SIGSEGV in backend when authenticator role (supautils+safeupdate preloaded) hits a denied-EXECUTE call
I maintainer di solito rispondono entro 2 giorni
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 35/100
Direzione di ricerca
Start by reproducing the isolated denied-EXECUTE call with supautils and safeupdate preloaded, then compare it with each library loaded alone. Trace the backend failure from the denied function call; done means the call returns 42501 and the backend connection remains usable.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Bug report
Calling a function you've been denied EXECUTE on crashes the backend connection
with SIGSEGV instead of returning a clean 42501, when the connecting role has
BOTH supautils and safeupdate in session_preload_libraries — exactly the
authenticator role's default configuration, i.e. what PostgREST uses for
every request via SET ROLE anon/authenticated.
Environment
- Local Supabase CLI stack (
supabase start), Postgres 17.6 - Nix-packaged build:
.../postgresql-and-plugins-17.6/bin/.postgres-wrapped
Reproduction (isolated, trivial function, no app logic involved)
CREATE FUNCTION test_trivial() RETURNS int LANGUAGE sql AS $$ SELECT 1 $$;REVOKE EXECUTE ON FUNCTION test_trivial() FROM <role>;(schema USAGE still granted)- Connect as
authenticator(session_preload_libraries = 'supautils, safeupdate'),
SET ROLE anon;(or any role denied EXECUTE on the function) SELECT test_trivial();- Connection dies instantly: "Connection terminated unexpectedly" client-side.
Isolation results
supautilsalone preloaded, same denied call → clean42501, no crash.safeupdatealone preloaded, same denied call → clean42501, no crash.- Both together (matching
authenticator's real config) → SIGSEGV, 100% reproducible
on the first call, regardless of function body (tested plain SQL and SECURITY
DEFINER; not specific to either).
Server-side evidence
dmesg inside the container shows, identically on every occurrence:
segfault at 0 ip <consistent offset> sp ... error 4 in .postgres-wrapped[...]
.postgres-wrapped: potentially unexpected fatal signal 11.
segfault at 0 = NULL-pointer dereference. pg_postmaster_start_time() is
unchanged across every crash — only the individual backend dies, not postmaster.
Ruled out OOM: host VM had 8.8GB free, zero OOM-killer lines in dmesg across the
whole session.
Why this matters
authenticator's preload-library combination is presumably the Supabase default
across all projects. Any real PostgREST request that correctly gets EXECUTE-denied
(a perfectly normal authorization outcome, not misconfiguration) will crash the
backend instead of returning 403, on any project using this default.
Happy to provide the full investigation transcript or test further if useful.
- Lingua principale
- Nix
- Stelle
- 1.8k
- Fork
- 267
- Merge medio
- 4g 21h
- PR unite (30g)
- 47
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di supabase/postgres
-
CREATE EXTENSION pgmq fails in Postgres 17.6.1.016+ due to function overload handling bug in after-create scriptForse di nuovo libera Una pull request per questa issue è stata chiusa senza essere unita. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
supabase/postgres#1867 · 14 commenti · 2 reazioni ·
I maintainer di solito rispondono entro 2 giorni
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
supabase/postgres#1586 · 1 commento · 2 reazioni ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
I maintainer di solito rispondono entro 2 giorni
-
supabase_auth_admin can CREATE rolesForse già presa @jaysomani l’ha presa 47 giorni fa. Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
supabase/postgres#1518 · 1 commento ·
I maintainer di solito rispondono entro 2 giorni
-
`supabase/postgres:17.6.1.105` (amd64) — backend SIGSEGV during a heavy pgTAP file, CI-CPU-specificAperta
Difficoltà 5/5 Più di una settimana Idoneità per principianti 30/100
I maintainer di solito rispondono entro 2 giorni
Tutte le issue di supabase/postgres
Issue simili
-
bug database
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
DiegoMicali/MovieFlix#12 ·
-
bug priority:high
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
coollabsio/shoutrrr#190 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 6 giorni
-
bug good first issue high Properties small
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno