pg.ddx.io  pgsql-hackers@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Bertrand Drouvot <bertranddrouvot.pg@gmail.com>
To: Jeff Davis <pgsql@j-davis.com>
Cc: Heikki Linnakangas <hlinnaka@iki.fi>
Cc: Robert Haas <robertmhaas@gmail.com>
Cc: Roman Eskin <r.eskin@arenadata.io>
Cc: Michael Paquier <michael@paquier.xyz>
Cc: Alexander Lakhin <exclusion@gmail.com>
Cc: pgsql-hackers@lists.postgresql.org, Tom Lane <tgl@sss.pgh.pa.us>
Subject: Re: Avoid orphaned objects dependencies, take 3
Date: Wed, 17 Jun 2026 05:44:47 +0000
Message-ID: <ajI0Tz9dIJvLGHNY@bdtpg> (raw)
In-Reply-To: <ac52a6aa6be9ccf5cf43c44d009b6e2aa7e2c93d.camel@j-davis.com>
References: <02e28438bd448ff4ee8f6fd78e6b74e657172d73.camel@j-davis.com>
	<aiLKkTC6QBt8i35P@bdtpg>
	<71eb9a8835a28165939da567a9d649fe6d21bfa7.camel@j-davis.com>
	<aie26jMSoEMrHLaI@bdtpg>
	<0fc145b9b5cf3f59207cf4ca60270448a2891c46.camel@j-davis.com>
	<ailZCCmS0bGlNBfe@bdtpg>
	<ail/6I6mcitovsUo@bdtpg>
	<a9eba27eeceebe751490951f0cf631906d4ffd75.camel@j-davis.com>
	<ajEg7PrJYWnmB6zk@bdtpg>
	<ac52a6aa6be9ccf5cf43c44d009b6e2aa7e2c93d.camel@j-davis.com>

Hi,

On Tue, Jun 16, 2026 at 12:14:12PM -0700, Jeff Davis wrote:
> On Tue, 2026-06-16 at 10:09 +0000, Bertrand Drouvot wrote:
> > 0002: fixes it by moving aclcheck_track_record() to after the
> > permission check
> > succeeds in object_aclcheck_ext() and pg_class_aclcheck_ext().
> > Indeed, there is
> > no need to track failed permission checks.
> 
> IIUC, this is necessary for correctness. If an ACL failure doesn't
> cause a transaction abort, then there's a danger that we cause the
> transaction to fail that should have succeeded.

Exactly, because we'd recheck an "harmless" failed ACL check and then produce
an error.

> So the ACL tracking needs to be precise: we can't track an ACL check
> unless a failure always causes transaction abort; and we must track an
> ACL check if it would cause a transaction abort. Right?

I would say: we just need to track (and recheck) ACL checks that succeeded.

I think that there is no reason to recheck (and so to record) a failed ACL as what
we are dealing with here is the TOCTOU window. Re-checking a failed ACL check would
handle cases when a GRANT has been given during the TOCTOU window which is not
useful (for our protection goal) compared to re-checking a REVOKE during the
TOCTOU window (as the latter would record a dependency on an object we don't have
permission on).

Doing so, as proposed in 0002, allows us to fix the "re-check a harmless failed
ACL bug" (demonstrated by the added test) and still protect us for REVOKE during
the TOCTOU window.

Thoughts?

Regards,

-- 
Bertrand Drouvot
PostgreSQL Contributors Team
RDS Open Source Databases
Amazon Web Services: https://aws.amazon.com





view thread (93+ messages)  latest in thread

Message-ID: <ajI0Tz9dIJvLGHNY@bdtpg>
Permalink:  ../ajI0Tz9dIJvLGHNY@bdtpg/
Also on:    postgresql.org/message-id/ajI0Tz9dIJvLGHNY@bdtpg

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-hackers@postgresql.org
  Cc: bertranddrouvot.pg@gmail.com, pgsql@j-davis.com, hlinnaka@iki.fi, robertmhaas@gmail.com, r.eskin@arenadata.io, michael@paquier.xyz, exclusion@gmail.com, tgl@sss.pgh.pa.us
  Subject: Re: Avoid orphaned objects dependencies, take 3
  In-Reply-To: <ajI0Tz9dIJvLGHNY@bdtpg>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox