X-Git-Url: https://git.sur5r.net/?a=blobdiff_plain;f=servers%2Fslapd%2Fback-ldap%2Finit.c;h=60e60c5fe9f1375d3e7b1fd0ae45f8d0ee2a18df;hb=473e2c997f6b1f226d35da186db8033c922001f3;hp=74ef0b6b44a45603b8479557c3e7a71e3a5164c5;hpb=3ebb40c4ddfc5ec2d3445a831a35096b48a7862f;p=openldap
diff --git a/servers/slapd/back-ldap/init.c b/servers/slapd/back-ldap/init.c
index 74ef0b6b44..60e60c5fe9 100644
--- a/servers/slapd/back-ldap/init.c
+++ b/servers/slapd/back-ldap/init.c
@@ -2,7 +2,7 @@
/* $OpenLDAP$ */
/* This work is part of OpenLDAP Software .
*
- * Copyright 2003-2006 The OpenLDAP Foundation.
+ * Copyright 2003-2011 The OpenLDAP Foundation.
* Portions Copyright 1999-2003 Howard Chu.
* Portions Copyright 2000-2003 Pierangelo Masarati.
* All rights reserved.
@@ -29,8 +29,21 @@
#include
#include "slap.h"
+#include "config.h"
#include "back-ldap.h"
+static const ldap_extra_t ldap_extra = {
+ ldap_back_proxy_authz_ctrl,
+ ldap_back_controls_free,
+ slap_idassert_authzfrom_parse_cf,
+ slap_idassert_passthru_parse_cf,
+ slap_idassert_parse_cf,
+ slap_retry_info_destroy,
+ slap_retry_info_parse,
+ slap_retry_info_unparse,
+ ldap_back_connid2str
+};
+
int
ldap_back_open( BackendInfo *bi )
{
@@ -41,6 +54,8 @@ ldap_back_open( BackendInfo *bi )
int
ldap_back_initialize( BackendInfo *bi )
{
+ int rc;
+
bi->bi_flags =
#ifdef LDAP_DYNAMIC_OBJECTS
/* this is set because all the support a proxy has to provide
@@ -49,7 +64,10 @@ ldap_back_initialize( BackendInfo *bi )
* and the entryTtl attribute */
SLAP_BFLAG_DYNAMIC |
#endif /* LDAP_DYNAMIC_OBJECTS */
- 0;
+
+ /* back-ldap recognizes RFC4525 increment;
+ * let the remote server complain, if needed (ITS#5912) */
+ SLAP_BFLAG_INCREMENT;
bi->bi_open = ldap_back_open;
bi->bi_config = 0;
@@ -59,7 +77,7 @@ ldap_back_initialize( BackendInfo *bi )
bi->bi_db_init = ldap_back_db_init;
bi->bi_db_config = config_generic_wrapper;
bi->bi_db_open = ldap_back_db_open;
- bi->bi_db_close = 0;
+ bi->bi_db_close = ldap_back_db_close;
bi->bi_db_destroy = ldap_back_db_destroy;
bi->bi_op_bind = ldap_back_bind;
@@ -80,23 +98,38 @@ ldap_back_initialize( BackendInfo *bi )
bi->bi_connection_init = 0;
bi->bi_connection_destroy = ldap_back_conn_destroy;
- if ( chain_initialize() ) {
- return -1;
+ bi->bi_extra = (void *)&ldap_extra;
+
+ rc = ldap_back_init_cf( bi );
+ if ( rc ) {
+ return rc;
}
-#ifdef LDAP_DEVEL
- if ( distproc_initialize() ) {
- return -1;
+ rc = chain_initialize();
+ if ( rc ) {
+ return rc;
+ }
+
+ rc = pbind_initialize();
+ if ( rc ) {
+ return rc;
}
-#endif
- return ldap_back_init_cf( bi );
+#ifdef SLAP_DISTPROC
+ rc = distproc_initialize();
+ if ( rc ) {
+ return rc;
+ }
+#endif
+ return rc;
}
int
-ldap_back_db_init( Backend *be )
+ldap_back_db_init( Backend *be, ConfigReply *cr )
{
ldapinfo_t *li;
+ int rc;
+ unsigned i;
li = (ldapinfo_t *)ch_calloc( 1, sizeof( ldapinfo_t ) );
if ( li == NULL ) {
@@ -141,19 +174,34 @@ ldap_back_db_init( Backend *be )
ldap_pvt_thread_mutex_init( &li->li_conninfo.lai_mutex );
+ for ( i = LDAP_BACK_PCONN_FIRST; i < LDAP_BACK_PCONN_LAST; i++ ) {
+ li->li_conn_priv[ i ].lic_num = 0;
+ LDAP_TAILQ_INIT( &li->li_conn_priv[ i ].lic_priv );
+ }
+ li->li_conn_priv_max = LDAP_BACK_CONN_PRIV_DEFAULT;
+
be->be_private = li;
SLAP_DBFLAGS( be ) |= SLAP_DBFLAG_NOLASTMOD;
be->be_cf_ocs = be->bd_info->bi_cf_ocs;
- return 0;
+ rc = ldap_back_monitor_db_init( be );
+ if ( rc != 0 ) {
+ /* ignore, by now */
+ rc = 0;
+ }
+
+ return rc;
}
int
-ldap_back_db_open( BackendDB *be )
+ldap_back_db_open( BackendDB *be, ConfigReply *cr )
{
ldapinfo_t *li = (ldapinfo_t *)be->be_private;
+ slap_bindconf sb = { BER_BVNULL };
+ int rc = 0;
+
Debug( LDAP_DEBUG_TRACE,
"ldap_back_db_open: URI=%s\n",
li->li_uri != NULL ? li->li_uri : "", 0, 0 );
@@ -171,39 +219,13 @@ ldap_back_db_open( BackendDB *be )
break;
}
-#if 0 && defined(SLAPD_MONITOR)
- {
- /* FIXME: disabled because namingContexts doesn't have
- * a matching rule, and using an MRA filter doesn't work
- * because the normalized assertion is compared to the
- * non-normalized value, which in general differs from
- * the normalized one. See ITS#3406 */
- struct berval filter,
- base = BER_BVC( "cn=Databases," SLAPD_MONITOR );
- Attribute a = { 0 };
-
- filter.bv_len = STRLENOF( "(&(namingContexts:distinguishedNameMatch:=)(monitoredInfo=ldap))" )
- + be->be_nsuffix[ 0 ].bv_len;
- filter.bv_val = ch_malloc( filter.bv_len + 1 );
- snprintf( filter.bv_val, filter.bv_len + 1,
- "(&(namingContexts:distinguishedNameMatch:=%s)(monitoredInfo=ldap))",
- be->be_nsuffix[ 0 ].bv_val );
-
- a.a_desc = slap_schema.si_ad_labeledURI;
- a.a_vals = li->li_bvuri;
- a.a_nvals = li->li_bvuri;
- if ( monitor_back_register_entry_attrs( NULL, &a, NULL, &base, LDAP_SCOPE_SUBTREE, &filter ) ) {
- /* error */
- }
-
- ch_free( filter.bv_val );
- }
-#endif /* SLAPD_MONITOR */
+ ber_str2bv( li->li_uri, 0, 0, &sb.sb_uri );
+ sb.sb_version = li->li_version;
+ sb.sb_method = LDAP_AUTH_SIMPLE;
+ BER_BVSTR( &sb.sb_binddn, "" );
if ( LDAP_BACK_T_F_DISCOVER( li ) && !LDAP_BACK_T_F( li ) ) {
- int rc;
-
- rc = slap_discover_feature( li->li_uri, li->li_version,
+ rc = slap_discover_feature( &sb,
slap_schema.si_ad_supportedFeatures->ad_cname.bv_val,
LDAP_FEATURE_ABSOLUTE_FILTERS );
if ( rc == LDAP_COMPARE_TRUE ) {
@@ -212,9 +234,7 @@ ldap_back_db_open( BackendDB *be )
}
if ( LDAP_BACK_CANCEL_DISCOVER( li ) && !LDAP_BACK_CANCEL( li ) ) {
- int rc;
-
- rc = slap_discover_feature( li->li_uri, li->li_version,
+ rc = slap_discover_feature( &sb,
slap_schema.si_ad_supportedExtension->ad_cname.bv_val,
LDAP_EXOP_CANCEL );
if ( rc == LDAP_COMPARE_TRUE ) {
@@ -222,9 +242,16 @@ ldap_back_db_open( BackendDB *be )
}
}
+ /* monitor setup */
+ rc = ldap_back_monitor_db_open( be );
+ if ( rc != 0 ) {
+ /* ignore by now */
+ rc = 0;
+ }
+
li->li_flags |= LDAP_BACK_F_ISOPEN;
- return 0;
+ return rc;
}
void
@@ -245,16 +272,31 @@ ldap_back_conn_free( void *v_lc )
if ( !BER_BVISNULL( &lc->lc_local_ndn ) ) {
ch_free( lc->lc_local_ndn.bv_val );
}
+ lc->lc_q.tqe_prev = NULL;
+ lc->lc_q.tqe_next = NULL;
ch_free( lc );
}
int
-ldap_back_db_destroy(
- Backend *be
-)
+ldap_back_db_close( Backend *be, ConfigReply *cr )
+{
+ int rc = 0;
+
+ if ( be->be_private ) {
+ rc = ldap_back_monitor_db_close( be );
+ }
+
+ return rc;
+}
+
+int
+ldap_back_db_destroy( Backend *be, ConfigReply *cr )
{
if ( be->be_private ) {
ldapinfo_t *li = ( ldapinfo_t * )be->be_private;
+ unsigned i;
+
+ (void)ldap_back_monitor_db_destroy( be );
ldap_pvt_thread_mutex_lock( &li->li_conninfo.lai_mutex );
@@ -266,50 +308,11 @@ ldap_back_db_destroy(
ber_bvarray_free( li->li_bvuri );
li->li_bvuri = NULL;
}
- if ( !BER_BVISNULL( &li->li_acl_authcID ) ) {
- ch_free( li->li_acl_authcID.bv_val );
- BER_BVZERO( &li->li_acl_authcID );
- }
- if ( !BER_BVISNULL( &li->li_acl_authcDN ) ) {
- ch_free( li->li_acl_authcDN.bv_val );
- BER_BVZERO( &li->li_acl_authcDN );
- }
- if ( !BER_BVISNULL( &li->li_acl_passwd ) ) {
- ch_free( li->li_acl_passwd.bv_val );
- BER_BVZERO( &li->li_acl_passwd );
- }
- if ( !BER_BVISNULL( &li->li_acl_sasl_mech ) ) {
- ch_free( li->li_acl_sasl_mech.bv_val );
- BER_BVZERO( &li->li_acl_sasl_mech );
- }
- if ( !BER_BVISNULL( &li->li_acl_sasl_realm ) ) {
- ch_free( li->li_acl_sasl_realm.bv_val );
- BER_BVZERO( &li->li_acl_sasl_realm );
- }
- if ( !BER_BVISNULL( &li->li_idassert_authcID ) ) {
- ch_free( li->li_idassert_authcID.bv_val );
- BER_BVZERO( &li->li_idassert_authcID );
- }
- if ( !BER_BVISNULL( &li->li_idassert_authcDN ) ) {
- ch_free( li->li_idassert_authcDN.bv_val );
- BER_BVZERO( &li->li_idassert_authcDN );
- }
- if ( !BER_BVISNULL( &li->li_idassert_passwd ) ) {
- ch_free( li->li_idassert_passwd.bv_val );
- BER_BVZERO( &li->li_idassert_passwd );
- }
- if ( !BER_BVISNULL( &li->li_idassert_authzID ) ) {
- ch_free( li->li_idassert_authzID.bv_val );
- BER_BVZERO( &li->li_idassert_authzID );
- }
- if ( !BER_BVISNULL( &li->li_idassert_sasl_mech ) ) {
- ch_free( li->li_idassert_sasl_mech.bv_val );
- BER_BVZERO( &li->li_idassert_sasl_mech );
- }
- if ( !BER_BVISNULL( &li->li_idassert_sasl_realm ) ) {
- ch_free( li->li_idassert_sasl_realm.bv_val );
- BER_BVZERO( &li->li_idassert_sasl_realm );
- }
+
+ bindconf_free( &li->li_tls );
+ bindconf_free( &li->li_acl );
+ bindconf_free( &li->li_idassert.si_bc );
+
if ( li->li_idassert_authz != NULL ) {
ber_bvarray_free( li->li_idassert_authz );
li->li_idassert_authz = NULL;
@@ -317,6 +320,14 @@ ldap_back_db_destroy(
if ( li->li_conninfo.lai_tree ) {
avl_free( li->li_conninfo.lai_tree, ldap_back_conn_free );
}
+ for ( i = LDAP_BACK_PCONN_FIRST; i < LDAP_BACK_PCONN_LAST; i++ ) {
+ while ( !LDAP_TAILQ_EMPTY( &li->li_conn_priv[ i ].lic_priv ) ) {
+ ldapconn_t *lc = LDAP_TAILQ_FIRST( &li->li_conn_priv[ i ].lic_priv );
+
+ LDAP_TAILQ_REMOVE( &li->li_conn_priv[ i ].lic_priv, lc, lc_q );
+ ldap_back_conn_free( lc );
+ }
+ }
if ( LDAP_BACK_QUARANTINE( li ) ) {
slap_retry_info_destroy( &li->li_quarantine );
ldap_pvt_thread_mutex_destroy( &li->li_quarantine_mutex );