From: Nathan Bossart <nathandbossart@gmail.com>
To: Jeff Davis <pgsql@j-davis.com>
Cc: Michael Paquier <michael@paquier.xyz>
Cc: Ted Yu <yuzhihong@gmail.com>
Cc: Pavel Luzanov <p.luzanov@postgrespro.ru>
Cc: Justin Pryzby <pryzby@telsasoft.com>
Cc: pgsql-hackers@postgresql.org
Subject: Re: allow granting CLUSTER, REFRESH MATERIALIZED VIEW, and REINDEX
Date: Tue, 20 Jun 2023 10:49:27 -0700
Message-ID: <20230620174927.GA494037@nathanxps13> (raw)
In-Reply-To: <20230620174032.GA471329@nathanxps13>
References: <ZIj4v1CwqlDVJZfB@paquier.xyz>
<20230613235442.GA222795@nathanxps13>
<20230614181711.GA488295@nathanxps13>
<ZIpfack6qJUHaw+g@paquier.xyz>
<20230615041044.GA736001@nathanxps13>
<20230615235700.GA877311@nathanxps13>
<20230616052025.GA1026700@nathanxps13>
<20230619215534.GA442477@nathanxps13>
<dd53c632abf86fc6dacf6653f9fbab9110ccdc14.camel@j-davis.com>
<20230620174032.GA471329@nathanxps13>
On Tue, Jun 20, 2023 at 10:40:32AM -0700, Nathan Bossart wrote:
> On Tue, Jun 20, 2023 at 10:04:37AM -0700, Jeff Davis wrote:
>> I think v4-0001 broke the handling of toast tables? It looks like you
>> removed the check for !skip_privs but need to add it to the flags in
>> vacuum_is_permitted_for_relation().
>
> Good catch. I'm not sure why some of the calls to
> vacuum_is_permitted_for_relation() are masking the options. AFAICT we can
> simply remove the masks. I've done so in the attached patch.
Oh, I think I see why. This appears to be used to control which WARNING
message is emitted. If you lose permissions before you get to analyzing in
a VACUUM (ANALYZE) command, you'll get a "permission denied to vacuum"
message instead of a "permission denied to analyze" message. IMO a better
way to do that would be to control only those two bits (VACOPT_VACUUM and
VACOPT_ANALYZE) in calls to vacuum_is_permitted_for_relation(), and to
leave the rest untouched.
Patch incoming...
--
Nathan Bossart
Amazon Web Services: https://aws.amazon.com
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: pgsql-hackers@postgresql.org
Cc: nathandbossart@gmail.com, pgsql@j-davis.com, michael@paquier.xyz, yuzhihong@gmail.com, p.luzanov@postgrespro.ru, pryzby@telsasoft.com
Subject: Re: allow granting CLUSTER, REFRESH MATERIALIZED VIEW, and REINDEX
In-Reply-To: <20230620174927.GA494037@nathanxps13>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox