s4:ldb - SQLite: port some constraints from the TDB backend also to the SQLITE one
[ira/wip.git] / source4 / lib / ldb / ldb_sqlite3 / ldb_sqlite3.c
index 6dfaa0627b80f802adcca11978cc695a4fbbed05..7e420e4ceb07571b04d23fac672c0a70400b5809 100644 (file)
@@ -1,25 +1,25 @@
-/* 
+/*
    ldb database library
-   
-   Copyright (C) Andrew Tridgell  2004
-   
+
+   Copyright (C) Derrell Lipman  2005
+   Copyright (C) Simo Sorce 2005-2009
+
    ** NOTE! The following LGPL license applies to the ldb
    ** library. This does NOT imply that all of Samba is released
    ** under the LGPL
-   
+
    This library is free software; you can redistribute it and/or
    modify it under the terms of the GNU Lesser General Public
    License as published by the Free Software Foundation; either
-   version 2 of the License, or (at your option) any later version.
-   
+   version 3 of the License, or (at your option) any later version.
+
    This library is distributed in the hope that it will be useful,
    but WITHOUT ANY WARRANTY; without even the implied warranty of
    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
    Lesser General Public License for more details.
-   
+
    You should have received a copy of the GNU Lesser General Public
-   License along with this library; if not, write to the Free Software
-   Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
+   License along with this library; if not, see <http://www.gnu.org/licenses/>.
 */
 
 /*
  *  Author: Derrell Lipman (based on Andrew Tridgell's LDAP backend)
  */
 
-#include "includes.h"
-#include "ldb/include/ldb.h"
-#include "ldb/include/ldb_private.h"
-#include "ldb/ldb_sqlite3/ldb_sqlite3.h"
+#include "ldb_module.h"
+
+#include <sqlite3.h>
+
+struct lsqlite3_private {
+       int trans_count;
+       char **options;
+        sqlite3 *sqlite;
+};
+
+struct lsql_context {
+       struct ldb_module *module;
+       struct ldb_request *req;
+
+       /* search stuff */
+       long long current_eid;
+       const char * const * attrs;
+       struct ldb_reply *ares;
+
+       bool callback_failed;
+       struct tevent_timer *timeout_event;
+};
+
+/*
+ * Macros used throughout
+ */
 
-#ifndef False
-# define False  (0)
-# define True   (! False)
+#ifndef FALSE
+# define FALSE  (0)
+# define TRUE   (! FALSE)
 #endif
 
-#define QUERY(lsqlite3, pppValues, pNumRows, bRollbackOnError, sql...)  \
-    do                                                                  \
-    {                                                                   \
-            if (lsqlite3_query(lsqlite3,                                \
-                               pppValues,                               \
-                               pNumRows,                                \
-                               sql) != 0) {                             \
-                if (bRollbackOnError) {                                 \
-                        lsqlite3_query(lsqlite3,                        \
-                                       NULL,                            \
-                                       NULL,                            \
-                                       "ROLLBACK;");                    \
-                }                                                       \
-                return -1;                                              \
-        }                                                               \
-    } while (0)
+#define RESULT_ATTR_TABLE       "temp_result_attrs"
 
 
-static int
-lsqlite3_query(const struct lsqlite3_private *lsqlite3,
-               char ***pppValues,
-               int *pNumRows,
-               const char *pSql,
-               ...)
-{
-        
-}
+/* for testing, define to nothing, (create non-temporary table) */
+#define TEMPTAB                 "TEMPORARY"
 
-static int
-lsqlite3_create_attr_table(struct ldb_module *module,
-                           char * pAttr)
+/*
+ * Static variables
+ */
+sqlite3_stmt *  stmtGetEID = NULL;
+
+static char *lsqlite3_tprintf(TALLOC_CTX *mem_ctx, const char *fmt, ...)
 {
+       char *str, *ret;
+       va_list ap;
 
+       va_start(ap, fmt);
+        str = sqlite3_vmprintf(fmt, ap);
+       va_end(ap);
+
+       if (str == NULL) return NULL;
+
+       ret = talloc_strdup(mem_ctx, str);
+       if (ret == NULL) {
+               sqlite3_free(str);
+               return NULL;
+       }
+
+       sqlite3_free(str);
+       return ret;
 }
 
+static char base160tab[161] = {
+        48 ,49 ,50 ,51 ,52 ,53 ,54 ,55 ,56 ,57 , /* 0-9 */
+        58 ,59 ,65 ,66 ,67 ,68 ,69 ,70 ,71 ,72 , /* : ; A-H */
+        73 ,74 ,75 ,76 ,77 ,78 ,79 ,80 ,81 ,82 , /* I-R */
+        83 ,84 ,85 ,86 ,87 ,88 ,89 ,90 ,97 ,98 , /* S-Z , a-b */
+        99 ,100,101,102,103,104,105,106,107,108, /* c-l */
+        109,110,111,112,113,114,115,116,117,118, /* m-v */
+        119,120,121,122,160,161,162,163,164,165, /* w-z, latin1 */
+        166,167,168,169,170,171,172,173,174,175, /* latin1 */
+        176,177,178,179,180,181,182,183,184,185, /* latin1 */
+        186,187,188,189,190,191,192,193,194,195, /* latin1 */
+        196,197,198,199,200,201,202,203,204,205, /* latin1 */
+        206,207,208,209,210,211,212,213,214,215, /* latin1 */
+        216,217,218,219,220,221,222,223,224,225, /* latin1 */
+        226,227,228,229,230,231,232,233,234,235, /* latin1 */
+        236,237,238,239,240,241,242,243,244,245, /* latin1 */
+        246,247,248,249,250,251,252,253,254,255, /* latin1 */
+        '\0'
+};
+
 
-#if 0
-p/*
- * we don't need this right now, but will once we add some backend options
+/*
+ * base160()
  *
- * find an option in an option list (a null terminated list of strings)
+ * Convert an unsigned long integer into a base160 representation of the
+ * number.
  *
- * this assumes the list is short. If it ever gets long then we really should
- * do this in some smarter way
+ * Parameters:
+ *   val --
+ *     value to be converted
+ *
+ *   result --
+ *     character array, 5 bytes long, into which the base160 representation
+ *     will be placed.  The result will be a four-digit representation of the
+ *     number (with leading zeros prepended as necessary), and null
+ *     terminated.
+ *
+ * Returns:
+ *   Nothing
  */
-static const char *
-lsqlite3_option_find(const struct lsqlite3_private *lsqlite3,
-                     const char *name)
+static void
+base160_sql(sqlite3_context * hContext,
+            int argc,
+            sqlite3_value ** argv)
 {
-       int                 i;
-       size_t              len = strlen(name);
+    int             i;
+    long long       val;
+    char            result[5];
 
-       if (!lsqlite3->options) return NULL;
+    val = sqlite3_value_int64(argv[0]);
 
-       for (i=0;lsqlite3->options[i];i++) {            
-               if (strncmp(lsqlite3->options[i], name, len) == 0 &&
-                   lsqlite3->options[i][len] == '=') {
-                       return &lsqlite3->options[i][len+1];
-               }
-       }
+    for (i = 3; i >= 0; i--) {
 
-       return NULL;
+        result[i] = base160tab[val % 160];
+        val /= 160;
+    }
+
+    result[4] = '\0';
+
+    sqlite3_result_text(hContext, result, -1, SQLITE_TRANSIENT);
 }
-#endif
+
 
 /*
-  callback function used in call to ldb_dn_fold() for determining whether an
-  attribute type requires case folding.
-*/
-static int lsqlite3_case_fold_attr_required(struct ldb_module *module,
-                                           char *attr)
+ * base160next_sql()
+ *
+ * This function enhances sqlite by adding a "base160_next()" function which is
+ * accessible via queries.
+ *
+ * Retrieve the next-greater number in the base160 sequence for the terminal
+ * tree node (the last four digits).  Only one tree level (four digits) is
+ * operated on.
+ *
+ * Input:
+ *   A character string: either an empty string (in which case no operation is
+ *   performed), or a string of base160 digits with a length of a multiple of
+ *   four digits.
+ *
+ * Output:
+ *   Upon return, the trailing four digits (one tree level) will have been
+ *   incremented by 1.
+ */
+static void
+base160next_sql(sqlite3_context * hContext,
+                int argc,
+                sqlite3_value ** argv)
 {
-#warning "currently, all attributes require case folding"
-        return True;
+        int                         i;
+        int                         len;
+        char *             pTab;
+        char *             pBase160 = strdup((const char *)sqlite3_value_text(argv[0]));
+        char *             pStart = pBase160;
+
+        /*
+         * We need a minimum of four digits, and we will always get a multiple
+         * of four digits.
+         */
+        if (pBase160 != NULL &&
+            (len = strlen(pBase160)) >= 4 &&
+            len % 4 == 0) {
+
+                if (pBase160 == NULL) {
+
+                        sqlite3_result_null(hContext);
+                        return;
+                }
+
+                pBase160 += strlen(pBase160) - 1;
+
+                /* We only carry through four digits: one level in the tree */
+                for (i = 0; i < 4; i++) {
+
+                        /* What base160 value does this digit have? */
+                        pTab = strchr(base160tab, *pBase160);
+
+                        /* Is there a carry? */
+                        if (pTab < base160tab + sizeof(base160tab) - 1) {
+
+                                /*
+                                 * Nope.  Just increment this value and we're
+                                 * done.
+                                 */
+                                *pBase160 = *++pTab;
+                                break;
+                        } else {
+
+                                /*
+                                 * There's a carry.  This value gets
+                                 * base160tab[0], we decrement the buffer
+                                 * pointer to get the next higher-order digit,
+                                 * and continue in the loop.
+                                 */
+                                *pBase160-- = base160tab[0];
+                        }
+                }
+
+                sqlite3_result_text(hContext,
+                                    pStart,
+                                    strlen(pStart),
+                                    free);
+        } else {
+                sqlite3_result_value(hContext, argv[0]);
+                if (pBase160 != NULL) {
+                        free(pBase160);
+                }
+        }
 }
 
+static char *parsetree_to_sql(struct ldb_module *module,
+                             void *mem_ctx,
+                             const struct ldb_parse_tree *t)
+{
+       struct ldb_context *ldb;
+       const struct ldb_schema_attribute *a;
+       struct ldb_val value, subval;
+       char *wild_card_string;
+       char *child, *tmp;
+       char *ret = NULL;
+       char *attr;
+       int i;
+
+       ldb = ldb_module_get_ctx(module);
+
+       switch(t->operation) {
+       case LDB_OP_AND:
+
+               tmp = parsetree_to_sql(module, mem_ctx, t->u.list.elements[0]);
+               if (tmp == NULL) return NULL;
+
+               for (i = 1; i < t->u.list.num_elements; i++) {
+
+                       child = parsetree_to_sql(module, mem_ctx, t->u.list.elements[i]);
+                       if (child == NULL) return NULL;
+
+                       tmp = talloc_asprintf_append(tmp, " INTERSECT %s ", child);
+                       if (tmp == NULL) return NULL;
+               }
+
+               ret = talloc_asprintf(mem_ctx, "SELECT * FROM ( %s )\n", tmp);
+
+               return ret;
+
+       case LDB_OP_OR:
+
+               tmp = parsetree_to_sql(module, mem_ctx, t->u.list.elements[0]);
+               if (tmp == NULL) return NULL;
+
+               for (i = 1; i < t->u.list.num_elements; i++) {
+
+                       child = parsetree_to_sql(module, mem_ctx, t->u.list.elements[i]);
+                       if (child == NULL) return NULL;
+
+                       tmp = talloc_asprintf_append(tmp, " UNION %s ", child);
+                       if (tmp == NULL) return NULL;
+               }
+
+               return talloc_asprintf(mem_ctx, "SELECT * FROM ( %s ) ", tmp);
+
+       case LDB_OP_NOT:
+
+               child = parsetree_to_sql(module, mem_ctx, t->u.isnot.child);
+               if (child == NULL) return NULL;
+
+               return talloc_asprintf(mem_ctx,
+                                       "SELECT eid FROM ldb_entry "
+                                       "WHERE eid NOT IN ( %s ) ", child);
+
+       case LDB_OP_EQUALITY:
+               /*
+                * For simple searches, we want to retrieve the list of EIDs that
+                * match the criteria.
+               */
+               attr = ldb_attr_casefold(mem_ctx, t->u.equality.attr);
+               if (attr == NULL) return NULL;
+               a = ldb_schema_attribute_by_name(ldb, attr);
+
+               /* Get a canonicalised copy of the data */
+               a->syntax->canonicalise_fn(ldb, mem_ctx, &(t->u.equality.value), &value);
+               if (value.data == NULL) {
+                       return NULL;
+               }
+
+               if (strcasecmp(t->u.equality.attr, "dn") == 0) {
+                       /* DN query is a special ldb case */
+                       const char *cdn = ldb_dn_get_casefold(
+                                               ldb_dn_new(mem_ctx, ldb,
+                                                             (const char *)value.data));
+
+                       return lsqlite3_tprintf(mem_ctx,
+                                               "SELECT eid FROM ldb_entry "
+                                               "WHERE norm_dn = '%q'", cdn);
+
+               } else {
+                       /* A normal query. */
+                       return lsqlite3_tprintf(mem_ctx,
+                                               "SELECT eid FROM ldb_attribute_values "
+                                               "WHERE norm_attr_name = '%q' "
+                                               "AND norm_attr_value = '%q'",
+                                               attr,
+                                               value.data);
+
+               }
+
+       case LDB_OP_SUBSTRING:
+
+               wild_card_string = talloc_strdup(mem_ctx,
+                                       (t->u.substring.start_with_wildcard)?"*":"");
+               if (wild_card_string == NULL) return NULL;
+
+               for (i = 0; t->u.substring.chunks[i]; i++) {
+                       wild_card_string = talloc_asprintf_append(wild_card_string, "%s*",
+                                                       t->u.substring.chunks[i]->data);
+                       if (wild_card_string == NULL) return NULL;
+               }
+
+               if ( ! t->u.substring.end_with_wildcard ) {
+                       /* remove last wildcard */
+                       wild_card_string[strlen(wild_card_string) - 1] = '\0';
+               }
+
+               attr = ldb_attr_casefold(mem_ctx, t->u.substring.attr);
+               if (attr == NULL) return NULL;
+               a = ldb_schema_attribute_by_name(ldb, attr);
+
+               subval.data = (void *)wild_card_string;
+               subval.length = strlen(wild_card_string) + 1;
+
+               /* Get a canonicalised copy of the data */
+               a->syntax->canonicalise_fn(ldb, mem_ctx, &(subval), &value);
+               if (value.data == NULL) {
+                       return NULL;
+               }
+
+               return lsqlite3_tprintf(mem_ctx,
+                                       "SELECT eid FROM ldb_attribute_values "
+                                       "WHERE norm_attr_name = '%q' "
+                                       "AND norm_attr_value GLOB '%q'",
+                                       attr,
+                                       value.data);
+
+       case LDB_OP_GREATER:
+               attr = ldb_attr_casefold(mem_ctx, t->u.equality.attr);
+               if (attr == NULL) return NULL;
+               a = ldb_schema_attribute_by_name(ldb, attr);
+
+               /* Get a canonicalised copy of the data */
+               a->syntax->canonicalise_fn(ldb, mem_ctx, &(t->u.equality.value), &value);
+               if (value.data == NULL) {
+                       return NULL;
+               }
+
+               return lsqlite3_tprintf(mem_ctx,
+                                       "SELECT eid FROM ldb_attribute_values "
+                                       "WHERE norm_attr_name = '%q' "
+                                       "AND ldap_compare(norm_attr_value, '>=', '%q', '%q') ",
+                                       attr,
+                                       value.data,
+                                       attr);
+
+       case LDB_OP_LESS:
+               attr = ldb_attr_casefold(mem_ctx, t->u.equality.attr);
+               if (attr == NULL) return NULL;
+               a = ldb_schema_attribute_by_name(ldb, attr);
+
+               /* Get a canonicalised copy of the data */
+               a->syntax->canonicalise_fn(ldb, mem_ctx, &(t->u.equality.value), &value);
+               if (value.data == NULL) {
+                       return NULL;
+               }
+
+               return lsqlite3_tprintf(mem_ctx,
+                                       "SELECT eid FROM ldb_attribute_values "
+                                       "WHERE norm_attr_name = '%q' "
+                                       "AND ldap_compare(norm_attr_value, '<=', '%q', '%q') ",
+                                       attr,
+                                       value.data,
+                                       attr);
+
+       case LDB_OP_PRESENT:
+               if (strcasecmp(t->u.present.attr, "dn") == 0) {
+                       return talloc_strdup(mem_ctx, "SELECT eid FROM ldb_entry");
+               }
+
+               attr = ldb_attr_casefold(mem_ctx, t->u.present.attr);
+               if (attr == NULL) return NULL;
+
+               return lsqlite3_tprintf(mem_ctx,
+                                       "SELECT eid FROM ldb_attribute_values "
+                                       "WHERE norm_attr_name = '%q' ",
+                                       attr);
+
+       case LDB_OP_APPROX:
+               attr = ldb_attr_casefold(mem_ctx, t->u.equality.attr);
+               if (attr == NULL) return NULL;
+               a = ldb_schema_attribute_by_name(ldb, attr);
+
+               /* Get a canonicalised copy of the data */
+               a->syntax->canonicalise_fn(ldb, mem_ctx, &(t->u.equality.value), &value);
+               if (value.data == NULL) {
+                       return NULL;
+               }
+
+               return lsqlite3_tprintf(mem_ctx,
+                                       "SELECT eid FROM ldb_attribute_values "
+                                       "WHERE norm_attr_name = '%q' "
+                                       "AND ldap_compare(norm_attr_value, '~%', 'q', '%q') ",
+                                       attr,
+                                       value.data,
+                                       attr);
+
+       case LDB_OP_EXTENDED:
+#warning  "work out how to handle bitops"
+               return NULL;
+
+       default:
+               break;
+       };
+
+       /* should never occur */
+       abort();
+       return NULL;
+}
 
 /*
- * rename a record
+ * query_int()
+ *
+ * This function is used for the common case of queries that return a single
+ * integer value.
+ *
+ * NOTE: If more than one value is returned by the query, all but the first
+ * one will be ignored.
  */
 static int
-lsqlite3_rename(struct ldb_module *module,
-                const char *olddn,
-                const char *newdn)
+query_int(const struct lsqlite3_private * lsqlite3,
+          long long * pRet,
+          const char * pSql,
+          ...)
 {
-       /* ignore ltdb specials */
-       if (olddn[0] == '@' ||newdn[0] == '@') {
-               return 0;
-       }
+        int             ret;
+        int             bLoop;
+        char *          p;
+        sqlite3_stmt *  pStmt;
+        va_list         args;
+
+        /* Begin access to variable argument list */
+        va_start(args, pSql);
+
+        /* Format the query */
+        if ((p = sqlite3_vmprintf(pSql, args)) == NULL) {
+               va_end(args);
+                return SQLITE_NOMEM;
+        }
 
-#warning "lsqlite3_rename() is not yet supported"
-        return -1;
+        /*
+         * Prepare and execute the SQL statement.  Loop allows retrying on
+         * certain errors, e.g. SQLITE_SCHEMA occurs if the schema changes,
+         * requiring retrying the operation.
+         */
+        for (bLoop = TRUE; bLoop; ) {
+
+                /* Compile the SQL statement into sqlite virtual machine */
+                if ((ret = sqlite3_prepare(lsqlite3->sqlite,
+                                           p,
+                                           -1,
+                                           &pStmt,
+                                           NULL)) == SQLITE_SCHEMA) {
+                        if (stmtGetEID != NULL) {
+                                sqlite3_finalize(stmtGetEID);
+                                stmtGetEID = NULL;
+                        }
+                        continue;
+                } else if (ret != SQLITE_OK) {
+                        break;
+                }
+
+                /* One row expected */
+                if ((ret = sqlite3_step(pStmt)) == SQLITE_SCHEMA) {
+                        if (stmtGetEID != NULL) {
+                                sqlite3_finalize(stmtGetEID);
+                                stmtGetEID = NULL;
+                        }
+                        (void) sqlite3_finalize(pStmt);
+                        continue;
+                } else if (ret != SQLITE_ROW) {
+                        (void) sqlite3_finalize(pStmt);
+                        break;
+                }
+
+                /* Get the value to be returned */
+                *pRet = sqlite3_column_int64(pStmt, 0);
+
+                /* Free the virtual machine */
+                if ((ret = sqlite3_finalize(pStmt)) == SQLITE_SCHEMA) {
+                        if (stmtGetEID != NULL) {
+                                sqlite3_finalize(stmtGetEID);
+                                stmtGetEID = NULL;
+                        }
+                        continue;
+                } else if (ret != SQLITE_OK) {
+                        (void) sqlite3_finalize(pStmt);
+                        break;
+                }
+
+                /*
+                 * Normal condition is only one time through loop.  Loop is
+                 * rerun in error conditions, via "continue", above.
+                 */
+                bLoop = FALSE;
+        }
+
+        /* All done with variable argument list */
+        va_end(args);
+
+
+        /* Free the memory we allocated for our query string */
+        sqlite3_free(p);
+
+        return ret;
 }
 
 /*
- * delete a record
+ * This is a bad hack to support ldap style comparisons whithin sqlite.
+ * val is the attribute in the row currently under test
+ * func is the desired test "<=" ">=" "~" ":"
+ * cmp is the value to compare against (eg: "test")
+ * attr is the attribute name the value of which we want to test
  */
-static int
-lsqlite3_delete(struct ldb_module *module,
-                const char *dn)
+
+static void lsqlite3_compare(sqlite3_context *ctx, int argc,
+                                       sqlite3_value **argv)
 {
-       /* ignore ltdb specials */
-       if (dn[0] == '@') {
-               return 0;
+       struct ldb_context *ldb = (struct ldb_context *)sqlite3_user_data(ctx);
+       const char *val = (const char *)sqlite3_value_text(argv[0]);
+       const char *func = (const char *)sqlite3_value_text(argv[1]);
+       const char *cmp = (const char *)sqlite3_value_text(argv[2]);
+       const char *attr = (const char *)sqlite3_value_text(argv[3]);
+       const struct ldb_schema_attribute *a;
+       struct ldb_val valX;
+       struct ldb_val valY;
+       int ret;
+
+       switch (func[0]) {
+       /* greater */
+       case '>': /* >= */
+               a = ldb_schema_attribute_by_name(ldb, attr);
+               valX.data = (uint8_t *)cmp;
+               valX.length = strlen(cmp);
+               valY.data = (uint8_t *)val;
+               valY.length = strlen(val);
+               ret = a->syntax->comparison_fn(ldb, ldb, &valY, &valX);
+               if (ret >= 0)
+                       sqlite3_result_int(ctx, 1);
+               else
+                       sqlite3_result_int(ctx, 0);
+               return;
+
+       /* lesser */
+       case '<': /* <= */
+               a = ldb_schema_attribute_by_name(ldb, attr);
+               valX.data = (uint8_t *)cmp;
+               valX.length = strlen(cmp);
+               valY.data = (uint8_t *)val;
+               valY.length = strlen(val);
+               ret = a->syntax->comparison_fn(ldb, ldb, &valY, &valX);
+               if (ret <= 0)
+                       sqlite3_result_int(ctx, 1);
+               else
+                       sqlite3_result_int(ctx, 0);
+               return;
+
+       /* approx */
+       case '~':
+               /* TODO */
+               sqlite3_result_int(ctx, 0);
+               return;
+
+       /* bitops */
+       case ':':
+               /* TODO */
+               sqlite3_result_int(ctx, 0);
+               return;
+
+       default:
+               break;
        }
-       
-        return -1;
+
+       sqlite3_result_error(ctx, "Value must start with a special operation char (<>~:)!", -1);
+       return;
 }
 
-#if 0 /* not currently used * /
-/*
- * free a search result
- */
-static int
-lsqlite3_search_free(struct ldb_module *module,
-                     struct ldb_message **res)
+
+/* rename a record */
+static int lsqlite3_safe_rollback(sqlite3 *sqlite)
 {
-       talloc_free(res);
-       return 0;
+       char *errmsg;
+       int ret;
+
+       /* execute */
+       ret = sqlite3_exec(sqlite, "ROLLBACK;", NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       printf("lsqlite3_safe_rollback: Error: %s\n", errmsg);
+                       free(errmsg);
+               }
+               return -1;
+       }
+
+        return 0;
 }
-#endif
 
+/* return an eid as result */
+static int lsqlite3_eid_callback(void *result, int col_num, char **cols, char **names)
+{
+       long long *eid = (long long *)result;
+
+       if (col_num != 1) return SQLITE_ABORT;
+       if (strcasecmp(names[0], "eid") != 0) return SQLITE_ABORT;
+
+       *eid = atoll(cols[0]);
+       return SQLITE_OK;
+}
 
 /*
  * add a single set of ldap message values to a ldb_message
  */
-
-/* get things to compile before we actually implement this function */
-struct berval
+static int lsqlite3_search_callback(void *result, int col_num, char **cols, char **names)
 {
-        int x;
-};
+       struct ldb_context *ldb;
+       struct lsql_context *ac;
+       struct ldb_message *msg;
+       long long eid;
+       int i, ret;
 
-#warning "lsqlite3_add_msg_attr() not yet implemented or used"
-#if 0
-static int
-lsqlite3_add_msg_attr(struct ldb_context *ldb,
-                      struct ldb_message *msg, 
-                      const char *attr,
-                      struct berval **bval)
-{
-        int                          i;
-       int                          count;
-       struct ldb_message_element * el;
+       ac = talloc_get_type(result, struct lsql_context);
+       ldb = ldb_module_get_ctx(ac->module);
 
-       count = ldap_count_values_len(bval);
+       /* eid, dn, attr_name, attr_value */
+       if (col_num != 4) return SQLITE_ABORT;
 
-       if (count <= 0) {
-               return -1;
-       }
+       eid = atoll(cols[0]);
 
-       el = talloc_realloc(msg, msg->elements, struct ldb_message_element, 
-                             msg->num_elements + 1);
-       if (!el) {
-               errno = ENOMEM;
-               return -1;
+       if (ac->ares) {
+               msg = ac->ares->message;
        }
 
-       msg->elements = el;
+       if (eid != ac->current_eid) { /* here begin a new entry */
 
-       el = &msg->elements[msg->num_elements];
+               /* call the async callback for the last entry
+                * except the first time */
+               if (ac->current_eid != 0) {
+                       msg = ldb_msg_canonicalize(ldb, msg);
+                       if (!msg) return SQLITE_ABORT;
 
-       el->name = talloc_strdup(msg->elements, attr);
-       if (!el->name) {
-               errno = ENOMEM;
-               return -1;
+                       ret = ldb_module_send_entry(ac->req, msg, NULL);
+                       if (ret != LDB_SUCCESS) {
+                               ac->callback_failed = true;
+                               return SQLITE_ABORT;
+                       }
+               }
+
+               /* start over */
+               ac->ares = talloc_zero(ac, struct ldb_reply);
+               if (!ac->ares) return SQLITE_ABORT;
+
+               msg = ldb_msg_new(ac->ares);
+               if (!msg) return SQLITE_ABORT;
+
+               ac->ares->type = LDB_REPLY_ENTRY;
+               ac->current_eid = eid;
        }
-       el->flags = 0;
 
-       el->num_values = 0;
-       el->values = talloc_array(msg->elements, struct ldb_val, count);
-       if (!el->values) {
-               errno = ENOMEM;
-               return -1;
+       if (msg->dn == NULL) {
+               msg->dn = ldb_dn_new(msg, ldb, cols[1]);
+               if (msg->dn == NULL)
+                       return SQLITE_ABORT;
        }
 
-       for (i=0;i<count;i++) {
-               el->values[i].data = talloc_memdup(el->values, bval[i]->bv_val, bval[i]->bv_len);
-               if (!el->values[i].data) {
-                       return -1;
+       if (ac->attrs) {
+               int found = 0;
+               for (i = 0; ac->attrs[i]; i++) {
+                       if (strcasecmp(cols[2], ac->attrs[i]) == 0) {
+                               found = 1;
+                               break;
+                       }
                }
-               el->values[i].length = bval[i]->bv_len;
-               el->num_values++;
+               if (!found) goto done;
        }
 
-       msg->num_elements++;
+       if (ldb_msg_add_string(msg, cols[2], cols[3]) != 0) {
+               return SQLITE_ABORT;
+       }
 
-       return 0;
+done:
+       ac->ares->message = msg;
+       return SQLITE_OK;
 }
-#endif
+
 
 /*
- * search for matching records
+ * lsqlite3_get_eid()
+ * lsqlite3_get_eid_ndn()
+ *
+ * These functions are used for the very common case of retrieving an EID value
+ * given a (normalized) DN.
  */
-static int
-lsqlite3_search(struct ldb_module *module,
-                const char *base,
-                enum ldb_scope scope,
-                const char *expression,
-                const char * const attrs[],
-                struct ldb_message ***res)
+
+static long long lsqlite3_get_eid_ndn(sqlite3 *sqlite, void *mem_ctx, const char *norm_dn)
 {
-#warning "lsqlite3_search() not yet implemented"
-#if 0
-       int                       count;
-        int                       msg_count;
-       struct ldb_context *      ldb = module->ldb;
-       struct lsqlite3_private * lsqlite3 = module->private_data;
-
-       if (base == NULL) {
-               base = "";
-       }
-
-       lsqlite3->last_rc = ldap_search_s(lsqlite3->ldap, base, (int)scope, 
-                                     expression, 
-                                     discard_const_p(char *, attrs), 
-                                     0, &ldapres);
-       if (lsqlite3->last_rc != LDAP_SUCCESS) {
+       char *errmsg;
+       char *query;
+       long long eid = -1;
+       long long ret;
+
+       /* get object eid */
+       query = lsqlite3_tprintf(mem_ctx, "SELECT eid "
+                                         "FROM ldb_entry "
+                                         "WHERE norm_dn = '%q';", norm_dn);
+       if (query == NULL) return -1;
+
+       ret = sqlite3_exec(sqlite, query, lsqlite3_eid_callback, &eid, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       printf("lsqlite3_get_eid: Fatal Error: %s\n", errmsg);
+                       free(errmsg);
+               }
                return -1;
        }
 
-       count = ldap_count_entries(lsqlite3->ldap, ldapres);
-       if (count == -1 || count == 0) {
-               ldap_msgfree(ldapres);
-               return count;
+       return eid;
+}
+
+static long long lsqlite3_get_eid(struct lsqlite3_private *lsqlite3,
+                                 struct ldb_dn *dn)
+{
+       TALLOC_CTX *local_ctx;
+       long long eid = -1;
+       char *cdn;
+
+       /* ignore ltdb specials */
+       if (ldb_dn_is_special(dn)) {
+               return -1;
        }
 
-       (*res) = talloc_array(lsqlite3, struct ldb_message *, count+1);
-       if (! *res) {
-               ldap_msgfree(ldapres);
-               errno = ENOMEM;
+       /* create a local ctx */
+       local_ctx = talloc_named(lsqlite3, 0, "lsqlite3_get_eid local context");
+       if (local_ctx == NULL) {
                return -1;
        }
 
-       (*res)[0] = NULL;
+       cdn = ldb_dn_alloc_casefold(local_ctx, dn);
+       if (!cdn) goto done;
+
+       eid = lsqlite3_get_eid_ndn(lsqlite3->sqlite, local_ctx, cdn);
 
-       msg_count = 0;
+done:
+       talloc_free(local_ctx);
+       return eid;
+}
 
-       /* loop over all messages */
-       for (msg=ldap_first_entry(lsqlite3->ldap, ldapres); 
-            msg; 
-            msg=ldap_next_entry(lsqlite3->ldap, msg)) {
-               BerElement *berptr = NULL;
-               char *attr, *dn;
+/*
+ * Interface functions referenced by lsqlite3_ops
+ */
 
-               if (msg_count == count) {
-                       /* hmm, got too many? */
-                       ldb_debug(ldb, LDB_DEBUG_FATAL, "Fatal: ldap message count inconsistent\n");
-                       break;
+/* search for matching records, by tree */
+int lsql_search(struct lsql_context *ctx)
+{
+       struct ldb_module *module = ctx->module;
+       struct ldb_request *req = ctx->req;
+       struct lsqlite3_private *lsqlite3;
+       struct ldb_context *ldb;
+       char *norm_basedn;
+       char *sqlfilter;
+       char *errmsg;
+       char *query = NULL;
+        int ret;
+
+       ldb = ldb_module_get_ctx(module);
+       lsqlite3 = talloc_get_type(ldb_module_get_private(module),
+                                  struct lsqlite3_private);
+
+       if ((( ! ldb_dn_is_valid(req->op.search.base)) ||
+            ldb_dn_is_null(req->op.search.base)) &&
+           (req->op.search.scope == LDB_SCOPE_BASE ||
+            req->op.search.scope == LDB_SCOPE_ONELEVEL)) {
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
+
+       if (req->op.search.base) {
+               norm_basedn = ldb_dn_alloc_casefold(ctx, req->op.search.base);
+               if (norm_basedn == NULL) {
+                       return LDB_ERR_OPERATIONS_ERROR;
+               }
+       } else norm_basedn = talloc_strdup(ctx, "");
+
+        /* Convert filter into a series of SQL conditions (constraints) */
+       sqlfilter = parsetree_to_sql(module, ctx, req->op.search.tree);
+
+        switch(req->op.search.scope) {
+        case LDB_SCOPE_DEFAULT:
+        case LDB_SCOPE_SUBTREE:
+               if (*norm_basedn != '\0') {
+                       query = lsqlite3_tprintf(ctx,
+                               "SELECT entry.eid,\n"
+                               "       entry.dn,\n"
+                               "       av.attr_name,\n"
+                               "       av.attr_value\n"
+                               "  FROM ldb_entry AS entry\n"
+
+                               "  LEFT OUTER JOIN ldb_attribute_values AS av\n"
+                               "    ON av.eid = entry.eid\n"
+
+                               "  WHERE entry.eid IN\n"
+                               "    (SELECT DISTINCT ldb_entry.eid\n"
+                               "       FROM ldb_entry\n"
+                               "       WHERE (ldb_entry.norm_dn GLOB('*,%q')\n"
+                               "       OR ldb_entry.norm_dn = '%q')\n"
+                               "       AND ldb_entry.eid IN\n"
+                               "         (%s)\n"
+                               "    )\n"
+
+                               "  ORDER BY entry.eid ASC;",
+                               norm_basedn,
+                               norm_basedn,
+                               sqlfilter);
+               } else {
+                       query = lsqlite3_tprintf(ctx,
+                               "SELECT entry.eid,\n"
+                               "       entry.dn,\n"
+                               "       av.attr_name,\n"
+                               "       av.attr_value\n"
+                               "  FROM ldb_entry AS entry\n"
+
+                               "  LEFT OUTER JOIN ldb_attribute_values AS av\n"
+                               "    ON av.eid = entry.eid\n"
+
+                               "  WHERE entry.eid IN\n"
+                               "    (SELECT DISTINCT ldb_entry.eid\n"
+                               "       FROM ldb_entry\n"
+                               "       WHERE ldb_entry.eid IN\n"
+                               "         (%s)\n"
+                               "    )\n"
+
+                               "  ORDER BY entry.eid ASC;",
+                               sqlfilter);
                }
 
-               (*res)[msg_count] = talloc(*res, struct ldb_message);
-               if (!(*res)[msg_count]) {
-                       goto failed;
+               break;
+
+        case LDB_SCOPE_BASE:
+                query = lsqlite3_tprintf(ctx,
+                        "SELECT entry.eid,\n"
+                        "       entry.dn,\n"
+                        "       av.attr_name,\n"
+                        "       av.attr_value\n"
+                        "  FROM ldb_entry AS entry\n"
+
+                        "  LEFT OUTER JOIN ldb_attribute_values AS av\n"
+                        "    ON av.eid = entry.eid\n"
+
+                        "  WHERE entry.eid IN\n"
+                        "    (SELECT DISTINCT ldb_entry.eid\n"
+                        "       FROM ldb_entry\n"
+                        "       WHERE ldb_entry.norm_dn = '%q'\n"
+                        "         AND ldb_entry.eid IN\n"
+                       "           (%s)\n"
+                        "    )\n"
+
+                        "  ORDER BY entry.eid ASC;",
+                       norm_basedn,
+                        sqlfilter);
+                break;
+
+        case LDB_SCOPE_ONELEVEL:
+                query = lsqlite3_tprintf(ctx,
+                        "SELECT entry.eid,\n"
+                        "       entry.dn,\n"
+                        "       av.attr_name,\n"
+                        "       av.attr_value\n"
+                        "  FROM ldb_entry AS entry\n"
+
+                        "  LEFT OUTER JOIN ldb_attribute_values AS av\n"
+                        "    ON av.eid = entry.eid\n"
+
+                        "  WHERE entry.eid IN\n"
+                        "    (SELECT DISTINCT ldb_entry.eid\n"
+                        "       FROM ldb_entry\n"
+                       "       WHERE norm_dn GLOB('*,%q')\n"
+                       "         AND NOT norm_dn GLOB('*,*,%q')\n"
+                        "         AND ldb_entry.eid IN\n(%s)\n"
+                        "    )\n"
+
+                        "  ORDER BY entry.eid ASC;",
+                        norm_basedn,
+                        norm_basedn,
+                        sqlfilter);
+                break;
+        }
+
+        if (query == NULL) {
+               return LDB_ERR_OPERATIONS_ERROR;
+        }
+
+       /* * /
+       printf ("%s\n", query);
+       / * */
+
+       ctx->current_eid = 0;
+       ctx->attrs = req->op.search.attrs;
+       ctx->ares = NULL;
+
+       ldb_request_set_state(req, LDB_ASYNC_PENDING);
+
+       ret = sqlite3_exec(lsqlite3->sqlite, query, lsqlite3_search_callback, ctx, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       ldb_set_errstring(ldb, errmsg);
+                       free(errmsg);
                }
-               (*res)[msg_count+1] = NULL;
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
 
-               dn = ldap_get_dn(lsqlite3->ldap, msg);
-               if (!dn) {
-                       goto failed;
+       /* complete the last message if any */
+       if (ctx->ares) {
+               ctx->ares->message = ldb_msg_canonicalize(ldb, ctx->ares->message);
+               if (ctx->ares->message == NULL) {
+                       return LDB_ERR_OPERATIONS_ERROR;
                }
 
-               (*res)[msg_count]->dn = talloc_strdup((*res)[msg_count], dn);
-               ldap_memfree(dn);
-               if (!(*res)[msg_count]->dn) {
-                       goto failed;
+               ret = ldb_module_send_entry(req, ctx->ares->message, NULL);
+               if (ret != LDB_SUCCESS) {
+                       return ret;
                }
+       }
 
 
-               (*res)[msg_count]->num_elements = 0;
-               (*res)[msg_count]->elements = NULL;
-               (*res)[msg_count]->private_data = NULL;
+       return LDB_SUCCESS;
+}
 
-               /* loop over all attributes */
-               for (attr=ldap_first_attribute(lsqlite3->ldap, msg, &berptr);
-                    attr;
-                    attr=ldap_next_attribute(lsqlite3->ldap, msg, berptr)) {
-                       struct berval **bval;
-                       bval = ldap_get_values_len(lsqlite3->ldap, msg, attr);
+/* add a record */
+static int lsql_add(struct lsql_context *ctx)
+{
+       struct ldb_module *module = ctx->module;
+       struct ldb_request *req = ctx->req;
+       struct lsqlite3_private *lsqlite3;
+       struct ldb_context *ldb;
+       struct ldb_message *msg = req->op.add.message;
+        long long eid;
+       char *dn, *ndn;
+       char *errmsg;
+       char *query;
+       int i;
+       int ret;
+
+       ldb = ldb_module_get_ctx(module);
+       lsqlite3 = talloc_get_type(ldb_module_get_private(module),
+                                  struct lsqlite3_private);
+
+        /* See if this is an ltdb special */
+       if (ldb_dn_is_special(msg->dn)) {
+/*
+               struct ldb_dn *c;
+               c = ldb_dn_new(local_ctx, ldb, "@INDEXLIST");
+               if (ldb_dn_compare(ldb, msg->dn, c) == 0) {
+#warning "should we handle indexes somehow ?"
+                       ret = LDB_ERR_UNWILLING_TO_PERFORM;
+                       goto done;
+               }
+*/
+                /* Others return an error */
+               return LDB_ERR_UNWILLING_TO_PERFORM;
+       }
+
+       /* create linearized and normalized dns */
+       dn = ldb_dn_alloc_linearized(ctx, msg->dn);
+       ndn = ldb_dn_alloc_casefold(ctx, msg->dn);
+       if (dn == NULL || ndn == NULL) {
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
 
-                       if (bval) {
-                               lsqlite3_add_msg_attr(ldb, (*res)[msg_count], attr, bval);
-                               ldap_value_free_len(bval);
-                       }                                         
-                       
-                       ldap_memfree(attr);
+       query = lsqlite3_tprintf(ctx,
+                                  /* Add new entry */
+                                  "INSERT OR ABORT INTO ldb_entry "
+                                  "('dn', 'norm_dn') "
+                                  "VALUES ('%q', '%q');",
+                               dn, ndn);
+       if (query == NULL) {
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
+
+       ret = sqlite3_exec(lsqlite3->sqlite, query, NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       ldb_set_errstring(ldb, errmsg);
+                       free(errmsg);
                }
-               if (berptr) ber_free(berptr, 0);
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
 
-               msg_count++;
+       eid = lsqlite3_get_eid_ndn(lsqlite3->sqlite, ctx, ndn);
+       if (eid == -1) {
+               return LDB_ERR_OPERATIONS_ERROR;
        }
 
-       ldap_msgfree(ldapres);
+       for (i = 0; i < msg->num_elements; i++) {
+               const struct ldb_message_element *el = &msg->elements[i];
+               const struct ldb_schema_attribute *a;
+               char *attr;
+               int j;
+
+               /* Get a case-folded copy of the attribute name */
+               attr = ldb_attr_casefold(ctx, el->name);
+               if (attr == NULL) {
+                       return LDB_ERR_OPERATIONS_ERROR;
+               }
 
-       return msg_count;
+               a = ldb_schema_attribute_by_name(ldb, el->name);
 
-failed:
-       if (*res) lsqlite3_search_free(module, *res);
-       return -1;
-#else
-        return 0;
-#endif
-}
+               if (el->num_value == 0) {
+                       ldb_asprintf_errstring(ldb, "attribute %s on %s specified, but with 0 values (illegal)",
+                                              el->name, ldb_dn_get_linearized(msg->dn));
+                       return LDB_ERR_CONSTRAINT_VIOLATION;
+               }
+               if (a && a->flags & LDB_ATTR_FLAG_SINGLE_VALUE) {
+                       if (el->num_values > 1) {
+                               ldb_asprintf_errstring(ldb, "SINGLE-VALUED attribute %s on %s specified more than once",
+                                                      el->name, ldb_dn_get_linearized(msg->dn));
+                               return LDB_ERR_CONSTRAINT_VIOLATION;
+                       }
+               }
 
+               /* For each value of the specified attribute name... */
+               for (j = 0; j < el->num_values; j++) {
+                       struct ldb_val value;
+                       char *insert;
 
-/*
- * Issue a series of SQL statements to implement the ADD/MODIFY/DELETE
- * requests in the ldb_message
- */
-static int
-lsqlite3_msg_to_sql(struct ldb_module *module,
-                    const struct ldb_message *msg,
-                    long long eid,
-                    int use_flags)
+                       /* Get a canonicalised copy of the data */
+                       a->syntax->canonicalise_fn(ldb, ctx, &(el->values[j]), &value);
+                       if (value.data == NULL) {
+                               return LDB_ERR_OPERATIONS_ERROR;
+                       }
+
+                       insert = lsqlite3_tprintf(ctx,
+                                       "INSERT OR ROLLBACK INTO ldb_attribute_values "
+                                       "('eid', 'attr_name', 'norm_attr_name',"
+                                       " 'attr_value', 'norm_attr_value') "
+                                       "VALUES ('%lld', '%q', '%q', '%q', '%q');",
+                                       eid, el->name, attr,
+                                       el->values[j].data, value.data);
+                       if (insert == NULL) {
+                               return LDB_ERR_OPERATIONS_ERROR;
+                       }
+
+                       ret = sqlite3_exec(lsqlite3->sqlite, insert, NULL, NULL, &errmsg);
+                       if (ret != SQLITE_OK) {
+                               if (errmsg) {
+                                       ldb_set_errstring(ldb, errmsg);
+                                       free(errmsg);
+                               }
+                               return LDB_ERR_OPERATIONS_ERROR;
+                       }
+               }
+       }
+
+       return LDB_SUCCESS;
+}
+
+/* modify a record */
+static int lsql_modify(struct lsql_context *ctx)
 {
-        int                         flags;
-       unsigned int                i;
-        unsigned int                j;
-       struct lsqlite3_private *   lsqlite3 = module->private_data;
+       struct ldb_module *module = ctx->module;
+       struct ldb_request *req = ctx->req;
+       struct lsqlite3_private *lsqlite3;
+       struct ldb_context *ldb;
+       struct ldb_message *msg = req->op.mod.message;
+        long long eid;
+       char *errmsg;
+       int i;
+       int ret;
+
+       ldb = ldb_module_get_ctx(module);
+       lsqlite3 = talloc_get_type(ldb_module_get_private(module),
+                                  struct lsqlite3_private);
+
+        /* See if this is an ltdb special */
+       if (ldb_dn_is_special(msg->dn)) {
+                /* Others return an error */
+               return LDB_ERR_UNWILLING_TO_PERFORM;
+       }
+
+       eid = lsqlite3_get_eid(lsqlite3, msg->dn);
+       if (eid == -1) {
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
 
        for (i = 0; i < msg->num_elements; i++) {
                const struct ldb_message_element *el = &msg->elements[i];
+               const struct ldb_schema_attribute *a;
+               int flags = el->flags & LDB_FLAG_MOD_MASK;
+               char *attr;
+               char *mod;
+               int j;
+
+               if (ldb_attr_cmp(el->name, "distinguishedName") == 0) {
+                       ldb_asprintf_errstring(ldb, "it is not permitted to perform a modify on 'distinguishedName' (use rename instead): %s",
+                                              ldb_dn_get_linearized(msg->dn));
+                       return LDB_ERR_CONSTRAINT_VIOLATION;
+               }
 
-                if (! use_flags) {
-                        flags = LDB_FLAG_MOD_ADD;
-                } else {
-                        flags = el->flags & LDB_FLAG_MOD_MASK;
-                }
+               /* Get a case-folded copy of the attribute name */
+               attr = ldb_attr_casefold(ctx, el->name);
+               if (attr == NULL) {
+                       return LDB_ERR_OPERATIONS_ERROR;
+               }
 
-                if (flags == LDB_FLAG_MOD_ADD) {
-                        /* Create the attribute table if it doesn't exist */
-                        if (lsqlite3_create_attr_table(module,
-                                                       el->name) != 0) {
-                                return -1;
-                        }
-                }
+               a = ldb_schema_attribute_by_name(ldb, el->name);
 
-                /* For each value of the specified attribute name... */
-               for (j = 0; j < el->num_values; j++) {
+               switch (flags) {
 
-                        /* ... bind the attribute value, if necessary */
-                        switch (flags) {
-                        case LDB_FLAG_MOD_ADD:
-                                QUERY(lsqlite3,
-                                      NULL, NULL,
-                                      False,
-                                      "INSERT INTO ldb_attr_%q "
-                                      "    (eid, attr_value) "
-                                      "  VALUES "
-                                      "    (%lld, %Q);",
-                                      eid, el->values[j].data);
-                                QUERY(lsqlite3,
-                                      NULL, NULL,
-                                      False,
-                                      "UPDATE ldb_entry "
-                                      "  SET entry_data = "
-                                      "        add_attr(entry_data, %Q, %Q) "
-                                      "  WHERE eid = %lld;",
-                                      el->name, el->values[j].data, eid);
-                                      
-                                break;
+               case LDB_FLAG_MOD_REPLACE:
 
-                        case LDB_FLAG_MOD_REPLACE:
-                                QUERY(lsqlite3,
-                                      NULL, NULL,
-                                      False,
-                                      "UPDATE ldb_attr_%q "
-                                      "  SET attr_value = %Q "
-                                      "  WHERE eid = %lld;",
-                                      el->values[j].data, eid);
-                                QUERY(lsqlite3,
-                                      NULL, NULL,
-                                      False,
-                                      "UPDATE ldb_entry "
-                                      "  SET entry_data = "
-                                      "        mod_attr(entry_data, %Q, %Q) "
-                                      "  WHERE eid = %lld;",
-                                      el->name, el->values[j].data, eid);
-                                break;
+                       if (a && a->flags & LDB_ATTR_FLAG_SINGLE_VALUE) {
+                               if (el->num_values > 1) {
+                                       ldb_asprintf_errstring(ldb, "SINGLE-VALUE attribute %s on %s specified more than once",
+                                                              el->name, ldb_dn_get_linearized(msg->dn));
+                                       return LDB_ERR_ATTRIBUTE_OR_VALUE_EXISTS;
+                               }
+                       }
 
-                        case LDB_FLAG_MOD_DELETE:
-                                /* No additional parameters to this query */
-                                QUERY(lsqlite3,
-                                      NULL, NULL,
-                                      False,
-                                      "DELETE FROM ldb_attr_%q "
-                                      "  WHERE eid = %lld "
-                                      "    AND attr_value = %Q;",
-                                      eid, el->values[j].data);
-                                QUERY(lsqlite3,
-                                      NULL, NULL,
-                                      False,
-                                      "UPDATE ldb_entry "
-                                      "  SET entry_data = "
-                                      "        del_attr(entry_data, %Q, %Q) "
-                                      "  WHERE eid = %lld;",
-                                      el->name, el->values[j].data, eid);
-                                break;
+                       for (j=0; j<el->num_values; j++) {
+                               if (ldb_msg_find_val(el, &el->values[j]) != &el->values[j]) {
+                                       ldb_asprintf_errstring(ldb, "%s: value #%d provided more than once", el->name, j);
+                                       return LDB_ERR_ATTRIBUTE_OR_VALUE_EXISTS;
+                               }
+                       }
+
+                       /* remove all attributes before adding the replacements */
+                       mod = lsqlite3_tprintf(ctx,
+                                               "DELETE FROM ldb_attribute_values "
+                                               "WHERE eid = '%lld' "
+                                               "AND norm_attr_name = '%q';",
+                                               eid, attr);
+                       if (mod == NULL) {
+                               return LDB_ERR_OPERATIONS_ERROR;
+                       }
+
+                       ret = sqlite3_exec(lsqlite3->sqlite, mod, NULL, NULL, &errmsg);
+                       if (ret != SQLITE_OK) {
+                               if (errmsg) {
+                                       ldb_set_errstring(ldb, errmsg);
+                                       free(errmsg);
+                               }
+                               return LDB_ERR_OPERATIONS_ERROR;
                         }
+
+                       /* MISSING break is INTENTIONAL */
+
+               case LDB_FLAG_MOD_ADD:
+
+                       if (el->num_values == 0) {
+                               ldb_asprintf_errstring(ldb, "attribute %s on %s specified, but with 0 values (illigal)",
+                                                      el->name, ldb_dn_get_linearized(msg->dn));
+                               return LDB_ERR_CONSTRAINT_VIOLATION;
+                       }
+
+                       if (a && a->flags & LDB_ATTR_FLAG_SINGLE_VALUE) {
+                               if (el->num_values > 1) {
+                                       ldb_asprintf_errstring(ldb, "SINGLE-VALUE attribute %s on %s specified more than once",
+                                                              el->name, ldb_dn_get_linearized(msg->dn));
+                                       return LDB_ERR_ATTRIBUTE_OR_VALUE_EXISTS;
+                               }
+                       }
+
+#warning "We should throw an error if no value is provided!"
+                       /* For each value of the specified attribute name... */
+                       for (j = 0; j < el->num_values; j++) {
+                               struct ldb_val value;
+
+                               /* Get a canonicalised copy of the data */
+                               a->syntax->canonicalise_fn(ldb, ctx, &(el->values[j]), &value);
+                               if (value.data == NULL) {
+                                       return LDB_ERR_OPERATIONS_ERROR;
+                               }
+
+                               mod = lsqlite3_tprintf(ctx,
+                                       "INSERT OR ROLLBACK INTO ldb_attribute_values "
+                                       "('eid', 'attr_name', 'norm_attr_name',"
+                                       " 'attr_value', 'norm_attr_value') "
+                                       "VALUES ('%lld', '%q', '%q', '%q', '%q');",
+                                       eid, el->name, attr,
+                                       el->values[j].data, value.data);
+
+                               if (mod == NULL) {
+                                       return LDB_ERR_OPERATIONS_ERROR;
+                               }
+
+                               ret = sqlite3_exec(lsqlite3->sqlite, mod, NULL, NULL, &errmsg);
+                               if (ret != SQLITE_OK) {
+                                       if (errmsg) {
+                                               ldb_set_errstring(ldb, errmsg);
+                                               free(errmsg);
+                                       }
+                                       return LDB_ERR_OPERATIONS_ERROR;
+                               }
+                       }
+
+                       break;
+
+               case LDB_FLAG_MOD_DELETE:
+#warning "We should throw an error if the attribute we are trying to delete does not exist!"
+                       if (el->num_values == 0) {
+                               mod = lsqlite3_tprintf(ctx,
+                                                       "DELETE FROM ldb_attribute_values "
+                                                       "WHERE eid = '%lld' "
+                                                       "AND norm_attr_name = '%q';",
+                                                       eid, attr);
+                               if (mod == NULL) {
+                                       return LDB_ERR_OPERATIONS_ERROR;
+                               }
+
+                               ret = sqlite3_exec(lsqlite3->sqlite, mod, NULL, NULL, &errmsg);
+                               if (ret != SQLITE_OK) {
+                                       if (errmsg) {
+                                               ldb_set_errstring(ldb, errmsg);
+                                               free(errmsg);
+                                       }
+                                       return LDB_ERR_OPERATIONS_ERROR;
+                               }
+                       }
+
+                       /* For each value of the specified attribute name... */
+                       for (j = 0; j < el->num_values; j++) {
+                               struct ldb_val value;
+
+                               /* Get a canonicalised copy of the data */
+                               a->syntax->canonicalise_fn(ldb, ctx, &(el->values[j]), &value);
+                               if (value.data == NULL) {
+                                       return LDB_ERR_OPERATIONS_ERROR;
+                               }
+
+                               mod = lsqlite3_tprintf(ctx,
+                                       "DELETE FROM ldb_attribute_values "
+                                       "WHERE eid = '%lld' "
+                                       "AND norm_attr_name = '%q' "
+                                       "AND norm_attr_value = '%q';",
+                                       eid, attr, value.data);
+
+                               if (mod == NULL) {
+                                       return LDB_ERR_OPERATIONS_ERROR;
+                               }
+
+                               ret = sqlite3_exec(lsqlite3->sqlite, mod, NULL, NULL, &errmsg);
+                               if (ret != SQLITE_OK) {
+                                       if (errmsg) {
+                                               ldb_set_errstring(ldb, errmsg);
+                                               free(errmsg);
+                                       }
+                                       return LDB_ERR_OPERATIONS_ERROR;
+                               }
+                       }
+
+                       break;
                }
        }
 
-       return 0;
+       return LDB_SUCCESS;
 }
 
-
-static int
-lsqlite3_insert_dn(struct lsqlite3_private * lsqlite3,
-                   char * pDN,
-                   long long * pEID)
+/* delete a record */
+static int lsql_delete(struct lsql_context *ctx)
 {
+       struct ldb_module *module = ctx->module;
+       struct ldb_request *req = ctx->req;
+       struct lsqlite3_private *lsqlite3;
+       struct ldb_context *ldb;
+        long long eid;
+       char *errmsg;
+       char *query;
+       int ret;
+
+       ldb = ldb_module_get_ctx(module);
+       lsqlite3 = talloc_get_type(ldb_module_get_private(module),
+                                  struct lsqlite3_private);
+
+       eid = lsqlite3_get_eid(lsqlite3, req->op.del.dn);
+       if (eid == -1) {
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
 
-}
+       query = lsqlite3_tprintf(ctx,
+                                  /* Delete entry */
+                                  "DELETE FROM ldb_entry WHERE eid = %lld; "
+                                  /* Delete attributes */
+                                  "DELETE FROM ldb_attribute_values WHERE eid = %lld; ",
+                               eid, eid);
+       if (query == NULL) {
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
 
+       ret = sqlite3_exec(lsqlite3->sqlite, query, NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       ldb_set_errstring(ldb, errmsg);
+                       free(errmsg);
+               }
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
 
-/*
- * add a record
- */
-static int
-lsqlite3_add(struct ldb_module *module,
-             const struct ldb_message *msg)
+       return LDB_SUCCESS;
+}
+
+/* rename a record */
+static int lsql_rename(struct lsql_context *ctx)
 {
-        long long                   eid;
-       struct lsqlite3_private *   lsqlite3 = module->private_data;
+       struct ldb_module *module = ctx->module;
+       struct ldb_request *req = ctx->req;
+       struct lsqlite3_private *lsqlite3;
+       struct ldb_context *ldb;
+       char *new_dn, *new_cdn, *old_cdn;
+       char *errmsg;
+       char *query;
+       int ret;
+
+       ldb = ldb_module_get_ctx(module);
+       lsqlite3 = talloc_get_type(ldb_module_get_private(module),
+                                  struct lsqlite3_private);
+
+       /* create linearized and normalized dns */
+       old_cdn = ldb_dn_alloc_casefold(ctx, req->op.rename.olddn);
+       new_cdn = ldb_dn_alloc_casefold(ctx, req->op.rename.newdn);
+       new_dn = ldb_dn_alloc_linearized(ctx, req->op.rename.newdn);
+       if (old_cdn == NULL || new_cdn == NULL || new_dn == NULL) {
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
 
-       /* ignore ltdb specials */
-       if (msg->dn[0] == '@') {
-               return 0;
+       /* build the SQL query */
+       query = lsqlite3_tprintf(ctx,
+                                "UPDATE ldb_entry SET dn = '%q', norm_dn = '%q' "
+                                "WHERE norm_dn = '%q';",
+                                new_dn, new_cdn, old_cdn);
+       if (query == NULL) {
+               return LDB_ERR_OPERATIONS_ERROR;
        }
 
-        /* Begin a transaction */
-        QUERY(lsqlite3, NULL, NULL, False, "BEGIN EXCLUSIVE;");
+       /* execute */
+       ret = sqlite3_exec(lsqlite3->sqlite, query, NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       ldb_set_errstring(ldb, errmsg);
+                       free(errmsg);
+               }
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
 
-        /*
-         * Build any portions of the directory tree that don't exist.  If the
-         * final component already exists, it's an error.
-         */
-        if (lsqlite3_insert_dn(lsqlite3,
-                               ldb_dn_fold(module,
-                                           msg->dn,
-                                           lsqlite3_case_fold_attr_required),
-                                         &eid) != 0) {
-                QUERY(lsqlite3, NULL, NULL, False, "ROLLBACK;");
-                return -1;
-        }
+       return LDB_SUCCESS;
+}
 
-        /* Add attributes to this new entry */
-       if (lsqlite3_msg_to_sql(module, msg, eid, False) != 0) {
-                QUERY(lsqlite3, NULL, NULL, False, "ROLLBACK;");
-                return -1;
-        }
+static int lsql_start_trans(struct ldb_module * module)
+{
+       int ret;
+       char *errmsg;
+       struct lsqlite3_private *lsqlite3;
+
+       lsqlite3 = talloc_get_type(ldb_module_get_private(module),
+                                  struct lsqlite3_private);
+
+       if (lsqlite3->trans_count == 0) {
+               ret = sqlite3_exec(lsqlite3->sqlite, "BEGIN IMMEDIATE;", NULL, NULL, &errmsg);
+               if (ret != SQLITE_OK) {
+                       if (errmsg) {
+                               printf("lsqlite3_start_trans: error: %s\n", errmsg);
+                               free(errmsg);
+                       }
+                       return -1;
+               }
+       };
 
-        /* Everything worked.  Commit it! */
-        QUERY(lsqlite3, NULL, NULL, True, "COMMIT;");
-        return 0;
-}
+       lsqlite3->trans_count++;
 
+       return 0;
+}
 
-/*
- * modify a record
- */
-static int
-lsqlite3_modify(struct ldb_module *module,
-                const struct ldb_message *msg)
+static int lsql_end_trans(struct ldb_module *module)
 {
-        int                         numRows;
-        long long                   eid;
-        char **                     ppValues;
-       struct lsqlite3_private *   lsqlite3 = module->private_data;
-
-       /* ignore ltdb specials */
-       if (msg->dn[0] == '@') {
-               return 0;
+       int ret;
+       char *errmsg;
+       struct lsqlite3_private *lsqlite3;
+
+       lsqlite3 = talloc_get_type(ldb_module_get_private(module),
+                                  struct lsqlite3_private);
+
+       if (lsqlite3->trans_count > 0) {
+               lsqlite3->trans_count--;
+       } else return -1;
+
+       if (lsqlite3->trans_count == 0) {
+               ret = sqlite3_exec(lsqlite3->sqlite, "COMMIT;", NULL, NULL, &errmsg);
+               if (ret != SQLITE_OK) {
+                       if (errmsg) {
+                               printf("lsqlite3_end_trans: error: %s\n", errmsg);
+                               free(errmsg);
+                       }
+                       return -1;
+               }
        }
 
-        /* Begin a transaction */
-        QUERY(lsqlite3, NULL, NULL, False, "BEGIN EXCLUSIVE;");
-
-        /* Get the id of this DN. */
-        QUERY(lsqlite3,
-              &ppValues,
-              &numRows,
-              True, 
-              "SELECT eid "
-              "  FROM ldb_entry "
-              "  WHERE dn = %Q;",
-              ldb_dn_fold(module,
-                          msg->dn,
-                          lsqlite3_case_fold_attr_required));
-
-        /* Did it exist? */
-        if (numRows != 1) {
-                /* Nope.  See ya! */
-                sqlite3_free_table(ppValues);
-                return -1;
-        }
+        return 0;
+}
 
-        /* Retrieve the eid */
-        eid = strtoll(ppValues[1], NULL, 10);
+static int lsql_del_trans(struct ldb_module *module)
+{
+       struct lsqlite3_private *lsqlite3;
 
-        /* Modify attributes as specified */
-       if (lsqlite3_msg_to_sql(module, msg, eid, False) != 0) {
-                QUERY(lsqlite3, NULL, NULL, False, "ROLLBACK;");
-                return -1;
-        }
+       lsqlite3 = talloc_get_type(ldb_module_get_private(module),
+                                  struct lsqlite3_private);
 
-        /* Everything worked.  Commit it! */
-        QUERY(lsqlite3, NULL, NULL, True, "COMMIT;");
-        return 0 ;
-}
+       if (lsqlite3->trans_count > 0) {
+               lsqlite3->trans_count--;
+       } else return -1;
 
-static int
-lsqlite3_lock(struct ldb_module *module,
-              const char *lockname)
-{
-       if (lockname == NULL) {
-               return -1;
+       if (lsqlite3->trans_count == 0) {
+               return lsqlite3_safe_rollback(lsqlite3->sqlite);
        }
 
-       /* TODO implement a local locking mechanism here */
+       return -1;
+}
 
+static int destructor(struct lsqlite3_private *lsqlite3)
+{
+       if (lsqlite3->sqlite) {
+               sqlite3_close(lsqlite3->sqlite);
+       }
        return 0;
 }
 
-static int
-lsqlite3_unlock(struct ldb_module *module,
-                const char *lockname)
+static void lsql_request_done(struct lsql_context *ctx, int error)
 {
-       if (lockname == NULL) {
-               return -1;
+       struct ldb_context *ldb;
+       struct ldb_request *req;
+       struct ldb_reply *ares;
+
+       ldb = ldb_module_get_ctx(ctx->module);
+       req = ctx->req;
+
+       /* if we already returned an error just return */
+       if (ldb_request_get_status(req) != LDB_SUCCESS) {
+               return;
        }
 
-       /* TODO implement a local locking mechanism here */
+       ares = talloc_zero(req, struct ldb_reply);
+       if (!ares) {
+               ldb_oom(ldb);
+               req->callback(req, NULL);
+               return;
+       }
+       ares->type = LDB_REPLY_DONE;
+       ares->error = error;
 
-        return 0;
+       req->callback(req, ares);
 }
 
-/*
- * return extended error information
- */
-static const char *
-lsqlite3_errstring(struct ldb_module *module)
+static void lsql_timeout(struct tevent_context *ev,
+                        struct tevent_timer *te,
+                        struct timeval t,
+                        void *private_data)
 {
-       struct lsqlite3_private *   lsqlite3 = module->private_data;
+       struct lsql_context *ctx;
+       ctx = talloc_get_type(private_data, struct lsql_context);
 
-       return sqlite3_errmsg(lsqlite3->sqlite);
+       lsql_request_done(ctx, LDB_ERR_TIME_LIMIT_EXCEEDED);
 }
 
-
-static const struct ldb_module_ops lsqlite3_ops = {
-       "sqlite",
-       lsqlite3_search,
-       lsqlite3_add,
-       lsqlite3_modify,
-       lsqlite3_delete,
-       lsqlite3_rename,
-       lsqlite3_lock,
-       lsqlite3_unlock,
-       lsqlite3_errstring
-};
-
-
-static int
-lsqlite3_destructor(void *p)
+static void lsql_callback(struct tevent_context *ev,
+                         struct tevent_timer *te,
+                         struct timeval t,
+                         void *private_data)
 {
-       struct lsqlite3_private *   lsqlite3 = p;
+       struct lsql_context *ctx;
+       int ret;
+
+       ctx = talloc_get_type(private_data, struct lsql_context);
+
+       switch (ctx->req->operation) {
+       case LDB_SEARCH:
+               ret = lsql_search(ctx);
+               break;
+       case LDB_ADD:
+               ret = lsql_add(ctx);
+               break;
+       case LDB_MODIFY:
+               ret = lsql_modify(ctx);
+               break;
+       case LDB_DELETE:
+               ret = lsql_delete(ctx);
+               break;
+       case LDB_RENAME:
+               ret = lsql_rename(ctx);
+               break;
+/* TODO:
+       case LDB_EXTENDED:
+               ret = lsql_extended(ctx);
+               break;
+ */
+       default:
+               /* no other op supported */
+               ret = LDB_ERR_UNWILLING_TO_PERFORM;
+       }
 
-        (void) sqlite3_close(lsqlite3->sqlite);
-       return 0;
+       if (!ctx->callback_failed) {
+               /* Once we are done, we do not need timeout events */
+               talloc_free(ctx->timeout_event);
+               lsql_request_done(ctx, ret);
+       }
 }
 
-static int
-lsqlite3_initialize(struct lsqlite3_private *lsqlite3,
-                    const char *url)
+static int lsql_handle_request(struct ldb_module *module, struct ldb_request *req)
 {
-        int             ret;
-        int             bNewDatabase = False;
-        char *          p;
-        const char *    pTail;
-        struct stat     statbuf;
-        sqlite3_stmt *  stmt;
-        const char *    schema =       
-                "-- ------------------------------------------------------"
+       struct ldb_context *ldb;
+       struct tevent_context *ev;
+       struct lsql_context *ac;
+       struct tevent_timer *te;
+       struct timeval tv;
+
+       if (check_critical_controls(req->controls)) {
+               return LDB_ERR_UNSUPPORTED_CRITICAL_EXTENSION;
+       }
 
-                "PRAGMA auto_vacuum=1;"
+       if (req->starttime == 0 || req->timeout == 0) {
+               ldb_set_errstring(ldb, "Invalid timeout settings");
+               return LDB_ERR_TIME_LIMIT_EXCEEDED;
+       }
 
-                "-- ------------------------------------------------------"
+       ldb = ldb_module_get_ctx(module);
+       ev = ldb_get_event_context(ldb);
 
-                "BEGIN EXCLUSIVE;"
+       ac = talloc_zero(req, struct lsql_context);
+       if (ac == NULL) {
+               ldb_set_errstring(ldb, "Out of Memory");
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
 
-                "-- ------------------------------------------------------"
+       ac->module = module;
+       ac->req = req;
 
-                "CREATE TABLE ldb_info AS"
-                "  SELECT 'LDB' AS database_type,"
-                "         '1.0' AS version;"
+       tv.tv_sec = 0;
+       tv.tv_usec = 0;
+       te = tevent_add_timer(ev, ac, tv, lsql_callback, ac);
+       if (NULL == te) {
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
 
-                "-- ------------------------------------------------------"
-                "-- Schema"
-
-                "/*"
-                " * The entry table holds the information about an entry. "
-                " * This table is used to obtain the EID of the entry and to "
-                " * support scope=one and scope=base.  The parent and child"
-                " * table is included in the entry table since all the other"
-                " * attributes are dependent on EID."
-                " */"
-                "CREATE TABLE ldb_entry"
-                "("
-                "  -- Unique identifier of this LDB entry"
-                "  eid                   INTEGER PRIMARY KEY,"
+       tv.tv_sec = req->starttime + req->timeout;
+       ac->timeout_event = tevent_add_timer(ev, ac, tv, lsql_timeout, ac);
+       if (NULL == ac->timeout_event) {
+               return LDB_ERR_OPERATIONS_ERROR;
+       }
+
+       return LDB_SUCCESS;
+}
 
-                "  -- Unique identifier of the parent LDB entry"
-                "  peid                  INTEGER REFERENCES ldb_entry,"
+/*
+ * Table of operations for the sqlite3 backend
+ */
+static const struct ldb_module_ops lsqlite3_ops = {
+       .name              = "sqlite",
+       .search            = lsql_handle_request,
+       .add               = lsql_handle_request,
+        .modify            = lsql_handle_request,
+        .del               = lsql_handle_request,
+        .rename            = lsql_handle_request,
+       .extended          = lsql_handle_request,
+       .start_transaction = lsql_start_trans,
+       .end_transaction   = lsql_end_trans,
+       .del_transaction   = lsql_del_trans,
+};
 
-                "  -- Distinguished name of this entry"
-                "  dn                    TEXT,"
+/*
+ * Static functions
+ */
 
-                "  -- Time when the entry was created"
-                "  create_timestamp      INTEGER,"
+static int initialize(struct lsqlite3_private *lsqlite3,
+                     struct ldb_context *ldb, const char *url, int flags)
+{
+       TALLOC_CTX *local_ctx;
+        long long queryInt;
+       int rollback = 0;
+       char *errmsg;
+        char *schema;
+        int ret;
+
+       /* create a local ctx */
+       local_ctx = talloc_named(lsqlite3, 0, "lsqlite3_rename local context");
+       if (local_ctx == NULL) {
+               return -1;
+       }
 
-                "  -- Time when the entry was last modified"
-                "  modify_timestamp      INTEGER,"
+       schema = lsqlite3_tprintf(local_ctx,
 
-                "  -- Attributes of this entry, in the form"
-                "  --   attr\1value\0[attr\1value\0]*\0"
-                "  entry_data            TEXT"
-                ");"
 
+                "CREATE TABLE ldb_info AS "
+                "  SELECT 'LDB' AS database_type,"
+                "         '1.0' AS version;"
 
-                "/*"
-                " * The purpose of the descendant table is to support the"
-                " * subtree search feature.  For each LDB entry with a unique"
-                " * ID (AEID), this table contains the unique identifiers"
-                " * (DEID) of the descendant entries."
-                " *"
-                " * For evern entry in the directory, a row exists in this"
-                " * table for each of its ancestors including itself.  The "
-                " * size of the table depends on the depth of each entry.  In "
-                " * the worst case, if all the entries were at the same "
-                " * depth, the number of rows in the table is O(nm) where "
-                " * n is the number of nodes in the directory and m is the "
-                " * depth of the tree. "
-                " */"
-                "CREATE TABLE ldb_descendants"
+                /*
+                 * The entry table holds the information about an entry.
+                 * This table is used to obtain the EID of the entry and to
+                 * support scope=one and scope=base.  The parent and child
+                 * table is included in the entry table since all the other
+                 * attributes are dependent on EID.
+                 */
+                "CREATE TABLE ldb_entry "
                 "("
-                "  -- The unique identifier of the ancestor LDB entry"
-                "  aeid                  INTEGER REFERENCES ldb_entry,"
-
-                "  -- The unique identifier of the descendant LDB entry"
-                "  deid                  INTEGER REFERENCES ldb_entry"
+                "  eid     INTEGER PRIMARY KEY AUTOINCREMENT,"
+                "  dn      TEXT UNIQUE NOT NULL,"
+               "  norm_dn TEXT UNIQUE NOT NULL"
                 ");"
 
 
                 "CREATE TABLE ldb_object_classes"
                 "("
-                "  -- Object classes are inserted into this table to track"
-                "  -- their class hierarchy.  'top' is the top-level class"
-                "  -- of which all other classes are subclasses."
                 "  class_name            TEXT PRIMARY KEY,"
-
-                "  -- tree_key tracks the position of the class in"
-                "  -- the hierarchy"
-                "  tree_key              TEXT UNIQUE"
+                "  parent_class_name     TEXT,"
+                "  tree_key              TEXT UNIQUE,"
+                "  max_child_num         INTEGER DEFAULT 0"
                 ");"
 
-                "/*"
-                " * There is one attribute table per searchable attribute."
-                " */"
-                "/*"
-                "CREATE TABLE ldb_attr_ATTRIBUTE_NAME"
+                /*
+                 * We keep a full listing of attribute/value pairs here
+                 */
+                "CREATE TABLE ldb_attribute_values"
                 "("
-                "  -- The unique identifier of the LDB entry"
-                "  eid                   INTEGER REFERENCES ldb_entry,"
-
-                "  -- Normalized attribute value"
-                "  attr_value            TEXT"
+                "  eid             INTEGER REFERENCES ldb_entry,"
+                "  attr_name       TEXT,"
+                "  norm_attr_name  TEXT,"
+                "  attr_value      TEXT,"
+                "  norm_attr_value TEXT "
                 ");"
-                "*/"
 
 
-                "-- ------------------------------------------------------"
-                "-- Indexes"
+                /*
+                 * Indexes
+                 */
+                "CREATE INDEX ldb_attribute_values_eid_idx "
+                "  ON ldb_attribute_values (eid);"
 
+                "CREATE INDEX ldb_attribute_values_name_value_idx "
+                "  ON ldb_attribute_values (attr_name, norm_attr_value);"
 
-                "-- ------------------------------------------------------"
-                "-- Triggers"
 
-                "CREATE TRIGGER ldb_entry_insert_tr"
+
+                /*
+                 * Triggers
+                 */
+
+                "CREATE TRIGGER ldb_object_classes_insert_tr"
                 "  AFTER INSERT"
-                "  ON ldb_entry"
+                "  ON ldb_object_classes"
                 "  FOR EACH ROW"
                 "    BEGIN"
-                "      UPDATE ldb_entry"
-                "        SET create_timestamp = strftime('%s', 'now'),"
-                "            modify_timestamp = strftime('%s', 'now')"
-                "        WHERE eid = new.eid;"
+                "      UPDATE ldb_object_classes"
+                "        SET tree_key = COALESCE(tree_key, "
+                "              ("
+                "                SELECT tree_key || "
+                "                       (SELECT base160(max_child_num + 1)"
+                "                                FROM ldb_object_classes"
+                "                                WHERE class_name = "
+                "                                      new.parent_class_name)"
+                "                  FROM ldb_object_classes "
+                "                  WHERE class_name = new.parent_class_name "
+                "              ));"
+                "      UPDATE ldb_object_classes "
+                "        SET max_child_num = max_child_num + 1"
+                "        WHERE class_name = new.parent_class_name;"
                 "    END;"
 
-                "CREATE TRIGGER ldb_entry_update_tr"
-                "  AFTER UPDATE"
-                "  ON ldb_entry"
-                "  FOR EACH ROW"
-                "    BEGIN"
-                "      UPDATE ldb_entry"
-                "        SET modify_timestamp = strftime('%s', 'now')"
-                "        WHERE eid = old.eid;"
-                "    END;"
+                /*
+                 * Table initialization
+                 */
+
+                "INSERT INTO ldb_object_classes "
+                "    (class_name, tree_key) "
+                "  VALUES "
+                "    ('TOP', '0001');");
+
+        /* Skip protocol indicator of url  */
+        if (strncmp(url, "sqlite3://", 10) != 0) {
+                return SQLITE_MISUSE;
+        }
 
-                "-- ------------------------------------------------------"
-                "-- Table initialization"
+        /* Update pointer to just after the protocol indicator */
+        url += 10;
 
-                "/* We need an implicit 'top' level object class */"
-                "INSERT INTO ldb_attributes (attr_name,"
-                "                            parent_tree_key)"
-                "  SELECT 'top', '';"
+        /* Try to open the (possibly empty/non-existent) database */
+        if ((ret = sqlite3_open(url, &lsqlite3->sqlite)) != SQLITE_OK) {
+                return ret;
+        }
 
-                "-- ------------------------------------------------------"
+        /* In case this is a new database, enable auto_vacuum */
+       ret = sqlite3_exec(lsqlite3->sqlite, "PRAGMA auto_vacuum = 1;", NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       printf("lsqlite3 initializaion error: %s\n", errmsg);
+                       free(errmsg);
+               }
+               goto failed;
+       }
 
-                "COMMIT;"
+       if (flags & LDB_FLG_NOSYNC) {
+               /* DANGEROUS */
+               ret = sqlite3_exec(lsqlite3->sqlite, "PRAGMA synchronous = OFF;", NULL, NULL, &errmsg);
+               if (ret != SQLITE_OK) {
+                       if (errmsg) {
+                               printf("lsqlite3 initializaion error: %s\n", errmsg);
+                               free(errmsg);
+                       }
+                       goto failed;
+               }
+       }
 
-                "-- ------------------------------------------------------"
-                ;
-        
-        /* Skip protocol indicator of url  */
-        if ((p = strchr(url, ':')) == NULL) {
-                return SQLITE_MISUSE;
-        } else {
-                ++p;
+       /* */
+
+        /* Establish a busy timeout of 30 seconds */
+        if ((ret = sqlite3_busy_timeout(lsqlite3->sqlite,
+                                        30000)) != SQLITE_OK) {
+                return ret;
         }
-                
-        /*
-         * See if we'll be creating a new database, or opening an existing one
-         */
-        if ((stat(p, &statbuf) < 0 && errno == ENOENT) ||
-            statbuf.st_size == 0) {
 
-                bNewDatabase = True;
+        /* Create a function, callable from sql, to increment a tree_key */
+        if ((ret =
+             sqlite3_create_function(lsqlite3->sqlite,/* handle */
+                                     "base160_next",  /* function name */
+                                     1,               /* number of args */
+                                     SQLITE_ANY,      /* preferred text type */
+                                     NULL,            /* user data */
+                                     base160next_sql, /* called func */
+                                     NULL,            /* step func */
+                                     NULL             /* final func */
+                     )) != SQLITE_OK) {
+                return ret;
         }
 
-        /* Try to open the (possibly empty/non-existent) database */
-        if ((ret = sqlite3_open(p, &lsqlite3->sqlite)) != SQLITE_OK) {
+        /* Create a function, callable from sql, to convert int to base160 */
+        if ((ret =
+             sqlite3_create_function(lsqlite3->sqlite,/* handle */
+                                     "base160",       /* function name */
+                                     1,               /* number of args */
+                                     SQLITE_ANY,      /* preferred text type */
+                                     NULL,            /* user data */
+                                     base160_sql,     /* called func */
+                                     NULL,            /* step func */
+                                     NULL             /* final func */
+                     )) != SQLITE_OK) {
                 return ret;
         }
 
-        if (bNewDatabase) {
+        /* Create a function, callable from sql, to perform various comparisons */
+        if ((ret =
+             sqlite3_create_function(lsqlite3->sqlite, /* handle */
+                                     "ldap_compare",   /* function name */
+                                     4,                /* number of args */
+                                     SQLITE_ANY,       /* preferred text type */
+                                     ldb  ,            /* user data */
+                                     lsqlite3_compare, /* called func */
+                                     NULL,             /* step func */
+                                     NULL              /* final func */
+                     )) != SQLITE_OK) {
+                return ret;
+        }
+
+        /* Begin a transaction */
+       ret = sqlite3_exec(lsqlite3->sqlite, "BEGIN EXCLUSIVE;", NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       printf("lsqlite3: initialization error: %s\n", errmsg);
+                       free(errmsg);
+               }
+               goto failed;
+       }
+       rollback = 1;
+
+        /* Determine if this is a new database.  No tables means it is. */
+        if (query_int(lsqlite3,
+                      &queryInt,
+                      "SELECT COUNT(*)\n"
+                      "  FROM sqlite_master\n"
+                      "  WHERE type = 'table';") != 0) {
+               goto failed;
+        }
+
+        if (queryInt == 0) {
                 /*
                  * Create the database schema
                  */
-                for (pTail = discard_const_p(char, schema); pTail != NULL; ) {
-
-                        if ((ret = sqlite3_prepare(
-                                     lsqlite3->sqlite,
-                                     pTail,
-                                     -1,
-                                     &stmt,
-                                     &pTail)) != SQLITE_OK ||
-                            (ret = sqlite3_step(stmt)) != SQLITE_DONE ||
-                            (ret = sqlite3_finalize(stmt)) != SQLITE_OK) {
-
-                                (void) sqlite3_close(lsqlite3->sqlite);
-                                return ret;
-                        }
-                }
+               ret = sqlite3_exec(lsqlite3->sqlite, schema, NULL, NULL, &errmsg);
+               if (ret != SQLITE_OK) {
+                       if (errmsg) {
+                               printf("lsqlite3 initializaion error: %s\n", errmsg);
+                               free(errmsg);
+                       }
+                       goto failed;
+               }
         } else {
                 /*
                  * Ensure that the database we opened is one of ours
                  */
-                if ((ret = sqlite3_prepare(
-                             lsqlite3->sqlite,
-                             "SELECT COUNT(*) "
-                             "  FROM sqlite_master "
-                             "  WHERE type = 'table' "
-                             "    AND name IN "
-                             "      ("
-                             "        'ldb_entry', "
-                             "        'ldb_descendants', "
-                             "        'ldb_object_classes' "
-                             "      );",
-                             -1,
-                             &stmt,
-                             &pTail)) != SQLITE_OK ||
-                    (ret = sqlite3_step(stmt)) != SQLITE_ROW ||
-                    sqlite3_column_int(stmt, 0) != 3 ||
-                    (ret = sqlite3_finalize(stmt)) != SQLITE_OK ||
-
-                    (ret = sqlite3_prepare(
-                             lsqlite3->sqlite,
-                             "SELECT 1 "
-                             "  FROM ldb_info "
-                             "  WHERE database_type = 'LDB' "
-                             "    AND version = '1.0';",
-                             -1,
-                             &stmt,
-                             &pTail)) != SQLITE_OK ||
-                    (ret = sqlite3_step(stmt)) != SQLITE_ROW ||
-                    (ret = sqlite3_finalize(stmt)) != SQLITE_OK) {
-                
+                if (query_int(lsqlite3,
+                              &queryInt,
+                              "SELECT "
+                              "  (SELECT COUNT(*) = 2"
+                              "     FROM sqlite_master "
+                              "     WHERE type = 'table' "
+                              "       AND name IN "
+                              "         ("
+                              "           'ldb_entry', "
+                              "           'ldb_object_classes' "
+                              "         ) "
+                              "  ) "
+                              "  AND "
+                              "  (SELECT 1 "
+                              "     FROM ldb_info "
+                              "     WHERE database_type = 'LDB' "
+                              "       AND version = '1.0'"
+                              "  );") != 0 ||
+                    queryInt != 1) {
+
                         /* It's not one that we created.  See ya! */
-                        (void) sqlite3_close(lsqlite3->sqlite);
-                        return SQLITE_MISUSE;
+                       goto failed;
                 }
         }
 
+        /* Commit the transaction */
+       ret = sqlite3_exec(lsqlite3->sqlite, "COMMIT;", NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       printf("lsqlite3: iniialization error: %s\n", errmsg);
+                       free(errmsg);
+               }
+               goto failed;
+       }
+
         return SQLITE_OK;
+
+failed:
+       if (rollback) lsqlite3_safe_rollback(lsqlite3->sqlite);
+       sqlite3_close(lsqlite3->sqlite);
+       return -1;
 }
 
 /*
  * connect to the database
  */
-struct ldb_context *
-lsqlite3_connect(const char *url, 
-                 unsigned int flags, 
-                 const char *options[])
+static int lsqlite3_connect(struct ldb_context *ldb,
+                           const char *url,
+                           unsigned int flags,
+                           const char *options[],
+                           struct ldb_module **_module)
 {
-       int                         i;
-        int                         ret;
-       struct ldb_context *        ldb = NULL;
-       struct lsqlite3_private *   lsqlite3 = NULL;
-
-       ldb = talloc(NULL, struct ldb_context);
-       if (!ldb) {
-               errno = ENOMEM;
-               goto failed;
-       }
+       struct ldb_module *module;
+       struct lsqlite3_private *lsqlite3;
+        int i, ret;
+
+       module = ldb_module_new(ldb, ldb, "ldb_sqlite3 backend", &lsqlite3_ops);
+       if (!module) return -1;
 
-       lsqlite3 = talloc(ldb, struct lsqlite3_private);
+       lsqlite3 = talloc(module, struct lsqlite3_private);
        if (!lsqlite3) {
-               errno = ENOMEM;
                goto failed;
        }
 
        lsqlite3->sqlite = NULL;
        lsqlite3->options = NULL;
-        lsqlite3->lock_count = 0;
+       lsqlite3->trans_count = 0;
 
-       ret = lsqlite3_initialize(&lsqlite3, url);
+       ret = initialize(lsqlite3, ldb, url, flags);
        if (ret != SQLITE_OK) {
                goto failed;
        }
 
-       talloc_set_destructor(lsqlite3, lsqlite3_destructor);
+       talloc_set_destructor(lsqlite3, destructor);
 
-       ldb->modules = talloc(ldb, struct ldb_module);
-       if (!ldb->modules) {
-               errno = ENOMEM;
-               goto failed;
-       }
-       ldb->modules->ldb = ldb;
-       ldb->modules->prev = ldb->modules->next = NULL;
-       ldb->modules->private_data = lsqlite3;
-       ldb->modules->ops = &lsqlite3_ops;
+       ldb_module_set_private(module, lsqlite3);
 
        if (options) {
                /*
@@ -905,7 +1928,7 @@ lsqlite3_connect(const char *url,
                if (!lsqlite3->options) {
                        goto failed;
                }
-               
+
                for (i=0;options[i];i++) {
 
                        lsqlite3->options[i+1] = NULL;
@@ -917,13 +1940,18 @@ lsqlite3_connect(const char *url,
                }
        }
 
-       return ldb;
+       *_module = module;
+       return 0;
 
 failed:
-        if (lsqlite3->sqlite != NULL) {
+        if (lsqlite3 && lsqlite3->sqlite != NULL) {
                 (void) sqlite3_close(lsqlite3->sqlite);
         }
-       talloc_free(ldb);
-       return NULL;
+       talloc_free(lsqlite3);
+       return -1;
 }
 
+const struct ldb_backend_ops ldb_sqlite3_backend_ops = {
+       .name = "sqlite3",
+       .connect_fn = lsqlite3_connect
+};