agora inbox for pgsql-docs@postgresql.org
help / color / mirror / Atom feedAdd sentence about SECURITY LABEL object ownership
5+ messages / 3 participants
[nested] [flat]
* Add sentence about SECURITY LABEL object ownership
@ 2025-06-05 13:29 Patrick Stählin <me@packi.ch>
0 siblings, 1 reply; 5+ messages in thread
From: Patrick Stählin @ 2025-06-05 13:29 UTC (permalink / raw)
To: pgsql-docs@lists.postgresql.org
Hi,
I noticed that we don't document that you need to own the object being
modified by SECURITY LABEL.
Page: https://www.postgresql.org/docs/current/sql-security-label.html
I've attached a patch that would have answered that question (for me)
without diving into the code.
Thanks,
Patrick
Attachments:
[text/x-patch] 0001-Document-ownership-requirement-for-SECURITY-LABEL-v1.patch (984B, ../../931e012a-57ba-41ba-9b88-24323a46dec5@packi.ch/2-0001-Document-ownership-requirement-for-SECURITY-LABEL-v1.patch)
download | inline diff:
From 318a37a35f1b9f1915ae03df869fb51b04f1353e Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Patrick=20St=C3=A4hlin?= <me@packi.ch>
Date: Thu, 5 Jun 2025 15:10:01 +0200
Subject: [PATCH] Document ownership requirement for SECURITY LABEL
Clarify that you need ownership of objects you issue SECURITY LABEL on.
---
doc/src/sgml/ref/security_label.sgml | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/doc/src/sgml/ref/security_label.sgml b/doc/src/sgml/ref/security_label.sgml
index e5e5fb483e9..ddcf92c967e 100644
--- a/doc/src/sgml/ref/security_label.sgml
+++ b/doc/src/sgml/ref/security_label.sgml
@@ -84,6 +84,10 @@ SECURITY LABEL [ FOR <replaceable class="parameter">provider</replaceable> ] ON
based on object labels, rather than traditional discretionary access control
(DAC) concepts such as users and groups.
</para>
+
+ <para>
+ You must own the database object to use the <command>SECURITY LABEL</command>.
+ </para>
</refsect1>
<refsect1>
--
2.48.1
^ permalink raw reply [nested|flat] 5+ messages in thread
* Re: Add sentence about SECURITY LABEL object ownership
@ 2025-06-05 14:21 Laurenz Albe <laurenz.albe@cybertec.at>
parent: Patrick Stählin <me@packi.ch>
0 siblings, 2 replies; 5+ messages in thread
From: Laurenz Albe @ 2025-06-05 14:21 UTC (permalink / raw)
To: Patrick Stählin <me@packi.ch>; pgsql-docs@lists.postgresql.org
On Thu, 2025-06-05 at 15:29 +0200, Patrick Stählin wrote:
> Hi,
>
> I noticed that we don't document that you need to own the object being
> modified by SECURITY LABEL.
>
> Page: https://www.postgresql.org/docs/current/sql-security-label.html
>
> I've attached a patch that would have answered that question (for me)
> without diving into the code.
> --- a/doc/src/sgml/ref/security_label.sgml
> +++ b/doc/src/sgml/ref/security_label.sgml
> @@ -84,6 +84,10 @@ SECURITY LABEL [ FOR <replaceable class="parameter">provider</replaceable> ] ON
> based on object labels, rather than traditional discretionary access control
> (DAC) concepts such as users and groups.
> </para>
> +
> + <para>
> + You must own the database object to use the <command>SECURITY LABEL</command>.
> + </para>
> </refsect1>
>
> <refsect1>
Wouldn't it be more accurate to say that you have to be a member of the owning role?
But perhaps that would be complicated enough to confuse many users.
In general, +1 for documenting that.
Yours,
Laurenz Albe
^ permalink raw reply [nested|flat] 5+ messages in thread
* Re: Add sentence about SECURITY LABEL object ownership
@ 2025-06-05 15:02 Patrick Stählin <me@packi.ch>
parent: Laurenz Albe <laurenz.albe@cybertec.at>
1 sibling, 0 replies; 5+ messages in thread
From: Patrick Stählin @ 2025-06-05 15:02 UTC (permalink / raw)
To: Laurenz Albe <laurenz.albe@cybertec.at>; +Cc: pgsql-docs@lists.postgresql.org
On 6/5/25 4:21 PM, Laurenz Albe wrote:
>> +
>> + <para>
>> + You must own the database object to use the <command>SECURITY LABEL</command>.
>> + </para>
>> </refsect1>
>>
>> <refsect1>
>
> Wouldn't it be more accurate to say that you have to be a member of the owning role?
> But perhaps that would be complicated enough to confuse many users.
We're calling check_object_ownership which errors out with:
aclcheck_error(ACLCHECK_NOT_OWNER, [...])
which in turn then aborts with "must be owner of [...]". But checking
the code, we do call has_privs_of_role, so you're absolutely right.
In doc/src/sgml/ref/alter_*.sgml we use the phrase "You must own the
[...]" to describe the privileges needed. Let me know if you want me to
change the wording.
While double checking I noticed that other docs don't have the extra
"the " before "<command>[...] " so I dropped that in my v2 patch.
Thanks for reviewing!
Patrick
Attachments:
[text/x-patch] 0001-Document-ownership-requirement-for-SECURITY-LABEL-v2.patch (980B, ../../69cd888d-2223-4880-9f57-dfe31bf2481a@packi.ch/2-0001-Document-ownership-requirement-for-SECURITY-LABEL-v2.patch)
download | inline diff:
From c90f9604ee7894c806d92e7fdbc87c304f8628eb Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Patrick=20St=C3=A4hlin?= <me@packi.ch>
Date: Thu, 5 Jun 2025 15:10:01 +0200
Subject: [PATCH] Document ownership requirement for SECURITY LABEL
Clarify that you need ownership of objects you issue SECURITY LABEL on.
---
doc/src/sgml/ref/security_label.sgml | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/doc/src/sgml/ref/security_label.sgml b/doc/src/sgml/ref/security_label.sgml
index e5e5fb483e9..aa45c0af248 100644
--- a/doc/src/sgml/ref/security_label.sgml
+++ b/doc/src/sgml/ref/security_label.sgml
@@ -84,6 +84,10 @@ SECURITY LABEL [ FOR <replaceable class="parameter">provider</replaceable> ] ON
based on object labels, rather than traditional discretionary access control
(DAC) concepts such as users and groups.
</para>
+
+ <para>
+ You must own the database object to use <command>SECURITY LABEL</command>.
+ </para>
</refsect1>
<refsect1>
--
2.48.1
^ permalink raw reply [nested|flat] 5+ messages in thread
* Re: Add sentence about SECURITY LABEL object ownership
@ 2025-06-05 15:19 Tom Lane <tgl@sss.pgh.pa.us>
parent: Laurenz Albe <laurenz.albe@cybertec.at>
1 sibling, 1 reply; 5+ messages in thread
From: Tom Lane @ 2025-06-05 15:19 UTC (permalink / raw)
To: Laurenz Albe <laurenz.albe@cybertec.at>; +Cc: Patrick Stählin <me@packi.ch>; pgsql-docs@lists.postgresql.org
Laurenz Albe <laurenz.albe@cybertec.at> writes:
> On Thu, 2025-06-05 at 15:29 +0200, Patrick Stählin wrote:
>> I noticed that we don't document that you need to own the object being
>> modified by SECURITY LABEL.
Yeah, clearly a documentation oversight.
> Wouldn't it be more accurate to say that you have to be a member of the owning role?
> But perhaps that would be complicated enough to confuse many users.
> In general, +1 for documenting that.
Our standard boilerplate for this is, eg,
You must own the table to use <command>ALTER TABLE</command>.
I don't see a reason to do it differently here.
regards, tom lane
^ permalink raw reply [nested|flat] 5+ messages in thread
* Re: Add sentence about SECURITY LABEL object ownership
@ 2025-06-06 01:18 Laurenz Albe <laurenz.albe@cybertec.at>
parent: Tom Lane <tgl@sss.pgh.pa.us>
0 siblings, 0 replies; 5+ messages in thread
From: Laurenz Albe @ 2025-06-06 01:18 UTC (permalink / raw)
To: Tom Lane <tgl@sss.pgh.pa.us>; +Cc: Patrick Stählin <me@packi.ch>; pgsql-docs@lists.postgresql.org
On Thu, 2025-06-05 at 11:19 -0400, Tom Lane wrote:
> Laurenz Albe <laurenz.albe@cybertec.at> writes:
> > On Thu, 2025-06-05 at 15:29 +0200, Patrick Stählin wrote:
> > > I noticed that we don't document that you need to own the object being
> > > modified by SECURITY LABEL.
>
> Yeah, clearly a documentation oversight.
>
> > Wouldn't it be more accurate to say that you have to be a member of the owning role?
> > But perhaps that would be complicated enough to confuse many users.
> > In general, +1 for documenting that.
>
> Our standard boilerplate for this is, eg,
>
> You must own the table to use <command>ALTER TABLE</command>.
>
> I don't see a reason to do it differently here.
Objection withdrawn.
Yours,
Laurenz Albe
^ permalink raw reply [nested|flat] 5+ messages in thread
end of thread, other threads:[~2025-06-06 01:18 UTC | newest]
Thread overview: 5+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2025-06-05 13:29 Add sentence about SECURITY LABEL object ownership Patrick Stählin <me@packi.ch>
2025-06-05 14:21 ` Laurenz Albe <laurenz.albe@cybertec.at>
2025-06-05 15:02 ` Patrick Stählin <me@packi.ch>
2025-06-05 15:19 ` Tom Lane <tgl@sss.pgh.pa.us>
2025-06-06 01:18 ` Laurenz Albe <laurenz.albe@cybertec.at>
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox