summaryrefslogtreecommitdiff
path: root/doc/src/sgml/ref/alter_user_mapping.sgml
diff options
context:
space:
mode:
authorTom Lane <tgl@sss.pgh.pa.us>2018-03-19 18:49:53 -0400
committerTom Lane <tgl@sss.pgh.pa.us>2018-03-19 18:50:05 -0400
commit6497a18e6c1b5874566a77737ec3d381fded3ec2 (patch)
treece065f94d95b5871626cb5a4ba1aeaceeb84a7ff /doc/src/sgml/ref/alter_user_mapping.sgml
parent9ad21a6957ff2d8743e9a59ba062d3c009b24ec4 (diff)
Fix some corner-case issues in REFRESH MATERIALIZED VIEW CONCURRENTLY.
refresh_by_match_merge() has some issues in the way it builds a SQL query to construct the "diff" table: 1. It doesn't require the selected unique index(es) to be indimmediate. 2. It doesn't pay attention to the particular equality semantics enforced by a given index, but just assumes that they must be those of the column datatype's default btree opclass. 3. It doesn't check that the indexes are btrees. 4. It's insufficiently careful to ensure that the parser will pick the intended operator when parsing the query. (This would have been a security bug before CVE-2018-1058.) 5. It's not careful about indexes on system columns. The way to fix #4 is to make use of the existing code in ri_triggers.c for generating an arbitrary binary operator clause. I chose to move that to ruleutils.c, since that seems a more reasonable place to be exporting such functionality from than ri_triggers.c. While #1, #3, and #5 are just latent given existing feature restrictions, and #2 doesn't arise in the core system for lack of alternate opclasses with different equality behaviors, #4 seems like an issue worth back-patching. That's the bulk of the change anyway, so just back-patch the whole thing to 9.4 where this code was introduced. Discussion: https://postgr.es/m/13836.1521413227@sss.pgh.pa.us
Diffstat (limited to 'doc/src/sgml/ref/alter_user_mapping.sgml')
0 files changed, 0 insertions, 0 deletions