agora inbox for pgsql-committers@postgresql.org
help / color / mirror / Atom feedFrom: Amit Langote <amitlan@postgresql.org>
To: pgsql-committers@lists.postgresql.org
Subject: pgsql: Ensure ExecutorCheckPerms_hook is called from RI fast path
Date: Thu, 24 Sep 2026 10:33:00 +0000
Message-ID: <E1x9glA-0000000138R-2DfZ@gemulon.postgresql.org> (raw)
Ensure ExecutorCheckPerms_hook is called from RI fast path
The fast path's ri_CheckPermissions() called ExecCheckOneRelPerms()
directly, so ExecutorCheckPerms_hook never saw the referenced-table
access that the SPI path's query exposed to it via ExecutorStart().
Modules such as sepgsql that rely on this hook therefore lost control
over FK checks against referenced tables that go through the fast
path.
So, build a one-entry range table and permission-info list and call
ExecCheckPermissions(). The hook now sees the same relation and
requiredPerms as before, once per check that goes through the fast
path. This also drops the shortcut that skipped the column-level
check when table-level privileges sufficed, since the hook must run
regardless. While at it, drop the explicit frees in the old code,
because both callers run ri_CheckPermissions() in a per-tuple context
that is reset after each check, so they were redundant.
Reported-by: Noah Misch <noah@leadboat.com>
Discussion: https://postgr.es/m/20260705210533.ee.noahmisch%40microsoft.com
Backpatch-through: 19
Branch
------
master
Details
-------
https://git.postgresql.org/pg/commitdiff/2cdd1950f28cf1567ebf1c747422691b09041b30
Modified Files
--------------
src/backend/utils/adt/ri_triggers.c | 30 +++++++++++++++---------------
1 file changed, 15 insertions(+), 15 deletions(-)
view thread (2+ messages)
Message-ID: <E1x9glA-0000000138R-2DfZ@gemulon.postgresql.org>
Permalink: ../E1x9glA-0000000138R-2DfZ@gemulon.postgresql.org/
Also on: postgresql.org/message-id/E1x9glA-0000000138R-2DfZ@gemulon.postgresql.org
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-committers@postgresql.org
Cc: amitlan@postgresql.org, pgsql-committers@lists.postgresql.org
Subject: Re: pgsql: Ensure ExecutorCheckPerms_hook is called from RI fast path
In-Reply-To: <E1x9glA-0000000138R-2DfZ@gemulon.postgresql.org>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox