Re: [HACKERS] pg_settings.sourcefile patch is a security breach

2008-09-23 Thread Magnus Hagander
Magnus Hagander wrote: > Tom Lane wrote: >> We go to some lengths to prevent non-superusers from examining >> data_directory and other values that would tell them exactly where the >> PG data directory is in the server's filesystem. The recently applied >> patch to expose full pathnames of GUC var

Re: [HACKERS] pg_settings.sourcefile patch is a security breach

2008-09-21 Thread Magnus Hagander
Tom Lane wrote: > We go to some lengths to prevent non-superusers from examining > data_directory and other values that would tell them exactly where the > PG data directory is in the server's filesystem. The recently applied > patch to expose full pathnames of GUC variables' source files blows a

[HACKERS] pg_settings.sourcefile patch is a security breach

2008-09-21 Thread Tom Lane
We go to some lengths to prevent non-superusers from examining data_directory and other values that would tell them exactly where the PG data directory is in the server's filesystem. The recently applied patch to expose full pathnames of GUC variables' source files blows a hole a mile wide in that