]> git.sur5r.net Git - openldap/blobdiff - libraries/libldap/schema.c
Braced ldap_connect_to_path() in #ifdef LDAP_PF_LOCAL so as to compile
[openldap] / libraries / libldap / schema.c
index 251d0cc6c83f0e4391529c407d377ebf6c560f89..78fbe8a3fa25079f7ee5a5e89017a1076b53a066 100644 (file)
@@ -1,7 +1,9 @@
+/* $OpenLDAP$ */
 /*
  * Copyright 1999 The OpenLDAP Foundation, All Rights Reserved.
  * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
- *
+ */
+/*
  * schema.c:  parsing routines used by servers and clients to process
  *     schema definitions
  */
 
 #include <ldap_schema.h>
 
+
+static LDAP_CONST char *
+choose_name( char *names[], LDAP_CONST char *fallback )
+{
+       return( (names != NULL && names[0] != NULL) ? names[0] : fallback );
+}
+
+LDAP_CONST char *
+ldap_syntax2name( LDAP_SYNTAX * syn )
+{
+       return( syn->syn_oid );
+}
+
+LDAP_CONST char *
+ldap_matchingrule2name( LDAP_MATCHING_RULE * mr )
+{
+       return( choose_name( mr->mr_names, mr->mr_oid ) );
+}
+
+LDAP_CONST char *
+ldap_attributetype2name( LDAP_ATTRIBUTE_TYPE * at )
+{
+       return( choose_name( at->at_names, at->at_oid ) );
+}
+
+LDAP_CONST char *
+ldap_objectclass2name( LDAP_OBJECT_CLASS * oc )
+{
+       return( choose_name( oc->oc_names, oc->oc_oid ) );
+}
+
+
 /*
  * When pretty printing the entities we will be appending to a buffer.
  * Since checking for overflow, realloc'ing and checking if no error
@@ -29,8 +63,8 @@
 
 typedef struct safe_string {
        char * val;
-       int size;
-       int pos;
+       ber_len_t size;
+       ber_len_t pos;
        int at_whsp;
 } safe_string;
 
@@ -126,6 +160,8 @@ print_numericoid(safe_string *ss, char *s)
 {
        if ( s )
                return(append_to_safe_string(ss,s));
+       else
+               return(append_to_safe_string(ss,""));
 }
 
 /* This one is identical to print_qdescr */
@@ -261,6 +297,52 @@ ldap_syntax2str( const LDAP_SYNTAX * syn )
        return(retstring);
 }
 
+char *
+ldap_matchingrule2str( const LDAP_MATCHING_RULE * mr )
+{
+       safe_string * ss;
+       char * retstring;
+       
+       ss = new_safe_string(256);
+       if ( !ss )
+               return NULL;
+
+       print_literal(ss,"(");
+       print_whsp(ss);
+
+       print_numericoid(ss, mr->mr_oid);
+       print_whsp(ss);
+
+       if ( mr->mr_names ) {
+               print_literal(ss,"NAME");
+               print_qdescrs(ss,mr->mr_names);
+       }
+
+       if ( mr->mr_desc ) {
+               print_literal(ss,"DESC");
+               print_qdstring(ss,mr->mr_desc);
+       }
+
+       if ( mr->mr_obsolete == LDAP_SCHEMA_YES ) {
+               print_literal(ss, "OBSOLETE");
+               print_whsp(ss);
+       }
+
+       if ( mr->mr_syntax_oid ) {
+               print_literal(ss,"SYNTAX");
+               print_whsp(ss);
+               print_literal(ss, mr->mr_syntax_oid);
+               print_whsp(ss);
+       }
+
+       print_whsp(ss);
+       print_literal(ss,")");
+
+       retstring = LDAP_STRDUP(safe_string_val(ss));
+       safe_string_free(ss);
+       return(retstring);
+}
+
 char *
 ldap_objectclass2str( const LDAP_OBJECT_CLASS * oc )
 {
@@ -483,6 +565,7 @@ get_token(const char ** sp, char ** token_val)
        const char * q;
        char * res;
 
+       *token_val = NULL;
        switch (**sp) {
        case '\0':
                kind = TK_EOS;
@@ -524,7 +607,12 @@ get_token(const char ** sp, char ** token_val)
        default:
                kind = TK_BAREWORD;
                p = *sp;
-               while ( !isspace(**sp) && **sp != '\0' )
+               while ( !isspace(**sp) &&
+                       **sp != '(' &&
+                       **sp != ')' &&
+                       **sp != '$' &&
+                       **sp != '\'' &&
+                       **sp != '\0' )
                        (*sp)++;
                q = *sp;
                res = LDAP_MALLOC(q-p+1);
@@ -561,12 +649,19 @@ parse_whsp(const char **sp)
 
 /* Parse a sequence of dot-separated decimal strings */
 static char *
-parse_numericoid(const char **sp, int *code)
+parse_numericoid(const char **sp, int *code, const int allow_quoted)
 {
        char * res;
        const char * start = *sp;
        int len;
+       int quoted = 0;
 
+       /* Netscape puts the SYNTAX value in quotes (incorrectly) */
+       if ( allow_quoted && **sp == '\'' ) {
+               quoted = 1;
+               (*sp)++;
+               start++;
+       }
        /* Each iteration of this loop gets one decimal string */
        while (**sp) {
                if ( !isdigit(**sp) ) {
@@ -594,6 +689,15 @@ parse_numericoid(const char **sp, int *code)
        }
        strncpy(res,start,len);
        res[len] = '\0';
+       if ( allow_quoted && quoted ) {
+               if ( **sp == '\'' ) {
+                       (*sp)++;
+               } else {
+                       *code = LDAP_SCHERR_UNEXPTOKEN;
+                       LDAP_FREE(res);
+                       return NULL;
+               }
+       }
        return(res);
 }
 
@@ -630,6 +734,7 @@ parse_qdescrs(const char **sp, int *code)
                                        res1 = LDAP_REALLOC(res,size*sizeof(char *));
                                        if ( !res1 ) {
                                                LDAP_VFREE(res);
+                                               LDAP_FREE(sval);
                                                *code = LDAP_SCHERR_OUTOFMEM;
                                                return(NULL);
                                        }
@@ -640,6 +745,7 @@ parse_qdescrs(const char **sp, int *code)
                                parse_whsp(sp);
                        } else {
                                LDAP_VFREE(res);
+                               LDAP_FREE(sval);
                                *code = LDAP_SCHERR_UNEXPTOKEN;
                                return(NULL);
                        }
@@ -658,6 +764,7 @@ parse_qdescrs(const char **sp, int *code)
                parse_whsp(sp);
                return res;
        } else {
+               LDAP_FREE(sval);
                *code = LDAP_SCHERR_BADNAME;
                return NULL;
        }
@@ -673,6 +780,7 @@ parse_woid(const char **sp, int *code)
        parse_whsp(sp);
        kind = get_token(sp, &sval);
        if ( kind != TK_BAREWORD ) {
+               LDAP_FREE(sval);
                *code = LDAP_SCHERR_UNEXPTOKEN;
                return NULL;
        }
@@ -682,19 +790,18 @@ parse_woid(const char **sp, int *code)
 
 /* Parse a noidlen */
 static char *
-parse_noidlen(const char **sp, int *code, int *len, int be_liberal)
+parse_noidlen(const char **sp, int *code, int *len, int allow_quoted)
 {
        char * sval;
-       int kind;
        int quoted = 0;
 
        *len = 0;
        /* Netscape puts the SYNTAX value in quotes (incorrectly) */
-       if ( be_liberal && **sp == '\'' ) {
+       if ( allow_quoted && **sp == '\'' ) {
                quoted = 1;
                (*sp)++;
        }
-       sval = parse_numericoid(sp, code);
+       sval = parse_numericoid(sp, code, 0);
        if ( !sval ) {
                return NULL;
        }
@@ -710,7 +817,7 @@ parse_noidlen(const char **sp, int *code, int *len, int be_liberal)
                }
                (*sp)++;
        }               
-       if ( be_liberal && quoted ) {
+       if ( allow_quoted && quoted ) {
                if ( **sp == '\'' ) {
                        (*sp)++;
                } else {
@@ -724,14 +831,14 @@ parse_noidlen(const char **sp, int *code, int *len, int be_liberal)
 
 /*
  * Next routine will accept a qdstring in place of an oid if
- * be_liberal is set.  This is necessary to interoperate with Netscape
- * Directory server that will improperly quote each oid (at least
- * those of the descr kind) in the SUP clause.
+ * allow_quoted is set.  This is necessary to interoperate with
+ * Netscape Directory server that will improperly quote each oid (at
+ * least those of the descr kind) in the SUP clause.
  */
 
 /* Parse a woid or a $-separated list of them enclosed in () */
 static char **
-parse_oids(const char **sp, int *code, const int be_liberal)
+parse_oids(const char **sp, int *code, const int allow_quoted)
 {
        char ** res;
        char ** res1;
@@ -760,11 +867,12 @@ parse_oids(const char **sp, int *code, const int be_liberal)
                parse_whsp(sp);
                kind = get_token(sp,&sval);
                if ( kind == TK_BAREWORD ||
-                    ( be_liberal && kind == TK_QDSTRING ) ) {
+                    ( allow_quoted && kind == TK_QDSTRING ) ) {
                        res[pos] = sval;
                        pos++;
                } else {
                        *code = LDAP_SCHERR_UNEXPTOKEN;
+                       LDAP_FREE(sval);
                        LDAP_VFREE(res);
                        return NULL;
                }
@@ -777,14 +885,16 @@ parse_oids(const char **sp, int *code, const int be_liberal)
                                parse_whsp(sp);
                                kind = get_token(sp,&sval);
                                if ( kind == TK_BAREWORD ||
-                                    ( be_liberal && kind == TK_QDSTRING ) ) {
+                                    ( allow_quoted &&
+                                      kind == TK_QDSTRING ) ) {
                                        if ( pos == size-2 ) {
                                                size++;
                                                res1 = LDAP_REALLOC(res,size*sizeof(char *));
                                                if ( !res1 ) {
-                                                 LDAP_VFREE(res);
-                                                 *code = LDAP_SCHERR_OUTOFMEM;
-                                                 return(NULL);
+                                                       LDAP_FREE(sval);
+                                                       LDAP_VFREE(res);
+                                                       *code = LDAP_SCHERR_OUTOFMEM;
+                                                       return(NULL);
                                                }
                                                res = res1;
                                        }
@@ -792,12 +902,14 @@ parse_oids(const char **sp, int *code, const int be_liberal)
                                        pos++;
                                } else {
                                        *code = LDAP_SCHERR_UNEXPTOKEN;
+                                       LDAP_FREE(sval);
                                        LDAP_VFREE(res);
                                        return NULL;
                                }
                                parse_whsp(sp);
                        } else {
                                *code = LDAP_SCHERR_UNEXPTOKEN;
+                               LDAP_FREE(sval);
                                LDAP_VFREE(res);
                                return NULL;
                        }
@@ -806,9 +918,10 @@ parse_oids(const char **sp, int *code, const int be_liberal)
                parse_whsp(sp);
                return(res);
        } else if ( kind == TK_BAREWORD ||
-                   ( be_liberal && kind == TK_QDSTRING ) ) {
+                   ( allow_quoted && kind == TK_QDSTRING ) ) {
                res = LDAP_CALLOC(2,sizeof(char *));
                if ( !res ) {
+                       LDAP_FREE(sval);
                        *code = LDAP_SCHERR_OUTOFMEM;
                        return NULL;
                }
@@ -817,6 +930,7 @@ parse_oids(const char **sp, int *code, const int be_liberal)
                parse_whsp(sp);
                return res;
        } else {
+               LDAP_FREE(sval);
                *code = LDAP_SCHERR_BADNAME;
                return NULL;
        }
@@ -856,13 +970,14 @@ ldap_str2syntax( const char * s, int * code, const char ** errp )
 
        kind = get_token(&ss,&sval);
        if ( kind != TK_LEFTPAREN ) {
+               LDAP_FREE(sval);
                *code = LDAP_SCHERR_NOLEFTPAREN;
                ldap_syntax_free(syn);
                return NULL;
        }
 
        parse_whsp(&ss);
-       syn->syn_oid = parse_numericoid(&ss,code);
+       syn->syn_oid = parse_numericoid(&ss,code,0);
        if ( !syn->syn_oid ) {
                *errp = ss;
                ldap_syntax_free(syn);
@@ -886,6 +1001,7 @@ ldap_str2syntax( const char * s, int * code, const char ** errp )
                        return syn;
                case TK_BAREWORD:
                        if ( !strcmp(sval,"DESC") ) {
+                               LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -898,12 +1014,14 @@ ldap_str2syntax( const char * s, int * code, const char ** errp )
                                if ( kind != TK_QDSTRING ) {
                                        *code = LDAP_SCHERR_UNEXPTOKEN;
                                        *errp = ss;
+                                       LDAP_FREE(sval);
                                        ldap_syntax_free(syn);
                                        return NULL;
                                }
                                syn->syn_desc = sval;
                                parse_whsp(&ss);
                        } else if ( sval[0] == 'X' && sval[1] == '-' ) {
+                               LDAP_FREE(sval);
                                /* Should be parse_qdstrings */
                                ssdummy = parse_qdescrs(&ss, code);
                                if ( !ssdummy ) {
@@ -914,6 +1032,7 @@ ldap_str2syntax( const char * s, int * code, const char ** errp )
                        } else {
                                *code = LDAP_SCHERR_UNEXPTOKEN;
                                *errp = ss;
+                               LDAP_FREE(sval);
                                ldap_syntax_free(syn);
                                return NULL;
                        }
@@ -921,12 +1040,197 @@ ldap_str2syntax( const char * s, int * code, const char ** errp )
                default:
                        *code = LDAP_SCHERR_UNEXPTOKEN;
                        *errp = ss;
+                       LDAP_FREE(sval);
                        ldap_syntax_free(syn);
                        return NULL;
                }
        }
 }
 
+void
+ldap_matchingrule_free( LDAP_MATCHING_RULE * mr )
+{
+       LDAP_FREE(mr->mr_oid);
+       LDAP_VFREE(mr->mr_names);
+       LDAP_FREE(mr->mr_desc);
+       LDAP_FREE(mr->mr_syntax_oid);
+       LDAP_FREE(mr);
+}
+
+LDAP_MATCHING_RULE *
+ldap_str2matchingrule( const char * s, int * code, const char ** errp )
+{
+       int kind;
+       const char * ss = s;
+       char * sval;
+       int be_liberal = 1;     /* Future additional argument */
+       int seen_name = 0;
+       int seen_desc = 0;
+       int seen_obsolete = 0;
+       int seen_syntax = 0;
+       LDAP_MATCHING_RULE * mr;
+       char ** ssdummy;
+       const char * savepos;
+
+       if ( !s ) {
+               *code = LDAP_SCHERR_EMPTY;
+               *errp = "";
+               return NULL;
+       }
+
+       *errp = s;
+       mr = LDAP_CALLOC(1,sizeof(LDAP_MATCHING_RULE));
+
+       if ( !mr ) {
+               *code = LDAP_SCHERR_OUTOFMEM;
+               return NULL;
+       }
+
+       kind = get_token(&ss,&sval);
+       if ( kind != TK_LEFTPAREN ) {
+               *code = LDAP_SCHERR_NOLEFTPAREN;
+               LDAP_FREE(sval);
+               ldap_matchingrule_free(mr);
+               return NULL;
+       }
+
+       parse_whsp(&ss);
+       savepos = ss;
+       mr->mr_oid = parse_numericoid(&ss,code,be_liberal);
+       if ( !mr->mr_oid ) {
+               if ( be_liberal ) {
+                       /* Backtracking */
+                       ss = savepos;
+                       kind = get_token(&ss,&sval);
+                       if ( kind == TK_BAREWORD ) {
+                               if ( !strcmp(sval, "NAME") ||
+                                    !strcmp(sval, "DESC") ||
+                                    !strcmp(sval, "OBSOLETE") ||
+                                    !strcmp(sval, "SYNTAX") ||
+                                    !strncmp(sval, "X-", 2) ) {
+                                       /* Missing OID, backtrack */
+                                       ss = savepos;
+                               } else {
+                                       /* Non-numerical OID, ignore */
+                               }
+                       }
+                       LDAP_FREE(sval);
+               } else {
+                       *errp = ss;
+                       ldap_matchingrule_free(mr);
+                       return NULL;
+               }
+       }
+       parse_whsp(&ss);
+
+       /*
+        * Beyond this point we will be liberal and accept the items
+        * in any order.
+        */
+       while (1) {
+               kind = get_token(&ss,&sval);
+               switch (kind) {
+               case TK_EOS:
+                       *code = LDAP_SCHERR_NORIGHTPAREN;
+                       *errp = ss;
+                       ldap_matchingrule_free(mr);
+                       return NULL;
+               case TK_RIGHTPAREN:
+                       return mr;
+               case TK_BAREWORD:
+                       if ( !strcmp(sval,"NAME") ) {
+                               LDAP_FREE(sval);
+                               if ( seen_name ) {
+                                       *code = LDAP_SCHERR_DUPOPT;
+                                       *errp = ss;
+                                       ldap_matchingrule_free(mr);
+                                       return(NULL);
+                               }
+                               seen_name = 1;
+                               mr->mr_names = parse_qdescrs(&ss,code);
+                               if ( !mr->mr_names ) {
+                                       if ( *code != LDAP_SCHERR_OUTOFMEM )
+                                               *code = LDAP_SCHERR_BADNAME;
+                                       *errp = ss;
+                                       ldap_matchingrule_free(mr);
+                                       return NULL;
+                               }
+                       } else if ( !strcmp(sval,"DESC") ) {
+                               LDAP_FREE(sval);
+                               if ( seen_desc ) {
+                                       *code = LDAP_SCHERR_DUPOPT;
+                                       *errp = ss;
+                                       ldap_matchingrule_free(mr);
+                                       return(NULL);
+                               }
+                               seen_desc = 1;
+                               parse_whsp(&ss);
+                               kind = get_token(&ss,&sval);
+                               if ( kind != TK_QDSTRING ) {
+                                       *code = LDAP_SCHERR_UNEXPTOKEN;
+                                       *errp = ss;
+                                       LDAP_FREE(sval);
+                                       ldap_matchingrule_free(mr);
+                                       return NULL;
+                               }
+                               mr->mr_desc = sval;
+                               parse_whsp(&ss);
+                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                               LDAP_FREE(sval);
+                               if ( seen_obsolete ) {
+                                       *code = LDAP_SCHERR_DUPOPT;
+                                       *errp = ss;
+                                       ldap_matchingrule_free(mr);
+                                       return(NULL);
+                               }
+                               seen_obsolete = 1;
+                               mr->mr_obsolete = LDAP_SCHEMA_YES;
+                               parse_whsp(&ss);
+                       } else if ( !strcmp(sval,"SYNTAX") ) {
+                               LDAP_FREE(sval);
+                               if ( seen_syntax ) {
+                                       *code = LDAP_SCHERR_DUPOPT;
+                                       *errp = ss;
+                                       ldap_matchingrule_free(mr);
+                                       return(NULL);
+                               }
+                               seen_syntax = 1;
+                               parse_whsp(&ss);
+                               mr->mr_syntax_oid =
+                                       parse_numericoid(&ss,code,be_liberal);
+                               if ( !mr->mr_syntax_oid ) {
+                                       *errp = ss;
+                                       ldap_matchingrule_free(mr);
+                                       return NULL;
+                               }
+                               parse_whsp(&ss);
+                       } else if ( sval[0] == 'X' && sval[1] == '-' ) {
+                               LDAP_FREE(sval);
+                               /* Should be parse_qdstrings */
+                               ssdummy = parse_qdescrs(&ss, code);
+                               if ( !ssdummy ) {
+                                       *errp = ss;
+                                       ldap_matchingrule_free(mr);
+                                       return NULL;
+                               }
+                       } else {
+                               *code = LDAP_SCHERR_UNEXPTOKEN;
+                               *errp = ss;
+                               LDAP_FREE(sval);
+                               ldap_matchingrule_free(mr);
+                               return NULL;
+                       }
+                       break;
+               default:
+                       *code = LDAP_SCHERR_UNEXPTOKEN;
+                       *errp = ss;
+                       LDAP_FREE(sval);
+                       ldap_matchingrule_free(mr);
+                       return NULL;
+               }
+       }
+}
+
 void
 ldap_attributetype_free(LDAP_ATTRIBUTE_TYPE * at)
 {
@@ -957,9 +1261,6 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
        int seen_substr = 0;
        int seen_syntax = 0;
        int seen_usage = 0;
-       int seen_kind = 0;
-       int seen_must = 0;
-       int seen_may = 0;
        LDAP_ATTRIBUTE_TYPE * at;
        char ** ssdummy;
        const char * savepos;
@@ -981,6 +1282,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
        kind = get_token(&ss,&sval);
        if ( kind != TK_LEFTPAREN ) {
                *code = LDAP_SCHERR_NOLEFTPAREN;
+               LDAP_FREE(sval);
                ldap_attributetype_free(at);
                return NULL;
        }
@@ -994,7 +1296,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
         */
        parse_whsp(&ss);
        savepos = ss;
-       at->at_oid = parse_numericoid(&ss,code);
+       at->at_oid = parse_numericoid(&ss,code,0);
        if ( !at->at_oid ) {
                if ( be_liberal ) {
                        /* Backtracking */
@@ -1019,7 +1321,8 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                } else {
                                        /* Non-numerical OID, ignore */
                                }
-                         }
+                       }
+                       LDAP_FREE(sval);
                } else {
                        *errp = ss;
                        ldap_attributetype_free(at);
@@ -1044,6 +1347,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                        return at;
                case TK_BAREWORD:
                        if ( !strcmp(sval,"NAME") ) {
+                               LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1060,6 +1364,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                        return NULL;
                                }
                        } else if ( !strcmp(sval,"DESC") ) {
+                               LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1072,12 +1377,14 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                if ( kind != TK_QDSTRING ) {
                                        *code = LDAP_SCHERR_UNEXPTOKEN;
                                        *errp = ss;
+                                       LDAP_FREE(sval);
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
                                at->at_desc = sval;
                                parse_whsp(&ss);
                        } else if ( !strcmp(sval,"OBSOLETE") ) {
+                               LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1088,6 +1395,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                at->at_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
                        } else if ( !strcmp(sval,"SUP") ) {
+                               LDAP_FREE(sval);
                                if ( seen_sup ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1102,6 +1410,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                        return NULL;
                                }
                        } else if ( !strcmp(sval,"EQUALITY") ) {
+                               LDAP_FREE(sval);
                                if ( seen_equality ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1116,6 +1425,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                        return NULL;
                                }
                        } else if ( !strcmp(sval,"ORDERING") ) {
+                               LDAP_FREE(sval);
                                if ( seen_ordering ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1130,6 +1440,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                        return NULL;
                                }
                        } else if ( !strcmp(sval,"SUBSTR") ) {
+                               LDAP_FREE(sval);
                                if ( seen_substr ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1144,6 +1455,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                        return NULL;
                                }
                        } else if ( !strcmp(sval,"SYNTAX") ) {
+                               LDAP_FREE(sval);
                                if ( seen_syntax ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1152,7 +1464,11 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                }
                                seen_syntax = 1;
                                parse_whsp(&ss);
-                               at->at_syntax_oid = parse_noidlen(&ss,code,&at->at_syntax_len,be_liberal);
+                               at->at_syntax_oid =
+                                       parse_noidlen(&ss,
+                                                     code,
+                                                     &at->at_syntax_len,
+                                                     be_liberal);
                                if ( !at->at_syntax_oid ) {
                                        *errp = ss;
                                        ldap_attributetype_free(at);
@@ -1160,6 +1476,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                }
                                parse_whsp(&ss);
                        } else if ( !strcmp(sval,"SINGLE-VALUE") ) {
+                               LDAP_FREE(sval);
                                if ( at->at_single_value ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1169,6 +1486,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                at->at_single_value = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
                        } else if ( !strcmp(sval,"COLLECTIVE") ) {
+                               LDAP_FREE(sval);
                                if ( at->at_collective ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1178,6 +1496,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                at->at_collective = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
                        } else if ( !strcmp(sval,"NO-USER-MODIFICATION") ) {
+                               LDAP_FREE(sval);
                                if ( at->at_no_user_mod ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1187,6 +1506,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                at->at_no_user_mod = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
                        } else if ( !strcmp(sval,"USAGE") ) {
+                               LDAP_FREE(sval);
                                if ( seen_usage ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1199,6 +1519,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                if ( kind != TK_BAREWORD ) {
                                        *code = LDAP_SCHERR_UNEXPTOKEN;
                                        *errp = ss;
+                                       LDAP_FREE(sval);
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
@@ -1217,11 +1538,14 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                                else {
                                        *code = LDAP_SCHERR_UNEXPTOKEN;
                                        *errp = ss;
+                                       LDAP_FREE(sval);
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
+                               LDAP_FREE(sval);
                                parse_whsp(&ss);
                        } else if ( sval[0] == 'X' && sval[1] == '-' ) {
+                               LDAP_FREE(sval);
                                /* Should be parse_qdstrings */
                                ssdummy = parse_qdescrs(&ss, code);
                                if ( !ssdummy ) {
@@ -1232,6 +1556,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                        } else {
                                *code = LDAP_SCHERR_UNEXPTOKEN;
                                *errp = ss;
+                               LDAP_FREE(sval);
                                ldap_attributetype_free(at);
                                return NULL;
                        }
@@ -1239,6 +1564,7 @@ ldap_str2attributetype( const char * s, int * code, const char ** errp )
                default:
                        *code = LDAP_SCHERR_UNEXPTOKEN;
                        *errp = ss;
+                       LDAP_FREE(sval);
                        ldap_attributetype_free(at);
                        return NULL;
                }
@@ -1292,6 +1618,7 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
        kind = get_token(&ss,&sval);
        if ( kind != TK_LEFTPAREN ) {
                *code = LDAP_SCHERR_NOLEFTPAREN;
+               LDAP_FREE(sval);
                ldap_objectclass_free(oc);
                return NULL;
        }
@@ -1305,7 +1632,7 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
         */
        parse_whsp(&ss);
        savepos = ss;
-       oc->oc_oid = parse_numericoid(&ss,code);
+       oc->oc_oid = parse_numericoid(&ss,code,0);
        if ( !oc->oc_oid ) {
                if ( be_liberal ) {
                        /* Backtracking */
@@ -1326,7 +1653,8 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
                                } else {
                                        /* Non-numerical OID, ignore */
                                }
-                         }
+                       }
+                       LDAP_FREE(sval);
                } else {
                        *errp = ss;
                        ldap_objectclass_free(oc);
@@ -1351,6 +1679,7 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
                        return oc;
                case TK_BAREWORD:
                        if ( !strcmp(sval,"NAME") ) {
+                               LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1367,6 +1696,7 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
                                        return NULL;
                                }
                        } else if ( !strcmp(sval,"DESC") ) {
+                               LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1379,12 +1709,14 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
                                if ( kind != TK_QDSTRING ) {
                                        *code = LDAP_SCHERR_UNEXPTOKEN;
                                        *errp = ss;
+                                       LDAP_FREE(sval);
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
                                oc->oc_desc = sval;
                                parse_whsp(&ss);
                        } else if ( !strcmp(sval,"OBSOLETE") ) {
+                               LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1395,6 +1727,7 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
                                oc->oc_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
                        } else if ( !strcmp(sval,"SUP") ) {
+                               LDAP_FREE(sval);
                                if ( seen_sup ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1402,13 +1735,16 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
                                        return(NULL);
                                }
                                seen_sup = 1;
-                               oc->oc_sup_oids = parse_oids(&ss,code,be_liberal);
+                               oc->oc_sup_oids = parse_oids(&ss,
+                                                            code,
+                                                            be_liberal);
                                if ( !oc->oc_sup_oids ) {
                                        *errp = ss;
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
                        } else if ( !strcmp(sval,"ABSTRACT") ) {
+                               LDAP_FREE(sval);
                                if ( seen_kind ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1419,6 +1755,7 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
                                oc->oc_kind = LDAP_SCHEMA_ABSTRACT;
                                parse_whsp(&ss);
                        } else if ( !strcmp(sval,"STRUCTURAL") ) {
+                               LDAP_FREE(sval);
                                if ( seen_kind ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1429,6 +1766,7 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
                                oc->oc_kind = LDAP_SCHEMA_STRUCTURAL;
                                parse_whsp(&ss);
                        } else if ( !strcmp(sval,"AUXILIARY") ) {
+                               LDAP_FREE(sval);
                                if ( seen_kind ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1439,6 +1777,7 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
                                oc->oc_kind = LDAP_SCHEMA_AUXILIARY;
                                parse_whsp(&ss);
                        } else if ( !strcmp(sval,"MUST") ) {
+                               LDAP_FREE(sval);
                                if ( seen_must ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1454,6 +1793,7 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
                                }
                                parse_whsp(&ss);
                        } else if ( !strcmp(sval,"MAY") ) {
+                               LDAP_FREE(sval);
                                if ( seen_may ) {
                                        *code = LDAP_SCHERR_DUPOPT;
                                        *errp = ss;
@@ -1469,6 +1809,7 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
                                }
                                parse_whsp(&ss);
                        } else if ( sval[0] == 'X' && sval[1] == '-' ) {
+                               LDAP_FREE(sval);
                                /* Should be parse_qdstrings */
                                ssdummy = parse_qdescrs(&ss, code);
                                if ( !ssdummy ) {
@@ -1479,6 +1820,7 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
                        } else {
                                *code = LDAP_SCHERR_UNEXPTOKEN;
                                *errp = ss;
+                               LDAP_FREE(sval);
                                ldap_objectclass_free(oc);
                                return NULL;
                        }
@@ -1486,13 +1828,14 @@ ldap_str2objectclass( const char * s, int * code, const char ** errp )
                default:
                        *code = LDAP_SCHERR_UNEXPTOKEN;
                        *errp = ss;
+                       LDAP_FREE(sval);
                        ldap_objectclass_free(oc);
                        return NULL;
                }
        }
 }
 
-static char *err2text[] = {
+static char *const err2text[] = {
        "",
        "Out of memory",
        "Unexpected token",