pgsql: Handle ALTER EXTENSION ADD/DROP with pg_init_privs

From: Stephen Frost <sfrost(at)snowman(dot)net>
To: pgsql-committers(at)postgresql(dot)org
Subject: pgsql: Handle ALTER EXTENSION ADD/DROP with pg_init_privs
Date: 2017-01-30 04:06:41
Message-ID: [email protected]
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Handle ALTER EXTENSION ADD/DROP with pg_init_privs

In commit 6c268df, pg_init_privs was added to track the initial
privileges of catalog objects and extensions. Unfortunately, that
commit didn't include understanding of ALTER EXTENSION ADD/DROP, which
allows the objects associated with an extension to be changed after the
initial CREATE EXTENSION script has been run.

The result of this meant that ACLs for objects added through
ALTER EXTENSION ADD were not recorded into pg_init_privs and we would
end up including those ACLs in pg_dump when we shouldn't have.

This commit corrects that by making sure to have pg_init_privs updated
when ALTER EXTENSION ADD/DROP is run, recording the permissions as they
are at ALTER EXTENSION ADD time, and removing any if/when ALTER
EXTENSION DROP is called.

This issue was pointed out by Moshe Jacobson as commentary on bug #14456
(which was actually a bug about versions prior to 9.6 not handling
custom ACLs on extensions correctly, an issue now addressed with
pg_init_privs in 9.6).

Back-patch to 9.6 where pg_init_privs was introduced.

Branch
------
REL9_6_STABLE

Details
-------
http://git.postgresql.org/pg/commitdiff/20064c0ec201fd2302757c1fdb2279e9dc9a4030

Modified Files
--------------
src/backend/catalog/aclchk.c | 436 +++++++++++++++++++--
src/backend/commands/extension.c | 21 +
src/include/utils/acl.h | 4 +
.../modules/test_pg_dump/expected/test_pg_dump.out | 100 ++++-
src/test/modules/test_pg_dump/sql/test_pg_dump.sql | 108 ++++-
src/test/modules/test_pg_dump/t/001_base.pl | 92 +++++
6 files changed, 732 insertions(+), 29 deletions(-)

Browse pgsql-committers by date

  From Date Subject
Next Message Heikki Linnakangas 2017-01-30 08:54:41 pgsql: Remove leftover reference to "indirect blocks" in comment.
Previous Message Robert Haas 2017-01-27 22:23:40 pgsql: Fix typo in comment.