agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
From: Fujii Masao <fujii@postgresql.org>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Validate subscription conninfo on owner change
Date: Thu, 23 Jul 2026 10:27:14 +0000
Message-ID: <E1wmqe2-00000000QHY-3YI4@gemulon.postgresql.org> (raw)

Validate subscription conninfo on owner change

For subscriptions using SERVER, changing the owner can change the
effective connection string. However, ALTER SUBSCRIPTION ... OWNER TO
did not validate the generated conninfo for the new owner.

As a result, ownership could be transferred to a non-superuser whose
generated connection string did not satisfy password_required=true.
The ownership change succeeded, but the subscription would fail later
when the worker or another command tried to connect.

Fix this by making ALTER SUBSCRIPTION ... OWNER TO validate the new
owner's generated conninfo with walrcv_check_conninfo().

Backpatch to v19, where SERVER subscriptions were introduced.

Author: Fujii Masao <masao.fujii@gmail.com>
Reviewed-by: Yuanchao Zhang <145zhangyc@gmail.com>
Reviewed-by: Hayato Kuroda <kuroda.hayato@fujitsu.com>
Discussion: https://postgr.es/m/CAHGQGwFGa6+wWVgUmZPFwN=fBY59mYPkMK3=TxT=Pv5C1mNNRQ@mail.gmail.com
Backpatch-through: 19

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/1c9c35890421e96a91129b51f2c6446a6d95af95

Modified Files
--------------
doc/src/sgml/ref/alter_subscription.sgml   |  7 +++++++
src/backend/commands/subscriptioncmds.c    | 14 ++++++++++++--
src/test/regress/expected/subscription.out | 17 +++++++++++++++++
src/test/regress/regress.c                 |  9 +++++++++
src/test/regress/sql/subscription.sql      | 16 ++++++++++++++++
5 files changed, 61 insertions(+), 2 deletions(-)



view thread (2+ messages)  latest in thread

Message-ID: <E1wmqe2-00000000QHY-3YI4@gemulon.postgresql.org>
Permalink:  ../E1wmqe2-00000000QHY-3YI4@gemulon.postgresql.org/
Also on:    postgresql.org/message-id/E1wmqe2-00000000QHY-3YI4@gemulon.postgresql.org

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-committers@postgresql.org
  Cc: fujii@postgresql.org, pgsql-committers@lists.postgresql.org
  Subject: Re: pgsql: Validate subscription conninfo on owner change
  In-Reply-To: <E1wmqe2-00000000QHY-3YI4@gemulon.postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox