]> git.sur5r.net Git - openldap/blobdiff - servers/slapd/mra.c
Extend checks to substrings rules. Need to kludge around
[openldap] / servers / slapd / mra.c
index eca939b02674fd8b17def10f75c736b76a158c53..5276c546e6700f1ac32a1411c2e6fc67dd8b941b 100644 (file)
@@ -170,21 +170,12 @@ get_mra(
                return SLAPD_DISCONNECT;
        }
 
-       if( ma->ma_dnattrs ) {
-               *text = "matching with \":dn\" not supported";
-               return LDAP_INAPPROPRIATE_MATCHING;
-       }
-
        if( type.bv_val != NULL ) {
                rc = slap_bv2ad( &type, &ma->ma_desc, text );
                if( rc != LDAP_SUCCESS ) {
                        mra_free( ma, 1 );
                        return rc;
                }
-
-       } else {
-               *text = "matching without attribute description rule not supported";
-               return LDAP_INAPPROPRIATE_MATCHING;
        }
 
        if( ma->ma_rule_text.bv_val != NULL ) {
@@ -196,36 +187,53 @@ get_mra(
                }
        }
 
-       if( ma->ma_desc != NULL &&
-               ma->ma_desc->ad_type->sat_equality != NULL &&
-               ma->ma_desc->ad_type->sat_equality->smr_usage & SLAP_MR_EXT )
-       {
-               /* no matching rule was provided, use the attribute's
-                  equality rule if it supports extensible matching. */
-               ma->ma_rule = ma->ma_desc->ad_type->sat_equality;
+       if ( ma->ma_rule == NULL ) {
+               /*
+                * Need either type or rule ...
+                */
+               if ( ma->ma_desc == NULL ) {
+                       mra_free( ma, 1 );
+                       *text = "no matching rule or type";
+                       return LDAP_INAPPROPRIATE_MATCHING;
+               }
 
-       } else {
-               mra_free( ma, 1 );
-               return LDAP_INAPPROPRIATE_MATCHING;
-       }
+               if ( ma->ma_desc->ad_type->sat_equality != NULL &&
+                       ma->ma_desc->ad_type->sat_equality->smr_usage & SLAP_MR_EXT )
+               {
+                       /* no matching rule was provided, use the attribute's
+                          equality rule if it supports extensible matching. */
+                       ma->ma_rule = ma->ma_desc->ad_type->sat_equality;
 
-       /* check to see if the matching rule is appropriate for
-          the syntax of the attribute.  This check will need
-          to be extended to support other kinds of extensible
-          matching rules */
-       if( strcmp( ma->ma_rule->smr_syntax->ssyn_oid,
-               ma->ma_desc->ad_type->sat_syntax->ssyn_oid ) != 0 )
-       {
-               mra_free( ma, 1 );
-               return LDAP_INAPPROPRIATE_MATCHING;
+               } else {
+                       *text = "no appropriate rule to use for type";
+                       mra_free( ma, 1 );
+                       return LDAP_INAPPROPRIATE_MATCHING;
+               }
        }
 
-       /*
-        * OK, if no matching rule, normalize for equality, otherwise
-        * normalize for the matching rule.
-        */
-       rc = value_validate_normalize( ma->ma_desc, SLAP_MR_EQUALITY,
-               &value, &ma->ma_value, text );
+       if ( ma->ma_desc != NULL ) {
+               if( !mr_usable_with_at( ma->ma_rule, ma->ma_desc->ad_type ) ) {
+                       mra_free( ma, 1 );
+                       *text = "matching rule use with this attribute not appropriate";
+                       return LDAP_INAPPROPRIATE_MATCHING;
+               }
+
+               /*
+                * OK, if no matching rule, normalize for equality, otherwise
+                * normalize for the matching rule.
+                */
+               rc = value_validate_normalize( ma->ma_desc, SLAP_MR_EQUALITY,
+                       &value, &ma->ma_value, text );
+       } else {
+               /*
+                * Need to normalize, but how?
+                */
+               rc = value_validate( ma->ma_rule, &value, text );
+               if ( rc == LDAP_SUCCESS ) {
+                       ber_dupbv( &ma->ma_value, &value );
+               }
+
+       }
 
        if( rc != LDAP_SUCCESS ) {
                mra_free( ma, 1 );