Re: Fwd: init scripts and su - Mailing list pgsql-hackers

From Peter Eisentraut
Subject Re: Fwd: init scripts and su
Date
Msg-id 200408091017.02555.peter_e@gmx.net
Whole thread Raw
In response to Re: Fwd: init scripts and su  (Tom Lane <tgl@sss.pgh.pa.us>)
List pgsql-hackers
Tom Lane wrote:
> (a) And there would be untrusted code running as postgres exactly
> why?

Because someone has cracked the PostgreSQL server.

> (b) Seems to me the real security bug here is the mere existence of
> that ioctl call.

Probably.  I'm just pointing out the findings about the environment 
we're operating in.  The fact is that right now "run as postgres to 
protect your root account" won't work on some systems and with 
unfortunately written init scripts.

-- 
Peter Eisentraut
http://developer.postgresql.org/~petere/



pgsql-hackers by date:

Previous
From: "Dave Page"
Date:
Subject: Re: Windows binary in the beta directory?
Next
From: Christopher Kings-Lynne
Date:
Subject: Changing the type of timestamp columns