On 8/15/21 4:36 PM, Michael Ströder wrote:
> First tests (OpenLDAP 2.5/master) show with customer ACLs reading all
> attrs of 100k user entries and one huge group entry takes
>
> 2m23.459s with standard acl.c
>
> but only
>
> 1m22.718s with patched acl.c which evaluates attrs= before dn.regex= a
On 8/15/21 9:12 PM, Howard Chu wrote:
> And what about non-regex forms of DN checking, which are more common
> than regex?
And that's why I suggest in ITS#9634 that DN simple checks are split
from dn.regex.
> Nobody can validate your conclusions since you haven't provided the
> actual test cases.
Michael Ströder wrote:
> HI!
>
> Moving this thread here to openldap-devel because it's not a usage
> question anymore:
>
> https://lists.openldap.org/hyperkitty/list/openldap-techni...@openldap.org/message/E4BK5DA5DUAUYLJT6DRGKV45SQBZJ5XZ/
>
> TL;DR:
> 1. Would you consider the attached patch a
HI!
Moving this thread here to openldap-devel because it's not a usage
question anymore:
https://lists.openldap.org/hyperkitty/list/openldap-techni...@openldap.org/message/E4BK5DA5DUAUYLJT6DRGKV45SQBZJ5XZ/
TL;DR:
1. Would you consider the attached patch as a valid solution?
2. Improving slapo-co