opravil-jan opened a new pull request, #117:
URL: https://github.com/apache/directory-studio/pull/117

   > **Depends on #116.** This branch is built on it so the new unit tests 
actually run in CI. Until #116 is merged, its commit (`build(test): run the 
plugins' JUnit 5 unit tests`) also shows up here. Only the three 
`fix(syncrepl)` commits belong to this PR.
   
   This fixes three bugs in `openldap.syncrepl`, one commit each, each with a 
regression test.
   
   ### 1. Parser hangs on a backslash in a quoted value
   `getQuotedOrNotQuotedOptionValue` consumed a backslash only when it escaped 
the closing quote. Any other backslash never advanced the position, so values 
like `credentials="p\ss"` or `tls_cacert="C:\certs\ca.pem"` looped forever. The 
parser is called from `DatabasesDetailsPage.getReplicationConsumerText` (a 
label provider), so opening an OpenLDAP config with such an `olcSyncrepl` value 
froze Studio.
   
   The fix follows slapd's `strtok_quote()` (`servers/slapd/config.c`): the 
backslash is dropped and the next character is taken literally, and a trailing 
backslash is kept. This means Studio now shows the value exactly as slapd reads 
it. `tls_cacert="C:\certs\ca.pem"` shows up as `C:certsca.pem`, which is what 
slapd actually uses.
   
   ### 2. `tls_cacertdir` could not be parsed
   `tls_cacert` was checked first and is a prefix of `tls_cacertdir`, so the 
option failed and the whole syncrepl value was rejected. The longer keyword is 
now checked first. I checked all 35 keywords and found no other prefix conflict.
   
   ### 3. Values written between quotes were not escaped
   `SyncRepl.toString()`, which produces the `olcSyncrepl` value that is 
written to the server, had two problems:
   - It wrote `credentials` unquoted, so a password with a space broke the 
directive.
   - It did not escape backslashes in quoted values. slapd strips those, so a 
filter like `(cn=a\2ab)` or a bind DN like `cn=Smith\, John,dc=example,dc=com` 
was changed on save.
   
   All quoted values (searchbase, filter, retry, attrs, binddn, authcid, 
authzid, credentials, logbase, logfilter) now have `\` and `"` escaped.
   
   ### Tests
   There are 5 new tests in `SyncReplParserTest`. Each one failed before its 
fix: a timeout for the hangs, a parse exception for `tls_cacertdir`, and 
assertion failures for the round trips. The two hang tests use 
`@Timeout(threadMode = SEPARATE_THREAD)`, because the loop never checks for 
interruption. Each commit passes on its own: 78, 79 and then 82 tests. 
`openldap.config.editor`, which uses `SyncRepl`, passes too (34 tests).
   
   ### Known remaining issues (not changed here)
   - `realm`, `secprops`, the `tls_*` paths and `syncdata` are still written 
unquoted, so values containing spaces or backslashes are still misread by slapd.
   - The parser also accepts `'...'` quoting, which slapd does not.
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to