Backport #8821: harden extract_deparse security regression test (release-14.0) - #8827
Merged
ibrahim halatci (ihalatci) merged 1 commit intoSep 7, 2026
Merged
Conversation
Backport of #8821 from main. The injection check looked for the table the payload creates with to_regclass('extract_deparse.injected') IS NULL, but the deparser fully qualifies task SQL on purpose (PushEmptySearchPath), so Citus never sets search_path on a worker for a SELECT task. A successful injection therefore creates the table in the worker's default search_path, not in the test schema, and the assertion reported success either way. Look the relation up by name in pg_class instead, which is how the other run_command_on_workers checks in the suite do it, so the test fails wherever the injected table lands. Also add a positive control. The payload is expected to raise invalid_parameter_value and the DO block swallows it, so the only assertion was a negative one: if a future change stopped the expression from being pushed down, nothing would run on a worker and the test would keep passing without covering the deparse path. This matters more here than on main: this branch has no PG19, so the version guard is always taken and this file is the only verification that the EXTRACT identifier quoting fix still works. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7c6370b2-06fd-4491-bf92-ecb811d34518
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## release-14.0 #8827 +/- ##
=================================================
+ Coverage 46.80% 88.50% +41.70%
=================================================
Files 289 289
Lines 64575 64585 +10
Branches 8116 8120 +4
=================================================
+ Hits 30227 57164 +26937
+ Misses 31635 5081 -26554
+ Partials 2713 2340 -373 🚀 New features to boost your workflow:
|
ibrahim halatci (ihalatci)
merged commit Sep 7, 2026
4bc1e1f
into
release-14.0
502 of 603 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
DESCRIPTION: Backport extract_deparse security regression test hardening to release-14.0
Backport of #8821 (merged to
mainas 2cfa425) torelease-14.0.The
extract_deparsesecurity regression test — which guards the EXTRACTidentifier-quoting fix — had two silent-pass paths:
It checked
to_regclass('extract_deparse.injected') IS NULL, but the deparserfully-qualifies task SQL and Citus sends no
SET search_pathfor SELECT taskexecution, so a successful injection would create
injectedin the worker'sdefault
publicschema. The assertion therefore passed even when theinjection succeeded. Replaced with a schema-agnostic
count(*) FROM pg_class WHERE relname = 'injected', matching the existingidiom in
citus_internal_distribute_object.sql.If a planner change stopped pushing the expression down, nothing would run on
a worker and the test would still pass. Added a positive control asserting the
same expression with a valid field is still pushed down.
Test-only change, +22/-4 across
sql/extract_deparse.sqlandexpected/extract_deparse.out. Thepg19.*half of #8821 is intentionallyexcluded — those files do not exist on this branch.
extract_deparseruns undercheck-multi-1-create-cituson this branch, whichpassed on PG16, PG17 and PG18 in the branch run (33888997131), and passed 8/8 in
the flakyness shard.
Known pre-existing failures on this branch, unrelated to this change (neither job
executes
extract_deparse, which is not inmulti_schedule):Test Citus Lib N-1 / PG18 - check-multi— fails onmulti_insert_selectinevery recent branch run (33168333398, 32951765361, 31358631548).
Test Citus SQL N-1 / PG18 - check-multi— fails onpg17due to a missingORDER BYin apg_inheritsquery, so partition rows come back innondeterministic order.