Re: Add a permission check to pg_stat_get_backend_subxact() - Mailing list pgsql-hackers

From Michael Paquier
Subject Re: Add a permission check to pg_stat_get_backend_subxact()
Date
Msg-id arJlSpeSs8yPKipu@paquier.xyz
Whole thread
In response to Re: Add a permission check to pg_stat_get_backend_subxact()  (Bertrand Drouvot <bertranddrouvot.pg@gmail.com>)
Responses Re: Add a permission check to pg_stat_get_backend_subxact()
List pgsql-hackers
On Tue, Sep 22, 2026 at 10:03:10AM +0000, Bertrand Drouvot wrote:
> I'm not sure the user ID alone is enough though: if B reuses A's ProcNumber,
> pg_stat_get_backend_wal(B_pid) could still return A's cached statistics when
> the caller is allowed to see A's data.
>
> I'd keep the PID check from 0002 as well. A generation would be more robust
> against PID reuse, as done for example for AIO handles, but introducing a
> backend generation seems like too much for this case.
>
> So storing both seems like the simplest approach: the user ID for the ACL
> check and the PID for matching the statistics to the requested backend.

The PID would also act as a kind of weaker generation number, slightly
weaker but simpler.  So that works here.  Perhaps you would like to
give it a shot?
--
Michael

Attachment

pgsql-hackers by date:

Previous
From: Nisha Moond
Date:
Subject: Re: Crashes on a partition whose concurrent detach never finished
Next
From: Pavel Luzanov
Date:
Subject: Re: Several issues with postgres_fdw stats import