1. 27 Jun, 2011 6 commits
  2. 26 Jun, 2011 7 commits
  3. 25 Jun, 2011 1 commit
  4. 24 Jun, 2011 1 commit
  5. 23 Jun, 2011 5 commits
  6. 22 Jun, 2011 16 commits
  7. 21 Jun, 2011 4 commits
    • Tom Lane's avatar
      Minor editing for README-SSI. · a3290f65
      Tom Lane authored
      Fix some grammatical issues, try to clarify a couple of proofs, make the
      terminology more consistent.
      a3290f65
    • Peter Eisentraut's avatar
      Message style and spelling improvements · e2a0cb1a
      Peter Eisentraut authored
      e2a0cb1a
    • Tom Lane's avatar
      Apply upstream fix for blowfish signed-character bug (CVE-2011-2483). · ca59dfa6
      Tom Lane authored
      A password containing a character with the high bit set was misprocessed
      on machines where char is signed (which is most).  This could cause the
      preceding one to three characters to fail to affect the hashed result,
      thus weakening the password.  The result was also unportable, and failed
      to match some other blowfish implementations such as OpenBSD's.
      
      Since the fix changes the output for such passwords, upstream chose
      to provide a compatibility hack: password salts beginning with $2x$
      (instead of the usual $2a$ for blowfish) are intentionally processed
      "wrong" to give the same hash as before.  Stored password hashes can
      thus be modified if necessary to still match, though it'd be better
      to change any affected passwords.
      
      In passing, sync a couple other upstream changes that marginally improve
      performance and/or tighten error checking.
      
      Back-patch to all supported branches.  Since this issue is already
      public, no reason not to commit the fix ASAP.
      ca59dfa6
    • Heikki Linnakangas's avatar
      Adjust the alternative expected output file for prepared_xacts test case, · 38c0e721
      Heikki Linnakangas authored
      used when max_prepared_transactions=0, for the recent changes in the test
      case.
      38c0e721