Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1uNBTe-00Dn4V-EQ for pgsql-docs@arkaria.postgresql.org; Thu, 05 Jun 2025 14:21:54 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1uNBTc-009sWp-0n for pgsql-docs@arkaria.postgresql.org; Thu, 05 Jun 2025 14:21:52 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1uNBTb-009sWg-Ob for pgsql-docs@lists.postgresql.org; Thu, 05 Jun 2025 14:21:52 +0000 Received: from mail-wm1-x32d.google.com ([2a00:1450:4864:20::32d]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.96) (envelope-from ) id 1uNBTa-000Op6-1h for pgsql-docs@lists.postgresql.org; Thu, 05 Jun 2025 14:21:51 +0000 Received: by mail-wm1-x32d.google.com with SMTP id 5b1f17b1804b1-451d41e1ad1so8656925e9.1 for ; Thu, 05 Jun 2025 07:21:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cybertec.at; s=google; t=1749133309; x=1749738109; darn=lists.postgresql.org; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:to:from:subject:message-id:from:to:cc:subject:date :message-id:reply-to; bh=m22mzv01GIj+U70AYbnW8WMnAZOTVhetNldqMDzJg1w=; b=kjteW0ZbPICOd8zQ06Wxqkwp4KWW4rW3xqndiF00N1H7Gf2HAvjZrU4TqD3eHKa3T5 uuZvlLIjBPUZzr0G6yy678wIFi9ZJoflAZVMw57ct1GQMXlNrKg+o2eMdyr8v6XxB/7/ sIQ4ztO7t6bUafYBxwmQ/BYeEwQZA1OSR+vsWcPEJgIo52M4ScsSInpDXZ2ZNbI8Vn+q 7ZWhV1wLh0D3ydtq21uaMAMTDzd0hCmzXPwtEHHwwWM3w3/1fhY5Od6Cv7SlVymyzj17 Nb6J8UbW/AL6hQ43T3x7kJLgMiyP5EkdOEOICyQoiBRX0MSp+2qXstikLwGcElnxc8Iw EGLA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1749133309; x=1749738109; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:to:from:subject:message-id:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=m22mzv01GIj+U70AYbnW8WMnAZOTVhetNldqMDzJg1w=; b=SXKsNU1tut1KB8UUEzK/5zioUJ/5KThHHr70Wai0pmjkhhTZ6vw2yYFHgbeeCswC4Z IEQlXVuFN8XgZUfM9lArbSvHcUDsRYyllJMu6b2R6FEO3fQaYATofqb89U9XdGFdhxMZ 0/Iny2lOtN+M+BSAo1s3v5KMlpb1+SYn9CRsRvWZpMfz4F0JDHkVnaA8mxBefFm9Ia3q oIQ7WeZSdMt3Zp2Gr2iYmL38PBt+lkMP7A1VM1l5qEwKAL4H656EJAxxawQ+PiTQ4bXp 8SOGJ+kSDYTk1InuoajoE8XfitP8MTfYWFLzQvFATfcsR+dEVqUvkYOOcSwXz6ipWio8 MXXg== X-Forwarded-Encrypted: i=1; AJvYcCXxWjCv7PNyfGeQYzJX/waY0xZ1mS7/VNCC6l3lBw0j+AurmxIP7oqjDw6xzK+ryADU+zTFMjAvBtlf@lists.postgresql.org X-Gm-Message-State: AOJu0Yz2JCWUnxeKOmFLE5rynAnkanV4U6iHM2PYDqZEiNe6YYXVfaO6 ADqk5P092erJiZi9TtowriDn2468fVdo8iCs6nY2UXa/Pc4vLTjsalgSWFo0SuPAd+xkc+87ge6 LP7Ha X-Gm-Gg: ASbGncvAIovHvD6yv+8c4qSyMe1izAW+m5wqwsCU2Y8B1TXLq7+jMZZJmf1xGvGFgVH sPXC7GnQOwu2WjZnSJE6TilGTJQqSWIRANutAwEA9JVo2prZc6iFYBDGC2hLt+ZYY0OHLHiGgzv QOxAE7uj8HvXOgKbIiQ1rIiMxH2ZMtJJBJIj1G80212JYGPTqUv+gf5/xt5iMLAIaQOKLKkdT8I WKienHNUEIp+ysqHb4F0552OFsiwqQ+vFyJmaOk3Yeww/m8L/ZsFvNA3YLvjqOB1WTwj9AkzA5H 9CmPca73nV63OJJD2Cdr7vuaYWe7zdC8E2hlBBMCJjWYbDbfgmh0AWB+6bM2V41EIPakp0uCug6 7WgI= X-Google-Smtp-Source: AGHT+IE2+F77/C7RGSGv7feLBFtG08kLkT+VitXA8Y67lqR7DxQzkuMUjZEpvZm4S+nYl9igVyCxoQ== X-Received: by 2002:a05:6000:1aca:b0:3a4:e6bb:2d32 with SMTP id ffacd0b85a97d-3a51dbcde08mr5810306f8f.22.1749133308575; Thu, 05 Jun 2025 07:21:48 -0700 (PDT) Received: from laurenz.albe-K4N0CV00F97414D ([199.168.44.34]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-4a4358d2baesm110412251cf.39.2025.06.05.07.21.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 05 Jun 2025 07:21:48 -0700 (PDT) Message-ID: <2c8f7b87b68fd2084faebdcf48b4edb23f4e93e0.camel@cybertec.at> Subject: Re: Add sentence about SECURITY LABEL object ownership From: Laurenz Albe To: Patrick =?ISO-8859-1?Q?St=E4hlin?= , pgsql-docs@lists.postgresql.org Date: Thu, 05 Jun 2025 09:21:47 -0500 In-Reply-To: <931e012a-57ba-41ba-9b88-24323a46dec5@packi.ch> References: <931e012a-57ba-41ba-9b88-24323a46dec5@packi.ch> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.56.2 (3.56.2-1.fc42) MIME-Version: 1.0 List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On Thu, 2025-06-05 at 15:29 +0200, Patrick St=C3=A4hlin wrote: > Hi, >=20 > I noticed that we don't document that you need to own the object being= =20 > modified by SECURITY LABEL. >=20 > Page: https://www.postgresql.org/docs/current/sql-security-label.html >=20 > I've attached a patch that would have answered that question (for me)=20 > without diving into the code. > --- a/doc/src/sgml/ref/security_label.sgml > +++ b/doc/src/sgml/ref/security_label.sgml > @@ -84,6 +84,10 @@ SECURITY LABEL [ FOR = provider ] ON > based on object labels, rather than traditional discretionary access = control > (DAC) concepts such as users and groups. > > + > + > + You must own the database object to use the SECURITY LABEL. > + > > =20 > Wouldn't it be more accurate to say that you have to be a member of the own= ing role? But perhaps that would be complicated enough to confuse many users. In general, +1 for documenting that. Yours, Laurenz Albe