]> git.sur5r.net Git - openldap/blobdiff - servers/slapd/entry.c
ACL logging was incomplete (and misleading)
[openldap] / servers / slapd / entry.c
index f854f8b0da65ed0c16150e932cdb3f6a6c8512db..9441de24e6317c7b18a2425ceab42870e89bac20 100644 (file)
@@ -1,8 +1,27 @@
 /* entry.c - routines for dealing with entries */
 /* $OpenLDAP$ */
-/*
- * Copyright 1998-2003 The OpenLDAP Foundation, All Rights Reserved.
- * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
+/* This work is part of OpenLDAP Software <http://www.openldap.org/>.
+ *
+ * Copyright 1998-2005 The OpenLDAP Foundation.
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted only as authorized by the OpenLDAP
+ * Public License.
+ *
+ * A copy of this license is available in the file LICENSE in the
+ * top-level directory of the distribution or, alternatively, at
+ * <http://www.OpenLDAP.org/license.html>.
+ */
+/* Portions Copyright (c) 1995 Regents of the University of Michigan.
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms are permitted
+ * provided that this notice is preserved and that due credit is given
+ * to the University of Michigan at Ann Arbor. The name of the University
+ * may not be used to endorse or promote products derived from this
+ * software without specific prior written permission. This software
+ * is provided ``as is'' without express or implied warranty.
  */
 
 #include "portable.h"
@@ -17,8 +36,8 @@
 #include "slap.h"
 #include "ldif.h"
 
-static unsigned char   *ebuf;  /* buf returned by entry2str             */
-static unsigned char   *ecur;  /* pointer to end of currently used ebuf */
+static char            *ebuf;  /* buf returned by entry2str             */
+static char            *ecur;  /* pointer to end of currently used ebuf */
 static int             emaxsize;/* max size of ebuf                     */
 
 /*
@@ -28,6 +47,8 @@ const Entry slap_entry_root = {
        NOID, { 0, "" }, { 0, "" }, NULL, 0, { 0, "" }, NULL
 };
 
+static const struct berval dn_bv = BER_BVC("dn");
+
 int entry_destroy(void)
 {
        if ( ebuf ) free( ebuf );
@@ -40,15 +61,23 @@ int entry_destroy(void)
 
 Entry *
 str2entry( char *s )
+{
+       return str2entry2( s, 1 );
+}
+
+Entry *
+str2entry2( char *s, int checkvals )
 {
        int rc;
        Entry           *e;
-       char            *type;
-       struct berval   vals[2];
-       struct berval   nvals[2], *nvalsp;
-       AttributeDescription *ad;
+       struct berval   *type, *vals, *nvals;
+       char    *freeval;
+       AttributeDescription *ad, *ad_prev;
        const char *text;
        char    *next;
+       int             attr_cnt;
+       int             i, lines;
+       Attribute       ahead, *atail;
 
        /*
         * LDIF is used as the string format.
@@ -65,24 +94,16 @@ str2entry( char *s )
         * or newline.
         */
 
-#ifdef NEW_LOGGING
-       LDAP_LOG( OPERATION, DETAIL1, "str2entry: \"%s\"\n", s ? s : "NULL", 0, 0 );
-#else
-       Debug( LDAP_DEBUG_TRACE, "=> str2entry\n",
+       Debug( LDAP_DEBUG_TRACE, "=> str2entry: \"%s\"\n",
                s ? s : "NULL", 0, 0 );
-#endif
 
        /* initialize reader/writer lock */
        e = (Entry *) ch_calloc( 1, sizeof(Entry) );
 
        if( e == NULL ) {
-#ifdef NEW_LOGGING
-               LDAP_LOG( OPERATION, ERR, "str2entry: entry allocation failed.\n", 0, 0, 0 );
-#else
                Debug( LDAP_DEBUG_ANY,
-                   "<= str2entry NULL (entry allocation failed)\n",
-                   0, 0, 0 );
-#endif
+                       "<= str2entry NULL (entry allocation failed)\n",
+                       0, 0, 0 );
                return( NULL );
        }
 
@@ -90,96 +111,154 @@ str2entry( char *s )
        e->e_id = NOID;
 
        /* dn + attributes */
-       vals[1].bv_len = 0;
-       vals[1].bv_val = NULL;
-
+       atail = &ahead;
+       ahead.a_next = NULL;
+       ad = NULL;
+       ad_prev = NULL;
+       attr_cnt = 0;
        next = s;
+
+       lines = ldif_countlines( s );
+       type = ch_calloc( 1, (lines+1)*3*sizeof(struct berval)+lines );
+       vals = type+lines+1;
+       nvals = vals+lines+1;
+       freeval = (char *)(nvals+lines+1);
+       i = -1;
+
+       /* parse into individual values, record DN */
        while ( (s = ldif_getline( &next )) != NULL ) {
+               int freev;
                if ( *s == '\n' || *s == '\0' ) {
                        break;
                }
+               i++;
 
-               if ( ldif_parse_line( s, &type, &vals[0].bv_val, &vals[0].bv_len ) != 0 ) {
-#ifdef NEW_LOGGING
-                       LDAP_LOG( OPERATION, DETAIL1, "str2entry:  NULL (parse_line)\n",0, 0, 0 );
-#else
+               rc = ldif_parse_line2( s, type+i, vals+i, &freev );
+               freeval[i] = freev;
+               if ( rc ) {
                        Debug( LDAP_DEBUG_TRACE,
-                           "<= str2entry NULL (parse_line)\n", 0, 0, 0 );
-#endif
+                               "<= str2entry NULL (parse_line)\n", 0, 0, 0 );
                        continue;
                }
 
-               if ( strcasecmp( type, "dn" ) == 0 ) {
-                       free( type );
+               if ( type[i].bv_len == dn_bv.bv_len &&
+                       strcasecmp( type[i].bv_val, dn_bv.bv_val ) == 0 ) {
 
                        if ( e->e_dn != NULL ) {
-#ifdef NEW_LOGGING
-                               LDAP_LOG( OPERATION, DETAIL1, "str2entry: "
-                                       "entry %ld has multiple DNs \"%s\" and \"%s\"\n",
-                                       (long) e->e_id, e->e_dn, vals[0].bv_val );
-#else
                                Debug( LDAP_DEBUG_ANY, "str2entry: "
                                        "entry %ld has multiple DNs \"%s\" and \"%s\"\n",
-                                   (long) e->e_id, e->e_dn, vals[0].bv_val );
-#endif
-                               free( vals[0].bv_val );
-                               entry_free( e );
-                               return NULL;
+                                       (long) e->e_id, e->e_dn, vals[i].bv_val );
+                               goto fail;
                        }
 
-                       rc = dnPrettyNormal( NULL, &vals[0], &e->e_name, &e->e_nname, NULL );
+                       rc = dnPrettyNormal( NULL, &vals[i], &e->e_name, &e->e_nname, NULL );
                        if( rc != LDAP_SUCCESS ) {
-#ifdef NEW_LOGGING
-                               LDAP_LOG( OPERATION, DETAIL1, 
-                                       "str2entry: entry %ld has invalid DN \"%s\"\n",
-                                       (long) e->e_id, vals[0].bv_val, 0 );
-#else
                                Debug( LDAP_DEBUG_ANY, "str2entry: "
                                        "entry %ld has invalid DN \"%s\"\n",
-                                       (long) e->e_id, vals[0].bv_val, 0 );
-#endif
-                               entry_free( e );
-                               free( vals[0].bv_val );
-                               return NULL;
+                                       (long) e->e_id, vals[i].bv_val, 0 );
+                               goto fail;
                        }
-                       free( vals[0].bv_val );
+                       if ( freeval[i] ) free( vals[i].bv_val );
+                       vals[i].bv_val = NULL;
+                       i--;
                        continue;
                }
+       }
+       lines = i+1;
 
-               ad = NULL;
-               rc = slap_str2ad( type, &ad, &text );
+       /* check to make sure there was a dn: line */
+       if ( BER_BVISNULL( &e->e_name )) {
+               Debug( LDAP_DEBUG_ANY, "str2entry: entry %ld has no dn\n",
+                       (long) e->e_id, 0, 0 );
+               goto fail;
+       }
 
-               if( rc != LDAP_SUCCESS ) {
-#ifdef NEW_LOGGING
-                       LDAP_LOG( OPERATION, DETAIL1, 
-                               "str2entry:  str2ad(%s): %s\n", type, text, 0 );
-#else
-                       Debug( slapMode & SLAP_TOOL_MODE
-                               ? LDAP_DEBUG_ANY : LDAP_DEBUG_TRACE,
-                               "<= str2entry: str2ad(%s): %s\n", type, text, 0 );
-#endif
-                       if( slapMode & SLAP_TOOL_MODE ) {
-                               entry_free( e );
-                               free( vals[0].bv_val );
-                               free( type );
-                               return NULL;
+       /* Make sure all attributes with multiple values are contiguous */
+       if ( checkvals ) {
+               int j, k;
+               struct berval bv;
+               int fv;
+
+               for (i=0; i<lines; i++) {
+                       for ( j=i+1; j<lines; j++ ) {
+                               if ( bvmatch( type+i, type+j )) {
+                                       /* out of order, move intervening attributes down */
+                                       if ( j != i+1 ) {
+                                               bv = vals[j];
+                                               fv = freeval[j];
+                                               for ( k=j; k>i; k-- ) {
+                                                       type[k] = type[k-1];
+                                                       vals[k] = vals[k-1];
+                                                       freeval[k] = freeval[k-1];
+                                               }
+                                               k++;
+                                               type[k] = type[i];
+                                               vals[k] = bv;
+                                               freeval[k] = fv;
+                                       }
+                                       i++;
+                               }
                        }
+               }
+       }
+
+       for ( i=0; i<=lines; i++ ) {
+               ad_prev = ad;
+               if ( !ad || ( i<lines && !bvmatch( type+i, &ad->ad_cname ))) {
+                       ad = NULL;
+                       rc = slap_bv2ad( type+i, &ad, &text );
 
-                       rc = slap_str2undef_ad( type, &ad, &text );
                        if( rc != LDAP_SUCCESS ) {
-#ifdef NEW_LOGGING
-                               LDAP_LOG( OPERATION, DETAIL1, 
-                                       "str2entry: str2undef_ad(%s): %s\n", type, text, 0 );
-#else
-                               Debug( LDAP_DEBUG_ANY,
-                                       "<= str2entry: str2undef_ad(%s): %s\n",
-                                               type, text, 0 );
-#endif
-                               entry_free( e );
-                               free( vals[0].bv_val );
-                               free( type );
-                               return NULL;
+                               Debug( slapMode & SLAP_TOOL_MODE
+                                       ? LDAP_DEBUG_ANY : LDAP_DEBUG_TRACE,
+                                       "<= str2entry: str2ad(%s): %s\n", type[i].bv_val, text, 0 );
+                               if( slapMode & SLAP_TOOL_MODE ) {
+                                       goto fail;
+                               }
+
+                               rc = slap_bv2undef_ad( type+i, &ad, &text );
+                               if( rc != LDAP_SUCCESS ) {
+                                       Debug( LDAP_DEBUG_ANY,
+                                               "<= str2entry: str2undef_ad(%s): %s\n",
+                                                       type[i].bv_val, text, 0 );
+                                       goto fail;
+                               }
+                       }
+               }
+
+               if (( ad_prev && ad != ad_prev ) || ( i == lines )) {
+                       int j, k;
+                       atail->a_next = (Attribute *) ch_malloc( sizeof(Attribute) );
+                       atail = atail->a_next;
+                       atail->a_flags = 0;
+                       atail->a_desc = ad_prev;
+                       atail->a_vals = ch_malloc( (attr_cnt + 1) * sizeof(struct berval));
+                       if( ad_prev->ad_type->sat_equality &&
+                               ad_prev->ad_type->sat_equality->smr_normalize )
+                               atail->a_nvals = ch_malloc( (attr_cnt + 1) * sizeof(struct berval));
+                       else
+                               atail->a_nvals = NULL;
+                       k = i - attr_cnt;
+                       for ( j=0; j<attr_cnt; j++ ) {
+                               if ( freeval[k] )
+                                       atail->a_vals[j] = vals[k];
+                               else
+                                       ber_dupbv( atail->a_vals+j, &vals[k] );
+                               vals[k].bv_val = NULL;
+                               if ( atail->a_nvals ) {
+                                       atail->a_nvals[j] = nvals[k];
+                                       nvals[k].bv_val = NULL;
+                               }
+                               k++;
                        }
+                       BER_BVZERO( &atail->a_vals[j] );
+                       if ( atail->a_nvals ) {
+                               BER_BVZERO( &atail->a_nvals[j] );
+                       } else {
+                               atail->a_nvals = atail->a_vals;
+                       }
+                       attr_cnt = 0;
+                       if ( i == lines ) break;
                }
 
                if( slapMode & SLAP_TOOL_MODE ) {
@@ -191,55 +270,39 @@ str2entry( char *s )
 
                        if( pretty ) {
                                rc = pretty( ad->ad_type->sat_syntax,
-                                       &vals[0], &pval, NULL );
+                                       &vals[i], &pval, NULL );
 
                        } else if( validate ) {
                                /*
                                 * validate value per syntax
                                 */
-                               rc = validate( ad->ad_type->sat_syntax, &vals[0] );
+                               rc = validate( ad->ad_type->sat_syntax, &vals[i] );
 
                        } else {
-#ifdef NEW_LOGGING
-                               LDAP_LOG( OPERATION, INFO, 
-                                       "str2entry: no validator for syntax %s\n", 
-                                       ad->ad_type->sat_syntax->ssyn_oid, 0, 0 );
-#else
                                Debug( LDAP_DEBUG_ANY,
-                                       "str2entry: no validator for syntax %s\n",
-                                       ad->ad_type->sat_syntax->ssyn_oid, 0, 0 );
-#endif
-                               entry_free( e );
-                               free( vals[0].bv_val );
-                               free( type );
-                               return NULL;
+                                       "str2entry: attributeType %s #%d: "
+                                       "no validator for syntax %s\n", 
+                                       ad->ad_cname.bv_val, attr_cnt,
+                                       ad->ad_type->sat_syntax->ssyn_oid );
+                               goto fail;
                        }
 
                        if( rc != 0 ) {
-#ifdef NEW_LOGGING
-                               LDAP_LOG( OPERATION, ERR, 
-                                       "str2entry:  invalid value for attribute %s (syntax %s)\n",
-                                       ad->ad_cname.bv_val, ad->ad_type->sat_syntax->ssyn_oid, 0 );
-#else
                                Debug( LDAP_DEBUG_ANY,
-                                       "str2entry: invalid value for attribute %s (syntax %s)\n",
-                                       ad->ad_cname.bv_val, ad->ad_type->sat_syntax->ssyn_oid, 0 );
-#endif
-                               entry_free( e );
-                               free( vals[0].bv_val );
-                               free( type );
-                               return NULL;
+                                       "str2entry: invalid value "
+                                       "for attributeType %s #%d (syntax %s)\n",
+                                       ad->ad_cname.bv_val, attr_cnt,
+                                       ad->ad_type->sat_syntax->ssyn_oid );
+                               goto fail;
                        }
 
                        if( pretty ) {
-                               free( vals[0].bv_val );
-                               vals[0] = pval;
+                               if ( freeval[i] ) free( vals[i].bv_val );
+                               vals[i] = pval;
+                               freeval[i] = 1;
                        }
                }
 
-               nvalsp = NULL;
-               nvals[0].bv_val = NULL;
-
                if( ad->ad_type->sat_equality &&
                        ad->ad_type->sat_equality->smr_normalize )
                {
@@ -247,70 +310,34 @@ str2entry( char *s )
                                SLAP_MR_VALUE_OF_ATTRIBUTE_SYNTAX,
                                ad->ad_type->sat_syntax,
                                ad->ad_type->sat_equality,
-                               &vals[0], &nvals[0], NULL );
+                               &vals[i], &nvals[i], NULL );
 
                        if( rc ) {
-#ifdef NEW_LOGGING
-                               LDAP_LOG( OPERATION, DETAIL1,
-                                       "str2entry:  NULL (smr_normalize %d)\n" , rc, 0, 0 );
-#else
                                Debug( LDAP_DEBUG_ANY,
                                        "<= str2entry NULL (smr_normalize %d)\n", rc, 0, 0 );
-#endif
-
-                               entry_free( e );
-                               free( vals[0].bv_val );
-                               free( type );
-                               return NULL;
+                               goto fail;
                        }
-
-                       nvals[1].bv_len = 0;
-                       nvals[1].bv_val = NULL;
-
-                       nvalsp = &nvals[0];
                }
 
-               rc = attr_merge( e, ad, vals, nvalsp );
-               if( rc != 0 ) {
-#ifdef NEW_LOGGING
-                       LDAP_LOG( OPERATION, DETAIL1,
-                               "str2entry:  NULL (attr_merge)\n" , 0, 0, 0 );
-#else
-                       Debug( LDAP_DEBUG_ANY,
-                           "<= str2entry NULL (attr_merge)\n", 0, 0, 0 );
-#endif
-                       entry_free( e );
-                       free( vals[0].bv_val );
-                       free( type );
-                       return( NULL );
-               }
-
-               free( type );
-               free( vals[0].bv_val );
-               free( nvals[0].bv_val );
+               attr_cnt++;
        }
 
-       /* check to make sure there was a dn: line */
-       if ( e->e_dn == NULL ) {
-#ifdef NEW_LOGGING
-               LDAP_LOG( OPERATION, INFO, 
-                       "str2entry:  entry %ld has no dn.\n", (long) e->e_id, 0, 0 );
-#else
-               Debug( LDAP_DEBUG_ANY, "str2entry: entry %ld has no dn\n",
-                   (long) e->e_id, 0, 0 );
-#endif
-               entry_free( e );
-               return NULL;
-       }
+       free( type );
+       atail->a_next = NULL;
+       e->e_attrs = ahead.a_next;
 
-#ifdef NEW_LOGGING
-       LDAP_LOG( OPERATION, DETAIL2,
-               "str2entry(%s) -> 0x%lx\n", e->e_dn, (unsigned long)e, 0 );
-#else
        Debug(LDAP_DEBUG_TRACE, "<= str2entry(%s) -> 0x%lx\n",
                e->e_dn, (unsigned long) e, 0 );
-#endif
        return( e );
+
+fail:
+       for ( i=0; i<lines; i++ ) {
+               if ( freeval[i] ) free( vals[i].bv_val );
+               free( nvals[i].bv_val );
+       }
+       free( type );
+       entry_free( e );
+       return NULL;
 }
 
 
@@ -320,8 +347,8 @@ str2entry( char *s )
                while ( ecur + (n) > ebuf + emaxsize ) { \
                        ptrdiff_t       offset; \
                        offset = (int) (ecur - ebuf); \
-                       ebuf = (unsigned char *) ch_realloc( (char *) ebuf, \
-                           emaxsize + GRABSIZE ); \
+                       ebuf = ch_realloc( ebuf, \
+                               emaxsize + GRABSIZE ); \
                        emaxsize += GRABSIZE; \
                        ecur = ebuf + offset; \
                } \
@@ -329,8 +356,8 @@ str2entry( char *s )
 
 char *
 entry2str(
-    Entry      *e,
-    int                *len )
+       Entry   *e,
+       int             *len )
 {
        Attribute       *a;
        struct berval   *bv;
@@ -352,7 +379,7 @@ entry2str(
                /* put "dn: <dn>" */
                tmplen = e->e_name.bv_len;
                MAKE_SPACE( LDIF_SIZE_NEEDED( 2, tmplen ));
-               ldif_sput( (char **) &ecur, LDIF_PUT_VALUE, "dn", e->e_dn, tmplen );
+               ldif_sput( &ecur, LDIF_PUT_VALUE, "dn", e->e_dn, tmplen );
        }
 
        /* put the attributes */
@@ -362,20 +389,20 @@ entry2str(
                        bv = &a->a_vals[i];
                        tmplen = a->a_desc->ad_cname.bv_len;
                        MAKE_SPACE( LDIF_SIZE_NEEDED( tmplen, bv->bv_len ));
-                       ldif_sput( (char **) &ecur, LDIF_PUT_VALUE,
+                       ldif_sput( &ecur, LDIF_PUT_VALUE,
                                a->a_desc->ad_cname.bv_val,
-                           bv->bv_val, bv->bv_len );
+                               bv->bv_val, bv->bv_len );
                }
        }
        MAKE_SPACE( 1 );
        *ecur = '\0';
        *len = ecur - ebuf;
 
-       return( (char *) ebuf );
+       return( ebuf );
 }
 
 void
-entry_free( Entry *e )
+entry_clean( Entry *e )
 {
        /* free an entry structure */
        assert( e != NULL );
@@ -385,23 +412,29 @@ entry_free( Entry *e )
        e->e_private = NULL;
 
        /* free DNs */
-       if ( e->e_dn != NULL ) {
-               free( e->e_dn );
-               e->e_dn = NULL;
+       if ( !BER_BVISNULL( &e->e_name ) ) {
+               free( e->e_name.bv_val );
+               BER_BVZERO( &e->e_name );
        }
-       if ( e->e_ndn != NULL ) {
-               free( e->e_ndn );
-               e->e_ndn = NULL;
+       if ( !BER_BVISNULL( &e->e_nname ) ) {
+               free( e->e_nname.bv_val );
+               BER_BVZERO( &e->e_nname );
        }
 
-       if ( e->e_bv.bv_val != NULL ) {
+       if ( !BER_BVISNULL( &e->e_bv ) ) {
                free( e->e_bv.bv_val );
-               e->e_bv.bv_val = NULL;
+               BER_BVZERO( &e->e_bv );
        }
 
        /* free attributes */
        attrs_free( e->e_attrs );
        e->e_attrs = NULL;
+}
+
+void
+entry_free( Entry *e )
+{
+       entry_clean( e );
 
        free( e );
 }
@@ -441,24 +474,9 @@ entry_id_cmp( const void *v_e1, const void *v_e2 )
        return( e1->e_id < e2->e_id ? -1 : (e1->e_id > e2->e_id ? 1 : 0) );
 }
 
-#define entry_lenlen(l)        ((l) < 0x80) ? 1 : ((l) < 0x100) ? 2 : \
-       ((l) < 0x10000) ? 3 : ((l) < 0x1000000) ? 4 : 5
-#if 0
 /* This is like a ber_len */
-static ber_len_t
-entry_lenlen(ber_len_t len)
-{
-       if (len <= 0x7f)
-               return 1;
-       if (len <= 0xff)
-               return 2;
-       if (len <= 0xffff)
-               return 3;
-       if (len <= 0xffffff)
-               return 4;
-       return 5;
-}
-#endif
+#define entry_lenlen(l)        (((l) < 0x80) ? 1 : ((l) < 0x100) ? 2 : \
+       ((l) < 0x10000) ? 3 : ((l) < 0x1000000) ? 4 : 5)
 
 static void
 entry_putlen(unsigned char **buf, ber_len_t len)
@@ -496,12 +514,12 @@ entry_getlen(unsigned char **buf)
        return len;
 }
 
-/* Add up the size of the entry for a flattened buffer */
-void entry_flatsize(Entry *e, ber_len_t *psiz, ber_len_t *plen, int norm)
+/* Count up the sizes of the components of an entry */
+void entry_partsize(Entry *e, ber_len_t *plen,
+       int *pnattrs, int *pnvals, int norm)
 {
-       ber_len_t siz = sizeof(Entry);
        ber_len_t len, dnlen, ndnlen;
-       int i;
+       int i, nat = 0, nval = 0;
        Attribute *a;
 
        dnlen = e->e_name.bv_len;
@@ -514,32 +532,45 @@ void entry_flatsize(Entry *e, ber_len_t *psiz, ber_len_t *plen, int norm)
        }
        for (a=e->e_attrs; a; a=a->a_next) {
                /* For AttributeDesc, we only store the attr name */
-               siz += sizeof(Attribute);
+               nat++;
                len += a->a_desc->ad_cname.bv_len+1;
                len += entry_lenlen(a->a_desc->ad_cname.bv_len);
                for (i=0; a->a_vals[i].bv_val; i++) {
-                       siz += sizeof(struct berval);
+                       nval++;
                        len += a->a_vals[i].bv_len + 1;
                        len += entry_lenlen(a->a_vals[i].bv_len);
                }
                len += entry_lenlen(i);
-               siz += sizeof(struct berval);   /* empty berval at end */
+               nval++; /* empty berval at end */
                if (norm && a->a_nvals != a->a_vals) {
                        for (i=0; a->a_nvals[i].bv_val; i++) {
-                               siz += sizeof(struct berval);
+                               nval++;
                                len += a->a_nvals[i].bv_len + 1;
                                len += entry_lenlen(a->a_nvals[i].bv_len);
                        }
                        len += entry_lenlen(i); /* i nvals */
-                       siz += sizeof(struct berval);
+                       nval++;
                } else {
                        len += entry_lenlen(0); /* 0 nvals */
                }
        }
-       len += 1;       /* NUL byte at end */
-       len += entry_lenlen(siz);
-       *psiz = siz;
+       len += entry_lenlen(nat);
+       len += entry_lenlen(nval);
        *plen = len;
+       *pnattrs = nat;
+       *pnvals = nval;
+}
+
+/* Add up the size of the entry for a flattened buffer */
+ber_len_t entry_flatsize(Entry *e, int norm)
+{
+       ber_len_t len;
+       int nattrs, nvals;
+
+       entry_partsize(e, &len, &nattrs, &nvals, norm);
+       len += sizeof(Entry) + (nattrs * sizeof(Attribute)) +
+               (nvals * sizeof(struct berval));
+       return len;
 }
 
 /* Flatten an Entry into a buffer. The buffer is filled with just the
@@ -551,28 +582,23 @@ void entry_flatsize(Entry *e, ber_len_t *psiz, ber_len_t *plen, int norm)
  */
 int entry_encode(Entry *e, struct berval *bv)
 {
-       ber_len_t siz = sizeof(Entry);
        ber_len_t len, dnlen, ndnlen;
-       int i;
+       int i, nattrs, nvals;
        Attribute *a;
        unsigned char *ptr;
 
-#ifdef NEW_LOGGING
-       LDAP_LOG( OPERATION, DETAIL1, "entry_encode: id: 0x%08lx  \"%s\"\n",
-               (long) e->e_id, e->e_dn, 0 );
-#else
        Debug( LDAP_DEBUG_TRACE, "=> entry_encode(0x%08lx): %s\n",
                (long) e->e_id, e->e_dn, 0 );
-#endif
        dnlen = e->e_name.bv_len;
        ndnlen = e->e_nname.bv_len;
 
-       entry_flatsize( e, &siz, &len, 1 );
+       entry_partsize( e, &len, &nattrs, &nvals, 1 );
 
        bv->bv_len = len;
        bv->bv_val = ch_malloc(len);
        ptr = (unsigned char *)bv->bv_val;
-       entry_putlen(&ptr, siz);
+       entry_putlen(&ptr, nattrs);
+       entry_putlen(&ptr, nvals);
        entry_putlen(&ptr, dnlen);
        AC_MEMCPY(ptr, e->e_dn, dnlen);
        ptr += dnlen;
@@ -589,30 +615,29 @@ int entry_encode(Entry *e, struct berval *bv)
                ptr += a->a_desc->ad_cname.bv_len;
                *ptr++ = '\0';
                if (a->a_vals) {
-                   for (i=0; a->a_vals[i].bv_val; i++);
-                   entry_putlen(&ptr, i);
-                   for (i=0; a->a_vals[i].bv_val; i++) {
-                       entry_putlen(&ptr, a->a_vals[i].bv_len);
-                       AC_MEMCPY(ptr, a->a_vals[i].bv_val,
-                               a->a_vals[i].bv_len);
-                       ptr += a->a_vals[i].bv_len;
-                       *ptr++ = '\0';
-                   }
-                   if (a->a_nvals != a->a_vals) {
-                       entry_putlen(&ptr, i);
-                       for (i=0; a->a_nvals[i].bv_val; i++) {
-                           entry_putlen(&ptr, a->a_nvals[i].bv_len);
-                           AC_MEMCPY(ptr, a->a_nvals[i].bv_val,
-                               a->a_nvals[i].bv_len);
-                           ptr += a->a_nvals[i].bv_len;
-                           *ptr++ = '\0';
+                       for (i=0; a->a_vals[i].bv_val; i++);
+                               entry_putlen(&ptr, i);
+                               for (i=0; a->a_vals[i].bv_val; i++) {
+                               entry_putlen(&ptr, a->a_vals[i].bv_len);
+                               AC_MEMCPY(ptr, a->a_vals[i].bv_val,
+                                       a->a_vals[i].bv_len);
+                               ptr += a->a_vals[i].bv_len;
+                               *ptr++ = '\0';
+                       }
+                       if (a->a_nvals != a->a_vals) {
+                               entry_putlen(&ptr, i);
+                               for (i=0; a->a_nvals[i].bv_val; i++) {
+                                       entry_putlen(&ptr, a->a_nvals[i].bv_len);
+                                       AC_MEMCPY(ptr, a->a_nvals[i].bv_val,
+                                       a->a_nvals[i].bv_len);
+                                       ptr += a->a_nvals[i].bv_len;
+                                       *ptr++ = '\0';
+                               }
+                       } else {
+                               entry_putlen(&ptr, 0);
                        }
-                   } else {
-                       entry_putlen(&ptr, 0);
-                   }
                }
        }
-       *ptr = '\0';
        return 0;
 }
 
@@ -627,9 +652,13 @@ int entry_encode(Entry *e, struct berval *bv)
  * you can not free individual attributes or names from this
  * structure. Attempting to do so will likely corrupt memory.
  */
+#ifdef SLAP_ZONE_ALLOC
+int entry_decode(struct berval *bv, Entry **e, void *ctx)
+#else
 int entry_decode(struct berval *bv, Entry **e)
+#endif
 {
-       int i, j, count;
+       int i, j, count, nattrs, nvals;
        int rc;
        Attribute *a;
        Entry *x;
@@ -638,23 +667,42 @@ int entry_decode(struct berval *bv, Entry **e)
        unsigned char *ptr = (unsigned char *)bv->bv_val;
        BerVarray bptr;
 
-       i = entry_getlen(&ptr);
+       nattrs = entry_getlen(&ptr);
+       if (!nattrs) {
+               Debug( LDAP_DEBUG_ANY,
+                       "entry_decode: attribute count was zero\n", 0, 0, 0);
+               return LDAP_OTHER;
+       }
+       nvals = entry_getlen(&ptr);
+       if (!nvals) {
+               Debug( LDAP_DEBUG_ANY,
+                       "entry_decode: value count was zero\n", 0, 0, 0);
+               return LDAP_OTHER;
+       }
+       i = sizeof(Entry) + (nattrs * sizeof(Attribute)) +
+               (nvals * sizeof(struct berval));
+#ifdef SLAP_ZONE_ALLOC
+       x = slap_zn_calloc(1, i + bv->bv_len, ctx);
+       AC_MEMCPY((char*)x + i, bv->bv_val, bv->bv_len);
+       bv->bv_val = (char*)x + i;
+       ptr = (unsigned char *)bv->bv_val;
+       /* pointer is reset, now advance past nattrs and nvals again */
+       entry_getlen(&ptr);
+       entry_getlen(&ptr);
+#else
        x = ch_calloc(1, i);
+#endif
        i = entry_getlen(&ptr);
-       x->e_name.bv_val = ptr;
+       x->e_name.bv_val = (char *) ptr;
        x->e_name.bv_len = i;
        ptr += i+1;
        i = entry_getlen(&ptr);
-       x->e_nname.bv_val = ptr;
+       x->e_nname.bv_val = (char *) ptr;
        x->e_nname.bv_len = i;
        ptr += i+1;
-#ifdef NEW_LOGGING
-       LDAP_LOG( OPERATION, DETAIL2, "entry_decode: \"%s\"\n", x->e_dn, 0, 0 );
-#else
        Debug( LDAP_DEBUG_TRACE,
-           "entry_decode: \"%s\"\n",
-           x->e_dn, 0, 0 );
-#endif
+               "entry_decode: \"%s\"\n",
+               x->e_dn, 0, 0 );
        x->e_bv = *bv;
 
        /* A valid entry must have at least one attr, so this
@@ -667,7 +715,7 @@ int entry_decode(struct berval *bv, Entry **e)
        while ((i = entry_getlen(&ptr))) {
                struct berval bv;
                bv.bv_len = i;
-               bv.bv_val = ptr;
+               bv.bv_val = (char *) ptr;
                if (a) {
                        a->a_next = (Attribute *)bptr;
                }
@@ -676,24 +724,14 @@ int entry_decode(struct berval *bv, Entry **e)
                rc = slap_bv2ad( &bv, &ad, &text );
 
                if( rc != LDAP_SUCCESS ) {
-#ifdef NEW_LOGGING
-                       LDAP_LOG( OPERATION, INFO, 
-                               "entry_decode: str2ad(%s): %s\n", ptr, text, 0 );
-#else
                        Debug( LDAP_DEBUG_TRACE,
                                "<= entry_decode: str2ad(%s): %s\n", ptr, text, 0 );
-#endif
                        rc = slap_bv2undef_ad( &bv, &ad, &text );
 
                        if( rc != LDAP_SUCCESS ) {
-#ifdef NEW_LOGGING
-                               LDAP_LOG( OPERATION, INFO, 
-                                       "entry_decode:  str2undef_ad(%s): %s\n", ptr, text, 0 );
-#else
                                Debug( LDAP_DEBUG_ANY,
                                        "<= entry_decode: str2undef_ad(%s): %s\n",
                                                ptr, text, 0 );
-#endif
                                return rc;
                        }
                }
@@ -702,6 +740,9 @@ int entry_decode(struct berval *bv, Entry **e)
                bptr = (BerVarray)(a+1);
                a->a_vals = bptr;
                a->a_flags = 0;
+#ifdef LDAP_COMP_MATCH
+               a->a_comp_data = NULL;
+#endif
                count = j = entry_getlen(&ptr);
 
                while (j) {
@@ -733,15 +774,33 @@ int entry_decode(struct berval *bv, Entry **e)
                } else {
                        a->a_nvals = a->a_vals;
                }
+               nattrs--;
+               if ( !nattrs )
+                       break;
        }
 
        if (a) a->a_next = NULL;
-#ifdef NEW_LOGGING
-       LDAP_LOG( OPERATION, DETAIL1, "entry_decode:  %s\n", x->e_dn, 0, 0 );
-#else
        Debug(LDAP_DEBUG_TRACE, "<= entry_decode(%s)\n",
                x->e_dn, 0, 0 );
-#endif
        *e = x;
        return 0;
 }
+
+Entry *entry_dup( Entry *e )
+{
+       Entry *ret;
+
+       ret = (Entry *)ch_calloc( 1, sizeof(*ret) );
+
+       ret->e_id = e->e_id;
+       ber_dupbv( &ret->e_name, &e->e_name );
+       ber_dupbv( &ret->e_nname, &e->e_nname );
+       ret->e_attrs = attrs_dup( e->e_attrs );
+       ret->e_ocflags = e->e_ocflags;
+       ret->e_bv.bv_val = NULL;
+       ret->e_bv.bv_len = 0;
+       ret->e_private = NULL;
+
+       return ret;
+}
+