summaryrefslogtreecommitdiff
path: root/contrib
Commit message (Collapse)AuthorAgeFilesLines
* More pgcrypto fixes: avoid bogus alignment assumptions in sha2,Tom Lane2005-07-1129-90/+99
| | | | | | be more wary about having a value for BYTE_ORDER, clean up randomly- chosen ways of including Postgres core headers. Marko Kreen and Tom Lane
* Add support for AES cipher with older OpenSSL libraries.Tom Lane2005-07-111-14/+41
| | | | Marko Kreen
* > One more failure:Bruce Momjian2005-07-101-3/+3
| | | | | | | | > > I think this is because we don't have -lz in SHLIB_LINK. > Following patch fixes it. Marko Kreen
* Add extra argument for new pg_regexec API.Bruce Momjian2005-07-101-1/+1
|
* Suppress compile warning.Tom Lane2005-07-101-2/+3
|
* Remove #include <openssl/bn.h> as compile fix.Bruce Momjian2005-07-101-3/+1
| | | | Marko Kreen
* As Kris Jurka found out, pgcrypto does not work withBruce Momjian2005-07-101-18/+38
| | | | | | | | | | | | | | | | | | | | | | | | | OpenSSL 0.9.6x. The DES functions use the older 'des_' API, but the newer 3DES functions use the 0.9.7x-only 'DES_' API. I think I just used /usr/include/openssl/des.h for reference when implementing them, and had upgraded OpenSSL in the meantime. Following patch converts DES also to newer API and provides compatibility functions for OpenSSL < 0.9.7. I chose this route because: - openssl.c uses few DES functions. - compatibility for old 'des_' API is going away at some point of time from OpenSSL. - as seen from macros, new API is saner - Thus pgcrypto supports any OpenSSL version from 0.9.5 to 1.0 Tested with OpenSSL 0.9.6c and 0.9.7e. Marko Kreen
* Add missing pgcrypto files from previous commit.Bruce Momjian2005-07-1044-0/+10539
|
* Major pgcrypto changes:Bruce Momjian2005-07-105-17/+408
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | of password-based encryption from RFC2440 (OpenPGP). The goal of this code is to be more featureful encryption solution than current encrypt(), which only functionality is running cipher over data. Compared to encrypt(), pgp_encrypt() does following: * It uses the equvialent of random Inital Vector to get cipher into random state before it processes user data * Stores SHA-1 of the data into result so any modification will be detected. * Remembers if data was text or binary - thus it can decrypt to/from text data. This was a major nuisance for encrypt(). * Stores info about used algorithms with result, so user needs not remember them - more user friendly! * Uses String2Key algorithms (similar to crypt()) with random salt to generate full-length binary key to be used for encrypting. * Uses standard format for data - you can feed it to GnuPG, if needed. Optional features (off by default): * Can use separate session key - user data will be encrypted with totally random key, which will be encrypted with S2K generated key and attached to result. * Data compression with zlib. * Can convert between CRLF<->LF line-endings - to get fully RFC2440-compliant behaviour. This is off by default as pgcrypto does not know the line-endings of user data. Interface is simple: pgp_encrypt(data text, key text) returns bytea pgp_decrypt(data text, key text) returns text pgp_encrypt_bytea(data bytea, key text) returns bytea pgp_decrypt_bytea(data bytea, key text) returns bytea To change parameters (cipher, compression, mdc): pgp_encrypt(data text, key text, parms text) returns bytea pgp_decrypt(data text, key text, parms text) returns text pgp_encrypt_bytea(data bytea, key text, parms text) returns bytea pgp_decrypt_bytea(data bytea, key text, parms text) returns bytea Parameter names I lifted from gpg: pgp_encrypt('message', 'key', 'compress-algo=1,cipher-algo=aes256') For text data, pgp_encrypt simply encrypts the PostgreSQL internal data. This maps to RFC2440 data type 't' - 'extenally specified encoding'. But this may cause problems if data is dumped and reloaded into database which as different internal encoding. My next goal is to implement data type 'u' - which means data is in UTF-8 encoding by converting internal encoding to UTF-8 and back. And there wont be any compatibility problems with current code, I think its ok to submit this without UTF-8 encoding by converting internal encoding to UTF-8 and back. And there wont be any compatibility problems with current code, I think its ok to submit this without UTF-8 support. Here is v4 of PGP encrypt. This depends on previously sent Fortuna-patch, as it uses the px_add_entropy function. - New function: pgp_key_id() for finding key id's. - Add SHA1 of user data and key into RNG pools. We need to get randomness from somewhere, and it is in user best interests to contribute. - Regenerate pgp-armor test for SQL_ASCII database. - Cleanup the key handling so that the pubkey support is less hackish. Marko Kreen
* - Add Fortuna PRNG to pgcrypto.Bruce Momjian2005-07-105-77/+284
| | | | | | | | | | | - Move openssl random provider to openssl.c and builtin provider to internal.c - Make px_random_bytes use Fortuna, instead of giving error. - Retarget random.c to aquiring system randomness, for initial seeding of Fortuna. There is ATM 2 functions for Windows, reader from /dev/urandom and the regular time()/getpid() silliness. Marko Kreen
* This patch adds implementation of SHA2 to pgcrypto.Bruce Momjian2005-07-102-4/+209
| | | | | | New hashes: SHA256, SHA384, SHA512. Marko Kreen
* Fix inadequate error checking: you can't assume that fcinfo->resultinfoTom Lane2005-07-092-41/+45
| | | | is a ReturnSetInfo unless you've tested it with IsA.
* This patch updates the DDL for contrib/pgcrypto to create allNeil Conway2005-07-081-14/+14
| | | | | | | | | | | | functions as STRICT, and all functions except gen_salt() as IMMUTABLE. gen_salt() is VOLATILE. Although the functions are now STRICT, I left their PG_ARGISNULL() checks in place as a protective measure for users who install the new code but use old (non-STRICT) catalog entries (e.g., restored from a dump). Per recent discussion in pgsql-hackers. Patch from Michael Fuhr.
* Fix incorrect PG_CPPFLAGS initialization, per Marko.Tom Lane2005-07-061-2/+2
|
* Dept of second thoughts: don't expose rijndael.tbl: rijndael.c dependencyTom Lane2005-07-051-2/+2
| | | | | | to make. We ship the table file in the tarball and so this dependency just opens file timestamp skew problems without doing anything useful. (Not that it should hurt, either ... except for cross-compile builds.)
* Fix contrib/pgcrypto to autoconfigure for OpenSSL when --with-opensslTom Lane2005-07-051-54/+26
| | | | is used in the toplevel configure. Per Marko Kreen.
* Fix initialization bug in pgcrypto openssl code. Marko KreenTom Lane2005-07-053-7/+7
|
* Arrange for the postmaster (and standalone backends, initdb, etc) toTom Lane2005-07-041-15/+12
| | | | | | | | chdir into PGDATA and subsequently use relative paths instead of absolute paths to access all files under PGDATA. This seems to give a small performance improvement, and it should make the system more robust against naive DBAs doing things like moving a database directory that has a live postmaster in it. Per recent discussion.
* Bruce, please apply this additional patch, that fixes theBruce Momjian2005-07-041-3/+4
| | | | | | | | | auto-detection of AES. Now openssl.c just checks OpenSSL version. Whoever compiles newer OpenSSL without AES is on his own. Marko Kreen
* This patch allows contrib/pgcrypto to build with OpenSSL 0.9.8Bruce Momjian2005-07-031-1/+4
| | | | | | | | | | | | | | | | | | (currently in beta) when cryptolib = openssl. According to the following checkin message from several years ago, OpenSSL application developers should no longer rely on <openssl/evp.h> to include everything they need: http://cvs.openssl.org/chngview?cn=9888 This patch adds the necessary header files. It doesn't appear to break anything when building against OpenSSL 0.9.7. BTW, core appears to build and work fine with OpenSSL 0.9.8. I've built 7.3 through HEAD against 0.9.8-beta6 without noticing any problems. Michael Fuhr
* Remove contrib version of rtree_gist --- now in core system.Tom Lane2005-07-0111-4436/+1
|
* Fixes from Janko Richter <jankorichter@yahoo.de>Teodor Sigaev2005-07-0127-304/+730
| | | | | | | | - Fix wrong index results on text, char, varchar for multibyte strings - Fix some SIGFPE signals - Add support for infinite timestamps - Because of locale settings, btree_gist can not be a prefix index anymore (for text). Each node holds now just the lower and upper boundary.
* Clean up the rather historically encumbered interface to now() andTom Lane2005-06-292-0/+5
| | | | | | | | current time: provide a GetCurrentTimestamp() function that returns current time in the form of a TimestampTz, instead of separate time_t and microseconds fields. This is what all the callers really want anyway, and it eliminates low-level dependencies on AbsoluteTime, which is a deprecated datatype that will have to disappear eventually.
* Remove the << >> &< and &> operators for contrib/cube, which wereTom Lane2005-06-277-978/+13
| | | | wrong, but nobody noticed because they were also useless.
* Adjust contrib/seg &< and &> operators so that r-tree indexing logicTom Lane2005-06-275-54/+60
| | | | | works properly for 1-D comparisons. Fix some other errors such as bogus commutator specifications.
* Add E'' syntax so eventually normal strings can treat backslashesBruce Momjian2005-06-262-30/+30
| | | | | | | | | | | | literally. Add GUC variables: "escape_string_warning" - warn about backslashes in non-E strings "escape_string_syntax" - supports E'' syntax? "standard_compliant_strings" - treats backslashes literally in '' Update code to use E'' when escapes are used.
* Extend r-tree operator classes to handle Y-direction tests equivalentTom Lane2005-06-242-9/+41
| | | | | | | | | | | | | | | to the existing X-direction tests. An rtree class now includes 4 actual 2-D tests, 4 1-D X-direction tests, and 4 1-D Y-direction tests. This involved adding four new Y-direction test operators for each of box and polygon; I followed the PostGIS project's lead as to the names of these operators. NON BACKWARDS COMPATIBLE CHANGE: the poly_overleft (&<) and poly_overright (&>) operators now have semantics comparable to box_overleft and box_overright. This is necessary to make r-tree indexes work correctly on polygons. Also, I changed circle_left and circle_right to agree with box_left and box_right --- formerly they allowed the boundaries to touch. This isn't actually essential given the lack of any r-tree opclass for circles, but it seems best to sync all the definitions while we are at it.
* Fix rtree and contrib/rtree_gist search behavior for the 1-D box andTom Lane2005-06-241-7/+12
| | | | | | | | | | polygon operators (<<, &<, >>, &>). Per ideas originally put forward by andrew@supernews and later rediscovered by moi. This patch just fixes the existing opclasses, and does not add any new behavior as I proposed earlier; that can be sorted out later. In principle this could be back-patched, since it changes only search behavior and not system catalog entries nor rtree index contents. I'm not currently planning to do that, though, since I think it could use more testing.
* Move findoidjoins out of contrib and into src/tools, which is a moreTom Lane2005-06-236-361/+1
| | | | | logical place for it since it is of no use to users. Per recent discussions on cleaning up contrib.
* Cleanup the contrib/lo module: there is no need anymore to implementTom Lane2005-06-236-203/+91
| | | | | | | | a physically separate type. Defining 'lo' as a domain over OID works just fine and is more efficient. Improve documentation and fix up the test script. (Would like to turn test script into a proper regression test, but right now its output is not constant because of numeric OIDs; plus it makes Unix-specific assumptions about files it can import.)
* Remove contrib modules that have been agreed to be obsolete.Tom Lane2005-06-2271-30667/+1
| | | | | (There are more that will be removed once they've been copied to pgfoundry.org.)
* Cause initdb to create a third standard database "postgres", whichTom Lane2005-06-217-14/+14
| | | | | | | | | | | | | | unlike template0 and template1 does not have any special status in terms of backend functionality. However, all external utilities such as createuser and createdb now connect to "postgres" instead of template1, and the documentation is changed to encourage people to use "postgres" instead of template1 as a play area. This should fix some longstanding gotchas involving unexpected propagation of database objects by createdb (when you used template1 without understanding the implications), as well as ameliorating the problem that CREATE DATABASE is unhappy if anyone else is connected to template1. Patch by Dave Page, minor editing by Tom Lane. All per recent pghackers discussions.
* Fix bogus assumption that sizeof() produces an int-sized result.Tom Lane2005-06-201-2/+2
|
* Simplify uses of readdir() by creating a function ReadDir() thatTom Lane2005-06-191-15/+4
| | | | | | | includes error checking and an appropriate ereport(ERROR) message. This gets rid of rather tedious and error-prone manipulation of errno, as well as a Windows-specific bug workaround, at more than a dozen call sites. After an idea in a recent patch by Heikki Linnakangas.
* Fix display of database name during autovacuum.Bruce Momjian2005-06-151-3/+3
| | | | Cosimo Streppone
* Simplify shared-memory lock data structures as per recent discussion:Tom Lane2005-06-141-3/+3
| | | | | | | | | | | | | | | | it is sufficient to track whether a backend holds a lock or not, and store information about transaction vs. session locks only in the inside-the-backend LocalLockTable. Since there can now be but one PROCLOCK per lock per backend, LockCountMyLocks() is no longer needed, thus eliminating some O(N^2) behavior when a backend holds many locks. Also simplify the LockAcquire/LockRelease API by passing just a 'sessionLock' boolean instead of a transaction ID. The previous API was designed with the idea that per-transaction lock holding would be important for subtransactions, but now that we have subtransactions we know that this is unwanted. While at it, add an 'isTempObject' parameter to LockAcquire to indicate whether the lock is being taken on a temp table. This is not used just yet, but will be needed shortly for two-phase commit.
* Prevent to divide by zero and range out of 0..1Teodor Sigaev2005-06-011-4/+7
|
* Change relblocknumber field of pg_buffercache view from numeric to int8Tom Lane2005-05-313-7/+7
| | | | for efficiency's sake. Mark Kirkwood.
* Document get_call_result_type() and friends; mark TypeGetTupleDesc()Tom Lane2005-05-309-205/+277
| | | | | | and RelationNameGetTupleDesc() as deprecated; remove uses of the latter in the contrib library. Along the way, clean up crosstab() code and documentation a little.
* Improve LockAcquire API per my recent proposal. All error conditionsTom Lane2005-05-291-2/+2
| | | | | | | | are now reported via elog, eliminating the need to test the result code at most call sites. Make it possible for the caller to distinguish a freshly acquired lock from one already held in the current transaction. Use that capability to avoid redundant AcceptInvalidationMessages() calls in LockRelation().
* Modify hash_search() API to prevent future occurrences of the errorTom Lane2005-05-292-9/+0
| | | | | | | | | | | | | spotted by Qingqing Zhou. The HASH_ENTER action now automatically fails with elog(ERROR) on out-of-memory --- which incidentally lets us eliminate duplicate error checks in quite a bunch of places. If you really need the old return-NULL-on-out-of-memory behavior, you can ask for HASH_ENTER_NULL. But there is now an Assert in that path checking that you aren't hoping to get that behavior in a palloc-based hash table. Along the way, remove the old HASH_FIND_SAVE/HASH_REMOVE_SAVED actions, which were not being used anywhere anymore, and were surely too ugly and unsafe to want to see revived again.
* Clean up bogus checking of date and numeric fields in DBF files,Tom Lane2005-05-271-38/+15
| | | | per report from Boris van Schooten.
* Remove second argument from textToQualifiedNameList(), as it is no longerNeil Conway2005-05-273-7/+5
| | | | used. From Jaime Casanova.
* Add parentheses to macros when args are used in computations. WithoutBruce Momjian2005-05-2518-124/+124
| | | | them, the executation behavior could be unexpected.
* Correct a thinko in pgbench that might result in incorrectly ignoring anNeil Conway2005-05-241-2/+2
| | | | error condition when executing some DDL. Per report from ITAGAKI Takahiro.
* Cleanup of GiST extensions in contrib/: now that we always invoke GiSTNeil Conway2005-05-2116-174/+18
| | | | | methods in a short-lived memory context, there is no need for GiST methods to do their own manual (and error-prone) memory management.
* Factor out lock cleanup code that is needed in several places in lock.c.Tom Lane2005-05-191-1/+3
| | | | | | | | Also, remove the rather useless return value of LockReleaseAll. Change response to detection of corruption in the shared lock tables to PANIC, since that is the only way of cleaning up fully. Originally an idea of Heikki Linnakangas, variously hacked on by Alvaro Herrera and Tom Lane.
* Extend the pg_locks system view so that it can fully display all lockTom Lane2005-05-171-3/+3
| | | | types, as per recent discussion.
* Add a --dbname option to the pg_regress script, and use pl_regressionTom Lane2005-05-173-17/+18
| | | | | | for testing PLs and contrib_regression for testing contrib, instead of overwriting the core system's regression database as formerly done. Andrew Dunstan
* Cleanup GiST header files. Since GiST extensions are often written asNeil Conway2005-05-171-0/+1
| | | | | | | | | | | | external projects, we should be careful about what parts of the GiST API are considered implementation details, and which are part of the public API. Therefore, I've moved internal-only declarations into gist_private.h -- future backward-incompatible changes to gist.h should be made with care, to avoid needlessly breaking external GiST extensions. Also did some related header cleanup: remove some unnecessary #includes from gist.h, and remove some unused definitions: isAttByVal(), _gistdump(), and GISTNStrategies.