Re: pgsql: Prevent running pg_basebackup as root

From: Ian Barwick <ian(dot)barwick(at)2ndquadrant(dot)com>
To: Andres Freund <andres(at)anarazel(dot)de>, Magnus Hagander <magnus(at)hagander(dot)net>
Cc: Michael Paquier <michael(at)paquier(dot)xyz>, Stephen Frost <sfrost(at)snowman(dot)net>, pgsql-committers <pgsql-committers(at)lists(dot)postgresql(dot)org>
Subject: Re: pgsql: Prevent running pg_basebackup as root
Date: 2020-02-07 02:23:56
Message-ID: 31687170-2e93-0f2c-aca1-974db69460ea@2ndquadrant.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-committers pgsql-hackers

On 2020/02/07 11:07, Andres Freund wrote:
> Hi,
>
> On 2020-02-06 13:02:07 +0100, Magnus Hagander wrote:
>> I agree with Stephen that this seems to be misguided, and my vote is
>> to revert.
>
> +1. I honestly don't think we should increase the number of "root
> disallowed" tools unless actually necessary.
>
> Maybe that's looking too far into the future, but I'd like to see
> improvements to pg_basebackup that make it integrate with root requiring
> tooling, to do more efficient base backups. E.g. having pg_basebackup
> handle start/stop backup and WAL handling, but do the actual backup of
> the data via a snapshot mechanism (yes, one needs start/stop backup in
> the general case, for multiple FSs), would be nice.
>
> Btw, I think it's good form in a discussion like this to CC the original
> author. I'll also add a reference to this discussion from the -hackers
> thread.

Thanks for the notification.

Points raised upthread seem reasonable enough; to be honest I was expecting
this patch to hang around a bit longer anway, because (as so often) there's
some aspect which wouldn't have occurred to me.

Regards

Ian Barwick

--
Ian Barwick https://www.2ndQuadrant.com/
PostgreSQL Development, 24x7 Support, Training & Services

In response to

Browse pgsql-committers by date

  From Date Subject
Next Message Michael Paquier 2020-02-07 03:42:31 pgsql: Fix typo in proc.c
Previous Message Andres Freund 2020-02-07 02:07:02 Re: pgsql: Prevent running pg_basebackup as root

Browse pgsql-hackers by date

  From Date Subject
Next Message Andres Freund 2020-02-07 02:36:00 Re: Internal key management system
Previous Message Masahiko Sawada 2020-02-07 02:18:29 Re: Internal key management system