#include <ac/unistd.h>
#include "slap.h"
+
+#ifdef LDAP_SLAPI
#include "slapi.h"
+#endif
static char *v2ref( BerVarray ref, const char *text )
{
text, ref, resoid, resdata, sasldata, ctrls );
return;
}
+
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp)
+ ber = op->o_res_ber;
+ else
+#endif
ber_init_w_nullc( ber, LBER_USE_DER );
}
#ifdef LDAP_CONNECTIONLESS
- if( conn->c_is_udp ) {
- rc = ber_write(ber,
- (char *)&op->o_peeraddr, sizeof(struct sockaddr), 0);
- if (rc != sizeof(struct sockaddr)) {
-#ifdef NEW_LOGGING
- LDAP_LOG( OPERATION, ERR,
- "send_ldap_response: conn %lu ber_write failed\n",
- conn ? conn->c_connid : 0 , 0, 0);
-#else
- Debug( LDAP_DEBUG_ANY, "ber_write failed\n", 0, 0, 0 );
-#endif
- ber_free_buf( ber );
- return;
- }
- }
if (conn->c_is_udp && op->o_protocol == LDAP_VERSION2) {
- rc = ber_printf( ber, "{is{t{ess" /*"}}}"*/,
- msgid, "", tag, err,
+ rc = ber_printf( ber, "t{ess" /*"}}"*/,
+ tag, err,
matched == NULL ? "" : matched,
text == NULL ? "" : text );
- } else
+ } else
#endif
{
rc = ber_printf( ber, "{it{ess" /*"}}"*/,
rc = ber_printf( ber, /*"{"*/ "N}" );
}
#endif
-
+
if ( rc == -1 ) {
#ifdef NEW_LOGGING
LDAP_LOG( OPERATION, ERR,
Debug( LDAP_DEBUG_ANY, "ber_printf failed\n", 0, 0, 0 );
#endif
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0)
+#endif
ber_free_buf( ber );
return;
}
/* send BER */
bytes = send_ldap_ber( conn, ber );
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0)
+#endif
ber_free_buf( ber );
if ( bytes < 0 ) {
assert( err != LDAP_PARTIAL_RESULTS );
if ( err == LDAP_REFERRAL ) {
+#ifdef LDAP_CONTROL_X_DOMAIN_SCOPE
+ if( op->o_domain_scope ) {
+ ref = NULL;
+ }
+#endif
if( ref == NULL ) {
err = LDAP_NO_SUCH_OBJECT;
} else if ( op->o_protocol < LDAP_VERSION3 ) {
rspoid, rspdata, NULL, ctrls );
}
+#ifdef LDAP_RES_INTERMEDIATE_RESP
+void
+slap_send_ldap_intermediate_resp(
+ Connection *conn,
+ Operation *op,
+ ber_int_t err,
+ const char *matched,
+ const char *text,
+ BerVarray refs,
+ const char *rspoid,
+ struct berval *rspdata,
+ LDAPControl **ctrls )
+{
+ ber_tag_t tag;
+ ber_int_t msgid;
+#ifdef NEW_LOGGING
+ LDAP_LOG( OPERATION, ENTRY,
+ "send_ldap_intermediate: err=%d oid=%s len=%ld\n",
+ err, rspoid ? rspoid : "",
+ rspdata != NULL ? rspdata->bv_len : 0 );
+#else
+ Debug( LDAP_DEBUG_TRACE,
+ "send_ldap_intermediate: err=%d oid=%s len=%ld\n",
+ err,
+ rspoid ? rspoid : "",
+ rspdata != NULL ? rspdata->bv_len : 0 );
+#endif
+ tag = LDAP_RES_INTERMEDIATE_RESP;
+ msgid = (tag != LBER_SEQUENCE) ? op->o_msgid : 0;
+ send_ldap_response( conn, op, tag, msgid,
+ err, matched, text, refs,
+ rspoid, rspdata, NULL, ctrls );
+}
+#endif
void
slap_send_search_result(
int opattrs;
AccessControlState acl_state = ACL_STATE_INIT;
#ifdef LDAP_SLAPI
- /* Support virtual attribute plugins. */
- Slapi_PBlock *pb = op->o_pb;
- Slapi_AttrSet *vattrs = NULL;
+ /* Support for computed attribute plugins */
+ computed_attr_context ctx;
+ AttributeName *anp;
#endif
AttributeDescription *ad_entry = slap_schema.si_ad_entry;
edn = e->e_ndn;
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp)
+ ber = op->o_res_ber;
+ else
+#endif
ber_init_w_nullc( ber, LBER_USE_DER );
#ifdef LDAP_CONNECTIONLESS
- if (conn->c_is_udp) {
- rc = ber_write(ber,
- (char *)&op->o_peeraddr, sizeof(struct sockaddr), 0);
- if (rc != sizeof(struct sockaddr)) {
-#ifdef NEW_LOGGING
- LDAP_LOG( OPERATION, ERR,
- "send_search_entry: conn %lu ber_write failed\n",
- conn ? conn->c_connid : 0, 0, 0 );
-#else
- Debug( LDAP_DEBUG_ANY, "ber_write failed\n", 0, 0, 0 );
-#endif
- ber_free_buf( ber );
- return( 1 );
- }
- }
if (conn->c_is_udp && op->o_protocol == LDAP_VERSION2) {
- rc = ber_printf( ber, "{is{t{O{" /*}}}*/,
- op->o_msgid, "", LDAP_RES_SEARCH_ENTRY, &e->e_name );
+ rc = ber_printf(ber, "t{O{" /*}}*/,
+ LDAP_RES_SEARCH_ENTRY, &e->e_name);
} else
-#endif /* LDAP_CONNECTIONLESS */
+#endif
{
rc = ber_printf( ber, "{it{O{" /*}}}*/, op->o_msgid,
LDAP_RES_SEARCH_ENTRY, &e->e_name );
Debug( LDAP_DEBUG_ANY, "ber_printf failed\n", 0, 0, 0 );
#endif
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0)
+#endif
ber_free_buf( ber );
send_ldap_result( conn, op, LDAP_OTHER,
NULL, "encoding DN error", NULL, NULL );
#else
Debug( LDAP_DEBUG_ANY,
"matched values filtering failed\n", 0, 0, 0 );
+#endif
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0)
#endif
ber_free( ber, 1 );
Debug( LDAP_DEBUG_ANY, "ber_printf failed\n", 0, 0, 0 );
#endif
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0)
+#endif
ber_free_buf( ber );
send_ldap_result( conn, op, LDAP_OTHER,
NULL, "encoding description error", NULL, NULL );
"ber_printf failed\n", 0, 0, 0 );
#endif
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0)
+#endif
ber_free_buf( ber );
send_ldap_result( conn, op, LDAP_OTHER,
NULL, "encoding values error",
Debug( LDAP_DEBUG_ANY, "ber_printf failed\n", 0, 0, 0 );
#endif
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0)
+#endif
ber_free_buf( ber );
send_ldap_result( conn, op, LDAP_OTHER,
NULL, "encode end error", NULL, NULL );
#else
Debug( LDAP_DEBUG_ANY,
"matched values filtering failed\n", 0, 0, 0 );
+#endif
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0)
#endif
ber_free( ber, 1 );
Debug( LDAP_DEBUG_ANY, "ber_printf failed\n", 0, 0, 0 );
#endif
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0)
+#endif
ber_free_buf( ber );
send_ldap_result( conn, op, LDAP_OTHER,
NULL, "encoding description error", NULL, NULL );
"ber_printf failed\n", 0, 0, 0 );
#endif
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0)
+#endif
ber_free_buf( ber );
send_ldap_result( conn, op, LDAP_OTHER,
NULL, "encoding values error",
Debug( LDAP_DEBUG_ANY, "ber_printf failed\n", 0, 0, 0 );
#endif
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0)
+#endif
ber_free_buf( ber );
send_ldap_result( conn, op, LDAP_OTHER,
NULL, "encode end error", NULL, NULL );
}
}
-#if defined( LDAP_SLAPI )
- /* Add virtual attributes */
- vattrs = slapi_x_attrset_new();
- slapi_pblock_set( pb, SLAPI_SEARCH_RESULT_ENTRY, (void *)e );
- slapi_pblock_set( pb, SLAPI_PLUGIN_OPATTR_COALESCE_DATA, (void *)vattrs );
- rc = doPluginFNs( be, SLAPI_PLUGIN_OPATTR_COALESCE_FN, pb );
- if ( rc == 0 ) {
+#ifdef LDAP_SLAPI
+ /*
+ * First, setup the computed attribute context that is
+ * passed to all plugins.
+ */
+ ctx.cac_pb = op->o_pb;
+ ctx.cac_attrs = attrs;
+ ctx.cac_attrsonly = attrsonly;
+ ctx.cac_userattrs = userattrs;
+ ctx.cac_opattrs = opattrs;
+ ctx.cac_acl_state = acl_state;
+ ctx.cac_private = (void *)ber;
+
+ /*
+ * For each client requested attribute, call the plugins.
+ */
+ if ( attrs != NULL ) {
+ for ( anp = attrs; anp->an_name.bv_val != NULL; anp++ ) {
+ rc = compute_evaluator( &ctx, anp->an_name.bv_val, e, slapi_x_compute_output_ber );
+ if ( rc == 1 ) {
+ break;
+ }
+ }
+ } else {
/*
- * Re-fetch this to be safe; plugin could have freed and
- * changed it, although it shouldn't.
+ * Technically we shouldn't be returning operational attributes
+ * when the user requested only user attributes. We'll let the
+ * plugin decide whether to be naughty or not.
*/
- rc = slapi_pblock_get( pb, SLAPI_PLUGIN_OPATTR_COALESCE_DATA, (void **)&vattrs );
- if ( rc != 0 ) {
- /* Something bad happened. */
- vattrs = NULL;
- }
+ rc = compute_evaluator( &ctx, "*", e, slapi_x_compute_output_ber );
}
-
- /* Now, send the virtual attributes. */
- if ( vattrs != NULL ) {
- for (a = *vattrs, j = 0; a != NULL; a = a->a_next, j++ ) {
- AttributeDescription *desc = a->a_desc;
-
- if ( attrs == NULL ) {
- /* all attrs request, skip operational attributes */
- if( is_at_operational( desc->ad_type ) ) {
- continue;
- }
-
- } else {
- /* specific attrs requested */
- if( is_at_operational( desc->ad_type ) ) {
- if( !opattrs && !ad_inlist( desc, attrs ) ) {
- continue;
- }
- } else {
- if (!userattrs && !ad_inlist( desc, attrs ) )
- {
- continue;
- }
- }
- }
-
- if ( ! access_allowed( be, conn, op, e, desc, NULL,
- ACL_READ, &acl_state ) )
- {
-#ifdef NEW_LOGGING
- LDAP_LOG( ACL, INFO,
- "send_search_entry: conn %lu "
- "access to attribute %s not allowed\n",
- op->o_connid, desc->ad_cname.bv_val, 0 );
-#else
- Debug( LDAP_DEBUG_ACL, "acl: access to attribute %s "
- "not allowed\n",
- desc->ad_cname.bv_val, 0, 0 );
-#endif
-
- continue;
- }
-
- rc = ber_printf( ber, "{O[" /*]}*/ , &desc->ad_cname );
- if ( rc == -1 ) {
-#ifdef NEW_LOGGING
- LDAP_LOG( OPERATION, ERR,
- "send_search_entry: conn %lu "
- "ber_printf failed\n", op->o_connid, 0, 0 );
-#else
- Debug( LDAP_DEBUG_ANY, "ber_printf failed\n", 0, 0, 0 );
-#endif
-
- ber_free_buf( ber );
- send_ldap_result( conn, op, LDAP_OTHER,
- NULL, "encoding description error", NULL, NULL );
-
- attrs_free( aa );
- goto error_return;
- }
-
- if ( ! attrsonly ) {
- for ( i = 0; a->a_vals[i].bv_val != NULL; i++ ) {
- if ( ! access_allowed( be, conn, op, e,
- desc, &a->a_vals[i], ACL_READ, &acl_state ) )
- {
-#ifdef NEW_LOGGING
- LDAP_LOG( ACL, INFO,
- "send_search_entry: conn %lu "
- "access to %s, value %d not allowed\n",
- op->o_connid, desc->ad_cname.bv_val, i );
-#else
- Debug( LDAP_DEBUG_ACL,
- "acl: access to attribute %s, "
- "value %d not allowed\n",
- desc->ad_cname.bv_val, i, 0 );
-#endif
-
- continue;
- }
-
- if ( op->vrFilter && e_flags[j][i] == 0 ){
- continue;
- }
-
- if (( rc = ber_printf( ber, "O", &a->a_vals[i] )) == -1 ) {
-#ifdef NEW_LOGGING
- LDAP_LOG( OPERATION, ERR,
- "send_search_entry: conn %lu ber_printf failed\n",
- op->o_connid, 0, 0 );
-#else
- Debug( LDAP_DEBUG_ANY,
- "ber_printf failed\n", 0, 0, 0 );
-#endif
-
- ber_free_buf( ber );
- send_ldap_result( conn, op, LDAP_OTHER,
- NULL, "encoding values error",
- NULL, NULL );
-
- attrs_free( aa );
- goto error_return;
- }
- }
- }
-
- if (( rc = ber_printf( ber, /*{[*/ "]N}" )) == -1 ) {
-#ifdef NEW_LOGGING
- LDAP_LOG( OPERATION, ERR,
- "send_search_entry: conn %lu ber_printf failed\n",
- op->o_connid, 0, 0 );
-#else
- Debug( LDAP_DEBUG_ANY, "ber_printf failed\n", 0, 0, 0 );
-#endif
-
- ber_free_buf( ber );
- send_ldap_result( conn, op, LDAP_OTHER,
- NULL, "encode end error", NULL, NULL );
-
- attrs_free( aa );
- goto error_return;
- }
- }
- slapi_x_attrset_free( &vattrs );
- slapi_pblock_set( pb, SLAPI_SEARCH_RESULT_ENTRY, NULL );
- slapi_pblock_set( pb, SLAPI_PLUGIN_OPATTR_COALESCE_DATA, NULL );
+ if ( rc == 1 ) {
+ ber_free_buf( ber );
+ send_ldap_result( conn, op, LDAP_OTHER,
+ NULL, "computed attribute error", NULL, NULL );
+ goto error_return;
}
#endif /* LDAP_SLAPI */
rc = send_ldap_controls( ber, ctrls );
}
+#ifdef LDAP_CONNECTIONLESS
+ if( conn->c_is_udp && op->o_protocol == LDAP_VERSION2 ) {
+ ; /* empty, skip following if */
+ } else
+#endif
if( rc != -1 ) {
rc = ber_printf( ber, /*{*/ "N}" );
}
-#ifdef LDAP_CONNECTIONLESS
- if (conn->c_is_udp && op->o_protocol == LDAP_VERSION2 && rc != -1) {
- rc = ber_printf( ber, "}" );
- }
-#endif
if ( rc == -1 ) {
#ifdef NEW_LOGGING
LDAP_LOG( OPERATION, ERR,
Debug( LDAP_DEBUG_ANY, "ber_printf failed\n", 0, 0, 0 );
#endif
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0)
+#endif
ber_free_buf( ber );
send_ldap_result( conn, op, LDAP_OTHER,
NULL, "encode entry end error", NULL, NULL );
return( 1 );
}
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0) {
+#endif
bytes = op->o_noop ? 0 : send_ldap_ber( conn, ber );
ber_free_buf( ber );
num_pdu_sent++;
ldap_pvt_thread_mutex_unlock( &num_sent_mutex );
+#ifdef LDAP_CONNECTIONLESS
+ }
+#endif
+
Statslog( LDAP_DEBUG_STATS2, "conn=%lu op=%lu ENTRY dn=\"%s\"\n",
conn->c_connid, op->o_opid, e->e_dn, 0, 0 );
AttributeDescription *ad_ref = slap_schema.si_ad_ref;
AttributeDescription *ad_entry = slap_schema.si_ad_entry;
+ if (op->o_callback && op->o_callback->sc_sendreference) {
+ return op->o_callback->sc_sendreference( be, conn, op, e, refs, ctrls, v2refs );
+ }
+
#ifdef NEW_LOGGING
LDAP_LOG( OPERATION, ENTRY,
"send_search_reference: conn %lu dn=\"%s\"\n",
e ? e->e_dn : "(null)", 0, 0 );
#endif
-
if ( e && ! access_allowed( be, conn, op, e,
ad_entry, NULL, ACL_READ, NULL ) )
{
return( 1 );
}
+#ifdef LDAP_CONTROL_X_DOMAIN_SCOPE
+ if( op->o_domain_scope ) {
+#ifdef NEW_LOGGING
+ LDAP_LOG( OPERATION, ERR,
+ "send_search_reference: conn %lu domainScope control in (%s).\n",
+ op->o_connid, e->e_dn, 0 );
+#else
+ Debug( LDAP_DEBUG_ANY,
+ "send_search_reference: domainScope control in (%s)\n",
+ e->e_dn, 0, 0 );
+#endif
+
+ return( 0 );
+ }
+#endif
+
if( refs == NULL ) {
#ifdef NEW_LOGGING
LDAP_LOG( OPERATION, ERR,
return 0;
}
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp)
+ ber = op->o_res_ber;
+ else
+#endif
ber_init_w_nullc( ber, LBER_USE_DER );
rc = ber_printf( ber, "{it{W}" /*"}"*/ , op->o_msgid,
"send_search_reference: ber_printf failed\n", 0, 0, 0 );
#endif
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0)
+#endif
ber_free_buf( ber );
send_ldap_result( conn, op, LDAP_OTHER,
NULL, "encode DN error", NULL, NULL );
return -1;
}
+#ifdef LDAP_CONNECTIONLESS
+ if (conn->c_is_udp == 0) {
+#endif
bytes = op->o_noop ? 0 : send_ldap_ber( conn, ber );
ber_free_buf( ber );
num_refs_sent++;
num_pdu_sent++;
ldap_pvt_thread_mutex_unlock( &num_sent_mutex );
+#ifdef LDAP_CONNECTIONLESS
+ }
+#endif
Statslog( LDAP_DEBUG_STATS2, "conn=%lu op=%lu REF dn=\"%s\"\n",
conn->c_connid, op->o_opid, e ? e->e_dn : "(null)", 0, 0 );