]> git.sur5r.net Git - openldap/blobdiff - libraries/libldap/schema.c
ITS#4844 add missing overlays
[openldap] / libraries / libldap / schema.c
index c413d1200d5f79fb4ea2a57258705b4f8a8ea33c..86f26e638828c28f3ecc4980e37e3796454960c7 100644 (file)
@@ -1,7 +1,7 @@
 /* $OpenLDAP$ */
 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
  *
- * Copyright 1998-2004 The OpenLDAP Foundation.
+ * Copyright 1998-2007 The OpenLDAP Foundation.
  * All rights reserved.
  *
  * Redistribution and use in source and binary forms, with or without
@@ -959,26 +959,23 @@ ldap_attributetype2bv(  LDAPAttributeType * at, struct berval *bv )
  * interpretation of the specs).
  */
 
-#define TK_NOENDQUOTE  -2
-#define TK_OUTOFMEM    -1
-#define TK_EOS         0
-#define TK_UNEXPCHAR   1
-#define TK_BAREWORD    2
-#define TK_QDSTRING    3
-#define TK_LEFTPAREN   4
-#define TK_RIGHTPAREN  5
-#define TK_DOLLAR      6
-#define TK_QDESCR      TK_QDSTRING
-
-struct token {
-       int type;
-       char *sval;
-};
-
-static int
+typedef enum tk_t {
+       TK_NOENDQUOTE   = -2,
+       TK_OUTOFMEM     = -1,
+       TK_EOS          = 0,
+       TK_UNEXPCHAR    = 1,
+       TK_BAREWORD     = 2,
+       TK_QDSTRING     = 3,
+       TK_LEFTPAREN    = 4,
+       TK_RIGHTPAREN   = 5,
+       TK_DOLLAR       = 6,
+       TK_QDESCR       = TK_QDSTRING
+} tk_t;
+
+static tk_t
 get_token( const char ** sp, char ** token_val )
 {
-       int kind;
+       tk_t kind;
        const char * p;
        const char * q;
        char * res;
@@ -1030,6 +1027,9 @@ get_token( const char ** sp, char ** token_val )
                        **sp != ')' &&
                        **sp != '$' &&
                        **sp != '\'' &&
+                       /* for suggested minimum upper bound on the number
+                        * of characters (RFC 4517) */
+                       **sp != '{' &&
                        **sp != '\0' )
                        (*sp)++;
                q = *sp;
@@ -1150,7 +1150,7 @@ parse_qdescrs(const char **sp, int *code)
 {
        char ** res;
        char ** res1;
-       int kind;
+       tk_t kind;
        char * sval;
        int size;
        int pos;
@@ -1217,7 +1217,7 @@ static char *
 parse_woid(const char **sp, int *code)
 {
        char * sval;
-       int kind;
+       tk_t kind;
 
        parse_whsp(sp);
        kind = get_token(sp, &sval);
@@ -1232,10 +1232,13 @@ parse_woid(const char **sp, int *code)
 
 /* Parse a noidlen */
 static char *
-parse_noidlen(const char **sp, int *code, int *len, int allow_quoted)
+parse_noidlen(const char **sp, int *code, int *len, int flags)
 {
        char * sval;
+       const char *savepos;
        int quoted = 0;
+       int allow_quoted = ( flags & LDAP_SCHEMA_ALLOW_QUOTED );
+       int allow_oidmacro = ( flags & LDAP_SCHEMA_ALLOW_OID_MACRO );
 
        *len = 0;
        /* Netscape puts the SYNTAX value in quotes (incorrectly) */
@@ -1243,9 +1246,22 @@ parse_noidlen(const char **sp, int *code, int *len, int allow_quoted)
                quoted = 1;
                (*sp)++;
        }
+       savepos = *sp;
        sval = ldap_int_parse_numericoid(sp, code, 0);
        if ( !sval ) {
-               return NULL;
+               if ( allow_oidmacro
+                       && *sp == savepos
+                       && *code == LDAP_SCHERR_NODIGIT )
+               {
+                       if ( get_token(sp, &sval) != TK_BAREWORD ) {
+                               if ( sval != NULL ) {
+                                       LDAP_FREE(sval);
+                               }
+                               return NULL;
+                       }
+               } else {
+                       return NULL;
+               }
        }
        if ( **sp == '{' /*}*/ ) {
                (*sp)++;
@@ -1284,7 +1300,7 @@ parse_oids(const char **sp, int *code, const int allow_quoted)
 {
        char ** res;
        char ** res1;
-       int kind;
+       tk_t kind;
        char * sval;
        int size;
        int pos;
@@ -1312,6 +1328,11 @@ parse_oids(const char **sp, int *code, const int allow_quoted)
                     ( allow_quoted && kind == TK_QDSTRING ) ) {
                        res[pos++] = sval;
                        res[pos] = NULL;
+               } else if ( kind == TK_RIGHTPAREN ) {
+                       /* FIXME: be liberal in what we accept... */
+                       parse_whsp(sp);
+                       LDAP_FREE(res);
+                       return NULL;
                } else {
                        *code = LDAP_SCHERR_UNEXPTOKEN;
                        LDAP_FREE(sval);
@@ -1393,16 +1414,20 @@ add_extension(LDAPSchemaExtensionItem ***extensions,
        if ( !*extensions ) {
                *extensions =
                  LDAP_CALLOC(2, sizeof(LDAPSchemaExtensionItem *));
-               if ( !*extensions )
-                 return 1;
+               if ( !*extensions ) {
+                       LDAP_FREE( ext );
+                       return 1;
+               }
                n = 0;
        } else {
                for ( n=0; (*extensions)[n] != NULL; n++ )
                        ;
                tmp = LDAP_REALLOC(*extensions,
                                   (n+2)*sizeof(LDAPSchemaExtensionItem *));
-               if ( !tmp )
+               if ( !tmp ) {
+                       LDAP_FREE( ext );
                        return 1;
+               }
                *extensions = tmp;
        }
        (*extensions)[n] = ext;
@@ -1441,7 +1466,7 @@ ldap_str2syntax( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -1495,7 +1520,7 @@ ldap_str2syntax( LDAP_CONST char * s,
                case TK_RIGHTPAREN:
                        return syn;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1512,7 +1537,7 @@ ldap_str2syntax( LDAP_CONST char * s,
                                        ldap_syntax_free(syn);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1583,7 +1608,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -1625,11 +1650,11 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                        ss = savepos;
                        kind = get_token(&ss,&sval);
                        if ( kind == TK_BAREWORD ) {
-                               if ( !strcmp(sval, "NAME") ||
-                                    !strcmp(sval, "DESC") ||
-                                    !strcmp(sval, "OBSOLETE") ||
-                                    !strcmp(sval, "SYNTAX") ||
-                                    !strncmp(sval, "X-", 2) ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "SYNTAX") ||
+                                    !strncasecmp(sval, "X-", 2) ) {
                                        /* Missing OID, backtrack */
                                        ss = savepos;
                                } else {
@@ -1665,7 +1690,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                        }
                        return mr;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1682,7 +1707,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                                        ldap_matchingrule_free(mr);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1702,7 +1727,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                                }
                                mr->mr_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1713,7 +1738,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                mr->mr_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"SYNTAX") ) {
+                       } else if ( !strcasecmp(sval,"SYNTAX") ) {
                                LDAP_FREE(sval);
                                if ( seen_syntax ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1782,7 +1807,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -1824,11 +1849,11 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                        ss = savepos;
                        kind = get_token(&ss,&sval);
                        if ( kind == TK_BAREWORD ) {
-                               if ( !strcmp(sval, "NAME") ||
-                                    !strcmp(sval, "DESC") ||
-                                    !strcmp(sval, "OBSOLETE") ||
-                                    !strcmp(sval, "APPLIES") ||
-                                    !strncmp(sval, "X-", 2) ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "APPLIES") ||
+                                    !strncasecmp(sval, "X-", 2) ) {
                                        /* Missing OID, backtrack */
                                        ss = savepos;
                                } else {
@@ -1864,7 +1889,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                        }
                        return mru;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1881,7 +1906,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                                        ldap_matchingruleuse_free(mru);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1901,7 +1926,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                                }
                                mru->mru_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1912,7 +1937,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                mru->mru_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"APPLIES") ) {
+                       } else if ( !strcasecmp(sval,"APPLIES") ) {
                                LDAP_FREE(sval);
                                if ( seen_applies ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1924,7 +1949,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                                mru->mru_applies_oids = parse_oids(&ss,
                                                             code,
                                                             flags);
-                               if ( !mru->mru_applies_oids ) {
+                               if ( !mru->mru_applies_oids && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_matchingruleuse_free(mru);
                                        return NULL;
@@ -1984,7 +2009,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -2035,28 +2060,31 @@ ldap_str2attributetype( LDAP_CONST char * s,
        if ( !at->at_oid ) {
                if ( ( flags & ( LDAP_SCHEMA_ALLOW_NO_OID
                                | LDAP_SCHEMA_ALLOW_OID_MACRO ) )
-                           && (ss == savepos) ) {
+                           && (ss == savepos) )
+               {
                        /* Backtracking */
                        ss = savepos;
                        kind = get_token(&ss,&sval);
                        if ( kind == TK_BAREWORD ) {
-                               if ( !strcmp(sval, "NAME") ||
-                                    !strcmp(sval, "DESC") ||
-                                    !strcmp(sval, "OBSOLETE") ||
-                                    !strcmp(sval, "SUP") ||
-                                    !strcmp(sval, "EQUALITY") ||
-                                    !strcmp(sval, "ORDERING") ||
-                                    !strcmp(sval, "SUBSTR") ||
-                                    !strcmp(sval, "SYNTAX") ||
-                                    !strcmp(sval, "SINGLE-VALUE") ||
-                                    !strcmp(sval, "COLLECTIVE") ||
-                                    !strcmp(sval, "NO-USER-MODIFICATION") ||
-                                    !strcmp(sval, "USAGE") ||
-                                    !strncmp(sval, "X-", 2) ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "SUP") ||
+                                    !strcasecmp(sval, "EQUALITY") ||
+                                    !strcasecmp(sval, "ORDERING") ||
+                                    !strcasecmp(sval, "SUBSTR") ||
+                                    !strcasecmp(sval, "SYNTAX") ||
+                                    !strcasecmp(sval, "SINGLE-VALUE") ||
+                                    !strcasecmp(sval, "COLLECTIVE") ||
+                                    !strcasecmp(sval, "NO-USER-MODIFICATION") ||
+                                    !strcasecmp(sval, "USAGE") ||
+                                    !strncasecmp(sval, "X-", 2) )
+                               {
                                        /* Missing OID, backtrack */
                                        ss = savepos;
                                } else if ( flags
-                                       & LDAP_SCHEMA_ALLOW_OID_MACRO) {
+                                       & LDAP_SCHEMA_ALLOW_OID_MACRO)
+                               {
                                        /* Non-numerical OID ... */
                                        int len = ss-savepos;
                                        at->at_oid = LDAP_MALLOC(len+1);
@@ -2088,7 +2116,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                case TK_RIGHTPAREN:
                        return at;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2105,7 +2133,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2125,7 +2153,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                }
                                at->at_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2136,7 +2164,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                at->at_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"SUP") ) {
+                       } else if ( !strcasecmp(sval,"SUP") ) {
                                LDAP_FREE(sval);
                                if ( seen_sup ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2151,7 +2179,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"EQUALITY") ) {
+                       } else if ( !strcasecmp(sval,"EQUALITY") ) {
                                LDAP_FREE(sval);
                                if ( seen_equality ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2166,7 +2194,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"ORDERING") ) {
+                       } else if ( !strcasecmp(sval,"ORDERING") ) {
                                LDAP_FREE(sval);
                                if ( seen_ordering ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2181,7 +2209,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"SUBSTR") ) {
+                       } else if ( !strcasecmp(sval,"SUBSTR") ) {
                                LDAP_FREE(sval);
                                if ( seen_substr ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2196,7 +2224,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"SYNTAX") ) {
+                       } else if ( !strcasecmp(sval,"SYNTAX") ) {
                                LDAP_FREE(sval);
                                if ( seen_syntax ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2240,7 +2268,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                    }
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"SINGLE-VALUE") ) {
+                       } else if ( !strcasecmp(sval,"SINGLE-VALUE") ) {
                                LDAP_FREE(sval);
                                if ( at->at_single_value ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2250,7 +2278,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                }
                                at->at_single_value = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"COLLECTIVE") ) {
+                       } else if ( !strcasecmp(sval,"COLLECTIVE") ) {
                                LDAP_FREE(sval);
                                if ( at->at_collective ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2260,7 +2288,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                }
                                at->at_collective = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"NO-USER-MODIFICATION") ) {
+                       } else if ( !strcasecmp(sval,"NO-USER-MODIFICATION") ) {
                                LDAP_FREE(sval);
                                if ( at->at_no_user_mod ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2270,7 +2298,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                }
                                at->at_no_user_mod = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"USAGE") ) {
+                       } else if ( !strcasecmp(sval,"USAGE") ) {
                                LDAP_FREE(sval);
                                if ( seen_usage ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2362,7 +2390,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -2415,16 +2443,16 @@ ldap_str2objectclass( LDAP_CONST char * s,
                        ss = savepos;
                        kind = get_token(&ss,&sval);
                        if ( kind == TK_BAREWORD ) {
-                               if ( !strcmp(sval, "NAME") ||
-                                    !strcmp(sval, "DESC") ||
-                                    !strcmp(sval, "OBSOLETE") ||
-                                    !strcmp(sval, "SUP") ||
-                                    !strcmp(sval, "ABSTRACT") ||
-                                    !strcmp(sval, "STRUCTURAL") ||
-                                    !strcmp(sval, "AUXILIARY") ||
-                                    !strcmp(sval, "MUST") ||
-                                    !strcmp(sval, "MAY") ||
-                                    !strncmp(sval, "X-", 2) ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "SUP") ||
+                                    !strcasecmp(sval, "ABSTRACT") ||
+                                    !strcasecmp(sval, "STRUCTURAL") ||
+                                    !strcasecmp(sval, "AUXILIARY") ||
+                                    !strcasecmp(sval, "MUST") ||
+                                    !strcasecmp(sval, "MAY") ||
+                                    !strncasecmp(sval, "X-", 2) ) {
                                        /* Missing OID, backtrack */
                                        ss = savepos;
                                } else if ( flags &
@@ -2437,6 +2465,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                }
                        }
                        LDAP_FREE(sval);
+                       *code = 0;
                } else {
                        *errp = ss;
                        ldap_objectclass_free(oc);
@@ -2460,7 +2489,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                case TK_RIGHTPAREN:
                        return oc;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2477,7 +2506,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2497,7 +2526,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                }
                                oc->oc_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2508,7 +2537,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                oc->oc_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"SUP") ) {
+                       } else if ( !strcasecmp(sval,"SUP") ) {
                                LDAP_FREE(sval);
                                if ( seen_sup ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2520,12 +2549,13 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                oc->oc_sup_oids = parse_oids(&ss,
                                                             code,
                                                             flags);
-                               if ( !oc->oc_sup_oids ) {
+                               if ( !oc->oc_sup_oids && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"ABSTRACT") ) {
+                               *code = 0;
+                       } else if ( !strcasecmp(sval,"ABSTRACT") ) {
                                LDAP_FREE(sval);
                                if ( seen_kind ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2536,7 +2566,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                seen_kind = 1;
                                oc->oc_kind = LDAP_SCHEMA_ABSTRACT;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"STRUCTURAL") ) {
+                       } else if ( !strcasecmp(sval,"STRUCTURAL") ) {
                                LDAP_FREE(sval);
                                if ( seen_kind ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2547,7 +2577,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                seen_kind = 1;
                                oc->oc_kind = LDAP_SCHEMA_STRUCTURAL;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"AUXILIARY") ) {
+                       } else if ( !strcasecmp(sval,"AUXILIARY") ) {
                                LDAP_FREE(sval);
                                if ( seen_kind ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2558,7 +2588,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                seen_kind = 1;
                                oc->oc_kind = LDAP_SCHEMA_AUXILIARY;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MUST") ) {
+                       } else if ( !strcasecmp(sval,"MUST") ) {
                                LDAP_FREE(sval);
                                if ( seen_must ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2568,13 +2598,14 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                }
                                seen_must = 1;
                                oc->oc_at_oids_must = parse_oids(&ss,code,0);
-                               if ( !oc->oc_at_oids_must ) {
+                               if ( !oc->oc_at_oids_must && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
+                               *code = 0;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MAY") ) {
+                       } else if ( !strcasecmp(sval,"MAY") ) {
                                LDAP_FREE(sval);
                                if ( seen_may ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2584,15 +2615,17 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                }
                                seen_may = 1;
                                oc->oc_at_oids_may = parse_oids(&ss,code,0);
-                               if ( !oc->oc_at_oids_may ) {
+                               if ( !oc->oc_at_oids_may && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
+                               *code = 0;
                                parse_whsp(&ss);
                        } else if ( sval[0] == 'X' && sval[1] == '-' ) {
                                /* Should be parse_qdstrings */
                                ext_vals = parse_qdescrs(&ss, code);
+                               *code = 0;
                                if ( !ext_vals ) {
                                        *errp = ss;
                                        ldap_objectclass_free(oc);
@@ -2644,7 +2677,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -2692,14 +2725,14 @@ ldap_str2contentrule( LDAP_CONST char * s,
                        ss = savepos;
                        kind = get_token(&ss,&sval);
                        if ( kind == TK_BAREWORD ) {
-                               if ( !strcmp(sval, "NAME") ||
-                                    !strcmp(sval, "DESC") ||
-                                    !strcmp(sval, "OBSOLETE") ||
-                                    !strcmp(sval, "AUX") ||
-                                    !strcmp(sval, "MUST") ||
-                                    !strcmp(sval, "MAY") ||
-                                    !strcmp(sval, "NOT") ||
-                                    !strncmp(sval, "X-", 2) ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "AUX") ||
+                                    !strcasecmp(sval, "MUST") ||
+                                    !strcasecmp(sval, "MAY") ||
+                                    !strcasecmp(sval, "NOT") ||
+                                    !strncasecmp(sval, "X-", 2) ) {
                                        /* Missing OID, backtrack */
                                        ss = savepos;
                                } else if ( flags &
@@ -2735,7 +2768,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                case TK_RIGHTPAREN:
                        return cr;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2752,7 +2785,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                        ldap_contentrule_free(cr);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2772,7 +2805,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                }
                                cr->cr_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2783,7 +2816,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                cr->cr_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"AUX") ) {
+                       } else if ( !strcasecmp(sval,"AUX") ) {
                                LDAP_FREE(sval);
                                if ( seen_aux ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2799,7 +2832,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                        return NULL;
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MUST") ) {
+                       } else if ( !strcasecmp(sval,"MUST") ) {
                                LDAP_FREE(sval);
                                if ( seen_must ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2809,13 +2842,13 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                }
                                seen_must = 1;
                                cr->cr_at_oids_must = parse_oids(&ss,code,0);
-                               if ( !cr->cr_at_oids_must ) {
+                               if ( !cr->cr_at_oids_must && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_contentrule_free(cr);
                                        return NULL;
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MAY") ) {
+                       } else if ( !strcasecmp(sval,"MAY") ) {
                                LDAP_FREE(sval);
                                if ( seen_may ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2825,13 +2858,13 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                }
                                seen_may = 1;
                                cr->cr_at_oids_may = parse_oids(&ss,code,0);
-                               if ( !cr->cr_at_oids_may ) {
+                               if ( !cr->cr_at_oids_may && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_contentrule_free(cr);
                                        return NULL;
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"NOT") ) {
+                       } else if ( !strcasecmp(sval,"NOT") ) {
                                LDAP_FREE(sval);
                                if ( seen_not ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2841,7 +2874,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                }
                                seen_not = 1;
                                cr->cr_at_oids_not = parse_oids(&ss,code,0);
-                               if ( !cr->cr_at_oids_not ) {
+                               if ( !cr->cr_at_oids_not && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_contentrule_free(cr);
                                        return NULL;
@@ -2898,7 +2931,8 @@ ldap_str2structurerule( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind, ret;
+       tk_t kind;
+       int ret;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -2964,7 +2998,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
                        }
                        return sr;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2981,7 +3015,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
                                        ldap_structurerule_free(sr);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3001,7 +3035,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
                                }
                                sr->sr_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3012,7 +3046,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                sr->sr_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"FORM") ) {
+                       } else if ( !strcasecmp(sval,"FORM") ) {
                                LDAP_FREE(sval);
                                if ( seen_nameform ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3081,7 +3115,7 @@ ldap_str2nameform( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -3153,7 +3187,7 @@ ldap_str2nameform( LDAP_CONST char * s,
                        }
                        return nf;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3170,7 +3204,7 @@ ldap_str2nameform( LDAP_CONST char * s,
                                        ldap_nameform_free(nf);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3190,7 +3224,7 @@ ldap_str2nameform( LDAP_CONST char * s,
                                }
                                nf->nf_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3201,7 +3235,22 @@ ldap_str2nameform( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                nf->nf_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MUST") ) {
+                       } else if ( !strcasecmp(sval,"OC") ) {
+                               LDAP_FREE(sval);
+                               if ( seen_class ) {
+                                       *code = LDAP_SCHERR_DUPOPT;
+                                       *errp = ss;
+                                       ldap_nameform_free(nf);
+                                       return(NULL);
+                               }
+                               seen_class = 1;
+                               nf->nf_objectclass = parse_woid(&ss,code);
+                               if ( !nf->nf_objectclass ) {
+                                       *errp = ss;
+                                       ldap_nameform_free(nf);
+                                       return NULL;
+                               }
+                       } else if ( !strcasecmp(sval,"MUST") ) {
                                LDAP_FREE(sval);
                                if ( seen_must ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3211,13 +3260,13 @@ ldap_str2nameform( LDAP_CONST char * s,
                                }
                                seen_must = 1;
                                nf->nf_at_oids_must = parse_oids(&ss,code,0);
-                               if ( !nf->nf_at_oids_must ) {
+                               if ( !nf->nf_at_oids_must && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_nameform_free(nf);
                                        return NULL;
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MAY") ) {
+                       } else if ( !strcasecmp(sval,"MAY") ) {
                                LDAP_FREE(sval);
                                if ( seen_may ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3227,7 +3276,7 @@ ldap_str2nameform( LDAP_CONST char * s,
                                }
                                seen_may = 1;
                                nf->nf_at_oids_may = parse_oids(&ss,code,0);
-                               if ( !nf->nf_at_oids_may ) {
+                               if ( !nf->nf_at_oids_may && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_nameform_free(nf);
                                        return NULL;