pgsql: Fix misbehavior of DROP OWNED BY with duplicate polroles entries

Started by Tom Laneabout 5 years ago1 messagescomitters
Jump to latest
#1Tom Lane
tgl@sss.pgh.pa.us

Fix misbehavior of DROP OWNED BY with duplicate polroles entries.

Ordinarily, a pg_policy.polroles array wouldn't list the same role
more than once; but CREATE POLICY does not prevent that. If we
perform DROP OWNED BY on a role that is listed more than once,
RemoveRoleFromObjectPolicy either suffered an assertion failure
or encountered a tuple-updated-by-self error. Rewrite it to cope
correctly with duplicate entries, and add a CommandCounterIncrement
call to prevent the other problem.

Per discussion, there's other cleanup that ought to happen here,
but this seems like the minimum essential fix.

Per bug #17062 from Alexander Lakhin. It's been broken all along,
so back-patch to all supported branches.

Discussion: /messages/by-id/17062-11f471ae3199ca23@postgresql.org

Branch
------
REL_12_STABLE

Details
-------
https://git.postgresql.org/pg/commitdiff/c58a41605ffabe8e4184b4c3b2d919638cd3357d

Modified Files
--------------
src/backend/commands/policy.c | 50 +++++++++++++++++--------------
src/test/regress/expected/rowsecurity.out | 9 ++++++
src/test/regress/sql/rowsecurity.sql | 10 +++++++
3 files changed, 46 insertions(+), 23 deletions(-)