pg.ddx.io  pgsql-hackers@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Jacob Champion <pchampion@vmware.com>
To: daniel@yesql.se <daniel@yesql.se>
To: magnus@hagander.net <magnus@hagander.net>
Cc: pgsql-hackers@lists.postgresql.org <pgsql-hackers@lists.postgresql.org>
Subject: Re: PROXY protocol support
Date: Mon, 15 Nov 2021 23:03:18 +0000
Message-ID: <ef8f4431460b96f8edad29fd624f850d4e26f679.camel@vmware.com> (raw)
In-Reply-To: <CABUevEy=nTqkfBCA5=vrWPEaS+D7rBLeoKVbk_e2WprGpTTMDQ@mail.gmail.com>
References: <CABUevExJ0ifpUEiX4uOREy0s2kHBrBrb=pXLEHhpMTR1vVR1XA@mail.gmail.com>
	<b097096a23f0c9ee5b4c8d97fcc4aa64ec3fc97c.camel@vmware.com>
	<CABUevEwpMNDB7UGAS596wEu_OrvAdfzZ1tJJHNXsNWvofGOqrQ@mail.gmail.com>
	<CABUevEzh6AoLxOvAoZf4WgNYoQv1OReb=2_XE49o-wturqUYvw@mail.gmail.com>
	<955367547640a1e24a72d0e79236f49ec7f0dd21.camel@vmware.com>
	<CABUevEy+aeHCCtKQMi38tvAjLfUq1Jf7fCpOB2z8V4g3y7Zrhg@mail.gmail.com>
	<d3a8e38c7a1c39034cbce45730456587b65479b1.camel@vmware.com>
	<CABUevExYtq2xuJXUWUCYMR12TwEcT8ODhn2n3Le09KeayXdegA@mail.gmail.com>
	<fafc3f393dd968dfbe71ca98a034472f4fbeeb15.camel@vmware.com>
	<CABUevEygBkZWyw0qYt8pMZ4jp3DOjMYKoj-68T_qFjeYqoi+6g@mail.gmail.com>
	<CABUevEy9MP0THCJNOb4NN8aQ3La40=ah3gKbYvoAmUs1hjknzw@mail.gmail.com>
	<CABUevEzE9FZfjc7ZS=iHzaw+8GFcFjzA7AqEyZ9fBJt=rkgj-A@mail.gmail.com>
	<d802f0761898a9efcd1a3181247717e458d219b0.camel@vmware.com>
	<CABUevEwJK52jqoXQOhGr2-6bA+MG3sFfELfPJ4hDGFoyH-orWA@mail.gmail.com>
	<8aeede56330ca5721265428302c7f73e4e2e1264.camel@vmware.com>
	<CABUevEwHUmYBXDvOWjN1wcn4mfZ1h1rwvg2AWYS9kD4ycykYFw@mail.gmail.com>
	<0c4b20fd6b33e21f3776cac88219920cac73a883.camel@vmware.com>
	<CABUevEw-yjGqrH6g7jv5R+vabjnisCteJ7KY2n1ouQ8E8g1V+A@mail.gmail.com>
	<84af2549930307353eea7422decf910dbcffb334.camel@vmware.com>
	<c5538db9aab8feacc931cc1881e30e6026ff3384.camel@vmware.com>
	<CABUevExeD7fn_=4m2EZVix48OYg5Js+1NBRU=tcXNwkLRk=sZg@mail.gmail.com>
	<313F83F5-3FD5-4FAF-B0E0-83818F1A41F9@yesql.se>
	<CABUevEy=nTqkfBCA5=vrWPEaS+D7rBLeoKVbk_e2WprGpTTMDQ@mail.gmail.com>

On Thu, 2021-11-04 at 12:03 +0100, Magnus Hagander wrote:
> Thanks for the pointer, PFA a rebase.

I think the Unix socket handling needs the same "success" fix that you
applied to the TCP socket handling above it:

> @@ -1328,9 +1364,23 @@ PostmasterMain(int argc, char *argv[])
>                 ereport(WARNING,
>                         (errmsg("could not create Unix-domain socket in directory \"%s\"",
>                                 socketdir)));
> +
> +           if (ProxyPortNumber)
> +           {
> +               socket = StreamServerPort(AF_UNIX, NULL,
> +                                         (unsigned short) ProxyPortNumber,
> +                                         socketdir,
> +                                         ListenSocket, MAXLISTEN);
> +               if (socket)
> +                   socket->isProxy = true;
> +               else
> +                   ereport(WARNING,
> +                           (errmsg("could not create Unix-domain PROXY socket for \"%s\"",
> +                                   socketdir)));
> +           }
>         }
>  
> -       if (!success && elemlist != NIL)
> +       if (socket == NULL && elemlist != NIL)
>             ereport(FATAL,
>                     (errmsg("could not create any Unix-domain sockets")));

Other than that, I can find nothing else to improve, and I think this
is ready for more eyes than mine. :)

--

To tie off some loose ends from upthread:

I didn't find any MAXLISTEN documentation either, so I guess it's only
a documentation issue if someone runs into it, heh.

I was not able to find any other cases (besides ident) where using
daddr instead of laddr would break things. I am going a bit snow-blind
on the patch, though, and there's a lot of auth code.

I never did hear back from the PROXY spec maintainer on how strict to
be with LOCAL; another contributor did chime in but only to add that
they didn't know the answer. That conversation is at [1], in case
someone picks it up in the future.

A summary of possible improvements talked about upthread, for a future
v2:

- SQL functions to get the laddr info (scoped to superusers, somehow),
if there's a use case for them

- Setting up PROXY Unix socket permissions separately from the "main"
socket

- Allowing PROXY-only communication (disable the "main" port)

Thanks,
--Jacob

[1] https://www.mail-archive.com/haproxy@formilux.org/msg40899.html


view thread (56+ messages)  latest in thread

Message-ID: <ef8f4431460b96f8edad29fd624f850d4e26f679.camel@vmware.com>
Permalink:  ../ef8f4431460b96f8edad29fd624f850d4e26f679.camel@vmware.com/
Also on:    postgresql.org/message-id/ef8f4431460b96f8edad29fd624f850d4e26f679.camel@vmware.com

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-hackers@postgresql.org
  Cc: pchampion@vmware.com, daniel@yesql.se, magnus@hagander.net, pgsql-hackers@lists.postgresql.org
  Subject: Re: PROXY protocol support
  In-Reply-To: <ef8f4431460b96f8edad29fd624f850d4e26f679.camel@vmware.com>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox