4 Copyright (C) Simo Sorce 2005
6 ** NOTE! The following LGPL license applies to the ldb
7 ** library. This does NOT imply that all of Samba is released
10 This library is free software; you can redistribute it and/or
11 modify it under the terms of the GNU Lesser General Public
12 License as published by the Free Software Foundation; either
13 version 3 of the License, or (at your option) any later version.
15 This library is distributed in the hope that it will be useful,
16 but WITHOUT ANY WARRANTY; without even the implied warranty of
17 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
18 Lesser General Public License for more details.
20 You should have received a copy of the GNU Lesser General Public
21 License along with this library; if not, see <http://www.gnu.org/licenses/>.
25 * Name: ldb_controls.c
27 * Component: ldb controls utility functions
29 * Description: helper functions for control modules
34 #include "ldb_private.h"
36 /* check if a control with the specified "oid" exist and return it */
37 /* returns NULL if not found */
38 struct ldb_control *ldb_request_get_control(struct ldb_request *req, const char *oid)
42 if (req->controls != NULL) {
43 for (i = 0; req->controls[i]; i++) {
44 if (req->controls[i]->oid && strcmp(oid, req->controls[i]->oid) == 0) {
49 return req->controls[i];
55 /* check if a control with the specified "oid" exist and return it */
56 /* returns NULL if not found */
57 struct ldb_control *ldb_reply_get_control(struct ldb_reply *rep, const char *oid)
61 if (rep->controls != NULL) {
62 for (i = 0; rep->controls[i]; i++) {
63 if (rep->controls[i]->oid && strcmp(oid, rep->controls[i]->oid) == 0) {
68 return rep->controls[i];
75 * Saves the current controls list into the "saver" (can also be NULL) and
76 * replace the one in "req" with a new one excluding the "exclude" control
77 * (if it is NULL then the list remains the same)
81 int ldb_save_controls(struct ldb_control *exclude, struct ldb_request *req, struct ldb_control ***saver)
83 struct ldb_control **lcs, **lcs_old;
86 lcs_old = req->controls;
91 for (i = 0; req->controls && req->controls[i]; i++);
97 lcs = talloc_array(req, struct ldb_control *, i + 1);
102 for (i = 0, j = 0; lcs_old[i]; i++) {
103 if (exclude == lcs_old[i]) continue;
109 req->controls = talloc_realloc(req, lcs, struct ldb_control *, j + 1);
110 if (req->controls == NULL) {
117 * Returns a list of controls, except the one specified with "exclude" (can
118 * also be NULL). Included controls become a child of returned list if they
119 * were children of "controls_in".
121 * Returns NULL on error (OOM) or an empty control list.
123 struct ldb_control **ldb_controls_except_specified(struct ldb_control **controls_in,
125 struct ldb_control *exclude)
127 struct ldb_control **lcs = NULL;
128 unsigned int i, j, n;
130 for (i = 0; controls_in && controls_in[i]; i++);
136 for (i = 0, j = 0; controls_in && controls_in[i]; i++) {
137 if (exclude == controls_in[i]) continue;
140 /* Allocate here so if we remove the only
141 * control, or there were no controls, we
142 * don't allocate at all, and just return
144 lcs = talloc_array(mem_ctx, struct ldb_control *,
151 lcs[j] = controls_in[i];
152 talloc_reparent(controls_in, lcs, lcs[j]);
158 lcs = talloc_realloc(mem_ctx, lcs, struct ldb_control *, j + 1);
164 /* check if there's any control marked as critical in the list */
165 /* return True if any, False if none */
166 int ldb_check_critical_controls(struct ldb_control **controls)
170 if (controls == NULL) {
174 for (i = 0; controls[i]; i++) {
175 if (controls[i]->critical) {
183 int ldb_request_add_control(struct ldb_request *req, const char *oid, bool critical, void *data)
186 struct ldb_control **ctrls;
187 struct ldb_control *ctrl;
189 for (n=0; req->controls && req->controls[n];n++) {
190 /* having two controls of the same OID makes no sense */
191 if (req->controls[n]->oid && strcmp(oid, req->controls[n]->oid) == 0) {
192 return LDB_ERR_ATTRIBUTE_OR_VALUE_EXISTS;
196 ctrls = talloc_array(req,
197 struct ldb_control *,
199 if (!ctrls) return LDB_ERR_OPERATIONS_ERROR;
201 for (i=0; i<n; i++) {
202 ctrls[i] = req->controls[i];
205 req->controls = ctrls;
209 ctrl = talloc(ctrls, struct ldb_control);
210 if (!ctrl) return LDB_ERR_OPERATIONS_ERROR;
212 ctrl->oid = talloc_strdup(ctrl, oid);
213 if (!ctrl->oid) return LDB_ERR_OPERATIONS_ERROR;
214 ctrl->critical = critical;
221 int ldb_reply_add_control(struct ldb_reply *ares, const char *oid, bool critical, void *data)
224 struct ldb_control **ctrls;
225 struct ldb_control *ctrl;
227 for (n=0; ares->controls && ares->controls[n];) {
228 /* having two controls of the same OID makes no sense */
229 if (ares->controls[n]->oid && strcmp(oid, ares->controls[n]->oid) == 0) {
230 return LDB_ERR_ATTRIBUTE_OR_VALUE_EXISTS;
235 ctrls = talloc_realloc(ares, ares->controls,
236 struct ldb_control *,
238 if (!ctrls) return LDB_ERR_OPERATIONS_ERROR;
239 ares->controls = ctrls;
243 ctrl = talloc(ctrls, struct ldb_control);
244 if (!ctrl) return LDB_ERR_OPERATIONS_ERROR;
246 ctrl->oid = talloc_strdup(ctrl, oid);
247 if (!ctrl->oid) return LDB_ERR_OPERATIONS_ERROR;
248 ctrl->critical = critical;
255 /* Add a control to the request, replacing the old one if it is already in the request */
256 int ldb_request_replace_control(struct ldb_request *req, const char *oid, bool critical, void *data)
261 ret = ldb_request_add_control(req, oid, critical, data);
262 if (ret != LDB_ERR_ATTRIBUTE_OR_VALUE_EXISTS) {
266 for (n=0; req->controls[n];n++) {
267 if (req->controls[n]->oid && strcmp(oid, req->controls[n]->oid) == 0) {
268 req->controls[n]->critical = critical;
269 req->controls[n]->data = data;
274 return LDB_ERR_OPERATIONS_ERROR;
278 * Return a control as string
279 * the project (ie. name:value1:value2:...:valuen
280 * The string didn't include the criticity of the critical flag
282 char *ldb_control_to_string(TALLOC_CTX *mem_ctx, const struct ldb_control *control)
286 if (strcmp(control->oid, LDB_CONTROL_PAGED_RESULTS_OID) == 0) {
287 struct ldb_paged_control *rep_control = talloc_get_type(control->data, struct ldb_paged_control);
290 cookie = ldb_base64_encode(mem_ctx, rep_control->cookie, rep_control->cookie_len);
291 if (cookie == NULL) {
294 if (cookie[0] != '\0') {
295 res = talloc_asprintf(mem_ctx, "%s:%d:%s",
296 LDB_CONTROL_PAGED_RESULTS_NAME,
302 res = talloc_asprintf(mem_ctx, "%s:%d",
303 LDB_CONTROL_PAGED_RESULTS_NAME,
309 if (strcmp(control->oid, LDB_CONTROL_VLV_RESP_OID) == 0) {
310 struct ldb_vlv_resp_control *rep_control = talloc_get_type(control->data,
311 struct ldb_vlv_resp_control);
313 res = talloc_asprintf(mem_ctx, "%s:%d:%d:%d:%d:%d:%s",
314 LDB_CONTROL_VLV_RESP_NAME,
316 rep_control->targetPosition,
317 rep_control->contentCount,
318 rep_control->vlv_result,
319 rep_control->ctxid_len,
320 rep_control->contextId);
325 if (strcmp(control->oid, LDB_CONTROL_SORT_RESP_OID) == 0) {
326 struct ldb_sort_resp_control *rep_control = talloc_get_type(control->data,
327 struct ldb_sort_resp_control);
329 res = talloc_asprintf(mem_ctx, "%s:%d:%d:%s",
330 LDB_CONTROL_SORT_RESP_NAME,
333 rep_control->attr_desc);
338 if (strcmp(control->oid, LDB_CONTROL_ASQ_OID) == 0) {
339 struct ldb_asq_control *rep_control = talloc_get_type(control->data,
340 struct ldb_asq_control);
342 res = talloc_asprintf(mem_ctx, "%s:%d:%d",
343 LDB_CONTROL_SORT_RESP_NAME,
345 rep_control->result);
350 if (strcmp(control->oid, LDB_CONTROL_DIRSYNC_OID) == 0) {
352 struct ldb_dirsync_control *rep_control = talloc_get_type(control->data,
353 struct ldb_dirsync_control);
355 cookie = ldb_base64_encode(mem_ctx, rep_control->cookie,
356 rep_control->cookie_len);
357 if (cookie == NULL) {
360 res = talloc_asprintf(mem_ctx, "%s:%d:%d:%d:%s",
361 LDB_CONTROL_DIRSYNC_NAME,
364 rep_control->max_attributes,
370 if (strcmp(control->oid, LDB_CONTROL_DIRSYNC_EX_OID) == 0) {
372 struct ldb_dirsync_control *rep_control = talloc_get_type(control->data,
373 struct ldb_dirsync_control);
375 cookie = ldb_base64_encode(mem_ctx, rep_control->cookie,
376 rep_control->cookie_len);
377 if (cookie == NULL) {
380 res = talloc_asprintf(mem_ctx, "%s:%d:%d:%d:%s",
381 LDB_CONTROL_DIRSYNC_EX_NAME,
384 rep_control->max_attributes,
391 if (strcmp(control->oid, LDB_CONTROL_VERIFY_NAME_OID) == 0) {
392 struct ldb_verify_name_control *rep_control = talloc_get_type(control->data, struct ldb_verify_name_control);
394 if (rep_control->gc != NULL) {
395 res = talloc_asprintf(mem_ctx, "%s:%d:%d:%s",
396 LDB_CONTROL_VERIFY_NAME_NAME,
402 res = talloc_asprintf(mem_ctx, "%s:%d:%d",
403 LDB_CONTROL_VERIFY_NAME_NAME,
411 * From here we don't know the control
413 if (control->data == NULL) {
415 * We don't know the control but there is no real data attached
416 * to it so we can represent it with local_oid:oid:criticity.
418 res = talloc_asprintf(mem_ctx, "local_oid:%s:%d",
422 res = talloc_asprintf(mem_ctx, "unknown oid:%s",
430 * A little trick to allow one to use constants defined in headers rather than
431 * hardwritten in the file.
432 * "sizeof" will return the \0 char as well so it will take the place of ":"
433 * in the length of the string.
435 #define LDB_CONTROL_CMP(control, NAME) strncmp(control, NAME ":", sizeof(NAME))
437 /* Parse one string and return associated control if parsing is successful*/
438 struct ldb_control *ldb_parse_control_from_string(struct ldb_context *ldb, TALLOC_CTX *mem_ctx, const char *control_strings)
440 struct ldb_control *ctrl;
441 char *error_string = NULL;
443 if (!(ctrl = talloc(mem_ctx, struct ldb_control))) {
448 if (LDB_CONTROL_CMP(control_strings,
449 LDB_CONTROL_VLV_REQ_NAME) == 0) {
450 struct ldb_vlv_req_control *control;
454 int crit, bc, ac, os, cc, ret;
458 p = &(control_strings[sizeof(LDB_CONTROL_VLV_REQ_NAME)]);
459 ret = sscanf(p, "%d:%d:%d:%d:%d:%1023[^$]", &crit, &bc, &ac, &os, &cc, ctxid);
461 ret = sscanf(p, "%d:%d:%d:%1023[^:]:%1023[^$]", &crit, &bc, &ac, attr, ctxid);
464 if ((ret < 4) || (crit < 0) || (crit > 1)) {
465 error_string = talloc_asprintf(mem_ctx, "invalid server_sort control syntax\n");
466 error_string = talloc_asprintf_append(error_string, " syntax: crit(b):bc(n):ac(n):<os(n):cc(n)|attr(s)>[:ctxid(o)]\n");
467 error_string = talloc_asprintf_append(error_string, " note: b = boolean, n = number, s = string, o = b64 binary blob");
468 ldb_set_errstring(ldb, error_string);
469 talloc_free(error_string);
473 ctrl->oid = LDB_CONTROL_VLV_REQ_OID;
474 ctrl->critical = crit;
475 if (!(control = talloc(ctrl,
476 struct ldb_vlv_req_control))) {
481 control->beforeCount = bc;
482 control->afterCount = ac;
485 control->match.gtOrEq.value = talloc_strdup(control, attr);
486 control->match.gtOrEq.value_len = strlen(attr);
489 control->match.byOffset.offset = os;
490 control->match.byOffset.contentCount = cc;
493 control->ctxid_len = ldb_base64_decode(ctxid);
494 control->contextId = (char *)talloc_memdup(control, ctxid, control->ctxid_len);
496 control->ctxid_len = 0;
497 control->contextId = NULL;
499 ctrl->data = control;
504 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_DIRSYNC_NAME) == 0) {
505 struct ldb_dirsync_control *control;
508 int crit, max_attrs, ret;
512 p = &(control_strings[sizeof(LDB_CONTROL_DIRSYNC_NAME)]);
513 ret = sscanf(p, "%d:%u:%d:%1023[^$]", &crit, &flags, &max_attrs, cookie);
515 if ((ret < 3) || (crit < 0) || (crit > 1) || (max_attrs < 0)) {
516 error_string = talloc_asprintf(mem_ctx, "invalid dirsync control syntax\n");
517 error_string = talloc_asprintf_append(error_string, " syntax: crit(b):flags(n):max_attrs(n)[:cookie(o)]\n");
518 error_string = talloc_asprintf_append(error_string, " note: b = boolean, n = number, o = b64 binary blob");
519 ldb_set_errstring(ldb, error_string);
520 talloc_free(error_string);
525 /* w2k3 seems to ignore the parameter,
526 * but w2k sends a wrong cookie when this value is to small
527 * this would cause looping forever, while getting
528 * the same data and same cookie forever
530 if (max_attrs == 0) max_attrs = 0x0FFFFFFF;
532 ctrl->oid = LDB_CONTROL_DIRSYNC_OID;
533 ctrl->critical = crit;
534 control = talloc(ctrl, struct ldb_dirsync_control);
535 control->flags = flags;
536 control->max_attributes = max_attrs;
538 control->cookie_len = ldb_base64_decode(cookie);
539 control->cookie = (char *)talloc_memdup(control, cookie, control->cookie_len);
541 control->cookie = NULL;
542 control->cookie_len = 0;
544 ctrl->data = control;
548 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_DIRSYNC_EX_NAME) == 0) {
549 struct ldb_dirsync_control *control;
552 int crit, max_attrs, ret;
556 p = &(control_strings[sizeof(LDB_CONTROL_DIRSYNC_EX_NAME)]);
557 ret = sscanf(p, "%d:%u:%d:%1023[^$]", &crit, &flags, &max_attrs, cookie);
559 if ((ret < 3) || (crit < 0) || (crit > 1) || (max_attrs < 0)) {
560 error_string = talloc_asprintf(mem_ctx, "invalid %s control syntax\n",
561 LDB_CONTROL_DIRSYNC_EX_NAME);
562 error_string = talloc_asprintf_append(error_string, " syntax: crit(b):flags(n):max_attrs(n)[:cookie(o)]\n");
563 error_string = talloc_asprintf_append(error_string, " note: b = boolean, n = number, o = b64 binary blob");
564 ldb_set_errstring(ldb, error_string);
565 talloc_free(error_string);
570 /* w2k3 seems to ignore the parameter,
571 * but w2k sends a wrong cookie when this value is to small
572 * this would cause looping forever, while getting
573 * the same data and same cookie forever
575 if (max_attrs == 0) max_attrs = 0x0FFFFFFF;
577 ctrl->oid = LDB_CONTROL_DIRSYNC_EX_OID;
578 ctrl->critical = crit;
579 control = talloc(ctrl, struct ldb_dirsync_control);
580 control->flags = flags;
581 control->max_attributes = max_attrs;
583 control->cookie_len = ldb_base64_decode(cookie);
584 control->cookie = (char *)talloc_memdup(control, cookie, control->cookie_len);
586 control->cookie = NULL;
587 control->cookie_len = 0;
589 ctrl->data = control;
594 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_ASQ_NAME) == 0) {
595 struct ldb_asq_control *control;
601 p = &(control_strings[sizeof(LDB_CONTROL_ASQ_NAME)]);
602 ret = sscanf(p, "%d:%255[^$]", &crit, attr);
603 if ((ret != 2) || (crit < 0) || (crit > 1) || (attr[0] == '\0')) {
604 error_string = talloc_asprintf(mem_ctx, "invalid asq control syntax\n");
605 error_string = talloc_asprintf_append(error_string, " syntax: crit(b):attr(s)\n");
606 error_string = talloc_asprintf_append(error_string, " note: b = boolean, s = string");
607 ldb_set_errstring(ldb, error_string);
608 talloc_free(error_string);
613 ctrl->oid = LDB_CONTROL_ASQ_OID;
614 ctrl->critical = crit;
615 control = talloc(ctrl, struct ldb_asq_control);
616 control->request = 1;
617 control->source_attribute = talloc_strdup(control, attr);
618 control->src_attr_len = strlen(attr);
619 ctrl->data = control;
624 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_EXTENDED_DN_NAME) == 0) {
625 struct ldb_extended_dn_control *control;
629 p = &(control_strings[sizeof(LDB_CONTROL_EXTENDED_DN_NAME)]);
630 ret = sscanf(p, "%d:%d", &crit, &type);
631 if ((ret != 2) || (crit < 0) || (crit > 1) || (type < 0) || (type > 1)) {
632 ret = sscanf(p, "%d", &crit);
633 if ((ret != 1) || (crit < 0) || (crit > 1)) {
634 error_string = talloc_asprintf(mem_ctx, "invalid extended_dn control syntax\n");
635 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)[:type(i)]\n");
636 error_string = talloc_asprintf_append(error_string, " note: b = boolean\n");
637 error_string = talloc_asprintf_append(error_string, " i = integer\n");
638 error_string = talloc_asprintf_append(error_string, " valid values are: 0 - hexadecimal representation\n");
639 error_string = talloc_asprintf_append(error_string, " 1 - normal string representation");
640 ldb_set_errstring(ldb, error_string);
641 talloc_free(error_string);
647 control = talloc(ctrl, struct ldb_extended_dn_control);
648 control->type = type;
651 ctrl->oid = LDB_CONTROL_EXTENDED_DN_OID;
652 ctrl->critical = crit;
653 ctrl->data = talloc_steal(ctrl, control);
658 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_SD_FLAGS_NAME) == 0) {
659 struct ldb_sd_flags_control *control;
662 unsigned secinfo_flags;
664 p = &(control_strings[sizeof(LDB_CONTROL_SD_FLAGS_NAME)]);
665 ret = sscanf(p, "%d:%u", &crit, &secinfo_flags);
666 if ((ret != 2) || (crit < 0) || (crit > 1) || (secinfo_flags > 0xF)) {
667 error_string = talloc_asprintf(mem_ctx, "invalid sd_flags control syntax\n");
668 error_string = talloc_asprintf_append(error_string, " syntax: crit(b):secinfo_flags(n)\n");
669 error_string = talloc_asprintf_append(error_string, " note: b = boolean, n = number");
670 ldb_set_errstring(ldb, error_string);
671 talloc_free(error_string);
676 ctrl->oid = LDB_CONTROL_SD_FLAGS_OID;
677 ctrl->critical = crit;
678 control = talloc(ctrl, struct ldb_sd_flags_control);
679 control->secinfo_flags = secinfo_flags;
680 ctrl->data = control;
685 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_SEARCH_OPTIONS_NAME) == 0) {
686 struct ldb_search_options_control *control;
689 unsigned search_options;
691 p = &(control_strings[sizeof(LDB_CONTROL_SEARCH_OPTIONS_NAME)]);
692 ret = sscanf(p, "%d:%u", &crit, &search_options);
693 if ((ret != 2) || (crit < 0) || (crit > 1) || (search_options > 0xF)) {
694 error_string = talloc_asprintf(mem_ctx, "invalid search_options control syntax\n");
695 error_string = talloc_asprintf_append(error_string, " syntax: crit(b):search_options(n)\n");
696 error_string = talloc_asprintf_append(error_string, " note: b = boolean, n = number");
697 ldb_set_errstring(ldb, error_string);
698 talloc_free(error_string);
703 ctrl->oid = LDB_CONTROL_SEARCH_OPTIONS_OID;
704 ctrl->critical = crit;
705 control = talloc(ctrl, struct ldb_search_options_control);
706 control->search_options = search_options;
707 ctrl->data = control;
712 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_BYPASS_OPERATIONAL_NAME) == 0) {
716 p = &(control_strings[sizeof(LDB_CONTROL_BYPASS_OPERATIONAL_NAME)]);
717 ret = sscanf(p, "%d", &crit);
718 if ((ret != 1) || (crit < 0) || (crit > 1)) {
719 error_string = talloc_asprintf(mem_ctx, "invalid bypassopreational control syntax\n");
720 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)\n");
721 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
722 ldb_set_errstring(ldb, error_string);
723 talloc_free(error_string);
728 ctrl->oid = LDB_CONTROL_BYPASS_OPERATIONAL_OID;
729 ctrl->critical = crit;
735 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_RELAX_NAME) == 0) {
739 p = &(control_strings[sizeof(LDB_CONTROL_RELAX_NAME)]);
740 ret = sscanf(p, "%d", &crit);
741 if ((ret != 1) || (crit < 0) || (crit > 1)) {
742 error_string = talloc_asprintf(mem_ctx, "invalid relax control syntax\n");
743 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)\n");
744 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
745 ldb_set_errstring(ldb, error_string);
746 talloc_free(error_string);
751 ctrl->oid = LDB_CONTROL_RELAX_OID;
752 ctrl->critical = crit;
758 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_RECALCULATE_SD_NAME) == 0) {
762 p = &(control_strings[sizeof(LDB_CONTROL_RECALCULATE_SD_NAME)]);
763 ret = sscanf(p, "%d", &crit);
764 if ((ret != 1) || (crit < 0) || (crit > 1)) {
765 error_string = talloc_asprintf(mem_ctx, "invalid recalculate_sd control syntax\n");
766 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)\n");
767 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
768 ldb_set_errstring(ldb, error_string);
769 talloc_free(error_string);
774 ctrl->oid = LDB_CONTROL_RECALCULATE_SD_OID;
775 ctrl->critical = crit;
781 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_DOMAIN_SCOPE_NAME) == 0) {
785 p = &(control_strings[sizeof(LDB_CONTROL_DOMAIN_SCOPE_NAME)]);
786 ret = sscanf(p, "%d", &crit);
787 if ((ret != 1) || (crit < 0) || (crit > 1)) {
788 error_string = talloc_asprintf(mem_ctx, "invalid domain_scope control syntax\n");
789 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)\n");
790 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
791 ldb_set_errstring(ldb, error_string);
792 talloc_free(error_string);
797 ctrl->oid = LDB_CONTROL_DOMAIN_SCOPE_OID;
798 ctrl->critical = crit;
804 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_PAGED_RESULTS_NAME) == 0) {
805 struct ldb_paged_control *control;
809 p = &(control_strings[sizeof(LDB_CONTROL_PAGED_RESULTS_NAME)]);
810 ret = sscanf(p, "%d:%d", &crit, &size);
811 if ((ret != 2) || (crit < 0) || (crit > 1) || (size < 0)) {
812 error_string = talloc_asprintf(mem_ctx, "invalid paged_results control syntax\n");
813 error_string = talloc_asprintf_append(error_string, " syntax: crit(b):size(n)\n");
814 error_string = talloc_asprintf_append(error_string, " note: b = boolean, n = number");
815 ldb_set_errstring(ldb, error_string);
816 talloc_free(error_string);
821 ctrl->oid = LDB_CONTROL_PAGED_RESULTS_OID;
822 ctrl->critical = crit;
823 control = talloc(ctrl, struct ldb_paged_control);
824 control->size = size;
825 control->cookie = NULL;
826 control->cookie_len = 0;
827 ctrl->data = control;
832 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_SERVER_SORT_NAME) == 0) {
833 struct ldb_server_sort_control **control;
841 p = &(control_strings[sizeof(LDB_CONTROL_SERVER_SORT_NAME)]);
842 ret = sscanf(p, "%d:%d:%255[^:]:%127[^:]", &crit, &rev, attr, rule);
843 if ((ret < 3) || (crit < 0) || (crit > 1) || (rev < 0 ) || (rev > 1) ||attr[0] == '\0') {
844 error_string = talloc_asprintf(mem_ctx, "invalid server_sort control syntax\n");
845 error_string = talloc_asprintf_append(error_string, " syntax: crit(b):rev(b):attr(s)[:rule(s)]\n");
846 error_string = talloc_asprintf_append(error_string, " note: b = boolean, s = string");
847 ldb_set_errstring(ldb, error_string);
848 talloc_free(error_string);
852 ctrl->oid = LDB_CONTROL_SERVER_SORT_OID;
853 ctrl->critical = crit;
854 control = talloc_array(ctrl, struct ldb_server_sort_control *, 2);
855 control[0] = talloc(control, struct ldb_server_sort_control);
856 control[0]->attributeName = talloc_strdup(control, attr);
858 control[0]->orderingRule = talloc_strdup(control, rule);
860 control[0]->orderingRule = NULL;
861 control[0]->reverse = rev;
863 ctrl->data = control;
868 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_NOTIFICATION_NAME) == 0) {
872 p = &(control_strings[sizeof(LDB_CONTROL_NOTIFICATION_NAME)]);
873 ret = sscanf(p, "%d", &crit);
874 if ((ret != 1) || (crit < 0) || (crit > 1)) {
875 error_string = talloc_asprintf(mem_ctx, "invalid notification control syntax\n");
876 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)\n");
877 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
878 ldb_set_errstring(ldb, error_string);
879 talloc_free(error_string);
884 ctrl->oid = LDB_CONTROL_NOTIFICATION_OID;
885 ctrl->critical = crit;
891 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_TREE_DELETE_NAME) == 0) {
895 p = &(control_strings[sizeof(LDB_CONTROL_TREE_DELETE_NAME)]);
896 ret = sscanf(p, "%d", &crit);
897 if ((ret != 1) || (crit < 0) || (crit > 1)) {
898 error_string = talloc_asprintf(mem_ctx, "invalid tree_delete control syntax\n");
899 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)\n");
900 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
901 ldb_set_errstring(ldb, error_string);
902 talloc_free(error_string);
907 ctrl->oid = LDB_CONTROL_TREE_DELETE_OID;
908 ctrl->critical = crit;
914 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_SHOW_DELETED_NAME) == 0) {
918 p = &(control_strings[sizeof(LDB_CONTROL_SHOW_DELETED_NAME)]);
919 ret = sscanf(p, "%d", &crit);
920 if ((ret != 1) || (crit < 0) || (crit > 1)) {
921 error_string = talloc_asprintf(mem_ctx, "invalid show_deleted control syntax\n");
922 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)\n");
923 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
924 ldb_set_errstring(ldb, error_string);
925 talloc_free(error_string);
930 ctrl->oid = LDB_CONTROL_SHOW_DELETED_OID;
931 ctrl->critical = crit;
937 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_SHOW_DEACTIVATED_LINK_NAME) == 0) {
941 p = &(control_strings[sizeof(LDB_CONTROL_SHOW_DEACTIVATED_LINK_NAME)]);
942 ret = sscanf(p, "%d", &crit);
943 if ((ret != 1) || (crit < 0) || (crit > 1)) {
944 error_string = talloc_asprintf(mem_ctx, "invalid show_deactivated_link control syntax\n");
945 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)\n");
946 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
947 ldb_set_errstring(ldb, error_string);
948 talloc_free(error_string);
953 ctrl->oid = LDB_CONTROL_SHOW_DEACTIVATED_LINK_OID;
954 ctrl->critical = crit;
960 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_SHOW_RECYCLED_NAME) == 0) {
964 p = &(control_strings[sizeof(LDB_CONTROL_SHOW_RECYCLED_NAME)]);
965 ret = sscanf(p, "%d", &crit);
966 if ((ret != 1) || (crit < 0) || (crit > 1)) {
967 error_string = talloc_asprintf(mem_ctx, "invalid show_recycled control syntax\n");
968 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)\n");
969 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
970 ldb_set_errstring(ldb, error_string);
971 talloc_free(error_string);
976 ctrl->oid = LDB_CONTROL_SHOW_RECYCLED_OID;
977 ctrl->critical = crit;
983 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_PERMISSIVE_MODIFY_NAME) == 0) {
987 p = &(control_strings[sizeof(LDB_CONTROL_PERMISSIVE_MODIFY_NAME)]);
988 ret = sscanf(p, "%d", &crit);
989 if ((ret != 1) || (crit < 0) || (crit > 1)) {
990 error_string = talloc_asprintf(mem_ctx, "invalid permissive_modify control syntax\n");
991 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)\n");
992 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
993 ldb_set_errstring(ldb, error_string);
994 talloc_free(error_string);
999 ctrl->oid = LDB_CONTROL_PERMISSIVE_MODIFY_OID;
1000 ctrl->critical = crit;
1006 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_REVEAL_INTERNALS_NAME) == 0) {
1010 p = &(control_strings[sizeof(LDB_CONTROL_REVEAL_INTERNALS_NAME)]);
1011 ret = sscanf(p, "%d", &crit);
1012 if ((ret != 1) || (crit < 0) || (crit > 1)) {
1013 error_string = talloc_asprintf(mem_ctx, "invalid reveal_internals control syntax\n");
1014 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)\n");
1015 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
1016 ldb_set_errstring(ldb, error_string);
1017 talloc_free(error_string);
1022 ctrl->oid = LDB_CONTROL_REVEAL_INTERNALS;
1023 ctrl->critical = crit;
1029 if (strncmp(control_strings, "local_oid:", 10) == 0) {
1031 int crit = 0, ret = 0;
1035 p = &(control_strings[10]);
1036 ret = sscanf(p, "%255[^:]:%d", oid, &crit);
1038 if ((ret != 2) || strlen(oid) == 0 || (crit < 0) || (crit > 1)) {
1039 error_string = talloc_asprintf(mem_ctx, "invalid local_oid control syntax\n");
1040 error_string = talloc_asprintf_append(error_string, " syntax: oid(s):crit(b)\n");
1041 error_string = talloc_asprintf_append(error_string, " note: b = boolean, s = string");
1042 ldb_set_errstring(ldb, error_string);
1043 talloc_free(error_string);
1048 ctrl->oid = talloc_strdup(ctrl, oid);
1054 ctrl->critical = crit;
1060 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_RODC_DCPROMO_NAME) == 0) {
1064 p = &(control_strings[sizeof(LDB_CONTROL_RODC_DCPROMO_NAME)]);
1065 ret = sscanf(p, "%d", &crit);
1066 if ((ret != 1) || (crit < 0) || (crit > 1)) {
1067 error_string = talloc_asprintf(mem_ctx, "invalid rodc_join control syntax\n");
1068 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)\n");
1069 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
1070 ldb_set_errstring(ldb, error_string);
1071 talloc_free(error_string);
1076 ctrl->oid = LDB_CONTROL_RODC_DCPROMO_OID;
1077 ctrl->critical = crit;
1083 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_PROVISION_NAME) == 0) {
1087 p = &(control_strings[sizeof(LDB_CONTROL_PROVISION_NAME)]);
1088 ret = sscanf(p, "%d", &crit);
1089 if ((ret != 1) || (crit < 0) || (crit > 1)) {
1090 error_string = talloc_asprintf(mem_ctx, "invalid provision control syntax\n");
1091 error_string = talloc_asprintf_append(error_string, " syntax: crit(b)\n");
1092 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
1093 ldb_set_errstring(ldb, error_string);
1094 talloc_free(error_string);
1099 ctrl->oid = LDB_CONTROL_PROVISION_OID;
1100 ctrl->critical = crit;
1105 if (LDB_CONTROL_CMP(control_strings, LDB_CONTROL_VERIFY_NAME_NAME) == 0) {
1108 int crit, flags, ret;
1109 struct ldb_verify_name_control *control;
1113 p = &(control_strings[sizeof(LDB_CONTROL_VERIFY_NAME_NAME)]);
1114 ret = sscanf(p, "%d:%d:%1023[^$]", &crit, &flags, gc);
1115 if ((ret != 3) || (crit < 0) || (crit > 1)) {
1116 ret = sscanf(p, "%d:%d", &crit, &flags);
1117 if ((ret != 2) || (crit < 0) || (crit > 1)) {
1118 error_string = talloc_asprintf(mem_ctx, "invalid verify_name control syntax\n");
1119 error_string = talloc_asprintf_append(error_string, " syntax: crit(b):flags(i)[:gc(s)]\n");
1120 error_string = talloc_asprintf_append(error_string, " note: b = boolean");
1121 error_string = talloc_asprintf_append(error_string, " note: i = integer");
1122 error_string = talloc_asprintf_append(error_string, " note: s = string");
1123 ldb_set_errstring(ldb, error_string);
1124 talloc_free(error_string);
1130 ctrl->oid = LDB_CONTROL_VERIFY_NAME_OID;
1131 ctrl->critical = crit;
1132 control = talloc(ctrl, struct ldb_verify_name_control);
1133 control->gc = talloc_strdup(control, gc);
1134 control->gc_len = strlen(gc);
1135 control->flags = flags;
1136 ctrl->data = control;
1140 * When no matching control has been found.
1145 /* Parse controls from the format used on the command line and in ejs */
1146 struct ldb_control **ldb_parse_control_strings(struct ldb_context *ldb, TALLOC_CTX *mem_ctx, const char **control_strings)
1149 struct ldb_control **ctrl;
1151 if (control_strings == NULL || control_strings[0] == NULL)
1154 for (i = 0; control_strings[i]; i++);
1156 ctrl = talloc_array(mem_ctx, struct ldb_control *, i + 1);
1158 ldb_reset_err_string(ldb);
1159 for (i = 0; control_strings[i]; i++) {
1160 ctrl[i] = ldb_parse_control_from_string(ldb, ctrl, control_strings[i]);
1161 if (ctrl[i] == NULL) {
1162 if (ldb_errstring(ldb) == NULL) {
1163 /* no controls matched, throw an error */
1164 ldb_asprintf_errstring(ldb, "Invalid control name: '%s'", control_strings[i]);