Re: Restricting permissions on Unix socket

Поиск
Список
Период
Сортировка
От Robert Kernell
Тема Re: Restricting permissions on Unix socket
Дата
Msg-id 200010312136.QAA12773@sundog.larc.nasa.gov
обсуждение исходный текст
Ответ на Restricting permissions on Unix socket  (Peter Eisentraut <peter_e@gmx.net>)
Список pgsql-hackers
> I'd like to add an option or two to restrict the set of users that can
> connect to the Unix domain socket of the postmaster, as an extra security
> option.
> 
> I imagine something like this:
> 
> unix_socket_perm = 0660
> unix_socket_group = pgusers
> 
> Obviously, permissions that don't have 6's in there don't make much sense,
> but I feel this notation is the most intuitive way for admins.
> 
> I'm not sure how to do the group thing, though.  If I use chown(2) then
> there's a race condition, but doing savegid; create socket; restoregid
> might be too awkward?  Any hints?
> 

Just curious. What is a race condition? 

Bob Kernell
Research Scientist
Surface Validation Group
Atmospheric Sciences Competency
Analytical Services & Materials, Inc.
email: kernell@sundog.larc.nasa.gov
tel: 757-827-4631



В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Mikheev, Vadim"
Дата:
Сообщение: RE: WAL status update
Следующее
От: "Jones, Colin"
Дата:
Сообщение: RE: Restricting permissions on Unix socket