Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sNZSw-009KZp-LG for pgsql-admin@arkaria.postgresql.org; Sat, 29 Jun 2024 14:54:14 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1sNZSt-009Udw-1E for pgsql-admin@arkaria.postgresql.org; Sat, 29 Jun 2024 14:54:11 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sNZSs-009Udn-Ly for pgsql-admin@lists.postgresql.org; Sat, 29 Jun 2024 14:54:10 +0000 Received: from sss.pgh.pa.us ([68.162.161.243]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sNZSq-004A3Q-6w for pgsql-admin@lists.postgresql.org; Sat, 29 Jun 2024 14:54:10 +0000 Received: from sss1.sss.pgh.pa.us (localhost [127.0.0.1]) by sss.pgh.pa.us (8.15.2/8.15.2) with ESMTP id 45TEs51m2207735; Sat, 29 Jun 2024 10:54:05 -0400 From: Tom Lane To: Ron Johnson cc: Pgsql-admin Subject: Re: Strange "permission denied" errors on pg_restore In-reply-to: References: <792db007dcc03570743afee23aa0da830207f0cf.camel@cybertec.at> <42d837098e471906e23ed5ef345a1172145c76da.camel@cybertec.at> Comments: In-reply-to Ron Johnson message dated "Sat, 29 Jun 2024 01:18:55 -0400" MIME-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Content-ID: <2207733.1719672845.1@sss.pgh.pa.us> Content-Transfer-Encoding: quoted-printable Date: Sat, 29 Jun 2024 10:54:05 -0400 Message-ID: <2207734.1719672845@sss.pgh.pa.us> List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk Ron Johnson writes: > On Sat, Jun 29, 2024 at 1:13=E2=80=AFAM Laurenz Albe > wrote: >> You should perform the restore as a superuser or as a user that has all >> the required permissions. Restoring with a non-superuser can be tricky= . > I do everything database-related as user "postgres". Only "sudo yum" is > run from my personal account. The failing query seems to be a foreign-key enforcement check that happened to be triggered from COPY. Those are run as the owner of the table that is being checked. So it appears that in pg_restore: error: COPY failed for table "batch_rp4_y2022m08": ERROR: perm= ission denied for schema tapschema LINE 1: SELECT 1 FROM ONLY "tapschema"."lockbox" x WHERE "lockbox_id... ^ QUERY: SELECT 1 FROM ONLY "tapschema"."lockbox" x WHERE "lockbox_id" OPER= ATOR(pg_catalog.=3D) $1 FOR KEY SHARE OF x the owner of table "lockbox" lacks usage permission on the containing schema "tapschema". That's a most bizarre situation and would have caused the same sort of FK failures in the originating database as well. pg_dump can't really promise to restore databases containing arbitrarily-broken permissions settings. regards, tom lane