From 3295ecee421bbfab950bf5e4bb32e9cc95746f5e Mon Sep 17 00:00:00 2001
From: Valery Kharseko <vharseko@3a-systems.ru>
Date: Wed, 30 Sep 2026 12:25:59 +0000
Subject: [PATCH] [#1118] Register the shipped Referential Integrity plugin for the pre-operation types check-references needs, and refuse check-references without them (#1123)

---
 opendj-server-legacy/src/main/java/org/opends/server/tools/upgrade/Upgrade.java |   18 +++++++++++++++++-
 1 files changed, 17 insertions(+), 1 deletions(-)

diff --git a/opendj-server-legacy/src/main/java/org/opends/server/tools/upgrade/Upgrade.java b/opendj-server-legacy/src/main/java/org/opends/server/tools/upgrade/Upgrade.java
index 10b0590..f20ba21 100644
--- a/opendj-server-legacy/src/main/java/org/opends/server/tools/upgrade/Upgrade.java
+++ b/opendj-server-legacy/src/main/java/org/opends/server/tools/upgrade/Upgrade.java
@@ -97,6 +97,12 @@
       "cn: End Transaction",
       "ds-cfg-java-class: org.opends.server.extensions.EndTransactionExtendedOperation",
       "ds-cfg-enabled: true" };
+  static final String REFERENTIAL_INTEGRITY_PLUGIN_FILTER =
+      "(objectClass=ds-cfg-referential-integrity-plugin)";
+  static final String[] ADD_REFERENTIAL_INTEGRITY_PRE_OPERATION_PLUGIN_TYPES = {
+      "add: ds-cfg-plugin-type",
+      "ds-cfg-plugin-type: preOperationAdd",
+      "ds-cfg-plugin-type: preOperationModify" };
 
   static
   {
@@ -638,6 +644,16 @@
             START_TRANSACTION_HANDLER_ENTRY),
         addConfigEntry(END_TRANSACTION_HANDLER_ENTRY));
 
+    /* See issue #1118: the shipped Referential Integrity plugin entry lacked the pre-operation plugin
+     * types that check-references runs in, so turning check-references on checked nothing. The plugin
+     * now refuses check-references without them, so every referential integrity plugin entry gets them:
+     * the add is permissive, and the upgrade schema matches plugin types ignoring case, so a type an
+     * administrator already added is not added a second time. */
+    register("5.2.0",
+        modifyConfigEntry(INFO_UPGRADE_TASK_ADD_REFERENTIAL_INTEGRITY_PRE_OPERATION_PLUGIN_TYPES.get(),
+            REFERENTIAL_INTEGRITY_PLUGIN_FILTER,
+            ADD_REFERENTIAL_INTEGRITY_PRE_OPERATION_PLUGIN_TYPES));
+
     /*
      * See issue #746. Builds before #661 (fixed in 5.1.2) shipped a duplicate
      * org.openidentityplatform.opendj.opendj-server-legacy.jar alongside opendj.jar in lib/.
@@ -763,7 +779,7 @@
    * @return A list containing all the tasks which are required in order to upgrade
    *         from {@code fromVersion} to {@code toVersion}.
    */
-  private static List<UpgradeTask> getUpgradeTasks(final BuildVersion fromVersion, final BuildVersion toVersion)
+  static List<UpgradeTask> getUpgradeTasks(final BuildVersion fromVersion, final BuildVersion toVersion)
   {
     final List<UpgradeTask> tasks = new LinkedList<>();
     try {

--
Gitblit v1.10.0