Re: [BUG] SECURITY DEFINER on call handler makes daemon crash
От | Robert Haas |
---|---|
Тема | Re: [BUG] SECURITY DEFINER on call handler makes daemon crash |
Дата | |
Msg-id | 603c8f071003191917s40150e1rb201ae1716b37b8d@mail.gmail.com обсуждение исходный текст |
Ответ на | Re: [BUG] SECURITY DEFINER on call handler makes daemon crash (Tom Lane <tgl@sss.pgh.pa.us>) |
Ответы |
Re: [BUG] SECURITY DEFINER on call handler makes daemon
crash
|
Список | pgsql-hackers |
On Fri, Mar 19, 2010 at 8:11 PM, Tom Lane <tgl@sss.pgh.pa.us> wrote: > Robert Haas <robertmhaas@gmail.com> writes: >> On Fri, Mar 19, 2010 at 8:18 AM, Tom Lane <tgl@sss.pgh.pa.us> wrote: >>> KaiGai Kohei <kaigai@ak.jp.nec.com> writes: >>>> When we assign "SECURITY DEFINER" attribute on plpgsql_call_handler(), >>>> it makes server process crashed. >>> >>> So don't do that. Whatever possessed you to think that's a sensible >>> idea anyway? > >> It might not be sensible, but the whole server going down as a result >> doesn't seem very sensible either. > > [ shrug... ] If you would like to start enumerating the ways in which > you can crash the server with erroneous pg_proc entries for C functions, > go for it. It'll keep you out of trouble for a very long time. It's obviously not possible to make this bulletproof in general, but that doesn't mean we should crash just for fun. ...Robert
В списке pgsql-hackers по дате отправления: