r13609: Get in the initial work on making ldb async
[kai/samba.git] / source / lib / ldb / ldb_sqlite3 / ldb_sqlite3.c
index e491fba6e08b2f908025fee34e56d2986723b92e..48d849746fe2479f8d0f5955d6a4d33e7d12f4da 100644 (file)
@@ -2,6 +2,7 @@
    ldb database library
    
    Copyright (C) Derrell Lipman  2005
+   Copyright (C) Simo Sorce 2005
    
    ** NOTE! The following LGPL license applies to the ldb
    ** library. This does NOT imply that all of Samba is released
  *  Author: Derrell Lipman (based on Andrew Tridgell's LDAP backend)
  */
 
-#include <stdarg.h>
 #include "includes.h"
-#include "ldb/include/ldb.h"
-#include "ldb/include/ldb_private.h"
-#include "ldb/include/ldb_parse.h"
-#include "ldb/include/ldb_explode_dn.h"
+#include "ldb/include/includes.h"
+
 #include "ldb/ldb_sqlite3/ldb_sqlite3.h"
 
 /*
 # define TRUE   (! FALSE)
 #endif
 
-#define QUERY_NOROWS(lsqlite3, bRollbackOnError, sql...)        \
-    do {                                                        \
-            if (query_norows(lsqlite3, sql) != 0) {             \
-                if (bRollbackOnError) {                         \
-                        query_norows(lsqlite3,                  \
-                                       "ROLLBACK;");            \
-                }                                               \
-                return -1;                                      \
-        }                                                       \
-    } while (0)
-
-#define QUERY_INT(lsqlite3, result_var, bRollbackOnError, sql...)       \
-    do {                                                                \
-            if (query_int(lsqlite3, &result_var, sql) != 0) {           \
-                    if (bRollbackOnError) {                             \
-                            query_norows(lsqlite3,                      \
-                                                  "ROLLBACK;");         \
-                    }                                                   \
-                    return -1;                                          \
-            }                                                           \
-    } while (0)
+#define RESULT_ATTR_TABLE       "temp_result_attrs"
 
+//#define TEMPTAB                 /* for testing, create non-temporary table */
+#define TEMPTAB                 "TEMPORARY"
 
 /*
- * Forward declarations
+ * Static variables
  */
-static int
-lsqlite3_rename(struct ldb_module * module,
-                const char * olddn,
-                const char * newdn);
-
-static int
-lsqlite3_delete(struct ldb_module *module,
-                const char *dn);
-
-static int
-lsqlite3_search(struct ldb_module * module,
-                const char * pBaseDN,
-                enum ldb_scope scope,
-                const char * pExpression,
-                const char * const attrs[],
-                struct ldb_message *** res);
-
-static int
-lsqlite3_add(struct ldb_module *module,
-             const struct ldb_message *msg);
-
-static int
-lsqlite3_modify(struct ldb_module *module,
-                const struct ldb_message *msg);
-
-static int
-lsqlite3_lock(struct ldb_module *module,
-              const char *lockname);
-
-static int
-lsqlite3_unlock(struct ldb_module *module,
-                const char *lockname);
-
-static const char *
-lsqlite3_errstring(struct ldb_module *module);
-
-static int
-initialize(struct lsqlite3_private *lsqlite3,
-           const char *url);
-
-static int
-destructor(void *p);
-
-static int
-query_norows(const struct lsqlite3_private *lsqlite3,
-             const char *pSql,
-             ...);
-
-static int
-query_int(const struct lsqlite3_private * lsqlite3,
-          long long * pRet,
-          const char * pSql,
-          ...);
-
-static int case_fold_attr_required(void * hUserData,
-                                   char *attr);
-
-static char *
-parsetree_to_sql(struct ldb_module *module,
-                          char * hTalloc,
-                 const struct ldb_parse_tree *t);
+sqlite3_stmt *  stmtGetEID = NULL;
 
-static char *
-parsetree_to_tablelist(struct ldb_module *module,
-                       char * hTalloc,
-                       const struct ldb_parse_tree *t);
+static char *lsqlite3_tprintf(TALLOC_CTX *mem_ctx, const char *fmt, ...)
+{
+       char *str, *ret;
+       va_list ap;
 
-static int
-msg_to_sql(struct ldb_module * module,
-           const struct ldb_message * msg,
-           long long eid,
-           int use_flags);
+       va_start(ap, fmt);
+        str = sqlite3_vmprintf(fmt, ap);
+       va_end(ap);
 
-static int
-new_dn(struct ldb_module * module,
-       char * pDN,
-       long long * pEID);
+       if (str == NULL) return NULL;
 
-static int
-new_attr(struct ldb_module * module,
-         char * pAttrName);
+       ret = talloc_strdup(mem_ctx, str);
+       if (ret == NULL) {
+               sqlite3_free(str);
+               return NULL;
+       }
 
+       sqlite3_free(str);
+       return ret;
+}
 
-/*
- * Table of operations for the sqlite3 backend
- */
-static const struct ldb_module_ops lsqlite3_ops = {
-       "sqlite",
-       lsqlite3_search,
-       lsqlite3_add,
-       lsqlite3_modify,
-       lsqlite3_delete,
-       lsqlite3_rename,
-       lsqlite3_lock,
-       lsqlite3_unlock,
-       lsqlite3_errstring
+static unsigned char        base160tab[161] = {
+        48 ,49 ,50 ,51 ,52 ,53 ,54 ,55 ,56 ,57 , /* 0-9 */
+        58 ,59 ,65 ,66 ,67 ,68 ,69 ,70 ,71 ,72 , /* : ; A-H */
+        73 ,74 ,75 ,76 ,77 ,78 ,79 ,80 ,81 ,82 , /* I-R */
+        83 ,84 ,85 ,86 ,87 ,88 ,89 ,90 ,97 ,98 , /* S-Z , a-b */
+        99 ,100,101,102,103,104,105,106,107,108, /* c-l */
+        109,110,111,112,113,114,115,116,117,118, /* m-v */
+        119,120,121,122,160,161,162,163,164,165, /* w-z, latin1 */
+        166,167,168,169,170,171,172,173,174,175, /* latin1 */
+        176,177,178,179,180,181,182,183,184,185, /* latin1 */
+        186,187,188,189,190,191,192,193,194,195, /* latin1 */
+        196,197,198,199,200,201,202,203,204,205, /* latin1 */
+        206,207,208,209,210,211,212,213,214,215, /* latin1 */
+        216,217,218,219,220,221,222,223,224,225, /* latin1 */
+        226,227,228,229,230,231,232,233,234,235, /* latin1 */
+        236,237,238,239,240,241,242,243,244,245, /* latin1 */
+        246,247,248,249,250,251,252,253,254,255, /* latin1 */
+        '\0'
 };
 
 
-
-
-/*
- * Public functions
- */
-
-
 /*
- * connect to the database
+ * base160()
+ *
+ * Convert an unsigned long integer into a base160 representation of the
+ * number.
+ *
+ * Parameters:
+ *   val --
+ *     value to be converted
+ *
+ *   result --
+ *     character array, 5 bytes long, into which the base160 representation
+ *     will be placed.  The result will be a four-digit representation of the
+ *     number (with leading zeros prepended as necessary), and null
+ *     terminated.
+ *
+ * Returns:
+ *   Nothing
  */
-struct ldb_context *
-lsqlite3_connect(const char *url, 
-                 unsigned int flags, 
-                 const char *options[])
+static void
+base160_sql(sqlite3_context * hContext,
+            int argc,
+            sqlite3_value ** argv)
 {
-       int                         i;
-        int                         ret;
-       struct ldb_context *        ldb = NULL;
-       struct lsqlite3_private *   lsqlite3 = NULL;
-
-       ldb = talloc(NULL, struct ldb_context);
-       if (!ldb) {
-               errno = ENOMEM;
-               goto failed;
-       }
-
-       lsqlite3 = talloc(ldb, struct lsqlite3_private);
-       if (!lsqlite3) {
-               errno = ENOMEM;
-               goto failed;
-       }
-
-       lsqlite3->sqlite = NULL;
-       lsqlite3->options = NULL;
-        lsqlite3->lock_count = 0;
+    int             i;
+    long long       val;
+    char            result[5];
 
-       ret = initialize(lsqlite3, url);
-       if (ret != SQLITE_OK) {
-               goto failed;
-       }
-
-       talloc_set_destructor(lsqlite3, destructor);
-
-       ldb->modules = talloc(ldb, struct ldb_module);
-       if (!ldb->modules) {
-               errno = ENOMEM;
-               goto failed;
-       }
-       ldb->modules->ldb = ldb;
-       ldb->modules->prev = ldb->modules->next = NULL;
-       ldb->modules->private_data = lsqlite3;
-       ldb->modules->ops = &lsqlite3_ops;
-
-       if (options) {
-               /*
-                 * take a copy of the options array, so we don't have to rely
-                 * on the caller keeping it around (it might be dynamic)
-                 */
-               for (i=0;options[i];i++) ;
-
-               lsqlite3->options = talloc_array(lsqlite3, char *, i+1);
-               if (!lsqlite3->options) {
-                       goto failed;
-               }
-               
-               for (i=0;options[i];i++) {
+    val = sqlite3_value_int64(argv[0]);
 
-                       lsqlite3->options[i+1] = NULL;
-                       lsqlite3->options[i] =
-                                talloc_strdup(lsqlite3->options, options[i]);
-                       if (!lsqlite3->options[i]) {
-                               goto failed;
-                       }
-               }
-       }
+    for (i = 3; i >= 0; i--) {
+        
+        result[i] = base160tab[val % 160];
+        val /= 160;
+    }
 
-       return ldb;
+    result[4] = '\0';
 
-failed:
-        if (lsqlite3->sqlite != NULL) {
-                (void) sqlite3_close(lsqlite3->sqlite);
-        }
-       talloc_free(ldb);
-       return NULL;
+    sqlite3_result_text(hContext, result, -1, SQLITE_TRANSIENT);
 }
 
 
 /*
- * Interface functions referenced by lsqlite3_ops
+ * base160next_sql()
+ *
+ * This function enhances sqlite by adding a "base160_next()" function which is
+ * accessible via queries.
+ *
+ * Retrieve the next-greater number in the base160 sequence for the terminal
+ * tree node (the last four digits).  Only one tree level (four digits) is
+ * operated on.
+ *
+ * Input:
+ *   A character string: either an empty string (in which case no operation is
+ *   performed), or a string of base160 digits with a length of a multiple of
+ *   four digits.
+ *
+ * Output:
+ *   Upon return, the trailing four digits (one tree level) will have been
+ *   incremented by 1.
  */
-
-/* rename a record */
-static int
-lsqlite3_rename(struct ldb_module * module,
-                const char * olddn,
-                const char * newdn)
-{
-       /* ignore ltdb specials */
-       if (olddn[0] == '@' ||newdn[0] == '@') {
-               return 0;
-       }
-
-#warning "lsqlite3_rename() is not yet supported"
-        return -1;
-}
-
-/* delete a record */
-static int
-lsqlite3_delete(struct ldb_module *module,
-                const char *dn)
-{
-       /* ignore ltdb specials */
-       if (dn[0] == '@') {
-               return 0;
-       }
-       
-        return -1;
-}
-
-/* search for matching records */
-static int
-lsqlite3_search(struct ldb_module * module,
-                const char * pBaseDN,
-                enum ldb_scope scope,
-                const char * pExpression,
-                const char * const attrs[],
-                struct ldb_message *** res)
+static void
+base160next_sql(sqlite3_context * hContext,
+                int argc,
+                sqlite3_value ** argv)
 {
-        long long                   eid = 0;
-        char *                      sql;
-       char *                      sql_constraints;
-        char *                      table_list;
-        char *                      hTalloc;
-       struct ldb_parse_tree *     pTree;
-       struct lsqlite3_private *   lsqlite3 = module->private_data;
-       
-       if (pBaseDN == NULL) {
-               pBaseDN = "";
-       }
-
-        /* Begin a transaction */
-        QUERY_NOROWS(lsqlite3, FALSE, "BEGIN IMMEDIATE;");
+        int                         i;
+        int                         len;
+        unsigned char *             pTab;
+        unsigned char *             pBase160 =
+                strdup(sqlite3_value_text(argv[0]));
+        unsigned char *             pStart = pBase160;
 
         /*
-         * Obtain the eid of the base DN
+         * We need a minimum of four digits, and we will always get a multiple
+         * of four digits.
          */
-        QUERY_INT(lsqlite3,
-                  eid,
-                  TRUE,
-                  "SELECT eid "
-                  "  FROM ldb_attr_dn "
-                  "  WHERE attr_value = %Q;",
-                  pBaseDN);
-
-        /* Parse the filter expression into a tree we can work with */
-       if ((pTree = ldb_parse_tree(module->ldb, pExpression)) == NULL) {
-               return -1;
-       }
-       
-        /* Allocate a temporary talloc context */
-       hTalloc = talloc_new(module->ldb);
-
-        /* Move the parse tree to our temporary context */
-       talloc_steal(hTalloc, pTree);
-       
-        /* Convert filter into a series of SQL statements (constraints) */
-       sql_constraints = parsetree_to_sql(module, hTalloc, pTree);
-       
-        /* Get the list of attribute names to use as our extra table list */
-        table_list = parsetree_to_tablelist(module, hTalloc, pTree);
-
-        switch(scope) {
-        case LDB_SCOPE_DEFAULT:
-        case LDB_SCOPE_SUBTREE:
-                sql = sqlite3_mprintf(
-                        "SELECT entry.entry_data\n"
-                        "  FROM ldb_entry AS entry\n"
-                        "  WHERE entry.eid IN\n"
-                        "    (SELECT DISTINCT ldb_entry.eid\n"
-                        "       FROM ldb_entry,\n"
-                        "            ldb_descendants,\n"
-                        "            %q\n"
-                        "       WHERE ldb_descendants.aeid = %lld\n"
-                        "         AND ldb_entry.eid = ldb_descendants.deid\n"
-                        "         AND ldap_entry.eid IN\n"
-                        "%s"
-                        ");",
-                        table_list,
-                        eid,
-                        sql_constraints);
-                break;
-
-        case LDB_SCOPE_BASE:
-                sql = sqlite3_mprintf(
-                        "SELECT entry.entry_data\n"
-                        "  FROM ldb_entry AS entry\n"
-                        "  WHERE entry.eid IN\n"
-                        "    (SELECT DISTINCT ldb_entry.eid\n"
-                        "       FROM %q\n"
-                        "       WHERE ldb_entry.eid = %lld\n"
-                        "         AND ldb_entry.eid IN\n"
-                        "%s"
-                        ");",
-                        table_list,
-                        eid,
-                        sql_constraints);
-                break;
-
-        case LDB_SCOPE_ONELEVEL:
-                sql = sqlite3_mprintf(
-                        "SELECT entry.entry_data\n"
-                        "  FROM ldb_entry AS entry\n"
-                        "  WHERE entry.eid IN\n"
-                        "    (SELECT DISTINCT ldb_entry.eid\n"
-                        "       FROM ldb_entry AS pchild, "
-                        "            %q\n"
-                        "       WHERE ldb_entry.eid = pchild.eid "
-                        "         AND pchild.peid = %lld "
-                        "         AND ldb_entry.eid IN\n"
-                        "%s"
-                        ");",
-                        table_list,
-                        eid,
-                        sql_constraints);
-                break;
-        }
-
-#warning "retrieve and return the result set of the search here"
+        if (pBase160 != NULL &&
+            (len = strlen(pBase160)) >= 4 &&
+            len % 4 == 0) {
 
-        /* End the transaction */
-        QUERY_NOROWS(lsqlite3, FALSE, "END TRANSACTION;");
+                if (pBase160 == NULL) {
 
-       return 0;
-}
+                        sqlite3_result_null(hContext);
+                        return;
+                }
 
+                pBase160 += strlen(pBase160) - 1;
 
-/* add a record */
-static int
-lsqlite3_add(struct ldb_module *module,
-             const struct ldb_message *msg)
-{
-        long long                   eid;
-       struct lsqlite3_private *   lsqlite3 = module->private_data;
+                /* We only carry through four digits: one level in the tree */
+                for (i = 0; i < 4; i++) {
 
-       /* ignore ltdb specials */
-       if (msg->dn[0] == '@') {
-               return 0;
-       }
+                        /* What base160 value does this digit have? */
+                        pTab = strchr(base160tab, *pBase160);
 
-        /* Begin a transaction */
-        QUERY_NOROWS(lsqlite3, FALSE, "BEGIN EXCLUSIVE;");
+                        /* Is there a carry? */
+                        if (pTab < base160tab + sizeof(base160tab) - 1) {
 
-        /*
-         * Build any portions of the directory tree that don't exist.  If the
-         * final component already exists, it's an error.
-         */
-        if (new_dn(module, msg->dn, &eid) != 0) {
-                QUERY_NOROWS(lsqlite3, FALSE, "ROLLBACK;");
-                return -1;
-        }
+                                /*
+                                 * Nope.  Just increment this value and we're
+                                 * done.
+                                 */
+                                *pBase160 = *++pTab;
+                                break;
+                        } else {
+
+                                /*
+                                 * There's a carry.  This value gets
+                                 * base160tab[0], we decrement the buffer
+                                 * pointer to get the next higher-order digit,
+                                 * and continue in the loop.
+                                 */
+                                *pBase160-- = base160tab[0];
+                        }
+                }
 
-        /* Add attributes to this new entry */
-       if (msg_to_sql(module, msg, eid, FALSE) != 0) {
-                QUERY_NOROWS(lsqlite3, FALSE, "ROLLBACK;");
-                return -1;
+                sqlite3_result_text(hContext,
+                                    pStart,
+                                    strlen(pStart),
+                                    free);
+        } else {
+                sqlite3_result_value(hContext, argv[0]);
+                if (pBase160 != NULL) {
+                        free(pBase160);
+                }
         }
-
-        /* Everything worked.  Commit it! */
-        QUERY_NOROWS(lsqlite3, TRUE, "COMMIT;");
-        return 0;
-}
-
-
-/* modify a record */
-static int
-lsqlite3_modify(struct ldb_module *module,
-                const struct ldb_message *msg)
-{
-       struct lsqlite3_private *   lsqlite3 = module->private_data;
-
-       /* ignore ltdb specials */
-       if (msg->dn[0] == '@') {
-               return 0;
-       }
-
-        /* Begin a transaction */
-        QUERY_NOROWS(lsqlite3, FALSE, "BEGIN EXCLUSIVE;");
-
-        /* Everything worked.  Commit it! */
-        QUERY_NOROWS(lsqlite3, TRUE, "COMMIT;");
-        return 0 ;
 }
 
-/* obtain a named lock */
-static int
-lsqlite3_lock(struct ldb_module *module,
-              const char *lockname)
+static char *parsetree_to_sql(struct ldb_module *module,
+                             void *mem_ctx,
+                             const struct ldb_parse_tree *t)
 {
-       if (lockname == NULL) {
-               return -1;
-       }
+       const struct ldb_attrib_handler *h;
+       struct ldb_val value, subval;
+       char *wild_card_string;
+       char *child, *tmp;
+       char *ret = NULL;
+       char *attr;
+       int i;
 
-       /* TODO implement a local locking mechanism here */
 
-       return 0;
-}
-
-/* release a named lock */
-static int
-lsqlite3_unlock(struct ldb_module *module,
-                const char *lockname)
-{
-       if (lockname == NULL) {
-               return -1;
-       }
+       switch(t->operation) {
+       case LDB_OP_AND:
 
-       /* TODO implement a local locking mechanism here */
+               tmp = parsetree_to_sql(module, mem_ctx, t->u.list.elements[0]);
+               if (tmp == NULL) return NULL;
 
-        return 0;
-}
+               for (i = 1; i < t->u.list.num_elements; i++) {
 
-/* return extended error information */
-static const char *
-lsqlite3_errstring(struct ldb_module *module)
-{
-       struct lsqlite3_private *   lsqlite3 = module->private_data;
+                       child = parsetree_to_sql(module, mem_ctx, t->u.list.elements[i]);
+                       if (child == NULL) return NULL;
 
-       return sqlite3_errmsg(lsqlite3->sqlite);
-}
+                       tmp = talloc_asprintf_append(tmp, " INTERSECT %s ", child);
+                       if (tmp == NULL) return NULL;
+               }
 
+               ret = talloc_asprintf(mem_ctx, "SELECT * FROM ( %s )\n", tmp);
 
+               return ret;
+                
+       case LDB_OP_OR:
 
+               tmp = parsetree_to_sql(module, mem_ctx, t->u.list.elements[0]);
+               if (tmp == NULL) return NULL;
 
-/*
- * Static functions
- */
+               for (i = 1; i < t->u.list.num_elements; i++) {
 
-static int
-initialize(struct lsqlite3_private *lsqlite3,
-           const char *url)
-{
-        int             ret;
-        long long       queryInt;
-        const char *    pTail;
-        sqlite3_stmt *  stmt;
-        const char *    schema =       
-                "-- ------------------------------------------------------"
+                       child = parsetree_to_sql(module, mem_ctx, t->u.list.elements[i]);
+                       if (child == NULL) return NULL;
 
-                "PRAGMA auto_vacuum=1;"
+                       tmp = talloc_asprintf_append(tmp, " UNION %s ", child);
+                       if (tmp == NULL) return NULL;
+               }
 
-                "-- ------------------------------------------------------"
+               return talloc_asprintf(mem_ctx, "SELECT * FROM ( %s ) ", tmp);
 
-                "BEGIN EXCLUSIVE;"
+       case LDB_OP_NOT:
 
-                "-- ------------------------------------------------------"
+               child = parsetree_to_sql(module, mem_ctx, t->u.isnot.child);
+               if (child == NULL) return NULL;
 
-                "CREATE TABLE ldb_info AS"
-                "  SELECT 'LDB' AS database_type,"
-                "         '1.0' AS version;"
+               return talloc_asprintf(mem_ctx,
+                                       "SELECT eid FROM ldb_entry "
+                                       "WHERE eid NOT IN ( %s ) ", child);
 
-                "-- ------------------------------------------------------"
-                "-- Schema"
-
-                "/*"
-                " * The entry table holds the information about an entry. "
-                " * This table is used to obtain the EID of the entry and to "
-                " * support scope=one and scope=base.  The parent and child"
-                " * table is included in the entry table since all the other"
-                " * attributes are dependent on EID."
-                " */"
-                "CREATE TABLE ldb_entry"
-                "("
-                "  -- Unique identifier of this LDB entry"
-                "  eid                   INTEGER PRIMARY KEY,"
+       case LDB_OP_EQUALITY:
+               /*
+                * For simple searches, we want to retrieve the list of EIDs that
+                * match the criteria.
+               */
+               attr = ldb_attr_casefold(module->ldb, mem_ctx, t->u.equality.attr);
+               if (attr == NULL) return NULL;
+               h = ldb_attrib_handler(module->ldb, attr);
+
+               /* Get a canonicalised copy of the data */
+               h->canonicalise_fn(module->ldb, mem_ctx, &(t->u.equality.value), &value);
+               if (value.data == NULL) {
+                       return NULL;
+               }
 
-                "  -- Unique identifier of the parent LDB entry"
-                "  peid                  INTEGER REFERENCES ldb_entry,"
+               if (strcasecmp(t->u.equality.attr, "objectclass") == 0) {
+               /*
+                * For object classes, we want to search for all objectclasses
+                * that are subclasses as well.
+               */
+                       return lsqlite3_tprintf(mem_ctx,
+                                       "SELECT eid  FROM ldb_attribute_values\n"
+                                       "WHERE norm_attr_name = 'OBJECTCLASS' "
+                                       "AND norm_attr_value IN\n"
+                                       "  (SELECT class_name FROM ldb_object_classes\n"
+                                       "   WHERE tree_key GLOB\n"
+                                       "     (SELECT tree_key FROM ldb_object_classes\n"
+                                       "      WHERE class_name = '%q'\n"
+                                       "     ) || '*'\n"
+                                       "  )\n", value.data);
+
+               } else if (strcasecmp(t->u.equality.attr, "dn") == 0) {
+                       /* DN query is a special ldb case */
+                       char *cdn = ldb_dn_linearize_casefold(module->ldb,
+                                                             ldb_dn_explode(module->ldb,
+                                                             value.data));
+
+                       return lsqlite3_tprintf(mem_ctx,
+                                               "SELECT eid FROM ldb_entry "
+                                               "WHERE norm_dn = '%q'", cdn);
+
+               } else {
+                       /* A normal query. */
+                       return lsqlite3_tprintf(mem_ctx,
+                                               "SELECT eid FROM ldb_attribute_values "
+                                               "WHERE norm_attr_name = '%q' "
+                                               "AND norm_attr_value = '%q'",
+                                               attr,
+                                               value.data);
 
-                "  -- Distinguished name of this entry"
-                "  dn                    TEXT,"
+               }
 
-                "  -- Time when the entry was created"
-                "  create_timestamp      INTEGER,"
+       case LDB_OP_SUBSTRING:
 
-                "  -- Time when the entry was last modified"
-                "  modify_timestamp      INTEGER,"
+               wild_card_string = talloc_strdup(mem_ctx,
+                                       (t->u.substring.start_with_wildcard)?"*":"");
+               if (wild_card_string == NULL) return NULL;
 
-                "  -- Attributes of this entry, in the form"
-                "  --   attr\1value\0[attr\1value\0]*\0"
-                "  entry_data            TEXT"
-                ");"
+               for (i = 0; t->u.substring.chunks[i]; i++) {
+                       wild_card_string = talloc_asprintf_append(wild_card_string, "%s*",
+                                                       t->u.substring.chunks[i]->data);
+                       if (wild_card_string == NULL) return NULL;
+               }
 
+               if ( ! t->u.substring.end_with_wildcard ) {
+                       /* remove last wildcard */
+                       wild_card_string[strlen(wild_card_string) - 1] = '\0';
+               }
 
-                "/*"
-                " * The purpose of the descendant table is to support the"
-                " * subtree search feature.  For each LDB entry with a unique"
-                " * ID (AEID), this table contains the unique identifiers"
-                " * (DEID) of the descendant entries."
-                " *"
-                " * For evern entry in the directory, a row exists in this"
-                " * table for each of its ancestors including itself.  The "
-                " * size of the table depends on the depth of each entry.  In "
-                " * the worst case, if all the entries were at the same "
-                " * depth, the number of rows in the table is O(nm) where "
-                " * n is the number of nodes in the directory and m is the "
-                " * depth of the tree. "
-                " */"
-                "CREATE TABLE ldb_descendants"
-                "("
-                "  -- The unique identifier of the ancestor LDB entry"
-                "  aeid                  INTEGER REFERENCES ldb_entry,"
+               attr = ldb_attr_casefold(module->ldb, mem_ctx, t->u.substring.attr);
+               if (attr == NULL) return NULL;
+               h = ldb_attrib_handler(module->ldb, attr);
 
-                "  -- The unique identifier of the descendant LDB entry"
-                "  deid                  INTEGER REFERENCES ldb_entry"
-                ");"
+               subval.data = wild_card_string;
+               subval.length = strlen(wild_card_string) + 1;
 
+               /* Get a canonicalised copy of the data */
+               h->canonicalise_fn(module->ldb, mem_ctx, &(subval), &value);
+               if (value.data == NULL) {
+                       return NULL;
+               }
 
-                "CREATE TABLE ldb_object_classes"
-                "("
-                "  -- Object classes are inserted into this table to track"
-                "  -- their class hierarchy.  'top' is the top-level class"
-                "  -- of which all other classes are subclasses."
-                "  class_name            TEXT PRIMARY KEY,"
+               return lsqlite3_tprintf(mem_ctx,
+                                       "SELECT eid FROM ldb_attribute_values "
+                                       "WHERE norm_attr_name = '%q' "
+                                       "AND norm_attr_value GLOB '%q'",
+                                       attr,
+                                       value.data);
+
+       case LDB_OP_GREATER:
+               attr = ldb_attr_casefold(module->ldb, mem_ctx, t->u.equality.attr);
+               if (attr == NULL) return NULL;
+               h = ldb_attrib_handler(module->ldb, attr);
+
+               /* Get a canonicalised copy of the data */
+               h->canonicalise_fn(module->ldb, mem_ctx, &(t->u.equality.value), &value);
+               if (value.data == NULL) {
+                       return NULL;
+               }
 
-                "  -- tree_key tracks the position of the class in"
-                "  -- the hierarchy"
-                "  tree_key              TEXT UNIQUE"
-                ");"
+               return lsqlite3_tprintf(mem_ctx,
+                                       "SELECT eid FROM ldb_attribute_values "
+                                       "WHERE norm_attr_name = '%q' "
+                                       "AND ldap_compare(norm_attr_value, '>=', '%q', '%q') ",
+                                       attr,
+                                       value.data,
+                                       attr);
+
+       case LDB_OP_LESS:
+               attr = ldb_attr_casefold(module->ldb, mem_ctx, t->u.equality.attr);
+               if (attr == NULL) return NULL;
+               h = ldb_attrib_handler(module->ldb, attr);
+
+               /* Get a canonicalised copy of the data */
+               h->canonicalise_fn(module->ldb, mem_ctx, &(t->u.equality.value), &value);
+               if (value.data == NULL) {
+                       return NULL;
+               }
 
-                "/*"
-                " * There is one attribute table per searchable attribute."
-                " */"
-                "/*"
-                "CREATE TABLE ldb_attr_ATTRIBUTE_NAME"
-                "("
-                "  -- The unique identifier of the LDB entry"
-                "  eid                   INTEGER REFERENCES ldb_entry,"
+               return lsqlite3_tprintf(mem_ctx,
+                                       "SELECT eid FROM ldb_attribute_values "
+                                       "WHERE norm_attr_name = '%q' "
+                                       "AND ldap_compare(norm_attr_value, '<=', '%q', '%q') ",
+                                       attr,
+                                       value.data,
+                                       attr);
+
+       case LDB_OP_PRESENT:
+               if (strcasecmp(t->u.present.attr, "dn") == 0) {
+                       return talloc_strdup(mem_ctx, "SELECT eid FROM ldb_entry");
+               }
 
-                "  -- Normalized attribute value"
-                "  attr_value            TEXT"
-                ");"
-                "*/"
+               attr = ldb_attr_casefold(module->ldb, mem_ctx, t->u.present.attr);
+               if (attr == NULL) return NULL;
 
+               return lsqlite3_tprintf(mem_ctx,
+                                       "SELECT eid FROM ldb_attribute_values "
+                                       "WHERE norm_attr_name = '%q' ",
+                                       attr);
 
-                "-- ------------------------------------------------------"
-                "-- Indexes"
+       case LDB_OP_APPROX:
+               attr = ldb_attr_casefold(module->ldb, mem_ctx, t->u.equality.attr);
+               if (attr == NULL) return NULL;
+               h = ldb_attrib_handler(module->ldb, attr);
 
+               /* Get a canonicalised copy of the data */
+               h->canonicalise_fn(module->ldb, mem_ctx, &(t->u.equality.value), &value);
+               if (value.data == NULL) {
+                       return NULL;
+               }
 
-                "-- ------------------------------------------------------"
-                "-- Triggers"
+               return lsqlite3_tprintf(mem_ctx,
+                                       "SELECT eid FROM ldb_attribute_values "
+                                       "WHERE norm_attr_name = '%q' "
+                                       "AND ldap_compare(norm_attr_value, '~%', 'q', '%q') ",
+                                       attr,
+                                       value.data,
+                                       attr);
+               
+       case LDB_OP_EXTENDED:
+#warning  "work out how to handle bitops"
+               return NULL;
 
-                "CREATE TRIGGER ldb_entry_insert_tr"
-                "  AFTER INSERT"
-                "  ON ldb_entry"
-                "  FOR EACH ROW"
-                "    BEGIN"
-                "      UPDATE ldb_entry"
-                "        SET create_timestamp = strftime('%s', 'now'),"
-                "            modify_timestamp = strftime('%s', 'now')"
-                "        WHERE eid = new.eid;"
-                "    END;"
-
-                "CREATE TRIGGER ldb_entry_update_tr"
-                "  AFTER UPDATE"
-                "  ON ldb_entry"
-                "  FOR EACH ROW"
-                "    BEGIN"
-                "      UPDATE ldb_entry"
-                "        SET modify_timestamp = strftime('%s', 'now')"
-                "        WHERE eid = old.eid;"
-                "    END;"
-
-                "-- ------------------------------------------------------"
-                "-- Table initialization"
-
-                "/* We need an implicit 'top' level object class */"
-                "INSERT INTO ldb_attributes (attr_name,"
-                "                            parent_tree_key)"
-                "  SELECT 'top', '';"
-
-                "-- ------------------------------------------------------"
-
-                "COMMIT;"
-
-                "-- ------------------------------------------------------"
-                ;
-        
-        /* Skip protocol indicator of url  */
-        if (strncmp(url, "sqlite://", 9) != 0) {
-                return SQLITE_MISUSE;
-        }
-
-        /* Update pointer to just after the protocol indicator */
-        url += 9;
-                
-        /* Try to open the (possibly empty/non-existent) database */
-        if ((ret = sqlite3_open(url, &lsqlite3->sqlite)) != SQLITE_OK) {
-                return ret;
-        }
-
-        /* Begin a transaction */
-        QUERY_NOROWS(lsqlite3, FALSE, "BEGIN EXCLUSIVE;");
-
-        /* Determine if this is a new database.  No tables means it is. */
-        QUERY_INT(lsqlite3,
-                  queryInt,
-                  TRUE,
-                  "SELECT COUNT(*) "
-                  "  FROM sqlite_master "
-                  "  WHERE type = 'table';");
-
-        if (queryInt == 0) {
-                /*
-                 * Create the database schema
-                 */
-                for (pTail = discard_const_p(char, schema); pTail != NULL; ) {
-
-                        if ((ret = sqlite3_prepare(
-                                     lsqlite3->sqlite,
-                                     pTail,
-                                     -1,
-                                     &stmt,
-                                     &pTail)) != SQLITE_OK ||
-                            (ret = sqlite3_step(stmt)) != SQLITE_DONE ||
-                            (ret = sqlite3_finalize(stmt)) != SQLITE_OK) {
-
-                                QUERY_NOROWS(lsqlite3, FALSE, "ROLLBACK;");
-                                (void) sqlite3_close(lsqlite3->sqlite);
-                                return ret;
-                        }
-                }
-        } else {
-                /*
-                 * Ensure that the database we opened is one of ours
-                 */
-                if (query_int(lsqlite3,
-                              &queryInt,
-                              "SELECT "
-                              "  (SELECT COUNT(*) = 3"
-                              "     FROM sqlite_master "
-                              "     WHERE type = 'table' "
-                              "       AND name IN "
-                              "         ("
-                              "           'ldb_entry', "
-                              "           'ldb_descendants', "
-                              "           'ldb_object_classes' "
-                              "         ) "
-                              "  ) "
-                              "  AND "
-                              "  (SELECT 1 "
-                              "     FROM ldb_info "
-                              "     WHERE database_type = 'LDB' "
-                              "       AND version = '1.0'"
-                              "  );") != 0 ||
-                    queryInt != 1) {
-                
-                        /* It's not one that we created.  See ya! */
-                        QUERY_NOROWS(lsqlite3, FALSE, "ROLLBACK;");
-                        (void) sqlite3_close(lsqlite3->sqlite);
-                        return SQLITE_MISUSE;
-                }
-        }
-
-        /* Commit the transaction */
-        QUERY_NOROWS(lsqlite3, FALSE, "COMMIT;");
-
-        return SQLITE_OK;
-}
-
-static int
-destructor(void *p)
-{
-       struct lsqlite3_private *   lsqlite3 = p;
-
-        (void) sqlite3_close(lsqlite3->sqlite);
-       return 0;
-}
-
-
-/*
- * query_norows()
- *
- * This function is used for queries that are not expected to return any rows,
- * e.g. BEGIN, COMMIT, ROLLBACK, CREATE TABLE, INSERT, UPDATE, DELETE, etc.
- * There are no provisions here for returning data from rows in a table, so do
- * not pass SELECT queries to this function.
- */
-static int
-query_norows(const struct lsqlite3_private *lsqlite3,
-             const char *pSql,
-             ...)
-{
-        int             ret;
-        int             bLoop;
-        char *          p;
-        const char *    pTail;
-        sqlite3_stmt *  pStmt;
-        va_list         args;
-        
-        /* Begin access to variable argument list */
-        va_start(args, pSql);
-
-        /* Format the query */
-        if ((p = sqlite3_vmprintf(pSql, args)) == NULL) {
-                return -1;
-        }
-
-        /*
-         * Prepare and execute the SQL statement.  Loop allows retrying on
-         * certain errors, e.g. SQLITE_SCHEMA occurs if the schema changes,
-         * requiring retrying the operation.
-         */
-        for (bLoop = TRUE; bLoop; ) {
-
-                /* Compile the SQL statement into sqlite virtual machine */
-                if ((ret = sqlite3_prepare(lsqlite3->sqlite,
-                                           pTail,
-                                           -1,
-                                           &pStmt,
-                                           &pTail)) != SQLITE_OK) {
-                        ret = -1;
-                        break;
-                }
-                
-                /* No rows expected, so just step through machine code once */
-                if ((ret = sqlite3_step(pStmt)) == SQLITE_SCHEMA) {
-                        (void) sqlite3_finalize(pStmt);
-                        continue;
-                } else if (ret != SQLITE_DONE) {
-                        (void) sqlite3_finalize(pStmt);
-                        ret = -1;
-                        break;
-                }
-
-                /* Free the virtual machine */
-                if ((ret = sqlite3_finalize(pStmt)) == SQLITE_SCHEMA) {
-                        (void) sqlite3_finalize(pStmt);
-                        continue;
-                } else if (ret != SQLITE_OK) {
-                        (void) sqlite3_finalize(pStmt);
-                        ret = -1;
-                        break;
-                }
-
-                /*
-                 * Normal condition is only one time through loop.  Loop is
-                 * rerun in error conditions, via "continue", above.
-                 */
-                ret = 0;
-                bLoop = FALSE;
-        }
-
-        /* All done with variable argument list */
-        va_end(args);
-
-        /* Free the memory we allocated for our query string */
-        sqlite3_free(p);
-
-        return ret;
-}
+       default:
+               break;
+       };
 
+       /* should never occur */
+       abort();
+       return NULL;
+}
 
 /*
  * query_int()
@@ -854,474 +474,1416 @@ query_int(const struct lsqlite3_private * lsqlite3,
         int             ret;
         int             bLoop;
         char *          p;
-        const char *    pTail;
         sqlite3_stmt *  pStmt;
         va_list         args;
         
         /* Begin access to variable argument list */
         va_start(args, pSql);
-
+        
         /* Format the query */
         if ((p = sqlite3_vmprintf(pSql, args)) == NULL) {
-                return -1;
+                return SQLITE_NOMEM;
         }
-
+        
         /*
          * Prepare and execute the SQL statement.  Loop allows retrying on
          * certain errors, e.g. SQLITE_SCHEMA occurs if the schema changes,
          * requiring retrying the operation.
          */
         for (bLoop = TRUE; bLoop; ) {
-
+                
                 /* Compile the SQL statement into sqlite virtual machine */
                 if ((ret = sqlite3_prepare(lsqlite3->sqlite,
-                                           pTail,
+                                           p,
                                            -1,
                                            &pStmt,
-                                           &pTail)) != SQLITE_OK) {
-                        ret = -1;
+                                           NULL)) == SQLITE_SCHEMA) {
+                        if (stmtGetEID != NULL) {
+                                sqlite3_finalize(stmtGetEID);
+                                stmtGetEID = NULL;
+                        }
+                        continue;
+                } else if (ret != SQLITE_OK) {
                         break;
                 }
                 
-                /* No rows expected, so just step through machine code once */
+                /* One row expected */
                 if ((ret = sqlite3_step(pStmt)) == SQLITE_SCHEMA) {
+                        if (stmtGetEID != NULL) {
+                                sqlite3_finalize(stmtGetEID);
+                                stmtGetEID = NULL;
+                        }
                         (void) sqlite3_finalize(pStmt);
                         continue;
                 } else if (ret != SQLITE_ROW) {
                         (void) sqlite3_finalize(pStmt);
-                        ret = -1;
                         break;
                 }
-
+                
                 /* Get the value to be returned */
                 *pRet = sqlite3_column_int64(pStmt, 0);
-
+                
                 /* Free the virtual machine */
                 if ((ret = sqlite3_finalize(pStmt)) == SQLITE_SCHEMA) {
-                        (void) sqlite3_finalize(pStmt);
+                        if (stmtGetEID != NULL) {
+                                sqlite3_finalize(stmtGetEID);
+                                stmtGetEID = NULL;
+                        }
                         continue;
                 } else if (ret != SQLITE_OK) {
                         (void) sqlite3_finalize(pStmt);
-                        ret = -1;
                         break;
                 }
-
+                
                 /*
                  * Normal condition is only one time through loop.  Loop is
                  * rerun in error conditions, via "continue", above.
                  */
-                ret = 0;
                 bLoop = FALSE;
         }
-
+        
         /* All done with variable argument list */
         va_end(args);
+        
 
         /* Free the memory we allocated for our query string */
         sqlite3_free(p);
-
-        return ret;
-}
-
-
-/*
-  callback function used in call to ldb_dn_fold() for determining whether an
-  attribute type requires case folding.
-*/
-static int
-case_fold_attr_required(void * hUserData,
-                        char *attr)
-{
-//        struct ldb_module * module = hUserData;
         
-#warning "currently, all attributes require case folding"
-        return TRUE;
+        return ret;
 }
 
-
 /*
- * add a single set of ldap message values to a ldb_message
+ * This is a bad hack to support ldap style comparisons whithin sqlite.
+ * val is the attribute in the row currently under test
+ * func is the desired test "<=" ">=" "~" ":"
+ * cmp is the value to compare against (eg: "test")
+ * attr is the attribute name the value of which we want to test
  */
 
-#warning "add_msg_attr() not yet implemented or used"
-#if 0
-static int
-add_msg_attr(struct ldb_context *ldb,
-                      struct ldb_message *msg, 
-                      const char *attr,
-                      struct berval **bval)
+static void lsqlite3_compare(sqlite3_context *ctx, int argc,
+                                       sqlite3_value **argv)
 {
-        int                          i;
-       int                          count;
-       struct ldb_message_element * el;
-
-       count = ldap_count_values_len(bval);
-
-       if (count <= 0) {
-               return -1;
+       struct ldb_context *ldb = (struct ldb_context *)sqlite3_user_data(ctx);
+       const unsigned char *val = sqlite3_value_text(argv[0]);
+       const unsigned char *func = sqlite3_value_text(argv[1]);
+       const unsigned char *cmp = sqlite3_value_text(argv[2]);
+       const unsigned char *attr = sqlite3_value_text(argv[3]);
+       const struct ldb_attrib_handler *h;
+       struct ldb_val valX;
+       struct ldb_val valY;
+       int ret;
+
+       switch (func[0]) {
+       /* greater */
+       case '>': /* >= */
+               h = ldb_attrib_handler(ldb, attr);
+               valX.data = cmp;
+               valX.length = strlen(cmp);
+               valY.data = val;
+               valY.length = strlen(val);
+               ret = h->comparison_fn(ldb, ldb, &valY, &valX);
+               if (ret >= 0)
+                       sqlite3_result_int(ctx, 1);
+               else
+                       sqlite3_result_int(ctx, 0);
+               return;
+
+       /* lesser */
+       case '<': /* <= */
+               h = ldb_attrib_handler(ldb, attr);
+               valX.data = cmp;
+               valX.length = strlen(cmp);
+               valY.data = val;
+               valY.length = strlen(val);
+               ret = h->comparison_fn(ldb, ldb, &valY, &valX);
+               if (ret <= 0)
+                       sqlite3_result_int(ctx, 1);
+               else
+                       sqlite3_result_int(ctx, 0);
+               return;
+
+       /* approx */
+       case '~':
+               /* TODO */
+               sqlite3_result_int(ctx, 0);
+               return;
+
+       /* bitops */
+       case ':':
+               /* TODO */
+               sqlite3_result_int(ctx, 0);
+               return;
+
+       default:
+               break;
        }
 
-       el = talloc_realloc(msg, msg->elements, struct ldb_message_element, 
-                             msg->num_elements + 1);
-       if (!el) {
-               errno = ENOMEM;
-               return -1;
-       }
+       sqlite3_result_error(ctx, "Value must start with a special operation char (<>~:)!", -1);
+       return;
+}
 
-       msg->elements = el;
 
-       el = &msg->elements[msg->num_elements];
+/* rename a record */
+static int lsqlite3_safe_rollback(sqlite3 *sqlite)
+{
+       char *errmsg;
+       int ret;
 
-       el->name = talloc_strdup(msg->elements, attr);
-       if (!el->name) {
-               errno = ENOMEM;
+       /* execute */
+       ret = sqlite3_exec(sqlite, "ROLLBACK;", NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       printf("lsqlite3_safe_rollback: Error: %s\n", errmsg);
+                       free(errmsg);
+               }
                return -1;
        }
-       el->flags = 0;
 
-       el->num_values = 0;
-       el->values = talloc_array(msg->elements, struct ldb_val, count);
-       if (!el->values) {
-               errno = ENOMEM;
-               return -1;
-       }
+        return 0;
+}
 
-       for (i=0;i<count;i++) {
-               el->values[i].data = talloc_memdup(el->values, bval[i]->bv_val, bval[i]->bv_len);
-               if (!el->values[i].data) {
-                       return -1;
-               }
-               el->values[i].length = bval[i]->bv_len;
-               el->num_values++;
-       }
+/* return an eid as result */
+static int lsqlite3_eid_callback(void *result, int col_num, char **cols, char **names)
+{
+       long long *eid = (long long *)result;
 
-       msg->num_elements++;
+       if (col_num != 1) return SQLITE_ABORT;
+       if (strcasecmp(names[0], "eid") != 0) return SQLITE_ABORT;
 
-       return 0;
+       *eid = atoll(cols[0]);
+       return SQLITE_OK;
 }
-#endif
 
-static char *
-parsetree_to_sql(struct ldb_module *module,
-                          char * hTalloc,
-                          const struct ldb_parse_tree *t)
+struct lsqlite3_msgs {
+       int count;
+       struct ldb_message **msgs;
+       long long current_eid;
+       const char * const * attrs;
+       TALLOC_CTX *mem_ctx;
+};
+
+/*
+ * add a single set of ldap message values to a ldb_message
+ */
+
+static int lsqlite3_search_callback(void *result, int col_num, char **cols, char **names)
 {
-       int                     i;
-       char *                  child;
-        char *                  p;
-       char *                  ret = NULL;
-        char *                  pAttrName;
-       
+       struct lsqlite3_msgs *msgs = (struct lsqlite3_msgs *)result;
+       struct ldb_message *msg;
+       long long eid;
+       int i;
 
-       switch(t->operation) {
-               case LDB_OP_SIMPLE:
-                       break;
+       /* eid, dn, attr_name, attr_value */
+       if (col_num != 4) return SQLITE_ABORT;
 
-               case LDB_OP_AND:
-                       ret = parsetree_to_sql(module,
-                                               hTalloc,
-                                               t->u.list.elements[0]);
-
-                       for (i = 1; i < t->u.list.num_elements; i++) {
-                               child =
-                                        parsetree_to_sql(
-                                                module,
-                                                hTalloc,
-                                                t->u.list.elements[i]);
-                               ret = talloc_asprintf_append(ret,
-                                                             "INTERSECT\n"
-                                                             "%s\n",
-                                                             child);
-                               talloc_free(child);
-                       }
+       eid = atoll(cols[0]);
 
-                        child = ret;
-                        ret = talloc_asprintf("(\n"
-                                              "%s\n"
-                                              ")\n",
-                                              child);
-                        talloc_free(child);
-                       return ret;
-
-               case LDB_OP_OR:
-                       child =
-                                parsetree_to_sql(
-                                        module,
-                                        hTalloc,
-                                        t->u.list.elements[0]);
-
-                       for (i = 1; i < t->u.list.num_elements; i++) {
-                               child =
-                                        parsetree_to_sql(
-                                                module,
-                                                hTalloc,
-                                                t->u.list.elements[i]);
-                               ret = talloc_asprintf_append(ret,
-                                                             "UNION\n"
-                                                             "%s\n",
-                                                             child);
-                               talloc_free(child);
-                       }
-                        child = ret;
-                        ret = talloc_asprintf("(\n"
-                                              "%s\n"
-                                              ")\n",
-                                              child);
-                        talloc_free(child);
-                       return ret;
-
-               case LDB_OP_NOT:
-                       child =
-                                parsetree_to_sql(
-                                        module,
-                                        hTalloc,
-                                        t->u.not.child);
-                       ret = talloc_asprintf(hTalloc,
-                                              "(\n"
-                                              "  SELECT eid\n"
-                                              "    FROM ldb_entry\n"
-                                              "    WHERE eid NOT IN %s\n"
-                                              ")\n",
-                                              child);
-                       talloc_free(child);
-                       return ret;
-
-               default:
-                        /* should never occur */
-                       abort();
-       };
-       
-        /* Get a case-folded copy of the attribute name */
-        pAttrName = ldb_casefold((struct ldb_context *) module,
-                                 t->u.simple.attr);
+       if (eid != msgs->current_eid) {
+               msgs->msgs = talloc_realloc(msgs->mem_ctx,
+                                           msgs->msgs,
+                                           struct ldb_message *,
+                                           msgs->count + 2);
+               if (msgs->msgs == NULL) return SQLITE_ABORT;
 
-        /*
-         * For simple searches, we want to retrieve the list of EIDs that
-         * match the criteria.  We accomplish this by searching the
-         * appropriate table, ldb_attr_<attributeName>, for the eid
-         * corresponding to all matching values.
-         */
-        if (t->u.simple.value.length == 1 &&
-            (*(const char *) t->u.simple.value.data) == '*') {
-               /*
-                 * Special case for "attr_name=*".  In this case, we want the
-                 * eid corresponding to all values in the specified attribute
-                 * table.
-                 */
-                if ((p = sqlite3_mprintf("(\n"
-                                         "  SELECT eid\n"
-                                         "    FROM ldb_attr_%q\n"
-                                         ")\n",
-                                         pAttrName)) == NULL) {
-                        return NULL;
-                }
+               msgs->msgs[msgs->count] = talloc(msgs->msgs, struct ldb_message);
+               if (msgs->msgs[msgs->count] == NULL) return SQLITE_ABORT;
 
-                ret = talloc_strdup(hTalloc, p);
-                sqlite3_free(p);
+               msgs->msgs[msgs->count]->dn = NULL;
+               msgs->msgs[msgs->count]->num_elements = 0;
+               msgs->msgs[msgs->count]->elements = NULL;
+               msgs->msgs[msgs->count]->private_data = NULL;
 
-       } else if (strcasecmp(t->u.simple.attr, "objectclass") == 0) {
-               /*
-                 * For object classes, we want to search for all objectclasses
-                 * that are subclasses as well.
-                 */
-                if ((p = sqlite3_mprintf(
-                             "(\n"
-                             "  SELECT eid\n"
-                             "    FROM ldb_attr_objectclass\n"
-                             "    WHERE attr_name IN\n"
-                             "      (SELECT class_name\n"
-                             "         FROM ldb_objectclasses\n"
-                             "         WHERE tree_key GLOB\n"
-                             "           (SELECT tree_key\n"
-                             "              FROM ldb_objectclasses\n"
-                             "              WHERE class_name = %Q) || '*')\n"
-                             ")\n",
-                             t->u.simple.value.data)) == NULL) {
-                        return NULL;
-                }
+               msgs->count++;
+               msgs->current_eid = eid;
+       }
 
-                ret = talloc_strdup(hTalloc, p);
-                sqlite3_free(p);
-
-       } else {
-                /* A normal query. */
-                if ((p = sqlite3_mprintf("(\n"
-                                         "  SELECT eid\n"
-                                         "    FROM ldb_attr_%q\n"
-                                         "    WHERE attr_value = %Q\n"
-                                         ")\n",
-                                         pAttrName,
-                                         t->u.simple.value.data)) == NULL) {
-                        return NULL;
-                }
+       msg = msgs->msgs[msgs->count -1];
 
-                ret = talloc_strdup(hTalloc, p);
-                sqlite3_free(p);
+       if (msg->dn == NULL) {
+               msg->dn = ldb_dn_explode(msg, cols[1]);
+               if (msg->dn == NULL) return SQLITE_ABORT;
        }
-       return ret;
-}
 
+       if (msgs->attrs) {
+               int found = 0;
+               for (i = 0; msgs->attrs[i]; i++) {
+                       if (strcasecmp(cols[2], msgs->attrs[i]) == 0) {
+                               found = 1;
+                               break;
+                       }
+               }
+               if (!found) return 0;
+       }
 
-static char *
-parsetree_to_tablelist(struct ldb_module *module,
-                                char * hTalloc,
-                                const struct ldb_parse_tree *t)
-{
-#warning "obtain talloc'ed array of attribute names for table list"
-        return NULL;
+       if (ldb_msg_add_string(msg, cols[2], cols[3]) != 0)
+               return SQLITE_ABORT;
+
+       return SQLITE_OK;
 }
 
 
 /*
- * Issue a series of SQL statements to implement the ADD/MODIFY/DELETE
- * requests in the ldb_message
+ * lsqlite3_get_eid()
+ * lsqlite3_get_eid_ndn()
+ *
+ * These functions are used for the very common case of retrieving an EID value
+ * given a (normalized) DN.
  */
-static int
-msg_to_sql(struct ldb_module * module,
-           const struct ldb_message * msg,
-           long long eid,
-           int use_flags)
-{
-        int                         flags;
-        char *                      pAttrName;
-       unsigned int                i;
-        unsigned int                j;
-       struct lsqlite3_private *   lsqlite3 = module->private_data;
-
-       for (i = 0; i < msg->num_elements; i++) {
-               const struct ldb_message_element *el = &msg->elements[i];
 
-                if (! use_flags) {
-                        flags = LDB_FLAG_MOD_ADD;
-                } else {
-                        flags = el->flags & LDB_FLAG_MOD_MASK;
-                }
+static long long lsqlite3_get_eid_ndn(sqlite3 *sqlite, void *mem_ctx, const char *norm_dn)
+{
+       char *errmsg;
+       char *query;
+       long long eid = -1;
+       long long ret;
+
+       /* get object eid */
+       query = lsqlite3_tprintf(mem_ctx, "SELECT eid "
+                                         "FROM ldb_entry "
+                                         "WHERE norm_dn = '%q';", norm_dn);
+       if (query == NULL) return -1;
+
+       ret = sqlite3_exec(sqlite, query, lsqlite3_eid_callback, &eid, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       printf("lsqlite3_get_eid: Fatal Error: %s\n", errmsg);
+                       free(errmsg);
+               }
+               return -1;
+       }
 
-                /* Get a case-folded copy of the attribute name */
-                pAttrName = ldb_casefold((struct ldb_context *) module,
-                                         el->name);
+       return eid;
+}
 
-                if (flags == LDB_FLAG_MOD_ADD) {
-                        /* Create the attribute table if it doesn't exist */
-                        if (new_attr(module, pAttrName) != 0) {
-                                return -1;
-                        }
-                }
+static long long lsqlite3_get_eid(struct ldb_module *module, const struct ldb_dn *dn)
+{
+       TALLOC_CTX *local_ctx;
+       struct lsqlite3_private *lsqlite3 = module->private_data;
+       long long eid = -1;
+       char *cdn;
 
-                /* For each value of the specified attribute name... */
-               for (j = 0; j < el->num_values; j++) {
+       /* ignore ltdb specials */
+       if (ldb_dn_is_special(dn)) {
+               return -1;
+       }
 
-                        /* ... bind the attribute value, if necessary */
-                        switch (flags) {
-                        case LDB_FLAG_MOD_ADD:
-                                QUERY_NOROWS(lsqlite3,
-                                             FALSE,
-                                             "INSERT INTO ldb_attr_%q "
-                                             "    (eid, attr_value) "
-                                             "  VALUES "
-                                             "    (%lld, %Q);",
-                                             pAttrName,
-                                             eid, el->values[j].data);
-                                QUERY_NOROWS(lsqlite3,
-                                             FALSE,
-                                             "UPDATE ldb_entry "
-                                             "  SET entry_data = "
-                                             "        add_attr(entry_data, "
-                                             "                 %Q, %Q) "
-                                             "  WHERE eid = %lld;",
-                                             el->name, el->values[j].data,
-                                             eid);
-                                      
-                                break;
+       /* create a local ctx */
+       local_ctx = talloc_named(lsqlite3, 0, "lsqlite3_get_eid local context");
+       if (local_ctx == NULL) {
+               return -1;
+       }
 
-                        case LDB_FLAG_MOD_REPLACE:
-                                QUERY_NOROWS(lsqlite3,
-                                             FALSE,
-                                             "UPDATE ldb_attr_%q "
-                                             "  SET attr_value = %Q "
-                                             "  WHERE eid = %lld;",
-                                             pAttrName,
-                                             el->values[j].data,
-                                             eid);
-                                QUERY_NOROWS(lsqlite3,
-                                             FALSE,
-                                             "UPDATE ldb_entry "
-                                             "  SET entry_data = "
-                                             "        mod_attr(entry_data, "
-                                             "                 %Q, %Q) "
-                                             "  WHERE eid = %lld;",
-                                             el->name, el->values[j].data,
-                                             eid);
-                                break;
+       cdn = ldb_dn_linearize(local_ctx, ldb_dn_casefold(module->ldb, dn));
+       if (!cdn) goto done;
 
-                        case LDB_FLAG_MOD_DELETE:
-                                /* No additional parameters to this query */
-                                QUERY_NOROWS(lsqlite3,
-                                             FALSE,
-                                             "DELETE FROM ldb_attr_%q "
-                                             "  WHERE eid = %lld "
-                                             "    AND attr_value = %Q;",
-                                             pAttrName,
-                                             eid,
-                                             el->values[j].data);
-                                QUERY_NOROWS(lsqlite3,
-                                             FALSE,
-                                             "UPDATE ldb_entry "
-                                             "  SET entry_data = "
-                                             "        del_attr(entry_data, "
-                                             "                 %Q, %Q) "
-                                             "  WHERE eid = %lld;",
-                                             el->name, el->values[j].data,
-                                             eid);
-                                break;
-                        }
-               }
-       }
+       eid = lsqlite3_get_eid_ndn(lsqlite3->sqlite, local_ctx, cdn);
 
-       return 0;
+done:
+       talloc_free(local_ctx);
+       return eid;
 }
 
+/*
+ * Interface functions referenced by lsqlite3_ops
+ */
 
-
-static int
-new_dn(struct ldb_module * module,
-       char * pDN,
-       long long * pEID)
+/* search for matching records, by tree */
+static int lsqlite3_search_bytree(struct ldb_module * module, const struct ldb_dn* basedn,
+                                 enum ldb_scope scope, struct ldb_parse_tree * tree,
+                                 const char * const * attrs, struct ldb_result ** res)
 {
-        struct ldb_dn *             pExplodedDN;
-       struct ldb_context *        ldb = module->ldb;
-//     struct lsqlite3_private *   lsqlite3 = module->private_data;
-
-        /* Explode and normalize the DN */
-        if ((pExplodedDN =
-             ldb_explode_dn(ldb,
-                            pDN,
-                            ldb,
-                            case_fold_attr_required)) == NULL) {
-                return -1;
-        }
+       TALLOC_CTX *local_ctx;
+       struct lsqlite3_private *lsqlite3 = module->private_data;
+       struct lsqlite3_msgs msgs;
+       char *norm_basedn;
+       char *sqlfilter;
+       char *errmsg;
+       char *query = NULL;
+        int ret, i;
+
+       /* create a local ctx */
+       local_ctx = talloc_named(lsqlite3, 0, "lsqlite3_search_bytree local context");
+       if (local_ctx == NULL) {
+               return -1;
+       }
 
-#warning "*** new_dn() not yet fully implemented ***"
-        return -1;
-}
+       if (basedn) {
+               norm_basedn = ldb_dn_linearize(local_ctx, ldb_dn_casefold(module->ldb, basedn));
+               if (norm_basedn == NULL) {
+                       ret = LDB_ERR_INVALID_DN_SYNTAX;
+                       goto failed;
+               }
+       } else norm_basedn = talloc_strdup(local_ctx, "");
 
+       if (*norm_basedn == '\0' &&
+               (scope == LDB_SCOPE_BASE || scope == LDB_SCOPE_ONELEVEL)) {
+                       ret = LDB_ERR_UNWILLING_TO_PERFORM;
+                       goto failed;
+               }
 
-static int
-new_attr(struct ldb_module * module,
-                  char * pAttrName)
+        /* Convert filter into a series of SQL conditions (constraints) */
+       sqlfilter = parsetree_to_sql(module, local_ctx, tree);
+        
+        switch(scope) {
+        case LDB_SCOPE_DEFAULT:
+        case LDB_SCOPE_SUBTREE:
+               if (*norm_basedn != '\0') {
+                       query = lsqlite3_tprintf(local_ctx,
+                               "SELECT entry.eid,\n"
+                               "       entry.dn,\n"
+                               "       av.attr_name,\n"
+                               "       av.attr_value\n"
+                               "  FROM ldb_entry AS entry\n"
+
+                               "  LEFT OUTER JOIN ldb_attribute_values AS av\n"
+                               "    ON av.eid = entry.eid\n"
+
+                               "  WHERE entry.eid IN\n"
+                               "    (SELECT DISTINCT ldb_entry.eid\n"
+                               "       FROM ldb_entry\n"
+                               "       WHERE (ldb_entry.norm_dn GLOB('*,%q')\n"
+                               "       OR ldb_entry.norm_dn = '%q')\n"
+                               "       AND ldb_entry.eid IN\n"
+                               "         (%s)\n"
+                               "    )\n"
+
+                               "  ORDER BY entry.eid ASC;",
+                               norm_basedn,
+                               norm_basedn,
+                               sqlfilter);
+               } else {
+                       query = lsqlite3_tprintf(local_ctx,
+                               "SELECT entry.eid,\n"
+                               "       entry.dn,\n"
+                               "       av.attr_name,\n"
+                               "       av.attr_value\n"
+                               "  FROM ldb_entry AS entry\n"
+
+                               "  LEFT OUTER JOIN ldb_attribute_values AS av\n"
+                               "    ON av.eid = entry.eid\n"
+
+                               "  WHERE entry.eid IN\n"
+                               "    (SELECT DISTINCT ldb_entry.eid\n"
+                               "       FROM ldb_entry\n"
+                               "       WHERE ldb_entry.eid IN\n"
+                               "         (%s)\n"
+                               "    )\n"
+
+                               "  ORDER BY entry.eid ASC;",
+                               sqlfilter);
+               }
+
+               break;
+                
+        case LDB_SCOPE_BASE:
+                query = lsqlite3_tprintf(local_ctx,
+                        "SELECT entry.eid,\n"
+                        "       entry.dn,\n"
+                        "       av.attr_name,\n"
+                        "       av.attr_value\n"
+                        "  FROM ldb_entry AS entry\n"
+
+                        "  LEFT OUTER JOIN ldb_attribute_values AS av\n"
+                        "    ON av.eid = entry.eid\n"
+
+                        "  WHERE entry.eid IN\n"
+                        "    (SELECT DISTINCT ldb_entry.eid\n"
+                        "       FROM ldb_entry\n"
+                        "       WHERE ldb_entry.norm_dn = '%q'\n"
+                        "         AND ldb_entry.eid IN\n"
+                       "           (%s)\n"
+                        "    )\n"
+
+                        "  ORDER BY entry.eid ASC;",
+                       norm_basedn,
+                        sqlfilter);
+                break;
+                
+        case LDB_SCOPE_ONELEVEL:
+                query = lsqlite3_tprintf(local_ctx,
+                        "SELECT entry.eid,\n"
+                        "       entry.dn,\n"
+                        "       av.attr_name,\n"
+                        "       av.attr_value\n"
+                        "  FROM ldb_entry AS entry\n"
+
+                        "  LEFT OUTER JOIN ldb_attribute_values AS av\n"
+                        "    ON av.eid = entry.eid\n"
+
+                        "  WHERE entry.eid IN\n"
+                        "    (SELECT DISTINCT ldb_entry.eid\n"
+                        "       FROM ldb_entry\n"
+                       "       WHERE norm_dn GLOB('*,%q')\n"
+                       "         AND NOT norm_dn GLOB('*,*,%q')\n"
+                        "         AND ldb_entry.eid IN\n(%s)\n"
+                        "    )\n"
+
+                        "  ORDER BY entry.eid ASC;",
+                        norm_basedn,
+                        norm_basedn,
+                        sqlfilter);
+                break;
+        }
+
+        if (query == NULL) {
+                ret = LDB_ERR_OTHER;
+                goto failed;
+        }
+
+       /* * /
+       printf ("%s\n", query);
+       / * */
+
+       msgs.msgs = NULL;
+       msgs.count = 0;
+       msgs.current_eid = 0;
+       msgs.mem_ctx = local_ctx;
+       msgs.attrs = attrs;
+
+       ret = sqlite3_exec(lsqlite3->sqlite, query, lsqlite3_search_callback, &msgs, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       ldb_set_errstring(module, talloc_strdup(module, errmsg));
+                       free(errmsg);
+               }
+               ret = LDB_ERR_OTHER;
+               goto failed;
+       }
+
+       for (i = 0; i < msgs.count; i++) {
+               msgs.msgs[i] = ldb_msg_canonicalize(module->ldb, msgs.msgs[i]);
+               if (msgs.msgs[i] ==  NULL) {
+                       goto failed;
+               }
+       }
+
+       *res = talloc(module, struct ldb_result);
+       if (! *res) {
+               goto failed;
+       }
+
+       (*res)->msgs = talloc_steal(*res, msgs.msgs);
+       (*res)->count = msgs.count;
+       (*res)->refs = NULL;
+       (*res)->controls = NULL;
+
+       talloc_free(local_ctx);
+       return LDB_SUCCESS;
+
+/* If error, return error code; otherwise return number of results */
+failed:
+        talloc_free(local_ctx);
+       return LDB_ERR_OTHER;
+}
+
+
+/* add a record */
+static int lsqlite3_add(struct ldb_module *module, const struct ldb_message *msg)
+{
+       TALLOC_CTX *local_ctx;
+       struct lsqlite3_private *lsqlite3 = module->private_data;
+        long long eid;
+       char *dn, *ndn;
+       char *errmsg;
+       char *query;
+       int ret;
+       int i;
+        
+       /* create a local ctx */
+       local_ctx = talloc_named(lsqlite3, 0, "lsqlite3_add local context");
+       if (local_ctx == NULL) {
+               return LDB_ERR_OTHER;
+       }
+
+        /* See if this is an ltdb special */
+       if (ldb_dn_is_special(msg->dn)) {
+               struct ldb_dn *c;
+
+               c = ldb_dn_explode(local_ctx, "@SUBCLASSES");
+               if (ldb_dn_compare(module->ldb, msg->dn, c) == 0) {
+#warning "insert subclasses into object class tree"
+                       ret = LDB_ERR_UNWILLING_TO_PERFORM;
+                       goto failed;
+               }
+
+/*
+               c = ldb_dn_explode(local_ctx, "@INDEXLIST");
+               if (ldb_dn_compare(module->ldb, msg->dn, c) == 0) {
+#warning "should we handle indexes somehow ?"
+                       goto failed;
+               }
+*/
+                /* Others are implicitly ignored */
+                return LDB_SUCCESS;
+       }
+
+       /* create linearized and normalized dns */
+       dn = ldb_dn_linearize(local_ctx, msg->dn);
+       ndn = ldb_dn_linearize(local_ctx, ldb_dn_casefold(module->ldb, msg->dn));
+       if (dn == NULL || ndn == NULL) {
+               ret = LDB_ERR_OTHER;
+               goto failed;
+       }
+
+       query = lsqlite3_tprintf(local_ctx,
+                                  /* Add new entry */
+                                  "INSERT OR ABORT INTO ldb_entry "
+                                  "('dn', 'norm_dn') "
+                                  "VALUES ('%q', '%q');",
+                               dn, ndn);
+       if (query == NULL) {
+               ret = LDB_ERR_OTHER;
+               goto failed;
+       }
+
+       ret = sqlite3_exec(lsqlite3->sqlite, query, NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       ldb_set_errstring(module, talloc_strdup(module, errmsg));
+                       free(errmsg);
+               }
+               ret = LDB_ERR_OTHER;
+               goto failed;
+       }
+
+       eid = lsqlite3_get_eid_ndn(lsqlite3->sqlite, local_ctx, ndn);
+       if (eid == -1) {
+               ret = LDB_ERR_OTHER;
+               goto failed;
+       }
+
+       for (i = 0; i < msg->num_elements; i++) {
+               const struct ldb_message_element *el = &msg->elements[i];
+               const struct ldb_attrib_handler *h;
+               char *attr;
+               int j;
+
+               /* Get a case-folded copy of the attribute name */
+               attr = ldb_attr_casefold(module->ldb, local_ctx, el->name);
+               if (attr == NULL) {
+                       ret = LDB_ERR_OTHER;
+                       goto failed;
+               }
+
+               h = ldb_attrib_handler(module->ldb, el->name);
+
+               /* For each value of the specified attribute name... */
+               for (j = 0; j < el->num_values; j++) {
+                       struct ldb_val value;
+                       char *insert;
+
+                       /* Get a canonicalised copy of the data */
+                       h->canonicalise_fn(module->ldb, local_ctx, &(el->values[j]), &value);
+                       if (value.data == NULL) {
+                               ret = LDB_ERR_OTHER;
+                               goto failed;
+                       }
+
+                       insert = lsqlite3_tprintf(local_ctx,
+                                       "INSERT OR ROLLBACK INTO ldb_attribute_values "
+                                       "('eid', 'attr_name', 'norm_attr_name',"
+                                       " 'attr_value', 'norm_attr_value') "
+                                       "VALUES ('%lld', '%q', '%q', '%q', '%q');",
+                                       eid, el->name, attr,
+                                       el->values[j].data, value.data);
+                       if (insert == NULL) {
+                               ret = LDB_ERR_OTHER;
+                               goto failed;
+                       }
+
+                       ret = sqlite3_exec(lsqlite3->sqlite, insert, NULL, NULL, &errmsg);
+                       if (ret != SQLITE_OK) {
+                               if (errmsg) {
+                                       ldb_set_errstring(module, talloc_strdup(module, errmsg));
+                                       free(errmsg);
+                               }
+                               ret = LDB_ERR_OTHER;
+                               goto failed;
+                       }
+               }
+       }
+
+       talloc_free(local_ctx);
+        return LDB_SUCCESS;
+
+failed:
+       talloc_free(local_ctx);
+       return ret;
+}
+
+
+/* modify a record */
+static int lsqlite3_modify(struct ldb_module *module, const struct ldb_message *msg)
+{
+       TALLOC_CTX *local_ctx;
+       struct lsqlite3_private *lsqlite3 = module->private_data;
+        long long eid;
+       char *errmsg;
+       int ret;
+       int i;
+        
+       /* create a local ctx */
+       local_ctx = talloc_named(lsqlite3, 0, "lsqlite3_modify local context");
+       if (local_ctx == NULL) {
+               return LDB_ERR_OTHER;
+       }
+
+        /* See if this is an ltdb special */
+       if (ldb_dn_is_special(msg->dn)) {
+               struct ldb_dn *c;
+
+               c = ldb_dn_explode(local_ctx, "@SUBCLASSES");
+               if (ldb_dn_compare(module->ldb, msg->dn, c) == 0) {
+#warning "modify subclasses into object class tree"
+                       ret = LDB_ERR_UNWILLING_TO_PERFORM;
+                       goto failed;
+               }
+
+                /* Others are implicitly ignored */
+                return LDB_SUCCESS;
+       }
+
+       eid = lsqlite3_get_eid(module, msg->dn);
+       if (eid == -1) {
+               ret = LDB_ERR_OTHER;
+               goto failed;
+       }
+
+       for (i = 0; i < msg->num_elements; i++) {
+               const struct ldb_message_element *el = &msg->elements[i];
+               const struct ldb_attrib_handler *h;
+               int flags = el->flags & LDB_FLAG_MOD_MASK;
+               char *attr;
+               char *mod;
+               int j;
+
+               /* Get a case-folded copy of the attribute name */
+               attr = ldb_attr_casefold(module->ldb, local_ctx, el->name);
+               if (attr == NULL) {
+                       ret = LDB_ERR_OTHER;
+                       goto failed;
+               }
+
+               h = ldb_attrib_handler(module->ldb, el->name);
+
+               switch (flags) {
+
+               case LDB_FLAG_MOD_REPLACE:
+                       
+                       /* remove all attributes before adding the replacements */
+                       mod = lsqlite3_tprintf(local_ctx,
+                                               "DELETE FROM ldb_attribute_values "
+                                               "WHERE eid = '%lld' "
+                                               "AND norm_attr_name = '%q';",
+                                               eid, attr);
+                       if (mod == NULL) {
+                               ret = LDB_ERR_OTHER;
+                               goto failed;
+                       }
+
+                       ret = sqlite3_exec(lsqlite3->sqlite, mod, NULL, NULL, &errmsg);
+                       if (ret != SQLITE_OK) {
+                               if (errmsg) {
+                                       ldb_set_errstring(module, talloc_strdup(module, errmsg));
+                                       free(errmsg);
+                               }
+                               ret = LDB_ERR_OTHER;
+                               goto failed;
+                        }
+
+                       /* MISSING break is INTENTIONAL */
+
+               case LDB_FLAG_MOD_ADD:
+#warning "We should throw an error if no value is provided!"
+                       /* For each value of the specified attribute name... */
+                       for (j = 0; j < el->num_values; j++) {
+                               struct ldb_val value;
+
+                               /* Get a canonicalised copy of the data */
+                               h->canonicalise_fn(module->ldb, local_ctx, &(el->values[j]), &value);
+                               if (value.data == NULL) {
+                                       ret = LDB_ERR_OTHER;
+                                       goto failed;
+                               }
+
+                               mod = lsqlite3_tprintf(local_ctx,
+                                       "INSERT OR ROLLBACK INTO ldb_attribute_values "
+                                       "('eid', 'attr_name', 'norm_attr_name',"
+                                       " 'attr_value', 'norm_attr_value') "
+                                       "VALUES ('%lld', '%q', '%q', '%q', '%q');",
+                                       eid, el->name, attr,
+                                       el->values[j].data, value.data);
+
+                               if (mod == NULL) {
+                                       ret = LDB_ERR_OTHER;
+                                       goto failed;
+                               }
+
+                               ret = sqlite3_exec(lsqlite3->sqlite, mod, NULL, NULL, &errmsg);
+                               if (ret != SQLITE_OK) {
+                                       if (errmsg) {
+                                               ldb_set_errstring(module, talloc_strdup(module, errmsg));
+                                               free(errmsg);
+                                       }
+                                       ret = LDB_ERR_OTHER;
+                                       goto failed;
+                               }
+                       }
+
+                       break;
+
+               case LDB_FLAG_MOD_DELETE:
+#warning "We should throw an error if the attribute we are trying to delete does not exist!"
+                       if (el->num_values == 0) {
+                               mod = lsqlite3_tprintf(local_ctx,
+                                                       "DELETE FROM ldb_attribute_values "
+                                                       "WHERE eid = '%lld' "
+                                                       "AND norm_attr_name = '%q';",
+                                                       eid, attr);
+                               if (mod == NULL) {
+                                       ret = LDB_ERR_OTHER;
+                                       goto failed;
+                               }
+
+                               ret = sqlite3_exec(lsqlite3->sqlite, mod, NULL, NULL, &errmsg);
+                               if (ret != SQLITE_OK) {
+                                       if (errmsg) {
+                                               ldb_set_errstring(module, talloc_strdup(module, errmsg));
+                                               free(errmsg);
+                                       }
+                                       ret = LDB_ERR_OTHER;
+                                       goto failed;
+                               }
+                       }
+
+                       /* For each value of the specified attribute name... */
+                       for (j = 0; j < el->num_values; j++) {
+                               struct ldb_val value;
+
+                               /* Get a canonicalised copy of the data */
+                               h->canonicalise_fn(module->ldb, local_ctx, &(el->values[j]), &value);
+                               if (value.data == NULL) {
+                                       ret = LDB_ERR_OTHER;
+                                       goto failed;
+                               }
+
+                               mod = lsqlite3_tprintf(local_ctx,
+                                       "DELETE FROM ldb_attribute_values "
+                                       "WHERE eid = '%lld' "
+                                       "AND norm_attr_name = '%q' "
+                                       "AND norm_attr_value = '%q';",
+                                       eid, attr, value.data);
+
+                               if (mod == NULL) {
+                                       ret = LDB_ERR_OTHER;
+                                       goto failed;
+                               }
+
+                               ret = sqlite3_exec(lsqlite3->sqlite, mod, NULL, NULL, &errmsg);
+                               if (ret != SQLITE_OK) {
+                                       if (errmsg) {
+                                               ldb_set_errstring(module, talloc_strdup(module, errmsg));
+                                               free(errmsg);
+                                       }
+                                       ret = LDB_ERR_OTHER;
+                                       goto failed;
+                               }
+                       }
+
+                       break;
+               }
+       }
+
+       talloc_free(local_ctx);
+        return LDB_SUCCESS;
+
+failed:
+       talloc_free(local_ctx);
+       return ret;
+}
+
+/* delete a record */
+static int lsqlite3_delete(struct ldb_module *module, const struct ldb_dn *dn)
+{
+       TALLOC_CTX *local_ctx;
+       struct lsqlite3_private *lsqlite3 = module->private_data;
+        long long eid;
+       char *errmsg;
+       char *query;
+       int ret;
+
+       /* ignore ltdb specials */
+       if (ldb_dn_is_special(dn)) {
+               return LDB_SUCCESS;
+       }
+
+       /* create a local ctx */
+       local_ctx = talloc_named(lsqlite3, 0, "lsqlite3_delete local context");
+       if (local_ctx == NULL) {
+               return LDB_ERR_OTHER;
+       }
+
+       eid = lsqlite3_get_eid(module, dn);
+       if (eid == -1) {
+               ret = LDB_ERR_OTHER;
+               goto failed;
+       }
+
+       query = lsqlite3_tprintf(local_ctx,
+                                  /* Delete entry */
+                                  "DELETE FROM ldb_entry WHERE eid = %lld; "
+                                  /* Delete attributes */
+                                  "DELETE FROM ldb_attribute_values WHERE eid = %lld; ",
+                               eid, eid);
+       if (query == NULL) {
+               ret = LDB_ERR_OTHER;
+               goto failed;
+       }
+
+       ret = sqlite3_exec(lsqlite3->sqlite, query, NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       ldb_set_errstring(module, talloc_strdup(module, errmsg));
+                       free(errmsg);
+               }
+               ret = LDB_ERR_OTHER;
+               goto failed;
+       }
+
+       talloc_free(local_ctx);
+        return LDB_SUCCESS;
+
+failed:
+       talloc_free(local_ctx);
+       return ret;
+}
+
+/* rename a record */
+static int lsqlite3_rename(struct ldb_module *module, const struct ldb_dn *olddn, const struct ldb_dn *newdn)
+{
+       TALLOC_CTX *local_ctx;
+       struct lsqlite3_private *lsqlite3 = module->private_data;
+       char *new_dn, *new_cdn, *old_cdn;
+       char *errmsg;
+       char *query;
+       int ret;
+
+       /* ignore ltdb specials */
+       if (ldb_dn_is_special(olddn) || ldb_dn_is_special(newdn)) {
+               return LDB_SUCCESS;
+       }
+
+       /* create a local ctx */
+       local_ctx = talloc_named(lsqlite3, 0, "lsqlite3_rename local context");
+       if (local_ctx == NULL) {
+               return LDB_ERR_OTHER;
+       }
+
+       /* create linearized and normalized dns */
+       old_cdn = ldb_dn_linearize(local_ctx, ldb_dn_casefold(module->ldb, olddn));
+       new_cdn = ldb_dn_linearize(local_ctx, ldb_dn_casefold(module->ldb, newdn));
+       new_dn = ldb_dn_linearize(local_ctx, newdn);
+       if (old_cdn == NULL || new_cdn == NULL || new_dn == NULL) {
+               ret = LDB_ERR_OTHER;
+               goto failed;
+       }
+
+       /* build the SQL query */
+       query = lsqlite3_tprintf(local_ctx,
+                                "UPDATE ldb_entry SET dn = '%q', norm_dn = '%q' "
+                                "WHERE norm_dn = '%q';",
+                                new_dn, new_cdn, old_cdn);
+       if (query == NULL) {
+               ret = LDB_ERR_OTHER;
+               goto failed;
+       }
+
+       /* execute */
+       ret = sqlite3_exec(lsqlite3->sqlite, query, NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       ldb_set_errstring(module, talloc_strdup(module, errmsg));
+                       free(errmsg);
+               }
+               ret = LDB_ERR_OTHER;
+               goto failed;
+       }
+
+       /* clean up and exit */
+       talloc_free(local_ctx);
+        return LDB_SUCCESS;
+
+failed:
+       talloc_free(local_ctx);
+       return ret;
+}
+
+static int lsqlite3_start_trans(struct ldb_module * module)
 {
+       int ret;
+       char *errmsg;
        struct lsqlite3_private *   lsqlite3 = module->private_data;
 
-        /* NOTE: pAttrName is assumed to already be case-folded here! */
-        QUERY_NOROWS(lsqlite3,
-                     FALSE,
-                     "CREATE TABLE ldb_attr_%q "
-                     "("
-                     "  eid        INTEGER REFERENCES ldb_entry, "
-                     "  attr_value TEXT"
-                     ");",
-                     pAttrName);
+       if (lsqlite3->trans_count == 0) {
+               ret = sqlite3_exec(lsqlite3->sqlite, "BEGIN IMMEDIATE;", NULL, NULL, &errmsg);
+               if (ret != SQLITE_OK) {
+                       if (errmsg) {
+                               printf("lsqlite3_start_trans: error: %s\n", errmsg);
+                               free(errmsg);
+                       }
+                       return -1;
+               }
+       };
+
+       lsqlite3->trans_count++;
+
+       return 0;
+}
+
+static int lsqlite3_end_trans(struct ldb_module *module)
+{
+       int ret;
+       char *errmsg;
+       struct lsqlite3_private *lsqlite3 = module->private_data;
+
+       if (lsqlite3->trans_count > 0) {
+               lsqlite3->trans_count--;
+       } else return -1;
+
+       if (lsqlite3->trans_count == 0) {
+               ret = sqlite3_exec(lsqlite3->sqlite, "COMMIT;", NULL, NULL, &errmsg);
+               if (ret != SQLITE_OK) {
+                       if (errmsg) {
+                               printf("lsqlite3_end_trans: error: %s\n", errmsg);
+                               free(errmsg);
+                       }
+                       return -1;
+               }
+       }
 
         return 0;
 }
 
+static int lsqlite3_del_trans(struct ldb_module *module)
+{
+       struct lsqlite3_private *lsqlite3 = module->private_data;
+
+       if (lsqlite3->trans_count > 0) {
+               lsqlite3->trans_count--;
+       } else return -1;
+
+       if (lsqlite3->trans_count == 0) {
+               return lsqlite3_safe_rollback(lsqlite3->sqlite);
+       }
+
+       return -1;
+}
+
+/*
+ * Static functions
+ */
+
+static int initialize(struct lsqlite3_private *lsqlite3,
+                     struct ldb_context *ldb, const char *url, int flags)
+{
+       TALLOC_CTX *local_ctx;
+        long long queryInt;
+       int rollback = 0;
+       char *errmsg;
+        char *schema;
+        int ret;
+
+       /* create a local ctx */
+       local_ctx = talloc_named(lsqlite3, 0, "lsqlite3_rename local context");
+       if (local_ctx == NULL) {
+               return -1;
+       }
+
+       schema = lsqlite3_tprintf(local_ctx,
+                
+                
+                "CREATE TABLE ldb_info AS "
+                "  SELECT 'LDB' AS database_type,"
+                "         '1.0' AS version;"
+                
+                /*
+                 * The entry table holds the information about an entry. 
+                 * This table is used to obtain the EID of the entry and to 
+                 * support scope=one and scope=base.  The parent and child
+                 * table is included in the entry table since all the other
+                 * attributes are dependent on EID.
+                 */
+                "CREATE TABLE ldb_entry "
+                "("
+                "  eid     INTEGER PRIMARY KEY AUTOINCREMENT,"
+                "  dn      TEXT UNIQUE NOT NULL,"
+               "  norm_dn TEXT UNIQUE NOT NULL"
+                ");"
+                
+
+                "CREATE TABLE ldb_object_classes"
+                "("
+                "  class_name            TEXT PRIMARY KEY,"
+                "  parent_class_name     TEXT,"
+                "  tree_key              TEXT UNIQUE,"
+                "  max_child_num         INTEGER DEFAULT 0"
+                ");"
+                
+                /*
+                 * We keep a full listing of attribute/value pairs here
+                 */
+                "CREATE TABLE ldb_attribute_values"
+                "("
+                "  eid             INTEGER REFERENCES ldb_entry,"
+                "  attr_name       TEXT,"
+                "  norm_attr_name  TEXT,"
+                "  attr_value      TEXT,"
+                "  norm_attr_value TEXT "
+                ");"
+                
+               
+                /*
+                 * Indexes
+                 */
+                "CREATE INDEX ldb_attribute_values_eid_idx "
+                "  ON ldb_attribute_values (eid);"
+                
+                "CREATE INDEX ldb_attribute_values_name_value_idx "
+                "  ON ldb_attribute_values (attr_name, norm_attr_value);"
+                
+                
+
+                /*
+                 * Triggers
+                 */
+                "CREATE TRIGGER ldb_object_classes_insert_tr"
+                "  AFTER INSERT"
+                "  ON ldb_object_classes"
+                "  FOR EACH ROW"
+                "    BEGIN"
+                "      UPDATE ldb_object_classes"
+                "        SET tree_key = COALESCE(tree_key, "
+                "              ("
+                "                SELECT tree_key || "
+                "                       (SELECT base160(max_child_num + 1)"
+                "                                FROM ldb_object_classes"
+                "                                WHERE class_name = "
+                "                                      new.parent_class_name)"
+                "                  FROM ldb_object_classes "
+                "                  WHERE class_name = new.parent_class_name "
+                "              ));"
+                "      UPDATE ldb_object_classes "
+                "        SET max_child_num = max_child_num + 1"
+                "        WHERE class_name = new.parent_class_name;"
+                "    END;"
+
+                /*
+                 * Table initialization
+                 */
+
+                "INSERT INTO ldb_object_classes "
+                "    (class_name, tree_key) "
+                "  VALUES "
+                "    ('TOP', '0001');");
+        
+        /* Skip protocol indicator of url  */
+        if (strncmp(url, "sqlite://", 9) != 0) {
+                return SQLITE_MISUSE;
+        }
+        
+        /* Update pointer to just after the protocol indicator */
+        url += 9;
+        
+        /* Try to open the (possibly empty/non-existent) database */
+        if ((ret = sqlite3_open(url, &lsqlite3->sqlite)) != SQLITE_OK) {
+                return ret;
+        }
+        
+        /* In case this is a new database, enable auto_vacuum */
+       ret = sqlite3_exec(lsqlite3->sqlite, "PRAGMA auto_vacuum = 1;", NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       printf("lsqlite3 initializaion error: %s\n", errmsg);
+                       free(errmsg);
+               }
+               goto failed;
+       }
+        
+       if (flags & LDB_FLG_NOSYNC) {
+               /* DANGEROUS */
+               ret = sqlite3_exec(lsqlite3->sqlite, "PRAGMA synchronous = OFF;", NULL, NULL, &errmsg);
+               if (ret != SQLITE_OK) {
+                       if (errmsg) {
+                               printf("lsqlite3 initializaion error: %s\n", errmsg);
+                               free(errmsg);
+                       }
+                       goto failed;
+               }
+       }
+        
+       /* */
+        
+        /* Establish a busy timeout of 30 seconds */
+        if ((ret = sqlite3_busy_timeout(lsqlite3->sqlite,
+                                        30000)) != SQLITE_OK) {
+                return ret;
+        }
+
+        /* Create a function, callable from sql, to increment a tree_key */
+        if ((ret =
+             sqlite3_create_function(lsqlite3->sqlite,/* handle */
+                                     "base160_next",  /* function name */
+                                     1,               /* number of args */
+                                     SQLITE_ANY,      /* preferred text type */
+                                     NULL,            /* user data */
+                                     base160next_sql, /* called func */
+                                     NULL,            /* step func */
+                                     NULL             /* final func */
+                     )) != SQLITE_OK) {
+                return ret;
+        }
+
+        /* Create a function, callable from sql, to convert int to base160 */
+        if ((ret =
+             sqlite3_create_function(lsqlite3->sqlite,/* handle */
+                                     "base160",       /* function name */
+                                     1,               /* number of args */
+                                     SQLITE_ANY,      /* preferred text type */
+                                     NULL,            /* user data */
+                                     base160_sql,     /* called func */
+                                     NULL,            /* step func */
+                                     NULL             /* final func */
+                     )) != SQLITE_OK) {
+                return ret;
+        }
+
+        /* Create a function, callable from sql, to perform various comparisons */
+        if ((ret =
+             sqlite3_create_function(lsqlite3->sqlite, /* handle */
+                                     "ldap_compare",   /* function name */
+                                     4,                /* number of args */
+                                     SQLITE_ANY,       /* preferred text type */
+                                     ldb  ,            /* user data */
+                                     lsqlite3_compare, /* called func */
+                                     NULL,             /* step func */
+                                     NULL              /* final func */
+                     )) != SQLITE_OK) {
+                return ret;
+        }
+
+        /* Begin a transaction */
+       ret = sqlite3_exec(lsqlite3->sqlite, "BEGIN EXCLUSIVE;", NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       printf("lsqlite3: initialization error: %s\n", errmsg);
+                       free(errmsg);
+               }
+               goto failed;
+       }
+       rollback = 1;
+        /* Determine if this is a new database.  No tables means it is. */
+        if (query_int(lsqlite3,
+                      &queryInt,
+                      "SELECT COUNT(*)\n"
+                      "  FROM sqlite_master\n"
+                      "  WHERE type = 'table';") != 0) {
+               goto failed;
+        }
+        
+        if (queryInt == 0) {
+                /*
+                 * Create the database schema
+                 */
+               ret = sqlite3_exec(lsqlite3->sqlite, schema, NULL, NULL, &errmsg);
+               if (ret != SQLITE_OK) {
+                       if (errmsg) {
+                               printf("lsqlite3 initializaion error: %s\n", errmsg);
+                               free(errmsg);
+                       }
+                       goto failed;
+               }
+        } else {
+                /*
+                 * Ensure that the database we opened is one of ours
+                 */
+                if (query_int(lsqlite3,
+                              &queryInt,
+                              "SELECT "
+                              "  (SELECT COUNT(*) = 2"
+                              "     FROM sqlite_master "
+                              "     WHERE type = 'table' "
+                              "       AND name IN "
+                              "         ("
+                              "           'ldb_entry', "
+                              "           'ldb_object_classes' "
+                              "         ) "
+                              "  ) "
+                              "  AND "
+                              "  (SELECT 1 "
+                              "     FROM ldb_info "
+                              "     WHERE database_type = 'LDB' "
+                              "       AND version = '1.0'"
+                              "  );") != 0 ||
+                    queryInt != 1) {
+                        
+                        /* It's not one that we created.  See ya! */
+                       goto failed;
+                }
+        }
+        
+        /* Commit the transaction */
+       ret = sqlite3_exec(lsqlite3->sqlite, "COMMIT;", NULL, NULL, &errmsg);
+       if (ret != SQLITE_OK) {
+               if (errmsg) {
+                       printf("lsqlite3: iniialization error: %s\n", errmsg);
+                       free(errmsg);
+               }
+               goto failed;
+       }
+        return SQLITE_OK;
+
+failed:
+       if (rollback) lsqlite3_safe_rollback(lsqlite3->sqlite); 
+       sqlite3_close(lsqlite3->sqlite);
+       return -1;
+}
+
+static int
+destructor(void *p)
+{
+       struct lsqlite3_private *lsqlite3 = p;
+        
+       if (lsqlite3->sqlite) {
+               sqlite3_close(lsqlite3->sqlite);
+       }
+       return 0;
+}
+
+
+static int lsqlite3_request(struct ldb_module *module, struct ldb_request *req)
+{
+       /* check for oustanding critical controls and return an error if found */
+       if (check_critical_controls(req->controls)) {
+               return LDB_ERR_UNSUPPORTED_CRITICAL_EXTENSION;
+       }
+       
+       switch (req->operation) {
+
+       case LDB_REQ_SEARCH:
+               return lsqlite3_search_bytree(module,
+                                         req->op.search.base,
+                                         req->op.search.scope, 
+                                         req->op.search.tree, 
+                                         req->op.search.attrs, 
+                                         &req->op.search.res);
+
+       case LDB_REQ_ADD:
+               return lsqlite3_add(module, req->op.add.message);
+
+       case LDB_REQ_MODIFY:
+               return lsqlite3_modify(module, req->op.mod.message);
+
+       case LDB_REQ_DELETE:
+               return lsqlite3_delete(module, req->op.del.dn);
+
+       case LDB_REQ_RENAME:
+               return lsqlite3_rename(module,
+                                       req->op.rename.olddn,
+                                       req->op.rename.newdn);
+
+       default:
+               return LDB_ERR_OPERATIONS_ERROR;
+
+       }
+}
+
+static int lsqlite3_init_2(struct ldb_module *module)
+{
+       return LDB_SUCCESS;
+}
+
+/*
+ * Table of operations for the sqlite3 backend
+ */
+static const struct ldb_module_ops lsqlite3_ops = {
+       .name              = "sqlite",
+       .request           = lsqlite3_request,
+       .start_transaction = lsqlite3_start_trans,
+       .end_transaction   = lsqlite3_end_trans,
+       .del_transaction   = lsqlite3_del_trans,
+       .second_stage_init = lsqlite3_init_2
+};
+
+/*
+ * connect to the database
+ */
+int lsqlite3_connect(struct ldb_context *ldb,
+                    const char *url, 
+                    unsigned int flags, 
+                    const char *options[])
+{
+       int                         i;
+        int                         ret;
+       struct lsqlite3_private *   lsqlite3 = NULL;
+        
+       lsqlite3 = talloc(ldb, struct lsqlite3_private);
+       if (!lsqlite3) {
+               goto failed;
+       }
+        
+       lsqlite3->sqlite = NULL;
+       lsqlite3->options = NULL;
+       lsqlite3->trans_count = 0;
+        
+       ret = initialize(lsqlite3, ldb, url, flags);
+       if (ret != SQLITE_OK) {
+               goto failed;
+       }
+        
+       talloc_set_destructor(lsqlite3, destructor);
+        
+       ldb->modules = talloc(ldb, struct ldb_module);
+       if (!ldb->modules) {
+               goto failed;
+       }
+       ldb->modules->ldb = ldb;
+       ldb->modules->prev = ldb->modules->next = NULL;
+       ldb->modules->private_data = lsqlite3;
+       ldb->modules->ops = &lsqlite3_ops;
+        
+       if (options) {
+               /*
+                 * take a copy of the options array, so we don't have to rely
+                 * on the caller keeping it around (it might be dynamic)
+                 */
+               for (i=0;options[i];i++) ;
+                
+               lsqlite3->options = talloc_array(lsqlite3, char *, i+1);
+               if (!lsqlite3->options) {
+                       goto failed;
+               }
+                
+               for (i=0;options[i];i++) {
+                        
+                       lsqlite3->options[i+1] = NULL;
+                       lsqlite3->options[i] =
+                                talloc_strdup(lsqlite3->options, options[i]);
+                       if (!lsqlite3->options[i]) {
+                               goto failed;
+                       }
+               }
+       }
+        
+       return 0;
+        
+failed:
+        if (lsqlite3->sqlite != NULL) {
+                (void) sqlite3_close(lsqlite3->sqlite);
+        }
+       talloc_free(lsqlite3);
+       return -1;
+}
+