1 /* filter.c - routines for parsing and dealing with filters */
4 * Copyright 1998-2000 The OpenLDAP Foundation, All Rights Reserved.
5 * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
12 #include <ac/socket.h>
13 #include <ac/string.h>
17 static int get_filter_list(
23 static int get_substring_filter(
44 Debug( LDAP_DEBUG_FILTER, "begin get_filter\n", 0, 0, 0 );
47 * A filter looks like this coming in:
49 * and [0] SET OF Filter,
50 * or [1] SET OF Filter,
52 * equalityMatch [3] AttributeValueAssertion,
53 * substrings [4] SubstringFilter,
54 * greaterOrEqual [5] AttributeValueAssertion,
55 * lessOrEqual [6] AttributeValueAssertion,
56 * present [7] AttributeType,,
57 * approxMatch [8] AttributeValueAssertion
58 * extensibleMatch [9] MatchingRuleAssertion
61 * SubstringFilter ::= SEQUENCE {
63 * SEQUENCE OF CHOICE {
64 * initial [0] IA5String,
70 * MatchingRuleAssertion ::= SEQUENCE {
71 * matchingRule [1] MatchingRuleId OPTIONAL,
72 * type [2] AttributeDescription OPTIONAL,
73 * matchValue [3] AssertionValue,
74 * dnAttributes [4] BOOLEAN DEFAULT FALSE
79 tag = ber_peek_tag( ber, &len );
81 if( tag == LBER_ERROR ) {
82 *text = "error decoding filter";
83 return SLAPD_DISCONNECT;
86 f = (Filter *) ch_malloc( sizeof(Filter) );
93 switch ( f->f_choice ) {
94 case LDAP_FILTER_EQUALITY:
95 Debug( LDAP_DEBUG_FILTER, "EQUALITY\n", 0, 0, 0 );
97 if ( (err = get_ava( ber, &f->f_ava )) != LDAP_SUCCESS ) {
98 *text = "error decoding filter";
102 #ifdef SLAPD_SCHEMA_NOT_COMPAT
103 *fstr = ch_malloc( sizeof("(=)")
104 + f->f_av_desc->ad_cname->bv_len
105 + f->f_av_value->bv_len );
107 sprintf( *fstr, "(%s=%s)",
108 f->f_av_desc->ad_cname->bv_val,
109 f->f_av_value->bv_val );
112 *fstr = ch_malloc( sizeof("(=)")
113 + strlen( f->f_avtype )
114 + f->f_avvalue.bv_len);
115 sprintf( *fstr, "(%s=%s)", f->f_avtype,
116 f->f_avvalue.bv_val );
120 case LDAP_FILTER_SUBSTRINGS:
121 Debug( LDAP_DEBUG_FILTER, "SUBSTRINGS\n", 0, 0, 0 );
122 err = get_substring_filter( conn, ber, f, fstr, text );
126 Debug( LDAP_DEBUG_FILTER, "GE\n", 0, 0, 0 );
128 if ( (err = get_ava( ber, &f->f_ava )) != LDAP_SUCCESS ) {
129 *text = "decoding filter error";
133 #ifdef SLAPD_SCHEMA_NOT_COMPAT
134 *fstr = ch_malloc( sizeof("(>=)")
135 + f->f_av_desc->ad_cname->bv_len
136 + f->f_av_value->bv_len );
138 sprintf( *fstr, "(%s>=%s)",
139 f->f_av_desc->ad_cname->bv_val,
140 f->f_av_value->bv_val );
143 *fstr = ch_malloc( sizeof("(>=)")
144 + strlen( f->f_avtype )
145 + f->f_avvalue.bv_len);
146 sprintf( *fstr, "(%s>=%s)", f->f_avtype,
147 f->f_avvalue.bv_val );
152 Debug( LDAP_DEBUG_FILTER, "LE\n", 0, 0, 0 );
154 if ( (err = get_ava( ber, &f->f_ava )) != LDAP_SUCCESS ) {
155 *text = "decoding filter error";
159 #ifdef SLAPD_SCHEMA_NOT_COMPAT
160 *fstr = ch_malloc( sizeof("(<=)")
161 + f->f_av_desc->ad_cname->bv_len
162 + f->f_av_value->bv_len );
164 sprintf( *fstr, "(%s<=%s)",
165 f->f_av_desc->ad_cname->bv_val,
166 f->f_av_value->bv_val );
169 *fstr = ch_malloc( sizeof("(<=)")
170 + strlen( f->f_avtype )
171 + f->f_avvalue.bv_len);
172 sprintf( *fstr, "(%s<=%s)", f->f_avtype,
173 f->f_avvalue.bv_val );
177 case LDAP_FILTER_PRESENT: {
180 Debug( LDAP_DEBUG_FILTER, "PRESENT\n", 0, 0, 0 );
182 if ( ber_scanf( ber, "o", &type ) == LBER_ERROR ) {
183 err = SLAPD_DISCONNECT;
184 *text = "error decoding filter";
188 #ifdef SLAPD_SCHEMA_NOT_COMPAT
193 err = slap_bv2ad( &type, &f->f_desc, &text );
195 if( err != LDAP_SUCCESS ) {
196 ch_free( type.bv_val );
200 ch_free( type.bv_val );
203 *fstr = ch_malloc( sizeof("(=*)")
204 + f->f_desc->ad_cname->bv_len );
205 sprintf( *fstr, "(%s=*)",
206 f->f_desc->ad_cname->bv_val );
209 f->f_type = type.bv_val;
211 attr_normalize( f->f_type );
212 *fstr = ch_malloc( sizeof("(=*)")
213 + strlen( f->f_type ) );
214 sprintf( *fstr, "(%s=*)", f->f_type );
218 case LDAP_FILTER_APPROX:
219 Debug( LDAP_DEBUG_FILTER, "APPROX\n", 0, 0, 0 );
221 if ( (err = get_ava( ber, &f->f_ava )) != LDAP_SUCCESS ) {
222 *text = "decoding filter error";
226 #ifdef SLAPD_SCHEMA_NOT_COMPAT
227 *fstr = ch_malloc( sizeof("(~=)")
228 + f->f_av_desc->ad_cname->bv_len
229 + f->f_av_value->bv_len );
231 sprintf( *fstr, "(%s~=%s)",
232 f->f_av_desc->ad_cname->bv_val,
233 f->f_av_value->bv_val );
236 *fstr = ch_malloc( sizeof("(~=)")
237 + strlen( f->f_avtype )
238 + f->f_avvalue.bv_len);
239 sprintf( *fstr, "(%s~=%s)", f->f_avtype,
240 f->f_avvalue.bv_val );
244 case LDAP_FILTER_AND:
245 Debug( LDAP_DEBUG_FILTER, "AND\n", 0, 0, 0 );
246 err = get_filter_list( conn, ber, &f->f_and, &ftmp, text );
247 if ( err != LDAP_SUCCESS ) {
250 *fstr = ch_malloc( sizeof("(&)")
251 + ( ftmp == NULL ? 0 : strlen( ftmp ) ) );
252 sprintf( *fstr, "(&%s)",
253 ftmp == NULL ? "" : ftmp );
257 Debug( LDAP_DEBUG_FILTER, "OR\n", 0, 0, 0 );
258 err = get_filter_list( conn, ber, &f->f_and, &ftmp, text );
259 if ( err != LDAP_SUCCESS ) {
262 *fstr = ch_malloc( sizeof("(!)")
263 + ( ftmp == NULL ? 0 : strlen( ftmp ) ) );
264 sprintf( *fstr, "(|%s)",
265 ftmp == NULL ? "" : ftmp );
268 case LDAP_FILTER_NOT:
269 Debug( LDAP_DEBUG_FILTER, "NOT\n", 0, 0, 0 );
270 (void) ber_skip_tag( ber, &len );
271 err = get_filter( conn, ber, &f->f_not, &ftmp, text );
272 if ( err != LDAP_SUCCESS ) {
275 *fstr = ch_malloc( sizeof("(!)")
276 + ( ftmp == NULL ? 0 : strlen( ftmp ) ) );
277 sprintf( *fstr, "(!%s)",
278 ftmp == NULL ? "" : ftmp );
281 case LDAP_FILTER_EXT:
282 /* not yet implemented */
283 Debug( LDAP_DEBUG_ANY, "extensible match not yet implemented.\n",
285 f->f_choice = SLAPD_FILTER_COMPUTED;
286 f->f_result = SLAPD_COMPARE_UNDEFINED;
287 *fstr = ch_strdup( "(extended)" );
291 Debug( LDAP_DEBUG_ANY, "get_filter: unknown filter type=%lu\n",
293 f->f_choice = SLAPD_FILTER_COMPUTED;
294 f->f_result = SLAPD_COMPARE_UNDEFINED;
295 *fstr = ch_strdup( "(undefined)" );
299 if ( err != LDAP_SUCCESS ) {
301 if ( *fstr != NULL ) {
310 Debug( LDAP_DEBUG_FILTER, "end get_filter %d\n", err, 0, 0 );
315 get_filter_list( Connection *conn, BerElement *ber, Filter **f, char **fstr, char **text )
323 Debug( LDAP_DEBUG_FILTER, "begin get_filter_list\n", 0, 0, 0 );
327 for ( tag = ber_first_element( ber, &len, &last ); tag != LBER_DEFAULT;
328 tag = ber_next_element( ber, &len, last ) )
330 err = get_filter( conn, ber, new, &ftmp, text );
331 if ( err != LDAP_SUCCESS )
334 if ( *fstr == NULL ) {
337 *fstr = ch_realloc( *fstr, strlen( *fstr ) +
338 strlen( ftmp ) + 1 );
339 strcat( *fstr, ftmp );
342 new = &(*new)->f_next;
346 Debug( LDAP_DEBUG_FILTER, "end get_filter_list\n", 0, 0, 0 );
347 return( LDAP_SUCCESS );
351 get_substring_filter(
367 *text = "error decoding filter";
369 Debug( LDAP_DEBUG_FILTER, "begin get_substring_filter\n", 0, 0, 0 );
371 if ( ber_scanf( ber, "{a" /*}*/, &type ) == LBER_ERROR ) {
372 return SLAPD_DISCONNECT;
375 #ifdef SLAPD_SCHEMA_NOT_COMPAT
376 /* not yet implemented */
378 f->f_sub_type = type;
379 attr_normalize( f->f_sub_type );
381 /* should get real syntax and see if we have a substring matching rule */
382 syntax = attr_syntax( f->f_sub_type );
385 f->f_sub_initial = NULL;
387 f->f_sub_final = NULL;
389 #ifdef SLAPD_SCHEMA_NOT_COMPAT
390 /* not yet implemented */
393 *fstr = ch_malloc( strlen( f->f_sub_type ) + 3 );
394 sprintf( *fstr, "(%s=" /*)*/, f->f_sub_type );
398 for ( tag = ber_first_element( ber, &len, &last ); tag != LBER_DEFAULT;
399 tag = ber_next_element( ber, &len, last ) )
401 rc = ber_scanf( ber, "O", &val );
402 if ( rc == LBER_ERROR ) {
403 rc = SLAPD_DISCONNECT;
407 if ( val == NULL || val->bv_len == 0 ) {
409 rc = LDAP_INVALID_SYNTAX;
413 rc = LDAP_PROTOCOL_ERROR;
415 #ifdef SLAPD_SCHEMA_NOT_COMPAT
416 /* not yet implemented */
418 /* we should call a substring syntax normalization routine */
419 value_normalize( val->bv_val, syntax );
420 /* this is bogus, value_normalize should take a berval */
421 val->bv_len = strlen( val->bv_val );
425 case LDAP_SUBSTRING_INITIAL:
426 Debug( LDAP_DEBUG_FILTER, " INITIAL\n", 0, 0, 0 );
427 if ( f->f_sub_initial != NULL ) {
431 f->f_sub_initial = val;
434 *fstr = ch_realloc( *fstr,
435 strlen( *fstr ) + val->bv_len + 1 );
436 strcat( *fstr, val->bv_val );
440 case LDAP_SUBSTRING_ANY:
441 Debug( LDAP_DEBUG_FILTER, " ANY\n", 0, 0, 0 );
442 if( ber_bvecadd( &f->f_sub_any, val ) < 0 ) {
448 *fstr = ch_realloc( *fstr,
449 strlen( *fstr ) + val->bv_len + 2 );
450 strcat( *fstr, "*" );
451 strcat( *fstr, val->bv_val );
455 case LDAP_SUBSTRING_FINAL:
456 Debug( LDAP_DEBUG_FILTER, " FINAL\n", 0, 0, 0 );
457 if ( f->f_sub_final != NULL ) {
461 f->f_sub_final = val;
464 *fstr = ch_realloc( *fstr,
465 strlen( *fstr ) + val->bv_len + 2 );
466 strcat( *fstr, "*" );
467 strcat( *fstr, val->bv_val );
472 Debug( LDAP_DEBUG_FILTER,
473 " unknown substring type=%ld\n",
479 Debug( LDAP_DEBUG_FILTER, " error=%ld\n",
487 #ifdef SLAPD_SCHEMA_NOT_COMPAT
488 /* not yet implemented */
490 ch_free( f->f_sub_type );
492 ber_bvfree( f->f_sub_initial );
493 ber_bvecfree( f->f_sub_any );
494 ber_bvfree( f->f_sub_final );
500 *fstr = ch_realloc( *fstr, strlen( *fstr ) + 3 );
501 if ( f->f_sub_final == NULL ) {
502 strcat( *fstr, "*" );
504 strcat( *fstr, /*(*/ ")" );
507 Debug( LDAP_DEBUG_FILTER, "end get_substring_filter\n", 0, 0, 0 );
508 return( LDAP_SUCCESS );
512 filter_free( Filter *f )
520 switch ( f->f_choice ) {
521 case LDAP_FILTER_PRESENT:
522 #ifdef SLAPD_SCHEMA_NOT_COMPAT
523 ad_free( f->f_desc, 1 );
525 if ( f->f_type != NULL ) {
531 case LDAP_FILTER_EQUALITY:
534 case LDAP_FILTER_APPROX:
535 #ifdef SLAPD_SCHEMA_NOT_COMPAT
536 ava_free( f->f_ava, 1 );
538 ava_free( &f->f_ava, 0 );
542 case LDAP_FILTER_SUBSTRINGS:
543 #ifdef SLAPD_SCHEMA_NOT_COMPAT
544 ad_free( f->f_sub_desc, 1 );
545 if ( f->f_sub_initial != NULL ) {
546 ber_bvfree( f->f_sub_initial );
548 ber_bvecfree( f->f_sub_any );
549 if ( f->f_sub_final != NULL ) {
550 ber_bvfree( f->f_sub_final );
553 if ( f->f_sub_type != NULL ) {
554 free( f->f_sub_type );
556 if ( f->f_sub_initial != NULL ) {
557 ber_bvfree( f->f_sub_initial );
559 ber_bvecfree( f->f_sub_any );
560 if ( f->f_sub_final != NULL ) {
561 ber_bvfree( f->f_sub_final );
566 case LDAP_FILTER_AND:
568 case LDAP_FILTER_NOT:
569 for ( p = f->f_list; p != NULL; p = next ) {
575 case SLAPD_FILTER_COMPUTED:
579 Debug( LDAP_DEBUG_ANY, "filter_free: unknown filter type=%lu\n",
590 filter_print( Filter *f )
596 fprintf( stderr, "No filter!" );
599 switch ( f->f_choice ) {
600 case LDAP_FILTER_EQUALITY:
601 #ifdef SLAPD_SCHEMA_NOT_COMPAT
602 fprintf( stderr, "(%s=%s)",
603 f->f_av_desc->ad_cname->bv_val,
604 f->f_av_value->bv_val );
606 fprintf( stderr, "(%s=%s)",
608 f->f_ava.ava_value.bv_val );
613 #ifdef SLAPD_SCHEMA_NOT_COMPAT
614 fprintf( stderr, "(%s>=%s)",
615 f->f_av_desc->ad_cname->bv_val,
616 f->f_av_value->bv_val );
618 fprintf( stderr, "(%s>=%s)",
620 f->f_ava.ava_value.bv_val );
625 #ifdef SLAPD_SCHEMA_NOT_COMPAT
626 fprintf( stderr, "(%s<=%s)",
627 f->f_ava->aa_desc->ad_cname->bv_val,
628 f->f_ava->aa_value->bv_val );
630 fprintf( stderr, "(%s<=%s)",
632 f->f_ava.ava_value.bv_val );
636 case LDAP_FILTER_APPROX:
637 #ifdef SLAPD_SCHEMA_NOT_COMPAT
638 fprintf( stderr, "(%s~=%s)",
639 f->f_ava->aa_desc->ad_cname->bv_val,
640 f->f_ava->aa_value->bv_val );
642 fprintf( stderr, "(%s~=%s)",
644 f->f_ava.ava_value.bv_val );
648 case LDAP_FILTER_SUBSTRINGS:
649 #ifdef SLAPD_SCHEMA_NOT_COMPAT
650 fprintf( stderr, "(%s=" /*)*/,
651 f->f_sub_desc->ad_cname->bv_val );
653 fprintf( stderr, "(%s=" /*)*/,
656 if ( f->f_sub_initial != NULL ) {
657 fprintf( stderr, "%s",
658 f->f_sub_initial->bv_val );
660 if ( f->f_sub_any != NULL ) {
661 for ( i = 0; f->f_sub_any[i] != NULL; i++ ) {
662 fprintf( stderr, "*%s",
663 f->f_sub_any[i]->bv_val );
666 if ( f->f_sub_final != NULL ) {
668 "*%s", f->f_sub_final->bv_val );
670 fprintf( stderr, /*(*/ ")" );
673 case LDAP_FILTER_PRESENT:
674 #ifdef SLAPD_SCHEMA_NOT_COMPAT
675 fprintf( stderr, "(%s=*)",
676 f->f_desc->ad_cname->bv_val );
678 fprintf( stderr, "(%s=*)",
683 case LDAP_FILTER_AND:
685 case LDAP_FILTER_NOT:
686 fprintf( stderr, "(%c" /*)*/,
687 f->f_choice == LDAP_FILTER_AND ? '&' :
688 f->f_choice == LDAP_FILTER_OR ? '|' : '!' );
689 for ( p = f->f_list; p != NULL; p = p->f_next ) {
692 fprintf( stderr, /*(*/ ")" );
695 case SLAPD_FILTER_COMPUTED:
696 fprintf( stderr, "(?=%s)",
697 f->f_result == LDAP_COMPARE_FALSE ? "false" :
698 f->f_result == LDAP_COMPARE_TRUE ? "true" :
699 f->f_result == SLAPD_COMPARE_UNDEFINED ? "undefined" :
704 fprintf( stderr, "(unknown-filter=%lu)", f->f_choice );
709 #endif /* ldap_debug */