diff options
author | Tom Lane <tgl@sss.pgh.pa.us> | 2020-02-19 16:59:14 -0500 |
---|---|---|
committer | Tom Lane <tgl@sss.pgh.pa.us> | 2020-02-19 16:59:14 -0500 |
commit | 70a7732007bc4689f4c7a44e738eb2d892dac1e3 (patch) | |
tree | ee0e3600986e53e6028658dbe2d1bfad3e1f7606 /src/pl/plpython | |
parent | 2f9c46a32b43d72c9384378827ee51fde896807c (diff) | |
download | postgresql-70a7732007bc4689f4c7a44e738eb2d892dac1e3.tar.gz postgresql-70a7732007bc4689f4c7a44e738eb2d892dac1e3.zip |
Remove support for upgrading extensions from "unpackaged" state.
Andres Freund pointed out that allowing non-superusers to run
"CREATE EXTENSION ... FROM unpackaged" has security risks, since
the unpackaged-to-1.0 scripts don't try to verify that the existing
objects they're modifying are what they expect. Just attaching such
objects to an extension doesn't seem too dangerous, but some of them
do more than that.
We could have resolved this, perhaps, by still requiring superuser
privilege to use the FROM option. However, it's fair to ask just what
we're accomplishing by continuing to lug the unpackaged-to-1.0 scripts
forward. None of them have received any real testing since 9.1 days,
so they may not even work anymore (even assuming that one could still
load the previous "loose" object definitions into a v13 database).
And an installation that's trying to go from pre-9.1 to v13 or later
in one jump is going to have worse compatibility problems than whether
there's a trivial way to convert their contrib modules into extension
style.
Hence, let's just drop both those scripts and the core-code support
for "CREATE EXTENSION ... FROM".
Discussion: https://postgr.es/m/20200213233015.r6rnubcvl4egdh5r@alap3.anarazel.de
Diffstat (limited to 'src/pl/plpython')
-rw-r--r-- | src/pl/plpython/Makefile | 4 | ||||
-rw-r--r-- | src/pl/plpython/plpython2u--unpackaged--1.0.sql | 7 | ||||
-rw-r--r-- | src/pl/plpython/plpython3u--unpackaged--1.0.sql | 7 | ||||
-rw-r--r-- | src/pl/plpython/plpythonu--unpackaged--1.0.sql | 7 |
4 files changed, 2 insertions, 23 deletions
diff --git a/src/pl/plpython/Makefile b/src/pl/plpython/Makefile index 0d53d3d7707..9e95285af89 100644 --- a/src/pl/plpython/Makefile +++ b/src/pl/plpython/Makefile @@ -34,9 +34,9 @@ OBJS = \ plpy_typeio.o \ plpy_util.o -DATA = $(NAME)u.control $(NAME)u--1.0.sql $(NAME)u--unpackaged--1.0.sql +DATA = $(NAME)u.control $(NAME)u--1.0.sql ifeq ($(python_majorversion),2) -DATA += plpythonu.control plpythonu--1.0.sql plpythonu--unpackaged--1.0.sql +DATA += plpythonu.control plpythonu--1.0.sql endif # header files to install - it's not clear which of these might be needed diff --git a/src/pl/plpython/plpython2u--unpackaged--1.0.sql b/src/pl/plpython/plpython2u--unpackaged--1.0.sql deleted file mode 100644 index 6efa2dbad93..00000000000 --- a/src/pl/plpython/plpython2u--unpackaged--1.0.sql +++ /dev/null @@ -1,7 +0,0 @@ -/* src/pl/plpython/plpython2u--unpackaged--1.0.sql */ - -ALTER EXTENSION plpython2u ADD LANGUAGE plpython2u; --- ALTER ADD LANGUAGE doesn't pick up the support functions, so we have to. -ALTER EXTENSION plpython2u ADD FUNCTION plpython2_call_handler(); -ALTER EXTENSION plpython2u ADD FUNCTION plpython2_inline_handler(internal); -ALTER EXTENSION plpython2u ADD FUNCTION plpython2_validator(oid); diff --git a/src/pl/plpython/plpython3u--unpackaged--1.0.sql b/src/pl/plpython/plpython3u--unpackaged--1.0.sql deleted file mode 100644 index fb8d3d6a652..00000000000 --- a/src/pl/plpython/plpython3u--unpackaged--1.0.sql +++ /dev/null @@ -1,7 +0,0 @@ -/* src/pl/plpython/plpython3u--unpackaged--1.0.sql */ - -ALTER EXTENSION plpython3u ADD LANGUAGE plpython3u; --- ALTER ADD LANGUAGE doesn't pick up the support functions, so we have to. -ALTER EXTENSION plpython3u ADD FUNCTION plpython3_call_handler(); -ALTER EXTENSION plpython3u ADD FUNCTION plpython3_inline_handler(internal); -ALTER EXTENSION plpython3u ADD FUNCTION plpython3_validator(oid); diff --git a/src/pl/plpython/plpythonu--unpackaged--1.0.sql b/src/pl/plpython/plpythonu--unpackaged--1.0.sql deleted file mode 100644 index 16b828f2fed..00000000000 --- a/src/pl/plpython/plpythonu--unpackaged--1.0.sql +++ /dev/null @@ -1,7 +0,0 @@ -/* src/pl/plpython/plpythonu--unpackaged--1.0.sql */ - -ALTER EXTENSION plpythonu ADD LANGUAGE plpythonu; --- ALTER ADD LANGUAGE doesn't pick up the support functions, so we have to. -ALTER EXTENSION plpythonu ADD FUNCTION plpython_call_handler(); -ALTER EXTENSION plpythonu ADD FUNCTION plpython_inline_handler(internal); -ALTER EXTENSION plpythonu ADD FUNCTION plpython_validator(oid); |