Re: partial replication of entries/attributes

> In LDAP/X.500, modifications are atomic, all-or-nothing. If any part of an
> update fails the entire update must fail. The place to limit things is on the
> master, when it generates the replog.

I definitely meant using some sort of ACLs when generating the replog
data, a sort of extension/generalization of the current code that
partially replicates a subtree.  One could think of generating only
partial changes based on some rule; ACLs may be one flexible way to
write those rules.