Re: Re: [HACKERS] [PATCH] Re: Setuid functions

Поиск
Список
Период
Сортировка
От Bruce Momjian
Тема Re: Re: [HACKERS] [PATCH] Re: Setuid functions
Дата
Msg-id 200107111958.f6BJwtj04779@candle.pha.pa.us
обсуждение исходный текст
Ответ на Re: Re: [HACKERS] [PATCH] Re: Setuid functions  (Peter Eisentraut <peter_e@gmx.net>)
Список pgsql-patches
> Bruce Momjian writes:
>
> > > I updated the patch to use the SET AUTHORIZATION { INVOKER | DEFINER }
> > > terminology. Also, the function owner is now determined and saved at compile
> > > time (no gotchas here, right?). It is located at
> > >
> > > http://volpe.home.mindspring.com/pgsql/set_auth.patch
> >
> > OK, patch applied.  Can I have some docs with that burger?  :-)
>
> I think we concluded that this feature introduced a security hole.

I thought that was addressed in the patch with the mention of:

> > > Also, the function owner is now determined and saved at compile
> > > time (no gotchas here, right?).

Does anyone remember?

--
  Bruce Momjian                        |  http://candle.pha.pa.us
  pgman@candle.pha.pa.us               |  (610) 853-3000
  +  If your life is a hard drive,     |  830 Blythe Avenue
  +  Christ can be your backup.        |  Drexel Hill, Pennsylvania 19026

В списке pgsql-patches по дате отправления:

Предыдущее
От: Peter Eisentraut
Дата:
Сообщение: Re: Re: [HACKERS] [PATCH] Re: Setuid functions
Следующее
От: Bruce Momjian
Дата:
Сообщение: Re: Re: [HACKERS] [PATCH] Re: Setuid functions