expand refint docs with usage info

Started by Nathan Bossart2 months ago5 messageshackers
Jump to latest
#1Nathan Bossart
nathandbossart@gmail.com

The security team has received a couple of reports about potential SQL
injection opportunities via refint's trigger arguments. We discussed this
while preparing CVE-2026-6637 and concluded that forcibly quoting these
arguments would be much more likely to break working code than to prevent
any exploits. Unlike data values, the table/column names come from trigger
arguments, and there is little reason for a trigger author to put hostile
inputs into those arguments.

The attached documentation patch was originally intended to go along with
CVE-2026-6637, but we ultimately scoped it down to only the
security-relevant parts. This should be back-patched to v14. Note that we
are preparing to removing refint completely in v20, but IMHO this doc
update is still worth doing.

Thoughts?

--
nathan

Attachments:

v1-0001-expand-refint-docs-with-usage-info.patchtext/plain; charset=us-asciiDownload+57-2
#2Christoph Berg
myon@debian.org
In reply to: Nathan Bossart (#1)
Re: expand refint docs with usage info

Re: Nathan Bossart

This should be back-patched to v14. Note that we are preparing to
removing refint completely in v20, but IMHO this doc update is still
worth doing.

I suggest mentioning the deprecation in the same place.

Christoph

#3SATYANARAYANA NARLAPURAM
satyanarlapuram@gmail.com
In reply to: Nathan Bossart (#1)
Re: expand refint docs with usage info

Hi,

On Tue, May 26, 2026 at 9:53 AM Nathan Bossart <nathandbossart@gmail.com>
wrote:

The security team has received a couple of reports about potential SQL
injection opportunities via refint's trigger arguments. We discussed this
while preparing CVE-2026-6637 and concluded that forcibly quoting these
arguments would be much more likely to break working code than to prevent
any exploits. Unlike data values, the table/column names come from trigger
arguments, and there is little reason for a trigger author to put hostile
inputs into those arguments.

The attached documentation patch was originally intended to go along with
CVE-2026-6637, but we ultimately scoped it down to only the
security-relevant parts. This should be back-patched to v14. Note that we
are preparing to removing refint completely in v20, but IMHO this doc
update is still worth doing.

Thoughts?

LGTM.

Thanks,
Satya

#4Nathan Bossart
nathandbossart@gmail.com
In reply to: Christoph Berg (#2)
Re: expand refint docs with usage info

On Tue, May 26, 2026 at 07:04:30PM +0200, Christoph Berg wrote:

Re: Nathan Bossart

This should be back-patched to v14. Note that we are preparing to
removing refint completely in v20, but IMHO this doc update is still
worth doing.

I suggest mentioning the deprecation in the same place.

Agreed, but I'd rather leave that for the removal effort.

--
nathan

#5Nathan Bossart
nathandbossart@gmail.com
In reply to: Nathan Bossart (#4)
Re: expand refint docs with usage info

Committed.

--
nathan