Andrew Dunstan <and...@dunslane.net> writes: >> On Thu, Sep 23, 2010 at 17:16, Tom Lane<t...@sss.pgh.pa.us> wrote: >>> I'm still wondering why we don't simply lobotomize git-cvsserver to >>> refuse requests to check out anything except the active branch tips.
> Are we sure that's going to stop the DOS issue? The claimed denial of service is that each checkout target requires a separate SQLite database. Limit the number of checkout targets accepted and you're done. Or at least, if you're not done, it behooves those claiming there's a security problem to show what the problem is. It's not like this piece of software isn't used in production, so I doubt it needs to be babied quite as much as this thread is assuming. regards, tom lane -- Sent via pgsql-hackers mailing list (pgsql-hackers@postgresql.org) To make changes to your subscription: http://www.postgresql.org/mailpref/pgsql-hackers