Re: Proposal of SE-PostgreSQL patches (for CommitFest:Sep)

From: Peter Eisentraut <peter_e(at)gmx(dot)net>
To: Bruce Momjian <bruce(at)momjian(dot)us>
Cc: Aidan Van Dyk <aidan(at)highrise(dot)ca>, Robert Haas <robertmhaas(at)gmail(dot)com>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>, josh(at)agliodbs(dot)com, pgsql-hackers(at)postgresql(dot)org
Subject: Re: Proposal of SE-PostgreSQL patches (for CommitFest:Sep)
Date: 2008-09-24 17:12:05
Message-ID: 48DA74E5.4050902@gmx.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Bruce Momjian wrote:
> Peter, I am confused how the above statement relates to a posting you
> made a week ago:
>
> http://archives.postgresql.org/pgsql-hackers/2008-09/msg01067.php
>
> Now these items are arguably useful and welcome features in their own
> right. Unfortunately, this patch has chosen to provide these features in
> a way that makes them accessible to the least amount of users. And
> moreover, it bunches them all in one feature, while they should really
> be available independently.

I just want to distinguish the causalities in the various arguments that
are being made. There are many ways to approach this, two of which
could be:

We want MAC => SELinux is the only proven way to implement MAC => let's
take the patch

or

SELinux is way too complex => We don't take the patch => Figure out the
MAC issue some other way

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Peter Eisentraut 2008-09-24 17:18:30 Re: Proposal of SE-PostgreSQL patches (for CommitFest:Sep)
Previous Message Andrew Dunstan 2008-09-24 16:56:34 Re: parallel pg_restore