-
Notifications
You must be signed in to change notification settings - Fork 27
[DPE-7584] Fix temp tablespace permissions #1137
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -20,6 +20,8 @@ | |
| """ | ||
|
|
||
| import logging | ||
| import os | ||
| import pwd | ||
| from collections import OrderedDict | ||
| from typing import Dict, List, Optional, Set, Tuple | ||
|
|
||
|
|
@@ -1058,6 +1060,11 @@ def set_up_database(self, temp_location: Optional[str] = None) -> None: | |
| cursor = connection.cursor() | ||
|
|
||
| if temp_location is not None: | ||
| # Fix permissions on the temporary tablespace location when a reboot happens and tmpfs is being used. | ||
| user = pwd.getpwnam("_daemon_") | ||
| os.chown(temp_location, uid=user.pw_uid, gid=user.pw_gid) | ||
| os.chmod(temp_location, 0o700) | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Also, it is 750 there Are we consistent? There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Good catch. I'm checking and testing a consistent approach in all the places where the permissions are specific. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. We'll need to change it to 700 everywhere, to be consistent. As we're always accessing the directories as the owner, there is no need to have permissions for the group to access them. |
||
|
|
||
| cursor.execute("SELECT TRUE FROM pg_tablespace WHERE spcname='temp';") | ||
| if cursor.fetchone() is None: | ||
| cursor.execute(f"CREATE TABLESPACE temp LOCATION '{temp_location}';") | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Should _change_owner() be moved to lib and used to avoid duplicates?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I believe it's a good idea. I'd change it a bit and create a different Python file (and also move it to the single kernel library repo) to contain utilities related to the filesystem, and keep this library containing only things related to the database connection and interaction.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I moved the
_change_owner()function to the single kernel lib on canonical/postgresql-single-kernel-library#10.