{"Entry":{"collection":"guc","key":"log_file_mode","name":"log_file_mode","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Reporting and Logging / Where to Log","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"9.0","status":"added","to":"9.1"}],"content_hash":"1e653c0b228449a2a6e36813ac70824e5b34ceaa515c63112b13dfd9f00cea1b","context":"","default_changed_in":[],"default_history":[{"from":"9.1","to":"19","value":"384"}],"editorial":{"advice":{"olap":"Analytical logs often contain query text and identifiers, so use the same or stricter mode; larger log volume is not a reason to broaden file access.","oltp":"Choose the least-privileged mode that still lets the approved collector or shipping group read new files. Verify ownership after a real rotation and explicitly remediate existing files if policy changes.","small":"Keep 0600 unless a controlled local group must ship logs; if 0640 is used, audit group membership and directory permissions rather than making files world-readable."},"mechanism":["log_file_mode is a chmod-style numeric mode for files newly created by logging_collector. Use a leading zero for customary octal notation: 0640 is not the same numeric value as decimal 640. The setting does not apply to syslog/eventlog output and does not change existing files.","It has SIGHUP context. After a reload, the new mode is used the next time logging_collector creates a file; reloading does not chmod the file that is currently open or historical files.","The effective access boundary also includes the PostgreSQL service account, file group, log_directory ownership and traversal permissions, shipping-agent group membership, and external retention copies. A group-readable mode is safe only when that group is controlled."],"pitfalls":["Editing log_file_mode without reloading configuration and verifying the effective value and subsequent behavior.","Combining incompatible destination, collector, filename, and rotation assumptions and then losing or overwriting logs.","Failing to monitor a full or unwritable log target, which can block logging or database activity depending on the path.","Writing 640 instead of octal 0640 and producing a different numeric permission mode."],"references":[{"title":"PostgreSQL 19 Beta 4: log_file_mode","url":"https://www.postgresql.org/docs/19/runtime-config-logging.html#GUC-LOG-FILE-MODE"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["logging_collector","log_destination","log_directory","log_filename","log_rotation_age","log_rotation_size"],"summary":"log_file_mode is the PostgreSQL setting that defines the file permissions for log files."},"enumvals":[],"first_version":"9.1","group":"Reporting and Logging","group_slug":"logging","imported_at":"2026-09-30T00:40:57.327752+08:00","intro_commit":{"authored_at":"2010-07-16T22:25:51Z","discussion":[],"hash":"3ec694e17bc01cec4ae2000847f25e3d549888c0","subject":"Add a log_file_mode GUC that allows control of the file permissions set on log files created by the syslogger process.","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=3ec694e17bc01cec4ae2000847f25e3d549888c0"},"key":"log_file_mode","last_version":"20","max_val":"","min_val":"","name":"log_file_mode","position":227,"present_in":["9.1","9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"On Unix systems this parameter sets the permissions for log files when logging_collector is enabled.","short_desc_zh":"","source_rev":"english-manuals:b8d49977e448d46528c72d50c464b47a3e0be6f8eae92a26d98e5acdc84ffc52","unit":"","vartype":"integer"}},"Definition":{"Collection":"guc","Key":"log_file_mode","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"log_file_mode","SourceRevision":"english-manuals:b8d49977e448d46528c72d50c464b47a3e0be6f8eae92a26d98e5acdc84ffc52","Facts":{"boot_val":"384","category":"Reporting and Logging / Where to Log","context":"sighup","description":"On Unix systems this parameter sets the permissions for log files when logging_collector is enabled. (On Microsoft Windows this parameter is ignored.) The parameter value is expected to be a numeric mode specified in the format accepted by the chmod and umask system calls. (To use the customary octal format the number must start with a 0 (zero).) The default permissions are 0600, meaning only the server owner can read or write the log files. The other commonly useful setting is 0640, allowing members of the owner's group to read the files. Note however that to make use of such a setting, you'll need to alter log_directory to store the files somewhere outside the cluster data directory. In any case, it's unwise to make the log files world-readable, since they might contain sensitive data. This parameter can only be set in the postgresql.conf file or on the server command line.","doc":{"anchor":"GUC-LOG-FILE-MODE","file":"runtime-config-logging.html","lang":"en","sha256":"93c48c522a72fca19705c4c91a71e951eae653662008eee2e4a9a74a11127fde","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"The parameter value is expected to be a numeric mode specification in the form accepted by the chmod and umask system calls. (To use the customary octal format the number must start with a 0 (zero).)","lang":"en","max_val":"511","metadata_version":"18","min_val":"0","name":"log_file_mode","short_desc":"Sets the file permissions for log files.","source":"pg-settings-source-snapshot","unit":null,"vartype":"integer"},"ManualEvidence":{"doc":{"anchor":"GUC-LOG-FILE-MODE","file":"runtime-config-logging.html","lang":"en","sha256":"93c48c522a72fca19705c4c91a71e951eae653662008eee2e4a9a74a11127fde","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"log_file_mode","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"log_file_mode","Summary":"","BodyHTML":"\u003cp\u003e在 Unix 系统上，当\u003ccode\u003elogging_collector\u003c/code\u003e被启用时，这个参数设置日志文件的权限（在微软 Windows 上这个参数将被忽略）。这个参数值应当是一个数字形式的模式，它可以被\u003ccode\u003echmod\u003c/code\u003e和\u003ccode\u003eumask\u003c/code\u003e系统调用接受（要使用通常的八进制格式，该数字必须以一个\u003ccode\u003e0\u003c/code\u003e（零）开始）。\u003c/p\u003e\u003cp\u003e默认的权限是\u003ccode\u003e0600\u003c/code\u003e，表示只有服务器拥有者才能读取或写入日志文件。其他常用的设置是\u003ccode\u003e0640\u003c/code\u003e，它允许拥有者的组成员读取文件。不过要注意你需要修改\u003ca href=\"/docs/18/runtime-config-logging.html#GUC-LOG-DIRECTORY\" rel=\"nofollow\"\u003elog_directory\u003c/a\u003e为将文件存储在集簇数据目录之外的某个位置，才能利用这个设置。在任何情况下，让日志文件变成任何人都可读是不明智的，因为日志文件中可能包含敏感数据。\u003c/p\u003e\u003cp\u003e这个参数只能在\u003ccode\u003epostgresql.conf\u003c/code\u003e文件中或通过服务器命令行进行设置。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"0b55205b7e0a4288f72c949091e8fefc99749e6083c786c13398bc79919ab0ef","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e在 Unix 系统上，当\u003ccode class=\"varname\"\u003elogging_collector\u003c/code\u003e被启用时，这个参数设置日志文件的权限（在微软 Windows 上这个参数将被忽略）。这个参数值应当是一个数字形式的模式，它可以被\u003ccode class=\"function\"\u003echmod\u003c/code\u003e和\u003ccode class=\"function\"\u003eumask\u003c/code\u003e系统调用接受（要使用通常的八进制格式，该数字必须以一个\u003ccode class=\"literal\"\u003e0\u003c/code\u003e（零）开始）。\u003c/p\u003e\u003cp\u003e默认的权限是\u003ccode class=\"literal\"\u003e0600\u003c/code\u003e，表示只有服务器拥有者才能读取或写入日志文件。其他常用的设置是\u003ccode class=\"literal\"\u003e0640\u003c/code\u003e，它允许拥有者的组成员读取文件。不过要注意你需要修改\u003ca href=\"/docs/18/runtime-config-logging.html#GUC-LOG-DIRECTORY\"\u003elog_directory\u003c/a\u003e为将文件存储在集簇数据目录之外的某个位置，才能利用这个设置。在任何情况下，让日志文件变成任何人都可读是不明智的，因为日志文件中可能包含敏感数据。\u003c/p\u003e\u003cp\u003e这个参数只能在\u003ccode class=\"filename\"\u003epostgresql.conf\u003c/code\u003e文件中或通过服务器命令行进行设置。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["10","11","12","13","14","15","16","17","18","19","20","9.1","9.2","9.3","9.4","9.5","9.6"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
