Don't believe MinMaxExpr is leakproof without checking.
authorTom Lane
Wed, 2 Jan 2019 21:33:48 +0000 (16:33 -0500)
committerTom Lane
Wed, 2 Jan 2019 21:33:48 +0000 (16:33 -0500)
MinMaxExpr invokes the btree comparison function for its input datatype,
so it's only leakproof if that function is.  Many such functions are
indeed leakproof, but others are not, and we should not just assume that
they are.  Hence, adjust contain_leaked_vars to verify the leakproofness
of the referenced function explicitly.

I didn't add a regression test because it would need to depend on
some particular comparison function being leaky, and that's a moving
target, per discussion.

This has been wrong all along, so back-patch to supported branches.

Discussion: https://postgr.es/m/31042.1546194242@sss.pgh.pa.us

src/backend/optimizer/util/clauses.c

index e549a27ef472715811f06cd4fa4706542faaa84a..89343e67e689736959db0e377cb16d90510531f2 100644 (file)
@@ -1426,7 +1426,6 @@ contain_leaky_functions_walker(Node *node, void *context)
        case T_CaseExpr:
        case T_CaseTestExpr:
        case T_RowExpr:
-       case T_MinMaxExpr:
        case T_NullTest:
        case T_BooleanTest:
        case T_List:
@@ -1518,6 +1517,35 @@ contain_leaky_functions_walker(Node *node, void *context)
            }
            break;
 
+       case T_MinMaxExpr:
+           {
+               /*
+                * MinMaxExpr is leakproof if the comparison function it calls
+                * is leakproof.
+                */
+               MinMaxExpr *minmaxexpr = (MinMaxExpr *) node;
+               TypeCacheEntry *typentry;
+               bool        leakproof;
+
+               /* Look up the btree comparison function for the datatype */
+               typentry = lookup_type_cache(minmaxexpr->minmaxtype,
+                                            TYPECACHE_CMP_PROC);
+               if (OidIsValid(typentry->cmp_proc))
+                   leakproof = get_func_leakproof(typentry->cmp_proc);
+               else
+               {
+                   /*
+                    * The executor will throw an error, but here we just
+                    * treat the missing function as leaky.
+                    */
+                   leakproof = false;
+               }
+
+               if (!leakproof)
+                   return true;
+           }
+           break;
+
        default:
 
            /*