Re: Postgres 15 upgrades and template1 public schema - Mailing list pgsql-general

From Tom Lane
Subject Re: Postgres 15 upgrades and template1 public schema
Date
Msg-id 2949522.1666223992@sss.pgh.pa.us
Whole thread Raw
In response to Re: Postgres 15 upgrades and template1 public schema  (Bruno Wolff III <bruno@wolff.to>)
Responses Re: Postgres 15 upgrades and template1 public schema
Re: Postgres 15 upgrades and template1 public schema
List pgsql-general
Bruno Wolff III <bruno@wolff.to> writes:
> On Wed, Oct 19, 2022 at 23:30:58 +0200,
>   Thomas Kellerer <shammat@gmx.net> wrote:
>> This is explained in the release notes:
>> 
>> The change applies to new database clusters and to newly-created
>> databases in existing clusters.
>> Upgrading a cluster or restoring a database dump will preserve
>> public's existing permissions.

> How do new databases in pre-existing clusters get the new public schema 
> security if it doesn't come from template1?

The release notes could probably use some tweaking here.  It looks to
me like pg_dumpall (and hence pg_upgrade) will adjust the ownership and
permissions of template1's public schema to match what was in the old
installation, but it doesn't touch template0.  Hence, whether a
"newly-created database in an existing cluster" has the old or new
properties of the public schema will depend on whether you clone it
from template1 or template0.  That definitely needs explained, and
maybe we should recommend that DBAs consider manually changing
what's in template1.

            regards, tom lane



pgsql-general by date:

Previous
From: Tom Lane
Date:
Subject: Re: Custom function ROWS hint ignored due to inlining?
Next
From: Ron
Date:
Subject: pg_restore 12 "permission denied for schema" errors