Re: RFC: seccomp-bpf support - Mailing list pgsql-hackers

From Peter Eisentraut
Subject Re: RFC: seccomp-bpf support
Date
Msg-id b822d5ce-dde1-8126-8164-908bd410dc46@2ndquadrant.com
Whole thread Raw
In response to Re: RFC: seccomp-bpf support  (Joshua Brindle <joshua.brindle@crunchydata.com>)
Responses Re: RFC: seccomp-bpf support
List pgsql-hackers
On 2019-08-28 21:38, Joshua Brindle wrote:
> I think we need to reign in the thread somewhat. The feature allows
> end users to define some sandboxing within PG. Nothing is being forced
> on anyone

Features come with a maintenance cost.  If we ship it, then people are
going to try it out.  Then weird things will happen.  They will report
mysterious bugs.  They will complain to their colleagues.  It all comes
with a cost.

> but we would like the capability to harden a PG installation
> for many reasons already stated.

Most if not all of those reasons seem to have been questioned.

-- 
Peter Eisentraut              http://www.2ndQuadrant.com/
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services



pgsql-hackers by date:

Previous
From: Taylor Vesely
Date:
Subject: Re: Memory-Bounded Hash Aggregation
Next
From: Alvaro Herrera
Date:
Subject: Re: RFC: seccomp-bpf support