nameoptuid.c 9.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279
  1. /** BEGIN COPYRIGHT BLOCK
  2. * Copyright (C) 2001 Sun Microsystems, Inc. Used by permission.
  3. * Copyright (C) 2009 Red Hat, Inc.
  4. * All rights reserved.
  5. *
  6. * License: GPL (version 3 or any later version).
  7. * See LICENSE for details.
  8. * END COPYRIGHT BLOCK **/
  9. #ifdef HAVE_CONFIG_H
  10. #include <config.h>
  11. #endif
  12. /* nameoptuid.c - Name And Optional UID syntax routines */
  13. #include <stdio.h>
  14. #include <string.h>
  15. #include <sys/types.h>
  16. #include "syntax.h"
  17. static int nameoptuid_filter_ava(Slapi_PBlock *pb, struct berval *bvfilter, Slapi_Value **bvals, int ftype, Slapi_Value **retVal);
  18. static int nameoptuid_filter_sub(Slapi_PBlock *pb, char *initial, char **any, char * final, Slapi_Value **bvals);
  19. static int nameoptuid_values2keys(Slapi_PBlock *pb, Slapi_Value **val, Slapi_Value ***ivals, int ftype);
  20. static int nameoptuid_assertion2keys_ava(Slapi_PBlock *pb, Slapi_Value *val, Slapi_Value ***ivals, int ftype);
  21. static int nameoptuid_assertion2keys_sub(Slapi_PBlock *pb, char *initial, char **any, char * final, Slapi_Value ***ivals);
  22. static int nameoptuid_compare(struct berval *v1, struct berval *v2);
  23. static int nameoptuid_validate(struct berval *val);
  24. static void nameoptuid_normalize(
  25. Slapi_PBlock *pb,
  26. char *s,
  27. int trim_spaces,
  28. char **alt);
  29. /* the first name is the official one from RFC 4517 */
  30. static char *names[] = {"Name And Optional UID", "nameoptuid", NAMEANDOPTIONALUID_SYNTAX_OID, 0};
  31. static Slapi_PluginDesc pdesc = {"nameoptuid-syntax", VENDOR, DS_PACKAGE_VERSION,
  32. "Name And Optional UID attribute syntax plugin"};
  33. static const char *uniqueMemberMatch_names[] = {"uniqueMemberMatch", "2.5.13.23", NULL};
  34. static struct mr_plugin_def mr_plugin_table[] = {
  35. {
  36. {
  37. "2.5.13.23",
  38. NULL,
  39. "uniqueMemberMatch",
  40. "The uniqueMemberMatch rule compares an assertion value of the Name "
  41. "And Optional UID syntax to an attribute value of a syntax (e.g., the "
  42. "Name And Optional UID syntax) whose corresponding ASN.1 type is "
  43. "NameAndOptionalUID. "
  44. "The rule evaluates to TRUE if and only if the <distinguishedName> "
  45. "components of the assertion value and attribute value match according "
  46. "to the distinguishedNameMatch rule and either, (1) the <BitString> "
  47. "component is absent from both the attribute value and assertion "
  48. "value, or (2) the <BitString> component is present in both the "
  49. "attribute value and the assertion value and the <BitString> component "
  50. "of the assertion value matches the <BitString> component of the "
  51. "attribute value according to the bitStringMatch rule. "
  52. "Note that this matching rule has been altered from its description in "
  53. "X.520 [X.520] in order to make the matching rule commutative. Server "
  54. "implementors should consider using the original X.520 semantics "
  55. "(where the matching was less exact) for approximate matching of "
  56. "attributes with uniqueMemberMatch as the equality matching rule.",
  57. NAMEANDOPTIONALUID_SYNTAX_OID,
  58. 0,
  59. NULL /* no other syntaxes supported */
  60. }, /* matching rule desc */
  61. {
  62. "uniqueMemberMatch-mr",
  63. VENDOR,
  64. DS_PACKAGE_VERSION,
  65. "uniqueMemberMatch matching rule plugin"}, /* plugin desc */
  66. uniqueMemberMatch_names, /* matching rule name/oid/aliases */
  67. NULL,
  68. NULL,
  69. nameoptuid_filter_ava,
  70. NULL,
  71. nameoptuid_values2keys,
  72. nameoptuid_assertion2keys_ava,
  73. NULL,
  74. nameoptuid_compare,
  75. NULL /* mr_normalise */
  76. },
  77. };
  78. static size_t mr_plugin_table_size = sizeof(mr_plugin_table) / sizeof(mr_plugin_table[0]);
  79. static int
  80. matching_rule_plugin_init(Slapi_PBlock *pb)
  81. {
  82. return syntax_matching_rule_plugin_init(pb, mr_plugin_table, mr_plugin_table_size);
  83. }
  84. static int
  85. register_matching_rule_plugins(void)
  86. {
  87. return syntax_register_matching_rule_plugins(mr_plugin_table, mr_plugin_table_size, matching_rule_plugin_init);
  88. }
  89. int
  90. nameoptuid_init(Slapi_PBlock *pb)
  91. {
  92. int rc, flags;
  93. slapi_log_err(SLAPI_LOG_PLUGIN, SYNTAX_PLUGIN_SUBSYSTEM, "=> nameoptuid_init\n");
  94. rc = slapi_pblock_set(pb, SLAPI_PLUGIN_VERSION,
  95. (void *)SLAPI_PLUGIN_VERSION_01);
  96. rc |= slapi_pblock_set(pb, SLAPI_PLUGIN_DESCRIPTION,
  97. (void *)&pdesc);
  98. rc |= slapi_pblock_set(pb, SLAPI_PLUGIN_SYNTAX_FILTER_AVA,
  99. (void *)nameoptuid_filter_ava);
  100. rc |= slapi_pblock_set(pb, SLAPI_PLUGIN_SYNTAX_FILTER_SUB,
  101. (void *)nameoptuid_filter_sub);
  102. rc |= slapi_pblock_set(pb, SLAPI_PLUGIN_SYNTAX_VALUES2KEYS,
  103. (void *)nameoptuid_values2keys);
  104. rc |= slapi_pblock_set(pb, SLAPI_PLUGIN_SYNTAX_ASSERTION2KEYS_AVA,
  105. (void *)nameoptuid_assertion2keys_ava);
  106. rc |= slapi_pblock_set(pb, SLAPI_PLUGIN_SYNTAX_ASSERTION2KEYS_SUB,
  107. (void *)nameoptuid_assertion2keys_sub);
  108. flags = SLAPI_PLUGIN_SYNTAX_FLAG_ORDERING;
  109. rc |= slapi_pblock_set(pb, SLAPI_PLUGIN_SYNTAX_FLAGS,
  110. (void *)&flags);
  111. rc |= slapi_pblock_set(pb, SLAPI_PLUGIN_SYNTAX_NAMES,
  112. (void *)names);
  113. rc |= slapi_pblock_set(pb, SLAPI_PLUGIN_SYNTAX_OID,
  114. (void *)NAMEANDOPTIONALUID_SYNTAX_OID);
  115. rc |= slapi_pblock_set(pb, SLAPI_PLUGIN_SYNTAX_COMPARE,
  116. (void *)nameoptuid_compare);
  117. rc |= slapi_pblock_set(pb, SLAPI_PLUGIN_SYNTAX_VALIDATE,
  118. (void *)nameoptuid_validate);
  119. rc |= slapi_pblock_set(pb, SLAPI_PLUGIN_SYNTAX_NORMALIZE,
  120. (void *)nameoptuid_normalize);
  121. rc |= register_matching_rule_plugins();
  122. slapi_log_err(SLAPI_LOG_PLUGIN, SYNTAX_PLUGIN_SUBSYSTEM, "<= nameoptuid_init %d\n", rc);
  123. return (rc);
  124. }
  125. static int
  126. nameoptuid_filter_ava(
  127. Slapi_PBlock *pb,
  128. struct berval *bvfilter,
  129. Slapi_Value **bvals,
  130. int ftype,
  131. Slapi_Value **retVal)
  132. {
  133. int filter_normalized = 0;
  134. int syntax = SYNTAX_CIS | SYNTAX_DN;
  135. if (pb) {
  136. slapi_pblock_get(pb, SLAPI_PLUGIN_SYNTAX_FILTER_NORMALIZED,
  137. &filter_normalized);
  138. if (filter_normalized) {
  139. syntax |= SYNTAX_NORM_FILT;
  140. }
  141. }
  142. return (string_filter_ava(bvfilter, bvals, syntax, ftype, retVal));
  143. }
  144. static int
  145. nameoptuid_filter_sub(
  146. Slapi_PBlock *pb,
  147. char *initial,
  148. char **any,
  149. char * final,
  150. Slapi_Value **bvals)
  151. {
  152. return (string_filter_sub(pb, initial, any, final, bvals,
  153. SYNTAX_CIS | SYNTAX_DN));
  154. }
  155. static int
  156. nameoptuid_values2keys(
  157. Slapi_PBlock *pb,
  158. Slapi_Value **vals,
  159. Slapi_Value ***ivals,
  160. int ftype)
  161. {
  162. return (string_values2keys(pb, vals, ivals, SYNTAX_CIS | SYNTAX_DN,
  163. ftype));
  164. }
  165. static int
  166. nameoptuid_assertion2keys_ava(
  167. Slapi_PBlock *pb,
  168. Slapi_Value *val,
  169. Slapi_Value ***ivals,
  170. int ftype)
  171. {
  172. return (string_assertion2keys_ava(pb, val, ivals,
  173. SYNTAX_CIS | SYNTAX_DN, ftype));
  174. }
  175. static int
  176. nameoptuid_assertion2keys_sub(
  177. Slapi_PBlock *pb,
  178. char *initial,
  179. char **any,
  180. char * final,
  181. Slapi_Value ***ivals)
  182. {
  183. return (string_assertion2keys_sub(pb, initial, any, final, ivals,
  184. SYNTAX_CIS | SYNTAX_DN));
  185. }
  186. static int
  187. nameoptuid_compare(
  188. struct berval *v1,
  189. struct berval *v2)
  190. {
  191. return value_cmp(v1, v2, SYNTAX_CIS | SYNTAX_DN, 3 /* Normalise both values */);
  192. }
  193. static int
  194. nameoptuid_validate(
  195. struct berval *val)
  196. {
  197. int rc = 0; /* assume the value is valid */
  198. int got_sharp = 0;
  199. const char *p = NULL;
  200. const char *start = NULL;
  201. const char *end = NULL;
  202. /* Per RFC4517:
  203. *
  204. * NameAndOptionalUID = distinguishedName [ SHARP BitString ]
  205. */
  206. /* Don't allow a 0 length string */
  207. if ((val == NULL) || (val->bv_len == 0)) {
  208. rc = 1;
  209. goto exit;
  210. }
  211. start = &(val->bv_val[0]);
  212. end = &(val->bv_val[val->bv_len - 1]);
  213. /* Find the last SHARP in the value that may be separating
  214. * the distinguishedName from the optional BitString. */
  215. for (p = end; p >= start + 1; p--) {
  216. if (IS_SHARP(*p)) {
  217. got_sharp = 1;
  218. break;
  219. }
  220. }
  221. if (got_sharp) {
  222. /* Try to validate everything after the sharp as
  223. * a BitString. If this fails, we may still have
  224. * a valid value since a sharp is allowed in a
  225. * distinguishedName. If we don't find a valid
  226. * BitString, just validate the entire value as
  227. * a distinguishedName. */
  228. if ((rc = bitstring_validate_internal(p + 1, end)) != 0) {
  229. rc = distinguishedname_validate(start, end);
  230. } else {
  231. rc = distinguishedname_validate(start, p - 1);
  232. }
  233. } else {
  234. /* No optional BitString is present, so validate
  235. * the entire value as a distinguishedName. */
  236. rc = distinguishedname_validate(start, end);
  237. }
  238. exit:
  239. return rc;
  240. }
  241. static void
  242. nameoptuid_normalize(
  243. Slapi_PBlock *pb __attribute__((unused)),
  244. char *s,
  245. int trim_spaces,
  246. char **alt)
  247. {
  248. value_normalize_ext(s, SYNTAX_CIS | SYNTAX_DN, trim_spaces, alt);
  249. return;
  250. }