 if ( lsc->ld != NULL ) {
257 * Attempts to initialize the connection to the target ds
259 err = ldap_initialize( &lsc->ld, lt->uri );
260 if ( err != LDAP_SUCCESS ) {
261 return ldap_back_map_result( err );
265 * Set LDAP version. This will always succeed: If the client
266 * bound with a particular version, then so can we.
268 ldap_set_option( lsc->ld, LDAP_OPT_PROTOCOL_VERSION, &vers );
271 * Sets a cookie for the rewrite session
273 ( void )rewrite_session_init( lt->rwinfo, conn );
276 * If the connection dn is not null, an attempt to rewrite it is made
278 if ( conn->c_cdn.bv_len != 0 ) {
281 * Rewrite the bind dn if needed
283 lsc->bound_dn.bv_val = NULL;
284 switch ( rewrite_session( lt->rwinfo, "bindDn",
285 conn->c_cdn.bv_val, conn,
286 &lsc->bound_dn.bv_val ) ) {
287 case REWRITE_REGEXEC_OK:
288 if ( lsc->bound_dn.bv_val == NULL ) {
289 ber_dupbv( &lsc->bound_dn, &conn->c_cdn );
292 LDAP_LOG(( "backend", LDAP_LEVEL_DETAIL1,
293 "[rw] bindDn: \"%s\" -> \"%s\"\n",
294 conn->c_cdn.bv_val, lsc->bound_dn.bv_val ));
295 #else /* !NEW_LOGGING */
296 Debug( LDAP_DEBUG_ARGS,
297 "rw> bindDn: \"%s\" -> \"%s\"\n",
298 conn->c_cdn.bv_val, lsc->bound_dn.bv_val, 0 );
299 #endif /* !NEW_LOGGING */
302 case REWRITE_REGEXEC_UNWILLING:
303 send_ldap_result( conn, op,
304 LDAP_UNWILLING_TO_PERFORM,
305 NULL, "Unwilling to perform",
307 return LDAP_UNWILLING_TO_PERFORM;
309 case REWRITE_REGEXEC_ERR:
310 send_ldap_result( conn, op,
311 LDAP_OPERATIONS_ERROR,
312 NULL, "Operations error",
314 return LDAP_OPERATIONS_ERROR;
317 assert( lsc->bound_dn.bv_val );
320 ber_str2bv( "", 0, 1, &lsc->bound_dn );
323 lsc->bound = META_UNBOUND;
326 * The candidate is activated
328 lsc->candidate = META_CANDIDATE;
335 * Prepares the connection structure
337 * FIXME: This function needs to receive some info on the type of operation
338 * it is invoked by, so that only the correct pool of candidate targets
339 * is initialized in case no connection was available yet.
341 * At present a flag that says whether the candidate target must be unique
342 * is passed; eventually an operation agent will be used.
353 struct metaconn *lc, lc_curr;
354 int vers, cached = -1, i = -1, err = LDAP_SUCCESS;
357 /* Searches for a metaconn in the avl tree */
359 ldap_pvt_thread_mutex_lock( &li->conn_mutex );
360 lc = (struct metaconn *)avl_find( li->conntree,
361 (caddr_t)&lc_curr, meta_back_conn_cmp );
362 ldap_pvt_thread_mutex_unlock( &li->conn_mutex );
364 /* Looks like we didn't get a bind. Open a new session... */
366 lc = metaconn_alloc( li->ntargets );
371 vers = conn->c_protocol;
374 * looks in cache, if any
376 if ( li->cache.ttl != META_DNCACHE_DISABLED ) {
377 cached = i = meta_dncache_get_target( &li->cache, ndn );
380 if ( op_type == META_OP_REQUIRE_SINGLE ) {
383 * tries to get a unique candidate
384 * (takes care of default target
387 i = meta_back_select_unique_candidate( li, ndn );
391 * if any is found, inits the connection
398 send_ldap_result( conn, op, LDAP_NO_SUCH_OBJECT,
399 NULL, "", NULL, NULL );
405 LDAP_LOG(( "backend", LDAP_LEVEL_INFO,
406 "meta_back_getconn: got target %d"
407 " for ndn=\"%s\" from cache\n",
409 #else /* !NEW_LOGGING */
410 Debug( LDAP_DEBUG_CACHE,
411 "==>meta_back_getconn: got target %d for ndn=\"%s\" from cache\n%s",
412 i, ndn->bv_val, "" );
413 #endif /* !NEW_LOGGING */
416 * Clear all other candidates
418 ( void )meta_clear_unused_candidates( li, lc, i, 0 );
421 * The target is activated; if needed, it is
422 * also init'd. In case of error, init_one_conn
423 * sends the appropriate result.
425 err = init_one_conn( conn, op, li->targets[ i ],
426 vers, lc->conns[ i ] );
427 if ( err != LDAP_SUCCESS ) {
430 * FIXME: in case one target cannot
431 * be init'd, should the other ones
434 ( void )meta_clear_one_candidate( lc->conns[ i ], 1 );
446 * require all connections ...
448 } else if (op_type == META_OP_REQUIRE_ALL) {
449 for ( i = 0; i < li->ntargets; i++ ) {
452 * The target is activated; if needed, it is
455 int lerr = init_one_conn( conn, op, li->targets[ i ],
456 vers, lc->conns[ i ] );
457 if ( lerr != LDAP_SUCCESS ) {
460 * FIXME: in case one target cannot
461 * be init'd, should the other ones
464 ( void )meta_clear_one_candidate( lc->conns[ i ], 1 );
471 * if no unique candidate ...
474 for ( i = 0; i < li->ntargets; i++ ) {
476 || meta_back_is_candidate( &li->targets[ i ]->suffix, ndn ) ) {
479 * The target is activated; if needed, it is
482 int lerr = init_one_conn( conn, op,
484 vers, lc->conns[ i ] );
485 if ( lerr != LDAP_SUCCESS ) {
488 * FIXME: in case one target cannot
489 * be init'd, should the other ones
492 ( void )meta_clear_one_candidate( lc->conns[ i ], 1 );
503 * Inserts the newly created metaconn in the avl tree
505 ldap_pvt_thread_mutex_lock( &li->conn_mutex );
506 err = avl_insert( &li->conntree, ( caddr_t )lc,
507 meta_back_conn_cmp, meta_back_conn_dup );
509 #if PRINT_CONNTREE > 0
510 myprint( li->conntree );
511 #endif /* PRINT_CONNTREE */
513 ldap_pvt_thread_mutex_unlock( &li->conn_mutex );
516 LDAP_LOG(( "backend", LDAP_LEVEL_INFO,
517 "meta_back_getconn: conn %ld inserted\n",
518 lc->conn->c_connid ));
519 #else /* !NEW_LOGGING */
520 Debug( LDAP_DEBUG_TRACE,
521 "=>meta_back_getconn: conn %ld inserted\n%s%s",
522 lc->conn->c_connid, "", "" );
523 #endif /* !NEW_LOGGING */
526 * Err could be -1 in case a duplicate metaconn is inserted
529 send_ldap_result( conn, op, LDAP_OPERATIONS_ERROR,
530 NULL, "Internal server error", NULL, NULL );
536 LDAP_LOG(( "backend", LDAP_LEVEL_INFO,
537 "meta_back_getconn: conn %ld fetched\n",
538 lc->conn->c_connid ));
539 #else /* !NEW_LOGGING */
540 Debug( LDAP_DEBUG_TRACE,
541 "=>meta_back_getconn: conn %ld fetched\n%s%s",
542 lc->conn->c_connid, "", "" );
543 #endif /* !NEW_LOGGING */