Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

SIGSEGV in backend when authenticator role (supautils+safeupdate preloaded) hits a denied-EXECUTE call

Aperta
#2,495 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 2 giorni

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
35/100
Tipo di issue
Bug
Chiarezza
Da chiarire
Stato di attività
Attiva
Stack tecnologico
postgresql

Direzione di ricerca

Start by reproducing the isolated denied-EXECUTE call with supautils and safeupdate preloaded, then compare it with each library loaded alone. Trace the backend failure from the denied function call; done means the call returns 42501 and the backend connection remains usable.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Bug report

Calling a function you've been denied EXECUTE on crashes the backend connection
with SIGSEGV instead of returning a clean 42501, when the connecting role has
BOTH supautils and safeupdate in session_preload_libraries — exactly the
authenticator role's default configuration, i.e. what PostgREST uses for
every request via SET ROLE anon/authenticated.

Environment
  • Local Supabase CLI stack (supabase start), Postgres 17.6
  • Nix-packaged build: .../postgresql-and-plugins-17.6/bin/.postgres-wrapped
Reproduction (isolated, trivial function, no app logic involved)
  1. CREATE FUNCTION test_trivial() RETURNS int LANGUAGE sql AS $$ SELECT 1 $$;
  2. REVOKE EXECUTE ON FUNCTION test_trivial() FROM <role>; (schema USAGE still granted)
  3. Connect as authenticator (session_preload_libraries = 'supautils, safeupdate'),
    SET ROLE anon; (or any role denied EXECUTE on the function)
  4. SELECT test_trivial();
  5. Connection dies instantly: "Connection terminated unexpectedly" client-side.
Isolation results
  • supautils alone preloaded, same denied call → clean 42501, no crash.
  • safeupdate alone preloaded, same denied call → clean 42501, no crash.
  • Both together (matching authenticator's real config) → SIGSEGV, 100% reproducible
    on the first call, regardless of function body (tested plain SQL and SECURITY
    DEFINER; not specific to either).
Server-side evidence

dmesg inside the container shows, identically on every occurrence:

segfault at 0 ip <consistent offset> sp ... error 4 in .postgres-wrapped[...]
.postgres-wrapped: potentially unexpected fatal signal 11.

segfault at 0 = NULL-pointer dereference. pg_postmaster_start_time() is
unchanged across every crash — only the individual backend dies, not postmaster.
Ruled out OOM: host VM had 8.8GB free, zero OOM-killer lines in dmesg across the
whole session.

Why this matters

authenticator's preload-library combination is presumably the Supabase default
across all projects. Any real PostgREST request that correctly gets EXECUTE-denied
(a perfectly normal authorization outcome, not misconfiguration) will crash the
backend instead of returning 403, on any project using this default.

Happy to provide the full investigation transcript or test further if useful.

Lingua principale
Nix
Stelle
1.8k
Fork
267
Merge medio
4g 21h
PR unite (30g)
47

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di supabase/postgres

Tutte le issue di supabase/postgres

Issue simili

Altre issue su Databases

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.