Skip to content

Backport #8821: harden extract_deparse security regression test (release-12.1) - #8826

Merged
ibrahim halatci (ihalatci) merged 1 commit into
release-12.1from
release-12.1-backport-8821
Sep 8, 2026
Merged

ibrahim halatci (ihalatci) merged 1 commit into
release-12.1from
release-12.1-backport-8821

Conversation

@ihalatci

Copy link
Copy Markdown
Contributor

DESCRIPTION: Backport extract_deparse security regression test hardening to release-12.1

Backport of #8821 (merged to main as 2cfa425) to release-12.1.

The extract_deparse security regression test — which guards the EXTRACT
identifier-quoting fix — had two silent-pass paths:

  1. It checked to_regclass('extract_deparse.injected') IS NULL, but the deparser
    fully-qualifies task SQL and Citus sends no SET search_path for SELECT task
    execution, so a successful injection would create injected in the worker's
    default public schema. The assertion therefore passed even when the
    injection succeeded. Replaced with a schema-agnostic
    count(*) FROM pg_class WHERE relname = 'injected', matching the existing
    idiom in citus_internal_distribute_object.sql.

  2. If a planner change stopped pushing the expression down, nothing would run on
    a worker and the test would still pass. Added a positive control asserting the
    same expression with a valid field is still pushed down.

Test-only change, +22/-4 across sql/extract_deparse.sql and
expected/extract_deparse.out. The pg19.* half of #8821 is intentionally
excluded — those files do not exist on this branch.

Note: extract_deparse runs under check-multi-1 on this branch
(multi_1_schedule), not check-multi-1-create-citus as on release-13.2/14.0.

Prior CI on this branch (manual dispatch, run 33889067381): 95 jobs, 0 failures.

Backport of #8821 from main.

The injection check looked for the table the payload creates with
to_regclass('extract_deparse.injected') IS NULL, but the deparser fully
qualifies task SQL on purpose (PushEmptySearchPath), so Citus never sets
search_path on a worker for a SELECT task. A successful injection therefore
creates the table in the worker's default search_path, not in the test
schema, and the assertion reported success either way.

Look the relation up by name in pg_class instead, which is how the other
run_command_on_workers checks in the suite do it, so the test fails
wherever the injected table lands.

Also add a positive control. The payload is expected to raise
invalid_parameter_value and the DO block swallows it, so the only assertion
was a negative one: if a future change stopped the expression from being
pushed down, nothing would run on a worker and the test would keep passing
without covering the deparse path.

This matters more here than on main: this branch has no PG19, so the
version guard is always taken and this file is the only verification that
the EXTRACT identifier quoting fix still works.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7c6370b2-06fd-4491-bf92-ecb811d34518
@ihalatci
ibrahim halatci (ihalatci) merged commit 4034bdb into release-12.1 Sep 8, 2026
312 of 313 checks passed
@ihalatci
ibrahim halatci (ihalatci) deleted the release-12.1-backport-8821 branch September 8, 2026 14:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants