Re: add a MAC check for TRUNCATE - Mailing list pgsql-hackers

From Tom Lane
Subject Re: add a MAC check for TRUNCATE
Date
Msg-id 26736.1569448666@sss.pgh.pa.us
Whole thread Raw
In response to Re: add a MAC check for TRUNCATE  (Alvaro Herrera <alvherre@2ndquadrant.com>)
Responses Re: add a MAC check for TRUNCATE
List pgsql-hackers
Alvaro Herrera <alvherre@2ndquadrant.com> writes:
> On 2019-Sep-25, Yuli Khodorkovskiy wrote:
>> Since all existing DAC checks should have MAC, should these patches be
>> considered a bug fix and therefore back patched?

> I don't know the answer to that.  My impression from earlier discussion
> is that this was seen as a non-backpatchable change, but I defer to Joe
> on that as committer.  If it were up to me, the ultimate question would
> be: would such a change adversely affect existing running systems?

I don't see how the addition of a new permissions check could sanely
be back-patched unless it were to default to "allow", which seems like
an odd choice.

            regards, tom lane



pgsql-hackers by date:

Previous
From: Alvaro Herrera
Date:
Subject: Re: add a MAC check for TRUNCATE
Next
From: Euler Taveira
Date:
Subject: Re: row filtering for logical replication