On Thu, Sep 24, 2026 at 7:46 PM Hayato Kuroda (Fujitsu) <[email protected]> wrote: > ``` > + /* > + * XXX SplitGUCList won't respect guc_malloc requirements, but this is > + * consistent with other check_hook implementations... > + */ > ``` > > Let me clarify: it's because the SplitGUCList()->lappend() can raise OOM > error, > right?
Right. > Is the same check in StartupDecodingContext() still needed? I.e. we can check > the returned value > by Assert() here. Ah, thanks. I think we should avoid relying on assertions in security-critical code, but I've simplified the dead code path to an elog(ERROR). > +# check.c assumes the list syntax of output_plugin_libraries is validated by > the > +# server, so take a moment to confirm that now. (This is difficult to test > via > +# regression suite, because our SET grammar won't accept the bad syntax.) > ``` > > Per my experiment, an SQL function set_config() is usable. So can't we put in > guc.sql? > PSA my idea. Thank you! I completely forgot about set_config(); that should make backpatching much simpler. I applied your patch with is_local set to true instead of false, so a regression failure won't change state for later tests in the file. v2 attached. Thanks, --Jacob
v2-0001-Add-a-check_hook-for-output_plugin_libraries.patch
Description: Binary data
