3 ms·
OK, that sounds fair enough. Just interested in whether you'll be running a patched Postgres to be honest :-). There is of course set_config in 9.4 - superuser
by yangyang 12y ago
OK, that sounds fair enough. Just interested in whether you'll be running a patched Postgres to be honest :-).
There is of course set_config in 9.4 - superusers can then edit the config file through that (a superuser can overwrite any file the user running the server can write to anyway, but through more convoluted means).
- pjlegato 12y agoInteresting. My reading of the 9.4 docs[1][2] is that set_config can't be used to change one-off settings that require a server restart, such as wal_level. It also doesn't seem to be able to change the config file at all. Is there some way to do that? I'd also like to know more about how superusers can overwrite files. Do you have a link? [1] http://www.postgresql.org/docs/9.4/static/functions-admin.html http://www.postgresql.org/docs/9.4/static/functions-admin.ht... [2] http://www.postgresql.org/docs/9.4/static/runtime-config-wal.html http://www.postgresql.org/docs/9.4/static/runtime-config-wal...
- yangyang 12y agoApologies - I was thinking of ALTER SYSTEM [1]. That writes to postgresql.auto.conf. It sounds like that file has priority over postgresql.conf [2]. You might well be able to just prevent writes by the postgres user (or whatever user you're running postgres as). Regarding superusers overwriting files - COPY can write to anywhere on the filesystem. From the docs "COPY naming a file is only allowed to database superusers, since it allows reading or writing any file that the server has privileges to access." [3]. [1] http://www.postgresql.org/docs/9.4/static/sql-altersystem.html http://www.postgresql.org/docs/9.4/static/sql-altersystem.ht... [2] http://michael.otacoo.com/postgresql-2/postgres-9-4-feature-highlight-alter-system-set-for-dynamic-configuration/ http://michael.otacoo.com/postgresql-2/postgres-9-4-feature-... [3] http://www.postgresql.org/docs/current/static/sql-copy.html http://www.postgresql.org/docs/current/static/sql-copy.html
- yangyang 12y agoAlso, if you have any untrusted PLs available, a superuser can create one of those and do what they like.