Re: RI fastpath misses checking EXECUTE on functions - Mailing list pgsql-hackers

From Kirill Reshke
Subject Re: RI fastpath misses checking EXECUTE on functions
Date
Msg-id CALdSSPgHU=um9oMK39NQg3MPQ-fFfBNL3gYPfiDNxPaGg9jBsg@mail.gmail.com
Whole thread
In response to Re: RI fastpath misses checking EXECUTE on functions  (Amit Langote <amitlangote09@gmail.com>)
Responses Re: RI fastpath misses checking EXECUTE on functions
List pgsql-hackers
On Sat, 26 Sept 2026 at 07:16, Amit Langote <amitlangote09@gmail.com> wrote:
>
> On Fri, Sep 25, 2026 at 8:45 PM Matheus Alcantara
> <matheusssilv97@gmail.com> wrote:
> > On 25/09/26 05:16, Amit Langote wrote:
> > >> ri_CheckFunctionPermissions(riinfo, fpmeta) passes both when fpmeta
> > >> == riinfo->fpmeta. I'm wondering if we could just pass riinfo?
> > >
> > > That's just for consistency with build_index_scankeys(); it isn't
> > > needed, so I don't feel strongly either way.
> > >
> >
> > Ok, make sense.
> >
> > >> IIUC this patch only fix the case for FastPath without batching right?
> > >> Since batching is still on master, I'm wondering if we could also fix
> > >> it. See attached patch (v2-0001 is your v1-0001).
> > >
> > > I've left the batch code alone because I intend to revert it from
> > > master too sometime next week. Thanks for the patch, though.
> > >
> >
> > Ok, thanks for letting me know.
> >
> > > I have attached a new version where I polished
> > > ri_CheckFunctionPermissions()'s comment and the commit message.  I
> > > would like to commit it tomorrow if there are no more comments.
> > >
> >
> > Looks good to me.
>
> Thanks, pushed.
>
> --
> Thanks, Amit Langote
>
>

HI!

Isn't ri_CheckFunctionPermissions missing in ri_FastPathBatchFlush ?

For this repro

CREATE SCHEMA s;
CREATE ROLE noproc NOLOGIN;
CREATE ROLE fkuser NOLOGIN;

CREATE FUNCTION s.eq(int4,int4) RETURNS bool AS 'int4eq'
  LANGUAGE internal IMMUTABLE STRICT;
CREATE OPERATOR s.=== (LEFTARG=int4, RIGHTARG=int4, PROCEDURE=s.eq);
CREATE OPERATOR CLASS s.ops FOR TYPE int4 USING btree AS
  OPERATOR 1 <, OPERATOR 2 <=, OPERATOR 3 s.===,
  OPERATOR 4 >=, OPERATOR 5 >, FUNCTION 1 btint4cmp(int4,int4);

REVOKE EXECUTE ON FUNCTION s.eq(int4,int4) FROM PUBLIC;

CREATE TABLE pk(a int4);
CREATE UNIQUE INDEX ON pk (a s.ops);
CREATE TABLE fk(a int4);
ALTER TABLE fk ADD FOREIGN KEY (a) REFERENCES pk(a);

ALTER TABLE pk OWNER TO noproc;
ALTER TABLE fk OWNER TO fkuser;
GRANT SELECT ON pk TO fkuser;
INSERT INTO pk VALUES (1);

SET ROLE fkuser;
INSERT INTO fk VALUES (1);

I expect `ERROR:  permission denied for function eq`, but on master
its executed without error.


This diff fixes issue
```
diff --git a/src/backend/utils/adt/ri_triggers.c
b/src/backend/utils/adt/ri_triggers.c
index 2797ac4abea..2799e8aea99 100644
--- a/src/backend/utils/adt/ri_triggers.c
+++ b/src/backend/utils/adt/ri_triggers.c
@@ -3141,6 +3141,7 @@ ri_FastPathBatchFlush(RI_FastPathEntry *fpentry,
Relation fk_rel,
                ri_populate_fastpath_metadata(riinfo, fk_rel, idx_rel);
        }
        Assert(riinfo->fpmeta);
+       ri_CheckFunctionPermissions(riinfo, riinfo->fpmeta);

        /*
         * Take our own reference to the metadata for the duration of the flush.
```


--
Best regards,
Kirill Reshke



pgsql-hackers by date:

Previous
From: Manu
Date:
Subject: Re: ATTACH PARTITION cost grows linearly with pg_constraint size (seqscan in CloneFkReferenced), much worse since not-null constraints are in pg_constraint (PG 18)
Next
From: Amit Langote
Date:
Subject: Re: RI fastpath misses checking EXECUTE on functions