postgres-github.git / summary / log / commit / refs

commit    ce146621f7860d2e19c509f1466feca3bf777678
Author:   Alexander Korotkov <akorotkov@postgresql.org>
Date:     Thu May 14 09:25:19 2026 +0000

    Prevent access to other sessions' temp tables
    
    Commit b7b0f3f2724 ("Use streaming I/O in sequential scans") routed
    sequential scans through read_stream_next_buffer(), bypassing the
    RELATION_IS_OTHER_TEMP() check in ReadBufferExtended().  As a result,
    a superuser can attempt to read or modify temp tables of other
    sessions through the read-stream path.  When the query plan uses no index,
    SELECT/UPDATE/DELETE/MERGE silently see no rows / report zero affected rows,
    and COPY produces an empty output -- because the buffer manager has no
    visibility into the owning session's local buffers and silently returns
    nothing.  Any query plan that uses, for instance, a btree index
    still errors out via the existing check in ReadBufferExtended(), which
    is reached from hio.c and nbtree respectively, but this is incidental.
    
    Fix by enforcing RELATION_IS_OTHER_TEMP() at the three additional
    buffer-manager entry points:
    
    - read_stream_begin_impl() rejects the read at stream setup time,
      covering sequential and bitmap scans that go through the
      read-stream path.
    - ReadBuffer_common() becomes the canonical place for the check,
      consolidating the existing one previously kept in
      ReadBufferExtended().  All ReadBufferExtended() callers go through
      ReadBuffer_common(), so the consolidation is behavior-preserving.
    - StartReadBuffersImpl() catches direct callers of StartReadBuffers()
      that bypass both of the above.  This is currently defense-in-depth,
      but documents the contract for future code.
    
    The companion test in src/test/modules/test_misc was added in the
    preceding commit; this commit updates the assertions for SELECT,
    UPDATE, DELETE, MERGE, and COPY (which previously documented the
    bug as silent success) to expect the new error.
    
    Author: Jim Jones <jim.jones@uni-muenster.de>
    Author: Daniil Davydov <3danissimo@gmail.com>
    Co-authored-by: Alexander Korotkov <aekorotkov@gmail.com>
    Reviewed-by: Michael Paquier <michael@paquier.xyz>
    Reviewed-by: Soumya S Murali <soumyamurali.work@gmail.com>
    Reviewed-by: Tom Lane <tgl@sss.pgh.pa.us>
    Discussion: https://postgr.es/m/CAJDiXghdFcZ8%3Dnh4G69te7iRr3Q0uFyXxb3ZdG09_GTNZXwH0g%40mail.gmail.com
    Backpatch-through: 17

[parent: 1fee0e857e33]