On Tue, Sep 22, 2026 at 10:03:10AM +0000, Bertrand Drouvot wrote: > I'm not sure the user ID alone is enough though: if B reuses A's ProcNumber, > pg_stat_get_backend_wal(B_pid) could still return A's cached statistics when > the caller is allowed to see A's data. > > I'd keep the PID check from 0002 as well. A generation would be more robust > against PID reuse, as done for example for AIO handles, but introducing a > backend generation seems like too much for this case. > > So storing both seems like the simplest approach: the user ID for the ACL > check and the PID for matching the statistics to the requested backend.
The PID would also act as a kind of weaker generation number, slightly weaker but simpler. So that works here. Perhaps you would like to give it a shot? -- Michael
signature.asc
Description: PGP signature
