Re: Adding support for SE-Linux security

From: Greg Smith <greg(at)2ndquadrant(dot)com>
To: Joshua Brindle <method(at)manicmethod(dot)com>
Cc: Stephen Frost <sfrost(at)snowman(dot)net>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, Robert Haas <robertmhaas(at)gmail(dot)com>, Bruce Momjian <bruce(at)momjian(dot)us>, Magnus Hagander <magnus(at)hagander(dot)net>, Chad Sellers <csellers(at)tresys(dot)com>, "David P(dot) Quigley" <dpquigl(at)tycho(dot)nsa(dot)gov>, Josh Berkus <josh(at)agliodbs(dot)com>, KaiGai Kohei <kaigai(at)ak(dot)jp(dot)nec(dot)com>, jd <jd(at)commandprompt(dot)com>, David Fetter <david(at)fetter(dot)org>, Itagaki Takahiro <itagaki(dot)takahiro(at)oss(dot)ntt(dot)co(dot)jp>, KaiGai Kohei <kaigai(at)kaigai(dot)gr(dot)jp>, pgsql-hackers <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Adding support for SE-Linux security
Date: 2009-12-12 00:15:20
Message-ID: 4B22E098.6000802@2ndquadrant.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

I just did a round of integrating some of the big-picture feedback that
has shown up here since the meeting into
http://wiki.postgresql.org/wiki/SEPostgreSQL_Review_at_the_BWPUG ,
mainly supplementing the references in the "Works outside of SELinux"
section with the new suggested reading here suggested by Stephen Smalley
and Joshua Brindle. I'm trying to keep that a fairly readable intro to
the controversial parts rather than going deeply technical.

What I'm not going to try to track is all the low-level implementation
details that are bouncing around right now, my brain is too full this
week to cram more about OID trivia into it right now. That would be a
good idea for someone to summarize eventually and then throw that onto
the wiki somewhere else, so that it's easier to remember the context of
what/why decisions were made. The way Simon has been keeping an ongoing
log at http://wiki.postgresql.org/wiki/Hot_Standby shows a reasonable
way to organize such a thing from a similarly complicated patch.

--
Greg Smith 2ndQuadrant Baltimore, MD
PostgreSQL Training, Services and Support
greg(at)2ndQuadrant(dot)com www.2ndQuadrant.com

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Andres Freund 2009-12-12 00:19:38 Re: 8.4.1 ubuntu karmic slow createdb
Previous Message Scott Marlowe 2009-12-11 23:59:13 Re: 8.4.1 ubuntu karmic slow createdb