agora inbox for pgsql-docs@postgresql.org  
help / color / mirror / Atom feed
Add sentence about SECURITY LABEL object ownership
5+ messages / 3 participants
[nested] [flat]

* Add sentence about SECURITY LABEL object ownership
@ 2025-06-05 13:29  Patrick Stählin <me@packi.ch>
  0 siblings, 1 reply; 5+ messages in thread

From: Patrick Stählin @ 2025-06-05 13:29 UTC (permalink / raw)
  To: pgsql-docs@lists.postgresql.org

Hi,

I noticed that we don't document that you need to own the object being 
modified by SECURITY LABEL.

Page: https://www.postgresql.org/docs/current/sql-security-label.html

I've attached a patch that would have answered that question (for me) 
without diving into the code.

Thanks,
Patrick

Attachments:

  [text/x-patch] 0001-Document-ownership-requirement-for-SECURITY-LABEL-v1.patch (984B, ../../931e012a-57ba-41ba-9b88-24323a46dec5@packi.ch/2-0001-Document-ownership-requirement-for-SECURITY-LABEL-v1.patch)
  download | inline diff:
From 318a37a35f1b9f1915ae03df869fb51b04f1353e Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Patrick=20St=C3=A4hlin?= <me@packi.ch>
Date: Thu, 5 Jun 2025 15:10:01 +0200
Subject: [PATCH] Document ownership requirement for SECURITY LABEL

Clarify that you need ownership of objects you issue SECURITY LABEL on.
---
 doc/src/sgml/ref/security_label.sgml | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/doc/src/sgml/ref/security_label.sgml b/doc/src/sgml/ref/security_label.sgml
index e5e5fb483e9..ddcf92c967e 100644
--- a/doc/src/sgml/ref/security_label.sgml
+++ b/doc/src/sgml/ref/security_label.sgml
@@ -84,6 +84,10 @@ SECURITY LABEL [ FOR <replaceable class="parameter">provider</replaceable> ] ON
    based on object labels, rather than traditional discretionary access control
    (DAC) concepts such as users and groups.
   </para>
+
+  <para>
+   You must own the database object to use the <command>SECURITY LABEL</command>.
+  </para>
  </refsect1>
 
  <refsect1>
-- 
2.48.1



^ permalink  raw  reply  [nested|flat] 5+ messages in thread

* Re: Add sentence about SECURITY LABEL object ownership
@ 2025-06-05 14:21  Laurenz Albe <laurenz.albe@cybertec.at>
  parent: Patrick Stählin <me@packi.ch>
  0 siblings, 2 replies; 5+ messages in thread

From: Laurenz Albe @ 2025-06-05 14:21 UTC (permalink / raw)
  To: Patrick Stählin <me@packi.ch>; pgsql-docs@lists.postgresql.org

On Thu, 2025-06-05 at 15:29 +0200, Patrick Stählin wrote:
> Hi,
> 
> I noticed that we don't document that you need to own the object being 
> modified by SECURITY LABEL.
> 
> Page: https://www.postgresql.org/docs/current/sql-security-label.html
> 
> I've attached a patch that would have answered that question (for me) 
> without diving into the code.

> --- a/doc/src/sgml/ref/security_label.sgml
> +++ b/doc/src/sgml/ref/security_label.sgml
> @@ -84,6 +84,10 @@ SECURITY LABEL [ FOR <replaceable class="parameter">provider</replaceable> ] ON
>     based on object labels, rather than traditional discretionary access control
>     (DAC) concepts such as users and groups.
>    </para>
> +
> +  <para>
> +   You must own the database object to use the <command>SECURITY LABEL</command>.
> +  </para>
>   </refsect1>
>  
>   <refsect1>

Wouldn't it be more accurate to say that you have to be a member of the owning role?
But perhaps that would be complicated enough to confuse many users.

In general, +1 for documenting that.

Yours,
Laurenz Albe





^ permalink  raw  reply  [nested|flat] 5+ messages in thread

* Re: Add sentence about SECURITY LABEL object ownership
@ 2025-06-05 15:02  Patrick Stählin <me@packi.ch>
  parent: Laurenz Albe <laurenz.albe@cybertec.at>
  1 sibling, 0 replies; 5+ messages in thread

From: Patrick Stählin @ 2025-06-05 15:02 UTC (permalink / raw)
  To: Laurenz Albe <laurenz.albe@cybertec.at>; +Cc: pgsql-docs@lists.postgresql.org

On 6/5/25 4:21 PM, Laurenz Albe wrote:
>> +
>> +  <para>
>> +   You must own the database object to use the <command>SECURITY LABEL</command>.
>> +  </para>
>>    </refsect1>
>>   
>>    <refsect1>
> 
> Wouldn't it be more accurate to say that you have to be a member of the owning role?
> But perhaps that would be complicated enough to confuse many users.

We're calling check_object_ownership which errors out with:

    aclcheck_error(ACLCHECK_NOT_OWNER, [...])

which in turn then aborts with "must be owner of [...]". But checking 
the code, we do call has_privs_of_role, so you're absolutely right.

In doc/src/sgml/ref/alter_*.sgml we use the phrase "You must own the 
[...]" to describe the privileges needed. Let me know if you want me to 
change the wording.

While double checking I noticed that other docs don't have the extra 
"the " before "<command>[...] " so I dropped that in my v2 patch.

Thanks for reviewing!
Patrick

Attachments:

  [text/x-patch] 0001-Document-ownership-requirement-for-SECURITY-LABEL-v2.patch (980B, ../../69cd888d-2223-4880-9f57-dfe31bf2481a@packi.ch/2-0001-Document-ownership-requirement-for-SECURITY-LABEL-v2.patch)
  download | inline diff:
From c90f9604ee7894c806d92e7fdbc87c304f8628eb Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Patrick=20St=C3=A4hlin?= <me@packi.ch>
Date: Thu, 5 Jun 2025 15:10:01 +0200
Subject: [PATCH] Document ownership requirement for SECURITY LABEL

Clarify that you need ownership of objects you issue SECURITY LABEL on.
---
 doc/src/sgml/ref/security_label.sgml | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/doc/src/sgml/ref/security_label.sgml b/doc/src/sgml/ref/security_label.sgml
index e5e5fb483e9..aa45c0af248 100644
--- a/doc/src/sgml/ref/security_label.sgml
+++ b/doc/src/sgml/ref/security_label.sgml
@@ -84,6 +84,10 @@ SECURITY LABEL [ FOR <replaceable class="parameter">provider</replaceable> ] ON
    based on object labels, rather than traditional discretionary access control
    (DAC) concepts such as users and groups.
   </para>
+
+  <para>
+   You must own the database object to use <command>SECURITY LABEL</command>.
+  </para>
  </refsect1>
 
  <refsect1>
-- 
2.48.1



^ permalink  raw  reply  [nested|flat] 5+ messages in thread

* Re: Add sentence about SECURITY LABEL object ownership
@ 2025-06-05 15:19  Tom Lane <tgl@sss.pgh.pa.us>
  parent: Laurenz Albe <laurenz.albe@cybertec.at>
  1 sibling, 1 reply; 5+ messages in thread

From: Tom Lane @ 2025-06-05 15:19 UTC (permalink / raw)
  To: Laurenz Albe <laurenz.albe@cybertec.at>; +Cc: Patrick Stählin <me@packi.ch>; pgsql-docs@lists.postgresql.org

Laurenz Albe <laurenz.albe@cybertec.at> writes:
> On Thu, 2025-06-05 at 15:29 +0200, Patrick Stählin wrote:
>> I noticed that we don't document that you need to own the object being 
>> modified by SECURITY LABEL.

Yeah, clearly a documentation oversight.

> Wouldn't it be more accurate to say that you have to be a member of the owning role?
> But perhaps that would be complicated enough to confuse many users.
> In general, +1 for documenting that.

Our standard boilerplate for this is, eg,

   You must own the table to use <command>ALTER TABLE</command>.

I don't see a reason to do it differently here.

			regards, tom lane





^ permalink  raw  reply  [nested|flat] 5+ messages in thread

* Re: Add sentence about SECURITY LABEL object ownership
@ 2025-06-06 01:18  Laurenz Albe <laurenz.albe@cybertec.at>
  parent: Tom Lane <tgl@sss.pgh.pa.us>
  0 siblings, 0 replies; 5+ messages in thread

From: Laurenz Albe @ 2025-06-06 01:18 UTC (permalink / raw)
  To: Tom Lane <tgl@sss.pgh.pa.us>; +Cc: Patrick Stählin <me@packi.ch>; pgsql-docs@lists.postgresql.org

On Thu, 2025-06-05 at 11:19 -0400, Tom Lane wrote:
> Laurenz Albe <laurenz.albe@cybertec.at> writes:
> > On Thu, 2025-06-05 at 15:29 +0200, Patrick Stählin wrote:
> > > I noticed that we don't document that you need to own the object being 
> > > modified by SECURITY LABEL.
> 
> Yeah, clearly a documentation oversight.
> 
> > Wouldn't it be more accurate to say that you have to be a member of the owning role?
> > But perhaps that would be complicated enough to confuse many users.
> > In general, +1 for documenting that.
> 
> Our standard boilerplate for this is, eg,
> 
>    You must own the table to use <command>ALTER TABLE</command>.
> 
> I don't see a reason to do it differently here.

Objection withdrawn.

Yours,
Laurenz Albe





^ permalink  raw  reply  [nested|flat] 5+ messages in thread


end of thread, other threads:[~2025-06-06 01:18 UTC | newest]

Thread overview: 5+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2025-06-05 13:29 Add sentence about SECURITY LABEL object ownership Patrick Stählin <me@packi.ch>
2025-06-05 14:21 ` Laurenz Albe <laurenz.albe@cybertec.at>
2025-06-05 15:02   ` Patrick Stählin <me@packi.ch>
2025-06-05 15:19   ` Tom Lane <tgl@sss.pgh.pa.us>
2025-06-06 01:18     ` Laurenz Albe <laurenz.albe@cybertec.at>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox