]> git.sur5r.net Git - openldap/blobdiff - libraries/libldap/schema.c
Happy new year (belated)
[openldap] / libraries / libldap / schema.c
index 2cfe8d46d11c1b2c9088b3f34eaceb90a9a07a20..9bfc85b848fe8c3f1b1ea994f29ba71f023edae3 100644 (file)
@@ -1,8 +1,18 @@
 /* $OpenLDAP$ */
-/*
- * Copyright 1999-2002 The OpenLDAP Foundation, All Rights Reserved.
- * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
+/* This work is part of OpenLDAP Software <http://www.openldap.org/>.
+ *
+ * Copyright 1998-2014 The OpenLDAP Foundation.
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted only as authorized by the OpenLDAP
+ * Public License.
+ *
+ * A copy of this license is available in the file LICENSE in the
+ * top-level directory of the distribution or, alternatively, at
+ * <http://www.OpenLDAP.org/license.html>.
  */
+
 /*
  * schema.c:  parsing routines used by servers and clients to process
  *     schema definitions
@@ -20,6 +30,8 @@
 
 #include <ldap_schema.h>
 
+static const char EndOfInput[] = "end of input";
+
 static const char *
 choose_name( char *names[], const char *fallback )
 {
@@ -29,57 +41,65 @@ choose_name( char *names[], const char *fallback )
 LDAP_CONST char *
 ldap_syntax2name( LDAPSyntax * syn )
 {
+       if (!syn) return NULL;
        return( syn->syn_oid );
 }
 
 LDAP_CONST char *
 ldap_matchingrule2name( LDAPMatchingRule * mr )
 {
+       if (!mr) return NULL;
        return( choose_name( mr->mr_names, mr->mr_oid ) );
 }
 
 LDAP_CONST char *
 ldap_matchingruleuse2name( LDAPMatchingRuleUse * mru )
 {
+       if (!mru) return NULL;
        return( choose_name( mru->mru_names, mru->mru_oid ) );
 }
 
 LDAP_CONST char *
 ldap_attributetype2name( LDAPAttributeType * at )
 {
+       if (!at) return NULL;
        return( choose_name( at->at_names, at->at_oid ) );
 }
 
 LDAP_CONST char *
 ldap_objectclass2name( LDAPObjectClass * oc )
 {
+       if (!oc) return NULL;
        return( choose_name( oc->oc_names, oc->oc_oid ) );
 }
 
 LDAP_CONST char *
 ldap_contentrule2name( LDAPContentRule * cr )
 {
+       if (!cr) return NULL;
        return( choose_name( cr->cr_names, cr->cr_oid ) );
 }
 
 LDAP_CONST char *
 ldap_nameform2name( LDAPNameForm * nf )
 {
+       if (!nf) return NULL;
        return( choose_name( nf->nf_names, nf->nf_oid ) );
 }
 
 LDAP_CONST char *
 ldap_structurerule2name( LDAPStructureRule * sr )
 {
+       if (!sr) return NULL;
        return( choose_name( sr->sr_names, NULL ) );
 }
 
 /*
  * When pretty printing the entities we will be appending to a buffer.
  * Since checking for overflow, realloc'ing and checking if no error
- * is extremely boring, we error until the end.  This layer is
- * implemented with the he will use a protection layer that will let
- * us blissfully ignore thlp of the next type.
+ * is extremely boring, we will use a protection layer that will let
+ * us blissfully ignore the error until the end.  This layer is
+ * implemented with the help of the next type.
  */
 
 typedef struct safe_string {
@@ -120,12 +140,14 @@ safe_string_free(safe_string * ss)
        LDAP_FREE(ss);
 }
 
+#if 0  /* unused */
 static char *
 safe_string_val(safe_string * ss)
 {
        ss->val[ss->pos] = '\0';
        return(ss->val);
 }
+#endif
 
 static char *
 safe_strdup(safe_string * ss)
@@ -365,7 +387,10 @@ struct berval *
 ldap_syntax2bv( LDAPSyntax * syn, struct berval *bv )
 {
        safe_string * ss;
-       
+
+       if ( !syn || !bv )
+               return NULL;
+
        ss = new_safe_string(256);
        if ( !ss )
                return NULL;
@@ -407,7 +432,10 @@ struct berval *
 ldap_matchingrule2bv( LDAPMatchingRule * mr, struct berval *bv )
 {
        safe_string * ss;
-       
+
+       if ( !mr || !bv )
+               return NULL;
+
        ss = new_safe_string(256);
        if ( !ss )
                return NULL;
@@ -466,7 +494,10 @@ struct berval *
 ldap_matchingruleuse2bv( LDAPMatchingRuleUse * mru, struct berval *bv )
 {
        safe_string * ss;
-       
+
+       if ( !mru || !bv )
+               return NULL;
+
        ss = new_safe_string(256);
        if ( !ss )
                return NULL;
@@ -525,7 +556,10 @@ struct berval *
 ldap_objectclass2bv( LDAPObjectClass * oc, struct berval *bv )
 {
        safe_string * ss;
-       
+
+       if ( !oc || !bv )
+               return NULL;
+
        ss = new_safe_string(256);
        if ( !ss )
                return NULL;
@@ -614,7 +648,10 @@ struct berval *
 ldap_contentrule2bv( LDAPContentRule * cr, struct berval *bv )
 {
        safe_string * ss;
-       
+
+       if ( !cr || !bv )
+               return NULL;
+
        ss = new_safe_string(256);
        if ( !ss )
                return NULL;
@@ -693,7 +730,10 @@ struct berval *
 ldap_structurerule2bv( LDAPStructureRule * sr, struct berval *bv )
 {
        safe_string * ss;
-       
+
+       if ( !sr || !bv )
+               return NULL;
+
        ss = new_safe_string(256);
        if ( !ss )
                return NULL;
@@ -757,7 +797,10 @@ struct berval *
 ldap_nameform2bv( LDAPNameForm * nf, struct berval *bv )
 {
        safe_string * ss;
-       
+
+       if ( !nf || !bv )
+               return NULL;
+
        ss = new_safe_string(256);
        if ( !ss )
                return NULL;
@@ -826,7 +869,10 @@ struct berval *
 ldap_attributetype2bv(  LDAPAttributeType * at, struct berval *bv )
 {
        safe_string * ss;
-       
+
+       if ( !at || !bv )
+               return NULL;
+
        ss = new_safe_string(256);
        if ( !ss )
                return NULL;
@@ -947,26 +993,23 @@ ldap_attributetype2bv(  LDAPAttributeType * at, struct berval *bv )
  * interpretation of the specs).
  */
 
-#define TK_NOENDQUOTE  -2
-#define TK_OUTOFMEM    -1
-#define TK_EOS         0
-#define TK_UNEXPCHAR   1
-#define TK_BAREWORD    2
-#define TK_QDSTRING    3
-#define TK_LEFTPAREN   4
-#define TK_RIGHTPAREN  5
-#define TK_DOLLAR      6
-#define TK_QDESCR      TK_QDSTRING
-
-struct token {
-       int type;
-       char *sval;
-};
-
-static int
+typedef enum tk_t {
+       TK_NOENDQUOTE   = -2,
+       TK_OUTOFMEM     = -1,
+       TK_EOS          = 0,
+       TK_UNEXPCHAR    = 1,
+       TK_BAREWORD     = 2,
+       TK_QDSTRING     = 3,
+       TK_LEFTPAREN    = 4,
+       TK_RIGHTPAREN   = 5,
+       TK_DOLLAR       = 6,
+       TK_QDESCR       = TK_QDSTRING
+} tk_t;
+
+static tk_t
 get_token( const char ** sp, char ** token_val )
 {
-       int kind;
+       tk_t kind;
        const char * p;
        const char * q;
        char * res;
@@ -1018,6 +1061,9 @@ get_token( const char ** sp, char ** token_val )
                        **sp != ')' &&
                        **sp != '$' &&
                        **sp != '\'' &&
+                       /* for suggested minimum upper bound on the number
+                        * of characters (RFC 4517) */
+                       **sp != '{' &&
                        **sp != '\0' )
                        (*sp)++;
                q = *sp;
@@ -1138,7 +1184,7 @@ parse_qdescrs(const char **sp, int *code)
 {
        char ** res;
        char ** res1;
-       int kind;
+       tk_t kind;
        char * sval;
        int size;
        int pos;
@@ -1171,8 +1217,8 @@ parse_qdescrs(const char **sp, int *code)
                                        }
                                        res = res1;
                                }
-                               res[pos] = sval;
-                               pos++;
+                               res[pos++] = sval;
+                               res[pos] = NULL;
                                parse_whsp(sp);
                        } else {
                                LDAP_VFREE(res);
@@ -1181,7 +1227,6 @@ parse_qdescrs(const char **sp, int *code)
                                return(NULL);
                        }
                }
-               res[pos] = NULL;
                parse_whsp(sp);
                return(res);
        } else if ( kind == TK_QDESCR ) {
@@ -1206,7 +1251,7 @@ static char *
 parse_woid(const char **sp, int *code)
 {
        char * sval;
-       int kind;
+       tk_t kind;
 
        parse_whsp(sp);
        kind = get_token(sp, &sval);
@@ -1221,10 +1266,13 @@ parse_woid(const char **sp, int *code)
 
 /* Parse a noidlen */
 static char *
-parse_noidlen(const char **sp, int *code, int *len, int allow_quoted)
+parse_noidlen(const char **sp, int *code, int *len, int flags)
 {
        char * sval;
+       const char *savepos;
        int quoted = 0;
+       int allow_quoted = ( flags & LDAP_SCHEMA_ALLOW_QUOTED );
+       int allow_oidmacro = ( flags & LDAP_SCHEMA_ALLOW_OID_MACRO );
 
        *len = 0;
        /* Netscape puts the SYNTAX value in quotes (incorrectly) */
@@ -1232,9 +1280,22 @@ parse_noidlen(const char **sp, int *code, int *len, int allow_quoted)
                quoted = 1;
                (*sp)++;
        }
+       savepos = *sp;
        sval = ldap_int_parse_numericoid(sp, code, 0);
        if ( !sval ) {
-               return NULL;
+               if ( allow_oidmacro
+                       && *sp == savepos
+                       && *code == LDAP_SCHERR_NODIGIT )
+               {
+                       if ( get_token(sp, &sval) != TK_BAREWORD ) {
+                               if ( sval != NULL ) {
+                                       LDAP_FREE(sval);
+                               }
+                               return NULL;
+                       }
+               } else {
+                       return NULL;
+               }
        }
        if ( **sp == '{' /*}*/ ) {
                (*sp)++;
@@ -1273,7 +1334,7 @@ parse_oids(const char **sp, int *code, const int allow_quoted)
 {
        char ** res;
        char ** res1;
-       int kind;
+       tk_t kind;
        char * sval;
        int size;
        int pos;
@@ -1299,8 +1360,13 @@ parse_oids(const char **sp, int *code, const int allow_quoted)
                kind = get_token(sp,&sval);
                if ( kind == TK_BAREWORD ||
                     ( allow_quoted && kind == TK_QDSTRING ) ) {
-                       res[pos] = sval;
-                       pos++;
+                       res[pos++] = sval;
+                       res[pos] = NULL;
+               } else if ( kind == TK_RIGHTPAREN ) {
+                       /* FIXME: be liberal in what we accept... */
+                       parse_whsp(sp);
+                       LDAP_FREE(res);
+                       return NULL;
                } else {
                        *code = LDAP_SCHERR_UNEXPTOKEN;
                        LDAP_FREE(sval);
@@ -1329,8 +1395,8 @@ parse_oids(const char **sp, int *code, const int allow_quoted)
                                                }
                                                res = res1;
                                        }
-                                       res[pos] = sval;
-                                       pos++;
+                                       res[pos++] = sval;
+                                       res[pos] = NULL;
                                } else {
                                        *code = LDAP_SCHERR_UNEXPTOKEN;
                                        LDAP_FREE(sval);
@@ -1345,7 +1411,6 @@ parse_oids(const char **sp, int *code, const int allow_quoted)
                                return NULL;
                        }
                }
-               res[pos] = NULL;
                parse_whsp(sp);
                return(res);
        } else if ( kind == TK_BAREWORD ||
@@ -1383,16 +1448,20 @@ add_extension(LDAPSchemaExtensionItem ***extensions,
        if ( !*extensions ) {
                *extensions =
                  LDAP_CALLOC(2, sizeof(LDAPSchemaExtensionItem *));
-               if ( !*extensions )
-                 return 1;
+               if ( !*extensions ) {
+                       LDAP_FREE( ext );
+                       return 1;
+               }
                n = 0;
        } else {
                for ( n=0; (*extensions)[n] != NULL; n++ )
                        ;
                tmp = LDAP_REALLOC(*extensions,
                                   (n+2)*sizeof(LDAPSchemaExtensionItem *));
-               if ( !tmp )
+               if ( !tmp ) {
+                       LDAP_FREE( ext );
                        return 1;
+               }
                *extensions = tmp;
        }
        (*extensions)[n] = ext;
@@ -1418,6 +1487,7 @@ free_extensions(LDAPSchemaExtensionItem **extensions)
 void
 ldap_syntax_free( LDAPSyntax * syn )
 {
+       if ( !syn ) return;
        LDAP_FREE(syn->syn_oid);
        if (syn->syn_names) LDAP_VFREE(syn->syn_names);
        if (syn->syn_desc) LDAP_FREE(syn->syn_desc);
@@ -1431,7 +1501,7 @@ ldap_str2syntax( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -1479,13 +1549,13 @@ ldap_str2syntax( LDAP_CONST char * s,
                switch (kind) {
                case TK_EOS:
                        *code = LDAP_SCHERR_NORIGHTPAREN;
-                       *errp = ss;
+                       *errp = EndOfInput;
                        ldap_syntax_free(syn);
                        return NULL;
                case TK_RIGHTPAREN:
                        return syn;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1502,7 +1572,7 @@ ldap_str2syntax( LDAP_CONST char * s,
                                        ldap_syntax_free(syn);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1559,6 +1629,7 @@ ldap_str2syntax( LDAP_CONST char * s,
 void
 ldap_matchingrule_free( LDAPMatchingRule * mr )
 {
+       if (!mr) return;
        LDAP_FREE(mr->mr_oid);
        if (mr->mr_names) LDAP_VFREE(mr->mr_names);
        if (mr->mr_desc) LDAP_FREE(mr->mr_desc);
@@ -1573,7 +1644,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -1615,11 +1686,11 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                        ss = savepos;
                        kind = get_token(&ss,&sval);
                        if ( kind == TK_BAREWORD ) {
-                               if ( !strcmp(sval, "NAME") ||
-                                    !strcmp(sval, "DESC") ||
-                                    !strcmp(sval, "OBSOLETE") ||
-                                    !strcmp(sval, "SYNTAX") ||
-                                    !strncmp(sval, "X-", 2) ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "SYNTAX") ||
+                                    !strncasecmp(sval, "X-", 2) ) {
                                        /* Missing OID, backtrack */
                                        ss = savepos;
                                } else {
@@ -1644,7 +1715,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                switch (kind) {
                case TK_EOS:
                        *code = LDAP_SCHERR_NORIGHTPAREN;
-                       *errp = ss;
+                       *errp = EndOfInput;
                        ldap_matchingrule_free(mr);
                        return NULL;
                case TK_RIGHTPAREN:
@@ -1655,7 +1726,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                        }
                        return mr;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1672,7 +1743,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                                        ldap_matchingrule_free(mr);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1692,7 +1763,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                                }
                                mr->mr_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1703,7 +1774,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                mr->mr_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"SYNTAX") ) {
+                       } else if ( !strcasecmp(sval,"SYNTAX") ) {
                                LDAP_FREE(sval);
                                if ( seen_syntax ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1758,6 +1829,7 @@ ldap_str2matchingrule( LDAP_CONST char * s,
 void
 ldap_matchingruleuse_free( LDAPMatchingRuleUse * mru )
 {
+       if (!mru) return;
        LDAP_FREE(mru->mru_oid);
        if (mru->mru_names) LDAP_VFREE(mru->mru_names);
        if (mru->mru_desc) LDAP_FREE(mru->mru_desc);
@@ -1772,7 +1844,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -1814,11 +1886,11 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                        ss = savepos;
                        kind = get_token(&ss,&sval);
                        if ( kind == TK_BAREWORD ) {
-                               if ( !strcmp(sval, "NAME") ||
-                                    !strcmp(sval, "DESC") ||
-                                    !strcmp(sval, "OBSOLETE") ||
-                                    !strcmp(sval, "APPLIES") ||
-                                    !strncmp(sval, "X-", 2) ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "APPLIES") ||
+                                    !strncasecmp(sval, "X-", 2) ) {
                                        /* Missing OID, backtrack */
                                        ss = savepos;
                                } else {
@@ -1843,7 +1915,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                switch (kind) {
                case TK_EOS:
                        *code = LDAP_SCHERR_NORIGHTPAREN;
-                       *errp = ss;
+                       *errp = EndOfInput;
                        ldap_matchingruleuse_free(mru);
                        return NULL;
                case TK_RIGHTPAREN:
@@ -1854,7 +1926,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                        }
                        return mru;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1871,7 +1943,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                                        ldap_matchingruleuse_free(mru);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1891,7 +1963,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                                }
                                mru->mru_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1902,7 +1974,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                mru->mru_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"APPLIES") ) {
+                       } else if ( !strcasecmp(sval,"APPLIES") ) {
                                LDAP_FREE(sval);
                                if ( seen_applies ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -1914,7 +1986,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
                                mru->mru_applies_oids = parse_oids(&ss,
                                                             code,
                                                             flags);
-                               if ( !mru->mru_applies_oids ) {
+                               if ( !mru->mru_applies_oids && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_matchingruleuse_free(mru);
                                        return NULL;
@@ -1956,6 +2028,7 @@ ldap_str2matchingruleuse( LDAP_CONST char * s,
 void
 ldap_attributetype_free(LDAPAttributeType * at)
 {
+       if (!at) return;
        LDAP_FREE(at->at_oid);
        if (at->at_names) LDAP_VFREE(at->at_names);
        if (at->at_desc) LDAP_FREE(at->at_desc);
@@ -1974,7 +2047,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -2025,28 +2098,31 @@ ldap_str2attributetype( LDAP_CONST char * s,
        if ( !at->at_oid ) {
                if ( ( flags & ( LDAP_SCHEMA_ALLOW_NO_OID
                                | LDAP_SCHEMA_ALLOW_OID_MACRO ) )
-                           && (ss == savepos) ) {
+                           && (ss == savepos) )
+               {
                        /* Backtracking */
                        ss = savepos;
                        kind = get_token(&ss,&sval);
                        if ( kind == TK_BAREWORD ) {
-                               if ( !strcmp(sval, "NAME") ||
-                                    !strcmp(sval, "DESC") ||
-                                    !strcmp(sval, "OBSOLETE") ||
-                                    !strcmp(sval, "SUP") ||
-                                    !strcmp(sval, "EQUALITY") ||
-                                    !strcmp(sval, "ORDERING") ||
-                                    !strcmp(sval, "SUBSTR") ||
-                                    !strcmp(sval, "SYNTAX") ||
-                                    !strcmp(sval, "SINGLE-VALUE") ||
-                                    !strcmp(sval, "COLLECTIVE") ||
-                                    !strcmp(sval, "NO-USER-MODIFICATION") ||
-                                    !strcmp(sval, "USAGE") ||
-                                    !strncmp(sval, "X-", 2) ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "SUP") ||
+                                    !strcasecmp(sval, "EQUALITY") ||
+                                    !strcasecmp(sval, "ORDERING") ||
+                                    !strcasecmp(sval, "SUBSTR") ||
+                                    !strcasecmp(sval, "SYNTAX") ||
+                                    !strcasecmp(sval, "SINGLE-VALUE") ||
+                                    !strcasecmp(sval, "COLLECTIVE") ||
+                                    !strcasecmp(sval, "NO-USER-MODIFICATION") ||
+                                    !strcasecmp(sval, "USAGE") ||
+                                    !strncasecmp(sval, "X-", 2) )
+                               {
                                        /* Missing OID, backtrack */
                                        ss = savepos;
                                } else if ( flags
-                                       & LDAP_SCHEMA_ALLOW_OID_MACRO) {
+                                       & LDAP_SCHEMA_ALLOW_OID_MACRO)
+                               {
                                        /* Non-numerical OID ... */
                                        int len = ss-savepos;
                                        at->at_oid = LDAP_MALLOC(len+1);
@@ -2072,13 +2148,13 @@ ldap_str2attributetype( LDAP_CONST char * s,
                switch (kind) {
                case TK_EOS:
                        *code = LDAP_SCHERR_NORIGHTPAREN;
-                       *errp = ss;
+                       *errp = EndOfInput;
                        ldap_attributetype_free(at);
                        return NULL;
                case TK_RIGHTPAREN:
                        return at;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2095,7 +2171,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2115,7 +2191,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                }
                                at->at_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2126,7 +2202,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                at->at_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"SUP") ) {
+                       } else if ( !strcasecmp(sval,"SUP") ) {
                                LDAP_FREE(sval);
                                if ( seen_sup ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2141,7 +2217,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"EQUALITY") ) {
+                       } else if ( !strcasecmp(sval,"EQUALITY") ) {
                                LDAP_FREE(sval);
                                if ( seen_equality ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2156,7 +2232,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"ORDERING") ) {
+                       } else if ( !strcasecmp(sval,"ORDERING") ) {
                                LDAP_FREE(sval);
                                if ( seen_ordering ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2171,7 +2247,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"SUBSTR") ) {
+                       } else if ( !strcasecmp(sval,"SUBSTR") ) {
                                LDAP_FREE(sval);
                                if ( seen_substr ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2186,7 +2262,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                        ldap_attributetype_free(at);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"SYNTAX") ) {
+                       } else if ( !strcasecmp(sval,"SYNTAX") ) {
                                LDAP_FREE(sval);
                                if ( seen_syntax ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2230,7 +2306,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                    }
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"SINGLE-VALUE") ) {
+                       } else if ( !strcasecmp(sval,"SINGLE-VALUE") ) {
                                LDAP_FREE(sval);
                                if ( at->at_single_value ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2240,7 +2316,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                }
                                at->at_single_value = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"COLLECTIVE") ) {
+                       } else if ( !strcasecmp(sval,"COLLECTIVE") ) {
                                LDAP_FREE(sval);
                                if ( at->at_collective ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2250,7 +2326,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                }
                                at->at_collective = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"NO-USER-MODIFICATION") ) {
+                       } else if ( !strcasecmp(sval,"NO-USER-MODIFICATION") ) {
                                LDAP_FREE(sval);
                                if ( at->at_no_user_mod ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2260,7 +2336,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
                                }
                                at->at_no_user_mod = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"USAGE") ) {
+                       } else if ( !strcasecmp(sval,"USAGE") ) {
                                LDAP_FREE(sval);
                                if ( seen_usage ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2336,6 +2412,7 @@ ldap_str2attributetype( LDAP_CONST char * s,
 void
 ldap_objectclass_free(LDAPObjectClass * oc)
 {
+       if (!oc) return;
        LDAP_FREE(oc->oc_oid);
        if (oc->oc_names) LDAP_VFREE(oc->oc_names);
        if (oc->oc_desc) LDAP_FREE(oc->oc_desc);
@@ -2352,7 +2429,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -2405,16 +2482,16 @@ ldap_str2objectclass( LDAP_CONST char * s,
                        ss = savepos;
                        kind = get_token(&ss,&sval);
                        if ( kind == TK_BAREWORD ) {
-                               if ( !strcmp(sval, "NAME") ||
-                                    !strcmp(sval, "DESC") ||
-                                    !strcmp(sval, "OBSOLETE") ||
-                                    !strcmp(sval, "SUP") ||
-                                    !strcmp(sval, "ABSTRACT") ||
-                                    !strcmp(sval, "STRUCTURAL") ||
-                                    !strcmp(sval, "AUXILIARY") ||
-                                    !strcmp(sval, "MUST") ||
-                                    !strcmp(sval, "MAY") ||
-                                    !strncmp(sval, "X-", 2) ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "SUP") ||
+                                    !strcasecmp(sval, "ABSTRACT") ||
+                                    !strcasecmp(sval, "STRUCTURAL") ||
+                                    !strcasecmp(sval, "AUXILIARY") ||
+                                    !strcasecmp(sval, "MUST") ||
+                                    !strcasecmp(sval, "MAY") ||
+                                    !strncasecmp(sval, "X-", 2) ) {
                                        /* Missing OID, backtrack */
                                        ss = savepos;
                                } else if ( flags &
@@ -2427,6 +2504,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                }
                        }
                        LDAP_FREE(sval);
+                       *code = 0;
                } else {
                        *errp = ss;
                        ldap_objectclass_free(oc);
@@ -2444,13 +2522,13 @@ ldap_str2objectclass( LDAP_CONST char * s,
                switch (kind) {
                case TK_EOS:
                        *code = LDAP_SCHERR_NORIGHTPAREN;
-                       *errp = ss;
+                       *errp = EndOfInput;
                        ldap_objectclass_free(oc);
                        return NULL;
                case TK_RIGHTPAREN:
                        return oc;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2467,7 +2545,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2487,7 +2565,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                }
                                oc->oc_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2498,7 +2576,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                oc->oc_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"SUP") ) {
+                       } else if ( !strcasecmp(sval,"SUP") ) {
                                LDAP_FREE(sval);
                                if ( seen_sup ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2510,12 +2588,13 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                oc->oc_sup_oids = parse_oids(&ss,
                                                             code,
                                                             flags);
-                               if ( !oc->oc_sup_oids ) {
+                               if ( !oc->oc_sup_oids && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"ABSTRACT") ) {
+                               *code = 0;
+                       } else if ( !strcasecmp(sval,"ABSTRACT") ) {
                                LDAP_FREE(sval);
                                if ( seen_kind ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2526,7 +2605,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                seen_kind = 1;
                                oc->oc_kind = LDAP_SCHEMA_ABSTRACT;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"STRUCTURAL") ) {
+                       } else if ( !strcasecmp(sval,"STRUCTURAL") ) {
                                LDAP_FREE(sval);
                                if ( seen_kind ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2537,7 +2616,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                seen_kind = 1;
                                oc->oc_kind = LDAP_SCHEMA_STRUCTURAL;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"AUXILIARY") ) {
+                       } else if ( !strcasecmp(sval,"AUXILIARY") ) {
                                LDAP_FREE(sval);
                                if ( seen_kind ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2548,7 +2627,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                seen_kind = 1;
                                oc->oc_kind = LDAP_SCHEMA_AUXILIARY;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MUST") ) {
+                       } else if ( !strcasecmp(sval,"MUST") ) {
                                LDAP_FREE(sval);
                                if ( seen_must ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2558,13 +2637,14 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                }
                                seen_must = 1;
                                oc->oc_at_oids_must = parse_oids(&ss,code,0);
-                               if ( !oc->oc_at_oids_must ) {
+                               if ( !oc->oc_at_oids_must && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
+                               *code = 0;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MAY") ) {
+                       } else if ( !strcasecmp(sval,"MAY") ) {
                                LDAP_FREE(sval);
                                if ( seen_may ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2574,15 +2654,17 @@ ldap_str2objectclass( LDAP_CONST char * s,
                                }
                                seen_may = 1;
                                oc->oc_at_oids_may = parse_oids(&ss,code,0);
-                               if ( !oc->oc_at_oids_may ) {
+                               if ( !oc->oc_at_oids_may && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_objectclass_free(oc);
                                        return NULL;
                                }
+                               *code = 0;
                                parse_whsp(&ss);
                        } else if ( sval[0] == 'X' && sval[1] == '-' ) {
                                /* Should be parse_qdstrings */
                                ext_vals = parse_qdescrs(&ss, code);
+                               *code = 0;
                                if ( !ext_vals ) {
                                        *errp = ss;
                                        ldap_objectclass_free(oc);
@@ -2617,6 +2699,7 @@ ldap_str2objectclass( LDAP_CONST char * s,
 void
 ldap_contentrule_free(LDAPContentRule * cr)
 {
+       if (!cr) return;
        LDAP_FREE(cr->cr_oid);
        if (cr->cr_names) LDAP_VFREE(cr->cr_names);
        if (cr->cr_desc) LDAP_FREE(cr->cr_desc);
@@ -2634,7 +2717,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -2677,9 +2760,36 @@ ldap_str2contentrule( LDAP_CONST char * s,
        savepos = ss;
        cr->cr_oid = ldap_int_parse_numericoid(&ss,code,0);
        if ( !cr->cr_oid ) {
-               *errp = ss;
-               ldap_contentrule_free(cr);
-               return NULL;
+               if ( (flags & LDAP_SCHEMA_ALLOW_ALL) && (ss == savepos) ) {
+                       /* Backtracking */
+                       ss = savepos;
+                       kind = get_token(&ss,&sval);
+                       if ( kind == TK_BAREWORD ) {
+                               if ( !strcasecmp(sval, "NAME") ||
+                                    !strcasecmp(sval, "DESC") ||
+                                    !strcasecmp(sval, "OBSOLETE") ||
+                                    !strcasecmp(sval, "AUX") ||
+                                    !strcasecmp(sval, "MUST") ||
+                                    !strcasecmp(sval, "MAY") ||
+                                    !strcasecmp(sval, "NOT") ||
+                                    !strncasecmp(sval, "X-", 2) ) {
+                                       /* Missing OID, backtrack */
+                                       ss = savepos;
+                               } else if ( flags &
+                                       LDAP_SCHEMA_ALLOW_OID_MACRO ) {
+                                       /* Non-numerical OID, ignore */
+                                       int len = ss-savepos;
+                                       cr->cr_oid = LDAP_MALLOC(len+1);
+                                       strncpy(cr->cr_oid, savepos, len);
+                                       cr->cr_oid[len] = 0;
+                               }
+                       }
+                       LDAP_FREE(sval);
+               } else {
+                       *errp = ss;
+                       ldap_contentrule_free(cr);
+                       return NULL;
+               }
        }
        parse_whsp(&ss);
 
@@ -2692,13 +2802,13 @@ ldap_str2contentrule( LDAP_CONST char * s,
                switch (kind) {
                case TK_EOS:
                        *code = LDAP_SCHERR_NORIGHTPAREN;
-                       *errp = ss;
+                       *errp = EndOfInput;
                        ldap_contentrule_free(cr);
                        return NULL;
                case TK_RIGHTPAREN:
                        return cr;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2715,7 +2825,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                        ldap_contentrule_free(cr);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2735,7 +2845,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                }
                                cr->cr_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2746,7 +2856,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                cr->cr_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"AUX") ) {
+                       } else if ( !strcasecmp(sval,"AUX") ) {
                                LDAP_FREE(sval);
                                if ( seen_aux ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2762,7 +2872,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                        return NULL;
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MUST") ) {
+                       } else if ( !strcasecmp(sval,"MUST") ) {
                                LDAP_FREE(sval);
                                if ( seen_must ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2772,13 +2882,13 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                }
                                seen_must = 1;
                                cr->cr_at_oids_must = parse_oids(&ss,code,0);
-                               if ( !cr->cr_at_oids_must ) {
+                               if ( !cr->cr_at_oids_must && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_contentrule_free(cr);
                                        return NULL;
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MAY") ) {
+                       } else if ( !strcasecmp(sval,"MAY") ) {
                                LDAP_FREE(sval);
                                if ( seen_may ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2788,13 +2898,13 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                }
                                seen_may = 1;
                                cr->cr_at_oids_may = parse_oids(&ss,code,0);
-                               if ( !cr->cr_at_oids_may ) {
+                               if ( !cr->cr_at_oids_may && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_contentrule_free(cr);
                                        return NULL;
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"NOT") ) {
+                       } else if ( !strcasecmp(sval,"NOT") ) {
                                LDAP_FREE(sval);
                                if ( seen_not ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2804,7 +2914,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
                                }
                                seen_not = 1;
                                cr->cr_at_oids_not = parse_oids(&ss,code,0);
-                               if ( !cr->cr_at_oids_not ) {
+                               if ( !cr->cr_at_oids_not && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_contentrule_free(cr);
                                        return NULL;
@@ -2847,6 +2957,7 @@ ldap_str2contentrule( LDAP_CONST char * s,
 void
 ldap_structurerule_free(LDAPStructureRule * sr)
 {
+       if (!sr) return;
        if (sr->sr_names) LDAP_VFREE(sr->sr_names);
        if (sr->sr_desc) LDAP_FREE(sr->sr_desc);
        if (sr->sr_nameform) LDAP_FREE(sr->sr_nameform);
@@ -2861,14 +2972,14 @@ ldap_str2structurerule( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind, ret;
+       tk_t kind;
+       int ret;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
        int seen_desc = 0;
        int seen_obsolete = 0;
        int seen_nameform = 0;
-       int seen_ruleids = 0;
        LDAPStructureRule * sr;
        char ** ext_vals;
        const char * savepos;
@@ -2917,7 +3028,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
                switch (kind) {
                case TK_EOS:
                        *code = LDAP_SCHERR_NORIGHTPAREN;
-                       *errp = ss;
+                       *errp = EndOfInput;
                        ldap_structurerule_free(sr);
                        return NULL;
                case TK_RIGHTPAREN:
@@ -2928,7 +3039,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
                        }
                        return sr;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2945,7 +3056,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
                                        ldap_structurerule_free(sr);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2965,7 +3076,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
                                }
                                sr->sr_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -2976,7 +3087,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                sr->sr_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"FORM") ) {
+                       } else if ( !strcasecmp(sval,"FORM") ) {
                                LDAP_FREE(sval);
                                if ( seen_nameform ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3029,6 +3140,7 @@ ldap_str2structurerule( LDAP_CONST char * s,
 void
 ldap_nameform_free(LDAPNameForm * nf)
 {
+       if (!nf) return;
        LDAP_FREE(nf->nf_oid);
        if (nf->nf_names) LDAP_VFREE(nf->nf_names);
        if (nf->nf_desc) LDAP_FREE(nf->nf_desc);
@@ -3045,7 +3157,7 @@ ldap_str2nameform( LDAP_CONST char * s,
        LDAP_CONST char ** errp,
        LDAP_CONST unsigned flags )
 {
-       int kind;
+       tk_t kind;
        const char * ss = s;
        char * sval;
        int seen_name = 0;
@@ -3106,7 +3218,7 @@ ldap_str2nameform( LDAP_CONST char * s,
                switch (kind) {
                case TK_EOS:
                        *code = LDAP_SCHERR_NORIGHTPAREN;
-                       *errp = ss;
+                       *errp = EndOfInput;
                        ldap_nameform_free(nf);
                        return NULL;
                case TK_RIGHTPAREN:
@@ -3117,7 +3229,7 @@ ldap_str2nameform( LDAP_CONST char * s,
                        }
                        return nf;
                case TK_BAREWORD:
-                       if ( !strcmp(sval,"NAME") ) {
+                       if ( !strcasecmp(sval,"NAME") ) {
                                LDAP_FREE(sval);
                                if ( seen_name ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3134,7 +3246,7 @@ ldap_str2nameform( LDAP_CONST char * s,
                                        ldap_nameform_free(nf);
                                        return NULL;
                                }
-                       } else if ( !strcmp(sval,"DESC") ) {
+                       } else if ( !strcasecmp(sval,"DESC") ) {
                                LDAP_FREE(sval);
                                if ( seen_desc ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3154,7 +3266,7 @@ ldap_str2nameform( LDAP_CONST char * s,
                                }
                                nf->nf_desc = sval;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"OBSOLETE") ) {
+                       } else if ( !strcasecmp(sval,"OBSOLETE") ) {
                                LDAP_FREE(sval);
                                if ( seen_obsolete ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3165,7 +3277,22 @@ ldap_str2nameform( LDAP_CONST char * s,
                                seen_obsolete = 1;
                                nf->nf_obsolete = LDAP_SCHEMA_YES;
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MUST") ) {
+                       } else if ( !strcasecmp(sval,"OC") ) {
+                               LDAP_FREE(sval);
+                               if ( seen_class ) {
+                                       *code = LDAP_SCHERR_DUPOPT;
+                                       *errp = ss;
+                                       ldap_nameform_free(nf);
+                                       return(NULL);
+                               }
+                               seen_class = 1;
+                               nf->nf_objectclass = parse_woid(&ss,code);
+                               if ( !nf->nf_objectclass ) {
+                                       *errp = ss;
+                                       ldap_nameform_free(nf);
+                                       return NULL;
+                               }
+                       } else if ( !strcasecmp(sval,"MUST") ) {
                                LDAP_FREE(sval);
                                if ( seen_must ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3175,13 +3302,13 @@ ldap_str2nameform( LDAP_CONST char * s,
                                }
                                seen_must = 1;
                                nf->nf_at_oids_must = parse_oids(&ss,code,0);
-                               if ( !nf->nf_at_oids_must ) {
+                               if ( !nf->nf_at_oids_must && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_nameform_free(nf);
                                        return NULL;
                                }
                                parse_whsp(&ss);
-                       } else if ( !strcmp(sval,"MAY") ) {
+                       } else if ( !strcasecmp(sval,"MAY") ) {
                                LDAP_FREE(sval);
                                if ( seen_may ) {
                                        *code = LDAP_SCHERR_DUPOPT;
@@ -3191,7 +3318,7 @@ ldap_str2nameform( LDAP_CONST char * s,
                                }
                                seen_may = 1;
                                nf->nf_at_oids_may = parse_oids(&ss,code,0);
-                               if ( !nf->nf_at_oids_may ) {
+                               if ( !nf->nf_at_oids_may && *code != LDAP_SUCCESS ) {
                                        *errp = ss;
                                        ldap_nameform_free(nf);
                                        return NULL;
@@ -3232,27 +3359,27 @@ ldap_str2nameform( LDAP_CONST char * s,
 }
 
 static char *const err2text[] = {
-       "Success",
-       "Out of memory",
-       "Unexpected token",
-       "Missing opening parenthesis",
-       "Missing closing parenthesis",
-       "Expecting digit",
-       "Expecting a name",
-       "Bad description",
-       "Bad superiors",
-       "Duplicate option",
-       "Unexpected end of data",
-       "Missing required field",
-       "Out of order field"
+       N_("Success"),
+       N_("Out of memory"),
+       N_("Unexpected token"),
+       N_("Missing opening parenthesis"),
+       N_("Missing closing parenthesis"),
+       N_("Expecting digit"),
+       N_("Expecting a name"),
+       N_("Bad description"),
+       N_("Bad superiors"),
+       N_("Duplicate option"),
+       N_("Unexpected end of data"),
+       N_("Missing required field"),
+       N_("Out of order field")
 };
 
 char *
 ldap_scherr2str(int code)
 {
        if ( code < 0 || code >= (int)(sizeof(err2text)/sizeof(char *)) ) {
-               return "Unknown error";
+               return _("Unknown error");
        } else {
-               return err2text[code];
+               return _(err2text[code]);
        }
 }