| From: | Jim Jones <jim(dot)jones(at)uni-muenster(dot)de> |
|---|---|
| To: | Alex Liapychev <coder(dot)sam(at)gmail(dot)com>, tomas(at)vondra(dot)me |
| Cc: | matheusssilv97 <matheusssilv97(at)gmail(dot)com>, Chao Li <li(dot)evan(dot)chao(at)gmail(dot)com>, "masao(dot)fujii" <masao(dot)fujii(at)gmail(dot)com>, "david(dot)g(dot)johnston" <david(dot)g(dot)johnston(at)gmail(dot)com>, tgl <tgl(at)sss(dot)pgh(dot)pa(dot)us>, "huseyin(dot)d3r" <huseyin(dot)d3r(at)gmail(dot)com>, pgsql-hackers <pgsql-hackers(at)lists(dot)postgresql(dot)org>, chochoforwork(at)gmail(dot)com, 44973863(at)qq(dot)com |
| Subject: | Re: COMMENTS are not being copied in CREATE TABLE LIKE |
| Date: | 2026-10-01 16:49:06 |
| Message-ID: | 6cc4ef4b-f997-4453-ab40-bc012d342fa0@uni-muenster.de |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-hackers |
On 01/10/2026 01:14, Alex Liapychev wrote:
>
> My personal view is that adding this functionality carries more risks
> than leaving it out. Although the code is relatively small and appears
> to work correctly, I would not merge it into the codebase.
You mean the multiple tables scenario or the whole patch?
> An example of how this functionality could be used maliciously:
>
> * A workflow creates a new table from several template tables in
> response to an event.
Can you elaborate more on this scenario? I'm afraid I didn't get your
point here. Thanks!
> * An adversarial user with sufficient database access adds one comment
> to each of two template tables. The combined size of these comments
> exceeds |MaxAllocSize|, causing the automation to fail unexpectedly.
An "adversarial" user with enough privileges can do many things break
it, like renaming a column causing a conflict. I see this large comment
scenario as purely theoretical -- at least I fail to see any practical
use case ever exhausting this limit.
Thanks!
Best, Jim
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Andres Freund | 2026-10-01 16:58:34 | Re: [PATCH] Corruption Issue: Fix missing tts_tid in ExecForceStoreHeapTuple |
| Previous Message | Nikolay Samokhvalov | 2026-10-01 16:47:33 | Re: postgres_fdw: transaction mode inheritance corner cases |