1 /* unique.c - attribute uniqueness module */
3 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
5 * Copyright 2004-2006 The OpenLDAP Foundation.
6 * Portions Copyright 2004 Symas Corporation.
9 * Redistribution and use in source and binary forms, with or without
10 * modification, are permitted only as authorized by the OpenLDAP
13 * A copy of this license is available in the file LICENSE in the
14 * top-level directory of the distribution or, alternatively, at
15 * <http://www.OpenLDAP.org/license.html>.
18 * This work was initially developed by Symas Corp. for inclusion in
19 * OpenLDAP Software. This work was sponsored by Hewlett-Packard.
24 #ifdef SLAPD_OVER_UNIQUE
28 #include <ac/string.h>
29 #include <ac/socket.h>
34 static slap_overinst unique;
36 typedef struct unique_attrs_s {
37 struct unique_attrs_s *next; /* list of attrs */
38 AttributeDescription *attr;
41 typedef struct unique_data_s {
42 const char *message; /* breadcrumbs */
43 struct unique_attrs_s *attrs; /* list of known attrs */
44 struct unique_attrs_s *ignore; /* list of ignored attrs */
45 BerValue dn; /* base of "unique tree" */
46 char strict; /* null considered unique too */
49 typedef struct unique_counter_s {
61 static ConfigDriver unique_cf_gen;
63 static ConfigTable uniquecfg[] = {
64 { "unique_base", "basedn", 2, 2, 0, ARG_DN|ARG_MAGIC|UNIQUE_BASE,
65 unique_cf_gen, "( OLcfgOvAt:10.1 NAME 'olcUniqueBase' "
66 "DESC 'Subtree for uniqueness searches' "
67 "SYNTAX OMsDN SINGLE-VALUE )", NULL, NULL },
68 { "unique_ignore", "attribute...", 2, 0, 0, ARG_MAGIC|UNIQUE_IGNORE,
69 unique_cf_gen, "( OLcfgOvAt:10.2 NAME 'olcUniqueIgnore' "
70 "DESC 'Attributes for which uniqueness shall not be enforced' "
71 "SYNTAX OMsDirectoryString )", NULL, NULL },
72 { "unique_attributes", "attribute...", 2, 0, 0, ARG_MAGIC|UNIQUE_ATTR,
73 unique_cf_gen, "( OLcfgOvAt:10.3 NAME 'olcUniqueAttribute' "
74 "DESC 'Attributes for which uniqueness shall be enforced' "
75 "SYNTAX OMsDirectoryString )", NULL, NULL },
76 { "unique_strict", "on|off", 1, 2, 0,
77 ARG_ON_OFF|ARG_OFFSET|UNIQUE_STRICT,
78 (void *)offsetof(unique_data, strict),
79 "( OLcfgOvAt:10.4 NAME 'olcUniqueStrict' "
80 "DESC 'Enforce uniqueness of null values' "
81 "SYNTAX OMsBoolean SINGLE-VALUE )", NULL, NULL },
82 { NULL, NULL, 0, 0, 0, ARG_IGNORED }
85 static ConfigOCs uniqueocs[] = {
87 "NAME 'olcUniqueConfig' "
88 "DESC 'Attribute value uniqueness configuration' "
89 "SUP olcOverlayConfig "
90 "MAY ( olcUniqueBase $ olcUniqueIgnore $ "
91 "olcUniqueAttribute $ olcUniqueStrict ) )",
92 Cft_Overlay, uniquecfg },
97 unique_cf_gen( ConfigArgs *c )
99 slap_overinst *on = (slap_overinst *)c->bi;
100 unique_data *ud = (unique_data *)on->on_bi.bi_private;
101 BackendDB *be = (BackendDB *)c->be;
102 unique_attrs *up, *pup, **pupp = NULL;
103 AttributeDescription *ad;
105 int rc = ARG_BAD_CONF;
109 case SLAP_CONFIG_EMIT:
112 if ( !BER_BVISEMPTY( &ud->dn )) {
113 rc = value_add_one( &c->rvalue_vals, &ud->dn );
115 rc = value_add_one( &c->rvalue_nvals, &ud->dn );
120 /* fallthrough to UNIQUE_ATTR */
122 if ( c->type == UNIQUE_IGNORE ) up = ud->ignore;
125 value_add_one( &c->rvalue_vals,
126 &up->attr->ad_cname );
132 /* handled via ARG_OFFSET */
133 /* fallthrough to default */
138 case LDAP_MOD_DELETE:
141 /* default to the base of our configured database */
142 if ( ud->dn.bv_val ) ber_memfree ( ud->dn.bv_val );
143 ber_dupbv( &ud->dn, &be->be_nsuffix[0] );
147 /* fallthrough to UNIQUE_ATTR */
149 if ( c->type == UNIQUE_IGNORE ) pupp = &ud->ignore;
150 else pupp = &ud->attrs;
163 /* delete from linked list */
164 for ( i=0; i < c->valx; ++i ) {
165 pupp = &(*pupp)->next;
168 *pupp = (*pupp)->next;
170 /* AttributeDescriptions are global so
171 * shouldn't be freed here... */
177 /* handled via ARG_OFFSET */
178 /* fallthrough to default */
183 case SLAP_CONFIG_ADD:
184 /* fallthrough to LDAP_MOD_ADD */
188 if ( !dnIsSuffix ( &c->value_ndn,
189 &be->be_nsuffix[0] ) ) {
190 sprintf ( c->msg, "dn is not a suffix of backend base" );
191 Debug ( LDAP_DEBUG_CONFIG, "unique add: %s\n",
192 c->msg, NULL, NULL );
195 if ( ud->dn.bv_val ) ber_memfree ( ud->dn.bv_val );
196 ud->dn = c->value_ndn;
200 /* fallthrough to UNIQUE_ATTR */
203 for ( i=1; i < c->argc; ++i ) {
205 if ( slap_str2ad ( c->argv[i], &ad, &text )
209 sizeof ( unique_attrs ) );
211 if ( c->type == UNIQUE_IGNORE ) {
212 up->next = ud->ignore;
215 up->next = ud->attrs;
219 Debug ( LDAP_DEBUG_CONFIG,
220 "unique add: <%s>: %s\n",
221 c->argv[i], text, NULL );
224 SLAP_TEXT_BUFLEN-1 );
225 c->msg[SLAP_TEXT_BUFLEN-1] = '\0';
231 /* handled via ARG_OFFSET */
232 /* fallthrough to default */
245 ** allocate new unique_data;
246 ** initialize, copy basedn;
247 ** store in on_bi.bi_private;
251 static int unique_db_init(
255 slap_overinst *on = (slap_overinst *)be->bd_info;
256 unique_data *ud = ch_malloc(sizeof(unique_data));
258 /* Debug(LDAP_DEBUG_TRACE, "==> unique_init\n", 0, 0, 0); */
260 ud->message = "_init";
265 /* default to the base of our configured database */
266 ber_dupbv(&ud->dn, &be->be_nsuffix[0]);
267 on->on_bi.bi_private = ud;
272 static int unique_db_destroy(
276 slap_overinst *on = (slap_overinst *)be->bd_info;
278 if ( on->on_bi.bi_private ) {
279 ch_free( on->on_bi.bi_private );
280 on->on_bi.bi_private = NULL;
286 ** mostly, just print the init message;
295 slap_overinst *on = (slap_overinst *)be->bd_info;
296 unique_data *ud = on->on_bi.bi_private;
297 ud->message = "_open";
299 Debug(LDAP_DEBUG_TRACE, "unique_open: overlay initialized\n", 0, 0, 0);
306 ** foreach configured attribute:
317 slap_overinst *on = (slap_overinst *) be->bd_info;
318 unique_data *ud = on->on_bi.bi_private;
319 unique_attrs *ii, *ij;
320 ud->message = "_close";
322 Debug(LDAP_DEBUG_TRACE, "==> unique_close\n", 0, 0, 0);
324 for(ii = ud->attrs; ii; ii = ij) {
330 for(ii = ud->ignore; ii; ii = ij) {
336 ch_free(ud->dn.bv_val);
337 BER_BVZERO( &ud->dn );
347 ** if this is a REP_SEARCH, count++;
351 static int count_attr_cb(
358 /* because you never know */
359 if(!op || !rs) return(0);
361 /* Only search entries are interesting */
362 if(rs->sr_type != REP_SEARCH) return(0);
364 uc = op->o_callback->sc_private;
366 /* Ignore the current entry */
367 if ( dn_match( uc->ndn, &rs->sr_entry->e_nname )) return(0);
369 Debug(LDAP_DEBUG_TRACE, "==> count_attr_cb <%s>\n",
370 rs->sr_entry ? rs->sr_entry->e_name.bv_val : "UNKNOWN_DN", 0, 0);
377 static int count_filter_len(
379 AttributeDescription *ad,
387 while ( !is_at_operational( ad->ad_type ) ) {
389 for ( up = ud->ignore; up; up = up->next ) {
390 if (ad == up->attr ) {
399 for ( up = ud->attrs; up; up = up->next ) {
400 if ( ad == up->attr ) {
408 if ( b && b[0].bv_val ) {
409 for (i = 0; b[i].bv_val; i++ ) {
410 /* note: make room for filter escaping... */
411 ks += ( 3 * b[i].bv_len ) + ad->ad_cname.bv_len + STRLENOF( "(=)" );
413 } else if ( ud->strict ) {
414 ks += ad->ad_cname.bv_len + STRLENOF( "(=*)" ); /* (attr=*) */
421 static char *build_filter(
423 AttributeDescription *ad,
432 while ( !is_at_operational( ad->ad_type ) ) {
434 for ( up = ud->ignore; up; up = up->next ) {
435 if ( ad == up->attr ) {
444 for ( up = ud->attrs; up; up = up->next ) {
445 if ( ad == up->attr ) {
453 if ( b && b[0].bv_val ) {
454 for ( i = 0; b[i].bv_val; i++ ) {
457 ldap_bv2escaped_filter_value_x( &b[i], &bv, 1, ctx );
458 kp += sprintf( kp, "(%s=%s)", ad->ad_cname.bv_val, bv.bv_val );
459 if ( bv.bv_val != b[i].bv_val ) {
460 ber_memfree_x( bv.bv_val, ctx );
463 } else if ( ud->strict ) {
464 kp += sprintf( kp, "(%s=*)", ad->ad_cname.bv_val );
471 static int unique_search(
478 slap_overinst *on = (slap_overinst *) op->o_bd->bd_info;
479 unique_data *ud = on->on_bi.bi_private;
480 SlapReply nrs = { REP_RESULT };
481 slap_callback cb = { NULL, NULL, NULL, NULL }; /* XXX */
482 unique_counter uq = { NULL, 0 };
485 nop->ors_filter = str2filter_x(nop, key);
486 ber_str2bv(key, 0, 0, &nop->ors_filterstr);
488 cb.sc_response = (slap_response*)count_attr_cb;
490 nop->o_callback = &cb;
491 nop->o_tag = LDAP_REQ_SEARCH;
492 nop->ors_scope = LDAP_SCOPE_SUBTREE;
493 nop->ors_deref = LDAP_DEREF_NEVER;
494 nop->ors_limit = NULL;
495 nop->ors_slimit = SLAP_NO_LIMIT;
496 nop->ors_tlimit = SLAP_NO_LIMIT;
497 nop->ors_attrs = slap_anlist_no_attrs;
498 nop->ors_attrsonly = 1;
500 uq.ndn = &op->o_req_ndn;
502 nop->o_req_ndn = ud->dn;
503 nop->o_ndn = op->o_bd->be_rootndn;
505 nop->o_bd = on->on_info->oi_origdb;
506 rc = nop->o_bd->be_search(nop, &nrs);
507 filter_free_x(nop, nop->ors_filter);
508 op->o_tmpfree( key, op->o_tmpmemctx );
510 if(rc != LDAP_SUCCESS && rc != LDAP_NO_SUCH_OBJECT) {
511 op->o_bd->bd_info = (BackendInfo *) on->on_info;
512 send_ldap_error(op, rs, rc, "unique_search failed");
516 Debug(LDAP_DEBUG_TRACE, "=> unique_search found %d records\n", uq.count, 0, 0);
519 op->o_bd->bd_info = (BackendInfo *) on->on_info;
520 send_ldap_error(op, rs, LDAP_CONSTRAINT_VIOLATION,
521 "some attributes not unique");
525 return(SLAP_CB_CONTINUE);
528 #define ALLOC_EXTRA 16 /* extra slop */
530 static int unique_add(
535 slap_overinst *on = (slap_overinst *) op->o_bd->bd_info;
536 unique_data *ud = on->on_bi.bi_private;
543 Debug(LDAP_DEBUG_TRACE, "==> unique_add <%s>\n", op->o_req_dn.bv_val, 0, 0);
545 if ( !dnIsSuffix( &op->o_req_ndn, &ud->dn ))
546 return SLAP_CB_CONTINUE;
549 ** count everything first;
550 ** allocate some memory;
551 ** write the search key;
555 if(!(a = op->ora_e->e_attrs)) {
556 op->o_bd->bd_info = (BackendInfo *) on->on_info;
557 send_ldap_error(op, rs, LDAP_INVALID_SYNTAX,
558 "unique_add() got null op.ora_e.e_attrs");
560 } else for(; a; a = a->a_next) {
561 ks = count_filter_len(ud, a->a_desc, a->a_vals, ks);
565 return SLAP_CB_CONTINUE;
568 key = op->o_tmpalloc(ks, op->o_tmpmemctx);
570 kp = key + sprintf(key, "(|");
572 for(a = op->ora_e->e_attrs; a; a = a->a_next) {
573 kp = build_filter(ud, a->a_desc, a->a_vals, kp, op->o_tmpmemctx);
578 Debug(LDAP_DEBUG_TRACE, "=> unique_add %s\n", key, 0, 0);
580 return unique_search(op, &nop, rs, key);
584 static int unique_modify(
589 slap_overinst *on = (slap_overinst *) op->o_bd->bd_info;
590 unique_data *ud = on->on_bi.bi_private;
597 Debug(LDAP_DEBUG_TRACE, "==> unique_modify <%s>\n", op->o_req_dn.bv_val, 0, 0);
599 if ( !dnIsSuffix( &op->o_req_ndn, &ud->dn ))
600 return SLAP_CB_CONTINUE;
603 ** count everything first;
604 ** allocate some memory;
605 ** write the search key;
609 if(!(m = op->orm_modlist)) {
610 op->o_bd->bd_info = (BackendInfo *) on->on_info;
611 send_ldap_error(op, rs, LDAP_INVALID_SYNTAX,
612 "unique_modify() got null op.orm_modlist");
614 } else for(; m; m = m->sml_next) {
615 if ((m->sml_op & LDAP_MOD_OP) == LDAP_MOD_DELETE) continue;
616 ks = count_filter_len(ud, m->sml_desc, m->sml_values, ks);
620 return SLAP_CB_CONTINUE;
623 key = op->o_tmpalloc(ks, op->o_tmpmemctx);
625 kp = key + sprintf(key, "(|");
627 for(m = op->orm_modlist; m; m = m->sml_next) {
628 if ((m->sml_op & LDAP_MOD_OP) == LDAP_MOD_DELETE) continue;
629 kp = build_filter(ud, m->sml_desc, m->sml_values, kp, op->o_tmpmemctx);
634 Debug(LDAP_DEBUG_TRACE, "=> unique_modify %s\n", key, 0, 0);
636 return unique_search(op, &nop, rs, key);
640 static int unique_modrdn(
645 slap_overinst *on = (slap_overinst *) op->o_bd->bd_info;
646 unique_data *ud = on->on_bi.bi_private;
654 Debug(LDAP_DEBUG_TRACE, "==> unique_modrdn <%s> <%s>\n",
655 op->o_req_dn.bv_val, op->orr_newrdn.bv_val, 0);
657 if ( !dnIsSuffix( &op->o_req_ndn, &ud->dn ) &&
658 (!op->orr_nnewSup || !dnIsSuffix( op->orr_nnewSup, &ud->dn )))
659 return SLAP_CB_CONTINUE;
661 if(ldap_bv2rdn_x(&op->oq_modrdn.rs_newrdn, &newrdn,
662 (char **)&rs->sr_text, LDAP_DN_FORMAT_LDAP, op->o_tmpmemctx )) {
663 op->o_bd->bd_info = (BackendInfo *) on->on_info;
664 send_ldap_error(op, rs, LDAP_INVALID_SYNTAX,
665 "unknown type(s) used in RDN");
668 for(i = 0; newrdn[i]; i++) {
669 AttributeDescription *ad = NULL;
670 if ( slap_bv2ad( &newrdn[i]->la_attr, &ad, &rs->sr_text )) {
671 ldap_rdnfree_x( newrdn, op->o_tmpmemctx );
672 rs->sr_err = LDAP_INVALID_SYNTAX;
673 send_ldap_result( op, rs );
676 newrdn[i]->la_private = ad;
682 for(i = 0; newrdn[i]; i++) {
683 bv[0] = newrdn[i]->la_value;
684 ks = count_filter_len(ud, newrdn[i]->la_private, bv, ks);
688 return SLAP_CB_CONTINUE;
691 key = op->o_tmpalloc(ks, op->o_tmpmemctx);
692 kp = key + sprintf(key, "(|");
694 for(i = 0; newrdn[i]; i++) {
695 bv[0] = newrdn[i]->la_value;
696 kp = build_filter(ud, newrdn[i]->la_private, bv, kp, op->o_tmpmemctx);
701 Debug(LDAP_DEBUG_TRACE, "=> unique_modrdn %s\n", key, 0, 0);
703 return unique_search(op, &nop, rs, key);
707 ** init_module is last so the symbols resolve "for free" --
708 ** it expects to be called automagically during dynamic module initialization
711 int unique_initialize() {
714 /* statically declared just after the #includes at top */
715 unique.on_bi.bi_type = "unique";
716 unique.on_bi.bi_db_init = unique_db_init;
717 unique.on_bi.bi_db_destroy = unique_db_destroy;
718 unique.on_bi.bi_db_open = unique_open;
719 unique.on_bi.bi_db_close = unique_close;
720 unique.on_bi.bi_op_add = unique_add;
721 unique.on_bi.bi_op_modify = unique_modify;
722 unique.on_bi.bi_op_modrdn = unique_modrdn;
723 unique.on_bi.bi_op_delete = NULL;
725 unique.on_bi.bi_cf_ocs = uniqueocs;
726 rc = config_register_schema( uniquecfg, uniqueocs );
729 return(overlay_register(&unique));
732 #if SLAPD_OVER_UNIQUE == SLAPD_MOD_DYNAMIC && defined(PIC)
733 int init_module(int argc, char *argv[]) {
734 return unique_initialize();
738 #endif /* SLAPD_OVER_UNIQUE */