Fix RI fast-path permission checks The fast path required table-level SELECT on the referenced table, rejecting checks that the SPI path allows with column-level grants. It also omitted the UPDATE privilege required by FOR KEY SHARE.
When table privileges do not suffice, use ExecCheckOneRelPerms() with the referenced key columns as selectedCols and an empty updatedCols. This accepts SELECT on all referenced columns and UPDATE on any column, the same privileges the executor would require for the SELECT ... FOR KEY SHARE the SPI path runs. Keep the table-privilege check as a shortcut that avoids constructing a column bitmap in the usual case. Add missing regression test coverage for the fixed cases. Reported-by: Nikolay Samokhvalov <[email protected]> Author: Nikolay Samokhvalov <[email protected]> Co-authored-by: Amit Langote <[email protected]> Discussion: https://www.postgr.es/m/CAM527d9BgPjeOOYmbCBTd57R145qHCk-dzw9qNq%2BnOrDq1j__A%40mail.gmail.com Backpatch-through: 19 Branch ------ master Details ------- https://git.postgresql.org/pg/commitdiff/2c45694a240e89c3f7d848d433f78e394521b6d6 Modified Files -------------- src/backend/utils/adt/ri_triggers.c | 47 ++++++++++++++++++------ src/test/regress/expected/foreign_key.out | 55 ++++++++++++++++++++++++++-- src/test/regress/sql/foreign_key.sql | 59 +++++++++++++++++++++++++++++-- 3 files changed, 146 insertions(+), 15 deletions(-)
