Re: Safe security - Mailing list pgsql-hackers

From Tim Bunce
Subject Re: Safe security
Date
Msg-id 20100308173203.GB1375@timac.local
Whole thread Raw
In response to Re: Safe security  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-hackers
On Mon, Mar 08, 2010 at 11:03:27AM -0500, Tom Lane wrote:
> Tim Bunce <Tim.Bunce@pobox.com> writes:
> > Here's a patch that:
> > 1. adds wording like that to the docs.
> > 2. randomises the container package name (a simple and sound security measure).
> > 3. requires Safe 2.25 (which has assorted fixes, including security).
> > 4. removed a harmless but suprious exclamation mark from the source.
> 
> #3 is still an absolute nonstarter, especially for a patch that we'd
> wish to backpatch.

This is a patch for 9.0. Backpatching is a separate issue.

I think Safe 2.25 should be required, but I'll let whoever applies the
patch tweak/delete that hunk as desired.

Tim.


pgsql-hackers by date:

Previous
From: Robert Haas
Date:
Subject: Re: SQL compatibility reminder: MySQL vs PostgreSQL
Next
From: "David E. Wheeler"
Date:
Subject: Re: Safe security