The duplicate-rule check in verify() compares every rule of a prefix-list with every other, on every policy commit. The cost is small at a few thousand rules and grows with the square of the list size.
Root cause. verify() keeps the rules seen so far in a list and tests each new rule with in.
Measurements. 0.08 s at 2,000 rules on a 1.5.1 node. verify() alone, benchmarked from the circinus source on a workstation: 41.8 s at 40,000 rules, 0.11 s with the fix.
Fix direction. Keep a set of tuple(sorted(rule_config.items())) instead of a list. The same rules are flagged, with the same message.