https://bugs.openldap.org/show_bug.cgi?id=10455
Issue ID: 10455 Summary: Allow handling of empty group in memberof_saveMember_cb() Product: OpenLDAP Version: 2.6.12 Hardware: All OS: All Status: UNCONFIRMED Keywords: needs_review Severity: normal Priority: --- Component: overlays Assignee: bugs@openldap.org Reporter: roger.j.meier@gmx.ch Target Milestone: ---
Created attachment 1117 --> https://bugs.openldap.org/attachment.cgi?id=1117&action=edit Protect e_attrs with a NULL pointer test instead of an assert() to allow empty groups
In slapd/overlays/memberof.c, the callback
memberof_saveMember_cb()
uses two assert statements for the sr_entry and its e_attrs pointer in sequence. This makes the service abort on an empty group. If the use of rs->sr_entry->e_attrs is just protected by a test of the e_attrs pointer, the code does not abort and allows empty groups.
Please consider to add this patch to the official source.
It was now several month in production and did not lead to unexpected results.
https://bugs.openldap.org/show_bug.cgi?id=10455
Quanah Gibson-Mount quanah@openldap.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Keywords|needs_review | Target Milestone|--- |2.7.0 Assignee|bugs@openldap.org |hyc@openldap.org
https://bugs.openldap.org/show_bug.cgi?id=10455
--- Comment #1 from Ondřej Kuzník ondra@mistotebe.net --- On Thu, Feb 26, 2026 at 10:19:10AM +0000, openldap-its@openldap.org wrote:
In slapd/overlays/memberof.c, the callback
memberof_saveMember_cb()
uses two assert statements for the sr_entry and its e_attrs pointer in sequence. This makes the service abort on an empty group. If the use of rs->sr_entry->e_attrs is just protected by a test of the e_attrs pointer, the code does not abort and allows empty groups.
Hi Roger, could you provide a configuration where this happens?
Thanks,
https://bugs.openldap.org/show_bug.cgi?id=10455
Quanah Gibson-Mount quanah@openldap.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Target Milestone|2.7.0 |2.7.1
https://bugs.openldap.org/show_bug.cgi?id=10455
Quanah Gibson-Mount quanah@openldap.org changed:
What |Removed |Added ---------------------------------------------------------------------------- Target Milestone|2.7.1 |2.7.2
https://bugs.openldap.org/show_bug.cgi?id=10455
--- Comment #2 from Ondřej Kuzník ondra@mistotebe.net --- Looks like there is (only) one place that can return an entry with e_attrs == NULL, that's back-ldap's ldap_build_entry().
Incidentally, it can also violate the following assert in memberof_saveMember_cb as well as it doesn't check that sender actually follows RFC4511 to the letter ("Attributes are returned at most once in an entry").
So yes, the first assert can be removed (attr_find can handle a NULL) and back-ldap should detect the RFC 4511 violation. Seems like ldap_build_entry papers over a lot of violations already, so merging the values in sounds like the right approach.
A fix is coming.
https://bugs.openldap.org/show_bug.cgi?id=10455
Ondřej Kuzník ondra@mistotebe.net changed:
What |Removed |Added ---------------------------------------------------------------------------- Status|UNCONFIRMED |IN_PROGRESS Assignee|hyc@openldap.org |ondra@mistotebe.net Ever confirmed|0 |1
--- Comment #3 from Ondřej Kuzník ondra@mistotebe.net --- https://git.openldap.org/openldap/openldap/-/merge_requests/918
https://bugs.openldap.org/show_bug.cgi?id=10455
--- Comment #4 from Quanah Gibson-Mount quanah@openldap.org --- head:
• ccd8a1f7 by Ondřej Kuzník at 2026-09-09T12:47:26+01:00 ITS#10455 memberof: drop unnecessary assert()
• 725ae5b0 by Ondřej Kuzník at 2026-09-09T13:51:12+01:00 ITS#10455 back-ldap: correct sender's RFC4511 violations