]> git.sur5r.net Git - openldap/blobdiff - servers/slapd/slapadd.c
add slapo-rdnval in support to Samba4
[openldap] / servers / slapd / slapadd.c
index 2d648278161dd4b3fb3950d685b9ee61366a8347..fe205eafb5f00bff907d0a83a8c2c3845be565a6 100644 (file)
@@ -1,7 +1,7 @@
 /* $OpenLDAP$ */
 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
  *
- * Copyright 1998-2004 The OpenLDAP Foundation.
+ * Copyright 1998-2010 The OpenLDAP Foundation.
  * Portions Copyright 1998-2003 Kurt D. Zeilenga.
  * Portions Copyright 2003 IBM Corporation.
  * All rights reserved.
 #include <lber.h>
 #include <ldif.h>
 #include <lutil.h>
+#include <lutil_meter.h>
+#include <sys/stat.h>
 
 #include "slapcommon.h"
 
-static char csnbuf[ LDAP_LUTIL_CSNSTR_BUFSIZE ];
-static const struct berval slap_syncrepl_bvc = BER_BVC("syncreplxxx");
-static const struct berval slap_syncrepl_cn_bvc = BER_BVC("cn=syncreplxxx");
-static struct berval slap_syncrepl_bv = BER_BVNULL;
-static struct berval slap_syncrepl_cn_bv = BER_BVNULL;
-
-struct subentryinfo {
-       struct berval cn;
-       struct berval ndn;
-       struct berval rdn;
-       struct berval cookie;
-       LDAP_SLIST_ENTRY( subentryinfo ) sei_next;
-};
+static char csnbuf[ LDAP_PVT_CSNSTR_BUFSIZE ];
+static char maxcsnbuf[ LDAP_PVT_CSNSTR_BUFSIZE * ( SLAP_SYNC_SID_MAX + 1 ) ];
 
 int
 slapadd( int argc, char **argv )
 {
-       char            *buf = NULL;
-       int         lineno;
-       int         lmax;
-       int                     rc = EXIT_SUCCESS;
-
+       char *buf = NULL;
        const char *text;
        char textbuf[SLAP_TEXT_BUFLEN] = { '\0' };
        size_t textlen = sizeof textbuf;
        const char *progname = "slapadd";
 
        struct berval csn;
-       struct berval maxcsn = BER_BVNULL;
-       struct berval ldifcsn = BER_BVNULL;
-       int match;
-       int     provider_subentry = 0;
-       struct subentryinfo *sei;
-       LDAP_SLIST_HEAD( consumer_subentry_slist, subentryinfo ) consumer_subentry;
+       struct berval maxcsn[ SLAP_SYNC_SID_MAX + 1 ];
+       unsigned long sid;
+       struct berval bvtext;
        Attribute *attr;
        Entry *ctxcsn_e;
-       ID      ctxcsn_id;
-       struct berval   ctxcsn_ndn = BER_BVNULL;
-       int ret;
-       struct berval bvtext;
-       int i;
-       struct berval mc;
-       struct sync_cookie sc;
+       ID      ctxcsn_id, id;
+       OperationBuffer opbuf;
+       Operation *op;
+
+       int match;
+       int checkvals;
+       int lineno, nextline, ldifrc;
+       int lmax;
+       int rc = EXIT_SUCCESS;
+       int manage = 0; 
+
+       int enable_meter = 0;
+       lutil_meter_t meter;
+       struct stat stat_buf;
+
+       /* default "000" */
+       csnsid = 0;
+
+       if ( isatty (2) ) enable_meter = 1;
        slap_tool_init( progname, SLAPADD, argc, argv );
 
-       LDAP_SLIST_INIT( &consumer_subentry );
+       memset( &opbuf, 0, sizeof(opbuf) );
+       op = &opbuf.ob_op;
+       op->o_hdr = &opbuf.ob_hdr;
 
        if( !be->be_entry_open ||
                !be->be_entry_close ||
-               !be->be_entry_put )
+               !be->be_entry_put ||
+               (update_ctxcsn &&
+                (!be->be_dn2id_get ||
+                 !be->be_entry_get ||
+                 !be->be_entry_modify)) )
        {
                fprintf( stderr, "%s: database doesn't support necessary operations.\n",
                        progname );
@@ -99,8 +101,15 @@ slapadd( int argc, char **argv )
                }
        }
 
+       checkvals = (slapMode & SLAP_TOOL_QUICK) ? 0 : 1;
+
        lmax = 0;
-       lineno = 0;
+       nextline = 0;
+
+       /* enforce schema checking unless not disabled */
+       if ( (slapMode & SLAP_TOOL_NO_SCHEMA_CHECK) == 0) {
+               SLAP_DBFLAGS(be) &= ~(SLAP_DBFLAG_NO_SCHEMA_CHECK);
+       }
 
        if( !dryrun && be->be_entry_open( be, 1 ) != 0 ) {
                fprintf( stderr, "%s: could not open database.\n",
@@ -108,8 +117,46 @@ slapadd( int argc, char **argv )
                exit( EXIT_FAILURE );
        }
 
-       while( ldif_read_record( ldiffp, &lineno, &buf, &lmax ) ) {
-               Entry *e = str2entry( buf );
+       if ( update_ctxcsn ) {
+               maxcsn[ 0 ].bv_val = maxcsnbuf;
+               for ( sid = 1; sid <= SLAP_SYNC_SID_MAX; sid++ ) {
+                       maxcsn[ sid ].bv_val = maxcsn[ sid - 1 ].bv_val + LDAP_PVT_CSNSTR_BUFSIZE;
+                       maxcsn[ sid ].bv_len = 0;
+               }
+       }
+
+       if ( enable_meter 
+#ifdef LDAP_DEBUG
+               /* tools default to "none" */
+               && slap_debug == LDAP_DEBUG_NONE
+#endif
+               && !fstat ( fileno ( ldiffp->fp ), &stat_buf )
+               && S_ISREG(stat_buf.st_mode) ) {
+               enable_meter = !lutil_meter_open(
+                       &meter,
+                       &lutil_meter_text_display,
+                       &lutil_meter_linear_estimator,
+                       stat_buf.st_size);
+       } else {
+               enable_meter = 0;
+       }
+
+       /* nextline is the line number of the end of the current entry */
+       for( lineno=1; ( ldifrc = ldif_read_record( ldiffp, &nextline, &buf, &lmax )) > 0;
+               lineno=nextline+1 )
+       {
+               BackendDB *bd;
+               Entry *e;
+
+               if ( lineno < jumpline )
+                       continue;
+
+               e = str2entry2( buf, checkvals );
+
+               if ( enable_meter )
+                       lutil_meter_update( &meter,
+                                        ftell( ldiffp->fp ),
+                                        0);
 
                /*
                 * Initialize text buffer
@@ -127,9 +174,29 @@ slapadd( int argc, char **argv )
                }
 
                /* make sure the DN is not empty */
-               if( !e->e_nname.bv_len ) {
-                       fprintf( stderr, "%s: empty dn=\"%s\" (line=%d)\n",
-                               progname, e->e_dn, lineno );
+               if( BER_BVISEMPTY( &e->e_nname ) &&
+                       !BER_BVISEMPTY( be->be_nsuffix ))
+               {
+                       fprintf( stderr, "%s: line %d: "
+                               "cannot add entry with empty dn=\"%s\"",
+                               progname, lineno, e->e_dn );
+                       bd = select_backend( &e->e_nname, nosubordinates );
+                       if ( bd ) {
+                               BackendDB *bdtmp;
+                               int dbidx = 0;
+                               LDAP_STAILQ_FOREACH( bdtmp, &backendDB, be_next ) {
+                                       if ( bdtmp == bd ) break;
+                                       dbidx++;
+                               }
+
+                               assert( bdtmp != NULL );
+                               
+                               fprintf( stderr, "; did you mean to use database #%d (%s)?",
+                                       dbidx,
+                                       bd->be_suffix[0].bv_val );
+
+                       }
+                       fprintf( stderr, "\n" );
                        rc = EXIT_FAILURE;
                        entry_free( e );
                        if( continuemode ) continue;
@@ -137,28 +204,39 @@ slapadd( int argc, char **argv )
                }
 
                /* check backend */
-               if( select_backend( &e->e_nname, is_entry_referral(e), nosubordinates )
-                       != be )
-               {
+               bd = select_backend( &e->e_nname, nosubordinates );
+               if ( bd != be ) {
                        fprintf( stderr, "%s: line %d: "
-                               "database (%s) not configured to hold \"%s\"\n",
+                               "database #%d (%s) not configured to hold \"%s\"",
                                progname, lineno,
-                               be ? be->be_suffix[0].bv_val : "<none>",
+                               dbnum,
+                               be->be_suffix[0].bv_val,
                                e->e_dn );
-                       fprintf( stderr, "%s: line %d: "
-                               "database (%s) not configured to hold \"%s\"\n",
-                               progname, lineno,
-                               be ? be->be_nsuffix[0].bv_val : "<none>",
-                               e->e_ndn );
+                       if ( bd ) {
+                               BackendDB *bdtmp;
+                               int dbidx = 0;
+                               LDAP_STAILQ_FOREACH( bdtmp, &backendDB, be_next ) {
+                                       if ( bdtmp == bd ) break;
+                                       dbidx++;
+                               }
+
+                               assert( bdtmp != NULL );
+                               
+                               fprintf( stderr, "; did you mean to use database #%d (%s)?",
+                                       dbidx,
+                                       bd->be_suffix[0].bv_val );
+
+                       } else {
+                               fprintf( stderr, "; no database configured for that naming context" );
+                       }
+                       fprintf( stderr, "\n" );
                        rc = EXIT_FAILURE;
                        entry_free( e );
                        if( continuemode ) continue;
                        break;
                }
 
-               if( global_schemacheck ) {
-                       Attribute *sc = attr_find( e->e_attrs,
-                               slap_schema.si_ad_structuralObjectClass );
+               {
                        Attribute *oc = attr_find( e->e_attrs,
                                slap_schema.si_ad_objectClass );
 
@@ -172,11 +250,12 @@ slapadd( int argc, char **argv )
                                break;
                        }
 
-                       if( sc == NULL ) {
-                               struct berval vals[2];
+                       /* check schema */
+                       op->o_bd = be;
 
-                               rc = structural_class( oc->a_vals, vals,
-                                       NULL, &text, textbuf, textlen );
+                       if ( (slapMode & SLAP_TOOL_NO_SCHEMA_CHECK) == 0) {
+                               rc = entry_schema_check( op, e, NULL, manage, 1, NULL,
+                                       &text, textbuf, textlen );
 
                                if( rc != LDAP_SUCCESS ) {
                                        fprintf( stderr, "%s: dn=\"%s\" (line=%d): (%d) %s\n",
@@ -186,29 +265,11 @@ slapadd( int argc, char **argv )
                                        if( continuemode ) continue;
                                        break;
                                }
-
-                               vals[1].bv_len = 0;
-                               vals[1].bv_val = NULL;
-
-                               attr_merge( e, slap_schema.si_ad_structuralObjectClass,
-                                       vals, NULL /* FIXME */ );
-                       }
-
-                       /* check schema */
-                       rc = entry_schema_check( be, e, NULL, &text, textbuf, textlen );
-
-                       if( rc != LDAP_SUCCESS ) {
-                               fprintf( stderr, "%s: dn=\"%s\" (line=%d): (%d) %s\n",
-                                       progname, e->e_dn, lineno, rc, text );
-                               rc = EXIT_FAILURE;
-                               entry_free( e );
-                               if( continuemode ) continue;
-                               break;
+                               textbuf[ 0 ] = '\0';
                        }
                }
 
                if ( SLAP_LASTMOD(be) ) {
-                       struct tm *ltm;
                        time_t now = slap_get_time();
                        char uuidbuf[ LDAP_LUTIL_UUIDSTR_BUFSIZE ];
                        struct berval vals[ 2 ];
@@ -219,20 +280,26 @@ slapadd( int argc, char **argv )
                        struct berval nname;
                        char timebuf[ LDAP_LUTIL_GENTIME_BUFSIZE ];
 
+                       enum {
+                               GOT_NONE = 0x0,
+                               GOT_CSN = 0x1,
+                               GOT_UUID = 0x2,
+                               GOT_ALL = (GOT_CSN|GOT_UUID)
+                       } got = GOT_ALL;
+
                        vals[1].bv_len = 0;
                        vals[1].bv_val = NULL;
 
                        nvals[1].bv_len = 0;
                        nvals[1].bv_val = NULL;
 
-                       ltm = gmtime(&now);
-                       lutil_gentime( timebuf, sizeof(timebuf), ltm );
-
-                       csn.bv_len = lutil_csnstr( csnbuf, sizeof( csnbuf ), 0, 0 );
+                       csn.bv_len = ldap_pvt_csnstr( csnbuf, sizeof( csnbuf ), csnsid, 0 );
                        csn.bv_val = csnbuf;
 
                        timestamp.bv_val = timebuf;
-                       timestamp.bv_len = strlen(timebuf);
+                       timestamp.bv_len = sizeof(timebuf);
+
+                       slap_timestamp( &now, &timestamp );
 
                        if ( BER_BVISEMPTY( &be->be_rootndn ) ) {
                                BER_BVSTR( &name, SLAPD_ANONYMOUS );
@@ -245,10 +312,10 @@ slapadd( int argc, char **argv )
                        if( attr_find( e->e_attrs, slap_schema.si_ad_entryUUID )
                                == NULL )
                        {
+                               got &= ~GOT_UUID;
                                vals[0].bv_len = lutil_uuidstr( uuidbuf, sizeof( uuidbuf ) );
                                vals[0].bv_val = uuidbuf;
-                               attr_merge_normalize_one( e,
-                                                       slap_schema.si_ad_entryUUID, vals, NULL );
+                               attr_merge_normalize_one( e, slap_schema.si_ad_entryUUID, vals, NULL );
                        }
 
                        if( attr_find( e->e_attrs, slap_schema.si_ad_creatorsName )
@@ -259,14 +326,6 @@ slapadd( int argc, char **argv )
                                attr_merge( e, slap_schema.si_ad_creatorsName, vals, nvals );
                        }
 
-                       if( attr_find( e->e_attrs, slap_schema.si_ad_modifiersName )
-                               == NULL )
-                       {
-                               vals[0] = name;
-                               nvals[0] = nname;
-                               attr_merge( e, slap_schema.si_ad_modifiersName, vals, nvals );
-                       }
-
                        if( attr_find( e->e_attrs, slap_schema.si_ad_createTimestamp )
                                == NULL )
                        {
@@ -274,458 +333,228 @@ slapadd( int argc, char **argv )
                                attr_merge( e, slap_schema.si_ad_createTimestamp, vals, NULL );
                        }
 
-                       if( attr_find( e->e_attrs, slap_schema.si_ad_modifyTimestamp )
+                       if( attr_find( e->e_attrs, slap_schema.si_ad_entryCSN )
                                == NULL )
                        {
-                               vals[0] = timestamp;
-                               attr_merge( e, slap_schema.si_ad_modifyTimestamp, vals, NULL );
+                               got &= ~GOT_CSN;
+                               vals[0] = csn;
+                               attr_merge( e, slap_schema.si_ad_entryCSN, vals, NULL );
                        }
 
-                       if( attr_find( e->e_attrs, slap_schema.si_ad_entryCSN )
+                       if( attr_find( e->e_attrs, slap_schema.si_ad_modifiersName )
                                == NULL )
                        {
-                               vals[0] = csn;
-                               attr_merge( e, slap_schema.si_ad_entryCSN, vals, NULL );
+                               vals[0] = name;
+                               nvals[0] = nname;
+                               attr_merge( e, slap_schema.si_ad_modifiersName, vals, nvals );
                        }
 
-                       if ( !is_entry_syncProviderSubentry( e ) &&
-                                !is_entry_syncConsumerSubentry( e ) &&
-                                update_ctxcsn != SLAP_TOOL_CTXCSN_KEEP ) {
-                               attr = attr_find( e->e_attrs, slap_schema.si_ad_entryCSN );
-                               if ( maxcsn.bv_len != 0 ) {
-                                       value_match( &match, slap_schema.si_ad_entryCSN,
-                                               slap_schema.si_ad_entryCSN->ad_type->sat_ordering,
-                                               SLAP_MR_VALUE_OF_ATTRIBUTE_SYNTAX,
-                                               &maxcsn, &attr->a_nvals[0], &text );
-                               } else {
-                                       match = -1;
-                               }
-                               if ( match < 0 ) {
-                                       if ( maxcsn.bv_val )
-                                               ch_free( maxcsn.bv_val );
-                                       ber_dupbv( &maxcsn, &attr->a_nvals[0] );
-                               }
+                       if( attr_find( e->e_attrs, slap_schema.si_ad_modifyTimestamp )
+                               == NULL )
+                       {
+                               vals[0] = timestamp;
+                               attr_merge( e, slap_schema.si_ad_modifyTimestamp, vals, NULL );
                        }
-               }
 
-               if ( dryrun ) {
-                       if ( verbose ) {
-                               fprintf( stderr, "(dry) added: \"%s\"\n", e->e_dn );
+                       if ( SLAP_SINGLE_SHADOW(be) && got != GOT_ALL ) {
+                               char buf[SLAP_TEXT_BUFLEN];
+
+                               snprintf( buf, sizeof(buf),
+                                       "%s%s%s",
+                                       ( !(got & GOT_UUID) ? slap_schema.si_ad_entryUUID->ad_cname.bv_val : "" ),
+                                       ( !(got & GOT_CSN) ? "," : "" ),
+                                       ( !(got & GOT_CSN) ? slap_schema.si_ad_entryCSN->ad_cname.bv_val : "" ) );
+
+                               Debug( LDAP_DEBUG_ANY, "%s: warning, missing attrs %s from entry dn=\"%s\"\n",
+                                       progname, buf, e->e_name.bv_val );
                        }
-                       goto done;
-               }
 
-               if ( update_ctxcsn == SLAP_TOOL_CTXCSN_KEEP &&
-                       ( replica_promotion || replica_demotion )) {
-                       if ( is_entry_syncProviderSubentry( e )) { 
-                               if ( !LDAP_SLIST_EMPTY( &consumer_subentry )) {
-                                       fprintf( stderr, "%s: consumer and provider subentries "
-                                                                        "are both present\n", progname );
-                                       rc = EXIT_FAILURE;
-                                       entry_free( e );
-                                       sei = LDAP_SLIST_FIRST( &consumer_subentry );
-                                       while ( sei ) {
-                                               ch_free( sei->cn.bv_val );
-                                               ch_free( sei->ndn.bv_val );
-                                               ch_free( sei->rdn.bv_val );
-                                               ch_free( sei->cookie.bv_val );
-                                               LDAP_SLIST_REMOVE_HEAD( &consumer_subentry, sei_next );
-                                               ch_free( sei );
-                                               sei = LDAP_SLIST_FIRST( &consumer_subentry );
-                                       }
-                                       break;
-                               }
-                               if ( provider_subentry ) {
-                                       fprintf( stderr, "%s: multiple provider subentries are "
-                                                       "present : add -w flag to refresh\n", progname );
-                                       rc = EXIT_FAILURE;
-                                       entry_free( e );
-                                       break;
-                               }
-                               attr = attr_find( e->e_attrs, slap_schema.si_ad_contextCSN );
-                               if ( attr == NULL ) {
-                                       entry_free( e );
-                                       continue;
-                               }
-                               provider_subentry = 1;
-                               ber_dupbv( &maxcsn, &attr->a_nvals[0] );
-                       } else if ( is_entry_syncConsumerSubentry( e )) {
-                               if ( provider_subentry ) {
-                                       fprintf( stderr, "%s: consumer and provider subentries "
-                                                                        "are both present\n", progname );
-                                       rc = EXIT_FAILURE;
-                                       entry_free( e );
-                                       break;
-                               }
+                       if ( update_ctxcsn ) {
+                               int rc_sid;
 
-                               attr = attr_find( e->e_attrs, slap_schema.si_ad_cn );
+                               attr = attr_find( e->e_attrs, slap_schema.si_ad_entryCSN );
+                               assert( attr != NULL );
 
-                               if ( attr == NULL ) {
-                                       entry_free( e );
-                                       continue;
-                               }
+                               rc_sid = slap_parse_csn_sid( &attr->a_nvals[ 0 ] );
+                               if ( rc_sid < 0 ) {
+                                       Debug( LDAP_DEBUG_ANY, "%s: could not "
+                                               "extract SID from entryCSN=%s, entry dn=\"%s\"\n",
+                                               progname, attr->a_nvals[ 0 ].bv_val, e->e_name.bv_val );
+
+                               } else {
+                                       assert( rc_sid <= SLAP_SYNC_SID_MAX );
 
-                               if ( !LDAP_SLIST_EMPTY( &consumer_subentry )) {
-                                       LDAP_SLIST_FOREACH( sei, &consumer_subentry, sei_next ) {
-                                               value_match( &match, slap_schema.si_ad_cn,
-                                                       slap_schema.si_ad_cn->ad_type->sat_equality,
+                                       sid = (unsigned)rc_sid;
+                                       if ( maxcsn[ sid ].bv_len != 0 ) {
+                                               match = 0;
+                                               value_match( &match, slap_schema.si_ad_entryCSN,
+                                                       slap_schema.si_ad_entryCSN->ad_type->sat_ordering,
                                                        SLAP_MR_VALUE_OF_ATTRIBUTE_SYNTAX,
-                                                       &sei->cn, &attr->a_nvals[0], &text );
+                                                       &maxcsn[ sid ], &attr->a_nvals[0], &text );
+                                       } else {
+                                               match = -1;
                                        }
-                                       if ( !match ) {
-                                               fprintf( stderr, "%s: multiple consumer subentries "
-                                                               "have the same id : add -w flag to refresh\n",
-                                                               progname );
-                                               rc = EXIT_FAILURE;
-                                               entry_free( e );
-                                               sei = LDAP_SLIST_FIRST( &consumer_subentry );
-                                               while ( sei ) {
-                                                       ch_free( sei->cn.bv_val );
-                                                       ch_free( sei->ndn.bv_val );
-                                                       ch_free( sei->rdn.bv_val );
-                                                       ch_free( sei->cookie.bv_val );
-                                                       LDAP_SLIST_REMOVE_HEAD( &consumer_subentry, sei_next );
-                                                       ch_free( sei );
-                                                       sei = LDAP_SLIST_FIRST( &consumer_subentry );
-                                               }
-                                               break;
+                                       if ( match < 0 ) {
+                                               strcpy( maxcsn[ sid ].bv_val, attr->a_nvals[0].bv_val );
+                                               maxcsn[ sid ].bv_len = attr->a_nvals[0].bv_len;
                                        }
                                }
-                               sei = ch_calloc( 1, sizeof( struct subentryinfo ));
-                               ber_dupbv( &sei->cn, &attr->a_nvals[0] );
-                               ber_dupbv( &sei->ndn, &e->e_nname );
-                               dnExtractRdn( &sei->ndn, &sei->rdn, NULL );
-                               attr = attr_find( e->e_attrs, slap_schema.si_ad_syncreplCookie );
-                               if ( attr == NULL ) {
-                                       ch_free( sei->cn.bv_val );
-                                       ch_free( sei->ndn.bv_val );
-                                       ch_free( sei->rdn.bv_val );
-                                       ch_free( sei->cookie.bv_val );
-                                       ch_free( sei );
-                                       entry_free( e );
-                                       continue;
-                               }
-                               ber_dupbv( &sei->cookie, &attr->a_nvals[0] );
-                               LDAP_SLIST_INSERT_HEAD( &consumer_subentry, sei, sei_next );
                        }
                }
 
-               if (( !is_entry_syncProviderSubentry( e ) &&
-                                !is_entry_syncConsumerSubentry( e )) ||
-                                ( !replica_promotion && !replica_demotion ))
-               {
-                       /* dryrun moved earlier */
-                       assert( !dryrun );
-
-                       if (!dryrun) {
-                               ID id = be->be_entry_put( be, e, &bvtext );
-                               if( id == NOID ) {
-                                       fprintf( stderr, "%s: could not add entry dn=\"%s\" "
-                                                                        "(line=%d): %s\n", progname, e->e_dn,
-                                                                        lineno, bvtext.bv_val );
-                                       rc = EXIT_FAILURE;
-                                       entry_free( e );
-                                       if( continuemode ) continue;
-                                       break;
-                               }
-       
-                               if ( verbose ) {
-                                       fprintf( stderr, "added: \"%s\" (%08lx)\n",
-                                               e->e_dn, (long) id );
-                               }
-                       } else {
-                               if ( verbose ) {
-                                       fprintf( stderr, "(dry) added: \"%s\"\n", e->e_dn );
-                               }
+               if ( !dryrun ) {
+                       id = be->be_entry_put( be, e, &bvtext );
+                       if( id == NOID ) {
+                               fprintf( stderr, "%s: could not add entry dn=\"%s\" "
+                                                                "(line=%d): %s\n", progname, e->e_dn,
+                                                                lineno, bvtext.bv_val );
+                               rc = EXIT_FAILURE;
+                               entry_free( e );
+                               if( continuemode ) continue;
+                               break;
                        }
+                       if ( verbose )
+                               fprintf( stderr, "added: \"%s\" (%08lx)\n",
+                                       e->e_dn, (long) id );
+               } else {
+                       if ( verbose )
+                               fprintf( stderr, "added: \"%s\"\n",
+                                       e->e_dn );
                }
 
-done:;
                entry_free( e );
        }
 
+       if ( ldifrc < 0 )
+               rc = EXIT_FAILURE;
+
        bvtext.bv_len = textlen;
        bvtext.bv_val = textbuf;
        bvtext.bv_val[0] = '\0';
 
-       if ( !LDAP_SLIST_EMPTY( &consumer_subentry )) {
-               maxcsn.bv_len = 0;
-               maxcsn.bv_val = NULL;
-               LDAP_SLIST_FOREACH( sei, &consumer_subentry, sei_next ) {
-                       sc.octet_str = &sei->cookie;
-                       slap_parse_sync_cookie( &sc );
-                       if ( maxcsn.bv_len != 0 ) {
-                               value_match( &match, slap_schema.si_ad_syncreplCookie,
-                                       slap_schema.si_ad_syncreplCookie->ad_type->sat_ordering,
-                                       SLAP_MR_VALUE_OF_ATTRIBUTE_SYNTAX,
-                                       &maxcsn, &sc.ctxcsn[0], &text );
-                       } else {
-                               match = -1;
-                       }
-                       if ( match < 0 ) {
-                               if ( maxcsn.bv_val )
-                                       ch_free( maxcsn.bv_val );
-                               ber_dupbv( &maxcsn, &sc.ctxcsn[0] );
-                       }
-                       sc.octet_str = NULL;
-                       slap_sync_cookie_free( &sc, 0 );
-               }
+       if ( enable_meter ) {
+               lutil_meter_update( &meter, ftell( ldiffp->fp ), 1);
+               lutil_meter_close( &meter );
        }
 
-       slap_compose_sync_cookie( NULL, &mc, &maxcsn, -1, -1 );
-
-       if ( SLAP_LASTMOD(be) && replica_promotion ) {
-               if ( provider_subentry || update_ctxcsn == SLAP_TOOL_CTXCSN_BATCH ||
-                        !LDAP_SLIST_EMPTY( &consumer_subentry )) {
-                       build_new_dn( &ctxcsn_ndn, &be->be_nsuffix[0],
-                                                 (struct berval *)&slap_ldapsync_cn_bv, NULL );
-                       ctxcsn_id = be->be_dn2id_get( be, &ctxcsn_ndn );
-               
-                       if ( ctxcsn_id == NOID ) {
-                               ctxcsn_e = slap_create_context_csn_entry( be, &maxcsn );
-                               
-                               /* dryrun moved earlier */
-                               assert( !dryrun );
-
-                               if ( !dryrun ) {
-                                       ctxcsn_id = be->be_entry_put( be, ctxcsn_e, &bvtext );
-                                       if( ctxcsn_id == NOID ) {
-                                               fprintf( stderr, "%s: could not add ctxcsn subentry\n",
-                                                                                progname);
-                                               rc = EXIT_FAILURE;
-                                       }
-                                       if ( verbose ) {
-                                               fprintf( stderr, "added: \"%s\" (%08lx)\n",
-                                                                                ctxcsn_e->e_dn, (long) ctxcsn_id );
-                                       }
-                               } else {
-                                       if ( verbose ) {
-                                               fprintf( stderr, "(dry) added: \"%s\"\n", ctxcsn_e->e_dn );
+       if ( rc == EXIT_SUCCESS && update_ctxcsn && !dryrun && sid != SLAP_SYNC_SID_MAX + 1 ) {
+               struct berval ctxdn;
+               if ( SLAP_SYNC_SUBENTRY( be )) {
+                       build_new_dn( &ctxdn, &be->be_nsuffix[0],
+                               (struct berval *)&slap_ldapsync_cn_bv, NULL );
+               } else {
+                       ctxdn = be->be_nsuffix[0];
+               }
+               ctxcsn_id = be->be_dn2id_get( be, &ctxdn );
+               if ( ctxcsn_id == NOID ) {
+                       if ( SLAP_SYNC_SUBENTRY( be )) {
+                               ctxcsn_e = slap_create_context_csn_entry( be, NULL );
+                               for ( sid = 0; sid <= SLAP_SYNC_SID_MAX; sid++ ) {
+                                       if ( maxcsn[ sid ].bv_len ) {
+                                               attr_merge_one( ctxcsn_e, slap_schema.si_ad_contextCSN,
+                                                       &maxcsn[ sid ], NULL );
                                        }
                                }
-                               entry_free( ctxcsn_e );
-                       } else {
-                               ret = be->be_id2entry_get( be, ctxcsn_id, &ctxcsn_e );
-                               if ( ret == LDAP_SUCCESS ) {
-                                       attr = attr_find( ctxcsn_e->e_attrs,
-                                                                               slap_schema.si_ad_contextCSN );
-                                       AC_MEMCPY( attr->a_vals[0].bv_val, maxcsn.bv_val, maxcsn.bv_len );
-                                       attr->a_vals[0].bv_val[maxcsn.bv_len] = '\0';
-                                       attr->a_vals[0].bv_len = maxcsn.bv_len;
-                               
-                                       /* dryrun moved earlier */
-                                       assert( !dryrun );
-
-                                       if ( !dryrun ) {
-                                               ctxcsn_id = be->be_entry_modify( be, ctxcsn_e, &bvtext );
-                                               if( ctxcsn_id == NOID ) {
-                                                       fprintf( stderr, "%s: could not modify ctxcsn "
-                                                                                        "subentry\n", progname);
-                                                       rc = EXIT_FAILURE;
-                                               }
-                                               if ( verbose ) {
-                                                       fprintf( stderr, "modified: \"%s\" (%08lx)\n",
-                                                                                        ctxcsn_e->e_dn, (long) ctxcsn_id );
-                                               }
-                                       } else {
-                                               if ( verbose ) {
-                                                       fprintf( stderr, "(dry) modified: \"%s\"\n",
-                                                                                        ctxcsn_e->e_dn );
-                                               }
-                                       }
-                               } else {
-                                       fprintf( stderr, "%s: could not modify ctxcsn subentry\n",
-                                                                        progname);
+                               ctxcsn_id = be->be_entry_put( be, ctxcsn_e, &bvtext );
+                               if ( ctxcsn_id == NOID ) {
+                                       fprintf( stderr, "%s: couldn't create context entry\n", progname );
                                        rc = EXIT_FAILURE;
                                }
+                       } else {
+                               fprintf( stderr, "%s: context entry is missing\n", progname );
+                               rc = EXIT_FAILURE;
                        }
-               } 
-       } else if ( SLAP_LASTMOD(be) && replica_demotion &&
-                               ( update_ctxcsn == SLAP_TOOL_CTXCSN_BATCH ||
-                               provider_subentry )) {
-
-               ber_dupbv( &slap_syncrepl_bv, (struct berval *) &slap_syncrepl_bvc );
-               ber_dupbv( &slap_syncrepl_cn_bv,
-                                       (struct berval *) &slap_syncrepl_cn_bvc );
-
-               if ( replica_id_list == NULL ) {
-                       replica_id_list = ch_calloc( 2, sizeof( int ));
-                       replica_id_list[0] = 0;
-                       replica_id_list[1] = -1;
-               }
+               } else {
+                       ctxcsn_e = be->be_entry_get( be, ctxcsn_id );
+                       if ( ctxcsn_e != NULL ) {
+                               Entry *e = entry_dup( ctxcsn_e );
+                               int change;
+                               attr = attr_find( e->e_attrs, slap_schema.si_ad_contextCSN );
+                               if ( attr ) {
+                                       int             i;
+
+                                       change = 0;
+
+                                       for ( i = 0; !BER_BVISNULL( &attr->a_nvals[ i ] ); i++ ) {
+                                               int rc_sid;
+
+                                               rc_sid = slap_parse_csn_sid( &attr->a_nvals[ i ] );
+                                               if ( rc_sid < 0 ) {
+                                                       Debug( LDAP_DEBUG_ANY,
+                                                               "%s: unable to extract SID "
+                                                               "from #%d contextCSN=%s\n",
+                                                               progname, i,
+                                                               attr->a_nvals[ i ].bv_val );
+                                                       continue;
+                                               }
 
-               for ( i = 0; replica_id_list[i] > -1 ; i++ ) {
-                       slap_syncrepl_bv.bv_len = snprintf( slap_syncrepl_bv.bv_val,
-                                                                       slap_syncrepl_bvc.bv_len+1,
-                                                                       "syncrepl%d", replica_id_list[i] );
-                       slap_syncrepl_cn_bv.bv_len = snprintf( slap_syncrepl_cn_bv.bv_val,
-                                                                               slap_syncrepl_cn_bvc.bv_len+1,
-                                                                               "cn=syncrepl%d", replica_id_list[i] );
-                       build_new_dn( &ctxcsn_ndn, &be->be_nsuffix[0],
-                                                 (struct berval *)&slap_syncrepl_cn_bv, NULL );
-                       ctxcsn_id = be->be_dn2id_get( be, &ctxcsn_ndn );
-
-                       if ( ctxcsn_id == NOID ) {
-                               ctxcsn_e = slap_create_syncrepl_entry( be, &mc,
-                                               &slap_syncrepl_cn_bv,
-                                               &slap_syncrepl_bv );
-
-                               /* dryrun moved earlier */
-                               assert( !dryrun );
-
-                               if ( !dryrun ) {
-                                       ctxcsn_id = be->be_entry_put( be, ctxcsn_e, &bvtext );
-                                       if( ctxcsn_id == NOID ) {
-                                               fprintf( stderr, "%s: could not add ctxcsn subentry\n",
-                                                                                progname);
-                                               rc = EXIT_FAILURE;
-                                       }
-                                       if ( verbose ) {
-                                               fprintf( stderr, "added: \"%s\" (%08lx)\n",
-                                                                                ctxcsn_e->e_dn, (long) ctxcsn_id );
-                                       }
-                               } else {
-                                       if ( verbose ) {
-                                               fprintf( stderr, "(dry) added: \"%s\"\n",
-                                                                                       ctxcsn_e->e_dn );
-                                       }
-                               }
-                               entry_free( ctxcsn_e );
-                       } else {
-                               ret = be->be_id2entry_get( be, ctxcsn_id, &ctxcsn_e );
-                               if ( ret == LDAP_SUCCESS ) {
-                                       attr = attr_find( ctxcsn_e->e_attrs,
-                                                                         slap_schema.si_ad_syncreplCookie );
-                                       AC_MEMCPY( attr->a_vals[0].bv_val, mc.bv_val, mc.bv_len );
-                                       attr->a_vals[0].bv_val[maxcsn.bv_len] = '\0';
-                                       attr->a_vals[0].bv_len = maxcsn.bv_len;
-                               
-                                       /* dryrun moved earlier */
-                                       assert( !dryrun );
-
-                                       if ( !dryrun ) {
-                                               ctxcsn_id = be->be_entry_modify( be,
-                                                                                       ctxcsn_e, &bvtext );
-                                               if( ctxcsn_id == NOID ) {
-                                                       fprintf( stderr, "%s: could not modify ctxcsn "
-                                                                                        "subentry\n", progname);
-                                                       rc = EXIT_FAILURE;
+                                               assert( rc_sid <= SLAP_SYNC_SID_MAX );
+
+                                               sid = (unsigned)rc_sid;
+
+                                               if ( maxcsn[ sid ].bv_len == 0 ) {
+                                                       match = -1;
+
+                                               } else {
+                                                       value_match( &match, slap_schema.si_ad_entryCSN,
+                                                               slap_schema.si_ad_entryCSN->ad_type->sat_ordering,
+                                                               SLAP_MR_VALUE_OF_ATTRIBUTE_SYNTAX,
+                                                               &maxcsn[ sid ], &attr->a_nvals[i], &text );
                                                }
-                                               if ( verbose ) {
-                                                       fprintf( stderr, "modified: \"%s\" (%08lx)\n",
-                                                                                        ctxcsn_e->e_dn, (long) ctxcsn_id );
+
+                                               if ( match > 0 ) {
+                                                       change = 1;
+                                               } else {
+                                                       AC_MEMCPY( maxcsn[ sid ].bv_val,
+                                                               attr->a_nvals[ i ].bv_val,
+                                                               attr->a_nvals[ i ].bv_len );
+                                                       maxcsn[ sid ].bv_val[ attr->a_nvals[ i ].bv_len ] = '\0';
+                                                       maxcsn[ sid ].bv_len = attr->a_nvals[ i ].bv_len;
                                                }
-                                       } else {
-                                               if ( verbose ) {
-                                                       fprintf( stderr, "(dry) modified: \"%s\"\n",
-                                                                                        ctxcsn_e->e_dn );
+                                       }
+
+                                       if ( change ) {
+                                               if ( attr->a_nvals != attr->a_vals ) {
+                                                       ber_bvarray_free( attr->a_nvals );
                                                }
+                                               attr->a_nvals = NULL;
+                                               ber_bvarray_free( attr->a_vals );
+                                               attr->a_vals = NULL;
+                                               attr->a_numvals = 0;
                                        }
                                } else {
-                                       fprintf( stderr, "%s: could not modify ctxcsn subentry\n",
-                                                                        progname);
-                                       rc = EXIT_FAILURE;
+                                       change = 1;
                                }
-                       }
-               }
-               
-               if ( slap_syncrepl_bv.bv_val ) {
-                       ch_free( slap_syncrepl_bv.bv_val );
-               }
-               if ( slap_syncrepl_cn_bv.bv_val ) {
-                       ch_free( slap_syncrepl_cn_bv.bv_val );
-               }
-       } else if ( SLAP_LASTMOD(be) && replica_demotion &&
-                               !LDAP_SLIST_EMPTY( &consumer_subentry )) {
 
-               LDAP_SLIST_FOREACH( sei, &consumer_subentry, sei_next ) {
-                       ctxcsn_id = be->be_dn2id_get( be, &sei->ndn );
-
-                       if ( ctxcsn_id == NOID ) {
-                               ctxcsn_e = slap_create_syncrepl_entry( be, &sei->cookie,
-                                               &sei->rdn, &sei->cn );
-
-                               /* dryrun moved earlier */
-                               assert( !dryrun );
+                               if ( change ) {
+                                       for ( sid = 0; sid <= SLAP_SYNC_SID_MAX; sid++ ) {
+                                               if ( maxcsn[ sid ].bv_len ) {
+                                                       attr_merge_one( e, slap_schema.si_ad_contextCSN,
+                                                               &maxcsn[ sid], NULL );
+                                               }
+                                       }
 
-                               if ( !dryrun ) {
-                                       ctxcsn_id = be->be_entry_put( be, ctxcsn_e, &bvtext );
+                                       ctxcsn_id = be->be_entry_modify( be, e, &bvtext );
                                        if( ctxcsn_id == NOID ) {
-                                               fprintf( stderr, "%s: could not add ctxcsn subentry\n",
-                                                                                progname);
+                                               fprintf( stderr, "%s: could not modify ctxcsn\n",
+                                                       progname);
                                                rc = EXIT_FAILURE;
-                                       }
-                                       if ( verbose ) {
-                                               fprintf( stderr, "added: \"%s\" (%08lx)\n",
-                                                                                ctxcsn_e->e_dn, (long) ctxcsn_id );
-                                       }
-                               } else {
-                                       if ( verbose ) {
-                                               fprintf( stderr, "(dry) added: \"%s\"\n",
-                                                                                       ctxcsn_e->e_dn );
+                                       } else if ( verbose ) {
+                                               fprintf( stderr, "modified: \"%s\" (%08lx)\n",
+                                                       e->e_dn, (long) ctxcsn_id );
                                        }
                                }
-                               entry_free( ctxcsn_e );
-                       } else {
-                               ret = be->be_id2entry_get( be, ctxcsn_id, &ctxcsn_e );
-                               if ( ret == LDAP_SUCCESS ) {
-                                       attr = attr_find( ctxcsn_e->e_attrs,
-                                                                         slap_schema.si_ad_syncreplCookie );
-                                       AC_MEMCPY( attr->a_vals[0].bv_val, sei->cookie.bv_val, sei->cookie.bv_len );
-                                       attr->a_vals[0].bv_val[sei->cookie.bv_len] = '\0';
-                                       attr->a_vals[0].bv_len = sei->cookie.bv_len;
-                                       
-                                       /* dryrun moved earlier */
-                                       assert( !dryrun );
-
-                                       if ( !dryrun ) {
-                                               ctxcsn_id = be->be_entry_modify( be,
-                                                                                       ctxcsn_e, &bvtext );
-                                               if( ctxcsn_id == NOID ) {
-                                                       fprintf( stderr, "%s: could not modify ctxcsn "
-                                                                                        "subentry\n", progname);
-                                                       rc = EXIT_FAILURE;
-                                               }
-                                               if ( verbose ) {
-                                                       fprintf( stderr, "modified: \"%s\" (%08lx)\n",
-                                                                                        ctxcsn_e->e_dn, (long) ctxcsn_id );
-                                               }
-                                       } else {
-                                               if ( verbose ) {
-                                                       fprintf( stderr, "(dry) modified: \"%s\"\n",
-                                                                                        ctxcsn_e->e_dn );
-                                               }
-                                       }
-                               } else {
-                                       fprintf( stderr, "%s: could not modify ctxcsn subentry\n",
-                                                                        progname);
-                                       rc = EXIT_FAILURE;
-                               }
+                               entry_free( e );
                        }
-               }
-               
-               if ( slap_syncrepl_bv.bv_val ) {
-                       ch_free( slap_syncrepl_bv.bv_val );
-               }
-               if ( slap_syncrepl_cn_bv.bv_val ) {
-                       ch_free( slap_syncrepl_cn_bv.bv_val );
-               }
-       }
-
-       sei = LDAP_SLIST_FIRST( &consumer_subentry );
-       while ( sei ) {
-               ch_free( sei->cn.bv_val );
-               ch_free( sei->ndn.bv_val );
-               ch_free( sei->rdn.bv_val );
-               ch_free( sei->cookie.bv_val );
-               LDAP_SLIST_REMOVE_HEAD( &consumer_subentry, sei_next );
-               ch_free( sei );
-               sei = LDAP_SLIST_FIRST( &consumer_subentry );
+               } 
        }
 
        ch_free( buf );
 
        if ( !dryrun ) {
+               if ( enable_meter ) {
+                       fprintf( stderr, "Closing DB..." );
+               }
                if( be->be_entry_close( be ) ) {
                        rc = EXIT_FAILURE;
                }
@@ -733,9 +562,13 @@ done:;
                if( be->be_sync ) {
                        be->be_sync( be );
                }
+               if ( enable_meter ) {
+                       fprintf( stderr, "\n" );
+               }
        }
 
-       slap_tool_destroy();
+       if ( slap_tool_destroy())
+               rc = EXIT_FAILURE;
 
        return rc;
 }