Locking in UFS
Posted in 2011
A user on Informix 11.5 under Solaris/UFS wanted Windows-style mandatory file locking so in-use chunk files couldn't be deleted or overwritten. The consensus: no such lock exists on Unix — file locking there is advisory, and the file owner can always remove a file. The practical advice was to set chunk permissions to informix:informix 660 (directories 770, path checked with onsecurity), keep nobody else in the informix group, or use raw devices (only symlinks can be deleted). Other tips: a wrapper rm script that refuses informix-owned files, dot-prefixed chunk names, and the note that an accidentally deleted chunk can still be backed up/restored while the engine holds the file open.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Storage & Space Management, Platform-Specific Issues
I want to implement the locking on UFS file system. Currently I am using informix 11.5 FC 7 on sun solaris using UFS file system. There is a problem that a chunk file of db space which is using by informix database can be updated or deleted by other than database process. So please guide me to prevent to overwrite and delete our database files when these are using by database.
On Sat, Feb 12, 2011 at 23:54, KHURRAM SHAHZAD <kshahzad02@i2cinc.com>wrote: > I want to implement the locking on UFS file system. > I don't think locking is what you're after. > Currently I am using informix 11.5 FC 7 on sun solaris using UFS file > system. > There is a problem that a chunk file of db space which is using by informix > database can be updated or deleted by other than database process. > > So please guide me to prevent to overwrite and delete our database files > when > these are using by database. > The permissions on the chunks should be informix:informix:660. Anything else is a mistake. The permissions on the directory containing the chunks should also be constrained - logically, the permissions are informix:informix:775 or more stringent, but the owner could be a trusted system user (root, bin, sys) and the group could be a trusted system group (root, bin, sys, wheel, admin; the list varies a bit depending on the o/s). The same should apply to all the directories leading to the chunk. You can check the security of chunks (and therefore of the directories containing chunks) with the onsecurity command. If you need recommendations on how to fix any problems it reports, use 'onsecurity -r /path/to/chunk/file'. Of course, allowing anyone other than user informix to belong to group informix is another mistake - one which is not unheard of. There is no fix for that other than removing everyone from group informix except user informix. Anyone who belongs to group informix can wreck the entire system. -- Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h> Guardian of DBD::Informix - v2008.0513 - http://dbi.perl.org "Blessed are we who can laugh at ourselves, for we shall never cease to be amused." --20cf3054a54772f193049c25d646
The OS permissions on the chunk files should be owner informix, group informix, and 0660 read and write privileges for owner and group ONLY. The same privileges, but also including execute privilege for informix:informix - so 0770 - should be on the directory containing the chunk files. If you have set that properly, then no other users except informix, and therefore only the database engine and DBAs (OK and root), will be able to modify or delete the files. There is nothing else you can or need to do. If you are that concerned about someone with root privileges damaging the database's files, you should be using RAW devices and not filesystem files for your chunks. Art Art S. Kagel Advanced DataTools (www.advancedatatools.com) IIUG Board of Directors (art@iiug.org) Blog: http://informix-myview.blogspot.com/ Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on my employer, Advanced DataTools, the IIUG, nor any other organization with which I am associated either explicitly, implicitly, or by inference. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves. On Sun, Feb 13, 2011 at 2:54 AM, KHURRAM SHAHZAD <kshahzad02@i2cinc.com>wrote: > I want to implement the locking on UFS file system. > Currently I am using informix 11.5 FC 7 on sun solaris using UFS file > system. > There is a problem that a chunk file of db space which is using by informix > database can be updated or deleted by other than database process. > > So please guide me to prevent to overwrite and delete our database files > when > these are using by database. > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --0015175cb2c622e72c049c2d9282
Hi Art, In windows Operating system if database is up and running nobody can delete the dbspace files weather he is administrator or a standard user because windows applied locks on all those files which are in use. I am seeking this type of locks in solaris , Because an informix user can remove db chunk file mistakenly . If UFS provide such type of locks we can minimize the risk.
On Sun, Feb 13, 2011 at 20:57, KHURRAM SHAHZAD <kshahzad02@i2cinc.com>wrote: > In Windows operating system, if database is up and running, nobody can > delete > the dbspace files whether he is administrator or a standard user because > Windows applied locks on all those files which are in use. > > I am seeking this type of locks in Solaris, because an informix user can > remove db chunk file mistakenly . If UFS provide such type of locks we can > minimize the risk. > Unix does not provide an equivalent protection mechanism. The owner of a file can always delete it. The disk space used by the file will not be released while some process still has it open, but another file of the same name can be created and other processes will use that file quite happily. Unix gives you permission to shoot yourself in the foot - and has ammunition available for all sizes of gun. It is recommended that you do not avail yourself of the facilities; it is painful when you do. If you can't trust your Informix administrator (or system administrator) not to remove files that are in use, train yourself a better administrator. -- Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h> Guardian of DBD::Informix - v2008.0513 - http://dbi.perl.org "Blessed are we who can laugh at ourselves, for we shall never cease to be amused." --20cf3054ad011966ea049c38318f
Hi all, just a hint: if you accidentally delete a chunk file, you can recover from that in case the database is still running. Because the inode is deleted, the file will not be freed until the last reference is closing. That way, you can backup the database and restore afterwards. But the others are right, either use raw devices, so nobody can delete them (only the links can be deleted, but are easy to recover), or e.g. make an rm script which check the files you want to delete for informix owner before it actually deletes the files. That way, also a root user cannot delete. A special filesystem will not help. Marcus -----Original Message----- From: Jonathan Leffler [mailto:jonathan.leffler@gmail.com] Sent: Monday, February 14, 2011 7:31 AM To: ids@iiug.org Subject: Re: Locking in UFS [22753] On Sun, Feb 13, 2011 at 20:57, KHURRAM SHAHZAD <kshahzad02@i2cinc.com>wrote: > In Windows operating system, if database is up and running, nobody can > delete the dbspace files whether he is administrator or a standard > user because Windows applied locks on all those files which are in > use. > > I am seeking this type of locks in Solaris, because an informix user > can remove db chunk file mistakenly . If UFS provide such type of > locks we can minimize the risk. > Unix does not provide an equivalent protection mechanism. The owner of a file can always delete it. The disk space used by the file will not be released while some process still has it open, but another file of the same name can be created and other processes will use that file quite happily. Unix gives you permission to shoot yourself in the foot - and has ammunition available for all sizes of gun. It is recommended that you do not avail yourself of the facilities; it is painful when you do. If you can't trust your Informix administrator (or system administrator) not to remove files that are in use, train yourself a better administrator. -- Jonathan Leffler <jonathan.leffler@gmail.com> #include <disclaimer.h> Guardian of DBD::Informix - v2008.0513 - http://dbi.perl.org "Blessed are we who can laugh at ourselves, for we shall never cease to be amused." --20cf3054ad011966ea049c38318f ************************************************************************ ******* Forum Note: Use "Reply" to post a response in the discussion forum.
Name your chunks starting with dot (e.g. .rootdbs) and your "administrator" will not see them ;o) Hrvoje On 14.02.2011. 05:57, KHURRAM SHAHZAD wrote: > Hi Art, > > In windows Operating system if database is up and running nobody can delete > the dbspace files weather he is administrator or a standard user because > windows applied locks on all those files which are in use. > > I am seeking this type of locks in solaris , Because an informix user can > remove db chunk file mistakenly . If UFS provide such type of locks we can > minimize the risk. > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > >
There is no such lock. Art Art S. Kagel Advanced DataTools (www.advancedatatools.com) IIUG Board of Directors (art@iiug.org) Blog: http://informix-myview.blogspot.com/ Disclaimer: Please keep in mind that my own opinions are my own opinions and do not reflect on my employer, Advanced DataTools, the IIUG, nor any other organization with which I am associated either explicitly, implicitly, or by inference. Neither do those opinions reflect those of other individuals affiliated with any entity with which I am affiliated nor those of the entities themselves. On Sun, Feb 13, 2011 at 11:57 PM, KHURRAM SHAHZAD <kshahzad02@i2cinc.com>wrote: > Hi Art, > > In windows Operating system if database is up and running nobody can delete > the dbspace files weather he is administrator or a standard user because > windows applied locks on all those files which are in use. > > I am seeking this type of locks in solaris , Because an informix user can > remove db chunk file mistakenly . If UFS provide such type of locks we can > minimize the risk. > > > > ******************************************************************************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > --0015175113e61c8113049c3d1af8
Hmm. UNIX does offer file locking mechanisms. :)
The "only" problem is, that this is not really enforced
by the OS or the file system itself ...
See e.g. http://en.wikipedia.org/wiki/File_locking
section "In UNIX" for more info on this topic.
Another problem with this locking for Informix Server
is that with Informix Server more than one of the
oninit processes may need to write to a file. So
even between themselves oninit processes constantly
would have to acquire and release these locks via
system calls ... probably causing considerable
performance loss ... [ As far as I know the UNIX file
locking is always 'per process' - the locks not
available for e.g. a process group. Informix Server
therefore has its internal, faster methods to ensure
file integrity when different oninit processes need to
write to the same file. ]
Regards, Martin
--
Martin Fuerderer
IBM Informix Development Munich, Germany
Information Management
-- Go Cruising with Informix in 2011 ...
-- IIUG Informix Conference
-- Overland Park Marriott, Kansas
-- May 15 - 18, 2011
IBM Deutschland Research & Development GmbH
Chairman of the Supervisory Board: Martin Jetter
Board of Management: Dirk Wittkopp
Corporate Seat: Boeblingen, Germany
Reg.-Gericht: Amtsgericht Stuttgart, HRB 243294
ids-bounces@iiug.org wrote on 02/14/2011 01:22:43 PM:
>
> There is no such lock.
>
> Art
>
> Art S. Kagel
> Advanced DataTools (www.advancedatatools.com)
> IIUG Board of Directors (art@iiug.org)
> Blog: http://informix-myview.blogspot.com/
>
> Disclaimer: Please keep in mind that my own opinions are my own opinions
and
> do not reflect on my employer, Advanced DataTools, the IIUG, nor any
other
> organization with which I am associated either explicitly, implicitly,
or by
> inference. Neither do those opinions reflect those of other individuals
> affiliated with any entity with which I am affiliated nor those of the
> entities themselves.
>
> On Sun, Feb 13, 2011 at 11:57 PM, KHURRAM SHAHZAD
> <kshahzad02@i2cinc.com>wrote:
>
> > Hi Art,
> >
> > In windows Operating system if database is up and running nobody can
delete
> > the dbspace files weather he is administrator or a standard user
because
> > windows applied locks on all those files which are in use.
> >
> > I am seeking this type of locks in solaris , Because an informix user
can
> > remove db chunk file mistakenly . If UFS provide such type of locks we
can
> > minimize the risk.
> >
> >
> >
> >
>
*******************************************************************************
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> >
>
> --0015175113e61c8113049c3d1af8
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
Correct, Martin. Unix file locking is voluntary, and so it is not the same
as the mandatory "in use" lock that WIndows provides which can prevent a
file that is in use from being deleted. Hence, my statement stands, "there
is no such lock!"
Art
Art S. Kagel
Advanced DataTools (www.advancedatatools.com)
IIUG Board of Directors (art@iiug.org)
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions and
do not reflect on my employer, Advanced DataTools, the IIUG, nor any other
organization with which I am associated either explicitly, implicitly, or by
inference. Neither do those opinions reflect those of other individuals
affiliated with any entity with which I am affiliated nor those of the
entities themselves.
On Mon, Feb 14, 2011 at 8:29 AM, Martin Fuerderer <MARTINFU@de.ibm.com>wrote:
> Hmm. UNIX does offer file locking mechanisms. :)
>
> The "only" problem is, that this is not really enforced
> by the OS or the file system itself ...
> See e.g. http://en.wikipedia.org/wiki/File_locking
> section "In UNIX" for more info on this topic.
>
> Another problem with this locking for Informix Server
> is that with Informix Server more than one of the
> oninit processes may need to write to a file. So
> even between themselves oninit processes constantly
> would have to acquire and release these locks via
> system calls ... probably causing considerable
> performance loss ... [ As far as I know the UNIX file
> locking is always 'per process' - the locks not
> available for e.g. a process group. Informix Server
> therefore has its internal, faster methods to ensure
> file integrity when different oninit processes need to
> write to the same file. ]
>
> Regards, Martin
> --
> Martin Fuerderer
> IBM Informix Development Munich, Germany
> Information Management
>
> -- Go Cruising with Informix in 2011 ...
> -- IIUG Informix Conference
> -- Overland Park Marriott, Kansas
> -- May 15 - 18, 2011
>
> IBM Deutschland Research & Development GmbH
> Chairman of the Supervisory Board: Martin Jetter
> Board of Management: Dirk Wittkopp
> Corporate Seat: Boeblingen, Germany
> Reg.-Gericht: Amtsgericht Stuttgart, HRB 243294
>
> ids-bounces@iiug.org wrote on 02/14/2011 01:22:43 PM:
> >
> > There is no such lock.
> >
> > Art
> >
> > Art S. Kagel
> > Advanced DataTools (www.advancedatatools.com)
> > IIUG Board of Directors (art@iiug.org)
> > Blog: http://informix-myview.blogspot.com/
> >
> > Disclaimer: Please keep in mind that my own opinions are my own opinions
> and
> > do not reflect on my employer, Advanced DataTools, the IIUG, nor any
> other
> > organization with which I am associated either explicitly, implicitly,
> or by
> > inference. Neither do those opinions reflect those of other individuals
> > affiliated with any entity with which I am affiliated nor those of the
> > entities themselves.
> >
> > On Sun, Feb 13, 2011 at 11:57 PM, KHURRAM SHAHZAD
> > <kshahzad02@i2cinc.com>wrote:
> >
> > > Hi Art,
> > >
> > > In windows Operating system if database is up and running nobody can
> delete
> > > the dbspace files weather he is administrator or a standard user
> because
> > > windows applied locks on all those files which are in use.
> > >
> > > I am seeking this type of locks in solaris , Because an informix user
> can
> > > remove db chunk file mistakenly . If UFS provide such type of locks we
> can
> > > minimize the risk.
> > >
> > >
> > >
> > >
> >
>
>
>
*******************************************************************************
>
> > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > >
> > >
> >
> > --0015175113e61c8113049c3d1af8
> >
> >
> >
>
>
>
*******************************************************************************
>
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--0015175cb2c66f87f2049c3fcad7