Re: Clarification on Role Access Rights to Table Indexes

From: Jeff Davis <pgsql(at)j-davis(dot)com>
To: Nathan Bossart <nathandbossart(at)gmail(dot)com>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: Ayush Vatsa <ayushvatsa1810(at)gmail(dot)com>, Robert Haas <robertmhaas(at)gmail(dot)com>, "David G(dot) Johnston" <david(dot)g(dot)johnston(at)gmail(dot)com>, PostgreSQL Hackers <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Clarification on Role Access Rights to Table Indexes
Date: 2025-10-09 03:06:04
Message-ID: 8af53c6e8992aa706e63aafe60a3bcf100b524d1.camel@j-davis.com
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-general pgsql-hackers

On Wed, 2025-09-24 at 11:52 -0500, Nathan Bossart wrote:
> On Wed, Sep 24, 2025 at 12:13:34PM -0400, Tom Lane wrote:
> > Nathan Bossart <nathandbossart(at)gmail(dot)com> writes:
> > > * RangeVarCallbackForReindexIndex() was checking privileges on
> > > the table
> > > before locking it, so I reversed it in 0002.
> >
> > Don't we do that intentionally, to make sure someone can't cause
> > DOS
> > on a table they have no privileges on?
>
> Ah, right.  I switched it back in v4.

v4-0001 looks good to me.

Just to make sure I understand: the actual problem would only happen
with OID wraparound, right?

Regards,
Jeff Davis

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Jeff Davis 2025-10-09 03:28:01 Re: Clarification on Role Access Rights to Table Indexes
Previous Message Adrian Klaver 2025-10-08 19:54:44 Re: Alerting on memory use and instance crash

Browse pgsql-hackers by date

  From Date Subject
Next Message Richard Guo 2025-10-09 03:10:31 Re: Eager aggregation, take 3
Previous Message Chao Li 2025-10-09 03:04:44 Re: doc: Improve description of io_combine_limit and io_max_combine_limit GUCs