Re: 8SEPostgres WAS: .4 release planning

From: Joshua Brindle <method(at)manicmethod(dot)com>
To: Josh Berkus <josh(at)agliodbs(dot)com>
Cc: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>, Robert Haas <robertmhaas(at)gmail(dot)com>, Merlin Moncure <mmoncure(at)gmail(dot)com>, "Jonah H(dot) Harris" <jonah(dot)harris(at)gmail(dot)com>, Gregory Stark <stark(at)enterprisedb(dot)com>, Simon Riggs <simon(at)2ndQuadrant(dot)com>, Bruce Momjian <bruce(at)momjian(dot)us>, Bernd Helmle <mailings(at)oopsware(dot)de>, Peter Eisentraut <peter_e(at)gmx(dot)net>, pgsql-hackers(at)postgresql(dot)org, KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
Subject: Re: 8SEPostgres WAS: .4 release planning
Date: 2009-01-26 22:44:24
Message-ID: 497E3CC8.8080501@manicmethod.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Josh Berkus wrote:
> Joshua,
>
>> So the security model has been looked at, though not the
>> implementation and we do have a community of developers, users and
>> customers interested in this work.
>
> Can you please take a look at it ASAP, then? In the next week, we will
> probably decide on whether or not to defer SEPostgres until 8.5. The
> fact that we haven't gotten a sign-off from any security expert anywhere
> is leaning the whole community towards "defer".
>

Yes, I will look at them to the extent I am able. As I am not familiar with the
postgresql codebase I won't be able to assert the correctness of the hook
placement (that is, where the security functions are called with respect to the
data they are protecting being accessed). The postgresql community should be
more familiar with the hook call sites and hopefully can assist there.

I should be able to handle the security backend and determining whether it
matches the security model we agreed on, but the hook placement is just as
important since a misplaced or missing hook will allow access that should not be
granted.

Joshua Brindle

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message decibel 2009-01-26 22:45:25 FK column doesn't exist error message could use more detail
Previous Message Ron Mayer 2009-01-26 22:42:32 Re: 8.4 release planning