postgresql/contrib
Tom Lane 6b11a46878 Make contrib modules' installation scripts more secure.
Hostile objects located within the installation-time search_path could
capture references in an extension's installation or upgrade script.
If the extension is being installed with superuser privileges, this
opens the door to privilege escalation.  While such hazards have existed
all along, their urgency increases with the v13 "trusted extensions"
feature, because that lets a non-superuser control the installation path
for a superuser-privileged script.  Therefore, make a number of changes
to make such situations more secure:

* Tweak the construction of the installation-time search_path to ensure
that references to objects in pg_catalog can't be subverted; and
explicitly add pg_temp to the end of the path to prevent attacks using
temporary objects.

* Disable check_function_bodies within installation/upgrade scripts,
so that any security gaps in SQL-language or PL-language function bodies
cannot create a risk of unwanted installation-time code execution.

* Adjust lookup of type input/receive functions and join estimator
functions to complain if there are multiple candidate functions.  This
prevents capture of references to functions whose signature is not the
first one checked; and it's arguably more user-friendly anyway.

* Modify various contrib upgrade scripts to ensure that catalog
modification queries are executed with secure search paths.  (These
are in-place modifications with no extension version changes, since
it is the update process itself that is at issue, not the end result.)

Extensions that depend on other extensions cannot be made fully secure
by these methods alone; therefore, revert the "trusted" marking that
commit eb67623c9 applied to earthdistance and hstore_plperl, pending
some better solution to that set of issues.

Also add documentation around these issues, to help extension authors
write secure installation scripts.

Patch by me, following an observation by Andres Freund; thanks
to Noah Misch for review.

Security: CVE-2020-14350
2020-08-10 10:44:43 -04:00
..
adminpack Add missing errcode() in a few ereport calls. 2020-03-18 10:10:27 +05:30
auth_delay Add file version information to most installed Windows binaries. 2014-07-14 14:07:52 -04:00
auto_explain Allow auto_explain.log_min_duration to go up to INT_MAX. 2018-02-23 14:39:21 -05:00
btree_gin Make contrib regression tests safe for Danish locale. 2016-07-21 16:52:36 -04:00
btree_gist Get rid of trailing semicolons in C macro definitions. 2020-05-01 17:28:01 -04:00
chkpass Avoid returning undefined bytes in chkpass_in(). 2015-02-14 12:20:56 -05:00
citext Make contrib modules' installation scripts more secure. 2020-08-10 10:44:43 -04:00
cube Enforce cube dimension limit in all cube construction functions 2018-08-31 20:06:49 +03:00
dblink Initialize dblink remoteConn struct in all cases 2020-05-28 13:45:15 -04:00
dict_int Ensure maxlen is at leat 1 in dict_int 2019-12-03 18:42:54 +01:00
dict_xsyn Update copyright for 2015 2015-01-06 11:43:47 -05:00
earthdistance Make contrib modules' installation scripts more secure. 2020-08-10 10:44:43 -04:00
file_fdw Ensure that foreign scans with lateral refs are planned correctly. 2019-02-07 13:11:17 -05:00
fuzzystrmatch Remove new coupling between NAMEDATALEN and MAX_LEVENSHTEIN_STRLEN. 2016-01-22 11:53:06 -05:00
hstore Make contrib modules' installation scripts more secure. 2020-08-10 10:44:43 -04:00
hstore_plperl Still further rethinking of build changes for macOS Mojave. 2018-10-18 14:55:23 -04:00
hstore_plpython Fix volatile vs. pointer confusion 2019-03-15 08:39:12 +01:00
intagg Fix typos in some error messages thrown by extension scripts when fed to psql. 2014-08-25 18:30:37 +02:00
intarray Make contrib modules' installation scripts more secure. 2020-08-10 10:44:43 -04:00
isn Fix typos in comments. 2017-02-06 11:34:18 +02:00
lo Fix bogus CALLED_AS_TRIGGER() defenses. 2020-04-03 11:24:56 -04:00
ltree Back-patch addition of stack overflow and interrupt checks for lquery. 2020-03-31 11:37:44 -04:00
ltree_plpython Prevent accidental linking of system-supplied copies of libpq.so etc. 2018-07-09 17:23:31 -04:00
oid2name Prevent accidental linking of system-supplied copies of libpq.so etc. 2018-07-09 17:23:31 -04:00
pageinspect Back-patch portability fixes for contrib/pageinspect/ginfuncs.c. 2016-11-04 12:37:29 -04:00
passwordcheck Fix handling of previous password hooks in passwordcheck 2019-08-01 09:38:25 +09:00
pg_buffercache pg_buffercache: Allow huge allocations. 2016-09-15 09:30:36 -04:00
pg_freespacemap Fix typos in some error messages thrown by extension scripts when fed to psql. 2014-08-25 18:30:37 +02:00
pg_prewarm Avoid using potentially-under-aligned page buffers. 2018-09-01 15:27:13 -04:00
pg_standby Fix new warnings from GCC 7 2017-05-16 08:43:55 -04:00
pg_stat_statements Fix typos in comments. 2017-02-06 11:34:18 +02:00
pg_trgm Make contrib modules' installation scripts more secure. 2020-08-10 10:44:43 -04:00
pgcrypto Fix corner case with 16kB-long decompression in pgcrypto, take 2 2020-07-27 15:59:22 +09:00
pgrowlocks Avoid holding a directory FD open across assorted SRF calls. 2020-03-16 21:05:29 -04:00
pgstattuple Remove unused macros. 2016-05-02 10:08:58 +03:00
postgres_fdw libpq should expose GSS-related parameters even when not implemented. 2019-12-20 15:34:08 -05:00
seg Fix typos in comments. 2017-02-06 11:34:18 +02:00
sepgsql Fix cache reference leak in contrib/sepgsql. 2020-04-16 14:45:54 -04:00
spi Prevent accidental linking of system-supplied copies of libpq.so etc. 2018-07-09 17:23:31 -04:00
sslinfo Fix error message wording in previous sslinfo commit 2015-09-08 11:10:20 -03:00
start-scripts Provide modern examples of how to auto-start Postgres on macOS. 2017-11-17 12:47:29 -05:00
tablefunc Disallow null category in crosstab_hash 2019-12-23 13:34:05 -05:00
tcn Update copyright for 2015 2015-01-06 11:43:47 -05:00
test_decoding Stop demanding that top xact must be seen before subxact in decoding. 2020-02-19 08:59:18 +05:30
tsearch2 Make contrib modules' installation scripts more secure. 2020-08-10 10:44:43 -04:00
tsm_system_rows Redesign tablesample method API, and do extensive code review. 2015-07-25 14:39:00 -04:00
tsm_system_time Some platforms now need contrib/tsm_system_time to be linked with libm. 2015-07-25 16:37:22 -04:00
unaccent Make contrib/unaccent's unaccent() function work when not in search path. 2018-09-06 10:49:45 -04:00
uuid-ossp Give a useful error message if uuid-ossp is built without preconfiguration. 2016-12-22 11:19:18 -05:00
vacuumlo Fix copy-pasto in freeing memory on error in vacuumlo. 2019-06-07 12:44:06 +03:00
xml2 Fix typos in comments. 2017-02-06 11:34:18 +02:00
Makefile Finish removing pg_audit 2015-05-28 12:48:25 -04:00
README Rename 'gmake' to 'make' in docs and recommended commands 2014-02-12 17:29:19 -05:00
contrib-global.mk Remove cvs keywords from all files. 2010-09-20 22:08:53 +02:00

README

The PostgreSQL contrib tree
---------------------------

This subtree contains porting tools, analysis utilities, and plug-in
features that are not part of the core PostgreSQL system, mainly
because they address a limited audience or are too experimental to be
part of the main source tree.  This does not preclude their
usefulness.

User documentation for each module appears in the main SGML
documentation.

When building from the source distribution, these modules are not
built automatically, unless you build the "world" target.  You can
also build and install them all by running "make all" and "make
install" in this directory; or to build and install just one selected
module, do the same in that module's subdirectory.

Some directories supply new user-defined functions, operators, or
types.  To make use of one of these modules, after you have installed
the code you need to register the new SQL objects in the database
system by executing a CREATE EXTENSION command.  In a fresh database,
you can simply do

    CREATE EXTENSION module_name;

See the PostgreSQL documentation for more information about this
procedure.