Re: DANGER! Re: Privilege.ace - updated
Posted in 1994
Alan, Thanks for pointing out the problem with privilege.ace and I apologize for any problems it may have caused. I will send a corrected version of the program to anyone who requests it, and to Walt to add to the ftp archives at emory. The ace report uses 3 tempory tables: users1 users pub IF YOU HAVE ANY TABLES IN YOU DATABASE WITH THESE NAMES PLEASE DO NOT USER THE REPORT WITHOUT CHANGING THE TEMP TABLE NAMES. I will be changing the temp tables to: users1 - tmp_u_111 users - tmp_u_112 pub - tmp_u_113 Regards - Lester Alan said: } } DANGER: See warning below! } } Lester's tool does a good job of what it is supposed to do, EXCEPT it } contains one very DANGEROUS error. } } It uses a temporary table named `users'. } } My database contained (note the past tense) a permanent table also named } `users'. When I ran Lester's tool against it, the report failed, stating } that there already was a table with that name. However, as part of the } normal program clean-up, the ACE program *DELETED* my permanent table!!!! } } I did not notice this problem immediately. I modified the report to use } table `users2' instead of `users', rebuilt it, and reran it. This is how } I know the tool works well. } } Based on this experience, I offer several suggestions: } } 1. Anyone who wants to use this tool should change the name of the temp table } `users' to something else: `users2', `usertmp2', whatever. } 2. People who post tools to the net should use less "obvious" names for temp } tables. Try to include something in the name that will reduce the likeli- } hood of colliding with an existing table name. For example, I consider } `users' to be an "obvious" table name, which might already exist, while } `usertmp1' or `user_qj_2' seem less likely to be permanent tables. This } naming technique is not perfect, but it will REDUCE the chance of problems. } 3. DBAs (myself included) should be less trusting of tools that they pull } off the net. They should check for temp table name collisions, etc., etc. } I have the highest regard for Lester's work, based on his many useful } postings. This lulled me into having a sense of safety regarding this } tool. I ran it after giving it only the most cursory review, and did not } notice this disastrous name collision. } } Regards, } ______________________| R. Alan Popiel |__________________________ } \\ Internet: | Martin Marietta, SLS | / } \\ alan@den.mmc.com | P.O. Box 179, M/S 3810 | Std disclaimers apply. / } )Voice: | Denver, CO 80201-0179 USA | ( } / 303-977-9998 |___________________________| (But you knew that!) \\ } /________________________) (____________________________\\ }