Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tAWPZ-00GDaA-SJ for pgsql-docs@arkaria.postgresql.org; Mon, 11 Nov 2024 15:33:05 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1tAWPX-00FP6B-9D for pgsql-docs@arkaria.postgresql.org; Mon, 11 Nov 2024 15:33:03 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tAWPV-00FP4k-JI for pgsql-docs@lists.postgresql.org; Mon, 11 Nov 2024 15:33:03 +0000 Received: from fhigh-b2-smtp.messagingengine.com ([202.12.124.153]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1tAWPT-001KUV-8d for pgsql-docs@lists.postgresql.org; Mon, 11 Nov 2024 15:33:00 +0000 Received: from phl-compute-10.internal (phl-compute-10.phl.internal [10.202.2.50]) by mailfhigh.stl.internal (Postfix) with ESMTP id E121525400F5; Mon, 11 Nov 2024 10:32:57 -0500 (EST) Received: from phl-mailfrontend-01 ([10.202.2.162]) by phl-compute-10.internal (MEProxy); Mon, 11 Nov 2024 10:32:57 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=eisentraut.org; h=cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm2; t=1731339177; x=1731425577; bh=v62IZE0iZkYrqar9kVMrQtOuBU2N0xmpeviP0+lmC+Q=; b= JE4nxPnNjpnJzKLjzrN8WKvawOjX+vmeS4OWF0XfxjbpKsjJZllYhga/rkFep+ML pADczm6U4CxkkjHTFIkz9DUGiirVZe9WvLgb7Boi9I78DJadZViDA6OJu/UzS1ta 7jKUbeFL3ixClJhmSabpggB6Vb5DIaM5Re4JC8h8IT+2k40IMumfsGonMetFXsHE N9H6wjzRlUPf79YTig7ALha57JSGG+/6CTutkKgweOI4pxRcdm3DLoRN958Zk80J j5wXOiPjqIdY/sQSP3rp1PonYsUQ50LENBJolS/ithJdoCMrA4hGV8nAUsLfi0JR 7NHArd2/nUjj7Id4Iq5tFQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm3; t=1731339177; x=1731425577; bh=v 62IZE0iZkYrqar9kVMrQtOuBU2N0xmpeviP0+lmC+Q=; b=CtkXuv7zlrGwr51ut nlBu+VPSOb2S8HZV/mE6jdgY+wam6bsz7v9biZ4TS0jJtmlSw42EOuR4Th/B8rzG m/r67Vx5HcPxc+1YxKS+woMZNzIsqOuUsrfOYFaWhk1u+RsRI9/hzmQywMbLS8/6 IYZPsOo3SN/9LvpMoEuehojcWtVGFnVQ6JHD8shgQYnijqjT40Di+RkUTD0UN8pL CpNeMIiKsvWDJ5SH8wjx2s3uS6BD/q/IMTCS4gc2deUbNM0pkt/jl+xmzbXESuhI uPj9T2s4kCTSsYLNN2vn6392DJHvFpPU2mdQjsrkl4nnecFI1iyH/eSr/27Pcs2L ma+pQ== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefuddruddvgdejjecutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpggftfghnshhusghstghrihgsvgdpuffr tefokffrpgfnqfghnecuuegrihhlohhuthemuceftddtnecunecujfgurhepkfffgggfuf fvfhfhjggtgfesthejredttddvjeenucfhrhhomheprfgvthgvrhcugfhishgvnhhtrhgr uhhtuceophgvthgvrhesvghishgvnhhtrhgruhhtrdhorhhgqeenucggtffrrghtthgvrh hnpeegueeuvdfhheeuieejtefguddthfevveefuefgtddvgfetteehjeetleeuvdevuden ucffohhmrghinhepphhoshhtghhrvghsqhhlrdhorhhgnecuvehluhhsthgvrhfuihiivg eptdenucfrrghrrghmpehmrghilhhfrhhomhepphgvthgvrhesvghishgvnhhtrhgruhht rdhorhhgpdhnsggprhgtphhtthhopedvpdhmohguvgepshhmthhpohhuthdprhgtphhtth hopegsghhilhgvshestghohihothgvshhonhhgrdgtohhmpdhrtghpthhtohepphhgshhq lhdqughotghssehlihhsthhsrdhpohhsthhgrhgvshhqlhdrohhrgh X-ME-Proxy: Feedback-ID: ie0a040ee:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 11 Nov 2024 10:32:56 -0500 (EST) Message-ID: <19968047-83d1-4582-af56-cf4ddfc25c2e@eisentraut.org> Date: Mon, 11 Nov 2024 16:32:55 +0100 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: Improved security for https://www.postgresql.org/docs/current/install-make.html To: bgiles@coyotesong.com, pgsql-docs@lists.postgresql.org References: <173093029303.708.7136095929535895689@wrigleys.postgresql.org> Content-Language: en-US From: Peter Eisentraut In-Reply-To: <173093029303.708.7136095929535895689@wrigleys.postgresql.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk On 06.11.24 22:58, PG Doc comments form wrote: > The 'short' script can then be rewritten as > > ``` > # work done as a regular user > ./configure > make build > > # work that requires ROOT access > su > mkdir /usr/local/pgsql/data > chown (current user):(current group) /usr/local/pgsql > adduser --system --group postgres > exit > > # work that requires POSTGRES access > su -u postgres > make install installdirs > exit We don't want the installed files to be owned by postgres. That would mean that a compromised PostgreSQL server (running as "postgres") could overwrite its own installation files. You don't have to use "root" for the installation, of course, but it should be separate from "postgres".