Re: Numeric is not leakproof
Stephen Frost <[email protected]>
| Newsgroups | gmane.comp.db.postgresql.bugs |
|---|---|
| Message-ID | <[email protected]> |
Greetings, * Konstantin Knizhnik ([email protected]) wrote: > Numeric functions are not marked as leakproof in pg_proc.dat > It cause unexpected behavior in case of using row-level security: The behavior you're getting is *entirely* expected, just to be clear. Perhaps unfortunate and not as performant as you were hoping, but definitely not unexpected. As Tom noted downthread, you can't just mark things 'leakproof' because you want them to be able to be used in an index- you need to actually show that they're leakproof. > I have not checked all other builtin type. > But it seems to me that it may be reasonable to mark ALL builtin functions > (described in pg_proc.dat) as leekprof by default. Absolutely not without careful verification of each and every one. There's nothing that guarantees builtins are leakproof (and indeed, there's no shortage of ones that are clearly *not* leakproof today). I'd love it for someone to go through and fix them all to actually be leakproof (or at least all of the ones that might be used with an index) but that clearly hasn't been done here. Thanks, Stephen
signature.asc
(application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCgAGBQJd5sjfAAoJEO1sijiDR2RVLQwP/iMHjBAz8RSqTSvR074j+b1F cJX0SBxnXjp2xdi7wr8stovDGb9Omsv+nPWX7kAMExZuHuIiF/ipX48Vpae64srs r+91I2BUYhf3dT+E2yp/v9y6fDThC08jWbB3Thy5o3nx3pmsS904gR25RAyx9mNT D3oyBS1+nf3K07DSmWBYBARHLpeX4HVY0TnyJsSkeK1UuxtqmalAFe/dZyqxUIk4 MYaycnpLxLYdOoMZr2YCd/2WzY8jftnbRvxz3TKRVQtPRA86HwmoKDTIlZrG6PXL E3iFsOpJdVvBiCp7ci7TQFc1VPMlqtts7EeqtEybMAEQiQq5DEhUDURWhoqoHIte nhaHTAoFg5F12Hs0dY1UUbeCm2Beo11+GA0B/GQAUkziU1vd2OpkZGyQeqyVMRea wm/fCSZbODmmGdyBzxbR0xFrYz1tnNmfk+jUdwN8PvYIpfoEMX+bIwaeYeL/xMdJ /pbqIrDclV4e2KbK2EK5Mj5jqAaxmDSAcBVirVaGx2g6VZbW4EtvzMLQQgpmNRA4 zJWhJ4AYWhQvjq+Xm6LXk97OFs0WQs4tN4YVa5sdVjeGIFs9/+e0i83Q6v4jYz38 BIzyFqsjecLZMdFRYho1VC/Pxs1X7YqD445INYoeYWDFCoJtOYnx6u2M/U9quGB2 eQJkhwaExuCNer64ns2t =f//P -----END PGP SIGNATURE-----