]> git.sur5r.net Git - openldap/blobdiff - libraries/libldap/schema.c
ldap_control*_dup() is no longer private; add ldap_pvt_put_control
[openldap] / libraries / libldap / schema.c
index 66c228eb0245b2d1578281333b61c1f797be42b8..86f26e638828c28f3ecc4980e37e3796454960c7 100644 (file)
@@ -1,7 +1,7 @@
 /* $OpenLDAP$ */
 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
  *
- * Copyright 1998-2003 The OpenLDAP Foundation.
+ * Copyright 1998-2007 The OpenLDAP Foundation.
  * All rights reserved.
  *
  * Redistribution and use in source and binary forms, with or without
@@ -959,26 +959,23 @@ ldap_attributetype2bv(  LDAPAttributeType * at, struct berval *bv )
  * interpretation of the specs).
  */
 
-#define TK_NOENDQUOTE  -2
-#define TK_OUTOFMEM    -1
-#define TK_EOS         0
-#define TK_UNEXPCHAR   1
-#define TK_BAREWORD    2
-#define TK_QDSTRING    3
-#define TK_LEFTPAREN   4
-#define TK_RIGHTPAREN  5
-#define TK_DOLLAR      6
-#define TK_QDESCR      TK_QDSTRING
-
-struct token {
-       int type;
-       char *sval;
-};
-
-static int
+typedef enum tk_t {
+       TK_NOENDQUOTE   = -2,
+       TK_OUTOFMEM     = -1,
+       TK_EOS          = 0,
+       TK_UNEXPCHAR    = 1,
+       TK_BAREWORD     = 2,
+       TK_QDSTRING     = 3,
+       TK_LEFTPAREN    = 4,
+       TK_RIGHTPAREN   = 5,
+       TK_DOLLAR       = 6,
+       TK_QDESCR       = TK_QDSTRING
+} tk_t;
+
+static tk_t
 get_token( const char ** sp, char ** token_val )
 {
-       int kind;
+       tk_t kind;
        const char * p;
        const char * q;
        char * res;
@@ -1030,6 +1027,9 @@ get_token( const char ** sp, char ** token_val )
                        **sp != ')' &&
                        **sp != '$' &&
                        **sp != '\'' &&
+                       /* for suggested minimum upper bound on the number
+                        * of characters (RFC 4517) */
+                       **sp != '{' &&
                        **sp != '\0' )
                        (*sp)++;
                q = *sp;
@@ -1150,7 +1150,7 @@ parse_qdescrs(const char **sp, int *code)
 {
        char ** res;
        char ** res1;
-       int kind;
+       tk_t kind;
        char * sval;
        int size;
        int pos;
@@ -1183,8 +1183,8 @@ parse_qdescrs(const char **sp, int *code)
                                        }
                                        res = res1;
                                }
-                               res[pos] = sval;
-                               pos++;
+                               res[pos++] = sval;
+                               res[pos] = NULL;
                                parse_whsp(sp);
                        } else {
                                LDAP_VFREE(res);
@@ -1193,7 +1193,6 @@ parse_qdescrs(const char **sp, int *code)
                                return(NULL);
                        }
                }
-               res[pos] = NULL;
                parse_whsp(sp);
                return(res);
        } else if ( kind == TK_QDESCR ) {
@@ -1218,7 +1217,7 @@ static char *
 parse_woid(const char **sp, int *code)
 {
        char * sval;
-       int kind;
+       tk_t kind;
 
        parse_whsp(sp);
        kind = get_token(sp, &sval);
@@ -1233,10 +1232,13 @@ parse_woid(const char **sp, int *code)
 
 /* Parse a noidlen */
 static char *
-parse_noidlen(const char **sp, int *code, int *len, int allow_quoted)
+parse_noidlen(const char **sp, int *code, int *len, int flags)
 {
        char * sval;
+       const char *savepos;
        int quoted = 0;
+       int allow_quoted = ( flags & LDAP_SCHEMA_ALLOW_QUOTED );
+       int allow_oidmacro = ( flags & LDAP_SCHEMA_ALLOW_OID_MACRO );
 
        *len = 0;
        /* Netscape puts the SYNTAX value in quotes (incorrectly) */
@@ -1244,9 +1246,22 @@ parse_noidlen(const char **sp, int *code, int *len, int allow_quoted)
                quoted = 1;
                (*sp)++;
        }
+       savepos = *sp;
        sval = ldap_int_parse_numericoid(sp, code, 0);
        if ( !sval ) {
-               return NULL;
+               if ( allow_oidmacro
+                       && *sp == savepos
+                       && *code == LDAP_SCHERR_NODIGIT )
+               {
+                       if ( get_token(sp, &sval) != TK_BAREWORD ) {
+                               if ( sval != NULL ) {
+                                       LDAP_FREE(sval);
+                               }
+                               return NULL;
+                       }
+               } else {
+                       return NULL;
+               }
        }
        if ( **sp == '{' /*}*/ ) {
                (*sp)++;
@@ -1285,7 +1300,7 @@ parse_oids(const char **sp, int *code, const int allow_quoted)
 {
        char ** res;
        char ** res1;
-       int kind;
+       tk_t kind;
        char * sval;
        int size;
        int pos;
@@ -1311,8 +1326,13 @@ parse_oids(const char **sp, int *code, const int allow_quoted)
                kind = get_token(sp,&sval);
                if ( kind == TK_BAREWORD ||
                     ( allow_quoted && kind == TK_QDSTRING ) ) {
-                       res[pos] = sval;
-                       pos++;
+                       res[pos++] = sval;
+                       res[pos] = NULL;
+               } else if ( kind == TK_RIGHTPAREN ) {
+                       /* FIXME: be liberal in what we accept... */
+                       parse_whsp(sp);
+                       LDAP_FREE(res);
+                       return NULL;
                } else {
                        *code = LDAP_SCHERR_UNEXPTOKEN;
                        LDAP_FREE(sval);
@@ -1341,8 +1361,8 @@ parse_oids(const char **sp, int *code, const int allow_quoted)
                                                }
                                                res = res1;
                                        }
-                                       res[pos] = sval;
-                                       pos++;
+                                       res[pos++] = sval;
+                                       res[pos] = NULL;
                                } else {
                                        *code = LDAP_SCHERR_UNEXPTOKEN;
                                        LDAP_FREE(sval);
@@ -1357,7 +1377,6 @@ parse_oids(const char **sp, int *code, const int allow_quoted)
                                return NULL;
                        }
                }
-               res[pos] = NULL;
                parse_whsp(sp);
                return(res);
        } else if ( kind == TK_BAREWORD ||
@@ -1395,16 +1414,20 @@ add_extension(LDAPSchemaExtensionItem ***extensions,
        if ( !*extensions ) {
                *extensions =
                  LDAP_CALLOC(2, sizeof(LDAPSchemaExtensionItem *));
-               if ( !*extensions )
-                 return 1;
+               if ( !*extensions ) {
+                       LDAP_FREE( ext );
+                       return 1;
+               }
                n = 0;
        } else {
                for ( n=0; (*extensions)[n] != NULL; n++ )
                        ;
                tmp = LDAP_REALLOC(*extensions,
                                   (n+2)*sizeof(LDAPSchemaExtensionItem *));
-               if ( !tmp )
+               if ( !tmp ) {
+                       LDAP_FREE( ext );
                        return 1;
+               }
                *extensions = tmp;
        }
        (*extensions)[n] = ext;
@@ -1443,7 +1466,7 @@ ldap_str2syntax( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -1497,7 +1520,7 @@ ldap_str2syntax( LDAP_CONST char * s,
                case TK_RIGHTPAREN:
                        return syn;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1514,7 +1537,7 @@ ldap_str2syntax( LDAP_CONST char * s,
                                        ldap_syntax_free(syn);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1585,7 +1608,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -1627,11 +1650,11 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                        ss = savepos;
                        kind = get_token(&ss,&sval);
                        if ( kind == TK_BAREWORD ) {
-                               if ( !strcmp(sval, "NAME") ||
-                                    !strcmp(sval, "DESC") ||
-                                    !strcmp(sval, "OBSOLETE") ||
-                                    !strcmp(sval, "SYNTAX") ||
-                                    !strncmp(sval, "X-", 2) ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "SYNTAX") ||
+                                    !strncasecmp(sval, "X-", 2) ) {
                                        /* Missing OID, backtrack */
                                        ss = savepos;
                                } else {
@@ -1667,7 +1690,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                        }
                        return mr;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1684,7 +1707,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                                        ldap_matchingrule_free(mr);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1704,7 +1727,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                                }
                                mr->mr_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1715,7 +1738,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                mr->mr_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"SYNTAX") ) {
+                       } else if ( !strcasecmp(sval,"SYNTAX") ) {
                                LDAP_FREE(sval);
                                if ( seen_syntax ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1784,7 +1807,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -1826,11 +1849,11 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                        ss = savepos;
                        kind = get_token(&ss,&sval);
                        if ( kind == TK_BAREWORD ) {
-                               if ( !strcmp(sval, "NAME") ||
-                                    !strcmp(sval, "DESC") ||
-                                    !strcmp(sval, "OBSOLETE") ||
-                                    !strcmp(sval, "APPLIES") ||
-                                    !strncmp(sval, "X-", 2) ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "APPLIES") ||
+                                    !strncasecmp(sval, "X-", 2) ) {
                                        /* Missing OID, backtrack */
                                        ss = savepos;
                                } else {
@@ -1866,7 +1889,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                        }
                        return mru;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1883,7 +1906,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                                        ldap_matchingruleuse_free(mru);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1903,7 +1926,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                                }
                                mru->mru_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1914,7 +1937,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                mru->mru_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"APPLIES") ) {
+                       } else if ( !strcasecmp(sval,"APPLIES") ) {
                                LDAP_FREE(sval);
                                if ( seen_applies ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1926,7 +1949,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                                mru->mru_applies_oids = parse_oids(&ss,
                                                             code,
                                                             flags);
-                               if ( !mru->mru_applies_oids ) {
+                               if ( !mru->mru_applies_oids && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_matchingruleuse_free(mru);
                                        return NULL;
@@ -1986,7 +2009,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -2037,28 +2060,31 @@ ldap_str2attributetype( LDAP_CONST char * s,
        if ( !at->at_oid ) {
                if ( ( flags & ( LDAP_SCHEMA_ALLOW_NO_OID
                                | LDAP_SCHEMA_ALLOW_OID_MACRO ) )
-                           && (ss == savepos) ) {
+                           && (ss == savepos) )
+               {
                        /* Backtracking */
                        ss = savepos;
                        kind = get_token(&ss,&sval);
                        if ( kind == TK_BAREWORD ) {
-                               if ( !strcmp(sval, "NAME") ||
-                                    !strcmp(sval, "DESC") ||
-                                    !strcmp(sval, "OBSOLETE") ||
-                                    !strcmp(sval, "SUP") ||
-                                    !strcmp(sval, "EQUALITY") ||
-                                    !strcmp(sval, "ORDERING") ||
-                                    !strcmp(sval, "SUBSTR") ||
-                                    !strcmp(sval, "SYNTAX") ||
-                                    !strcmp(sval, "SINGLE-VALUE") ||
-                                    !strcmp(sval, "COLLECTIVE") ||
-                                    !strcmp(sval, "NO-USER-MODIFICATION") ||
-                                    !strcmp(sval, "USAGE") ||
-                                    !strncmp(sval, "X-", 2) ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "SUP") ||
+                                    !strcasecmp(sval, "EQUALITY") ||
+                                    !strcasecmp(sval, "ORDERING") ||
+                                    !strcasecmp(sval, "SUBSTR") ||
+                                    !strcasecmp(sval, "SYNTAX") ||
+                                    !strcasecmp(sval, "SINGLE-VALUE") ||
+                                    !strcasecmp(sval, "COLLECTIVE") ||
+                                    !strcasecmp(sval, "NO-USER-MODIFICATION") ||
+                                    !strcasecmp(sval, "USAGE") ||
+                                    !strncasecmp(sval, "X-", 2) )
+                               {
                                        /* Missing OID, backtrack */
                                        ss = savepos;
                                } else if ( flags
-                                       & LDAP_SCHEMA_ALLOW_OID_MACRO) {
+                                       & LDAP_SCHEMA_ALLOW_OID_MACRO)
+                               {
                                        /* Non-numerical OID ... */
                                        int len = ss-savepos;
                                        at->at_oid = LDAP_MALLOC(len+1);
@@ -2090,7 +2116,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                case TK_RIGHTPAREN:
                        return at;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2107,7 +2133,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2127,7 +2153,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                }
                                at->at_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2138,7 +2164,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                at->at_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"SUP") ) {
+                       } else if ( !strcasecmp(sval,"SUP") ) {
                                LDAP_FREE(sval);
                                if ( seen_sup ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2153,7 +2179,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"EQUALITY") ) {
+                       } else if ( !strcasecmp(sval,"EQUALITY") ) {
                                LDAP_FREE(sval);
                                if ( seen_equality ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2168,7 +2194,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"ORDERING") ) {
+                       } else if ( !strcasecmp(sval,"ORDERING") ) {
                                LDAP_FREE(sval);
                                if ( seen_ordering ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2183,7 +2209,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"SUBSTR") ) {
+                       } else if ( !strcasecmp(sval,"SUBSTR") ) {
                                LDAP_FREE(sval);
                                if ( seen_substr ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2198,7 +2224,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"SYNTAX") ) {
+                       } else if ( !strcasecmp(sval,"SYNTAX") ) {
                                LDAP_FREE(sval);
                                if ( seen_syntax ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2242,7 +2268,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                    }
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"SINGLE-VALUE") ) {
+                       } else if ( !strcasecmp(sval,"SINGLE-VALUE") ) {
                                LDAP_FREE(sval);
                                if ( at->at_single_value ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2252,7 +2278,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                }
                                at->at_single_value = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"COLLECTIVE") ) {
+                       } else if ( !strcasecmp(sval,"COLLECTIVE") ) {
                                LDAP_FREE(sval);
                                if ( at->at_collective ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2262,7 +2288,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                }
                                at->at_collective = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"NO-USER-MODIFICATION") ) {
+                       } else if ( !strcasecmp(sval,"NO-USER-MODIFICATION") ) {
                                LDAP_FREE(sval);
                                if ( at->at_no_user_mod ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2272,7 +2298,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                }
                                at->at_no_user_mod = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"USAGE") ) {
+                       } else if ( !strcasecmp(sval,"USAGE") ) {
                                LDAP_FREE(sval);
                                if ( seen_usage ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2364,7 +2390,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -2417,16 +2443,16 @@ ldap_str2objectclass( LDAP_CONST char * s,
                        ss = savepos;
                        kind = get_token(&ss,&sval);
                        if ( kind == TK_BAREWORD ) {
-                               if ( !strcmp(sval, "NAME") ||
-                                    !strcmp(sval, "DESC") ||
-                                    !strcmp(sval, "OBSOLETE") ||
-                                    !strcmp(sval, "SUP") ||
-                                    !strcmp(sval, "ABSTRACT") ||
-                                    !strcmp(sval, "STRUCTURAL") ||
-                                    !strcmp(sval, "AUXILIARY") ||
-                                    !strcmp(sval, "MUST") ||
-                                    !strcmp(sval, "MAY") ||
-                                    !strncmp(sval, "X-", 2) ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "SUP") ||
+                                    !strcasecmp(sval, "ABSTRACT") ||
+                                    !strcasecmp(sval, "STRUCTURAL") ||
+                                    !strcasecmp(sval, "AUXILIARY") ||
+                                    !strcasecmp(sval, "MUST") ||
+                                    !strcasecmp(sval, "MAY") ||
+                                    !strncasecmp(sval, "X-", 2) ) {
                                        /* Missing OID, backtrack */
                                        ss = savepos;
                                } else if ( flags &
@@ -2439,6 +2465,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                }
                        }
                        LDAP_FREE(sval);
+                       *code = 0;
                } else {
                        *errp = ss;
                        ldap_objectclass_free(oc);
@@ -2462,7 +2489,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                case TK_RIGHTPAREN:
                        return oc;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2479,7 +2506,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2499,7 +2526,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                }
                                oc->oc_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2510,7 +2537,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                oc->oc_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"SUP") ) {
+                       } else if ( !strcasecmp(sval,"SUP") ) {
                                LDAP_FREE(sval);
                                if ( seen_sup ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2522,12 +2549,13 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                oc->oc_sup_oids = parse_oids(&ss,
                                                             code,
                                                             flags);
-                               if ( !oc->oc_sup_oids ) {
+                               if ( !oc->oc_sup_oids && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"ABSTRACT") ) {
+                               *code = 0;
+                       } else if ( !strcasecmp(sval,"ABSTRACT") ) {
                                LDAP_FREE(sval);
                                if ( seen_kind ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2538,7 +2566,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                seen_kind = 1;
                                oc->oc_kind = LDAP_SCHEMA_ABSTRACT;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"STRUCTURAL") ) {
+                       } else if ( !strcasecmp(sval,"STRUCTURAL") ) {
                                LDAP_FREE(sval);
                                if ( seen_kind ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2549,7 +2577,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                seen_kind = 1;
                                oc->oc_kind = LDAP_SCHEMA_STRUCTURAL;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"AUXILIARY") ) {
+                       } else if ( !strcasecmp(sval,"AUXILIARY") ) {
                                LDAP_FREE(sval);
                                if ( seen_kind ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2560,7 +2588,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                seen_kind = 1;
                                oc->oc_kind = LDAP_SCHEMA_AUXILIARY;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MUST") ) {
+                       } else if ( !strcasecmp(sval,"MUST") ) {
                                LDAP_FREE(sval);
                                if ( seen_must ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2570,13 +2598,14 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                }
                                seen_must = 1;
                                oc->oc_at_oids_must = parse_oids(&ss,code,0);
-                               if ( !oc->oc_at_oids_must ) {
+                               if ( !oc->oc_at_oids_must && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
+                               *code = 0;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MAY") ) {
+                       } else if ( !strcasecmp(sval,"MAY") ) {
                                LDAP_FREE(sval);
                                if ( seen_may ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2586,15 +2615,17 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                }
                                seen_may = 1;
                                oc->oc_at_oids_may = parse_oids(&ss,code,0);
-                               if ( !oc->oc_at_oids_may ) {
+                               if ( !oc->oc_at_oids_may && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
+                               *code = 0;
                                parse_whsp(&ss);
                        } else if ( sval[0] == 'X' && sval[1] == '-' ) {
                                /* Should be parse_qdstrings */
                                ext_vals = parse_qdescrs(&ss, code);
+                               *code = 0;
                                if ( !ext_vals ) {
                                        *errp = ss;
                                        ldap_objectclass_free(oc);
@@ -2646,7 +2677,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -2689,9 +2720,36 @@ ldap_str2contentrule( LDAP_CONST char * s,
        savepos = ss;
        cr->cr_oid = ldap_int_parse_numericoid(&ss,code,0);
        if ( !cr->cr_oid ) {
-               *errp = ss;
-               ldap_contentrule_free(cr);
-               return NULL;
+               if ( (flags & LDAP_SCHEMA_ALLOW_ALL) && (ss == savepos) ) {
+                       /* Backtracking */
+                       ss = savepos;
+                       kind = get_token(&ss,&sval);
+                       if ( kind == TK_BAREWORD ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "AUX") ||
+                                    !strcasecmp(sval, "MUST") ||
+                                    !strcasecmp(sval, "MAY") ||
+                                    !strcasecmp(sval, "NOT") ||
+                                    !strncasecmp(sval, "X-", 2) ) {
+                                       /* Missing OID, backtrack */
+                                       ss = savepos;
+                               } else if ( flags &
+                                       LDAP_SCHEMA_ALLOW_OID_MACRO ) {
+                                       /* Non-numerical OID, ignore */
+                                       int len = ss-savepos;
+                                       cr->cr_oid = LDAP_MALLOC(len+1);
+                                       strncpy(cr->cr_oid, savepos, len);
+                                       cr->cr_oid[len] = 0;
+                               }
+                       }
+                       LDAP_FREE(sval);
+               } else {
+                       *errp = ss;
+                       ldap_contentrule_free(cr);
+                       return NULL;
+               }
        }
        parse_whsp(&ss);
 
@@ -2710,7 +2768,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                case TK_RIGHTPAREN:
                        return cr;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2727,7 +2785,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                        ldap_contentrule_free(cr);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2747,7 +2805,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                }
                                cr->cr_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2758,7 +2816,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                cr->cr_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"AUX") ) {
+                       } else if ( !strcasecmp(sval,"AUX") ) {
                                LDAP_FREE(sval);
                                if ( seen_aux ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2774,7 +2832,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                        return NULL;
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MUST") ) {
+                       } else if ( !strcasecmp(sval,"MUST") ) {
                                LDAP_FREE(sval);
                                if ( seen_must ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2784,13 +2842,13 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                }
                                seen_must = 1;
                                cr->cr_at_oids_must = parse_oids(&ss,code,0);
-                               if ( !cr->cr_at_oids_must ) {
+                               if ( !cr->cr_at_oids_must && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_contentrule_free(cr);
                                        return NULL;
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MAY") ) {
+                       } else if ( !strcasecmp(sval,"MAY") ) {
                                LDAP_FREE(sval);
                                if ( seen_may ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2800,13 +2858,13 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                }
                                seen_may = 1;
                                cr->cr_at_oids_may = parse_oids(&ss,code,0);
-                               if ( !cr->cr_at_oids_may ) {
+                               if ( !cr->cr_at_oids_may && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_contentrule_free(cr);
                                        return NULL;
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"NOT") ) {
+                       } else if ( !strcasecmp(sval,"NOT") ) {
                                LDAP_FREE(sval);
                                if ( seen_not ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2816,7 +2874,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                }
                                seen_not = 1;
                                cr->cr_at_oids_not = parse_oids(&ss,code,0);
-                               if ( !cr->cr_at_oids_not ) {
+                               if ( !cr->cr_at_oids_not && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_contentrule_free(cr);
                                        return NULL;
@@ -2873,7 +2931,8 @@ ldap_str2structurerule( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind, ret;
+       tk_t kind;
+       int ret;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -2939,7 +2998,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
                        }
                        return sr;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2956,7 +3015,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
                                        ldap_structurerule_free(sr);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2976,7 +3035,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
                                }
                                sr->sr_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2987,7 +3046,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                sr->sr_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"FORM") ) {
+                       } else if ( !strcasecmp(sval,"FORM") ) {
                                LDAP_FREE(sval);
                                if ( seen_nameform ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3056,7 +3115,7 @@ ldap_str2nameform( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -3128,7 +3187,7 @@ ldap_str2nameform( LDAP_CONST char * s,
                        }
                        return nf;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3145,7 +3204,7 @@ ldap_str2nameform( LDAP_CONST char * s,
                                        ldap_nameform_free(nf);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3165,7 +3224,7 @@ ldap_str2nameform( LDAP_CONST char * s,
                                }
                                nf->nf_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3176,7 +3235,22 @@ ldap_str2nameform( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                nf->nf_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MUST") ) {
+                       } else if ( !strcasecmp(sval,"OC") ) {
+                               LDAP_FREE(sval);
+                               if ( seen_class ) {
+                                       *code = LDAP_SCHERR_DUPOPT;
+                                       *errp = ss;
+                                       ldap_nameform_free(nf);
+                                       return(NULL);
+                               }
+                               seen_class = 1;
+                               nf->nf_objectclass = parse_woid(&ss,code);
+                               if ( !nf->nf_objectclass ) {
+                                       *errp = ss;
+                                       ldap_nameform_free(nf);
+                                       return NULL;
+                               }
+                       } else if ( !strcasecmp(sval,"MUST") ) {
                                LDAP_FREE(sval);
                                if ( seen_must ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3186,13 +3260,13 @@ ldap_str2nameform( LDAP_CONST char * s,
                                }
                                seen_must = 1;
                                nf->nf_at_oids_must = parse_oids(&ss,code,0);
-                               if ( !nf->nf_at_oids_must ) {
+                               if ( !nf->nf_at_oids_must && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_nameform_free(nf);
                                        return NULL;
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MAY") ) {
+                       } else if ( !strcasecmp(sval,"MAY") ) {
                                LDAP_FREE(sval);
                                if ( seen_may ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3202,7 +3276,7 @@ ldap_str2nameform( LDAP_CONST char * s,
                                }
                                seen_may = 1;
                                nf->nf_at_oids_may = parse_oids(&ss,code,0);
-                               if ( !nf->nf_at_oids_may ) {
+                               if ( !nf->nf_at_oids_may && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_nameform_free(nf);
                                        return NULL;