PostgreSQL and user restrictive view with functions involved

In PostgreSQL it’s quite easy to restrict access for user to some tables:

  1. create restrictive view
  2. grant usage on view schema
  3. grant select on view to restricted user
  4. done

Really easy. And it’s not working when the restrictive view, is selecting from another view that is using function(s) ! In that case, you might get very informative error:

ERROR:  permission denied for relation <TABLE>


ERROR:  permission denied for schema <SCHEMA>

Why ? Well everything works as expected, you have permission to SELECT from that restrictive VIEW and thus you really have some access to the underlying view/table, but function used in that view is still executed with permission of restricted user and therefore you obviously end up with ‘permission denied‘.

Solution for this is simple, force affected function(s) to execute with privileges of user that created it:


See CREATE FUNCTION manual for more info.

PowerDNS + systemd fail

I encountered this problem again, so let’s write it down to avoid googling it.


PowerDNS fails to start with
pdns.service: Failed at step ADDRESS_FAMILIES spawning /usr/sbin/pdns_server: Invalid argument


  1. edit /lib/systemd/system/pdns.service
  2. comment out RestrictAddressFamilies
  3. comment out ProtectSystem=full
  4. possibly kill systemd-resolved
  5. systemctl daemon-reload
  6. ask yourself again, why are you using debian with systemd on server ? And why the hell it is starting services I’ve never configured to start ? Isn’t it time to switch to windows ? It seems more predictable to me…

TINC VPN config generator

tinc is a great mesh Virtual Private Network daemon, with just one little glitch (and also little crypto problems ;-). I find its configuration really tedious and complicated compared to OpenVPN and its possibility to centrally assign IP addresses and push options to clients. I know, that’s the tax for being mesh, but wouldn’t it be great to configure your mesh network a bit centrally ?

Continue reading