agora inbox for pgsql-docs@postgresql.org  
help / color / mirror / Atom feed
From: Peter Eisentraut <peter@eisentraut.org>
To: bgiles@coyotesong.com
To: pgsql-docs@lists.postgresql.org
Subject: Re: Improved security for https://www.postgresql.org/docs/current/install-make.html
Date: Mon, 11 Nov 2024 16:32:55 +0100
Message-ID: <19968047-83d1-4582-af56-cf4ddfc25c2e@eisentraut.org> (raw)
In-Reply-To: <173093029303.708.7136095929535895689@wrigleys.postgresql.org>
References: <173093029303.708.7136095929535895689@wrigleys.postgresql.org>

On 06.11.24 22:58, PG Doc comments form wrote:
> The 'short' script can then be rewritten as
> 
> ```
> # work done as a regular user
> ./configure
> make build
> 
> # work that requires ROOT access
> su
> mkdir /usr/local/pgsql/data
> chown (current user):(current group) /usr/local/pgsql
> adduser --system --group postgres
> exit
> 
> # work that requires POSTGRES access
> su -u postgres
> make install installdirs
> exit

We don't want the installed files to be owned by postgres.  That would 
mean that a compromised PostgreSQL server (running as "postgres") could 
overwrite its own installation files.  You don't have to use "root" for 
the installation, of course, but it should be separate from "postgres".






view thread (4+ messages)  latest in thread

Message-ID: <19968047-83d1-4582-af56-cf4ddfc25c2e@eisentraut.org>
Permalink:  ../19968047-83d1-4582-af56-cf4ddfc25c2e@eisentraut.org/
Also on:    postgresql.org/message-id/19968047-83d1-4582-af56-cf4ddfc25c2e@eisentraut.org

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-docs@postgresql.org
  Cc: peter@eisentraut.org, bgiles@coyotesong.com, pgsql-docs@lists.postgresql.org
  Subject: Re: Improved security for https://www.postgresql.org/docs/current/install-make.html
  In-Reply-To: <19968047-83d1-4582-af56-cf4ddfc25c2e@eisentraut.org>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox