Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1uNCN1-00E41h-Kj for pgsql-docs@arkaria.postgresql.org; Thu, 05 Jun 2025 15:19:07 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1uNCMz-00AY10-Ns for pgsql-docs@arkaria.postgresql.org; Thu, 05 Jun 2025 15:19:06 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1uNCMz-00AY0V-GJ for pgsql-docs@lists.postgresql.org; Thu, 05 Jun 2025 15:19:06 +0000 Received: from sss.pgh.pa.us ([68.162.161.243]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1uNCMy-000PFu-1j for pgsql-docs@lists.postgresql.org; Thu, 05 Jun 2025 15:19:05 +0000 Received: from sss1.sss.pgh.pa.us (localhost [127.0.0.1]) by sss.pgh.pa.us (8.15.2/8.15.2) with ESMTP id 555FJ2qJ1284779; Thu, 5 Jun 2025 11:19:02 -0400 From: Tom Lane To: Laurenz Albe cc: Patrick =?ISO-8859-1?Q?St=E4hlin?= , pgsql-docs@lists.postgresql.org Subject: Re: Add sentence about SECURITY LABEL object ownership In-reply-to: <2c8f7b87b68fd2084faebdcf48b4edb23f4e93e0.camel@cybertec.at> References: <931e012a-57ba-41ba-9b88-24323a46dec5@packi.ch> <2c8f7b87b68fd2084faebdcf48b4edb23f4e93e0.camel@cybertec.at> Comments: In-reply-to Laurenz Albe message dated "Thu, 05 Jun 2025 09:21:47 -0500" MIME-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Content-ID: <1284777.1749136742.1@sss.pgh.pa.us> Content-Transfer-Encoding: quoted-printable Date: Thu, 05 Jun 2025 11:19:02 -0400 Message-ID: <1284778.1749136742@sss.pgh.pa.us> List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk Laurenz Albe writes: > On Thu, 2025-06-05 at 15:29 +0200, Patrick St=C3=A4hlin wrote: >> I noticed that we don't document that you need to own the object being = >> modified by SECURITY LABEL. Yeah, clearly a documentation oversight. > Wouldn't it be more accurate to say that you have to be a member of the = owning role? > But perhaps that would be complicated enough to confuse many users. > In general, +1 for documenting that. Our standard boilerplate for this is, eg, You must own the table to use ALTER TABLE. I don't see a reason to do it differently here. regards, tom lane