From:
Heikki Linnakangas <heikki(dot)linnakangas(at)enterprisedb(dot)com>
To:
Stephen Frost <sfrost(at)snowman(dot)net>
Cc:
Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>,
KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>,
Bruce Momjian <bruce(at)momjian(dot)us>,
Joshua Brindle <method(at)manicmethod(dot)com>,
Robert Haas <robertmhaas(at)gmail(dot)com>,
Andrew Dunstan <andrew(at)dunslane(dot)net>,
Josh Berkus <josh(at)agliodbs(dot)com>,
PG Hackers <pgsql-hackers(at)postgresql(dot)org>,
Jaime Casanova <jcasanov(at)systemguards(dot)com(dot)ec>
Subject:
Re: Updates of SE-PostgreSQL 8.4devel patches (r1704)
Date:
2009-03-10 10:11:27
Message-ID:
49B63CCF.70501@enterprisedb.com (view raw or flat )
Thread:
2009-01-28 10:18:16 from Peter Eisentraut <peter_e(at)gmx(dot)net>
2009-01-28 13:28:11 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-01-28 14:02:14 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-01-28 14:41:49 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-01-28 14:50:54 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-01-28 15:31:35 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-01-28 14:30:55 from Stephen Frost <sfrost(at)snowman(dot)net>
2009-01-28 14:36:12 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-01-28 15:13:49 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-01-28 15:20:19 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-01-28 15:56:18 from Joshua Brindle <method(at)manicmethod(dot)com>
2009-01-28 18:20:09 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-01-28 18:49:21 from Joshua Brindle <method(at)manicmethod(dot)com>
2009-01-28 19:02:37 from Gregory Stark <stark(at)enterprisedb(dot)com>
2009-01-28 19:38:36 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-01-29 05:03:18 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-01-29 05:29:43 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-01-29 05:34:36 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-01-29 14:14:29 from Joshua Brindle <method(at)manicmethod(dot)com>
2009-01-30 21:34:46 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-01-30 21:39:57 from Josh Berkus <josh(at)agliodbs(dot)com>
2009-01-30 21:41:22 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-01-30 22:02:35 from Josh Berkus <josh(at)agliodbs(dot)com>
2009-01-30 22:19:16 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-01-30 22:30:16 from Ron Mayer <rm_pg(at)cheapcomplexdevices(dot)com>
2009-01-30 22:37:17 from Josh Berkus <josh(at)agliodbs(dot)com>
2009-01-30 22:38:46 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-01-30 23:00:24 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-01-30 22:43:56 from Josh Berkus <josh(at)agliodbs(dot)com>
2009-01-30 23:06:12 from Andrew Dunstan <andrew(at)dunslane(dot)net>
2009-01-30 23:13:04 from Stephen Frost <sfrost(at)snowman(dot)net>
2009-01-31 00:28:31 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-01-31 01:28:24 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-01-31 01:43:53 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-01-31 02:52:57 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-01-31 05:09:58 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-01-31 08:22:20 from Stephen Frost <sfrost(at)snowman(dot)net>
2009-01-31 10:25:16 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-01-31 13:32:59 from Stephen Frost <sfrost(at)snowman(dot)net>
2009-01-31 14:09:47 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-01-31 14:22:54 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-01-31 16:42:17 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-02-01 02:46:03 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-02-01 02:57:02 from Stephen Frost <sfrost(at)snowman(dot)net>
2009-02-01 03:01:40 from Andrew Dunstan <andrew(at)dunslane(dot)net>
2009-02-01 03:08:06 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-02-01 11:10:05 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-02-01 13:36:28 from Stephen Frost <sfrost(at)snowman(dot)net>
2009-02-07 15:24:46 from Alvaro Herrera <alvherre(at)commandprompt(dot)com>
2009-02-09 17:27:05 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-02-09 17:44:24 from Alvaro Herrera <alvherre(at)commandprompt(dot)com>
2009-02-02 17:42:59 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-02-03 00:27:39 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-02-03 00:47:42 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-02-03 01:28:22 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-02-03 02:15:22 from Joshua Brindle <method(at)manicmethod(dot)com>
2009-02-03 03:00:10 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-02-03 04:09:55 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-02-03 05:55:46 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-02-06 05:16:23 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-02-10 01:53:41 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-02-13 01:15:47 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-02-13 14:07:53 from Joshua Brindle <method(at)manicmethod(dot)com>
2009-02-13 16:24:46 from Jaime Casanova <jcasanov(at)systemguards(dot)com(dot)ec>
2009-02-14 01:32:22 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-02-14 05:03:42 from Jaime Casanova <jcasanov(at)systemguards(dot)com(dot)ec>
2009-02-14 05:46:49 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-02-14 14:01:38 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-02-15 00:16:16 from Jaime Casanova <jcasanov(at)systemguards(dot)com(dot)ec>
2009-02-19 21:35:43 from Jaime Casanova <jcasanov(at)systemguards(dot)com(dot)ec>
2009-02-27 21:53:51 from Jaime Casanova <jcasanov(at)systemguards(dot)com(dot)ec>
2009-02-27 22:06:35 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-02-27 22:59:05 from Jaime Casanova <jcasanov(at)systemguards(dot)com(dot)ec>
2009-02-22 08:29:46 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-02-24 09:03:00 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-02-26 04:04:40 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-02-26 06:23:17 from Jaime Casanova <jcasanov(at)systemguards(dot)com(dot)ec>
2009-02-26 06:26:09 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-02-26 06:46:54 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-02-26 06:56:19 from Jaime Casanova <jcasanov(at)systemguards(dot)com(dot)ec>
2009-03-03 07:39:30 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-04 20:28:02 from Heikki Linnakangas <heikki(dot)linnakangas(at)enterprisedb(dot)com>
2009-03-05 01:01:14 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-05 07:24:27 from Heikki Linnakangas <heikki(dot)linnakangas(at)enterprisedb(dot)com>
2009-03-05 08:38:00 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-05 13:53:13 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-03-06 10:25:13 from Heikki Linnakangas <heikki(dot)linnakangas(at)enterprisedb(dot)com>
2009-03-09 06:52:40 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-09 09:01:18 from Heikki Linnakangas <heikki(dot)linnakangas(at)enterprisedb(dot)com>
2009-03-09 09:16:05 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-09 09:11:45 from Heikki Linnakangas <heikki(dot)linnakangas(at)enterprisedb(dot)com>
2009-03-09 14:55:46 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-03-09 17:25:30 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-09 19:00:46 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-03-09 20:04:59 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-09 20:22:12 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-03-09 20:39:24 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-09 23:09:15 from Hannu Krosing <hannu(at)2ndQuadrant(dot)com>
2009-03-09 23:45:45 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-09 23:57:14 from "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
2009-03-10 00:05:30 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-10 00:22:39 from "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
2009-03-10 00:31:11 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-03-10 00:45:36 from "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
2009-03-10 00:55:34 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-10 01:33:51 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-10 03:53:52 from Josh Berkus <josh(at)agliodbs(dot)com>
2009-03-10 04:23:44 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-10 05:02:55 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-10 16:41:35 from "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
2009-03-10 17:08:26 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-10 17:26:49 from "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
2009-03-10 17:47:43 from Alvaro Herrera <alvherre(at)commandprompt(dot)com>
2009-03-10 17:49:35 from "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
2009-03-10 18:14:14 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-10 18:44:21 from "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
2009-03-10 18:59:22 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-10 19:08:43 from "Joshua D(dot) Drake" <jd(at)commandprompt(dot)com>
2009-03-10 19:13:56 from Devrim GÜNDÜZ <devrim(at)gunduz(dot)org>
2009-03-10 19:25:34 from Devrim GÜNDÜZ <devrim(at)gunduz(dot)org>
2009-03-10 18:45:13 from Devrim GÜNDÜZ <devrim(at)gunduz(dot)org>
2009-03-10 18:37:21 from Ron Mayer <rm_pg(at)cheapcomplexdevices(dot)com>
2009-03-10 19:17:37 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-11 05:14:40 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-10 00:56:36 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-10 08:58:46 from Hannu Krosing <hannu(at)2ndQuadrant(dot)com>
2009-03-10 09:26:48 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-10 23:53:44 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-10 00:41:55 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-10 05:19:57 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-09 09:25:12 from Heikki Linnakangas <heikki(dot)linnakangas(at)enterprisedb(dot)com>
2009-03-09 12:26:26 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-09 13:35:47 from Stephen Frost <sfrost(at)snowman(dot)net>
2009-03-10 10:11:27 from Heikki Linnakangas <heikki(dot)linnakangas(at)enterprisedb(dot)com>
2009-03-10 11:02:05 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-03-10 11:48:32 from Gregory Stark <stark(at)enterprisedb(dot)com>
2009-03-10 14:32:50 from David Fetter <david(at)fetter(dot)org>
2009-03-10 12:35:17 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-11 04:09:10 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-11 08:44:10 from Heikki Linnakangas <heikki(dot)linnakangas(at)enterprisedb(dot)com>
2009-03-11 09:17:18 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-03-11 09:25:31 from Heikki Linnakangas <heikki(dot)linnakangas(at)enterprisedb(dot)com>
2009-03-11 10:39:19 from Gregory Stark <stark(at)enterprisedb(dot)com>
2009-03-11 13:54:13 from Alvaro Herrera <alvherre(at)commandprompt(dot)com>
2009-03-11 16:53:52 from Ron Mayer <rm_pg(at)cheapcomplexdevices(dot)com>
2009-03-12 00:50:46 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-12 01:22:45 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-03-12 02:20:57 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-12 04:06:52 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-11 17:22:23 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-13 01:37:19 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-16 02:56:19 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-03-16 05:05:47 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-16 13:54:24 from Heikki Linnakangas <heikki(dot)linnakangas(at)enterprisedb(dot)com>
2009-03-16 16:57:40 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-03-17 02:22:27 from Koichi Suzuki <koichi(dot)szk(at)gmail(dot)com>
2009-03-17 06:30:15 from Heikki Linnakangas <heikki(dot)linnakangas(at)enterprisedb(dot)com>
2009-03-18 01:06:55 from Koichi Suzuki <koichi(dot)szk(at)gmail(dot)com>
2009-03-13 01:16:25 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-03-10 03:24:53 from Jaime Casanova <jcasanov(at)systemguards(dot)com(dot)ec>
2009-03-10 03:44:53 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-02-26 16:35:37 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-02-26 19:02:07 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-02-03 00:55:31 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-01-31 14:17:48 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-01-31 00:20:05 from KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>
2009-02-02 15:50:12 from Joshua Brindle <method(at)manicmethod(dot)com>
2009-02-02 16:17:40 from Chad Sellers <csellers(at)tresys(dot)com>
2009-01-29 17:50:34 from Zeugswetter Andreas OSB sIT <Andreas(dot)Zeugswetter(at)s-itsolutions(dot)at>
2009-01-28 19:43:51 from Andrew Sullivan <ajs(at)crankycanuck(dot)ca>
2009-01-28 20:58:17 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-01-28 22:07:12 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-01-28 23:34:27 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-01-28 23:46:12 from Andrew Dunstan <andrew(at)dunslane(dot)net>
2009-01-29 00:39:50 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-01-29 02:19:35 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-01-29 02:05:48 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-01-29 02:49:06 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-01-29 03:08:57 from Stephen Frost <sfrost(at)snowman(dot)net>
2009-01-29 03:43:41 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-01-29 04:33:01 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-01-29 05:55:36 from "Jonah H(dot) Harris" <jonah(dot)harris(at)gmail(dot)com>
2009-01-28 21:09:46 from Dimitri Fontaine <dfontaine(at)hi-media(dot)com>
2009-01-28 22:23:37 from Ron Mayer <rm_pg(at)cheapcomplexdevices(dot)com>
2009-01-28 22:18:27 from Stephen Frost <sfrost(at)snowman(dot)net>
2009-01-28 22:25:20 from Ron Mayer <rm_pg(at)cheapcomplexdevices(dot)com>
2009-01-28 22:47:00 from Joshua Brindle <method(at)manicmethod(dot)com>
2009-01-28 23:19:34 from Ron Mayer <rm_pg(at)cheapcomplexdevices(dot)com>
2009-01-29 01:52:09 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-01-29 02:22:45 from Stephen Frost <sfrost(at)snowman(dot)net>
2009-01-28 23:57:52 from Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
2009-01-29 00:31:18 from Joshua Brindle <method(at)manicmethod(dot)com>
2009-01-29 02:18:19 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-01-29 02:27:34 from Stephen Frost <sfrost(at)snowman(dot)net>
2009-01-29 03:35:22 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-01-29 03:44:50 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-01-29 02:36:14 from Joshua Brindle <method(at)manicmethod(dot)com>
2009-01-29 03:15:27 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-01-29 03:52:43 from Robert Haas <robertmhaas(at)gmail(dot)com>
2009-01-29 04:10:58 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-01-29 05:19:30 from Bruce Momjian <bruce(at)momjian(dot)us>
2009-01-29 05:46:38 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
2009-01-29 10:58:13 from Gregory Stark <stark(at)enterprisedb(dot)com>
2009-01-28 23:15:32 from Gregory Stark <stark(at)enterprisedb(dot)com>
2009-01-29 00:03:21 from KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>
Lists:
pgsql-hackers
Stephen Frost wrote:
> * Tom Lane (tgl(at)sss(dot)pgh(dot)pa(dot)us) wrote:
>> Heikki Linnakangas <heikki(dot)linnakangas(at)enterprisedb(dot)com> writes:
>>> KaiGai Kohei wrote:
>>>> As I promised last week, SE-PostgreSQL patches are revised here:
>>> The patch adds permission checks to SET/SHOW. If that's useful
>>> functionality, it would be nice to see that as a separate patch, not
>>> requiring SE-Linux.
>> My goodness. This patch seems to be going FAR beyond what I thought
>> its charter was.
>
> I agree. I thought the idea was that the first round of SE-PostgreSQL
> additions would be to add SE hooks for permissions that PG already
> implements. Other permissions would then be implemented in a PG-way
> first, and SE hooks then added to those later.
This seems to be a recurring theme with this patch. We stripped
row-level permissions, now we have SET/SHOW and the "function
installation" permissions. And the read/write file permissions. To make
progress, we need to consider each new feature like that separately, as
separate patches.
KaiGei: Let's drop SET/SHOW permissions from the patch, I presume that's
not critical for the overall goal.
Dropping the "function installation" permissions would simplify the
patch a lot. It would make the patch as whole a lot easier to swallow.
Let's ask the same question as with the row-level permissions: If we
drop the function installation stuff, would the rest of the patch still
be useful? We can revisit that part in the future.
I have the same concern as Tom about trying to curtail what superusers
can do. We have not been concerned about what a superuser can and can't
do before, so there could be small loopholes all over the codebase that
we haven't thought about. Just as an example, you added checks to COPY
to prevent reads from/writes to files. That's restricted to superusers.
However, you left pg_read_file() in src/backend/utils/adt/genfile.c wide
open.
If we drop the goal of trying to restrict what a superuser can do, is
the patch still useful?
One idea is to add a single "is superuser" permission to sepgsql. That
can be checked in a single place: superuser_arg(). If SE-Linux says that
you don't have superuser permissions, then superuser() will return false
even if the current user is marked as a superuser in pg_role. It would
give the same level of protection as sprinkling those fine-grained
checks all over the code, just in a more coarse-grain fashion.
--
Heikki Linnakangas
EnterpriseDB http://www.enterprisedb.com
In response to
Responses
pgsql-hackers by date
Next :From: KaiGai KoheiDate: 2009-03-10 11:02:05
Subject : Re: Updates of SE-PostgreSQL 8.4devel patches (r1704)
Previous :From : KaiGai KoheiDate : 2009-03-10 09:26:48
Subject : Re: Updates of SE-PostgreSQL 8.4devel patches (r1704)