fix(query): validate security policy metadata in planner cache#19897
Merged
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 34bfdffcbb
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
cc085ab to
f2d2f39
Compare
Planner cache used to validate cached plans only by table schema and snapshot. This could reuse a stale plan after row access policy or masking policy metadata changed on a table. This change records security policy metadata in the planner cache context and compares it on cache lookup. Normal table queries keep the SQL-only cache key. Queries involving security policies use a secure key that also includes tenant, current user, current role, and secondary roles, avoiding cross-user reuse when policy bodies depend on session context such as current_user(). Also enable planner cache in security policy regression suites and add targeted coverage for RAP attach/detach, masking policy set/unset, and same-role different-user masking policy plans.
zhang2014
approved these changes
May 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
I hereby agree to the terms of the CLA available at: https://docs.databend.com/dev/policies/cla/
Summary
Planner cache used to validate cached plans only by table schema and snapshot. This could reuse a stale plan after row access policy or masking policy metadata changed on a table.
This change records security policy metadata in the planner cache context and compares it on cache lookup. Normal table queries keep the SQL-only cache key. Queries involving security policies use a secure key that also includes tenant, current user, current role, and secondary roles, avoiding cross-user reuse when policy bodies depend on session context such as current_user().
Also enable planner cache in security policy regression suites and add targeted coverage for RAP attach/detach, masking policy set/unset, and same-role different-user masking policy plans.
Tests
Type of change
This change is