Skip to content

SHOW TENANT <name> not supported (only by usage-in-database form); no path for basic per-tenant introspection #126

Description

@emanzx

Tested against: origin/main @ a178aa5b6b0b260d105962c928f07304360b7b30 (fetched 2026-05-20)

Severity: Low (workaround exists)

SHOW TENANT <name> is not supported; only the SHOW TENANT USAGE FOR <name> IN DATABASE <db> variant works (per docs). Basic per-tenant introspection by name is missing.

Reproduction

SHOW TENANT mae8;
-- → ERROR: unsupported: statement type: SHOW TENANT mae8

SHOW TENANTS WITH NAME mae8;
-- → ERROR: unsupported: statement type: SHOW TENANTS WITH NAME mae8

For an admin who wants "tell me about tenant 'mae8' — what's its ID, quotas, db, status?", the only path is:

SHOW TENANTS;
-- iterate the list, find the row by name

…which works but is awkward for scripts and admin tooling.

Suggested fix

Add SHOW TENANT <name|id> for basic per-tenant introspection. Returns: tenant_id, name, database, quotas, active_requests, total_requests, rejected_requests, etc. Useful both interactively and from admin scripts that need tenant-by-name lookup.

Workaround

SHOW TENANTS + grep / awk for the desired name. Workable but every admin tool reinvents this filter.

Context

Caught during mae8 v2 Phase 0 bootstrap (2026-05-20). Full bug catalog: /home/system/rnd/mae8/docs/origin_bugs_2026-05-20.md (this is Bug 6 from that file).

Activity

  1. farhan-syah commented on May 23, 2026

    @farhan-syah
    Member

    Fixed in 56a29f1.

    Added two new typed forms:

    • SHOW TENANT <name|id> — single-row introspection. Resolves numeric ids first, then falls back to case-insensitive name match. Returns 42704 (undefined_object) when no tenant matches.
    • SHOW TENANTS WITH NAME <name> — filter form on the existing SHOW TENANTS row shape.

    Both run through the AST-typed dispatcher (pgwire/ddl/router/ast/database_ops.rs) rather than string-prefix routing. The legacy starts_with("SHOW TENANTS") branches in the pgwire admin router and the user_auth AST parser were tightened to exact match — left as prefix matches, SHOW TENANTS WITH NAME <name> would silently fall through and list every tenant, which is a data-disclosure hazard. The native protocol's is_session_show was likewise updated so SHOW TENANT <ident> reaches DDL instead of the per-session SHOW <param> handler.

    Coverage in nodedb/tests/pgwire_auth_tenants.rs:

    • show_tenant_by_name / show_tenant_by_id — happy paths
    • show_tenants_with_name_filter_unknown_name_does_not_silently_listall — regression guard against the silent prefix-fallthrough
    • show_tenant_by_name_requires_superuser — privilege gate parity with SHOW TENANTS
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:sqlParser, planner, SQL semanticstype:featureNew capability or behavior change

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions