{"Entry":{"collection":"guc","key":"unix_socket_permissions","name":"unix_socket_permissions","aliases":[],"metadata":{"baseline":true,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / Connection Settings","category_zh":"","changed_in":[],"changes":[{"documentation_changed":true,"fields":{},"from":"7.4","status":"changed","to":"8.0"},{"documentation_changed":true,"fields":{},"from":"8.0","status":"changed","to":"8.1"},{"documentation_changed":true,"fields":{},"from":"8.1","status":"changed","to":"8.2"},{"documentation_changed":true,"fields":{},"from":"8.2","status":"changed","to":"8.3"},{"documentation_changed":true,"fields":{},"from":"8.3","status":"changed","to":"8.4"},{"documentation_changed":true,"fields":{},"from":"8.4","status":"changed","to":"9.0"},{"documentation_changed":true,"fields":{},"from":"9.2","status":"changed","to":"9.3"},{"documentation_changed":true,"fields":{},"from":"9.5","status":"changed","to":"9.6"},{"documentation_changed":true,"fields":{},"from":"12","status":"changed","to":"13"},{"documentation_changed":true,"fields":{},"from":"13","status":"changed","to":"14"},{"documentation_changed":true,"fields":{},"from":"16","status":"changed","to":"17"}],"content_hash":"540c4d697a69e15316fdc29576e692b4a7f4251485ec175c7c63a50045a7a6ec","context":"","default_changed_in":[],"default_history":[{"from":"9.0","to":"19","value":"511"}],"editorial":{"advice":{"olap":"Apply the same local policy to analytical tools. Do not weaken the mode to solve a missing group or directory deployment; repair the operating-system identity path instead.","oltp":"Use 0770 or 0700 only when local operating-system membership is an intentional first boundary, and verify that directory permissions and pg_hba.conf still enforce the desired policy. The portable default 0777 can be acceptable when pg_hba.conf is authoritative.","small":"Choose the simplest mode supported by the platform and test it after restart. For abstract sockets or systems that ignore socket modes, enforce access through the directory choice where applicable and pg_hba.conf."},"mechanism":["unix_socket_permissions sets the chmod-style mode of filesystem Unix-domain sockets. Use a leading zero for octal notation. For a socket, only the write bit controls the ability to connect; read and execute bits do not provide meaningful additional socket access.","It is a POSTMASTER-context setting, so the mode changes only when sockets are recreated at server restart. Directory traversal permissions and unix_socket_group can form another local boundary, while pg_hba.conf local records still authenticate database users independently.","Abstract-namespace sockets have no filesystem permissions, so this setting is ignored for @-prefixed socket entries. Some operating systems also ignore socket modes entirely; the page must not present the mode as a portable replacement for directory permissions or pg_hba.conf."],"pitfalls":["Writing decimal 770 instead of octal 0770 and creating an unintended numeric mode.","Expecting read or execute bits to control socket connection access; only the write bit matters.","Relying on the mode for abstract-namespace sockets or operating systems that ignore socket permissions.","Treating a restrictive socket mode as a substitute for pg_hba.conf authentication, role privileges, or directory traversal controls."],"references":[{"title":"PostgreSQL 19 Beta 4: unix_socket_permissions","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-UNIX-SOCKET-PERMISSIONS"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["listen_addresses","port","max_connections","reserved_connections","superuser_reserved_connections","unix_socket_directories"],"summary":"unix_socket_permissions is the PostgreSQL setting that defines the access permissions of the Unix-domain socket."},"enumvals":[],"first_version":"7.4","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:32.255552+08:00","intro_commit":{},"key":"unix_socket_permissions","last_version":"20","max_val":"","min_val":"","name":"unix_socket_permissions","position":442,"present_in":["7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6","10","11","12","13","14","15","16","17","18","19","20"],"short_desc":"Sets the access permissions of the Unix-domain socket(s).","short_desc_zh":"","source_rev":"english-manuals:f1cebe0a11051cab815406dd6a2d2695c489d85ce4a08c5ace3667bdb935a24a","unit":"","vartype":"integer"}},"Definition":{"Collection":"guc","Key":"unix_socket_permissions","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"unix_socket_permissions","SourceRevision":"english-manuals:f1cebe0a11051cab815406dd6a2d2695c489d85ce4a08c5ace3667bdb935a24a","Facts":{"boot_val":"511","category":"Connections and Authentication / Connection Settings","context":"postmaster","description":"Sets the access permissions of the Unix-domain socket(s). Unix-domain sockets use the usual Unix file system permission set. The parameter value is expected to be a numeric mode specified in the format accepted by the chmod and umask system calls. (To use the customary octal format the number must start with a 0 (zero).) The default permissions are 0777, meaning anyone can connect. Reasonable alternatives are 0770 (only user and group, see also unix_socket_group) and 0700 (only user). (Note that for a Unix-domain socket, only write permission matters, so there is no point in setting or revoking read or execute permissions.) This access control mechanism is independent of the one described in Chapter 20. This parameter can only be set at server start. This parameter is irrelevant on systems, notably Solaris as of Solaris 10, that ignore socket permissions entirely. There, one can achieve a similar effect by pointing unix_socket_directories to a directory having search permission limited to the desired audience. Sockets in the abstract namespace have no file permissions, so this setting is also ignored in that case.","doc":{"anchor":"GUC-UNIX-SOCKET-PERMISSIONS","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":null,"extra_desc":"Unix-domain sockets use the usual Unix file system permission set. The parameter value is expected to be a numeric mode specification in the form accepted by the chmod and umask system calls. (To use the customary octal format the number must start with a 0 (zero).)","lang":"en","max_val":"511","metadata_version":"18","min_val":"0","name":"unix_socket_permissions","short_desc":"Sets the access permissions of the Unix-domain socket.","source":"pg-settings-source-snapshot","unit":null,"vartype":"integer"},"ManualEvidence":{"doc":{"anchor":"GUC-UNIX-SOCKET-PERMISSIONS","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"unix_socket_permissions","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"unix_socket_permissions","Summary":"","BodyHTML":"\u003cp\u003e设置 Unix 域套接字的访问权限。Unix 域套接字使用通常的 Unix 文件系统权限集。参数值应是以 \u003ccode\u003echmod\u003c/code\u003e 和 \u003ccode\u003eumask\u003c/code\u003e 系统调用所接受格式指定的数字权限模式。（要使用惯用的八进制格式，数字必须以 \u003ccode\u003e0\u003c/code\u003e（零）开头。）\u003c/p\u003e\u003cp\u003e默认权限是 \u003ccode\u003e0777\u003c/code\u003e，表示任何人都可以连接。合理的其他取值包括 \u003ccode\u003e0770\u003c/code\u003e（仅属主和所属组，另见 \u003ccode\u003eunix_socket_group\u003c/code\u003e）和 \u003ccode\u003e0700\u003c/code\u003e（仅属主）。（注意，对 Unix 域套接字而言，只有写权限起作用，因此设置或撤销读权限和执行权限没有意义。）\u003c/p\u003e\u003cp\u003e此访问控制机制独立于\u003ca href=\"/docs/18/client-authentication.html\" rel=\"nofollow\"\u003e第 20 章\u003c/a\u003e中描述的机制。\u003c/p\u003e\u003cp\u003e此参数只能在服务器启动时设置。\u003c/p\u003e\u003cp\u003e此参数对完全忽略套接字权限的系统无效，尤其是 Solaris（截至 Solaris 10）。在这些系统上，可以将 \u003ccode\u003eunix_socket_directories\u003c/code\u003e 指向一个仅向目标用户授予搜索权限的目录，以达到类似效果。\u003c/p\u003e\u003cp\u003e抽象命名空间中的套接字没有文件权限，因此这种情况下也会忽略此设置。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"c7009efa6844ec35816329c2916c9d655030abf2afab8efafb319ba26e75e8df","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e设置 Unix 域套接字的访问权限。Unix 域套接字使用通常的 Unix 文件系统权限集。参数值应是以 \u003ccode class=\"function\"\u003echmod\u003c/code\u003e 和 \u003ccode class=\"function\"\u003eumask\u003c/code\u003e 系统调用所接受格式指定的数字权限模式。（要使用惯用的八进制格式，数字必须以 \u003ccode class=\"literal\"\u003e0\u003c/code\u003e（零）开头。）\u003c/p\u003e\u003cp\u003e默认权限是 \u003ccode class=\"literal\"\u003e0777\u003c/code\u003e，表示任何人都可以连接。合理的其他取值包括 \u003ccode class=\"literal\"\u003e0770\u003c/code\u003e（仅属主和所属组，另见 \u003ccode class=\"varname\"\u003eunix_socket_group\u003c/code\u003e）和 \u003ccode class=\"literal\"\u003e0700\u003c/code\u003e（仅属主）。（注意，对 Unix 域套接字而言，只有写权限起作用，因此设置或撤销读权限和执行权限没有意义。）\u003c/p\u003e\u003cp\u003e此访问控制机制独立于\u003ca href=\"/docs/18/client-authentication.html\" title=\"第 20 章 客户端认证\"\u003e第 20 章\u003c/a\u003e中描述的机制。\u003c/p\u003e\u003cp\u003e此参数只能在服务器启动时设置。\u003c/p\u003e\u003cp\u003e此参数对完全忽略套接字权限的系统无效，尤其是 Solaris（截至 Solaris 10）。在这些系统上，可以将 \u003ccode class=\"varname\"\u003eunix_socket_directories\u003c/code\u003e 指向一个仅向目标用户授予搜索权限的目录，以达到类似效果。\u003c/p\u003e\u003cp\u003e抽象命名空间中的套接字没有文件权限，因此这种情况下也会忽略此设置。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["10","11","12","13","14","15","16","17","18","19","20","7.4","8.0","8.1","8.2","8.3","8.4","9.0","9.1","9.2","9.3","9.4","9.5","9.6"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
