[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: OpenLDAP goes too deep with regex's (ITS#2174)




--On Monday, November 11, 2002 11:13 AM -0800 "Kurt D. Zeilenga" 
<Kurt@OpenLDAP.org> wrote:

>
> At 11:01 AM 2002-11-11, Quanah Gibson-Mount wrote:
>> Nov 11 10:48:33 ldap3.Stanford.EDU slapd[1851]: [ID 791166 local4.debug]
>> <= test_filter 5
>
> FALSE
>
>> Nov 11 10:48:34 ldap3.Stanford.EDU slapd[1851]: [ID 791166 local4.debug]
>> <= test_filter 6
>
> TRUE
>
>> Nov 11 10:48:34 ldap3.Stanford.EDU slapd[1851]: [ID 238222 local4.debug]
>> <= test_filter_or 6
>
>
> TRUE
>
>> Nov 11 10:48:34 ldap3.Stanford.EDU slapd[1851]: [ID 791166 local4.debug]
>> <= test_filter 6
>
>
> TRUE
>
>> So, even though it received the EQUALITY for krb5PrincipalName
>
> The above shows the first EQUALITY match resulted in FALSE (5).
>
>> , it did not short-circuit the search, and continued with a check for
>> suKrb5Name.
>
> and hence it did not short circuit the OR evaluation.

Kurt,

*sigh* You can close this.  Someone played with my People data for some 
testing, and didn't tell me, switching my principal's around.

--Quanah

--
Quanah Gibson-Mount
Senior Systems Administrator
ITSS/TSS/Computing Systems
Stanford University
GnuPG Public Key: http://www.stanford.edu/~quanah/pgp.html