]> git.sur5r.net Git - openldap/commitdiff
Disallow inappropriate operations upon the root dse.
authorKurt Zeilenga <kurt@openldap.org>
Fri, 8 Sep 2000 05:20:46 +0000 (05:20 +0000)
committerKurt Zeilenga <kurt@openldap.org>
Fri, 8 Sep 2000 05:20:46 +0000 (05:20 +0000)
servers/slapd/add.c
servers/slapd/delete.c
servers/slapd/tools/slapadd.c

index de88b57f869983f373fd46b37ade7f8f591f8eac..e2aad2ef7058d4c3898b176f018f73d5115656a7 100644 (file)
@@ -142,6 +142,13 @@ do_add( Connection *conn, Operation *op )
        Statslog( LDAP_DEBUG_STATS, "conn=%ld op=%d ADD dn=\"%s\"\n",
            op->o_connid, op->o_opid, e->e_ndn, 0, 0 );
 
+       if( e->e_ndn == NULL || *e->e_ndn == '\0' ) {
+               /* protocolError may be a more appropriate error */
+               send_ldap_result( conn, op, rc = LDAP_ALREADY_EXISTS,
+                       NULL, "root DSE exists", NULL, NULL );
+               goto done;
+       }
+
        /*
         * We could be serving multiple database backends.  Select the
         * appropriate one, or send a referral to our "referral server"
index d3bb5d96fafb590f4556c554d28f5a9d61ced498..140e8251521d08722500aa39e98035fb5572b6a3 100644 (file)
@@ -65,6 +65,14 @@ do_delete(
                goto cleanup;
        }
 
+       if( ndn == '\0' ) {
+               Debug( LDAP_DEBUG_ANY, "do_delete: root dse!\n", 0, 0, 0 );
+               /* protocolError would likely be a more appropriate error */
+               send_ldap_result( conn, op, rc = LDAP_UNWILLING_TO_PERFORM,
+                       NULL, "cannot delete the root DSE", NULL, NULL );
+               goto cleanup;
+       }
+
        Statslog( LDAP_DEBUG_STATS, "conn=%ld op=%d DEL dn=\"%s\"\n",
                op->o_connid, op->o_opid, dn, 0, 0 );
 
index 55cf92408c3b68482d41e263cc337c1a33efd512..4cf22f2457dd5a647923943868ab4812a12361fe 100644 (file)
@@ -67,6 +67,16 @@ main( int argc, char **argv )
                        break;
                }
 
+               /* make sure the DN is valid */
+               if( e->e_ndn == '\0' ) {
+                       fprintf( stderr, "%s: empty dn=\"%s\" (line=%d)\n",
+                               progname, e->e_dn, lineno );
+                       rc = EXIT_FAILURE;
+                       entry_free( e );
+                       if( continuemode ) continue;
+                       break;
+               }
+
                if( !noschemacheck ) {
                        /* check schema */
                        const char *text;