Re: more RLS oversights
От | Stephen Frost |
---|---|
Тема | Re: more RLS oversights |
Дата | |
Msg-id | 20150226043724.GJ29780@tamriel.snowman.net обсуждение исходный текст |
Ответ на | Re: more RLS oversights (Stephen Frost <sfrost@snowman.net>) |
Ответы |
Re: more RLS oversights
|
Список | pgsql-hackers |
Robert, all, * Stephen Frost (sfrost@snowman.net) wrote: > * Robert Haas (robertmhaas@gmail.com) wrote: > > I happened to notice this morning while hacking that the > > "hasRowSecurity" fields added to PlannerGlobal and PlannedStmt have > > not been given proper nodefuncs.c support. Both need to be added to > > outfuncs.c, and the latter to copyfuncs.c. The latter omission may > > well be a security bug, although I haven't attempted to verify that, > > but fortunately this isn't released yet. > > I saw this and will address it. Would be great if you wouldn't mind > CC'ing me directly on anything RLS-related, same as you CC'd me on the > column-privilege backpatch. I expect I'll probably notice anyway, but > I'll see them faster when I'm CC'd. > > I agree that it's great that we're catching issues prior to when the > feature is released and look forward to anything else you (or anyone > else!) finds. I've pushed a fix for this. Please let me know if you see any other issues or run into any problems. Thanks! Stephen
В списке pgsql-hackers по дате отправления: