3 ms·
Apologies - I was thinking of ALTER SYSTEM [1]. That writes to postgresql.auto.conf. It sounds like that file has priority over postgresql.conf [2]. You might w
by yangyang 12y ago
Apologies - I was thinking of ALTER SYSTEM [1]. That writes to postgresql.auto.conf. It sounds like that file has priority over postgresql.conf [2]. You might well be able to just prevent writes by the postgres user (or whatever user you're running postgres as).
Regarding superusers overwriting files - COPY can write to anywhere on the filesystem. From the docs "COPY naming a file is only allowed to database superusers, since it allows reading or writing any file that the server has privileges to access." [3].
[1] http://www.postgresql.org/docs/9.4/static/sql-altersystem.html http://www.postgresql.org/docs/9.4/static/sql-altersystem.ht...
[2] http://michael.otacoo.com/postgresql-2/postgres-9-4-feature-highlight-alter-system-set-for-dynamic-configuration/ http://michael.otacoo.com/postgresql-2/postgres-9-4-feature-...
[3] http://www.postgresql.org/docs/current/static/sql-copy.html http://www.postgresql.org/docs/current/static/sql-copy.html
- yangyang 12y agoAlso, if you have any untrusted PLs available, a superuser can create one of those and do what they like.