mirror of
https://github.com/postgres/postgres.git
synced 2025-06-30 21:42:05 +03:00
Require the schema qualification in pg_temp.type_name(arg).
Commit aa27977fe2
introduced this
restriction for pg_temp.function_name(arg); do likewise for types
created in temporary schemas. Programs that this breaks should add
"pg_temp." schema qualification or switch to arg::type_name syntax.
Back-patch to 9.4 (all supported versions).
Reviewed by Tom Lane. Reported by Tom Lane.
Security: CVE-2019-10208
This commit is contained in:
@ -1746,7 +1746,12 @@ FuncNameAsType(List *funcname)
|
||||
Oid result;
|
||||
Type typtup;
|
||||
|
||||
typtup = LookupTypeName(NULL, makeTypeNameFromNameList(funcname), NULL, false);
|
||||
/*
|
||||
* temp_ok=false protects the <refsect1 id="sql-createfunction-security">
|
||||
* contract for writing SECURITY DEFINER functions safely.
|
||||
*/
|
||||
typtup = LookupTypeNameExtended(NULL, makeTypeNameFromNameList(funcname),
|
||||
NULL, false, false);
|
||||
if (typtup == NULL)
|
||||
return InvalidOid;
|
||||
|
||||
|
@ -33,6 +33,18 @@ static int32 typenameTypeMod(ParseState *pstate, const TypeName *typeName,
|
||||
|
||||
/*
|
||||
* LookupTypeName
|
||||
* Wrapper for typical case.
|
||||
*/
|
||||
Type
|
||||
LookupTypeName(ParseState *pstate, const TypeName *typeName,
|
||||
int32 *typmod_p, bool missing_ok)
|
||||
{
|
||||
return LookupTypeNameExtended(pstate,
|
||||
typeName, typmod_p, true, missing_ok);
|
||||
}
|
||||
|
||||
/*
|
||||
* LookupTypeNameExtended
|
||||
* Given a TypeName object, lookup the pg_type syscache entry of the type.
|
||||
* Returns NULL if no such type can be found. If the type is found,
|
||||
* the typmod value represented in the TypeName struct is computed and
|
||||
@ -51,11 +63,17 @@ static int32 typenameTypeMod(ParseState *pstate, const TypeName *typeName,
|
||||
* found but is a shell, and there is typmod decoration, an error will be
|
||||
* thrown --- this is intentional.
|
||||
*
|
||||
* If temp_ok is false, ignore types in the temporary namespace. Pass false
|
||||
* when the caller will decide, using goodness of fit criteria, whether the
|
||||
* typeName is actually a type or something else. If typeName always denotes
|
||||
* a type (or denotes nothing), pass true.
|
||||
*
|
||||
* pstate is only used for error location info, and may be NULL.
|
||||
*/
|
||||
Type
|
||||
LookupTypeName(ParseState *pstate, const TypeName *typeName,
|
||||
int32 *typmod_p, bool missing_ok)
|
||||
LookupTypeNameExtended(ParseState *pstate,
|
||||
const TypeName *typeName, int32 *typmod_p,
|
||||
bool temp_ok, bool missing_ok)
|
||||
{
|
||||
Oid typoid;
|
||||
HeapTuple tup;
|
||||
@ -172,7 +190,7 @@ LookupTypeName(ParseState *pstate, const TypeName *typeName,
|
||||
else
|
||||
{
|
||||
/* Unqualified type name, so search the search path */
|
||||
typoid = TypenameGetTypid(typname);
|
||||
typoid = TypenameGetTypidExtended(typname, temp_ok);
|
||||
}
|
||||
|
||||
/* If an array reference, return the array type instead */
|
||||
|
Reference in New Issue
Block a user