Re: Feature Request on Extensions - Mailing list pgsql-hackers

From Hannu Krosing
Subject Re: Feature Request on Extensions
Date
Msg-id 521095B3.80107@2ndQuadrant.com
Whole thread Raw
In response to Feature Request on Extensions  (Steven Citron-Pousty <spousty@redhat.com>)
Responses Re: Feature Request on Extensions  (Hannu Krosing <hannu@2ndQuadrant.com>)
List pgsql-hackers
On 08/17/2013 11:53 PM, Steven Citron-Pousty wrote:
Greetings all:
I spoke to Josh B and company at OSCON about a feature we really need for PostgreSQL  extensions on OpenShift (Red Hat's Platform as a Service).

What we need is the ability for Postgresql to load extensions from a users file space.
There were objections earlier against loading anything "binary" from
a directory not being writable by root only.

But allowing loading modules from the directory of the user the server
runs as (usually postgres, but could be any system user other than root)
seems like a really good idea.

I can not see how this would create any additional security problems,
as the user can already do anything that user can do. adding postgresql
binary in this mix running as the same user can not possibly add any
new security concerns.

If anybody can point out something I overlook here, please do so!

Cheers

-- 
Hannu Krosing
PostgreSQL Consultant
Performance, Scalability and High Availability
2ndQuadrant Nordic OÜ

pgsql-hackers by date:

Previous
From: Nicolas Barbier
Date:
Subject: Re: Chinese in Postgres
Next
From: Stefan Kaltenbrunner
Date:
Subject: CREATE FUNCTION .. SET vs. pg_dump