Team Ai
Datasetpublic

codekingpro/portable-devtools

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes15kdownloads
planner-stats-security.html49 linesDownload Raw Back to html
1<?xml version="1.0" encoding="UTF-8" standalone="no"?>2<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /><title>76.3. Planner Statistics and Security</title><link rel="stylesheet" type="text/css" href="stylesheet.css" /><link rev="made" href="pgsql-docs@lists.postgresql.org" /><meta name="generator" content="DocBook XSL Stylesheets Vsnapshot" /><link rel="prev" href="multivariate-statistics-examples.html" title="76.2. Multivariate Statistics Examples" /><link rel="next" href="backup-manifest-format.html" title="Chapter 77. Backup Manifest Format" /></head><body id="docContent" class="container-fluid col-10"><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="5" align="center">76.3. Planner Statistics and Security</th></tr><tr><td width="10%" align="left"><a accesskey="p" href="multivariate-statistics-examples.html" title="76.2. Multivariate Statistics Examples">Prev</a> </td><td width="10%" align="left"><a accesskey="u" href="planner-stats-details.html" title="Chapter 76. How the Planner Uses Statistics">Up</a></td><th width="60%" align="center">Chapter 76. How the Planner Uses Statistics</th><td width="10%" align="right"><a accesskey="h" href="index.html" title="PostgreSQL 16.3 Documentation">Home</a></td><td width="10%" align="right"> <a accesskey="n" href="backup-manifest-format.html" title="Chapter 77. Backup Manifest Format">Next</a></td></tr></table><hr /></div><div class="sect1" id="PLANNER-STATS-SECURITY"><div class="titlepage"><div><div><h2 class="title" style="clear: both">76.3. Planner Statistics and Security <a href="#PLANNER-STATS-SECURITY" class="id_link">#</a></h2></div></div></div><p>3   Access to the table <code class="structname">pg_statistic</code> is restricted to4   superusers, so that ordinary users cannot learn about the contents of the5   tables of other users from it.  Some selectivity estimation functions will6   use a user-provided operator (either the operator appearing in the query or7   a related operator) to analyze the stored statistics.  For example, in order8   to determine whether a stored most common value is applicable, the9   selectivity estimator will have to run the appropriate <code class="literal">=</code>10   operator to compare the constant in the query to the stored value.11   Thus the data in <code class="structname">pg_statistic</code> is potentially12   passed to user-defined operators.  An appropriately crafted operator can13   intentionally leak the passed operands (for example, by logging them14   or writing them to a different table), or accidentally leak them by showing15   their values in error messages, in either case possibly exposing data from16   <code class="structname">pg_statistic</code> to a user who should not be able to17   see it.18  </p><p>19   In order to prevent this, the following applies to all built-in selectivity20   estimation functions.  When planning a query, in order to be able to use21   stored statistics, the current user must either22   have <code class="literal">SELECT</code> privilege on the table or the involved23   columns, or the operator used must be <code class="literal">LEAKPROOF</code> (more24   accurately, the function that the operator is based on).  If not, then the25   selectivity estimator will behave as if no statistics are available, and26   the planner will proceed with default or fall-back assumptions.27  </p><p>28   If a user does not have the required privilege on the table or columns,29   then in many cases the query will ultimately receive a permission-denied30   error, in which case this mechanism is invisible in practice.  But if the31   user is reading from a security-barrier view, then the planner might wish32   to check the statistics of an underlying table that is otherwise33   inaccessible to the user.  In that case, the operator should be leak-proof34   or the statistics will not be used.  There is no direct feedback about35   that, except that the plan might be suboptimal.  If one suspects that this36   is the case, one could try running the query as a more privileged user,37   to see if a different plan results.38  </p><p>39   This restriction applies only to cases where the planner would need to40   execute a user-defined operator on one or more values41   from <code class="structname">pg_statistic</code>.  Thus the planner is permitted42   to use generic statistical information, such as the fraction of null values43   or the number of distinct values in a column, regardless of access44   privileges.45  </p><p>46   Selectivity estimation functions contained in third-party extensions that47   potentially operate on statistics with user-defined operators should follow48   the same security rules.  Consult the PostgreSQL source code for guidance.49  </p></div><div class="navfooter"><hr /><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="multivariate-statistics-examples.html" title="76.2. Multivariate Statistics Examples">Prev</a> </td><td width="20%" align="center"><a accesskey="u" href="planner-stats-details.html" title="Chapter 76. How the Planner Uses Statistics">Up</a></td><td width="40%" align="right"> <a accesskey="n" href="backup-manifest-format.html" title="Chapter 77. Backup Manifest Format">Next</a></td></tr><tr><td width="40%" align="left" valign="top">76.2. Multivariate Statistics Examples </td><td width="20%" align="center"><a accesskey="h" href="index.html" title="PostgreSQL 16.3 Documentation">Home</a></td><td width="40%" align="right" valign="top"> Chapter 77. Backup Manifest Format</td></tr></table></div></body></html>
codekingpro/portable-devtools · Team Ai