Hi,

On Thu, Aug 27, 2026 at 12:52 PM Matheus Alcantara
<[email protected]> wrote:
>
> On 27/08/26 16:19, Nathan Bossart wrote:
> > The patch looks reasonable to me.
> >
> > On Thu, Aug 27, 2026 at 03:55:11PM -0300, Matheus Alcantara wrote:
> >> Added this new test case on attached.
> >
> > I'm not sure the new tests are necessary.  It seems unlikely that we'll
> > accidentally remove the flags down the road.
> >
>
> Yeah, I also think that is unlikely that we'll remove, I just put the
> test to be more conservative. I think that is good to have such tests
> to ensure that these bugs are not re-introduced but given that this
> seems a minor/oversight I'm not totally against not adding them.
> Attached is v3 without the tests.

+1 not skipping the test.

The patch looks good to me. I've slightly rephrased the comment and
commit message. I'm going to push it barring any objections.

Regards,

-- 
Masahiko Sawada
Amazon Web Services: https://aws.amazon.com
From a044532e65a7cb1da56aa761eefc9ca082c4d02c Mon Sep 17 00:00:00 2001
From: Matheus Alcantara <[email protected]>
Date: Thu, 27 Aug 2026 15:07:39 -0300
Subject: [PATCH v4] Fix REPACK (CONCURRENTLY) when the table owner lacks
 CONNECT.

REPACK (CONCURRENTLY) launches a background worker to decode changes
made while the table is being rewritten. The worker connects as the
table owner but bypassed the LOGIN check only, so CONNECT was still
checked against a role that need not have it, and the command could
fail with "permission denied for database".

Pass BGWORKER_BYPASS_ALLOWCONN as well, as we do for parallel
workers. That is safe because the leader already checked the invoking
user's privileges on the table before starting the worker.

Reported-by: Nathan Bossart <[email protected]>
Author: Matheus Alcantara <[email protected]>
Reviewed-by: Nathan Bossart <[email protected]>
Reviewed-by: Bharath Rupireddy <[email protected]>
Reviewed-by: Masahiko Sawada <[email protected]>
Discussion: https://postgr.es/m/apBbzFd_EYAfHV45@nathan
Backpatch-through: 19
---
 src/backend/commands/repack_worker.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/src/backend/commands/repack_worker.c b/src/backend/commands/repack_worker.c
index af7e2a94764..b4ba9cfc67b 100644
--- a/src/backend/commands/repack_worker.c
+++ b/src/backend/commands/repack_worker.c
@@ -101,8 +101,14 @@ RepackWorkerMain(Datum main_arg)
 	pq_set_parallel_leader(shared->backend_pid,
 						   shared->backend_proc_number);
 
-	/* Connect to the database. LOGIN is not required. */
+	/*
+	 * Connect to the database, skipping the connection authorization checks
+	 * as parallel workers do.  Note that we run as the owner of the table
+	 * being repacked, who need not be able to log in or connect; the leader
+	 * checked the invoking user's privileges before starting us.
+	 */
 	BackgroundWorkerInitializeConnectionByOid(shared->dbid, shared->roleid,
+											  BGWORKER_BYPASS_ALLOWCONN |
 											  BGWORKER_BYPASS_ROLELOGINCHECK);
 
 	/*
-- 
2.55.0

Reply via email to