vitvara opened a new pull request, #68795:
URL: https://github.com/apache/doris/pull/68795
### What problem does this PR solve?
Issue Number: None
Related PR: None
Problem Summary:
A row policy may compare a column against a user variable, so one policy
serves every session and each session says which rows it may see:
```sql
CREATE ROW POLICY p ON db.t AS RESTRICTIVE TO ROLE r
USING (restaurant_id = @authorized_restaurant);
```
The policy is created, but afterwards `SHOW ROW POLICY` fails with `Invalid
call to sql on unbound object`. It fails for every listing that includes the
policy, not only for a listing of this one policy, because the listing builds
the rows of all matching policies in one pass.
Root cause: `RowPolicy#getShowInfo` renders the stored predicate with
`Expression#toSql`. The variable stays an `UnboundVariable` until a query binds
it to the session value, and `UnboundVariable` does not override
`computeToSql`, so it falls back to `Expression#computeToSql`, which throws
`UnboundException`. Its bound counterpart `Variable` already renders itself.
Fix: implement `UnboundVariable#computeToSql`, rendering the variable the
way the parser reads it (`@name`, `@@name`, `@@session.name`, `@@global.name`),
so the text parses back to the same variable.
Before: `SHOW ROW POLICY` → `ERROR: Invalid call to sql on unbound object`
After: `SHOW ROW POLICY` → lists the policy with `WherePredicate =
(restaurant_id = @authorized_restaurant)`
Hit on 4.1.3 in production. Could a committer add the `dev/4.1.x` label? The
automatic pick will conflict on `RowPolicyFilterSqlTest.java` (the file does
not exist on branch-4.1); a manual backport branch without that test change is
ready and will be opened against branch-4.1 once this is merged.
### Release note
Fix `SHOW ROW POLICY` failing with "Invalid call to sql on unbound object"
when a row policy's `USING` clause references a user or system variable.
### Check List (For Author)
- Test
- [x] Regression test
- [x] Unit Test
- [x] Manual test (add detailed scripts or steps below)
- Same Doris 4.1.4 cluster (`apache/doris:fe-4.1.4` + `be-4.1.4`,
Docker), FE jar swapped:
1. Official FE: `CREATE ROW POLICY ... AS RESTRICTIVE TO
ROLE r USING (Host = @authorized_restaurant);` then `SHOW ROW POLICY` → `ERROR:
Invalid call to sql on unbound object`.
2. Replaced `doris-fe.jar` with one built from tag 4.1.4
plus this change and restarted the FE (the policy was loaded back from FE
metadata). `SHOW ROW POLICY` → returns the policy, `WherePredicate = (Host =
@authorized_restaurant)`.
- [ ] No need to test or manual test. Explain why:
- [ ] This is a refactor/code format and no logic has been changed.
- [ ] Previous test can cover this change.
- [ ] No code files have been changed.
- [ ] Other reason <!-- Add your reason? -->
- Behavior changed:
- [x] No.
- [ ] Yes. <!-- Explain the behavior change -->
- Does this need documentation?
- [x] No.
- [ ] Yes. <!-- Add document PR link here. eg:
https://github.com/apache/doris-website/pull/1214 -->
### Check List (For Reviewer who merge this PR)
- [ ] Confirm the release note
- [ ] Confirm test cases
- [ ] Confirm document
- [ ] Add branch pick label <!-- Add branch pick label that this PR should
merge into -->
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]