On Wed, Mar 27, 2013 at 10:32 AM, Alvaro Herrera <alvhe...@2ndquadrant.com> wrote: >> Surely creating an extension template must be a superuser-only >> operation, in which case this is an issue because Mallory could also >> have just blown up the world directly if he's already a superuser >> anyway. > > Yeah .. (except "this is NOT an issue") > >> If the current patch isn't enforcing that, it's 100% broken. > > Even if it's not enforcing that, it's not 100% broken, it only contains > one more bug we need to fix.
Sure. I didn't mean that such a mistake would make the patch unsalvageable, only that it would be disastrous from a security point of view. But as you say, pretty easy to fix. -- Robert Haas EnterpriseDB: http://www.enterprisedb.com The Enterprise PostgreSQL Company -- Sent via pgsql-hackers mailing list (email@example.com) To make changes to your subscription: http://www.postgresql.org/mailpref/pgsql-hackers