This file collects guidance about PostgreSQL itself rather than about PGXNtool. It lives here because these questions come up constantly while writing an extension, and PGXNtool’s docs are where extension authors already are. Nothing here describes PGXNtool behavior, and nothing PGXNtool does depends on it.
For PGXNtool’s own documentation, see README.asc.
By default only a superuser can run CREATE EXTENSION or ALTER EXTENSION … UPDATE
for your extension. Two .control file parameters change that.
superuser = false-
Removes the superuser requirement outright. The install/update script then runs as the user who invoked
CREATE EXTENSION, so that user must already hold every privilege the script needs — nothing is granted implicitly. trusted = true-
Lets any non-superuser with
CREATEprivilege on the database install the extension, but runs the install/update script as the bootstrap superuser instead of as the caller. It is only consulted whensuperuseris true (the default), and requires PostgreSQL 13 or later.
|
Warning
|
trusted = true has real security consequences. Because the script runs with
superuser rights on behalf of an unprivileged caller, any weakness in it becomes a
privilege-escalation path, and writing a trusted extension’s SQL safely takes deliberate
effort. Read PostgreSQL’s own
Security
Considerations for Extensions before setting it.
|
If your extension doesn’t need superuser-only capabilities, superuser = false is
usually the better of the two: it grants nothing, it merely stops requiring superuser.