]>
git.ipfire.org Git - thirdparty/openldap.git/log
Ondřej Kuzník [Mon, 28 Apr 2025 13:36:24 +0000 (14:36 +0100)]
ITS#10297 Defer hostname resolution til first use
Greg Noe [Fri, 17 Jan 2025 21:52:12 +0000 (13:52 -0800)]
ITS#10140 Add microsecond timestamp format for local file logging
Ondřej Kuzník [Fri, 25 Apr 2025 12:45:09 +0000 (13:45 +0100)]
ITS#10331 Add helpful error messages for usage errors
Howard Chu [Tue, 22 Apr 2025 16:39:05 +0000 (17:39 +0100)]
ITS#10328 librewrite: fix substitution cleanup
Ondřej Kuzník [Mon, 14 Apr 2025 16:51:06 +0000 (17:51 +0100)]
ITS#10327 Allow lockless config_back_search() during server pause
The assumption is that the only reason it is allowed to run at this
point is that it is called from the reconfiguration context anyway.
Ondřej Kuzník [Mon, 14 Apr 2025 13:56:58 +0000 (14:56 +0100)]
ITS#10325 slapd-dsaschema: Use assigned OIDs
Ondřej Kuzník [Mon, 14 Apr 2025 13:56:25 +0000 (14:56 +0100)]
ITS#10325 slapo-variant: Use assigned OIDs
Ondřej Kuzník [Mon, 14 Apr 2025 10:11:03 +0000 (11:11 +0100)]
ITS#10323 Apply olcBkLloadStartTLS runtime changes directly
Howard Chu [Thu, 3 Apr 2025 16:18:07 +0000 (17:18 +0100)]
ITS#10320 autogroup: mark internal searches
Avoid any other overlays munging autogroup's searches
Howard Chu [Tue, 1 Apr 2025 15:54:10 +0000 (16:54 +0100)]
ITS#10168 back-mdb: cleanup index setup
Nop index setup when index config resulted in no configured indices
Howard Chu [Tue, 22 Apr 2025 16:22:59 +0000 (17:22 +0100)]
ITS#10326 mbedtls: always call mbedtls_ssl_set_hostname()
Even if hostname is NULL, the library requires this be called once.
If non-NULL, mbedtls may do a hostname check which is redundant
since libldap does its own check.
Howard Chu [Thu, 27 Mar 2025 16:14:32 +0000 (16:14 +0000)]
ITS#10299 slapacl(8): fix dry-run description
Howard Chu [Thu, 27 Mar 2025 16:11:17 +0000 (16:11 +0000)]
ITS#10299 slapacl: use dummy entry_get in dry-run mode
Howard Chu [Tue, 25 Mar 2025 16:32:12 +0000 (16:32 +0000)]
ITS#9934 slapd-config(5) add new TLS cert/key settings
Howard Chu [Tue, 25 Mar 2025 16:07:11 +0000 (16:07 +0000)]
ITS#10020 slapo-dynlist(5) note static objectclasses can only be used once
Andrew Elble [Fri, 11 Oct 2024 12:43:47 +0000 (08:43 -0400)]
ITS#10270 slapo-pcache: negative cache entries are not loaded when pcachePersist is on
Andrew Elble [Fri, 11 Oct 2024 12:38:36 +0000 (08:38 -0400)]
ITS#10270 slapo-pcache: queries with ttr/x-refresh are not loaded when pcachePersist is on
Andrew Elble [Fri, 11 Oct 2024 12:37:13 +0000 (08:37 -0400)]
ITS#10270 slapo-pcache: ttr was not being applied to negatively cached entries
Quanah Gibson-Mount [Fri, 21 Mar 2025 21:51:20 +0000 (21:51 +0000)]
ITS#10163 - Regenerate configure
Ondřej Kuzník [Mon, 17 Mar 2025 10:58:31 +0000 (10:58 +0000)]
Add missing olcFrontendConfig to example
Ondřej Kuzník [Mon, 10 Mar 2025 11:37:59 +0000 (11:37 +0000)]
ITS#10312 Explicitly allow FALSE in 'subordinate'
Ondřej Kuzník [Mon, 10 Mar 2025 12:27:23 +0000 (12:27 +0000)]
ITS#10163 Add missed otp overlay to configure.ac
Howard Chu [Wed, 25 Sep 2024 19:08:10 +0000 (20:08 +0100)]
ITS#9367 back-mdb: add encryption support
Enabled if MDB_ENCRYPT is defined, which is currently only in mdb.master3.
Ondřej Kuzník [Thu, 20 Feb 2025 12:57:57 +0000 (12:57 +0000)]
ITS#10309 Check for strdup allocation failures
Howard Chu [Wed, 26 Feb 2025 13:36:50 +0000 (13:36 +0000)]
ITS#10310 pw-pbkdf2: make iterations configurable
Ondřej Kuzník [Wed, 14 Aug 2024 10:10:43 +0000 (11:10 +0100)]
ITS#10266 Adding a test script
Ondřej Kuzník [Mon, 19 Aug 2024 13:05:44 +0000 (14:05 +0100)]
ITS#10266 Linked clients should also be tagged for closing
Ondřej Kuzník [Wed, 14 Aug 2024 09:55:29 +0000 (10:55 +0100)]
ITS#10266 Adopt broader RFC4511 NoD interpretation, receiving side
Ondřej Kuzník [Wed, 14 Aug 2024 09:57:42 +0000 (10:57 +0100)]
ITS#10265 Allow runtime reconfig of olcBkLloadListen
Ondřej Kuzník [Thu, 16 Jan 2025 15:27:20 +0000 (15:27 +0000)]
ITS#7249 Disallow memberof-addcheck when memberof is global
Ondřej Kuzník [Thu, 16 Jan 2025 15:26:52 +0000 (15:26 +0000)]
ITS#7249 Let backend_attribute know who's calling it
Ondřej Kuzník [Thu, 16 Jan 2025 15:35:06 +0000 (15:35 +0000)]
ITS#10279 Let client notify when LDAP_DEBUG is disabled but -d specified
Ondřej Kuzník [Mon, 10 Feb 2025 14:37:45 +0000 (14:37 +0000)]
ITS#10307 Initialise last if we use it later
Ondřej Kuzník [Wed, 15 Jan 2025 12:32:58 +0000 (12:32 +0000)]
Update and clarify replication docs
Alexandre Jousset [Wed, 12 Feb 2025 17:46:55 +0000 (17:46 +0000)]
ITS#10160 - Add "neguri" and "negset" constraint types to slapo-constraint
Howard Chu [Tue, 4 Feb 2025 17:00:36 +0000 (17:00 +0000)]
ITS#10302 slapd-mdb: fix idcursor double-free in slapadd shutdown
Caused when calling tool_entry_modify to update ctxcsn after all adds are done.
Nadezhda Ivanova [Fri, 1 Nov 2024 13:03:57 +0000 (15:03 +0200)]
ITS#9186 Add deferred ops statistics counters
Ondřej Kuzník [Mon, 9 Dec 2024 16:41:44 +0000 (16:41 +0000)]
ITS#10290 Move syncrepl_modify_cb to the end of the list
The way op->orm_modlist is allocated by syncrepl_op_modify is not
compatible with slap_mods_free() and so callbacks from any overlays that
touch op->orm_modlist on the way down need a chance to undo their state
first as we go back up.
Nadezhda Ivanova [Mon, 28 Oct 2024 13:48:33 +0000 (15:48 +0200)]
ITS#9186 Add a counter to cn=Listener to track total number of established connections since startup
Ondřej Kuzník [Thu, 24 Oct 2024 15:01:15 +0000 (16:01 +0100)]
ITS#7080 Do not reuse back-ldif's stack for controls
Ondřej Kuzník [Thu, 24 Oct 2024 15:00:09 +0000 (16:00 +0100)]
ITS#7080 Implement pre/postread for modrdn
Ondřej Kuzník [Thu, 24 Oct 2024 14:59:37 +0000 (15:59 +0100)]
ITS#7080 Do not munge path twice
Ondřej Kuzník [Thu, 26 Sep 2024 11:27:05 +0000 (12:27 +0100)]
ITS#10229 Adjust ldap_result behaviour with LDAP_MSG_RECEIVED
Howard Chu [Fri, 29 Nov 2024 14:46:10 +0000 (14:46 +0000)]
ITS#10288 autoca: fix olcAutoCAserverClass config
Bjarni Ingi Gislason [Fri, 28 Jun 2024 17:23:05 +0000 (17:23 +0000)]
ITS#10226 - Fix ldap.conf(5) formatting issues
Ondřej Kuzník [Tue, 29 Oct 2024 12:43:37 +0000 (12:43 +0000)]
ITS#10272 Request all attributes from remote
Fixes a regression introduced in
fc1bcaf9ded9410cd825112be8db994163c06b04
leaving us unable to check the full filter after we recreate the entry.
Ondřej Kuzník [Tue, 22 Oct 2024 12:59:20 +0000 (13:59 +0100)]
ITS#10155 manage option values more carefully
Ondřej Kuzník [Mon, 21 Oct 2024 10:50:11 +0000 (11:50 +0100)]
ITS#8047 Fix TLS connection timeout handling
The test for async in ldap_int_tls_start was inverted, we already
support calling ldap_int_tls_connect repeatedly. And so long as
LBER_SB_OPT_NEEDS_* are managed correctly, the application should be
able to do the right thing.
Might require a new result code rather than reporposing
LDAP_X_CONNECTING for this.
Ondřej Kuzník [Thu, 3 Oct 2024 11:39:52 +0000 (12:39 +0100)]
ITS#10263 Reject modifications with invalid whitespace
Ondřej Kuzník [Wed, 23 Oct 2024 09:19:57 +0000 (10:19 +0100)]
ITS#9393 Expose and document ldap_pvt_put_filter
Ondřej Kuzník [Mon, 21 Oct 2024 13:58:23 +0000 (14:58 +0100)]
ITS#9042 Log modify values under STATS2
Nadezhda Ivanova [Fri, 18 Oct 2024 11:48:35 +0000 (14:48 +0300)]
ITS#9914 Add OS pagesize to the back-mdb monitor information
Page size is now provided with the olmMDBPageSize attribute.
Ondřej Kuzník [Wed, 2 Oct 2024 12:23:44 +0000 (13:23 +0100)]
ITS#10264 Free NoD data we stored locally
Ondřej Kuzník [Fri, 19 Jul 2024 08:59:56 +0000 (09:59 +0100)]
ITS#10234 Reinit retry state on refreshDone
Ondřej Kuzník [Fri, 19 Jul 2024 08:53:35 +0000 (09:53 +0100)]
ITS#10232 Reset cs_refreshing on config delete
Ondřej Kuzník [Fri, 27 Sep 2024 13:21:20 +0000 (14:21 +0100)]
ITS#7982 Log TLS proto+cipher suite on client side
Michael Nolta [Tue, 3 Sep 2024 10:38:48 +0000 (11:38 +0100)]
ITS#10248 Regression test script
Ondřej Kuzník [Fri, 23 Aug 2024 11:57:34 +0000 (12:57 +0100)]
ITS#10248 Always generate a result on the original op
Ondřej Kuzník [Tue, 3 Sep 2024 10:29:25 +0000 (11:29 +0100)]
ITS#10249 slapo-nestgroup: plug leak in nestgroup_memberFilter
Howard Chu [Tue, 10 Sep 2024 16:41:39 +0000 (17:41 +0100)]
ITS#10256 cn=config: reject modify requests on cn=schema,cn=config
Add requests already handled it specially; corresponding treatment
for modify requests was missing. The docs have always stated that
cn=schema,cn=config is only for slapd's hardcoded schema so this
only affects users who don't read docs.
Ryan Tandy [Thu, 22 Aug 2024 00:48:45 +0000 (17:48 -0700)]
ITS#10253 Fix incompatible pointer type
Howard Chu [Tue, 6 Aug 2024 16:52:11 +0000 (17:52 +0100)]
ITS#10247 libldap: add ldap_url_check_ext() to check URL extensions
And check validity earlier, in ldap_initialize() and ldap_init_fd().
Howard Chu [Tue, 6 Aug 2024 15:18:36 +0000 (16:18 +0100)]
ITS#10247 libldap: reject unrecognized critical URL extensions
Ondřej Kuzník [Tue, 13 Aug 2024 08:21:15 +0000 (09:21 +0100)]
ITS#10251 cast sa when passed to getsockname
Quanah Gibson-Mount [Wed, 31 Jul 2024 22:50:32 +0000 (22:50 +0000)]
ITS#7400 - Fix exattr to exattrs option
Ondřej Kuzník [Fri, 19 Jul 2024 14:45:53 +0000 (15:45 +0100)]
ITS#10242 Record rid in operation related logs
HAMANO Tsukasa [Wed, 26 Jun 2024 01:51:17 +0000 (10:51 +0900)]
fix idl intersection ITS#10233
The `mdb_idl_intersection()` and `wt_idl_intersection()` functions derived from back-bdb return wrong results.
expect:
[1, 3] ∩ [2] = []
actual:
[1, 3] ∩ [2] = [2]
also
- Add scope checking for back-wt
- fix compiler warning
Howard Chu [Thu, 4 Jul 2024 17:52:44 +0000 (18:52 +0100)]
ITS#10237 fix prev commit
Howard Chu [Thu, 4 Jul 2024 17:35:45 +0000 (18:35 +0100)]
ITS#10237 back-ldap: fix usage of multi-precision add for op counters
Howard Chu [Wed, 26 Jun 2024 23:49:21 +0000 (00:49 +0100)]
ITS#10235 slapo-nestgroup: silence extraneous register_at message
Howard Chu [Tue, 18 Jun 2024 16:14:12 +0000 (17:14 +0100)]
ITS#10231 slapadd: check for NULL suffix in error message
Howard Chu [Mon, 17 Jun 2024 20:40:48 +0000 (21:40 +0100)]
ITS#10230 slapo-memberof: fix addcheck search to omit dynamic values
Nadezhda Ivanova [Fri, 1 Mar 2024 13:13:47 +0000 (15:13 +0200)]
ITS#10227 Asyncmeta will not reset a connection if a bind operation fails with LDAP_OTHER, leaving the connection in invalid state
Nadezhda Ivanova [Thu, 23 May 2024 13:09:26 +0000 (16:09 +0300)]
ITS#10219 Modify of olcDisabled by removing and adding a value invokes db_open twice
Do not invoke db_open if the database is not actually disabled
Nadezhda Ivanova [Thu, 23 May 2024 12:54:04 +0000 (15:54 +0300)]
ITS#10218 Disabling and re-enabling an asyncmeta database via cn=config leaks memory
Make sure asyncmeta frees the pending operations structures, resets all connections, frees connection structures and stops the timeout-loop.
Quanah Gibson-Mount [Tue, 11 Jun 2024 17:06:33 +0000 (17:06 +0000)]
ITS#9827 - Use 7MB memory/5 iterations as default
This has the same protections as 19MB/2 iterations, but requires less system memory
Howard Chu [Fri, 7 Jun 2024 14:33:04 +0000 (15:33 +0100)]
ITS#10224 libldap: check for OpenSSL EVP_Digest* failure
Howard Chu [Fri, 7 Jun 2024 14:26:45 +0000 (15:26 +0100)]
ITS#10223 libldap: check for OpenSSL SSL_CTX_set_ciphersuites failure
Quanah Gibson-Mount [Tue, 21 May 2024 17:16:40 +0000 (17:16 +0000)]
Merge remote-tracking branch 'origin/mdb.RE/0.9'
Quanah Gibson-Mount [Tue, 21 May 2024 17:16:06 +0000 (17:16 +0000)]
Prep for release
Howard Chu [Tue, 14 May 2024 15:13:15 +0000 (16:13 +0100)]
ITS#10216 libldap: fix OpenSSL channel binding digest
The OBJ_find_ API is undocumented but this is what OpenSSL libcrypto does itself.
Howard Chu [Tue, 7 May 2024 18:47:35 +0000 (19:47 +0100)]
ITS#10209 libldap: only use OPENSSL_INIT_NO_ATEXIT if it's defined
Fake OpenSSL clones like LibreSSL don't support it.
In general we will make no effort to support fake OpenSSL clones.
Quanah Gibson-Mount [Thu, 9 May 2024 17:08:12 +0000 (17:08 +0000)]
ITS#10214 - Regenerate configure
HAMANO Tsukasa [Wed, 8 May 2024 23:26:41 +0000 (08:26 +0900)]
refactoring
- remove __attribute__ destructor
- use sendto instead of connect/write
HAMANO Tsukasa [Tue, 7 May 2024 10:59:17 +0000 (19:59 +0900)]
ITS#10214 Reduce library dependencies
Currently, slapd links libsystemd to notify service state to systemd.
However, libsystemd link several unnecessary libraries, which increases security risks.
The systemd documentation provides a method to send state notifications to systemd using a simple protocol without the need to link against libsystemd.
https://www.freedesktop.org/software/systemd/man/devel/sd_notify.html
Quanah Gibson-Mount [Tue, 7 May 2024 17:29:31 +0000 (17:29 +0000)]
Merge remote-tracking branch 'origin/mdb.RE/0.9'
Quanah Gibson-Mount [Tue, 7 May 2024 17:29:20 +0000 (17:29 +0000)]
Merge remote-tracking branch 'origin/mdb.RE/0.9'
Quanah Gibson-Mount [Tue, 7 May 2024 16:49:34 +0000 (16:49 +0000)]
ITS#10212
Quanah Gibson-Mount [Tue, 7 May 2024 16:49:00 +0000 (16:49 +0000)]
ITS#10198
Howard Chu [Fri, 3 May 2024 19:43:39 +0000 (20:43 +0100)]
ITS#10212 LMDB: better fix
Nick Porter [Thu, 2 May 2024 07:48:14 +0000 (08:48 +0100)]
ITS#10211 slapd: Fix peercred uid and gid format
uid and gid are unsigned int and so should be formatted as such when
creating the authid string.
Ryan Tandy [Sun, 28 Apr 2024 22:31:26 +0000 (15:31 -0700)]
ITS#10206 Include <kadm5/private.h> for kadm5_s_init_with_password_ctx
Howard Chu [Thu, 2 May 2024 15:29:03 +0000 (16:29 +0100)]
ITS#10212 LMDB: init txnid for read-only DBs
Quanah Gibson-Mount [Wed, 1 May 2024 16:23:20 +0000 (16:23 +0000)]
ITS#10207 - regenerate configure
Howard Chu [Wed, 1 May 2024 14:11:43 +0000 (15:11 +0100)]
ITS#10207 configure.ac: fix typo from ITS#10177
Howard Chu [Tue, 30 Apr 2024 14:55:01 +0000 (15:55 +0100)]
ITS#10204 slapo-constraint: fix double-free on invalid attr
Nadezhda Ivanova [Thu, 11 Apr 2024 11:10:07 +0000 (14:10 +0300)]
ITS#10197 Back-meta and back-asyncmeta add a new target structure and increase the number of targets even if uri parsing fails
Reproducible when adding a new target via cn=config
Howard Chu [Tue, 27 Feb 2024 13:13:25 +0000 (13:13 +0000)]
ITS#10183 ldapmodify: add jump to lineno option
Quanah Gibson-Mount [Fri, 12 Apr 2024 21:29:11 +0000 (21:29 +0000)]
ITS#10202 - Regenerate configure
Nadezhda Ivanova [Fri, 12 Apr 2024 12:53:04 +0000 (15:53 +0300)]
ITS#10202 slapd fails to start if compiled with --enable-overlays=yes