Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1x9HJt-00000001sIk-0liX for pgsql-hackers@arkaria.postgresql.org; Wed, 23 Sep 2026 07:23:09 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.98.2) (envelope-from ) id 1x9HJs-00000003Up6-10tm for pgsql-hackers@arkaria.postgresql.org; Wed, 23 Sep 2026 07:23:08 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1x9HJr-00000003Uoy-3ype for pgsql-hackers@lists.postgresql.org; Wed, 23 Sep 2026 07:23:07 +0000 Received: from mail-wm2-x10.google.com ([2a00:1450:4864:31::10]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.98.2) (envelope-from ) id 1x9HJp-00000000pnM-1ipw for pgsql-hackers@lists.postgresql.org; Wed, 23 Sep 2026 07:23:07 +0000 Received: by mail-wm2-x10.google.com with SMTP id 5b1f17b1804b1-49cd5462b69so2858135e9.1 for ; Wed, 23 Sep 2026 00:23:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1790148183; x=1790752983; darn=lists.postgresql.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=PBOlddj/gG4DGe1kbtuoCcBDdYV6MZNiodo7YhoJjfc=; b=rSIeuG6WlU3DC24303YV44Rp/Jn4mcox0cM69Bco0OR64zzVLyqmio7KnEehqMSPtQ kJmVJrWcpDfvp3/JhUyPUNln3hAtybVx31pCvtM+M5FSGRhsNk8BeeEAasie02vr6LEO K2XWpvgWfCxfnkaVR35fJs/ss6szxYb25w/T5ZW0nVPjXPqmzC2IUzu700U8Ps5C4kVz wEnNL5+MVj1r5dbzY+I7kWwT2KIeB/UIskIuUQnN/66yBtP1mNVAja1R4WfmpWLuGJXo pdNy4Y+WKtZFOTYvQzRD8EYW1bEULtBvJlK7L0e5gVMgvn9J5WpKirVcYT3gTMv/cqKJ ZdBw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790148183; x=1790752983; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=PBOlddj/gG4DGe1kbtuoCcBDdYV6MZNiodo7YhoJjfc=; b=PIn/XeSfwzejnqp4FmrXM6CqHUJTAVqC5vXY6CA69CuDaxpVlhVu9J9bGVkG1fxobA UwfQwUEKRAqqmt6Ib4PLemW081jDhBcHDHr29Y7FF7ud9JHEL5PCRkvvNqbriroERnNJ ZN8QBcbWLhk44yCnyrRdL4gPVU5fchezw98Mdkwp7ikQz1DfDoZDVs2CKnZVx7069Coh DSN5lFWIE2Z57yCek8fZD+TJeUiXW60QNyaZu8FUChRBYTJEL0IbuHSwMQukESh0LPRA F6FeFbhJjIijn3r+a1K2zKDITwDEwvmUSsEOQs4GR1KXQEWx5T7XA30CJbOqImYvFzFC 8pLA== X-Forwarded-Encrypted: i=1; AKwUvBxrR9+GAHvH683n2ay6qDwSwZCDV/nGStodVrKP1IWgryobUEmotBlu2ew0rHFEMQL5FuLLTmQ4v8QhAY8y@lists.postgresql.org X-Gm-Message-State: AFuF++k8oAE/ilbq+qmAGqP1sf/+FSqhaqXNBu1ItPc20zVMiM1tt9Iq tcGKMnQczL/S7IomhJkdBQclRJwwQGjnZqc9T/fGSuuLfUTcuJ29h/bd X-Gm-Gg: AYBFou2GcKQ9p3OnCq652klK/HtY1ngT0ebPsQowBKb3x57QJuy3gO8tAka0jV0zCzs mxL3irAjFefrQ7fWlOrIFlhEyZu3WM1nWVkk5wlXmGQ2Bd3r7Y+DyvIbX7I97mnIcs9V311YqFo eCjaSfX6UouTDg5XH6DorVk593bosNoSXO3YU83jFwJnbBrKD8qd+e43Q1ZLwLxo1I17LlSsBSk dRmaxXTALFRLiIS9vo3HJM1BBkdzFL89DOS045wd7i/q1hd9pZX8SBjVJSfJXBbptDr7HnHgtZ0 gW5ReEwFT8928We0b/4F/vabyScKL8E621m3R6Nr62HCMbowjeyPjoSddJZ1GGViYCXLn7RfaFa dbjuG/wtmCD9d6pdbJ/Ru7fMfmBqQ+9/fYhiGcGFWeW9Le0tepszGLZBYfgPLH9iJWb/sz4wirH wGGP1FjMgNZW9Lm6idP7lMkx9DVoDgxU14OQe40/mJicAeUJhdHDkZP5AnOBtcclO9+56G9thkc /HP96s+gLPDEsk0V4jufEKWtxxyEuYL/LxzIOu0ScIQCzm2Hf1waLPnEQ== X-Received: by 2002:a05:600c:37c8:b0:49f:ce78:356e with SMTP id 5b1f17b1804b1-49fdf0feec3mr18213555e9.31.1790148183004; Wed, 23 Sep 2026 00:23:03 -0700 (PDT) Received: from bdtpg (ec2-15-237-197-144.eu-west-3.compute.amazonaws.com. [15.237.197.144]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49fde199c21sm52065695e9.9.2026.09.23.00.23.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 23 Sep 2026 00:23:02 -0700 (PDT) Date: Wed, 23 Sep 2026 07:23:01 +0000 From: Bertrand Drouvot To: shihao zhong Cc: Michael Paquier , Jim Jones , pgsql-hackers Subject: Re: Add a permission check to pg_stat_get_backend_subxact() Message-ID: References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk Hi, On Tue, Sep 22, 2026 at 11:22:40PM -0400, shihao zhong wrote: > > Do you mean adding the user ID on top of Shihao's 0002? If so, I can have > a look, > > unless Shihao is already planning to update the patch along those lines? > > Done in v8, attached. Thanks! I've a few comments: > 0001 is the PID check, same as v7-0002. It goes first now because 0002 > needs a field in PgStat_Backend. > > 0002 stores the user ID in PgStat_Backend next to the PID when the entry > is created, and pg_stat_get_backend_io(), wal() and lock() check the > caller against that instead of the beentry. The reset callback restores > both fields. pg_stat_get_backend_subxact() still checks the beentry, the > counters it reports come from there. === 1 pgstat_read_current_status() first copies the activity entry and then calls ProcNumberGetTransactionIds() separately. If the backend exits and its ProcNumber is reused in between, the userid can belong to the old backend while the subxact counters belong to the new one. This race exists before the patch, but it matters for the new permission check. I wonder if we should pass the copied PID to ProcNumberGetTransactionIds() and validate it under ProcArrayLock, following the same idea as pgstat_fetch_stat_backend_by_pid()? === 2 typedef struct PgStat_Backend { + int pid; /* PID of the backend owning these stats */ TimestampTz stat_reset_timestamp; 0002 explicitly says that it is not intended for backpatching, but what about 0001? If it is backpatched to v18, adding pid here changes the offsets of all the existing fields. I think it would make sense to add pid at the end in the backbranches (if we back patch it), as suggested in [1]. That would preserve the existing field offsets, though it would still change sizeof(PgStat_Backend). FWIW, I could not find any use of sizeof(PgStat_Backend) in a GitHub code search and there is no padding to add the new field into. [1]: https://wiki.postgresql.org/wiki/Committing_checklist Regards, -- Bertrand Drouvot PostgreSQL Contributors Team RDS Open Source Databases Amazon Web Services: https://aws.amazon.com