Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1uNyeE-00D6P3-NJ for pgsql-docs@arkaria.postgresql.org; Sat, 07 Jun 2025 18:52:06 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1uNyeC-00EgiR-Q5 for pgsql-docs@arkaria.postgresql.org; Sat, 07 Jun 2025 18:52:05 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1uNC7U-00AKkk-BR for pgsql-docs@lists.postgresql.org; Thu, 05 Jun 2025 15:03:04 +0000 Received: from mail-gateway-shared12.cyon.net ([194.126.200.65]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1uNC7R-000P5g-1o for pgsql-docs@lists.postgresql.org; Thu, 05 Jun 2025 15:03:04 +0000 Received: from [149.126.4.71] (helo=s062.cyon.net) by mail-gateway-shared12.cyon.net with esmtpsa (TLS1.2:ECDHE_SECP256R1__RSA_SHA512__AES_256_GCM:256) (Exim) (envelope-from ) id 1uNC7F-009vPD-0W for pgsql-docs@lists.postgresql.org; Thu, 05 Jun 2025 17:02:50 +0200 Received: from [10.20.10.53] (port=21540 helo=mail.cyon.ch) by s062.cyon.net with esmtpa (Exim 4.98.1) (envelope-from ) id 1uNC7A-0000000Ek63-0Mgb; Thu, 05 Jun 2025 17:02:44 +0200 Content-Type: multipart/mixed; boundary="------------V50uO0n80ie3edIrvj0tNqzi" Message-ID: <69cd888d-2223-4880-9f57-dfe31bf2481a@packi.ch> Date: Thu, 5 Jun 2025 17:02:43 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: Add sentence about SECURITY LABEL object ownership To: Laurenz Albe References: <931e012a-57ba-41ba-9b88-24323a46dec5@packi.ch> <2c8f7b87b68fd2084faebdcf48b4edb23f4e93e0.camel@cybertec.at> Content-Language: en-US From: =?UTF-8?Q?Patrick_St=C3=A4hlin?= Cc: pgsql-docs@lists.postgresql.org In-Reply-To: <2c8f7b87b68fd2084faebdcf48b4edb23f4e93e0.camel@cybertec.at> X-AntiAbuse: This header was added to track abuse, please include it with any abuse report X-AntiAbuse: Primary Hostname - s062.cyon.net X-AntiAbuse: Original Domain - lists.postgresql.org X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12] X-AntiAbuse: Sender Address Domain - packi.ch X-Get-Message-Sender-Via: s062.cyon.net: authenticated_id: me@packi.ch X-Authenticated-Sender: s062.cyon.net: me@packi.ch List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk This is a multi-part message in MIME format. --------------V50uO0n80ie3edIrvj0tNqzi Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 6/5/25 4:21 PM, Laurenz Albe wrote: >> + >> + >> + You must own the database object to use the SECURITY LABEL. >> + >> >> >> > > Wouldn't it be more accurate to say that you have to be a member of the owning role? > But perhaps that would be complicated enough to confuse many users. We're calling check_object_ownership which errors out with: aclcheck_error(ACLCHECK_NOT_OWNER, [...]) which in turn then aborts with "must be owner of [...]". But checking the code, we do call has_privs_of_role, so you're absolutely right. In doc/src/sgml/ref/alter_*.sgml we use the phrase "You must own the [...]" to describe the privileges needed. Let me know if you want me to change the wording. While double checking I noticed that other docs don't have the extra "the " before "[...] " so I dropped that in my v2 patch. Thanks for reviewing! Patrick --------------V50uO0n80ie3edIrvj0tNqzi Content-Type: text/x-patch; charset=UTF-8; name="0001-Document-ownership-requirement-for-SECURITY-LABEL-v2.patch" Content-Disposition: attachment; filename*0="0001-Document-ownership-requirement-for-SECURITY-LABEL-v2.pa"; filename*1="tch" Content-Transfer-Encoding: base64 RnJvbSBjOTBmOTYwNGVlNzg5NGM4MDZkOTJlN2ZkYmM4N2MzMDRmODYyOGViIE1vbiBTZXAg MTcgMDA6MDA6MDAgMjAwMQpGcm9tOiA9P1VURi04P3E/UGF0cmljaz0yMFN0PUMzPUE0aGxp bj89IDxtZUBwYWNraS5jaD4KRGF0ZTogVGh1LCA1IEp1biAyMDI1IDE1OjEwOjAxICswMjAw ClN1YmplY3Q6IFtQQVRDSF0gRG9jdW1lbnQgb3duZXJzaGlwIHJlcXVpcmVtZW50IGZvciBT RUNVUklUWSBMQUJFTAoKQ2xhcmlmeSB0aGF0IHlvdSBuZWVkIG93bmVyc2hpcCBvZiBvYmpl Y3RzIHlvdSBpc3N1ZSBTRUNVUklUWSBMQUJFTCBvbi4KLS0tCiBkb2Mvc3JjL3NnbWwvcmVm L3NlY3VyaXR5X2xhYmVsLnNnbWwgfCA0ICsrKysKIDEgZmlsZSBjaGFuZ2VkLCA0IGluc2Vy dGlvbnMoKykKCmRpZmYgLS1naXQgYS9kb2Mvc3JjL3NnbWwvcmVmL3NlY3VyaXR5X2xhYmVs LnNnbWwgYi9kb2Mvc3JjL3NnbWwvcmVmL3NlY3VyaXR5X2xhYmVsLnNnbWwKaW5kZXggZTVl NWZiNDgzZTkuLmFhNDVjMGFmMjQ4IDEwMDY0NAotLS0gYS9kb2Mvc3JjL3NnbWwvcmVmL3Nl Y3VyaXR5X2xhYmVsLnNnbWwKKysrIGIvZG9jL3NyYy9zZ21sL3JlZi9zZWN1cml0eV9sYWJl bC5zZ21sCkBAIC04NCw2ICs4NCwxMCBAQCBTRUNVUklUWSBMQUJFTCBbIEZPUiA8cmVwbGFj ZWFibGUgY2xhc3M9InBhcmFtZXRlciI+cHJvdmlkZXI8L3JlcGxhY2VhYmxlPiBdIE9OCiAg ICBiYXNlZCBvbiBvYmplY3QgbGFiZWxzLCByYXRoZXIgdGhhbiB0cmFkaXRpb25hbCBkaXNj cmV0aW9uYXJ5IGFjY2VzcyBjb250cm9sCiAgICAoREFDKSBjb25jZXB0cyBzdWNoIGFzIHVz ZXJzIGFuZCBncm91cHMuCiAgIDwvcGFyYT4KKworICA8cGFyYT4KKyAgIFlvdSBtdXN0IG93 biB0aGUgZGF0YWJhc2Ugb2JqZWN0IHRvIHVzZSA8Y29tbWFuZD5TRUNVUklUWSBMQUJFTDwv Y29tbWFuZD4uCisgIDwvcGFyYT4KICA8L3JlZnNlY3QxPgogCiAgPHJlZnNlY3QxPgotLSAK Mi40OC4xCgo= --------------V50uO0n80ie3edIrvj0tNqzi--