Re: One question about security label command

Поиск
Список
Период
Сортировка
От Alvaro Herrera
Тема Re: One question about security label command
Дата
Msg-id 20150316134056.GB3636@alvh.no-ip.org
обсуждение исходный текст
Ответ на Re: One question about security label command  (Kohei KaiGai <kaigai@kaigai.gr.jp>)
Ответы Re: One question about security label command  (Stephen Frost <sfrost@snowman.net>)
Список pgsql-hackers
Kohei KaiGai wrote:

> This regression test fail come from the base security policy of selinux.
> In the recent selinux-policy package, "unconfined" domain was changed
> to have unrestricted permission as literal. So, this test case relies multi-
> category policy restricts unconfined domain, but its assumption is not
> correct now.

Makes sense.

> The attached patch fixes the policy module of regression test.

What branches need this patch?  Do we need a modified patch for
earlier branches?

Could you provide a buildfarm animal that runs the sepgsql test in all
branches on a regular basis?

> However, I also think we may stop to rely permission set of pre-defined
> selinux domains. Instead of pre-defined one, sepgsql-regtest.te may be
> ought to define own domain with appropriate permission set independent
> from the base selinux-policy version.

Is this something we would backpatch?

-- 
Álvaro Herrera                http://www.2ndQuadrant.com/
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Simon Riggs
Дата:
Сообщение: Re: Reduce pinning in btree indexes
Следующее
От: Stephen Frost
Дата:
Сообщение: Re: One question about security label command