Fix permissions check on pg_stat_get_wal_senders

Started by Feike Steenbergenover 8 years ago7 messageshackers
Beta feature

Hackorum builds and tests every patch posted to the lists, not only commitfest submissions. This is Hackorum's own CI rather than the PostgreSQL project's, and it is still under testing - please report anything that looks wrong.

won't retrysuccessCI history

You can run a PostgreSQL built from this patch straight from Docker, with no checkout and no build:

docker run --rm -p 5432:5432 ghcr.io/hackorum-dev/postgres-patch:t37917
psql -h localhost -U postgres

Built from patchset v3 (message #3), July 27, 2026 at 09:32 PM.

Every patchset is also pushed to a branch of our PostgreSQL fork, so you can check out the same tree CI built. Without a PostgreSQL checkout:

git clone --branch t37917_3 https://github.com/hackorum-dev/postgres.git

In a checkout you already have, add the fork once:

git remote add hackorum https://github.com/hackorum-dev/postgres.git

then, for this patchset and every later one:

git fetch hackorum t37917_3 && git checkout t37917_3

Patchset v3 (message #3) is on t37917_3

Jump to latest
#1Feike Steenbergen
feikesteenbergen@gmail.com

Fix permissions check on pg_stat_get_wal_senders

Commit 25fff40798fc4ac11a241bfd9ab0c45c085e2212 introduced the
possibility for the pg_read_all_stats to have access to all pg_stat_*
views.
In the discussion, the pg_stat_replication and pg_stat_wal_receiver
views were also considered to be part of that, however
pg_stat_get_wal_senders was somehow not part of that commit, that
seems an oversight.

1: /messages/by-id/CA+OCxoyYxO+Jmzv2Micj4uAaQdAi6nq0w25BPQgLLxsrvTmREw@mail.gmail.com%5C

regards,

Feike Steenbergen

Attachments:

0001-Fix-permissions-check-on-pg_stat_get_wal_senders.patchapplication/octet-stream; name=0001-Fix-permissions-check-on-pg_stat_get_wal_senders.patchDownload+6-6
#2Michael Paquier
michael@paquier.xyz
In reply to: Feike Steenbergen (#1)
Re: Fix permissions check on pg_stat_get_wal_senders

On Thu, Dec 21, 2017 at 7:30 PM, Feike Steenbergen
<feikesteenbergen@gmail.com> wrote:

Fix permissions check on pg_stat_get_wal_senders

Commit 25fff40798fc4ac11a241bfd9ab0c45c085e2212 introduced the
possibility for the pg_read_all_stats to have access to all pg_stat_*
views.
In the discussion, the pg_stat_replication and pg_stat_wal_receiver
views were also considered to be part of that, however
pg_stat_get_wal_senders was somehow not part of that commit, that
seems an oversight.

1: /messages/by-id/CA+OCxoyYxO+Jmzv2Micj4uAaQdAi6nq0w25BPQgLLxsrvTmREw@mail.gmail.com%5C

Yes, that's a bug, albeit a minor one.

-        * Only superusers can see details. Other users only get the pid value
-        * to know whether it is a WAL receiver, but no details.
+        * Only superusers and members of pg_read_all_stats can see details.
+        * Other users only get the pid value to know it's a
walsender, but no details.
You mean a WAL receiver here, not a WAL sender.
-- 
Michael
#3Feike Steenbergen
feikesteenbergen@gmail.com
In reply to: Michael Paquier (#2)
Re: Fix permissions check on pg_stat_get_wal_senders

On 21 December 2017 at 14:11, Michael Paquier <michael.paquier@gmail.com> wrote:

You mean a WAL receiver here, not a WAL sender.

Fixed, thanks

Attachments:

t37917_3
0002-Fix-permissions-check-on-pg_stat_get_wal_senders.patchapplication/octet-stream; name=0002-Fix-permissions-check-on-pg_stat_get_wal_senders.patchDownload+7-5
#4Michael Paquier
michael@paquier.xyz
In reply to: Feike Steenbergen (#3)
Re: Fix permissions check on pg_stat_get_wal_senders

On Fri, Dec 22, 2017 at 07:49:34AM +0100, Feike Steenbergen wrote:

On 21 December 2017 at 14:11, Michael Paquier <michael.paquier@gmail.com> wrote:

You mean a WAL receiver here, not a WAL sender.

Fixed, thanks

[nit]
 		/*
 -		 * Only superusers can see details. Other users only get the pid value
+		 * Only superusers and members of pg_read_all_stats can see details.
+		 * Other users only get the pid value
 		 * to know whether it is a WAL receiver, but no details.
 		 */

Incorrect comment format.
[/nit]

Committers run pgindent on each patch before committing anyway, and what
you are proposing here looks good to me, so I am marking that as ready for
committer. Simon, as the original committer of 25fff407, could you look
at what is proposed here?
--
Michael

#5Simon Riggs
simon@2ndQuadrant.com
In reply to: Michael Paquier (#4)
Re: Fix permissions check on pg_stat_get_wal_senders

On 23 December 2017 at 10:56, Michael Paquier <michael.paquier@gmail.com> wrote:

On Fri, Dec 22, 2017 at 07:49:34AM +0100, Feike Steenbergen wrote:

On 21 December 2017 at 14:11, Michael Paquier <michael.paquier@gmail.com> wrote:

You mean a WAL receiver here, not a WAL sender.

Fixed, thanks

[nit]
/*
-               * Only superusers can see details. Other users only get the pid value
+                * Only superusers and members of pg_read_all_stats can see details.
+                * Other users only get the pid value
* to know whether it is a WAL receiver, but no details.
*/

Incorrect comment format.
[/nit]

Committers run pgindent on each patch before committing anyway, and what
you are proposing here looks good to me, so I am marking that as ready for
committer. Simon, as the original committer of 25fff407, could you look
at what is proposed here?

Yup, I got this.

--
Simon Riggs http://www.2ndQuadrant.com/
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services

#6Feike Steenbergen
feikesteenbergen@gmail.com
In reply to: Simon Riggs (#5)
Re: Fix permissions check on pg_stat_get_wal_senders

On 5 January 2018 at 15:19, Simon Riggs <simon@2ndquadrant.com> wrote:

Yup, I got this.

I saw the commit in the master branch but not in the REL_10_STABLE branch,
I'm totally not up-to-date with the backpatching process, but I was wondering
if it still needs to be added to REL_10_STABLE

regards,

Feike

#7Simon Riggs
simon@2ndQuadrant.com
In reply to: Feike Steenbergen (#6)
Re: Fix permissions check on pg_stat_get_wal_senders

On 24 January 2018 at 13:15, Feike Steenbergen
<feikesteenbergen@gmail.com> wrote:

On 5 January 2018 at 15:19, Simon Riggs <simon@2ndquadrant.com> wrote:

Yup, I got this.

I saw the commit in the master branch but not in the REL_10_STABLE branch,
I'm totally not up-to-date with the backpatching process, but I was wondering
if it still needs to be added to REL_10_STABLE

Yep, as the commit message said: "then later backpatch to 10". Will do.

--
Simon Riggs http://www.2ndQuadrant.com/
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services