Skip to content

Latest commit

 

History

History
43 lines (34 loc) · 2.05 KB

File metadata and controls

43 lines (34 loc) · 2.05 KB

General PostgreSQL Notes

This file collects guidance about PostgreSQL itself rather than about PGXNtool. It lives here because these questions come up constantly while writing an extension, and PGXNtool’s docs are where extension authors already are. Nothing here describes PGXNtool behavior, and nothing PGXNtool does depends on it.

For PGXNtool’s own documentation, see README.asc.

By default only a superuser can run CREATE EXTENSION or ALTER EXTENSION …​ UPDATE for your extension. Two .control file parameters change that.

superuser = false

Removes the superuser requirement outright. The install/update script then runs as the user who invoked CREATE EXTENSION, so that user must already hold every privilege the script needs — nothing is granted implicitly.

trusted = true

Lets any non-superuser with CREATE privilege on the database install the extension, but runs the install/update script as the bootstrap superuser instead of as the caller. It is only consulted when superuser is true (the default), and requires PostgreSQL 13 or later.

Warning
trusted = true has real security consequences. Because the script runs with superuser rights on behalf of an unprivileged caller, any weakness in it becomes a privilege-escalation path, and writing a trusted extension’s SQL safely takes deliberate effort. Read PostgreSQL’s own Security Considerations for Extensions before setting it.

If your extension doesn’t need superuser-only capabilities, superuser = false is usually the better of the two: it grants nothing, it merely stops requiring superuser.

PostgreSQL’s reference documentation for both parameters: superuser and trusted.