agora inbox for pgsql-committers@postgresql.orghelp / color / mirror / Atom feed
pgsql: Ensure ExecutorCheckPerms_hook is called from RI fast path 2+ messages / 1 participants [nested] [flat]
* pgsql: Ensure ExecutorCheckPerms_hook is called from RI fast path @ 2026-09-24 10:32 Amit Langote <amitlan@postgresql.org> 0 siblings, 0 replies; 2+ messages in thread From: Amit Langote @ 2026-09-24 10:32 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Ensure ExecutorCheckPerms_hook is called from RI fast path The fast path's ri_CheckPermissions() called ExecCheckOneRelPerms() directly, so ExecutorCheckPerms_hook never saw the referenced-table access that the SPI path's query exposed to it via ExecutorStart(). Modules such as sepgsql that rely on this hook therefore lost control over FK checks against referenced tables that go through the fast path. So, build a one-entry range table and permission-info list and call ExecCheckPermissions(). The hook now sees the same relation and requiredPerms as before, once per check that goes through the fast path. This also drops the shortcut that skipped the column-level check when table-level privileges sufficed, since the hook must run regardless. While at it, drop the explicit frees in the old code, because both callers run ri_CheckPermissions() in a per-tuple context that is reset after each check, so they were redundant. Reported-by: Noah Misch <noah@leadboat.com> Discussion: https://postgr.es/m/20260705210533.ee.noahmisch%40microsoft.com Backpatch-through: 19 Branch ------ REL_19_STABLE Details ------- https://git.postgresql.org/pg/commitdiff/5aeb36f3273c768831284082f85b63066e84f16d Modified Files -------------- src/backend/utils/adt/ri_triggers.c | 30 +++++++++++++++--------------- 1 file changed, 15 insertions(+), 15 deletions(-) ^ permalink raw reply [nested|flat] 2+ messages in thread
* pgsql: Ensure ExecutorCheckPerms_hook is called from RI fast path @ 2026-09-24 10:33 Amit Langote <amitlan@postgresql.org> 0 siblings, 0 replies; 2+ messages in thread From: Amit Langote @ 2026-09-24 10:33 UTC (permalink / raw) To: pgsql-committers@lists.postgresql.org Ensure ExecutorCheckPerms_hook is called from RI fast path The fast path's ri_CheckPermissions() called ExecCheckOneRelPerms() directly, so ExecutorCheckPerms_hook never saw the referenced-table access that the SPI path's query exposed to it via ExecutorStart(). Modules such as sepgsql that rely on this hook therefore lost control over FK checks against referenced tables that go through the fast path. So, build a one-entry range table and permission-info list and call ExecCheckPermissions(). The hook now sees the same relation and requiredPerms as before, once per check that goes through the fast path. This also drops the shortcut that skipped the column-level check when table-level privileges sufficed, since the hook must run regardless. While at it, drop the explicit frees in the old code, because both callers run ri_CheckPermissions() in a per-tuple context that is reset after each check, so they were redundant. Reported-by: Noah Misch <noah@leadboat.com> Discussion: https://postgr.es/m/20260705210533.ee.noahmisch%40microsoft.com Backpatch-through: 19 Branch ------ master Details ------- https://git.postgresql.org/pg/commitdiff/2cdd1950f28cf1567ebf1c747422691b09041b30 Modified Files -------------- src/backend/utils/adt/ri_triggers.c | 30 +++++++++++++++--------------- 1 file changed, 15 insertions(+), 15 deletions(-) ^ permalink raw reply [nested|flat] 2+ messages in thread
end of thread, other threads:[~2026-09-24 10:33 UTC | newest] Thread overview: 2+ messages (download: mbox mbox.gz follow: Atom feed) -- links below jump to the message on this page -- 2026-09-24 10:32 pgsql: Ensure ExecutorCheckPerms_hook is called from RI fast path Amit Langote <amitlan@postgresql.org> 2026-09-24 10:33 pgsql: Ensure ExecutorCheckPerms_hook is called from RI fast path Amit Langote <amitlan@postgresql.org>
This inbox is served by agora; see mirroring instructions for how to clone and mirror all data and code used for this inbox