Re: Specification for Trusted PLs?
От
Alexey Klyukin
Тема
Re: Specification for Trusted PLs?
Дата
Msg-id
AANLkTimcldxGodA5OYAL_v78v-xBW6hBgq2a-Grto_6a@mail.gmail.com
Ответ на
Re: Specification for Trusted PLs? (Magnus Hagander)
Список
Дерево обсуждения
Specification for Trusted PLs? David Fetter <david@fetter.org>
Re: Specification for Trusted PLs? Stephen Frost <sfrost@snowman.net>
Re: Specification for Trusted PLs? Peter Geoghegan <peter.geoghegan86@gmail.com>
Re: Specification for Trusted PLs? Tom Lane <tgl@sss.pgh.pa.us>
Re: Specification for Trusted PLs? Josh Berkus <josh@agliodbs.com>
Re: Specification for Trusted PLs? Craig Ringer <craig@postnewspapers.com.au>
Re: Specification for Trusted PLs? Magnus Hagander <magnus@hagander.net>
Re: Specification for Trusted PLs? David Fetter <david@fetter.org>
Re: Specification for Trusted PLs? Stephen Frost <sfrost@snowman.net>
Re: Specification for Trusted PLs? David Fetter <david@fetter.org>
Re: Specification for Trusted PLs? Stephen Frost <sfrost@snowman.net>
Re: Specification for Trusted PLs? David Fetter <david@fetter.org>
Re: Specification for Trusted PLs? Stephen Frost <sfrost@snowman.net>
Re: Specification for Trusted PLs? Robert Haas <robertmhaas@gmail.com>
Re: Specification for Trusted PLs? Stephen Frost <sfrost@snowman.net>
Re: Specification for Trusted PLs? Tom Lane <tgl@sss.pgh.pa.us>
Re: Specification for Trusted PLs? Ron Mayer <rm_pg@cheapcomplexdevices.com>
Re: Specification for Trusted PLs? Jan Wieck <JanWieck@Yahoo.com>
Re: Specification for Trusted PLs? Andrew Dunstan <andrew@dunslane.net>
Re: Specification for Trusted PLs? Jan Wieck <JanWieck@Yahoo.com>
Re: Specification for Trusted PLs? Andrew Dunstan <andrew@dunslane.net>
Re: Specification for Trusted PLs? Jan Wieck <JanWieck@Yahoo.com>
Re: Specification for Trusted PLs? Robert Haas <robertmhaas@gmail.com>
Re: Specification for Trusted PLs? Peter Eisentraut <peter_e@gmx.net>
Re: Specification for Trusted PLs? David Fetter <david@fetter.org>
Re: Specification for Trusted PLs? Robert Haas <robertmhaas@gmail.com>
Re: Specification for Trusted PLs? David Fetter <david@fetter.org>
Re: Specification for Trusted PLs? Tom Lane <tgl@sss.pgh.pa.us>
Re: Specification for Trusted PLs? Sam Mason <sam@samason.me.uk>
Re: Specification for Trusted PLs? Peter Eisentraut <peter_e@gmx.net>
Re: Specification for Trusted PLs? Andrew Dunstan <andrew@dunslane.net>
Re: Specification for Trusted PLs? Tom Lane <tgl@sss.pgh.pa.us>
Re: Specification for Trusted PLs? David Fetter <david@fetter.org>
Re: Specification for Trusted PLs? David Fetter <david@fetter.org>
Re: Specification for Trusted PLs? Joshua Tolley <eggyknap@gmail.com>
Re: Specification for Trusted PLs? Tom Lane <tgl@sss.pgh.pa.us>
Re: Specification for Trusted PLs? Bruce Momjian <bruce@momjian.us>
Re: Specification for Trusted PLs? David Fetter <david@fetter.org>
Re: Specification for Trusted PLs? Jan Wieck <JanWieck@Yahoo.com>
Re: Specification for Trusted PLs? Cédric Villemain <cedric.villemain.debian@gmail.com>
Re: Specification for Trusted PLs? Robert Haas <robertmhaas@gmail.com>
Re: Specification for Trusted PLs? Bruce Momjian <bruce@momjian.us>
Re: Specification for Trusted PLs? Joshua Tolley <eggyknap@gmail.com>
Re: Specification for Trusted PLs? Jonathan Leto <jonathan@leto.net>
Re: Specification for Trusted PLs? Craig Ringer <craig@postnewspapers.com.au>
Re: Specification for Trusted PLs? Tom Lane <tgl@sss.pgh.pa.us>
Re: Specification for Trusted PLs? Florian Pflug <fgp@phlo.org>
Re: Specification for Trusted PLs? Magnus Hagander <magnus@hagander.net>
Re: Specification for Trusted PLs? "Greg Sabino Mullane" <greg@turnstep.com>
Re: Specification for Trusted PLs? Tom Lane <tgl@sss.pgh.pa.us>
Re: Specification for Trusted PLs? Alexey Klyukin <alexk@commandprompt.com>
Re: Specification for Trusted PLs? "Greg Sabino Mullane" <greg@turnstep.com>
Re: Specification for Trusted PLs? Josh Berkus <josh@agliodbs.com>
On Fri, May 21, 2010 at 7:25 PM, Magnus Hagander wrote: > On Fri, May 21, 2010 at 12:22 PM, David Fetter wrote: >> On Fri, May 21, 2010 at 11:57:33AM -0400, Magnus Hagander wrote: >>> On Fri, May 21, 2010 at 11:55 AM, Josh Berkus wrote: >>> > So, here's a working definition: >>> > >>> > 1) cannot directly read or write files on the server. >>> > 2) cannot bind network ports >>> >>> To make that more covering, don't yu really need something like >>> "cannot communicate with outside processes"? >> >> These need to be testable conditions, and new tests need to get added >> any time we find that we've missed something. Making this concept >> fuzzier is exactly the wrong direction to go. > > Well, the best way to define what a trusted language can do is to > define a *whitelist* of what it can do, not a blacklist of what it > can't do. That's the only way to get a complete definition. It's then > up to the implementation step to figure out how to represent that in > the form of tests. Yes, PL/Perl is following this approach. For a whitelist see plperl_opmask.h (generated by plperl_opmask.pl at build phase). -- Alexey Klyukin www.CommandPrompt.com The PostgreSQL Company - Command Prompt, Inc
В списке pgsql-hackers по дате отправления
От: Mohammad Heykal Abdillah
Дата: