1/* $OpenLDAP$ */
2/* This work is part of OpenLDAP Software <http://www.openldap.org/>.
3 *
4 * Copyright 1999-2011 The OpenLDAP Foundation.
5 * Portions Copyright 1999 Dmitry Kovalev.
6 * Portions Copyright 2002 Pierangelo Masarati.
7 * All rights reserved.
8 *
9 * Redistribution and use in source and binary forms, with or without
10 * modification, are permitted only as authorized by the OpenLDAP
11 * Public License.
12 *
13 * A copy of this license is available in the file LICENSE in the
14 * top-level directory of the distribution or, alternatively, at
15 * <http://www.OpenLDAP.org/license.html>.
16 */
17/* ACKNOWLEDGEMENTS:
18 * This work was initially developed by Dmitry Kovalev for inclusion
19 * by OpenLDAP Software.  Additional significant contributors include
20 * Pierangelo Masarati.
21 */
22
23#include "portable.h"
24
25#include <stdio.h>
26#include <sys/types.h>
27#include "ac/string.h"
28
29#include "slap.h"
30#include "proto-sql.h"
31
32int
33backsql_modify( Operation *op, SlapReply *rs )
34{
35	backsql_info		*bi = (backsql_info*)op->o_bd->be_private;
36	SQLHDBC 		dbh = SQL_NULL_HDBC;
37	backsql_oc_map_rec	*oc = NULL;
38	backsql_srch_info	bsi = { 0 };
39	Entry			m = { 0 }, *e = NULL;
40	int			manageDSAit = get_manageDSAit( op );
41	SQLUSMALLINT		CompletionType = SQL_ROLLBACK;
42
43	/*
44	 * FIXME: in case part of the operation cannot be performed
45	 * (missing mapping, SQL write fails or so) the entire operation
46	 * should be rolled-back
47	 */
48	Debug( LDAP_DEBUG_TRACE, "==>backsql_modify(): modifying entry \"%s\"\n",
49		op->o_req_ndn.bv_val, 0, 0 );
50
51	rs->sr_err = backsql_get_db_conn( op, &dbh );
52	if ( rs->sr_err != LDAP_SUCCESS ) {
53		Debug( LDAP_DEBUG_TRACE, "   backsql_modify(): "
54			"could not get connection handle - exiting\n",
55			0, 0, 0 );
56		/*
57		 * FIXME: we don't want to send back
58		 * excessively detailed messages
59		 */
60		rs->sr_text = ( rs->sr_err == LDAP_OTHER )
61			? "SQL-backend error" : NULL;
62		goto done;
63	}
64
65	bsi.bsi_e = &m;
66	rs->sr_err = backsql_init_search( &bsi, &op->o_req_ndn,
67			LDAP_SCOPE_BASE,
68			(time_t)(-1), NULL, dbh, op, rs,
69			slap_anlist_all_attributes,
70			( BACKSQL_ISF_MATCHED | BACKSQL_ISF_GET_ENTRY | BACKSQL_ISF_GET_OC ) );
71	switch ( rs->sr_err ) {
72	case LDAP_SUCCESS:
73		break;
74
75	case LDAP_REFERRAL:
76		if ( manageDSAit && !BER_BVISNULL( &bsi.bsi_e->e_nname ) &&
77				dn_match( &op->o_req_ndn, &bsi.bsi_e->e_nname ) )
78		{
79			rs->sr_err = LDAP_SUCCESS;
80			rs->sr_text = NULL;
81			rs->sr_matched = NULL;
82			if ( rs->sr_ref ) {
83				ber_bvarray_free( rs->sr_ref );
84				rs->sr_ref = NULL;
85			}
86			break;
87		}
88		e = &m;
89		/* fallthru */
90
91	default:
92		Debug( LDAP_DEBUG_TRACE, "backsql_modify(): "
93			"could not retrieve modifyDN ID - no such entry\n",
94			0, 0, 0 );
95		if ( !BER_BVISNULL( &m.e_nname ) ) {
96			/* FIXME: should always be true! */
97			e = &m;
98
99		} else {
100			e = NULL;
101		}
102		goto done;
103	}
104
105	Debug( LDAP_DEBUG_TRACE, "   backsql_modify(): "
106		"modifying entry \"%s\" (id=" BACKSQL_IDFMT ")\n",
107		bsi.bsi_base_id.eid_dn.bv_val,
108		BACKSQL_IDARG(bsi.bsi_base_id.eid_id), 0 );
109
110	if ( get_assert( op ) &&
111			( test_filter( op, &m, get_assertion( op ) )
112			  != LDAP_COMPARE_TRUE ))
113	{
114		rs->sr_err = LDAP_ASSERTION_FAILED;
115		e = &m;
116		goto done;
117	}
118
119	slap_mods_opattrs( op, &op->orm_modlist, 1 );
120
121	assert( bsi.bsi_base_id.eid_oc != NULL );
122	oc = bsi.bsi_base_id.eid_oc;
123
124	if ( !acl_check_modlist( op, &m, op->orm_modlist ) ) {
125		rs->sr_err = LDAP_INSUFFICIENT_ACCESS;
126		e = &m;
127		goto done;
128	}
129
130	rs->sr_err = backsql_modify_internal( op, rs, dbh, oc,
131			&bsi.bsi_base_id, op->orm_modlist );
132	if ( rs->sr_err != LDAP_SUCCESS ) {
133		e = &m;
134		goto do_transact;
135	}
136
137	if ( BACKSQL_CHECK_SCHEMA( bi ) ) {
138		char		textbuf[ SLAP_TEXT_BUFLEN ] = { '\0' };
139
140		backsql_entry_clean( op, &m );
141
142		bsi.bsi_e = &m;
143		rs->sr_err = backsql_id2entry( &bsi, &bsi.bsi_base_id );
144		if ( rs->sr_err != LDAP_SUCCESS ) {
145			e = &m;
146			goto do_transact;
147		}
148
149		rs->sr_err = entry_schema_check( op, &m, NULL, 0, 0, NULL,
150			&rs->sr_text, textbuf, sizeof( textbuf ) );
151		if ( rs->sr_err != LDAP_SUCCESS ) {
152			Debug( LDAP_DEBUG_TRACE, "   backsql_modify(\"%s\"): "
153				"entry failed schema check -- aborting\n",
154				m.e_name.bv_val, 0, 0 );
155			e = NULL;
156			goto do_transact;
157		}
158	}
159
160do_transact:;
161	/*
162	 * Commit only if all operations succeed
163	 */
164	if ( rs->sr_err == LDAP_SUCCESS && !op->o_noop ) {
165		assert( e == NULL );
166		CompletionType = SQL_COMMIT;
167	}
168
169	SQLTransact( SQL_NULL_HENV, dbh, CompletionType );
170
171done:;
172	if ( e != NULL ) {
173		if ( !access_allowed( op, e, slap_schema.si_ad_entry, NULL,
174					ACL_DISCLOSE, NULL ) )
175		{
176			rs->sr_err = LDAP_NO_SUCH_OBJECT;
177			rs->sr_text = NULL;
178			rs->sr_matched = NULL;
179			if ( rs->sr_ref ) {
180				ber_bvarray_free( rs->sr_ref );
181				rs->sr_ref = NULL;
182			}
183		}
184	}
185
186	if ( op->o_noop && rs->sr_err == LDAP_SUCCESS ) {
187		rs->sr_err = LDAP_X_NO_OPERATION;
188	}
189
190	send_ldap_result( op, rs );
191	slap_graduate_commit_csn( op );
192
193	if ( !BER_BVISNULL( &bsi.bsi_base_id.eid_ndn ) ) {
194		(void)backsql_free_entryID( &bsi.bsi_base_id, 0, op->o_tmpmemctx );
195	}
196
197	if ( !BER_BVISNULL( &m.e_nname ) ) {
198		backsql_entry_clean( op, &m );
199	}
200
201	if ( bsi.bsi_attrs != NULL ) {
202		op->o_tmpfree( bsi.bsi_attrs, op->o_tmpmemctx );
203	}
204
205	if ( rs->sr_ref ) {
206		ber_bvarray_free( rs->sr_ref );
207		rs->sr_ref = NULL;
208	}
209
210	Debug( LDAP_DEBUG_TRACE, "<==backsql_modify()\n", 0, 0, 0 );
211
212	return rs->sr_err;
213}
214
215