agora inbox for pgsql-docs@postgresql.org  
help / color / mirror / Atom feed
From: Patrick Stählin <me@packi.ch>
To: Laurenz Albe <laurenz.albe@cybertec.at>
Cc: pgsql-docs@lists.postgresql.org
Subject: Re: Add sentence about SECURITY LABEL object ownership
Date: Thu, 5 Jun 2025 17:02:43 +0200
Message-ID: <69cd888d-2223-4880-9f57-dfe31bf2481a@packi.ch> (raw)
In-Reply-To: <2c8f7b87b68fd2084faebdcf48b4edb23f4e93e0.camel@cybertec.at>
References: <931e012a-57ba-41ba-9b88-24323a46dec5@packi.ch>
	<2c8f7b87b68fd2084faebdcf48b4edb23f4e93e0.camel@cybertec.at>

On 6/5/25 4:21 PM, Laurenz Albe wrote:
>> +
>> +  <para>
>> +   You must own the database object to use the <command>SECURITY LABEL</command>.
>> +  </para>
>>    </refsect1>
>>   
>>    <refsect1>
> 
> Wouldn't it be more accurate to say that you have to be a member of the owning role?
> But perhaps that would be complicated enough to confuse many users.

We're calling check_object_ownership which errors out with:

    aclcheck_error(ACLCHECK_NOT_OWNER, [...])

which in turn then aborts with "must be owner of [...]". But checking 
the code, we do call has_privs_of_role, so you're absolutely right.

In doc/src/sgml/ref/alter_*.sgml we use the phrase "You must own the 
[...]" to describe the privileges needed. Let me know if you want me to 
change the wording.

While double checking I noticed that other docs don't have the extra 
"the " before "<command>[...] " so I dropped that in my v2 patch.

Thanks for reviewing!
Patrick

Attachments:

  [text/x-patch] 0001-Document-ownership-requirement-for-SECURITY-LABEL-v2.patch (980B, ../69cd888d-2223-4880-9f57-dfe31bf2481a@packi.ch/2-0001-Document-ownership-requirement-for-SECURITY-LABEL-v2.patch)
  download | inline diff:
From c90f9604ee7894c806d92e7fdbc87c304f8628eb Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Patrick=20St=C3=A4hlin?= <me@packi.ch>
Date: Thu, 5 Jun 2025 15:10:01 +0200
Subject: [PATCH] Document ownership requirement for SECURITY LABEL

Clarify that you need ownership of objects you issue SECURITY LABEL on.
---
 doc/src/sgml/ref/security_label.sgml | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/doc/src/sgml/ref/security_label.sgml b/doc/src/sgml/ref/security_label.sgml
index e5e5fb483e9..aa45c0af248 100644
--- a/doc/src/sgml/ref/security_label.sgml
+++ b/doc/src/sgml/ref/security_label.sgml
@@ -84,6 +84,10 @@ SECURITY LABEL [ FOR <replaceable class="parameter">provider</replaceable> ] ON
    based on object labels, rather than traditional discretionary access control
    (DAC) concepts such as users and groups.
   </para>
+
+  <para>
+   You must own the database object to use <command>SECURITY LABEL</command>.
+  </para>
  </refsect1>
 
  <refsect1>
-- 
2.48.1



view thread (5+ messages)  latest in thread

Message-ID: <69cd888d-2223-4880-9f57-dfe31bf2481a@packi.ch>
Permalink:  ../69cd888d-2223-4880-9f57-dfe31bf2481a@packi.ch/
Also on:    postgresql.org/message-id/69cd888d-2223-4880-9f57-dfe31bf2481a@packi.ch

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-docs@postgresql.org
  Cc: me@packi.ch, laurenz.albe@cybertec.at, pgsql-docs@lists.postgresql.org
  Subject: Re: Add sentence about SECURITY LABEL object ownership
  In-Reply-To: <69cd888d-2223-4880-9f57-dfe31bf2481a@packi.ch>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox