postgresql/src/backend/parser
Tom Lane b9b21acc76 In extensions, don't replace objects not belonging to the extension.
Previously, if an extension script did CREATE OR REPLACE and there was
an existing object not belonging to the extension, it would overwrite
the object and adopt it into the extension.  This is problematic, first
because the overwrite is probably unintentional, and second because we
didn't change the object's ownership.  Thus a hostile user could create
an object in advance of an expected CREATE EXTENSION command, and would
then have ownership rights on an extension object, which could be
modified for trojan-horse-type attacks.

Hence, forbid CREATE OR REPLACE of an existing object unless it already
belongs to the extension.  (Note that we've always forbidden replacing
an object that belongs to some other extension; only the behavior for
previously-free-standing objects changes here.)

For the same reason, also fail CREATE IF NOT EXISTS when there is
an existing object that doesn't belong to the extension.

Our thanks to Sven Klemm for reporting this problem.

Security: CVE-2022-2625
2022-08-08 11:12:31 -04:00
..
.gitignore Convert cvsignore to gitignore, and add .gitignore for build targets. 2010-09-22 12:57:04 +02:00
analyze.c Make subquery aliases optional in the FROM clause. 2022-07-20 09:29:42 +01:00
check_keywords.pl Update copyright for 2022 2022-01-07 19:04:57 -05:00
gram.y Fix a few issues with REINDEX grammar 2022-07-26 10:16:26 +09:00
Makefile JSON_TABLE 2022-04-04 16:03:47 -04:00
parse_agg.c Add support for MERGE SQL command 2022-03-28 16:47:48 +02:00
parse_clause.c Make subquery aliases optional in the FROM clause. 2022-07-20 09:29:42 +01:00
parse_coerce.c Fix failure to validate the result of select_common_type(). 2022-01-29 11:41:18 -05:00
parse_collate.c Pre-beta mechanical code beautification. 2022-05-12 15:17:30 -04:00
parse_cte.c Update copyright for 2022 2022-01-07 19:04:57 -05:00
parse_enr.c Update copyright for 2022 2022-01-07 19:04:57 -05:00
parse_expr.c Improve performance of ORDER BY / DISTINCT aggregates 2022-08-02 23:11:45 +12:00
parse_func.c Improve performance of ORDER BY / DISTINCT aggregates 2022-08-02 23:11:45 +12:00
parse_jsontable.c Tweak detail and hint messages to be consistent with project policy 2022-07-20 09:50:12 +09:00
parse_merge.c Change mechanism to set up source targetlist in MERGE 2022-04-12 09:29:39 +02:00
parse_node.c In transformRowExpr(), check for too many columns in the row. 2022-07-29 13:31:10 -04:00
parse_oper.c Update copyright for 2022 2022-01-07 19:04:57 -05:00
parse_param.c Pre-beta mechanical code beautification. 2022-05-12 15:17:30 -04:00
parse_relation.c Check maximum number of columns in function RTEs, too. 2022-08-01 12:22:35 -04:00
parse_target.c Replace many MemSet calls with struct initialization 2022-07-16 08:50:49 +02:00
parse_type.c Add construct_array_builtin, deconstruct_array_builtin 2022-07-01 11:23:15 +02:00
parse_utilcmd.c In extensions, don't replace objects not belonging to the extension. 2022-08-08 11:12:31 -04:00
parser.c SQL/JSON constructors 2022-03-27 17:03:34 -04:00
README Update src/backend/parser/README 2022-07-22 12:56:21 +02:00
scan.l Reject trailing junk after numeric literals 2022-02-16 10:37:31 +01:00
scansup.c Update copyright for 2022 2022-01-07 19:04:57 -05:00

src/backend/parser/README

Parser
======

This directory does more than tokenize and parse SQL queries.  It also
creates Query structures for the various complex queries that are passed
to the optimizer and then executor.

parser.c	things start here
scan.l		break query into tokens
scansup.c	handle escapes in input strings
gram.y		parse the tokens and produce a "raw" parse tree
analyze.c	top level of parse analysis for optimizable queries
parse_agg.c	handle aggregates, like SUM(col1),  AVG(col2), ...
parse_clause.c	handle clauses like WHERE, ORDER BY, GROUP BY, ...
parse_coerce.c	handle coercing expressions to different data types
parse_collate.c	assign collation information in completed expressions
parse_cte.c	handle Common Table Expressions (WITH clauses)
parse_expr.c	handle expressions like col, col + 3, x = 3 or x = 4
parse_enr.c	handle ephemeral named rels (trigger transition tables, ...)
parse_func.c	handle functions, table.column and column identifiers
parse_jsontable.c handle JSON_TABLE
parse_merge.c	handle MERGE
parse_node.c	create nodes for various structures
parse_oper.c	handle operators in expressions
parse_param.c	handle Params (for the cases used in the core backend)
parse_relation.c support routines for tables and column handling
parse_target.c	handle the result list of the query
parse_type.c	support routines for data type handling
parse_utilcmd.c	parse analysis for utility commands (done at execution time)

See also src/common/keywords.c, which contains the table of standard
keywords and the keyword lookup function.  We separated that out because
various frontend code wants to use it too.