pgsql: Flatten join alias Vars before pulling up targetlist items from - Mailing list pgsql-committers

From Tom Lane
Subject pgsql: Flatten join alias Vars before pulling up targetlist items from
Date
Msg-id E1VjwYN-00005w-Pq@gemulon.postgresql.org
Whole thread Raw
List pgsql-committers
Flatten join alias Vars before pulling up targetlist items from a subquery.

pullup_replace_vars()'s decisions about whether a pulled-up replacement
expression needs to be wrapped in a PlaceHolderVar depend on the assumption
that what looks like a Var behaves like a Var.  However, if the Var is a
join alias reference, later flattening of join aliases might replace the
Var with something that's not a Var at all, and should have been wrapped.

To fix, do a forcible pass of flatten_join_alias_vars() on the subquery
targetlist before we start to copy items out of it.  We'll re-run that
processing on the pulled-up expressions later, but that's harmless.

Per report from Ken Tanzer; the added regression test case is based on his
example.  This bug has been there since the PlaceHolderVar mechanism was
invented, but has escaped detection because the circumstances that trigger
it are fairly narrow.  You need a flattenable query underneath an outer
join, which contains another flattenable query inside a join of its own,
with a dangerous expression (a constant or something else non-strict)
in that one's targetlist.

Having seen this, I'm wondering if it wouldn't be prudent to do all
alias-variable flattening earlier, perhaps even in the rewriter.
But that would probably not be a back-patchable change.

Branch
------
REL9_1_STABLE

Details
-------
http://git.postgresql.org/pg/commitdiff/92a752151fa9c279595ab6f896534e49a5625920

Modified Files
--------------
src/backend/optimizer/prep/prepjointree.c |   12 +++++++
src/backend/optimizer/util/var.c          |    8 ++---
src/test/regress/expected/join.out        |   52 +++++++++++++++++++++++++++++
src/test/regress/sql/join.sql             |   31 +++++++++++++++++
4 files changed, 97 insertions(+), 6 deletions(-)


pgsql-committers by date:

Previous
From: Tom Lane
Date:
Subject: pgsql: Flatten join alias Vars before pulling up targetlist items from
Next
From: Peter Eisentraut
Date:
Subject: pgsql: Avoid potential buffer overflow crash