pg.ddx.io  pgsql-hackers@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Nathan Bossart <nathandbossart@gmail.com>
To: Jeff Davis <pgsql@j-davis.com>
Cc: Ted Yu <yuzhihong@gmail.com>
Cc: Pavel Luzanov <p.luzanov@postgrespro.ru>
Cc: Justin Pryzby <pryzby@telsasoft.com>
Cc: pgsql-hackers@postgresql.org
Subject: Re: allow granting CLUSTER, REFRESH MATERIALIZED VIEW, and REINDEX
Date: Fri, 13 Jan 2023 12:33:34 -0800
Message-ID: <20230113203334.GA2206335@nathanxps13> (raw)
In-Reply-To: <7d2a8b72e23c8236281c6e00ae790327f965a8e5.camel@j-davis.com>
References: <20221214221140.GA1153@telsasoft.com>
	<cf56dc1a36e5c15e19c4be634038029096d96dab.camel@j-davis.com>
	<b41c0577-8e16-c0fc-0d98-f17155047354@postgrespro.ru>
	<295e86c7aeafb8e2623f8eccdc846855bf2c7e0c.camel@j-davis.com>
	<20221217060408.GA1256247@nathanxps13>
	<CALte62zW+s+V3fDUxP2ZYk2f=DZsyZO-Aa_bbiA39=wrz=UHuQ@mail.gmail.com>
	<20221218233018.GA1476904@nathanxps13>
	<20230103234549.GA289060@nathanxps13>
	<20230109225157.GA1288965@nathanxps13>
	<7d2a8b72e23c8236281c6e00ae790327f965a8e5.camel@j-davis.com>

On Fri, Jan 13, 2023 at 11:56:03AM -0800, Jeff Davis wrote:
> I'm hesitant to add an index to pg_class just for the privilege checks
> on toast tables, and I don't think we need to.

I bet this index will be useful for more than just these privilege checks
(e.g., autovacuum currently creates a hash table for the
toast-to-main-relation mapping), but I do understand the hesitation.

> Instead, we can just
> skip the privilege check on a toast table if it's not referenced
> directly, because we already checked the privileges on the parent, and
> we still hold the session lock so nothing strange should have happened.

That would fix the problem in the original complaint, but it wouldn't allow
for vacuuming toast tables directly if you only have MAINTAIN privileges on
the main relation.  If you can vacuum the toast table indirectly via the
main relation, shouldn't it be possible to vacuum it directly?

-- 
Nathan Bossart
Amazon Web Services: https://aws.amazon.com





view thread (79+ messages)  latest in thread

Message-ID: <20230113203334.GA2206335@nathanxps13>
Permalink:  ../20230113203334.GA2206335@nathanxps13/
Also on:    postgresql.org/message-id/20230113203334.GA2206335@nathanxps13

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-hackers@postgresql.org
  Cc: nathandbossart@gmail.com, pgsql@j-davis.com, yuzhihong@gmail.com, p.luzanov@postgrespro.ru, pryzby@telsasoft.com
  Subject: Re: allow granting CLUSTER, REFRESH MATERIALIZED VIEW, and REINDEX
  In-Reply-To: <20230113203334.GA2206335@nathanxps13>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox