nameoptuid.c 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300
  1. /** BEGIN COPYRIGHT BLOCK
  2. * This Program is free software; you can redistribute it and/or modify it under
  3. * the terms of the GNU General Public License as published by the Free Software
  4. * Foundation; version 2 of the License.
  5. *
  6. * This Program is distributed in the hope that it will be useful, but WITHOUT
  7. * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
  8. * FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.
  9. *
  10. * You should have received a copy of the GNU General Public License along with
  11. * this Program; if not, write to the Free Software Foundation, Inc., 59 Temple
  12. * Place, Suite 330, Boston, MA 02111-1307 USA.
  13. *
  14. * In addition, as a special exception, Red Hat, Inc. gives You the additional
  15. * right to link the code of this Program with code not covered under the GNU
  16. * General Public License ("Non-GPL Code") and to distribute linked combinations
  17. * including the two, subject to the limitations in this paragraph. Non-GPL Code
  18. * permitted under this exception must only link to the code of this Program
  19. * through those well defined interfaces identified in the file named EXCEPTION
  20. * found in the source code files (the "Approved Interfaces"). The files of
  21. * Non-GPL Code may instantiate templates or use macros or inline functions from
  22. * the Approved Interfaces without causing the resulting work to be covered by
  23. * the GNU General Public License. Only Red Hat, Inc. may make changes or
  24. * additions to the list of Approved Interfaces. You must obey the GNU General
  25. * Public License in all respects for all of the Program code and other code used
  26. * in conjunction with the Program except the Non-GPL Code covered by this
  27. * exception. If you modify this file, you may extend this exception to your
  28. * version of the file, but you are not obligated to do so. If you do not wish to
  29. * provide this exception without modification, you must delete this exception
  30. * statement from your version and license this file solely under the GPL without
  31. * exception.
  32. *
  33. *
  34. * Copyright (C) 2001 Sun Microsystems, Inc. Used by permission.
  35. * Copyright (C) 2009 Red Hat, Inc.
  36. * All rights reserved.
  37. * END COPYRIGHT BLOCK **/
  38. #ifdef HAVE_CONFIG_H
  39. # include <config.h>
  40. #endif
  41. /* nameoptuid.c - Name And Optional UID syntax routines */
  42. #include <stdio.h>
  43. #include <string.h>
  44. #include <sys/types.h>
  45. #include "syntax.h"
  46. static int nameoptuid_filter_ava( Slapi_PBlock *pb, struct berval *bvfilter,
  47. Slapi_Value **bvals, int ftype, Slapi_Value **retVal );
  48. static int nameoptuid_filter_sub( Slapi_PBlock *pb, char *initial, char **any,
  49. char *final, Slapi_Value **bvals );
  50. static int nameoptuid_values2keys( Slapi_PBlock *pb, Slapi_Value **val,
  51. Slapi_Value ***ivals, int ftype );
  52. static int nameoptuid_assertion2keys_ava( Slapi_PBlock *pb, Slapi_Value *val,
  53. Slapi_Value ***ivals, int ftype );
  54. static int nameoptuid_assertion2keys_sub( Slapi_PBlock *pb, char *initial, char **any,
  55. char *final, Slapi_Value ***ivals );
  56. static int nameoptuid_compare(struct berval *v1, struct berval *v2);
  57. static int nameoptuid_validate(struct berval *val);
  58. static void nameoptuid_normalize(
  59. Slapi_PBlock *pb,
  60. char *s,
  61. int trim_spaces,
  62. char **alt
  63. );
  64. /* the first name is the official one from RFC 4517 */
  65. static char *names[] = { "Name And Optional UID", "nameoptuid", NAMEANDOPTIONALUID_SYNTAX_OID, 0 };
  66. static Slapi_PluginDesc pdesc = { "nameoptuid-syntax", VENDOR, DS_PACKAGE_VERSION,
  67. "Name And Optional UID attribute syntax plugin" };
  68. static const char *uniqueMemberMatch_names[] = {"uniqueMemberMatch", "2.5.13.23", NULL};
  69. static struct mr_plugin_def mr_plugin_table[] = {
  70. {{"2.5.13.23", NULL, "uniqueMemberMatch", "The uniqueMemberMatch rule compares an assertion value of the Name "
  71. "And Optional UID syntax to an attribute value of a syntax (e.g., the "
  72. "Name And Optional UID syntax) whose corresponding ASN.1 type is "
  73. "NameAndOptionalUID. "
  74. "The rule evaluates to TRUE if and only if the <distinguishedName> "
  75. "components of the assertion value and attribute value match according "
  76. "to the distinguishedNameMatch rule and either, (1) the <BitString> "
  77. "component is absent from both the attribute value and assertion "
  78. "value, or (2) the <BitString> component is present in both the "
  79. "attribute value and the assertion value and the <BitString> component "
  80. "of the assertion value matches the <BitString> component of the "
  81. "attribute value according to the bitStringMatch rule. "
  82. "Note that this matching rule has been altered from its description in "
  83. "X.520 [X.520] in order to make the matching rule commutative. Server "
  84. "implementors should consider using the original X.520 semantics "
  85. "(where the matching was less exact) for approximate matching of "
  86. "attributes with uniqueMemberMatch as the equality matching rule.",
  87. NAMEANDOPTIONALUID_SYNTAX_OID, 0, NULL /* no other syntaxes supported */}, /* matching rule desc */
  88. {"uniqueMemberMatch-mr", VENDOR, DS_PACKAGE_VERSION, "uniqueMemberMatch matching rule plugin"}, /* plugin desc */
  89. uniqueMemberMatch_names, /* matching rule name/oid/aliases */
  90. NULL, NULL, nameoptuid_filter_ava, NULL, nameoptuid_values2keys,
  91. nameoptuid_assertion2keys_ava, NULL, nameoptuid_compare},
  92. };
  93. static size_t mr_plugin_table_size = sizeof(mr_plugin_table)/sizeof(mr_plugin_table[0]);
  94. static int
  95. matching_rule_plugin_init(Slapi_PBlock *pb)
  96. {
  97. return syntax_matching_rule_plugin_init(pb, mr_plugin_table, mr_plugin_table_size);
  98. }
  99. static int
  100. register_matching_rule_plugins()
  101. {
  102. return syntax_register_matching_rule_plugins(mr_plugin_table, mr_plugin_table_size, matching_rule_plugin_init);
  103. }
  104. int
  105. nameoptuid_init( Slapi_PBlock *pb )
  106. {
  107. int rc, flags;
  108. LDAPDebug( LDAP_DEBUG_PLUGIN, "=> nameoptuid_init\n", 0, 0, 0 );
  109. rc = slapi_pblock_set( pb, SLAPI_PLUGIN_VERSION,
  110. (void *) SLAPI_PLUGIN_VERSION_01 );
  111. rc |= slapi_pblock_set( pb, SLAPI_PLUGIN_DESCRIPTION,
  112. (void *)&pdesc );
  113. rc |= slapi_pblock_set( pb, SLAPI_PLUGIN_SYNTAX_FILTER_AVA,
  114. (void *) nameoptuid_filter_ava );
  115. rc |= slapi_pblock_set( pb, SLAPI_PLUGIN_SYNTAX_FILTER_SUB,
  116. (void *) nameoptuid_filter_sub );
  117. rc |= slapi_pblock_set( pb, SLAPI_PLUGIN_SYNTAX_VALUES2KEYS,
  118. (void *) nameoptuid_values2keys );
  119. rc |= slapi_pblock_set( pb, SLAPI_PLUGIN_SYNTAX_ASSERTION2KEYS_AVA,
  120. (void *) nameoptuid_assertion2keys_ava );
  121. rc |= slapi_pblock_set( pb, SLAPI_PLUGIN_SYNTAX_ASSERTION2KEYS_SUB,
  122. (void *) nameoptuid_assertion2keys_sub );
  123. flags = SLAPI_PLUGIN_SYNTAX_FLAG_ORDERING;
  124. rc |= slapi_pblock_set( pb, SLAPI_PLUGIN_SYNTAX_FLAGS,
  125. (void *) &flags );
  126. rc |= slapi_pblock_set( pb, SLAPI_PLUGIN_SYNTAX_NAMES,
  127. (void *) names );
  128. rc |= slapi_pblock_set( pb, SLAPI_PLUGIN_SYNTAX_OID,
  129. (void *) NAMEANDOPTIONALUID_SYNTAX_OID );
  130. rc |= slapi_pblock_set( pb, SLAPI_PLUGIN_SYNTAX_COMPARE,
  131. (void *) nameoptuid_compare );
  132. rc |= slapi_pblock_set( pb, SLAPI_PLUGIN_SYNTAX_VALIDATE,
  133. (void *) nameoptuid_validate );
  134. rc |= slapi_pblock_set( pb, SLAPI_PLUGIN_SYNTAX_NORMALIZE,
  135. (void *) nameoptuid_normalize );
  136. rc |= register_matching_rule_plugins();
  137. LDAPDebug( LDAP_DEBUG_PLUGIN, "<= nameoptuid_init %d\n", rc, 0, 0 );
  138. return( rc );
  139. }
  140. static int
  141. nameoptuid_filter_ava(
  142. Slapi_PBlock *pb,
  143. struct berval *bvfilter,
  144. Slapi_Value **bvals,
  145. int ftype,
  146. Slapi_Value **retVal
  147. )
  148. {
  149. int filter_normalized = 0;
  150. int syntax = SYNTAX_CIS | SYNTAX_DN;
  151. if (pb) {
  152. slapi_pblock_get( pb, SLAPI_PLUGIN_SYNTAX_FILTER_NORMALIZED,
  153. &filter_normalized );
  154. if (filter_normalized) {
  155. syntax |= SYNTAX_NORM_FILT;
  156. }
  157. }
  158. return( string_filter_ava( bvfilter, bvals, syntax, ftype, retVal ) );
  159. }
  160. static int
  161. nameoptuid_filter_sub(
  162. Slapi_PBlock *pb,
  163. char *initial,
  164. char **any,
  165. char *final,
  166. Slapi_Value **bvals
  167. )
  168. {
  169. return( string_filter_sub( pb, initial, any, final, bvals,
  170. SYNTAX_CIS | SYNTAX_DN ) );
  171. }
  172. static int
  173. nameoptuid_values2keys(
  174. Slapi_PBlock *pb,
  175. Slapi_Value **vals,
  176. Slapi_Value ***ivals,
  177. int ftype
  178. )
  179. {
  180. return( string_values2keys( pb, vals, ivals, SYNTAX_CIS | SYNTAX_DN,
  181. ftype ) );
  182. }
  183. static int
  184. nameoptuid_assertion2keys_ava(
  185. Slapi_PBlock *pb,
  186. Slapi_Value *val,
  187. Slapi_Value ***ivals,
  188. int ftype
  189. )
  190. {
  191. return(string_assertion2keys_ava( pb, val, ivals,
  192. SYNTAX_CIS | SYNTAX_DN, ftype ));
  193. }
  194. static int
  195. nameoptuid_assertion2keys_sub(
  196. Slapi_PBlock *pb,
  197. char *initial,
  198. char **any,
  199. char *final,
  200. Slapi_Value ***ivals
  201. )
  202. {
  203. return( string_assertion2keys_sub( pb, initial, any, final, ivals,
  204. SYNTAX_CIS | SYNTAX_DN ) );
  205. }
  206. static int nameoptuid_compare(
  207. struct berval *v1,
  208. struct berval *v2
  209. )
  210. {
  211. return value_cmp(v1, v2, SYNTAX_CIS | SYNTAX_DN, 3 /* Normalise both values */);
  212. }
  213. static int
  214. nameoptuid_validate(
  215. struct berval *val
  216. )
  217. {
  218. int rc = 0; /* assume the value is valid */
  219. int got_sharp = 0;
  220. const char *p = NULL;
  221. const char *start = NULL;
  222. const char *end = NULL;
  223. /* Per RFC4517:
  224. *
  225. * NameAndOptionalUID = distinguishedName [ SHARP BitString ]
  226. */
  227. /* Don't allow a 0 length string */
  228. if ((val == NULL) || (val->bv_len == 0)) {
  229. rc = 1;
  230. goto exit;
  231. }
  232. start = &(val->bv_val[0]);
  233. end = &(val->bv_val[val->bv_len - 1]);
  234. /* Find the last SHARP in the value that may be separating
  235. * the distinguishedName from the optional BitString. */
  236. for (p = end; p >= start + 1; p--) {
  237. if (IS_SHARP(*p)) {
  238. got_sharp = 1;
  239. break;
  240. }
  241. }
  242. if (got_sharp) {
  243. /* Try to validate everything after the sharp as
  244. * a BitString. If this fails, we may still have
  245. * a valid value since a sharp is allowed in a
  246. * distinguishedName. If we don't find a valid
  247. * BitString, just validate the entire value as
  248. * a distinguishedName. */
  249. if ((rc = bitstring_validate_internal(p + 1, end)) != 0) {
  250. rc = distinguishedname_validate(start, end);
  251. } else {
  252. rc = distinguishedname_validate(start, p - 1);
  253. }
  254. } else {
  255. /* No optional BitString is present, so validate
  256. * the entire value as a distinguishedName. */
  257. rc = distinguishedname_validate(start, end);
  258. }
  259. exit:
  260. return rc;
  261. }
  262. static void nameoptuid_normalize(
  263. Slapi_PBlock *pb,
  264. char *s,
  265. int trim_spaces,
  266. char **alt
  267. )
  268. {
  269. value_normalize_ext(s, SYNTAX_CIS | SYNTAX_DN, trim_spaces, alt);
  270. return;
  271. }