Re: How to get SE-PostgreSQL acceptable - Mailing list pgsql-hackers

From Joshua Brindle
Subject Re: How to get SE-PostgreSQL acceptable
Date
Msg-id 49871634.3090403@manicmethod.com
Whole thread Raw
In response to Re: How to get SE-PostgreSQL acceptable  (Josh Berkus <josh@agliodbs.com>)
List pgsql-hackers
Josh Berkus wrote:
> Joshua, Kohei-san,
> 
> So, for 8.4:  *if* we included in 8.4 a version of SEPostgres with all 
> features *except* row-level security, would it still be useful to the 
> SELinux community?
> 
> I think we're just not going to work out the headache-inducing issues 
> around row-level security in time for 8.4, and it seems to me that 
> integrated system-level security labels at the table-and-column level 
> are still very useful, even without row-level security.
> 

Sorry for the delay in answering, I'm currently on vacation (I haven't been able 
to catch up on this thread yet either, I'll try to a little later).

The answer is yes, at least to get people started using it and make sure there 
are no practical issues with the security model sans row access control.

But as I said earlier row based access control is going to be the most 
compelling part so hopefully the issues everyone is having can get worked out 
and the community will agree on the path forward, sooner rather than later.


pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: parallel restore
Next
From: Grzegorz Jaskiewicz
Date:
Subject: Re: add_path optimization