Re: Updates of SE-PostgreSQL 8.4devel patches (r1268) - Mailing list pgsql-hackers

From KaiGai Kohei
Subject Re: Updates of SE-PostgreSQL 8.4devel patches (r1268)
Date
Msg-id 49413ED6.5030306@kaigai.gr.jp
Whole thread Raw
In response to Re: Updates of SE-PostgreSQL 8.4devel patches (r1268)  (Peter Eisentraut <peter_e@gmx.net>)
Responses Re: Updates of SE-PostgreSQL 8.4devel patches (r1268)
List pgsql-hackers
Peter Eisentraut wrote:
> On Thursday 11 December 2008 17:09:25 Tom Lane wrote:
>> I think there should be only *one* underlying column and that it should
>> be manipulable by either SQL commands or selinux.  Otherwise you're
>> making a lie of the primary argument for having the SQL feature at all.
> 
> Well, an SQL-manipulated row security column will probably have a content like
> 
>     {joe=rw/bob,staff=r/bob}
> 
> An SELinux-aware row security column will probably have a content like
> 
>    blah_t:foo_t:quux_t
> 
> And a Solaris TX-aware security column will probably have a content like
> 
>    Classified
> 
> How can we stick all of these in the same column at the same time?

To choose it on compile-time option is the most simple approach.


pgsql-hackers by date:

Previous
From: "Pavel Stehule"
Date:
Subject: Re: COCOMO & Indians
Next
From: Peter Eisentraut
Date:
Subject: Re: Updates of SE-PostgreSQL 8.4devel patches (r1268)