Eine aufbereitete Darstellung der Quelle

 
     
 
 
Anforderungen  |   Konzepte  |   Entwurf  |   Entwicklung  |   Qualitätssicherung  |   Lebenszyklus  |   Steuerung
 
 
 
 

Benutzer

Quelle  deny_bugs.result   Sprache: Lisp

 

#
# MDEV-40014 Access to freed/poisoned memory in SHOW GRANTS
# after REVOKE DENY, if only negative grants are present
#
CREATE TABLE t1(val int);
CREATE USER u;
DENY EXECUTE ON test.* TO u;
DENY UPDATE (val) ON t1 TO u;
REVOKE DENY EXECUTE ON test.* FROM u;
SHOW GRANTS FOR u;
Grants for u@%
GRANT USAGE ON *.* TO `u`@`%`
DENY UPDATE (`val`) ON `test`.`t1` TO `u`@`%`
DROP USER u;
DROP TABLE t1;
#
# MDEV-40028 Assertion `rights.allow_bits() == merged->cols' failed in int update_role_columns
#
CREATE TABLE t (c1 INT, c2 INT, c3 int);
CREATE ROLE r;
DENY SELECT (c2) ON t TO r;
SHOW GRANTS FOR r;
Grants for r
GRANT USAGE ON *.* TO `r`
DENY SELECT (`c2`) ON `test`.`t` TO `r`
REVOKE DENY SELECT (c2) ON t FROM r;
SHOW GRANTS FOR r;
Grants for r
GRANT USAGE ON *.* TO `r`
DROP ROLE r;
DROP TABLE t;
#
# MDEV-36503 Single routine-level DENY EXECUTE hides other routine metadata in the database
#
CREATE DATABASE d1;
CREATE DEFINER=root@localhost PROCEDURE d1.p1() BEGIN SELECT 1; END$$
CREATE DEFINER=root@localhost PROCEDURE d1.p2() BEGIN SELECT 2; END$$
CREATE USER u@localhost;
GRANT EXECUTE ON d1.* TO u@localhost;
DENY EXECUTE ON PROCEDURE d1.p1 TO u@localhost;
DENY ALTER ROUTINE ON PROCEDURE d1.p2 TO u@localhost;
FLUSH PRIVILEGES;
connect  con_bug36503, localhost, u,,d1;
# p2 must be callable and both p1, p2 must appear in INFORMATION_SCHEMA.ROUTINES
CALL p2();
2
2
SELECT ROUTINE_NAME FROM information_schema.ROUTINES WHERE ROUTINE_SCHEMA='d1' ORDER BY ROUTINE_NAME;
ROUTINE_NAME
p2
# p1 is denied, calling it must fail
CALL p1();
ERROR 42000: execute command denied to user 'u'@'localhost' for routine 'd1.p1'
disconnect con_bug36503;
connection default;
DROP DATABASE d1;
DROP USER u@localhost;
#
# MDEV-40116 Column-level DENY SELECT hides accessible columns and table metadata
#
CREATE DATABASE d1;
CREATE TABLE d1.t1 (a INT, b INT, c INT, KEY(a));
INSERT INTO d1.t1 VALUES (1,2,3);
CREATE USER u@localhost;
GRANT SELECT ON d1.t1 TO u@localhost;
DENY SELECT (b) ON d1.t1 TO u@localhost;
FLUSH PRIVILEGES;
connect  con_bug40116, localhost, u,,d1;
# a and c are accessible, b is denied
SELECT a, c FROM d1.t1;
a c
1 3
SELECT * FROM d1.t1;
ERROR 42000: SELECT command denied to user 'u'@'localhost' for column 'b' in table 't1'
# metadata commands must work and show a, c (not b)
SHOW COLUMNS FROM d1.t1;
Field Type Null Key Default Extra
a int(11) YES MUL NULL 
c int(11) YES  NULL 
SHOW INDEX FROM d1.t1;
Table Non_unique Key_name Seq_in_index Column_name Collation Cardinality Sub_part Packed Null Index_type Comment Index_comment Ignored
t1 1 a 1 a A NULL NULL NULL YES BTREE   NO
SHOW CREATE TABLE d1.t1;
Table Create Table
t1 CREATE TABLE `t1` (
  `a` int(11) DEFAULT NULL,
  `b` int(11) DEFAULT NULL,
  `c` int(11) DEFAULT NULL,
  KEY `a` (`a`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_uca1400_ai_ci
SELECT COLUMN_NAME FROM information_schema.COLUMNS
WHERE TABLE_SCHEMA='d1' AND TABLE_NAME='t1' ORDER BY COLUMN_NAME;
COLUMN_NAME
a
c
disconnect con_bug40116;
connection default;
DROP DATABASE d1;
DROP USER u@localhost;
#
# MDEV-40026 SIGSEGV in acl_insert_db on FLUSH PRIVILEGES with overlong DENY names
#
CREATE USER u@localhost;
CALL mtr.add_suppression('.*Malformed DENY entry in mysql\\.global_priv at array position [0-2] for ''u''@''localhost'' ignored');
UPDATE mysql.global_priv SET Priv= json_set(Priv, '$.denies', json_array(
json_object('type','db',  'db',REPEAT('a',300),'bits',1),
json_object('type','table','db','d1','table',REPEAT('b',300),'bits',1),
json_object('type','column','db','d1','table','t1','column',REPEAT('c',300),'bits',1)
)) WHERE User='u' AND Host='localhost';
FLUSH PRIVILEGES;
FOUND 1 /Malformed DENY entry in mysql.global_priv at array position 0 for 'u'@'localhost' ignored/ in mysqld.1.err
FOUND 1 /Malformed DENY entry in mysql.global_priv at array position 1 for 'u'@'localhost' ignored/ in mysqld.1.err
FOUND 1 /Malformed DENY entry in mysql.global_priv at array position 2 for 'u'@'localhost' ignored/ in mysqld.1.err
DROP USER u@localhost;
#
# MDEV-40131 DENY not reloaded, granted to a ROLEs exclusively
#
CREATE DATABASE d1;
CREATE TABLE d1.t1 (a INT);
INSERT INTO d1.t1 VALUES (1);
CREATE ROLE r;
GRANT SELECT ON d1.* TO r;
DENY SELECT ON d1.t1 TO r;
CREATE USER u@localhost;
GRANT r TO u@localhost;
SET DEFAULT ROLE r FOR u@localhost;
# BEFORE reload: role DENY correctly enforced
connect  p, localhost, u,, d1;
SELECT * FROM d1.t1;
ERROR 42000: SELECT command denied to user 'u'@'localhost' for table `d1`.`t1`
connection default;
disconnect p;
FLUSH PRIVILEGES;
# role DENY must survive the reload
SHOW GRANTS FOR r;
Grants for r
GRANT USAGE ON *.* TO `r`
GRANT SELECT ON `d1`.* TO `r`
DENY SELECT ON `d1`.`t1` TO `r`
# AFTER reload: role DENY must still be enforced
connect  p, localhost, u,, d1;
SELECT * FROM d1.t1;
ERROR 42000: SELECT command denied to user 'u'@'localhost' for table `d1`.`t1`
connection default;
disconnect p;
DROP ROLE r;
DROP DATABASE d1;
DROP USER u@localhost;
#
# MDEV-40300 Assertion in update_role_columns on DROP ROLE
#
CREATE TABLE t1 (c1 INT,c2 INT,c3 INT);
CREATE ROLE r1;
CREATE ROLE r2;
GRANT r2 TO r1;
DENY DELETE ON t1 TO r1;
DENY SELECT (c2) ON t1 TO r1;
GRANT SELECT (c3) ON t1 TO r2;
REVOKE DENY ALL PRIVILEGES ON t1 FROM r1;
DROP ROLE IF EXISTS r2;
SHOW GRANTS FOR r1;
Grants for r1
GRANT USAGE ON *.* TO `r1`
DENY SELECT (`c2`) ON `test`.`t1` TO `r1`
DROP ROLE r1;
DROP TABLE t1;

Messung V0.5 in Prozent
C=47 H=100 G=78

¤ Dauer der Verarbeitung: 0.11 Sekunden  (vorverarbeitet am  2026-10-08) ¤

*© Formatika GbR, Deutschland






Wurzel

Suchen

PVS Prover

Isabelle Prover

NIST Cobol Testsuite

Cephes Mathematical Library

Vienna Development Method

Haftungshinweis

Die Informationen auf dieser Webseite wurden nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit, noch Qualität der bereit gestellten Informationen zugesichert.

Bemerkung:

Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.






                                                                                                                                                                                                                                                                                                                                                                                                     


Neuigkeiten

     Aktuelles
     Motto des Tages

Open Source Software

     Quellcodebibliothek
     Eigene Quellcodes
     Fremde Quellcodes
     Suchen

Jenseits des Üblichen ....
    

Besucherstatistik

Besucherstatistik

Statistik
#Sources=1126864
#Domains=1897691