pg.ddx.io  pgsql-committers@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Álvaro Herrera <alvherre@kurilemu.de>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Tighten ACL check in repack_is_permitted_for_relation()
Date: Wed, 19 Aug 2026 10:27:16 +0000
Message-ID: <E1wwdVr-00000001CRo-1deh@gemulon.postgresql.org> (raw)

Tighten ACL check in repack_is_permitted_for_relation()

repack_is_permitted_for_relation() uses pg_class_aclcheck_ext()
to silently skip a concurrently-dropped relation.  That's wrong
for a caller that may already hold a lock on the relation whose
ACL is checked, where missing a relation is not fine, and it
makes the single-relation REPACK and CLUSTER cases more brittle.
So only detect a missing relation where that's expected,
following the fix for vacuum_is_permitted_for_relation() in
commit 824d5f6241ea.

The new already_locked behavior is limited to get_tables_to_repack()
and get_tables_to_repack_partitioned().  All other callers of
repack_is_permitted_for_relation() hold a lock on the relation
that prevents it from being concurrently dropped, so this commit
also adds an assertion to that effect.

While at it, update the comment in RangeVarCallbackMaintainsTable to
also mention REPACK.

Author: Bharath Rupireddy <bharath.rupireddyforpostgres@gmail.com>
Backpatch-through: 19
Discussion: https://www.postgresql.org/message-id/CALj2ACX3pyuRS8%2B%2B6L20cJUMRTf_qbbVp69J1btJ3y6%3D77e5gw%40ma...

Branch
------
REL_19_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/9bb8e16bd53e2c8a822bf13832c4dcb3905a34e5

Modified Files
--------------
src/backend/commands/repack.c    | 35 ++++++++++++++++++++++++-----------
src/backend/commands/tablecmds.c |  2 +-
2 files changed, 25 insertions(+), 12 deletions(-)



view thread (2+ messages)

Message-ID: <E1wwdVr-00000001CRo-1deh@gemulon.postgresql.org>
Permalink:  ../E1wwdVr-00000001CRo-1deh@gemulon.postgresql.org/
Also on:    postgresql.org/message-id/E1wwdVr-00000001CRo-1deh@gemulon.postgresql.org

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-committers@postgresql.org
  Cc: alvherre@kurilemu.de, pgsql-committers@lists.postgresql.org
  Subject: Re: pgsql: Tighten ACL check in repack_is_permitted_for_relation()
  In-Reply-To: <E1wwdVr-00000001CRo-1deh@gemulon.postgresql.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox