replmd: Cache recycle-bin state to avoid DB lookup
[samba.git] / lib / ldb / common / ldb_controls.c
1 /* 
2    ldb database library
3
4    Copyright (C) Simo Sorce  2005
5
6      ** NOTE! The following LGPL license applies to the ldb
7      ** library. This does NOT imply that all of Samba is released
8      ** under the LGPL
9    
10    This library is free software; you can redistribute it and/or
11    modify it under the terms of the GNU Lesser General Public
12    License as published by the Free Software Foundation; either
13    version 3 of the License, or (at your option) any later version.
14
15    This library is distributed in the hope that it will be useful,
16    but WITHOUT ANY WARRANTY; without even the implied warranty of
17    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
18    Lesser General Public License for more details.
19
20    You should have received a copy of the GNU Lesser General Public
21    License along with this library; if not, see <http://www.gnu.org/licenses/>.
22 */
23
24 /*
25  *  Name: ldb_controls.c
26  *
27  *  Component: ldb controls utility functions
28  *
29  *  Description: helper functions for control modules
30  *
31  *  Author: Simo Sorce
32  */
33
34 #include "ldb_private.h"
35
36 /* check if a control with the specified "oid" exist and return it */
37 /* returns NULL if not found */
38 struct ldb_control *ldb_request_get_control(struct ldb_request *req, const char *oid)
39 {
40         unsigned int i;
41
42         if (req->controls != NULL) {
43                 for (i = 0; req->controls[i]; i++) {
44                         if (req->controls[i]->oid && strcmp(oid, req->controls[i]->oid) == 0) {
45                                 break;
46                         }
47                 }
48
49                 return req->controls[i];
50         }
51
52         return NULL;
53 }
54
55 /* check if a control with the specified "oid" exist and return it */
56 /* returns NULL if not found */
57 struct ldb_control *ldb_reply_get_control(struct ldb_reply *rep, const char *oid)
58 {
59         unsigned int i;
60
61         if (rep->controls != NULL) {
62                 for (i = 0; rep->controls[i]; i++) {
63                         if (rep->controls[i]->oid && strcmp(oid, rep->controls[i]->oid) == 0) {
64                                 break;
65                         }
66                 }
67
68                 return rep->controls[i];
69         }
70
71         return NULL;
72 }
73
74 /*
75  * Saves the current controls list into the "saver" (can also be NULL) and
76  * replace the one in "req" with a new one excluding the "exclude" control
77  * (if it is NULL then the list remains the same)
78  *
79  * Returns 0 on error.
80  */
81 int ldb_save_controls(struct ldb_control *exclude, struct ldb_request *req, struct ldb_control ***saver)
82 {
83         struct ldb_control **lcs, **lcs_old;
84         unsigned int i, j;
85
86         lcs_old = req->controls;
87         if (saver != NULL) {
88                 *saver = lcs_old;
89         }
90
91         for (i = 0; req->controls && req->controls[i]; i++);
92         if (i == 0) {
93                 req->controls = NULL;
94                 return 1;
95         }
96
97         lcs = talloc_array(req, struct ldb_control *, i + 1);
98         if (!lcs) {
99                 return 0;
100         }
101
102         for (i = 0, j = 0; lcs_old[i]; i++) {
103                 if (exclude == lcs_old[i]) continue;
104                 lcs[j] = lcs_old[i];
105                 j++;
106         }
107         lcs[j] = NULL;
108
109         req->controls = talloc_realloc(req, lcs, struct ldb_control *, j + 1);
110         if (req->controls == NULL) {
111                 return 0;
112         }
113         return 1;
114 }
115
116 /*
117  * Returns a list of controls, except the one specified with "exclude" (can
118  * also be NULL).  Included controls become a child of returned list if they
119  * were children of "controls_in".
120  *
121  * Returns NULL on error (OOM) or an empty control list.
122  */
123 struct ldb_control **ldb_controls_except_specified(struct ldb_control **controls_in, 
124                                                TALLOC_CTX *mem_ctx, 
125                                                struct ldb_control *exclude)
126 {
127         struct ldb_control **lcs = NULL;
128         unsigned int i, j, n;
129
130         for (i = 0; controls_in && controls_in[i]; i++);
131         if (i == 0) {
132                 return NULL;
133         }
134         n = i;
135
136         for (i = 0, j = 0; controls_in && controls_in[i]; i++) {
137                 if (exclude == controls_in[i]) continue;
138
139                 if (!lcs) {
140                         /* Allocate here so if we remove the only
141                          * control, or there were no controls, we
142                          * don't allocate at all, and just return
143                          * NULL */
144                         lcs = talloc_array(mem_ctx, struct ldb_control *,
145                                            n + 1);
146                         if (!lcs) {
147                                 return NULL;
148                         }
149                 }
150
151                 lcs[j] = controls_in[i];
152                 talloc_reparent(controls_in, lcs, lcs[j]);
153                 j++;
154         }
155         if (lcs) {
156                 lcs[j] = NULL;
157
158                 lcs = talloc_realloc(mem_ctx, lcs, struct ldb_control *, j + 1);
159         }
160
161         return lcs;
162 }
163
164 /* check if there's any control marked as critical in the list */
165 /* return True if any, False if none */
166 int ldb_check_critical_controls(struct ldb_control **controls)
167 {
168         unsigned int i;
169
170         if (controls == NULL) {
171                 return 0;
172         }
173
174         for (i = 0; controls[i]; i++) {
175                 if (controls[i]->critical) {
176                         return 1;
177                 }
178         }
179
180         return 0;
181 }
182
183 int ldb_request_add_control(struct ldb_request *req, const char *oid, bool critical, void *data)
184 {
185         unsigned int i, n;
186         struct ldb_control **ctrls;
187         struct ldb_control *ctrl;
188
189         for (n=0; req->controls && req->controls[n];n++) { 
190                 /* having two controls of the same OID makes no sense */
191                 if (req->controls[n]->oid && strcmp(oid, req->controls[n]->oid) == 0) {
192                         return LDB_ERR_ATTRIBUTE_OR_VALUE_EXISTS;
193                 }
194         }
195
196         ctrls = talloc_array(req,
197                                struct ldb_control *,
198                                n + 2);
199         if (!ctrls) return LDB_ERR_OPERATIONS_ERROR;
200
201         for (i=0; i<n; i++) {
202                 ctrls[i] = req->controls[i];
203         }
204
205         req->controls = ctrls;
206         ctrls[n] = NULL;
207         ctrls[n+1] = NULL;
208
209         ctrl = talloc(ctrls, struct ldb_control);
210         if (!ctrl) return LDB_ERR_OPERATIONS_ERROR;
211
212         ctrl->oid       = talloc_strdup(ctrl, oid);
213         if (!ctrl->oid) return LDB_ERR_OPERATIONS_ERROR;
214         ctrl->critical  = critical;
215         ctrl->data      = data;
216
217         ctrls[n] = ctrl;
218         return LDB_SUCCESS;
219 }
220
221 int ldb_reply_add_control(struct ldb_reply *ares, const char *oid, bool critical, void *data)
222 {
223         unsigned n;
224         struct ldb_control **ctrls;
225         struct ldb_control *ctrl;
226
227         for (n=0; ares->controls && ares->controls[n];) { 
228                 /* having two controls of the same OID makes no sense */
229                 if (ares->controls[n]->oid && strcmp(oid, ares->controls[n]->oid) == 0) {
230                         return LDB_ERR_ATTRIBUTE_OR_VALUE_EXISTS;
231                 }
232                 n++; 
233         }
234
235         ctrls = talloc_realloc(ares, ares->controls,
236                                struct ldb_control *,
237                                n + 2);
238         if (!ctrls) return LDB_ERR_OPERATIONS_ERROR;
239         ares->controls = ctrls;
240         ctrls[n] = NULL;
241         ctrls[n+1] = NULL;
242
243         ctrl = talloc(ctrls, struct ldb_control);
244         if (!ctrl) return LDB_ERR_OPERATIONS_ERROR;
245
246         ctrl->oid       = talloc_strdup(ctrl, oid);
247         if (!ctrl->oid) return LDB_ERR_OPERATIONS_ERROR;
248         ctrl->critical  = critical;
249         ctrl->data      = data;
250
251         ctrls[n] = ctrl;
252         return LDB_SUCCESS;
253 }
254
255 /* Add a control to the request, replacing the old one if it is already in the request */
256 int ldb_request_replace_control(struct ldb_request *req, const char *oid, bool critical, void *data)
257 {
258         unsigned int n;
259         int ret;
260
261         ret = ldb_request_add_control(req, oid, critical, data);
262         if (ret != LDB_ERR_ATTRIBUTE_OR_VALUE_EXISTS) {
263                 return ret;
264         }
265
266         for (n=0; req->controls[n];n++) {
267                 if (req->controls[n]->oid && strcmp(oid, req->controls[n]->oid) == 0) {
268                         req->controls[n]->critical = critical;
269                         req->controls[n]->data = data;
270                         return LDB_SUCCESS;
271                 }
272         }
273
274         return LDB_ERR_OPERATIONS_ERROR;
275 }
276
277 /*
278  * Return a control as string
279  * the project (ie. name:value1:value2:...:valuen
280  * The string didn't include the criticity of the critical flag
281  */
282 char *ldb_control_to_string(TALLOC_CTX *mem_ctx, const struct ldb_control *control)
283 {
284         char *res = NULL;
285
286         if (strcmp(control->oid, LDB_CONTROL_PAGED_RESULTS_OID) == 0) {
287                 struct ldb_paged_control *rep_control = talloc_get_type(control->data, struct ldb_paged_control);
288                 char *cookie;
289
290                 cookie = ldb_base64_encode(mem_ctx, rep_control->cookie, rep_control->cookie_len);
291                 if (cookie == NULL) {
292                         return NULL;
293                 }
294                 if (cookie[0] != '\0') {
295                         res = talloc_asprintf(mem_ctx, "%s:%d:%s",
296                                                 LDB_CONTROL_PAGED_RESULTS_NAME,
297                                                 control->critical,
298                                                 cookie);
299
300                         talloc_free(cookie);
301                 } else {
302                         res = talloc_asprintf(mem_ctx, "%s:%d",
303                                                 LDB_CONTROL_PAGED_RESULTS_NAME,
304                                                 control->critical);
305                 }
306                 return res;
307         }
308
309         if (strcmp(control->oid, LDB_CONTROL_VLV_RESP_OID) == 0) {
310                 struct ldb_vlv_resp_control *rep_control = talloc_get_type(control->data,
311                                                                 struct ldb_vlv_resp_control);
312
313                 char *cookie;
314
315                 cookie = ldb_base64_encode(mem_ctx,
316                                            (char *)rep_control->contextId,
317                                            rep_control->ctxid_len);
318                 if (cookie == NULL) {
319                         return NULL;
320                 }
321
322                 res = talloc_asprintf(mem_ctx, "%s:%d:%d:%d:%d:%s",
323                                                 LDB_CONTROL_VLV_RESP_NAME,
324                                                 control->critical,
325                                                 rep_control->targetPosition,
326                                                 rep_control->contentCount,
327                                                 rep_control->vlv_result,
328                                                 cookie);
329
330                 return res;
331         }
332
333         if (strcmp(control->oid, LDB_CONTROL_SORT_RESP_OID) == 0) {
334                 struct ldb_sort_resp_control *rep_control = talloc_get_type(control->data,
335                                                                 struct ldb_sort_resp_control);
336
337                 res = talloc_asprintf(mem_ctx, "%s:%d:%d:%s",
338                                         LDB_CONTROL_SORT_RESP_NAME,
339                                         control->critical,
340                                         rep_control->result,
341                                         rep_control->attr_desc);
342
343                 return res;
344         }
345
346         if (strcmp(control->oid, LDB_CONTROL_ASQ_OID) == 0) {
347                 struct ldb_asq_control *rep_control = talloc_get_type(control->data,
348                                                                 struct ldb_asq_control);
349
350                 res = talloc_asprintf(mem_ctx, "%s:%d:%d",
351                                         LDB_CONTROL_SORT_RESP_NAME,
352                                         control->critical,
353                                         rep_control->result);
354
355                 return res;
356         }
357
358         if (strcmp(control->oid, LDB_CONTROL_DIRSYNC_OID) == 0) {
359                 char *cookie;
360                 struct ldb_dirsync_control *rep_control = talloc_get_type(control->data,
361                                                                 struct ldb_dirsync_control);
362
363                 cookie = ldb_base64_encode(mem_ctx, rep_control->cookie,
364                                 rep_control->cookie_len);
365                 if (cookie == NULL) {
366                         return NULL;
367                 }
368                 res = talloc_asprintf(mem_ctx, "%s:%d:%d:%d:%s",
369                                         LDB_CONTROL_DIRSYNC_NAME,
370                                         control->critical,
371                                         rep_control->flags,
372                                         rep_control->max_attributes,
373                                         cookie);
374
375                 talloc_free(cookie);
376                 return res;
377         }
378         if (strcmp(control->oid, LDB_CONTROL_DIRSYNC_EX_OID) == 0) {
379                 char *cookie;
380                 struct ldb_dirsync_control *rep_control = talloc_get_type(control->data,
381                                                                 struct ldb_dirsync_control);
382
383                 cookie = ldb_base64_encode(mem_ctx, rep_control->cookie,
384                                 rep_control->cookie_len);
385                 if (cookie == NULL) {
386                         return NULL;
387                 }
388                 res = talloc_asprintf(mem_ctx, "%s:%d:%d:%d:%s",
389                                         LDB_CONTROL_DIRSYNC_EX_NAME,
390                                         control->critical,
391                                         rep_control->flags,
392                                         rep_control->max_attributes,
393                                         cookie);
394
395                 talloc_free(cookie);
396                 return res;
397         }
398
399         if (strcmp(control->oid, LDB_CONTROL_VERIFY_NAME_OID) == 0) {
400                 struct ldb_verify_name_control *rep_control = talloc_get_type(control->data, struct ldb_verify_name_control);
401
402                 if (rep_control->gc != NULL) {
403                         res = talloc_asprintf(mem_ctx, "%s:%d:%d:%s",
404                                                 LDB_CONTROL_VERIFY_NAME_NAME,
405                                                 control->critical,
406                                                 rep_control->flags,
407                                                 rep_control->gc);
408
409                 } else {
410                         res = talloc_asprintf(mem_ctx, "%s:%d:%d",
411                                                 LDB_CONTROL_VERIFY_NAME_NAME,
412                                                 control->critical,
413                                                 rep_control->flags);
414                 }
415                 return res;
416         }
417
418         /*
419          * From here we don't know the control
420          */
421         if (control->data == NULL) {
422                 /*
423                  * We don't know the control but there is no real data attached
424                  * to it so we can represent it with local_oid:oid:criticity.
425                  */
426                 res = talloc_asprintf(mem_ctx, "local_oid:%s:%d",
427                                         control->oid,
428                                         control->critical);
429         } else {
430                 res = talloc_asprintf(mem_ctx, "unknown oid:%s",
431                                         control->oid);
432         }
433         return res;
434 }
435
436
437 /*
438  * A little trick to allow one to use constants defined in headers rather than
439  * hardwritten in the file.
440  * "sizeof" will return the \0 char as well so it will take the place of ":"
441  * in the length of the string.
442  */
443 #define LDB_CONTROL_CMP(control, NAME) strncmp(control, NAME ":", sizeof(NAME))
444
445 /* Parse one string and return associated control if parsing is successful*/
446 struct ldb_control *ldb_parse_control_from_string(struct ldb_context *ldb, TALLOC_CTX *mem_ctx, const char *control_strings)
447 {
448         struct ldb_control *ctrl;
449
450         if (!(ctrl = talloc(mem_ctx, struct ldb_control))) {
451                 ldb_oom(ldb);
452                 return NULL;
453         }
454
455         if (LDB_CONTROL_CMP(control_strings,
456                                 LDB_CONTROL_VLV_REQ_NAME) == 0) {
457                 struct ldb_vlv_req_control *control;
458                 const char *p;
459                 char attr[1024];
460                 char ctxid[1024];
461                 int crit, bc, ac, os, cc, ret;
462
463                 attr[0] = '\0';
464                 ctxid[0] = '\0';
465                 p = &(control_strings[sizeof(LDB_CONTROL_VLV_REQ_NAME)]);
466                 ret = sscanf(p, "%d:%d:%d:%d:%d:%1023[^$]", &crit, &bc, &ac, &os, &cc, ctxid);
467                 /* We allow 2 ways to encode the GT_EQ case, because the
468                    comparison string might contain null bytes or colons, which
469                    would break sscanf (or indeed any parsing mechanism). */
470                 if (ret == 3) {
471                         ret = sscanf(p, "%d:%d:%d:>=%1023[^:]:%1023[^$]", &crit, &bc, &ac, attr, ctxid);
472                 }
473                 if (ret == 3) {
474                         int len;
475                         ret = sscanf(p, "%d:%d:%d:base64>=%1023[^:]:%1023[^$]", &crit, &bc, &ac, attr, ctxid);
476                         len = ldb_base64_decode(attr);
477                         if (len < 0) {
478                                 ret = -1;
479                         }
480                 }
481
482                 if ((ret < 4) || (crit < 0) || (crit > 1)) {
483                         ldb_set_errstring(ldb,
484                                           "invalid VLV control syntax\n"
485                                           " syntax: crit(b):bc(n):ac(n):"
486                                           "{os(n):cc(n)|>=val(s)|base64>=val(o)}[:ctxid(o)]\n"
487                                           "   note: b = boolean, n = number, s = string, o = b64 binary blob");
488                         talloc_free(ctrl);
489                         return NULL;
490                 }
491                 ctrl->oid = LDB_CONTROL_VLV_REQ_OID;
492                 ctrl->critical = crit;
493                 if (!(control = talloc(ctrl,
494                                         struct ldb_vlv_req_control))) {
495                         ldb_oom(ldb);
496                         talloc_free(ctrl);
497                         return NULL;
498                 }
499                 control->beforeCount = bc;
500                 control->afterCount = ac;
501                 if (attr[0]) {
502                         control->type = 1;
503                         control->match.gtOrEq.value = talloc_strdup(control, attr);
504                         control->match.gtOrEq.value_len = strlen(attr);
505                 } else {
506                         control->type = 0;
507                         control->match.byOffset.offset = os;
508                         control->match.byOffset.contentCount = cc;
509                 }
510                 if (ctxid[0]) {
511                         int len = ldb_base64_decode(ctxid);
512                         if (len < 0) {
513                                 ldb_set_errstring(ldb,
514                                                   "invalid VLV context_id\n");
515                                 talloc_free(ctrl);
516                                 return NULL;
517                         }
518                         control->ctxid_len = len;
519                         control->contextId = talloc_memdup(control, ctxid,
520                                                            control->ctxid_len);
521                         if (control->contextId == NULL) {
522                                 ldb_oom(ldb);
523                                 return NULL;
524                         }
525                 } else {
526                         control->ctxid_len = 0;
527                         control->contextId = NULL;
528                 }
529                 ctrl->data = control;
530
531                 return ctrl;
532         }
533
534         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_DIRSYNC_NAME) == 0) {
535                 struct ldb_dirsync_control *control;
536                 const char *p;
537                 char cookie[1024];
538                 int crit, max_attrs, ret;
539                 uint32_t flags;
540
541                 cookie[0] = '\0';
542                 p = &(control_strings[sizeof(LDB_CONTROL_DIRSYNC_NAME)]);
543                 ret = sscanf(p, "%d:%u:%d:%1023[^$]", &crit, &flags, &max_attrs, cookie);
544
545                 if ((ret < 3) || (crit < 0) || (crit > 1) || (max_attrs < 0)) {
546                         ldb_set_errstring(ldb,
547                                           "invalid dirsync control syntax\n"
548                                           " syntax: crit(b):flags(n):max_attrs(n)[:cookie(o)]\n"
549                                           "   note: b = boolean, n = number, o = b64 binary blob");
550                         talloc_free(ctrl);
551                         return NULL;
552                 }
553
554                 /* w2k3 seems to ignore the parameter,
555                  * but w2k sends a wrong cookie when this value is to small
556                  * this would cause looping forever, while getting
557                  * the same data and same cookie forever
558                  */
559                 if (max_attrs == 0) max_attrs = 0x0FFFFFFF;
560
561                 ctrl->oid = LDB_CONTROL_DIRSYNC_OID;
562                 ctrl->critical = crit;
563                 control = talloc(ctrl, struct ldb_dirsync_control);
564                 control->flags = flags;
565                 control->max_attributes = max_attrs;
566                 if (*cookie) {
567                         int len = ldb_base64_decode(cookie);
568                         if (len < 0) {
569                                 ldb_set_errstring(ldb,
570                                                   "invalid dirsync cookie\n");
571                                 talloc_free(ctrl);
572                                 return NULL;
573                         }
574                         control->cookie_len = len;
575                         control->cookie = (char *)talloc_memdup(control, cookie, control->cookie_len);
576                         if (control->cookie == NULL) {
577                                 ldb_oom(ldb);
578                                 return NULL;
579                         }
580                 } else {
581                         control->cookie = NULL;
582                         control->cookie_len = 0;
583                 }
584                 ctrl->data = control;
585
586                 return ctrl;
587         }
588         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_DIRSYNC_EX_NAME) == 0) {
589                 struct ldb_dirsync_control *control;
590                 const char *p;
591                 char cookie[1024];
592                 int crit, max_attrs, ret;
593                 uint32_t flags;
594
595                 cookie[0] = '\0';
596                 p = &(control_strings[sizeof(LDB_CONTROL_DIRSYNC_EX_NAME)]);
597                 ret = sscanf(p, "%d:%u:%d:%1023[^$]", &crit, &flags, &max_attrs, cookie);
598
599                 if ((ret < 3) || (crit < 0) || (crit > 1) || (max_attrs < 0)) {
600                         ldb_set_errstring(ldb,
601                                           "invalid dirsync_ex control syntax\n"
602                                           " syntax: crit(b):flags(n):max_attrs(n)[:cookie(o)]\n"
603                                           "   note: b = boolean, n = number, o = b64 binary blob");
604                         talloc_free(ctrl);
605                         return NULL;
606                 }
607
608                 /* w2k3 seems to ignore the parameter,
609                  * but w2k sends a wrong cookie when this value is to small
610                  * this would cause looping forever, while getting
611                  * the same data and same cookie forever
612                  */
613                 if (max_attrs == 0) max_attrs = 0x0FFFFFFF;
614
615                 ctrl->oid = LDB_CONTROL_DIRSYNC_EX_OID;
616                 ctrl->critical = crit;
617                 control = talloc(ctrl, struct ldb_dirsync_control);
618                 control->flags = flags;
619                 control->max_attributes = max_attrs;
620                 if (*cookie) {
621                         int len = ldb_base64_decode(cookie);
622                         if (len < 0) {
623                                 ldb_set_errstring(ldb,
624                                                   "invalid dirsync_ex cookie"
625                                                   " (probably too long)\n");
626                                 talloc_free(ctrl);
627                                 return NULL;
628                         }
629                         control->cookie_len = len;
630                         control->cookie = (char *)talloc_memdup(control, cookie, control->cookie_len);
631                         if (control->cookie == NULL) {
632                                 ldb_oom(ldb);
633                                 return NULL;
634                         }
635                 } else {
636                         control->cookie = NULL;
637                         control->cookie_len = 0;
638                 }
639                 ctrl->data = control;
640
641                 return ctrl;
642         }
643
644         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_ASQ_NAME) == 0) {
645                 struct ldb_asq_control *control;
646                 const char *p;
647                 char attr[256];
648                 int crit, ret;
649
650                 attr[0] = '\0';
651                 p = &(control_strings[sizeof(LDB_CONTROL_ASQ_NAME)]);
652                 ret = sscanf(p, "%d:%255[^$]", &crit, attr);
653                 if ((ret != 2) || (crit < 0) || (crit > 1) || (attr[0] == '\0')) {
654                         ldb_set_errstring(ldb,
655                                           "invalid asq control syntax\n"
656                                           " syntax: crit(b):attr(s)\n"
657                                           "   note: b = boolean, s = string");
658                         talloc_free(ctrl);
659                         return NULL;
660                 }
661
662                 ctrl->oid = LDB_CONTROL_ASQ_OID;
663                 ctrl->critical = crit;
664                 control = talloc(ctrl, struct ldb_asq_control);
665                 control->request = 1;
666                 control->source_attribute = talloc_strdup(control, attr);
667                 control->src_attr_len = strlen(attr);
668                 ctrl->data = control;
669
670                 return ctrl;
671         }
672
673         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_EXTENDED_DN_NAME) == 0) {
674                 struct ldb_extended_dn_control *control;
675                 const char *p;
676                 int crit, type, ret;
677
678                 p = &(control_strings[sizeof(LDB_CONTROL_EXTENDED_DN_NAME)]);
679                 ret = sscanf(p, "%d:%d", &crit, &type);
680                 if ((ret != 2) || (crit < 0) || (crit > 1) || (type < 0) || (type > 1)) {
681                         ret = sscanf(p, "%d", &crit);
682                         if ((ret != 1) || (crit < 0) || (crit > 1)) {
683                                 ldb_set_errstring(ldb,
684                                                   "invalid extended_dn control syntax\n"
685                                                   " syntax: crit(b)[:type(i)]\n"
686                                                   "   note: b = boolean\n"
687                                                   "         i = integer\n"
688                                                   "   valid values are: 0 - hexadecimal representation\n"
689                                                   "                     1 - normal string representation");
690                                 talloc_free(ctrl);
691                                 return NULL;
692                         }
693                         control = NULL;
694                 } else {
695                         control = talloc(ctrl, struct ldb_extended_dn_control);
696                         control->type = type;
697                 }
698
699                 ctrl->oid = LDB_CONTROL_EXTENDED_DN_OID;
700                 ctrl->critical = crit;
701                 ctrl->data = talloc_steal(ctrl, control);
702
703                 return ctrl;
704         }
705
706         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_SD_FLAGS_NAME) == 0) {
707                 struct ldb_sd_flags_control *control;
708                 const char *p;
709                 int crit, ret;
710                 unsigned secinfo_flags;
711
712                 p = &(control_strings[sizeof(LDB_CONTROL_SD_FLAGS_NAME)]);
713                 ret = sscanf(p, "%d:%u", &crit, &secinfo_flags);
714                 if ((ret != 2) || (crit < 0) || (crit > 1) || (secinfo_flags > 0xF)) {
715                         ldb_set_errstring(ldb,
716                                           "invalid sd_flags control syntax\n"
717                                           " syntax: crit(b):secinfo_flags(n)\n"
718                                           "   note: b = boolean, n = number");
719                         talloc_free(ctrl);
720                         return NULL;
721                 }
722
723                 ctrl->oid = LDB_CONTROL_SD_FLAGS_OID;
724                 ctrl->critical = crit;
725                 control = talloc(ctrl, struct ldb_sd_flags_control);
726                 control->secinfo_flags = secinfo_flags;
727                 ctrl->data = control;
728
729                 return ctrl;
730         }
731
732         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_SEARCH_OPTIONS_NAME) == 0) {
733                 struct ldb_search_options_control *control;
734                 const char *p;
735                 int crit, ret;
736                 unsigned search_options;
737
738                 p = &(control_strings[sizeof(LDB_CONTROL_SEARCH_OPTIONS_NAME)]);
739                 ret = sscanf(p, "%d:%u", &crit, &search_options);
740                 if ((ret != 2) || (crit < 0) || (crit > 1) || (search_options > 0xF)) {
741                         ldb_set_errstring(ldb,
742                                           "invalid search_options control syntax\n"
743                                           " syntax: crit(b):search_options(n)\n"
744                                           "   note: b = boolean, n = number");
745                         talloc_free(ctrl);
746                         return NULL;
747                 }
748
749                 ctrl->oid = LDB_CONTROL_SEARCH_OPTIONS_OID;
750                 ctrl->critical = crit;
751                 control = talloc(ctrl, struct ldb_search_options_control);
752                 control->search_options = search_options;
753                 ctrl->data = control;
754
755                 return ctrl;
756         }
757
758         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_BYPASS_OPERATIONAL_NAME) == 0) {
759                 const char *p;
760                 int crit, ret;
761
762                 p = &(control_strings[sizeof(LDB_CONTROL_BYPASS_OPERATIONAL_NAME)]);
763                 ret = sscanf(p, "%d", &crit);
764                 if ((ret != 1) || (crit < 0) || (crit > 1)) {
765                         ldb_set_errstring(ldb,
766                                           "invalid bypassopreational control syntax\n"
767                                           " syntax: crit(b)\n"
768                                           "   note: b = boolean");
769                         talloc_free(ctrl);
770                         return NULL;
771                 }
772
773                 ctrl->oid = LDB_CONTROL_BYPASS_OPERATIONAL_OID;
774                 ctrl->critical = crit;
775                 ctrl->data = NULL;
776
777                 return ctrl;
778         }
779
780         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_RELAX_NAME) == 0) {
781                 const char *p;
782                 int crit, ret;
783
784                 p = &(control_strings[sizeof(LDB_CONTROL_RELAX_NAME)]);
785                 ret = sscanf(p, "%d", &crit);
786                 if ((ret != 1) || (crit < 0) || (crit > 1)) {
787                         ldb_set_errstring(ldb,
788                                           "invalid relax control syntax\n"
789                                           " syntax: crit(b)\n"
790                                           "   note: b = boolean");
791                         talloc_free(ctrl);
792                         return NULL;
793                 }
794
795                 ctrl->oid = LDB_CONTROL_RELAX_OID;
796                 ctrl->critical = crit;
797                 ctrl->data = NULL;
798
799                 return ctrl;
800         }
801
802         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_RECALCULATE_SD_NAME) == 0) {
803                 const char *p;
804                 int crit, ret;
805
806                 p = &(control_strings[sizeof(LDB_CONTROL_RECALCULATE_SD_NAME)]);
807                 ret = sscanf(p, "%d", &crit);
808                 if ((ret != 1) || (crit < 0) || (crit > 1)) {
809                         ldb_set_errstring(ldb,
810                                           "invalid recalculate_sd control syntax\n"
811                                           " syntax: crit(b)\n"
812                                           "   note: b = boolean");
813                         talloc_free(ctrl);
814                         return NULL;
815                 }
816
817                 ctrl->oid = LDB_CONTROL_RECALCULATE_SD_OID;
818                 ctrl->critical = crit;
819                 ctrl->data = NULL;
820
821                 return ctrl;
822         }
823
824         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_DOMAIN_SCOPE_NAME) == 0) {
825                 const char *p;
826                 int crit, ret;
827
828                 p = &(control_strings[sizeof(LDB_CONTROL_DOMAIN_SCOPE_NAME)]);
829                 ret = sscanf(p, "%d", &crit);
830                 if ((ret != 1) || (crit < 0) || (crit > 1)) {
831                         ldb_set_errstring(ldb,
832                                           "invalid domain_scope control syntax\n"
833                                           " syntax: crit(b)\n"
834                                           "   note: b = boolean");
835                         talloc_free(ctrl);
836                         return NULL;
837                 }
838
839                 ctrl->oid = LDB_CONTROL_DOMAIN_SCOPE_OID;
840                 ctrl->critical = crit;
841                 ctrl->data = NULL;
842
843                 return ctrl;
844         }
845
846         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_PAGED_RESULTS_NAME) == 0) {
847                 struct ldb_paged_control *control;
848                 const char *p;
849                 char cookie[1024];
850                 int crit, size, ret;
851
852                 cookie[0] = '\0';
853                 p = &(control_strings[sizeof(LDB_CONTROL_PAGED_RESULTS_NAME)]);
854                 ret = sscanf(p, "%d:%d:%1023[^$]", &crit, &size, cookie);
855                 if ((ret < 2) || (ret > 3) || (crit < 0) || (crit > 1) ||
856                     (size < 0)) {
857                         ldb_set_errstring(ldb,
858                                 "invalid paged_results control syntax\n"
859                                 " syntax: crit(b):size(n)[:cookie(base64)]\n"
860                                 "   note: b = boolean, n = number");
861                         talloc_free(ctrl);
862                         return NULL;
863                 }
864
865                 ctrl->oid = LDB_CONTROL_PAGED_RESULTS_OID;
866                 ctrl->critical = crit;
867                 control = talloc(ctrl, struct ldb_paged_control);
868                 control->size = size;
869                 if (cookie[0] != '\0') {
870                         int len = ldb_base64_decode(cookie);
871                         if (len < 0) {
872                                 ldb_set_errstring(ldb,
873                                                   "invalid paged_results cookie"
874                                                   " (probably too long)\n");
875                                 talloc_free(ctrl);
876                                 return NULL;
877                         }
878                         control->cookie_len = len;
879                         control->cookie = talloc_memdup(control, cookie, control->cookie_len);
880                         if (control->cookie == NULL) {
881                                 ldb_oom(ldb);
882                                 return NULL;
883                         }
884                 } else {
885                         control->cookie = NULL;
886                         control->cookie_len = 0;
887                 }
888                 ctrl->data = control;
889
890                 return ctrl;
891         }
892
893         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_SERVER_SORT_NAME) == 0) {
894                 struct ldb_server_sort_control **control;
895                 const char *p;
896                 char attr[256];
897                 char rule[128];
898                 int crit, rev, ret;
899
900                 attr[0] = '\0';
901                 rule[0] = '\0';
902                 p = &(control_strings[sizeof(LDB_CONTROL_SERVER_SORT_NAME)]);
903                 ret = sscanf(p, "%d:%d:%255[^:]:%127[^:]", &crit, &rev, attr, rule);
904                 if ((ret < 3) || (crit < 0) || (crit > 1) || (rev < 0 ) || (rev > 1) ||attr[0] == '\0') {
905                         ldb_set_errstring(ldb,
906                                           "invalid server_sort control syntax\n"
907                                           " syntax: crit(b):rev(b):attr(s)[:rule(s)]\n"
908                                           "   note: b = boolean, s = string");
909                         talloc_free(ctrl);
910                         return NULL;
911                 }
912                 ctrl->oid = LDB_CONTROL_SERVER_SORT_OID;
913                 ctrl->critical = crit;
914                 control = talloc_array(ctrl, struct ldb_server_sort_control *, 2);
915                 control[0] = talloc(control, struct ldb_server_sort_control);
916                 control[0]->attributeName = talloc_strdup(control, attr);
917                 if (rule[0])
918                         control[0]->orderingRule = talloc_strdup(control, rule);
919                 else
920                         control[0]->orderingRule = NULL;
921                 control[0]->reverse = rev;
922                 control[1] = NULL;
923                 ctrl->data = control;
924
925                 return ctrl;
926         }
927
928         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_NOTIFICATION_NAME) == 0) {
929                 const char *p;
930                 int crit, ret;
931
932                 p = &(control_strings[sizeof(LDB_CONTROL_NOTIFICATION_NAME)]);
933                 ret = sscanf(p, "%d", &crit);
934                 if ((ret != 1) || (crit < 0) || (crit > 1)) {
935                         ldb_set_errstring(ldb,
936                                           "invalid notification control syntax\n"
937                                           " syntax: crit(b)\n"
938                                           "   note: b = boolean");
939                         talloc_free(ctrl);
940                         return NULL;
941                 }
942
943                 ctrl->oid = LDB_CONTROL_NOTIFICATION_OID;
944                 ctrl->critical = crit;
945                 ctrl->data = NULL;
946
947                 return ctrl;
948         }
949
950         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_TREE_DELETE_NAME) == 0) {
951                 const char *p;
952                 int crit, ret;
953
954                 p = &(control_strings[sizeof(LDB_CONTROL_TREE_DELETE_NAME)]);
955                 ret = sscanf(p, "%d", &crit);
956                 if ((ret != 1) || (crit < 0) || (crit > 1)) {
957                         ldb_set_errstring(ldb,
958                                           "invalid tree_delete control syntax\n"
959                                           " syntax: crit(b)\n"
960                                           "   note: b = boolean");
961                         talloc_free(ctrl);
962                         return NULL;
963                 }
964
965                 ctrl->oid = LDB_CONTROL_TREE_DELETE_OID;
966                 ctrl->critical = crit;
967                 ctrl->data = NULL;
968
969                 return ctrl;
970         }
971
972         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_SHOW_DELETED_NAME) == 0) {
973                 const char *p;
974                 int crit, ret;
975
976                 p = &(control_strings[sizeof(LDB_CONTROL_SHOW_DELETED_NAME)]);
977                 ret = sscanf(p, "%d", &crit);
978                 if ((ret != 1) || (crit < 0) || (crit > 1)) {
979                         ldb_set_errstring(ldb,
980                                           "invalid show_deleted control syntax\n"
981                                           " syntax: crit(b)\n"
982                                           "   note: b = boolean");
983                         talloc_free(ctrl);
984                         return NULL;
985                 }
986
987                 ctrl->oid = LDB_CONTROL_SHOW_DELETED_OID;
988                 ctrl->critical = crit;
989                 ctrl->data = NULL;
990
991                 return ctrl;
992         }
993
994         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_SHOW_DEACTIVATED_LINK_NAME) == 0) {
995                 const char *p;
996                 int crit, ret;
997
998                 p = &(control_strings[sizeof(LDB_CONTROL_SHOW_DEACTIVATED_LINK_NAME)]);
999                 ret = sscanf(p, "%d", &crit);
1000                 if ((ret != 1) || (crit < 0) || (crit > 1)) {
1001                         ldb_set_errstring(ldb,
1002                                           "invalid show_deactivated_link control syntax\n"
1003                                           " syntax: crit(b)\n"
1004                                           "   note: b = boolean");
1005                         talloc_free(ctrl);
1006                         return NULL;
1007                 }
1008
1009                 ctrl->oid = LDB_CONTROL_SHOW_DEACTIVATED_LINK_OID;
1010                 ctrl->critical = crit;
1011                 ctrl->data = NULL;
1012
1013                 return ctrl;
1014         }
1015
1016         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_SHOW_RECYCLED_NAME) == 0) {
1017                 const char *p;
1018                 int crit, ret;
1019
1020                 p = &(control_strings[sizeof(LDB_CONTROL_SHOW_RECYCLED_NAME)]);
1021                 ret = sscanf(p, "%d", &crit);
1022                 if ((ret != 1) || (crit < 0) || (crit > 1)) {
1023                         ldb_set_errstring(ldb,
1024                                           "invalid show_recycled control syntax\n"
1025                                           " syntax: crit(b)\n"
1026                                           "   note: b = boolean");
1027                         talloc_free(ctrl);
1028                         return NULL;
1029                 }
1030
1031                 ctrl->oid = LDB_CONTROL_SHOW_RECYCLED_OID;
1032                 ctrl->critical = crit;
1033                 ctrl->data = NULL;
1034
1035                 return ctrl;
1036         }
1037
1038         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_PERMISSIVE_MODIFY_NAME) == 0) {
1039                 const char *p;
1040                 int crit, ret;
1041
1042                 p = &(control_strings[sizeof(LDB_CONTROL_PERMISSIVE_MODIFY_NAME)]);
1043                 ret = sscanf(p, "%d", &crit);
1044                 if ((ret != 1) || (crit < 0) || (crit > 1)) {
1045                         ldb_set_errstring(ldb,
1046                                           "invalid permissive_modify control syntax\n"
1047                                           " syntax: crit(b)\n"
1048                                           "   note: b = boolean");
1049                         talloc_free(ctrl);
1050                         return NULL;
1051                 }
1052
1053                 ctrl->oid = LDB_CONTROL_PERMISSIVE_MODIFY_OID;
1054                 ctrl->critical = crit;
1055                 ctrl->data = NULL;
1056
1057                 return ctrl;
1058         }
1059
1060         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_REVEAL_INTERNALS_NAME) == 0) {
1061                 const char *p;
1062                 int crit, ret;
1063
1064                 p = &(control_strings[sizeof(LDB_CONTROL_REVEAL_INTERNALS_NAME)]);
1065                 ret = sscanf(p, "%d", &crit);
1066                 if ((ret != 1) || (crit < 0) || (crit > 1)) {
1067                         ldb_set_errstring(ldb,
1068                                           "invalid reveal_internals control syntax\n"
1069                                           " syntax: crit(b)\n"
1070                                           "   note: b = boolean");
1071                         talloc_free(ctrl);
1072                         return NULL;
1073                 }
1074
1075                 ctrl->oid = LDB_CONTROL_REVEAL_INTERNALS;
1076                 ctrl->critical = crit;
1077                 ctrl->data = NULL;
1078
1079                 return ctrl;
1080         }
1081
1082         if (strncmp(control_strings, "local_oid:", 10) == 0) {
1083                 const char *p;
1084                 int crit = 0, ret = 0;
1085                 char oid[256];
1086
1087                 oid[0] = '\0';
1088                 p = &(control_strings[10]);
1089                 ret = sscanf(p, "%255[^:]:%d", oid, &crit);
1090
1091                 if ((ret != 2) || strlen(oid) == 0 || (crit < 0) || (crit > 1)) {
1092                         ldb_set_errstring(ldb,
1093                                           "invalid local_oid control syntax\n"
1094                                           " syntax: oid(s):crit(b)\n"
1095                                           "   note: b = boolean, s = string");
1096                         talloc_free(ctrl);
1097                         return NULL;
1098                 }
1099
1100                 ctrl->oid = talloc_strdup(ctrl, oid);
1101                 if (!ctrl->oid) {
1102                         ldb_oom(ldb);
1103                         talloc_free(ctrl);
1104                         return NULL;
1105                 }
1106                 ctrl->critical = crit;
1107                 ctrl->data = NULL;
1108
1109                 return ctrl;
1110         }
1111
1112         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_RODC_DCPROMO_NAME) == 0) {
1113                 const char *p;
1114                 int crit, ret;
1115
1116                 p = &(control_strings[sizeof(LDB_CONTROL_RODC_DCPROMO_NAME)]);
1117                 ret = sscanf(p, "%d", &crit);
1118                 if ((ret != 1) || (crit < 0) || (crit > 1)) {
1119                         ldb_set_errstring(ldb,
1120                                           "invalid rodc_join control syntax\n"
1121                                           " syntax: crit(b)\n"
1122                                           "   note: b = boolean");
1123                         talloc_free(ctrl);
1124                         return NULL;
1125                 }
1126
1127                 ctrl->oid = LDB_CONTROL_RODC_DCPROMO_OID;
1128                 ctrl->critical = crit;
1129                 ctrl->data = NULL;
1130
1131                 return ctrl;
1132         }
1133
1134         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_PROVISION_NAME) == 0) {
1135                 const char *p;
1136                 int crit, ret;
1137
1138                 p = &(control_strings[sizeof(LDB_CONTROL_PROVISION_NAME)]);
1139                 ret = sscanf(p, "%d", &crit);
1140                 if ((ret != 1) || (crit < 0) || (crit > 1)) {
1141                         ldb_set_errstring(ldb,
1142                                           "invalid provision control syntax\n"
1143                                           " syntax: crit(b)\n"
1144                                           "   note: b = boolean");
1145                         talloc_free(ctrl);
1146                         return NULL;
1147                 }
1148
1149                 ctrl->oid = LDB_CONTROL_PROVISION_OID;
1150                 ctrl->critical = crit;
1151                 ctrl->data = NULL;
1152
1153                 return ctrl;
1154         }
1155         if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_VERIFY_NAME_NAME) == 0) {
1156                 const char *p;
1157                 char gc[1024];
1158                 int crit, flags, ret;
1159                 struct ldb_verify_name_control *control;
1160
1161                 gc[0] = '\0';
1162
1163                 p = &(control_strings[sizeof(LDB_CONTROL_VERIFY_NAME_NAME)]);
1164                 ret = sscanf(p, "%d:%d:%1023[^$]", &crit, &flags, gc);
1165                 if ((ret != 3) || (crit < 0) || (crit > 1)) {
1166                         ret = sscanf(p, "%d:%d", &crit, &flags);
1167                         if ((ret != 2) || (crit < 0) || (crit > 1)) {
1168                                 ldb_set_errstring(ldb,
1169                                                   "invalid verify_name control syntax\n"
1170                                                   " syntax: crit(b):flags(i)[:gc(s)]\n"
1171                                                   "   note: b = boolean"
1172                                                   "   note: i = integer"
1173                                                   "   note: s = string");
1174                                 talloc_free(ctrl);
1175                                 return NULL;
1176                         }
1177                 }
1178
1179                 ctrl->oid = LDB_CONTROL_VERIFY_NAME_OID;
1180                 ctrl->critical = crit;
1181                 control = talloc(ctrl, struct ldb_verify_name_control);
1182                 control->gc = talloc_strdup(control, gc);
1183                 control->gc_len = strlen(gc);
1184                 control->flags = flags;
1185                 ctrl->data = control;
1186                 return ctrl;
1187         }
1188         /*
1189          * When no matching control has been found.
1190          */
1191         return NULL;
1192 }
1193
1194 /* Parse controls from the format used on the command line and in ejs */
1195 struct ldb_control **ldb_parse_control_strings(struct ldb_context *ldb, TALLOC_CTX *mem_ctx, const char **control_strings)
1196 {
1197         unsigned int i;
1198         struct ldb_control **ctrl;
1199
1200         if (control_strings == NULL || control_strings[0] == NULL)
1201                 return NULL;
1202
1203         for (i = 0; control_strings[i]; i++);
1204
1205         ctrl = talloc_array(mem_ctx, struct ldb_control *, i + 1);
1206
1207         ldb_reset_err_string(ldb);
1208         for (i = 0; control_strings[i]; i++) {
1209                 ctrl[i] = ldb_parse_control_from_string(ldb, ctrl, control_strings[i]);
1210                 if (ctrl[i] == NULL) {
1211                         if (ldb_errstring(ldb) == NULL) {
1212                                 /* no controls matched, throw an error */
1213                                 ldb_asprintf_errstring(ldb, "Invalid control name: '%s'", control_strings[i]);
1214                         }
1215                         talloc_free(ctrl);
1216                         return NULL;
1217                 }
1218         }
1219
1220         ctrl[i] = NULL;
1221
1222         return ctrl;
1223 }
1224
1225