Re: plpythonu - Mailing list pgsql-general

From Marko Kreen
Subject Re: plpythonu
Date
Msg-id e51f66da0801181234u739db0c4u98309e9ffcbe91e0@mail.gmail.com
Whole thread Raw
In response to Re: plpythonu  (Erik Jones <erik@myemma.com>)
List pgsql-general
On 1/18/08, Erik Jones <erik@myemma.com> wrote:
> On Jan 18, 2008, at 7:48 AM, Stuart Bishop wrote:
> > plpython !=3D plpythonu.
> >
> > plpython was the 'secure' sandboxed version. The Python devs gave up
> > supporting any sort of sandboxing feature in Python declaring it
> > impossib=
> > le.
>
> Someone should definitely take a look at this:  http://
> sayspy.blogspot.com/2007/05/i-have-finished-securing-python.html
>
> That guy claims he's locked down the python interpreter there.

Interesting.  But the problem has never been in locking down
the interpreter vX.Y, but locking down interpreter vX.Y+1, when
previously work was done on vX.Y.  Without upstream developers
cooperation this has been too painful.

So the interesting thing in the posting is not that he succeeded
locking Python down, but that he is pushing the patch to core.

--
marko

pgsql-general by date:

Previous
From: Tom Lane
Date:
Subject: Re: Postgresql 8.2.4 on linux-sparc problem
Next
From: Tom Lane
Date:
Subject: Re: Stupid question about WAL archiving