]> git.sur5r.net Git - openldap/blobdiff - servers/slapd/schemaparse.c
make additional checking optional (more on ITS#5860)
[openldap] / servers / slapd / schemaparse.c
index 3dbc87233579b36fe5bf7c0973566c86d6079368..c02fdea215f2e38c16e84f3475f0bc8df79640d0 100644 (file)
@@ -1,8 +1,17 @@
 /* schemaparse.c - routines to parse config file objectclass definitions */
 /* $OpenLDAP$ */
-/*
- * Copyright 1998-1999 The OpenLDAP Foundation, All Rights Reserved.
- * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
+/* This work is part of OpenLDAP Software <http://www.openldap.org/>.
+ *
+ * Copyright 1998-2008 The OpenLDAP Foundation.
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted only as authorized by the OpenLDAP
+ * Public License.
+ *
+ * A copy of this license is available in the file LICENSE in the
+ * top-level directory of the distribution or, alternatively, at
+ * <http://www.OpenLDAP.org/license.html>.
  */
 
 #include "portable.h"
 
 #include "slap.h"
 #include "ldap_schema.h"
+#include "config.h"
 
-int    global_schemacheck = 1; /* schemacheck on is default */
-
-#ifdef SLAPD_SCHEMA_COMPAT
-static void            oc_usage_old(void) LDAP_GCCATTR((noreturn));
-#endif
-static void            oc_usage(void)     LDAP_GCCATTR((noreturn));
-static void            at_usage(void)     LDAP_GCCATTR((noreturn));
+static void            oc_usage(void); 
+static void            at_usage(void);
 
 static char *const err2text[] = {
-       "",
+       "Success",
        "Out of memory",
-       "Objectclass not found",
-       "Attribute type not found",
-       "Duplicate objectclass",
-       "Duplicate attributetype",
-       "Duplicate syntax",
-       "Duplicate matchingrule",
-       "OID or name required",
-       "Syntax or superior required",
-       "Matchingrule not found",
+       "ObjectClass not found",
+       "user-defined ObjectClass includes operational attributes",
+       "user-defined ObjectClass has inappropriate SUPerior",
+       "Duplicate objectClass",
+       "Inconsistent duplicate objectClass",
+       "AttributeType not found",
+       "AttributeType inappropriate matching rule",
+       "AttributeType inappropriate USAGE",
+       "AttributeType inappropriate SUPerior",
+       "AttributeType SYNTAX or SUPerior required",
+       "Duplicate attributeType",
+       "Inconsistent duplicate attributeType",
+       "MatchingRule not found",
+       "MatchingRule incomplete",
+       "Duplicate matchingRule",
        "Syntax not found",
-       "Syntax required"
+       "Duplicate ldapSyntax",
+       "Superior syntax not found",
+       "OID or name required",
+       "Qualifier not supported",
+       "Invalid NAME",
+       "OID could not be expanded",
+       "Duplicate Content Rule",
+       "Content Rule not for STRUCTURAL object class",
+       "Content Rule AUX contains inappropriate object class",
+       "Content Rule attribute type list contains duplicate",
+       NULL
 };
 
 char *
 scherr2str(int code)
 {
-       if ( code < 1 || code >= (sizeof(err2text)/sizeof(char *)) ) {
+       if ( code < 0 || SLAP_SCHERR_LAST <= code ) {
                return "Unknown error";
        } else {
                return err2text[code];
        }
 }
 
-#ifdef SLAPD_SCHEMA_COMPAT
-void
-parse_oc_old(
-    Backend    *be,
-    const char *fname,
-    int                lineno,
-    int                argc,
-    char       **argv
-)
+/* check schema descr validity */
+int slap_valid_descr( const char *descr )
 {
-       int             i;
-       char            last;
-       LDAP_OBJECT_CLASS       *oc;
-       int             code;
-       const char      *err;
-       char            **namep;
-
-       oc = (LDAP_OBJECT_CLASS *) ch_calloc( 1, sizeof(LDAP_OBJECT_CLASS) );
-       oc->oc_names = ch_calloc( 2, sizeof(char *) );
-       oc->oc_names[0] = ch_strdup( argv[1] );
-       oc->oc_names[1] = NULL;
-
-       if ( strcasecmp( oc->oc_names[0], "top" ) ) {
-               /*
-                * no way to distinguish "auxiliary" from "structural"
-                * This may lead to future problems.
-                */
-               oc->oc_kind = LDAP_SCHEMA_STRUCTURAL;
-       }
-       for ( i = 2; i < argc; i++ ) {
-               /* required attributes */
-               if ( strcasecmp( argv[i], "requires" ) == 0 ) {
-                       do {
-                               i++;
-                               if ( i < argc ) {
-                                       char **s = str2charray( argv[i], "," );
-                                       last = argv[i][strlen( argv[i] ) - 1];
-                                       charray_merge( &oc->oc_at_oids_must, s );
-                                       charray_free( s );
-                               }
-                       } while ( i < argc && last == ',' );
-
-               /* optional attributes */
-               } else if ( strcasecmp( argv[i], "allows" ) == 0 ) {
-                       do {
-                               i++;
-                               if ( i < argc ) {
-                                       char **s = str2charray( argv[i], "," );
-                                       last = argv[i][strlen( argv[i] ) - 1];
-                                       
-                                       charray_merge( &oc->oc_at_oids_may, s );
-                                       charray_free( s );
-                               }
-                       } while ( i < argc && last == ',' );
-
-               } else {
-                       fprintf( stderr,
-           "%s: line %d: expecting \"requires\" or \"allows\" got \"%s\"\n",
-                           fname, lineno, argv[i] );
-                       oc_usage_old();
-               }
-       }
+       int i=0;
 
-       /*
-        * There was no requirement in the old schema that all attributes
-        * types were defined before use and they would just default to
-        * SYNTAX_CIS.  To support this, we need to make attribute types
-        * out of thin air.
-        */
-       if ( oc->oc_at_oids_must ) {
-               for( namep = oc->oc_at_oids_must; *namep ; namep++ ) {
-                       code = at_fake_if_needed( *namep );
-                       if ( code ) {
-                               fprintf( stderr, "%s: line %d: %s %s\n",
-                                        fname, lineno, scherr2str(code), *namep);
-                               exit( EXIT_FAILURE );
-                       }
-               }
+       if( !DESC_LEADCHAR( descr[i] ) ) {
+               return 0;
        }
-       if ( oc->oc_at_oids_may ) {
-               for( namep = oc->oc_at_oids_may; *namep; namep++ ) {
-                       code = at_fake_if_needed( *namep );
-                       if ( code ) {
-                               fprintf( stderr, "%s: line %d: %s %s\n",
-                                        fname, lineno, scherr2str(code), *namep);
-                               exit( EXIT_FAILURE );
-                       }
+
+       while( descr[++i] ) {
+               if( !DESC_CHAR( descr[i] ) ) {
+                       return 0;
                }
        }
-       
-       code = oc_add(oc,&err);
-       if ( code ) {
-               fprintf( stderr, "%s: line %d: %s %s\n",
-                        fname, lineno, scherr2str(code), err);
-               exit( EXIT_FAILURE );
-       }
-       ldap_memfree(oc);
+
+       return 1;
 }
-#endif
+
 
 /* OID Macros */
 
@@ -168,248 +108,226 @@ dscompare(const char *s1, const char *s2, char delim)
        return 0;
 }
 
-static OidMacro *om_list = NULL;
-
-/* Replace an OID Macro invocation with its full numeric OID.
- * If the macro is used with "macroname:suffix" append ".suffix"
- * to the expansion.
- */
-static char *
-find_oidm(char *oid)
+static void
+cr_usage( void )
 {
-       OidMacro *om;
-       char *new;
-       int pos, suflen;
-
-       /* OID macros must start alpha */
-       if ( !isdigit( *oid ) )
-       {
-           for (om = om_list; om; om=om->som_next)
-           {
-               if ((pos = dscompare(om->som_name, oid, ':')))
-               {
-                       suflen = strlen(oid + pos);
-                       new = ch_calloc(1, om->som_oidlen + suflen + 1);
-                       strcpy(new, om->som_oid);
-                       if (suflen)
-                       {
-                               suflen = om->som_oidlen;
-                               new[suflen++] = '.';
-                               strcpy(new+suflen, oid+pos+1);
-                       }
-                       return new;
-               }
-           }
-           return NULL;
-       }
-       return oid;
+       fprintf( stderr,
+               "DITContentRuleDescription = \"(\" whsp\n"
+               "  numericoid whsp       ; StructuralObjectClass identifier\n"
+               "  [ \"NAME\" qdescrs ]\n"
+               "  [ \"DESC\" qdstring ]\n"
+               "  [ \"OBSOLETE\" whsp ]\n"
+               "  [ \"AUX\" oids ]      ; Auxiliary ObjectClasses\n"
+               "  [ \"MUST\" oids ]     ; AttributeTypes\n"
+               "  [ \"MAY\" oids ]      ; AttributeTypes\n"
+               "  [ \"NOT\" oids ]      ; AttributeTypes\n"
+               "  whsp \")\"\n" );
 }
 
-void
-parse_oidm(
-    const char *fname,
-    int                lineno,
-    int                argc,
-    char       **argv
-)
+int
+parse_cr(
+       struct config_args_s *c,
+       ContentRule     **scr )
 {
-       OidMacro *om;
-
-       if (argc != 3) {
-usage: fprintf( stderr, "ObjectIdentifier <name> <oid>\n");
-               exit( EXIT_FAILURE );
+       LDAPContentRule *cr;
+       int             code;
+       const char      *err;
+       char *line = strchr( c->line, '(' );
+
+       cr = ldap_str2contentrule( line, &code, &err, LDAP_SCHEMA_ALLOW_ALL );
+       if ( !cr ) {
+               snprintf( c->cr_msg, sizeof( c->cr_msg ), "%s: %s before %s",
+                       c->argv[0], ldap_scherr2str( code ), err );
+               Debug( LDAP_DEBUG_CONFIG|LDAP_DEBUG_NONE,
+                       "%s %s\n", c->log, c->cr_msg, 0 );
+               cr_usage();
+               return 1;
        }
 
-       om = (OidMacro *) ch_malloc( sizeof(OidMacro) );
-       om->som_name = ch_strdup( argv[1] );
-       om->som_oid = find_oidm( argv[2] );
+       if ( cr->cr_oid == NULL ) {
+               snprintf( c->cr_msg, sizeof( c->cr_msg ), "%s: OID is missing",
+                       c->argv[0] );
+               Debug( LDAP_DEBUG_CONFIG|LDAP_DEBUG_NONE,
+                       "%s %s\n", c->log, c->cr_msg, 0 );
+               cr_usage();
+               code = 1;
+               goto done;
+       }
 
-       if (!om->som_oid) {
-               fprintf( stderr, "%s: line %d: OID %s not recognized\n",
-                       fname, lineno, argv[2] );
-               goto usage;
+       code = cr_add( cr, 1, scr, &err );
+       if ( code ) {
+               snprintf( c->cr_msg, sizeof( c->cr_msg ), "%s: %s: \"%s\"",
+                       c->argv[0], scherr2str(code), err);
+               Debug( LDAP_DEBUG_CONFIG|LDAP_DEBUG_NONE,
+                       "%s %s\n", c->log, c->cr_msg, 0 );
+               code = 1;
+               goto done;
        }
 
-       if (om->som_oid == argv[2]) {
-               om->som_oid = ch_strdup( argv[2] );
+done:;
+       if ( code ) {
+               ldap_contentrule_free( cr );
+
+       } else {
+               ldap_memfree( cr );
        }
 
-       om->som_oidlen = strlen( om->som_oid );
-       om->som_next = om_list;
-       om_list = om;
+       return code;
 }
 
-void
+int
 parse_oc(
-    const char *fname,
-    int                lineno,
-    char       *line,
-    char       **argv
-)
+       struct config_args_s *c,
+       ObjectClass     **soc,
+       ObjectClass *prev )
 {
-       LDAP_OBJECT_CLASS *oc;
+       LDAPObjectClass *oc;
        int             code;
        const char      *err;
-       char            *oid = NULL;
+       char *line = strchr( c->line, '(' );
 
-       oc = ldap_str2objectclass(line,&code,&err);
+       oc = ldap_str2objectclass(line, &code, &err, LDAP_SCHEMA_ALLOW_ALL );
        if ( !oc ) {
-               fprintf( stderr, "%s: line %d: %s before %s\n",
-                        fname, lineno, ldap_scherr2str(code), err );
+               snprintf( c->cr_msg, sizeof( c->cr_msg ), "%s: %s before %s",
+                       c->argv[0], ldap_scherr2str( code ), err );
+               Debug( LDAP_DEBUG_CONFIG|LDAP_DEBUG_NONE,
+                       "%s %s\n", c->log, c->cr_msg, 0 );
                oc_usage();
+               return 1;
        }
-       if ( oc->oc_oid ) {
-               if ( !isdigit( oc->oc_oid[0] )) {
-                       /* Expand OID macros */
-                       oid = find_oidm( oc->oc_oid );
-                       if ( !oid ) {
-                               fprintf(stderr,
-                                       "%s: line %d: OID %s not recognized\n",
-                                       fname, lineno, oc->oc_oid);
-                               exit( EXIT_FAILURE );
-                       }
-                       if ( oid != oc->oc_oid ) {
-                               ldap_memfree( oc->oc_oid );
-                               oc->oc_oid = oid;
-                       }
-               }
+
+       if ( oc->oc_oid == NULL ) {
+               snprintf( c->cr_msg, sizeof( c->cr_msg ), "%s: OID is missing",
+                       c->argv[0] );
+               Debug( LDAP_DEBUG_CONFIG|LDAP_DEBUG_NONE,
+                       "%s %s\n", c->log, c->cr_msg, 0 );
+               oc_usage();
+               code = 1;
+               goto done;
        }
-       /* oc->oc_oid == NULL will be an error someday */
-       code = oc_add(oc,&err);
+
+       code = oc_add( oc, 1, soc, prev, &err );
        if ( code ) {
-               fprintf( stderr, "%s: line %d: %s %s\n",
-                        fname, lineno, scherr2str(code), err);
-               exit( EXIT_FAILURE );
+               snprintf( c->cr_msg, sizeof( c->cr_msg ), "%s: %s: \"%s\"",
+                       c->argv[0], scherr2str(code), err);
+               Debug( LDAP_DEBUG_CONFIG|LDAP_DEBUG_NONE,
+                       "%s %s\n", c->log, c->cr_msg, 0 );
+               code = 1;
+               goto done;
        }
-       ldap_memfree(oc);
-}
 
-static void
-oc_usage( void )
-{
-       fprintf( stderr, "ObjectClassDescription = \"(\" whsp\n");
-       fprintf( stderr, "  numericoid whsp      ; ObjectClass identifier\n");
-       fprintf( stderr, "  [ \"NAME\" qdescrs ]\n");
-       fprintf( stderr, "  [ \"DESC\" qdstring ]\n");
-       fprintf( stderr, "  [ \"OBSOLETE\" whsp ]\n");
-       fprintf( stderr, "  [ \"SUP\" oids ]       ; Superior ObjectClasses\n");
-       fprintf( stderr, "  [ ( \"ABSTRACT\" / \"STRUCTURAL\" / \"AUXILIARY\" ) whsp ]\n");
-       fprintf( stderr, "                       ; default structural\n");
-       fprintf( stderr, "  [ \"MUST\" oids ]      ; AttributeTypes\n");
-       fprintf( stderr, "  [ \"MAY\" oids ]       ; AttributeTypes\n");
-       fprintf( stderr, "whsp \")\"\n");
-       exit( EXIT_FAILURE );
+done:;
+       if ( code ) {
+               ldap_objectclass_free( oc );
+
+       } else {
+               ldap_memfree( oc );
+       }
+
+       return code;
 }
 
-#ifdef SLAPD_SCHEMA_COMPAT
 static void
-oc_usage_old( void )
+oc_usage( void )
 {
-       fprintf( stderr, "<oc clause> ::= objectclass <ocname>\n" );
-       fprintf( stderr, "                [ requires <attrlist> ]\n" );
-       fprintf( stderr, "                [ allows <attrlist> ]\n" );
-       exit( EXIT_FAILURE );
+       fprintf( stderr,
+               "ObjectClassDescription = \"(\" whsp\n"
+               "  numericoid whsp                 ; ObjectClass identifier\n"
+               "  [ \"NAME\" qdescrs ]\n"
+               "  [ \"DESC\" qdstring ]\n"
+               "  [ \"OBSOLETE\" whsp ]\n"
+               "  [ \"SUP\" oids ]                ; Superior ObjectClasses\n"
+               "  [ ( \"ABSTRACT\" / \"STRUCTURAL\" / \"AUXILIARY\" ) whsp ]\n"
+               "                                  ; default structural\n"
+               "  [ \"MUST\" oids ]               ; AttributeTypes\n"
+               "  [ \"MAY\" oids ]                ; AttributeTypes\n"
+               "  whsp \")\"\n" );
 }
-#endif
 
 static void
 at_usage( void )
 {
-       fprintf( stderr, "AttributeTypeDescription = \"(\" whsp\n");
-       fprintf( stderr, "  numericoid whsp      ; AttributeType identifier\n");
-       fprintf( stderr, "  [ \"NAME\" qdescrs ]             ; name used in AttributeType\n");
-       fprintf( stderr, "  [ \"DESC\" qdstring ]            ; description\n");
-       fprintf( stderr, "  [ \"OBSOLETE\" whsp ]\n");
-       fprintf( stderr, "  [ \"SUP\" woid ]                 ; derived from this other\n");
-       fprintf( stderr, "                                 ; AttributeType\n");
-       fprintf( stderr, "  [ \"EQUALITY\" woid ]            ; Matching Rule name\n");
-        fprintf( stderr, "  [ \"ORDERING\" woid ]            ; Matching Rule name\n");
-       fprintf( stderr, "  [ \"SUBSTR\" woid ]              ; Matching Rule name\n");
-       fprintf( stderr, "  [ \"SYNTAX\" whsp noidlen whsp ] ; see section 4.3\n");
-       fprintf( stderr, "  [ \"SINGLE-VALUE\" whsp ]        ; default multi-valued\n");
-       fprintf( stderr, "  [ \"COLLECTIVE\" whsp ]          ; default not collective\n");
-       fprintf( stderr, "  [ \"NO-USER-MODIFICATION\" whsp ]; default user modifiable\n");
-       fprintf( stderr, "  [ \"USAGE\" whsp AttributeUsage ]; default userApplications\n");
-       fprintf( stderr, "                                 ; userApplications\n");
-       fprintf( stderr, "                                 ; directoryOperation\n");
-       fprintf( stderr, "                                 ; distributedOperation\n");
-       fprintf( stderr, "                                 ; dSAOperation\n");
-       fprintf( stderr, "whsp \")\"\n");
-       exit( EXIT_FAILURE );
+       fprintf( stderr, "%s%s%s",
+               "AttributeTypeDescription = \"(\" whsp\n"
+               "  numericoid whsp      ; AttributeType identifier\n"
+               "  [ \"NAME\" qdescrs ]             ; name used in AttributeType\n"
+               "  [ \"DESC\" qdstring ]            ; description\n"
+               "  [ \"OBSOLETE\" whsp ]\n"
+               "  [ \"SUP\" woid ]                 ; derived from this other\n"
+               "                                   ; AttributeType\n",
+               "  [ \"EQUALITY\" woid ]            ; Matching Rule name\n"
+               "  [ \"ORDERING\" woid ]            ; Matching Rule name\n"
+               "  [ \"SUBSTR\" woid ]              ; Matching Rule name\n"
+               "  [ \"SYNTAX\" whsp noidlen whsp ] ; see section 4.3\n"
+               "  [ \"SINGLE-VALUE\" whsp ]        ; default multi-valued\n"
+               "  [ \"COLLECTIVE\" whsp ]          ; default not collective\n",
+               "  [ \"NO-USER-MODIFICATION\" whsp ]; default user modifiable\n"
+               "  [ \"USAGE\" whsp AttributeUsage ]; default userApplications\n"
+               "                                   ; userApplications\n"
+               "                                   ; directoryOperation\n"
+               "                                   ; distributedOperation\n"
+               "                                   ; dSAOperation\n"
+               "  whsp \")\"\n");
 }
 
-void
+int
 parse_at(
-    const char *fname,
-    int                lineno,
-    char       *line,
-    char       **argv
-)
+       struct config_args_s *c,
+       AttributeType   **sat,
+       AttributeType   *prev )
 {
-       LDAP_ATTRIBUTE_TYPE *at;
+       LDAPAttributeType *at;
        int             code;
        const char      *err;
-       char            *oid = NULL;
-       char            *soid = NULL;
-
-       /* Kludge for OIDmacros for syntaxes. If the syntax field starts
-        * nonnumeric, look for and expand a macro. The macro's place in
-        * the input line will be replaced with a field of '0's to keep
-        * ldap_str2attributetype happy. The actual oid will be swapped
-        * into place afterwards.
-        */
-       for (; argv[3]; argv++)
-       {
-               if (!strcasecmp(argv[3], "syntax") &&
-                   !isdigit(*argv[4]))
-               {
-                       int slen;
-                       Syntax *syn;
-                       syn = syn_find_desc(argv[4], &slen);
-                       if (!syn)
-                       {
-                           fprintf(stderr, "%s: line %d: OID %s not found\n",
-                               fname, lineno, argv[4]);
-                           exit( EXIT_FAILURE );
-                       }
-                       memset(strstr(line, argv[4]), '0', slen);
-                       soid = ch_strdup(syn->ssyn_syn.syn_oid );
-                       break;
-               }
-       }
-       at = ldap_str2attributetype(line,&code,&err);
+       char *line = strchr( c->line, '(' );
+
+       at = ldap_str2attributetype( line, &code, &err, LDAP_SCHEMA_ALLOW_ALL );
        if ( !at ) {
-               fprintf( stderr, "%s: line %d: %s before %s\n",
-                        fname, lineno, ldap_scherr2str(code), err );
+               snprintf( c->cr_msg, sizeof( c->cr_msg ), "%s: %s before %s",
+                       c->argv[0], ldap_scherr2str(code), err );
+               Debug( LDAP_DEBUG_CONFIG|LDAP_DEBUG_NONE,
+                       "%s %s\n", c->log, c->cr_msg, 0 );
                at_usage();
+               return 1;
        }
-       if ( at->at_oid ) {
-               if ( !isdigit( at->at_oid[0] )) {
-                       /* Expand OID macros */
-                       oid = find_oidm( at->at_oid );
-                       if ( !oid ) {
-                               fprintf(stderr,
-                                       "%s: line %d: OID %s not recognized\n",
-                                       fname, lineno, at->at_oid);
-                               exit( EXIT_FAILURE );
-                       }
-                       if ( oid != at->at_oid ) {
-                               ldap_memfree( at->at_oid );
-                               at->at_oid = oid;
-                       }
-               }
+
+       if ( at->at_oid == NULL ) {
+               snprintf( c->cr_msg, sizeof( c->cr_msg ), "%s: OID is missing",
+                       c->argv[0] );
+               Debug( LDAP_DEBUG_CONFIG|LDAP_DEBUG_NONE,
+                       "%s %s\n", c->log, c->cr_msg, 0 );
+               at_usage();
+               code = 1;
+               goto done;
+       }
+
+       /* operational attributes should be defined internally */
+       if ( at->at_usage ) {
+               snprintf( c->cr_msg, sizeof( c->cr_msg ), "%s: \"%s\" is operational",
+                       c->argv[0], at->at_oid );
+               Debug( LDAP_DEBUG_CONFIG|LDAP_DEBUG_NONE,
+                       "%s %s\n", c->log, c->cr_msg, 0 );
+               code = 1;
+               goto done;
        }
-       /* at->at_oid == NULL will be an error someday */
-       if (soid)
-       {
-               ldap_memfree(at->at_syntax_oid);
-               at->at_syntax_oid = soid;
+
+       code = at_add( at, 1, sat, prev, &err);
+       if ( code ) {
+               snprintf( c->cr_msg, sizeof( c->cr_msg ), "%s: %s: \"%s\"",
+                       c->argv[0], scherr2str(code), err);
+               Debug( LDAP_DEBUG_CONFIG|LDAP_DEBUG_NONE,
+                       "%s %s\n", c->log, c->cr_msg, 0 );
+               code = 1;
+               goto done;
        }
-       code = at_add(at,&err);
+
+done:;
        if ( code ) {
-               fprintf( stderr, "%s: line %d: %s %s\n",
-                        fname, lineno, scherr2str(code), err);
-               exit( EXIT_FAILURE );
+               ldap_attributetype_free( at );
+
+       } else {
+               ldap_memfree( at );
        }
-       ldap_memfree(at);
+
+       return code;
 }