agora inbox for pgsql-docs@postgresql.org
help / color / mirror / Atom feedImproved security for https://www.postgresql.org/docs/current/install-make.html
4+ messages / 3 participants
[nested] [flat]
* Improved security for https://www.postgresql.org/docs/current/install-make.html
@ 2024-11-06 21:58 PG Doc comments form <noreply@postgresql.org>
2024-11-11 15:32 ` Re: Improved security for https://www.postgresql.org/docs/current/install-make.html Peter Eisentraut <peter@eisentraut.org>
0 siblings, 1 reply; 4+ messages in thread
From: PG Doc comments form @ 2024-11-06 21:58 UTC (permalink / raw)
To: pgsql-docs@lists.postgresql.org; +Cc: bgiles@coyotesong.com
The following documentation comment has been logged on the website:
Page: https://www.postgresql.org/docs/17/install-make.html
Description:
The current 'short' version is
```
./configure
make
su
make install
adduser postgres
mkdir -p /usr/local/pgsql/data
chown postgres /usr/local/pgsql/data
su - postgres
/usr/local/pgsql/bin/initdb -D /usr/local/pgsql/data
/usr/local/pgsql/bin/pg_ctl -D /usr/local/pgsql/data -l logfile start
/usr/local/pgsql/bin/createdb test
/usr/local/pgsql/bin/psql test
```
The security could be improved by limiting the amount of work that is done
as root. (sudo make
install -- shudder!)
First, split `make install` so `make build` gets as far as building the
libraries **under the current directory**, not on location in the start
directory.
Second, verify that `make install` does nothing but create directories and
copy files into them. It can probably also include the tasks currently done
by `make installdir` but the latter might still be required by some external
process. This target should be reviewed by security experts.
The 'short' script can then be rewritten as
```
# work done as a regular user
./configure
make build
# work that requires ROOT access
su
mkdir /usr/local/pgsql/data
chown (current user):(current group) /usr/local/pgsql
adduser --system --group postgres
exit
# work that requires POSTGRES access
su -u postgres
make install installdirs
exit
# work that requires ROOT access
su
adduser --system --group postgres
chown -R postgres:postgres /usr/local/pgsql
exit
# work that requires POSTGRES access
su - postgres
/usr/local/pgsql/bin/initdb -D /usr/local/pgsql/data
/usr/local/pgsql/bin/pg_ctl -D /usr/local/pgsql/data -l logfile start
/usr/local/pgsql/bin/createdb test
/usr/local/pgsql/bin/psql test
exit
```
^ permalink raw reply [nested|flat] 4+ messages in thread
* Re: Improved security for https://www.postgresql.org/docs/current/install-make.html
2024-11-06 21:58 Improved security for https://www.postgresql.org/docs/current/install-make.html PG Doc comments form <noreply@postgresql.org>
@ 2024-11-11 15:32 ` Peter Eisentraut <peter@eisentraut.org>
2024-11-12 21:50 ` Re: Improved security for https://www.postgresql.org/docs/current/install-make.html Bear Giles <bgiles@coyotesong.com>
0 siblings, 1 reply; 4+ messages in thread
From: Peter Eisentraut @ 2024-11-11 15:32 UTC (permalink / raw)
To: bgiles@coyotesong.com; pgsql-docs@lists.postgresql.org
On 06.11.24 22:58, PG Doc comments form wrote:
> The 'short' script can then be rewritten as
>
> ```
> # work done as a regular user
> ./configure
> make build
>
> # work that requires ROOT access
> su
> mkdir /usr/local/pgsql/data
> chown (current user):(current group) /usr/local/pgsql
> adduser --system --group postgres
> exit
>
> # work that requires POSTGRES access
> su -u postgres
> make install installdirs
> exit
We don't want the installed files to be owned by postgres. That would
mean that a compromised PostgreSQL server (running as "postgres") could
overwrite its own installation files. You don't have to use "root" for
the installation, of course, but it should be separate from "postgres".
^ permalink raw reply [nested|flat] 4+ messages in thread
* Re: Improved security for https://www.postgresql.org/docs/current/install-make.html
2024-11-06 21:58 Improved security for https://www.postgresql.org/docs/current/install-make.html PG Doc comments form <noreply@postgresql.org>
2024-11-11 15:32 ` Re: Improved security for https://www.postgresql.org/docs/current/install-make.html Peter Eisentraut <peter@eisentraut.org>
@ 2024-11-12 21:50 ` Bear Giles <bgiles@coyotesong.com>
2024-11-13 08:10 ` Re: Improved security for https://www.postgresql.org/docs/current/install-make.html Peter Eisentraut <peter@eisentraut.org>
0 siblings, 1 reply; 4+ messages in thread
From: Bear Giles @ 2024-11-12 21:50 UTC (permalink / raw)
To: Peter Eisentraut <peter@eisentraut.org>; +Cc: pgsql-docs@lists.postgresql.org
You'll want to update the existing page then! :-)
My point was mostly that I did a fresh 'git clone', followed the
instructions, and was immediately hit by a "permission denied" error
because the make script tried to create a directory under /usr/local. It
wasn't clear whether that was the only thing that required root access. The
script I provided was one approach, but it can be greatly simplified if all
that's required is creating the directory and chancing its ownership prior
to running the 'make install'.
(I still think it's a Good Idea to separate compilation and
deployment/'installation but that's a separate issue.)
Bear
On Mon, Nov 11, 2024 at 8:32 AM Peter Eisentraut <peter@eisentraut.org>
wrote:
> On 06.11.24 22:58, PG Doc comments form wrote:
> > The 'short' script can then be rewritten as
> >
> > ```
> > # work done as a regular user
> > ./configure
> > make build
> >
> > # work that requires ROOT access
> > su
> > mkdir /usr/local/pgsql/data
> > chown (current user):(current group) /usr/local/pgsql
> > adduser --system --group postgres
> > exit
> >
> > # work that requires POSTGRES access
> > su -u postgres
> > make install installdirs
> > exit
>
> We don't want the installed files to be owned by postgres. That would
> mean that a compromised PostgreSQL server (running as "postgres") could
> overwrite its own installation files. You don't have to use "root" for
> the installation, of course, but it should be separate from "postgres".
>
>
^ permalink raw reply [nested|flat] 4+ messages in thread
* Re: Improved security for https://www.postgresql.org/docs/current/install-make.html
2024-11-06 21:58 Improved security for https://www.postgresql.org/docs/current/install-make.html PG Doc comments form <noreply@postgresql.org>
2024-11-11 15:32 ` Re: Improved security for https://www.postgresql.org/docs/current/install-make.html Peter Eisentraut <peter@eisentraut.org>
2024-11-12 21:50 ` Re: Improved security for https://www.postgresql.org/docs/current/install-make.html Bear Giles <bgiles@coyotesong.com>
@ 2024-11-13 08:10 ` Peter Eisentraut <peter@eisentraut.org>
0 siblings, 0 replies; 4+ messages in thread
From: Peter Eisentraut @ 2024-11-13 08:10 UTC (permalink / raw)
To: Bear Giles <bgiles@coyotesong.com>; +Cc: pgsql-docs@lists.postgresql.org
On 12.11.24 22:50, Bear Giles wrote:
> My point was mostly that I did a fresh 'git clone', followed the
> instructions, and was immediately hit by a "permission denied" error
> because the make script tried to create a directory under /usr/local. It
> wasn't clear whether that was the only thing that required root access.
Please provide a precise description of what steps you did and what the
result or output from each was. This report is not clear enough to be
actionable. As far as I can tell, the existing instructions are sound
for a typical use, so it's not clear where your situation diverged.
^ permalink raw reply [nested|flat] 4+ messages in thread
end of thread, other threads:[~2024-11-13 08:10 UTC | newest]
Thread overview: 4+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2024-11-06 21:58 Improved security for https://www.postgresql.org/docs/current/install-make.html PG Doc comments form <noreply@postgresql.org>
2024-11-11 15:32 ` Peter Eisentraut <peter@eisentraut.org>
2024-11-12 21:50 ` Bear Giles <bgiles@coyotesong.com>
2024-11-13 08:10 ` Peter Eisentraut <peter@eisentraut.org>
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox