Re: Re: [HACKERS] [PATCH] Re: Setuid functions
От | Bruce Momjian |
---|---|
Тема | Re: Re: [HACKERS] [PATCH] Re: Setuid functions |
Дата | |
Msg-id | 200107111958.f6BJwtj04779@candle.pha.pa.us обсуждение исходный текст |
Ответ на | Re: Re: [HACKERS] [PATCH] Re: Setuid functions (Peter Eisentraut <peter_e@gmx.net>) |
Список | pgsql-patches |
> Bruce Momjian writes: > > > > I updated the patch to use the SET AUTHORIZATION { INVOKER | DEFINER } > > > terminology. Also, the function owner is now determined and saved at compile > > > time (no gotchas here, right?). It is located at > > > > > > http://volpe.home.mindspring.com/pgsql/set_auth.patch > > > > OK, patch applied. Can I have some docs with that burger? :-) > > I think we concluded that this feature introduced a security hole. I thought that was addressed in the patch with the mention of: > > > Also, the function owner is now determined and saved at compile > > > time (no gotchas here, right?). Does anyone remember? -- Bruce Momjian | http://candle.pha.pa.us pgman@candle.pha.pa.us | (610) 853-3000 + If your life is a hard drive, | 830 Blythe Avenue + Christ can be your backup. | Drexel Hill, Pennsylvania 19026
В списке pgsql-patches по дате отправления: