Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1q9eJx-00063M-Cn for pgsql-hackers@arkaria.postgresql.org; Thu, 15 Jun 2023 04:10:53 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.92) (envelope-from ) id 1q9eJv-0005kT-9d for pgsql-hackers@arkaria.postgresql.org; Thu, 15 Jun 2023 04:10:51 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1q9eJu-0005kK-Tr for pgsql-hackers@lists.postgresql.org; Thu, 15 Jun 2023 04:10:51 +0000 Received: from mail-pg1-x534.google.com ([2607:f8b0:4864:20::534]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1q9eJs-002HPq-Bu for pgsql-hackers@postgresql.org; Thu, 15 Jun 2023 04:10:49 +0000 Received: by mail-pg1-x534.google.com with SMTP id 41be03b00d2f7-54f87d5f1abso2441107a12.0 for ; Wed, 14 Jun 2023 21:10:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20221208; t=1686802247; x=1689394247; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=6ANeTNMUOG3qK5tlZ5v8gj6UwB6z84w/ZYqsopRKaig=; b=bFRfutJsgihytiChhTMsuXZQj6DlPzw2cTDi5yUCtVkMlUFNeXsQQYieq4x2O5XFt2 wEDbjlRoUTjqgDBAyVHRJohbUBPXkAgSueiPdQ/vFSgVbwOJM+cnsTCBL6rFew0ZmavQ G0H8748tcWrAisJ7HSkJb9sPenrsGSJXiiM1wbepJJ+rprSzMop+wdqvE9tTwlcIexmf MjAIXFu30AvZcgeS4C5UIsGu6KdtjyOeHF5sD+Pi0670e1WPp1V2hHdScOtHVeSUhP4k cPwfhpD+mk3IzV9WOvphz6R6bI8rJTULogb6SN71Ss+HySq4oVSdxB7oH/1jSXiHEQn7 BsJQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1686802247; x=1689394247; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=6ANeTNMUOG3qK5tlZ5v8gj6UwB6z84w/ZYqsopRKaig=; b=djBEBvWw24XwSey6yIZ8Wt8U21MqmJnGPNEXRZKMqyfBnq9i3VUAzNDKtDLSSirXiA /ZqczbX45uIuzCZh6HZ1690fZbzrQ6kaAVNMansS85FfrWqxwy0ZunU5ScZkTHPFo8JR zYXovrmvNtx8CY48Dvo7iU3AUVymEWl+BDoLfmFCcSUMQ6gYrBLfGMxpCzqR7HBtyVQt HbT6xa5nMWmeuUZ3kFTVmoFLUaR4g2ad2+9FMw0nbg4crPu4VoBK05AYQlwTtAWyzCVD A4F5vlvALWat0uSc2NMQP0MxiCYdOX6CAQYPFDS22BAou1DwAtwYyOXtUcn7qBdgzRvK LUbQ== X-Gm-Message-State: AC+VfDxEkUelrZ41qHCuKjXWJNd6XtTOuOJ5JJ0ny6otRZxaFTWOrKW1 aBVszK/4FBqDFgnKV9KVrxI= X-Google-Smtp-Source: ACHHUZ7amahJLPBb5YYixZtNOVLU79IHSELgw9o+DIIQtaX9KOAKNyhez8N+UFKtP3gUvsVHQFkKPQ== X-Received: by 2002:a17:90a:341:b0:25b:f862:43a6 with SMTP id 1-20020a17090a034100b0025bf86243a6mr2696348pjf.21.1686802247317; Wed, 14 Jun 2023 21:10:47 -0700 (PDT) Received: from nathanxps13 ([50.47.162.83]) by smtp.gmail.com with ESMTPSA id nn4-20020a17090b38c400b002562cfb81dfsm13486869pjb.28.2023.06.14.21.10.46 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 14 Jun 2023 21:10:46 -0700 (PDT) Date: Wed, 14 Jun 2023 21:10:44 -0700 From: Nathan Bossart To: Michael Paquier Cc: Jeff Davis , Ted Yu , Pavel Luzanov , Justin Pryzby , pgsql-hackers@postgresql.org Subject: Re: allow granting CLUSTER, REFRESH MATERIALIZED VIEW, and REINDEX Message-ID: <20230615041044.GA736001@nathanxps13> References: <7d2a8b72e23c8236281c6e00ae790327f965a8e5.camel@j-davis.com> <20230113203334.GA2206335@nathanxps13> <20230113225626.GA2380176@nathanxps13> <20230113231339.GA2422750@nathanxps13> <20230613211246.GA219055@nathanxps13> <20230613235442.GA222795@nathanxps13> <20230614181711.GA488295@nathanxps13> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On Thu, Jun 15, 2023 at 09:46:33AM +0900, Michael Paquier wrote: > The result after 0001 is applied is that a couple of > object_ownercheck() calls that existed before ff9618e are removed from > some ACL checks in the REINDEX, CLUSTER and VACUUM paths. Is that OK > for shared relations and shouldn't cluster_is_permitted_for_relation() > include that? vacuum_is_permitted_for_relation() is consistent on > this side. These object_ownercheck() calls were removed because they were redundant, as owners have all privileges by default. Privileges can be revoked from the owner, so an extra ownership check would effectively bypass the relation's ACL in that case. I looked around and didn't see any other examples of a combined ownership and ACL check like we were doing for MAINTAIN. The only thing that gives me pause is that the docs call out ownership as sufficient for some maintenance commands. With these patches, that's only true as long as no one revokes privileges from the owner. IMO we should update the docs and leave out the ownership checks since MAINTAIN is now a grantable privilege like any other. WDYT? -- Nathan Bossart Amazon Web Services: https://aws.amazon.com