X-Git-Url: https://git.sur5r.net/?a=blobdiff_plain;f=servers%2Fslapd%2Fschema_init.c;h=789c7f001aba99ad81d6520cd3b4bd0143a07cd2;hb=86bd3651e1bc6129cf2bd4ba271f33207843aaff;hp=09bdc46e1eb8d3e01d97698d05ee84574f8b8eb4;hpb=448e2dcad4d7c8d719358c8837d2ea653bda01bb;p=openldap
diff --git a/servers/slapd/schema_init.c b/servers/slapd/schema_init.c
index 09bdc46e1e..789c7f001a 100644
--- a/servers/slapd/schema_init.c
+++ b/servers/slapd/schema_init.c
@@ -2,7 +2,7 @@
/* $OpenLDAP$ */
/* This work is part of OpenLDAP Software .
*
- * Copyright 1998-2004 The OpenLDAP Foundation.
+ * Copyright 1998-2005 The OpenLDAP Foundation.
* All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
@@ -17,7 +17,9 @@
#include "portable.h"
#include
+#ifdef HAVE_LIMITS_H
#include
+#endif
#include
#include
@@ -25,8 +27,6 @@
#include
#include "slap.h"
-#include "ldap_pvt.h"
-#include "lber_pvt.h"
#include "ldap_utf8.h"
@@ -42,6 +42,7 @@
#include
#endif
+#include "lutil.h"
#include "lutil_hash.h"
#define HASH_BYTES LUTIL_HASH_BYTES
#define HASH_CONTEXT lutil_HASH_CTX
@@ -49,8 +50,6 @@
#define HASH_Update(c,buf,len) lutil_HASHUpdate(c,buf,len)
#define HASH_Final(d,c) lutil_HASHFinal(d,c)
-#define OpenLDAPaciMatch NULL
-
/* approx matching rules */
#define directoryStringApproxMatchOID "1.3.6.1.4.1.4203.666.4.4"
#define directoryStringApproxMatch approxMatch
@@ -61,6 +60,26 @@
#define IA5StringApproxIndexer approxIndexer
#define IA5StringApproxFilter approxFilter
+/* Change Sequence Number (CSN) - much of this will change */
+#define csnValidate blobValidate
+#define csnMatch octetStringMatch
+#define csnOrderingMatch octetStringOrderingMatch
+#define csnIndexer generalizedTimeIndexer
+#define csnFilter generalizedTimeFilter
+
+#ifdef SLAP_AUTHZ_SYNTAX
+/* FIXME: temporary */
+#define authzMatch octetStringMatch
+#endif /* SLAP_AUTHZ_SYNTAX */
+
+unsigned int index_substr_if_minlen = SLAP_INDEX_SUBSTR_IF_MINLEN_DEFAULT;
+unsigned int index_substr_if_maxlen = SLAP_INDEX_SUBSTR_IF_MAXLEN_DEFAULT;
+unsigned int index_substr_any_len = SLAP_INDEX_SUBSTR_ANY_LEN_DEFAULT;
+unsigned int index_substr_any_step = SLAP_INDEX_SUBSTR_ANY_STEP_DEFAULT;
+
+ldap_pvt_thread_mutex_t ad_undef_mutex;
+ldap_pvt_thread_mutex_t oc_undef_mutex;
+
static int
inValidate(
Syntax *syntax,
@@ -108,7 +127,7 @@ static int certificateValidate( Syntax *syntax, struct berval *in )
#define certificateValidate sequenceValidate
#endif
-static int
+int
octetStringMatch(
int *matchp,
slap_mask_t flags,
@@ -150,6 +169,30 @@ octetStringOrderingMatch(
return LDAP_SUCCESS;
}
+void
+hashDigestify(
+ HASH_CONTEXT *HASHcontext,
+ unsigned char *HASHdigest,
+ struct berval *prefix,
+ char pre,
+ Syntax *syntax,
+ MatchingRule *mr,
+ unsigned char *value,
+ int value_len)
+{
+ HASH_Init(HASHcontext);
+ if(prefix && prefix->bv_len > 0) {
+ HASH_Update(HASHcontext,
+ (unsigned char *)prefix->bv_val, prefix->bv_len);
+ }
+ if(pre) HASH_Update(HASHcontext, (unsigned char*)&pre, sizeof(pre));
+ HASH_Update(HASHcontext, (unsigned char*)syntax->ssyn_oid, syntax->ssyn_oidlen);
+ HASH_Update(HASHcontext, (unsigned char*)mr->smr_oid, mr->smr_oidlen);
+ HASH_Update(HASHcontext, value, value_len);
+ HASH_Final(HASHdigest, HASHcontext);
+ return;
+}
+
/* Index generation function */
int octetStringIndexer(
slap_mask_t use,
@@ -170,7 +213,7 @@ int octetStringIndexer(
digest.bv_val = (char *)HASHdigest;
digest.bv_len = sizeof(HASHdigest);
- for( i=0; values[i].bv_val != NULL; i++ ) {
+ for( i=0; !BER_BVISNULL( &values[i] ); i++ ) {
/* just count them */
}
@@ -182,26 +225,13 @@ int octetStringIndexer(
slen = syntax->ssyn_oidlen;
mlen = mr->smr_oidlen;
- for( i=0; values[i].bv_val != NULL; i++ ) {
- HASH_Init( &HASHcontext );
- if( prefix != NULL && prefix->bv_len > 0 ) {
- HASH_Update( &HASHcontext,
- (unsigned char *)prefix->bv_val,
- prefix->bv_len );
- }
- HASH_Update( &HASHcontext,
- (unsigned char *)syntax->ssyn_oid, slen );
- HASH_Update( &HASHcontext,
- (unsigned char *)mr->smr_oid, mlen );
- HASH_Update( &HASHcontext,
- (unsigned char *)values[i].bv_val, values[i].bv_len );
- HASH_Final( HASHdigest, &HASHcontext );
-
+ for( i=0; !BER_BVISNULL( &values[i] ); i++ ) {
+ hashDigestify( &HASHcontext, HASHdigest, prefix, 0,
+ syntax, mr, (unsigned char *)values[i].bv_val, values[i].bv_len );
ber_dupbv_x( &keys[i], &digest, ctx );
}
- keys[i].bv_val = NULL;
- keys[i].bv_len = 0;
+ BER_BVZERO( &keys[i] );
*keysp = keys;
@@ -233,22 +263,11 @@ int octetStringFilter(
keys = slap_sl_malloc( sizeof( struct berval ) * 2, ctx );
- HASH_Init( &HASHcontext );
- if( prefix != NULL && prefix->bv_len > 0 ) {
- HASH_Update( &HASHcontext,
- (unsigned char *)prefix->bv_val, prefix->bv_len );
- }
- HASH_Update( &HASHcontext,
- (unsigned char *)syntax->ssyn_oid, slen );
- HASH_Update( &HASHcontext,
- (unsigned char *)mr->smr_oid, mlen );
- HASH_Update( &HASHcontext,
- (unsigned char *)value->bv_val, value->bv_len );
- HASH_Final( HASHdigest, &HASHcontext );
+ hashDigestify( &HASHcontext, HASHdigest, prefix, 0,
+ syntax, mr, (unsigned char *)value->bv_val, value->bv_len );
ber_dupbv_x( keys, &digest, ctx );
- keys[1].bv_val = NULL;
- keys[1].bv_len = 0;
+ BER_BVZERO( &keys[1] );
*keysp = keys;
@@ -271,20 +290,20 @@ octetStringSubstringsMatch(
ber_len_t inlen = 0;
/* Add up asserted input length */
- if( sub->sa_initial.bv_val ) {
+ if ( !BER_BVISNULL( &sub->sa_initial ) ) {
inlen += sub->sa_initial.bv_len;
}
- if( sub->sa_any ) {
- for(i=0; sub->sa_any[i].bv_val != NULL; i++) {
+ if ( sub->sa_any ) {
+ for ( i = 0; !BER_BVISNULL( &sub->sa_any[i] ); i++ ) {
inlen += sub->sa_any[i].bv_len;
}
}
- if( sub->sa_final.bv_val ) {
+ if ( !BER_BVISNULL( &sub->sa_final ) ) {
inlen += sub->sa_final.bv_len;
}
- if( sub->sa_initial.bv_val ) {
- if( inlen > left.bv_len ) {
+ if ( !BER_BVISNULL( &sub->sa_initial ) ) {
+ if ( inlen > left.bv_len ) {
match = 1;
goto done;
}
@@ -292,7 +311,7 @@ octetStringSubstringsMatch(
match = memcmp( sub->sa_initial.bv_val, left.bv_val,
sub->sa_initial.bv_len );
- if( match != 0 ) {
+ if ( match != 0 ) {
goto done;
}
@@ -301,8 +320,8 @@ octetStringSubstringsMatch(
inlen -= sub->sa_initial.bv_len;
}
- if( sub->sa_final.bv_val ) {
- if( inlen > left.bv_len ) {
+ if ( !BER_BVISNULL( &sub->sa_final ) ) {
+ if ( inlen > left.bv_len ) {
match = 1;
goto done;
}
@@ -311,7 +330,7 @@ octetStringSubstringsMatch(
&left.bv_val[left.bv_len - sub->sa_final.bv_len],
sub->sa_final.bv_len );
- if( match != 0 ) {
+ if ( match != 0 ) {
goto done;
}
@@ -319,19 +338,19 @@ octetStringSubstringsMatch(
inlen -= sub->sa_final.bv_len;
}
- if( sub->sa_any ) {
- for(i=0; sub->sa_any[i].bv_val; i++) {
+ if ( sub->sa_any ) {
+ for ( i = 0; !BER_BVISNULL( &sub->sa_any[i] ); i++ ) {
ber_len_t idx;
char *p;
retry:
- if( inlen > left.bv_len ) {
+ if ( inlen > left.bv_len ) {
/* not enough length */
match = 1;
goto done;
}
- if( sub->sa_any[i].bv_len == 0 ) {
+ if ( BER_BVISEMPTY( &sub->sa_any[i] ) ) {
continue;
}
@@ -344,7 +363,7 @@ retry:
idx = p - left.bv_val;
- if( idx >= left.bv_len ) {
+ if ( idx >= left.bv_len ) {
/* this shouldn't happen */
return LDAP_OTHER;
}
@@ -352,7 +371,7 @@ retry:
left.bv_val = p;
left.bv_len -= idx;
- if( sub->sa_any[i].bv_len > left.bv_len ) {
+ if ( sub->sa_any[i].bv_len > left.bv_len ) {
/* not enough left */
match = 1;
goto done;
@@ -362,7 +381,7 @@ retry:
sub->sa_any[i].bv_val,
sub->sa_any[i].bv_len );
- if( match != 0 ) {
+ if ( match != 0 ) {
left.bv_val++;
left.bv_len--;
goto retry;
@@ -391,7 +410,7 @@ octetStringSubstringsIndexer(
BerVarray *keysp,
void *ctx )
{
- ber_len_t i, j, nkeys;
+ ber_len_t i, nkeys;
size_t slen, mlen;
BerVarray keys;
@@ -401,31 +420,31 @@ octetStringSubstringsIndexer(
digest.bv_val = (char *)HASHdigest;
digest.bv_len = sizeof(HASHdigest);
- nkeys=0;
+ nkeys = 0;
- for( i=0; values[i].bv_val != NULL; i++ ) {
+ for ( i = 0; !BER_BVISNULL( &values[i] ); i++ ) {
/* count number of indices to generate */
if( flags & SLAP_INDEX_SUBSTR_INITIAL ) {
- if( values[i].bv_len >= SLAP_INDEX_SUBSTR_IF_MAXLEN ) {
- nkeys += SLAP_INDEX_SUBSTR_IF_MAXLEN -
- (SLAP_INDEX_SUBSTR_IF_MINLEN - 1);
- } else if( values[i].bv_len >= SLAP_INDEX_SUBSTR_IF_MINLEN ) {
- nkeys += values[i].bv_len - (SLAP_INDEX_SUBSTR_IF_MINLEN - 1);
+ if( values[i].bv_len >= index_substr_if_maxlen ) {
+ nkeys += index_substr_if_maxlen -
+ (index_substr_if_minlen - 1);
+ } else if( values[i].bv_len >= index_substr_if_minlen ) {
+ nkeys += values[i].bv_len - (index_substr_if_minlen - 1);
}
}
if( flags & SLAP_INDEX_SUBSTR_ANY ) {
- if( values[i].bv_len >= SLAP_INDEX_SUBSTR_ANY_LEN ) {
- nkeys += values[i].bv_len - (SLAP_INDEX_SUBSTR_ANY_LEN - 1);
+ if( values[i].bv_len >= index_substr_any_len ) {
+ nkeys += values[i].bv_len - (index_substr_any_len - 1);
}
}
if( flags & SLAP_INDEX_SUBSTR_FINAL ) {
- if( values[i].bv_len >= SLAP_INDEX_SUBSTR_IF_MAXLEN ) {
- nkeys += SLAP_INDEX_SUBSTR_IF_MAXLEN -
- ( SLAP_INDEX_SUBSTR_IF_MINLEN - 1);
- } else if( values[i].bv_len >= SLAP_INDEX_SUBSTR_IF_MINLEN ) {
- nkeys += values[i].bv_len - (SLAP_INDEX_SUBSTR_IF_MINLEN - 1);
+ if( values[i].bv_len >= index_substr_if_maxlen ) {
+ nkeys += index_substr_if_maxlen -
+ (index_substr_if_minlen - 1);
+ } else if( values[i].bv_len >= index_substr_if_minlen ) {
+ nkeys += values[i].bv_len - (index_substr_if_minlen - 1);
}
}
}
@@ -441,84 +460,43 @@ octetStringSubstringsIndexer(
slen = syntax->ssyn_oidlen;
mlen = mr->smr_oidlen;
- nkeys=0;
- for( i=0; values[i].bv_val != NULL; i++ ) {
+ nkeys = 0;
+ for ( i = 0; !BER_BVISNULL( &values[i] ); i++ ) {
ber_len_t j,max;
if( ( flags & SLAP_INDEX_SUBSTR_ANY ) &&
- ( values[i].bv_len >= SLAP_INDEX_SUBSTR_ANY_LEN ) )
+ ( values[i].bv_len >= index_substr_any_len ) )
{
char pre = SLAP_INDEX_SUBSTR_PREFIX;
- max = values[i].bv_len - (SLAP_INDEX_SUBSTR_ANY_LEN - 1);
+ max = values[i].bv_len - (index_substr_any_len - 1);
for( j=0; jbv_len > 0 ) {
- HASH_Update( &HASHcontext,
- (unsigned char *)prefix->bv_val, prefix->bv_len );
- }
-
- HASH_Update( &HASHcontext,
- (unsigned char *)&pre, sizeof( pre ) );
- HASH_Update( &HASHcontext,
- (unsigned char *)syntax->ssyn_oid, slen );
- HASH_Update( &HASHcontext,
- (unsigned char *)mr->smr_oid, mlen );
- HASH_Update( &HASHcontext,
- (unsigned char *)&values[i].bv_val[j],
- SLAP_INDEX_SUBSTR_ANY_LEN );
- HASH_Final( HASHdigest, &HASHcontext );
-
+ hashDigestify( &HASHcontext, HASHdigest, prefix, pre,
+ syntax, mr, (unsigned char *)&values[i].bv_val[j], index_substr_any_len);
ber_dupbv_x( &keys[nkeys++], &digest, ctx );
}
}
/* skip if too short */
- if( values[i].bv_len < SLAP_INDEX_SUBSTR_IF_MINLEN ) continue;
+ if( values[i].bv_len < index_substr_if_minlen ) continue;
- max = SLAP_INDEX_SUBSTR_IF_MAXLEN < values[i].bv_len
- ? SLAP_INDEX_SUBSTR_IF_MAXLEN : values[i].bv_len;
+ max = index_substr_if_maxlen < values[i].bv_len
+ ? index_substr_if_maxlen : values[i].bv_len;
- for( j=SLAP_INDEX_SUBSTR_IF_MINLEN; j<=max; j++ ) {
+ for( j=index_substr_if_minlen; j<=max; j++ ) {
char pre;
if( flags & SLAP_INDEX_SUBSTR_INITIAL ) {
pre = SLAP_INDEX_SUBSTR_INITIAL_PREFIX;
- HASH_Init( &HASHcontext );
- if( prefix != NULL && prefix->bv_len > 0 ) {
- HASH_Update( &HASHcontext,
- (unsigned char *)prefix->bv_val, prefix->bv_len );
- }
- HASH_Update( &HASHcontext,
- (unsigned char *)&pre, sizeof( pre ) );
- HASH_Update( &HASHcontext,
- (unsigned char *)syntax->ssyn_oid, slen );
- HASH_Update( &HASHcontext,
- (unsigned char *)mr->smr_oid, mlen );
- HASH_Update( &HASHcontext,
- (unsigned char *)values[i].bv_val, j );
- HASH_Final( HASHdigest, &HASHcontext );
-
+ hashDigestify( &HASHcontext, HASHdigest, prefix, pre,
+ syntax, mr, (unsigned char *)values[i].bv_val, j );
ber_dupbv_x( &keys[nkeys++], &digest, ctx );
}
if( flags & SLAP_INDEX_SUBSTR_FINAL ) {
pre = SLAP_INDEX_SUBSTR_FINAL_PREFIX;
- HASH_Init( &HASHcontext );
- if( prefix != NULL && prefix->bv_len > 0 ) {
- HASH_Update( &HASHcontext,
- (unsigned char *)prefix->bv_val, prefix->bv_len );
- }
- HASH_Update( &HASHcontext,
- (unsigned char *)&pre, sizeof( pre ) );
- HASH_Update( &HASHcontext,
- (unsigned char *)syntax->ssyn_oid, slen );
- HASH_Update( &HASHcontext,
- (unsigned char *)mr->smr_oid, mlen );
- HASH_Update( &HASHcontext,
- (unsigned char *)&values[i].bv_val[values[i].bv_len-j], j );
- HASH_Final( HASHdigest, &HASHcontext );
-
+ hashDigestify( &HASHcontext, HASHdigest, prefix, pre,
+ syntax, mr, (unsigned char *)&values[i].bv_val[values[i].bv_len-j], j );
ber_dupbv_x( &keys[nkeys++], &digest, ctx );
}
@@ -526,7 +504,7 @@ octetStringSubstringsIndexer(
}
if( nkeys > 0 ) {
- keys[nkeys].bv_val = NULL;
+ BER_BVZERO( &keys[nkeys] );
*keysp = keys;
} else {
ch_free( keys );
@@ -560,28 +538,38 @@ octetStringSubstringsFilter (
sa = (SubstringsAssertion *) assertedValue;
if( flags & SLAP_INDEX_SUBSTR_INITIAL &&
- sa->sa_initial.bv_val != NULL &&
- sa->sa_initial.bv_len >= SLAP_INDEX_SUBSTR_IF_MINLEN )
+ !BER_BVISNULL( &sa->sa_initial ) &&
+ sa->sa_initial.bv_len >= index_substr_if_minlen )
{
nkeys++;
+ if ( sa->sa_initial.bv_len > index_substr_if_maxlen &&
+ ( flags & SLAP_INDEX_SUBSTR_ANY ))
+ {
+ nkeys += 1 + (sa->sa_initial.bv_len - index_substr_if_maxlen) / index_substr_any_step;
+ }
}
- if( flags & SLAP_INDEX_SUBSTR_ANY && sa->sa_any != NULL ) {
+ if ( flags & SLAP_INDEX_SUBSTR_ANY && sa->sa_any != NULL ) {
ber_len_t i;
- for( i=0; sa->sa_any[i].bv_val != NULL; i++ ) {
- if( sa->sa_any[i].bv_len >= SLAP_INDEX_SUBSTR_ANY_LEN ) {
+ for( i=0; !BER_BVISNULL( &sa->sa_any[i] ); i++ ) {
+ if( sa->sa_any[i].bv_len >= index_substr_any_len ) {
/* don't bother accounting with stepping */
nkeys += sa->sa_any[i].bv_len -
- ( SLAP_INDEX_SUBSTR_ANY_LEN - 1 );
+ ( index_substr_any_len - 1 );
}
}
}
if( flags & SLAP_INDEX_SUBSTR_FINAL &&
- sa->sa_final.bv_val != NULL &&
- sa->sa_final.bv_len >= SLAP_INDEX_SUBSTR_IF_MINLEN )
+ !BER_BVISNULL( &sa->sa_final ) &&
+ sa->sa_final.bv_len >= index_substr_if_minlen )
{
nkeys++;
+ if ( sa->sa_final.bv_len > index_substr_if_maxlen &&
+ ( flags & SLAP_INDEX_SUBSTR_ANY ))
+ {
+ nkeys += 1 + (sa->sa_final.bv_len - index_substr_if_maxlen) / index_substr_any_step;
+ }
}
if( nkeys == 0 ) {
@@ -599,99 +587,90 @@ octetStringSubstringsFilter (
nkeys = 0;
if( flags & SLAP_INDEX_SUBSTR_INITIAL &&
- sa->sa_initial.bv_val != NULL &&
- sa->sa_initial.bv_len >= SLAP_INDEX_SUBSTR_IF_MINLEN )
+ !BER_BVISNULL( &sa->sa_initial ) &&
+ sa->sa_initial.bv_len >= index_substr_if_minlen )
{
pre = SLAP_INDEX_SUBSTR_INITIAL_PREFIX;
value = &sa->sa_initial;
- klen = SLAP_INDEX_SUBSTR_IF_MAXLEN < value->bv_len
- ? SLAP_INDEX_SUBSTR_IF_MAXLEN : value->bv_len;
-
- HASH_Init( &HASHcontext );
- if( prefix != NULL && prefix->bv_len > 0 ) {
- HASH_Update( &HASHcontext,
- (unsigned char *)prefix->bv_val, prefix->bv_len );
- }
- HASH_Update( &HASHcontext,
- (unsigned char *)&pre, sizeof( pre ) );
- HASH_Update( &HASHcontext,
- (unsigned char *)syntax->ssyn_oid, slen );
- HASH_Update( &HASHcontext,
- (unsigned char *)mr->smr_oid, mlen );
- HASH_Update( &HASHcontext,
- (unsigned char *)value->bv_val, klen );
- HASH_Final( HASHdigest, &HASHcontext );
+ klen = index_substr_if_maxlen < value->bv_len
+ ? index_substr_if_maxlen : value->bv_len;
+ hashDigestify( &HASHcontext, HASHdigest, prefix, pre,
+ syntax, mr, (unsigned char *)value->bv_val, klen );
ber_dupbv_x( &keys[nkeys++], &digest, ctx );
+
+ /* If initial is too long and we have subany indexed, use it
+ * to match the excess...
+ */
+ if (value->bv_len > index_substr_if_maxlen && (flags & SLAP_INDEX_SUBSTR_ANY))
+ {
+ ber_len_t j;
+ pre = SLAP_INDEX_SUBSTR_PREFIX;
+ for ( j=index_substr_if_maxlen-1; j <= value->bv_len - index_substr_any_len; j+=index_substr_any_step )
+ {
+ hashDigestify( &HASHcontext, HASHdigest, prefix, pre,
+ syntax, mr, (unsigned char *)&value->bv_val[j], index_substr_any_len );
+ ber_dupbv_x( &keys[nkeys++], &digest, ctx );
+ }
+ }
}
if( flags & SLAP_INDEX_SUBSTR_ANY && sa->sa_any != NULL ) {
ber_len_t i, j;
pre = SLAP_INDEX_SUBSTR_PREFIX;
- klen = SLAP_INDEX_SUBSTR_ANY_LEN;
+ klen = index_substr_any_len;
- for( i=0; sa->sa_any[i].bv_val != NULL; i++ ) {
- if( sa->sa_any[i].bv_len < SLAP_INDEX_SUBSTR_ANY_LEN ) {
+ for( i=0; !BER_BVISNULL( &sa->sa_any[i] ); i++ ) {
+ if( sa->sa_any[i].bv_len < index_substr_any_len ) {
continue;
}
value = &sa->sa_any[i];
for(j=0;
- j <= value->bv_len - SLAP_INDEX_SUBSTR_ANY_LEN;
- j += SLAP_INDEX_SUBSTR_ANY_STEP )
+ j <= value->bv_len - index_substr_any_len;
+ j += index_substr_any_step )
{
- HASH_Init( &HASHcontext );
- if( prefix != NULL && prefix->bv_len > 0 ) {
- HASH_Update( &HASHcontext,
- (unsigned char *)prefix->bv_val, prefix->bv_len );
- }
- HASH_Update( &HASHcontext,
- (unsigned char *)&pre, sizeof( pre ) );
- HASH_Update( &HASHcontext,
- (unsigned char *)syntax->ssyn_oid, slen );
- HASH_Update( &HASHcontext,
- (unsigned char *)mr->smr_oid, mlen );
- HASH_Update( &HASHcontext,
- (unsigned char *)&value->bv_val[j], klen );
- HASH_Final( HASHdigest, &HASHcontext );
-
+ hashDigestify( &HASHcontext, HASHdigest, prefix, pre,
+ syntax, mr, (unsigned char *)&value->bv_val[j], klen );
ber_dupbv_x( &keys[nkeys++], &digest, ctx );
}
}
}
if( flags & SLAP_INDEX_SUBSTR_FINAL &&
- sa->sa_final.bv_val != NULL &&
- sa->sa_final.bv_len >= SLAP_INDEX_SUBSTR_IF_MINLEN )
+ !BER_BVISNULL( &sa->sa_final ) &&
+ sa->sa_final.bv_len >= index_substr_if_minlen )
{
pre = SLAP_INDEX_SUBSTR_FINAL_PREFIX;
value = &sa->sa_final;
- klen = SLAP_INDEX_SUBSTR_IF_MAXLEN < value->bv_len
- ? SLAP_INDEX_SUBSTR_IF_MAXLEN : value->bv_len;
-
- HASH_Init( &HASHcontext );
- if( prefix != NULL && prefix->bv_len > 0 ) {
- HASH_Update( &HASHcontext,
- (unsigned char *)prefix->bv_val, prefix->bv_len );
- }
- HASH_Update( &HASHcontext,
- (unsigned char *)&pre, sizeof( pre ) );
- HASH_Update( &HASHcontext,
- (unsigned char *)syntax->ssyn_oid, slen );
- HASH_Update( &HASHcontext,
- (unsigned char *)mr->smr_oid, mlen );
- HASH_Update( &HASHcontext,
- (unsigned char *)&value->bv_val[value->bv_len-klen], klen );
- HASH_Final( HASHdigest, &HASHcontext );
+ klen = index_substr_if_maxlen < value->bv_len
+ ? index_substr_if_maxlen : value->bv_len;
+ hashDigestify( &HASHcontext, HASHdigest, prefix, pre,
+ syntax, mr, (unsigned char *)&value->bv_val[value->bv_len-klen], klen );
ber_dupbv_x( &keys[nkeys++], &digest, ctx );
+
+ /* If final is too long and we have subany indexed, use it
+ * to match the excess...
+ */
+ if (value->bv_len > index_substr_if_maxlen && (flags & SLAP_INDEX_SUBSTR_ANY))
+ {
+ ber_len_t j;
+ pre = SLAP_INDEX_SUBSTR_PREFIX;
+ for ( j=0; j <= value->bv_len - index_substr_if_maxlen; j+=index_substr_any_step )
+ {
+ hashDigestify( &HASHcontext, HASHdigest, prefix, pre,
+ syntax, mr, (unsigned char *)&value->bv_val[j], index_substr_any_len );
+ ber_dupbv_x( &keys[nkeys++], &digest, ctx );
+ }
+ }
}
if( nkeys > 0 ) {
- keys[nkeys].bv_val = NULL;
+ BER_BVZERO( &keys[nkeys] );
*keysp = keys;
} else {
ch_free( keys );
@@ -723,13 +702,13 @@ bitStringValidate(
*/
if( in->bv_val[0] != '\'' ||
- in->bv_val[in->bv_len-2] != '\'' ||
- in->bv_val[in->bv_len-1] != 'B' )
+ in->bv_val[in->bv_len - 2] != '\'' ||
+ in->bv_val[in->bv_len - 1] != 'B' )
{
return LDAP_INVALID_SYNTAX;
}
- for( i=in->bv_len-3; i>0; i-- ) {
+ for( i = in->bv_len - 3; i > 0; i-- ) {
if( in->bv_val[i] != '0' && in->bv_val[i] != '1' ) {
return LDAP_INVALID_SYNTAX;
}
@@ -886,14 +865,14 @@ nameUIDValidate(
int rc;
struct berval dn, uid;
- if( in->bv_len == 0 ) return LDAP_SUCCESS;
+ if( BER_BVISEMPTY( in ) ) return LDAP_SUCCESS;
ber_dupbv( &dn, in );
if( !dn.bv_val ) return LDAP_OTHER;
/* if there's a "#", try bitStringValidate()... */
uid.bv_val = strrchr( dn.bv_val, '#' );
- if ( uid.bv_val ) {
+ if ( !BER_BVISNULL( &uid ) ) {
uid.bv_val++;
uid.bv_len = dn.bv_len - ( uid.bv_val - dn.bv_val );
@@ -919,17 +898,13 @@ nameUIDPretty(
struct berval *out,
void *ctx )
{
- assert( val );
- assert( out );
+ assert( val != NULL );
+ assert( out != NULL );
-#ifdef NEW_LOGGING
- LDAP_LOG( OPERATION, ARGS, ">>> nameUIDPretty: <%s>\n", val->bv_val, 0, 0 );
-#else
Debug( LDAP_DEBUG_TRACE, ">>> nameUIDPretty: <%s>\n", val->bv_val, 0, 0 );
-#endif
- if( val->bv_len == 0 ) {
+ if( BER_BVISEMPTY( val ) ) {
ber_dupbv_x( out, val, ctx );
} else if ( val->bv_len > SLAP_LDAPDN_MAXLEN ) {
@@ -941,7 +916,7 @@ nameUIDPretty(
struct berval uidval = BER_BVNULL;
uidval.bv_val = strrchr( val->bv_val, '#' );
- if ( uidval.bv_val ) {
+ if ( !BER_BVISNULL( &uidval ) ) {
uidval.bv_val++;
uidval.bv_len = val->bv_len - ( uidval.bv_val - val->bv_val );
@@ -953,7 +928,7 @@ nameUIDPretty(
dnval.bv_val[dnval.bv_len] = '\0';
} else {
- uidval.bv_val = NULL;
+ BER_BVZERO( &uidval );
}
}
@@ -965,7 +940,7 @@ nameUIDPretty(
return rc;
}
- if( uidval.bv_val ) {
+ if( !BER_BVISNULL( &uidval ) ) {
int i, c, got1;
char *tmp;
@@ -1000,11 +975,7 @@ nameUIDPretty(
}
}
-#ifdef NEW_LOGGING
- LDAP_LOG( OPERATION, ARGS, "<<< nameUIDPretty: <%s>\n", out->bv_val, 0, 0 );
-#else
Debug( LDAP_DEBUG_TRACE, "<<< nameUIDPretty: <%s>\n", out->bv_val, 0, 0 );
-#endif
return LDAP_SUCCESS;
}
@@ -1031,7 +1002,7 @@ uniqueMemberNormalize(
struct berval uid = BER_BVNULL;
uid.bv_val = strrchr( out.bv_val, '#' );
- if ( uid.bv_val ) {
+ if ( !BER_BVISNULL( &uid ) ) {
uid.bv_val++;
uid.bv_len = out.bv_len - ( uid.bv_val - out.bv_val );
@@ -1040,7 +1011,7 @@ uniqueMemberNormalize(
uid.bv_val[-1] = '\0';
out.bv_len -= uid.bv_len + 1;
} else {
- uid.bv_val = NULL;
+ BER_BVZERO( &uid );
}
}
@@ -1051,7 +1022,7 @@ uniqueMemberNormalize(
return LDAP_INVALID_SYNTAX;
}
- if( uid.bv_val ) {
+ if( !BER_BVISNULL( &uid ) ) {
char *tmp;
tmp = ch_realloc( normalized->bv_val,
@@ -1095,8 +1066,9 @@ uniqueMemberMatch(
struct berval *asserted = (struct berval *) assertedValue;
struct berval assertedDN = *asserted;
struct berval assertedUID = BER_BVNULL;
- struct berval valueDN = BER_BVNULL;
+ struct berval valueDN = *value;
struct berval valueUID = BER_BVNULL;
+ int approx = ((flags & SLAP_MR_EQUALITY_APPROX) == SLAP_MR_EQUALITY_APPROX);
if ( !BER_BVISEMPTY( asserted ) ) {
assertedUID.bv_val = strrchr( assertedDN.bv_val, '#' );
@@ -1115,7 +1087,6 @@ uniqueMemberMatch(
}
if ( !BER_BVISEMPTY( value ) ) {
- valueDN = *value;
valueUID.bv_val = strrchr( valueDN.bv_val, '#' );
if ( !BER_BVISNULL( &valueUID ) ) {
@@ -1144,11 +1115,109 @@ uniqueMemberMatch(
*matchp = match;
return LDAP_SUCCESS;
}
+
+ } else if ( !approx && valueUID.bv_len ) {
+ match = -1;
+ *matchp = match;
+ return LDAP_SUCCESS;
+
+ } else if ( !approx && assertedUID.bv_len ) {
+ match = 1;
+ *matchp = match;
+ return LDAP_SUCCESS;
}
return dnMatch( matchp, flags, syntax, mr, &valueDN, &assertedDN );
}
+static int
+uniqueMemberIndexer(
+ slap_mask_t use,
+ slap_mask_t flags,
+ Syntax *syntax,
+ MatchingRule *mr,
+ struct berval *prefix,
+ BerVarray values,
+ BerVarray *keysp,
+ void *ctx )
+{
+ BerVarray dnvalues;
+ int rc;
+ int i;
+ for( i=0; !BER_BVISNULL( &values[i] ); i++ ) {
+ /* just count them */
+ }
+ assert( i > 0 );
+
+ dnvalues = slap_sl_malloc( sizeof( struct berval ) * (i+1), ctx );
+
+ for( i=0; !BER_BVISNULL( &values[i] ); i++ ) {
+ struct berval assertedDN = values[i];
+ struct berval assertedUID = BER_BVNULL;
+
+ if ( !BER_BVISEMPTY( &assertedDN ) ) {
+ assertedUID.bv_val = strrchr( assertedDN.bv_val, '#' );
+ if ( !BER_BVISNULL( &assertedUID ) ) {
+ assertedUID.bv_val++;
+ assertedUID.bv_len = assertedDN.bv_len
+ - ( assertedUID.bv_val - assertedDN.bv_val );
+
+ if ( bitStringValidate( NULL, &assertedUID ) == LDAP_SUCCESS ) {
+ assertedDN.bv_len -= assertedUID.bv_len + 1;
+
+ } else {
+ BER_BVZERO( &assertedUID );
+ }
+ }
+ }
+
+ dnvalues[i] = assertedDN;
+ }
+ BER_BVZERO( &dnvalues[i] );
+
+ rc = octetStringIndexer( use, flags, syntax, mr, prefix,
+ dnvalues, keysp, ctx );
+
+ slap_sl_free( dnvalues, ctx );
+ return rc;
+}
+
+static int
+uniqueMemberFilter(
+ slap_mask_t use,
+ slap_mask_t flags,
+ Syntax *syntax,
+ MatchingRule *mr,
+ struct berval *prefix,
+ void * assertedValue,
+ BerVarray *keysp,
+ void *ctx )
+{
+ struct berval *asserted = (struct berval *) assertedValue;
+ struct berval assertedDN = *asserted;
+ struct berval assertedUID = BER_BVNULL;
+
+ if ( !BER_BVISEMPTY( asserted ) ) {
+ assertedUID.bv_val = strrchr( assertedDN.bv_val, '#' );
+ if ( !BER_BVISNULL( &assertedUID ) ) {
+ assertedUID.bv_val++;
+ assertedUID.bv_len = assertedDN.bv_len
+ - ( assertedUID.bv_val - assertedDN.bv_val );
+
+ if ( bitStringValidate( NULL, &assertedUID ) == LDAP_SUCCESS ) {
+ assertedDN.bv_len -= assertedUID.bv_len + 1;
+
+ } else {
+ BER_BVZERO( &assertedUID );
+ }
+ }
+ }
+
+ return octetStringFilter( use, flags, syntax, mr, prefix,
+ &assertedDN, keysp, ctx );
+}
+
+
/*
* Handling boolean syntax and matching is quite rigid.
* A more flexible approach would be to allow a variety
@@ -1273,12 +1342,12 @@ UTF8StringValidate(
int len;
unsigned char *u = (unsigned char *)in->bv_val;
- if( in->bv_len == 0 && syntax == slap_schema.si_syn_directoryString ) {
+ if( BER_BVISEMPTY( in ) && syntax == slap_schema.si_syn_directoryString ) {
/* directory strings cannot be empty */
return LDAP_INVALID_SYNTAX;
}
- for( count = in->bv_len; count > 0; count-=len, u+=len ) {
+ for( count = in->bv_len; count > 0; count -= len, u += len ) {
/* get the length indicated by the first byte */
len = LDAP_UTF8_CHARLEN2( u, len );
@@ -1338,12 +1407,11 @@ UTF8StringNormalize(
assert( SLAP_MR_IS_VALUE_OF_SYNTAX( use ));
- if( val->bv_val == NULL ) {
+ if( BER_BVISNULL( val ) ) {
/* assume we're dealing with a syntax (e.g., UTF8String)
* which allows empty strings
*/
- normalized->bv_len = 0;
- normalized->bv_val = NULL;
+ BER_BVZERO( normalized );
return LDAP_SUCCESS;
}
@@ -1361,8 +1429,11 @@ UTF8StringNormalize(
nvalue.bv_len = 0;
nvalue.bv_val = tmp.bv_val;
- wasspace=1; /* trim leading spaces */
- for( i=0; isa_initial ) ) {
+ if ( sub->sa_initial.bv_len > left.bv_len ) {
+ /* not enough left */
+ match = 1;
+ goto done;
+ }
+
+ match = memcmp( sub->sa_initial.bv_val, left.bv_val,
+ sub->sa_initial.bv_len );
+
+ if ( match != 0 ) {
+ goto done;
+ }
+
+ left.bv_val += sub->sa_initial.bv_len;
+ left.bv_len -= sub->sa_initial.bv_len;
+
+ priorspace = ASCII_SPACE(
+ sub->sa_initial.bv_val[sub->sa_initial.bv_len] );
+ }
+
+ if ( sub->sa_any ) {
+ for ( i = 0; !BER_BVISNULL( &sub->sa_any[i] ); i++ ) {
+ ber_len_t idx;
+ char *p;
+
+ if( priorspace && !BER_BVISEMPTY( &sub->sa_any[i] )
+ && ASCII_SPACE( sub->sa_any[i].bv_val[0] ))
+ {
+ /* allow next space to match */
+ left.bv_val--;
+ left.bv_len++;
+ }
+ priorspace=0;
+
+retry:
+ if ( BER_BVISEMPTY( &sub->sa_any[i] ) ) {
+ continue;
+ }
+
+ if ( sub->sa_any[i].bv_len > left.bv_len ) {
+ /* not enough left */
+ match = 1;
+ goto done;
+ }
+
+ p = memchr( left.bv_val, *sub->sa_any[i].bv_val, left.bv_len );
+
+ if( p == NULL ) {
+ match = 1;
+ goto done;
+ }
+
+ idx = p - left.bv_val;
+
+ if ( idx >= left.bv_len ) {
+ /* this shouldn't happen */
+ return LDAP_OTHER;
+ }
+
+ left.bv_val = p;
+ left.bv_len -= idx;
+
+ if ( sub->sa_any[i].bv_len > left.bv_len ) {
+ /* not enough left */
+ match = 1;
+ goto done;
+ }
+
+ match = memcmp( left.bv_val,
+ sub->sa_any[i].bv_val,
+ sub->sa_any[i].bv_len );
+
+ if ( match != 0 ) {
+ left.bv_val++;
+ left.bv_len--;
+ goto retry;
+ }
+
+ left.bv_val += sub->sa_any[i].bv_len;
+ left.bv_len -= sub->sa_any[i].bv_len;
+
+ priorspace = ASCII_SPACE(
+ sub->sa_any[i].bv_val[sub->sa_any[i].bv_len] );
+ }
+ }
+
+ if ( !BER_BVISNULL( &sub->sa_final ) ) {
+ if( priorspace && !BER_BVISEMPTY( &sub->sa_final )
+ && ASCII_SPACE( sub->sa_final.bv_val[0] ))
+ {
+ /* allow next space to match */
+ left.bv_val--;
+ left.bv_len++;
+ }
+
+ if ( sub->sa_final.bv_len > left.bv_len ) {
+ /* not enough left */
+ match = 1;
+ goto done;
+ }
+
+ match = memcmp( sub->sa_final.bv_val,
+ &left.bv_val[left.bv_len - sub->sa_final.bv_len],
+ sub->sa_final.bv_len );
+
+ if ( match != 0 ) {
+ goto done;
+ }
+ }
+
+done:
+ *matchp = match;
+ return LDAP_SUCCESS;
+}
+
#if defined(SLAPD_APPROX_INITIALS)
# define SLAPD_APPROX_DELIMITER "._ "
# define SLAPD_APPROX_WORDLEN 2
@@ -1525,11 +1730,11 @@ approxIndexer(
struct berval *newkeys;
BerVarray keys=NULL;
- for( j=0; values[j].bv_val != NULL; j++ ) {
+ for( j = 0; !BER_BVISNULL( &values[j] ); j++ ) {
struct berval val = BER_BVNULL;
/* Yes, this is necessary */
UTF8bvnormalize( &values[j], &val, LDAP_UTF8_APPROX, NULL );
- assert( val.bv_val != NULL );
+ assert( !BER_BVISNULL( &val ) );
/* Isolate how many words there are. There will be a key for each */
for( wordcount = 0, c = val.bv_val; *c; c++) {
@@ -1558,7 +1763,7 @@ approxIndexer(
ber_memfree( val.bv_val );
}
- keys[keycount].bv_val = NULL;
+ BER_BVZERO( &keys[keycount] );
*keysp = keys;
return LDAP_SUCCESS;
@@ -1583,9 +1788,9 @@ approxFilter(
/* Yes, this is necessary */
val = UTF8bvnormalize( ((struct berval *)assertedValue),
NULL, LDAP_UTF8_APPROX, NULL );
- if( val == NULL || val->bv_val == NULL ) {
+ if( val == NULL || BER_BVISNULL( val ) ) {
keys = (struct berval *)ch_malloc( sizeof(struct berval) );
- keys[0].bv_val = NULL;
+ BER_BVZERO( &keys[0] );
*keysp = keys;
ber_bvfree( val );
return LDAP_SUCCESS;
@@ -1613,7 +1818,7 @@ approxFilter(
ber_bvfree( val );
- keys[count].bv_val = NULL;
+ BER_BVZERO( &keys[count] );
*keysp = keys;
return LDAP_SUCCESS;
@@ -1634,7 +1839,7 @@ telephoneNumberNormalize(
assert( SLAP_MR_IS_VALUE_OF_SYNTAX( usage ));
/* validator should have refused an empty string */
- assert( val->bv_len );
+ assert( !BER_BVISEMPTY( val ) );
q = normalized->bv_val = slap_sl_malloc( val->bv_len + 1, ctx );
@@ -1647,23 +1852,23 @@ telephoneNumberNormalize(
normalized->bv_len = q - normalized->bv_val;
- if( normalized->bv_len == 0 ) {
+ if( BER_BVISEMPTY( normalized ) ) {
slap_sl_free( normalized->bv_val, ctx );
- normalized->bv_val = NULL;
+ BER_BVZERO( normalized );
return LDAP_INVALID_SYNTAX;
}
return LDAP_SUCCESS;
}
-static int
+int
numericoidValidate(
Syntax *syntax,
struct berval *in )
{
struct berval val = *in;
- if( val.bv_len == 0 ) {
+ if( BER_BVISEMPTY( &val ) ) {
/* disallow empty strings */
return LDAP_INVALID_SYNTAX;
}
@@ -1673,7 +1878,7 @@ numericoidValidate(
return LDAP_SUCCESS;
}
- if ( val.bv_val[0] == '0' ) {
+ if ( val.bv_val[0] == '0' && !OID_SEPARATOR( val.bv_val[1] )) {
break;
}
@@ -1708,13 +1913,13 @@ integerValidate(
ber_len_t i;
struct berval val = *in;
- if( val.bv_len == 0 ) return LDAP_INVALID_SYNTAX;
+ if ( BER_BVISEMPTY( &val ) ) return LDAP_INVALID_SYNTAX;
if ( val.bv_val[0] == '-' ) {
val.bv_len--;
val.bv_val++;
- if( val.bv_len == 0 ) { /* bare "-" */
+ if( BER_BVISEMPTY( &val ) ) { /* bare "-" */
return LDAP_INVALID_SYNTAX;
}
@@ -1760,7 +1965,7 @@ integerMatch(
v.bv_len--;
}
- if( v.bv_len == 0 ) vsign = 0;
+ if( BER_BVISEMPTY( &v ) ) vsign = 0;
a = *asserted;
if( a.bv_val[0] == '-' ) {
@@ -1769,7 +1974,7 @@ integerMatch(
a.bv_len--;
}
- if( a.bv_len == 0 ) vsign = 0;
+ if( BER_BVISEMPTY( &a ) ) vsign = 0;
match = vsign - asign;
if( match == 0 ) {
@@ -1807,7 +2012,7 @@ printableStringValidate(
{
ber_len_t i;
- if( val->bv_len == 0 ) return LDAP_INVALID_SYNTAX;
+ if( BER_BVISEMPTY( val ) ) return LDAP_INVALID_SYNTAX;
for(i=0; i < val->bv_len; i++) {
if( !SLAP_PRINTABLE(val->bv_val[i]) ) {
@@ -1825,7 +2030,7 @@ printablesStringValidate(
{
ber_len_t i, len;
- if( val->bv_len == 0 ) return LDAP_INVALID_SYNTAX;
+ if( BER_BVISEMPTY( val ) ) return LDAP_INVALID_SYNTAX;
for(i=0,len=0; i < val->bv_len; i++) {
int c = val->bv_val[i];
@@ -1857,7 +2062,7 @@ IA5StringValidate(
{
ber_len_t i;
- if( val->bv_len == 0 ) return LDAP_INVALID_SYNTAX;
+ if( BER_BVISEMPTY( val ) ) return LDAP_INVALID_SYNTAX;
for(i=0; i < val->bv_len; i++) {
if( !LDAP_ASCII(val->bv_val[i]) ) {
@@ -1880,7 +2085,7 @@ IA5StringNormalize(
char *p, *q;
int casefold = !SLAP_MR_ASSOCIATED(mr, slap_schema.si_mr_caseExactIA5Match);
- assert( val->bv_len );
+ assert( !BER_BVISEMPTY( val ) );
assert( SLAP_MR_IS_VALUE_OF_SYNTAX( use ));
@@ -1924,7 +2129,7 @@ IA5StringNormalize(
*q = '\0';
normalized->bv_len = q - normalized->bv_val;
- if( normalized->bv_len == 0 ) {
+ if( BER_BVISEMPTY( normalized ) ) {
normalized->bv_val = slap_sl_realloc( normalized->bv_val, 2, ctx );
normalized->bv_val[0] = ' ';
normalized->bv_val[1] = '\0';
@@ -1941,7 +2146,6 @@ UUIDValidate(
{
int i;
if( in->bv_len != 36 ) {
- assert(0);
return LDAP_INVALID_SYNTAX;
}
@@ -1978,7 +2182,7 @@ UUIDNormalize(
int i;
int j;
normalized->bv_len = 16;
- normalized->bv_val = slap_sl_malloc( normalized->bv_len+1, ctx );
+ normalized->bv_val = slap_sl_malloc( normalized->bv_len + 1, ctx );
for( i=0, j=0; i<36; i++ ) {
unsigned char nibble;
@@ -2021,7 +2225,7 @@ numericStringValidate(
{
ber_len_t i;
- if( in->bv_len == 0 ) return LDAP_INVALID_SYNTAX;
+ if( BER_BVISEMPTY( in ) ) return LDAP_INVALID_SYNTAX;
for(i=0; i < in->bv_len; i++) {
if( !SLAP_NUMERIC(in->bv_val[i]) ) {
@@ -2044,7 +2248,7 @@ numericStringNormalize(
/* removal all spaces */
char *p, *q;
- assert( val->bv_len );
+ assert( !BER_BVISEMPTY( val ) );
normalized->bv_val = slap_sl_malloc( val->bv_len + 1, ctx );
@@ -2068,7 +2272,7 @@ numericStringNormalize(
normalized->bv_len = q - normalized->bv_val;
- if( normalized->bv_len == 0 ) {
+ if( BER_BVISEMPTY( normalized ) ) {
normalized->bv_val = slap_sl_realloc( normalized->bv_val, 2, ctx );
normalized->bv_val[0] = ' ';
normalized->bv_val[1] = '\0';
@@ -2122,7 +2326,7 @@ integerBitAndMatch(
return LDAP_CONSTRAINT_VIOLATION;
}
- *matchp = (lValue & lAssertedValue) ? 0 : 1;
+ *matchp = ((lValue & lAssertedValue) == lAssertedValue) ? 0 : 1;
return LDAP_SUCCESS;
}
@@ -2153,7 +2357,7 @@ integerBitOrMatch(
return LDAP_CONSTRAINT_VIOLATION;
}
- *matchp = (lValue | lAssertedValue) ? 0 : -1;
+ *matchp = ((lValue & lAssertedValue) != 0) ? 0 : -1;
return LDAP_SUCCESS;
}
@@ -2163,13 +2367,12 @@ serialNumberAndIssuerValidate(
struct berval *in )
{
int rc;
- int state;
ber_len_t n;
struct berval sn, i;
if( in->bv_len < 3 ) return LDAP_INVALID_SYNTAX;
i.bv_val = strchr( in->bv_val, '$' );
- if( i.bv_val == NULL ) return LDAP_INVALID_SYNTAX;
+ if( BER_BVISNULL( &i ) ) return LDAP_INVALID_SYNTAX;
sn.bv_val = in->bv_val;
sn.bv_len = i.bv_val - in->bv_val;
@@ -2197,25 +2400,19 @@ serialNumberAndIssuerPretty(
void *ctx )
{
int rc;
- int state;
ber_len_t n;
struct berval sn, i, newi;
- assert( val );
- assert( out );
+ assert( val != NULL );
+ assert( out != NULL );
-#ifdef NEW_LOGGING
- LDAP_LOG( OPERATION, ARGS, ">>> serialNumberAndIssuerPretty: <%s>\n",
- val->bv_val, 0, 0 );
-#else
Debug( LDAP_DEBUG_TRACE, ">>> serialNumberAndIssuerPretty: <%s>\n",
val->bv_val, 0, 0 );
-#endif
if( val->bv_len < 3 ) return LDAP_INVALID_SYNTAX;
i.bv_val = strchr( val->bv_val, '$' );
- if( i.bv_val == NULL ) return LDAP_INVALID_SYNTAX;
+ if( BER_BVISNULL( &i ) ) return LDAP_INVALID_SYNTAX;
sn.bv_val = val->bv_val;
sn.bv_len = i.bv_val - val->bv_val;
@@ -2243,25 +2440,21 @@ serialNumberAndIssuerPretty(
out->bv_val = slap_sl_realloc( newi.bv_val, out->bv_len + 1, ctx );
if( out->bv_val == NULL ) {
+ out->bv_len = 0;
slap_sl_free( newi.bv_val, ctx );
return LDAP_OTHER;
}
/* push issuer over */
- AC_MEMCPY( &out->bv_val[sn.bv_len+1], newi.bv_val, newi.bv_len );
+ AC_MEMCPY( &out->bv_val[sn.bv_len+1], out->bv_val, newi.bv_len );
/* insert sn and "$" */
AC_MEMCPY( out->bv_val, sn.bv_val, sn.bv_len );
out->bv_val[sn.bv_len] = '$';
/* terminate */
out->bv_val[out->bv_len] = '\0';
-#ifdef NEW_LOGGING
- LDAP_LOG( OPERATION, ARGS, "<<< serialNumberAndIssuerPretty: <%s>\n",
- out->bv_val, 0, 0 );
-#else
Debug( LDAP_DEBUG_TRACE, "<<< serialNumberAndIssuerPretty: <%s>\n",
out->bv_val, 0, 0 );
-#endif
return LDAP_SUCCESS;
}
@@ -2282,25 +2475,19 @@ serialNumberAndIssuerNormalize(
void *ctx )
{
int rc;
- int state;
ber_len_t n;
struct berval sn, i, newi;
- assert( val );
- assert( out );
+ assert( val != NULL );
+ assert( out != NULL );
-#ifdef NEW_LOGGING
- LDAP_LOG( OPERATION, ARGS, ">>> serialNumberAndIssuerNormalize: <%s>\n",
- val->bv_val, 0, 0 );
-#else
Debug( LDAP_DEBUG_TRACE, ">>> serialNumberAndIssuerNormalize: <%s>\n",
val->bv_val, 0, 0 );
-#endif
if( val->bv_len < 3 ) return LDAP_INVALID_SYNTAX;
i.bv_val = strchr( val->bv_val, '$' );
- if( i.bv_val == NULL ) return LDAP_INVALID_SYNTAX;
+ if( BER_BVISNULL( &i ) ) return LDAP_INVALID_SYNTAX;
sn.bv_val = val->bv_val;
sn.bv_len = i.bv_val - val->bv_val;
@@ -2330,25 +2517,21 @@ serialNumberAndIssuerNormalize(
out->bv_val = slap_sl_realloc( newi.bv_val, out->bv_len + 1, ctx );
if( out->bv_val == NULL ) {
+ out->bv_len = 0;
slap_sl_free( newi.bv_val, ctx );
return LDAP_OTHER;
}
/* push issuer over */
- AC_MEMCPY( &out->bv_val[sn.bv_len+1], newi.bv_val, newi.bv_len );
+ AC_MEMCPY( &out->bv_val[sn.bv_len+1], out->bv_val, newi.bv_len );
/* insert sn and "$" */
AC_MEMCPY( out->bv_val, sn.bv_val, sn.bv_len );
out->bv_val[sn.bv_len] = '$';
/* terminate */
out->bv_val[out->bv_len] = '\0';
-#ifdef NEW_LOGGING
- LDAP_LOG( OPERATION, ARGS, "<<< serialNumberAndIssuerNormalize: <%s>\n",
- out->bv_val, 0, 0 );
-#else
Debug( LDAP_DEBUG_TRACE, "<<< serialNumberAndIssuerNormalize: <%s>\n",
out->bv_val, 0, 0 );
-#endif
return rc;
}
@@ -2372,7 +2555,7 @@ certificateExactNormalize(
ASN1_INTEGER *sn = NULL;
X509 *xcert = NULL;
- if( val->bv_len == 0 ) goto done;
+ if( BER_BVISEMPTY( val ) ) goto done;
if( SLAP_MR_IS_VALUE_OF_ASSERTION_SYNTAX(usage) ) {
return serialNumberAndIssuerNormalize(0,NULL,NULL,val,normalized,ctx);
@@ -2405,13 +2588,8 @@ certificateExactNormalize(
p += issuer_dn.bv_len;
*p = '\0';
-#ifdef NEW_LOGGING
- LDAP_LOG( CONFIG, ARGS, "certificateExactNormalize: %s\n",
- normalized->bv_val, 0, 0 );
-#else
Debug( LDAP_DEBUG_TRACE, "certificateExactNormalize: %s\n",
normalized->bv_val, NULL, NULL );
-#endif
done:
if (xcert) X509_free(xcert);
@@ -2490,8 +2668,7 @@ check_time_syntax (struct berval *val,
}
/* leapyear check for the Gregorian calendar (year>1581) */
- if (parts[parts[1] == 0 ? 0 : 1] % 4 == 0)
- {
+ if (parts[parts[1] == 0 ? 0 : 1] % 4 == 0) {
leapyear = 1;
}
@@ -2504,16 +2681,17 @@ check_time_syntax (struct berval *val,
fraction->bv_len = 0;
if (p < e && (*p == '.' || *p == ',')) {
char *end_num;
- while (++p < e && ASCII_DIGIT(*p))
- ;
+ while (++p < e && ASCII_DIGIT(*p)) {
+ /* EMTPY */;
+ }
if (p - fraction->bv_val == 1) {
return LDAP_INVALID_SYNTAX;
}
- for (end_num = p; end_num[-1] == '0'; --end_num)
- ;
+ for (end_num = p; end_num[-1] == '0'; --end_num) {
+ /* EMPTY */;
+ }
c = end_num - fraction->bv_val;
- if (c != 1)
- fraction->bv_len = c;
+ if (c != 1) fraction->bv_len = c;
}
}
@@ -2674,14 +2852,14 @@ generalizedTimeNormalize(
len = sizeof("YYYYmmddHHMMSSZ")-1 + fraction.bv_len;
normalized->bv_val = slap_sl_malloc( len + 1, ctx );
- if ( normalized->bv_val == NULL ) {
+ if ( BER_BVISNULL( normalized ) ) {
return LBER_ERROR_MEMORY;
}
sprintf( normalized->bv_val, "%02d%02d%02d%02d%02d%02d%02d",
parts[0], parts[1], parts[2] + 1, parts[3] + 1,
parts[4], parts[5], parts[6] );
- if ( fraction.bv_len ) {
+ if ( !BER_BVISEMPTY( &fraction ) ) {
memcpy( normalized->bv_val + sizeof("YYYYmmddHHMMSSZ")-2,
fraction.bv_val, fraction.bv_len );
normalized->bv_val[sizeof("YYYYmmddHHMMSSZ")-2] = '.';
@@ -2714,6 +2892,110 @@ generalizedTimeOrderingMatch(
return LDAP_SUCCESS;
}
+/* Index generation function */
+int generalizedTimeIndexer(
+ slap_mask_t use,
+ slap_mask_t flags,
+ Syntax *syntax,
+ MatchingRule *mr,
+ struct berval *prefix,
+ BerVarray values,
+ BerVarray *keysp,
+ void *ctx )
+{
+ int i, j;
+ BerVarray keys;
+ char tmp[5];
+ BerValue bvtmp; /* 40 bit index */
+ struct lutil_tm tm;
+ struct lutil_timet tt;
+
+ bvtmp.bv_len = sizeof(tmp);
+ bvtmp.bv_val = tmp;
+ for( i=0; values[i].bv_val != NULL; i++ ) {
+ /* just count them */
+ }
+
+ /* we should have at least one value at this point */
+ assert( i > 0 );
+
+ keys = slap_sl_malloc( sizeof( struct berval ) * (i+1), ctx );
+
+ /* GeneralizedTime YYYYmmddHH[MM[SS]][(./,)d...](Z|(+/-)HH[MM]) */
+ for( i=0, j=0; values[i].bv_val != NULL; i++ ) {
+ assert(values[i].bv_val != NULL && values[i].bv_len >= 10);
+ /* Use 40 bits of time for key */
+ if ( lutil_parsetime( values[i].bv_val, &tm ) == 0 ) {
+ lutil_tm2time( &tm, &tt );
+ tmp[0] = tt.tt_gsec & 0xff;
+ tmp[4] = tt.tt_sec & 0xff;
+ tt.tt_sec >>= 8;
+ tmp[3] = tt.tt_sec & 0xff;
+ tt.tt_sec >>= 8;
+ tmp[2] = tt.tt_sec & 0xff;
+ tt.tt_sec >>= 8;
+ tmp[1] = tt.tt_sec & 0xff;
+
+ ber_dupbv_x(&keys[j++], &bvtmp, ctx );
+ }
+ }
+
+ keys[j].bv_val = NULL;
+ keys[j].bv_len = 0;
+
+ *keysp = keys;
+
+ return LDAP_SUCCESS;
+}
+
+/* Index generation function */
+int generalizedTimeFilter(
+ slap_mask_t use,
+ slap_mask_t flags,
+ Syntax *syntax,
+ MatchingRule *mr,
+ struct berval *prefix,
+ void * assertedValue,
+ BerVarray *keysp,
+ void *ctx )
+{
+ BerVarray keys;
+ char tmp[5];
+ BerValue bvtmp; /* 40 bit index */
+ BerValue *value = (BerValue *) assertedValue;
+ struct lutil_tm tm;
+ struct lutil_timet tt;
+
+ bvtmp.bv_len = sizeof(tmp);
+ bvtmp.bv_val = tmp;
+ /* GeneralizedTime YYYYmmddHH[MM[SS]][(./,)d...](Z|(+/-)HH[MM]) */
+ /* Use 40 bits of time for key */
+ if ( value->bv_val && value->bv_len >= 10 &&
+ lutil_parsetime( value->bv_val, &tm ) == 0 ) {
+
+ lutil_tm2time( &tm, &tt );
+ tmp[0] = tt.tt_gsec & 0xff;
+ tmp[4] = tt.tt_sec & 0xff;
+ tt.tt_sec >>= 8;
+ tmp[3] = tt.tt_sec & 0xff;
+ tt.tt_sec >>= 8;
+ tmp[2] = tt.tt_sec & 0xff;
+ tt.tt_sec >>= 8;
+ tmp[1] = tt.tt_sec & 0xff;
+
+ keys = slap_sl_malloc( sizeof( struct berval ) * 2, ctx );
+ ber_dupbv_x(keys, &bvtmp, ctx );
+ keys[1].bv_val = NULL;
+ keys[1].bv_len = 0;
+ } else {
+ keys = NULL;
+ }
+
+ *keysp = keys;
+
+ return LDAP_SUCCESS;
+}
+
static int
deliveryMethodValidate(
Syntax *syntax,
@@ -2827,19 +3109,19 @@ again:
return LDAP_INVALID_SYNTAX;
}
- if( tmp.bv_len == 0 ) return LDAP_SUCCESS;
+ if( BER_BVISEMPTY( &tmp ) ) return LDAP_SUCCESS;
- while( tmp.bv_len && ( tmp.bv_val[0] == ' ' )) {
+ while( !BER_BVISEMPTY( &tmp ) && ( tmp.bv_val[0] == ' ' ) ) {
tmp.bv_len++;
tmp.bv_val--;
}
- if( tmp.bv_len && ( tmp.bv_val[0] == '$' )) {
+ if( !BER_BVISEMPTY( &tmp ) && ( tmp.bv_val[0] == '$' ) ) {
tmp.bv_len++;
tmp.bv_val--;
} else {
return LDAP_INVALID_SYNTAX;
}
- while( tmp.bv_len && ( tmp.bv_val[0] == ' ' )) {
+ while( !BER_BVISEMPTY( &tmp ) && ( tmp.bv_val[0] == ' ' ) ) {
tmp.bv_len++;
tmp.bv_val--;
}
@@ -2855,7 +3137,7 @@ nisNetgroupTripleValidate(
char *p, *e;
int commas = 0;
- if ( val->bv_len == 0 ) {
+ if ( BER_BVISEMPTY( val ) ) {
return LDAP_INVALID_SYNTAX;
}
@@ -2898,7 +3180,7 @@ bootParameterValidate(
{
char *p, *e;
- if ( val->bv_len == 0 ) {
+ if ( BER_BVISEMPTY( val ) ) {
return LDAP_INVALID_SYNTAX;
}
@@ -2974,7 +3256,7 @@ firstComponentNormalize(
/* grab next word */
comp.bv_val = &val->bv_val[len];
len = val->bv_len - len;
- for( comp.bv_len=0;
+ for( comp.bv_len = 0;
!ASCII_SPACE(comp.bv_val[comp.bv_len]) && comp.bv_len < len;
comp.bv_len++ )
{
@@ -3032,10 +3314,14 @@ static slap_syntax_defs_rec syntax_defs[] = {
0, countryStringValidate, NULL},
{"( 1.3.6.1.4.1.1466.115.121.1.12 DESC 'Distinguished Name' )",
0, dnValidate, dnPretty},
-
{"( 1.2.36.79672281.1.5.0 DESC 'RDN' )",
0, rdnValidate, rdnPretty},
-
+#ifdef LDAP_COMP_MATCH
+ {"( 1.2.36.79672281.1.5.3 DESC 'allComponents' )",
+ 0, allComponentsValidate, NULL},
+ {"( 1.2.36.79672281.1.5.2 DESC 'componentFilterMatch assertion') ",
+ 0, componentFilterValidate, NULL},
+#endif
{"( 1.3.6.1.4.1.1466.115.121.1.13 DESC 'Data Quality' )",
0, NULL, NULL},
{"( 1.3.6.1.4.1.1466.115.121.1.14 DESC 'Delivery Method' )",
@@ -3137,14 +3423,6 @@ static slap_syntax_defs_rec syntax_defs[] = {
serialNumberAndIssuerValidate,
serialNumberAndIssuerPretty},
-#ifdef SLAPD_ACI_ENABLED
- /* OpenLDAP Experimental Syntaxes */
- {"( 1.3.6.1.4.1.4203.666.2.1 DESC 'OpenLDAP Experimental ACI' )",
- SLAP_SYNTAX_HIDE,
- UTF8StringValidate /* THIS WILL CHANGE FOR NEW ACI SYNTAX */,
- NULL},
-#endif
-
#ifdef SLAPD_AUTHPASSWD
/* needs updating */
{"( 1.3.6.1.4.1.4203.666.2.2 DESC 'OpenLDAP authPassword' )",
@@ -3154,9 +3432,19 @@ static slap_syntax_defs_rec syntax_defs[] = {
{"( 1.3.6.1.4.1.4203.666.2.6 DESC 'UUID' )",
SLAP_SYNTAX_HIDE, UUIDValidate, NULL},
+ {"( 1.3.6.1.4.1.4203.666.11.2.1 DESC 'CSN' )",
+ SLAP_SYNTAX_HIDE, csnValidate, NULL},
+
/* OpenLDAP Void Syntax */
{"( 1.3.6.1.4.1.4203.1.1.1 DESC 'OpenLDAP void' )" ,
SLAP_SYNTAX_HIDE, inValidate, NULL},
+
+#ifdef SLAP_AUTHZ_SYNTAX
+ /* FIXME: OID is unused, but not registered yet */
+ {"( 1.3.6.1.4.1.4203.666.2.7 DESC 'OpenLDAP authz' )",
+ SLAP_SYNTAX_HIDE, authzValidate, authzPretty},
+#endif /* SLAP_AUTHZ_SYNTAX */
+
{NULL, 0, NULL, NULL}
};
@@ -3164,6 +3452,12 @@ char *certificateExactMatchSyntaxes[] = {
"1.3.6.1.4.1.1466.115.121.1.8" /* certificate */,
NULL
};
+#ifdef LDAP_COMP_MATCH
+char *componentFilterMatchSyntaxes[] = {
+ "1.3.6.1.4.1.1466.115.121.1.8" /* certificate */,
+ NULL
+};
+#endif
char *directoryStringSyntaxes[] = {
"1.3.6.1.4.1.1466.115.121.1.44" /* printableString */,
NULL
@@ -3241,6 +3535,35 @@ static slap_mrule_defs_rec mrule_defs[] = {
NULL, dnNormalize, dnMatch,
octetStringIndexer, octetStringFilter,
NULL },
+
+ {"( 1.3.6.1.4.1.4203.666.4.9 NAME 'dnSubtreeMatch' "
+ "SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )",
+ SLAP_MR_HIDE | SLAP_MR_EXT, NULL,
+ NULL, dnNormalize, dnRelativeMatch,
+ NULL, NULL,
+ NULL },
+
+ {"( 1.3.6.1.4.1.4203.666.4.8 NAME 'dnOneLevelMatch' "
+ "SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )",
+ SLAP_MR_HIDE | SLAP_MR_EXT, NULL,
+ NULL, dnNormalize, dnRelativeMatch,
+ NULL, NULL,
+ NULL },
+
+ {"( 1.3.6.1.4.1.4203.666.4.10 NAME 'dnSubordinateMatch' "
+ "SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )",
+ SLAP_MR_HIDE | SLAP_MR_EXT, NULL,
+ NULL, dnNormalize, dnRelativeMatch,
+ NULL, NULL,
+ NULL },
+
+ {"( 1.3.6.1.4.1.4203.666.4.11 NAME 'dnSuperiorMatch' "
+ "SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )",
+ SLAP_MR_HIDE | SLAP_MR_EXT, NULL,
+ NULL, dnNormalize, dnRelativeMatch,
+ NULL, NULL,
+ NULL },
+
{"( 1.2.36.79672281.1.13.3 NAME 'rdnMatch' "
"SYNTAX 1.2.36.79672281.1.5.0 )",
SLAP_MR_EQUALITY | SLAP_MR_EXT, NULL,
@@ -3248,6 +3571,29 @@ static slap_mrule_defs_rec mrule_defs[] = {
octetStringIndexer, octetStringFilter,
NULL },
+#ifdef LDAP_COMP_MATCH
+ {"( 1.2.36.79672281.1.13.2 NAME 'componentFilterMatch' "
+ "SYNTAX 1.2.36.79672281.1.5.2 )",
+ SLAP_MR_EXT|SLAP_MR_COMPONENT, componentFilterMatchSyntaxes,
+ NULL, NULL , componentFilterMatch,
+ octetStringIndexer, octetStringFilter,
+ NULL },
+
+ {"( 1.2.36.79672281.1.13.6 NAME 'allComponentsMatch' "
+ "SYNTAX 1.2.36.79672281.1.5.3 )",
+ SLAP_MR_EQUALITY|SLAP_MR_EXT|SLAP_MR_COMPONENT, NULL,
+ NULL, NULL , allComponentsMatch,
+ octetStringIndexer, octetStringFilter,
+ NULL },
+
+ {"( 1.2.36.79672281.1.13.7 NAME 'directoryComponentsMatch' "
+ "SYNTAX 1.2.36.79672281.1.5.3 )",
+ SLAP_MR_EQUALITY|SLAP_MR_EXT|SLAP_MR_COMPONENT, NULL,
+ NULL, NULL , directoryComponentsMatch,
+ octetStringIndexer, octetStringFilter,
+ NULL },
+#endif
+
{"( 2.5.13.2 NAME 'caseIgnoreMatch' "
"SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )",
SLAP_MR_EQUALITY | SLAP_MR_EXT, directoryStringSyntaxes,
@@ -3265,7 +3611,7 @@ static slap_mrule_defs_rec mrule_defs[] = {
{"( 2.5.13.4 NAME 'caseIgnoreSubstringsMatch' "
"SYNTAX 1.3.6.1.4.1.1466.115.121.1.58 )",
SLAP_MR_SUBSTR, directoryStringSyntaxes,
- NULL, UTF8StringNormalize, octetStringSubstringsMatch,
+ NULL, UTF8StringNormalize, directoryStringSubstringsMatch,
octetStringSubstringsIndexer, octetStringSubstringsFilter,
"caseIgnoreMatch" },
@@ -3286,7 +3632,7 @@ static slap_mrule_defs_rec mrule_defs[] = {
{"( 2.5.13.7 NAME 'caseExactSubstringsMatch' "
"SYNTAX 1.3.6.1.4.1.1466.115.121.1.58 )",
SLAP_MR_SUBSTR, directoryStringSyntaxes,
- NULL, UTF8StringNormalize, octetStringSubstringsMatch,
+ NULL, UTF8StringNormalize, directoryStringSubstringsMatch,
octetStringSubstringsIndexer, octetStringSubstringsFilter,
"caseExactMatch" },
@@ -3395,7 +3741,7 @@ static slap_mrule_defs_rec mrule_defs[] = {
"SYNTAX 1.3.6.1.4.1.1466.115.121.1.34 )",
SLAP_MR_EQUALITY | SLAP_MR_EXT, NULL,
NULL, uniqueMemberNormalize, uniqueMemberMatch,
- NULL, NULL,
+ uniqueMemberIndexer, uniqueMemberFilter,
NULL },
{"( 2.5.13.24 NAME 'protocolInformationMatch' "
@@ -3405,14 +3751,14 @@ static slap_mrule_defs_rec mrule_defs[] = {
{"( 2.5.13.27 NAME 'generalizedTimeMatch' "
"SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 )",
- SLAP_MR_EQUALITY | SLAP_MR_EXT, NULL,
+ SLAP_MR_EQUALITY | SLAP_MR_EXT | SLAP_MR_ORDERED_INDEX, NULL,
NULL, generalizedTimeNormalize, octetStringMatch,
- NULL, NULL,
+ generalizedTimeIndexer, generalizedTimeFilter,
NULL },
{"( 2.5.13.28 NAME 'generalizedTimeOrderingMatch' "
"SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 )",
- SLAP_MR_ORDERING, NULL,
+ SLAP_MR_ORDERING | SLAP_MR_ORDERED_INDEX, NULL,
NULL, generalizedTimeNormalize, generalizedTimeOrderingMatch,
NULL, NULL,
"generalizedTimeMatch" },
@@ -3472,14 +3818,14 @@ static slap_mrule_defs_rec mrule_defs[] = {
{"( 1.3.6.1.4.1.1466.109.114.3 NAME 'caseIgnoreIA5SubstringsMatch' "
"SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )",
SLAP_MR_SUBSTR, NULL,
- NULL, IA5StringNormalize, octetStringSubstringsMatch,
+ NULL, IA5StringNormalize, directoryStringSubstringsMatch,
octetStringSubstringsIndexer, octetStringSubstringsFilter,
"caseIgnoreIA5Match" },
{"( 1.3.6.1.4.1.4203.1.2.1 NAME 'caseExactIA5SubstringsMatch' "
"SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 )",
SLAP_MR_SUBSTR, NULL,
- NULL, IA5StringNormalize, octetStringSubstringsMatch,
+ NULL, IA5StringNormalize, directoryStringSubstringsMatch,
octetStringSubstringsIndexer, octetStringSubstringsFilter,
"caseExactIA5Match" },
@@ -3493,15 +3839,6 @@ static slap_mrule_defs_rec mrule_defs[] = {
NULL},
#endif
-#ifdef SLAPD_ACI_ENABLED
- {"( 1.3.6.1.4.1.4203.666.4.2 NAME 'OpenLDAPaciMatch' "
- "SYNTAX 1.3.6.1.4.1.4203.666.2.1 )",
- SLAP_MR_HIDE | SLAP_MR_EQUALITY, NULL,
- NULL, NULL, OpenLDAPaciMatch,
- NULL, NULL,
- NULL},
-#endif
-
{"( 1.2.840.113556.1.4.803 NAME 'integerBitAndMatch' "
"SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 )",
SLAP_MR_EXT, NULL,
@@ -3530,6 +3867,30 @@ static slap_mrule_defs_rec mrule_defs[] = {
octetStringIndexer, octetStringFilter,
"UUIDMatch"},
+ {"( 1.3.6.1.4.1.4203.666.11.2.2 NAME 'CSNMatch' "
+ "SYNTAX 1.3.6.1.4.1.4203.666.11.2.1 )",
+ SLAP_MR_HIDE | SLAP_MR_EQUALITY | SLAP_MR_ORDERED_INDEX, NULL,
+ NULL, NULL, csnMatch,
+ csnIndexer, csnFilter,
+ NULL},
+
+ {"( 1.3.6.1.4.1.4203.666.11.2.3 NAME 'CSNOrderingMatch' "
+ "SYNTAX 1.3.6.1.4.1.4203.666.11.2.1 )",
+ SLAP_MR_HIDE | SLAP_MR_ORDERING | SLAP_MR_ORDERED_INDEX, NULL,
+ NULL, NULL, csnOrderingMatch,
+ NULL, NULL,
+ "CSNMatch" },
+
+#ifdef SLAP_AUTHZ_SYNTAX
+ /* FIXME: OID is unused, but not registered yet */
+ {"( 1.3.6.1.4.1.4203.666.4.12 NAME 'authzMatch' "
+ "SYNTAX 1.3.6.1.4.1.4203.666.2.7 )",
+ SLAP_MR_HIDE | SLAP_MR_EQUALITY, NULL,
+ NULL, authzNormalize, authzMatch,
+ NULL, NULL,
+ NULL},
+#endif /* SLAP_AUTHZ_SYNTAX */
+
{NULL, SLAP_MR_NONE, NULL,
NULL, NULL, NULL, NULL, NULL,
NULL }
@@ -3588,4 +3949,7 @@ schema_destroy( void )
mr_destroy();
mru_destroy();
syn_destroy();
+
+ ldap_pvt_thread_mutex_destroy( &ad_undef_mutex );
+ ldap_pvt_thread_mutex_destroy( &oc_undef_mutex );
}