Skip to content

Make scan_arrow_ipc safe by not allowing direct pass of pointer arguments in a SQL call. #9

@paleolimbot

Description

@paleolimbot

@pdet Something I've wondered is whether scan_arrow_ipc() constitutes a security issue if enabled in an arbitrary user session. It seems like anybody could cause the host process to crash if they pass a random integer into that function? Obviously it's needed for some clients and it makes sense to enable it there, and apologies if this is something that has been considered and is a total non issue 😬

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions