/* $OpenLDAP$ */
/* This work is part of OpenLDAP Software <http://www.openldap.org/>.
*
- * Copyright 1998-2004 The OpenLDAP Foundation.
+ * Copyright 1998-2005 The OpenLDAP Foundation.
* All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
Modifications *modlist = NULL;
Modifications **modtail = &modlist;
int increment = 0;
+ char textbuf[ SLAP_TEXT_BUFLEN ];
+ size_t textlen = sizeof( textbuf );
Debug( LDAP_DEBUG_TRACE, "do_modify\n", 0, 0, 0 );
goto cleanup;
}
- /* FIXME: temporary */
+ rs->sr_err = slap_mods_check( modlist, &rs->sr_text,
+ textbuf, textlen, NULL );
+
+ if ( rs->sr_err != LDAP_SUCCESS ) {
+ send_ldap_result( op, rs );
+ goto cleanup;
+ }
+
+ /* FIXME: needs review */
op->orm_modlist = modlist;
op->orm_increment = increment;
LDAPMod **modv = NULL;
#endif
int increment = op->orm_increment;
+ int rc = 0;
if( op->o_req_ndn.bv_len == 0 ) {
Debug( LDAP_DEBUG_ANY, "do_modify: root dse!\n", 0, 0, 0 );
* appropriate one, or send a referral to our "referral server"
* if we don't hold it.
*/
- op->o_bd = select_backend( &op->o_req_ndn, manageDSAit, 0 );
+ op->o_bd = select_backend( &op->o_req_ndn, manageDSAit, 1 );
if ( op->o_bd == NULL ) {
- rs->sr_ref = referral_rewrite( SLAPD_GLOBAL(default_referral),
+ rs->sr_ref = referral_rewrite( default_referral,
NULL, &op->o_req_dn, LDAP_SCOPE_DEFAULT );
- if (!rs->sr_ref) rs->sr_ref = SLAPD_GLOBAL(default_referral);
+ if (!rs->sr_ref) rs->sr_ref = default_referral;
if (rs->sr_ref != NULL ) {
rs->sr_err = LDAP_REFERRAL;
+ op->o_bd = frontendDB;
send_ldap_result( op, rs );
+ op->o_bd = NULL;
- if (rs->sr_ref != SLAPD_GLOBAL(default_referral)) ber_bvarray_free( rs->sr_ref );
+ if (rs->sr_ref != default_referral) ber_bvarray_free( rs->sr_ref );
} else {
+ op->o_bd = frontendDB;
send_ldap_error( op, rs, LDAP_UNWILLING_TO_PERFORM,
"no global superior knowledge" );
+ op->o_bd = NULL;
}
goto cleanup;
}
if ( !SLAP_SHADOW(op->o_bd) || repl_user )
#endif
{
- int update = op->o_bd->be_update_ndn.bv_len;
- char textbuf[SLAP_TEXT_BUFLEN];
- size_t textlen = sizeof textbuf;
- slap_callback cb = { NULL, slap_replog_cb, NULL, NULL };
+ int update = !BER_BVISEMPTY( &op->o_bd->be_update_ndn );
+ char textbuf[ SLAP_TEXT_BUFLEN ];
+ size_t textlen = sizeof( textbuf );
+ slap_callback cb = { NULL, slap_replog_cb, NULL, NULL };
- rs->sr_err = slap_mods_check( modlist, update, &rs->sr_text,
- textbuf, textlen, NULL );
- if( rs->sr_err != LDAP_SUCCESS ) {
- send_ldap_result( op, rs );
- goto cleanup;
+ if ( !update ) {
+ rs->sr_err = slap_mods_no_update_check( modlist,
+ &rs->sr_text, textbuf, textlen );
+ if ( rs->sr_err != LDAP_SUCCESS ) {
+ send_ldap_result( op, rs );
+ goto cleanup;
+ }
}
+
+
if ( !repl_user ) {
for( modtail = &modlist;
*modtail != NULL;
if ( !repl_user )
#endif
{
- /* but we log only the ones not from a replicator user */
+ /* but multimaster slapd logs only the ones
+ * not from a replicator user */
cb.sc_next = op->o_callback;
op->o_callback = &cb;
}
/* send a referral */
} else {
BerVarray defref = op->o_bd->be_update_refs
- ? op->o_bd->be_update_refs : SLAPD_GLOBAL(default_referral);
+ ? op->o_bd->be_update_refs : default_referral;
if ( defref != NULL ) {
rs->sr_ref = referral_rewrite( defref,
NULL, &op->o_req_dn,
LDAP_SCOPE_DEFAULT );
- if (!rs->sr_ref) rs->sr_ref = defref;
+ if ( rs->sr_ref == NULL ) {
+ /* FIXME: must duplicate, because
+ * overlays may muck with it */
+ rs->sr_ref = defref;
+ }
rs->sr_err = LDAP_REFERRAL;
send_ldap_result( op, rs );
- if (rs->sr_ref != defref) {
+ if ( rs->sr_ref != defref ) {
ber_bvarray_free( rs->sr_ref );
}
+
} else {
send_ldap_error( op, rs, LDAP_UNWILLING_TO_PERFORM,
"shadow context; no update referral" );
return rs->sr_err;
}
+/*
+ * Do non-update constraint checking.
+ */
+int
+slap_mods_no_update_check(
+ Modifications *ml,
+ const char **text,
+ char *textbuf,
+ size_t textlen )
+{
+ for ( ; ml != NULL; ml = ml->sml_next ) {
+ if ( is_at_no_user_mod( ml->sml_desc->ad_type ) ) {
+ /* user modification disallowed */
+ snprintf( textbuf, textlen,
+ "%s: no user modification allowed",
+ ml->sml_type.bv_val );
+ *text = textbuf;
+ return LDAP_CONSTRAINT_VIOLATION;
+ }
+ }
+
+ return LDAP_SUCCESS;
+}
+
/*
* Do basic attribute type checking and syntax validation.
*/
int slap_mods_check(
Modifications *ml,
- int update,
const char **text,
char *textbuf,
size_t textlen,
return LDAP_UNDEFINED_TYPE;
}
+#if 0
+ /* moved to slap_mods_no_update_check() */
if (!update && is_at_no_user_mod( ad->ad_type )) {
/* user modification disallowed */
snprintf( textbuf, textlen,
*text = textbuf;
return LDAP_CONSTRAINT_VIOLATION;
}
+#endif
if ( is_at_obsolete( ad->ad_type ) &&
(( ml->sml_op != LDAP_MOD_REPLACE &&
#ifdef HAVE_GMTIME_R
ltm = gmtime_r( &now, <m_buf );
#else
- ldap_pvt_thread_mutex_lock( &SLAPD_GLOBAL(gmtime_mutex) );
+ ldap_pvt_thread_mutex_lock( &gmtime_mutex );
ltm = gmtime( &now );
#endif /* HAVE_GMTIME_R */
lutil_gentime( timebuf, sizeof(timebuf), ltm );
slap_get_csn( op, csnbuf, sizeof(csnbuf), &csn, manage_ctxcsn );
#ifndef HAVE_GMTIME_R
- ldap_pvt_thread_mutex_unlock( &SLAPD_GLOBAL(gmtime_mutex) );
+ ldap_pvt_thread_mutex_unlock( &gmtime_mutex );
#endif
timestamp.bv_val = timebuf;
if( op->o_tag == LDAP_REQ_ADD ) {
struct berval tmpval;
- if( SLAPD_GLOBAL(schemachecking) ) {
+ if( global_schemacheck ) {
int rc = mods_structural_class( mods, &tmpval,
text, textbuf, textlen );
if( rc != LDAP_SUCCESS ) return rc;