Re: [0/4] Proposal of SE-PostgreSQL patches

From: "Dawid Kuroczko" <qnex42(at)gmail(dot)com>
To: "KaiGai Kohei" <kaigai(at)ak(dot)jp(dot)nec(dot)com>
Cc: pgsql-hackers(at)postgresql(dot)org
Subject: Re: [0/4] Proposal of SE-PostgreSQL patches
Date: 2008-06-02 10:09:19
Message-ID: 758d5e7f0806020309t2028fd90r52826146901813de@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers pgsql-patches

On Wed, May 7, 2008 at 7:52 AM, KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com> wrote:
> Tom, Thanks for your reviewing.
>> The patch hasn't got a mode in which SELinux support is compiled in but
>> not active. This is a good way to ensure that no one will ever ship
>> standard RPMs with the feature compiled in, because they will be entirely
>> nonfunctional for people who aren't interested in setting up SELinux.
>> I think you need an "enable_sepostgres" GUC, or something like that.
>> (Of course, the overhead of the per-row security column would probably
>> discourage anyone from wanting to use such a configuration anyway,
>> so maybe the point is moot.)
> We can turn on/off SELinux globally, not bounded to SE-PostgreSQL.
> The reason why I didn't provide a mode bit like "enable_sepostgresql"
> is to keep consistency in system configuration.

Hmm, I think ACE should be a CREATE DATABASE parameter.

If I were to create a SE-database I would wish that disabling it was
more difficult than changing a GUC in database. And being able to
set it on per-database basis would help get SE/ACE enabled by
packagers.

Regards,
Dawid
--
Solving [site load issues] with [more database replication] is a lot
like solving your own personal problems with heroin - at first it
sorta works, but after a while things just get out of hand.

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Greg Smith 2008-06-02 10:21:05 Re: Overhauling GUCS
Previous Message Kaare Rasmussen 2008-06-02 09:18:34 Re: [ANNOUNCE] == PostgreSQL Weekly News - June 01 2008 ==

Browse pgsql-patches by date

  From Date Subject
Next Message David Fetter 2008-06-02 10:12:36 Re: Feature: give pg_dump a WHERE clause expression
Previous Message Heikki Linnakangas 2008-06-02 07:52:51 Re: extend VacAttrStats to allow stavalues of different types