Re: [ADMIN] postgresql in FreeBSD jails: proposal

From: Stephen Frost <sfrost(at)snowman(dot)net>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: "Marc G(dot) Fournier" <scrappy(at)hub(dot)org>, pgsql-hackers(at)postgreSQL(dot)org
Subject: Re: [ADMIN] postgresql in FreeBSD jails: proposal
Date: 2008-01-17 14:37:29
Message-ID: 20080117143729.GR5031@tamriel.snowman.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-admin pgsql-bugs pgsql-committers pgsql-general pgsql-hackers pgsql-jdbc pgsql-odbc pgsql-patches

* Tom Lane (tgl(at)sss(dot)pgh(dot)pa(dot)us) wrote:
> "Marc G. Fournier" <scrappy(at)hub(dot)org> writes:
> > Easiest fix: change the UID of the user running the postmaster (ie. pgsql) so
> > that each runs as a distinct UID (instead of distinct PGPORT) ... been doing
> > this since moving to FreeBSD 6.x ... no patches required ...
>
> Sure, but in the spirit of "belt and suspenders too", I'd think that
> doing that *and* something like Mischa's proposal wouldn't be bad.

I agree that we should try to be careful about stepping on segments that
might still be in use, but I would also discourage jail users from using
the same uid for multiple PG clusters since the jail doesn't protect the
shmem segment. We use seperate uids even w/ linux-vservers where shmem
and everything *is* seperate, following the same 'belt and suspenders
too' spirit for security.

Thanks,

Stephen

In response to

Responses

Browse pgsql-admin by date

  From Date Subject
Next Message Milen A. Radev 2008-01-17 15:15:30 Re: select only user
Previous Message Jessica Richard 2008-01-17 14:30:37 select only user

Browse pgsql-bugs by date

  From Date Subject
Next Message Jan Mate 2008-01-17 15:44:32 BUG #3882: unexpected PARAM_SUBLINK ID
Previous Message Dave Page 2008-01-17 13:58:36 Re: [ADMIN] postgresql in FreeBSD jails: proposal

Browse pgsql-committers by date

  From Date Subject
Next Message Bruce Momjian 2008-01-17 18:53:20 pgsql: Update Japanese FAQ.
Previous Message Magnus Hagander 2008-01-17 14:34:45 pgsql: Typo fix.

Browse pgsql-general by date

  From Date Subject
Next Message James B. Byrne 2008-01-17 15:05:24 Re: Help with pre-loaded arbitrary key sequences
Previous Message Sim Zacks 2008-01-17 14:27:50 Re: Don't cascade drop to view

Browse pgsql-hackers by date

  From Date Subject
Next Message Pavel Stehule 2008-01-17 15:01:18 proposal for 8.4: PL/pgSQL - statement CASE
Previous Message Dave Page 2008-01-17 13:58:36 Re: [ADMIN] postgresql in FreeBSD jails: proposal

Browse pgsql-jdbc by date

  From Date Subject
Next Message Albe Laurenz 2008-01-17 15:46:26 Re: trying to connect to pg from within a local network
Previous Message Dave Page 2008-01-17 13:58:36 Re: [ADMIN] postgresql in FreeBSD jails: proposal

Browse pgsql-odbc by date

  From Date Subject
Next Message Benjamin Krajmalnik 2008-01-17 17:49:01 FW: [ADMIN] Strange client encoding issue
Previous Message Dave Page 2008-01-17 13:58:36 Re: [ADMIN] postgresql in FreeBSD jails: proposal

Browse pgsql-patches by date

  From Date Subject
Next Message Bruce Momjian 2008-01-17 16:10:47 Re: [HACKERS] SSL over Unix-domain sockets
Previous Message Dave Page 2008-01-17 13:58:36 Re: [ADMIN] postgresql in FreeBSD jails: proposal