Re: [PATCH] unalias of ACL_SELECT_FOR_UPDATE

Поиск
Список
Период
Сортировка
От KaiGai Kohei
Тема Re: [PATCH] unalias of ACL_SELECT_FOR_UPDATE
Дата
Msg-id 49EADF16.3050400@kaigai.gr.jp
обсуждение исходный текст
Ответ на [PATCH] unalias of ACL_SELECT_FOR_UPDATE  (KaiGai Kohei <kaigai@ak.jp.nec.com>)
Ответы Re: [PATCH] unalias of ACL_SELECT_FOR_UPDATE  (Tom Lane <tgl@sss.pgh.pa.us>)
Список pgsql-hackers
Heikki Linnakangas wrote:
> KaiGai Kohei wrote:
>> However, ACL_UPDATE and ACL_SELECT_FOR_UPDATE internally shares same bit
>> so SE-PostgreSQL cannot discriminate between UPDATE and SELECT FOR UPDATE
>> or SHARE.
> 
> Why should it discriminate between them?

Typically, we cannot set up a foreign-key which refers a primary-key within
read-only table from SELinux's viewpoint.
The vanilla access control mechanism switches the current userid, and it enables
to run SELECT FOR SHARE without ACL_UPDATE, but SELinux's security model does not
have a concept of ownership.

Thanks,
-- 
KaiGai Kohei <kaigai@kaigai.gr.jp>


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Brendan Jurd
Дата:
Сообщение: to_timestamp() changes in 8.4 release notes
Следующее
От: Heikki Linnakangas
Дата:
Сообщение: Re: 8.4b1: Query returning results in different order to 8.3