From: | Stephen Frost <sfrost(at)snowman(dot)net> |
---|---|
To: | Dean Rasheed <dean(dot)a(dot)rasheed(at)gmail(dot)com> |
Cc: | Haribabu Kommi <kommi(dot)haribabu(at)gmail(dot)com>, "pgsql-hackers(at)postgresql(dot)org" <pgsql-hackers(at)postgresql(dot)org> |
Subject: | Re: RLS bug in expanding security quals |
Date: | 2015-10-09 02:48:11 |
Message-ID: | 20151009024811.GE3685@tamriel.snowman.net |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-hackers |
Dean,
* Dean Rasheed (dean(dot)a(dot)rasheed(at)gmail(dot)com) wrote:
> On 8 October 2015 at 15:05, Dean Rasheed <dean(dot)a(dot)rasheed(at)gmail(dot)com> wrote:
> > Attached is a simple patch that appears to work, but it needs more
> > testing (and some regression tests).
>
> Here's an updated patch with an extra regression test case that
> triggers the issue.
Thanks!
> I've also updated the function comment for expand_security_quals() to
> better explain the situations where it actually has work to do --
> tables with RLS and updates to auto-updatable security barrier views,
> but not SELECTs from security berrier views. This explains why this
> bug doesn't affect security barrier views (UNION ALL views aren't
> auto-updatable), so only 9.5 and HEAD need to be patched.
Excellent, I definitely like the additional comments.
I plan to do a bit more testing tomorrow morning, but barring any
issues found or concerns raised, I'll push this sometime tomorrow.
Thanks again!
Stephen
From | Date | Subject | |
---|---|---|---|
Next Message | Etsuro Fujita | 2015-10-09 03:00:30 | Re: Foreign join pushdown vs EvalPlanQual |
Previous Message | Haribabu Kommi | 2015-10-09 01:13:00 | Re: RLS bug in expanding security quals |