Re: BUG #15708: RLS 'using' running as wrong user when called from a view - Mailing list pgsql-bugs

From Dean Rasheed
Subject Re: BUG #15708: RLS 'using' running as wrong user when called from a view
Date
Msg-id CAEZATCV_yDYoptaxtjiVB4yLwxQ=N7OWu8Ls98rA5MvBL+jKiQ@mail.gmail.com
Whole thread Raw
In response to Re: BUG #15708: RLS 'using' running as wrong user when called from a view  (Daurnimator <quae@daurnimator.com>)
List pgsql-bugs
On Mon, 29 Apr 2019 at 04:56, Daurnimator <quae@daurnimator.com> wrote:
>
> On Wed, 27 Mar 2019 at 23:46, Dean Rasheed <dean.a.rasheed@gmail.com> wrote:
> > On second thoughts, it actually needs to be in
> > get_row_security_policies(), after making copies of the quals from the
> > policies, otherwise it would be scribbling on the copies from the
> > relcache. Actually that makes the code change a bit simpler too.
>
> Thanks for writing the patch!
>
> I'm sad this missed the last commit fest; I think this bug might be
> causing security issues in a few deployments.
> Could you submit the patch for the next commit fest?

Actually I pushed the fix for this a while ago [1] (sorry I forgot to
reply back to this thread), so it will be available in the next set of
minor version updates later this week.

Regards,
Dean

[1] https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=e2d28c0f404713f564dc2250646551c75172f17b



pgsql-bugs by date:

Previous
From: Jozef Mlich
Date:
Subject: crash of postgresql 11.2-2PGDG.rhel7 in StartupXLOG () atxlog.c:6355
Next
From: Flo Rance
Date:
Subject: Re: Reg: Postgresql8.3 Using on Ubuntu