slap.h 27.4 KB
Newer Older
Kurt Zeilenga's avatar
Kurt Zeilenga committed
1
/* slap.h - stand alone ldap server include file */
2
/* $OpenLDAP$ */
3
4
5
6
/*
 * Copyright 1998-1999 The OpenLDAP Foundation, All Rights Reserved.
 * COPYING RESTRICTIONS APPLY, see COPYRIGHT file
 */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
7
8
9
10

#ifndef _SLDAPD_H_
#define _SLDAPD_H_

11
12
#include "ldap_defaults.h"

Kurt Zeilenga's avatar
Kurt Zeilenga committed
13
#include <ac/stdlib.h>
Kurt Zeilenga's avatar
Kurt Zeilenga committed
14

15
#include <sys/types.h>
Kurt Zeilenga's avatar
Kurt Zeilenga committed
16
17
#include <ac/syslog.h>
#include <ac/regex.h>
Kurt Zeilenga's avatar
Kurt Zeilenga committed
18
#include <ac/socket.h>
19
#include <ac/time.h>
20
#include <ac/param.h>
Kurt Zeilenga's avatar
Kurt Zeilenga committed
21

22
23
24
25
#ifdef HAVE_CYRUS_SASL
#include <sasl.h>
#endif

Kurt Zeilenga's avatar
Kurt Zeilenga committed
26
#include "avl.h"
27
28
29
30
31

#ifndef ldap_debug
#define ldap_debug slap_debug
#endif

32

33
34
#include "ldap_log.h"

Kurt Zeilenga's avatar
Kurt Zeilenga committed
35
36
#include <ldap.h>
#include <ldap_schema.h>
37

38
#include "ldap_pvt_thread.h"
Kurt Zeilenga's avatar
Kurt Zeilenga committed
39
#include "ldif.h"
40
41
42

LDAP_BEGIN_DECL

Hallvard Furuseth's avatar
Hallvard Furuseth committed
43
44
45
#ifdef f_next
#undef f_next /* name conflict between sys/file.h on SCO and struct filter */
#endif
Kurt Zeilenga's avatar
Kurt Zeilenga committed
46

47
48
#define SERVICE_NAME  OPENLDAP_PACKAGE "-slapd"

Juan Gomez's avatar
Juan Gomez committed
49
50
51
52
53
54
55
/* LDAPMod.mod_op value ===> Must be kept in sync with ldap.h!
 *
 * This is a value used internally by the backends. It is needed to allow
 * adding values that already exist without getting an error as required by
 * modrdn when the new rdn was already an attribute value itself.
 * JCG 05/1999 (gomez@engr.sgi.com)
 */
56
#define LDAP_MOD_SOFTADD	0x1000
Juan Gomez's avatar
Juan Gomez committed
57

Kurt Zeilenga's avatar
Kurt Zeilenga committed
58
59
#define ON	1
#define OFF	(-1)
60
#define UNDEFINED 0
Kurt Zeilenga's avatar
Kurt Zeilenga committed
61

62
63
#define MAXREMATCHES 10

64
65
66
/* psuedo error code to indicating abandoned operation */
#define SLAPD_ABANDON -1

67
/* XXYYZ: these macros assume 'x' is an ASCII x */
68
69
70
#define DNSEPARATOR(c)	((c) == ',' || (c) == ';')
#define SEPARATOR(c)	((c) == ',' || (c) == ';' || (c) == '+')
#define SPACE(c)	((c) == ' ' || (c) == '\n')
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85

#define ASCII_LOWER(c)	( (c) >= 'a' && (c) <= 'z' )
#define ASCII_UPPER(c)	( (c) >= 'A' && (c) <= 'Z' )
#define ASCII_ALPHA(c)	( ASCII_LOWER(c) || ASCII_UPPER(c) )
#define ASCII_DIGIT(c)	( (c) >= '0' && (c) <= '9' )
#define ASCII_ALNUM(c)	( ASCII_ALPHA(c) || ASCII_DIGIT(c) )

#define LEADKEYCHAR(c)	( ASCII_ALPHA(c) )
#define KEYCHAR(c)	( ASCII_ALNUM(c) || (c) == '-' )
#define LEADOIDCHAR(c)	( ASCII_DIGIT(c) )
#define OIDCHAR(c)	( ASCII_DIGIT(c) || (c) == '.' )

#define LEADATTRCHAR(c)	( LEADKEYCHAR(c) || LEADOIDCHAR(c) )
#define ATTRCHAR(c)	( KEYCHAR((c)) || (c) == '.' )

86
87
#define NEEDSESCAPE(c)	((c) == '\\' || (c) == '"')

88
89
#define SLAPD_ACI_DEFAULT_ATTR		"aci"

90
91
/* schema needed by slapd */
#define SLAPD_OID_DN_SYNTAX "1.3.6.1.4.1.1466.115.121.1.12"
92
#define SLAPD_OID_ACI_SYNTAX "1.1.1" /* bogus */
93

94
95
LIBSLAPD_F (int) slap_debug;

96
97
98
99
100
101
102
103
104
105
/*
 * Index types
 */
#define SLAP_INDEX_PRESENCE      0x0001U
#define SLAP_INDEX_EQUALITY      0x0002U
#define SLAP_INDEX_APPROX        0x0004U
#define SLAP_INDEX_SUB           0x0008U
#define SLAP_INDEX_UNKNOWN       0x0010U
#define SLAP_INDEX_FROMINIT      0x8000U	/* psuedo type */

106
107
108
109

/*
 * represents schema information for a database
 */
Julio Sánchez Fernández's avatar
   
Julio Sánchez Fernández committed
110
111
112
113
114
#define SLAP_SCHERR_OUTOFMEM		1
#define SLAP_SCHERR_CLASS_NOT_FOUND	2
#define SLAP_SCHERR_ATTR_NOT_FOUND	3
#define SLAP_SCHERR_DUP_CLASS		4
#define SLAP_SCHERR_DUP_ATTR		5
Julio Sánchez Fernández's avatar
   
Julio Sánchez Fernández committed
115
116
117
118
119
120
#define SLAP_SCHERR_DUP_SYNTAX		6
#define SLAP_SCHERR_DUP_RULE		7
#define SLAP_SCHERR_NO_NAME		8
#define SLAP_SCHERR_ATTR_INCOMPLETE	9
#define SLAP_SCHERR_MR_NOT_FOUND	10
#define SLAP_SCHERR_SYN_NOT_FOUND	11
121
#define SLAP_SCHERR_MR_INCOMPLETE	12
Julio Sánchez Fernández's avatar
   
Julio Sánchez Fernández committed
122

123
typedef struct slap_oid_macro {
Kurt Zeilenga's avatar
Kurt Zeilenga committed
124
125
126
127
	char *som_name;
	char *som_oid;
	int som_oidlen;
	struct slap_oid_macro *som_next;
128
129
} OidMacro;

Kurt Zeilenga's avatar
Kurt Zeilenga committed
130
131
132
133
134
/* forward declarations */
struct slap_syntax;
struct slap_matching_rule;


135
typedef int slap_syntax_validate_func LDAP_P((
Kurt Zeilenga's avatar
Kurt Zeilenga committed
136
	struct slap_syntax *syntax,
137
138
	struct berval * in));

Kurt Zeilenga's avatar
Kurt Zeilenga committed
139
140
typedef int slap_syntax_transform_func LDAP_P((
	struct slap_syntax *syntax,
141
142
143
144
145
	struct berval * in,
	struct berval ** out));

typedef struct slap_syntax {
	LDAP_SYNTAX			ssyn_syn;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
146
147
	int	ssyn_flags;

148
149
150
#define SLAP_SYNTAX_NONE	0
#define SLAP_SYNTAX_BINARY	1

151
	slap_syntax_validate_func	*ssyn_validate;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
152
153
154
155
156

	/* convert to and from binary */
	slap_syntax_transform_func	*ssyn_ber2str;
	slap_syntax_transform_func	*ssyn_str2ber;

157
158
159
160
161
	struct slap_syntax		*ssyn_next;
#define ssyn_oid			ssyn_syn.syn_oid
#define ssyn_desc			ssyn_syn.syn_desc
} Syntax;

162
163
164
165
/* XXX -> UCS-2 Converter */
typedef int slap_mr_convert_func LDAP_P((
	struct berval * in,
	struct berval ** out ));
Kurt Zeilenga's avatar
Kurt Zeilenga committed
166
167
168
169
170
171
172
173
174

/* Normalizer */
typedef int slap_mr_normalize_func LDAP_P((
	struct slap_syntax *syntax, /* NULL if in is asserted value */
	struct slap_matching_rule *mr,
	struct berval * in,
	struct berval ** out ));

/* Match (compare) function */
175
typedef int slap_mr_match_func LDAP_P((
Kurt Zeilenga's avatar
Kurt Zeilenga committed
176
177
178
179
	struct slap_syntax *syntax,	/* syntax of stored value */
	struct slap_matching_rule *mr,
	struct berval * value,
	struct berval * assertValue ));
180

181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
/* Index generation function */
typedef int slap_mr_indexer_func LDAP_P((
	struct slap_syntax *syntax,	/* syntax of stored value */
	struct slap_matching_rule *mr,
	struct berval **values,
	struct berval **keys ));

struct slap_filter; 	/* forward declaration */
/* Filter index function */
typedef int slap_mr_filter_func LDAP_P((
	struct slap_syntax *syntax,	/* syntax of stored value */
	struct slap_matching_rule *mr,
	struct slap_filter *filter,
	struct berval **keys ));

196
197
typedef struct slap_matching_rule {
	LDAP_MATCHING_RULE		smr_mrule;
198
	Syntax					*smr_syntax;
199
	slap_mr_convert_func	*smr_convert;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
200
	slap_mr_normalize_func	*smr_normalize;
201
	slap_mr_match_func		*smr_match;
202
203
	slap_mr_indexer_func	*smr_indexer;
	slap_mr_filter_func		*smr_filter;
204
205
206
207
	struct slap_matching_rule	*smr_next;
#define smr_oid				smr_mrule.mr_oid
#define smr_names			smr_mrule.mr_names
#define smr_desc			smr_mrule.mr_desc
Kurt Zeilenga's avatar
Kurt Zeilenga committed
208
209
#define smr_obsolete		smr_mrule.mr_obsolete
#define smr_syntax_oid		smr_mrule.mr_syntax_oid
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
} MatchingRule;

typedef struct slap_attribute_type {
	LDAP_ATTRIBUTE_TYPE		sat_atype;
	struct slap_attribute_type	*sat_sup;
	struct slap_attribute_type	**sat_subtypes;
	MatchingRule			*sat_equality;
	MatchingRule			*sat_ordering;
	MatchingRule			*sat_substr;
	Syntax				*sat_syntax;
	/* The next one is created to help in the transition */
	int				sat_syntax_compat;
	struct slap_attribute_type	*sat_next;
#define sat_oid			sat_atype.at_oid
#define sat_names		sat_atype.at_names
#define sat_desc		sat_atype.at_desc
#define sat_obsolete		sat_atype.at_obsolete
#define sat_sup_oid		sat_atype.at_sup_oid
#define sat_equality_oid	sat_atype.at_equality_oid
#define sat_ordering_oid	sat_atype.at_ordering_oid
#define sat_substr_oid		sat_atype.at_substr_oid
#define sat_syntax_oid		sat_atype.at_syntax_oid
#define sat_single_value	sat_atype.at_single_value
#define sat_collective		sat_atype.at_collective
234
#define sat_no_user_mod		sat_atype.at_no_user_mod
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
#define sat_usage		sat_atype.at_usage
} AttributeType;

typedef struct slap_object_class {
	LDAP_OBJECT_CLASS		soc_oclass;
	struct slap_object_class	**soc_sups;
	AttributeType			**soc_required;
	AttributeType			**soc_allowed;
	struct slap_object_class	*soc_next;
#define soc_oid			soc_oclass.oc_oid
#define soc_names		soc_oclass.oc_names
#define soc_desc		soc_oclass.oc_desc
#define soc_obsolete		soc_oclass.oc_obsolete
#define soc_sup_oids		soc_oclass.oc_sup_oids
#define soc_kind		soc_oclass.oc_kind
#define soc_at_oids_must	soc_oclass.oc_at_oids_must
#define soc_at_oids_may		soc_oclass.oc_at_oids_may
} ObjectClass;
253

254

255
256
struct slap_op;
struct slap_conn;
257

Kurt Zeilenga's avatar
Kurt Zeilenga committed
258
259
260
261
262
263
struct replog_moddn {
	char *newrdn;
	int	deloldrdn;
	char *newsup;
};

Kurt Zeilenga's avatar
Kurt Zeilenga committed
264
/*
Kurt Zeilenga's avatar
Kurt Zeilenga committed
265
 * represents an attribute value assertion (i.e., attr;option=value)
Kurt Zeilenga's avatar
Kurt Zeilenga committed
266
 */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
267
typedef struct slap_ava {
268
	char		*ava_type;	/* attribute description */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
269
270
271
	struct berval	ava_value;
} Ava;

Kurt Zeilenga's avatar
Kurt Zeilenga committed
272
273
274
/*
 * represents an matching rule assertion
 */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
275
typedef struct slap_mra {
276
277
	char	*mra_rule;	/* optional */
	char	*mra_type;	/* attribute description -- optional */
278
	int		mra_dnattrs;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
279
	struct berval	*mra_value;
280
281
} Mra;

Kurt Zeilenga's avatar
Kurt Zeilenga committed
282
283
284
/*
 * represents a search filter
 */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
285
typedef struct slap_filter {
286
	ber_tag_t	f_choice;	/* values taken from ldap.h */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
287

Kurt Zeilenga's avatar
Kurt Zeilenga committed
288
	union f_un_u {
Kurt Zeilenga's avatar
Kurt Zeilenga committed
289
290
291
292
293
294
		/* present */
		char		*f_un_type;

		/* equality, lessorequal, greaterorequal, approx */
		Ava		f_un_ava;

295
296
297
		/* extensible */
		Mra		f_un_fra;	

Kurt Zeilenga's avatar
Kurt Zeilenga committed
298
		/* and, or, not */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
299
		struct slap_filter	*f_un_complex;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
300
301
302
303

		/* substrings */
		struct sub {
			char	*f_un_sub_type;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
304
305
306
307

			struct berval	*f_un_sub_initial;
			struct berval	**f_un_sub_any;
			struct berval	*f_un_sub_final;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
308
309
		} f_un_sub;
	} f_un;
310
311

#define f_dn		f_un.f_un_type  /* used for DN indices */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
312
313
314
315
#define f_type		f_un.f_un_type
#define f_ava		f_un.f_un_ava
#define f_avtype	f_un.f_un_ava.ava_type
#define f_avvalue	f_un.f_un_ava.ava_value
316
317
318
319
#define f_mra		f_un.f_un_mra
#define f_mrtype	f_un.f_un_mra.mra_type
#define f_mrvalue	f_un.f_un_mra.mra_value
#define	f_mrdnaddrs	f_un.f_un_mra.mra_dnattrs
Kurt Zeilenga's avatar
Kurt Zeilenga committed
320
321
322
323
324
325
326
327
328
329
#define f_and		f_un.f_un_complex
#define f_or		f_un.f_un_complex
#define f_not		f_un.f_un_complex
#define f_list		f_un.f_un_complex
#define f_sub		f_un.f_un_sub
#define f_sub_type	f_un.f_un_sub.f_un_sub_type
#define f_sub_initial	f_un.f_un_sub.f_un_sub_initial
#define f_sub_any	f_un.f_un_sub.f_un_sub_any
#define f_sub_final	f_un.f_un_sub.f_un_sub_final

Kurt Zeilenga's avatar
Kurt Zeilenga committed
330
	struct slap_filter	*f_next;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
331
332
333
334
335
} Filter;

/*
 * represents an attribute (type + values + syntax)
 */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
336
typedef struct slap_attr {
337
	char		*a_type;	/* description */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
338
	struct berval	**a_vals;
339
#ifndef SLAPD_SCHEMA_NOT_COMPAT
Kurt Zeilenga's avatar
Kurt Zeilenga committed
340
	int		a_syntax;
341
#endif
Kurt Zeilenga's avatar
Kurt Zeilenga committed
342
	struct slap_attr	*a_next;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
343
344
} Attribute;

345
#ifndef SLAPD_SCHEMA_NOT_COMPAT
Kurt Zeilenga's avatar
Kurt Zeilenga committed
346
347
348
349
350
351
352
353
354
/*
 * the attr_syntax() routine returns one of these values
 * telling what kind of syntax an attribute supports.
 */
#define SYNTAX_CIS	0x01	/* case insensitive string		*/
#define SYNTAX_CES	0x02	/* case sensitive string		*/
#define SYNTAX_BIN	0x04	/* binary data 				*/
#define SYNTAX_TEL	0x08	/* telephone number string		*/
#define SYNTAX_DN	0x10	/* dn string				*/
355
#endif
Kurt Zeilenga's avatar
Kurt Zeilenga committed
356
357
358
359
360

/*
 * the id used in the indexes to refer to an entry
 */
typedef unsigned long	ID;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
361
#define NOID	((ID)~0)
Kurt Zeilenga's avatar
Kurt Zeilenga committed
362
363
364
365

/*
 * represents an entry in core
 */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
366
typedef struct slap_entry {
367
368
369
370
371
	/*
	 * The ID field should only be changed before entry is
	 * inserted into a cache.  The ID value is backend
	 * specific.
	 */
372
	ID		e_id;
373

374
375
376
	char		*e_dn;		/* DN of this entry */
	char		*e_ndn;		/* normalized DN of this entry */
	Attribute	*e_attrs;	/* list of attributes + values */
377

378
379
	/* for use by the backend for any purpose */
	void*	e_private;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
380
381
382
383
384
385
} Entry;

/*
 * represents an access control list
 */

386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
typedef enum slap_access_e {
	ACL_INVALID_ACCESS = -1,
	ACL_NONE = 0,
	ACL_AUTH,
	ACL_COMPARE,
	ACL_SEARCH,
	ACL_READ,
	ACL_WRITE
} slap_access_t;

typedef enum slap_control_e {
	ACL_INVALID_CONTROL	= 0,
	ACL_STOP,
	ACL_CONTINUE,
	ACL_BREAK
} slap_control_t;

typedef unsigned long slap_access_mask_t;

Kurt Zeilenga's avatar
Kurt Zeilenga committed
405
/* the "by" part */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
406
typedef struct slap_access {
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
	slap_control_t a_type;

#define ACL_ACCESS2PRIV(access)	(0x01U << (access))

#define ACL_PRIV_NONE			ACL_ACCESS2PRIV( ACL_NONE )
#define ACL_PRIV_AUTH			ACL_ACCESS2PRIV( ACL_AUTH )
#define ACL_PRIV_COMPARE		ACL_ACCESS2PRIV( ACL_COMPARE )
#define ACL_PRIV_SEARCH			ACL_ACCESS2PRIV( ACL_SEARCH )
#define ACL_PRIV_READ			ACL_ACCESS2PRIV( ACL_READ )
#define ACL_PRIV_WRITE			ACL_ACCESS2PRIV( ACL_WRITE )

#define ACL_PRIV_MASK			0x00ffUL

/* priv flags */
#define ACL_PRIV_LEVEL			0x1000UL
#define ACL_PRIV_ADDITIVE		0x2000UL
#define ACL_PRIV_SUBSTRACTIVE	0x4000UL

/* invalid privs */
#define ACL_PRIV_INVALID		0x0UL

#define ACL_PRIV_ISSET(m,p)		(((m) & (p)) == (p))
#define ACL_PRIV_ASSIGN(m,p)	do { (m)  =  (p); } while(0)
#define ACL_PRIV_SET(m,p)		do { (m) |=  (p); } while(0)
#define ACL_PRIV_CLR(m,p)		do { (m) &= ~(p); } while(0)

#define ACL_INIT(m)				ACL_PRIV_ASSIGN(m, ACL_PRIV_NONE)
#define ACL_INVALIDATE(m)		ACL_PRIV_ASSIGN(m, ACL_PRIV_INVALID)

#define ACL_GRANT(m,a)			ACL_PRIV_ISSET((m),ACL_ACCESS2PRIV(a))

#define ACL_IS_INVALID(m)		((m) == ACL_PRIV_INVALID)

#define ACL_IS_LEVEL(m)			ACL_PRIV_ISSET((m),ACL_PRIV_LEVEL)
#define ACL_IS_ADDITIVE(m)		ACL_PRIV_ISSET((m),ACL_PRIV_ADDITIVE)
#define ACL_IS_SUBTRACTIVE(m)	ACL_PRIV_ISSET((m),ACL_PRIV_SUBSTRACTIVE)

#define ACL_LVL_NONE			(ACL_PRIV_NONE|ACL_PRIV_LEVEL)
#define ACL_LVL_AUTH			(ACL_PRIV_AUTH|ACL_LVL_NONE)
#define ACL_LVL_COMPARE			(ACL_PRIV_COMPARE|ACL_LVL_AUTH)
#define ACL_LVL_SEARCH			(ACL_PRIV_SEARCH|ACL_LVL_COMPARE)
#define ACL_LVL_READ			(ACL_PRIV_READ|ACL_LVL_SEARCH)
#define ACL_LVL_WRITE			(ACL_PRIV_WRITE|ACL_LVL_READ)

#define ACL_LVL(m,l)			(((m)&ACL_PRIV_MASK) == ((l)&ACL_PRIV_MASK))
#define ACL_LVL_IS_NONE(m)		ACL_LVL((m),ACL_LVL_NONE)
#define ACL_LVL_IS_AUTH(m)		ACL_LVL((m),ACL_LVL_AUTH)
#define ACL_LVL_IS_COMPARE(m)	ACL_LVL((m),ACL_LVL_COMPARE)
#define ACL_LVL_IS_SEARCH(m)	ACL_LVL((m),ACL_LVL_SEARCH)
#define ACL_LVL_IS_READ(m)		ACL_LVL((m),ACL_LVL_READ)
#define ACL_LVL_IS_WRITE(m)		ACL_LVL((m),ACL_LVL_WRITE)

#define ACL_LVL_ASSIGN_NONE(m)		ACL_PRIV_ASSIGN((m),ACL_LVL_NONE)
#define ACL_LVL_ASSIGN_AUTH(m)		ACL_PRIV_ASSIGN((m),ACL_LVL_AUTH)
#define ACL_LVL_ASSIGN_COMPARE(m)	ACL_PRIV_ASSIGN((m),ACL_LVL_COMPARE)
#define ACL_LVL_ASSIGN_SEARCH(m)	ACL_PRIV_ASSIGN((m),ACL_LVL_SEARCH)
#define ACL_LVL_ASSIGN_READ(m)		ACL_PRIV_ASSIGN((m),ACL_LVL_READ)
#define ACL_LVL_ASSIGN_WRITE(m)		ACL_PRIV_ASSIGN((m),ACL_LVL_WRITE)
465

466
	slap_access_mask_t	a_mask;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
467

Kurt Zeilenga's avatar
Kurt Zeilenga committed
468
	char		*a_dn_pat;
469
#ifdef SLAPD_SCHEMA_NOT_COMPAT
470
	AttributeType	*a_dn_at;
471
472
#else
	char		*a_dn_at;
473
#endif
474
	int			a_dn_self;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
475
476
477
478
479

	char		*a_peername_pat;
	char		*a_sockname_pat;

	char		*a_domain_pat;
480
	char		*a_sockurl_pat;
481

482
#ifdef SLAPD_ACI_ENABLED
483
#ifdef SLAPD_SCHEMA_NOT_COMPAT
484
	AttributeType	*a_aci_at;
485
486
#else
	char		*a_aci_at;
487
#endif
488
489
#endif

490
	/* ACL Groups */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
491
	char		*a_group_pat;
492
	char		*a_group_oc;
493
#ifdef SLAPD_SCHEMA_NOT_COMPAT
494
	AttributeType	*a_group_at;
495
496
#else
	char		*a_group_at;
497
#endif
498

Kurt Zeilenga's avatar
Kurt Zeilenga committed
499
500
	struct slap_access	*a_next;
} Access;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
501
502

/* the "to" part */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
503
typedef struct slap_acl {
Kurt Zeilenga's avatar
Kurt Zeilenga committed
504
505
	/* "to" part: the entries this acl applies to */
	Filter		*acl_filter;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
506
507
	regex_t		acl_dn_re;
	char		*acl_dn_pat;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
508
509
510
	char		**acl_attrs;

	/* "by" part: list of who has what access to the entries */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
511
	Access	*acl_access;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
512

Kurt Zeilenga's avatar
Kurt Zeilenga committed
513
514
	struct slap_acl	*acl_next;
} AccessControl;
Kurt Zeilenga's avatar
Kurt Zeilenga committed
515

Kurt Zeilenga's avatar
Kurt Zeilenga committed
516
517
518
519
520
521
522
523
524
525
526
527
/*
 * A list of LDAPMods
 */
typedef struct ldapmodlist {
	struct ldapmod ml_mod;
	struct ldapmodlist *ml_next;
#define ml_op		ml_mod.mod_op
#define ml_type		ml_mod.mod_type
#define ml_values	ml_mod.mod_values
#define ml_bvalues	ml_mod.mod_bvalues
} LDAPModList;

Kurt Zeilenga's avatar
Kurt Zeilenga committed
528
/*
529
530
 * Backend-info
 * represents a backend 
Kurt Zeilenga's avatar
Kurt Zeilenga committed
531
532
 */

Kurt Zeilenga's avatar
Kurt Zeilenga committed
533
534
typedef struct slap_backend_info BackendInfo;	/* per backend type */
typedef struct slap_backend_db BackendDB;		/* per backend database */
535

Howard Chu's avatar
Howard Chu committed
536
537
538
539
LIBSLAPD_F (int) nBackendInfo;
LIBSLAPD_F (int) nBackendDB;
LIBSLAPD_F (BackendInfo	*) backendInfo;
LIBSLAPD_F (BackendDB *) backendDB;
540

Howard Chu's avatar
Howard Chu committed
541
LIBSLAPD_F (int) slapMode;	
542
543
544
545
546
547
#define SLAP_UNDEFINED_MODE	0x0000
#define SLAP_SERVER_MODE	0x0001
#define SLAP_TOOL_MODE		0x0002
#define SLAP_MODE			0x0003

#define SLAP_TRUNCATE_MODE	0x0100
548
#ifdef SLAPD_BDB2
549
#define SLAP_TIMED_MODE		0x1000
550
#endif
551
#define SLAP_TOOLID_MODE    4
552
553
554
555
556
557

/* temporary aliases */
typedef BackendDB Backend;
#define nbackends nBackendDB
#define backends backendDB

Kurt Zeilenga's avatar
Kurt Zeilenga committed
558
struct slap_backend_db {
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
	BackendInfo	*bd_info;	/* pointer to shared backend info */

	/* BackendInfo accessors */
#define		be_config	bd_info->bi_db_config
#define		be_type		bd_info->bi_type

#define		be_bind		bd_info->bi_op_bind
#define		be_unbind	bd_info->bi_op_unbind
#define		be_add		bd_info->bi_op_add
#define		be_compare	bd_info->bi_op_compare
#define		be_delete	bd_info->bi_op_delete
#define		be_modify	bd_info->bi_op_modify
#define		be_modrdn	bd_info->bi_op_modrdn
#define		be_search	bd_info->bi_op_search

574
575
#define		be_extended	bd_info->bi_extended

576
#define		be_release	bd_info->bi_entry_release_rw
577
578
#define		be_group	bd_info->bi_acl_group

579
580
#define		be_controls	bd_info->bi_controls

581
582
583
#define		be_connection_init	bd_info->bi_connection_init
#define		be_connection_destroy	bd_info->bi_connection_destroy

584
585
586
587
588
589
590
591
592
593
#ifdef SLAPD_TOOLS
#define		be_entry_open bd_info->bi_tool_entry_open
#define		be_entry_close bd_info->bi_tool_entry_close
#define		be_entry_first bd_info->bi_tool_entry_first
#define		be_entry_next bd_info->bi_tool_entry_next
#define		be_entry_get bd_info->bi_tool_entry_get
#define		be_entry_put bd_info->bi_tool_entry_put
#define		be_index_attr bd_info->bi_tool_index_attr
#define		be_index_change bd_info->bi_tool_index_change
#define		be_sync bd_info->bi_tool_sync
594
595
596
597
598
599
#endif

#ifdef HAVE_CYRUS_SASL
#define		be_sasl_authorize bd_info->bi_sasl_authorize
#define		be_sasl_getsecret bd_info->bi_sasl_getsecret
#define		be_sasl_putsecret bd_info->bi_sasl_putsecret
600
#endif
601

602
	/* these should be renamed from be_ to bd_ */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
603
	char	**be_suffix;	/* the DN suffixes of data in this backend */
604
	char	**be_nsuffix;	/* the normalized DN suffixes in this backend */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
605
	char	**be_suffixAlias; /* pairs of DN suffix aliases and deref values */
606
607
	char	*be_root_dn;	/* the magic "root" dn for this db 	*/
	char	*be_root_ndn;	/* the magic "root" normalized dn for this db	*/
608
	struct berval be_root_pw;	/* the magic "root" password for this db	*/
Kurt Zeilenga's avatar
Kurt Zeilenga committed
609
	int	be_readonly;	/* 1 => db is in "read only" mode	   */
610
	unsigned int be_max_deref_depth;       /* limit for depth of an alias deref  */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
611
612
	int	be_sizelimit;	/* size limit for this backend   	   */
	int	be_timelimit;	/* time limit for this backend       	   */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
613
	AccessControl *be_acl;	/* access control list for this backend	   */
614
	slap_access_t	be_dfltaccess;	/* access given if no acl matches	   */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
615
616
	char	**be_replica;	/* replicas of this backend (in master)	   */
	char	*be_replogfile;	/* replication log file (in master)	   */
617
	char	*be_update_ndn;	/* allowed to make changes (in replicas) */
618
	struct berval **be_update_refs;	/* where to refer modifying clients to */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
619
620
	int	be_lastmod;	/* keep track of lastmodified{by,time}	   */

621
622
	char	*be_realm;

623
	void	*be_private;	/* anything the backend database needs 	   */
624
625
};

626
627
628
629
typedef int (*SLAP_EXTENDED_FN) LDAP_P((
    Backend		*be,
    struct slap_conn		*conn,
    struct slap_op		*op,
630
	char		*reqoid,
631
    struct berval * reqdata,
632
	char		**rspoid,
633
    struct berval ** rspdata,
634
635
636
	LDAPControl *** rspctrls,
	char **	text,
	struct berval *** refs ));
637

Kurt Zeilenga's avatar
Kurt Zeilenga committed
638
struct slap_backend_info {
639
	char	*bi_type;	/* type of backend */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
640

641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
	/*
	 * per backend type routines:
	 * bi_init: called to allocate a backend_info structure,
	 *		called once BEFORE configuration file is read.
	 *		bi_init() initializes this structure hence is
	 *		called directly from be_initialize()
	 * bi_config: called per 'backend' specific option
	 *		all such options must before any 'database' options
	 *		bi_config() is called only from read_config()
	 * bi_open: called to open each database, called
	 *		once AFTER configuration file is read but
	 *		BEFORE any bi_db_open() calls.
	 *		bi_open() is called from backend_startup()
	 * bi_close: called to close each database, called
	 *		once during shutdown after all bi_db_close calls.
	 *		bi_close() is called from backend_shutdown()
	 * bi_destroy: called to destroy each database, called
	 *		once during shutdown after all bi_db_destroy calls.
	 *		bi_destory() is called from backend_destroy()
	 */
	int (*bi_init)	LDAP_P((BackendInfo *bi));
	int	(*bi_config) LDAP_P((BackendInfo *bi,
Kurt Zeilenga's avatar
Kurt Zeilenga committed
663
		const char *fname, int lineno, int argc, char **argv ));
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
	int (*bi_open) LDAP_P((BackendInfo *bi));
	int (*bi_close) LDAP_P((BackendInfo *bi));
	int (*bi_destroy) LDAP_P((BackendInfo *bi));

	/*
	 * per database routines:
	 * bi_db_init: called to initialize each database,
	 *	called upon reading 'database <type>' 
	 *	called only from backend_db_init()
	 * bi_db_config: called to configure each database,
	 *  called per database to handle per database options
	 *	called only from read_config()
	 * bi_db_open: called to open each database
	 *	called once per database immediately AFTER bi_open()
	 *	calls but before daemon startup.
	 *  called only by backend_startup()
	 * bi_db_close: called to close each database
	 *	called once per database during shutdown but BEFORE
	 *  any bi_close call.
	 *  called only by backend_shutdown()
	 * bi_db_destroy: called to destroy each database
	 *  called once per database during shutdown AFTER all
	 *  bi_close calls but before bi_destory calls.
	 *  called only by backend_destory()
	 */
	int (*bi_db_init) LDAP_P((Backend *bd));
	int	(*bi_db_config) LDAP_P((Backend *bd,
Kurt Zeilenga's avatar
Kurt Zeilenga committed
691
		const char *fname, int lineno, int argc, char **argv ));
692
693
694
695
696
697
	int (*bi_db_open) LDAP_P((Backend *bd));
	int (*bi_db_close) LDAP_P((Backend *bd));
	int (*bi_db_destroy) LDAP_P((Backend *db));

	/* LDAP Operations Handling Routines */
	int	(*bi_op_bind)  LDAP_P(( BackendDB *bd,
698
		struct slap_conn *c, struct slap_op *o,
699
		char *dn, char *ndn, int method, char* mechanism,
700
		struct berval *cred, char** edn ));
701
	int (*bi_op_unbind) LDAP_P((BackendDB *bd,
702
		struct slap_conn *c, struct slap_op *o ));
703
	int	(*bi_op_search) LDAP_P((BackendDB *bd,
704
		struct slap_conn *c, struct slap_op *o,
705
		char *base, char *nbase, int scope, int deref,
706
707
708
		int slimit, int tlimit,
		Filter *f, char *filterstr, char **attrs,
		int attrsonly));
709
	int	(*bi_op_compare)LDAP_P((BackendDB *bd,
710
		struct slap_conn *c, struct slap_op *o,
711
		char *dn, char *ndn, Ava *ava));
712
	int	(*bi_op_modify) LDAP_P((BackendDB *bd,
713
		struct slap_conn *c, struct slap_op *o,
714
		char *dn, char *ndn, LDAPModList *m));
715
	int	(*bi_op_modrdn) LDAP_P((BackendDB *bd,
716
		struct slap_conn *c, struct slap_op *o,
717
		char *dn, char *ndn, char *newrdn, int deleteoldrdn,
718
		char *newSuperior));
719
	int	(*bi_op_add)    LDAP_P((BackendDB *bd,
720
721
		struct slap_conn *c, struct slap_op *o,
		Entry *e));
722
	int	(*bi_op_delete) LDAP_P((BackendDB *bd,
723
		struct slap_conn *c, struct slap_op *o,
724
		char *dn, char *ndn));
725
	int	(*bi_op_abandon) LDAP_P((BackendDB *bd,
726
		struct slap_conn *c, struct slap_op *o,
727
		ber_int_t msgid));
728

729
730
731
	/* Extended Operations Helper */
	SLAP_EXTENDED_FN bi_extended;

732
	/* Auxilary Functions */
733
	int	(*bi_entry_release_rw) LDAP_P((BackendDB *bd, Entry *e, int rw));
734

735
#ifdef SLAPD_SCHEMA_NOT_COMPAT
736
	int	(*bi_acl_group)  LDAP_P((Backend *bd,
Kurt Zeilenga's avatar
Kurt Zeilenga committed
737
		Entry *e, const char *bdn, const char *edn,
738
739
		const char *objectclassValue,
		AttributeType *group_at ));
740
741
742
743
744
745
#else
	int	(*bi_acl_group)  LDAP_P((Backend *bd,
		Entry *e, const char *bdn, const char *edn,
		const char *objectclassValue,
		const char *group_at ));
#endif
746

747
748
749
750
751
	int	(*bi_connection_init) LDAP_P((BackendDB *bd,
		struct slap_conn *c));
	int	(*bi_connection_destroy) LDAP_P((BackendDB *bd,
		struct slap_conn *c));

752
753
754
755
756
757
758
759
760
761
762
763
	/* hooks for slap tools */
	int (*bi_tool_entry_open) LDAP_P(( BackendDB *be, int mode ));
	int (*bi_tool_entry_close) LDAP_P(( BackendDB *be ));
	ID (*bi_tool_entry_first) LDAP_P(( BackendDB *be ));
	ID (*bi_tool_entry_next) LDAP_P(( BackendDB *be ));
	Entry* (*bi_tool_entry_get) LDAP_P(( BackendDB *be, ID id ));
	ID (*bi_tool_entry_put) LDAP_P(( BackendDB *be, Entry *e ));
	int (*bi_tool_index_attr) LDAP_P(( BackendDB *be, char* type ));
	int (*bi_tool_index_change) LDAP_P(( BackendDB *be, char* type,
		struct berval **bv, ID id, int op ));
	int (*bi_tool_sync) LDAP_P(( BackendDB *be ));

764
765
766
767
768
769
770
771
772
773
774
775
#ifdef HAVE_CYRUS_SASL
	int (*bi_sasl_authorize) LDAP_P(( BackendDB *be,
		const char *authnid, const char *authzid,
		const char **canon_authzid, const char **errstr ));
	int (*bi_sasl_getsecret) LDAP_P(( BackendDB *be,
		const char *mechanism, const char *authzid,
		const char *realm, sasl_secret_t **secret ));
	int (*bi_sasl_putsecret) LDAP_P(( BackendDB *be,
		const char *mechanism, const char *auth_identity,
		const char *realm, const sasl_secret_t *secret ));
#endif /* HAVE_CYRUS_SASL */

776
777
#define SLAP_INDEX_ADD_OP		0x0001
#define SLAP_INDEX_DELETE_OP	0x0002
778

779
780
	char **bi_controls;		/* supported controls */

781
	unsigned int bi_nDB;	/* number of databases of this type */
782
	void	*bi_private;	/* anything the backend type needs */
783
};
Kurt Zeilenga's avatar
Kurt Zeilenga committed
784
785
786
787
788

/*
 * represents an operation pending from an ldap client
 */

789
typedef struct slap_op {
790
791
	ber_int_t	o_opid;		/* id of this operation		  */
	ber_int_t	o_msgid;	/* msgid of the request		  */
792
793
794

	ldap_pvt_thread_t	o_tid;		/* thread handling this op	  */

Kurt Zeilenga's avatar
Kurt Zeilenga committed
795
	BerElement	*o_ber;		/* ber of the request		  */
796

797
	ber_tag_t	o_tag;		/* tag of the request		  */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
798
	time_t		o_time;		/* time op was initiated	  */
799

Kurt Zeilenga's avatar
Kurt Zeilenga committed
800
	int		o_bind_in_progress;	/* multi-step bind in progress */
801
802
803
804
805
806
807
#ifdef SLAP_AUTHZID
	/* should only be used for reporting purposes */
	char	*o_authc_dn;	/* authentication DN */

	/* should be used as the DN of the User */
	char	*o_authz_dn;	/* authorization DN */
	char	*o_authz_ndn;	/* authorizaiton NDN */
808

809
#else
Kurt Zeilenga's avatar
Kurt Zeilenga committed
810
	char		*o_dn;		/* dn bound when op was initiated */
811
	char		*o_ndn;		/* normalized dn bound when op was initiated */
812
813
#endif

814
	ber_int_t	o_protocol;	/* version of the LDAP protocol used by client */
815
	ber_tag_t	o_authtype;	/* auth method used to bind dn	  */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
816
817
					/* values taken from ldap.h	  */
					/* LDAP_AUTH_*			  */
818
819
820
	char		*o_authmech; /* SASL mechanism used to bind dn */

	LDAPControl	**o_ctrls;	 /* controls */
821

822
	unsigned long	o_connid; /* id of conn initiating this op  */
823

Kurt Zeilenga's avatar
Kurt Zeilenga committed
824
#ifdef LDAP_CONNECTIONLESS
Kurt Zeilenga's avatar
Kurt Zeilenga committed
825
826
827
828
829
	int		o_cldap;	/* != 0 if this came in via CLDAP */
	struct sockaddr	o_clientaddr;	/* client address if via CLDAP	  */
	char		o_searchbase;	/* search base if via CLDAP	  */
#endif

830
831
832
833
	ldap_pvt_thread_mutex_t	o_abandonmutex; /* protects o_abandon  */
	int		o_abandon;	/* abandon flag */

	struct slap_op	*o_next;	/* next operation in list	  */
834
	void	*o_private;	/* anything the backend needs	  */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
835
836
837
838
839
840
} Operation;

/*
 * represents a connection from an ldap client
 */

841
typedef struct slap_conn {
842
843
844
845
	int			c_struct_state; /* structure management state */
	int			c_conn_state;	/* connection state */

	ldap_pvt_thread_mutex_t	c_mutex; /* protect the connection */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
846
	Sockbuf		*c_sb;			/* ber connection stuff		  */
847
848
849

	/* only can be changed by connect_init */
	time_t		c_starttime;	/* when the connection was opened */
850
	time_t		c_activitytime;	/* when the connection was last used */
851
	unsigned long		c_connid;	/* id of this connection for stats*/
Kurt Zeilenga's avatar
Kurt Zeilenga committed
852
853
854
855
856

	char		*c_listener_url;	/* listener URL */
	char		*c_peer_domain;	/* DNS name of client */
	char		*c_peer_name;	/* peer name (trans=addr:port) */
	char		*c_sock_name;	/* sock name (trans=addr:port) */
857

858
859
	/* only can be changed by binding thread */
	int		c_bind_in_progress;	/* multi-op bind in progress */
860
861
862
#ifdef HAVE_CYRUS_SASL
	sasl_conn_t	*c_sasl_context;
#endif
863
	void	*c_authstate;	/* SASL state data */
864

865
866
867
868
	Backend *c_authc_backend;

	/* authorization backend */
	Backend *c_authz_backend;
869

870
871
872
873
874
875
876
877
878
879
#ifdef SLAP_AUTHZID
	/* authentication backend */
	/* should only be used for reporting purposes */
	char	*c_authc_dn;	/* authentication DN */

	/* should be used as the DN of the User */
	char	*c_authz_dn;	/* authorization DN */
	char	*c_authz_ndn;	/* authorization NDN */

#else
880
881
	char	*c_cdn;		/* DN provided by the client */
	char	*c_dn;		/* DN bound to this conn  */
882
883
#endif

884
	ber_int_t	c_protocol;	/* version of the LDAP protocol used by client */
885
	ber_tag_t	c_authtype;/* auth method used to bind c_dn  */
886
	char	*c_authmech;	/* SASL mechanism used to bind c_dn */
887

888
889
890
	Operation	*c_ops;			/* list of operations being processed */
	Operation	*c_pending_ops;	/* list of pending operations */

891
892
	ldap_pvt_thread_mutex_t	c_write_mutex;	/* only one pdu written at a time */
	ldap_pvt_thread_cond_t	c_write_cv;		/* used to wait for sd write-ready*/
893

894
895
896
	BerElement	*c_currentber;	/* ber we're attempting to read */
	int		c_writewaiter;	/* true if writer is waiting */

Kurt Zeilenga's avatar
Kurt Zeilenga committed
897
#ifdef HAVE_TLS
898
899
	int	c_is_tls;		/* true if this LDAP over raw TLS */
	int	c_needs_tls_accept;	/* true if SSL_accept should be called */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
900
#endif
901

902
903
904
905
	long	c_n_ops_received;		/* num of ops received (next op_id) */
	long	c_n_ops_executing;	/* num of ops currently executing */
	long	c_n_ops_pending;		/* num of ops pending execution */
	long	c_n_ops_completed;	/* num of ops completed */
906
907
908
909

	long	c_n_get;		/* num of get calls */
	long	c_n_read;		/* num of read calls */
	long	c_n_write;		/* num of write calls */
Kurt Zeilenga's avatar
Kurt Zeilenga committed
910
911
912
913
} Connection;

#if defined(LDAP_SYSLOG) && defined(LDAP_DEBUG)
#define Statslog( level, fmt, connid, opid, arg1, arg2, arg3 )	\
914
	do { \
915
916
917
918
919
		if ( ldap_debug & (level) ) \
			fprintf( stderr, (fmt), (connid), (opid), (arg1), (arg2), (arg3) );\
		if ( ldap_syslog & (level) ) \
			syslog( ldap_syslog_level, (fmt), (connid), (opid), (arg1), \
			        (arg2), (arg3) ); \
920
	} while (0)
Kurt Zeilenga's avatar
Kurt Zeilenga committed
921
922
923
924
#else
#define Statslog( level, fmt, connid, opid, arg1, arg2, arg3 )
#endif

Kurt Zeilenga's avatar
Kurt Zeilenga committed
925
LDAP_END_DECL
Kurt Zeilenga's avatar
Kurt Zeilenga committed
926

927
928
#include "proto-slap.h"

Kurt Zeilenga's avatar
Kurt Zeilenga committed
929
#endif /* _slap_h_ */