Home | History | Annotate | Line # | Download | only in slapd
schema_prep.c revision 1.1
      1  1.1  lukem /* schema_prep.c - load builtin schema */
      2  1.1  lukem /* $OpenLDAP: pkg/ldap/servers/slapd/schema_prep.c,v 1.169.2.6 2008/02/11 23:26:44 kurt Exp $ */
      3  1.1  lukem /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
      4  1.1  lukem  *
      5  1.1  lukem  * Copyright 1998-2008 The OpenLDAP Foundation.
      6  1.1  lukem  * All rights reserved.
      7  1.1  lukem  *
      8  1.1  lukem  * Redistribution and use in source and binary forms, with or without
      9  1.1  lukem  * modification, are permitted only as authorized by the OpenLDAP
     10  1.1  lukem  * Public License.
     11  1.1  lukem  *
     12  1.1  lukem  * A copy of this license is available in the file LICENSE in the
     13  1.1  lukem  * top-level directory of the distribution or, alternatively, at
     14  1.1  lukem  * <http://www.OpenLDAP.org/license.html>.
     15  1.1  lukem  */
     16  1.1  lukem 
     17  1.1  lukem #include "portable.h"
     18  1.1  lukem 
     19  1.1  lukem #include <stdio.h>
     20  1.1  lukem 
     21  1.1  lukem #include <ac/ctype.h>
     22  1.1  lukem #include <ac/string.h>
     23  1.1  lukem #include <ac/socket.h>
     24  1.1  lukem 
     25  1.1  lukem #include "slap.h"
     26  1.1  lukem 
     27  1.1  lukem #define OCDEBUG 0
     28  1.1  lukem 
     29  1.1  lukem int schema_init_done = 0;
     30  1.1  lukem 
     31  1.1  lukem struct slap_internal_schema slap_schema;
     32  1.1  lukem 
     33  1.1  lukem static int
     34  1.1  lukem oidValidate(
     35  1.1  lukem 	Syntax *syntax,
     36  1.1  lukem 	struct berval *in )
     37  1.1  lukem {
     38  1.1  lukem 	struct berval val = *in;
     39  1.1  lukem 
     40  1.1  lukem 	if( val.bv_len == 0 ) {
     41  1.1  lukem 		/* disallow empty strings */
     42  1.1  lukem 		return LDAP_INVALID_SYNTAX;
     43  1.1  lukem 	}
     44  1.1  lukem 
     45  1.1  lukem 	if( DESC_LEADCHAR( val.bv_val[0] ) ) {
     46  1.1  lukem 		val.bv_val++;
     47  1.1  lukem 		val.bv_len--;
     48  1.1  lukem 		if ( val.bv_len == 0 ) return LDAP_SUCCESS;
     49  1.1  lukem 
     50  1.1  lukem 		while( DESC_CHAR( val.bv_val[0] ) ) {
     51  1.1  lukem 			val.bv_val++;
     52  1.1  lukem 			val.bv_len--;
     53  1.1  lukem 
     54  1.1  lukem 			if ( val.bv_len == 0 ) return LDAP_SUCCESS;
     55  1.1  lukem 		}
     56  1.1  lukem 
     57  1.1  lukem 	} else {
     58  1.1  lukem 		int sep = 0;
     59  1.1  lukem 		while( OID_LEADCHAR( val.bv_val[0] ) ) {
     60  1.1  lukem 			val.bv_val++;
     61  1.1  lukem 			val.bv_len--;
     62  1.1  lukem 
     63  1.1  lukem 			if ( val.bv_val[-1] != '0' ) {
     64  1.1  lukem 				while ( OID_LEADCHAR( val.bv_val[0] )) {
     65  1.1  lukem 					val.bv_val++;
     66  1.1  lukem 					val.bv_len--;
     67  1.1  lukem 				}
     68  1.1  lukem 			}
     69  1.1  lukem 
     70  1.1  lukem 			if( val.bv_len == 0 ) {
     71  1.1  lukem 				if( sep == 0 ) break;
     72  1.1  lukem 				return LDAP_SUCCESS;
     73  1.1  lukem 			}
     74  1.1  lukem 
     75  1.1  lukem 			if( !OID_SEPARATOR( val.bv_val[0] )) break;
     76  1.1  lukem 
     77  1.1  lukem 			sep++;
     78  1.1  lukem 			val.bv_val++;
     79  1.1  lukem 			val.bv_len--;
     80  1.1  lukem 		}
     81  1.1  lukem 	}
     82  1.1  lukem 
     83  1.1  lukem 	return LDAP_INVALID_SYNTAX;
     84  1.1  lukem }
     85  1.1  lukem 
     86  1.1  lukem 
     87  1.1  lukem static int objectClassPretty(
     88  1.1  lukem 	Syntax *syntax,
     89  1.1  lukem 	struct berval *in,
     90  1.1  lukem 	struct berval *out,
     91  1.1  lukem 	void *ctx )
     92  1.1  lukem {
     93  1.1  lukem 	ObjectClass *oc;
     94  1.1  lukem 
     95  1.1  lukem 	if( oidValidate( NULL, in )) return LDAP_INVALID_SYNTAX;
     96  1.1  lukem 
     97  1.1  lukem 	oc = oc_bvfind( in );
     98  1.1  lukem 	if( oc == NULL ) return LDAP_INVALID_SYNTAX;
     99  1.1  lukem 
    100  1.1  lukem 	ber_dupbv_x( out, &oc->soc_cname, ctx );
    101  1.1  lukem 	return LDAP_SUCCESS;
    102  1.1  lukem }
    103  1.1  lukem 
    104  1.1  lukem static int
    105  1.1  lukem attributeTypeMatch(
    106  1.1  lukem 	int *matchp,
    107  1.1  lukem 	slap_mask_t flags,
    108  1.1  lukem 	Syntax *syntax,
    109  1.1  lukem 	MatchingRule *mr,
    110  1.1  lukem 	struct berval *value,
    111  1.1  lukem 	void *assertedValue )
    112  1.1  lukem {
    113  1.1  lukem 	struct berval *a = (struct berval *) assertedValue;
    114  1.1  lukem 	AttributeType *at = at_bvfind( value );
    115  1.1  lukem 	AttributeType *asserted = at_bvfind( a );
    116  1.1  lukem 
    117  1.1  lukem 	if( asserted == NULL ) {
    118  1.1  lukem 		if( OID_LEADCHAR( *a->bv_val ) ) {
    119  1.1  lukem 			/* OID form, return FALSE */
    120  1.1  lukem 			*matchp = 1;
    121  1.1  lukem 			return LDAP_SUCCESS;
    122  1.1  lukem 		}
    123  1.1  lukem 
    124  1.1  lukem 		/* desc form, return undefined */
    125  1.1  lukem 		return LDAP_INVALID_SYNTAX;
    126  1.1  lukem 	}
    127  1.1  lukem 
    128  1.1  lukem 	if ( at == NULL ) {
    129  1.1  lukem 		/* unrecognized stored value */
    130  1.1  lukem 		return LDAP_INVALID_SYNTAX;
    131  1.1  lukem 	}
    132  1.1  lukem 
    133  1.1  lukem 	*matchp = ( asserted != at );
    134  1.1  lukem 	return LDAP_SUCCESS;
    135  1.1  lukem }
    136  1.1  lukem 
    137  1.1  lukem static int
    138  1.1  lukem matchingRuleMatch(
    139  1.1  lukem 	int *matchp,
    140  1.1  lukem 	slap_mask_t flags,
    141  1.1  lukem 	Syntax *syntax,
    142  1.1  lukem 	MatchingRule *mr,
    143  1.1  lukem 	struct berval *value,
    144  1.1  lukem 	void *assertedValue )
    145  1.1  lukem {
    146  1.1  lukem 	struct berval *a = (struct berval *) assertedValue;
    147  1.1  lukem 	MatchingRule *mrv = mr_bvfind( value );
    148  1.1  lukem 	MatchingRule *asserted = mr_bvfind( a );
    149  1.1  lukem 
    150  1.1  lukem 	if( asserted == NULL ) {
    151  1.1  lukem 		if( OID_LEADCHAR( *a->bv_val ) ) {
    152  1.1  lukem 			/* OID form, return FALSE */
    153  1.1  lukem 			*matchp = 1;
    154  1.1  lukem 			return LDAP_SUCCESS;
    155  1.1  lukem 		}
    156  1.1  lukem 
    157  1.1  lukem 		/* desc form, return undefined */
    158  1.1  lukem 		return LDAP_INVALID_SYNTAX;
    159  1.1  lukem 	}
    160  1.1  lukem 
    161  1.1  lukem 	if ( mrv == NULL ) {
    162  1.1  lukem 		/* unrecognized stored value */
    163  1.1  lukem 		return LDAP_INVALID_SYNTAX;
    164  1.1  lukem 	}
    165  1.1  lukem 
    166  1.1  lukem 	*matchp = ( asserted != mrv );
    167  1.1  lukem 	return LDAP_SUCCESS;
    168  1.1  lukem }
    169  1.1  lukem 
    170  1.1  lukem static int
    171  1.1  lukem objectClassMatch(
    172  1.1  lukem 	int *matchp,
    173  1.1  lukem 	slap_mask_t flags,
    174  1.1  lukem 	Syntax *syntax,
    175  1.1  lukem 	MatchingRule *mr,
    176  1.1  lukem 	struct berval *value,
    177  1.1  lukem 	void *assertedValue )
    178  1.1  lukem {
    179  1.1  lukem 	struct berval *a = (struct berval *) assertedValue;
    180  1.1  lukem 	ObjectClass *oc = oc_bvfind( value );
    181  1.1  lukem 	ObjectClass *asserted = oc_bvfind( a );
    182  1.1  lukem 
    183  1.1  lukem 	if( asserted == NULL ) {
    184  1.1  lukem 		if( OID_LEADCHAR( *a->bv_val ) ) {
    185  1.1  lukem 			/* OID form, return FALSE */
    186  1.1  lukem 			*matchp = 1;
    187  1.1  lukem 			return LDAP_SUCCESS;
    188  1.1  lukem 		}
    189  1.1  lukem 
    190  1.1  lukem 		/* desc form, return undefined */
    191  1.1  lukem 		return LDAP_INVALID_SYNTAX;
    192  1.1  lukem 	}
    193  1.1  lukem 
    194  1.1  lukem 	if ( oc == NULL ) {
    195  1.1  lukem 		/* unrecognized stored value */
    196  1.1  lukem 		return LDAP_INVALID_SYNTAX;
    197  1.1  lukem 	}
    198  1.1  lukem 
    199  1.1  lukem 	*matchp = ( asserted != oc );
    200  1.1  lukem 	return LDAP_SUCCESS;
    201  1.1  lukem }
    202  1.1  lukem 
    203  1.1  lukem static int
    204  1.1  lukem objectSubClassMatch(
    205  1.1  lukem 	int *matchp,
    206  1.1  lukem 	slap_mask_t flags,
    207  1.1  lukem 	Syntax *syntax,
    208  1.1  lukem 	MatchingRule *mr,
    209  1.1  lukem 	struct berval *value,
    210  1.1  lukem 	void *assertedValue )
    211  1.1  lukem {
    212  1.1  lukem 	struct berval *a = (struct berval *) assertedValue;
    213  1.1  lukem 	ObjectClass *oc = oc_bvfind( value );
    214  1.1  lukem 	ObjectClass *asserted = oc_bvfind( a );
    215  1.1  lukem 
    216  1.1  lukem 	if( asserted == NULL ) {
    217  1.1  lukem 		if( OID_LEADCHAR( *a->bv_val ) ) {
    218  1.1  lukem 			/* OID form, return FALSE */
    219  1.1  lukem 			*matchp = 1;
    220  1.1  lukem 			return LDAP_SUCCESS;
    221  1.1  lukem 		}
    222  1.1  lukem 
    223  1.1  lukem 		/* desc form, return undefined */
    224  1.1  lukem 		return LDAP_INVALID_SYNTAX;
    225  1.1  lukem 	}
    226  1.1  lukem 
    227  1.1  lukem 	if ( oc == NULL ) {
    228  1.1  lukem 		/* unrecognized stored value */
    229  1.1  lukem 		return LDAP_INVALID_SYNTAX;
    230  1.1  lukem 	}
    231  1.1  lukem 
    232  1.1  lukem 	if( SLAP_MR_IS_VALUE_OF_ATTRIBUTE_SYNTAX( flags ) ) {
    233  1.1  lukem 		*matchp = ( asserted != oc );
    234  1.1  lukem 	} else {
    235  1.1  lukem 		*matchp = !is_object_subclass( asserted, oc );
    236  1.1  lukem 	}
    237  1.1  lukem 
    238  1.1  lukem 	return LDAP_SUCCESS;
    239  1.1  lukem }
    240  1.1  lukem 
    241  1.1  lukem static int objectSubClassIndexer(
    242  1.1  lukem 	slap_mask_t use,
    243  1.1  lukem 	slap_mask_t mask,
    244  1.1  lukem 	Syntax *syntax,
    245  1.1  lukem 	MatchingRule *mr,
    246  1.1  lukem 	struct berval *prefix,
    247  1.1  lukem 	BerVarray values,
    248  1.1  lukem 	BerVarray *keysp,
    249  1.1  lukem 	void *ctx )
    250  1.1  lukem {
    251  1.1  lukem 	int rc, noc, i;
    252  1.1  lukem 	BerVarray ocvalues;
    253  1.1  lukem 	ObjectClass **socs;
    254  1.1  lukem 
    255  1.1  lukem 	for( noc=0; values[noc].bv_val != NULL; noc++ ) {
    256  1.1  lukem 		/* just count em */;
    257  1.1  lukem 	}
    258  1.1  lukem 
    259  1.1  lukem 	/* over allocate */
    260  1.1  lukem 	socs = slap_sl_malloc( (noc+16) * sizeof( ObjectClass * ), ctx );
    261  1.1  lukem 
    262  1.1  lukem 	/* initialize */
    263  1.1  lukem 	for( i=0; i<noc; i++ ) {
    264  1.1  lukem 		socs[i] = oc_bvfind( &values[i] );
    265  1.1  lukem 	}
    266  1.1  lukem 
    267  1.1  lukem 	/* expand values */
    268  1.1  lukem 	for( i=0; i<noc; i++ ) {
    269  1.1  lukem 		int j;
    270  1.1  lukem 		ObjectClass *oc = socs[i];
    271  1.1  lukem 		if( oc == NULL || oc->soc_sups == NULL ) continue;
    272  1.1  lukem 
    273  1.1  lukem 		for( j=0; oc->soc_sups[j] != NULL; j++ ) {
    274  1.1  lukem 			int found = 0;
    275  1.1  lukem 			ObjectClass *sup = oc->soc_sups[j];
    276  1.1  lukem 			int k;
    277  1.1  lukem 
    278  1.1  lukem 			for( k=0; k<noc; k++ ) {
    279  1.1  lukem 				if( sup == socs[k] ) {
    280  1.1  lukem 					found++;
    281  1.1  lukem 					break;
    282  1.1  lukem 				}
    283  1.1  lukem 			}
    284  1.1  lukem 
    285  1.1  lukem 			if( !found ) {
    286  1.1  lukem 				socs = slap_sl_realloc( socs,
    287  1.1  lukem 					sizeof( ObjectClass * ) * (noc+2), ctx );
    288  1.1  lukem 
    289  1.1  lukem 				assert( k == noc );
    290  1.1  lukem 				socs[noc++] = sup;
    291  1.1  lukem 			}
    292  1.1  lukem 		}
    293  1.1  lukem 	}
    294  1.1  lukem 
    295  1.1  lukem 	ocvalues = slap_sl_malloc( sizeof( struct berval ) * (noc+1), ctx );
    296  1.1  lukem 	/* copy values */
    297  1.1  lukem 	for( i=0; i<noc; i++ ) {
    298  1.1  lukem 		if ( socs[i] )
    299  1.1  lukem 			ocvalues[i] = socs[i]->soc_cname;
    300  1.1  lukem 		else
    301  1.1  lukem 			ocvalues[i] = values[i];
    302  1.1  lukem 	}
    303  1.1  lukem 	BER_BVZERO( &ocvalues[i] );
    304  1.1  lukem 
    305  1.1  lukem 	rc = octetStringIndexer( use, mask, syntax, mr,
    306  1.1  lukem 		prefix, ocvalues, keysp, ctx );
    307  1.1  lukem 
    308  1.1  lukem 	slap_sl_free( ocvalues, ctx );
    309  1.1  lukem 	slap_sl_free( socs, ctx );
    310  1.1  lukem 	return rc;
    311  1.1  lukem }
    312  1.1  lukem 
    313  1.1  lukem #define objectSubClassFilter octetStringFilter
    314  1.1  lukem 
    315  1.1  lukem static ObjectClassSchemaCheckFN rootDseObjectClass;
    316  1.1  lukem static ObjectClassSchemaCheckFN aliasObjectClass;
    317  1.1  lukem static ObjectClassSchemaCheckFN referralObjectClass;
    318  1.1  lukem static ObjectClassSchemaCheckFN subentryObjectClass;
    319  1.1  lukem #ifdef LDAP_DYNAMIC_OBJECTS
    320  1.1  lukem static ObjectClassSchemaCheckFN dynamicObjectClass;
    321  1.1  lukem #endif
    322  1.1  lukem 
    323  1.1  lukem static struct slap_schema_oc_map {
    324  1.1  lukem 	char *ssom_name;
    325  1.1  lukem 	char *ssom_defn;
    326  1.1  lukem 	ObjectClassSchemaCheckFN *ssom_check;
    327  1.1  lukem 	slap_mask_t ssom_flags;
    328  1.1  lukem 	size_t ssom_offset;
    329  1.1  lukem } oc_map[] = {
    330  1.1  lukem 	{ "top", "( 2.5.6.0 NAME 'top' "
    331  1.1  lukem 			"DESC 'top of the superclass chain' "
    332  1.1  lukem 			"ABSTRACT MUST objectClass )",
    333  1.1  lukem 		0, 0, offsetof(struct slap_internal_schema, si_oc_top) },
    334  1.1  lukem 	{ "extensibleObject", "( 1.3.6.1.4.1.1466.101.120.111 "
    335  1.1  lukem 			"NAME 'extensibleObject' "
    336  1.1  lukem 			"DESC 'RFC4512: extensible object' "
    337  1.1  lukem 			"SUP top AUXILIARY )",
    338  1.1  lukem 		0, SLAP_OC_OPERATIONAL,
    339  1.1  lukem 		offsetof(struct slap_internal_schema, si_oc_extensibleObject) },
    340  1.1  lukem 	{ "alias", "( 2.5.6.1 NAME 'alias' "
    341  1.1  lukem 			"DESC 'RFC4512: an alias' "
    342  1.1  lukem 			"SUP top STRUCTURAL "
    343  1.1  lukem 			"MUST aliasedObjectName )",
    344  1.1  lukem 		aliasObjectClass, SLAP_OC_ALIAS|SLAP_OC_OPERATIONAL,
    345  1.1  lukem 		offsetof(struct slap_internal_schema, si_oc_alias) },
    346  1.1  lukem 	{ "referral", "( 2.16.840.1.113730.3.2.6 NAME 'referral' "
    347  1.1  lukem 			"DESC 'namedref: named subordinate referral' "
    348  1.1  lukem 			"SUP top STRUCTURAL MUST ref )",
    349  1.1  lukem 		referralObjectClass, SLAP_OC_REFERRAL|SLAP_OC_OPERATIONAL,
    350  1.1  lukem 		offsetof(struct slap_internal_schema, si_oc_referral) },
    351  1.1  lukem 	{ "LDAProotDSE", "( 1.3.6.1.4.1.4203.1.4.1 "
    352  1.1  lukem 			"NAME ( 'OpenLDAProotDSE' 'LDAProotDSE' ) "
    353  1.1  lukem 			"DESC 'OpenLDAP Root DSE object' "
    354  1.1  lukem 			"SUP top STRUCTURAL MAY cn )",
    355  1.1  lukem 		rootDseObjectClass, SLAP_OC_OPERATIONAL,
    356  1.1  lukem 		offsetof(struct slap_internal_schema, si_oc_rootdse) },
    357  1.1  lukem 	{ "subentry", "( 2.5.17.0 NAME 'subentry' "
    358  1.1  lukem 			"DESC 'RFC3672: subentry' "
    359  1.1  lukem 			"SUP top STRUCTURAL "
    360  1.1  lukem 			"MUST ( cn $ subtreeSpecification ) )",
    361  1.1  lukem 		subentryObjectClass, SLAP_OC_SUBENTRY|SLAP_OC_OPERATIONAL,
    362  1.1  lukem 		offsetof(struct slap_internal_schema, si_oc_subentry) },
    363  1.1  lukem 	{ "subschema", "( 2.5.20.1 NAME 'subschema' "
    364  1.1  lukem 		"DESC 'RFC4512: controlling subschema (sub)entry' "
    365  1.1  lukem 		"AUXILIARY "
    366  1.1  lukem 		"MAY ( dITStructureRules $ nameForms $ dITContentRules $ "
    367  1.1  lukem 			"objectClasses $ attributeTypes $ matchingRules $ "
    368  1.1  lukem 			"matchingRuleUse ) )",
    369  1.1  lukem 		subentryObjectClass, SLAP_OC_OPERATIONAL,
    370  1.1  lukem 		offsetof(struct slap_internal_schema, si_oc_subschema) },
    371  1.1  lukem #ifdef LDAP_COLLECTIVE_ATTRIBUTES
    372  1.1  lukem 	{ "collectiveAttributeSubentry", "( 2.5.17.2 "
    373  1.1  lukem 			"NAME 'collectiveAttributeSubentry' "
    374  1.1  lukem 			"DESC 'RFC3671: collective attribute subentry' "
    375  1.1  lukem 			"AUXILIARY )",
    376  1.1  lukem 		subentryObjectClass,
    377  1.1  lukem 		SLAP_OC_COLLECTIVEATTRIBUTESUBENTRY|SLAP_OC_OPERATIONAL|SLAP_OC_HIDE,
    378  1.1  lukem 		offsetof( struct slap_internal_schema,
    379  1.1  lukem 			si_oc_collectiveAttributeSubentry) },
    380  1.1  lukem #endif
    381  1.1  lukem #ifdef LDAP_DYNAMIC_OBJECTS
    382  1.1  lukem 	{ "dynamicObject", "( 1.3.6.1.4.1.1466.101.119.2 "
    383  1.1  lukem 			"NAME 'dynamicObject' "
    384  1.1  lukem 			"DESC 'RFC2589: Dynamic Object' "
    385  1.1  lukem 			"SUP top AUXILIARY )",
    386  1.1  lukem 		dynamicObjectClass, SLAP_OC_DYNAMICOBJECT,
    387  1.1  lukem 		offsetof(struct slap_internal_schema, si_oc_dynamicObject) },
    388  1.1  lukem #endif
    389  1.1  lukem 	{ "glue", "( 1.3.6.1.4.1.4203.666.3.4 "
    390  1.1  lukem 			"NAME 'glue' "
    391  1.1  lukem 			"DESC 'Glue Entry' "
    392  1.1  lukem 			"SUP top STRUCTURAL )",
    393  1.1  lukem 		0, SLAP_OC_GLUE|SLAP_OC_OPERATIONAL|SLAP_OC_HIDE,
    394  1.1  lukem 		offsetof(struct slap_internal_schema, si_oc_glue) },
    395  1.1  lukem 	{ "syncConsumerSubentry", "( 1.3.6.1.4.1.4203.666.3.5 "
    396  1.1  lukem 			"NAME 'syncConsumerSubentry' "
    397  1.1  lukem 			"DESC 'Persistent Info for SyncRepl Consumer' "
    398  1.1  lukem 			"AUXILIARY "
    399  1.1  lukem 			"MAY syncreplCookie )",
    400  1.1  lukem 		0, SLAP_OC_SYNCCONSUMERSUBENTRY|SLAP_OC_OPERATIONAL|SLAP_OC_HIDE,
    401  1.1  lukem 		offsetof(struct slap_internal_schema, si_oc_syncConsumerSubentry) },
    402  1.1  lukem 	{ "syncProviderSubentry", "( 1.3.6.1.4.1.4203.666.3.6 "
    403  1.1  lukem 			"NAME 'syncProviderSubentry' "
    404  1.1  lukem 			"DESC 'Persistent Info for SyncRepl Producer' "
    405  1.1  lukem 			"AUXILIARY "
    406  1.1  lukem 			"MAY contextCSN )",
    407  1.1  lukem 		0, SLAP_OC_SYNCPROVIDERSUBENTRY|SLAP_OC_OPERATIONAL|SLAP_OC_HIDE,
    408  1.1  lukem 		offsetof(struct slap_internal_schema, si_oc_syncProviderSubentry) },
    409  1.1  lukem 
    410  1.1  lukem 	{ NULL, NULL, NULL, 0, 0 }
    411  1.1  lukem };
    412  1.1  lukem 
    413  1.1  lukem static AttributeTypeSchemaCheckFN rootDseAttribute;
    414  1.1  lukem static AttributeTypeSchemaCheckFN aliasAttribute;
    415  1.1  lukem static AttributeTypeSchemaCheckFN referralAttribute;
    416  1.1  lukem static AttributeTypeSchemaCheckFN subentryAttribute;
    417  1.1  lukem static AttributeTypeSchemaCheckFN administrativeRoleAttribute;
    418  1.1  lukem #ifdef LDAP_DYNAMIC_OBJECTS
    419  1.1  lukem static AttributeTypeSchemaCheckFN dynamicAttribute;
    420  1.1  lukem #endif
    421  1.1  lukem 
    422  1.1  lukem static struct slap_schema_ad_map {
    423  1.1  lukem 	char *ssam_name;
    424  1.1  lukem 	char *ssam_defn;
    425  1.1  lukem 	AttributeTypeSchemaCheckFN *ssam_check;
    426  1.1  lukem 	slap_mask_t ssam_flags;
    427  1.1  lukem 	slap_syntax_validate_func *ssam_syn_validate;
    428  1.1  lukem 	slap_syntax_transform_func *ssam_syn_pretty;
    429  1.1  lukem 	slap_mr_convert_func *ssam_mr_convert;
    430  1.1  lukem 	slap_mr_normalize_func *ssam_mr_normalize;
    431  1.1  lukem 	slap_mr_match_func *ssam_mr_match;
    432  1.1  lukem 	slap_mr_indexer_func *ssam_mr_indexer;
    433  1.1  lukem 	slap_mr_filter_func *ssam_mr_filter;
    434  1.1  lukem 	size_t ssam_offset;
    435  1.1  lukem } ad_map[] = {
    436  1.1  lukem 	{ "objectClass", "( 2.5.4.0 NAME 'objectClass' "
    437  1.1  lukem 			"DESC 'RFC4512: object classes of the entity' "
    438  1.1  lukem 			"EQUALITY objectIdentifierMatch "
    439  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.38 )",
    440  1.1  lukem 		NULL, SLAP_AT_FINAL,
    441  1.1  lukem 		oidValidate, objectClassPretty,
    442  1.1  lukem 		NULL, NULL, objectSubClassMatch,
    443  1.1  lukem 			objectSubClassIndexer, objectSubClassFilter,
    444  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_objectClass) },
    445  1.1  lukem 
    446  1.1  lukem 	/* user entry operational attributes */
    447  1.1  lukem 	{ "structuralObjectClass", "( 2.5.21.9 NAME 'structuralObjectClass' "
    448  1.1  lukem 			"DESC 'RFC4512: structural object class of entry' "
    449  1.1  lukem 			"EQUALITY objectIdentifierMatch "
    450  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.38 "
    451  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )",
    452  1.1  lukem 		NULL, SLAP_AT_MANAGEABLE,
    453  1.1  lukem 		oidValidate, objectClassPretty,
    454  1.1  lukem 		NULL, NULL, objectSubClassMatch,
    455  1.1  lukem 			objectSubClassIndexer, objectSubClassFilter,
    456  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_structuralObjectClass) },
    457  1.1  lukem 	{ "createTimestamp", "( 2.5.18.1 NAME 'createTimestamp' "
    458  1.1  lukem 			"DESC 'RFC4512: time which object was created' "
    459  1.1  lukem 			"EQUALITY generalizedTimeMatch "
    460  1.1  lukem 			"ORDERING generalizedTimeOrderingMatch "
    461  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 "
    462  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )",
    463  1.1  lukem 		NULL, SLAP_AT_MANAGEABLE,
    464  1.1  lukem 		NULL, NULL,
    465  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    466  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_createTimestamp) },
    467  1.1  lukem 	{ "modifyTimestamp", "( 2.5.18.2 NAME 'modifyTimestamp' "
    468  1.1  lukem 			"DESC 'RFC4512: time which object was last modified' "
    469  1.1  lukem 			"EQUALITY generalizedTimeMatch "
    470  1.1  lukem 			"ORDERING generalizedTimeOrderingMatch "
    471  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 "
    472  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )",
    473  1.1  lukem 		NULL, SLAP_AT_MANAGEABLE,
    474  1.1  lukem 		NULL, NULL,
    475  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    476  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_modifyTimestamp) },
    477  1.1  lukem 	{ "creatorsName", "( 2.5.18.3 NAME 'creatorsName' "
    478  1.1  lukem 			"DESC 'RFC4512: name of creator' "
    479  1.1  lukem 			"EQUALITY distinguishedNameMatch "
    480  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 "
    481  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )",
    482  1.1  lukem 		NULL, SLAP_AT_MANAGEABLE,
    483  1.1  lukem 		NULL, NULL,
    484  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    485  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_creatorsName) },
    486  1.1  lukem 	{ "modifiersName", "( 2.5.18.4 NAME 'modifiersName' "
    487  1.1  lukem 			"DESC 'RFC4512: name of last modifier' "
    488  1.1  lukem 			"EQUALITY distinguishedNameMatch "
    489  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 "
    490  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )",
    491  1.1  lukem 		NULL, SLAP_AT_MANAGEABLE,
    492  1.1  lukem 		NULL, NULL,
    493  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    494  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_modifiersName) },
    495  1.1  lukem 	{ "hasSubordinates", "( 2.5.18.9 NAME 'hasSubordinates' "
    496  1.1  lukem 			"DESC 'X.501: entry has children' "
    497  1.1  lukem 			"EQUALITY booleanMatch "
    498  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.7 "
    499  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )",
    500  1.1  lukem 		NULL, SLAP_AT_DYNAMIC,
    501  1.1  lukem 		NULL, NULL,
    502  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    503  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_hasSubordinates) },
    504  1.1  lukem 	{ "subschemaSubentry", "( 2.5.18.10 NAME 'subschemaSubentry' "
    505  1.1  lukem 			"DESC 'RFC4512: name of controlling subschema entry' "
    506  1.1  lukem 			"EQUALITY distinguishedNameMatch "
    507  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 SINGLE-VALUE "
    508  1.1  lukem 			"NO-USER-MODIFICATION USAGE directoryOperation )",
    509  1.1  lukem 		NULL, SLAP_AT_DYNAMIC,
    510  1.1  lukem 		NULL, NULL,
    511  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    512  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_subschemaSubentry) },
    513  1.1  lukem #ifdef LDAP_COLLECTIVE_ATTRIBUTES
    514  1.1  lukem 	{ "collectiveAttributeSubentries", "( 2.5.18.12 "
    515  1.1  lukem 			"NAME 'collectiveAttributeSubentries' "
    516  1.1  lukem 			"DESC 'RFC3671: collective attribute subentries' "
    517  1.1  lukem 			"EQUALITY distinguishedNameMatch "
    518  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 "
    519  1.1  lukem 			"NO-USER-MODIFICATION USAGE directoryOperation )",
    520  1.1  lukem 		NULL, SLAP_AT_HIDE,
    521  1.1  lukem 		NULL, NULL,
    522  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    523  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_collectiveSubentries) },
    524  1.1  lukem 	{ "collectiveExclusions", "( 2.5.18.7 NAME 'collectiveExclusions' "
    525  1.1  lukem 			"DESC 'RFC3671: collective attribute exclusions' "
    526  1.1  lukem 			"EQUALITY objectIdentifierMatch "
    527  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.38 "
    528  1.1  lukem 			"USAGE directoryOperation )",
    529  1.1  lukem 		NULL, SLAP_AT_HIDE,
    530  1.1  lukem 		NULL, NULL,
    531  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    532  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_collectiveExclusions) },
    533  1.1  lukem #endif
    534  1.1  lukem 
    535  1.1  lukem 	{ "entryDN", "( 1.3.6.1.1.20 NAME 'entryDN' "
    536  1.1  lukem 			"DESC 'DN of the entry' "
    537  1.1  lukem 			"EQUALITY distinguishedNameMatch "
    538  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 "
    539  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )",
    540  1.1  lukem 		NULL, SLAP_AT_DYNAMIC,
    541  1.1  lukem 		NULL, NULL,
    542  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    543  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_entryDN) },
    544  1.1  lukem 	{ "entryUUID", "( 1.3.6.1.1.16.4 NAME 'entryUUID' "
    545  1.1  lukem 			"DESC 'UUID of the entry' "
    546  1.1  lukem 			"EQUALITY UUIDMatch "
    547  1.1  lukem 			"ORDERING UUIDOrderingMatch "
    548  1.1  lukem 			"SYNTAX 1.3.6.1.1.16.1 "
    549  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )",
    550  1.1  lukem 		NULL, SLAP_AT_MANAGEABLE,
    551  1.1  lukem 		NULL, NULL,
    552  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    553  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_entryUUID) },
    554  1.1  lukem 	{ "entryCSN", "( 1.3.6.1.4.1.4203.666.1.7 NAME 'entryCSN' "
    555  1.1  lukem 			"DESC 'change sequence number of the entry content' "
    556  1.1  lukem 			"EQUALITY CSNMatch "
    557  1.1  lukem 			"ORDERING CSNOrderingMatch "
    558  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.4203.666.11.2.1{64} "
    559  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )",
    560  1.1  lukem 		NULL, SLAP_AT_HIDE,
    561  1.1  lukem 		NULL, NULL,
    562  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    563  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_entryCSN) },
    564  1.1  lukem 	{ "namingCSN", "( 1.3.6.1.4.1.4203.666.1.13 NAME 'namingCSN' "
    565  1.1  lukem 			"DESC 'change sequence number of the entry naming (RDN)' "
    566  1.1  lukem 			"EQUALITY CSNMatch "
    567  1.1  lukem 			"ORDERING CSNOrderingMatch "
    568  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.4203.666.11.2.1{64} "
    569  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )",
    570  1.1  lukem 		NULL, SLAP_AT_HIDE,
    571  1.1  lukem 		NULL, NULL,
    572  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    573  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_namingCSN) },
    574  1.1  lukem 
    575  1.1  lukem #ifdef LDAP_SUPERIOR_UUID
    576  1.1  lukem 	{ "superiorUUID", "( 1.3.6.1.4.1.4203.666.1.11 NAME 'superiorUUID' "
    577  1.1  lukem 			"DESC 'UUID of the superior entry' "
    578  1.1  lukem 			"EQUALITY UUIDMatch "
    579  1.1  lukem 			"ORDERING UUIDOrderingMatch "
    580  1.1  lukem 			"SYNTAX 1.3.6.1.1.16.1 "
    581  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE directoryOperation )",
    582  1.1  lukem 		NULL, SLAP_AT_HIDE,
    583  1.1  lukem 		NULL, NULL,
    584  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    585  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_superiorUUID) },
    586  1.1  lukem #endif
    587  1.1  lukem 
    588  1.1  lukem 	{ "syncreplCookie", "( 1.3.6.1.4.1.4203.666.1.23 "
    589  1.1  lukem 			"NAME 'syncreplCookie' "
    590  1.1  lukem 			"DESC 'syncrepl Cookie for shadow copy' "
    591  1.1  lukem 			"EQUALITY octetStringMatch "
    592  1.1  lukem 			"ORDERING octetStringOrderingMatch "
    593  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.40 "
    594  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE dSAOperation )",
    595  1.1  lukem 		NULL, SLAP_AT_HIDE,
    596  1.1  lukem 		NULL, NULL,
    597  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    598  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_syncreplCookie) },
    599  1.1  lukem 
    600  1.1  lukem 	{ "contextCSN", "( 1.3.6.1.4.1.4203.666.1.25 "
    601  1.1  lukem 			"NAME 'contextCSN' "
    602  1.1  lukem 			"DESC 'the largest committed CSN of a context' "
    603  1.1  lukem 			"EQUALITY CSNMatch "
    604  1.1  lukem 			"ORDERING CSNOrderingMatch "
    605  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.4203.666.11.2.1{64} "
    606  1.1  lukem 			"NO-USER-MODIFICATION USAGE dSAOperation )",
    607  1.1  lukem 		NULL, SLAP_AT_HIDE,
    608  1.1  lukem 		NULL, NULL,
    609  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    610  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_contextCSN) },
    611  1.1  lukem 
    612  1.1  lukem #ifdef LDAP_SYNC_TIMESTAMP
    613  1.1  lukem 	{ "syncTimestamp", "( 1.3.6.1.4.1.4203.666.1.26 NAME 'syncTimestamp' "
    614  1.1  lukem 			"DESC 'Time which object was replicated' "
    615  1.1  lukem 			"EQUALITY generalizedTimeMatch "
    616  1.1  lukem 			"ORDERING generalizedTimeOrderingMatch "
    617  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.24 "
    618  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE dSAOperation )",
    619  1.1  lukem 		NULL, 0,
    620  1.1  lukem 		NULL, NULL,
    621  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    622  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_syncTimestamp) },
    623  1.1  lukem #endif
    624  1.1  lukem 
    625  1.1  lukem 	/* root DSE attributes */
    626  1.1  lukem 	{ "altServer", "( 1.3.6.1.4.1.1466.101.120.6 NAME 'altServer' "
    627  1.1  lukem 			"DESC 'RFC4512: alternative servers' "
    628  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.26 USAGE dSAOperation )",
    629  1.1  lukem 		rootDseAttribute, 0,
    630  1.1  lukem 		NULL, NULL,
    631  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    632  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_altServer) },
    633  1.1  lukem 	{ "namingContexts", "( 1.3.6.1.4.1.1466.101.120.5 "
    634  1.1  lukem 			"NAME 'namingContexts' "
    635  1.1  lukem 			"DESC 'RFC4512: naming contexts' "
    636  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 USAGE dSAOperation )",
    637  1.1  lukem 		rootDseAttribute, 0,
    638  1.1  lukem 		NULL, NULL,
    639  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    640  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_namingContexts) },
    641  1.1  lukem 	{ "supportedControl", "( 1.3.6.1.4.1.1466.101.120.13 "
    642  1.1  lukem 			"NAME 'supportedControl' "
    643  1.1  lukem 			"DESC 'RFC4512: supported controls' "
    644  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.38 USAGE dSAOperation )",
    645  1.1  lukem 		rootDseAttribute, 0,
    646  1.1  lukem 		NULL, NULL,
    647  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    648  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_supportedControl) },
    649  1.1  lukem 	{ "supportedExtension", "( 1.3.6.1.4.1.1466.101.120.7 "
    650  1.1  lukem 			"NAME 'supportedExtension' "
    651  1.1  lukem 			"DESC 'RFC4512: supported extended operations' "
    652  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.38 USAGE dSAOperation )",
    653  1.1  lukem 		rootDseAttribute, 0,
    654  1.1  lukem 		NULL, NULL,
    655  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    656  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_supportedExtension) },
    657  1.1  lukem 	{ "supportedLDAPVersion", "( 1.3.6.1.4.1.1466.101.120.15 "
    658  1.1  lukem 			"NAME 'supportedLDAPVersion' "
    659  1.1  lukem 			"DESC 'RFC4512: supported LDAP versions' "
    660  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 USAGE dSAOperation )",
    661  1.1  lukem 		rootDseAttribute, 0,
    662  1.1  lukem 		NULL, NULL,
    663  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    664  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_supportedLDAPVersion) },
    665  1.1  lukem 	{ "supportedSASLMechanisms", "( 1.3.6.1.4.1.1466.101.120.14 "
    666  1.1  lukem 			"NAME 'supportedSASLMechanisms' "
    667  1.1  lukem 			"DESC 'RFC4512: supported SASL mechanisms'"
    668  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 USAGE dSAOperation )",
    669  1.1  lukem 		rootDseAttribute, 0,
    670  1.1  lukem 		NULL, NULL,
    671  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    672  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_supportedSASLMechanisms) },
    673  1.1  lukem 	{ "supportedFeatures", "( 1.3.6.1.4.1.4203.1.3.5 "
    674  1.1  lukem 			"NAME 'supportedFeatures' "
    675  1.1  lukem 			"DESC 'RFC4512: features supported by the server' "
    676  1.1  lukem 			"EQUALITY objectIdentifierMatch "
    677  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.38 "
    678  1.1  lukem 			"USAGE dSAOperation )",
    679  1.1  lukem 		rootDseAttribute, 0,
    680  1.1  lukem 		NULL, NULL,
    681  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    682  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_supportedFeatures) },
    683  1.1  lukem 	{ "monitorContext", "( 1.3.6.1.4.1.4203.666.1.10 "
    684  1.1  lukem 			"NAME 'monitorContext' "
    685  1.1  lukem 			"DESC 'monitor context' "
    686  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 "
    687  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION "
    688  1.1  lukem 			"USAGE dSAOperation )",
    689  1.1  lukem 		rootDseAttribute, SLAP_AT_HIDE,
    690  1.1  lukem 		NULL, NULL,
    691  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    692  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_monitorContext) },
    693  1.1  lukem 	{ "configContext", "( 1.3.6.1.4.1.4203.666.11.1.1 "
    694  1.1  lukem 			"NAME 'configContext' "
    695  1.1  lukem 			"DESC 'config context' "
    696  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 "
    697  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION "
    698  1.1  lukem 			"USAGE dSAOperation )",
    699  1.1  lukem 		rootDseAttribute, SLAP_AT_HIDE,
    700  1.1  lukem 		NULL, NULL,
    701  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    702  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_configContext) },
    703  1.1  lukem 	{ "vendorName", "( 1.3.6.1.1.4 NAME 'vendorName' "
    704  1.1  lukem 			"DESC 'RFC3045: name of implementation vendor' "
    705  1.1  lukem 			"EQUALITY caseExactMatch "
    706  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 "
    707  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION "
    708  1.1  lukem 			"USAGE dSAOperation )",
    709  1.1  lukem 		rootDseAttribute, 0,
    710  1.1  lukem 		NULL, NULL,
    711  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    712  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_vendorName) },
    713  1.1  lukem 	{ "vendorVersion", "( 1.3.6.1.1.5 NAME 'vendorVersion' "
    714  1.1  lukem 			"DESC 'RFC3045: version of implementation' "
    715  1.1  lukem 			"EQUALITY caseExactMatch "
    716  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 "
    717  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION "
    718  1.1  lukem 			"USAGE dSAOperation )",
    719  1.1  lukem 		rootDseAttribute, 0,
    720  1.1  lukem 		NULL, NULL,
    721  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    722  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_vendorVersion) },
    723  1.1  lukem 
    724  1.1  lukem 	/* subentry attributes */
    725  1.1  lukem 	{ "administrativeRole", "( 2.5.18.5 NAME 'administrativeRole' "
    726  1.1  lukem 			"DESC 'RFC3672: administrative role' "
    727  1.1  lukem 			"EQUALITY objectIdentifierMatch "
    728  1.1  lukem 			"USAGE directoryOperation "
    729  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.38 )",
    730  1.1  lukem 		administrativeRoleAttribute, SLAP_AT_HIDE,
    731  1.1  lukem 		NULL, NULL,
    732  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    733  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_administrativeRole) },
    734  1.1  lukem 	{ "subtreeSpecification", "( 2.5.18.6 NAME 'subtreeSpecification' "
    735  1.1  lukem 			"DESC 'RFC3672: subtree specification' "
    736  1.1  lukem 			"SINGLE-VALUE "
    737  1.1  lukem 			"USAGE directoryOperation "
    738  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.45 )",
    739  1.1  lukem 		subentryAttribute, SLAP_AT_HIDE,
    740  1.1  lukem 		NULL, NULL,
    741  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    742  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_subtreeSpecification) },
    743  1.1  lukem 
    744  1.1  lukem 	/* subschema subentry attributes */
    745  1.1  lukem 	{ "dITStructureRules", "( 2.5.21.1 NAME 'dITStructureRules' "
    746  1.1  lukem 			"DESC 'RFC4512: DIT structure rules' "
    747  1.1  lukem 			"EQUALITY integerFirstComponentMatch "
    748  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.17 "
    749  1.1  lukem 			"USAGE directoryOperation ) ",
    750  1.1  lukem 		subentryAttribute, SLAP_AT_HIDE,
    751  1.1  lukem 		NULL, NULL,
    752  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    753  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_ditStructureRules) },
    754  1.1  lukem 	{ "dITContentRules", "( 2.5.21.2 NAME 'dITContentRules' "
    755  1.1  lukem 			"DESC 'RFC4512: DIT content rules' "
    756  1.1  lukem 			"EQUALITY objectIdentifierFirstComponentMatch "
    757  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.16 USAGE directoryOperation )",
    758  1.1  lukem 		subentryAttribute, SLAP_AT_HIDE,
    759  1.1  lukem 		oidValidate, NULL,
    760  1.1  lukem 		NULL, NULL, objectClassMatch, NULL, NULL,
    761  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_ditContentRules) },
    762  1.1  lukem 	{ "matchingRules", "( 2.5.21.4 NAME 'matchingRules' "
    763  1.1  lukem 			"DESC 'RFC4512: matching rules' "
    764  1.1  lukem 			"EQUALITY objectIdentifierFirstComponentMatch "
    765  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.30 USAGE directoryOperation )",
    766  1.1  lukem 		subentryAttribute, 0,
    767  1.1  lukem 		oidValidate, NULL,
    768  1.1  lukem 		NULL, NULL, matchingRuleMatch, NULL, NULL,
    769  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_matchingRules) },
    770  1.1  lukem 	{ "attributeTypes", "( 2.5.21.5 NAME 'attributeTypes' "
    771  1.1  lukem 			"DESC 'RFC4512: attribute types' "
    772  1.1  lukem 			"EQUALITY objectIdentifierFirstComponentMatch "
    773  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.3 USAGE directoryOperation )",
    774  1.1  lukem 		subentryAttribute, 0,
    775  1.1  lukem 		oidValidate, NULL,
    776  1.1  lukem 		NULL, NULL, attributeTypeMatch, NULL, NULL,
    777  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_attributeTypes) },
    778  1.1  lukem 	{ "objectClasses", "( 2.5.21.6 NAME 'objectClasses' "
    779  1.1  lukem 			"DESC 'RFC4512: object classes' "
    780  1.1  lukem 			"EQUALITY objectIdentifierFirstComponentMatch "
    781  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.37 USAGE directoryOperation )",
    782  1.1  lukem 		subentryAttribute, 0,
    783  1.1  lukem 		oidValidate, NULL,
    784  1.1  lukem 		NULL, NULL, objectClassMatch, NULL, NULL,
    785  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_objectClasses) },
    786  1.1  lukem 	{ "nameForms", "( 2.5.21.7 NAME 'nameForms' "
    787  1.1  lukem 			"DESC 'RFC4512: name forms ' "
    788  1.1  lukem 			"EQUALITY objectIdentifierFirstComponentMatch "
    789  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.35 USAGE directoryOperation )",
    790  1.1  lukem 		subentryAttribute, SLAP_AT_HIDE,
    791  1.1  lukem 		NULL, NULL,
    792  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    793  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_nameForms) },
    794  1.1  lukem 	{ "matchingRuleUse", "( 2.5.21.8 NAME 'matchingRuleUse' "
    795  1.1  lukem 			"DESC 'RFC4512: matching rule uses' "
    796  1.1  lukem 			"EQUALITY objectIdentifierFirstComponentMatch "
    797  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.31 USAGE directoryOperation )",
    798  1.1  lukem 		subentryAttribute, 0,
    799  1.1  lukem 		oidValidate, NULL,
    800  1.1  lukem 		NULL, NULL, matchingRuleMatch, NULL, NULL,
    801  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_matchingRuleUse) },
    802  1.1  lukem 
    803  1.1  lukem 	{ "ldapSyntaxes", "( 1.3.6.1.4.1.1466.101.120.16 NAME 'ldapSyntaxes' "
    804  1.1  lukem 			"DESC 'RFC4512: LDAP syntaxes' "
    805  1.1  lukem 			"EQUALITY objectIdentifierFirstComponentMatch "
    806  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.54 USAGE directoryOperation )",
    807  1.1  lukem 		subentryAttribute, 0,
    808  1.1  lukem 		NULL, NULL,
    809  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    810  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_ldapSyntaxes) },
    811  1.1  lukem 
    812  1.1  lukem 	/* knowledge information */
    813  1.1  lukem 	{ "aliasedObjectName", "( 2.5.4.1 "
    814  1.1  lukem 			"NAME ( 'aliasedObjectName' 'aliasedEntryName' ) "
    815  1.1  lukem 			"DESC 'RFC4512: name of aliased object' "
    816  1.1  lukem 			"EQUALITY distinguishedNameMatch "
    817  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 SINGLE-VALUE )",
    818  1.1  lukem 		aliasAttribute, SLAP_AT_FINAL,
    819  1.1  lukem 		NULL, NULL,
    820  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    821  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_aliasedObjectName) },
    822  1.1  lukem 	{ "ref", "( 2.16.840.1.113730.3.1.34 NAME 'ref' "
    823  1.1  lukem 			"DESC 'RFC3296: subordinate referral URL' "
    824  1.1  lukem 			"EQUALITY caseExactMatch "
    825  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 "
    826  1.1  lukem 			"USAGE distributedOperation )",
    827  1.1  lukem 		referralAttribute, 0,
    828  1.1  lukem 		NULL, NULL,
    829  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    830  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_ref) },
    831  1.1  lukem 
    832  1.1  lukem 	/* access control internals */
    833  1.1  lukem 	{ "entry", "( 1.3.6.1.4.1.4203.1.3.1 "
    834  1.1  lukem 			"NAME 'entry' "
    835  1.1  lukem 			"DESC 'OpenLDAP ACL entry pseudo-attribute' "
    836  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.4203.1.1.1 "
    837  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE dSAOperation )",
    838  1.1  lukem 		NULL, SLAP_AT_HIDE,
    839  1.1  lukem 		NULL, NULL,
    840  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    841  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_entry) },
    842  1.1  lukem 	{ "children", "( 1.3.6.1.4.1.4203.1.3.2 "
    843  1.1  lukem 			"NAME 'children' "
    844  1.1  lukem 			"DESC 'OpenLDAP ACL children pseudo-attribute' "
    845  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.4203.1.1.1 "
    846  1.1  lukem 			"SINGLE-VALUE NO-USER-MODIFICATION USAGE dSAOperation )",
    847  1.1  lukem 		NULL, SLAP_AT_HIDE,
    848  1.1  lukem 		NULL, NULL,
    849  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    850  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_children) },
    851  1.1  lukem 
    852  1.1  lukem 	/* access control externals */
    853  1.1  lukem 	{ "authzTo", "( 1.3.6.1.4.1.4203.666.1.8 "
    854  1.1  lukem 			"NAME ( 'authzTo' 'saslAuthzTo' ) "
    855  1.1  lukem 			"DESC 'proxy authorization targets' "
    856  1.1  lukem 			"EQUALITY authzMatch "
    857  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.4203.666.2.7 "
    858  1.1  lukem 			"X-ORDERED 'VALUES' "
    859  1.1  lukem 			"USAGE distributedOperation )",
    860  1.1  lukem 		NULL, SLAP_AT_HIDE,
    861  1.1  lukem 		NULL, NULL,
    862  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    863  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_saslAuthzTo) },
    864  1.1  lukem 	{ "authzFrom", "( 1.3.6.1.4.1.4203.666.1.9 "
    865  1.1  lukem 			"NAME ( 'authzFrom' 'saslAuthzFrom' ) "
    866  1.1  lukem 			"DESC 'proxy authorization sources' "
    867  1.1  lukem 			"EQUALITY authzMatch "
    868  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.4203.666.2.7 "
    869  1.1  lukem 			"X-ORDERED 'VALUES' "
    870  1.1  lukem 			"USAGE distributedOperation )",
    871  1.1  lukem 		NULL, SLAP_AT_HIDE,
    872  1.1  lukem 		NULL, NULL,
    873  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    874  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_saslAuthzFrom) },
    875  1.1  lukem 
    876  1.1  lukem #ifdef LDAP_DYNAMIC_OBJECTS
    877  1.1  lukem 	{ "entryTtl", "( 1.3.6.1.4.1.1466.101.119.3 NAME 'entryTtl' "
    878  1.1  lukem 			"DESC 'RFC2589: entry time-to-live' "
    879  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE "
    880  1.1  lukem 			"NO-USER-MODIFICATION USAGE dSAOperation )",
    881  1.1  lukem 		dynamicAttribute, SLAP_AT_MANAGEABLE,
    882  1.1  lukem 		NULL, NULL,
    883  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    884  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_entryTtl) },
    885  1.1  lukem 	{ "dynamicSubtrees", "( 1.3.6.1.4.1.1466.101.119.4 "
    886  1.1  lukem 			"NAME 'dynamicSubtrees' "
    887  1.1  lukem 			"DESC 'RFC2589: dynamic subtrees' "
    888  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 NO-USER-MODIFICATION "
    889  1.1  lukem 			"USAGE dSAOperation )",
    890  1.1  lukem 		rootDseAttribute, 0,
    891  1.1  lukem 		NULL, NULL,
    892  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    893  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_dynamicSubtrees) },
    894  1.1  lukem #endif
    895  1.1  lukem 
    896  1.1  lukem 	/* userApplication attributes (which system schema depends upon) */
    897  1.1  lukem 	{ "distinguishedName", "( 2.5.4.49 NAME 'distinguishedName' "
    898  1.1  lukem 			"DESC 'RFC4519: common supertype of DN attributes' "
    899  1.1  lukem 			"EQUALITY distinguishedNameMatch "
    900  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.12 )",
    901  1.1  lukem 		NULL, SLAP_AT_ABSTRACT,
    902  1.1  lukem 		NULL, NULL,
    903  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    904  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_distinguishedName) },
    905  1.1  lukem 	{ "name", "( 2.5.4.41 NAME 'name' "
    906  1.1  lukem 			"DESC 'RFC4519: common supertype of name attributes' "
    907  1.1  lukem 			"EQUALITY caseIgnoreMatch "
    908  1.1  lukem 			"SUBSTR caseIgnoreSubstringsMatch "
    909  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{32768} )",
    910  1.1  lukem 		NULL, SLAP_AT_ABSTRACT,
    911  1.1  lukem 		NULL, NULL,
    912  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    913  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_name) },
    914  1.1  lukem 	{ "cn", "( 2.5.4.3 NAME ( 'cn' 'commonName' ) "
    915  1.1  lukem 			"DESC 'RFC4519: common name(s) for which the entity is known by' "
    916  1.1  lukem 			"SUP name )",
    917  1.1  lukem 		NULL, 0,
    918  1.1  lukem 		NULL, NULL,
    919  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    920  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_cn) },
    921  1.1  lukem 	{ "uid", "( 0.9.2342.19200300.100.1.1 NAME ( 'uid' 'userid' ) "
    922  1.1  lukem 			"DESC 'RFC4519: user identifier' "
    923  1.1  lukem 			"EQUALITY caseIgnoreMatch "
    924  1.1  lukem 			"SUBSTR caseIgnoreSubstringsMatch "
    925  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{256} )",
    926  1.1  lukem 		NULL, 0,
    927  1.1  lukem 		NULL, NULL,
    928  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    929  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_uid) },
    930  1.1  lukem 	{ "uidNumber", /* for ldapi:// */
    931  1.1  lukem 		"( 1.3.6.1.1.1.1.0 NAME 'uidNumber' "
    932  1.1  lukem     		"DESC 'RFC2307: An integer uniquely identifying a user "
    933  1.1  lukem 				"in an administrative domain' "
    934  1.1  lukem     		"EQUALITY integerMatch "
    935  1.1  lukem     		"SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE )",
    936  1.1  lukem 		NULL, 0,
    937  1.1  lukem 		NULL, NULL,
    938  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    939  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_uidNumber) },
    940  1.1  lukem 	{ "gidNumber", /* for ldapi:// */
    941  1.1  lukem 		"( 1.3.6.1.1.1.1.1 NAME 'gidNumber' "
    942  1.1  lukem     		"DESC 'RFC2307: An integer uniquely identifying a group "
    943  1.1  lukem 				"in an administrative domain' "
    944  1.1  lukem     		"EQUALITY integerMatch "
    945  1.1  lukem     		"SYNTAX 1.3.6.1.4.1.1466.115.121.1.27 SINGLE-VALUE )",
    946  1.1  lukem 		NULL, 0,
    947  1.1  lukem 		NULL, NULL,
    948  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    949  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_gidNumber) },
    950  1.1  lukem 	{ "userPassword", "( 2.5.4.35 NAME 'userPassword' "
    951  1.1  lukem 			"DESC 'RFC4519/2307: password of user' "
    952  1.1  lukem 			"EQUALITY octetStringMatch "
    953  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.40{128} )",
    954  1.1  lukem 		NULL, 0,
    955  1.1  lukem 		NULL, NULL,
    956  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    957  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_userPassword) },
    958  1.1  lukem 
    959  1.1  lukem 	{ "labeledURI", "( 1.3.6.1.4.1.250.1.57 NAME 'labeledURI' "
    960  1.1  lukem 			"DESC 'RFC2079: Uniform Resource Identifier with optional label' "
    961  1.1  lukem 			"EQUALITY caseExactMatch "
    962  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.15 )",
    963  1.1  lukem 		NULL, 0,
    964  1.1  lukem 		NULL, NULL,
    965  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    966  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_labeledURI) },
    967  1.1  lukem 
    968  1.1  lukem #ifdef SLAPD_AUTHPASSWD
    969  1.1  lukem 	{ "authPassword", "( 1.3.6.1.4.1.4203.1.3.4 "
    970  1.1  lukem 			"NAME 'authPassword' "
    971  1.1  lukem 			"DESC 'RFC3112: authentication password attribute' "
    972  1.1  lukem 			"EQUALITY 1.3.6.1.4.1.4203.1.2.2 "
    973  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.4203.1.1.2 )",
    974  1.1  lukem 		NULL, 0,
    975  1.1  lukem 		NULL, NULL,
    976  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    977  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_authPassword) },
    978  1.1  lukem 	{ "supportedAuthPasswordSchemes", "( 1.3.6.1.4.1.4203.1.3.3 "
    979  1.1  lukem 			"NAME 'supportedAuthPasswordSchemes' "
    980  1.1  lukem 			"DESC 'RFC3112: supported authPassword schemes' "
    981  1.1  lukem 			"EQUALITY caseExactIA5Match "
    982  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.26{32} "
    983  1.1  lukem 			"USAGE dSAOperation )",
    984  1.1  lukem 		subschemaAttribute, 0,
    985  1.1  lukem 		NULL, NULL,
    986  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    987  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_authPasswordSchemes) },
    988  1.1  lukem #endif
    989  1.1  lukem 
    990  1.1  lukem 	{ "description", "( 2.5.4.13 NAME 'description' "
    991  1.1  lukem 			"DESC 'RFC4519: descriptive information' "
    992  1.1  lukem 			"EQUALITY caseIgnoreMatch "
    993  1.1  lukem 			"SUBSTR caseIgnoreSubstringsMatch "
    994  1.1  lukem 			"SYNTAX 1.3.6.1.4.1.1466.115.121.1.15{1024} )",
    995  1.1  lukem 		NULL, 0,
    996  1.1  lukem 		NULL, NULL,
    997  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
    998  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_description) },
    999  1.1  lukem 
   1000  1.1  lukem 	{ "seeAlso", "( 2.5.4.34 NAME 'seeAlso' "
   1001  1.1  lukem 			"DESC 'RFC4519: DN of related object' "
   1002  1.1  lukem 			"SUP distinguishedName )",
   1003  1.1  lukem 		NULL, 0,
   1004  1.1  lukem 		NULL, NULL,
   1005  1.1  lukem 		NULL, NULL, NULL, NULL, NULL,
   1006  1.1  lukem 		offsetof(struct slap_internal_schema, si_ad_seeAlso) },
   1007  1.1  lukem 
   1008  1.1  lukem 	{ NULL, NULL, NULL, 0, NULL, NULL, NULL, NULL, NULL, NULL, NULL, 0 }
   1009  1.1  lukem };
   1010  1.1  lukem 
   1011  1.1  lukem static AttributeType slap_at_undefined = {
   1012  1.1  lukem 	{ "1.1.1", NULL, "Catchall for undefined attribute types", 1, NULL,
   1013  1.1  lukem 		NULL, NULL, NULL, NULL,
   1014  1.1  lukem 		0, 0, 0, 1, LDAP_SCHEMA_DSA_OPERATION, NULL }, /* LDAPAttributeType */
   1015  1.1  lukem 	BER_BVC("UNDEFINED"), /* cname */
   1016  1.1  lukem 	NULL, /* sup */
   1017  1.1  lukem 	NULL, /* subtypes */
   1018  1.1  lukem 	NULL, NULL, NULL, NULL,	/* matching rules routines */
   1019  1.1  lukem 	NULL, /* syntax (will be set later to "octetString") */
   1020  1.1  lukem 	NULL, /* schema check function */
   1021  1.1  lukem 	NULL, /* oidmacro */
   1022  1.1  lukem 	SLAP_AT_ABSTRACT|SLAP_AT_FINAL,	/* mask */
   1023  1.1  lukem 	{ NULL }, /* next */
   1024  1.1  lukem 	NULL /* attribute description */
   1025  1.1  lukem 	/* mutex (don't know how to initialize it :) */
   1026  1.1  lukem };
   1027  1.1  lukem 
   1028  1.1  lukem static AttributeType slap_at_proxied = {
   1029  1.1  lukem 	{ "1.1.1", NULL, "Catchall for undefined proxied attribute types", 1, NULL,
   1030  1.1  lukem 		NULL, NULL, NULL, NULL,
   1031  1.1  lukem 		0, 0, 0, 0, LDAP_SCHEMA_USER_APPLICATIONS, NULL }, /* LDAPAttributeType */
   1032  1.1  lukem 	BER_BVC("PROXIED"), /* cname */
   1033  1.1  lukem 	NULL, /* sup */
   1034  1.1  lukem 	NULL, /* subtypes */
   1035  1.1  lukem 	NULL, NULL, NULL, NULL,	/* matching rules routines (will be set later) */
   1036  1.1  lukem 	NULL, /* syntax (will be set later to "octetString") */
   1037  1.1  lukem 	NULL, /* schema check function */
   1038  1.1  lukem 	NULL, /* oidmacro */
   1039  1.1  lukem 	SLAP_AT_ABSTRACT|SLAP_AT_FINAL,	/* mask */
   1040  1.1  lukem 	{ NULL }, /* next */
   1041  1.1  lukem 	NULL /* attribute description */
   1042  1.1  lukem 	/* mutex (don't know how to initialize it :) */
   1043  1.1  lukem };
   1044  1.1  lukem 
   1045  1.1  lukem static struct slap_schema_mr_map {
   1046  1.1  lukem 	char *ssmm_name;
   1047  1.1  lukem 	size_t ssmm_offset;
   1048  1.1  lukem } mr_map[] = {
   1049  1.1  lukem 	{ "caseExactIA5Match",
   1050  1.1  lukem 		offsetof(struct slap_internal_schema, si_mr_caseExactIA5Match) },
   1051  1.1  lukem 	{ "caseExactMatch",
   1052  1.1  lukem 		offsetof(struct slap_internal_schema, si_mr_caseExactMatch) },
   1053  1.1  lukem 	{ "caseExactSubstringsMatch",
   1054  1.1  lukem 		offsetof(struct slap_internal_schema, si_mr_caseExactSubstringsMatch) },
   1055  1.1  lukem 	{ "distinguishedNameMatch",
   1056  1.1  lukem 		offsetof(struct slap_internal_schema, si_mr_distinguishedNameMatch) },
   1057  1.1  lukem 	{ "dnSubtreeMatch",
   1058  1.1  lukem 		offsetof(struct slap_internal_schema, si_mr_dnSubtreeMatch) },
   1059  1.1  lukem 	{ "dnOneLevelMatch",
   1060  1.1  lukem 		offsetof(struct slap_internal_schema, si_mr_dnOneLevelMatch) },
   1061  1.1  lukem 	{ "dnSubordinateMatch",
   1062  1.1  lukem 		offsetof(struct slap_internal_schema, si_mr_dnSubordinateMatch) },
   1063  1.1  lukem 	{ "dnSuperiorMatch",
   1064  1.1  lukem 		offsetof(struct slap_internal_schema, si_mr_dnSuperiorMatch) },
   1065  1.1  lukem 	{ "integerMatch",
   1066  1.1  lukem 		offsetof(struct slap_internal_schema, si_mr_integerMatch) },
   1067  1.1  lukem 	{ "integerFirstComponentMatch",
   1068  1.1  lukem 		offsetof(struct slap_internal_schema,
   1069  1.1  lukem 			si_mr_integerFirstComponentMatch) },
   1070  1.1  lukem 	{ "objectIdentifierFirstComponentMatch",
   1071  1.1  lukem 		offsetof(struct slap_internal_schema,
   1072  1.1  lukem 			si_mr_objectIdentifierFirstComponentMatch) },
   1073  1.1  lukem 	{ NULL, 0 }
   1074  1.1  lukem };
   1075  1.1  lukem 
   1076  1.1  lukem static struct slap_schema_syn_map {
   1077  1.1  lukem 	char *sssm_name;
   1078  1.1  lukem 	size_t sssm_offset;
   1079  1.1  lukem } syn_map[] = {
   1080  1.1  lukem 	{ "1.3.6.1.4.1.1466.115.121.1.15",
   1081  1.1  lukem 		offsetof(struct slap_internal_schema, si_syn_directoryString) },
   1082  1.1  lukem 	{ "1.3.6.1.4.1.1466.115.121.1.12",
   1083  1.1  lukem 		offsetof(struct slap_internal_schema, si_syn_distinguishedName) },
   1084  1.1  lukem 	{ "1.3.6.1.4.1.1466.115.121.1.27",
   1085  1.1  lukem 		offsetof(struct slap_internal_schema, si_syn_integer) },
   1086  1.1  lukem 	{ "1.3.6.1.4.1.1466.115.121.1.40",
   1087  1.1  lukem 		offsetof(struct slap_internal_schema, si_syn_octetString) },
   1088  1.1  lukem 	{ "1.3.6.1.4.1.1466.115.121.1.3",
   1089  1.1  lukem 		offsetof(struct slap_internal_schema, si_syn_attributeTypeDesc) },
   1090  1.1  lukem 	{ "1.3.6.1.4.1.1466.115.121.1.16",
   1091  1.1  lukem 		offsetof(struct slap_internal_schema, si_syn_ditContentRuleDesc) },
   1092  1.1  lukem 	{ "1.3.6.1.4.1.1466.115.121.1.54",
   1093  1.1  lukem 		offsetof(struct slap_internal_schema, si_syn_ldapSyntaxDesc) },
   1094  1.1  lukem 	{ "1.3.6.1.4.1.1466.115.121.1.30",
   1095  1.1  lukem 		offsetof(struct slap_internal_schema, si_syn_matchingRuleDesc) },
   1096  1.1  lukem 	{ "1.3.6.1.4.1.1466.115.121.1.31",
   1097  1.1  lukem 		offsetof(struct slap_internal_schema, si_syn_matchingRuleUseDesc) },
   1098  1.1  lukem 	{ "1.3.6.1.4.1.1466.115.121.1.35",
   1099  1.1  lukem 		offsetof(struct slap_internal_schema, si_syn_nameFormDesc) },
   1100  1.1  lukem 	{ "1.3.6.1.4.1.1466.115.121.1.37",
   1101  1.1  lukem 		offsetof(struct slap_internal_schema, si_syn_objectClassDesc) },
   1102  1.1  lukem 	{ "1.3.6.1.4.1.1466.115.121.1.17",
   1103  1.1  lukem 		offsetof(struct slap_internal_schema, si_syn_ditStructureRuleDesc) },
   1104  1.1  lukem 	{ NULL, 0 }
   1105  1.1  lukem };
   1106  1.1  lukem 
   1107  1.1  lukem int
   1108  1.1  lukem slap_schema_load( void )
   1109  1.1  lukem {
   1110  1.1  lukem 	int i;
   1111  1.1  lukem 
   1112  1.1  lukem 	for( i=0; syn_map[i].sssm_name; i++ ) {
   1113  1.1  lukem 		Syntax ** synp = (Syntax **)
   1114  1.1  lukem 			&(((char *) &slap_schema)[syn_map[i].sssm_offset]);
   1115  1.1  lukem 
   1116  1.1  lukem 		assert( *synp == NULL );
   1117  1.1  lukem 
   1118  1.1  lukem 		*synp = syn_find( syn_map[i].sssm_name );
   1119  1.1  lukem 
   1120  1.1  lukem 		if( *synp == NULL ) {
   1121  1.1  lukem 			fprintf( stderr, "slap_schema_load: Syntax: "
   1122  1.1  lukem 				"No syntax \"%s\" defined in schema\n",
   1123  1.1  lukem 				syn_map[i].sssm_name );
   1124  1.1  lukem 			return LDAP_INVALID_SYNTAX;
   1125  1.1  lukem 		}
   1126  1.1  lukem 	}
   1127  1.1  lukem 
   1128  1.1  lukem 	for( i=0; mr_map[i].ssmm_name; i++ ) {
   1129  1.1  lukem 		MatchingRule ** mrp = (MatchingRule **)
   1130  1.1  lukem 			&(((char *) &slap_schema)[mr_map[i].ssmm_offset]);
   1131  1.1  lukem 
   1132  1.1  lukem 		assert( *mrp == NULL );
   1133  1.1  lukem 
   1134  1.1  lukem 		*mrp = mr_find( mr_map[i].ssmm_name );
   1135  1.1  lukem 
   1136  1.1  lukem 		if( *mrp == NULL ) {
   1137  1.1  lukem 			fprintf( stderr, "slap_schema_load: MatchingRule: "
   1138  1.1  lukem 				"No matching rule \"%s\" defined in schema\n",
   1139  1.1  lukem 				mr_map[i].ssmm_name );
   1140  1.1  lukem 			return LDAP_INAPPROPRIATE_MATCHING;
   1141  1.1  lukem 		}
   1142  1.1  lukem 	}
   1143  1.1  lukem 
   1144  1.1  lukem 	slap_at_undefined.sat_syntax = slap_schema.si_syn_octetString;
   1145  1.1  lukem 	slap_schema.si_at_undefined = &slap_at_undefined;
   1146  1.1  lukem 
   1147  1.1  lukem 	slap_at_proxied.sat_equality = mr_find( "octetStringMatch" );
   1148  1.1  lukem 	slap_at_proxied.sat_approx = mr_find( "octetStringMatch" );
   1149  1.1  lukem 	slap_at_proxied.sat_ordering = mr_find( "octetStringOrderingMatch" );
   1150  1.1  lukem 	slap_at_proxied.sat_substr = mr_find( "octetStringSubstringsMatch" );
   1151  1.1  lukem 	slap_at_proxied.sat_syntax = slap_schema.si_syn_octetString;
   1152  1.1  lukem 	slap_schema.si_at_proxied = &slap_at_proxied;
   1153  1.1  lukem 
   1154  1.1  lukem 	ldap_pvt_thread_mutex_init( &ad_undef_mutex );
   1155  1.1  lukem 	ldap_pvt_thread_mutex_init( &oc_undef_mutex );
   1156  1.1  lukem 
   1157  1.1  lukem 	for( i=0; ad_map[i].ssam_name; i++ ) {
   1158  1.1  lukem 		assert( ad_map[i].ssam_defn != NULL );
   1159  1.1  lukem 		{
   1160  1.1  lukem 			LDAPAttributeType *at;
   1161  1.1  lukem 			int		code;
   1162  1.1  lukem 			const char	*err;
   1163  1.1  lukem 
   1164  1.1  lukem 			at = ldap_str2attributetype( ad_map[i].ssam_defn,
   1165  1.1  lukem 				&code, &err, LDAP_SCHEMA_ALLOW_ALL );
   1166  1.1  lukem 			if ( !at ) {
   1167  1.1  lukem 				fprintf( stderr,
   1168  1.1  lukem 					"slap_schema_load: AttributeType \"%s\": %s before %s\n",
   1169  1.1  lukem 					 ad_map[i].ssam_name, ldap_scherr2str(code), err );
   1170  1.1  lukem 				return code;
   1171  1.1  lukem 			}
   1172  1.1  lukem 
   1173  1.1  lukem 			if ( at->at_oid == NULL ) {
   1174  1.1  lukem 				fprintf( stderr, "slap_schema_load: "
   1175  1.1  lukem 					"AttributeType \"%s\": no OID\n",
   1176  1.1  lukem 					ad_map[i].ssam_name );
   1177  1.1  lukem 				ldap_attributetype_free( at );
   1178  1.1  lukem 				return LDAP_OTHER;
   1179  1.1  lukem 			}
   1180  1.1  lukem 
   1181  1.1  lukem 			code = at_add( at, 0, NULL, NULL, &err );
   1182  1.1  lukem 			if ( code ) {
   1183  1.1  lukem 				ldap_attributetype_free( at );
   1184  1.1  lukem 				fprintf( stderr, "slap_schema_load: AttributeType "
   1185  1.1  lukem 					"\"%s\": %s: \"%s\"\n",
   1186  1.1  lukem 					 ad_map[i].ssam_name, scherr2str(code), err );
   1187  1.1  lukem 				return code;
   1188  1.1  lukem 			}
   1189  1.1  lukem 			ldap_memfree( at );
   1190  1.1  lukem 		}
   1191  1.1  lukem 		{
   1192  1.1  lukem 			int rc;
   1193  1.1  lukem 			const char *text;
   1194  1.1  lukem 			Syntax *syntax = NULL;
   1195  1.1  lukem 
   1196  1.1  lukem 			AttributeDescription ** adp = (AttributeDescription **)
   1197  1.1  lukem 				&(((char *) &slap_schema)[ad_map[i].ssam_offset]);
   1198  1.1  lukem 
   1199  1.1  lukem 			assert( *adp == NULL );
   1200  1.1  lukem 
   1201  1.1  lukem 			rc = slap_str2ad( ad_map[i].ssam_name, adp, &text );
   1202  1.1  lukem 			if( rc != LDAP_SUCCESS ) {
   1203  1.1  lukem 				fprintf( stderr, "slap_schema_load: AttributeType \"%s\": "
   1204  1.1  lukem 					"not defined in schema\n",
   1205  1.1  lukem 					ad_map[i].ssam_name );
   1206  1.1  lukem 				return rc;
   1207  1.1  lukem 			}
   1208  1.1  lukem 
   1209  1.1  lukem 			if( ad_map[i].ssam_check ) {
   1210  1.1  lukem 				/* install check routine */
   1211  1.1  lukem 				(*adp)->ad_type->sat_check = ad_map[i].ssam_check;
   1212  1.1  lukem 			}
   1213  1.1  lukem 			/* install flags */
   1214  1.1  lukem 			(*adp)->ad_type->sat_flags |= ad_map[i].ssam_flags;
   1215  1.1  lukem 
   1216  1.1  lukem 			/* install custom syntax routines */
   1217  1.1  lukem 			if( ad_map[i].ssam_syn_validate ||
   1218  1.1  lukem 				ad_map[i].ssam_syn_pretty )
   1219  1.1  lukem 			{
   1220  1.1  lukem 				Syntax *syn;
   1221  1.1  lukem 
   1222  1.1  lukem 				syntax = (*adp)->ad_type->sat_syntax;
   1223  1.1  lukem 
   1224  1.1  lukem 				syn = ch_malloc( sizeof( Syntax ) );
   1225  1.1  lukem 				*syn = *syntax;
   1226  1.1  lukem 
   1227  1.1  lukem 				if( ad_map[i].ssam_syn_validate ) {
   1228  1.1  lukem 					syn->ssyn_validate = ad_map[i].ssam_syn_validate;
   1229  1.1  lukem 				}
   1230  1.1  lukem 				if( ad_map[i].ssam_syn_pretty ) {
   1231  1.1  lukem 					syn->ssyn_pretty = ad_map[i].ssam_syn_pretty;
   1232  1.1  lukem 				}
   1233  1.1  lukem 
   1234  1.1  lukem 				(*adp)->ad_type->sat_syntax = syn;
   1235  1.1  lukem 			}
   1236  1.1  lukem 
   1237  1.1  lukem 			/* install custom rule routines */
   1238  1.1  lukem 			if( syntax != NULL ||
   1239  1.1  lukem 				ad_map[i].ssam_mr_convert ||
   1240  1.1  lukem 				ad_map[i].ssam_mr_normalize ||
   1241  1.1  lukem 				ad_map[i].ssam_mr_match ||
   1242  1.1  lukem 				ad_map[i].ssam_mr_indexer ||
   1243  1.1  lukem 				ad_map[i].ssam_mr_filter )
   1244  1.1  lukem 			{
   1245  1.1  lukem 				MatchingRule *mr = ch_malloc( sizeof( MatchingRule ) );
   1246  1.1  lukem 				*mr = *(*adp)->ad_type->sat_equality;
   1247  1.1  lukem 
   1248  1.1  lukem 				if ( syntax != NULL ) {
   1249  1.1  lukem 					mr->smr_syntax = (*adp)->ad_type->sat_syntax;
   1250  1.1  lukem 				}
   1251  1.1  lukem 				if ( ad_map[i].ssam_mr_convert ) {
   1252  1.1  lukem 					mr->smr_convert = ad_map[i].ssam_mr_convert;
   1253  1.1  lukem 				}
   1254  1.1  lukem 				if ( ad_map[i].ssam_mr_normalize ) {
   1255  1.1  lukem 					mr->smr_normalize = ad_map[i].ssam_mr_normalize;
   1256  1.1  lukem 				}
   1257  1.1  lukem 				if ( ad_map[i].ssam_mr_match ) {
   1258  1.1  lukem 					mr->smr_match = ad_map[i].ssam_mr_match;
   1259  1.1  lukem 				}
   1260  1.1  lukem 				if ( ad_map[i].ssam_mr_indexer ) {
   1261  1.1  lukem 					mr->smr_indexer = ad_map[i].ssam_mr_indexer;
   1262  1.1  lukem 				}
   1263  1.1  lukem 				if ( ad_map[i].ssam_mr_filter ) {
   1264  1.1  lukem 					mr->smr_filter = ad_map[i].ssam_mr_filter;
   1265  1.1  lukem 				}
   1266  1.1  lukem 
   1267  1.1  lukem 				/* FIXME: no-one will free this at exit */
   1268  1.1  lukem 				(*adp)->ad_type->sat_equality = mr;
   1269  1.1  lukem 			}
   1270  1.1  lukem 		}
   1271  1.1  lukem 	}
   1272  1.1  lukem 
   1273  1.1  lukem 	for( i=0; oc_map[i].ssom_name; i++ ) {
   1274  1.1  lukem 		assert( oc_map[i].ssom_defn != NULL );
   1275  1.1  lukem 		{
   1276  1.1  lukem 			LDAPObjectClass *oc;
   1277  1.1  lukem 			int		code;
   1278  1.1  lukem 			const char	*err;
   1279  1.1  lukem 
   1280  1.1  lukem 			oc = ldap_str2objectclass( oc_map[i].ssom_defn, &code, &err,
   1281  1.1  lukem 				LDAP_SCHEMA_ALLOW_ALL );
   1282  1.1  lukem 			if ( !oc ) {
   1283  1.1  lukem 				fprintf( stderr, "slap_schema_load: ObjectClass "
   1284  1.1  lukem 					"\"%s\": %s before %s\n",
   1285  1.1  lukem 				 	oc_map[i].ssom_name, ldap_scherr2str(code), err );
   1286  1.1  lukem 				return code;
   1287  1.1  lukem 			}
   1288  1.1  lukem 
   1289  1.1  lukem 			if ( oc->oc_oid == NULL ) {
   1290  1.1  lukem 				fprintf( stderr, "slap_schema_load: ObjectClass "
   1291  1.1  lukem 					"\"%s\": no OID\n",
   1292  1.1  lukem 					oc_map[i].ssom_name );
   1293  1.1  lukem 				ldap_objectclass_free( oc );
   1294  1.1  lukem 				return LDAP_OTHER;
   1295  1.1  lukem 			}
   1296  1.1  lukem 
   1297  1.1  lukem 			code = oc_add(oc,0,NULL,NULL,&err);
   1298  1.1  lukem 			if ( code ) {
   1299  1.1  lukem 				ldap_objectclass_free( oc );
   1300  1.1  lukem 				fprintf( stderr, "slap_schema_load: ObjectClass "
   1301  1.1  lukem 					"\"%s\": %s: \"%s\"\n",
   1302  1.1  lukem 				 	oc_map[i].ssom_name, scherr2str(code), err);
   1303  1.1  lukem 				return code;
   1304  1.1  lukem 			}
   1305  1.1  lukem 			ldap_memfree(oc);
   1306  1.1  lukem 
   1307  1.1  lukem 		}
   1308  1.1  lukem 		{
   1309  1.1  lukem 			ObjectClass ** ocp = (ObjectClass **)
   1310  1.1  lukem 				&(((char *) &slap_schema)[oc_map[i].ssom_offset]);
   1311  1.1  lukem 
   1312  1.1  lukem 			assert( *ocp == NULL );
   1313  1.1  lukem 
   1314  1.1  lukem 			*ocp = oc_find( oc_map[i].ssom_name );
   1315  1.1  lukem 			if( *ocp == NULL ) {
   1316  1.1  lukem 				fprintf( stderr, "slap_schema_load: "
   1317  1.1  lukem 					"ObjectClass \"%s\": not defined in schema\n",
   1318  1.1  lukem 					oc_map[i].ssom_name );
   1319  1.1  lukem 				return LDAP_OBJECT_CLASS_VIOLATION;
   1320  1.1  lukem 			}
   1321  1.1  lukem 
   1322  1.1  lukem 			if( oc_map[i].ssom_check ) {
   1323  1.1  lukem 				/* install check routine */
   1324  1.1  lukem 				(*ocp)->soc_check = oc_map[i].ssom_check;
   1325  1.1  lukem 			}
   1326  1.1  lukem 			/* install flags */
   1327  1.1  lukem 			(*ocp)->soc_flags |= oc_map[i].ssom_flags;
   1328  1.1  lukem 		}
   1329  1.1  lukem 	}
   1330  1.1  lukem 
   1331  1.1  lukem 	return LDAP_SUCCESS;
   1332  1.1  lukem }
   1333  1.1  lukem 
   1334  1.1  lukem int
   1335  1.1  lukem slap_schema_check( void )
   1336  1.1  lukem {
   1337  1.1  lukem 	/* we should only be called once after schema_init() was called */
   1338  1.1  lukem 	assert( schema_init_done == 1 );
   1339  1.1  lukem 
   1340  1.1  lukem 	/*
   1341  1.1  lukem 	 * cycle thru attributeTypes to build matchingRuleUse
   1342  1.1  lukem 	 */
   1343  1.1  lukem 	if ( matching_rule_use_init() ) {
   1344  1.1  lukem 		return LDAP_OTHER;
   1345  1.1  lukem 	}
   1346  1.1  lukem 
   1347  1.1  lukem 	++schema_init_done;
   1348  1.1  lukem 	return LDAP_SUCCESS;
   1349  1.1  lukem }
   1350  1.1  lukem 
   1351  1.1  lukem static int rootDseObjectClass (
   1352  1.1  lukem 	Backend *be,
   1353  1.1  lukem 	Entry *e,
   1354  1.1  lukem 	ObjectClass *oc,
   1355  1.1  lukem 	const char** text,
   1356  1.1  lukem 	char *textbuf, size_t textlen )
   1357  1.1  lukem {
   1358  1.1  lukem 	*text = textbuf;
   1359  1.1  lukem 
   1360  1.1  lukem 	if( e->e_nname.bv_len ) {
   1361  1.1  lukem 		snprintf( textbuf, textlen,
   1362  1.1  lukem 			"objectClass \"%s\" only allowed in the root DSE",
   1363  1.1  lukem 			oc->soc_oid );
   1364  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1365  1.1  lukem 	}
   1366  1.1  lukem 
   1367  1.1  lukem 	/* we should not be called for the root DSE */
   1368  1.1  lukem 	assert( 0 );
   1369  1.1  lukem 	return LDAP_SUCCESS;
   1370  1.1  lukem }
   1371  1.1  lukem 
   1372  1.1  lukem static int aliasObjectClass (
   1373  1.1  lukem 	Backend *be,
   1374  1.1  lukem 	Entry *e,
   1375  1.1  lukem 	ObjectClass *oc,
   1376  1.1  lukem 	const char** text,
   1377  1.1  lukem 	char *textbuf, size_t textlen )
   1378  1.1  lukem {
   1379  1.1  lukem 	*text = textbuf;
   1380  1.1  lukem 
   1381  1.1  lukem 	if( !SLAP_ALIASES(be) ) {
   1382  1.1  lukem 		snprintf( textbuf, textlen,
   1383  1.1  lukem 			"objectClass \"%s\" not supported in context",
   1384  1.1  lukem 			oc->soc_oid );
   1385  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1386  1.1  lukem 	}
   1387  1.1  lukem 
   1388  1.1  lukem 	return LDAP_SUCCESS;
   1389  1.1  lukem }
   1390  1.1  lukem 
   1391  1.1  lukem static int referralObjectClass (
   1392  1.1  lukem 	Backend *be,
   1393  1.1  lukem 	Entry *e,
   1394  1.1  lukem 	ObjectClass *oc,
   1395  1.1  lukem 	const char** text,
   1396  1.1  lukem 	char *textbuf, size_t textlen )
   1397  1.1  lukem {
   1398  1.1  lukem 	*text = textbuf;
   1399  1.1  lukem 
   1400  1.1  lukem 	if( !SLAP_REFERRALS(be) ) {
   1401  1.1  lukem 		snprintf( textbuf, textlen,
   1402  1.1  lukem 			"objectClass \"%s\" not supported in context",
   1403  1.1  lukem 			oc->soc_oid );
   1404  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1405  1.1  lukem 	}
   1406  1.1  lukem 
   1407  1.1  lukem 	return LDAP_SUCCESS;
   1408  1.1  lukem }
   1409  1.1  lukem 
   1410  1.1  lukem static int subentryObjectClass (
   1411  1.1  lukem 	Backend *be,
   1412  1.1  lukem 	Entry *e,
   1413  1.1  lukem 	ObjectClass *oc,
   1414  1.1  lukem 	const char** text,
   1415  1.1  lukem 	char *textbuf, size_t textlen )
   1416  1.1  lukem {
   1417  1.1  lukem 	*text = textbuf;
   1418  1.1  lukem 
   1419  1.1  lukem 	if( !SLAP_SUBENTRIES(be) ) {
   1420  1.1  lukem 		snprintf( textbuf, textlen,
   1421  1.1  lukem 			"objectClass \"%s\" not supported in context",
   1422  1.1  lukem 			oc->soc_oid );
   1423  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1424  1.1  lukem 	}
   1425  1.1  lukem 
   1426  1.1  lukem 	if( oc != slap_schema.si_oc_subentry && !is_entry_subentry( e ) ) {
   1427  1.1  lukem 		snprintf( textbuf, textlen,
   1428  1.1  lukem 			"objectClass \"%s\" only allowed in subentries",
   1429  1.1  lukem 			oc->soc_oid );
   1430  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1431  1.1  lukem 	}
   1432  1.1  lukem 
   1433  1.1  lukem 	return LDAP_SUCCESS;
   1434  1.1  lukem }
   1435  1.1  lukem 
   1436  1.1  lukem #ifdef LDAP_DYNAMIC_OBJECTS
   1437  1.1  lukem static int dynamicObjectClass (
   1438  1.1  lukem 	Backend *be,
   1439  1.1  lukem 	Entry *e,
   1440  1.1  lukem 	ObjectClass *oc,
   1441  1.1  lukem 	const char** text,
   1442  1.1  lukem 	char *textbuf, size_t textlen )
   1443  1.1  lukem {
   1444  1.1  lukem 	*text = textbuf;
   1445  1.1  lukem 
   1446  1.1  lukem 	if( !SLAP_DYNAMIC(be) ) {
   1447  1.1  lukem 		snprintf( textbuf, textlen,
   1448  1.1  lukem 			"objectClass \"%s\" not supported in context",
   1449  1.1  lukem 			oc->soc_oid );
   1450  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1451  1.1  lukem 	}
   1452  1.1  lukem 
   1453  1.1  lukem 	return LDAP_SUCCESS;
   1454  1.1  lukem }
   1455  1.1  lukem #endif /* LDAP_DYNAMIC_OBJECTS */
   1456  1.1  lukem 
   1457  1.1  lukem static int rootDseAttribute (
   1458  1.1  lukem 	Backend *be,
   1459  1.1  lukem 	Entry *e,
   1460  1.1  lukem 	Attribute *attr,
   1461  1.1  lukem 	const char** text,
   1462  1.1  lukem 	char *textbuf, size_t textlen )
   1463  1.1  lukem {
   1464  1.1  lukem 	*text = textbuf;
   1465  1.1  lukem 
   1466  1.1  lukem 	if( e->e_nname.bv_len ) {
   1467  1.1  lukem 		snprintf( textbuf, textlen,
   1468  1.1  lukem 			"attribute \"%s\" only allowed in the root DSE",
   1469  1.1  lukem 			attr->a_desc->ad_cname.bv_val );
   1470  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1471  1.1  lukem 	}
   1472  1.1  lukem 
   1473  1.1  lukem 	/* we should not be called for the root DSE */
   1474  1.1  lukem 	assert( 0 );
   1475  1.1  lukem 	return LDAP_SUCCESS;
   1476  1.1  lukem }
   1477  1.1  lukem 
   1478  1.1  lukem static int aliasAttribute (
   1479  1.1  lukem 	Backend *be,
   1480  1.1  lukem 	Entry *e,
   1481  1.1  lukem 	Attribute *attr,
   1482  1.1  lukem 	const char** text,
   1483  1.1  lukem 	char *textbuf, size_t textlen )
   1484  1.1  lukem {
   1485  1.1  lukem 	*text = textbuf;
   1486  1.1  lukem 
   1487  1.1  lukem 	if( !SLAP_ALIASES(be) ) {
   1488  1.1  lukem 		snprintf( textbuf, textlen,
   1489  1.1  lukem 			"attribute \"%s\" not supported in context",
   1490  1.1  lukem 			attr->a_desc->ad_cname.bv_val );
   1491  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1492  1.1  lukem 	}
   1493  1.1  lukem 
   1494  1.1  lukem 	if( !is_entry_alias( e ) ) {
   1495  1.1  lukem 		snprintf( textbuf, textlen,
   1496  1.1  lukem 			"attribute \"%s\" only allowed in the alias",
   1497  1.1  lukem 			attr->a_desc->ad_cname.bv_val );
   1498  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1499  1.1  lukem 	}
   1500  1.1  lukem 
   1501  1.1  lukem 	return LDAP_SUCCESS;
   1502  1.1  lukem }
   1503  1.1  lukem 
   1504  1.1  lukem static int referralAttribute (
   1505  1.1  lukem 	Backend *be,
   1506  1.1  lukem 	Entry *e,
   1507  1.1  lukem 	Attribute *attr,
   1508  1.1  lukem 	const char** text,
   1509  1.1  lukem 	char *textbuf, size_t textlen )
   1510  1.1  lukem {
   1511  1.1  lukem 	*text = textbuf;
   1512  1.1  lukem 
   1513  1.1  lukem 	if( !SLAP_REFERRALS(be) ) {
   1514  1.1  lukem 		snprintf( textbuf, textlen,
   1515  1.1  lukem 			"attribute \"%s\" not supported in context",
   1516  1.1  lukem 			attr->a_desc->ad_cname.bv_val );
   1517  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1518  1.1  lukem 	}
   1519  1.1  lukem 
   1520  1.1  lukem 	if( !is_entry_referral( e ) ) {
   1521  1.1  lukem 		snprintf( textbuf, textlen,
   1522  1.1  lukem 			"attribute \"%s\" only allowed in the referral",
   1523  1.1  lukem 			attr->a_desc->ad_cname.bv_val );
   1524  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1525  1.1  lukem 	}
   1526  1.1  lukem 
   1527  1.1  lukem 	return LDAP_SUCCESS;
   1528  1.1  lukem }
   1529  1.1  lukem 
   1530  1.1  lukem static int subentryAttribute (
   1531  1.1  lukem 	Backend *be,
   1532  1.1  lukem 	Entry *e,
   1533  1.1  lukem 	Attribute *attr,
   1534  1.1  lukem 	const char** text,
   1535  1.1  lukem 	char *textbuf, size_t textlen )
   1536  1.1  lukem {
   1537  1.1  lukem 	*text = textbuf;
   1538  1.1  lukem 
   1539  1.1  lukem 	if( !SLAP_SUBENTRIES(be) ) {
   1540  1.1  lukem 		snprintf( textbuf, textlen,
   1541  1.1  lukem 			"attribute \"%s\" not supported in context",
   1542  1.1  lukem 			attr->a_desc->ad_cname.bv_val );
   1543  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1544  1.1  lukem 	}
   1545  1.1  lukem 
   1546  1.1  lukem 	if( !is_entry_subentry( e ) ) {
   1547  1.1  lukem 		snprintf( textbuf, textlen,
   1548  1.1  lukem 			"attribute \"%s\" only allowed in the subentry",
   1549  1.1  lukem 			attr->a_desc->ad_cname.bv_val );
   1550  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1551  1.1  lukem 	}
   1552  1.1  lukem 
   1553  1.1  lukem 	return LDAP_SUCCESS;
   1554  1.1  lukem }
   1555  1.1  lukem 
   1556  1.1  lukem static int administrativeRoleAttribute (
   1557  1.1  lukem 	Backend *be,
   1558  1.1  lukem 	Entry *e,
   1559  1.1  lukem 	Attribute *attr,
   1560  1.1  lukem 	const char** text,
   1561  1.1  lukem 	char *textbuf, size_t textlen )
   1562  1.1  lukem {
   1563  1.1  lukem 	*text = textbuf;
   1564  1.1  lukem 
   1565  1.1  lukem 	if( !SLAP_SUBENTRIES(be) ) {
   1566  1.1  lukem 		snprintf( textbuf, textlen,
   1567  1.1  lukem 			"attribute \"%s\" not supported in context",
   1568  1.1  lukem 			attr->a_desc->ad_cname.bv_val );
   1569  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1570  1.1  lukem 	}
   1571  1.1  lukem 
   1572  1.1  lukem 	snprintf( textbuf, textlen,
   1573  1.1  lukem 		"attribute \"%s\" not supported!",
   1574  1.1  lukem 		attr->a_desc->ad_cname.bv_val );
   1575  1.1  lukem 	return LDAP_OBJECT_CLASS_VIOLATION;
   1576  1.1  lukem }
   1577  1.1  lukem 
   1578  1.1  lukem #ifdef LDAP_DYNAMIC_OBJECTS
   1579  1.1  lukem static int dynamicAttribute (
   1580  1.1  lukem 	Backend *be,
   1581  1.1  lukem 	Entry *e,
   1582  1.1  lukem 	Attribute *attr,
   1583  1.1  lukem 	const char** text,
   1584  1.1  lukem 	char *textbuf, size_t textlen )
   1585  1.1  lukem {
   1586  1.1  lukem 	*text = textbuf;
   1587  1.1  lukem 
   1588  1.1  lukem 	if( !SLAP_DYNAMIC(be) ) {
   1589  1.1  lukem 		snprintf( textbuf, textlen,
   1590  1.1  lukem 			"attribute \"%s\" not supported in context",
   1591  1.1  lukem 			attr->a_desc->ad_cname.bv_val );
   1592  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1593  1.1  lukem 	}
   1594  1.1  lukem 
   1595  1.1  lukem 	if( !is_entry_dynamicObject( e ) ) {
   1596  1.1  lukem 		snprintf( textbuf, textlen,
   1597  1.1  lukem 			"attribute \"%s\" only allowed in dynamic object",
   1598  1.1  lukem 			attr->a_desc->ad_cname.bv_val );
   1599  1.1  lukem 		return LDAP_OBJECT_CLASS_VIOLATION;
   1600  1.1  lukem 	}
   1601  1.1  lukem 
   1602  1.1  lukem 	return LDAP_SUCCESS;
   1603  1.1  lukem }
   1604  1.1  lukem #endif /* LDAP_DYNAMIC_OBJECTS */
   1605