Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1x8xLJ-00000001eX9-2pfr for pgsql-hackers@arkaria.postgresql.org; Tue, 22 Sep 2026 10:03:17 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.98.2) (envelope-from ) id 1x8xLI-0000000F5Yn-2usp for pgsql-hackers@arkaria.postgresql.org; Tue, 22 Sep 2026 10:03:16 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1x8xLI-0000000F5Ye-1hXV for pgsql-hackers@lists.postgresql.org; Tue, 22 Sep 2026 10:03:16 +0000 Received: from mail-wm2-x10.google.com ([2a00:1450:4864:31::10]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.98.2) (envelope-from ) id 1x8xLF-00000000g54-3VGp for pgsql-hackers@lists.postgresql.org; Tue, 22 Sep 2026 10:03:16 +0000 Received: by mail-wm2-x10.google.com with SMTP id 5b1f17b1804b1-49d1ca5b0d6so29247005e9.0 for ; Tue, 22 Sep 2026 03:03:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790071392; x=1790676192; darn=lists.postgresql.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=gMJINodVmntYXUwFLyqtJkW1VO5nCZwaVpx8HnKCTHw=; b=IXvfYOkZK5HA9Q+OIMh6w9Qst5RN2R2aPC7QD26cSuTS/LpXzQKQe1nJN02BRmDJoN hKCnsn4NLCiOoANWx2K3ktNsMbBsx30OiEeweyPxKTohQ9xkl9zo0YZlRj1WZ1yrMPwB N4j9k5AUkvFgIdqfafreMff1ePKzfNG1mqsrtdQ7hN4L3zj0gZ2qk0wMZB+okF2S5rke fcZI6JFg1fV+kfMIX2jOx0iZFtH4NGvaCnybsDyf99PUh+f0Tv0VJitLSLC+tD2lim0d AeYEGrjf1bMk8C+ycs5Ofbz3cd/YZDWHf+sr2WK23qKzVu6Z8DXXmN93vzlzmNrk5pK8 l4EQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790071392; x=1790676192; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=gMJINodVmntYXUwFLyqtJkW1VO5nCZwaVpx8HnKCTHw=; b=zqMvCkbp4n0ytmftF2DnrAR/3CasRRm8haLQShc6NE+3C+LIi5VTPi6pa6tfTZ+HBX IswUZDzWglHUAYbH7kwO2CTwMsMrKqB4yuGMmGfqaG1OrIGn2Lvdq/DWFK1wutbDFvMd ZmBr4v/tZQgUomlKx3mVkSJO6zkwBK/jCbUwd6zsORnIhWsdsCI25o5g6K7idKoHRGo4 QunWDM1684VKPHVdzLEDuVY2q+rRHJUD/2THIOOOIsGDLfujzNBL1Yvm5qUjRCV7jv80 TNm9r/XO/3fJMjCfJPrNXUpaf49JGElrPOczi3poWVaZawhxAx3bCVirglsuahF+x9Ty ElQQ== X-Forwarded-Encrypted: i=1; AKwUvBzhjvPgvXp/O3G9vrfpANmNWdb0DulvW0PT/eSHglJgwNNprf/KCvStdb2gnIsIGJ+clHdb8CgGVlGc8J1k@lists.postgresql.org X-Gm-Message-State: AFuF++nitTAVWoqOZUu8XRuNSu7l+6LBOqf+AsSAw8UYaF0Li2i9Bi6x gJ7HRyIj7XRVCG6LyLtuOecAtluQXhNQtzDhEOnDiqRQAEWh6vxztwdi X-Gm-Gg: AYBFou1Jf3dFX8sYTBpKYldItVLvPdwaUczhgntQj04nlZ39ajIQ/8ziikyV9o/K2yx GxZJkuEbsa+AsCT5nVjcz9SGSEwkulY0zRQXEx1dn/suQXmMP1PYLVoEDdFY6vG0hQurWe0ECif oV2gloeoYqBS0RBljKJPVbny3skcjaDi1J3BBtlGTIFNocvw2F+QKKKzlHTPZTNPgDuO50UsgoQ acJe2CdfH2cQaWoCKG5zRJDtPckhpQtEImWD6P/bVLy+0y2UpnSnml4+jVXtS5YlbTfgnGYQaCU zFxeFIZrVT1pMNKj1UI1yIgvCBRb/9oHTh/tLMzt9GbPfRNl+p2Qx1PTTygrjDfCJ8YcJCPinOb ek1akP92oFeeILZMoXSXyDpUKVjl0vTjoAKqjWRalJ3ZJojuWNCAHMfgiPLXnZZs6z+DSS2mVlo vBFXalT6T7ppgJx9Li65WD8sG63RzrYm3+6XH6ctE0W59uw3OJzhcVZno96wcoI44I+zXADJmRA taj5BE04OMKKxNTZw5JdeWdBv3Bq9OTgWyjb0ERQDjL7h/2rpHmtSDvdg== X-Received: by 2002:a05:600c:698c:b0:49d:462:6eda with SMTP id 5b1f17b1804b1-49fc5743c19mr174048935e9.28.1790071392404; Tue, 22 Sep 2026 03:03:12 -0700 (PDT) Received: from bdtpg (ec2-15-237-197-144.eu-west-3.compute.amazonaws.com. [15.237.197.144]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fd8cd8dd6sm61410295e9.11.2026.09.22.03.03.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 22 Sep 2026 03:03:11 -0700 (PDT) Date: Tue, 22 Sep 2026 10:03:10 +0000 From: Bertrand Drouvot To: Michael Paquier Cc: shihao zhong , Jim Jones , pgsql-hackers Subject: Re: Add a permission check to pg_stat_get_backend_subxact() Message-ID: References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk Hi, On Tue, Sep 22, 2026 at 06:24:36PM +0900, Michael Paquier wrote: > On Mon, Sep 21, 2026 at 09:58:27AM +0000, Bertrand Drouvot wrote: > > One thing I noticed while looking at this is that with stats_fetch_consistency = snapshot, > > pgstat_fetch_stat_backend_by_pid() could validate the PID and user from one backend > > while returning cumulative statistics cached for an older backend that used the > > same ProcNumber. > > I'd slightly prefer storing a user ID, I think, because it means that > the ACL check is done only based on the stats data, and there would be > no cross-dependency between the data in the beentry and the stats > data. Perhaps you have a different view or more ideas? Yeah, storing the user ID in PgStat_Backend and using it for the ACL check makes sense to me. I'm not sure the user ID alone is enough though: if B reuses A's ProcNumber, pg_stat_get_backend_wal(B_pid) could still return A's cached statistics when the caller is allowed to see A's data. I'd keep the PID check from 0002 as well. A generation would be more robust against PID reuse, as done for example for AIO handles, but introducing a backend generation seems like too much for this case. So storing both seems like the simplest approach: the user ID for the ACL check and the PID for matching the statistics to the requested backend. Thoughts? Regards, -- Bertrand Drouvot PostgreSQL Contributors Team RDS Open Source Databases Amazon Web Services: https://aws.amazon.com