Re: First draft of the PG 15 release notes

From: Bruce Momjian <bruce(at)momjian(dot)us>
To: Noah Misch <noah(at)leadboat(dot)com>
Cc: PostgreSQL-development <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: First draft of the PG 15 release notes
Date: 2022-07-12 18:47:07
Message-ID: Ys3BqwfxDAwCDjES@momjian.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On Mon, Jul 11, 2022 at 11:31:32PM -0700, Noah Misch wrote:
> On Mon, Jul 11, 2022 at 12:39:57PM -0400, Bruce Momjian wrote:
> > I had trouble reading the sentences in the order you used so I
> > restructured it:
> >
> > The new default is one of the secure schema usage patterns that <xref
> > linkend="ddl-schemas-patterns"/> has recommended since the security
> > release for CVE-2018-1058. The change applies to newly-created
> > databases in existing clusters and for new clusters. Upgrading a
> > cluster or restoring a database dump will preserve existing permissions.
>
> I agree with the sentence order change.

Great.

> > For existing databases, especially those having multiple users, consider
> > issuing <literal>REVOKE</literal> to adopt this new default. For new
> > databases having zero need to defend against insider threats, granting
> > <literal>USAGE</literal> permission on their <literal>public</literal>
> > schemas will yield the behavior of prior releases.
>
> s/USAGE/CREATE/ in the last sentence. Looks good with that change.

Ah, yes, of course.

--
Bruce Momjian <bruce(at)momjian(dot)us> https://momjian.us
EDB https://enterprisedb.com

Indecision is a decision. Inaction is an action. Mark Batterson

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Peter Eisentraut 2022-07-12 18:56:01 Re: System catalog documentation chapter
Previous Message Alvaro Herrera 2022-07-12 18:35:16 Re: pgsql: Add copy/equal support for XID lists