I-Redis 7.0 ifika nophuculo lokusebenza, ukulungiswa kwebug kunye nokunye

Inguqulelo entsha ye-DBMS Redis 7.0 sele ikhutshiwe, I-Redis inikezela ngeempawu zokugcina idatha kwifomathi engundoqo / yexabiso, eyandisiweyo ngenkxaso yeefomathi zedatha ezicwangcisiweyo ezifana noluhlu, i-hashes, kunye neeseti, kunye nokukwazi ukuqhuba i-server-side Lua script drivers.

Ngokungafaniyo neenkqubo zokugcina kwimemori ezifana neMemcached, iRedis ibonelela ngokuqhubekayo ukugcinwa kwedatha kwidiski kwaye iqinisekisa ukhuseleko lwedatha xa kwenzeka ukuvalwa okungaqhelekanga. Izicatshulwa zomthombo weprojekthi zihanjiswa phantsi kwelayisensi ye-BSD.

Iilayibrari zabaxumi ziyafumaneka kwezona lwimi zidumileyo, kubandakanya iPerl, iPython, i-PHP, iJava, iRuby, kunye neTcl. I-Redis ixhasa iintengiselwano ezikuvumela ukuba wenze iqela lemiyalelo kwinqanaba elinye, ukuqinisekisa ukuhambelana kunye nokungaguquguquki (imiyalelo evela kwezinye izicelo ayikwazi ukubhloka) ukuphunyezwa kweseti yemiyalelo enikiweyo, kwaye kwimeko yeengxaki, ikuvumela ukuba ubuyele umva. utshintsho. Yonke idatha igcinwe ngokupheleleyo kwi-RAM.

I-Redis 7.0 yeempawu eziphambili

Kolu guqulelo lutsha lweDBMS oluvezwayo inkxaso eyongeziweyo yemisebenzi yecala lomncedisi, ngokungafaniyo nezikripthi zeLua ezixhasiweyo ngaphambili, imisebenzi ayikhankanyi kwisicelo kwaye ijolise ekuphumezeni ingqiqo eyongezelelweyo eyandisa ubunakho bomncedisi.

Imisebenzi icutshungulwa ngokungafaniyo kunye nedatha kwaye ngokumalunga nesiseko sedatha, kwaye kungekhona isicelo, kubandakanywa ukuphindaphinda kunye nokugcinwa okuqhubekayo.

Enye into entsha ebalaseleyo kwiRedis 7.0 yi ACL uhlelo lwesibini, ekuvumela ukuba ulawule ukufikelela kwidatha esekelwe kwizitshixo kwaye ikuvumela ukuba uchaze iiseti ezahlukeneyo zemithetho yokufikelela kwimiyalelo enekhono lokubopha abakhethi abaninzi (iiseti zemvume) kumsebenzisi ngamnye. Isitshixo ngasinye sinokuchongwa ngeemvume ezithile, umzekelo unokunqanda ukufikelela ekufundeni kuphela okanye ukubhala kwiseti ethile yezitshixo.

Ukongeza koku, kuphawulwe ukuba Redis 7.0 ibonelela unayo ukuphunyezwa okucandekileyo yeparadigm yokuhanjiswa komyalezo Papasha-Bhalisa, esebenza kwiqela, apho umyalezo uthunyelwa kwindawo ethile apho ijelo lomyalezo lincanyathiselwe, emva koko lo myalezo uqondiswe kwakhona kwiindawo eziseleyo ezifakwe kwi-hull. Abathengi banokufumana imiyalezo ngokubhalisela kwitshaneli, zombini ngokudibanisa kwi-node ephambili kunye nakwiindawo zesibini zecandelo.

Kuyacaciswa ukuba inike amandla okuphatha uqwalaselo oluninzi ngexesha elinye kwifowuni enye CONFIG SET/GET kwaye iinketho "-json", "-2", "-scan", "-functions-rdb" ziye zongezwa kwi-redis-cli eluncedo.

Ngokuzenzekela, ukufikelela kuseto kunye nemiyalelo echaphazela ukhuseleko ivaliwe kubathengi (umzekelo, DEBUG kunye neMODULE imiyalelo zivaliwe, ukutshintsha ubumbeko nge PROTECTED_CONFIG iflegi akuvumelekanga). I-Redis-cli iyekile ukuthumela imiyalelo equlethe idatha ebuthathaka kwifayile yembali.

Kwelinye icala, kuyabonakala ukubae wenze inxalenye enkulu yokulungiswa okujoliswe ekuphuculeni ukusebenza kunye nokunciphisa ukusetyenziswa kwememori. Umzekelo, ukusetyenziswa kwememori kuye kwancitshiswa kakhulu xa imowudi yeqela yenziwe, xa kusenziwa imisebenzi yokukhuphela-kwi-bhala, kwaye xa usebenza ngehash kunye nezitshixo ze-zset, kunye nengqiqo yaphuculwa ukugungxula idatha kwidisk (ebizwa ngokuba yi-fsync).

Ubuthathaka obuzinzileyo CVE-2022-24735 Kwimeko-bume yophumezo lweskripthi se-Lua, ekuvumela ukuba ubhale ngaphezulu eyakho ikhowudi ye-Lua kwaye ibangele ukuba iqhube kumxholo womnye umsebenzisi, kuquka lawo anamalungelo aphezulu.

Ngaphezu koko, sinokukhomba ukuba sesichengeni (CVE-2022-0543) kwiiphakheji ezineRedis zoBuntu kunye neDebian (umcimbi ungqale kwiindibano zomntu ngamnye kwaye awunxulumananga neRedis ngokwayo), evumela ukuba ikhowudi yeLua iqhutywe kwiseva ekude kwaye idlule indlela yokubeka yodwa yebhokisi yesanti yokusingqongileyo ekusebenziseni izikripthi kwiRedis.

Ubuthathaka obongeziweyo CVE-2022-24736 obunokuvumela inkqubo yeseva ye-redis ukuba ingqubene ngenxa yesalathiso esingenanto. Uhlaselo lwenziwa ngokulayisha ngokukhethekileyo imibhalo yesiLua eyilwe ngokukhethekileyo.

ekugqibeleni ukuba ukhona unomdla wokwazi ngakumbi ngayo, Ungajonga iinkcukacha koku kulandelayo unxibelelwano


Shiya uluvo lwakho

Idilesi yakho ye email aziyi kupapashwa. ezidingekayo ziphawulwe *

*

*

  1. Inoxanduva lwedatha: I-AB Internet Networks 2008 SL
  2. Injongo yedatha: Ulawulo lwe-SPAM, ulawulo lwezimvo.
  3. Umthetho: Imvume yakho
  4. Unxibelelwano lwedatha: Idatha ayizukuhanjiswa kubantu besithathu ngaphandle koxanduva lomthetho.
  5. Ukugcinwa kweenkcukacha
  6. Amalungelo: Ngalo naliphi na ixesha unganciphisa, uphinde uphinde ucime ulwazi lwakho.