Hi Andrey, On Fri, Jan 09, 2009 at 08:52:15PM +0100, Andrey Hristov wrote: > It is there, in mysqld, to protect the server from being DoS-ed. Because > the queries are being re-assembled in the server and the passed for > parsing, a user with low privs can send a 2GB query to the server and > DoS it. The admin can define how big that max query can be by adjusting > max_allowed_packet. Although the name references the protocol it has > security implications on the server. > I won't kill that one.
Thanks for the insight! As Kristian noted in another reply, part of this decision is from the Drizzle direction of putting more trust in the client than MySQL does (like auth being off by default). The other reason is that, in my opinion, this type of DoS protection belongs only in the server, and should not be part of the protocol. I think having a pre-parse memory limit is valuable, but this should not be exposed to the client. Perhaps we can rename max_allowed_packet to something more server-internal specific, and just take it out of the protocol negotiation. Best regards, -Eric _______________________________________________ Mailing list: https://launchpad.net/~drizzle-discuss Post to : [email protected] Unsubscribe : https://launchpad.net/~drizzle-discuss More help : https://help.launchpad.net/ListHelp

