Ensure Postgres data directories have group-read permission #4227
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Postgres has allowed group-read on its data directories since v11. This permission enables more avenues for data recovery when storage misbehaves.
🙇🏻 This includes some unrelated fixes and improvements to the test suite.
Checklist:
Type of Changes:
What is the current behavior (link to any open issues here)?
PGO sets permissions on Postgres directories to
0700
after which Postgres creates files and directories with zero group permissions,g-rwx
.What is the new behavior (if this is a feature change)?
PGO sets permissions on these directories to
0750
, the most liberal allowed by Postgres. With that, Postgres creates files and directories with group-read,g+rx
. This group access allows:Other Information:
Issue: PGO-300