1*549b59edSchristos /* $NetBSD: ldapdelete.c,v 1.3 2021/08/14 16:14:49 christos Exp $ */
24e6df137Slukem
32de962bdSlukem /* ldapdelete.c - simple program to delete an entry using LDAP */
4d11b170bStron /* $OpenLDAP$ */
52de962bdSlukem /* This work is part of OpenLDAP Software <http://www.openldap.org/>.
62de962bdSlukem *
7*549b59edSchristos * Copyright 1998-2021 The OpenLDAP Foundation.
82de962bdSlukem * Portions Copyright 1998-2003 Kurt D. Zeilenga.
92de962bdSlukem * All rights reserved.
102de962bdSlukem *
112de962bdSlukem * Redistribution and use in source and binary forms, with or without
122de962bdSlukem * modification, are permitted only as authorized by the OpenLDAP
132de962bdSlukem * Public License.
142de962bdSlukem *
152de962bdSlukem * A copy of this license is available in the file LICENSE in the
162de962bdSlukem * top-level directory of the distribution or, alternatively, at
172de962bdSlukem * <http://www.OpenLDAP.org/license.html>.
182de962bdSlukem */
192de962bdSlukem /* Portions Copyright (c) 1992-1996 Regents of the University of Michigan.
202de962bdSlukem * All rights reserved.
212de962bdSlukem *
222de962bdSlukem * Redistribution and use in source and binary forms are permitted
232de962bdSlukem * provided that this notice is preserved and that due credit is given
242de962bdSlukem * to the University of Michigan at Ann Arbor. The name of the
252de962bdSlukem * University may not be used to endorse or promote products derived
262de962bdSlukem * from this software without specific prior written permission. This
272de962bdSlukem * software is provided ``as is'' without express or implied warranty.
282de962bdSlukem */
292de962bdSlukem /* ACKNOWLEDGEMENTS:
302de962bdSlukem * This work was originally developed by the University of Michigan
312de962bdSlukem * (as part of U-MICH LDAP). Additional significant contributors
322de962bdSlukem * include:
332de962bdSlukem * Kurt D. Zeilenga
342de962bdSlukem */
352de962bdSlukem
36376af7d7Schristos #include <sys/cdefs.h>
37*549b59edSchristos __RCSID("$NetBSD: ldapdelete.c,v 1.3 2021/08/14 16:14:49 christos Exp $");
38376af7d7Schristos
392de962bdSlukem #include "portable.h"
402de962bdSlukem
412de962bdSlukem #include <stdio.h>
422de962bdSlukem
432de962bdSlukem #include <ac/stdlib.h>
442de962bdSlukem #include <ac/ctype.h>
452de962bdSlukem #include <ac/string.h>
462de962bdSlukem #include <ac/unistd.h>
472de962bdSlukem #include <ac/socket.h>
482de962bdSlukem #include <ac/time.h>
492de962bdSlukem
502de962bdSlukem #include <ldap.h>
512de962bdSlukem #include "lutil.h"
522de962bdSlukem #include "lutil_ldap.h"
532de962bdSlukem #include "ldap_defaults.h"
542de962bdSlukem
552de962bdSlukem #include "common.h"
562de962bdSlukem
572de962bdSlukem
582de962bdSlukem static int prune = 0;
592de962bdSlukem static int sizelimit = -1;
602de962bdSlukem
612de962bdSlukem
622de962bdSlukem static int dodelete LDAP_P((
632de962bdSlukem LDAP *ld,
642de962bdSlukem const char *dn));
652de962bdSlukem
662de962bdSlukem static int deletechildren LDAP_P((
672de962bdSlukem LDAP *ld,
682de962bdSlukem const char *dn,
692de962bdSlukem int subentries ));
702de962bdSlukem
712de962bdSlukem void
usage(void)722de962bdSlukem usage( void )
732de962bdSlukem {
742de962bdSlukem fprintf( stderr, _("Delete entries from an LDAP server\n\n"));
752de962bdSlukem fprintf( stderr, _("usage: %s [options] [dn]...\n"), prog);
76*549b59edSchristos fprintf( stderr, _(" dn: list of DNs to delete. If not given, it will be read from stdin\n"));
772de962bdSlukem fprintf( stderr, _(" or from the file specified with \"-f file\".\n"));
782de962bdSlukem fprintf( stderr, _("Delete Options:\n"));
794e6df137Slukem fprintf( stderr, _(" -c continuous operation mode (do not stop on errors)\n"));
804e6df137Slukem fprintf( stderr, _(" -f file read operations from `file'\n"));
814e6df137Slukem fprintf( stderr, _(" -M enable Manage DSA IT control (-MM to make critical)\n"));
824e6df137Slukem fprintf( stderr, _(" -P version protocol version (default: 3)\n"));
832de962bdSlukem fprintf( stderr, _(" -r delete recursively\n"));
842de962bdSlukem tool_common_usage();
852de962bdSlukem exit( EXIT_FAILURE );
862de962bdSlukem }
872de962bdSlukem
882de962bdSlukem
892de962bdSlukem const char options[] = "r"
904e6df137Slukem "cd:D:e:f:h:H:IMnNO:o:p:P:QR:U:vVw:WxX:y:Y:z:Z";
912de962bdSlukem
922de962bdSlukem int
handle_private_option(int i)932de962bdSlukem handle_private_option( int i )
942de962bdSlukem {
952de962bdSlukem int ival;
962de962bdSlukem char *next;
972de962bdSlukem switch ( i ) {
982de962bdSlukem #if 0
992de962bdSlukem int crit;
1002de962bdSlukem char *control, *cvalue;
1012de962bdSlukem case 'E': /* delete extensions */
1022de962bdSlukem if( protocol == LDAP_VERSION2 ) {
1032de962bdSlukem fprintf( stderr, _("%s: -E incompatible with LDAPv%d\n"),
1042de962bdSlukem prog, protocol );
1052de962bdSlukem exit( EXIT_FAILURE );
1062de962bdSlukem }
1072de962bdSlukem
1082de962bdSlukem /* should be extended to support comma separated list of
1092de962bdSlukem * [!]key[=value] parameters, e.g. -E !foo,bar=567
1102de962bdSlukem */
1112de962bdSlukem
1122de962bdSlukem crit = 0;
1132de962bdSlukem cvalue = NULL;
1142de962bdSlukem if( optarg[0] == '!' ) {
1152de962bdSlukem crit = 1;
1162de962bdSlukem optarg++;
1172de962bdSlukem }
1182de962bdSlukem
119*549b59edSchristos control = optarg;
1202de962bdSlukem if ( (cvalue = strchr( control, '=' )) != NULL ) {
1212de962bdSlukem *cvalue++ = '\0';
1222de962bdSlukem }
1232de962bdSlukem fprintf( stderr, _("Invalid delete extension name: %s\n"), control );
1242de962bdSlukem usage();
1252de962bdSlukem #endif
1262de962bdSlukem
1272de962bdSlukem case 'r':
1282de962bdSlukem prune = 1;
1292de962bdSlukem break;
1302de962bdSlukem
1312de962bdSlukem case 'z': /* size limit */
1322de962bdSlukem if ( strcasecmp( optarg, "none" ) == 0 ) {
1332de962bdSlukem sizelimit = 0;
1342de962bdSlukem
1352de962bdSlukem } else if ( strcasecmp( optarg, "max" ) == 0 ) {
1362de962bdSlukem sizelimit = LDAP_MAXINT;
1372de962bdSlukem
1382de962bdSlukem } else {
1392de962bdSlukem ival = strtol( optarg, &next, 10 );
1402de962bdSlukem if ( next == NULL || next[0] != '\0' ) {
1412de962bdSlukem fprintf( stderr,
1422de962bdSlukem _("Unable to parse size limit \"%s\"\n"), optarg );
1432de962bdSlukem exit( EXIT_FAILURE );
1442de962bdSlukem }
1452de962bdSlukem sizelimit = ival;
1462de962bdSlukem }
1472de962bdSlukem if( sizelimit < 0 || sizelimit > LDAP_MAXINT ) {
1482de962bdSlukem fprintf( stderr, _("%s: invalid sizelimit (%d) specified\n"),
1492de962bdSlukem prog, sizelimit );
1502de962bdSlukem exit( EXIT_FAILURE );
1512de962bdSlukem }
1522de962bdSlukem break;
1532de962bdSlukem
1542de962bdSlukem default:
1552de962bdSlukem return 0;
1562de962bdSlukem }
1572de962bdSlukem return 1;
1582de962bdSlukem }
1592de962bdSlukem
1602de962bdSlukem
1612de962bdSlukem static void
private_conn_setup(LDAP * ld)1622de962bdSlukem private_conn_setup( LDAP *ld )
1632de962bdSlukem {
1642de962bdSlukem /* this seems prudent for searches below */
1652de962bdSlukem int deref = LDAP_DEREF_NEVER;
1662de962bdSlukem ldap_set_option( ld, LDAP_OPT_DEREF, &deref );
1672de962bdSlukem }
1682de962bdSlukem
1692de962bdSlukem
1702de962bdSlukem int
main(int argc,char ** argv)1712de962bdSlukem main( int argc, char **argv )
1722de962bdSlukem {
1732de962bdSlukem char buf[ 4096 ];
1744e6df137Slukem FILE *fp = NULL;
1752de962bdSlukem LDAP *ld;
1762de962bdSlukem int rc, retval;
1772de962bdSlukem
1782de962bdSlukem tool_init( TOOL_DELETE );
1792de962bdSlukem prog = lutil_progname( "ldapdelete", argc, argv );
1802de962bdSlukem
1812de962bdSlukem tool_args( argc, argv );
1822de962bdSlukem
1832de962bdSlukem if ( infile != NULL ) {
1842de962bdSlukem if (( fp = fopen( infile, "r" )) == NULL ) {
1852de962bdSlukem perror( optarg );
1862de962bdSlukem exit( EXIT_FAILURE );
1872de962bdSlukem }
1882de962bdSlukem } else {
1892de962bdSlukem if ( optind >= argc ) {
1902de962bdSlukem fp = stdin;
1912de962bdSlukem }
1922de962bdSlukem }
1932de962bdSlukem
1942de962bdSlukem ld = tool_conn_setup( 0, &private_conn_setup );
1952de962bdSlukem
1962de962bdSlukem tool_bind( ld );
1972de962bdSlukem
1982de962bdSlukem tool_server_controls( ld, NULL, 0 );
1992de962bdSlukem
2002de962bdSlukem retval = rc = 0;
2012de962bdSlukem
2022de962bdSlukem if ( fp == NULL ) {
2032de962bdSlukem for ( ; optind < argc; ++optind ) {
2042de962bdSlukem rc = dodelete( ld, argv[ optind ] );
2052de962bdSlukem
2062de962bdSlukem /* Stop on error and no -c option */
2072de962bdSlukem if( rc != 0 ) {
2082de962bdSlukem retval = rc;
2092de962bdSlukem if( contoper == 0 ) break;
2102de962bdSlukem }
2112de962bdSlukem }
2122de962bdSlukem } else {
2132de962bdSlukem while ((rc == 0 || contoper) && fgets(buf, sizeof(buf), fp) != NULL) {
2142de962bdSlukem buf[ strlen( buf ) - 1 ] = '\0'; /* remove trailing newline */
2152de962bdSlukem
2162de962bdSlukem if ( *buf != '\0' ) {
2172de962bdSlukem rc = dodelete( ld, buf );
2182de962bdSlukem if ( rc != 0 )
2192de962bdSlukem retval = rc;
2202de962bdSlukem }
2212de962bdSlukem }
2224e6df137Slukem if ( fp != stdin )
2234e6df137Slukem fclose( fp );
2242de962bdSlukem }
2252de962bdSlukem
226d11b170bStron tool_exit( ld, retval );
2272de962bdSlukem }
2282de962bdSlukem
2292de962bdSlukem
dodelete(LDAP * ld,const char * dn)2302de962bdSlukem static int dodelete(
2312de962bdSlukem LDAP *ld,
2322de962bdSlukem const char *dn)
2332de962bdSlukem {
2342de962bdSlukem int id;
2352de962bdSlukem int rc, code;
2362de962bdSlukem char *matcheddn = NULL, *text = NULL, **refs = NULL;
2372de962bdSlukem LDAPControl **ctrls = NULL;
2382de962bdSlukem LDAPMessage *res;
2392de962bdSlukem int subentries = 0;
2402de962bdSlukem
2412de962bdSlukem if ( verbose ) {
2422de962bdSlukem printf( _("%sdeleting entry \"%s\"\n"),
2432de962bdSlukem (dont ? "!" : ""), dn );
2442de962bdSlukem }
2452de962bdSlukem
2462de962bdSlukem if ( dont ) {
2472de962bdSlukem return LDAP_SUCCESS;
2482de962bdSlukem }
2492de962bdSlukem
2502de962bdSlukem /* If prune is on, remove a whole subtree. Delete the children of the
2512de962bdSlukem * DN recursively, then the DN requested.
2522de962bdSlukem */
2532de962bdSlukem if ( prune ) {
2542de962bdSlukem retry:;
2552de962bdSlukem deletechildren( ld, dn, subentries );
2562de962bdSlukem }
2572de962bdSlukem
2582de962bdSlukem rc = ldap_delete_ext( ld, dn, NULL, NULL, &id );
2592de962bdSlukem if ( rc != LDAP_SUCCESS ) {
2602de962bdSlukem fprintf( stderr, "%s: ldap_delete_ext: %s (%d)\n",
2612de962bdSlukem prog, ldap_err2string( rc ), rc );
2622de962bdSlukem return rc;
2632de962bdSlukem }
2642de962bdSlukem
2652de962bdSlukem for ( ; ; ) {
2662de962bdSlukem struct timeval tv;
2672de962bdSlukem
2682de962bdSlukem if ( tool_check_abandon( ld, id ) ) {
2692de962bdSlukem return LDAP_CANCELLED;
2702de962bdSlukem }
2712de962bdSlukem
2722de962bdSlukem tv.tv_sec = 0;
2732de962bdSlukem tv.tv_usec = 100000;
2742de962bdSlukem
2752de962bdSlukem rc = ldap_result( ld, LDAP_RES_ANY, LDAP_MSG_ALL, &tv, &res );
2762de962bdSlukem if ( rc < 0 ) {
2772de962bdSlukem tool_perror( "ldap_result", rc, NULL, NULL, NULL, NULL );
2782de962bdSlukem return rc;
2792de962bdSlukem }
2802de962bdSlukem
2812de962bdSlukem if ( rc != 0 ) {
2822de962bdSlukem break;
2832de962bdSlukem }
2842de962bdSlukem }
2852de962bdSlukem
2862de962bdSlukem rc = ldap_parse_result( ld, res, &code, &matcheddn, &text, &refs, &ctrls, 1 );
2872de962bdSlukem
2882de962bdSlukem switch ( rc ) {
2892de962bdSlukem case LDAP_SUCCESS:
2902de962bdSlukem break;
2912de962bdSlukem
2922de962bdSlukem case LDAP_NOT_ALLOWED_ON_NONLEAF:
2932de962bdSlukem if ( prune && !subentries ) {
2942de962bdSlukem subentries = 1;
2952de962bdSlukem goto retry;
2962de962bdSlukem }
2972de962bdSlukem /* fallthru */
2982de962bdSlukem
2992de962bdSlukem default:
3002de962bdSlukem fprintf( stderr, "%s: ldap_parse_result: %s (%d)\n",
3012de962bdSlukem prog, ldap_err2string( rc ), rc );
3022de962bdSlukem return rc;
3032de962bdSlukem }
3042de962bdSlukem
3052de962bdSlukem if( code != LDAP_SUCCESS ) {
3062de962bdSlukem tool_perror( "ldap_delete", code, NULL, matcheddn, text, refs );
3072de962bdSlukem } else if ( verbose &&
3082de962bdSlukem ((matcheddn && *matcheddn) || (text && *text) || (refs && *refs) ))
3092de962bdSlukem {
3102de962bdSlukem printf( _("Delete Result: %s (%d)\n"),
3112de962bdSlukem ldap_err2string( code ), code );
3122de962bdSlukem
3132de962bdSlukem if( text && *text ) {
3142de962bdSlukem printf( _("Additional info: %s\n"), text );
3152de962bdSlukem }
3162de962bdSlukem
3172de962bdSlukem if( matcheddn && *matcheddn ) {
3182de962bdSlukem printf( _("Matched DN: %s\n"), matcheddn );
3192de962bdSlukem }
3202de962bdSlukem
3212de962bdSlukem if( refs ) {
3222de962bdSlukem int i;
3232de962bdSlukem for( i=0; refs[i]; i++ ) {
3242de962bdSlukem printf(_("Referral: %s\n"), refs[i] );
3252de962bdSlukem }
3262de962bdSlukem }
3272de962bdSlukem }
3282de962bdSlukem
3292de962bdSlukem if (ctrls) {
3302de962bdSlukem tool_print_ctrls( ld, ctrls );
3312de962bdSlukem ldap_controls_free( ctrls );
3322de962bdSlukem }
3332de962bdSlukem
3342de962bdSlukem ber_memfree( text );
3352de962bdSlukem ber_memfree( matcheddn );
3362de962bdSlukem ber_memvfree( (void **) refs );
3372de962bdSlukem
3382de962bdSlukem return code;
3392de962bdSlukem }
3402de962bdSlukem
3412de962bdSlukem /*
3422de962bdSlukem * Delete all the children of an entry recursively until leaf nodes are reached.
3432de962bdSlukem */
deletechildren(LDAP * ld,const char * base,int subentries)3442de962bdSlukem static int deletechildren(
3452de962bdSlukem LDAP *ld,
3462de962bdSlukem const char *base,
3472de962bdSlukem int subentries )
3482de962bdSlukem {
3492de962bdSlukem LDAPMessage *res, *e;
3502de962bdSlukem int entries;
3512de962bdSlukem int rc = LDAP_SUCCESS, srch_rc;
3522de962bdSlukem static char *attrs[] = { LDAP_NO_ATTRS, NULL };
3532de962bdSlukem LDAPControl c, *ctrls[2], **ctrlsp = NULL;
3542de962bdSlukem BerElement *ber = NULL;
3552de962bdSlukem
3562de962bdSlukem if ( verbose ) printf ( _("deleting children of: %s\n"), base );
3572de962bdSlukem
3582de962bdSlukem if ( subentries ) {
3592de962bdSlukem /*
3602de962bdSlukem * Do a one level search at base for subentry children.
3612de962bdSlukem */
3622de962bdSlukem
3632de962bdSlukem if ((ber = ber_alloc_t(LBER_USE_DER)) == NULL) {
3642de962bdSlukem return EXIT_FAILURE;
3652de962bdSlukem }
3662de962bdSlukem rc = ber_printf( ber, "b", 1 );
3672de962bdSlukem if ( rc == -1 ) {
3682de962bdSlukem ber_free( ber, 1 );
3692de962bdSlukem fprintf( stderr, _("Subentries control encoding error!\n"));
3702de962bdSlukem return EXIT_FAILURE;
3712de962bdSlukem }
3722de962bdSlukem if ( ber_flatten2( ber, &c.ldctl_value, 0 ) == -1 ) {
3732de962bdSlukem return EXIT_FAILURE;
3742de962bdSlukem }
3752de962bdSlukem c.ldctl_oid = LDAP_CONTROL_SUBENTRIES;
3762de962bdSlukem c.ldctl_iscritical = 1;
3772de962bdSlukem ctrls[0] = &c;
3782de962bdSlukem ctrls[1] = NULL;
3792de962bdSlukem ctrlsp = ctrls;
3802de962bdSlukem }
3812de962bdSlukem
3822de962bdSlukem /*
3832de962bdSlukem * Do a one level search at base for children. For each, delete its children.
3842de962bdSlukem */
3852de962bdSlukem more:;
3862de962bdSlukem srch_rc = ldap_search_ext_s( ld, base, LDAP_SCOPE_ONELEVEL, NULL, attrs, 1,
3872de962bdSlukem ctrlsp, NULL, NULL, sizelimit, &res );
3882de962bdSlukem switch ( srch_rc ) {
3892de962bdSlukem case LDAP_SUCCESS:
3902de962bdSlukem case LDAP_SIZELIMIT_EXCEEDED:
3912de962bdSlukem break;
3922de962bdSlukem default:
3932de962bdSlukem tool_perror( "ldap_search", srch_rc, NULL, NULL, NULL, NULL );
3942de962bdSlukem return( srch_rc );
3952de962bdSlukem }
3962de962bdSlukem
3972de962bdSlukem entries = ldap_count_entries( ld, res );
3982de962bdSlukem
3992de962bdSlukem if ( entries > 0 ) {
4002de962bdSlukem int i;
4012de962bdSlukem
4022de962bdSlukem for (e = ldap_first_entry( ld, res ), i = 0; e != NULL;
4032de962bdSlukem e = ldap_next_entry( ld, e ), i++ )
4042de962bdSlukem {
4052de962bdSlukem char *dn = ldap_get_dn( ld, e );
4062de962bdSlukem
4072de962bdSlukem if( dn == NULL ) {
4082de962bdSlukem ldap_get_option( ld, LDAP_OPT_RESULT_CODE, &rc );
4092de962bdSlukem tool_perror( "ldap_prune", rc, NULL, NULL, NULL, NULL );
4102de962bdSlukem ber_memfree( dn );
4112de962bdSlukem return rc;
4122de962bdSlukem }
4132de962bdSlukem
4142de962bdSlukem rc = deletechildren( ld, dn, 0 );
4152de962bdSlukem if ( rc != LDAP_SUCCESS ) {
4162de962bdSlukem tool_perror( "ldap_prune", rc, NULL, NULL, NULL, NULL );
4172de962bdSlukem ber_memfree( dn );
4182de962bdSlukem return rc;
4192de962bdSlukem }
4202de962bdSlukem
4212de962bdSlukem if ( verbose ) {
4222de962bdSlukem printf( _("\tremoving %s\n"), dn );
4232de962bdSlukem }
4242de962bdSlukem
4252de962bdSlukem rc = ldap_delete_ext_s( ld, dn, NULL, NULL );
4262de962bdSlukem if ( rc != LDAP_SUCCESS ) {
4272de962bdSlukem tool_perror( "ldap_delete", rc, NULL, NULL, NULL, NULL );
4282de962bdSlukem ber_memfree( dn );
4292de962bdSlukem return rc;
4302de962bdSlukem
4312de962bdSlukem }
4322de962bdSlukem
4332de962bdSlukem if ( verbose ) {
4342de962bdSlukem printf( _("\t%s removed\n"), dn );
4352de962bdSlukem }
4362de962bdSlukem
4372de962bdSlukem ber_memfree( dn );
4382de962bdSlukem }
4392de962bdSlukem }
4402de962bdSlukem
4412de962bdSlukem ldap_msgfree( res );
4422de962bdSlukem
4432de962bdSlukem if ( srch_rc == LDAP_SIZELIMIT_EXCEEDED ) {
4442de962bdSlukem goto more;
4452de962bdSlukem }
4462de962bdSlukem
4472de962bdSlukem return rc;
4482de962bdSlukem }
449