Allow pg_read_all_stats to access all stats views again
authorMagnus Hagander
Mon, 20 Apr 2020 10:53:40 +0000 (12:53 +0200)
committerMagnus Hagander
Mon, 20 Apr 2020 10:56:26 +0000 (12:56 +0200)
The views pg_stat_progress_* had not gotten the memo that
pg_read_all_stats is supposed to be able to read all statistics. Also
make a pass over all text-returning pg_stat_xyz functions that could
return "insufficient privilege" and make sure they also respect
pg_read_all_status.

Reported-by: Andrey M. Borodin
Reviewed-by: Andrey M. Borodin, Kyotaro Horiguchi
Discussion: https://postgr.es/m/13145F2F-8458-4977-9D2D-7B2E862E5722@yandex-team.ru

src/backend/utils/adt/pgstatfuncs.c

index 93b7814418db72517a80399aacb685fc56f53b0a..50f7cec4425ffa0a1050c44635f92c04d48a6cd2 100644 (file)
@@ -33,6 +33,8 @@
 
 #define UINT32_ACCESS_ONCE(var)         ((uint32)(*((volatile uint32 *)&(var))))
 
+#define HAS_PGSTAT_PERMISSIONS(role)    (is_member_of_role(GetUserId(), DEFAULT_ROLE_READ_ALL_STATS) || has_privs_of_role(GetUserId(), role))
+
 /* Global bgwriter statistics, from bgwriter.c */
 extern PgStat_MsgBgWriter bgwriterStats;
 
@@ -518,7 +520,7 @@ pg_stat_get_progress_info(PG_FUNCTION_ARGS)
        values[1] = ObjectIdGetDatum(beentry->st_databaseid);
 
        /* show rest of the values including relid only to role members */
-       if (has_privs_of_role(GetUserId(), beentry->st_userid))
+       if (HAS_PGSTAT_PERMISSIONS(beentry->st_userid))
        {
            values[2] = ObjectIdGetDatum(beentry->st_progress_command_target);
            for (i = 0; i < PGSTAT_NUM_PROGRESS_PARAM; i++)
@@ -651,8 +653,7 @@ pg_stat_get_activity(PG_FUNCTION_ARGS)
            nulls[16] = true;
 
        /* Values only available to role member or pg_read_all_stats */
-       if (has_privs_of_role(GetUserId(), beentry->st_userid) ||
-           is_member_of_role(GetUserId(), DEFAULT_ROLE_READ_ALL_STATS))
+       if (HAS_PGSTAT_PERMISSIONS(beentry->st_userid))
        {
            SockAddr    zero_clientaddr;
            char       *clipped_activity;
@@ -981,7 +982,7 @@ pg_stat_get_backend_activity(PG_FUNCTION_ARGS)
 
    if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL)
        activity = "";
-   else if (!has_privs_of_role(GetUserId(), beentry->st_userid))
+   else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid))
        activity = "";
    else if (*(beentry->st_activity_raw) == '\0')
        activity = "";
@@ -1005,7 +1006,7 @@ pg_stat_get_backend_wait_event_type(PG_FUNCTION_ARGS)
 
    if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL)
        wait_event_type = "";
-   else if (!has_privs_of_role(GetUserId(), beentry->st_userid))
+   else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid))
        wait_event_type = "";
    else if ((proc = BackendPidGetProc(beentry->st_procpid)) != NULL)
        wait_event_type = pgstat_get_wait_event_type(proc->wait_event_info);
@@ -1026,7 +1027,7 @@ pg_stat_get_backend_wait_event(PG_FUNCTION_ARGS)
 
    if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL)
        wait_event = "";
-   else if (!has_privs_of_role(GetUserId(), beentry->st_userid))
+   else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid))
        wait_event = "";
    else if ((proc = BackendPidGetProc(beentry->st_procpid)) != NULL)
        wait_event = pgstat_get_wait_event(proc->wait_event_info);
@@ -1048,7 +1049,7 @@ pg_stat_get_backend_activity_start(PG_FUNCTION_ARGS)
    if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL)
        PG_RETURN_NULL();
 
-   if (!has_privs_of_role(GetUserId(), beentry->st_userid))
+   else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid))
        PG_RETURN_NULL();
 
    result = beentry->st_activity_start_timestamp;
@@ -1074,7 +1075,7 @@ pg_stat_get_backend_xact_start(PG_FUNCTION_ARGS)
    if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL)
        PG_RETURN_NULL();
 
-   if (!has_privs_of_role(GetUserId(), beentry->st_userid))
+   else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid))
        PG_RETURN_NULL();
 
    result = beentry->st_xact_start_timestamp;
@@ -1096,7 +1097,7 @@ pg_stat_get_backend_start(PG_FUNCTION_ARGS)
    if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL)
        PG_RETURN_NULL();
 
-   if (!has_privs_of_role(GetUserId(), beentry->st_userid))
+   else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid))
        PG_RETURN_NULL();
 
    result = beentry->st_proc_start_timestamp;
@@ -1120,7 +1121,7 @@ pg_stat_get_backend_client_addr(PG_FUNCTION_ARGS)
    if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL)
        PG_RETURN_NULL();
 
-   if (!has_privs_of_role(GetUserId(), beentry->st_userid))
+   else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid))
        PG_RETURN_NULL();
 
    /* A zeroed client addr means we don't know */
@@ -1167,7 +1168,7 @@ pg_stat_get_backend_client_port(PG_FUNCTION_ARGS)
    if ((beentry = pgstat_fetch_stat_beentry(beid)) == NULL)
        PG_RETURN_NULL();
 
-   if (!has_privs_of_role(GetUserId(), beentry->st_userid))
+   else if (!HAS_PGSTAT_PERMISSIONS(beentry->st_userid))
        PG_RETURN_NULL();
 
    /* A zeroed client addr means we don't know */