Re: Adding support for SE-Linux security - Mailing list pgsql-hackers

From Greg Smith
Subject Re: Adding support for SE-Linux security
Date
Msg-id 4B22E098.6000802@2ndquadrant.com
Whole thread Raw
In response to Re: Adding support for SE-Linux security  (Joshua Brindle <method@manicmethod.com>)
List pgsql-hackers
I just did a round of integrating some of the big-picture feedback that 
has shown up here since the meeting into 
http://wiki.postgresql.org/wiki/SEPostgreSQL_Review_at_the_BWPUG , 
mainly supplementing the references in the "Works outside of SELinux" 
section with the new suggested reading here suggested by Stephen Smalley 
and Joshua Brindle.  I'm trying to keep that a fairly readable intro to 
the controversial parts rather than going deeply technical. 

What I'm not going to try to track is all the low-level implementation 
details that are bouncing around right now, my brain is too full this 
week to cram more about OID trivia into it right now.  That would be a 
good idea for someone to summarize eventually and then throw that onto 
the wiki somewhere else, so that it's easier to remember the context of 
what/why decisions were made.  The way Simon has been keeping an ongoing 
log at http://wiki.postgresql.org/wiki/Hot_Standby shows a reasonable 
way to organize such a thing from a similarly complicated patch.

-- 
Greg Smith    2ndQuadrant   Baltimore, MD
PostgreSQL Training, Services and Support
greg@2ndQuadrant.com  www.2ndQuadrant.com



pgsql-hackers by date:

Previous
From: Greg Smith
Date:
Subject: Re: [PATCH] dtrace probes for memory manager
Next
From: Robert Haas
Date:
Subject: Re: Adding support for SE-Linux security