Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

This project is archived and is in readonly mode.

PostgreSQL adapter: quote_string is not thread safe

#2547

PostgreSQL adapter calls PGconn.escape class method which is not thread safe. Should call PGconn#escape instance method which is thread safe. Simple as that.

The same goes with escape_bytea. There's no PQunescapeByteaConn, so I assume unescpae_bytea is thread safe.

The problem exists at least in 2.2.2+.

Reported by Eugene Pimenov · April 23rd, 2009 @ 10:51 AM

State: resolved
Milestone: 2.x
Assigned to: Tarmo Tänav Tarmo Tänav
Importance: none

Activity

  1. Max Lapshin
    Max Lapshin
    • Assigned user set to Tarmo Tänav

    Eugene, where is written, that PGconn.escape is unsafe?

    April 27th, 2009 @ 03:04 PM

  2. Eugene Pimenov
    Eugene Pimenov
    
    >> puts $$
    94100
    >> PGconn.escape('test')
    => "test"
    >> PGconn.new({}).escape('test')
    => "test"
    
    
     sudo dtrace -n 'pid94100::PQescapeString:entry { printf("it called me\n") } pid94100::PQescapeStringConn:entry { printf("it called me\n") }'
    dtrace: description 'pid94100::PQescapeString:entry ' matched 2 probes
    CPU     ID                    FUNCTION:NAME
      1  22323             PQescapeString:entry it called me
    
      0  22324         PQescapeStringConn:entry it called me
    

    http://www.postgresql.org/docs/8...

    
    PQescapeString can be used safely in single-threaded client programs that work with only one PostgreSQL connection at a time (in this case it can find out what it needs to know "behind the scenes"). In other contexts it is a security hazard and should be avoided in favor of PQescapeStringConn.
    

    April 27th, 2009 @ 03:12 PM

  3. Max Lapshin
    Max Lapshin
    • Tag changed from activecord, database, escape, escaping, patch, postgres, postgresql to activecord, bug, database, escape, escaping, patch, postgres, postgresql

    +1 This patch works for me, all test passed and it seems to be rather good.

    April 27th, 2009 @ 03:33 PM

  4. Michael Koziarski
    Michael Koziarski
    • State changed from new to resolved

    June 9th, 2009 @ 09:13 AM