<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<html lang="en" style='--code-editor-font: var(--default-mono-font, "GitLab Mono"), JetBrains Mono, Menlo, DejaVu Sans Mono, Liberation Mono, Consolas, Ubuntu Mono, Courier New, andale mono, lucida console, monospace;'>
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
<title>
GitLab
</title>

<style data-premailer="ignore" type="text/css">
a { color: #1068bf; }
</style>


<style>img {
max-width: 100%; height: auto;
}
body {
font-size: .875rem;
}
body {
-webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px;
}
body {
font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji"; font-size: inherit;
}
</style>
</head>
<body style='font-size: inherit; -webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px; font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji";'>
<div class="content">

<h3 style="margin-top: 20px; margin-bottom: 10px;">
Timo Aaltonen pushed to branch master at <a href="https://salsa.debian.org/freeipa-team/389-ds-base">FreeIPA packaging / 389-ds-base</a>
</h3>
<h4 style="margin-top: 10px; margin-bottom: 10px;">
Commits:
</h4>
<ul>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/e19137fb0270ad825d8618d8eaa92950142485da">e19137fb</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2025-12-16T15:48:35-08:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7150 - Compressed access log rotations skipped, accesslog-list out of sync (#7151)

Description: Accept `.gz`-suffixed rotated log filenames when
rebuilding rotation info and checking previous logs, preventing
compressed rotations from being dropped from the internal list.

Add regression tests to stress log rotation with compression,
verify `nsslapd-accesslog-list` stays in sync, and guard against
crashes when flushing buffered logs during rotation.
Minor doc fix in test.

Fixes: https://github.com/389ds/389-ds-base/issues/7150

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/018247ecd0f61027003060f7b38abeb2a9fac33b">018247ec</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2025-12-17T15:53:07+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket47970 test to sasl/regression_test.py using DSLdapObject (#7146)

Description: The old ticket47970_test.py had compatibility issues.
This ports the functionality to sasl/regression_test.py using modern DSLdapObject methods.

Relates: https://github.com/389ds/389-ds-base/issues/6753

Reviewed by: @progier389</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/346e4306f6d93fbebbb9d2ced92633b80087fe86">346e4306</a></strong>
<div>
<span> by progier389 </span> <i> at 2025-12-17T14:35:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6951 - Dynamic Certificate refresh phase 2 - Add/Modify/Delete support (#7140)

Second phase of Dynamic Certificate Refresh

cn=dynamiccertificates backend now supports the following operations:

add
modify
modrdn
delete
Allowing to store and modify dynamically the nss database

issue: #6951

Reviewed by: @tbordaz (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/de9459d6c073971311eea97ad4f03a029ff39a9b">de9459d6</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2025-12-17T19:09:51+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket47953 test to acl/misc_test.py using DSLdapObject (#7153)

Description: The old ticket47953_test.py had compatibility issues.
This ports the functionality to acl/misc_test.py::test_delete_aci_with_invalid_syntax
using modern DSLdapObject methods.

Relates: https://github.com/389ds/389-ds-base/issues/6753

Reviewed by: @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/978148d4ca64762168267615133c38e6dbebbf64">978148d4</a></strong>
<div>
<span> by Stanislav Levin </span> <i> at 2025-12-18T16:20:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Make nss include paths platform-agnostic (#7159)

Bug Description:
The NSS headers can be packaged in different paths on different
platforms.

Fix Description:
Rely on pkg-config to include correct platform paths.

Fixes: https://github.com/389ds/389-ds-base/issues/7158

Reviewed by: (Thanks!)

Signed-off-by: Stanislav Levin <slev@altlinux.org></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/8c2229a02e0d8d6ef8573e014073f27d4cef523c">8c2229a0</a></strong>
<div>
<span> by progier389 </span> <i> at 2025-12-19T12:45:06+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7155 - build_candidate_list - Database error 11 with range search (#7156)

Range search behavior discrepancy when hitting nsslapd-rangelookthroughlimit whether filter_candidates_ext returns a short or long list of candidates:
Search is successful if the candidate list is long but fail if it is short
Error should be ignored in both case

Issue: #7155

Reviewed by: @tbordaz (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/38045ad5785334d3d8aa022628656813e5e3fd3b">38045ad5</a></strong>
<div>
<span> by progier389 </span> <i> at 2025-12-19T12:46:42+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6951 - Dynamic Certificate refresh phase 3 - Certificates switch (#7157)

Third phase of Dynamic Certificate Refresh

cn=dynamiccertificates backend now supports the following operations:

server certificate is switched when modified. This is done by:

Block listening and accept threads (to ensure that they are not in a middle of an I/O
Removing SSL layer from listening FileDescriptor
Switch Certificate in NSS layers
Add back SSl layer with new certificates in listening FileDescriptor
Unblock all the threads
Allowing to store and modify dynamically the nss database

issue: #6951

Reviewed by: @tbordaz, @jchapma (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/5f15223280002803a932187c22b10beaeaa74bc2">5f152232</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-01-05T14:38:38+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7166 - db_config_set asserts because of dynamic list (#7167)

Avoid assertion in db_config_set when args does not contains dynamic list attributes

Issue: #7166

Reviewed by: @tbordaz (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/57fb09fbf899a91faadc3736386ce7781af1089a">57fb09fb</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-01-05T18:32:52-08:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7160 - Add lib389 version sync check to configure (#7165)

Description: Add version validation during configure that ensures
lib389 version in pyproject.toml matches the main project version
in VERSION.sh. Configure fails with clear error message and fix
instructions when versions mismatch, preventing inconsistent releases.

Fixes: https://github.com/389ds/389-ds-base/issues/7160

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/37dcafc0bbbdec8be4e392136e54b3b146ac56fc">37dcafc0</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-01-06T08:58:09-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Bump version to 3.2.0
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/1c9c535888b9a850095794787d67900b04924a76">1c9c5358</a></strong>
<div>
<span> by tbordaz </span> <i> at 2026-01-07T11:21:12+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7096 - During replication online total init the function idl_id_is_in_idlist is not scaling with large database (#7145)

Bug description:
        During a online total initialization, the supplier sorts
        the candidate list of entries so that the parents are sent before
        children entries.
        With large DB the ID array used for the sorting is not
        scaling. It takes so long to build the candidate list that
        the connection gets closed

Fix description:
        Instead of using an ID array, uses a list of ID ranges

fixes: #7096

Reviewed by: Mark Reynolds, Pierre Rogier (Thanks !!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/446bc42e7b64a8496c2c3fe486f86bba318bed5e">446bc42e</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-01-08T08:31:14-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue - Revise paged result search locking

Description:

Move to a single lock approach verses having two locks. This will impact
concurrency when multiple async paged result searches are done on the same
connection, but it simplifies the code and avoids race conditions and
deadlocks.

Relates: https://github.com/389ds/389-ds-base/issues/7118

Reviewed by: progier & tbordaz (Thanks!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4936f953fa3b0726c2b178f135cd78dcac7463ba">4936f953</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-01-08T10:02:39-08:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7108 - Fix shutdown crash in entry cache destruction (#7163)

Description: The entry cache could experience LRU list corruption when
using pinned entries, leading to crashes during cache flush operations.

In entrycache_add_int(), when returning an existing cached entry, the
code checked the wrong entry's state before calling lru_delete(). It
checked the new entry 'e' but operated on the existing entry 'my_alt',
causing lru_delete() to be called on entries not in the LRU list. This
is fixed by checking my_alt's refcnt and pinned state instead.

In flush_hash(), pinned_remove() and lru_delete() were both called on
pinned entries. Since pinned entries are in the pinned list, calling
lru_delete() afterwards corrupted the list. This is fixed by calling
either pinned_remove() or lru_delete() based on the entry's state.

A NULL check is added in entrycache_flush() and dncache_flush() to
gracefully handle corrupted LRU lists and prevent crashes when
traversing backwards through the list encounters an unexpected NULL.

Entry pointers are now always cleared after lru_delete() removal to
prevent stale pointer issues in non-debug builds.

Fixes: https://github.com/389ds/389-ds-base/issues/7108

Reviewed by: @progier389, @vashirov (Thanks!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/742c12e0247ab64e87da000a4de2f3e5c99044ab">742c12e0</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-01-09T11:39:50+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7172 - Index ordering mismatch after upgrade (#7173)

Bug Description:
Commit daf731f55071d45eaf403a52b63d35f4e699ff28 introduced a regression.
After upgrading to a version that adds `integerOrderingMatch` matching
rule to `parentid` and `ancestorid` indexes, searches may return empty
or incorrect results.

This happens because the existing index data was created with
lexicographic ordering, but the new compare function expects integer
ordering. Index lookups fail because the compare function doesn't match
the data ordering.
The root cause is that `ldbm_instance_create_default_indexes()` calls
`attr_index_config()` unconditionally for `parentid` and `ancestorid`
indexes, which triggers `ainfo_dup()` to overwrite `ai_key_cmp_fn` on
existing indexes. This breaks indexes that were created without the
`integerOrderingMatch` matching rule.

Fix Description:
* Call `attr_index_config()` for `parentid` and `ancestorid` indexes
only if index config doesn't exist.

* Add `upgrade_check_id_index_matching_rule()` that logs an error on
server startup if `parentid` or `ancestorid` indexes are missing the
integerOrderingMatch matching rule, advising administrators to reindex.

Fixes: https://github.com/389ds/389-ds-base/issues/7172

Reviewed by: @tbordaz, @progier389, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/f5de84e309d5a4435198c9cc9b31b5722979f1ff">f5de84e3</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-01-12T10:58:02+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7172 - (2nd) Index ordering mismatch after upgrade (#7180)

Commit 742c12e0247ab64e87da000a4de2f3e5c99044ab introduced a regression
where the check to skip creating parentid/ancestorid indexes if they
already exist was incorrect.
The `ainfo_get()` function falls back to returning
LDBM_PSEUDO_ATTR_DEFAULT attrinfo when the requested attribute is not
found.
Since LDBM_PSEUDO_ATTR_DEFAULT is created before the ancestorid check,
`ainfo_get()` returns LDBM_PSEUDO_ATTR_DEFAULT instead of NULL, causing
the ancestorid index creation to be skipped entirely.

When operations later try to use the ancestorid index, they fall back to
LDBM_PSEUDO_ATTR_DEFAULT, and attempting to open the .default dbi
mid-transaction fails with MDB_NOTFOUND (-30798).

Fix Description:
Instead of just checking if `ainfo_get()` returns non-NULL, verify that
the returned attrinfo is actually for the requested attribute.

Fixes: https://github.com/389ds/389-ds-base/issues/7172

Reviewed by: @tbordaz (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/fb23c9e366f5eafa6bdbb8cd71afd78e3edefde2">fb23c9e3</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-01-13T15:14:15+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 548 test (#7101)

Description:
Port ticket 548 test into
dirsrvtests/tests/suites/password/pwdPolicy_attribute_test.py

Relates: #6753

Author: Lenka Doudova, aadhikar
Assisted by: Cursor
Reviewer: @droideck(Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/7c8a16c6bed524fb54d18a5b7e93d4bd5bb19d49">7c8a16c6</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-01-14T17:55:29+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7152 - ns-slapd fails to shutdown when deferred memberof update is in progress (#7187)

Bug Description:
When a deferred memberof update is in progress during shutdown, the
backend operations (add, modify, delete, modrdn) wait in a polling loop
for the deferred task to complete. However, if the deferred thread exits
before clearing the SLAPI_DEFERRED_MEMBEROF flag, the loop becomes
infinite, causing the server to hang during shutdown.

Fix Description:
Add additional check to the polling loops so they exit immediately when
the server is shutting down.

Fixes: https://github.com/389ds/389-ds-base/issues/7152

Reviewed by: @tbordaz (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a84a6a7d8323316bfa4055729a3604a0fcfebaf9">a84a6a7d</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-01-16T19:35:42+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7169 - Fix automember_plugin CI test failures (#7181)

Description: Issue 7053 removed member cleanup from MemberOf plugin,
transferring it to Referential Integrity plugin. Enable this plugin
in automember tests and clean up groups before rebuild task tests.

Fixes: #7169

Reviewed by: @progier389</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/5b32479abcd68f8b37d2fb207c502113a5b4b16c">5b32479a</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-01-19T19:45:29+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6758 - Use OUIA selectors for WebUI plugin tests (#7182)

Description:
Add ouiaId to plugin NavItems and update tests to use OUIA selectors
instead of text matching.

Relates: #6758

Reviewed by: @droideck</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/9bd93dc618c261d52222e713c56500abbce4113e">9bd93dc6</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-01-19T17:24:40+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7196 - DynamicCertificates returns empty DER (#7197)

Fixing a mistake done while fixing memory leaks.
Value was freed before being added in the entry rather than after ...

Issue: #7196

Reviewed by: @jchapma (thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/c6f458b421598b18a545582441472b910b5ba56e">c6f458b4</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-01-20T09:52:47+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7189 - DSBLE0007 generates incorrect remediation commands for scan limits

Bug Description:

The generated dsconf commands for fixing missing system indexes had two issues:

1. The --add-scanlimit value was not quoted, causing the shell to interpret
   "limit=5000 type=eq flags=AND" as multiple arguments instead of a single
   value, resulting in "unrecognized arguments: type=eq flags=AND" error.

2. When both matching rule and scanlimit were missing, two separate commands
   were generated where the second would fail because the matching rule was
   already added by the first command.

Fix Description:

1. Quote the scanlimit value in all remediation commands

2. Combine matching rule and scanlimit fixes into a single command when
   both are missing for the same index instead of expected_scanlimit)

Fixes: https://github.com/389ds/389-ds-base/issues/7189

Reviewed by: @progier389, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/6ce33b1bedd2cd13d7e6544692354715f6e613b8">6ce33b1b</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-01-20T19:41:05+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7170 - Support of PQC keys (#7188)

Support of Post Quantum Cryptography Keys in certificates:
Added support of a new key type: ML_DSA
Enable the following policies (that are not enabled by defaut): ML-DSA-44, ML-DSA-65- ML-DSA-87
Replaced deprecated function SSL_ConfigSecureServer by SSL_ConfigServerCert
Added test case for ML-DSA certificate. That test case rely of openssl command because python cryptography module does not yet support ML-DSA keys

Issue: #7170

Reviewed by: @tbordaz, @droideck and @vashirov (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4068f68bea77f466f9b3d87c766ea14d2f175b17">4068f68b</a></strong>
<div>
<span> by dependabot[bot] </span> <i> at 2026-01-21T19:58:46-08:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Bump lodash from 4.17.21 to 4.17.23 in /src/cockpit/389-console (#7203)

Bumps [lodash](https://github.com/lodash/lodash) from 4.17.21 to 4.17.23.
- [Release notes](https://github.com/lodash/lodash/releases)
- [Commits](https://github.com/lodash/lodash/compare/4.17.21...4.17.23)

---
updated-dependencies:
- dependency-name: lodash
  dependency-version: 4.17.23
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/3ff253af76df07fe0519481795b7ed155fefaa9e">3ff253af</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-01-23T17:35:45-08:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7198 - Web console doesn't show sub-suffix when parent-suffix points to an entry (#7202)

Description: The web console doesn't show sub-suffixes when the
nsslapd-parent-suffix attribute points to an entry rather than a backend
suffix.
For example, creating a sub-suffix ou=foo,ou=people,dc=example,dc=com
with parent-suffix ou=people,dc=example,dc=com (where ou=people is just an
entry, not a suffix) would not appear in the web console tree.

Fix: In backend_build_tree() and get_sub_suffixes(), the code only matched
when nsslapd-parent-suffix exactly equaled an existing backend suffix.
Now it also checks if the parent-suffix is an entry under the current
suffix (ends with ,suffix) and is not itself a backend suffix. This
correctly attaches sub-suffixes to their containing suffix when the
parent-suffix points to an intermediate entry.

Fixes: https://github.com/389ds/389-ds-base/issues/7198

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/aa24c00d9ed1ea9730c0e8c5dccc1bbb5b61e312">aa24c00d</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-01-26T16:46:21+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7014 - memberOf - ignored deferred updates with LMDB

Description:
Fix typo in pytest marker reason.

Relates: #7014

Author: Lenka Doudova
Reviewed by: ???
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4a73a31e6c91e507e5aa2cba1e5bd55d1d07894d">4a73a31e</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-01-26T13:46:56-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7184 - argparse.HelpFormatter _format_actions_usage() is deprecated

Description:

_format_actions_usage() was removed in python 3.15. Instead we can use
_get_actions_usage_parts() but it also behaves differently between
python 3.14 and 3.15 so we need special handling.

Relates: https://github.com/389ds/389-ds-base/issues/7184

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/bc28406778534a77064a26b4f0467dffecde33ea">bc284067</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-01-27T09:40:12+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6947 - Revise time skew check in healthcheck tool - add tests (#7208)

Description:
Add tests for DSSKEWLE0003 and DSSKEWLE0004 checks.

Relates: https://github.com/389ds/389-ds-base/issues/6947

Reviewed by: @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a53c0e4dea5c35fef196500b2a36c92bc8f07a51">a53c0e4d</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-01-27T09:49:16+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7201 - Syscall overhead in LMDB import writer thread (#7204)

Bug Description:
ldif2db import is slower with LMDB than with BDB (~3500 vs ~4500
entries/s) due to 2 issues:
1. The MDB_STAT_STEP macro calls `clock_gettime()` to collect
performance statistics. This was called on every single operation inside
the writer loop, resulting in ~3 syscalls per write or ~6000 syscalls
per transaction (with 2000 as the default batch size).

2. In `dbmdb_import_workerq_push()`, after copying work to a worker
slot, the condition variable was never signaled. This caused workers to
spend up to 100ms in `safe_cond_wait()` before checking for new work,
severely limiting import throughput.

Fix Description:
1. Add a new config parameter `nsslapd-mdb-import-stats` (default: off)
   to control whether performance statistics collection is enabled.
2. Add `pthread_cond_broadcast()` immediately after copying data to wake
   the workers.

After applying these fixes ldif2db import rate is about ~10000 entries/s.

Fixes: https://github.com/389ds/389-ds-base/issues/7201

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/40484cb0b5034bc3c1e23b2ae1f2d39eedce07e9">40484cb0</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-01-27T14:26:29+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7096 - (2nd) During replication online total init the function idl_id_is_in_idlist is not scaling with large database (#7205)

Bug Description:
The fix for #7096 optimized the BDB backend's `idl_new_range_fetch()`
function to use ID ranges instead of checking the full ID list during
online total initialization. However, the LMDB backend's
`idl_lmdb_range_fetch()` function and its callback
`idl_range_add_id_cb()` were not updated and still use the non-scaling
`idl_id_is_in_idlist()` function.

Fix Description:
Apply the same optimization to the LMDB backend.

Fixes: https://github.com/389ds/389-ds-base/issues/7096

Reviewed by: @tbordaz, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/8c6d1cfca22f87b20b79a419ceabdb182846ff4a">8c6d1cfc</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-01-27T15:39:39+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7206 - Should log whether TLS key is PQC or not (#7207)

Append [PQC] to the cipher name when logging SSL/TLS if the Key Exchange is one of the KEM group
If connection debug level is enabled, logs in error log the keaType and keaGroup (as integer)

Issue: #7206

Reviewed by: @tbordaz, @droideck (Thanks!)

* Issue 7206 - Should log whether TLS key is PQC or not

* Fix Sourcery A/I comments

* Check PQC in test case

* Update ldap/servers/slapd/auth.c

Co-authored-by: Simon Pichugin <spichugi@redhat.com>

---------

Co-authored-by: Simon Pichugin <spichugi@redhat.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/27d3ea211847fa7ae674c5e4dcf485706e4ac591">27d3ea21</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-01-30T12:00:13+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7027 - (2nd) 389-ds-base OpenScanHub Leaks Detected (#7211)

Fix Description:
Update coverity annotations.

Relates: https://github.com/389ds/389-ds-base/issues/7027

Reviewed by: @aadhikar (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/5ebce22d4214bec5ed94ad84c4448164be99389a">5ebce22d</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-02-02T15:39:18+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7213 - MDB_BAD_VALSIZE error while handling VLV (#7214)

* Issue 7213 - MDB_BAD_VALSIZE error while handling VLV
Avoid failing lmdb operation when handling VLV index by truncating the key so that key+data is small enough.

Issue: #7213

Reviewed by: @mreynolds389 , @vashirov (Thanks!)

Assisted by: Claude A/I
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/56f1881b5fb0198af4810eeca9e98736c297a2a5">56f1881b</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-02-03T10:28:02+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 47781 test (#7210)

Description:
Port ticket 47781 test into dirsrvtests/tests/suites/replication/replication_deadlock_test.py

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: Mark Reynolds</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/c2921e87bf8e8fee566edd09cb528b1c3ac3e41d">c2921e87</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-02-03T17:17:02-08:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7194 - Repl Log Analysis - Add CSN propagation details (#7195)

Description: The replication log analyzer now shows per‑CSN propagation
details and the console UI can drill into them from chart points. This
adds CSN IDs to chart datapoints, builds detailed arrivals/hops data, and
links replica IDs to origin servers for more accurate origin detection.

The report JSON now includes csnDetails and sampling metadata; when
sampling is active, CSN details are limited to sampled IDs to control
memory use. A new originIncludedInArrivals flag is exposed and the UI
shows an explicit note when origin records are outside the time range.
The cockpit report modal gains an interactive CSN detail view and
clickable chart points.

Tests were expanded to cover CSN details, origin out‑of‑scope behavior,
and partial replication, and include helper functions to reduce duplication.

Fixes: https://github.com/389ds/389-ds-base/issues/7194

Reviewed by: @progier389, @mreynolds389 (Thanks!!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/603f4deb1e87c819c1830f58c7be4281d981fbbd">603f4deb</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-02-04T13:24:19+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48896 test

Description:
Port ticket 48896 test into dirsrvtests/tests/suites/password/pwdPolicy_token_test.py

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: Mark Reynolds
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ff44acffcc67c985148c4df280685a674fec010a">ff44acff</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-02-05T15:19:58+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6810 - Fix PAM PTA test (#7219)

Description: Fix the PAM PTA test by add missing yield in fixture.

Relates: #6810

Reviewed by: @jchapma</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/2a0ed9c267fc56a14e84ad53ffaeb0b822594367">2a0ed9c2</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-02-05T15:41:09+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7076 - Fix revert_cache() never called in modrdn (#7220)

Description: The postentry check in PR #7077 was broken - postentry is always NULL
at that point, fixed by removing the check.

Relates: #7076

Reviewed by: @vashirov, @mreynolds389, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/3d63c2bc1ec7e89fe2ce6360ddd72748a6d1e1c5">3d63c2bc</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-02-05T15:19:07+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6951 - Dynamic Certificate refresh phase 4 - Update lib389 and dsconf (#7171)

Desciption:
Add the CertManager abstraction layer and DynamicCerts backend module. Enhance
the NssSsl backend to support importing PKCS#12 containers, containing cert and
private key. Update dsconf to support new PKCS#12-related args, allowing users
to supply passwords via text, stdin, or file.

Fix:
- Introduce CertManager abstraction layer for uniform cert management.
- Implement DynamicCerts backend with add/list/delete operations.
- Extend NssSsl.add_cert to handle PKCS#12 files with passwords via text, stdin, or file.
- Update dsconf CLI to accept PKCS#12 arguments (--pkcs12-pin-text, --pkcs12-pin-stdin, --pkcs12-pin-path).

Relates: https://github.com/389ds/389-ds-base/issues/6951

Reviewed by: @progier389, @mreynolds389, @droideck (Thank you)



</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/d5a83e8f2ccd0c9d11792f026947c4785996b4a6">d5a83e8f</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-02-05T15:33:08+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7224 - CI Test - Simplify test_reserve_descriptor_validation (#7225)

Description:
Previously, the test_reserve_descriptor_validation CItest calculated
the expected number of file descriptors based on backends, indexes,
SSL/FIPS mode, and compared it to the value returned by the server.
This approach is fragile, especially in FIPS mode.

Fix:
The test has been updated to simply verify that the server corrects
the configured nsslapd-reservedescriptors value if it is set too low,
instead of calculating the expected total.

Fixes: https://github.com/389ds/389-ds-base/issues/7224

Reviewed by: @bsimonova  (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/9bfbec8c4aad1c698fd80b3086e11f06fd9df26d">9bfbec8c</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-09T13:15:44+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7178 - Bundled jemalloc fails to build with GCC 15 (#7216)

Description:
Update spec file to fix build failures on Fedora Rawhide

Fixes: https://github.com/389ds/389-ds-base/issues/7178

Reviewed by: @progier389, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/fb4254a97fe0da25064d2f6296705c9e1810ffda">fb4254a9</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-09T13:18:09+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7121 - (2nd) LeakSanitizer: various leaks during replication (#7212)

Bug Description:
With the previous fix 75e0e487545893a7b0d83f94f9264c10f8bb0353 applied,
server can crash in ber_bvcpy.

```
Program terminated with signal SIGSEGV, Segmentation fault.
#0  ber_bvcpy (bvs=0x7f1d00000000, bvd=0x7f1da2cd73c0) at ldap/servers/slapd/value.c:47
47          len = bvs->bv_len;
[Current thread is 1 (Thread 0x7f1db47fe640 (LWP 36576))]
(gdb) bt
#0  ber_bvcpy (bvs=0x7f1d00000000, bvd=0x7f1da2cd73c0) at ldap/servers/slapd/value.c:47
#1  ber_bvcpy (bvs=0x7f1d00000000, bvd=0x7f1da2cd73c0) at ldap/servers/slapd/value.c:40
#2  slapi_value_set_berval (bval=0x7f1d00000000, value=0x7f1da2cd73c0) at ldap/servers/slapd/value.c:322
#3  slapi_value_set_berval (value=value@entry=0x7f1da2cd73c0, bval=bval@entry=0x7f1d00000000) at ldap/servers/slapd/value.c:317
#4  0x00007f1e48b7d787 in value_init (v=v@entry=0x7f1da2cd73c0, bval=bval@entry=0x7f1d00000000, t=t@entry=0 '\000', csn=csn@entry=0x0)
    at ldap/servers/slapd/value.c:179
#5  0x00007f1e48b7d884 in value_new (bval=bval@entry=0x7f1d00000000, t=t@entry=0 '\000', csn=csn@entry=0x0) at ldap/servers/slapd/value.c:158
#6  0x00007f1e48b7ddb7 in slapi_value_dup (v=0x7f1d00000000) at ldap/servers/slapd/value.c:147
#7  0x00007f1e48b7e262 in valueset_set_valueset (vs2=0x7f1d502b5218, vs1=0x7f1da2c5b358) at ldap/servers/slapd/valueset.c:1244
#8  valueset_set_valueset (vs1=0x7f1da2c5b358, vs2=0x7f1d502b5218) at ldap/servers/slapd/valueset.c:1220
#9  0x00007f1e48add4af in slapi_attr_dup (attr=0x7f1d502b51e0) at ldap/servers/slapd/attr.c:396
#10 0x00007f1e48af0f60 in slapi_entry_dup (e=0x7f1da2c19000) at ldap/servers/slapd/entry.c:2036
#11 0x00007f1e442c734e in ldbm_back_modify (pb=0x7f1da2c00000) at ldap/servers/slapd/back-ldbm/ldbm_modify.c:741
#12 0x00007f1e48b30076 in op_shared_modify (pb=pb@entry=0x7f1da2c00000, pw_change=pw_change@entry=0, old_pw=0x0)
    at ldap/servers/slapd/modify.c:1079
#13 0x00007f1e48b30ced in do_modify (pb=pb@entry=0x7f1da2c00000) at ldap/servers/slapd/modify.c:377
#14 0x000055e990e2fd1c in connection_dispatch_operation (pb=0x7f1da2c00000, op=<optimized out>, conn=<optimized out>)
    at ldap/servers/slapd/connection.c:672
#15 connection_threadmain (arg=<optimized out>) at ldap/servers/slapd/connection.c:1955
#16 0x00007f1e48839bd4 in _pt_root (arg=0x7f1e439d9500) at pthreads/../../../../nspr/pr/src/pthreads/ptthread.c:191
#17 0x00007f1e4868a19a in start_thread (arg=<optimized out>) at pthread_create.c:443
#18 0x00007f1e4870f100 in clone3 () at ../sysdeps/unix/sysv/linux/x86_64/clone3.S:81
```

The fix changed from always setting `v_csnset = NULL` to only freeing it
inside the if-block.

Fix Description:
Keep `csnset_free()` outside the if-block to handle all values, not just
those matching the condtion.

Related: https://github.com/389ds/389-ds-base/issues/7121

Reviewed by: @progier389, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/3938942a5418add83616b1413f3070d394c30a7f">3938942a</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-10T08:51:50+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7223 - Revert index scan limits for system indexes

This reverts changes introduced by the following commits:
c6f458b42 Issue 7189 - DSBLE0007 generates incorrect remediation commands for scan limits
8b6b3a9f9 Issue 6966 - On large DB, unlimited IDL scan limit reduce the SRCH performance

Relates: https://github.com/389ds/389-ds-base/issues/7223

Reviewed by: @progier389, @tbordaz, @droideck (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4c44e4c522afc0f5401754f29a47645889e21aca">4c44e4c5</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-10T08:51:50+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7223 - Add upgrade function to remove nsIndexIDListScanLimit from parentid

Description:
Add `upgrade_remove_index_scanlimit()` function that removes the
nsIndexIDListScanLimit attribute from parentid index configuration
if present.

This attribute was incorrectly added by a previous version and can
cause issues with index configuration. The upgrade function runs
automatically on server startup and removes the attribute if found.

Relates: https://github.com/389ds/389-ds-base/issues/7223

Reviewed by: @progier389, @tbordaz, @droideck (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/41670301ccad5558296a3380a4974f7c0d4baede">41670301</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-10T08:51:50+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7223 - Add upgrade function to remove ancestorid index config entry

Description:
Add `upgrade_remove_ancestorid_index_config()` function that removes:
* ancestorid from `cn=default indexes`
* ancestorid index config entries from each backend's `cn=index`

Also remove ancestorid index configuration from template-dse.ldif.

Relates: https://github.com/389ds/389-ds-base/issues/7223

Reviewed by: @progier389, @tbordaz, @droideck (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a260b50aa0c8e6c5b8b3fd0b164e9bbc4a15983f">a260b50a</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-10T08:51:50+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7223 - Detect and log index ordering mismatch during backend startup

Description:
Add `ldbm_instance_check_index_config()` function that checks on-disk
index data and logs a message in case of a mismatch with DSE config entry.

Relates: https://github.com/389ds/389-ds-base/issues/7223

Reviewed by: @progier389, @tbordaz, @droideck (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/9e5f22c94b822fcd3decb8f98ce2eb383cc16a7c">9e5f22c9</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-10T08:51:50+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7223 - Add dsctl index-check command for offline index repair

Description:
Add `dsctl <instance> index-check [backend] [--fix]` command for offline
detection and repair of index ordering mismatches. This is needed after
upgrade from versions that didn't use integerOrderingMatch for
parentid/ancestorid system indexes.

It's automatically executed as part of RPM %post scriptlet during
upgrade.

Relates: https://github.com/389ds/389-ds-base/issues/7223

Reviewed by: @progier389, @tbordaz, @droideck (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/3ebb30a65e2b40610301e5feedda0408ac9f3631">3ebb30a6</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-02-10T10:35:48+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7230 - Regression in healtcheck NssCheck (#7235)

Description:
Dynamic Certificate lib389 updadates modified get_cert_details() to
return a dict instead of tuple format. _lint_certificate_expiration() and 
tls.list_cas() still assumes tuple style access. 

Fix:
Update method to use dict key.

Fixes: https://github.com/389ds/389-ds-base/issues/7230

Co-authored-by: @flo-renaud

Reviewed by: @droideck (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b24ae4a7710c66b8c224ebd498dc82463e46f45b">b24ae4a7</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-02-10T13:09:22-08:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 3555 - UI - Fix audit issue with npm - @isaacs/brace-expansion (#7228)

Description: Run npm audit fix to address the vulnerability
in @isaacs/brace-expansion.

Relates: https://github.com/389ds/389-ds-base/issues/3555

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ae4a39474df08d56064453f0fb6c2272e6c3dc8b">ae4a3947</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-02-11T09:28:58-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7221 - CI tests - fix some flaky tests

Description:

Try to harden some of the flaky tests with sleeps and more relaxed contraints

Relates: https://github.com/389ds/389-ds-base/issues/7221

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/58f5d129496cc8b4271daf5d0cd3ab31e8b926a8">58f5d129</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-02-12T12:47:23+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7233 - test_produce_division_by_zero fails with IsADirectoryError in conftest.py (#7234)

Description: glob('/*/*') matches directories causing open() to fail.

Fixes: #7233

Reviewed by: @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/bbda49b86f3841ac5100894da426edc541b6226c">bbda49b8</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-12T09:15:18+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7241 - Drop dateutil (#7242)

Bug Description:
python-dateutil is unmaintained upstream and is marked for deprecation.

Fix Description:
* Replace `dateutil.tz.tzoffset` with `datetime.timezone(datetime.timedelta())`.
* Replace `dateutil.parser.parse` with standard `datetime` calls.
* Import `datetime` as `dt` to avoid confusion between module and class.
* Fix month lookup bug ('Oct': 9 / 'Sep': 10).

Fixes: https://github.com/389ds/389-ds-base/issues/7241

Reviewed by: jchapma, droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/d19c50372d5c5d901f05ce6e7dd03313f41fc197">d19c5037</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-02-12T10:42:09+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7231 - Sync repl tests fail in FIPS mode due to non FIPS compliant crypto (#7232)

Description:
Several sync_repl tests fail when running on a FIPS enabled system. The failures
are caused by the sync repl client (Sync_persist), using TLS options and ciphers
that are not FIPS compatible.

Fix:
Update the sync repl client to use FIPS approved TLS version.

Fixes: https://github.com/389ds/389-ds-base/issues/7231

Reviewed by: @progier389, @droideck (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/1df3852cf0e073cfe006d661aecdd909862fc79a">1df3852c</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-02-12T12:52:39-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7248 - CLI - attribute uniqueness - fix usage for exclude subtree option

Description:

Fix typo in usage message for the exclude subtree option

relates: https://github.com/389ds/389-ds-base/issues/7248

Reviewed by: progier (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/63bf648f699b8fcd8f319254b0348d969ceea7a0">63bf648f</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-02-12T15:10:19-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue - CLI - dsctl db2index needs some hardening with MBD

Description:

The usage for dsctl db2index was confusing. The way the attr options and
backend name were displayed it looks like the backend name could come after
the attributes, but instead the backend name was treated as an attribute.

Instead make the backend name required, and change the attribute naming to
require individual options instead of a list of values.

Relates: https://github.com/389ds/389-ds-base/issues/7250

Reviewed by: progier(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/d52901f69e9b7952b33b219ec197308a1a20bda9">d52901f6</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-02-13T15:13:05+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7252 - PQC - Need to iterate on SECOidTag instead of using OID (#7254)

* Issue 7252 - PQC - Need to iterate on SECOidTag instead of using OID

Need to dynamically iterate on SECOidTag instead of using SEC_OID_ML_DSA_* OIDs to avoid issue with upcoming nss versions and fix a RHEL build break with nss 3.112

Issue: #7252

Reviewed by: @mreynolds389, @droideck, @vashirov


* Update ldap/servers/slapd/ssl.c

Co-authored-by: Simon Pichugin <spichugi@redhat.com>

---------

Co-authored-by: Simon Pichugin <spichugi@redhat.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/2005e2670c474212a2daa7b3947b41c8db18c9c9">2005e267</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-02-13T15:34:13+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6951 - Dynamic Certificas Refresh - CI tests (#7238)

* Issue 6951 - Dynamic Certificas Refresh - CI tests

Add CI test for Dynamic Certificas Refresh:

clu/dsconf_dsctl_security_cli_test.py test dsconf/dsctl instance security ... interface
tls/dynamic_certificates_test.py test the LDAP API
Fix some issues found while running these tests:
Fix rpm_is_older function in mldsa_test.py
Add missing code to handle IP Address in alternate subject name
FIx test failure related to rehash warning

Issue: #6951

Reviewed by: @jchapma (Thanks!)

Assisted by: Claude AI
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/48ad61231203d9ccb96d0fe542aae93dbb74a9bf">48ad6123</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-13T15:38:52+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7184 - (2nd) argparse.HelpFormatter _format_actions_usage() is deprecated (#7257)

Description:
`_format_actions_usage()` was also removed in Python 3.14.3.
Replace version check with `isinstance()` to handle the return type of
`_get_actions_usage_parts()` more robustly across Python versions.

Relates: https://github.com/389ds/389-ds-base/issues/7184
Fixes: https://github.com/389ds/389-ds-base/issues/7253

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/c7ef5b3073bbd94a5d2b544556368c830c165e0d">c7ef5b30</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-13T16:27:25+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7213 - (2nd) MDB_BAD_VALSIZE error while handling VLV (#7258)

Decription:
Disable test_vlv_long_attribute_value on BDB as it hangs sometimes in
CI, blocking other pipelines.

Relates: https://github.com/389ds/389-ds-base/issues/7213

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/7e575cc8cc6f1bf558f50ca0fc55145e469d60d2">7e575cc8</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-13T16:58:24+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7223 - Use lexicographical order for ancestorid (#7256)

Description:
`ldbm_instance_create_default_indexes()` configured ancestorid with
integerOrderingMatch in the in-memory attrinfo, but ancestorid on disk
might be using lexicographic ordering (data before the upgrade or after
ldif2db import).

Relates: https://github.com/389ds/389-ds-base/issues/7223

Reviewed by: @tbordaz (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/245bc3b53f385e12e4dc9d2cb765a55e10e0fdc5">245bc3b5</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-02-13T17:51:12+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 3134 - Fix build break (#7260)

Fix build break of PR #7238 related to import rpm

Issue: #3134

Reviewed by: @vashirov (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ac3d9253e0a7a4b5f0108506bcf25255b302fd16">ac3d9253</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-02-16T12:40:55-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7066/7052 - allow password history to be set to zero and remove history

Description:

For local password policies the server was incorrectly rejecting updates that
set the value to zero.  When password history is set to zero the old passwords
in the entry history are not cleaned as expected.

relates: https://github.com/389ds/389-ds-base/issues/7052
relates: https://github.com/389ds/389-ds-base/issues/7066

Reviewed by: progier(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/56563c9083a01fc26d853edf4538ce70900d259c">56563c90</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-02-16T16:33:40-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7243 - UI - add support for hot certificates

Description:

In the "Add Server Certificate" modal add password options for pkcs#12
certificates. Also improved validation for certificate names

relates: https://github.com/389ds/389-ds-base/issues/7243

Reviewed by: jchapman & spichugi (Thanks!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b216b86c5607dc0421eb609c46f3004844fb37c0">b216b86c</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-02-17T17:40:44+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6758 - Fix Enable Replication dropdown not opening (#7262)

Description: Removed hardcoded isOpen={false} and empty onToggle handler that
prevented dropdown from opening. Let component manage its own state.

Relates: #6758

Reviewed by: @vashirov</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/6ce19a9a3e36213a5604144aa5eb3cba666e5ed4">6ce19a9a</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-18T09:26:57+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7223 - Remove integerOrderingMatch requirement for parentid (#7264)

Description:
integerOrderingMatch was introduced as a requirement for parentid and
ancestorid indexes for performance reasons. But after #7096 the order
for parentid doesn't make a lot of difference.

Fix Description:
* Remove integerOrderingMatch requirement for parentid.
* Read only first 100 keys from dbscan in index ordering check
* Do not run dsctl index-check during RPM upgrade

Relates: https://github.com/389ds/389-ds-base/pull/7223

Reviewed by: @progier389, @tbordaz (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/26feecae026581e39a43f001faff59e81a92c03d">26feecae</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-02-18T14:33:49+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7236 - Fix GSSAPI tests (#7237)

* Issue 7236 - Fix GSSAPI tests

Description:
Fix for failing GSSAPI tests
Add GSSAPI_ACK variable to pytest workflow for proper execution in
Github CI

Relates: #7236
Author: Lenka Doudova
Reviewer: Barbora Simonova, Viktor Ashirov</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a4ae29afc6547e8231b933cfa1b95d7f7b37a25c">a4ae29af</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-02-19T15:16:02+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 49039 test

Description:
Port ticket 49039 test into
dirsrvtests/tests/suites/password/pwp_test.py

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: Barbora Simonova, Viktor Ashirov
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/0e2d9c4288873446dcb3d8bff61c558ff2b6681a">0e2d9c42</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-23T09:49:52+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 5853 - Update concread to 0.5.10

Description:
Update concread to 0.5.10 and update Cargo.lock

Relates: https://github.com/389ds/389-ds-base/issues/5853

Reviewed by: @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/8b4dbf35ace326e5b836982d428e7029313a2247">8b4dbf35</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-02-23T15:06:30-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7271 - plugins that create threads need to update
 active thread count

Description:

Plugins that create threads need to up to the global active thread count.
Otherwise when the server is being stopped the plugin's close function gets
called while these threads are still running and still using the plugin
configuration. This can lead to crashes.

relates: https://github.com/389ds/389-ds-base/issues/7271

Reviewed by: progier & tbordaz (Thanks!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ffe1909e69ab2aecef396f31cf95cdcecd992782">ffe1909e</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-02-24T08:14:38-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7273 - In a chaining environment binding as remote user causes an invalid error in the logs

Description:

In a database link/chaining environment you can bind as a remote user, and
this triggers an error when trying to "upgrade_on_bind" as the user does not
locally have a userpassword since it's remote. There is no strong case to
log an error in this situation.

relates: http://github.com/389ds/389-ds-base/issues/7273

Reviewed by: vashirov(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/3a233116a564fc339aee1021913c995504951d86">3a233116</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-02-24T09:28:24-08:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7279 - UI - Fix typo in export certificate dialog (#7280)

Description: Fix typo "cetificate" -> "certificate" in the
export certificate dialog message.

Fixes: https://github.com/389ds/389-ds-base/issues/7279

Reviewed by: @vashirov (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/fff8e54cb265ac6e68b0069679bd4e7685647dcb">fff8e54c</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-02-24T09:32:41-08:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7275 - UI - Improve password policy field validation in Cockpit UI (#7276)

Description: Password policy fields in the Cockpit UI lack client-side validation.
Invalid values only produce generic server-side errors after clicking Save.
Add a shared pwpValidation module and inline validation to all numeric
password policy fields in globalPwp.jsx and localPwp.jsx.

Fixes: https://github.com/389ds/389-ds-base/issues/7275

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/f4d8df66187c0d1db6c9f5c9aa55946a8564de4b">f4d8df66</a></strong>
<div>
<span> by Sam Morris </span> <i> at 2026-02-25T13:30:01+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7246 - correct formatting of 'Gen as CSN' in dsctl get-nsstate output (#7247)

Description: CSNs are formatted as hexadecimal, but the replica id and
sequence number are displayed in decomal.

Fix: use correct format specifiers for hexadecimal output.

Fixes: https://github.com/389ds/389-ds-base/issues/7246

Signed-off-by: Sam Morris <sam@robots.org.uk></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/2e424110def2e3998f6045e136fb0d43f47b7f5a">2e424110</a></strong>
<div>
<span> by tbordaz </span> <i> at 2026-02-25T14:07:25+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Security fix for CVE-2025-14905

Description:
        A vulnerability was found in the 389 Directory Server.
        The 389 Directory Server present a risk of heap buffer overflow that
        can be exploited to excute a Denial of Service and potential Remote
        Code Execution

References:
    - https://access.redhat.com/security/cve/CVE-2025-14905
    - https://bugzilla.redhat.com/show_bug.cgi?id=2423624
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/c7e1eb08eb36fd9a16c745935f56fa4a4b2a99df">c7e1eb08</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-02-25T18:00:24+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7267 - MDB_BAD_VALSIZE error when updating index (#7268)

* Issue 7267 - MDB_BAD_VALSIZE error when updating index
* Improve import log when writer fails
* Fix Sourcery AI comments
* Fix INDEX_KEY_LENGTH typo

Problem with the key prefix handling when key is too long and must be hashed.
The issue is that the # that is prepended is not reset when iterating over the valueset values (Ending up with very long prefix)

Also refactored the code to avoid duplicate the code that prepare the key from the attribute value (used when updating the index or retrieving a value from an index)

Issue: #7267

Reviewed by: @tbordaz , @vashirov (Thanks!)

Co-authored-by: Viktor Ashirov <vashirov@redhat.com>

---------

Co-authored-by: Viktor Ashirov <vashirov@redhat.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/336f1ba7dcc895929ac2fb2d6cd630ddb645e94c">336f1ba7</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-02-25T09:05:40-08:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7277 - UI - Fix Japanese translation for "Successfully updated group" in Cockpit UI (#7278)

Description: The Japanese translation for "Successfully updated group"
incorrectly displays a "failed" message instead of a "succeeded" message.
This is a copy-paste error from the adjacent failure message translation.

Fixes: https://github.com/389ds/389-ds-base/issues/7277

Reviewed by: @vashirov (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/185178ef52d6f665a53c69f794daf8c2ec15b455">185178ef</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-02-26T12:55:47+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value (#7285)

Description:
attr_check_minmax used strtol(value, NULL, 0), which silently converted
invalid strings to 0, passing subsequent range checks.

Fix:
Add checks for NULL or empty values and uses strtol with endptr to
validate int input before range checks.

Fixes: https://github.com/389ds/389-ds-base/issues/7284

Reviewed by: @vashirov, @tbordaz (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a603fcdebb5e7056938840c8a1b476aed8145bf5">a603fcde</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-02-27T09:37:46+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6220 - Add Packit configuration (#6221)

Description:
Add initial configuration for Packit integration

Fixes: https://github.com/389ds/389-ds-base/issues/6220

Reviewed by: @progier389, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/8618fd59efecbf54458eb48bb901987ce81dbd21">8618fd59</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-02-27T08:30:01-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7265 - changelog maxage validation is not strict enough

Description:

We need to enforce a duration unit is set and the first digit is not zero
when setting maxage for the replication and retro changelogs.

relates: https://github.com/389ds/389-ds-base/issues/7265

Reviewed by: vashirov & spichugi(Thanks!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/968cbfa161e55b354f7da513d1edcd4dae0cf19a">968cbfa1</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-02-27T08:37:56-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7281 - RFE - CLI - add support to managing additional encryption modules

Description:

Right now there is no way to add/manage additional encryption modules through
the CLI/UI. We need this for allowing multiple server certificates.

relates: https://github.com/389ds/389-ds-base/issues/7281

Reviewed by: vashirov, progier, anbd spichugi(Thanks!!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ab7e1fe4f6d633f866514a49a6e43e7b9b2b3e98">ab7e1fe4</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-03-03T13:51:44+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7061 - Test for improved error message

Description:
Adding automated test coverage for issue 7061 ("Improve error messages
for dsconf localpwp list")

Relates: #7061
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: Viktor Ashirov
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/2acf2cb9574947a288c8c28a50b1dab8b7986abe">2acf2cb9</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-03T10:54:39-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7271 - implement a pre-close plugin function

Description:

replication protocol could benefit from being notifioed the shutdown process
has started before calling the "close" plugin function. This would allow the
replication protocol to wake up and adjust its active thread count to prevent
a hang during shutdown.

relates: https://github.com/389ds/389-ds-base/issues/7271

Reviewed by: progier, spichugi, and vashirov(Thanks!!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ee06feb84a8491bcc0e147be79e518f9345b7c65">ee06feb8</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-03-03T16:04:16+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7291 - Crash when configuring a replica with an incorrect nsds5ReplicaRoot (#7292)

Description:
Configuring a replica when the replica_root does not exist, results in
a NULL mapping tree node extension, which is deferenced without checking
for NULL.

Fix:
Add a  NULL check, log an error message, return LDAP_UNWILLING_TO_PERFORM. Added a CI test.

Fixes: https://github.com/389ds/389-ds-base/issues/7291

Reviewed by: @progier389, @mreynolds389, @droideck  (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/2018c846a0c5fa09874736bae9251ff2994abbdb">2018c846</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-03-04T09:27:41+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 3555 - UI - Fix audit issue with npm - ajv, minimatch (#7298)

Description:
Run npm audit fix to address the vulnerabilities in ajv and minimatch.

Relates: https://github.com/389ds/389-ds-base/issues/3555

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/761452f79c30bbfd0d6756c4a8ed39549fde5717">761452f7</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-04T14:38:29-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7265 - Add dse modify callback to validate retrocl trimming settings

Description:

Add dse modify callback to verify retrocl trimming settings are valid

relates: https://github.com/389ds/389-ds-base/issues/7265

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/da306ee7bcaf989651fdb72e4d8f1afdbdac2dd9">da306ee7</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-05T08:29:07-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7304 - retrocl should not cache DN

Description:

When adding a record to the retro changelog we pass in the flag
SLAPI_OP_FLAG_NEVER_CACHE to prevent the entry from being cached,
but we still update the DN cache leading to unexpected memory growth.

relates: https://github.com/389ds/389-ds-base/issues/7304

Reviewed by: tbordaz(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/5cc3edb9732784e8a3edb033962b6312f2bb7b55">5cc3edb9</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-05T09:58:19-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7271 - Add new plugin pre-close function check to plugin_invoke_plugin_pb

Description:

In plugin_invoke_plugin_pb we were not checking for the new pre-close function
which led to an error in the logs: pb_op is NULL. In a debug build this leads
to an assertion error at shutdown.

relates: https://github.com/389ds/389-ds-base/issues/7271

Reviewed by: vashirov(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/1a55373c50fb98fea00e922dc737bb039c34f65e">1a55373c</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-03-05T17:09:13-08:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7300 - RFE - Add OS-level thread names to all server threads (#7301)

Description: Add slapi_set_thread_name() API wrapping pthread_setname_np
and apply it to all server threads.
Workers appear as worker-0..N, the listener as "listener",
replication threads as "repl-prot", "repl-inc-res", etc.

For functions that serve as both thread entry points and direct calls
(db2ldif_skip_all, dbmdb_recno_cache_build), thin wrapper functions
are used to keep thread naming separate from the core logic.

Fixes: https://github.com/389ds/389-ds-base/issues/7300

Reviewed by: @vashirov, @jchapma, @mreynolds389 (Thanks!!!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a3e4c2ff5a85550879e0932cf0ca579247654532">a3e4c2ff</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-03-05T17:11:01-08:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7307 - RFE - Expose work queue and worker utilization metrics (#7308)

Description: Add four new read-only attributes to cn=monitor:
currentworkqueue, maxworkqueue, currentbusyworkers, and maxbusyworkers.
These let administrators detect thread pool saturation using external
monitoring tools (PCP, Grafana, custom scripts).
Worker counts use lock-free atomics with defensive clamping to
guarantee non-negative values.
Add tests for basic metrics validation and concurrent
busy worker tracking.
Add Cockpit UI fields to Monitor - Server Statistics.

Fixes: https://github.com/389ds/389-ds-base/issues/7307

Reviewed by: @progier389, @mreynolds389 (Thanks!!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/45a00d97a9ee3517be2d4100f0708fe04fa3f7b4">45a00d97</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-03-06T14:26:24+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7296 - Introduce time limits for GH Actions (#7297)

Description:
* Limit test jobs to 90 mins, compile to 30 mins.
* Adjust default test timeout to 85 minutes.
* Bump actions versions.

Fixes: https://github.com/389ds/389-ds-base/issues/7296

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/3f5f32ef36cf2c797c9379eba1ba2d8b2fd9841b">3f5f32ef</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-03-06T17:19:58+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7302 - dblib bdb2mdb fails on F43 -> F43 upgrade (#7303)

Bug Description:
`db->stat` is stubbed with `nothing()` which returns DB_SUCCESS without
populating the stats output parameter. Both `bdb_get_page_count()` and
`bdb_get_entries_count()` then dereference the NULL stats pointer,
causing a segfault.

Fix Descrption:
Add NULL checks for the stats pointer after `db->stat()` calls in both
`bdb_get_page_count()` and `bdb_get_entries_count()`.

Fixes: https://github.com/389ds/389-ds-base/issues/7302

Reviewed by: @tbordaz, @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/486fb249ca8a90a419baa3ffb75b25b4142687b0">486fb249</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-06T13:44:21-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issuei 7281 - UI - Add encryption module management

Description:

Implement the Security page Encryption Modules tab with list/create/edit/enable-disable/delete
workflows.

relates: https://github.com/389ds/389-ds-base/issues/7281

Assisted by: Cursor

Reviewed by: jchapman(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/87ef50609ba21243e758477be873a962ec0ddda9">87ef5060</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-08T16:46:48-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7314 - UI - Add progress steppers to Security, Database, and Replication tabs

Description:

The Security, Databasei (and suffix), and Replication tabs can take a long
time to load. A progress stepper would be a nice addition to give the user
feedback as to why the loading is taking so long.

The database tab took extra work to get all the cockpit API calls in an
ordered nested approach.

relates: https://github.com/389ds/389-ds-base/issues/7314

Assisted-by: Cursor

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b5e25b6bd7929e4dc07be046eb198f5192001f6d">b5e25b6b</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-09T08:43:52-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7316 - UI - update npm module immutable

Description:

Update immutable module to resolve vulnerability issue

relates: https://github.com/389ds/389-ds-base/issues/7316

Reviewed by: vashirov(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/7d5de9965e6945e995ce5d9c06c7913b5b7e4154">7d5de996</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-03-09T15:43:08+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7093 - A password policy can be created even when an identical policy already exists (#7283)

Description:
Currently, during password policy creation, if an existing policy entry is found,
a MOD_REPLACE operation is silently performed instead of alerting the user. This
behaviour makes the operation appear successful but hides the fact that the policy
already exists.

Fix:
Introduce a strict mode in ensure_state that returns the actual outcome of the
operation. Update the UI to handle ensure_state responses and add CI test to
verify the behaviour.

Fixes: https://github.com/389ds/389-ds-base/issues/7093

Reviewed by: @droideck  (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/520d19f02d1a3abc9028ade238d4528b921e6688">520d19f0</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-10T15:10:19-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7265 - CI - fix retro changelog maxage validation test

Description:

Previously the retro changelog allowed invalid values even though they are
ignored, but not they are rejected and the CI test needs to be updated

relates: https://github.com/389ds/389-ds-base/issues/7265

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/22b9d0cff2e8ccac43bd8ede5e60fd5cbf37ccd2">22b9d0cf</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-03-11T16:21:00+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 47980 and 47981 tests (#7323)

Description:
Port ticket 47980 and 47981 tests into dirsrvtests/tests/suites/password/regression_test.py using lib389 API

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: progier389</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/887d50180f65d4d2a2fda6f09f836a9f5567e44f">887d5018</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-03-12T12:25:58+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7319 - Action menu for certificates remains in empty certificate list (#7320)

Description:
Action buttons were displayed even when tables were empty

Fix:
Added hasRows condition to pnly show actions when the table contains
data

Fixes: https://github.com/389ds/389-ds-base/issues/7319

Reviewed by: @mreynolds389   (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/66b6fe3aafc21e36461dcc1458ab779bfd535a73">66b6fe3a</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-12T13:50:49-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7325 - UI - create an error parser for cockpit spawn errors

Description:

When we call cockpit spawn and one of our CLI tools the error message can
either be in JSON or plain text. We should have a universal parser to properly
handle these types, because right now there are places were the browser
crashes because it thinks the error should be in JSON when it's just a string.

relates: https://github.com/389ds/389-ds-base/issues/7325

Reviewed by: jchapman(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/8693ea7b3f3064569e4fbd92210bb8a7abc499b7">8693ea7b</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-12T14:12:06-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7325 - UI - new error parser missing import

Description:

Missing import for cockpit.gettext

relates: https://github.com/389ds/389-ds-base/issues/7325

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/05738feeb45dd3532a2834b0b0f60043494bcec1">05738fee</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-13T08:13:28-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue - UI - Improve suffix import LDIF table

Description:

Under a suffix you can initialize the database using a table of available
LDIF files. There is an action column with just one option (to import it).
This should just be a single button since there are no other options
available.

Also the table was missing a column for the suffix in the LDIF file.

relates: https://github.com/389ds/389-ds-base/issues/7331

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/e240eaf9b05d28c1ee946063d59f647d5d6464b4">e240eaf9</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-03-15T17:29:11+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 47976 test

Description:
Port ticket 47976 test into dirsrvtests/tests/suites/plugins/managed_entry_test.py
using lib389 API.

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: Akshay Adhikari
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a2a3b76eecd2d399cace342dfef3a5ab2098e6b1">a2a3b76e</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-16T15:43:53-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7339 - Return the exact DN during export

Description:

During an export if the entry is not in the DN cache we rebuild the DN from
scratch using the entryrdn index, but this resets the case of the DN.

If we want to use the orginal case of the DN, and the dsEntryDN attribute is
present then use that DN for exported ldif.

relates: https://github.com/389ds/389-ds-base/issues/7339

Reviewed by: progier(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/500f86c530b63bd698e5cf82d804654309c5baa3">500f86c5</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-03-17T07:44:42+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48005 test (#7340)

Description:
Port ticket 48005 test to dirsrvtests/tests/suites/clu/task_shutdown_test.py

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: Pierre Rogier</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b9f03541e602afcae471dd00448518aa5490dda6">b9f03541</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-03-17T18:12:59+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Remove ticket 48013 test (#7344)

Description:
Removing ticket 48013 test as the same test case is covered within dirsrvtests/tests/suites/syncrepl_plugin/basic_test.py::test_sync_repl_invalid_cookie.

Relates: #6753
Author: Lenka Doudova
Reviewer: Barbora Simonova</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/d7995be4dbbf7bf174c8f848ceffdedc4035f339">d7995be4</a></strong>
<div>
<span> by tbordaz </span> <i> at 2026-03-18T17:22:06+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7346 - DS does not handle escape char in bind user (#7347)

Bug description:
        When normalization assertion value in a DN, the fix #4383
        keeps the escaped spaces (i.e '\20') whatever their position
        in the value.
        The RFC requires this for heading spaces but not for the others.
        This prevent to authenticate with a DN containing escaped spaces
        in the middle of assertion value
Fix description:
        Apply the fix #4383 only for the 1rst value of the assertion
        and extend it also to heading sharp

fixes: #7346

Reviewed by: Mark Reynolds (Thanks !)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/0f65ae6ba2b0c7e38294b11fcbe9a3a8661d8b4c">0f65ae6b</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-03-18T19:02:20+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7342 - CI - repl config regression (#7343)

Description:
Test failed to purge existing repl info

Fixes: https://github.com/389ds/389-ds-base/issues/7342

Co-authored-by: Mark Reynolds <mreynolds@redhat.com>

Reviewed by: @mreynolds389  (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/942c8eeb115ed1893eced34b4ce0b4081507b2c3">942c8eeb</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-03-19T10:12:24+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7312 - UI - Database Maximum Size cannot be easily set by typing (#7313)

Description:
The mdb max size field was clamping user input while typing. With a min
value of 100, when users tried to type values, the first digit would
clamp to 100, making it impossible to enter valid values.

Fix:
NumberInput validation updates, aligned client side validation with server side
updated dynamic lists enablement.

Tidied up the conversion from bytes to MB, converting only at the dsconf
boundaries.

Fixes:
https://github.com/389ds/389-ds-base/issues/7312

Reviewed by: @mreynolds389, @droideck (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/3d6977e254ad566711e2ea2399135eb8e7f8a073">3d6977e2</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-03-19T11:42:25+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7333 - Fail open condition in ACL (#7334)

Fix Fail open condition in ACL

Issue: #7333

Reviewed by: @mreynolds389 , @droideck (Thanks!)

Summary by Sourcery
Tighten access control handling for referrals by removing a fail-open ACL condition and extending tests to cover referral behavior for both privileged and anonymous binds.

Bug Fixes:

Eliminate the fail-open ACL behavior that granted access when no backend was present in the pblock during access checks.
Tests:

Extend referral tests to verify that both directory manager and anonymous clients receive referral errors without following referrals.

---------

Co-authored-by: Simon Pichugin <spichugi@redhat.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/0443a5a748a2ac4a500439eaab2074c1cc84fa72">0443a5a7</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-19T08:15:55-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7322 - Reject adding a replication agreement that points to itself

Description:

There is nothing that stops you from adding a replication agreement that points
to itself. This will break replication. We need to check and reject this.

relates: https://github.com/389ds/389-ds-base/issues/7322

Reviewed by: spichugi && progier && vahirov (Thanks!!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/462f5c2a850fa2098968848459f99c04366a99e2">462f5c2a</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-03-20T15:32:20+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7348 - CI - Fix failing dsconf security CLI add cert test (#7349)

Description:
Server side cert validation via the DynamicCerts backend uses CERT_VerifyCertificateNow()
to verify the cert being added. This function is stricter than client side NSS and rejects
the test cert due to cert chain validation issues, even though the certificate is valid.

Fix:
Update the CI test to use the --do-it flag, which bypasses strict validation

Fixes: https://github.com/389ds/389-ds-base/issues/7348

Reviewed by: @progier389  (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/c9dc8ba9973e34b61c7f79a01da9c14ad99e9b01">c9dc8ba9</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-03-20T16:47:30-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 1704 - DNA plugin creates invalid shared config entry with port 0 (#7352)

Description: When the server runs in isolated mode (nsslapd-port=0
and nsslapd-security=off), the DNA plugin creates shared config entries
with dnaPortNum=0. These entries are never updated and cause other
servers to target this instance for range requests it cannot serve.

Skip shared config creation and periodic updates when the server is
isolated. Read nsslapd-security at startup to distinguish isolated
mode from LDAPS-only mode (port=0, security=on).

Add a test that verifies no dnaPortNum=0 entry is created in isolated
mode and the original shared config entry persists.

Fixes: https://github.com/389ds/389-ds-base/issues/1704

Reviewed by: @progier389, @tbordaz (Thanks!!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/22278a4e7f08c0e3ad47161c56bd1a5b1b2b10b7">22278a4e</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-23T14:02:58-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7337 - UI - refactor all error handling to use getApiErrorMessge

Description:

Since dsconf/dsctl/dsidm can return errors in text and JSON so we need to use
the new getApiErrorMessage() function to safely parse the error in fail() and
generate the error message.

relates: https://github.com/389ds/389-ds-base/issues/7337

Generated-by: Cursor

Reviewed by: mreynolds and jchapman(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/bd7aafeae1e603441f1967126981762ecde94635">bd7aafea</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-03-24T11:23:02+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7126 - WARN - keys2idl - received NULL idl from index_read_ext_allids (#7127)

Bug Description:
Under high concurrency, occasional NULL IDL warnings were logged:

[29/Nov/2025:22:59:13.930441639 +0000] - WARN - keys2idl - received NULL idl from index_read_ext_allids, treating as empty set
[29/Nov/2025:22:59:13.936543122 +0000] - WARN - keys2idl - this is probably a bug that should be reported
[29/Nov/2025:22:59:13.947131944 +0000] - ERR - build_candidate_list - Database error -12795

Since #7124 all cursor operations use transaction isolation, which
increases read-write lock contention under high concurrency. Deadlocked
read transactions returned DBI_RC_RETRY, and after retry exhaustion
`index_read_ext_allids()` returned NULL to callers that did not expect it.

Fix Description:
* Ensure `index_read_ext_allids()` never returns NULL. All early exits
  and the retry-exhaustion path now return `idl_alloc(0)` (empty IDL).
* Increase IDL_FETCH_RETRY_COUNT from 5 to 10 and replace the uniform
  random sleep with exponential backoff.

Fixes: https://github.com/389ds/389-ds-base/issues/7126

Reviewed by: @tbordaz, @droideck, @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/386216ce5314900b3cc90ed2a6f1703f5901863e">386216ce</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-03-25T23:28:08+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7358 - NSACLPlugin - acl_access_allowed - Missing aclpb 1 (#7359)

Bug Description:
`sync_pblock_copy()` creates a new operation using
`slapi_operation_new(0)` without calling `factory_create_extension()`,
so the ACL pblock extension is never initialized. When the sync-send
thread evaluates a filter with access checks finds no aclpb and logs
'Missing aclpb 1', returning LDAP_OPERATIONS_ERROR to the client.

Fix Description:
Call `factory_create_extension()` after creating the new operation
so that all operation extensions (including the ACL pblock) are
properly initialized. Also copy SLAPI_REQUESTOR_DN so that ACL
checks evaluate against the correct bind identity.

Fixes: https://github.com/389ds/389-ds-base/issues/7358

Reviewed by: @progier389, @tbordaz, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/e93ec132efb5cf10b2bbc2dc27e1a6c98c7fdcc4">e93ec132</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-03-26T13:28:21+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 3555 - UI - Fix audit issue with npm - flatted, picomatch (#7364)

Description:
Run npm audit fix to address the vulnerabilities in flatted and picomatch.

Relates: https://github.com/389ds/389-ds-base/issues/3555

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/f8630870fe7774be39803b37a656683725ffc2e7">f8630870</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-03-26T15:42:24+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7271 - Add test for retrocl trimming shutdown crash (#7356)

Description: Validates server does not crash when shutdown occurs while
retro changelog trim thread is actively running.

Relates: #7271

Reviewed by: progier389</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/085613d1332cb7197c59359a2e85731dc7b71a37">085613d1</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-03-26T16:07:11+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7284 - CI - Fix test_grace_limit_section after pwpolicy validation fix (#7357)

Description:
The test replaced passwordGraceLimit with a space to remove it, which is
now correctly rejected after attr_check_minmax validation was tightened.
Use remove_all() to properly delete the attribute instead.

Fixes: #7284

Reviewed by: progier389, droideck</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b4201811af1e4030ee1c59edd2b5e75096558152">b4201811</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-03-26T15:31:16-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 3658 - UI/CLI - show progress of db tasks

Description:

Currently the CLI/UI does not show you the progress of
import/export/reindex/backup/restore tasks (offline & online)

Part 1:

Server code does not always update the task log, and in archive if
just a name and not a path is provided it default to writting it to
the logs directory instead of the backup directory.

Part 2:

Update CLI to include "watch" options to write the status of tasks
in real time to stdout.

Part 3:

Update UI to use the new watch options and to add a textarea
for the task progress

relates: https://github.com/389ds/389-ds-base/issues/3658

Reviewed by: spichugi(Thanks!)

Update lib389 for the new options to write the task propgress to stdout

Update the UI track task progress

Fix leftovers

Add CI tests

Improve modal behavior:

- Use LogViewer
- Don't close modal after task is complete
- Hide "action" button after success

Add progress viewer for instance creation
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/855651a5c3d650fb5e852931c487a35e57359e9b">855651a5</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-03-27T19:14:14+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6724 - Log fine grained details of operation timing (#7350)


Implement 2 new timing measure:
wqtime (time spent to wait for working threads)
write time (time spend to write results over the network (included poll time if needed)
Allow to select set of timing measure among
wqtime, wtime, writetime, optime, etime
Design document is https://www.port389.org/docs/389ds/design/fine-grain-operation-timing.html

Issues: #6724 and #6326

Reviewed by: @droideck . @mreynolds389, @tbordaz (Thanks !)

Summary by Sourcery
Add configurable fine-grained operation timing and expose it in access logs.

New Features:

Introduce fine-grained operation timing counters for different phases of request processing, including work queue, wait, processing, write, and total times.
Add a configurable ds-fine-grain-operation-timing setting to control which timing metrics are collected and logged, with sensible defaults.
Enhancements:

Include fine-grained timing data in both text and JSON access log formats, replacing legacy etime/wtime/optime fields with a unified, extensible representation.
Track network write time for both regular and SASL I/O paths to better understand response delivery latency.
Tests:

Add integration tests to verify fine-grained timing configuration combinations and to ensure work-queue wait time is reflected correctly in access logs.</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/bee36196d9bba14d73e7fa621d7c965671dd168f">bee36196</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-03-30T19:19:05+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7053 - Add tests for duplicate member operations (#7345)

Description: Validates MemberOf plugin no longer creates duplicate changelog entries
when users are deleted or renamed in replicated topology.

Relates: #7053

Reviewed by: @tbordaz (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/22ba6179bd1ceb66029e62606171b41d42bb94d2">22ba6179</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-03-30T22:18:49-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7366 - Memory leaks in syncrepl plugin during persistent search operations (#7367)

Description: When running a syncrepl persistent search as a non-root user,
LeakSanitizer detects memory leaks in the sync repl plugin.
Multiple cleanup paths for SyncRequest had inconsistent
and incomplete resource freeing, leaking pblock contents, filters,
queue nodes, and base DNs. Per-thread operation lists were also leaked
on thread exit due to a missing NSPR thread-private destructor.

Consolidate all SyncRequest cleanup into sync_request_free() and
register a destructor for per-thread OPERATION_PL_CTX_T lists.

Add a test for non-root persistent syncrepl search verifying no
OPERATIONS_ERROR or 'Missing aclpb' errors.

Fixes: https://github.com/389ds/389-ds-base/issues/7366

Reviewed by:  @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/dbecd9b25024af84a288c4ca57e0962b99e74454">dbecd9b2</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-04-01T13:44:47-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7368 - UI - global password policy page is missing passwordmintokenlength

Description:

The input field for passwordmintokenlength was missing on the global password
policy page, but it was present on the local password policy page

relates: https://github.com/389ds/389-ds-base/issues/7368

Reviewed by: bsimonova & spichugi(Thanks!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/7d69bde60d10110fd43c450f352727d9d631bd09">7d69bde6</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-04-01T13:48:40-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7362 - UI - Some FormSelect onChange parameters are reversed

Description:

Some FormSelect onChange handleers were not updated for PF5 and the parameters
are reversed.

https://github.com/389ds/389-ds-base/issues/7362

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/2dec24d5c8e6d19175a0eb7385b12b608643af49">2dec24d5</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-04-01T21:28:33+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7375 - CI - Fix clu/dsconf_tasks_test (#7376)

Description:
The dsconf_tasks_test fails because of checking for a string that is not always included in the command output.
Modifying the test so that is checks for a string that is included in the command output with --watch option, but not without it.

Fixes: #7375
Author: Lenka Doudova
Reviewer: Pierre Rogier</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ad5460a7f90adac740e749324fcbac61830e6486">ad5460a7</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-04-01T23:04:56+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7380 - Internal op with negative wtime and large optime (#7381)

Description:
The retro CL plugin triggers internal operations that log incorrect wtime and optime
to the server access logs.This happens because seq_internal_callback_pb() calls the
backend directly without setting the operation start time.

Fix:
Add slapi_operation_set_time_started(op) to seq_internal_callback_pb() to record
when the operation actually starts processing.

Fixes: https://github.com/389ds/389-ds-base/issues/7380

Reviewed by: @mreynolds389 (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/9d58949a6108e81a1e1eb898756ea3449e655026">9d58949a</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-04-02T17:04:37-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7378 - Make sure suffix entry always gets assigned ID 1

Description:

When enabling replication and we add the database RUV tombstone entry check if
this is the first entry being added.  If it is, then set the ID to 2, and set a
flag indicating that after we add the suffix entry to bump the next ID count
past the RUV entry id.

And at server startup when we get the "next id from disk" also check if there
if only the RUV entry.  If it is, then set the next ID to 1 (for the suffix)
and set the ruv flag that indicating that the entry ID count needs to be
bumped past the RUV entry when the suffix is finally added.

relates: https://github.com/389ds/389-ds-base/issues/7378

CI test assisted by: Cursor

Reviewed by: progier, tbordaz, and spichugi(Thanks!!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ab2fa87199c2ece1f36933938828c559ab987695">ab2fa871</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-04-02T22:50:11-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7370 - Runtime LSan/TSan injection for pytest (#7371)

Description: Add --sanitizer=lsan|tsan pytest option to inject
sanitizers into ns-slapd without rebuilding.

Use systemd drop-in files (dirsrv@.service.d/sanitizer.conf)
on systemd hosts and direct env var injection via DirSrv._start_env
on containers and prefix builds. Drop-ins correctly override the
jemalloc LD_PRELOAD from custom.conf.

Include setup_host.sh for sysctl configuration and a targeted
SELinux policy module (ds_sanitizer.te) that grants dirsrv_t only
ptrace and execmem instead of using domain_can_mmap_files or
setenforce 0.

Fixes: https://github.com/389ds/389-ds-base/issues/7370

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/52d865cf3087617cb2bfcf7883d45c64682c120a">52d865cf</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-04-08T23:56:15+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7327 - dsctl healthcheck DSMOLE0001 inaccurate recommendations with multiple backends (#7328)

Description:
The dsctl healthcheck tool generates incorrect recommendations for the MO plugin when
multiple backends are present. This commonly occurs in IPA environments where both
userroot and ipaca backends exist. Healthcheck incorrectly suggests indexing attributes
for backends that are not within the MemberOf plugin scope.

Fix:
Determine the MO plugin scope while iterating over backends and only generate
recommendations for backends that fall within that scope.

Removed references to nsslapd-plugincontainerscope as we dont use it.

Fixes:
https://github.com/389ds/389-ds-base/issues/7327

Reviewed by: @droideck  (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/f974643f7c54e166913d6ca525603f3fa880382c">f974643f</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-04-09T00:40:07+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7360 - Expose stats from deferred memberof (#7361)

Description:
Currently, there's no visibility into deferred memberof processing performance.
When deferredupdate is enabled, admins cannot monitor the processing.

Fix:
Add a monitoring interface accessible via dsconf that exposes real time stats.

Relates: https://github.com/389ds/389-ds-base/issues/7360

Reviewed by: @tbordaz, @droideck  (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/57daabd4e550b3c989aa746d1d35a93dcd20cda7">57daabd4</a></strong>
<div>
<span> by Barbora Simonova </span> <i> at 2026-04-09T09:55:05+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7353 - CI - Fix checks for plugins/accpol_test.py::test_glinact_nsact

Description:
Update the test to check for inactivity before unlocking the account

Fixes: https://github.com/389ds/389-ds-base/issues/7353

Reviewed by: @droideck, @progier389 (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/3157ad3715fa7d4152142b039aa77d0266535bc4">3157ad37</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-04-09T12:30:48+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7389 - Allow to ignore criticality flags for specific controls (#7390)

* Issue 7389 - Allow to ignore criticality flags for specific controls

Add a new multivalued ds-ignored-control-criticality config attribute containing the list of control type (could be an oid or any utf-8 string) whose criticality flags will be then ignored

Issue: #7389

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/82390379cf8b8427d84c2b5fd273c0305e7586aa">82390379</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-04-09T18:09:23-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7277 - UI - Fix Japanese translation errors errors in Cockpit UI (#7386)

Description: Fix translation errors in the Japanese locale file (ja.po)
including meaning reversals (success/failure swaps), wrong technical terms
(DNA->DNS, slapd->lapi, time skew->time schedule), copy-paste errors
(edit->delete, ACI->CSR, initialize->export), typos (VLV->VLL, stray characters),
and incorrect grammatical forms.

Fixes: https://github.com/389ds/389-ds-base/issues/7277

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/5e1647f40930282e52134220f9de8fc04bd7aa3e">5e1647f4</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-04-10T09:27:01+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48265 test (#7388)

Description:
Porting ticket 48265 test into dirsrvtests/tests/suites/filter/complex_filters_test.py

Relates: #6753
Author: Lenka Doudova
Reviewer: Pierre Rogier</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/05693d93495e6ae990be99672248a5608fd87401">05693d93</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-04-10T09:28:18+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48170 test (#7387)

Description:
Porting ticket 48170 test into dirsrvtests/suites/indexes/regression_test.py::test_reject_ns_index_type_comma_packed_value
using lib389 API

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: Pierre Rogier</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/2168b0f9c461551740d8ee7db64b23fea6ea6326">2168b0f9</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-04-10T10:27:37+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7396 - Testimony failure in monitor_test.py (#7397)

Description:
Docstring error.

Fixes: https://github.com/389ds/389-ds-base/issues/7396

Reviewed by: @mirielka  (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/e8072370f12bd18cd4da35167500158c0e182a87">e8072370</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-04-10T10:59:32+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7394 - UI - Manual typing of ports can leave out digits (#7395)

Description:
The onChange event triggered port validation on every keystroke, resulting
in calls to check for used ports.

Fix:
Moved port validation from onChange to onBlur event.

Fixes: https://github.com/389ds/389-ds-base/issues/7394

Reviewed by: @mirielka    (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/6d40d18bcc47eb57a49894f7ea87858b22b7ca4a">6d40d18b</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-04-14T10:52:45+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7119 - CI - Fix flaky test_dna_shared_config_replication (#7385)

Description: Add retry loop around shared config lookup to handle
dna_update_config_event (fires 30s post-restart) which briefly
deletes and recreates shared config entries.

Relates: #7119

Reviewed by: @progier389</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/687b2a260703c07fb5346afda73529b638a60659">687b2a26</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-04-14T10:54:28+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7227 - CI - Fix flaky dynamic certificates test crash (#7382)

Description: Add restart workaround before tests to clear
corrupted NSS PKIX cache state from prior cert operations.

Relates: #7227

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b019653688216e49cafd3080fdc4e00563fd7040">b0196536</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-04-14T10:55:41+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 4148 - Add unit tests for CSN clock error handling (#7330)

Description: Add 5 CMOCKA unit tests validating CSN generator
properly handles clock failures and time skew detection.

Relates: https://github.com/389ds/389-ds-base/issues/4148

Reviewed by: @tbordaz, @jchapma (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/411276274b7df603d45ff1a7d5438cabe7b62472">41127627</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-04-14T15:13:28-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7404 - fix latest compiler warnings

Description:

Fix compiler warnings

relates: https://github.com/389ds/389-ds-base/issues/7404

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/220d84a0a516338b5ec99e730f6b6b035570a8cd">220d84a0</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-04-20T09:14:16-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7407 - dbscan -k option display entries that do not match the specified key

Description:

dbscan starts with locating the requested key, but then it continues to
display every entry after that one until it hits the end of the db.  As a side
effect it also always returns a non-zero result code.

relates: https://github.com/389ds/389-ds-base/issues/7407

Reviewed by: progier & tbordaz(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/95d70941cc0a3da8a53e4c80265d63f5f0da8c31">95d70941</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-04-21T16:56:26+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7418 - Use-after-free in deferred memberof (#7419)

Bug Description:
On a server under high load a crash can occur when deferred memberof is
enabled.

Fix Description:
Add a common helper `deferred_pblock_cleanup()` for a consistent cleanup
across all deferred_* functions.

Fixes: https://github.com/389ds/389-ds-base/issues/7418

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/e3606a78f20ad721c68a14b9a56543f092b4e83e">e3606a78</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-04-21T11:52:42-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7423 - cleanup pblock after freeing pre/post entries

Description:

There are few places where we don't see the pre/post entry in the pblock to
NULL after freeing them. Just being overly cautious as some of these changes
might not be needed, but it's still good to set the code example and also
future-proof these areas.

relates: https://github.com/389ds/389-ds-base/issues/7423

Reviewed by: vashirov(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/c7ec9e10a9cdfb69a29e6fb447cefa6ffd00cf1f">c7ec9e10</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-04-21T14:25:25-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7088 - Change log level for "Can't locate CSN" error message

Description:

There are legitimate reasons for a CSN temporarily not found in the changelog,
and in recent cases it always resolves itself.  Instead of logging a scary
message by default move the log level to "replication".

relates: https://github.com/389ds/389-ds-base/issues/7088

Reviewed by: progier & tbordaz (Thanks!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/204df3c991049d9f65fec2f3019cfe7aff0a5649">204df3c9</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-04-21T17:57:36-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7411)

Description: Run npm audit fix to address the vulnerabilities
in brace-expansion.

Relates: https://github.com/389ds/389-ds-base/issues/3555

Reviewed by: @vashirov (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/e863ad276294acd06c48663f588c9c020c560c30">e863ad27</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-04-22T16:34:34+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7375 - CI - Fix flaky dsconf_tasks_test watch output (#7410)

Description: Print the initial nsTaskLog snapshot in Task.watch()
so early log lines are not silently dropped.

Relates: #7375

Reviewed by: @mreynolds389</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a82465a20400ce0e7e98f91578beb0930161d9c2">a82465a2</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-04-22T15:03:15+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7389 - Fix CONFIG_CHARRAY crash (#7415)

* Issue 7389 - Fix CONFIG_CHARRAY crash

Fix crash related to CONFIG_CHARRAY because config_set does was calling successively the callback with a single value rather than providing the value array.
And fix the bug in the test that hid the problem.

Issue: #7389

Reviewed by: @tbordaz and @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/03be3fb31da58c0edf5fcad158f2e50803bf2917">03be3fb3</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-04-22T15:32:56+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7420 - Inconsistencies in the password policy log messages (#7421)

Bug Description:
There are some inconsistencies in the password policy log messages:

- Mixed first letter case
- Different separators/punctuation before Entry/Policy fields

Fix Description:
Capitalize the first letter of PWDPOLICY_DEBUG messages, standardize
punctuation before Entry/Policy fields, fix `slapi_log_err()` argument
order in charray.c and compare.c, fix function name typo in pw_retry.c,
and update tests to match.

Fixes: https://github.com/389ds/389-ds-base/issues/7420

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/c8e0624acb0c6d49e782fa9cb9c626e3f196d83b">c8e0624a</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-04-23T08:18:01-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7417 - UI - global password policy syntax settings missing passwordMaxRepeats

Description:

The global password policy syntax settings were missing passwordMaxRepeats,
but it is present under the local password policy settings.

relates: https://github.com/389ds/389-ds-base/issues/7417

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b9cc14bf4b0316c8d085704126711ef8d4217f9d">b9cc14bf</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-04-23T16:19:54-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7412 - Report thread pool saturation on per-operation access log RESULT lines (#7413)

Description: Extend nsslapd-statlog-level with LDAP_STAT_THREAD_POOL (2).
When enabled, every external operation's RESULT line in the access log
includes wbusy=N/M and wqdepth=N, correlating individual operation
latency with pool utilization at dequeue time.

wbusy=N/M: workers active (N) out of configured max (M).
High ratio signals near-saturation before wtime detects starvation.
wqdepth=N: operations still queued after this one was dequeued.
Non-zero indicates backlog accumulation.

Runtime-toggleable via dsconf. Supported in plain-text (wbusy/wqdepth)
and JSON (wbusy, wmax, wqdepth) formats for all externally-initiated
op types. Internal operations are excluded as they bypass the work
queue. logconv extended to parse and summarize pool stats.

Fixes: https://github.com/389ds/389-ds-base/issues/7412

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a362dcdfd195d00c9ba84058dccf3007ba41ae9c">a362dcdf</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-04-24T09:14:22+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7365 - Add integration with Renovate (#7439)

Description:
Automate updating npm, pip, cargo dependencies using Renovate bot.

Fixes: https://github.com/389ds/389-ds-base/issues/7365

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/8d77b8d45df68d921a4bcaae196896b3c9fe82da">8d77b8d4</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-04-24T11:19:04+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7437 - LeakSanitizer: memory leaks in CoS cache error paths (#7438)

Description:
Fix memory leaks in CoS plugin when a CoS definition fails validation
or is incomplete.

Fixes: https://github.com/389ds/389-ds-base/issues/7437

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a7002a725e13603cd3d99622afb3ea49583c9230">a7002a72</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-04-27T12:04:56+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Migrate config .github/renovate.json (#7450)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/7a0e31397ed81a0ad6af3469cd821fdabc364a02">7a0e3139</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-04-27T13:16:12-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7426 - logconv.py is out of sync with server-emitted note codes (#7427)

Description: notes=N (asynchronous) and notes=B (blocked) were not
tracked or reported, and notes=M (MFA) silently failed to produce any
per-operation output because the class-level dict shadowed the
ResultData field.

Add counters and detail dicts for notes=N and notes=B in ResultData,
remove the shadowing assignments in logAnalyser, and log a debug message
(instead of crashing) when an unrecognized note code is encountered
so future codes do not break analysis.

Decrease redundancy with a shared helper.
Add a test that injects SRCH/RESULT pairs for every known note code
plus an unknown one and asserts both summary counters and
verbose detail blocks.

Fixes: https://github.com/389ds/389-ds-base/issues/7426

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/971fd2d9ac4e09bae97008da898c45be9edadc4a">971fd2d9</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-04-28T12:44:27+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update rust-dependencies to v1 (major) (#7449)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Viktor Ashirov <vashirov@redhat.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/87f19fccd9fe3b415a9fbf67365193c1a848a2a8">87f19fcc</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-04-28T12:54:14+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update cockpit-389-ds-npm (major) (#7448)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Viktor Ashirov <vashirov@redhat.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/c8359aeb50225ab914cd1e17ae44da587a0a94b6">c8359aeb</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-04-28T12:56:05+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update Rust crate openssl to v0.10.78 [SECURITY] (#7455)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/1ab704694c123c5a9a5511f4152d59f45ebd52bb">1ab70469</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-04-28T13:08:41+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7440 - Substring index produces empty results and can crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured (#7441)

Bug Description:
1. With begin=1, middle=3, end=3, search doesn't return results for matching entries.
2. With begin=2, middle=2, end=3, server crashes with SEGV

Fix Description:
1. Fix signed/unsigned comparision by casting `bvp->bv_len` and `slapi_value_get_length()` results to `(int)`.
2. Avoid underallocation when (begin + end) > middle*2.

Also port ticket48109_test.py to DSLdapObject.

Fixes: https://github.com/389ds/389-ds-base/issues/7440

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/58bbb7d0ab09d641234879d80034f8c946024183">58bbb7d0</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-04-28T13:52:54+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update dependency uuid to v14 [SECURITY] (#7456)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/86f6ea1a74e255da1f5f4623d7b0d99f96f017ae">86f6ea1a</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-04-28T09:48:23-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7431 - password policy - passwordBadWords is ignored in local policies

Description:

When processing local password policies we only initialize the "bad words"
setting from the global config. So the local policy setting for passwordBadWords
is always skipped/ignored.

In fact we do initialize the password policy config, but when we do the actual
syntax check we directly pull from the global config via:
config_get_pw_bad_words_array()

relates: https://github.com/389ds/389-ds-base/issues/7431

CI test assisted by: Cursor

Reviewed by: progier(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/e5e577112afaa47c0e24f53d5ed48ffbd81de060">e5e57711</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-04-28T16:27:44+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48270 test

Description:
Port ticket 48270 test into dirsrvtests/tests/suites/indexes/regression_test.py

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: @progier (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/c5b4f8ba1732148c15d2c3852c6caa287fc29d1d">c5b4f8ba</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-04-28T19:07:25+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Porting ticket 48312 test

Description:
Porting ticket 48312 test into dirsrvtests/tests/suites/plugins/managed_entry_test.py by adding the testcase as a part of already existing test test_mentry01.

Relates: #6753
Author: Lenka Doudova
Reviewer: @bsimonova (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/d05b790091e947571ed9c0313415af63c09cb283">d05b7900</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-04-29T11:22:50+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6942 - Crash in `slapi_sdn_get_ndn()` (#7318)

Bug Description:
In `id2entry_add_ext()` we have a workaround that normalizes entry DN
against the parent's cached DN to fix case difference (bz628300). But
`cache_add_tentative()` has already inserted the entry into the
`c_dntable` hash table under the old normalized DN (slot A). When the
workaround for bz628300 changes the DN in-place, the subsequent
`CACHE_ADD()` inserts the entry into `c_dntable` under the new
normalized DN (slot B). The entry now exists in 2 hash slots at the same
time. And when the entry is later freed or evicted, only slot B is
cleaned up. Slot A still contains a dangling pointer to the freed
memory. Any further operation that walks the slot A hash chain (search
via `id2entry` or delete via `cache_find_dn`), calls `entry_same_dn()`,
which dereferences the dangling pointer, leading to SIGSEGV.

Fix Description:

1. In `id2entry_add_ext()` call `cache_remove_dn_hash()` under CACHE_LOCK
   immediately before the bz628300 DN change to remove the entry from
   its current hash slot.

2. Add a new `ep_dn_hash_ndn` field to backentry struct to save the
   normalized DN at tentative-add time. When confirming the add in
   `entrycache_add_int()`, use the saved NDN to locate and remove the
   entry from its original `c_dntable` hash slot before re-inserting
   under the current DN. This handles the case where a betxn pre-add
   plugin changed the DN between cache_add_tentative() and CACHE_ADD().

Fixes: https://github.com/389ds/389-ds-base/issues/6942

Reviewed by: @progier389, @tbordaz, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/12b9c830f71312e8fd29282db5a67c2d2c2ab9d2">12b9c830</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-04-29T17:55:41-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Bump version to 3.2.1
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/f1fd5c3c9c7502a4506b863b73060d180d14f74a">f1fd5c3c</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-04-30T08:38:54-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7452 - UI - password polices - reorganize settings

Description:

Password min token length only works with "passwordUserAttributes", but in the
global policy page it was not located logically. Local policy edit page is
also missing the "max repeats" and "passwordMinTokenLength" settings.

relates: https://github.com/389ds/389-ds-base/issues/7452

Reviewed by: mirielka(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/8560f7614657af01f0f8ab4fb82e0ad103cc8852">8560f761</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-04-30T15:29:19+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>issue 6867 - check file access in dsctl ldif2db (#7459)

Check file access in dsctl ldif2db so that the command fails before clearing the backend.
in order to check that a sub process is spawed so that we can safely change its uid and gid to the instance localuser one

issue: #6867

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/758adca10499a6b9c2a11556933fbc7961d67c5b">758adca1</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-04-30T15:51:01+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48272 test (#7442)

Description:
Porting ticket 48272 test into dirsrvtests/tests/suites/plugins/addn_test.py

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: @progier (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/400466b3e3b91a87de3998fa0708ef01be10dc1e">400466b3</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-05-04T06:09:03+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48214 test

Description:
Port ticket 48214 test into dirsrvtests/tests/suites/config/config_test.py

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: @mreynolds389, @droideck (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/61d6233eafd01ab5f4861b5ce6749ecb6cbc862a">61d6233e</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-05-04T10:19:05+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update github-actions (#7474)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/7b1fd88269727351379b0411189ba1a75ce59930">7b1fd882</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-05-04T17:16:37-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7457 - Refactor memberOf perf test (#7458)

Description: The memberof perf test module uses old and
legacy lib389 objects, polls memberOf sync on a fixed 30s
sleep with a full (memberOf=*) walk per iteration,
and has hard-coded perf-grade parameters that make it
unusable in a CI budget.

Use correct lib389 objects, add intervals, low-power mode
for smoke-runs and add two benchmarks
(test_replace_member_list, test_ldif2db_dense_member_import)
that report median/p95/p99.
Fix minor issues.

Fixes: https://github.com/389ds/389-ds-base/issues/7457

Assisted by: Claude Code

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4ef9bb0a1dc8d1c7be34ed9dc47845e5a3050345">4ef9bb0a</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-05-05T11:13:47+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7372 - Reindex adds tombstones to ancestorid causing export failures (#7373)

Bug Description:
During import/reindex, tombstone entries are added to the ancestorid
index. When those tombstones are later purged, the purge thread skips
updates to ancestorid index. This leaves stale entry IDs in the
ancestorid index referencing entries in id2entry that are no longer
there.

Fix Description:
Skip tombstone entries when building the ancestorid index during
import/reindex.

Fixes: https://github.com/389ds/389-ds-base/issues/7372

Reviewed by: @progier389, @tbordaz, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/bec7af16b0360755a000d626a24a08c1a63a2cab">bec7af16</a></strong>
<div>
<span> by Firstyear </span> <i> at 2026-05-05T11:15:00+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7289 - RFE - Container First Run Improvements (#7290)

Bug Description: On first run of a container we always are creating
the self-signed-cert even if it's not used. Additionally setting
the DS_SUFFIX_NAME only adjusted dsrc, it didn't create the suffix

Fix Description:

* If a TLS certificate is being imported, don't generate self-signed
  certificates on first run.
* If a DS_SUFFIX_NAME is set, create the suffix on first run

fixes: https://github.com/389ds/389-ds-base/issues/7289

Author: William Brown <william@blackhats.net.au>

Review by: @vashirov</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/1e42929335950c956a363e07642beb5dd6a201f4">1e429293</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-05-05T12:28:47+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 3082 - Separate test code from lib389 (#7430)

* Issue 3082 - Separate test code from lib389

Remove pytest module adherence from lib389 by moving the pytest fixtures in a new test389 library:

Moving topologies, perf_tools, dsrate in dirsrvtests
Duplicate topologies into lib389.tests
Replace lib389.topologies by test389.topologies in dirsrvtests tests
Replace lib389.topologies by lib389.tests.topologies in lib389.tests tests
Issue: #3082

Reviewed by: @vashirov (Big Thanks!)

* fix lib389.tests

* Fix lib389.test paths

Co-authored-by: Viktor Ashirov <vashirov@redhat.com>

* Set proper libpath in create_test.py

* Fix new testcase after rebase

* Update dirsrvtests/create_test.py

Co-authored-by: Viktor Ashirov <vashirov@redhat.com>

---------

Co-authored-by: Viktor Ashirov <vashirov@redhat.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/f8c69923d46270c31dec9d7475064387ce27683f">f8c69923</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-05-05T13:52:12+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7478 - Regression in FreeIPA backup-restore test (#7479)

* Issue 7478 - Regression in FreeIPA backup-restore test

Fix a regression caused by #6867
It seems due by the use of inner function inside a function.
Using class static method instead

Issue: #7478

Reviewed by: @vashirov (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/fdb828b6a7b5085c4d67e5cd7276cb6cf5836c12">fdb828b6</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-05-05T16:03:09+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7470 - dsctl localhost tls import-server-key-cert fails with 'expected str, bytes or os.PathLike object, not NoneType' (#7477)

Fix Description:
Replace `getattr()` with `args.nickname or CERT_NAME` to properly fall
back to 'Server-Cert' when nickname is not provided.

Fixes: https://github.com/389ds/389-ds-base/issues/7470

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/edde6f7a7f7274ab556c15f8ddebbe61c75c60ac">edde6f7a</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-05-06T18:57:23+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6641 - MODRDN fails when referint-tracked attr is MUST and SINGLE-VALUE (#7409)

Description: Group consecutive DEL+ADD modifications on the same
attribute into a single atomic modify so that schema_check sees
the final state rather than the intermediate empty state.

Relates: #6641

Reviewed by: @droideck, @tbordaz, @jchapma (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/37e91a1511027f0b1819280e60e0ff4f4883166d">37e91a15</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-05-06T15:44:32+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7475 - Fix CI test failures (#7476)

Description:
`retrocl`, `resource_limits` and `clu` test suites are flaky and fail
from time to time.

Fixes: https://github.com/389ds/389-ds-base/issues/7475

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/bbaa0667537621ed3647b360cfc5aa7b3269dd04">bbaa0667</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-05-07T08:48:27+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Remove ticket 48497 test (#7482)

Description:
Ticket 48497 tests are already covered in dirsrvtests/suites/indexes/regression_test.py,
namely in test_reindex_homedirectory_matching_rules and test_reindex_homedirectory_mixed_value tests),
therefore the ticket 48497 can be removed.

Relates: #6753
Author: Lenka Doudova
Reviewer: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ba46496018c8ec18cc102e847cfa6240302262fd">ba464960</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-05-07T08:57:06+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48194 test

Description:
Porting ticket 48194 test to dirsrvtests/tests/suites/tls/cipher_test.py

Relates: #6753
Author: Lenka Doudova
Reviewer: @progier389, @jchapma (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/cb7ddaa5ddba275e05c4330b9a230063e8c1ff6b">cb7ddaa5</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-05-07T09:38:02+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update Rust crate openssl to v0.10.79 [SECURITY] (#7484)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/825e25d132f000ac2f444ca460e13fa346ce122c">825e25d1</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-05-07T15:37:17+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48366 test (#7481)

Description:
Porting ticket 48366 test into dirsrvtests/tests/suites/acl/proxy_authz_test.py

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: @mreynolds389, @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/d2d96daa34422ea6ac3a80be15efdb8bf3ba0648">d2d96daa</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-05-11T08:37:46+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48383 test (#7486)

Description:
Porting ticket 48383 test into dirsrvtests/suites/import/import_test.py
as test_realloc_on_offline_import_export.

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/71713897bf37b52f95c65cf68f4de96c4f391c10">71713897</a></strong>
<div>
<span> by dependabot[bot] </span> <i> at 2026-05-11T10:42:15+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Bump fast-uri from 3.1.0 to 3.1.2 in /src/cockpit/389-console (#7487)

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.0 to 3.1.2.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](https://github.com/fastify/fast-uri/compare/v3.1.0...v3.1.2)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/d7f6b938ff1fa82a56074fbb03615b00c980ecfc">d7f6b938</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-05-11T11:23:02+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48266 test

Description:
Port ticket 48266 test into dirsrvtests/tests/suites/fractional/fractional_test.py using lib389 API.

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: @droideck (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/0c9ce1e875c8f4eb92e2a1e3a75ab1f8711e06b8">0c9ce1e8</a></strong>
<div>
<span> by Barbora Simonova </span> <i> at 2026-05-11T17:38:33+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7435 - Add AGENTS.md to support AI coding assistants

Description:
Add AGENTS.md with project context and related documentation with
building, contributing and testing guidelines for AI assistants.
Add rules for Cursor, Claude and Gemini.

Fixes: https://github.com/389ds/389-ds-base/issues/7435

Reviewed by: @mreynolds389, @progier389, @droideck (Thanks!)
Assisted by: Cursor
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/1502d93f323a93f5b1e98a4861c5b059818ffa48">1502d93f</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-05-12T09:54:21-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7464 - CLI - allow dsidm to work with other user types

Description:

In the UI you can create these entry types:

- Posix (default for dsidm)
- Basic (similar to nsUserAccount but without posix requirements)
- Traditional (old style entries from DS 1.3)
- Service account

Add a user "--user-type" option to dsiadm users to specifiy these optional types.
The default is stil "posix".

relates: https://github.com/389ds/389-ds-base/issues/7464

reviewed by: spichugi & progier(Thanks!!)

Update argparse to correctly handle different user types when creating a new entry.

Thanks Simon for the assist on this one!
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/db06e152920380f80ea45299d3676cdb05c7cba1">db06e152</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-05-12T22:39:36+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Removing ticket49287 test and porting to DSLdapObject (#7480)

Description:
The old ticket49287_test.py had compatibility issues with raw
python-ldap methods. This ports the functionality to
memberof_multi_backend_test.py using modern lib389 patterns.

The new test focuses on the core memberOf functionality across
multiple backends using UserAccounts, Groups, and MemberOfPlugin
classes instead of raw add_s/modify_s operations.

Relates: #6753

Reviewed by: @progier389
Assisted by: Claude</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/800939f2cd861506aff14e1821133f0b96919a59">800939f2</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-05-12T18:08:01-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets (#7461)

Description: memberof_replace_list and linked_attrs_replace_backpointers
sort pre/post with slapi_attr_value_cmp_ext, which returns 0 on match
and a negative value or LDAP error code on non-match — not a strict
weak ordering. The merge loop's cmp > 0 branch is never taken, so
overlap members are deleted and re-added on every MOD_REPLACE,
bumping entryUSN.

Switch both comparators to slapi_utf8casecmp on raw bv_val.
For that to work, normalize DN-syntax values in str2entry_fast
(which did not normalize at all — the old code sat under an unset
OBSOLETE_DN_SYNTAX_CHECK) and route str2entry_dupcheck through the
same helper. Skip the upgradedn path (SLAPI_STR2ENTRY_USE_OBSOLETE_DNFORMAT)
in both, preserving raw bytes for the LMDB import. Fix a stray missing
comma in the dupcheck strict-fail slapi_log_err. Drop the now-unused
qsortConfig plugin global.

Add Python regression tests for both memberOf and linkedAttrs cases.

Fixes: https://github.com/389ds/389-ds-base/issues/7460

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/bb43de9f2c4dece1286be9b6b86fcd492e016c33">bb43de9f</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-05-13T16:31:18+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Removing ticket49303_test and porting to DSLdapObject (#7429)

Description:
The old ticket49303_test.py had compatibility issues.
This ports the functionality to tls_renegotiation_test.py
using modern Encryption class from lib389.

Relates: #6753

Reviewed by: @progier389
Assisted by: Claude</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/3dc55b29928016db6c2dfa540dd38af15d342205">3dc55b29</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-05-13T16:39:16+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Removing ticket49412_test and porting to DSLdapObject (#7428)

Description:
Port test to changelog_test.py using Changelog/Changelog5 classes,
supporting both legacy and new changelog. Replace wildcard imports.

Relates: #6753

Reviewed by: @bsimonova, @mreynolds389 (Thanks!)
Assisted by: Claude</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a2551eacf4950b60cb4e7692afe683f0659f33c9">a2551eac</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-05-17T12:09:49-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7402 - CLI - allow healthcheck to work when server is stopped

Description:

Use and extend the DSEldif class to handle most of the lint checks that query
cn=config. If a check must be skipped a message is displayed to the user.

relates: https://github.com/389ds/389-ds-base/issues/7402

Assisted by: Cursor

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ccab7e336b103b5894c0e2e78927e210560f0c15">ccab7e33</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-05-17T12:09:49-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add disk space checking functionality for offline server
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4f3a04317d28b3fdf6cfa531af85d5270d969627">4f3a0431</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-05-17T12:09:49-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>fix CI tests
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/5f6b41afd8c03fefc173ef9d33f5b7a1ced89bf2">5f6b41af</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-05-17T12:09:49-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Minor fixes
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/3269cd863bafa39e23f5dde598cf2731f9b0e4e6">3269cd86</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-05-17T12:09:49-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>address Simon's comments
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/aeabd2874abd51b9b552f8749c74b9f211f3b06d">aeabd287</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-05-18T08:24:31-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7402 - remove debug print state

Description:

Remove debugging print state from offline healthcheck commit

relates: https://github.com/389ds/389-ds-base/issues/7402

Reviewed by: spichugi and mirielka(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/6c48ff6bea69f476586ee61cdcc379d5fa4e5860">6c48ff6b</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-05-20T09:57:47+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7468 - RFE - Add HIBP HTTP client (#7469)

Description:
Implement an HTTP client for querying the Have I Been Pwned (HIBP)
Pwned Passwords API using the k-anonymity model. This is the first
commit toward password breach detection in 389 Directory Server.
Requires libcurl (optional dependency, enabled via --enable-hibp).

- HTTP transport using libcurl
- SHA-1 hashing via NSS
- Unit tests with mock transport

Fixes:  https://github.com/389ds/389-ds-base/issues/7468

Reviewed by: @vashirov, @progier389, @mreynolds389 (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/1a3c98c0df8313f27dc39bccc3b9a12aee13f800">1a3c98c0</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-05-21T13:46:26-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7503 - CVE-2026-9064 - Add a limit to the number controls per operation

Description:

Security fix for CVE-2026-9064

To prevent resource starvation limit the number of controls the server will
process per operation. Reject the operation if number of controls exceeds
the limit

relates: https://github.com/389ds/389-ds-base/issues/7503

References:
    - https://access.redhat.com/security/cve/cve-2026-9064
    - https://bugzilla.redhat.com/show_bug.cgi?id=2480093

CI test assisted by: Cursor

Reviewed by: jchapman & tbordaz (Thanks!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/05796473d3828a8221ac8be60c6320dcfef0ef48">05796473</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-05-21T15:11:56-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7496 - Fix latest GCC compiler warnings

Description:

Fix latest GCC (gcc-16.1.1-1) compiler warnings

relates: https://github.com/389ds/389-ds-base/issues/7496

Reviewed by: jchapman (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/6c7ff6b55364c673f9aec167182ef889161fcfb6">6c7ff6b5</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-05-26T18:11:38-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7475 - Fix CI test failures in test_fd_limits (#7488)

Description: MAX_FD_VAL was computed from pytest's RLIMIT_NOFILE,
but the server caps against its own rlim_max (set by systemd
LimitNOFILE for dirsrv@). When pytest's limit is lower,
TOO_HIGH_VAL = MAX_FD_VAL+1 stays below the server cap and
the modify is accepted instead of rejected.

Compute MAX_FD_VAL from SYSTEMD_LIMIT (handling "infinity"),
and use it for CUSTOM_VAL and the default assertion.

Fixes: https://github.com/389ds/389-ds-base/issues/7475

Reviewed by: @mirielka (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/1a9bf0a4503f0ddb07230ab6cc5b75f1f7ad9569">1a9bf0a4</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-05-29T12:40:51-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7516 - dblayer_bulk_nextdata should not return an error when maxrecords is hit

Description:

When doing a bulk read of an index if the candidates were more than 100 it
would silently stop processing the index read. This would lead to database
corruption. This is most easily reproduced by doing a moddn with a subtree
that had a lot of child entries. The "maxrecords" check is not even needed
so it was removed and this allows all children to be correctly updated

relates: https://github.com/389ds/389-ds-base/issues/7516

Reviewed by: progier(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b584197cc5f35b2436bf9439fe32e89a0d840022">b584197c</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-05-29T12:45:38-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7514 - Crash when doing moddn on very large subtree

Description:

Attempting to move a subtree underneath another subtree leads to an assertion
failure on debug builds.

Revise the logic of this code so we only call cache_remove if the entry was
actually added to the cache, and also make sure we add dsEntryDN during
imports.

relates: https://github.com/389ds/389-ds-base/issues/7514

Reviewed by: progier & tbordaz (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/e66b8ca1842aa93bcf7f46f1a83e4195704e263c">e66b8ca1</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-05-29T13:20:47-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7507 - UI - cleanup style and alignments

Description:

Cleanup the layout on some on the settings pages, and the alignment. Some
fields used the entire width of the page for a very small value, and some
places the width of the fields needed indents.

Also NumberInput's minus buttons wouldn't behave correctly unless the value
was an integer (versus a string).

relates: https://github.com/389ds/389-ds-base/issues/7507

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a8d63d5d8d84e3141c35debc742c614a6c7a66da">a8d63d5d</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-06-02T17:00:44-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7493 - RFE - Add ShadowAccount fixup task

Description:

ShadowAccount attributes are generated when a password is updated, but when
users are imported these "shadow" attributes are not updated. We need a fixup
tasks to set ShadowLastChange if it's missing, but also to fix the value if
it is stale.

Design doc:

https://www.port389.org/docs/389ds/design/shadow-fixup-design.html

Relates: https://github.com/389ds/389-ds-base/issues/7493

Reviewed by: spichugi & tbordaz(Thanks!)

Apply Simon's requests
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/e0d444810d2a53f71663b0e81692139f83dfeee2">e0d44481</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-06-03T10:36:08+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48745 and 48746 tests (#7513)

Description:
Porting ticket 48745 and 48736 tests into dirsrvtests/tests/suites/indexes/regression_test.py.
Cleaning up unused imports in the file.

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: @progier389, @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/520a4d702cf7b3fd7b44eadfa75ccb855b326e29">520a4d70</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-06-03T12:21:40+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48354 test

Description:
Port ticket 48354 test to dirsrvtests/tests/suites/acl/anonymous_default_aci_test.py using lib389 API.

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: @mreynolds389, @progier389
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/cfa1a0cdf133c2955cf86efb86c35c150b0ce5f5">cfa1a0cd</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-06-03T16:01:21+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Removing ticket48252_test and porting to DSLdapObject (#7520)

Description:
The old ticket48252_test.py had compatibility issues.
This ports the functionality to entryusn_test.py
using modern DSLdapObject methods.

Relates: #6753

Reviewed by: @mreynolds389  (Thanks!)

Assisted by: Claude</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b1d14c1078c0462aba669866c90cd997e7fafdbd">b1d14c10</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-06-03T16:30:44+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 49658 test

Description:
Porting ticket 49658 test into dirsrvtests/tests/suites/replication/mmr_single_value_conflict_test.py

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: @progier389
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/01a3dfa82c0c0121be34cfe1646d8ced3684a18d">01a3dfa8</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-06-03T17:30:32+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Bump version to 3.3.0</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/514a374149e004a3af2f33996cfb086228d38b95">514a3741</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-06-04T11:43:29+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7391 - Harden systemd service unit (#7392)

* Issue 7391 - Harden systemd service unit

Set NoNewPrivileges and MemoryDenyWriteExecute settings in systemd unit

Issue: #7391

Reviewed by: @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/f98e364a5714a14aea2c10f56cc960ed762fcfff">f98e364a</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-06-04T11:50:42+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7532 - CI - Fix BDB CLU dbmon tests leaving instance offline (#7553)

Fix CLU dbmon CI test by adding the missing import

Issue #7532

Reviewed by: @mreynolds389 (Thanks!)

Summary by Sourcery
Tests:

Update CLU dbmon test module to import the DSEldif helper needed for its execution.</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/c36ad54ed05c4821fbd2211f0be78163cfdc1464">c36ad54e</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-06-04T09:34:36-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7554 - deref plugin null pointer dereference if ber_init fails

Description:

**CWE**: CWE-476 (NULL Pointer Dereference)

A flaw in the 389 Directory Server's dereference control plugin allows an
unauthenticated attacker to crash the LDAP server when the system is under
memory pressure(OOM). The deref plugin, enabled by default, fails to check for
a memory allocation failure before using the result, causing the server
process to terminate.

CI test 'test_deref_and_access_control' already covers this fix.

relates: https://github.com/389ds/389-ds-base/issues/7554

Reviewed by: tbordaz & progier(Thanks!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/cd0b0e7e16538b6775847e45430bc757a2b15c38">cd0b0e7e</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-06-04T19:21:30-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7556)

Description: Run npm audit fix to address the vulnerability
in brace-expansion.

Relates: https://github.com/389ds/389-ds-base/issues/3555
Relates: https://github.com/389ds/389-ds-base/issues/7527

Reviewed by: jchapma (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/971e6f1405a102b6a3692f1f97d373dcb670e973">971e6f14</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-06-05T11:45:07+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7549 - Substring index should validate minimum nsSubStrBegin/nsSubStrEnd values (#7550)

Bug Description:
The `nsSubStrBegin` and `nsSubStrEnd` values include the anchor character
(`^` for begin, `$` for end) in the configured length. The actual number of
value characters stored in the index key is `configured_value - 1`.
A value of 1 for begin or end produces an index key with 0 value
characters, which matches everything and is not useful.

Fix Description:
Add validation to detect nsSubStrBegin/nsSubStrEnd values less than 2,
adjust them to 2, and log a warning.

Relates: https://github.com/389ds/389-ds-base/issues/7440
Fixes: https://github.com/389ds/389-ds-base/issues/7549

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4a4b23d33a279884e64ace10207d1fdbfbc2256b">4a4b23d3</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-06-05T11:45:45+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7539 - Server shutdown during online reindex may lead to data loss (#7540)

Bug Description:
When an online reindex task is aborted, for example by shutting down the
server with SIGTERM while the reindex is in progress, the database data
is lost, id2entry contains only 1 entry - RUV tombstone.
Additionally, a SIGSEGV in `dbmdb_public_db_op` is observed when
replication plugin tries to save the RUV state.

Fix Description:
When a reindex fails, don't close or delete the db. The backend is kept
busy (unavailable for client operations) to prevent searches against
incomplete indexes from returning wrong results. A CRIT message is
logged advising the admin to perform an offline reindex to rebuild
the indexes.

Fixes: https://github.com/389ds/389-ds-base/issues/7539

Reviewed by: @tbordaz, @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/efe15cacd729b04f1fec26a17cf5c1da1e35ae7c">efe15cac</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-06-05T10:34:21-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7560 - lib389 - Add helper function for checking ASAN files

Description:

Add a helper function for checking specific strings in an ASAN file

relates: https://github.com/389ds/389-ds-base/issues/7560

Reviewed by: tbordaz(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a988101824c26eaa85bda9ea1430a6e8f19ca4d5">a9881018</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-06-05T18:59:25+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7562 - Error: NssSsl.add_cert() got an unexpected keyword argument 'input_file' (#7563)

Bug Description:
In #7281 `input_file` parameter was renamed to `cert_file`, but not all
callers were updated. This causes a TypeError at runtime.

Fix Description:
Update dscontainer and dsctl to use the new `cert_file` parameter name.

Relates: https://github.com/389ds/389-ds-base/issues/7281
Fixes: https://github.com/389ds/389-ds-base/issues/7562

Reviewed by: @ mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/65a1afcdee407b85d6d1720560836f0a5f37ebfc">65a1afcd</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-06-09T09:34:29-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7500 - Prevent unsigned integer underflow during stalled import

Description:

During a stalled import the foreman's first ID could be greater than the
history progress size which leads to underflowing the rate. Check if the
foreman's first ID is greater than the progress size and just set it to
zero.

Relates: https://github.com/389ds/389-ds-base/issues/7500

Reviewed by: progier(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b885a34a79aeeb18ad7792da1a29cb83d0f3268c">b885a34a</a></strong>
<div>
<span> by tbordaz </span> <i> at 2026-06-10T15:14:08+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559)

Bug description:
        The online initialization requires that the supplier builds a sorted IDL.
        It is sorted in the way that the parent entry appears before the children in the IDL.
        The current implementation goes through the parentid index from the first entry
        until the end (next). To make sure parent entry is already in IDL before adding a child
        it uses a list of ID ranges.
        This list works well if the ID are mostly consecutive and with limited number of holes,
        else the list grows (lot of singleton) and checking the list becomes costly as well.

Fix description:
        Instead of walking the parentid index from the first entry to the end it walks
        the parentid in depth first. So there is no need to check that the parent ID is already
        present in IDL

fixes: #7558

Reviewed by: Pierre Rogier (Thanks !!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/9bc67fedfd6836887d777074aad771df600edf94">9bc67fed</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-06-15T12:39:34+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7573 - Post-import cache autotuning does not recompute entry cache size (#7574)

Bug Description:
When a new empty backend is created, and an online import is completed,
`dbmdb_start_autotune()` runs but doesn’t apply recomputed cache values.
A server restart is required for the new cache sizes to take effect.

Fix Description:
Always apply autotuning when autosize > 0.

Fixes: https://github.com/389ds/389-ds-base/issues/7573
Relates: https://github.com/389ds/389-ds-base/issues/6805

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ec0272007b8d78b36a326ef4d6e698d6d3195e46">ec027200</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-06-15T10:21:12-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload

Description:

After attr_syntax_swap_ht() promotes the tmp tables to live use and sets
oid2asi_tmp and name2asi_tmp to NULL, attr_syntax_init() was recreating
them on every attr_syntax_read_lock() call (e.g. from LDAP searches via
slapi_filter_schema_check), leaking PL_NewHashTable allocations.

Create the tmp tables lazily with attr_syntax_init_tmp() only during
schema reload, and discard them with attr_syntax_destroy_tmp() on reload
start, failure, or before rebuilding. attr_syntax_init() now initializes
only the live oid2asi and name2asi tables.

relates: https://github.com/389ds/389-ds-base/issues/7576

co-authored by: Cursor

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/06211300155546eb978a7718cc8057203b655e61">06211300</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-06-15T17:49:46-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7490 - Enable USDT probes by default in RPM (#7491)

Description: STAP_PROBE points exist in the source tree
but production RPMs are built without --enable-systemtap
and don't pull in systemtap-sdt-devel, so operators
cannot attach bpftrace or stap to a live ns-slapd
without rebuilding.

Default the RPM build to USDT-on. Rename the configure
flag to --enable-usdt (SystemTap is one of several
consumers). Add five work-queue probes: work_q__enqueue,
work_q__dequeue, worker__busy, worker__idle,
work__blocked. Ship paired bpftrace .bt scripts.

Fixes: https://github.com/389ds/389-ds-base/issues/7490

Assisted by (writing tests): Claude Code

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/36073835542f76e45cd8f6c932a518659fb4fc89">36073835</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-06-17T12:59:49+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7531 - Fix LMDB replication regression_m2 failures and core dumps (#7575)

Description:
During a nested rename, _entryrdn_append_childidl walks the entryrdn
index to collect descendant entry IDs. On LMDB it recursed into child
subtrees inside the bulk_nextdata loop, which repositions the shared
cursor before all duplicates under the parent key are read. That
corrupts the affected IDList and crashes in idl_append_extend. The fix
is to collect direct children into a temp LDList during the bulk loop,
and recurse when it completes.

Fixes: https://github.com/389ds/389-ds-base/issues/7531

Reviewed by: @progier389, @droideck (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/150a1a6131ccf1ec000a4fce6d9aa16ec20b8a2b">150a1a61</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-06-17T14:31:49+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6753 - Port ticket 48392 test (#7523)

Description:
Port ticket 48362 test to dirsrvtests/tests/suites/plugins/dna_repl_test.py using lib389 API.

Relates: #6753
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/325456fc5f08face617282feca3d7dbe1cd88939">325456fc</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-06-17T16:15:39+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7534 - CI - Fix resource_limits fdlimits failures in BDB and LMDB (#7585)

Change CI test to compute the limit from the ns-slapd process rather than relying on systemd one.

Issue: #7534

Reviewed by: @droideck (Thanks!)

Summary by Sourcery
Tests:

Adjust fdlimits tests to read RLIMIT_NOFILE from the server process via /proc rather than systemd LimitNOFILE, and base assertions on the process-specific max descriptor value.</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/862d02961efb281e71ba90a744af41b855df1fa2">862d0296</a></strong>
<div>
<span> by IliaKash1 </span> <i> at 2026-06-17T20:12:32-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() (#7542)

Bug description:

Various heap-buffer-overflows can be triggered with a specific input
passed to acl_parse().

Fix description:

Additional checks are added to prevent OOB memory access.

Fixes: https://github.com/389ds/389-ds-base/issues/7541

Author: Ilia Kashintsev

Reviewed by: @progier389, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/49613417c14a6b55a3169d4157d13c6ed5af1915">49613417</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-06-18T18:03:45+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7529 - Fix WebUI CI failure cascade and missing screenshots (#7566)

Description: Fix Firefox iframe crash that broke retry loop and cascaded
failures. Add cleanup fallback and upload .playwright-screenshots in CI.
Disable AppArmor unix-chkpwd profile on ubuntu-24.04 runners to fix
Cockpit PAM authentication. Update tuning test to match UI changes
from Issue 7507 that removed the ExpandableSection.

Fixes: #7529

Reviewed by: @droideck, @jchapma (Thanks!)

Assisted by: Claude</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/87a5c0a06d604aeb1a389da9faef7dfa11a8e662">87a5c0a0</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-06-18T11:26:34-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7521 - UI - make changes for cockpit API updates

Description:

Previously we used cockpit.spawn superuser argument as:

    cockpit.spawn(cmd, { superuser: true, err: "message" })

But the API changed and now instead of "true" the value should be "require":

    cockpit.spawn(cmd, { superuser: "require", err: "message" })

relates: https://github.com/389ds/389-ds-base/issues/7521

Authored-by: Cursor

Reviewed by: mreynolds & spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b90d03e092976601e5a7b6486d9c1cc3a04a78b9">b90d03e0</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-06-18T12:13:06-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7554 - UI - Revise local password policy layout

Description:

Editing and creating local policies uses a "tabs" approach, but it's confusing
about editing/creating policies. Move the edit & create pages to modals and
revise how the "saving" works to usea single button for all categories.

Other various/minor spacing and layout changes were also made.

relates: https://github.com/389ds/389-ds-base/issues/7454

Assisted-by: Cursor

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/2323aa660df5f77a684ffe6c304fc0eec4e4b262">2323aa66</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-06-22T18:46:21-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7541 - Add invalid ACL text header regression test (#7591)

Description: Malformed ACI values with missing or too-short
ACL text headers should be rejected during syntax validation.

Add parameterized coverage for empty ACL text headers, short
headers, and headers without an ACL name. The test verifies
these values fail with invalid syntax and ASAN doesn't crash.

Related: https://github.com/389ds/389-ds-base/issues/7541

Reviewed by: @mirielka (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/f4f3095a51709651bffc8124ebc4e66ab5f13704">f4f3095a</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-06-22T18:50:48-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7263 - UI - Use cockpit.file API for temporary file writes (#7590)

Description: Replace shell-based echo writes with cockpit.file().replace()
for pasted certificate imports and temporary instance setup INF files.
This avoids shell quoting issues, keeps sensitive file contents out of
command logs, and resets setup INF permissions after atomic replacement
before running dscreate.

Fixes: https://github.com/389ds/389-ds-base/issues/7263

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ecf33a59727cbdd3f3c80627178b5aad97a2b986">ecf33a59</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-06-22T18:58:14-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, babel/core (#7599)

Description: Run npm audit fix to address the vulnerability
in ws, js-yaml, babel/core.

Relates: https://github.com/389ds/389-ds-base/issues/3555

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/dd16813093d0a2cbcb3c64cd72fc6a796a12fe7c">dd168130</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-06-23T10:07:00+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7593 - Reject invalid SASL packet length values in sasl_io_start_packet (#7594)

Description:
While processing SASL encrypted traffic, sasl_io_start_packet() reads a
4-byte length from the connection and adds sizeof(uint32_t) before resizing
the read buffer. Certain large length values can wrap in uint32_t, causing
incorrect buffer sizing when malformed SASL data is received on an
established connection.

Fixes: https://github.com/389ds/389-ds-base/issues/7593

Reviewed by: @tbordaz, @progier389 (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/9652a30ee6905ddcbae8322b779df8e4ed793308">9652a30e</a></strong>
<div>
<span> by tbordaz </span> <i> at 2026-06-23T11:41:01+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7567 - Content Sync plugin unbounded queue growth and race conditions (#7568)

Bug description:
        Main issue is that the queue of each syncrepl persistent search is not limited.
        Also fixing some race condition cases

Fix description:
        Support of two new configuration attributes for the sync repl configuration
        entry (cn=Content Synchronization,cn=plugins,cn=config)
        - syncrepl-max-concurrent (default 10)
          that was previously configured with nsslapd-pluginarg0
        - syncrepl_queue_max-size (default 10000)
          that is the maximum size of the queue of the updated entries
        Also changing the access to 'thread_count' and 'plugin_closing'

fixes: #7567

Assisted by: Cursor

Reviewed by: Simon Pichugin (Thanks !!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/e83bc3fd71de66377a485a942a20a50b7a938f6b">e83bc3fd</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-06-23T15:14:53+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI (#7572)

Description:
dna_interval_test.py failed in teardown with NameError for DSEldif, leaving
standalone1 stopped and causing later tests in the module to fail with
SERVER_DOWN. Add pause replication around accpol_test restarts to avoid
release_replica timeouts, and acknowledge endReplication on the consumer
when no session is active.

Fixes: https://github.com/389ds/389-ds-base/issues/7530

Reviewed by: @droideck, @tbordaz, @progier389 (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/fc0d28173e3d2b865dd3527bfeed3484c6b26a3a">fc0d2817</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-06-24T16:12:43+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7583 - Compressed logs are prematurely deleted (#7584)

Bug Description:
When log compression is enabled and the full path to a rotated
compressed log file exceeds 75 characters, the server fails to read the
actual compressed file size and falls back to the uncompressed
maxlogsize value 100 MB. This causes the maxdiskspace deletion check to
use incorrect sizes, triggering log deletion before the configured disk
space limit is reached.

Fix Description:
Use `sizeof(logfile)` instead of `sizeof(tbuf)` to construct the
compressed filename.

Fixes: https://github.com/389ds/389-ds-base/issues/7583

Reviewed by: @progier389, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/58e126ec91745fe62957e280d1284290f2d76d53">58e126ec</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-06-25T10:45:21+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7593 - Fix testimony docstring for SASL overflow test (#7606)

Description:
The test added in #7594 failed testimony validation because the docstring
summary was not separated from the metadata fields with a blank line.

Relates: https://github.com/389ds/389-ds-base/issues/7593

Reviewed by: @progier389 (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/40e8c13a8eb6714d4ee938f8f497eab5b8660c63">40e8c13a</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-06-25T10:53:50+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7537 - CI - Fix replication log monitoring parser/timing failures (#7592)

Description:
During repl total init on LMDB, a duplicate suffix DN was mishandled and
could trigger DNRC_NOPARENT_DN, aborting bulk import and crashing the joining
supplier.

Fix:
Treat repeat suffix entries as DNRC_BAD_SUFFIX_ID and skip that case.
Add a case for DNRC_NOPARENT_DN in dbmdb_bulk_producer, instead of
defaulting to abort and generating a coredump.

Fixes: https://github.com/389ds/389-ds-base/issues/7537

Reviewed by: @droideck (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/13023a2ad2431558857b42f07cd2a8a670ff0cad">13023a2a</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-06-25T16:24:39+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7147 - entrycache_eviction_test CI test is failing (#7607)

* Issue 7147 - entrycache_eviction_test CI test is failing

Fix entry cache LRU list corruption by preventing pinned_add to add the entry in the LRU if it is already there

Issue: #7147

Reviewed by: @tbordaz (Thanks!)

Assisted by: Claude Ai</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/575ca72cf944ce812514b54b1cbcfb661e5e3c66">575ca72c</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-06-29T17:21:49+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7380 - Automated test for negative wtime (#7616)

Description:
Adding automated test to check access log does not contain negative wtime values when retrochangelog plugin is enabled.

Relates: #7380
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4b7fec95f9b2191a1c2c0c1667fefcb3dbd1965a">4b7fec95</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-06-29T17:11:04-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7602 - CI - lib389 user compare fails due to parentid mismatch (#7603)

Description: Fix UserAccount.compare() failures between replicated entries
where backend-local parentid values differ across suppliers. Treat parentid
like entryid by excluding it from generic DSLdapObject compare attributes,
since it is an internal database operational attribute generated per
instance. Add regression coverage to ensure replicated user comparison does
not include parentid.

Fixes: https://github.com/389ds/389-ds-base/issues/7602

Reviewed by: progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/835ed49647b828d9a15afe296b338ecc7ecc54c9">835ed496</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-07-02T16:40:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7617 - Fix wrong PR_ASSERT about entry cache (#7618)

Fix crash in debug build.

Issue: #7617

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/74a782c3a60522567184fc37e768f25a905a7d06">74a782c3</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-07-02T23:08:14-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7529 - Fix WebUI local policy availability test (#7609)

Description: Update the local password policy WebUI test to match the
current table and modal workflow. Check empty and populated table states,
open the Create New Local Policy modal, and verify the edit action only
when editable policies are present.

Fixes: https://github.com/389ds/389-ds-base/issues/7529

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/dd63a5891cfa8bf2d4467fa5937df0a1d88bf122">dd63a589</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-07-03T17:05:49+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7610 - Still some lib389.topologies in CI tests (#7612)

* Issue 7610 - Still some lib389.topologies in CI tests

Some CI tests still import lib389.topologies instead of test389.topologies

Issue: #7610

Reviewed by: @mreynolds389, @vashirov (Thanks!)

Co-authored-by: Viktor Ashirov <vashirov@redhat.com>

---------

Co-authored-by: Viktor Ashirov <vashirov@redhat.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/9bd4a1117454344436c472edaffaa46b9b8cafdb">9bd4a111</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-07-03T17:45:53+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7536 - CI - Fix backup_task_after_failure race (#7588)

Avoid the Directory Not Empty exception by ensuring that os.rename target directory is always new

Issue: #7536

Reviewed by: @tbordaz, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/9b46b6cc7362254c3deddee0d2844cf4f1ac6744">9b46b6cc</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-07-05T20:30:15-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7569 - Add CodeQL advanced setup workflow (#7570)

Bug Description:
We have Coverity static analysis but no GitHub-native CodeQL/code
scanning workflow. Adding CodeQL would provide PR-visible security
and quality analysis for C/C++ and Python without relying on Coverity
credentials or external dashboard access.

Fix Description:
Add a focused CodeQL advanced setup workflow for C/C++ and Python.
The workflow follows the existing Fedora/autotools CI pattern, uses manual
build mode for C/C++ analysis, enables the security-and-quality query suite,
uploads useful build/config artifacts, and requires only GitHub code
scanning permissions.

Related: https://github.com/389ds/389-ds-base/issues/7533
Fixes: https://github.com/389ds/389-ds-base/issues/7569

Reviewed by: progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/38d4da2f8902a9d7d1e7121efc63c7c1d301959d">38d4da2f</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-07-06T16:56:49-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7623  - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking

Description:

When password storage scheme is set to CLEAR and you set a password that is
less than 23-bytes then a possible heap overflow is possible.

Replace the unsafe `strcpy` with a bounded copy that respects the available
space in the buffer

Severity: Low (CVSS 3.3)
CWE: CWE-122 (Heap-based Buffer Overflow)

relates: https://github.com/389ds/389-ds-base/issues/7623

Reviewed by: progier(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/5609f0ef9c815c9a9c6ea4618c491b269afad580">5609f0ef</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-07-06T17:04:24-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7621 - Stack Buffer Overflow in Password checkPrefix

Description:

A stack buffer overflow in checkPrefix() function allows a Directory Manager to
crash the LDAP server by storing a reversible-encrypted attribute with an
oversized algorithm ID.

Add a bounds check before the `memcpy` at `pw.c:466` to prevent the overflow.

relates: https://github.com/389ds/389-ds-base/issues/7621

Reviewed by: progier(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/5d575d37c6babcf2d051ecd70764aa98eb168bfc">5d575d37</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-07-07T17:26:30-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7406 - Fix ldap-agent SNMP stats file loading (#7630)

Description: Fix ldap-agent stats file path construction so it opens the
instance .stats file instead of the truncated .stat path.
Move SNMP counter slot allocation after the configured worker thread count
is available so per-thread SNMP counter slots are created.

Add SNMP test that checks bindSecurityErrors updates in cn=snmp,cn=monitor
and verifies ldap-agent loads the instance stats file used for SNMP counters.

Fixes: https://github.com/389ds/389-ds-base/issues/7406

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/95201a81505ca2aec59d442376ad506261a1a4ce">95201a81</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-07-08T14:39:38+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7284 - Automated test for creating local password policy with incorrect passwordInHistory value (#7608)

Description:
Adding automated test for creating local password policy with incorrect passwordInHistory value

Relates: #7284
Author: Lenka Doudova
Assisted by: Cursor
Reviewer: @progier389</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ceca3138147bfaf62f17a630a1d859d303c72539">ceca3138</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-07-09T16:32:21+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7635 - Integer Underflow in {SMD5} Password Comparison (#7636)

Description;
smd5_pw_cmp() does not validate the decoded length of a stored {SMD5} hash
before computing the salt offset and length. Truncated hashes could produce
an incorrect salt length during password comparison.

Fix:
Add a length check in smd5_pwd.c to reject decoded hashes shorter than
MD5_LENGTH. Added CI test for validation.

Fixes: https://github.com/389ds/389-ds-base/issues/7635

Reviewed by: @tbordaz (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/814a5ee208e104217d6178aedc9255b19c22e56b">814a5ee2</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-07-10T18:16:44-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7147 - Fix DN cache ownership during online reindex (#7641)

Description: dncache_find_id() treated any nonzero ep_state as
unavailable. This could hide valid DN cache entries and cause online
reindex/export to recompose a DN, release it after a cache collision,
and use it again.

Treat cached DNs as missing only when they are deleted, incomplete, or invalid.
Valid entries queued in the LRU remain available for lookup.
Give db2index, db2ldif, and upgradedn producers independent DN ownership
after CACHE_RETURN.
Replace stale upgradedn cache entries after conflict renames, release
parent-cache references on hits, and log cache-owned values before
releasing their entries.

In the test, wait for the concurrent reindex task to finish
and require a successful exit code before performing the final checks.

Fixes: https://github.com/389ds/389-ds-base/issues/7147

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/1c26f9551c9aed29ab83ddd91215f22054e152d6">1c26f955</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-07-10T18:17:40-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7558 - Total init sends the suffix entry twice (#7640)

Description: Exclude the suffix entry from the depth-first parentid
walk because total init sends it separately.
Preserve NEW_IDL_NO_ALLID across all parentid fetches and honor it in
the LMDB fetch path to maintain parent-first ordering.
Update LMDB reindex handling so entries with an explicit parentid are
treated as regular entries when their RDN matches the suffix.

Add a regression test with a wide moved subtree that verifies entry order
and ensures the suffix is sent only once.

Fixes: https://github.com/389ds/389-ds-base/issues/7558
Fixes: https://github.com/389ds/389-ds-base/issues/7604

Reviewed by: progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/7af85d5748255b1fd715d7b64fc12aa2e0163a55">7af85d57</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-07-10T20:40:57-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7595 - Reduce Actions queue saturation (#7596)

Description: Limit the pytest matrix workflows with max-parallel so large
runs release jobs in smaller batches while preserving full coverage.

Scope broad push triggers to main and 389-ds-base-* release branches to
avoid duplicate push and pull_request runs for in-repo PR branches. Add
manual dispatch where needed for odd branches.

Also fix the GCC Strict compile matrix name and ignore cache/hidden suite
directories in the pytest matrix generator.

Related: https://github.com/389ds/389-ds-base/issues/7595

Reviewed by: progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/f29e1e6ab75facfdba76d8162d262f1f0aeffaba">f29e1e6a</a></strong>
<div>
<span> by Akshay Adhikari </span> <i> at 2026-07-13T09:23:30-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7535 - Fix race in test_schema_update_policy_reject

Description: Removed temporary_oc2 fixture that added OC2 before
the reject policy was active. Moved OC2 creation after the policy
is set and supplier1 is restarted.

Fixes: #7535

Reviewed by: @droideck, @mreynolds389, @tbordaz (Thanks!)

Assisted by: Claude
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4ce7a49576f84c1d8bcbf8635fdb6d18b31db771">4ce7a495</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-07-13T15:19:41+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7611 - PBKDF2 password verification should reject invalid iteration count (#7613)

Description:
The C PBKDF2 password verification code does not validate the extracted
iteration count before invoking PBKDF2 hash function.

Fix:
Reject hashes whose iteration count is outside the supported range before
before performing password verification.

Fixes: https://github.com/389ds/389-ds-base/issues/7611

Reviewed by: @tbordaz, @progier389 (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/6e1e933745313622593d943e983ff710de8db732">6e1e9337</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-07-13T20:17:23-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7569 - Reduce noisy CodeQL false-positive alerts (#7629)

Description: Add a CodeQL configuration file and wire the
workflow to use it. Keep code scanning security-focused by
switching to the security-extended query suite and ignoring
noisy non-product areas such as dirsrvtests, lib389 tests,
Cockpit node_modules, and vendored dependencies.

Related: https://github.com/389ds/389-ds-base/issues/7569

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b813b5b9aa7a183b347c34dbc4ddabc77d8434e4">b813b5b9</a></strong>
<div>
<span> by IliaKash1 </span> <i> at 2026-07-16T10:50:53+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7545 - Heap buffer overflow in str2entry_state_information_from_type() (#7546)

Bug description:

Heap buffer overflow in str2entry_state_information_from_type() can be triggered with a specific input, since ';' is supposed to precede enough symbols.

Fix description:

Additional strlen() check before accessing specific symbols is added.

Fixes: #7545

Reviewed by: @progier389 (thanks!)

Author: Ilia Kashintsev</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/1253246aa7d10249ac7bd59071591432a442a658">1253246a</a></strong>
<div>
<span> by IliaKash1 </span> <i> at 2026-07-16T10:53:02+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7543 - buffer overflow in slapi_dn_find_parent_ext() (#7544)

Bug description:

Buffer overflow can be triggered in slapi_dn_find_parent_ext() if the input ends with a separator.

Fix description:

Additional check is implemented to prevent the for loop from going to the next iteration when that results in a crash.

Fixes: #7543

Reviewed by: @progier389 (Thanks!)

Author: Ilia Kashintsev</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/6bb1ccc8a48bba049f6cca1058374bf5efd3841b">6bb1ccc8</a></strong>
<div>
<span> by Ilia Kashintsev </span> <i> at 2026-07-16T15:51:48-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7547 - Heap buffer overflow in ldap_utf8prev()

Bug description:

Heap buffer overflow in ldap_utf8prev() can be triggered via str2simple if '=' is not preceded by proper symbols.

Fix description:

Additional checks are added to account for '=' being preceded by nothing
or by non-ASCII bytes.

Fixes: #7547

Author: Ilia Kashintsev

Reviewed by: @progier389 (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/0e3b049653bcc0d9f4deecca5051a10b567f6a4d">0e3b0496</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-07-16T22:59:41-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7611 - Preserve legacy PBKDF2 hash compatibility (#7649)

Description: Use a fixed 50,000-round verification ceiling
so legacy C PBKDF2_SHA256 hashes continue to authenticate across
upgrades and restarts.
Cap generated legacy hashes at the configured ceiling, fall back
safely on invalid configuration, and keep the optional object-class
upgrade non-fatal.
Exercise migration from the legacy underscore scheme to a separately
configured modern PBKDF2-SHA256 scheme at 600,000 rounds, without
changing the legacy verification ceiling.
Keep the regression coverage self-contained and restore modified server state.

Relates: https://github.com/389ds/389-ds-base/issues/7611

Reviewed by: @tbordaz (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/05a17d0c6ca6bf22aab89b560b73d4c366ef2bbc">05a17d0c</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-07-19T22:15:12-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7633 - RFE - Add offline diagnostics for thread pool saturation (#7634)

Description: When the worker pool is fully saturated, cn=monitor cannot be used
for diagnostics because the monitor search itself needs a worker thread.

Add offline thread-pool status reporting by publishing pool gauges and
per-worker activity into a hardened memory-mapped file under the instance run
directory. The new dsctl thread-pool-status command reads this file directly,
without an LDAP connection, so admins can inspect the pool even when worker
threads are exhausted.

cn=monitor also exposes a sanitized threadpoolworker attribute backed by the
same data source. The feature is enabled by default and can be disabled with
the new nsslapd-thread-pool-stats cn=config attribute. Changing this setting
requires a restart.

Fixes: https://github.com/389ds/389-ds-base/issues/7633

Reviewed by: @jchapma, @tbordaz, @mreynolds389 (Thanks!!!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b4c2cc24553ee5a05ac9d5eadc7ba584786b0d23">b4c2cc24</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-07-20T08:40:04+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7327 - Unify topology naming in tests (#7650)

Description:
Unify topology naming in dirsrvtests/tests/suites/memberof_plugin/memberof_include_scopes_test.py so that the used name always reflects topology import in the file.

Relates: #7327
Author: Lenka Doudova
Reviewer: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/1245426598f994d5a2fb8c0283bebc7250d31ee0">12454265</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-07-20T14:25:38+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update Rust crate openssl to v0.10.80 [SECURITY]</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/5f66a03347caed648176e4dbd6f835316f585f71">5f66a033</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-07-21T12:42:25+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update actions/checkout action to v7</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/bd9cae36fbfc77c9f59f30b247872e4f0d457506">bd9cae36</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-07-22T09:53:06+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Pin dependencies

Modify renovate config to ignore image dependencies
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/990fad42d77ce2db32030950f68a88cb4558d998">990fad42</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-07-22T14:06:40+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update rust-dependencies (#7472)

Update rust-dependencies

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Lenka Doudova <mirielka@users.noreply.github.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/8ce124e7bd7b526eae6aef45eec9f8d8941b8ad6">8ce124e7</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-07-23T09:58:40+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7200 - repl-agmt create doesn't set some parameters (#7663)

Bug Description:
The `add_agmt()` function in the dsconf CLI silently ignored flow
and timeout parameters:
  --conn-timeout
  --protocol-timeout
  --wait-async-results
  --busy-wait-time
  --session-pause-time
  --flow-control-window
  --flow-control-pause
The CLI args and attribute mappings existed, but the properties dict was
never populated with these values during agreement creation.

Fix Description:
Add the missing args-to-properties assignments.

Fixes: https://github.com/389ds/389-ds-base/issues/7200

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/773f7c7e5794010b54305ff819c69ffb48a6f75b">773f7c7e</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-07-27T09:58:51+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value (#7662)

Description:
Creating a local password policy accepts invalid passwordrInHistory values.
Updating an existing policy via dsconf localpwp set correctly rejects the
same values with Constraint violation.

Fine grained password policy validation ran only on the modify path. Local
policy create uses the add path, which wasnt updated, so invalid values were
accepted.

Fix:
Add fine grained password policy attribute validation to the ADD path,
sharing the same checks used by MODIFY.

Fixes: https://github.com/389ds/389-ds-base/issues/7284

Reviewed by: @mreynolds389  (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/de1656410a7edd63823b212a6e7cc72adf046851">de165641</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-07-28T15:44:31+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7652 - change bind result with password but no dn (#7653)

Reject bind operation with password and no dn whose behavior is not defined in RFC 4513

Issue: #7652

Reviewed by: @tbordaz , @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/1a48ac3d5185c1d6f5915548571239109d476dae">1a48ac3d</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-07-28T19:58:46-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7670 - BDB range searches intermittently fail with err=1 under write load (#7671)

Description: Since #7125 index cursor walks run inside DB_TXN_NOWAIT transactions,
so under concurrent write load a range scan such as SSSD's "(entryUSN>=N)"
fails immediately with DB_LOCK_DEADLOCK, surfaced as DBI_RC_RETRY (-12795).
The equality lookup path retries since #7126, but the range path did not:
every conflict failed the whole search with err=1 and flooded the errors
log.

Retry the range fetch with the same bounded exponential backoff as the
equality path, skipping the retry in both paths when the fetch runs inside
a caller transaction that must be retried as a whole.
Log transient attempts at debug level and emit a single ERR line only when
the retry budget is exhausted and the search really fails.
Also document why serializable cursor isolation must not be weakened,
fix a NULL dereference on the idl_lmdb_range_fetch error path,
add the missing backoff to the old-idl and ldbm_back_seq loops, and
add a stress suite reproducing the entryusn workload.

Fixes: https://github.com/389ds/389-ds-base/issues/7670
Relates: #7124 #7126 #7462

Reviewed by: @vashirov, @progier389, @tbordaz (Thanks!!!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/0c03102c4b65a9e49d0806b1353efc0b578c3720">0c03102c</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-07-29T15:33:58+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7675 - memory leak in test_libslapd_csngen_clock_failure- #7676 #7676

Description:
The csn_free() calls were missing in error handling paths within the CSN unit test code.
This leak only occurs when running the test suite with ASAN, it does not affect production.

Fix:
Free csn if allocated on error path

Fixes: https://github.com/389ds/389-ds-base/issues/7675

Reviewed by: @tbordaz, @progier389 (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/55470d38349d1607af0fdb48b1b38d40109f37d4">55470d38</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-07-31T07:36:23+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update github/codeql-action digest to f205ea1</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/9e6d975d3c04243f279794cbdcebc46ebfb3448c">9e6d975d</a></strong>
<div>
<span> by Lenka Doudova </span> <i> at 2026-07-31T08:58:22+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7652 - Fix acl_test after fixing anonymous bind with password (#7678)

Description:
Fixing acl test after bind result with NULL dn and non NULL password behavior was changed.
The test now also sets password to NULL in order to perform its actions as intended.

Relates: #7652
Author: Lenka Doudova
Reviewer: @droideck (Thanks!!!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/3e4308488fc4223b455089124a1db38ded0c993b">3e430848</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-07-31T09:50:57-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7505 - RFE - CLI - add feature to determine which password policy applies to a user

Description:

Update CLI where you can enter a user's DN and find out what password policies
are apply to them (global or local) and the policy settings.

Design doc:

https://www.port389.org/docs/389ds/design/dsidm-user-get-pwp-design.html

Relates: https://github.com/389ds/389-ds-base/issues/7505

co-authored-by: Cursor

Reviewed by: progier & spichugi(Thanks!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b9075f942b5b0d48bb5abca0135211e73d8f60fe">b9075f94</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-07-31T21:06:38+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update rust-dependencies (#7669)

* Update rust-dependencies

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Lenka Doudova <mirielka@users.noreply.github.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a0d7251e9ad61999142b6465508a50c9224b021e">a0d7251e</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-08-03T19:12:13+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update rust-dependencies</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/9361a3acc4380d6ea2b3d41f3a795fb79e2e7610">9361a3ac</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-08-03T19:12:13+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Migrate pwdchan to base64 0.23 Engine API
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/00c4bb8ac6181b1240de2264f5fe91e75a4115d6">00c4bb8a</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-08-04T17:32:01-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7466 - UI - Refactor all TextInput number types to NumberInput

Description:

TextInput "number" types allow for invalid values, while NumberInput
has built-in functionality to prevent this.

relates: https://github.com/389ds/389-ds-base/issues/7466

Assisted-by: Cursor

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/417f3eeb73ad7d03903b1e78f11ad2807305d7ee">417f3eeb</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-08-05T18:53:34+05:30 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update cockpit-389-ds-npm (#7565)

* Update cockpit-389-ds-npm and fix npm audit vulnerabilities

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Akshay Adhikari <aadhikar@redhat.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/2d36969d0af2da12c2e262611d6619d6abb4ac6d">2d36969d</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-08-05T16:28:03+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>re-add python3-setuptools to build-deps
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a67a308a9d2d2dee4aaf287c6cfe6c5c725be88b">a67a308a</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-08-05T16:30:00+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Merge tag '389-ds-base-3.1.4' into m
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/f40b349a7771ae12e2dfb23d647e975c8e9d53b8">f40b349a</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-08-05T16:30:28+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Merge branch 'master' into m
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/7ec8b1d9e681c3d4033b90340f3fccb8b590832c">7ec8b1d9</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-08-05T16:35:05+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>version bump
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/7120521cb1159ea1adfeadef011e398c6f5f73e0">7120521c</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-08-05T16:36:05+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>drop more upstreamed patches
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/9756ffbf21e69faf3baf817308575d1212810afa">9756ffbf</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-08-05T16:43:50+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>delete agent symlinks, breaks building the source
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4cfb6da9fb93d4d684bb845b4dd7a27f89eea0d6">4cfb6da9</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-08-05T16:52:54+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>fix-nss-include.diff: Dropped, obsolete.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/40659fad241dc89d44cdbda0e92454e2414579a5">40659fad</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-08-05T16:53:45+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>releasing package 389-ds-base version 3.3.0-1
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a9c87e76a48c838a456cd38004efcacf3f3aa815">a9c87e76</a></strong>
<div>
<span> by Luca Boccassi </span> <i> at 2026-08-05T17:17:51+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Stop deleting system user on remove/purge

This is widely considered bad practice, as the kernel recycles
UIDs/GIDs. So any potential leftover file/directory can then become
owned by the next user/group that gets added, with unpredictable
consequences.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/f7fd9cd641e765ea0f6be767bde0f9848983b2e6">f7fd9cd6</a></strong>
<div>
<span> by Luca Boccassi </span> <i> at 2026-08-05T17:18:04+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Install and use sysusers.d/tmpfiles.d config files

sysusers.d/tmpfiles.d config files allow a package to use declarative
configuration instead of manually written maintainer scripts. This also
allows image-based systems to be created with /usr/ only, and also
allows for factory resetting a system and recreating /etc/ on boot.

https://www.freedesktop.org/software/systemd/man/latest/sysusers.d.html
https://www.freedesktop.org/software/systemd/man/latest/tmpfiles.d.html
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4fed11224ced9cae9dfcdf62e91330d1808733f3">4fed1122</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-08-05T17:18:35+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>releasing package 389-ds-base version 3.3.0-2
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/bdfceb57f593e963b6fc2b9e63646e6d2f8d46a4">bdfceb57</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-08-10T10:22:59+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Backport Issue 7519 — ignore obsolete entrydn when entryrdn is in use (#7657)

Description:
Upgraded instances can retain leftover cn=entrydn while entryrdn is in use,
causing bad searches and reindex failures. Fixed on 2.8 by 539cad4 (#7519/#7526).
This adapts that fix for branches where nsslapd-subtree-rename-switch
was removed (Issue #6639).

Fix:
Always ignore leftover entrydn by index name, skip reindex and add
healthcheck DSBLE0008 + CI test.

Relates: https://github.com/389ds/389-ds-base/issues/7519
Fixes: https://github.com/389ds/389-ds-base/issues/7654

Reviewed by: @droideck (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/074c03b07eec6d36d22da4ff2ebb95036ff102c4">074c03b0</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-08-10T15:05:49-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7528 - Retry the CI image pull instead of failing the job (#7691)

Bug Description: Test jobs die before pytest starts when the implicit
image pull of the bare 'docker run quay.io/389ds/ci-images:test' hits
a transient quay.io timeout (exit 125).

Fix Description: Pull the image explicitly before docker run, retrying
up to 5 times with increasing backoff, and fail the step only after
the last attempt. This covers a transient timeout, not a longer
registry outage.

Fixes: https://github.com/389ds/389-ds-base/issues/7528

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/81417b0e1c10dbe8010889435d12a754a655e039">81417b0e</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-08-10T16:39:32-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7605 - Harden CI test ports against ephemeral allocation (#7692)

Bug Description: Test jobs sometimes fail at topology setup because
ns-slapd can't bind one of the fixed lib389 test ports (38902, 39002, 39004,
39202 seen): PR_Bind returns EADDRINUSE and the whole module errors out.
Those ports are inside the kernel's default ephemeral range (32768-60999),
while the secure ports at 636xx sit outside it and have never failed,
so an outgoing connection briefly grabbing a test port is the likely cause.

Fix Description: Pass --sysctl net.ipv4.ip_local_reserved_ports=38900-39399
to the test container, covering all four lib389 role ranges. Reserved ports are
skipped when the kernel picks a source port but can still be bound explicitly,
so the listeners are unaffected.

Fixes: https://github.com/389ds/389-ds-base/issues/7605

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/77fb31d70b1752a96cf3a1812064879c59ece78d">77fb31d7</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-08-11T13:01:46+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7468 - RFE - HIBP password breach validation (#7492)

Description:
Integrate the HIBP HTTP client into password policy. Adds config,
schema, and password validation logic to check passwords against
the HIBP breach database during password add and modify operations.
Depends on the HIBP client PR.
- Schema: passwordBreachCheck, passwordBreachDbUrl, passwordBreachDbTimeout
- Config: Config setters in libglobs.c
- Validation: Check passwords on add/modify for both admin and non-admin users
- rootDN: Also validates nsslapd-rootpw changes against breach database

Dependencies:
- Issue 7468 - RFE - Add HIBP HTTP client

Relates: https://github.com/389ds/389-ds-base/issues/7468

Reviewed by: @mreynolds389, @droideck (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/3d7b599ca7ee06302eedc53e23129a861719bb9c">3d7b599c</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-08-11T12:25:16-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7578 - schema - attribute refcount is not maintained properly

Description:

The refcount mechanism for attributes is not correctly used, and this prevents
its use for synchronizing hashtable access. We increment the refcount, but we
don't decrement it correctly. This can potentially cause a rare race condition
with schema reload task and heap-use-after-free with searches running at the
same time as the reload task.

**CWE**: CWE-416 (Use After Free) via CWE-362 (Race Condition)

CI test assisted by: Cursor

relates: https://github.com/389ds/389-ds-base/issues/7578

Reviewed by: progier, tbordaz, and spichugi(Thanks!!!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b9b8c4f3cb381937ce41a8fdcaf56a7f46d58adc">b9b8c4f3</a></strong>
<div>
<span> by Firstyear </span> <i> at 2026-08-12T12:56:42+10:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7685 - BUG - Avoid ioblocktimeout (#7687)

Bug Description: In some cases, the fd will trigger on poll which causes it to
move to the active list. This then leads to connection_read_operation attempting
a PR_Poll and then assuming that the ioblock might be occuring even if no data
was actually received.

Fix Description: Instead of calling a second PR_Poll with the ioblocktimeout
immediately, if we are a new operation and there is no buffered data available
then we immediately shortcut out to prevent the extra delay.

fixes: https://github.com/389ds/389-ds-base/issues/7685

Author: William Brown <william@blackhats.net.au>

Review by: @progier389  </pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/aa377a647d17caab64316abd570a8def60769dc1">aa377a64</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-08-13T09:38:49-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7637 - UI - Using Arrow Keys in New Object Wizard Resulted in DOM Reload

Description:

When creating a new entry, or adding COS, the arrow keys did not work properly
because the component would reload/remount and it would lose focus on the radio
button group making it impossible to use the arrow keys to select different
radio buttons.

The radios are controlled via isChecked={selected === '...'}, so React only
shows a selection when state changes. Arrow keys moved focus in the DOM, but
PatternFly’s onChange doesn’t run for keyboard navigation.

We need to revise how the state is ahndled to keep focus on the button group.

Assisted-by: Cursor

relates: https://github.com/389ds/389-ds-base/issues/7637

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/46ad803595ea1d9d09f5f7c2b7e9a757e8a182fa">46ad8035</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-08-13T10:50:16-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7710 - MemberOf deferred update - Use condvar instead of sleep loop

Description:

Currently we use a while/sleep loop to check if a deferred update is complete.
Better to use a condition variable instead.

Deferred updates also needs to skip special backends:

- cn=config
- cn=schema
- cn=changelog

relates: https://github.com/389ds/389-ds-base/issues/7710

Assisted-by: Cursor

Reviewed by: tbordaz(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/7046a144c6834110e9079479b1cc5fe409de72c4">7046a144</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-08-13T12:52:54-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND

Description:

In sasl_io.c, function sasl_io_recv(), when sasl_io_start_packet() returns
SASL_IO_BUFFER_NOT_ENCRYPTED (triggered by sending an unencrypted LDAP UNBIND
after SASL layer setup) there is no check that

sp->encrypted_buffer_count <= len before the memcpy

relates: https://github.com/389ds/389-ds-base/issues/7658

Reviewed by: jchapman & spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/710e6a20d8a4d0d1928c6a90fa48c9c6e1683ada">710e6a20</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-08-14T11:20:43-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7714 - UI - sass import rules are deprecated

Description:

Sass no longer supports @import, and we need to use "@use" or "@forward"

relates: https://github.com/389ds/389-ds-base/issues/7714

Reviewed by: jchapman(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/571fa959c4c151cac52048352ffcc29d5f591e96">571fa959</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-08-14T12:03:17-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7709 - Add EPEL 10 target to Packit COPR builds

Description:

Add epel-10 to Packit copr build targets, and bundle libdb
tarball unconditionally

relates: https://github.com/389ds/389-ds-base/issues/7709

Co-authored-by: vashirov

Reviewed by: vashirov & mreynolds
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ad3d8dad8071b54cc2a3f8304f3e18e18d7c48b6">ad3d8dad</a></strong>
<div>
<span> by Barbora Simonova </span> <i> at 2026-08-14T20:26:22+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7273 - In a chaining environment binding as remote user causes an invalid error in the logs

Description:
Add a CI test to check binding as remote user
in a chaining environment does not log a warning message

Relates: https://github.com/389ds/389-ds-base/issues/7273

Assisted by: Cursor

Reviewed by: @progier389 (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/8b8fb27f3d6d48dd56162ebcd4834375f8ee0452">8b8fb27f</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-08-17T10:15:12+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7645 - Add runtime LeakSanitizer leak check (#7646)

Description:
If the server is built with ASAN or LD_PRELOADed with libasan,
a recoverable leak check can be triggered at runtime by sending
SIGUSR1 to ns-slapd.
Before calling LeakSanitizer, a fork+ptrace probe verifies that ptrace
is permitted. Without this check, LeakSanitizer calls exit(1) when
ptrace is denied by SELinux or suid_dumpable restrictions.

Fixes: https://github.com/389ds/389-ds-base/issues/7645

Reviewed by: @progier389, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a23cd2dc1e906b06ef87938e3175039852f937aa">a23cd2dc</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-08-17T10:23:21+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7666 - Replication performance degradation during total init on high-latency storage (#7667)

Bug Description:
During replication total init the consumer's LMDB writer thread commits
transactions with fsync on each commit. This causes progressive
performance degradation as the database grows. This is especially
noticeable on network-attached storage, for example AWS EBS, where fsync
latency is high and grows under sustained write load.

The offline LDIF import sets MDB_NOSYNC on the LMDB environment during
import, which skips per-commit fsync, and only flushes at the end via
mdb_env_sync. But the online total init doesn't do that.

Additionally, the nsslapd-db-durable-transactions config parameter was
not honored by the LMDB backend (only BDB checked it).

Fix Description:
- Add nsslapd-mdb-online-import-nosync config parameter (default: off)
  that sets MDB_NOSYNC on the LMDB environment during online import, same
  as offline LDIF import. The final mdb_env_sync() in the writer thread
  ensures all data is flushed when import completes.

- Honor nsslapd-db-durable-transactions for the LMDB backend by
  setting MDB_NOSYNC when the environment is opened if this parameter
  is set to off. Previously this config was only effective for BDB.

Fixes: https://github.com/389ds/389-ds-base/issues/7666

Reviewed by: @progier389, @jchapma, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/8d994c0bfc1012aea39fc4831e90cb0a07b14e0b">8d994c0b</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-08-17T11:52:46+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7709 - Add EPEL 10 target to Packit COPR builds (#7721)

Bug Description:
Build fails when libdb tarball is missing, it's only downloaded when
BUNDLE_LIBDB=1 is used.

Fix Description:
Make libdb tarball download and copy unconditional in rpm.mk.
Replace epel-10 with epel-10-all to cover latest and branched releases.
Add `preserve_project: true` to keep copr available more than 60 days.

Fixes: https://github.com/389ds/389-ds-base/issues/7709

Reviewed by: @mirielka (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/90d412178384d946accee8218c327277a57e0ac4">90d41217</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-08-17T12:53:21+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update github-actions</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/348671271aa08ac56da842a284c893292a911102">34867127</a></strong>
<div>
<span> by Akshay Sakure </span> <i> at 2026-08-17T12:55:45-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6419 - Error: name 'cockpit_present' is not defined (#7719)

Description:
PR #5615 removed cockpit enable check for cockpit package
but open-firewall, close-firewall, and disable still called it,
causing NameError. Drop those leftover checks as well so
dsctl cockpit commands work again.

Fixes: https://github.com/389ds/389-ds-base/issues/6419

Signed-off-by: Akshay Sakure <asakure@redhat.com>

Reviewed by: mreynolds</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/380dd695972303a0dceb056faab67bab97809a4e">380dd695</a></strong>
<div>
<span> by Akshay Sakure </span> <i> at 2026-08-17T12:56:44-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7711 - Fix typo in accountpolicy --login-history-size help text (#7713)

Description: This patch corrects the typo in help text for
--login-history-size argument in the Account Policy plugin CLI.
It currently references lastLoginHistSize, which is not a valid
attribute name. The correct attribute name is lastLoginHistorySize.
It also removes an extra stray closing parenthesis in the same string.

Fixes: https://github.com/389ds/389-ds-base/issues/7711

Signed-off-by: Akshay Sakure <asakure@redhat.com>

Reviewed by: mreynolds</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/48f1c2adcf67d2fd92925113076daba061061d25">48f1c2ad</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-08-17T17:20:59-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7698 - Fix silent entry loss in LMDB bulk import waiter handling (#7699)

Bug Description: During an online total init the LMDB bulk producer parks
an entry processed before its parent on waitingq. A tombstone waits on
its parent's nsuniqueid, but the release loop only matched the parent's ndn,
so such a tombstone was never released and was freed silently at producer exit:
the init reported success while the entry was missing on the consumer.

Fix Description: Release waiters by the processed entry's nsuniqueid too,
using the same guard and key format as the private-db registration in
dbmdb_import_entry_info_by_param(), so a parked tombstone is recognized
when its parent is processed.
On a clean producer exit with a non-empty waitingq, log a bounded sample
of the stranded DNs with a total count and abort, so the loss is visible
instead of silent.
Also fix a pre-existing leak of a released waiter's key buffer.
The regression test drives the total update extended operations directly,
which is the only way to control the nsuniqueid that a plain add discards.

Relates: https://github.com/389ds/389-ds-base/issues/7698

Reviewed by: @progier389, @tbordaz (Thanks!!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/eec156188e9ac0803542d2e7d696ef88611f24df">eec15618</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-08-17T17:43:31-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7705 - With memberOfEntryScope set, deferred memberOf skips MODIFY operations (#7706)

Description: deferred_mod_func checks the entry scope against a pre-op entry
it never reads from the task pblock. With memberOfEntryScope set the check
always fails, so the memberOf fanout of every grouping attribute MODIFY
is silently skipped, for direct and replicated operations alike.
Possibly, a regression from the issue 7035 scoping refactor.

Read the post-op entry the way the direct modify path does, and add
a regression test.

Fixes: https://github.com/389ds/389-ds-base/issues/7705

Reviewed by: @tbordaz (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/3ed5b4077728c071e28180fb956cb3bc70d6634a">3ed5b407</a></strong>
<div>
<span> by Firstyear </span> <i> at 2026-08-18T15:14:11+10:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7688 - BUG - partial address leak in sso token (#7689)

Bug Description: A pointer was incorrectly passed to ber_printf rather
than a ber_int_t

Fix Description: Use the direct rc value without a pointer

fixes: https://github.com/389ds/389-ds-base/issues/7688

Author: William Brown <william@blackhats.net.au>

Review by: ???</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/30fcdc399877f3475e647a945a8c9ba4d3b61b79">30fcdc39</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-08-18T20:05:29-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7679 - Add layered agent docs, task skills, and guides (#7686)

Description: Introduce a layered contributor workflow for coding agents.
Keep repository-wide invariants and navigation in AGENTS.md, place detailed
area-specific guidance under docs/agents/, and add task-focused recipes under
.agents/skills/. Expose the skills to Claude Code, route Cursor through the
same guidance, and add scoped AGENTS.md files for major source areas.

Route verification through environment-provided build and test skills so
agents do not run 389 Directory Server builds in unsupported or unprepared
environments.

Modernize dirsrvtests/create_test.py to emit the standard test preamble,
delegate cleanup and timeout handling to create_topology(request=request),
and resolve the test tree relative to the script so UUID checks work from
any directory.

Relates: https://github.com/389ds/389-ds-base/issues/7679

Assisted by: Claude
Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/fb58b11665b9cf12ff1ec815f948fddb858b450f">fb58b116</a></strong>
<div>
<span> by Masahiro Matsuya </span> <i> at 2026-08-19T10:31:10+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() in join_supplier/hub/consumer (#7708)

Bug Description:
join_supplier(), join_hub(), and join_consumer() set nsDS5ReplicaBindDNGroup
on the consumer after calling ensure_agreement(). The supplier's replication
thread starts immediately when the agreement is created and may send a
startReplication request before the bind DN group is configured, causing
check_replica_auth() to reject it with LDAP_INSUFFICIENT_ACCESS and entering
a permanent 'requires administrator action' state with no retry.

Fix Description:
Move nsDS5ReplicaBindDNGroup before ensure_agreement() in all three call sites
and add an explanatory comment to prevent future regressions.

Fixes: https://github.com/389ds/389-ds-base/issues/7707

Author: Masahiro Matsuya <mmatsuya@redhat.com>

Reviewed by: @tbordaz, @mreynolds389

Signed-off-by: Masahiro Matsuya <mmatsuya@redhat.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4dab7ff649dae5599aa9fcde468774335c87d202">4dab7ff6</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-08-20T08:37:25+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 3555 - UI - Fix audit issue with npm - fast-uri, js-yaml, nanoid (#7700)

Description: Run npm audit fix to address the vulnerability
in fast-uri, js-yaml, nanoid.

Relates: https://github.com/389ds/389-ds-base/issues/3555

Reviewed by: @mirielka</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/e4d6eec8f47ef07a7e8dfad432fc7681642dddd8">e4d6eec8</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-08-20T15:00:42+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update rust-dependencies</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/552118173568257d3722498b8a329ba13a84816d">55211817</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-08-20T15:45:55+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict (#7734)

tombstone_to_conflict tries to retrieve "nsuiqueid" instead of "nsuniqueid"
So there is a risk that the internal modify get applied on a wrong entry (because nscpdn is used instead of uuid)
Note as it impacts the tombstone/conflict entry handling, (which are usually hidden) there are fair chance that the issue never got noticed

Issue: #7733

Reviewed by: @mreynolds389</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/986ff15bb6afa12579f49171d5e2ceaa548d6b79">986ff15b</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-08-20T11:06:19-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7735 - Heap overflow when parsing objectclass superior (#7736)

Description:

When adding/parsing an objectclass the superior or parent objectclass is not
properly calculated into the buffer size and can lead to a buffer overflow if
the superior value is too large.

Relates: https://github.com/389ds/389-ds-base/issues/7735

Reviewed by: progier, spichugi, mirielka(Thanks!!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b64b940918da24cdd3d48d09f2bdc2e320b089c7">b64b9409</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-08-20T09:01:26-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7631 - Don't install bpftrace by default (#7726)

Description: bpftrace is needed only for debugging, it doesn't need to be
installed on every production system.
It also pulls in a compiler which is also prohibited on most production systems.
Use Suggests instead of Recommend.

Fixes: https://github.com/389ds/389-ds-base/issues/7631

Reviewed by: @mreynolds389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4731986532fde46136f60dc1356ad77a67adb73c">47319865</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-08-20T13:59:39-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7595 - Skip redundant CI runs to relieve the Actions queue (#7717)

Description:
The org's free plan allows 20 concurrent Actions jobs, while each
push/PR event schedules ~222 (111 suites x 2 backends). Full runs take
40+ hours; backport sweeps take days. Remove the runs whose result is
already known:

- Drop push triggers from the test workflows: backports already pass
  full PR CI. A nightly dispatcher instead runs each release branch
  (X.Y and X.Y.Z) that changed in the last 30 days, once per head
  commit. (Push runs use the workflow on the pushed ref, so this needs
  backporting to active branches to fully take effect.)
- Skip main's nightly when HEAD already passed the previous one.
- Ignore doc-only paths (markdown, docs/agents, docs/design, LICENSE,
  .packit.yaml) in the test and CodeQL workflows. docs/slapi.doxy.in
  and the doxygen assets stay CI-visible because make all consumes
  them.
- Run only the webui suite for PRs that touch nothing outside
  src/cockpit/389-console; renamed files count both their old and new
  path.
- Fix the pytest_tests default: "false" made bare manual dispatches
  run an empty matrix. The dispatcher also passes explicit empty
  inputs so older branch workflows run in full.

Gates fail open, including on gate job failure, and there are no
required status checks, so skipped workflows cannot block merges.

Relates: https://github.com/389ds/389-ds-base/issues/7595

Assisted by: Claude
Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/afcba8d33bd19d8e965ef78b06f7bd691626a725">afcba8d3</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-08-20T17:18:25-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7639 - Move log compression outside of global write lock

Description:

Add a dedicated log maintenance worker thread that compresses rotated log
archives and runs retention cleanup outside the per-stream write locks.
During rotation, compress jobs are staged on a per-stream pending list
under the write lock and moved to a global FIFO when the lock is released,
so gzip work no longer blocks active log writes.

Update logging_compression_test.py for background compression and add
async_log_compress_chain_uaf_test.py to exercise rapid rotation, logdir
changes, and empty-.gz regression coverage. Drain maintenance jobs during
server shutdown before final log flush.

Design doc: https://www.port389.org/docs/389ds/design/log-async-compress-delete-design.html

relates: https://github.com/389ds/389-ds-base/issues/7639

Co-authored-by: Cursor

Reviewed by: spichugi(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b23597b7219e994ab04dd89873f6a421ee922646">b23597b7</a></strong>
<div>
<span> by apeddire-wq </span> <i> at 2026-08-21T15:34:23+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7728 - bdb: Fix nsslapd-db-compactdb-interval: 0 not disabling auto compaction

* bdb: Fix nsslapd-db-compactdb-interval: 0 not disabling auto compaction

  Setting nsslapd-db-compactdb-interval to 0 is documented to disable
  automatic database compaction, but bdb_checkpoint_threadmain() and
  bdb_compact() never check for interval == 0 before scheduling or
  running compaction. This causes auto-compaction to keep running once
  a day, and nsslapd-db-compactdb-starttime to keep drifting on every
  restart, even when the admin has disabled the feature.

  Added two regression tests covering the startup race and the
  already-queued-event race.

  Fixes #7728

* Address review feedback: lower log level, speed up tests

  - Lower the disabled-compaction log message in bdb_compact() from
    NOTICE to DEBUG, since it fires during expected admin behavior
    (intentionally disabling auto-compaction), not an error condition.

  - Replace long blind time.sleep() calls in the new regression tests
    with short polling helpers that fail fast as soon as an unexpected
    log line appears, instead of waiting out the full duration before
    checking. Also shrink the compactdb-time offsets from 90s/60s down
    to 15s, since the checkpoint thread re-evaluates scheduling every
    ~2.5s (DBLAYER_SLEEP_INTERVAL * 10) regardless of any configured
    interval, so the original margins were far more conservative than
    necessary.

---------

Co-authored-by: Abhinay Reddy Peddireddy <apeddire-wq@users.noreply.github.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/c96ab1106ca669ee39c3720d8bd051a214c25097">c96ab110</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-08-21T11:16:43-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7723 - Range search returns an empty result when its start key is removed (#7724)

Bug Description: idl_new_range_fetch positions on its start key with an
exact match. A concurrent modify can delete that key, so the walk fails
with DBI_RC_NOTFOUND, logs "Error is -12797", and the search silently
returns an empty result.

Fix Description: When the exact match misses, seek to the nearest key
on the same cursor and transaction and resume the walk there. Fix
strict '>' dropping its first candidate when the bound key is absent,
at the initial seek and in index_range_next_key's deleted-key fallback.
Extend the stress suite with a stale start key test, assert -12797 and
impossible empty results never appear, and count rare, logged retry
exhaustion as load shedding.

Fixes: https://github.com/389ds/389-ds-base/issues/7723
Relates: https://github.com/389ds/389-ds-base/issues/7670

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/70dcccafacc672a1add2fdd34388f84c5f42188d">70dcccaf</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-08-22T07:11:34+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update cockpit-389-ds-npm</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/2b00aac580f2a7330609d2ad539ca94f92552b43">2b00aac5</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-08-24T07:21:59+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update github/codeql-action digest to db488dd</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/847025a75be3792f40209ce6159bdba6fc541f52">847025a7</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-08-24T12:15:36+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 4701 - Fix UAF when excluding attrs from retro changelog (#7730)

Description:
When exclude attributes are configured for the retro changelog plugin,
add and delete operations remove the excluded attributes from the
operation entry. This deletes an entry still in use and could cause a
use after free when slapi_entry2str() walks the entry attribute list.

Fix:
Add slapi_entry2str_exclude_attrs() to filter out excluded attributes at
serialisation time, without modifying the entry.

Fixes: https://github.com/389ds/389-ds-base/issues/4701

Reviewed by: @mreynolds389 (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/02d7941adaa9359871a93004703239558647c84c">02d7941a</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-08-24T15:21:33+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7764 - Remove stale Cargo.lock (#7765)

Bug Description:
`src/librslapd/Cargo.lock` is a stale per-crate lock file left over
before the workspace-level src/Cargo.lock was introduced.

Fix Description:
Delete `src/librslapd/Cargo.lock` and update `Makefile.am`.

Fixes: https://github.com/389ds/389-ds-base/issues/7764

Reviewed by: @mirielka (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/9cc69f2f1e6cc555f22578d400218802f0c6bfb4">9cc69f2f</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-08-24T18:05:09+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update rust-dependencies to v1.4.4</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/45f8b23c44f0d8d95c33d1537e2df9a9fb08cd3f">45f8b23c</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-08-24T16:12:01-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7760 - CI - harden dsconf_task_test.py

Description:

Tasks were finishing too fast. Increase the workload so the tasks run longer

Relates: https://github.com/389ds/389-ds-base/issues/7760

Reviewed by: mirielka(Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/25cc9af657d2d90436fed54b362e6766bcb1eb02">25cc9af6</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-08-24T14:28:25-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7595 - Run PR tests when the nightly gate is skipped (#7766)

Bug Description: The gate job only exists to dedupe nightlies, so it
is intentionally limited to schedule events and reports skipped on
every pull_request and workflow_dispatch run. The BDB Test and LMDB
Test jobs carry no explicit if condition, so they use the implicit
success() status check, and that check is false whenever any job in
the transitive needs chain was skipped (actions/runner#491). Since
commit 4731986 those runs built the RPMs but skipped all pytest
suites, while still reporting overall success.

Fix Description: Give both test jobs an explicit condition that
depends on the build result alone, so the skipped gate no longer
propagates past the build job. Nightly runs are unchanged: there the
gate runs and succeeds, and a failed or cancelled build still skips
the tests.

Relates: https://github.com/389ds/389-ds-base/issues/7595

Reviewed by: @mirielka (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/03729b25d953ee21684e8fbce4fd18800673dd5e">03729b25</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-08-26T10:54:10+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Security fix for CVE-2026-11770

Description:
Add authentication checks for all replication extended operations
and implement LDAP injection protection for REPL_CLEANRUV_CHECK_STATUS_OID.

  - Check that binddn is accepted by a replica for cleanruv and
    start replication session extended operations:
      REPL_CLEANRUV_OID
      REPL_ABORT_CLEANRUV_OID
      REPL_CLEANRUV_GET_MAXCSN_OID
      REPL_CLEANRUV_CHECK_STATUS_OID
      REPL_START_NSDS50_REPLICATION_REQUEST_OID
      REPL_START_NSDS90_REPLICATION_REQUEST_OID
  - Check that an active replication session is associated with the
    connection for session-related operations:
      REPL_END_NSDS50_REPLICATION_REQUEST_OID
      REPL_NSDS50_REPLICATION_ENTRY_REQUEST_OID
      REPL_NSDS71_REPLICATION_ENTRY_REQUEST_OID
  - Implement LDAP injection protection for CleanRUV filters
  - Fix isdigit() undefined behavior for non-ASCII characters
  - Use safer replica iteration to avoid deadlocks in callbacks
  - Add comprehensive test suite (38+ test cases)

References:
- https://access.redhat.com/security/cve/CVE-2026-11770
- https://bugzilla.redhat.com/show_bug.cgi?id=2484802
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/b4748cd36652d03cf5d35c090e18d78f528083d6">b4748cd3</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-08-26T10:55:13+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>CVE-2026-11770 - Fix StartReplicationRequest auth gate response format

Bug Description:
The CVE-2026-11770 fix sends a bare `slapi_send_ldap_result()` when
`check_replica_auth()` rejects an authenticated bind DN in
StartNSDS50ReplicationRequest. The supplier expects a BER-encoded extop
response, cannot parse the bare LDAP error, and treats it as a fatal
non-retryable failure. This breaks total init when
nsDS5ReplicaBindDNGroup is set after the agreement is created.

Fix Description:
For authenticated connections, send a proper BER-encoded extop response
with NSDS50_REPL_PERMISSION_DENIED so the supplier retries. Keep the
bare LDAP error for anonymous connections (no legitimate supplier binds
anonymously).

Reviewed by: @progier (Thanks!)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/cd5023698b3f4679035823832f259877503a9c3e">cd502369</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-08-26T15:21:14+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7770 - Testimony failure in test_cleanruv_extop_security.py (#7771)

Bug Description:
`test_cleanruv_extop_security.py` fails testimony validation.
It also should be renamed to `cleanruv_extop_security_test.py` to be
picked up by pytest test discovery.

Fix Description:
Remove unsupported docstring section, rename the file.

Fixes: https://github.com/389ds/389-ds-base/issues/7770

Reviewed by: @mirielka (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/5b248a976b98ab4b3c8054d63473d86ea90f293f">5b248a97</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-08-27T13:11:35+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7774 - Add backport action (#7775)

Bug Description:
Manual backports are prone to errors (merge conflicts, missing test
results). All commits should go through PRs and have green pipelines
before merging.

Fix Description:
Add a GitHub Actions workflow that automatically creates backport PRs
when a merged PR has `backport/<version>` labels (e.g. `backport/3.1`).

Fixes: https://github.com/389ds/389-ds-base/issues/7774

Reviewed by: @mirielka (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/25801b684a2af02ada1d25679618e91bb6c52685">25801b68</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-08-27T15:31:20+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 6176 - Add sysusers.d support and modernize systemd path detection (#7776)

Bug Description:
The `dirsrv` user/group was created by downstream packaging using
sysusers config rather than shipped upstream.

Several systemd directory paths were detected using fragile methods:
`tmpfiles.d` relied on a filesystem check at configure time and
defaulted to the wrong location (`/etc/tmpfiles.d` instead of
`/usr/lib/tmpfiles.d`), `sysctldir` was hardcoded in `Makefile.am`, and
`systemdsystemunitdir/confdir` required explicit `--with-*` flags
because the auto-detection only worked when `yes` was passed.

Fix Description:
Add a sysusers.d config file to the upstream source and install it when
systemd is enabled.

Modernize all systemd directory detection to use `pkg-config` with
fallbacks.

Fixes: https://github.com/389ds/389-ds-base/issues/6176

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/d390133a6beb135adaf7eb004f8ccbc0dd302f0f">d390133a</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-08-27T15:42:19+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7722 - Switch to `logconv.py` as default (#7778)

Description:
Move `logconv.pl` and its Perl dependencies to a new
`389-ds-base-logconv-perl` subpackage. The subpackage is marked as
deprecated and won't be build after Fedora >= 46 and RHEL >= 11.

`logconv.py` is the recommended replacement.

Fixes: https://github.com/389ds/389-ds-base/issues/7722

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/fa7f2662a77b440e553fabd00f6793efe68c7a62">fa7f2662</a></strong>
<div>
<span> by Bernhard M. Wiedemann </span> <i> at 2026-08-27T09:50:17-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix expiration time check (#7718)

Issue 7718 - Fix pwp expiration time check

A misplaced bracket caused a bool to be passed to difftime instead of a timestamp.

Signed-off-by: @bmwiedemann

Reviewed by: mreynolds

relates: https://github.com/389ds/389-ds-base/issues/7769</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/6c05628195c1de0ce53110ea72d3bec3cb50ca14">6c056281</a></strong>
<div>
<span> by Andrew Rukin </span> <i> at 2026-08-27T14:45:34-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Reject mismatched cn in dynamic certificate add requests (#7680)

Issue 7780 - Reject mismatched cn in dynamic certificate add request

Description:  Reject mismatched cn in dynamic certificate add requests

Signed-off-by: Andrew Rukin <9697001+drewrukin@users.noreply.github.com>

Reviewed by: mreynolds</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/bac0fa0d39829619ef6aad445a55d2d94db07152">bac0fa0d</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-08-31T12:38:07+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update github-actions</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/93b2c1e8587906a4241baea0c07ab5f57a8c9c7e">93b2c1e8</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-08-31T12:38:51+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update dependency eslint to v10.9.1</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/ba50e4926a9681cb90667bc1784f1587b2df3826">ba50e492</a></strong>
<div>
<span> by renovate[bot] </span> <i> at 2026-08-31T12:39:37+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update Rust crate uuid to v1.26.0</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a5e819afc1c8a949f4812d4bd12f0d9a7c60c4b3">a5e819af</a></strong>
<div>
<span> by progier389 </span> <i> at 2026-08-31T18:38:12+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7769 - Password may wrongly be reported as expired (#7777)

Added AccountUsabilityControl class in lib389 to easily send the control and decode its result

And added tests to verify the account availability control behavior

Issue: #7769

Reviewed by: @mreynolds389

Assisted by: Claude AI</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/989e13895684ff0df2e7ee848e348a43ba9e5f14">989e1389</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-08-31T21:59:26+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 2779 - Streamline SPEC file for potential inclusion in Fedora (#7784)

Bug Description:
For the integration with Packit we need to have a single spec file that
can be reused for downstream release promotion between Fedora, CentOS
Stream, and RHEL.

Fix Description:
Streamline `389-ds-base.spec.in` so that a single spec file works
across Fedora, CentOS Stream, and RHEL builds.
Update `rpm/bundle-rust-npm.py` to correctly insert Provides.

Fixes: https://github.com/389ds/389-ds-base/issues/2779
Fixes: https://github.com/389ds/389-ds-base/issues/7485

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/e0d4e289a6e663321bd3865eb5ca3dc0680b1033">e0d4e289</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-08-31T21:59:49+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7785 - Downstream release automation using Packit (#7786)

Bug Description:
Add Packit integration to automate the upstream-to-Fedora release
pipeline.

Fix Description:
Add new Packit jobs:
- propose_downstream: on every GitHub release, Packit generates the
tarball, updates the spec with bundled crate/npm Provides, uploads the
tarball to the Fedora lookaside cache, and opens a dist-git PR against
the appropriate Fedora branches.
- koji_build: automatically triggers a Koji build when the dist-git PR
is merged.
- bodhi_update: automatically creates a Bodhi update for branched
Fedora after a successful Koji build.

Fixes: https://github.com/389ds/389-ds-base/issues/7785

Reviewed by: @progier389 (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/293b88c91c913ca58bc2aa08e31b241870e9540c">293b88c9</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-09-01T10:20:27+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7611 - PBKDF2 password verification should reject invalid iteration counts (#7632)

Description:
The Rust pwdchan PBKDF2 password verification code does not validate the
extracted iteration count before invoking the PBKDF2 hash function.

Fix:
Add nsslapd-pwdPBKDF2AcceptMaxIterations configuration for each PBKDF2
plugin variant and reject stored hashes whose iteration count is below the
minimum or above the configured accept maximum before password verification.
Add lib389 and dsconf support to get, set, and delete the accept max setting.

Depends on the schema change adding nsslapd-pwdPBKDF2AcceptMaxIterations
to pwdPBKDF2PluginConfig.

Fixes: https://github.com/389ds/389-ds-base/issues/7611

Assisted by: Cursor

Reviewed by: @droideck (Thank you)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/89ad82cc2e4f525ddf790678525a7f574c0106d2">89ad82cc</a></strong>
<div>
<span> by Simon Pichugin </span> <i> at 2026-09-02T19:48:57-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs (#7792)

Description: The Gate job skipped main's nightly at an unchanged head,
which is when a nightly is useful... (since the test image is rebuilt
from Fedora every night)
It never fired for the pytest workflows and switched the cargo nightly
off entirely. Every dispatched release-branch run that got past
the build also failed in the tmate step, because the dispatcher's empty
debug_enabled input resolved to the string "false", which is true in
the step condition.

Drop the gate from all three workflows, require debug_enabled == 'true',
let the dispatcher rely on each branch's workflow defaults, fail the
Build job on an unknown pytest_tests value, and document the dispatch
inputs and the unconditional nightly in building.md.

Relates: https://github.com/389ds/389-ds-base/issues/7595

Reviewed by: @vashirov (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/251bb3ffd40b2cd6a7dd71043c81a54fff839916">251bb3ff</a></strong>
<div>
<span> by dependabot[bot] </span> <i> at 2026-09-03T12:28:50+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Bump fast-uri from 3.1.5 to 3.1.7 in /src/cockpit/389-console

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.7.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](https://github.com/fastify/fast-uri/compare/v3.1.5...v3.1.7)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/badfae6a9b1cdcadc778649cfaed2fce05646721">badfae6a</a></strong>
<div>
<span> by Mark Reynolds </span> <i> at 2026-09-04T10:42:05-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7808 - CI - harden online_import_nosync_test (#7809)

Description:

dirsrvtests/tests/suites/replication/online_import_nosync_test.py can be flaky
and run too fast. Need to increase the load to properly measure the performance

relates: https://github.com/389ds/389-ds-base/issues/7808

Reviewed by: progier(Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/c7c998d2e757889a017e8c24de2f69481dfbe04d">c7c998d2</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-09-04T16:52:18+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Issue 7806 - Preserve dsEntryDN case on modify (#7807)

Bug Description:
`id2entry_add_ext()` unconditionally overwrites dsEntryDN every time an
entry is written to the database. When an entry is loaded from disk with
`nsslapd-return-original-entrydn` is off, the DN is rebuilt from the
entryrdn index in normalized form. A plain modify then permanently
replaces the original-case dsEntryDN with this normalized value.

Fix Description:
Compare the existing dsEntryDN with the current entry DN before
overwriting.
If they refer to the same entry, keep the stored value.
If the DN changed (MODRDN) or is not set yet (ADD), update it.

Fixes: https://github.com/389ds/389-ds-base/issues/7806

Reviewed by: @mreynolds389, @droideck (Thanks!)</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/82476f96808f4d22cf6db1ea97a799f27b9412f1">82476f96</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-09-07T11:36:16+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Security fix for CVE-2026-18355

Description:
A missing minimum-length validation in sasl_io_start_packet() allows an
authenticated SASL user to crash the 389 Directory Server by sending a
SASL-framed packet with a length field of 0, 1, or 2. This causes an
unsigned integer underflow in sasl_io_read_packet(), which then calls
PR_Recv() with a near-4 GB read size into a 1024-byte heap buffer,
resulting in heap corruption and a SIGSEGV crash.

This is the complementary fix to Issue 7593 (CVE-2026-11774), which
added a maximum overflow check but missed the minimum underflow check.

Fixes: https://github.com/389ds/389-ds-base/issues/7593

References:
- https://access.redhat.com/security/cve/CVE-2026-18355
- https://bugzilla.redhat.com/show_bug.cgi?id=2509186
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/350113ba569c2992d70ab3a70d474f9e151e97d1">350113ba</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-09-07T13:44:56+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Security fix for CVE-2026-18453

Description:
A flaw was found in 389 Directory Server. The op_shared_search function
does not check for a NULL backend pointer when reusing a paged-results
slot in the USE_ONE_BACKEND control code path. An unauthenticated client
can crash ns-slapd by sending two SEARCH requests on the same
connection: the first stores NULL in a paged-results slot via a
non-existent backend name, the second dereferences it through
slapi_be_Rlock(NULL), causing a SIGSEGV. Paged results and anonymous
access are both enabled by default.

Fix:
- Reject allocating a paged-results slot when the backend pointer is NULL
- Check pr_be for NULL before swapping be_single in the be_name code path

References:
- https://access.redhat.com/security/cve/CVE-2026-18453
- https://bugzilla.redhat.com/show_bug.cgi?id=2509696
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/12e6d744435753edef60d07f5ae8e7322021c981">12e6d744</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-09-07T13:44:59+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Security fix for CVE-2026-18922

Description:
A failed one-shot SASL exchange (e.g. PLAIN with wrong password) leaves
stale identity data in the auxprop context from the canon_user callback
that ran before the credential check. Without resetting the context,
a subsequent successful bind on the same connection inherits the stale
identity, allowing privilege escalation to Directory Manager.

References:
- https://access.redhat.com/security/cve/CVE-2026-18922
- https://bugzilla.redhat.com/show_bug.cgi?id=2511388
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/8c7732a08d2eccc98fa1186222c1a53784502ad9">8c7732a0</a></strong>
<div>
<span> by James Chapman </span> <i> at 2026-09-07T13:44:59+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Security fix for CVE-2026-19843

Description:
The LDAP editor can run ldapsearch as root through cockpit by concatenating the entry DN
into sh -c. Double quotes allow command substitution, DNs may contain $, (, and ). A user
who can create or rename an entry can plant that syntax in the DN, so when an admin later
opens the entry or manage ACIs, the host executes it as root.

Fix:
Spawn ldapsearch as an argv array instead, matching getBaseLevelEntryFullAttributes().

References:
- http://access.redhat.com/security/cve/CVE-2026-19843
- https://bugzilla.redhat.com/show_bug.cgi?id=2515965
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/bfa0c00c7f41849532ef17dbc88a46dd258ea98a">bfa0c00c</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-09-07T13:44:59+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Security fix for CVE-2026-76560

Description:
A flaw in ACL bind-rule evaluation allows anonymous clients to satisfy
SELFDN, USERDNATTR, or LDAPURL rules. An empty anonymous bind DN can match
empty attribute values or broad LDAP URL filters, granting unauthorized access.

Fix:
Reject anonymous clients before evaluating these bind rules.

References:
- https://access.redhat.com/security/cve/CVE-2026-76560
- https://bugzilla.redhat.com/show_bug.cgi?id=2519521
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/59009c84a7408948974688a78367505615cbf3d8">59009c84</a></strong>
<div>
<span> by Viktor Ashirov </span> <i> at 2026-09-07T13:45:00+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Bump version to 3.3.1
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/a5c0e15a69f7f970669c13d57c48b7fd2c127a93">a5c0e15a</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-09-08T12:06:57+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Merge branch 'upstream'
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/11ad711e5b38683906382183a0b52d18679d939e">11ad711e</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-09-09T12:51:53+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>version bump
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/1df5594ccd7f2262926f6464add38827a41c5b56">1df5594c</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-09-09T14:56:08+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>DEBIAN: remove yet another agent symlink
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/bcc1b93ab9360a11b8a36201286e2b43445ede8a">bcc1b93a</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-09-09T15:24:43+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>install: Updated.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/60ad746a96a82f93395cdfe581957ede51150a85">60ad746a</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-09-09T15:25:15+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>rules: Remove upstream sysusers conf, we have our own.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/0bb746b852cc851a8692cb3488f50b3261c8174b">0bb746b8</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-09-09T15:38:36+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>control: Drop libdb-dev from build-depends. (Closes: #1119174)
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/19e1d5dce831f046bae6df313c40675cd826d33a">19e1d5dc</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-09-09T15:38:54+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>releasing package 389-ds-base version 3.3.1-1
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/4accccb94eabe5d03e5f384be01dc981b2655f58">4accccb9</a></strong>
<div>
<span> by Ujjwal Sarswat </span> <i> at 2026-09-09T17:08:38+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>d/tests/setup: fix path to dscreate which is in /usr/bin now</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/commit/413ea783a120e7740565c281b20b01dbf5931df1">413ea783</a></strong>
<div>
<span> by Timo Aaltonen </span> <i> at 2026-09-09T17:09:15+03:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>releasing package 389-ds-base version 3.3.1-2
</pre>
</li>
</ul>
<h4 style="margin-top: 10px; margin-bottom: 10px;">
935 changed files:
</h4>
<ul>
<li class="file-stats">
<a href="#1a09b4b7169a24562719d23904d42915d8eede1e">
<span class="new-file">
+
.agents/skills/add-cli-option/SKILL.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#07fb4406468bffd3db739a2a2c84928eaba14592">
<span class="new-file">
+
.agents/skills/add-cli-option/references/handler-patterns.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#2acca31b482690c7baff1056e831ade32274b508">
<span class="new-file">
+
.agents/skills/add-cli-option/references/new-noun.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#395cd93d414510a637a1d683441064ec6e466236">
<span class="new-file">
+
.agents/skills/add-config-attribute/SKILL.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#e6addc08b2857bafe8ebe81a39cf450c581d4749">
<span class="new-file">
+
.agents/skills/add-config-attribute/references/core-config-chain.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#96c37ca4aa4e47f39af0568da42de7919bf95e3e">
<span class="new-file">
+
.agents/skills/add-config-attribute/references/new-plugin.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#2e53c4facc3b53a7a25e3c5548ff9d41e14c111f">
<span class="new-file">
+
.agents/skills/add-config-attribute/references/plugin-config.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#37137259ef687381ad0ecf4c05ed0d0876ceea31">
<span class="new-file">
+
.agents/skills/commit-and-pr/SKILL.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#a04587ab33616c3f252cb614f06dc2f742a2ed50">
<span class="new-file">
+
.agents/skills/touch-backend/SKILL.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#df21124ce161ff54236f81da85c6f40dc2ff4f48">
<span class="new-file">
+
.agents/skills/ui-expose-attribute/SKILL.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#109e13ef7165e132581e628a56a6c5db96c4995c">
<span class="new-file">
+
.agents/skills/ui-expose-attribute/references/new-page.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#67432708edbbf94abc311c64f073e70cfb5cbb8c">
<span class="new-file">
+
.agents/skills/verify-changes/SKILL.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#e4d0a76f7dadcf6ac57411cd70e9f968dce8f7ea">
<span class="new-file">
+
.agents/skills/verify-changes/references/container-recipe.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#5441ecae87889f49a210266080c740395fd6a500">
<span class="new-file">
+
.agents/skills/write-test/SKILL.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#9b0f813deb2c7d130e406f966da47f98755c3851">
<span class="new-file">
+
.agents/skills/write-test/references/cmocka.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#2ad260bad36f63cfb06098f30a7757cb34ebc8bd">
<span class="new-file">
+
.cursor/rules/agents.mdc
</span>
</a>
</li>
<li class="file-stats">
<a href="#c48a897b585e69ab440bf090d10f1cae8a123ca1">
<span class="new-file">
+
.github/codeql/codeql-config.yml
</span>
</a>
</li>
<li class="file-stats">
<a href="#a76538a5bde8f8b029844bb761a5234bcdce8d15">
<span class="new-file">
+
.github/renovate.json
</span>
</a>
</li>
<li class="file-stats">
<a href="#418a6df66384fbccf0232c5fc704681e6cd55655">
.github/scripts/generate_matrix.py
</a>
</li>
<li class="file-stats">
<a href="#f5fa4aacb410d0d6582397e960bbbbeb2b7d32a8">
<span class="new-file">
+
.github/scripts/pr_scope.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#29c5060591f41a25ae4fdef0d163a0f63056f20a">
<span class="new-file">
+
.github/workflows/backport.yml
</span>
</a>
</li>
<li class="file-stats">
<a href="#38b37a85a0ea0bbbcd67965688feb5b459ebfa93">
.github/workflows/cargotest.yml
</a>
</li>
<li class="file-stats">
<a href="#37c182e857c9d9bb0eb6218a00392ab9f8e4d264">
<span class="new-file">
+
.github/workflows/codeql.yml
</span>
</a>
</li>
<li class="file-stats">
<a href="#fefa7ecf1d406811a36def12ceb26be922add9ee">
.github/workflows/compile.yml
</a>
</li>
<li class="file-stats">
<a href="#f34eaf19b34e4ae5135212c79909cfd8d3c70b6b">
.github/workflows/coverity.yml
</a>
</li>
<li class="file-stats">
<a href="#7b1d1fdeb8c80da780e8d0ee8fd14f530a610b17">
.github/workflows/lmdbpytest.yml
</a>
</li>
<li class="file-stats">
<a href="#94f55677eb70b235148f0cb0d60c22ba72be9cd7">
<span class="new-file">
+
.github/workflows/nightly-dispatch.yml
</span>
</a>
</li>
<li class="file-stats">
<a href="#7af05dabe0abb5b90410ad75f3f1c86411081618">
.github/workflows/npm.yml
</a>
</li>
<li class="file-stats">
<a href="#c912f4d2f00cf8e018013a90a8dd6e257a5eb6e5">
.github/workflows/pytest.yml
</a>
</li>
<li class="file-stats">
<a href="#16911b9809e0d05b7b124ba8453fa5303d74924c">
.github/workflows/release.yml
</a>
</li>
<li class="file-stats">
<a href="#93751d0860fc8bdb85ae1aef6764e7aa694b4f1f">
.github/workflows/validate.yml
</a>
</li>
<li class="file-stats">
<a href="#a5cc2925ca8258af241be7e5b0381edf30266302">
.gitignore
</a>
</li>
<li class="file-stats">
<a href="#8eef649c6f3efda90b9e4f57ec6593b23880057e">
<span class="new-file">
+
.packit.yaml
</span>
</a>
</li>
<li class="file-stats">
<a href="#37dd68363fc1d45d64469b999d3d36da51da9c94">
<span class="new-file">
+
AGENTS.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#d5b4de16d947214ec306bd57bed1bd23a939b5f9">
Makefile.am
</a>
</li>
<li class="file-stats">
<a href="#d7e560a1b9a915cc82a4a544b31706fd6db5f6fd">
VERSION.sh
</a>
</li>
<li class="file-stats">
<a href="#87db583be5c13c1f7b3c958b10e03d67b6a2ca06">
configure.ac
</a>
</li>
<li class="file-stats">
<a href="#ef41d2fe5e063fa612055a4c9a7c9476b8536acf">
<span class="deleted-file">

debian/389-ds-base.dirs
</span>
</a>
</li>
<li class="file-stats">
<a href="#927f8e691e4c06faec9cf1eea77d5474e857fcae">
debian/389-ds-base.install
</a>
</li>
<li class="file-stats">
<a href="#08e8ae74f105152d6f4a466ce2c0354f21fb448a">
debian/389-ds-base.postinst
</a>
</li>
<li class="file-stats">
<a href="#6686dcaccbe4680741a9e1ecc4e2f706033b0ea6">
debian/389-ds-base.postrm
</a>
</li>
<li class="file-stats">
<a href="#b365999890e02a0d05f46159846c152ca8e11ce6">
<span class="new-file">
+
debian/389-ds-base.sysusers
</span>
</a>
</li>
<li class="file-stats">
<a href="#ba0b565159513afdb5e004d38e37a8e8147eb3e8">
<span class="new-file">
+
debian/389-ds-base.tmpfiles
</span>
</a>
</li>
<li class="file-stats">
<a href="#9c96da0e9f91d7d8937b69b524702c106258f0d1">
debian/changelog
</a>
</li>
<li class="file-stats">
<a href="#58ef006ab62b83b4bec5d81fe5b32c3b4c2d1cc2">
debian/control
</a>
</li>
<li class="file-stats">
<a href="#27dfb45a801075d5072cd442f9713b4457251097">
<span class="deleted-file">

debian/patches/0001-Issue-7184-2nd-argparse.HelpFormatter-_format_action.patch
</span>
</a>
</li>
<li class="file-stats">
<a href="#cc3571a24e898c7746b300e8891b96de4e974b0f">
<span class="deleted-file">

debian/patches/0001-Issue-7184-argparse.HelpFormatter-_format_actions_us.patch
</span>
</a>
</li>
<li class="file-stats">
<a href="#cd9cdda675a5ad106c33799049d1b5b13666fc80">
<span class="deleted-file">

debian/patches/0001-Security-fix-for-CVE-2025-14905.patch
</span>
</a>
</li>
<li class="file-stats">
<a href="#81a16e56f40770a7d531727b4790634bb9a6f526">
<span class="deleted-file">

debian/patches/fix-nss-include.diff
</span>
</a>
</li>
<li class="file-stats">
<a href="#bc34014ab4b9a49dd7a27bdd8d352912607c3a96">
debian/patches/series
</a>
</li>
<li class="file-stats">
<a href="#8756c63497c8dc39f7773438edf53b220c773f67">
debian/rules
</a>
</li>
<li class="file-stats">
<a href="#7de01e8afc6367703d41e465b3a15ebc2bcb3011">
debian/tests/setup
</a>
</li>
<li class="file-stats">
<a href="#59b999aa09147113d8ed06dddc46b9d73a25a75e">
<span class="new-file">
+
dirsrvtests/AGENTS.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#dea9a48deca97dbb73ba1a685f389310fd90a855">
dirsrvtests/conftest.py
</a>
</li>
<li class="file-stats">
<a href="#60ea306b2db02a8c521992c515b83ad5a7724f49">
dirsrvtests/create_test.py
</a>
</li>
<li class="file-stats">
<a href="#5f736b5a008bb29d37b41951d52b49d3e8cfff4f">
dirsrvtests/tests/data/ticket47953/__init__.py

dirsrvtests/lib/__init__.py
</a>
</li>
<li class="file-stats">
<a href="#36f30073324cec47f76f5519b3babbf55aa9d295">
<span class="new-file">
+
dirsrvtests/lib/test389/__init__.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#94f55161a107c381fc7d05c262dd6f26ffdfdae8">
src/lib389/lib389/perftools.py

dirsrvtests/lib/test389/perftools.py
</a>
</li>
<li class="file-stats">
<a href="#c2740def39dda1229beaacd2407122b1eeac2391">
src/lib389/lib389/topologies.py

dirsrvtests/lib/test389/topologies.py
</a>
</li>
<li class="file-stats">
<a href="#9b6793f488050dcec5b57e9260368fae3e6774df">
<span class="new-file">
+
dirsrvtests/sanitizers/README.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#37c3d6fb495135d695da2efce0c7db553631c91f">
<span class="new-file">
+
dirsrvtests/sanitizers/__init__.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#a835287efa79a02dd417f257ecedfd37ee6ee1b8">
<span class="new-file">
+
dirsrvtests/sanitizers/ds_sanitizer.te
</span>
</a>
</li>
<li class="file-stats">
<a href="#5cfe45769e65d76550e1cd3af7059cb1023dbe7a">
<span class="new-file">
+
dirsrvtests/sanitizers/setup_host.sh
</span>
</a>
</li>
<li class="file-stats">
<a href="#9065d63f14d585ecfe0c3b9c62dbd8b56c9fdd92">
<span class="deleted-file">

dirsrvtests/tests/data/ticket47953/ticket47953.ldif
</span>
</a>
</li>
<li class="file-stats">
<a href="#82b96472da4b30281208e4cf127143601540a1db">
dirsrvtests/tests/longduration/automembers_long_test.py
</a>
</li>
<li class="file-stats">
<a href="#279a3482264bd1f47263c974e056dae3b2de5fd6">
dirsrvtests/tests/longduration/db_protect_long_test.py
</a>
</li>
<li class="file-stats">
<a href="#003d03e6548e50f6a1e647aa5577ff43b1f057be">
src/lib389/cli/dsrate

dirsrvtests/tests/perf/dsrate
</a>
</li>
<li class="file-stats">
<a href="#f1bd12f18f54331a776dc9d31205b8cef7123542">
dirsrvtests/tests/perf/memberof_test.py
</a>
</li>
<li class="file-stats">
<a href="#3e6c75e28701dbd5c0c046857a2dbbbeb3984fe8">
dirsrvtests/tests/perf/ndncache_test.py
</a>
</li>
<li class="file-stats">
<a href="#8a753c9e0b510b8a8576e9277c06cd0f576e0cdf">
dirsrvtests/tests/perf/search_performance_test.py
</a>
</li>
<li class="file-stats">
<a href="#5adc326d238020afa0d993b50ef20687a4bd87b3">
dirsrvtests/tests/stress/backend/bdb_cursor_race_test.py
</a>
</li>
<li class="file-stats">
<a href="#acacd7c7195e873c9d65145acd888405cb2b0e8d">
<span class="new-file">
+
dirsrvtests/tests/stress/backend/range_deadlock_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#467535903b569d6f9d43171fbb319325d7051905">
dirsrvtests/tests/stress/cos/cos_scale_template_test.py
</a>
</li>
<li class="file-stats">
<a href="#649f29c81af11fc0bc255f6895851d2648b59c84">
dirsrvtests/tests/stress/reliabilty/reliab_conn_test.py
</a>
</li>
<li class="file-stats">
<a href="#786ebc53064f65a4ff7c1e7f11e00308f30832fd">
dirsrvtests/tests/stress/search/simple.py
</a>
</li>
<li class="file-stats">
<a href="#38ff14ce651d3d3ba4e8b634da530111add24236">
dirsrvtests/tests/suites/acl/aci_excl_filter_test.py
</a>
</li>
<li class="file-stats">
<a href="#2d8c7a054b64aef5923ce7bd1af2c17c4b9e3a42">
dirsrvtests/tests/suites/acl/aci_ip_restriction_test.py
</a>
</li>
<li class="file-stats">
<a href="#ad0df7100163bb8ecc0bcfb48c2d9e17d6cc4975">
dirsrvtests/tests/suites/acl/acivattr_test.py
</a>
</li>
<li class="file-stats">
<a href="#1015ac5112c20a9dd66644285fbfc9d08443b3a9">
dirsrvtests/tests/suites/acl/acl_deny_test.py
</a>
</li>
<li class="file-stats">
<a href="#18c7f8b18bde0a44780cd64ef8ecd2105b6d5bd7">
dirsrvtests/tests/suites/acl/acl_test.py
</a>
</li>
<li class="file-stats">
<a href="#b8aeed2ca3171b6a1fc01319a7231cef1a41346e">
<span class="new-file">
+
dirsrvtests/tests/suites/acl/anonymous_default_aci_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#dc2bbf1b393d1b3ede4e019f5a3f2630c0936289">
dirsrvtests/tests/suites/acl/conftest.py
</a>
</li>
<li class="file-stats">
<a href="#fb8ea4aae3c882631446ce9d60af9a9f0fca82a1">
dirsrvtests/tests/suites/acl/default_aci_allows_self_write_test.py
</a>
</li>
<li class="file-stats">
<a href="#8f14e625d499b4ef081654dc274b81ebd5fc1639">
dirsrvtests/tests/suites/acl/deladd_test.py
</a>
</li>
<li class="file-stats">
<a href="#57fb4f8e74a2d6f58bc4130104a221447583360d">
dirsrvtests/tests/suites/acl/enhanced_aci_modrnd_test.py
</a>
</li>
<li class="file-stats">
<a href="#711975c14c3d38b7baaed6c4b81226e68432e736">
dirsrvtests/tests/suites/acl/globalgroup_part2_test.py
</a>
</li>
<li class="file-stats">
<a href="#5523c7fbdf3f1ec67e2dfb422854064b0abebc91">
dirsrvtests/tests/suites/acl/globalgroup_test.py
</a>
</li>
<li class="file-stats">
<a href="#e47af2c035c17748a2cb533e0d98680df9bc440c">
dirsrvtests/tests/suites/acl/misc_test.py
</a>
</li>
<li class="file-stats">
<a href="#2f2143b319178dc07a9fb7a78159b57ac22d4b84">
dirsrvtests/tests/suites/acl/modify_test.py
</a>
</li>
<li class="file-stats">
<a href="#4300a92e5ff985e2b073f33967785259fd5ad6cc">
dirsrvtests/tests/suites/acl/modrdn_test.py
</a>
</li>
<li class="file-stats">
<a href="#7982b874549dcab36b1539e469ec0862977d2bcb">
<span class="new-file">
+
dirsrvtests/tests/suites/acl/proxy_authz_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#5ce019e40682c8009aff21c36cb6da20a360fcb2">
dirsrvtests/tests/suites/acl/repeated_ldap_add_test.py
</a>
</li>
<li class="file-stats">
<a href="#d41f16dfa4ed96b59ec8891125fe4d7be87fabe5">
dirsrvtests/tests/suites/acl/roledn_test.py
</a>
</li>
<li class="file-stats">
<a href="#24fe4c6b913095c7efb563a5e2dff130cd64845b">
dirsrvtests/tests/suites/acl/search_real_part2_test.py
</a>
</li>
<li class="file-stats">
<a href="#155da4baddfb019eec3c1409d3fb81f39a5b5baf">
dirsrvtests/tests/suites/acl/search_real_part3_test.py
</a>
</li>
<li class="file-stats">
<a href="#415e82d82416832970d7162101bea49cd4c6b636">
dirsrvtests/tests/suites/acl/search_real_test.py
</a>
</li>
<li class="file-stats">
<a href="#630eba1e72229f99b5f917cceae541bf1c932e85">
<span class="new-file">
+
dirsrvtests/tests/suites/acl/selfdn_anon_bypass_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#93a51749f56ce1f41ba776252af6cf439da64c74">
dirsrvtests/tests/suites/acl/selfdn_permissions_test.py
</a>
</li>
<li class="file-stats">
<a href="#5109cd28cb7bd9d2367b3e83ecdad8cebef39f2e">
dirsrvtests/tests/suites/acl/syntax_test.py
</a>
</li>
<li class="file-stats">
<a href="#3eea72bf25cb88fa118506219e759b33272e6415">
dirsrvtests/tests/suites/acl/userattr_test.py
</a>
</li>
<li class="file-stats">
<a href="#fe7c8bf586c0c663b8394617267a3e6b9ffe5507">
dirsrvtests/tests/suites/acl/valueacl_part2_test.py
</a>
</li>
<li class="file-stats">
<a href="#f807116d8f610ac0c7ad3bf308883757e760f031">
dirsrvtests/tests/suites/acl/valueacl_test.py
</a>
</li>
<li class="file-stats">
<a href="#97b169f8f6fe5df64278ff0b2911a9ca871230ce">
dirsrvtests/tests/suites/attr_encryption/attr_encryption_test.py
</a>
</li>
<li class="file-stats">
<a href="#f40d372ca67383e5d54b24d9f51e7206a4f44209">
dirsrvtests/tests/suites/auth_token/basic_auth_test.py
</a>
</li>
<li class="file-stats">
<a href="#86267aa12ab716f2bbe1ca6f22dbac92d3f039af">
dirsrvtests/tests/suites/automember_plugin/automember_abort_test.py
</a>
</li>
<li class="file-stats">
<a href="#065b762ed6fa99117318d7186e5d03b5e4588a16">
dirsrvtests/tests/suites/automember_plugin/automember_mod_test.py
</a>
</li>
<li class="file-stats">
<a href="#d87188b0e40d1a430777e3130c7d3e7351ad221a">
dirsrvtests/tests/suites/automember_plugin/automember_test.py
</a>
</li>
<li class="file-stats">
<a href="#3e1a8b47b38101330b69f73be793efdd7864cdb0">
dirsrvtests/tests/suites/automember_plugin/basic_test.py
</a>
</li>
<li class="file-stats">
<a href="#7ea07ba13348cb8b71085aeeca59b512fcb8a8b3">
dirsrvtests/tests/suites/automember_plugin/configuration_test.py
</a>
</li>
<li class="file-stats">
<a href="#62951f4f31f102a462ebf16b2d0c555472f9d5c0">
dirsrvtests/tests/suites/backups/backup_test.py
</a>
</li>
<li class="file-stats">
<a href="#7cffca0bd7a0ae4a4c2a74bc2df07196d4867dfb">
dirsrvtests/tests/suites/basic/basic_test.py
</a>
</li>
<li class="file-stats">
<a href="#26a1e64558552753605b04a196d42fd89305a252">
dirsrvtests/tests/suites/basic/ds_entrydn_test.py
</a>
</li>
<li class="file-stats">
<a href="#7ea5a5b8cb22c9c5e94d5bb1ccd9fdd9d19b1dd1">
dirsrvtests/tests/suites/basic/haproxy_test.py
</a>
</li>
<li class="file-stats">
<a href="#2aff9c4bc1b38590999bf044a373547c822fd1b6">
<span class="new-file">
+
dirsrvtests/tests/suites/basic/modrdn_bulk_children_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#6824ca491b87913fc1a320c818faf4b93b8c1896">
dirsrvtests/tests/suites/basic/vlv_test.py
</a>
</li>
<li class="file-stats">
<a href="#0d862e5479366a579c86358e4f2b7b400c5e4ae2">
dirsrvtests/tests/suites/betxns/betxn_test.py
</a>
</li>
<li class="file-stats">
<a href="#11b325eb877edcf7928edfe7d92b20a7775ff8e7">
<span class="new-file">
+
dirsrvtests/tests/suites/betxns/entrycache_dn_hash_corruption_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#7e2473fc6aaa4e00195bc4aeae63d21e8132356c">
dirsrvtests/tests/suites/chaining_plugin/anonymous_access_denied_basic_test.py
</a>
</li>
<li class="file-stats">
<a href="#895e63e66987e5b85f2d8181a61abab19f78057e">
<span class="new-file">
+
dirsrvtests/tests/suites/chaining_plugin/chaining_bind_pw_encoding_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#480a1a422e6e0e93420ff207b424a839c57d66c0">
dirsrvtests/tests/suites/chaining_plugin/paged_search_test.py
</a>
</li>
<li class="file-stats">
<a href="#d3a9f3194f6f3cb99a17b7f6aa2b3fcc1562d929">
dirsrvtests/tests/suites/clu/ca_cert_bundle_test.py
</a>
</li>
<li class="file-stats">
<a href="#bdb40f71df8f196d20be650805e8f5556062a9c8">
dirsrvtests/tests/suites/clu/clu_test.py
</a>
</li>
<li class="file-stats">
<a href="#74604195b9b789ce9c2580956b379c2a4097947d">
dirsrvtests/tests/suites/clu/dbgen_test.py
</a>
</li>
<li class="file-stats">
<a href="#50117cbdbdf76599856de1d8b94c5f14376ff462">
dirsrvtests/tests/suites/clu/dbgen_usan_test.py
</a>
</li>
<li class="file-stats">
<a href="#8b2964ea53c212b3c31da36287e8f3b72af40528">
dirsrvtests/tests/suites/clu/dbmon_test.py
</a>
</li>
<li class="file-stats">
<a href="#22ab2b51aae74b977a914c6d5887b533bbc3a3b2">
dirsrvtests/tests/suites/clu/dbscan_test.py
</a>
</li>
<li class="file-stats">
<a href="#b729b36d5b54e805808c27531346eb8fad8593a7">
dirsrvtests/tests/suites/clu/dbverify_test.py
</a>
</li>
<li class="file-stats">
<a href="#248956ce0ecb91f0283610ce4a1cfe52e142eb26">
dirsrvtests/tests/suites/clu/dsconf_agmt_create_test.py
</a>
</li>
<li class="file-stats">
<a href="#5fdef5e48664732e339ab0a1c8972a94e0c96159">
<span class="new-file">
+
dirsrvtests/tests/suites/clu/dsconf_agmt_timeout_attrs_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#142b555b16ac3daeb2d612294d6ccae6f78ea1a6">
dirsrvtests/tests/suites/clu/dsconf_backend_dynamic_lists_test.py
</a>
</li>
<li class="file-stats">
<a href="#5fc2ec8fa38c11d6e667f5d824f434dedafeb19f">
dirsrvtests/tests/suites/clu/dsconf_config_test.py
</a>
</li>
<li class="file-stats">
<a href="#7fee8f89881c14fb5a51789a35a612ba7ccd2aa7">
dirsrvtests/tests/suites/clu/dsconf_conflict_test.py
</a>
</li>
<li class="file-stats">
<a href="#5c1fb8cc44ea45cd1021a4018fda623ce841d5f7">
<span class="new-file">
+
dirsrvtests/tests/suites/clu/dsconf_dsctl_security_cli_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#2846df2b5fe4cd6685219e3d22480cb33451ba3e">
dirsrvtests/tests/suites/clu/dsconf_logging_test.py
</a>
</li>
<li class="file-stats">
<a href="#4ffb4780fb5c7ef6e66e6c0923d7a90ae132f31d">
dirsrvtests/tests/suites/clu/dsconf_memberof_test.py
</a>
</li>
<li class="file-stats">
<a href="#e021561d0de2aeee0d549ed310d6579d8d25d0d7">
dirsrvtests/tests/suites/clu/dsconf_pta_add_url_test.py
</a>
</li>
<li class="file-stats">
<a href="#cf4860be3409905e524da4ec9cda897aa194f404">
<span class="new-file">
+
dirsrvtests/tests/suites/clu/dsconf_pwstorage_scheme_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#95d2b241eee50d47cd7f2d2910e6488104911a5f">
dirsrvtests/tests/suites/clu/dsconf_schema_superior_test.py
</a>
</li>
<li class="file-stats">
<a href="#3b0fe99e01411a7257f9e80b56c7fac29b441780">
dirsrvtests/tests/suites/clu/dsconf_tasks_test.py
</a>
</li>
<li class="file-stats">
<a href="#944b5377610832fbc88776abc9d54a196980d54a">
dirsrvtests/tests/suites/clu/dsconf_test.py
</a>
</li>
<li class="file-stats">
<a href="#c1395e1ff10fb39970c61dd48c4c96cc0fb50821">
dirsrvtests/tests/suites/clu/dsctl_acceptance_test.py
</a>
</li>
<li class="file-stats">
<a href="#3a1bfd6abe422958056f23c18c724483701b3ebc">
dirsrvtests/tests/suites/clu/dsctl_dblib_test.py
</a>
</li>
<li class="file-stats">
<a href="#3f29c3c18b45cd00eedf418a13e18a9beef0e873">
<span class="new-file">
+
dirsrvtests/tests/suites/clu/dsctl_tasks_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#bbda9e5b8d757bb87485e63969542cfe860ebf09">
dirsrvtests/tests/suites/clu/dsctl_tls_test.py
</a>
</li>
<li class="file-stats">
<a href="#dea3bf5171c3a590341078e12faf8adb6e515c87">
dirsrvtests/tests/suites/clu/dsidm_account_inactivity_test.py
</a>
</li>
<li class="file-stats">
<a href="#c2c18c731e35c009e472aab5ac7f56f37a6de83d">
dirsrvtests/tests/suites/clu/dsidm_account_test.py
</a>
</li>
<li class="file-stats">
<a href="#0aafae10b6d8823f1413b5f96d38d162ce55d802">
dirsrvtests/tests/suites/clu/dsidm_bulk_update_test.py
</a>
</li>
<li class="file-stats">
<a href="#34284ef39e238c14c41741c07e1868e628ee4a3b">
dirsrvtests/tests/suites/clu/dsidm_config_test.py
</a>
</li>
<li class="file-stats">
<a href="#8fffaeb83c0c81006a040746007db376ceee31d9">
dirsrvtests/tests/suites/clu/dsidm_group_test.py
</a>
</li>
<li class="file-stats">
<a href="#6f69f81554d1a06efd67182546691709f36e3b16">
dirsrvtests/tests/suites/clu/dsidm_init_test.py
</a>
</li>
<li class="file-stats">
<a href="#b7697b99d59e548c719b7852524791c54ef4df64">
dirsrvtests/tests/suites/clu/dsidm_organizational_unit_test.py
</a>
</li>
<li class="file-stats">
<a href="#1887f37e78a3e8a4ca97dcbd8eebbd9016a03863">
dirsrvtests/tests/suites/clu/dsidm_posixgroup_test.py
</a>
</li>
<li class="file-stats">
<a href="#c25a902c47e7ac44953458e789e10b00ae062829">
dirsrvtests/tests/suites/clu/dsidm_role_test.py
</a>
</li>
<li class="file-stats">
<a href="#0d4f42c55d72d4d228cd3d3df9aa45114ebb829a">
dirsrvtests/tests/suites/clu/dsidm_services_test.py
</a>
</li>
<li class="file-stats">
<a href="#92f3dd5e39ce525c2982ce2c905adb75c7a29207">
dirsrvtests/tests/suites/clu/dsidm_uniquegroup_test.py
</a>
</li>
<li class="file-stats">
<a href="#eca558026d3a0da0dce9f9e2ad3ba4e6163b13e9">
<span class="new-file">
+
dirsrvtests/tests/suites/clu/dsidm_user_get_pwp_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#fedb22e18b12871bf68be6a1a101aac3fc558a5b">
dirsrvtests/tests/suites/clu/dsidm_user_test.py
</a>
</li>
<li class="file-stats">
<a href="#75d2518d05bed33c24452fb3c1e516778d9848a7">
dirsrvtests/tests/suites/clu/dsrc_test.py
</a>
</li>
<li class="file-stats">
<a href="#bed90afa9050f296062ed186ab4472f7afb0ca29">
dirsrvtests/tests/suites/clu/fixup_test.py
</a>
</li>
<li class="file-stats">
<a href="#68af6d903f24a3d6e412eea54831dfa9bfea04b7">
dirsrvtests/tests/suites/clu/repl_monitor_test.py
</a>
</li>
<li class="file-stats">
<a href="#1a0f459ae8121525e3b7dffe146488b3c4e7ce2a">
dirsrvtests/tests/suites/clu/schema_test.py
</a>
</li>
<li class="file-stats">
<a href="#d91b518e9efbe6bcd106b718ec493bfcfd5049e3">
<span class="new-file">
+
dirsrvtests/tests/suites/clu/task_shutdown_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#cfd304e4ae8a8c789bb8af1a172645b4c3d90513">
dirsrvtests/tests/suites/config/autotuning_test.py
</a>
</li>
<li class="file-stats">
<a href="#3263bb6ee399ac2f4aa72de3eb71f7e2871cb178">
dirsrvtests/tests/suites/config/compact_test.py
</a>
</li>
<li class="file-stats">
<a href="#3a4cc9a05b01d4359216a82fa65b3afb5ab8fe17">
dirsrvtests/tests/suites/config/config_delete_attr_test.py
</a>
</li>
<li class="file-stats">
<a href="#e08020dfe9247cd66ca3076ffce8c056447acca5">
dirsrvtests/tests/suites/config/config_test.py
</a>
</li>
<li class="file-stats">
<a href="#845bf85fec68690ba0f18e6f53eac09d0f96eaf4">
dirsrvtests/tests/suites/config/regression_test.py
</a>
</li>
<li class="file-stats">
<a href="#4d3153fd8d07caa4ee3450c129aca444c7c4a0e6">
dirsrvtests/tests/suites/config/removed_config_49298_test.py
</a>
</li>
<li class="file-stats">
<a href="#5e3e0cd4d447f444fb00c466ff67d9b10a09b436">
dirsrvtests/tests/suites/cos/cos_test.py
</a>
</li>
<li class="file-stats">
<a href="#8a137d4d16d6359573a99e246edfa08973d10ae4">
dirsrvtests/tests/suites/cos/indirect_cos_test.py
</a>
</li>
<li class="file-stats">
<a href="#709d7a875618a96d702e742a1208d61f069b3497">
dirsrvtests/tests/suites/disk_monitoring/disk_monitoring_divide_test.py
</a>
</li>
<li class="file-stats">
<a href="#294cf48041d0487b438a4bf6b4512d037784881c">
dirsrvtests/tests/suites/disk_monitoring/disk_monitoring_test.py
</a>
</li>
<li class="file-stats">
<a href="#af9adec64ac02895bb46525c188b5899eef4ae9c">
dirsrvtests/tests/suites/disk_monitoring/disk_space_test.py
</a>
</li>
<li class="file-stats">
<a href="#0cf60f6dd8f3971a6768c130c3a9e6b7738742e7">
dirsrvtests/tests/suites/ds_logs/audit_log_test.py
</a>
</li>
<li class="file-stats">
<a href="#1ebff6c3e6c4ffd2428487fa84244ea5eb7abfcd">
dirsrvtests/tests/suites/ds_logs/ds_logs_test.py
</a>
</li>
<li class="file-stats">
<a href="#9a3d297ec2a73b0d8eda388f8ea2e41abd9d510c">
dirsrvtests/tests/suites/ds_logs/regression_test.py
</a>
</li>
<li class="file-stats">
<a href="#2f916ce59c28d4e9f1fec5b7cf8045d702e2a594">
dirsrvtests/tests/suites/ds_tools/logpipe_test.py
</a>
</li>
<li class="file-stats">
<a href="#9c17fe39490c38fd25f8f030e58fcf1c927b5b15">
dirsrvtests/tests/suites/ds_tools/replcheck_test.py
</a>
</li>
<li class="file-stats">
<a href="#44a6b479aa81121145ce0e7ab200f30578ff59be">
dirsrvtests/tests/suites/dynamic_lists/dynamic_lists_test.py
</a>
</li>
<li class="file-stats">
<a href="#a96bab5a9d6b771c53fd6648232940759bbe97e9">
dirsrvtests/tests/suites/dynamic_plugins/dynamic_plugins_test.py
</a>
</li>
<li class="file-stats">
<a href="#c083654337e052015350f670678747cb059ea49e">
dirsrvtests/tests/suites/dynamic_plugins/notice_for_restart_test.py
</a>
</li>
<li class="file-stats">
<a href="#30450d53b9fbd1abec1a2d125e1b9776c2e34ce8">
dirsrvtests/tests/suites/entryuuid/basic_test.py
</a>
</li>
<li class="file-stats">
<a href="#fd12c738fd095081d1f8264f923cf201915e50e1">
dirsrvtests/tests/suites/entryuuid/replicated_test.py
</a>
</li>
<li class="file-stats">
<a href="#b76a708214fc04c5e9763c8578d5468f6a6f8cbe">
<span class="new-file">
+
dirsrvtests/tests/suites/export/export_reindex_tombstone_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#54618436f0e8023b5307423069bb42bdb9cc4f64">
dirsrvtests/tests/suites/export/export_test.py
</a>
</li>
<li class="file-stats">
<a href="#be9c59b725ddb11809c075612e02172944754cc5">
dirsrvtests/tests/suites/features/entrycache_eviction_test.py
</a>
</li>
<li class="file-stats">
<a href="#d2c04292e1bca4c49882ddb67c089abe9f58a760">
dirsrvtests/tests/suites/features/ldap_controls_test.py
</a>
</li>
<li class="file-stats">
<a href="#ab27f6ab1b55b70b8ad7afad859d69b4c15fde79">
dirsrvtests/tests/suites/filter/basic_filter_test.py
</a>
</li>
<li class="file-stats">
<a href="#ac442c6ac26b28267462e96891fb72ad5d296fc9">
dirsrvtests/tests/suites/filter/bitw_filter_test.py
</a>
</li>
<li class="file-stats">
<a href="#668ccad77b876b3e9e1dffcdaab0ae4c6aa69e27">
dirsrvtests/tests/suites/filter/complex_filters_test.py
</a>
</li>
<li class="file-stats">
<a href="#9d1e378bf1270594d4b71518bfb29e046dd54834">
dirsrvtests/tests/suites/filter/filter_aci_with_optimiser_test.py
</a>
</li>
<li class="file-stats">
<a href="#bb944569afdadf51093c8b99ecb51ec038a1c566">
dirsrvtests/tests/suites/filter/filter_cert_test.py
</a>
</li>
<li class="file-stats">
<a href="#b99b6a510721fcc8ff391930e4f83ff89f4ea8b4">
dirsrvtests/tests/suites/filter/filter_index_match_test.py
</a>
</li>
<li class="file-stats">
<a href="#2eb348962594be0beaa3cf740b81ce427b6bc49d">
dirsrvtests/tests/suites/filter/filter_indexing_test.py
</a>
</li>
<li class="file-stats">
<a href="#8e893c2c33e17626c575812219d1c45ed1173e14">
dirsrvtests/tests/suites/filter/filter_logic_test.py
</a>
</li>
<li class="file-stats">
<a href="#8da96cc895417f55aae267e6abdbac950ead7426">
dirsrvtests/tests/suites/filter/filter_match_test.py
</a>
</li>
<li class="file-stats">
<a href="#4225df1db45d16be7cb3cdd593d3c9f68ee3cd35">
dirsrvtests/tests/suites/filter/filter_onelevel_aci_test.py
</a>
</li>
<li class="file-stats">
<a href="#e23142c4156b0dd0e4db23cd138a941b334d8258">
dirsrvtests/tests/suites/filter/filter_test.py
</a>
</li>
<li class="file-stats">
<a href="#7d5ffafbaf5816f662280ee52de7d37f5b8d08be">
dirsrvtests/tests/suites/filter/filter_with_non_root_user_test.py
</a>
</li>
<li class="file-stats">
<a href="#3a9eef3e4bba4e2fa444ded6329a4ac965fd7afb">
dirsrvtests/tests/suites/filter/filterscanlimit_test.py
</a>
</li>
<li class="file-stats">
<a href="#2a74543836ede72b6a2909e3b758ac8a5f684cba">
dirsrvtests/tests/suites/filter/inchain_test.py
</a>
</li>
<li class="file-stats">
<a href="#a818a349627914e04fb3ed6a36a907ab4b973973">
dirsrvtests/tests/suites/filter/large_filter_test.py
</a>
</li>
<li class="file-stats">
<a href="#f3ea6275b06beb8b1a73f141ecd5f4a3a8d81769">
dirsrvtests/tests/suites/filter/rfc3673_all_oper_attrs_test.py
</a>
</li>
<li class="file-stats">
<a href="#a071e2b9a31a280656bcb9cdf9d1f9b2943f28de">
dirsrvtests/tests/suites/filter/schema_validation_test.py
</a>
</li>
<li class="file-stats">
<a href="#c537061fd9c6039e2e946a10acf1ae654bd7f297">
dirsrvtests/tests/suites/filter/vfilter_attribute_test.py
</a>
</li>
<li class="file-stats">
<a href="#f5c607c75c04ac871f6d6e1b6e86e7d8c37433da">
dirsrvtests/tests/suites/filter/vfilter_simple_test.py
</a>
</li>
<li class="file-stats">
<a href="#f8aed133783e4c4d76c8c690ae5f19cdade5f505">
dirsrvtests/tests/suites/fourwaymmr/fourwaymmr_test.py
</a>
</li>
<li class="file-stats">
<a href="#6b0ef0e5b6a4fe980a5746350b7251d485cce183">
dirsrvtests/tests/suites/fractional/fractional_test.py
</a>
</li>
<li class="file-stats">
<a href="#3bbaed456857b02bad48dd6eebc10b4d084e81e5">
dirsrvtests/tests/suites/get_effective_rights/acceptance_test.py
</a>
</li>
<li class="file-stats">
<a href="#0acf2fe75cf0f2a1a013192b22b259795f1925de">
dirsrvtests/tests/suites/gssapi/simple_gssapi_test.py
</a>
</li>
<li class="file-stats">
<a href="#3db4d44b3090393559e3b916e1e66353802d2b2f">
dirsrvtests/tests/suites/gssapi_repl/gssapi_repl_test.py
</a>
</li>
<li class="file-stats">
<a href="#39f7a64842816db3166920b259b7ff11943a1b93">
dirsrvtests/tests/suites/healthcheck/health_config_test.py
</a>
</li>
<li class="file-stats">
<a href="#4fffda4e4450146ec6e7cd088f40512bf8c9f3c0">
dirsrvtests/tests/suites/healthcheck/health_repl_test.py
</a>
</li>
<li class="file-stats">
<a href="#ec6c84dbd00abbf47a4694f4c4f1689112e18bb7">
dirsrvtests/tests/suites/healthcheck/health_security_test.py
</a>
</li>
<li class="file-stats">
<a href="#88620c04acf876fa645fc835a4e3789e2563a9ae">
<span class="new-file">
+
dirsrvtests/tests/suites/healthcheck/health_skew_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#f79b16cd3f3f03d9ee62d0ea6b77125524833b15">
dirsrvtests/tests/suites/healthcheck/health_system_indexes_test.py
</a>
</li>
<li class="file-stats">
<a href="#49b8a3643546a629798679b63c778c82d7a54447">
dirsrvtests/tests/suites/healthcheck/health_tunables_test.py
</a>
</li>
<li class="file-stats">
<a href="#fc745b7329408642ad5ca2846097fdbbb1cfc158">
dirsrvtests/tests/suites/healthcheck/healthcheck_test.py
</a>
</li>
<li class="file-stats">
<a href="#5f6b84baa8b5e5bd57e20409a72351c939537dc8">
<span class="new-file">
+
dirsrvtests/tests/suites/import/bulk_import_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#0735c3850847723c2a147a126b9df7f62397a3ed">
dirsrvtests/tests/suites/import/import_test.py
</a>
</li>
<li class="file-stats">
<a href="#f3ba1358d897fb891fd33f13763ade207aca3710">
dirsrvtests/tests/suites/import/import_warning_test.py
</a>
</li>
<li class="file-stats">
<a href="#8a71cb76126324fd29a365586568423c32d090ce">
dirsrvtests/tests/suites/import/regression_test.py
</a>
</li>
<li class="file-stats">
<a href="#4eb171006eaf23616f0fa5544ebfde9e98d5d9de">
dirsrvtests/tests/suites/indexes/entryrdn_test.py
</a>
</li>
<li class="file-stats">
<a href="#cf60c4b0c61d7b5be64086b5b02140f994c436dc">
dirsrvtests/tests/suites/indexes/huge_index_key_test.py
</a>
</li>
<li class="file-stats">
<a href="#f37bc5bbce1449101c04bedbb1ddaca9d234bba5">
dirsrvtests/tests/suites/indexes/regression_test.py
</a>
</li>
<li class="file-stats">
<a href="#4b1f421efe914e048f4d406f1debe4592f58d57d">
<span class="new-file">
+
dirsrvtests/tests/suites/indexes/reindex_abort_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#e58502916dd572c03e9ddabb5af80aad0373d2d9">
<span class="new-file">
+
dirsrvtests/tests/suites/indexes/substring_index_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#137bc87f90c267fd920569eeedf4fd5eba739e12">
dirsrvtests/tests/suites/ldapi/ldapi_test.py
</a>
</li>
<li class="file-stats">
<a href="#64a9c58081b2eeea543bed0b7b5cab54094eda24">
dirsrvtests/tests/suites/lib389/config_compare_test.py
</a>
</li>
<li class="file-stats">
<a href="#94b228d8e95303bab4ae47b8c33f1069141488f8">
dirsrvtests/tests/suites/lib389/dsldapobject/dn_construct_test.py
</a>
</li>
<li class="file-stats">
<a href="#afbcf2c4264985307b15130fd95672a9c7f25ea7">
dirsrvtests/tests/suites/lib389/idm/account_test.py
</a>
</li>
<li class="file-stats">
<a href="#433305b8c5d81c80f61b70344230d1dcffc3a08a">
dirsrvtests/tests/suites/lib389/idm/user_compare_i2_test.py
</a>
</li>
<li class="file-stats">
<a href="#d3f9d788602deb53b0fd1d6d0633c8182334d70e">
dirsrvtests/tests/suites/lib389/idm/user_compare_m2Repl_test.py
</a>
</li>
<li class="file-stats">
<a href="#daabc114560f11f09caa8ba711dc62fbc10e4439">
dirsrvtests/tests/suites/lib389/idm/user_compare_st_test.py
</a>
</li>
<li class="file-stats">
<a href="#43b326d097fb408686b022da4af688fdb709b561">
<span class="new-file">
+
dirsrvtests/tests/suites/lib389/subsuffix_tree_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#9723ebad6e9b2436d752af155d832649180b267a">
dirsrvtests/tests/suites/lib389/timeout_test.py
</a>
</li>
<li class="file-stats">
<a href="#ea6b957be4fc5dbaeb31a09fa33a8e4b4f3869f1">
<span class="new-file">
+
dirsrvtests/tests/suites/logging/access_fgot_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#f4054fba4005f791847454609a8a8583c9fc5fcd">
dirsrvtests/tests/suites/logging/access_json_logging_test.py
</a>
</li>
<li class="file-stats">
<a href="#35313b30d4b21d7a85911846e713cd3b560913cc">
<span class="new-file">
+
dirsrvtests/tests/suites/logging/async_log_compress_chain_uaf_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#2959895face223f4f3d1dc16b789360cb3138554">
dirsrvtests/tests/suites/logging/audit_json_logging_test.py
</a>
</li>
<li class="file-stats">
<a href="#d23aec57dfefd331432a0b45e58ff49eccebe7f5">
dirsrvtests/tests/suites/logging/audit_password_masking_test.py
</a>
</li>
<li class="file-stats">
<a href="#6c968d06832de4391715f66f871da3cbe06647c4">
<span class="new-file">
+
dirsrvtests/tests/suites/logging/auditlog_pwd_mask_overflow_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#ba47f0419495052628fdd1a997f717d2d81caf3d">
dirsrvtests/tests/suites/logging/error_json_logging_test.py
</a>
</li>
<li class="file-stats">
<a href="#7d86b7a687f664aac647586295c8e53a4542b2df">
dirsrvtests/tests/suites/logging/log_flush_rotation_test.py
</a>
</li>
<li class="file-stats">
<a href="#ad29855ccc7e920bf39cafbb124253d894e2c135">
dirsrvtests/tests/suites/logging/logconv_test.py
</a>
</li>
<li class="file-stats">
<a href="#9017541cc7c1ff5030cb7b3fd304e79d6f7141ef">
dirsrvtests/tests/suites/logging/logging_compression_test.py
</a>
</li>
<li class="file-stats">
<a href="#14a199e702e8ed15f287e0e7d1d431cca693883a">
dirsrvtests/tests/suites/logging/logging_config_test.py
</a>
</li>
<li class="file-stats">
<a href="#6f650c12250660b5839fa3db78aa4b906af7b917">
<span class="new-file">
+
dirsrvtests/tests/suites/logging/logging_long_path_compression_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#b4ee6be613b160fc6cf1909ba237759573ed7f74">
dirsrvtests/tests/suites/logging/security_basic_test.py
</a>
</li>
<li class="file-stats">
<a href="#d49f627e7e5c3d44ab0d2f099491c06e0fb2891e">
dirsrvtests/tests/suites/mapping_tree/acceptance_test.py
</a>
</li>
<li class="file-stats">
<a href="#27db641ab5a6b55cfc12879ac59c39328355b4e9">
dirsrvtests/tests/suites/mapping_tree/be_del_and_default_naming_attr_test.py
</a>
</li>
<li class="file-stats">
<a href="#536700de0b696a35c9d887fecf89e94f7a4205ab">
dirsrvtests/tests/suites/mapping_tree/mt_cursed_test.py
</a>
</li>
<li class="file-stats">
<a href="#879526db470e7dd651850f609946db0301143d71">
dirsrvtests/tests/suites/mapping_tree/referral_during_tot_init_test.py
</a>
</li>
<li class="file-stats">
<a href="#284a4857ca07d1206ac074677332fa1391ecc779">
dirsrvtests/tests/suites/mapping_tree/regression_test.py
</a>
</li>
<li class="file-stats">
<a href="#89772f1dd6d0ba1fa686a9135334b4d31496c356">
dirsrvtests/tests/suites/memberof_plugin/conftest.py
</a>
</li>
<li class="file-stats">
<a href="#bebf03d8b5bbe5e2795d2e2820c7f3c825ca6d87">
dirsrvtests/tests/suites/memberof_plugin/fixup_test.py
</a>
</li>
<li class="file-stats">
<a href="#bd1333fcbbd764be2243965686762fc072f93baa">
dirsrvtests/tests/suites/memberof_plugin/memberof_deferred_lmdb_test.py
</a>
</li>
<li class="file-stats">
<a href="#c04d890b1ba4620081b7f66ad055c330551c4ed6">
dirsrvtests/tests/suites/memberof_plugin/memberof_deferred_repl_test.py
</a>
</li>
<li class="file-stats">
<a href="#ae66b2d22037e059c4ccfe485c6eb4f5015af1ed">
<span class="new-file">
+
dirsrvtests/tests/suites/memberof_plugin/memberof_deferred_scope_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#98f3b669366988c7c4325050cafb56642b290842">
dirsrvtests/tests/suites/memberof_plugin/memberof_exclude_subtrees_test.py
</a>
</li>
<li class="file-stats">
<a href="#ca1bd3cf1003152005ad1cc1f45aa59784f5ff7b">
dirsrvtests/tests/suites/memberof_plugin/memberof_include_scopes_test.py
</a>
</li>
<li class="file-stats">
<a href="#4aa07fc5046d87edb7dd0cf0f4657eca4334f9fb">
<span class="new-file">
+
dirsrvtests/tests/suites/memberof_plugin/memberof_multi_backend_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#b77b62c92ef917eb85e9f028de27f1d0b6b9eae2">
dirsrvtests/tests/suites/memberof_plugin/memberof_skipnested_test.py
</a>
</li>
<li class="file-stats">
<a href="#55f85de76af819cd4f91f899e894df3885e39975">
dirsrvtests/tests/suites/memberof_plugin/memberof_specific_group_test.py
</a>
</li>
<li class="file-stats">
<a href="#9303d7ca0afb64dc8a858f4c94f1b815b625cb80">
dirsrvtests/tests/suites/memberof_plugin/nested_groups_test.py
</a>
</li>
<li class="file-stats">
<a href="#628bb6c6c3af6fd6f3b2b4c188f9b60e46c63b13">
dirsrvtests/tests/suites/memberof_plugin/regression_test.py
</a>
</li>
<li class="file-stats">
<a href="#16c077038cc7265ab6b979238edbd619e2af3561">
dirsrvtests/tests/suites/memory_leaks/MMR_double_free_test.py
</a>
</li>
<li class="file-stats">
<a href="#db5eabfd5b90d9b54ea3e8461d71b35eaae37926">
dirsrvtests/tests/suites/memory_leaks/allids_search_test.py
</a>
</li>
<li class="file-stats">
<a href="#6f2deb03aa1b5e4a760f4fc597537bf805596869">
dirsrvtests/tests/suites/memory_leaks/range_search_test.py
</a>
</li>
<li class="file-stats">
<a href="#5d81072243670687914b7659eae7476387d66a9d">
dirsrvtests/tests/suites/migration/export_data_test.py
</a>
</li>
<li class="file-stats">
<a href="#03b5abaee628ed36511c1fdc85f1b00158606e20">
dirsrvtests/tests/suites/migration/import_data_test.py
</a>
</li>
<li class="file-stats">
<a href="#6e19dc55dcd8954bd35a23366a26518920f4c8c3">
dirsrvtests/tests/suites/monitor/db_locks_monitor_test.py
</a>
</li>
<li class="file-stats">
<a href="#15b269c751477e9f09e90a212b2029898bbd32cf">
dirsrvtests/tests/suites/monitor/monitor_test.py
</a>
</li>
<li class="file-stats">
<a href="#c12d85ba9a34241e7f17ff5b2cac50f28465dfc3">
<span class="new-file">
+
dirsrvtests/tests/suites/monitor/threadpool_status_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#7a818e77ee781889719ed53dc115095812dd97b0">
dirsrvtests/tests/suites/openldap_2_389/migrate_hdb_test.py
</a>
</li>
<li class="file-stats">
<a href="#a3d800ebcf977ea4234b0ad8c9cb0843f686de2d">
dirsrvtests/tests/suites/openldap_2_389/migrate_memberof_test.py
</a>
</li>
<li class="file-stats">
<a href="#d2356a028ac016c59d447117d7a87c0370d6796e">
dirsrvtests/tests/suites/openldap_2_389/migrate_monitor_test.py
</a>
</li>
<li class="file-stats">
<a href="#1f62fde78e1271e0fa251dda583c40ef0c49bc95">
dirsrvtests/tests/suites/openldap_2_389/migrate_test.py
</a>
</li>
<li class="file-stats">
<a href="#f5135b9781d34df17bf04992587275cd75d7f216">
dirsrvtests/tests/suites/openldap_2_389/password_migrate_test.py
</a>
</li>
<li class="file-stats">
<a href="#0d59afce506e6c888e4e3e8be90208a6a8c46c00">
dirsrvtests/tests/suites/paged_results/paged_results_test.py
</a>
</li>
<li class="file-stats">
<a href="#9e61bdb5f84f60cd3218d939d0eb89eef7c5bd5e">
dirsrvtests/tests/suites/password/password_TPR_policy_test.py
</a>
</li>
<li class="file-stats">
<a href="#f90a4539b6f409b0e076891be7f43510a456c8a1">
dirsrvtests/tests/suites/password/password_policy_test.py
</a>
</li>
<li class="file-stats">
<a href="#e8f54ba39794e843eb2a0526b768b9939149555f">
dirsrvtests/tests/suites/password/password_test.py
</a>
</li>
<li class="file-stats">
<a href="#157b943e6213a9e5f4d1c654ff7e170dd8e711b5">
dirsrvtests/tests/suites/password/pbkdf2_upgrade_plugin_test.py
</a>
</li>
<li class="file-stats">
<a href="#b8bfc34f4d69fd9c3e8ef69d120bd9e4db34b6fe">
dirsrvtests/tests/suites/password/pw_expired_access_test.py
</a>
</li>
<li class="file-stats">
<a href="#70d243a145c3850912fa7b33ae6217f90d6d3d7b">
dirsrvtests/tests/suites/password/pwdAdmin_test.py
</a>
</li>
<li class="file-stats">
<a href="#179950064162fe97179174ae4b40affffa58cd15">
dirsrvtests/tests/suites/password/pwdModify_test.py
</a>
</li>
<li class="file-stats">
<a href="#7b1b490bb442f12b6656f61dec43b5e0d76cb3cb">
dirsrvtests/tests/suites/password/pwdPolicy_attribute_test.py
</a>
</li>
<li class="file-stats">
<a href="#4bdd5ea9e6675873c0c5b71f037c860b611ef05f">
<span class="new-file">
+
dirsrvtests/tests/suites/password/pwdPolicy_breach_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#c95c449ed9238b9d47f1385634ed4fdb1f891f7f">
dirsrvtests/tests/suites/password/pwdPolicy_controls_sequence_test.py
</a>
</li>
<li class="file-stats">
<a href="#c6193d64eb4014b0209822447918a509afe1c758">
dirsrvtests/tests/suites/password/pwdPolicy_controls_test.py
</a>
</li>
<li class="file-stats">
<a href="#976935f36dfdcd125c77062b94365c3ae1e687a3">
dirsrvtests/tests/suites/password/pwdPolicy_inherit_global_test.py
</a>
</li>
<li class="file-stats">
<a href="#93fce4e22c9151df8ed83e946ead10282ae98495">
dirsrvtests/tests/suites/password/pwdPolicy_logging_test.py
</a>
</li>
<li class="file-stats">
<a href="#b8d86245a5932b4871a7788b6dd267865fb647aa">
dirsrvtests/tests/suites/password/pwdPolicy_syntax_test.py
</a>
</li>
<li class="file-stats">
<a href="#8720567b121569895cebfeda0dbdb935e59a5ecd">
dirsrvtests/tests/suites/password/pwdPolicy_temporary_password_test.py
</a>
</li>
<li class="file-stats">
<a href="#6b085c3a69bfdfc2b9952ff0853d1a0318321dc3">
dirsrvtests/tests/suites/password/pwdPolicy_token_test.py
</a>
</li>
<li class="file-stats">
<a href="#82e8d648b6de67c756f8e92c781f5f2ae68c0b0a">
dirsrvtests/tests/suites/password/pwdPolicy_warning_test.py
</a>
</li>
<li class="file-stats">
<a href="#63422f651498245d3c7bc1d1caba371b4de637ed">
dirsrvtests/tests/suites/password/pwd_algo_test.py
</a>
</li>
<li class="file-stats">
<a href="#5dec8cda14eaf20a52c151b23788dcdc92050a29">
<span class="new-file">
+
dirsrvtests/tests/suites/password/pwd_check_prefix_crash_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#08fe5091e331e76547d33050466d285ecd08b07c">
dirsrvtests/tests/suites/password/pwd_crypt_asterisk_test.py
</a>
</li>
<li class="file-stats">
<a href="#74fe60d85b32fe7d8217c620d96ae650ffd0c27c">
dirsrvtests/tests/suites/password/pwd_lockout_bypass_test.py
</a>
</li>
<li class="file-stats">
<a href="#fba9dbf252189875712f3357bbe5c4f2d64aada1">
dirsrvtests/tests/suites/password/pwd_log_test.py
</a>
</li>
<li class="file-stats">
<a href="#b55ad34e935c1ac3b1923c7af95c5ec640e35bd7">
dirsrvtests/tests/suites/password/pwd_upgrade_on_bind_test.py
</a>
</li>
<li class="file-stats">
<a href="#4bf599f8fd5b47baa3f10403817a782c1418e027">
dirsrvtests/tests/suites/password/pwp_gracel_test.py
</a>
</li>
<li class="file-stats">
<a href="#708f3021922c5a4f5fbebc0140736d5edfa214a1">
dirsrvtests/tests/suites/password/pwp_history_local_override_test.py
</a>
</li>
<li class="file-stats">
<a href="#3b01b418741a169d1a08b985de2c0e7a5af2d117">
dirsrvtests/tests/suites/password/pwp_history_test.py
</a>
</li>
<li class="file-stats">
<a href="#b9e37c48352ba83ee425702a147fc930a6202c20">
dirsrvtests/tests/suites/password/pwp_test.py
</a>
</li>
<li class="file-stats">
<a href="#78914d4f9fa2162317edb8986547d93d11ee8fcc">
<span class="new-file">
+
dirsrvtests/tests/suites/password/pwpolicy_effective_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#858c4fe10fd8792a7f9fd18bdd0cb7fedd6c4dd7">
dirsrvtests/tests/suites/password/regression_of_bugs_test.py
</a>
</li>
<li class="file-stats">
<a href="#0c346db4210804de17b54ff2e626921589e116cb">
dirsrvtests/tests/suites/password/regression_test.py
</a>
</li>
<li class="file-stats">
<a href="#eed5e15b809a03ab9cafa60d09b635049425ff2a">
<span class="new-file">
+
dirsrvtests/tests/suites/password/uac_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#89c9b08b9450f9b4a6d49f9d4a2f63c6c24ce0a6">
dirsrvtests/tests/suites/plugins/acceptance_test.py
</a>
</li>
<li class="file-stats">
<a href="#299e5edec3212788c079dbd4579f8aa3433feba8">
dirsrvtests/tests/suites/plugins/account_policy_login_attr_test.py
</a>
</li>
<li class="file-stats">
<a href="#77c4a3bf5df7c947ab2222f7a44376179e383380">
dirsrvtests/tests/suites/plugins/accpol_check_all_state_attrs_test.py
</a>
</li>
<li class="file-stats">
<a href="#73003bc791f743b788d93eb4dd7f5a6a1de80278">
dirsrvtests/tests/suites/plugins/accpol_test.py
</a>
</li>
<li class="file-stats">
<a href="#b43b3af16a66116a3b7c17db58d8b56d8acbd43e">
<span class="new-file">
+
dirsrvtests/tests/suites/plugins/addn_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#19975738642d2378a3a16d26f4d6aabbe68622a8">
dirsrvtests/tests/suites/plugins/alias_entries_test.py
</a>
</li>
<li class="file-stats">
<a href="#c07b622e96fb40cdcdc38b58c9d4f87a52efb067">
dirsrvtests/tests/suites/plugins/attr_nsslapd-pluginarg_test.py
</a>
</li>
<li class="file-stats">
<a href="#5bdb3c6a8abaf36252bdb89e0e30982d6cae2766">
dirsrvtests/tests/suites/plugins/attruniq_test.py
</a>
</li>
<li class="file-stats">
<a href="#e20350c0044da215589de7ff961d5f94e8ea8393">
dirsrvtests/tests/suites/plugins/cos_test.py
</a>
</li>
<li class="file-stats">
<a href="#a9b89a1895bbf1589542830de4bb1761a96c3773">
dirsrvtests/tests/suites/plugins/deref_aci_test.py
</a>
</li>
<li class="file-stats">
<a href="#324d602b8a03badfe262e0e4a1c8f06e6a3abd61">
dirsrvtests/tests/suites/plugins/dna_interval_test.py
</a>
</li>
<li class="file-stats">
<a href="#f2e9a429598003e443d48cb330869d6402aebf9c">
dirsrvtests/tests/suites/plugins/dna_repl_test.py
</a>
</li>
<li class="file-stats">
<a href="#8b570eee8d25dd742309c4be464e2a0f9151dbd5">
dirsrvtests/tests/suites/plugins/dna_test.py
</a>
</li>
<li class="file-stats">
<a href="#b077cdcb6f215d4f98371a69a3d322d9a692525b">
dirsrvtests/tests/suites/plugins/entryusn_overflow_test.py
</a>
</li>
<li class="file-stats">
<a href="#26bf71a1004839aee569b52d76b0a6355a1afe02">
dirsrvtests/tests/suites/plugins/entryusn_test.py
</a>
</li>
<li class="file-stats">
<a href="#f52314d788f3188417490ba8e20319683be3bd7a">
dirsrvtests/tests/suites/plugins/linked_attributes_test.py
</a>
</li>
<li class="file-stats">
<a href="#d3ef3b7f75fa9b5fd709acf72e1bea6a8227bd12">
dirsrvtests/tests/suites/plugins/managed_entry_test.py
</a>
</li>
<li class="file-stats">
<a href="#7c41e921e950a603a50e81ae7dc3725b27b55b57">
dirsrvtests/tests/suites/plugins/memberof_test.py
</a>
</li>
<li class="file-stats">
<a href="#1508207594eac3830ed4a05a48c24f8f3e5b22ef">
dirsrvtests/tests/suites/plugins/modrdn_test.py
</a>
</li>
<li class="file-stats">
<a href="#563c37998de6511e7c67e168b85a7ac6b415c23c">
dirsrvtests/tests/suites/plugins/pam_pta_test.py
</a>
</li>
<li class="file-stats">
<a href="#aff0ce2f0881dc32772aa163e736facd500e1086">
dirsrvtests/tests/suites/plugins/pluginpath_validation_test.py
</a>
</li>
<li class="file-stats">
<a href="#87cc6ed156e225d79a74962e7a381664206eeb73">
dirsrvtests/tests/suites/plugins/referint_test.py
</a>
</li>
<li class="file-stats">
<a href="#d1a4e21e0e7681e37de687a9dbd77807bc863f3c">
dirsrvtests/tests/suites/plugins/rootdn_plugin_test.py
</a>
</li>
<li class="file-stats">
<a href="#43c4ce6e5ed959ca8919b1f78276e9a1bc68239a">
dirsrvtests/tests/suites/psearch/psearch_test.py
</a>
</li>
<li class="file-stats">
<a href="#5dc7395650d32aff34deb0b607d23c579260cada">
dirsrvtests/tests/suites/pwp_storage/storage_test.py
</a>
</li>
<li class="file-stats">
<a href="#27fc8ea4bb4aaba58f982da7502663b973cd680b">
<span class="new-file">
+
dirsrvtests/tests/suites/referint_plugin/memberof_duplicate_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#fbf4a68c9a488741824aa23ba9a4e5961280fee6">
dirsrvtests/tests/suites/referint_plugin/rename_test.py
</a>
</li>
<li class="file-stats">
<a href="#dae58349ae9bf707b7d6a70913228c26d819c9c7">
dirsrvtests/tests/suites/replication/acceptance_test.py
</a>
</li>
<li class="file-stats">
<a href="#bc4ad6a527ea305d41867c55903b1a550b24f926">
dirsrvtests/tests/suites/replication/acl_replication_test.py
</a>
</li>
<li class="file-stats">
<a href="#fb482513e525e6fc816a4b01c4b2b76df7f1a9d1">
dirsrvtests/tests/suites/replication/cascading_test.py
</a>
</li>
<li class="file-stats">
<a href="#a68d16bb1c342d0192c4ce7c52d201caceac1de8">
dirsrvtests/tests/suites/replication/changelog_encryption_test.py
</a>
</li>
<li class="file-stats">
<a href="#f1c8a8c7c1054b54d893cb7719717fd739372988">
dirsrvtests/tests/suites/replication/changelog_test.py
</a>
</li>
<li class="file-stats">
<a href="#1af02cb4ea115d42c1c034070f6941b58fe8db81">
dirsrvtests/tests/suites/replication/changelog_trimming_test.py
</a>
</li>
<li class="file-stats">
<a href="#4747bdf339533601845a80225918d3b10b26f3a2">
dirsrvtests/tests/suites/replication/cleanallruv_abort_certify_test.py
</a>
</li>
<li class="file-stats">
<a href="#c59ef082d8b52f9b8d3f44347c334105b071df17">
dirsrvtests/tests/suites/replication/cleanallruv_abort_restart_test.py
</a>
</li>
<li class="file-stats">
<a href="#79d54ce04d4b8f4474429fe866165c94bf43cf1f">
dirsrvtests/tests/suites/replication/cleanallruv_abort_test.py
</a>
</li>
<li class="file-stats">
<a href="#f4d512b18a6e71c5523cf2cca84871397a1f1bec">
dirsrvtests/tests/suites/replication/cleanallruv_force_test.py
</a>
</li>
<li class="file-stats">
<a href="#cacb41ae444107d418430fe1080cdcb6b1507c9e">
dirsrvtests/tests/suites/replication/cleanallruv_fractional_test.py
</a>
</li>
<li class="file-stats">
<a href="#3afb79b1fa79ea6ebd4b76305687a0a0319294c6">
dirsrvtests/tests/suites/replication/cleanallruv_max_tasks_test.py
</a>
</li>
<li class="file-stats">
<a href="#9d40eb8fd74e2902fc5c1b67fba75b86111155de">
dirsrvtests/tests/suites/replication/cleanallruv_multiple_force_test.py
</a>
</li>
<li class="file-stats">
<a href="#b2985abf6fbda0bba57ad6a0ee5c48864dafd4c9">
dirsrvtests/tests/suites/replication/cleanallruv_restart_test.py
</a>
</li>
<li class="file-stats">
<a href="#50d88c35c06dd9e2e400868bd1971466712d69f4">
dirsrvtests/tests/suites/replication/cleanallruv_shutdown_crash_test.py
</a>
</li>
<li class="file-stats">
<a href="#585c907696499d0a7cd40d9b03733d14564c4dbf">
dirsrvtests/tests/suites/replication/cleanallruv_stress_test.py
</a>
</li>
<li class="file-stats">
<a href="#92214462dd71b1f9bbd54b90970169251eabb82f">
dirsrvtests/tests/suites/replication/cleanallruv_test.py
</a>
</li>
<li class="file-stats">
<a href="#221e2a1e8223921b503a49629370893b6cbdc06b">
<span class="new-file">
+
dirsrvtests/tests/suites/replication/cleanruv_extop_security_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#362c4f2e583c9c0f8e5642e8d2584fdee80633f9">
dirsrvtests/tests/suites/replication/conftest.py
</a>
</li>
<li class="file-stats">
<a href="#938c865101384685a131d87ca825aacabda9cae1">
dirsrvtests/tests/suites/replication/encryption_cl5_test.py
</a>
</li>
<li class="file-stats">
<a href="#5e2d54b335b35ace3c656d07ce96d1a0523899b3">
<span class="new-file">
+
dirsrvtests/tests/suites/replication/mmr_single_value_conflict_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#142f2f6733e35a0350c077515ad9cec0bc1b0f98">
dirsrvtests/tests/suites/replication/multiple_changelogs_test.py
</a>
</li>
<li class="file-stats">
<a href="#4fbb3c6bd7ec8929369755ea10062fe07dbac706">
dirsrvtests/tests/suites/replication/numsubordinates_replication_test.py
</a>
</li>
<li class="file-stats">
<a href="#b9f23b2316c11720dbefcd5b5d45ecfa6b86c322">
<span class="new-file">
+
dirsrvtests/tests/suites/replication/online_import_nosync_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#ea845cad43cbb763bed343905f9ef36a2c51b2b9">
dirsrvtests/tests/suites/replication/promote_demote_test.py
</a>
</li>
<li class="file-stats">
<a href="#77930eaf1e124a6748412d629ca10ff23d357d03">
dirsrvtests/tests/suites/replication/regression_i2_test.py
</a>
</li>
<li class="file-stats">
<a href="#4ac91f2ad01602a177c4a0c7c0f366e34973d0d2">
dirsrvtests/tests/suites/replication/regression_m2_test.py
</a>
</li>
<li class="file-stats">
<a href="#ccb5f2a83c0ef7f337d9ebf570c1ccbe214088b3">
dirsrvtests/tests/suites/replication/regression_m2c1_test.py
</a>
</li>
<li class="file-stats">
<a href="#17adacb55a325a4e1250c3ac6c94bb1642e32152">
dirsrvtests/tests/suites/replication/regression_m2c2_test.py
</a>
</li>
<li class="file-stats">
<a href="#e056226c9f23df3ceb0d6cb89b502d5e49bedfeb">
dirsrvtests/tests/suites/replication/regression_m3_test.py
</a>
</li>
<li class="file-stats">
<a href="#52b0dca1069020acdd7603f19d82a3029b0b350f">
dirsrvtests/tests/suites/replication/repl_agmt_bootstrap_test.py
</a>
</li>
<li class="file-stats">
<a href="#3387af8984800d5d664102e5e33edb3dd710b50f">
dirsrvtests/tests/suites/replication/repl_conflict_delete_modify_test.py
</a>
</li>
<li class="file-stats">
<a href="#f843e586bfc249cc1bc10cc4ade5cbc323f01cd3">
dirsrvtests/tests/suites/replication/repl_log_monitoring_test.py
</a>
</li>
<li class="file-stats">
<a href="#8e69d4b157cab694e049845f4beaa9a8beffe75c">
dirsrvtests/tests/suites/replication/replica_config_test.py
</a>
</li>
<li class="file-stats">
<a href="#d35d1e5a6d2207a3f0da4e5e6cb8fe4c0e9b41a4">
dirsrvtests/tests/suites/replication/replica_roles_test.py
</a>
</li>
<li class="file-stats">
<a href="#f90df458aadc8d476a5e50f9f099fd5838119934">
dirsrvtests/tests/suites/replication/replication_deadlock_test.py
</a>
</li>
<li class="file-stats">
<a href="#73301fddc84aa753db956361ec13077084389688">
<span class="new-file">
+
dirsrvtests/tests/suites/replication/ruv_before_suffix_entryid_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#346277661c7722b540ff6afa1e867184978a41c5">
dirsrvtests/tests/suites/replication/ruvstore_test.py
</a>
</li>
<li class="file-stats">
<a href="#9ca79c635087bb396ded11b5b889c9b467659c98">
dirsrvtests/tests/suites/replication/sasl_m2_test.py
</a>
</li>
<li class="file-stats">
<a href="#eba38f6022c7b43f0027af684025da4fb96f8ac0">
dirsrvtests/tests/suites/replication/selfdn_acl_replication_test.py
</a>
</li>
<li class="file-stats">
<a href="#a53caad8dc94f0c33cdaad906264be1363d0d02a">
dirsrvtests/tests/suites/replication/series_of_repl_bugs_test.py
</a>
</li>
<li class="file-stats">
<a href="#0a7898144c86141bfff54584ff9251137342c3c6">
dirsrvtests/tests/suites/replication/single_master_test.py
</a>
</li>
<li class="file-stats">
<a href="#aec0a2bebf305673c46968ae52255afa3571c7f4">
<span class="new-file">
+
dirsrvtests/tests/suites/replication/startrepl_auth_race_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#01d98a0dbc120e7cacdf71d4b77a834e3e570fc5">
dirsrvtests/tests/suites/replication/tls_client_auth_repl_test.py
</a>
</li>
<li class="file-stats">
<a href="#e9b0e49c3e6f1520145a66740867b78915830568">
dirsrvtests/tests/suites/replication/tombstone_fixup_test.py
</a>
</li>
<li class="file-stats">
<a href="#e8196a63819805f1b25c6c26cd595fa13b1aedd8">
dirsrvtests/tests/suites/replication/tombstone_repl_mods_test.py
</a>
</li>
<li class="file-stats">
<a href="#daa352f89f4f6e6f5e3e9537142279d0bd221455">
dirsrvtests/tests/suites/replication/tombstone_test.py
</a>
</li>
<li class="file-stats">
<a href="#ebc6ea2f358d0dab467be9291b3d53ba58050805">
dirsrvtests/tests/suites/replication/urp_test.py
</a>
</li>
<li class="file-stats">
<a href="#71e7612fa0800f43ff15c54065fcee4d72eb699b">
dirsrvtests/tests/suites/replication/virtual_attribute_replication_test.py
</a>
</li>
<li class="file-stats">
<a href="#f1b04d93b7fbd80050c5d608aa77407aa29c49dc">
dirsrvtests/tests/suites/replication/wait_for_async_feature_test.py
</a>
</li>
<li class="file-stats">
<a href="#deab23957ad5d3228072c65932e6535ab7edbecf">
dirsrvtests/tests/suites/resource_limits/fdlimits_test.py
</a>
</li>
<li class="file-stats">
<a href="#2bb7320f7de6f5add4b1ae6c0988cfe24acebbf0">
dirsrvtests/tests/suites/retrocl/basic_test.py
</a>
</li>
<li class="file-stats">
<a href="#099969c604c06b3085d1c31dab80b58456d46b49">
<span class="new-file">
+
dirsrvtests/tests/suites/retrocl/regression_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#df7773bb1ae484c7e0ff05d5bb9b8cff7962b9c3">
dirsrvtests/tests/suites/retrocl/retrocl_indexing_test.py
</a>
</li>
<li class="file-stats">
<a href="#344e6528438d36a3350ff31dfc8ae27183f19c89">
dirsrvtests/tests/suites/rewriters/adfilter_test.py
</a>
</li>
<li class="file-stats">
<a href="#6238ef74deb817b95746b0b6614524e07d9e92cb">
dirsrvtests/tests/suites/rewriters/basic_test.py
</a>
</li>
<li class="file-stats">
<a href="#e8b453c3e981702f0aa6b10f6f1bb0ea7a56af94">
dirsrvtests/tests/suites/roles/basic_test.py
</a>
</li>
<li class="file-stats">
<a href="#8f16bccd80e5a2b76018787b142b4d66189520a3">
dirsrvtests/tests/suites/sasl/allowed_mechs_test.py
</a>
</li>
<li class="file-stats">
<a href="#ff2de6edd4094bad04e180e80d7c15a7b1ddf1d7">
<span class="new-file">
+
dirsrvtests/tests/suites/sasl/io_overflow_asan_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#f87760415fb967291b76b8108b033ab4b0a0aafb">
dirsrvtests/tests/suites/sasl/plain_test.py
</a>
</li>
<li class="file-stats">
<a href="#5154131c14d9aec021837a09282f877ef651e8dc">
dirsrvtests/tests/suites/sasl/regression_test.py
</a>
</li>
<li class="file-stats">
<a href="#8e9f4640c2d3ddc48ffbee1f881e642d3bb8278e">
<span class="new-file">
+
dirsrvtests/tests/suites/sasl/sasl_io_overflow_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#f223a92b8468f056000d3907e568c39b7704667f">
<span class="new-file">
+
dirsrvtests/tests/suites/sasl/sasl_stale_identity_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#75d0a29eefa9249e5b0faecaf84755a388084559">
dirsrvtests/tests/suites/schema/eduperson_test.py
</a>
</li>
<li class="file-stats">
<a href="#445df1898c72574c1d8a1c35283676729b5b3528">
dirsrvtests/tests/suites/schema/schema_csn_replication_test.py
</a>
</li>
<li class="file-stats">
<a href="#7eb546c84578cd9367031703123266408cbfcf9e">
<span class="new-file">
+
dirsrvtests/tests/suites/schema/schema_oc_sup_overflow_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#b24aaee280699ef9f26ac5d09866912f5d2825db">
<span class="new-file">
+
dirsrvtests/tests/suites/schema/schema_reload_heap_use_after_free_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#36ba90d1d0629341f194517bcc427d37d8ee6a65">
dirsrvtests/tests/suites/schema/schema_reload_test.py
</a>
</li>
<li class="file-stats">
<a href="#d0e2546261a3c9f6b58833d9a09301715b85914a">
dirsrvtests/tests/suites/schema/schema_replication_origin_test.py
</a>
</li>
<li class="file-stats">
<a href="#2389cae51abd567ce3afdd7b0125834b3e9991ea">
dirsrvtests/tests/suites/schema/schema_replication_test.py
</a>
</li>
<li class="file-stats">
<a href="#2f9c016f4ccf900f525fa376abb33a6153ff8193">
dirsrvtests/tests/suites/schema/schema_standard_update_test.py
</a>
</li>
<li class="file-stats">
<a href="#48f285b3b2fd9c0d687f4ce6bb4092a944c5eb5b">
dirsrvtests/tests/suites/schema/schema_test.py
</a>
</li>
<li class="file-stats">
<a href="#a5d7c86dff597333290df72fb528286e984cc4f4">
dirsrvtests/tests/suites/schema/schema_update_policy_test.py
</a>
</li>
<li class="file-stats">
<a href="#ee1a7e03abdad4e4dddad65869b6b3958596c22e">
dirsrvtests/tests/suites/schema/x_attribute_descr_oid_test.py
</a>
</li>
<li class="file-stats">
<a href="#fc0a321a7ef066910f5ebdc3547416a5a8ed0335">
dirsrvtests/tests/suites/session_tracking/session_test.py
</a>
</li>
<li class="file-stats">
<a href="#a562af8468ffb6dbf550f2ac7dff2a0275f6559a">
dirsrvtests/tests/suites/setup_ds/db_home_test.py
</a>
</li>
<li class="file-stats">
<a href="#8bbfd666a291516b048108c252d6700f30849b2a">
dirsrvtests/tests/suites/setup_ds/remove_test.py
</a>
</li>
<li class="file-stats">
<a href="#e8209d0c30b8f9e4c314dabc05114c978512b573">
dirsrvtests/tests/suites/slapi_memberof/basic_interface_test.py
</a>
</li>
<li class="file-stats">
<a href="#8463b98a8eafa77f13608d3f94e169e1d6ad2542">
<span class="new-file">
+
dirsrvtests/tests/suites/snmp/regression_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#50855f5375fa38f5cb853078eb69f5c2255dd9cf">
dirsrvtests/tests/suites/state/mmt_state_test.py
</a>
</li>
<li class="file-stats">
<a href="#4de0a2558fccee345c4cf30d233ddcc020e36699">
dirsrvtests/tests/suites/subentries/subentries_test.py
</a>
</li>
<li class="file-stats">
<a href="#728e34ef55f390f8e9348bd2c29e552d166b6f1e">
dirsrvtests/tests/suites/syncrepl_plugin/__init__.py
</a>
</li>
<li class="file-stats">
<a href="#01c0a527c514aea727e5f5808ef03699dda0dbcc">
dirsrvtests/tests/suites/syncrepl_plugin/basic_test.py
</a>
</li>
<li class="file-stats">
<a href="#193c24137e33771b2da594464b7902de304bf11b">
<span class="new-file">
+
dirsrvtests/tests/suites/syncrepl_plugin/clu_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#def891689af18398af6e6f178a550ed3db6acb41">
dirsrvtests/tests/suites/syncrepl_plugin/openldap_test.py
</a>
</li>
<li class="file-stats">
<a href="#970692628d656315c2df697f560df6b846d50ab1">
dirsrvtests/tests/suites/syntax/acceptance_test.py
</a>
</li>
<li class="file-stats">
<a href="#dd9ac5c5fd7d2377682c5160c2b89cf8c61b4135">
dirsrvtests/tests/suites/syntax/mr_test.py
</a>
</li>
<li class="file-stats">
<a href="#afbe0feec02a9421eaebc30d77a192a6e72e43e0">
<span class="new-file">
+
dirsrvtests/tests/suites/threads/__init__.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#ea6f26f0967c71d1ed48c39b616ceb345a69717f">
<span class="new-file">
+
dirsrvtests/tests/suites/threads/thread_naming_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#15d661cefde6f781f51860466e29c0e3509ae14e">
dirsrvtests/tests/suites/tls/cipher_test.py
</a>
</li>
<li class="file-stats">
<a href="#734cde7d6f013ee6acb169a191fa4c00c7bcf40c">
<span class="new-file">
+
dirsrvtests/tests/suites/tls/dynamic_certificates_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#fc97af4039c17197a360105c195aba05eae009d5">
dirsrvtests/tests/suites/tls/ecdsa_test.py
</a>
</li>
<li class="file-stats">
<a href="#a5dcf621774a3d9e3c22193cb12fb3a32e023c52">
<span class="new-file">
+
dirsrvtests/tests/suites/tls/mldsa_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#e59d38a3809e66b8ae148a6d859f2dd4575a2454">
dirsrvtests/tests/suites/tls/ssl_version_test.py
</a>
</li>
<li class="file-stats">
<a href="#e06e4ec12fb7310d135d592566afec651181e1b7">
dirsrvtests/tests/suites/tls/tls_cert_namespace_test.py
</a>
</li>
<li class="file-stats">
<a href="#26ed52c81f67ed44cbf61e691143cf505a0d44b5">
dirsrvtests/tests/suites/tls/tls_check_crl_test.py
</a>
</li>
<li class="file-stats">
<a href="#271b9192ac72a6562fca5d7cd82ca77f218849a5">
dirsrvtests/tests/suites/tls/tls_import_ca_chain_test.py
</a>
</li>
<li class="file-stats">
<a href="#11e8b1ba02504daf2a53a5e07d9c37ae62f179d4">
dirsrvtests/tests/suites/tls/tls_ldaps_only_test.py
</a>
</li>
<li class="file-stats">
<a href="#6c819634748c054b53d0dc14aeeaf6e633b3917c">
<span class="new-file">
+
dirsrvtests/tests/suites/tls/tls_renegotiation_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#72b048b29ec34cad9e0ed283bb56f1c961f8f8df">
dirsrvtests/tests/suites/tls/tls_repl_clientauth_test.py
</a>
</li>
<li class="file-stats">
<a href="#78e6363fed887988597feec3a8ebe2076951edf6">
dirsrvtests/tests/suites/upgrade/upgrade_bdb2mdb_test.py
</a>
</li>
<li class="file-stats">
<a href="#d67a5068a12e7591caecc65cd45612187c222dfe">
<span class="new-file">
+
dirsrvtests/tests/suites/upgrade/upgrade_plugin_attribute.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#9afd5f0e821940b2b6b3c2c94e2dc4d39bb53c30">
dirsrvtests/tests/suites/upgrade/upgrade_repl_plugin_test.py
</a>
</li>
<li class="file-stats">
<a href="#829c98f1145843439efea83a4b0c4884a1fd2bc4">
dirsrvtests/tests/suites/upgrade/upgradednformat_test.py
</a>
</li>
<li class="file-stats">
<a href="#481e35ffbed0467999485c9d0a0454acc5a3a60a">
<span class="new-file">
+
dirsrvtests/tests/suites/usdt/__init__.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#82e5b9171ce312627ed7b112160a0bfdad060e40">
<span class="new-file">
+
dirsrvtests/tests/suites/usdt/_common.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#ba476cf19148159d3b9e0e7f144159229c81ec3e">
<span class="new-file">
+
dirsrvtests/tests/suites/usdt/usdt_bpftrace_scripts_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#89f1a92cdc9731a5332961410a8555f406fe854e">
<span class="new-file">
+
dirsrvtests/tests/suites/usdt/usdt_probes_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#a8892c54a0ebda21d84923d0209a45c288417c8e">
<span class="new-file">
+
dirsrvtests/tests/suites/usdt/usdt_stap_scripts_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#0d322197e40595f5d39e262ad1220728980ebc78">
<span class="new-file">
+
dirsrvtests/tests/suites/usdt/usdt_tracing_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#a691d402a62ffc06a2088f9f3f36e0cdfc07e68a">
dirsrvtests/tests/suites/vlv/regression_test.py
</a>
</li>
<li class="file-stats">
<a href="#cbad9d1be89ca520d86e5db02643e2a2d22e8e87">
dirsrvtests/tests/suites/webui/__init__.py
</a>
</li>
<li class="file-stats">
<a href="#6a0b45df24cecb7422ee3dba32a5bbb3454ae0dd">
dirsrvtests/tests/suites/webui/backup/backup_test.py
</a>
</li>
<li class="file-stats">
<a href="#45090aef19fb634b7d46a3c577a53ddba4670168">
dirsrvtests/tests/suites/webui/create/create_instance_test.py
</a>
</li>
<li class="file-stats">
<a href="#db49216a629e37327290c3c79f909f32ee3ae93a">
dirsrvtests/tests/suites/webui/database/database_test.py
</a>
</li>
<li class="file-stats">
<a href="#c01c42dc253917145274782d44728d682815879c">
dirsrvtests/tests/suites/webui/ldap_browser/ldap_browser_test.py
</a>
</li>
<li class="file-stats">
<a href="#bead831d6374158614a99239e51d40ff0b3ddb1a">
dirsrvtests/tests/suites/webui/login/login_test.py
</a>
</li>
<li class="file-stats">
<a href="#c440ce12a649b847ea961e84634f30a201ab7d90">
dirsrvtests/tests/suites/webui/monitoring/monitoring_test.py
</a>
</li>
<li class="file-stats">
<a href="#c5ac849b0e5ea5cbc12cf90bd4b12538ce232574">
dirsrvtests/tests/suites/webui/plugins/plugins_test.py
</a>
</li>
<li class="file-stats">
<a href="#ac3be7a1f4c24a531518a81d9a1ca1b6ed069b4c">
dirsrvtests/tests/suites/webui/replication/replication_test.py
</a>
</li>
<li class="file-stats">
<a href="#93bfd94ae3d2cbbd4bc2cabf082b0e346895aff4">
dirsrvtests/tests/suites/webui/schema/schema_test.py
</a>
</li>
<li class="file-stats">
<a href="#81210f7c6e9716269208ee4a6d2fac54c34daea0">
dirsrvtests/tests/suites/webui/server/server_test.py
</a>
</li>
<li class="file-stats">
<a href="#2cd62b403d54c4f489033239dc1304c8d04c281a">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket47781_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#3c0487bbc49f1a639db5ce580f91d980089d9553">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket47953_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#061841b3ec8574b7199113d3112974adf79e3d59">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket47970_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#40fa9272e6727408ddc1014da8d73aa98aaf96cf">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket47976_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#f0d45dcb8165e53848b5d2d98da0dadef7be27c2">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket47980_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#d7d4a1f8cf4b3ff3ad5b98d33c50288e619fa1cb">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket47981_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#400ffdf32c1ba3ad7ad0379b4e7be21b771fe35a">
dirsrvtests/tests/tickets/ticket47988_test.py
</a>
</li>
<li class="file-stats">
<a href="#6669e49c8812bb148aa86cbd15cb84ff9c944575">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48005_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#b53438b6fc6d2fd86c1a65e0f05edd4046f00b8f">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48013_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#3bce8b9c64cd8211c5cb234c04d9700048f8684f">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48109_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#9969d4807d4976a5b1725aa29b4aa3155c3172d7">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48170_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#335dcd62a99c67f8e7ed26d9c572adee5c685749">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48194_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#dceddfbd23976c1504e642c5061173d69a2c9e9f">
dirsrvtests/tests/tickets/ticket48212_test.py
</a>
</li>
<li class="file-stats">
<a href="#61aa28eddd1d515f32c66602cbce77b6fbcf1fda">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48214_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#1d3dd49f968d9865f6f4b6f1d6b1367d90c2b638">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48252_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#ad4e0dd5aebf084f1146a2bd95b6135abdc2a171">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48265_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#d57df68684522944fb1ca333e26e7cf0c098be87">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48266_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#7441587cfdaf33b830e110d639e7213d6cec95dc">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48270_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#8871bc7c6b886788eacecdf8d9a80a23bda9ac1a">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48272_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#d515d2fcec67ece203eb5ac5e4f17e97cd1bedca">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48312_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#c075e3447ab5610914fe30edcb5696732242d22b">
dirsrvtests/tests/tickets/ticket48325_test.py
</a>
</li>
<li class="file-stats">
<a href="#a062ceccb59cb91449393301a57cfce7cd00f58e">
dirsrvtests/tests/tickets/ticket48342_test.py
</a>
</li>
<li class="file-stats">
<a href="#784ba761d679e5f2704ec0063d0ba9f5edb2d449">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48354_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#1ddb70169dd165deaa80f0bc994ebadfda8147fb">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48362_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#42582b901d156274bca7cff61349e91756cb0500">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48366_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#a1499d991556c74d97a5eb4857614e42ba75130b">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48383_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#311f7267eef4a8f72e18d4b065a05694b2d3c896">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48497_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#f0213b93e8214df6db7ce76647f9d45ead59da99">
dirsrvtests/tests/tickets/ticket48637_test.py
</a>
</li>
<li class="file-stats">
<a href="#16c745ef102792d04dab0854cdd5cd180904d46a">
dirsrvtests/tests/tickets/ticket48665_test.py
</a>
</li>
<li class="file-stats">
<a href="#e05645abb95196d9d9e69bf50c8fbf1893bfdf97">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48745_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#6b526b3253dd424159a23a832f4199011fd2fb10">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48746_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#ade58e9cb265f5a70bd16258700fae16fd12063a">
dirsrvtests/tests/tickets/ticket48759_test.py
</a>
</li>
<li class="file-stats">
<a href="#3aa38d54cf8683027fd9c8555b16c27e098cd09d">
dirsrvtests/tests/tickets/ticket48784_test.py
</a>
</li>
<li class="file-stats">
<a href="#9f54a5168aca6b9ac4fc2418a1cbcc648227c7e2">
dirsrvtests/tests/tickets/ticket48798_test.py
</a>
</li>
<li class="file-stats">
<a href="#07b0e4d829939a3573f3ea5907dc715b6ff0a5c2">
dirsrvtests/tests/tickets/ticket48799_test.py
</a>
</li>
<li class="file-stats">
<a href="#42a152fd9a6f1f808db751b163180f2e54c5756a">
dirsrvtests/tests/tickets/ticket48808_test.py
</a>
</li>
<li class="file-stats">
<a href="#9ad88b5b359f2c1969f65186be667417db3f1d8b">
dirsrvtests/tests/tickets/ticket48844_test.py
</a>
</li>
<li class="file-stats">
<a href="#905f7a70ec7e299e5ac2abd86d056421ab74d157">
dirsrvtests/tests/tickets/ticket48891_test.py
</a>
</li>
<li class="file-stats">
<a href="#96bded1c941027effc648bd022c461376cc7aacb">
dirsrvtests/tests/tickets/ticket48893_test.py
</a>
</li>
<li class="file-stats">
<a href="#e131e8c433e12ecc418e44f1bf94ee10be953533">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket48896_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#81d61feb0e5ed84253cdb7051ec0f163e8a48d93">
dirsrvtests/tests/tickets/ticket48906_test.py
</a>
</li>
<li class="file-stats">
<a href="#566c5a786aad9a1ad750c04aa8551abe8ad592b5">
dirsrvtests/tests/tickets/ticket48916_test.py
</a>
</li>
<li class="file-stats">
<a href="#0fff5a3f408be9dbcd05e64f430a4785534780b3">
dirsrvtests/tests/tickets/ticket48944_test.py
</a>
</li>
<li class="file-stats">
<a href="#43f114893e86328290c0f0dd30b65a574067a49b">
dirsrvtests/tests/tickets/ticket48956_test.py
</a>
</li>
<li class="file-stats">
<a href="#e0dbef14a4237e22967b396d48dfe6cfbc3093b2">
dirsrvtests/tests/tickets/ticket49020_test.py
</a>
</li>
<li class="file-stats">
<a href="#fc92da0c8c1513d14d701da7f11443f8196139a2">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket49039_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#da414c54e3ea02bf2dae4582fb332cab82918941">
dirsrvtests/tests/tickets/ticket49076_test.py
</a>
</li>
<li class="file-stats">
<a href="#8f19115bc6d13c353108360e02c64165dc18167f">
dirsrvtests/tests/tickets/ticket49095_test.py
</a>
</li>
<li class="file-stats">
<a href="#f8c375de58bb0bbf0d53e2389ed4dd076a2b011a">
dirsrvtests/tests/tickets/ticket49104_test.py
</a>
</li>
<li class="file-stats">
<a href="#518daff39439b80eecb087a32285ff5b5f0209a9">
dirsrvtests/tests/tickets/ticket49121_test.py
</a>
</li>
<li class="file-stats">
<a href="#28201af6e6008918f8375a904c1e802345dfc201">
dirsrvtests/tests/tickets/ticket49122_test.py
</a>
</li>
<li class="file-stats">
<a href="#ed046b7aaba54f469b5726370b3056b4935eeea7">
dirsrvtests/tests/tickets/ticket49180_test.py
</a>
</li>
<li class="file-stats">
<a href="#2f259424f25eb0d2ac5f08540a35c85645189ce1">
dirsrvtests/tests/tickets/ticket49192_test.py
</a>
</li>
<li class="file-stats">
<a href="#5645f0d8b0a780266f803a972371fc35af565085">
dirsrvtests/tests/tickets/ticket49227_test.py
</a>
</li>
<li class="file-stats">
<a href="#190b53bf7707f02c39e2ce0208d71cda84ff71a6">
dirsrvtests/tests/tickets/ticket49249_test.py
</a>
</li>
<li class="file-stats">
<a href="#f62225908f25510b396a08f18e5744e0a5910ca1">
dirsrvtests/tests/tickets/ticket49273_test.py
</a>
</li>
<li class="file-stats">
<a href="#e91fdb2726c38ac7edd96f5cda7d791696c0c1f4">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket49287_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#1a83dfe11af7d22b2bad8b0dc801b5ac4f4b35d6">
dirsrvtests/tests/tickets/ticket49290_test.py
</a>
</li>
<li class="file-stats">
<a href="#cad064a1786110465817db5ec80f21240db8474f">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket49303_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#b1579ce51973b7fe4fa512864bb660b85152f734">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket49412_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#6f7f19474e6df8b89a4f05e79d6f8448b72e18dd">
dirsrvtests/tests/tickets/ticket49441_test.py
</a>
</li>
<li class="file-stats">
<a href="#880b8de0f46aaf583e83fcca8ff56659ea026691">
dirsrvtests/tests/tickets/ticket49460_test.py
</a>
</li>
<li class="file-stats">
<a href="#cc31a036e4b2ed6261ccc327b5cc847e3f454e54">
dirsrvtests/tests/tickets/ticket49471_test.py
</a>
</li>
<li class="file-stats">
<a href="#c1d003a1b286610d117ee710aed65160876b7924">
dirsrvtests/tests/tickets/ticket49623_2_test.py
</a>
</li>
<li class="file-stats">
<a href="#40c6c284fd9044bec119e3057558ae6911d51901">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket49658_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#559c4272409223b80050a5a1eeaf2ea618dec8ce">
dirsrvtests/tests/tickets/ticket49788_test.py
</a>
</li>
<li class="file-stats">
<a href="#5b96612ac3236c19083bb0365e5d0facbc0e5698">
dirsrvtests/tests/tickets/ticket50078_test.py
</a>
</li>
<li class="file-stats">
<a href="#8103906db5e9b704044140a5498b8d86684a100c">
dirsrvtests/tests/tickets/ticket50234_test.py
</a>
</li>
<li class="file-stats">
<a href="#7b623032bbe3545fe28c4712b968fe162e784970">
<span class="deleted-file">

dirsrvtests/tests/tickets/ticket548_test.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#8aba22461c02761ffd62ebfb20e8d5ef3f83df0f">
<span class="new-file">
+
docs/agents/architecture.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#98afcc833ac7b43f7f59b4cfdafe2e7f1c11875e">
<span class="new-file">
+
docs/agents/backends.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#b4aa684c40272c4708f7e1269e3bf52be7f495cd">
<span class="new-file">
+
docs/agents/building.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#75d5cb02c49f459faaa18388061c6133caa63856">
<span class="new-file">
+
docs/agents/c-server.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#571e0813ccbf42729ff4463964ab4b50cb0aedd2">
<span class="new-file">
+
docs/agents/cli.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#c86abb3494d3efd18c534535b941175429f76fa5">
<span class="new-file">
+
docs/agents/contributing.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#f4595802dfef8566fcf5cee65c2eb5848c2fc7ce">
<span class="new-file">
+
docs/agents/lib389.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#db1b233d3e44862c481ebe21a3d12afdb5d93ae2">
<span class="new-file">
+
docs/agents/plugins.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#5162ed5196e457663b75d974818f44ce7e67fffd">
<span class="new-file">
+
docs/agents/replication.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#5dcef59bf511f76d75418ed5f4a84799eab3f3e1">
<span class="new-file">
+
docs/agents/rust.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#41fbd8a2b4bc260b5499c1e8ae3823345a2d5794">
<span class="new-file">
+
docs/agents/testing.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#03f335cf3bc0b12b58f7cb078455059476767691">
<span class="new-file">
+
docs/agents/ui.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#622a57a56a3b7edc521383826161876e0276ac1b">
<span class="new-file">
+
ldap/AGENTS.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#0758d5e28aefb60d97815d6ea538040575119cb8">
<span class="new-file">
+
ldap/admin/src/389-ds-base.sysusers
</span>
</a>
</li>
<li class="file-stats">
<a href="#b3565d49fc2d6b03937d92f5968ea7d8f85a3460">
ldap/admin/src/defaults.inf.in
</a>
</li>
<li class="file-stats">
<a href="#b96ea8073446c801633905d2dee0d301c74033a9">
ldap/admin/src/logconv.py
</a>
</li>
<li class="file-stats">
<a href="#8f37058f4922b92f2643c1d87e6daa36b5ddf715">
ldap/ldif/template-dse-minimal.ldif.in
</a>
</li>
<li class="file-stats">
<a href="#a42d584072620409bd373bc0168cbe6046a9f78c">
ldap/ldif/template-dse.ldif.in
</a>
</li>
<li class="file-stats">
<a href="#1ace27a4ce7aedf43fbc1561897c2f0e25ad7a4e">
ldap/schema/01core389.ldif
</a>
</li>
<li class="file-stats">
<a href="#5a9e957e9a1bf22842eca421216c819f1af0e6cc">
ldap/schema/02common.ldif
</a>
</li>
<li class="file-stats">
<a href="#5342002d6c1658b0ac327aa374714ba3c88d529a">
ldap/servers/plugins/acl/acl.c
</a>
</li>
<li class="file-stats">
<a href="#00c96b03d255a24eb6e6ff5d6294d44c3d1d20c2">
ldap/servers/plugins/acl/acllas.c
</a>
</li>
<li class="file-stats">
<a href="#04e18a5176af108fe98952af2eef7fec1f058732">
ldap/servers/plugins/acl/aclparse.c
</a>
</li>
<li class="file-stats">
<a href="#0c138b5cb1df309971e6da83baffb2e935c1cb9d">
ldap/servers/plugins/automember/automember.c
</a>
</li>
<li class="file-stats">
<a href="#50024ac46390f9870d5377bb39d6ec86227622a2">
ldap/servers/plugins/collation/orfilter.c
</a>
</li>
<li class="file-stats">
<a href="#50d73e300ba9e523fa1fd51063accb78cae86227">
ldap/servers/plugins/cos/cos_cache.c
</a>
</li>
<li class="file-stats">
<a href="#0ec25d713710ac8be801e2e11c4ece21db685c6b">
ldap/servers/plugins/deref/deref.c
</a>
</li>
<li class="file-stats">
<a href="#433746478f48a22ea99e9b5a393bf76d04e94a3c">
ldap/servers/plugins/dna/dna.c
</a>
</li>
<li class="file-stats">
<a href="#b8710a3c1fc1e8c07545b37dcc384639a1adaa24">
ldap/servers/plugins/linkedattrs/fixup_task.c
</a>
</li>
<li class="file-stats">
<a href="#6570360a7ec8111e89e620cdb68aebc4cb5d3ea7">
ldap/servers/plugins/linkedattrs/linked_attrs.c
</a>
</li>
<li class="file-stats">
<a href="#0cb1ee6438c60a4a9c5e1c83a1433a65374d15d4">
ldap/servers/plugins/memberof/memberof.c
</a>
</li>
<li class="file-stats">
<a href="#d661e8322cda40007c3c00bcb514b2e7441a8b23">
ldap/servers/plugins/posix-winsync/posix-group-task.c
</a>
</li>
<li class="file-stats">
<a href="#fb8165d8e26ac019f491420e69c643f607427a30">
ldap/servers/plugins/pwdstorage/pbkdf2_pwd.c
</a>
</li>
<li class="file-stats">
<a href="#ac876f8d73ea49f0b20f3fb6ed8c0b07199c7228">
ldap/servers/plugins/pwdstorage/pwdstorage.h
</a>
</li>
<li class="file-stats">
<a href="#34d9c95c1c91af330dc67bdc03aa079ee8f5e08f">
ldap/servers/plugins/pwdstorage/smd5_pwd.c
</a>
</li>
<li class="file-stats">
<a href="#713c1a56aef62a457903aa7211b2c091d883df6a">
ldap/servers/plugins/referint/referint.c
</a>
</li>
<li class="file-stats">
<a href="#b4915431b529b1a5f808a6e4c24d3191231054fc">
ldap/servers/plugins/replication/cl5_api.c
</a>
</li>
<li class="file-stats">
<a href="#db32658f241fb1275d5332bc5a0046a8d5b46d01">
ldap/servers/plugins/replication/cl5_clcache.c
</a>
</li>
<li class="file-stats">
<a href="#2d5cf4cc6488b7d8e07423af0c2321a1e4183fa9">
ldap/servers/plugins/replication/cl5_config.c
</a>
</li>
<li class="file-stats">
<a href="#1a56159682ce1818571685fa7e791d2c5829ad19">
ldap/servers/plugins/replication/cl5_test.c
</a>
</li>
<li class="file-stats">
<a href="#882232b28ff8bed9ee84a6b81ff2e812bc05bae5">
ldap/servers/plugins/replication/repl5.h
</a>
</li>
<li class="file-stats">
<a href="#6c2d7e5bd3448633c64737e8105fa1c82fa456f9">
ldap/servers/plugins/replication/repl5_agmtlist.c
</a>
</li>
<li class="file-stats">
<a href="#684011a07ac16ddd4a7aed1830c04b5243260472">
ldap/servers/plugins/replication/repl5_inc_protocol.c
</a>
</li>
<li class="file-stats">
<a href="#3d71200641c722737b63c14b80fea437b6ea4837">
ldap/servers/plugins/replication/repl5_init.c
</a>
</li>
<li class="file-stats">
<a href="#883a92bca5637ffd103eab9df9674a301e71e17e">
ldap/servers/plugins/replication/repl5_protocol.c
</a>
</li>
<li class="file-stats">
<a href="#faf31f1111adf54b74a217c1ba99b6d352b1b82e">
ldap/servers/plugins/replication/repl5_replica.c
</a>
</li>
<li class="file-stats">
<a href="#ee3540806bbde6120d644d91d659c07c27b39921">
ldap/servers/plugins/replication/repl5_replica_config.c
</a>
</li>
<li class="file-stats">
<a href="#b2701c7e253468e1020958e0686425d5b942cb19">
ldap/servers/plugins/replication/repl5_tot_protocol.c
</a>
</li>
<li class="file-stats">
<a href="#9498e263c2a1696b696c2d8830ad6451f176ed9d">
ldap/servers/plugins/replication/repl5_total.c
</a>
</li>
<li class="file-stats">
<a href="#c6c57dfad57bf9ea2250c146126f97945384805c">
ldap/servers/plugins/replication/repl_cleanallruv.c
</a>
</li>
<li class="file-stats">
<a href="#d394138113076ec87c2c564153917c14785ee73d">
ldap/servers/plugins/replication/repl_extop.c
</a>
</li>
<li class="file-stats">
<a href="#8a1ac72ee887b1c24b496d35571f4e1a9dbd445d">
ldap/servers/plugins/replication/urp_tombstone.c
</a>
</li>
<li class="file-stats">
<a href="#86c01b1356b0c189edce752c76136863c6fea75c">
ldap/servers/plugins/replication/windows_protocol_util.c
</a>
</li>
<li class="file-stats">
<a href="#715cbb750bcdd5c17e695fa23e39cdb2747de676">
ldap/servers/plugins/retrocl/retrocl.c
</a>
</li>
<li class="file-stats">
<a href="#438f67af9dbd6619981d30f94dc2f1b0bd3cfe4f">
ldap/servers/plugins/retrocl/retrocl.h
</a>
</li>
<li class="file-stats">
<a href="#25ef844ea9636b5fe65e0a8852667f7004a38bde">
ldap/servers/plugins/retrocl/retrocl_po.c
</a>
</li>
<li class="file-stats">
<a href="#251fc5004493e583b5545b986f8bc9fccb37001b">
ldap/servers/plugins/retrocl/retrocl_trim.c
</a>
</li>
<li class="file-stats">
<a href="#d8dbbeee8c8f9721cc74a09c121a55bd4e64f4e0">
ldap/servers/plugins/roles/roles_cache.c
</a>
</li>
<li class="file-stats">
<a href="#8acce42477a785e16c3bfe03687f74564f49b4be">
ldap/servers/plugins/schema_reload/schema_reload.c
</a>
</li>
<li class="file-stats">
<a href="#7f6e805b829712c0f20753826391fc25046b17fc">
ldap/servers/plugins/sync/sync.h
</a>
</li>
<li class="file-stats">
<a href="#30ff3475ba90deab3478c993229a712f8b7bf2aa">
ldap/servers/plugins/sync/sync_init.c
</a>
</li>
<li class="file-stats">
<a href="#5cdb66310083a02bf2b7d5f9df33ad1ad020e30c">
ldap/servers/plugins/sync/sync_persist.c
</a>
</li>
<li class="file-stats">
<a href="#3f38d736efaf6fb096910a474d81588c31e435d4">
ldap/servers/plugins/sync/sync_util.c
</a>
</li>
<li class="file-stats">
<a href="#f6ce478f5d2d2909e17f6d3fc1e3366924730dd7">
ldap/servers/plugins/syntaxes/string.c
</a>
</li>
<li class="file-stats">
<a href="#0f5e05179db54c7c5f49ee3aff3c8ba651275381">
ldap/servers/plugins/syntaxes/validate_task.c
</a>
</li>
<li class="file-stats">
<a href="#c11de0bac06c8c0fe504b068819692f10a7e468b">
ldap/servers/plugins/uiduniq/uid.c
</a>
</li>
<li class="file-stats">
<a href="#315eae3bf7c25cc8a28fba880608a5c0edc4b1af">
ldap/servers/plugins/usn/usn_cleanup.c
</a>
</li>
<li class="file-stats">
<a href="#da50aa5ffc4a4f7efb059cd2cbe882eb17d20d6a">
ldap/servers/plugins/views/views.c
</a>
</li>
<li class="file-stats">
<a href="#738fbe02d124320ac8db1200be4279e579402cb6">
ldap/servers/slapd/abandon.c
</a>
</li>
<li class="file-stats">
<a href="#0b6002856274448a58d06b7eb1e1d068027ec933">
ldap/servers/slapd/accesslog.c
</a>
</li>
<li class="file-stats">
<a href="#9dc5e78aeaede7d0d12de4997f290d28dbbca91a">
ldap/servers/slapd/add.c
</a>
</li>
<li class="file-stats">
<a href="#34b465d4436ddcc3f92648ff4f27304d3dd47ff2">
ldap/servers/slapd/attr.c
</a>
</li>
<li class="file-stats">
<a href="#6950ae19aa70b140040145fcfdd78937acb66345">
ldap/servers/slapd/attrsyntax.c
</a>
</li>
<li class="file-stats">
<a href="#61c7fd99a9fb9daec65108788d359db92fe6492f">
ldap/servers/slapd/auditlog.c
</a>
</li>
<li class="file-stats">
<a href="#0b5ab745928a725cabdd9faa61f006cde805094d">
ldap/servers/slapd/auth.c
</a>
</li>
<li class="file-stats">
<a href="#8d6bcf53861b118b21ff154dd4c96822c77c9179">
ldap/servers/slapd/back-ldbm/archive.c
</a>
</li>
<li class="file-stats">
<a href="#107666c99dba2dca86e8780fedbb8e68fc492add">
ldap/servers/slapd/back-ldbm/attrcrypt.h
</a>
</li>
<li class="file-stats">
<a href="#bc0b7af062f93d38b91f67dfe33811539badc3c1">
ldap/servers/slapd/back-ldbm/back-ldbm.h
</a>
</li>
<li class="file-stats">
<a href="#e56331d9199d992932f9cca4565c3c9284cbbf37">
ldap/servers/slapd/back-ldbm/backentry.c
</a>
</li>
<li class="file-stats">
<a href="#bcb813ffdb857f4b37d2cd4befa1137a2995188f">
ldap/servers/slapd/back-ldbm/cache.c
</a>
</li>
<li class="file-stats">
<a href="#af2d0b7e6f60bcc09c81e6898598263771eaf83b">
ldap/servers/slapd/back-ldbm/db-bdb/bdb_import.c
</a>
</li>
<li class="file-stats">
<a href="#9a446ca974c43ae6d1dd36e0d9d94c678d92a851">
ldap/servers/slapd/back-ldbm/db-bdb/bdb_import_threads.c
</a>
</li>
<li class="file-stats">
<a href="#dc7bfc8503bdd4c8da43e3dece68c1fa5926d42b">
ldap/servers/slapd/back-ldbm/db-bdb/bdb_layer.c
</a>
</li>
<li class="file-stats">
<a href="#c1354cf55793fd8cb904daa6feb15ec73eb39698">
ldap/servers/slapd/back-ldbm/db-bdb/bdb_ldif2db.c
</a>
</li>
<li class="file-stats">
<a href="#85b1f7fdea5bdd7c22ca73191d5f3076d986d481">
ldap/servers/slapd/back-ldbm/db-mdb/mdb_config.c
</a>
</li>
<li class="file-stats">
<a href="#23a45888537286f0a3d65feef3975846a4657770">
ldap/servers/slapd/back-ldbm/db-mdb/mdb_import.c
</a>
</li>
<li class="file-stats">
<a href="#ef2da923412fbfa272b7b7eb37cbf505f63177bb">
ldap/servers/slapd/back-ldbm/db-mdb/mdb_import_threads.c
</a>
</li>
<li class="file-stats">
<a href="#d48ff095e7061812de08052c6b4d7bf4e926001c">
ldap/servers/slapd/back-ldbm/db-mdb/mdb_instance.c
</a>
</li>
<li class="file-stats">
<a href="#f3350c00731494f66a048c63e4d57da994e585cf">
ldap/servers/slapd/back-ldbm/db-mdb/mdb_layer.c
</a>
</li>
<li class="file-stats">
<a href="#f59db9e23b48e99bdd90c9af300d2f45cda0aea3">
ldap/servers/slapd/back-ldbm/db-mdb/mdb_layer.h
</a>
</li>
<li class="file-stats">
<a href="#3c3602484f163cbd9a9a9443ecf3b3c3ebeeeac1">
ldap/servers/slapd/back-ldbm/db-mdb/mdb_ldif2db.c
</a>
</li>
<li class="file-stats">
<a href="#2551d3bec14b7c5369a4ff9b78f5c8e77d18b261">
ldap/servers/slapd/back-ldbm/db-mdb/mdb_misc.c
</a>
</li>
<li class="file-stats">
<a href="#8c398724684620f8d2c0fad49d404cc7735a4c65">
ldap/servers/slapd/back-ldbm/filterindex.c
</a>
</li>
<li class="file-stats">
<a href="#17948e560ba6f47c7d3179d2e43b1fbb8778bff7">
ldap/servers/slapd/back-ldbm/id2entry.c
</a>
</li>
<li class="file-stats">
<a href="#48aee7c2d8eb43b6933a90c4fa07ec94684b327e">
ldap/servers/slapd/back-ldbm/idl_common.c
</a>
</li>
<li class="file-stats">
<a href="#43011de6ccb117e709a21879a67c3c0005204870">
ldap/servers/slapd/back-ldbm/idl_new.c
</a>
</li>
<li class="file-stats">
<a href="#a157f5d3f1c42452fc4944fe6de2586914b64479">
ldap/servers/slapd/back-ldbm/import.c
</a>
</li>
<li class="file-stats">
<a href="#2cc3db62175f93ce54583fa9e0ae6dc58402ea2e">
ldap/servers/slapd/back-ldbm/import.h
</a>
</li>
<li class="file-stats">
<a href="#20dda463977c1587d5b272f1a2fdf737935cc069">
ldap/servers/slapd/back-ldbm/index.c
</a>
</li>
<li class="file-stats">
<a href="#ee1864aeae15345fe0cf31e3c8e5f42d0d187874">
ldap/servers/slapd/back-ldbm/instance.c
</a>
</li>
<li class="file-stats">
<a href="#237f4fcd8cc0a5133c4613b4210ed3f27c5318e8">
ldap/servers/slapd/back-ldbm/ldbm_add.c
</a>
</li>
<li class="file-stats">
<a href="#d8ed970e20e841ee6d082a71952089744cf28149">
ldap/servers/slapd/back-ldbm/ldbm_attr.c
</a>
</li>
<li class="file-stats">
<a href="#520bef8e9b9e371625f5ce96c104ebc1101eacb9">
ldap/servers/slapd/back-ldbm/ldbm_attrcrypt.c
</a>
</li>
<li class="file-stats">
<a href="#fcb2f36d430cb8d060a3e0e7e8a59714e799caa3">
ldap/servers/slapd/back-ldbm/ldbm_config.c
</a>
</li>
<li class="file-stats">
<a href="#568ccf25dbe97b22815bfdaadec1310bed203dd9">
ldap/servers/slapd/back-ldbm/ldbm_config.h
</a>
</li>
<li class="file-stats">
<a href="#8045a71398359c06534e05568b87e9fd0e267333">
ldap/servers/slapd/back-ldbm/ldbm_delete.c
</a>
</li>
<li class="file-stats">
<a href="#4d534e56baada22d35d19b8959f69d9aadd20f8d">
ldap/servers/slapd/back-ldbm/ldbm_entryrdn.c
</a>
</li>
<li class="file-stats">
<a href="#35ec9f17cdd96ceb63cfb892cc5bd677e7398472">
ldap/servers/slapd/back-ldbm/ldbm_index_config.c
</a>
</li>
<li class="file-stats">
<a href="#56b35ffbe77e9acf840cb747333b32e5e11f92af">
ldap/servers/slapd/back-ldbm/ldbm_modify.c
</a>
</li>
<li class="file-stats">
<a href="#4870a3e011bb77b5f18f5fd38776191397677460">
ldap/servers/slapd/back-ldbm/ldbm_modrdn.c
</a>
</li>
<li class="file-stats">
<a href="#0181930ae7d709e45244956a00c31760c73d45c2">
ldap/servers/slapd/back-ldbm/ldbm_search.c
</a>
</li>
<li class="file-stats">
<a href="#43807f83cc3831882aa0cf8985eb9a57e233c130">
ldap/servers/slapd/back-ldbm/misc.c
</a>
</li>
<li class="file-stats">
<a href="#a5e813de23c822df0cfadaf0d2b2ed624feb0e01">
ldap/servers/slapd/back-ldbm/nextid.c
</a>
</li>
<li class="file-stats">
<a href="#9aba92f51fa86a4405f79c3432a8dffcd6adbd93">
ldap/servers/slapd/back-ldbm/proto-back-ldbm.h
</a>
</li>
<li class="file-stats">
<a href="#55167e2060376edf4d35cd99c037bf6f51b41434">
ldap/servers/slapd/back-ldbm/seq.c
</a>
</li>
<li class="file-stats">
<a href="#b81fec4bafdfee4524cc7b570913dd2ba38738ac">
ldap/servers/slapd/back-ldbm/vlv.c
</a>
</li>
<li class="file-stats">
<a href="#407457e99e9237e82faf5950a837cc4cfbbfe53c">
ldap/servers/slapd/bind.c
</a>
</li>
<li class="file-stats">
<a href="#f00787820ec466a62bcdc5a7aa7ddb1215a16635">
ldap/servers/slapd/charray.c
</a>
</li>
<li class="file-stats">
<a href="#313a318a42c137175b65ca4d0d56e4c49910ad05">
ldap/servers/slapd/compare.c
</a>
</li>
<li class="file-stats">
<a href="#0d48e5dbb4e34a803f45dde878fd1d4e0f84d0ce">
ldap/servers/slapd/configdse.c
</a>
</li>
<li class="file-stats">
<a href="#bba7a6d281accf31c1837cb3fe19f2219211c04b">
ldap/servers/slapd/connection.c
</a>
</li>
<li class="file-stats">
<a href="#2a56f97965e530e0b32e4738577f6784b98e4bf8">
ldap/servers/slapd/control.c
</a>
</li>
<li class="file-stats">
<a href="#acccc630d66b05ab8f052ac3160f8a1238b2412a">
ldap/servers/slapd/csngen.c
</a>
</li>
<li class="file-stats">
<a href="#d72f55382e3c406e64615d9699b7d4757980f255">
ldap/servers/slapd/daemon.c
</a>
</li>
<li class="file-stats">
<a href="#2e165f953f9b3c99485039bc1b3d015fbeca91e8">
ldap/servers/slapd/dn.c
</a>
</li>
<li class="file-stats">
<a href="#376603ba61f86d8e98e5eb3653d1ab023c763634">
ldap/servers/slapd/dyncerts.c
</a>
</li>
<li class="file-stats">
<a href="#dddc024eac48644a455f3f1ff74ada99b84dc2f5">
ldap/servers/slapd/dyncerts.h
</a>
</li>
<li class="file-stats">
<a href="#ffe1aef560b240ff950d1ec8deeb967fe6eff701">
ldap/servers/slapd/entry.c
</a>
</li>
<li class="file-stats">
<a href="#7c844e68f7509d13e7b3761e49900154e019907b">
ldap/servers/slapd/entrywsi.c
</a>
</li>
<li class="file-stats">
<a href="#25e898aaff162768eb76b71072452609c6947a78">
ldap/servers/slapd/eventq-deprecated.c
</a>
</li>
<li class="file-stats">
<a href="#704d02d5bfa2a98f67e9b00a377657d82f724817">
ldap/servers/slapd/eventq.c
</a>
</li>
<li class="file-stats">
<a href="#badd039662986e377ad68b866837ca6e3d870826">
ldap/servers/slapd/extendop.c
</a>
</li>
<li class="file-stats">
<a href="#29a7ff8bcd2ad583e33a781ba14c137a7c31c422">
ldap/servers/slapd/fe.h
</a>
</li>
<li class="file-stats">
<a href="#aa46e1fb89c2568d36a2e37187c5f9bec775a5ed">
ldap/servers/slapd/fedse.c
</a>
</li>
<li class="file-stats">
<a href="#3597762831df084343d9dfc8a20846fe7d354dcc">
ldap/servers/slapd/generation.c
</a>
</li>
<li class="file-stats">
<a href="#d2c41c876c471c3c1aa7c08429b81c634900a616">
ldap/servers/slapd/globals.c
</a>
</li>
<li class="file-stats">
<a href="#99afa4fa46d7c867d881f256e0bb814a8b741eb6">
ldap/servers/slapd/haproxy.c
</a>
</li>
<li class="file-stats">
<a href="#2a9c7a66a7e6a5d0f4075cc8181bb0669015106b">
<span class="new-file">
+
ldap/servers/slapd/hibp.h
</span>
</a>
</li>
<li class="file-stats">
<a href="#8f1c4e9db1c5ace1861857b85e4378eda7e5ffdf">
<span class="new-file">
+
ldap/servers/slapd/hibp_client.c
</span>
</a>
</li>
<li class="file-stats">
<a href="#cfd4334dbfd1704d9341251dd5638307bef614a3">
ldap/servers/slapd/house.c
</a>
</li>
<li class="file-stats">
<a href="#d7e13f9848f10ecb114f1fec27847d8163a8be79">
ldap/servers/slapd/ldaputil.c
</a>
</li>
<li class="file-stats">
<a href="#bb120068614c4cc9b1005576a11632b044a5a44f">
ldap/servers/slapd/libglobs.c
</a>
</li>
<li class="file-stats">
<a href="#232a213d5c8938b953d6ec10c5c9137b76f93766">
ldap/servers/slapd/log.c
</a>
</li>
<li class="file-stats">
<a href="#57bb5e1bedf7aadf1a111811f9502d35d9bbcbe1">
ldap/servers/slapd/log.h
</a>
</li>
<li class="file-stats">
<a href="#8d2b82fbb50bcbec90db372897d7cafb3dd9c544">
ldap/servers/slapd/main.c
</a>
</li>
<li class="file-stats">
<a href="#466012cb6844b7d4e52da5b41ca0ce3a497d81bd">
ldap/servers/slapd/mapping_tree.c
</a>
</li>
<li class="file-stats">
<a href="#112d6179067b05664ce050204bf84542c124a8e0">
ldap/servers/slapd/modify.c
</a>
</li>
<li class="file-stats">
<a href="#a45b3dc01528f0793e483349dfc6a94aa194aecd">
ldap/servers/slapd/modrdn.c
</a>
</li>
<li class="file-stats">
<a href="#e0877e936c036b7c0d89c006fc78ef7f14d59a75">
ldap/servers/slapd/monitor.c
</a>
</li>
<li class="file-stats">
<a href="#a681f5400f91992c6034b8e2e52c31b8003e9f99">
ldap/servers/slapd/operation.c
</a>
</li>
<li class="file-stats">
<a href="#96bdff9e65f14a9ffb0030189550617b29940649">
ldap/servers/slapd/opshared.c
</a>
</li>
<li class="file-stats">
<a href="#8fc5e685d81683826eb9c4ac7cdbdcc197c1f8c6">
ldap/servers/slapd/pagedresults.c
</a>
</li>
<li class="file-stats">
<a href="#f4a3f4dca431b8116b118f66c6a4d77bf015e60c">
ldap/servers/slapd/passwd_extop.c
</a>
</li>
<li class="file-stats">
<a href="#d7389709509706de301e9e405c4c1ee564300c7d">
ldap/servers/slapd/pblock.c
</a>
</li>
<li class="file-stats">
<a href="#7fa4f1468fa94f97565cfccc9b6885c3c685d519">
ldap/servers/slapd/pblock_v3.h
</a>
</li>
<li class="file-stats">
<a href="#a100e42b2720617ed5f1b2acf4fddb25f6cc2a2e">
ldap/servers/slapd/plugin.c
</a>
</li>
<li class="file-stats">
<a href="#3605b02def2c61ac5cdf76dc18dacb9b59ee780a">
ldap/servers/slapd/plugin_internal_op.c
</a>
</li>
<li class="file-stats">
<a href="#b4d3ac554cf80abe29c701efb1382f691a66db5e">
ldap/servers/slapd/proto-slap.h
</a>
</li>
<li class="file-stats">
<a href="#b3acbffdbc4b3e517f8e90e643cffab8676c9a0f">
ldap/servers/slapd/psearch.c
</a>
</li>
<li class="file-stats">
<a href="#07311ee8e3f5772e83b9a40d080db59f171e3feb">
ldap/servers/slapd/pw.c
</a>
</li>
<li class="file-stats">
<a href="#4ae9e1a268ff8566958d4d2549b46b84066537d4">
ldap/servers/slapd/pw.h
</a>
</li>
<li class="file-stats">
<a href="#471b1262be712421986bcfe16eeb42bd2f51c8d3">
ldap/servers/slapd/pw_mgmt.c
</a>
</li>
<li class="file-stats">
<a href="#ea54bc431d49225e4d085271595ed6c23d0d11b4">
ldap/servers/slapd/pw_retry.c
</a>
</li>
<li class="file-stats">
<a href="#845697d2499bdad68ecde80b80a1f330629bd8a6">
ldap/servers/slapd/result.c
</a>
</li>
<li class="file-stats">
<a href="#b65ef015d0049721a98fba9681cc4d095eb7a3cc">
ldap/servers/slapd/sasl_io.c
</a>
</li>
<li class="file-stats">
<a href="#a416cfd71e04e82f28b238a5b4ac4b3dd582b1d7">
ldap/servers/slapd/saslbind.c
</a>
</li>
<li class="file-stats">
<a href="#890e20841b24a299baa4ff58542c5e71a6a73a75">
ldap/servers/slapd/schema.c
</a>
</li>
<li class="file-stats">
<a href="#8852c3667762071c99cbd464e52eb9cdca8ccb9a">
ldap/servers/slapd/search.c
</a>
</li>
<li class="file-stats">
<a href="#4af1ef1ccc5b3f04935da6353890e024903fdc2f">
ldap/servers/slapd/slap.h
</a>
</li>
<li class="file-stats">
<a href="#207b990dc2c75c8e1d4e83ea680ad4790a084e50">
ldap/servers/slapd/slapi-memberof.c
</a>
</li>
<li class="file-stats">
<a href="#c5542fda9f2328b44d98c64f5147805beea7f94b">
ldap/servers/slapd/slapi-plugin.h
</a>
</li>
<li class="file-stats">
<a href="#87f7c7caec89ea1c84282bac1ddfbedd446ae661">
ldap/servers/slapd/slapi-private.h
</a>
</li>
<li class="file-stats">
<a href="#14b3b50785d17f8688cda3daa1229c8044be1bc9">
ldap/servers/slapd/ssl.c
</a>
</li>
<li class="file-stats">
<a href="#c7c88bf61ec2b1b1143fa947bcdeef410d28fe57">
ldap/servers/slapd/str2filter.c
</a>
</li>
<li class="file-stats">
<a href="#eb9399dddce3f9e638d3cb568ee7219056c27d8c">
ldap/servers/slapd/task.c
</a>
</li>
<li class="file-stats">
<a href="#9187b9462fc44c09f54e3aae3ddd907362d691ad">
ldap/servers/slapd/test-plugins/sampletask.c
</a>
</li>
<li class="file-stats">
<a href="#5b51376470f08fc6df0f358521944ad660ca635e">
ldap/servers/slapd/thread_data.c
</a>
</li>
<li class="file-stats">
<a href="#142ec276e7994b8f25e8d317fd73ebb0bc8c9cdf">
<span class="new-file">
+
ldap/servers/slapd/threadpool_stats.c
</span>
</a>
</li>
<li class="file-stats">
<a href="#dec9fe6304251ca6ae7493b0d619665ad0d7cf0f">
<span class="new-file">
+
ldap/servers/slapd/threadpool_stats.h
</span>
</a>
</li>
<li class="file-stats">
<a href="#4617737db5cddd2d1311cc7d2dd57e12e8855002">
ldap/servers/slapd/time.c
</a>
</li>
<li class="file-stats">
<a href="#10d4213e9eeb63f290fb07f4f5be7479f0fb21bd">
ldap/servers/slapd/tools/dbscan.c
</a>
</li>
<li class="file-stats">
<a href="#a07024b34dfadbc5f9245423914d14c67116a749">
ldap/servers/slapd/tools/ldclt/ldapfct.c
</a>
</li>
<li class="file-stats">
<a href="#714f2624daab845b669ba9c53ff451944bba4baf">
ldap/servers/slapd/upgrade.c
</a>
</li>
<li class="file-stats">
<a href="#eaf20732a3be1cb473296d08c6b9811f4a4b2f34">
ldap/servers/slapd/util.c
</a>
</li>
<li class="file-stats">
<a href="#86f0e9debd41fbc0d956d0f4faa8a4ae4e332ec5">
ldap/servers/slapd/vattr.c
</a>
</li>
<li class="file-stats">
<a href="#aae05e446323fb37524c77878c3ee2969ac89d01">
ldap/servers/snmp/main.c
</a>
</li>
<li class="file-stats">
<a href="#b5dc9843c2e88603a9e4ce5eecc5cf9825270dd1">
m4/systemd.m4
</a>
</li>
<li class="file-stats">
<a href="#d11ccaafd3f2460d57aec21a477e101da11ec7d7">
<span class="new-file">
+
profiling/bpftrace/probe_do_search_detail.bt
</span>
</a>
</li>
<li class="file-stats">
<a href="#2367b38e0a7b9fdf9e88296ee063cdb79f2112a4">
<span class="new-file">
+
profiling/bpftrace/probe_log_access_detail.bt
</span>
</a>
</li>
<li class="file-stats">
<a href="#2a9230f6730097d9120f7b9a2f60ac595825815b">
<span class="new-file">
+
profiling/bpftrace/probe_op_shared_search.bt
</span>
</a>
</li>
<li class="file-stats">
<a href="#d54a4419e3188c55859f76e644ee9b6348cf56fa">
<span class="new-file">
+
profiling/bpftrace/probe_work_queue.bt
</span>
</a>
</li>
<li class="file-stats">
<a href="#1311510803eaa8fd6b2389ca5ae670d1a8fb64ac">
profiling/stap/probe_do_search_detail.stp
</a>
</li>
<li class="file-stats">
<a href="#e619301705a98ff1c46742d606cae5326cda4fa5">
profiling/stap/probe_log_access_detail.stp
</a>
</li>
<li class="file-stats">
<a href="#fac8e68666349cc65e47253d590e10aca4f0941c">
profiling/stap/probe_op_shared_search.stp
</a>
</li>
<li class="file-stats">
<a href="#8e334d402810a60acce53465ba4ff6d4935ea6b5">
<span class="new-file">
+
profiling/stap/probe_work_queue.stp
</span>
</a>
</li>
<li class="file-stats">
<a href="#61a3885e28a7c123f2b88f5c9fa1600b50cd94f1">
rpm.mk
</a>
</li>
<li class="file-stats">
<a href="#db89186449a2d34551f1646da8d902c01ee7c164">
rpm/389-ds-base.spec.in
</a>
</li>
<li class="file-stats">
<a href="#f16f7b905942da4b45103d4bfdc48ae125fbfce8">
rpm/bundle-libdb.spec

rpm/bundle-libdb.spec.in
</a>
</li>
<li class="file-stats">
<a href="#9401bbe6d950e0ef5a0b1466bcf4a5865c14efe4">
rpm/bundle-rust-npm.py
</a>
</li>
<li class="file-stats">
<a href="#b1c6ab7a48ed3c0516b6ba409ddb188f75bca210">
<span class="new-file">
+
rpm/jemalloc-5.3.0_throw_bad_alloc.patch
</span>
</a>
</li>
<li class="file-stats">
<a href="#f492a61d7dd2523a92f1ca988358cb41abf1605d">
<span class="deleted-file">

src/cockpit/389-console/.eslintignore
</span>
</a>
</li>
<li class="file-stats">
<a href="#9e0ef2c0643f74713cb7ef59edf9aae945d60b00">
<span class="deleted-file">

src/cockpit/389-console/.eslintrc.json
</span>
</a>
</li>
<li class="file-stats">
<a href="#982c6309336675acdb1ca5882ea0582b7b235306">
src/cockpit/389-console/.stylelintrc.json
</a>
</li>
<li class="file-stats">
<a href="#414e0969291c534fd68540194caef64d2c7884e3">
<span class="new-file">
+
src/cockpit/389-console/AGENTS.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#0011f9e5b30e26fe40cbeb1c6aee9a9ac313e42e">
<span class="new-file">
+
src/cockpit/389-console/eslint.config.js
</span>
</a>
</li>
<li class="file-stats">
<a href="#dcc67697e0088ccf0bb42c8246f9ddb7784bcab4">
src/cockpit/389-console/package-lock.json
</a>
</li>
<li class="file-stats">
<a href="#fedd3768213fe69b005d450f2e9e10db7be1a0d4">
src/cockpit/389-console/package.json
</a>
</li>
<li class="file-stats">
<a href="#c7be19ab9d52d03b19545857c884f96cc605b8d1">
src/cockpit/389-console/pkg/lib/hooks.js
</a>
</li>
<li class="file-stats">
<a href="#9f90deefd3647ec594b2ccf4d3163dc23ce54a18">
src/cockpit/389-console/pkg/lib/patternfly/patternfly-5-cockpit.scss
</a>
</li>
<li class="file-stats">
<a href="#3f092778a0af474b0ead97cc83caf0faab484a64">
src/cockpit/389-console/po/ja.po
</a>
</li>
<li class="file-stats">
<a href="#87a20151555b8c6f257e4956b37015b7b36b072e">
src/cockpit/389-console/src/LDAPEditor.jsx
</a>
</li>
<li class="file-stats">
<a href="#058bccfcf136cf5aab0c7c879af0256139accb64">
src/cockpit/389-console/src/css/ds.css
</a>
</li>
<li class="file-stats">
<a href="#a85c061d8009a217e36ff3c56e4c11ec33333795">
src/cockpit/389-console/src/database.jsx
</a>
</li>
<li class="file-stats">
<a href="#f6c18d947f297730b082bb508419a19cd176f060">
src/cockpit/389-console/src/ds.jsx
</a>
</li>
<li class="file-stats">
<a href="#952c14e1664bb49ba6d81282240f5e627e670238">
src/cockpit/389-console/src/dsBasicComponents.jsx
</a>
</li>
<li class="file-stats">
<a href="#e91190e9c9f55442d61197202fa6d00b2288486f">
src/cockpit/389-console/src/dsModals.jsx
</a>
</li>
<li class="file-stats">
<a href="#a339383af850f1f1316ebc714d7a8367cf5fc3b5">
src/cockpit/389-console/src/lib/database/attrEncryption.jsx
</a>
</li>
<li class="file-stats">
<a href="#d63d6f1673ccf180fb9429d518893ede4bf30bf5">
src/cockpit/389-console/src/lib/database/backups.jsx
</a>
</li>
<li class="file-stats">
<a href="#769aa0f9e0ab91b981425b18070ed8c972d99c52">
src/cockpit/389-console/src/lib/database/chaining.jsx
</a>
</li>
<li class="file-stats">
<a href="#5ac559b43163af8fa70be502467e455043681ae2">
src/cockpit/389-console/src/lib/database/databaseConfig.jsx
</a>
</li>
<li class="file-stats">
<a href="#a53d4a07284a788f9055753d5682eeab8ad3b0eb">
src/cockpit/389-console/src/lib/database/databaseModal.jsx
</a>
</li>
<li class="file-stats">
<a href="#bd2762e8522bb1fdbaaad832a499796fbc7f4a2f">
src/cockpit/389-console/src/lib/database/databaseTables.jsx
</a>
</li>
<li class="file-stats">
<a href="#040b59a1d3f8822ba2a751de2ac42337c3dcb743">
src/cockpit/389-console/src/lib/database/globalPwp.jsx
</a>
</li>
<li class="file-stats">
<a href="#a2c7aa9fc1c0b1f91dced28f36a130338b357a86">
src/cockpit/389-console/src/lib/database/indexes.jsx
</a>
</li>
<li class="file-stats">
<a href="#40ea8636f98e2f5784dea79de4f22d1a31478ff5">
src/cockpit/389-console/src/lib/database/localPwp.jsx
</a>
</li>
<li class="file-stats">
<a href="#99cf713ad2554402189cef1bfd8d597c8f2d9831">
<span class="new-file">
+
src/cockpit/389-console/src/lib/database/pwpFixupTasks.tsx
</span>
</a>
</li>
<li class="file-stats">
<a href="#6320bf00ef5406e5e8b0978acfeca46b2f9debc2">
<span class="new-file">
+
src/cockpit/389-console/src/lib/database/pwpValidation.jsx
</span>
</a>
</li>
<li class="file-stats">
<a href="#f20c3d363f5f5a67b328076a08b4bf2a723e0be6">
src/cockpit/389-console/src/lib/database/referrals.jsx
</a>
</li>
<li class="file-stats">
<a href="#3c33232fd7d6b4565f2ac9ca05974893edcaf697">
src/cockpit/389-console/src/lib/database/suffix.jsx
</a>
</li>
<li class="file-stats">
<a href="#7364a3bf1952d0dc453efdd6560bd85c0b6cb1d0">
src/cockpit/389-console/src/lib/database/suffixConfig.jsx
</a>
</li>
<li class="file-stats">
<a href="#9afbeab6706d32c5af41300c0b14db3052f56c19">
src/cockpit/389-console/src/lib/database/vlvIndexes.jsx
</a>
</li>
<li class="file-stats">
<a href="#2e0f21d433bcc6f3295917706cd0d7a6b66ebdf1">
<span class="new-file">
+
src/cockpit/389-console/src/lib/dsNumberInput.jsx
</span>
</a>
</li>
<li class="file-stats">
<a href="#48ec97c18eff4a639177dcfe089111a35fb40304">
<span class="new-file">
+
src/cockpit/389-console/src/lib/ldap_editor/effectivePwpModal.jsx
</span>
</a>
</li>
<li class="file-stats">
<a href="#763934deb70e5c9f1d10be160a92db9e33cbc4ba">
src/cockpit/389-console/src/lib/ldap_editor/lib/constants.jsx
</a>
</li>
<li class="file-stats">
<a href="#b6541d7687f04b7a3aebfa8cf61ee262109ea07b">
src/cockpit/389-console/src/lib/ldap_editor/lib/utils.jsx
</a>
</li>
<li class="file-stats">
<a href="#86c8d66d2d8730b310110126bab82b867bb0e78c">
src/cockpit/389-console/src/lib/ldap_editor/search.jsx
</a>
</li>
<li class="file-stats">
<a href="#2eddab19e93cb3f04e1511d004e5392d9f2f12fb">
src/cockpit/389-console/src/lib/ldap_editor/treeView.jsx
</a>
</li>
<li class="file-stats">
<a href="#b73d97ec44693b404ddaf1310527b76892a17a36">
src/cockpit/389-console/src/lib/ldap_editor/wizards/cos.jsx
</a>
</li>
<li class="file-stats">
<a href="#2b43bf0cff932944315d57c9e35314618ec0e63e">
src/cockpit/389-console/src/lib/ldap_editor/wizards/newEntry.jsx
</a>
</li>
<li class="file-stats">
<a href="#d06e92bd51c3d754f079af61c71568b2d3b7fb4f">
src/cockpit/389-console/src/lib/ldap_editor/wizards/operations/aciNew.jsx
</a>
</li>
<li class="file-stats">
<a href="#69402c03d3ac8d58521f94948ae7494934bc24b3">
src/cockpit/389-console/src/lib/ldap_editor/wizards/operations/addCosDefinition.jsx
</a>
</li>
<li class="file-stats">
<a href="#be28d81d59777ceaaaef9190192d0c67210da263">
src/cockpit/389-console/src/lib/ldap_editor/wizards/operations/addGroup.jsx
</a>
</li>
<li class="file-stats">
<a href="#bb36027f2506feea87624d3fe4f93e0f470145e0">
src/cockpit/389-console/src/lib/ldap_editor/wizards/operations/addLdapEntry.jsx
</a>
</li>
<li class="file-stats">
<a href="#41732d193bee6b34f9abcc8023718aeb58810932">
src/cockpit/389-console/src/lib/ldap_editor/wizards/operations/addRole.jsx
</a>
</li>
<li class="file-stats">
<a href="#2b8461cf6b5388cd343b8a020817103d15aba8f5">
src/cockpit/389-console/src/lib/ldap_editor/wizards/operations/addUser.jsx
</a>
</li>
<li class="file-stats">
<a href="#83fe79bcf86adb59729e67072fa08752c63d30c3">
src/cockpit/389-console/src/lib/ldap_editor/wizards/operations/editGroup.jsx
</a>
</li>
<li class="file-stats">
<a href="#eba5237e2724a8a9c586daed55826ecff6f331ac">
src/cockpit/389-console/src/lib/ldap_editor/wizards/operations/genericUpdate.jsx
</a>
</li>
<li class="file-stats">
<a href="#9a9386703d94097f259edc188b7a5f2bf5775d67">
src/cockpit/389-console/src/lib/ldap_editor/wizards/operations/renameEntry.jsx
</a>
</li>
<li class="file-stats">
<a href="#798e46977322727e063e0b5e444c08b88058c024">
src/cockpit/389-console/src/lib/monitor/accesslog.jsx
</a>
</li>
<li class="file-stats">
<a href="#b5fb2a294ebf73342bea7db5494ab37f9906d05f">
src/cockpit/389-console/src/lib/monitor/auditfaillog.jsx
</a>
</li>
<li class="file-stats">
<a href="#8e1856c7a017e0d861ef140091f6ea679ad13ef5">
src/cockpit/389-console/src/lib/monitor/auditlog.jsx
</a>
</li>
<li class="file-stats">
<a href="#d2ec3a6a867e37067453cef4a7eee82e371037ba">
src/cockpit/389-console/src/lib/monitor/dbMonitor.jsx
</a>
</li>
<li class="file-stats">
<a href="#a33531b48ae9e530d0ede4b54e72543d1866aab7">
src/cockpit/389-console/src/lib/monitor/errorlog.jsx
</a>
</li>
<li class="file-stats">
<a href="#9b84a0255fe4fcb1a992494370b4c7fd89418d74">
src/cockpit/389-console/src/lib/monitor/monitorModals.jsx
</a>
</li>
<li class="file-stats">
<a href="#964067d8740a8cb0ee492b13219230eb931ecee2">
src/cockpit/389-console/src/lib/monitor/monitorTables.jsx
</a>
</li>
<li class="file-stats">
<a href="#29cba987e0a0172b3bf06493e5c7c80897ee5dfa">
src/cockpit/389-console/src/lib/monitor/replLogAnalysis.jsx
</a>
</li>
<li class="file-stats">
<a href="#85a1ebdfeca432e323f1898cfb4a144396632b47">
src/cockpit/389-console/src/lib/monitor/replMonAgmts.jsx
</a>
</li>
<li class="file-stats">
<a href="#86fac7a1aebd5404b06a24d0cb8aa0f92690fc7c">
src/cockpit/389-console/src/lib/monitor/replMonConflict.jsx
</a>
</li>
<li class="file-stats">
<a href="#7e04a0bb326f935f0025c8813b34890f171c209c">
src/cockpit/389-console/src/lib/monitor/replMonWinsync.jsx
</a>
</li>
<li class="file-stats">
<a href="#edc843d5d6952fc745f4cad0c6a29db5e4a60bd9">
src/cockpit/389-console/src/lib/monitor/replMonitor.jsx
</a>
</li>
<li class="file-stats">
<a href="#576653354731c326fa2471215ea343e7a76ce13d">
src/cockpit/389-console/src/lib/monitor/securitylog.jsx
</a>
</li>
<li class="file-stats">
<a href="#3d60d88c775577917a854a0332e4586686504b57">
src/cockpit/389-console/src/lib/monitor/serverMonitor.jsx
</a>
</li>
<li class="file-stats">
<a href="#142f2f0b14974a060e4abf8b42f1ecd74f39d0a2">
src/cockpit/389-console/src/lib/monitor/suffixMonitor.jsx
</a>
</li>
<li class="file-stats">
<a href="#b19f958920873159ec682b95f53fb22b63fdb5e7">
src/cockpit/389-console/src/lib/notifications.jsx
</a>
</li>
<li class="file-stats">
<a href="#78d7859bb9c98ff486427155ab7aacec0ec21a2c">
src/cockpit/389-console/src/lib/plugins/accountPolicy.jsx
</a>
</li>
<li class="file-stats">
<a href="#f070523102c76fb0d9a3218639c77c2d80301e66">
src/cockpit/389-console/src/lib/plugins/attributeUniqueness.jsx
</a>
</li>
<li class="file-stats">
<a href="#8c9a8a65f9308a1e5052796bbb0c389c8fec5147">
src/cockpit/389-console/src/lib/plugins/autoMembership.jsx
</a>
</li>
<li class="file-stats">
<a href="#2e1d758b9456457643a033c2647db8c83e44137c">
src/cockpit/389-console/src/lib/plugins/dna.jsx
</a>
</li>
<li class="file-stats">
<a href="#6d38c2ed59755b2de1da642595250750b28c923a">
src/cockpit/389-console/src/lib/plugins/linkedAttributes.jsx
</a>
</li>
<li class="file-stats">
<a href="#c1223b828a6499762ca46df2c457c4291e13f674">
src/cockpit/389-console/src/lib/plugins/managedEntries.jsx
</a>
</li>
<li class="file-stats">
<a href="#ea9e85f1ce1ae92f9acead141e83833ae746ef90">
src/cockpit/389-console/src/lib/plugins/memberOf.jsx
</a>
</li>
<li class="file-stats">
<a href="#11b94ffeb0a205ee700c2416100a61a8b250d886">
src/cockpit/389-console/src/lib/plugins/pamPassThru.jsx
</a>
</li>
<li class="file-stats">
<a href="#a59fc7caa5a99f48a28d7eaaf90f6319c1fdbc07">
src/cockpit/389-console/src/lib/plugins/passthroughAuthentication.jsx
</a>
</li>
<li class="file-stats">
<a href="#3f0ce50eba0c8089d70f7cafd0c6987a6eb11146">
src/cockpit/389-console/src/lib/plugins/pluginBasicConfig.jsx
</a>
</li>
<li class="file-stats">
<a href="#2488ff5620b6256e26496a56b61bc30d6c9d47b4">
src/cockpit/389-console/src/lib/plugins/referentialIntegrity.jsx
</a>
</li>
<li class="file-stats">
<a href="#901668705722fb03850d33ea6567a4a34e6c7a57">
src/cockpit/389-console/src/lib/plugins/retroChangelog.jsx
</a>
</li>
<li class="file-stats">
<a href="#243d65e017d380ebab965092af0ab250ef229def">
src/cockpit/389-console/src/lib/plugins/rootDNAccessControl.jsx
</a>
</li>
<li class="file-stats">
<a href="#f15b9a6cf897776ab35ed5c14d8c5f94117da562">
src/cockpit/389-console/src/lib/plugins/usn.jsx
</a>
</li>
<li class="file-stats">
<a href="#caf5782528c6559942b4d763df924dcb2c10ad83">
src/cockpit/389-console/src/lib/plugins/winsync.jsx
</a>
</li>
<li class="file-stats">
<a href="#93587e2f18b46acd2b22eb36b37e89e3b757bc57">
src/cockpit/389-console/src/lib/replication/replAgmts.jsx
</a>
</li>
<li class="file-stats">
<a href="#c092daf2563175ec111b6f887e704114c8710504">
src/cockpit/389-console/src/lib/replication/replChangelog.jsx
</a>
</li>
<li class="file-stats">
<a href="#40b452e0c17f2fcff059c9aebed432c4c8cb696a">
src/cockpit/389-console/src/lib/replication/replConfig.jsx
</a>
</li>
<li class="file-stats">
<a href="#e061569380881f25a3a8a3300d84d8c4aabe719e">
src/cockpit/389-console/src/lib/replication/replModals.jsx
</a>
</li>
<li class="file-stats">
<a href="#5fac5ad7fe64be9038d00f6e057ddfe0f53db74f">
src/cockpit/389-console/src/lib/replication/replSuffix.jsx
</a>
</li>
<li class="file-stats">
<a href="#028f11cd74f3a428ad3920e6a4acfd2c4ca76239">
src/cockpit/389-console/src/lib/replication/replTasks.jsx
</a>
</li>
<li class="file-stats">
<a href="#177a4a1ccc7138dfc33b02904acf37583785ad18">
src/cockpit/389-console/src/lib/replication/winsyncAgmts.jsx
</a>
</li>
<li class="file-stats">
<a href="#43f5caa9cce87aae04094b2242b75be45b825668">
src/cockpit/389-console/src/lib/security/certificateManagement.jsx
</a>
</li>
<li class="file-stats">
<a href="#1bd9b14a914f2ea4b81a2c5c555c0fc956f9caca">
src/cockpit/389-console/src/lib/security/ciphers.jsx
</a>
</li>
<li class="file-stats">
<a href="#0dfe46cedddb419eb801962751613c445d634340">
<span class="new-file">
+
src/cockpit/389-console/src/lib/security/encryptionModules.jsx
</span>
</a>
</li>
<li class="file-stats">
<a href="#910cf8a310dbed4a851e8c505d30d918ac577766">
src/cockpit/389-console/src/lib/security/securityModals.jsx
</a>
</li>
<li class="file-stats">
<a href="#bf622405c3dafb02ea5282d1ef8ab3ad7293369f">
src/cockpit/389-console/src/lib/security/securityTables.jsx
</a>
</li>
<li class="file-stats">
<a href="#9bd17e6ce2a42b85c8d50c6ff0a30b08062aaebf">
src/cockpit/389-console/src/lib/server/accessLog.jsx
</a>
</li>
<li class="file-stats">
<a href="#998647284ac6df798a7fd451a3125269f5a7da87">
src/cockpit/389-console/src/lib/server/auditLog.jsx
</a>
</li>
<li class="file-stats">
<a href="#b7ca45de0c95051ad266dbb0b30ae16a130b8141">
src/cockpit/389-console/src/lib/server/auditfailLog.jsx
</a>
</li>
<li class="file-stats">
<a href="#8c8a9372a4edf6a76b366bf8c958754471a727b3">
src/cockpit/389-console/src/lib/server/errorLog.jsx
</a>
</li>
<li class="file-stats">
<a href="#17f09c63cd5224993589bdb45c815d0771127972">
src/cockpit/389-console/src/lib/server/ldapi.jsx
</a>
</li>
<li class="file-stats">
<a href="#e2e9a7fdfe15830b03f2d537f73506517923a0e9">
src/cockpit/389-console/src/lib/server/sasl.jsx
</a>
</li>
<li class="file-stats">
<a href="#677d836fb327789e1247a738202b4dc4e1293ba5">
src/cockpit/389-console/src/lib/server/securityLog.jsx
</a>
</li>
<li class="file-stats">
<a href="#7da338bf2d66840e9b75fa139b6efe3ff2915518">
src/cockpit/389-console/src/lib/server/serverModals.jsx
</a>
</li>
<li class="file-stats">
<a href="#c072cffc02f92dd0892997a787defaed53d39349">
src/cockpit/389-console/src/lib/server/settings.jsx
</a>
</li>
<li class="file-stats">
<a href="#dec4647d989e3a6284d4be8937b8fecc093b2f5b">
src/cockpit/389-console/src/lib/server/tuning.jsx
</a>
</li>
<li class="file-stats">
<a href="#030442dd6439abc307dba87a6b22d4deb4cede17">
src/cockpit/389-console/src/lib/tools.jsx
</a>
</li>
<li class="file-stats">
<a href="#6deac535c943bc0d2eca4b185e27e040a2c5b9b5">
src/cockpit/389-console/src/monitor.jsx
</a>
</li>
<li class="file-stats">
<a href="#6ace6fee93f56baee9319533d15c66590f842377">
src/cockpit/389-console/src/plugins.jsx
</a>
</li>
<li class="file-stats">
<a href="#d810fffa0ab1c81aed25cdb09e198ead621a0a42">
src/cockpit/389-console/src/replication.jsx
</a>
</li>
<li class="file-stats">
<a href="#123bfefa882942fdb6f4b535ff05542098dacec9">
src/cockpit/389-console/src/schema.jsx
</a>
</li>
<li class="file-stats">
<a href="#ab2524f4a604a527648844afeb1cf4cc68a1c520">
src/cockpit/389-console/src/security.jsx
</a>
</li>
<li class="file-stats">
<a href="#a64954387d8651c0023b94020b19bfc46a0a5652">
src/cockpit/389-console/src/server.jsx
</a>
</li>
<li class="file-stats">
<a href="#393378f87ba2c77ca969c3fa998508fae237b7f5">
<span class="new-file">
+
src/cockpit/389-console/tsconfig.json
</span>
</a>
</li>
<li class="file-stats">
<a href="#e995ac91fff442613faaf20b09235c6b6c45f897">
<span class="new-file">
+
src/lib389/AGENTS.md
</span>
</a>
</li>
<li class="file-stats">
<a href="#503a6352d502b728de43af23310cb308d6e619f9">
src/lib389/cli/dscontainer
</a>
</li>
<li class="file-stats">
<a href="#3cff09cd06aa9b05f4c5e32164ac00a37e7df137">
src/lib389/cli/dsctl
</a>
</li>
<li class="file-stats">
<a href="#100dd49293cba82d9e529b9d3ec2d85b72ee0546">
src/lib389/cli/dsidm
</a>
</li>
<li class="file-stats">
<a href="#d2f2b9ba51cd8265c18db6c88fbcd4f86b3ed6d9">
src/lib389/doc/source/paths.rst
</a>
</li>
<li class="file-stats">
<a href="#408ceef8344b632bd62f88c93d86f4beb48ddf85">
src/lib389/doc/source/replica.rst
</a>
</li>
<li class="file-stats">
<a href="#34e7b9428c4cb35c828af9466a36729c631076da">
src/lib389/lib389/__init__.py
</a>
</li>
<li class="file-stats">
<a href="#df19897fe499b77c52de7998d0ed3dda88866d48">
src/lib389/lib389/_constants.py
</a>
</li>
<li class="file-stats">
<a href="#6b590ba3275a82a607bbc68aadfbbccbc9d7c7b0">
src/lib389/lib389/_controls.py
</a>
</li>
<li class="file-stats">
<a href="#94e01ff9e9ffb4e3ad97fdf3a9db19691aba16f3">
src/lib389/lib389/_mapped_object.py
</a>
</li>
<li class="file-stats">
<a href="#47267ef651f8e63d673752f99f1974e23f160923">
src/lib389/lib389/_mapped_object_lint.py
</a>
</li>
<li class="file-stats">
<a href="#5f747596068ebce57208e07ec74cdf2dc5952893">
src/lib389/lib389/backend.py
</a>
</li>
<li class="file-stats">
<a href="#372164f5139b05a867fa93a28f962066da98b08e">
<span class="new-file">
+
src/lib389/lib389/cert_manager.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#20ddcc62d023b00bfb6843a92eea01df5f03e077">
src/lib389/lib389/cli_base/__init__.py
</a>
</li>
<li class="file-stats">
<a href="#f4065a36ceaa7b191d32fdb8beb1c8fecd03d2fc">
src/lib389/lib389/cli_conf/backend.py
</a>
</li>
<li class="file-stats">
<a href="#a9ab742f13b9fe2a184d4760a3043505fe1a8dbb">
src/lib389/lib389/cli_conf/backup.py
</a>
</li>
<li class="file-stats">
<a href="#c55602ce1ae581e82a19d3aa9784978063e3a191">
src/lib389/lib389/cli_conf/monitor.py
</a>
</li>
<li class="file-stats">
<a href="#7979ff115e4c7e96566166081aa4f8fc010695ed">
src/lib389/lib389/cli_conf/plugins/accountpolicy.py
</a>
</li>
<li class="file-stats">
<a href="#65d9e28374620136a7088f13a30829291bb05c31">
src/lib389/lib389/cli_conf/plugins/attruniq.py
</a>
</li>
<li class="file-stats">
<a href="#4c22fbc382b9801e5e095c69d9cd2a0df997dc3d">
src/lib389/lib389/cli_conf/plugins/contentsync.py
</a>
</li>
<li class="file-stats">
<a href="#e6e29eb2996bb606ed304eec8602de22f3966d35">
src/lib389/lib389/cli_conf/plugins/pwstorage.py
</a>
</li>
<li class="file-stats">
<a href="#96102e19b25edbd06af83dff839077308d3b461d">
src/lib389/lib389/cli_conf/plugins/retrochangelog.py
</a>
</li>
<li class="file-stats">
<a href="#b41a8baa54a918369b8310a82352563b337d6c5d">
src/lib389/lib389/cli_conf/pwpolicy.py
</a>
</li>
<li class="file-stats">
<a href="#0d3017cefea0db22572e5942e8753ca16cf6184d">
src/lib389/lib389/cli_conf/replication.py
</a>
</li>
<li class="file-stats">
<a href="#7e7f1c649fc5009cf5998e8602558af56d463d6f">
src/lib389/lib389/cli_conf/security.py
</a>
</li>
<li class="file-stats">
<a href="#7fa1483c315a6936170ec579c0061956af498e7e">
src/lib389/lib389/cli_ctl/cockpit.py
</a>
</li>
<li class="file-stats">
<a href="#d8072a9ac1e67c1fe34f046ed750e6c54504c3f8">
src/lib389/lib389/cli_ctl/dbtasks.py
</a>
</li>
<li class="file-stats">
<a href="#d9583a3e0a43705c1cfee9f55e721d8eebdbebd1">
src/lib389/lib389/cli_ctl/health.py
</a>
</li>
<li class="file-stats">
<a href="#27ac6cbb5c6952388d6c742cdc03c539c8d88f01">
<span class="new-file">
+
src/lib389/lib389/cli_ctl/threadpool.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#a0a18e3d1e0b036822150a5a3033db5f4b20f02e">
src/lib389/lib389/cli_ctl/tls.py
</a>
</li>
<li class="file-stats">
<a href="#de27264201813548d5c864c64b02b6583634f797">
src/lib389/lib389/cli_idm/user.py
</a>
</li>
<li class="file-stats">
<a href="#17a8af093f6d283195ce37db04241fa7bfab78b4">
src/lib389/lib389/config.py
</a>
</li>
<li class="file-stats">
<a href="#9b168c431dd6a6a5a1a8f12aa1614bb4b4b235c4">
src/lib389/lib389/dirsrv_log.py
</a>
</li>
<li class="file-stats">
<a href="#4c465167fba34bb30401a4f11f240d47872df5da">
src/lib389/lib389/dseldif.py
</a>
</li>
<li class="file-stats">
<a href="#2b6fbfb12c05151cb1a7de51883eb5b593184fcd">
<span class="new-file">
+
src/lib389/lib389/dseutils.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#847783e7098b55d0a3cff103188a7ba9c1420827">
<span class="new-file">
+
src/lib389/lib389/dyncerts.py
</span>
</a>
</li>
<li class="file-stats">
<a href="#8b37a1ee942d652439a9063ebc2f5bfd9b993f49">
src/lib389/lib389/idm/services.py
</a>
</li>
<li class="file-stats">
<a href="#d640f5c3f972b2226255f375b04e0dcbab8e4a90">
src/lib389/lib389/idm/user.py
</a>
</li>
<li class="file-stats">
<a href="#84501a5b4cbd15a1a9d1f27f5463ec6a742949a3">
src/lib389/lib389/lint.py
</a>
</li>
<li class="file-stats">
<a href="#4a810aaef1e5789bb6c9de3e8fa66bb142be6c63">
src/lib389/lib389/monitor.py
</a>
</li>
<li class="file-stats">
<a href="#cf6cddbba8f04ae951b9741be1bffe0e8b8e90f7">
src/lib389/lib389/nss_ssl.py
</a>
</li>
<li class="file-stats">
<a href="#c87fb4996743b548bfb08203e05a4d885b64bdcf">
src/lib389/lib389/password_plugins.py
</a>
</li>
<li class="file-stats">
<a href="#5feded498e42e1e508a318a5b2f640046df640f2">
src/lib389/lib389/paths.py
</a>
</li>
<li class="file-stats">
<a href="#c6941bd04b9d8316e83d3217542dac8ad0ac217b">
src/lib389/lib389/plugins.py
</a>
</li>
<li class="file-stats">
<a href="#9c778349ac5b9d6a0f3b2684e15bad9e2f3a75b7">
src/lib389/lib389/properties.py
</a>
</li>
<li class="file-stats">
<a href="#e8107af7b9a2a2d62b5724596affaa4511348178">
src/lib389/lib389/pwpolicy.py
</a>
</li>
<li class="file-stats">
<a href="#ad55fd2caf28a94975d35a83af14aac82498cf1d">
src/lib389/lib389/replica.py
</a>
</li>
<li class="file-stats">
<a href="#d77f49690cf7460efd4d3db3b62533a55d163d85">
src/lib389/lib389/repltools.py
</a>
</li>
<li class="file-stats">
<a href="#0128f375fc5e8d490e5f3a2dd97c958e3538c5dc">
src/lib389/lib389/tasks.py
</a>
</li>
<li class="file-stats">
<a href="#fcb0e5c83451ab7afda251bb638581b30839d129">
src/lib389/lib389/tests/backend_test.py
</a>
</li>
<li class="file-stats">
<a href="#d7aac92a263f3914b77433da7c1a6702b4b17fbe">
src/lib389/lib389/tests/cli/__init__.py
</a>
</li>
<li class="file-stats">
<a href="#e7fd012376c9332e0b45c4549e3e97c5a769d2e8">
src/lib389/lib389/tests/cli/conf_backend_test.py
</a>
</li>
<li class="file-stats">
<a href="#36f76a638eb6a12cd45faa8c1e97983431ee630c">
src/lib389/lib389/tests/cli/conf_backup_test.py
</a>
</li>
<li class="file-stats">
<a href="#4e9329011b0d271908763eb0c62904c1c5bb7530">
src/lib389/lib389/tests/cli/conf_chaining_test.py
</a>
</li>
<li class="file-stats">
<a href="#3c1f901b0e97af2e8f2276b5bbf1d0b7e5c2b4c7">
src/lib389/lib389/tests/cli/conf_conflicts_test.py
</a>
</li>
<li class="file-stats">
<a href="#1b30a8b7b8d77fb51c3d2ec56ec24711c3456750">
src/lib389/lib389/tests/cli/conf_pwpolicy_test.py
</a>
</li>
<li class="file-stats">
<a href="#8e41a03600dbbe8766fa2468e63041af23f6d264">
src/lib389/lib389/tests/configurations/config_001003006_test.py
</a>
</li>
<li class="file-stats">
<a href="#8a30a1b1437d44b6a05053f15aa9a4d150009a81">
src/lib389/lib389/tests/configurations/config_001004000_test.py
</a>
</li>
<li class="file-stats">
<a href="#b31c10c5da5687d62050b5f878305e23fb6f9865">
src/lib389/lib389/tests/dirsrv_log_test.py
</a>
</li>
<li class="file-stats">
<a href="#148a7674489bf97d496a50c1edaca1022e5ddef8">
src/lib389/lib389/tests/dseldif_test.py
</a>
</li>
<li class="file-stats">
<a href="#0d337d74a0b63f8d02760b612640c10c2f8e5bc6">
src/lib389/lib389/tests/healthcheck_test.py
</a>
</li>
<li class="file-stats">
<a href="#9dad0044fda7b514ec5a1b14f5f46c285711faf8">
src/lib389/lib389/tests/idm/account_test.py
</a>
</li>
<li class="file-stats">
<a href="#e3d257cae4e344051ca77b5b84ee99e0486827c8">
src/lib389/lib389/tests/idm/services_test.py
</a>
</li>
<li class="file-stats">
<a href="#36e751603e421512882b1b6a4497c6ced715e033">
src/lib389/lib389/tests/idm/user_and_group_test.py
</a>
</li>
<li class="file-stats">
<a href="#2ad9be765fbf9aba104632a4920c57b06d9593c9">
src/lib389/lib389/tests/index_test.py
</a>
</li>
<li class="file-stats">
<a href="#320140032ae1ff619705cf699c6ed8a894a7dfc0">
src/lib389/lib389/tests/mapped_object_test.py
</a>
</li>
<li class="file-stats">
<a href="#ed4f1cd1c66d6df8cdfb6770d6f74226ecaafe19">
src/lib389/lib389/tests/nss_ssl_test.py
</a>
</li>
<li class="file-stats">
<a href="#cee52c793ad25613090ad4ac46391ee35ef4341c">
src/lib389/lib389/tests/plugins/memberof_test.py
</a>
</li>
<li class="file-stats">
<a href="#3f16b4170a482ce654852c73087f6c2917787747">
src/lib389/lib389/tests/plugins/referint_test.py
</a>
</li>
<li class="file-stats">
<a href="#3d99544de76c07bc7565f7b9dc23cbff4556ad71">
src/lib389/lib389/tests/plugins/usn_test.py
</a>
</li>
<li class="file-stats">
<a href="#3d14228ddfac5756390a05143d8e38bfd056b289">
src/lib389/lib389/tests/referral_test.py
</a>
</li>
<li class="file-stats">
<a href="#9ae25aa4c0fb0653ee186580a87d5c2909d43a8e">
src/lib389/lib389/tests/replica_test.py
</a>
</li>
<li class="file-stats">
<a href="#4be0b1d623e72bdb008d48eba8cf9c3610334401">
src/lib389/lib389/tests/schema_test.py
</a>
</li>
<li class="file-stats">
<a href="#2e64104a02908d7b8a1ed778d286e234e190e528">
src/lib389/lib389/tests/tls_external_test.py
</a>
</li>
<li class="file-stats">
<a href="#dba9dd0297b3a761766f4481c195f02f47347c1b">
src/lib389/lib389/tunables.py
</a>
</li>
<li class="file-stats">
<a href="#f2a2ee5c672e420ab850ef59d1ea31b0e78776f7">
src/lib389/lib389/utils.py
</a>
</li>
<li class="file-stats">
<a href="#76498f5f9eb22a4d6c2f9dd2cc355fb29216182d">
src/lib389/pyproject.toml
</a>
</li>
<li class="file-stats">
<a href="#c883f7609f1ea61572219c267eced5bc11e73519">
src/lib389/requirements.txt
</a>
</li>
<li class="file-stats">
<a href="#c87b9e1ddafef813c5fa167fd4a0a4e2ff61409b">
src/librnsslapd/Cargo.toml
</a>
</li>
<li class="file-stats">
<a href="#aef9b7227b1f8292b1d2aa16134450c476c188e5">
src/librslapd/Cargo.toml
</a>
</li>
<li class="file-stats">
<a href="#3a80d42feabb8c0b2e1978e651d2d58fd98d7699">
src/plugins/entryuuid/Cargo.toml
</a>
</li>
<li class="file-stats">
<a href="#b20ac90680ca747ea8a8352886fb5a3d00e49b48">
src/plugins/entryuuid_syntax/Cargo.toml
</a>
</li>
<li class="file-stats">
<a href="#df43b82a686e10d4b316e4b6e4e1e74dde051a2c">
src/plugins/entryuuid_syntax/src/lib.rs
</a>
</li>
<li class="file-stats">
<a href="#19d1def580a4bbb2168115939d857b942f468134">
src/plugins/pwdchan/Cargo.toml
</a>
</li>
<li class="file-stats">
<a href="#cf48059c78100da12ec505383b61ea604e8eae15">
src/plugins/pwdchan/src/lib.rs
</a>
</li>
<li class="file-stats">
<a href="#ba4739853ed1928c718e31c71460b0b8171bd9e8">
src/slapd/Cargo.toml
</a>
</li>
<li class="file-stats">
<a href="#ffa53cea5da293b8b749f4546c6ba123a8846a59">
src/slapi_r_plugin/Cargo.toml
</a>
</li>
<li class="file-stats">
<a href="#78070cd498f566c609a9de95c2078a8e1c65d98f">
src/slapi_r_plugin/src/value.rs
</a>
</li>
<li class="file-stats">
<a href="#b1cfcf987ee3ecb596fa5fad9099112b2a30edfb">
src/svrcore/src/systemd-ask-pass.c
</a>
</li>
<li class="file-stats">
<a href="#f276750727657fe2b88e29a0dffec2c7dc2167ad">
<span class="new-file">
+
test/libslapd/csngen/clock_error.c
</span>
</a>
</li>
<li class="file-stats">
<a href="#58730759b9bb73ed4a3361de7a50b53c0e171f9f">
<span class="new-file">
+
test/libslapd/hibp/parse.c
</span>
</a>
</li>
<li class="file-stats">
<a href="#ceafed5596ea8070d6bc094e6c90a8cfb12068ad">
test/libslapd/test.c
</a>
</li>
<li class="file-stats">
<a href="#13ca926638be44201cc6064a8cf0e99ce060004a">
test/plugins/pwdstorage/pbkdf2.c
</a>
</li>
<li class="file-stats">
<a href="#3f68d51d8afbebbba852ae8569643b15b6be9cc1">
test/plugins/test.c
</a>
</li>
<li class="file-stats">
<a href="#cca9d04ff288da04a59086aecbf3dcefc88a16f4">
test/test_slapd.h
</a>
</li>
<li class="file-stats">
<a href="#4064dd15af1165fd932864aa39c5962c5244cf9c">
wrappers/systemd-snmp.service.in
</a>
</li>
<li class="file-stats">
<a href="#9f832dbbf456b1c159071e5f529b98fcd26cf119">
wrappers/systemd.template.service.in
</a>
</li>
</ul>
<h5 style="margin-top: 10px; margin-bottom: 10px; font-size: .875rem;">
The diff was not included because it is too large.
</h5>

</div>
<div class="footer" style="margin-top: 10px;">
<p style="font-size: small; color: #626168;">

<br>
<a href="https://salsa.debian.org/freeipa-team/389-ds-base/-/compare/b6ac325cb41937b9b8bc8217f0ec4f63153a0c0f...413ea783a120e7740565c281b20b01dbf5931df1">View it on GitLab</a>.
<br>
You're receiving this email because of your account on <a target="_blank" rel="noopener noreferrer" href="https://salsa.debian.org">salsa.debian.org</a>. <a href="https://salsa.debian.org/-/profile/notifications" target="_blank" rel="noopener noreferrer" class="mng-notif-link">Manage all notifications</a> · <a href="https://salsa.debian.org/help" target="_blank" rel="noopener noreferrer" class="help-link">Help</a>
<span style="color: transparent; font-size: 0; display: none; overflow: hidden; opacity: 0; width: 0; height: 0; max-width: 0; max-height: 0;">
Notification message regarding https://salsa.debian.org/freeipa-team/389-ds-base/-/compare/b6ac325cb41937b9b8bc8217f0ec4f63153a0c0f...413ea783a120e7740565c281b20b01dbf5931df1 at 1788963273
</span>



</p>
</div>
</body>
</html>