Re: Attention PL authors: want to be listed in template table?

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Attention PL authors: want to be listed in template table?
Дата
Msg-id 11399.1126200906@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Attention PL authors: want to be listed in template table?  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: Attention PL authors: want to be listed in template table?  (Thomas Hallgren <thhal@mailblocks.com>)
Список pgsql-hackers
Peter Eisentraut <peter_e@gmx.net> writes:
> Thomas Hallgren wrote:
>> PL/Java is designed to run perfectly safe with a JVM that has the
>> correct features implemented. GCJ has serious issues with security
>> and I don't see that PL/Java, nor PostgreSQL should make any attempt
>> to fix them.

> Well, we had a similar discussion about the time when the Python 
> security support was decreed nonexistent by its author.  Clearly, 
> people still use Python, and people still use PL/Python.  It's really 
> easy to spread a panic by claiming that GCJ has "no security".  That's 
> clearly wrong because GCJ can be used safely in many useful situations.

Actually, I've just been discussing this with Red Hat's gcj people in
connection with a different project.  What they say is that the Java
security manager is completely implemented now, but what is still
missing is that it's possible to bypass Java security if you can execute
untrusted bytecode.  So if I understand correctly, a gcj environment is
secure as long as you can prevent hacked-up class files from getting
into your classpath.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Peter Eisentraut
Дата:
Сообщение: Re: pg_config/share_dir
Следующее
От: Simon Riggs
Дата:
Сообщение: Re: statement logging / extended query protocol issues