Segfault: postgres session + SET ROLE authenticated + call to a function with EXECUTE revoked (17.6.1.104 / 17.6.1.106)
I maintainer di solito rispondono entro 2 giorni
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 52/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- docker, postgresql
- Ambito
- databases
Direzione di ricerca
Inizia con la riproduzione Docker minima usando supabase/postgres:17.6.1.104 e i comandi psql nel report, quindi confronta il percorso diretto di postgres con SET ROLE con il percorso authenticator/PostgREST. Analizza il controllo del permesso EXECUTE della funzione e le shared_preload_libraries elencate. Il lavoro è completato quando la chiamata negata restituisce ERROR 42501 senza un crash del backend o un ripristino del cluster.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
On supabase/postgres:17.6.1.104 and 17.6.1.106, a session connected as the postgres role that does SET ROLE authenticated and then calls any function on which EXECUTE has been revoked from authenticated crashes the backend with signal 11 (Segmentation fault) instead of returning permission denied for function. The whole cluster goes into recovery for ~1 s.
It reproduces with a trivial select 1 function, LANGUAGE sql or plpgsql, scalar or set-returning, inside or outside a DO block, with SET ROLE or SET LOCAL ROLE.
It does not reproduce through the PostgREST path (authenticator → SET ROLE authenticated → call): that returns a clean ERROR: permission denied for function f. Permission errors on tables (RLS 42501, revoked TRUNCATE) do not crash either — only the function-EXECUTE denial from a postgres session does.
Minimal repro (bare image, no user data)
docker run --rm -d --name pgrepro -e POSTGRES_PASSWORD=postgres -p 54334:5432 supabase/postgres:17.6.1.104
# wait for pg_isready
docker exec pgrepro psql -U postgres -d postgres -c "
create function public.f() returns int language sql as \$f\$ select 1 \$f\$;
revoke execute on function public.f() from public, authenticated;"
docker exec pgrepro psql -U postgres -d postgres -c "set role authenticated; select public.f();"
# server closed the connection unexpectedly
docker logs pgrepro 2>&1 | grep 'terminated by signal'
# LOG: server process (PID 238) was terminated by signal 11: Segmentation fault
Same result with supabase/postgres:17.6.1.106 (the image supabase start pins with CLI 2.90.0). Also reproduced inside a full supabase start stack.
show shared_preload_libraries in the image: pg_stat_statements, pgaudit, plpgsql, plpgsql_check, pg_cron, pg_net, pgsodium, auto_explain, pg_tle, plan_filter, supabase_vault.
Expected
ERROR: permission denied for function f (SQLSTATE 42501), as it happens via authenticator.
Why it matters
The postgres role is the one used by migration runners, CI test harnesses (psql as postgres + SET LOCAL ROLE authenticated to exercise RLS/grants) and the Supabase MCP execute_sql. A test that legitimately checks "authenticated cannot execute this function" takes the database down — in CI it kills the job; against a hosted project it would restart the primary. We hit it in CI first, then confirmed on both images. Postgres logs on our hosted project (same 17.6 line) show no segfaults, so the PostgREST/client path looks unaffected; we are only reporting the privileged-session path.
Happy to provide a core dump / more details if useful.
- Lingua principale
- Nix
- Stelle
- 1.8k
- Fork
- 268
- Merge medio
- 3g 22h
- PR unite (30g)
- 44
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di supabase/postgres
-
CREATE EXTENSION pgmq fails in Postgres 17.6.1.016+ due to function overload handling bug in after-create scriptForse di nuovo libera Una pull request per questa issue è stata chiusa senza essere unita. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
supabase/postgres#1867 · 14 commenti · 2 reazioni ·
I maintainer di solito rispondono entro 2 giorni
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
supabase/postgres#1586 · 1 commento · 2 reazioni ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
I maintainer di solito rispondono entro 2 giorni
-
supabase_auth_admin can CREATE rolesForse già presa @jaysomani l’ha presa 51 giorni fa. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
supabase/postgres#1518 · 1 commento ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
I maintainer di solito rispondono entro 2 giorni
Tutte le issue di supabase/postgres
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
debpalash/VoiceStudio#2751 ·
I maintainer di solito rispondono entro 1 giorno
-
Add: CartoonitoApertacheck:failed feeds:add
Difficoltà 2/5 1-3 ore Idoneità per principianti 63/100
iptv-org/database#37390 · 1 commento ·
I maintainer di solito rispondono entro 9 giorni
-
backlog:medium bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
simonoppowa/OpenNutriTracker#1349 ·
I maintainer di solito rispondono entro 1 giorno
-
[BUG] LazyStackedTensorDictStore zeroes the last byte of a new key set on the last elementForse già presa @peterdsharpe l’ha presa oggi. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
pytorch/tensordict#2307 ·
I maintainer di solito rispondono entro 1 giorno
-
Add Group doesn't trim the group name, so a spaces-only name creates a blank group and "fossy " bypasses the duplicate checkForse già presa @bhuvan-somisetty l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 90/100
fossology/fossology#3917 · 1 commento ·
I maintainer di solito rispondono entro 2 giorni