Re: BUG #19523: psql tab-completion shadows pg_db_role_setting - Mailing list pgsql-bugs

From Kirill Reshke
Subject Re: BUG #19523: psql tab-completion shadows pg_db_role_setting
Date
Msg-id CALdSSPiAmy3ZoUyRXMqFazm0D0b1Y4oMhUKVpXwSBhrDh+odew@mail.gmail.com
Whole thread
Responses Re: BUG #19523: psql tab-completion shadows pg_db_role_setting
List pgsql-bugs

Hi! You seem to create two threads on the issue, so I don't quite understand where to respond. anyway:

On Thu, 9 Jul 2026, 15:14 Vismay Tiwari, <vismay.t@gmail.com> wrote:
Hi,

Reproduced on current master. The tab-completion query for
"ALTER DATABASE ... RESET" (Query_for_list_of_database_vars) references
pg_db_role_setting and pg_database without a pg_catalog qualification, so a
same-named table earlier in search_path shadows the catalog:

    CREATE SCHEMA attacker;
    CREATE TABLE attacker.pg_db_role_setting (setdatabase oid, setrole
oid, setconfig text[]);
    INSERT INTO attacker.pg_db_role_setting
      SELECT oid, 0, ARRAY['evil_var=x'] FROM pg_database WHERE
datname = 'postgres';
    SET search_path = attacker, pg_catalog;
    -- "ALTER DATABASE postgres RESET <TAB>" then offers evil_var


Preventing this makes sense in case somebody accidentally misconfigured their server. Which is not very probable for a table with `pg_db_role_setting` name.
Also note that this is not a vulnerability: from https://www.postgresql.org/docs/current/app-psql.html says:

  If untrusted users have access to a database that has not adopted a secure
  schema usage pattern, begin your session by removing publicly-writable
  schemas from search_path.

Anyway +1 on fixing

 

pgsql-bugs by date:

Previous
From: Vismay Tiwari
Date:
Subject: [PATCH v1] psql: schema-qualify catalog references in a tab-completion query
Next
From: Vismay Tiwari
Date:
Subject: Re: BUG #19523: psql tab-completion shadows pg_db_role_setting