Re: [HACKERS] [PATCH] Re: Setuid functions

Поиск
Список
Период
Сортировка
От Mark Volpe
Тема Re: [HACKERS] [PATCH] Re: Setuid functions
Дата
Msg-id 3B4DEF3D.AF19D7D1@epa.gov
обсуждение исходный текст
Ответ на Re: [HACKERS] [PATCH] Re: Setuid functions  (Bruce Momjian <pgman@candle.pha.pa.us>)
Список pgsql-patches
Might as well just get rid of that one; Peter's right about the security hole.

The simplest fix I see is to allow SET AUTHORIZATION only in superuser-owned
functions. It would still be potentially useful that way. Doing this the
"right" way (with users needing regrantable privileges, etc.) would involve
too much effort for too little reward, IMHO.

Mark

Bruce Momjian wrote:
>
> I am backing out this SET AUTHORIZATION patch until we can resolve the
> security issues.  It will remain in the patch queue at:
>
>         http://candle.pha.pa.us/cgi-bin/pgpatches
>

В списке pgsql-patches по дате отправления:

Предыдущее
От: Martijn van Oosterhout
Дата:
Сообщение: Patch to add support for partial indices
Следующее
От: Mark Volpe
Дата:
Сообщение: Re: Re: [HACKERS] [PATCH] Re: Setuid functions