Re: SE-PgSQL patch review - Mailing list pgsql-hackers

From Tom Lane
Subject Re: SE-PgSQL patch review
Date
Msg-id 6133.1259696787@sss.pgh.pa.us
Whole thread Raw
In response to Re: SE-PgSQL patch review  ("Joshua D. Drake" <jd@commandprompt.com>)
Responses Re: SE-PgSQL patch review  ("Joshua D. Drake" <jd@commandprompt.com>)
Re: SE-PgSQL patch review  (KaiGai Kohei <kaigai@ak.jp.nec.com>)
Re: SE-PgSQL patch review  ("Joshua D. Drake" <jd@commandprompt.com>)
List pgsql-hackers
"Joshua D. Drake" <jd@commandprompt.com> writes:
> On Mon, 2009-11-30 at 20:28 -0800, David Fetter wrote:
>> This is totally separate from the really important question of whether
>> SE-Linux has a future, and another about whether, if SE-Linux has a
>> future, PostgreSQL needs to go there.

> Why would we think that it doesn't?

Have you noticed anyone except Red Hat taking it seriously?

I work for Red Hat and have drunk a reasonable amount of the SELinux
koolaid, but I can't help observing that it's had very limited uptake
outside Red Hat.  It's not clear that there are many people who find
it a cost-effective solution to their problems.  As for the number of
people prepared to write custom policy for it --- which would be
required to use it effectively for almost any PG application ---
I could probably hold a house party for all of them and not break a
sweat serving drinks.
        regards, tom lane


pgsql-hackers by date:

Previous
From: Greg Stark
Date:
Subject: Re: Block-level CRC checks
Next
From: Robert Haas
Date:
Subject: Re: Block-level CRC checks