agora inbox for pgsql-committers@postgresql.org  
help / color / mirror / Atom feed
pgsql: Fix RI fast-path permission checks
2+ messages / 1 participants
[nested] [flat]

* pgsql: Fix RI fast-path permission checks
@ 2026-09-19 02:05  Amit Langote <amitlan@postgresql.org>
  0 siblings, 0 replies; 2+ messages in thread

From: Amit Langote @ 2026-09-19 02:05 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix RI fast-path permission checks

The fast path required table-level SELECT on the referenced table,
rejecting checks that the SPI path allows with column-level grants.
It also omitted the UPDATE privilege required by FOR KEY SHARE.

When table privileges do not suffice, use ExecCheckOneRelPerms() with
the referenced key columns as selectedCols and an empty updatedCols.
This accepts SELECT on all referenced columns and UPDATE on any column,
the same privileges the executor would require for the SELECT ... FOR
KEY SHARE the SPI path runs.  Keep the table-privilege check as a
shortcut that avoids constructing a column bitmap in the usual case.

Add missing regression test coverage for the fixed cases.

Reported-by: Nikolay Samokhvalov <nik@postgres.ai>
Author: Nikolay Samokhvalov <nik@postgres.ai>
Co-authored-by: Amit Langote <amitlangote09@gmail.com>
Discussion: https://www.postgr.es/m/CAM527d9BgPjeOOYmbCBTd57R145qHCk-dzw9qNq%2BnOrDq1j__A%40mail.gmail.com
Backpatch-through: 19

Branch
------
REL_19_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/2fc654e1133e987319d54661f0f7ee2babb33488

Modified Files
--------------
src/backend/utils/adt/ri_triggers.c       | 45 +++++++++++++++++------
src/test/regress/expected/foreign_key.out | 55 ++++++++++++++++++++++++++--
src/test/regress/sql/foreign_key.sql      | 59 +++++++++++++++++++++++++++++--
3 files changed, 145 insertions(+), 14 deletions(-)



^ permalink  raw  reply  [nested|flat] 2+ messages in thread

* pgsql: Fix RI fast-path permission checks
@ 2026-09-19 02:06  Amit Langote <amitlan@postgresql.org>
  0 siblings, 0 replies; 2+ messages in thread

From: Amit Langote @ 2026-09-19 02:06 UTC (permalink / raw)
  To: pgsql-committers@lists.postgresql.org

Fix RI fast-path permission checks

The fast path required table-level SELECT on the referenced table,
rejecting checks that the SPI path allows with column-level grants.
It also omitted the UPDATE privilege required by FOR KEY SHARE.

When table privileges do not suffice, use ExecCheckOneRelPerms() with
the referenced key columns as selectedCols and an empty updatedCols.
This accepts SELECT on all referenced columns and UPDATE on any column,
the same privileges the executor would require for the SELECT ... FOR
KEY SHARE the SPI path runs.  Keep the table-privilege check as a
shortcut that avoids constructing a column bitmap in the usual case.

Add missing regression test coverage for the fixed cases.

Reported-by: Nikolay Samokhvalov <nik@postgres.ai>
Author: Nikolay Samokhvalov <nik@postgres.ai>
Co-authored-by: Amit Langote <amitlangote09@gmail.com>
Discussion: https://www.postgr.es/m/CAM527d9BgPjeOOYmbCBTd57R145qHCk-dzw9qNq%2BnOrDq1j__A%40mail.gmail.com
Backpatch-through: 19

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/2c45694a240e89c3f7d848d433f78e394521b6d6

Modified Files
--------------
src/backend/utils/adt/ri_triggers.c       | 47 ++++++++++++++++++------
src/test/regress/expected/foreign_key.out | 55 ++++++++++++++++++++++++++--
src/test/regress/sql/foreign_key.sql      | 59 +++++++++++++++++++++++++++++--
3 files changed, 146 insertions(+), 15 deletions(-)



^ permalink  raw  reply  [nested|flat] 2+ messages in thread


end of thread, other threads:[~2026-09-19 02:06 UTC | newest]

Thread overview: 2+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2026-09-19 02:05 pgsql: Fix RI fast-path permission checks Amit Langote <amitlan@postgresql.org>
2026-09-19 02:06 pgsql: Fix RI fast-path permission checks Amit Langote <amitlan@postgresql.org>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox