Updates of SE-PostgreSQL 8.4devel patches (r1076)
From:
KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
To:
pgsql-hackers(at)postgresql(dot)org
Cc:
Bruce Momjian <bruce(at)momjian(dot)us>, Josh Berkus <josh(at)agliodbs(dot)com>,
KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>,
Robert Haas <robertmhaas(at)gmail(dot)com>
Subject:
Updates of SE-PostgreSQL 8.4devel patches (r1076)
Date:
2008-10-01 06:48:24
Message-ID:
48E31D38.5060000@ak.jp.nec.com (view raw or flat )
Thread:
2008-09-24 02:43:19 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-24 02:51:21 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-24 14:13:18 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2008-09-24 19:29:33 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-09-25 01:22:59 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-25 01:39:00 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-09-25 02:31:56 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-25 02:52:50 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-09-25 04:11:25 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-25 19:56:51 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-09-26 00:12:26 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-09-26 00:28:43 from "Robert Haas" <robertmhaas(at)gmail(dot)com>
2008-09-26 00:57:46 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-09-26 02:09:37 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-26 13:34:41 from Andrew Sullivan <ajs(at)commandprompt(dot)com>
2008-09-26 14:04:59 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-09-26 21:32:25 from Andrew Sullivan <ajs(at)commandprompt(dot)com>
2008-09-27 03:18:45 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2008-09-29 22:26:30 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2008-09-29 23:17:23 from Josh Berkus <josh(at)agliodbs(dot)com>
2008-09-29 23:22:23 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-09-30 01:19:21 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-30 01:06:02 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-30 01:52:07 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-09 14:21:55 from Andrew Sullivan <ajs(at)commandprompt(dot)com>
2008-10-10 04:44:49 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-10 13:07:49 from Andrew Sullivan <ajs(at)commandprompt(dot)com>
2008-10-14 03:35:57 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-26 00:29:02 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-09-26 01:01:19 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-26 08:09:06 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-26 00:57:40 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-26 00:32:21 from "Robert Haas" <robertmhaas(at)gmail(dot)com>
2008-09-26 01:23:21 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-09-26 01:41:00 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-09-26 02:19:52 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-09-26 02:24:10 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-09-26 02:54:28 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-09-26 05:30:00 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-26 02:41:02 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-26 02:58:57 from "Robert Haas" <robertmhaas(at)gmail(dot)com>
2008-09-26 03:27:42 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-26 02:10:03 from "Robert Haas" <robertmhaas(at)gmail(dot)com>
2008-09-26 02:32:24 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-09-26 03:34:47 from "Robert Haas" <robertmhaas(at)gmail(dot)com>
2008-09-26 06:53:30 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-26 22:11:14 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-09-26 13:39:04 from Andrew Sullivan <ajs(at)commandprompt(dot)com>
2008-09-26 22:15:46 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-09-26 22:23:56 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2008-09-27 02:31:16 from "Robert Haas" <robertmhaas(at)gmail(dot)com>
2008-09-27 03:05:49 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-09-27 09:59:53 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2008-09-29 23:24:20 from Josh Berkus <josh(at)agliodbs(dot)com>
2008-09-30 00:21:29 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-09-30 01:28:02 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-01 06:48:24 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-02 01:23:53 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-06 08:25:06 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-08 17:49:30 from Simon Riggs <simon(at)2ndQuadrant(dot)com>
2008-10-09 01:01:12 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-27 02:50:22 from Andrew Sullivan <ajs(at)commandprompt(dot)com>
2008-09-26 00:48:14 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-09-26 12:43:42 from Zeugswetter Andreas OSB sIT <Andreas(dot)Zeugswetter(at)s-itsolutions(dot)at>
2008-09-26 14:07:06 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2008-10-07 23:09:20 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2008-10-07 23:33:17 from Josh Berkus <josh(at)agliodbs(dot)com>
2008-10-07 23:34:50 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2008-10-08 01:11:14 from "Robert Haas" <robertmhaas(at)gmail(dot)com>
2008-10-08 02:36:19 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-08 17:14:47 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-10-08 17:26:28 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-10-09 01:00:21 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-14 09:27:34 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-14 15:48:25 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2008-10-09 14:01:34 from Andrew Sullivan <ajs(at)commandprompt(dot)com>
2008-10-10 04:09:48 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-10 13:00:21 from Andrew Sullivan <ajs(at)commandprompt(dot)com>
2008-10-14 19:16:30 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-10-15 08:10:59 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-15 13:55:54 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-10-16 00:31:00 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-16 10:57:58 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-29 08:42:43 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-29 10:20:45 from Simon Riggs <simon(at)2ndQuadrant(dot)com>
2008-10-30 02:51:54 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-10-31 09:34:02 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-11-01 22:39:45 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-11-02 00:26:00 from "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
2008-11-03 11:36:37 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2008-11-03 19:30:01 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-11-04 02:32:45 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2008-11-04 22:43:11 from Bruce Momjian <bruce(at)momjian(dot)us>
2008-10-14 15:53:20 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2008-10-12 17:31:00 from Andres Freund <andres(at)anarazel(dot)de>
2008-10-14 03:36:51 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
Lists:
pgsql-hackers
I updated the following SE-PostgreSQL patches:
[1/5] http://sepgsql.googlecode.com/files/sepostgresql-sepgsql-8.4devel-3-r1076.patch
[2/5] http://sepgsql.googlecode.com/files/sepostgresql-pg_dump-8.4devel-3-r1076.patch
[3/5] http://sepgsql.googlecode.com/files/sepostgresql-policy-8.4devel-3-r1076.patch
[4/5] http://sepgsql.googlecode.com/files/sepostgresql-docs-8.4devel-3-r1076.patch
[5/5] http://sepgsql.googlecode.com/files/sepostgresql-tests-8.4devel-3-r1076.patch
- Patches are rebased to the latest CVS HEAD.
- Improvement of performance penalty for access checks.
Reworks in access vector chache enables to reduce performance loss, as follows:
http://kaigai.sakura.ne.jp/sblo_files/kaigai/image/080930_sepgsql_performance.png
It shows about 8% loss in maximum, and larger scale database give us
smaller losses in trend.
- Add a hook to check permission on "COPY TO/FROM <file>".
In the previous version, SE-PostgreSQL does not check permissions
to the file used in COPY statement. It is fixed.
- Documentation updates
- Descriptions for build & install are reworked, because most of
security policy for SE-PostgreSQL now got merged into the upstream
selinux-policy package.
- Add a "Limitation" section to describe about covert channel and
reference integrity.
Thanks,
--
OSS Platform Development Division, NEC
KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
In response to
Responses
pgsql-hackers by date
Next :From: Paul SchlieDate: 2008-10-01 06:57:47
Subject : Re: Block-level CRC checks
Previous :From : Gurjeet SinghDate : 2008-10-01 05:12:28
Subject : Re: Bad error message