Re: Expect problems with PL/Python and Python version 2.2.3+ & 2.3+ - Mailing list pgsql-hackers

From Tom Lane
Subject Re: Expect problems with PL/Python and Python version 2.2.3+ & 2.3+
Date
Msg-id 26025.1053931596@sss.pgh.pa.us
Whole thread Raw
In response to Expect problems with PL/Python and Python version 2.2.3+ & 2.3+  (Sean Reifschneider <jafo@tummy.com>)
Responses Re: Expect problems with PL/Python and Python version 2.2.3+ & 2.3+  (Sean Reifschneider <jafo@tummy.com>)
List pgsql-hackers
Guido van Rossum <guido@python.org> writes:
> I'm not saying I'm not sorry about this state of affairs.  But I
> prefer to be upfront and say "there is currently no secure restricted
> execution mode" rather than pretend everything is cool and let bad
> guys hack into your system via the rexec holes.

Fair enough (and thanks for the prompt, authoritative answer!)

Looks like we either change plpython to untrusted status or remove it
entirely :-(.  Sean, do you have time to prepare a patch for the former?
        regards, tom lane


pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: Testing patches
Next
From: Rajesh Kumar Mallah
Date:
Subject: slow \d commands.