Re: pg_dump needs SELECT privileges on irrelevant extension table - Mailing list pgsql-hackers

From Stephen Frost
Subject Re: pg_dump needs SELECT privileges on irrelevant extension table
Date
Msg-id ZTA8D6w8Pg3T80CS@tamriel.snowman.net
Whole thread Raw
In response to Re: pg_dump needs SELECT privileges on irrelevant extension table  (Tom Lane <tgl@sss.pgh.pa.us>)
Responses Re: pg_dump needs SELECT privileges on irrelevant extension table
List pgsql-hackers
Greetings,

* Tom Lane (tgl@sss.pgh.pa.us) wrote:
> I wrote:
> > Why are we marking extension member objects as being subject to SECLABEL
> > or POLICY dumping?  As the comment notes, that isn't really sensible
> > unless what we are dumping is a delta from the extension's initial
> > assignments.  But we have no infrastructure for that, and none seems
> > likely to appear in the near future.
>
> Here's a quick patch that does it that way.  The test changes
> are identical to Jacob's v3-0001.

What the comment is talking about is that we don't support initial
policies, not that we don't support policies on extension tables at all.
That said ... even the claim that we don't support such policies isn't
supported by code and there are people out there doing it, which creates
its own set of problems (ones we should really try to find solutions to
though..).

This change would mean that policies added by a user after the extension
is created would just be lost by a pg_dump/reload, doesn't it?

Thanks,

Stephen

Attachment

pgsql-hackers by date:

Previous
From: Stephen Frost
Date:
Subject: Re: Parent/child context relation in pg_get_backend_memory_contexts()
Next
From: Tom Lane
Date:
Subject: Re: pg_dump needs SELECT privileges on irrelevant extension table