Re: RLS bug in expanding security quals - Mailing list pgsql-hackers

From Stephen Frost
Subject Re: RLS bug in expanding security quals
Date
Msg-id 20151009145235.GM3685@tamriel.snowman.net
Whole thread Raw
In response to Re: RLS bug in expanding security quals  (Haribabu Kommi <kommi.haribabu@gmail.com>)
List pgsql-hackers
* Haribabu Kommi (kommi.haribabu@gmail.com) wrote:
> On Fri, Oct 9, 2015 at 3:50 AM, Dean Rasheed <dean.a.rasheed@gmail.com> wrote:
> > On 8 October 2015 at 15:05, Dean Rasheed <dean.a.rasheed@gmail.com> wrote:
> >> Attached is a simple patch that appears to work, but it needs more
> >> testing (and some regression tests).
> >>
> >
> > Here's an updated patch with an extra regression test case that
> > triggers the issue.
> >
> > I've also updated the function comment for expand_security_quals() to
> > better explain the situations where it actually has work to do --
> > tables with RLS and updates to auto-updatable security barrier views,
> > but not SELECTs from security berrier views. This explains why this
> > bug doesn't affect security barrier views (UNION ALL views aren't
> > auto-updatable), so only 9.5 and HEAD need to be patched.
>
> Thanks for the patch. I didn't find any problem in my test with the patch.

Excellent, fix pushed.

I also updated the Open Items wiki (putting this under 'resolved after
9.5beta1), in case folks run into it while testing beta1.

Thanks!

Stephen

pgsql-hackers by date:

Previous
From: Tomas Vondra
Date:
Subject: Re: PATCH: index-only scans with partial indexes
Next
From: Stephen Frost
Date:
Subject: Re: Multi-tenancy with RLS