permissions and owners of raw devices
Posted in 2006
Malcolm asked why an AIX 5.2 / IDS 9.40.UC4 instance runs fine with raw character devices owned by root:system at 660 instead of informix:informix, and whether this would break on reboot or upgrade. Replies explained it can work because the engine (started by root) keeps root privileges in the I/O VPs, so permission checks are effectively bypassed, but it's unreliable: wrong ownership can cause chunks to be marked offline or initialisation to fail. The consensus advice was to set devices to informix:informix with exactly 660 (and watch $INFORMIXDIR permissions too), since newer versions are stricter.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Storage & Space Management, Platform-Specific Issues, Versions, Editions & End-of-Life
I am sure I am going to get hundreds of answers telling me this can't work but I have a system that has been working for months with raw devices owned by root and group system. The permissions are 660 and they are using the character device. The platform is AIX 5.2 with IDS 9.40.UC4. I discovered this when the system complained about the ownership of raw devices used by temp dbspaces. My real concern is that we might encounter problems when rebooting or when converting to a new release. regards Malcolm
mweallans@panacea.co.uk wrote: > I am sure I am going to get hundreds of answers telling me this can't > work but I have a system that has been working for months with raw > devices owned by root and group system. The permissions are 660 and > they are using the character device. > The platform is AIX 5.2 with IDS 9.40.UC4. > I discovered this when the system complained about the ownership of raw > devices used by temp dbspaces. Speaking from a Linux perspective, it's possible to be _running_ but not start the system with raw devices owned by users and groups other than informix. I guess in your case that user 'informix' is not a member of group 'group', I'm not sure what happens in this case since it would seem that you ought not have access. Do access rights apply from when the raw device was opened, I wonder? This problem also occurs on SUSE where raw devices are owned by root, group disk, permissions 660. > My real concern is that we might encounter problems when rebooting or > when converting to a new release. If rootdbs is owned by other users and groups the initialisation of the engine will just fail. If the problem afflicts some chunks and not rootdbs the engine may decide any affected chunks are bad and take them off-line. So you do need to be careful. Surely the simple answer is to change the device ownership and permissions just before you start IDS? Do you have a script for this? Ben.
Was the engine started by user 'root'?
mweallans@panacea.co.uk said:
> I am sure I am going to get hundreds of answers telling me this can't
> work but I have a system that has been working for months with raw
> devices owned by root and group system. The permissions are 660 and
> they are using the character device.
> The platform is AIX 5.2 with IDS 9.40.UC4.
> I discovered this when the system complained about the ownership of raw
> devices used by temp dbspaces.
>
> My real concern is that we might encounter problems when rebooting or
> when converting to a new release.
Depends on who owns oninit and so forth ... ;)
--
Bye now,
Obnoxio
"It's easier with pictures."
-- Cosmo
"But wait, it gets worse."
-- Cosmo
"Run, don't walk, for the nearest exit."
-- Cosmo
I suspect the engine was last started by root as it was an automatic
startup following an outage for hardware replacement.
And oninit is owned by root:informix
Would the ownership of the raw devices give me problems if I started
oninit from informix then?
regards
Malcolm
"Obnoxio The Clown" <obnoxio@serendipita.com> wrote in message
news:mailman.141.1142958937.18205.informix-list@iiug.org...
>
> mweallans@panacea.co.uk said:
>> I am sure I am going to get hundreds of answers telling me this can't
>> work but I have a system that has been working for months with raw
>> devices owned by root and group system. The permissions are 660 and
>> they are using the character device.
>> The platform is AIX 5.2 with IDS 9.40.UC4.
>> I discovered this when the system complained about the ownership of raw
>> devices used by temp dbspaces.
>>
>> My real concern is that we might encounter problems when rebooting or
>> when converting to a new release.
>
> Depends on who owns oninit and so forth ... ;)
It's Paul Watson, isn't it?
Neil Truby said:
> "Obnoxio The Clown" <obnoxio@serendipita.com> wrote in message
> news:mailman.141.1142958937.18205.informix-list@iiug.org...
>>
>> mweallans@panacea.co.uk said:
>>> I am sure I am going to get hundreds of answers telling me this can't
>>> work but I have a system that has been working for months with raw
>>> devices owned by root and group system. The permissions are 660 and
>>> they are using the character device.
>>> The platform is AIX 5.2 with IDS 9.40.UC4.
>>> I discovered this when the system complained about the ownership of raw
>>> devices used by temp dbspaces.
>>>
>>> My real concern is that we might encounter problems when rebooting or
>>> when converting to a new release.
>>
>> Depends on who owns oninit and so forth ... ;)
>
> It's Paul Watson, isn't it?
Ha.
Ha.
Ha.
--
Bye now,
Obnoxio
"It's easier with pictures."
-- Cosmo
"But wait, it gets worse."
-- Cosmo
"Run, don't walk, for the nearest exit."
-- Cosmo
mweallans@panacea.co.uk wrote: > I am sure I am going to get hundreds of answers telling me this can't > work but I have a system that has been working for months with raw > devices owned by root and group system. The permissions are 660 and > they are using the character device. > The platform is AIX 5.2 with IDS 9.40.UC4. > I discovered this when the system complained about the ownership of raw > devices used by temp dbspaces. As others have commented, you can get away with a number of mismatches between the owner, group and permissions - primarily because the xIO VPs retain their root privileges, even if the CPU VPs set their privileges to user informix. And root-owned processes can do what they like. > My real concern is that we might encounter problems when rebooting or > when converting to a new release. Yes; you can expect problems in the future - it would be as well to ensure the correct permissions: user informix, group informix, exactly 660 privileges on the files. At the moment, you may get away with other permissions (though I must confess I thought 9.40.UC4 was already a bit more stringent than that); do not rely on doing so. There's a similar issue with $INFORMIXDIR permissions; old versions used to permit sloppy permissions, but newer versions do not. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/
I'm running AIX as well. I have always had the raw devices created with an informix.informix ownership. When we were on 7.31 it didn't mind so much about the ownership as long as the mode was open enough for IDS to read and write. When IDS is started by root 600 will get it done. After upgrading to AIX 5.3 and IDS 9.4-FC6 I noticed that IDS is much more picky about ownership and mode. Not just the chunks but also $INFORMIXDIR.