Bruce Momjian <pgman@candle.pha.pa.us> writes:
> I understand, but how do we get suid execution. Does someone have to
> set the seuid bit on the executable?
Probably so, but I could see someone thinking they could do that as a
substitute for saying "su - postgres" on every startup.
If we are going to take the trouble to refuse to run when euid = 0,
then it also behooves us to guard against ruid = 0.
regards, tom lane