1 /* filter.c - routines for parsing and dealing with filters */
4 * Copyright 1998-2000 The OpenLDAP Foundation, All Rights Reserved.
5 * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
12 #include <ac/socket.h>
13 #include <ac/string.h>
17 static int get_filter_list(
24 static int get_substring_filter(
45 Debug( LDAP_DEBUG_FILTER, "begin get_filter\n", 0, 0, 0 );
48 * A filter looks like this coming in:
50 * and [0] SET OF Filter,
51 * or [1] SET OF Filter,
53 * equalityMatch [3] AttributeValueAssertion,
54 * substrings [4] SubstringFilter,
55 * greaterOrEqual [5] AttributeValueAssertion,
56 * lessOrEqual [6] AttributeValueAssertion,
57 * present [7] AttributeType,,
58 * approxMatch [8] AttributeValueAssertion
59 * extensibleMatch [9] MatchingRuleAssertion
62 * SubstringFilter ::= SEQUENCE {
64 * SEQUENCE OF CHOICE {
65 * initial [0] IA5String,
71 * MatchingRuleAssertion ::= SEQUENCE {
72 * matchingRule [1] MatchingRuleId OPTIONAL,
73 * type [2] AttributeDescription OPTIONAL,
74 * matchValue [3] AssertionValue,
75 * dnAttributes [4] BOOLEAN DEFAULT FALSE
80 tag = ber_peek_tag( ber, &len );
82 if( tag == LBER_ERROR ) {
83 *text = "error decoding filter";
84 return SLAPD_DISCONNECT;
87 f = (Filter *) ch_malloc( sizeof(Filter) );
94 switch ( f->f_choice ) {
95 case LDAP_FILTER_EQUALITY:
96 Debug( LDAP_DEBUG_FILTER, "EQUALITY\n", 0, 0, 0 );
98 #ifdef SLAPD_SCHEMA_NOT_COMPAT
99 err = get_ava( ber, &f->f_ava, SLAP_MR_EQUALITY, text );
101 err = get_ava( ber, &f->f_ava, text );
103 if ( err != LDAP_SUCCESS ) {
107 #ifdef SLAPD_SCHEMA_NOT_COMPAT
108 assert( f->f_ava != NULL );
110 *fstr = ch_malloc( sizeof("(=)")
111 + f->f_av_desc->ad_cname->bv_len
112 + f->f_av_value->bv_len );
114 sprintf( *fstr, "(%s=%s)",
115 f->f_av_desc->ad_cname->bv_val,
116 f->f_av_value->bv_val );
119 *fstr = ch_malloc( sizeof("(=)")
120 + strlen( f->f_avtype )
121 + f->f_avvalue.bv_len);
122 sprintf( *fstr, "(%s=%s)", f->f_avtype,
123 f->f_avvalue.bv_val );
127 case LDAP_FILTER_SUBSTRINGS:
128 Debug( LDAP_DEBUG_FILTER, "SUBSTRINGS\n", 0, 0, 0 );
129 err = get_substring_filter( conn, ber, f, fstr, text );
133 Debug( LDAP_DEBUG_FILTER, "GE\n", 0, 0, 0 );
135 #ifdef SLAPD_SCHEMA_NOT_COMPAT
136 err = get_ava( ber, &f->f_ava, SLAP_MR_ORDERING, text );
138 err = get_ava( ber, &f->f_ava, text );
140 if ( err != LDAP_SUCCESS ) {
144 #ifdef SLAPD_SCHEMA_NOT_COMPAT
145 *fstr = ch_malloc( sizeof("(>=)")
146 + f->f_av_desc->ad_cname->bv_len
147 + f->f_av_value->bv_len );
149 sprintf( *fstr, "(%s>=%s)",
150 f->f_av_desc->ad_cname->bv_val,
151 f->f_av_value->bv_val );
154 *fstr = ch_malloc( sizeof("(>=)")
155 + strlen( f->f_avtype )
156 + f->f_avvalue.bv_len);
157 sprintf( *fstr, "(%s>=%s)", f->f_avtype,
158 f->f_avvalue.bv_val );
163 Debug( LDAP_DEBUG_FILTER, "LE\n", 0, 0, 0 );
165 #ifdef SLAPD_SCHEMA_NOT_COMPAT
166 err = get_ava( ber, &f->f_ava, SLAP_MR_ORDERING, text );
168 err = get_ava( ber, &f->f_ava, text );
170 if ( err != LDAP_SUCCESS ) {
175 #ifdef SLAPD_SCHEMA_NOT_COMPAT
176 *fstr = ch_malloc( sizeof("(<=)")
177 + f->f_av_desc->ad_cname->bv_len
178 + f->f_av_value->bv_len );
180 sprintf( *fstr, "(%s<=%s)",
181 f->f_av_desc->ad_cname->bv_val,
182 f->f_av_value->bv_val );
185 *fstr = ch_malloc( sizeof("(<=)")
186 + strlen( f->f_avtype )
187 + f->f_avvalue.bv_len);
188 sprintf( *fstr, "(%s<=%s)", f->f_avtype,
189 f->f_avvalue.bv_val );
193 case LDAP_FILTER_PRESENT: {
196 Debug( LDAP_DEBUG_FILTER, "PRESENT\n", 0, 0, 0 );
198 if ( ber_scanf( ber, "o", &type ) == LBER_ERROR ) {
199 err = SLAPD_DISCONNECT;
200 *text = "error decoding filter";
204 #ifdef SLAPD_SCHEMA_NOT_COMPAT
206 err = slap_bv2ad( &type, &f->f_desc, text );
208 if( err != LDAP_SUCCESS ) {
209 ch_free( type.bv_val );
213 ch_free( type.bv_val );
215 *fstr = ch_malloc( sizeof("(=*)")
216 + f->f_desc->ad_cname->bv_len );
217 sprintf( *fstr, "(%s=*)",
218 f->f_desc->ad_cname->bv_val );
221 f->f_type = type.bv_val;
223 attr_normalize( f->f_type );
224 *fstr = ch_malloc( sizeof("(=*)")
225 + strlen( f->f_type ) );
226 sprintf( *fstr, "(%s=*)", f->f_type );
230 case LDAP_FILTER_APPROX:
231 Debug( LDAP_DEBUG_FILTER, "APPROX\n", 0, 0, 0 );
233 #ifdef SLAPD_SCHEMA_NOT_COMPAT
234 err = get_ava( ber, &f->f_ava, SLAP_MR_EQUALITY_APPROX, text );
236 err = get_ava( ber, &f->f_ava, text );
238 if ( err != LDAP_SUCCESS ) {
242 #ifdef SLAPD_SCHEMA_NOT_COMPAT
243 *fstr = ch_malloc( sizeof("(~=)")
244 + f->f_av_desc->ad_cname->bv_len
245 + f->f_av_value->bv_len );
247 sprintf( *fstr, "(%s~=%s)",
248 f->f_av_desc->ad_cname->bv_val,
249 f->f_av_value->bv_val );
252 *fstr = ch_malloc( sizeof("(~=)")
253 + strlen( f->f_avtype )
254 + f->f_avvalue.bv_len);
255 sprintf( *fstr, "(%s~=%s)", f->f_avtype,
256 f->f_avvalue.bv_val );
260 case LDAP_FILTER_AND:
261 Debug( LDAP_DEBUG_FILTER, "AND\n", 0, 0, 0 );
262 err = get_filter_list( conn, ber, &f->f_and, &ftmp, text );
263 if ( err != LDAP_SUCCESS ) {
266 *fstr = ch_malloc( sizeof("(&)")
267 + ( ftmp == NULL ? 0 : strlen( ftmp ) ) );
268 sprintf( *fstr, "(&%s)",
269 ftmp == NULL ? "" : ftmp );
273 Debug( LDAP_DEBUG_FILTER, "OR\n", 0, 0, 0 );
274 err = get_filter_list( conn, ber, &f->f_and, &ftmp, text );
275 if ( err != LDAP_SUCCESS ) {
278 *fstr = ch_malloc( sizeof("(!)")
279 + ( ftmp == NULL ? 0 : strlen( ftmp ) ) );
280 sprintf( *fstr, "(|%s)",
281 ftmp == NULL ? "" : ftmp );
284 case LDAP_FILTER_NOT:
285 Debug( LDAP_DEBUG_FILTER, "NOT\n", 0, 0, 0 );
286 (void) ber_skip_tag( ber, &len );
287 err = get_filter( conn, ber, &f->f_not, &ftmp, text );
288 if ( err != LDAP_SUCCESS ) {
291 *fstr = ch_malloc( sizeof("(!)")
292 + ( ftmp == NULL ? 0 : strlen( ftmp ) ) );
293 sprintf( *fstr, "(!%s)",
294 ftmp == NULL ? "" : ftmp );
297 case LDAP_FILTER_EXT:
298 /* not yet implemented */
299 Debug( LDAP_DEBUG_ANY, "extensible match not yet implemented.\n",
301 f->f_choice = SLAPD_FILTER_COMPUTED;
302 f->f_result = SLAPD_COMPARE_UNDEFINED;
303 *fstr = ch_strdup( "(extended)" );
307 Debug( LDAP_DEBUG_ANY, "get_filter: unknown filter type=%lu\n",
309 f->f_choice = SLAPD_FILTER_COMPUTED;
310 f->f_result = SLAPD_COMPARE_UNDEFINED;
311 *fstr = ch_strdup( "(undefined)" );
317 if ( err != LDAP_SUCCESS ) {
318 if ( *fstr != NULL ) {
322 if( err != SLAPD_DISCONNECT ) {
324 f->f_choice = SLAPD_FILTER_COMPUTED;
325 f->f_result = SLAPD_COMPARE_UNDEFINED;
326 *fstr = ch_strdup( "(badfilter)" );
337 Debug( LDAP_DEBUG_FILTER, "end get_filter %d\n", err, 0, 0 );
342 get_filter_list( Connection *conn, BerElement *ber,
343 Filter **f, char **fstr,
352 Debug( LDAP_DEBUG_FILTER, "begin get_filter_list\n", 0, 0, 0 );
356 for ( tag = ber_first_element( ber, &len, &last ); tag != LBER_DEFAULT;
357 tag = ber_next_element( ber, &len, last ) )
359 err = get_filter( conn, ber, new, &ftmp, text );
360 if ( err != LDAP_SUCCESS )
363 if ( *fstr == NULL ) {
366 *fstr = ch_realloc( *fstr, strlen( *fstr ) +
367 strlen( ftmp ) + 1 );
368 strcat( *fstr, ftmp );
371 new = &(*new)->f_next;
375 Debug( LDAP_DEBUG_FILTER, "end get_filter_list\n", 0, 0, 0 );
376 return( LDAP_SUCCESS );
380 get_substring_filter(
391 struct berval *value;
394 #ifdef SLAPD_SCHEMA_NOT_COMPAT
395 struct berval *nvalue;
399 *text = "error decoding filter";
401 Debug( LDAP_DEBUG_FILTER, "begin get_substring_filter\n", 0, 0, 0 );
403 if ( ber_scanf( ber, "{o" /*}*/, &type ) == LBER_ERROR ) {
404 return SLAPD_DISCONNECT;
407 #ifdef SLAPD_SCHEMA_NOT_COMPAT
408 f->f_sub = ch_calloc( 1, sizeof(SubstringsAssertion) );
409 f->f_sub_desc = NULL;
410 rc = slap_bv2ad( &type, &f->f_sub_desc, text );
412 ch_free( type.bv_val );
414 if( rc != LDAP_SUCCESS ) {
417 f->f_choice = SLAPD_FILTER_COMPUTED;
418 f->f_result = SLAPD_COMPARE_UNDEFINED;
419 *fstr = ch_strdup( "(undefined)" );
423 f->f_sub_type = type.bv_val;
424 attr_normalize( f->f_sub_type );
426 /* should get real syntax and see if we have a substring matching rule */
427 syntax = attr_syntax( f->f_sub_type );
430 f->f_sub_initial = NULL;
432 f->f_sub_final = NULL;
434 #ifdef SLAPD_SCHEMA_NOT_COMPAT
436 *fstr = ch_malloc( sizeof("(=" /*)*/) +
437 f->f_sub_desc->ad_cname->bv_len );
438 sprintf( *fstr, "(%s=" /*)*/, f->f_sub_desc->ad_cname->bv_val );
442 *fstr = ch_malloc( strlen( f->f_sub_type ) + 3 );
443 sprintf( *fstr, "(%s=" /*)*/, f->f_sub_type );
447 for ( tag = ber_first_element( ber, &len, &last ); tag != LBER_DEFAULT;
448 tag = ber_next_element( ber, &len, last ) )
450 #ifdef SLAPD_SCHEMA_NOT_COMPAT
454 rc = ber_scanf( ber, "O", &value );
455 if ( rc == LBER_ERROR ) {
456 rc = SLAPD_DISCONNECT;
460 if ( value == NULL || value->bv_len == 0 ) {
462 rc = LDAP_INVALID_SYNTAX;
466 #ifdef SLAPD_SCHEMA_NOT_COMPAT
468 case LDAP_SUBSTRING_INITIAL:
469 usage = SLAP_MR_SUBSTR_INITIAL;
472 case LDAP_SUBSTRING_ANY:
473 usage = SLAP_MR_SUBSTR_ANY;
476 case LDAP_SUBSTRING_FINAL:
477 usage = SLAP_MR_SUBSTR_FINAL;
481 rc = LDAP_PROTOCOL_ERROR;
483 Debug( LDAP_DEBUG_FILTER,
484 " unknown substring choice=%ld\n",
491 rc = value_normalize( f->f_sub_desc, usage, value, &nvalue, text );
494 if( rc != LDAP_SUCCESS ) {
501 /* we should call a substring syntax normalization routine */
502 value_normalize( value->bv_val, syntax );
503 /* this is bogus, value_normalize should take a berval */
504 value->bv_len = strlen( value->bv_val );
507 rc = LDAP_PROTOCOL_ERROR;
510 case LDAP_SUBSTRING_INITIAL:
511 Debug( LDAP_DEBUG_FILTER, " INITIAL\n", 0, 0, 0 );
512 if ( f->f_sub_initial != NULL ) {
517 f->f_sub_initial = value;
520 *fstr = ch_realloc( *fstr,
521 strlen( *fstr ) + value->bv_len + 1 );
522 strcat( *fstr, value->bv_val );
526 case LDAP_SUBSTRING_ANY:
527 Debug( LDAP_DEBUG_FILTER, " ANY\n", 0, 0, 0 );
528 if( ber_bvecadd( &f->f_sub_any, value ) < 0 ) {
534 *fstr = ch_realloc( *fstr,
535 strlen( *fstr ) + value->bv_len + 2 );
536 strcat( *fstr, "*" );
537 strcat( *fstr, value->bv_val );
541 case LDAP_SUBSTRING_FINAL:
542 Debug( LDAP_DEBUG_FILTER, " FINAL\n", 0, 0, 0 );
543 if ( f->f_sub_final != NULL ) {
547 f->f_sub_final = value;
550 *fstr = ch_realloc( *fstr,
551 strlen( *fstr ) + value->bv_len + 2 );
552 strcat( *fstr, "*" );
553 strcat( *fstr, value->bv_val );
558 Debug( LDAP_DEBUG_FILTER,
559 " unknown substring type=%ld\n",
565 Debug( LDAP_DEBUG_FILTER, " error=%ld\n",
573 #ifdef SLAPD_SCHEMA_NOT_COMPAT
574 ad_free( f->f_sub_desc, 1 );
576 ch_free( f->f_sub_type );
578 ber_bvfree( f->f_sub_initial );
579 ber_bvecfree( f->f_sub_any );
580 ber_bvfree( f->f_sub_final );
581 #ifdef SLAPD_SCHEMA_NOT_COMPAT
589 *fstr = ch_realloc( *fstr, strlen( *fstr ) + 3 );
590 if ( f->f_sub_final == NULL ) {
591 strcat( *fstr, "*" );
593 strcat( *fstr, /*(*/ ")" );
596 Debug( LDAP_DEBUG_FILTER, "end get_substring_filter\n", 0, 0, 0 );
597 return( LDAP_SUCCESS );
601 filter_free( Filter *f )
609 switch ( f->f_choice ) {
610 case LDAP_FILTER_PRESENT:
611 #ifdef SLAPD_SCHEMA_NOT_COMPAT
612 ad_free( f->f_desc, 1 );
614 if ( f->f_type != NULL ) {
620 case LDAP_FILTER_EQUALITY:
623 case LDAP_FILTER_APPROX:
624 #ifdef SLAPD_SCHEMA_NOT_COMPAT
625 ava_free( f->f_ava, 1 );
627 ava_free( &f->f_ava, 0 );
631 case LDAP_FILTER_SUBSTRINGS:
632 #ifdef SLAPD_SCHEMA_NOT_COMPAT
633 ad_free( f->f_sub_desc, 1 );
634 if ( f->f_sub_initial != NULL ) {
635 ber_bvfree( f->f_sub_initial );
637 ber_bvecfree( f->f_sub_any );
638 if ( f->f_sub_final != NULL ) {
639 ber_bvfree( f->f_sub_final );
642 if ( f->f_sub_type != NULL ) {
643 free( f->f_sub_type );
645 if ( f->f_sub_initial != NULL ) {
646 ber_bvfree( f->f_sub_initial );
648 ber_bvecfree( f->f_sub_any );
649 if ( f->f_sub_final != NULL ) {
650 ber_bvfree( f->f_sub_final );
655 case LDAP_FILTER_AND:
657 case LDAP_FILTER_NOT:
658 for ( p = f->f_list; p != NULL; p = next ) {
664 case SLAPD_FILTER_COMPUTED:
668 Debug( LDAP_DEBUG_ANY, "filter_free: unknown filter type=%lu\n",
679 filter_print( Filter *f )
685 fprintf( stderr, "No filter!" );
688 switch ( f->f_choice ) {
689 case LDAP_FILTER_EQUALITY:
690 #ifdef SLAPD_SCHEMA_NOT_COMPAT
691 fprintf( stderr, "(%s=%s)",
692 f->f_av_desc->ad_cname->bv_val,
693 f->f_av_value->bv_val );
695 fprintf( stderr, "(%s=%s)",
697 f->f_ava.ava_value.bv_val );
702 #ifdef SLAPD_SCHEMA_NOT_COMPAT
703 fprintf( stderr, "(%s>=%s)",
704 f->f_av_desc->ad_cname->bv_val,
705 f->f_av_value->bv_val );
707 fprintf( stderr, "(%s>=%s)",
709 f->f_ava.ava_value.bv_val );
714 #ifdef SLAPD_SCHEMA_NOT_COMPAT
715 fprintf( stderr, "(%s<=%s)",
716 f->f_ava->aa_desc->ad_cname->bv_val,
717 f->f_ava->aa_value->bv_val );
719 fprintf( stderr, "(%s<=%s)",
721 f->f_ava.ava_value.bv_val );
725 case LDAP_FILTER_APPROX:
726 #ifdef SLAPD_SCHEMA_NOT_COMPAT
727 fprintf( stderr, "(%s~=%s)",
728 f->f_ava->aa_desc->ad_cname->bv_val,
729 f->f_ava->aa_value->bv_val );
731 fprintf( stderr, "(%s~=%s)",
733 f->f_ava.ava_value.bv_val );
737 case LDAP_FILTER_SUBSTRINGS:
738 #ifdef SLAPD_SCHEMA_NOT_COMPAT
739 fprintf( stderr, "(%s=" /*)*/,
740 f->f_sub_desc->ad_cname->bv_val );
742 fprintf( stderr, "(%s=" /*)*/,
745 if ( f->f_sub_initial != NULL ) {
746 fprintf( stderr, "%s",
747 f->f_sub_initial->bv_val );
749 if ( f->f_sub_any != NULL ) {
750 for ( i = 0; f->f_sub_any[i] != NULL; i++ ) {
751 fprintf( stderr, "*%s",
752 f->f_sub_any[i]->bv_val );
755 if ( f->f_sub_final != NULL ) {
757 "*%s", f->f_sub_final->bv_val );
759 fprintf( stderr, /*(*/ ")" );
762 case LDAP_FILTER_PRESENT:
763 #ifdef SLAPD_SCHEMA_NOT_COMPAT
764 fprintf( stderr, "(%s=*)",
765 f->f_desc->ad_cname->bv_val );
767 fprintf( stderr, "(%s=*)",
772 case LDAP_FILTER_AND:
774 case LDAP_FILTER_NOT:
775 fprintf( stderr, "(%c" /*)*/,
776 f->f_choice == LDAP_FILTER_AND ? '&' :
777 f->f_choice == LDAP_FILTER_OR ? '|' : '!' );
778 for ( p = f->f_list; p != NULL; p = p->f_next ) {
781 fprintf( stderr, /*(*/ ")" );
784 case SLAPD_FILTER_COMPUTED:
785 fprintf( stderr, "(?=%s)",
786 f->f_result == LDAP_COMPARE_FALSE ? "false" :
787 f->f_result == LDAP_COMPARE_TRUE ? "true" :
788 f->f_result == SLAPD_COMPARE_UNDEFINED ? "undefined" :
793 fprintf( stderr, "(unknown-filter=%lu)", f->f_choice );
798 #endif /* ldap_debug */