]> git.sur5r.net Git - openldap/blobdiff - libraries/libldap/url.c
Merge remote branch 'origin/mdb.master' into OPENLDAP_REL_ENG_2_4
[openldap] / libraries / libldap / url.c
index a0f7dab38dd136607e23ad42bd8e899ce5905ec2..083c37f5d5c4ef84313695468661d9029d33a9d6 100644 (file)
@@ -1,8 +1,8 @@
-/* LIBLDAP url.c -- LDAP URL (RFC 2255) related routines */
+/* LIBLDAP url.c -- LDAP URL (RFC 4516) related routines */
 /* $OpenLDAP$ */
 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
  *
- * Copyright 1998-2004 The OpenLDAP Foundation.
+ * Copyright 1998-2013 The OpenLDAP Foundation.
  * All rights reserved.
  *
  * Redistribution and use in source and binary forms, with or without
 
 /*
  *  LDAP URLs look like this:
- *    ldap[is]://host:port[/[dn[?[attributes][?[scope][?[filter][?exts]]]]]]
+ *    ldap[is]://host[:port][/[dn[?[attributes][?[scope][?[filter][?exts]]]]]]
  *
  *  where:
  *   attributes is a comma separated list
  *   scope is one of these three strings:  base one sub (default=base)
- *   filter is an string-represented filter as in RFC 2254
+ *   filter is an string-represented filter as in RFC 4515
  *
  *  e.g.,  ldap://host:port/dc=com?o,cn?base?(o=openldap)?extension
  *
@@ -37,6 +37,7 @@
 #include <stdio.h>
 
 #include <ac/stdlib.h>
+#include <ac/ctype.h>
 
 #include <ac/socket.h>
 #include <ac/string.h>
@@ -52,7 +53,7 @@ static const char* skip_url_prefix LDAP_P((
 
 int ldap_pvt_url_scheme2proto( const char *scheme )
 {
-       assert( scheme );
+       assert( scheme != NULL );
 
        if( scheme == NULL ) {
                return -1;
@@ -80,7 +81,7 @@ int ldap_pvt_url_scheme2proto( const char *scheme )
 
 int ldap_pvt_url_scheme_port( const char *scheme, int port )
 {
-       assert( scheme );
+       assert( scheme != NULL );
 
        if( port ) return port;
        if( scheme == NULL ) return port;
@@ -109,7 +110,7 @@ int ldap_pvt_url_scheme_port( const char *scheme, int port )
 int
 ldap_pvt_url_scheme2tls( const char *scheme )
 {
-       assert( scheme );
+       assert( scheme != NULL );
 
        if( scheme == NULL ) {
                return -1;
@@ -256,227 +257,539 @@ skip_url_prefix(
        return( NULL );
 }
 
-
-static int str2scope( const char *p )
+int
+ldap_pvt_scope2bv( int scope, struct berval *bv )
 {
-       if ( strcasecmp( p, "one" ) == 0 ) {
-               return LDAP_SCOPE_ONELEVEL;
+       switch ( scope ) {
+       case LDAP_SCOPE_BASE:
+               BER_BVSTR( bv, "base" );
+               break;
 
-       } else if ( strcasecmp( p, "onelevel" ) == 0 ) {
-               return LDAP_SCOPE_ONELEVEL;
+       case LDAP_SCOPE_ONELEVEL:
+               BER_BVSTR( bv, "one" );
+               break;
 
-       } else if ( strcasecmp( p, "base" ) == 0 ) {
-               return LDAP_SCOPE_BASE;
+       case LDAP_SCOPE_SUBTREE:
+               BER_BVSTR( bv, "sub" );
+               break;
 
-       } else if ( strcasecmp( p, "sub" ) == 0 ) {
-               return LDAP_SCOPE_SUBTREE;
+       case LDAP_SCOPE_SUBORDINATE:
+               BER_BVSTR( bv, "subordinate" );
+               break;
 
-       } else if ( strcasecmp( p, "subtree" ) == 0 ) {
-               return LDAP_SCOPE_SUBTREE;
+       default:
+               return LDAP_OTHER;
+       }
 
-#ifdef LDAP_SCOPE_SUBORDINATE
-       } else if ( strcasecmp( p, "subordinate" ) == 0 ) {
-               return LDAP_SCOPE_SUBORDINATE;
+       return LDAP_SUCCESS;
+}
 
-       } else if ( strcasecmp( p, "children" ) == 0 ) {
-               return LDAP_SCOPE_SUBORDINATE;
-#endif
+const char *
+ldap_pvt_scope2str( int scope )
+{
+       struct berval   bv;
+
+       if ( ldap_pvt_scope2bv( scope, &bv ) == LDAP_SUCCESS ) {
+               return bv.bv_val;
+       }
+
+       return NULL;
+}
+
+int
+ldap_pvt_bv2scope( struct berval *bv )
+{
+       static struct {
+               struct berval   bv;
+               int             scope;
+       }       v[] = {
+               { BER_BVC( "one" ),             LDAP_SCOPE_ONELEVEL },
+               { BER_BVC( "onelevel" ),        LDAP_SCOPE_ONELEVEL },
+               { BER_BVC( "base" ),            LDAP_SCOPE_BASE },
+               { BER_BVC( "sub" ),             LDAP_SCOPE_SUBTREE },
+               { BER_BVC( "subtree" ),         LDAP_SCOPE_SUBTREE },
+               { BER_BVC( "subord" ),          LDAP_SCOPE_SUBORDINATE },
+               { BER_BVC( "subordinate" ),     LDAP_SCOPE_SUBORDINATE },
+               { BER_BVC( "children" ),        LDAP_SCOPE_SUBORDINATE },
+               { BER_BVNULL,                   -1 }
+       };
+       int     i;
+
+       for ( i = 0; v[ i ].scope != -1; i++ ) {
+               if ( ber_bvstrcasecmp( bv, &v[ i ].bv ) == 0 ) {
+                       return v[ i ].scope;
+               }
        }
 
        return( -1 );
 }
 
-static int hex_escape( char *buf, const char *s, int list )
+int
+ldap_pvt_str2scope( const char *p )
 {
-       int i;
-       int pos;
-       static const char hex[] = "0123456789ABCDEF";
+       struct berval   bv;
 
-       if( s == NULL ) return 0;
+       ber_str2bv( p, 0, 0, &bv );
 
-       for( pos=0,i=0; s[i]; i++ ) {
-               int escape = 0;
-               switch( s[i] ) {
-                       case ',':
-                               escape = list;
-                               break;
-                       case '%':
-                       case '?':
-                       case ' ':
-                       case '<':
-                       case '>':
-                       case '"':
-                       case '#':
-                       case '{':
-                       case '}':
-                       case '|':
-                       case '\\':
-                       case '^':
-                       case '~':
-                       case '`':
-                       case '[':
-                       case ']':
+       return ldap_pvt_bv2scope( &bv );
+}
+
+static const char      hex[] = "0123456789ABCDEF";
+
+#define URLESC_NONE    0x0000U
+#define URLESC_COMMA   0x0001U
+#define URLESC_SLASH   0x0002U
+
+static int
+hex_escape_len( const char *s, unsigned list )
+{
+       int     len;
+
+       if ( s == NULL ) {
+               return 0;
+       }
+
+       for ( len = 0; s[0]; s++ ) {
+               switch ( s[0] ) {
+               /* RFC 2396: reserved */
+               case '?':
+                       len += 3;
+                       break;
+
+               case ',':
+                       if ( list & URLESC_COMMA ) {
+                               len += 3;
+                       } else {
+                               len++;
+                       }
+                       break;
+
+               case '/':
+                       if ( list & URLESC_SLASH ) {
+                               len += 3;
+                       } else {
+                               len++;
+                       }
+                       break;
+
+               case ';':
+               case ':':
+               case '@':
+               case '&':
+               case '=':
+               case '+':
+               case '$':
+
+               /* RFC 2396: unreserved mark */
+               case '-':
+               case '_':
+               case '.':
+               case '!':
+               case '~':
+               case '*':
+               case '\'':
+               case '(':
+               case ')':
+                       len++;
+                       break;
+                       
+               /* RFC 2396: unreserved alphanum */
+               default:
+                       if ( !isalnum( (unsigned char) s[0] ) ) {
+                               len += 3;
+                       } else {
+                               len++;
+                       }
+                       break;
+               }
+       }
+
+       return len;
+}
+
+static int
+hex_escape( char *buf, int len, const char *s, unsigned list )
+{
+       int     i;
+       int     pos;
+
+       if ( s == NULL ) {
+               return 0;
+       }
+
+       for ( pos = 0, i = 0; s[i] && pos < len; i++ ) {
+               int     escape = 0;
+
+               switch ( s[i] ) {
+               /* RFC 2396: reserved */
+               case '?':
+                       escape = 1;
+                       break;
+
+               case ',':
+                       if ( list & URLESC_COMMA ) {
                                escape = 1;
-                               break;
+                       }
+                       break;
+
+               case '/':
+                       if ( list & URLESC_SLASH ) {
+                               escape = 1;
+                       }
+                       break;
 
-                       default:
-                               escape = s[i] < 0x20 || 0x1f >= s[i];
+               case ';':
+               case ':':
+               case '@':
+               case '&':
+               case '=':
+               case '+':
+               case '$':
+
+               /* RFC 2396: unreserved mark */
+               case '-':
+               case '_':
+               case '.':
+               case '!':
+               case '~':
+               case '*':
+               case '\'':
+               case '(':
+               case ')':
+                       break;
+                       
+               /* RFC 2396: unreserved alphanum */
+               default:
+                       if ( !isalnum( (unsigned char) s[i] ) ) {
+                               escape = 1;
+                       }
+                       break;
                }
 
-               if( escape ) {
+               if ( escape ) {
                        buf[pos++] = '%';
                        buf[pos++] = hex[ (s[i] >> 4) & 0x0f ];
                        buf[pos++] = hex[ s[i] & 0x0f ];
+
                } else {
                        buf[pos++] = s[i];
                }
        }
 
        buf[pos] = '\0';
+
        return pos;
 }
 
-static int hex_escape_args( char *buf, char **s )
+static int
+hex_escape_len_list( char **s, unsigned flags )
 {
-       int pos;
-       int i;
+       int     len;
+       int     i;
+
+       if ( s == NULL ) {
+               return 0;
+       }
+
+       len = 0;
+       for ( i = 0; s[i] != NULL; i++ ) {
+               if ( len ) {
+                       len++;
+               }
+               len += hex_escape_len( s[i], flags );
+       }
+
+       return len;
+}
 
-       if( s == NULL ) return 0;
+static int
+hex_escape_list( char *buf, int len, char **s, unsigned flags )
+{
+       int     pos;
+       int     i;
+
+       if ( s == NULL ) {
+               return 0;
+       }
 
        pos = 0;
-       for( i=0; s[i] != NULL; i++ ) {
-               if( pos ) {
+       for ( i = 0; s[i] != NULL; i++ ) {
+               int     curlen;
+
+               if ( pos ) {
                        buf[pos++] = ',';
+                       len--;
                }
-               pos += hex_escape( &buf[pos], s[i], 1 );
+               curlen = hex_escape( &buf[pos], len, s[i], flags );
+               len -= curlen;
+               pos += curlen;
        }
 
        return pos;
 }
 
-char * ldap_url_desc2str( LDAPURLDesc *u )
+static int
+desc2str_len( LDAPURLDesc *u )
 {
-       char *s;
-       int i;
-       int sep = 0;
-       int sofar;
-       size_t len = 0;
-       if( u == NULL ) return NULL;
-
-       if( u->lud_exts ) {
-               for( i=0; u->lud_exts[i]; i++ ) {
-                       len += strlen( u->lud_exts[i] ) + 1;
-               }
-               if( !sep ) sep = 5;
+       int             sep = 0;
+       int             len = 0;
+       int             is_ipc = 0;
+       struct berval   scope;
+
+       if ( u == NULL || u->lud_scheme == NULL ) {
+               return -1;
        }
 
-       if( u->lud_filter ) {
-               len += strlen( u->lud_filter );
-               if( !sep ) sep = 4;
+       if ( !strcmp( "ldapi", u->lud_scheme )) {
+               is_ipc = 1;
        }
-       if ( len ) len++; /* ? */
 
-       switch( u->lud_scope ) {
-               case LDAP_SCOPE_BASE:
-               case LDAP_SCOPE_ONELEVEL:
-               case LDAP_SCOPE_SUBTREE:
-#ifdef LDAP_FEATURE_SUBORDINATE_SCOPE
-               case LDAP_SCOPE_SUBORDINATE:
-#endif
-                       len += sizeof("subordinate");
-                       if( !sep ) sep = 3;
-                       break;
+       if ( u->lud_exts ) {
+               len += hex_escape_len_list( u->lud_exts, URLESC_COMMA );
+               if ( !sep ) {
+                       sep = 5;
+               }
+       }
 
-               default:
-                       if ( len ) len++; /* ? */
+       if ( u->lud_filter ) {
+               len += hex_escape_len( u->lud_filter, URLESC_NONE );
+               if ( !sep ) {
+                       sep = 4;
+               }
+       }
+
+       if ( ldap_pvt_scope2bv( u->lud_scope, &scope ) == LDAP_SUCCESS ) {
+               len += scope.bv_len;
+               if ( !sep ) {
+                       sep = 3;
+               }
        }
 
-       if( u->lud_attrs ) {
-               for( i=0; u->lud_attrs[i]; i++ ) {
-                       len += strlen( u->lud_attrs[i] ) + 1;
+       if ( u->lud_attrs ) {
+               len += hex_escape_len_list( u->lud_attrs, URLESC_NONE );
+               if ( !sep ) {
+                       sep = 2;
                }
-               if( !sep ) sep = 2;
-       } else if ( len ) len++; /* ? */
+       }
 
-       if( u->lud_dn ) {
-               len += strlen( u->lud_dn ) + 1;
-               if( !sep ) sep = 1;
+       if ( u->lud_dn && u->lud_dn[0] ) {
+               len += hex_escape_len( u->lud_dn, URLESC_NONE );
+               if ( !sep ) {
+                       sep = 1;
+               }
        };
 
-       if( u->lud_port ) {
-               len += sizeof(":65535") - 1;
+       len += sep;
+
+       if ( u->lud_port ) {
+               unsigned p = u->lud_port;
+               if ( p > 65535 )
+                       return -1;
+
+               len += (p > 999 ? 5 + (p > 9999) : p > 99 ? 4 : 2 + (p > 9));
        }
 
-       if( u->lud_host ) {
-               len+=strlen( u->lud_host );
+       if ( u->lud_host && u->lud_host[0] ) {
+               char *ptr;
+               len += hex_escape_len( u->lud_host, URLESC_SLASH );
+               if ( !is_ipc && ( ptr = strchr( u->lud_host, ':' ))) {
+                       if ( strchr( ptr+1, ':' ))
+                               len += 2;       /* IPv6, [] */
+               }
        }
 
-       len += strlen( u->lud_scheme ) + sizeof("://");
+       len += strlen( u->lud_scheme ) + STRLENOF( "://" );
 
-       /* allocate enough to hex escape everything -- overkill */
-       s = LDAP_MALLOC( 3*len );
+       return len;
+}
+
+static int
+desc2str( LDAPURLDesc *u, char *s, int len )
+{
+       int             i;
+       int             sep = 0;
+       int             sofar = 0;
+       int             is_v6 = 0;
+       int             is_ipc = 0;
+       struct berval   scope = BER_BVNULL;
+       char            *ptr;
+
+       if ( u == NULL ) {
+               return -1;
+       }
+
+       if ( s == NULL ) {
+               return -1;
+       }
+
+       if ( u->lud_scheme && !strcmp( "ldapi", u->lud_scheme )) {
+               is_ipc = 1;
+       }
+
+       ldap_pvt_scope2bv( u->lud_scope, &scope );
+
+       if ( u->lud_exts ) {
+               sep = 5;
+       } else if ( u->lud_filter ) {
+               sep = 4;
+       } else if ( !BER_BVISEMPTY( &scope ) ) {
+               sep = 3;
+       } else if ( u->lud_attrs ) {
+               sep = 2;
+       } else if ( u->lud_dn && u->lud_dn[0] ) {
+               sep = 1;
+       }
 
-       if( s == NULL ) return NULL;
+       if ( !is_ipc && u->lud_host && ( ptr = strchr( u->lud_host, ':' ))) {
+               if ( strchr( ptr+1, ':' ))
+                       is_v6 = 1;
+       }
+
+       if ( u->lud_port ) {
+               sofar = sprintf( s, "%s://%s%s%s:%d", u->lud_scheme,
+                               is_v6 ? "[" : "",
+                               u->lud_host ? u->lud_host : "",
+                               is_v6 ? "]" : "",
+                               u->lud_port );
+               len -= sofar;
 
-       if( u->lud_port ) {
-               sprintf( s,     "%s://%s:%d%n", u->lud_scheme,
-                       u->lud_host, u->lud_port, &sofar );
        } else {
-               sprintf( s,     "%s://%s%n", u->lud_scheme,
-                       u->lud_host, &sofar );
+               sofar = sprintf( s, "%s://", u->lud_scheme );
+               len -= sofar;
+               if ( u->lud_host && u->lud_host[0] ) {
+                       if ( is_v6 ) {
+                               s[sofar++] = '[';
+                               len--;
+                       }
+                       i = hex_escape( &s[sofar], len, u->lud_host, URLESC_SLASH );
+                       sofar += i;
+                       len -= i;
+                       if ( is_v6 ) {
+                               s[sofar++] = ']';
+                               len--;
+                       }
+               }
        }
-       
-       if( sep < 1 ) goto done;
+
+       assert( len >= 0 );
+
+       if ( sep < 1 ) {
+               goto done;
+       }
+
        s[sofar++] = '/';
+       len--;
 
-       sofar += hex_escape( &s[sofar], u->lud_dn, 0 );
+       assert( len >= 0 );
 
-       if( sep < 2 ) goto done;
+       if ( u->lud_dn && u->lud_dn[0] ) {
+               i = hex_escape( &s[sofar], len, u->lud_dn, URLESC_NONE );
+               sofar += i;
+               len -= i;
+
+               assert( len >= 0 );
+       }
+
+       if ( sep < 2 ) {
+               goto done;
+       }
        s[sofar++] = '?';
+       len--;
+
+       assert( len >= 0 );
 
-       sofar += hex_escape_args( &s[sofar], u->lud_attrs );
+       i = hex_escape_list( &s[sofar], len, u->lud_attrs, URLESC_NONE );
+       sofar += i;
+       len -= i;
 
-       if( sep < 3 ) goto done;
+       assert( len >= 0 );
+
+       if ( sep < 3 ) {
+               goto done;
+       }
        s[sofar++] = '?';
+       len--;
 
-       switch( u->lud_scope ) {
-       case LDAP_SCOPE_BASE:
-               strcpy( &s[sofar], "base" );
-               sofar += sizeof("base") - 1;
-               break;
-       case LDAP_SCOPE_ONELEVEL:
-               strcpy( &s[sofar], "one" );
-               sofar += sizeof("one") - 1;
-               break;
-       case LDAP_SCOPE_SUBTREE:
-               strcpy( &s[sofar], "sub" );
-               sofar += sizeof("sub") - 1;
-               break;
-#ifdef LDAP_FEATURE_SUBORDINATE_SCOPE
-       case LDAP_SCOPE_SUBORDINATE:
-               strcpy( &s[sofar], "children" );
-               sofar += sizeof("children") - 1;
-               break;
-#endif
+       assert( len >= 0 );
+
+       if ( !BER_BVISNULL( &scope ) ) {
+               strcpy( &s[sofar], scope.bv_val );
+               sofar += scope.bv_len;
+               len -= scope.bv_len;
        }
 
-       if( sep < 4 ) goto done;
+       assert( len >= 0 );
+
+       if ( sep < 4 ) {
+               goto done;
+       }
        s[sofar++] = '?';
+       len--;
+
+       assert( len >= 0 );
 
-       sofar += hex_escape( &s[sofar], u->lud_filter, 0 );
+       i = hex_escape( &s[sofar], len, u->lud_filter, URLESC_NONE );
+       sofar += i;
+       len -= i;
 
-       if( sep < 5 ) goto done;
+       assert( len >= 0 );
+
+       if ( sep < 5 ) {
+               goto done;
+       }
        s[sofar++] = '?';
+       len--;
+
+       assert( len >= 0 );
 
-       sofar += hex_escape_args( &s[sofar], u->lud_exts );
+       i = hex_escape_list( &s[sofar], len, u->lud_exts, URLESC_COMMA );
+       sofar += i;
+       len -= i;
+
+       assert( len >= 0 );
 
 done:
-       s[sofar] = '\0';
+       if ( len < 0 ) {
+               return -1;
+       }
+
+       return sofar;
+}
+
+char *
+ldap_url_desc2str( LDAPURLDesc *u )
+{
+       int     len;
+       char    *s;
+
+       if ( u == NULL ) {
+               return NULL;
+       }
+
+       len = desc2str_len( u );
+       if ( len < 0 ) {
+               return NULL;
+       }
+       
+       /* allocate enough to hex escape everything -- overkill */
+       s = LDAP_MALLOC( len + 1 );
+
+       if ( s == NULL ) {
+               return NULL;
+       }
+
+       if ( desc2str( u, s, len ) != len ) {
+               LDAP_FREE( s );
+               return NULL;
+       }
+
+       s[len] = '\0';
+
        return s;
 }
 
 int
-ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
+ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp, unsigned flags )
 {
 /*
  *  Pick apart the pieces of an LDAP URL.
@@ -484,11 +797,13 @@ ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
 
        LDAPURLDesc     *ludp;
        char    *p, *q, *r;
-       int             i, enclosed;
+       int             i, enclosed, proto, is_v6 = 0;
        const char *scheme = NULL;
        const char *url_tmp;
        char *url;
 
+       int     check_dn = 1;
+
        if( url_in == NULL || ludpp == NULL ) {
                return LDAP_URL_ERR_PARAM;
        }
@@ -499,11 +814,7 @@ ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
         * because a call to LDAP_INT_GLOBAL_OPT() will try to allocate
         * the options and cause infinite recursion
         */
-#ifdef NEW_LOGGING
-       LDAP_LOG ( OPERATION, ENTRY, "ldap_url_parse_ext(%s)\n", url_in, 0, 0 );
-#else
        Debug( LDAP_DEBUG_TRACE, "ldap_url_parse_ext(%s)\n", url_in, 0, 0 );
-#endif
 #endif
 
        *ludpp = NULL;  /* pessimistic */
@@ -514,7 +825,12 @@ ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
                return LDAP_URL_ERR_BADSCHEME;
        }
 
-       assert( scheme );
+       assert( scheme != NULL );
+
+       proto = ldap_pvt_url_scheme2proto( scheme );
+       if ( proto == -1 ) {
+               return LDAP_URL_ERR_BADSCHEME;
+       }
 
        /* make working copy of the remainder of the URL */
        url = LDAP_STRDUP( url_tmp );
@@ -546,7 +862,7 @@ ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
        ludp->lud_port = 0;
        ludp->lud_dn = NULL;
        ludp->lud_attrs = NULL;
-       ludp->lud_scope = LDAP_SCOPE_DEFAULT;
+       ludp->lud_scope = ( flags & LDAP_PVT_URL_PARSE_NODEF_SCOPE ) ? LDAP_SCOPE_BASE : LDAP_SCOPE_DEFAULT;
        ludp->lud_filter = NULL;
        ludp->lud_exts = NULL;
 
@@ -560,50 +876,83 @@ ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
 
        /* scan forward for '/' that marks end of hostport and begin. of dn */
        p = strchr( url, '/' );
+       q = NULL;
 
        if( p != NULL ) {
                /* terminate hostport; point to start of dn */
                *p++ = '\0';
+       } else {
+               /* check for Novell kludge, see below */
+               p = strchr( url, '?' );
+               if ( p ) {
+                       *p++ = '\0';
+                       q = p;
+                       p = NULL;
+               }
        }
 
-       /* IPv6 syntax with [ip address]:port */
-       if ( *url == '[' ) {
-               r = strchr( url, ']' );
-               if ( r == NULL ) {
-                       LDAP_FREE( url );
-                       ldap_free_urldesc( ludp );
-                       return LDAP_URL_ERR_BADURL;
+       if ( proto != LDAP_PROTO_IPC ) {
+               /* IPv6 syntax with [ip address]:port */
+               if ( *url == '[' ) {
+                       r = strchr( url, ']' );
+                       if ( r == NULL ) {
+                               LDAP_FREE( url );
+                               ldap_free_urldesc( ludp );
+                               return LDAP_URL_ERR_BADURL;
+                       }
+                       *r++ = '\0';
+                       q = strchr( r, ':' );
+                       if ( q && q != r ) {
+                               LDAP_FREE( url );
+                               ldap_free_urldesc( ludp );
+                               return LDAP_URL_ERR_BADURL;
+                       }
+                       is_v6 = 1;
+               } else {
+                       q = strchr( url, ':' );
                }
-               *r++ = '\0';
-               q = strchr( r, ':' );
-       } else {
-               q = strchr( url, ':' );
-       }
 
-       if ( q != NULL ) {
-               char    *next;
+               if ( q != NULL ) {
+                       char    *next;
 
-               *q++ = '\0';
-               ldap_pvt_hex_unescape( q );
+                       *q++ = '\0';
+                       ldap_pvt_hex_unescape( q );
 
-               if( *q == '\0' ) {
-                       LDAP_FREE( url );
-                       ldap_free_urldesc( ludp );
-                       return LDAP_URL_ERR_BADURL;
+                       if( *q == '\0' ) {
+                               LDAP_FREE( url );
+                               ldap_free_urldesc( ludp );
+                               return LDAP_URL_ERR_BADURL;
+                       }
+
+                       ludp->lud_port = strtol( q, &next, 10 );
+                       if ( next == q || next[0] != '\0' ) {
+                               LDAP_FREE( url );
+                               ldap_free_urldesc( ludp );
+                               return LDAP_URL_ERR_BADURL;
+                       }
+                       /* check for Novell kludge */
+                       if ( !p ) {
+                               if ( *next != '\0' ) {
+                                       q = &next[1];
+                               } else {
+                                       q = NULL;
+                               }
+                       }
                }
 
-               ludp->lud_port = strtol( q, &next, 10 );
-               if ( next == NULL || next[0] != '\0' ) {
-                       LDAP_FREE( url );
-                       ldap_free_urldesc( ludp );
-                       return LDAP_URL_ERR_BADURL;
+               if ( ( flags & LDAP_PVT_URL_PARSE_DEF_PORT ) && ludp->lud_port == 0 ) {
+                       if ( strcmp( ludp->lud_scheme, "ldaps" ) == 0 ) {
+                               ludp->lud_port = LDAPS_PORT;
+                       } else {
+                               ludp->lud_port = LDAP_PORT;
+                       }
                }
        }
 
        ldap_pvt_hex_unescape( url );
 
        /* If [ip address]:port syntax, url is [ip and we skip the [ */
-       ludp->lud_host = LDAP_STRDUP( url + ( *url == '[' ) );
+       ludp->lud_host = LDAP_STRDUP( url + is_v6 );
 
        if( ludp->lud_host == NULL ) {
                LDAP_FREE( url );
@@ -611,6 +960,14 @@ ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
                return LDAP_URL_ERR_MEM;
        }
 
+       if ( ( flags & LDAP_PVT_URL_PARSE_NOEMPTY_HOST )
+               && ludp->lud_host != NULL
+               && *ludp->lud_host == '\0' )
+       {
+               LDAP_FREE( ludp->lud_host );
+               ludp->lud_host = NULL;
+       }
+
        /*
         * Kludge.  ldap://111.222.333.444:389??cn=abc,o=company
         *
@@ -620,24 +977,25 @@ ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
         * but we need to account for it. Fortunately it can't be confused with
         * anything real.
         */
-       if( (p == NULL) && (q != NULL) && ((q = strchr( q, '?')) != NULL)) {
-               q++;            
+       if( (p == NULL) && (q != NULL) && (*q == '?') ) {
                /* ? immediately followed by question */
-               if( *q == '?') {
-                       q++;
-                       if( *q != '\0' ) {
-                               /* parse dn part */
-                               ldap_pvt_hex_unescape( q );
-                               ludp->lud_dn = LDAP_STRDUP( q );
-                       } else {
-                               ludp->lud_dn = LDAP_STRDUP( "" );
-                       }
+               q++;
+               if( *q != '\0' ) {
+                       /* parse dn part */
+                       ldap_pvt_hex_unescape( q );
+                       ludp->lud_dn = LDAP_STRDUP( q );
 
-                       if( ludp->lud_dn == NULL ) {
-                               LDAP_FREE( url );
-                               ldap_free_urldesc( ludp );
-                               return LDAP_URL_ERR_MEM;
-                       }
+               } else if ( !( flags & LDAP_PVT_URL_PARSE_NOEMPTY_DN ) ) {
+                       ludp->lud_dn = LDAP_STRDUP( "" );
+
+               } else {
+                       check_dn = 0;
+               }
+
+               if ( check_dn && ludp->lud_dn == NULL ) {
+                       LDAP_FREE( url );
+                       ldap_free_urldesc( ludp );
+                       return LDAP_URL_ERR_MEM;
                }
        }
 
@@ -659,11 +1017,15 @@ ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
                /* parse dn part */
                ldap_pvt_hex_unescape( p );
                ludp->lud_dn = LDAP_STRDUP( p );
-       } else {
+
+       } else if ( !( flags & LDAP_PVT_URL_PARSE_NOEMPTY_DN ) ) {
                ludp->lud_dn = LDAP_STRDUP( "" );
+
+       } else {
+               check_dn = 0;
        }
 
-       if( ludp->lud_dn == NULL ) {
+       if( check_dn && ludp->lud_dn == NULL ) {
                LDAP_FREE( url );
                ldap_free_urldesc( ludp );
                return LDAP_URL_ERR_MEM;
@@ -716,7 +1078,7 @@ ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
        if( *p != '\0' ) {
                /* parse the scope */
                ldap_pvt_hex_unescape( p );
-               ludp->lud_scope = str2scope( p );
+               ludp->lud_scope = ldap_pvt_str2scope( p );
 
                if( ludp->lud_scope == -1 ) {
                        LDAP_FREE( url );
@@ -813,34 +1175,7 @@ ldap_url_parse_ext( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
 int
 ldap_url_parse( LDAP_CONST char *url_in, LDAPURLDesc **ludpp )
 {
-       int rc = ldap_url_parse_ext( url_in, ludpp );
-
-       if( rc != LDAP_URL_SUCCESS ) {
-               return rc;
-       }
-
-       if ((*ludpp)->lud_scope == LDAP_SCOPE_DEFAULT) {
-               (*ludpp)->lud_scope = LDAP_SCOPE_BASE;
-       }
-
-       if ((*ludpp)->lud_host != NULL && *(*ludpp)->lud_host == '\0') {
-               LDAP_FREE( (*ludpp)->lud_host );
-               (*ludpp)->lud_host = NULL;
-       }
-
-       if ((*ludpp)->lud_port == 0) {
-               if( strcmp((*ludpp)->lud_scheme, "ldap") == 0 ) {
-                       (*ludpp)->lud_port = LDAP_PORT;
-#ifdef LDAP_CONNECTIONLESS
-               } else if( strcmp((*ludpp)->lud_scheme, "cldap") == 0 ) {
-                       (*ludpp)->lud_port = LDAP_PORT;
-#endif
-               } else if( strcmp((*ludpp)->lud_scheme, "ldaps") == 0 ) {
-                       (*ludpp)->lud_port = LDAPS_PORT;
-               }
-       }
-
-       return rc;
+       return ldap_url_parse_ext( url_in, ludpp, LDAP_PVT_URL_PARSE_HISTORIC );
 }
 
 LDAPURLDesc *
@@ -938,14 +1273,9 @@ ldap_url_duplist (LDAPURLDesc *ludlist)
        return dest;
 }
 
-int
-ldap_url_parselist (LDAPURLDesc **ludlist, const char *url )
-{
-       return ldap_url_parselist_ext( ludlist, url, ", " );
-}
-
-int
-ldap_url_parselist_ext (LDAPURLDesc **ludlist, const char *url, const char *sep )
+static int
+ldap_url_parselist_int (LDAPURLDesc **ludlist, const char *url, const char *sep, unsigned flags )
+       
 {
        int i, rc;
        LDAPURLDesc *ludp;
@@ -956,7 +1286,11 @@ ldap_url_parselist_ext (LDAPURLDesc **ludlist, const char *url, const char *sep
 
        *ludlist = NULL;
 
-       urls = ldap_str2charray(url, sep);
+       if ( sep == NULL ) {
+               sep = ", ";
+       }
+
+       urls = ldap_str2charray( url, sep );
        if (urls == NULL)
                return LDAP_URL_ERR_MEM;
 
@@ -964,20 +1298,32 @@ ldap_url_parselist_ext (LDAPURLDesc **ludlist, const char *url, const char *sep
        for (i = 0; urls[i] != NULL; i++) ;
        /* ...and put them in the "stack" backward */
        while (--i >= 0) {
-               rc = ldap_url_parse( urls[i], &ludp );
+               rc = ldap_url_parse_ext( urls[i], &ludp, flags );
                if ( rc != 0 ) {
-                       ldap_charray_free(urls);
-                       ldap_free_urllist(*ludlist);
+                       ldap_charray_free( urls );
+                       ldap_free_urllist( *ludlist );
                        *ludlist = NULL;
                        return rc;
                }
                ludp->lud_next = *ludlist;
                *ludlist = ludp;
        }
-       ldap_charray_free(urls);
+       ldap_charray_free( urls );
        return LDAP_URL_SUCCESS;
 }
 
+int
+ldap_url_parselist (LDAPURLDesc **ludlist, const char *url )
+{
+       return ldap_url_parselist_int( ludlist, url, ", ", LDAP_PVT_URL_PARSE_HISTORIC );
+}
+
+int
+ldap_url_parselist_ext (LDAPURLDesc **ludlist, const char *url, const char *sep, unsigned flags )
+{
+       return ldap_url_parselist_int( ludlist, url, sep, flags );
+}
+
 int
 ldap_url_parsehosts(
        LDAPURLDesc **ludlist,
@@ -1023,12 +1369,18 @@ ldap_url_parsehosts(
                                        specs[i] = ludp->lud_host;
                                        ludp->lud_host = p;
                                        p = strchr( ludp->lud_host, ']' );
-                                       if ( p == NULL )
+                                       if ( p == NULL ) {
+                                               LDAP_FREE(ludp);
+                                               ldap_charray_free(specs);
                                                return LDAP_PARAM_ERROR;
+                                       }
                                        *p++ = '\0';
                                        if ( *p != ':' ) {
-                                               if ( *p != '\0' )
+                                               if ( *p != '\0' ) {
+                                                       LDAP_FREE(ludp);
+                                                       ldap_charray_free(specs);
                                                        return LDAP_PARAM_ERROR;
+                                               }
                                                p = NULL;
                                        }
                                } else {
@@ -1041,7 +1393,9 @@ ldap_url_parsehosts(
                                *p++ = 0;
                                ldap_pvt_hex_unescape(p);
                                ludp->lud_port = strtol( p, &next, 10 );
-                               if ( next == NULL || next[0] != '\0' ) {
+                               if ( next == p || next[0] != '\0' ) {
+                                       LDAP_FREE(ludp);
+                                       ldap_charray_free(specs);
                                        return LDAP_PARAM_ERROR;
                                }
                        }
@@ -1071,6 +1425,7 @@ ldap_url_list2hosts (LDAPURLDesc *ludlist)
        /* figure out how big the string is */
        size = 1;       /* nul-term */
        for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
+               if ( ludp->lud_host == NULL ) continue;
                size += strlen(ludp->lud_host) + 1;             /* host and space */
                if (strchr(ludp->lud_host, ':'))        /* will add [ ] below */
                        size += 2;
@@ -1083,6 +1438,7 @@ ldap_url_list2hosts (LDAPURLDesc *ludlist)
 
        p = s;
        for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
+               if ( ludp->lud_host == NULL ) continue;
                if (strchr(ludp->lud_host, ':')) {
                        p += sprintf(p, "[%s]", ludp->lud_host);
                } else {
@@ -1095,7 +1451,7 @@ ldap_url_list2hosts (LDAPURLDesc *ludlist)
        }
        if (p != s)
                p--;    /* nuke that extra space */
-       *p = 0;
+       *p = '\0';
        return s;
 }
 
@@ -1103,50 +1459,50 @@ char *
 ldap_url_list2urls(
        LDAPURLDesc *ludlist )
 {
-       LDAPURLDesc *ludp;
-       int size;
-       char *s, *p, buf[32];   /* big enough to hold a long decimal # (overkill) */
+       LDAPURLDesc     *ludp;
+       int             size, sofar;
+       char            *s;
 
-       if (ludlist == NULL)
+       if ( ludlist == NULL ) {
                return NULL;
+       }
 
        /* figure out how big the string is */
-       size = 1;       /* nul-term */
-       for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
-               size += strlen(ludp->lud_scheme);
-               if ( ludp->lud_host ) {
-                       size += strlen(ludp->lud_host);
-                       /* will add [ ] below */
-                       if (strchr(ludp->lud_host, ':'))
-                               size += 2;
-               }
-               size += sizeof(":/// ");
-
-               if (ludp->lud_port != 0) {
-                       size += sprintf(buf, ":%d", ludp->lud_port);
+       for ( size = 0, ludp = ludlist; ludp != NULL; ludp = ludp->lud_next ) {
+               int     len = desc2str_len( ludp );
+               if ( len < 0 ) {
+                       return NULL;
                }
+               size += len + 1;
        }
+       
+       s = LDAP_MALLOC( size );
 
-       s = LDAP_MALLOC(size);
-       if (s == NULL) {
+       if ( s == NULL ) {
                return NULL;
        }
 
-       p = s;
-       for (ludp = ludlist; ludp != NULL; ludp = ludp->lud_next) {
-               p += sprintf(p, "%s://", ludp->lud_scheme);
-               if ( ludp->lud_host ) {
-                       p += sprintf(p, strchr(ludp->lud_host, ':') 
-                                       ? "[%s]" : "%s", ludp->lud_host);
+       for ( sofar = 0, ludp = ludlist; ludp != NULL; ludp = ludp->lud_next ) {
+               int     len;
+
+               len = desc2str( ludp, &s[sofar], size );
+               
+               if ( len < 0 ) {
+                       LDAP_FREE( s );
+                       return NULL;
                }
-               if (ludp->lud_port != 0)
-                       p += sprintf(p, ":%d", ludp->lud_port);
-               *p++ = '/';
-               *p++ = ' ';
+
+               sofar += len;
+               size -= len;
+
+               s[sofar++] = ' ';
+               size--;
+
+               assert( size >= 0 );
        }
-       if (p != s)
-               p--;    /* nuke that extra space */
-       *p = 0;
+
+       s[sofar - 1] = '\0';
+
        return s;
 }
 
@@ -1195,6 +1551,30 @@ ldap_free_urldesc( LDAPURLDesc *ludp )
        LDAP_FREE( ludp );
 }
 
+static int
+ldap_int_is_hexpair( char *s )
+{
+       int     i;
+
+       for ( i = 0; i < 2; i++ ) {
+               if ( s[i] >= '0' && s[i] <= '9' ) {
+                       continue;
+               }
+
+               if ( s[i] >= 'A' && s[i] <= 'F' ) {
+                       continue;
+               }
+
+               if ( s[i] >= 'a' && s[i] <= 'f' ) {
+                       continue;
+               }
+
+               return 0;
+       }
+       
+       return 1;       
+}
+       
 static int
 ldap_int_unhex( int c )
 {
@@ -1210,10 +1590,20 @@ ldap_pvt_hex_unescape( char *s )
         * Remove URL hex escapes from s... done in place.  The basic concept for
         * this routine is borrowed from the WWW library HTUnEscape() routine.
         */
-       char    *p;
+       char    *p,
+               *save_s = s;
 
        for ( p = s; *s != '\0'; ++s ) {
                if ( *s == '%' ) {
+                       /*
+                        * FIXME: what if '%' is followed
+                        * by non-hexpair chars?
+                        */
+                       if ( !ldap_int_is_hexpair( s + 1 ) ) {
+                               p = save_s;
+                               break;
+                       }
+
                        if ( *++s == '\0' ) {
                                break;
                        }
@@ -1230,4 +1620,3 @@ ldap_pvt_hex_unescape( char *s )
        *p = '\0';
 }
 
-