]> git.sur5r.net Git - openldap/blobdiff - servers/slapd/slapi/slapi_ops.c
Misc changes from HEAD
[openldap] / servers / slapd / slapi / slapi_ops.c
index b9c34195220a04c44df217432d242e08cbe5ebe5..aba0caeb44460bb6c4f1e9dd3458a1eb4f0ad1a8 100644 (file)
@@ -1,7 +1,7 @@
 /* $OpenLDAP$ */
 /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
  *
- * Copyright 2002-2005 The OpenLDAP Foundation.
+ * Copyright 2002-2006 The OpenLDAP Foundation.
  * Portions Copyright 1997,2002-2003 IBM Corporation.
  * All rights reserved.
  *
 #include <lber_pvt.h>
 #include <slapi.h>
 
-/*
- * use a fake listener when faking a connection,
- * so it can be used in ACLs
- */
-static struct slap_listener slap_unknown_listener = {
-       BER_BVC("unknown"),     /* FIXME: use a URI form? (e.g. slapi://) */
-       BER_BVC("UNKNOWN")
+#ifdef LDAP_SLAPI
+
+static struct slap_listener slapi_listener = {
+       BER_BVC("slapi://"),
+       BER_BVC("slapi://")
 };
 
-static void
-slapi_int_mods_free( Modifications *ml )
+static LDAPControl **
+slapi_int_dup_controls( LDAPControl **controls )
 {
-       Modifications           *next;
+       LDAPControl **c;
+       size_t i;
 
-       for ( ; ml != NULL; ml = next ) {
-               next = ml->sml_next;
+       if ( controls == NULL )
+               return NULL;
 
-               /* Don't free unnormalized values */
-               if ( ml->sml_nvalues != NULL ) {
-                       ber_bvarray_free( ml->sml_nvalues );
-                       ml->sml_nvalues = NULL;
-               }
-               slapi_ch_free((void **)&ml->sml_values);
-               slapi_ch_free((void **)&ml);
+       for ( i = 0; controls[i] != NULL; i++ )
+               ;
+
+       c = (LDAPControl **) slapi_ch_calloc( i + 1, sizeof(LDAPControl *) );
+
+       for ( i = 0; controls[i] != NULL; i++ ) {
+               c[i] = slapi_dup_control( controls[i] );
        }
+
+       return c;
 }
 
 static int
@@ -63,42 +64,25 @@ slapi_int_result(
        Operation       *op, 
        SlapReply       *rs )
 {
-       LDAPControl             **controls = NULL;
-       size_t                  i;
+       Slapi_PBlock            *pb = SLAPI_OPERATION_PBLOCK( op );
        plugin_result_callback  prc = NULL;
        void                    *callback_data = NULL;
-       Slapi_PBlock            *pb = SLAPI_OPERATION_PBLOCK( op );
+       LDAPControl             **ctrls = NULL;
 
        assert( pb != NULL );   
 
-       slapi_pblock_get( pb, SLAPI_RESCONTROLS,             (void **)&controls );
        slapi_pblock_get( pb, SLAPI_X_INTOP_RESULT_CALLBACK, (void **)&prc );
        slapi_pblock_get( pb, SLAPI_X_INTOP_CALLBACK_DATA,   &callback_data );
 
-       assert( controls == NULL );
-
-       /* Copy these before they go out of scope */
-       if ( rs->sr_ctrls != NULL ) {
-               for ( i = 0; rs->sr_ctrls[i] != NULL; i++ )
-                       ;
-
-               controls = (LDAPControl **)slapi_ch_calloc( i + 1,
-                       sizeof(LDAPControl ));
-
-               for ( i = 0; rs->sr_ctrls[i] != NULL; i++ )
-                       controls[i] = slapi_dup_control( rs->sr_ctrls[i] );
-
-               controls[i] = NULL;
-       }
-
-       slapi_pblock_set( pb, SLAPI_RESCONTROLS,         (void *)controls );
-       slapi_pblock_set( pb, SLAPI_PLUGIN_INTOP_RESULT, (void *)rs->sr_err );
+       /* we need to duplicate controls because they might go out of scope */
+       ctrls = slapi_int_dup_controls( rs->sr_ctrls );
+       slapi_pblock_set( pb, SLAPI_RESCONTROLS, ctrls );
 
        if ( prc != NULL ) {
                (*prc)( rs->sr_err, callback_data );
        }
 
-       return LDAP_SUCCESS;
+       return rs->sr_err;
 }
 
 static int
@@ -106,10 +90,10 @@ slapi_int_search_entry(
        Operation       *op,
        SlapReply       *rs )
 {
+       Slapi_PBlock                    *pb = SLAPI_OPERATION_PBLOCK( op );
        plugin_search_entry_callback    psec = NULL;
        void                            *callback_data = NULL;
-       Slapi_PBlock                    *pb = SLAPI_OPERATION_PBLOCK( op );
-       int                             rc = SLAP_CB_CONTINUE;
+       int                             rc = LDAP_SUCCESS;
 
        assert( pb != NULL );
 
@@ -120,7 +104,7 @@ slapi_int_search_entry(
                rc = (*psec)( rs->sr_entry, callback_data );
        }
 
-       return LDAP_SUCCESS;
+       return rc;
 }
 
 static int
@@ -170,165 +154,34 @@ slapi_int_response( Slapi_Operation *op, SlapReply *rs )
                break;
        }
 
-       assert( rc != SLAP_CB_CONTINUE );
+       assert( rc != SLAP_CB_CONTINUE ); /* never try to send a wire response */
 
        return rc;
 }
 
 static int
-slapi_int_get_ctrls( Operation *op, SlapReply *rs, LDAPControl **controls )
+slapi_int_get_ctrls( Slapi_PBlock *pb )
 {
        LDAPControl             **c;
-       int                     rc;
+       int                     rc = LDAP_SUCCESS;
 
-       op->o_ctrls = controls;
-       if ( op->o_ctrls == NULL ) {
-               return LDAP_SUCCESS;
-       }
-
-       for ( c = op->o_ctrls; *c != NULL; c++ ) {
-               rc = slap_parse_ctrl( op, rs, *c, &rs->sr_text );
-               if ( rc != LDAP_SUCCESS )
-                       break;
+       if ( pb->pb_op->o_ctrls != NULL ) {
+               for ( c = pb->pb_op->o_ctrls; *c != NULL; c++ ) {
+                       rc = slap_parse_ctrl( pb->pb_op, pb->pb_rs, *c, &pb->pb_rs->sr_text );
+                       if ( rc != LDAP_SUCCESS )
+                               break;
+               }
        }
 
        return rc;
 }
 
-/*
- * To allow plugins to forward frontend requests to internal operations,
- * the internal operation and connection structures should import as
- * much state as practicable from the supplied parameter block.
- */
-
-/*
- * Select the backend to be used for an internal operation, either
- * from the operation target DN or from the parameter block.
- */
-static int
-slapi_int_pblock_get_backend( Slapi_PBlock *pb, Operation *op )
-{
-       int                     manageDsaIt = 0, isCritical;
-       LDAPControl             **controls = NULL;
-       BackendDB               *be_op;
-
-       slapi_pblock_get( pb, SLAPI_REQCONTROLS, (void **)&controls );
-
-       slapi_pblock_get( pb, SLAPI_MANAGEDSAIT, (void **)&manageDsaIt );
-       if ( manageDsaIt != 0 )
-               manageDsaIt = SLAP_CONTROL_CRITICAL;
-       else if ( slapi_control_present( controls, SLAPI_CONTROL_MANAGEDSAIT_OID,
-                   NULL, &isCritical ))
-               manageDsaIt = isCritical ? SLAP_CONTROL_CRITICAL : SLAP_CONTROL_NONCRITICAL;
-
-       /* let caller force a specific backend */
-       slapi_pblock_get( pb, SLAPI_BACKEND, (void **)&be_op );
-       if ( be_op == NULL ) {
-               be_op = select_backend( &op->o_req_ndn, 0, 0 );
-               slapi_pblock_set( pb, SLAPI_BACKEND, (void *)be_op );
-       }
-
-       op->o_bd = frontendDB; /* but we actually use frontend DB */
-
-       return LDAP_SUCCESS;
-}
-
-static int
-slapi_int_pblock_get_connection( Slapi_PBlock *pb, Operation *op )
-{
-       char                    *connDn = NULL;
-       Connection              *conn = op->o_conn;
-
-       slapi_pblock_get( pb, SLAPI_X_CONN_SSF, (void **)&conn->c_ssf );
-       slapi_pblock_get( pb, SLAPI_X_CONN_SASL_CONTEXT, (void **)&conn->c_sasl_authctx );
-
-       if ( slapi_pblock_get( pb, SLAPI_CONN_DN, (void **)&connDn ) != 0
-                       || connDn == NULL )
-       {
-               /* default to operation DN */
-               conn->c_ndn = op->o_ndn;
-               conn->c_dn = op->o_ndn;
-
-       } else {
-               /* NB: conn DN must be normalized */
-               ber_str2bv( connDn, 0, 0, &conn->c_ndn );
-               conn->c_dn = conn->c_ndn;
-       }
-
-       return LDAP_SUCCESS;
-}
-
-static int
-slapi_int_pblock_get_operation( Slapi_PBlock *pb, Operation *op, SlapReply *rs )
-{
-       int                     isRoot = 0;
-       int                     isUpdateDn = 0;
-       char                    *requestorDn = NULL;
-       struct berval           targetDn = BER_BVNULL;
-       LDAPControl             **controls;
-       int                     rc;
-       BackendDB               *be_op;
-
-       /* All internal operations must specify a target DN */
-       slapi_pblock_get( pb, SLAPI_TARGET_DN, (void **)&targetDn.bv_val );
-       if ( targetDn.bv_val == NULL) {
-               return LDAP_PARAM_ERROR; 
-       }
-       targetDn.bv_len = strlen( targetDn.bv_val );
-
-       rc = dnPrettyNormal( NULL, &targetDn, &op->o_req_dn, &op->o_req_ndn, NULL );
-       if ( rc != LDAP_SUCCESS ) {
-               return rc;
-       }
-
-       rc = slapi_int_pblock_get_backend( pb, op );
-       if ( rc != LDAP_SUCCESS ) {
-               return rc;
-       }
-
-       slapi_pblock_get( pb, SLAPI_REQUESTOR_ISROOT, (void **)&isRoot );
-       slapi_pblock_get( pb, SLAPI_REQUESTOR_ISUPDATEDN, (void **)&isUpdateDn );
-       /* NB: requestor DN must be normalized */
-       slapi_pblock_get( pb, SLAPI_REQUESTOR_DN, (void **)&requestorDn );
-       slapi_pblock_get( pb, SLAPI_BACKEND, (void **)&be_op );
-
-       /* Default authorization identity for internal operations is root DN */
-       if ( isRoot || requestorDn == NULL ) {
-               assert( be_op != NULL );
-               op->o_dn = be_op->be_rootdn;
-               op->o_ndn = be_op->be_rootndn;
-               isRoot = 1;
-       } else {
-               ber_str2bv( requestorDn, 0, 0, &op->o_ndn );
-               op->o_dn = op->o_ndn;
-       }
-
-       slapi_pblock_set( pb, SLAPI_REQUESTOR_ISROOT, (void *)isRoot );
-
-       rc = slapi_int_pblock_get_connection( pb, op );
-       if ( rc != LDAP_SUCCESS ) {
-               return rc;
-       }
-
-       slapi_pblock_get( pb, SLAPI_REQCONTROLS, (void **)&controls );
-       rc = slapi_int_get_ctrls( op, rs, controls );
-       if ( rc != LDAP_SUCCESS ) {
-               return rs->sr_err;
-       }
-
-       return LDAP_SUCCESS;
-}
-
-int
-slapi_int_connection_init( Slapi_PBlock *pb,
-       SlapReply *rs,
-       int OpType,
-       Connection **pConn )
+void
+slapi_int_connection_init_pb( Slapi_PBlock *pb, ber_tag_t tag )
 {
        Connection              *conn;
        Operation               *op;
        ber_len_t               max = sockbuf_max_incoming;
-       int                     rc;
 
        conn = (Connection *) slapi_ch_calloc( 1, sizeof(Connection) );
 
@@ -336,7 +189,6 @@ slapi_int_connection_init( Slapi_PBlock *pb,
 
        op = (Operation *) slapi_ch_calloc( 1, OPERATION_BUFFER_SIZE );
        op->o_hdr = (Opheader *)(op + 1);
-       op->o_hdr->oh_extensions = NULL;
        op->o_controls = (void **)(op->o_hdr + 1);
 
        op->o_callback = (slap_callback *) slapi_ch_calloc( 1, sizeof(slap_callback) );
@@ -353,7 +205,7 @@ slapi_int_connection_init( Slapi_PBlock *pb,
        BER_BVZERO( &conn->c_dn );
        BER_BVZERO( &conn->c_ndn );
 
-       conn->c_listener = &slap_unknown_listener;
+       conn->c_listener = &slapi_listener;
        ber_dupbv( &conn->c_peer_domain, (struct berval *)&slap_unknown_bv );
        ber_dupbv( &conn->c_peer_name, (struct berval *)&slap_unknown_bv );
 
@@ -364,7 +216,7 @@ slapi_int_connection_init( Slapi_PBlock *pb,
        conn->c_sasl_sockctx = NULL;
        conn->c_sasl_extra = NULL;
 
-       conn->c_sb = ber_sockbuf_alloc( );
+       conn->c_sb = ber_sockbuf_alloc();
 
        ber_sockbuf_ctrl( conn->c_sb, LBER_SB_OPT_SET_MAX_INCOMING, &max );
 
@@ -401,7 +253,7 @@ slapi_int_connection_init( Slapi_PBlock *pb,
        conn->c_conn_state  = 0x01;     /* SLAP_C_ACTIVE */
        conn->c_struct_state = 0x02;    /* SLAP_C_USED */
 
-       conn->c_ssf = conn->c_transport_ssf = 0;
+       conn->c_ssf = conn->c_transport_ssf = local_ssf;
        conn->c_tls_ssf = 0;
 
        backend_connection_init( conn );
@@ -412,7 +264,7 @@ slapi_int_connection_init( Slapi_PBlock *pb,
        conn->c_send_search_reference = slap_send_search_reference;
 
        /* operation object */
-       op->o_tag = OpType;
+       op->o_tag = tag;
        op->o_protocol = LDAP_VERSION3; 
        BER_BVZERO( &op->o_authmech );
        op->o_time = slap_get_time();
@@ -422,326 +274,295 @@ slapi_int_connection_init( Slapi_PBlock *pb,
        op->o_tmpmfuncs = &ch_mfuncs;
        op->o_conn = conn;
        op->o_connid = conn->c_connid;
+       op->o_bd = frontendDB;
 
-       rc = slapi_int_pblock_get_operation( pb, op, rs );
+       /* extensions */
+       slapi_int_create_object_extensions( SLAPI_X_EXT_OPERATION, op );
+       slapi_int_create_object_extensions( SLAPI_X_EXT_CONNECTION, conn );
 
-       slapi_pblock_set( pb, SLAPI_OPERATION, op );
-       slapi_pblock_set( pb, SLAPI_CONNECTION, conn );
+       pb->pb_rs = (SlapReply *)slapi_ch_calloc( 1, sizeof(SlapReply) );
+       pb->pb_op = op;
+       pb->pb_conn = conn;
+       pb->pb_intop = 1;
 
        ldap_pvt_thread_mutex_unlock( &conn->c_mutex );
+}
 
-       if ( rc != LDAP_SUCCESS ) {
-               slapi_int_connection_destroy( &conn );
-               return rc;
+static void
+slapi_int_set_operation_dn( Slapi_PBlock *pb )
+{
+       Backend                 *be;
+       Operation               *op = pb->pb_op;
+
+       if ( BER_BVISNULL( &op->o_ndn ) ) {
+               /* set to root DN */
+               be = select_backend( &op->o_req_ndn, get_manageDSAit( op ), 1 );
+               if ( be != NULL ) {
+                       ber_dupbv( &op->o_dn, &be->be_rootdn );
+                       ber_dupbv( &op->o_ndn, &be->be_rootndn );
+               }
        }
-
-       *pConn = conn;
-
-       return LDAP_SUCCESS;
 }
 
-void slapi_int_connection_destroy( Connection **pConn )
+void
+slapi_int_connection_done_pb( Slapi_PBlock *pb )
 {
-       Connection              *conn = *pConn;
+       Connection              *conn;
        Operation               *op;
-       Slapi_PBlock            *pb;
 
-       if ( conn == NULL ) {
-               return;
+       PBLOCK_ASSERT_INTOP( pb, 0 );
+
+       conn = pb->pb_conn;
+       op = pb->pb_op;
+
+       /* free allocated DNs */
+       if ( !BER_BVISNULL( &op->o_dn ) )
+               op->o_tmpfree( op->o_dn.bv_val, op->o_tmpmemctx );
+       if ( !BER_BVISNULL( &op->o_ndn ) )
+               op->o_tmpfree( op->o_ndn.bv_val, op->o_tmpmemctx );
+
+       if ( !BER_BVISNULL( &op->o_req_dn ) )
+               op->o_tmpfree( op->o_req_dn.bv_val, op->o_tmpmemctx );
+       if ( !BER_BVISNULL( &op->o_req_ndn ) )
+               op->o_tmpfree( op->o_req_ndn.bv_val, op->o_tmpmemctx );
+
+       switch ( op->o_tag ) {
+       case LDAP_REQ_MODRDN:
+               if ( !BER_BVISNULL( &op->orr_newrdn ))
+                       op->o_tmpfree( op->orr_newrdn.bv_val, op->o_tmpmemctx );
+               if ( !BER_BVISNULL( &op->orr_nnewrdn ))
+                       op->o_tmpfree( op->orr_nnewrdn.bv_val, op->o_tmpmemctx );
+               if ( op->orr_newSup != NULL ) {
+                       assert( !BER_BVISNULL( op->orr_newSup ) );
+                       op->o_tmpfree( op->orr_newSup->bv_val, op->o_tmpmemctx );
+                       op->o_tmpfree( op->orr_newSup, op->o_tmpmemctx );
+               }
+               if ( op->orr_nnewSup != NULL ) {
+                       assert( !BER_BVISNULL( op->orr_nnewSup ) );
+                       op->o_tmpfree( op->orr_nnewSup->bv_val, op->o_tmpmemctx );
+                       op->o_tmpfree( op->orr_nnewSup, op->o_tmpmemctx );
+               }
+               slap_mods_free( op->orr_modlist, 1 );
+               break;
+       case LDAP_REQ_ADD:
+               slap_mods_free( op->ora_modlist, 0 );
+               break;
+       case LDAP_REQ_MODIFY:
+               slap_mods_free( op->orm_modlist, 1 );
+               break;
+       case LDAP_REQ_SEARCH:
+               if ( op->ors_attrs != NULL ) {
+                       op->o_tmpfree( op->ors_attrs, op->o_tmpmemctx );
+                       op->ors_attrs = NULL;
+               }
+               break;
+       default:
+               break;
        }
 
-       op = (Operation *)conn->c_pending_ops.stqh_first;
-       pb = SLAPI_OPERATION_PBLOCK( op );
-
-       slap_graduate_commit_csn( op );
-
-       slapi_ch_free_string( &op->o_req_dn.bv_val );
-       slapi_ch_free_string( &op->o_req_ndn.bv_val );
-       slapi_ch_free( (void **)&op->o_callback );
+       slapi_ch_free_string( &conn->c_authmech.bv_val );
+       slapi_ch_free_string( &conn->c_dn.bv_val );
+       slapi_ch_free_string( &conn->c_ndn.bv_val );
+       slapi_ch_free_string( &conn->c_peer_domain.bv_val );
+       slapi_ch_free_string( &conn->c_peer_name.bv_val );
 
        if ( conn->c_sb != NULL ) {
                ber_sockbuf_free( conn->c_sb );
        }
 
-       slapi_pblock_set( pb, SLAPI_OPERATION,  NULL );
-       slapi_pblock_set( pb, SLAPI_CONNECTION, NULL );
+       slapi_int_free_object_extensions( SLAPI_X_EXT_OPERATION, op );
+       slapi_int_free_object_extensions( SLAPI_X_EXT_CONNECTION, conn );
 
-       slapi_ch_free( (void **)&op );
-       slapi_ch_free( (void **)pConn );
+       slapi_ch_free( (void **)&pb->pb_op->o_callback );
+       slapi_ch_free( (void **)&pb->pb_op );
+       slapi_ch_free( (void **)&pb->pb_conn );
+       slapi_ch_free( (void **)&pb->pb_rs );
 }
 
-int
-slapi_delete_internal_pb( Slapi_PBlock *pb )
+static int
+slapi_int_func_internal_pb( Slapi_PBlock *pb, slap_operation_t which )
 {
-#ifdef LDAP_SLAPI
-       Connection              *conn = NULL;
-       Operation               *op = NULL;
+       BI_op_bind              **func;
+       SlapReply               *rs = pb->pb_rs;
+       int                     rc;
 
-       SlapReply               rs = { REP_RESULT };
+       PBLOCK_ASSERT_INTOP( pb, 0 );
 
-       if ( pb == NULL ) {
-               return -1;
+       rc = slapi_int_get_ctrls( pb );
+       if ( rc != LDAP_SUCCESS ) {
+               rs->sr_err = rc;
+               return rc;
        }
 
-       rs.sr_err = slapi_int_connection_init( pb, &rs, LDAP_REQ_DELETE, &conn );
-       if ( rs.sr_err != LDAP_SUCCESS ) {
-               slapi_pblock_set( pb, SLAPI_PLUGIN_INTOP_RESULT, (void *)rs.sr_err );
-               return 0;
+       pb->pb_op->o_bd = frontendDB;
+       func = &frontendDB->be_bind;
+
+       return func[which]( pb->pb_op, pb->pb_rs );
+}
+
+int
+slapi_delete_internal_pb( Slapi_PBlock *pb )
+{
+       if ( pb == NULL ) {
+               return -1;
        }
 
-       op = conn->c_pending_ops.stqh_first;
-       rs.sr_err = frontendDB->be_delete( op, &rs );
+       PBLOCK_ASSERT_INTOP( pb, LDAP_REQ_DELETE );
 
-       slapi_int_connection_destroy( &conn );
+       slapi_int_func_internal_pb( pb, op_delete );
 
        return 0;
-#else
-       return -1;
-#endif /* LDAP_SLAPI */
 }
 
 int
 slapi_add_internal_pb( Slapi_PBlock *pb )
 {
-#ifdef LDAP_SLAPI
-       Connection              *conn = NULL;
-       Slapi_Entry             *entry = NULL;
-       char                    *dn = NULL;
-       LDAPMod                 **mods = NULL;
-       Operation               *op = NULL;
-       char                    textbuf[ SLAP_TEXT_BUFLEN ];
-       size_t                  textlen = sizeof( textbuf );
-
-       SlapReply               rs = { REP_RESULT };
+       SlapReply               *rs;
+       Slapi_Entry             *entry_orig = NULL;
 
        if ( pb == NULL ) {
                return -1;
        }
 
-       slapi_pblock_get( pb, SLAPI_ADD_ENTRY,     (void **)&entry );
-       slapi_pblock_get( pb, SLAPI_ADD_TARGET,    (void **)&dn );
-       slapi_pblock_get( pb, SLAPI_MODIFY_MODS,   (void **)&mods );
+       PBLOCK_ASSERT_INTOP( pb, LDAP_REQ_ADD );
+
+       rs = pb->pb_rs;
 
-       if ( entry != NULL ) {
-               if ( dn != NULL ) {
-                       rs.sr_err = LDAP_PARAM_ERROR;
+       entry_orig = pb->pb_op->ora_e;
+       pb->pb_op->ora_e = NULL;
+
+       /*
+        * The caller can specify a new entry, or a target DN and set
+        * of modifications, but not both.
+        */
+       if ( entry_orig != NULL ) {
+               if ( pb->pb_op->ora_modlist != NULL || !BER_BVISNULL( &pb->pb_op->o_req_ndn )) {
+                       rs->sr_err = LDAP_PARAM_ERROR;
                        goto cleanup;
                }
 
-               dn = slapi_entry_get_dn( entry );
-               slapi_pblock_set( pb, SLAPI_ADD_TARGET, dn );
-       } else if ( mods == NULL || dn == NULL ) {
-               rs.sr_err = LDAP_PARAM_ERROR;
+               assert( BER_BVISNULL( &pb->pb_op->o_req_dn ) ); /* shouldn't get set */
+               ber_dupbv( &pb->pb_op->o_req_dn, &entry_orig->e_name );
+               ber_dupbv( &pb->pb_op->o_req_ndn, &entry_orig->e_nname );
+       } else if ( pb->pb_op->ora_modlist == NULL || BER_BVISNULL( &pb->pb_op->o_req_ndn )) {
+               rs->sr_err = LDAP_PARAM_ERROR;
                goto cleanup;
        }
 
-       rs.sr_err = slapi_int_connection_init( pb, &rs, LDAP_REQ_ADD, &conn );
-       if ( rs.sr_err != LDAP_SUCCESS ) {
-               goto cleanup;
-       }
+       pb->pb_op->ora_e = (Entry *)slapi_ch_calloc( 1, sizeof(Entry) );
+       ber_dupbv( &pb->pb_op->ora_e->e_name,  &pb->pb_op->o_req_dn );
+       ber_dupbv( &pb->pb_op->ora_e->e_nname, &pb->pb_op->o_req_ndn );
 
-       op = (Operation *)conn->c_pending_ops.stqh_first;
-       op->ora_e = NULL;
-       op->ora_modlist = NULL;
+       if ( entry_orig != NULL ) {
+               assert( pb->pb_op->ora_modlist == NULL );
 
-       /*
-        * The caller can specify a new entry, or a target DN and set
-        * of modifications, but not both.
-        */
-       op->ora_e = (Entry *)slapi_ch_calloc( 1, sizeof(*entry) );
-       ber_dupbv( &op->ora_e->e_name,  &op->o_req_dn );
-       ber_dupbv( &op->ora_e->e_nname, &op->o_req_ndn );
-
-       if ( mods != NULL ) {
-               /* Entry just contains name; attributes are in modlist */
-               op->ora_modlist = slapi_int_ldapmods2modifications( mods );
-               if ( op->ora_modlist == NULL ) {
-                       rs.sr_err = LDAP_PROTOCOL_ERROR;
+               rs->sr_err = slap_entry2mods( entry_orig, &pb->pb_op->ora_modlist,
+                       &rs->sr_text, pb->pb_textbuf, sizeof( pb->pb_textbuf ) );
+               if ( rs->sr_err != LDAP_SUCCESS ) {
                        goto cleanup;
                }
        } else {
-               rs.sr_err = slap_entry2mods( entry, &op->ora_modlist,
-                       &rs.sr_text, textbuf, textlen );
-               if ( rs.sr_err != LDAP_SUCCESS )
-                       goto cleanup;
+               assert( pb->pb_op->ora_modlist != NULL );
        }
 
-       rs.sr_err = slap_mods_check( op->ora_modlist, &rs.sr_text,
-               textbuf, textlen, NULL );
-       if ( rs.sr_err != LDAP_SUCCESS ) {
+       rs->sr_err = slap_mods_check( pb->pb_op->ora_modlist, &rs->sr_text,
+               pb->pb_textbuf, sizeof( pb->pb_textbuf ), NULL );
+       if ( rs->sr_err != LDAP_SUCCESS ) {
                 goto cleanup;
         }
 
-       rs.sr_err = frontendDB->be_add( op, &rs );
-       if ( rs.sr_err == 0 ) {
-               if ( op->ora_e != NULL && op->o_private != NULL ) {
-                       BackendDB       *bd = op->o_bd;
-
-                       /* could we use SLAPI_BACKEND instead? */
-                       op->o_bd = (BackendDB *)op->o_private;
-                       op->o_private = NULL;
-                       be_entry_release_w( op, op->ora_e );
-                       op->ora_e = NULL;
-                       op->o_bd = bd;
-                       op->o_private = NULL;
+       /* Duplicate the values, because we may call slapi_entry_free() */
+       rs->sr_err = slap_mods2entry( pb->pb_op->ora_modlist, &pb->pb_op->ora_e,
+               1, 0, &rs->sr_text, pb->pb_textbuf, sizeof( pb->pb_textbuf ) );
+       if ( rs->sr_err != LDAP_SUCCESS ) {
+               goto cleanup;
+       }
+
+       if ( slapi_int_func_internal_pb( pb, op_add ) == 0 ) {
+               if ( pb->pb_op->ora_e != NULL && pb->pb_op->o_private != NULL ) {
+                       BackendDB       *bd = pb->pb_op->o_bd;
+
+                       pb->pb_op->o_bd = (BackendDB *)pb->pb_op->o_private;
+                       pb->pb_op->o_private = NULL;
+                       be_entry_release_w( pb->pb_op, pb->pb_op->ora_e );
+                       pb->pb_op->ora_e = NULL;
+                       pb->pb_op->o_bd = bd;
+                       pb->pb_op->o_private = NULL;
                }
        }
 
 cleanup:
-       slapi_pblock_set( pb, SLAPI_PLUGIN_INTOP_RESULT, (void *)rs.sr_err );
 
-       slapi_entry_free( op->ora_e );
-       slapi_int_mods_free( op->ora_modlist );
-       slapi_int_connection_destroy( &conn );
+       if ( pb->pb_op->ora_e != NULL ) {
+               slapi_entry_free( pb->pb_op->ora_e );
+               pb->pb_op->ora_e = NULL;
+       }
+       if ( entry_orig != NULL ) {
+               pb->pb_op->ora_e = entry_orig;
+               slap_mods_free( pb->pb_op->ora_modlist, 1 );
+               pb->pb_op->ora_modlist = NULL;
+       }
 
        return 0;
-#else
-       return -1;
-#endif /* LDAP_SLAPI */
 }
 
 int
 slapi_modrdn_internal_pb( Slapi_PBlock *pb )
 {
-#ifdef LDAP_SLAPI
-       struct berval           newrdn = BER_BVNULL;
-       struct berval           newsupdn = BER_BVNULL;
-       struct berval           newSuperiorPretty = BER_BVNULL;
-       struct berval           newSuperiorNormalized = BER_BVNULL;
-       Connection              *conn = NULL;
-       Operation               *op = NULL;
-
-       char                    *lnewrdn;
-       char                    *newsuperior;
-       int                     deloldrdn;
-
-       SlapReply               rs = { REP_RESULT };
-
        if ( pb == NULL ) {
                return -1;
        }
 
-       slapi_pblock_get( pb, SLAPI_MODRDN_NEWRDN,      (void **)&lnewrdn );
-       slapi_pblock_get( pb, SLAPI_MODRDN_NEWSUPERIOR, (void **)&newsuperior );
-       slapi_pblock_get( pb, SLAPI_MODRDN_DELOLDRDN,   (void **)&deloldrdn );
+       PBLOCK_ASSERT_INTOP( pb, LDAP_REQ_MODRDN );
 
-       rs.sr_err = slapi_int_connection_init( pb, &rs, LDAP_REQ_MODRDN, &conn );
-       if ( rs.sr_err != LDAP_SUCCESS ) {
+       if ( BER_BVISEMPTY( &pb->pb_op->o_req_ndn ) ) {
+               pb->pb_rs->sr_err = LDAP_UNWILLING_TO_PERFORM;
                goto cleanup;
        }
 
-       op = (Operation *)conn->c_pending_ops.stqh_first;
-
-       if ( op->o_req_dn.bv_len == 0 ) {
-               rs.sr_err = LDAP_UNWILLING_TO_PERFORM;
-               goto cleanup;
-       }
-
-       newrdn.bv_val = lnewrdn;
-       newrdn.bv_len = strlen( lnewrdn );
-
-       rs.sr_err = dnPrettyNormal( NULL, &newrdn, &op->orr_newrdn, &op->orr_nnewrdn, NULL );
-       if ( rs.sr_err != LDAP_SUCCESS ) {
-               goto cleanup;
-       }
-
-       if ( rdn_validate( &op->orr_nnewrdn ) != LDAP_SUCCESS ) {
-               goto cleanup;
-       }
-
-       if ( newsuperior != NULL ) {
-               newsupdn.bv_val = (char *)newsuperior;
-               newsupdn.bv_len = strlen( newsuperior );
-
-               rs.sr_err = dnPrettyNormal( NULL, &newsupdn, &newSuperiorPretty, &newSuperiorNormalized, NULL );
-               if ( rs.sr_err != LDAP_SUCCESS )
-                       goto cleanup;
-
-               op->orr_newSup = &newSuperiorPretty;
-               op->orr_nnewSup = &newSuperiorNormalized;
-       } else {
-               op->orr_newSup = NULL;
-               op->orr_nnewSup = NULL;
-       }
-
-       op->orr_deleteoldrdn = deloldrdn;
-
-       rs.sr_err = frontendDB->be_modrdn( op, &rs );
+       slapi_int_func_internal_pb( pb, op_modrdn );
 
 cleanup:
-       slapi_pblock_set( pb, SLAPI_PLUGIN_INTOP_RESULT, (void *)rs.sr_err );
-
-       slapi_ch_free_string( &op->orr_newrdn.bv_val );
-       slapi_ch_free_string( &op->orr_nnewrdn.bv_val );
-       slapi_ch_free_string( &newSuperiorPretty.bv_val );
-       slapi_ch_free_string( &newSuperiorNormalized.bv_val );
-
-       slapi_int_connection_destroy( &conn );
 
        return 0;
-#else
-       return -1;
-#endif /* LDAP_SLAPI */
 }
 
 int
 slapi_modify_internal_pb( Slapi_PBlock *pb )
 {
-#ifdef LDAP_SLAPI
-       Connection              *conn = NULL;
-       Operation               *op = NULL;
-       LDAPMod                 **mods = NULL;
-       char                    textbuf[ SLAP_TEXT_BUFLEN ];
-       size_t                  textlen = sizeof( textbuf );
-
-       SlapReply               rs = { REP_RESULT };
+       SlapReply               *rs;
 
        if ( pb == NULL ) {
                return -1;
        }
 
-       slapi_pblock_get( pb, SLAPI_MODIFY_MODS, (void **)&mods );
+       PBLOCK_ASSERT_INTOP( pb, LDAP_REQ_MODIFY );
 
-       if ( mods == NULL ) {
-               rs.sr_err = LDAP_PARAM_ERROR ;
-               goto cleanup;
-       }
+       rs = pb->pb_rs;
 
-       rs.sr_err = slapi_int_connection_init( pb, &rs, LDAP_REQ_MODIFY, &conn );
-       if ( rs.sr_err != LDAP_SUCCESS ) {
+       if ( pb->pb_op->orm_modlist == NULL ) {
+               rs->sr_err = LDAP_PARAM_ERROR;
                goto cleanup;
        }
 
-       op = (Operation *)conn->c_pending_ops.stqh_first;
-
-       if ( op->o_req_ndn.bv_len == 0 ) {
-               rs.sr_err = LDAP_UNWILLING_TO_PERFORM;
+       if ( BER_BVISEMPTY( &pb->pb_op->o_req_ndn ) ) {
+               rs->sr_err = LDAP_UNWILLING_TO_PERFORM;
                goto cleanup;
        }
 
-       op->orm_modlist = slapi_int_ldapmods2modifications( mods );
-
-       rs.sr_err = slap_mods_check( op->orm_modlist, &rs.sr_text,
-               textbuf, textlen, NULL );
-       if ( rs.sr_err != LDAP_SUCCESS ) {
+       rs->sr_err = slap_mods_check( pb->pb_op->orm_modlist,
+               &rs->sr_text, pb->pb_textbuf, sizeof( pb->pb_textbuf ), NULL );
+       if ( rs->sr_err != LDAP_SUCCESS ) {
                 goto cleanup;
         }
 
-       rs.sr_err = frontendDB->be_modify( op, &rs );
+       slapi_int_func_internal_pb( pb, op_modify );
 
 cleanup:
-       slapi_pblock_set( pb, SLAPI_PLUGIN_INTOP_RESULT, (void *)rs.sr_err );
-
-       slapi_int_mods_free( op->orm_modlist );
-       slapi_int_connection_destroy( &conn );
 
        return 0;
-#else
-       return -1;
-#endif /* LDAP_SLAPI */
 }
 
-#ifdef LDAP_SLAPI
 static int
 slapi_int_search_entry_callback( Slapi_Entry *entry, void *callback_data )
 {
@@ -749,9 +570,11 @@ slapi_int_search_entry_callback( Slapi_Entry *entry, void *callback_data )
        Slapi_Entry     **head = NULL, **tp;
        Slapi_PBlock    *pb = (Slapi_PBlock *)callback_data;
 
+       PBLOCK_ASSERT_INTOP( pb, LDAP_REQ_SEARCH );
+
        entry = slapi_entry_dup( entry );
        if ( entry == NULL ) {
-               return 1;
+               return LDAP_NO_MEMORY;
        }
 
        slapi_pblock_get( pb, SLAPI_NENTRIES, &nentries );
@@ -762,40 +585,35 @@ slapi_int_search_entry_callback( Slapi_Entry *entry, void *callback_data )
                tp = (Slapi_Entry **)slapi_ch_malloc( 2 * sizeof(Slapi_Entry *) );
                if ( tp == NULL ) {
                        slapi_entry_free( entry );
-                       return 1;
+                       return LDAP_NO_MEMORY;
                }
 
-               tp[ 0 ] = entry;
+               tp[0] = entry;
        } else {
                tp = (Slapi_Entry **)slapi_ch_realloc( (char *)head,
                                sizeof(Slapi_Entry *) * ( i + 1 ) );
                if ( tp == NULL ) {
                        slapi_entry_free( entry );
-                       return 1;
+                       return LDAP_NO_MEMORY;
                }
-               tp[ i - 1 ] = entry;
+               tp[i - 1] = entry;
        }
-       tp[ i ] = NULL;
+       tp[i] = NULL;
                  
        slapi_pblock_set( pb, SLAPI_PLUGIN_INTOP_SEARCH_ENTRIES, (void *)tp );
-       slapi_pblock_set( pb, SLAPI_NENTRIES, (void *)i );
+       slapi_pblock_set( pb, SLAPI_NENTRIES, (void *)&i );
 
        return LDAP_SUCCESS;
 }
-#endif /* LDAP_SLAPI */
 
 int
 slapi_search_internal_pb( Slapi_PBlock *pb )
 {
-#ifdef LDAP_SLAPI
        return slapi_search_internal_callback_pb( pb,
                (void *)pb,
                NULL,
                slapi_int_search_entry_callback,
                NULL );
-#else
-       return -1;
-#endif
 }
 
 int
@@ -805,37 +623,16 @@ slapi_search_internal_callback_pb( Slapi_PBlock *pb,
        plugin_search_entry_callback psec,
        plugin_referral_entry_callback prec )
 {
-#ifdef LDAP_SLAPI
-       Connection              *conn = NULL;
-       Operation               *op = NULL;
-       Filter                  *filter = NULL;
-       struct berval           fstr = BER_BVNULL;
-       AttributeName           *an = NULL;
-       const char              *text = NULL;
-
-       int                     scope = LDAP_SCOPE_BASE;
-       char                    *filStr = NULL;
-       char                    **attrs = NULL;
-       int                     attrsonly = 0;
-       int                     freeFilter = 0;
-       int                     i;
-
-       SlapReply               rs = { REP_RESULT };
+       int                     free_filter = 0;
+       SlapReply               *rs;
 
        if ( pb == NULL ) {
                return -1;
        }
 
-       slapi_pblock_get( pb, SLAPI_SEARCH_SCOPE,     (void **)&scope );
-       slapi_pblock_get( pb, SLAPI_SEARCH_FILTER,    (void **)&filter );
-       slapi_pblock_get( pb, SLAPI_SEARCH_STRFILTER, (void **)&filStr );
-       slapi_pblock_get( pb, SLAPI_SEARCH_ATTRS,     (void **)&attrs );
-       slapi_pblock_get( pb, SLAPI_SEARCH_ATTRSONLY, (void **)&attrsonly );
+       PBLOCK_ASSERT_INTOP( pb, LDAP_REQ_SEARCH );
 
-       rs.sr_err = slapi_int_connection_init( pb, &rs, LDAP_REQ_SEARCH, &conn );
-       if ( rs.sr_err != LDAP_SUCCESS ) {
-               goto cleanup;
-       }
+       rs = pb->pb_rs;
 
        /* search callback and arguments */
        slapi_pblock_set( pb, SLAPI_X_INTOP_RESULT_CALLBACK,         (void *)prc );
@@ -843,87 +640,35 @@ slapi_search_internal_callback_pb( Slapi_PBlock *pb,
        slapi_pblock_set( pb, SLAPI_X_INTOP_REFERRAL_ENTRY_CALLBACK, (void *)prec );
        slapi_pblock_set( pb, SLAPI_X_INTOP_CALLBACK_DATA,           (void *)callback_data );
 
-       op = (Operation *)conn->c_pending_ops.stqh_first;
-
-       switch ( scope ) {
-               case LDAP_SCOPE_BASE:
-               case LDAP_SCOPE_ONELEVEL:
-               case LDAP_SCOPE_SUBTREE:
-#ifdef LDAP_SCOPE_SUBORDINATE
-               case LDAP_SCOPE_SUBORDINATE:
-#endif
-                       break;
-               default:
-                       rs.sr_err = LDAP_PROTOCOL_ERROR;
-                       goto cleanup;
+       if ( BER_BVISEMPTY( &pb->pb_op->ors_filterstr )) {
+               rs->sr_err = LDAP_PARAM_ERROR;
+               goto cleanup;
        }
 
-       if ( filter == NULL ) {
-               if ( filStr == NULL ) {
-                       rs.sr_err = LDAP_PARAM_ERROR;
+       if ( pb->pb_op->ors_filter == NULL ) {
+               pb->pb_op->ors_filter = slapi_str2filter( pb->pb_op->ors_filterstr.bv_val );
+               if ( pb->pb_op->ors_filter == NULL ) {
+                       rs->sr_err = LDAP_PROTOCOL_ERROR;
                        goto cleanup;
                }
 
-               filter = slapi_str2filter( filStr );
-               if ( filter == NULL ) {
-                       rs.sr_err = LDAP_PROTOCOL_ERROR;
-                       goto cleanup;
-               }
-
-               freeFilter = 1;
-       }
-
-       filter2bv( filter, &fstr );
-
-       for ( i = 0; attrs != NULL && attrs[i] != NULL; i++ ) {
-               ; /* count the number of attributes */
-       }
-
-       if ( i > 0 ) {
-               an = (AttributeName *)slapi_ch_calloc( (i + 1), sizeof(AttributeName) );
-               for (i = 0; attrs[i] != 0; i++) {
-                       an[i].an_desc = NULL;
-                       an[i].an_oc = NULL;
-                       an[i].an_oc_exclude = 0;
-                       an[i].an_name.bv_val = attrs[i];
-                       an[i].an_name.bv_len = strlen(attrs[i]);
-                       slap_bv2ad( &an[i].an_name, &an[i].an_desc, &text );
-               }
-               an[i].an_name.bv_val = NULL;
+               free_filter = 1;
        }
 
-       rs.sr_type = REP_RESULT;
-       rs.sr_err = LDAP_SUCCESS;
-       rs.sr_entry = NULL; /* paranoia */
-       op->ors_scope = scope;
-       op->ors_deref = 0;
-       op->ors_slimit = SLAP_NO_LIMIT;
-       op->ors_tlimit = SLAP_NO_LIMIT;
-       op->ors_attrsonly = attrsonly;
-       op->ors_attrs = an;
-       op->ors_filter = filter;
-       op->ors_filterstr = fstr;
-
-       rs.sr_err = frontendDB->be_search( op, &rs );
+       slapi_int_func_internal_pb( pb, op_search );
 
 cleanup:
-       slapi_pblock_set( pb, SLAPI_PLUGIN_INTOP_RESULT,            (void *)rs.sr_err );
-       slapi_pblock_set( pb, SLAPI_X_INTOP_RESULT_CALLBACK,         NULL );
-       slapi_pblock_set( pb, SLAPI_X_INTOP_SEARCH_ENTRY_CALLBACK,   NULL );
-       slapi_pblock_set( pb, SLAPI_X_INTOP_REFERRAL_ENTRY_CALLBACK, NULL );
-       slapi_pblock_set( pb, SLAPI_X_INTOP_CALLBACK_DATA,           NULL );
-
-       if ( freeFilter && filter != NULL )
-               slapi_filter_free( filter, 1 );
-       slapi_ch_free_string( &fstr.bv_val );
-       slapi_ch_free( (void **)&an );
+       if ( free_filter ) {
+               slapi_filter_free( pb->pb_op->ors_filter, 1 );
+               pb->pb_op->ors_filter = NULL;
+       }
 
-       slapi_int_connection_destroy( &conn );
+       slapi_pblock_delete_param( pb, SLAPI_X_INTOP_RESULT_CALLBACK );
+       slapi_pblock_delete_param( pb, SLAPI_X_INTOP_SEARCH_ENTRY_CALLBACK );
+       slapi_pblock_delete_param( pb, SLAPI_X_INTOP_REFERRAL_ENTRY_CALLBACK );
+       slapi_pblock_delete_param( pb, SLAPI_X_INTOP_CALLBACK_DATA );
 
        return 0;
-#else
-       return -1;
-#endif /* LDAP_SLAPI */
 }
 
 /* Wrappers for old API */
@@ -940,18 +685,25 @@ slapi_search_internal_set_pb( Slapi_PBlock *pb,
        Slapi_ComponentId *plugin_identity,
        int operation_flags )
 {
-#ifdef LDAP_SLAPI
+       int no_limit = SLAP_NO_LIMIT;
+       int deref = LDAP_DEREF_NEVER;
+
+       slapi_int_connection_init_pb( pb, LDAP_REQ_SEARCH );
        slapi_pblock_set( pb, SLAPI_SEARCH_TARGET,    (void *)base );
-       slapi_pblock_set( pb, SLAPI_SEARCH_SCOPE,     (void *)scope );
-       slapi_pblock_set( pb, SLAPI_SEARCH_FILTER,     NULL );
+       slapi_pblock_set( pb, SLAPI_SEARCH_SCOPE,     (void *)&scope );
+       slapi_pblock_set( pb, SLAPI_SEARCH_FILTER,    (void *)0 );
        slapi_pblock_set( pb, SLAPI_SEARCH_STRFILTER, (void *)filter );
        slapi_pblock_set( pb, SLAPI_SEARCH_ATTRS,     (void *)attrs );
-       slapi_pblock_set( pb, SLAPI_SEARCH_ATTRSONLY, (void *)attrsonly );
+       slapi_pblock_set( pb, SLAPI_SEARCH_ATTRSONLY, (void *)&attrsonly );
        slapi_pblock_set( pb, SLAPI_REQCONTROLS,      (void *)controls );
        slapi_pblock_set( pb, SLAPI_TARGET_UNIQUEID,  (void *)uniqueid );
        slapi_pblock_set( pb, SLAPI_PLUGIN_IDENTITY,  (void *)plugin_identity );
-       slapi_pblock_set( pb, SLAPI_X_INTOP_FLAGS,    (void *)operation_flags );
-#endif /* LDAP_SLAPI */
+       slapi_pblock_set( pb, SLAPI_X_INTOP_FLAGS,    (void *)&operation_flags );
+       slapi_pblock_set( pb, SLAPI_SEARCH_DEREF,     (void *)&deref );
+       slapi_pblock_set( pb, SLAPI_SEARCH_SIZELIMIT, (void *)&no_limit );
+       slapi_pblock_set( pb, SLAPI_SEARCH_TIMELIMIT, (void *)&no_limit );
+
+       slapi_int_set_operation_dn( pb );
 }
 
 Slapi_PBlock *
@@ -963,23 +715,17 @@ slapi_search_internal(
        char **attrs, 
        int attrsonly ) 
 {
-#ifdef LDAP_SLAPI
        Slapi_PBlock *pb;
 
        pb = slapi_pblock_new();
-       if ( pb == NULL ) {
-               return NULL;
-       }
 
-       slapi_search_internal_set_pb( pb, ldn, scope, filStr, attrs, attrsonly,
+       slapi_search_internal_set_pb( pb, ldn, scope, filStr,
+               attrs, attrsonly,
                controls, NULL, NULL, 0 );
 
        slapi_search_internal_pb( pb );
 
        return pb;
-#else
-       return NULL;
-#endif /* LDAP_SLAPI */
 }
 
 void
@@ -991,14 +737,14 @@ slapi_modify_internal_set_pb( Slapi_PBlock *pb,
        Slapi_ComponentId *plugin_identity,
        int operation_flags )
 {
-#ifdef LDAP_SLAPI
+       slapi_int_connection_init_pb( pb, LDAP_REQ_MODIFY );
        slapi_pblock_set( pb, SLAPI_MODIFY_TARGET,   (void *)dn );
        slapi_pblock_set( pb, SLAPI_MODIFY_MODS,     (void *)mods );
        slapi_pblock_set( pb, SLAPI_REQCONTROLS,     (void *)controls );
        slapi_pblock_set( pb, SLAPI_TARGET_UNIQUEID, (void *)uniqueid );
        slapi_pblock_set( pb, SLAPI_PLUGIN_IDENTITY, (void *)plugin_identity );
-       slapi_pblock_set( pb, SLAPI_X_INTOP_FLAGS,   (void *)operation_flags );
-#endif /* LDAP_SLAPI */
+       slapi_pblock_set( pb, SLAPI_X_INTOP_FLAGS,   (void *)&operation_flags );
+       slapi_int_set_operation_dn( pb );
 }
 
 /* Function : slapi_modify_internal
@@ -1018,23 +764,15 @@ slapi_modify_internal(
        LDAPControl **controls, 
        int log_change )
 {
-#ifdef LDAP_SLAPI
        Slapi_PBlock *pb;
 
        pb = slapi_pblock_new();
-       if ( pb == NULL ) {
-               return NULL;
-       }
-
-       slapi_modify_internal_set_pb( pb, ldn, mods, controls, NULL, NULL,
-               log_change ? SLAPI_OP_FLAG_LOG_CHANGE : 0 );
 
+       slapi_modify_internal_set_pb( pb, ldn, mods, controls, NULL, NULL, 0 );
+       slapi_pblock_set( pb, SLAPI_LOG_OPERATION, (void *)&log_change );
        slapi_modify_internal_pb( pb );
 
        return pb;
-#else
-       return NULL;
-#endif /* LDAP_SLAPI */
 }
 
 int
@@ -1045,17 +783,15 @@ slapi_add_internal_set_pb( Slapi_PBlock *pb,
        Slapi_ComponentId *plugin_identity,
        int operation_flags )
 {
-#ifdef LDAP_SLAPI
+       slapi_int_connection_init_pb( pb, LDAP_REQ_ADD );
        slapi_pblock_set( pb, SLAPI_ADD_TARGET,      (void *)dn );
        slapi_pblock_set( pb, SLAPI_MODIFY_MODS,     (void *)attrs );
        slapi_pblock_set( pb, SLAPI_REQCONTROLS,     (void *)controls );
        slapi_pblock_set( pb, SLAPI_PLUGIN_IDENTITY, (void *)plugin_identity );
-       slapi_pblock_set( pb, SLAPI_X_INTOP_FLAGS,   (void *)operation_flags );
+       slapi_pblock_set( pb, SLAPI_X_INTOP_FLAGS,   (void *)&operation_flags );
+       slapi_int_set_operation_dn( pb );
 
        return 0;
-#else
-       return -1;
-#endif /* LDAP_SLAPI */
 }
 
 Slapi_PBlock *
@@ -1063,24 +799,17 @@ slapi_add_internal(
        char * dn,
        LDAPMod **attrs,
        LDAPControl **controls,
-       int log_changes )
+       int log_change )
 {
-#ifdef LDAP_SLAPI
        Slapi_PBlock *pb;
 
        pb = slapi_pblock_new();
-       if ( pb == NULL )
-               return NULL;
 
-       slapi_add_internal_set_pb( pb, dn, attrs, controls, NULL,
-               log_changes ? SLAPI_OP_FLAG_LOG_CHANGE : 0 );
-       
+       slapi_add_internal_set_pb( pb, dn, attrs, controls, NULL, 0);
+       slapi_pblock_set( pb, SLAPI_LOG_OPERATION, (void *)&log_change );
        slapi_add_internal_pb( pb );
 
        return pb;
-#else
-       return NULL;
-#endif /* LDAP_SLAPI */
 }
 
 void
@@ -1090,36 +819,29 @@ slapi_add_entry_internal_set_pb( Slapi_PBlock *pb,
        Slapi_ComponentId *plugin_identity,
        int operation_flags )
 {
-#ifdef LDAP_SLAPI
+       slapi_int_connection_init_pb( pb, LDAP_REQ_ADD );
        slapi_pblock_set( pb, SLAPI_ADD_ENTRY,       (void *)e );
        slapi_pblock_set( pb, SLAPI_REQCONTROLS,     (void *)controls );
        slapi_pblock_set( pb, SLAPI_PLUGIN_IDENTITY, (void *)plugin_identity );
-       slapi_pblock_set( pb, SLAPI_X_INTOP_FLAGS,   (void *)operation_flags );
-#endif /* LDAP_SLAPI */
+       slapi_pblock_set( pb, SLAPI_X_INTOP_FLAGS,   (void *)&operation_flags );
+       slapi_int_set_operation_dn( pb );
 }
 
 Slapi_PBlock * 
 slapi_add_entry_internal(
        Slapi_Entry *e, 
        LDAPControl **controls, 
-       int log_changes )
+       int log_change )
 {
-#ifdef LDAP_SLAPI
        Slapi_PBlock *pb;
 
        pb = slapi_pblock_new();
-       if ( pb == NULL )
-               return NULL;
 
-       slapi_add_entry_internal_set_pb( pb, e, controls, NULL,
-               log_changes ? SLAPI_OP_FLAG_LOG_CHANGE : 0 );
-       
+       slapi_add_entry_internal_set_pb( pb, e, controls, NULL, 0 );
+       slapi_pblock_set( pb, SLAPI_LOG_OPERATION, (void *)&log_change );
        slapi_add_internal_pb( pb );
 
        return pb;
-#else
-       return NULL;
-#endif /* LDAP_SLAPI */
 }
 
 void
@@ -1133,16 +855,17 @@ slapi_rename_internal_set_pb( Slapi_PBlock *pb,
        Slapi_ComponentId *plugin_identity,
        int operation_flags )
 {
-#ifdef LDAP_SLAPI
+       slapi_int_connection_init_pb( pb, LDAP_REQ_MODRDN );
        slapi_pblock_set( pb, SLAPI_MODRDN_TARGET,      (void *)olddn );
        slapi_pblock_set( pb, SLAPI_MODRDN_NEWRDN,      (void *)newrdn );
        slapi_pblock_set( pb, SLAPI_MODRDN_NEWSUPERIOR, (void *)newsuperior );
-       slapi_pblock_set( pb, SLAPI_MODRDN_DELOLDRDN,   (void *)deloldrdn );
+       slapi_pblock_set( pb, SLAPI_MODRDN_DELOLDRDN,   (void *)&deloldrdn );
        slapi_pblock_set( pb, SLAPI_REQCONTROLS,        (void *)controls );
        slapi_pblock_set( pb, SLAPI_TARGET_UNIQUEID,    (void *)uniqueid );
        slapi_pblock_set( pb, SLAPI_PLUGIN_IDENTITY,    (void *)plugin_identity );
-       slapi_pblock_set( pb, SLAPI_X_INTOP_FLAGS,      (void *)operation_flags );
-#endif /* LDAP_SLAPI */
+       slapi_pblock_set( pb, SLAPI_X_INTOP_FLAGS,      (void *)&operation_flags );
+       slap_modrdn2mods( pb->pb_op, pb->pb_rs );
+       slapi_int_set_operation_dn( pb );
 }
 
 /* Function : slapi_modrdn_internal
@@ -1165,24 +888,16 @@ slapi_modrdn_internal(
        LDAPControl **controls, 
        int log_change )
 {
-#ifdef LDAP_SLAPI
        Slapi_PBlock *pb;
 
-       pb = slapi_pblock_new();
-       if ( pb == NULL ) {
-               return NULL;
-       }
+       pb = slapi_pblock_new ();
 
        slapi_rename_internal_set_pb( pb, olddn, lnewrdn, NULL,
-               deloldrdn, controls, NULL, NULL,
-               log_change ? SLAPI_OP_FLAG_LOG_CHANGE : 0 );
-
+               deloldrdn, controls, NULL, NULL, 0 );
+       slapi_pblock_set( pb, SLAPI_LOG_OPERATION, (void *)&log_change );
        slapi_modrdn_internal_pb( pb );
 
        return pb;
-#else
-       return NULL;
-#endif /* LDAP_SLAPI */
 }
 
 void
@@ -1193,13 +908,13 @@ slapi_delete_internal_set_pb( Slapi_PBlock *pb,
        Slapi_ComponentId *plugin_identity,
        int operation_flags )
 {
-#ifdef LDAP_SLAPI
+       slapi_int_connection_init_pb( pb, LDAP_REQ_DELETE );
        slapi_pblock_set( pb, SLAPI_TARGET_DN,       (void *)dn );
        slapi_pblock_set( pb, SLAPI_REQCONTROLS,     (void *)controls );
        slapi_pblock_set( pb, SLAPI_TARGET_UNIQUEID, (void *)uniqueid );
        slapi_pblock_set( pb, SLAPI_PLUGIN_IDENTITY, (void *)plugin_identity );
-       slapi_pblock_set( pb, SLAPI_X_INTOP_FLAGS,   (void *)operation_flags );
-#endif /* LDAP_SLAPI */
+       slapi_pblock_set( pb, SLAPI_X_INTOP_FLAGS,   (void *)&operation_flags );
+       slapi_int_set_operation_dn( pb );
 }
 
 /* Function : slapi_delete_internal
@@ -1218,21 +933,16 @@ slapi_delete_internal(
        LDAPControl **controls, 
        int log_change )
 {
-#ifdef LDAP_SLAPI
        Slapi_PBlock *pb;
 
        pb = slapi_pblock_new();
-       if ( pb == NULL )
-               return NULL;
-
-       slapi_delete_internal_set_pb( pb, ldn, controls, NULL, NULL,
-               log_change ? SLAPI_OP_FLAG_LOG_CHANGE : 0 );
 
+       slapi_delete_internal_set_pb( pb, ldn, controls, NULL, NULL, 0 );
+       slapi_pblock_set( pb, SLAPI_LOG_OPERATION, (void *)&log_change );
        slapi_delete_internal_pb( pb );
 
        return pb;
-#else
-       return NULL;
-#endif /* LDAP_SLAPI */
 }
 
+#endif /* LDAP_SLAPI */
+