]>
git.sur5r.net Git - openldap/log
Pierangelo Masarati [Fri, 8 Jul 2011 06:47:28 +0000 (08:47 +0200)]
blind fix build on solaris native compilers (ITS#6992)
Pierangelo Masarati [Thu, 7 Jul 2011 06:14:14 +0000 (08:14 +0200)]
fix config emit (ITS#6986)
Howard Chu [Sat, 2 Jul 2011 05:55:06 +0000 (22:55 -0700)]
ITS#6982 fix md5 memset invocation
Pierangelo Masarati [Thu, 30 Jun 2011 19:52:28 +0000 (21:52 +0200)]
authTimestamp should be manageable (ITS#6873)
Pierangelo Masarati [Thu, 30 Jun 2011 19:20:54 +0000 (21:20 +0200)]
response tag is [1] according to RFC 2589 (ITS#6886)
Rich Megginson [Wed, 29 Jun 2011 16:47:10 +0000 (10:47 -0600)]
ITS#6980 free the result of SSL_PeerCertificate
In tlsm_auth_cert_handler, we get the peer's cert from the socket using
SSL_PeerCertificate. This value is allocated and/or cached. We must
destroy it using CERT_DestroyCertificate.
Howard Chu [Tue, 28 Jun 2011 01:43:31 +0000 (18:43 -0700)]
ITS#6828 set ld_errno on connect failures
Rein Tollevik [Mon, 27 Jun 2011 12:21:35 +0000 (14:21 +0200)]
Merge branch 'master' of ssh://git-master.openldap.org/~git/git/openldap
Rein Tollevik [Mon, 27 Jun 2011 12:17:39 +0000 (14:17 +0200)]
ITS#6716 Extend test where consumer/provider holds CSNs with differing SIDs.
Howard Chu [Mon, 27 Jun 2011 11:48:25 +0000 (04:48 -0700)]
ITS#6872 re-enable test058
Howard Chu [Mon, 27 Jun 2011 11:46:43 +0000 (04:46 -0700)]
ITS#6872 fix test058 breakage from prev patch
Howard Chu [Sat, 25 Jun 2011 01:03:11 +0000 (18:03 -0700)]
ITS#6828 silence warning in prev commit
Howard Chu [Fri, 24 Jun 2011 00:10:37 +0000 (17:10 -0700)]
ITS#6977 fix verbose check in client tools
Howard Chu [Thu, 23 Jun 2011 20:17:08 +0000 (13:17 -0700)]
ITS#6978 bail out on invalid input
Howard Chu [Thu, 23 Jun 2011 03:03:02 +0000 (20:03 -0700)]
Fix NO_THREADS typo
Quanah Gibson-Mount [Wed, 22 Jun 2011 22:16:08 +0000 (15:16 -0700)]
Disable test058 until it someone can track down what's wrong with it
Howard Chu [Wed, 22 Jun 2011 07:29:47 +0000 (00:29 -0700)]
ITS#6716 Use sorted CSNs in syncrepl too
Howard Chu [Wed, 22 Jun 2011 04:42:44 +0000 (21:42 -0700)]
ITS#6716 use sorted CSNs, fix sessionlog
track a CSN per SID in the log->sl_mincsn
Howard Chu [Wed, 22 Jun 2011 03:44:53 +0000 (20:44 -0700)]
ITS#6716 Keep CSN lists sorted by SID
Howard Chu [Wed, 22 Jun 2011 00:05:53 +0000 (17:05 -0700)]
ITS#6817 fix RE24 build breakage
Should SLAP_AUTH_DN be #defined in release now?
Rich Megginson [Tue, 21 Jun 2011 22:58:49 +0000 (15:58 -0700)]
ITS#6862 MozNSS - workaround PR_SetEnv bug
Rich Megginson [Tue, 21 Jun 2011 00:28:48 +0000 (18:28 -0600)]
ITS#6975 MozNSS - allow cacertdir in most cases
OpenLDAP built with OpenSSL allows most any value of cacertdir - directory
is a file, directory does not contain any CA certs, directory does not
exist - users expect if they specify TLS_REQCERT=never, no matter what
the TLS_CACERTDIR setting is, TLS/SSL will just work.
TLS_CACERT, on the other hand, is a hard error. Even if TLS_REQCERT=never,
if TLS_CACERT is specified and is not a valid CA cert file, TLS/SSL will
fail. This patch makes CACERT errors hard errors, and makes CACERTDIR
errors "soft" errors. The code checks CACERT first and, even though
the function will return an error, checks CACERTDIR anyway so that if the
user sets TRACE mode they will get CACERTDIR processing messages.
Howard Chu [Tue, 21 Jun 2011 09:40:38 +0000 (02:40 -0700)]
ITS#6973 need limits_check if overlay is global
Jan Vcelak [Mon, 20 Jun 2011 15:31:57 +0000 (17:31 +0200)]
ITS#6947 Handle missing '\n' termination in LDIF input
Ondrej Kuznik [Thu, 16 Jun 2011 09:12:27 +0000 (11:12 +0200)]
ITS#6974 (Re)moving stray cleanup code.
Hallvard Furuseth [Mon, 20 Jun 2011 19:33:50 +0000 (21:33 +0200)]
Tweak back-ldif messages about CRC checksums.
Hallvard Furuseth [Mon, 20 Jun 2011 19:20:29 +0000 (21:20 +0200)]
Cleanup back-ldif CRC code.
Handle interrupted write() again. Fix warnings/types. #ifdef LDAP_DEBUG.
Howard Chu [Mon, 20 Jun 2011 17:57:57 +0000 (10:57 -0700)]
More fixes, add test script
Howard Chu [Mon, 20 Jun 2011 13:51:33 +0000 (06:51 -0700)]
Fix missing si_syncCookie numcsns
Howard Chu [Mon, 20 Jun 2011 11:27:11 +0000 (04:27 -0700)]
More tweaks for delta-mmr
Howard Chu [Mon, 20 Jun 2011 03:03:01 +0000 (20:03 -0700)]
delta-mmr conflict resolution
Howard Chu [Mon, 20 Jun 2011 00:04:19 +0000 (17:04 -0700)]
More for conflict detection
Howard Chu [Sun, 19 Jun 2011 22:54:45 +0000 (15:54 -0700)]
Setup delta-mmr using an overlay
Ralf Haferkamp [Wed, 15 Jun 2011 13:28:55 +0000 (15:28 +0200)]
Additional getter methods for LDAPModification
Howard Chu [Mon, 13 Jun 2011 20:54:56 +0000 (13:54 -0700)]
ITS#6657/6691 use proper SQL length data type
Quanah Gibson-Mount [Mon, 13 Jun 2011 20:46:01 +0000 (13:46 -0700)]
ITS#6971 correct option is --enable-wrappers
Howard Chu [Fri, 10 Jun 2011 10:27:40 +0000 (03:27 -0700)]
ITS#6944 limit op cache to 10 ops per thread
Howard Chu [Fri, 10 Jun 2011 09:11:26 +0000 (02:11 -0700)]
Add LDAP_OPT_X_TLS_PACKAGE
to return the name of the underlying TLS implementation
Howard Chu [Fri, 10 Jun 2011 08:44:30 +0000 (01:44 -0700)]
ITS#6892 shortcut for non-replicated ops
Howard Chu [Fri, 10 Jun 2011 08:35:19 +0000 (01:35 -0700)]
ITS#6967 normalize schema RDN
Howard Chu [Fri, 10 Jun 2011 04:09:41 +0000 (21:09 -0700)]
Add CRC32 checksum to back-ldif files
Currently just logs a complaint on checksum mismatch. Could get
more obnoxious later.
Howard Chu [Fri, 10 Jun 2011 01:07:13 +0000 (18:07 -0700)]
Fix prev commit
Howard Chu [Fri, 10 Jun 2011 00:59:08 +0000 (17:59 -0700)]
Try to discourage editing back-ldif files
Howard Chu [Thu, 9 Jun 2011 22:37:11 +0000 (15:37 -0700)]
Revert "ITS#6688 enforce search ACL in back-perl"
This reverts commit
53bb95a2e3456806b503415fb745eae1146c0627 .
Code was working as designed/documented. Changing now will
probably break other users.
Howard Chu [Thu, 9 Jun 2011 22:25:32 +0000 (15:25 -0700)]
ITS#6688 enforce search ACL in back-perl
Quanah Gibson-Mount [Thu, 9 Jun 2011 18:05:09 +0000 (11:05 -0700)]
ITS#6889 regenerate configure
cmikk@qwest.net [Tue, 29 Mar 2011 21:49:53 +0000 (21:49 +0000)]
ITS#6872
Perform the internal FIND_CSN search based at the backend's suffix with the
privileges of the backend's root DN.
SATOH Fumiyasu [Thu, 26 May 2011 15:41:54 +0000 (00:41 +0900)]
ITS#6955 smbk5pwd: Support shadowLastChange
Fix typo -- hyc
Howard Chu [Thu, 9 Jun 2011 08:01:06 +0000 (01:01 -0700)]
ITS#6936 add connID and peername to auditlog
From ksmith @ ycp.edu, with fixes by hyc
Tim Mooney [Tue, 12 Apr 2011 22:57:57 +0000 (17:57 -0500)]
ITS#6906 Update cachesize recommendations
to remove references to indexes in Hash format
Fix whitespace error -- hyc
Tim Mooney [Tue, 12 Apr 2011 20:54:03 +0000 (15:54 -0500)]
ITS#6905 Update intro of slapd-config/slapd.conf
Tim Mooney [Tue, 12 Apr 2011 16:31:31 +0000 (11:31 -0500)]
ITS#6904 Update to reflect that hdb is preferred
Tweak wording -- hyc
Howard Chu [Thu, 9 Jun 2011 07:21:47 +0000 (00:21 -0700)]
ITS#6934 fix typo
Howard Chu [Thu, 9 Jun 2011 02:17:50 +0000 (19:17 -0700)]
ITS#6901 fix filter with zero-length values
Howard Chu [Thu, 9 Jun 2011 01:52:52 +0000 (18:52 -0700)]
ITS#6889 libfetch is a libldap dependency
Howard Chu [Thu, 9 Jun 2011 01:27:54 +0000 (18:27 -0700)]
ITS#6828 fix TLS setup with async connect
Ondrej Kuznik [Fri, 6 May 2011 11:07:53 +0000 (13:07 +0200)]
ITS#6641 Bypass checks on ops with managedsait
Document the uniqueness changes
Fix whitespace in original patch -- hyc
Pierangelo Masarati [Wed, 8 Jun 2011 20:14:54 +0000 (22:14 +0200)]
ITS#6899
tag read entry response control value with [APPLICATION 4] (SearchResultEntry)
Pierangelo Masarati [Tue, 7 Jun 2011 22:29:39 +0000 (00:29 +0200)]
fix typo in previous commit
Howard Chu [Tue, 7 Jun 2011 02:55:09 +0000 (19:55 -0700)]
ITS#6948 partial revert of #6837, unnecessary
Howard Chu [Sun, 5 Jun 2011 20:59:19 +0000 (13:59 -0700)]
ITS#6948 fix ITS#6837 patch
Howard Chu [Sat, 4 Jun 2011 20:40:57 +0000 (13:40 -0700)]
ITS#6963 config entries' objectclass is read-only
Howard Chu [Sat, 4 Jun 2011 05:22:48 +0000 (22:22 -0700)]
ITS#6831 don't push stack unless needed
Howard Chu [Sat, 4 Jun 2011 04:55:22 +0000 (21:55 -0700)]
Fix
ce9bbd2 missing success return
Howard Chu [Sat, 4 Jun 2011 04:40:27 +0000 (21:40 -0700)]
ITS#6831 additional filter cmp fixes
Howard Chu [Sat, 4 Jun 2011 02:31:29 +0000 (19:31 -0700)]
ITS#6946 fix double-free, broken by
77a7ef0
Howard Chu [Sat, 4 Jun 2011 02:13:24 +0000 (19:13 -0700)]
ITS#6831 fix filter comparison
Howard Chu [Fri, 3 Jun 2011 18:51:11 +0000 (11:51 -0700)]
ITS#6959 document ldap_dnfree()
Howard Chu [Fri, 3 Jun 2011 18:24:19 +0000 (11:24 -0700)]
Drop note about slapcat for mirrormode
slapcat will always be self-consistent since the contextCSN is
snapshotted at the beginning of the dump.
Howard Chu [Wed, 1 Jun 2011 18:29:39 +0000 (11:29 -0700)]
More for ITS#6961 - deadlock checking
Howard Chu [Wed, 1 Jun 2011 08:44:51 +0000 (01:44 -0700)]
Fix for sparse ranges, get next ID from DB
Instead of iterating thru potentially many nonexistent IDs
Ralf Haferkamp [Thu, 26 May 2011 12:49:23 +0000 (14:49 +0200)]
ITS#6954 fix consistency checker prematurely deleting cached queries
Ralf Haferkamp [Thu, 26 May 2011 11:48:11 +0000 (13:48 +0200)]
fix uninitialized bindref_time (found with valgrind)
Ralf Haferkamp [Thu, 26 May 2011 07:05:01 +0000 (09:05 +0200)]
ITS#6953 do not use the cache db when refreshing
Howard Chu [Tue, 24 May 2011 18:20:12 +0000 (11:20 -0700)]
ITS#6915 document replication behavior
Howard Chu [Tue, 24 May 2011 18:14:58 +0000 (11:14 -0700)]
ITS#6915 Don't replicate internal operations
Howard Chu [Tue, 24 May 2011 18:06:56 +0000 (11:06 -0700)]
Revert "update entryCSN (and operational attrs in general) when changing memberOf (ITS#6329)"
This reverts commit
716eaf0e8b3554d8a1629970cab5490c9ffab97c .
Howard Chu [Tue, 24 May 2011 18:06:26 +0000 (11:06 -0700)]
Revert "force the generation of a new CSN (ITS#6766)"
This reverts commit
53343b421cddb808f03fb4639e57ed52850b53d9 .
Howard Chu [Tue, 24 May 2011 18:06:11 +0000 (11:06 -0700)]
Revert "ITS#6915 fix op timestamps"
This reverts commit
81687b321ca878e27824e017a111455e47c6231b .
Ralf Haferkamp [Tue, 24 May 2011 13:23:11 +0000 (15:23 +0200)]
ITS#6951 Fix two buffersize issue in "pcacheBind" config processing
Found with valgrind
Ralf Haferkamp [Tue, 24 May 2011 12:28:07 +0000 (14:28 +0200)]
ITS#6950 Fix '1.1', '+' and '*' in pcacheAttrSets
Pierangelo Masarati [Sun, 22 May 2011 22:22:12 +0000 (00:22 +0200)]
check sat_equality before using it (ITS#6943)
Hallvard Furuseth [Fri, 6 May 2011 15:32:25 +0000 (17:32 +0200)]
ITS#6935 Fix uninitialized cert-syntax vars.
serialNumberAndIssuerNormalize(): s3,
attributeCertificateExactNormalize():sn2,i_sn2.
Hallvard Furuseth [Sun, 8 May 2011 20:15:13 +0000 (22:15 +0200)]
ITS#6933 Add missing strdup of lutil_getRegParam()
Luke Howard [Mon, 9 May 2011 08:24:42 +0000 (10:24 +0200)]
Add GSS naming extensions ACL plugin
Hallvard Furuseth [Fri, 6 May 2011 20:45:39 +0000 (22:45 +0200)]
Fix test062-config-delete typo 2>%1 to 2>&1
Hallvard Furuseth [Mon, 2 May 2011 17:54:51 +0000 (19:54 +0200)]
ITS#6932: Move assert(str) before Debug(..str).
Hallvard Furuseth [Wed, 20 Apr 2011 20:11:38 +0000 (22:11 +0200)]
ITS#6932: Clean up strange asserts & nearby code.
Mostly found by Klocwork: Issues #213,298-300,331,342-343,374,390,410.
Hallvard Furuseth [Wed, 20 Apr 2011 20:38:21 +0000 (22:38 +0200)]
ITS#6931 Catch NULL ld for LDAP_OPT_SESSION_REFCNT.
Klocwork issue#111, ldap_get_option().
Hallvard Furuseth [Wed, 20 Apr 2011 21:00:24 +0000 (23:00 +0200)]
ITS#6930 Plug ldapi://too-long-path socket leak.
Klocwork issue#117, ldap_connect_to_path().
Hallvard Furuseth [Thu, 21 Apr 2011 17:09:20 +0000 (19:09 +0200)]
klocwork#255 Fix sprintf(%d, u_int32_t)
Hallvard Furuseth [Thu, 21 Apr 2011 15:50:50 +0000 (17:50 +0200)]
ITS#6929 fclose(password file) on failure.
lutil_get_filed_password() bug; klocwork issue#203.
Hallvard Furuseth [Thu, 21 Apr 2011 17:30:12 +0000 (19:30 +0200)]
ITS#6870 .gitignore += libldap_r/<ldif.c,fetch.c>.
Followup to moving these files to libldap/.
Ralf Haferkamp [Tue, 3 May 2011 09:21:07 +0000 (11:21 +0200)]
Fix build with gcc 4.6
Howard Chu [Sun, 24 Apr 2011 04:11:52 +0000 (21:11 -0700)]
ITS#6909 blind fix. re-init creds for retry.
Move retry so that cred validity is also re-checked.
Howard Chu [Sun, 24 Apr 2011 03:56:11 +0000 (20:56 -0700)]
ITS#6915 fix op timestamps
This has always been broken since memberof was first written
Howard Chu [Wed, 20 Apr 2011 19:31:27 +0000 (12:31 -0700)]
More for ITS#6815, Unbind and Abandon
Howard Chu [Fri, 15 Apr 2011 18:13:38 +0000 (11:13 -0700)]
Add strictrefresh syncrepl option
Only affects delta-syncrepl - stop listening to clients while
refresh is running.
Howard Chu [Fri, 15 Apr 2011 17:41:31 +0000 (10:41 -0700)]
Log when delta-sync has to fallback
Howard Chu [Fri, 15 Apr 2011 05:07:12 +0000 (22:07 -0700)]
Log entry DN on syncrepl errors