Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Commitfe2b538

Browse files
committed
Validate the OID argument of pg_import_system_collations().
"SELECT pg_import_system_collations(0)" caused an assertion failure.With a random nonzero argument --- or indeed with zero, in non-assertbuilds --- it would happily make pg_collation entries with garbagevalues of collnamespace. These are harmless as far as I can tell(unless maybe the OID happens to become used for a schema, later on?).In any case this isn't a security issue, since the function issuperuser-only. But it seems like a gotcha for unwary DBAs, so let'sadd a check that the given OID belongs to some schema.Back-patch to v10 where this function was introduced.
1 parent21d5a06 commitfe2b538

File tree

1 file changed

+5
-3
lines changed

1 file changed

+5
-3
lines changed

‎src/backend/commands/collationcmds.c

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -522,14 +522,16 @@ pg_import_system_collations(PG_FUNCTION_ARGS)
522522
Oidnspid=PG_GETARG_OID(0);
523523
intncreated=0;
524524

525-
/* silence compiler warning if we have no locale implementation at all */
526-
(void)nspid;
527-
528525
if (!superuser())
529526
ereport(ERROR,
530527
(errcode(ERRCODE_INSUFFICIENT_PRIVILEGE),
531528
errmsg("must be superuser to import system collations")));
532529

530+
if (!SearchSysCacheExists1(NAMESPACEOID,ObjectIdGetDatum(nspid)))
531+
ereport(ERROR,
532+
(errcode(ERRCODE_UNDEFINED_SCHEMA),
533+
errmsg("schema with OID %u does not exist",nspid)));
534+
533535
/* Load collations known to libc, using "locale -a" to enumerate them */
534536
#ifdefREAD_LOCALE_A_OUTPUT
535537
{

0 commit comments

Comments
 (0)

[8]ページ先頭

©2009-2025 Movatter.jp