]> git.sur5r.net Git - openldap/blobdiff - libraries/libldap/options.c
further clarify size limit related issues in sync replication (ITS#5243)
[openldap] / libraries / libldap / options.c
index 5c5580cb272944d119aa5a9734afc668b10d693b..69f730211ea00726abc32f2fa0fe6e7d65de40f1 100644 (file)
@@ -1,22 +1,89 @@
+/* $OpenLDAP$ */
+/* This work is part of OpenLDAP Software <http://www.openldap.org/>.
+ *
+ * Copyright 1998-2007 The OpenLDAP Foundation.
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted only as authorized by the OpenLDAP
+ * Public License.
+ *
+ * A copy of this license is available in the file LICENSE in the
+ * top-level directory of the distribution or, alternatively, at
+ * <http://www.OpenLDAP.org/license.html>.
+ */
+
 #include "portable.h"
 
 #include <stdio.h>
-#include <stdlib.h>
+
+#include <ac/stdlib.h>
 
 #include <ac/socket.h>
 #include <ac/string.h>
-extern char *strdup (const char *);
+#include <ac/time.h>
 
 #include "ldap-int.h"
 
-static const char* features[] = {
-#ifdef LDAP_API_FEATURE_X_OPENLDAP_V2_DNS
-       "X_OPENLDAP_V2_DNS",
+#define LDAP_OPT_REBIND_PROC 0x4e814d
+#define LDAP_OPT_REBIND_PARAMS 0x4e814e
+
+#define LDAP_OPT_NEXTREF_PROC 0x4e815d
+#define LDAP_OPT_NEXTREF_PARAMS 0x4e815e
+
+static const LDAPAPIFeatureInfo features[] = {
+#ifdef LDAP_API_FEATURE_X_OPENLDAP
+       {       /* OpenLDAP Extensions API Feature */
+               LDAP_FEATURE_INFO_VERSION,
+               "X_OPENLDAP",
+               LDAP_API_FEATURE_X_OPENLDAP
+       },
+#endif
+
+#ifdef LDAP_API_FEATURE_THREAD_SAFE
+       {       /* Basic Thread Safe */
+               LDAP_FEATURE_INFO_VERSION,
+               "THREAD_SAFE",
+               LDAP_API_FEATURE_THREAD_SAFE
+       },
+#endif
+#ifdef LDAP_API_FEATURE_SESSION_THREAD_SAFE
+       {       /* Session Thread Safe */
+               LDAP_FEATURE_INFO_VERSION,
+               "SESSION_THREAD_SAFE",
+               LDAP_API_FEATURE_SESSION_THREAD_SAFE
+       },
+#endif
+#ifdef LDAP_API_FEATURE_OPERATION_THREAD_SAFE
+       {       /* Operation Thread Safe */
+               LDAP_FEATURE_INFO_VERSION,
+               "OPERATION_THREAD_SAFE",
+               LDAP_API_FEATURE_OPERATION_THREAD_SAFE
+       },
+#endif
+#ifdef LDAP_API_FEATURE_X_OPENLDAP_REENTRANT
+       {       /* OpenLDAP Reentrant */
+               LDAP_FEATURE_INFO_VERSION,
+               "X_OPENLDAP_REENTRANT",
+               LDAP_API_FEATURE_X_OPENLDAP_REENTRANT
+       },
+#endif
+#if defined( LDAP_API_FEATURE_X_OPENLDAP_THREAD_SAFE ) && \
+       defined( LDAP_THREAD_SAFE )
+       {       /* OpenLDAP Thread Safe */
+               LDAP_FEATURE_INFO_VERSION,
+               "X_OPENLDAP_THREAD_SAFE",
+               LDAP_API_FEATURE_X_OPENLDAP_THREAD_SAFE
+       },
 #endif
 #ifdef LDAP_API_FEATURE_X_OPENLDAP_V2_REFERRALS
-       "X_OPENLDAP_V2_REFERRALS",
+       {       /* V2 Referrals */
+               LDAP_FEATURE_INFO_VERSION,
+               "X_OPENLDAP_V2_REFERRALS",
+               LDAP_API_FEATURE_X_OPENLDAP_V2_REFERRALS
+       },
 #endif
-       NULL
+       {0, NULL, 0}
 };
 
 int
@@ -27,113 +94,141 @@ ldap_get_option(
 {
        struct ldapoptions *lo;
 
-       if(!openldap_ldap_initialized) {
-               openldap_ldap_initialize();
+       /* Get pointer to global option structure */
+       lo = LDAP_INT_GLOBAL_OPT();   
+       if (NULL == lo) {
+               return LDAP_NO_MEMORY;
        }
 
-       if(outvalue == NULL) {
-               /* no place to get to */
-               return -1;
+       if( lo->ldo_valid != LDAP_INITIALIZED ) {
+               ldap_int_initialize(lo, NULL);
        }
 
-       if(ld == NULL) {
-               lo = &openldap_ldap_global_options;
-       } else {
+       if(ld != NULL) {
+               assert( LDAP_VALID( ld ) );
+
+               if( !LDAP_VALID( ld ) ) {
+                       return LDAP_OPT_ERROR;
+               }
+
                lo = &ld->ld_options;
        }
 
+       if(outvalue == NULL) {
+               /* no place to get to */
+               return LDAP_OPT_ERROR;
+       }
+
        switch(option) {
        case LDAP_OPT_API_INFO: {
                        struct ldapapiinfo *info = (struct ldapapiinfo *) outvalue;
 
                        if(info == NULL) {
                                /* outvalue must point to an apiinfo structure */
-                               return -1;
+                               return LDAP_OPT_ERROR;
                        }
 
                        if(info->ldapai_info_version != LDAP_API_INFO_VERSION) {
                                /* api info version mismatch */
                                info->ldapai_info_version = LDAP_API_INFO_VERSION;
-                               return -1;
+                               return LDAP_OPT_ERROR;
                        }
 
-                       info->ldapai_api_version = LDAP_API_VERSION;
                        info->ldapai_api_version = LDAP_API_VERSION;
                        info->ldapai_protocol_version = LDAP_VERSION_MAX;
-                       if(features[0] == NULL) {
+
+                       if(features[0].ldapaif_name == NULL) {
                                info->ldapai_extensions = NULL;
                        } else {
                                int i;
-                               info->ldapai_extensions = malloc(sizeof(features));
+                               info->ldapai_extensions = LDAP_MALLOC(sizeof(char *) *
+                                       sizeof(features)/sizeof(LDAPAPIFeatureInfo));
 
-                               for(i=0; features[i] != NULL; i++) {
-                                       info->ldapai_extensions[i] = strdup(features[i]);
+                               for(i=0; features[i].ldapaif_name != NULL; i++) {
+                                       info->ldapai_extensions[i] =
+                                               LDAP_STRDUP(features[i].ldapaif_name);
                                }
 
                                info->ldapai_extensions[i] = NULL;
                        }
 
-                       info->ldapai_vendor_name = strdup(LDAP_VENDOR_NAME);
+                       info->ldapai_vendor_name = LDAP_STRDUP(LDAP_VENDOR_NAME);
                        info->ldapai_vendor_version = LDAP_VENDOR_VERSION;
 
-                       return 0;
+                       return LDAP_OPT_SUCCESS;
                } break;
 
        case LDAP_OPT_DESC:
-               if(ld == NULL) {
+               if( ld == NULL || ld->ld_sb == NULL ) {
                        /* bad param */
                        break;
                } 
 
-               * (int *) outvalue = ld->ld_sb.sb_sd;
-               return 0;
+               ber_sockbuf_ctrl( ld->ld_sb, LBER_SB_OPT_GET_FD, outvalue );
+               return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_SOCKBUF:
+               if( ld == NULL ) break;
+               *(Sockbuf **)outvalue = ld->ld_sb;
+               return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_TIMEOUT:
+               /* the caller has to free outvalue ! */
+               if ( ldap_int_timeval_dup( outvalue, lo->ldo_tm_api) != 0 ) {
+                       return LDAP_OPT_ERROR;
+               }
+               return LDAP_OPT_SUCCESS;
+               
+       case LDAP_OPT_NETWORK_TIMEOUT:
+               /* the caller has to free outvalue ! */
+               if ( ldap_int_timeval_dup( outvalue, lo->ldo_tm_net ) != 0 ) {
+                       return LDAP_OPT_ERROR;
+               }
+               return LDAP_OPT_SUCCESS;
 
        case LDAP_OPT_DEREF:
                * (int *) outvalue = lo->ldo_deref;
-               return 0;
+               return LDAP_OPT_SUCCESS;
 
        case LDAP_OPT_SIZELIMIT:
                * (int *) outvalue = lo->ldo_sizelimit;
-               return 0;
+               return LDAP_OPT_SUCCESS;
 
        case LDAP_OPT_TIMELIMIT:
                * (int *) outvalue = lo->ldo_timelimit;
-               return 0;
+               return LDAP_OPT_SUCCESS;
 
        case LDAP_OPT_REFERRALS:
                * (int *) outvalue = (int) LDAP_BOOL_GET(lo, LDAP_BOOL_REFERRALS);
-               return 0;
+               return LDAP_OPT_SUCCESS;
                
        case LDAP_OPT_RESTART:
                * (int *) outvalue = (int) LDAP_BOOL_GET(lo, LDAP_BOOL_RESTART);
-               return 0;
-
-       case LDAP_OPT_DNS:      /* LDAPv2 */
-               * (int *) outvalue = (int) LDAP_BOOL_GET(lo, LDAP_BOOL_DNS);
-               return 0;
+               return LDAP_OPT_SUCCESS;
 
        case LDAP_OPT_PROTOCOL_VERSION:
-               if ((ld != NULL) && ld->ld_version) {
-                       * (int *) outvalue = ld->ld_version;
-               } else { 
-                       * (int *) outvalue = lo->ldo_version;
-               }
-               return 0;
+               * (int *) outvalue = lo->ldo_version;
+               return LDAP_OPT_SUCCESS;
 
        case LDAP_OPT_SERVER_CONTROLS:
+               * (LDAPControl ***) outvalue =
+                       ldap_controls_dup( lo->ldo_sctrls );
+
+               return LDAP_OPT_SUCCESS;
+
        case LDAP_OPT_CLIENT_CONTROLS:
-               /* not yet supported */
-               break;
+               * (LDAPControl ***) outvalue =
+                       ldap_controls_dup( lo->ldo_cctrls );
+
+               return LDAP_OPT_SUCCESS;
 
        case LDAP_OPT_HOST_NAME:
-               /*
-                * draft-ietf-ldapext-ldap-c-api-01 doesn't state
-                * whether client to have to free host names or no,
-                * we do
-                */
+               * (char **) outvalue = ldap_url_list2hosts(lo->ldo_defludp);
+               return LDAP_OPT_SUCCESS;
 
-               * (char **) outvalue = strdup(lo->ldo_defhost);
-               return 0;
+       case LDAP_OPT_URI:
+               * (char **) outvalue = ldap_url_list2urls(lo->ldo_defludp);
+               return LDAP_OPT_SUCCESS;
 
        case LDAP_OPT_ERROR_NUMBER:
                if(ld == NULL) {
@@ -141,144 +236,365 @@ ldap_get_option(
                        break;
                } 
                * (int *) outvalue = ld->ld_errno;
-               return 0;
+               return LDAP_OPT_SUCCESS;
 
        case LDAP_OPT_ERROR_STRING:
-               /* not yet supported */
                if(ld == NULL) {
                        /* bad param */
                        break;
                } 
 
-               /*
-                * draft-ietf-ldapext-ldap-c-api-01 doesn't require
-                *      the client to have to free error strings, we do
-                */
-
                if( ld->ld_error == NULL ) {
                        * (char **) outvalue = NULL;
                } else {
-                       * (char **) outvalue = strdup(ld->ld_error);
+                       * (char **) outvalue = LDAP_STRDUP(ld->ld_error);
+               }
+
+               return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_MATCHED_DN:
+               if(ld == NULL) {
+                       /* bad param */
+                       break;
+               } 
+
+               if( ld->ld_matched == NULL ) {
+                       * (char **) outvalue = NULL;
+               } else {
+                       * (char **) outvalue = LDAP_STRDUP( ld->ld_matched );
+               }
+
+               return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_REFERRAL_URLS:
+               if(ld == NULL) {
+                       /* bad param */
+                       break;
+               } 
+
+               if( ld->ld_referrals == NULL ) {
+                       * (char ***) outvalue = NULL;
+               } else {
+                       * (char ***) outvalue = ldap_value_dup(ld->ld_referrals);
+               }
+
+               return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_API_FEATURE_INFO: {
+                       LDAPAPIFeatureInfo *info = (LDAPAPIFeatureInfo *) outvalue;
+                       int i;
+
+                       if(info == NULL) return LDAP_OPT_ERROR;
+
+                       if(info->ldapaif_info_version != LDAP_FEATURE_INFO_VERSION) {
+                               /* api info version mismatch */
+                               info->ldapaif_info_version = LDAP_FEATURE_INFO_VERSION;
+                               return LDAP_OPT_ERROR;
+                       }
+
+                       if(info->ldapaif_name == NULL) return LDAP_OPT_ERROR;
+
+                       for(i=0; features[i].ldapaif_name != NULL; i++) {
+                               if(!strcmp(info->ldapaif_name, features[i].ldapaif_name)) {
+                                       info->ldapaif_version =
+                                               features[i].ldapaif_version;
+                                       return LDAP_OPT_SUCCESS;
+                               }
+                       }
                }
                break;
 
+       case LDAP_OPT_DEBUG_LEVEL:
+               * (int *) outvalue = lo->ldo_debug;
+               return LDAP_OPT_SUCCESS;
+
        default:
+#ifdef HAVE_TLS
+               if ( ldap_pvt_tls_get_option( ld, option, outvalue ) == 0 ) {
+                       return LDAP_OPT_SUCCESS;
+               }
+#endif
+#ifdef HAVE_CYRUS_SASL
+               if ( ldap_int_sasl_get_option( ld, option, outvalue ) == 0 ) {
+                       return LDAP_OPT_SUCCESS;
+               }
+#endif
                /* bad param */
                break;
        }
 
-       return -1;
+       return LDAP_OPT_ERROR;
 }
 
 int
 ldap_set_option(
        LDAP    *ld,
        int             option,
-       void    *invalue)
+       LDAP_CONST void *invalue)
 {
        struct ldapoptions *lo;
+       int *dbglvl = NULL;
 
-       if(!openldap_ldap_initialized) {
-               openldap_ldap_initialize();
+       /* Get pointer to global option structure */
+       lo = LDAP_INT_GLOBAL_OPT();
+       if (lo == NULL) {
+               return LDAP_NO_MEMORY;
        }
 
-       if(invalue == NULL) {
-               /* no place to set from */
-               return -1;
-       }
+       /*
+        * The architecture to turn on debugging has a chicken and egg
+        * problem. Thus, we introduce a fix here.
+        */
 
-       if(ld == NULL) {
-               lo = &openldap_ldap_global_options;
-       } else {
-               lo = &ld->ld_options;
+       if (option == LDAP_OPT_DEBUG_LEVEL) {
+               dbglvl = (int *) invalue;
        }
 
-       switch(option) {
-       case LDAP_OPT_API_INFO:
-       case LDAP_OPT_DESC:
-               /* READ ONLY */
-               break;
+       if( lo->ldo_valid != LDAP_INITIALIZED ) {
+               ldap_int_initialize(lo, dbglvl);
+       }
 
-       case LDAP_OPT_DEREF:
-               lo->ldo_deref = * (int *) invalue;
-               return 0;
+       if(ld != NULL) {
+               assert( LDAP_VALID( ld ) );
 
-       case LDAP_OPT_SIZELIMIT:
-               lo->ldo_sizelimit = * (int *) invalue;
-               return 0;
+               if( !LDAP_VALID( ld ) ) {
+                       return LDAP_OPT_ERROR;
+               }
 
-       case LDAP_OPT_TIMELIMIT:
-               lo->ldo_timelimit = * (int *) invalue;
-               return 0;
+               lo = &ld->ld_options;
+       }
 
+       switch(option) {
        case LDAP_OPT_REFERRALS:
-               if((int) invalue == (int) LDAP_OPT_ON) {
-                       LDAP_BOOL_SET(lo, LDAP_BOOL_REFERRALS);
-               } else {
+               if(invalue == LDAP_OPT_OFF) {
                        LDAP_BOOL_CLR(lo, LDAP_BOOL_REFERRALS);
+               } else {
+                       LDAP_BOOL_SET(lo, LDAP_BOOL_REFERRALS);
                }
-               return 0;
+               return LDAP_OPT_SUCCESS;
 
        case LDAP_OPT_RESTART:
-               if((int) invalue == (int) LDAP_OPT_ON) {
-                       LDAP_BOOL_SET(lo, LDAP_BOOL_RESTART);
-               } else {
+               if(invalue == LDAP_OPT_OFF) {
                        LDAP_BOOL_CLR(lo, LDAP_BOOL_RESTART);
+               } else {
+                       LDAP_BOOL_SET(lo, LDAP_BOOL_RESTART);
                }
-               return 0;
+               return LDAP_OPT_SUCCESS;
+       }
 
-       case LDAP_OPT_PROTOCOL_VERSION: {
-                       int vers = * (int *) invalue;
-                       if (vers < LDAP_VERSION_MIN || vers > LDAP_VERSION_MAX) {
-                               /* not supported */
+       /* options which can withstand invalue == NULL */
+       switch ( option ) {
+       case LDAP_OPT_SERVER_CONTROLS: {
+                       LDAPControl *const *controls =
+                               (LDAPControl *const *) invalue;
+
+                       if( lo->ldo_sctrls )
+                               ldap_controls_free( lo->ldo_sctrls );
+
+                       if( controls == NULL || *controls == NULL ) {
+                               lo->ldo_sctrls = NULL;
+                               return LDAP_OPT_SUCCESS;
+                       }
+                               
+                       lo->ldo_sctrls = ldap_controls_dup( controls );
+
+                       if(lo->ldo_sctrls == NULL) {
+                               /* memory allocation error ? */
                                break;
                        }
-                       ld->ld_version = vers;
-               } return 0;
+               } return LDAP_OPT_SUCCESS;
 
-       case LDAP_OPT_SERVER_CONTROLS:
-       case LDAP_OPT_CLIENT_CONTROLS:
-               /* not yet supported */
-               break;
+       case LDAP_OPT_CLIENT_CONTROLS: {
+                       LDAPControl *const *controls =
+                               (LDAPControl *const *) invalue;
 
-       case LDAP_OPT_HOST_NAME: {
-                       char* host = * (char **) invalue;
+                       if( lo->ldo_cctrls )
+                               ldap_controls_free( lo->ldo_cctrls );
+
+                       if( controls == NULL || *controls == NULL ) {
+                               lo->ldo_cctrls = NULL;
+                               return LDAP_OPT_SUCCESS;
+                       }
+                               
+                       lo->ldo_cctrls = ldap_controls_dup( controls );
+
+                       if(lo->ldo_cctrls == NULL) {
+                               /* memory allocation error ? */
+                               break;
+                       }
+               } return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_TIMEOUT: {
+                       const struct timeval *tv = 
+                               (const struct timeval *) invalue;
+
+                       if ( lo->ldo_tm_api != NULL ) {
+                               LDAP_FREE( lo->ldo_tm_api );
+                               lo->ldo_tm_api = NULL;
+                       }
+
+                       if ( ldap_int_timeval_dup( &lo->ldo_tm_api, tv ) != 0 ) {
+                               return LDAP_OPT_ERROR;
+                       }
+               } return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_NETWORK_TIMEOUT: {
+                       const struct timeval *tv = 
+                               (const struct timeval *) invalue;
+
+                       if ( lo->ldo_tm_net != NULL ) {
+                               LDAP_FREE( lo->ldo_tm_net );
+                               lo->ldo_tm_net = NULL;
+                       }
 
-                       if(lo->ldo_defhost != NULL) {
-                               free(lo->ldo_defhost);
-                               lo->ldo_defhost = NULL;
+                       if ( ldap_int_timeval_dup( &lo->ldo_tm_net, tv ) != 0 ) {
+                               return LDAP_OPT_ERROR;
                        }
+               } return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_HOST_NAME: {
+                       const char *host = (const char *) invalue;
+                       LDAPURLDesc *ludlist = NULL;
+                       int rc = LDAP_OPT_SUCCESS;
 
                        if(host != NULL) {
-                               lo->ldo_defhost = strdup(host);
-                               return 0;
+                               rc = ldap_url_parsehosts( &ludlist, host,
+                                       lo->ldo_defport ? lo->ldo_defport : LDAP_PORT );
+
+                       } else if(ld == NULL) {
+                               /*
+                                * must want global default returned
+                                * to initial condition.
+                                */
+                               rc = ldap_url_parselist(&ludlist, "ldap://localhost/");
+
+                       } else {
+                               /*
+                                * must want the session default
+                                *   updated to the current global default
+                                */
+                               ludlist = ldap_url_duplist(
+                                       ldap_int_global_options.ldo_defludp);
+                               if (ludlist == NULL)
+                                       rc = LDAP_NO_MEMORY;
                        }
 
-                       if(ld == NULL) {
+                       if (rc == LDAP_OPT_SUCCESS) {
+                               if (lo->ldo_defludp != NULL)
+                                       ldap_free_urllist(lo->ldo_defludp);
+                               lo->ldo_defludp = ludlist;
+                       }
+                       return rc;
+               }
+
+       case LDAP_OPT_URI: {
+                       const char *urls = (const char *) invalue;
+                       LDAPURLDesc *ludlist = NULL;
+                       int rc = LDAP_OPT_SUCCESS;
+
+                       if(urls != NULL) {
+                               rc = ldap_url_parselist(&ludlist, urls);
+                       } else if(ld == NULL) {
                                /*
                                 * must want global default returned
                                 * to initial condition.
                                 */
-                               lo->ldo_defhost = strdup("localhost");
+                               rc = ldap_url_parselist(&ludlist, "ldap://localhost/");
 
                        } else {
                                /*
                                 * must want the session default
                                 *   updated to the current global default
                                 */
-                               lo->ldo_defhost = strdup(
-                                       openldap_ldap_global_options.ldo_defhost);
+                               ludlist = ldap_url_duplist(
+                                       ldap_int_global_options.ldo_defludp);
+                               if (ludlist == NULL)
+                                       rc = LDAP_NO_MEMORY;
                        }
-               } return 0;
 
-       case LDAP_OPT_ERROR_NUMBER: {
-                       int err = * (int *) invalue;
+                       switch (rc) {
+                       case LDAP_URL_SUCCESS:          /* Success */
+                               rc = LDAP_SUCCESS;
+                               break;
+
+                       case LDAP_URL_ERR_MEM:          /* can't allocate memory space */
+                               rc = LDAP_NO_MEMORY;
+                               break;
+
+                       case LDAP_URL_ERR_PARAM:        /* parameter is bad */
+                       case LDAP_URL_ERR_BADSCHEME:    /* URL doesn't begin with "ldap[si]://" */
+                       case LDAP_URL_ERR_BADENCLOSURE: /* URL is missing trailing ">" */
+                       case LDAP_URL_ERR_BADURL:       /* URL is bad */
+                       case LDAP_URL_ERR_BADHOST:      /* host port is bad */
+                       case LDAP_URL_ERR_BADATTRS:     /* bad (or missing) attributes */
+                       case LDAP_URL_ERR_BADSCOPE:     /* scope string is invalid (or missing) */
+                       case LDAP_URL_ERR_BADFILTER:    /* bad or missing filter */
+                       case LDAP_URL_ERR_BADEXTS:      /* bad or missing extensions */
+                               rc = LDAP_PARAM_ERROR;
+                               break;
+                       }
+
+                       if (rc == LDAP_OPT_SUCCESS) {
+                               if (lo->ldo_defludp != NULL)
+                                       ldap_free_urllist(lo->ldo_defludp);
+                               lo->ldo_defludp = ludlist;
+                       }
+                       return rc;
+               }
+
+       /* Only accessed from inside this function by ldap_set_rebind_proc() */
+       case LDAP_OPT_REBIND_PROC: {
+                       lo->ldo_rebind_proc = (LDAP_REBIND_PROC *)invalue;              
+               } return LDAP_OPT_SUCCESS;
+       case LDAP_OPT_REBIND_PARAMS: {
+                       lo->ldo_rebind_params = (void *)invalue;                
+               } return LDAP_OPT_SUCCESS;
+
+       /* Only accessed from inside this function by ldap_set_nextref_proc() */
+       case LDAP_OPT_NEXTREF_PROC: {
+                       lo->ldo_nextref_proc = (LDAP_NEXTREF_PROC *)invalue;            
+               } return LDAP_OPT_SUCCESS;
+       case LDAP_OPT_NEXTREF_PARAMS: {
+                       lo->ldo_nextref_params = (void *)invalue;               
+               } return LDAP_OPT_SUCCESS;
+       }
+
+       if(invalue == NULL) {
+               /* no place to set from */
+               return LDAP_OPT_ERROR;
+       }
 
-                       if (err != 0 ) {
+       /* options which cannot withstand invalue == NULL */
+
+       switch(option) {
+       case LDAP_OPT_API_INFO:
+       case LDAP_OPT_DESC:
+               /* READ ONLY */
+               break;
+
+       case LDAP_OPT_DEREF:
+               lo->ldo_deref = * (const int *) invalue;
+               return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_SIZELIMIT:
+               lo->ldo_sizelimit = * (const int *) invalue;
+               return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_TIMELIMIT:
+               lo->ldo_timelimit = * (const int *) invalue;
+               return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_PROTOCOL_VERSION: {
+                       int vers = * (const int *) invalue;
+                       if (vers < LDAP_VERSION_MIN || vers > LDAP_VERSION_MAX) {
                                /* not supported */
-                               /* we only allow ld_errno to be cleared. */
                                break;
                        }
+                       lo->ldo_version = vers;
+               } return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_ERROR_NUMBER: {
+                       int err = * (const int *) invalue;
 
                        if(ld == NULL) {
                                /* need a struct ldap */
@@ -286,28 +602,100 @@ ldap_set_option(
                        }
 
                        ld->ld_errno = err;
-               } return 0;
+               } return LDAP_OPT_SUCCESS;
 
        case LDAP_OPT_ERROR_STRING: {
-                       char* err = * (char **) invalue;
+                       const char *err = (const char *) invalue;
 
-                       if (err != NULL ) {
-                               /* not supported */
-                               /* we only allow ld_error to be cleared. */
+                       if(ld == NULL) {
+                               /* need a struct ldap */
+                               break;
+                       }
+
+                       if( ld->ld_error ) {
+                               LDAP_FREE(ld->ld_error);
+                               ld->ld_error = NULL;
+                       }
+
+                       if ( err ) {
+                               ld->ld_error = LDAP_STRDUP(err);
+                       }
+               } return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_MATCHED_DN: {
+                       const char *matched = (const char *) invalue;
+
+                       if (ld == NULL) {
+                               /* need a struct ldap */
                                break;
                        }
 
+                       if( ld->ld_matched ) {
+                               LDAP_FREE(ld->ld_matched);
+                               ld->ld_matched = NULL;
+                       }
+
+                       if ( matched ) {
+                               ld->ld_matched = LDAP_STRDUP( matched );
+                       }
+               } return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_REFERRAL_URLS: {
+                       char *const *referrals = (char *const *) invalue;
+                       
                        if(ld == NULL) {
                                /* need a struct ldap */
                                break;
                        }
 
-                       ld->ld_error = err;
-               } return 0;
+                       if( ld->ld_referrals ) {
+                               LDAP_VFREE(ld->ld_referrals);
+                       }
+
+                       ld->ld_referrals = ldap_value_dup(referrals);
+               } return LDAP_OPT_SUCCESS;
+
+       case LDAP_OPT_API_FEATURE_INFO:
+               /* read-only */
+               break;
+
+       case LDAP_OPT_DEBUG_LEVEL:
+               lo->ldo_debug = * (const int *) invalue;
+               return LDAP_OPT_SUCCESS;
 
        default:
+#ifdef HAVE_TLS
+               if ( ldap_pvt_tls_set_option( ld, option, (void *)invalue ) == 0 )
+                       return LDAP_OPT_SUCCESS;
+#endif
+#ifdef HAVE_CYRUS_SASL
+               if ( ldap_int_sasl_set_option( ld, option, (void *)invalue ) == 0 )
+                       return LDAP_OPT_SUCCESS;
+#endif
                /* bad param */
                break;
        }
-       return -1;
+       return LDAP_OPT_ERROR;
+}
+
+int
+ldap_set_rebind_proc( LDAP *ld, LDAP_REBIND_PROC *proc, void *params )
+{
+       int rc;
+       rc = ldap_set_option( ld, LDAP_OPT_REBIND_PROC, (void *)proc );
+       if( rc != LDAP_OPT_SUCCESS ) return rc;
+
+       rc = ldap_set_option( ld, LDAP_OPT_REBIND_PARAMS, (void *)params );
+       return rc;
+}
+
+int
+ldap_set_nextref_proc( LDAP *ld, LDAP_NEXTREF_PROC *proc, void *params )
+{
+       int rc;
+       rc = ldap_set_option( ld, LDAP_OPT_NEXTREF_PROC, (void *)proc );
+       if( rc != LDAP_OPT_SUCCESS ) return rc;
+
+       rc = ldap_set_option( ld, LDAP_OPT_NEXTREF_PARAMS, (void *)params );
+       return rc;
 }