Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1t1B2g-00F3Jo-Lq for pgsql-docs@arkaria.postgresql.org; Wed, 16 Oct 2024 20:54:50 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1t1B2e-00AA5v-DM for pgsql-docs@arkaria.postgresql.org; Wed, 16 Oct 2024 20:54:48 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1t1B2e-00AA5m-5X for pgsql-docs@lists.postgresql.org; Wed, 16 Oct 2024 20:54:48 +0000 Received: from momjian.us ([72.94.173.45]) by makus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1t1B2b-001F95-L9 for pgsql-docs@lists.postgresql.org; Wed, 16 Oct 2024 20:54:47 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=momjian.us; s=2024011501; h=In-Reply-To:Content-Transfer-Encoding:Content-Type: MIME-Version:References:Message-ID:Subject:Cc:To:From:Date:Sender:Reply-To: Content-ID:Content-Description; bh=FhlJQC6BlrKHchOsHrIN+3y94BgAMZa8BvEUYLMM1j4=; b=aK2+Wri7KW8E4vWzwWjiRKtTSx pi1Xb91iMr1OwR7NbGvOV+9OZPfvARvDKK0NnQTXJdLia3l9MErI/+da/smbZqBk8M3WFWKUVndGx Y1dlLgVSA4qMwJC9yjIEJsZleGhU1EavFJAIJP8TYzW6IiZC3LFt/6w7NtJ8VAyh5cxRhPUvxoSVz 1BFTgfopZpEfgF5zcqS7ppq4A1W/pR2h7k3oqLuakzsz+xd/kwgGGgmnElemgaDxCXKqLrEYKsSvQ rvqzlaGUeKCdaVCvY5qAHNfaw80SkrD7quAw1+RcNxS95MTqf8KP06YjHD0pdHWIJHuvrsJdmdrtp DjYUkMwQ==; Received: from bruce by momjian.us with local (Exim 4.96) (envelope-from ) id 1t1B2Z-009RsC-0N; Wed, 16 Oct 2024 16:54:43 -0400 Date: Wed, 16 Oct 2024 16:54:43 -0400 From: Bruce Momjian To: "David G. Johnston" Cc: marc@msys.ch, pgsql-docs@lists.postgresql.org Subject: Re: Documentation of .pgpass for Unix is incomplete Message-ID: References: <172311029184.915368.14898011794686876553@wrigleys.postgresql.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="2KCFEcop39rxdjOr" Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk --2KCFEcop39rxdjOr Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit On Mon, Aug 19, 2024 at 05:42:33PM -0700, David G. Johnston wrote: > On Mon, Aug 19, 2024 at 5:06 PM Bruce Momjian wrote: > Well, it is more complicated than checking just HOME because it calls > getpwuid_r() if HOME is not set: > >         https://doxygen.postgresql.org/fe-connect_8c.html# > a3f49cbb20595c1765bd0db5ff434c9c3 > > Is it worth going into that detail in the docs? > > > > Yes, "the user's home directory" and the "HOME" environment variable are > distinct things.  The current docs are wrong. > > The .pgpass file, located in $HOME (a.k.a. ~) on non-Microsoft Windows systems, > can contain passwords...  In the absence of the HOME environment variable, the > path recorded as the user's home directory in the operating system's passwd > file will be checked.  This is not a fallback mechanism - if HOME is set, and > the file is not present there, this directory will not be checked).  On > Microsoft Windows... Alternatively, the password file to use ... > > I"m somewhat loath to repeat that in: > https://www.postgresql.org/docs/16/libpq-connect.html#LIBPQ-CONNECT-PASSFILE > > passfile > Specifies the name of the file used to store passwords (see Section 34.16). > Defaults to ~/.pgpass, or %APPDATA%\postgresql\pgpass.conf on Microsoft > Windows. (No error is reported if this file does not exist.) > > So I'd suggest just removing the talk of defaults, changing it to: > > "Specifies the name of the file used to store passwords.  See Section 34.16 for > details, including the default file name and path resolution mechanics." I have written the attached patch to add the home directory details. I specified in one place and referenced it to two others. Did I miss any places? -- Bruce Momjian https://momjian.us EDB https://enterprisedb.com When a patient asks the doctor, "Am I going to die?", he means "Am I going to die soon?" --2KCFEcop39rxdjOr Content-Type: text/x-diff; charset=us-ascii Content-Disposition: attachment; filename="home.diff" diff --git a/doc/src/sgml/libpq.sgml b/doc/src/sgml/libpq.sgml index afc9346757a..bfefb1289e8 100644 --- a/doc/src/sgml/libpq.sgml +++ b/doc/src/sgml/libpq.sgml @@ -9256,7 +9256,9 @@ myEventProc(PGEventId evtId, void *evtInfo, void *passThrough) The file .pgpass in a user's home directory can contain passwords to be used if the connection requires a password (and no password has been - specified otherwise). On Microsoft Windows the file is named + specified otherwise). On Unix systems, the directory can be specified by + the HOME environment variable, or if undefined, the home + directory of the effective user. On Microsoft Windows the file is named %APPDATA%\postgresql\pgpass.conf (where %APPDATA% refers to the Application Data subdirectory in the user's profile). diff --git a/doc/src/sgml/postgres-fdw.sgml b/doc/src/sgml/postgres-fdw.sgml index 627bb5ab5cc..188e8f0b4d0 100644 --- a/doc/src/sgml/postgres-fdw.sgml +++ b/doc/src/sgml/postgres-fdw.sgml @@ -194,7 +194,9 @@ OPTIONS (ADD password_required 'false'); user can potentially use any client certificates, .pgpass, .pg_service.conf etc. in the unix home directory of the - system user the postgres server runs as. They can also use any trust + system user the postgres server runs as. (For details on how home + directories are found, see .) They can + also use any trust relationship granted by authentication modes like peer or ident authentication. diff --git a/doc/src/sgml/ref/psql-ref.sgml b/doc/src/sgml/ref/psql-ref.sgml index b825ca96a23..e42073ed748 100644 --- a/doc/src/sgml/ref/psql-ref.sgml +++ b/doc/src/sgml/ref/psql-ref.sgml @@ -1048,7 +1048,8 @@ INSERT INTO tbls1 VALUES ($1, $2) \parse stmt1 Changes the current working directory to directory. Without argument, changes - to the current user's home directory. + to the current user's home directory. For details on how home + directories are found, see . --2KCFEcop39rxdjOr--