postgresql/src/backend/catalog
Joe Conway 7b4bfc87d5 Plug RLS related information leak in pg_stats view.
The pg_stats view is supposed to be restricted to only show rows
about tables the user can read. However, it sometimes can leak
information which could not otherwise be seen when row level security
is enabled. Fix that by not showing pg_stats rows to users that would
be subject to RLS on the table the row is related to. This is done
by creating/using the newly introduced SQL visible function,
row_security_active().

Along the way, clean up three call sites of check_enable_rls(). The second
argument of that function should only be specified as other than
InvalidOid when we are checking as a different user than the current one,
as in when querying through a view. These sites were passing GetUserId()
instead of InvalidOid, which can cause the function to return incorrect
results if the current user has the BYPASSRLS privilege and row_security
has been set to OFF.

Additionally fix a bug causing RI Trigger error messages to unintentionally
leak information when RLS is enabled, and other minor cleanup and
improvements. Also add WITH (security_barrier) to the definition of pg_stats.

Bumped CATVERSION due to new SQL functions and pg_stats view definition.

Back-patch to 9.5 where RLS was introduced. Reported by Yaroslav.
Patch by Joe Conway and Dean Rasheed with review and input by
Michael Paquier and Stephen Frost.
2015-07-28 13:21:22 -07:00
..
.gitignore Convert cvsignore to gitignore, and add .gitignore for build targets. 2010-09-22 12:57:04 +02:00
Catalog.pm pgindent run for 9.5 2015-05-23 21:35:49 -04:00
Makefile Redesign tablesample method API, and do extensive code review. 2015-07-25 14:39:00 -04:00
README Fix typo in README 2014-01-27 09:33:18 +02:00
aclchk.c pgindent run for 9.5 2015-05-23 21:35:49 -04:00
catalog.c Collection of typo fixes. 2015-05-20 16:56:22 +03:00
dependency.c Redesign tablesample method API, and do extensive code review. 2015-07-25 14:39:00 -04:00
genbki.pl pgindent run for 9.5 2015-05-23 21:35:49 -04:00
heap.c Integrate pg_upgrade_support module into backend 2015-04-14 19:26:37 -04:00
index.c Fix some oversights in BRIN patch. 2015-07-21 13:38:24 -04:00
indexing.c Add support for INSERT ... ON CONFLICT DO NOTHING/UPDATE. 2015-05-08 05:43:10 +02:00
information_schema.sql Add transforms feature 2015-04-26 10:33:14 -04:00
namespace.c Replace some appendStringInfo* calls with more appropriate variants 2015-05-11 20:38:55 -04:00
objectaccess.c Update copyright for 2015 2015-01-06 11:43:47 -05:00
objectaddress.c Fix misuse of TextDatumGetCString(). 2015-07-02 17:02:08 -04:00
pg_aggregate.c pgindent run for 9.5 2015-05-23 21:35:49 -04:00
pg_collation.c Update copyright for 2015 2015-01-06 11:43:47 -05:00
pg_constraint.c Return ObjectAddress in many ALTER TABLE sub-routines 2015-03-25 17:17:56 -03:00
pg_conversion.c Silence warning in non-assert-enabled build 2015-03-05 15:38:37 -03:00
pg_db_role_setting.c Update copyright for 2015 2015-01-06 11:43:47 -05:00
pg_depend.c Update copyright for 2015 2015-01-06 11:43:47 -05:00
pg_enum.c pgindent run for 9.5 2015-05-23 21:35:49 -04:00
pg_inherits.c Update copyright for 2015 2015-01-06 11:43:47 -05:00
pg_largeobject.c Update copyright for 2015 2015-01-06 11:43:47 -05:00
pg_namespace.c Update copyright for 2015 2015-01-06 11:43:47 -05:00
pg_operator.c Change many routines to return ObjectAddress rather than OID 2015-03-03 14:10:50 -03:00
pg_proc.c pgindent run for 9.5 2015-05-23 21:35:49 -04:00
pg_range.c Update copyright for 2015 2015-01-06 11:43:47 -05:00
pg_shdepend.c Rename pg_shdepend.c's typedef "objectType" to SharedDependencyObjectType. 2015-05-24 13:03:45 -04:00
pg_type.c pgindent run for 9.5 2015-05-23 21:35:49 -04:00
sql_feature_packages.txt > I have installed your patch and adjusted the names of the standards 2004-12-02 22:51:28 +00:00
sql_features.txt Support GROUPING SETS, CUBE and ROLLUP. 2015-05-16 03:46:31 +02:00
storage.c Collection of typo fixes. 2015-05-20 16:56:22 +03:00
system_views.sql Plug RLS related information leak in pg_stats view. 2015-07-28 13:21:22 -07:00
toasting.c pgindent run for 9.5 2015-05-23 21:35:49 -04:00

README

src/backend/catalog/README

System Catalog
==============

This directory contains .c files that manipulate the system catalogs;
src/include/catalog contains the .h files that define the structure
of the system catalogs.

When the compile-time scripts (Gen_fmgrtab.pl and genbki.pl)
execute, they grep the DATA statements out of the .h files and munge
these in order to generate the postgres.bki file.  The .bki file is then
used as input to initdb (which is just a wrapper around postgres
running single-user in bootstrapping mode) in order to generate the
initial (template) system catalog relation files.

-----------------------------------------------------------------

People who are going to hose around with the .h files should be aware
of the following facts:

- It is very important that the DATA statements be properly formatted
(e.g., no broken lines, proper use of white-space and _null_).  The
scripts are line-oriented and break easily.  In addition, the only
documentation on the proper format for them is the code in the
bootstrap/ directory.  Just be careful when adding new DATA
statements.

- Some catalogs require that OIDs be preallocated to tuples because
of cross-references from other pre-loaded tuples.  For example, pg_type
contains pointers into pg_proc (e.g., pg_type.typinput), and pg_proc
contains back-pointers into pg_type (pg_proc.proargtypes).  For such
cases, the OID assigned to a tuple may be explicitly set by use of the
"OID = n" clause of the .bki insert statement.  If no such pointers are
required to a given tuple, then the OID = n clause may be omitted
(then the system generates an OID in the usual way, or leaves it 0 in a
catalog that has no OIDs).  In practice we usually preassign OIDs
for all or none of the pre-loaded tuples in a given catalog, even if only
some of them are actually cross-referenced.

- We also sometimes preallocate OIDs for catalog tuples whose OIDs must
be known directly in the C code.  In such cases, put a #define in the
catalog's .h file, and use the #define symbol in the C code.  Writing
the actual numeric value of any OID in C code is considered very bad form.
Direct references to pg_proc OIDs are common enough that there's a special
mechanism to create the necessary #define's automatically: see
backend/utils/Gen_fmgrtab.pl.  We also have standard conventions for setting
up #define's for the pg_class OIDs of system catalogs and indexes.  For all
the other system catalogs, you have to manually create any #define's you
need.

- If you need to find a valid OID for a new predefined tuple,
use the unused_oids script.  It generates inclusive ranges of
*unused* OIDs (e.g., the line "45-900" means OIDs 45 through 900 have
not been allocated yet).  Currently, OIDs 1-9999 are reserved for manual
assignment; the unused_oids script simply looks through the include/catalog
headers to see which ones do not appear in "OID =" clauses in DATA lines.
(As of Postgres 8.1, it also looks at CATALOG and DECLARE_INDEX lines.)
You can also use the duplicate_oids script to check for mistakes.

- The OID counter starts at 10000 at bootstrap.  If a catalog row is in a
table that requires OIDs, but no OID was preassigned by an "OID =" clause,
then it will receive an OID of 10000 or above.

- To create a "BOOTSTRAP" table you have to do a lot of extra work: these
tables are not created through a normal CREATE TABLE operation, but spring
into existence when first written to during initdb.  Therefore, you must
manually create appropriate entries for them in the pre-loaded contents of
pg_class, pg_attribute, and pg_type.  Avoid making new catalogs be bootstrap
catalogs if at all possible; generally, only tables that must be written to
in order to create a table should be bootstrapped.

- Certain BOOTSTRAP tables must be at the start of the Makefile
POSTGRES_BKI_SRCS variable, as these cannot be created through the standard
heap_create_with_catalog process, because it needs these tables to exist
already.  The list of files this currently includes is:
	pg_proc.h pg_type.h pg_attribute.h pg_class.h
Within this list, pg_type.h must come before pg_attribute.h.
Also, indexing.h must be last, since the indexes can't be created until all
the tables are in place, and toasting.h should probably be next-to-last
(or at least after all the tables that need toast tables).  There are
reputedly some other order dependencies in the .bki list, too.

-----------------------------------------------------------------

When munging the .c files, you should be aware of certain conventions:

- The system catalog cache code (and most catalog-munging code in
general) assumes that the fixed-length portions of all system catalog
tuples are in fact present, because it maps C struct declarations onto
them.  Thus, the variable-length fields must all be at the end, and
only the variable-length fields of a catalog tuple are permitted to be
NULL.  For example, if you set pg_type.typrelid to be NULL, a
piece of code will likely perform "typetup->typrelid" (or, worse,
"typetup->typelem", which follows typrelid).  This will result in
random errors or even segmentation violations.  Hence, do NOT insert
catalog tuples that contain NULL attributes except in their
variable-length portions!  (The bootstrapping code is fairly good about
marking NOT NULL each of the columns that can legally be referenced via
C struct declarations ... but those markings won't be enforced against
DATA commands, so you must get it right in a DATA line.)

- Modification of the catalogs must be performed with the proper
updating of catalog indexes!  That is, most catalogs have indexes
on them; when you munge them using the executor, the executor will
take care of doing the index updates, but if you make direct access
method calls to insert new or modified tuples into a heap, you must
also make the calls to insert the tuple into ALL of its indexes!  If
not, the new tuple will generally be "invisible" to the system because
most of the accesses to the catalogs in question will be through the
associated indexes.