| From: | Noah Misch <noah(at)leadboat(dot)com> |
|---|---|
| To: | pgsql-committers(at)lists(dot)postgresql(dot)org |
| Subject: | pgsql: Add an output_plugin_libraries GUC to bless trusted output plugi |
| Date: | 2026-08-10 13:41:22 |
| Message-ID: | E1wtQFm-00000000y5E-3s0f@gemulon.postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-committers |
Add an output_plugin_libraries GUC to bless trusted output plugins
REPLICATION users were not previously subject to restrictions on output
plugin paths, so they were able to bypass LOAD-time protections during
logical decoding. Unfortunately, adding the standard LOAD restrictions
now would retroactively require all third-party output plugins to be
installed under the $libdir/plugins directory. This would prevent the
use of dynamic_library_path, introduce a wire incompatibility for
clients, and require all plugin authors to check that their libraries
are safe for use by any unprivileged user; we want to avoid that.
Instead, introduce an output_plugin_libraries GUC so that DBAs can
specify the output plugins that are trusted for use in logical decoding.
For simplicity, superusers are subject to the restriction as well
(though they're free to modify the GUC at will during a session, so no
power is actually lost).
The default setting is 'pgoutput, test_decoding'. If other third-party
plugins are in use, DBAs will need to modify this parameter after they
update. Some pointers have been added to the documentation to assist
with this.
Author: Jacob Champion <jacob(dot)champion(at)enterprisedb(dot)com>
Reported-by: Vladimir Tokarev <vladimirelitokarev(at)gmail(dot)com>
Reported-by: Yu Kunpeng <yu443940816(at)live(dot)com>
Reviewed-by: Álvaro Herrera <alvherre(at)kurilemu(dot)de>
Reviewed-by: Noah Misch <noah(at)leadboat(dot)com>
Reviewed-by: Robert Haas <robertmhaas(at)gmail(dot)com>
Reviewed-by: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Backpatch-through: 14
Security: CVE-2026-6471
Branch
------
REL_19_STABLE
Details
-------
https://git.postgresql.org/pg/commitdiff/5d47df21e89967e351df5ad7aa93bc3af40db64a
Author: Jacob Champion <jchampion(at)postgresql(dot)org>
Modified Files
--------------
contrib/test_decoding/expected/permissions.out | 11 +++
contrib/test_decoding/expected/repack.out | 1 -
contrib/test_decoding/expected/slot.out | 3 +
contrib/test_decoding/sql/permissions.sql | 8 +++
contrib/test_decoding/sql/slot.sql | 3 +
doc/src/sgml/config.sgml | 57 +++++++++++++++
doc/src/sgml/logical-replication.sgml | 13 +++-
src/backend/replication/logical/logical.c | 97 ++++++++++++++++++++++++--
src/backend/replication/pgrepack/pgrepack.c | 10 ++-
src/backend/utils/misc/guc_parameters.dat | 9 +++
src/backend/utils/misc/guc_tables.c | 1 +
src/backend/utils/misc/postgresql.conf.sample | 1 +
src/bin/pg_dump/dumputils.c | 1 +
src/bin/pg_upgrade/check.c | 85 +++++++++++++++++++++-
src/bin/pg_upgrade/t/003_logical_slots.pl | 53 ++++++++++++--
src/include/replication/logical.h | 3 +
src/test/subscription/t/100_bugs.pl | 27 ++++++-
17 files changed, 359 insertions(+), 24 deletions(-)
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Noah Misch | 2026-08-10 13:41:23 | pgsql: Check for USAGE privilege on the subtype in CREATE TYPE AS RANGE |
| Previous Message | Noah Misch | 2026-08-10 13:41:21 | pgsql: Guard against overlength time zone abbreviations in to_char(). |