Re: Commitfest 2021-11 Patch Triage - Part 2

From: Andrey Borodin <x4mmm(at)yandex-team(dot)ru>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: PostgreSQL Hackers <pgsql-hackers(at)lists(dot)postgresql(dot)org>, Daniel Gustafsson <daniel(at)yesql(dot)se>
Subject: Re: Commitfest 2021-11 Patch Triage - Part 2
Date: 2021-11-10 15:54:21
Message-ID: 261311636559661@vla1-4ea76ba32639.qloud-c.yandex.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

> Daniel Gustafsson <daniel(at)yesql(dot)se> writes:
>
>> 2773: libpq compression
>> =======================
>> This patch intended to provide libpq connection compression to "replace SSL
>> compression" which was doomed when the patch was written, and have since been
>> removed altogether. The initial approach didn't get much traction but there
>> was significant discussion and work, which has since fizzled out. The patch
>> has been updated but there hasn't been meaningful review the past months, the
>> last comments seem to imply there being a fair amount of questionmarks left in
>> here. Robert, having been very involved in this do you have any thoughts on
>> where we are and where to go (if at all IYO)?
>
> I'm not Robert, but I still have an opinion here, and that it's that this
> feature would at best be an attractive nuisance. If you need compression
> on a database session, it probably means that the connection is over the
> open internet, which means that you need encryption even more. And we
> know that compression and encryption do not play well together. The
> reason compression was taken out of the latest TLS standards is not that
> they wouldn't have liked to have it, nor that applying compression in a
> separate code layer would be any safer. I fear offering this would
> merely lead people to build CVE-worthy setups.
>

Compression is crucial for highly available setups. Replication traffic is often billed. Or route has bandwidth limits.
An entropy added by WAL headers makes CRIME attack against replication encryption impractical.

Best regards, Andrey Borodin.

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Justin Pryzby 2021-11-10 15:56:44 Re: terminate called after throwing an instance of 'std::bad_alloc'
Previous Message Dagfinn Ilmari Mannsåker 2021-11-10 15:42:00 Re: Removed unused import modules from tap tests