This is an automated email from the ASF dual-hosted git repository.

leborchuk pushed a commit to branch REL_2_STABLE
in repository https://gitbox.apache.org/repos/asf/cloudberry.git

commit 4391e256fe8dc3ec05b64695d1ace7646c467116
Author: Tom Lane <[email protected]>
AuthorDate: Wed Jan 3 17:40:38 2024 -0500

    Avoid masking EOF (no-password-supplied) conditions in auth.c.
    
    CheckPWChallengeAuth() would return STATUS_ERROR if the user does not
    exist or has no password assigned, even if the client disconnected
    without responding to the password challenge (as libpq often will,
    for example).  We should return STATUS_EOF in that case, and the
    lower-level functions do, but this code level got it wrong since the
    refactoring done in 7ac955b34.  This breaks the intent of not logging
    anything for EOF cases (cf. comments in auth_failed()) and might
    also confuse users of ClientAuthentication_hook.
    
    Per report from Liu Lang.  Back-patch to all supported versions.
    
    Discussion: 
https://postgr.es/m/[email protected]
    (cherry picked from commit 9b042e27eb1dea6adce8d939aa658ef91d911ce2)
---
 src/backend/libpq/auth.c | 12 +++++-------
 1 file changed, 5 insertions(+), 7 deletions(-)

diff --git a/src/backend/libpq/auth.c b/src/backend/libpq/auth.c
index b0e1f15c829..fdc6fb47a65 100644
--- a/src/backend/libpq/auth.c
+++ b/src/backend/libpq/auth.c
@@ -1221,15 +1221,13 @@ CheckPWChallengeAuth(Port *port, char **logdetail)
 
        if (shadow_pass)
                pfree(shadow_pass);
-
-       /*
-        * If get_role_password() returned error, return error, even if the
-        * authentication succeeded.
-        */
-       if (!shadow_pass)
+       else
        {
+               /*
+                * If get_role_password() returned error, authentication better 
not
+                * have succeeded.
+                */
                Assert(auth_result != STATUS_OK);
-               return STATUS_ERROR;
        }
 
        if (auth_result == STATUS_OK)


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to