You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
#585 bounds PostgreSQL U&"..." identity for pg_settings UPDATE, but the direct SET path still matches only a normalized token equal to session_replication_role. The shared lexer currently preserves the U& prefix separately and projects the following quoted identifier. PostgreSQL's grammar accepts generic SET parameter names through var_name: ColId, and Unicode-escaped quoted identifiers are converted to ordinary identifier tokens before grammar reduction. Therefore a committed statement such as:
SET U&"session_replication_role"= replica;
or a code-point spelling such as:
SET U&"session_replication_\0072ole" TO replica;
resolves to the protected configuration parameter in PostgreSQL but can miss TEPP's direct-SET execution-context guard. That can suppress ordinary/default triggers while historical append-only/retention trigger definitions remain present.
PostgreSQL parser grammar reduces generic SET names through var_name: ColId and Unicode identifiers are decoded to identifier tokens by the raw parser (src/backend/parser/gram.y, src/backend/parser/parser.c, REL_18_STABLE).
Reuse the single lexical pass and the committed execution-context fold. Do not rewrite executable migration SQL. Prefer one helper that resolves the direct SET parameter span consistently with #585's interim Unicode handling and leaves non-SET structural consumers untouched.
Keep open until post-#538 non-force-restack exact-head hosted Rust/Live PostgreSQL, current-topology rustdoc/coverage/security, resolved valid findings, and qualifying independent approval exist. Draft-skipped execution is not GREEN.
Finding
#585 bounds PostgreSQL
U&"..."identity forpg_settingsUPDATE, but the directSETpath still matches only a normalized token equal tosession_replication_role. The shared lexer currently preserves theU&prefix separately and projects the following quoted identifier. PostgreSQL's grammar accepts generic SET parameter names throughvar_name: ColId, and Unicode-escaped quoted identifiers are converted to ordinary identifier tokens before grammar reduction. Therefore a committed statement such as:or a code-point spelling such as:
resolves to the protected configuration parameter in PostgreSQL but can miss TEPP's direct-SET execution-context guard. That can suppress ordinary/default triggers while historical append-only/retention trigger definitions remain present.
Primary PostgreSQL 18 authority:
U&"...", code-point escapes, optionalUESCAPE) are PostgreSQL identifier syntax: https://www.postgresql.org/docs/18/sql-syntax-lexical.htmlSETnames throughvar_name: ColIdand Unicode identifiers are decoded to identifier tokens by the raw parser (src/backend/parser/gram.y,src/backend/parser/parser.c, REL_18_STABLE).session_replication_role=replicasuppresses ordinary/default triggers and rules: https://www.postgresql.org/docs/18/runtime-config-client.html#GUC-SESSION-REPLICATION-ROLERequired contract
At exported
validate_migration_catalog():SET U&"session_replication_role" = replicafails the runtime-role contract;UESCAPEspellings fail closed;SET LOCAL/SET SESSIONvariants cross the same boundary;origin/localremain statically safe only when protected parameter identity is established;Repair boundary
Reuse the single lexical pass and the committed execution-context fold. Do not rewrite executable migration SQL. Prefer one helper that resolves the direct SET parameter span consistently with #585's interim Unicode handling and leaves non-SET structural consumers untouched.
Keep open until post-#538 non-force-restack exact-head hosted Rust/Live PostgreSQL, current-topology rustdoc/coverage/security, resolved valid findings, and qualifying independent approval exist. Draft-skipped execution is not GREEN.