Re: CVE-2017-7484-induced bugs, or, btree cmp functions are not leakproof?

From: Dilip Kumar <dilipbalaut(at)gmail(dot)com>
To: Amit Langote <Langote_Amit_f8(at)lab(dot)ntt(dot)co(dot)jp>
Cc: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Amit Langote <amitlangote09(at)gmail(dot)com>, Peter Eisentraut <peter(dot)eisentraut(at)2ndquadrant(dot)com>, PostgreSQL Hackers <pgsql-hackers(at)lists(dot)postgresql(dot)org>
Subject: Re: CVE-2017-7484-induced bugs, or, btree cmp functions are not leakproof?
Date: 2019-07-10 04:29:19
Message-ID: CAFiTN-sWVz9JXuzLSjnASvR1WPvyEOpqWcjafLpdHODGwYO9sg@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On Wed, Jul 10, 2019 at 9:44 AM Dilip Kumar <dilipbalaut(at)gmail(dot)com> wrote:
>
> On Fri, Nov 2, 2018 at 1:34 PM Amit Langote
> <Langote_Amit_f8(at)lab(dot)ntt(dot)co(dot)jp> wrote:
> >
> > On 2018/11/01 20:34, Dilip Kumar wrote:
> > > On Mon, Oct 29, 2018 at 2:53 PM Amit Langote wrote:
> > >> Anyway, why don't we just use the child table's AppendRelInfo to get the
> > >> parent's version of varattno instead of creating a new function? It can
> > >> be done as shown in the attached revised version of the portion of the
> > >> patch changing selfuncs.c. Please take a look.
> > >
> > > +1
> >
> > Okay, here are two patches:
> >
> > 0001 adds a new RelOptInfo member inh_root_parent that's set for
> > inheritance child otherrels and contains the RT index of the inheritance
> > parent table mentioned in the query from which they originated.
> >
> > 0002 is your patch that modifies examine_variable, etc. to use the
> > permissions granted on parent before reading stats on otherrel inheritance
> > child tables. I've added your name as the author in the 2nd patch.
> >
>
> I have looked into the patches and these look fine to me. I have also
> added it to the next commitfest.
>
Hi Amit,

I have reviewed your 0001 patch and I think you have already taken a
look on 0002. So should I move it to "Ready for Committer" or you
want to review it further?

--
Regards,
Dilip Kumar
EnterpriseDB: http://www.enterprisedb.com

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Kyotaro Horiguchi 2019-07-10 04:35:52 Re: shared-memory based stats collector
Previous Message Paul A Jungwirth 2019-07-10 04:26:33 Re: range_agg