pg.ddx.io  pgsql-bugs@postgresql.org mailing list archive  
help / color / mirror / Atom feed
BUG #19740: `has_language_privilege` returns TRUE for a nonexistent language OID when the user is a superuser
2+ messages / 2 participants
[nested] [flat]

* BUG #19740: `has_language_privilege` returns TRUE for a nonexistent language OID when the user is a superuser
@ 2026-10-02 22:38 PG Bug reporting form <noreply@postgresql.org>
  2026-10-04 13:39 ` Re: BUG #19740: `has_language_privilege` returns TRUE for a nonexistent language OID when the user is a superuser Laurenz Albe <laurenz.albe@cybertec.at>
  0 siblings, 1 reply; 2+ messages in thread

From: PG Bug reporting form @ 2026-10-02 22:38 UTC (permalink / raw)
  To: pgsql-bugs@lists.postgresql.org; +Cc: theshallow27@gmail.com

The following bug has been logged on the website:

Bug reference:      19740
Logged by:          Shallow
Email address:      theshallow27@gmail.com
PostgreSQL version: 18.6
Operating system:   Linux
Description:        

For a nonexistent language OID, the implicit-current-user form returns TRUE
when the current user is a superuser. An explicit non-superuser role returns
NULL for the same missing OID. This makes the result depend on the role's
superuser status even though the referenced language does not exist.

**Reproduction:** Run as the default `postgres` superuser:

```sql
SELECT NOT EXISTS (SELECT FROM pg_language WHERE oid = 0),
       has_language_privilege(0::oid, 'USAGE'),
       has_language_privilege('pg_monitor', 0::oid, 'USAGE');
```

**Actual result:** `true | true | NULL`.

**Expected result:** The privilege inquiry should return NULL for the
missing
language OID in both forms, matching the function's missing-object handling
for non-superuser roles.








^ permalink  raw  reply  [nested|flat] 2+ messages in thread

* Re: BUG #19740: `has_language_privilege` returns TRUE for a nonexistent language OID when the user is a superuser
  2026-10-02 22:38 BUG #19740: `has_language_privilege` returns TRUE for a nonexistent language OID when the user is a superuser PG Bug reporting form <noreply@postgresql.org>
@ 2026-10-04 13:39 ` Laurenz Albe <laurenz.albe@cybertec.at>
  0 siblings, 0 replies; 2+ messages in thread

From: Laurenz Albe @ 2026-10-04 13:39 UTC (permalink / raw)
  To: theshallow27@gmail.com; pgsql-bugs@lists.postgresql.org

On Fri, 2026-10-02 at 22:38 +0000, PG Bug reporting form wrote:
> ostgreSQL version: 18.6
> 
> For a nonexistent language OID, the implicit-current-user form returns TRUE
> when the current user is a superuser. An explicit non-superuser role returns
> NULL for the same missing OID. This makes the result depend on the role's
> superuser status even though the referenced language does not exist.
> 
> **Reproduction:** Run as the default `postgres` superuser:
> 
> ```sql
> SELECT NOT EXISTS (SELECT FROM pg_language WHERE oid = 0),
>        has_language_privilege(0::oid, 'USAGE'),
>        has_language_privilege('pg_monitor', 0::oid, 'USAGE');
> ```
> 
> **Actual result:** `true | true | NULL`.
> 
> **Expected result:** The privilege inquiry should return NULL for the
> missing
> language OID in both forms, matching the function's missing-object handling
> for non-superuser roles.

I agree that that is not so great.  Since this behavior is in the function
object_aclcheck_ext(), which is used by all the has_*_privilege functions,
the same oddity affects all those functions.

I think that would be easy to change, but I wonder if it is a good idea.
That bug hardly hurts: has_language_privilege() is typically not what you
use to find out if a procedural language exists or not.
And perhaps there is a misguided script somewhere out there that would
suddenly start to misbehave if a superuser no longer is reported as having
all privileges on non-existing objects.

Is it a real problem for you?

Yours,
Laurenz Albe






^ permalink  raw  reply  [nested|flat] 2+ messages in thread


end of thread, other threads:[~2026-10-04 13:39 UTC | newest]

Thread overview: 2+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2026-10-02 22:38 BUG #19740: `has_language_privilege` returns TRUE for a nonexistent language OID when the user is a superuser PG Bug reporting form <noreply@postgresql.org>
2026-10-04 13:39 ` Laurenz Albe <laurenz.albe@cybertec.at>

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox