Re: Possible major bug in PlPython (plus some other ideas)

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Possible major bug in PlPython (plus some other ideas)
Дата
Msg-id 21461.1005335302@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: Possible major bug in PlPython (plus some other ideas)  (Hannu Krosing <hannu@tm.ee>)
Ответы Re: Possible major bug in PlPython (plus some other ideas)  (teg@redhat.com (Trond Eivind Glomsrød))
Список pgsql-hackers
Hannu Krosing <hannu@tm.ee> writes:
>> However, the default behavior of the restricted execution environment
>> being used allows read-only filesystem access.

> we have 'read-only filesystem access anyhow' :

> pg72b2=# create table hack(row text);
> CREATE
> pg72b2=# copy hack from '/home/pg72b2/data/pg_hba.conf' DELIMITERS
> '\01';

Only if you're superuser, which is exactly the point of the trusted
vs untrusted function restriction.  The plpython problem lets
non-superusers read any file that the postgres user can read, which
is not cool.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Bradley McLean
Дата:
Сообщение: Re: Possible major bug in PlPython (plus some other ideas)
Следующее
От: Tom Lane
Дата:
Сообщение: Re: 'real' strange problem in 7.1.3