]> git.sur5r.net Git - openldap/blobdiff - libraries/libldap/cyrus.c
Rework Modify statslog too
[openldap] / libraries / libldap / cyrus.c
index 28c241b0bf47b508ed34b82a9f958467cb1967d0..f073c7735f9fdcb9ae57c578ba3f62161a70cebf 100644 (file)
@@ -1,7 +1,7 @@
 /* $OpenLDAP$ */
 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
  *
- * Copyright 1998-2013 The OpenLDAP Foundation.
+ * Copyright 1998-2015 The OpenLDAP Foundation.
  * All rights reserved.
  *
  * Redistribution and use in source and binary forms, with or without
@@ -369,6 +369,10 @@ int ldap_int_sasl_close( LDAP *ld, LDAPConn *lc )
                lc->lconn_sasl_sockctx = NULL;
                lc->lconn_sasl_authctx = NULL;
        }
+       if( lc->lconn_sasl_cbind ) {
+               ldap_memfree( lc->lconn_sasl_cbind );
+               lc->lconn_sasl_cbind = NULL;
+       }
 
        return LDAP_SUCCESS;
 }
@@ -482,6 +486,25 @@ ldap_int_sasl_bind(
 
                        (void) ldap_int_sasl_external( ld, ld->ld_defconn, authid.bv_val, fac );
                        LDAP_FREE( authid.bv_val );
+#ifdef SASL_CHANNEL_BINDING    /* 2.1.25+ */
+                       {
+                               char cbinding[64];
+                               struct berval cbv = { sizeof(cbinding), cbinding };
+                               if ( ldap_pvt_tls_get_unique( ssl, &cbv, 0 )) {
+                                       sasl_channel_binding_t *cb = ldap_memalloc( sizeof(*cb) +
+                                               cbv.bv_len);
+                                       void *cb_data; /* used since cb->data is const* */
+                                       cb->name = "ldap";
+                                       cb->critical = 0;
+                                       cb->len = cbv.bv_len;
+                                       cb->data = cb_data = cb+1;
+                                       memcpy( cb_data, cbv.bv_val, cbv.bv_len );
+                                       sasl_setprop( ld->ld_defconn->lconn_sasl_authctx,
+                                               SASL_CHANNEL_BINDING, cb );
+                                       ld->ld_defconn->lconn_sasl_cbind = cb;
+                               }
+                       }
+#endif
                }
 #endif
 
@@ -545,8 +568,11 @@ ldap_int_sasl_bind(
                ctx = ld->ld_defconn->lconn_sasl_authctx;
 
                rc = ldap_parse_sasl_bind_result( ld, result, &scred, 0 );
-               if ( rc != LDAP_SUCCESS )
+               if ( rc != LDAP_SUCCESS ) {
+                       if ( scred )
+                               ber_bvfree( scred );
                        goto done;
+               }
 
                rc = ldap_result2error( ld, result, 0 );
                if ( rc != LDAP_SUCCESS && rc != LDAP_SASL_BIND_IN_PROGRESS ) {
@@ -562,8 +588,11 @@ ldap_int_sasl_bind(
                }
 
                mech = *rmech;
-               if ( rc == LDAP_SUCCESS && mech == NULL )
+               if ( rc == LDAP_SUCCESS && mech == NULL ) {
+                       if ( scred )
+                               ber_bvfree( scred );
                        goto success;
+               }
 
                do {
                        if( ! scred ) {
@@ -1143,6 +1172,7 @@ void *ldap_pvt_sasl_mutex_new(void)
        if ( ldap_pvt_thread_mutex_init( mutex ) == 0 ) {
                return mutex;
        }
+       LDAP_FREE( mutex );
 #ifndef LDAP_DEBUG_R_SASL
        assert( 0 );
 #endif /* !LDAP_DEBUG_R_SASL */