Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1x915R-00000001hHb-060E for pgsql-hackers@arkaria.postgresql.org; Tue, 22 Sep 2026 14:03:09 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.98.2) (envelope-from ) id 1x915P-0000000GMV1-3lTS for pgsql-hackers@arkaria.postgresql.org; Tue, 22 Sep 2026 14:03:07 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1x915P-0000000GMUt-2ZAl for pgsql-hackers@lists.postgresql.org; Tue, 22 Sep 2026 14:03:07 +0000 Received: from mail-wr2-x10.google.com ([2a00:1450:4864:30::10]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.98.2) (envelope-from ) id 1x915N-00000000g71-1CiK for pgsql-hackers@lists.postgresql.org; Tue, 22 Sep 2026 14:03:06 +0000 Received: by mail-wr2-x10.google.com with SMTP id ffacd0b85a97d-4843f22dcb8so2752316f8f.0 for ; Tue, 22 Sep 2026 07:03:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790085784; x=1790690584; darn=lists.postgresql.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=un71Jwle+jiruo+gfK8O+XRrLX/g+UPsCXGX8CG6ugc=; b=J4xHmAyaaQeItLjYqc1um18WKg4Ysqsd3tcmnBWPd/2f10WB8QA9P3npKM0nSsS6sb aVGrk50XkhMWLZngm19XlRtjxjTlHmMEY+v20iqHyMXkGz3KAe6mGmFTcOPckYethByi 7bTKPJvFFukegy01muUZde8I4v3f6iA4ueKJ/grVZyszyOa4BJs11ITgLQnfjlRMCtgu HFB3ZVQ1xB5rqJdQtNDk++G24P+S/J/A/d4nxwjLkyHVlvb/aDLClbUoJMODRkXxERMX rLX3fCngRRwPjfMTnbzoWe/5qroPa8da9yMtxVSNMuKmJTptRxDg9h4d3rFy7V4eZcGf wLow== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790085784; x=1790690584; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=un71Jwle+jiruo+gfK8O+XRrLX/g+UPsCXGX8CG6ugc=; b=VjeM+72sjmralRchYjcCOBXcLsLJprtD4YwdzqXXtBJLfnWW84LQYypbObBTFz0yxA kFWh5EX5j5d4q3CbvGcqrMbzojUyugAPjJyfMxvUJiF2VE2+Eoa3tnuf5W3b6E/CQp20 ZNp1ZXimQai3W2Jt56pTmTd856cy1G8K8t9CnkObRjqesXPNU1u6rAV46LS34il//ZMF iY7OV/h5CBaO3XTs0Hx0yefl6jw4n67fTgBeNUpqJgmHiJMmJozbiTI/mQK1MYhorSN1 bhPg/9f2H7VFeAlkEUDADyXPtNZUrqSGVw3/zo7ZYuRoFA9I9xBVq0h5a1XpRXeaGgst d0PQ== X-Forwarded-Encrypted: i=1; AKwUvBzDPaNtioYnHa6UeWfLk8bZPBr9yM8r1PZdJVWTLeFvksgedSlFLLIx82Wh/kmZZeHnDXtkaG3I/00anDZ4@lists.postgresql.org X-Gm-Message-State: AFuF++mswf4gwwg9PDp65Hng+69L5ALNiy4Opct47bAunvTmmdc/ZGWi 577nNcaUL5lXj9JNWsfdCJvoFuqg6wY82aYYGRd1yoAdXu6+JGXJj8oj X-Gm-Gg: AYBFou1ziarU2dAYLU7mHHo5NBX/1zt6hpng6KJJYfG+5vZeASHdxnTMzG/u8xhaKNO BqVel7WksqjTguFkUFop9lAuQWO9229nxcMM3tdbu2xXDwMSgB8WUPEiLxQTGCC+yLgFCD1GRDT +VqzafXUn4/nlVcJDV+Otss7i1L+IiYHlzAEYjPR7zXetAHp18Q1fEq1AjN5acBygUzmqE7CgIA luPWuFZ8duypQzsvRuXFV2oqQeHZiLqAjeK2Mh/umvFX9Q8MEeQUEIzt5AtyXgq0XZojI8ZQLfG 4B+rHa4r9iwZUVubACnC2syVJj+cUW/AcDEAJdJFQttDc4jia0TLmj0bMhmBExw7WNcDc7QjJDH Bb0aAHFC43r6yFEUcsCFh2FnYZnCPvOZLjfNi0ttS3Z9BkCyvQqbWzqwyZiRWQuighK3DzuC5qH WnF8M2Jgw/HNJu4mgCM4Xv+PAT7F2a6QiMFDFvVbT4OgSO7DVdmQ4BgUMcVGVGQlv+rvEkId/96 2lq1drss+LOf8tJrdj7BAaMsEnuNDunGvu19yrBXCgVUF8BEPOL4Pod+SrLKAZHkIuJ X-Received: by 2002:a5d:584b:0:b0:487:1575:ebe2 with SMTP id ffacd0b85a97d-4871e36e068mr20823198f8f.44.1790085784202; Tue, 22 Sep 2026 07:03:04 -0700 (PDT) Received: from bdtpg (ec2-15-237-197-144.eu-west-3.compute.amazonaws.com. [15.237.197.144]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48862774483sm4944739f8f.8.2026.09.22.07.03.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 22 Sep 2026 07:03:03 -0700 (PDT) Date: Tue, 22 Sep 2026 14:03:02 +0000 From: Bertrand Drouvot To: Michael Paquier Cc: shihao zhong , Jim Jones , pgsql-hackers Subject: Re: Add a permission check to pg_stat_get_backend_subxact() Message-ID: References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk Hi, On Tue, Sep 22, 2026 at 08:23:54PM +0900, Michael Paquier wrote: > On Tue, Sep 22, 2026 at 10:03:10AM +0000, Bertrand Drouvot wrote: > > I'm not sure the user ID alone is enough though: if B reuses A's ProcNumber, > > pg_stat_get_backend_wal(B_pid) could still return A's cached statistics when > > the caller is allowed to see A's data. > > > > I'd keep the PID check from 0002 as well. A generation would be more robust > > against PID reuse, as done for example for AIO handles, but introducing a > > backend generation seems like too much for this case. > > > > So storing both seems like the simplest approach: the user ID for the ACL > > check and the PID for matching the statistics to the requested backend. > > The PID would also act as a kind of weaker generation number, slightly > weaker but simpler. So that works here. Perhaps you would like to > give it a shot? Do you mean adding the user ID on top of Shihao's 0002? If so, I can have a look, unless Shihao is already planning to update the patch along those lines? Regards, -- Bertrand Drouvot PostgreSQL Contributors Team RDS Open Source Databases Amazon Web Services: https://aws.amazon.com