All of lore.kernel.org
 help / color / mirror / Atom feed
* postgresql policy
@ 2015-05-28 16:52 Ted Toth
  2015-05-28 18:54 ` Stephen Smalley
  0 siblings, 1 reply; 14+ messages in thread
From: Ted Toth @ 2015-05-28 16:52 UTC (permalink / raw)
  To: SELinux

The ref policy contains a number of sepgsql_ types that are specific
to the sepgsql postgresql module. The sepgsql module was written to
support a postgresql security patch that was never accepted by the
upstream. Now postgresql has gone in a different direction security
wise adding row level security (RLS). I've been working on developing
RLS policy to label rows on insert and update and to check access
perms on select. I've tried using the sepgsql module in the RLS policy
but have come to the conclusion that because it was not designed for
this purpose it is not usable. So I'd like to suggest that these types
be moved out of the postgresql policy possibly into their own module
although I personally think they have little if any use.

Ted

^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2015-05-29 14:48 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-05-28 16:52 postgresql policy Ted Toth
2015-05-28 18:54 ` Stephen Smalley
2015-05-28 19:09   ` Stephen Frost
2015-05-28 19:27     ` Stephen Smalley
2015-05-28 19:40       ` Ted Toth
2015-05-28 19:43         ` Stephen Frost
2015-05-28 19:50           ` Ted Toth
2015-05-28 19:10   ` Ted Toth
2015-05-28 19:28     ` Stephen Smalley
2015-05-28 19:34       ` Ted Toth
2015-05-28 19:41         ` Stephen Frost
2015-05-28 19:43           ` Ted Toth
2015-05-28 19:49             ` Stephen Frost
2015-05-29 14:48   ` Christopher J. PeBenito

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.