agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
From: Noah Misch <noah@leadboat.com>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Add an output_plugin_libraries GUC to bless trusted output plugi
Date: Mon, 10 Aug 2026 13:41:29 +0000
Message-ID: <E1wtQFt-00000000yGy-2lbh@gemulon.postgresql.org> (raw)

Add an output_plugin_libraries GUC to bless trusted output plugins

REPLICATION users were not previously subject to restrictions on output
plugin paths, so they were able to bypass LOAD-time protections during
logical decoding. Unfortunately, adding the standard LOAD restrictions
now would retroactively require all third-party output plugins to be
installed under the $libdir/plugins directory. This would prevent the
use of dynamic_library_path, introduce a wire incompatibility for
clients, and require all plugin authors to check that their libraries
are safe for use by any unprivileged user; we want to avoid that.

Instead, introduce an output_plugin_libraries GUC so that DBAs can
specify the output plugins that are trusted for use in logical decoding.
For simplicity, superusers are subject to the restriction as well
(though they're free to modify the GUC at will during a session, so no
power is actually lost).

The default setting is 'pgoutput, test_decoding'. If other third-party
plugins are in use, DBAs will need to modify this parameter after they
update. Some pointers have been added to the documentation to assist
with this.

Author: Jacob Champion <jacob.champion@enterprisedb.com>
Reported-by: Vladimir Tokarev <vladimirelitokarev@gmail.com>
Reported-by: Yu Kunpeng <yu443940816@live.com>
Reviewed-by: Álvaro Herrera <alvherre@kurilemu.de>
Reviewed-by: Noah Misch <noah@leadboat.com>
Reviewed-by: Robert Haas <robertmhaas@gmail.com>
Reviewed-by: Tom Lane <tgl@sss.pgh.pa.us>
Backpatch-through: 14
Security: CVE-2026-6471

Branch
------
REL_16_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/4e1252ee56c33b8a1144b25b5803f47276662519
Author: Jacob Champion <jchampion@postgresql.org>

Modified Files
--------------
contrib/test_decoding/expected/permissions.out | 11 ++++
contrib/test_decoding/expected/slot.out        |  3 +
contrib/test_decoding/sql/permissions.sql      |  8 +++
contrib/test_decoding/sql/slot.sql             |  3 +
doc/src/sgml/config.sgml                       | 57 +++++++++++++++++++
doc/src/sgml/logical-replication.sgml          |  9 +++
src/backend/replication/logical/logical.c      | 76 +++++++++++++++++++++++++-
src/backend/utils/misc/guc_tables.c            | 12 ++++
src/backend/utils/misc/postgresql.conf.sample  |  1 +
src/bin/pg_dump/dumputils.c                    |  1 +
src/include/replication/logical.h              |  3 +
src/test/subscription/t/100_bugs.pl            | 28 +++++++++-
12 files changed, 209 insertions(+), 3 deletions(-)



view thread (5+ messages)

Message-ID: <E1wtQFt-00000000yGy-2lbh@gemulon.postgresql.org>
Permalink:  ../E1wtQFt-00000000yGy-2lbh@gemulon.postgresql.org/
Also on:    postgresql.org/message-id/E1wtQFt-00000000yGy-2lbh@gemulon.postgresql.org

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-committers@postgresql.org
  Cc: noah@leadboat.com, pgsql-committers@lists.postgresql.org
  Subject: Re: pgsql: Add an output_plugin_libraries GUC to bless trusted output plugi
  In-Reply-To: <E1wtQFt-00000000yGy-2lbh@gemulon.postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox