Re: Support custom socket directory in pg_upgrade

Поиск
Список
Период
Сортировка
От Daniel Gustafsson
Тема Re: Support custom socket directory in pg_upgrade
Дата
Msg-id A7BD0B64-8B0A-406A-A185-D72681964CF1@yesql.se
обсуждение исходный текст
Ответ на Re: Support custom socket directory in pg_upgrade  (Tom Lane <tgl@sss.pgh.pa.us>)
Ответы Re: Support custom socket directory in pg_upgrade  (Noah Misch <noah@leadboat.com>)
Список pgsql-hackers
> On 15 Nov 2018, at 22:42, Tom Lane <tgl@sss.pgh.pa.us> wrote:

> Further point about that: pg_regress's method of creating a temp
> directory under /tmp is secure only on machines with the stickybit
> set on /tmp; otherwise it's possible for an attacker to rename the
> temp dir out of the way and inject his own socket.  We agreed that
> that was an okay risk to take for testing purposes, but I'm much
> less willing to assume that it's okay for production use with
> pg_upgrade.

That’s a good point, it’s not an assumption I’d be comfortable with when it
deals with system upgrades.

cheers ./daniel

В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: Now/current_date and proleakproof
Следующее
От: Tomas Vondra
Дата:
Сообщение: Re: valgrind issues on Fedora 28