Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wTJd3-000Ry3-0h for pgsql-hackers@arkaria.postgresql.org; Sat, 30 May 2026 13:21:29 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1wTJd1-0060GE-2R for pgsql-hackers@arkaria.postgresql.org; Sat, 30 May 2026 13:21:28 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wTJd1-0060G6-1Y for pgsql-hackers@lists.postgresql.org; Sat, 30 May 2026 13:21:27 +0000 Received: from mail-qk1-x734.google.com ([2607:f8b0:4864:20::734]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.98.2) (envelope-from ) id 1wTJcz-00000000JKe-2iQ7 for pgsql-hackers@postgresql.org; Sat, 30 May 2026 13:21:27 +0000 Received: by mail-qk1-x734.google.com with SMTP id af79cd13be357-9102e90bcbeso1493384385a.1 for ; Sat, 30 May 2026 06:21:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=dunslane-net.20251104.gappssmtp.com; s=20251104; t=1780147284; x=1780752084; darn=postgresql.org; h=content-transfer-encoding:in-reply-to:autocrypt:content-language :from:references:cc:to:subject:user-agent:mime-version:date :message-id:from:to:cc:subject:date:message-id:reply-to; bh=3ENRHWdTXIXYNVUmKAVtqohJvczjFEM/KUnXjQ5ekHo=; b=hZH5NaEg2VVCX7WTNqa4/Fn0iXrM7m+jahBIP3HxM4DlPU5AO7MFpTjpS8b0v6hY60 sT0OrVkHjb9pwMQXTFb2JyaXOQpvWvNqSaVaO7f3VKSbwhV965Sww+JZNtaeMjksrOVu aWjs195ICHu2gczc/ncBxZb1yAz1zhGilXtQpY8vk+wHhG9XMoy29As9m2AQT1qAivis GbTOzDmKvOpmCHOJbcpy7r60G9CxTkVkqNv/xFtXtPGBUEepi3Yy+whgVXYBtjhd9nB/ 9pJN5P+n6COVlpgyZ23HBUHyUZj5jic7L31Qf0xj10Ws53eGVx1ngUWXZ0eVKm1HTPZ0 qEIg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780147284; x=1780752084; h=content-transfer-encoding:in-reply-to:autocrypt:content-language :from:references:cc:to:subject:user-agent:mime-version:date :message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=3ENRHWdTXIXYNVUmKAVtqohJvczjFEM/KUnXjQ5ekHo=; b=eAzY6IliQROpzh+7/9ioHOuCeBaY/uFWs0t67zmyYXrIecUixWfcbloGv9NVSxTPFe vlA5/mUOBVQ4mLbTXnCN/YffczIv8g+098jMGYhdG1yJ57HL+dFG9MgTKBW+fbcvYrco sSoYI2XiOeSgjn/0yL2LWCoC8dhWDJZVduvb1OvPald+BK2Tspl2bLcIXJt9KEdNFfke cRWeV94E6TaG5GjUOHUlTOqO0FU3S65MCYSkVz7D6wi62amSUCgF98H+oWljAZSPZJUr yftN5rmp8whA4xipXW5G8SuWt7YNCFbGqZIipVZCNnTGYDP+K6B3sO+qaZC2R+P3QUs7 gmNg== X-Forwarded-Encrypted: i=1; AFNElJ81c+1uqMJ0ThG/j5BIR/FefwtW0wHYdcYOfzftKxIE7i5d4bdIf/zMgPgiK9r8SGF0FdPNhr8dmdPExgnU@postgresql.org X-Gm-Message-State: AOJu0YxhJkYJ5wrVO/Ue9kkQZaUgFzaZhBkLN/vdhf815a5T58XKLHxk gYYqw8RtgHB37XC8PAhg47aj29EQRxNbwPxdRTf7hLzVTPhmkxY4gptj9NMQBedyR7tHigOGvzD efxZh X-Gm-Gg: Acq92OGMhu50MUoDDyylt1vgf7P1IrKjyGnWh4id5nFM9qSrzj9yA0v25sczwwV0aCG 94XHP/oR1rymzPflYlbMBwychL01SO+UrllJq4ZjDPUq7I7x538nl7E7b4Z1ICN4ot8r0Rhz/o1 DN6G0D18/tHo2o8ldtWw3BepVFRxItd/4fdN5j7y+wKBgqgpEdosdF4/Ly2BJPJc2RQle2Jv24N CPbIsDcyzXua/sILfSUAWeTBbp5z8r2ve2BgAiP1Sn1qhAz5+WnfDRTzHPleEzWC/kSzjPa3pIG TKTCNr1QyZD53fwzIUa647QQOpcHSil4u2NiC5/VYXdW+i4czipEb+yqzI3sT2KBsoLfSpM19Sl x+j0mFIIdn2uEDM2vZcwaKDXLkcpAP++oe5xi+apAZovRzX89f0p9JrFaWs+eua9FQCyrtWDF7k alHfQh1zpGPxzL/4XrQ2etWo12AFsa4wg2UVVscvqAXhOFywxzsIo= X-Received: by 2002:a05:620a:438a:b0:914:ee1a:fc15 with SMTP id af79cd13be357-9153d9f5f20mr560350785a.29.1780147283881; Sat, 30 May 2026 06:21:23 -0700 (PDT) Received: from ?IPV6:2605:a601:a6b0:500::1cb? ([2605:a601:a6b0:500::1cb]) by smtp.googlemail.com with ESMTPSA id af79cd13be357-9153244c085sm493941885a.6.2026.05.30.06.21.23 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Sat, 30 May 2026 06:21:23 -0700 (PDT) Message-ID: <5ce9de1e-0b89-4c62-ab3e-9e4513ba69b7@dunslane.net> Date: Sat, 30 May 2026 09:21:21 -0400 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: Avoid leaking system path from pg_available_extensions To: Matheus Alcantara , Chao Li Cc: Jim Jones , PostgreSQL-development References: <357C774A-ECE9-4455-B641-315205D4D9A1@gmail.com> <96203151-6929-4d88-85a0-d552ee258a24@gmail.com> <87c8f8ac-614b-4679-afc7-f591b76c8ff7@gmail.com> <83AF10FE-7655-43DF-A302-3CAC796B572F@gmail.com> From: Andrew Dunstan Content-Language: en-US Autocrypt: addr=andrew@dunslane.net; keydata= xsBNBE7KWFkBCAClridxur2AIc7eW2AR7izbfp3EnNefie2HbLF0izW5Ik5UjX2HBXBx4syI gY6b0ugohXrr274+baoAlvSbq6cAoQuEVrk5IZFzt20b1Xkx65FwGSEj526yiKLocqkJceSq Xr9xcA5SGY+FZv441chh5SU92v4q6z+6LPpoHOh97ptAVXZYNTtU0LevyvD5lja0TzbvJm6C eFXitJfnm1pLEr0DGJCR/iUOl/N62Kh4855zZC7NHIjQHPOvV5Stz/l5ilDhvGVk+xkXFPys SjZoUr1rXhYLpiyi5sR0X9FHXT0KnGuz1F5ERO7ZTLSSQ6fJwPj6gOk9K+vvoKvoeql5ABEB AAHNJEFuZHJldyBEdW5zdGFuIDxhbmRyZXdAZHVuc2xhbmUubmV0PsLAlwQTAQgAQQIbAwIX gAIZAQULCQgHAwUVCgkICwUWAgMBAAIeBRYhBOQ+WEYd/Hy/RGkVpZn6f8tZ/DuBBQJoGNGd BQkdEO8nAAoJEJn6f8tZ/DuBq74H/jkTR4Zi3stbw+xC7v2u3QozssK7MYPL2AsVfh7OealS h182fiWXpfvmmAB7WUHbhk9GC2RAOnHI/2d2jgKaMLAHsGYOT0YopTVIwRY43fCw/mK67yxc wmDcX+zyKfLaivNbf5A7QPLNwda98bEAMSJ8Sn652Uc6cA8t3uKGsVzbRBQOoYzjgvBCfSrE 9ql3PDNg0l4BfAqabd2f70ZUm9VAMEPrgv/v2xI7M2XiL4g5BVmqLCOwxLM8RMCotCuoweUr VO43DeBCIDwLxotMJKvGWDjBzQYlU1NPUAtNcz/gN9ITUe1VUGjyvGj4u1lxBOcQQUw7l1+T 5moZ4iZxXzvOwE0ETspYWQEIANGc4zQULOxhbqO2dyD51YhqCNRmm9oKWaqf+wmW4tpDe/VV cxAnNizd4LWCHfzpb5cHAtGkOPePMfzWVf6nvdF7d3eglbtf59+zG7O7llV0xSSoFiieQBsr GvqDInXYX/4mRRXMtyhM353/tixC9RWLs1oofyYmCPPXXY7h9R7en3B8BoVrRFcdzlIY/NFN hFGW/9dkEiGjgna2Rk6e15kln4ZvFBWUg23p93w/pqXcxY6+k/8TEk+C4R+M6w7o2PLGOjdZ +kPiUcw5H85zf/yZJwQXzisXaNduwWB6Vads9YC9dj6kPR1c4VGRqAaYL++LAEOqrlvm2Tvq QqZRtnEAEQEAAcLAfAQYAQgAJgIbDBYhBOQ+WEYd/Hy/RGkVpZn6f8tZ/DuBBQJoGNI2BQkd EODdAAoJEJn6f8tZ/DuBfw0IAKTsfD40teP/pp+bsLLMSxPXUYrrprTj7WFB5v61p6dkpSr/ qXmMlyahdxQFaPmfVgVirB1Vk/kHiWNnnGjfUV9nB2Zg9LI0Xb9/ts3LsUiRWXzG3tkMY6XL vsVOxW4XFRND9l2q+WW93aZ1DZl+fqWfYgMvsusFRhmGFOKTRfKPta2Pkv+AhA24N4+PrR5p bU4k2MO8PAGiK8eaYKGFG1bHKuAvoDoF7WXJ3FHxuWqLnKEt4dfOLm5pAe3zq1Lt6q8azT9i QWGpSAK5vQUWQHBHpiDjdPeqKZ6HiAXIIKfSmb+jrvXBqoP+D6/K7rUjG2aXiRtTIAXms9sm VRu7cmw= In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On 2026-05-26 Tu 9:29 AM, Matheus Alcantara wrote: > On 26/05/26 04:14, Chao Li wrote: >> >> >>> On May 22, 2026, at 23:40, Matheus Alcantara >>> wrote: >>> >>> On 22/05/26 04:25, Jim Jones wrote: >>>> On 21/05/2026 17:12, Matheus Alcantara wrote: >>>>> I've reproduced the issue and the fix looks correct to me. >>>> same here, +1 >>> >>> Thank you for also testing. >>> >>>> I was wondering if creating a constant for it would be, stylistically >>>> speaking, a cleaner solution. For instance: >>>> #define EXTENSION_SYSTEM_MACRO  "$system" >>>> I realize that it's used only inside >>>> get_extension_control_directories() >>>> but since it is even mentioned in the docs, I guess it wouldn't be >>>> a bad >>>> idea. >>> >>> I'm not against it but I don't think that it's necessary since as >>> you mention, only get_extension_control_directories() use. >>> >> >> In theory, I’m not against the idea either. In practice, there are >> many hard-coded strings in the source tree, and I’m not sure where >> the right place would be to define this macro. >> >> Since this string is only used in >> get_extension_control_directories(), and now it is used three times, >> I defined it at the beginning of the function and undefined it at the >> end. Let’s see if there are any objections to that. >> >> Please see the attached v2. >> > > We have such pattern in other parts of the codebase (e.g > pg_resetwal.c), so it works for me. > > Thanks for the patch. > > Pushed. cheers andrew -- Andrew Dunstan EDB: https://www.enterprisedb.com