Re: Possible make_oidjoins_check Security Issue

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Andrew Dunstan <andrew(at)dunslane(dot)net>
Cc: Neil Conway <neilc(at)samurai(dot)com>, Rod Taylor <pg(at)rbt(dot)ca>, PostgreSQL Development <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Possible make_oidjoins_check Security Issue
Date: 2004-10-20 14:38:25
Message-ID: 3820.1098283105@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers pgsql-patches

Andrew Dunstan <andrew(at)dunslane(dot)net> writes:
> Tom Lane wrote:
>> I suspect that no one on the planet
>> except Bruce and myself have ever actually run this script.

> Then why don't we just remove it? Problem solved ...

Because it's a needed maintenance tool. There isn't any particularly
good reason for it to get installed as though it were an interesting
program for users, though, so I think that this is mostly a matter of
poor packaging choices. I am in fact intending to remove the
contrib/findoidjoins files from the set of stuff installed by Red Hat's
RPMs.

I suppose you could make an argument for moving this directory out of
contrib and putting it under src/tools instead, but that seems like more
work (and loss of CVS history) than it's worth.

regards, tom lane

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Andrew Dunstan 2004-10-20 15:23:43 Re: Possible make_oidjoins_check Security Issue
Previous Message Andrew Dunstan 2004-10-20 11:54:27 Re: Possible make_oidjoins_check Security Issue

Browse pgsql-patches by date

  From Date Subject
Next Message Andrew Dunstan 2004-10-20 15:23:43 Re: Possible make_oidjoins_check Security Issue
Previous Message Fabien COELHO 2004-10-20 11:57:52 Re: pg_regress --temp-keep