Re: One question about security label command

From: Stephen Frost <sfrost(at)snowman(dot)net>
To: Alvaro Herrera <alvherre(at)2ndquadrant(dot)com>
Cc: Kohei KaiGai <kaigai(at)kaigai(dot)gr(dot)jp>, Robert Haas <robertmhaas(at)gmail(dot)com>, Kouhei Kaigai <kaigai(at)ak(dot)jp(dot)nec(dot)com>, 张元超 <zhangyuanchao(at)highgo(dot)com>, "pgsql-hackers(at)postgresql(dot)org" <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: One question about security label command
Date: 2015-03-16 13:51:41
Message-ID: 20150316135141.GH29780@tamriel.snowman.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Alvaro, KaiGai,

* Alvaro Herrera (alvherre(at)2ndquadrant(dot)com) wrote:
> Kohei KaiGai wrote:
>
> > This regression test fail come from the base security policy of selinux.
> > In the recent selinux-policy package, "unconfined" domain was changed
> > to have unrestricted permission as literal. So, this test case relies multi-
> > category policy restricts unconfined domain, but its assumption is not
> > correct now.
>
> Makes sense.
>
> > The attached patch fixes the policy module of regression test.
>
> What branches need this patch? Do we need a modified patch for
> earlier branches?
>
> Could you provide a buildfarm animal that runs the sepgsql test in all
> branches on a regular basis?

Would be great if KaiGai can, of course, but I'm planning to stand one
up here soon in any case.

> > However, I also think we may stop to rely permission set of pre-defined
> > selinux domains. Instead of pre-defined one, sepgsql-regtest.te may be
> > ought to define own domain with appropriate permission set independent
> > from the base selinux-policy version.
>
> Is this something we would backpatch?

As it's just a change to the regression tests, it seems like it'd be a
good idea to backpatch it to me as there's very low risk of it breaking
anything and it'd actually fix the tests when they're run.

Thanks!

Stephen

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Tom Lane 2015-03-16 14:09:01 Re: One question about security label command
Previous Message Alvaro Herrera 2015-03-16 13:40:56 Re: One question about security label command