mirror of
				https://github.com/postgres/postgres.git
				synced 2025-10-22 14:32:25 +03:00 
			
		
		
		
	Allow pg_read_all_stats to access all stats views again
The views pg_stat_progress_* had not gotten the memo that pg_read_all_stats is supposed to be able to read all statistics. Also make a pass over all text-returning pg_stat_xyz functions that could return "insufficient privilege" and make sure they also respect pg_read_all_status. Reported-by: Andrey M. Borodin Reviewed-by: Andrey M. Borodin, Kyotaro Horiguchi Discussion: https://postgr.es/m/13145F2F-8458-4977-9D2D-7B2E862E5722@yandex-team.ru
This commit is contained in:
		| @@ -33,6 +33,8 @@ | ||||
|  | ||||
| #define UINT32_ACCESS_ONCE(var)		 ((uint32)(*((volatile uint32 *)&(var)))) | ||||
|  | ||||
| #define HAS_PGSTAT_PERMISSIONS(role)	 (is_member_of_role(GetUserId(), DEFAULT_ROLE_READ_ALL_STATS) || has_privs_of_role(GetUserId(), role)) | ||||
|  | ||||
| /* Global bgwriter statistics, from bgwriter.c */ | ||||
| extern PgStat_MsgBgWriter bgwriterStats; | ||||
|  | ||||
| @@ -518,7 +520,7 @@ pg_stat_get_progress_info(PG_FUNCTION_ARGS) | ||||
| 		values[1] = ObjectIdGetDatum(beentry->st_databaseid); | ||||
|  | ||||
| 		/* show rest of the values including relid only to role members */ | ||||
| 		if (has_privs_of_role(GetUserId(), beentry->st_userid)) | ||||
| 		if (HAS_PGSTAT_PERMISSIONS(beentry->st_userid)) | ||||
| 		{ | ||||
| 			values[2] = ObjectIdGetDatum(beentry->st_progress_command_target); | ||||
| 			for (i = 0; i < PGSTAT_NUM_PROGRESS_PARAM; i++) | ||||
| @@ -651,8 +653,7 @@ pg_stat_get_activity(PG_FUNCTION_ARGS) | ||||
| 			nulls[16] = true; | ||||
|  | ||||
| 		/* Values only available to role member or pg_read_all_stats */ | ||||
| 		if (has_privs_of_role(GetUserId(), beentry->st_userid) || | ||||
| 			is_member_of_role(GetUserId(), DEFAULT_ROLE_READ_ALL_STATS)) | ||||
| 		if (HAS_PGSTAT_PERMISSIONS(beentry->st_userid)) | ||||
| 		{ | ||||
| 			SockAddr	zero_clientaddr; | ||||
| 			char	   *clipped_activity; | ||||
| @@ -981,7 +982,7 @@ pg_stat_get_backend_activity(PG_FUNCTION_ARGS) | ||||
|  | ||||
| 	if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL) | ||||
| 		activity = "<backend information not available>"; | ||||
| 	else if (!has_privs_of_role(GetUserId(), beentry->st_userid)) | ||||
| 	else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid)) | ||||
| 		activity = "<insufficient privilege>"; | ||||
| 	else if (*(beentry->st_activity_raw) == '\0') | ||||
| 		activity = "<command string not enabled>"; | ||||
| @@ -1005,7 +1006,7 @@ pg_stat_get_backend_wait_event_type(PG_FUNCTION_ARGS) | ||||
|  | ||||
| 	if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL) | ||||
| 		wait_event_type = "<backend information not available>"; | ||||
| 	else if (!has_privs_of_role(GetUserId(), beentry->st_userid)) | ||||
| 	else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid)) | ||||
| 		wait_event_type = "<insufficient privilege>"; | ||||
| 	else if ((proc = BackendPidGetProc(beentry->st_procpid)) != NULL) | ||||
| 		wait_event_type = pgstat_get_wait_event_type(proc->wait_event_info); | ||||
| @@ -1026,7 +1027,7 @@ pg_stat_get_backend_wait_event(PG_FUNCTION_ARGS) | ||||
|  | ||||
| 	if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL) | ||||
| 		wait_event = "<backend information not available>"; | ||||
| 	else if (!has_privs_of_role(GetUserId(), beentry->st_userid)) | ||||
| 	else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid)) | ||||
| 		wait_event = "<insufficient privilege>"; | ||||
| 	else if ((proc = BackendPidGetProc(beentry->st_procpid)) != NULL) | ||||
| 		wait_event = pgstat_get_wait_event(proc->wait_event_info); | ||||
| @@ -1048,7 +1049,7 @@ pg_stat_get_backend_activity_start(PG_FUNCTION_ARGS) | ||||
| 	if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL) | ||||
| 		PG_RETURN_NULL(); | ||||
|  | ||||
| 	if (!has_privs_of_role(GetUserId(), beentry->st_userid)) | ||||
| 	else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid)) | ||||
| 		PG_RETURN_NULL(); | ||||
|  | ||||
| 	result = beentry->st_activity_start_timestamp; | ||||
| @@ -1074,7 +1075,7 @@ pg_stat_get_backend_xact_start(PG_FUNCTION_ARGS) | ||||
| 	if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL) | ||||
| 		PG_RETURN_NULL(); | ||||
|  | ||||
| 	if (!has_privs_of_role(GetUserId(), beentry->st_userid)) | ||||
| 	else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid)) | ||||
| 		PG_RETURN_NULL(); | ||||
|  | ||||
| 	result = beentry->st_xact_start_timestamp; | ||||
| @@ -1096,7 +1097,7 @@ pg_stat_get_backend_start(PG_FUNCTION_ARGS) | ||||
| 	if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL) | ||||
| 		PG_RETURN_NULL(); | ||||
|  | ||||
| 	if (!has_privs_of_role(GetUserId(), beentry->st_userid)) | ||||
| 	else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid)) | ||||
| 		PG_RETURN_NULL(); | ||||
|  | ||||
| 	result = beentry->st_proc_start_timestamp; | ||||
| @@ -1120,7 +1121,7 @@ pg_stat_get_backend_client_addr(PG_FUNCTION_ARGS) | ||||
| 	if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL) | ||||
| 		PG_RETURN_NULL(); | ||||
|  | ||||
| 	if (!has_privs_of_role(GetUserId(), beentry->st_userid)) | ||||
| 	else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid)) | ||||
| 		PG_RETURN_NULL(); | ||||
|  | ||||
| 	/* A zeroed client addr means we don't know */ | ||||
| @@ -1167,7 +1168,7 @@ pg_stat_get_backend_client_port(PG_FUNCTION_ARGS) | ||||
| 	if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL) | ||||
| 		PG_RETURN_NULL(); | ||||
|  | ||||
| 	if (!has_privs_of_role(GetUserId(), beentry->st_userid)) | ||||
| 	else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid)) | ||||
| 		PG_RETURN_NULL(); | ||||
|  | ||||
| 	/* A zeroed client addr means we don't know */ | ||||
|   | ||||
		Reference in New Issue
	
	Block a user