Re: SE-PgSQL patch review - Mailing list pgsql-hackers

From Bruce Momjian
Subject Re: SE-PgSQL patch review
Date
Msg-id 200912020315.nB23FtB22523@momjian.us
Whole thread Raw
In response to Re: SE-PgSQL patch review  (Greg Williamson <gwilliamson39@yahoo.com>)
List pgsql-hackers
Greg Williamson wrote:
> As far as I can see, SUSE, Ubuntu and Debian provide SELinux
> option.  But they are more conservative than RedHat/Fedora,
> because it is not enabled in the default installation.
> 
> I don't think it is unpreferable decision. Users can choose the
> option by themself according to requirements in the system.
> 
> ===
> 
> How much of the work currently at hand might be applicable to
> other security models ? Would this be useful groundwork for
> anyone who wanted to implement other frameworks in terms of
> hooks, cleanup of existing code, etc. ?

Yes, it would offer clear groundwork for that, and could be easily
extended.  We didn't implement such a system at this stage because it
would have added additional code, but once there is demand the system
could be easily extended.

-- Bruce Momjian  <bruce@momjian.us>        http://momjian.us EnterpriseDB
http://enterprisedb.com
 + If your life is a hard drive, Christ can be your backup. +


pgsql-hackers by date:

Previous
From: Greg Williamson
Date:
Subject: Re: SE-PgSQL patch review
Next
From: Robert Haas
Date:
Subject: Re: Page-level version upgrade (was: Block-level CRC checks)