Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wEn4Z-004PHp-2R for pgsql-hackers@arkaria.postgresql.org; Mon, 20 Apr 2026 11:45:52 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.96) (envelope-from ) id 1wEn4X-002FbR-1Q for pgsql-hackers@arkaria.postgresql.org; Mon, 20 Apr 2026 11:45:49 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wEn4W-002FbI-2S for pgsql-hackers@lists.postgresql.org; Mon, 20 Apr 2026 11:45:49 +0000 Received: from fout-b7-smtp.messagingengine.com ([202.12.124.150]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wEn4S-000000027lb-3SiE for pgsql-hackers@lists.postgresql.org; Mon, 20 Apr 2026 11:45:48 +0000 Received: from phl-compute-05.internal (phl-compute-05.internal [10.202.2.45]) by mailfout.stl.internal (Postfix) with ESMTP id 008671D00152; Mon, 20 Apr 2026 07:45:40 -0400 (EDT) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-05.internal (MEProxy); Mon, 20 Apr 2026 07:45:41 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :reply-to:subject:subject:to:to:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm2; t=1776685540; x=1776771940; bh=h Uvb7Chxd2LITvtBgOZLtZmcDSG0vBUCBiRbzm4zxec=; b=igxn3rNUy4drjagfJ GrpXjM2TlxP2XsWDEU+3UtJldgikFbpLAfFu1NomWFnW+IEfYoSGGFQ9zeCXmooL 63oqcn+wHGpXAql1NNCQpYwVJovxxjFiTxc36HmAEfL83tTawvx3AdJTlsPu0ZNW 0IdACAqDfbDjcCv9NRHuMf0Gj8zCgZRLS1iw3QIgNfEVyp3L8cUDRQDdOWhlx1Sy dKisyrUaPodRTu4pTFNOggyooPIBabAxtJCGM20vKl6QLZdcBnKq+pb41nU8Ftyv +pxB7BWnjBvlP/NE3yuL707L22peh8NhQBBOZgru/8DVTzDe80TyTeLjQe8xiIhP kQFsw== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefhedrtddtgdehkeegfecutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpuffrtefokffrpgfnqfghnecuuegr ihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmdenucfjug hrpeffhffvvefukfggtggugfgjsehmkeerredttdejnecuhfhrohhmpeetlhhvrghrohcu jfgvrhhrvghrrgcuoegrlhhvhhgvrhhrvgesrghlvhhhrdhnohdqihhprdhorhhgqeenuc ggtffrrghtthgvrhhnpeduleekkefgtddttedtkefguddvieffleetgeejiefhteehkeev feettdduvdfhueenucffohhmrghinhepvghnthgvrhhprhhishgvuggsrdgtohhmnecuve hluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomheprghlvhhhvghr rhgvsegrlhhvhhdrnhhoqdhiphdrohhrghdpnhgspghrtghpthhtohepledpmhhouggvpe hsmhhtphhouhhtpdhrtghpthhtoheprghnughrvghssegrnhgrrhgriigvlhdruggvpdhr tghpthhtoheprghhsegthigsvghrthgvtgdrrghtpdhrtghpthhtoheprghmihhtrdhkrg hpihhlrgduieesghhmrghilhdrtghomhdprhgtphhtthhopegsohgvkhgvfihurhhmodhp ohhsthhgrhgvshesghhmrghilhdrtghomhdprhgtphhtthhopehmihhhrghilhhnihhkrg hlrgihvghusehgmhgrihhlrdgtohhmpdhrtghpthhtohepshhrihhnrghthhdvudeffees ghhmrghilhdrtghomhdprhgtphhtthhopehpghhsqhhlqdhhrggtkhgvrhhssehlihhsth hsrdhpohhsthhgrhgvshhqlhdrohhrghdprhgtphhtthhopehprhihiigshiesthgvlhhs rghsohhfthdrtghomhdprhgtphhtthhopehrohgsseigiihilhhlrgdrnhgvth X-ME-Proxy: Feedback-ID: ia2694551:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 20 Apr 2026 07:45:39 -0400 (EDT) Received: by ida.kurilemu.internal (Postfix, from userid 1000) id 51555B03189; Mon, 20 Apr 2026 13:45:35 +0200 (CEST) Date: Mon, 20 Apr 2026 13:45:35 +0200 From: Alvaro Herrera To: Antonin Houska Cc: Justin Pryzby , Mihail Nikalayeu , Andres Freund , Amit Kapila , Srinath Reddy Sadipiralla , Matthias van de Meent , pgsql-hackers@lists.postgresql.org, Robert Treat Subject: Re: Adding REPACK [concurrently] Message-ID: MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="m6zy3l65ushq557m" Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <22338.1776671256@localhost> List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk --m6zy3l65ushq557m Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit On 2026-Apr-20, Antonin Houska wrote: > Antonin Houska wrote: > > > It was discussed earlier [1] and the concerns about possibly excessive > > resource consumptions were addressed by [2]. So I think it the fix was just > > forgotten. Attached here. > > Sorry, I attached wrong patch. This is what I meant. Yeah, I had also written the same patch a couple of days ago. BTW I ran into a small problem after adding some tests in cluster.sql that would exercise this -- that test would die more or less randomly but frequently in CI (which it never did in my laptop) because of the size of the snapshot, ALTER TABLE ptnowner1 REPLICA IDENTITY USING INDEX ptnowner1_i_key; REPACK (CONCURRENTLY) ptnowner1; +ERROR: initial slot snapshot too large +CONTEXT: REPACK decoding worker RESET SESSION AUTHORIZATION; I think the solution for this is to move cluster to a separate parallel test. The one where it is now is a bit too crowded. Maybe the one for compression is okay? I'll test and push if I see it passing CI. Another obvious thing after adding tests is that the LOGIN privilege is required, which is also quite bogus IMO. 0002 here should solve that. -- Álvaro Herrera Breisgau, Deutschland — https://www.EnterpriseDB.com/ "If you want to have good ideas, you must have many ideas. Most of them will be wrong, and what you have to learn is which ones to throw away." (Linus Pauling) --m6zy3l65ushq557m Content-Type: text/x-diff; charset=utf-8 Content-Disposition: attachment; filename="0001-REPACK-do-not-require-the-user-to-have-REPLICATION.patch" From b3d4158356f4914d2b0cba86eef6994c0ee50ab9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C3=81lvaro=20Herrera?= Date: Mon, 20 Apr 2026 11:38:48 +0200 Subject: [PATCH 1/2] REPACK: do not require the user to have REPLICATION Although REPACK (CONCURRENTLY) uses replication slots, there is no concern that the slot will leak data of other users, because the MAINTAIN privilege on the table is required anyway; requiring REPLICATION is user-unfriendly without providing any actual protection. A related aspect is that the REPLICATION attribute is not needed to prevent REPACK from stealing slots from logical replication, since commit e76d8c749c31 made REPACK use a separate pool of replication slots. Because there are now successful concurrent repack runs in the regression tests, we're forced to run test_plan_advice under wal_level=replica. Author: Antonin Houska Reported-by: Justin Pryzby Reviewed-by: Chao Li Discussion: https://postgr.es/m/aeJHPNmL4vVy3oPw@pryzbyj2023 --- src/backend/commands/repack_worker.c | 1 - .../test_plan_advice/t/001_replan_regress.pl | 1 + src/test/regress/expected/cluster.out | 20 +++++++++++++++++-- src/test/regress/sql/cluster.sql | 11 ++++++++-- 4 files changed, 28 insertions(+), 5 deletions(-) diff --git a/src/backend/commands/repack_worker.c b/src/backend/commands/repack_worker.c index b17edd771e2..e4a4860805b 100644 --- a/src/backend/commands/repack_worker.c +++ b/src/backend/commands/repack_worker.c @@ -214,7 +214,6 @@ repack_setup_logical_decoding(Oid relid) /* * Make sure we can use logical decoding. */ - CheckSlotPermissions(); CheckLogicalDecodingRequirements(true); /* diff --git a/src/test/modules/test_plan_advice/t/001_replan_regress.pl b/src/test/modules/test_plan_advice/t/001_replan_regress.pl index 38ffa4d11ae..452b179a665 100644 --- a/src/test/modules/test_plan_advice/t/001_replan_regress.pl +++ b/src/test/modules/test_plan_advice/t/001_replan_regress.pl @@ -18,6 +18,7 @@ $node->init(); # Set up our desired configuration. $node->append_conf('postgresql.conf', < Date: Mon, 20 Apr 2026 13:19:49 +0200 Subject: [PATCH 2/2] REPACK: do not require LOGIN privileges Normally, starting a background worker does require LOGIN, which is fine. However, the bgworker used for REPACK has no business requiring it. It's just user-unfriendly and prevents repacking tables comfortably. --- src/backend/commands/repack_worker.c | 5 +++-- src/test/regress/expected/cluster.out | 2 +- src/test/regress/sql/cluster.sql | 2 +- 3 files changed, 5 insertions(+), 4 deletions(-) diff --git a/src/backend/commands/repack_worker.c b/src/backend/commands/repack_worker.c index e4a4860805b..c40f8c98e06 100644 --- a/src/backend/commands/repack_worker.c +++ b/src/backend/commands/repack_worker.c @@ -106,8 +106,9 @@ RepackWorkerMain(Datum main_arg) pq_set_parallel_leader(shared->backend_pid, shared->backend_proc_number); - /* Connect to the database. */ - BackgroundWorkerInitializeConnectionByOid(shared->dbid, shared->roleid, 0); + /* Connect to the database. LOGIN is not required. */ + BackgroundWorkerInitializeConnectionByOid(shared->dbid, shared->roleid, + BGWORKER_BYPASS_ROLELOGINCHECK); /* * Transaction is needed to open relation, and it also provides us with a diff --git a/src/test/regress/expected/cluster.out b/src/test/regress/expected/cluster.out index e17bc91fae1..71270134985 100644 --- a/src/test/regress/expected/cluster.out +++ b/src/test/regress/expected/cluster.out @@ -546,7 +546,7 @@ DROP TABLE clstrpart; CREATE TABLE ptnowner(i int unique not null) PARTITION BY LIST (i); CREATE INDEX ptnowner_i_idx ON ptnowner(i); CREATE TABLE ptnowner1 PARTITION OF ptnowner FOR VALUES IN (1); -CREATE ROLE regress_ptnowner LOGIN; +CREATE ROLE regress_ptnowner; CREATE TABLE ptnowner2 PARTITION OF ptnowner FOR VALUES IN (2); ALTER TABLE ptnowner1 OWNER TO regress_ptnowner; SET SESSION AUTHORIZATION regress_ptnowner; diff --git a/src/test/regress/sql/cluster.sql b/src/test/regress/sql/cluster.sql index 1f471a8821a..6746236ffec 100644 --- a/src/test/regress/sql/cluster.sql +++ b/src/test/regress/sql/cluster.sql @@ -257,7 +257,7 @@ DROP TABLE clstrpart; CREATE TABLE ptnowner(i int unique not null) PARTITION BY LIST (i); CREATE INDEX ptnowner_i_idx ON ptnowner(i); CREATE TABLE ptnowner1 PARTITION OF ptnowner FOR VALUES IN (1); -CREATE ROLE regress_ptnowner LOGIN; +CREATE ROLE regress_ptnowner; CREATE TABLE ptnowner2 PARTITION OF ptnowner FOR VALUES IN (2); ALTER TABLE ptnowner1 OWNER TO regress_ptnowner; SET SESSION AUTHORIZATION regress_ptnowner; -- 2.47.3 --m6zy3l65ushq557m--