Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL
Дата
Msg-id 26651.1030682520@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: @(#)Mordred Labs advisory 0x0007: Remove DoS in PostgreSQL  (Þórhallur Hálfdánarson <tolli@tol.li>)
Список pgsql-hackers
Þórhallur Hálfdánarson <tolli@tol.li> writes:
> And another (perhaps silly) thought: Currently, if the authentication
> process is exploited, it would kill the postmaster, resulting in a
> total crash of the whole database system.  Would it be beneficial to
> split the connection handling/authorization process to a seperate
> process, and if that process dies, the postmaster would simply start a
> new one, there for not affecting any other backends that are running
> (for authorized users) ? Or am I way of track? :) 

No, just behind the times ;-).  We did that in 7.2.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: [7.3devl] Using PGPASSWORDFILE with psql requires -U
Следующее
От: Bruce Momjian
Дата:
Сообщение: Re: Reporting query duration