Re: exposing pg_controldata and pg_config as functions

Поиск
Список
Период
Сортировка
От Stephen Frost
Тема Re: exposing pg_controldata and pg_config as functions
Дата
Msg-id 20160118221035.GV3685@tamriel.snowman.net
обсуждение исходный текст
Ответ на Re: exposing pg_controldata and pg_config as functions  (Robert Haas <robertmhaas@gmail.com>)
Ответы Re: exposing pg_controldata and pg_config as functions  (Andres Freund <andres@anarazel.de>)
Список pgsql-hackers
* Robert Haas (robertmhaas@gmail.com) wrote:
> On Mon, Jan 18, 2016 at 4:43 AM, Andres Freund <andres@anarazel.de> wrote:
> > Meh, that seems pretty far into pseudo security arguments.
>
> Yeah, I really don't see anything in the pg_controldata output that
> looks sensitive.  The WAL locations are the closest of anything,
> AFAICS.

Heikki already showed how the WAL location information could be
exploited if compression is enabled.

I believe that's something we should care about and fix in one way or
another (my initial approach was using defualt roles, but using the ACL
system and starting out w/ no rights granted to that function also
works).

Thanks!

Stephen

В списке pgsql-hackers по дате отправления:

Предыдущее
От: Joe Conway
Дата:
Сообщение: Re: exposing pg_controldata and pg_config as functions
Следующее
От: Kevin Grittner
Дата:
Сообщение: Re: [PATCH] Improve spinlock inline assembly for x86.