Re: Adding support for SE-Linux security

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Adding support for SE-Linux security
Дата
Msg-id 4816.1260201348@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: Adding support for SE-Linux security  (Robert Haas <robertmhaas@gmail.com>)
Ответы Re: Adding support for SE-Linux security  (KaiGai Kohei <kaigai@ak.jp.nec.com>)
Список pgsql-hackers
Robert Haas <robertmhaas@gmail.com> writes:
> On Mon, Dec 7, 2009 at 9:48 AM, Bruce Momjian <bruce@momjian.us> wrote:
>> I wonder if we should rephrase this as, "How hard will this feature be
>> to add, and how hard will it be to remove in a few years if we decide we
>> don't want it?"

> Yes, I think that's the right way to think about it.  At a guess, it's
> two man-months of work to get it in,

It's not the "get it in" part that scares me.  The problem I have with
it is that I see it as a huge time sink for future maintenance problems,
most of which will be classifiable as security breaches which increases
the pain of dealing with them immeasurably.

If I had more confidence that the basic design was right or useful
I might not be so worried about the maintenance prospects, but frankly
I have almost no confidence in it.  This comes back to the lack of
involvement of any potential user community.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Jaime Casanova
Дата:
Сообщение: Re: New PostgreSQL Committers
Следующее
От: Dimitri Fontaine
Дата:
Сообщение: Re: [GENERAL] Installing PL/pgSQL by default