Re: That mode-700 check on DATADIR again

2017-12-13 Thread David Steele
On 12/11/17 9:41 PM, Chapman Flack wrote: I have, more or less, this classic question: https://www.postgresql.org/message-id/4667C403.1070807%40t3go.de However, when you stat a file with a POSIX ACL, you get shown the ACL's 'mask' entry (essentially the ceiling of all the 'extra' ACL entrie

Re: That mode-700 check on DATADIR again

2017-12-11 Thread Stephen Frost
Greetings Chapman, * Chapman Flack (c...@anastigmatix.net) wrote: > I have, more or less, this classic question: > > https://www.postgresql.org/message-id/4667C403.1070807%40t3go.de [...] > So, it seems there's at least one use case where some kind of > no_really_the_datadir_permissions_are_fin

That mode-700 check on DATADIR again

2017-12-11 Thread Chapman Flack
I have, more or less, this classic question: https://www.postgresql.org/message-id/4667C403.1070807%40t3go.de But I have it for a newer reason, where again it seems as if a better answer than "don't do that" might be worth having. 1. Suppose you are running PG in a VM (named pgvm just for exposi