Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Segfault: postgres session + SET ROLE authenticated + call to a function with EXECUTE revoked (17.6.1.104 / 17.6.1.106)

Aperta
#2,377 10 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 2 giorni

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
52/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
docker, postgresql
Ambito
databases

Direzione di ricerca

Inizia con la riproduzione Docker minima usando supabase/postgres:17.6.1.104 e i comandi psql nel report, quindi confronta il percorso diretto di postgres con SET ROLE con il percorso authenticator/PostgREST. Analizza il controllo del permesso EXECUTE della funzione e le shared_preload_libraries elencate. Il lavoro è completato quando la chiamata negata restituisce ERROR 42501 senza un crash del backend o un ripristino del cluster.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Summary

On supabase/postgres:17.6.1.104 and 17.6.1.106, a session connected as the postgres role that does SET ROLE authenticated and then calls any function on which EXECUTE has been revoked from authenticated crashes the backend with signal 11 (Segmentation fault) instead of returning permission denied for function. The whole cluster goes into recovery for ~1 s.

It reproduces with a trivial select 1 function, LANGUAGE sql or plpgsql, scalar or set-returning, inside or outside a DO block, with SET ROLE or SET LOCAL ROLE.

It does not reproduce through the PostgREST path (authenticator → SET ROLE authenticated → call): that returns a clean ERROR: permission denied for function f. Permission errors on tables (RLS 42501, revoked TRUNCATE) do not crash either — only the function-EXECUTE denial from a postgres session does.

Minimal repro (bare image, no user data)

docker run --rm -d --name pgrepro -e POSTGRES_PASSWORD=postgres -p 54334:5432 supabase/postgres:17.6.1.104
# wait for pg_isready
docker exec pgrepro psql -U postgres -d postgres -c "
  create function public.f() returns int language sql as \$f\$ select 1 \$f\$;
  revoke execute on function public.f() from public, authenticated;"
docker exec pgrepro psql -U postgres -d postgres -c "set role authenticated; select public.f();"
#   server closed the connection unexpectedly
docker logs pgrepro 2>&1 | grep 'terminated by signal'
#   LOG:  server process (PID 238) was terminated by signal 11: Segmentation fault

Same result with supabase/postgres:17.6.1.106 (the image supabase start pins with CLI 2.90.0). Also reproduced inside a full supabase start stack.

show shared_preload_libraries in the image: pg_stat_statements, pgaudit, plpgsql, plpgsql_check, pg_cron, pg_net, pgsodium, auto_explain, pg_tle, plan_filter, supabase_vault.

Expected

ERROR: permission denied for function f (SQLSTATE 42501), as it happens via authenticator.

Why it matters

The postgres role is the one used by migration runners, CI test harnesses (psql as postgres + SET LOCAL ROLE authenticated to exercise RLS/grants) and the Supabase MCP execute_sql. A test that legitimately checks "authenticated cannot execute this function" takes the database down — in CI it kills the job; against a hosted project it would restart the primary. We hit it in CI first, then confirmed on both images. Postgres logs on our hosted project (same 17.6 line) show no segfaults, so the PostgREST/client path looks unaffected; we are only reporting the privileged-session path.

Happy to provide a core dump / more details if useful.

Lingua principale
Nix
Stelle
1.8k
Fork
268
Merge medio
3g 22h
PR unite (30g)
44

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di supabase/postgres

Tutte le issue di supabase/postgres

Issue simili

Altre issue su Databases

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.