Re: Adding support for SE-Linux security - Mailing list pgsql-hackers

From Stephen Frost
Subject Re: Adding support for SE-Linux security
Date
Msg-id 20091215032106.GW17756@tamriel.snowman.net
Whole thread Raw
In response to Re: Adding support for SE-Linux security  (Bruce Momjian <bruce@momjian.us>)
Responses Re: Adding support for SE-Linux security
List pgsql-hackers
Bruce,

* Bruce Momjian (bruce@momjian.us) wrote:
> You are fine.  I was just saying that at a time I was one of the few
> loud voices on this, and if this is going to happen, it will be because
> we have a team that wants to do this, not because I am being loud.  I
> see the team forming nicely.

Not to rain down on the parade too much here, but I have to disagree
about a team forming nicely.  That's, unfortunately, what it looks like
from the 10k-foot level.  Indeed, it looks like we're making good
headway to get some kind of support into core from that level.

The reality is that we've barely started and really have still got
quite a ways to go and it would really be useful to bring in additional
resources on this.  I wouldn't consider myself to be that "additional
resource" unless and until I can get funding for dedicated time (either
my own or someone else's).  I've got a few action items that I'm
planning to resolve in the next few weeks, but I've been involved in
this for over a year now and it hasn't made much progress, overall, in
that time.

So, for anyone else who's interested in label-based security happening
for PostgreSQL (for whatever reason, masochisim perfectly acceptable),
please speak up and offer to help.  We could use it.
Thanks,
    Stephen

pgsql-hackers by date:

Previous
From: Jaime Casanova
Date:
Subject: Re: Syntax for partitioning
Next
From: Robert Haas
Date:
Subject: Re: Row-Level Security