Wiki / Procedural Languages / PL/Tcl
pltclu
PL/TclU untrusted procedural language
Reading PostgreSQL 18.6.
Description
PL/TclU untrusted procedural language
- Kind
- Bundled procedural-language variant
- Family
- PL/Tcl
- Trusted
- f
- Handler
- pltclu_call_handler
- Library
- $libdir/pltcl
- Default version
- 1.0
- Module pathname
- $libdir/pltcl
- Comment
- PL/TclU untrusted procedural language
Installation definition from the matching source archive
This extension is shipped with the source. Its presence does not establish that the language or external runtime is installed.
/* src/pl/tcl/pltclu--1.0.sql */
CREATE FUNCTION pltclu_call_handler() RETURNS language_handler
LANGUAGE c AS 'MODULE_PATHNAME';
CREATE LANGUAGE pltclu
HANDLER pltclu_call_handler;
COMMENT ON LANGUAGE pltclu IS 'PL/TclU untrusted procedural language';Manual definition
42.1. Overview
PL/Tcl offers most of the capabilities a function writer has in the C language, with a few restrictions, and with the addition of the powerful string processing libraries that are available for Tcl.
One compelling good restriction is that everything is executed from within the safety of the context of a Tcl interpreter. In addition to the limited command set of safe Tcl, only a few commands are available to access the database via SPI and to raise messages via elog(). PL/Tcl provides no way to access internals of the database server or to gain OS-level access under the permissions of the PostgreSQL server process, as a C function can do. Thus, unprivileged database users can be trusted to use this language; it does not give them unlimited authority.
The other notable implementation restriction is that Tcl functions cannot be used to create input/output functions for new data types.
Sometimes it is desirable to write Tcl functions that are not restricted to safe Tcl. For example, one might want a Tcl function that sends email. To handle these cases, there is a variant of PL/Tcl called PL/TclU (for untrusted Tcl). This is exactly the same language except that a full Tcl interpreter is used. If PL/TclU is used, it must be installed as an untrusted procedural language so that only database superusers can create functions in it. The writer of a PL/TclU function must take care that the function cannot be used to do anything unwanted, since it will be able to do anything that could be done by a user logged in as the database administrator.
The shared object code for the PL/Tcl and PL/TclU call handlers is automatically built and installed in the PostgreSQL library directory if Tcl support is specified in the configuration step of the installation procedure. To install PL/Tcl and/or PL/TclU in a particular database, use the CREATE EXTENSION command, for example CREATE EXTENSION pltcl or CREATE EXTENSION pltclu.
Related entries
Documentation and source
Source build
- Version
- 18.6
- Build
- https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2
- Source fingerprint
555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f
Compare versions
PostgreSQL 17 → 18: unchanged.
Compares recorded interfaces and attributes. Source fingerprints and build metadata are excluded; an absent sample is not proof of the introduction or removal release.
Related entries
Export JSON · Back to Procedural Languages · Recorded in PostgreSQL 10 through 20; the first sample is not necessarily its introduction.