mirror of
https://github.com/postgres/postgres.git
synced 2025-07-21 16:02:15 +03:00
Add documentation about running postmasters in FreeBSD jails (use
separate users).
This commit is contained in:
@ -1,5 +1,5 @@
|
||||
<!--
|
||||
$PostgreSQL: pgsql/doc/src/sgml/runtime.sgml,v 1.357.2.1 2006/03/02 20:30:33 momjian Exp $
|
||||
$PostgreSQL: pgsql/doc/src/sgml/runtime.sgml,v 1.357.2.2 2006/04/11 19:28:03 momjian Exp $
|
||||
-->
|
||||
|
||||
<chapter Id="runtime">
|
||||
@ -766,6 +766,18 @@ options "SEMMNS=240"
|
||||
setting <literal>kern.ipc.shm_use_phys</literal>.
|
||||
</para>
|
||||
|
||||
<para>
|
||||
If running in FreeBSD jails by enabling <application>sysconf</>'s
|
||||
<literal>security.jail.sysvipc_allowed</>, <application>postmaster</>s
|
||||
running in different jails should be run by different operating system
|
||||
users. This improves security because it prevents one jail from
|
||||
interfering with shared memory or semaphores in another, and it
|
||||
allows the PostgreSQL IPC cleanup code to function properly.
|
||||
(In FreeBSD 6.0 and later the IPC cleanup code doesn't properly detect
|
||||
processes in other jails, preventing the running of postmasters on the
|
||||
same port in different jails.)
|
||||
</para>
|
||||
|
||||
<para>
|
||||
<systemitem class="osname">FreeBSD</> versions before 4.0 work like
|
||||
<systemitem class="osname">NetBSD</> and <systemitem class="osname">
|
||||
|
Reference in New Issue
Block a user