Re: [sepgsql] missing checks of process:transition on trusted procedure invocation

Поиск
Список
Период
Сортировка
От Robert Haas
Тема Re: [sepgsql] missing checks of process:transition on trusted procedure invocation
Дата
Msg-id BANLkTikMyhv+0meGGoBWravO_VhOM9QJew@mail.gmail.com
обсуждение исходный текст
Список pgsql-hackers
On Mon, Apr 4, 2011 at 11:01 AM, Kohei Kaigai <Kohei.Kaigai@eu.nec.com> wrote:
> Sorry, I missed a permission check on invocation of trusted procedures.
>
> When client's label getting switched to Y from X, we needed to check
> process:transition permission between label X and label Y.
> It is same manner when OS launches a program with a special label to
> cause domain transition.
>
> The attached patch adds checks this permission when user tries to
> invoke a trusted procedure and switch security label of the client.
> In addition, it also adds a case of regression test of this problem.

Committed.

-- 
Robert Haas
EnterpriseDB: http://www.enterprisedb.com
The Enterprise PostgreSQL Company


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Robert Haas
Дата:
Сообщение: Re: trivial patch: show SIREAD pids in pg_locks
Следующее
От: Susanne Ebrecht
Дата:
Сообщение: Re: [DOCS] Uppercase SGML entity declarations