https://bugs.openldap.org/show_bug.cgi?id=9211
Bug ID: 9211
Summary: Relax control is not consistently access-restricted
Product: OpenLDAP
Version: 2.4.49
Hardware: All
OS: All
Status: UNCONFIRMED
Severity: normal
Priority: ---
Component: slapd
Assignee: bugs(a)openldap.org
Reporter: ryan(a)openldap.org
Target Milestone: ---
The following operations can be performed by anyone having 'write' access (not
even 'manage') using the Relax control:
- modifying/replacing structural objectClass
- adding/modifying OBSOLETE attributes
Some operations are correctly restricted:
- adding/modifying NO-USER-MODIFICATION attributes marked as manageable
(Modification of non-conformant objects doesn't appear to be implemented at
all.)
In the absence of ACLs for controls, I'm of the opinion that all use of the
Relax control should require manage access. The Relax draft clearly and
repeatedly discusses its use cases in terms of directory _administrators_
temporarily relaxing constraints in order to accomplish a specific task.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugs.openldap.org/show_bug.cgi?id=6198
Quanah Gibson-Mount <quanah(a)openldap.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
Status|IN_PROGRESS |RESOLVED
Resolution|--- |TEST
--- Comment #9 from Quanah Gibson-Mount <quanah(a)openldap.org> ---
head:
• 50befa2a
by OndÅ™ej KuznÃk at 2026-04-30T16:41:28+00:00
ITS#6198 Expose verbmasks globally
• c28108fb
by OndÅ™ej KuznÃk at 2026-04-30T16:41:28+00:00
ITS#6198 backend: Simplify opflag handling
• bb64b0b5
by OndÅ™ej KuznÃk at 2026-04-30T16:41:28+00:00
ITS#6198 ACL: separate <who> checking
• fbf682a6
by OndÅ™ej KuznÃk at 2026-04-30T16:41:28+00:00
ITS#6198 Allow extop and control restrictions in ACLs
• aefd96f8
by OndÅ™ej KuznÃk at 2026-04-30T16:41:28+00:00
ITS#6198 Introduce restrictop functionality
• 0160e81d
by OndÅ™ej KuznÃk at 2026-04-30T16:41:28+00:00
ITS#6198 Register exop and control OID macros in schema
--
You are receiving this mail because:
You are on the CC list for the issue.
https://bugs.openldap.org/show_bug.cgi?id=9011
Quanah Gibson-Mount <quanah(a)openldap.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
Target Milestone|--- |1.0.0
Assignee|bugs(a)openldap.org |hyc(a)openldap.org
--- Comment #6 from Quanah Gibson-Mount <quanah(a)openldap.org> ---
mdb.master3:
• cf1478d2
by Christopher Zimmermann at 2026-05-04T14:46:11+01:00
ITS#9011 LMDB: add mdb_txn_flags()
• 4de954fe
by Howard Chu at 2026-05-04T14:47:50+01:00
Whitespace cleanup
• c38375ec
by Howard Chu at 2026-05-04T14:50:25+01:00
ITS#9011 LMDB: fix typo in prev commit
mdb.RE/1.0:
• 11ebc033
by Christopher Zimmermann at 2026-05-04T14:48:56+01:00
ITS#9011 LMDB: add mdb_txn_flags()
• 1924ae9b
by Howard Chu at 2026-05-04T14:49:07+01:00
Whitespace cleanup
• c2b1cab5
by Howard Chu at 2026-05-04T14:50:46+01:00
ITS#9011 LMDB: fix typo in prev commit
--
You are receiving this mail because:
You are on the CC list for the issue.
https://bugs.openldap.org/show_bug.cgi?id=8335
Quanah Gibson-Mount <quanah(a)openldap.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
Target Milestone|--- |0.9.36
Assignee|bugs(a)openldap.org |hyc(a)openldap.org
--- Comment #9 from Quanah Gibson-Mount <quanah(a)openldap.org> ---
mdb.RE/0.9:
• 8029fc6f
by Howard Chu at 2026-04-27T18:44:21+01:00
ITS#8335 LMDB: reject MDB_MULTIPLE put with 0 items
mdb.master:
• 6888aa47
by Howard Chu at 2026-04-27T18:43:52+01:00
ITS#8335 LMDB: reject MDB_MULTIPLE put with 0 items
mdb.master3:
• 0ff5b99e
by Howard Chu at 2026-04-27T18:42:49+01:00
ITS#8335 LMDB: reject MDB_MULTIPLE put with 0 items
--
You are receiving this mail because:
You are on the CC list for the issue.
https://bugs.openldap.org/show_bug.cgi?id=7772
Quanah Gibson-Mount <quanah(a)openldap.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
Assignee|bugs(a)openldap.org |hyc(a)openldap.org
Target Milestone|--- |0.9.36
--- Comment #6 from Quanah Gibson-Mount <quanah(a)openldap.org> ---
mdb.master:
• 143ce300
by Howard Chu at 2026-04-27T15:02:14+01:00
ITS#7772 LMDB: fix sub-page growth
mdb.RE/0.9:
• 510aa4b8
by Howard Chu at 2026-04-27T15:02:25+01:00
ITS#7772 LMDB: fix sub-page growth
mdb.master3:
• 134e5ace
by Howard Chu at 2026-04-27T14:59:00+01:00
ITS#7772 LMDB: fix sub-page growth
--
You are receiving this mail because:
You are on the CC list for the issue.
https://bugs.openldap.org/show_bug.cgi?id=8803
Quanah Gibson-Mount <quanah(a)openldap.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
Target Milestone|--- |1.0.0
Assignee|bugs(a)openldap.org |hyc(a)openldap.org
--- Comment #3 from Quanah Gibson-Mount <quanah(a)openldap.org> ---
mdb.master3:
• 7a1f36d5
by Nir Soffer at 2026-04-24T20:19:46+01:00
ITS#8803 LMDB: add tool option to disable locking
--
You are receiving this mail because:
You are on the CC list for the issue.
https://bugs.openldap.org/show_bug.cgi?id=8192
--- Comment #6 from Quanah Gibson-Mount <quanah(a)openldap.org> ---
mdb.master3:
• ba6e0018
by Howard Chu at 2026-04-24T18:07:42+01:00
ITS#8192 fix prev commit
--
You are receiving this mail because:
You are on the CC list for the issue.
https://bugs.openldap.org/show_bug.cgi?id=8192
Quanah Gibson-Mount <quanah(a)openldap.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
Target Milestone|--- |1.0.0
Assignee|bugs(a)openldap.org |hyc(a)openldap.org
--- Comment #5 from Quanah Gibson-Mount <quanah(a)openldap.org> ---
mdb.master3:
• bf5c4e0f
by Howard Chu at 2026-04-24T16:05:40+01:00
ITS#8192 LMDB: define new error codes to avoid errno abuse
--
You are receiving this mail because:
You are on the CC list for the issue.
https://bugs.openldap.org/show_bug.cgi?id=8579
Quanah Gibson-Mount <quanah(a)openldap.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
Assignee|bugs(a)openldap.org |hyc(a)openldap.org
--- Comment #3 from Quanah Gibson-Mount <quanah(a)openldap.org> ---
mdb.master3:
• cf52db2b
by Howard Chu at 2026-04-23T18:55:06+01:00
ITS#8579 LMDB: all descriptors should have O_CLOEXEC
--
You are receiving this mail because:
You are on the CC list for the issue.
https://bugs.openldap.org/show_bug.cgi?id=9027
Quanah Gibson-Mount <quanah(a)openldap.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
Target Milestone|--- |1.0.0
Assignee|bugs(a)openldap.org |hyc(a)openldap.org
--- Comment #6 from Quanah Gibson-Mount <quanah(a)openldap.org> ---
mdb.master3:
• 63698faf
by Howard Chu at 2026-04-22T19:22:56+01:00
ITS#9027 LMDB: expose address of memory map
--
You are receiving this mail because:
You are on the CC list for the issue.