Skip to content

Backport #8821: harden extract_deparse security regression test (release-14.0) - #8827

Merged
ibrahim halatci (ihalatci) merged 1 commit into
release-14.0from
release-14.0-backport-8821
Sep 7, 2026
Merged

ibrahim halatci (ihalatci) merged 1 commit into
release-14.0from
release-14.0-backport-8821

Conversation

@ihalatci

Copy link
Copy Markdown
Contributor

DESCRIPTION: Backport extract_deparse security regression test hardening to release-14.0

Backport of #8821 (merged to main as 2cfa425) to release-14.0.

The extract_deparse security regression test — which guards the EXTRACT
identifier-quoting fix — had two silent-pass paths:

  1. It checked to_regclass('extract_deparse.injected') IS NULL, but the deparser
    fully-qualifies task SQL and Citus sends no SET search_path for SELECT task
    execution, so a successful injection would create injected in the worker's
    default public schema. The assertion therefore passed even when the
    injection succeeded. Replaced with a schema-agnostic
    count(*) FROM pg_class WHERE relname = 'injected', matching the existing
    idiom in citus_internal_distribute_object.sql.

  2. If a planner change stopped pushing the expression down, nothing would run on
    a worker and the test would still pass. Added a positive control asserting the
    same expression with a valid field is still pushed down.

Test-only change, +22/-4 across sql/extract_deparse.sql and
expected/extract_deparse.out. The pg19.* half of #8821 is intentionally
excluded — those files do not exist on this branch.

extract_deparse runs under check-multi-1-create-citus on this branch, which
passed on PG16, PG17 and PG18 in the branch run (33888997131), and passed 8/8 in
the flakyness shard.

Known pre-existing failures on this branch, unrelated to this change (neither job
executes extract_deparse, which is not in multi_schedule):

  • Test Citus Lib N-1 / PG18 - check-multi — fails on multi_insert_select in
    every recent branch run (33168333398, 32951765361, 31358631548).
  • Test Citus SQL N-1 / PG18 - check-multi — fails on pg17 due to a missing
    ORDER BY in a pg_inherits query, so partition rows come back in
    nondeterministic order.

Backport of #8821 from main.

The injection check looked for the table the payload creates with
to_regclass('extract_deparse.injected') IS NULL, but the deparser fully
qualifies task SQL on purpose (PushEmptySearchPath), so Citus never sets
search_path on a worker for a SELECT task. A successful injection therefore
creates the table in the worker's default search_path, not in the test
schema, and the assertion reported success either way.

Look the relation up by name in pg_class instead, which is how the other
run_command_on_workers checks in the suite do it, so the test fails
wherever the injected table lands.

Also add a positive control. The payload is expected to raise
invalid_parameter_value and the DO block swallows it, so the only assertion
was a negative one: if a future change stopped the expression from being
pushed down, nothing would run on a worker and the test would keep passing
without covering the deparse path.

This matters more here than on main: this branch has no PG19, so the
version guard is always taken and this file is the only verification that
the EXTRACT identifier quoting fix still works.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7c6370b2-06fd-4491-bf92-ecb811d34518
@codecov

codecov Bot commented Sep 6, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 88.50%. Comparing base (5b1bc79) to head (a69eb69).

Additional details and impacted files
@@                Coverage Diff                @@
##           release-14.0    #8827       +/-   ##
=================================================
+ Coverage         46.80%   88.50%   +41.70%     
=================================================
  Files               289      289               
  Lines             64575    64585       +10     
  Branches           8116     8120        +4     
=================================================
+ Hits              30227    57164    +26937     
+ Misses            31635     5081    -26554     
+ Partials           2713     2340      -373     
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@ihalatci
ibrahim halatci (ihalatci) merged commit 4bc1e1f into release-14.0 Sep 7, 2026
502 of 603 checks passed
@ihalatci
ibrahim halatci (ihalatci) deleted the release-14.0-backport-8821 branch September 7, 2026 08:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant