On 10/1/26 18:49, Jim Jones wrote: > On 01/10/2026 01:14, Alex Liapychev wrote: >> >> My personal view is that adding this functionality carries more risks >> than leaving it out. Although the code is relatively small and appears >> to work correctly, I would not merge it into the codebase. > > You mean the multiple tables scenario or the whole patch? >
Multiple tables scenario, I think. I suggested asking for a "real" use case on Discord, because (a) I still don't know if anyone actually needs this feature, and (b) if there's such use case, it'd probably give us insights what to do about duplicate comments. Yes, I can construct a made-up example, but I struggle to create an example where copying table comments would be meaningful. I think this lack of use case is partially due to the origin of the patch. If it was written because of genuine need for the feature, we'd have the use case by definition. But it was written "because it's missing" and so no use case. I was wondering if maybe this was discussed when the INCLUDING COMMENTS was added, so I did a bit of digging in the archives, and I found this thread from 2009: https://www.postgresql.org/message-id/flat/20090907114058.C855.52131E4D%40oss.ntt.co.jp Unfortunately, there's no discussion about (not) copying table comments. >> An example of how this functionality could be used maliciously: >> >> * A workflow creates a new table from several template tables in >> response to an event. > > Can you elaborate more on this scenario? I'm afraid I didn't get your > point here. Thanks! > >> * An adversarial user with sufficient database access adds one comment >> to each of two template tables. The combined size of these comments >> exceeds |MaxAllocSize|, causing the automation to fail unexpectedly. > > An "adversarial" user with enough privileges can do many things break > it, like renaming a column causing a conflict. I see this large comment > scenario as purely theoretical -- at least I fail to see any practical > use case ever exhausting this limit. > Right. To add comments on an object you have to be an owner, at which point you can do all kinds of dangerous stuff. I was more worried about "accidental breakage" where suddenly copying comments breaks something else. But I failed to construct a practical example, so maybe it's fine. regards -- Tomas Vondra
