eeshwarg opened a new pull request, #2497:
URL: https://github.com/apache/age/pull/2497
## Problem
Any non-superuser calling `drop_label('graph', 'label')` (or dropping a
vertex/edge label) fails with:
```
ERROR: unrecognized class ID: <oid>
```
Superusers are unaffected.
## Root cause
In `src/backend/commands/label_commands.c`,
`range_var_callback_for_remove_relation()` calls the PG16+
`object_ownercheck()` with the wrong argument order. The API is:
```c
bool object_ownercheck(Oid classid, Oid objectid, Oid roleid);
```
AGE passed `rel_oid` as `classid` (should be `RelationRelationId`) and a
namespace OID as `objectid` (should be `rel_oid`). Since `classid` isn't a real
catalog OID, the lookup hits the `default` case in `get_object_property` and
raises `unrecognized class ID`. Superusers escape because `object_ownercheck`
early-returns via `superuser_arg(roleid)` before the classid lookup.
This was introduced in the PG16 port: before PG16 the code used the correct
2-arg `pg_class_ownercheck(rel_oid, GetUserId())`. The same defect is present
on `master`, `PG16`, `PG17`, and `PG18`; PG15 and earlier are unaffected. This
PR fixes `master`.
## Fix
```c
- if (!object_ownercheck(rel_oid, get_rel_namespace(rel_oid),
GetUserId()))
+ if (!object_ownercheck(RelationRelationId, rel_oid, GetUserId()))
```
This matches upstream PostgreSQL's own `RangeVarCallbackForDropRelation`
usage. `RelationRelationId` is already available via existing includes
(`catalog/pg_class_d.h`); no new include needed.
## Testing
- Added a regression test in `regress/sql/security.sql`: a `NOSUPERUSER`
role creates (and therefore owns) a graph and label, then successfully runs
`drop_label`. Verified it **fails** with `ERROR: unrecognized class ID` on the
unpatched build and **passes** after the fix.
- `make installcheck` full suite: **42/42 tests pass** (PostgreSQL 18).
Co-authored-by: Copilot <[email protected]>
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]