pgsql: Fix RI fast-path permission checks - Mailing list pgsql-committers

From Amit Langote
Subject pgsql: Fix RI fast-path permission checks
Date
Msg-id E1x7kSz-00000000L1G-3iXU@gemulon.postgresql.org
Whole thread
List pgsql-committers
Fix RI fast-path permission checks

The fast path required table-level SELECT on the referenced table,
rejecting checks that the SPI path allows with column-level grants.
It also omitted the UPDATE privilege required by FOR KEY SHARE.

When table privileges do not suffice, use ExecCheckOneRelPerms() with
the referenced key columns as selectedCols and an empty updatedCols.
This accepts SELECT on all referenced columns and UPDATE on any column,
the same privileges the executor would require for the SELECT ... FOR
KEY SHARE the SPI path runs.  Keep the table-privilege check as a
shortcut that avoids constructing a column bitmap in the usual case.

Add missing regression test coverage for the fixed cases.

Reported-by: Nikolay Samokhvalov <nik@postgres.ai>
Author: Nikolay Samokhvalov <nik@postgres.ai>
Co-authored-by: Amit Langote <amitlangote09@gmail.com>
Discussion: https://www.postgr.es/m/CAM527d9BgPjeOOYmbCBTd57R145qHCk-dzw9qNq%2BnOrDq1j__A%40mail.gmail.com
Backpatch-through: 19

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/2c45694a240e89c3f7d848d433f78e394521b6d6

Modified Files
--------------
src/backend/utils/adt/ri_triggers.c       | 47 ++++++++++++++++++------
src/test/regress/expected/foreign_key.out | 55 ++++++++++++++++++++++++++--
src/test/regress/sql/foreign_key.sql      | 59 +++++++++++++++++++++++++++++--
3 files changed, 146 insertions(+), 15 deletions(-)


pgsql-committers by date:

Previous
From: Amit Langote
Date:
Subject: pgsql: Fix RI fast-path permission checks
Next
From: Michael Paquier
Date:
Subject: pgsql: Add test for logical decoding with an oid8 TOAST table and OID >