pgsql: Fix postmaster crash on whitespace-only oauth_validator_librarie - Mailing list pgsql-committers

From Daniel Gustafsson
Subject pgsql: Fix postmaster crash on whitespace-only oauth_validator_librarie
Date
Msg-id E1x7BdP-0000000072Q-1yos@gemulon.postgresql.org
Whole thread
List pgsql-committers
Fix postmaster crash on whitespace-only oauth_validator_libraries

The check_oauth_validator check for an empty validator list didn't test
for a string with only whitespace, which would cause the postmaster to
crash.  Instead of testing for the empty string cases, pass the config
value to SplitDirectoriesString unconditionally.  If an empty list is
returned then the input string was empty.  Since pstrdup cannot handle
NULL, assert that the string ie set.  While users cannot set the string
to NULL, it is initialized to NULL so guard against programmer error.

Check the parsed list instead.  Assert that the GUC string is non-NULL
before pstrdup(); users cannot set it to NULL, but the C variable is
initialized that way.

This also adds a TAP test that reloads a whitespace-only setting after
pg_hba_file_rules and waits until the existing backend sees the restored
GUC.

Author: Grigorev Jurij <ju.grigorev@ftdata.ru>
Reviewed-by: Jacob Champion <jacob.champion@enterprisedb.com>
Reviewed-by: Daniel Gustafsson <daniel@yesql.se>
Discussion: https://postgr.es/m/04fa84f6ebbe400f940e179ebe1070e9@localhost.localdomain
Backpatch-through: 18

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/bca67e5a33b07180c2f1703faf4443f2a1b92134

Modified Files
--------------
src/backend/libpq/auth-oauth.c                   | 27 ++++++++++++------------
src/test/modules/oauth_validator/t/001_server.pl | 18 ++++++++++++++++
2 files changed, 32 insertions(+), 13 deletions(-)


pgsql-committers by date:

Previous
From: Álvaro Herrera
Date:
Subject: pgsql: Have the REPACK decoding worker use timeout values from the stee
Next
From: Daniel Gustafsson
Date:
Subject: pgsql: Fix postmaster crash on whitespace-only oauth_validator_librarie