Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Usenet -> c.d.o.server -> Re: Permission Problems revisited

Re: Permission Problems revisited

From: Peter Sylvester <peters_at_mitre.org>
Date: Tue, 10 Dec 2002 12:37:32 -0500
Message-ID: <at58os$6kg$1@newslocal.mitre.org>


Is "user-A" the owner of the oracle installation, typically "oracle"?

If so, you need to check ownership and permissions on the database and/or executables.

The "oracle" executable, as well as a few other things, needs to have setuid and setgid permissions. Note the "s" in the permissions below. These tend to get lost if you happen to move an installation using "tar" as a non-root user.

% cd $ORACLE_HOME/bin
% ls -l oracle
-rwsr-s--x 1 oracle dba 64469924 Nov 21 12:25 oracle

Database files should be owned and read/write by the oracle installation owner and dba group.

You probably need to shutdown, fix permissions, and restart.

--Peter

Gerold Krommer wrote:
> Sorry for the repeat. I have browsed google and found a few entries, but non
> were really satisfying. My Oracle knowledge is (let's say) moderate.
>
> The problem:
> Oracle 8.0.6, Solaris 2.6, but I m pretty sure I have seen this on older
> versions and other platforms, too (e.g. Oracle 8.1.7 and HPUX 11i).
>
> We are able to access the database with e.g. SQLPLUS when logged on as Unix
> user A, but not as User B.
>
> The error is:
> QL*Plus: Release 8.0.6.0.0 - Production on Tue Dec 10 15:13:55 2002
> (c) Copyright 1999 Oracle Corporation. All rights reserved.
> ERROR:
> ORA-00604: error occurred at recursive SQL level 1
> ORA-01115: IO error reading block from file 1 (block # 1122)
> ORA-01110: data file 1: '/fnsw/dev/1/oracle_sys0'
> ORA-27041: unable to open file
> SVR4 Error: 13: Permission denied
> Additional information: 3
>
> First I have a problem understanding why the Unix user matters. Isn't it,
> that only the Oracle processes access the data files ? So I only need to
> authenticate to Oracle by logging on.
>
> Second, my research on google has shown that certain protections on certain
> files must be set, but this information was really dispersed over several
> notes entries. Is there a place where there is a concise description on what
> must be set to what (e.g.SUID bit, etc.)
>
> Thanks very much,
>
> /Gerold (g.krommer_at_doremove.fns.co.at)
>
>
Received on Tue Dec 10 2002 - 11:37:32 CST

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US