Re: sepgsql logging - Mailing list pgsql-hackers

From Dave Page
Subject Re: sepgsql logging
Date
Msg-id CA+OCxoxbCwOgu=6jDAO56vN=JJOzeQjbGCzEomHAgLvAo8JzJA@mail.gmail.com
Whole thread Raw
In response to Re: sepgsql logging  (Tom Lane <tgl@sss.pgh.pa.us>)
Responses Re: sepgsql logging  (Dave Page <dpage@pgadmin.org>)
List pgsql-hackers


On Thu, Apr 1, 2021 at 3:23 PM Tom Lane <tgl@sss.pgh.pa.us> wrote:
Andrew Dunstan <andrew@dunslane.net> writes:
> On 4/1/21 8:32 AM, Dave Page wrote:
>> It seems to me that sepgsql should also log the denial, but flag that
>> permissive mode is on.

> +1 for doing what selinux does if possible.

+1.  If selinux itself is doing that, it's hard to see a reason why
we should not; and I concur that the info is useful.

Thanks both. I'll take a look at the code and see if I can whip up a patch (it'll be a week or so as I'm taking some time off for Easter).
 
--
Dave Page
Blog: http://pgsnake.blogspot.com
Twitter: @pgsnake

EDB: http://www.enterprisedb.com

pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: sepgsql logging
Next
From: Arne Roland
Date:
Subject: Re: Rename of triggers for partitioned tables