{"Entry":{"collection":"language","key":"pltclu","name":"pltclu","aliases":[],"metadata":{"aliases":[],"category":"PL/Tcl","content_hash":"978d6468963c6b1f279806e037135a9949da86234aa52b54dc3d6db189fc31ab","imported_at":"2026-09-30T00:40:44.373921+08:00","name":"pltclu","name_zh":"","slug":"pltclu","summary":"PL/TclU untrusted procedural language"}},"Definition":{"Collection":"language","Key":"pltclu","SourceDatabase":"center","Version":"18","SourceTable":"procedural_language","SourceKey":"pltclu","SourceRevision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","Facts":{"aliases":[],"attributes":{"comment":"PL/TclU untrusted procedural language","default_version":"1.0","family":"PL/Tcl","handler":"pltclu_call_handler","inline_handler":"","kind":"Bundled procedural-language variant","library":"$libdir/pltcl","module_pathname":"$libdir/pltcl","trusted":"f","validator":""},"comparison_data":{"default_version":"1.0","family":"PL/Tcl","handler":"pltclu_call_handler","inline_handler":"","kind":"Bundled procedural-language variant","library":"$libdir/pltcl","trusted":"f","validator":""},"comparison_hash":"f76f2eec7aa9560ce301885f25a023a15137ef259d3f0536f267d92fdb9f3ffe","description":["PL/TclU untrusted procedural language"],"facts":[{"label":"Kind","value":"Bundled procedural-language variant"},{"label":"Family","value":"PL/Tcl"},{"label":"Trusted","value":"f"},{"label":"Handler","value":"pltclu_call_handler"},{"label":"Library","value":"$libdir/pltcl"},{"label":"Default version","value":"1.0"},{"label":"Module pathname","value":"$libdir/pltcl"},{"label":"Comment","value":"PL/TclU untrusted procedural language"}],"manual_html":"\u003cdiv class=\"sect1\" id=\"PLTCL-OVERVIEW\"\u003e\n\u003cdiv class=\"titlepage\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2 class=\"title\"\u003e42.1. Overview \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003ePL/Tcl offers most of the capabilities a function writer has in the C language, with a few restrictions, and with the addition of the powerful string processing libraries that are available for Tcl.\u003c/p\u003e\n\u003cp\u003eOne compelling \u003cspan class=\"emphasis\"\u003e\u003cem\u003egood\u003c/em\u003e\u003c/span\u003e restriction is that everything is executed from within the safety of the context of a Tcl interpreter. In addition to the limited command set of safe Tcl, only a few commands are available to access the database via SPI and to raise messages via \u003ccode class=\"function\"\u003eelog()\u003c/code\u003e. PL/Tcl provides no way to access internals of the database server or to gain OS-level access under the permissions of the \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e server process, as a C function can do. Thus, unprivileged database users can be trusted to use this language; it does not give them unlimited authority.\u003c/p\u003e\n\u003cp\u003eThe other notable implementation restriction is that Tcl functions cannot be used to create input/output functions for new data types.\u003c/p\u003e\n\u003cp\u003eSometimes it is desirable to write Tcl functions that are not restricted to safe Tcl. For example, one might want a Tcl function that sends email. To handle these cases, there is a variant of \u003cspan class=\"application\"\u003ePL/Tcl\u003c/span\u003e called \u003ccode class=\"literal\"\u003ePL/TclU\u003c/code\u003e (for untrusted Tcl). This is exactly the same language except that a full Tcl interpreter is used. \u003cspan class=\"emphasis\"\u003e\u003cem\u003eIf \u003cspan class=\"application\"\u003ePL/TclU\u003c/span\u003e is used, it must be installed as an untrusted procedural language\u003c/em\u003e\u003c/span\u003e so that only database superusers can create functions in it. The writer of a \u003cspan class=\"application\"\u003ePL/TclU\u003c/span\u003e function must take care that the function cannot be used to do anything unwanted, since it will be able to do anything that could be done by a user logged in as the database administrator.\u003c/p\u003e\n\u003cp\u003eThe shared object code for the \u003cspan class=\"application\"\u003ePL/Tcl\u003c/span\u003e and \u003cspan class=\"application\"\u003ePL/TclU\u003c/span\u003e call handlers is automatically built and installed in the \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e library directory if Tcl support is specified in the configuration step of the installation procedure. To install \u003cspan class=\"application\"\u003ePL/Tcl\u003c/span\u003e and/or \u003cspan class=\"application\"\u003ePL/TclU\u003c/span\u003e in a particular database, use the \u003ccode class=\"command\"\u003eCREATE EXTENSION\u003c/code\u003e command, for example \u003ccode class=\"literal\"\u003eCREATE EXTENSION pltcl\u003c/code\u003e or \u003ccode class=\"literal\"\u003eCREATE EXTENSION pltclu\u003c/code\u003e.\u003c/p\u003e\n\u003c/div\u003e","manual_path":"/docs/18/pltcl-overview.html","related":[{"label":"pltcl-config","url":"/docs/18/pltcl-config.html"},{"label":"pltcl-data","url":"/docs/18/pltcl-data.html"},{"label":"pltcl-dbaccess","url":"/docs/18/pltcl-dbaccess.html"},{"label":"pltcl-error-handling","url":"/docs/18/pltcl-error-handling.html"},{"label":"pltcl-event-trigger","url":"/docs/18/pltcl-event-trigger.html"},{"label":"pltcl-functions","url":"/docs/18/pltcl-functions.html"},{"label":"pltcl-global","url":"/docs/18/pltcl-global.html"},{"label":"pltcl-overview","url":"/docs/18/pltcl-overview.html"},{"label":"pltcl-procnames","url":"/docs/18/pltcl-procnames.html"},{"label":"pltcl-subtransactions","url":"/docs/18/pltcl-subtransactions.html"},{"label":"pltcl-transactions","url":"/docs/18/pltcl-transactions.html"},{"label":"pltcl-trigger","url":"/docs/18/pltcl-trigger.html"}],"release":{"catalog_fingerprint":"65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502","channel":"stable","label":"18.6","major":"18","ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sections":[{"code":"/* src/pl/tcl/pltclu--1.0.sql */\n\nCREATE FUNCTION pltclu_call_handler() RETURNS language_handler\n  LANGUAGE c AS 'MODULE_PATHNAME';\n\nCREATE LANGUAGE pltclu\n  HANDLER pltclu_call_handler;\n\nCOMMENT ON LANGUAGE pltclu IS 'PL/TclU untrusted procedural language';","paragraphs":["This extension is shipped with the source. Its presence does not establish that the language or external runtime is installed."],"title":"Installation definition from the matching source archive"}],"signature":"","source_files":{"src/pl/tcl/pltclu--1.0.sql":"81990a8e4dd323fd70a2669dcbd33a9d74d250bc7a965790dee9d96b3f823d0c","src/pl/tcl/pltclu.control":"f8b2f8f3b14be8d14326913047eb320227f6891f6d303eecf300f0231ac853d4"},"sources":[{"label":"Matching PostgreSQL source archive","sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"label":"PostgreSQL 18 English manual","path":"pltcl-overview.html","sha256":"ed93c7e7682e446657a8c944dbabdabb0236e2d09c48db1c7e804270ce480044","url":"/docs/18/pltcl-overview.html"}],"tables":[]},"ManualEvidence":{"manual_path":"/docs/18/pltcl-overview.html","release":{"catalog_fingerprint":"65c93d6048ef30e61023a84f9680fa6a92b1c383b7eb226741170077eb078502","channel":"stable","label":"18.6","major":"18","ref":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2","revision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","source_sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f"},"sources":[{"label":"Matching PostgreSQL source archive","sha256":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","url":"https://ftp.postgresql.org/pub/source/v18.6/postgresql-18.6.tar.bz2"},{"label":"PostgreSQL 18 English manual","path":"pltcl-overview.html","sha256":"ed93c7e7682e446657a8c944dbabdabb0236e2d09c48db1c7e804270ce480044","url":"/docs/18/pltcl-overview.html"}]},"MeasuredEvidence":{}},"Text":{"Collection":"language","Key":"pltclu","SourceDatabase":"center","Version":"18","Locale":"en","Title":"pltclu","Summary":"PL/TclU untrusted procedural language","BodyHTML":"\u003cdiv id=\"PLTCL-OVERVIEW\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2\u003e42.1. Overview \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003ePL/Tcl offers most of the capabilities a function writer has in the C language, with a few restrictions, and with the addition of the powerful string processing libraries that are available for Tcl.\u003c/p\u003e\n\u003cp\u003eOne compelling \u003cspan\u003e\u003cem\u003egood\u003c/em\u003e\u003c/span\u003e restriction is that everything is executed from within the safety of the context of a Tcl interpreter. In addition to the limited command set of safe Tcl, only a few commands are available to access the database via SPI and to raise messages via \u003ccode\u003eelog()\u003c/code\u003e. PL/Tcl provides no way to access internals of the database server or to gain OS-level access under the permissions of the \u003cspan\u003ePostgreSQL\u003c/span\u003e server process, as a C function can do. Thus, unprivileged database users can be trusted to use this language; it does not give them unlimited authority.\u003c/p\u003e\n\u003cp\u003eThe other notable implementation restriction is that Tcl functions cannot be used to create input/output functions for new data types.\u003c/p\u003e\n\u003cp\u003eSometimes it is desirable to write Tcl functions that are not restricted to safe Tcl. For example, one might want a Tcl function that sends email. To handle these cases, there is a variant of \u003cspan\u003ePL/Tcl\u003c/span\u003e called \u003ccode\u003ePL/TclU\u003c/code\u003e (for untrusted Tcl). This is exactly the same language except that a full Tcl interpreter is used. \u003cspan\u003e\u003cem\u003eIf \u003cspan\u003ePL/TclU\u003c/span\u003e is used, it must be installed as an untrusted procedural language\u003c/em\u003e\u003c/span\u003e so that only database superusers can create functions in it. The writer of a \u003cspan\u003ePL/TclU\u003c/span\u003e function must take care that the function cannot be used to do anything unwanted, since it will be able to do anything that could be done by a user logged in as the database administrator.\u003c/p\u003e\n\u003cp\u003eThe shared object code for the \u003cspan\u003ePL/Tcl\u003c/span\u003e and \u003cspan\u003ePL/TclU\u003c/span\u003e call handlers is automatically built and installed in the \u003cspan\u003ePostgreSQL\u003c/span\u003e library directory if Tcl support is specified in the configuration step of the installation procedure. To install \u003cspan\u003ePL/Tcl\u003c/span\u003e and/or \u003cspan\u003ePL/TclU\u003c/span\u003e in a particular database, use the \u003ccode\u003eCREATE EXTENSION\u003c/code\u003e command, for example \u003ccode\u003eCREATE EXTENSION pltcl\u003c/code\u003e or \u003ccode\u003eCREATE EXTENSION pltclu\u003c/code\u003e.\u003c/p\u003e\n\u003c/div\u003e","SourceRevision":"555610c24d53e4316da5b7d3fc25c279d96856d5e0e23ee308c328c5fa881d9f","ContentHash":"3f724ec86ef33ace30131af1cbb39dfff53e7f3fd4af6ed1d844b9cd39cb41c5","Payload":{"description":["PL/TclU untrusted procedural language"],"manual_html":"\u003cdiv class=\"sect1\" id=\"PLTCL-OVERVIEW\"\u003e\n\u003cdiv class=\"titlepage\"\u003e\n\u003cdiv\u003e\n\u003cdiv\u003e\n\u003ch2 class=\"title\"\u003e42.1. Overview \u003c/h2\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003c/div\u003e\n\u003cp\u003ePL/Tcl offers most of the capabilities a function writer has in the C language, with a few restrictions, and with the addition of the powerful string processing libraries that are available for Tcl.\u003c/p\u003e\n\u003cp\u003eOne compelling \u003cspan class=\"emphasis\"\u003e\u003cem\u003egood\u003c/em\u003e\u003c/span\u003e restriction is that everything is executed from within the safety of the context of a Tcl interpreter. In addition to the limited command set of safe Tcl, only a few commands are available to access the database via SPI and to raise messages via \u003ccode class=\"function\"\u003eelog()\u003c/code\u003e. PL/Tcl provides no way to access internals of the database server or to gain OS-level access under the permissions of the \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e server process, as a C function can do. Thus, unprivileged database users can be trusted to use this language; it does not give them unlimited authority.\u003c/p\u003e\n\u003cp\u003eThe other notable implementation restriction is that Tcl functions cannot be used to create input/output functions for new data types.\u003c/p\u003e\n\u003cp\u003eSometimes it is desirable to write Tcl functions that are not restricted to safe Tcl. For example, one might want a Tcl function that sends email. To handle these cases, there is a variant of \u003cspan class=\"application\"\u003ePL/Tcl\u003c/span\u003e called \u003ccode class=\"literal\"\u003ePL/TclU\u003c/code\u003e (for untrusted Tcl). This is exactly the same language except that a full Tcl interpreter is used. \u003cspan class=\"emphasis\"\u003e\u003cem\u003eIf \u003cspan class=\"application\"\u003ePL/TclU\u003c/span\u003e is used, it must be installed as an untrusted procedural language\u003c/em\u003e\u003c/span\u003e so that only database superusers can create functions in it. The writer of a \u003cspan class=\"application\"\u003ePL/TclU\u003c/span\u003e function must take care that the function cannot be used to do anything unwanted, since it will be able to do anything that could be done by a user logged in as the database administrator.\u003c/p\u003e\n\u003cp\u003eThe shared object code for the \u003cspan class=\"application\"\u003ePL/Tcl\u003c/span\u003e and \u003cspan class=\"application\"\u003ePL/TclU\u003c/span\u003e call handlers is automatically built and installed in the \u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e library directory if Tcl support is specified in the configuration step of the installation procedure. To install \u003cspan class=\"application\"\u003ePL/Tcl\u003c/span\u003e and/or \u003cspan class=\"application\"\u003ePL/TclU\u003c/span\u003e in a particular database, use the \u003ccode class=\"command\"\u003eCREATE EXTENSION\u003c/code\u003e command, for example \u003ccode class=\"literal\"\u003eCREATE EXTENSION pltcl\u003c/code\u003e or \u003ccode class=\"literal\"\u003eCREATE EXTENSION pltclu\u003c/code\u003e.\u003c/p\u003e\n\u003c/div\u003e","related":[{"label":"pltcl-config","url":"/docs/18/pltcl-config.html"},{"label":"pltcl-data","url":"/docs/18/pltcl-data.html"},{"label":"pltcl-dbaccess","url":"/docs/18/pltcl-dbaccess.html"},{"label":"pltcl-error-handling","url":"/docs/18/pltcl-error-handling.html"},{"label":"pltcl-event-trigger","url":"/docs/18/pltcl-event-trigger.html"},{"label":"pltcl-functions","url":"/docs/18/pltcl-functions.html"},{"label":"pltcl-global","url":"/docs/18/pltcl-global.html"},{"label":"pltcl-overview","url":"/docs/18/pltcl-overview.html"},{"label":"pltcl-procnames","url":"/docs/18/pltcl-procnames.html"},{"label":"pltcl-subtransactions","url":"/docs/18/pltcl-subtransactions.html"},{"label":"pltcl-transactions","url":"/docs/18/pltcl-transactions.html"},{"label":"pltcl-trigger","url":"/docs/18/pltcl-trigger.html"}],"sections":[{"code":"/* src/pl/tcl/pltclu--1.0.sql */\n\nCREATE FUNCTION pltclu_call_handler() RETURNS language_handler\n  LANGUAGE c AS 'MODULE_PATHNAME';\n\nCREATE LANGUAGE pltclu\n  HANDLER pltclu_call_handler;\n\nCOMMENT ON LANGUAGE pltclu IS 'PL/TclU untrusted procedural language';","paragraphs":["This extension is shipped with the source. Its presence does not establish that the language or external runtime is installed."],"title":"Installation definition from the matching source archive"}],"tables":[]}},"RequestedLocale":"zh-Hans","Fallback":true,"Versions":["10","11","12","13","14","15","16","17","18","19","20"],"Locales":["en"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
