Skip to content

fix: SQL quality rules on mysql/iceberg read as DuckDB SQL - #1663

Merged
jschoedl merged 1 commit into
mainfrom
mysql-rules-duckdb-dialect
Sep 25, 2026
Merged

jschoedl merged 1 commit into
mainfrom
mysql-rules-duckdb-dialect

Conversation

@jschoedl

Copy link
Copy Markdown
Collaborator

SQL quality rules on mysql and iceberg servers are now parsed by the read-only SQL guard as DuckDB SQL, which is what actually runs them. That closes a parser-differential smuggling hole. On the mysql path, the attached MySQL catalog is DETACHed once tables are copied, and untrusted contracts get restrict_to_paths(con, []). Double-quotes in table names are escaped to prevent SQL injection through physicalName.

Fixes:

  • Parser differential where a MySQL backslash escape hides a second statement from the guard
  • A posted contract reaching MySQL with environment credentials via malicious physicalName
  • A posted contract reading the MySQL connection string (password included) via duckdb_databases()

@jschoedl
jschoedl force-pushed the mysql-rules-duckdb-dialect branch from ab31a5b to cd0dbb8 Compare September 25, 2026 12:20
@jschoedl
jschoedl merged commit 1b31b67 into main Sep 25, 2026
19 checks passed
@jschoedl
jschoedl deleted the mysql-rules-duckdb-dialect branch September 25, 2026 12:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant