]> git.sur5r.net Git - openldap/blob - servers/slapd/overlays/pcache.c
ITS#5680
[openldap] / servers / slapd / overlays / pcache.c
1 /* $OpenLDAP$ */
2 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
3  *
4  * Copyright 2003-2008 The OpenLDAP Foundation.
5  * Portions Copyright 2003 IBM Corporation.
6  * Portions Copyright 2003 Symas Corporation.
7  * All rights reserved.
8  *
9  * Redistribution and use in source and binary forms, with or without
10  * modification, are permitted only as authorized by the OpenLDAP
11  * Public License.
12  *
13  * A copy of this license is available in the file LICENSE in the
14  * top-level directory of the distribution or, alternatively, at
15  * <http://www.OpenLDAP.org/license.html>.
16  */
17 /* ACKNOWLEDGEMENTS:
18  * This work was initially developed by Apurva Kumar for inclusion
19  * in OpenLDAP Software and subsequently rewritten by Howard Chu.
20  */
21
22 #include "portable.h"
23
24 #ifdef SLAPD_OVER_PROXYCACHE
25
26 #include <stdio.h>
27
28 #include <ac/string.h>
29 #include <ac/time.h>
30
31 #include "slap.h"
32 #include "lutil.h"
33 #include "ldap_rq.h"
34 #include "avl.h"
35
36 #include "config.h"
37
38 #ifdef LDAP_DEVEL
39 /*
40  * Control that allows to access the private DB
41  * instead of the public one
42  */
43 #define PCACHE_CONTROL_PRIVDB           "1.3.6.1.4.1.4203.666.11.9.5.1"
44
45 /*
46  * Extended Operation that allows to remove a query from the cache
47  */
48 #define PCACHE_EXOP_QUERY_DELETE        "1.3.6.1.4.1.4203.666.11.9.6.1"
49 #endif
50
51 /* query cache structs */
52 /* query */
53
54 typedef struct Query_s {
55         Filter*         filter;         /* Search Filter */
56         struct berval   base;           /* Search Base */
57         int             scope;          /* Search scope */
58 } Query;
59
60 struct query_template_s;
61
62 typedef struct Qbase_s {
63         Avlnode *scopes[4];             /* threaded AVL trees of cached queries */
64         struct berval base;
65         int queries;
66 } Qbase;
67
68 /* struct representing a cached query */
69 typedef struct cached_query_s {
70         Filter                                  *filter;
71         Filter                                  *first;
72         Qbase                                   *qbase;
73         int                                             scope;
74         struct berval                   q_uuid;         /* query identifier */
75         int                                             q_sizelimit;
76         struct query_template_s         *qtemp; /* template of the query */
77         time_t                                          expiry_time;    /* time till the query is considered valid */
78         struct cached_query_s           *next;          /* next query in the template */
79         struct cached_query_s           *prev;          /* previous query in the template */
80         struct cached_query_s           *lru_up;        /* previous query in the LRU list */
81         struct cached_query_s           *lru_down;      /* next query in the LRU list */
82         ldap_pvt_thread_rdwr_t          rwlock;
83 } CachedQuery;
84
85 /*
86  * URL representation:
87  *
88  * ldap:///<base>??<scope>?<filter>?x-uuid=<uid>,x-template=<template>,x-attrset=<attrset>,x-expiry=<expiry>
89  *
90  * <base> ::= CachedQuery.qbase->base
91  * <scope> ::= CachedQuery.scope
92  * <filter> ::= filter2bv(CachedQuery.filter)
93  * <uuid> ::= CachedQuery.q_uuid
94  * <attrset> ::= CachedQuery.qtemp->attr_set_index
95  * <expiry> ::= CachedQuery.expiry_time
96  *
97  * quick hack: parse URI, call add_query() and then fix
98  * CachedQuery.expiry_time and CachedQuery.q_uuid
99  */
100
101 /*
102  * Represents a set of projected attributes.
103  */
104
105 struct attr_set {
106         struct query_template_s *templates;
107         AttributeName*  attrs;          /* specifies the set */
108         unsigned        flags;
109 #define PC_CONFIGURED   (0x1)
110 #define PC_REFERENCED   (0x2)
111 #define PC_GOT_OC               (0x4)
112         int             count;          /* number of attributes */
113 };
114
115 /* struct representing a query template
116  * e.g. template string = &(cn=)(mail=)
117  */
118 typedef struct query_template_s {
119         struct query_template_s *qtnext;
120         struct query_template_s *qmnext;
121
122         Avlnode*                qbase;
123         CachedQuery*    query;          /* most recent query cached for the template */
124         CachedQuery*    query_last;     /* oldest query cached for the template */
125         ldap_pvt_thread_rdwr_t t_rwlock; /* Rd/wr lock for accessing queries in the template */
126         struct berval   querystr;       /* Filter string corresponding to the QT */
127
128         int             attr_set_index; /* determines the projected attributes */
129         int             no_of_queries;  /* Total number of queries in the template */
130         time_t          ttl;            /* TTL for the queries of this template */
131         time_t          negttl;         /* TTL for negative results */
132         time_t          limitttl;       /* TTL for sizelimit exceeding results */
133         struct attr_set t_attrs;        /* filter attrs + attr_set */
134 } QueryTemplate;
135
136 typedef enum {
137         PC_IGNORE = 0,
138         PC_POSITIVE,
139         PC_NEGATIVE,
140         PC_SIZELIMIT
141 } pc_caching_reason_t;
142
143 static const char *pc_caching_reason_str[] = {
144         "IGNORE",
145         "POSITIVE",
146         "NEGATIVE",
147         "SIZELIMIT",
148
149         NULL
150 };
151
152 struct query_manager_s;
153
154 /* prototypes for functions for 1) query containment
155  * 2) query addition, 3) cache replacement
156  */
157 typedef CachedQuery *(QCfunc)(Operation *op, struct query_manager_s*,
158         Query*, QueryTemplate*);
159 typedef CachedQuery *(AddQueryfunc)(Operation *op, struct query_manager_s*,
160         Query*, QueryTemplate*, pc_caching_reason_t, int wlock);
161 typedef void (CRfunc)(struct query_manager_s*, struct berval*);
162
163 /* LDAP query cache */
164 typedef struct query_manager_s {
165         struct attr_set*        attr_sets;              /* possible sets of projected attributes */
166         QueryTemplate*          templates;              /* cacheable templates */
167
168         CachedQuery*            lru_top;                /* top and bottom of LRU list */
169         CachedQuery*            lru_bottom;
170
171         ldap_pvt_thread_mutex_t         lru_mutex;      /* mutex for accessing LRU list */
172
173         /* Query cache methods */
174         QCfunc                  *qcfunc;                        /* Query containment*/
175         CRfunc                  *crfunc;                        /* cache replacement */
176         AddQueryfunc    *addfunc;                       /* add query */
177 } query_manager;
178
179 /* LDAP query cache manager */
180 typedef struct cache_manager_s {
181         BackendDB       db;     /* underlying database */
182         unsigned long   num_cached_queries;             /* total number of cached queries */
183         unsigned long   max_queries;                    /* upper bound on # of cached queries */
184         int             save_queries;                   /* save cached queries across restarts */
185         int     numattrsets;                    /* number of attribute sets */
186         int     cur_entries;                    /* current number of entries cached */
187         int     max_entries;                    /* max number of entries cached */
188         int     num_entries_limit;              /* max # of entries in a cacheable query */
189
190         char    response_cb;                    /* install the response callback
191                                                  * at the tail of the callback list */
192 #define PCACHE_RESPONSE_CB_HEAD 0
193 #define PCACHE_RESPONSE_CB_TAIL 1
194         char    defer_db_open;                  /* defer open for online add */
195
196         time_t  cc_period;              /* interval between successive consistency checks (sec) */
197         int     cc_paused;
198         void    *cc_arg;
199
200         ldap_pvt_thread_mutex_t         cache_mutex;
201
202         query_manager*   qm;    /* query cache managed by the cache manager */
203 } cache_manager;
204
205 static int pcache_debug;
206
207 #ifdef PCACHE_CONTROL_PRIVDB
208 static int privDB_cid;
209 #endif /* PCACHE_CONTROL_PRIVDB */
210
211 static AttributeDescription *ad_queryId, *ad_cachedQueryURL;
212 static struct {
213         char    *desc;
214         AttributeDescription **adp;
215 } as[] = {
216         { "( 1.3.6.1.4.1.4203.666.11.9.1.1 "
217                 "NAME 'queryId' "
218                 "DESC 'ID of query the entry belongs to, formatted as a UUID' "
219                 "EQUALITY octetStringMatch "
220                 "SYNTAX 1.3.6.1.4.1.1466.115.121.1.40{64} "
221                 "NO-USER-MODIFICATION "
222                 "USAGE directoryOperation )",
223                 &ad_queryId },
224         { "( 1.3.6.1.4.1.4203.666.11.9.1.2 "
225                 "NAME 'cachedQueryURL' "
226                 "DESC 'URI describing a cached query' "
227                 "EQUALITY caseExactMatch "
228                 "SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 "
229                 "NO-USER-MODIFICATION "
230                 "USAGE directoryOperation )",
231                 &ad_cachedQueryURL },
232         { NULL }
233 };
234
235 static int
236 filter2template(
237         Operation               *op,
238         Filter                  *f,
239         struct                  berval *fstr,
240         AttributeName**         filter_attrs,
241         int*                    filter_cnt,
242         int*                    filter_got_oc );
243
244 static CachedQuery *
245 add_query(
246         Operation *op,
247         query_manager* qm,
248         Query* query,
249         QueryTemplate *templ,
250         pc_caching_reason_t why,
251         int wlock);
252
253 static int
254 remove_query_data(
255         Operation       *op,
256         SlapReply       *rs,
257         struct berval   *query_uuid );
258
259 /*
260  * Turn a cached query into its URL representation
261  */
262 static int
263 query2url( Operation *op, CachedQuery *q, struct berval *urlbv )
264 {
265         struct berval   bv_scope,
266                         bv_filter;
267         char            attrset_buf[ 32 ],
268                         expiry_buf[ 32 ],
269                         *ptr;
270         ber_len_t       attrset_len,
271                         expiry_len;
272
273         ldap_pvt_scope2bv( q->scope, &bv_scope );
274         filter2bv_x( op, q->filter, &bv_filter );
275         attrset_len = snprintf( attrset_buf, sizeof( attrset_buf ),
276                 "%lu", (unsigned long)q->qtemp->attr_set_index );
277         expiry_len = snprintf( expiry_buf, sizeof( expiry_buf ),
278                 "%lu", (unsigned long)q->expiry_time );
279
280         urlbv->bv_len = STRLENOF( "ldap:///" )
281                 + q->qbase->base.bv_len
282                 + STRLENOF( "??" )
283                 + bv_scope.bv_len
284                 + STRLENOF( "?" )
285                 + bv_filter.bv_len
286                 + STRLENOF( "?x-uuid=" )
287                 + q->q_uuid.bv_len
288                 + STRLENOF( ",x-attrset=" )
289                 + attrset_len
290                 + STRLENOF( ",x-expiry=" )
291                 + expiry_len;
292         ptr = urlbv->bv_val = ber_memalloc_x( urlbv->bv_len + 1, op->o_tmpmemctx );
293         ptr = lutil_strcopy( ptr, "ldap:///" );
294         ptr = lutil_strcopy( ptr, q->qbase->base.bv_val );
295         ptr = lutil_strcopy( ptr, "??" );
296         ptr = lutil_strcopy( ptr, bv_scope.bv_val );
297         ptr = lutil_strcopy( ptr, "?" );
298         ptr = lutil_strcopy( ptr, bv_filter.bv_val );
299         ptr = lutil_strcopy( ptr, "?x-uuid=" );
300         ptr = lutil_strcopy( ptr, q->q_uuid.bv_val );
301         ptr = lutil_strcopy( ptr, ",x-attrset=" );
302         ptr = lutil_strcopy( ptr, attrset_buf );
303         ptr = lutil_strcopy( ptr, ",x-expiry=" );
304         ptr = lutil_strcopy( ptr, expiry_buf );
305
306         ber_memfree_x( bv_filter.bv_val, op->o_tmpmemctx );
307
308         return 0;
309 }
310
311 /*
312  * Turn an URL representing a formerly cached query into a cached query,
313  * and try to cache it
314  */
315 static int
316 url2query(
317         char            *url,
318         Operation       *op,
319         query_manager   *qm )
320 {
321         Query           query = { 0 };
322         QueryTemplate   *qt;
323         CachedQuery     *cq;
324         LDAPURLDesc     *lud = NULL;
325         struct berval   base,
326                         tempstr = BER_BVNULL,
327                         uuid;
328         int             attrset;
329         time_t          expiry_time;
330         int             i,
331                         got_uuid = 0,
332                         got_attrset = 0,
333                         got_expiry = 0,
334                         rc = 0;
335
336         rc = ldap_url_parse( url, &lud );
337         if ( rc != LDAP_URL_SUCCESS ) {
338                 return -1;
339         }
340
341         /* non-allowed fields */
342         if ( lud->lud_host != NULL ) {
343                 rc = 1;
344                 goto error;
345         }
346
347         if ( lud->lud_attrs != NULL ) {
348                 rc = 1;
349                 goto error;
350         }
351
352         /* be pedantic */
353         if ( strcmp( lud->lud_scheme, "ldap" ) != 0 ) {
354                 rc = 1;
355                 goto error;
356         }
357
358         /* required fields */
359         if ( lud->lud_dn == NULL || lud->lud_dn[ 0 ] == '\0' ) {
360                 rc = 1;
361                 goto error;
362         }
363
364         switch ( lud->lud_scope ) {
365         case LDAP_SCOPE_BASE:
366         case LDAP_SCOPE_ONELEVEL:
367         case LDAP_SCOPE_SUBTREE:
368         case LDAP_SCOPE_SUBORDINATE:
369                 break;
370
371         default:
372                 rc = 1;
373                 goto error;
374         }
375
376         if ( lud->lud_filter == NULL || lud->lud_filter[ 0 ] == '\0' ) {
377                 rc = 1;
378                 goto error;
379         }
380
381         if ( lud->lud_exts == NULL ) {
382                 rc = 1;
383                 goto error;
384         }
385
386         for ( i = 0; lud->lud_exts[ i ] != NULL; i++ ) {
387                 if ( strncmp( lud->lud_exts[ i ], "x-uuid=", STRLENOF( "x-uuid=" ) ) == 0 ) {
388                         struct berval   tmpUUID;
389                         Syntax          *syn_UUID = slap_schema.si_ad_entryUUID->ad_type->sat_syntax;
390
391                         ber_str2bv( &lud->lud_exts[ i ][ STRLENOF( "x-uuid=" ) ], 0, 0, &tmpUUID );
392                         rc = syn_UUID->ssyn_pretty( syn_UUID, &tmpUUID, &uuid, NULL );
393                         if ( rc != LDAP_SUCCESS ) {
394                                 goto error;
395                         }
396                         got_uuid = 1;
397
398                 } else if ( strncmp( lud->lud_exts[ i ], "x-attrset=", STRLENOF( "x-attrset=" ) ) == 0 ) {
399                         rc = lutil_atoi( &attrset, &lud->lud_exts[ i ][ STRLENOF( "x-attrset=" ) ] );
400                         if ( rc ) {
401                                 goto error;
402                         }
403                         got_attrset = 1;
404
405                 } else if ( strncmp( lud->lud_exts[ i ], "x-expiry=", STRLENOF( "x-expiry=" ) ) == 0 ) {
406                         unsigned long l;
407
408                         rc = lutil_atoul( &l, &lud->lud_exts[ i ][ STRLENOF( "x-expiry=" ) ] );
409                         if ( rc ) {
410                                 goto error;
411                         }
412                         expiry_time = (time_t)l;
413                         got_expiry = 1;
414
415                 } else {
416                         rc = -1;
417                         goto error;
418                 }
419         }
420
421         if ( !got_uuid ) {
422                 rc = 1;
423                 goto error;
424         }
425
426         if ( !got_attrset ) {
427                 rc = 1;
428                 goto error;
429         }
430
431         if ( !got_expiry ) {
432                 rc = 1;
433                 goto error;
434         }
435
436         /* ignore expired queries */
437         if ( expiry_time <= slap_get_time()) {
438                 Operation       op2 = *op;
439                 SlapReply       rs2 = { 0 };
440
441                 memset( &op2.oq_search, 0, sizeof( op2.oq_search ) );
442
443                 (void)remove_query_data( &op2, &rs2, &uuid );
444
445                 rc = 0;
446
447         } else {
448                 ber_str2bv( lud->lud_dn, 0, 0, &base );
449                 rc = dnNormalize( 0, NULL, NULL, &base, &query.base, NULL );
450                 if ( rc != LDAP_SUCCESS ) {
451                         goto error;
452                 }
453                 query.scope = lud->lud_scope;
454                 query.filter = str2filter( lud->lud_filter );
455
456                 tempstr.bv_val = ch_malloc( strlen( lud->lud_filter ) + 1 );
457                 tempstr.bv_len = 0;
458                 if ( filter2template( op, query.filter, &tempstr, NULL, NULL, NULL ) ) {
459                         ch_free( tempstr.bv_val );
460                         rc = -1;
461                         goto error;
462                 }
463
464                 /* check for query containment */
465                 qt = qm->attr_sets[attrset].templates;
466                 for ( ; qt; qt = qt->qtnext ) {
467                         /* find if template i can potentially answer tempstr */
468                         if ( bvmatch( &qt->querystr, &tempstr ) ) {
469                                 break;
470                         }
471                 }
472
473                 if ( qt == NULL ) {
474                         rc = 1;
475                         goto error;
476                 }
477
478                 cq = add_query( op, qm, &query, qt, PC_POSITIVE, 0 );
479                 if ( cq != NULL ) {
480                         cq->expiry_time = expiry_time;
481                         cq->q_uuid = uuid;
482
483                         /* it's now into cq->filter */
484                         BER_BVZERO( &uuid );
485                         query.filter = NULL;
486
487                 } else {
488                         rc = 1;
489                 }
490         }
491
492 error:;
493         if ( query.filter != NULL ) filter_free( query.filter );
494         if ( !BER_BVISNULL( &tempstr ) ) ch_free( tempstr.bv_val );
495         if ( !BER_BVISNULL( &query.base ) ) ch_free( query.base.bv_val );
496         if ( !BER_BVISNULL( &uuid ) ) ch_free( uuid.bv_val );
497         if ( lud != NULL ) ldap_free_urldesc( lud );
498
499         return rc;
500 }
501
502 /* Return 1 for an added entry, else 0 */
503 static int
504 merge_entry(
505         Operation               *op,
506         Entry                   *e,
507         struct berval*          query_uuid )
508 {
509         int             rc;
510         Modifications* modlist = NULL;
511         const char*     text = NULL;
512         Attribute               *attr;
513         char                    textbuf[SLAP_TEXT_BUFLEN];
514         size_t                  textlen = sizeof(textbuf);
515
516         SlapReply sreply = {REP_RESULT};
517
518         slap_callback cb = { NULL, slap_null_cb, NULL, NULL };
519
520         attr = e->e_attrs;
521         e->e_attrs = NULL;
522
523         /* add queryId attribute */
524         attr_merge_one( e, ad_queryId, query_uuid, NULL );
525
526         /* append the attribute list from the fetched entry */
527         e->e_attrs->a_next = attr;
528
529         op->o_tag = LDAP_REQ_ADD;
530         op->o_protocol = LDAP_VERSION3;
531         op->o_callback = &cb;
532         op->o_time = slap_get_time();
533         op->o_do_not_cache = 1;
534
535         op->ora_e = e;
536         op->o_req_dn = e->e_name;
537         op->o_req_ndn = e->e_nname;
538         rc = op->o_bd->be_add( op, &sreply );
539
540         if ( rc != LDAP_SUCCESS ) {
541                 if ( rc == LDAP_ALREADY_EXISTS ) {
542                         slap_entry2mods( e, &modlist, &text, textbuf, textlen );
543                         modlist->sml_op = LDAP_MOD_ADD;
544                         op->o_tag = LDAP_REQ_MODIFY;
545                         op->orm_modlist = modlist;
546                         op->o_bd->be_modify( op, &sreply );
547                         slap_mods_free( modlist, 1 );
548                 } else if ( rc == LDAP_REFERRAL ||
549                                         rc == LDAP_NO_SUCH_OBJECT ) {
550                         syncrepl_add_glue( op, e );
551                         e = NULL;
552                         rc = 1;
553                 }
554                 if ( e ) {
555                         entry_free( e );
556                         rc = 0;
557                 }
558         } else {
559                 if ( op->ora_e == e )
560                         be_entry_release_w( op, e );
561                 rc = 1;
562         }
563
564         return rc;
565 }
566
567 /* Length-ordered sort on normalized DNs */
568 static int pcache_dn_cmp( const void *v1, const void *v2 )
569 {
570         const Qbase *q1 = v1, *q2 = v2;
571
572         int rc = q1->base.bv_len - q2->base.bv_len;
573         if ( rc == 0 )
574                 rc = strncmp( q1->base.bv_val, q2->base.bv_val, q1->base.bv_len );
575         return rc;
576 }
577
578 static int lex_bvcmp( struct berval *bv1, struct berval *bv2 )
579 {
580         int len, dif;
581         dif = bv1->bv_len - bv2->bv_len;
582         len = bv1->bv_len;
583         if ( dif > 0 ) len -= dif;
584         len = memcmp( bv1->bv_val, bv2->bv_val, len );
585         if ( !len )
586                 len = dif;
587         return len;
588 }
589
590 /* compare the first value in each filter */
591 static int pcache_filter_cmp( const void *v1, const void *v2 )
592 {
593         const CachedQuery *q1 = v1, *q2 =v2;
594         int rc, weight1, weight2;
595
596         switch( q1->first->f_choice ) {
597         case LDAP_FILTER_PRESENT:
598                 weight1 = 0;
599                 break;
600         case LDAP_FILTER_EQUALITY:
601         case LDAP_FILTER_GE:
602         case LDAP_FILTER_LE:
603                 weight1 = 1;
604                 break;
605         default:
606                 weight1 = 2;
607         }
608         switch( q2->first->f_choice ) {
609         case LDAP_FILTER_PRESENT:
610                 weight2 = 0;
611                 break;
612         case LDAP_FILTER_EQUALITY:
613         case LDAP_FILTER_GE:
614         case LDAP_FILTER_LE:
615                 weight2 = 1;
616                 break;
617         default:
618                 weight2 = 2;
619         }
620         rc = weight1 - weight2;
621         if ( !rc ) {
622                 switch( weight1 ) {
623                 case 0: return 0;
624                 case 1:
625                         rc = lex_bvcmp( &q1->first->f_av_value, &q2->first->f_av_value );
626                         break;
627                 case 2:
628                         if ( q1->first->f_choice == LDAP_FILTER_SUBSTRINGS ) {
629                                 rc = 0;
630                                 if ( !BER_BVISNULL( &q1->first->f_sub_initial )) {
631                                         if ( !BER_BVISNULL( &q2->first->f_sub_initial )) {
632                                                 rc = lex_bvcmp( &q1->first->f_sub_initial,
633                                                         &q2->first->f_sub_initial );
634                                         } else {
635                                                 rc = 1;
636                                         }
637                                 } else if ( !BER_BVISNULL( &q2->first->f_sub_initial )) {
638                                         rc = -1;
639                                 }
640                                 if ( rc ) break;
641                                 if ( q1->first->f_sub_any ) {
642                                         if ( q2->first->f_sub_any ) {
643                                                 rc = lex_bvcmp( q1->first->f_sub_any,
644                                                         q2->first->f_sub_any );
645                                         } else {
646                                                 rc = 1;
647                                         }
648                                 } else if ( q2->first->f_sub_any ) {
649                                         rc = -1;
650                                 }
651                                 if ( rc ) break;
652                                 if ( !BER_BVISNULL( &q1->first->f_sub_final )) {
653                                         if ( !BER_BVISNULL( &q2->first->f_sub_final )) {
654                                                 rc = lex_bvcmp( &q1->first->f_sub_final,
655                                                         &q2->first->f_sub_final );
656                                         } else {
657                                                 rc = 1;
658                                         }
659                                 } else if ( !BER_BVISNULL( &q2->first->f_sub_final )) {
660                                         rc = -1;
661                                 }
662                         } else {
663                                 rc = lex_bvcmp( &q1->first->f_mr_value,
664                                         &q2->first->f_mr_value );
665                         }
666                         break;
667                 }
668         }
669
670         return rc;
671 }
672
673 /* add query on top of LRU list */
674 static void
675 add_query_on_top (query_manager* qm, CachedQuery* qc)
676 {
677         CachedQuery* top = qm->lru_top;
678
679         qm->lru_top = qc;
680
681         if (top)
682                 top->lru_up = qc;
683         else
684                 qm->lru_bottom = qc;
685
686         qc->lru_down = top;
687         qc->lru_up = NULL;
688         Debug( pcache_debug, "Base of added query = %s\n",
689                         qc->qbase->base.bv_val, 0, 0 );
690 }
691
692 /* remove_query from LRU list */
693
694 static void
695 remove_query (query_manager* qm, CachedQuery* qc)
696 {
697         CachedQuery* up;
698         CachedQuery* down;
699
700         if (!qc)
701                 return;
702
703         up = qc->lru_up;
704         down = qc->lru_down;
705
706         if (!up)
707                 qm->lru_top = down;
708
709         if (!down)
710                 qm->lru_bottom = up;
711
712         if (down)
713                 down->lru_up = up;
714
715         if (up)
716                 up->lru_down = down;
717
718         qc->lru_up = qc->lru_down = NULL;
719 }
720
721 /* find and remove string2 from string1
722  * from start if position = 1,
723  * from end if position = 3,
724  * from anywhere if position = 2
725  * string1 is overwritten if position = 2.
726  */
727
728 static int
729 find_and_remove(struct berval* ber1, struct berval* ber2, int position)
730 {
731         int ret=0;
732
733         if ( !ber2->bv_val )
734                 return 1;
735         if ( !ber1->bv_val )
736                 return 0;
737
738         switch( position ) {
739         case 1:
740                 if ( ber1->bv_len >= ber2->bv_len && !memcmp( ber1->bv_val,
741                         ber2->bv_val, ber2->bv_len )) {
742                         ret = 1;
743                         ber1->bv_val += ber2->bv_len;
744                         ber1->bv_len -= ber2->bv_len;
745                 }
746                 break;
747         case 2: {
748                 char *temp;
749                 ber1->bv_val[ber1->bv_len] = '\0';
750                 temp = strstr( ber1->bv_val, ber2->bv_val );
751                 if ( temp ) {
752                         strcpy( temp, temp+ber2->bv_len );
753                         ber1->bv_len -= ber2->bv_len;
754                         ret = 1;
755                 }
756                 break;
757                 }
758         case 3:
759                 if ( ber1->bv_len >= ber2->bv_len &&
760                         !memcmp( ber1->bv_val+ber1->bv_len-ber2->bv_len, ber2->bv_val,
761                                 ber2->bv_len )) {
762                         ret = 1;
763                         ber1->bv_len -= ber2->bv_len;
764                 }
765                 break;
766         }
767         return ret;
768 }
769
770
771 static struct berval*
772 merge_init_final(Operation *op, struct berval* init, struct berval* any,
773         struct berval* final)
774 {
775         struct berval* merged, *temp;
776         int i, any_count, count;
777
778         for (any_count=0; any && any[any_count].bv_val; any_count++)
779                 ;
780
781         count = any_count;
782
783         if (init->bv_val)
784                 count++;
785         if (final->bv_val)
786                 count++;
787
788         merged = (struct berval*)op->o_tmpalloc( (count+1)*sizeof(struct berval),
789                 op->o_tmpmemctx );
790         temp = merged;
791
792         if (init->bv_val) {
793                 ber_dupbv_x( temp, init, op->o_tmpmemctx );
794                 temp++;
795         }
796
797         for (i=0; i<any_count; i++) {
798                 ber_dupbv_x( temp, any, op->o_tmpmemctx );
799                 temp++; any++;
800         }
801
802         if (final->bv_val){
803                 ber_dupbv_x( temp, final, op->o_tmpmemctx );
804                 temp++;
805         }
806         BER_BVZERO( temp );
807         return merged;
808 }
809
810 /* Each element in stored must be found in incoming. Incoming is overwritten.
811  */
812 static int
813 strings_containment(struct berval* stored, struct berval* incoming)
814 {
815         struct berval* element;
816         int k=0;
817         int j, rc = 0;
818
819         for ( element=stored; element->bv_val != NULL; element++ ) {
820                 for (j = k; incoming[j].bv_val != NULL; j++) {
821                         if (find_and_remove(&(incoming[j]), element, 2)) {
822                                 k = j;
823                                 rc = 1;
824                                 break;
825                         }
826                         rc = 0;
827                 }
828                 if ( rc ) {
829                         continue;
830                 } else {
831                         return 0;
832                 }
833         }
834         return 1;
835 }
836
837 static int
838 substr_containment_substr(Operation *op, Filter* stored, Filter* incoming)
839 {
840         int rc = 0;
841
842         struct berval init_incoming;
843         struct berval final_incoming;
844         struct berval *remaining_incoming = NULL;
845
846         if ((!(incoming->f_sub_initial.bv_val) && (stored->f_sub_initial.bv_val))
847            || (!(incoming->f_sub_final.bv_val) && (stored->f_sub_final.bv_val)))
848                 return 0;
849
850         init_incoming = incoming->f_sub_initial;
851         final_incoming =  incoming->f_sub_final;
852
853         if (find_and_remove(&init_incoming,
854                         &(stored->f_sub_initial), 1) && find_and_remove(&final_incoming,
855                         &(stored->f_sub_final), 3))
856         {
857                 if (stored->f_sub_any == NULL) {
858                         rc = 1;
859                         goto final;
860                 }
861                 remaining_incoming = merge_init_final(op, &init_incoming,
862                                                 incoming->f_sub_any, &final_incoming);
863                 rc = strings_containment(stored->f_sub_any, remaining_incoming);
864                 ber_bvarray_free_x( remaining_incoming, op->o_tmpmemctx );
865         }
866 final:
867         return rc;
868 }
869
870 static int
871 substr_containment_equality(Operation *op, Filter* stored, Filter* incoming)
872 {
873         struct berval incoming_val[2];
874         int rc = 0;
875
876         incoming_val[1] = incoming->f_av_value;
877
878         if (find_and_remove(incoming_val+1,
879                         &(stored->f_sub_initial), 1) && find_and_remove(incoming_val+1,
880                         &(stored->f_sub_final), 3)) {
881                 if (stored->f_sub_any == NULL){
882                         rc = 1;
883                         goto final;
884                 }
885                 ber_dupbv_x( incoming_val, incoming_val+1, op->o_tmpmemctx );
886                 BER_BVZERO( incoming_val+1 );
887                 rc = strings_containment(stored->f_sub_any, incoming_val);
888                 op->o_tmpfree( incoming_val[0].bv_val, op->o_tmpmemctx );
889         }
890 final:
891         return rc;
892 }
893
894 static Filter *
895 filter_first( Filter *f )
896 {
897         while ( f->f_choice == LDAP_FILTER_OR || f->f_choice == LDAP_FILTER_AND )
898                 f = f->f_and;
899         return f;
900 }
901
902
903 static CachedQuery *
904 find_filter( Operation *op, Avlnode *root, Filter *inputf, Filter *first )
905 {
906         Filter* fs;
907         Filter* fi;
908         MatchingRule* mrule = NULL;
909         int res=0, eqpass= 0;
910         int ret, rc, dir;
911         Avlnode *ptr;
912         CachedQuery cq, *qc;
913
914         cq.filter = inputf;
915         cq.first = first;
916
917         /* substring matches sort to the end, and we just have to
918          * walk the entire list.
919          */
920         if ( first->f_choice == LDAP_FILTER_SUBSTRINGS ) {
921                 ptr = tavl_end( root, 1 );
922                 dir = TAVL_DIR_LEFT;
923         } else {
924                 ptr = tavl_find3( root, &cq, pcache_filter_cmp, &ret );
925                 dir = (first->f_choice == LDAP_FILTER_GE) ? TAVL_DIR_LEFT :
926                         TAVL_DIR_RIGHT;
927         }
928
929         while (ptr) {
930                 qc = ptr->avl_data;
931                 fi = inputf;
932                 fs = qc->filter;
933
934                 /* an incoming substr query can only be satisfied by a cached
935                  * substr query.
936                  */
937                 if ( first->f_choice == LDAP_FILTER_SUBSTRINGS &&
938                         qc->first->f_choice != LDAP_FILTER_SUBSTRINGS )
939                         break;
940
941                 /* an incoming eq query can be satisfied by a cached eq or substr
942                  * query
943                  */
944                 if ( first->f_choice == LDAP_FILTER_EQUALITY ) {
945                         if ( eqpass == 0 ) {
946                                 if ( qc->first->f_choice != LDAP_FILTER_EQUALITY ) {
947 nextpass:                       eqpass = 1;
948                                         ptr = tavl_end( root, 1 );
949                                         dir = TAVL_DIR_LEFT;
950                                         continue;
951                                 }
952                         } else {
953                                 if ( qc->first->f_choice != LDAP_FILTER_SUBSTRINGS )
954                                         break;
955                         }
956                 }
957                 do {
958                         res=0;
959                         switch (fs->f_choice) {
960                         case LDAP_FILTER_EQUALITY:
961                                 if (fi->f_choice == LDAP_FILTER_EQUALITY)
962                                         mrule = fs->f_ava->aa_desc->ad_type->sat_equality;
963                                 else
964                                         ret = 1;
965                                 break;
966                         case LDAP_FILTER_GE:
967                         case LDAP_FILTER_LE:
968                                 mrule = fs->f_ava->aa_desc->ad_type->sat_ordering;
969                                 break;
970                         default:
971                                 mrule = NULL; 
972                         }
973                         if (mrule) {
974                                 const char *text;
975                                 rc = value_match(&ret, fs->f_ava->aa_desc, mrule,
976                                         SLAP_MR_VALUE_OF_ASSERTION_SYNTAX,
977                                         &(fi->f_ava->aa_value),
978                                         &(fs->f_ava->aa_value), &text);
979                                 if (rc != LDAP_SUCCESS) {
980                                         return NULL;
981                                 }
982                                 if ( fi==first && fi->f_choice==LDAP_FILTER_EQUALITY && ret )
983                                         goto nextpass;
984                         }
985                         switch (fs->f_choice) {
986                         case LDAP_FILTER_OR:
987                         case LDAP_FILTER_AND:
988                                 fs = fs->f_and;
989                                 fi = fi->f_and;
990                                 res=1;
991                                 break;
992                         case LDAP_FILTER_SUBSTRINGS:
993                                 /* check if the equality query can be
994                                 * answered with cached substring query */
995                                 if ((fi->f_choice == LDAP_FILTER_EQUALITY)
996                                         && substr_containment_equality( op,
997                                         fs, fi))
998                                         res=1;
999                                 /* check if the substring query can be
1000                                 * answered with cached substring query */
1001                                 if ((fi->f_choice ==LDAP_FILTER_SUBSTRINGS
1002                                         ) && substr_containment_substr( op,
1003                                         fs, fi))
1004                                         res= 1;
1005                                 fs=fs->f_next;
1006                                 fi=fi->f_next;
1007                                 break;
1008                         case LDAP_FILTER_PRESENT:
1009                                 res=1;
1010                                 fs=fs->f_next;
1011                                 fi=fi->f_next;
1012                                 break;
1013                         case LDAP_FILTER_EQUALITY:
1014                                 if (ret == 0)
1015                                         res = 1;
1016                                 fs=fs->f_next;
1017                                 fi=fi->f_next;
1018                                 break;
1019                         case LDAP_FILTER_GE:
1020                                 if (mrule && ret >= 0)
1021                                         res = 1;
1022                                 fs=fs->f_next;
1023                                 fi=fi->f_next;
1024                                 break;
1025                         case LDAP_FILTER_LE:
1026                                 if (mrule && ret <= 0)
1027                                         res = 1;
1028                                 fs=fs->f_next;
1029                                 fi=fi->f_next;
1030                                 break;
1031                         case LDAP_FILTER_NOT:
1032                                 res=0;
1033                                 break;
1034                         default:
1035                                 break;
1036                         }
1037                 } while((res) && (fi != NULL) && (fs != NULL));
1038
1039                 if ( res )
1040                         return qc;
1041                 ptr = tavl_next( ptr, dir );
1042         }
1043         return NULL;
1044 }
1045
1046 /* check whether query is contained in any of
1047  * the cached queries in template
1048  */
1049 static CachedQuery *
1050 query_containment(Operation *op, query_manager *qm,
1051                   Query *query,
1052                   QueryTemplate *templa)
1053 {
1054         CachedQuery* qc;
1055         int depth = 0, tscope;
1056         Qbase qbase, *qbptr = NULL;
1057         struct berval pdn;
1058
1059         if (query->filter != NULL) {
1060                 Filter *first;
1061
1062                 Debug( pcache_debug, "Lock QC index = %p\n",
1063                                 (void *) templa, 0, 0 );
1064                 qbase.base = query->base;
1065
1066                 first = filter_first( query->filter );
1067
1068                 ldap_pvt_thread_rdwr_rlock(&templa->t_rwlock);
1069                 for( ;; ) {
1070                         /* Find the base */
1071                         qbptr = avl_find( templa->qbase, &qbase, pcache_dn_cmp );
1072                         if ( qbptr ) {
1073                                 tscope = query->scope;
1074                                 /* Find a matching scope:
1075                                  * match at depth 0 OK
1076                                  * scope is BASE,
1077                                  *      one at depth 1 OK
1078                                  *  subord at depth > 0 OK
1079                                  *      subtree at any depth OK
1080                                  * scope is ONE,
1081                                  *  subtree or subord at any depth OK
1082                                  * scope is SUBORD,
1083                                  *  subtree or subord at any depth OK
1084                                  * scope is SUBTREE,
1085                                  *  subord at depth > 0 OK
1086                                  *  subtree at any depth OK
1087                                  */
1088                                 for ( tscope = 0 ; tscope <= LDAP_SCOPE_CHILDREN; tscope++ ) {
1089                                         switch ( query->scope ) {
1090                                         case LDAP_SCOPE_BASE:
1091                                                 if ( tscope == LDAP_SCOPE_BASE && depth ) continue;
1092                                                 if ( tscope == LDAP_SCOPE_ONE && depth != 1) continue;
1093                                                 if ( tscope == LDAP_SCOPE_CHILDREN && !depth ) continue;
1094                                                 break;
1095                                         case LDAP_SCOPE_ONE:
1096                                                 if ( tscope == LDAP_SCOPE_BASE )
1097                                                         tscope = LDAP_SCOPE_ONE;
1098                                                 if ( tscope == LDAP_SCOPE_ONE && depth ) continue;
1099                                                 if ( !depth ) break;
1100                                                 if ( tscope < LDAP_SCOPE_SUBTREE )
1101                                                         tscope = LDAP_SCOPE_SUBTREE;
1102                                                 break;
1103                                         case LDAP_SCOPE_SUBTREE:
1104                                                 if ( tscope < LDAP_SCOPE_SUBTREE )
1105                                                         tscope = LDAP_SCOPE_SUBTREE;
1106                                                 if ( tscope == LDAP_SCOPE_CHILDREN && !depth ) continue;
1107                                                 break;
1108                                         case LDAP_SCOPE_CHILDREN:
1109                                                 if ( tscope < LDAP_SCOPE_SUBTREE )
1110                                                         tscope = LDAP_SCOPE_SUBTREE;
1111                                                 break;
1112                                         }
1113                                         if ( !qbptr->scopes[tscope] ) continue;
1114
1115                                         /* Find filter */
1116                                         qc = find_filter( op, qbptr->scopes[tscope],
1117                                                         query->filter, first );
1118                                         if ( qc ) {
1119                                                 if ( qc->q_sizelimit ) {
1120                                                         ldap_pvt_thread_rdwr_runlock(&templa->t_rwlock);
1121                                                         return NULL;
1122                                                 }
1123                                                 ldap_pvt_thread_mutex_lock(&qm->lru_mutex);
1124                                                 if (qm->lru_top != qc) {
1125                                                         remove_query(qm, qc);
1126                                                         add_query_on_top(qm, qc);
1127                                                 }
1128                                                 ldap_pvt_thread_mutex_unlock(&qm->lru_mutex);
1129                                                 return qc;
1130                                         }
1131                                 }
1132                         }
1133                         if ( be_issuffix( op->o_bd, &qbase.base ))
1134                                 break;
1135                         /* Up a level */
1136                         dnParent( &qbase.base, &pdn );
1137                         qbase.base = pdn;
1138                         depth++;
1139                 }
1140
1141                 Debug( pcache_debug,
1142                         "Not answerable: Unlock QC index=%p\n",
1143                         (void *) templa, 0, 0 );
1144                 ldap_pvt_thread_rdwr_runlock(&templa->t_rwlock);
1145         }
1146         return NULL;
1147 }
1148
1149 static void
1150 free_query (CachedQuery* qc)
1151 {
1152         free(qc->q_uuid.bv_val);
1153         filter_free(qc->filter);
1154         free(qc);
1155 }
1156
1157
1158 /* Add query to query cache, the returned Query is locked for writing */
1159 static CachedQuery *
1160 add_query(
1161         Operation *op,
1162         query_manager* qm,
1163         Query* query,
1164         QueryTemplate *templ,
1165         pc_caching_reason_t why,
1166         int wlock)
1167 {
1168         CachedQuery* new_cached_query = (CachedQuery*) ch_malloc(sizeof(CachedQuery));
1169         Qbase *qbase, qb;
1170         Filter *first;
1171         int rc;
1172         time_t ttl = 0;;
1173
1174         new_cached_query->qtemp = templ;
1175         BER_BVZERO( &new_cached_query->q_uuid );
1176         new_cached_query->q_sizelimit = 0;
1177
1178         switch ( why ) {
1179         case PC_POSITIVE:
1180                 ttl = templ->ttl;
1181                 break;
1182
1183         case PC_NEGATIVE:
1184                 ttl = templ->negttl;
1185                 break;
1186
1187         case PC_SIZELIMIT:
1188                 ttl = templ->limitttl;
1189                 break;
1190
1191         default:
1192                 assert( 0 );
1193                 break;
1194         }
1195         new_cached_query->expiry_time = slap_get_time() + ttl;
1196         new_cached_query->lru_up = NULL;
1197         new_cached_query->lru_down = NULL;
1198         Debug( pcache_debug, "Added query expires at %ld (%s)\n",
1199                         (long) new_cached_query->expiry_time,
1200                         pc_caching_reason_str[ why ], 0 );
1201
1202         new_cached_query->scope = query->scope;
1203         new_cached_query->filter = query->filter;
1204         new_cached_query->first = first = filter_first( query->filter );
1205         
1206         ldap_pvt_thread_rdwr_init(&new_cached_query->rwlock);
1207         if (wlock)
1208                 ldap_pvt_thread_rdwr_wlock(&new_cached_query->rwlock);
1209
1210         qb.base = query->base;
1211
1212         /* Adding a query    */
1213         Debug( pcache_debug, "Lock AQ index = %p\n",
1214                         (void *) templ, 0, 0 );
1215         ldap_pvt_thread_rdwr_wlock(&templ->t_rwlock);
1216         qbase = avl_find( templ->qbase, &qb, pcache_dn_cmp );
1217         if ( !qbase ) {
1218                 qbase = ch_calloc( 1, sizeof(Qbase) + qb.base.bv_len + 1 );
1219                 qbase->base.bv_len = qb.base.bv_len;
1220                 qbase->base.bv_val = (char *)(qbase+1);
1221                 memcpy( qbase->base.bv_val, qb.base.bv_val, qb.base.bv_len );
1222                 qbase->base.bv_val[qbase->base.bv_len] = '\0';
1223                 avl_insert( &templ->qbase, qbase, pcache_dn_cmp, avl_dup_error );
1224         }
1225         new_cached_query->next = templ->query;
1226         new_cached_query->prev = NULL;
1227         new_cached_query->qbase = qbase;
1228         rc = tavl_insert( &qbase->scopes[query->scope], new_cached_query,
1229                 pcache_filter_cmp, avl_dup_error );
1230         if ( rc == 0 ) {
1231                 qbase->queries++;
1232                 if (templ->query == NULL)
1233                         templ->query_last = new_cached_query;
1234                 else
1235                         templ->query->prev = new_cached_query;
1236                 templ->query = new_cached_query;
1237                 templ->no_of_queries++;
1238         } else {
1239                 ch_free( new_cached_query );
1240                 new_cached_query = find_filter( op, qbase->scopes[query->scope],
1241                                                         query->filter, first );
1242                 filter_free( query->filter );
1243         }
1244         Debug( pcache_debug, "TEMPLATE %p QUERIES++ %d\n",
1245                         (void *) templ, templ->no_of_queries, 0 );
1246
1247         Debug( pcache_debug, "Unlock AQ index = %p \n",
1248                         (void *) templ, 0, 0 );
1249         ldap_pvt_thread_rdwr_wunlock(&templ->t_rwlock);
1250
1251         /* Adding on top of LRU list  */
1252         if ( rc == 0 ) {
1253                 ldap_pvt_thread_mutex_lock(&qm->lru_mutex);
1254                 add_query_on_top(qm, new_cached_query);
1255                 ldap_pvt_thread_mutex_unlock(&qm->lru_mutex);
1256         }
1257         return rc == 0 ? new_cached_query : NULL;
1258 }
1259
1260 static void
1261 remove_from_template (CachedQuery* qc, QueryTemplate* template)
1262 {
1263         if (!qc->prev && !qc->next) {
1264                 template->query_last = template->query = NULL;
1265         } else if (qc->prev == NULL) {
1266                 qc->next->prev = NULL;
1267                 template->query = qc->next;
1268         } else if (qc->next == NULL) {
1269                 qc->prev->next = NULL;
1270                 template->query_last = qc->prev;
1271         } else {
1272                 qc->next->prev = qc->prev;
1273                 qc->prev->next = qc->next;
1274         }
1275         tavl_delete( &qc->qbase->scopes[qc->scope], qc, pcache_filter_cmp );
1276         qc->qbase->queries--;
1277         if ( qc->qbase->queries == 0 ) {
1278                 avl_delete( &template->qbase, qc->qbase, pcache_dn_cmp );
1279                 ch_free( qc->qbase );
1280                 qc->qbase = NULL;
1281         }
1282
1283         template->no_of_queries--;
1284 }
1285
1286 /* remove bottom query of LRU list from the query cache */
1287 /*
1288  * NOTE: slight change in functionality.
1289  *
1290  * - if result->bv_val is NULL, the query at the bottom of the LRU
1291  *   is removed
1292  * - otherwise, the query whose UUID is *result is removed
1293  *      - if not found, result->bv_val is zeroed
1294  */
1295 static void
1296 cache_replacement(query_manager* qm, struct berval *result)
1297 {
1298         CachedQuery* bottom;
1299         QueryTemplate *temp;
1300
1301         ldap_pvt_thread_mutex_lock(&qm->lru_mutex);
1302         if ( BER_BVISNULL( result ) ) {
1303                 bottom = qm->lru_bottom;
1304
1305                 if (!bottom) {
1306                         Debug ( pcache_debug,
1307                                 "Cache replacement invoked without "
1308                                 "any query in LRU list\n", 0, 0, 0 );
1309                         ldap_pvt_thread_mutex_unlock(&qm->lru_mutex);
1310                         return;
1311                 }
1312
1313         } else {
1314                 for ( bottom = qm->lru_bottom;
1315                         bottom != NULL;
1316                         bottom = bottom->lru_up )
1317                 {
1318                         if ( bvmatch( result, &bottom->q_uuid ) ) {
1319                                 break;
1320                         }
1321                 }
1322
1323                 if ( !bottom ) {
1324                         Debug ( pcache_debug,
1325                                 "Could not find query with uuid=\"%s\""
1326                                 "in LRU list\n", result->bv_val, 0, 0 );
1327                         ldap_pvt_thread_mutex_unlock(&qm->lru_mutex);
1328                         BER_BVZERO( result );
1329                         return;
1330                 }
1331         }
1332
1333         temp = bottom->qtemp;
1334         remove_query(qm, bottom);
1335         ldap_pvt_thread_mutex_unlock(&qm->lru_mutex);
1336
1337         *result = bottom->q_uuid;
1338         BER_BVZERO( &bottom->q_uuid );
1339
1340         Debug( pcache_debug, "Lock CR index = %p\n", (void *) temp, 0, 0 );
1341         ldap_pvt_thread_rdwr_wlock(&temp->t_rwlock);
1342         remove_from_template(bottom, temp);
1343         Debug( pcache_debug, "TEMPLATE %p QUERIES-- %d\n",
1344                 (void *) temp, temp->no_of_queries, 0 );
1345         Debug( pcache_debug, "Unlock CR index = %p\n", (void *) temp, 0, 0 );
1346         ldap_pvt_thread_rdwr_wunlock(&temp->t_rwlock);
1347         free_query(bottom);
1348 }
1349
1350 struct query_info {
1351         struct query_info *next;
1352         struct berval xdn;
1353         int del;
1354 };
1355
1356 static int
1357 remove_func (
1358         Operation       *op,
1359         SlapReply       *rs
1360 )
1361 {
1362         Attribute *attr;
1363         struct query_info *qi;
1364         int count = 0;
1365
1366         if ( rs->sr_type != REP_SEARCH ) return 0;
1367
1368         attr = attr_find( rs->sr_entry->e_attrs,  ad_queryId );
1369         if ( attr == NULL ) return 0;
1370
1371         count = attr->a_numvals;
1372         assert( count > 0 );
1373         qi = op->o_tmpalloc( sizeof( struct query_info ), op->o_tmpmemctx );
1374         qi->next = op->o_callback->sc_private;
1375         op->o_callback->sc_private = qi;
1376         ber_dupbv_x( &qi->xdn, &rs->sr_entry->e_nname, op->o_tmpmemctx );
1377         qi->del = ( count == 1 );
1378
1379         return 0;
1380 }
1381
1382 static int
1383 remove_query_data(
1384         Operation       *op,
1385         SlapReply       *rs,
1386         struct berval   *query_uuid )
1387 {
1388         struct query_info       *qi, *qnext;
1389         char                    filter_str[ LDAP_LUTIL_UUIDSTR_BUFSIZE + STRLENOF( "(queryId=)" ) ];
1390         AttributeAssertion      ava = ATTRIBUTEASSERTION_INIT;
1391         Filter                  filter = {LDAP_FILTER_EQUALITY};
1392         SlapReply               sreply = {REP_RESULT};
1393         slap_callback cb = { NULL, remove_func, NULL, NULL };
1394         int deleted = 0;
1395
1396         sreply.sr_entry = NULL;
1397         sreply.sr_nentries = 0;
1398         op->ors_filterstr.bv_len = snprintf(filter_str, sizeof(filter_str),
1399                 "(%s=%s)", ad_queryId->ad_cname.bv_val, query_uuid->bv_val);
1400         filter.f_ava = &ava;
1401         filter.f_av_desc = ad_queryId;
1402         filter.f_av_value = *query_uuid;
1403
1404         op->o_tag = LDAP_REQ_SEARCH;
1405         op->o_protocol = LDAP_VERSION3;
1406         op->o_callback = &cb;
1407         op->o_time = slap_get_time();
1408         op->o_do_not_cache = 1;
1409
1410         op->o_req_dn = op->o_bd->be_suffix[0];
1411         op->o_req_ndn = op->o_bd->be_nsuffix[0];
1412         op->ors_scope = LDAP_SCOPE_SUBTREE;
1413         op->ors_deref = LDAP_DEREF_NEVER;
1414         op->ors_slimit = SLAP_NO_LIMIT;
1415         op->ors_tlimit = SLAP_NO_LIMIT;
1416         op->ors_filter = &filter;
1417         op->ors_filterstr.bv_val = filter_str;
1418         op->ors_filterstr.bv_len = strlen(filter_str);
1419         op->ors_attrs = NULL;
1420         op->ors_attrsonly = 0;
1421
1422         op->o_bd->be_search( op, &sreply );
1423
1424         for ( qi=cb.sc_private; qi; qi=qnext ) {
1425                 qnext = qi->next;
1426
1427                 op->o_req_dn = qi->xdn;
1428                 op->o_req_ndn = qi->xdn;
1429
1430                 if ( qi->del ) {
1431                         Debug( pcache_debug, "DELETING ENTRY TEMPLATE=%s\n",
1432                                 query_uuid->bv_val, 0, 0 );
1433
1434                         op->o_tag = LDAP_REQ_DELETE;
1435
1436                         if (op->o_bd->be_delete(op, &sreply) == LDAP_SUCCESS) {
1437                                 deleted++;
1438                         }
1439
1440                 } else {
1441                         Modifications mod;
1442                         struct berval vals[2];
1443
1444                         vals[0] = *query_uuid;
1445                         vals[1].bv_val = NULL;
1446                         vals[1].bv_len = 0;
1447                         mod.sml_op = LDAP_MOD_DELETE;
1448                         mod.sml_flags = 0;
1449                         mod.sml_desc = ad_queryId;
1450                         mod.sml_type = ad_queryId->ad_cname;
1451                         mod.sml_values = vals;
1452                         mod.sml_nvalues = NULL;
1453                         mod.sml_numvals = 1;
1454                         mod.sml_next = NULL;
1455                         Debug( pcache_debug,
1456                                 "REMOVING TEMP ATTR : TEMPLATE=%s\n",
1457                                 query_uuid->bv_val, 0, 0 );
1458
1459                         op->orm_modlist = &mod;
1460
1461                         op->o_bd->be_modify( op, &sreply );
1462                 }
1463                 op->o_tmpfree( qi->xdn.bv_val, op->o_tmpmemctx );
1464                 op->o_tmpfree( qi, op->o_tmpmemctx );
1465         }
1466         return deleted;
1467 }
1468
1469 static int
1470 get_attr_set(
1471         AttributeName* attrs,
1472         query_manager* qm,
1473         int num
1474 );
1475
1476 static int
1477 filter2template(
1478         Operation               *op,
1479         Filter                  *f,
1480         struct                  berval *fstr,
1481         AttributeName**         filter_attrs,
1482         int*                    filter_cnt,
1483         int*                    filter_got_oc )
1484 {
1485         AttributeDescription *ad;
1486         int len, ret;
1487
1488         switch ( f->f_choice ) {
1489         case LDAP_FILTER_EQUALITY:
1490                 ad = f->f_av_desc;
1491                 len = STRLENOF( "(=)" ) + ad->ad_cname.bv_len;
1492                 ret = snprintf( fstr->bv_val+fstr->bv_len, len + 1, "(%s=)", ad->ad_cname.bv_val );
1493                 assert( ret == len );
1494                 fstr->bv_len += len;
1495                 break;
1496
1497         case LDAP_FILTER_GE:
1498                 ad = f->f_av_desc;
1499                 len = STRLENOF( "(>=)" ) + ad->ad_cname.bv_len;
1500                 ret = snprintf( fstr->bv_val+fstr->bv_len, len + 1, "(%s>=)", ad->ad_cname.bv_val);
1501                 assert( ret == len );
1502                 fstr->bv_len += len;
1503                 break;
1504
1505         case LDAP_FILTER_LE:
1506                 ad = f->f_av_desc;
1507                 len = STRLENOF( "(<=)" ) + ad->ad_cname.bv_len;
1508                 ret = snprintf( fstr->bv_val+fstr->bv_len, len + 1, "(%s<=)", ad->ad_cname.bv_val);
1509                 assert( ret == len );
1510                 fstr->bv_len += len;
1511                 break;
1512
1513         case LDAP_FILTER_APPROX:
1514                 ad = f->f_av_desc;
1515                 len = STRLENOF( "(~=)" ) + ad->ad_cname.bv_len;
1516                 ret = snprintf( fstr->bv_val+fstr->bv_len, len + 1, "(%s~=)", ad->ad_cname.bv_val);
1517                 assert( ret == len );
1518                 fstr->bv_len += len;
1519                 break;
1520
1521         case LDAP_FILTER_SUBSTRINGS:
1522                 ad = f->f_sub_desc;
1523                 len = STRLENOF( "(=)" ) + ad->ad_cname.bv_len;
1524                 ret = snprintf( fstr->bv_val+fstr->bv_len, len + 1, "(%s=)", ad->ad_cname.bv_val );
1525                 assert( ret == len );
1526                 fstr->bv_len += len;
1527                 break;
1528
1529         case LDAP_FILTER_PRESENT:
1530                 ad = f->f_desc;
1531                 len = STRLENOF( "(=*)" ) + ad->ad_cname.bv_len;
1532                 ret = snprintf( fstr->bv_val+fstr->bv_len, len + 1, "(%s=*)", ad->ad_cname.bv_val );
1533                 assert( ret == len );
1534                 fstr->bv_len += len;
1535                 break;
1536
1537         case LDAP_FILTER_AND:
1538         case LDAP_FILTER_OR:
1539         case LDAP_FILTER_NOT: {
1540                 int rc = 0;
1541                 fstr->bv_val[fstr->bv_len++] = '(';
1542                 switch ( f->f_choice ) {
1543                 case LDAP_FILTER_AND:
1544                         fstr->bv_val[fstr->bv_len] = '&';
1545                         break;
1546                 case LDAP_FILTER_OR:
1547                         fstr->bv_val[fstr->bv_len] = '|';
1548                         break;
1549                 case LDAP_FILTER_NOT:
1550                         fstr->bv_val[fstr->bv_len] = '!';
1551                         break;
1552                 }
1553                 fstr->bv_len++;
1554
1555                 for ( f = f->f_list; f != NULL; f = f->f_next ) {
1556                         rc = filter2template( op, f, fstr, filter_attrs, filter_cnt,
1557                                 filter_got_oc );
1558                         if ( rc ) break;
1559                 }
1560                 fstr->bv_val[fstr->bv_len++] = ')';
1561                 fstr->bv_val[fstr->bv_len] = '\0';
1562
1563                 return rc;
1564                 }
1565
1566         default:
1567                 /* a filter should at least have room for "()",
1568                  * an "=" and for a 1-char attr */
1569                 strcpy( fstr->bv_val, "(?=)" );
1570                 fstr->bv_len += STRLENOF("(?=)");
1571                 return -1;
1572         }
1573
1574         if ( filter_attrs != NULL ) {
1575                 *filter_attrs = (AttributeName *)op->o_tmprealloc(*filter_attrs,
1576                                 (*filter_cnt + 2)*sizeof(AttributeName), op->o_tmpmemctx);
1577
1578                 (*filter_attrs)[*filter_cnt].an_desc = ad;
1579                 (*filter_attrs)[*filter_cnt].an_name = ad->ad_cname;
1580                 (*filter_attrs)[*filter_cnt].an_oc = NULL;
1581                 (*filter_attrs)[*filter_cnt].an_oc_exclude = 0;
1582                 BER_BVZERO( &(*filter_attrs)[*filter_cnt+1].an_name );
1583                 (*filter_cnt)++;
1584                 if ( ad == slap_schema.si_ad_objectClass )
1585                         *filter_got_oc = 1;
1586         }
1587
1588         return 0;
1589 }
1590
1591 struct search_info {
1592         slap_overinst *on;
1593         Query query;
1594         QueryTemplate *qtemp;
1595         AttributeName*  save_attrs;     /* original attributes, saved for response */
1596         int swap_saved_attrs;
1597         int max;
1598         int over;
1599         int count;
1600         int slimit;
1601         int slimit_exceeded;
1602         pc_caching_reason_t caching_reason;
1603         Entry *head, *tail;
1604 };
1605
1606 static void
1607 remove_query_and_data(
1608         Operation       *op,
1609         SlapReply       *rs,
1610         cache_manager   *cm,
1611         struct berval   *uuid )
1612 {
1613         query_manager*          qm = cm->qm;
1614
1615         qm->crfunc( qm, uuid );
1616         if ( !BER_BVISNULL( uuid ) ) {
1617                 int     return_val;
1618
1619                 Debug( pcache_debug,
1620                         "Removing query UUID %s\n",
1621                         uuid->bv_val, 0, 0 );
1622                 return_val = remove_query_data( op, rs, uuid );
1623                 Debug( pcache_debug,
1624                         "QUERY REMOVED, SIZE=%d\n",
1625                         return_val, 0, 0);
1626                 ldap_pvt_thread_mutex_lock( &cm->cache_mutex );
1627                 cm->cur_entries -= return_val;
1628                 cm->num_cached_queries--;
1629                 Debug( pcache_debug,
1630                         "STORED QUERIES = %lu\n",
1631                         cm->num_cached_queries, 0, 0 );
1632                 ldap_pvt_thread_mutex_unlock( &cm->cache_mutex );
1633                 Debug( pcache_debug,
1634                         "QUERY REMOVED, CACHE ="
1635                         "%d entries\n",
1636                         cm->cur_entries, 0, 0 );
1637         }
1638 }
1639
1640 /*
1641  * Callback used to fetch queryId values based on entryUUID;
1642  * used by pcache_remove_entries_from_cache()
1643  */
1644 static int
1645 fetch_queryId_cb( Operation *op, SlapReply *rs )
1646 {
1647         int             rc = 0;
1648
1649         /* only care about searchEntry responses */
1650         if ( rs->sr_type != REP_SEARCH ) {
1651                 return 0;
1652         }
1653
1654         /* allow only one response per entryUUID */
1655         if ( op->o_callback->sc_private != NULL ) {
1656                 rc = 1;
1657
1658         } else {
1659                 Attribute       *a;
1660
1661                 /* copy all queryId values into callback's private data */
1662                 a = attr_find( rs->sr_entry->e_attrs, ad_queryId );
1663                 if ( a != NULL ) {
1664                         BerVarray       vals = NULL;
1665
1666                         ber_bvarray_dup_x( &vals, a->a_nvals, op->o_tmpmemctx );
1667                         op->o_callback->sc_private = (void *)vals;
1668                 }
1669         }
1670
1671         /* clear entry if required */
1672         if ( rs->sr_flags & REP_ENTRY_MUSTBEFREED ) {
1673                 entry_free( rs->sr_entry );
1674                 rs->sr_entry = NULL;
1675                 rs->sr_flags ^= REP_ENTRY_MUSTBEFREED;
1676         }
1677
1678         return rc;
1679 }
1680
1681 /*
1682  * Call that allows to remove a set of entries from the cache,
1683  * by forcing the removal of all the related queries.
1684  */
1685 int
1686 pcache_remove_entries_from_cache(
1687         Operation       *op,
1688         cache_manager   *cm,
1689         BerVarray       entryUUIDs )
1690 {
1691         Connection      conn = { 0 };
1692         OperationBuffer opbuf;
1693         Operation       op2;
1694         slap_callback   sc = { 0 };
1695         SlapReply       rs = { REP_RESULT };
1696         Filter          f = { 0 };
1697         char            filtbuf[ LDAP_LUTIL_UUIDSTR_BUFSIZE + STRLENOF( "(entryUUID=)" ) ];
1698         AttributeAssertion ava = ATTRIBUTEASSERTION_INIT;
1699         AttributeName   attrs[ 2 ] = { 0 };
1700         int             s, rc;
1701
1702         if ( op == NULL ) {
1703                 void    *thrctx = ldap_pvt_thread_pool_context();
1704
1705                 connection_fake_init( &conn, &opbuf, thrctx );
1706                 op = &opbuf.ob_op;
1707
1708         } else {
1709                 op2 = *op;
1710                 op = &op2;
1711         }
1712
1713         memset( &op->oq_search, 0, sizeof( op->oq_search ) );
1714         op->ors_scope = LDAP_SCOPE_SUBTREE;
1715         op->ors_deref = LDAP_DEREF_NEVER;
1716         f.f_choice = LDAP_FILTER_EQUALITY;
1717         f.f_ava = &ava;
1718         ava.aa_desc = slap_schema.si_ad_entryUUID;
1719         op->ors_filter = &f;
1720         op->ors_slimit = 1;
1721         op->ors_tlimit = SLAP_NO_LIMIT;
1722         attrs[ 0 ].an_desc = ad_queryId;
1723         attrs[ 0 ].an_name = ad_queryId->ad_cname;
1724         op->ors_attrs = attrs;
1725         op->ors_attrsonly = 0;
1726
1727         op->o_req_dn = cm->db.be_suffix[ 0 ];
1728         op->o_req_ndn = cm->db.be_nsuffix[ 0 ];
1729
1730         op->o_tag = LDAP_REQ_SEARCH;
1731         op->o_protocol = LDAP_VERSION3;
1732         op->o_managedsait = SLAP_CONTROL_CRITICAL;
1733         op->o_bd = &cm->db;
1734         op->o_dn = op->o_bd->be_rootdn;
1735         op->o_ndn = op->o_bd->be_rootndn;
1736         sc.sc_response = fetch_queryId_cb;
1737         op->o_callback = &sc;
1738
1739         for ( s = 0; !BER_BVISNULL( &entryUUIDs[ s ] ); s++ ) {
1740                 BerVarray       vals = NULL;
1741
1742                 op->ors_filterstr.bv_len = snprintf( filtbuf, sizeof( filtbuf ),
1743                         "(entryUUID=%s)", entryUUIDs[ s ].bv_val );
1744                 op->ors_filterstr.bv_val = filtbuf;
1745                 ava.aa_value = entryUUIDs[ s ];
1746
1747                 rc = op->o_bd->be_search( op, &rs );
1748                 if ( rc != LDAP_SUCCESS ) {
1749                         continue;
1750                 }
1751
1752                 vals = (BerVarray)op->o_callback->sc_private;
1753                 if ( vals != NULL ) {
1754                         int             i;
1755
1756                         for ( i = 0; !BER_BVISNULL( &vals[ i ] ); i++ ) {
1757                                 struct berval   val = vals[ i ];
1758
1759                                 remove_query_and_data( op, &rs, cm, &val );
1760
1761                                 if ( !BER_BVISNULL( &val ) && val.bv_val != vals[ i ].bv_val ) {
1762                                         ch_free( val.bv_val );
1763                                 }
1764                         }
1765
1766                         ber_bvarray_free_x( vals, op->o_tmpmemctx );
1767                         op->o_callback->sc_private = NULL;
1768                 }
1769         }
1770
1771         return 0;
1772 }
1773
1774 /*
1775  * Call that allows to remove a query from the cache.
1776  */
1777 int
1778 pcache_remove_query_from_cache(
1779         Operation       *op,
1780         cache_manager   *cm,
1781         struct berval   *queryid )
1782 {
1783         Operation       op2 = *op;
1784         SlapReply       rs2 = { 0 };
1785
1786         op2.o_bd = &cm->db;
1787
1788         /* remove the selected query */
1789         remove_query_and_data( &op2, &rs2, cm, queryid );
1790
1791         return LDAP_SUCCESS;
1792 }
1793
1794 /*
1795  * Call that allows to remove a set of queries related to an entry 
1796  * from the cache; if queryid is not null, the entry must belong to
1797  * the query indicated by queryid.
1798  */
1799 int
1800 pcache_remove_entry_queries_from_cache(
1801         Operation       *op,
1802         cache_manager   *cm,
1803         struct berval   *ndn,
1804         struct berval   *queryid )
1805 {
1806         Connection              conn = { 0 };
1807         OperationBuffer         opbuf;
1808         Operation               op2;
1809         slap_callback           sc = { 0 };
1810         SlapReply               rs = { REP_RESULT };
1811         Filter                  f = { 0 };
1812         char                    filter_str[ LDAP_LUTIL_UUIDSTR_BUFSIZE + STRLENOF( "(queryId=)" ) ];
1813         AttributeAssertion      ava = ATTRIBUTEASSERTION_INIT;
1814         AttributeName           attrs[ 2 ] = { 0 };
1815         int                     rc;
1816
1817         BerVarray               vals = NULL;
1818
1819         if ( op == NULL ) {
1820                 void    *thrctx = ldap_pvt_thread_pool_context();
1821
1822                 connection_fake_init( &conn, &opbuf, thrctx );
1823                 op = &opbuf.ob_op;
1824
1825         } else {
1826                 op2 = *op;
1827                 op = &op2;
1828         }
1829
1830         memset( &op->oq_search, 0, sizeof( op->oq_search ) );
1831         op->ors_scope = LDAP_SCOPE_BASE;
1832         op->ors_deref = LDAP_DEREF_NEVER;
1833         if ( queryid == NULL || BER_BVISNULL( queryid ) ) {
1834                 BER_BVSTR( &op->ors_filterstr, "(objectClass=*)" );
1835                 f.f_choice = LDAP_FILTER_PRESENT;
1836                 f.f_desc = slap_schema.si_ad_objectClass;
1837
1838         } else {
1839                 op->ors_filterstr.bv_len = snprintf( filter_str,
1840                         sizeof( filter_str ), "(%s=%s)",
1841                         ad_queryId->ad_cname.bv_val, queryid->bv_val );
1842                 f.f_choice = LDAP_FILTER_EQUALITY;
1843                 f.f_ava = &ava;
1844                 f.f_av_desc = ad_queryId;
1845                 f.f_av_value = *queryid;
1846         }
1847         op->ors_filter = &f;
1848         op->ors_slimit = 1;
1849         op->ors_tlimit = SLAP_NO_LIMIT;
1850         attrs[ 0 ].an_desc = ad_queryId;
1851         attrs[ 0 ].an_name = ad_queryId->ad_cname;
1852         op->ors_attrs = attrs;
1853         op->ors_attrsonly = 0;
1854
1855         op->o_req_dn = *ndn;
1856         op->o_req_ndn = *ndn;
1857
1858         op->o_tag = LDAP_REQ_SEARCH;
1859         op->o_protocol = LDAP_VERSION3;
1860         op->o_managedsait = SLAP_CONTROL_CRITICAL;
1861         op->o_bd = &cm->db;
1862         op->o_dn = op->o_bd->be_rootdn;
1863         op->o_ndn = op->o_bd->be_rootndn;
1864         sc.sc_response = fetch_queryId_cb;
1865         op->o_callback = &sc;
1866
1867         rc = op->o_bd->be_search( op, &rs );
1868         if ( rc != LDAP_SUCCESS ) {
1869                 return rc;
1870         }
1871
1872         vals = (BerVarray)op->o_callback->sc_private;
1873         if ( vals != NULL ) {
1874                 int             i;
1875
1876                 for ( i = 0; !BER_BVISNULL( &vals[ i ] ); i++ ) {
1877                         struct berval   val = vals[ i ];
1878
1879                         remove_query_and_data( op, &rs, cm, &val );
1880
1881                         if ( !BER_BVISNULL( &val ) && val.bv_val != vals[ i ].bv_val ) {
1882                                 ch_free( val.bv_val );
1883                         }
1884                 }
1885
1886                 ber_bvarray_free_x( vals, op->o_tmpmemctx );
1887         }
1888
1889         return LDAP_SUCCESS;
1890 }
1891
1892 static int
1893 cache_entries(
1894         Operation       *op,
1895         SlapReply       *rs,
1896         struct berval *query_uuid )
1897 {
1898         struct search_info *si = op->o_callback->sc_private;
1899         slap_overinst *on = si->on;
1900         cache_manager *cm = on->on_bi.bi_private;
1901         int             return_val = 0;
1902         Entry           *e;
1903         struct berval   crp_uuid;
1904         char            uuidbuf[ LDAP_LUTIL_UUIDSTR_BUFSIZE ];
1905         Operation       *op_tmp;
1906         Connection      conn = {0};
1907         OperationBuffer opbuf;
1908         void            *thrctx = ldap_pvt_thread_pool_context();
1909
1910         query_uuid->bv_len = lutil_uuidstr(uuidbuf, sizeof(uuidbuf));
1911         ber_str2bv(uuidbuf, query_uuid->bv_len, 1, query_uuid);
1912
1913         connection_fake_init2( &conn, &opbuf, thrctx, 0 );
1914         op_tmp = &opbuf.ob_op;
1915         op_tmp->o_bd = &cm->db;
1916         op_tmp->o_dn = cm->db.be_rootdn;
1917         op_tmp->o_ndn = cm->db.be_rootndn;
1918
1919         Debug( pcache_debug, "UUID for query being added = %s\n",
1920                         uuidbuf, 0, 0 );
1921
1922         for ( e=si->head; e; e=si->head ) {
1923                 si->head = e->e_private;
1924                 e->e_private = NULL;
1925                 while ( cm->cur_entries > (cm->max_entries) ) {
1926                         BER_BVZERO( &crp_uuid );
1927                         remove_query_and_data( op_tmp, rs, cm, &crp_uuid );
1928                 }
1929
1930                 return_val = merge_entry(op_tmp, e, query_uuid);
1931                 ldap_pvt_thread_mutex_lock(&cm->cache_mutex);
1932                 cm->cur_entries += return_val;
1933                 Debug( pcache_debug,
1934                         "ENTRY ADDED/MERGED, CACHED ENTRIES=%d\n",
1935                         cm->cur_entries, 0, 0 );
1936                 return_val = 0;
1937                 ldap_pvt_thread_mutex_unlock(&cm->cache_mutex);
1938         }
1939
1940         return return_val;
1941 }
1942
1943 static int
1944 pcache_op_cleanup( Operation *op, SlapReply *rs ) {
1945         slap_callback   *cb = op->o_callback;
1946         struct search_info *si = cb->sc_private;
1947         slap_overinst *on = si->on;
1948         cache_manager *cm = on->on_bi.bi_private;
1949         query_manager*          qm = cm->qm;
1950
1951         if ( rs->sr_type == REP_SEARCH ) {
1952                 Entry *e;
1953
1954                 /* don't return more entries than requested by the client */
1955                 if ( si->slimit && rs->sr_nentries >= si->slimit ) {
1956                         si->slimit_exceeded = 1;
1957                 }
1958
1959                 /* If we haven't exceeded the limit for this query,
1960                  * build a chain of answers to store. If we hit the
1961                  * limit, empty the chain and ignore the rest.
1962                  */
1963                 if ( !si->over ) {
1964                         /* check if the entry contains undefined
1965                          * attributes/objectClasses (ITS#5680) */
1966                         if ( test_filter( op, rs->sr_entry, si->query.filter ) != LDAP_COMPARE_TRUE ) {
1967                                 Debug( pcache_debug, "%s: query not cacheable because of schema issues in DN \"%s\"\n",
1968                                         op->o_log_prefix, rs->sr_entry->e_name.bv_val, 0 );
1969                                 goto over;
1970                         }
1971
1972                         if ( si->count < si->max ) {
1973                                 si->count++;
1974                                 e = entry_dup( rs->sr_entry );
1975                                 if ( !si->head ) si->head = e;
1976                                 if ( si->tail ) si->tail->e_private = e;
1977                                 si->tail = e;
1978
1979                         } else {
1980 over:;
1981                                 si->over = 1;
1982                                 si->count = 0;
1983                                 for (;si->head; si->head=e) {
1984                                         e = si->head->e_private;
1985                                         si->head->e_private = NULL;
1986                                         entry_free(si->head);
1987                                 }
1988                                 si->tail = NULL;
1989                         }
1990                 }
1991
1992         }
1993
1994         if ( rs->sr_type == REP_RESULT || 
1995                 op->o_abandon || rs->sr_err == SLAPD_ABANDON )
1996         {
1997                 if ( si->swap_saved_attrs ) {
1998                         rs->sr_attrs = si->save_attrs;
1999                         op->ors_attrs = si->save_attrs;
2000                 }
2001                 if ( (op->o_abandon || rs->sr_err == SLAPD_ABANDON) && 
2002                                 si->caching_reason == PC_IGNORE ) {
2003                         filter_free( si->query.filter );
2004                         if ( si->count ) {
2005                                 /* duplicate query, free it */
2006                                 Entry *e;
2007                                 for (;si->head; si->head=e) {
2008                                         e = si->head->e_private;
2009                                         si->head->e_private = NULL;
2010                                         entry_free(si->head);
2011                                 }
2012                         }
2013                         op->o_callback = op->o_callback->sc_next;
2014                         op->o_tmpfree( cb, op->o_tmpmemctx );
2015                 } else if ( si->caching_reason != PC_IGNORE ) {
2016                         CachedQuery *qc = qm->addfunc(op, qm, &si->query,
2017                                 si->qtemp, si->caching_reason, 1 );
2018
2019                         if ( qc != NULL ) {
2020                                 switch ( si->caching_reason ) {
2021                                 case PC_POSITIVE:
2022                                         cache_entries( op, rs, &qc->q_uuid );
2023                                         break;
2024
2025                                 case PC_SIZELIMIT:
2026                                         qc->q_sizelimit = rs->sr_nentries;
2027                                         break;
2028
2029                                 case PC_NEGATIVE:
2030                                         break;
2031
2032                                 default:
2033                                         assert( 0 );
2034                                         break;
2035                                 }
2036                                 ldap_pvt_thread_rdwr_wunlock(&qc->rwlock);
2037                                 ldap_pvt_thread_mutex_lock(&cm->cache_mutex);
2038                                 cm->num_cached_queries++;
2039                                 Debug( pcache_debug, "STORED QUERIES = %lu\n",
2040                                                 cm->num_cached_queries, 0, 0 );
2041                                 ldap_pvt_thread_mutex_unlock(&cm->cache_mutex);
2042
2043                                 /* If the consistency checker suspended itself,
2044                                  * wake it back up
2045                                  */
2046                                 if ( cm->cc_paused ) {
2047                                         ldap_pvt_thread_mutex_lock( &slapd_rq.rq_mutex );
2048                                         if ( cm->cc_paused ) {
2049                                                 cm->cc_paused = 0;
2050                                                 ldap_pvt_runqueue_resched( &slapd_rq, cm->cc_arg, 0 );
2051                                         }
2052                                         ldap_pvt_thread_mutex_unlock( &slapd_rq.rq_mutex );
2053                                 }
2054
2055                         } else if ( si->count ) {
2056                                 /* duplicate query, free it */
2057                                 Entry *e;
2058                                 for (;si->head; si->head=e) {
2059                                         e = si->head->e_private;
2060                                         si->head->e_private = NULL;
2061                                         entry_free(si->head);
2062                                 }
2063                         }
2064
2065                 } else {
2066                         filter_free( si->query.filter );
2067                 }
2068         }
2069
2070         return SLAP_CB_CONTINUE;
2071 }
2072
2073 static int
2074 pcache_response(
2075         Operation       *op,
2076         SlapReply       *rs )
2077 {
2078         struct search_info *si = op->o_callback->sc_private;
2079
2080         if ( si->swap_saved_attrs ) {
2081                 rs->sr_attrs = si->save_attrs;
2082                 op->ors_attrs = si->save_attrs;
2083         }
2084
2085         if ( rs->sr_type == REP_SEARCH ) {
2086                 /* don't return more entries than requested by the client */
2087                 if ( si->slimit_exceeded ) {
2088                         return 0;
2089                 }
2090
2091         } else if ( rs->sr_type == REP_RESULT ) {
2092
2093                 if ( si->count ) {
2094                         if ( rs->sr_err == LDAP_SUCCESS ) {
2095                                 si->caching_reason = PC_POSITIVE;
2096
2097                         } else if ( rs->sr_err == LDAP_SIZELIMIT_EXCEEDED
2098                                 && si->qtemp->limitttl )
2099                         {
2100                                 si->caching_reason = PC_SIZELIMIT;
2101                         }
2102
2103                 } else if ( si->qtemp->negttl && !si->count && !si->over &&
2104                                 rs->sr_err == LDAP_SUCCESS )
2105                 {
2106                         si->caching_reason = PC_NEGATIVE;
2107                 }
2108
2109
2110                 if ( si->slimit_exceeded ) {
2111                         rs->sr_err = LDAP_SIZELIMIT_EXCEEDED;
2112                 }
2113         }
2114
2115         return SLAP_CB_CONTINUE;
2116 }
2117
2118 static int
2119 add_filter_attrs(
2120         Operation *op,
2121         AttributeName** new_attrs,
2122         struct attr_set *attrs,
2123         AttributeName* filter_attrs,
2124         int fattr_cnt,
2125         int fattr_got_oc)
2126 {
2127         int alluser = 0;
2128         int allop = 0;
2129         int i, j;
2130         int count;
2131         int addoc = 0;
2132
2133         /* duplicate attrs */
2134         count = attrs->count + fattr_cnt;
2135         if ( !fattr_got_oc && !(attrs->flags & PC_GOT_OC)) {
2136                 addoc = 1;
2137                 count++;
2138         }
2139
2140         *new_attrs = (AttributeName*)ch_calloc( count + 1,
2141                 sizeof(AttributeName) );
2142         for (i=0; i<attrs->count; i++) {
2143                 (*new_attrs)[i].an_name = attrs->attrs[i].an_name;
2144                 (*new_attrs)[i].an_desc = attrs->attrs[i].an_desc;
2145         }
2146         BER_BVZERO( &(*new_attrs)[i].an_name );
2147         alluser = an_find(*new_attrs, &AllUser);
2148         allop = an_find(*new_attrs, &AllOper);
2149
2150         j = i;
2151         for ( i=0; i<fattr_cnt; i++ ) {
2152                 if ( an_find(*new_attrs, &filter_attrs[i].an_name ) ) {
2153                         continue;
2154                 }
2155                 if ( is_at_operational(filter_attrs[i].an_desc->ad_type) ) {
2156                         if ( allop ) {
2157                                 continue;
2158                         }
2159                 } else if ( alluser ) {
2160                         continue;
2161                 }
2162                 (*new_attrs)[j].an_name = filter_attrs[i].an_name;
2163                 (*new_attrs)[j].an_desc = filter_attrs[i].an_desc;
2164                 (*new_attrs)[j].an_oc = NULL;
2165                 (*new_attrs)[j].an_oc_exclude = 0;
2166                 j++;
2167         }
2168         if ( addoc ) {
2169                 (*new_attrs)[j].an_name = slap_schema.si_ad_objectClass->ad_cname;
2170                 (*new_attrs)[j].an_desc = slap_schema.si_ad_objectClass;
2171                 (*new_attrs)[j].an_oc = NULL;
2172                 (*new_attrs)[j].an_oc_exclude = 0;
2173                 j++;
2174         }
2175         BER_BVZERO( &(*new_attrs)[j].an_name );
2176
2177         return j;
2178 }
2179
2180 /* NOTE: this is a quick workaround to let pcache minimally interact
2181  * with pagedResults.  A more articulated solutions would be to
2182  * perform the remote query without control and cache all results,
2183  * performing the pagedResults search only within the client
2184  * and the proxy.  This requires pcache to understand pagedResults. */
2185 static int
2186 pcache_chk_controls(
2187         Operation       *op,
2188         SlapReply       *rs )
2189 {
2190         const char      *non = "";
2191         const char      *stripped = "";
2192
2193         switch( op->o_pagedresults ) {
2194         case SLAP_CONTROL_NONCRITICAL:
2195                 non = "non-";
2196                 stripped = "; stripped";
2197                 /* fallthru */
2198
2199         case SLAP_CONTROL_CRITICAL:
2200                 Debug( pcache_debug, "%s: "
2201                         "%scritical pagedResults control "
2202                         "disabled with proxy cache%s.\n",
2203                         op->o_log_prefix, non, stripped );
2204                 
2205                 slap_remove_control( op, rs, slap_cids.sc_pagedResults, NULL );
2206                 break;
2207
2208         default:
2209                 rs->sr_err = SLAP_CB_CONTINUE;
2210                 break;
2211         }
2212
2213         return rs->sr_err;
2214 }
2215
2216 #ifdef PCACHE_CONTROL_PRIVDB
2217 static int
2218 pcache_op_privdb(
2219         Operation               *op,
2220         SlapReply               *rs )
2221 {
2222         slap_overinst   *on = (slap_overinst *)op->o_bd->bd_info;
2223         cache_manager   *cm = on->on_bi.bi_private;
2224         slap_callback   *save_cb;
2225         slap_op_t       type;
2226
2227         /* skip if control is unset */
2228         if ( op->o_ctrlflag[ privDB_cid ] != SLAP_CONTROL_CRITICAL ) {
2229                 return SLAP_CB_CONTINUE;
2230         }
2231
2232         /* The cache DB isn't open yet */
2233         if ( cm->defer_db_open ) {
2234                 send_ldap_error( op, rs, LDAP_UNAVAILABLE,
2235                         "pcachePrivDB: cacheDB not available" );
2236                 return rs->sr_err;
2237         }
2238
2239         /* FIXME: might be a little bit exaggerated... */
2240         if ( !be_isroot( op ) ) {
2241                 save_cb = op->o_callback;
2242                 op->o_callback = NULL;
2243                 send_ldap_error( op, rs, LDAP_UNWILLING_TO_PERFORM,
2244                         "pcachePrivDB: operation not allowed" );
2245                 op->o_callback = save_cb;
2246
2247                 return rs->sr_err;
2248         }
2249
2250         /* map tag to operation */
2251         type = slap_req2op( op->o_tag );
2252         if ( type != SLAP_OP_LAST ) {
2253                 BI_op_func      **func;
2254                 int             rc;
2255
2256                 /* execute, if possible */
2257                 func = &cm->db.be_bind;
2258                 if ( func[ type ] != NULL ) {
2259                         Operation       op2 = *op;
2260         
2261                         op2.o_bd = &cm->db;
2262
2263                         rc = func[ type ]( &op2, rs );
2264                         if ( type == SLAP_OP_BIND && rc == LDAP_SUCCESS ) {
2265                                 op->o_conn->c_authz_cookie = cm->db.be_private;
2266                         }
2267                 }
2268         }
2269
2270         /* otherwise fall back to error */
2271         save_cb = op->o_callback;
2272         op->o_callback = NULL;
2273         send_ldap_error( op, rs, LDAP_UNWILLING_TO_PERFORM,
2274                 "operation not supported with pcachePrivDB control" );
2275         op->o_callback = save_cb;
2276
2277         return rs->sr_err;
2278 }
2279 #endif /* PCACHE_CONTROL_PRIVDB */
2280
2281 static int
2282 pcache_op_search(
2283         Operation       *op,
2284         SlapReply       *rs )
2285 {
2286         slap_overinst *on = (slap_overinst *)op->o_bd->bd_info;
2287         cache_manager *cm = on->on_bi.bi_private;
2288         query_manager*          qm = cm->qm;
2289
2290         int i = -1;
2291
2292         AttributeName   *filter_attrs = NULL;
2293
2294         Query           query;
2295         QueryTemplate   *qtemp = NULL;
2296
2297         int             attr_set = -1;
2298         CachedQuery     *answerable = NULL;
2299         int             cacheable = 0;
2300         int             fattr_cnt=0;
2301         int             fattr_got_oc = 0;
2302
2303         struct berval   tempstr;
2304
2305 #ifdef PCACHE_CONTROL_PRIVDB
2306         if ( op->o_ctrlflag[ privDB_cid ] == SLAP_CONTROL_CRITICAL ) {
2307                 return pcache_op_privdb( op, rs );
2308         }
2309 #endif /* PCACHE_CONTROL_PRIVDB */
2310
2311         /* The cache DB isn't open yet */
2312         if ( cm->defer_db_open ) {
2313                 send_ldap_error( op, rs, LDAP_UNAVAILABLE,
2314                         "pcachePrivDB: cacheDB not available" );
2315                 return rs->sr_err;
2316         }
2317
2318         tempstr.bv_val = op->o_tmpalloc( op->ors_filterstr.bv_len+1, op->o_tmpmemctx );
2319         tempstr.bv_len = 0;
2320         if ( filter2template( op, op->ors_filter, &tempstr, &filter_attrs,
2321                 &fattr_cnt, &fattr_got_oc )) {
2322                 op->o_tmpfree( tempstr.bv_val, op->o_tmpmemctx );
2323                 return SLAP_CB_CONTINUE;
2324         }
2325
2326         Debug( pcache_debug, "query template of incoming query = %s\n",
2327                                         tempstr.bv_val, 0, 0 );
2328
2329         /* FIXME: cannot cache/answer requests with pagedResults control */
2330
2331         /* find attr set */
2332         attr_set = get_attr_set(op->ors_attrs, qm, cm->numattrsets);
2333
2334         query.filter = op->ors_filter;
2335         query.base = op->o_req_ndn;
2336         query.scope = op->ors_scope;
2337
2338         /* check for query containment */
2339         if (attr_set > -1) {
2340                 QueryTemplate *qt = qm->attr_sets[attr_set].templates;
2341                 for (; qt; qt = qt->qtnext ) {
2342                         /* find if template i can potentially answer tempstr */
2343                         if (qt->querystr.bv_len != tempstr.bv_len ||
2344                                 strcasecmp( qt->querystr.bv_val, tempstr.bv_val ))
2345                                 continue;
2346                         cacheable = 1;
2347                         qtemp = qt;
2348                         Debug( pcache_debug, "Entering QC, querystr = %s\n",
2349                                         op->ors_filterstr.bv_val, 0, 0 );
2350                         answerable = (*(qm->qcfunc))(op, qm, &query, qt);
2351
2352                         if (answerable)
2353                                 break;
2354                 }
2355         }
2356         op->o_tmpfree( tempstr.bv_val, op->o_tmpmemctx );
2357
2358         if (answerable) {
2359                 /* Need to clear the callbacks of the original operation,
2360                  * in case there are other overlays */
2361                 BackendDB       *save_bd = op->o_bd;
2362                 slap_callback   *save_cb = op->o_callback;
2363
2364                 Debug( pcache_debug, "QUERY ANSWERABLE\n", 0, 0, 0 );
2365                 op->o_tmpfree( filter_attrs, op->o_tmpmemctx );
2366                 ldap_pvt_thread_rdwr_rlock(&answerable->rwlock);
2367                 if ( BER_BVISNULL( &answerable->q_uuid )) {
2368                         /* No entries cached, just an empty result set */
2369                         i = rs->sr_err = 0;
2370                         send_ldap_result( op, rs );
2371                 } else {
2372                         op->o_bd = &cm->db;
2373                         op->o_callback = NULL;
2374                         i = cm->db.bd_info->bi_op_search( op, rs );
2375                 }
2376                 ldap_pvt_thread_rdwr_runlock(&answerable->rwlock);
2377                 ldap_pvt_thread_rdwr_runlock(&qtemp->t_rwlock);
2378                 op->o_bd = save_bd;
2379                 op->o_callback = save_cb;
2380                 return i;
2381         }
2382
2383         Debug( pcache_debug, "QUERY NOT ANSWERABLE\n", 0, 0, 0 );
2384
2385         ldap_pvt_thread_mutex_lock(&cm->cache_mutex);
2386         if (cm->num_cached_queries >= cm->max_queries) {
2387                 cacheable = 0;
2388         }
2389         ldap_pvt_thread_mutex_unlock(&cm->cache_mutex);
2390
2391         if (op->ors_attrsonly)
2392                 cacheable = 0;
2393
2394         if (cacheable) {
2395                 slap_callback           *cb;
2396                 struct search_info      *si;
2397
2398                 Debug( pcache_debug, "QUERY CACHEABLE\n", 0, 0, 0 );
2399                 query.filter = filter_dup(op->ors_filter, NULL);
2400                 ldap_pvt_thread_rdwr_wlock(&qtemp->t_rwlock);
2401                 if ( !qtemp->t_attrs.count ) {
2402                         qtemp->t_attrs.count = add_filter_attrs(op,
2403                                 &qtemp->t_attrs.attrs,
2404                                 &qm->attr_sets[attr_set],
2405                                 filter_attrs, fattr_cnt, fattr_got_oc);
2406                 }
2407                 ldap_pvt_thread_rdwr_wunlock(&qtemp->t_rwlock);
2408
2409                 cb = op->o_tmpalloc( sizeof(*cb) + sizeof(*si), op->o_tmpmemctx );
2410                 cb->sc_response = pcache_response;
2411                 cb->sc_cleanup = pcache_op_cleanup;
2412                 cb->sc_private = (cb+1);
2413                 si = cb->sc_private;
2414                 si->on = on;
2415                 si->query = query;
2416                 si->qtemp = qtemp;
2417                 si->max = cm->num_entries_limit ;
2418                 si->over = 0;
2419                 si->count = 0;
2420                 si->slimit = 0;
2421                 si->slimit_exceeded = 0;
2422                 si->caching_reason = PC_IGNORE;
2423                 if ( op->ors_slimit && op->ors_slimit < cm->num_entries_limit ) {
2424                         si->slimit = op->ors_slimit;
2425                         op->ors_slimit = cm->num_entries_limit;
2426                 }
2427                 si->head = NULL;
2428                 si->tail = NULL;
2429                 si->swap_saved_attrs = 1;
2430                 si->save_attrs = op->ors_attrs;
2431
2432                 op->ors_attrs = qtemp->t_attrs.attrs;
2433
2434                 if ( cm->response_cb == PCACHE_RESPONSE_CB_HEAD ) {
2435                         cb->sc_next = op->o_callback;
2436                         op->o_callback = cb;
2437
2438                 } else {
2439                         slap_callback           **pcb;
2440
2441                         /* need to move the callback at the end, in case other
2442                          * overlays are present, so that the final entry is
2443                          * actually cached */
2444                         cb->sc_next = NULL;
2445                         for ( pcb = &op->o_callback; *pcb; pcb = &(*pcb)->sc_next );
2446                         *pcb = cb;
2447                 }
2448
2449         } else {
2450                 Debug( pcache_debug, "QUERY NOT CACHEABLE\n",
2451                                         0, 0, 0);
2452         }
2453
2454         op->o_tmpfree( filter_attrs, op->o_tmpmemctx );
2455
2456         return SLAP_CB_CONTINUE;
2457 }
2458
2459 static int
2460 get_attr_set(
2461         AttributeName* attrs,
2462         query_manager* qm,
2463         int num )
2464 {
2465         int i;
2466         int count = 0;
2467
2468         if ( attrs ) {
2469                 for ( ; attrs[count].an_name.bv_val; count++ );
2470         }
2471
2472         /* recognize a single "*" or a "1.1" */
2473         if ( count == 0 ) {
2474                 count = 1;
2475                 attrs = slap_anlist_all_user_attributes;
2476
2477         } else if ( count == 1 && strcmp( attrs[0].an_name.bv_val, LDAP_NO_ATTRS ) == 0 ) {
2478                 count = 0;
2479                 attrs = NULL;
2480         }
2481
2482         for ( i = 0; i < num; i++ ) {
2483                 AttributeName *a2;
2484                 int found = 1;
2485
2486                 if ( count > qm->attr_sets[i].count ) {
2487                         continue;
2488                 }
2489
2490                 if ( !count ) {
2491                         if ( !qm->attr_sets[i].count ) {
2492                                 break;
2493                         }
2494                         continue;
2495                 }
2496
2497                 for ( a2 = attrs; a2->an_name.bv_val; a2++ ) {
2498                         if ( !an_find( qm->attr_sets[i].attrs, &a2->an_name ) ) {
2499                                 found = 0;
2500                                 break;
2501                         }
2502                 }
2503
2504                 if ( found ) {
2505                         break;
2506                 }
2507         }
2508
2509         if ( i == num ) {
2510                 i = -1;
2511         }
2512
2513         return i;
2514 }
2515
2516 static void*
2517 consistency_check(
2518         void *ctx,
2519         void *arg )
2520 {
2521         struct re_s *rtask = arg;
2522         slap_overinst *on = rtask->arg;
2523         cache_manager *cm = on->on_bi.bi_private;
2524         query_manager *qm = cm->qm;
2525         Connection conn = {0};
2526         OperationBuffer opbuf;
2527         Operation *op;
2528
2529         SlapReply rs = {REP_RESULT};
2530         CachedQuery* query;
2531         int return_val, pause = 1;
2532         QueryTemplate* templ;
2533
2534         connection_fake_init( &conn, &opbuf, ctx );
2535         op = &opbuf.ob_op;
2536
2537         op->o_bd = &cm->db;
2538         op->o_dn = cm->db.be_rootdn;
2539         op->o_ndn = cm->db.be_rootndn;
2540
2541         cm->cc_arg = arg;
2542
2543         for (templ = qm->templates; templ; templ=templ->qmnext) {
2544                 query = templ->query_last;
2545                 if ( query ) pause = 0;
2546                 op->o_time = slap_get_time();
2547                 while (query && (query->expiry_time < op->o_time)) {
2548                         int rem = 0;
2549                         Debug( pcache_debug, "Lock CR index = %p\n",
2550                                         (void *) templ, 0, 0 );
2551                         ldap_pvt_thread_rdwr_wlock(&templ->t_rwlock);
2552                         if ( query == templ->query_last ) {
2553                                 rem = 1;
2554                                 remove_from_template(query, templ);
2555                                 Debug( pcache_debug, "TEMPLATE %p QUERIES-- %d\n",
2556                                                 (void *) templ, templ->no_of_queries, 0 );
2557                                 Debug( pcache_debug, "Unlock CR index = %p\n",
2558                                                 (void *) templ, 0, 0 );
2559                         }
2560                         ldap_pvt_thread_rdwr_wunlock(&templ->t_rwlock);
2561                         if ( !rem ) {
2562                                 query = templ->query_last;
2563                                 continue;
2564                         }
2565                         ldap_pvt_thread_mutex_lock(&qm->lru_mutex);
2566                         remove_query(qm, query);
2567                         ldap_pvt_thread_mutex_unlock(&qm->lru_mutex);
2568                         if ( BER_BVISNULL( &query->q_uuid ))
2569                                 return_val = 0;
2570                         else
2571                                 return_val = remove_query_data(op, &rs, &query->q_uuid);
2572                         Debug( pcache_debug, "STALE QUERY REMOVED, SIZE=%d\n",
2573                                                 return_val, 0, 0 );
2574                         ldap_pvt_thread_mutex_lock(&cm->cache_mutex);
2575                         cm->cur_entries -= return_val;
2576                         cm->num_cached_queries--;
2577                         Debug( pcache_debug, "STORED QUERIES = %lu\n",
2578                                         cm->num_cached_queries, 0, 0 );
2579                         ldap_pvt_thread_mutex_unlock(&cm->cache_mutex);
2580                         Debug( pcache_debug,
2581                                 "STALE QUERY REMOVED, CACHE ="
2582                                 "%d entries\n",
2583                                 cm->cur_entries, 0, 0 );
2584                         free_query(query);
2585                         query = templ->query_last;
2586                 }
2587         }
2588         ldap_pvt_thread_mutex_lock( &slapd_rq.rq_mutex );
2589         if ( ldap_pvt_runqueue_isrunning( &slapd_rq, rtask )) {
2590                 ldap_pvt_runqueue_stoptask( &slapd_rq, rtask );
2591         }
2592         /* If there were no queries, defer processing for a while */
2593         cm->cc_paused = pause;
2594         ldap_pvt_runqueue_resched( &slapd_rq, rtask, pause );
2595
2596         ldap_pvt_thread_mutex_unlock( &slapd_rq.rq_mutex );
2597         return NULL;
2598 }
2599
2600
2601 #define MAX_ATTR_SETS 500
2602
2603 enum {
2604         PC_MAIN = 1,
2605         PC_ATTR,
2606         PC_TEMP,
2607         PC_RESP,
2608         PC_QUERIES
2609 };
2610
2611 static ConfigDriver pc_cf_gen;
2612 static ConfigLDAPadd pc_ldadd;
2613 static ConfigCfAdd pc_cfadd;
2614
2615 static ConfigTable pccfg[] = {
2616         { "proxycache", "backend> <max_entries> <numattrsets> <entry limit> "
2617                                 "<cycle_time",
2618                 6, 6, 0, ARG_MAGIC|ARG_NO_DELETE|PC_MAIN, pc_cf_gen,
2619                 "( OLcfgOvAt:2.1 NAME 'olcProxyCache' "
2620                         "DESC 'ProxyCache basic parameters' "
2621                         "SYNTAX OMsDirectoryString SINGLE-VALUE )", NULL, NULL },
2622         { "proxyattrset", "index> <attributes...",
2623                 2, 0, 0, ARG_MAGIC|PC_ATTR, pc_cf_gen,
2624                 "( OLcfgOvAt:2.2 NAME 'olcProxyAttrset' "
2625                         "DESC 'A set of attributes to cache' "
2626                         "SYNTAX OMsDirectoryString )", NULL, NULL },
2627         { "proxytemplate", "filter> <attrset-index> <TTL> <negTTL",
2628                 4, 6, 0, ARG_MAGIC|PC_TEMP, pc_cf_gen,
2629                 "( OLcfgOvAt:2.3 NAME 'olcProxyTemplate' "
2630                         "DESC 'Filter template, attrset, cache TTL, "
2631                                 "optional negative TTL, optional sizelimit TTL' "
2632                         "SYNTAX OMsDirectoryString )", NULL, NULL },
2633         { "response-callback", "head|tail(default)",
2634                 2, 2, 0, ARG_MAGIC|PC_RESP, pc_cf_gen,
2635                 "( OLcfgOvAt:2.4 NAME 'olcProxyResponseCB' "
2636                         "DESC 'Response callback position in overlay stack' "
2637                         "SYNTAX OMsDirectoryString )", NULL, NULL },
2638         { "proxyCacheQueries", "queries",
2639                 2, 2, 0, ARG_INT|ARG_MAGIC|PC_QUERIES, pc_cf_gen,
2640                 "( OLcfgOvAt:2.5 NAME 'olcProxyCacheQueries' "
2641                         "DESC 'Maximum number of queries to cache' "
2642                         "SYNTAX OMsInteger )", NULL, NULL },
2643         { "proxySaveQueries", "TRUE|FALSE",
2644                 2, 2, 0, ARG_ON_OFF|ARG_OFFSET, (void *)offsetof(cache_manager, save_queries),
2645                 "( OLcfgOvAt:2.6 NAME 'olcProxySaveQueries' "
2646                         "DESC 'Save cached queries for hot restart' "
2647                         "SYNTAX OMsBoolean )", NULL, NULL },
2648
2649         { NULL, NULL, 0, 0, 0, ARG_IGNORED }
2650 };
2651
2652 /* Need to no-op this keyword for dynamic config */
2653 static ConfigTable pcdummy[] = {
2654         { "", "", 0, 0, 0, ARG_IGNORED,
2655                 NULL, "( OLcfgGlAt:13 NAME 'olcDatabase' "
2656                         "DESC 'The backend type for a database instance' "
2657                         "SUP olcBackend SINGLE-VALUE X-ORDERED 'SIBLINGS' )", NULL, NULL },
2658         { NULL, NULL, 0, 0, 0, ARG_IGNORED }
2659 };
2660
2661 static ConfigOCs pcocs[] = {
2662         { "( OLcfgOvOc:2.1 "
2663                 "NAME 'olcPcacheConfig' "
2664                 "DESC 'ProxyCache configuration' "
2665                 "SUP olcOverlayConfig "
2666                 "MUST ( olcProxyCache $ olcProxyAttrset $ olcProxyTemplate ) "
2667                 "MAY ( olcProxyResponseCB $ olcProxyCacheQueries $ olcProxySaveQueries ) )",
2668                 Cft_Overlay, pccfg, NULL, pc_cfadd },
2669         { "( OLcfgOvOc:2.2 "
2670                 "NAME 'olcPcacheDatabase' "
2671                 "DESC 'Cache database configuration' "
2672                 "AUXILIARY )", Cft_Misc, pcdummy, pc_ldadd },
2673         { NULL, 0, NULL }
2674 };
2675
2676 static int pcache_db_open2( slap_overinst *on, ConfigReply *cr );
2677
2678 static int
2679 pc_ldadd_cleanup( ConfigArgs *c )
2680 {
2681         slap_overinst *on = c->ca_private;
2682         return pcache_db_open2( on, &c->reply );
2683 }
2684
2685 static int
2686 pc_ldadd( CfEntryInfo *p, Entry *e, ConfigArgs *ca )
2687 {
2688         slap_overinst *on;
2689         cache_manager *cm;
2690
2691         if ( p->ce_type != Cft_Overlay || !p->ce_bi ||
2692                 p->ce_bi->bi_cf_ocs != pcocs )
2693                 return LDAP_CONSTRAINT_VIOLATION;
2694
2695         on = (slap_overinst *)p->ce_bi;
2696         cm = on->on_bi.bi_private;
2697         ca->be = &cm->db;
2698         /* Defer open if this is an LDAPadd */
2699         if ( CONFIG_ONLINE_ADD( ca ))
2700                 ca->cleanup = pc_ldadd_cleanup;
2701         else
2702                 cm->defer_db_open = 0;
2703         ca->ca_private = on;
2704         return LDAP_SUCCESS;
2705 }
2706
2707 static int
2708 pc_cfadd( Operation *op, SlapReply *rs, Entry *p, ConfigArgs *ca )
2709 {
2710         CfEntryInfo *pe = p->e_private;
2711         slap_overinst *on = (slap_overinst *)pe->ce_bi;
2712         cache_manager *cm = on->on_bi.bi_private;
2713         struct berval bv;
2714
2715         /* FIXME: should not hardcode "olcDatabase" here */
2716         bv.bv_len = snprintf( ca->cr_msg, sizeof( ca->cr_msg ),
2717                 "olcDatabase=%s", cm->db.bd_info->bi_type );
2718         if ( bv.bv_len < 0 || bv.bv_len >= sizeof( ca->cr_msg ) ) {
2719                 return -1;
2720         }
2721         bv.bv_val = ca->cr_msg;
2722         ca->be = &cm->db;
2723         cm->defer_db_open = 0;
2724
2725         /* We can only create this entry if the database is table-driven
2726          */
2727         if ( cm->db.bd_info->bi_cf_ocs )
2728                 config_build_entry( op, rs, pe, ca, &bv, cm->db.bd_info->bi_cf_ocs,
2729                         &pcocs[1] );
2730
2731         return 0;
2732 }
2733
2734 static int
2735 pc_cf_gen( ConfigArgs *c )
2736 {
2737         slap_overinst   *on = (slap_overinst *)c->bi;
2738         cache_manager*  cm = on->on_bi.bi_private;
2739         query_manager*  qm = cm->qm;
2740         QueryTemplate*  temp;
2741         AttributeName*  attr_name;
2742         AttributeName*  attrarray;
2743         const char*     text=NULL;
2744         int             i, num, rc = 0;
2745         char            *ptr;
2746         unsigned long   t;
2747
2748         if ( c->op == SLAP_CONFIG_EMIT ) {
2749                 struct berval bv;
2750                 switch( c->type ) {
2751                 case PC_MAIN:
2752                         bv.bv_len = snprintf( c->cr_msg, sizeof( c->cr_msg ), "%s %d %d %d %ld",
2753                                 cm->db.bd_info->bi_type, cm->max_entries, cm->numattrsets,
2754                                 cm->num_entries_limit, cm->cc_period );
2755                         bv.bv_val = c->cr_msg;
2756                         value_add_one( &c->rvalue_vals, &bv );
2757                         break;
2758                 case PC_ATTR:
2759                         for (i=0; i<cm->numattrsets; i++) {
2760                                 if ( !qm->attr_sets[i].count ) continue;
2761
2762                                 bv.bv_len = snprintf( c->cr_msg, sizeof( c->cr_msg ), "%d", i );
2763
2764                                 /* count the attr length */
2765                                 for ( attr_name = qm->attr_sets[i].attrs;
2766                                         attr_name->an_name.bv_val; attr_name++ )
2767                                         bv.bv_len += attr_name->an_name.bv_len + 1;
2768
2769                                 bv.bv_val = ch_malloc( bv.bv_len+1 );
2770                                 ptr = lutil_strcopy( bv.bv_val, c->cr_msg );
2771                                 for ( attr_name = qm->attr_sets[i].attrs;
2772                                         attr_name->an_name.bv_val; attr_name++ ) {
2773                                         *ptr++ = ' ';
2774                                         ptr = lutil_strcopy( ptr, attr_name->an_name.bv_val );
2775                                 }
2776                                 ber_bvarray_add( &c->rvalue_vals, &bv );
2777                         }
2778                         if ( !c->rvalue_vals )
2779                                 rc = 1;
2780                         break;
2781                 case PC_TEMP:
2782                         for (temp=qm->templates; temp; temp=temp->qmnext) {
2783                                 /* HEADS-UP: always print all;
2784                                  * if optional == 0, ignore */
2785                                 bv.bv_len = snprintf( c->cr_msg, sizeof( c->cr_msg ),
2786                                         " %d %ld %ld %ld",
2787                                         temp->attr_set_index,
2788                                         temp->ttl,
2789                                         temp->negttl,
2790                                         temp->limitttl );
2791                                 bv.bv_len += temp->querystr.bv_len + 2;
2792                                 bv.bv_val = ch_malloc( bv.bv_len+1 );
2793                                 ptr = bv.bv_val;
2794                                 *ptr++ = '"';
2795                                 ptr = lutil_strcopy( ptr, temp->querystr.bv_val );
2796                                 *ptr++ = '"';
2797                                 strcpy( ptr, c->cr_msg );
2798                                 ber_bvarray_add( &c->rvalue_vals, &bv );
2799                         }
2800                         if ( !c->rvalue_vals )
2801                                 rc = 1;
2802                         break;
2803                 case PC_RESP:
2804                         if ( cm->response_cb == PCACHE_RESPONSE_CB_HEAD ) {
2805                                 BER_BVSTR( &bv, "head" );
2806                         } else {
2807                                 BER_BVSTR( &bv, "tail" );
2808                         }
2809                         value_add_one( &c->rvalue_vals, &bv );
2810                         break;
2811                 case PC_QUERIES:
2812                         c->value_int = cm->max_queries;
2813                         break;
2814                 }
2815                 return rc;
2816         } else if ( c->op == LDAP_MOD_DELETE ) {
2817                 return 1;       /* FIXME */
2818 #if 0
2819                 switch( c->type ) {
2820                 case PC_ATTR:
2821                 case PC_TEMP:
2822                 }
2823                 return rc;
2824 #endif
2825         }
2826
2827         switch( c->type ) {
2828         case PC_MAIN:
2829                 if ( cm->numattrsets > 0 ) {
2830                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "\"proxycache\" directive already provided" );
2831                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2832                         return( 1 );
2833                 }
2834
2835                 if ( lutil_atoi( &cm->numattrsets, c->argv[3] ) != 0 ) {
2836                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "unable to parse num attrsets=\"%s\" (arg #3)",
2837                                 c->argv[3] );
2838                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2839                         return( 1 );
2840                 }
2841                 if ( cm->numattrsets <= 0 ) {
2842                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "numattrsets (arg #3) must be positive" );
2843                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2844                         return( 1 );
2845                 }
2846                 if ( cm->numattrsets > MAX_ATTR_SETS ) {
2847                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "numattrsets (arg #3) must be <= %d", MAX_ATTR_SETS );
2848                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2849                         return( 1 );
2850                 }
2851
2852                 if ( !backend_db_init( c->argv[1], &cm->db, -1, NULL )) {
2853                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "unknown backend type (arg #1)" );
2854                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2855                         return( 1 );
2856                 }
2857
2858                 if ( lutil_atoi( &cm->max_entries, c->argv[2] ) != 0 ) {
2859                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "unable to parse max entries=\"%s\" (arg #2)",
2860                                 c->argv[2] );
2861                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2862                         return( 1 );
2863                 }
2864                 if ( cm->max_entries <= 0 ) {
2865                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "max entries (arg #2) must be positive.\n" );
2866                         Debug( LDAP_DEBUG_CONFIG, "%s: %s\n", c->log, c->cr_msg, 0 );
2867                         return( 1 );
2868                 }
2869
2870                 if ( lutil_atoi( &cm->num_entries_limit, c->argv[4] ) != 0 ) {
2871                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "unable to parse entry limit=\"%s\" (arg #4)",
2872                                 c->argv[4] );
2873                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2874                         return( 1 );
2875                 }
2876                 if ( cm->num_entries_limit <= 0 ) {
2877                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "entry limit (arg #4) must be positive" );
2878                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2879                         return( 1 );
2880                 }
2881                 if ( cm->num_entries_limit > cm->max_entries ) {
2882                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "entry limit (arg #4) must be less than max entries %d (arg #2)", cm->max_entries );
2883                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2884                         return( 1 );
2885                 }
2886
2887                 if ( lutil_parse_time( c->argv[5], &t ) != 0 ) {
2888                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "unable to parse period=\"%s\" (arg #5)",
2889                                 c->argv[5] );
2890                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2891                         return( 1 );
2892                 }
2893
2894                 cm->cc_period = (time_t)t;
2895                 Debug( pcache_debug,
2896                                 "Total # of attribute sets to be cached = %d.\n",
2897                                 cm->numattrsets, 0, 0 );
2898                 qm->attr_sets = ( struct attr_set * )ch_calloc( cm->numattrsets,
2899                                                 sizeof( struct attr_set ) );
2900                 break;
2901         case PC_ATTR:
2902                 if ( cm->numattrsets == 0 ) {
2903                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "\"proxycache\" directive not provided yet" );
2904                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2905                         return( 1 );
2906                 }
2907                 if ( lutil_atoi( &num, c->argv[1] ) != 0 ) {
2908                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "unable to parse attrset #=\"%s\"",
2909                                 c->argv[1] );
2910                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2911                         return( 1 );
2912                 }
2913
2914                 if ( num < 0 || num >= cm->numattrsets ) {
2915                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "attrset index %d out of bounds (must be %s%d)",
2916                                 num, cm->numattrsets > 1 ? "0->" : "", cm->numattrsets - 1 );
2917                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2918                         return 1;
2919                 }
2920                 qm->attr_sets[num].flags |= PC_CONFIGURED;
2921                 if ( c->argc == 2 ) {
2922                         /* assume "1.1" */
2923                         snprintf( c->cr_msg, sizeof( c->cr_msg ),
2924                                 "need an explicit attr in attrlist; use \"*\" to indicate all attrs" );
2925                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2926                         return 1;
2927
2928                 } else if ( c->argc == 3 ) {
2929                         if ( strcmp( c->argv[2], LDAP_ALL_USER_ATTRIBUTES ) == 0 ) {
2930                                 qm->attr_sets[num].count = 1;
2931                                 qm->attr_sets[num].attrs = (AttributeName*)ch_calloc( 2,
2932                                         sizeof( AttributeName ) );
2933                                 BER_BVSTR( &qm->attr_sets[num].attrs[0].an_name, LDAP_ALL_USER_ATTRIBUTES );
2934                                 break;
2935
2936                         } else if ( strcmp( c->argv[2], LDAP_ALL_OPERATIONAL_ATTRIBUTES ) == 0 ) {
2937                                 qm->attr_sets[num].count = 1;
2938                                 qm->attr_sets[num].attrs = (AttributeName*)ch_calloc( 2,
2939                                         sizeof( AttributeName ) );
2940                                 BER_BVSTR( &qm->attr_sets[num].attrs[0].an_name, LDAP_ALL_OPERATIONAL_ATTRIBUTES );
2941                                 break;
2942
2943                         } else if ( strcmp( c->argv[2], LDAP_NO_ATTRS ) == 0 ) {
2944                                 break;
2945                         }
2946                         /* else: fallthru */
2947
2948                 } else if ( c->argc == 4 ) {
2949                         if ( ( strcmp( c->argv[2], LDAP_ALL_USER_ATTRIBUTES ) == 0 && strcmp( c->argv[3], LDAP_ALL_OPERATIONAL_ATTRIBUTES ) == 0 )
2950                                 || ( strcmp( c->argv[2], LDAP_ALL_OPERATIONAL_ATTRIBUTES ) == 0 && strcmp( c->argv[3], LDAP_ALL_USER_ATTRIBUTES ) == 0 ) )
2951                         {
2952                                 qm->attr_sets[num].count = 2;
2953                                 qm->attr_sets[num].attrs = (AttributeName*)ch_calloc( 3,
2954                                         sizeof( AttributeName ) );
2955                                 BER_BVSTR( &qm->attr_sets[num].attrs[0].an_name, LDAP_ALL_USER_ATTRIBUTES );
2956                                 BER_BVSTR( &qm->attr_sets[num].attrs[1].an_name, LDAP_ALL_OPERATIONAL_ATTRIBUTES );
2957                                 break;
2958                         }
2959                         /* else: fallthru */
2960                 }
2961
2962                 if ( c->argc > 2 ) {
2963                         int all_user = 0, all_op = 0;
2964
2965                         qm->attr_sets[num].count = c->argc - 2;
2966                         qm->attr_sets[num].attrs = (AttributeName*)ch_calloc( c->argc - 1,
2967                                 sizeof( AttributeName ) );
2968                         attr_name = qm->attr_sets[num].attrs;
2969                         for ( i = 2; i < c->argc; i++ ) {
2970                                 attr_name->an_desc = NULL;
2971                                 if ( strcmp( c->argv[i], LDAP_NO_ATTRS ) == 0 ) {
2972                                         snprintf( c->cr_msg, sizeof( c->cr_msg ),
2973                                                 "invalid attr #%d \"%s\" in attrlist",
2974                                                 i - 2, c->argv[i] );
2975                                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2976                                         ch_free( qm->attr_sets[num].attrs );
2977                                         qm->attr_sets[num].attrs = NULL;
2978                                         qm->attr_sets[num].count = 0;
2979                                         return 1;
2980                                 }
2981                                 if ( strcmp( c->argv[i], LDAP_ALL_USER_ATTRIBUTES ) == 0 ) {
2982                                         all_user = 1;
2983                                         BER_BVSTR( &attr_name->an_name, LDAP_ALL_USER_ATTRIBUTES );
2984                                 } else if ( strcmp( c->argv[i], LDAP_ALL_OPERATIONAL_ATTRIBUTES ) == 0 ) {
2985                                         all_op = 1;
2986                                         BER_BVSTR( &attr_name->an_name, LDAP_ALL_OPERATIONAL_ATTRIBUTES );
2987                                 } else {
2988                                         if ( slap_str2ad( c->argv[i], &attr_name->an_desc, &text ) ) {
2989                                                 strcpy( c->cr_msg, text );
2990                                                 Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
2991                                                 ch_free( qm->attr_sets[num].attrs );
2992                                                 qm->attr_sets[num].attrs = NULL;
2993                                                 qm->attr_sets[num].count = 0;
2994                                                 return 1;
2995                                         }
2996                                         attr_name->an_name = attr_name->an_desc->ad_cname;
2997                                 }
2998                                 attr_name->an_oc = NULL;
2999                                 attr_name->an_oc_exclude = 0;
3000                                 if ( attr_name->an_desc == slap_schema.si_ad_objectClass )
3001                                         qm->attr_sets[num].flags |= PC_GOT_OC;
3002                                 attr_name++;
3003                                 BER_BVZERO( &attr_name->an_name );
3004                         }
3005
3006                         /* warn if list contains both "*" and "+" */
3007                         if ( i > 4 && all_user && all_op ) {
3008                                 snprintf( c->cr_msg, sizeof( c->cr_msg ),
3009                                         "warning: attribute list contains \"*\" and \"+\"" );
3010                                 Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
3011                         }
3012                 }
3013                 break;
3014         case PC_TEMP:
3015                 if ( cm->numattrsets == 0 ) {
3016                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "\"proxycache\" directive not provided yet" );
3017                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
3018                         return( 1 );
3019                 }
3020                 if ( lutil_atoi( &i, c->argv[2] ) != 0 ) {
3021                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "unable to parse template #=\"%s\"",
3022                                 c->argv[2] );
3023                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
3024                         return( 1 );
3025                 }
3026
3027                 if ( i < 0 || i >= cm->numattrsets || 
3028                         !(qm->attr_sets[i].flags & PC_CONFIGURED )) {
3029                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "template index %d invalid (%s%d)",
3030                                 i, cm->numattrsets > 1 ? "0->" : "", cm->numattrsets - 1 );
3031                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
3032                         return 1;
3033                 }
3034                 temp = ch_calloc( 1, sizeof( QueryTemplate ));
3035                 temp->qmnext = qm->templates;
3036                 qm->templates = temp;
3037                 ldap_pvt_thread_rdwr_init( &temp->t_rwlock );
3038                 temp->query = temp->query_last = NULL;
3039                 if ( lutil_parse_time( c->argv[3], &t ) != 0 ) {
3040                         snprintf( c->cr_msg, sizeof( c->cr_msg ),
3041                                 "unable to parse template ttl=\"%s\"",
3042                                 c->argv[3] );
3043                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
3044                         return( 1 );
3045                 }
3046                 temp->ttl = (time_t)t;
3047                 temp->negttl = (time_t)0;
3048                 temp->limitttl = (time_t)0;
3049                 switch ( c->argc ) {
3050                 case 6:
3051                         if ( lutil_parse_time( c->argv[5], &t ) != 0 ) {
3052                                 snprintf( c->cr_msg, sizeof( c->cr_msg ),
3053                                         "unable to parse template sizelimit ttl=\"%s\"",
3054                                         c->argv[5] );
3055                                 Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
3056                                         return( 1 );
3057                         }
3058                         temp->limitttl = (time_t)t;
3059                         /* fallthru */
3060
3061                 case 5:
3062                         if ( lutil_parse_time( c->argv[4], &t ) != 0 ) {
3063                                 snprintf( c->cr_msg, sizeof( c->cr_msg ),
3064                                         "unable to parse template negative ttl=\"%s\"",
3065                                         c->argv[4] );
3066                                 Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
3067                                         return( 1 );
3068                         }
3069                         temp->negttl = (time_t)t;
3070                         break;
3071                 }
3072
3073                 temp->no_of_queries = 0;
3074
3075                 ber_str2bv( c->argv[1], 0, 1, &temp->querystr );
3076                 Debug( pcache_debug, "Template:\n", 0, 0, 0 );
3077                 Debug( pcache_debug, "  query template: %s\n",
3078                                 temp->querystr.bv_val, 0, 0 );
3079                 temp->attr_set_index = i;
3080                 qm->attr_sets[i].flags |= PC_REFERENCED;
3081                 temp->qtnext = qm->attr_sets[i].templates;
3082                 qm->attr_sets[i].templates = temp;
3083                 Debug( pcache_debug, "  attributes: \n", 0, 0, 0 );
3084                 if ( ( attrarray = qm->attr_sets[i].attrs ) != NULL ) {
3085                         for ( i=0; attrarray[i].an_name.bv_val; i++ )
3086                                 Debug( pcache_debug, "\t%s\n",
3087                                         attrarray[i].an_name.bv_val, 0, 0 );
3088                 }
3089                 break;
3090         case PC_RESP:
3091                 if ( strcasecmp( c->argv[1], "head" ) == 0 ) {
3092                         cm->response_cb = PCACHE_RESPONSE_CB_HEAD;
3093
3094                 } else if ( strcasecmp( c->argv[1], "tail" ) == 0 ) {
3095                         cm->response_cb = PCACHE_RESPONSE_CB_TAIL;
3096
3097                 } else {
3098                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "unknown specifier" );
3099                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
3100                         return 1;
3101                 }
3102                 break;
3103         case PC_QUERIES:
3104                 if ( c->value_int <= 0 ) {
3105                         snprintf( c->cr_msg, sizeof( c->cr_msg ), "max queries must be positive" );
3106                         Debug( LDAP_DEBUG_CONFIG, "%s: %s.\n", c->log, c->cr_msg, 0 );
3107                         return( 1 );
3108                 }
3109                 cm->max_queries = c->value_int;
3110                 break;
3111         }
3112         return rc;
3113 }
3114
3115 static int
3116 pcache_db_config(
3117         BackendDB       *be,
3118         const char      *fname,
3119         int             lineno,
3120         int             argc,
3121         char            **argv
3122 )
3123 {
3124         slap_overinst   *on = (slap_overinst *)be->bd_info;
3125         cache_manager*  cm = on->on_bi.bi_private;
3126
3127         /* Something for the cache database? */
3128         if ( cm->db.bd_info && cm->db.bd_info->bi_db_config )
3129                 return cm->db.bd_info->bi_db_config( &cm->db, fname, lineno,
3130                         argc, argv );
3131         return SLAP_CONF_UNKNOWN;
3132 }
3133
3134 static int
3135 pcache_db_init(
3136         BackendDB *be,
3137         ConfigReply *cr)
3138 {
3139         slap_overinst *on = (slap_overinst *)be->bd_info;
3140         cache_manager *cm;
3141         query_manager *qm;
3142
3143         cm = (cache_manager *)ch_malloc(sizeof(cache_manager));
3144         on->on_bi.bi_private = cm;
3145
3146         qm = (query_manager*)ch_malloc(sizeof(query_manager));
3147
3148         cm->db = *be;
3149         SLAP_DBFLAGS(&cm->db) |= SLAP_DBFLAG_NO_SCHEMA_CHECK;
3150         cm->db.be_private = NULL;
3151         cm->db.be_pcl_mutexp = &cm->db.be_pcl_mutex;
3152         cm->qm = qm;
3153         cm->numattrsets = 0;
3154         cm->num_entries_limit = 5;
3155         cm->num_cached_queries = 0;
3156         cm->max_entries = 0;
3157         cm->cur_entries = 0;
3158         cm->max_queries = 10000;
3159         cm->save_queries = 0;
3160         cm->response_cb = PCACHE_RESPONSE_CB_TAIL;
3161         cm->defer_db_open = 1;
3162         cm->cc_period = 1000;
3163         cm->cc_paused = 0;
3164         cm->cc_arg = NULL;
3165
3166         qm->attr_sets = NULL;
3167         qm->templates = NULL;
3168         qm->lru_top = NULL;
3169         qm->lru_bottom = NULL;
3170
3171         qm->qcfunc = query_containment;
3172         qm->crfunc = cache_replacement;
3173         qm->addfunc = add_query;
3174         ldap_pvt_thread_mutex_init(&qm->lru_mutex);
3175
3176         ldap_pvt_thread_mutex_init(&cm->cache_mutex);
3177         return 0;
3178 }
3179
3180 static int
3181 pcache_cachedquery_open_cb( Operation *op, SlapReply *rs )
3182 {
3183         assert( op->o_tag == LDAP_REQ_SEARCH );
3184
3185         if ( rs->sr_type == REP_SEARCH ) {
3186                 Attribute       *a;
3187
3188                 a = attr_find( rs->sr_entry->e_attrs, ad_cachedQueryURL );
3189                 if ( a != NULL ) {
3190                         BerVarray       *valsp;
3191
3192                         assert( a->a_nvals != NULL );
3193
3194                         valsp = op->o_callback->sc_private;
3195                         assert( *valsp == NULL );
3196
3197                         ber_bvarray_dup_x( valsp, a->a_nvals, op->o_tmpmemctx );
3198                 }
3199         }
3200
3201         return 0;
3202 }
3203
3204 static int
3205 pcache_cachedquery_count_cb( Operation *op, SlapReply *rs )
3206 {
3207         assert( op->o_tag == LDAP_REQ_SEARCH );
3208
3209         if ( rs->sr_type == REP_SEARCH ) {
3210                 int     *countp = (int *)op->o_callback->sc_private;
3211
3212                 (*countp)++;
3213         }
3214
3215         return 0;
3216 }
3217
3218 static int
3219 pcache_db_open2(
3220         slap_overinst *on,
3221         ConfigReply *cr )
3222 {
3223         cache_manager   *cm = on->on_bi.bi_private;
3224         query_manager*  qm = cm->qm;
3225         int rc;
3226
3227         rc = backend_startup_one( &cm->db, cr );
3228         if ( rc == 0 ) {
3229                 cm->defer_db_open = 0;
3230         }
3231
3232         /* There is no runqueue in TOOL mode */
3233         if (( slapMode & SLAP_SERVER_MODE ) && rc == 0 ) {
3234                 ldap_pvt_thread_mutex_lock( &slapd_rq.rq_mutex );
3235                 ldap_pvt_runqueue_insert( &slapd_rq, cm->cc_period,
3236                         consistency_check, on,
3237                         "pcache_consistency", cm->db.be_suffix[0].bv_val );
3238                 ldap_pvt_thread_mutex_unlock( &slapd_rq.rq_mutex );
3239
3240                 /* Cached database must have the rootdn */
3241                 if ( BER_BVISNULL( &cm->db.be_rootndn )
3242                                 || BER_BVISEMPTY( &cm->db.be_rootndn ) )
3243                 {
3244                         Debug( LDAP_DEBUG_ANY, "pcache_db_open(): "
3245                                 "underlying database of type \"%s\"\n"
3246                                 "    serving naming context \"%s\"\n"
3247                                 "    has no \"rootdn\", required by \"proxycache\".\n",
3248                                 on->on_info->oi_orig->bi_type,
3249                                 cm->db.be_suffix[0].bv_val, 0 );
3250                         return 1;
3251                 }
3252
3253                 if ( cm->save_queries ) {
3254                         void            *thrctx = ldap_pvt_thread_pool_context();
3255                         Connection      conn = { 0 };
3256                         OperationBuffer opbuf;
3257                         Operation       *op;
3258                         slap_callback   cb = { 0 };
3259                         SlapReply       rs = { 0 };
3260                         BerVarray       vals = NULL;
3261                         Filter          f = { 0 }, f2 = { 0 };
3262                         AttributeAssertion      ava = ATTRIBUTEASSERTION_INIT;
3263                         AttributeName   attrs[ 2 ] = { 0 };
3264
3265                         connection_fake_init( &conn, &opbuf, thrctx );
3266                         op = &opbuf.ob_op;
3267
3268                         op->o_bd = &cm->db;
3269
3270                         op->o_tag = LDAP_REQ_SEARCH;
3271                         op->o_protocol = LDAP_VERSION3;
3272                         cb.sc_response = pcache_cachedquery_open_cb;
3273                         cb.sc_private = &vals;
3274                         op->o_callback = &cb;
3275                         op->o_time = slap_get_time();
3276                         op->o_do_not_cache = 1;
3277                         op->o_managedsait = SLAP_CONTROL_CRITICAL;
3278
3279                         op->o_dn = cm->db.be_rootdn;
3280                         op->o_ndn = cm->db.be_rootndn;
3281                         op->o_req_dn = cm->db.be_suffix[ 0 ];
3282                         op->o_req_ndn = cm->db.be_nsuffix[ 0 ];
3283
3284                         op->ors_scope = LDAP_SCOPE_BASE;
3285                         op->ors_deref = LDAP_DEREF_NEVER;
3286                         op->ors_slimit = 1;
3287                         op->ors_tlimit = SLAP_NO_LIMIT;
3288                         ber_str2bv( "(cachedQueryURL=*)", 0, 0, &op->ors_filterstr );
3289                         f.f_choice = LDAP_FILTER_PRESENT;
3290                         f.f_desc = ad_cachedQueryURL;
3291                         op->ors_filter = &f;
3292                         attrs[ 0 ].an_desc = ad_cachedQueryURL;
3293                         attrs[ 0 ].an_name = ad_cachedQueryURL->ad_cname;
3294                         op->ors_attrs = attrs;
3295                         op->ors_attrsonly = 0;
3296
3297                         rc = op->o_bd->be_search( op, &rs );
3298                         if ( rc == LDAP_SUCCESS && vals != NULL ) {
3299                                 int     i;
3300
3301                                 for ( i = 0; !BER_BVISNULL( &vals[ i ] ); i++ ) {
3302                                         if ( url2query( vals[ i ].bv_val, op, qm ) == 0 ) {
3303                                                 cm->num_cached_queries++;
3304                                         }
3305                                 }
3306
3307                                 ber_bvarray_free_x( vals, op->o_tmpmemctx );
3308                         }
3309
3310                         /* count cached entries */
3311                         f.f_choice = LDAP_FILTER_NOT;
3312                         f.f_not = &f2;
3313                         f2.f_choice = LDAP_FILTER_EQUALITY;
3314                         f2.f_ava = &ava;
3315                         f2.f_av_desc = slap_schema.si_ad_objectClass;
3316                         BER_BVSTR( &f2.f_av_value, "glue" );
3317                         ber_str2bv( "(!(objectClass=glue))", 0, 0, &op->ors_filterstr );
3318
3319                         op->ors_slimit = SLAP_NO_LIMIT;
3320                         op->ors_scope = LDAP_SCOPE_SUBTREE;
3321                         op->ors_attrs = slap_anlist_no_attrs;
3322
3323                         op->o_callback->sc_response = pcache_cachedquery_count_cb;
3324                         rs.sr_nentries = 0;
3325                         op->o_callback->sc_private = &rs.sr_nentries;
3326
3327                         rc = op->o_bd->be_search( op, &rs );
3328
3329                         cm->cur_entries = rs.sr_nentries;
3330
3331                         /* ignore errors */
3332                         rc = 0;
3333                 }
3334         }
3335         return rc;
3336 }
3337
3338 static int
3339 pcache_db_open(
3340         BackendDB *be,
3341         ConfigReply *cr )
3342 {
3343         slap_overinst   *on = (slap_overinst *)be->bd_info;
3344         cache_manager   *cm = on->on_bi.bi_private;
3345         query_manager*  qm = cm->qm;
3346         int             i, ncf = 0, rf = 0, nrf = 0, rc = 0;
3347
3348         /* check attr sets */
3349         for ( i = 0; i < cm->numattrsets; i++) {
3350                 if ( !( qm->attr_sets[i].flags & PC_CONFIGURED ) ) {
3351                         if ( qm->attr_sets[i].flags & PC_REFERENCED ) {
3352                                 Debug( LDAP_DEBUG_CONFIG, "pcache: attr set #%d not configured but referenced.\n", i, 0, 0 );
3353                                 rf++;
3354
3355                         } else {
3356                                 Debug( LDAP_DEBUG_CONFIG, "pcache: warning, attr set #%d not configured.\n", i, 0, 0 );
3357                         }
3358                         ncf++;
3359
3360                 } else if ( !( qm->attr_sets[i].flags & PC_REFERENCED ) ) {
3361                         Debug( LDAP_DEBUG_CONFIG, "pcache: attr set #%d configured but not referenced.\n", i, 0, 0 );
3362                         nrf++;
3363                 }
3364         }
3365
3366         if ( ncf || rf || nrf ) {
3367                 Debug( LDAP_DEBUG_CONFIG, "pcache: warning, %d attr sets configured but not referenced.\n", nrf, 0, 0 );
3368                 Debug( LDAP_DEBUG_CONFIG, "pcache: warning, %d attr sets not configured.\n", ncf, 0, 0 );
3369                 Debug( LDAP_DEBUG_CONFIG, "pcache: %d attr sets not configured but referenced.\n", rf, 0, 0 );
3370
3371                 if ( rf > 0 ) {
3372                         return 1;
3373                 }
3374         }
3375
3376         /* need to inherit something from the original database... */
3377         cm->db.be_def_limit = be->be_def_limit;
3378         cm->db.be_limits = be->be_limits;
3379         cm->db.be_acl = be->be_acl;
3380         cm->db.be_dfltaccess = be->be_dfltaccess;
3381
3382         if ( SLAP_DBMONITORING( be ) ) {
3383                 SLAP_DBFLAGS( &cm->db ) |= SLAP_DBFLAG_MONITORING;
3384
3385         } else {
3386                 SLAP_DBFLAGS( &cm->db ) &= ~SLAP_DBFLAG_MONITORING;
3387         }
3388
3389         if ( !cm->defer_db_open )
3390                 rc = pcache_db_open2( on, cr );
3391
3392         return rc;
3393 }
3394
3395 static void
3396 pcache_free_qbase( void *v )
3397 {
3398         Qbase *qb = v;
3399         int i;
3400
3401         for (i=0; i<3; i++)
3402                 tavl_free( qb->scopes[i], NULL );
3403         ch_free( qb );
3404 }
3405
3406 static int
3407 pcache_db_close(
3408         BackendDB *be,
3409         ConfigReply *cr
3410 )
3411 {
3412         slap_overinst *on = (slap_overinst *)be->bd_info;
3413         cache_manager *cm = on->on_bi.bi_private;
3414         query_manager *qm = cm->qm;
3415         QueryTemplate *tm;
3416         int i, rc = 0;
3417
3418         if ( cm->save_queries ) {
3419                 CachedQuery     *qc;
3420                 BerVarray       vals = NULL;
3421
3422                 void            *thrctx;
3423                 Connection      conn = { 0 };
3424                 OperationBuffer opbuf;
3425                 Operation       *op;
3426                 slap_callback   cb = { 0 };
3427
3428                 SlapReply       rs = { REP_RESULT };
3429                 Modifications   mod = { 0 };
3430
3431                 thrctx = ldap_pvt_thread_pool_context();
3432
3433                 connection_fake_init( &conn, &opbuf, thrctx );
3434                 op = &opbuf.ob_op;
3435
3436                 if ( qm->templates != NULL ) {
3437                         for ( tm = qm->templates; tm != NULL; tm = tm->qmnext ) {
3438                                 for ( qc = tm->query; qc; qc = qc->next ) {
3439                                         struct berval   bv;
3440
3441                                         if ( query2url( op, qc, &bv ) == 0 ) {
3442                                                 ber_bvarray_add_x( &vals, &bv, op->o_tmpmemctx );
3443                                         }
3444                                 }
3445                         }
3446                 }
3447
3448                 op->o_bd = &cm->db;
3449                 op->o_dn = cm->db.be_rootdn;
3450                 op->o_ndn = cm->db.be_rootndn;
3451
3452                 op->o_tag = LDAP_REQ_MODIFY;
3453                 op->o_protocol = LDAP_VERSION3;
3454                 cb.sc_response = slap_null_cb;
3455                 op->o_callback = &cb;
3456                 op->o_time = slap_get_time();
3457                 op->o_do_not_cache = 1;
3458                 op->o_managedsait = SLAP_CONTROL_CRITICAL;
3459
3460                 op->o_req_dn = op->o_bd->be_suffix[0];
3461                 op->o_req_ndn = op->o_bd->be_nsuffix[0];
3462
3463                 mod.sml_op = LDAP_MOD_REPLACE;
3464                 mod.sml_flags = 0;
3465                 mod.sml_desc = ad_cachedQueryURL;
3466                 mod.sml_type = ad_cachedQueryURL->ad_cname;
3467                 mod.sml_values = vals;
3468                 mod.sml_nvalues = NULL;
3469                 mod.sml_numvals = 1;
3470                 mod.sml_next = NULL;
3471                 Debug( pcache_debug,
3472                         "%sSETTING CACHED QUERY URLS\n",
3473                         vals == NULL ? "RE" : "", 0, 0 );
3474
3475                 op->orm_modlist = &mod;
3476
3477                 op->o_bd->be_modify( op, &rs );
3478
3479                 ber_bvarray_free_x( vals, op->o_tmpmemctx );
3480         }
3481
3482         /* cleanup stuff inherited from the original database... */
3483         cm->db.be_limits = NULL;
3484         cm->db.be_acl = NULL;
3485
3486         /* stop the thread ... */
3487         if ( cm->cc_arg ) {
3488                 ldap_pvt_thread_mutex_lock( &slapd_rq.rq_mutex );
3489                 if ( ldap_pvt_runqueue_isrunning( &slapd_rq, cm->cc_arg ) ) {
3490                         ldap_pvt_runqueue_stoptask( &slapd_rq, cm->cc_arg );
3491                 }
3492                 ldap_pvt_runqueue_remove( &slapd_rq, cm->cc_arg );
3493                 ldap_pvt_thread_mutex_unlock( &slapd_rq.rq_mutex );
3494         }
3495
3496         if ( cm->db.bd_info->bi_db_close ) {
3497                 rc = cm->db.bd_info->bi_db_close( &cm->db, NULL );
3498         }
3499         while ( (tm = qm->templates) != NULL ) {
3500                 CachedQuery *qc, *qn;
3501                 qm->templates = tm->qmnext;
3502                 for ( qc = tm->query; qc; qc = qn ) {
3503                         qn = qc->next;
3504                         free_query( qc );
3505                 }
3506                 avl_free( tm->qbase, pcache_free_qbase );
3507                 free( tm->querystr.bv_val );
3508                 ldap_pvt_thread_rdwr_destroy( &tm->t_rwlock );
3509                 free( tm->t_attrs.attrs );
3510                 free( tm );
3511         }
3512
3513         for ( i=0; i<cm->numattrsets; i++ ) {
3514                 free( qm->attr_sets[i].attrs );
3515         }
3516         free( qm->attr_sets );
3517         qm->attr_sets = NULL;
3518
3519         return rc;
3520 }
3521
3522 static int
3523 pcache_db_destroy(
3524         BackendDB *be,
3525         ConfigReply *cr
3526 )
3527 {
3528         slap_overinst *on = (slap_overinst *)be->bd_info;
3529         cache_manager *cm = on->on_bi.bi_private;
3530         query_manager *qm = cm->qm;
3531
3532         if ( cm->db.be_private != NULL ) {
3533                 backend_stopdown_one( &cm->db );
3534         }
3535
3536         ldap_pvt_thread_mutex_destroy( &qm->lru_mutex );
3537         ldap_pvt_thread_mutex_destroy( &cm->cache_mutex );
3538         free( qm );
3539         free( cm );
3540
3541         return 0;
3542 }
3543
3544 #ifdef PCACHE_CONTROL_PRIVDB
3545 /*
3546         Control ::= SEQUENCE {
3547              controlType             LDAPOID,
3548              criticality             BOOLEAN DEFAULT FALSE,
3549              controlValue            OCTET STRING OPTIONAL }
3550
3551         controlType ::= 1.3.6.1.4.1.4203.666.11.9.5.1
3552
3553  * criticality must be TRUE; controlValue must be absent.
3554  */
3555 static int
3556 parse_privdb_ctrl(
3557         Operation       *op,
3558         SlapReply       *rs,
3559         LDAPControl     *ctrl )
3560 {
3561         if ( op->o_ctrlflag[ privDB_cid ] != SLAP_CONTROL_NONE ) {
3562                 rs->sr_text = "privateDB control specified multiple times";
3563                 return LDAP_PROTOCOL_ERROR;
3564         }
3565
3566         if ( !BER_BVISNULL( &ctrl->ldctl_value ) ) {
3567                 rs->sr_text = "privateDB control value not absent";
3568                 return LDAP_PROTOCOL_ERROR;
3569         }
3570
3571         if ( !ctrl->ldctl_iscritical ) {
3572                 rs->sr_text = "privateDB control criticality required";
3573                 return LDAP_PROTOCOL_ERROR;
3574         }
3575
3576         op->o_ctrlflag[ privDB_cid ] = SLAP_CONTROL_CRITICAL;
3577
3578         return LDAP_SUCCESS;
3579 }
3580
3581 static char *extops[] = {
3582         LDAP_EXOP_MODIFY_PASSWD,
3583         NULL
3584 };
3585 #endif /* PCACHE_CONTROL_PRIVDB */
3586
3587 #ifdef PCACHE_EXOP_QUERY_DELETE
3588 static struct berval pcache_exop_QUERY_DELETE = BER_BVC( PCACHE_EXOP_QUERY_DELETE );
3589
3590 #define LDAP_TAG_EXOP_QUERY_DELETE_BASE ((LBER_CLASS_CONTEXT|LBER_CONSTRUCTED) + 0)
3591 #define LDAP_TAG_EXOP_QUERY_DELETE_DN   ((LBER_CLASS_CONTEXT|LBER_CONSTRUCTED) + 1)
3592 #define LDAP_TAG_EXOP_QUERY_DELETE_UUID ((LBER_CLASS_CONTEXT|LBER_CONSTRUCTED) + 2)
3593
3594 /*
3595         ExtendedRequest ::= [APPLICATION 23] SEQUENCE {
3596              requestName      [0] LDAPOID,
3597              requestValue     [1] OCTET STRING OPTIONAL }
3598
3599         requestName ::= 1.3.6.1.4.1.4203.666.11.9.6.1
3600
3601         requestValue ::= SEQUENCE { CHOICE {
3602                   baseDN           [0] LDAPDN
3603                   entryDN          [1] LDAPDN },
3604              queryID          [2] OCTET STRING (SIZE(16))
3605                   -- constrained to UUID }
3606
3607  * Either baseDN or entryDN must be present, to allow database selection.
3608  *
3609  * 1. if baseDN and queryID are present, then the query corresponding
3610  *    to queryID is deleted;
3611  * 2. if baseDN is present and queryID is absent, then all queries
3612  *    are deleted;
3613  * 3. if entryDN is present and queryID is absent, then all queries
3614  *    corresponding to the queryID values present in entryDN are deleted;
3615  * 4. if entryDN and queryID are present, then all queries
3616  *    corresponding to the queryID values present in entryDN are deleted,
3617  *    but only if the value of queryID is contained in the entry;
3618  *
3619  * Currently, only 1, 3 and 4 are implemented.  2 can be obtained by either
3620  * recursively deleting the database (ldapdelete -r) with PRIVDB control,
3621  * or by removing the database files.
3622
3623         ExtendedResponse ::= [APPLICATION 24] SEQUENCE {
3624              COMPONENTS OF LDAPResult,
3625              responseName     [10] LDAPOID OPTIONAL,
3626              responseValue    [11] OCTET STRING OPTIONAL }
3627
3628  * responseName and responseValue must be absent.
3629  */
3630
3631 /*
3632  * - on success, *tagp is either LDAP_TAG_EXOP_QUERY_DELETE_BASE
3633  *   or LDAP_TAG_EXOP_QUERY_DELETE_DN.
3634  * - if ndn != NULL, it is set to the normalized DN in the request
3635  *   corresponding to either the baseDN or the entryDN, according
3636  *   to *tagp; memory is malloc'ed on the Operation's slab, and must
3637  *   be freed by the caller.
3638  * - if uuid != NULL, it is set to point to the normalized UUID;
3639  *   memory is malloc'ed on the Operation's slab, and must
3640  *   be freed by the caller.
3641  */
3642 static int
3643 pcache_parse_query_delete(
3644         struct berval   *in,
3645         ber_tag_t       *tagp,
3646         struct berval   *ndn,
3647         struct berval   *uuid,
3648         const char      **text,
3649         void            *ctx )
3650 {
3651         int                     rc = LDAP_SUCCESS;
3652         ber_tag_t               tag;
3653         ber_len_t               len = -1;
3654         BerElementBuffer        berbuf;
3655         BerElement              *ber = (BerElement *)&berbuf;
3656         struct berval           reqdata = BER_BVNULL;
3657
3658         *text = NULL;
3659
3660         if ( ndn ) {
3661                 BER_BVZERO( ndn );
3662         }
3663
3664         if ( uuid ) {
3665                 BER_BVZERO( uuid );
3666         }
3667
3668         if ( in == NULL || in->bv_len == 0 ) {
3669                 *text = "empty request data field in queryDelete exop";
3670                 return LDAP_PROTOCOL_ERROR;
3671         }
3672
3673         ber_dupbv_x( &reqdata, in, ctx );
3674
3675         /* ber_init2 uses reqdata directly, doesn't allocate new buffers */
3676         ber_init2( ber, &reqdata, 0 );
3677
3678         tag = ber_scanf( ber, "{" /*}*/ );
3679
3680         if ( tag == LBER_ERROR ) {
3681                 Debug( LDAP_DEBUG_TRACE,
3682                         "pcache_parse_query_delete: decoding error.\n",
3683                         0, 0, 0 );
3684                 goto decoding_error;
3685         }
3686
3687         tag = ber_peek_tag( ber, &len );
3688         if ( tag == LDAP_TAG_EXOP_QUERY_DELETE_BASE
3689                 || tag == LDAP_TAG_EXOP_QUERY_DELETE_DN )
3690         {
3691                 *tagp = tag;
3692
3693                 if ( ndn != NULL ) {
3694                         struct berval   dn;
3695
3696                         tag = ber_scanf( ber, "m", &dn );
3697                         if ( tag == LBER_ERROR ) {
3698                                 Debug( LDAP_DEBUG_TRACE,
3699                                         "pcache_parse_query_delete: DN parse failed.\n",
3700                                         0, 0, 0 );
3701                                 goto decoding_error;
3702                         }
3703
3704                         rc = dnNormalize( 0, NULL, NULL, &dn, ndn, ctx );
3705                         if ( rc != LDAP_SUCCESS ) {
3706                                 *text = "invalid DN in queryDelete exop request data";
3707                                 goto done;
3708                         }
3709
3710                 } else {
3711                         tag = ber_scanf( ber, "x" /* "m" */ );
3712                         if ( tag == LBER_DEFAULT ) {
3713                                 goto decoding_error;
3714                         }
3715                 }
3716
3717                 tag = ber_peek_tag( ber, &len );
3718         }
3719
3720         if ( tag == LDAP_TAG_EXOP_QUERY_DELETE_UUID ) {
3721                 if ( uuid != NULL ) {
3722                         struct berval   bv;
3723                         char            uuidbuf[ LDAP_LUTIL_UUIDSTR_BUFSIZE ];
3724
3725                         tag = ber_scanf( ber, "m", &bv );
3726                         if ( tag == LBER_ERROR ) {
3727                                 Debug( LDAP_DEBUG_TRACE,
3728                                         "pcache_parse_query_delete: UUID parse failed.\n",
3729                                         0, 0, 0 );
3730                                 goto decoding_error;
3731                         }
3732
3733                         if ( bv.bv_len != 16 ) {
3734                                 Debug( LDAP_DEBUG_TRACE,
3735                                         "pcache_parse_query_delete: invalid UUID length %lu.\n",
3736                                         (unsigned long)bv.bv_len, 0, 0 );
3737                                 goto decoding_error;
3738                         }
3739
3740                         rc = lutil_uuidstr_from_normalized(
3741                                 bv.bv_val, bv.bv_len,
3742                                 uuidbuf, sizeof( uuidbuf ) );
3743                         if ( rc == -1 ) {
3744                                 goto decoding_error;
3745                         }
3746                         ber_str2bv( uuidbuf, rc, 1, uuid );
3747                         rc = LDAP_SUCCESS;
3748
3749                 } else {
3750                         tag = ber_skip_tag( ber, &len );
3751                         if ( tag == LBER_DEFAULT ) {
3752                                 goto decoding_error;
3753                         }
3754
3755                         if ( len != 16 ) {
3756                                 Debug( LDAP_DEBUG_TRACE,
3757                                         "pcache_parse_query_delete: invalid UUID length %lu.\n",
3758                                         (unsigned long)len, 0, 0 );
3759                                 goto decoding_error;
3760                         }
3761                 }
3762
3763                 tag = ber_peek_tag( ber, &len );
3764         }
3765
3766         if ( tag != LBER_DEFAULT || len != 0 ) {
3767 decoding_error:;
3768                 Debug( LDAP_DEBUG_TRACE,
3769                         "pcache_parse_query_delete: decoding error\n",
3770                         0, 0, 0 );
3771                 rc = LDAP_PROTOCOL_ERROR;
3772                 *text = "queryDelete data decoding error";
3773
3774 done:;
3775                 if ( ndn && !BER_BVISNULL( ndn ) ) {
3776                         slap_sl_free( ndn->bv_val, ctx );
3777                         BER_BVZERO( ndn );
3778                 }
3779
3780                 if ( uuid && !BER_BVISNULL( uuid ) ) {
3781                         slap_sl_free( uuid->bv_val, ctx );
3782                         BER_BVZERO( uuid );
3783                 }
3784         }
3785
3786         if ( !BER_BVISNULL( &reqdata ) ) {
3787                 ber_memfree_x( reqdata.bv_val, ctx );
3788         }
3789
3790         return rc;
3791 }
3792
3793 static int
3794 pcache_exop_query_delete(
3795         Operation       *op,
3796         SlapReply       *rs )
3797 {
3798         BackendDB       *bd = op->o_bd;
3799
3800         struct berval   uuid = BER_BVNULL,
3801                         *uuidp = NULL;
3802         char            buf[ SLAP_TEXT_BUFLEN ] = { '\0' };
3803         int             len = 0;
3804         ber_tag_t       tag = LBER_DEFAULT;
3805
3806         if ( LogTest( LDAP_DEBUG_STATS ) ) {
3807                 uuidp = &uuid;
3808         }
3809
3810         rs->sr_err = pcache_parse_query_delete( op->ore_reqdata,
3811                 &tag, &op->o_req_ndn, uuidp,
3812                 &rs->sr_text, op->o_tmpmemctx );
3813         if ( rs->sr_err != LDAP_SUCCESS ) {
3814                 return rs->sr_err;
3815         }
3816
3817         if ( LogTest( LDAP_DEBUG_STATS ) ) {
3818                 assert( !BER_BVISNULL( &op->o_req_ndn ) );
3819                 len = snprintf( buf, sizeof( buf ), " dn=\"%s\"", op->o_req_ndn.bv_val );
3820
3821                 if ( !BER_BVISNULL( &uuid ) ) {
3822                         snprintf( &buf[ len ], sizeof( buf ) - len, " queryId=\"%s\"", uuid.bv_val );
3823                 }
3824
3825                 Debug( LDAP_DEBUG_STATS, "%s QUERY DELETE%s\n",
3826                         op->o_log_prefix, buf, 0 );
3827         }
3828         op->o_req_dn = op->o_req_ndn;
3829
3830         op->o_bd = select_backend( &op->o_req_ndn, 0 );
3831         rs->sr_err = backend_check_restrictions( op, rs,
3832                 (struct berval *)&pcache_exop_QUERY_DELETE );
3833         if ( rs->sr_err != LDAP_SUCCESS ) {
3834                 goto done;
3835         }
3836
3837         if ( op->o_bd->be_extended == NULL ) {
3838                 send_ldap_error( op, rs, LDAP_UNAVAILABLE_CRITICAL_EXTENSION,
3839                         "backend does not support extended operations" );
3840                 goto done;
3841         }
3842
3843         op->o_bd->be_extended( op, rs );
3844
3845 done:;
3846         if ( !BER_BVISNULL( &op->o_req_ndn ) ) {
3847                 op->o_tmpfree( op->o_req_ndn.bv_val, op->o_tmpmemctx );
3848                 BER_BVZERO( &op->o_req_ndn );
3849                 BER_BVZERO( &op->o_req_dn );
3850         }
3851
3852         if ( !BER_BVISNULL( &uuid ) ) {
3853                 op->o_tmpfree( uuid.bv_val, op->o_tmpmemctx );
3854         }
3855
3856         op->o_bd = bd;
3857
3858         return rs->sr_err;
3859 }
3860
3861 static int
3862 pcache_op_extended( Operation *op, SlapReply *rs )
3863 {
3864         slap_overinst   *on = (slap_overinst *)op->o_bd->bd_info;
3865         cache_manager   *cm = on->on_bi.bi_private;
3866
3867 #ifdef PCACHE_CONTROL_PRIVDB
3868         if ( op->o_ctrlflag[ privDB_cid ] == SLAP_CONTROL_CRITICAL ) {
3869                 return pcache_op_privdb( op, rs );
3870         }
3871 #endif /* PCACHE_CONTROL_PRIVDB */
3872
3873         if ( bvmatch( &op->ore_reqoid, &pcache_exop_QUERY_DELETE ) ) {
3874                 struct berval   uuid = BER_BVNULL;
3875                 ber_tag_t       tag = LBER_DEFAULT;
3876
3877                 rs->sr_err = pcache_parse_query_delete( op->ore_reqdata,
3878                         &tag, NULL, &uuid, &rs->sr_text, op->o_tmpmemctx );
3879                 assert( rs->sr_err == LDAP_SUCCESS );
3880
3881                 if ( tag == LDAP_TAG_EXOP_QUERY_DELETE_DN ) {
3882                         /* remove all queries related to the selected entry */
3883                         rs->sr_err = pcache_remove_entry_queries_from_cache( op,
3884                                 cm, &op->o_req_ndn, &uuid );
3885
3886                 } else if ( tag == LDAP_TAG_EXOP_QUERY_DELETE_BASE ) {
3887                         if ( !BER_BVISNULL( &uuid ) ) {
3888                                 /* remove the selected query */
3889                                 rs->sr_err = pcache_remove_query_from_cache( op,
3890                                         cm, &uuid );
3891
3892                         } else {
3893                                 /* TODO: remove all queries */
3894                                 rs->sr_err = LDAP_UNWILLING_TO_PERFORM;
3895                                 rs->sr_text = "deletion of all queries not implemented";
3896                         }
3897                 }
3898
3899                 op->o_tmpfree( uuid.bv_val, op->o_tmpmemctx );
3900         }
3901
3902         return rs->sr_err;
3903 }
3904 #endif /* PCACHE_EXOP_QUERY_DELETE */
3905
3906 static slap_overinst pcache;
3907
3908 static char *obsolete_names[] = {
3909         "proxycache",
3910         NULL
3911 };
3912
3913 #if SLAPD_OVER_PROXYCACHE == SLAPD_MOD_DYNAMIC
3914 static
3915 #endif /* SLAPD_OVER_PROXYCACHE == SLAPD_MOD_DYNAMIC */
3916 int
3917 pcache_initialize()
3918 {
3919         int i, code;
3920         struct berval debugbv = BER_BVC("pcache");
3921
3922         code = slap_loglevel_get( &debugbv, &pcache_debug );
3923         if ( code ) {
3924                 return code;
3925         }
3926
3927 #ifdef PCACHE_CONTROL_PRIVDB
3928         code = register_supported_control( PCACHE_CONTROL_PRIVDB,
3929                 SLAP_CTRL_BIND|SLAP_CTRL_ACCESS|SLAP_CTRL_HIDE, extops,
3930                 parse_privdb_ctrl, &privDB_cid );
3931         if ( code != LDAP_SUCCESS ) {
3932                 Debug( LDAP_DEBUG_ANY,
3933                         "pcache_initialize: failed to register control %s (%d)\n",
3934                         PCACHE_CONTROL_PRIVDB, code, 0 );
3935                 return code;
3936         }
3937 #endif /* PCACHE_CONTROL_PRIVDB */
3938
3939 #ifdef PCACHE_EXOP_QUERY_DELETE
3940         code = load_extop2( (struct berval *)&pcache_exop_QUERY_DELETE,
3941                 SLAP_EXOP_WRITES|SLAP_EXOP_HIDE, pcache_exop_query_delete,
3942                 0 );
3943         if ( code != LDAP_SUCCESS ) {
3944                 Debug( LDAP_DEBUG_ANY,
3945                         "pcache_initialize: unable to register queryDelete exop: %d.\n",
3946                         code, 0, 0 );
3947                 return code;
3948         }
3949 #endif /* PCACHE_EXOP_QUERY_DELETE */
3950
3951         for ( i = 0; as[i].desc != NULL; i++ ) {
3952                 code = register_at( as[i].desc, as[i].adp, 0 );
3953                 if ( code ) {
3954                         Debug( LDAP_DEBUG_ANY,
3955                                 "pcache_initialize: register_at #%d failed\n", i, 0, 0 );
3956                         return code;
3957                 }
3958                 (*as[i].adp)->ad_type->sat_flags |= SLAP_AT_HIDE;
3959         }
3960
3961         pcache.on_bi.bi_type = "pcache";
3962         pcache.on_bi.bi_obsolete_names = obsolete_names;
3963         pcache.on_bi.bi_db_init = pcache_db_init;
3964         pcache.on_bi.bi_db_config = pcache_db_config;
3965         pcache.on_bi.bi_db_open = pcache_db_open;
3966         pcache.on_bi.bi_db_close = pcache_db_close;
3967         pcache.on_bi.bi_db_destroy = pcache_db_destroy;
3968
3969         pcache.on_bi.bi_op_search = pcache_op_search;
3970 #ifdef PCACHE_CONTROL_PRIVDB
3971         pcache.on_bi.bi_op_bind = pcache_op_privdb;
3972         pcache.on_bi.bi_op_compare = pcache_op_privdb;
3973         pcache.on_bi.bi_op_modrdn = pcache_op_privdb;
3974         pcache.on_bi.bi_op_modify = pcache_op_privdb;
3975         pcache.on_bi.bi_op_add = pcache_op_privdb;
3976         pcache.on_bi.bi_op_delete = pcache_op_privdb;
3977 #endif /* PCACHE_CONTROL_PRIVDB */
3978 #ifdef PCACHE_EXOP_QUERY_DELETE
3979         pcache.on_bi.bi_extended = pcache_op_extended;
3980 #elif defined( PCACHE_CONTROL_PRIVDB )
3981         pcache.on_bi.bi_extended = pcache_op_privdb;
3982 #endif
3983
3984         pcache.on_bi.bi_chk_controls = pcache_chk_controls;
3985
3986         pcache.on_bi.bi_cf_ocs = pcocs;
3987
3988         code = config_register_schema( pccfg, pcocs );
3989         if ( code ) return code;
3990
3991         {
3992                 const char *text;
3993                 code = slap_str2ad( "olcDatabase", &pcdummy[0].ad, &text );
3994                 if ( code ) return code;
3995         }
3996         return overlay_register( &pcache );
3997 }
3998
3999 #if SLAPD_OVER_PROXYCACHE == SLAPD_MOD_DYNAMIC
4000 int init_module(int argc, char *argv[]) {
4001         return pcache_initialize();
4002 }
4003 #endif
4004
4005 #endif  /* defined(SLAPD_OVER_PROXYCACHE) */