From: | Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us> |
---|---|
To: | Nathan Bossart <nathandbossart(at)gmail(dot)com> |
Cc: | Kyotaro Horiguchi <horikyota(dot)ntt(at)gmail(dot)com>, michael(at)paquier(dot)xyz, gurjeet(at)singh(dot)im, pgsql-hackers(at)postgresql(dot)org |
Subject: | Re: Unprivileged user can induce crash by using an SUSET param in PGOPTIONS |
Date: | 2022-07-25 14:32:42 |
Message-ID: | 2015981.1658759562@sss.pgh.pa.us |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-hackers |
Nathan Bossart <nathandbossart(at)gmail(dot)com> writes:
> Given all this, I think I'm inclined for the new argument.
Pushed like that then (after a bit more fooling with the comments).
I haven't done anything about a test case. We can't rely on plperl
getting built, and even if we could, it doesn't have any TAP-style
tests so it'd be hard to get it to test this scenario. However,
I do see that we're not testing session_preload_libraries anywhere,
which seems bad. I wonder if it'd be a good idea to convert
auto_explain's TAP test to load auto_explain via session_preload_libraries
instead of shared_preload_libraries, and then pass in the settings for
each test via PGOPTIONS instead of constantly rewriting postgresql.conf.
regards, tom lane
From | Date | Subject | |
---|---|---|---|
Next Message | Thomas Munro | 2022-07-25 14:35:35 | Re: Cleaning up historical portability baggage |
Previous Message | Jack Christensen | 2022-07-25 14:07:25 | Re: Proposal to provide the facility to set binary format output for specific OID's per session |