Backport #8821: harden extract_deparse security regression test (release-12.1) - #8826
Merged
ibrahim halatci (ihalatci) merged 1 commit intoSep 8, 2026
Merged
Conversation
Backport of #8821 from main. The injection check looked for the table the payload creates with to_regclass('extract_deparse.injected') IS NULL, but the deparser fully qualifies task SQL on purpose (PushEmptySearchPath), so Citus never sets search_path on a worker for a SELECT task. A successful injection therefore creates the table in the worker's default search_path, not in the test schema, and the assertion reported success either way. Look the relation up by name in pg_class instead, which is how the other run_command_on_workers checks in the suite do it, so the test fails wherever the injected table lands. Also add a positive control. The payload is expected to raise invalid_parameter_value and the DO block swallows it, so the only assertion was a negative one: if a future change stopped the expression from being pushed down, nothing would run on a worker and the test would keep passing without covering the deparse path. This matters more here than on main: this branch has no PG19, so the version guard is always taken and this file is the only verification that the EXTRACT identifier quoting fix still works. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7c6370b2-06fd-4491-bf92-ecb811d34518
Onur Tirtir (onurctirtir)
approved these changes
Sep 8, 2026
ibrahim halatci (ihalatci)
merged commit Sep 8, 2026
4034bdb
into
release-12.1
312 of 313 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
DESCRIPTION: Backport extract_deparse security regression test hardening to release-12.1
Backport of #8821 (merged to
mainas 2cfa425) torelease-12.1.The
extract_deparsesecurity regression test — which guards the EXTRACTidentifier-quoting fix — had two silent-pass paths:
It checked
to_regclass('extract_deparse.injected') IS NULL, but the deparserfully-qualifies task SQL and Citus sends no
SET search_pathfor SELECT taskexecution, so a successful injection would create
injectedin the worker'sdefault
publicschema. The assertion therefore passed even when theinjection succeeded. Replaced with a schema-agnostic
count(*) FROM pg_class WHERE relname = 'injected', matching the existingidiom in
citus_internal_distribute_object.sql.If a planner change stopped pushing the expression down, nothing would run on
a worker and the test would still pass. Added a positive control asserting the
same expression with a valid field is still pushed down.
Test-only change, +22/-4 across
sql/extract_deparse.sqlandexpected/extract_deparse.out. Thepg19.*half of #8821 is intentionallyexcluded — those files do not exist on this branch.
Note:
extract_deparseruns undercheck-multi-1on this branch(
multi_1_schedule), notcheck-multi-1-create-citusas on release-13.2/14.0.Prior CI on this branch (manual dispatch, run 33889067381): 95 jobs, 0 failures.