Re: Possible major bug in PlPython (plus some other ideas)

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Possible major bug in PlPython (plus some other ideas)
Дата
Msg-id 3608.1005686235@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: Possible major bug in PlPython (plus some other ideas)  (Bradley McLean <brad@bradm.net>)
Ответы Re: Possible major bug in PlPython (plus some other ideas)  (Bruce Momjian <pgman@candle.pha.pa.us>)
Список pgsql-hackers
Bradley McLean <brad@bradm.net> writes:
> (Everyone)  Would a patch to add trusted language support be accepted
> for 7.2, or is it too late?

I think the code in there already is the trusted case, no?  The addition
would be an untrusted mode for plpython.

trusted = language handler prevents security violations, so unprivileged
users are allowed to define functions in the language (ie, we trust the
language itself to prevent security breaches)

untrusted = language allows user to access things outside database,
so only Postgres superusers are allowed to define functions in the
language (ie, we must trust the function author instead of the language)

In any case, a second security level in plpython would clearly be a new
feature, and so I'd say it's too late to consider it for 7.2.  All that
we want to do at this point is verify Kevin's proposed patch for the
existing security level.  But certainly a "plpythonu" addition would
be welcome for 7.3.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Liam Stewart
Дата:
Сообщение: Re: [JDBC] Funny timezone shift causes failure in test suite
Следующее
От: Tom Lane
Дата:
Сообщение: Re: pg locking problem