Remix.run Logo
groundzeros2015 13 hours ago

Lately I been questioning whether it’s actually a good idea to pool connections. Don’t your in the risk of leaking privileges or information from other requests?

hans_castorp 13 hours ago | parent | next [-]

Typically no.

In most (all?) cases the pooler manages one pool per database user, so even if there was something leaking, it would not be anything that the database user couldn't access anyway.

But if you are paranoid, you can configure the pooler to run "RESET ALL", "RESET ROLE", "RESET SESSION AUTHORIZATION" and "ROLLBACK" before handing out a connection.

nomel 13 hours ago | parent | prev | next [-]

The cursor is not shared.

groundzeros2015 12 hours ago | parent [-]

Shared memory is shared memory. Are the pages zeroed out?

nomel 11 hours ago | parent [-]

This worry relies on a zero day bug/memory exploit in one of the most widely used access methods for Postgres. This worry can be applied to every component of the software stack, including the OS.

groundzeros2015 11 hours ago | parent [-]

Hmm, not really. Whether the kernel is managing memory for processes properly is different than asking whether a reused Postgres connection clears all relevant memory.

But thanks for info about level of issue.

13 hours ago | parent | prev [-]
[deleted]