]> git.sur5r.net Git - openldap/blob - servers/slapd/slapmodify.c
ITS#7256 Add some necessary checks.
[openldap] / servers / slapd / slapmodify.c
1 /* $OpenLDAP$ */
2 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
3  *
4  * Copyright 1998-2014 The OpenLDAP Foundation.
5  * Portions Copyright 1998-2003 Kurt D. Zeilenga.
6  * Portions Copyright 2003 IBM Corporation.
7  * All rights reserved.
8  *
9  * Redistribution and use in source and binary forms, with or without
10  * modification, are permitted only as authorized by the OpenLDAP
11  * Public License.
12  *
13  * A copy of this license is available in file LICENSE in the
14  * top-level directory of the distribution or, alternatively, at
15  * <http://www.OpenLDAP.org/license.html>.
16  */
17 /* ACKNOWLEDGEMENTS:
18  * This work was initially developed by Pierangelo Masarati for inclusion
19  * in OpenLDAP Software.
20  */
21
22 #include "portable.h"
23
24 #include <stdio.h>
25
26 #include "ac/stdlib.h"
27
28 #include "ac/ctype.h"
29 #include "ac/string.h"
30 #include "ac/socket.h"
31 #include "ac/unistd.h"
32
33 #include "lber.h"
34 #include "ldif.h"
35 #include "lutil.h"
36 #include "lutil_meter.h"
37 #include <sys/stat.h>
38
39 #include "slapcommon.h"
40
41 static char csnbuf[ LDAP_PVT_CSNSTR_BUFSIZE ];
42
43 int
44 slapmodify( int argc, char **argv )
45 {
46         char *buf = NULL;
47         const char *text;
48         char textbuf[SLAP_TEXT_BUFLEN] = { '\0' };
49         size_t textlen = sizeof textbuf;
50         const char *progname = "slapmodify";
51
52         struct berval csn;
53         unsigned long sid;
54         struct berval bvtext;
55         ID id;
56         OperationBuffer opbuf;
57         Operation *op;
58
59         int checkvals, ldifrc;
60         unsigned long lineno, nextline;
61         int lmax;
62         int rc = EXIT_SUCCESS;
63
64         int enable_meter = 0;
65         lutil_meter_t meter;
66         struct stat stat_buf;
67
68         /* default "000" */
69         csnsid = 0;
70
71         if ( isatty (2) ) enable_meter = 1;
72         slap_tool_init( progname, SLAPMODIFY, argc, argv );
73
74         memset( &opbuf, 0, sizeof(opbuf) );
75         op = &opbuf.ob_op;
76         op->o_hdr = &opbuf.ob_hdr;
77         op->o_bd = be;
78
79         if ( !be->be_entry_open ||
80                 !be->be_entry_close ||
81                 !be->be_entry_put ||
82                 !be->be_dn2id_get ||
83                 !be->be_entry_get ||
84                 !be->be_entry_modify )
85         {
86                 fprintf( stderr, "%s: database doesn't support necessary operations.\n",
87                         progname );
88                 if ( dryrun ) {
89                         fprintf( stderr, "\t(dry) continuing...\n" );
90
91                 } else {
92                         exit( EXIT_FAILURE );
93                 }
94         }
95
96         checkvals = (slapMode & SLAP_TOOL_QUICK) ? 0 : 1;
97
98         lmax = 0;
99         nextline = 0;
100
101         /* enforce schema checking unless not disabled */
102         if ( (slapMode & SLAP_TOOL_NO_SCHEMA_CHECK) == 0) {
103                 SLAP_DBFLAGS(be) &= ~(SLAP_DBFLAG_NO_SCHEMA_CHECK);
104         }
105
106         if( !dryrun && be->be_entry_open( be, 1 ) != 0 ) {
107                 fprintf( stderr, "%s: could not open database.\n",
108                         progname );
109                 exit( EXIT_FAILURE );
110         }
111
112         (void)slap_tool_update_ctxcsn_init();
113
114         if ( enable_meter 
115 #ifdef LDAP_DEBUG
116                 /* tools default to "none" */
117                 && slap_debug == LDAP_DEBUG_NONE
118 #endif
119                 && !fstat ( fileno ( ldiffp->fp ), &stat_buf )
120                 && S_ISREG(stat_buf.st_mode) ) {
121                 enable_meter = !lutil_meter_open(
122                         &meter,
123                         &lutil_meter_text_display,
124                         &lutil_meter_linear_estimator,
125                         stat_buf.st_size);
126         } else {
127                 enable_meter = 0;
128         }
129
130         /* nextline is the line number of the end of the current entry */
131         for( lineno=1; ( ldifrc = ldif_read_record( ldiffp, &nextline, &buf, &lmax )) > 0;
132                 lineno=nextline+1 )
133         {
134                 BackendDB *bd;
135                 Entry *e;
136                 struct berval rbuf;
137                 LDIFRecord lr;
138                 struct berval ndn;
139                 int n;
140                 int is_oc = 0;
141                 int local_rc;
142                 int mod_err = 0;
143                 char *request = "(unknown)";
144
145                 ber_str2bv( buf, 0, 0, &rbuf );
146
147                 if ( lineno < jumpline )
148                         continue;
149
150                 if ( enable_meter )
151                         lutil_meter_update( &meter,
152                                          ftell( ldiffp->fp ),
153                                          0);
154
155                 /*
156                  * Initialize text buffer
157                  */
158                 bvtext.bv_len = textlen;
159                 bvtext.bv_val = textbuf;
160                 bvtext.bv_val[0] = '\0';
161
162                 local_rc = ldap_parse_ldif_record( &rbuf, lineno, &lr,
163                         "slapmodify", LDIF_NO_CONTROLS );
164
165                 if ( local_rc != LDAP_SUCCESS ) {
166                         fprintf( stderr, "%s: could not parse entry (line=%lu)\n",
167                                 progname, lineno );
168                         rc = EXIT_FAILURE;
169                         if( continuemode ) continue;
170                         break;
171                 }
172
173                 switch ( lr.lr_op ) {
174                 case LDAP_REQ_ADD:
175                         request = "add";
176                         break;
177
178                 case LDAP_REQ_MODIFY:
179                         request = "modify";
180                         break;
181
182                 case LDAP_REQ_DELETE:
183                         if ( be->be_entry_delete )
184                         {
185                                 request = "delete";
186                                 break;
187                         }
188                         /* backend does not support delete, fallthrough */
189
190                 case LDAP_REQ_MODRDN:
191                         fprintf( stderr, "%s: request 0x%lx not supported (line=%lu)\n",
192                                 progname, (unsigned long)lr.lr_op, lineno );
193                         rc = EXIT_FAILURE;
194                         if( continuemode ) continue;
195                         goto done;
196
197                 default:
198                         /* record skipped e.g. version: or comment or something we don't handle yet */
199                         continue;
200                 }
201
202                 local_rc = dnNormalize( 0, NULL, NULL, &lr.lr_dn, &ndn, NULL );
203                 if ( local_rc != LDAP_SUCCESS ) {
204                         fprintf( stderr, "%s: DN=\"%s\" normalization failed (line=%lu)\n",
205                                 progname, lr.lr_dn.bv_val, lineno );
206                         rc = EXIT_FAILURE;
207                         if( continuemode ) continue;
208                         break;
209                 }
210
211                 /* make sure the DN is not empty */
212                 if( BER_BVISEMPTY( &ndn ) &&
213                         !BER_BVISEMPTY( be->be_nsuffix ))
214                 {
215                         fprintf( stderr, "%s: line %lu: "
216                                 "%s entry with empty dn=\"\"",
217                                 progname, lineno, request );
218                         bd = select_backend( &ndn, nosubordinates );
219                         if ( bd ) {
220                                 BackendDB *bdtmp;
221                                 int dbidx = 0;
222                                 LDAP_STAILQ_FOREACH( bdtmp, &backendDB, be_next ) {
223                                         if ( bdtmp == bd ) break;
224                                         dbidx++;
225                                 }
226
227                                 assert( bdtmp != NULL );
228                                 
229                                 fprintf( stderr, "; did you mean to use database #%d (%s)?",
230                                         dbidx,
231                                         bd->be_suffix[0].bv_val );
232
233                         }
234                         fprintf( stderr, "\n" );
235                         rc = EXIT_FAILURE;
236                         SLAP_FREE( ndn.bv_val );
237                         ldap_ldif_record_done( &lr );
238                         if( continuemode ) continue;
239                         break;
240                 }
241
242                 /* check backend */
243                 bd = select_backend( &ndn, nosubordinates );
244                 if ( bd != be ) {
245                         fprintf( stderr, "%s: line %lu: "
246                                 "database #%d (%s) not configured to hold \"%s\"",
247                                 progname, lineno,
248                                 dbnum,
249                                 be->be_suffix[0].bv_val,
250                                 lr.lr_dn.bv_val );
251                         if ( bd ) {
252                                 BackendDB *bdtmp;
253                                 int dbidx = 0;
254                                 LDAP_STAILQ_FOREACH( bdtmp, &backendDB, be_next ) {
255                                         if ( bdtmp == bd ) break;
256                                         dbidx++;
257                                 }
258
259                                 assert( bdtmp != NULL );
260                                 
261                                 fprintf( stderr, "; did you mean to use database #%d (%s)?",
262                                         dbidx,
263                                         bd->be_suffix[0].bv_val );
264
265                         } else {
266                                 fprintf( stderr, "; no database configured for that naming context" );
267                         }
268                         fprintf( stderr, "\n" );
269                         rc = EXIT_FAILURE;
270                         SLAP_FREE( ndn.bv_val );
271                         ldap_ldif_record_done( &lr );
272                         if( continuemode ) continue;
273                         break;
274                 }
275
276                 /* get entry */
277                 id = be->be_dn2id_get( be, &ndn );
278                 e = be->be_entry_get( be, id );
279                 if ( e != NULL ) {
280                         Entry *e_tmp = entry_dup( e );
281                         /* FIXME: release? */
282                         e = e_tmp;
283                 }
284
285                 if ( lr.lrop_mods ) {
286                         for ( n = 0; lr.lrop_mods && lr.lrop_mods[ n ] != NULL; n++ ) {
287                                 LDAPMod *mod = lr.lrop_mods[ n ];
288                                 Modification mods = { 0 };
289                                 unsigned i = 0;
290                                 int bin = (mod->mod_op & LDAP_MOD_BVALUES);
291                                 int pretty = 0;
292                                 int normalize = 0;
293
294                                 local_rc = slap_str2ad( mod->mod_type, &mods.sm_desc, &text );
295                                 if ( local_rc != LDAP_SUCCESS ) {
296                                         fprintf( stderr, "%s: slap_str2ad(\"%s\") failed for entry \"%s\" (%d: %s, lineno=%lu)\n",
297                                                 progname, mod->mod_type, lr.lr_dn.bv_val, local_rc, text, lineno );
298                                         rc = EXIT_FAILURE;
299                                         mod_err = 1;
300                                         if( continuemode ) continue;
301                                         SLAP_FREE( ndn.bv_val );
302                                         ldap_ldif_record_done( &lr );
303                                         entry_free( e );
304                                         goto done;
305                                 }
306
307                                 mods.sm_type = mods.sm_desc->ad_cname;
308
309                                 if ( mods.sm_desc->ad_type->sat_syntax->ssyn_pretty ) {
310                                         pretty = 1;
311
312                                 } else {
313                                         assert( mods.sm_desc->ad_type->sat_syntax->ssyn_validate != NULL );
314                                 }
315
316                                 if ( mods.sm_desc->ad_type->sat_equality &&
317                                         mods.sm_desc->ad_type->sat_equality->smr_normalize )
318                                 {
319                                         normalize = 1;
320                                 }
321
322                                 if ( bin && mod->mod_bvalues ) {
323                                         for ( i = 0; mod->mod_bvalues[ i ] != NULL; i++ )
324                                                 ;
325
326                                 } else if ( !bin && mod->mod_values ) {
327                                         for ( i = 0; mod->mod_values[ i ] != NULL; i++ )
328                                                 ;
329                                 }
330
331                                 if ( i != 0 )
332                                 {
333                                         mods.sm_values = SLAP_CALLOC( sizeof( struct berval ), i + 1 );
334                                         if ( normalize ) {
335                                                 mods.sm_nvalues = SLAP_CALLOC( sizeof( struct berval ), i + 1 );
336                                         } else {
337                                                 mods.sm_nvalues = NULL;
338                                         }
339                                 }
340                                 mods.sm_numvals = i;
341
342                                 for ( i = 0; i < mods.sm_numvals; i++ ) {
343                                         struct berval bv;
344
345                                         if ( bin ) {
346                                                 bv = *mod->mod_bvalues[ i ];
347                                         } else {
348                                                 ber_str2bv( mod->mod_values[ i ], 0, 0, &bv );
349                                         }
350
351                                         if ( pretty ) {
352                                                 local_rc = ordered_value_pretty( mods.sm_desc,
353                                                 &bv, &mods.sm_values[i], NULL );
354
355                                         } else {
356                                                 local_rc = ordered_value_validate( mods.sm_desc,
357                                                         &bv, 0 );
358                                         }
359
360                                         if ( local_rc != LDAP_SUCCESS ) {
361                                                 fprintf( stderr, "%s: DN=\"%s\": unable to %s attr=%s value #%d\n",
362                                                         progname, e->e_dn, pretty ? "prettify" : "validate",
363                                                         mods.sm_desc->ad_cname.bv_val, i );
364                                                 /* handle error */
365                                                 mod_err = 1;
366                                                 rc = EXIT_FAILURE;
367                                                 ber_bvarray_free( mods.sm_values );
368                                                 ber_bvarray_free( mods.sm_nvalues );
369                                                 if( continuemode ) continue;
370                                                 SLAP_FREE( ndn.bv_val );
371                                                 ldap_ldif_record_done( &lr );
372                                                 entry_free( e );
373                                                 goto done;
374                                         }
375
376                                         if ( !pretty ) {
377                                                 ber_dupbv( &mods.sm_values[i], &bv );
378                                         }
379
380                                         if ( normalize ) {
381                                                 local_rc = ordered_value_normalize(
382                                                         SLAP_MR_VALUE_OF_ATTRIBUTE_SYNTAX,
383                                                         mods.sm_desc,
384                                                         mods.sm_desc->ad_type->sat_equality,
385                                                         &mods.sm_values[i], &mods.sm_nvalues[i],
386                                                         NULL );
387                                                 if ( local_rc != LDAP_SUCCESS ) {
388                                                         fprintf( stderr, "%s: DN=\"%s\": unable to normalize attr=%s value #%d\n",
389                                                                 progname, e->e_dn, mods.sm_desc->ad_cname.bv_val, i );
390                                                         /* handle error */
391                                                         mod_err = 1;
392                                                         rc = EXIT_FAILURE;
393                                                         ber_bvarray_free( mods.sm_values );
394                                                         ber_bvarray_free( mods.sm_nvalues );
395                                                         if( continuemode ) continue;
396                                                         SLAP_FREE( ndn.bv_val );
397                                                         ldap_ldif_record_done( &lr );
398                                                         entry_free( e );
399                                                         goto done;
400                                                 }
401                                         }
402                                 }
403
404                                 mods.sm_op = (mod->mod_op & ~LDAP_MOD_BVALUES);
405                                 mods.sm_flags = 0;
406
407                                 if ( mods.sm_desc == slap_schema.si_ad_objectClass ) {
408                                         is_oc = 1;
409                                 }
410
411                                 switch ( mods.sm_op ) {
412                                 case LDAP_MOD_ADD:
413                                         local_rc = modify_add_values( e, &mods,
414                                                 0, &text, textbuf, textlen );
415                                         break;
416
417                                 case LDAP_MOD_DELETE:
418                                         local_rc = modify_delete_values( e, &mods,
419                                                 0, &text, textbuf, textlen );
420                                         break;
421
422                                 case LDAP_MOD_REPLACE:
423                                         local_rc = modify_replace_values( e, &mods,
424                                                 0, &text, textbuf, textlen );
425                                         break;
426
427                                 case LDAP_MOD_INCREMENT:
428                                         local_rc = modify_increment_values( e, &mods,
429                                                 0, &text, textbuf, textlen );
430                                         break;
431                                 }
432
433                                 if ( local_rc != LDAP_SUCCESS ) {
434                                         fprintf( stderr, "%s: DN=\"%s\": unable to modify attr=%s\n",
435                                                 progname, e->e_dn, mods.sm_desc->ad_cname.bv_val );
436                                         rc = EXIT_FAILURE;
437                                         ber_bvarray_free( mods.sm_values );
438                                         ber_bvarray_free( mods.sm_nvalues );
439                                         if( continuemode ) continue;
440                                         SLAP_FREE( ndn.bv_val );
441                                         ldap_ldif_record_done( &lr );
442                                         entry_free( e );
443                                         goto done;
444                                 }
445                         }
446
447                         rc = slap_tool_entry_check( progname, op, e, lineno, &text, textbuf, textlen );
448                         if ( rc != LDAP_SUCCESS ) {
449                                 rc = EXIT_FAILURE;
450                                 SLAP_FREE( ndn.bv_val );
451                                 ldap_ldif_record_done( &lr );
452                                 if( continuemode ) continue;
453                                 entry_free( e );
454                                 break;
455                         }
456                 }
457
458                 if ( SLAP_LASTMOD(be) ) {
459                         time_t now = slap_get_time();
460                         char uuidbuf[ LDAP_LUTIL_UUIDSTR_BUFSIZE ];
461                         struct berval vals[ 2 ];
462
463                         struct berval name, timestamp;
464
465                         struct berval nvals[ 2 ];
466                         struct berval nname;
467                         char timebuf[ LDAP_LUTIL_GENTIME_BUFSIZE ];
468
469                         Attribute *a;
470
471                         vals[1].bv_len = 0;
472                         vals[1].bv_val = NULL;
473
474                         nvals[1].bv_len = 0;
475                         nvals[1].bv_val = NULL;
476
477                         csn.bv_len = ldap_pvt_csnstr( csnbuf, sizeof( csnbuf ), csnsid, 0 );
478                         csn.bv_val = csnbuf;
479
480                         timestamp.bv_val = timebuf;
481                         timestamp.bv_len = sizeof(timebuf);
482
483                         slap_timestamp( &now, &timestamp );
484
485                         if ( BER_BVISEMPTY( &be->be_rootndn ) ) {
486                                 BER_BVSTR( &name, SLAPD_ANONYMOUS );
487                                 nname = name;
488                         } else {
489                                 name = be->be_rootdn;
490                                 nname = be->be_rootndn;
491                         }
492
493                         a = attr_find( e->e_attrs, slap_schema.si_ad_entryUUID );
494                         if ( a != NULL ) {
495                                 vals[0].bv_len = lutil_uuidstr( uuidbuf, sizeof( uuidbuf ) );
496                                 vals[0].bv_val = uuidbuf;
497                                 if ( a->a_vals != a->a_nvals ) {
498                                         SLAP_FREE( a->a_nvals[0].bv_val );
499                                         SLAP_FREE( a->a_nvals );
500                                 }
501                                 SLAP_FREE( a->a_vals[0].bv_val );
502                                 SLAP_FREE( a->a_vals );
503                                 a->a_vals = NULL;
504                                 a->a_nvals = NULL;
505                                 a->a_numvals = 0;
506                         }
507                         attr_merge_normalize_one( e, slap_schema.si_ad_entryUUID, vals, NULL );
508
509                         a = attr_find( e->e_attrs, slap_schema.si_ad_creatorsName );
510                         if ( a == NULL ) {
511                                 vals[0] = name;
512                                 nvals[0] = nname;
513                                 attr_merge( e, slap_schema.si_ad_creatorsName, vals, nvals );
514
515                         } else {
516                                 ber_bvreplace( &a->a_vals[0], &name );
517                                 ber_bvreplace( &a->a_nvals[0], &nname );
518                         }
519
520                         a = attr_find( e->e_attrs, slap_schema.si_ad_createTimestamp );
521                         if ( a == NULL ) {
522                                 vals[0] = timestamp;
523                                 attr_merge( e, slap_schema.si_ad_createTimestamp, vals, NULL );
524
525                         } else {
526                                 ber_bvreplace( &a->a_vals[0], &timestamp );
527                         }
528
529                         a = attr_find( e->e_attrs, slap_schema.si_ad_entryCSN );
530                         if ( a == NULL ) {
531                                 vals[0] = csn;
532                                 attr_merge( e, slap_schema.si_ad_entryCSN, vals, NULL );
533
534                         } else {
535                                 ber_bvreplace( &a->a_vals[0], &csn );
536                         }
537
538                         a = attr_find( e->e_attrs, slap_schema.si_ad_modifiersName );
539                         if ( a == NULL ) {
540                                 vals[0] = name;
541                                 nvals[0] = nname;
542                                 attr_merge( e, slap_schema.si_ad_modifiersName, vals, nvals );
543
544                         } else {
545                                 ber_bvreplace( &a->a_vals[0], &name );
546                                 ber_bvreplace( &a->a_nvals[0], &nname );
547                         }
548
549                         a = attr_find( e->e_attrs, slap_schema.si_ad_modifyTimestamp );
550                         if ( a == NULL ) {
551                                 vals[0] = timestamp;
552                                 attr_merge( e, slap_schema.si_ad_modifyTimestamp, vals, NULL );
553
554                         } else {
555                                 ber_bvreplace( &a->a_vals[0], &timestamp );
556                         }
557                 }
558
559                 if ( mod_err ) break;
560
561                 /* check schema, objectClass etc */
562
563                 if ( !dryrun ) {
564                         switch ( lr.lr_op ) {
565                         case LDAP_REQ_ADD:
566                                 id = be->be_entry_put( be, e, &bvtext );
567                                 rc = (id == NOID);
568                                 break;
569
570                         case LDAP_REQ_MODIFY:
571                                 id = be->be_entry_modify( be, e, &bvtext );
572                                 rc = (id == NOID);
573                                 break;
574
575                         case LDAP_REQ_DELETE:
576                                 rc = be->be_entry_delete( be, id, &bvtext );
577                                 break;
578
579                         }
580
581                         if( rc != LDAP_SUCCESS ) {
582                                 fprintf( stderr, "%s: could not %s entry dn=\"%s\" "
583                                         "(line=%lu): %s\n", progname, request, e->e_dn,
584                                         lineno, bvtext.bv_val );
585                                 rc = EXIT_FAILURE;
586                                 entry_free( e );
587                                 if( continuemode ) continue;
588                                 break;
589                         }
590
591                         sid = slap_tool_update_ctxcsn_check( progname, e );
592
593                         if ( verbose )
594                                 fprintf( stderr, "%s: \"%s\" (%08lx)\n",
595                                         request, e->e_dn, (long) id );
596                 } else {
597                         if ( verbose )
598                                 fprintf( stderr, "%s: \"%s\"\n",
599                                         request, e->e_dn );
600                 }
601
602                 entry_free( e );
603         }
604
605 done:;
606         if ( ldifrc < 0 )
607                 rc = EXIT_FAILURE;
608
609         bvtext.bv_len = textlen;
610         bvtext.bv_val = textbuf;
611         bvtext.bv_val[0] = '\0';
612
613         if ( enable_meter ) {
614                 lutil_meter_update( &meter, ftell( ldiffp->fp ), 1);
615                 lutil_meter_close( &meter );
616         }
617
618         if ( rc == EXIT_SUCCESS ) {
619                 rc = slap_tool_update_ctxcsn( progname, sid, &bvtext );
620         }
621
622         ch_free( buf );
623
624         if ( !dryrun ) {
625                 if ( enable_meter ) {
626                         fprintf( stderr, "Closing DB..." );
627                 }
628                 if( be->be_entry_close( be ) ) {
629                         rc = EXIT_FAILURE;
630                 }
631
632                 if( be->be_sync ) {
633                         be->be_sync( be );
634                 }
635                 if ( enable_meter ) {
636                         fprintf( stderr, "\n" );
637                 }
638         }
639
640         if ( slap_tool_destroy())
641                 rc = EXIT_FAILURE;
642
643         return rc;
644 }
645