On Apr 30, 2009, at 10:18 PM, William Stein wrote: > On Thu, Apr 30, 2009 at 10:13 PM, mabshoff > <mabsh...@googlemail.com> wrote: >> >> >> >> On Apr 30, 10:06 pm, John H Palmieri <jhpalmier...@gmail.com> wrote: >>> On Apr 30, 8:54 pm, mabshoff <mabsh...@googlemail.com> wrote: >> >> <SNIP> >> >>>> Is this reproducible? >>> >>> Apparently not: I've been trying to get it again, but >>> unsuccessfully. >> >> Yeah, my experience is that that code is inherently racy and no one >> has even been able to reproduce it. I don't see it on sage.math at >> all, but I am also use a RAM disk for DOT_SAGE, so I think that has >> something to do with it. >> >>> John >> >> It looks like we should consider merging "#5952: Worksheet >> downloading >> blocks the entire server" since otherwise you can trivially DOS the >> whole server. > >> Maybe that option should be disabled per default for >> now? No patch has been posted and I am not 100% sure RobertWB is >> working on a patch. Comments? > > I could easily DOS any sage notebook server right now in many ways, > which I won't list here since I don't want to give anybody any ideas. > #5952 only stops the server *while* the directories with the > worksheets are being tar'd up -- once that filesystem operation > finishes, things go back to being nonblocking.
Yes, it is easily to DOS the notebook if one tries, but I'm wary of a big button that "accidently" does so. Taring up the directories for a dozen worksheets can take several minutes. I'll try to get a patch out tonight, perhaps as a first pass it would be good to use to the opposite of the accounts option in the notebook () command. - Robert --~--~---------~--~----~------------~-------~--~----~ To post to this group, send email to sage-devel@googlegroups.com To unsubscribe from this group, send email to sage-devel-unsubscr...@googlegroups.com For more options, visit this group at http://groups.google.com/group/sage-devel URLs: http://www.sagemath.org -~----------~----~----~----~------~----~------~--~---