Re: [RFC] sepgsql: prohibit users to relabel objects

From: Denis Kirjanov <kda(at)itsirius(dot)su>
To: Robert Haas <robertmhaas(at)gmail(dot)com>
Cc: Denis Kirjanov <kda(at)linux-powerpc(dot)org>, pgsql-hackers(at)postgresql(dot)org, Alexey Zhuchkov <alexey(at)itsirius(dot)su>
Subject: Re: [RFC] sepgsql: prohibit users to relabel objects
Date: 2015-04-30 08:13:50
Message-ID: 857759077.307154.1430381630482.JavaMail.zimbra@itsirius.su
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Oh, I wasn't aware of that.
Any hints where to look at?

Thanks!

PS: sorry for top posting.

----- Original Message -----
From: "Robert Haas" <robertmhaas(at)gmail(dot)com>
To: "Denis Kirjanov" <kda(at)linux-powerpc(dot)org>
Cc: pgsql-hackers(at)postgresql(dot)org, "Alexey Zhuchkov" <alexey(at)itsirius(dot)su>, "Denis Kirjanov" <kda(at)itsirius(dot)su>
Sent: Wednesday, April 29, 2015 9:01:36 PM
Subject: Re: [HACKERS] [RFC] sepgsql: prohibit users to relabel objects

On Wed, Apr 29, 2015 at 9:15 AM, Denis Kirjanov <kda(at)linux-powerpc(dot)org> wrote:
> Enforce access control on security labels defined by admin
> and prohibit users to relabel the objects

Really? Why? I would think it's the policy's job to restrict relabel
operations.

--
Robert Haas
EnterpriseDB: http://www.enterprisedb.com
The Enterprise PostgreSQL Company

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Etsuro Fujita 2015-04-30 08:15:46 Re: Missing importing option of postgres_fdw
Previous Message Etsuro Fujita 2015-04-30 07:59:54 Re: Minor improvement to config.sgml