Re: Security implications of config-file-location patch

Поиск
Список
Период
Сортировка
От Zeugswetter Andreas DAZ SD
Тема Re: Security implications of config-file-location patch
Дата
Msg-id 46C15C39FEB2C44BA555E356FBCD6FA40184D1D7@m0114.s-mxs.net
обсуждение исходный текст
Ответ на Security implications of config-file-location patch  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: Security implications of config-file-location patch  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
> > If they are using tablespaces is it OK that anyone can see their
> > location?
>
> Good point.  Should we obscure pg_tablespace similarly to
> what we do for pg_shadow?

Hmm, I can not see how a person with file access could not easily find the
file for a specific table without pg_tablespace anyway (since oid names will
be quite unique). Without file access, what malicious act is he going to do
with that info ?

I think hiding that info would not really be safer, thus not worth it.

Andreas


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Oleg Bartunov
Дата:
Сообщение: Re: plans for bitmap indexes?
Следующее
От: Euler Taveira de Oliveira
Дата:
Сообщение: Re: initdb crash