Re: [HACKERS] mode of libs - Mailing list pgsql-hackers

From Thomas G. Lockhart
Subject Re: [HACKERS] mode of libs
Date
Msg-id 34F4E9ED.4BAC21B1@alumni.caltech.edu
Whole thread Raw
In response to Re: [HACKERS] mode of libs  (Bruce Momjian <maillist@candle.pha.pa.us>)
Responses Re: [HACKERS] mode of libs  (Bruce Momjian <maillist@candle.pha.pa.us>)
List pgsql-hackers
> Now there is a bigger problem.  pg_pwd is mode rw-rw-rw- because a COPY
> is used to create it.  Any ideas how to fix this?  Copy sets the
> permissions to this before it creates the file.  It temporarily changes
> the umask to create the file.  If pg_pwd ever has data in it and it is
> world-readable, it is unsecure.
>
> Anyone have a brilliant idea on a fix?

Well, the data directory itself is protected from anyone other than the postgres
account, so it may not matter as much if an individual file is not right. My (former)
Ingres installation had the directory protected, and then permissions of 777 on all the
directories and files within it as I recall...

We should fix it up to match the protections on other files though...

                                                      - Tom


pgsql-hackers by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: [PORTS] alpha/64bit & mkoidname problem
Next
From: Brett McCormick
Date:
Subject: transaction not valid ColID