Re: Git cvsserver serious issue

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Git cvsserver serious issue
Дата
Msg-id 2548.1285256475@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: Git cvsserver serious issue  (Andrew Dunstan <andrew@dunslane.net>)
Список pgsql-hackers
Andrew Dunstan <andrew@dunslane.net> writes:
>> On Thu, Sep 23, 2010 at 17:16, Tom Lane<tgl@sss.pgh.pa.us>  wrote:
>>> I'm still wondering why we don't simply lobotomize git-cvsserver to
>>> refuse requests to check out anything except the active branch tips.

> Are we sure that's going to stop the DOS issue?

The claimed denial of service is that each checkout target requires a
separate SQLite database.  Limit the number of checkout targets accepted
and you're done.  Or at least, if you're not done, it behooves those
claiming there's a security problem to show what the problem is.  It's
not like this piece of software isn't used in production, so I doubt
it needs to be babied quite as much as this thread is assuming.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Magnus Hagander
Дата:
Сообщение: Re: Git cvsserver serious issue
Следующее
От: Tom Lane
Дата:
Сообщение: Re: Configuring synchronous replication