pg.ddx.io  pgsql-general@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Nathan Bossart <nathandbossart@gmail.com>
To: Jeff Davis <pgsql@j-davis.com>
Cc: Tom Lane <tgl@sss.pgh.pa.us>
Cc: Ayush Vatsa <ayushvatsa1810@gmail.com>
Cc: Robert Haas <robertmhaas@gmail.com>
Cc: David G. Johnston <david.g.johnston@gmail.com>
Cc: PostgreSQL Hackers <pgsql-hackers@postgresql.org>
Subject: Re: Clarification on Role Access Rights to Table Indexes
Date: Fri, 10 Oct 2025 11:26:08 -0500
Message-ID: <aOkzoH-pXdBr0ewf@nathan> (raw)
In-Reply-To: <aOgmi6avE6qMw_6t@nathan>
References: <Z8zwVmGzXyDdkAXj@nathan>
	<279947.1741535285@sss.pgh.pa.us>
	<Z88CB-vDehJ9rW8u@nathan>
	<aNQVIVKarUipPcnW@nathan>
	<3432170.1758730414@sss.pgh.pa.us>
	<aNQhuRQfD3PlpeuT@nathan>
	<8af53c6e8992aa706e63aafe60a3bcf100b524d1.camel@j-davis.com>
	<7b0e2774cdcc8f522ac82f64a8d7266f353a5094.camel@j-davis.com>
	<aOfXNAFkj_EFm-8q@nathan>
	<aOgmi6avE6qMw_6t@nathan>

On Thu, Oct 09, 2025 at 04:18:03PM -0500, Nathan Bossart wrote:
> There's a similar pattern in get_rel_from_relname() in dblink.c, which also
> seems to only be used with an AccessShareLock (like pg_prewarm).  My best
> guess from reading lots of code, commit messages, and old e-mails in the
> archives is that the original check-privileges-before-locking work was
> never completed.

I added an 0004 that changes dblink to use RangeVarGetRelidExtended().

> I'm currently leaning towards continuing with v4 of the patch set.  0001
> and 0003 are a little weird in that a concurrent change could lead to a
> "could not find parent table" ERROR, but IIUC that is an extremely remote
> possibility.

After sleeping on it, I still think this is the right call.  In any case,
I've spent way too much time on this stuff, so I plan to commit the
attached soon.

-- 
nathan


Attachments:

  [text/plain] v5-0001-fix-priv-checks-in-stats-code.patch (0B, ../aOkzoH-pXdBr0ewf@nathan/2-v5-0001-fix-priv-checks-in-stats-code.patch)
  download

view thread (53+ messages)  latest in thread

Message-ID: <aOkzoH-pXdBr0ewf@nathan>
Permalink:  ../aOkzoH-pXdBr0ewf@nathan/
Also on:    postgresql.org/message-id/aOkzoH-pXdBr0ewf@nathan

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-general@postgresql.org
  Cc: nathandbossart@gmail.com, pgsql@j-davis.com, tgl@sss.pgh.pa.us, ayushvatsa1810@gmail.com, robertmhaas@gmail.com, david.g.johnston@gmail.com, pgsql-hackers@postgresql.org
  Subject: Re: Clarification on Role Access Rights to Table Indexes
  In-Reply-To: <aOkzoH-pXdBr0ewf@nathan>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox