Re: plperl Safe restrictions

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: plperl Safe restrictions
Дата
Msg-id 9385.1097853365@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: plperl Safe restrictions  (Andrew Dunstan <andrew@dunslane.net>)
Список pgsql-hackers
Andrew Dunstan <andrew@dunslane.net> writes:
> You can now - it's part of :base_math. What we should do, however, is 
> disallow is calling srand, since pg goes to quite a bit of trouble to 
> seed the PRNG.

But changing the PRNG seed within one backend is not a security issue.
At least, we allow anyone to do "SET SEED" or call setseed, so I don't
see any reason to disallow it in plperl.

In general I'm pretty sure that no one has reviewed the list of
restrictions carefully, so by all means send in a patch once you've
done so.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Dave Page"
Дата:
Сообщение: Re: get_progname and .exe suffix
Следующее
От: Tom Lane
Дата:
Сообщение: Re: plperl Safe restrictions