Re: allowing privileges on untrusted languages

Поиск
Список
Период
Сортировка
От Simon Riggs
Тема Re: allowing privileges on untrusted languages
Дата
Msg-id CA+U5nM+BEO9J=i_J7xgeoD7P-8Ea6PyV80XMTH02jFE6FWvZfw@mail.gmail.com
обсуждение исходный текст
Ответ на Re: allowing privileges on untrusted languages  (Kohei KaiGai <kaigai@kaigai.gr.jp>)
Ответы Re: allowing privileges on untrusted languages  (Robert Haas <robertmhaas@gmail.com>)
Список pgsql-hackers
On 19 January 2013 13:45, Kohei KaiGai <kaigai@kaigai.gr.jp> wrote:

> I think, it is a time to investigate separation of database superuser privileges
> into several fine-grained capabilities, like as operating system doing.
> https://github.com/torvalds/linux/blob/master/include/uapi/linux/capability.h
>
> In case of Linux, the latest kernel has 36 kinds of capabilities that reflects
> a part of root privileges, such as privilege to open listen port less than 1024,
> privilege to override DAC permission and so on. Traditional root performs
> as a user who has all the capability in default.

Sounds like the best way to go. The reasoning that led to that change
works for us as well.

-- Simon Riggs                   http://www.2ndQuadrant.com/PostgreSQL Development, 24x7 Support, Training & Services



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Kohei KaiGai
Дата:
Сообщение: Re: allowing privileges on untrusted languages
Следующее
От: Andrew Dunstan
Дата:
Сообщение: Re: Contrib PROGRAM problem