Cause: Using the Referential Integrity plugin with a delay time greater than 0, and doing an LDAP RENAME operation on a user entry where that user's entry DN is specified by one or more groups under the scope of the Referential Integrity plugin.
Consequence: The group entries still have the old user entry DN, not the new one.
Fix: The code was writing the literal string "NULL" instead of an empty field to the referential integrity changelog in the newsuperior field. The fix is to write an empty field when there is no newsuperior.
Result: LDAP RENAME operations work when Referential Integrity is enabled with delay time > 0.