Re: check_circularity does not prevent from creating circular grants

From: Ayush Tiwari <ayushtiwari(dot)slg01(at)gmail(dot)com>
To: Andrey Borodin <x4mmm(at)yandex-team(dot)ru>
Cc: Kirill Reshke <reshkekirill(at)gmail(dot)com>, PostgreSQL Hackers <pgsql-hackers(at)lists(dot)postgresql(dot)org>
Subject: Re: check_circularity does not prevent from creating circular grants
Date: 2026-08-10 10:35:29
Message-ID: CAJTYsWW_yxKep5FrqPEs13UExjK8CSd7gxeN1P=sZM6FBnyP4g@mail.gmail.com
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Hi,

On Mon, 10 Aug 2026 at 15:13, Andrey Borodin <x4mmm(at)yandex-team(dot)ru> wrote:

>
>
> > On 10 Aug 2026, at 12:03, Kirill Reshke <reshkekirill(at)gmail(dot)com> wrote:
> >
> > I discovered a sequence of ddl which creates grant configuration,
> > unrestorable from pg_dump-pg_restore.
>
> The diagnosis looks right, but I think the proposed fix is too broad.
>
> Suppose the owner grants an option directly to role A, role B is a member
> of A, and A grants the option to B. This is not circular: after revoking
> B's membership in A, the grant from A remains valid. Changing the loop to
> has_privs_of_role(B, A) would remove A's independently held option and
> reject this case.
>
> select_best_grantor() uses aclmask_direct() instead of aclmask(). WDYT
> about
> this route?
>

There was some prior discussion around this area on [0].

Not sure if it's the same block, but just adding reference.

Regards,
Ayush

[0]
https://www.postgresql.org/message-id/CAJTYsWUvyQchDAA6y2a9YdLcApG%3DccArpsbr77FeNZyx40bnmQ%40mail.gmail.com

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message John Naylor 2026-08-10 10:41:31 Re: [PATCH] Use ssup_datum_*_cmp for int2, oid, and oid8 sort support
Previous Message Joel Jacobson 2026-08-10 10:29:28 Re: Key joins