The documentation says that SUPER should be required for ALTER FUNCTION when log_bin_trust_function_creators=OFF and log_bin=ON:
https://mariadb.com/kb/en/library/alter-function/
https://mariadb.com/kb/en/library/binary-logging-of-stored-routines/
https://mariadb.com/kb/en/library/replication-and-binary-log-system-variables/#log_bin_trust_function_creators
But a quick test shows that this is not the case.
For example, if I create a function as a user with SUPER:
CREATE FUNCTION trust_me(x INT)
|
RETURNS INT
|
DETERMINISTIC
|
READS SQL DATA
|
RETURN (x);
|
And then create a user with the ALTER ROUTINE privilege, but without SUPER:
CREATE USER 'function_test'@localhost IDENTIFIED BY 'password';
|
GRANT ALTER ROUTINE ON db1.* TO 'function_test'@localhost;
|
And then ensure that both log_bin_trust_function_creators=OFF and log_bin=ON:
MariaDB [db1]> SHOW GLOBAL VARIABLES WHERE Variable_name IN('log_bin_trust_function_creators', 'log_bin');
|
+---------------------------------+-------+
|
| Variable_name | Value |
|
+---------------------------------+-------+
|
| log_bin | ON |
|
| log_bin_trust_function_creators | OFF |
|
+---------------------------------+-------+
|
2 rows in set (0.01 sec)
|
You would think that this user would not be able to alter the function. But a test shows that the user can:
MariaDB [db1]> ALTER FUNCTION trust_me NO SQL;
|
Query OK, 0 rows affected (0.00 sec)
|
|
MariaDB [db1]> SHOW GRANTS;
|
+----------------------------------------------------------------------------------------------------------------------+
|
| Grants for function_test@localhost |
|
+----------------------------------------------------------------------------------------------------------------------+
|
| GRANT USAGE ON *.* TO 'function_test'@'localhost' IDENTIFIED BY PASSWORD '*2470C0C06DEE42FD1618BB99005ADCA2EC9D1E19' |
|
| GRANT ALTER ROUTINE ON `db1`.* TO 'function_test'@'localhost' |
|
+----------------------------------------------------------------------------------------------------------------------+
|
2 rows in set (0.00 sec)
|
Code analysis shows that the Sp_handler::sp_update_routine does not check SUPER_ACL like Sp_handler::sp_create_routine does.
sp_create_routine check:
https://github.com/MariaDB/server/blob/8cf7e3459d7309ce122824146260c4aecfa6ca77/sql/sp.cc#L1397
sp_update_routine check:
https://github.com/MariaDB/server/blob/8cf7e3459d7309ce122824146260c4aecfa6ca77/sql/sp.cc#L1632
There are no comments yet on this issue.
{"report":{"fcp":729.7999999523163,"ttfb":141.70000004768372,"pageVisibility":"visible","entityId":74091,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":1,"journeyId":"5eb2af2b-394e-484b-a2c8-785af2e3bee4","navigationType":0,"readyForUser":787.7000000476837,"redirectCount":0,"resourceLoadedEnd":859.7999999523163,"resourceLoadedStart":146.89999985694885,"resourceTiming":[{"duration":156.70000004768372,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":146.89999985694885,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":146.89999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":303.59999990463257,"responseStart":0,"secureConnectionStart":0},{"duration":156.39999985694885,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":147.20000004768372,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":147.20000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":303.59999990463257,"responseStart":0,"secureConnectionStart":0},{"duration":165.59999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/fbf975c0cce4b1abf04784eeae9ba1f4-CDN/lu2bu7/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":147.29999995231628,"connectEnd":147.29999995231628,"connectStart":147.29999995231628,"domainLookupEnd":147.29999995231628,"domainLookupStart":147.29999995231628,"fetchStart":147.29999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":147.29999995231628,"responseEnd":312.89999985694885,"responseStart":312.89999985694885,"secureConnectionStart":147.29999995231628},{"duration":237.10000014305115,"initiatorType":"script","name":"https://jira.mariadb.org/s/099b33461394b8015fc36c0a4b96e19f-CDN/lu2bu7/820016/12ta74/8679b4946efa1a0bb029a3a22206fb5d/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":147.39999985694885,"connectEnd":147.39999985694885,"connectStart":147.39999985694885,"domainLookupEnd":147.39999985694885,"domainLookupStart":147.39999985694885,"fetchStart":147.39999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":147.39999985694885,"responseEnd":384.5,"responseStart":384.5,"secureConnectionStart":147.39999985694885},{"duration":240.79999995231628,"initiatorType":"script","name":"https://jira.mariadb.org/s/94c15bff32baef80f4096a08aceae8bc-CDN/lu2bu7/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":147.5,"connectEnd":147.5,"connectStart":147.5,"domainLookupEnd":147.5,"domainLookupStart":147.5,"fetchStart":147.5,"redirectEnd":0,"redirectStart":0,"requestStart":147.5,"responseEnd":388.2999999523163,"responseStart":388.2999999523163,"secureConnectionStart":147.5},{"duration":241.10000014305115,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":147.59999990463257,"connectEnd":147.59999990463257,"connectStart":147.59999990463257,"domainLookupEnd":147.59999990463257,"domainLookupStart":147.59999990463257,"fetchStart":147.59999990463257,"redirectEnd":0,"redirectStart":0,"requestStart":147.59999990463257,"responseEnd":388.7000000476837,"responseStart":388.7000000476837,"secureConnectionStart":147.59999990463257},{"duration":241.39999985694885,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":147.70000004768372,"connectEnd":147.70000004768372,"connectStart":147.70000004768372,"domainLookupEnd":147.70000004768372,"domainLookupStart":147.70000004768372,"fetchStart":147.70000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":147.70000004768372,"responseEnd":389.09999990463257,"responseStart":389.09999990463257,"secureConnectionStart":147.70000004768372},{"duration":241.90000009536743,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2bu7/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":147.79999995231628,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":147.79999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":389.7000000476837,"responseStart":0,"secureConnectionStart":0},{"duration":241.60000014305115,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":147.89999985694885,"connectEnd":147.89999985694885,"connectStart":147.89999985694885,"domainLookupEnd":147.89999985694885,"domainLookupStart":147.89999985694885,"fetchStart":147.89999985694885,"redirectEnd":0,"redirectStart":0,"requestStart":147.89999985694885,"responseEnd":389.5,"responseStart":389.5,"secureConnectionStart":147.89999985694885},{"duration":242,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":148,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":148,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":390,"responseStart":0,"secureConnectionStart":0},{"duration":241.79999995231628,"initiatorType":"script","name":"https://jira.mariadb.org/s/3339d87fa2538a859872f2df449bf8d0-CDN/lu2bu7/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":148.20000004768372,"connectEnd":148.20000004768372,"connectStart":148.20000004768372,"domainLookupEnd":148.20000004768372,"domainLookupStart":148.20000004768372,"fetchStart":148.20000004768372,"redirectEnd":0,"redirectStart":0,"requestStart":148.20000004768372,"responseEnd":390,"responseStart":390,"secureConnectionStart":148.20000004768372},{"duration":647.7000000476837,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":148.79999995231628,"connectEnd":148.79999995231628,"connectStart":148.79999995231628,"domainLookupEnd":148.79999995231628,"domainLookupStart":148.79999995231628,"fetchStart":148.79999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":148.79999995231628,"responseEnd":796.5,"responseStart":796.5,"secureConnectionStart":148.79999995231628},{"duration":647.9000000953674,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":148.79999995231628,"connectEnd":148.79999995231628,"connectStart":148.79999995231628,"domainLookupEnd":148.79999995231628,"domainLookupStart":148.79999995231628,"fetchStart":148.79999995231628,"redirectEnd":0,"redirectStart":0,"requestStart":148.79999995231628,"responseEnd":796.7000000476837,"responseStart":796.7000000476837,"secureConnectionStart":148.79999995231628},{"duration":263.5,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":532.5,"connectEnd":532.5,"connectStart":532.5,"domainLookupEnd":532.5,"domainLookupStart":532.5,"fetchStart":532.5,"redirectEnd":0,"redirectStart":0,"requestStart":532.5,"responseEnd":796,"responseStart":796,"secureConnectionStart":532.5},{"duration":98.09999990463257,"initiatorType":"script","name":"https://www.google-analytics.com/analytics.js","startTime":708.7000000476837,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":708.7000000476837,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":806.7999999523163,"responseStart":0,"secureConnectionStart":0},{"duration":21.09999990463257,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2bu7/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":824.2999999523163,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":824.2999999523163,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":845.3999998569489,"responseStart":0,"secureConnectionStart":0},{"duration":20.5,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2bu7/820016/12ta74/e65b778d185daf5aee24936755b43da6/_/download/contextbatch/js/browser-metrics-plugin.contrib,-_super,-project.issue.navigator,-jira.view.issue,-atl.general/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true","startTime":825.2999999523163,"connectEnd":825.2999999523163,"connectStart":825.2999999523163,"domainLookupEnd":825.2999999523163,"domainLookupStart":825.2999999523163,"fetchStart":825.2999999523163,"redirectEnd":0,"redirectStart":0,"requestStart":825.2999999523163,"responseEnd":845.7999999523163,"responseStart":845.7999999523163,"secureConnectionStart":825.2999999523163},{"duration":34.09999990463257,"initiatorType":"script","name":"https://jira.mariadb.org/s/f51ef5507eea4c158f257c66c93b2a3f-CDN/lu2bu7/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/js/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true","startTime":825.7000000476837,"connectEnd":825.7000000476837,"connectStart":825.7000000476837,"domainLookupEnd":825.7000000476837,"domainLookupStart":825.7000000476837,"fetchStart":825.7000000476837,"redirectEnd":0,"redirectStart":0,"requestStart":825.7000000476837,"responseEnd":859.7999999523163,"responseStart":859.7999999523163,"secureConnectionStart":825.7000000476837}],"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":21,"responseStart":142,"responseEnd":144,"domLoading":145,"domInteractive":913,"domContentLoadedEventStart":913,"domContentLoadedEventEnd":960,"domComplete":1032,"loadEventStart":1032,"loadEventEnd":1032,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":882.2000000476837},{"name":"bigPipe.sidebar-id.end","time":883},{"name":"bigPipe.activity-panel-pipe-id.start","time":883.2000000476837},{"name":"bigPipe.activity-panel-pipe-id.end","time":883.7000000476837},{"name":"activityTabFullyLoaded","time":968.3999998569489}],"measures":[],"correlationId":"6c2d5623c5839e","effectiveType":"4g","downlink":9.4,"rtt":0,"serverDuration":66,"dbReadsTimeInMs":11,"dbConnsTimeInMs":19,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}