-
Notifications
You must be signed in to change notification settings - Fork 5.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
planner: only users with SUPER or CONNECTION_ADMIN privilege can kill auto analyze #33057
Conversation
[REVIEW NOTIFICATION] This pull request has been approved by:
To complete the pull request process, please ask the reviewers in the list to review by filling The full list of commands accepted by this bot can be found here. Reviewer can indicate their review by submitting an approval review. |
Code Coverage Details: https://codecov.io/github/pingcap/tidb/commit/afda468cda9f8d44a21263c52d890a6fabfdb142 |
planner/core/planbuilder.go
Outdated
} else if raw.ConnectionID == util2.GetAutoAnalyzeProcID() { | ||
// Only the users with the SUPER privilege can kill auto analyze. | ||
err := ErrSpecificAccessDenied.GenWithStackByArgs("SUPER") | ||
b.visitInfo = appendVisitInfo(b.visitInfo, mysql.SuperPriv, "", "", "", err) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Historically PROCESS
privilege is required to kill connections that belong to other users. MySQL 8.0 changes this to requiring CONNECTION_ADMIN
: https://dev.mysql.com/doc/refman/8.0/en/privileges-provided.html#priv_connection-admin
This helps avoid the problem that super is overloaded (it is used by too many features, which makes it less secure).
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fixed.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
/merge |
This pull request has been accepted and is ready to merge. Commit hash: a80965e
|
/merge |
@xuyifangreeneyes: Your PR was out of date, I have automatically updated it for you. At the same time I will also trigger all tests for you: /run-all-tests If the CI test fails, you just re-trigger the test that failed and the bot will merge the PR for you after the CI passes. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the ti-community-infra/tichi repository. |
What problem does this PR solve?
Issue Number: close #33058
Problem Summary:
Users without privilege can kill auto analyze.
What is changed and how it works?
Only users with SUPER or CONNECTION_ADMIN privilege can kill auto analyze
Check List
Tests
Side effects
Documentation
Release note