Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Remove undocumented shorthand for when setting keys #383

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jun 2, 2025
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions contrib/pg_tde/expected/key_provider.out
Original file line number Diff line number Diff line change
Expand Up @@ -328,6 +328,15 @@ SELECT pg_tde_delete_database_key_provider(NULL);
ERROR: provider_name cannot be null
SELECT pg_tde_delete_global_key_provider(NULL);
ERROR: provider_name cannot be null
-- Setting principal key fails if provider name is NULL
SELECT pg_tde_set_default_key_using_global_key_provider('key', NULL);
ERROR: key provider name cannot be null
SELECT pg_tde_set_key_using_database_key_provider('key', NULL);
ERROR: key provider name cannot be null
SELECT pg_tde_set_key_using_global_key_provider('key', NULL);
ERROR: key provider name cannot be null
SELECT pg_tde_set_server_key_using_global_key_provider('key', NULL);
ERROR: key provider name cannot be null
-- Setting principal key fails if key name is NULL
SELECT pg_tde_set_default_key_using_global_key_provider(NULL, 'file-keyring');
ERROR: key name cannot be null
Expand Down
8 changes: 4 additions & 4 deletions contrib/pg_tde/pg_tde--1.0-rc.sql
Original file line number Diff line number Diff line change
Expand Up @@ -419,22 +419,22 @@ STRICT
LANGUAGE C
AS 'MODULE_PATHNAME';

CREATE FUNCTION pg_tde_set_key_using_database_key_provider(key_name TEXT, provider_name TEXT DEFAULT NULL, ensure_new_key BOOLEAN DEFAULT FALSE)
CREATE FUNCTION pg_tde_set_key_using_database_key_provider(key_name TEXT, provider_name TEXT, ensure_new_key BOOLEAN DEFAULT FALSE)
RETURNS VOID
LANGUAGE C
AS 'MODULE_PATHNAME';

CREATE FUNCTION pg_tde_set_key_using_global_key_provider(key_name TEXT, provider_name TEXT DEFAULT NULL, ensure_new_key BOOLEAN DEFAULT FALSE)
CREATE FUNCTION pg_tde_set_key_using_global_key_provider(key_name TEXT, provider_name TEXT, ensure_new_key BOOLEAN DEFAULT FALSE)
RETURNS VOID
LANGUAGE C
AS 'MODULE_PATHNAME';

CREATE FUNCTION pg_tde_set_server_key_using_global_key_provider(key_name TEXT, provider_name TEXT DEFAULT NULL, ensure_new_key BOOLEAN DEFAULT FALSE)
CREATE FUNCTION pg_tde_set_server_key_using_global_key_provider(key_name TEXT, provider_name TEXT, ensure_new_key BOOLEAN DEFAULT FALSE)
RETURNS VOID
LANGUAGE C
AS 'MODULE_PATHNAME';

CREATE FUNCTION pg_tde_set_default_key_using_global_key_provider(key_name TEXT, provider_name TEXT DEFAULT NULL, ensure_new_key BOOLEAN DEFAULT FALSE)
CREATE FUNCTION pg_tde_set_default_key_using_global_key_provider(key_name TEXT, provider_name TEXT, ensure_new_key BOOLEAN DEFAULT FALSE)
RETURNS VOID
AS 'MODULE_PATHNAME'
LANGUAGE C;
Expand Down
6 changes: 6 additions & 0 deletions contrib/pg_tde/sql/key_provider.sql
Original file line number Diff line number Diff line change
Expand Up @@ -160,6 +160,12 @@ DROP DATABASE db_using_database_provider;
SELECT pg_tde_delete_database_key_provider(NULL);
SELECT pg_tde_delete_global_key_provider(NULL);

-- Setting principal key fails if provider name is NULL
SELECT pg_tde_set_default_key_using_global_key_provider('key', NULL);
SELECT pg_tde_set_key_using_database_key_provider('key', NULL);
SELECT pg_tde_set_key_using_global_key_provider('key', NULL);
SELECT pg_tde_set_server_key_using_global_key_provider('key', NULL);

-- Setting principal key fails if key name is NULL
SELECT pg_tde_set_default_key_using_global_key_provider(NULL, 'file-keyring');
SELECT pg_tde_set_key_using_database_key_provider(NULL, 'file-keyring');
Expand Down
31 changes: 8 additions & 23 deletions contrib/pg_tde/src/catalog/tde_principal_key.c
Original file line number Diff line number Diff line change
Expand Up @@ -228,10 +228,10 @@ void
set_principal_key_with_keyring(const char *key_name, const char *provider_name,
Oid providerOid, Oid dbOid, bool ensure_new_key)
{
TDEPrincipalKey *curr_principal_key = NULL;
TDEPrincipalKey *new_principal_key = NULL;
TDEPrincipalKey *curr_principal_key;
TDEPrincipalKey *new_principal_key;
LWLock *lock_files = tde_lwlock_enc_keys();
bool already_has_key = false;
bool already_has_key;
GenericKeyring *new_keyring;
const KeyInfo *keyInfo = NULL;

Expand All @@ -249,21 +249,7 @@ set_principal_key_with_keyring(const char *key_name, const char *provider_name,
curr_principal_key = GetPrincipalKeyNoDefault(dbOid, LW_EXCLUSIVE);
already_has_key = (curr_principal_key != NULL);

if (provider_name == NULL && !already_has_key)
{
ereport(ERROR,
errmsg("provider_name is a required parameter when creating the first principal key for a database"));
}

if (provider_name != NULL)
{
new_keyring = GetKeyProviderByName(provider_name, providerOid);
}
else
{
new_keyring = GetKeyProviderByID(curr_principal_key->keyInfo.keyringId,
curr_principal_key->keyInfo.databaseId);
}
new_keyring = GetKeyProviderByName(provider_name, providerOid);

{
KeyringReturnCodes kr_ret;
Expand Down Expand Up @@ -292,11 +278,6 @@ set_principal_key_with_keyring(const char *key_name, const char *provider_name,
if (keyInfo == NULL)
keyInfo = KeyringGenerateNewKeyAndStore(new_keyring, key_name, PRINCIPAL_KEY_LEN);

if (keyInfo == NULL)
{
ereport(ERROR, errmsg("failed to retrieve/create principal key."));
}

new_principal_key = palloc_object(TDEPrincipalKey);
new_principal_key->keyInfo.databaseId = dbOid;
new_principal_key->keyInfo.keyringId = new_keyring->keyring_id;
Expand Down Expand Up @@ -549,6 +530,10 @@ pg_tde_set_principal_key_internal(Oid providerOid, Oid dbOid, const char *key_na
ereport(ERROR,
errcode(ERRCODE_INVALID_PARAMETER_VALUE),
errmsg("key name \"\" is too short"));
if (provider_name == NULL)
ereport(ERROR,
errcode(ERRCODE_NULL_VALUE_NOT_ALLOWED),
errmsg("key provider name cannot be null"));

ereport(LOG, errmsg("Setting principal key [%s : %s] for the database", key_name, provider_name));

Expand Down
3 changes: 2 additions & 1 deletion contrib/pg_tde/t/002_rotate_key.pl
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,8 @@

# Rotate key
PGTDE::psql($node, 'postgres',
"SELECT pg_tde_set_key_using_database_key_provider('rotated-key1');");
"SELECT pg_tde_set_key_using_database_key_provider('rotated-key1', 'file-vault');"
);
PGTDE::psql($node, 'postgres', 'SELECT * FROM test_enc ORDER BY id;');

PGTDE::append_to_result_file("-- server restart");
Expand Down
2 changes: 1 addition & 1 deletion contrib/pg_tde/t/expected/002_rotate_key.out
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ SELECT * FROM test_enc ORDER BY id;
2 | 6
(2 rows)

SELECT pg_tde_set_key_using_database_key_provider('rotated-key1');
SELECT pg_tde_set_key_using_database_key_provider('rotated-key1', 'file-vault');
pg_tde_set_key_using_database_key_provider
--------------------------------------------

Expand Down