AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

SIGSEGV When Anon Role Calls SECURITY DEFINER Function Without EXECUTE Via PostgREST LATERAL CTE On Local Supabase Stack

Local Supabase backend crashes with signal 11 when the anon role calls a SECURITY DEFINER function via PostgREST RPC after EXECUTE has been revoked from anon. The crash occurs inside PostgreSQL during permission error handling inside a LATERAL join, and is triggered by the supautils extension's hint_roles feature configured to include 'anon'.

highConfidence 75%SupabaseAffected VSupabase CLI 2.98.2Affected VPostgreSQL 17.6Affected VPostgREST 14.5Affected Vsupautils (local Preload, Hint_roles Includes Anon)

Origin Analysis

The local Supabase stack preloads supautils on the authenticator role with session_preload_libraries=supautils,safeupdate and sets supautils.hint_roles='anon, authenticated, service_role'. When PostgREST wraps the RPC in a LATERAL CTE and the anon role lacks EXECUTE on the SECURITY DEFINER function, PostgreSQL raises a permission denied error inside the LATERAL evaluation. supautils attempts to generate a permission hint for the anon role during error handling, and a critical memory bug in the supautils C code on PostgreSQL 17.6 causes the backend process to segfault instead of returning SQLSTATE 42501 cleanly.
1. Create a SECURITY DEFINER function in public and revoke EXECUTE from anon while granting to authenticated and service_role. 2. Start a local Supabase stack with supautils preloaded and hint_roles including anon. 3. As anon, call the function via PostgREST RPC endpoint with a valid anon API key and Authorization header. 4. Observe PostgreSQL logs: server process terminated by signal 11: Segmentation fault; failed process running the LATERAL CTE wrapper.

Fixing Code Block

Edge Case Audit

This is a temporary mitigation, not a permanent fix. The underlying memory bug in supautils must be addressed in the extension for PostgreSQL 17. Excluding anon from hint_roles means anon will no longer receive permission hints for denied operations. The change is global and persists in postgresql.auto.conf. To roll back, execute: ALTER SYSTEM RESET supautils.hint_roles; SELECT pg_reload_conf(); Test thoroughly after any supautils upgrade. Production Supabase is not affected because it uses a different supautils build that handles the error cleanly.

Ecosystem Topology