PostgreSQL码农集散地

PostgreSQL 18 preview - 连接协议兼容、安全改进, 支持min/max_protocol_version

PostgreSQL 18 preview - 连接协议兼容、安全改进, 支持min/max_protocol_version

这个补丁给 PostgreSQL 客户端库 libpq 添加了两个新的连接选项:min_protocol_version 和 max_protocol_version。 这些选项允许用户控制客户端和服务器之间协商的协议版本。

类似tls 最低版本要求, 解决安全问题.

最大版本则用来解决兼容性问题(兼容更老的客户端), 因为老的客户端可能不能支持未来的更高版本的能力.

https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=5070349102af12832c8528651c8ed18b16346323

libpq: Handle NegotiateProtocolVersion message differently
author Heikki Linnakangas <[email protected]> 
Wed, 2 Apr 2025 13:41:42 +0000 (16:41 +0300)
committer Heikki Linnakangas <[email protected]> 
Wed, 2 Apr 2025 13:41:42 +0000 (16:41 +0300)
commit 5070349102af12832c8528651c8ed18b16346323
tree d976387818fc63535a86ca33893819f52d18dd67 tree
parent 748e98d05b752e05c0f860f35f17bb0ba83631ed commit | diff
libpq: Handle NegotiateProtocolVersion message differently

Previously libpq would always error out if the server sends a
NegotiateProtocolVersion message. This was fine because libpq only
supported a single protocol version and did not support any protocol
parameters. But in the upcoming commits, we will introduce a new
protocol version and the NegotiateProtocolVersion message starts to
actually be used.

This patch modifies the client side checks to allow a range of
supported protocol versions, instead of only allowing the exact
version that was requested. Currently this "range" only contains the
3.0 version, but in a future commit we'll change this.

Also clarify the error messages, making them suitable for the world
where libpq will support multiple protocol versions and protocol
extensions.

Note that until the later commits that introduce new protocol version,
this change does not have any behavioural effect, because libpq will
only request version 3.0 and will never send protocol parameters, and
therefore will never receive a NegotiateProtocolVersion message from
the server.

Author: Jelte Fennema-Nio <[email protected]>
Reviewed-by: Robert Haas <[email protected]> (earlier versions)
Discussion: https://www.postgresql.org/message-id/CAGECzQTfc_O%[email protected]
Discussion: https://www.postgresql.org/message-id/CAGECzQRbAGqJnnJJxTdKewTsNOovUt4bsx3NFfofz3m2j-t7tA@mail.gmail.com

https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=285613c60a7aff5daaf281c67002483b0d26e715

libpq: Add min/max_protocol_version connection options  
author Heikki Linnakangas <[email protected]>   
Wed, 2 Apr 2025 13:41:45 +0000 (16:41 +0300)  
committer Heikki Linnakangas <[email protected]>   
Wed, 2 Apr 2025 13:41:45 +0000 (16:41 +0300)  
commit 285613c60a7aff5daaf281c67002483b0d26e715  
tree cee61e8b4cba4c93fba029532d65370428e004d9 tree  
parent 5070349102af12832c8528651c8ed18b16346323 commit | diff  
libpq: Add min/max_protocol_version connection options  

All supported version of the PostgreSQL server send the  
NegotiateProtocolVersion message when an unsupported minor protocol  
version is requested by a client. But many other applications that  
implement the PostgreSQL protocol (connection poolers, or other  
databases) do not, and the same is truefor PostgreSQL server versions  
older than 9.3. Connecting to such other applications thus fails if a  
client requests a protocol version different than 3.0.  

This patch adds a max_protocol_version connection option to libpq that  
specifies the protocol version that libpq should request from the  
server. Currently only 3.0 is supported, but that will change in a  
future commit that bumps the protocol version. Even after that version  
bump the default will likely stay 3.0 for the time being. Once more of  
the ecosystem supports the NegotiateProtocolVersion message we might  
want to change the default to the latest minor version.  

This also adds the similar min_protocol_version connection option, to  
allow the client to specify that connecting should fail if a lower  
protocol version is attempted by the server. This can be used to  
ensure that certain protocol features are used, which can be  
particularly useful if those features impact security.  

Author: Jelte Fennema-Nio <[email protected]>  
Reviewed-by: Robert Haas <[email protected]> (earlier versions)  
Discussion: https://www.postgresql.org/message-id/CAGECzQTfc_O%[email protected]  
Discussion: https://www.postgresql.org/message-id/CAGECzQRbAGqJnnJJxTdKewTsNOovUt4bsx3NFfofz3m2j-t7tA@mail.gmail.com  

AI 解读

这个补丁给 PostgreSQL 客户端库 libpq 添加了两个新的连接选项:min_protocol_version 和 max_protocol_version。 这些选项允许用户控制客户端和服务器之间协商的协议版本。 以下是问题和解决方案的分解:

问题:

  • 协议版本协商: PostgreSQL 服务器(9.3 及更高版本)使用 NegotiateProtocolVersion 消息来通知客户端,如果客户端请求了不受支持的次要协议版本。 这允许客户端优雅地回退到受支持的版本。
  • 非标准服务器/连接池: 许多实现 PostgreSQL 协议的应用程序(连接池、其他数据库或旧版本的 PostgreSQL)没有实现此 NegotiateProtocolVersion 消息。
  • 连接失败: 如果 libpq 客户端从这些非标准服务器之一请求高于 3.0(当前标准)的协议版本,则连接将失败,因为服务器不会响应协商消息。 客户端期望收到一个它永远不会收到的响应。

解决方案:

该补丁引入了两个新的连接选项来解决这个问题:

  • max_protocol_version: 此选项允许用户指定 libpq 应从服务器请求的最高协议版本。 默认情况下,它可能会暂时保持在 3.0,以确保与更广泛的服务器和连接池的兼容性。 这可以防止客户端请求服务器可能不支持的更高版本,从而避免连接失败。 该补丁预计未来会进行版本升级,届时此默认值可能会更改。
  • min_protocol_version: 此选项允许用户指定客户端将接受的最低协议版本。 如果服务器尝试协商低于此值的协议版本,则连接将失败。 这对于确保连接使用某些协议功能(尤其是与安全性相关的功能)非常有用。 例如,如果在更高版本的协议中引入了新的安全功能,则设置 min_protocol_version 将保证连接使用该功能。

为什么这很重要?

  • 兼容性:max_protocol_version 确保 libpq 可以连接到更广泛的服务器,包括那些没有完全实现 PostgreSQL 协议协商的服务器。
  • 安全性:min_protocol_version 允许用户强制使用特定的协议功能,特别是那些与安全性相关的功能。 这有助于防止旧版本协议中的漏洞。
  • 面向未来: 该补丁预计未来会进行协议版本升级,并提供了一种控制 libpq 使用的协议版本的方法。

总结:

此补丁增加了对 libpq 中协议版本协商过程的灵活性和控制。 它提高了与非标准服务器的兼容性,并允许用户强制使用特定的协议功能,尤其是那些与安全性相关的功能。 max_protocol_version 选项是针对未正确协商协议版本的服务器的解决方法,而 min_protocol_version 提供了一种确保连接满足某些安全要求的方法。