diff --git a/servers/slapd/limits.c b/servers/slapd/limits.c index b32ea0be77a63f5cfbb08f054a9838c1a9402207..0f43faf54883f01db4e40406d80df86dc7e44f49 100644 --- a/servers/slapd/limits.c +++ b/servers/slapd/limits.c @@ -1027,7 +1027,10 @@ limits_check( Operation *op, SlapReply *rs ) } } else if ( op->ors_limit->lms_t_hard > 0 ) { - if ( op->ors_tlimit < 0 || op->ors_tlimit > op->ors_limit->lms_t_hard ) { + if ( op->ors_tlimit == SLAP_MAX_LIMIT ) { + op->ors_tlimit = op->ors_limit->lms_t_hard; + + } else if ( op->ors_tlimit < 0 || op->ors_tlimit > op->ors_limit->lms_t_hard ) { /* error if exceeding hard limit */ rs->sr_err = LDAP_ADMINLIMIT_EXCEEDED; send_ldap_result( op, rs ); @@ -1084,7 +1087,9 @@ limits_check( Operation *op, SlapReply *rs ) if ( pr_total == -1 ) { slimit = -1; - } else if ( pr_total > 0 && ( op->ors_slimit == SLAP_NO_LIMIT || op->ors_slimit > pr_total ) ) { + } else if ( pr_total > 0 && op->ors_slimit != SLAP_MAX_LIMIT + && ( op->ors_slimit == SLAP_NO_LIMIT || op->ors_slimit > pr_total ) ) + { rs->sr_err = LDAP_ADMINLIMIT_EXCEEDED; send_ldap_result( op, rs ); rs->sr_err = LDAP_SUCCESS; @@ -1097,8 +1102,11 @@ limits_check( Operation *op, SlapReply *rs ) /* first round of pagedResults: set count to any appropriate limit */ - /* if the limit is set, check that it does not violate any limit */ - if ( op->ors_slimit > 0 ) { + /* if the limit is set, check that it does not violate any server-side limit */ + if ( op->ors_slimit == SLAP_MAX_LIMIT ) { + slimit2 = op->ors_slimit = pr_total; + + } else if ( op->ors_slimit > 0 ) { slimit2 = op->ors_slimit; } else if ( op->ors_slimit == 0 ) { @@ -1173,7 +1181,10 @@ limits_check( Operation *op, SlapReply *rs ) /* explicit hard limit: error if violated */ } else if ( op->ors_limit->lms_s_hard > 0 ) { - if ( op->ors_slimit > op->ors_limit->lms_s_hard ) { + if ( op->ors_slimit == SLAP_MAX_LIMIT ) { + op->ors_slimit = op->ors_limit->lms_s_hard; + + } else if ( op->ors_slimit > op->ors_limit->lms_s_hard ) { /* if limit exceeds hard, error */ rs->sr_err = LDAP_ADMINLIMIT_EXCEEDED; send_ldap_result( op, rs ); diff --git a/servers/slapd/slap.h b/servers/slapd/slap.h index e0330c07bbde4bb209657d9e697e2f39bcf2e91e..f1853ee04f3456ee0c7735e208c19b34e355fa71 100644 --- a/servers/slapd/slap.h +++ b/servers/slapd/slap.h @@ -1314,6 +1314,7 @@ struct slap_limits_set { /* Note: this is different from LDAP_NO_LIMIT (0); slapd internal use only */ #define SLAP_NO_LIMIT -1 +#define SLAP_MAX_LIMIT 2147483647 struct slap_limits { unsigned lm_flags; /* type of pattern */