MDEV-31535: Add privilege-based fast path for SHOW DATABASES listing#5457
MDEV-31535: Add privilege-based fast path for SHOW DATABASES listing#5457itzanway wants to merge 1 commit into
Conversation
For users without global database-listing privileges, build the database list from in-memory ACL tables instead of scanning the data directory when grants are exact-name only. Mirror acl_get_all3()/check_grant_db() grantee handling (user, active role, PUBLIC), scope the optimization to SCHEMATA, preserve find_files() ordering, and add MTR coverage.
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
janlindstrom
left a comment
There was a problem hiding this comment.
Looks very promising but requires some cleanup and additional work so that
user can verify is fast path used or not.
There was a problem hiding this comment.
Please no white space changes.
There was a problem hiding this comment.
Can you please avoid lambda-functions and use inline functions instead.
There was a problem hiding this comment.
Similar conditions in two places, consider using inline function
| create user mdev31535_u1@localhost; | ||
| grant select on mdev31535a.* to mdev31535_u1@localhost; | ||
|
|
||
| connect (con1,localhost,mdev31535_u1,,); |
There was a problem hiding this comment.
Sure, but how we could verify that fast path was used and cases where not it was not used?
Maybe need again after select schema_name from information_schema.schemata; additional
explain format=json ...; so that it would show fast path in some field...
Check also if you do select schema_name from information_schema.schemata more than once does result come from query_cache or is same code executed again.
There was a problem hiding this comment.
Please use strncmp instead
Summary
For users without global database-listing privileges, avoid a full data-directory
scan when building the database list for
SHOW DATABASESandINFORMATION_SCHEMA.SCHEMATA.Instead of always calling
find_files()inmake_db_list(), restricted userscan now use a new helper
get_acl_databases_for_user()that builds the listfrom in-memory privilege tables (
acl_dbs,column_priv_hash).Problem
make_db_list()currently scans the entire data directory viafind_files(),even for users who only have privileges on a small, known set of databases.
This is unnecessary work or restricted users and does not scale well on
installations with many databases.
Solution
Add
get_acl_databases_for_user()insql/sql_acl.cc.mysql.dband table/column-level grants.priv_user, active role, andPUBLIC(mirrorsacl_get_all3())priv_userand active role (mirrorscheck_grant_db())sctx->host/sctx->ipfor host matching.Gate the fast path in
make_db_list()(sql/sql_show.cc) when:fill_schema_schemata()(SHOW DATABASES / SCHEMATA only)%or_wildcards)If any applicable grant contains a wildcard, decline the fast path and fall
back to the existing
find_files()scan.Preserve existing output ordering by applying the same sort used by
find_files()(Discovered_table_list::sort()/sort_desc()in debugbuilds).
On fast-path decline, restore the caller's database list to its entry size
so partial results are not duplicated by the fallback scan.