Re: pg_hba.conf and IP-MASK - Mailing list pgsql-hackers

From Andrew Dunstan
Subject Re: pg_hba.conf and IP-MASK
Date
Msg-id 4394.24.211.141.25.1093164297.squirrel@www.dunslane.net
Whole thread Raw
In response to Re: pg_hba.conf and IP-MASK  (Bruce Momjian <pgman@candle.pha.pa.us>)
Responses Re: pg_hba.conf and IP-MASK
List pgsql-hackers
Bruce Momjian said:
> Joshua D. Drake wrote:
>> Bruce Momjian wrote:
>>
>> >We have an IP-MASK column in pg_hba.conf.  Now that we are using CIDR
>> >addresses by default, should we remove the column label?
>> >
>> >
>> >
>> I would mark it optional.
>
> We could do that, but we could use the space if we removed it.  One
> other confusing thing is that it isn't the last column in the row, so
> it is optional only if you used CIDR format --- kind of strange.
>

The syntax rule (debated at length around May last year when this work was
done) is that you have to have either addr/nn for CIDR format or
addr<space>mask for the old-style format - both are documented in
ph_hba.conf and in the docs. So in fact the IP-MASK column is not optional
at all - it must be present if, and only if, you did not use a CIDR mask.

Since our defaults don't use old-style masks any more, I would be tempted to
remove the column labels for IP-ADDRESS and IP-MASK, and instead put in a
single heading of IP-ADDRESS/CIDR-MASK. If people want to use old-style
masks there is plenty of info on how to, without extra column headings.

cheers

andrew




pgsql-hackers by date:

Previous
From: Philip Warner
Date:
Subject: Re: [PATCHES] ALTER SCHEMA ... SET TABLESPACE
Next
From: Shachar Shemesh
Date:
Subject: Compilation problems and extension on Windows