agora inbox for pgsql-docs@postgresql.org  
help / color / mirror / Atom feed
Improved security for https://www.postgresql.org/docs/current/install-make.html
4+ messages / 3 participants
[nested] [flat]

* Improved security for https://www.postgresql.org/docs/current/install-make.html
@ 2024-11-06 21:58 PG Doc comments form <noreply@postgresql.org>
  2024-11-11 15:32 ` Re: Improved security for https://www.postgresql.org/docs/current/install-make.html Peter Eisentraut <peter@eisentraut.org>
  0 siblings, 1 reply; 4+ messages in thread

From: PG Doc comments form @ 2024-11-06 21:58 UTC (permalink / raw)
  To: pgsql-docs@lists.postgresql.org; +Cc: bgiles@coyotesong.com

The following documentation comment has been logged on the website:

Page: https://www.postgresql.org/docs/17/install-make.html
Description:

The current 'short' version is

```
./configure
make
su
make install
adduser postgres
mkdir -p /usr/local/pgsql/data
chown postgres /usr/local/pgsql/data
su - postgres
/usr/local/pgsql/bin/initdb -D /usr/local/pgsql/data
/usr/local/pgsql/bin/pg_ctl -D /usr/local/pgsql/data -l logfile start
/usr/local/pgsql/bin/createdb test
/usr/local/pgsql/bin/psql test
```

The security could be improved by limiting the amount of work that is done
as root. (sudo make 
install -- shudder!)

First, split `make install` so `make build` gets as far as building the
libraries **under the current directory**, not on location in the start
directory.

Second, verify that `make install` does nothing but create directories and
copy files into them. It can probably also include the tasks currently done
by `make installdir` but the latter might still be required by some external
process. This target should be reviewed by security experts.

The 'short' script can then be rewritten as

```
# work done as a regular user
./configure
make build

# work that requires ROOT access
su
mkdir /usr/local/pgsql/data
chown (current user):(current group) /usr/local/pgsql
adduser --system --group postgres
exit

# work that requires POSTGRES access
su -u postgres
make install installdirs
exit

# work that requires ROOT access
su
adduser --system --group postgres
chown -R postgres:postgres /usr/local/pgsql
exit

# work that requires POSTGRES access
su - postgres
/usr/local/pgsql/bin/initdb -D /usr/local/pgsql/data
/usr/local/pgsql/bin/pg_ctl -D /usr/local/pgsql/data -l logfile start
/usr/local/pgsql/bin/createdb test
/usr/local/pgsql/bin/psql test
exit
```


^ permalink  raw  reply  [nested|flat] 4+ messages in thread

* Re: Improved security for https://www.postgresql.org/docs/current/install-make.html
  2024-11-06 21:58 Improved security for https://www.postgresql.org/docs/current/install-make.html PG Doc comments form <noreply@postgresql.org>
@ 2024-11-11 15:32 ` Peter Eisentraut <peter@eisentraut.org>
  2024-11-12 21:50   ` Re: Improved security for https://www.postgresql.org/docs/current/install-make.html Bear Giles <bgiles@coyotesong.com>
  0 siblings, 1 reply; 4+ messages in thread

From: Peter Eisentraut @ 2024-11-11 15:32 UTC (permalink / raw)
  To: bgiles@coyotesong.com; pgsql-docs@lists.postgresql.org

On 06.11.24 22:58, PG Doc comments form wrote:
> The 'short' script can then be rewritten as
> 
> ```
> # work done as a regular user
> ./configure
> make build
> 
> # work that requires ROOT access
> su
> mkdir /usr/local/pgsql/data
> chown (current user):(current group) /usr/local/pgsql
> adduser --system --group postgres
> exit
> 
> # work that requires POSTGRES access
> su -u postgres
> make install installdirs
> exit

We don't want the installed files to be owned by postgres.  That would 
mean that a compromised PostgreSQL server (running as "postgres") could 
overwrite its own installation files.  You don't have to use "root" for 
the installation, of course, but it should be separate from "postgres".






^ permalink  raw  reply  [nested|flat] 4+ messages in thread

* Re: Improved security for https://www.postgresql.org/docs/current/install-make.html
  2024-11-06 21:58 Improved security for https://www.postgresql.org/docs/current/install-make.html PG Doc comments form <noreply@postgresql.org>
  2024-11-11 15:32 ` Re: Improved security for https://www.postgresql.org/docs/current/install-make.html Peter Eisentraut <peter@eisentraut.org>
@ 2024-11-12 21:50   ` Bear Giles <bgiles@coyotesong.com>
  2024-11-13 08:10     ` Re: Improved security for https://www.postgresql.org/docs/current/install-make.html Peter Eisentraut <peter@eisentraut.org>
  0 siblings, 1 reply; 4+ messages in thread

From: Bear Giles @ 2024-11-12 21:50 UTC (permalink / raw)
  To: Peter Eisentraut <peter@eisentraut.org>; +Cc: pgsql-docs@lists.postgresql.org

You'll want to update the existing page then! :-)

My point was mostly that I did a fresh 'git clone', followed the
instructions, and was immediately hit by a "permission denied" error
because the make script tried to create a directory under /usr/local. It
wasn't clear whether that was the only thing that required root access. The
script I provided was one approach, but it can be greatly simplified if all
that's required is creating the directory and chancing its ownership prior
to running the 'make install'.

(I still think it's a Good Idea to separate compilation and
deployment/'installation but that's a separate issue.)

Bear

On Mon, Nov 11, 2024 at 8:32 AM Peter Eisentraut <peter@eisentraut.org>
wrote:

> On 06.11.24 22:58, PG Doc comments form wrote:
> > The 'short' script can then be rewritten as
> >
> > ```
> > # work done as a regular user
> > ./configure
> > make build
> >
> > # work that requires ROOT access
> > su
> > mkdir /usr/local/pgsql/data
> > chown (current user):(current group) /usr/local/pgsql
> > adduser --system --group postgres
> > exit
> >
> > # work that requires POSTGRES access
> > su -u postgres
> > make install installdirs
> > exit
>
> We don't want the installed files to be owned by postgres.  That would
> mean that a compromised PostgreSQL server (running as "postgres") could
> overwrite its own installation files.  You don't have to use "root" for
> the installation, of course, but it should be separate from "postgres".
>
>

^ permalink  raw  reply  [nested|flat] 4+ messages in thread

* Re: Improved security for https://www.postgresql.org/docs/current/install-make.html
  2024-11-06 21:58 Improved security for https://www.postgresql.org/docs/current/install-make.html PG Doc comments form <noreply@postgresql.org>
  2024-11-11 15:32 ` Re: Improved security for https://www.postgresql.org/docs/current/install-make.html Peter Eisentraut <peter@eisentraut.org>
  2024-11-12 21:50   ` Re: Improved security for https://www.postgresql.org/docs/current/install-make.html Bear Giles <bgiles@coyotesong.com>
@ 2024-11-13 08:10     ` Peter Eisentraut <peter@eisentraut.org>
  0 siblings, 0 replies; 4+ messages in thread

From: Peter Eisentraut @ 2024-11-13 08:10 UTC (permalink / raw)
  To: Bear Giles <bgiles@coyotesong.com>; +Cc: pgsql-docs@lists.postgresql.org

On 12.11.24 22:50, Bear Giles wrote:
> My point was mostly that I did a fresh 'git clone', followed the 
> instructions, and was immediately hit by a "permission denied" error 
> because the make script tried to create a directory under /usr/local. It 
> wasn't clear whether that was the only thing that required root access. 

Please provide a precise description of what steps you did and what the 
result or output from each was.  This report is not clear enough to be 
actionable.  As far as I can tell, the existing instructions are sound 
for a typical use, so it's not clear where your situation diverged.






^ permalink  raw  reply  [nested|flat] 4+ messages in thread


end of thread, other threads:[~2024-11-13 08:10 UTC | newest]

Thread overview: 4+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2024-11-06 21:58 Improved security for https://www.postgresql.org/docs/current/install-make.html PG Doc comments form <noreply@postgresql.org>
2024-11-11 15:32 ` Peter Eisentraut <peter@eisentraut.org>
2024-11-12 21:50   ` Bear Giles <bgiles@coyotesong.com>
2024-11-13 08:10     ` Peter Eisentraut <peter@eisentraut.org>

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox